{"version":3,"file":"firebase-auth-compat.js","sources":["../util/dist/postinstall.mjs","../util/src/crypt.ts","../util/src/defaults.ts","../util/src/global.ts","../logger/src/logger.ts","../util/src/environment.ts","../util/src/errors.ts","../util/src/obj.ts","../util/src/query.ts","../util/src/subscribe.ts","../util/src/compat.ts","../util/src/url.ts","../component/src/component.ts","../auth/src/model/enum_maps.ts","../auth/src/core/errors.ts","../auth/src/core/util/log.ts","../auth/src/core/util/assert.ts","../auth/src/core/util/location.ts","../auth/src/core/util/delay.ts","../auth/src/core/util/navigator.ts","../auth/src/core/util/emulator.ts","../auth/src/core/util/fetch_provider.ts","../auth/src/api/errors.ts","../auth/src/api/index.ts","../auth/src/platform_browser/recaptcha/recaptcha.ts","../auth/src/api/authentication/recaptcha.ts","../auth/src/api/account_management/account.ts","../auth/src/core/util/time.ts","../auth/src/core/user/id_token_result.ts","../auth/src/core/user/invalidation.ts","../auth/src/core/user/proactive_refresh.ts","../auth/src/core/user/user_metadata.ts","../auth/src/core/user/reload.ts","../auth/src/core/user/token_manager.ts","../auth/src/api/authentication/token.ts","../auth/src/core/user/user_impl.ts","../auth/src/core/util/instantiator.ts","../auth/src/core/persistence/in_memory.ts","../auth/src/core/persistence/persistence_user_manager.ts","../auth/src/core/util/browser.ts","../auth/src/core/util/version.ts","../auth/src/core/auth/middleware.ts","../auth/src/core/auth/password_policy_impl.ts","../auth/src/core/auth/auth_impl.ts","../auth/src/api/password_policy/get_password_policy.ts","../auth/src/platform_browser/load_js.ts","../auth/src/platform_browser/recaptcha/recaptcha_mock.ts","../auth/src/platform_browser/recaptcha/recaptcha_enterprise_verifier.ts","../auth/src/core/auth/emulator.ts","../auth/src/core/credentials/auth_credential.ts","../auth/src/api/account_management/email_and_password.ts","../auth/src/api/authentication/email_and_password.ts","../auth/src/core/credentials/email.ts","../auth/src/api/authentication/email_link.ts","../auth/src/api/authentication/idp.ts","../auth/src/core/credentials/oauth.ts","../auth/src/api/authentication/sms.ts","../auth/src/core/credentials/phone.ts","../auth/src/core/action_code_url.ts","../auth/src/core/providers/email.ts","../auth/src/core/providers/federated.ts","../auth/src/core/providers/oauth.ts","../auth/src/core/providers/facebook.ts","../auth/src/core/providers/google.ts","../auth/src/core/providers/github.ts","../auth/src/core/credentials/saml.ts","../auth/src/core/providers/saml.ts","../auth/src/core/providers/twitter.ts","../auth/src/api/authentication/sign_up.ts","../auth/src/core/user/user_credential_impl.ts","../auth/src/mfa/mfa_error.ts","../auth/src/core/util/providers.ts","../auth/src/core/user/link_unlink.ts","../auth/src/core/user/reauthenticate.ts","../auth/src/core/strategies/credential.ts","../auth/src/core/strategies/custom_token.ts","../auth/src/api/authentication/custom_token.ts","../auth/src/mfa/mfa_info.ts","../auth/src/core/strategies/action_code_settings.ts","../auth/src/core/strategies/email_and_password.ts","../auth/src/core/strategies/email.ts","../auth/src/api/authentication/create_auth_uri.ts","../auth/src/core/user/account_info.ts","../auth/src/api/account_management/profile.ts","../auth/src/core/user/additional_user_info.ts","../auth/src/mfa/mfa_session.ts","../auth/src/mfa/mfa_resolver.ts","../auth/src/api/account_management/mfa.ts","../auth/src/mfa/mfa_user.ts","../auth/src/core/persistence/index.ts","../auth/src/platform_browser/persistence/browser.ts","../auth/src/platform_browser/persistence/local_storage.ts","../auth/src/platform_browser/persistence/session_storage.ts","../auth/src/platform_browser/messagechannel/receiver.ts","../auth/src/platform_browser/messagechannel/promise.ts","../auth/src/core/util/event_id.ts","../auth/src/platform_browser/messagechannel/sender.ts","../auth/src/platform_browser/auth_window.ts","../auth/src/platform_browser/util/worker.ts","../auth/src/platform_browser/persistence/indexed_db.ts","../auth/src/api/authentication/mfa.ts","../auth/src/platform_browser/recaptcha/recaptcha_loader.ts","../auth/src/platform_browser/recaptcha/recaptcha_verifier.ts","../auth/src/platform_browser/strategies/phone.ts","../auth/src/platform_browser/providers/phone.ts","../auth/src/core/util/resolver.ts","../auth/src/core/strategies/idp.ts","../auth/src/core/strategies/abstract_popup_redirect_operation.ts","../auth/src/platform_browser/strategies/popup.ts","../auth/src/core/strategies/redirect.ts","../auth/src/platform_browser/strategies/redirect.ts","../auth/src/core/auth/auth_event_manager.ts","../auth/src/api/project_config/get_project_config.ts","../auth/src/core/util/validate_origin.ts","../auth/src/platform_browser/iframe/gapi.ts","../auth/src/platform_browser/iframe/iframe.ts","../auth/src/platform_browser/util/popup.ts","../auth/src/core/util/handler.ts","../auth/src/platform_browser/popup_redirect.ts","../auth/src/platform_browser/mfa/assertions/phone.ts","../auth/src/mfa/mfa_assertion.ts","../auth/src/core/auth/firebase_internal.ts","../auth/src/platform_browser/index.ts","../auth/src/core/auth/register.ts","../auth/src/platform_cordova/plugins.ts","../auth/src/core/auth/initialize.ts","../auth/src/platform_cordova/popup_redirect/utils.ts","../auth/src/platform_cordova/popup_redirect/events.ts","../auth/src/platform_cordova/popup_redirect/popup_redirect.ts","../auth-compat/index.ts","../auth-compat/src/platform.ts","../auth-compat/src/persistence.ts","../auth-compat/src/popup_redirect.ts","../auth-compat/src/wrap.ts","../auth-compat/src/user_credential.ts","../auth-compat/src/user.ts","../auth-compat/src/auth.ts","../auth/src/core/strategies/email_link.ts","../auth/internal/index.ts","../auth/src/core/strategies/anonymous.ts","../auth-compat/src/phone_auth_provider.ts","../auth-compat/src/recaptcha_verifier.ts"],"sourcesContent":["/**\n * @license\n * Copyright 2025 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n// This value is retrieved and hardcoded by the NPM postinstall script\nconst getDefaultsFromPostinstall = () => undefined;\n\nexport { getDefaultsFromPostinstall };\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nconst stringToByteArray = function (str: string): number[] {\n  // TODO(user): Use native implementations if/when available\n  const out: number[] = [];\n  let p = 0;\n  for (let i = 0; i < str.length; i++) {\n    let c = str.charCodeAt(i);\n    if (c < 128) {\n      out[p++] = c;\n    } else if (c < 2048) {\n      out[p++] = (c >> 6) | 192;\n      out[p++] = (c & 63) | 128;\n    } else if (\n      (c & 0xfc00) === 0xd800 &&\n      i + 1 < str.length &&\n      (str.charCodeAt(i + 1) & 0xfc00) === 0xdc00\n    ) {\n      // Surrogate Pair\n      c = 0x10000 + ((c & 0x03ff) << 10) + (str.charCodeAt(++i) & 0x03ff);\n      out[p++] = (c >> 18) | 240;\n      out[p++] = ((c >> 12) & 63) | 128;\n      out[p++] = ((c >> 6) & 63) | 128;\n      out[p++] = (c & 63) | 128;\n    } else {\n      out[p++] = (c >> 12) | 224;\n      out[p++] = ((c >> 6) & 63) | 128;\n      out[p++] = (c & 63) | 128;\n    }\n  }\n  return out;\n};\n\n/**\n * Turns an array of numbers into the string given by the concatenation of the\n * characters to which the numbers correspond.\n * @param bytes Array of numbers representing characters.\n * @return Stringification of the array.\n */\nconst byteArrayToString = function (bytes: number[]): string {\n  // TODO(user): Use native implementations if/when available\n  const out: string[] = [];\n  let pos = 0,\n    c = 0;\n  while (pos < bytes.length) {\n    const c1 = bytes[pos++];\n    if (c1 < 128) {\n      out[c++] = String.fromCharCode(c1);\n    } else if (c1 > 191 && c1 < 224) {\n      const c2 = bytes[pos++];\n      out[c++] = String.fromCharCode(((c1 & 31) << 6) | (c2 & 63));\n    } else if (c1 > 239 && c1 < 365) {\n      // Surrogate Pair\n      const c2 = bytes[pos++];\n      const c3 = bytes[pos++];\n      const c4 = bytes[pos++];\n      const u =\n        (((c1 & 7) << 18) | ((c2 & 63) << 12) | ((c3 & 63) << 6) | (c4 & 63)) -\n        0x10000;\n      out[c++] = String.fromCharCode(0xd800 + (u >> 10));\n      out[c++] = String.fromCharCode(0xdc00 + (u & 1023));\n    } else {\n      const c2 = bytes[pos++];\n      const c3 = bytes[pos++];\n      out[c++] = String.fromCharCode(\n        ((c1 & 15) << 12) | ((c2 & 63) << 6) | (c3 & 63)\n      );\n    }\n  }\n  return out.join('');\n};\n\ninterface Base64 {\n  byteToCharMap_: { [key: number]: string } | null;\n  charToByteMap_: { [key: string]: number } | null;\n  byteToCharMapWebSafe_: { [key: number]: string } | null;\n  charToByteMapWebSafe_: { [key: string]: number } | null;\n  ENCODED_VALS_BASE: string;\n  readonly ENCODED_VALS: string;\n  readonly ENCODED_VALS_WEBSAFE: string;\n  HAS_NATIVE_SUPPORT: boolean;\n  encodeByteArray(input: number[] | Uint8Array, webSafe?: boolean): string;\n  encodeString(input: string, webSafe?: boolean): string;\n  decodeString(input: string, webSafe: boolean): string;\n  decodeStringToByteArray(input: string, webSafe: boolean): number[];\n  init_(): void;\n}\n\n// We define it as an object literal instead of a class because a class compiled down to es5 can't\n// be treeshaked. https://github.com/rollup/rollup/issues/1691\n// Static lookup maps, lazily populated by init_()\n// TODO(dlarocque): Define this as a class, since we no longer target ES5.\nexport const base64: Base64 = {\n  /**\n   * Maps bytes to characters.\n   */\n  byteToCharMap_: null,\n\n  /**\n   * Maps characters to bytes.\n   */\n  charToByteMap_: null,\n\n  /**\n   * Maps bytes to websafe characters.\n   * @private\n   */\n  byteToCharMapWebSafe_: null,\n\n  /**\n   * Maps websafe characters to bytes.\n   * @private\n   */\n  charToByteMapWebSafe_: null,\n\n  /**\n   * Our default alphabet, shared between\n   * ENCODED_VALS and ENCODED_VALS_WEBSAFE\n   */\n  ENCODED_VALS_BASE:\n    'ABCDEFGHIJKLMNOPQRSTUVWXYZ' + 'abcdefghijklmnopqrstuvwxyz' + '0123456789',\n\n  /**\n   * Our default alphabet. Value 64 (=) is special; it means \"nothing.\"\n   */\n  get ENCODED_VALS() {\n    return this.ENCODED_VALS_BASE + '+/=';\n  },\n\n  /**\n   * Our websafe alphabet.\n   */\n  get ENCODED_VALS_WEBSAFE() {\n    return this.ENCODED_VALS_BASE + '-_.';\n  },\n\n  /**\n   * Whether this browser supports the atob and btoa functions. This extension\n   * started at Mozilla but is now implemented by many browsers. We use the\n   * ASSUME_* variables to avoid pulling in the full useragent detection library\n   * but still allowing the standard per-browser compilations.\n   *\n   */\n  HAS_NATIVE_SUPPORT: typeof atob === 'function',\n\n  /**\n   * Base64-encode an array of bytes.\n   *\n   * @param input An array of bytes (numbers with\n   *     value in [0, 255]) to encode.\n   * @param webSafe Boolean indicating we should use the\n   *     alternative alphabet.\n   * @return The base64 encoded string.\n   */\n  encodeByteArray(input: number[] | Uint8Array, webSafe?: boolean): string {\n    if (!Array.isArray(input)) {\n      throw Error('encodeByteArray takes an array as a parameter');\n    }\n\n    this.init_();\n\n    const byteToCharMap = webSafe\n      ? this.byteToCharMapWebSafe_!\n      : this.byteToCharMap_!;\n\n    const output = [];\n\n    for (let i = 0; i < input.length; i += 3) {\n      const byte1 = input[i];\n      const haveByte2 = i + 1 < input.length;\n      const byte2 = haveByte2 ? input[i + 1] : 0;\n      const haveByte3 = i + 2 < input.length;\n      const byte3 = haveByte3 ? input[i + 2] : 0;\n\n      const outByte1 = byte1 >> 2;\n      const outByte2 = ((byte1 & 0x03) << 4) | (byte2 >> 4);\n      let outByte3 = ((byte2 & 0x0f) << 2) | (byte3 >> 6);\n      let outByte4 = byte3 & 0x3f;\n\n      if (!haveByte3) {\n        outByte4 = 64;\n\n        if (!haveByte2) {\n          outByte3 = 64;\n        }\n      }\n\n      output.push(\n        byteToCharMap[outByte1],\n        byteToCharMap[outByte2],\n        byteToCharMap[outByte3],\n        byteToCharMap[outByte4]\n      );\n    }\n\n    return output.join('');\n  },\n\n  /**\n   * Base64-encode a string.\n   *\n   * @param input A string to encode.\n   * @param webSafe If true, we should use the\n   *     alternative alphabet.\n   * @return The base64 encoded string.\n   */\n  encodeString(input: string, webSafe?: boolean): string {\n    // Shortcut for Mozilla browsers that implement\n    // a native base64 encoder in the form of \"btoa/atob\"\n    if (this.HAS_NATIVE_SUPPORT && !webSafe) {\n      return btoa(input);\n    }\n    return this.encodeByteArray(stringToByteArray(input), webSafe);\n  },\n\n  /**\n   * Base64-decode a string.\n   *\n   * @param input to decode.\n   * @param webSafe True if we should use the\n   *     alternative alphabet.\n   * @return string representing the decoded value.\n   */\n  decodeString(input: string, webSafe: boolean): string {\n    // Shortcut for Mozilla browsers that implement\n    // a native base64 encoder in the form of \"btoa/atob\"\n    if (this.HAS_NATIVE_SUPPORT && !webSafe) {\n      return atob(input);\n    }\n    return byteArrayToString(this.decodeStringToByteArray(input, webSafe));\n  },\n\n  /**\n   * Base64-decode a string.\n   *\n   * In base-64 decoding, groups of four characters are converted into three\n   * bytes.  If the encoder did not apply padding, the input length may not\n   * be a multiple of 4.\n   *\n   * In this case, the last group will have fewer than 4 characters, and\n   * padding will be inferred.  If the group has one or two characters, it decodes\n   * to one byte.  If the group has three characters, it decodes to two bytes.\n   *\n   * @param input Input to decode.\n   * @param webSafe True if we should use the web-safe alphabet.\n   * @return bytes representing the decoded value.\n   */\n  decodeStringToByteArray(input: string, webSafe: boolean): number[] {\n    this.init_();\n\n    const charToByteMap = webSafe\n      ? this.charToByteMapWebSafe_!\n      : this.charToByteMap_!;\n\n    const output: number[] = [];\n\n    for (let i = 0; i < input.length; ) {\n      const byte1 = charToByteMap[input.charAt(i++)];\n\n      const haveByte2 = i < input.length;\n      const byte2 = haveByte2 ? charToByteMap[input.charAt(i)] : 0;\n      ++i;\n\n      const haveByte3 = i < input.length;\n      const byte3 = haveByte3 ? charToByteMap[input.charAt(i)] : 64;\n      ++i;\n\n      const haveByte4 = i < input.length;\n      const byte4 = haveByte4 ? charToByteMap[input.charAt(i)] : 64;\n      ++i;\n\n      if (byte1 == null || byte2 == null || byte3 == null || byte4 == null) {\n        throw new DecodeBase64StringError();\n      }\n\n      const outByte1 = (byte1 << 2) | (byte2 >> 4);\n      output.push(outByte1);\n\n      if (byte3 !== 64) {\n        const outByte2 = ((byte2 << 4) & 0xf0) | (byte3 >> 2);\n        output.push(outByte2);\n\n        if (byte4 !== 64) {\n          const outByte3 = ((byte3 << 6) & 0xc0) | byte4;\n          output.push(outByte3);\n        }\n      }\n    }\n\n    return output;\n  },\n\n  /**\n   * Lazy static initialization function. Called before\n   * accessing any of the static map variables.\n   * @private\n   */\n  init_() {\n    if (!this.byteToCharMap_) {\n      this.byteToCharMap_ = {};\n      this.charToByteMap_ = {};\n      this.byteToCharMapWebSafe_ = {};\n      this.charToByteMapWebSafe_ = {};\n\n      // We want quick mappings back and forth, so we precompute two maps.\n      for (let i = 0; i < this.ENCODED_VALS.length; i++) {\n        this.byteToCharMap_[i] = this.ENCODED_VALS.charAt(i);\n        this.charToByteMap_[this.byteToCharMap_[i]] = i;\n        this.byteToCharMapWebSafe_[i] = this.ENCODED_VALS_WEBSAFE.charAt(i);\n        this.charToByteMapWebSafe_[this.byteToCharMapWebSafe_[i]] = i;\n\n        // Be forgiving when decoding and correctly decode both encodings.\n        if (i >= this.ENCODED_VALS_BASE.length) {\n          this.charToByteMap_[this.ENCODED_VALS_WEBSAFE.charAt(i)] = i;\n          this.charToByteMapWebSafe_[this.ENCODED_VALS.charAt(i)] = i;\n        }\n      }\n    }\n  }\n};\n\n/**\n * An error encountered while decoding base64 string.\n */\nexport class DecodeBase64StringError extends Error {\n  readonly name = 'DecodeBase64StringError';\n}\n\n/**\n * URL-safe base64 encoding\n */\nexport const base64Encode = function (str: string): string {\n  const utf8Bytes = stringToByteArray(str);\n  return base64.encodeByteArray(utf8Bytes, true);\n};\n\n/**\n * URL-safe base64 encoding (without \".\" padding in the end).\n * e.g. Used in JSON Web Token (JWT) parts.\n */\nexport const base64urlEncodeWithoutPadding = function (str: string): string {\n  // Use base64url encoding and remove padding in the end (dot characters).\n  return base64Encode(str).replace(/\\./g, '');\n};\n\n/**\n * URL-safe base64 decoding\n *\n * NOTE: DO NOT use the global atob() function - it does NOT support the\n * base64Url variant encoding.\n *\n * @param str To be decoded\n * @return Decoded result, if possible\n */\nexport const base64Decode = function (str: string): string | null {\n  try {\n    return base64.decodeString(str, true);\n  } catch (e) {\n    console.error('base64Decode failed: ', e);\n  }\n  return null;\n};\n","/**\n * @license\n * Copyright 2022 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { base64Decode } from './crypt';\nimport { getGlobal } from './global';\nimport { getDefaultsFromPostinstall } from './postinstall';\n\n/**\n * Keys for experimental properties on the `FirebaseDefaults` object.\n * @public\n */\nexport type ExperimentalKey = 'authTokenSyncURL' | 'authIdTokenMaxAge';\n\n/**\n * An object that can be injected into the environment as __FIREBASE_DEFAULTS__,\n * either as a property of globalThis, a shell environment variable, or a\n * cookie.\n *\n * This object can be used to automatically configure and initialize\n * a Firebase app as well as any emulators.\n *\n * @public\n */\nexport interface FirebaseDefaults {\n  config?: Record<string, string>;\n  emulatorHosts?: Record<string, string>;\n  _authTokenSyncURL?: string;\n  _authIdTokenMaxAge?: number;\n  /**\n   * Override Firebase's runtime environment detection and\n   * force the SDK to act as if it were in the specified environment.\n   */\n  forceEnvironment?: 'browser' | 'node';\n  [key: string]: unknown;\n}\n\ndeclare global {\n  // Need `var` for this to work.\n  // eslint-disable-next-line no-var\n  var __FIREBASE_DEFAULTS__: FirebaseDefaults | undefined;\n}\n\nconst getDefaultsFromGlobal = (): FirebaseDefaults | undefined =>\n  getGlobal().__FIREBASE_DEFAULTS__;\n\n/**\n * Attempt to read defaults from a JSON string provided to\n * process(.)env(.)__FIREBASE_DEFAULTS__ or a JSON file whose path is in\n * process(.)env(.)__FIREBASE_DEFAULTS_PATH__\n * The dots are in parens because certain compilers (Vite?) cannot\n * handle seeing that variable in comments.\n * See https://github.com/firebase/firebase-js-sdk/issues/6838\n */\nconst getDefaultsFromEnvVariable = (): FirebaseDefaults | undefined => {\n  if (typeof process === 'undefined' || typeof process.env === 'undefined') {\n    return;\n  }\n  const defaultsJsonString = process.env.__FIREBASE_DEFAULTS__;\n  if (defaultsJsonString) {\n    return JSON.parse(defaultsJsonString);\n  }\n};\n\nconst getDefaultsFromCookie = (): FirebaseDefaults | undefined => {\n  if (typeof document === 'undefined') {\n    return;\n  }\n  let match;\n  try {\n    match = document.cookie.match(/__FIREBASE_DEFAULTS__=([^;]+)/);\n  } catch (e) {\n    // Some environments such as Angular Universal SSR have a\n    // `document` object but error on accessing `document.cookie`.\n    return;\n  }\n  const decoded = match && base64Decode(match[1]);\n  return decoded && JSON.parse(decoded);\n};\n\n/**\n * Get the __FIREBASE_DEFAULTS__ object. It checks in order:\n * (1) if such an object exists as a property of `globalThis`\n * (2) if such an object was provided on a shell environment variable\n * (3) if such an object exists in a cookie\n * @public\n */\nexport const getDefaults = (): FirebaseDefaults | undefined => {\n  try {\n    return (\n      getDefaultsFromPostinstall() ||\n      getDefaultsFromGlobal() ||\n      getDefaultsFromEnvVariable() ||\n      getDefaultsFromCookie()\n    );\n  } catch (e) {\n    /**\n     * Catch-all for being unable to get __FIREBASE_DEFAULTS__ due\n     * to any environment case we have not accounted for. Log to\n     * info instead of swallowing so we can find these unknown cases\n     * and add paths for them if needed.\n     */\n    console.info(`Unable to get __FIREBASE_DEFAULTS__ due to: ${e}`);\n    return;\n  }\n};\n\n/**\n * Returns emulator host stored in the __FIREBASE_DEFAULTS__ object\n * for the given product.\n * @returns a URL host formatted like `127.0.0.1:9999` or `[::1]:4000` if available\n * @public\n */\nexport const getDefaultEmulatorHost = (\n  productName: string\n): string | undefined => getDefaults()?.emulatorHosts?.[productName];\n\n/**\n * Returns emulator hostname and port stored in the __FIREBASE_DEFAULTS__ object\n * for the given product.\n * @returns a pair of hostname and port like `[\"::1\", 4000]` if available\n * @public\n */\nexport const getDefaultEmulatorHostnameAndPort = (\n  productName: string\n): [hostname: string, port: number] | undefined => {\n  const host = getDefaultEmulatorHost(productName);\n  if (!host) {\n    return undefined;\n  }\n  const separatorIndex = host.lastIndexOf(':'); // Finding the last since IPv6 addr also has colons.\n  if (separatorIndex <= 0 || separatorIndex + 1 === host.length) {\n    throw new Error(`Invalid host ${host} with no separate hostname and port!`);\n  }\n  // eslint-disable-next-line no-restricted-globals\n  const port = parseInt(host.substring(separatorIndex + 1), 10);\n  if (host[0] === '[') {\n    // Bracket-quoted `[ipv6addr]:port` => return \"ipv6addr\" (without brackets).\n    return [host.substring(1, separatorIndex - 1), port];\n  } else {\n    return [host.substring(0, separatorIndex), port];\n  }\n};\n\n/**\n * Returns Firebase app config stored in the __FIREBASE_DEFAULTS__ object.\n * @public\n */\nexport const getDefaultAppConfig = (): Record<string, string> | undefined =>\n  getDefaults()?.config;\n\n/**\n * Returns an experimental setting on the __FIREBASE_DEFAULTS__ object (properties\n * prefixed by \"_\")\n * @public\n */\nexport const getExperimentalSetting = <T extends ExperimentalKey>(\n  name: T\n): FirebaseDefaults[`_${T}`] =>\n  getDefaults()?.[`_${name}`] as FirebaseDefaults[`_${T}`];\n","/**\n * @license\n * Copyright 2022 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/**\n * Polyfill for `globalThis` object.\n * @returns the `globalThis` object for the given environment.\n * @public\n */\nexport function getGlobal(): typeof globalThis {\n  if (typeof self !== 'undefined') {\n    return self;\n  }\n  if (typeof window !== 'undefined') {\n    return window;\n  }\n  if (typeof global !== 'undefined') {\n    return global;\n  }\n  throw new Error('Unable to locate global object.');\n}\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport type LogLevelString =\n  | 'debug'\n  | 'verbose'\n  | 'info'\n  | 'warn'\n  | 'error'\n  | 'silent';\n\nexport interface LogOptions {\n  level: LogLevelString;\n}\n\nexport type LogCallback = (callbackParams: LogCallbackParams) => void;\n\nexport interface LogCallbackParams {\n  level: LogLevelString;\n  message: string;\n  args: unknown[];\n  type: string;\n}\n\n/**\n * A container for all of the Logger instances\n */\nexport const instances: Logger[] = [];\n\n/**\n * The JS SDK supports 5 log levels and also allows a user the ability to\n * silence the logs altogether.\n *\n * The order is a follows:\n * DEBUG < VERBOSE < INFO < WARN < ERROR\n *\n * All of the log types above the current log level will be captured (i.e. if\n * you set the log level to `INFO`, errors will still be logged, but `DEBUG` and\n * `VERBOSE` logs will not)\n */\nexport enum LogLevel {\n  DEBUG,\n  VERBOSE,\n  INFO,\n  WARN,\n  ERROR,\n  SILENT\n}\n\nconst levelStringToEnum: { [key in LogLevelString]: LogLevel } = {\n  'debug': LogLevel.DEBUG,\n  'verbose': LogLevel.VERBOSE,\n  'info': LogLevel.INFO,\n  'warn': LogLevel.WARN,\n  'error': LogLevel.ERROR,\n  'silent': LogLevel.SILENT\n};\n\n/**\n * The default log level\n */\nconst defaultLogLevel: LogLevel = LogLevel.INFO;\n\n/**\n * We allow users the ability to pass their own log handler. We will pass the\n * type of log, the current log level, and any other arguments passed (i.e. the\n * messages that the user wants to log) to this function.\n */\nexport type LogHandler = (\n  loggerInstance: Logger,\n  logType: LogLevel,\n  ...args: unknown[]\n) => void;\n\n/**\n * By default, `console.debug` is not displayed in the developer console (in\n * chrome). To avoid forcing users to have to opt-in to these logs twice\n * (i.e. once for firebase, and once in the console), we are sending `DEBUG`\n * logs to the `console.log` function.\n */\nconst ConsoleMethod = {\n  [LogLevel.DEBUG]: 'log',\n  [LogLevel.VERBOSE]: 'log',\n  [LogLevel.INFO]: 'info',\n  [LogLevel.WARN]: 'warn',\n  [LogLevel.ERROR]: 'error'\n};\n\n/**\n * The default log handler will forward DEBUG, VERBOSE, INFO, WARN, and ERROR\n * messages on to their corresponding console counterparts (if the log method\n * is supported by the current log level)\n */\nconst defaultLogHandler: LogHandler = (instance, logType, ...args): void => {\n  if (logType < instance.logLevel) {\n    return;\n  }\n  const now = new Date().toISOString();\n  const method = ConsoleMethod[logType as keyof typeof ConsoleMethod];\n  if (method) {\n    console[method as 'log' | 'info' | 'warn' | 'error'](\n      `[${now}]  ${instance.name}:`,\n      ...args\n    );\n  } else {\n    throw new Error(\n      `Attempted to log a message with an invalid logType (value: ${logType})`\n    );\n  }\n};\n\nexport class Logger {\n  /**\n   * Gives you an instance of a Logger to capture messages according to\n   * Firebase's logging scheme.\n   *\n   * @param name The name that the logs will be associated with\n   */\n  constructor(public name: string) {\n    /**\n     * Capture the current instance for later use\n     */\n    instances.push(this);\n  }\n\n  /**\n   * The log level of the given Logger instance.\n   */\n  private _logLevel = defaultLogLevel;\n\n  get logLevel(): LogLevel {\n    return this._logLevel;\n  }\n\n  set logLevel(val: LogLevel) {\n    if (!(val in LogLevel)) {\n      throw new TypeError(`Invalid value \"${val}\" assigned to \\`logLevel\\``);\n    }\n    this._logLevel = val;\n  }\n\n  // Workaround for setter/getter having to be the same type.\n  setLogLevel(val: LogLevel | LogLevelString): void {\n    this._logLevel = typeof val === 'string' ? levelStringToEnum[val] : val;\n  }\n\n  /**\n   * The main (internal) log handler for the Logger instance.\n   * Can be set to a new function in internal package code but not by user.\n   */\n  private _logHandler: LogHandler = defaultLogHandler;\n  get logHandler(): LogHandler {\n    return this._logHandler;\n  }\n  set logHandler(val: LogHandler) {\n    if (typeof val !== 'function') {\n      throw new TypeError('Value assigned to `logHandler` must be a function');\n    }\n    this._logHandler = val;\n  }\n\n  /**\n   * The optional, additional, user-defined log handler for the Logger instance.\n   */\n  private _userLogHandler: LogHandler | null = null;\n  get userLogHandler(): LogHandler | null {\n    return this._userLogHandler;\n  }\n  set userLogHandler(val: LogHandler | null) {\n    this._userLogHandler = val;\n  }\n\n  /**\n   * The functions below are all based on the `console` interface\n   */\n\n  debug(...args: unknown[]): void {\n    this._userLogHandler && this._userLogHandler(this, LogLevel.DEBUG, ...args);\n    this._logHandler(this, LogLevel.DEBUG, ...args);\n  }\n  log(...args: unknown[]): void {\n    this._userLogHandler &&\n      this._userLogHandler(this, LogLevel.VERBOSE, ...args);\n    this._logHandler(this, LogLevel.VERBOSE, ...args);\n  }\n  info(...args: unknown[]): void {\n    this._userLogHandler && this._userLogHandler(this, LogLevel.INFO, ...args);\n    this._logHandler(this, LogLevel.INFO, ...args);\n  }\n  warn(...args: unknown[]): void {\n    this._userLogHandler && this._userLogHandler(this, LogLevel.WARN, ...args);\n    this._logHandler(this, LogLevel.WARN, ...args);\n  }\n  error(...args: unknown[]): void {\n    this._userLogHandler && this._userLogHandler(this, LogLevel.ERROR, ...args);\n    this._logHandler(this, LogLevel.ERROR, ...args);\n  }\n}\n\nexport function setLogLevel(level: LogLevelString | LogLevel): void {\n  instances.forEach(inst => {\n    inst.setLogLevel(level);\n  });\n}\n\nexport function setUserLogHandler(\n  logCallback: LogCallback | null,\n  options?: LogOptions\n): void {\n  for (const instance of instances) {\n    let customLogLevel: LogLevel | null = null;\n    if (options && options.level) {\n      customLogLevel = levelStringToEnum[options.level];\n    }\n    if (logCallback === null) {\n      instance.userLogHandler = null;\n    } else {\n      instance.userLogHandler = (\n        instance: Logger,\n        level: LogLevel,\n        ...args: unknown[]\n      ) => {\n        const message = args\n          .map(arg => {\n            if (arg == null) {\n              return null;\n            } else if (typeof arg === 'string') {\n              return arg;\n            } else if (typeof arg === 'number' || typeof arg === 'boolean') {\n              return arg.toString();\n            } else if (arg instanceof Error) {\n              return arg.message;\n            } else {\n              try {\n                return JSON.stringify(arg);\n              } catch (ignored) {\n                return null;\n              }\n            }\n          })\n          .filter(arg => arg)\n          .join(' ');\n        if (level >= (customLogLevel ?? instance.logLevel)) {\n          logCallback({\n            level: LogLevel[level].toLowerCase() as LogLevelString,\n            message,\n            args,\n            type: instance.name\n          });\n        }\n      };\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { CONSTANTS } from './constants';\nimport { getDefaults } from './defaults';\n\n/**\n * Type placeholder for `WorkerGlobalScope` from `webworker`\n */\ndeclare class WorkerGlobalScope {}\n\n/**\n * Returns navigator.userAgent string or '' if it's not defined.\n * @return user agent string\n */\nexport function getUA(): string {\n  if (\n    typeof navigator !== 'undefined' &&\n    typeof navigator['userAgent'] === 'string'\n  ) {\n    return navigator['userAgent'];\n  } else {\n    return '';\n  }\n}\n\n/**\n * Detect Cordova / PhoneGap / Ionic frameworks on a mobile device.\n *\n * Deliberately does not rely on checking `file://` URLs (as this fails PhoneGap\n * in the Ripple emulator) nor Cordova `onDeviceReady`, which would normally\n * wait for a callback.\n */\nexport function isMobileCordova(): boolean {\n  return (\n    typeof window !== 'undefined' &&\n    // @ts-ignore Setting up an broadly applicable index signature for Window\n    // just to deal with this case would probably be a bad idea.\n    !!(window['cordova'] || window['phonegap'] || window['PhoneGap']) &&\n    /ios|iphone|ipod|ipad|android|blackberry|iemobile/i.test(getUA())\n  );\n}\n\n/**\n * Detect Node.js.\n *\n * @return true if Node.js environment is detected or specified.\n */\n// Node detection logic from: https://github.com/iliakan/detect-node/\nexport function isNode(): boolean {\n  const forceEnvironment = getDefaults()?.forceEnvironment;\n  if (forceEnvironment === 'node') {\n    return true;\n  } else if (forceEnvironment === 'browser') {\n    return false;\n  }\n\n  try {\n    return (\n      Object.prototype.toString.call(global.process) === '[object process]'\n    );\n  } catch (e) {\n    return false;\n  }\n}\n\n/**\n * Detect Browser Environment.\n * Note: This will return true for certain test frameworks that are incompletely\n * mimicking a browser, and should not lead to assuming all browser APIs are\n * available.\n */\nexport function isBrowser(): boolean {\n  return typeof window !== 'undefined' || isWebWorker();\n}\n\n/**\n * Detect Web Worker context.\n */\nexport function isWebWorker(): boolean {\n  return (\n    typeof WorkerGlobalScope !== 'undefined' &&\n    typeof self !== 'undefined' &&\n    self instanceof WorkerGlobalScope\n  );\n}\n\n/**\n * Detect Cloudflare Worker context.\n */\nexport function isCloudflareWorker(): boolean {\n  return (\n    typeof navigator !== 'undefined' &&\n    navigator.userAgent === 'Cloudflare-Workers'\n  );\n}\n\n/**\n * Detect browser extensions (Chrome and Firefox at least).\n */\ninterface BrowserRuntime {\n  id?: unknown;\n}\ndeclare const chrome: { runtime?: BrowserRuntime };\ndeclare const browser: { runtime?: BrowserRuntime };\nexport function isBrowserExtension(): boolean {\n  const runtime =\n    typeof chrome === 'object'\n      ? chrome.runtime\n      : typeof browser === 'object'\n      ? browser.runtime\n      : undefined;\n  return typeof runtime === 'object' && runtime.id !== undefined;\n}\n\n/**\n * Detect React Native.\n *\n * @return true if ReactNative environment is detected.\n */\nexport function isReactNative(): boolean {\n  return (\n    typeof navigator === 'object' && navigator['product'] === 'ReactNative'\n  );\n}\n\n/** Detects Electron apps. */\nexport function isElectron(): boolean {\n  return getUA().indexOf('Electron/') >= 0;\n}\n\n/** Detects Internet Explorer. */\nexport function isIE(): boolean {\n  const ua = getUA();\n  return ua.indexOf('MSIE ') >= 0 || ua.indexOf('Trident/') >= 0;\n}\n\n/** Detects Universal Windows Platform apps. */\nexport function isUWP(): boolean {\n  return getUA().indexOf('MSAppHost/') >= 0;\n}\n\n/**\n * Detect whether the current SDK build is the Node version.\n *\n * @return true if it's the Node SDK build.\n */\nexport function isNodeSdk(): boolean {\n  return CONSTANTS.NODE_CLIENT === true || CONSTANTS.NODE_ADMIN === true;\n}\n\n/** Returns true if we are running in Safari. */\nexport function isSafari(): boolean {\n  return (\n    !isNode() &&\n    !!navigator.userAgent &&\n    navigator.userAgent.includes('Safari') &&\n    !navigator.userAgent.includes('Chrome')\n  );\n}\n\n/** Returns true if we are running in Safari or WebKit */\nexport function isSafariOrWebkit(): boolean {\n  return (\n    !isNode() &&\n    !!navigator.userAgent &&\n    (navigator.userAgent.includes('Safari') ||\n      navigator.userAgent.includes('WebKit')) &&\n    !navigator.userAgent.includes('Chrome')\n  );\n}\n\n/**\n * This method checks if indexedDB is supported by current browser/service worker context\n * @return true if indexedDB is supported by current browser/service worker context\n */\nexport function isIndexedDBAvailable(): boolean {\n  try {\n    return typeof indexedDB === 'object';\n  } catch (e) {\n    return false;\n  }\n}\n\n/**\n * This method validates browser/sw context for indexedDB by opening a dummy indexedDB database and reject\n * if errors occur during the database open operation.\n *\n * @throws exception if current browser/sw context can't run idb.open (ex: Safari iframe, Firefox\n * private browsing)\n */\nexport function validateIndexedDBOpenable(): Promise<boolean> {\n  return new Promise((resolve, reject) => {\n    try {\n      let preExist: boolean = true;\n      const DB_CHECK_NAME =\n        'validate-browser-context-for-indexeddb-analytics-module';\n      const request = self.indexedDB.open(DB_CHECK_NAME);\n      request.onsuccess = () => {\n        request.result.close();\n        // delete database only when it doesn't pre-exist\n        if (!preExist) {\n          self.indexedDB.deleteDatabase(DB_CHECK_NAME);\n        }\n        resolve(true);\n      };\n      request.onupgradeneeded = () => {\n        preExist = false;\n      };\n\n      request.onerror = () => {\n        reject(request.error?.message || '');\n      };\n    } catch (error) {\n      reject(error);\n    }\n  });\n}\n\n/**\n *\n * This method checks whether cookie is enabled within current browser\n * @return true if cookie is enabled within current browser\n */\nexport function areCookiesEnabled(): boolean {\n  if (typeof navigator === 'undefined' || !navigator.cookieEnabled) {\n    return false;\n  }\n  return true;\n}\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n/**\n * @fileoverview Standardized Firebase Error.\n *\n * Usage:\n *\n *   // TypeScript string literals for type-safe codes\n *   type Err =\n *     'unknown' |\n *     'object-not-found'\n *     ;\n *\n *   // Closure enum for type-safe error codes\n *   // at-enum {string}\n *   var Err = {\n *     UNKNOWN: 'unknown',\n *     OBJECT_NOT_FOUND: 'object-not-found',\n *   }\n *\n *   let errors: Map<Err, string> = {\n *     'generic-error': \"Unknown error\",\n *     'file-not-found': \"Could not find file: {$file}\",\n *   };\n *\n *   // Type-safe function - must pass a valid error code as param.\n *   let error = new ErrorFactory<Err>('service', 'Service', errors);\n *\n *   ...\n *   throw error.create(Err.GENERIC);\n *   ...\n *   throw error.create(Err.FILE_NOT_FOUND, {'file': fileName});\n *   ...\n *   // Service: Could not file file: foo.txt (service/file-not-found).\n *\n *   catch (e) {\n *     assert(e.message === \"Could not find file: foo.txt.\");\n *     if ((e as FirebaseError)?.code === 'service/file-not-found') {\n *       console.log(\"Could not read file: \" + e['file']);\n *     }\n *   }\n */\n\nexport type ErrorMap<ErrorCode extends string> = {\n  readonly [K in ErrorCode]: string;\n};\n\nconst ERROR_NAME = 'FirebaseError';\n\nexport interface StringLike {\n  toString(): string;\n}\n\nexport interface ErrorData {\n  [key: string]: unknown;\n}\n\n// Based on code from:\n// https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Error#Custom_Error_Types\nexport class FirebaseError extends Error {\n  /** The custom name for all FirebaseErrors. */\n  readonly name: string = ERROR_NAME;\n\n  constructor(\n    /** The error code for this error. */\n    readonly code: string,\n    message: string,\n    /** Custom data for this error. */\n    public customData?: Record<string, unknown>\n  ) {\n    super(message);\n\n    // Fix For ES5\n    // https://github.com/Microsoft/TypeScript-wiki/blob/master/Breaking-Changes.md#extending-built-ins-like-error-array-and-map-may-no-longer-work\n    // TODO(dlarocque): Replace this with `new.target`: https://www.typescriptlang.org/docs/handbook/release-notes/typescript-2-2.html#support-for-newtarget\n    //                   which we can now use since we no longer target ES5.\n    Object.setPrototypeOf(this, FirebaseError.prototype);\n\n    // Maintains proper stack trace for where our error was thrown.\n    // Only available on V8.\n    if (Error.captureStackTrace) {\n      Error.captureStackTrace(this, ErrorFactory.prototype.create);\n    }\n  }\n}\n\nexport class ErrorFactory<\n  ErrorCode extends string,\n  ErrorParams extends { readonly [K in ErrorCode]?: ErrorData } = {}\n> {\n  constructor(\n    private readonly service: string,\n    private readonly serviceName: string,\n    private readonly errors: ErrorMap<ErrorCode>\n  ) {}\n\n  create<K extends ErrorCode>(\n    code: K,\n    ...data: K extends keyof ErrorParams ? [ErrorParams[K]] : []\n  ): FirebaseError {\n    const customData = (data[0] as ErrorData) || {};\n    const fullCode = `${this.service}/${code}`;\n    const template = this.errors[code];\n\n    const message = template ? replaceTemplate(template, customData) : 'Error';\n    // Service Name: Error message (service/code).\n    const fullMessage = `${this.serviceName}: ${message} (${fullCode}).`;\n\n    const error = new FirebaseError(fullCode, fullMessage, customData);\n\n    return error;\n  }\n}\n\nfunction replaceTemplate(template: string, data: ErrorData): string {\n  return template.replace(PATTERN, (_, key) => {\n    const value = data[key];\n    return value != null ? String(value) : `<${key}?>`;\n  });\n}\n\nconst PATTERN = /\\{\\$([^}]+)}/g;\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport function contains<T extends object>(obj: T, key: string): boolean {\n  return Object.prototype.hasOwnProperty.call(obj, key);\n}\n\nexport function safeGet<T extends object, K extends keyof T>(\n  obj: T,\n  key: K\n): T[K] | undefined {\n  if (Object.prototype.hasOwnProperty.call(obj, key)) {\n    return obj[key];\n  } else {\n    return undefined;\n  }\n}\n\nexport function isEmpty(obj: object): obj is {} {\n  for (const key in obj) {\n    if (Object.prototype.hasOwnProperty.call(obj, key)) {\n      return false;\n    }\n  }\n  return true;\n}\n\nexport function map<K extends string, V, U>(\n  obj: { [key in K]: V },\n  fn: (value: V, key: K, obj: { [key in K]: V }) => U,\n  contextObj?: unknown\n): { [key in K]: U } {\n  const res: Partial<{ [key in K]: U }> = {};\n  for (const key in obj) {\n    if (Object.prototype.hasOwnProperty.call(obj, key)) {\n      res[key] = fn.call(contextObj, obj[key], key, obj);\n    }\n  }\n  return res as { [key in K]: U };\n}\n\n/**\n * Deep equal two objects. Support Arrays and Objects.\n */\nexport function deepEqual(a: object, b: object): boolean {\n  if (a === b) {\n    return true;\n  }\n\n  const aKeys = Object.keys(a);\n  const bKeys = Object.keys(b);\n  for (const k of aKeys) {\n    if (!bKeys.includes(k)) {\n      return false;\n    }\n\n    const aProp = (a as Record<string, unknown>)[k];\n    const bProp = (b as Record<string, unknown>)[k];\n    if (isObject(aProp) && isObject(bProp)) {\n      if (!deepEqual(aProp, bProp)) {\n        return false;\n      }\n    } else if (aProp !== bProp) {\n      return false;\n    }\n  }\n\n  for (const k of bKeys) {\n    if (!aKeys.includes(k)) {\n      return false;\n    }\n  }\n  return true;\n}\n\nfunction isObject(thing: unknown): thing is object {\n  return thing !== null && typeof thing === 'object';\n}\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/**\n * Returns a querystring-formatted string (e.g. &arg=val&arg2=val2) from a\n * params object (e.g. {arg: 'val', arg2: 'val2'})\n * Note: You must prepend it with ? when adding it to a URL.\n */\nexport function querystring(querystringParams: {\n  [key: string]: string | number;\n}): string {\n  const params = [];\n  for (const [key, value] of Object.entries(querystringParams)) {\n    if (Array.isArray(value)) {\n      value.forEach(arrayVal => {\n        params.push(\n          encodeURIComponent(key) + '=' + encodeURIComponent(arrayVal)\n        );\n      });\n    } else {\n      params.push(encodeURIComponent(key) + '=' + encodeURIComponent(value));\n    }\n  }\n  return params.length ? '&' + params.join('&') : '';\n}\n\n/**\n * Decodes a querystring (e.g. ?arg=val&arg2=val2) into a params object\n * (e.g. {arg: 'val', arg2: 'val2'})\n */\nexport function querystringDecode(querystring: string): Record<string, string> {\n  const obj: Record<string, string> = {};\n  const tokens = querystring.replace(/^\\?/, '').split('&');\n\n  tokens.forEach(token => {\n    if (token) {\n      const [key, value] = token.split('=');\n      obj[decodeURIComponent(key)] = decodeURIComponent(value);\n    }\n  });\n  return obj;\n}\n\n/**\n * Extract the query string part of a URL, including the leading question mark (if present).\n */\nexport function extractQuerystring(url: string): string {\n  const queryStart = url.indexOf('?');\n  if (!queryStart) {\n    return '';\n  }\n  const fragmentStart = url.indexOf('#', queryStart);\n  return url.substring(\n    queryStart,\n    fragmentStart > 0 ? fragmentStart : undefined\n  );\n}\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\nexport type NextFn<T> = (value: T) => void;\nexport type ErrorFn = (error: Error) => void;\nexport type CompleteFn = () => void;\n\nexport interface Observer<T> {\n  // Called once for each value in a stream of values.\n  next: NextFn<T>;\n\n  // A stream terminates by a single call to EITHER error() or complete().\n  error: ErrorFn;\n\n  // No events will be sent to next() once complete() is called.\n  complete: CompleteFn;\n}\n\nexport type PartialObserver<T> = Partial<Observer<T>>;\n\n// TODO: Support also Unsubscribe.unsubscribe?\nexport type Unsubscribe = () => void;\n\n/**\n * The Subscribe interface has two forms - passing the inline function\n * callbacks, or a object interface with callback properties.\n */\nexport interface Subscribe<T> {\n  (next?: NextFn<T>, error?: ErrorFn, complete?: CompleteFn): Unsubscribe;\n  (observer: PartialObserver<T>): Unsubscribe;\n}\n\nexport interface Observable<T> {\n  // Subscribe method\n  subscribe: Subscribe<T>;\n}\n\nexport type Executor<T> = (observer: Observer<T>) => void;\n\n/**\n * Helper to make a Subscribe function (just like Promise helps make a\n * Thenable).\n *\n * @param executor Function which can make calls to a single Observer\n *     as a proxy.\n * @param onNoObservers Callback when count of Observers goes to zero.\n */\nexport function createSubscribe<T>(\n  executor: Executor<T>,\n  onNoObservers?: Executor<T>\n): Subscribe<T> {\n  const proxy = new ObserverProxy<T>(executor, onNoObservers);\n  return proxy.subscribe.bind(proxy);\n}\n\n/**\n * Implement fan-out for any number of Observers attached via a subscribe\n * function.\n */\nclass ObserverProxy<T> implements Observer<T> {\n  private observers: Array<Observer<T>> | undefined = [];\n  private unsubscribes: Unsubscribe[] = [];\n  private onNoObservers: Executor<T> | undefined;\n  private observerCount = 0;\n  // Micro-task scheduling by calling task.then().\n  private task = Promise.resolve();\n  private finalized = false;\n  private finalError?: Error;\n\n  /**\n   * @param executor Function which can make calls to a single Observer\n   *     as a proxy.\n   * @param onNoObservers Callback when count of Observers goes to zero.\n   */\n  constructor(executor: Executor<T>, onNoObservers?: Executor<T>) {\n    this.onNoObservers = onNoObservers;\n    // Call the executor asynchronously so subscribers that are called\n    // synchronously after the creation of the subscribe function\n    // can still receive the very first value generated in the executor.\n    this.task\n      .then(() => {\n        executor(this);\n      })\n      .catch(e => {\n        this.error(e);\n      });\n  }\n\n  next(value: T): void {\n    this.forEachObserver((observer: Observer<T>) => {\n      observer.next(value);\n    });\n  }\n\n  error(error: Error): void {\n    this.forEachObserver((observer: Observer<T>) => {\n      observer.error(error);\n    });\n    this.close(error);\n  }\n\n  complete(): void {\n    this.forEachObserver((observer: Observer<T>) => {\n      observer.complete();\n    });\n    this.close();\n  }\n\n  /**\n   * Subscribe function that can be used to add an Observer to the fan-out list.\n   *\n   * - We require that no event is sent to a subscriber synchronously to their\n   *   call to subscribe().\n   */\n  subscribe(\n    nextOrObserver?: NextFn<T> | PartialObserver<T>,\n    error?: ErrorFn,\n    complete?: CompleteFn\n  ): Unsubscribe {\n    let observer: Observer<T>;\n\n    if (\n      nextOrObserver === undefined &&\n      error === undefined &&\n      complete === undefined\n    ) {\n      throw new Error('Missing Observer.');\n    }\n\n    // Assemble an Observer object when passed as callback functions.\n    if (\n      implementsAnyMethods(nextOrObserver as { [key: string]: unknown }, [\n        'next',\n        'error',\n        'complete'\n      ])\n    ) {\n      observer = nextOrObserver as Observer<T>;\n    } else {\n      observer = {\n        next: nextOrObserver as NextFn<T>,\n        error,\n        complete\n      } as Observer<T>;\n    }\n\n    if (observer.next === undefined) {\n      observer.next = noop as NextFn<T>;\n    }\n    if (observer.error === undefined) {\n      observer.error = noop as ErrorFn;\n    }\n    if (observer.complete === undefined) {\n      observer.complete = noop as CompleteFn;\n    }\n\n    const unsub = this.unsubscribeOne.bind(this, this.observers!.length);\n\n    // Attempt to subscribe to a terminated Observable - we\n    // just respond to the Observer with the final error or complete\n    // event.\n    if (this.finalized) {\n      // eslint-disable-next-line @typescript-eslint/no-floating-promises\n      this.task.then(() => {\n        try {\n          if (this.finalError) {\n            observer.error(this.finalError);\n          } else {\n            observer.complete();\n          }\n        } catch (e) {\n          // nothing\n        }\n        return;\n      });\n    }\n\n    this.observers!.push(observer as Observer<T>);\n\n    return unsub;\n  }\n\n  // Unsubscribe is synchronous - we guarantee that no events are sent to\n  // any unsubscribed Observer.\n  private unsubscribeOne(i: number): void {\n    if (this.observers === undefined || this.observers[i] === undefined) {\n      return;\n    }\n\n    delete this.observers[i];\n\n    this.observerCount -= 1;\n    if (this.observerCount === 0 && this.onNoObservers !== undefined) {\n      this.onNoObservers(this);\n    }\n  }\n\n  private forEachObserver(fn: (observer: Observer<T>) => void): void {\n    if (this.finalized) {\n      // Already closed by previous event....just eat the additional values.\n      return;\n    }\n\n    // Since sendOne calls asynchronously - there is no chance that\n    // this.observers will become undefined.\n    for (let i = 0; i < this.observers!.length; i++) {\n      this.sendOne(i, fn);\n    }\n  }\n\n  // Call the Observer via one of it's callback function. We are careful to\n  // confirm that the observe has not been unsubscribed since this asynchronous\n  // function had been queued.\n  private sendOne(i: number, fn: (observer: Observer<T>) => void): void {\n    // Execute the callback asynchronously\n    // eslint-disable-next-line @typescript-eslint/no-floating-promises\n    this.task.then(() => {\n      if (this.observers !== undefined && this.observers[i] !== undefined) {\n        try {\n          fn(this.observers[i]);\n        } catch (e) {\n          // Ignore exceptions raised in Observers or missing methods of an\n          // Observer.\n          // Log error to console. b/31404806\n          if (typeof console !== 'undefined' && console.error) {\n            console.error(e);\n          }\n        }\n      }\n    });\n  }\n\n  private close(err?: Error): void {\n    if (this.finalized) {\n      return;\n    }\n    this.finalized = true;\n    if (err !== undefined) {\n      this.finalError = err;\n    }\n    // Proxy is no longer needed - garbage collect references\n    // eslint-disable-next-line @typescript-eslint/no-floating-promises\n    this.task.then(() => {\n      this.observers = undefined;\n      this.onNoObservers = undefined;\n    });\n  }\n}\n\n/** Turn synchronous function into one called asynchronously. */\n// eslint-disable-next-line @typescript-eslint/ban-types\nexport function async(fn: Function, onError?: ErrorFn): Function {\n  return (...args: unknown[]) => {\n    Promise.resolve(true)\n      .then(() => {\n        fn(...args);\n      })\n      .catch((error: Error) => {\n        if (onError) {\n          onError(error);\n        }\n      });\n  };\n}\n\n/**\n * Return true if the object passed in implements any of the named methods.\n */\nfunction implementsAnyMethods(\n  obj: { [key: string]: unknown },\n  methods: string[]\n): boolean {\n  if (typeof obj !== 'object' || obj === null) {\n    return false;\n  }\n\n  for (const method of methods) {\n    if (method in obj && typeof obj[method] === 'function') {\n      return true;\n    }\n  }\n\n  return false;\n}\n\nfunction noop(): void {\n  // do nothing\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport interface Compat<T> {\n  _delegate: T;\n}\n\nexport function getModularInstance<ExpService>(\n  service: Compat<ExpService> | ExpService\n): ExpService {\n  if (service && (service as Compat<ExpService>)._delegate) {\n    return (service as Compat<ExpService>)._delegate;\n  } else {\n    return service as ExpService;\n  }\n}\n","/**\n * @license\n * Copyright 2025 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/**\n * Checks whether host is a cloud workstation or not.\n * @public\n */\nexport function isCloudWorkstation(url: string): boolean {\n  // `isCloudWorkstation` is called without protocol in certain connect*Emulator functions\n  // In HTTP request builders, it's called with the protocol.\n  // If called with protocol prefix, it's a valid URL, so we extract the hostname\n  // If called without, we assume the string is the hostname.\n  try {\n    const host =\n      url.startsWith('http://') || url.startsWith('https://')\n        ? new URL(url).hostname\n        : url;\n    return host.endsWith('.cloudworkstations.dev');\n  } catch {\n    return false;\n  }\n}\n\n/**\n * Makes a fetch request to the given server.\n * Mostly used for forwarding cookies in Firebase Studio.\n * @public\n */\nexport async function pingServer(endpoint: string): Promise<boolean> {\n  const result = await fetch(endpoint, {\n    credentials: 'include'\n  });\n  return result.ok;\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\nimport {\n  InstantiationMode,\n  InstanceFactory,\n  ComponentType,\n  Dictionary,\n  Name,\n  onInstanceCreatedCallback\n} from './types';\n\n/**\n * Component for service name T, e.g. `auth`, `auth-internal`\n */\nexport class Component<T extends Name = Name> {\n  multipleInstances = false;\n  /**\n   * Properties to be added to the service namespace\n   */\n  serviceProps: Dictionary = {};\n\n  instantiationMode = InstantiationMode.LAZY;\n\n  onInstanceCreated: onInstanceCreatedCallback<T> | null = null;\n\n  /**\n   *\n   * @param name The public service name, e.g. app, auth, firestore, database\n   * @param instanceFactory Service factory responsible for creating the public interface\n   * @param type whether the service provided by the component is public or private\n   */\n  constructor(\n    readonly name: T,\n    readonly instanceFactory: InstanceFactory<T>,\n    readonly type: ComponentType\n  ) {}\n\n  setInstantiationMode(mode: InstantiationMode): this {\n    this.instantiationMode = mode;\n    return this;\n  }\n\n  setMultipleInstances(multipleInstances: boolean): this {\n    this.multipleInstances = multipleInstances;\n    return this;\n  }\n\n  setServiceProps(props: Dictionary): this {\n    this.serviceProps = props;\n    return this;\n  }\n\n  setInstanceCreatedCallback(callback: onInstanceCreatedCallback<T>): this {\n    this.onInstanceCreated = callback;\n    return this;\n  }\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/**\n * An enum of factors that may be used for multifactor authentication.\n *\n * @public\n */\nexport const FactorId = {\n  /** Phone as second factor */\n  PHONE: 'phone',\n  TOTP: 'totp'\n} as const;\n\n/**\n * Enumeration of supported providers.\n *\n * @public\n */\nexport const ProviderId = {\n  /** Facebook provider ID */\n  FACEBOOK: 'facebook.com',\n  /** GitHub provider ID */\n  GITHUB: 'github.com',\n  /** Google provider ID */\n  GOOGLE: 'google.com',\n  /** Password provider */\n  PASSWORD: 'password',\n  /** Phone provider */\n  PHONE: 'phone',\n  /** Twitter provider ID */\n  TWITTER: 'twitter.com'\n} as const;\n\n/**\n * Enumeration of supported sign-in methods.\n *\n * @public\n */\nexport const SignInMethod = {\n  /** Email link sign in method */\n  EMAIL_LINK: 'emailLink',\n  /** Email/password sign in method */\n  EMAIL_PASSWORD: 'password',\n  /** Facebook sign in method */\n  FACEBOOK: 'facebook.com',\n  /** GitHub sign in method */\n  GITHUB: 'github.com',\n  /** Google sign in method */\n  GOOGLE: 'google.com',\n  /** Phone sign in method */\n  PHONE: 'phone',\n  /** Twitter sign in method */\n  TWITTER: 'twitter.com'\n} as const;\n\n/**\n * Enumeration of supported operation types.\n *\n * @public\n */\nexport const OperationType = {\n  /** Operation involving linking an additional provider to an already signed-in user. */\n  LINK: 'link',\n  /** Operation involving using a provider to reauthenticate an already signed-in user. */\n  REAUTHENTICATE: 'reauthenticate',\n  /** Operation involving signing in a user. */\n  SIGN_IN: 'signIn'\n} as const;\n\n/**\n * An enumeration of the possible email action types.\n *\n * @public\n */\nexport const ActionCodeOperation = {\n  /** The email link sign-in action. */\n  EMAIL_SIGNIN: 'EMAIL_SIGNIN',\n  /** The password reset action. */\n  PASSWORD_RESET: 'PASSWORD_RESET',\n  /** The email revocation action. */\n  RECOVER_EMAIL: 'RECOVER_EMAIL',\n  /** The revert second factor addition email action. */\n  REVERT_SECOND_FACTOR_ADDITION: 'REVERT_SECOND_FACTOR_ADDITION',\n  /** The revert second factor addition email action. */\n  VERIFY_AND_CHANGE_EMAIL: 'VERIFY_AND_CHANGE_EMAIL',\n  /** The email verification action. */\n  VERIFY_EMAIL: 'VERIFY_EMAIL'\n} as const;\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthErrorMap, User } from '../model/public_types';\nimport { ErrorFactory, ErrorMap } from '@firebase/util';\n\nimport { IdTokenMfaResponse } from '../api/authentication/mfa';\nimport { AppName } from '../model/auth';\nimport { AuthCredential } from './credentials';\n\n/**\n * Enumeration of Firebase Auth error codes.\n *\n * @internal\n */\nexport const enum AuthErrorCode {\n  ADMIN_ONLY_OPERATION = 'admin-restricted-operation',\n  ARGUMENT_ERROR = 'argument-error',\n  APP_NOT_AUTHORIZED = 'app-not-authorized',\n  APP_NOT_INSTALLED = 'app-not-installed',\n  CAPTCHA_CHECK_FAILED = 'captcha-check-failed',\n  CODE_EXPIRED = 'code-expired',\n  CORDOVA_NOT_READY = 'cordova-not-ready',\n  CORS_UNSUPPORTED = 'cors-unsupported',\n  CREDENTIAL_ALREADY_IN_USE = 'credential-already-in-use',\n  CREDENTIAL_MISMATCH = 'custom-token-mismatch',\n  CREDENTIAL_TOO_OLD_LOGIN_AGAIN = 'requires-recent-login',\n  DEPENDENT_SDK_INIT_BEFORE_AUTH = 'dependent-sdk-initialized-before-auth',\n  DYNAMIC_LINK_NOT_ACTIVATED = 'dynamic-link-not-activated',\n  EMAIL_CHANGE_NEEDS_VERIFICATION = 'email-change-needs-verification',\n  EMAIL_EXISTS = 'email-already-in-use',\n  EMULATOR_CONFIG_FAILED = 'emulator-config-failed',\n  EXPIRED_OOB_CODE = 'expired-action-code',\n  EXPIRED_POPUP_REQUEST = 'cancelled-popup-request',\n  INTERNAL_ERROR = 'internal-error',\n  INVALID_API_KEY = 'invalid-api-key',\n  INVALID_APP_CREDENTIAL = 'invalid-app-credential',\n  INVALID_APP_ID = 'invalid-app-id',\n  INVALID_AUTH = 'invalid-user-token',\n  INVALID_AUTH_EVENT = 'invalid-auth-event',\n  INVALID_CERT_HASH = 'invalid-cert-hash',\n  INVALID_CODE = 'invalid-verification-code',\n  INVALID_CONTINUE_URI = 'invalid-continue-uri',\n  INVALID_CORDOVA_CONFIGURATION = 'invalid-cordova-configuration',\n  INVALID_CUSTOM_TOKEN = 'invalid-custom-token',\n  INVALID_DYNAMIC_LINK_DOMAIN = 'invalid-dynamic-link-domain',\n  INVALID_EMAIL = 'invalid-email',\n  INVALID_EMULATOR_SCHEME = 'invalid-emulator-scheme',\n  INVALID_CREDENTIAL = 'invalid-credential',\n  INVALID_MESSAGE_PAYLOAD = 'invalid-message-payload',\n  INVALID_MFA_SESSION = 'invalid-multi-factor-session',\n  INVALID_OAUTH_CLIENT_ID = 'invalid-oauth-client-id',\n  INVALID_OAUTH_PROVIDER = 'invalid-oauth-provider',\n  INVALID_OOB_CODE = 'invalid-action-code',\n  INVALID_ORIGIN = 'unauthorized-domain',\n  INVALID_PASSWORD = 'wrong-password',\n  INVALID_PERSISTENCE = 'invalid-persistence-type',\n  INVALID_PHONE_NUMBER = 'invalid-phone-number',\n  INVALID_PROVIDER_ID = 'invalid-provider-id',\n  INVALID_RECIPIENT_EMAIL = 'invalid-recipient-email',\n  INVALID_SENDER = 'invalid-sender',\n  INVALID_SESSION_INFO = 'invalid-verification-id',\n  INVALID_TENANT_ID = 'invalid-tenant-id',\n  LOGIN_BLOCKED = 'login-blocked',\n  MFA_INFO_NOT_FOUND = 'multi-factor-info-not-found',\n  MFA_REQUIRED = 'multi-factor-auth-required',\n  MISSING_ANDROID_PACKAGE_NAME = 'missing-android-pkg-name',\n  MISSING_APP_CREDENTIAL = 'missing-app-credential',\n  MISSING_AUTH_DOMAIN = 'auth-domain-config-required',\n  MISSING_CODE = 'missing-verification-code',\n  MISSING_CONTINUE_URI = 'missing-continue-uri',\n  MISSING_IFRAME_START = 'missing-iframe-start',\n  MISSING_IOS_BUNDLE_ID = 'missing-ios-bundle-id',\n  MISSING_OR_INVALID_NONCE = 'missing-or-invalid-nonce',\n  MISSING_MFA_INFO = 'missing-multi-factor-info',\n  MISSING_MFA_SESSION = 'missing-multi-factor-session',\n  MISSING_PHONE_NUMBER = 'missing-phone-number',\n  MISSING_PASSWORD = 'missing-password',\n  MISSING_SESSION_INFO = 'missing-verification-id',\n  MODULE_DESTROYED = 'app-deleted',\n  NEED_CONFIRMATION = 'account-exists-with-different-credential',\n  NETWORK_REQUEST_FAILED = 'network-request-failed',\n  NULL_USER = 'null-user',\n  NO_AUTH_EVENT = 'no-auth-event',\n  NO_SUCH_PROVIDER = 'no-such-provider',\n  OPERATION_NOT_ALLOWED = 'operation-not-allowed',\n  OPERATION_NOT_SUPPORTED = 'operation-not-supported-in-this-environment',\n  POPUP_BLOCKED = 'popup-blocked',\n  POPUP_CLOSED_BY_USER = 'popup-closed-by-user',\n  PROVIDER_ALREADY_LINKED = 'provider-already-linked',\n  QUOTA_EXCEEDED = 'quota-exceeded',\n  REDIRECT_CANCELLED_BY_USER = 'redirect-cancelled-by-user',\n  REDIRECT_OPERATION_PENDING = 'redirect-operation-pending',\n  REJECTED_CREDENTIAL = 'rejected-credential',\n  SECOND_FACTOR_ALREADY_ENROLLED = 'second-factor-already-in-use',\n  SECOND_FACTOR_LIMIT_EXCEEDED = 'maximum-second-factor-count-exceeded',\n  TENANT_ID_MISMATCH = 'tenant-id-mismatch',\n  TIMEOUT = 'timeout',\n  TOKEN_EXPIRED = 'user-token-expired',\n  TOO_MANY_ATTEMPTS_TRY_LATER = 'too-many-requests',\n  UNAUTHORIZED_DOMAIN = 'unauthorized-continue-uri',\n  UNSUPPORTED_FIRST_FACTOR = 'unsupported-first-factor',\n  UNSUPPORTED_PERSISTENCE = 'unsupported-persistence-type',\n  UNSUPPORTED_TENANT_OPERATION = 'unsupported-tenant-operation',\n  UNVERIFIED_EMAIL = 'unverified-email',\n  USER_CANCELLED = 'user-cancelled',\n  USER_DELETED = 'user-not-found',\n  USER_DISABLED = 'user-disabled',\n  USER_MISMATCH = 'user-mismatch',\n  USER_SIGNED_OUT = 'user-signed-out',\n  WEAK_PASSWORD = 'weak-password',\n  WEB_STORAGE_UNSUPPORTED = 'web-storage-unsupported',\n  ALREADY_INITIALIZED = 'already-initialized',\n  RECAPTCHA_NOT_ENABLED = 'recaptcha-not-enabled',\n  MISSING_RECAPTCHA_TOKEN = 'missing-recaptcha-token',\n  INVALID_RECAPTCHA_TOKEN = 'invalid-recaptcha-token',\n  INVALID_RECAPTCHA_ACTION = 'invalid-recaptcha-action',\n  MISSING_CLIENT_TYPE = 'missing-client-type',\n  MISSING_RECAPTCHA_VERSION = 'missing-recaptcha-version',\n  INVALID_RECAPTCHA_VERSION = 'invalid-recaptcha-version',\n  INVALID_REQ_TYPE = 'invalid-req-type',\n  UNSUPPORTED_PASSWORD_POLICY_SCHEMA_VERSION = 'unsupported-password-policy-schema-version',\n  PASSWORD_DOES_NOT_MEET_REQUIREMENTS = 'password-does-not-meet-requirements',\n  INVALID_HOSTING_LINK_DOMAIN = 'invalid-hosting-link-domain'\n}\n\nfunction _debugErrorMap(): ErrorMap<AuthErrorCode> {\n  return {\n    [AuthErrorCode.ADMIN_ONLY_OPERATION]:\n      'This operation is restricted to administrators only.',\n    [AuthErrorCode.ARGUMENT_ERROR]: '',\n    [AuthErrorCode.APP_NOT_AUTHORIZED]:\n      \"This app, identified by the domain where it's hosted, is not \" +\n      'authorized to use Firebase Authentication with the provided API key. ' +\n      'Review your key configuration in the Google API console.',\n    [AuthErrorCode.APP_NOT_INSTALLED]:\n      'The requested mobile application corresponding to the identifier (' +\n      'Android package name or iOS bundle ID) provided is not installed on ' +\n      'this device.',\n    [AuthErrorCode.CAPTCHA_CHECK_FAILED]:\n      'The reCAPTCHA response token provided is either invalid, expired, ' +\n      'already used or the domain associated with it does not match the list ' +\n      'of whitelisted domains.',\n    [AuthErrorCode.CODE_EXPIRED]:\n      'The SMS code has expired. Please re-send the verification code to try ' +\n      'again.',\n    [AuthErrorCode.CORDOVA_NOT_READY]: 'Cordova framework is not ready.',\n    [AuthErrorCode.CORS_UNSUPPORTED]: 'This browser is not supported.',\n    [AuthErrorCode.CREDENTIAL_ALREADY_IN_USE]:\n      'This credential is already associated with a different user account.',\n    [AuthErrorCode.CREDENTIAL_MISMATCH]:\n      'The custom token corresponds to a different audience.',\n    [AuthErrorCode.CREDENTIAL_TOO_OLD_LOGIN_AGAIN]:\n      'This operation is sensitive and requires recent authentication. Log in ' +\n      'again before retrying this request.',\n    [AuthErrorCode.DEPENDENT_SDK_INIT_BEFORE_AUTH]:\n      'Another Firebase SDK was initialized and is trying to use Auth before Auth is ' +\n      'initialized. Please be sure to call `initializeAuth` or `getAuth` before ' +\n      'starting any other Firebase SDK.',\n    [AuthErrorCode.DYNAMIC_LINK_NOT_ACTIVATED]:\n      'Please activate Dynamic Links in the Firebase Console and agree to the terms and ' +\n      'conditions.',\n    [AuthErrorCode.EMAIL_CHANGE_NEEDS_VERIFICATION]:\n      'Multi-factor users must always have a verified email.',\n    [AuthErrorCode.EMAIL_EXISTS]:\n      'The email address is already in use by another account.',\n    [AuthErrorCode.EMULATOR_CONFIG_FAILED]:\n      'Auth instance has already been used to make a network call. Auth can ' +\n      'no longer be configured to use the emulator. Try calling ' +\n      '\"connectAuthEmulator()\" sooner.',\n    [AuthErrorCode.EXPIRED_OOB_CODE]: 'The action code has expired.',\n    [AuthErrorCode.EXPIRED_POPUP_REQUEST]:\n      'This operation has been cancelled due to another conflicting popup being opened.',\n    [AuthErrorCode.INTERNAL_ERROR]: 'An internal AuthError has occurred.',\n    [AuthErrorCode.INVALID_APP_CREDENTIAL]:\n      'The phone verification request contains an invalid application verifier.' +\n      ' The reCAPTCHA token response is either invalid or expired.',\n    [AuthErrorCode.INVALID_APP_ID]:\n      'The mobile app identifier is not registered for the current project.',\n    [AuthErrorCode.INVALID_AUTH]:\n      \"This user's credential isn't valid for this project. This can happen \" +\n      \"if the user's token has been tampered with, or if the user isn't for \" +\n      'the project associated with this API key.',\n    [AuthErrorCode.INVALID_AUTH_EVENT]: 'An internal AuthError has occurred.',\n    [AuthErrorCode.INVALID_CODE]:\n      'The SMS verification code used to create the phone auth credential is ' +\n      'invalid. Please resend the verification code sms and be sure to use the ' +\n      'verification code provided by the user.',\n    [AuthErrorCode.INVALID_CONTINUE_URI]:\n      'The continue URL provided in the request is invalid.',\n    [AuthErrorCode.INVALID_CORDOVA_CONFIGURATION]:\n      'The following Cordova plugins must be installed to enable OAuth sign-in: ' +\n      'cordova-plugin-buildinfo, cordova-universal-links-plugin, ' +\n      'cordova-plugin-browsertab, cordova-plugin-inappbrowser and ' +\n      'cordova-plugin-customurlscheme.',\n    [AuthErrorCode.INVALID_CUSTOM_TOKEN]:\n      'The custom token format is incorrect. Please check the documentation.',\n    [AuthErrorCode.INVALID_DYNAMIC_LINK_DOMAIN]:\n      'The provided dynamic link domain is not configured or authorized for the current project.',\n    [AuthErrorCode.INVALID_EMAIL]: 'The email address is badly formatted.',\n    [AuthErrorCode.INVALID_EMULATOR_SCHEME]:\n      'Emulator URL must start with a valid scheme (http:// or https://).',\n    [AuthErrorCode.INVALID_API_KEY]:\n      'Your API key is invalid, please check you have copied it correctly.',\n    [AuthErrorCode.INVALID_CERT_HASH]:\n      'The SHA-1 certificate hash provided is invalid.',\n    [AuthErrorCode.INVALID_CREDENTIAL]:\n      'The supplied auth credential is incorrect, malformed or has expired.',\n    [AuthErrorCode.INVALID_MESSAGE_PAYLOAD]:\n      'The email template corresponding to this action contains invalid characters in its message. ' +\n      'Please fix by going to the Auth email templates section in the Firebase Console.',\n    [AuthErrorCode.INVALID_MFA_SESSION]:\n      'The request does not contain a valid proof of first factor successful sign-in.',\n    [AuthErrorCode.INVALID_OAUTH_PROVIDER]:\n      'EmailAuthProvider is not supported for this operation. This operation ' +\n      'only supports OAuth providers.',\n    [AuthErrorCode.INVALID_OAUTH_CLIENT_ID]:\n      'The OAuth client ID provided is either invalid or does not match the ' +\n      'specified API key.',\n    [AuthErrorCode.INVALID_ORIGIN]:\n      'This domain is not authorized for OAuth operations for your Firebase ' +\n      'project. Edit the list of authorized domains from the Firebase console.',\n    [AuthErrorCode.INVALID_OOB_CODE]:\n      'The action code is invalid. This can happen if the code is malformed, ' +\n      'expired, or has already been used.',\n    [AuthErrorCode.INVALID_PASSWORD]:\n      'The password is invalid or the user does not have a password.',\n    [AuthErrorCode.INVALID_PERSISTENCE]:\n      'The specified persistence type is invalid. It can only be local, session or none.',\n    [AuthErrorCode.INVALID_PHONE_NUMBER]:\n      'The format of the phone number provided is incorrect. Please enter the ' +\n      'phone number in a format that can be parsed into E.164 format. E.164 ' +\n      'phone numbers are written in the format [+][country code][subscriber ' +\n      'number including area code].',\n    [AuthErrorCode.INVALID_PROVIDER_ID]:\n      'The specified provider ID is invalid.',\n    [AuthErrorCode.INVALID_RECIPIENT_EMAIL]:\n      'The email corresponding to this action failed to send as the provided ' +\n      'recipient email address is invalid.',\n    [AuthErrorCode.INVALID_SENDER]:\n      'The email template corresponding to this action contains an invalid sender email or name. ' +\n      'Please fix by going to the Auth email templates section in the Firebase Console.',\n    [AuthErrorCode.INVALID_SESSION_INFO]:\n      'The verification ID used to create the phone auth credential is invalid.',\n    [AuthErrorCode.INVALID_TENANT_ID]:\n      \"The Auth instance's tenant ID is invalid.\",\n    [AuthErrorCode.LOGIN_BLOCKED]:\n      'Login blocked by user-provided method: {$originalMessage}',\n    [AuthErrorCode.MISSING_ANDROID_PACKAGE_NAME]:\n      'An Android Package Name must be provided if the Android App is required to be installed.',\n    [AuthErrorCode.MISSING_AUTH_DOMAIN]:\n      'Be sure to include authDomain when calling firebase.initializeApp(), ' +\n      'by following the instructions in the Firebase console.',\n    [AuthErrorCode.MISSING_APP_CREDENTIAL]:\n      'The phone verification request is missing an application verifier ' +\n      'assertion. A reCAPTCHA response token needs to be provided.',\n    [AuthErrorCode.MISSING_CODE]:\n      'The phone auth credential was created with an empty SMS verification code.',\n    [AuthErrorCode.MISSING_CONTINUE_URI]:\n      'A continue URL must be provided in the request.',\n    [AuthErrorCode.MISSING_IFRAME_START]: 'An internal AuthError has occurred.',\n    [AuthErrorCode.MISSING_IOS_BUNDLE_ID]:\n      'An iOS Bundle ID must be provided if an App Store ID is provided.',\n    [AuthErrorCode.MISSING_OR_INVALID_NONCE]:\n      'The request does not contain a valid nonce. This can occur if the ' +\n      'SHA-256 hash of the provided raw nonce does not match the hashed nonce ' +\n      'in the ID token payload.',\n    [AuthErrorCode.MISSING_PASSWORD]: 'A non-empty password must be provided',\n    [AuthErrorCode.MISSING_MFA_INFO]:\n      'No second factor identifier is provided.',\n    [AuthErrorCode.MISSING_MFA_SESSION]:\n      'The request is missing proof of first factor successful sign-in.',\n    [AuthErrorCode.MISSING_PHONE_NUMBER]:\n      'To send verification codes, provide a phone number for the recipient.',\n    [AuthErrorCode.MISSING_SESSION_INFO]:\n      'The phone auth credential was created with an empty verification ID.',\n    [AuthErrorCode.MODULE_DESTROYED]:\n      'This instance of FirebaseApp has been deleted.',\n    [AuthErrorCode.MFA_INFO_NOT_FOUND]:\n      'The user does not have a second factor matching the identifier provided.',\n    [AuthErrorCode.MFA_REQUIRED]:\n      'Proof of ownership of a second factor is required to complete sign-in.',\n    [AuthErrorCode.NEED_CONFIRMATION]:\n      'An account already exists with the same email address but different ' +\n      'sign-in credentials. Sign in using a provider associated with this ' +\n      'email address.',\n    [AuthErrorCode.NETWORK_REQUEST_FAILED]:\n      'A network AuthError (such as timeout, interrupted connection or unreachable host) has occurred.',\n    [AuthErrorCode.NO_AUTH_EVENT]: 'An internal AuthError has occurred.',\n    [AuthErrorCode.NO_SUCH_PROVIDER]:\n      'User was not linked to an account with the given provider.',\n    [AuthErrorCode.NULL_USER]:\n      'A null user object was provided as the argument for an operation which ' +\n      'requires a non-null user object.',\n    [AuthErrorCode.OPERATION_NOT_ALLOWED]:\n      'The given sign-in provider is disabled for this Firebase project. ' +\n      'Enable it in the Firebase console, under the sign-in method tab of the ' +\n      'Auth section.',\n    [AuthErrorCode.OPERATION_NOT_SUPPORTED]:\n      'This operation is not supported in the environment this application is ' +\n      'running on. \"location.protocol\" must be http, https or chrome-extension' +\n      ' and web storage must be enabled.',\n    [AuthErrorCode.POPUP_BLOCKED]:\n      'Unable to establish a connection with the popup. It may have been blocked by the browser.',\n    [AuthErrorCode.POPUP_CLOSED_BY_USER]:\n      'The popup has been closed by the user before finalizing the operation.',\n    [AuthErrorCode.PROVIDER_ALREADY_LINKED]:\n      'User can only be linked to one identity for the given provider.',\n    [AuthErrorCode.QUOTA_EXCEEDED]:\n      \"The project's quota for this operation has been exceeded.\",\n    [AuthErrorCode.REDIRECT_CANCELLED_BY_USER]:\n      'The redirect operation has been cancelled by the user before finalizing.',\n    [AuthErrorCode.REDIRECT_OPERATION_PENDING]:\n      'A redirect sign-in operation is already pending.',\n    [AuthErrorCode.REJECTED_CREDENTIAL]:\n      'The request contains malformed or mismatching credentials.',\n    [AuthErrorCode.SECOND_FACTOR_ALREADY_ENROLLED]:\n      'The second factor is already enrolled on this account.',\n    [AuthErrorCode.SECOND_FACTOR_LIMIT_EXCEEDED]:\n      'The maximum allowed number of second factors on a user has been exceeded.',\n    [AuthErrorCode.TENANT_ID_MISMATCH]:\n      \"The provided tenant ID does not match the Auth instance's tenant ID\",\n    [AuthErrorCode.TIMEOUT]: 'The operation has timed out.',\n    [AuthErrorCode.TOKEN_EXPIRED]:\n      \"The user's credential is no longer valid. The user must sign in again.\",\n    [AuthErrorCode.TOO_MANY_ATTEMPTS_TRY_LATER]:\n      'We have blocked all requests from this device due to unusual activity. ' +\n      'Try again later.',\n    [AuthErrorCode.UNAUTHORIZED_DOMAIN]:\n      'The domain of the continue URL is not whitelisted.  Please whitelist ' +\n      'the domain in the Firebase console.',\n    [AuthErrorCode.UNSUPPORTED_FIRST_FACTOR]:\n      'Enrolling a second factor or signing in with a multi-factor account requires sign-in with a supported first factor.',\n    [AuthErrorCode.UNSUPPORTED_PERSISTENCE]:\n      'The current environment does not support the specified persistence type.',\n    [AuthErrorCode.UNSUPPORTED_TENANT_OPERATION]:\n      'This operation is not supported in a multi-tenant context.',\n    [AuthErrorCode.UNVERIFIED_EMAIL]:\n      'The operation requires a verified email.',\n    [AuthErrorCode.USER_CANCELLED]:\n      'The user did not grant your application the permissions it requested.',\n    [AuthErrorCode.USER_DELETED]:\n      'There is no user record corresponding to this identifier. The user may ' +\n      'have been deleted.',\n    [AuthErrorCode.USER_DISABLED]:\n      'The user account has been disabled by an administrator.',\n    [AuthErrorCode.USER_MISMATCH]:\n      'The supplied credentials do not correspond to the previously signed in user.',\n    [AuthErrorCode.USER_SIGNED_OUT]: '',\n    [AuthErrorCode.WEAK_PASSWORD]:\n      'The password must be 6 characters long or more.',\n    [AuthErrorCode.WEB_STORAGE_UNSUPPORTED]:\n      'This browser is not supported or 3rd party cookies and data may be disabled.',\n    [AuthErrorCode.ALREADY_INITIALIZED]:\n      'initializeAuth() has already been called with ' +\n      'different options. To avoid this error, call initializeAuth() with the ' +\n      'same options as when it was originally called, or call getAuth() to return the' +\n      ' already initialized instance.',\n    [AuthErrorCode.MISSING_RECAPTCHA_TOKEN]:\n      'The reCAPTCHA token is missing when sending request to the backend.',\n    [AuthErrorCode.INVALID_RECAPTCHA_TOKEN]:\n      'The reCAPTCHA token is invalid when sending request to the backend.',\n    [AuthErrorCode.INVALID_RECAPTCHA_ACTION]:\n      'The reCAPTCHA action is invalid when sending request to the backend.',\n    [AuthErrorCode.RECAPTCHA_NOT_ENABLED]:\n      'reCAPTCHA Enterprise integration is not enabled for this project.',\n    [AuthErrorCode.MISSING_CLIENT_TYPE]:\n      'The reCAPTCHA client type is missing when sending request to the backend.',\n    [AuthErrorCode.MISSING_RECAPTCHA_VERSION]:\n      'The reCAPTCHA version is missing when sending request to the backend.',\n    [AuthErrorCode.INVALID_REQ_TYPE]: 'Invalid request parameters.',\n    [AuthErrorCode.INVALID_RECAPTCHA_VERSION]:\n      'The reCAPTCHA version is invalid when sending request to the backend.',\n    [AuthErrorCode.UNSUPPORTED_PASSWORD_POLICY_SCHEMA_VERSION]:\n      'The password policy received from the backend uses a schema version that is not supported by this version of the Firebase SDK.',\n    [AuthErrorCode.PASSWORD_DOES_NOT_MEET_REQUIREMENTS]:\n      'The password does not meet the requirements.',\n    [AuthErrorCode.INVALID_HOSTING_LINK_DOMAIN]:\n      'The provided Hosting link domain is not configured in Firebase Hosting or is not owned by ' +\n      'the current project. This cannot be a default Hosting domain (`web.app` or `firebaseapp.com`).'\n  };\n}\n\nexport interface ErrorMapRetriever extends AuthErrorMap {\n  (): ErrorMap<AuthErrorCode>;\n}\n\nfunction _prodErrorMap(): ErrorMap<AuthErrorCode> {\n  // We will include this one message in the prod error map since by the very\n  // nature of this error, developers will never be able to see the message\n  // using the debugErrorMap (which is installed during auth initialization).\n  return {\n    [AuthErrorCode.DEPENDENT_SDK_INIT_BEFORE_AUTH]:\n      'Another Firebase SDK was initialized and is trying to use Auth before Auth is ' +\n      'initialized. Please be sure to call `initializeAuth` or `getAuth` before ' +\n      'starting any other Firebase SDK.'\n  } as ErrorMap<AuthErrorCode>;\n}\n\n/**\n * A verbose error map with detailed descriptions for most error codes.\n *\n * See discussion at {@link AuthErrorMap}\n *\n * @public\n */\nexport const debugErrorMap: AuthErrorMap = _debugErrorMap;\n\n/**\n * A minimal error map with all verbose error messages stripped.\n *\n * See discussion at {@link AuthErrorMap}\n *\n * @public\n */\nexport const prodErrorMap: AuthErrorMap = _prodErrorMap;\n\nexport interface NamedErrorParams {\n  appName: AppName;\n  credential?: AuthCredential;\n  email?: string;\n  phoneNumber?: string;\n  tenantId?: string;\n  user?: User;\n  _serverResponse?: object;\n}\n\n/**\n * @internal\n */\ntype GenericAuthErrorParams = {\n  [key in Exclude<\n    AuthErrorCode,\n    | AuthErrorCode.ARGUMENT_ERROR\n    | AuthErrorCode.DEPENDENT_SDK_INIT_BEFORE_AUTH\n    | AuthErrorCode.INTERNAL_ERROR\n    | AuthErrorCode.MFA_REQUIRED\n    | AuthErrorCode.NO_AUTH_EVENT\n    | AuthErrorCode.OPERATION_NOT_SUPPORTED\n  >]: {\n    appName?: AppName;\n    email?: string;\n    phoneNumber?: string;\n    message?: string;\n  };\n};\n\n/**\n * @internal\n */\nexport interface AuthErrorParams extends GenericAuthErrorParams {\n  [AuthErrorCode.ARGUMENT_ERROR]: { appName?: AppName };\n  [AuthErrorCode.DEPENDENT_SDK_INIT_BEFORE_AUTH]: { appName?: AppName };\n  [AuthErrorCode.INTERNAL_ERROR]: { appName?: AppName };\n  [AuthErrorCode.LOGIN_BLOCKED]: {\n    appName?: AppName;\n    originalMessage?: string;\n  };\n  [AuthErrorCode.OPERATION_NOT_SUPPORTED]: { appName?: AppName };\n  [AuthErrorCode.NO_AUTH_EVENT]: { appName?: AppName };\n  [AuthErrorCode.MFA_REQUIRED]: {\n    appName: AppName;\n    _serverResponse: IdTokenMfaResponse;\n  };\n  [AuthErrorCode.INVALID_CORDOVA_CONFIGURATION]: {\n    appName: AppName;\n    missingPlugin?: string;\n  };\n}\n\nexport const _DEFAULT_AUTH_ERROR_FACTORY = new ErrorFactory<\n  AuthErrorCode,\n  AuthErrorParams\n>('auth', 'Firebase', _prodErrorMap());\n\n/**\n * A map of potential `Auth` error codes, for easier comparison with errors\n * thrown by the SDK.\n *\n * @remarks\n * Note that you can't tree-shake individual keys\n * in the map, so by using the map you might substantially increase your\n * bundle size.\n *\n * @public\n */\nexport const AUTH_ERROR_CODES_MAP_DO_NOT_USE_INTERNALLY = {\n  ADMIN_ONLY_OPERATION: 'auth/admin-restricted-operation',\n  ARGUMENT_ERROR: 'auth/argument-error',\n  APP_NOT_AUTHORIZED: 'auth/app-not-authorized',\n  APP_NOT_INSTALLED: 'auth/app-not-installed',\n  CAPTCHA_CHECK_FAILED: 'auth/captcha-check-failed',\n  CODE_EXPIRED: 'auth/code-expired',\n  CORDOVA_NOT_READY: 'auth/cordova-not-ready',\n  CORS_UNSUPPORTED: 'auth/cors-unsupported',\n  CREDENTIAL_ALREADY_IN_USE: 'auth/credential-already-in-use',\n  CREDENTIAL_MISMATCH: 'auth/custom-token-mismatch',\n  CREDENTIAL_TOO_OLD_LOGIN_AGAIN: 'auth/requires-recent-login',\n  DEPENDENT_SDK_INIT_BEFORE_AUTH: 'auth/dependent-sdk-initialized-before-auth',\n  DYNAMIC_LINK_NOT_ACTIVATED: 'auth/dynamic-link-not-activated',\n  EMAIL_CHANGE_NEEDS_VERIFICATION: 'auth/email-change-needs-verification',\n  EMAIL_EXISTS: 'auth/email-already-in-use',\n  EMULATOR_CONFIG_FAILED: 'auth/emulator-config-failed',\n  EXPIRED_OOB_CODE: 'auth/expired-action-code',\n  EXPIRED_POPUP_REQUEST: 'auth/cancelled-popup-request',\n  INTERNAL_ERROR: 'auth/internal-error',\n  INVALID_API_KEY: 'auth/invalid-api-key',\n  INVALID_APP_CREDENTIAL: 'auth/invalid-app-credential',\n  INVALID_APP_ID: 'auth/invalid-app-id',\n  INVALID_AUTH: 'auth/invalid-user-token',\n  INVALID_AUTH_EVENT: 'auth/invalid-auth-event',\n  INVALID_CERT_HASH: 'auth/invalid-cert-hash',\n  INVALID_CODE: 'auth/invalid-verification-code',\n  INVALID_CONTINUE_URI: 'auth/invalid-continue-uri',\n  INVALID_CORDOVA_CONFIGURATION: 'auth/invalid-cordova-configuration',\n  INVALID_CUSTOM_TOKEN: 'auth/invalid-custom-token',\n  INVALID_DYNAMIC_LINK_DOMAIN: 'auth/invalid-dynamic-link-domain',\n  INVALID_EMAIL: 'auth/invalid-email',\n  INVALID_EMULATOR_SCHEME: 'auth/invalid-emulator-scheme',\n  INVALID_IDP_RESPONSE: 'auth/invalid-credential',\n  INVALID_LOGIN_CREDENTIALS: 'auth/invalid-credential',\n  INVALID_MESSAGE_PAYLOAD: 'auth/invalid-message-payload',\n  INVALID_MFA_SESSION: 'auth/invalid-multi-factor-session',\n  INVALID_OAUTH_CLIENT_ID: 'auth/invalid-oauth-client-id',\n  INVALID_OAUTH_PROVIDER: 'auth/invalid-oauth-provider',\n  INVALID_OOB_CODE: 'auth/invalid-action-code',\n  INVALID_ORIGIN: 'auth/unauthorized-domain',\n  INVALID_PASSWORD: 'auth/wrong-password',\n  INVALID_PERSISTENCE: 'auth/invalid-persistence-type',\n  INVALID_PHONE_NUMBER: 'auth/invalid-phone-number',\n  INVALID_PROVIDER_ID: 'auth/invalid-provider-id',\n  INVALID_RECIPIENT_EMAIL: 'auth/invalid-recipient-email',\n  INVALID_SENDER: 'auth/invalid-sender',\n  INVALID_SESSION_INFO: 'auth/invalid-verification-id',\n  INVALID_TENANT_ID: 'auth/invalid-tenant-id',\n  MFA_INFO_NOT_FOUND: 'auth/multi-factor-info-not-found',\n  MFA_REQUIRED: 'auth/multi-factor-auth-required',\n  MISSING_ANDROID_PACKAGE_NAME: 'auth/missing-android-pkg-name',\n  MISSING_APP_CREDENTIAL: 'auth/missing-app-credential',\n  MISSING_AUTH_DOMAIN: 'auth/auth-domain-config-required',\n  MISSING_CODE: 'auth/missing-verification-code',\n  MISSING_CONTINUE_URI: 'auth/missing-continue-uri',\n  MISSING_IFRAME_START: 'auth/missing-iframe-start',\n  MISSING_IOS_BUNDLE_ID: 'auth/missing-ios-bundle-id',\n  MISSING_OR_INVALID_NONCE: 'auth/missing-or-invalid-nonce',\n  MISSING_MFA_INFO: 'auth/missing-multi-factor-info',\n  MISSING_MFA_SESSION: 'auth/missing-multi-factor-session',\n  MISSING_PHONE_NUMBER: 'auth/missing-phone-number',\n  MISSING_PASSWORD: 'auth/missing-password',\n  MISSING_SESSION_INFO: 'auth/missing-verification-id',\n  MODULE_DESTROYED: 'auth/app-deleted',\n  NEED_CONFIRMATION: 'auth/account-exists-with-different-credential',\n  NETWORK_REQUEST_FAILED: 'auth/network-request-failed',\n  NULL_USER: 'auth/null-user',\n  NO_AUTH_EVENT: 'auth/no-auth-event',\n  NO_SUCH_PROVIDER: 'auth/no-such-provider',\n  OPERATION_NOT_ALLOWED: 'auth/operation-not-allowed',\n  OPERATION_NOT_SUPPORTED: 'auth/operation-not-supported-in-this-environment',\n  POPUP_BLOCKED: 'auth/popup-blocked',\n  POPUP_CLOSED_BY_USER: 'auth/popup-closed-by-user',\n  PROVIDER_ALREADY_LINKED: 'auth/provider-already-linked',\n  QUOTA_EXCEEDED: 'auth/quota-exceeded',\n  REDIRECT_CANCELLED_BY_USER: 'auth/redirect-cancelled-by-user',\n  REDIRECT_OPERATION_PENDING: 'auth/redirect-operation-pending',\n  REJECTED_CREDENTIAL: 'auth/rejected-credential',\n  SECOND_FACTOR_ALREADY_ENROLLED: 'auth/second-factor-already-in-use',\n  SECOND_FACTOR_LIMIT_EXCEEDED: 'auth/maximum-second-factor-count-exceeded',\n  TENANT_ID_MISMATCH: 'auth/tenant-id-mismatch',\n  TIMEOUT: 'auth/timeout',\n  TOKEN_EXPIRED: 'auth/user-token-expired',\n  TOO_MANY_ATTEMPTS_TRY_LATER: 'auth/too-many-requests',\n  UNAUTHORIZED_DOMAIN: 'auth/unauthorized-continue-uri',\n  UNSUPPORTED_FIRST_FACTOR: 'auth/unsupported-first-factor',\n  UNSUPPORTED_PERSISTENCE: 'auth/unsupported-persistence-type',\n  UNSUPPORTED_TENANT_OPERATION: 'auth/unsupported-tenant-operation',\n  UNVERIFIED_EMAIL: 'auth/unverified-email',\n  USER_CANCELLED: 'auth/user-cancelled',\n  USER_DELETED: 'auth/user-not-found',\n  USER_DISABLED: 'auth/user-disabled',\n  USER_MISMATCH: 'auth/user-mismatch',\n  USER_SIGNED_OUT: 'auth/user-signed-out',\n  WEAK_PASSWORD: 'auth/weak-password',\n  WEB_STORAGE_UNSUPPORTED: 'auth/web-storage-unsupported',\n  ALREADY_INITIALIZED: 'auth/already-initialized',\n  RECAPTCHA_NOT_ENABLED: 'auth/recaptcha-not-enabled',\n  MISSING_RECAPTCHA_TOKEN: 'auth/missing-recaptcha-token',\n  INVALID_RECAPTCHA_TOKEN: 'auth/invalid-recaptcha-token',\n  INVALID_RECAPTCHA_ACTION: 'auth/invalid-recaptcha-action',\n  MISSING_CLIENT_TYPE: 'auth/missing-client-type',\n  MISSING_RECAPTCHA_VERSION: 'auth/missing-recaptcha-version',\n  INVALID_RECAPTCHA_VERSION: 'auth/invalid-recaptcha-version',\n  INVALID_REQ_TYPE: 'auth/invalid-req-type',\n  INVALID_HOSTING_LINK_DOMAIN: 'auth/invalid-hosting-link-domain'\n} as const;\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Logger, LogLevel } from '@firebase/logger';\nimport { SDK_VERSION } from '@firebase/app';\n\nexport { LogLevel };\n\nconst logClient = new Logger('@firebase/auth');\n\n// Helper methods are needed because variables can't be exported as read/write\nexport function _getLogLevel(): LogLevel {\n  return logClient.logLevel;\n}\n\nexport function _setLogLevel(newLevel: LogLevel): void {\n  logClient.logLevel = newLevel;\n}\n\nexport function _logDebug(msg: string, ...args: string[]): void {\n  if (logClient.logLevel <= LogLevel.DEBUG) {\n    logClient.debug(`Auth (${SDK_VERSION}): ${msg}`, ...args);\n  }\n}\n\nexport function _logWarn(msg: string, ...args: string[]): void {\n  if (logClient.logLevel <= LogLevel.WARN) {\n    logClient.warn(`Auth (${SDK_VERSION}): ${msg}`, ...args);\n  }\n}\n\nexport function _logError(msg: string, ...args: string[]): void {\n  if (logClient.logLevel <= LogLevel.ERROR) {\n    logClient.error(`Auth (${SDK_VERSION}): ${msg}`, ...args);\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Auth } from '../../model/public_types';\nimport { ErrorFactory, FirebaseError } from '@firebase/util';\nimport { AuthInternal } from '../../model/auth';\nimport {\n  _DEFAULT_AUTH_ERROR_FACTORY,\n  AuthErrorCode,\n  AuthErrorParams,\n  prodErrorMap,\n  ErrorMapRetriever\n} from '../errors';\nimport { _logError } from './log';\n\ntype AuthErrorListParams<K> = K extends keyof AuthErrorParams\n  ? [AuthErrorParams[K]]\n  : [];\ntype LessAppName<K extends AuthErrorCode> = Omit<AuthErrorParams[K], 'appName'>;\n\n/**\n * Unconditionally fails, throwing a developer facing INTERNAL_ERROR\n *\n * @example\n * ```javascript\n * fail(auth, AuthErrorCode.MFA_REQUIRED);  // Error: the MFA_REQUIRED error needs more params than appName\n * fail(auth, AuthErrorCode.MFA_REQUIRED, {serverResponse});  // Compiles\n * fail(AuthErrorCode.INTERNAL_ERROR);  // Compiles; internal error does not need appName\n * fail(AuthErrorCode.USER_DELETED);  // Error: USER_DELETED requires app name\n * fail(auth, AuthErrorCode.USER_DELETED);  // Compiles; USER_DELETED _only_ needs app name\n * ```\n *\n * @param appName App name for tagging the error\n * @throws FirebaseError\n */\nexport function _fail<K extends AuthErrorCode>(\n  code: K,\n  ...data: {} extends AuthErrorParams[K]\n    ? [AuthErrorParams[K]?]\n    : [AuthErrorParams[K]]\n): never;\nexport function _fail<K extends AuthErrorCode>(\n  auth: Auth,\n  code: K,\n  ...data: {} extends LessAppName<K> ? [LessAppName<K>?] : [LessAppName<K>]\n): never;\nexport function _fail<K extends AuthErrorCode>(\n  authOrCode: Auth | K,\n  ...rest: unknown[]\n): never {\n  throw createErrorInternal(authOrCode, ...rest);\n}\n\nexport function _createError<K extends AuthErrorCode>(\n  code: K,\n  ...data: {} extends AuthErrorParams[K]\n    ? [AuthErrorParams[K]?]\n    : [AuthErrorParams[K]]\n): FirebaseError;\nexport function _createError<K extends AuthErrorCode>(\n  auth: Auth,\n  code: K,\n  ...data: {} extends LessAppName<K> ? [LessAppName<K>?] : [LessAppName<K>]\n): FirebaseError;\nexport function _createError<K extends AuthErrorCode>(\n  authOrCode: Auth | K,\n  ...rest: unknown[]\n): FirebaseError {\n  return createErrorInternal(authOrCode, ...rest);\n}\n\nexport function _errorWithCustomMessage(\n  auth: Auth,\n  code: AuthErrorCode,\n  message: string\n): FirebaseError {\n  const errorMap = {\n    ...(prodErrorMap as ErrorMapRetriever)(),\n    [code]: message\n  };\n  const factory = new ErrorFactory<AuthErrorCode, AuthErrorParams>(\n    'auth',\n    'Firebase',\n    errorMap\n  );\n  return factory.create(code, {\n    appName: auth.name\n  });\n}\n\nexport function _serverAppCurrentUserOperationNotSupportedError(\n  auth: Auth\n): FirebaseError {\n  return _errorWithCustomMessage(\n    auth,\n    AuthErrorCode.OPERATION_NOT_SUPPORTED,\n    'Operations that alter the current user are not supported in conjunction with FirebaseServerApp'\n  );\n}\n\nexport function _assertInstanceOf(\n  auth: Auth,\n  object: object,\n  instance: unknown\n): void {\n  const constructorInstance = instance as { new (...args: unknown[]): unknown };\n  if (!(object instanceof constructorInstance)) {\n    if (constructorInstance.name !== object.constructor.name) {\n      _fail(auth, AuthErrorCode.ARGUMENT_ERROR);\n    }\n\n    throw _errorWithCustomMessage(\n      auth,\n      AuthErrorCode.ARGUMENT_ERROR,\n      `Type of ${object.constructor.name} does not match expected instance.` +\n        `Did you pass a reference from a different Auth SDK?`\n    );\n  }\n}\n\nfunction createErrorInternal<K extends AuthErrorCode>(\n  authOrCode: Auth | K,\n  ...rest: unknown[]\n): FirebaseError {\n  if (typeof authOrCode !== 'string') {\n    const code = rest[0] as K;\n    const fullParams = [...rest.slice(1)] as AuthErrorListParams<K>;\n    if (fullParams[0]) {\n      fullParams[0].appName = authOrCode.name;\n    }\n\n    return (authOrCode as AuthInternal)._errorFactory.create(\n      code,\n      ...fullParams\n    );\n  }\n\n  return _DEFAULT_AUTH_ERROR_FACTORY.create(\n    authOrCode,\n    ...(rest as AuthErrorListParams<K>)\n  );\n}\n\nexport function _assert<K extends AuthErrorCode>(\n  assertion: unknown,\n  code: K,\n  ...data: {} extends AuthErrorParams[K]\n    ? [AuthErrorParams[K]?]\n    : [AuthErrorParams[K]]\n): asserts assertion;\nexport function _assert<K extends AuthErrorCode>(\n  assertion: unknown,\n  auth: Auth,\n  code: K,\n  ...data: {} extends LessAppName<K> ? [LessAppName<K>?] : [LessAppName<K>]\n): asserts assertion;\nexport function _assert<K extends AuthErrorCode>(\n  assertion: unknown,\n  authOrCode: Auth | K,\n  ...rest: unknown[]\n): asserts assertion {\n  if (!assertion) {\n    throw createErrorInternal(authOrCode, ...rest);\n  }\n}\n\n// We really do want to accept literally any function type here\n// eslint-disable-next-line @typescript-eslint/ban-types\ntype TypeExpectation = Function | string | MapType;\n\ninterface MapType extends Record<string, TypeExpectation | Optional> {}\n\nclass Optional {\n  constructor(readonly type: TypeExpectation) {}\n}\n\nexport function opt(type: TypeExpectation): Optional {\n  return new Optional(type);\n}\n\n/**\n * Asserts the runtime types of arguments. The 'expected' field can be one of\n * a class, a string (representing a \"typeof\" call), or a record map of name\n * to type. Furthermore, the opt() function can be used to mark a field as\n * optional. For example:\n *\n * function foo(auth: Auth, profile: {displayName?: string}, update = false) {\n *   assertTypes(arguments, [AuthImpl, {displayName: opt('string')}, opt('boolean')]);\n * }\n *\n * opt() can be used for any type:\n * function foo(auth?: Auth) {\n *   assertTypes(arguments, [opt(AuthImpl)]);\n * }\n *\n * The string types can be or'd together, and you can use \"null\" as well (note\n * that typeof null === 'object'; this is an edge case). For example:\n *\n * function foo(profile: {displayName?: string | null}) {\n *   assertTypes(arguments, [{displayName: opt('string|null')}]);\n * }\n *\n * @param args\n * @param expected\n */\nexport function assertTypes(\n  args: Omit<IArguments, 'callee'>,\n  ...expected: Array<TypeExpectation | Optional>\n): void {\n  if (args.length > expected.length) {\n    _fail(AuthErrorCode.ARGUMENT_ERROR, {});\n  }\n\n  for (let i = 0; i < expected.length; i++) {\n    let expect = expected[i];\n    const arg = args[i];\n\n    if (expect instanceof Optional) {\n      // If the arg is undefined, then it matches \"optional\" and we can move to\n      // the next arg\n      if (typeof arg === 'undefined') {\n        continue;\n      }\n      expect = expect.type;\n    }\n\n    if (typeof expect === 'string') {\n      // Handle the edge case for null because typeof null === 'object'\n      if (expect.includes('null') && arg === null) {\n        continue;\n      }\n\n      const required = expect.split('|');\n      _assert(required.includes(typeof arg), AuthErrorCode.ARGUMENT_ERROR, {});\n    } else if (typeof expect === 'object') {\n      // Recursively check record arguments\n      const record = arg as Record<string, unknown>;\n      const map = expect as MapType;\n      const keys = Object.keys(expect);\n\n      assertTypes(\n        keys.map(k => record[k]),\n        ...keys.map(k => map[k])\n      );\n    } else {\n      _assert(arg instanceof expect, AuthErrorCode.ARGUMENT_ERROR, {});\n    }\n  }\n}\n\n/**\n * Unconditionally fails, throwing an internal error with the given message.\n *\n * @param failure type of failure encountered\n * @throws Error\n */\nexport function debugFail(failure: string): never {\n  // Log the failure in addition to throw an exception, just in case the\n  // exception is swallowed.\n  const message = `INTERNAL ASSERTION FAILED: ` + failure;\n  _logError(message);\n\n  // NOTE: We don't use FirebaseError here because these are internal failures\n  // that cannot be handled by the user. (Also it would create a circular\n  // dependency between the error and assert modules which doesn't work.)\n  throw new Error(message);\n}\n\n/**\n * Fails if the given assertion condition is false, throwing an Error with the\n * given message if it did.\n *\n * @param assertion\n * @param message\n */\nexport function debugAssert(\n  assertion: unknown,\n  message: string\n): asserts assertion {\n  if (!assertion) {\n    debugFail(message);\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport function _getCurrentUrl(): string {\n  return (typeof self !== 'undefined' && self.location?.href) || '';\n}\n\nexport function _isHttpOrHttps(): boolean {\n  return _getCurrentScheme() === 'http:' || _getCurrentScheme() === 'https:';\n}\n\nexport function _getCurrentScheme(): string | null {\n  return (typeof self !== 'undefined' && self.location?.protocol) || null;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { isMobileCordova, isReactNative } from '@firebase/util';\nimport { _isOnline } from './navigator';\nimport { debugAssert } from './assert';\n\nexport const enum DelayMin {\n  OFFLINE = 5000\n}\n\n/**\n * A structure to help pick between a range of long and short delay durations\n * depending on the current environment. In general, the long delay is used for\n * mobile environments whereas short delays are used for desktop environments.\n */\nexport class Delay {\n  // The default value for the offline delay timeout in ms.\n\n  private readonly isMobile: boolean;\n  constructor(\n    private readonly shortDelay: number,\n    private readonly longDelay: number\n  ) {\n    // Internal error when improperly initialized.\n    debugAssert(\n      longDelay > shortDelay,\n      'Short delay should be less than long delay!'\n    );\n    this.isMobile = isMobileCordova() || isReactNative();\n  }\n\n  get(): number {\n    if (!_isOnline()) {\n      // Pick the shorter timeout.\n      return Math.min(DelayMin.OFFLINE, this.shortDelay);\n    }\n    // If running in a mobile environment, return the long delay, otherwise\n    // return the short delay.\n    // This could be improved in the future to dynamically change based on other\n    // variables instead of just reading the current environment.\n    return this.isMobile ? this.longDelay : this.shortDelay;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { isBrowserExtension } from '@firebase/util';\nimport { _isHttpOrHttps } from './location';\n\n/**\n * Determine whether the browser is working online\n */\nexport function _isOnline(): boolean {\n  if (\n    typeof navigator !== 'undefined' &&\n    navigator &&\n    'onLine' in navigator &&\n    typeof navigator.onLine === 'boolean' &&\n    // Apply only for traditional web apps and Chrome extensions.\n    // This is especially true for Cordova apps which have unreliable\n    // navigator.onLine behavior unless cordova-plugin-network-information is\n    // installed which overwrites the native navigator.onLine value and\n    // defines navigator.connection.\n    (_isHttpOrHttps() || isBrowserExtension() || 'connection' in navigator)\n  ) {\n    return navigator.onLine;\n  }\n  // If we can't determine the state, assume it is online.\n  return true;\n}\n\nexport function _getUserLanguage(): string | null {\n  if (typeof navigator === 'undefined') {\n    return null;\n  }\n  const navigatorLanguage: NavigatorLanguage = navigator;\n  return (\n    // Most reliable, but only supported in Chrome/Firefox.\n    (navigatorLanguage.languages && navigatorLanguage.languages[0]) ||\n    // Supported in most browsers, but returns the language of the browser\n    // UI, not the language set in browser settings.\n    navigatorLanguage.language ||\n    // Couldn't determine language.\n    null\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { ConfigInternal } from '../../model/auth';\nimport { debugAssert } from './assert';\n\nexport function _emulatorUrl(config: ConfigInternal, path?: string): string {\n  debugAssert(config.emulator, 'Emulator should always be set here');\n  const { url } = config.emulator;\n\n  if (!path) {\n    return url;\n  }\n\n  return `${url}${path.startsWith('/') ? path.slice(1) : path}`;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { debugFail } from './assert';\n\nexport class FetchProvider {\n  private static fetchImpl: typeof fetch | null;\n  private static headersImpl: typeof Headers | null;\n  private static responseImpl: typeof Response | null;\n\n  static initialize(\n    fetchImpl: typeof fetch,\n    headersImpl?: typeof Headers,\n    responseImpl?: typeof Response\n  ): void {\n    this.fetchImpl = fetchImpl;\n    if (headersImpl) {\n      this.headersImpl = headersImpl;\n    }\n    if (responseImpl) {\n      this.responseImpl = responseImpl;\n    }\n  }\n\n  static fetch(): typeof fetch {\n    if (this.fetchImpl) {\n      return this.fetchImpl;\n    }\n    if (typeof self !== 'undefined' && 'fetch' in self) {\n      return self.fetch;\n    }\n    if (typeof globalThis !== 'undefined' && globalThis.fetch) {\n      return globalThis.fetch;\n    }\n    if (typeof fetch !== 'undefined') {\n      return fetch;\n    }\n    debugFail(\n      'Could not find fetch implementation, make sure you call FetchProvider.initialize() with an appropriate polyfill'\n    );\n  }\n\n  static headers(): typeof Headers {\n    if (this.headersImpl) {\n      return this.headersImpl;\n    }\n    if (typeof self !== 'undefined' && 'Headers' in self) {\n      return self.Headers;\n    }\n    if (typeof globalThis !== 'undefined' && globalThis.Headers) {\n      return globalThis.Headers;\n    }\n    if (typeof Headers !== 'undefined') {\n      return Headers;\n    }\n    debugFail(\n      'Could not find Headers implementation, make sure you call FetchProvider.initialize() with an appropriate polyfill'\n    );\n  }\n\n  static response(): typeof Response {\n    if (this.responseImpl) {\n      return this.responseImpl;\n    }\n    if (typeof self !== 'undefined' && 'Response' in self) {\n      return self.Response;\n    }\n    if (typeof globalThis !== 'undefined' && globalThis.Response) {\n      return globalThis.Response;\n    }\n    if (typeof Response !== 'undefined') {\n      return Response;\n    }\n    debugFail(\n      'Could not find Response implementation, make sure you call FetchProvider.initialize() with an appropriate polyfill'\n    );\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthErrorCode } from '../core/errors';\n\n/**\n * Errors that can be returned by the backend\n */\nexport const enum ServerError {\n  ADMIN_ONLY_OPERATION = 'ADMIN_ONLY_OPERATION',\n  BLOCKING_FUNCTION_ERROR_RESPONSE = 'BLOCKING_FUNCTION_ERROR_RESPONSE',\n  CAPTCHA_CHECK_FAILED = 'CAPTCHA_CHECK_FAILED',\n  CORS_UNSUPPORTED = 'CORS_UNSUPPORTED',\n  CREDENTIAL_MISMATCH = 'CREDENTIAL_MISMATCH',\n  CREDENTIAL_TOO_OLD_LOGIN_AGAIN = 'CREDENTIAL_TOO_OLD_LOGIN_AGAIN',\n  DYNAMIC_LINK_NOT_ACTIVATED = 'DYNAMIC_LINK_NOT_ACTIVATED',\n  EMAIL_CHANGE_NEEDS_VERIFICATION = 'EMAIL_CHANGE_NEEDS_VERIFICATION',\n  EMAIL_EXISTS = 'EMAIL_EXISTS',\n  EMAIL_NOT_FOUND = 'EMAIL_NOT_FOUND',\n  EXPIRED_OOB_CODE = 'EXPIRED_OOB_CODE',\n  FEDERATED_USER_ID_ALREADY_LINKED = 'FEDERATED_USER_ID_ALREADY_LINKED',\n  INVALID_APP_CREDENTIAL = 'INVALID_APP_CREDENTIAL',\n  INVALID_APP_ID = 'INVALID_APP_ID',\n  INVALID_CERT_HASH = 'INVALID_CERT_HASH',\n  INVALID_CODE = 'INVALID_CODE',\n  INVALID_CONTINUE_URI = 'INVALID_CONTINUE_URI',\n  INVALID_CUSTOM_TOKEN = 'INVALID_CUSTOM_TOKEN',\n  INVALID_DYNAMIC_LINK_DOMAIN = 'INVALID_DYNAMIC_LINK_DOMAIN',\n  INVALID_EMAIL = 'INVALID_EMAIL',\n  INVALID_ID_TOKEN = 'INVALID_ID_TOKEN',\n  INVALID_IDP_RESPONSE = 'INVALID_IDP_RESPONSE',\n  INVALID_IDENTIFIER = 'INVALID_IDENTIFIER',\n  INVALID_LOGIN_CREDENTIALS = 'INVALID_LOGIN_CREDENTIALS',\n  INVALID_MESSAGE_PAYLOAD = 'INVALID_MESSAGE_PAYLOAD',\n  INVALID_MFA_PENDING_CREDENTIAL = 'INVALID_MFA_PENDING_CREDENTIAL',\n  INVALID_OAUTH_CLIENT_ID = 'INVALID_OAUTH_CLIENT_ID',\n  INVALID_OOB_CODE = 'INVALID_OOB_CODE',\n  INVALID_PASSWORD = 'INVALID_PASSWORD',\n  INVALID_PENDING_TOKEN = 'INVALID_PENDING_TOKEN',\n  INVALID_PHONE_NUMBER = 'INVALID_PHONE_NUMBER',\n  INVALID_PROVIDER_ID = 'INVALID_PROVIDER_ID',\n  INVALID_RECIPIENT_EMAIL = 'INVALID_RECIPIENT_EMAIL',\n  INVALID_SENDER = 'INVALID_SENDER',\n  INVALID_SESSION_INFO = 'INVALID_SESSION_INFO',\n  INVALID_TEMPORARY_PROOF = 'INVALID_TEMPORARY_PROOF',\n  INVALID_TENANT_ID = 'INVALID_TENANT_ID',\n  MFA_ENROLLMENT_NOT_FOUND = 'MFA_ENROLLMENT_NOT_FOUND',\n  MISSING_ANDROID_PACKAGE_NAME = 'MISSING_ANDROID_PACKAGE_NAME',\n  MISSING_APP_CREDENTIAL = 'MISSING_APP_CREDENTIAL',\n  MISSING_CODE = 'MISSING_CODE',\n  MISSING_CONTINUE_URI = 'MISSING_CONTINUE_URI',\n  MISSING_CUSTOM_TOKEN = 'MISSING_CUSTOM_TOKEN',\n  MISSING_IOS_BUNDLE_ID = 'MISSING_IOS_BUNDLE_ID',\n  MISSING_MFA_ENROLLMENT_ID = 'MISSING_MFA_ENROLLMENT_ID',\n  MISSING_MFA_PENDING_CREDENTIAL = 'MISSING_MFA_PENDING_CREDENTIAL',\n  MISSING_OOB_CODE = 'MISSING_OOB_CODE',\n  MISSING_OR_INVALID_NONCE = 'MISSING_OR_INVALID_NONCE',\n  MISSING_PASSWORD = 'MISSING_PASSWORD',\n  MISSING_REQ_TYPE = 'MISSING_REQ_TYPE',\n  MISSING_PHONE_NUMBER = 'MISSING_PHONE_NUMBER',\n  MISSING_SESSION_INFO = 'MISSING_SESSION_INFO',\n  OPERATION_NOT_ALLOWED = 'OPERATION_NOT_ALLOWED',\n  PASSWORD_LOGIN_DISABLED = 'PASSWORD_LOGIN_DISABLED',\n  QUOTA_EXCEEDED = 'QUOTA_EXCEEDED',\n  RESET_PASSWORD_EXCEED_LIMIT = 'RESET_PASSWORD_EXCEED_LIMIT',\n  REJECTED_CREDENTIAL = 'REJECTED_CREDENTIAL',\n  SECOND_FACTOR_EXISTS = 'SECOND_FACTOR_EXISTS',\n  SECOND_FACTOR_LIMIT_EXCEEDED = 'SECOND_FACTOR_LIMIT_EXCEEDED',\n  SESSION_EXPIRED = 'SESSION_EXPIRED',\n  TENANT_ID_MISMATCH = 'TENANT_ID_MISMATCH',\n  TOKEN_EXPIRED = 'TOKEN_EXPIRED',\n  TOO_MANY_ATTEMPTS_TRY_LATER = 'TOO_MANY_ATTEMPTS_TRY_LATER',\n  UNSUPPORTED_FIRST_FACTOR = 'UNSUPPORTED_FIRST_FACTOR',\n  UNSUPPORTED_TENANT_OPERATION = 'UNSUPPORTED_TENANT_OPERATION',\n  UNAUTHORIZED_DOMAIN = 'UNAUTHORIZED_DOMAIN',\n  UNVERIFIED_EMAIL = 'UNVERIFIED_EMAIL',\n  USER_CANCELLED = 'USER_CANCELLED',\n  USER_DISABLED = 'USER_DISABLED',\n  USER_NOT_FOUND = 'USER_NOT_FOUND',\n  WEAK_PASSWORD = 'WEAK_PASSWORD',\n  RECAPTCHA_NOT_ENABLED = 'RECAPTCHA_NOT_ENABLED',\n  MISSING_RECAPTCHA_TOKEN = 'MISSING_RECAPTCHA_TOKEN',\n  INVALID_RECAPTCHA_TOKEN = 'INVALID_RECAPTCHA_TOKEN',\n  INVALID_RECAPTCHA_ACTION = 'INVALID_RECAPTCHA_ACTION',\n  MISSING_CLIENT_TYPE = 'MISSING_CLIENT_TYPE',\n  MISSING_RECAPTCHA_VERSION = 'MISSING_RECAPTCHA_VERSION',\n  INVALID_RECAPTCHA_VERSION = 'INVALID_RECAPTCHA_VERSION',\n  INVALID_REQ_TYPE = 'INVALID_REQ_TYPE',\n  PASSWORD_DOES_NOT_MEET_REQUIREMENTS = 'PASSWORD_DOES_NOT_MEET_REQUIREMENTS',\n  INVALID_HOSTING_LINK_DOMAIN = 'INVALID_HOSTING_LINK_DOMAIN'\n}\n\n/**\n * API Response in the event of an error\n */\nexport interface JsonError {\n  error: {\n    code: number;\n    message: string;\n    errors?: [\n      {\n        message: ServerError;\n        domain: string;\n        reason: string;\n      }\n    ];\n  };\n}\n\n/**\n * Type definition for a map from server errors to developer visible errors\n */\nexport declare type ServerErrorMap<ApiError extends string> = {\n  readonly [K in ApiError]: AuthErrorCode;\n};\n\n/**\n * Map from errors returned by the server to errors to developer visible errors\n */\nexport const SERVER_ERROR_MAP: Partial<ServerErrorMap<ServerError>> = {\n  // Custom token errors.\n  [ServerError.CREDENTIAL_MISMATCH]: AuthErrorCode.CREDENTIAL_MISMATCH,\n  // This can only happen if the SDK sends a bad request.\n  [ServerError.MISSING_CUSTOM_TOKEN]: AuthErrorCode.INTERNAL_ERROR,\n\n  // Create Auth URI errors.\n  [ServerError.INVALID_IDENTIFIER]: AuthErrorCode.INVALID_EMAIL,\n  // This can only happen if the SDK sends a bad request.\n  [ServerError.MISSING_CONTINUE_URI]: AuthErrorCode.INTERNAL_ERROR,\n\n  // Sign in with email and password errors (some apply to sign up too).\n  [ServerError.INVALID_PASSWORD]: AuthErrorCode.INVALID_PASSWORD,\n  // This can only happen if the SDK sends a bad request.\n  [ServerError.MISSING_PASSWORD]: AuthErrorCode.MISSING_PASSWORD,\n  // Thrown if Email Enumeration Protection is enabled in the project and the email or password is\n  // invalid.\n  [ServerError.INVALID_LOGIN_CREDENTIALS]: AuthErrorCode.INVALID_CREDENTIAL,\n\n  // Sign up with email and password errors.\n  [ServerError.EMAIL_EXISTS]: AuthErrorCode.EMAIL_EXISTS,\n  [ServerError.PASSWORD_LOGIN_DISABLED]: AuthErrorCode.OPERATION_NOT_ALLOWED,\n\n  // Verify assertion for sign in with credential errors:\n  [ServerError.INVALID_IDP_RESPONSE]: AuthErrorCode.INVALID_CREDENTIAL,\n  [ServerError.INVALID_PENDING_TOKEN]: AuthErrorCode.INVALID_CREDENTIAL,\n  [ServerError.FEDERATED_USER_ID_ALREADY_LINKED]:\n    AuthErrorCode.CREDENTIAL_ALREADY_IN_USE,\n\n  // This can only happen if the SDK sends a bad request.\n  [ServerError.MISSING_REQ_TYPE]: AuthErrorCode.INTERNAL_ERROR,\n\n  // Send Password reset email errors:\n  [ServerError.EMAIL_NOT_FOUND]: AuthErrorCode.USER_DELETED,\n  [ServerError.RESET_PASSWORD_EXCEED_LIMIT]:\n    AuthErrorCode.TOO_MANY_ATTEMPTS_TRY_LATER,\n\n  [ServerError.EXPIRED_OOB_CODE]: AuthErrorCode.EXPIRED_OOB_CODE,\n  [ServerError.INVALID_OOB_CODE]: AuthErrorCode.INVALID_OOB_CODE,\n  // This can only happen if the SDK sends a bad request.\n  [ServerError.MISSING_OOB_CODE]: AuthErrorCode.INTERNAL_ERROR,\n\n  // Operations that require ID token in request:\n  [ServerError.CREDENTIAL_TOO_OLD_LOGIN_AGAIN]:\n    AuthErrorCode.CREDENTIAL_TOO_OLD_LOGIN_AGAIN,\n  [ServerError.INVALID_ID_TOKEN]: AuthErrorCode.INVALID_AUTH,\n  [ServerError.TOKEN_EXPIRED]: AuthErrorCode.TOKEN_EXPIRED,\n  [ServerError.USER_NOT_FOUND]: AuthErrorCode.TOKEN_EXPIRED,\n\n  // Other errors.\n  [ServerError.TOO_MANY_ATTEMPTS_TRY_LATER]:\n    AuthErrorCode.TOO_MANY_ATTEMPTS_TRY_LATER,\n  [ServerError.PASSWORD_DOES_NOT_MEET_REQUIREMENTS]:\n    AuthErrorCode.PASSWORD_DOES_NOT_MEET_REQUIREMENTS,\n\n  // Phone Auth related errors.\n  [ServerError.INVALID_CODE]: AuthErrorCode.INVALID_CODE,\n  [ServerError.INVALID_SESSION_INFO]: AuthErrorCode.INVALID_SESSION_INFO,\n  [ServerError.INVALID_TEMPORARY_PROOF]: AuthErrorCode.INVALID_CREDENTIAL,\n  [ServerError.MISSING_SESSION_INFO]: AuthErrorCode.MISSING_SESSION_INFO,\n  [ServerError.SESSION_EXPIRED]: AuthErrorCode.CODE_EXPIRED,\n\n  // Other action code errors when additional settings passed.\n  // MISSING_CONTINUE_URI is getting mapped to INTERNAL_ERROR above.\n  // This is OK as this error will be caught by client side validation.\n  [ServerError.MISSING_ANDROID_PACKAGE_NAME]:\n    AuthErrorCode.MISSING_ANDROID_PACKAGE_NAME,\n  [ServerError.UNAUTHORIZED_DOMAIN]: AuthErrorCode.UNAUTHORIZED_DOMAIN,\n\n  // getProjectConfig errors when clientId is passed.\n  [ServerError.INVALID_OAUTH_CLIENT_ID]: AuthErrorCode.INVALID_OAUTH_CLIENT_ID,\n\n  // User actions (sign-up or deletion) disabled errors.\n  [ServerError.ADMIN_ONLY_OPERATION]: AuthErrorCode.ADMIN_ONLY_OPERATION,\n\n  // Multi factor related errors.\n  [ServerError.INVALID_MFA_PENDING_CREDENTIAL]:\n    AuthErrorCode.INVALID_MFA_SESSION,\n  [ServerError.MFA_ENROLLMENT_NOT_FOUND]: AuthErrorCode.MFA_INFO_NOT_FOUND,\n  [ServerError.MISSING_MFA_ENROLLMENT_ID]: AuthErrorCode.MISSING_MFA_INFO,\n  [ServerError.MISSING_MFA_PENDING_CREDENTIAL]:\n    AuthErrorCode.MISSING_MFA_SESSION,\n  [ServerError.SECOND_FACTOR_EXISTS]:\n    AuthErrorCode.SECOND_FACTOR_ALREADY_ENROLLED,\n  [ServerError.SECOND_FACTOR_LIMIT_EXCEEDED]:\n    AuthErrorCode.SECOND_FACTOR_LIMIT_EXCEEDED,\n\n  // Blocking functions related errors.\n  [ServerError.BLOCKING_FUNCTION_ERROR_RESPONSE]: AuthErrorCode.INTERNAL_ERROR,\n\n  // Recaptcha related errors.\n  [ServerError.RECAPTCHA_NOT_ENABLED]: AuthErrorCode.RECAPTCHA_NOT_ENABLED,\n  [ServerError.MISSING_RECAPTCHA_TOKEN]: AuthErrorCode.MISSING_RECAPTCHA_TOKEN,\n  [ServerError.INVALID_RECAPTCHA_TOKEN]: AuthErrorCode.INVALID_RECAPTCHA_TOKEN,\n  [ServerError.INVALID_RECAPTCHA_ACTION]:\n    AuthErrorCode.INVALID_RECAPTCHA_ACTION,\n  [ServerError.MISSING_CLIENT_TYPE]: AuthErrorCode.MISSING_CLIENT_TYPE,\n  [ServerError.MISSING_RECAPTCHA_VERSION]:\n    AuthErrorCode.MISSING_RECAPTCHA_VERSION,\n  [ServerError.INVALID_RECAPTCHA_VERSION]:\n    AuthErrorCode.INVALID_RECAPTCHA_VERSION,\n  [ServerError.INVALID_REQ_TYPE]: AuthErrorCode.INVALID_REQ_TYPE\n};\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  FirebaseError,\n  isCloudflareWorker,\n  isCloudWorkstation,\n  querystring\n} from '@firebase/util';\n\nimport { AuthErrorCode, NamedErrorParams } from '../core/errors';\nimport {\n  _createError,\n  _errorWithCustomMessage,\n  _fail\n} from '../core/util/assert';\nimport { Delay } from '../core/util/delay';\nimport { _emulatorUrl } from '../core/util/emulator';\nimport { FetchProvider } from '../core/util/fetch_provider';\nimport { Auth } from '../model/public_types';\nimport { AuthInternal, ConfigInternal } from '../model/auth';\nimport { IdTokenResponse, TaggedWithTokenResponse } from '../model/id_token';\nimport { IdTokenMfaResponse } from './authentication/mfa';\nimport { SERVER_ERROR_MAP, ServerError, ServerErrorMap } from './errors';\nimport { PersistenceType } from '../core/persistence';\nimport { CookiePersistence } from '../platform_browser/persistence/cookie_storage';\n\nexport const enum HttpMethod {\n  POST = 'POST',\n  GET = 'GET'\n}\n\nexport const enum HttpHeader {\n  CONTENT_TYPE = 'Content-Type',\n  X_FIREBASE_LOCALE = 'X-Firebase-Locale',\n  X_CLIENT_VERSION = 'X-Client-Version',\n  X_FIREBASE_GMPID = 'X-Firebase-gmpid',\n  X_FIREBASE_CLIENT = 'X-Firebase-Client',\n  X_FIREBASE_APP_CHECK = 'X-Firebase-AppCheck'\n}\n\nexport const enum Endpoint {\n  CREATE_AUTH_URI = '/v1/accounts:createAuthUri',\n  DELETE_ACCOUNT = '/v1/accounts:delete',\n  RESET_PASSWORD = '/v1/accounts:resetPassword',\n  SIGN_UP = '/v1/accounts:signUp',\n  SIGN_IN_WITH_CUSTOM_TOKEN = '/v1/accounts:signInWithCustomToken',\n  SIGN_IN_WITH_EMAIL_LINK = '/v1/accounts:signInWithEmailLink',\n  SIGN_IN_WITH_IDP = '/v1/accounts:signInWithIdp',\n  SIGN_IN_WITH_PASSWORD = '/v1/accounts:signInWithPassword',\n  SIGN_IN_WITH_PHONE_NUMBER = '/v1/accounts:signInWithPhoneNumber',\n  SEND_VERIFICATION_CODE = '/v1/accounts:sendVerificationCode',\n  SEND_OOB_CODE = '/v1/accounts:sendOobCode',\n  SET_ACCOUNT_INFO = '/v1/accounts:update',\n  GET_ACCOUNT_INFO = '/v1/accounts:lookup',\n  GET_RECAPTCHA_PARAM = '/v1/recaptchaParams',\n  START_MFA_ENROLLMENT = '/v2/accounts/mfaEnrollment:start',\n  FINALIZE_MFA_ENROLLMENT = '/v2/accounts/mfaEnrollment:finalize',\n  START_MFA_SIGN_IN = '/v2/accounts/mfaSignIn:start',\n  FINALIZE_MFA_SIGN_IN = '/v2/accounts/mfaSignIn:finalize',\n  WITHDRAW_MFA = '/v2/accounts/mfaEnrollment:withdraw',\n  GET_PROJECT_CONFIG = '/v1/projects',\n  GET_RECAPTCHA_CONFIG = '/v2/recaptchaConfig',\n  GET_PASSWORD_POLICY = '/v2/passwordPolicy',\n  TOKEN = '/v1/token',\n  REVOKE_TOKEN = '/v2/accounts:revokeToken'\n}\n\nconst CookieAuthProxiedEndpoints: string[] = [\n  Endpoint.SIGN_IN_WITH_CUSTOM_TOKEN,\n  Endpoint.SIGN_IN_WITH_EMAIL_LINK,\n  Endpoint.SIGN_IN_WITH_IDP,\n  Endpoint.SIGN_IN_WITH_PASSWORD,\n  Endpoint.SIGN_IN_WITH_PHONE_NUMBER,\n  Endpoint.TOKEN\n];\n\nexport const enum RecaptchaClientType {\n  WEB = 'CLIENT_TYPE_WEB',\n  ANDROID = 'CLIENT_TYPE_ANDROID',\n  IOS = 'CLIENT_TYPE_IOS'\n}\n\nexport const enum RecaptchaVersion {\n  ENTERPRISE = 'RECAPTCHA_ENTERPRISE'\n}\n\nexport const enum RecaptchaActionName {\n  SIGN_IN_WITH_PASSWORD = 'signInWithPassword',\n  GET_OOB_CODE = 'getOobCode',\n  SIGN_UP_PASSWORD = 'signUpPassword',\n  SEND_VERIFICATION_CODE = 'sendVerificationCode',\n  MFA_SMS_ENROLLMENT = 'mfaSmsEnrollment',\n  MFA_SMS_SIGNIN = 'mfaSmsSignIn'\n}\n\nexport const enum EnforcementState {\n  ENFORCE = 'ENFORCE',\n  AUDIT = 'AUDIT',\n  OFF = 'OFF',\n  ENFORCEMENT_STATE_UNSPECIFIED = 'ENFORCEMENT_STATE_UNSPECIFIED'\n}\n\n// Providers that have reCAPTCHA Enterprise support.\nexport const enum RecaptchaAuthProvider {\n  EMAIL_PASSWORD_PROVIDER = 'EMAIL_PASSWORD_PROVIDER',\n  PHONE_PROVIDER = 'PHONE_PROVIDER'\n}\n\nexport const DEFAULT_API_TIMEOUT_MS = new Delay(30_000, 60_000);\n\nexport function _addTidIfNecessary<T extends { tenantId?: string }>(\n  auth: Auth,\n  request: T\n): T {\n  if (auth.tenantId && !request.tenantId) {\n    return {\n      ...request,\n      tenantId: auth.tenantId\n    };\n  }\n  return request;\n}\n\nexport async function _performApiRequest<T, V>(\n  auth: Auth,\n  method: HttpMethod,\n  path: Endpoint,\n  request?: T,\n  customErrorMap: Partial<ServerErrorMap<ServerError>> = {}\n): Promise<V> {\n  return _performFetchWithErrorHandling(auth, customErrorMap, async () => {\n    let body = {};\n    let params = {};\n    if (request) {\n      if (method === HttpMethod.GET) {\n        params = request;\n      } else {\n        body = {\n          body: JSON.stringify(request)\n        };\n      }\n    }\n\n    const query = querystring({\n      key: auth.config.apiKey,\n      ...params\n    }).slice(1);\n\n    const headers = await (auth as AuthInternal)._getAdditionalHeaders();\n    headers[HttpHeader.CONTENT_TYPE] = 'application/json';\n\n    if (auth.languageCode) {\n      headers[HttpHeader.X_FIREBASE_LOCALE] = auth.languageCode;\n    }\n\n    const fetchArgs: RequestInit = {\n      method,\n      headers,\n      ...body\n    };\n\n    /* Security-conscious server-side frameworks tend to have built in mitigations for referrer\n       problems\". See the Cloudflare GitHub issue #487: Error: The 'referrerPolicy' field on\n       'RequestInitializerDict' is not implemented.\"\n       https://github.com/cloudflare/next-on-pages/issues/487 */\n    if (!isCloudflareWorker()) {\n      fetchArgs.referrerPolicy = 'no-referrer';\n    }\n\n    if (auth.emulatorConfig && isCloudWorkstation(auth.emulatorConfig.host)) {\n      fetchArgs.credentials = 'include';\n    }\n\n    return FetchProvider.fetch()(\n      await _getFinalTarget(auth, auth.config.apiHost, path, query),\n      fetchArgs\n    );\n  });\n}\n\nexport async function _performFetchWithErrorHandling<V>(\n  auth: Auth,\n  customErrorMap: Partial<ServerErrorMap<ServerError>>,\n  fetchFn: () => Promise<Response>\n): Promise<V> {\n  (auth as AuthInternal)._canInitEmulator = false;\n  const errorMap = { ...SERVER_ERROR_MAP, ...customErrorMap };\n  try {\n    const networkTimeout = new NetworkTimeout<Response>(auth);\n    const response: Response = await Promise.race<Promise<Response>>([\n      fetchFn(),\n      networkTimeout.promise\n    ]);\n\n    // If we've reached this point, the fetch succeeded and the networkTimeout\n    // didn't throw; clear the network timeout delay so that Node won't hang\n    networkTimeout.clearNetworkTimeout();\n\n    const json = await response.json();\n    if ('needConfirmation' in json) {\n      throw _makeTaggedError(auth, AuthErrorCode.NEED_CONFIRMATION, json);\n    }\n\n    if (response.ok && !('errorMessage' in json)) {\n      return json;\n    } else {\n      const errorMessage = response.ok ? json.errorMessage : json.error.message;\n      const [serverErrorCode, serverErrorMessage] = errorMessage.split(' : ');\n      if (serverErrorCode === ServerError.FEDERATED_USER_ID_ALREADY_LINKED) {\n        throw _makeTaggedError(\n          auth,\n          AuthErrorCode.CREDENTIAL_ALREADY_IN_USE,\n          json\n        );\n      } else if (serverErrorCode === ServerError.EMAIL_EXISTS) {\n        throw _makeTaggedError(auth, AuthErrorCode.EMAIL_EXISTS, json);\n      } else if (serverErrorCode === ServerError.USER_DISABLED) {\n        throw _makeTaggedError(auth, AuthErrorCode.USER_DISABLED, json);\n      }\n      const authError =\n        errorMap[serverErrorCode as ServerError] ||\n        (serverErrorCode\n          .toLowerCase()\n          .replace(/[_\\s]+/g, '-') as unknown as AuthErrorCode);\n      if (serverErrorMessage) {\n        throw _errorWithCustomMessage(auth, authError, serverErrorMessage);\n      } else {\n        _fail(auth, authError);\n      }\n    }\n  } catch (e) {\n    if (e instanceof FirebaseError) {\n      throw e;\n    }\n    // Changing this to a different error code will log user out when there is a network error\n    // because we treat any error other than NETWORK_REQUEST_FAILED as token is invalid.\n    // https://github.com/firebase/firebase-js-sdk/blob/4fbc73610d70be4e0852e7de63a39cb7897e8546/packages/auth/src/core/auth/auth_impl.ts#L309-L316\n    _fail(auth, AuthErrorCode.NETWORK_REQUEST_FAILED, { 'message': String(e) });\n  }\n}\n\nexport async function _performSignInRequest<T, V extends IdTokenResponse>(\n  auth: Auth,\n  method: HttpMethod,\n  path: Endpoint,\n  request?: T,\n  customErrorMap: Partial<ServerErrorMap<ServerError>> = {}\n): Promise<V> {\n  const serverResponse = await _performApiRequest<T, V | IdTokenMfaResponse>(\n    auth,\n    method,\n    path,\n    request,\n    customErrorMap\n  );\n  if ('mfaPendingCredential' in serverResponse) {\n    _fail(auth, AuthErrorCode.MFA_REQUIRED, {\n      _serverResponse: serverResponse\n    });\n  }\n\n  return serverResponse as V;\n}\n\nexport async function _getFinalTarget(\n  auth: Auth,\n  host: string,\n  path: string,\n  query: string\n): Promise<string> {\n  const base = `${host}${path}?${query}`;\n\n  const authInternal = auth as AuthInternal;\n  const finalTarget = authInternal.config.emulator\n    ? _emulatorUrl(auth.config as ConfigInternal, base)\n    : `${auth.config.apiScheme}://${base}`;\n\n  // Cookie auth works by MiTMing the signIn and token endpoints from the developer's backend,\n  // saving the idToken and refreshToken into cookies, and then redacting the refreshToken\n  // from the response\n  if (CookieAuthProxiedEndpoints.includes(path)) {\n    // Persistence manager is async, we need to await it. We can't just wait for auth initialized\n    // here since auth initialization calls this function.\n    await authInternal._persistenceManagerAvailable;\n    if (authInternal._getPersistenceType() === PersistenceType.COOKIE) {\n      const cookiePersistence =\n        authInternal._getPersistence() as CookiePersistence;\n      return cookiePersistence._getFinalTarget(finalTarget).toString();\n    }\n  }\n\n  return finalTarget;\n}\n\nexport function _parseEnforcementState(\n  enforcementStateStr: string\n): EnforcementState {\n  switch (enforcementStateStr) {\n    case 'ENFORCE':\n      return EnforcementState.ENFORCE;\n    case 'AUDIT':\n      return EnforcementState.AUDIT;\n    case 'OFF':\n      return EnforcementState.OFF;\n    default:\n      return EnforcementState.ENFORCEMENT_STATE_UNSPECIFIED;\n  }\n}\n\nclass NetworkTimeout<T> {\n  // Node timers and browser timers are fundamentally incompatible, but we\n  // don't care about the value here\n  // eslint-disable-next-line @typescript-eslint/no-explicit-any\n  private timer: any | null = null;\n  readonly promise = new Promise<T>((_, reject) => {\n    this.timer = setTimeout(() => {\n      return reject(\n        _createError(this.auth, AuthErrorCode.NETWORK_REQUEST_FAILED)\n      );\n    }, DEFAULT_API_TIMEOUT_MS.get());\n  });\n\n  clearNetworkTimeout(): void {\n    clearTimeout(this.timer);\n  }\n\n  constructor(private readonly auth: Auth) {}\n}\n\ninterface PotentialResponse extends IdTokenResponse {\n  email?: string;\n  phoneNumber?: string;\n}\n\nexport function _makeTaggedError(\n  auth: Auth,\n  code: AuthErrorCode,\n  response: PotentialResponse\n): FirebaseError {\n  const errorParams: NamedErrorParams = {\n    appName: auth.name\n  };\n\n  if (response.email) {\n    errorParams.email = response.email;\n  }\n  if (response.phoneNumber) {\n    errorParams.phoneNumber = response.phoneNumber;\n  }\n\n  const error = _createError(auth, code, errorParams);\n\n  // We know customData is defined on error because errorParams is defined\n  (error.customData! as TaggedWithTokenResponse)._tokenResponse = response;\n  return error;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { RecaptchaParameters } from '../../model/public_types';\nimport {\n  GetRecaptchaConfigResponse,\n  RecaptchaEnforcementProviderState\n} from '../../api/authentication/recaptcha';\nimport {\n  EnforcementState,\n  RecaptchaAuthProvider,\n  _parseEnforcementState\n} from '../../api/index';\n\n// reCAPTCHA v2 interface\nexport interface Recaptcha {\n  render: (container: HTMLElement, parameters: RecaptchaParameters) => number;\n  getResponse: (id: number) => string;\n  execute: (id: number) => unknown;\n  reset: (id: number) => unknown;\n}\n\nexport function isV2(\n  grecaptcha: Recaptcha | GreCAPTCHA | undefined\n): grecaptcha is Recaptcha {\n  return (\n    grecaptcha !== undefined &&\n    (grecaptcha as Recaptcha).getResponse !== undefined\n  );\n}\n\n// reCAPTCHA Enterprise & v3 shared interface\nexport interface GreCAPTCHATopLevel extends GreCAPTCHA {\n  enterprise: GreCAPTCHA;\n}\n\n// reCAPTCHA Enterprise interface\nexport interface GreCAPTCHA {\n  ready: (callback: () => void) => void;\n  execute: (siteKey: string, options: { action: string }) => Promise<string>;\n  render: (\n    container: string | HTMLElement,\n    parameters: GreCAPTCHARenderOption\n  ) => string;\n}\n\nexport interface GreCAPTCHARenderOption {\n  sitekey: string;\n  size: 'invisible';\n}\n\nexport function isEnterprise(\n  grecaptcha: Recaptcha | GreCAPTCHA | undefined\n): grecaptcha is GreCAPTCHATopLevel {\n  return (\n    grecaptcha !== undefined &&\n    (grecaptcha as GreCAPTCHATopLevel).enterprise !== undefined\n  );\n}\n\n// TODO(chuanr): Replace this with the AuthWindow after resolving the dependency issue in Node.js env.\ndeclare global {\n  interface Window {\n    grecaptcha?: Recaptcha | GreCAPTCHATopLevel;\n  }\n}\n\nexport class RecaptchaConfig {\n  /**\n   * The reCAPTCHA site key.\n   */\n  siteKey: string = '';\n\n  /**\n   * The list of providers and their enablement status for reCAPTCHA Enterprise.\n   */\n  recaptchaEnforcementState: RecaptchaEnforcementProviderState[] = [];\n\n  constructor(response: GetRecaptchaConfigResponse) {\n    if (response.recaptchaKey === undefined) {\n      throw new Error('recaptchaKey undefined');\n    }\n    // Example response.recaptchaKey: \"projects/proj123/keys/sitekey123\"\n    this.siteKey = response.recaptchaKey.split('/')[3];\n    this.recaptchaEnforcementState = response.recaptchaEnforcementState;\n  }\n\n  /**\n   * Returns the reCAPTCHA Enterprise enforcement state for the given provider.\n   *\n   * @param providerStr - The provider whose enforcement state is to be returned.\n   * @returns The reCAPTCHA Enterprise enforcement state for the given provider.\n   */\n  getProviderEnforcementState(providerStr: string): EnforcementState | null {\n    if (\n      !this.recaptchaEnforcementState ||\n      this.recaptchaEnforcementState.length === 0\n    ) {\n      return null;\n    }\n\n    for (const recaptchaEnforcementState of this.recaptchaEnforcementState) {\n      if (\n        recaptchaEnforcementState.provider &&\n        recaptchaEnforcementState.provider === providerStr\n      ) {\n        return _parseEnforcementState(\n          recaptchaEnforcementState.enforcementState\n        );\n      }\n    }\n    return null;\n  }\n\n  /**\n   * Returns true if the reCAPTCHA Enterprise enforcement state for the provider is set to ENFORCE or AUDIT.\n   *\n   * @param providerStr - The provider whose enablement state is to be returned.\n   * @returns Whether or not reCAPTCHA Enterprise protection is enabled for the given provider.\n   */\n  isProviderEnabled(providerStr: string): boolean {\n    return (\n      this.getProviderEnforcementState(providerStr) ===\n        EnforcementState.ENFORCE ||\n      this.getProviderEnforcementState(providerStr) === EnforcementState.AUDIT\n    );\n  }\n\n  /**\n   * Returns true if reCAPTCHA Enterprise protection is enabled in at least one provider, otherwise\n   * returns false.\n   *\n   * @returns Whether or not reCAPTCHA Enterprise protection is enabled for at least one provider.\n   */\n  isAnyProviderEnabled(): boolean {\n    return (\n      this.isProviderEnabled(RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER) ||\n      this.isProviderEnabled(RecaptchaAuthProvider.PHONE_PROVIDER)\n    );\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Endpoint,\n  HttpMethod,\n  RecaptchaClientType,\n  RecaptchaVersion,\n  _performApiRequest,\n  _addTidIfNecessary\n} from '../index';\nimport { Auth } from '../../model/public_types';\n\ninterface GetRecaptchaParamResponse {\n  recaptchaSiteKey?: string;\n}\n\nexport async function getRecaptchaParams(auth: Auth): Promise<string> {\n  return (\n    (\n      await _performApiRequest<void, GetRecaptchaParamResponse>(\n        auth,\n        HttpMethod.GET,\n        Endpoint.GET_RECAPTCHA_PARAM\n      )\n    ).recaptchaSiteKey || ''\n  );\n}\n\n// The following functions are for reCAPTCHA enterprise integration.\ninterface GetRecaptchaConfigRequest {\n  tenantId?: string;\n  clientType?: RecaptchaClientType;\n  version?: RecaptchaVersion;\n}\n\nexport interface RecaptchaEnforcementProviderState {\n  provider: string;\n  enforcementState: string;\n}\n\nexport interface GetRecaptchaConfigResponse {\n  recaptchaKey: string;\n  recaptchaEnforcementState: RecaptchaEnforcementProviderState[];\n}\n\nexport async function getRecaptchaConfig(\n  auth: Auth,\n  request: GetRecaptchaConfigRequest\n): Promise<GetRecaptchaConfigResponse> {\n  return _performApiRequest<\n    GetRecaptchaConfigRequest,\n    GetRecaptchaConfigResponse\n  >(\n    auth,\n    HttpMethod.GET,\n    Endpoint.GET_RECAPTCHA_CONFIG,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Endpoint, HttpMethod, _performApiRequest } from '../index';\nimport { MfaEnrollment } from './mfa';\nimport { Auth } from '../../model/public_types';\n\nexport interface DeleteAccountRequest {\n  idToken: string;\n}\n\nexport async function deleteAccount(\n  auth: Auth,\n  request: DeleteAccountRequest\n): Promise<void> {\n  return _performApiRequest<DeleteAccountRequest, void>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.DELETE_ACCOUNT,\n    request\n  );\n}\n\nexport interface ProviderUserInfo {\n  providerId: string;\n  rawId?: string;\n  email?: string;\n  displayName?: string;\n  photoUrl?: string;\n  phoneNumber?: string;\n}\n\nexport interface DeleteLinkedAccountsRequest {\n  idToken: string;\n  deleteProvider: string[];\n}\n\nexport interface DeleteLinkedAccountsResponse {\n  providerUserInfo: ProviderUserInfo[];\n}\n\nexport async function deleteLinkedAccounts(\n  auth: Auth,\n  request: DeleteLinkedAccountsRequest\n): Promise<DeleteLinkedAccountsResponse> {\n  return _performApiRequest<\n    DeleteLinkedAccountsRequest,\n    DeleteLinkedAccountsResponse\n  >(auth, HttpMethod.POST, Endpoint.SET_ACCOUNT_INFO, request);\n}\n\nexport interface APIUserInfo {\n  localId?: string;\n  displayName?: string;\n  photoUrl?: string;\n  email?: string;\n  emailVerified?: boolean;\n  phoneNumber?: string;\n  lastLoginAt?: number;\n  createdAt?: number;\n  tenantId?: string;\n  passwordHash?: string;\n  providerUserInfo?: ProviderUserInfo[];\n  mfaInfo?: MfaEnrollment[];\n}\n\nexport interface GetAccountInfoRequest {\n  idToken: string;\n}\n\nexport interface GetAccountInfoResponse {\n  users: APIUserInfo[];\n}\n\nexport async function getAccountInfo(\n  auth: Auth,\n  request: GetAccountInfoRequest\n): Promise<GetAccountInfoResponse> {\n  return _performApiRequest<GetAccountInfoRequest, GetAccountInfoResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.GET_ACCOUNT_INFO,\n    request\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport function utcTimestampToDateString(\n  utcTimestamp?: string | number\n): string | undefined {\n  if (!utcTimestamp) {\n    return undefined;\n  }\n  try {\n    // Convert to date object.\n    const date = new Date(Number(utcTimestamp));\n    // Test date is valid.\n    if (!isNaN(date.getTime())) {\n      // Convert to UTC date string.\n      return date.toUTCString();\n    }\n  } catch (e) {\n    // Do nothing. undefined will be returned.\n  }\n  return undefined;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { IdTokenResult, ParsedToken, User } from '../../model/public_types';\nimport { base64Decode, getModularInstance } from '@firebase/util';\n\nimport { UserInternal } from '../../model/user';\nimport { _assert } from '../util/assert';\nimport { _logError } from '../util/log';\nimport { utcTimestampToDateString } from '../util/time';\nimport { AuthErrorCode } from '../errors';\n\n/**\n * Returns a JSON Web Token (JWT) used to identify the user to a Firebase service.\n *\n * @remarks\n * Returns the current token if it has not expired or if it will not expire in the next five\n * minutes. Otherwise, this will refresh the token and return a new one.\n *\n * @param user - The user.\n * @param forceRefresh - Force refresh regardless of token expiration.\n *\n * @public\n */\nexport function getIdToken(user: User, forceRefresh = false): Promise<string> {\n  return getModularInstance(user).getIdToken(forceRefresh);\n}\n\n/**\n * Returns a deserialized JSON Web Token (JWT) used to identify the user to a Firebase service.\n *\n * @remarks\n * Returns the current token if it has not expired or if it will not expire in the next five\n * minutes. Otherwise, this will refresh the token and return a new one.\n *\n * @param user - The user.\n * @param forceRefresh - Force refresh regardless of token expiration.\n *\n * @public\n */\nexport async function getIdTokenResult(\n  user: User,\n  forceRefresh = false\n): Promise<IdTokenResult> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  const token = await userInternal.getIdToken(forceRefresh);\n  const claims = _parseToken(token);\n\n  _assert(\n    claims && claims.exp && claims.auth_time && claims.iat,\n    userInternal.auth,\n    AuthErrorCode.INTERNAL_ERROR\n  );\n  const firebase =\n    typeof claims.firebase === 'object' ? claims.firebase : undefined;\n\n  const signInProvider: string | undefined = firebase?.['sign_in_provider'];\n\n  return {\n    claims,\n    token,\n    authTime: utcTimestampToDateString(\n      secondsStringToMilliseconds(claims.auth_time)\n    )!,\n    issuedAtTime: utcTimestampToDateString(\n      secondsStringToMilliseconds(claims.iat)\n    )!,\n    expirationTime: utcTimestampToDateString(\n      secondsStringToMilliseconds(claims.exp)\n    )!,\n    signInProvider: signInProvider || null,\n    signInSecondFactor: firebase?.['sign_in_second_factor'] || null\n  };\n}\n\nfunction secondsStringToMilliseconds(seconds: string): number {\n  return Number(seconds) * 1000;\n}\n\nexport function _parseToken(token: string): ParsedToken | null {\n  const [algorithm, payload, signature] = token.split('.');\n  if (\n    algorithm === undefined ||\n    payload === undefined ||\n    signature === undefined\n  ) {\n    _logError('JWT malformed, contained fewer than 3 sections');\n    return null;\n  }\n\n  try {\n    const decoded = base64Decode(payload);\n    if (!decoded) {\n      _logError('Failed to decode base64 JWT payload');\n      return null;\n    }\n    return JSON.parse(decoded);\n  } catch (e) {\n    _logError(\n      'Caught error parsing JWT payload as JSON',\n      (e as Error)?.toString()\n    );\n    return null;\n  }\n}\n\n/**\n * Extract expiresIn TTL from a token by subtracting the expiration from the issuance.\n */\nexport function _tokenExpiresIn(token: string): number {\n  const parsedToken = _parseToken(token);\n  _assert(parsedToken, AuthErrorCode.INTERNAL_ERROR);\n  _assert(typeof parsedToken.exp !== 'undefined', AuthErrorCode.INTERNAL_ERROR);\n  _assert(typeof parsedToken.iat !== 'undefined', AuthErrorCode.INTERNAL_ERROR);\n  return Number(parsedToken.exp) - Number(parsedToken.iat);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FirebaseError } from '@firebase/util';\n\nimport { UserInternal } from '../../model/user';\nimport { AuthErrorCode } from '../errors';\n\nexport async function _logoutIfInvalidated<T>(\n  user: UserInternal,\n  promise: Promise<T>,\n  bypassAuthState = false\n): Promise<T> {\n  if (bypassAuthState) {\n    return promise;\n  }\n  try {\n    return await promise;\n  } catch (e) {\n    if (e instanceof FirebaseError && isUserInvalidated(e)) {\n      if (user.auth.currentUser === user) {\n        await user.auth.signOut();\n      }\n    }\n\n    throw e;\n  }\n}\n\nfunction isUserInvalidated({ code }: FirebaseError): boolean {\n  return (\n    code === `auth/${AuthErrorCode.USER_DISABLED}` ||\n    code === `auth/${AuthErrorCode.TOKEN_EXPIRED}`\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FirebaseError } from '@firebase/util';\nimport { UserInternal } from '../../model/user';\nimport { AuthErrorCode } from '../errors';\n\n// Refresh the token five minutes before expiration\nexport const enum Duration {\n  OFFSET = 5 * 1000 * 60,\n  RETRY_BACKOFF_MIN = 30 * 1000,\n  RETRY_BACKOFF_MAX = 16 * 60 * 1000\n}\n\nexport class ProactiveRefresh {\n  private isRunning = false;\n\n  // Node timers and browser timers return fundamentally different types.\n  // We don't actually care what the value is but TS won't accept unknown and\n  // we can't cast properly in both environments.\n  // eslint-disable-next-line @typescript-eslint/no-explicit-any\n  private timerId: any | null = null;\n  private errorBackoff = Duration.RETRY_BACKOFF_MIN;\n\n  constructor(private readonly user: UserInternal) {}\n\n  _start(): void {\n    if (this.isRunning) {\n      return;\n    }\n\n    this.isRunning = true;\n    this.schedule();\n  }\n\n  _stop(): void {\n    if (!this.isRunning) {\n      return;\n    }\n\n    this.isRunning = false;\n    if (this.timerId !== null) {\n      clearTimeout(this.timerId);\n    }\n  }\n\n  private getInterval(wasError: boolean): number {\n    if (wasError) {\n      const interval = this.errorBackoff;\n      this.errorBackoff = Math.min(\n        this.errorBackoff * 2,\n        Duration.RETRY_BACKOFF_MAX\n      );\n      return interval;\n    } else {\n      // Reset the error backoff\n      this.errorBackoff = Duration.RETRY_BACKOFF_MIN;\n      const expTime = this.user.stsTokenManager.expirationTime ?? 0;\n      const interval = expTime - Date.now() - Duration.OFFSET;\n\n      return Math.max(0, interval);\n    }\n  }\n\n  private schedule(wasError = false): void {\n    if (!this.isRunning) {\n      // Just in case...\n      return;\n    }\n\n    const interval = this.getInterval(wasError);\n    this.timerId = setTimeout(async () => {\n      await this.iteration();\n    }, interval);\n  }\n\n  private async iteration(): Promise<void> {\n    try {\n      await this.user.getIdToken(true);\n    } catch (e) {\n      // Only retry on network errors\n      if (\n        (e as FirebaseError)?.code ===\n        `auth/${AuthErrorCode.NETWORK_REQUEST_FAILED}`\n      ) {\n        this.schedule(/* wasError */ true);\n      }\n\n      return;\n    }\n    this.schedule();\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { UserMetadata as UserMetadataType } from '../../model/public_types';\n\nimport { utcTimestampToDateString } from '../util/time';\n\nexport class UserMetadata implements UserMetadataType {\n  creationTime?: string;\n  lastSignInTime?: string;\n\n  constructor(\n    private createdAt?: string | number,\n    private lastLoginAt?: string | number\n  ) {\n    this._initializeTime();\n  }\n\n  private _initializeTime(): void {\n    this.lastSignInTime = utcTimestampToDateString(this.lastLoginAt);\n    this.creationTime = utcTimestampToDateString(this.createdAt);\n  }\n\n  _copy(metadata: UserMetadata): void {\n    this.createdAt = metadata.createdAt;\n    this.lastLoginAt = metadata.lastLoginAt;\n    this._initializeTime();\n  }\n\n  toJSON(): object {\n    return {\n      createdAt: this.createdAt,\n      lastLoginAt: this.lastLoginAt\n    };\n  }\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { User, UserInfo } from '../../model/public_types';\n\nimport {\n  getAccountInfo,\n  ProviderUserInfo\n} from '../../api/account_management/account';\nimport { UserInternal } from '../../model/user';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\nimport { _logoutIfInvalidated } from './invalidation';\nimport { UserMetadata } from './user_metadata';\nimport { getModularInstance } from '@firebase/util';\n\nexport async function _reloadWithoutSaving(user: UserInternal): Promise<void> {\n  const auth = user.auth;\n  const idToken = await user.getIdToken();\n  const response = await _logoutIfInvalidated(\n    user,\n    getAccountInfo(auth, { idToken })\n  );\n\n  _assert(response?.users.length, auth, AuthErrorCode.INTERNAL_ERROR);\n\n  const coreAccount = response.users[0];\n\n  user._notifyReloadListener(coreAccount);\n\n  const newProviderData = coreAccount.providerUserInfo?.length\n    ? extractProviderData(coreAccount.providerUserInfo)\n    : [];\n\n  const providerData = mergeProviderData(user.providerData, newProviderData);\n\n  // Preserves the non-nonymous status of the stored user, even if no more\n  // credentials (federated or email/password) are linked to the user. If\n  // the user was previously anonymous, then use provider data to update.\n  // On the other hand, if it was not anonymous before, it should never be\n  // considered anonymous now.\n  const oldIsAnonymous = user.isAnonymous;\n  const newIsAnonymous =\n    !(user.email && coreAccount.passwordHash) && !providerData?.length;\n  const isAnonymous = !oldIsAnonymous ? false : newIsAnonymous;\n\n  const updates: Partial<UserInternal> = {\n    uid: coreAccount.localId,\n    displayName: coreAccount.displayName || null,\n    photoURL: coreAccount.photoUrl || null,\n    email: coreAccount.email || null,\n    emailVerified: coreAccount.emailVerified || false,\n    phoneNumber: coreAccount.phoneNumber || null,\n    tenantId: coreAccount.tenantId || null,\n    providerData,\n    metadata: new UserMetadata(coreAccount.createdAt, coreAccount.lastLoginAt),\n    isAnonymous\n  };\n\n  Object.assign(user, updates);\n}\n\n/**\n * Reloads user account data, if signed in.\n *\n * @param user - The user.\n *\n * @public\n */\nexport async function reload(user: User): Promise<void> {\n  const userInternal: UserInternal = getModularInstance(user) as UserInternal;\n  await _reloadWithoutSaving(userInternal);\n\n  // Even though the current user hasn't changed, update\n  // current user will trigger a persistence update w/ the\n  // new info.\n  await userInternal.auth._persistUserIfCurrent(userInternal);\n  userInternal.auth._notifyListenersIfCurrent(userInternal);\n}\n\nfunction mergeProviderData(\n  original: UserInfo[],\n  newData: UserInfo[]\n): UserInfo[] {\n  const deduped = original.filter(\n    o => !newData.some(n => n.providerId === o.providerId)\n  );\n  return [...deduped, ...newData];\n}\n\nexport function extractProviderData(providers: ProviderUserInfo[]): UserInfo[] {\n  return providers.map(({ providerId, ...provider }) => {\n    return {\n      providerId,\n      uid: provider.rawId || '',\n      displayName: provider.displayName || null,\n      email: provider.email || null,\n      phoneNumber: provider.phoneNumber || null,\n      photoURL: provider.photoUrl || null\n    };\n  });\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FinalizeMfaResponse } from '../../api/authentication/mfa';\nimport { requestStsToken } from '../../api/authentication/token';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { AuthErrorCode } from '../errors';\nimport { PersistedBlob } from '../persistence';\nimport { _assert, debugFail } from '../util/assert';\nimport { _tokenExpiresIn } from './id_token_result';\n\n/**\n * The number of milliseconds before the official expiration time of a token\n * to refresh that token, to provide a buffer for RPCs to complete.\n */\nexport const enum Buffer {\n  TOKEN_REFRESH = 30_000\n}\n\n/**\n * We need to mark this class as internal explicitly to exclude it in the public typings, because\n * it references AuthInternal which has a circular dependency with UserInternal.\n *\n * @internal\n */\nexport class StsTokenManager {\n  refreshToken: string | null = null;\n  accessToken: string | null = null;\n  expirationTime: number | null = null;\n\n  get isExpired(): boolean {\n    return (\n      !this.expirationTime ||\n      Date.now() > this.expirationTime - Buffer.TOKEN_REFRESH\n    );\n  }\n\n  updateFromServerResponse(\n    response: IdTokenResponse | FinalizeMfaResponse\n  ): void {\n    _assert(response.idToken, AuthErrorCode.INTERNAL_ERROR);\n    _assert(\n      typeof response.idToken !== 'undefined',\n      AuthErrorCode.INTERNAL_ERROR\n    );\n    _assert(\n      typeof response.refreshToken !== 'undefined',\n      AuthErrorCode.INTERNAL_ERROR\n    );\n    const expiresIn =\n      'expiresIn' in response && typeof response.expiresIn !== 'undefined'\n        ? Number(response.expiresIn)\n        : _tokenExpiresIn(response.idToken);\n    this.updateTokensAndExpiration(\n      response.idToken,\n      response.refreshToken,\n      expiresIn\n    );\n  }\n\n  updateFromIdToken(idToken: string): void {\n    _assert(idToken.length !== 0, AuthErrorCode.INTERNAL_ERROR);\n    const expiresIn = _tokenExpiresIn(idToken);\n    this.updateTokensAndExpiration(idToken, null, expiresIn);\n  }\n\n  async getToken(\n    auth: AuthInternal,\n    forceRefresh = false\n  ): Promise<string | null> {\n    if (!forceRefresh && this.accessToken && !this.isExpired) {\n      return this.accessToken;\n    }\n\n    _assert(this.refreshToken, auth, AuthErrorCode.TOKEN_EXPIRED);\n\n    if (this.refreshToken) {\n      await this.refresh(auth, this.refreshToken!);\n      return this.accessToken;\n    }\n\n    return null;\n  }\n\n  clearRefreshToken(): void {\n    this.refreshToken = null;\n  }\n\n  private async refresh(auth: AuthInternal, oldToken: string): Promise<void> {\n    const { accessToken, refreshToken, expiresIn } = await requestStsToken(\n      auth,\n      oldToken\n    );\n    this.updateTokensAndExpiration(\n      accessToken,\n      refreshToken,\n      Number(expiresIn)\n    );\n  }\n\n  private updateTokensAndExpiration(\n    accessToken: string,\n    refreshToken: string | null,\n    expiresInSec: number\n  ): void {\n    this.refreshToken = refreshToken || null;\n    this.accessToken = accessToken || null;\n    this.expirationTime = Date.now() + expiresInSec * 1000;\n  }\n\n  static fromJSON(appName: string, object: PersistedBlob): StsTokenManager {\n    const { refreshToken, accessToken, expirationTime } = object;\n\n    const manager = new StsTokenManager();\n    if (refreshToken) {\n      _assert(typeof refreshToken === 'string', AuthErrorCode.INTERNAL_ERROR, {\n        appName\n      });\n      manager.refreshToken = refreshToken;\n    }\n    if (accessToken) {\n      _assert(typeof accessToken === 'string', AuthErrorCode.INTERNAL_ERROR, {\n        appName\n      });\n      manager.accessToken = accessToken;\n    }\n    if (expirationTime) {\n      _assert(\n        typeof expirationTime === 'number',\n        AuthErrorCode.INTERNAL_ERROR,\n        {\n          appName\n        }\n      );\n      manager.expirationTime = expirationTime;\n    }\n    return manager;\n  }\n\n  toJSON(): object {\n    return {\n      refreshToken: this.refreshToken,\n      accessToken: this.accessToken,\n      expirationTime: this.expirationTime\n    };\n  }\n\n  _assign(stsTokenManager: StsTokenManager): void {\n    this.accessToken = stsTokenManager.accessToken;\n    this.refreshToken = stsTokenManager.refreshToken;\n    this.expirationTime = stsTokenManager.expirationTime;\n  }\n\n  _clone(): StsTokenManager {\n    return Object.assign(new StsTokenManager(), this.toJSON());\n  }\n\n  _performRefresh(): never {\n    return debugFail('not implemented');\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/* eslint-disable camelcase */\n\nimport { isCloudWorkstation, querystring } from '@firebase/util';\n\nimport {\n  _getFinalTarget,\n  _performFetchWithErrorHandling,\n  _performApiRequest,\n  _addTidIfNecessary,\n  HttpMethod,\n  HttpHeader,\n  Endpoint\n} from '../index';\nimport { FetchProvider } from '../../core/util/fetch_provider';\nimport { Auth } from '../../model/public_types';\nimport { AuthInternal } from '../../model/auth';\n\nexport const enum TokenType {\n  REFRESH_TOKEN = 'REFRESH_TOKEN',\n  ACCESS_TOKEN = 'ACCESS_TOKEN'\n}\n\n/** The server responses with snake_case; we convert to camelCase */\ninterface RequestStsTokenServerResponse {\n  access_token: string;\n  expires_in: string;\n  refresh_token: string;\n}\n\nexport interface RequestStsTokenResponse {\n  accessToken: string;\n  expiresIn: string;\n  refreshToken: string;\n}\n\nexport interface RevokeTokenRequest {\n  providerId: string;\n  tokenType: TokenType;\n  token: string;\n  idToken: string;\n  tenantId?: string;\n}\n\nexport interface RevokeTokenResponse {}\n\nexport async function requestStsToken(\n  auth: Auth,\n  refreshToken: string\n): Promise<RequestStsTokenResponse> {\n  const response =\n    await _performFetchWithErrorHandling<RequestStsTokenServerResponse>(\n      auth,\n      {},\n      async () => {\n        const body = querystring({\n          'grant_type': 'refresh_token',\n          'refresh_token': refreshToken\n        }).slice(1);\n        const { tokenApiHost, apiKey } = auth.config;\n        const url = await _getFinalTarget(\n          auth,\n          tokenApiHost,\n          Endpoint.TOKEN,\n          `key=${apiKey}`\n        );\n\n        const headers = await (auth as AuthInternal)._getAdditionalHeaders();\n        headers[HttpHeader.CONTENT_TYPE] = 'application/x-www-form-urlencoded';\n\n        const options: RequestInit = {\n          method: HttpMethod.POST,\n          headers,\n          body\n        };\n        if (\n          auth.emulatorConfig &&\n          isCloudWorkstation(auth.emulatorConfig.host)\n        ) {\n          options.credentials = 'include';\n        }\n        return FetchProvider.fetch()(url, options);\n      }\n    );\n\n  // The response comes back in snake_case. Convert to camel:\n  return {\n    accessToken: response.access_token,\n    expiresIn: response.expires_in,\n    refreshToken: response.refresh_token\n  };\n}\n\nexport async function revokeToken(\n  auth: Auth,\n  request: RevokeTokenRequest\n): Promise<RevokeTokenResponse> {\n  return _performApiRequest<RevokeTokenRequest, RevokeTokenResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.REVOKE_TOKEN,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { IdTokenResult, UserInfo } from '../../model/public_types';\nimport { NextFn } from '@firebase/util';\nimport {\n  APIUserInfo,\n  GetAccountInfoResponse,\n  deleteAccount\n} from '../../api/account_management/account';\nimport { FinalizeMfaResponse } from '../../api/authentication/mfa';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport {\n  MutableUserInfo,\n  UserInternal,\n  UserParameters\n} from '../../model/user';\nimport { AuthErrorCode } from '../errors';\nimport { PersistedBlob } from '../persistence';\nimport {\n  _assert,\n  _serverAppCurrentUserOperationNotSupportedError\n} from '../util/assert';\nimport { getIdTokenResult } from './id_token_result';\nimport { _logoutIfInvalidated } from './invalidation';\nimport { ProactiveRefresh } from './proactive_refresh';\nimport { extractProviderData, _reloadWithoutSaving, reload } from './reload';\nimport { StsTokenManager } from './token_manager';\nimport { UserMetadata } from './user_metadata';\nimport { ProviderId } from '../../model/enums';\nimport { _isFirebaseServerApp } from '@firebase/app';\n\nfunction assertStringOrUndefined(\n  assertion: unknown,\n  appName: string\n): asserts assertion is string | undefined {\n  _assert(\n    typeof assertion === 'string' || typeof assertion === 'undefined',\n    AuthErrorCode.INTERNAL_ERROR,\n    { appName }\n  );\n}\n\nexport class UserImpl implements UserInternal {\n  // For the user object, provider is always Firebase.\n  readonly providerId = ProviderId.FIREBASE;\n  stsTokenManager: StsTokenManager;\n  // Last known accessToken so we know when it changes\n  private accessToken: string | null;\n\n  uid: string;\n  auth: AuthInternal;\n  emailVerified: boolean;\n  isAnonymous: boolean;\n  tenantId: string | null;\n  readonly metadata: UserMetadata;\n  providerData: MutableUserInfo[];\n\n  // Optional fields from UserInfo\n  displayName: string | null;\n  email: string | null;\n  phoneNumber: string | null;\n  photoURL: string | null;\n\n  _redirectEventId?: string;\n  private readonly proactiveRefresh = new ProactiveRefresh(this);\n\n  constructor({ uid, auth, stsTokenManager, ...opt }: UserParameters) {\n    this.uid = uid;\n    this.auth = auth;\n    this.stsTokenManager = stsTokenManager;\n    this.accessToken = stsTokenManager.accessToken;\n    this.displayName = opt.displayName || null;\n    this.email = opt.email || null;\n    this.emailVerified = opt.emailVerified || false;\n    this.phoneNumber = opt.phoneNumber || null;\n    this.photoURL = opt.photoURL || null;\n    this.isAnonymous = opt.isAnonymous || false;\n    this.tenantId = opt.tenantId || null;\n    this.providerData = opt.providerData ? [...opt.providerData] : [];\n    this.metadata = new UserMetadata(\n      opt.createdAt || undefined,\n      opt.lastLoginAt || undefined\n    );\n  }\n\n  async getIdToken(forceRefresh?: boolean): Promise<string> {\n    const accessToken = await _logoutIfInvalidated(\n      this,\n      this.stsTokenManager.getToken(this.auth, forceRefresh)\n    );\n    _assert(accessToken, this.auth, AuthErrorCode.INTERNAL_ERROR);\n\n    if (this.accessToken !== accessToken) {\n      this.accessToken = accessToken;\n      await this.auth._persistUserIfCurrent(this);\n      this.auth._notifyListenersIfCurrent(this);\n    }\n\n    return accessToken;\n  }\n\n  getIdTokenResult(forceRefresh?: boolean): Promise<IdTokenResult> {\n    return getIdTokenResult(this, forceRefresh);\n  }\n\n  reload(): Promise<void> {\n    return reload(this);\n  }\n\n  private reloadUserInfo: APIUserInfo | null = null;\n  private reloadListener: NextFn<APIUserInfo> | null = null;\n\n  _assign(user: UserInternal): void {\n    if (this === user) {\n      return;\n    }\n    _assert(this.uid === user.uid, this.auth, AuthErrorCode.INTERNAL_ERROR);\n    this.displayName = user.displayName;\n    this.photoURL = user.photoURL;\n    this.email = user.email;\n    this.emailVerified = user.emailVerified;\n    this.phoneNumber = user.phoneNumber;\n    this.isAnonymous = user.isAnonymous;\n    this.tenantId = user.tenantId;\n    this.providerData = user.providerData.map(userInfo => ({ ...userInfo }));\n    this.metadata._copy(user.metadata);\n    this.stsTokenManager._assign(user.stsTokenManager);\n  }\n\n  _clone(auth: AuthInternal): UserInternal {\n    const newUser = new UserImpl({\n      ...this,\n      auth,\n      stsTokenManager: this.stsTokenManager._clone()\n    });\n    newUser.metadata._copy(this.metadata);\n    return newUser;\n  }\n\n  _onReload(callback: NextFn<APIUserInfo>): void {\n    // There should only ever be one listener, and that is a single instance of MultiFactorUser\n    _assert(!this.reloadListener, this.auth, AuthErrorCode.INTERNAL_ERROR);\n    this.reloadListener = callback;\n    if (this.reloadUserInfo) {\n      this._notifyReloadListener(this.reloadUserInfo);\n      this.reloadUserInfo = null;\n    }\n  }\n\n  _notifyReloadListener(userInfo: APIUserInfo): void {\n    if (this.reloadListener) {\n      this.reloadListener(userInfo);\n    } else {\n      // If no listener is subscribed yet, save the result so it's available when they do subscribe\n      this.reloadUserInfo = userInfo;\n    }\n  }\n\n  _startProactiveRefresh(): void {\n    this.proactiveRefresh._start();\n  }\n\n  _stopProactiveRefresh(): void {\n    this.proactiveRefresh._stop();\n  }\n\n  async _updateTokensIfNecessary(\n    response: IdTokenResponse | FinalizeMfaResponse,\n    reload = false\n  ): Promise<void> {\n    let tokensRefreshed = false;\n    if (\n      response.idToken &&\n      response.idToken !== this.stsTokenManager.accessToken\n    ) {\n      this.stsTokenManager.updateFromServerResponse(response);\n      tokensRefreshed = true;\n    }\n\n    if (reload) {\n      await _reloadWithoutSaving(this);\n    }\n\n    await this.auth._persistUserIfCurrent(this);\n    if (tokensRefreshed) {\n      this.auth._notifyListenersIfCurrent(this);\n    }\n  }\n\n  async delete(): Promise<void> {\n    if (_isFirebaseServerApp(this.auth.app)) {\n      return Promise.reject(\n        _serverAppCurrentUserOperationNotSupportedError(this.auth)\n      );\n    }\n    const idToken = await this.getIdToken();\n    await _logoutIfInvalidated(this, deleteAccount(this.auth, { idToken }));\n    this.stsTokenManager.clearRefreshToken();\n\n    // TODO: Determine if cancellable-promises are necessary to use in this class so that delete()\n    //       cancels pending actions...\n\n    return this.auth.signOut();\n  }\n\n  toJSON(): PersistedBlob {\n    return {\n      uid: this.uid,\n      email: this.email || undefined,\n      emailVerified: this.emailVerified,\n      displayName: this.displayName || undefined,\n      isAnonymous: this.isAnonymous,\n      photoURL: this.photoURL || undefined,\n      phoneNumber: this.phoneNumber || undefined,\n      tenantId: this.tenantId || undefined,\n      providerData: this.providerData.map(userInfo => ({ ...userInfo })),\n      stsTokenManager: this.stsTokenManager.toJSON(),\n      // Redirect event ID must be maintained in case there is a pending\n      // redirect event.\n      _redirectEventId: this._redirectEventId,\n      ...this.metadata.toJSON(),\n\n      // Required for compatibility with the legacy SDK (go/firebase-auth-sdk-persistence-parsing):\n      apiKey: this.auth.config.apiKey,\n      appName: this.auth.name\n      // Missing authDomain will be tolerated by the legacy SDK.\n      // stsTokenManager.apiKey isn't actually required (despite the legacy SDK persisting it).\n    };\n  }\n\n  get refreshToken(): string {\n    return this.stsTokenManager.refreshToken || '';\n  }\n\n  static _fromJSON(auth: AuthInternal, object: PersistedBlob): UserInternal {\n    const displayName = object.displayName ?? undefined;\n    const email = object.email ?? undefined;\n    const phoneNumber = object.phoneNumber ?? undefined;\n    const photoURL = object.photoURL ?? undefined;\n    const tenantId = object.tenantId ?? undefined;\n    const _redirectEventId = object._redirectEventId ?? undefined;\n    const createdAt = object.createdAt ?? undefined;\n    const lastLoginAt = object.lastLoginAt ?? undefined;\n    const {\n      uid,\n      emailVerified,\n      isAnonymous,\n      providerData,\n      stsTokenManager: plainObjectTokenManager\n    } = object;\n\n    _assert(uid && plainObjectTokenManager, auth, AuthErrorCode.INTERNAL_ERROR);\n\n    const stsTokenManager = StsTokenManager.fromJSON(\n      this.name,\n      plainObjectTokenManager as PersistedBlob\n    );\n\n    _assert(typeof uid === 'string', auth, AuthErrorCode.INTERNAL_ERROR);\n    assertStringOrUndefined(displayName, auth.name);\n    assertStringOrUndefined(email, auth.name);\n    _assert(\n      typeof emailVerified === 'boolean',\n      auth,\n      AuthErrorCode.INTERNAL_ERROR\n    );\n    _assert(\n      typeof isAnonymous === 'boolean',\n      auth,\n      AuthErrorCode.INTERNAL_ERROR\n    );\n    assertStringOrUndefined(phoneNumber, auth.name);\n    assertStringOrUndefined(photoURL, auth.name);\n    assertStringOrUndefined(tenantId, auth.name);\n    assertStringOrUndefined(_redirectEventId, auth.name);\n    assertStringOrUndefined(createdAt, auth.name);\n    assertStringOrUndefined(lastLoginAt, auth.name);\n    const user = new UserImpl({\n      uid,\n      auth,\n      email,\n      emailVerified,\n      displayName,\n      isAnonymous,\n      photoURL,\n      phoneNumber,\n      tenantId,\n      stsTokenManager,\n      createdAt,\n      lastLoginAt\n    });\n\n    if (providerData && Array.isArray(providerData)) {\n      user.providerData = providerData.map(userInfo => ({ ...userInfo }));\n    }\n\n    if (_redirectEventId) {\n      user._redirectEventId = _redirectEventId;\n    }\n\n    return user;\n  }\n\n  /**\n   * Initialize a User from an idToken server response\n   * @param auth\n   * @param idTokenResponse\n   */\n  static async _fromIdTokenResponse(\n    auth: AuthInternal,\n    idTokenResponse: IdTokenResponse,\n    isAnonymous: boolean = false\n  ): Promise<UserInternal> {\n    const stsTokenManager = new StsTokenManager();\n    stsTokenManager.updateFromServerResponse(idTokenResponse);\n\n    // Initialize the Firebase Auth user.\n    const user = new UserImpl({\n      uid: idTokenResponse.localId,\n      auth,\n      stsTokenManager,\n      isAnonymous\n    });\n\n    // Updates the user info and data and resolves with a user instance.\n    await _reloadWithoutSaving(user);\n    return user;\n  }\n\n  /**\n   * Initialize a User from an idToken server response\n   * @param auth\n   * @param idTokenResponse\n   */\n  static async _fromGetAccountInfoResponse(\n    auth: AuthInternal,\n    response: GetAccountInfoResponse,\n    idToken: string\n  ): Promise<UserInternal> {\n    const coreAccount = response.users[0];\n    _assert(coreAccount.localId !== undefined, AuthErrorCode.INTERNAL_ERROR);\n\n    const providerData: UserInfo[] =\n      coreAccount.providerUserInfo !== undefined\n        ? extractProviderData(coreAccount.providerUserInfo)\n        : [];\n\n    const isAnonymous =\n      !(coreAccount.email && coreAccount.passwordHash) && !providerData?.length;\n\n    const stsTokenManager = new StsTokenManager();\n    stsTokenManager.updateFromIdToken(idToken);\n\n    // Initialize the Firebase Auth user.\n    const user = new UserImpl({\n      uid: coreAccount.localId,\n      auth,\n      stsTokenManager,\n      isAnonymous\n    });\n\n    // update the user with data from the GetAccountInfo response.\n    const updates: Partial<UserInternal> = {\n      uid: coreAccount.localId,\n      displayName: coreAccount.displayName || null,\n      photoURL: coreAccount.photoUrl || null,\n      email: coreAccount.email || null,\n      emailVerified: coreAccount.emailVerified || false,\n      phoneNumber: coreAccount.phoneNumber || null,\n      tenantId: coreAccount.tenantId || null,\n      providerData,\n      metadata: new UserMetadata(\n        coreAccount.createdAt,\n        coreAccount.lastLoginAt\n      ),\n      isAnonymous:\n        !(coreAccount.email && coreAccount.passwordHash) &&\n        !providerData?.length\n    };\n\n    Object.assign(user, updates);\n    return user;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { debugAssert } from './assert';\n\n/**\n * Our API has a lot of one-off constants that are used to do things.\n * Unfortunately we can't export these as classes instantiated directly since\n * the constructor may side effect and therefore can't be proven to be safely\n * culled. Instead, we export these classes themselves as a lowerCamelCase\n * constant, and instantiate them under the hood.\n */\nexport interface SingletonInstantiator<T> {\n  new (): T;\n}\n\nconst instanceCache: Map<unknown, unknown> = new Map();\n\nexport function _getInstance<T>(cls: unknown): T {\n  debugAssert(cls instanceof Function, 'Expected a class definition');\n  let instance = instanceCache.get(cls) as T | undefined;\n\n  if (instance) {\n    debugAssert(\n      instance instanceof cls,\n      'Instance stored in cache mismatched with class'\n    );\n    return instance;\n  }\n\n  instance = new (cls as SingletonInstantiator<T>)();\n  instanceCache.set(cls, instance);\n  return instance;\n}\n\nexport function _clearInstanceMap(): void {\n  instanceCache.clear();\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Persistence } from '../../model/public_types';\n\nimport {\n  PersistenceInternal,\n  PersistenceType,\n  PersistenceValue,\n  StorageEventListener\n} from '../persistence';\n\nexport class InMemoryPersistence implements PersistenceInternal {\n  static type: 'NONE' = 'NONE';\n  readonly type = PersistenceType.NONE;\n  storage: Record<string, PersistenceValue> = {};\n\n  async _isAvailable(): Promise<boolean> {\n    return true;\n  }\n\n  async _set(key: string, value: PersistenceValue): Promise<void> {\n    this.storage[key] = value;\n  }\n\n  async _get<T extends PersistenceValue>(key: string): Promise<T | null> {\n    const value = this.storage[key];\n    return value === undefined ? null : (value as T);\n  }\n\n  async _remove(key: string): Promise<void> {\n    delete this.storage[key];\n  }\n\n  _addListener(_key: string, _listener: StorageEventListener): void {\n    // Listeners are not supported for in-memory storage since it cannot be shared across windows/workers\n    return;\n  }\n\n  _removeListener(_key: string, _listener: StorageEventListener): void {\n    // Listeners are not supported for in-memory storage since it cannot be shared across windows/workers\n    return;\n  }\n}\n\n/**\n * An implementation of {@link Persistence} of type 'NONE'.\n *\n * @public\n */\nexport const inMemoryPersistence: Persistence = InMemoryPersistence;\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { getAccountInfo } from '../../api/account_management/account';\nimport { ApiKey, AppName, AuthInternal } from '../../model/auth';\nimport { UserInternal } from '../../model/user';\nimport { PersistedBlob, PersistenceInternal } from '../persistence';\nimport { UserImpl } from '../user/user_impl';\nimport { _getInstance } from '../util/instantiator';\nimport { inMemoryPersistence } from './in_memory';\n\nexport const enum KeyName {\n  AUTH_USER = 'authUser',\n  AUTH_EVENT = 'authEvent',\n  REDIRECT_USER = 'redirectUser',\n  PERSISTENCE_USER = 'persistence'\n}\nexport const enum Namespace {\n  PERSISTENCE = 'firebase'\n}\n\nexport function _persistenceKeyName(\n  key: string,\n  apiKey: ApiKey,\n  appName: AppName\n): string {\n  return `${Namespace.PERSISTENCE}:${key}:${apiKey}:${appName}`;\n}\n\nexport class PersistenceUserManager {\n  private readonly fullUserKey: string;\n  private readonly fullPersistenceKey: string;\n  private readonly boundEventHandler: () => void;\n\n  private constructor(\n    public persistence: PersistenceInternal,\n    private readonly auth: AuthInternal,\n    private readonly userKey: string\n  ) {\n    const { config, name } = this.auth;\n    this.fullUserKey = _persistenceKeyName(this.userKey, config.apiKey, name);\n    this.fullPersistenceKey = _persistenceKeyName(\n      KeyName.PERSISTENCE_USER,\n      config.apiKey,\n      name\n    );\n    this.boundEventHandler = auth._onStorageEvent.bind(auth);\n    this.persistence._addListener(this.fullUserKey, this.boundEventHandler);\n  }\n\n  setCurrentUser(user: UserInternal): Promise<void> {\n    return this.persistence._set(this.fullUserKey, user.toJSON());\n  }\n\n  async getCurrentUser(): Promise<UserInternal | null> {\n    const blob = await this.persistence._get<PersistedBlob | string>(\n      this.fullUserKey\n    );\n    if (!blob) {\n      return null;\n    }\n    if (typeof blob === 'string') {\n      const response = await getAccountInfo(this.auth, { idToken: blob }).catch(\n        () => undefined\n      );\n      if (!response) {\n        return null;\n      }\n      return UserImpl._fromGetAccountInfoResponse(this.auth, response, blob);\n    }\n    return UserImpl._fromJSON(this.auth, blob);\n  }\n\n  removeCurrentUser(): Promise<void> {\n    return this.persistence._remove(this.fullUserKey);\n  }\n\n  savePersistenceForRedirect(): Promise<void> {\n    return this.persistence._set(\n      this.fullPersistenceKey,\n      this.persistence.type\n    );\n  }\n\n  async setPersistence(newPersistence: PersistenceInternal): Promise<void> {\n    if (this.persistence === newPersistence) {\n      return;\n    }\n\n    const currentUser = await this.getCurrentUser();\n    await this.removeCurrentUser();\n\n    this.persistence = newPersistence;\n\n    if (currentUser) {\n      return this.setCurrentUser(currentUser);\n    }\n  }\n\n  delete(): void {\n    this.persistence._removeListener(this.fullUserKey, this.boundEventHandler);\n  }\n\n  static async create(\n    auth: AuthInternal,\n    persistenceHierarchy: PersistenceInternal[],\n    userKey = KeyName.AUTH_USER\n  ): Promise<PersistenceUserManager> {\n    if (!persistenceHierarchy.length) {\n      return new PersistenceUserManager(\n        _getInstance(inMemoryPersistence),\n        auth,\n        userKey\n      );\n    }\n\n    // Eliminate any persistences that are not available\n    const availablePersistences = (\n      await Promise.all(\n        persistenceHierarchy.map(async persistence => {\n          if (await persistence._isAvailable()) {\n            return persistence;\n          }\n          return undefined;\n        })\n      )\n    ).filter(persistence => persistence) as PersistenceInternal[];\n\n    // Fall back to the first persistence listed, or in memory if none available\n    let selectedPersistence =\n      availablePersistences[0] ||\n      _getInstance<PersistenceInternal>(inMemoryPersistence);\n\n    const key = _persistenceKeyName(userKey, auth.config.apiKey, auth.name);\n\n    // Pull out the existing user, setting the chosen persistence to that\n    // persistence if the user exists.\n    let userToMigrate: UserInternal | null = null;\n    // Note, here we check for a user in _all_ persistences, not just the\n    // ones deemed available. If we can migrate a user out of a broken\n    // persistence, we will (but only if that persistence supports migration).\n    for (const persistence of persistenceHierarchy) {\n      try {\n        const blob = await persistence._get<PersistedBlob | string>(key);\n        if (blob) {\n          let user: UserInternal;\n          if (typeof blob === 'string') {\n            const response = await getAccountInfo(auth, {\n              idToken: blob\n            }).catch(() => undefined);\n            if (!response) {\n              break;\n            }\n            user = await UserImpl._fromGetAccountInfoResponse(\n              auth,\n              response,\n              blob\n            );\n          } else {\n            user = UserImpl._fromJSON(auth, blob); // throws for unparsable blob (wrong format)\n          }\n          if (persistence !== selectedPersistence) {\n            userToMigrate = user;\n          }\n          selectedPersistence = persistence;\n          break;\n        }\n      } catch {}\n    }\n\n    // If we find the user in a persistence that does support migration, use\n    // that migration path (of only persistences that support migration)\n    const migrationHierarchy = availablePersistences.filter(\n      p => p._shouldAllowMigration\n    );\n\n    // If the persistence does _not_ allow migration, just finish off here\n    if (\n      !selectedPersistence._shouldAllowMigration ||\n      !migrationHierarchy.length\n    ) {\n      return new PersistenceUserManager(selectedPersistence, auth, userKey);\n    }\n\n    selectedPersistence = migrationHierarchy[0];\n    if (userToMigrate) {\n      // This normally shouldn't throw since chosenPersistence.isAvailable() is true, but if it does\n      // we'll just let it bubble to surface the error.\n      await selectedPersistence._set(key, userToMigrate.toJSON());\n    }\n\n    // Attempt to clear the key in other persistences but ignore errors. This helps prevent issues\n    // such as users getting stuck with a previous account after signing out and refreshing the tab.\n    await Promise.all(\n      persistenceHierarchy.map(async persistence => {\n        if (persistence !== selectedPersistence) {\n          try {\n            await persistence._remove(key);\n          } catch {}\n        }\n      })\n    );\n    return new PersistenceUserManager(selectedPersistence, auth, userKey);\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { isIE, getUA } from '@firebase/util';\n\ninterface NavigatorStandalone extends Navigator {\n  standalone?: unknown;\n}\n\ninterface Document {\n  documentMode?: number;\n}\n\n/**\n * Enums for Browser name.\n */\nexport const enum BrowserName {\n  ANDROID = 'Android',\n  BLACKBERRY = 'Blackberry',\n  EDGE = 'Edge',\n  FIREFOX = 'Firefox',\n  IE = 'IE',\n  IEMOBILE = 'IEMobile',\n  OPERA = 'Opera',\n  OTHER = 'Other',\n  CHROME = 'Chrome',\n  SAFARI = 'Safari',\n  SILK = 'Silk',\n  WEBOS = 'Webos'\n}\n\n/**\n * Determine the browser for the purposes of reporting usage to the API\n */\nexport function _getBrowserName(userAgent: string): BrowserName | string {\n  const ua = userAgent.toLowerCase();\n  if (ua.includes('opera/') || ua.includes('opr/') || ua.includes('opios/')) {\n    return BrowserName.OPERA;\n  } else if (_isIEMobile(ua)) {\n    // Windows phone IEMobile browser.\n    return BrowserName.IEMOBILE;\n  } else if (ua.includes('msie') || ua.includes('trident/')) {\n    return BrowserName.IE;\n  } else if (ua.includes('edge/')) {\n    return BrowserName.EDGE;\n  } else if (_isFirefox(ua)) {\n    return BrowserName.FIREFOX;\n  } else if (ua.includes('silk/')) {\n    return BrowserName.SILK;\n  } else if (_isBlackBerry(ua)) {\n    // Blackberry browser.\n    return BrowserName.BLACKBERRY;\n  } else if (_isWebOS(ua)) {\n    // WebOS default browser.\n    return BrowserName.WEBOS;\n  } else if (_isSafari(ua)) {\n    return BrowserName.SAFARI;\n  } else if (\n    (ua.includes('chrome/') || _isChromeIOS(ua)) &&\n    !ua.includes('edge/')\n  ) {\n    return BrowserName.CHROME;\n  } else if (_isAndroid(ua)) {\n    // Android stock browser.\n    return BrowserName.ANDROID;\n  } else {\n    // Most modern browsers have name/version at end of user agent string.\n    const re = /([a-zA-Z\\d\\.]+)\\/[a-zA-Z\\d\\.]*$/;\n    const matches = userAgent.match(re);\n    if (matches?.length === 2) {\n      return matches[1];\n    }\n  }\n  return BrowserName.OTHER;\n}\n\nexport function _isFirefox(ua = getUA()): boolean {\n  return /firefox\\//i.test(ua);\n}\n\nexport function _isSafari(userAgent = getUA()): boolean {\n  const ua = userAgent.toLowerCase();\n  return (\n    ua.includes('safari/') &&\n    !ua.includes('chrome/') &&\n    !ua.includes('crios/') &&\n    !ua.includes('android')\n  );\n}\n\nexport function _isChromeIOS(ua = getUA()): boolean {\n  return /crios\\//i.test(ua);\n}\n\nexport function _isIEMobile(ua = getUA()): boolean {\n  return /iemobile/i.test(ua);\n}\n\nexport function _isAndroid(ua = getUA()): boolean {\n  return /android/i.test(ua);\n}\n\nexport function _isBlackBerry(ua = getUA()): boolean {\n  return /blackberry/i.test(ua);\n}\n\nexport function _isWebOS(ua = getUA()): boolean {\n  return /webos/i.test(ua);\n}\n\nexport function _isIOS(ua = getUA()): boolean {\n  return (\n    /iphone|ipad|ipod/i.test(ua) ||\n    (/macintosh/i.test(ua) && /mobile/i.test(ua))\n  );\n}\n\nexport function _isIOS7Or8(ua = getUA()): boolean {\n  return (\n    /(iPad|iPhone|iPod).*OS 7_\\d/i.test(ua) ||\n    /(iPad|iPhone|iPod).*OS 8_\\d/i.test(ua)\n  );\n}\n\nexport function _isIOSStandalone(ua = getUA()): boolean {\n  return _isIOS(ua) && !!(window.navigator as NavigatorStandalone)?.standalone;\n}\n\nexport function _isIE10(): boolean {\n  return isIE() && (document as Document).documentMode === 10;\n}\n\nexport function _isMobileBrowser(ua: string = getUA()): boolean {\n  // TODO: implement getBrowserName equivalent for OS.\n  return (\n    _isIOS(ua) ||\n    _isAndroid(ua) ||\n    _isWebOS(ua) ||\n    _isBlackBerry(ua) ||\n    /windows phone/i.test(ua) ||\n    _isIEMobile(ua)\n  );\n}\n\nexport function _isIframe(): boolean {\n  try {\n    // Check that the current window is not the top window.\n    // If so, return true.\n    return !!(window && window !== window.top);\n  } catch (e) {\n    return false;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { SDK_VERSION } from '@firebase/app';\nimport { _getBrowserName } from './browser';\nimport { getUA } from '@firebase/util';\n\nexport const enum ClientImplementation {\n  CORE = 'JsCore'\n}\n\n/**\n * @internal\n */\nexport const enum ClientPlatform {\n  BROWSER = 'Browser',\n  NODE = 'Node',\n  REACT_NATIVE = 'ReactNative',\n  CORDOVA = 'Cordova',\n  WORKER = 'Worker',\n  WEB_EXTENSION = 'WebExtension'\n}\n\n/*\n * Determine the SDK version string\n */\nexport function _getClientVersion(\n  clientPlatform: ClientPlatform,\n  frameworks: readonly string[] = []\n): string {\n  let reportedPlatform: string;\n  switch (clientPlatform) {\n    case ClientPlatform.BROWSER:\n      // In a browser environment, report the browser name.\n      reportedPlatform = _getBrowserName(getUA());\n      break;\n    case ClientPlatform.WORKER:\n      // Technically a worker runs from a browser but we need to differentiate a\n      // worker from a browser.\n      // For example: Chrome-Worker/JsCore/4.9.1/FirebaseCore-web.\n      reportedPlatform = `${_getBrowserName(getUA())}-${clientPlatform}`;\n      break;\n    default:\n      reportedPlatform = clientPlatform;\n  }\n  const reportedFrameworks = frameworks.length\n    ? frameworks.join(',')\n    : 'FirebaseCore-web'; /* default value if no other framework is used */\n  return `${reportedPlatform}/${ClientImplementation.CORE}/${SDK_VERSION}/${reportedFrameworks}`;\n}\n","/**\n * @license\n * Copyright 2022 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthInternal } from '../../model/auth';\nimport { Unsubscribe, User } from '../../model/public_types';\nimport { AuthErrorCode } from '../errors';\n\ninterface MiddlewareEntry {\n  (user: User | null): Promise<void>;\n  onAbort?: () => void;\n}\n\nexport class AuthMiddlewareQueue {\n  private readonly queue: MiddlewareEntry[] = [];\n\n  constructor(private readonly auth: AuthInternal) {}\n\n  pushCallback(\n    callback: (user: User | null) => void | Promise<void>,\n    onAbort?: () => void\n  ): Unsubscribe {\n    // The callback could be sync or async. Wrap it into a\n    // function that is always async.\n    const wrappedCallback: MiddlewareEntry = (\n      user: User | null\n    ): Promise<void> =>\n      new Promise((resolve, reject) => {\n        try {\n          const result = callback(user);\n          // Either resolve with existing promise or wrap a non-promise\n          // return value into a promise.\n          resolve(result);\n        } catch (e) {\n          // Sync callback throws.\n          reject(e);\n        }\n      });\n    // Attach the onAbort if present\n    wrappedCallback.onAbort = onAbort;\n    this.queue.push(wrappedCallback);\n\n    const index = this.queue.length - 1;\n    return () => {\n      // Unsubscribe. Replace with no-op. Do not remove from array, or it will disturb\n      // indexing of other elements.\n      this.queue[index] = () => Promise.resolve();\n    };\n  }\n\n  async runMiddleware(nextUser: User | null): Promise<void> {\n    if (this.auth.currentUser === nextUser) {\n      return;\n    }\n\n    // While running the middleware, build a temporary stack of onAbort\n    // callbacks to call if one middleware callback rejects.\n\n    const onAbortStack: Array<() => void> = [];\n    try {\n      for (const beforeStateCallback of this.queue) {\n        await beforeStateCallback(nextUser);\n\n        // Only push the onAbort if the callback succeeds\n        if (beforeStateCallback.onAbort) {\n          onAbortStack.push(beforeStateCallback.onAbort);\n        }\n      }\n    } catch (e) {\n      // Run all onAbort, with separate try/catch to ignore any errors and\n      // continue\n      onAbortStack.reverse();\n      for (const onAbort of onAbortStack) {\n        try {\n          onAbort();\n        } catch (_) {\n          /* swallow error */\n        }\n      }\n\n      throw this.auth._errorFactory.create(AuthErrorCode.LOGIN_BLOCKED, {\n        originalMessage: (e as Error)?.message\n      });\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2023 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { GetPasswordPolicyResponse } from '../../api/password_policy/get_password_policy';\nimport {\n  PasswordPolicyCustomStrengthOptions,\n  PasswordPolicyInternal,\n  PasswordValidationStatusInternal\n} from '../../model/password_policy';\nimport { PasswordValidationStatus } from '../../model/public_types';\n\n// Minimum min password length enforced by the backend, even if no minimum length is set.\nconst MINIMUM_MIN_PASSWORD_LENGTH = 6;\n\n/**\n * Stores password policy requirements and provides password validation against the policy.\n *\n * @internal\n */\nexport class PasswordPolicyImpl implements PasswordPolicyInternal {\n  readonly customStrengthOptions: PasswordPolicyCustomStrengthOptions;\n  readonly allowedNonAlphanumericCharacters: string;\n  readonly enforcementState: string;\n  readonly forceUpgradeOnSignin: boolean;\n  readonly schemaVersion: number;\n\n  constructor(response: GetPasswordPolicyResponse) {\n    // Only include custom strength options defined in the response.\n    const responseOptions = response.customStrengthOptions;\n    this.customStrengthOptions = {};\n    // TODO: Remove once the backend is updated to include the minimum min password length instead of undefined when there is no minimum length set.\n    this.customStrengthOptions.minPasswordLength =\n      responseOptions.minPasswordLength ?? MINIMUM_MIN_PASSWORD_LENGTH;\n    if (responseOptions.maxPasswordLength) {\n      this.customStrengthOptions.maxPasswordLength =\n        responseOptions.maxPasswordLength;\n    }\n    if (responseOptions.containsLowercaseCharacter !== undefined) {\n      this.customStrengthOptions.containsLowercaseLetter =\n        responseOptions.containsLowercaseCharacter;\n    }\n    if (responseOptions.containsUppercaseCharacter !== undefined) {\n      this.customStrengthOptions.containsUppercaseLetter =\n        responseOptions.containsUppercaseCharacter;\n    }\n    if (responseOptions.containsNumericCharacter !== undefined) {\n      this.customStrengthOptions.containsNumericCharacter =\n        responseOptions.containsNumericCharacter;\n    }\n    if (responseOptions.containsNonAlphanumericCharacter !== undefined) {\n      this.customStrengthOptions.containsNonAlphanumericCharacter =\n        responseOptions.containsNonAlphanumericCharacter;\n    }\n\n    this.enforcementState = response.enforcementState;\n    if (this.enforcementState === 'ENFORCEMENT_STATE_UNSPECIFIED') {\n      this.enforcementState = 'OFF';\n    }\n\n    // Use an empty string if no non-alphanumeric characters are specified in the response.\n    this.allowedNonAlphanumericCharacters =\n      response.allowedNonAlphanumericCharacters?.join('') ?? '';\n\n    this.forceUpgradeOnSignin = response.forceUpgradeOnSignin ?? false;\n    this.schemaVersion = response.schemaVersion;\n  }\n\n  validatePassword(password: string): PasswordValidationStatus {\n    const status: PasswordValidationStatusInternal = {\n      isValid: true,\n      passwordPolicy: this\n    };\n\n    // Check the password length and character options.\n    this.validatePasswordLengthOptions(password, status);\n    this.validatePasswordCharacterOptions(password, status);\n\n    // Combine the status into single isValid property.\n    status.isValid &&= status.meetsMinPasswordLength ?? true;\n    status.isValid &&= status.meetsMaxPasswordLength ?? true;\n    status.isValid &&= status.containsLowercaseLetter ?? true;\n    status.isValid &&= status.containsUppercaseLetter ?? true;\n    status.isValid &&= status.containsNumericCharacter ?? true;\n    status.isValid &&= status.containsNonAlphanumericCharacter ?? true;\n\n    return status;\n  }\n\n  /**\n   * Validates that the password meets the length options for the policy.\n   *\n   * @param password Password to validate.\n   * @param status Validation status.\n   */\n  private validatePasswordLengthOptions(\n    password: string,\n    status: PasswordValidationStatusInternal\n  ): void {\n    const minPasswordLength = this.customStrengthOptions.minPasswordLength;\n    const maxPasswordLength = this.customStrengthOptions.maxPasswordLength;\n    if (minPasswordLength) {\n      status.meetsMinPasswordLength = password.length >= minPasswordLength;\n    }\n    if (maxPasswordLength) {\n      status.meetsMaxPasswordLength = password.length <= maxPasswordLength;\n    }\n  }\n\n  /**\n   * Validates that the password meets the character options for the policy.\n   *\n   * @param password Password to validate.\n   * @param status Validation status.\n   */\n  private validatePasswordCharacterOptions(\n    password: string,\n    status: PasswordValidationStatusInternal\n  ): void {\n    // Assign statuses for requirements even if the password is an empty string.\n    this.updatePasswordCharacterOptionsStatuses(\n      status,\n      /* containsLowercaseCharacter= */ false,\n      /* containsUppercaseCharacter= */ false,\n      /* containsNumericCharacter= */ false,\n      /* containsNonAlphanumericCharacter= */ false\n    );\n\n    let passwordChar;\n    for (let i = 0; i < password.length; i++) {\n      passwordChar = password.charAt(i);\n      this.updatePasswordCharacterOptionsStatuses(\n        status,\n        /* containsLowercaseCharacter= */ passwordChar >= 'a' &&\n          passwordChar <= 'z',\n        /* containsUppercaseCharacter= */ passwordChar >= 'A' &&\n          passwordChar <= 'Z',\n        /* containsNumericCharacter= */ passwordChar >= '0' &&\n          passwordChar <= '9',\n        /* containsNonAlphanumericCharacter= */ this.allowedNonAlphanumericCharacters.includes(\n          passwordChar\n        )\n      );\n    }\n  }\n\n  /**\n   * Updates the running validation status with the statuses for the character options.\n   * Expected to be called each time a character is processed to update each option status\n   * based on the current character.\n   *\n   * @param status Validation status.\n   * @param containsLowercaseCharacter Whether the character is a lowercase letter.\n   * @param containsUppercaseCharacter Whether the character is an uppercase letter.\n   * @param containsNumericCharacter Whether the character is a numeric character.\n   * @param containsNonAlphanumericCharacter Whether the character is a non-alphanumeric character.\n   */\n  private updatePasswordCharacterOptionsStatuses(\n    status: PasswordValidationStatusInternal,\n    containsLowercaseCharacter: boolean,\n    containsUppercaseCharacter: boolean,\n    containsNumericCharacter: boolean,\n    containsNonAlphanumericCharacter: boolean\n  ): void {\n    if (this.customStrengthOptions.containsLowercaseLetter) {\n      status.containsLowercaseLetter ||= containsLowercaseCharacter;\n    }\n    if (this.customStrengthOptions.containsUppercaseLetter) {\n      status.containsUppercaseLetter ||= containsUppercaseCharacter;\n    }\n    if (this.customStrengthOptions.containsNumericCharacter) {\n      status.containsNumericCharacter ||= containsNumericCharacter;\n    }\n    if (this.customStrengthOptions.containsNonAlphanumericCharacter) {\n      status.containsNonAlphanumericCharacter ||=\n        containsNonAlphanumericCharacter;\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  _isFirebaseServerApp,\n  _FirebaseService,\n  FirebaseApp\n} from '@firebase/app';\nimport { Provider } from '@firebase/component';\nimport { AppCheckInternalComponentName } from '@firebase/app-check-interop-types';\nimport {\n  Auth,\n  AuthErrorMap,\n  AuthSettings,\n  EmulatorConfig,\n  NextOrObserver,\n  Persistence,\n  PopupRedirectResolver,\n  User,\n  UserCredential,\n  CompleteFn,\n  ErrorFn,\n  NextFn,\n  Unsubscribe,\n  PasswordValidationStatus\n} from '../../model/public_types';\nimport {\n  createSubscribe,\n  ErrorFactory,\n  FirebaseError,\n  getModularInstance,\n  Observer,\n  Subscribe\n} from '@firebase/util';\n\nimport { AuthInternal, ConfigInternal } from '../../model/auth';\nimport { PopupRedirectResolverInternal } from '../../model/popup_redirect';\nimport { UserInternal } from '../../model/user';\nimport {\n  AuthErrorCode,\n  AuthErrorParams,\n  ErrorMapRetriever,\n  _DEFAULT_AUTH_ERROR_FACTORY\n} from '../errors';\nimport { PersistenceInternal } from '../persistence';\nimport {\n  KeyName,\n  PersistenceUserManager\n} from '../persistence/persistence_user_manager';\nimport { _reloadWithoutSaving } from '../user/reload';\nimport {\n  _assert,\n  _serverAppCurrentUserOperationNotSupportedError\n} from '../util/assert';\nimport { _getInstance } from '../util/instantiator';\nimport { _getUserLanguage } from '../util/navigator';\nimport { _getClientVersion } from '../util/version';\nimport { HttpHeader } from '../../api';\nimport {\n  RevokeTokenRequest,\n  TokenType,\n  revokeToken\n} from '../../api/authentication/token';\nimport { AuthMiddlewareQueue } from './middleware';\nimport { RecaptchaConfig } from '../../platform_browser/recaptcha/recaptcha';\nimport { _logWarn } from '../util/log';\nimport { _getPasswordPolicy } from '../../api/password_policy/get_password_policy';\nimport { PasswordPolicyInternal } from '../../model/password_policy';\nimport { PasswordPolicyImpl } from './password_policy_impl';\nimport { getAccountInfo } from '../../api/account_management/account';\nimport { UserImpl } from '../user/user_impl';\n\ninterface AsyncAction {\n  (): Promise<void>;\n}\n\nexport const enum DefaultConfig {\n  TOKEN_API_HOST = 'securetoken.googleapis.com',\n  API_HOST = 'identitytoolkit.googleapis.com',\n  API_SCHEME = 'https'\n}\n\nexport class AuthImpl implements AuthInternal, _FirebaseService {\n  currentUser: User | null = null;\n  emulatorConfig: EmulatorConfig | null = null;\n  private operations = Promise.resolve();\n  private persistenceManager?: PersistenceUserManager;\n  private redirectPersistenceManager?: PersistenceUserManager;\n  private authStateSubscription = new Subscription<User>(this);\n  private idTokenSubscription = new Subscription<User>(this);\n  private readonly beforeStateQueue = new AuthMiddlewareQueue(this);\n  private redirectUser: UserInternal | null = null;\n  private isProactiveRefreshEnabled = false;\n  private readonly EXPECTED_PASSWORD_POLICY_SCHEMA_VERSION: number = 1;\n\n  // Any network calls will set this to true and prevent subsequent emulator\n  // initialization\n  _canInitEmulator = true;\n  _isInitialized = false;\n  _deleted = false;\n  _initializationPromise: Promise<void> | null = null;\n  _popupRedirectResolver: PopupRedirectResolverInternal | null = null;\n  _errorFactory: ErrorFactory<AuthErrorCode, AuthErrorParams> =\n    _DEFAULT_AUTH_ERROR_FACTORY;\n  _agentRecaptchaConfig: RecaptchaConfig | null = null;\n  _tenantRecaptchaConfigs: Record<string, RecaptchaConfig> = {};\n  _projectPasswordPolicy: PasswordPolicyInternal | null = null;\n  _tenantPasswordPolicies: Record<string, PasswordPolicyInternal> = {};\n  _resolvePersistenceManagerAvailable:\n    | ((value: void | PromiseLike<void>) => void)\n    | undefined = undefined;\n  _persistenceManagerAvailable: Promise<void>;\n  readonly name: string;\n\n  // Tracks the last notified UID for state change listeners to prevent\n  // repeated calls to the callbacks. Undefined means it's never been\n  // called, whereas null means it's been called with a signed out user\n  private lastNotifiedUid: string | null | undefined = undefined;\n\n  languageCode: string | null = null;\n  tenantId: string | null = null;\n  settings: AuthSettings = { appVerificationDisabledForTesting: false };\n\n  constructor(\n    public readonly app: FirebaseApp,\n    private readonly heartbeatServiceProvider: Provider<'heartbeat'>,\n    private readonly appCheckServiceProvider: Provider<AppCheckInternalComponentName>,\n    public readonly config: ConfigInternal\n  ) {\n    this.name = app.name;\n    this.clientVersion = config.sdkClientVersion;\n    // TODO(jamesdaniels) explore less hacky way to do this, cookie authentication needs\n    // persistenceMananger to be available. see _getFinalTarget for more context\n    this._persistenceManagerAvailable = new Promise<void>(\n      resolve => (this._resolvePersistenceManagerAvailable = resolve)\n    );\n  }\n\n  _initializeWithPersistence(\n    persistenceHierarchy: PersistenceInternal[],\n    popupRedirectResolver?: PopupRedirectResolver\n  ): Promise<void> {\n    if (popupRedirectResolver) {\n      this._popupRedirectResolver = _getInstance(popupRedirectResolver);\n    }\n\n    // Have to check for app deletion throughout initialization (after each\n    // promise resolution)\n    this._initializationPromise = this.queue(async () => {\n      if (this._deleted) {\n        return;\n      }\n\n      this.persistenceManager = await PersistenceUserManager.create(\n        this,\n        persistenceHierarchy\n      );\n      this._resolvePersistenceManagerAvailable?.();\n\n      if (this._deleted) {\n        return;\n      }\n\n      // Initialize the resolver early if necessary (only applicable to web:\n      // this will cause the iframe to load immediately in certain cases)\n      if (this._popupRedirectResolver?._shouldInitProactively) {\n        // If this fails, don't halt auth loading\n        try {\n          await this._popupRedirectResolver._initialize(this);\n        } catch (e) {\n          /* Ignore the error */\n        }\n      }\n\n      await this.initializeCurrentUser(popupRedirectResolver);\n\n      this.lastNotifiedUid = this.currentUser?.uid || null;\n\n      if (this._deleted) {\n        return;\n      }\n\n      this._isInitialized = true;\n    });\n\n    return this._initializationPromise;\n  }\n\n  /**\n   * If the persistence is changed in another window, the user manager will let us know\n   */\n  async _onStorageEvent(): Promise<void> {\n    if (this._deleted) {\n      return;\n    }\n\n    const user = await this.assertedPersistence.getCurrentUser();\n\n    if (!this.currentUser && !user) {\n      // No change, do nothing (was signed out and remained signed out).\n      return;\n    }\n\n    // If the same user is to be synchronized.\n    if (this.currentUser && user && this.currentUser.uid === user.uid) {\n      // Data update, simply copy data changes.\n      this._currentUser._assign(user);\n      // If tokens changed from previous user tokens, this will trigger\n      // notifyAuthListeners_.\n      await this.currentUser.getIdToken();\n      return;\n    }\n\n    // Update current Auth state. Either a new login or logout.\n    // Skip blocking callbacks, they should not apply to a change in another tab.\n    await this._updateCurrentUser(user, /* skipBeforeStateCallbacks */ true);\n  }\n\n  private async initializeCurrentUserFromIdToken(\n    idToken: string\n  ): Promise<void> {\n    try {\n      const response = await getAccountInfo(this, { idToken });\n      const user = await UserImpl._fromGetAccountInfoResponse(\n        this,\n        response,\n        idToken\n      );\n      await this.directlySetCurrentUser(user);\n    } catch (err) {\n      console.warn(\n        'FirebaseServerApp could not login user with provided authIdToken: ',\n        err\n      );\n      await this.directlySetCurrentUser(null);\n    }\n  }\n\n  private async initializeCurrentUser(\n    popupRedirectResolver?: PopupRedirectResolver\n  ): Promise<void> {\n    if (_isFirebaseServerApp(this.app)) {\n      const idToken = this.app.settings.authIdToken;\n      if (idToken) {\n        // Start the auth operation in the next tick to allow a moment for the customer's app to\n        // attach an emulator, if desired.\n        return new Promise<void>(resolve => {\n          setTimeout(() =>\n            this.initializeCurrentUserFromIdToken(idToken).then(\n              resolve,\n              resolve\n            )\n          );\n        });\n      } else {\n        return this.directlySetCurrentUser(null);\n      }\n    }\n\n    // First check to see if we have a pending redirect event.\n    const previouslyStoredUser =\n      (await this.assertedPersistence.getCurrentUser()) as UserInternal | null;\n    let futureCurrentUser = previouslyStoredUser;\n    let needsTocheckMiddleware = false;\n    if (popupRedirectResolver && this.config.authDomain) {\n      await this.getOrInitRedirectPersistenceManager();\n      const redirectUserEventId = this.redirectUser?._redirectEventId;\n      const storedUserEventId = futureCurrentUser?._redirectEventId;\n      const result = await this.tryRedirectSignIn(popupRedirectResolver);\n\n      // If the stored user (i.e. the old \"currentUser\") has a redirectId that\n      // matches the redirect user, then we want to initially sign in with the\n      // new user object from result.\n      // TODO(samgho): More thoroughly test all of this\n      if (\n        (!redirectUserEventId || redirectUserEventId === storedUserEventId) &&\n        result?.user\n      ) {\n        futureCurrentUser = result.user as UserInternal;\n        needsTocheckMiddleware = true;\n      }\n    }\n\n    // If no user in persistence, there is no current user. Set to null.\n    if (!futureCurrentUser) {\n      return this.directlySetCurrentUser(null);\n    }\n\n    if (!futureCurrentUser._redirectEventId) {\n      // This isn't a redirect link operation, we can reload and bail.\n      // First though, ensure that we check the middleware is happy.\n      if (needsTocheckMiddleware) {\n        try {\n          await this.beforeStateQueue.runMiddleware(futureCurrentUser);\n        } catch (e) {\n          futureCurrentUser = previouslyStoredUser;\n          // We know this is available since the bit is only set when the\n          // resolver is available\n          this._popupRedirectResolver!._overrideRedirectResult(this, () =>\n            Promise.reject(e)\n          );\n        }\n      }\n\n      if (futureCurrentUser) {\n        return this.reloadAndSetCurrentUserOrClear(futureCurrentUser);\n      } else {\n        return this.directlySetCurrentUser(null);\n      }\n    }\n\n    _assert(this._popupRedirectResolver, this, AuthErrorCode.ARGUMENT_ERROR);\n    await this.getOrInitRedirectPersistenceManager();\n\n    // If the redirect user's event ID matches the current user's event ID,\n    // DO NOT reload the current user, otherwise they'll be cleared from storage.\n    // This is important for the reauthenticateWithRedirect() flow.\n    if (\n      this.redirectUser &&\n      this.redirectUser._redirectEventId === futureCurrentUser._redirectEventId\n    ) {\n      return this.directlySetCurrentUser(futureCurrentUser);\n    }\n\n    return this.reloadAndSetCurrentUserOrClear(futureCurrentUser);\n  }\n\n  private async tryRedirectSignIn(\n    redirectResolver: PopupRedirectResolver\n  ): Promise<UserCredential | null> {\n    // The redirect user needs to be checked (and signed in if available)\n    // during auth initialization. All of the normal sign in and link/reauth\n    // flows call back into auth and push things onto the promise queue. We\n    // need to await the result of the redirect sign in *inside the promise\n    // queue*. This presents a problem: we run into deadlock. See:\n    //    ┌> [Initialization] ─────┐\n    //    ┌> [<other queue tasks>] │\n    //    └─ [getRedirectResult] <─┘\n    //    where [] are tasks on the queue and arrows denote awaits\n    // Initialization will never complete because it's waiting on something\n    // that's waiting for initialization to complete!\n    //\n    // Instead, this method calls getRedirectResult() (stored in\n    // _completeRedirectFn) with an optional parameter that instructs all of\n    // the underlying auth operations to skip anything that mutates auth state.\n\n    let result: UserCredential | null = null;\n    try {\n      // We know this._popupRedirectResolver is set since redirectResolver\n      // is passed in. The _completeRedirectFn expects the unwrapped extern.\n      result = await this._popupRedirectResolver!._completeRedirectFn(\n        this,\n        redirectResolver,\n        true\n      );\n    } catch (e) {\n      // Swallow any errors here; the code can retrieve them in\n      // getRedirectResult().\n      await this._setRedirectUser(null);\n    }\n\n    return result;\n  }\n\n  private async reloadAndSetCurrentUserOrClear(\n    user: UserInternal\n  ): Promise<void> {\n    try {\n      await _reloadWithoutSaving(user);\n    } catch (e) {\n      if (\n        (e as FirebaseError)?.code !==\n        `auth/${AuthErrorCode.NETWORK_REQUEST_FAILED}`\n      ) {\n        // Something's wrong with the user's token. Log them out and remove\n        // them from storage\n        return this.directlySetCurrentUser(null);\n      }\n    }\n\n    return this.directlySetCurrentUser(user);\n  }\n\n  useDeviceLanguage(): void {\n    this.languageCode = _getUserLanguage();\n  }\n\n  async _delete(): Promise<void> {\n    this._deleted = true;\n  }\n\n  async updateCurrentUser(userExtern: User | null): Promise<void> {\n    if (_isFirebaseServerApp(this.app)) {\n      return Promise.reject(\n        _serverAppCurrentUserOperationNotSupportedError(this)\n      );\n    }\n    // The public updateCurrentUser method needs to make a copy of the user,\n    // and also check that the project matches\n    const user = userExtern\n      ? (getModularInstance(userExtern) as UserInternal)\n      : null;\n    if (user) {\n      _assert(\n        user.auth.config.apiKey === this.config.apiKey,\n        this,\n        AuthErrorCode.INVALID_AUTH\n      );\n    }\n    return this._updateCurrentUser(user && user._clone(this));\n  }\n\n  async _updateCurrentUser(\n    user: User | null,\n    skipBeforeStateCallbacks: boolean = false\n  ): Promise<void> {\n    if (this._deleted) {\n      return;\n    }\n    if (user) {\n      _assert(\n        this.tenantId === user.tenantId,\n        this,\n        AuthErrorCode.TENANT_ID_MISMATCH\n      );\n    }\n\n    if (!skipBeforeStateCallbacks) {\n      await this.beforeStateQueue.runMiddleware(user);\n    }\n\n    return this.queue(async () => {\n      await this.directlySetCurrentUser(user as UserInternal | null);\n      this.notifyAuthListeners();\n    });\n  }\n\n  async signOut(): Promise<void> {\n    if (_isFirebaseServerApp(this.app)) {\n      return Promise.reject(\n        _serverAppCurrentUserOperationNotSupportedError(this)\n      );\n    }\n    // Run first, to block _setRedirectUser() if any callbacks fail.\n    await this.beforeStateQueue.runMiddleware(null);\n    // Clear the redirect user when signOut is called\n    if (this.redirectPersistenceManager || this._popupRedirectResolver) {\n      await this._setRedirectUser(null);\n    }\n\n    // Prevent callbacks from being called again in _updateCurrentUser, as\n    // they were already called in the first line.\n    return this._updateCurrentUser(null, /* skipBeforeStateCallbacks */ true);\n  }\n\n  setPersistence(persistence: Persistence): Promise<void> {\n    if (_isFirebaseServerApp(this.app)) {\n      return Promise.reject(\n        _serverAppCurrentUserOperationNotSupportedError(this)\n      );\n    }\n    return this.queue(async () => {\n      await this.assertedPersistence.setPersistence(_getInstance(persistence));\n    });\n  }\n\n  _getRecaptchaConfig(): RecaptchaConfig | null {\n    if (this.tenantId == null) {\n      return this._agentRecaptchaConfig;\n    } else {\n      return this._tenantRecaptchaConfigs[this.tenantId];\n    }\n  }\n\n  async validatePassword(password: string): Promise<PasswordValidationStatus> {\n    if (!this._getPasswordPolicyInternal()) {\n      await this._updatePasswordPolicy();\n    }\n\n    // Password policy will be defined after fetching.\n    const passwordPolicy: PasswordPolicyInternal =\n      this._getPasswordPolicyInternal()!;\n\n    // Check that the policy schema version is supported by the SDK.\n    // TODO: Update this logic to use a max supported policy schema version once we have multiple schema versions.\n    if (\n      passwordPolicy.schemaVersion !==\n      this.EXPECTED_PASSWORD_POLICY_SCHEMA_VERSION\n    ) {\n      return Promise.reject(\n        this._errorFactory.create(\n          AuthErrorCode.UNSUPPORTED_PASSWORD_POLICY_SCHEMA_VERSION,\n          {}\n        )\n      );\n    }\n\n    return passwordPolicy.validatePassword(password);\n  }\n\n  _getPasswordPolicyInternal(): PasswordPolicyInternal | null {\n    if (this.tenantId === null) {\n      return this._projectPasswordPolicy;\n    } else {\n      return this._tenantPasswordPolicies[this.tenantId];\n    }\n  }\n\n  async _updatePasswordPolicy(): Promise<void> {\n    const response = await _getPasswordPolicy(this);\n\n    const passwordPolicy: PasswordPolicyInternal = new PasswordPolicyImpl(\n      response\n    );\n\n    if (this.tenantId === null) {\n      this._projectPasswordPolicy = passwordPolicy;\n    } else {\n      this._tenantPasswordPolicies[this.tenantId] = passwordPolicy;\n    }\n  }\n\n  _getPersistenceType(): string {\n    return this.assertedPersistence.persistence.type;\n  }\n\n  _getPersistence(): PersistenceInternal {\n    return this.assertedPersistence.persistence;\n  }\n\n  _updateErrorMap(errorMap: AuthErrorMap): void {\n    this._errorFactory = new ErrorFactory<AuthErrorCode, AuthErrorParams>(\n      'auth',\n      'Firebase',\n      (errorMap as ErrorMapRetriever)()\n    );\n  }\n\n  onAuthStateChanged(\n    nextOrObserver: NextOrObserver<User>,\n    error?: ErrorFn,\n    completed?: CompleteFn\n  ): Unsubscribe {\n    return this.registerStateListener(\n      this.authStateSubscription,\n      nextOrObserver,\n      error,\n      completed\n    );\n  }\n\n  beforeAuthStateChanged(\n    callback: (user: User | null) => void | Promise<void>,\n    onAbort?: () => void\n  ): Unsubscribe {\n    return this.beforeStateQueue.pushCallback(callback, onAbort);\n  }\n\n  onIdTokenChanged(\n    nextOrObserver: NextOrObserver<User>,\n    error?: ErrorFn,\n    completed?: CompleteFn\n  ): Unsubscribe {\n    return this.registerStateListener(\n      this.idTokenSubscription,\n      nextOrObserver,\n      error,\n      completed\n    );\n  }\n\n  authStateReady(): Promise<void> {\n    return new Promise((resolve, reject) => {\n      if (this.currentUser) {\n        resolve();\n      } else {\n        const unsubscribe = this.onAuthStateChanged(() => {\n          unsubscribe();\n          resolve();\n        }, reject);\n      }\n    });\n  }\n\n  /**\n   * Revokes the given access token. Currently only supports Apple OAuth access tokens.\n   */\n  async revokeAccessToken(token: string): Promise<void> {\n    if (this.currentUser) {\n      const idToken = await this.currentUser.getIdToken();\n      // Generalize this to accept other providers once supported.\n      const request: RevokeTokenRequest = {\n        providerId: 'apple.com',\n        tokenType: TokenType.ACCESS_TOKEN,\n        token,\n        idToken\n      };\n      if (this.tenantId != null) {\n        request.tenantId = this.tenantId;\n      }\n      await revokeToken(this, request);\n    }\n  }\n\n  toJSON(): object {\n    return {\n      apiKey: this.config.apiKey,\n      authDomain: this.config.authDomain,\n      appName: this.name,\n      currentUser: this._currentUser?.toJSON()\n    };\n  }\n\n  async _setRedirectUser(\n    user: UserInternal | null,\n    popupRedirectResolver?: PopupRedirectResolver\n  ): Promise<void> {\n    const redirectManager = await this.getOrInitRedirectPersistenceManager(\n      popupRedirectResolver\n    );\n    return user === null\n      ? redirectManager.removeCurrentUser()\n      : redirectManager.setCurrentUser(user);\n  }\n\n  private async getOrInitRedirectPersistenceManager(\n    popupRedirectResolver?: PopupRedirectResolver\n  ): Promise<PersistenceUserManager> {\n    if (!this.redirectPersistenceManager) {\n      const resolver: PopupRedirectResolverInternal | null =\n        (popupRedirectResolver && _getInstance(popupRedirectResolver)) ||\n        this._popupRedirectResolver;\n      _assert(resolver, this, AuthErrorCode.ARGUMENT_ERROR);\n      this.redirectPersistenceManager = await PersistenceUserManager.create(\n        this,\n        [_getInstance(resolver._redirectPersistence)],\n        KeyName.REDIRECT_USER\n      );\n      this.redirectUser =\n        await this.redirectPersistenceManager.getCurrentUser();\n    }\n\n    return this.redirectPersistenceManager;\n  }\n\n  async _redirectUserForId(id: string): Promise<UserInternal | null> {\n    // Make sure we've cleared any pending persistence actions if we're not in\n    // the initializer\n    if (this._isInitialized) {\n      await this.queue(async () => {});\n    }\n\n    if (this._currentUser?._redirectEventId === id) {\n      return this._currentUser;\n    }\n\n    if (this.redirectUser?._redirectEventId === id) {\n      return this.redirectUser;\n    }\n\n    return null;\n  }\n\n  async _persistUserIfCurrent(user: UserInternal): Promise<void> {\n    if (user === this.currentUser) {\n      return this.queue(async () => this.directlySetCurrentUser(user));\n    }\n  }\n\n  /** Notifies listeners only if the user is current */\n  _notifyListenersIfCurrent(user: UserInternal): void {\n    if (user === this.currentUser) {\n      this.notifyAuthListeners();\n    }\n  }\n\n  _key(): string {\n    return `${this.config.authDomain}:${this.config.apiKey}:${this.name}`;\n  }\n\n  _startProactiveRefresh(): void {\n    this.isProactiveRefreshEnabled = true;\n    if (this.currentUser) {\n      this._currentUser._startProactiveRefresh();\n    }\n  }\n\n  _stopProactiveRefresh(): void {\n    this.isProactiveRefreshEnabled = false;\n    if (this.currentUser) {\n      this._currentUser._stopProactiveRefresh();\n    }\n  }\n\n  /** Returns the current user cast as the internal type */\n  get _currentUser(): UserInternal {\n    return this.currentUser as UserInternal;\n  }\n\n  private notifyAuthListeners(): void {\n    if (!this._isInitialized) {\n      return;\n    }\n\n    this.idTokenSubscription.next(this.currentUser);\n\n    const currentUid = this.currentUser?.uid ?? null;\n    if (this.lastNotifiedUid !== currentUid) {\n      this.lastNotifiedUid = currentUid;\n      this.authStateSubscription.next(this.currentUser);\n    }\n  }\n\n  private registerStateListener(\n    subscription: Subscription<User>,\n    nextOrObserver: NextOrObserver<User>,\n    error?: ErrorFn,\n    completed?: CompleteFn\n  ): Unsubscribe {\n    if (this._deleted) {\n      return () => {};\n    }\n\n    const cb =\n      typeof nextOrObserver === 'function'\n        ? nextOrObserver\n        : nextOrObserver.next.bind(nextOrObserver);\n\n    let isUnsubscribed = false;\n\n    const promise = this._isInitialized\n      ? Promise.resolve()\n      : this._initializationPromise;\n    _assert(promise, this, AuthErrorCode.INTERNAL_ERROR);\n    // The callback needs to be called asynchronously per the spec.\n    // eslint-disable-next-line @typescript-eslint/no-floating-promises\n    promise.then(() => {\n      if (isUnsubscribed) {\n        return;\n      }\n      cb(this.currentUser);\n    });\n\n    if (typeof nextOrObserver === 'function') {\n      const unsubscribe = subscription.addObserver(\n        nextOrObserver,\n        error,\n        completed\n      );\n      return () => {\n        isUnsubscribed = true;\n        unsubscribe();\n      };\n    } else {\n      const unsubscribe = subscription.addObserver(nextOrObserver);\n      return () => {\n        isUnsubscribed = true;\n        unsubscribe();\n      };\n    }\n  }\n\n  /**\n   * Unprotected (from race conditions) method to set the current user. This\n   * should only be called from within a queued callback. This is necessary\n   * because the queue shouldn't rely on another queued callback.\n   */\n  private async directlySetCurrentUser(\n    user: UserInternal | null\n  ): Promise<void> {\n    if (this.currentUser && this.currentUser !== user) {\n      this._currentUser._stopProactiveRefresh();\n    }\n    if (user && this.isProactiveRefreshEnabled) {\n      user._startProactiveRefresh();\n    }\n\n    this.currentUser = user;\n\n    if (user) {\n      await this.assertedPersistence.setCurrentUser(user);\n    } else {\n      await this.assertedPersistence.removeCurrentUser();\n    }\n  }\n\n  private queue(action: AsyncAction): Promise<void> {\n    // In case something errors, the callback still should be called in order\n    // to keep the promise chain alive\n    this.operations = this.operations.then(action, action);\n    return this.operations;\n  }\n\n  private get assertedPersistence(): PersistenceUserManager {\n    _assert(this.persistenceManager, this, AuthErrorCode.INTERNAL_ERROR);\n    return this.persistenceManager;\n  }\n\n  private frameworks: string[] = [];\n  private clientVersion: string;\n  _logFramework(framework: string): void {\n    if (!framework || this.frameworks.includes(framework)) {\n      return;\n    }\n    this.frameworks.push(framework);\n\n    // Sort alphabetically so that \"FirebaseCore-web,FirebaseUI-web\" and\n    // \"FirebaseUI-web,FirebaseCore-web\" aren't viewed as different.\n    this.frameworks.sort();\n    this.clientVersion = _getClientVersion(\n      this.config.clientPlatform,\n      this._getFrameworks()\n    );\n  }\n  _getFrameworks(): readonly string[] {\n    return this.frameworks;\n  }\n  async _getAdditionalHeaders(): Promise<Record<string, string>> {\n    // Additional headers on every request\n    const headers: Record<string, string> = {\n      [HttpHeader.X_CLIENT_VERSION]: this.clientVersion\n    };\n\n    if (this.app.options.appId) {\n      headers[HttpHeader.X_FIREBASE_GMPID] = this.app.options.appId;\n    }\n\n    // If the heartbeat service exists, add the heartbeat string\n    const heartbeatsHeader = await this.heartbeatServiceProvider\n      .getImmediate({\n        optional: true\n      })\n      ?.getHeartbeatsHeader();\n    if (heartbeatsHeader) {\n      headers[HttpHeader.X_FIREBASE_CLIENT] = heartbeatsHeader;\n    }\n\n    // If the App Check service exists, add the App Check token in the headers\n    const appCheckToken = await this._getAppCheckToken();\n    if (appCheckToken) {\n      headers[HttpHeader.X_FIREBASE_APP_CHECK] = appCheckToken;\n    }\n\n    return headers;\n  }\n\n  async _getAppCheckToken(): Promise<string | undefined> {\n    if (_isFirebaseServerApp(this.app) && this.app.settings.appCheckToken) {\n      return this.app.settings.appCheckToken;\n    }\n    const appCheckTokenResult = await this.appCheckServiceProvider\n      .getImmediate({ optional: true })\n      ?.getToken();\n    if (appCheckTokenResult?.error) {\n      // Context: appCheck.getToken() will never throw even if an error happened.\n      // In the error case, a dummy token will be returned along with an error field describing\n      // the error. In general, we shouldn't care about the error condition and just use\n      // the token (actual or dummy) to send requests.\n      _logWarn(\n        `Error while retrieving App Check token: ${appCheckTokenResult.error}`\n      );\n    }\n    return appCheckTokenResult?.token;\n  }\n}\n\n/**\n * Method to be used to cast down to our private implementation of Auth.\n * It will also handle unwrapping from the compat type if necessary\n *\n * @param auth Auth object passed in from developer\n */\nexport function _castAuth(auth: Auth): AuthInternal {\n  return getModularInstance(auth) as AuthInternal;\n}\n\n/** Helper class to wrap subscriber logic */\nclass Subscription<T> {\n  private observer: Observer<T | null> | null = null;\n  readonly addObserver: Subscribe<T | null> = createSubscribe(\n    observer => (this.observer = observer)\n  );\n\n  constructor(readonly auth: AuthInternal) {}\n\n  get next(): NextFn<T | null> {\n    _assert(this.observer, this.auth, AuthErrorCode.INTERNAL_ERROR);\n    return this.observer.next.bind(this.observer);\n  }\n}\n","/**\n * @license\n * Copyright 2023 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  _performApiRequest,\n  Endpoint,\n  HttpMethod,\n  _addTidIfNecessary\n} from '../index';\nimport { Auth } from '../../model/public_types';\n\n/**\n * Request object for fetching the password policy.\n */\nexport interface GetPasswordPolicyRequest {\n  tenantId?: string;\n}\n\n/**\n * Response object for fetching the password policy.\n */\nexport interface GetPasswordPolicyResponse {\n  customStrengthOptions: {\n    minPasswordLength?: number;\n    maxPasswordLength?: number;\n    containsLowercaseCharacter?: boolean;\n    containsUppercaseCharacter?: boolean;\n    containsNumericCharacter?: boolean;\n    containsNonAlphanumericCharacter?: boolean;\n  };\n  allowedNonAlphanumericCharacters?: string[];\n  enforcementState: string;\n  forceUpgradeOnSignin?: boolean;\n  schemaVersion: number;\n}\n\n/**\n * Fetches the password policy for the currently set tenant or the project if no tenant is set.\n *\n * @param auth Auth object.\n * @param request Password policy request.\n * @returns Password policy response.\n */\nexport async function _getPasswordPolicy(\n  auth: Auth,\n  request: GetPasswordPolicyRequest = {}\n): Promise<GetPasswordPolicyResponse> {\n  return _performApiRequest<\n    GetPasswordPolicyRequest,\n    GetPasswordPolicyResponse\n  >(\n    auth,\n    HttpMethod.GET,\n    Endpoint.GET_PASSWORD_POLICY,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\ninterface ExternalJSProvider {\n  loadJS(url: string): Promise<Event>;\n  recaptchaV2Script: string;\n  recaptchaEnterpriseScript: string;\n  gapiScript: string;\n}\n\nlet externalJSProvider: ExternalJSProvider = {\n  async loadJS() {\n    throw new Error('Unable to load external scripts');\n  },\n\n  recaptchaV2Script: '',\n  recaptchaEnterpriseScript: '',\n  gapiScript: ''\n};\n\nexport function _setExternalJSProvider(p: ExternalJSProvider): void {\n  externalJSProvider = p;\n}\n\nexport function _loadJS(url: string): Promise<Event> {\n  return externalJSProvider.loadJS(url);\n}\n\nexport function _recaptchaV2ScriptUrl(): string {\n  return externalJSProvider.recaptchaV2Script;\n}\n\nexport function _recaptchaEnterpriseScriptUrl(): string {\n  return externalJSProvider.recaptchaEnterpriseScript;\n}\n\nexport function _gapiScriptUrl(): string {\n  return externalJSProvider.gapiScript;\n}\n\nexport function _generateCallbackName(prefix: string): string {\n  return `__${prefix}${Math.floor(Math.random() * 1000000)}`;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthErrorCode } from '../../core/errors';\nimport { _assert } from '../../core/util/assert';\nimport { AuthInternal } from '../../model/auth';\nimport { RecaptchaParameters } from '../../model/public_types';\nimport {\n  Recaptcha,\n  GreCAPTCHATopLevel,\n  GreCAPTCHARenderOption,\n  GreCAPTCHA\n} from './recaptcha';\n\nexport const _SOLVE_TIME_MS = 500;\nexport const _EXPIRATION_TIME_MS = 60_000;\nexport const _WIDGET_ID_START = 1_000_000_000_000;\n\nexport interface Widget {\n  getResponse: () => string | null;\n  delete: () => void;\n  execute: () => void;\n}\n\nexport class MockReCaptcha implements Recaptcha {\n  private counter = _WIDGET_ID_START;\n  _widgets = new Map<number, Widget>();\n\n  constructor(private readonly auth: AuthInternal) {}\n\n  render(\n    container: string | HTMLElement,\n    parameters?: RecaptchaParameters\n  ): number {\n    const id = this.counter;\n    this._widgets.set(\n      id,\n      new MockWidget(container, this.auth.name, parameters || {})\n    );\n    this.counter++;\n    return id;\n  }\n\n  reset(optWidgetId?: number): void {\n    const id = optWidgetId || _WIDGET_ID_START;\n    void this._widgets.get(id)?.delete();\n    this._widgets.delete(id);\n  }\n\n  getResponse(optWidgetId?: number): string {\n    const id = optWidgetId || _WIDGET_ID_START;\n    return this._widgets.get(id)?.getResponse() || '';\n  }\n\n  async execute(optWidgetId?: number | string): Promise<string> {\n    const id: number = (optWidgetId as number) || _WIDGET_ID_START;\n    void this._widgets.get(id)?.execute();\n    return '';\n  }\n}\n\nexport class MockGreCAPTCHATopLevel implements GreCAPTCHATopLevel {\n  enterprise: GreCAPTCHA = new MockGreCAPTCHA();\n  ready(callback: () => void): void {\n    callback();\n  }\n\n  execute(\n    // eslint-disable-next-line @typescript-eslint/no-unused-vars\n    _siteKey: string,\n    _options: { action: string }\n  ): Promise<string> {\n    return Promise.resolve('token');\n  }\n  render(\n    // eslint-disable-next-line @typescript-eslint/no-unused-vars\n    _container: string | HTMLElement,\n    _parameters: GreCAPTCHARenderOption\n  ): string {\n    return '';\n  }\n}\n\nexport class MockGreCAPTCHA implements GreCAPTCHA {\n  ready(callback: () => void): void {\n    callback();\n  }\n\n  execute(\n    // eslint-disable-next-line @typescript-eslint/no-unused-vars\n    _siteKey: string,\n    _options: { action: string }\n  ): Promise<string> {\n    return Promise.resolve('token');\n  }\n  render(\n    // eslint-disable-next-line @typescript-eslint/no-unused-vars\n    _container: string | HTMLElement,\n    _parameters: GreCAPTCHARenderOption\n  ): string {\n    return '';\n  }\n}\n\nexport class MockWidget {\n  private readonly container: HTMLElement;\n  private readonly isVisible: boolean;\n  private timerId: number | null = null;\n  private deleted = false;\n  private responseToken: string | null = null;\n  private readonly clickHandler = (): void => {\n    this.execute();\n  };\n\n  constructor(\n    containerOrId: string | HTMLElement,\n    appName: string,\n    private readonly params: RecaptchaParameters\n  ) {\n    const container =\n      typeof containerOrId === 'string'\n        ? document.getElementById(containerOrId)\n        : containerOrId;\n    _assert(container, AuthErrorCode.ARGUMENT_ERROR, { appName });\n\n    this.container = container;\n    this.isVisible = this.params.size !== 'invisible';\n    if (this.isVisible) {\n      this.execute();\n    } else {\n      this.container.addEventListener('click', this.clickHandler);\n    }\n  }\n\n  getResponse(): string | null {\n    this.checkIfDeleted();\n    return this.responseToken;\n  }\n\n  delete(): void {\n    this.checkIfDeleted();\n    this.deleted = true;\n    if (this.timerId) {\n      clearTimeout(this.timerId);\n      this.timerId = null;\n    }\n    this.container.removeEventListener('click', this.clickHandler);\n  }\n\n  execute(): void {\n    this.checkIfDeleted();\n    if (this.timerId) {\n      return;\n    }\n\n    this.timerId = window.setTimeout(() => {\n      this.responseToken = generateRandomAlphaNumericString(50);\n      const { callback, 'expired-callback': expiredCallback } = this.params;\n      if (callback) {\n        try {\n          callback(this.responseToken);\n        } catch (e) {}\n      }\n\n      this.timerId = window.setTimeout(() => {\n        this.timerId = null;\n        this.responseToken = null;\n        if (expiredCallback) {\n          try {\n            expiredCallback();\n          } catch (e) {}\n        }\n\n        if (this.isVisible) {\n          this.execute();\n        }\n      }, _EXPIRATION_TIME_MS);\n    }, _SOLVE_TIME_MS);\n  }\n\n  private checkIfDeleted(): void {\n    if (this.deleted) {\n      throw new Error('reCAPTCHA mock was already deleted!');\n    }\n  }\n}\n\nfunction generateRandomAlphaNumericString(len: number): string {\n  const chars = [];\n  const allowedChars =\n    '1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';\n  for (let i = 0; i < len; i++) {\n    chars.push(\n      allowedChars.charAt(Math.floor(Math.random() * allowedChars.length))\n    );\n  }\n  return chars.join('');\n}\n","/* eslint-disable @typescript-eslint/no-require-imports */\n/**\n * @license\n * Copyright 2022 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { isEnterprise, RecaptchaConfig } from './recaptcha';\nimport { getRecaptchaConfig } from '../../api/authentication/recaptcha';\nimport {\n  RecaptchaClientType,\n  RecaptchaVersion,\n  RecaptchaActionName,\n  RecaptchaAuthProvider,\n  EnforcementState\n} from '../../api';\n\nimport { Auth } from '../../model/public_types';\nimport { AuthInternal } from '../../model/auth';\nimport { _castAuth } from '../../core/auth/auth_impl';\nimport * as jsHelpers from '../load_js';\nimport { AuthErrorCode } from '../../core/errors';\nimport { StartPhoneMfaEnrollmentRequest } from '../../api/account_management/mfa';\nimport { StartPhoneMfaSignInRequest } from '../../api/authentication/mfa';\nimport { MockGreCAPTCHATopLevel } from './recaptcha_mock';\n\nexport const RECAPTCHA_ENTERPRISE_VERIFIER_TYPE = 'recaptcha-enterprise';\nexport const FAKE_TOKEN = 'NO_RECAPTCHA';\n\nexport class RecaptchaEnterpriseVerifier {\n  /**\n   * Identifies the type of application verifier (e.g. \"recaptcha-enterprise\").\n   */\n  readonly type = RECAPTCHA_ENTERPRISE_VERIFIER_TYPE;\n\n  private readonly auth: AuthInternal;\n\n  /**\n   *\n   * @param authExtern - The corresponding Firebase {@link Auth} instance.\n   *\n   */\n  constructor(authExtern: Auth) {\n    this.auth = _castAuth(authExtern);\n  }\n\n  /**\n   * Executes the verification process.\n   *\n   * @returns A Promise for a token that can be used to assert the validity of a request.\n   */\n  async verify(\n    action: string = 'verify',\n    forceRefresh = false\n  ): Promise<string> {\n    async function retrieveSiteKey(auth: AuthInternal): Promise<string> {\n      if (!forceRefresh) {\n        if (auth.tenantId == null && auth._agentRecaptchaConfig != null) {\n          return auth._agentRecaptchaConfig.siteKey;\n        }\n        if (\n          auth.tenantId != null &&\n          auth._tenantRecaptchaConfigs[auth.tenantId] !== undefined\n        ) {\n          return auth._tenantRecaptchaConfigs[auth.tenantId].siteKey;\n        }\n      }\n\n      return new Promise<string>(async (resolve, reject) => {\n        getRecaptchaConfig(auth, {\n          clientType: RecaptchaClientType.WEB,\n          version: RecaptchaVersion.ENTERPRISE\n        })\n          .then(response => {\n            if (response.recaptchaKey === undefined) {\n              reject(new Error('recaptcha Enterprise site key undefined'));\n            } else {\n              const config = new RecaptchaConfig(response);\n              if (auth.tenantId == null) {\n                auth._agentRecaptchaConfig = config;\n              } else {\n                auth._tenantRecaptchaConfigs[auth.tenantId] = config;\n              }\n              return resolve(config.siteKey);\n            }\n          })\n          .catch(error => {\n            reject(error);\n          });\n      });\n    }\n\n    function retrieveRecaptchaToken(\n      siteKey: string,\n      resolve: (value: string | PromiseLike<string>) => void,\n      reject: (reason?: unknown) => void\n    ): void {\n      const grecaptcha = window.grecaptcha;\n      if (isEnterprise(grecaptcha)) {\n        grecaptcha.enterprise.ready(() => {\n          grecaptcha.enterprise\n            .execute(siteKey, { action })\n            .then(token => {\n              resolve(token);\n            })\n            .catch(() => {\n              resolve(FAKE_TOKEN);\n            });\n        });\n      } else {\n        reject(Error('No reCAPTCHA enterprise script loaded.'));\n      }\n    }\n\n    // Returns Promise for a mock token when appVerificationDisabledForTesting is true.\n    if (this.auth.settings.appVerificationDisabledForTesting) {\n      const mockRecaptcha = new MockGreCAPTCHATopLevel();\n      return mockRecaptcha.execute('siteKey', { action: 'verify' });\n    }\n\n    return new Promise<string>((resolve, reject) => {\n      retrieveSiteKey(this.auth)\n        .then(siteKey => {\n          if (!forceRefresh && isEnterprise(window.grecaptcha)) {\n            retrieveRecaptchaToken(siteKey, resolve, reject);\n          } else {\n            if (typeof window === 'undefined') {\n              reject(\n                new Error('RecaptchaVerifier is only supported in browser')\n              );\n              return;\n            }\n            let url = jsHelpers._recaptchaEnterpriseScriptUrl();\n            if (url.length !== 0) {\n              url += siteKey;\n            }\n            jsHelpers\n              ._loadJS(url)\n              .then(() => {\n                retrieveRecaptchaToken(siteKey, resolve, reject);\n              })\n              .catch(error => {\n                reject(error);\n              });\n          }\n        })\n        .catch(error => {\n          reject(error);\n        });\n    });\n  }\n}\n\nexport async function injectRecaptchaFields<T extends object>(\n  auth: AuthInternal,\n  request: T,\n  action: RecaptchaActionName,\n  isCaptchaResp = false,\n  isFakeToken = false\n): Promise<T> {\n  const verifier = new RecaptchaEnterpriseVerifier(auth);\n  let captchaResponse;\n\n  if (isFakeToken) {\n    captchaResponse = FAKE_TOKEN;\n  } else {\n    try {\n      captchaResponse = await verifier.verify(action);\n    } catch (error) {\n      captchaResponse = await verifier.verify(action, true);\n    }\n  }\n\n  const newRequest = { ...request };\n  if (\n    action === RecaptchaActionName.MFA_SMS_ENROLLMENT ||\n    action === RecaptchaActionName.MFA_SMS_SIGNIN\n  ) {\n    if ('phoneEnrollmentInfo' in newRequest) {\n      const phoneNumber = (\n        newRequest as unknown as StartPhoneMfaEnrollmentRequest\n      ).phoneEnrollmentInfo.phoneNumber;\n      const recaptchaToken = (\n        newRequest as unknown as StartPhoneMfaEnrollmentRequest\n      ).phoneEnrollmentInfo.recaptchaToken;\n\n      Object.assign(newRequest, {\n        'phoneEnrollmentInfo': {\n          phoneNumber,\n          recaptchaToken,\n          captchaResponse,\n          'clientType': RecaptchaClientType.WEB,\n          'recaptchaVersion': RecaptchaVersion.ENTERPRISE\n        }\n      });\n    } else if ('phoneSignInInfo' in newRequest) {\n      const recaptchaToken = (\n        newRequest as unknown as StartPhoneMfaSignInRequest\n      ).phoneSignInInfo.recaptchaToken;\n\n      Object.assign(newRequest, {\n        'phoneSignInInfo': {\n          recaptchaToken,\n          captchaResponse,\n          'clientType': RecaptchaClientType.WEB,\n          'recaptchaVersion': RecaptchaVersion.ENTERPRISE\n        }\n      });\n    }\n    return newRequest;\n  }\n\n  if (!isCaptchaResp) {\n    Object.assign(newRequest, { captchaResponse });\n  } else {\n    Object.assign(newRequest, { 'captchaResp': captchaResponse });\n  }\n  Object.assign(newRequest, { 'clientType': RecaptchaClientType.WEB });\n  Object.assign(newRequest, {\n    'recaptchaVersion': RecaptchaVersion.ENTERPRISE\n  });\n  return newRequest;\n}\n\ntype ActionMethod<TRequest, TResponse> = (\n  auth: AuthInternal,\n  request: TRequest\n) => Promise<TResponse>;\n\nexport async function handleRecaptchaFlow<TRequest extends object, TResponse>(\n  authInstance: AuthInternal,\n  request: TRequest,\n  actionName: RecaptchaActionName,\n  actionMethod: ActionMethod<TRequest, TResponse>,\n  recaptchaAuthProvider: RecaptchaAuthProvider\n): Promise<TResponse> {\n  if (recaptchaAuthProvider === RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER) {\n    if (\n      authInstance\n        ._getRecaptchaConfig()\n        ?.isProviderEnabled(RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER)\n    ) {\n      const requestWithRecaptcha = await injectRecaptchaFields(\n        authInstance,\n        request,\n        actionName,\n        actionName === RecaptchaActionName.GET_OOB_CODE\n      );\n      return actionMethod(authInstance, requestWithRecaptcha);\n    } else {\n      return actionMethod(authInstance, request).catch(async error => {\n        if (error.code === `auth/${AuthErrorCode.MISSING_RECAPTCHA_TOKEN}`) {\n          console.log(\n            `${actionName} is protected by reCAPTCHA Enterprise for this project. Automatically triggering the reCAPTCHA flow and restarting the flow.`\n          );\n          const requestWithRecaptcha = await injectRecaptchaFields(\n            authInstance,\n            request,\n            actionName,\n            actionName === RecaptchaActionName.GET_OOB_CODE\n          );\n          return actionMethod(authInstance, requestWithRecaptcha);\n        } else {\n          return Promise.reject(error);\n        }\n      });\n    }\n  } else if (recaptchaAuthProvider === RecaptchaAuthProvider.PHONE_PROVIDER) {\n    if (\n      authInstance\n        ._getRecaptchaConfig()\n        ?.isProviderEnabled(RecaptchaAuthProvider.PHONE_PROVIDER)\n    ) {\n      const requestWithRecaptcha = await injectRecaptchaFields(\n        authInstance,\n        request,\n        actionName\n      );\n\n      return actionMethod(authInstance, requestWithRecaptcha).catch(\n        async error => {\n          if (\n            authInstance\n              ._getRecaptchaConfig()\n              ?.getProviderEnforcementState(\n                RecaptchaAuthProvider.PHONE_PROVIDER\n              ) === EnforcementState.AUDIT\n          ) {\n            // AUDIT mode\n            if (\n              error.code === `auth/${AuthErrorCode.MISSING_RECAPTCHA_TOKEN}` ||\n              error.code === `auth/${AuthErrorCode.INVALID_APP_CREDENTIAL}`\n            ) {\n              console.log(\n                `Failed to verify with reCAPTCHA Enterprise. Automatically triggering the reCAPTCHA v2 flow to complete the ${actionName} flow.`\n              );\n              // reCAPTCHA Enterprise token is missing or reCAPTCHA Enterprise token\n              // check fails.\n              // Fallback to reCAPTCHA v2 flow.\n              const requestWithRecaptchaFields = await injectRecaptchaFields(\n                authInstance,\n                request,\n                actionName,\n                false, // isCaptchaResp\n                true // isFakeToken\n              );\n              // This will call the PhoneApiCaller to fetch and inject reCAPTCHA v2 token.\n              return actionMethod(authInstance, requestWithRecaptchaFields);\n            }\n          }\n          // ENFORCE mode or AUDIT mode with any other error.\n          return Promise.reject(error);\n        }\n      );\n    } else {\n      // Do reCAPTCHA v2 flow.\n      const requestWithRecaptchaFields = await injectRecaptchaFields(\n        authInstance,\n        request,\n        actionName,\n        false, // isCaptchaResp\n        true // isFakeToken\n      );\n\n      // This will call the PhoneApiCaller to fetch and inject v2 token.\n      return actionMethod(authInstance, requestWithRecaptchaFields);\n    }\n  } else {\n    return Promise.reject(\n      recaptchaAuthProvider + ' provider is not supported.'\n    );\n  }\n}\n\nexport async function _initializeRecaptchaConfig(auth: Auth): Promise<void> {\n  const authInternal = _castAuth(auth);\n\n  const response = await getRecaptchaConfig(authInternal, {\n    clientType: RecaptchaClientType.WEB,\n    version: RecaptchaVersion.ENTERPRISE\n  });\n\n  const config = new RecaptchaConfig(response);\n  if (authInternal.tenantId == null) {\n    authInternal._agentRecaptchaConfig = config;\n  } else {\n    authInternal._tenantRecaptchaConfigs[authInternal.tenantId] = config;\n  }\n\n  if (config.isAnyProviderEnabled()) {\n    const verifier = new RecaptchaEnterpriseVerifier(authInternal);\n    void verifier.verify();\n  }\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\nimport { Auth } from '../../model/public_types';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\nimport { _castAuth } from './auth_impl';\nimport { deepEqual, isCloudWorkstation, pingServer } from '@firebase/util';\n\n/**\n * Changes the {@link Auth} instance to communicate with the Firebase Auth Emulator, instead of production\n * Firebase Auth services.\n *\n * @remarks\n * This must be called synchronously immediately following the first call to\n * {@link initializeAuth}.  Do not use with production credentials as emulator\n * traffic is not encrypted.\n *\n *\n * @example\n * ```javascript\n * connectAuthEmulator(auth, 'http://127.0.0.1:9099', { disableWarnings: true });\n * ```\n *\n * @param auth - The {@link Auth} instance.\n * @param url - The URL at which the emulator is running (eg, 'http://localhost:9099').\n * @param options - Optional. `options.disableWarnings` defaults to `false`. Set it to\n * `true` to disable the warning banner attached to the DOM.\n *\n * @public\n */\nexport function connectAuthEmulator(\n  auth: Auth,\n  url: string,\n  options?: { disableWarnings: boolean }\n): void {\n  const authInternal = _castAuth(auth);\n  _assert(\n    /^https?:\\/\\//.test(url),\n    authInternal,\n    AuthErrorCode.INVALID_EMULATOR_SCHEME\n  );\n\n  const disableWarnings = !!options?.disableWarnings;\n\n  const protocol = extractProtocol(url);\n  const { host, port } = extractHostAndPort(url);\n  const portStr = port === null ? '' : `:${port}`;\n\n  // Always replace path with \"/\" (even if input url had no path at all, or had a different one).\n  const emulator = { url: `${protocol}//${host}${portStr}/` };\n  const emulatorConfig = Object.freeze({\n    host,\n    port,\n    protocol: protocol.replace(':', ''),\n    options: Object.freeze({ disableWarnings })\n  });\n\n  // There are a few scenarios to guard against if the Auth instance has already started:\n  if (!authInternal._canInitEmulator) {\n    // Applications may not initialize the emulator for the first time if Auth has already started\n    // to make network requests.\n    _assert(\n      authInternal.config.emulator && authInternal.emulatorConfig,\n      authInternal,\n      AuthErrorCode.EMULATOR_CONFIG_FAILED\n    );\n\n    // Applications may not alter the configuration of the emulator (aka pass a different config)\n    // once Auth has started to make network requests.\n    _assert(\n      deepEqual(emulator, authInternal.config.emulator) &&\n        deepEqual(emulatorConfig, authInternal.emulatorConfig),\n      authInternal,\n      AuthErrorCode.EMULATOR_CONFIG_FAILED\n    );\n\n    // It's valid, however, to invoke connectAuthEmulator() after Auth has started making\n    // connections, so long as the config matches the existing config. This results in a no-op.\n    return;\n  }\n\n  authInternal.config.emulator = emulator;\n  authInternal.emulatorConfig = emulatorConfig;\n  authInternal.settings.appVerificationDisabledForTesting = true;\n\n  // Workaround to get cookies in Firebase Studio\n  if (isCloudWorkstation(host)) {\n    void pingServer(`${protocol}//${host}${portStr}`);\n  } else if (!disableWarnings) {\n    emitEmulatorWarning();\n  }\n}\n\nfunction extractProtocol(url: string): string {\n  const protocolEnd = url.indexOf(':');\n  return protocolEnd < 0 ? '' : url.substr(0, protocolEnd + 1);\n}\n\nfunction extractHostAndPort(url: string): {\n  host: string;\n  port: number | null;\n} {\n  const protocol = extractProtocol(url);\n  const authority = /(\\/\\/)?([^?#/]+)/.exec(url.substr(protocol.length)); // Between // and /, ? or #.\n  if (!authority) {\n    return { host: '', port: null };\n  }\n  const hostAndPort = authority[2].split('@').pop() || ''; // Strip out \"username:password@\".\n  const bracketedIPv6 = /^(\\[[^\\]]+\\])(:|$)/.exec(hostAndPort);\n  if (bracketedIPv6) {\n    const host = bracketedIPv6[1];\n    return { host, port: parsePort(hostAndPort.substr(host.length + 1)) };\n  } else {\n    const [host, port] = hostAndPort.split(':');\n    return { host, port: parsePort(port) };\n  }\n}\n\nfunction parsePort(portStr: string): number | null {\n  if (!portStr) {\n    return null;\n  }\n  const port = Number(portStr);\n  if (isNaN(port)) {\n    return null;\n  }\n  return port;\n}\n\nfunction emitEmulatorWarning(): void {\n  function attachBanner(): void {\n    const el = document.createElement('p');\n    const sty = el.style;\n    el.innerText =\n      'Running in emulator mode. Do not use with production credentials.';\n    sty.position = 'fixed';\n    sty.width = '100%';\n    sty.backgroundColor = '#ffffff';\n    sty.border = '.1em solid #000000';\n    sty.color = '#b50000';\n    sty.bottom = '0px';\n    sty.left = '0px';\n    sty.margin = '0px';\n    sty.zIndex = '10000';\n    sty.textAlign = 'center';\n    el.classList.add('firebase-emulator-warning');\n    document.body.appendChild(el);\n  }\n\n  if (typeof console !== 'undefined' && typeof console.info === 'function') {\n    console.info(\n      'WARNING: You are using the Auth Emulator,' +\n        ' which is intended for local testing only.  Do not use with' +\n        ' production credentials.'\n    );\n  }\n  if (typeof window !== 'undefined' && typeof document !== 'undefined') {\n    if (document.readyState === 'loading') {\n      window.addEventListener('DOMContentLoaded', attachBanner);\n    } else {\n      attachBanner();\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { PhoneOrOauthTokenResponse } from '../../api/authentication/mfa';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { debugFail } from '../util/assert';\n\n/**\n * Interface that represents the credentials returned by an {@link AuthProvider}.\n *\n * @remarks\n * Implementations specify the details about each auth provider's credential requirements.\n *\n * @public\n */\nexport class AuthCredential {\n  /** @internal */\n  protected constructor(\n    /**\n     * The authentication provider ID for the credential.\n     *\n     * @remarks\n     * For example, 'facebook.com', or 'google.com'.\n     */\n    readonly providerId: string,\n    /**\n     * The authentication sign in method for the credential.\n     *\n     * @remarks\n     * For example, {@link SignInMethod}.EMAIL_PASSWORD, or\n     * {@link SignInMethod}.EMAIL_LINK. This corresponds to the sign-in method\n     * identifier as returned in {@link fetchSignInMethodsForEmail}.\n     */\n    readonly signInMethod: string\n  ) {}\n\n  /**\n   * Returns a JSON-serializable representation of this object.\n   *\n   * @returns a JSON-serializable representation of this object.\n   */\n  toJSON(): object {\n    return debugFail('not implemented');\n  }\n\n  /** @internal */\n  _getIdTokenResponse(_auth: AuthInternal): Promise<PhoneOrOauthTokenResponse> {\n    return debugFail('not implemented');\n  }\n  /** @internal */\n  _linkToIdToken(\n    _auth: AuthInternal,\n    _idToken: string\n  ): Promise<IdTokenResponse> {\n    return debugFail('not implemented');\n  }\n  /** @internal */\n  _getReauthenticationResolver(_auth: AuthInternal): Promise<IdTokenResponse> {\n    return debugFail('not implemented');\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { ActionCodeOperation, Auth } from '../../model/public_types';\n\nimport {\n  Endpoint,\n  HttpMethod,\n  _addTidIfNecessary,\n  _performApiRequest\n} from '../index';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { MfaEnrollment } from './mfa';\nimport { SignUpRequest, SignUpResponse } from '../authentication/sign_up';\n\nexport interface ResetPasswordRequest {\n  oobCode: string;\n  newPassword?: string;\n  tenantId?: string;\n}\n\nexport interface ResetPasswordResponse {\n  email: string;\n  newEmail?: string;\n  requestType?: ActionCodeOperation;\n  mfaInfo?: MfaEnrollment;\n}\n\nexport async function resetPassword(\n  auth: Auth,\n  request: ResetPasswordRequest\n): Promise<ResetPasswordResponse> {\n  return _performApiRequest<ResetPasswordRequest, ResetPasswordResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.RESET_PASSWORD,\n    _addTidIfNecessary(auth, request)\n  );\n}\nexport interface UpdateEmailPasswordRequest {\n  idToken: string;\n  returnSecureToken?: boolean;\n  email?: string;\n  password?: string;\n}\n\nexport interface UpdateEmailPasswordResponse extends IdTokenResponse {}\n\nexport async function updateEmailPassword(\n  auth: Auth,\n  request: UpdateEmailPasswordRequest\n): Promise<UpdateEmailPasswordResponse> {\n  return _performApiRequest<\n    UpdateEmailPasswordRequest,\n    UpdateEmailPasswordResponse\n  >(auth, HttpMethod.POST, Endpoint.SET_ACCOUNT_INFO, request);\n}\n\n// Used for linking an email/password account to an existing idToken. Uses the same request/response\n// format as updateEmailPassword.\nexport async function linkEmailPassword(\n  auth: Auth,\n  request: SignUpRequest\n): Promise<SignUpResponse> {\n  return _performApiRequest<SignUpRequest, SignUpResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_UP,\n    request\n  );\n}\n\nexport interface ApplyActionCodeRequest {\n  oobCode: string;\n  tenantId?: string;\n}\n\nexport interface ApplyActionCodeResponse {}\n\nexport async function applyActionCode(\n  auth: Auth,\n  request: ApplyActionCodeRequest\n): Promise<ApplyActionCodeResponse> {\n  return _performApiRequest<ApplyActionCodeRequest, ApplyActionCodeResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SET_ACCOUNT_INFO,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { ActionCodeOperation, Auth } from '../../model/public_types';\n\nimport {\n  Endpoint,\n  HttpMethod,\n  RecaptchaClientType,\n  RecaptchaVersion,\n  _addTidIfNecessary,\n  _performApiRequest,\n  _performSignInRequest\n} from '../index';\nimport { IdToken, IdTokenResponse } from '../../model/id_token';\n\nexport interface SignInWithPasswordRequest {\n  returnSecureToken?: boolean;\n  email: string;\n  password: string;\n  tenantId?: string;\n  captchaResponse?: string;\n  clientType?: RecaptchaClientType;\n  recaptchaVersion?: RecaptchaVersion;\n}\n\nexport interface SignInWithPasswordResponse extends IdTokenResponse {\n  email: string;\n  displayName: string;\n}\n\nexport async function signInWithPassword(\n  auth: Auth,\n  request: SignInWithPasswordRequest\n): Promise<SignInWithPasswordResponse> {\n  return _performSignInRequest<\n    SignInWithPasswordRequest,\n    SignInWithPasswordResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_PASSWORD,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport interface GetOobCodeRequest {\n  email?: string; // Everything except VERIFY_AND_CHANGE_EMAIL\n  continueUrl?: string;\n  iOSBundleId?: string;\n  iosAppStoreId?: string;\n  androidPackageName?: string;\n  androidInstallApp?: boolean;\n  androidMinimumVersionCode?: string;\n  canHandleCodeInApp?: boolean;\n  dynamicLinkDomain?: string;\n  tenantId?: string;\n  targetProjectid?: string;\n  linkDomain?: string;\n}\n\nexport interface VerifyEmailRequest extends GetOobCodeRequest {\n  requestType: ActionCodeOperation.VERIFY_EMAIL;\n  idToken: IdToken;\n}\n\nexport interface PasswordResetRequest extends GetOobCodeRequest {\n  requestType: ActionCodeOperation.PASSWORD_RESET;\n  email: string;\n  captchaResp?: string;\n  clientType?: RecaptchaClientType;\n  recaptchaVersion?: RecaptchaVersion;\n}\n\nexport interface EmailSignInRequest extends GetOobCodeRequest {\n  requestType: ActionCodeOperation.EMAIL_SIGNIN;\n  email: string;\n  captchaResp?: string;\n  clientType?: RecaptchaClientType;\n  recaptchaVersion?: RecaptchaVersion;\n}\n\nexport interface VerifyAndChangeEmailRequest extends GetOobCodeRequest {\n  requestType: ActionCodeOperation.VERIFY_AND_CHANGE_EMAIL;\n  idToken: IdToken;\n  newEmail: string;\n}\n\ninterface GetOobCodeResponse {\n  email: string;\n}\n\nexport interface VerifyEmailResponse extends GetOobCodeResponse {}\nexport interface PasswordResetResponse extends GetOobCodeResponse {}\nexport interface EmailSignInResponse extends GetOobCodeResponse {}\nexport interface VerifyAndChangeEmailResponse extends GetOobCodeRequest {}\n\nasync function sendOobCode(\n  auth: Auth,\n  request: GetOobCodeRequest\n): Promise<GetOobCodeResponse> {\n  return _performApiRequest<GetOobCodeRequest, GetOobCodeResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SEND_OOB_CODE,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport async function sendEmailVerification(\n  auth: Auth,\n  request: VerifyEmailRequest\n): Promise<VerifyEmailResponse> {\n  return sendOobCode(auth, request);\n}\n\nexport async function sendPasswordResetEmail(\n  auth: Auth,\n  request: PasswordResetRequest\n): Promise<PasswordResetResponse> {\n  return sendOobCode(auth, request);\n}\n\nexport async function sendSignInLinkToEmail(\n  auth: Auth,\n  request: EmailSignInRequest\n): Promise<EmailSignInResponse> {\n  return sendOobCode(auth, request);\n}\n\nexport async function verifyAndChangeEmail(\n  auth: Auth,\n  request: VerifyAndChangeEmailRequest\n): Promise<VerifyAndChangeEmailResponse> {\n  return sendOobCode(auth, request);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { ProviderId, SignInMethod } from '../../model/enums';\n\nimport { linkEmailPassword } from '../../api/account_management/email_and_password';\nimport {\n  signInWithPassword,\n  SignInWithPasswordRequest\n} from '../../api/authentication/email_and_password';\nimport {\n  signInWithEmailLink,\n  signInWithEmailLinkForLinking\n} from '../../api/authentication/email_link';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { AuthErrorCode } from '../errors';\nimport { _fail } from '../util/assert';\nimport { AuthCredential } from './auth_credential';\nimport { handleRecaptchaFlow } from '../../platform_browser/recaptcha/recaptcha_enterprise_verifier';\nimport {\n  RecaptchaActionName,\n  RecaptchaClientType,\n  RecaptchaAuthProvider\n} from '../../api';\nimport { SignUpRequest } from '../../api/authentication/sign_up';\n/**\n * Interface that represents the credentials returned by {@link EmailAuthProvider} for\n * {@link ProviderId}.PASSWORD\n *\n * @remarks\n * Covers both {@link SignInMethod}.EMAIL_PASSWORD and\n * {@link SignInMethod}.EMAIL_LINK.\n *\n * @public\n */\nexport class EmailAuthCredential extends AuthCredential {\n  /** @internal */\n  private constructor(\n    /** @internal */\n    readonly _email: string,\n    /** @internal */\n    readonly _password: string,\n    signInMethod: SignInMethod,\n    /** @internal */\n    readonly _tenantId: string | null = null\n  ) {\n    super(ProviderId.PASSWORD, signInMethod);\n  }\n\n  /** @internal */\n  static _fromEmailAndPassword(\n    email: string,\n    password: string\n  ): EmailAuthCredential {\n    return new EmailAuthCredential(\n      email,\n      password,\n      SignInMethod.EMAIL_PASSWORD\n    );\n  }\n\n  /** @internal */\n  static _fromEmailAndCode(\n    email: string,\n    oobCode: string,\n    tenantId: string | null = null\n  ): EmailAuthCredential {\n    return new EmailAuthCredential(\n      email,\n      oobCode,\n      SignInMethod.EMAIL_LINK,\n      tenantId\n    );\n  }\n\n  /** {@inheritdoc AuthCredential.toJSON} */\n  toJSON(): object {\n    return {\n      email: this._email,\n      password: this._password,\n      signInMethod: this.signInMethod,\n      tenantId: this._tenantId\n    };\n  }\n\n  /**\n   * Static method to deserialize a JSON representation of an object into an {@link  AuthCredential}.\n   *\n   * @param json - Either `object` or the stringified representation of the object. When string is\n   * provided, `JSON.parse` would be called first.\n   *\n   * @returns If the JSON input does not represent an {@link AuthCredential}, null is returned.\n   */\n  static fromJSON(json: object | string): EmailAuthCredential | null {\n    const obj = typeof json === 'string' ? JSON.parse(json) : json;\n    if (obj?.email && obj?.password) {\n      if (obj.signInMethod === SignInMethod.EMAIL_PASSWORD) {\n        return this._fromEmailAndPassword(obj.email, obj.password);\n      } else if (obj.signInMethod === SignInMethod.EMAIL_LINK) {\n        return this._fromEmailAndCode(obj.email, obj.password, obj.tenantId);\n      }\n    }\n    return null;\n  }\n\n  /** @internal */\n  async _getIdTokenResponse(auth: AuthInternal): Promise<IdTokenResponse> {\n    switch (this.signInMethod) {\n      case SignInMethod.EMAIL_PASSWORD:\n        const request: SignInWithPasswordRequest = {\n          returnSecureToken: true,\n          email: this._email,\n          password: this._password,\n          clientType: RecaptchaClientType.WEB\n        };\n        return handleRecaptchaFlow(\n          auth,\n          request,\n          RecaptchaActionName.SIGN_IN_WITH_PASSWORD,\n          signInWithPassword,\n          RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER\n        );\n      case SignInMethod.EMAIL_LINK:\n        return signInWithEmailLink(auth, {\n          email: this._email,\n          oobCode: this._password\n        });\n      default:\n        _fail(auth, AuthErrorCode.INTERNAL_ERROR);\n    }\n  }\n\n  /** @internal */\n  async _linkToIdToken(\n    auth: AuthInternal,\n    idToken: string\n  ): Promise<IdTokenResponse> {\n    switch (this.signInMethod) {\n      case SignInMethod.EMAIL_PASSWORD:\n        const request: SignUpRequest = {\n          idToken,\n          returnSecureToken: true,\n          email: this._email,\n          password: this._password,\n          clientType: RecaptchaClientType.WEB\n        };\n        return handleRecaptchaFlow(\n          auth,\n          request,\n          RecaptchaActionName.SIGN_UP_PASSWORD,\n          linkEmailPassword,\n          RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER\n        );\n      case SignInMethod.EMAIL_LINK:\n        return signInWithEmailLinkForLinking(auth, {\n          idToken,\n          email: this._email,\n          oobCode: this._password\n        });\n      default:\n        _fail(auth, AuthErrorCode.INTERNAL_ERROR);\n    }\n  }\n\n  /** @internal */\n  _getReauthenticationResolver(auth: AuthInternal): Promise<IdTokenResponse> {\n    return this._getIdTokenResponse(auth);\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  _performSignInRequest,\n  Endpoint,\n  HttpMethod,\n  _addTidIfNecessary\n} from '../index';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { Auth } from '../../model/public_types';\n\nexport interface SignInWithEmailLinkRequest {\n  email: string;\n  oobCode: string;\n  tenantId?: string;\n}\n\nexport interface SignInWithEmailLinkResponse extends IdTokenResponse {\n  email: string;\n  isNewUser: boolean;\n}\n\nexport async function signInWithEmailLink(\n  auth: Auth,\n  request: SignInWithEmailLinkRequest\n): Promise<SignInWithEmailLinkResponse> {\n  return _performSignInRequest<\n    SignInWithEmailLinkRequest,\n    SignInWithEmailLinkResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_EMAIL_LINK,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport interface SignInWithEmailLinkForLinkingRequest\n  extends SignInWithEmailLinkRequest {\n  idToken: string;\n}\n\nexport async function signInWithEmailLinkForLinking(\n  auth: Auth,\n  request: SignInWithEmailLinkForLinkingRequest\n): Promise<SignInWithEmailLinkResponse> {\n  return _performSignInRequest<\n    SignInWithEmailLinkForLinkingRequest,\n    SignInWithEmailLinkResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_EMAIL_LINK,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Endpoint,\n  HttpMethod,\n  _addTidIfNecessary,\n  _performSignInRequest\n} from '../index';\nimport { IdToken, IdTokenResponse } from '../../model/id_token';\nimport { Auth } from '../../model/public_types';\n\nexport interface SignInWithIdpRequest {\n  requestUri: string;\n  postBody?: string;\n  sessionId?: string;\n  tenantId?: string;\n  returnSecureToken: boolean;\n  returnIdpCredential?: boolean;\n  idToken?: IdToken;\n  autoCreate?: boolean;\n  pendingToken?: string;\n}\n\n/**\n * @internal\n */\nexport interface SignInWithIdpResponse extends IdTokenResponse {\n  oauthAccessToken?: string;\n  oauthTokenSecret?: string;\n  nonce?: string;\n  oauthIdToken?: string;\n  pendingToken?: string;\n}\n\nexport async function signInWithIdp(\n  auth: Auth,\n  request: SignInWithIdpRequest\n): Promise<SignInWithIdpResponse> {\n  return _performSignInRequest<SignInWithIdpRequest, SignInWithIdpResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_IDP,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { querystring } from '@firebase/util';\n\nimport {\n  signInWithIdp,\n  SignInWithIdpRequest\n} from '../../api/authentication/idp';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { AuthErrorCode } from '../errors';\nimport { _fail } from '../util/assert';\nimport { AuthCredential } from './auth_credential';\n\nconst IDP_REQUEST_URI = 'http://localhost';\n\nexport interface OAuthCredentialParams {\n  // OAuth 2 uses either id token or access token\n  idToken?: string | null;\n  accessToken?: string | null;\n\n  // These fields are used with OAuth 1\n  oauthToken?: string;\n  secret?: string;\n  oauthTokenSecret?: string;\n\n  // Nonce is only set if pendingToken is not present\n  nonce?: string;\n  pendingToken?: string;\n\n  // Utilities\n  providerId: string;\n  signInMethod: string;\n}\n\n/**\n * Represents the OAuth credentials returned by an {@link OAuthProvider}.\n *\n * @remarks\n * Implementations specify the details about each auth provider's credential requirements.\n *\n * @public\n */\nexport class OAuthCredential extends AuthCredential {\n  /**\n   * The OAuth ID token associated with the credential if it belongs to an OIDC provider,\n   * such as `google.com`.\n   * @readonly\n   */\n  idToken?: string;\n  /**\n   * The OAuth access token associated with the credential if it belongs to an\n   * {@link OAuthProvider}, such as `facebook.com`, `twitter.com`, etc.\n   * @readonly\n   */\n  accessToken?: string;\n  /**\n   * The OAuth access token secret associated with the credential if it belongs to an OAuth 1.0\n   * provider, such as `twitter.com`.\n   * @readonly\n   */\n  secret?: string;\n\n  private nonce?: string;\n  private pendingToken: string | null = null;\n\n  /** @internal */\n  static _fromParams(params: OAuthCredentialParams): OAuthCredential {\n    const cred = new OAuthCredential(params.providerId, params.signInMethod);\n\n    if (params.idToken || params.accessToken) {\n      // OAuth 2 and either ID token or access token.\n      if (params.idToken) {\n        cred.idToken = params.idToken;\n      }\n\n      if (params.accessToken) {\n        cred.accessToken = params.accessToken;\n      }\n\n      // Add nonce if available and no pendingToken is present.\n      if (params.nonce && !params.pendingToken) {\n        cred.nonce = params.nonce;\n      }\n\n      if (params.pendingToken) {\n        cred.pendingToken = params.pendingToken;\n      }\n    } else if (params.oauthToken && params.oauthTokenSecret) {\n      // OAuth 1 and OAuth token with token secret\n      cred.accessToken = params.oauthToken;\n      cred.secret = params.oauthTokenSecret;\n    } else {\n      _fail(AuthErrorCode.ARGUMENT_ERROR);\n    }\n\n    return cred;\n  }\n\n  /** {@inheritdoc AuthCredential.toJSON}  */\n  toJSON(): object {\n    return {\n      idToken: this.idToken,\n      accessToken: this.accessToken,\n      secret: this.secret,\n      nonce: this.nonce,\n      pendingToken: this.pendingToken,\n      providerId: this.providerId,\n      signInMethod: this.signInMethod\n    };\n  }\n\n  /**\n   * Static method to deserialize a JSON representation of an object into an\n   * {@link  AuthCredential}.\n   *\n   * @param json - Input can be either Object or the stringified representation of the object.\n   * When string is provided, JSON.parse would be called first.\n   *\n   * @returns If the JSON input does not represent an {@link  AuthCredential}, null is returned.\n   */\n  static fromJSON(json: string | object): OAuthCredential | null {\n    const obj = typeof json === 'string' ? JSON.parse(json) : json;\n    const { providerId, signInMethod, ...rest }: OAuthCredentialParams = obj;\n    if (!providerId || !signInMethod) {\n      return null;\n    }\n\n    const cred = new OAuthCredential(providerId, signInMethod);\n    cred.idToken = rest.idToken || undefined;\n    cred.accessToken = rest.accessToken || undefined;\n    cred.secret = rest.secret;\n    cred.nonce = rest.nonce;\n    cred.pendingToken = rest.pendingToken || null;\n    return cred;\n  }\n\n  /** @internal */\n  _getIdTokenResponse(auth: AuthInternal): Promise<IdTokenResponse> {\n    const request = this.buildRequest();\n    return signInWithIdp(auth, request);\n  }\n\n  /** @internal */\n  _linkToIdToken(\n    auth: AuthInternal,\n    idToken: string\n  ): Promise<IdTokenResponse> {\n    const request = this.buildRequest();\n    request.idToken = idToken;\n    return signInWithIdp(auth, request);\n  }\n\n  /** @internal */\n  _getReauthenticationResolver(auth: AuthInternal): Promise<IdTokenResponse> {\n    const request = this.buildRequest();\n    request.autoCreate = false;\n    return signInWithIdp(auth, request);\n  }\n\n  private buildRequest(): SignInWithIdpRequest {\n    const request: SignInWithIdpRequest = {\n      requestUri: IDP_REQUEST_URI,\n      returnSecureToken: true\n    };\n\n    if (this.pendingToken) {\n      request.pendingToken = this.pendingToken;\n    } else {\n      const postBody: Record<string, string> = {};\n      if (this.idToken) {\n        postBody['id_token'] = this.idToken;\n      }\n      if (this.accessToken) {\n        postBody['access_token'] = this.accessToken;\n      }\n      if (this.secret) {\n        postBody['oauth_token_secret'] = this.secret;\n      }\n\n      postBody['providerId'] = this.providerId;\n      if (this.nonce && !this.pendingToken) {\n        postBody['nonce'] = this.nonce;\n      }\n\n      request.postBody = querystring(postBody);\n    }\n\n    return request;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Endpoint,\n  HttpMethod,\n  RecaptchaClientType,\n  RecaptchaVersion,\n  _addTidIfNecessary,\n  _makeTaggedError,\n  _performApiRequest,\n  _performSignInRequest\n} from '../index';\nimport { AuthErrorCode } from '../../core/errors';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { ServerError, ServerErrorMap } from '../errors';\nimport { Auth } from '../../model/public_types';\n\nexport interface SendPhoneVerificationCodeRequest {\n  phoneNumber: string;\n  // reCAPTCHA v2 token\n  recaptchaToken?: string;\n  tenantId?: string;\n  // reCAPTCHA Enterprise token\n  captchaResponse?: string;\n  clientType?: RecaptchaClientType;\n  recaptchaVersion?: RecaptchaVersion;\n}\n\nexport interface SendPhoneVerificationCodeResponse {\n  sessionInfo: string;\n}\n\nexport async function sendPhoneVerificationCode(\n  auth: Auth,\n  request: SendPhoneVerificationCodeRequest\n): Promise<SendPhoneVerificationCodeResponse> {\n  return _performApiRequest<\n    SendPhoneVerificationCodeRequest,\n    SendPhoneVerificationCodeResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SEND_VERIFICATION_CODE,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\n/**\n * @internal\n */\nexport interface SignInWithPhoneNumberRequest {\n  temporaryProof?: string;\n  phoneNumber?: string;\n  sessionInfo?: string;\n  code?: string;\n  tenantId?: string;\n}\n\nexport interface LinkWithPhoneNumberRequest\n  extends SignInWithPhoneNumberRequest {\n  idToken: string;\n}\n\n/**\n * @internal\n */\nexport interface SignInWithPhoneNumberResponse extends IdTokenResponse {\n  temporaryProof?: string;\n  phoneNumber?: string;\n}\n\nexport async function signInWithPhoneNumber(\n  auth: Auth,\n  request: SignInWithPhoneNumberRequest\n): Promise<SignInWithPhoneNumberResponse> {\n  return _performSignInRequest<\n    SignInWithPhoneNumberRequest,\n    SignInWithPhoneNumberResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_PHONE_NUMBER,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport async function linkWithPhoneNumber(\n  auth: Auth,\n  request: LinkWithPhoneNumberRequest\n): Promise<SignInWithPhoneNumberResponse> {\n  const response = await _performSignInRequest<\n    LinkWithPhoneNumberRequest,\n    SignInWithPhoneNumberResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_PHONE_NUMBER,\n    _addTidIfNecessary(auth, request)\n  );\n  if (response.temporaryProof) {\n    throw _makeTaggedError(auth, AuthErrorCode.NEED_CONFIRMATION, response);\n  }\n  return response;\n}\n\ninterface VerifyPhoneNumberForExistingRequest\n  extends SignInWithPhoneNumberRequest {\n  operation: 'REAUTH';\n}\n\nconst VERIFY_PHONE_NUMBER_FOR_EXISTING_ERROR_MAP_: Partial<\n  ServerErrorMap<ServerError>\n> = {\n  [ServerError.USER_NOT_FOUND]: AuthErrorCode.USER_DELETED\n};\n\nexport async function verifyPhoneNumberForExisting(\n  auth: Auth,\n  request: SignInWithPhoneNumberRequest\n): Promise<SignInWithPhoneNumberResponse> {\n  const apiRequest: VerifyPhoneNumberForExistingRequest = {\n    ...request,\n    operation: 'REAUTH'\n  };\n  return _performSignInRequest<\n    VerifyPhoneNumberForExistingRequest,\n    SignInWithPhoneNumberResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_PHONE_NUMBER,\n    _addTidIfNecessary(auth, apiRequest),\n    VERIFY_PHONE_NUMBER_FOR_EXISTING_ERROR_MAP_\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { ProviderId, SignInMethod } from '../../model/enums';\n\nimport { PhoneOrOauthTokenResponse } from '../../api/authentication/mfa';\nimport {\n  linkWithPhoneNumber,\n  signInWithPhoneNumber,\n  SignInWithPhoneNumberRequest,\n  verifyPhoneNumberForExisting\n} from '../../api/authentication/sms';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { AuthCredential } from './auth_credential';\n\nexport interface PhoneAuthCredentialParameters {\n  verificationId?: string;\n  verificationCode?: string;\n  phoneNumber?: string;\n  temporaryProof?: string;\n}\n\n/**\n * Represents the credentials returned by {@link PhoneAuthProvider}.\n *\n * @public\n */\nexport class PhoneAuthCredential extends AuthCredential {\n  private constructor(private readonly params: PhoneAuthCredentialParameters) {\n    super(ProviderId.PHONE, SignInMethod.PHONE);\n  }\n\n  /** @internal */\n  static _fromVerification(\n    verificationId: string,\n    verificationCode: string\n  ): PhoneAuthCredential {\n    return new PhoneAuthCredential({ verificationId, verificationCode });\n  }\n\n  /** @internal */\n  static _fromTokenResponse(\n    phoneNumber: string,\n    temporaryProof: string\n  ): PhoneAuthCredential {\n    return new PhoneAuthCredential({ phoneNumber, temporaryProof });\n  }\n\n  /** @internal */\n  _getIdTokenResponse(auth: AuthInternal): Promise<PhoneOrOauthTokenResponse> {\n    return signInWithPhoneNumber(auth, this._makeVerificationRequest());\n  }\n\n  /** @internal */\n  _linkToIdToken(\n    auth: AuthInternal,\n    idToken: string\n  ): Promise<IdTokenResponse> {\n    return linkWithPhoneNumber(auth, {\n      idToken,\n      ...this._makeVerificationRequest()\n    });\n  }\n\n  /** @internal */\n  _getReauthenticationResolver(auth: AuthInternal): Promise<IdTokenResponse> {\n    return verifyPhoneNumberForExisting(auth, this._makeVerificationRequest());\n  }\n\n  /** @internal */\n  _makeVerificationRequest(): SignInWithPhoneNumberRequest {\n    const { temporaryProof, phoneNumber, verificationId, verificationCode } =\n      this.params;\n    if (temporaryProof && phoneNumber) {\n      return { temporaryProof, phoneNumber };\n    }\n\n    return {\n      sessionInfo: verificationId,\n      code: verificationCode\n    };\n  }\n\n  /** {@inheritdoc AuthCredential.toJSON} */\n  toJSON(): object {\n    const obj: Record<string, string> = {\n      providerId: this.providerId\n    };\n    if (this.params.phoneNumber) {\n      obj.phoneNumber = this.params.phoneNumber;\n    }\n    if (this.params.temporaryProof) {\n      obj.temporaryProof = this.params.temporaryProof;\n    }\n    if (this.params.verificationCode) {\n      obj.verificationCode = this.params.verificationCode;\n    }\n    if (this.params.verificationId) {\n      obj.verificationId = this.params.verificationId;\n    }\n\n    return obj;\n  }\n\n  /** Generates a phone credential based on a plain object or a JSON string. */\n  static fromJSON(json: object | string): PhoneAuthCredential | null {\n    if (typeof json === 'string') {\n      json = JSON.parse(json);\n    }\n\n    const { verificationId, verificationCode, phoneNumber, temporaryProof } =\n      json as { [key: string]: string };\n    if (\n      !verificationCode &&\n      !verificationId &&\n      !phoneNumber &&\n      !temporaryProof\n    ) {\n      return null;\n    }\n\n    return new PhoneAuthCredential({\n      verificationId,\n      verificationCode,\n      phoneNumber,\n      temporaryProof\n    });\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { extractQuerystring, querystringDecode } from '@firebase/util';\nimport { ActionCodeOperation } from '../model/public_types';\nimport { AuthErrorCode } from './errors';\nimport { _assert } from './util/assert';\n\n/**\n * Enums for fields in URL query string.\n *\n * @enum {string}\n */\nconst enum QueryField {\n  API_KEY = 'apiKey',\n  CODE = 'oobCode',\n  CONTINUE_URL = 'continueUrl',\n  LANGUAGE_CODE = 'lang',\n  MODE = 'mode',\n  TENANT_ID = 'tenantId'\n}\n\n/**\n * Maps the mode string in action code URL to Action Code Info operation.\n *\n * @param mode\n */\nfunction parseMode(mode: string | null): ActionCodeOperation | null {\n  switch (mode) {\n    case 'recoverEmail':\n      return ActionCodeOperation.RECOVER_EMAIL;\n    case 'resetPassword':\n      return ActionCodeOperation.PASSWORD_RESET;\n    case 'signIn':\n      return ActionCodeOperation.EMAIL_SIGNIN;\n    case 'verifyEmail':\n      return ActionCodeOperation.VERIFY_EMAIL;\n    case 'verifyAndChangeEmail':\n      return ActionCodeOperation.VERIFY_AND_CHANGE_EMAIL;\n    case 'revertSecondFactorAddition':\n      return ActionCodeOperation.REVERT_SECOND_FACTOR_ADDITION;\n    default:\n      return null;\n  }\n}\n\n/**\n * Helper to parse FDL links\n *\n * @param url\n */\nfunction parseDeepLink(url: string): string {\n  const link = querystringDecode(extractQuerystring(url))['link'];\n\n  // Double link case (automatic redirect).\n  const doubleDeepLink = link\n    ? querystringDecode(extractQuerystring(link))['deep_link_id']\n    : null;\n  // iOS custom scheme links.\n  const iOSDeepLink = querystringDecode(extractQuerystring(url))[\n    'deep_link_id'\n  ];\n  const iOSDoubleDeepLink = iOSDeepLink\n    ? querystringDecode(extractQuerystring(iOSDeepLink))['link']\n    : null;\n  return iOSDoubleDeepLink || iOSDeepLink || doubleDeepLink || link || url;\n}\n\n/**\n * A utility class to parse email action URLs such as password reset, email verification,\n * email link sign in, etc.\n *\n * @public\n */\nexport class ActionCodeURL {\n  /**\n   * The API key of the email action link.\n   */\n  readonly apiKey: string;\n  /**\n   * The action code of the email action link.\n   */\n  readonly code: string;\n  /**\n   * The continue URL of the email action link. Null if not provided.\n   */\n  readonly continueUrl: string | null;\n  /**\n   * The language code of the email action link. Null if not provided.\n   */\n  readonly languageCode: string | null;\n  /**\n   * The action performed by the email action link. It returns from one of the types from\n   * {@link ActionCodeInfo}\n   */\n  readonly operation: string;\n  /**\n   * The tenant ID of the email action link. Null if the email action is from the parent project.\n   */\n  readonly tenantId: string | null;\n\n  /**\n   * @param actionLink - The link from which to extract the URL.\n   * @returns The {@link ActionCodeURL} object, or null if the link is invalid.\n   *\n   * @internal\n   */\n  constructor(actionLink: string) {\n    const searchParams = querystringDecode(extractQuerystring(actionLink));\n    const apiKey = searchParams[QueryField.API_KEY] ?? null;\n    const code = searchParams[QueryField.CODE] ?? null;\n    const operation = parseMode(searchParams[QueryField.MODE] ?? null);\n    // Validate API key, code and mode.\n    _assert(apiKey && code && operation, AuthErrorCode.ARGUMENT_ERROR);\n    this.apiKey = apiKey;\n    this.operation = operation;\n    this.code = code;\n    this.continueUrl = searchParams[QueryField.CONTINUE_URL] ?? null;\n    this.languageCode = searchParams[QueryField.LANGUAGE_CODE] ?? null;\n    this.tenantId = searchParams[QueryField.TENANT_ID] ?? null;\n  }\n\n  /**\n   * Parses the email action link string and returns an {@link ActionCodeURL} if the link is valid,\n   * otherwise returns null.\n   *\n   * @param link  - The email action link string.\n   * @returns The {@link ActionCodeURL} object, or null if the link is invalid.\n   *\n   * @public\n   */\n  static parseLink(link: string): ActionCodeURL | null {\n    const actionLink = parseDeepLink(link);\n    try {\n      return new ActionCodeURL(actionLink);\n    } catch {\n      return null;\n    }\n  }\n}\n\n/**\n * Parses the email action link string and returns an {@link ActionCodeURL} if\n * the link is valid, otherwise returns null.\n *\n * @public\n */\nexport function parseActionCodeURL(link: string): ActionCodeURL | null {\n  return ActionCodeURL.parseLink(link);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { ProviderId, SignInMethod } from '../../model/enums';\nimport { AuthProvider } from '../../model/public_types';\n\nimport { ActionCodeURL } from '../action_code_url';\nimport { EmailAuthCredential } from '../credentials/email';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\n\n/**\n * Provider for generating {@link EmailAuthCredential}.\n *\n * @public\n */\nexport class EmailAuthProvider implements AuthProvider {\n  /**\n   * Always set to {@link ProviderId}.PASSWORD, even for email link.\n   */\n  static readonly PROVIDER_ID: 'password' = ProviderId.PASSWORD;\n  /**\n   * Always set to {@link SignInMethod}.EMAIL_PASSWORD.\n   */\n  static readonly EMAIL_PASSWORD_SIGN_IN_METHOD: 'password' =\n    SignInMethod.EMAIL_PASSWORD;\n  /**\n   * Always set to {@link SignInMethod}.EMAIL_LINK.\n   */\n  static readonly EMAIL_LINK_SIGN_IN_METHOD: 'emailLink' =\n    SignInMethod.EMAIL_LINK;\n  /**\n   * Always set to {@link ProviderId}.PASSWORD, even for email link.\n   */\n  readonly providerId = EmailAuthProvider.PROVIDER_ID;\n\n  /**\n   * Initialize an {@link AuthCredential} using an email and password.\n   *\n   * @example\n   * ```javascript\n   * const authCredential = EmailAuthProvider.credential(email, password);\n   * const userCredential = await signInWithCredential(auth, authCredential);\n   * ```\n   *\n   * @example\n   * ```javascript\n   * const userCredential = await signInWithEmailAndPassword(auth, email, password);\n   * ```\n   *\n   * @param email - Email address.\n   * @param password - User account password.\n   * @returns The auth provider credential.\n   */\n  static credential(email: string, password: string): EmailAuthCredential {\n    return EmailAuthCredential._fromEmailAndPassword(email, password);\n  }\n\n  /**\n   * Initialize an {@link AuthCredential} using an email and an email link after a sign in with\n   * email link operation.\n   *\n   * @example\n   * ```javascript\n   * const authCredential = EmailAuthProvider.credentialWithLink(auth, email, emailLink);\n   * const userCredential = await signInWithCredential(auth, authCredential);\n   * ```\n   *\n   * @example\n   * ```javascript\n   * await sendSignInLinkToEmail(auth, email);\n   * // Obtain emailLink from user.\n   * const userCredential = await signInWithEmailLink(auth, email, emailLink);\n   * ```\n   *\n   * @param auth - The {@link Auth} instance used to verify the link.\n   * @param email - Email address.\n   * @param emailLink - Sign-in email link.\n   * @returns - The auth provider credential.\n   */\n  static credentialWithLink(\n    email: string,\n    emailLink: string\n  ): EmailAuthCredential {\n    const actionCodeUrl = ActionCodeURL.parseLink(emailLink);\n    _assert(actionCodeUrl, AuthErrorCode.ARGUMENT_ERROR);\n\n    return EmailAuthCredential._fromEmailAndCode(\n      email,\n      actionCodeUrl.code,\n      actionCodeUrl.tenantId\n    );\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthProvider } from '../../model/public_types';\n\n/**\n * Map of OAuth Custom Parameters.\n *\n * @public\n */\nexport type CustomParameters = Record<string, string>;\n\n/**\n * The base class for all Federated providers (OAuth (including OIDC), SAML).\n *\n * This class is not meant to be instantiated directly.\n *\n * @public\n */\nexport abstract class FederatedAuthProvider implements AuthProvider {\n  /** @internal */\n  defaultLanguageCode: string | null = null;\n  /** @internal */\n  private customParameters: CustomParameters = {};\n\n  /**\n   * Constructor for generic OAuth providers.\n   *\n   * @param providerId - Provider for which credentials should be generated.\n   */\n  constructor(readonly providerId: string) {}\n\n  /**\n   * Set the language gode.\n   *\n   * @param languageCode - language code\n   */\n  setDefaultLanguage(languageCode: string | null): void {\n    this.defaultLanguageCode = languageCode;\n  }\n\n  /**\n   * Sets the OAuth custom parameters to pass in an OAuth request for popup and redirect sign-in\n   * operations.\n   *\n   * @remarks\n   * For a detailed list, check the reserved required OAuth 2.0 parameters such as `client_id`,\n   * `redirect_uri`, `scope`, `response_type`, and `state` are not allowed and will be ignored.\n   *\n   * @param customOAuthParameters - The custom OAuth parameters to pass in the OAuth request.\n   */\n  setCustomParameters(customOAuthParameters: CustomParameters): AuthProvider {\n    this.customParameters = customOAuthParameters;\n    return this;\n  }\n\n  /**\n   * Retrieve the current list of {@link CustomParameters}.\n   */\n  getCustomParameters(): CustomParameters {\n    return this.customParameters;\n  }\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthProvider, UserCredential } from '../../model/public_types';\n\nimport { _assert } from '../util/assert';\nimport { AuthErrorCode } from '../errors';\n\nimport { OAuthCredential, OAuthCredentialParams } from '../credentials/oauth';\nimport { UserCredentialInternal } from '../../model/user';\nimport { FirebaseError } from '@firebase/util';\nimport { TaggedWithTokenResponse } from '../../model/id_token';\nimport { SignInWithIdpResponse } from '../../../internal';\nimport { FederatedAuthProvider } from './federated';\n\n/**\n * Defines the options for initializing an {@link OAuthCredential}.\n *\n * @remarks\n * For ID tokens with nonce claim, the raw nonce has to also be provided.\n *\n * @public\n */\nexport interface OAuthCredentialOptions {\n  /**\n   * The OAuth ID token used to initialize the {@link OAuthCredential}.\n   */\n  idToken?: string;\n  /**\n   * The OAuth access token used to initialize the {@link OAuthCredential}.\n   */\n  accessToken?: string;\n  /**\n   * The raw nonce associated with the ID token.\n   *\n   * @remarks\n   * It is required when an ID token with a nonce field is provided. The SHA-256 hash of the\n   * raw nonce must match the nonce field in the ID token.\n   */\n  rawNonce?: string;\n}\n\n/**\n * Common code to all OAuth providers. This is separate from the\n * {@link OAuthProvider} so that child providers (like\n * {@link GoogleAuthProvider}) don't inherit the `credential` instance method.\n * Instead, they rely on a static `credential` method.\n */\nexport abstract class BaseOAuthProvider\n  extends FederatedAuthProvider\n  implements AuthProvider\n{\n  /** @internal */\n  private scopes: string[] = [];\n\n  /**\n   * Add an OAuth scope to the credential.\n   *\n   * @param scope - Provider OAuth scope to add.\n   */\n  addScope(scope: string): AuthProvider {\n    // If not already added, add scope to list.\n    if (!this.scopes.includes(scope)) {\n      this.scopes.push(scope);\n    }\n    return this;\n  }\n\n  /**\n   * Retrieve the current list of OAuth scopes.\n   */\n  getScopes(): string[] {\n    return [...this.scopes];\n  }\n}\n\n/**\n * Provider for generating generic {@link OAuthCredential}.\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new OAuthProvider('google.com');\n * // Start a sign in process for an unauthenticated user.\n * provider.addScope('profile');\n * provider.addScope('email');\n * await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * if (result) {\n *   // This is the signed-in user\n *   const user = result.user;\n *   // This gives you a OAuth Access Token for the provider.\n *   const credential = provider.credentialFromResult(auth, result);\n *   const token = credential.accessToken;\n * }\n * ```\n *\n * @example\n * ```javascript\n * // Sign in using a popup.\n * const provider = new OAuthProvider('google.com');\n * provider.addScope('profile');\n * provider.addScope('email');\n * const result = await signInWithPopup(auth, provider);\n *\n * // The signed-in user info.\n * const user = result.user;\n * // This gives you a OAuth Access Token for the provider.\n * const credential = provider.credentialFromResult(auth, result);\n * const token = credential.accessToken;\n * ```\n * @public\n */\nexport class OAuthProvider extends BaseOAuthProvider {\n  /**\n   * Creates an {@link OAuthCredential} from a JSON string or a plain object.\n   * @param json - A plain object or a JSON string\n   */\n  static credentialFromJSON(json: object | string): OAuthCredential {\n    const obj = typeof json === 'string' ? JSON.parse(json) : json;\n    _assert(\n      'providerId' in obj && 'signInMethod' in obj,\n      AuthErrorCode.ARGUMENT_ERROR\n    );\n    return OAuthCredential._fromParams(obj);\n  }\n\n  /**\n   * Creates a {@link OAuthCredential} from a generic OAuth provider's access token or ID token.\n   *\n   * @remarks\n   * The raw nonce is required when an ID token with a nonce field is provided. The SHA-256 hash of\n   * the raw nonce must match the nonce field in the ID token.\n   *\n   * @example\n   * ```javascript\n   * // `googleUser` from the onsuccess Google Sign In callback.\n   * // Initialize a generate OAuth provider with a `google.com` providerId.\n   * const provider = new OAuthProvider('google.com');\n   * const credential = provider.credential({\n   *   idToken: googleUser.getAuthResponse().id_token,\n   * });\n   * const result = await signInWithCredential(credential);\n   * ```\n   *\n   * @param params - Either the options object containing the ID token, access token and raw nonce\n   * or the ID token string.\n   */\n  credential(params: OAuthCredentialOptions): OAuthCredential {\n    return this._credential({ ...params, nonce: params.rawNonce });\n  }\n\n  /** An internal credential method that accepts more permissive options */\n  private _credential(\n    params: Omit<OAuthCredentialParams, 'signInMethod' | 'providerId'>\n  ): OAuthCredential {\n    _assert(params.idToken || params.accessToken, AuthErrorCode.ARGUMENT_ERROR);\n    // For OAuthCredential, sign in method is same as providerId.\n    return OAuthCredential._fromParams({\n      ...params,\n      providerId: this.providerId,\n      signInMethod: this.providerId\n    });\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link UserCredential}.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromResult(\n    userCredential: UserCredential\n  ): OAuthCredential | null {\n    return OAuthProvider.oauthCredentialFromTaggedObject(\n      userCredential as UserCredentialInternal\n    );\n  }\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link AuthError} which was\n   * thrown during a sign-in, link, or reauthenticate operation.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromError(error: FirebaseError): OAuthCredential | null {\n    return OAuthProvider.oauthCredentialFromTaggedObject(\n      (error.customData || {}) as TaggedWithTokenResponse\n    );\n  }\n\n  private static oauthCredentialFromTaggedObject({\n    _tokenResponse: tokenResponse\n  }: TaggedWithTokenResponse): OAuthCredential | null {\n    if (!tokenResponse) {\n      return null;\n    }\n\n    const {\n      oauthIdToken,\n      oauthAccessToken,\n      oauthTokenSecret,\n      pendingToken,\n      nonce,\n      providerId\n    } = tokenResponse as SignInWithIdpResponse;\n    if (\n      !oauthAccessToken &&\n      !oauthTokenSecret &&\n      !oauthIdToken &&\n      !pendingToken\n    ) {\n      return null;\n    }\n\n    if (!providerId) {\n      return null;\n    }\n\n    try {\n      return new OAuthProvider(providerId)._credential({\n        idToken: oauthIdToken,\n        accessToken: oauthAccessToken,\n        nonce,\n        pendingToken\n      });\n    } catch (e) {\n      return null;\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { UserCredential } from '../../model/public_types';\nimport { FirebaseError } from '@firebase/util';\n\nimport { TaggedWithTokenResponse } from '../../model/id_token';\nimport { UserCredentialInternal } from '../../model/user';\nimport { OAuthCredential } from '../credentials/oauth';\nimport { BaseOAuthProvider } from './oauth';\nimport { ProviderId, SignInMethod } from '../../model/enums';\n\n/**\n * Provider for generating an {@link OAuthCredential} for {@link ProviderId}.FACEBOOK.\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new FacebookAuthProvider();\n * // Start a sign in process for an unauthenticated user.\n * provider.addScope('user_birthday');\n * await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * if (result) {\n *   // This is the signed-in user\n *   const user = result.user;\n *   // This gives you a Facebook Access Token.\n *   const credential = FacebookAuthProvider.credentialFromResult(result);\n *   const token = credential.accessToken;\n * }\n * ```\n *\n * @example\n * ```javascript\n * // Sign in using a popup.\n * const provider = new FacebookAuthProvider();\n * provider.addScope('user_birthday');\n * const result = await signInWithPopup(auth, provider);\n *\n * // The signed-in user info.\n * const user = result.user;\n * // This gives you a Facebook Access Token.\n * const credential = FacebookAuthProvider.credentialFromResult(result);\n * const token = credential.accessToken;\n * ```\n *\n * @public\n */\nexport class FacebookAuthProvider extends BaseOAuthProvider {\n  /** Always set to {@link SignInMethod}.FACEBOOK. */\n  static readonly FACEBOOK_SIGN_IN_METHOD: 'facebook.com' =\n    SignInMethod.FACEBOOK;\n  /** Always set to {@link ProviderId}.FACEBOOK. */\n  static readonly PROVIDER_ID: 'facebook.com' = ProviderId.FACEBOOK;\n\n  constructor() {\n    super(ProviderId.FACEBOOK);\n  }\n\n  /**\n   * Creates a credential for Facebook.\n   *\n   * @example\n   * ```javascript\n   * // `event` from the Facebook auth.authResponseChange callback.\n   * const credential = FacebookAuthProvider.credential(event.authResponse.accessToken);\n   * const result = await signInWithCredential(credential);\n   * ```\n   *\n   * @param accessToken - Facebook access token.\n   */\n  static credential(accessToken: string): OAuthCredential {\n    return OAuthCredential._fromParams({\n      providerId: FacebookAuthProvider.PROVIDER_ID,\n      signInMethod: FacebookAuthProvider.FACEBOOK_SIGN_IN_METHOD,\n      accessToken\n    });\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link UserCredential}.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromResult(\n    userCredential: UserCredential\n  ): OAuthCredential | null {\n    return FacebookAuthProvider.credentialFromTaggedObject(\n      userCredential as UserCredentialInternal\n    );\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link AuthError} which was\n   * thrown during a sign-in, link, or reauthenticate operation.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromError(error: FirebaseError): OAuthCredential | null {\n    return FacebookAuthProvider.credentialFromTaggedObject(\n      (error.customData || {}) as TaggedWithTokenResponse\n    );\n  }\n\n  private static credentialFromTaggedObject({\n    _tokenResponse: tokenResponse\n  }: TaggedWithTokenResponse): OAuthCredential | null {\n    if (!tokenResponse || !('oauthAccessToken' in tokenResponse)) {\n      return null;\n    }\n\n    if (!tokenResponse.oauthAccessToken) {\n      return null;\n    }\n\n    try {\n      return FacebookAuthProvider.credential(tokenResponse.oauthAccessToken);\n    } catch {\n      return null;\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { UserCredential } from '../../model/public_types';\nimport { FirebaseError } from '@firebase/util';\n\nimport { SignInWithIdpResponse } from '../../api/authentication/idp';\nimport { TaggedWithTokenResponse } from '../../model/id_token';\nimport { UserCredentialInternal } from '../../model/user';\nimport { OAuthCredential } from '../credentials/oauth';\nimport { BaseOAuthProvider } from './oauth';\nimport { ProviderId, SignInMethod } from '../../model/enums';\n\n/**\n * Provider for generating an {@link OAuthCredential} for {@link ProviderId}.GOOGLE.\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new GoogleAuthProvider();\n * // Start a sign in process for an unauthenticated user.\n * provider.addScope('profile');\n * provider.addScope('email');\n * await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * if (result) {\n *   // This is the signed-in user\n *   const user = result.user;\n *   // This gives you a Google Access Token.\n *   const credential = GoogleAuthProvider.credentialFromResult(result);\n *   const token = credential.accessToken;\n * }\n * ```\n *\n * @example\n * ```javascript\n * // Sign in using a popup.\n * const provider = new GoogleAuthProvider();\n * provider.addScope('profile');\n * provider.addScope('email');\n * const result = await signInWithPopup(auth, provider);\n *\n * // The signed-in user info.\n * const user = result.user;\n * // This gives you a Google Access Token.\n * const credential = GoogleAuthProvider.credentialFromResult(result);\n * const token = credential.accessToken;\n * ```\n *\n * @public\n */\nexport class GoogleAuthProvider extends BaseOAuthProvider {\n  /** Always set to {@link SignInMethod}.GOOGLE. */\n  static readonly GOOGLE_SIGN_IN_METHOD: 'google.com' = SignInMethod.GOOGLE;\n  /** Always set to {@link ProviderId}.GOOGLE. */\n  static readonly PROVIDER_ID: 'google.com' = ProviderId.GOOGLE;\n\n  constructor() {\n    super(ProviderId.GOOGLE);\n    this.addScope('profile');\n  }\n\n  /**\n   * Creates a credential for Google. At least one of ID token and access token is required.\n   *\n   * @example\n   * ```javascript\n   * // \\`googleUser\\` from the onsuccess Google Sign In callback.\n   * const credential = GoogleAuthProvider.credential(googleUser.getAuthResponse().id_token);\n   * const result = await signInWithCredential(credential);\n   * ```\n   *\n   * @param idToken - Google ID token.\n   * @param accessToken - Google access token.\n   */\n  static credential(\n    idToken?: string | null,\n    accessToken?: string | null\n  ): OAuthCredential {\n    return OAuthCredential._fromParams({\n      providerId: GoogleAuthProvider.PROVIDER_ID,\n      signInMethod: GoogleAuthProvider.GOOGLE_SIGN_IN_METHOD,\n      idToken,\n      accessToken\n    });\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link UserCredential}.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromResult(\n    userCredential: UserCredential\n  ): OAuthCredential | null {\n    return GoogleAuthProvider.credentialFromTaggedObject(\n      userCredential as UserCredentialInternal\n    );\n  }\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link AuthError} which was\n   * thrown during a sign-in, link, or reauthenticate operation.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromError(error: FirebaseError): OAuthCredential | null {\n    return GoogleAuthProvider.credentialFromTaggedObject(\n      (error.customData || {}) as TaggedWithTokenResponse\n    );\n  }\n\n  private static credentialFromTaggedObject({\n    _tokenResponse: tokenResponse\n  }: TaggedWithTokenResponse): OAuthCredential | null {\n    if (!tokenResponse) {\n      return null;\n    }\n\n    const { oauthIdToken, oauthAccessToken } =\n      tokenResponse as SignInWithIdpResponse;\n    if (!oauthIdToken && !oauthAccessToken) {\n      // This could be an oauth 1 credential or a phone credential\n      return null;\n    }\n\n    try {\n      return GoogleAuthProvider.credential(oauthIdToken, oauthAccessToken);\n    } catch {\n      return null;\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { UserCredential } from '../../model/public_types';\nimport { FirebaseError } from '@firebase/util';\n\nimport { TaggedWithTokenResponse } from '../../model/id_token';\nimport { UserCredentialInternal } from '../../model/user';\nimport { OAuthCredential } from '../credentials/oauth';\nimport { BaseOAuthProvider } from './oauth';\nimport { ProviderId, SignInMethod } from '../../model/enums';\n\n/**\n * Provider for generating an {@link OAuthCredential} for {@link ProviderId}.GITHUB.\n *\n * @remarks\n * GitHub requires an OAuth 2.0 redirect, so you can either handle the redirect directly, or use\n * the {@link signInWithPopup} handler:\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new GithubAuthProvider();\n * // Start a sign in process for an unauthenticated user.\n * provider.addScope('repo');\n * await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * if (result) {\n *   // This is the signed-in user\n *   const user = result.user;\n *   // This gives you a GitHub Access Token.\n *   const credential = GithubAuthProvider.credentialFromResult(result);\n *   const token = credential.accessToken;\n * }\n * ```\n *\n * @example\n * ```javascript\n * // Sign in using a popup.\n * const provider = new GithubAuthProvider();\n * provider.addScope('repo');\n * const result = await signInWithPopup(auth, provider);\n *\n * // The signed-in user info.\n * const user = result.user;\n * // This gives you a GitHub Access Token.\n * const credential = GithubAuthProvider.credentialFromResult(result);\n * const token = credential.accessToken;\n * ```\n * @public\n */\nexport class GithubAuthProvider extends BaseOAuthProvider {\n  /** Always set to {@link SignInMethod}.GITHUB. */\n  static readonly GITHUB_SIGN_IN_METHOD: 'github.com' = SignInMethod.GITHUB;\n  /** Always set to {@link ProviderId}.GITHUB. */\n  static readonly PROVIDER_ID: 'github.com' = ProviderId.GITHUB;\n\n  constructor() {\n    super(ProviderId.GITHUB);\n  }\n\n  /**\n   * Creates a credential for GitHub.\n   *\n   * @param accessToken - GitHub access token.\n   */\n  static credential(accessToken: string): OAuthCredential {\n    return OAuthCredential._fromParams({\n      providerId: GithubAuthProvider.PROVIDER_ID,\n      signInMethod: GithubAuthProvider.GITHUB_SIGN_IN_METHOD,\n      accessToken\n    });\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link UserCredential}.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromResult(\n    userCredential: UserCredential\n  ): OAuthCredential | null {\n    return GithubAuthProvider.credentialFromTaggedObject(\n      userCredential as UserCredentialInternal\n    );\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link AuthError} which was\n   * thrown during a sign-in, link, or reauthenticate operation.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromError(error: FirebaseError): OAuthCredential | null {\n    return GithubAuthProvider.credentialFromTaggedObject(\n      (error.customData || {}) as TaggedWithTokenResponse\n    );\n  }\n\n  private static credentialFromTaggedObject({\n    _tokenResponse: tokenResponse\n  }: TaggedWithTokenResponse): OAuthCredential | null {\n    if (!tokenResponse || !('oauthAccessToken' in tokenResponse)) {\n      return null;\n    }\n\n    if (!tokenResponse.oauthAccessToken) {\n      return null;\n    }\n\n    try {\n      return GithubAuthProvider.credential(tokenResponse.oauthAccessToken);\n    } catch {\n      return null;\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/**\n * Represents the SAML credentials returned by an {@link SAMLAuthProvider}.\n *\n * @public\n */\n\nimport {\n  signInWithIdp,\n  SignInWithIdpRequest\n} from '../../api/authentication/idp';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { AuthCredential } from './auth_credential';\n\nconst IDP_REQUEST_URI = 'http://localhost';\n\n/**\n * @public\n */\nexport class SAMLAuthCredential extends AuthCredential {\n  /** @internal */\n  private constructor(\n    providerId: string,\n    private readonly pendingToken: string\n  ) {\n    super(providerId, providerId);\n  }\n\n  /** @internal */\n  _getIdTokenResponse(auth: AuthInternal): Promise<IdTokenResponse> {\n    const request = this.buildRequest();\n    return signInWithIdp(auth, request);\n  }\n\n  /** @internal */\n  _linkToIdToken(\n    auth: AuthInternal,\n    idToken: string\n  ): Promise<IdTokenResponse> {\n    const request = this.buildRequest();\n    request.idToken = idToken;\n    return signInWithIdp(auth, request);\n  }\n\n  /** @internal */\n  _getReauthenticationResolver(auth: AuthInternal): Promise<IdTokenResponse> {\n    const request = this.buildRequest();\n    request.autoCreate = false;\n    return signInWithIdp(auth, request);\n  }\n\n  /** {@inheritdoc AuthCredential.toJSON}  */\n  toJSON(): object {\n    return {\n      signInMethod: this.signInMethod,\n      providerId: this.providerId,\n      pendingToken: this.pendingToken\n    };\n  }\n\n  /**\n   * Static method to deserialize a JSON representation of an object into an\n   * {@link  AuthCredential}.\n   *\n   * @param json - Input can be either Object or the stringified representation of the object.\n   * When string is provided, JSON.parse would be called first.\n   *\n   * @returns If the JSON input does not represent an {@link  AuthCredential}, null is returned.\n   */\n  static fromJSON(json: string | object): SAMLAuthCredential | null {\n    const obj = typeof json === 'string' ? JSON.parse(json) : json;\n    const { providerId, signInMethod, pendingToken }: Record<string, string> =\n      obj;\n    if (\n      !providerId ||\n      !signInMethod ||\n      !pendingToken ||\n      providerId !== signInMethod\n    ) {\n      return null;\n    }\n\n    return new SAMLAuthCredential(providerId, pendingToken);\n  }\n\n  /**\n   * Helper static method to avoid exposing the constructor to end users.\n   *\n   * @internal\n   */\n  static _create(providerId: string, pendingToken: string): SAMLAuthCredential {\n    return new SAMLAuthCredential(providerId, pendingToken);\n  }\n\n  private buildRequest(): SignInWithIdpRequest {\n    return {\n      requestUri: IDP_REQUEST_URI,\n      returnSecureToken: true,\n      pendingToken: this.pendingToken\n    };\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FirebaseError } from '@firebase/util';\nimport { SignInWithIdpResponse } from '../../api/authentication/idp';\nimport { TaggedWithTokenResponse } from '../../model/id_token';\nimport { UserCredential } from '../../model/public_types';\nimport { UserCredentialInternal } from '../../model/user';\nimport { AuthCredential } from '../credentials';\nimport { SAMLAuthCredential } from '../credentials/saml';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\nimport { FederatedAuthProvider } from './federated';\n\nconst SAML_PROVIDER_PREFIX = 'saml.';\n\n/**\n * An {@link AuthProvider} for SAML.\n *\n * @public\n */\nexport class SAMLAuthProvider extends FederatedAuthProvider {\n  /**\n   * Constructor. The providerId must start with \"saml.\"\n   * @param providerId - SAML provider ID.\n   */\n  constructor(providerId: string) {\n    _assert(\n      providerId.startsWith(SAML_PROVIDER_PREFIX),\n      AuthErrorCode.ARGUMENT_ERROR\n    );\n    super(providerId);\n  }\n\n  /**\n   * Generates an {@link AuthCredential} from a {@link UserCredential} after a\n   * successful SAML flow completes.\n   *\n   * @remarks\n   *\n   * For example, to get an {@link AuthCredential}, you could write the\n   * following code:\n   *\n   * ```js\n   * const userCredential = await signInWithPopup(auth, samlProvider);\n   * const credential = SAMLAuthProvider.credentialFromResult(userCredential);\n   * ```\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromResult(\n    userCredential: UserCredential\n  ): AuthCredential | null {\n    return SAMLAuthProvider.samlCredentialFromTaggedObject(\n      userCredential as UserCredentialInternal\n    );\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link AuthError} which was\n   * thrown during a sign-in, link, or reauthenticate operation.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromError(error: FirebaseError): AuthCredential | null {\n    return SAMLAuthProvider.samlCredentialFromTaggedObject(\n      (error.customData || {}) as TaggedWithTokenResponse\n    );\n  }\n\n  /**\n   * Creates an {@link AuthCredential} from a JSON string or a plain object.\n   * @param json - A plain object or a JSON string\n   */\n  static credentialFromJSON(json: string | object): AuthCredential {\n    const credential = SAMLAuthCredential.fromJSON(json);\n    _assert(credential, AuthErrorCode.ARGUMENT_ERROR);\n    return credential;\n  }\n\n  private static samlCredentialFromTaggedObject({\n    _tokenResponse: tokenResponse\n  }: TaggedWithTokenResponse): SAMLAuthCredential | null {\n    if (!tokenResponse) {\n      return null;\n    }\n\n    const { pendingToken, providerId } = tokenResponse as SignInWithIdpResponse;\n\n    if (!pendingToken || !providerId) {\n      return null;\n    }\n\n    try {\n      return SAMLAuthCredential._create(providerId, pendingToken);\n    } catch (e) {\n      return null;\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/**\n * @license\n * Copyright 2020 Twitter LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { UserCredential } from '../../model/public_types';\nimport { FirebaseError } from '@firebase/util';\n\nimport { SignInWithIdpResponse } from '../../api/authentication/idp';\nimport { TaggedWithTokenResponse } from '../../model/id_token';\nimport { UserCredentialInternal } from '../../model/user';\nimport { OAuthCredential } from '../credentials/oauth';\nimport { BaseOAuthProvider } from './oauth';\nimport { ProviderId, SignInMethod } from '../../model/enums';\n\n/**\n * Provider for generating an {@link OAuthCredential} for {@link ProviderId}.TWITTER.\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new TwitterAuthProvider();\n * // Start a sign in process for an unauthenticated user.\n * await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * if (result) {\n *   // This is the signed-in user\n *   const user = result.user;\n *   // This gives you a Twitter Access Token and Secret.\n *   const credential = TwitterAuthProvider.credentialFromResult(result);\n *   const token = credential.accessToken;\n *   const secret = credential.secret;\n * }\n * ```\n *\n * @example\n * ```javascript\n * // Sign in using a popup.\n * const provider = new TwitterAuthProvider();\n * const result = await signInWithPopup(auth, provider);\n *\n * // The signed-in user info.\n * const user = result.user;\n * // This gives you a Twitter Access Token and Secret.\n * const credential = TwitterAuthProvider.credentialFromResult(result);\n * const token = credential.accessToken;\n * const secret = credential.secret;\n * ```\n *\n * @public\n */\nexport class TwitterAuthProvider extends BaseOAuthProvider {\n  /** Always set to {@link SignInMethod}.TWITTER. */\n  static readonly TWITTER_SIGN_IN_METHOD: 'twitter.com' = SignInMethod.TWITTER;\n  /** Always set to {@link ProviderId}.TWITTER. */\n  static readonly PROVIDER_ID: 'twitter.com' = ProviderId.TWITTER;\n\n  constructor() {\n    super(ProviderId.TWITTER);\n  }\n\n  /**\n   * Creates a credential for Twitter.\n   *\n   * @param token - Twitter access token.\n   * @param secret - Twitter secret.\n   */\n  static credential(token: string, secret: string): OAuthCredential {\n    return OAuthCredential._fromParams({\n      providerId: TwitterAuthProvider.PROVIDER_ID,\n      signInMethod: TwitterAuthProvider.TWITTER_SIGN_IN_METHOD,\n      oauthToken: token,\n      oauthTokenSecret: secret\n    });\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link UserCredential}.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromResult(\n    userCredential: UserCredential\n  ): OAuthCredential | null {\n    return TwitterAuthProvider.credentialFromTaggedObject(\n      userCredential as UserCredentialInternal\n    );\n  }\n\n  /**\n   * Used to extract the underlying {@link OAuthCredential} from a {@link AuthError} which was\n   * thrown during a sign-in, link, or reauthenticate operation.\n   *\n   * @param userCredential - The user credential.\n   */\n  static credentialFromError(error: FirebaseError): OAuthCredential | null {\n    return TwitterAuthProvider.credentialFromTaggedObject(\n      (error.customData || {}) as TaggedWithTokenResponse\n    );\n  }\n\n  private static credentialFromTaggedObject({\n    _tokenResponse: tokenResponse\n  }: TaggedWithTokenResponse): OAuthCredential | null {\n    if (!tokenResponse) {\n      return null;\n    }\n    const { oauthAccessToken, oauthTokenSecret } =\n      tokenResponse as SignInWithIdpResponse;\n    if (!oauthAccessToken || !oauthTokenSecret) {\n      return null;\n    }\n\n    try {\n      return TwitterAuthProvider.credential(oauthAccessToken, oauthTokenSecret);\n    } catch {\n      return null;\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Endpoint,\n  HttpMethod,\n  RecaptchaClientType,\n  RecaptchaVersion,\n  _addTidIfNecessary,\n  _performSignInRequest\n} from '../index';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { Auth } from '../../model/public_types';\n\nexport interface SignUpRequest {\n  idToken?: string;\n  returnSecureToken?: boolean;\n  email?: string;\n  password?: string;\n  tenantId?: string;\n  captchaResponse?: string;\n  clientType?: RecaptchaClientType;\n  recaptchaVersion?: RecaptchaVersion;\n}\n\nexport interface SignUpResponse extends IdTokenResponse {\n  displayName?: string;\n  email?: string;\n}\n\nexport async function signUp(\n  auth: Auth,\n  request: SignUpRequest\n): Promise<SignUpResponse> {\n  return _performSignInRequest<SignUpRequest, SignUpResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_UP,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { PhoneOrOauthTokenResponse } from '../../api/authentication/mfa';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { UserInternal, UserCredentialInternal } from '../../model/user';\nimport { UserImpl } from './user_impl';\nimport { AuthInternal } from '../../model/auth';\nimport { OperationType, ProviderId } from '../../model/enums';\n\ninterface UserCredentialParams {\n  readonly user: UserInternal;\n  readonly providerId: ProviderId | string | null;\n  readonly _tokenResponse?: PhoneOrOauthTokenResponse;\n  readonly operationType: OperationType;\n}\n\nexport class UserCredentialImpl\n  implements UserCredentialInternal, UserCredentialParams\n{\n  readonly user: UserInternal;\n  readonly providerId: ProviderId | string | null;\n  readonly _tokenResponse: PhoneOrOauthTokenResponse | undefined;\n  readonly operationType: OperationType;\n\n  constructor(params: UserCredentialParams) {\n    this.user = params.user;\n    this.providerId = params.providerId;\n    this._tokenResponse = params._tokenResponse;\n    this.operationType = params.operationType;\n  }\n\n  static async _fromIdTokenResponse(\n    auth: AuthInternal,\n    operationType: OperationType,\n    idTokenResponse: IdTokenResponse,\n    isAnonymous: boolean = false\n  ): Promise<UserCredentialInternal> {\n    const user = await UserImpl._fromIdTokenResponse(\n      auth,\n      idTokenResponse,\n      isAnonymous\n    );\n    const providerId = providerIdForResponse(idTokenResponse);\n    const userCred = new UserCredentialImpl({\n      user,\n      providerId,\n      _tokenResponse: idTokenResponse,\n      operationType\n    });\n    return userCred;\n  }\n\n  static async _forOperation(\n    user: UserInternal,\n    operationType: OperationType,\n    response: PhoneOrOauthTokenResponse\n  ): Promise<UserCredentialImpl> {\n    await user._updateTokensIfNecessary(response, /* reload */ true);\n    const providerId = providerIdForResponse(response);\n    return new UserCredentialImpl({\n      user,\n      providerId,\n      _tokenResponse: response,\n      operationType\n    });\n  }\n}\n\nfunction providerIdForResponse(\n  response: IdTokenResponse\n): ProviderId | string | null {\n  if (response.providerId) {\n    return response.providerId;\n  }\n\n  if ('phoneNumber' in response) {\n    return ProviderId.PHONE;\n  }\n\n  return null;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { MultiFactorError as MultiFactorErrorPublic } from '../model/public_types';\nimport { FirebaseError } from '@firebase/util';\nimport { AuthInternal } from '../model/auth';\nimport { IdTokenResponse } from '../model/id_token';\nimport { AuthErrorCode } from '../core/errors';\nimport { UserInternal } from '../model/user';\nimport { AuthCredential } from '../core/credentials';\nimport { IdTokenMfaResponse } from '../api/authentication/mfa';\nimport { OperationType } from '../model/enums';\n\nexport type MultiFactorErrorData = MultiFactorErrorPublic['customData'] & {\n  _serverResponse: IdTokenMfaResponse;\n};\n\nexport class MultiFactorError\n  extends FirebaseError\n  implements MultiFactorErrorPublic\n{\n  readonly customData: MultiFactorErrorData;\n\n  private constructor(\n    auth: AuthInternal,\n    error: FirebaseError,\n    readonly operationType: OperationType,\n    readonly user?: UserInternal\n  ) {\n    super(error.code, error.message);\n    // https://github.com/Microsoft/TypeScript-wiki/blob/master/Breaking-Changes.md#extending-built-ins-like-error-array-and-map-may-no-longer-work\n    Object.setPrototypeOf(this, MultiFactorError.prototype);\n    this.customData = {\n      appName: auth.name,\n      tenantId: auth.tenantId ?? undefined,\n      _serverResponse: error.customData!._serverResponse as IdTokenMfaResponse,\n      operationType\n    };\n  }\n\n  static _fromErrorAndOperation(\n    auth: AuthInternal,\n    error: FirebaseError,\n    operationType: OperationType,\n    user?: UserInternal\n  ): MultiFactorError {\n    return new MultiFactorError(auth, error, operationType, user);\n  }\n}\n\nexport function _processCredentialSavingMfaContextIfNecessary(\n  auth: AuthInternal,\n  operationType: OperationType,\n  credential: AuthCredential,\n  user?: UserInternal\n): Promise<IdTokenResponse> {\n  const idTokenProvider =\n    operationType === OperationType.REAUTHENTICATE\n      ? credential._getReauthenticationResolver(auth)\n      : credential._getIdTokenResponse(auth);\n\n  return idTokenProvider.catch(error => {\n    if (error.code === `auth/${AuthErrorCode.MFA_REQUIRED}`) {\n      throw MultiFactorError._fromErrorAndOperation(\n        auth,\n        error,\n        operationType,\n        user\n      );\n    }\n\n    throw error;\n  });\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport interface ProviderAssociatedObject {\n  providerId?: string;\n}\n\n/**\n * Takes a set of UserInfo provider data and converts it to a set of names\n */\nexport function providerDataAsNames<T extends ProviderAssociatedObject>(\n  providerData: T[]\n): Set<string> {\n  return new Set(\n    providerData\n      .map(({ providerId }) => providerId)\n      .filter(pid => !!pid) as string[]\n  );\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { User } from '../../model/public_types';\n\nimport { deleteLinkedAccounts } from '../../api/account_management/account';\nimport { UserInternal, UserCredentialInternal } from '../../model/user';\nimport { AuthCredential } from '../credentials';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\nimport { providerDataAsNames } from '../util/providers';\nimport { _logoutIfInvalidated } from './invalidation';\nimport { _reloadWithoutSaving } from './reload';\nimport { UserCredentialImpl } from './user_credential_impl';\nimport { getModularInstance } from '@firebase/util';\nimport { OperationType, ProviderId } from '../../model/enums';\n\n/**\n * Unlinks a provider from a user account.\n *\n * @param user - The user.\n * @param providerId - The provider to unlink.\n *\n * @public\n */\nexport async function unlink(user: User, providerId: string): Promise<User> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  await _assertLinkedStatus(true, userInternal, providerId);\n  const { providerUserInfo } = await deleteLinkedAccounts(userInternal.auth, {\n    idToken: await userInternal.getIdToken(),\n    deleteProvider: [providerId]\n  });\n\n  const providersLeft = providerDataAsNames(providerUserInfo || []);\n\n  userInternal.providerData = userInternal.providerData.filter(pd =>\n    providersLeft.has(pd.providerId)\n  );\n  if (!providersLeft.has(ProviderId.PHONE)) {\n    userInternal.phoneNumber = null;\n  }\n\n  await userInternal.auth._persistUserIfCurrent(userInternal);\n  return userInternal;\n}\n\nexport async function _link(\n  user: UserInternal,\n  credential: AuthCredential,\n  bypassAuthState = false\n): Promise<UserCredentialInternal> {\n  const response = await _logoutIfInvalidated(\n    user,\n    credential._linkToIdToken(user.auth, await user.getIdToken()),\n    bypassAuthState\n  );\n  return UserCredentialImpl._forOperation(user, OperationType.LINK, response);\n}\n\nexport async function _assertLinkedStatus(\n  expected: boolean,\n  user: UserInternal,\n  provider: string\n): Promise<void> {\n  await _reloadWithoutSaving(user);\n  const providerIds = providerDataAsNames(user.providerData);\n\n  const code =\n    expected === false\n      ? AuthErrorCode.PROVIDER_ALREADY_LINKED\n      : AuthErrorCode.NO_SUCH_PROVIDER;\n  _assert(providerIds.has(provider) === expected, user.auth, code);\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FirebaseError } from '@firebase/util';\nimport { _processCredentialSavingMfaContextIfNecessary } from '../../mfa/mfa_error';\nimport { OperationType } from '../../model/enums';\nimport { UserInternal } from '../../model/user';\nimport { AuthCredential } from '../credentials';\nimport { AuthErrorCode } from '../errors';\nimport { _assert, _fail } from '../util/assert';\nimport { _parseToken } from './id_token_result';\nimport { _logoutIfInvalidated } from './invalidation';\nimport { UserCredentialImpl } from './user_credential_impl';\nimport { _isFirebaseServerApp } from '@firebase/app';\nimport { _serverAppCurrentUserOperationNotSupportedError } from '../../core/util/assert';\n\nexport async function _reauthenticate(\n  user: UserInternal,\n  credential: AuthCredential,\n  bypassAuthState = false\n): Promise<UserCredentialImpl> {\n  const { auth } = user;\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const operationType = OperationType.REAUTHENTICATE;\n\n  try {\n    const response = await _logoutIfInvalidated(\n      user,\n      _processCredentialSavingMfaContextIfNecessary(\n        auth,\n        operationType,\n        credential,\n        user\n      ),\n      bypassAuthState\n    );\n    _assert(response.idToken, auth, AuthErrorCode.INTERNAL_ERROR);\n    const parsed = _parseToken(response.idToken);\n    _assert(parsed, auth, AuthErrorCode.INTERNAL_ERROR);\n\n    const { sub: localId } = parsed;\n    _assert(user.uid === localId, auth, AuthErrorCode.USER_MISMATCH);\n\n    return UserCredentialImpl._forOperation(user, operationType, response);\n  } catch (e) {\n    // Convert user deleted error into user mismatch\n    if ((e as FirebaseError)?.code === `auth/${AuthErrorCode.USER_DELETED}`) {\n      _fail(auth, AuthErrorCode.USER_MISMATCH);\n    }\n    throw e;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { UserCredential, Auth, User } from '../../model/public_types';\n\nimport { _processCredentialSavingMfaContextIfNecessary } from '../../mfa/mfa_error';\nimport { AuthInternal } from '../../model/auth';\nimport { UserInternal } from '../../model/user';\nimport { AuthCredential } from '../credentials';\nimport { _assertLinkedStatus, _link } from '../user/link_unlink';\nimport { _reauthenticate } from '../user/reauthenticate';\nimport { UserCredentialImpl } from '../user/user_credential_impl';\nimport { _castAuth } from '../auth/auth_impl';\nimport { getModularInstance } from '@firebase/util';\nimport { OperationType } from '../../model/enums';\nimport { _isFirebaseServerApp } from '@firebase/app';\nimport { _serverAppCurrentUserOperationNotSupportedError } from '../../core/util/assert';\n\nexport async function _signInWithCredential(\n  auth: AuthInternal,\n  credential: AuthCredential,\n  bypassAuthState = false\n): Promise<UserCredential> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const operationType = OperationType.SIGN_IN;\n  const response = await _processCredentialSavingMfaContextIfNecessary(\n    auth,\n    operationType,\n    credential\n  );\n  const userCredential = await UserCredentialImpl._fromIdTokenResponse(\n    auth,\n    operationType,\n    response\n  );\n\n  if (!bypassAuthState) {\n    await auth._updateCurrentUser(userCredential.user);\n  }\n  return userCredential;\n}\n\n/**\n * Asynchronously signs in with the given credentials.\n *\n * @remarks\n * An {@link AuthProvider} can be used to generate the credential.\n *\n * This method is not supported by {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * @param auth - The {@link Auth} instance.\n * @param credential - The auth credential.\n *\n * @public\n */\nexport async function signInWithCredential(\n  auth: Auth,\n  credential: AuthCredential\n): Promise<UserCredential> {\n  return _signInWithCredential(_castAuth(auth), credential);\n}\n\n/**\n * Links the user account with the given credentials.\n *\n * @remarks\n * An {@link AuthProvider} can be used to generate the credential.\n *\n * @param user - The user.\n * @param credential - The auth credential.\n *\n * @public\n */\nexport async function linkWithCredential(\n  user: User,\n  credential: AuthCredential\n): Promise<UserCredential> {\n  const userInternal = getModularInstance(user) as UserInternal;\n\n  await _assertLinkedStatus(false, userInternal, credential.providerId);\n\n  return _link(userInternal, credential);\n}\n\n/**\n * Re-authenticates a user using a fresh credential.\n *\n * @remarks\n * Use before operations such as {@link updatePassword} that require tokens from recent sign-in\n * attempts. This method can be used to recover from a `CREDENTIAL_TOO_OLD_LOGIN_AGAIN` error\n * or a `TOKEN_EXPIRED` error.\n *\n * This method is not supported on any {@link User} signed in by {@link Auth} instances\n * created with a {@link @firebase/app#FirebaseServerApp}.\n *\n * @param user - The user.\n * @param credential - The auth credential.\n *\n * @public\n */\nexport async function reauthenticateWithCredential(\n  user: User,\n  credential: AuthCredential\n): Promise<UserCredential> {\n  return _reauthenticate(getModularInstance(user) as UserInternal, credential);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Auth, UserCredential } from '../../model/public_types';\n\nimport { signInWithCustomToken as getIdTokenResponse } from '../../api/authentication/custom_token';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { UserCredentialImpl } from '../user/user_credential_impl';\nimport { _castAuth } from '../auth/auth_impl';\nimport { OperationType } from '../../model/enums';\nimport { _isFirebaseServerApp } from '@firebase/app';\nimport { _serverAppCurrentUserOperationNotSupportedError } from '../../core/util/assert';\n/**\n * Asynchronously signs in using a custom token.\n *\n * @remarks\n * Custom tokens are used to integrate Firebase Auth with existing auth systems, and must\n * be generated by an auth backend using the\n * {@link https://firebase.google.com/docs/reference/admin/node/admin.auth.Auth#createcustomtoken | createCustomToken}\n * method in the {@link https://firebase.google.com/docs/auth/admin | Admin SDK} .\n *\n * Fails with an error if the token is invalid, expired, or not accepted by the Firebase Auth service.\n *\n * This method is not supported by {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * @param auth - The {@link Auth} instance.\n * @param customToken - The custom token to sign in with.\n *\n * @public\n */\nexport async function signInWithCustomToken(\n  auth: Auth,\n  customToken: string\n): Promise<UserCredential> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const authInternal = _castAuth(auth);\n  const response: IdTokenResponse = await getIdTokenResponse(authInternal, {\n    token: customToken,\n    returnSecureToken: true\n  });\n  const cred = await UserCredentialImpl._fromIdTokenResponse(\n    authInternal,\n    OperationType.SIGN_IN,\n    response\n  );\n  await authInternal._updateCurrentUser(cred.user);\n  return cred;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Endpoint,\n  HttpMethod,\n  _addTidIfNecessary,\n  _performSignInRequest\n} from '../index';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { Auth } from '../../model/public_types';\n\nexport interface SignInWithCustomTokenRequest {\n  token: string;\n  returnSecureToken: boolean;\n  tenantId?: string;\n}\n\nexport interface SignInWithCustomTokenResponse extends IdTokenResponse {}\n\nexport async function signInWithCustomToken(\n  auth: Auth,\n  request: SignInWithCustomTokenRequest\n): Promise<SignInWithCustomTokenResponse> {\n  return _performSignInRequest<\n    SignInWithCustomTokenRequest,\n    SignInWithCustomTokenResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SIGN_IN_WITH_CUSTOM_TOKEN,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  FactorId,\n  MultiFactorInfo,\n  PhoneMultiFactorInfo,\n  TotpMultiFactorInfo\n} from '../model/public_types';\nimport {\n  PhoneMfaEnrollment,\n  MfaEnrollment,\n  TotpMfaEnrollment\n} from '../api/account_management/mfa';\nimport { AuthErrorCode } from '../core/errors';\nimport { _fail } from '../core/util/assert';\nimport { AuthInternal } from '../model/auth';\n\nexport abstract class MultiFactorInfoImpl implements MultiFactorInfo {\n  readonly uid: string;\n  readonly displayName?: string | null;\n  readonly enrollmentTime: string;\n\n  protected constructor(readonly factorId: FactorId, response: MfaEnrollment) {\n    this.uid = response.mfaEnrollmentId;\n    this.enrollmentTime = new Date(response.enrolledAt).toUTCString();\n    this.displayName = response.displayName;\n  }\n\n  static _fromServerResponse(\n    auth: AuthInternal,\n    enrollment: MfaEnrollment\n  ): MultiFactorInfoImpl {\n    if ('phoneInfo' in enrollment) {\n      return PhoneMultiFactorInfoImpl._fromServerResponse(auth, enrollment);\n    } else if ('totpInfo' in enrollment) {\n      return TotpMultiFactorInfoImpl._fromServerResponse(auth, enrollment);\n    }\n    return _fail(auth, AuthErrorCode.INTERNAL_ERROR);\n  }\n}\n\nexport class PhoneMultiFactorInfoImpl\n  extends MultiFactorInfoImpl\n  implements PhoneMultiFactorInfo\n{\n  readonly phoneNumber: string;\n\n  private constructor(response: PhoneMfaEnrollment) {\n    super(FactorId.PHONE, response);\n    this.phoneNumber = response.phoneInfo;\n  }\n\n  static _fromServerResponse(\n    _auth: AuthInternal,\n    enrollment: MfaEnrollment\n  ): PhoneMultiFactorInfoImpl {\n    return new PhoneMultiFactorInfoImpl(enrollment as PhoneMfaEnrollment);\n  }\n}\nexport class TotpMultiFactorInfoImpl\n  extends MultiFactorInfoImpl\n  implements TotpMultiFactorInfo\n{\n  private constructor(response: TotpMfaEnrollment) {\n    super(FactorId.TOTP, response);\n  }\n\n  static _fromServerResponse(\n    _auth: AuthInternal,\n    enrollment: MfaEnrollment\n  ): TotpMultiFactorInfoImpl {\n    return new TotpMultiFactorInfoImpl(enrollment as TotpMfaEnrollment);\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { ActionCodeSettings, Auth } from '../../model/public_types';\n\nimport { GetOobCodeRequest } from '../../api/authentication/email_and_password';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\n\nexport function _setActionCodeSettingsOnRequest(\n  auth: Auth,\n  request: GetOobCodeRequest,\n  actionCodeSettings: ActionCodeSettings\n): void {\n  _assert(\n    actionCodeSettings.url?.length > 0,\n    auth,\n    AuthErrorCode.INVALID_CONTINUE_URI\n  );\n  _assert(\n    typeof actionCodeSettings.dynamicLinkDomain === 'undefined' ||\n      actionCodeSettings.dynamicLinkDomain.length > 0,\n    auth,\n    AuthErrorCode.INVALID_DYNAMIC_LINK_DOMAIN\n  );\n  _assert(\n    typeof actionCodeSettings.linkDomain === 'undefined' ||\n      actionCodeSettings.linkDomain.length > 0,\n    auth,\n    AuthErrorCode.INVALID_HOSTING_LINK_DOMAIN\n  );\n\n  request.continueUrl = actionCodeSettings.url;\n  request.dynamicLinkDomain = actionCodeSettings.dynamicLinkDomain;\n  request.linkDomain = actionCodeSettings.linkDomain;\n  request.canHandleCodeInApp = actionCodeSettings.handleCodeInApp;\n\n  if (actionCodeSettings.iOS) {\n    _assert(\n      actionCodeSettings.iOS.bundleId.length > 0,\n      auth,\n      AuthErrorCode.MISSING_IOS_BUNDLE_ID\n    );\n    request.iOSBundleId = actionCodeSettings.iOS.bundleId;\n  }\n\n  if (actionCodeSettings.android) {\n    _assert(\n      actionCodeSettings.android.packageName.length > 0,\n      auth,\n      AuthErrorCode.MISSING_ANDROID_PACKAGE_NAME\n    );\n    request.androidInstallApp = actionCodeSettings.android.installApp;\n    request.androidMinimumVersionCode =\n      actionCodeSettings.android.minimumVersion;\n    request.androidPackageName = actionCodeSettings.android.packageName;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  ActionCodeInfo,\n  ActionCodeOperation,\n  ActionCodeSettings,\n  Auth,\n  UserCredential\n} from '../../model/public_types';\n\nimport * as account from '../../api/account_management/email_and_password';\nimport * as authentication from '../../api/authentication/email_and_password';\nimport { signUp, SignUpRequest } from '../../api/authentication/sign_up';\nimport { MultiFactorInfoImpl } from '../../mfa/mfa_info';\nimport { EmailAuthProvider } from '../providers/email';\nimport { UserCredentialImpl } from '../user/user_credential_impl';\nimport {\n  _assert,\n  _serverAppCurrentUserOperationNotSupportedError\n} from '../util/assert';\nimport { _setActionCodeSettingsOnRequest } from './action_code_settings';\nimport { signInWithCredential } from './credential';\nimport { _castAuth } from '../auth/auth_impl';\nimport { AuthErrorCode } from '../errors';\nimport { getModularInstance } from '@firebase/util';\nimport { OperationType } from '../../model/enums';\nimport { handleRecaptchaFlow } from '../../platform_browser/recaptcha/recaptcha_enterprise_verifier';\nimport { IdTokenResponse } from '../../model/id_token';\nimport {\n  RecaptchaActionName,\n  RecaptchaClientType,\n  RecaptchaAuthProvider\n} from '../../api';\nimport { _isFirebaseServerApp } from '@firebase/app';\n\n/**\n * Updates the password policy cached in the {@link Auth} instance if a policy is already\n * cached for the project or tenant.\n *\n * @remarks\n * We only fetch the password policy if the password did not meet policy requirements and\n * there is an existing policy cached. A developer must call validatePassword at least\n * once for the cache to be automatically updated.\n *\n * @param auth - The {@link Auth} instance.\n *\n * @private\n */\nasync function recachePasswordPolicy(auth: Auth): Promise<void> {\n  const authInternal = _castAuth(auth);\n  if (authInternal._getPasswordPolicyInternal()) {\n    await authInternal._updatePasswordPolicy();\n  }\n}\n\n/**\n * Sends a password reset email to the given email address. This method does not throw an error when\n * there's no user account with the given email address and\n * {@link https://cloud.google.com/identity-platform/docs/admin/email-enumeration-protection | Email Enumeration Protection}\n * is enabled.\n *\n * @remarks\n * To complete the password reset, call {@link confirmPasswordReset} with the code supplied in\n * the email sent to the user, along with the new password specified by the user.\n *\n * @example\n * ```javascript\n * const actionCodeSettings = {\n *   url: 'https://www.example.com/?email=user@example.com',\n *   iOS: {\n *      bundleId: 'com.example.ios'\n *   },\n *   android: {\n *     packageName: 'com.example.android',\n *     installApp: true,\n *     minimumVersion: '12'\n *   },\n *   handleCodeInApp: true\n * };\n * await sendPasswordResetEmail(auth, 'user@example.com', actionCodeSettings);\n * // Obtain code from user.\n * await confirmPasswordReset('user@example.com', code);\n * ```\n *\n * @param auth - The {@link Auth} instance.\n * @param email - The user's email address.\n * @param actionCodeSettings - The {@link ActionCodeSettings}.\n *\n * @public\n */\nexport async function sendPasswordResetEmail(\n  auth: Auth,\n  email: string,\n  actionCodeSettings?: ActionCodeSettings\n): Promise<void> {\n  const authInternal = _castAuth(auth);\n  const request: authentication.PasswordResetRequest = {\n    requestType: ActionCodeOperation.PASSWORD_RESET,\n    email,\n    clientType: RecaptchaClientType.WEB\n  };\n  if (actionCodeSettings) {\n    _setActionCodeSettingsOnRequest(authInternal, request, actionCodeSettings);\n  }\n  await handleRecaptchaFlow(\n    authInternal,\n    request,\n    RecaptchaActionName.GET_OOB_CODE,\n    authentication.sendPasswordResetEmail,\n    RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER\n  );\n}\n\n/**\n * Completes the password reset process, given a confirmation code and new password.\n *\n * @param auth - The {@link Auth} instance.\n * @param oobCode - A confirmation code sent to the user.\n * @param newPassword - The new password.\n *\n * @public\n */\nexport async function confirmPasswordReset(\n  auth: Auth,\n  oobCode: string,\n  newPassword: string\n): Promise<void> {\n  await account\n    .resetPassword(getModularInstance(auth), {\n      oobCode,\n      newPassword\n    })\n    .catch(async error => {\n      if (\n        error.code ===\n        `auth/${AuthErrorCode.PASSWORD_DOES_NOT_MEET_REQUIREMENTS}`\n      ) {\n        void recachePasswordPolicy(auth);\n      }\n\n      throw error;\n    });\n  // Do not return the email.\n}\n\n/**\n * Applies a verification code sent to the user by email or other out-of-band mechanism.\n *\n * @param auth - The {@link Auth} instance.\n * @param oobCode - A verification code sent to the user.\n *\n * @public\n */\nexport async function applyActionCode(\n  auth: Auth,\n  oobCode: string\n): Promise<void> {\n  await account.applyActionCode(getModularInstance(auth), { oobCode });\n}\n\n/**\n * Checks a verification code sent to the user by email or other out-of-band mechanism.\n *\n * @returns metadata about the code.\n *\n * @param auth - The {@link Auth} instance.\n * @param oobCode - A verification code sent to the user.\n *\n * @public\n */\nexport async function checkActionCode(\n  auth: Auth,\n  oobCode: string\n): Promise<ActionCodeInfo> {\n  const authModular = getModularInstance(auth);\n  const response = await account.resetPassword(authModular, { oobCode });\n\n  // Email could be empty only if the request type is EMAIL_SIGNIN or\n  // VERIFY_AND_CHANGE_EMAIL.\n  // New email should not be empty if the request type is\n  // VERIFY_AND_CHANGE_EMAIL.\n  // Multi-factor info could not be empty if the request type is\n  // REVERT_SECOND_FACTOR_ADDITION.\n  const operation = response.requestType;\n  _assert(operation, authModular, AuthErrorCode.INTERNAL_ERROR);\n  switch (operation) {\n    case ActionCodeOperation.EMAIL_SIGNIN:\n      break;\n    case ActionCodeOperation.VERIFY_AND_CHANGE_EMAIL:\n      _assert(response.newEmail, authModular, AuthErrorCode.INTERNAL_ERROR);\n      break;\n    case ActionCodeOperation.REVERT_SECOND_FACTOR_ADDITION:\n      _assert(response.mfaInfo, authModular, AuthErrorCode.INTERNAL_ERROR);\n    // fall through\n    default:\n      _assert(response.email, authModular, AuthErrorCode.INTERNAL_ERROR);\n  }\n\n  // The multi-factor info for revert second factor addition\n  let multiFactorInfo: MultiFactorInfoImpl | null = null;\n  if (response.mfaInfo) {\n    multiFactorInfo = MultiFactorInfoImpl._fromServerResponse(\n      _castAuth(authModular),\n      response.mfaInfo\n    );\n  }\n\n  return {\n    data: {\n      email:\n        (response.requestType === ActionCodeOperation.VERIFY_AND_CHANGE_EMAIL\n          ? response.newEmail\n          : response.email) || null,\n      previousEmail:\n        (response.requestType === ActionCodeOperation.VERIFY_AND_CHANGE_EMAIL\n          ? response.email\n          : response.newEmail) || null,\n      multiFactorInfo\n    },\n    operation\n  };\n}\n\n/**\n * Checks a password reset code sent to the user by email or other out-of-band mechanism.\n *\n * @returns the user's email address if valid.\n *\n * @param auth - The {@link Auth} instance.\n * @param code - A verification code sent to the user.\n *\n * @public\n */\nexport async function verifyPasswordResetCode(\n  auth: Auth,\n  code: string\n): Promise<string> {\n  const { data } = await checkActionCode(getModularInstance(auth), code);\n  // Email should always be present since a code was sent to it\n  return data.email!;\n}\n\n/**\n * Creates a new user account associated with the specified email address and password.\n *\n * @remarks\n * On successful creation of the user account, this user will also be signed in to your application.\n *\n * User account creation can fail if the account already exists or the password is invalid.\n *\n * This method is not supported on {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * Note: The email address acts as a unique identifier for the user and enables an email-based\n * password reset. This function will create a new user account and set the initial user password.\n *\n * @param auth - The {@link Auth} instance.\n * @param email - The user's email address.\n * @param password - The user's chosen password.\n *\n * @public\n */\nexport async function createUserWithEmailAndPassword(\n  auth: Auth,\n  email: string,\n  password: string\n): Promise<UserCredential> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const authInternal = _castAuth(auth);\n  const request: SignUpRequest = {\n    returnSecureToken: true,\n    email,\n    password,\n    clientType: RecaptchaClientType.WEB\n  };\n  const signUpResponse: Promise<IdTokenResponse> = handleRecaptchaFlow(\n    authInternal,\n    request,\n    RecaptchaActionName.SIGN_UP_PASSWORD,\n    signUp,\n    RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER\n  );\n  const response = await signUpResponse.catch(error => {\n    if (\n      error.code === `auth/${AuthErrorCode.PASSWORD_DOES_NOT_MEET_REQUIREMENTS}`\n    ) {\n      void recachePasswordPolicy(auth);\n    }\n\n    throw error;\n  });\n\n  const userCredential = await UserCredentialImpl._fromIdTokenResponse(\n    authInternal,\n    OperationType.SIGN_IN,\n    response\n  );\n  await authInternal._updateCurrentUser(userCredential.user);\n\n  return userCredential;\n}\n\n/**\n * Asynchronously signs in using an email and password.\n *\n * @remarks\n * Fails with an error if the email address and password do not match. When\n * {@link https://cloud.google.com/identity-platform/docs/admin/email-enumeration-protection | Email Enumeration Protection}\n * is enabled, this method fails with \"auth/invalid-credential\" in case of an invalid\n * email/password.\n *\n * This method is not supported on {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * Note: The user's password is NOT the password used to access the user's email account. The\n * email address serves as a unique identifier for the user, and the password is used to access\n * the user's account in your Firebase project. See also: {@link createUserWithEmailAndPassword}.\n *\n *\n * @param auth - The {@link Auth} instance.\n * @param email - The users email address.\n * @param password - The users password.\n *\n * @public\n */\nexport function signInWithEmailAndPassword(\n  auth: Auth,\n  email: string,\n  password: string\n): Promise<UserCredential> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  return signInWithCredential(\n    getModularInstance(auth),\n    EmailAuthProvider.credential(email, password)\n  ).catch(async error => {\n    if (\n      error.code === `auth/${AuthErrorCode.PASSWORD_DOES_NOT_MEET_REQUIREMENTS}`\n    ) {\n      void recachePasswordPolicy(auth);\n    }\n\n    throw error;\n  });\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  ActionCodeOperation,\n  ActionCodeSettings,\n  Auth,\n  User\n} from '../../model/public_types';\n\nimport {\n  createAuthUri,\n  CreateAuthUriRequest\n} from '../../api/authentication/create_auth_uri';\nimport * as api from '../../api/authentication/email_and_password';\nimport { UserInternal } from '../../model/user';\nimport { _getCurrentUrl, _isHttpOrHttps } from '../util/location';\nimport { _setActionCodeSettingsOnRequest } from './action_code_settings';\nimport { getModularInstance } from '@firebase/util';\n\n/**\n * Gets the list of possible sign in methods for the given email address. This method returns an\n * empty list when\n * {@link https://cloud.google.com/identity-platform/docs/admin/email-enumeration-protection | Email Enumeration Protection}\n * is enabled, irrespective of the number of authentication methods available for the given email.\n *\n * @remarks\n * This is useful to differentiate methods of sign-in for the same provider, eg.\n * {@link EmailAuthProvider} which has 2 methods of sign-in,\n * {@link SignInMethod}.EMAIL_PASSWORD and\n * {@link SignInMethod}.EMAIL_LINK.\n *\n * @param auth - The {@link Auth} instance.\n * @param email - The user's email address.\n *\n * Deprecated. Migrating off of this method is recommended as a security best-practice.\n * Learn more in the Identity Platform documentation for\n * {@link https://cloud.google.com/identity-platform/docs/admin/email-enumeration-protection | Email Enumeration Protection}.\n * @public\n */\nexport async function fetchSignInMethodsForEmail(\n  auth: Auth,\n  email: string\n): Promise<string[]> {\n  // createAuthUri returns an error if continue URI is not http or https.\n  // For environments like Cordova, Chrome extensions, native frameworks, file\n  // systems, etc, use http://localhost as continue URL.\n  const continueUri = _isHttpOrHttps() ? _getCurrentUrl() : 'http://localhost';\n  const request: CreateAuthUriRequest = {\n    identifier: email,\n    continueUri\n  };\n\n  const { signinMethods } = await createAuthUri(\n    getModularInstance(auth),\n    request\n  );\n\n  return signinMethods || [];\n}\n\n/**\n * Sends a verification email to a user.\n *\n * @remarks\n * The verification process is completed by calling {@link applyActionCode}.\n *\n * @example\n * ```javascript\n * const actionCodeSettings = {\n *   url: 'https://www.example.com/?email=user@example.com',\n *   iOS: {\n *      bundleId: 'com.example.ios'\n *   },\n *   android: {\n *     packageName: 'com.example.android',\n *     installApp: true,\n *     minimumVersion: '12'\n *   },\n *   handleCodeInApp: true\n * };\n * await sendEmailVerification(user, actionCodeSettings);\n * // Obtain code from the user.\n * await applyActionCode(auth, code);\n * ```\n *\n * @param user - The user.\n * @param actionCodeSettings - The {@link ActionCodeSettings}.\n *\n * @public\n */\nexport async function sendEmailVerification(\n  user: User,\n  actionCodeSettings?: ActionCodeSettings | null\n): Promise<void> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  const idToken = await user.getIdToken();\n  const request: api.VerifyEmailRequest = {\n    requestType: ActionCodeOperation.VERIFY_EMAIL,\n    idToken\n  };\n  if (actionCodeSettings) {\n    _setActionCodeSettingsOnRequest(\n      userInternal.auth,\n      request,\n      actionCodeSettings\n    );\n  }\n\n  const { email } = await api.sendEmailVerification(userInternal.auth, request);\n\n  if (email !== user.email) {\n    await user.reload();\n  }\n}\n\n/**\n * Sends a verification email to a new email address.\n *\n * @remarks\n * The user's email will be updated to the new one after being verified.\n *\n * If you have a custom email action handler, you can complete the verification process by calling\n * {@link applyActionCode}.\n *\n * @example\n * ```javascript\n * const actionCodeSettings = {\n *   url: 'https://www.example.com/?email=user@example.com',\n *   iOS: {\n *      bundleId: 'com.example.ios'\n *   },\n *   android: {\n *     packageName: 'com.example.android',\n *     installApp: true,\n *     minimumVersion: '12'\n *   },\n *   handleCodeInApp: true\n * };\n * await verifyBeforeUpdateEmail(user, 'newemail@example.com', actionCodeSettings);\n * // Obtain code from the user.\n * await applyActionCode(auth, code);\n * ```\n *\n * @param user - The user.\n * @param newEmail - The new email address to be verified before update.\n * @param actionCodeSettings - The {@link ActionCodeSettings}.\n *\n * @public\n */\nexport async function verifyBeforeUpdateEmail(\n  user: User,\n  newEmail: string,\n  actionCodeSettings?: ActionCodeSettings | null\n): Promise<void> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  const idToken = await user.getIdToken();\n  const request: api.VerifyAndChangeEmailRequest = {\n    requestType: ActionCodeOperation.VERIFY_AND_CHANGE_EMAIL,\n    idToken,\n    newEmail\n  };\n  if (actionCodeSettings) {\n    _setActionCodeSettingsOnRequest(\n      userInternal.auth,\n      request,\n      actionCodeSettings\n    );\n  }\n\n  const { email } = await api.verifyAndChangeEmail(userInternal.auth, request);\n\n  if (email !== user.email) {\n    // If the local copy of the email on user is outdated, reload the\n    // user.\n    await user.reload();\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Endpoint,\n  HttpMethod,\n  _addTidIfNecessary,\n  _performApiRequest\n} from '../index';\nimport { Auth } from '../../model/public_types';\n\nexport interface CreateAuthUriRequest {\n  identifier: string;\n  continueUri: string;\n  tenantId?: string;\n}\n\nexport interface CreateAuthUriResponse {\n  signinMethods: string[];\n}\n\nexport async function createAuthUri(\n  auth: Auth,\n  request: CreateAuthUriRequest\n): Promise<CreateAuthUriResponse> {\n  return _performApiRequest<CreateAuthUriRequest, CreateAuthUriResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.CREATE_AUTH_URI,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { User } from '../../model/public_types';\n\nimport {\n  updateEmailPassword as apiUpdateEmailPassword,\n  UpdateEmailPasswordRequest\n} from '../../api/account_management/email_and_password';\nimport { updateProfile as apiUpdateProfile } from '../../api/account_management/profile';\nimport { UserInternal } from '../../model/user';\nimport { _logoutIfInvalidated } from './invalidation';\nimport { getModularInstance } from '@firebase/util';\nimport { ProviderId } from '../../model/enums';\nimport { _isFirebaseServerApp } from '@firebase/app';\nimport { _serverAppCurrentUserOperationNotSupportedError } from '../../core/util/assert';\n\n/**\n * Updates a user's profile data.\n *\n * @param user - The user.\n * @param profile - The profile's `displayName` and `photoURL` to update.\n *\n * @public\n */\nexport async function updateProfile(\n  user: User,\n  {\n    displayName,\n    photoURL: photoUrl\n  }: { displayName?: string | null; photoURL?: string | null }\n): Promise<void> {\n  if (displayName === undefined && photoUrl === undefined) {\n    return;\n  }\n\n  const userInternal = getModularInstance(user) as UserInternal;\n  const idToken = await userInternal.getIdToken();\n  const profileRequest = {\n    idToken,\n    displayName,\n    photoUrl,\n    returnSecureToken: true\n  };\n  const response = await _logoutIfInvalidated(\n    userInternal,\n    apiUpdateProfile(userInternal.auth, profileRequest)\n  );\n\n  userInternal.displayName = response.displayName || null;\n  userInternal.photoURL = response.photoUrl || null;\n\n  // Update the password provider as well\n  const passwordProvider = userInternal.providerData.find(\n    ({ providerId }) => providerId === ProviderId.PASSWORD\n  );\n  if (passwordProvider) {\n    passwordProvider.displayName = userInternal.displayName;\n    passwordProvider.photoURL = userInternal.photoURL;\n  }\n\n  await userInternal._updateTokensIfNecessary(response);\n}\n\n/**\n * Updates the user's email address.\n *\n * @remarks\n * An email will be sent to the original email address (if it was set) that allows to revoke the\n * email address change, in order to protect them from account hijacking.\n *\n * This method is not supported on any {@link User} signed in by {@link Auth} instances\n * created with a {@link @firebase/app#FirebaseServerApp}.\n *\n * Important: this is a security sensitive operation that requires the user to have recently signed\n * in. If this requirement isn't met, ask the user to authenticate again and then call\n * {@link reauthenticateWithCredential}.\n *\n * @param user - The user.\n * @param newEmail - The new email address.\n *\n * Throws \"auth/operation-not-allowed\" error when\n * {@link https://cloud.google.com/identity-platform/docs/admin/email-enumeration-protection | Email Enumeration Protection}\n * is enabled.\n * Deprecated - Use {@link verifyBeforeUpdateEmail} instead.\n *\n * @public\n */\nexport function updateEmail(user: User, newEmail: string): Promise<void> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  if (_isFirebaseServerApp(userInternal.auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(userInternal.auth)\n    );\n  }\n  return updateEmailOrPassword(userInternal, newEmail, null);\n}\n\n/**\n * Updates the user's password.\n *\n * @remarks\n * Important: this is a security sensitive operation that requires the user to have recently signed\n * in. If this requirement isn't met, ask the user to authenticate again and then call\n * {@link reauthenticateWithCredential}.\n *\n * @param user - The user.\n * @param newPassword - The new password.\n *\n * @public\n */\nexport function updatePassword(user: User, newPassword: string): Promise<void> {\n  return updateEmailOrPassword(\n    getModularInstance(user) as UserInternal,\n    null,\n    newPassword\n  );\n}\n\nasync function updateEmailOrPassword(\n  user: UserInternal,\n  email: string | null,\n  password: string | null\n): Promise<void> {\n  const { auth } = user;\n  const idToken = await user.getIdToken();\n  const request: UpdateEmailPasswordRequest = {\n    idToken,\n    returnSecureToken: true\n  };\n\n  if (email) {\n    request.email = email;\n  }\n\n  if (password) {\n    request.password = password;\n  }\n\n  const response = await _logoutIfInvalidated(\n    user,\n    apiUpdateEmailPassword(auth, request)\n  );\n  await user._updateTokensIfNecessary(response, /* reload */ true);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Endpoint, HttpMethod, _performApiRequest } from '../index';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { Auth } from '../../model/public_types';\n\nexport interface UpdateProfileRequest {\n  idToken: string;\n  displayName?: string | null;\n  photoUrl?: string | null;\n  returnSecureToken: boolean;\n}\n\nexport interface UpdateProfileResponse extends IdTokenResponse {\n  displayName?: string | null;\n  photoUrl?: string | null;\n}\n\nexport async function updateProfile(\n  auth: Auth,\n  request: UpdateProfileRequest\n): Promise<UpdateProfileResponse> {\n  return _performApiRequest<UpdateProfileRequest, UpdateProfileResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.SET_ACCOUNT_INFO,\n    request\n  );\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AdditionalUserInfo, UserCredential } from '../../model/public_types';\nimport { IdTokenResponse, IdTokenResponseKind } from '../../model/id_token';\nimport { _parseToken } from './id_token_result';\nimport { UserCredentialInternal } from '../../model/user';\nimport { ProviderId } from '../../model/enums';\n\n/**\n * Parse the `AdditionalUserInfo` from the ID token response.\n *\n */\nexport function _fromIdTokenResponse(\n  idTokenResponse?: IdTokenResponse\n): AdditionalUserInfo | null {\n  if (!idTokenResponse) {\n    return null;\n  }\n  const { providerId } = idTokenResponse;\n  const profile = idTokenResponse.rawUserInfo\n    ? JSON.parse(idTokenResponse.rawUserInfo)\n    : {};\n  const isNewUser =\n    idTokenResponse.isNewUser ||\n    idTokenResponse.kind === IdTokenResponseKind.SignupNewUser;\n  if (!providerId && idTokenResponse?.idToken) {\n    const signInProvider = _parseToken(idTokenResponse.idToken)?.firebase?.[\n      'sign_in_provider'\n    ];\n    if (signInProvider) {\n      const filteredProviderId =\n        signInProvider !== ProviderId.ANONYMOUS &&\n        signInProvider !== ProviderId.CUSTOM\n          ? (signInProvider as ProviderId)\n          : null;\n      // Uses generic class in accordance with the legacy SDK.\n      return new GenericAdditionalUserInfo(isNewUser, filteredProviderId);\n    }\n  }\n  if (!providerId) {\n    return null;\n  }\n  switch (providerId) {\n    case ProviderId.FACEBOOK:\n      return new FacebookAdditionalUserInfo(isNewUser, profile);\n    case ProviderId.GITHUB:\n      return new GithubAdditionalUserInfo(isNewUser, profile);\n    case ProviderId.GOOGLE:\n      return new GoogleAdditionalUserInfo(isNewUser, profile);\n    case ProviderId.TWITTER:\n      return new TwitterAdditionalUserInfo(\n        isNewUser,\n        profile,\n        idTokenResponse.screenName || null\n      );\n    case ProviderId.CUSTOM:\n    case ProviderId.ANONYMOUS:\n      return new GenericAdditionalUserInfo(isNewUser, null);\n    default:\n      return new GenericAdditionalUserInfo(isNewUser, providerId, profile);\n  }\n}\n\nclass GenericAdditionalUserInfo implements AdditionalUserInfo {\n  constructor(\n    readonly isNewUser: boolean,\n    readonly providerId: ProviderId | string | null,\n    readonly profile: Record<string, unknown> = {}\n  ) {}\n}\n\nclass FederatedAdditionalUserInfoWithUsername extends GenericAdditionalUserInfo {\n  constructor(\n    isNewUser: boolean,\n    providerId: ProviderId,\n    profile: Record<string, unknown>,\n    readonly username: string | null\n  ) {\n    super(isNewUser, providerId, profile);\n  }\n}\n\nclass FacebookAdditionalUserInfo extends GenericAdditionalUserInfo {\n  constructor(isNewUser: boolean, profile: Record<string, unknown>) {\n    super(isNewUser, ProviderId.FACEBOOK, profile);\n  }\n}\n\nclass GithubAdditionalUserInfo extends FederatedAdditionalUserInfoWithUsername {\n  constructor(isNewUser: boolean, profile: Record<string, unknown>) {\n    super(\n      isNewUser,\n      ProviderId.GITHUB,\n      profile,\n      typeof profile?.login === 'string' ? profile?.login : null\n    );\n  }\n}\n\nclass GoogleAdditionalUserInfo extends GenericAdditionalUserInfo {\n  constructor(isNewUser: boolean, profile: Record<string, unknown>) {\n    super(isNewUser, ProviderId.GOOGLE, profile);\n  }\n}\n\nclass TwitterAdditionalUserInfo extends FederatedAdditionalUserInfoWithUsername {\n  constructor(\n    isNewUser: boolean,\n    profile: Record<string, unknown>,\n    screenName: string | null\n  ) {\n    super(isNewUser, ProviderId.TWITTER, profile, screenName);\n  }\n}\n\n/**\n * Extracts provider specific {@link AdditionalUserInfo} for the given credential.\n *\n * @param userCredential - The user credential.\n *\n * @public\n */\nexport function getAdditionalUserInfo(\n  userCredential: UserCredential\n): AdditionalUserInfo | null {\n  const { user, _tokenResponse } = userCredential as UserCredentialInternal;\n  if (user.isAnonymous && !_tokenResponse) {\n    // Handle the special case where signInAnonymously() gets called twice.\n    // No network call is made so there's nothing to actually fill this in\n    return {\n      providerId: null,\n      isNewUser: false,\n      profile: null\n    };\n  }\n\n  return _fromIdTokenResponse(_tokenResponse);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { UserInternal } from '../model/user';\nimport { MultiFactorSession } from '../model/public_types';\n\nexport const enum MultiFactorSessionType {\n  ENROLL = 'enroll',\n  SIGN_IN = 'signin'\n}\n\ninterface SerializedMultiFactorSession {\n  multiFactorSession: {\n    idToken?: string;\n    pendingCredential?: string;\n  };\n}\n\nexport class MultiFactorSessionImpl implements MultiFactorSession {\n  private constructor(\n    readonly type: MultiFactorSessionType,\n    readonly credential: string,\n    readonly user?: UserInternal\n  ) {}\n\n  static _fromIdtoken(\n    idToken: string,\n    user?: UserInternal\n  ): MultiFactorSessionImpl {\n    return new MultiFactorSessionImpl(\n      MultiFactorSessionType.ENROLL,\n      idToken,\n      user\n    );\n  }\n\n  static _fromMfaPendingCredential(\n    mfaPendingCredential: string\n  ): MultiFactorSessionImpl {\n    return new MultiFactorSessionImpl(\n      MultiFactorSessionType.SIGN_IN,\n      mfaPendingCredential\n    );\n  }\n\n  toJSON(): SerializedMultiFactorSession {\n    const key =\n      this.type === MultiFactorSessionType.ENROLL\n        ? 'idToken'\n        : 'pendingCredential';\n    return {\n      multiFactorSession: {\n        [key]: this.credential\n      }\n    };\n  }\n\n  static fromJSON(\n    obj: Partial<SerializedMultiFactorSession>\n  ): MultiFactorSessionImpl | null {\n    if (obj?.multiFactorSession) {\n      if (obj.multiFactorSession?.pendingCredential) {\n        return MultiFactorSessionImpl._fromMfaPendingCredential(\n          obj.multiFactorSession.pendingCredential\n        );\n      } else if (obj.multiFactorSession?.idToken) {\n        return MultiFactorSessionImpl._fromIdtoken(\n          obj.multiFactorSession.idToken\n        );\n      }\n    }\n    return null;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Auth,\n  MultiFactorResolver,\n  UserCredential,\n  MultiFactorError\n} from '../model/public_types';\n\nimport { _castAuth } from '../core/auth/auth_impl';\nimport { AuthErrorCode } from '../core/errors';\nimport { UserCredentialImpl } from '../core/user/user_credential_impl';\nimport { _assert, _fail } from '../core/util/assert';\nimport { UserCredentialInternal } from '../model/user';\nimport { MultiFactorAssertionImpl } from './mfa_assertion';\nimport { MultiFactorError as MultiFactorErrorInternal } from './mfa_error';\nimport { MultiFactorInfoImpl } from './mfa_info';\nimport { MultiFactorSessionImpl } from './mfa_session';\nimport { getModularInstance } from '@firebase/util';\nimport { OperationType } from '../model/enums';\n\nexport class MultiFactorResolverImpl implements MultiFactorResolver {\n  private constructor(\n    readonly session: MultiFactorSessionImpl,\n    readonly hints: MultiFactorInfoImpl[],\n    private readonly signInResolver: (\n      assertion: MultiFactorAssertionImpl\n    ) => Promise<UserCredentialInternal>\n  ) {}\n\n  /** @internal */\n  static _fromError(\n    authExtern: Auth,\n    error: MultiFactorErrorInternal\n  ): MultiFactorResolverImpl {\n    const auth = _castAuth(authExtern);\n    const serverResponse = error.customData._serverResponse;\n    const hints = (serverResponse.mfaInfo || []).map(enrollment =>\n      MultiFactorInfoImpl._fromServerResponse(auth, enrollment)\n    );\n\n    _assert(\n      serverResponse.mfaPendingCredential,\n      auth,\n      AuthErrorCode.INTERNAL_ERROR\n    );\n    const session = MultiFactorSessionImpl._fromMfaPendingCredential(\n      serverResponse.mfaPendingCredential\n    );\n\n    return new MultiFactorResolverImpl(\n      session,\n      hints,\n      async (\n        assertion: MultiFactorAssertionImpl\n      ): Promise<UserCredentialInternal> => {\n        const mfaResponse = await assertion._process(auth, session);\n        // Clear out the unneeded fields from the old login response\n        delete serverResponse.mfaInfo;\n        delete serverResponse.mfaPendingCredential;\n\n        // Use in the new token & refresh token in the old response\n        const idTokenResponse = {\n          ...serverResponse,\n          idToken: mfaResponse.idToken,\n          refreshToken: mfaResponse.refreshToken\n        };\n\n        // TODO: we should collapse this switch statement into UserCredentialImpl._forOperation and have it support the SIGN_IN case\n        switch (error.operationType) {\n          case OperationType.SIGN_IN:\n            const userCredential =\n              await UserCredentialImpl._fromIdTokenResponse(\n                auth,\n                error.operationType,\n                idTokenResponse\n              );\n            await auth._updateCurrentUser(userCredential.user);\n            return userCredential;\n          case OperationType.REAUTHENTICATE:\n            _assert(error.user, auth, AuthErrorCode.INTERNAL_ERROR);\n            return UserCredentialImpl._forOperation(\n              error.user,\n              error.operationType,\n              idTokenResponse\n            );\n          default:\n            _fail(auth, AuthErrorCode.INTERNAL_ERROR);\n        }\n      }\n    );\n  }\n\n  async resolveSignIn(\n    assertionExtern: MultiFactorAssertionImpl\n  ): Promise<UserCredential> {\n    const assertion = assertionExtern as MultiFactorAssertionImpl;\n    return this.signInResolver(assertion);\n  }\n}\n\n/**\n * Provides a {@link MultiFactorResolver} suitable for completion of a\n * multi-factor flow.\n *\n * @param auth - The {@link Auth} instance.\n * @param error - The {@link MultiFactorError} raised during a sign-in, or\n * reauthentication operation.\n *\n * @public\n */\nexport function getMultiFactorResolver(\n  auth: Auth,\n  error: MultiFactorError\n): MultiFactorResolver {\n  const authModular = getModularInstance(auth);\n  const errorInternal = error as MultiFactorErrorInternal;\n  _assert(\n    error.customData.operationType,\n    authModular,\n    AuthErrorCode.ARGUMENT_ERROR\n  );\n  _assert(\n    errorInternal.customData._serverResponse?.mfaPendingCredential,\n    authModular,\n    AuthErrorCode.ARGUMENT_ERROR\n  );\n\n  return MultiFactorResolverImpl._fromError(authModular, errorInternal);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Endpoint,\n  HttpMethod,\n  RecaptchaClientType,\n  RecaptchaVersion,\n  _addTidIfNecessary,\n  _performApiRequest\n} from '../index';\nimport { SignInWithPhoneNumberRequest } from '../authentication/sms';\nimport { FinalizeMfaResponse } from '../authentication/mfa';\nimport { AuthInternal } from '../../model/auth';\n\n/**\n * MFA Info as returned by the API.\n */\ninterface BaseMfaEnrollment {\n  mfaEnrollmentId: string;\n  enrolledAt: number;\n  displayName?: string;\n}\n\n/**\n * An MFA provided by SMS verification.\n */\nexport interface PhoneMfaEnrollment extends BaseMfaEnrollment {\n  phoneInfo: string;\n}\n\n/**\n * An MFA provided by TOTP (Time-based One Time Password).\n */\nexport interface TotpMfaEnrollment extends BaseMfaEnrollment {}\n\n/**\n * MfaEnrollment can be any subtype of BaseMfaEnrollment, currently only PhoneMfaEnrollment and TotpMfaEnrollment are supported.\n */\nexport type MfaEnrollment = PhoneMfaEnrollment | TotpMfaEnrollment;\n\nexport interface StartPhoneMfaEnrollmentRequest {\n  idToken: string;\n  phoneEnrollmentInfo: {\n    phoneNumber: string;\n    // reCAPTCHA v2 token\n    recaptchaToken?: string;\n    // reCAPTCHA Enterprise token\n    captchaResponse?: string;\n    clientType?: RecaptchaClientType;\n    recaptchaVersion?: RecaptchaVersion;\n  };\n  tenantId?: string;\n}\n\nexport interface StartPhoneMfaEnrollmentResponse {\n  phoneSessionInfo: {\n    sessionInfo: string;\n  };\n}\n\nexport function startEnrollPhoneMfa(\n  auth: AuthInternal,\n  request: StartPhoneMfaEnrollmentRequest\n): Promise<StartPhoneMfaEnrollmentResponse> {\n  return _performApiRequest<\n    StartPhoneMfaEnrollmentRequest,\n    StartPhoneMfaEnrollmentResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.START_MFA_ENROLLMENT,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport interface FinalizePhoneMfaEnrollmentRequest {\n  idToken: string;\n  phoneVerificationInfo: SignInWithPhoneNumberRequest;\n  displayName?: string | null;\n  tenantId?: string;\n}\n\nexport interface FinalizePhoneMfaEnrollmentResponse\n  extends FinalizeMfaResponse {}\n\nexport function finalizeEnrollPhoneMfa(\n  auth: AuthInternal,\n  request: FinalizePhoneMfaEnrollmentRequest\n): Promise<FinalizePhoneMfaEnrollmentResponse> {\n  return _performApiRequest<\n    FinalizePhoneMfaEnrollmentRequest,\n    FinalizePhoneMfaEnrollmentResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.FINALIZE_MFA_ENROLLMENT,\n    _addTidIfNecessary(auth, request)\n  );\n}\nexport interface StartTotpMfaEnrollmentRequest {\n  idToken: string;\n  totpEnrollmentInfo: {};\n  tenantId?: string;\n}\n\nexport interface StartTotpMfaEnrollmentResponse {\n  totpSessionInfo: {\n    sharedSecretKey: string;\n    verificationCodeLength: number;\n    hashingAlgorithm: string;\n    periodSec: number;\n    sessionInfo: string;\n    finalizeEnrollmentTime: number;\n  };\n}\n\nexport function startEnrollTotpMfa(\n  auth: AuthInternal,\n  request: StartTotpMfaEnrollmentRequest\n): Promise<StartTotpMfaEnrollmentResponse> {\n  return _performApiRequest<\n    StartTotpMfaEnrollmentRequest,\n    StartTotpMfaEnrollmentResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.START_MFA_ENROLLMENT,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport interface TotpVerificationInfo {\n  sessionInfo: string;\n  verificationCode: string;\n}\nexport interface FinalizeTotpMfaEnrollmentRequest {\n  idToken: string;\n  totpVerificationInfo: TotpVerificationInfo;\n  displayName?: string | null;\n  tenantId?: string;\n}\n\nexport interface FinalizeTotpMfaEnrollmentResponse\n  extends FinalizeMfaResponse {}\n\nexport function finalizeEnrollTotpMfa(\n  auth: AuthInternal,\n  request: FinalizeTotpMfaEnrollmentRequest\n): Promise<FinalizeTotpMfaEnrollmentResponse> {\n  return _performApiRequest<\n    FinalizeTotpMfaEnrollmentRequest,\n    FinalizeTotpMfaEnrollmentResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.FINALIZE_MFA_ENROLLMENT,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport interface WithdrawMfaRequest {\n  idToken: string;\n  mfaEnrollmentId: string;\n  tenantId?: string;\n}\n\nexport interface WithdrawMfaResponse extends FinalizeMfaResponse {}\n\nexport function withdrawMfa(\n  auth: AuthInternal,\n  request: WithdrawMfaRequest\n): Promise<WithdrawMfaResponse> {\n  return _performApiRequest<WithdrawMfaRequest, WithdrawMfaResponse>(\n    auth,\n    HttpMethod.POST,\n    Endpoint.WITHDRAW_MFA,\n    _addTidIfNecessary(auth, request)\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\nimport {\n  MultiFactorAssertion,\n  MultiFactorInfo,\n  MultiFactorSession,\n  MultiFactorUser,\n  User\n} from '../model/public_types';\n\nimport { withdrawMfa } from '../api/account_management/mfa';\nimport { _logoutIfInvalidated } from '../core/user/invalidation';\nimport { UserInternal } from '../model/user';\nimport { MultiFactorAssertionImpl } from './mfa_assertion';\nimport { MultiFactorInfoImpl } from './mfa_info';\nimport { MultiFactorSessionImpl } from './mfa_session';\nimport { getModularInstance } from '@firebase/util';\n\nexport class MultiFactorUserImpl implements MultiFactorUser {\n  enrolledFactors: MultiFactorInfo[] = [];\n\n  private constructor(readonly user: UserInternal) {\n    user._onReload(userInfo => {\n      if (userInfo.mfaInfo) {\n        this.enrolledFactors = userInfo.mfaInfo.map(enrollment =>\n          MultiFactorInfoImpl._fromServerResponse(user.auth, enrollment)\n        );\n      }\n    });\n  }\n\n  static _fromUser(user: UserInternal): MultiFactorUserImpl {\n    return new MultiFactorUserImpl(user);\n  }\n\n  async getSession(): Promise<MultiFactorSession> {\n    return MultiFactorSessionImpl._fromIdtoken(\n      await this.user.getIdToken(),\n      this.user\n    );\n  }\n\n  async enroll(\n    assertionExtern: MultiFactorAssertion,\n    displayName?: string | null\n  ): Promise<void> {\n    const assertion = assertionExtern as MultiFactorAssertionImpl;\n    const session = (await this.getSession()) as MultiFactorSessionImpl;\n    const finalizeMfaResponse = await _logoutIfInvalidated(\n      this.user,\n      assertion._process(this.user.auth, session, displayName)\n    );\n    // New tokens will be issued after enrollment of the new second factors.\n    // They need to be updated on the user.\n    await this.user._updateTokensIfNecessary(finalizeMfaResponse);\n    // The user needs to be reloaded to get the new multi-factor information\n    // from server. USER_RELOADED event will be triggered and `enrolledFactors`\n    // will be updated.\n    return this.user.reload();\n  }\n\n  async unenroll(infoOrUid: MultiFactorInfo | string): Promise<void> {\n    const mfaEnrollmentId =\n      typeof infoOrUid === 'string' ? infoOrUid : infoOrUid.uid;\n    const idToken = await this.user.getIdToken();\n    try {\n      const idTokenResponse = await _logoutIfInvalidated(\n        this.user,\n        withdrawMfa(this.user.auth, {\n          idToken,\n          mfaEnrollmentId\n        })\n      );\n      // Remove the second factor from the user's list.\n      this.enrolledFactors = this.enrolledFactors.filter(\n        ({ uid }) => uid !== mfaEnrollmentId\n      );\n      // Depending on whether the backend decided to revoke the user's session,\n      // the tokenResponse may be empty. If the tokens were not updated (and they\n      // are now invalid), reloading the user will discover this and invalidate\n      // the user's state accordingly.\n      await this.user._updateTokensIfNecessary(idTokenResponse);\n      await this.user.reload();\n    } catch (e) {\n      throw e;\n    }\n  }\n}\n\nconst multiFactorUserCache = new WeakMap<User, MultiFactorUser>();\n\n/**\n * The {@link MultiFactorUser} corresponding to the user.\n *\n * @remarks\n * This is used to access all multi-factor properties and operations related to the user.\n *\n * @param user - The user.\n *\n * @public\n */\nexport function multiFactor(user: User): MultiFactorUser {\n  const userModular = getModularInstance(user);\n  if (!multiFactorUserCache.has(userModular)) {\n    multiFactorUserCache.set(\n      userModular,\n      MultiFactorUserImpl._fromUser(userModular as UserInternal)\n    );\n  }\n  return multiFactorUserCache.get(userModular)!;\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\nimport { Persistence } from '../../model/public_types';\n\nexport const enum PersistenceType {\n  SESSION = 'SESSION',\n  LOCAL = 'LOCAL',\n  NONE = 'NONE',\n  COOKIE = 'COOKIE'\n}\n\nexport type PersistedBlob = Record<string, unknown>;\n\nexport interface Instantiator<T> {\n  (blob: PersistedBlob): T;\n}\n\nexport type PersistenceValue = PersistedBlob | string;\n\nexport const STORAGE_AVAILABLE_KEY = '__sak';\n\nexport interface StorageEventListener {\n  (value: PersistenceValue | null): void;\n}\n\nexport interface PersistenceInternal extends Persistence {\n  type: PersistenceType;\n  _isAvailable(): Promise<boolean>;\n  _set(key: string, value: PersistenceValue): Promise<void>;\n  _get<T extends PersistenceValue>(key: string): Promise<T | null>;\n  _remove(key: string): Promise<void>;\n  _addListener(key: string, listener: StorageEventListener): void;\n  _removeListener(key: string, listener: StorageEventListener): void;\n  // Should this persistence allow migration up the chosen hierarchy?\n  _shouldAllowMigration?: boolean;\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  PersistenceValue,\n  STORAGE_AVAILABLE_KEY,\n  PersistenceType\n} from '../../core/persistence';\n\n// There are two different browser persistence types: local and session.\n// Both have the same implementation but use a different underlying storage\n// object.\n\nexport abstract class BrowserPersistenceClass {\n  protected constructor(\n    protected readonly storageRetriever: () => Storage,\n    readonly type: PersistenceType\n  ) {}\n\n  _isAvailable(): Promise<boolean> {\n    try {\n      if (!this.storage) {\n        return Promise.resolve(false);\n      }\n      this.storage.setItem(STORAGE_AVAILABLE_KEY, '1');\n      this.storage.removeItem(STORAGE_AVAILABLE_KEY);\n      return Promise.resolve(true);\n    } catch {\n      return Promise.resolve(false);\n    }\n  }\n\n  _set(key: string, value: PersistenceValue): Promise<void> {\n    this.storage.setItem(key, JSON.stringify(value));\n    return Promise.resolve();\n  }\n\n  _get<T extends PersistenceValue>(key: string): Promise<T | null> {\n    const json = this.storage.getItem(key);\n    return Promise.resolve(json ? JSON.parse(json) : null);\n  }\n\n  _remove(key: string): Promise<void> {\n    this.storage.removeItem(key);\n    return Promise.resolve();\n  }\n\n  protected get storage(): Storage {\n    return this.storageRetriever();\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Persistence } from '../../model/public_types';\n\nimport { _isMobileBrowser, _isIE10 } from '../../core/util/browser';\nimport {\n  PersistenceInternal as InternalPersistence,\n  PersistenceType,\n  PersistenceValue,\n  StorageEventListener\n} from '../../core/persistence';\nimport { BrowserPersistenceClass } from './browser';\n\n// The polling period in case events are not supported\nexport const _POLLING_INTERVAL_MS = 1000;\n\n// The IE 10 localStorage cross tab synchronization delay in milliseconds\nconst IE10_LOCAL_STORAGE_SYNC_DELAY = 10;\n\nclass BrowserLocalPersistence\n  extends BrowserPersistenceClass\n  implements InternalPersistence\n{\n  static type: 'LOCAL' = 'LOCAL';\n\n  constructor() {\n    super(() => window.localStorage, PersistenceType.LOCAL);\n  }\n\n  private readonly boundEventHandler = (\n    event: StorageEvent,\n    poll?: boolean\n  ): void => this.onStorageEvent(event, poll);\n  private readonly listeners: Record<string, Set<StorageEventListener>> = {};\n  private readonly localCache: Record<string, string | null> = {};\n  // setTimeout return value is platform specific\n  // eslint-disable-next-line @typescript-eslint/no-explicit-any\n  private pollTimer: any | null = null;\n\n  // Whether to use polling instead of depending on window events\n  private readonly fallbackToPolling = _isMobileBrowser();\n  readonly _shouldAllowMigration = true;\n\n  private forAllChangedKeys(\n    cb: (key: string, oldValue: string | null, newValue: string | null) => void\n  ): void {\n    // Check all keys with listeners on them.\n    for (const key of Object.keys(this.listeners)) {\n      // Get value from localStorage.\n      const newValue = this.storage.getItem(key);\n      const oldValue = this.localCache[key];\n      // If local map value does not match, trigger listener with storage event.\n      // Differentiate this simulated event from the real storage event.\n      if (newValue !== oldValue) {\n        cb(key, oldValue, newValue);\n      }\n    }\n  }\n\n  private onStorageEvent(event: StorageEvent, poll = false): void {\n    // Key would be null in some situations, like when localStorage is cleared\n    if (!event.key) {\n      this.forAllChangedKeys(\n        (key: string, _oldValue: string | null, newValue: string | null) => {\n          this.notifyListeners(key, newValue);\n        }\n      );\n      return;\n    }\n\n    const key = event.key;\n\n    // Check the mechanism how this event was detected.\n    // The first event will dictate the mechanism to be used.\n    if (poll) {\n      // Environment detects storage changes via polling.\n      // Remove storage event listener to prevent possible event duplication.\n      this.detachListener();\n    } else {\n      // Environment detects storage changes via storage event listener.\n      // Remove polling listener to prevent possible event duplication.\n      this.stopPolling();\n    }\n\n    const triggerListeners = (): void => {\n      // Keep local map up to date in case storage event is triggered before\n      // poll.\n      const storedValue = this.storage.getItem(key);\n      if (!poll && this.localCache[key] === storedValue) {\n        // Real storage event which has already been detected, do nothing.\n        // This seems to trigger in some IE browsers for some reason.\n        return;\n      }\n      this.notifyListeners(key, storedValue);\n    };\n\n    const storedValue = this.storage.getItem(key);\n    if (\n      _isIE10() &&\n      storedValue !== event.newValue &&\n      event.newValue !== event.oldValue\n    ) {\n      // IE 10 has this weird bug where a storage event would trigger with the\n      // correct key, oldValue and newValue but localStorage.getItem(key) does\n      // not yield the updated value until a few milliseconds. This ensures\n      // this recovers from that situation.\n      setTimeout(triggerListeners, IE10_LOCAL_STORAGE_SYNC_DELAY);\n    } else {\n      triggerListeners();\n    }\n  }\n\n  private notifyListeners(key: string, value: string | null): void {\n    this.localCache[key] = value;\n    const listeners = this.listeners[key];\n    if (listeners) {\n      for (const listener of Array.from(listeners)) {\n        listener(value ? JSON.parse(value) : value);\n      }\n    }\n  }\n\n  private startPolling(): void {\n    this.stopPolling();\n\n    this.pollTimer = setInterval(() => {\n      this.forAllChangedKeys(\n        (key: string, oldValue: string | null, newValue: string | null) => {\n          this.onStorageEvent(\n            new StorageEvent('storage', {\n              key,\n              oldValue,\n              newValue\n            }),\n            /* poll */ true\n          );\n        }\n      );\n    }, _POLLING_INTERVAL_MS);\n  }\n\n  private stopPolling(): void {\n    if (this.pollTimer) {\n      clearInterval(this.pollTimer);\n      this.pollTimer = null;\n    }\n  }\n\n  private attachListener(): void {\n    window.addEventListener('storage', this.boundEventHandler);\n  }\n\n  private detachListener(): void {\n    window.removeEventListener('storage', this.boundEventHandler);\n  }\n\n  _addListener(key: string, listener: StorageEventListener): void {\n    if (Object.keys(this.listeners).length === 0) {\n      // Whether browser can detect storage event when it had already been pushed to the background.\n      // This may happen in some mobile browsers. A localStorage change in the foreground window\n      // will not be detected in the background window via the storage event.\n      // This was detected in iOS 7.x mobile browsers\n      if (this.fallbackToPolling) {\n        this.startPolling();\n      } else {\n        this.attachListener();\n      }\n    }\n    if (!this.listeners[key]) {\n      this.listeners[key] = new Set();\n      // Populate the cache to avoid spuriously triggering on first poll.\n      this.localCache[key] = this.storage.getItem(key);\n    }\n    this.listeners[key].add(listener);\n  }\n\n  _removeListener(key: string, listener: StorageEventListener): void {\n    if (this.listeners[key]) {\n      this.listeners[key].delete(listener);\n\n      if (this.listeners[key].size === 0) {\n        delete this.listeners[key];\n      }\n    }\n\n    if (Object.keys(this.listeners).length === 0) {\n      this.detachListener();\n      this.stopPolling();\n    }\n  }\n\n  // Update local cache on base operations:\n\n  async _set(key: string, value: PersistenceValue): Promise<void> {\n    await super._set(key, value);\n    this.localCache[key] = JSON.stringify(value);\n  }\n\n  async _get<T extends PersistenceValue>(key: string): Promise<T | null> {\n    const value = await super._get<T>(key);\n    this.localCache[key] = JSON.stringify(value);\n    return value;\n  }\n\n  async _remove(key: string): Promise<void> {\n    await super._remove(key);\n    delete this.localCache[key];\n  }\n}\n\n/**\n * An implementation of {@link Persistence} of type `LOCAL` using `localStorage`\n * for the underlying storage.\n *\n * @public\n */\nexport const browserLocalPersistence: Persistence = BrowserLocalPersistence;\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Persistence } from '../../model/public_types';\n\nimport {\n  PersistenceInternal as InternalPersistence,\n  PersistenceType,\n  StorageEventListener\n} from '../../core/persistence';\nimport { BrowserPersistenceClass } from './browser';\n\nclass BrowserSessionPersistence\n  extends BrowserPersistenceClass\n  implements InternalPersistence\n{\n  static type: 'SESSION' = 'SESSION';\n\n  constructor() {\n    super(() => window.sessionStorage, PersistenceType.SESSION);\n  }\n\n  _addListener(_key: string, _listener: StorageEventListener): void {\n    // Listeners are not supported for session storage since it cannot be shared across windows\n    return;\n  }\n\n  _removeListener(_key: string, _listener: StorageEventListener): void {\n    // Listeners are not supported for session storage since it cannot be shared across windows\n    return;\n  }\n}\n\n/**\n * An implementation of {@link Persistence} of `SESSION` using `sessionStorage`\n * for the underlying storage.\n *\n * @public\n */\nexport const browserSessionPersistence: Persistence = BrowserSessionPersistence;\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  ReceiverHandler,\n  _EventType,\n  _ReceiverResponse,\n  SenderMessageEvent,\n  _Status,\n  _SenderRequest\n} from './index';\nimport { _allSettled } from './promise';\n\n/**\n * Interface class for receiving messages.\n *\n */\nexport class Receiver {\n  private static readonly receivers: Receiver[] = [];\n  private readonly boundEventHandler: EventListener;\n\n  private readonly handlersMap: {\n    // TypeScript doesn't have existential types :(\n    // eslint-disable-next-line @typescript-eslint/no-explicit-any\n    [eventType: string]: Set<ReceiverHandler<any, any>>;\n  } = {};\n\n  constructor(private readonly eventTarget: EventTarget) {\n    this.boundEventHandler = this.handleEvent.bind(this);\n  }\n\n  /**\n   * Obtain an instance of a Receiver for a given event target, if none exists it will be created.\n   *\n   * @param eventTarget - An event target (such as window or self) through which the underlying\n   * messages will be received.\n   */\n  static _getInstance(eventTarget: EventTarget): Receiver {\n    // The results are stored in an array since objects can't be keys for other\n    // objects. In addition, setting a unique property on an event target as a\n    // hash map key may not be allowed due to CORS restrictions.\n    const existingInstance = this.receivers.find(receiver =>\n      receiver.isListeningto(eventTarget)\n    );\n    if (existingInstance) {\n      return existingInstance;\n    }\n    const newInstance = new Receiver(eventTarget);\n    this.receivers.push(newInstance);\n    return newInstance;\n  }\n\n  private isListeningto(eventTarget: EventTarget): boolean {\n    return this.eventTarget === eventTarget;\n  }\n\n  /**\n   * Fans out a MessageEvent to the appropriate listeners.\n   *\n   * @remarks\n   * Sends an {@link Status.ACK} upon receipt and a {@link Status.DONE} once all handlers have\n   * finished processing.\n   *\n   * @param event - The MessageEvent.\n   *\n   */\n  private async handleEvent<\n    T extends _ReceiverResponse,\n    S extends _SenderRequest\n  >(event: Event): Promise<void> {\n    const messageEvent = event as MessageEvent<SenderMessageEvent<S>>;\n    const { eventId, eventType, data } = messageEvent.data;\n\n    const handlers: Set<ReceiverHandler<T, S>> | undefined =\n      this.handlersMap[eventType];\n    if (!handlers?.size) {\n      return;\n    }\n\n    messageEvent.ports[0].postMessage({\n      status: _Status.ACK,\n      eventId,\n      eventType\n    });\n\n    const promises = Array.from(handlers).map(async handler =>\n      handler(messageEvent.origin, data)\n    );\n    const response = await _allSettled(promises);\n    messageEvent.ports[0].postMessage({\n      status: _Status.DONE,\n      eventId,\n      eventType,\n      response\n    });\n  }\n\n  /**\n   * Subscribe an event handler for a particular event.\n   *\n   * @param eventType - Event name to subscribe to.\n   * @param eventHandler - The event handler which should receive the events.\n   *\n   */\n  _subscribe<T extends _ReceiverResponse, S extends _SenderRequest>(\n    eventType: _EventType,\n    eventHandler: ReceiverHandler<T, S>\n  ): void {\n    if (Object.keys(this.handlersMap).length === 0) {\n      this.eventTarget.addEventListener('message', this.boundEventHandler);\n    }\n\n    if (!this.handlersMap[eventType]) {\n      this.handlersMap[eventType] = new Set();\n    }\n\n    this.handlersMap[eventType].add(eventHandler);\n  }\n\n  /**\n   * Unsubscribe an event handler from a particular event.\n   *\n   * @param eventType - Event name to unsubscribe from.\n   * @param eventHandler - Optional event handler, if none provided, unsubscribe all handlers on this event.\n   *\n   */\n  _unsubscribe<T extends _ReceiverResponse, S extends _SenderRequest>(\n    eventType: _EventType,\n    eventHandler?: ReceiverHandler<T, S>\n  ): void {\n    if (this.handlersMap[eventType] && eventHandler) {\n      this.handlersMap[eventType].delete(eventHandler);\n    }\n    if (!eventHandler || this.handlersMap[eventType].size === 0) {\n      delete this.handlersMap[eventType];\n    }\n\n    if (Object.keys(this.handlersMap).length === 0) {\n      this.eventTarget.removeEventListener('message', this.boundEventHandler);\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/** TODO: remove this once tslib has a polyfill for Promise.allSettled */\ninterface PromiseFulfilledResult<T> {\n  fulfilled: true;\n  value: T;\n}\n\ninterface PromiseRejectedResult {\n  fulfilled: false;\n  // eslint-disable-next-line @typescript-eslint/no-explicit-any\n  reason: any;\n}\n\nexport type PromiseSettledResult<T> =\n  | PromiseFulfilledResult<T>\n  | PromiseRejectedResult;\n\n/**\n * Shim for Promise.allSettled, note the slightly different format of `fulfilled` vs `status`.\n *\n * @param promises - Array of promises to wait on.\n */\nexport function _allSettled<T>(\n  promises: Array<Promise<T>>\n): Promise<Array<PromiseSettledResult<T>>> {\n  return Promise.all(\n    promises.map(async promise => {\n      try {\n        const value = await promise;\n        return {\n          fulfilled: true,\n          value\n        } as PromiseFulfilledResult<T>;\n      } catch (reason) {\n        return {\n          fulfilled: false,\n          reason\n        } as PromiseRejectedResult;\n      }\n    })\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport function _generateEventId(prefix = '', digits = 10): string {\n  let random = '';\n  for (let i = 0; i < digits; i++) {\n    random += Math.floor(Math.random() * 10);\n  }\n  return prefix + random;\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { _generateEventId } from '../../core/util/event_id';\nimport {\n  _SenderRequest,\n  _EventType,\n  ReceiverMessageEvent,\n  _MessageError,\n  SenderMessageEvent,\n  _Status,\n  _ReceiverMessageResponse,\n  _ReceiverResponse,\n  _TimeoutDuration\n} from './index';\n\ninterface MessageHandler {\n  messageChannel: MessageChannel;\n  onMessage: EventListenerOrEventListenerObject;\n}\n\n/**\n * Interface for sending messages and waiting for a completion response.\n *\n */\nexport class Sender {\n  private readonly handlers = new Set<MessageHandler>();\n\n  constructor(private readonly target: ServiceWorker) {}\n\n  /**\n   * Unsubscribe the handler and remove it from our tracking Set.\n   *\n   * @param handler - The handler to unsubscribe.\n   */\n  private removeMessageHandler(handler: MessageHandler): void {\n    if (handler.messageChannel) {\n      handler.messageChannel.port1.removeEventListener(\n        'message',\n        handler.onMessage\n      );\n      handler.messageChannel.port1.close();\n    }\n    this.handlers.delete(handler);\n  }\n\n  /**\n   * Send a message to the Receiver located at {@link target}.\n   *\n   * @remarks\n   * We'll first wait a bit for an ACK , if we get one we will wait significantly longer until the\n   * receiver has had a chance to fully process the event.\n   *\n   * @param eventType - Type of event to send.\n   * @param data - The payload of the event.\n   * @param timeout - Timeout for waiting on an ACK from the receiver.\n   *\n   * @returns An array of settled promises from all the handlers that were listening on the receiver.\n   */\n  async _send<T extends _ReceiverResponse, S extends _SenderRequest>(\n    eventType: _EventType,\n    data: S,\n    timeout = _TimeoutDuration.ACK\n  ): Promise<_ReceiverMessageResponse<T>> {\n    const messageChannel =\n      typeof MessageChannel !== 'undefined' ? new MessageChannel() : null;\n    if (!messageChannel) {\n      throw new Error(_MessageError.CONNECTION_UNAVAILABLE);\n    }\n    // Node timers and browser timers return fundamentally different types.\n    // We don't actually care what the value is but TS won't accept unknown and\n    // we can't cast properly in both environments.\n    // eslint-disable-next-line @typescript-eslint/no-explicit-any\n    let completionTimer: any;\n    let handler: MessageHandler;\n    return new Promise<_ReceiverMessageResponse<T>>((resolve, reject) => {\n      const eventId = _generateEventId('', 20);\n      messageChannel.port1.start();\n      const ackTimer = setTimeout(() => {\n        reject(new Error(_MessageError.UNSUPPORTED_EVENT));\n      }, timeout);\n      handler = {\n        messageChannel,\n        onMessage(event: Event): void {\n          const messageEvent = event as MessageEvent<ReceiverMessageEvent<T>>;\n          if (messageEvent.data.eventId !== eventId) {\n            return;\n          }\n          switch (messageEvent.data.status) {\n            case _Status.ACK:\n              // The receiver should ACK first.\n              clearTimeout(ackTimer);\n              completionTimer = setTimeout(() => {\n                reject(new Error(_MessageError.TIMEOUT));\n              }, _TimeoutDuration.COMPLETION);\n              break;\n            case _Status.DONE:\n              // Once the receiver's handlers are finished we will get the results.\n              clearTimeout(completionTimer);\n              resolve(messageEvent.data.response);\n              break;\n            default:\n              clearTimeout(ackTimer);\n              clearTimeout(completionTimer);\n              reject(new Error(_MessageError.INVALID_RESPONSE));\n              break;\n          }\n        }\n      };\n      this.handlers.add(handler);\n      messageChannel.port1.addEventListener('message', handler.onMessage);\n      this.target.postMessage(\n        {\n          eventType,\n          eventId,\n          data\n        } as SenderMessageEvent<S>,\n        [messageChannel.port2]\n      );\n    }).finally(() => {\n      if (handler) {\n        this.removeMessageHandler(handler);\n      }\n    });\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Recaptcha, GreCAPTCHATopLevel } from './recaptcha/recaptcha';\n\n/**\n * A specialized window type that melds the normal window type plus the\n * various bits we need. The three different blocks that are &'d together\n * cant be defined in the same block together.\n */\nexport type AuthWindow = {\n  // Standard window types\n  [T in keyof Window]: Window[T];\n} & {\n  // Any known / named properties we want to add\n  grecaptcha?: Recaptcha | GreCAPTCHATopLevel;\n  /* eslint-disable-next-line @typescript-eslint/no-explicit-any */\n  ___jsl?: Record<string, any>;\n  gapi?: typeof gapi;\n} & {\n  // A final catch-all for callbacks (which will have random names) that\n  // we will stick on the window.\n  [callback: string]: (...args: unknown[]) => void;\n};\n\n/**\n * Lazy accessor for window, since the compat layer won't tree shake this out,\n * we need to make sure not to mess with window unless we have to\n */\nexport function _window(): AuthWindow {\n  return window as unknown as AuthWindow;\n}\n\nexport function _setWindowLocation(url: string): void {\n  _window().location.href = url;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC.\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { _window } from '../auth_window';\n\nexport function _isWorker(): boolean {\n  return (\n    typeof _window()['WorkerGlobalScope'] !== 'undefined' &&\n    typeof _window()['importScripts'] === 'function'\n  );\n}\n\nexport async function _getActiveServiceWorker(): Promise<ServiceWorker | null> {\n  if (!navigator?.serviceWorker) {\n    return null;\n  }\n  try {\n    const registration = await navigator.serviceWorker.ready;\n    return registration.active;\n  } catch {\n    return null;\n  }\n}\n\nexport function _getServiceWorkerController(): ServiceWorker | null {\n  return navigator?.serviceWorker?.controller || null;\n}\n\nexport function _getWorkerGlobalScope(): ServiceWorker | null {\n  return _isWorker() ? (self as unknown as ServiceWorker) : null;\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Persistence } from '../../model/public_types';\nimport {\n  PersistedBlob,\n  PersistenceInternal as InternalPersistence,\n  PersistenceType,\n  PersistenceValue,\n  StorageEventListener,\n  STORAGE_AVAILABLE_KEY\n} from '../../core/persistence/';\nimport {\n  _EventType,\n  _PingResponse,\n  KeyChangedResponse,\n  KeyChangedRequest,\n  PingRequest,\n  _TimeoutDuration\n} from '../messagechannel/index';\nimport { Receiver } from '../messagechannel/receiver';\nimport { Sender } from '../messagechannel/sender';\nimport {\n  _isWorker,\n  _getActiveServiceWorker,\n  _getServiceWorkerController,\n  _getWorkerGlobalScope\n} from '../util/worker';\n\nexport const DB_NAME = 'firebaseLocalStorageDb';\nconst DB_VERSION = 1;\nconst DB_OBJECTSTORE_NAME = 'firebaseLocalStorage';\nconst DB_DATA_KEYPATH = 'fbase_key';\n\ninterface DBObject {\n  [DB_DATA_KEYPATH]: string;\n  value: PersistedBlob;\n}\n\n/**\n * Promise wrapper for IDBRequest\n *\n * Unfortunately we can't cleanly extend Promise<T> since promises are not callable in ES6\n *\n */\nclass DBPromise<T> {\n  constructor(private readonly request: IDBRequest) {}\n\n  toPromise(): Promise<T> {\n    return new Promise<T>((resolve, reject) => {\n      this.request.addEventListener('success', () => {\n        resolve(this.request.result);\n      });\n      this.request.addEventListener('error', () => {\n        reject(this.request.error);\n      });\n    });\n  }\n}\n\nfunction getObjectStore(db: IDBDatabase, isReadWrite: boolean): IDBObjectStore {\n  return db\n    .transaction([DB_OBJECTSTORE_NAME], isReadWrite ? 'readwrite' : 'readonly')\n    .objectStore(DB_OBJECTSTORE_NAME);\n}\n\nexport async function _clearDatabase(db: IDBDatabase): Promise<void> {\n  const objectStore = getObjectStore(db, true);\n  return new DBPromise<void>(objectStore.clear()).toPromise();\n}\n\nexport function _deleteDatabase(): Promise<void> {\n  const request = indexedDB.deleteDatabase(DB_NAME);\n  return new DBPromise<void>(request).toPromise();\n}\n\nexport function _openDatabase(): Promise<IDBDatabase> {\n  const request = indexedDB.open(DB_NAME, DB_VERSION);\n  return new Promise((resolve, reject) => {\n    request.addEventListener('error', () => {\n      reject(request.error);\n    });\n\n    request.addEventListener('upgradeneeded', () => {\n      const db = request.result;\n\n      try {\n        db.createObjectStore(DB_OBJECTSTORE_NAME, { keyPath: DB_DATA_KEYPATH });\n      } catch (e) {\n        reject(e);\n      }\n    });\n\n    request.addEventListener('success', async () => {\n      const db: IDBDatabase = request.result;\n      // Strange bug that occurs in Firefox when multiple tabs are opened at the\n      // same time. The only way to recover seems to be deleting the database\n      // and re-initializing it.\n      // https://github.com/firebase/firebase-js-sdk/issues/634\n\n      if (!db.objectStoreNames.contains(DB_OBJECTSTORE_NAME)) {\n        // Need to close the database or else you get a `blocked` event\n        db.close();\n        await _deleteDatabase();\n        resolve(await _openDatabase());\n      } else {\n        resolve(db);\n      }\n    });\n  });\n}\n\nexport async function _putObject(\n  db: IDBDatabase,\n  key: string,\n  value: PersistenceValue | string\n): Promise<void> {\n  const request = getObjectStore(db, true).put({\n    [DB_DATA_KEYPATH]: key,\n    value\n  });\n  return new DBPromise<void>(request).toPromise();\n}\n\nasync function getObject(\n  db: IDBDatabase,\n  key: string\n): Promise<PersistedBlob | null> {\n  const request = getObjectStore(db, false).get(key);\n  const data = await new DBPromise<DBObject | undefined>(request).toPromise();\n  return data === undefined ? null : data.value;\n}\n\nexport function _deleteObject(db: IDBDatabase, key: string): Promise<void> {\n  const request = getObjectStore(db, true).delete(key);\n  return new DBPromise<void>(request).toPromise();\n}\n\nexport const _POLLING_INTERVAL_MS = 800;\nexport const _TRANSACTION_RETRY_COUNT = 3;\n\nclass IndexedDBLocalPersistence implements InternalPersistence {\n  static type: 'LOCAL' = 'LOCAL';\n\n  type = PersistenceType.LOCAL;\n  db?: IDBDatabase;\n  readonly _shouldAllowMigration = true;\n\n  private readonly listeners: Record<string, Set<StorageEventListener>> = {};\n  private readonly localCache: Record<string, PersistenceValue | null> = {};\n  // setTimeout return value is platform specific\n  // eslint-disable-next-line @typescript-eslint/no-explicit-any\n  private pollTimer: any | null = null;\n  private pendingWrites = 0;\n\n  private receiver: Receiver | null = null;\n  private sender: Sender | null = null;\n  private serviceWorkerReceiverAvailable = false;\n  private activeServiceWorker: ServiceWorker | null = null;\n  // Visible for testing only\n  readonly _workerInitializationPromise: Promise<void>;\n\n  constructor() {\n    // Fire & forget the service worker registration as it may never resolve\n    this._workerInitializationPromise =\n      this.initializeServiceWorkerMessaging().then(\n        () => {},\n        () => {}\n      );\n  }\n\n  async _openDb(): Promise<IDBDatabase> {\n    if (this.db) {\n      return this.db;\n    }\n    this.db = await _openDatabase();\n    return this.db;\n  }\n\n  async _withRetries<T>(op: (db: IDBDatabase) => Promise<T>): Promise<T> {\n    let numAttempts = 0;\n\n    while (true) {\n      try {\n        const db = await this._openDb();\n        return await op(db);\n      } catch (e) {\n        if (numAttempts++ > _TRANSACTION_RETRY_COUNT) {\n          throw e;\n        }\n        if (this.db) {\n          this.db.close();\n          this.db = undefined;\n        }\n        // TODO: consider adding exponential backoff\n      }\n    }\n  }\n\n  /**\n   * IndexedDB events do not propagate from the main window to the worker context.  We rely on a\n   * postMessage interface to send these events to the worker ourselves.\n   */\n  private async initializeServiceWorkerMessaging(): Promise<void> {\n    return _isWorker() ? this.initializeReceiver() : this.initializeSender();\n  }\n\n  /**\n   * As the worker we should listen to events from the main window.\n   */\n  private async initializeReceiver(): Promise<void> {\n    this.receiver = Receiver._getInstance(_getWorkerGlobalScope()!);\n    // Refresh from persistence if we receive a KeyChanged message.\n    this.receiver._subscribe(\n      _EventType.KEY_CHANGED,\n      async (_origin: string, data: KeyChangedRequest) => {\n        const keys = await this._poll();\n        return {\n          keyProcessed: keys.includes(data.key)\n        };\n      }\n    );\n    // Let the sender know that we are listening so they give us more timeout.\n    this.receiver._subscribe(\n      _EventType.PING,\n      async (_origin: string, _data: PingRequest) => {\n        return [_EventType.KEY_CHANGED];\n      }\n    );\n  }\n\n  /**\n   * As the main window, we should let the worker know when keys change (set and remove).\n   *\n   * @remarks\n   * {@link https://developer.mozilla.org/en-US/docs/Web/API/ServiceWorkerContainer/ready | ServiceWorkerContainer.ready}\n   * may not resolve.\n   */\n  private async initializeSender(): Promise<void> {\n    // Check to see if there's an active service worker.\n    this.activeServiceWorker = await _getActiveServiceWorker();\n    if (!this.activeServiceWorker) {\n      return;\n    }\n    this.sender = new Sender(this.activeServiceWorker);\n    // Ping the service worker to check what events they can handle.\n    const results = await this.sender._send<_PingResponse, PingRequest>(\n      _EventType.PING,\n      {},\n      _TimeoutDuration.LONG_ACK\n    );\n    if (!results) {\n      return;\n    }\n    if (\n      results[0]?.fulfilled &&\n      results[0]?.value.includes(_EventType.KEY_CHANGED)\n    ) {\n      this.serviceWorkerReceiverAvailable = true;\n    }\n  }\n\n  /**\n   * Let the worker know about a changed key, the exact key doesn't technically matter since the\n   * worker will just trigger a full sync anyway.\n   *\n   * @remarks\n   * For now, we only support one service worker per page.\n   *\n   * @param key - Storage key which changed.\n   */\n  private async notifyServiceWorker(key: string): Promise<void> {\n    if (\n      !this.sender ||\n      !this.activeServiceWorker ||\n      _getServiceWorkerController() !== this.activeServiceWorker\n    ) {\n      return;\n    }\n    try {\n      await this.sender._send<KeyChangedResponse, KeyChangedRequest>(\n        _EventType.KEY_CHANGED,\n        { key },\n        // Use long timeout if receiver has previously responded to a ping from us.\n        this.serviceWorkerReceiverAvailable\n          ? _TimeoutDuration.LONG_ACK\n          : _TimeoutDuration.ACK\n      );\n    } catch {\n      // This is a best effort approach. Ignore errors.\n    }\n  }\n\n  async _isAvailable(): Promise<boolean> {\n    try {\n      if (!indexedDB) {\n        return false;\n      }\n      const db = await _openDatabase();\n      await _putObject(db, STORAGE_AVAILABLE_KEY, '1');\n      await _deleteObject(db, STORAGE_AVAILABLE_KEY);\n      return true;\n    } catch {}\n    return false;\n  }\n\n  private async _withPendingWrite(write: () => Promise<void>): Promise<void> {\n    this.pendingWrites++;\n    try {\n      await write();\n    } finally {\n      this.pendingWrites--;\n    }\n  }\n\n  async _set(key: string, value: PersistenceValue): Promise<void> {\n    return this._withPendingWrite(async () => {\n      await this._withRetries((db: IDBDatabase) => _putObject(db, key, value));\n      this.localCache[key] = value;\n      return this.notifyServiceWorker(key);\n    });\n  }\n\n  async _get<T extends PersistenceValue>(key: string): Promise<T | null> {\n    const obj = (await this._withRetries((db: IDBDatabase) =>\n      getObject(db, key)\n    )) as T;\n    this.localCache[key] = obj;\n    return obj;\n  }\n\n  async _remove(key: string): Promise<void> {\n    return this._withPendingWrite(async () => {\n      await this._withRetries((db: IDBDatabase) => _deleteObject(db, key));\n      delete this.localCache[key];\n      return this.notifyServiceWorker(key);\n    });\n  }\n\n  private async _poll(): Promise<string[]> {\n    // TODO: check if we need to fallback if getAll is not supported\n    const result = await this._withRetries((db: IDBDatabase) => {\n      const getAllRequest = getObjectStore(db, false).getAll();\n      return new DBPromise<DBObject[] | null>(getAllRequest).toPromise();\n    });\n\n    if (!result) {\n      return [];\n    }\n\n    // If we have pending writes in progress abort, we'll get picked up on the next poll\n    if (this.pendingWrites !== 0) {\n      return [];\n    }\n\n    const keys = [];\n    const keysInResult = new Set();\n    if (result.length !== 0) {\n      for (const { fbase_key: key, value } of result) {\n        keysInResult.add(key);\n        if (JSON.stringify(this.localCache[key]) !== JSON.stringify(value)) {\n          this.notifyListeners(key, value as PersistenceValue);\n          keys.push(key);\n        }\n      }\n    }\n\n    for (const localKey of Object.keys(this.localCache)) {\n      if (this.localCache[localKey] && !keysInResult.has(localKey)) {\n        // Deleted\n        this.notifyListeners(localKey, null);\n        keys.push(localKey);\n      }\n    }\n    return keys;\n  }\n\n  private notifyListeners(\n    key: string,\n    newValue: PersistenceValue | null\n  ): void {\n    this.localCache[key] = newValue;\n    const listeners = this.listeners[key];\n    if (listeners) {\n      for (const listener of Array.from(listeners)) {\n        listener(newValue);\n      }\n    }\n  }\n\n  private startPolling(): void {\n    this.stopPolling();\n\n    this.pollTimer = setInterval(\n      async () => this._poll(),\n      _POLLING_INTERVAL_MS\n    );\n  }\n\n  private stopPolling(): void {\n    if (this.pollTimer) {\n      clearInterval(this.pollTimer);\n      this.pollTimer = null;\n    }\n  }\n\n  _addListener(key: string, listener: StorageEventListener): void {\n    if (Object.keys(this.listeners).length === 0) {\n      this.startPolling();\n    }\n    if (!this.listeners[key]) {\n      this.listeners[key] = new Set();\n      // Populate the cache to avoid spuriously triggering on first poll.\n      void this._get(key); // This can happen in the background async and we can return immediately.\n    }\n    this.listeners[key].add(listener);\n  }\n\n  _removeListener(key: string, listener: StorageEventListener): void {\n    if (this.listeners[key]) {\n      this.listeners[key].delete(listener);\n\n      if (this.listeners[key].size === 0) {\n        delete this.listeners[key];\n      }\n    }\n\n    if (Object.keys(this.listeners).length === 0) {\n      this.stopPolling();\n    }\n  }\n}\n\n/**\n * An implementation of {@link Persistence} of type `LOCAL` using `indexedDB`\n * for the underlying storage.\n *\n * @public\n */\nexport const indexedDBLocalPersistence: Persistence = IndexedDBLocalPersistence;\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  _performApiRequest,\n  Endpoint,\n  HttpMethod,\n  RecaptchaClientType,\n  RecaptchaVersion,\n  _addTidIfNecessary\n} from '../index';\nimport { Auth } from '../../model/public_types';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { MfaEnrollment } from '../account_management/mfa';\nimport { SignInWithIdpResponse } from './idp';\nimport {\n  SignInWithPhoneNumberRequest,\n  SignInWithPhoneNumberResponse\n} from './sms';\n\nexport interface FinalizeMfaResponse {\n  idToken: string;\n  refreshToken: string;\n}\n\n/**\n * @internal\n */\nexport interface IdTokenMfaResponse extends IdTokenResponse {\n  mfaPendingCredential?: string;\n  mfaInfo?: MfaEnrollment[];\n}\n\nexport interface StartPhoneMfaSignInRequest {\n  mfaPendingCredential: string;\n  mfaEnrollmentId: string;\n  phoneSignInInfo: {\n    // reCAPTCHA v2 token\n    recaptchaToken?: string;\n    // reCAPTCHA Enterprise token\n    captchaResponse?: string;\n    clientType?: RecaptchaClientType;\n    recaptchaVersion?: RecaptchaVersion;\n  };\n  tenantId?: string;\n}\n\nexport interface StartPhoneMfaSignInResponse {\n  phoneResponseInfo: {\n    sessionInfo: string;\n  };\n}\n\nexport function startSignInPhoneMfa(\n  auth: Auth,\n  request: StartPhoneMfaSignInRequest\n): Promise<StartPhoneMfaSignInResponse> {\n  return _performApiRequest<\n    StartPhoneMfaSignInRequest,\n    StartPhoneMfaSignInResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.START_MFA_SIGN_IN,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport interface FinalizePhoneMfaSignInRequest {\n  mfaPendingCredential: string;\n  phoneVerificationInfo: SignInWithPhoneNumberRequest;\n  tenantId?: string;\n}\n\n// TOTP MFA Sign in only has a finalize phase. Phone MFA has a start phase to initiate sending an\n// SMS and a finalize phase to complete sign in. With TOTP, the user already has the OTP in the\n// TOTP/Authenticator app.\nexport interface FinalizeTotpMfaSignInRequest {\n  mfaPendingCredential: string;\n  totpVerificationInfo: { verificationCode: string };\n  tenantId?: string;\n  mfaEnrollmentId: string;\n}\n\nexport interface FinalizePhoneMfaSignInResponse extends FinalizeMfaResponse {}\n\nexport interface FinalizeTotpMfaSignInResponse extends FinalizeMfaResponse {}\n\nexport function finalizeSignInPhoneMfa(\n  auth: Auth,\n  request: FinalizePhoneMfaSignInRequest\n): Promise<FinalizePhoneMfaSignInResponse> {\n  return _performApiRequest<\n    FinalizePhoneMfaSignInRequest,\n    FinalizePhoneMfaSignInResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.FINALIZE_MFA_SIGN_IN,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\nexport function finalizeSignInTotpMfa(\n  auth: Auth,\n  request: FinalizeTotpMfaSignInRequest\n): Promise<FinalizeTotpMfaSignInResponse> {\n  return _performApiRequest<\n    FinalizeTotpMfaSignInRequest,\n    FinalizeTotpMfaSignInResponse\n  >(\n    auth,\n    HttpMethod.POST,\n    Endpoint.FINALIZE_MFA_SIGN_IN,\n    _addTidIfNecessary(auth, request)\n  );\n}\n\n/**\n * @internal\n */\nexport type PhoneOrOauthTokenResponse =\n  | SignInWithPhoneNumberResponse\n  | SignInWithIdpResponse\n  | IdTokenResponse;\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { querystring } from '@firebase/util';\n\nimport { AuthErrorCode } from '../../core/errors';\nimport { _assert, _createError } from '../../core/util/assert';\nimport { Delay } from '../../core/util/delay';\nimport { AuthInternal } from '../../model/auth';\nimport { _window } from '../auth_window';\nimport * as jsHelpers from '../load_js';\nimport { Recaptcha, isV2 } from './recaptcha';\nimport { MockReCaptcha } from './recaptcha_mock';\n\n// ReCaptcha will load using the same callback, so the callback function needs\n// to be kept around\nexport const _JSLOAD_CALLBACK = jsHelpers._generateCallbackName('rcb');\nconst NETWORK_TIMEOUT_DELAY = new Delay(30000, 60000);\n\n/**\n * We need to mark this interface as internal explicitly to exclude it in the public typings, because\n * it references AuthInternal which has a circular dependency with UserInternal.\n *\n * @internal\n */\nexport interface ReCaptchaLoader {\n  load(auth: AuthInternal, hl?: string): Promise<Recaptcha>;\n  clearedOneInstance(): void;\n}\n\n/**\n * Loader for the GReCaptcha library. There should only ever be one of this.\n */\nexport class ReCaptchaLoaderImpl implements ReCaptchaLoader {\n  private hostLanguage = '';\n  private counter = 0;\n  /**\n   * Check for `render()` method. `window.grecaptcha` will exist if the Enterprise\n   * version of the ReCAPTCHA script was loaded by someone else (e.g. App Check) but\n   * `window.grecaptcha.render()` will not. Another load will add it.\n   */\n  private readonly librarySeparatelyLoaded = !!_window().grecaptcha?.render;\n\n  load(auth: AuthInternal, hl = ''): Promise<Recaptcha> {\n    _assert(isHostLanguageValid(hl), auth, AuthErrorCode.ARGUMENT_ERROR);\n\n    if (this.shouldResolveImmediately(hl) && isV2(_window().grecaptcha)) {\n      return Promise.resolve(_window().grecaptcha! as Recaptcha);\n    }\n    return new Promise<Recaptcha>((resolve, reject) => {\n      const networkTimeout = _window().setTimeout(() => {\n        reject(_createError(auth, AuthErrorCode.NETWORK_REQUEST_FAILED));\n      }, NETWORK_TIMEOUT_DELAY.get());\n\n      _window()[_JSLOAD_CALLBACK] = () => {\n        _window().clearTimeout(networkTimeout);\n        delete _window()[_JSLOAD_CALLBACK];\n\n        const recaptcha = _window().grecaptcha as Recaptcha;\n\n        if (!recaptcha || !isV2(recaptcha)) {\n          reject(_createError(auth, AuthErrorCode.INTERNAL_ERROR));\n          return;\n        }\n\n        // Wrap the recaptcha render function so that we know if the developer has\n        // called it separately\n        const render = recaptcha.render;\n        recaptcha.render = (container, params) => {\n          const widgetId = render(container, params);\n          this.counter++;\n          return widgetId;\n        };\n\n        this.hostLanguage = hl;\n        resolve(recaptcha);\n      };\n\n      const url = `${jsHelpers._recaptchaV2ScriptUrl()}?${querystring({\n        onload: _JSLOAD_CALLBACK,\n        render: 'explicit',\n        hl\n      })}`;\n\n      jsHelpers._loadJS(url).catch(() => {\n        clearTimeout(networkTimeout);\n        reject(_createError(auth, AuthErrorCode.INTERNAL_ERROR));\n      });\n    });\n  }\n\n  clearedOneInstance(): void {\n    this.counter--;\n  }\n\n  private shouldResolveImmediately(hl: string): boolean {\n    // We can resolve immediately if:\n    //   • grecaptcha is already defined AND (\n    //     1. the requested language codes are the same OR\n    //     2. there exists already a ReCaptcha on the page\n    //     3. the library was already loaded by the app\n    // In cases (2) and (3), we _can't_ reload as it would break the recaptchas\n    // that are already in the page\n    return (\n      !!_window().grecaptcha?.render &&\n      (hl === this.hostLanguage ||\n        this.counter > 0 ||\n        this.librarySeparatelyLoaded)\n    );\n  }\n}\n\nfunction isHostLanguageValid(hl: string): boolean {\n  return hl.length <= 6 && /^\\s*[a-zA-Z0-9\\-]*\\s*$/.test(hl);\n}\n\nexport class MockReCaptchaLoaderImpl implements ReCaptchaLoader {\n  async load(auth: AuthInternal): Promise<Recaptcha> {\n    return new MockReCaptcha(auth);\n  }\n\n  clearedOneInstance(): void {}\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Auth, RecaptchaParameters } from '../../model/public_types';\nimport { getRecaptchaParams } from '../../api/authentication/recaptcha';\nimport { _castAuth } from '../../core/auth/auth_impl';\nimport { AuthErrorCode } from '../../core/errors';\nimport { _assert } from '../../core/util/assert';\nimport { _isHttpOrHttps } from '../../core/util/location';\nimport { ApplicationVerifierInternal } from '../../model/application_verifier';\nimport { AuthInternal } from '../../model/auth';\nimport { _window } from '../auth_window';\nimport { _isWorker } from '../util/worker';\nimport { Recaptcha } from './recaptcha';\nimport {\n  MockReCaptchaLoaderImpl,\n  ReCaptchaLoader,\n  ReCaptchaLoaderImpl\n} from './recaptcha_loader';\n\nexport const RECAPTCHA_VERIFIER_TYPE = 'recaptcha';\n\nconst DEFAULT_PARAMS: RecaptchaParameters = {\n  theme: 'light',\n  type: 'image'\n};\n\ntype TokenCallback = (token: string) => void;\n\n/**\n * An {@link https://www.google.com/recaptcha/ | reCAPTCHA}-based application verifier.\n *\n * @remarks\n * `RecaptchaVerifier` does not work in a Node.js environment.\n *\n * @public\n */\nexport class RecaptchaVerifier implements ApplicationVerifierInternal {\n  /**\n   * The application verifier type.\n   *\n   * @remarks\n   * For a reCAPTCHA verifier, this is 'recaptcha'.\n   */\n  readonly type = RECAPTCHA_VERIFIER_TYPE;\n  private destroyed = false;\n  private widgetId: number | null = null;\n  private readonly container: HTMLElement;\n  private readonly isInvisible: boolean;\n  private readonly tokenChangeListeners = new Set<TokenCallback>();\n  private renderPromise: Promise<number> | null = null;\n  private readonly auth: AuthInternal;\n\n  /** @internal */\n  readonly _recaptchaLoader: ReCaptchaLoader;\n  private recaptcha: Recaptcha | null = null;\n\n  /**\n   * @param authExtern - The corresponding Firebase {@link Auth} instance.\n   *\n   * @param containerOrId - The reCAPTCHA container parameter.\n   *\n   * @remarks\n   * This has different meaning depending on whether the reCAPTCHA is hidden or visible. For a\n   * visible reCAPTCHA the container must be empty. If a string is used, it has to correspond to\n   * an element ID. The corresponding element must also must be in the DOM at the time of\n   * initialization.\n   *\n   * @param parameters - The optional reCAPTCHA parameters.\n   *\n   * @remarks\n   * Check the reCAPTCHA docs for a comprehensive list. All parameters are accepted except for\n   * the sitekey. Firebase Auth backend provisions a reCAPTCHA for each project and will\n   * configure this upon rendering. For an invisible reCAPTCHA, a size key must have the value\n   * 'invisible'.\n   */\n  constructor(\n    authExtern: Auth,\n    containerOrId: HTMLElement | string,\n    private readonly parameters: RecaptchaParameters = {\n      ...DEFAULT_PARAMS\n    }\n  ) {\n    this.auth = _castAuth(authExtern);\n    this.isInvisible = this.parameters.size === 'invisible';\n    _assert(\n      typeof document !== 'undefined',\n      this.auth,\n      AuthErrorCode.OPERATION_NOT_SUPPORTED\n    );\n    const container =\n      typeof containerOrId === 'string'\n        ? document.getElementById(containerOrId)\n        : containerOrId;\n    _assert(container, this.auth, AuthErrorCode.ARGUMENT_ERROR);\n\n    this.container = container;\n    this.parameters.callback = this.makeTokenCallback(this.parameters.callback);\n\n    this._recaptchaLoader = this.auth.settings.appVerificationDisabledForTesting\n      ? new MockReCaptchaLoaderImpl()\n      : new ReCaptchaLoaderImpl();\n\n    this.validateStartingState();\n    // TODO: Figure out if sdk version is needed\n  }\n\n  /**\n   * Waits for the user to solve the reCAPTCHA and resolves with the reCAPTCHA token.\n   *\n   * @returns A Promise for the reCAPTCHA token.\n   */\n  async verify(): Promise<string> {\n    this.assertNotDestroyed();\n    const id = await this.render();\n    const recaptcha = this.getAssertedRecaptcha();\n\n    const response = recaptcha.getResponse(id);\n    if (response) {\n      return response;\n    }\n\n    return new Promise<string>(resolve => {\n      const tokenChange = (token: string): void => {\n        if (!token) {\n          return; // Ignore token expirations.\n        }\n        this.tokenChangeListeners.delete(tokenChange);\n        resolve(token);\n      };\n\n      this.tokenChangeListeners.add(tokenChange);\n      if (this.isInvisible) {\n        recaptcha.execute(id);\n      }\n    });\n  }\n\n  /**\n   * Renders the reCAPTCHA widget on the page.\n   *\n   * @returns A Promise that resolves with the reCAPTCHA widget ID.\n   */\n  render(): Promise<number> {\n    try {\n      this.assertNotDestroyed();\n    } catch (e) {\n      // This method returns a promise. Since it's not async (we want to return the\n      // _same_ promise if rendering is still occurring), the API surface should\n      // reject with the error rather than just throw\n      return Promise.reject(e);\n    }\n\n    if (this.renderPromise) {\n      return this.renderPromise;\n    }\n\n    this.renderPromise = this.makeRenderPromise().catch(e => {\n      this.renderPromise = null;\n      throw e;\n    });\n\n    return this.renderPromise;\n  }\n\n  /** @internal */\n  _reset(): void {\n    this.assertNotDestroyed();\n    if (this.widgetId !== null) {\n      this.getAssertedRecaptcha().reset(this.widgetId);\n    }\n  }\n\n  /**\n   * Clears the reCAPTCHA widget from the page and destroys the instance.\n   */\n  clear(): void {\n    this.assertNotDestroyed();\n    this.destroyed = true;\n    this._recaptchaLoader.clearedOneInstance();\n    if (!this.isInvisible) {\n      this.container.childNodes.forEach(node => {\n        this.container.removeChild(node);\n      });\n    }\n  }\n\n  private validateStartingState(): void {\n    _assert(!this.parameters.sitekey, this.auth, AuthErrorCode.ARGUMENT_ERROR);\n    _assert(\n      this.isInvisible || !this.container.hasChildNodes(),\n      this.auth,\n      AuthErrorCode.ARGUMENT_ERROR\n    );\n    _assert(\n      typeof document !== 'undefined',\n      this.auth,\n      AuthErrorCode.OPERATION_NOT_SUPPORTED\n    );\n  }\n\n  private makeTokenCallback(\n    existing: TokenCallback | string | undefined\n  ): TokenCallback {\n    return token => {\n      this.tokenChangeListeners.forEach(listener => listener(token));\n      if (typeof existing === 'function') {\n        existing(token);\n      } else if (typeof existing === 'string') {\n        const globalFunc = _window()[existing];\n        if (typeof globalFunc === 'function') {\n          globalFunc(token);\n        }\n      }\n    };\n  }\n\n  private assertNotDestroyed(): void {\n    _assert(!this.destroyed, this.auth, AuthErrorCode.INTERNAL_ERROR);\n  }\n\n  private async makeRenderPromise(): Promise<number> {\n    await this.init();\n    if (!this.widgetId) {\n      let container = this.container;\n      if (!this.isInvisible) {\n        const guaranteedEmpty = document.createElement('div');\n        container.appendChild(guaranteedEmpty);\n        container = guaranteedEmpty;\n      }\n\n      this.widgetId = this.getAssertedRecaptcha().render(\n        container,\n        this.parameters\n      );\n    }\n\n    return this.widgetId;\n  }\n\n  private async init(): Promise<void> {\n    _assert(\n      _isHttpOrHttps() && !_isWorker(),\n      this.auth,\n      AuthErrorCode.INTERNAL_ERROR\n    );\n\n    await domReady();\n    this.recaptcha = await this._recaptchaLoader.load(\n      this.auth,\n      this.auth.languageCode || undefined\n    );\n\n    const siteKey = await getRecaptchaParams(this.auth);\n    _assert(siteKey, this.auth, AuthErrorCode.INTERNAL_ERROR);\n    this.parameters.sitekey = siteKey;\n  }\n\n  private getAssertedRecaptcha(): Recaptcha {\n    _assert(this.recaptcha, this.auth, AuthErrorCode.INTERNAL_ERROR);\n    return this.recaptcha;\n  }\n}\n\nfunction domReady(): Promise<void> {\n  let resolver: (() => void) | null = null;\n  return new Promise<void>(resolve => {\n    if (document.readyState === 'complete') {\n      resolve();\n      return;\n    }\n\n    // Document not ready, wait for load before resolving.\n    // Save resolver, so we can remove listener in case it was externally\n    // cancelled.\n    resolver = () => resolve();\n    window.addEventListener('load', resolver);\n  }).catch(e => {\n    if (resolver) {\n      window.removeEventListener('load', resolver);\n    }\n\n    throw e;\n  });\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  ApplicationVerifier,\n  Auth,\n  ConfirmationResult,\n  PhoneInfoOptions,\n  User,\n  UserCredential\n} from '../../model/public_types';\n\nimport {\n  startEnrollPhoneMfa,\n  StartPhoneMfaEnrollmentRequest,\n  StartPhoneMfaEnrollmentResponse\n} from '../../api/account_management/mfa';\nimport {\n  startSignInPhoneMfa,\n  StartPhoneMfaSignInRequest,\n  StartPhoneMfaSignInResponse\n} from '../../api/authentication/mfa';\nimport {\n  sendPhoneVerificationCode,\n  SendPhoneVerificationCodeRequest,\n  SendPhoneVerificationCodeResponse\n} from '../../api/authentication/sms';\nimport {\n  RecaptchaActionName,\n  RecaptchaClientType,\n  RecaptchaAuthProvider\n} from '../../api';\nimport { ApplicationVerifierInternal } from '../../model/application_verifier';\nimport { PhoneAuthCredential } from '../../core/credentials/phone';\nimport { AuthErrorCode } from '../../core/errors';\nimport { _assertLinkedStatus, _link } from '../../core/user/link_unlink';\nimport {\n  _assert,\n  _serverAppCurrentUserOperationNotSupportedError\n} from '../../core/util/assert';\nimport { AuthInternal } from '../../model/auth';\nimport {\n  linkWithCredential,\n  reauthenticateWithCredential,\n  signInWithCredential\n} from '../../core/strategies/credential';\nimport {\n  MultiFactorSessionImpl,\n  MultiFactorSessionType\n} from '../../mfa/mfa_session';\nimport { UserInternal } from '../../model/user';\nimport { RECAPTCHA_VERIFIER_TYPE } from '../recaptcha/recaptcha_verifier';\nimport { _castAuth } from '../../core/auth/auth_impl';\nimport { getModularInstance } from '@firebase/util';\nimport { ProviderId } from '../../model/enums';\nimport {\n  FAKE_TOKEN,\n  handleRecaptchaFlow,\n  _initializeRecaptchaConfig\n} from '../recaptcha/recaptcha_enterprise_verifier';\nimport { _isFirebaseServerApp } from '@firebase/app';\n\ninterface OnConfirmationCallback {\n  (credential: PhoneAuthCredential): Promise<UserCredential>;\n}\n\nclass ConfirmationResultImpl implements ConfirmationResult {\n  constructor(\n    readonly verificationId: string,\n    private readonly onConfirmation: OnConfirmationCallback\n  ) {}\n\n  confirm(verificationCode: string): Promise<UserCredential> {\n    const authCredential = PhoneAuthCredential._fromVerification(\n      this.verificationId,\n      verificationCode\n    );\n    return this.onConfirmation(authCredential);\n  }\n}\n\n/**\n * Asynchronously signs in using a phone number.\n *\n * @remarks\n * This method sends a code via SMS to the given\n * phone number, and returns a {@link ConfirmationResult}. After the user\n * provides the code sent to their phone, call {@link ConfirmationResult.confirm}\n * with the code to sign the user in.\n *\n * For abuse prevention, this method requires a {@link ApplicationVerifier}.\n * This SDK includes an implementation based on reCAPTCHA v2, {@link RecaptchaVerifier}.\n * This function can work on other platforms that do not support the\n * {@link RecaptchaVerifier} (like React Native), but you need to use a\n * third-party {@link ApplicationVerifier} implementation.\n *\n * If you've enabled project-level reCAPTCHA Enterprise bot protection in\n * Enforce mode, you can omit the {@link ApplicationVerifier}.\n *\n * This method does not work in a Node.js environment or with {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```javascript\n * // 'recaptcha-container' is the ID of an element in the DOM.\n * const applicationVerifier = new firebase.auth.RecaptchaVerifier('recaptcha-container');\n * const confirmationResult = await signInWithPhoneNumber(auth, phoneNumber, applicationVerifier);\n * // Obtain a verificationCode from the user.\n * const credential = await confirmationResult.confirm(verificationCode);\n * ```\n *\n * @param auth - The {@link Auth} instance.\n * @param phoneNumber - The user's phone number in E.164 format (e.g. +16505550101).\n * @param appVerifier - The {@link ApplicationVerifier}.\n *\n * @public\n */\nexport async function signInWithPhoneNumber(\n  auth: Auth,\n  phoneNumber: string,\n  appVerifier?: ApplicationVerifier\n): Promise<ConfirmationResult> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const authInternal = _castAuth(auth);\n  const verificationId = await _verifyPhoneNumber(\n    authInternal,\n    phoneNumber,\n    getModularInstance(appVerifier as ApplicationVerifierInternal)\n  );\n  return new ConfirmationResultImpl(verificationId, cred =>\n    signInWithCredential(authInternal, cred)\n  );\n}\n\n/**\n * Links the user account with the given phone number.\n *\n * @remarks\n * This method does not work in a Node.js environment.\n *\n * @param user - The user.\n * @param phoneNumber - The user's phone number in E.164 format (e.g. +16505550101).\n * @param appVerifier - The {@link ApplicationVerifier}.\n *\n * @public\n */\nexport async function linkWithPhoneNumber(\n  user: User,\n  phoneNumber: string,\n  appVerifier?: ApplicationVerifier\n): Promise<ConfirmationResult> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  await _assertLinkedStatus(false, userInternal, ProviderId.PHONE);\n  const verificationId = await _verifyPhoneNumber(\n    userInternal.auth,\n    phoneNumber,\n    getModularInstance(appVerifier as ApplicationVerifierInternal)\n  );\n  return new ConfirmationResultImpl(verificationId, cred =>\n    linkWithCredential(userInternal, cred)\n  );\n}\n\n/**\n * Re-authenticates a user using a fresh phone credential.\n *\n * @remarks\n * Use before operations such as {@link updatePassword} that require tokens from recent sign-in attempts.\n *\n * This method does not work in a Node.js environment or on any {@link User} signed in by\n * {@link Auth} instances created with a {@link @firebase/app#FirebaseServerApp}.\n *\n * @param user - The user.\n * @param phoneNumber - The user's phone number in E.164 format (e.g. +16505550101).\n * @param appVerifier - The {@link ApplicationVerifier}.\n *\n * @public\n */\nexport async function reauthenticateWithPhoneNumber(\n  user: User,\n  phoneNumber: string,\n  appVerifier?: ApplicationVerifier\n): Promise<ConfirmationResult> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  if (_isFirebaseServerApp(userInternal.auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(userInternal.auth)\n    );\n  }\n  const verificationId = await _verifyPhoneNumber(\n    userInternal.auth,\n    phoneNumber,\n    getModularInstance(appVerifier as ApplicationVerifierInternal)\n  );\n  return new ConfirmationResultImpl(verificationId, cred =>\n    reauthenticateWithCredential(userInternal, cred)\n  );\n}\n\ntype PhoneApiCaller<TRequest, TResponse> = (\n  auth: AuthInternal,\n  request: TRequest\n) => Promise<TResponse>;\n\n/**\n * Returns a verification ID to be used in conjunction with the SMS code that is sent.\n *\n */\nexport async function _verifyPhoneNumber(\n  auth: AuthInternal,\n  options: PhoneInfoOptions | string,\n  verifier?: ApplicationVerifierInternal\n): Promise<string> {\n  if (!auth._getRecaptchaConfig()) {\n    try {\n      await _initializeRecaptchaConfig(auth);\n    } catch (error) {\n      // If an error occurs while fetching the config, there is no way to know the enablement state\n      // of Phone provider, so we proceed with recaptcha V2 verification.\n      // The error is likely \"recaptchaKey undefined\", as reCAPTCHA Enterprise is not\n      // enabled for any provider.\n      console.log(\n        'Failed to initialize reCAPTCHA Enterprise config. Triggering the reCAPTCHA v2 verification.'\n      );\n    }\n  }\n\n  try {\n    let phoneInfoOptions: PhoneInfoOptions;\n\n    if (typeof options === 'string') {\n      phoneInfoOptions = {\n        phoneNumber: options\n      };\n    } else {\n      phoneInfoOptions = options;\n    }\n\n    if ('session' in phoneInfoOptions) {\n      const session = phoneInfoOptions.session as MultiFactorSessionImpl;\n\n      if ('phoneNumber' in phoneInfoOptions) {\n        _assert(\n          session.type === MultiFactorSessionType.ENROLL,\n          auth,\n          AuthErrorCode.INTERNAL_ERROR\n        );\n\n        const startPhoneMfaEnrollmentRequest: StartPhoneMfaEnrollmentRequest = {\n          idToken: session.credential,\n          phoneEnrollmentInfo: {\n            phoneNumber: phoneInfoOptions.phoneNumber,\n            clientType: RecaptchaClientType.WEB\n          }\n        };\n\n        const startEnrollPhoneMfaActionCallback: PhoneApiCaller<\n          StartPhoneMfaEnrollmentRequest,\n          StartPhoneMfaEnrollmentResponse\n        > = async (\n          authInstance: AuthInternal,\n          request: StartPhoneMfaEnrollmentRequest\n        ) => {\n          // If reCAPTCHA Enterprise token is FAKE_TOKEN, fetch reCAPTCHA v2 token and inject into request.\n          if (request.phoneEnrollmentInfo.captchaResponse === FAKE_TOKEN) {\n            _assert(\n              verifier?.type === RECAPTCHA_VERIFIER_TYPE,\n              authInstance,\n              AuthErrorCode.ARGUMENT_ERROR\n            );\n\n            const requestWithRecaptchaV2 = await injectRecaptchaV2Token(\n              authInstance,\n              request,\n              verifier\n            );\n            return startEnrollPhoneMfa(authInstance, requestWithRecaptchaV2);\n          }\n          return startEnrollPhoneMfa(authInstance, request);\n        };\n\n        const startPhoneMfaEnrollmentResponse: Promise<StartPhoneMfaEnrollmentResponse> =\n          handleRecaptchaFlow(\n            auth,\n            startPhoneMfaEnrollmentRequest,\n            RecaptchaActionName.MFA_SMS_ENROLLMENT,\n            startEnrollPhoneMfaActionCallback,\n            RecaptchaAuthProvider.PHONE_PROVIDER\n          );\n\n        const response = await startPhoneMfaEnrollmentResponse.catch(error => {\n          return Promise.reject(error);\n        });\n\n        return response.phoneSessionInfo.sessionInfo;\n      } else {\n        _assert(\n          session.type === MultiFactorSessionType.SIGN_IN,\n          auth,\n          AuthErrorCode.INTERNAL_ERROR\n        );\n        const mfaEnrollmentId =\n          phoneInfoOptions.multiFactorHint?.uid ||\n          phoneInfoOptions.multiFactorUid;\n        _assert(mfaEnrollmentId, auth, AuthErrorCode.MISSING_MFA_INFO);\n\n        const startPhoneMfaSignInRequest: StartPhoneMfaSignInRequest = {\n          mfaPendingCredential: session.credential,\n          mfaEnrollmentId,\n          phoneSignInInfo: {\n            clientType: RecaptchaClientType.WEB\n          }\n        };\n\n        const startSignInPhoneMfaActionCallback: PhoneApiCaller<\n          StartPhoneMfaSignInRequest,\n          StartPhoneMfaSignInResponse\n        > = async (\n          authInstance: AuthInternal,\n          request: StartPhoneMfaSignInRequest\n        ) => {\n          // If reCAPTCHA Enterprise token is FAKE_TOKEN, fetch reCAPTCHA v2 token and inject into request.\n          if (request.phoneSignInInfo.captchaResponse === FAKE_TOKEN) {\n            _assert(\n              verifier?.type === RECAPTCHA_VERIFIER_TYPE,\n              authInstance,\n              AuthErrorCode.ARGUMENT_ERROR\n            );\n\n            const requestWithRecaptchaV2 = await injectRecaptchaV2Token(\n              authInstance,\n              request,\n              verifier\n            );\n            return startSignInPhoneMfa(authInstance, requestWithRecaptchaV2);\n          }\n          return startSignInPhoneMfa(authInstance, request);\n        };\n\n        const startPhoneMfaSignInResponse: Promise<StartPhoneMfaSignInResponse> =\n          handleRecaptchaFlow(\n            auth,\n            startPhoneMfaSignInRequest,\n            RecaptchaActionName.MFA_SMS_SIGNIN,\n            startSignInPhoneMfaActionCallback,\n            RecaptchaAuthProvider.PHONE_PROVIDER\n          );\n\n        const response = await startPhoneMfaSignInResponse.catch(error => {\n          return Promise.reject(error);\n        });\n\n        return response.phoneResponseInfo.sessionInfo;\n      }\n    } else {\n      const sendPhoneVerificationCodeRequest: SendPhoneVerificationCodeRequest =\n        {\n          phoneNumber: phoneInfoOptions.phoneNumber,\n          clientType: RecaptchaClientType.WEB\n        };\n\n      const sendPhoneVerificationCodeActionCallback: PhoneApiCaller<\n        SendPhoneVerificationCodeRequest,\n        SendPhoneVerificationCodeResponse\n      > = async (\n        authInstance: AuthInternal,\n        request: SendPhoneVerificationCodeRequest\n      ) => {\n        // If reCAPTCHA Enterprise token is FAKE_TOKEN, fetch reCAPTCHA v2 token and inject into request.\n        if (request.captchaResponse === FAKE_TOKEN) {\n          _assert(\n            verifier?.type === RECAPTCHA_VERIFIER_TYPE,\n            authInstance,\n            AuthErrorCode.ARGUMENT_ERROR\n          );\n\n          const requestWithRecaptchaV2 = await injectRecaptchaV2Token(\n            authInstance,\n            request,\n            verifier\n          );\n          return sendPhoneVerificationCode(\n            authInstance,\n            requestWithRecaptchaV2\n          );\n        }\n        return sendPhoneVerificationCode(authInstance, request);\n      };\n\n      const sendPhoneVerificationCodeResponse: Promise<SendPhoneVerificationCodeResponse> =\n        handleRecaptchaFlow(\n          auth,\n          sendPhoneVerificationCodeRequest,\n          RecaptchaActionName.SEND_VERIFICATION_CODE,\n          sendPhoneVerificationCodeActionCallback,\n          RecaptchaAuthProvider.PHONE_PROVIDER\n        );\n\n      const response = await sendPhoneVerificationCodeResponse.catch(error => {\n        return Promise.reject(error);\n      });\n\n      return response.sessionInfo;\n    }\n  } finally {\n    verifier?._reset();\n  }\n}\n\n/**\n * Updates the user's phone number.\n *\n * @remarks\n * This method does not work in a Node.js environment or on any {@link User} signed in by\n * {@link Auth} instances created with a {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```\n * // 'recaptcha-container' is the ID of an element in the DOM.\n * const applicationVerifier = new RecaptchaVerifier('recaptcha-container');\n * const provider = new PhoneAuthProvider(auth);\n * const verificationId = await provider.verifyPhoneNumber('+16505550101', applicationVerifier);\n * // Obtain the verificationCode from the user.\n * const phoneCredential = PhoneAuthProvider.credential(verificationId, verificationCode);\n * await updatePhoneNumber(user, phoneCredential);\n * ```\n *\n * @param user - The user.\n * @param credential - A credential authenticating the new phone number.\n *\n * @public\n */\nexport async function updatePhoneNumber(\n  user: User,\n  credential: PhoneAuthCredential\n): Promise<void> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  if (_isFirebaseServerApp(userInternal.auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(userInternal.auth)\n    );\n  }\n  await _link(userInternal, credential);\n}\n\n// Helper function that fetches and injects a reCAPTCHA v2 token into the request.\nexport async function injectRecaptchaV2Token<T extends object>(\n  auth: AuthInternal,\n  request: T,\n  recaptchaV2Verifier: ApplicationVerifierInternal\n): Promise<T> {\n  _assert(\n    recaptchaV2Verifier.type === RECAPTCHA_VERIFIER_TYPE,\n    auth,\n    AuthErrorCode.ARGUMENT_ERROR\n  );\n\n  const recaptchaV2Token = await recaptchaV2Verifier.verify();\n\n  _assert(\n    typeof recaptchaV2Token === 'string',\n    auth,\n    AuthErrorCode.ARGUMENT_ERROR\n  );\n\n  const newRequest = { ...request };\n\n  if ('phoneEnrollmentInfo' in newRequest) {\n    const phoneNumber = (\n      newRequest as unknown as StartPhoneMfaEnrollmentRequest\n    ).phoneEnrollmentInfo.phoneNumber;\n    const captchaResponse = (\n      newRequest as unknown as StartPhoneMfaEnrollmentRequest\n    ).phoneEnrollmentInfo.captchaResponse;\n    const clientType = (newRequest as unknown as StartPhoneMfaEnrollmentRequest)\n      .phoneEnrollmentInfo.clientType;\n    const recaptchaVersion = (\n      newRequest as unknown as StartPhoneMfaEnrollmentRequest\n    ).phoneEnrollmentInfo.recaptchaVersion;\n\n    Object.assign(newRequest, {\n      'phoneEnrollmentInfo': {\n        phoneNumber,\n        recaptchaToken: recaptchaV2Token,\n        captchaResponse,\n        clientType,\n        recaptchaVersion\n      }\n    });\n\n    return newRequest;\n  } else if ('phoneSignInInfo' in newRequest) {\n    const captchaResponse = (\n      newRequest as unknown as StartPhoneMfaSignInRequest\n    ).phoneSignInInfo.captchaResponse;\n    const clientType = (newRequest as unknown as StartPhoneMfaSignInRequest)\n      .phoneSignInInfo.clientType;\n    const recaptchaVersion = (\n      newRequest as unknown as StartPhoneMfaSignInRequest\n    ).phoneSignInInfo.recaptchaVersion;\n\n    Object.assign(newRequest, {\n      'phoneSignInInfo': {\n        recaptchaToken: recaptchaV2Token,\n        captchaResponse,\n        clientType,\n        recaptchaVersion\n      }\n    });\n\n    return newRequest;\n  } else {\n    Object.assign(newRequest, { 'recaptchaToken': recaptchaV2Token });\n    return newRequest;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Auth,\n  PhoneInfoOptions,\n  ApplicationVerifier,\n  UserCredential\n} from '../../model/public_types';\n\nimport { SignInWithPhoneNumberResponse } from '../../api/authentication/sms';\nimport { ApplicationVerifierInternal as ApplicationVerifierInternal } from '../../model/application_verifier';\nimport { AuthInternal as AuthInternal } from '../../model/auth';\nimport { UserCredentialInternal as UserCredentialInternal } from '../../model/user';\nimport { PhoneAuthCredential } from '../../core/credentials/phone';\nimport { _verifyPhoneNumber } from '../strategies/phone';\nimport { _castAuth } from '../../core/auth/auth_impl';\nimport { AuthCredential } from '../../core';\nimport { FirebaseError, getModularInstance } from '@firebase/util';\nimport { TaggedWithTokenResponse } from '../../model/id_token';\nimport { ProviderId, SignInMethod } from '../../model/enums';\n\n/**\n * Provider for generating an {@link PhoneAuthCredential}.\n *\n * @remarks\n * `PhoneAuthProvider` does not work in a Node.js environment.\n *\n * @example\n * ```javascript\n * // 'recaptcha-container' is the ID of an element in the DOM.\n * const applicationVerifier = new RecaptchaVerifier('recaptcha-container');\n * const provider = new PhoneAuthProvider(auth);\n * const verificationId = await provider.verifyPhoneNumber('+16505550101', applicationVerifier);\n * // Obtain the verificationCode from the user.\n * const phoneCredential = PhoneAuthProvider.credential(verificationId, verificationCode);\n * const userCredential = await signInWithCredential(auth, phoneCredential);\n * ```\n *\n * @public\n */\nexport class PhoneAuthProvider {\n  /** Always set to {@link ProviderId}.PHONE. */\n  static readonly PROVIDER_ID: 'phone' = ProviderId.PHONE;\n  /** Always set to {@link SignInMethod}.PHONE. */\n  static readonly PHONE_SIGN_IN_METHOD: 'phone' = SignInMethod.PHONE;\n\n  /** Always set to {@link ProviderId}.PHONE. */\n  readonly providerId = PhoneAuthProvider.PROVIDER_ID;\n  private readonly auth: AuthInternal;\n\n  /**\n   * @param auth - The Firebase {@link Auth} instance in which sign-ins should occur.\n   *\n   */\n  constructor(auth: Auth) {\n    this.auth = _castAuth(auth);\n  }\n\n  /**\n   *\n   * Starts a phone number authentication flow by sending a verification code to the given phone\n   * number.\n   *\n   * @example\n   * ```javascript\n   * const provider = new PhoneAuthProvider(auth);\n   * const verificationId = await provider.verifyPhoneNumber(phoneNumber, applicationVerifier);\n   * // Obtain verificationCode from the user.\n   * const authCredential = PhoneAuthProvider.credential(verificationId, verificationCode);\n   * const userCredential = await signInWithCredential(auth, authCredential);\n   * ```\n   *\n   * @example\n   * An alternative flow is provided using the `signInWithPhoneNumber` method.\n   * ```javascript\n   * const confirmationResult = signInWithPhoneNumber(auth, phoneNumber, applicationVerifier);\n   * // Obtain verificationCode from the user.\n   * const userCredential = confirmationResult.confirm(verificationCode);\n   * ```\n   *\n   * @param phoneInfoOptions - The user's {@link PhoneInfoOptions}. The phone number should be in\n   * E.164 format (e.g. +16505550101).\n   * @param applicationVerifier - An {@link ApplicationVerifier}, which prevents\n   * requests from unauthorized clients. This SDK includes an implementation\n   * based on reCAPTCHA v2, {@link RecaptchaVerifier}. If you've enabled\n   * reCAPTCHA Enterprise bot protection in Enforce mode, this parameter is\n   * optional; in all other configurations, the parameter is required.\n   *\n   * @returns A Promise for a verification ID that can be passed to\n   * {@link PhoneAuthProvider.credential} to identify this flow.\n   */\n  verifyPhoneNumber(\n    phoneOptions: PhoneInfoOptions | string,\n    applicationVerifier?: ApplicationVerifier\n  ): Promise<string> {\n    return _verifyPhoneNumber(\n      this.auth,\n      phoneOptions,\n      getModularInstance(applicationVerifier as ApplicationVerifierInternal)\n    );\n  }\n\n  /**\n   * Creates a phone auth credential, given the verification ID from\n   * {@link PhoneAuthProvider.verifyPhoneNumber} and the code that was sent to the user's\n   * mobile device.\n   *\n   * @example\n   * ```javascript\n   * const provider = new PhoneAuthProvider(auth);\n   * const verificationId = provider.verifyPhoneNumber(phoneNumber, applicationVerifier);\n   * // Obtain verificationCode from the user.\n   * const authCredential = PhoneAuthProvider.credential(verificationId, verificationCode);\n   * const userCredential = signInWithCredential(auth, authCredential);\n   * ```\n   *\n   * @example\n   * An alternative flow is provided using the `signInWithPhoneNumber` method.\n   * ```javascript\n   * const confirmationResult = await signInWithPhoneNumber(auth, phoneNumber, applicationVerifier);\n   * // Obtain verificationCode from the user.\n   * const userCredential = await confirmationResult.confirm(verificationCode);\n   * ```\n   *\n   * @param verificationId - The verification ID returned from {@link PhoneAuthProvider.verifyPhoneNumber}.\n   * @param verificationCode - The verification code sent to the user's mobile device.\n   *\n   * @returns The auth provider credential.\n   */\n  static credential(\n    verificationId: string,\n    verificationCode: string\n  ): PhoneAuthCredential {\n    return PhoneAuthCredential._fromVerification(\n      verificationId,\n      verificationCode\n    );\n  }\n\n  /**\n   * Generates an {@link AuthCredential} from a {@link UserCredential}.\n   * @param userCredential - The user credential.\n   */\n  static credentialFromResult(\n    userCredential: UserCredential\n  ): AuthCredential | null {\n    const credential = userCredential as UserCredentialInternal;\n    return PhoneAuthProvider.credentialFromTaggedObject(credential);\n  }\n\n  /**\n   * Returns an {@link AuthCredential} when passed an error.\n   *\n   * @remarks\n   *\n   * This method works for errors like\n   * `auth/account-exists-with-different-credentials`. This is useful for\n   * recovering when attempting to set a user's phone number but the number\n   * in question is already tied to another account. For example, the following\n   * code tries to update the current user's phone number, and if that\n   * fails, links the user with the account associated with that number:\n   *\n   * ```js\n   * const provider = new PhoneAuthProvider(auth);\n   * const verificationId = await provider.verifyPhoneNumber(number, verifier);\n   * try {\n   *   const code = ''; // Prompt the user for the verification code\n   *   await updatePhoneNumber(\n   *       auth.currentUser,\n   *       PhoneAuthProvider.credential(verificationId, code));\n   * } catch (e) {\n   *   if ((e as FirebaseError)?.code === 'auth/account-exists-with-different-credential') {\n   *     const cred = PhoneAuthProvider.credentialFromError(e);\n   *     await linkWithCredential(auth.currentUser, cred);\n   *   }\n   * }\n   *\n   * // At this point, auth.currentUser.phoneNumber === number.\n   * ```\n   *\n   * @param error - The error to generate a credential from.\n   */\n  static credentialFromError(error: FirebaseError): AuthCredential | null {\n    return PhoneAuthProvider.credentialFromTaggedObject(\n      (error.customData || {}) as TaggedWithTokenResponse\n    );\n  }\n\n  private static credentialFromTaggedObject({\n    _tokenResponse: tokenResponse\n  }: TaggedWithTokenResponse): AuthCredential | null {\n    if (!tokenResponse) {\n      return null;\n    }\n    const { phoneNumber, temporaryProof } =\n      tokenResponse as SignInWithPhoneNumberResponse;\n    if (phoneNumber && temporaryProof) {\n      return PhoneAuthCredential._fromTokenResponse(\n        phoneNumber,\n        temporaryProof\n      );\n    }\n    return null;\n  }\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { PopupRedirectResolver } from '../../model/public_types';\nimport { AuthInternal } from '../../model/auth';\nimport { PopupRedirectResolverInternal } from '../../model/popup_redirect';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from './assert';\nimport { _getInstance } from './instantiator';\n\n/**\n * Chooses a popup/redirect resolver to use. This prefers the override (which\n * is directly passed in), and falls back to the property set on the auth\n * object. If neither are available, this function errors w/ an argument error.\n */\nexport function _withDefaultResolver(\n  auth: AuthInternal,\n  resolverOverride: PopupRedirectResolver | undefined\n): PopupRedirectResolverInternal {\n  if (resolverOverride) {\n    return _getInstance(resolverOverride);\n  }\n\n  _assert(auth._popupRedirectResolver, auth, AuthErrorCode.ARGUMENT_ERROR);\n\n  return auth._popupRedirectResolver;\n}\n","/**\n * @license\n * Copyright 2019 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  signInWithIdp,\n  SignInWithIdpRequest\n} from '../../api/authentication/idp';\nimport { PhoneOrOauthTokenResponse } from '../../api/authentication/mfa';\nimport { AuthInternal } from '../../model/auth';\nimport { IdTokenResponse } from '../../model/id_token';\nimport { UserInternal, UserCredentialInternal } from '../../model/user';\nimport { AuthCredential } from '../credentials';\nimport { _link as _linkUser } from '../user/link_unlink';\nimport { _reauthenticate } from '../user/reauthenticate';\nimport { _assert } from '../util/assert';\nimport { _signInWithCredential } from './credential';\nimport { AuthErrorCode } from '../errors';\nimport { ProviderId } from '../../model/enums';\n\nexport interface IdpTaskParams {\n  auth: AuthInternal;\n  requestUri: string;\n  sessionId?: string;\n  tenantId?: string;\n  postBody?: string;\n  pendingToken?: string;\n  user?: UserInternal;\n  bypassAuthState?: boolean;\n}\n\nexport type IdpTask = (\n  params: IdpTaskParams\n) => Promise<UserCredentialInternal>;\n\nclass IdpCredential extends AuthCredential {\n  constructor(readonly params: IdpTaskParams) {\n    super(ProviderId.CUSTOM, ProviderId.CUSTOM);\n  }\n\n  _getIdTokenResponse(auth: AuthInternal): Promise<PhoneOrOauthTokenResponse> {\n    return signInWithIdp(auth, this._buildIdpRequest());\n  }\n\n  _linkToIdToken(\n    auth: AuthInternal,\n    idToken: string\n  ): Promise<IdTokenResponse> {\n    return signInWithIdp(auth, this._buildIdpRequest(idToken));\n  }\n\n  _getReauthenticationResolver(auth: AuthInternal): Promise<IdTokenResponse> {\n    return signInWithIdp(auth, this._buildIdpRequest());\n  }\n\n  private _buildIdpRequest(idToken?: string): SignInWithIdpRequest {\n    const request: SignInWithIdpRequest = {\n      requestUri: this.params.requestUri,\n      sessionId: this.params.sessionId,\n      postBody: this.params.postBody,\n      tenantId: this.params.tenantId,\n      pendingToken: this.params.pendingToken,\n      returnSecureToken: true,\n      returnIdpCredential: true\n    };\n\n    if (idToken) {\n      request.idToken = idToken;\n    }\n\n    return request;\n  }\n}\n\nexport function _signIn(\n  params: IdpTaskParams\n): Promise<UserCredentialInternal> {\n  return _signInWithCredential(\n    params.auth,\n    new IdpCredential(params),\n    params.bypassAuthState\n  ) as Promise<UserCredentialInternal>;\n}\n\nexport function _reauth(\n  params: IdpTaskParams\n): Promise<UserCredentialInternal> {\n  const { auth, user } = params;\n  _assert(user, auth, AuthErrorCode.INTERNAL_ERROR);\n  return _reauthenticate(\n    user,\n    new IdpCredential(params),\n    params.bypassAuthState\n  );\n}\n\nexport async function _link(\n  params: IdpTaskParams\n): Promise<UserCredentialInternal> {\n  const { auth, user } = params;\n  _assert(user, auth, AuthErrorCode.INTERNAL_ERROR);\n  return _linkUser(user, new IdpCredential(params), params.bypassAuthState);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FirebaseError } from '@firebase/util';\n\nimport {\n  AuthEvent,\n  AuthEventConsumer,\n  AuthEventType,\n  EventManager,\n  PopupRedirectResolverInternal\n} from '../../model/popup_redirect';\nimport { UserInternal, UserCredentialInternal } from '../../model/user';\nimport { AuthErrorCode } from '../errors';\nimport { debugAssert, _fail } from '../util/assert';\nimport {\n  _link,\n  _reauth,\n  _signIn,\n  IdpTask,\n  IdpTaskParams\n} from '../strategies/idp';\nimport { AuthInternal } from '../../model/auth';\n\ninterface PendingPromise {\n  resolve: (cred: UserCredentialInternal | null) => void;\n  reject: (error: Error) => void;\n}\n\n/**\n * Popup event manager. Handles the popup's entire lifecycle; listens to auth\n * events\n */\nexport abstract class AbstractPopupRedirectOperation\n  implements AuthEventConsumer\n{\n  private pendingPromise: PendingPromise | null = null;\n  private eventManager: EventManager | null = null;\n  readonly filter: AuthEventType[];\n\n  abstract eventId: string | null;\n\n  constructor(\n    protected readonly auth: AuthInternal,\n    filter: AuthEventType | AuthEventType[],\n    protected readonly resolver: PopupRedirectResolverInternal,\n    protected user?: UserInternal,\n    protected readonly bypassAuthState = false\n  ) {\n    this.filter = Array.isArray(filter) ? filter : [filter];\n  }\n\n  abstract onExecution(): Promise<void>;\n\n  execute(): Promise<UserCredentialInternal | null> {\n    return new Promise<UserCredentialInternal | null>(\n      async (resolve, reject) => {\n        this.pendingPromise = { resolve, reject };\n\n        try {\n          this.eventManager = await this.resolver._initialize(this.auth);\n          await this.onExecution();\n          this.eventManager.registerConsumer(this);\n        } catch (e) {\n          this.reject(e as Error);\n        }\n      }\n    );\n  }\n\n  async onAuthEvent(event: AuthEvent): Promise<void> {\n    const { urlResponse, sessionId, postBody, tenantId, error, type } = event;\n    if (error) {\n      this.reject(error);\n      return;\n    }\n\n    const params: IdpTaskParams = {\n      auth: this.auth,\n      requestUri: urlResponse!,\n      sessionId: sessionId!,\n      tenantId: tenantId || undefined,\n      postBody: postBody || undefined,\n      user: this.user,\n      bypassAuthState: this.bypassAuthState\n    };\n\n    try {\n      this.resolve(await this.getIdpTask(type)(params));\n    } catch (e) {\n      this.reject(e as Error);\n    }\n  }\n\n  onError(error: FirebaseError): void {\n    this.reject(error);\n  }\n\n  private getIdpTask(type: AuthEventType): IdpTask {\n    switch (type) {\n      case AuthEventType.SIGN_IN_VIA_POPUP:\n      case AuthEventType.SIGN_IN_VIA_REDIRECT:\n        return _signIn;\n      case AuthEventType.LINK_VIA_POPUP:\n      case AuthEventType.LINK_VIA_REDIRECT:\n        return _link;\n      case AuthEventType.REAUTH_VIA_POPUP:\n      case AuthEventType.REAUTH_VIA_REDIRECT:\n        return _reauth;\n      default:\n        _fail(this.auth, AuthErrorCode.INTERNAL_ERROR);\n    }\n  }\n\n  protected resolve(cred: UserCredentialInternal | null): void {\n    debugAssert(this.pendingPromise, 'Pending promise was never set');\n    this.pendingPromise.resolve(cred);\n    this.unregisterAndCleanUp();\n  }\n\n  protected reject(error: Error): void {\n    debugAssert(this.pendingPromise, 'Pending promise was never set');\n    this.pendingPromise.reject(error);\n    this.unregisterAndCleanUp();\n  }\n\n  private unregisterAndCleanUp(): void {\n    if (this.eventManager) {\n      this.eventManager.unregisterConsumer(this);\n    }\n\n    this.pendingPromise = null;\n    this.cleanUp();\n  }\n\n  abstract cleanUp(): void;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Auth,\n  AuthProvider,\n  PopupRedirectResolver,\n  User,\n  UserCredential\n} from '../../model/public_types';\n\nimport { _castAuth } from '../../core/auth/auth_impl';\nimport { AuthErrorCode } from '../../core/errors';\nimport {\n  _assert,\n  debugAssert,\n  _createError,\n  _assertInstanceOf\n} from '../../core/util/assert';\nimport { Delay } from '../../core/util/delay';\nimport { _generateEventId } from '../../core/util/event_id';\nimport { AuthInternal } from '../../model/auth';\nimport {\n  AuthEventType,\n  PopupRedirectResolverInternal\n} from '../../model/popup_redirect';\nimport { UserInternal } from '../../model/user';\nimport { _withDefaultResolver } from '../../core/util/resolver';\nimport { AuthPopup } from '../util/popup';\nimport { AbstractPopupRedirectOperation } from '../../core/strategies/abstract_popup_redirect_operation';\nimport { FederatedAuthProvider } from '../../core/providers/federated';\nimport { getModularInstance } from '@firebase/util';\nimport { _isFirebaseServerApp } from '@firebase/app';\n\n/*\n * The event timeout is the same on mobile and desktop, no need for Delay. Set this to 8s since\n * blocking functions can take upto 7s to complete sign in, as documented in:\n * https://cloud.google.com/identity-platform/docs/blocking-functions#understanding_blocking_functions\n * https://firebase.google.com/docs/auth/extend-with-blocking-functions#understanding_blocking_functions\n */\nexport const enum _Timeout {\n  AUTH_EVENT = 8000\n}\nexport const _POLL_WINDOW_CLOSE_TIMEOUT = new Delay(2000, 10000);\n\n/**\n * Authenticates a Firebase client using a popup-based OAuth authentication flow.\n *\n * @remarks\n * If succeeds, returns the signed in user along with the provider's credential. If sign in was\n * unsuccessful, returns an error object containing additional information about the error.\n *\n * This method does not work in a Node.js environment or with {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```javascript\n * // Sign in using a popup.\n * const provider = new FacebookAuthProvider();\n * const result = await signInWithPopup(auth, provider);\n *\n * // The signed-in user info.\n * const user = result.user;\n * // This gives you a Facebook Access Token.\n * const credential = provider.credentialFromResult(auth, result);\n * const token = credential.accessToken;\n * ```\n *\n * @param auth - The {@link Auth} instance.\n * @param provider - The provider to authenticate. The provider has to be an {@link OAuthProvider}.\n * Non-OAuth providers like {@link EmailAuthProvider} will throw an error.\n * @param resolver - An instance of {@link PopupRedirectResolver}, optional\n * if already supplied to {@link initializeAuth} or provided by {@link getAuth}.\n *\n * @public\n */\nexport async function signInWithPopup(\n  auth: Auth,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<UserCredential> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _createError(auth, AuthErrorCode.OPERATION_NOT_SUPPORTED)\n    );\n  }\n  const authInternal = _castAuth(auth);\n  _assertInstanceOf(auth, provider, FederatedAuthProvider);\n  const resolverInternal = _withDefaultResolver(authInternal, resolver);\n  const action = new PopupOperation(\n    authInternal,\n    AuthEventType.SIGN_IN_VIA_POPUP,\n    provider,\n    resolverInternal\n  );\n  return action.executeNotNull();\n}\n\n/**\n * Reauthenticates the current user with the specified {@link OAuthProvider} using a pop-up based\n * OAuth flow.\n *\n * @remarks\n * If the reauthentication is successful, the returned result will contain the user and the\n * provider's credential.\n *\n * This method does not work in a Node.js environment or on any {@link User} signed in by\n * {@link Auth} instances created with a {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```javascript\n * // Sign in using a popup.\n * const provider = new FacebookAuthProvider();\n * const result = await signInWithPopup(auth, provider);\n * // Reauthenticate using a popup.\n * await reauthenticateWithPopup(result.user, provider);\n * ```\n *\n * @param user - The user.\n * @param provider - The provider to authenticate. The provider has to be an {@link OAuthProvider}.\n * Non-OAuth providers like {@link EmailAuthProvider} will throw an error.\n * @param resolver - An instance of {@link PopupRedirectResolver}, optional\n * if already supplied to {@link initializeAuth} or provided by {@link getAuth}.\n *\n * @public\n */\nexport async function reauthenticateWithPopup(\n  user: User,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<UserCredential> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  if (_isFirebaseServerApp(userInternal.auth.app)) {\n    return Promise.reject(\n      _createError(userInternal.auth, AuthErrorCode.OPERATION_NOT_SUPPORTED)\n    );\n  }\n  _assertInstanceOf(userInternal.auth, provider, FederatedAuthProvider);\n  const resolverInternal = _withDefaultResolver(userInternal.auth, resolver);\n  const action = new PopupOperation(\n    userInternal.auth,\n    AuthEventType.REAUTH_VIA_POPUP,\n    provider,\n    resolverInternal,\n    userInternal\n  );\n  return action.executeNotNull();\n}\n\n/**\n * Links the authenticated provider to the user account using a pop-up based OAuth flow.\n *\n * @remarks\n * If the linking is successful, the returned result will contain the user and the provider's credential.\n *\n * This method does not work in a Node.js environment.\n *\n * @example\n * ```javascript\n * // Sign in using some other provider.\n * const result = await signInWithEmailAndPassword(auth, email, password);\n * // Link using a popup.\n * const provider = new FacebookAuthProvider();\n * await linkWithPopup(result.user, provider);\n * ```\n *\n * @param user - The user.\n * @param provider - The provider to authenticate. The provider has to be an {@link OAuthProvider}.\n * Non-OAuth providers like {@link EmailAuthProvider} will throw an error.\n * @param resolver - An instance of {@link PopupRedirectResolver}, optional\n * if already supplied to {@link initializeAuth} or provided by {@link getAuth}.\n *\n * @public\n */\nexport async function linkWithPopup(\n  user: User,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<UserCredential> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  _assertInstanceOf(userInternal.auth, provider, FederatedAuthProvider);\n  const resolverInternal = _withDefaultResolver(userInternal.auth, resolver);\n\n  const action = new PopupOperation(\n    userInternal.auth,\n    AuthEventType.LINK_VIA_POPUP,\n    provider,\n    resolverInternal,\n    userInternal\n  );\n  return action.executeNotNull();\n}\n\n/**\n * Popup event manager. Handles the popup's entire lifecycle; listens to auth\n * events\n *\n */\nclass PopupOperation extends AbstractPopupRedirectOperation {\n  // Only one popup is ever shown at once. The lifecycle of the current popup\n  // can be managed / cancelled by the constructor.\n  private static currentPopupAction: PopupOperation | null = null;\n  private authWindow: AuthPopup | null = null;\n  private pollId: number | null = null;\n\n  constructor(\n    auth: AuthInternal,\n    filter: AuthEventType,\n    private readonly provider: AuthProvider,\n    resolver: PopupRedirectResolverInternal,\n    user?: UserInternal\n  ) {\n    super(auth, filter, resolver, user);\n    if (PopupOperation.currentPopupAction) {\n      PopupOperation.currentPopupAction.cancel();\n    }\n\n    PopupOperation.currentPopupAction = this;\n  }\n\n  async executeNotNull(): Promise<UserCredential> {\n    const result = await this.execute();\n    _assert(result, this.auth, AuthErrorCode.INTERNAL_ERROR);\n    return result;\n  }\n\n  async onExecution(): Promise<void> {\n    debugAssert(\n      this.filter.length === 1,\n      'Popup operations only handle one event'\n    );\n    const eventId = _generateEventId();\n    this.authWindow = await this.resolver._openPopup(\n      this.auth,\n      this.provider,\n      this.filter[0], // There's always one, see constructor\n      eventId\n    );\n    this.authWindow.associatedEvent = eventId;\n\n    // Check for web storage support and origin validation _after_ the popup is\n    // loaded. These operations are slow (~1 second or so) Rather than\n    // waiting on them before opening the window, optimistically open the popup\n    // and check for storage support at the same time. If storage support is\n    // not available, this will cause the whole thing to reject properly. It\n    // will also close the popup, but since the promise has already rejected,\n    // the popup closed by user poll will reject into the void.\n    this.resolver._originValidation(this.auth).catch(e => {\n      this.reject(e);\n    });\n\n    this.resolver._isIframeWebStorageSupported(this.auth, isSupported => {\n      if (!isSupported) {\n        this.reject(\n          _createError(this.auth, AuthErrorCode.WEB_STORAGE_UNSUPPORTED)\n        );\n      }\n    });\n\n    // Handle user closure. Notice this does *not* use await\n    this.pollUserCancellation();\n  }\n\n  get eventId(): string | null {\n    return this.authWindow?.associatedEvent || null;\n  }\n\n  cancel(): void {\n    this.reject(_createError(this.auth, AuthErrorCode.EXPIRED_POPUP_REQUEST));\n  }\n\n  cleanUp(): void {\n    if (this.authWindow) {\n      this.authWindow.close();\n    }\n\n    if (this.pollId) {\n      window.clearTimeout(this.pollId);\n    }\n\n    this.authWindow = null;\n    this.pollId = null;\n    PopupOperation.currentPopupAction = null;\n  }\n\n  private pollUserCancellation(): void {\n    const poll = (): void => {\n      if (this.authWindow?.window?.closed) {\n        // Make sure that there is sufficient time for whatever action to\n        // complete. The window could have closed but the sign in network\n        // call could still be in flight. This is specifically true for\n        // Firefox or if the opener is in an iframe, in which case the oauth\n        // helper closes the popup.\n        this.pollId = window.setTimeout(() => {\n          this.pollId = null;\n          this.reject(\n            _createError(this.auth, AuthErrorCode.POPUP_CLOSED_BY_USER)\n          );\n        }, _Timeout.AUTH_EVENT);\n        return;\n      }\n\n      this.pollId = window.setTimeout(poll, _POLL_WINDOW_CLOSE_TIMEOUT.get());\n    };\n\n    poll();\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthInternal } from '../../model/auth';\nimport {\n  AuthEvent,\n  AuthEventType,\n  PopupRedirectResolverInternal\n} from '../../model/popup_redirect';\nimport { UserCredentialInternal } from '../../model/user';\nimport { PersistenceInternal } from '../persistence';\nimport { _persistenceKeyName } from '../persistence/persistence_user_manager';\nimport { _getInstance } from '../util/instantiator';\nimport { AbstractPopupRedirectOperation } from './abstract_popup_redirect_operation';\n\nconst PENDING_REDIRECT_KEY = 'pendingRedirect';\n\n// We only get one redirect outcome for any one auth, so just store it\n// in here.\nconst redirectOutcomeMap: Map<\n  string,\n  () => Promise<UserCredentialInternal | null>\n> = new Map();\n\nexport class RedirectAction extends AbstractPopupRedirectOperation {\n  eventId = null;\n\n  constructor(\n    auth: AuthInternal,\n    resolver: PopupRedirectResolverInternal,\n    bypassAuthState = false\n  ) {\n    super(\n      auth,\n      [\n        AuthEventType.SIGN_IN_VIA_REDIRECT,\n        AuthEventType.LINK_VIA_REDIRECT,\n        AuthEventType.REAUTH_VIA_REDIRECT,\n        AuthEventType.UNKNOWN\n      ],\n      resolver,\n      undefined,\n      bypassAuthState\n    );\n  }\n\n  /**\n   * Override the execute function; if we already have a redirect result, then\n   * just return it.\n   */\n  async execute(): Promise<UserCredentialInternal | null> {\n    let readyOutcome = redirectOutcomeMap.get(this.auth._key());\n    if (!readyOutcome) {\n      try {\n        const hasPendingRedirect = await _getAndClearPendingRedirectStatus(\n          this.resolver,\n          this.auth\n        );\n        const result = hasPendingRedirect ? await super.execute() : null;\n        readyOutcome = () => Promise.resolve(result);\n      } catch (e) {\n        readyOutcome = () => Promise.reject(e);\n      }\n\n      redirectOutcomeMap.set(this.auth._key(), readyOutcome);\n    }\n\n    // If we're not bypassing auth state, the ready outcome should be set to\n    // null.\n    if (!this.bypassAuthState) {\n      redirectOutcomeMap.set(this.auth._key(), () => Promise.resolve(null));\n    }\n\n    return readyOutcome();\n  }\n\n  async onAuthEvent(event: AuthEvent): Promise<void> {\n    if (event.type === AuthEventType.SIGN_IN_VIA_REDIRECT) {\n      return super.onAuthEvent(event);\n    } else if (event.type === AuthEventType.UNKNOWN) {\n      // This is a sentinel value indicating there's no pending redirect\n      this.resolve(null);\n      return;\n    }\n\n    if (event.eventId) {\n      const user = await this.auth._redirectUserForId(event.eventId);\n      if (user) {\n        this.user = user;\n        return super.onAuthEvent(event);\n      } else {\n        this.resolve(null);\n      }\n    }\n  }\n\n  async onExecution(): Promise<void> {}\n\n  cleanUp(): void {}\n}\n\nexport async function _getAndClearPendingRedirectStatus(\n  resolver: PopupRedirectResolverInternal,\n  auth: AuthInternal\n): Promise<boolean> {\n  const key = pendingRedirectKey(auth);\n  const persistence = resolverPersistence(resolver);\n  if (!(await persistence._isAvailable())) {\n    return false;\n  }\n  const hasPendingRedirect = (await persistence._get(key)) === 'true';\n  await persistence._remove(key);\n  return hasPendingRedirect;\n}\n\nexport async function _setPendingRedirectStatus(\n  resolver: PopupRedirectResolverInternal,\n  auth: AuthInternal\n): Promise<void> {\n  return resolverPersistence(resolver)._set(pendingRedirectKey(auth), 'true');\n}\n\nexport function _clearRedirectOutcomes(): void {\n  redirectOutcomeMap.clear();\n}\n\nexport function _overrideRedirectResult(\n  auth: AuthInternal,\n  result: () => Promise<UserCredentialInternal | null>\n): void {\n  redirectOutcomeMap.set(auth._key(), result);\n}\n\nfunction resolverPersistence(\n  resolver: PopupRedirectResolverInternal\n): PersistenceInternal {\n  return _getInstance(resolver._redirectPersistence);\n}\n\nfunction pendingRedirectKey(auth: AuthInternal): string {\n  return _persistenceKeyName(\n    PENDING_REDIRECT_KEY,\n    auth.config.apiKey,\n    auth.name\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  Auth,\n  AuthProvider,\n  PopupRedirectResolver,\n  User,\n  UserCredential\n} from '../../model/public_types';\n\nimport { _castAuth } from '../../core/auth/auth_impl';\nimport { _assertLinkedStatus } from '../../core/user/link_unlink';\nimport {\n  _assertInstanceOf,\n  _serverAppCurrentUserOperationNotSupportedError\n} from '../../core/util/assert';\nimport { _generateEventId } from '../../core/util/event_id';\nimport { AuthEventType } from '../../model/popup_redirect';\nimport { UserInternal } from '../../model/user';\nimport { _withDefaultResolver } from '../../core/util/resolver';\nimport {\n  RedirectAction,\n  _setPendingRedirectStatus\n} from '../../core/strategies/redirect';\nimport { FederatedAuthProvider } from '../../core/providers/federated';\nimport { getModularInstance } from '@firebase/util';\nimport { _isFirebaseServerApp } from '@firebase/app';\n\n/**\n * Authenticates a Firebase client using a full-page redirect flow.\n *\n * @remarks\n * To handle the results and errors for this operation, refer to {@link getRedirectResult}.\n * Follow the {@link https://firebase.google.com/docs/auth/web/redirect-best-practices\n * | best practices} when using {@link signInWithRedirect}.\n *\n * This method does not work in a Node.js environment or with {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new FacebookAuthProvider();\n * // You can add additional scopes to the provider:\n * provider.addScope('user_birthday');\n * // Start a sign in process for an unauthenticated user.\n * await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * if (result) {\n *   // This is the signed-in user\n *   const user = result.user;\n *   // This gives you a Facebook Access Token.\n *   const credential = provider.credentialFromResult(auth, result);\n *   const token = credential.accessToken;\n * }\n * // As this API can be used for sign-in, linking and reauthentication,\n * // check the operationType to determine what triggered this redirect\n * // operation.\n * const operationType = result.operationType;\n * ```\n *\n * @param auth - The {@link Auth} instance.\n * @param provider - The provider to authenticate. The provider has to be an {@link OAuthProvider}.\n * Non-OAuth providers like {@link EmailAuthProvider} will throw an error.\n * @param resolver - An instance of {@link PopupRedirectResolver}, optional\n * if already supplied to {@link initializeAuth} or provided by {@link getAuth}.\n *\n * @public\n */\nexport function signInWithRedirect(\n  auth: Auth,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<never> {\n  return _signInWithRedirect(auth, provider, resolver) as Promise<never>;\n}\n\nexport async function _signInWithRedirect(\n  auth: Auth,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<void | never> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const authInternal = _castAuth(auth);\n  _assertInstanceOf(auth, provider, FederatedAuthProvider);\n  // Wait for auth initialization to complete, this will process pending redirects and clear the\n  // PENDING_REDIRECT_KEY in persistence. This should be completed before starting a new\n  // redirect and creating a PENDING_REDIRECT_KEY entry.\n  await authInternal._initializationPromise;\n  const resolverInternal = _withDefaultResolver(authInternal, resolver);\n  await _setPendingRedirectStatus(resolverInternal, authInternal);\n\n  return resolverInternal._openRedirect(\n    authInternal,\n    provider,\n    AuthEventType.SIGN_IN_VIA_REDIRECT\n  );\n}\n\n/**\n * Reauthenticates the current user with the specified {@link OAuthProvider} using a full-page redirect flow.\n * @remarks\n * To handle the results and errors for this operation, refer to {@link getRedirectResult}.\n * Follow the {@link https://firebase.google.com/docs/auth/web/redirect-best-practices\n * | best practices} when using {@link reauthenticateWithRedirect}.\n *\n * This method does not work in a Node.js environment or with {@link Auth} instances\n * created with a {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new FacebookAuthProvider();\n * const result = await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * // Reauthenticate using a redirect.\n * await reauthenticateWithRedirect(result.user, provider);\n * // This will again trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * ```\n *\n * @param user - The user.\n * @param provider - The provider to authenticate. The provider has to be an {@link OAuthProvider}.\n * Non-OAuth providers like {@link EmailAuthProvider} will throw an error.\n * @param resolver - An instance of {@link PopupRedirectResolver}, optional\n * if already supplied to {@link initializeAuth} or provided by {@link getAuth}.\n *\n * @public\n */\nexport function reauthenticateWithRedirect(\n  user: User,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<never> {\n  return _reauthenticateWithRedirect(\n    user,\n    provider,\n    resolver\n  ) as Promise<never>;\n}\nexport async function _reauthenticateWithRedirect(\n  user: User,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<void | never> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  _assertInstanceOf(userInternal.auth, provider, FederatedAuthProvider);\n  if (_isFirebaseServerApp(userInternal.auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(userInternal.auth)\n    );\n  }\n  // Wait for auth initialization to complete, this will process pending redirects and clear the\n  // PENDING_REDIRECT_KEY in persistence. This should be completed before starting a new\n  // redirect and creating a PENDING_REDIRECT_KEY entry.\n  await userInternal.auth._initializationPromise;\n  // Allow the resolver to error before persisting the redirect user\n  const resolverInternal = _withDefaultResolver(userInternal.auth, resolver);\n  await _setPendingRedirectStatus(resolverInternal, userInternal.auth);\n\n  const eventId = await prepareUserForRedirect(userInternal);\n  return resolverInternal._openRedirect(\n    userInternal.auth,\n    provider,\n    AuthEventType.REAUTH_VIA_REDIRECT,\n    eventId\n  );\n}\n\n/**\n * Links the {@link OAuthProvider} to the user account using a full-page redirect flow.\n * @remarks\n * To handle the results and errors for this operation, refer to {@link getRedirectResult}.\n * Follow the {@link https://firebase.google.com/docs/auth/web/redirect-best-practices\n * | best practices} when using {@link linkWithRedirect}.\n *\n * This method does not work in a Node.js environment or with {@link Auth} instances\n * created with a {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```javascript\n * // Sign in using some other provider.\n * const result = await signInWithEmailAndPassword(auth, email, password);\n * // Link using a redirect.\n * const provider = new FacebookAuthProvider();\n * await linkWithRedirect(result.user, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * ```\n *\n * @param user - The user.\n * @param provider - The provider to authenticate. The provider has to be an {@link OAuthProvider}.\n * Non-OAuth providers like {@link EmailAuthProvider} will throw an error.\n * @param resolver - An instance of {@link PopupRedirectResolver}, optional\n * if already supplied to {@link initializeAuth} or provided by {@link getAuth}.\n *\n * @public\n */\nexport function linkWithRedirect(\n  user: User,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<never> {\n  return _linkWithRedirect(user, provider, resolver) as Promise<never>;\n}\nexport async function _linkWithRedirect(\n  user: User,\n  provider: AuthProvider,\n  resolver?: PopupRedirectResolver\n): Promise<void | never> {\n  const userInternal = getModularInstance(user) as UserInternal;\n  _assertInstanceOf(userInternal.auth, provider, FederatedAuthProvider);\n  // Wait for auth initialization to complete, this will process pending redirects and clear the\n  // PENDING_REDIRECT_KEY in persistence. This should be completed before starting a new\n  // redirect and creating a PENDING_REDIRECT_KEY entry.\n  await userInternal.auth._initializationPromise;\n  // Allow the resolver to error before persisting the redirect user\n  const resolverInternal = _withDefaultResolver(userInternal.auth, resolver);\n  await _assertLinkedStatus(false, userInternal, provider.providerId);\n  await _setPendingRedirectStatus(resolverInternal, userInternal.auth);\n\n  const eventId = await prepareUserForRedirect(userInternal);\n  return resolverInternal._openRedirect(\n    userInternal.auth,\n    provider,\n    AuthEventType.LINK_VIA_REDIRECT,\n    eventId\n  );\n}\n\n/**\n * Returns a {@link UserCredential} from the redirect-based sign-in flow.\n *\n * @remarks\n * If sign-in succeeded, returns the signed in user. If sign-in was unsuccessful, fails with an\n * error. If no redirect operation was called, returns `null`.\n *\n * This method does not work in a Node.js environment or with {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * @example\n * ```javascript\n * // Sign in using a redirect.\n * const provider = new FacebookAuthProvider();\n * // You can add additional scopes to the provider:\n * provider.addScope('user_birthday');\n * // Start a sign in process for an unauthenticated user.\n * await signInWithRedirect(auth, provider);\n * // This will trigger a full page redirect away from your app\n *\n * // After returning from the redirect when your app initializes you can obtain the result\n * const result = await getRedirectResult(auth);\n * if (result) {\n *   // This is the signed-in user\n *   const user = result.user;\n *   // This gives you a Facebook Access Token.\n *   const credential = provider.credentialFromResult(auth, result);\n *   const token = credential.accessToken;\n * }\n * // As this API can be used for sign-in, linking and reauthentication,\n * // check the operationType to determine what triggered this redirect\n * // operation.\n * const operationType = result.operationType;\n * ```\n *\n * @param auth - The {@link Auth} instance.\n * @param resolver - An instance of {@link PopupRedirectResolver}, optional\n * if already supplied to {@link initializeAuth} or provided by {@link getAuth}.\n *\n * @public\n */\nexport async function getRedirectResult(\n  auth: Auth,\n  resolver?: PopupRedirectResolver\n): Promise<UserCredential | null> {\n  await _castAuth(auth)._initializationPromise;\n  return _getRedirectResult(auth, resolver, false);\n}\n\nexport async function _getRedirectResult(\n  auth: Auth,\n  resolverExtern?: PopupRedirectResolver,\n  bypassAuthState = false\n): Promise<UserCredential | null> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const authInternal = _castAuth(auth);\n  const resolver = _withDefaultResolver(authInternal, resolverExtern);\n  const action = new RedirectAction(authInternal, resolver, bypassAuthState);\n  const result = await action.execute();\n\n  if (result && !bypassAuthState) {\n    delete result.user._redirectEventId;\n    await authInternal._persistUserIfCurrent(result.user as UserInternal);\n    await authInternal._setRedirectUser(null, resolverExtern);\n  }\n\n  return result;\n}\n\nasync function prepareUserForRedirect(user: UserInternal): Promise<string> {\n  const eventId = _generateEventId(`${user.uid}:::`);\n  user._redirectEventId = eventId;\n  await user.auth._setRedirectUser(user);\n  await user.auth._persistUserIfCurrent(user);\n  return eventId;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  AuthEvent,\n  AuthEventConsumer,\n  AuthEventType,\n  EventManager\n} from '../../model/popup_redirect';\nimport { AuthErrorCode } from '../errors';\nimport { AuthInternal } from '../../model/auth';\nimport { _createError } from '../util/assert';\n\n// The amount of time to store the UIDs of seen events; this is\n// set to 10 min by default\nconst EVENT_DUPLICATION_CACHE_DURATION_MS = 10 * 60 * 1000;\n\nexport class AuthEventManager implements EventManager {\n  private readonly cachedEventUids: Set<string> = new Set();\n  private readonly consumers: Set<AuthEventConsumer> = new Set();\n  protected queuedRedirectEvent: AuthEvent | null = null;\n  protected hasHandledPotentialRedirect = false;\n  private lastProcessedEventTime = Date.now();\n\n  constructor(private readonly auth: AuthInternal) {}\n\n  registerConsumer(authEventConsumer: AuthEventConsumer): void {\n    this.consumers.add(authEventConsumer);\n\n    if (\n      this.queuedRedirectEvent &&\n      this.isEventForConsumer(this.queuedRedirectEvent, authEventConsumer)\n    ) {\n      this.sendToConsumer(this.queuedRedirectEvent, authEventConsumer);\n      this.saveEventToCache(this.queuedRedirectEvent);\n      this.queuedRedirectEvent = null;\n    }\n  }\n\n  unregisterConsumer(authEventConsumer: AuthEventConsumer): void {\n    this.consumers.delete(authEventConsumer);\n  }\n\n  onEvent(event: AuthEvent): boolean {\n    // Check if the event has already been handled\n    if (this.hasEventBeenHandled(event)) {\n      return false;\n    }\n\n    let handled = false;\n    this.consumers.forEach(consumer => {\n      if (this.isEventForConsumer(event, consumer)) {\n        handled = true;\n        this.sendToConsumer(event, consumer);\n        this.saveEventToCache(event);\n      }\n    });\n\n    if (this.hasHandledPotentialRedirect || !isRedirectEvent(event)) {\n      // If we've already seen a redirect before, or this is a popup event,\n      // bail now\n      return handled;\n    }\n\n    this.hasHandledPotentialRedirect = true;\n\n    // If the redirect wasn't handled, hang on to it\n    if (!handled) {\n      this.queuedRedirectEvent = event;\n      handled = true;\n    }\n\n    return handled;\n  }\n\n  private sendToConsumer(event: AuthEvent, consumer: AuthEventConsumer): void {\n    if (event.error && !isNullRedirectEvent(event)) {\n      const code =\n        (event.error.code?.split('auth/')[1] as AuthErrorCode) ||\n        AuthErrorCode.INTERNAL_ERROR;\n      consumer.onError(_createError(this.auth, code));\n    } else {\n      consumer.onAuthEvent(event);\n    }\n  }\n\n  private isEventForConsumer(\n    event: AuthEvent,\n    consumer: AuthEventConsumer\n  ): boolean {\n    const eventIdMatches =\n      consumer.eventId === null ||\n      (!!event.eventId && event.eventId === consumer.eventId);\n    return consumer.filter.includes(event.type) && eventIdMatches;\n  }\n\n  private hasEventBeenHandled(event: AuthEvent): boolean {\n    if (\n      Date.now() - this.lastProcessedEventTime >=\n      EVENT_DUPLICATION_CACHE_DURATION_MS\n    ) {\n      this.cachedEventUids.clear();\n    }\n\n    return this.cachedEventUids.has(eventUid(event));\n  }\n\n  private saveEventToCache(event: AuthEvent): void {\n    this.cachedEventUids.add(eventUid(event));\n    this.lastProcessedEventTime = Date.now();\n  }\n}\n\nfunction eventUid(e: AuthEvent): string {\n  return [e.type, e.eventId, e.sessionId, e.tenantId].filter(v => v).join('-');\n}\n\nfunction isNullRedirectEvent({ type, error }: AuthEvent): boolean {\n  return (\n    type === AuthEventType.UNKNOWN &&\n    error?.code === `auth/${AuthErrorCode.NO_AUTH_EVENT}`\n  );\n}\n\nfunction isRedirectEvent(event: AuthEvent): boolean {\n  switch (event.type) {\n    case AuthEventType.SIGN_IN_VIA_REDIRECT:\n    case AuthEventType.LINK_VIA_REDIRECT:\n    case AuthEventType.REAUTH_VIA_REDIRECT:\n      return true;\n    case AuthEventType.UNKNOWN:\n      return isNullRedirectEvent(event);\n    default:\n      return false;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { _performApiRequest, Endpoint, HttpMethod } from '../index';\nimport { Auth } from '../../model/public_types';\n\nexport interface GetProjectConfigRequest {\n  androidPackageName?: string;\n  iosBundleId?: string;\n}\n\nexport interface GetProjectConfigResponse {\n  authorizedDomains: string[];\n}\n\nexport async function _getProjectConfig(\n  auth: Auth,\n  request: GetProjectConfigRequest = {}\n): Promise<GetProjectConfigResponse> {\n  return _performApiRequest<GetProjectConfigRequest, GetProjectConfigResponse>(\n    auth,\n    HttpMethod.GET,\n    Endpoint.GET_PROJECT_CONFIG,\n    request\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { _getProjectConfig } from '../../api/project_config/get_project_config';\nimport { AuthInternal } from '../../model/auth';\nimport { AuthErrorCode } from '../errors';\nimport { _fail } from './assert';\nimport { _getCurrentUrl } from './location';\n\nconst IP_ADDRESS_REGEX = /^\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}$/;\nconst HTTP_REGEX = /^https?/;\n\nexport async function _validateOrigin(auth: AuthInternal): Promise<void> {\n  // Skip origin validation if we are in an emulated environment\n  if (auth.config.emulator) {\n    return;\n  }\n\n  const { authorizedDomains } = await _getProjectConfig(auth);\n\n  for (const domain of authorizedDomains) {\n    try {\n      if (matchDomain(domain)) {\n        return;\n      }\n    } catch {\n      // Do nothing if there's a URL error; just continue searching\n    }\n  }\n\n  // In the old SDK, this error also provides helpful messages.\n  _fail(auth, AuthErrorCode.INVALID_ORIGIN);\n}\n\nfunction matchDomain(expected: string): boolean {\n  const currentUrl = _getCurrentUrl();\n  const { protocol, hostname } = new URL(currentUrl);\n  if (expected.startsWith('chrome-extension://')) {\n    const ceUrl = new URL(expected);\n\n    if (ceUrl.hostname === '' && hostname === '') {\n      // For some reason we're not parsing chrome URLs properly\n      return (\n        protocol === 'chrome-extension:' &&\n        expected.replace('chrome-extension://', '') ===\n          currentUrl.replace('chrome-extension://', '')\n      );\n    }\n\n    return protocol === 'chrome-extension:' && ceUrl.hostname === hostname;\n  }\n\n  if (!HTTP_REGEX.test(protocol)) {\n    return false;\n  }\n\n  if (IP_ADDRESS_REGEX.test(expected)) {\n    // The domain has to be exactly equal to the pattern, as an IP domain will\n    // only contain the IP, no extra character.\n    return hostname === expected;\n  }\n\n  // Dots in pattern should be escaped.\n  const escapedDomainPattern = expected.replace(/\\./g, '\\\\.');\n  // Non ip address domains.\n  // domain.com = *.domain.com OR domain.com\n  const re = new RegExp(\n    '^(.+\\\\.' + escapedDomainPattern + '|' + escapedDomainPattern + ')$',\n    'i'\n  );\n  return re.test(hostname);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC.\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthErrorCode } from '../../core/errors';\nimport { _createError } from '../../core/util/assert';\nimport { Delay } from '../../core/util/delay';\nimport { AuthInternal } from '../../model/auth';\nimport { _window } from '../auth_window';\nimport * as js from '../load_js';\n\nconst NETWORK_TIMEOUT = new Delay(30000, 60000);\n\n/**\n * Reset unloaded GApi modules. If gapi.load fails due to a network error,\n * it will stop working after a retrial. This is a hack to fix this issue.\n */\nfunction resetUnloadedGapiModules(): void {\n  // Clear last failed gapi.load state to force next gapi.load to first\n  // load the failed gapi.iframes module.\n  // Get gapix.beacon context.\n  const beacon = _window().___jsl;\n  // Get current hint.\n  if (beacon?.H) {\n    // Get gapi hint.\n    for (const hint of Object.keys(beacon.H)) {\n      // Requested modules.\n      beacon.H[hint].r = beacon.H[hint].r || [];\n      // Loaded modules.\n      beacon.H[hint].L = beacon.H[hint].L || [];\n      // Set requested modules to a copy of the loaded modules.\n      beacon.H[hint].r = [...beacon.H[hint].L];\n      // Clear pending callbacks.\n      if (beacon.CP) {\n        for (let i = 0; i < beacon.CP.length; i++) {\n          // Remove all failed pending callbacks.\n          beacon.CP[i] = null;\n        }\n      }\n    }\n  }\n}\n\nfunction loadGapi(auth: AuthInternal): Promise<gapi.iframes.Context> {\n  return new Promise<gapi.iframes.Context>((resolve, reject) => {\n    // Function to run when gapi.load is ready.\n    function loadGapiIframe(): void {\n      // The developer may have tried to previously run gapi.load and failed.\n      // Run this to fix that.\n      resetUnloadedGapiModules();\n      gapi.load('gapi.iframes', {\n        callback: () => {\n          resolve(gapi.iframes.getContext());\n        },\n        ontimeout: () => {\n          // The above reset may be sufficient, but having this reset after\n          // failure ensures that if the developer calls gapi.load after the\n          // connection is re-established and before another attempt to embed\n          // the iframe, it would work and would not be broken because of our\n          // failed attempt.\n          // Timeout when gapi.iframes.Iframe not loaded.\n          resetUnloadedGapiModules();\n          reject(_createError(auth, AuthErrorCode.NETWORK_REQUEST_FAILED));\n        },\n        timeout: NETWORK_TIMEOUT.get()\n      });\n    }\n\n    if (_window().gapi?.iframes?.Iframe) {\n      // If gapi.iframes.Iframe available, resolve.\n      resolve(gapi.iframes.getContext());\n    } else if (!!_window().gapi?.load) {\n      // Gapi loader ready, load gapi.iframes.\n      loadGapiIframe();\n    } else {\n      // Create a new iframe callback when this is called so as not to overwrite\n      // any previous defined callback. This happens if this method is called\n      // multiple times in parallel and could result in the later callback\n      // overwriting the previous one. This would end up with a iframe\n      // timeout.\n      const cbName = js._generateCallbackName('iframefcb');\n      // GApi loader not available, dynamically load platform.js.\n      _window()[cbName] = () => {\n        // GApi loader should be ready.\n        if (!!gapi.load) {\n          loadGapiIframe();\n        } else {\n          // Gapi loader failed, throw error.\n          reject(_createError(auth, AuthErrorCode.NETWORK_REQUEST_FAILED));\n        }\n      };\n      // Load GApi loader.\n      return js\n        ._loadJS(`${js._gapiScriptUrl()}?onload=${cbName}`)\n        .catch(e => reject(e));\n    }\n  }).catch(error => {\n    // Reset cached promise to allow for retrial.\n    cachedGApiLoader = null;\n    throw error;\n  });\n}\n\nlet cachedGApiLoader: Promise<gapi.iframes.Context> | null = null;\nexport function _loadGapi(auth: AuthInternal): Promise<gapi.iframes.Context> {\n  cachedGApiLoader = cachedGApiLoader || loadGapi(auth);\n  return cachedGApiLoader;\n}\n\nexport function _resetLoader(): void {\n  cachedGApiLoader = null;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC.\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { SDK_VERSION } from '@firebase/app';\nimport { querystring } from '@firebase/util';\nimport { DefaultConfig } from '../../../internal';\n\nimport { AuthErrorCode } from '../../core/errors';\nimport { _assert, _createError } from '../../core/util/assert';\nimport { Delay } from '../../core/util/delay';\nimport { _emulatorUrl } from '../../core/util/emulator';\nimport { AuthInternal } from '../../model/auth';\nimport { _window } from '../auth_window';\nimport * as gapiLoader from './gapi';\n\nconst PING_TIMEOUT = new Delay(5000, 15000);\nconst IFRAME_PATH = '__/auth/iframe';\nconst EMULATED_IFRAME_PATH = 'emulator/auth/iframe';\n\nconst IFRAME_ATTRIBUTES = {\n  style: {\n    position: 'absolute',\n    top: '-100px',\n    width: '1px',\n    height: '1px'\n  },\n  'aria-hidden': 'true',\n  tabindex: '-1'\n};\n\n// Map from apiHost to endpoint ID for passing into iframe. In current SDK, apiHost can be set to\n// anything (not from a list of endpoints with IDs as in legacy), so this is the closest we can get.\nconst EID_FROM_APIHOST = new Map([\n  [DefaultConfig.API_HOST, 'p'], // production\n  ['staging-identitytoolkit.sandbox.googleapis.com', 's'], // staging\n  ['test-identitytoolkit.sandbox.googleapis.com', 't'] // test\n]);\n\nfunction getIframeUrl(auth: AuthInternal): string {\n  const config = auth.config;\n  _assert(config.authDomain, auth, AuthErrorCode.MISSING_AUTH_DOMAIN);\n  const url = config.emulator\n    ? _emulatorUrl(config, EMULATED_IFRAME_PATH)\n    : `https://${auth.config.authDomain}/${IFRAME_PATH}`;\n\n  const params: Record<string, string> = {\n    apiKey: config.apiKey,\n    appName: auth.name,\n    v: SDK_VERSION\n  };\n  const eid = EID_FROM_APIHOST.get(auth.config.apiHost);\n  if (eid) {\n    params.eid = eid;\n  }\n  const frameworks = auth._getFrameworks();\n  if (frameworks.length) {\n    params.fw = frameworks.join(',');\n  }\n  return `${url}?${querystring(params).slice(1)}`;\n}\n\nexport async function _openIframe(\n  auth: AuthInternal\n): Promise<gapi.iframes.Iframe> {\n  const context = await gapiLoader._loadGapi(auth);\n  const gapi = _window().gapi;\n  _assert(gapi, auth, AuthErrorCode.INTERNAL_ERROR);\n  return context.open(\n    {\n      where: document.body,\n      url: getIframeUrl(auth),\n      messageHandlersFilter: gapi.iframes.CROSS_ORIGIN_IFRAMES_FILTER,\n      attributes: IFRAME_ATTRIBUTES,\n      dontclear: true\n    },\n    (iframe: gapi.iframes.Iframe) =>\n      new Promise(async (resolve, reject) => {\n        await iframe.restyle({\n          // Prevent iframe from closing on mouse out.\n          setHideOnLeave: false\n        });\n\n        const networkError = _createError(\n          auth,\n          AuthErrorCode.NETWORK_REQUEST_FAILED\n        );\n        // Confirm iframe is correctly loaded.\n        // To fallback on failure, set a timeout.\n        const networkErrorTimer = _window().setTimeout(() => {\n          reject(networkError);\n        }, PING_TIMEOUT.get());\n        // Clear timer and resolve pending iframe ready promise.\n        function clearTimerAndResolve(): void {\n          _window().clearTimeout(networkErrorTimer);\n          resolve(iframe);\n        }\n        // This returns an IThenable. However the reject part does not call\n        // when the iframe is not loaded.\n        iframe.ping(clearTimerAndResolve).then(clearTimerAndResolve, () => {\n          reject(networkError);\n        });\n      })\n  );\n}\n","/**\n * @license\n * Copyright 2020 Google LLC.\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { getUA } from '@firebase/util';\n\nimport { AuthErrorCode } from '../../core/errors';\nimport { _assert } from '../../core/util/assert';\nimport {\n  _isChromeIOS,\n  _isFirefox,\n  _isIOSStandalone\n} from '../../core/util/browser';\nimport { AuthInternal } from '../../model/auth';\n\nconst BASE_POPUP_OPTIONS = {\n  location: 'yes',\n  resizable: 'yes',\n  statusbar: 'yes',\n  toolbar: 'no'\n};\n\nconst DEFAULT_WIDTH = 500;\nconst DEFAULT_HEIGHT = 600;\nconst TARGET_BLANK = '_blank';\n\nconst FIREFOX_EMPTY_URL = 'http://localhost';\n\nexport class AuthPopup {\n  associatedEvent: string | null = null;\n\n  constructor(readonly window: Window | null) {}\n\n  close(): void {\n    if (this.window) {\n      try {\n        this.window.close();\n      } catch (e) {}\n    }\n  }\n}\n\nexport function _open(\n  auth: AuthInternal,\n  url?: string,\n  name?: string,\n  width = DEFAULT_WIDTH,\n  height = DEFAULT_HEIGHT\n): AuthPopup {\n  const top = Math.max((window.screen.availHeight - height) / 2, 0).toString();\n  const left = Math.max((window.screen.availWidth - width) / 2, 0).toString();\n  let target = '';\n\n  const options: { [key: string]: string } = {\n    ...BASE_POPUP_OPTIONS,\n    width: width.toString(),\n    height: height.toString(),\n    top,\n    left\n  };\n\n  // Chrome iOS 7 and 8 is returning an undefined popup win when target is\n  // specified, even though the popup is not necessarily blocked.\n  const ua = getUA().toLowerCase();\n\n  if (name) {\n    target = _isChromeIOS(ua) ? TARGET_BLANK : name;\n  }\n\n  if (_isFirefox(ua)) {\n    // Firefox complains when invalid URLs are popped out. Hacky way to bypass.\n    url = url || FIREFOX_EMPTY_URL;\n    // Firefox disables by default scrolling on popup windows, which can create\n    // issues when the user has many Google accounts, for instance.\n    options.scrollbars = 'yes';\n  }\n\n  const optionsString = Object.entries(options).reduce(\n    (accum, [key, value]) => `${accum}${key}=${value},`,\n    ''\n  );\n\n  if (_isIOSStandalone(ua) && target !== '_self') {\n    openAsNewWindowIOS(url || '', target);\n    return new AuthPopup(null);\n  }\n\n  // about:blank getting sanitized causing browsers like IE/Edge to display\n  // brief error message before redirecting to handler.\n  const newWin = window.open(url || '', target, optionsString);\n  _assert(newWin, auth, AuthErrorCode.POPUP_BLOCKED);\n\n  // Flaky on IE edge, encapsulate with a try and catch.\n  try {\n    newWin.focus();\n  } catch (e) {}\n\n  return new AuthPopup(newWin);\n}\n\nfunction openAsNewWindowIOS(url: string, target: string): void {\n  const el = document.createElement('a');\n  el.href = url;\n  el.target = target;\n  const click = document.createEvent('MouseEvent');\n  click.initMouseEvent(\n    'click',\n    true,\n    true,\n    window,\n    1,\n    0,\n    0,\n    0,\n    0,\n    false,\n    false,\n    false,\n    false,\n    1,\n    null\n  );\n  el.dispatchEvent(click);\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { SDK_VERSION } from '@firebase/app';\nimport { AuthProvider } from '../../model/public_types';\nimport { ApiKey, AppName, AuthInternal } from '../../model/auth';\nimport { AuthEventType } from '../../model/popup_redirect';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from './assert';\nimport { isEmpty, querystring } from '@firebase/util';\nimport { _emulatorUrl } from './emulator';\nimport { FederatedAuthProvider } from '../providers/federated';\nimport { BaseOAuthProvider } from '../providers/oauth';\n\n/**\n * URL for Authentication widget which will initiate the OAuth handshake\n *\n * @internal\n */\nconst WIDGET_PATH = '__/auth/handler';\n\n/**\n * URL for emulated environment\n *\n * @internal\n */\nconst EMULATOR_WIDGET_PATH = 'emulator/auth/handler';\n\n/**\n * Fragment name for the App Check token that gets passed to the widget\n *\n * @internal\n */\nconst FIREBASE_APP_CHECK_FRAGMENT_ID = encodeURIComponent('fac');\n\n// eslint-disable-next-line @typescript-eslint/consistent-type-definitions\ntype WidgetParams = {\n  apiKey: ApiKey;\n  appName: AppName;\n  authType: AuthEventType;\n  redirectUrl?: string;\n  v: string;\n  providerId?: string;\n  scopes?: string;\n  customParameters?: string;\n  eventId?: string;\n  tid?: string;\n} & { [key: string]: string | undefined };\n\nexport async function _getRedirectUrl(\n  auth: AuthInternal,\n  provider: AuthProvider,\n  authType: AuthEventType,\n  redirectUrl?: string,\n  eventId?: string,\n  additionalParams?: Record<string, string>\n): Promise<string> {\n  _assert(auth.config.authDomain, auth, AuthErrorCode.MISSING_AUTH_DOMAIN);\n  _assert(auth.config.apiKey, auth, AuthErrorCode.INVALID_API_KEY);\n\n  const params: WidgetParams = {\n    apiKey: auth.config.apiKey,\n    appName: auth.name,\n    authType,\n    redirectUrl,\n    v: SDK_VERSION,\n    eventId\n  };\n\n  if (provider instanceof FederatedAuthProvider) {\n    provider.setDefaultLanguage(auth.languageCode);\n    params.providerId = provider.providerId || '';\n    if (!isEmpty(provider.getCustomParameters())) {\n      params.customParameters = JSON.stringify(provider.getCustomParameters());\n    }\n\n    // TODO set additionalParams from the provider as well?\n    for (const [key, value] of Object.entries(additionalParams || {})) {\n      params[key] = value;\n    }\n  }\n\n  if (provider instanceof BaseOAuthProvider) {\n    const scopes = provider.getScopes().filter(scope => scope !== '');\n    if (scopes.length > 0) {\n      params.scopes = scopes.join(',');\n    }\n  }\n\n  if (auth.tenantId) {\n    params.tid = auth.tenantId;\n  }\n\n  // TODO: maybe set eid as endpointId\n  // TODO: maybe set fw as Frameworks.join(\",\")\n\n  const paramsDict = params as Record<string, string | number>;\n  for (const key of Object.keys(paramsDict)) {\n    if (paramsDict[key] === undefined) {\n      delete paramsDict[key];\n    }\n  }\n\n  // Sets the App Check token to pass to the widget\n  const appCheckToken = await auth._getAppCheckToken();\n  const appCheckTokenFragment = appCheckToken\n    ? `#${FIREBASE_APP_CHECK_FRAGMENT_ID}=${encodeURIComponent(appCheckToken)}`\n    : '';\n\n  // Start at index 1 to skip the leading '&' in the query string\n  return `${getHandlerBase(auth)}?${querystring(paramsDict).slice(\n    1\n  )}${appCheckTokenFragment}`;\n}\n\nfunction getHandlerBase({ config }: AuthInternal): string {\n  if (!config.emulator) {\n    return `https://${config.authDomain}/${WIDGET_PATH}`;\n  }\n\n  return _emulatorUrl(config, EMULATOR_WIDGET_PATH);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthProvider, PopupRedirectResolver } from '../model/public_types';\n\nimport { AuthEventManager } from '../core/auth/auth_event_manager';\nimport { AuthErrorCode } from '../core/errors';\nimport { _assert, debugAssert, _fail } from '../core/util/assert';\nimport { _generateEventId } from '../core/util/event_id';\nimport { _getCurrentUrl } from '../core/util/location';\nimport { _validateOrigin } from '../core/util/validate_origin';\nimport { AuthInternal } from '../model/auth';\nimport {\n  AuthEventType,\n  EventManager,\n  GapiAuthEvent,\n  GapiOutcome,\n  PopupRedirectResolverInternal\n} from '../model/popup_redirect';\nimport { _setWindowLocation } from './auth_window';\nimport { _openIframe } from './iframe/iframe';\nimport { browserSessionPersistence } from './persistence/session_storage';\nimport { _open, AuthPopup } from './util/popup';\nimport { _getRedirectResult } from './strategies/redirect';\nimport { _getRedirectUrl } from '../core/util/handler';\nimport { _isIOS, _isMobileBrowser, _isSafari } from '../core/util/browser';\nimport { _overrideRedirectResult } from '../core/strategies/redirect';\n\n/**\n * The special web storage event\n *\n */\nconst WEB_STORAGE_SUPPORT_KEY = 'webStorageSupport';\n\ninterface WebStorageSupportMessage extends gapi.iframes.Message {\n  [index: number]: Record<string, boolean>;\n}\n\ninterface ManagerOrPromise {\n  manager?: EventManager;\n  promise?: Promise<EventManager>;\n}\n\nclass BrowserPopupRedirectResolver implements PopupRedirectResolverInternal {\n  private readonly eventManagers: Record<string, ManagerOrPromise> = {};\n  private readonly iframes: Record<string, gapi.iframes.Iframe> = {};\n  private readonly originValidationPromises: Record<string, Promise<void>> = {};\n\n  readonly _redirectPersistence = browserSessionPersistence;\n\n  // Wrapping in async even though we don't await anywhere in order\n  // to make sure errors are raised as promise rejections\n  async _openPopup(\n    auth: AuthInternal,\n    provider: AuthProvider,\n    authType: AuthEventType,\n    eventId?: string\n  ): Promise<AuthPopup> {\n    debugAssert(\n      this.eventManagers[auth._key()]?.manager,\n      '_initialize() not called before _openPopup()'\n    );\n\n    const url = await _getRedirectUrl(\n      auth,\n      provider,\n      authType,\n      _getCurrentUrl(),\n      eventId\n    );\n    return _open(auth, url, _generateEventId());\n  }\n\n  async _openRedirect(\n    auth: AuthInternal,\n    provider: AuthProvider,\n    authType: AuthEventType,\n    eventId?: string\n  ): Promise<never> {\n    await this._originValidation(auth);\n    const url = await _getRedirectUrl(\n      auth,\n      provider,\n      authType,\n      _getCurrentUrl(),\n      eventId\n    );\n    _setWindowLocation(url);\n    return new Promise(() => {});\n  }\n\n  _initialize(auth: AuthInternal): Promise<EventManager> {\n    const key = auth._key();\n    if (this.eventManagers[key]) {\n      const { manager, promise } = this.eventManagers[key];\n      if (manager) {\n        return Promise.resolve(manager);\n      } else {\n        debugAssert(promise, 'If manager is not set, promise should be');\n        return promise;\n      }\n    }\n\n    const promise = this.initAndGetManager(auth);\n    this.eventManagers[key] = { promise };\n\n    // If the promise is rejected, the key should be removed so that the\n    // operation can be retried later.\n    promise.catch(() => {\n      delete this.eventManagers[key];\n    });\n\n    return promise;\n  }\n\n  private async initAndGetManager(auth: AuthInternal): Promise<EventManager> {\n    const iframe = await _openIframe(auth);\n    const manager = new AuthEventManager(auth);\n    iframe.register<GapiAuthEvent>(\n      'authEvent',\n      (iframeEvent: GapiAuthEvent | null) => {\n        _assert(iframeEvent?.authEvent, auth, AuthErrorCode.INVALID_AUTH_EVENT);\n        // TODO: Consider splitting redirect and popup events earlier on\n\n        const handled = manager.onEvent(iframeEvent.authEvent);\n        return { status: handled ? GapiOutcome.ACK : GapiOutcome.ERROR };\n      },\n      gapi.iframes.CROSS_ORIGIN_IFRAMES_FILTER\n    );\n\n    this.eventManagers[auth._key()] = { manager };\n    this.iframes[auth._key()] = iframe;\n    return manager;\n  }\n\n  _isIframeWebStorageSupported(\n    auth: AuthInternal,\n    cb: (supported: boolean) => unknown\n  ): void {\n    const iframe = this.iframes[auth._key()];\n    iframe.send<gapi.iframes.Message, WebStorageSupportMessage>(\n      WEB_STORAGE_SUPPORT_KEY,\n      { type: WEB_STORAGE_SUPPORT_KEY },\n      result => {\n        const isSupported = result?.[0]?.[WEB_STORAGE_SUPPORT_KEY];\n        if (isSupported !== undefined) {\n          cb(!!isSupported);\n        }\n\n        _fail(auth, AuthErrorCode.INTERNAL_ERROR);\n      },\n      gapi.iframes.CROSS_ORIGIN_IFRAMES_FILTER\n    );\n  }\n\n  _originValidation(auth: AuthInternal): Promise<void> {\n    const key = auth._key();\n    if (!this.originValidationPromises[key]) {\n      this.originValidationPromises[key] = _validateOrigin(auth);\n    }\n\n    return this.originValidationPromises[key];\n  }\n\n  get _shouldInitProactively(): boolean {\n    // Mobile browsers and Safari need to optimistically initialize\n    return _isMobileBrowser() || _isSafari() || _isIOS();\n  }\n\n  _completeRedirectFn = _getRedirectResult;\n\n  _overrideRedirectResult = _overrideRedirectResult;\n}\n\n/**\n * An implementation of {@link PopupRedirectResolver} suitable for browser\n * based applications.\n *\n * @remarks\n * This method does not work in a Node.js environment.\n *\n * @public\n */\nexport const browserPopupRedirectResolver: PopupRedirectResolver =\n  BrowserPopupRedirectResolver;\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\nimport {\n  FactorId,\n  PhoneMultiFactorAssertion\n} from '../../../model/public_types';\n\nimport { MultiFactorAssertionImpl } from '../../../mfa/mfa_assertion';\nimport { AuthInternal } from '../../../model/auth';\nimport { finalizeEnrollPhoneMfa } from '../../../api/account_management/mfa';\nimport { PhoneAuthCredential } from '../../../core/credentials/phone';\nimport {\n  finalizeSignInPhoneMfa,\n  FinalizeMfaResponse\n} from '../../../api/authentication/mfa';\n\n/**\n * {@inheritdoc PhoneMultiFactorAssertion}\n *\n * @public\n */\nexport class PhoneMultiFactorAssertionImpl\n  extends MultiFactorAssertionImpl\n  implements PhoneMultiFactorAssertion\n{\n  private constructor(private readonly credential: PhoneAuthCredential) {\n    super(FactorId.PHONE);\n  }\n\n  /** @internal */\n  static _fromCredential(\n    credential: PhoneAuthCredential\n  ): PhoneMultiFactorAssertionImpl {\n    return new PhoneMultiFactorAssertionImpl(credential);\n  }\n\n  /** @internal */\n  _finalizeEnroll(\n    auth: AuthInternal,\n    idToken: string,\n    displayName?: string | null\n  ): Promise<FinalizeMfaResponse> {\n    return finalizeEnrollPhoneMfa(auth, {\n      idToken,\n      displayName,\n      phoneVerificationInfo: this.credential._makeVerificationRequest()\n    });\n  }\n\n  /** @internal */\n  _finalizeSignIn(\n    auth: AuthInternal,\n    mfaPendingCredential: string\n  ): Promise<FinalizeMfaResponse> {\n    return finalizeSignInPhoneMfa(auth, {\n      mfaPendingCredential,\n      phoneVerificationInfo: this.credential._makeVerificationRequest()\n    });\n  }\n}\n\n/**\n * Provider for generating a {@link PhoneMultiFactorAssertion}.\n *\n * @public\n */\nexport class PhoneMultiFactorGenerator {\n  private constructor() {}\n\n  /**\n   * Provides a {@link PhoneMultiFactorAssertion} to confirm ownership of the phone second factor.\n   *\n   * @remarks\n   * This method does not work in a Node.js environment.\n   *\n   * @param phoneAuthCredential - A credential provided by {@link PhoneAuthProvider.credential}.\n   * @returns A {@link PhoneMultiFactorAssertion} which can be used with\n   * {@link MultiFactorResolver.resolveSignIn}\n   */\n  static assertion(credential: PhoneAuthCredential): PhoneMultiFactorAssertion {\n    return PhoneMultiFactorAssertionImpl._fromCredential(credential);\n  }\n\n  /**\n   * The identifier of the phone second factor: `phone`.\n   */\n  static FACTOR_ID = 'phone';\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\nimport { FactorId, MultiFactorAssertion } from '../model/public_types';\nimport { debugFail } from '../core/util/assert';\nimport { MultiFactorSessionImpl, MultiFactorSessionType } from './mfa_session';\nimport { FinalizeMfaResponse } from '../api/authentication/mfa';\nimport { AuthInternal } from '../model/auth';\n\nexport abstract class MultiFactorAssertionImpl implements MultiFactorAssertion {\n  protected constructor(readonly factorId: FactorId) {}\n\n  _process(\n    auth: AuthInternal,\n    session: MultiFactorSessionImpl,\n    displayName?: string | null\n  ): Promise<FinalizeMfaResponse> {\n    switch (session.type) {\n      case MultiFactorSessionType.ENROLL:\n        return this._finalizeEnroll(auth, session.credential, displayName);\n      case MultiFactorSessionType.SIGN_IN:\n        return this._finalizeSignIn(auth, session.credential);\n      default:\n        return debugFail('unexpected MultiFactorSessionType');\n    }\n  }\n\n  abstract _finalizeEnroll(\n    auth: AuthInternal,\n    idToken: string,\n    displayName?: string | null\n  ): Promise<FinalizeMfaResponse>;\n  abstract _finalizeSignIn(\n    auth: AuthInternal,\n    mfaPendingCredential: string\n  ): Promise<FinalizeMfaResponse>;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Unsubscribe } from '@firebase/util';\nimport { FirebaseAuthInternal } from '@firebase/auth-interop-types';\n\nimport { AuthInternal } from '../../model/auth';\nimport { UserInternal } from '../../model/user';\nimport { _assert } from '../util/assert';\nimport { AuthErrorCode } from '../errors';\n\ninterface TokenListener {\n  (tok: string | null): unknown;\n}\n\nexport class AuthInterop implements FirebaseAuthInternal {\n  private readonly internalListeners: Map<TokenListener, Unsubscribe> =\n    new Map();\n\n  constructor(private readonly auth: AuthInternal) {}\n\n  getUid(): string | null {\n    this.assertAuthConfigured();\n    return this.auth.currentUser?.uid || null;\n  }\n\n  async getToken(\n    forceRefresh?: boolean\n  ): Promise<{ accessToken: string } | null> {\n    this.assertAuthConfigured();\n    await this.auth._initializationPromise;\n    if (!this.auth.currentUser) {\n      return null;\n    }\n\n    const accessToken = await this.auth.currentUser.getIdToken(forceRefresh);\n    return { accessToken };\n  }\n\n  addAuthTokenListener(listener: TokenListener): void {\n    this.assertAuthConfigured();\n    if (this.internalListeners.has(listener)) {\n      return;\n    }\n\n    const unsubscribe = this.auth.onIdTokenChanged(user => {\n      listener(\n        (user as UserInternal | null)?.stsTokenManager.accessToken || null\n      );\n    });\n    this.internalListeners.set(listener, unsubscribe);\n    this.updateProactiveRefresh();\n  }\n\n  removeAuthTokenListener(listener: TokenListener): void {\n    this.assertAuthConfigured();\n    const unsubscribe = this.internalListeners.get(listener);\n    if (!unsubscribe) {\n      return;\n    }\n\n    this.internalListeners.delete(listener);\n    unsubscribe();\n    this.updateProactiveRefresh();\n  }\n\n  private assertAuthConfigured(): void {\n    _assert(\n      this.auth._initializationPromise,\n      AuthErrorCode.DEPENDENT_SDK_INIT_BEFORE_AUTH\n    );\n  }\n\n  private updateProactiveRefresh(): void {\n    if (this.internalListeners.size > 0) {\n      this.auth._startProactiveRefresh();\n    } else {\n      this.auth._stopProactiveRefresh();\n    }\n  }\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FirebaseApp, getApp, _getProvider } from '@firebase/app';\n\nimport {\n  initializeAuth,\n  beforeAuthStateChanged,\n  onIdTokenChanged,\n  connectAuthEmulator\n} from '..';\nimport { registerAuth } from '../core/auth/register';\nimport { ClientPlatform } from '../core/util/version';\nimport { browserLocalPersistence } from './persistence/local_storage';\nimport { browserSessionPersistence } from './persistence/session_storage';\nimport { indexedDBLocalPersistence } from './persistence/indexed_db';\nimport { browserPopupRedirectResolver } from './popup_redirect';\nimport { Auth, User } from '../model/public_types';\nimport { getDefaultEmulatorHost, getExperimentalSetting } from '@firebase/util';\nimport { _setExternalJSProvider } from './load_js';\nimport { _createError } from '../core/util/assert';\nimport { AuthErrorCode } from '../core/errors';\n\nconst DEFAULT_ID_TOKEN_MAX_AGE = 5 * 60;\nconst authIdTokenMaxAge =\n  getExperimentalSetting('authIdTokenMaxAge') || DEFAULT_ID_TOKEN_MAX_AGE;\n\nlet lastPostedIdToken: string | undefined | null = null;\n\nconst mintCookieFactory = (url: string) => async (user: User | null) => {\n  const idTokenResult = user && (await user.getIdTokenResult());\n  const idTokenAge =\n    idTokenResult &&\n    (new Date().getTime() - Date.parse(idTokenResult.issuedAtTime)) / 1_000;\n  if (idTokenAge && idTokenAge > authIdTokenMaxAge) {\n    return;\n  }\n  // Specifically trip null => undefined when logged out, to delete any existing cookie\n  const idToken = idTokenResult?.token;\n  if (lastPostedIdToken === idToken) {\n    return;\n  }\n  lastPostedIdToken = idToken;\n  await fetch(url, {\n    method: idToken ? 'POST' : 'DELETE',\n    headers: idToken\n      ? {\n          'Authorization': `Bearer ${idToken}`\n        }\n      : {}\n  });\n};\n\n/**\n * Returns the Auth instance associated with the provided {@link @firebase/app#FirebaseApp}.\n * If no instance exists, initializes an Auth instance with platform-specific default dependencies.\n *\n * @param app - The Firebase App.\n *\n * @public\n */\nexport function getAuth(app: FirebaseApp = getApp()): Auth {\n  const provider = _getProvider(app, 'auth');\n\n  if (provider.isInitialized()) {\n    return provider.getImmediate();\n  }\n\n  const auth = initializeAuth(app, {\n    popupRedirectResolver: browserPopupRedirectResolver,\n    persistence: [\n      indexedDBLocalPersistence,\n      browserLocalPersistence,\n      browserSessionPersistence\n    ]\n  });\n\n  const authTokenSyncPath = getExperimentalSetting('authTokenSyncURL');\n  // Only do the Cookie exchange in a secure context\n  if (\n    authTokenSyncPath &&\n    typeof isSecureContext === 'boolean' &&\n    isSecureContext\n  ) {\n    // Don't allow urls (XSS possibility), only paths on the same domain\n    const authTokenSyncUrl = new URL(authTokenSyncPath, location.origin);\n    if (location.origin === authTokenSyncUrl.origin) {\n      const mintCookie = mintCookieFactory(authTokenSyncUrl.toString());\n      beforeAuthStateChanged(auth, mintCookie, () =>\n        mintCookie(auth.currentUser)\n      );\n      onIdTokenChanged(auth, user => mintCookie(user));\n    }\n  }\n\n  const authEmulatorHost = getDefaultEmulatorHost('auth');\n  if (authEmulatorHost) {\n    connectAuthEmulator(auth, `http://${authEmulatorHost}`);\n  }\n\n  return auth;\n}\n\nfunction getScriptParentElement(): HTMLDocument | HTMLHeadElement {\n  return document.getElementsByTagName('head')?.[0] ?? document;\n}\n\n_setExternalJSProvider({\n  loadJS(url: string): Promise<Event> {\n    // TODO: consider adding timeout support & cancellation\n    return new Promise((resolve, reject) => {\n      const el = document.createElement('script');\n      el.setAttribute('src', url);\n      el.onload = resolve;\n      el.onerror = e => {\n        const error = _createError(AuthErrorCode.INTERNAL_ERROR);\n        error.customData = e as unknown as Record<string, unknown>;\n        reject(error);\n      };\n      el.type = 'text/javascript';\n      el.charset = 'UTF-8';\n      getScriptParentElement().appendChild(el);\n    });\n  },\n\n  gapiScript: 'https://apis.google.com/js/api.js',\n  recaptchaV2Script: 'https://www.google.com/recaptcha/api.js',\n  recaptchaEnterpriseScript:\n    'https://www.google.com/recaptcha/enterprise.js?render='\n});\n\nregisterAuth(ClientPlatform.BROWSER);\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { _registerComponent, registerVersion } from '@firebase/app';\nimport {\n  Component,\n  ComponentType,\n  InstantiationMode\n} from '@firebase/component';\n\nimport { name, version } from '../../../package.json';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\nimport { _getClientVersion, ClientPlatform } from '../util/version';\nimport { _castAuth, AuthImpl, DefaultConfig } from './auth_impl';\nimport { AuthInterop } from './firebase_internal';\nimport { ConfigInternal } from '../../model/auth';\nimport { Dependencies } from '../../model/public_types';\nimport { _initializeAuthInstance } from './initialize';\n\nexport const enum _ComponentName {\n  AUTH = 'auth',\n  AUTH_INTERNAL = 'auth-internal'\n}\n\nfunction getVersionForPlatform(\n  clientPlatform: ClientPlatform\n): string | undefined {\n  switch (clientPlatform) {\n    case ClientPlatform.NODE:\n      return 'node';\n    case ClientPlatform.REACT_NATIVE:\n      return 'rn';\n    case ClientPlatform.WORKER:\n      return 'webworker';\n    case ClientPlatform.CORDOVA:\n      return 'cordova';\n    case ClientPlatform.WEB_EXTENSION:\n      return 'web-extension';\n    default:\n      return undefined;\n  }\n}\n\n/** @internal */\nexport function registerAuth(clientPlatform: ClientPlatform): void {\n  _registerComponent(\n    new Component(\n      _ComponentName.AUTH,\n      (container, { options: deps }: { options?: Dependencies }) => {\n        const app = container.getProvider('app').getImmediate()!;\n        const heartbeatServiceProvider =\n          container.getProvider<'heartbeat'>('heartbeat');\n        const appCheckServiceProvider =\n          container.getProvider<'app-check-internal'>('app-check-internal');\n        const { apiKey, authDomain } = app.options;\n\n        _assert(\n          apiKey && !apiKey.includes(':'),\n          AuthErrorCode.INVALID_API_KEY,\n          { appName: app.name }\n        );\n\n        const config: ConfigInternal = {\n          apiKey,\n          authDomain,\n          clientPlatform,\n          apiHost: DefaultConfig.API_HOST,\n          tokenApiHost: DefaultConfig.TOKEN_API_HOST,\n          apiScheme: DefaultConfig.API_SCHEME,\n          sdkClientVersion: _getClientVersion(clientPlatform)\n        };\n\n        const authInstance = new AuthImpl(\n          app,\n          heartbeatServiceProvider,\n          appCheckServiceProvider,\n          config\n        );\n        _initializeAuthInstance(authInstance, deps);\n\n        return authInstance;\n      },\n      ComponentType.PUBLIC\n    )\n      /**\n       * Auth can only be initialized by explicitly calling getAuth() or initializeAuth()\n       * For why we do this, See go/firebase-next-auth-init\n       */\n      .setInstantiationMode(InstantiationMode.EXPLICIT)\n      /**\n       * Because all firebase products that depend on auth depend on auth-internal directly,\n       * we need to initialize auth-internal after auth is initialized to make it available to other firebase products.\n       */\n      .setInstanceCreatedCallback(\n        (container, _instanceIdentifier, _instance) => {\n          const authInternalProvider = container.getProvider(\n            _ComponentName.AUTH_INTERNAL\n          );\n          authInternalProvider.initialize();\n        }\n      )\n  );\n\n  _registerComponent(\n    new Component(\n      _ComponentName.AUTH_INTERNAL,\n      container => {\n        const auth = _castAuth(\n          container.getProvider(_ComponentName.AUTH).getImmediate()!\n        );\n        return (auth => new AuthInterop(auth))(auth);\n      },\n      ComponentType.PRIVATE\n    ).setInstantiationMode(InstantiationMode.EXPLICIT)\n  );\n\n  registerVersion(name, version, getVersionForPlatform(clientPlatform));\n  // BUILD_TARGET will be replaced by values like esm, cjs, etc during the compilation\n  registerVersion(name, version, '__BUILD_TARGET__');\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nexport interface CordovaWindow extends Window {\n  cordova: {\n    plugins: {\n      browsertab: {\n        isAvailable(cb: (available: boolean) => void): void;\n        openUrl(url: string): void;\n        close(): void;\n      };\n    };\n\n    InAppBrowser: {\n      open(url: string, target: string, options: string): InAppBrowserRef;\n    };\n  };\n\n  universalLinks: {\n    subscribe(\n      n: null,\n      cb: (event: Record<string, string> | null) => void\n    ): void;\n  };\n\n  BuildInfo: {\n    readonly packageName: string;\n    readonly displayName: string;\n  };\n\n  handleOpenURL(url: string): void;\n}\n\nexport interface InAppBrowserRef {\n  close?: () => void;\n}\n\nexport function _cordovaWindow(): CordovaWindow {\n  return window as unknown as CordovaWindow;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { _getProvider, FirebaseApp } from '@firebase/app';\nimport { deepEqual } from '@firebase/util';\nimport { Auth, Dependencies } from '../../model/public_types';\n\nimport { AuthErrorCode } from '../errors';\nimport { PersistenceInternal } from '../persistence';\nimport { _fail } from '../util/assert';\nimport { _getInstance } from '../util/instantiator';\nimport { AuthImpl } from './auth_impl';\n\n/**\n * Initializes an {@link Auth} instance with fine-grained control over\n * {@link Dependencies}.\n *\n * @remarks\n *\n * This function allows more control over the {@link Auth} instance than\n * {@link getAuth}. `getAuth` uses platform-specific defaults to supply\n * the {@link Dependencies}. In general, `getAuth` is the easiest way to\n * initialize Auth and works for most use cases. Use `initializeAuth` if you\n * need control over which persistence layer is used, or to minimize bundle\n * size if you're not using either `signInWithPopup` or `signInWithRedirect`.\n *\n * For example, if your app only uses anonymous accounts and you only want\n * accounts saved for the current session, initialize `Auth` with:\n *\n * ```js\n * const auth = initializeAuth(app, {\n *   persistence: browserSessionPersistence,\n *   popupRedirectResolver: undefined,\n * });\n * ```\n *\n * @public\n */\nexport function initializeAuth(app: FirebaseApp, deps?: Dependencies): Auth {\n  const provider = _getProvider(app, 'auth');\n\n  if (provider.isInitialized()) {\n    const auth = provider.getImmediate() as AuthImpl;\n    const initialOptions = provider.getOptions() as Dependencies;\n    if (deepEqual(initialOptions, deps ?? {})) {\n      return auth;\n    } else {\n      _fail(auth, AuthErrorCode.ALREADY_INITIALIZED);\n    }\n  }\n\n  const auth = provider.initialize({ options: deps }) as AuthImpl;\n\n  return auth;\n}\n\nexport function _initializeAuthInstance(\n  auth: AuthImpl,\n  deps?: Dependencies\n): void {\n  const persistence = deps?.persistence || [];\n  const hierarchy = (\n    Array.isArray(persistence) ? persistence : [persistence]\n  ).map<PersistenceInternal>(_getInstance);\n  if (deps?.errorMap) {\n    auth._updateErrorMap(deps.errorMap);\n  }\n\n  // This promise is intended to float; auth initialization happens in the\n  // background, meanwhile the auth object may be used by the app.\n  // eslint-disable-next-line @typescript-eslint/no-floating-promises\n  auth._initializeWithPersistence(hierarchy, deps?.popupRedirectResolver);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthProvider } from '../../model/public_types';\nimport { AuthErrorCode } from '../../core/errors';\nimport {\n  debugAssert,\n  _assert,\n  _createError,\n  _fail\n} from '../../core/util/assert';\nimport { _isAndroid, _isIOS, _isIOS7Or8 } from '../../core/util/browser';\nimport { _getRedirectUrl } from '../../core/util/handler';\nimport { AuthInternal } from '../../model/auth';\nimport { AuthEvent } from '../../model/popup_redirect';\nimport { InAppBrowserRef, _cordovaWindow } from '../plugins';\nimport {\n  GetProjectConfigRequest,\n  _getProjectConfig\n} from '../../api/project_config/get_project_config';\n\n/**\n * How long to wait after the app comes back into focus before concluding that\n * the user closed the sign in tab.\n */\nconst REDIRECT_TIMEOUT_MS = 2000;\n\n/**\n * Generates the URL for the OAuth handler.\n */\nexport async function _generateHandlerUrl(\n  auth: AuthInternal,\n  event: AuthEvent,\n  provider: AuthProvider\n): Promise<string> {\n  // Get the cordova plugins\n  const { BuildInfo } = _cordovaWindow();\n  debugAssert(event.sessionId, 'AuthEvent did not contain a session ID');\n  const sessionDigest = await computeSha256(event.sessionId);\n\n  const additionalParams: Record<string, string> = {};\n  if (_isIOS()) {\n    // iOS app identifier\n    additionalParams['ibi'] = BuildInfo.packageName;\n  } else if (_isAndroid()) {\n    // Android app identifier\n    additionalParams['apn'] = BuildInfo.packageName;\n  } else {\n    _fail(auth, AuthErrorCode.OPERATION_NOT_SUPPORTED);\n  }\n\n  // Add the display name if available\n  if (BuildInfo.displayName) {\n    additionalParams['appDisplayName'] = BuildInfo.displayName;\n  }\n\n  // Attached the hashed session ID\n  additionalParams['sessionId'] = sessionDigest;\n  return _getRedirectUrl(\n    auth,\n    provider,\n    event.type,\n    undefined,\n    event.eventId ?? undefined,\n    additionalParams\n  );\n}\n\n/**\n * Validates that this app is valid for this project configuration\n */\nexport async function _validateOrigin(auth: AuthInternal): Promise<void> {\n  const { BuildInfo } = _cordovaWindow();\n  const request: GetProjectConfigRequest = {};\n  if (_isIOS()) {\n    request.iosBundleId = BuildInfo.packageName;\n  } else if (_isAndroid()) {\n    request.androidPackageName = BuildInfo.packageName;\n  } else {\n    _fail(auth, AuthErrorCode.OPERATION_NOT_SUPPORTED);\n  }\n\n  // Will fail automatically if package name is not authorized\n  await _getProjectConfig(auth, request);\n}\n\nexport function _performRedirect(\n  handlerUrl: string\n): Promise<InAppBrowserRef | null> {\n  // Get the cordova plugins\n  const { cordova } = _cordovaWindow();\n\n  return new Promise(resolve => {\n    cordova.plugins.browsertab.isAvailable(browserTabIsAvailable => {\n      let iabRef: InAppBrowserRef | null = null;\n      if (browserTabIsAvailable) {\n        cordova.plugins.browsertab.openUrl(handlerUrl);\n      } else {\n        // TODO: Return the inappbrowser ref that's returned from the open call\n        iabRef = cordova.InAppBrowser.open(\n          handlerUrl,\n          _isIOS7Or8() ? '_blank' : '_system',\n          'location=yes'\n        );\n      }\n      resolve(iabRef);\n    });\n  });\n}\n\n// Thin interface wrapper to avoid circular dependency with ./events module\ninterface PassiveAuthEventListener {\n  addPassiveListener(cb: () => void): void;\n  removePassiveListener(cb: () => void): void;\n}\n\n/**\n * This function waits for app activity to be seen before resolving. It does\n * this by attaching listeners to various dom events. Once the app is determined\n * to be visible, this promise resolves. AFTER that resolution, the listeners\n * are detached and any browser tabs left open will be closed.\n */\nexport async function _waitForAppResume(\n  auth: AuthInternal,\n  eventListener: PassiveAuthEventListener,\n  iabRef: InAppBrowserRef | null\n): Promise<void> {\n  // Get the cordova plugins\n  const { cordova } = _cordovaWindow();\n\n  let cleanup = (): void => {};\n  try {\n    await new Promise<void>((resolve, reject) => {\n      let onCloseTimer: number | null = null;\n\n      // DEFINE ALL THE CALLBACKS =====\n      function authEventSeen(): void {\n        // Auth event was detected. Resolve this promise and close the extra\n        // window if it's still open.\n        resolve();\n        const closeBrowserTab = cordova.plugins.browsertab?.close;\n        if (typeof closeBrowserTab === 'function') {\n          closeBrowserTab();\n        }\n        // Close inappbrowser embedded webview in iOS7 and 8 case if still\n        // open.\n        if (typeof iabRef?.close === 'function') {\n          iabRef.close();\n        }\n      }\n\n      function resumed(): void {\n        if (onCloseTimer) {\n          // This code already ran; do not rerun.\n          return;\n        }\n\n        onCloseTimer = window.setTimeout(() => {\n          // Wait two seconds after resume then reject.\n          reject(_createError(auth, AuthErrorCode.REDIRECT_CANCELLED_BY_USER));\n        }, REDIRECT_TIMEOUT_MS);\n      }\n\n      function visibilityChanged(): void {\n        if (document?.visibilityState === 'visible') {\n          resumed();\n        }\n      }\n\n      // ATTACH ALL THE LISTENERS =====\n      // Listen for the auth event\n      eventListener.addPassiveListener(authEventSeen);\n\n      // Listen for resume and visibility events\n      document.addEventListener('resume', resumed, false);\n      if (_isAndroid()) {\n        document.addEventListener('visibilitychange', visibilityChanged, false);\n      }\n\n      // SETUP THE CLEANUP FUNCTION =====\n      cleanup = () => {\n        eventListener.removePassiveListener(authEventSeen);\n        document.removeEventListener('resume', resumed, false);\n        document.removeEventListener(\n          'visibilitychange',\n          visibilityChanged,\n          false\n        );\n        if (onCloseTimer) {\n          window.clearTimeout(onCloseTimer);\n        }\n      };\n    });\n  } finally {\n    cleanup();\n  }\n}\n\n/**\n * Checks the configuration of the Cordova environment. This has no side effect\n * if the configuration is correct; otherwise it throws an error with the\n * missing plugin.\n */\nexport function _checkCordovaConfiguration(auth: AuthInternal): void {\n  const win = _cordovaWindow();\n  // Check all dependencies installed.\n  // https://github.com/nordnet/cordova-universal-links-plugin\n  // Note that cordova-universal-links-plugin has been abandoned.\n  // A fork with latest fixes is available at:\n  // https://www.npmjs.com/package/cordova-universal-links-plugin-fix\n  _assert(\n    typeof win?.universalLinks?.subscribe === 'function',\n    auth,\n    AuthErrorCode.INVALID_CORDOVA_CONFIGURATION,\n    {\n      missingPlugin: 'cordova-universal-links-plugin-fix'\n    }\n  );\n\n  // https://www.npmjs.com/package/cordova-plugin-buildinfo\n  _assert(\n    typeof win?.BuildInfo?.packageName !== 'undefined',\n    auth,\n    AuthErrorCode.INVALID_CORDOVA_CONFIGURATION,\n    {\n      missingPlugin: 'cordova-plugin-buildInfo'\n    }\n  );\n\n  // https://github.com/google/cordova-plugin-browsertab\n  _assert(\n    typeof win?.cordova?.plugins?.browsertab?.openUrl === 'function',\n    auth,\n    AuthErrorCode.INVALID_CORDOVA_CONFIGURATION,\n    {\n      missingPlugin: 'cordova-plugin-browsertab'\n    }\n  );\n  _assert(\n    typeof win?.cordova?.plugins?.browsertab?.isAvailable === 'function',\n    auth,\n    AuthErrorCode.INVALID_CORDOVA_CONFIGURATION,\n    {\n      missingPlugin: 'cordova-plugin-browsertab'\n    }\n  );\n\n  // https://cordova.apache.org/docs/en/latest/reference/cordova-plugin-inappbrowser/\n  _assert(\n    typeof win?.cordova?.InAppBrowser?.open === 'function',\n    auth,\n    AuthErrorCode.INVALID_CORDOVA_CONFIGURATION,\n    {\n      missingPlugin: 'cordova-plugin-inappbrowser'\n    }\n  );\n}\n\n/**\n * Computes the SHA-256 of a session ID. The SubtleCrypto interface is only\n * available in \"secure\" contexts, which covers Cordova (which is served on a file\n * protocol).\n */\nasync function computeSha256(sessionId: string): Promise<string> {\n  const bytes = stringToArrayBuffer(sessionId);\n\n  // TODO: For IE11 crypto has a different name and this operation comes back\n  //       as an object, not a promise. This is the old proposed standard that\n  //       is used by IE11:\n  // https://www.w3.org/TR/2013/WD-WebCryptoAPI-20130108/#cryptooperation-interface\n  const buf = await crypto.subtle.digest('SHA-256', bytes);\n  const arr = Array.from(new Uint8Array(buf));\n  return arr.map(num => num.toString(16).padStart(2, '0')).join('');\n}\n\nfunction stringToArrayBuffer(str: string): Uint8Array {\n  // This function is only meant to deal with an ASCII charset and makes\n  // certain simplifying assumptions.\n  debugAssert(\n    /[0-9a-zA-Z]+/.test(str),\n    'Can only convert alpha-numeric strings'\n  );\n  if (typeof TextEncoder !== 'undefined') {\n    return new TextEncoder().encode(str);\n  }\n\n  const buff = new ArrayBuffer(str.length);\n  const view = new Uint8Array(buff);\n  for (let i = 0; i < str.length; i++) {\n    view[i] = str.charCodeAt(i);\n  }\n  return view;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { querystringDecode } from '@firebase/util';\nimport { AuthEventManager } from '../../core/auth/auth_event_manager';\nimport { AuthErrorCode } from '../../core/errors';\nimport { PersistedBlob, PersistenceInternal } from '../../core/persistence';\nimport {\n  KeyName,\n  _persistenceKeyName\n} from '../../core/persistence/persistence_user_manager';\nimport { _createError } from '../../core/util/assert';\nimport { _getInstance } from '../../core/util/instantiator';\nimport { AuthInternal } from '../../model/auth';\nimport { AuthEvent, AuthEventType } from '../../model/popup_redirect';\nimport { browserLocalPersistence } from '../../platform_browser/persistence/local_storage';\n\nconst SESSION_ID_LENGTH = 20;\n\n/** Custom AuthEventManager that adds passive listeners to events */\nexport class CordovaAuthEventManager extends AuthEventManager {\n  private readonly passiveListeners = new Set<(e: AuthEvent) => void>();\n  private resolveInitialized!: () => void;\n  private initPromise = new Promise<void>(resolve => {\n    this.resolveInitialized = resolve;\n  });\n\n  addPassiveListener(cb: (e: AuthEvent) => void): void {\n    this.passiveListeners.add(cb);\n  }\n\n  removePassiveListener(cb: (e: AuthEvent) => void): void {\n    this.passiveListeners.delete(cb);\n  }\n\n  // In a Cordova environment, this manager can live through multiple redirect\n  // operations\n  resetRedirect(): void {\n    this.queuedRedirectEvent = null;\n    this.hasHandledPotentialRedirect = false;\n  }\n\n  /** Override the onEvent method */\n  onEvent(event: AuthEvent): boolean {\n    this.resolveInitialized();\n    this.passiveListeners.forEach(cb => cb(event));\n    return super.onEvent(event);\n  }\n\n  async initialized(): Promise<void> {\n    await this.initPromise;\n  }\n}\n\n/**\n * Generates a (partial) {@link AuthEvent}.\n */\nexport function _generateNewEvent(\n  auth: AuthInternal,\n  type: AuthEventType,\n  eventId: string | null = null\n): AuthEvent {\n  return {\n    type,\n    eventId,\n    urlResponse: null,\n    sessionId: generateSessionId(),\n    postBody: null,\n    tenantId: auth.tenantId,\n    error: _createError(auth, AuthErrorCode.NO_AUTH_EVENT)\n  };\n}\n\nexport function _savePartialEvent(\n  auth: AuthInternal,\n  event: AuthEvent\n): Promise<void> {\n  return storage()._set(persistenceKey(auth), event as object as PersistedBlob);\n}\n\nexport async function _getAndRemoveEvent(\n  auth: AuthInternal\n): Promise<AuthEvent | null> {\n  const event = (await storage()._get(\n    persistenceKey(auth)\n  )) as AuthEvent | null;\n  if (event) {\n    await storage()._remove(persistenceKey(auth));\n  }\n  return event;\n}\n\nexport function _eventFromPartialAndUrl(\n  partialEvent: AuthEvent,\n  url: string\n): AuthEvent | null {\n  // Parse the deep link within the dynamic link URL.\n  const callbackUrl = _getDeepLinkFromCallback(url);\n  // Confirm it is actually a callback URL.\n  // Currently the universal link will be of this format:\n  // https://<AUTH_DOMAIN>/__/auth/callback<OAUTH_RESPONSE>\n  // This is a fake URL but is not intended to take the user anywhere\n  // and just redirect to the app.\n  if (callbackUrl.includes('/__/auth/callback')) {\n    // Check if there is an error in the URL.\n    // This mechanism is also used to pass errors back to the app:\n    // https://<AUTH_DOMAIN>/__/auth/callback?firebaseError=<STRINGIFIED_ERROR>\n    const params = searchParamsOrEmpty(callbackUrl);\n    // Get the error object corresponding to the stringified error if found.\n    const errorObject = params['firebaseError']\n      ? parseJsonOrNull(decodeURIComponent(params['firebaseError']))\n      : null;\n    const code = errorObject?.['code']?.split('auth/')?.[1];\n    const error = code ? _createError(code) : null;\n    if (error) {\n      return {\n        type: partialEvent.type,\n        eventId: partialEvent.eventId,\n        tenantId: partialEvent.tenantId,\n        error,\n        urlResponse: null,\n        sessionId: null,\n        postBody: null\n      };\n    } else {\n      return {\n        type: partialEvent.type,\n        eventId: partialEvent.eventId,\n        tenantId: partialEvent.tenantId,\n        sessionId: partialEvent.sessionId,\n        urlResponse: callbackUrl,\n        postBody: null\n      };\n    }\n  }\n\n  return null;\n}\n\nfunction generateSessionId(): string {\n  const chars = [];\n  const allowedChars =\n    '1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';\n  for (let i = 0; i < SESSION_ID_LENGTH; i++) {\n    const idx = Math.floor(Math.random() * allowedChars.length);\n    chars.push(allowedChars.charAt(idx));\n  }\n  return chars.join('');\n}\n\nfunction storage(): PersistenceInternal {\n  return _getInstance(browserLocalPersistence);\n}\n\nfunction persistenceKey(auth: AuthInternal): string {\n  return _persistenceKeyName(KeyName.AUTH_EVENT, auth.config.apiKey, auth.name);\n}\n\nfunction parseJsonOrNull(json: string): ReturnType<typeof JSON.parse> | null {\n  try {\n    return JSON.parse(json);\n  } catch (e) {\n    return null;\n  }\n}\n\n// Exported for testing\nexport function _getDeepLinkFromCallback(url: string): string {\n  const params = searchParamsOrEmpty(url);\n  const link = params['link'] ? decodeURIComponent(params['link']) : undefined;\n  // Double link case (automatic redirect)\n  const doubleDeepLink = searchParamsOrEmpty(link)['link'];\n  // iOS custom scheme links.\n  const iOSDeepLink = params['deep_link_id']\n    ? decodeURIComponent(params['deep_link_id'])\n    : undefined;\n  const iOSDoubleDeepLink = searchParamsOrEmpty(iOSDeepLink)['link'];\n  return iOSDoubleDeepLink || iOSDeepLink || doubleDeepLink || link || url;\n}\n\n/**\n * Optimistically tries to get search params from a string, or else returns an\n * empty search params object.\n */\nfunction searchParamsOrEmpty(url: string | undefined): Record<string, string> {\n  if (!url?.includes('?')) {\n    return {};\n  }\n\n  const [_, ...rest] = url.split('?');\n  return querystringDecode(rest.join('?')) as Record<string, string>;\n}\n","/**\n * @license\n * Copyright 2021 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { AuthProvider, PopupRedirectResolver } from '../../model/public_types';\nimport { browserSessionPersistence } from '../../platform_browser/persistence/session_storage';\nimport { AuthInternal } from '../../model/auth';\nimport {\n  AuthEvent,\n  AuthEventType,\n  PopupRedirectResolverInternal\n} from '../../model/popup_redirect';\nimport { AuthPopup } from '../../platform_browser/util/popup';\nimport { _createError, _fail } from '../../core/util/assert';\nimport { AuthErrorCode } from '../../core/errors';\nimport {\n  _checkCordovaConfiguration,\n  _generateHandlerUrl,\n  _performRedirect,\n  _validateOrigin,\n  _waitForAppResume\n} from './utils';\nimport {\n  CordovaAuthEventManager,\n  _eventFromPartialAndUrl,\n  _generateNewEvent,\n  _getAndRemoveEvent,\n  _savePartialEvent\n} from './events';\nimport { AuthEventManager } from '../../core/auth/auth_event_manager';\nimport { _getRedirectResult } from '../../platform_browser/strategies/redirect';\nimport {\n  _clearRedirectOutcomes,\n  _overrideRedirectResult\n} from '../../core/strategies/redirect';\nimport { _cordovaWindow } from '../plugins';\n\n/**\n * How long to wait for the initial auth event before concluding no\n * redirect pending\n */\nconst INITIAL_EVENT_TIMEOUT_MS = 500;\n\nclass CordovaPopupRedirectResolver implements PopupRedirectResolverInternal {\n  readonly _redirectPersistence = browserSessionPersistence;\n  readonly _shouldInitProactively = true; // This is lightweight for Cordova\n  private readonly eventManagers = new Map<string, CordovaAuthEventManager>();\n  private readonly originValidationPromises: Record<string, Promise<void>> = {};\n\n  _completeRedirectFn = _getRedirectResult;\n  _overrideRedirectResult = _overrideRedirectResult;\n\n  async _initialize(auth: AuthInternal): Promise<CordovaAuthEventManager> {\n    const key = auth._key();\n    let manager = this.eventManagers.get(key);\n    if (!manager) {\n      manager = new CordovaAuthEventManager(auth);\n      this.eventManagers.set(key, manager);\n      this.attachCallbackListeners(auth, manager);\n    }\n    return manager;\n  }\n\n  _openPopup(auth: AuthInternal): Promise<AuthPopup> {\n    _fail(auth, AuthErrorCode.OPERATION_NOT_SUPPORTED);\n  }\n\n  async _openRedirect(\n    auth: AuthInternal,\n    provider: AuthProvider,\n    authType: AuthEventType,\n    eventId?: string\n  ): Promise<void> {\n    _checkCordovaConfiguration(auth);\n    const manager = await this._initialize(auth);\n    await manager.initialized();\n\n    // Reset the persisted redirect states. This does not matter on Web where\n    // the redirect always blows away application state entirely. On Cordova,\n    // the app maintains control flow through the redirect.\n    manager.resetRedirect();\n    _clearRedirectOutcomes();\n\n    await this._originValidation(auth);\n\n    const event = _generateNewEvent(auth, authType, eventId);\n    await _savePartialEvent(auth, event);\n    const url = await _generateHandlerUrl(auth, event, provider);\n    const iabRef = await _performRedirect(url);\n    return _waitForAppResume(auth, manager, iabRef);\n  }\n\n  _isIframeWebStorageSupported(\n    _auth: AuthInternal,\n    _cb: (support: boolean) => unknown\n  ): void {\n    throw new Error('Method not implemented.');\n  }\n\n  _originValidation(auth: AuthInternal): Promise<void> {\n    const key = auth._key();\n    if (!this.originValidationPromises[key]) {\n      this.originValidationPromises[key] = _validateOrigin(auth);\n    }\n\n    return this.originValidationPromises[key];\n  }\n\n  private attachCallbackListeners(\n    auth: AuthInternal,\n    manager: AuthEventManager\n  ): void {\n    // Get the global plugins\n    const { universalLinks, handleOpenURL, BuildInfo } = _cordovaWindow();\n\n    const noEventTimeout = setTimeout(async () => {\n      // We didn't see that initial event. Clear any pending object and\n      // dispatch no event\n      await _getAndRemoveEvent(auth);\n      manager.onEvent(generateNoEvent());\n    }, INITIAL_EVENT_TIMEOUT_MS);\n\n    const universalLinksCb = async (\n      eventData: Record<string, string> | null\n    ): Promise<void> => {\n      // We have an event so we can clear the no event timeout\n      clearTimeout(noEventTimeout);\n\n      const partialEvent = await _getAndRemoveEvent(auth);\n      let finalEvent: AuthEvent | null = null;\n      if (partialEvent && eventData?.['url']) {\n        finalEvent = _eventFromPartialAndUrl(partialEvent, eventData['url']);\n      }\n\n      // If finalEvent is never filled, trigger with no event\n      manager.onEvent(finalEvent || generateNoEvent());\n    };\n\n    // Universal links subscriber doesn't exist for iOS, so we need to check\n    if (\n      typeof universalLinks !== 'undefined' &&\n      typeof universalLinks.subscribe === 'function'\n    ) {\n      universalLinks.subscribe(null, universalLinksCb);\n    }\n\n    // iOS 7 or 8 custom URL schemes.\n    // This is also the current default behavior for iOS 9+.\n    // For this to work, cordova-plugin-customurlscheme needs to be installed.\n    // https://github.com/EddyVerbruggen/Custom-URL-scheme\n    // Do not overwrite the existing developer's URL handler.\n    const existingHandleOpenURL = handleOpenURL;\n    const packagePrefix = `${BuildInfo.packageName.toLowerCase()}://`;\n    _cordovaWindow().handleOpenURL = async url => {\n      if (url.toLowerCase().startsWith(packagePrefix)) {\n        // We want this intentionally to float\n        // eslint-disable-next-line @typescript-eslint/no-floating-promises\n        universalLinksCb({ url });\n      }\n      // Call the developer's handler if it is present.\n      if (typeof existingHandleOpenURL === 'function') {\n        try {\n          existingHandleOpenURL(url);\n        } catch (e) {\n          // This is a developer error. Don't stop the flow of the SDK.\n          console.error(e);\n        }\n      }\n    };\n  }\n}\n\n/**\n * An implementation of {@link PopupRedirectResolver} suitable for Cordova\n * based applications.\n *\n * @public\n */\nexport const cordovaPopupRedirectResolver: PopupRedirectResolver =\n  CordovaPopupRedirectResolver;\n\nfunction generateNoEvent(): AuthEvent {\n  return {\n    type: AuthEventType.UNKNOWN,\n    eventId: null,\n    sessionId: null,\n    urlResponse: null,\n    postBody: null,\n    tenantId: null,\n    error: _createError(AuthErrorCode.NO_AUTH_EVENT)\n  };\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/* eslint-disable camelcase */\n\nimport firebase, { _FirebaseNamespace } from '@firebase/app-compat';\nimport * as impl from '@firebase/auth/internal';\nimport {\n  Component,\n  ComponentType,\n  InstantiationMode\n} from '@firebase/component';\nimport { FirebaseError } from '@firebase/util';\n\nimport * as types from '@firebase/auth-types';\nimport { name, version } from './package.json';\nimport { Auth } from './src/auth';\nimport { PhoneAuthProvider as CompatAuthProvider } from './src/phone_auth_provider';\nimport { RecaptchaVerifier as CompatRecaptchaVerifier } from './src/recaptcha_verifier';\n\nconst AUTH_TYPE = 'auth-compat';\n\ndeclare module '@firebase/component' {\n  interface NameServiceMapping {\n    'auth-compat': types.FirebaseAuth;\n  }\n}\n\ndeclare module '@firebase/app-compat' {\n  interface FirebaseNamespace {\n    auth: {\n      (app?: FirebaseApp): types.FirebaseAuth;\n      Auth: typeof types.FirebaseAuth;\n      EmailAuthProvider: typeof types.EmailAuthProvider;\n      EmailAuthProvider_Instance: typeof types.EmailAuthProvider_Instance;\n      FacebookAuthProvider: typeof types.FacebookAuthProvider;\n      FacebookAuthProvider_Instance: typeof types.FacebookAuthProvider_Instance;\n      GithubAuthProvider: typeof types.GithubAuthProvider;\n      GithubAuthProvider_Instance: typeof types.GithubAuthProvider_Instance;\n      GoogleAuthProvider: typeof types.GoogleAuthProvider;\n      GoogleAuthProvider_Instance: typeof types.GoogleAuthProvider_Instance;\n      OAuthProvider: typeof types.OAuthProvider;\n      SAMLAuthProvider: typeof types.SAMLAuthProvider;\n      PhoneAuthProvider: typeof types.PhoneAuthProvider;\n      PhoneAuthProvider_Instance: typeof types.PhoneAuthProvider_Instance;\n      PhoneMultiFactorGenerator: typeof types.PhoneMultiFactorGenerator;\n      RecaptchaVerifier: typeof types.RecaptchaVerifier;\n      RecaptchaVerifier_Instance: typeof types.RecaptchaVerifier_Instance;\n      TwitterAuthProvider: typeof types.TwitterAuthProvider;\n      TwitterAuthProvider_Instance: typeof types.TwitterAuthProvider_Instance;\n    };\n  }\n  interface FirebaseApp {\n    auth?(): types.FirebaseAuth;\n  }\n}\n\n// Create auth components to register with firebase.\n// Provides Auth public APIs.\nfunction registerAuthCompat(instance: _FirebaseNamespace): void {\n  instance.INTERNAL.registerComponent(\n    new Component(\n      AUTH_TYPE,\n      container => {\n        // getImmediate for FirebaseApp will always succeed\n        const app = container.getProvider('app-compat').getImmediate();\n        const authProvider = container.getProvider('auth');\n        return new Auth(app, authProvider);\n      },\n      ComponentType.PUBLIC\n    )\n      .setServiceProps({\n        ActionCodeInfo: {\n          Operation: {\n            EMAIL_SIGNIN: impl.ActionCodeOperation.EMAIL_SIGNIN,\n            PASSWORD_RESET: impl.ActionCodeOperation.PASSWORD_RESET,\n            RECOVER_EMAIL: impl.ActionCodeOperation.RECOVER_EMAIL,\n            REVERT_SECOND_FACTOR_ADDITION:\n              impl.ActionCodeOperation.REVERT_SECOND_FACTOR_ADDITION,\n            VERIFY_AND_CHANGE_EMAIL:\n              impl.ActionCodeOperation.VERIFY_AND_CHANGE_EMAIL,\n            VERIFY_EMAIL: impl.ActionCodeOperation.VERIFY_EMAIL\n          }\n        },\n        EmailAuthProvider: impl.EmailAuthProvider,\n        FacebookAuthProvider: impl.FacebookAuthProvider,\n        GithubAuthProvider: impl.GithubAuthProvider,\n        GoogleAuthProvider: impl.GoogleAuthProvider,\n        OAuthProvider: impl.OAuthProvider,\n        SAMLAuthProvider: impl.SAMLAuthProvider,\n        PhoneAuthProvider: CompatAuthProvider,\n        PhoneMultiFactorGenerator: impl.PhoneMultiFactorGenerator,\n        RecaptchaVerifier: CompatRecaptchaVerifier,\n        TwitterAuthProvider: impl.TwitterAuthProvider,\n        Auth,\n        AuthCredential: impl.AuthCredential,\n        Error: FirebaseError\n      })\n      .setInstantiationMode(InstantiationMode.LAZY)\n      .setMultipleInstances(false)\n  );\n\n  instance.registerVersion(name, version);\n}\n\nregisterAuthCompat(firebase as _FirebaseNamespace);\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport * as impl from '@firebase/auth/internal';\nimport {\n  getUA,\n  isBrowserExtension,\n  isReactNative,\n  isNode,\n  isIE,\n  isIndexedDBAvailable\n} from '@firebase/util';\n\ndeclare global {\n  interface Document {\n    documentMode?: number;\n  }\n}\n\nconst CORDOVA_ONDEVICEREADY_TIMEOUT_MS = 1000;\n\nfunction _getCurrentScheme(): string | null {\n  return self?.location?.protocol || null;\n}\n\n/**\n * @return {boolean} Whether the current environment is http or https.\n */\nfunction _isHttpOrHttps(): boolean {\n  return _getCurrentScheme() === 'http:' || _getCurrentScheme() === 'https:';\n}\n\n/**\n * @param {?string=} ua The user agent.\n * @return {boolean} Whether the app is rendered in a mobile iOS or Android\n *     Cordova environment.\n */\nexport function _isAndroidOrIosCordovaScheme(ua: string = getUA()): boolean {\n  return !!(\n    (_getCurrentScheme() === 'file:' ||\n      _getCurrentScheme() === 'ionic:' ||\n      _getCurrentScheme() === 'capacitor:') &&\n    ua.toLowerCase().match(/iphone|ipad|ipod|android/)\n  );\n}\n\n/**\n * @return {boolean} Whether the environment is a native environment, where\n *     CORS checks do not apply.\n */\nfunction _isNativeEnvironment(): boolean {\n  return isReactNative() || isNode();\n}\n\n/**\n * Checks whether the user agent is IE11.\n * @return {boolean} True if it is IE11.\n */\nfunction _isIe11(): boolean {\n  return isIE() && document?.documentMode === 11;\n}\n\n/**\n * Checks whether the user agent is Edge.\n * @param {string} userAgent The browser user agent string.\n * @return {boolean} True if it is Edge.\n */\nfunction _isEdge(ua: string = getUA()): boolean {\n  return /Edge\\/\\d+/.test(ua);\n}\n\n/**\n * @param {?string=} opt_userAgent The navigator user agent.\n * @return {boolean} Whether local storage is not synchronized between an iframe\n *     and a popup of the same domain.\n */\nfunction _isLocalStorageNotSynchronized(ua: string = getUA()): boolean {\n  return _isIe11() || _isEdge(ua);\n}\n\n/** @return {boolean} Whether web storage is supported. */\nexport function _isWebStorageSupported(): boolean {\n  try {\n    const storage = self.localStorage;\n    const key = impl._generateEventId();\n    if (storage) {\n      // setItem will throw an exception if we cannot access WebStorage (e.g.,\n      // Safari in private mode).\n      storage['setItem'](key, '1');\n      storage['removeItem'](key);\n      // For browsers where iframe web storage does not synchronize with a popup\n      // of the same domain, indexedDB is used for persistent storage. These\n      // browsers include IE11 and Edge.\n      // Make sure it is supported (IE11 and Edge private mode does not support\n      // that).\n      if (_isLocalStorageNotSynchronized()) {\n        // In such browsers, if indexedDB is not supported, an iframe cannot be\n        // notified of the popup sign in result.\n        return isIndexedDBAvailable();\n      }\n      return true;\n    }\n  } catch (e) {\n    // localStorage is not available from a worker. Test availability of\n    // indexedDB.\n    return _isWorker() && isIndexedDBAvailable();\n  }\n  return false;\n}\n\n/**\n * @param {?Object=} global The optional global scope.\n * @return {boolean} Whether current environment is a worker.\n */\nexport function _isWorker(): boolean {\n  // WorkerGlobalScope only defined in worker environment.\n  return (\n    typeof global !== 'undefined' &&\n    'WorkerGlobalScope' in global &&\n    'importScripts' in global\n  );\n}\n\nexport function _isPopupRedirectSupported(): boolean {\n  return (\n    (_isHttpOrHttps() ||\n      isBrowserExtension() ||\n      _isAndroidOrIosCordovaScheme()) &&\n    // React Native with remote debugging reports its location.protocol as\n    // http.\n    !_isNativeEnvironment() &&\n    // Local storage has to be supported for browser popup and redirect\n    // operations to work.\n    _isWebStorageSupported() &&\n    // DOM, popups and redirects are not supported within a worker.\n    !_isWorker()\n  );\n}\n\n/** Quick check that indicates the platform *may* be Cordova */\nexport function _isLikelyCordova(): boolean {\n  return _isAndroidOrIosCordovaScheme() && typeof document !== 'undefined';\n}\n\nexport async function _isCordova(): Promise<boolean> {\n  if (!_isLikelyCordova()) {\n    return false;\n  }\n\n  return new Promise(resolve => {\n    const timeoutId = setTimeout(() => {\n      // We've waited long enough; the telltale Cordova event didn't happen\n      resolve(false);\n    }, CORDOVA_ONDEVICEREADY_TIMEOUT_MS);\n\n    document.addEventListener('deviceready', () => {\n      clearTimeout(timeoutId);\n      resolve(true);\n    });\n  });\n}\n\nexport function _getSelfWindow(): Window | null {\n  return typeof window !== 'undefined' ? window : null;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport * as exp from '@firebase/auth/internal';\nimport { isIndexedDBAvailable, isNode, isReactNative } from '@firebase/util';\nimport { _getSelfWindow, _isWebStorageSupported, _isWorker } from './platform';\n\nexport const Persistence = {\n  LOCAL: 'local',\n  NONE: 'none',\n  SESSION: 'session'\n};\n\nconst _assert: typeof exp._assert = exp._assert;\n\nconst PERSISTENCE_KEY = 'persistence';\n\n/**\n * Validates that an argument is a valid persistence value. If an invalid type\n * is specified, an error is thrown synchronously.\n */\nexport function _validatePersistenceArgument(\n  auth: exp.Auth,\n  persistence: string\n): void {\n  _assert(\n    Object.values(Persistence).includes(persistence),\n    auth,\n    exp.AuthErrorCode.INVALID_PERSISTENCE\n  );\n  // Validate if the specified type is supported in the current environment.\n  if (isReactNative()) {\n    // This is only supported in a browser.\n    _assert(\n      persistence !== Persistence.SESSION,\n      auth,\n      exp.AuthErrorCode.UNSUPPORTED_PERSISTENCE\n    );\n    return;\n  }\n  if (isNode()) {\n    // Only none is supported in Node.js.\n    _assert(\n      persistence === Persistence.NONE,\n      auth,\n      exp.AuthErrorCode.UNSUPPORTED_PERSISTENCE\n    );\n    return;\n  }\n  if (_isWorker()) {\n    // In a worker environment, either LOCAL or NONE are supported.\n    // If indexedDB not supported and LOCAL provided, throw an error\n    _assert(\n      persistence === Persistence.NONE ||\n        (persistence === Persistence.LOCAL && isIndexedDBAvailable()),\n      auth,\n      exp.AuthErrorCode.UNSUPPORTED_PERSISTENCE\n    );\n    return;\n  }\n  // This is restricted by what the browser supports.\n  _assert(\n    persistence === Persistence.NONE || _isWebStorageSupported(),\n    auth,\n    exp.AuthErrorCode.UNSUPPORTED_PERSISTENCE\n  );\n}\n\nexport async function _savePersistenceForRedirect(\n  auth: exp.AuthInternal\n): Promise<void> {\n  await auth._initializationPromise;\n  const session = getSessionStorageIfAvailable();\n  const key = exp._persistenceKeyName(\n    PERSISTENCE_KEY,\n    auth.config.apiKey,\n    auth.name\n  );\n  if (session) {\n    session.setItem(key, auth._getPersistenceType());\n  }\n}\n\nexport function _getPersistencesFromRedirect(\n  apiKey: string,\n  appName: string\n): exp.Persistence[] {\n  const session = getSessionStorageIfAvailable();\n  if (!session) {\n    return [];\n  }\n\n  const key = exp._persistenceKeyName(PERSISTENCE_KEY, apiKey, appName);\n  const persistence = session.getItem(key);\n\n  switch (persistence) {\n    case Persistence.NONE:\n      return [exp.inMemoryPersistence];\n    case Persistence.LOCAL:\n      return [exp.indexedDBLocalPersistence, exp.browserSessionPersistence];\n    case Persistence.SESSION:\n      return [exp.browserSessionPersistence];\n    default:\n      return [];\n  }\n}\n\n/** Returns session storage, or null if the property access errors */\nfunction getSessionStorageIfAvailable(): Storage | null {\n  try {\n    return _getSelfWindow()?.sessionStorage || null;\n  } catch (e) {\n    return null;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport * as exp from '@firebase/auth/internal';\nimport { _isCordova, _isLikelyCordova } from './platform';\n\nconst _assert: typeof exp._assert = exp._assert;\n\n/** Platform-agnostic popup-redirect resolver */\nexport class CompatPopupRedirectResolver\n  implements exp.PopupRedirectResolverInternal\n{\n  // Create both resolvers for dynamic resolution later\n  private readonly browserResolver: exp.PopupRedirectResolverInternal =\n    exp._getInstance(exp.browserPopupRedirectResolver);\n  private readonly cordovaResolver: exp.PopupRedirectResolverInternal =\n    exp._getInstance(exp.cordovaPopupRedirectResolver);\n  // The actual resolver in use: either browserResolver or cordovaResolver.\n  private underlyingResolver: exp.PopupRedirectResolverInternal | null = null;\n  _redirectPersistence = exp.browserSessionPersistence;\n\n  _completeRedirectFn: (\n    auth: exp.Auth,\n    resolver: exp.PopupRedirectResolver,\n    bypassAuthState: boolean\n  ) => Promise<exp.UserCredential | null> = exp._getRedirectResult;\n  _overrideRedirectResult = exp._overrideRedirectResult;\n\n  async _initialize(auth: exp.AuthImpl): Promise<exp.EventManager> {\n    await this.selectUnderlyingResolver();\n    return this.assertedUnderlyingResolver._initialize(auth);\n  }\n\n  async _openPopup(\n    auth: exp.AuthImpl,\n    provider: exp.AuthProvider,\n    authType: exp.AuthEventType,\n    eventId?: string\n  ): Promise<exp.AuthPopup> {\n    await this.selectUnderlyingResolver();\n    return this.assertedUnderlyingResolver._openPopup(\n      auth,\n      provider,\n      authType,\n      eventId\n    );\n  }\n\n  async _openRedirect(\n    auth: exp.AuthImpl,\n    provider: exp.AuthProvider,\n    authType: exp.AuthEventType,\n    eventId?: string\n  ): Promise<void> {\n    await this.selectUnderlyingResolver();\n    return this.assertedUnderlyingResolver._openRedirect(\n      auth,\n      provider,\n      authType,\n      eventId\n    );\n  }\n\n  _isIframeWebStorageSupported(\n    auth: exp.AuthImpl,\n    cb: (support: boolean) => unknown\n  ): void {\n    this.assertedUnderlyingResolver._isIframeWebStorageSupported(auth, cb);\n  }\n\n  _originValidation(auth: exp.Auth): Promise<void> {\n    return this.assertedUnderlyingResolver._originValidation(auth);\n  }\n\n  get _shouldInitProactively(): boolean {\n    return _isLikelyCordova() || this.browserResolver._shouldInitProactively;\n  }\n\n  private get assertedUnderlyingResolver(): exp.PopupRedirectResolverInternal {\n    _assert(this.underlyingResolver, exp.AuthErrorCode.INTERNAL_ERROR);\n    return this.underlyingResolver;\n  }\n\n  private async selectUnderlyingResolver(): Promise<void> {\n    if (this.underlyingResolver) {\n      return;\n    }\n\n    // We haven't yet determined whether or not we're in Cordova; go ahead\n    // and determine that state now.\n    const isCordova = await _isCordova();\n    this.underlyingResolver = isCordova\n      ? this.cordovaResolver\n      : this.browserResolver;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\n/** Forward direction wrapper from Compat --unwrap-> Exp */\nexport interface Wrapper<T> {\n  unwrap(): T;\n}\n\n/** Reverse direction wrapper from Exp --wrapped--> Compat */\nexport interface ReverseWrapper<T> {\n  wrapped(): T;\n}\n\nexport function unwrap<T>(object: unknown): T {\n  return (object as Wrapper<T>).unwrap();\n}\n\nexport function wrapped<T>(object: unknown): T {\n  return (object as ReverseWrapper<T>).wrapped();\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport * as exp from '@firebase/auth/internal';\nimport * as compat from '@firebase/auth-types';\nimport { FirebaseError } from '@firebase/util';\nimport { Auth } from './auth';\nimport { User } from './user';\nimport { unwrap, wrapped } from './wrap';\n\nfunction credentialFromResponse(\n  userCredential: exp.UserCredentialInternal\n): exp.AuthCredential | null {\n  return credentialFromObject(userCredential);\n}\n\nfunction attachExtraErrorFields(auth: exp.Auth, e: FirebaseError): void {\n  // The response contains all fields from the server which may or may not\n  // actually match the underlying type\n  const response = (e.customData as exp.TaggedWithTokenResponse | undefined)\n    ?._tokenResponse as unknown as Record<string, string>;\n  if ((e as FirebaseError)?.code === 'auth/multi-factor-auth-required') {\n    const mfaErr = e as compat.MultiFactorError;\n    mfaErr.resolver = new MultiFactorResolver(\n      auth,\n      exp.getMultiFactorResolver(auth, e as exp.MultiFactorError)\n    );\n  } else if (response) {\n    const credential = credentialFromObject(e);\n    const credErr = e as compat.AuthError;\n    if (credential) {\n      credErr.credential = credential;\n      credErr.tenantId = response.tenantId || undefined;\n      credErr.email = response.email || undefined;\n      credErr.phoneNumber = response.phoneNumber || undefined;\n    }\n  }\n}\n\nfunction credentialFromObject(\n  object: FirebaseError | exp.UserCredential\n): exp.AuthCredential | null {\n  const { _tokenResponse } = (\n    object instanceof FirebaseError ? object.customData : object\n  ) as exp.TaggedWithTokenResponse;\n  if (!_tokenResponse) {\n    return null;\n  }\n\n  // Handle phone Auth credential responses, as they have a different format\n  // from other backend responses (i.e. no providerId). This is also only the\n  // case for user credentials (does not work for errors).\n  if (!(object instanceof FirebaseError)) {\n    if ('temporaryProof' in _tokenResponse && 'phoneNumber' in _tokenResponse) {\n      return exp.PhoneAuthProvider.credentialFromResult(object);\n    }\n  }\n\n  const providerId = _tokenResponse.providerId;\n\n  // Email and password is not supported as there is no situation where the\n  // server would return the password to the client.\n  if (!providerId || providerId === exp.ProviderId.PASSWORD) {\n    return null;\n  }\n\n  let provider: Pick<\n    typeof exp.OAuthProvider,\n    'credentialFromResult' | 'credentialFromError'\n  >;\n  switch (providerId) {\n    case exp.ProviderId.GOOGLE:\n      provider = exp.GoogleAuthProvider;\n      break;\n    case exp.ProviderId.FACEBOOK:\n      provider = exp.FacebookAuthProvider;\n      break;\n    case exp.ProviderId.GITHUB:\n      provider = exp.GithubAuthProvider;\n      break;\n    case exp.ProviderId.TWITTER:\n      provider = exp.TwitterAuthProvider;\n      break;\n    default:\n      const {\n        oauthIdToken,\n        oauthAccessToken,\n        oauthTokenSecret,\n        pendingToken,\n        nonce\n      } = _tokenResponse as exp.SignInWithIdpResponse;\n      if (\n        !oauthAccessToken &&\n        !oauthTokenSecret &&\n        !oauthIdToken &&\n        !pendingToken\n      ) {\n        return null;\n      }\n      // TODO(avolkovi): uncomment this and get it working with SAML & OIDC\n      if (pendingToken) {\n        if (providerId.startsWith('saml.')) {\n          return exp.SAMLAuthCredential._create(providerId, pendingToken);\n        } else {\n          // OIDC and non-default providers excluding Twitter.\n          return exp.OAuthCredential._fromParams({\n            providerId,\n            signInMethod: providerId,\n            pendingToken,\n            idToken: oauthIdToken,\n            accessToken: oauthAccessToken\n          });\n        }\n      }\n      return new exp.OAuthProvider(providerId).credential({\n        idToken: oauthIdToken,\n        accessToken: oauthAccessToken,\n        rawNonce: nonce\n      });\n  }\n\n  return object instanceof FirebaseError\n    ? provider.credentialFromError(object)\n    : provider.credentialFromResult(object);\n}\n\nexport function convertCredential(\n  auth: exp.Auth,\n  credentialPromise: Promise<exp.UserCredential>\n): Promise<compat.UserCredential> {\n  return credentialPromise\n    .catch(e => {\n      if (e instanceof FirebaseError) {\n        attachExtraErrorFields(auth, e);\n      }\n      throw e;\n    })\n    .then(credential => {\n      const operationType = credential.operationType;\n      const user = credential.user;\n\n      return {\n        operationType,\n        credential: credentialFromResponse(\n          credential as exp.UserCredentialInternal\n        ),\n        additionalUserInfo: exp.getAdditionalUserInfo(\n          credential as exp.UserCredential\n        ),\n        user: User.getOrCreate(user)\n      };\n    });\n}\n\nexport async function convertConfirmationResult(\n  auth: exp.Auth,\n  confirmationResultPromise: Promise<exp.ConfirmationResult>\n): Promise<compat.ConfirmationResult> {\n  const confirmationResultExp = await confirmationResultPromise;\n  return {\n    verificationId: confirmationResultExp.verificationId,\n    confirm: (verificationCode: string) =>\n      convertCredential(auth, confirmationResultExp.confirm(verificationCode))\n  };\n}\n\nclass MultiFactorResolver implements compat.MultiFactorResolver {\n  readonly auth: Auth;\n  constructor(\n    auth: exp.Auth,\n    private readonly resolver: exp.MultiFactorResolver\n  ) {\n    this.auth = wrapped(auth);\n  }\n\n  get session(): compat.MultiFactorSession {\n    return this.resolver.session;\n  }\n\n  get hints(): compat.MultiFactorInfo[] {\n    return this.resolver.hints;\n  }\n\n  resolveSignIn(\n    assertion: compat.MultiFactorAssertion\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      unwrap(this.auth),\n      this.resolver.resolveSignIn(assertion as exp.MultiFactorAssertion)\n    );\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport * as exp from '@firebase/auth/internal';\nimport * as compat from '@firebase/auth-types';\nimport { Compat } from '@firebase/util';\nimport { _savePersistenceForRedirect } from './persistence';\nimport { CompatPopupRedirectResolver } from './popup_redirect';\nimport {\n  convertConfirmationResult,\n  convertCredential\n} from './user_credential';\n\nexport class User implements compat.User, Compat<exp.User> {\n  // Maintain a map so that there's always a 1:1 mapping between new User and\n  // legacy compat users\n  private static readonly USER_MAP = new WeakMap<exp.User, User>();\n\n  readonly multiFactor: compat.MultiFactorUser;\n\n  private constructor(readonly _delegate: exp.User) {\n    this.multiFactor = exp.multiFactor(_delegate);\n  }\n\n  static getOrCreate(user: exp.User): User {\n    if (!User.USER_MAP.has(user)) {\n      User.USER_MAP.set(user, new User(user));\n    }\n\n    return User.USER_MAP.get(user)!;\n  }\n\n  delete(): Promise<void> {\n    return this._delegate.delete();\n  }\n  reload(): Promise<void> {\n    return this._delegate.reload();\n  }\n  toJSON(): object {\n    return this._delegate.toJSON();\n  }\n  getIdTokenResult(forceRefresh?: boolean): Promise<compat.IdTokenResult> {\n    return this._delegate.getIdTokenResult(forceRefresh);\n  }\n  getIdToken(forceRefresh?: boolean): Promise<string> {\n    return this._delegate.getIdToken(forceRefresh);\n  }\n  linkAndRetrieveDataWithCredential(\n    credential: compat.AuthCredential\n  ): Promise<compat.UserCredential> {\n    return this.linkWithCredential(credential);\n  }\n  async linkWithCredential(\n    credential: compat.AuthCredential\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this.auth,\n      exp.linkWithCredential(this._delegate, credential as exp.AuthCredential)\n    );\n  }\n  async linkWithPhoneNumber(\n    phoneNumber: string,\n    applicationVerifier: compat.ApplicationVerifier\n  ): Promise<compat.ConfirmationResult> {\n    return convertConfirmationResult(\n      this.auth,\n      exp.linkWithPhoneNumber(this._delegate, phoneNumber, applicationVerifier)\n    );\n  }\n  async linkWithPopup(\n    provider: compat.AuthProvider\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this.auth,\n      exp.linkWithPopup(\n        this._delegate,\n        provider as exp.AuthProvider,\n        CompatPopupRedirectResolver\n      )\n    );\n  }\n  async linkWithRedirect(provider: compat.AuthProvider): Promise<void> {\n    await _savePersistenceForRedirect(exp._castAuth(this.auth));\n    return exp.linkWithRedirect(\n      this._delegate,\n      provider as exp.AuthProvider,\n      CompatPopupRedirectResolver\n    );\n  }\n  reauthenticateAndRetrieveDataWithCredential(\n    credential: compat.AuthCredential\n  ): Promise<compat.UserCredential> {\n    return this.reauthenticateWithCredential(credential);\n  }\n  async reauthenticateWithCredential(\n    credential: compat.AuthCredential\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this.auth as unknown as exp.Auth,\n      exp.reauthenticateWithCredential(\n        this._delegate,\n        credential as exp.AuthCredential\n      )\n    );\n  }\n  reauthenticateWithPhoneNumber(\n    phoneNumber: string,\n    applicationVerifier: compat.ApplicationVerifier\n  ): Promise<compat.ConfirmationResult> {\n    return convertConfirmationResult(\n      this.auth,\n      exp.reauthenticateWithPhoneNumber(\n        this._delegate,\n        phoneNumber,\n        applicationVerifier\n      )\n    );\n  }\n  reauthenticateWithPopup(\n    provider: compat.AuthProvider\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this.auth,\n      exp.reauthenticateWithPopup(\n        this._delegate,\n        provider as exp.AuthProvider,\n        CompatPopupRedirectResolver\n      )\n    );\n  }\n  async reauthenticateWithRedirect(\n    provider: compat.AuthProvider\n  ): Promise<void> {\n    await _savePersistenceForRedirect(exp._castAuth(this.auth));\n    return exp.reauthenticateWithRedirect(\n      this._delegate,\n      provider as exp.AuthProvider,\n      CompatPopupRedirectResolver\n    );\n  }\n  sendEmailVerification(\n    actionCodeSettings?: compat.ActionCodeSettings | null\n  ): Promise<void> {\n    return exp.sendEmailVerification(this._delegate, actionCodeSettings);\n  }\n  async unlink(providerId: string): Promise<compat.User> {\n    await exp.unlink(this._delegate, providerId);\n    return this;\n  }\n  updateEmail(newEmail: string): Promise<void> {\n    return exp.updateEmail(this._delegate, newEmail);\n  }\n  updatePassword(newPassword: string): Promise<void> {\n    return exp.updatePassword(this._delegate, newPassword);\n  }\n  updatePhoneNumber(phoneCredential: compat.AuthCredential): Promise<void> {\n    return exp.updatePhoneNumber(\n      this._delegate,\n      phoneCredential as exp.PhoneAuthCredential\n    );\n  }\n  updateProfile(profile: {\n    displayName?: string | null;\n    photoURL?: string | null;\n  }): Promise<void> {\n    return exp.updateProfile(this._delegate, profile);\n  }\n  verifyBeforeUpdateEmail(\n    newEmail: string,\n    actionCodeSettings?: compat.ActionCodeSettings | null\n  ): Promise<void> {\n    return exp.verifyBeforeUpdateEmail(\n      this._delegate,\n      newEmail,\n      actionCodeSettings\n    );\n  }\n  get emailVerified(): boolean {\n    return this._delegate.emailVerified;\n  }\n  get isAnonymous(): boolean {\n    return this._delegate.isAnonymous;\n  }\n  get metadata(): compat.UserMetadata {\n    return this._delegate.metadata;\n  }\n  get phoneNumber(): string | null {\n    return this._delegate.phoneNumber;\n  }\n  get providerData(): Array<compat.UserInfo | null> {\n    return this._delegate.providerData;\n  }\n  get refreshToken(): string {\n    return this._delegate.refreshToken;\n  }\n  get tenantId(): string | null {\n    return this._delegate.tenantId;\n  }\n  get displayName(): string | null {\n    return this._delegate.displayName;\n  }\n  get email(): string | null {\n    return this._delegate.email;\n  }\n  get photoURL(): string | null {\n    return this._delegate.photoURL;\n  }\n  get providerId(): string {\n    return this._delegate.providerId;\n  }\n  get uid(): string {\n    return this._delegate.uid;\n  }\n  private get auth(): exp.Auth {\n    return (this._delegate as exp.UserImpl).auth as unknown as exp.Auth;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { FirebaseApp, _FirebaseService } from '@firebase/app-compat';\nimport * as exp from '@firebase/auth/internal';\nimport * as compat from '@firebase/auth-types';\nimport { Provider } from '@firebase/component';\nimport { ErrorFn, Observer, Unsubscribe } from '@firebase/util';\n\nimport {\n  _validatePersistenceArgument,\n  Persistence,\n  _getPersistencesFromRedirect,\n  _savePersistenceForRedirect\n} from './persistence';\nimport { _isPopupRedirectSupported } from './platform';\nimport { CompatPopupRedirectResolver } from './popup_redirect';\nimport { User } from './user';\nimport {\n  convertConfirmationResult,\n  convertCredential\n} from './user_credential';\nimport { ReverseWrapper, Wrapper } from './wrap';\n\nconst _assert: typeof exp._assert = exp._assert;\n\nexport class Auth\n  implements compat.FirebaseAuth, Wrapper<exp.Auth>, _FirebaseService\n{\n  static Persistence = Persistence;\n  readonly _delegate: exp.AuthImpl;\n\n  constructor(readonly app: FirebaseApp, provider: Provider<'auth'>) {\n    if (provider.isInitialized()) {\n      this._delegate = provider.getImmediate() as exp.AuthImpl;\n      this.linkUnderlyingAuth();\n      return;\n    }\n\n    const { apiKey } = app.options;\n    // TODO: platform needs to be determined using heuristics\n    _assert(apiKey, exp.AuthErrorCode.INVALID_API_KEY, {\n      appName: app.name\n    });\n\n    // TODO: platform needs to be determined using heuristics\n    _assert(apiKey, exp.AuthErrorCode.INVALID_API_KEY, {\n      appName: app.name\n    });\n\n    // Only use a popup/redirect resolver in browser environments\n    const resolver =\n      typeof window !== 'undefined' ? CompatPopupRedirectResolver : undefined;\n    this._delegate = provider.initialize({\n      options: {\n        persistence: buildPersistenceHierarchy(apiKey, app.name),\n        popupRedirectResolver: resolver\n      }\n    }) as exp.AuthImpl;\n\n    this._delegate._updateErrorMap(exp.debugErrorMap);\n    this.linkUnderlyingAuth();\n  }\n\n  get emulatorConfig(): compat.EmulatorConfig | null {\n    return this._delegate.emulatorConfig;\n  }\n\n  get currentUser(): compat.User | null {\n    if (!this._delegate.currentUser) {\n      return null;\n    }\n\n    return User.getOrCreate(this._delegate.currentUser);\n  }\n  get languageCode(): string | null {\n    return this._delegate.languageCode;\n  }\n  set languageCode(languageCode: string | null) {\n    this._delegate.languageCode = languageCode;\n  }\n  get settings(): compat.AuthSettings {\n    return this._delegate.settings;\n  }\n  get tenantId(): string | null {\n    return this._delegate.tenantId;\n  }\n  set tenantId(tid: string | null) {\n    this._delegate.tenantId = tid;\n  }\n  useDeviceLanguage(): void {\n    this._delegate.useDeviceLanguage();\n  }\n  signOut(): Promise<void> {\n    return this._delegate.signOut();\n  }\n  useEmulator(url: string, options?: { disableWarnings: boolean }): void {\n    exp.connectAuthEmulator(this._delegate, url, options);\n  }\n  applyActionCode(code: string): Promise<void> {\n    return exp.applyActionCode(this._delegate, code);\n  }\n\n  checkActionCode(code: string): Promise<compat.ActionCodeInfo> {\n    return exp.checkActionCode(this._delegate, code);\n  }\n\n  confirmPasswordReset(code: string, newPassword: string): Promise<void> {\n    return exp.confirmPasswordReset(this._delegate, code, newPassword);\n  }\n\n  async createUserWithEmailAndPassword(\n    email: string,\n    password: string\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this._delegate,\n      exp.createUserWithEmailAndPassword(this._delegate, email, password)\n    );\n  }\n  fetchProvidersForEmail(email: string): Promise<string[]> {\n    return this.fetchSignInMethodsForEmail(email);\n  }\n  fetchSignInMethodsForEmail(email: string): Promise<string[]> {\n    return exp.fetchSignInMethodsForEmail(this._delegate, email);\n  }\n  isSignInWithEmailLink(emailLink: string): boolean {\n    return exp.isSignInWithEmailLink(this._delegate, emailLink);\n  }\n  async getRedirectResult(): Promise<compat.UserCredential> {\n    _assert(\n      _isPopupRedirectSupported(),\n      this._delegate,\n      exp.AuthErrorCode.OPERATION_NOT_SUPPORTED\n    );\n    const credential = await exp.getRedirectResult(\n      this._delegate,\n      CompatPopupRedirectResolver\n    );\n    if (!credential) {\n      return {\n        credential: null,\n        user: null\n      };\n    }\n    return convertCredential(this._delegate, Promise.resolve(credential));\n  }\n\n  // This function should only be called by frameworks (e.g. FirebaseUI-web) to log their usage.\n  // It is not intended for direct use by developer apps. NO jsdoc here to intentionally leave it\n  // out of autogenerated documentation pages to reduce accidental misuse.\n  addFrameworkForLogging(framework: string): void {\n    exp.addFrameworkForLogging(this._delegate, framework);\n  }\n\n  onAuthStateChanged(\n    nextOrObserver: Observer<unknown> | ((a: compat.User | null) => unknown),\n    errorFn?: (error: compat.Error) => unknown,\n    completed?: Unsubscribe\n  ): Unsubscribe {\n    const { next, error, complete } = wrapObservers(\n      nextOrObserver,\n      errorFn,\n      completed\n    );\n    return this._delegate.onAuthStateChanged(next!, error, complete);\n  }\n  onIdTokenChanged(\n    nextOrObserver: Observer<unknown> | ((a: compat.User | null) => unknown),\n    errorFn?: (error: compat.Error) => unknown,\n    completed?: Unsubscribe\n  ): Unsubscribe {\n    const { next, error, complete } = wrapObservers(\n      nextOrObserver,\n      errorFn,\n      completed\n    );\n    return this._delegate.onIdTokenChanged(next!, error, complete);\n  }\n  sendSignInLinkToEmail(\n    email: string,\n    actionCodeSettings: compat.ActionCodeSettings\n  ): Promise<void> {\n    return exp.sendSignInLinkToEmail(this._delegate, email, actionCodeSettings);\n  }\n  sendPasswordResetEmail(\n    email: string,\n    actionCodeSettings?: compat.ActionCodeSettings | null\n  ): Promise<void> {\n    return exp.sendPasswordResetEmail(\n      this._delegate,\n      email,\n      actionCodeSettings || undefined\n    );\n  }\n  async setPersistence(persistence: string): Promise<void> {\n    _validatePersistenceArgument(this._delegate, persistence);\n    let converted;\n    switch (persistence) {\n      case Persistence.SESSION:\n        converted = exp.browserSessionPersistence;\n        break;\n      case Persistence.LOCAL:\n        // Not using isIndexedDBAvailable() since it only checks if indexedDB is defined.\n        const isIndexedDBFullySupported = await exp\n          ._getInstance<exp.PersistenceInternal>(exp.indexedDBLocalPersistence)\n          ._isAvailable();\n        converted = isIndexedDBFullySupported\n          ? exp.indexedDBLocalPersistence\n          : exp.browserLocalPersistence;\n        break;\n      case Persistence.NONE:\n        converted = exp.inMemoryPersistence;\n        break;\n      default:\n        return exp._fail(exp.AuthErrorCode.ARGUMENT_ERROR, {\n          appName: this._delegate.name\n        });\n    }\n\n    return this._delegate.setPersistence(converted);\n  }\n\n  signInAndRetrieveDataWithCredential(\n    credential: compat.AuthCredential\n  ): Promise<compat.UserCredential> {\n    return this.signInWithCredential(credential);\n  }\n  signInAnonymously(): Promise<compat.UserCredential> {\n    return convertCredential(\n      this._delegate,\n      exp.signInAnonymously(this._delegate)\n    );\n  }\n  signInWithCredential(\n    credential: compat.AuthCredential\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this._delegate,\n      exp.signInWithCredential(this._delegate, credential as exp.AuthCredential)\n    );\n  }\n  signInWithCustomToken(token: string): Promise<compat.UserCredential> {\n    return convertCredential(\n      this._delegate,\n      exp.signInWithCustomToken(this._delegate, token)\n    );\n  }\n  signInWithEmailAndPassword(\n    email: string,\n    password: string\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this._delegate,\n      exp.signInWithEmailAndPassword(this._delegate, email, password)\n    );\n  }\n  signInWithEmailLink(\n    email: string,\n    emailLink?: string\n  ): Promise<compat.UserCredential> {\n    return convertCredential(\n      this._delegate,\n      exp.signInWithEmailLink(this._delegate, email, emailLink)\n    );\n  }\n  signInWithPhoneNumber(\n    phoneNumber: string,\n    applicationVerifier: compat.ApplicationVerifier\n  ): Promise<compat.ConfirmationResult> {\n    return convertConfirmationResult(\n      this._delegate,\n      exp.signInWithPhoneNumber(\n        this._delegate,\n        phoneNumber,\n        applicationVerifier\n      )\n    );\n  }\n  async signInWithPopup(\n    provider: compat.AuthProvider\n  ): Promise<compat.UserCredential> {\n    _assert(\n      _isPopupRedirectSupported(),\n      this._delegate,\n      exp.AuthErrorCode.OPERATION_NOT_SUPPORTED\n    );\n    return convertCredential(\n      this._delegate,\n      exp.signInWithPopup(\n        this._delegate,\n        provider as exp.AuthProvider,\n        CompatPopupRedirectResolver\n      )\n    );\n  }\n  async signInWithRedirect(provider: compat.AuthProvider): Promise<void> {\n    _assert(\n      _isPopupRedirectSupported(),\n      this._delegate,\n      exp.AuthErrorCode.OPERATION_NOT_SUPPORTED\n    );\n\n    await _savePersistenceForRedirect(this._delegate);\n    return exp.signInWithRedirect(\n      this._delegate,\n      provider as exp.AuthProvider,\n      CompatPopupRedirectResolver\n    );\n  }\n  updateCurrentUser(user: compat.User | null): Promise<void> {\n    // remove ts-ignore once overloads are defined for exp functions to accept compat objects\n    // @ts-ignore\n    return this._delegate.updateCurrentUser(user);\n  }\n  verifyPasswordResetCode(code: string): Promise<string> {\n    return exp.verifyPasswordResetCode(this._delegate, code);\n  }\n  unwrap(): exp.Auth {\n    return this._delegate;\n  }\n  _delete(): Promise<void> {\n    return this._delegate._delete();\n  }\n  private linkUnderlyingAuth(): void {\n    (this._delegate as unknown as ReverseWrapper<Auth>).wrapped = () => this;\n  }\n}\n\nfunction wrapObservers(\n  nextOrObserver: Observer<unknown> | ((a: compat.User | null) => unknown),\n  error?: (error: compat.Error) => unknown,\n  complete?: Unsubscribe\n): Partial<Observer<exp.User | null>> {\n  let next = nextOrObserver;\n  if (typeof nextOrObserver !== 'function') {\n    ({ next, error, complete } = nextOrObserver);\n  }\n\n  // We know 'next' is now a function\n  const oldNext = next as (a: compat.User | null) => unknown;\n\n  const newNext = (user: exp.User | null): unknown =>\n    oldNext(user && User.getOrCreate(user as exp.User));\n  return {\n    next: newNext,\n    error: error as ErrorFn,\n    complete\n  };\n}\n\nfunction buildPersistenceHierarchy(\n  apiKey: string,\n  appName: string\n): exp.Persistence[] {\n  // Note this is slightly different behavior: in this case, the stored\n  // persistence is checked *first* rather than last. This is because we want\n  // to prefer stored persistence type in the hierarchy. This is an empty\n  // array if window is not available or there is no pending redirect\n  const persistences = _getPersistencesFromRedirect(apiKey, appName);\n\n  // If \"self\" is available, add indexedDB\n  if (\n    typeof self !== 'undefined' &&\n    !persistences.includes(exp.indexedDBLocalPersistence)\n  ) {\n    persistences.push(exp.indexedDBLocalPersistence);\n  }\n\n  // If \"window\" is available, add HTML Storage persistences\n  if (typeof window !== 'undefined') {\n    for (const persistence of [\n      exp.browserLocalPersistence,\n      exp.browserSessionPersistence\n    ]) {\n      if (!persistences.includes(persistence)) {\n        persistences.push(persistence);\n      }\n    }\n  }\n\n  // Add in-memory as a final fallback\n  if (!persistences.includes(exp.inMemoryPersistence)) {\n    persistences.push(exp.inMemoryPersistence);\n  }\n\n  return persistences;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport {\n  ActionCodeOperation,\n  ActionCodeSettings,\n  Auth,\n  UserCredential\n} from '../../model/public_types';\n\nimport * as api from '../../api/authentication/email_and_password';\nimport { ActionCodeURL } from '../action_code_url';\nimport { EmailAuthProvider } from '../providers/email';\nimport { _getCurrentUrl } from '../util/location';\nimport { _setActionCodeSettingsOnRequest } from './action_code_settings';\nimport { signInWithCredential } from './credential';\nimport { AuthErrorCode } from '../errors';\nimport { _assert } from '../util/assert';\nimport { getModularInstance } from '@firebase/util';\nimport { _castAuth } from '../auth/auth_impl';\nimport { handleRecaptchaFlow } from '../../platform_browser/recaptcha/recaptcha_enterprise_verifier';\nimport {\n  RecaptchaActionName,\n  RecaptchaClientType,\n  RecaptchaAuthProvider\n} from '../../api';\nimport { _isFirebaseServerApp } from '@firebase/app';\nimport { _serverAppCurrentUserOperationNotSupportedError } from '../../core/util/assert';\n\n/**\n * Sends a sign-in email link to the user with the specified email.\n *\n * @remarks\n * The sign-in operation has to always be completed in the app unlike other out of band email\n * actions (password reset and email verifications). This is because, at the end of the flow,\n * the user is expected to be signed in and their Auth state persisted within the app.\n *\n * To complete sign in with the email link, call {@link signInWithEmailLink} with the email\n * address and the email link supplied in the email sent to the user.\n *\n * @example\n * ```javascript\n * const actionCodeSettings = {\n *   url: 'https://www.example.com/?email=user@example.com',\n *   iOS: {\n *      bundleId: 'com.example.ios'\n *   },\n *   android: {\n *     packageName: 'com.example.android',\n *     installApp: true,\n *     minimumVersion: '12'\n *   },\n *   handleCodeInApp: true\n * };\n * await sendSignInLinkToEmail(auth, 'user@example.com', actionCodeSettings);\n * // Obtain emailLink from the user.\n * if(isSignInWithEmailLink(auth, emailLink)) {\n *   await signInWithEmailLink(auth, 'user@example.com', emailLink);\n * }\n * ```\n *\n * @param authInternal - The {@link Auth} instance.\n * @param email - The user's email address.\n * @param actionCodeSettings - The {@link ActionCodeSettings}.\n *\n * @public\n */\nexport async function sendSignInLinkToEmail(\n  auth: Auth,\n  email: string,\n  actionCodeSettings: ActionCodeSettings\n): Promise<void> {\n  const authInternal = _castAuth(auth);\n  const request: api.EmailSignInRequest = {\n    requestType: ActionCodeOperation.EMAIL_SIGNIN,\n    email,\n    clientType: RecaptchaClientType.WEB\n  };\n  function setActionCodeSettings(\n    request: api.EmailSignInRequest,\n    actionCodeSettings: ActionCodeSettings\n  ): void {\n    _assert(\n      actionCodeSettings.handleCodeInApp,\n      authInternal,\n      AuthErrorCode.ARGUMENT_ERROR\n    );\n    if (actionCodeSettings) {\n      _setActionCodeSettingsOnRequest(\n        authInternal,\n        request,\n        actionCodeSettings\n      );\n    }\n  }\n  setActionCodeSettings(request, actionCodeSettings);\n  await handleRecaptchaFlow(\n    authInternal,\n    request,\n    RecaptchaActionName.GET_OOB_CODE,\n    api.sendSignInLinkToEmail,\n    RecaptchaAuthProvider.EMAIL_PASSWORD_PROVIDER\n  );\n}\n\n/**\n * Checks if an incoming link is a sign-in with email link suitable for {@link signInWithEmailLink}.\n *\n * @param auth - The {@link Auth} instance.\n * @param emailLink - The link sent to the user's email address.\n *\n * @public\n */\nexport function isSignInWithEmailLink(auth: Auth, emailLink: string): boolean {\n  const actionCodeUrl = ActionCodeURL.parseLink(emailLink);\n  return actionCodeUrl?.operation === ActionCodeOperation.EMAIL_SIGNIN;\n}\n\n/**\n * Asynchronously signs in using an email and sign-in email link.\n *\n * @remarks\n * If no link is passed, the link is inferred from the current URL.\n *\n * Fails with an error if the email address is invalid or OTP in email link expires.\n *\n * This method is not supported by {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * Note: Confirm the link is a sign-in email link before calling this method firebase.auth.Auth.isSignInWithEmailLink.\n *\n * @example\n * ```javascript\n * const actionCodeSettings = {\n *   url: 'https://www.example.com/?email=user@example.com',\n *   iOS: {\n *      bundleId: 'com.example.ios'\n *   },\n *   android: {\n *     packageName: 'com.example.android',\n *     installApp: true,\n *     minimumVersion: '12'\n *   },\n *   handleCodeInApp: true\n * };\n * await sendSignInLinkToEmail(auth, 'user@example.com', actionCodeSettings);\n * // Obtain emailLink from the user.\n * if(isSignInWithEmailLink(auth, emailLink)) {\n *   await signInWithEmailLink(auth, 'user@example.com', emailLink);\n * }\n * ```\n *\n *\n * @param auth - The {@link Auth} instance.\n * @param email - The user's email address.\n * @param emailLink - The link sent to the user's email address.\n *\n * @public\n */\nexport async function signInWithEmailLink(\n  auth: Auth,\n  email: string,\n  emailLink?: string\n): Promise<UserCredential> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const authModular = getModularInstance(auth);\n  const credential = EmailAuthProvider.credentialWithLink(\n    email,\n    emailLink || _getCurrentUrl()\n  );\n  // Check if the tenant ID in the email link matches the tenant ID on Auth\n  // instance.\n  _assert(\n    credential._tenantId === (authModular.tenantId || null),\n    authModular,\n    AuthErrorCode.TENANT_ID_MISMATCH\n  );\n  return signInWithCredential(authModular, credential);\n}\n","/**\n * @license\n * Copyright 2017 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { _castAuth } from '../src/core/auth/auth_impl';\nimport { Auth } from '../src/model/public_types';\n\n/**\n * This interface is intended only for use by @firebase/auth-compat, do not use directly\n */\nexport * from '../index';\n\nexport { SignInWithIdpResponse } from '../src/api/authentication/idp';\nexport { AuthErrorCode } from '../src/core/errors';\nexport { PersistenceInternal } from '../src/core/persistence';\nexport { _persistenceKeyName } from '../src/core/persistence/persistence_user_manager';\nexport { UserImpl } from '../src/core/user/user_impl';\nexport { _getInstance } from '../src/core/util/instantiator';\nexport {\n  PopupRedirectResolverInternal,\n  EventManager,\n  AuthEventType\n} from '../src/model/popup_redirect';\nexport { UserCredentialInternal, UserParameters } from '../src/model/user';\nexport { AuthInternal, ConfigInternal } from '../src/model/auth';\nexport { DefaultConfig, AuthImpl, _castAuth } from '../src/core/auth/auth_impl';\n\nexport { ClientPlatform, _getClientVersion } from '../src/core/util/version';\n\nexport { _generateEventId } from '../src/core/util/event_id';\nexport { TaggedWithTokenResponse } from '../src/model/id_token';\nexport { _fail, _assert } from '../src/core/util/assert';\nexport { AuthPopup } from '../src/platform_browser/util/popup';\nexport { _getRedirectResult } from '../src/platform_browser/strategies/redirect';\nexport { _overrideRedirectResult } from '../src/core/strategies/redirect';\nexport { cordovaPopupRedirectResolver } from '../src/platform_cordova/popup_redirect/popup_redirect';\nexport { FetchProvider } from '../src/core/util/fetch_provider';\nexport { SAMLAuthCredential } from '../src/core/credentials/saml';\n\n// This function should only be called by frameworks (e.g. FirebaseUI-web) to log their usage.\n// It is not intended for direct use by developer apps. NO jsdoc here to intentionally leave it out\n// of autogenerated documentation pages to reduce accidental misuse.\nexport function addFrameworkForLogging(auth: Auth, framework: string): void {\n  _castAuth(auth)._logFramework(framework);\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport { Auth, UserCredential } from '../../model/public_types';\nimport { signUp } from '../../api/authentication/sign_up';\nimport { UserInternal } from '../../model/user';\nimport { UserCredentialImpl } from '../user/user_credential_impl';\nimport { _castAuth } from '../auth/auth_impl';\nimport { OperationType } from '../../model/enums';\nimport { _isFirebaseServerApp } from '@firebase/app';\nimport { _serverAppCurrentUserOperationNotSupportedError } from '../../core/util/assert';\n\n/**\n * Asynchronously signs in as an anonymous user.\n *\n * @remarks\n * If there is already an anonymous user signed in, that user will be returned; otherwise, a\n * new anonymous user identity will be created and returned.\n *\n * This method is not supported by {@link Auth} instances created with a\n * {@link @firebase/app#FirebaseServerApp}.\n *\n * @param auth - The {@link Auth} instance.\n *\n * @public\n */\nexport async function signInAnonymously(auth: Auth): Promise<UserCredential> {\n  if (_isFirebaseServerApp(auth.app)) {\n    return Promise.reject(\n      _serverAppCurrentUserOperationNotSupportedError(auth)\n    );\n  }\n  const authInternal = _castAuth(auth);\n  await authInternal._initializationPromise;\n  if (authInternal.currentUser?.isAnonymous) {\n    // If an anonymous user is already signed in, no need to sign them in again.\n    return new UserCredentialImpl({\n      user: authInternal.currentUser as UserInternal,\n      providerId: null,\n      operationType: OperationType.SIGN_IN\n    });\n  }\n  const response = await signUp(authInternal, {\n    returnSecureToken: true\n  });\n  const userCredential = await UserCredentialImpl._fromIdTokenResponse(\n    authInternal,\n    OperationType.SIGN_IN,\n    response,\n    true\n  );\n  await authInternal._updateCurrentUser(userCredential.user);\n  return userCredential;\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport * as exp from '@firebase/auth/internal';\nimport * as compat from '@firebase/auth-types';\nimport firebase from '@firebase/app-compat';\nimport { Compat } from '@firebase/util';\nimport { unwrap } from './wrap';\n\nexport class PhoneAuthProvider\n  implements compat.PhoneAuthProvider, Compat<exp.PhoneAuthProvider>\n{\n  providerId = 'phone';\n  readonly _delegate: exp.PhoneAuthProvider;\n\n  static PHONE_SIGN_IN_METHOD = exp.PhoneAuthProvider.PHONE_SIGN_IN_METHOD;\n  static PROVIDER_ID = exp.PhoneAuthProvider.PROVIDER_ID;\n\n  static credential(\n    verificationId: string,\n    verificationCode: string\n  ): compat.AuthCredential {\n    return exp.PhoneAuthProvider.credential(verificationId, verificationCode);\n  }\n\n  constructor() {\n    // TODO: remove ts-ignore when moving types from auth-types to auth-compat\n    // @ts-ignore\n    this._delegate = new exp.PhoneAuthProvider(unwrap(firebase.auth!()));\n  }\n\n  verifyPhoneNumber(\n    phoneInfoOptions:\n      | string\n      | compat.PhoneSingleFactorInfoOptions\n      | compat.PhoneMultiFactorEnrollInfoOptions\n      | compat.PhoneMultiFactorSignInInfoOptions,\n    applicationVerifier: compat.ApplicationVerifier\n  ): Promise<string> {\n    return this._delegate.verifyPhoneNumber(\n      // The implementation matches but the types are subtly incompatible\n      // eslint-disable-next-line @typescript-eslint/no-explicit-any\n      phoneInfoOptions as any,\n      applicationVerifier\n    );\n  }\n\n  unwrap(): exp.PhoneAuthProvider {\n    return this._delegate;\n  }\n}\n","/**\n * @license\n * Copyright 2020 Google LLC\n *\n * Licensed under the Apache License, Version 2.0 (the \"License\");\n * you may not use this file except in compliance with the License.\n * You may obtain a copy of the License at\n *\n *   http://www.apache.org/licenses/LICENSE-2.0\n *\n * Unless required by applicable law or agreed to in writing, software\n * distributed under the License is distributed on an \"AS IS\" BASIS,\n * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n * See the License for the specific language governing permissions and\n * limitations under the License.\n */\n\nimport firebase, { FirebaseApp } from '@firebase/app-compat';\nimport * as exp from '@firebase/auth/internal';\nimport * as compat from '@firebase/auth-types';\nimport { Compat } from '@firebase/util';\n\nconst _assert: typeof exp._assert = exp._assert;\n\nexport class RecaptchaVerifier\n  implements compat.RecaptchaVerifier, Compat<exp.ApplicationVerifier>\n{\n  readonly _delegate: exp.RecaptchaVerifier;\n  type: string;\n  constructor(\n    container: HTMLElement | string,\n    parameters?: object | null,\n    app: FirebaseApp = firebase.app()\n  ) {\n    // API key is required for web client RPC calls.\n    _assert(app.options?.apiKey, exp.AuthErrorCode.INVALID_API_KEY, {\n      appName: app.name\n    });\n    this._delegate = new exp.RecaptchaVerifier(\n      // TODO: remove ts-ignore when moving types from auth-types to auth-compat\n      // @ts-ignore\n      app.auth!(),\n      container,\n      // eslint-disable-next-line @typescript-eslint/no-explicit-any\n      parameters as any\n    );\n    this.type = this._delegate.type;\n  }\n  clear(): void {\n    this._delegate.clear();\n  }\n  render(): Promise<number> {\n    return this._delegate.render();\n  }\n  verify(): Promise<string> {\n    return this._delegate.verify();\n  }\n}\n"],"names":["getDefaultsFromPostinstall","base64","byteToCharMap_","charToByteMap_","byteToCharMapWebSafe_","charToByteMapWebSafe_","ENCODED_VALS_BASE","ENCODED_VALS","this","ENCODED_VALS_WEBSAFE","HAS_NATIVE_SUPPORT","atob","encodeByteArray","input","webSafe","Array","isArray","Error","init_","byteToCharMap","output","let","i","length","byte1","haveByte2","byte2","haveByte3","byte3","outByte3","outByte4","push","join","encodeString","btoa","str","out","p","c","charCodeAt","decodeString","byteArrayToString","bytes","decodeStringToByteArray","pos","u","c2","c3","c1","String","fromCharCode","charToByteMap","charAt","byte4","DecodeBase64StringError","constructor","name","base64Decode","e","console","error","getDefaultsFromGlobal","self","window","global","__FIREBASE_DEFAULTS__","getDefaultsFromEnvVariable","defaultsJsonString","process","env","JSON","parse","getDefaultsFromCookie","document","match","cookie","decoded","getDefaults","info","LogLevel","getUA","navigator","isNode","forceEnvironment","Object","prototype","toString","call","isBrowserExtension","runtime","chrome","browser","undefined","id","isReactNative","isIE","ua","indexOf","isIndexedDBAvailable","indexedDB","FirebaseError","code","message","customData","super","setPrototypeOf","captureStackTrace","ErrorFactory","create","service","serviceName","errors","data","fullCode","template","replace","PATTERN","_","key","value","fullMessage","deepEqual","a","b","k","aKeys","keys","bKeys","includes","aProp","bProp","isObject","thing","querystring","querystringParams","params","entries","forEach","arrayVal","encodeURIComponent","querystringDecode","obj","split","token","decodeURIComponent","extractQuerystring","url","fragmentStart","queryStart","substring","ObserverProxy","executor","onNoObservers","observers","unsubscribes","observerCount","task","Promise","resolve","finalized","then","catch","next","forEachObserver","observer","close","complete","subscribe","nextOrObserver","methods","method","noop","unsub","unsubscribeOne","bind","finalError","fn","sendOne","err","getModularInstance","_delegate","isCloudWorkstation","startsWith","URL","hostname","endsWith","levelStringToEnum","debug","DEBUG","verbose","VERBOSE","INFO","warn","WARN","ERROR","silent","SILENT","defaultLogLevel","ConsoleMethod","defaultLogHandler","instance","logType","args","logLevel","now","Date","toISOString","Component","instanceFactory","type","multipleInstances","serviceProps","instantiationMode","onInstanceCreated","setInstantiationMode","mode","setMultipleInstances","setServiceProps","props","setInstanceCreatedCallback","callback","ProviderId","FACEBOOK","GITHUB","GOOGLE","PASSWORD","PHONE","TWITTER","ActionCodeOperation","EMAIL_SIGNIN","PASSWORD_RESET","RECOVER_EMAIL","REVERT_SECOND_FACTOR_ADDITION","VERIFY_AND_CHANGE_EMAIL","VERIFY_EMAIL","_prodErrorMap","dependent-sdk-initialized-before-auth","debugErrorMap","admin-restricted-operation","argument-error","app-not-authorized","app-not-installed","captcha-check-failed","code-expired","cordova-not-ready","cors-unsupported","credential-already-in-use","custom-token-mismatch","requires-recent-login","dynamic-link-not-activated","email-change-needs-verification","email-already-in-use","emulator-config-failed","expired-action-code","cancelled-popup-request","internal-error","invalid-app-credential","invalid-app-id","invalid-user-token","invalid-auth-event","invalid-verification-code","invalid-continue-uri","invalid-cordova-configuration","invalid-custom-token","invalid-dynamic-link-domain","invalid-email","invalid-emulator-scheme","invalid-api-key","invalid-cert-hash","invalid-credential","invalid-message-payload","invalid-multi-factor-session","invalid-oauth-provider","invalid-oauth-client-id","unauthorized-domain","invalid-action-code","wrong-password","invalid-persistence-type","invalid-phone-number","invalid-provider-id","invalid-recipient-email","invalid-sender","invalid-verification-id","invalid-tenant-id","login-blocked","missing-android-pkg-name","auth-domain-config-required","missing-app-credential","missing-verification-code","missing-continue-uri","missing-iframe-start","missing-ios-bundle-id","missing-or-invalid-nonce","missing-password","missing-multi-factor-info","missing-multi-factor-session","missing-phone-number","missing-verification-id","app-deleted","multi-factor-info-not-found","multi-factor-auth-required","account-exists-with-different-credential","network-request-failed","no-auth-event","no-such-provider","null-user","operation-not-allowed","operation-not-supported-in-this-environment","popup-blocked","popup-closed-by-user","provider-already-linked","quota-exceeded","redirect-cancelled-by-user","redirect-operation-pending","rejected-credential","second-factor-already-in-use","maximum-second-factor-count-exceeded","tenant-id-mismatch","timeout","user-token-expired","too-many-requests","unauthorized-continue-uri","unsupported-first-factor","unsupported-persistence-type","unsupported-tenant-operation","unverified-email","user-cancelled","user-not-found","user-disabled","user-mismatch","user-signed-out","weak-password","web-storage-unsupported","already-initialized","missing-recaptcha-token","invalid-recaptcha-token","invalid-recaptcha-action","recaptcha-not-enabled","missing-client-type","missing-recaptcha-version","invalid-req-type","invalid-recaptcha-version","unsupported-password-policy-schema-version","password-does-not-meet-requirements","invalid-hosting-link-domain","prodErrorMap","_DEFAULT_AUTH_ERROR_FACTORY","logClient","_logLevel","_logHandler","_userLogHandler","val","TypeError","setLogLevel","logHandler","userLogHandler","log","_logError","msg","SDK_VERSION","_fail","authOrCode","rest","createErrorInternal","_createError","_errorWithCustomMessage","auth","errorMap","appName","_serverAppCurrentUserOperationNotSupportedError","_assertInstanceOf","object","constructorInstance","fullParams","slice","_errorFactory","_assert","assertion","debugFail","failure","debugAssert","_getCurrentUrl","location","href","_isHttpOrHttps","_getCurrentScheme","protocol","Delay","shortDelay","longDelay","isMobile","test","get","onLine","Math","min","_emulatorUrl","config","path","emulator","FetchProvider","initialize","fetchImpl","headersImpl","responseImpl","fetch","globalThis","headers","Headers","response","Response","SERVER_ERROR_MAP","CREDENTIAL_MISMATCH","MISSING_CUSTOM_TOKEN","INVALID_IDENTIFIER","MISSING_CONTINUE_URI","INVALID_PASSWORD","MISSING_PASSWORD","INVALID_LOGIN_CREDENTIALS","EMAIL_EXISTS","PASSWORD_LOGIN_DISABLED","INVALID_IDP_RESPONSE","INVALID_PENDING_TOKEN","FEDERATED_USER_ID_ALREADY_LINKED","MISSING_REQ_TYPE","EMAIL_NOT_FOUND","RESET_PASSWORD_EXCEED_LIMIT","EXPIRED_OOB_CODE","INVALID_OOB_CODE","MISSING_OOB_CODE","CREDENTIAL_TOO_OLD_LOGIN_AGAIN","INVALID_ID_TOKEN","TOKEN_EXPIRED","USER_NOT_FOUND","TOO_MANY_ATTEMPTS_TRY_LATER","PASSWORD_DOES_NOT_MEET_REQUIREMENTS","INVALID_CODE","INVALID_SESSION_INFO","INVALID_TEMPORARY_PROOF","MISSING_SESSION_INFO","SESSION_EXPIRED","MISSING_ANDROID_PACKAGE_NAME","UNAUTHORIZED_DOMAIN","INVALID_OAUTH_CLIENT_ID","ADMIN_ONLY_OPERATION","INVALID_MFA_PENDING_CREDENTIAL","MFA_ENROLLMENT_NOT_FOUND","MISSING_MFA_ENROLLMENT_ID","MISSING_MFA_PENDING_CREDENTIAL","SECOND_FACTOR_EXISTS","SECOND_FACTOR_LIMIT_EXCEEDED","BLOCKING_FUNCTION_ERROR_RESPONSE","RECAPTCHA_NOT_ENABLED","MISSING_RECAPTCHA_TOKEN","INVALID_RECAPTCHA_TOKEN","INVALID_RECAPTCHA_ACTION","MISSING_CLIENT_TYPE","MISSING_RECAPTCHA_VERSION","INVALID_RECAPTCHA_VERSION","INVALID_REQ_TYPE","CookieAuthProxiedEndpoints","DEFAULT_API_TIMEOUT_MS","_addTidIfNecessary","request","tenantId","async","_performApiRequest","customErrorMap","_performFetchWithErrorHandling","body","stringify","query","apiKey","await","_getAdditionalHeaders","fetchArgs","languageCode","userAgent","referrerPolicy","emulatorConfig","host","credentials","_getFinalTarget","apiHost","fetchFn","_canInitEmulator","networkTimeout","NetworkTimeout","race","promise","json","clearNetworkTimeout","_makeTaggedError","ok","serverErrorCode","serverErrorMessage","errorMessage","authError","toLowerCase","_performSignInRequest","serverResponse","_serverResponse","base","authInternal","finalTarget","apiScheme","_persistenceManagerAvailable","_getPersistenceType","_getPersistence","clearTimeout","timer","reject","setTimeout","errorParams","email","phoneNumber","_tokenResponse","isV2","grecaptcha","getResponse","isEnterprise","enterprise","RecaptchaConfig","siteKey","recaptchaEnforcementState","recaptchaKey","getProviderEnforcementState","providerStr","provider","enforcementState","_parseEnforcementState","isProviderEnabled","isAnyProviderEnabled","getRecaptchaConfig","getAccountInfo","utcTimestampToDateString","utcTimestamp","date","Number","isNaN","getTime","toUTCString","secondsStringToMilliseconds","seconds","_parseToken","algorithm","payload","signature","_tokenExpiresIn","parsedToken","exp","iat","_logoutIfInvalidated","user","bypassAuthState","isUserInvalidated","currentUser","signOut","ProactiveRefresh","isRunning","timerId","errorBackoff","_start","schedule","_stop","getInterval","wasError","interval","stsTokenManager","expirationTime","max","iteration","getIdToken","UserMetadata","createdAt","lastLoginAt","_initializeTime","lastSignInTime","creationTime","_copy","metadata","toJSON","_reloadWithoutSaving","original","newData","idToken","coreAccount","users","newProviderData","_notifyReloadListener","providerUserInfo","extractProviderData","providerData","filter","o","some","n","providerId","newIsAnonymous","passwordHash","isAnonymous","oldIsAnonymous","updates","uid","localId","displayName","photoURL","photoUrl","emailVerified","assign","providers","map","rawId","StsTokenManager","refreshToken","accessToken","isExpired","updateFromServerResponse","expiresIn","updateTokensAndExpiration","updateFromIdToken","getToken","forceRefresh","refresh","clearRefreshToken","oldToken","grant_type","refresh_token","tokenApiHost","options","access_token","expires_in","expiresInSec","fromJSON","manager","_assign","_clone","_performRefresh","assertStringOrUndefined","UserImpl","opt","proactiveRefresh","reloadUserInfo","reloadListener","_persistUserIfCurrent","_notifyListenersIfCurrent","getIdTokenResult","userInternal","claims","signInProvider","auth_time","firebase","authTime","issuedAtTime","signInSecondFactor","reload","userInfo","newUser","_onReload","_startProactiveRefresh","_stopProactiveRefresh","_updateTokensIfNecessary","tokensRefreshed","delete","_isFirebaseServerApp","app","_redirectEventId","_fromJSON","plainObjectTokenManager","_fromIdTokenResponse","idTokenResponse","_fromGetAccountInfoResponse","instanceCache","Map","_getInstance","cls","Function","set","InMemoryPersistence","storage","_isAvailable","_set","_get","_remove","_addListener","_key","_listener","_removeListener","inMemoryPersistence","_persistenceKeyName","PersistenceUserManager","persistence","userKey","fullUserKey","fullPersistenceKey","boundEventHandler","_onStorageEvent","setCurrentUser","getCurrentUser","blob","removeCurrentUser","savePersistenceForRedirect","setPersistence","newPersistence","persistenceHierarchy","availablePersistences","all","selectedPersistence","userToMigrate","migrationHierarchy","_shouldAllowMigration","_getBrowserName","_isIEMobile","_isFirefox","_isBlackBerry","_isWebOS","_isSafari","_isChromeIOS","_isAndroid","matches","_isIOS","_isMobileBrowser","_getClientVersion","clientPlatform","frameworks","reportedPlatform","reportedFrameworks","AuthMiddlewareQueue","queue","pushCallback","onAbort","wrappedCallback","index","runMiddleware","nextUser","onAbortStack","beforeStateCallback","reverse","originalMessage","PasswordPolicyImpl","responseOptions","customStrengthOptions","minPasswordLength","maxPasswordLength","containsLowercaseCharacter","containsLowercaseLetter","containsUppercaseCharacter","containsUppercaseLetter","containsNumericCharacter","containsNonAlphanumericCharacter","allowedNonAlphanumericCharacters","forceUpgradeOnSignin","schemaVersion","validatePassword","password","status","isValid","passwordPolicy","validatePasswordLengthOptions","validatePasswordCharacterOptions","meetsMinPasswordLength","meetsMaxPasswordLength","passwordChar","updatePasswordCharacterOptionsStatuses","AuthImpl","heartbeatServiceProvider","appCheckServiceProvider","operations","authStateSubscription","Subscription","idTokenSubscription","beforeStateQueue","redirectUser","isProactiveRefreshEnabled","EXPECTED_PASSWORD_POLICY_SCHEMA_VERSION","_isInitialized","_deleted","_initializationPromise","_popupRedirectResolver","_agentRecaptchaConfig","_tenantRecaptchaConfigs","_projectPasswordPolicy","_tenantPasswordPolicies","_resolvePersistenceManagerAvailable","lastNotifiedUid","settings","appVerificationDisabledForTesting","clientVersion","sdkClientVersion","_initializeWithPersistence","popupRedirectResolver","persistenceManager","_shouldInitProactively","_initialize","initializeCurrentUser","assertedPersistence","_currentUser","_updateCurrentUser","initializeCurrentUserFromIdToken","directlySetCurrentUser","authIdToken","redirectUserEventId","storedUserEventId","result","previouslyStoredUser","futureCurrentUser","needsTocheckMiddleware","authDomain","getOrInitRedirectPersistenceManager","tryRedirectSignIn","reloadAndSetCurrentUserOrClear","_overrideRedirectResult","redirectResolver","_completeRedirectFn","_setRedirectUser","useDeviceLanguage","navigatorLanguage","languages","language","_delete","updateCurrentUser","userExtern","skipBeforeStateCallbacks","notifyAuthListeners","redirectPersistenceManager","_getRecaptchaConfig","_getPasswordPolicyInternal","_updatePasswordPolicy","_updateErrorMap","onAuthStateChanged","completed","registerStateListener","beforeAuthStateChanged","onIdTokenChanged","authStateReady","unsubscribe","revokeAccessToken","tokenType","redirectManager","resolver","_redirectPersistence","_redirectUserForId","currentUid","subscription","cb","isUnsubscribed","addObserver","action","_logFramework","framework","sort","_getFrameworks","X-Client-Version","heartbeatsHeader","appId","getImmediate","optional","getHeartbeatsHeader","appCheckToken","_getAppCheckToken","appCheckTokenResult","_logWarn","_castAuth","proxy","externalJSProvider","loadJS","recaptchaV2Script","recaptchaEnterpriseScript","gapiScript","_loadJS","_generateCallbackName","prefix","floor","random","MockReCaptcha","counter","_widgets","render","container","parameters","MockWidget","reset","optWidgetId","execute","MockGreCAPTCHATopLevel","MockGreCAPTCHA","ready","_siteKey","_options","_container","_parameters","containerOrId","deleted","responseToken","clickHandler","getElementById","isVisible","size","addEventListener","checkIfDeleted","removeEventListener","len","chars","allowedChars","expired-callback","expiredCallback","FAKE_TOKEN","RecaptchaEnterpriseVerifier","authExtern","verify","retrieveRecaptchaToken","clientType","version","jsHelpers\n                        ._loadJS","injectRecaptchaFields","isCaptchaResp","isFakeToken","verifier","captchaResponse","recaptchaToken","newRequest","phoneEnrollmentInfo","recaptchaVersion","phoneSignInInfo","captchaResp","handleRecaptchaFlow","authInstance","actionName","actionMethod","recaptchaAuthProvider","requestWithRecaptchaFields","requestWithRecaptcha","connectAuthEmulator","disableWarnings","extractProtocol","port","bracketedIPv6","authority","exec","substr","hostAndPort","pop","parsePort","portStr","freeze","attachBanner","el","createElement","sty","style","innerText","position","width","backgroundColor","border","color","bottom","left","margin","zIndex","textAlign","classList","add","appendChild","endpoint","readyState","protocolEnd","AuthCredential","signInMethod","_getIdTokenResponse","_auth","_linkToIdToken","_idToken","_getReauthenticationResolver","resetPassword","linkEmailPassword","signInWithPassword","sendOobCode","sendPasswordResetEmail","sendSignInLinkToEmail","EmailAuthCredential","_email","_password","_tenantId","_fromEmailAndPassword","_fromEmailAndCode","oobCode","returnSecureToken","signInWithIdp","OAuthCredential","pendingToken","_fromParams","cred","nonce","oauthToken","oauthTokenSecret","secret","buildRequest","autoCreate","postBody","requestUri","sendPhoneVerificationCode","VERIFY_PHONE_NUMBER_FOR_EXISTING_ERROR_MAP_","PhoneAuthCredential","_fromVerification","verificationId","verificationCode","_fromTokenResponse","temporaryProof","_makeVerificationRequest","operation","sessionInfo","ActionCodeURL","actionLink","searchParams","continueUrl","parseLink","link","doubleDeepLink","iOSDeepLink","EmailAuthProvider","PROVIDER_ID","credential","credentialWithLink","emailLink","actionCodeUrl","EMAIL_PASSWORD_SIGN_IN_METHOD","EMAIL_LINK_SIGN_IN_METHOD","FederatedAuthProvider","defaultLanguageCode","customParameters","setDefaultLanguage","setCustomParameters","customOAuthParameters","getCustomParameters","BaseOAuthProvider","scopes","addScope","scope","getScopes","OAuthProvider","credentialFromJSON","_credential","rawNonce","credentialFromResult","userCredential","oauthCredentialFromTaggedObject","credentialFromError","tokenResponse","oauthIdToken","oauthAccessToken","FacebookAuthProvider","FACEBOOK_SIGN_IN_METHOD","credentialFromTaggedObject","GoogleAuthProvider","GOOGLE_SIGN_IN_METHOD","GithubAuthProvider","GITHUB_SIGN_IN_METHOD","SAMLAuthCredential","_create","SAMLAuthProvider","samlCredentialFromTaggedObject","TwitterAuthProvider","TWITTER_SIGN_IN_METHOD","signUp","UserCredentialImpl","operationType","providerIdForResponse","_forOperation","MultiFactorError","_fromErrorAndOperation","_processCredentialSavingMfaContextIfNecessary","providerDataAsNames","Set","pid","unlink","_assertLinkedStatus","deleteProvider","providersLeft","pd","has","_link","expected","_reauthenticate","parsed","_signInWithCredential","signInWithCredential","linkWithCredential","reauthenticateWithCredential","signInWithCustomToken","customToken","MultiFactorInfoImpl","factorId","mfaEnrollmentId","enrollmentTime","enrolledAt","_fromServerResponse","enrollment","PhoneMultiFactorInfoImpl","TotpMultiFactorInfoImpl","phoneInfo","_setActionCodeSettingsOnRequest","actionCodeSettings","dynamicLinkDomain","linkDomain","canHandleCodeInApp","handleCodeInApp","iOS","bundleId","iOSBundleId","android","packageName","androidInstallApp","installApp","androidMinimumVersionCode","minimumVersion","androidPackageName","recachePasswordPolicy","applyActionCode","checkActionCode","authModular","account.resetPassword","requestType","newEmail","mfaInfo","multiFactorInfo","previousEmail","fetchSignInMethodsForEmail","continueUri","signinMethods","identifier","sendEmailVerification","verifyBeforeUpdateEmail","updateProfile","passwordProvider","find","updateEmailOrPassword","GenericAdditionalUserInfo","isNewUser","profile","FederatedAdditionalUserInfoWithUsername","username","FacebookAdditionalUserInfo","GithubAdditionalUserInfo","login","GoogleAdditionalUserInfo","TwitterAdditionalUserInfo","screenName","getAdditionalUserInfo","rawUserInfo","kind","filteredProviderId","MultiFactorSessionImpl","_fromIdtoken","_fromMfaPendingCredential","mfaPendingCredential","multiFactorSession","pendingCredential","MultiFactorResolverImpl","session","hints","signInResolver","_fromError","mfaResponse","_process","resolveSignIn","assertionExtern","startEnrollPhoneMfa","MultiFactorUserImpl","enrolledFactors","_fromUser","getSession","enroll","finalizeMfaResponse","unenroll","infoOrUid","multiFactorUserCache","WeakMap","STORAGE_AVAILABLE_KEY","BrowserPersistenceClass","storageRetriever","setItem","removeItem","getItem","BrowserLocalPersistence","localStorage","event","poll","onStorageEvent","listeners","localCache","pollTimer","fallbackToPolling","forAllChangedKeys","newValue","oldValue","detachListener","stopPolling","triggerListeners","storedValue","notifyListeners","documentMode","_oldValue","listener","from","startPolling","setInterval","StorageEvent","clearInterval","attachListener","browserLocalPersistence","BrowserSessionPersistence","sessionStorage","browserSessionPersistence","Receiver","eventTarget","handlersMap","handleEvent","existingInstance","receivers","receiver","isListeningto","newInstance","messageEvent","eventId","eventType","handlers","ports","postMessage","promises","handler","origin","fulfilled","reason","_subscribe","eventHandler","_unsubscribe","_generateEventId","digits","Sender","target","removeMessageHandler","messageChannel","port1","onMessage","_send","MessageChannel","completionTimer","ackTimer","start","port2","finally","_window","_isWorker","DB_NAME","DB_OBJECTSTORE_NAME","DB_DATA_KEYPATH","DBPromise","toPromise","getObjectStore","db","isReadWrite","transaction","objectStore","_openDatabase","open","createObjectStore","keyPath","objectStoreNames","contains","deleteDatabase","_putObject","put","fbase_key","_deleteObject","IndexedDBLocalPersistence","pendingWrites","sender","serviceWorkerReceiverAvailable","activeServiceWorker","_workerInitializationPromise","initializeServiceWorkerMessaging","_openDb","_withRetries","op","numAttempts","initializeReceiver","initializeSender","_origin","keyProcessed","_poll","_data","results","serviceWorker","active","notifyServiceWorker","controller","_withPendingWrite","write","getAllRequest","getAll","localKey","keysInResult","indexedDBLocalPersistence","startSignInPhoneMfa","_JSLOAD_CALLBACK","jsHelpers._generateCallbackName","NETWORK_TIMEOUT_DELAY","ReCaptchaLoaderImpl","hostLanguage","librarySeparatelyLoaded","load","hl","shouldResolveImmediately","recaptcha","widgetId","jsHelpers._loadJS","onload","clearedOneInstance","MockReCaptchaLoaderImpl","RECAPTCHA_VERIFIER_TYPE","DEFAULT_PARAMS","theme","RecaptchaVerifier","destroyed","tokenChangeListeners","renderPromise","isInvisible","makeTokenCallback","_recaptchaLoader","validateStartingState","assertNotDestroyed","getAssertedRecaptcha","tokenChange","makeRenderPromise","_reset","clear","childNodes","node","removeChild","sitekey","hasChildNodes","existing","globalFunc","init","guaranteedEmpty","recaptchaSiteKey","ConfirmationResultImpl","onConfirmation","confirm","authCredential","_verifyPhoneNumber","startPhoneMfaEnrollmentRequest","startPhoneMfaSignInRequest","sendPhoneVerificationCodeRequest","phoneInfoOptions","injectRecaptchaV2Token","phoneSessionInfo","multiFactorHint","multiFactorUid","phoneResponseInfo","recaptchaV2Verifier","recaptchaV2Token","PhoneAuthProvider","verifyPhoneNumber","phoneOptions","applicationVerifier","_withDefaultResolver","resolverOverride","PHONE_SIGN_IN_METHOD","IdpCredential","_buildIdpRequest","sessionId","returnIdpCredential","_signIn","_reauth","_linkUser","AbstractPopupRedirectOperation","pendingPromise","eventManager","onExecution","registerConsumer","onAuthEvent","urlResponse","getIdpTask","onError","unregisterAndCleanUp","unregisterConsumer","cleanUp","_POLL_WINDOW_CLOSE_TIMEOUT","PopupOperation","authWindow","pollId","currentPopupAction","cancel","executeNotNull","_openPopup","associatedEvent","_originValidation","_isIframeWebStorageSupported","isSupported","pollUserCancellation","closed","PENDING_REDIRECT_KEY","redirectOutcomeMap","RedirectAction","readyOutcome","hasPendingRedirect","pendingRedirectKey","resolverPersistence","_setPendingRedirectStatus","signInWithRedirect","resolverInternal","_openRedirect","reauthenticateWithRedirect","prepareUserForRedirect","linkWithRedirect","_getRedirectResult","resolverExtern","AuthEventManager","cachedEventUids","consumers","queuedRedirectEvent","hasHandledPotentialRedirect","lastProcessedEventTime","authEventConsumer","isEventForConsumer","sendToConsumer","saveEventToCache","onEvent","hasEventBeenHandled","handled","consumer","isNullRedirectEvent","eventIdMatches","eventUid","v","_getProjectConfig","IP_ADDRESS_REGEX","HTTP_REGEX","_validateOrigin","domain","authorizedDomains","re","currentUrl","ceUrl","escapedDomainPattern","RegExp","NETWORK_TIMEOUT","resetUnloadedGapiModules","beacon","___jsl","H","hint","r","L","CP","loadGapi","loadGapiIframe","gapi","iframes","getContext","ontimeout","Iframe","cbName","js._generateCallbackName","js\n                ._loadJS","cachedGApiLoader","PING_TIMEOUT","IFRAME_PATH","EMULATED_IFRAME_PATH","IFRAME_ATTRIBUTES","top","height","aria-hidden","tabindex","EID_FROM_APIHOST","_openIframe","eid","context","where","fw","messageHandlersFilter","CROSS_ORIGIN_IFRAMES_FILTER","attributes","dontclear","iframe","restyle","setHideOnLeave","networkError","networkErrorTimer","clearTimerAndResolve","ping","BASE_POPUP_OPTIONS","resizable","statusbar","toolbar","AuthPopup","_open","screen","availHeight","availWidth","click","optionsString","scrollbars","reduce","accum","_isIOSStandalone","standalone","createEvent","initMouseEvent","dispatchEvent","newWin","focus","WIDGET_PATH","EMULATOR_WIDGET_PATH","FIREBASE_APP_CHECK_FRAGMENT_ID","_getRedirectUrl","authType","redirectUrl","additionalParams","hasOwnProperty","tid","paramsDict","appCheckTokenFragment","getHandlerBase","WEB_STORAGE_SUPPORT_KEY","BrowserPopupRedirectResolver","eventManagers","originValidationPromises","initAndGetManager","register","iframeEvent","authEvent","send","browserPopupRedirectResolver","PhoneMultiFactorAssertionImpl","_finalizeEnroll","_finalizeSignIn","_fromCredential","phoneVerificationInfo","PhoneMultiFactorGenerator","FACTOR_ID","AuthInterop","internalListeners","getUid","assertAuthConfigured","addAuthTokenListener","updateProactiveRefresh","removeAuthTokenListener","_cordovaWindow","setAttribute","onerror","charset","getElementsByTagName","_registerComponent","deps","getProvider","hierarchy","_instanceIdentifier","_instance","registerVersion","_generateHandlerUrl","BuildInfo","sessionDigest","TextEncoder","encode","buff","ArrayBuffer","view","Uint8Array","buf","crypto","subtle","digest","arr","num","padStart","_performRedirect","handlerUrl","cordova","plugins","browsertab","isAvailable","browserTabIsAvailable","iabRef","openUrl","InAppBrowser","SESSION_ID_LENGTH","CordovaAuthEventManager","passiveListeners","initPromise","resolveInitialized","addPassiveListener","removePassiveListener","resetRedirect","initialized","_generateNewEvent","idx","_getAndRemoveEvent","persistenceKey","_eventFromPartialAndUrl","partialEvent","searchParamsOrEmpty","callbackUrl","CordovaPopupRedirectResolver","attachCallbackListeners","win","universalLinks","missingPlugin","eventListener","cleanup","onCloseTimer","authEventSeen","closeBrowserTab","resumed","visibilityChanged","visibilityState","_cb","iosBundleId","handleOpenURL","noEventTimeout","generateNoEvent","universalLinksCb","eventData","finalEvent","existingHandleOpenURL","packagePrefix","cordovaPopupRedirectResolver","_isAndroidOrIosCordovaScheme","_isLocalStorageNotSynchronized","_isEdge","_isWebStorageSupported","impl","_isPopupRedirectSupported","_isLikelyCordova","Persistence","LOCAL","NONE","SESSION","exp._assert","PERSISTENCE_KEY","_savePersistenceForRedirect","getSessionStorageIfAvailable","exp._persistenceKeyName","CompatPopupRedirectResolver","browserResolver","exp._getInstance","exp.browserPopupRedirectResolver","cordovaResolver","exp.cordovaPopupRedirectResolver","underlyingResolver","exp.browserSessionPersistence","exp._getRedirectResult","exp._overrideRedirectResult","selectUnderlyingResolver","assertedUnderlyingResolver","isCordova","timeoutId","unwrap","attachExtraErrorFields","errorInternal","MultiFactorResolver","credentialFromObject","credErr","exp.PhoneAuthProvider","exp.ProviderId","exp.GoogleAuthProvider","exp.FacebookAuthProvider","exp.GithubAuthProvider","exp.TwitterAuthProvider","exp.SAMLAuthCredential","exp.OAuthCredential","exp.OAuthProvider","convertCredential","credentialPromise","additionalUserInfo","exp.getAdditionalUserInfo","User","getOrCreate","convertConfirmationResult","confirmationResultPromise","confirmationResultExp","wrapped","userModular","multiFactor","USER_MAP","linkAndRetrieveDataWithCredential","exp.linkWithCredential","linkWithPhoneNumber","appVerifier","linkWithPopup","exp._castAuth","exp.linkWithRedirect","reauthenticateAndRetrieveDataWithCredential","exp.reauthenticateWithCredential","reauthenticateWithPhoneNumber","reauthenticateWithPopup","exp.reauthenticateWithRedirect","exp.sendEmailVerification","exp.unlink","updateEmail","updatePassword","newPassword","updatePhoneNumber","phoneCredential","exp.updateProfile","exp.verifyBeforeUpdateEmail","Auth","isInitialized","persistences","exp.inMemoryPersistence","exp.indexedDBLocalPersistence","exp.browserLocalPersistence","exp.debugErrorMap","linkUnderlyingAuth","useEmulator","exp.connectAuthEmulator","exp.applyActionCode","exp.checkActionCode","confirmPasswordReset","account\n        .resetPassword","createUserWithEmailAndPassword","fetchProvidersForEmail","exp.fetchSignInMethodsForEmail","isSignInWithEmailLink","getRedirectResult","addFrameworkForLogging","errorFn","wrapObservers","api.sendSignInLinkToEmail","authentication.sendPasswordResetEmail","values","converted","isIndexedDBFullySupported","exp\n                    ._getInstance","exp._fail","signInAndRetrieveDataWithCredential","signInAnonymously","exp.signInWithCredential","exp.signInWithCustomToken","signInWithEmailAndPassword","signInWithEmailLink","signInWithPhoneNumber","signInWithPopup","exp.signInWithRedirect","verifyPasswordResetCode","oldNext","exp.RecaptchaVerifier","INTERNAL","registerComponent","authProvider","ActionCodeInfo","Operation","CompatAuthProvider","CompatRecaptchaVerifier"],"mappings":"ibAiBA,IAAMA,EAA6B,OC0FtBC,EAAiB,CAI5BC,eAAgB,KAKhBC,eAAgB,KAMhBC,sBAAuB,KAMvBC,sBAAuB,KAMvBC,kBACE,iEAKFC,mBACE,OAAOC,KAAKF,kBAAoB,KACjC,EAKDG,2BACE,OAAOD,KAAKF,kBAAoB,KACjC,EASDI,mBAAoC,YAAhB,OAAOC,KAW3BC,gBAAgBC,EAA8BC,GAC5C,GAAI,CAACC,MAAMC,QAAQH,CAAK,EACtB,MAAMI,MAAM,+CAA+C,EAG7DT,KAAKU,MAAK,EAEV,IAAMC,EAAgBL,EAClBN,KAAKJ,sBACLI,KAAKN,eAEHkB,EAAS,GAEf,IAAKC,IAAIC,EAAI,EAAGA,EAAIT,EAAMU,OAAQD,GAAK,EAAG,CACxC,IAAME,EAAQX,EAAMS,GACdG,EAAYH,EAAI,EAAIT,EAAMU,OAC1BG,EAAQD,EAAYZ,EAAMS,EAAI,GAAK,EACnCK,EAAYL,EAAI,EAAIT,EAAMU,OAC1BK,EAAQD,EAAYd,EAAMS,EAAI,GAAK,EAIzCD,IAAIQ,GAAqB,GAARH,IAAiB,EAAME,GAAS,EAC7CE,EAAmB,GAARF,EAEVD,IACHG,EAAW,GAENL,KACHI,EAAW,IAIfT,EAAOW,KACLZ,EAdeK,GAAS,GAexBL,GAdyB,EAARK,IAAiB,EAAME,GAAS,GAejDP,EAAcU,GACdV,EAAcW,EAAS,CAE1B,CAED,OAAOV,EAAOY,KAAK,EAAE,CACtB,EAUDC,aAAapB,EAAeC,GAG1B,OAAIN,KAAKE,oBAAsB,CAACI,EACvBoB,KAAKrB,CAAK,EAEZL,KAAKI,iBAlNoBuB,IAElC,IAAMC,EAAgB,GACtBf,IAAIgB,EAAI,EACR,IAAKhB,IAAIC,EAAI,EAAGA,EAAIa,EAAIZ,OAAQD,CAAC,GAAI,CACnCD,IAAIiB,EAAIH,EAAII,WAAWjB,CAAC,EACpBgB,EAAI,IACNF,EAAIC,CAAC,IAAMC,GACFA,EAAI,KACbF,EAAIC,CAAC,IAAOC,GAAK,EAAK,KAGL,QAAZ,MAAJA,IACDhB,EAAI,EAAIa,EAAIZ,QACyB,QAAZ,MAAxBY,EAAII,WAAWjB,EAAI,CAAC,IAGrBgB,EAAI,QAAgB,KAAJA,IAAe,KAA6B,KAAtBH,EAAII,WAAW,EAAEjB,CAAC,GACxDc,EAAIC,CAAC,IAAOC,GAAK,GAAM,IACvBF,EAAIC,CAAC,IAAQC,GAAK,GAAM,GAAM,KAI9BF,EAAIC,CAAC,IAAOC,GAAK,GAAM,IACvBF,EAAIC,CAAC,IAAQC,GAAK,EAAK,GAAM,KAC7BF,EAAIC,CAAC,IAAW,GAAJC,EAAU,IAEzB,CACD,OAAOF,CACT,GAqLkDvB,CAAK,EAAGC,CAAO,CAC9D,EAUD0B,aAAa3B,EAAeC,GAG1B,GAAIN,KAAKE,oBAAsB,CAACI,EAC9B,OAAOH,KAAKE,CAAK,EAEZ4B,CAAAA,IA9LyBC,EA8LPlC,KAAKmC,wBAAwB9B,EAAOC,CAAO,EA5LtE,IAAMsB,EAAgB,GACtBf,IAAIuB,EAAM,EACRN,EAAI,EACN,KAAOM,EAAMF,EAAMnB,QAAQ,CACzB,IAWQsB,EAMAC,EACAC,EAlBFC,EAAKN,EAAME,CAAG,IAChBI,EAAK,IACPZ,EAAIE,CAAC,IAAMW,OAAOC,aAAaF,CAAE,EACnB,IAALA,GAAYA,EAAK,KACpBF,EAAKJ,EAAME,CAAG,IACpBR,EAAIE,CAAC,IAAMW,OAAOC,cAAoB,GAALF,IAAY,EAAW,GAALF,CAAQ,GAC7C,IAALE,GAAYA,EAAK,KAKpBH,IACI,EAALG,IAAW,IAAa,GAJlBN,EAAME,CAAG,MAIgB,IAAa,GAHtCF,EAAME,CAAG,MAGoC,EAAW,GAFxDF,EAAME,CAAG,KAGlB,MACFR,EAAIE,CAAC,IAAMW,OAAOC,aAAa,OAAUL,GAAK,GAAG,EACjDT,EAAIE,CAAC,IAAMW,OAAOC,aAAa,OAAc,KAAJL,EAAS,IAE5CC,EAAKJ,EAAME,CAAG,IACdG,EAAKL,EAAME,CAAG,IACpBR,EAAIE,CAAC,IAAMW,OAAOC,cACT,GAALF,IAAY,IAAa,GAALF,IAAY,EAAW,GAALC,CAAQ,EAGrD,CACD,OAAOX,EAAIJ,KAAK,EAAE,EAgKTS,MAA8D,CACtE,EAiBDE,wBAAwB9B,EAAeC,GACrCN,KAAKU,MAAK,EAEV,IAAMiC,EAAgBrC,EAClBN,KAAKH,sBACLG,KAAKL,eAEHiB,EAAmB,GAEzB,IAAKC,IAAIC,EAAI,EAAGA,EAAIT,EAAMU,QAAU,CAClC,IAAMC,EAAQ2B,EAActC,EAAMuC,OAAO9B,CAAC,EAAE,GAGtCI,EADYJ,EAAIT,EAAMU,OACF4B,EAActC,EAAMuC,OAAO9B,CAAC,GAAK,EAIrDM,EAHN,EAAEN,EAEoBT,EAAMU,OACF4B,EAActC,EAAMuC,OAAO9B,CAAC,GAAK,GAIrD+B,EAHN,EAAE/B,EAEoBT,EAAMU,OACF4B,EAActC,EAAMuC,OAAO9B,CAAC,GAAK,GAG3D,GAFA,EAAEA,EAEW,MAATE,GAA0B,MAATE,GAA0B,MAATE,GAA0B,MAATyB,EACrD,MAAM,IAAIC,EAIZlC,EAAOW,KADWP,GAAS,EAAME,GAAS,CACtB,EAEN,KAAVE,IAEFR,EAAOW,KADYL,GAAS,EAAK,IAASE,GAAS,CAC/B,EAEN,KAAVyB,IAEFjC,EAAOW,KADYH,GAAS,EAAK,IAAQyB,CACrB,CAGzB,CAED,OAAOjC,CACR,EAODF,QACE,GAAI,CAACV,KAAKN,eAAgB,CACxBM,KAAKN,eAAiB,GACtBM,KAAKL,eAAiB,GACtBK,KAAKJ,sBAAwB,GAC7BI,KAAKH,sBAAwB,GAG7B,IAAKgB,IAAIC,EAAI,EAAGA,EAAId,KAAKD,aAAagB,OAAQD,CAAC,GAC7Cd,KAAKN,eAAeoB,GAAKd,KAAKD,aAAa6C,OAAO9B,CAAC,EACnDd,KAAKL,eAAeK,KAAKN,eAAeoB,IAAMA,EAC9Cd,KAAKJ,sBAAsBkB,GAAKd,KAAKC,qBAAqB2C,OAAO9B,CAAC,GAClEd,KAAKH,sBAAsBG,KAAKJ,sBAAsBkB,IAAMA,IAGnDd,KAAKF,kBAAkBiB,SAC9Bf,KAAKL,eAAeK,KAAKC,qBAAqB2C,OAAO9B,CAAC,GAAKA,EAC3Dd,KAAKH,sBAAsBG,KAAKD,aAAa6C,OAAO9B,CAAC,GAAKA,EAG/D,CACF,CACD,QAKWgC,UAAgCrC,MAA7CsC,kCACW/C,KAAIgD,KAAG,yBACjB,CAAA,CA4BM,IAAMC,EAAe,SAAUtB,GACpC,IACE,OAAOlC,EAAOuC,aAAaL,EAAK,CAAA,CAAI,CAGrC,CAFC,MAAOuB,GACPC,QAAQC,MAAM,wBAAyBF,CAAC,CACzC,CACD,OAAO,IACT,EChUA,IAAMG,EAAwB,UCjC5B,GAAoB,aAAhB,OAAOC,KACT,OAAOA,KAET,GAAsB,aAAlB,OAAOC,OACT,OAAOA,OAET,GAAsB,aAAlB,OAAOC,OACT,OAAOA,OAET,MAAM,IAAI/C,MAAM,iCAAiC,CACnD,GDwBa,EAACgD,sBAURC,EAA6B,KACjC,IAGMC,EAHN,MAAuB,aAAnB,OAAOC,SAAkD,KAAA,IAAhBA,QAAQC,MAG/CF,EAAqBC,QAAQC,IAAIJ,uBAE9BK,KAAKC,MAAMJ,CAAkB,EALtC,KAAA,CAOF,EAEMK,EAAwB,KAC5B,GAAwB,aAApB,OAAOC,SAAX,CAGApD,IAAIqD,EACJ,IACEA,EAAQD,SAASE,OAAOD,MAAM,+BAA+B,CAK9D,CAJC,MAAOhB,GAGP,MACD,CACD,IAAMkB,EAAUF,GAASjB,EAAaiB,EAAM,EAAE,EAC9C,OAAOE,GAAWN,KAAKC,MAAMK,CAAO,CAVnC,CAWH,EASaC,EAAc,KACzB,IACE,OACE7E,EAA4B,GAC5B6D,EAAuB,GACvBK,EAA4B,GAC5BM,GAWH,CATC,MAAOd,GAOPC,QAAQmB,KAAK,+CAA+CpB,CAAG,CAEhE,CACH,EAmDa,IEnHDqB,WCzBIC,IACd,MACuB,aAArB,OAAOC,WAC2B,UAAlC,OAAOA,UAAqB,UAErBA,UAAqB,UAErB,EAEX,UAyBgBC,IACd,IAAMC,EAAmBN,EAAa,GAAEM,iBACxC,GAAyB,SAArBA,EACF,MAAO,CAAA,EACF,GAAyB,YAArBA,EACT,MAAO,CAAA,EAGT,IACE,MACqD,qBAAnDC,OAAOC,UAAUC,SAASC,KAAKvB,OAAOI,OAAO,CAIhD,CAFC,MAAOV,GACP,MAAO,CAAA,CACR,CACH,UAyCgB8B,IACd,IAAMC,EACc,UAAlB,OAAOC,OACHA,OAAOD,QACY,UAAnB,OAAOE,QACPA,QAAQF,QACRG,KAAAA,EACN,MAA0B,UAAnB,OAAOH,GAAuCG,KAAAA,IAAfH,EAAQI,EAChD,UAOgBC,IACd,MACuB,UAArB,OAAOb,WAAmD,gBAAzBA,UAAmB,OAExD,UAQgBc,IACd,IAAMC,EAAKhB,IACX,OAA8B,GAAvBgB,EAAGC,QAAQ,OAAO,GAAoC,GAA1BD,EAAGC,QAAQ,UAAU,CAC1D,UAyCgBC,IACd,IACE,MAA4B,UAArB,OAAOC,SAGf,CAFC,MAAOzC,GACP,MAAO,CAAA,CACR,CACH,OC3Ha0C,UAAsBnF,MAIjCsC,YAEW8C,EACTC,EAEOC,GAEPC,MAAMF,CAAO,EALJ9F,KAAI6F,KAAJA,EAGF7F,KAAU+F,WAAVA,EAPA/F,KAAIgD,KAdI,gBA6Bf4B,OAAOqB,eAAejG,KAAM4F,EAAcf,SAAS,EAI/CpE,MAAMyF,mBACRzF,MAAMyF,kBAAkBlG,KAAMmG,EAAatB,UAAUuB,MAAM,CAE9D,CACF,OAEYD,EAIXpD,YACmBsD,EACAC,EACAC,GAFAvG,KAAOqG,QAAPA,EACArG,KAAWsG,YAAXA,EACAtG,KAAMuG,OAANA,CACf,CAEJH,OACEP,KACGW,GAEH,IAcuCA,EAdjCT,EAAcS,EAAK,IAAoB,GACvCC,EAAczG,KAAKqG,QAAR,IAAmBR,EAC9Ba,EAAW1G,KAAKuG,OAAOV,GAEvBC,EAAUY,GAUuBF,EAVcT,EAAVW,EAW7BC,QAAQC,EAAS,CAACC,EAAGC,KACnC,IAAMC,EAAQP,EAAKM,GACnB,OAAgB,MAATC,EAAgBtE,OAAOsE,CAAK,MAAQD,KAC7C,CAAC,GAdoE,QAE7DE,EAAiBhH,KAAKsG,iBAAgBR,MAAYW,MAIxD,OAFc,IAAIb,EAAca,EAAUO,EAAajB,CAAU,CAGlE,CACF,CASD,IAAMa,EAAU,gBC7EA,SAAAK,EAAUC,EAAWC,GACnC,GAAID,IAAMC,EAAV,CAIA,IAEWC,EAgBAA,EAlBLC,EAAQzC,OAAO0C,KAAKJ,CAAC,EACrBK,EAAQ3C,OAAO0C,KAAKH,CAAC,EAC3B,IAAWC,KAAKC,EAAO,CACrB,GAAI,CAACE,EAAMC,SAASJ,CAAC,EACnB,MAAO,CAAA,EAGT,IAAMK,EAASP,EAA8BE,GACvCM,EAASP,EAA8BC,GAC7C,GAAIO,GAASF,CAAK,GAAKE,GAASD,CAAK,GACnC,GAAI,CAACT,EAAUQ,EAAOC,CAAK,EACzB,MAAO,CAAA,CACR,MACI,GAAID,IAAUC,EACnB,MAAO,CAAA,CAEV,CAED,IAAWN,KAAKG,EACd,GAAI,CAACF,EAAMG,SAASJ,CAAC,EACnB,MAAO,CAAA,CAtBV,CAyBD,MAAO,CAAA,CACT,CAEA,SAASO,GAASC,GAChB,OAAiB,OAAVA,GAAmC,UAAjB,OAAOA,CAClC,CCrEM,SAAUC,GAAYC,GAG1B,IAAMC,EAAS,GACf,IAAK,GAAM,CAACjB,EAAKC,KAAUnC,OAAOoD,QAAQF,CAAiB,EACrDvH,MAAMC,QAAQuG,CAAK,EACrBA,EAAMkB,QAAQC,IACZH,EAAOxG,KACL4G,mBAAmBrB,CAAG,EAAI,IAAMqB,mBAAmBD,CAAQ,CAAC,CAEhE,CAAC,EAEDH,EAAOxG,KAAK4G,mBAAmBrB,CAAG,EAAI,IAAMqB,mBAAmBpB,CAAK,CAAC,EAGzE,OAAOgB,EAAOhH,OAAS,IAAMgH,EAAOvG,KAAK,GAAG,EAAI,EAClD,CAMM,SAAU4G,GAAkBP,GAChC,IAAMQ,EAA8B,GASpC,OAReR,EAAYlB,QAAQ,MAAO,EAAE,EAAE2B,MAAM,GAAG,EAEhDL,QAAQM,IACb,IACSzB,EAAKC,EADVwB,IACI,CAACzB,EAAKC,GAASwB,EAAMD,MAAM,GAAG,EACpCD,EAAIG,mBAAmB1B,CAAG,GAAK0B,mBAAmBzB,CAAK,EAE3D,CAAC,EACMsB,CACT,CAKM,SAAUI,GAAmBC,GACjC,IAIMC,EAJAC,EAAaF,EAAIjD,QAAQ,GAAG,EAClC,OAAKmD,GAGCD,EAAgBD,EAAIjD,QAAQ,IAAKmD,CAAU,EAC1CF,EAAIG,UACTD,EACgB,EAAhBD,EAAoBA,EAAgBvD,KAAAA,CAAS,GALtC,EAOX,OCEM0D,GAeJ/F,YAAYgG,EAAuBC,GAd3BhJ,KAASiJ,UAAmC,GAC5CjJ,KAAYkJ,aAAkB,GAE9BlJ,KAAamJ,cAAG,EAEhBnJ,KAAAoJ,KAAOC,QAAQC,UACftJ,KAASuJ,UAAG,CAAA,EASlBvJ,KAAKgJ,cAAgBA,EAIrBhJ,KAAKoJ,KACFI,KAAK,KACJT,EAAS/I,IAAI,CACf,CAAC,EACAyJ,MAAMvG,IACLlD,KAAKoD,MAAMF,CAAC,CACd,CAAC,CACJ,CAEDwG,KAAK3C,GACH/G,KAAK2J,gBAAgB,IACnBC,EAASF,KAAK3C,CAAK,CACrB,CAAC,CACF,CAED3D,MAAMA,GACJpD,KAAK2J,gBAAgB,IACnBC,EAASxG,MAAMA,CAAK,CACtB,CAAC,EACDpD,KAAK6J,MAAMzG,CAAK,CACjB,CAED0G,WACE9J,KAAK2J,gBAAgB,IACnBC,EAASE,SAAQ,CACnB,CAAC,EACD9J,KAAK6J,MAAK,CACX,CAQDE,UACEC,EACA5G,EACA0G,GAEAjJ,IAAI+I,EAEJ,GACqBxE,KAAAA,IAAnB4E,GACU5E,KAAAA,IAAVhC,GACagC,KAAAA,IAAb0E,EAEA,MAAM,IAAIrJ,MAAM,mBAAmB,EAoBf2E,KAAAA,KATpBwE,GAmIN,CACEvB,EACA4B,KAEA,GAAmB,UAAf,OAAO5B,GAA4B,OAARA,EAI/B,IAAK,IAAM6B,KAAUD,EACnB,GAAIC,KAAU7B,GAA8B,YAAvB,OAAOA,EAAI6B,GAC9B,OAAO,CAKb,GAxJ2BF,EAA8C,CACjE,OACA,QACA,WACD,EAEUA,EAEA,CACTN,KAAMM,EACN5G,MAAAA,EACA0G,SAAAA,CACc,GAGLJ,OACXE,EAASF,KAAOS,IAEK/E,KAAAA,IAAnBwE,EAASxG,QACXwG,EAASxG,MAAQ+G,IAEO/E,KAAAA,IAAtBwE,EAASE,WACXF,EAASE,SAAWK,IAGtB,IAAMC,EAAQpK,KAAKqK,eAAeC,KAAKtK,KAAMA,KAAKiJ,UAAWlI,MAAM,EAuBnE,OAlBIf,KAAKuJ,WAEPvJ,KAAKoJ,KAAKI,KAAK,KACb,IACMxJ,KAAKuK,WACPX,EAASxG,MAAMpD,KAAKuK,UAAU,EAE9BX,EAASE,SAAQ,CAIpB,CAFC,MAAO5G,IAIX,CAAC,EAGHlD,KAAKiJ,UAAW1H,KAAKqI,CAAuB,EAErCQ,CACR,CAIOC,eAAevJ,GACEsE,KAAAA,IAAnBpF,KAAKiJ,WAAiD7D,KAAAA,IAAtBpF,KAAKiJ,UAAUnI,KAInD,OAAOd,KAAKiJ,UAAUnI,GAEtBd,EAAAA,KAAKmJ,cACsB,IAAvBnJ,KAAKmJ,gBAA8C/D,KAAAA,IAAvBpF,KAAKgJ,eACnChJ,KAAKgJ,cAAchJ,IAAI,CAE1B,CAEO2J,gBAAgBa,GACtB,GAAIxK,CAAAA,KAAKuJ,UAOT,IAAK1I,IAAIC,EAAI,EAAGA,EAAId,KAAKiJ,UAAWlI,OAAQD,CAAC,GAC3Cd,KAAKyK,QAAQ3J,EAAG0J,CAAE,CAErB,CAKOC,QAAQ3J,EAAW0J,GAGzBxK,KAAKoJ,KAAKI,KAAK,KACb,GAAuBpE,KAAAA,IAAnBpF,KAAKiJ,WAAiD7D,KAAAA,IAAtBpF,KAAKiJ,UAAUnI,GACjD,IACE0J,EAAGxK,KAAKiJ,UAAUnI,EAAE,CAQrB,CAPC,MAAOoC,GAIgB,aAAnB,OAAOC,SAA2BA,QAAQC,OAC5CD,QAAQC,MAAMF,CAAC,CAElB,CAEL,CAAC,CACF,CAEO2G,MAAMa,GACR1K,KAAKuJ,YAGTvJ,KAAKuJ,UAAY,CAAA,EACLnE,KAAAA,IAARsF,IACF1K,KAAKuK,WAAaG,GAIpB1K,KAAKoJ,KAAKI,KAAK,KACbxJ,KAAKiJ,UAAY7D,KAAAA,EACjBpF,KAAKgJ,cAAgB5D,KAAAA,CACvB,CAAC,EACF,CACF,CAsCD,SAAS+E,MCrRH,SAAUQ,EACdtE,GAEA,OAAIA,GAAYA,EAA+BuE,UACrCvE,EAA+BuE,UAEhCvE,CAEX,CCRM,SAAUwE,GAAmBnC,GAKjC,IAKE,OAHEA,EAAIoC,WAAW,SAAS,GAAKpC,EAAIoC,WAAW,UAAU,EAClD,IAAIC,IAAIrC,CAAG,EAAEsC,SACbtC,GACMuC,SAAS,wBAAwB,CAG9C,CAFC,OAGJ,EPmBY1G,EAAAA,EAAAA,GAOX,IANCA,EAAA,MAAA,GAAA,QACAA,EAAAA,EAAA,QAAA,GAAA,UACAA,EAAAA,EAAA,KAAA,GAAA,OACAA,EAAAA,EAAA,KAAA,GAAA,OACAA,EAAAA,EAAA,MAAA,GAAA,QACAA,EAAAA,EAAA,OAAA,GAAA,SAGF,IAAM2G,GAA2D,CAC/DC,MAAS5G,EAAS6G,MAClBC,QAAW9G,EAAS+G,QACpBhH,KAAQC,EAASgH,KACjBC,KAAQjH,EAASkH,KACjBrI,MAASmB,EAASmH,MAClBC,OAAUpH,EAASqH,QAMfC,GAA4BtH,EAASgH,KAmBrCO,GAAgB,EACnBvH,EAAS6G,OAAQ,OACjB7G,EAAS+G,SAAU,OACnB/G,EAASgH,MAAO,QAChBhH,EAASkH,MAAO,QAChBlH,EAASmH,OAAQ,SAQdK,GAAgC,CAACC,EAAUC,KAAYC,KAC3D,GAAID,EAAAA,EAAUD,EAASG,UAAvB,CAGA,IAAMC,GAAM,IAAIC,MAAOC,YAAW,EAC5BpC,EAAS4B,GAAcG,GAC7B,GAAI/B,CAAAA,EAMF,MAAM,IAAIzJ,oEACsDwL,IAAU,EAN1E9I,QAAQ+G,OACFkC,OAASJ,EAAShJ,QACtB,GAAGkJ,CAAI,CANV,CAaH,QQ/FaK,GAiBXxJ,YACWC,EACAwJ,EACAC,GAFAzM,KAAIgD,KAAJA,EACAhD,KAAewM,gBAAfA,EACAxM,KAAIyM,KAAJA,EAnBXzM,KAAiB0M,kBAAG,CAAA,EAIpB1M,KAAY2M,aAAe,GAE3B3M,KAAA4M,kBAA2C,OAE3C5M,KAAiB6M,kBAAwC,IAYrD,CAEJC,qBAAqBC,GAEnB,OADA/M,KAAK4M,kBAAoBG,EAClB/M,IACR,CAEDgN,qBAAqBN,GAEnB,OADA1M,KAAK0M,kBAAoBA,EAClB1M,IACR,CAEDiN,gBAAgBC,GAEd,OADAlN,KAAK2M,aAAeO,EACblN,IACR,CAEDmN,2BAA2BC,GAEzB,OADApN,KAAK6M,kBAAoBO,EAClBpN,IACR,CACF,CCrCY,IAAAqN,GAAa,CAExBC,SAAU,eAEVC,OAAQ,aAERC,OAAQ,aAERC,SAAU,WAEVC,MAAO,QAEPC,QAAS,aACA,EA2CEC,GAAsB,CAEjCC,aAAc,eAEdC,eAAgB,iBAEhBC,cAAe,gBAEfC,8BAA+B,gCAE/BC,wBAAyB,0BAEzBC,aAAc,gBC4ShB,SAASC,KAIP,MAAO,CACLC,wCACE,0LAIN,CA/QA,SAwRaC,KAvRX,MAAO,CACLC,6BACE,uDACFC,iBAAgC,GAChCC,qBACE,6LAGFC,oBACE,qJAGFC,uBACE,kKAGFC,eACE,+EAEFC,oBAAmC,kCACnCC,mBAAkC,iCAClCC,4BACE,uEACFC,wBACE,wDACFC,wBACE,6GAEFZ,wCACE,0LAGFa,6BACE,+FAEFC,kCACE,wDACFC,uBACE,0DACFC,yBACE,gKAGFC,sBAAkC,+BAClCC,0BACE,mFACFC,iBAAgC,sCAChCC,yBACE,sIAEFC,iBACE,uEACFC,qBACE,sLAGFC,qBAAoC,sCACpCC,4BACE,wLAGFC,uBACE,uDACFC,gCACE,gOAIFC,uBACE,wEACFC,8BACE,4FACFC,gBAA+B,wCAC/BC,0BACE,qEACFC,kBACE,sEACFC,oBACE,kDACFC,qBACE,uEACFC,0BACE,+KAEFC,+BACE,iFACFC,yBACE,uGAEFC,0BACE,0FAEFC,sBACE,+IAEFC,sBACE,2GAEFC,iBACE,gEACFC,2BACE,oFACFC,uBACE,gPAIFC,sBACE,wCACFC,0BACE,4GAEFC,iBACE,6KAEFC,0BACE,2EACFC,oBACE,4CACFC,gBACE,4DACFC,2BACE,2FACFC,8BACE,8HAEFC,yBACE,gIAEFC,4BACE,6EACFC,uBACE,kDACFC,uBAAsC,sCACtCC,wBACE,oEACFC,2BACE,oKAGFC,mBAAkC,wCAClCC,4BACE,2CACFC,+BACE,mEACFC,uBACE,wEACFC,0BACE,uEACFC,cACE,iDACFC,8BACE,2EACFC,6BACE,yEACFC,2CACE,wJAGFC,yBACE,kGACFC,gBAA+B,sCAC/BC,mBACE,6DACFC,YACE,0GAEFC,wBACE,yJAGFC,8CACE,kLAGFC,gBACE,4FACFC,uBACE,yEACFC,0BACE,kEACFC,iBACE,4DACFC,6BACE,2EACFC,6BACE,mDACFC,sBACE,6DACFC,+BACE,yDACFC,uCACE,4EACFC,qBACE,sEACFC,QAAyB,+BACzBC,qBACE,yEACFC,oBACE,0FAEFC,4BACE,2GAEFC,2BACE,sHACFC,+BACE,2EACFC,+BACE,6DACFC,mBACE,2CACFC,iBACE,wEACFC,iBACE,4FAEFC,gBACE,0DACFC,gBACE,+EACFC,kBAAiC,GACjCC,gBACE,kDACFC,0BACE,+EACFC,sBACE,oOAIFC,0BACE,sEACFC,0BACE,sEACFC,2BACE,uEACFC,wBACE,oEACFC,sBACE,4EACFC,4BACE,wEACFC,mBAAkC,8BAClCC,4BACE,wEACFC,6CACE,iIACFC,sCACE,+CACFC,8BACE,2LAGN,CAyBO,IASMC,GAA6B9G,GAuD7B+G,GAA8B,IAAI/O,EAG7C,OAAQ,WAAYgI,GAAe,CAAA,ECjd/BgH,GAAY,UX8GhBpS,YAAmBC,GAAAhD,KAAIgD,KAAJA,EAUXhD,KAASoV,UAAGvJ,GAsBZ7L,KAAWqV,YAAetJ,GAc1B/L,KAAesV,gBAAsB,IAzC5C,CAODnJ,eACE,OAAOnM,KAAKoV,SACb,CAEDjJ,aAAaoJ,GACX,GAAI,EAAEA,KAAOhR,GACX,MAAM,IAAIiR,4BAA4BD,6BAA+B,EAEvEvV,KAAKoV,UAAYG,CAClB,CAGDE,YAAYF,GACVvV,KAAKoV,UAA2B,UAAf,OAAOG,EAAmBrK,GAAkBqK,GAAOA,CACrE,CAODG,iBACE,OAAO1V,KAAKqV,WACb,CACDK,eAAeH,GACb,GAAmB,YAAf,OAAOA,EACT,MAAM,IAAIC,UAAU,mDAAmD,EAEzExV,KAAKqV,YAAcE,CACpB,CAMDI,qBACE,OAAO3V,KAAKsV,eACb,CACDK,mBAAmBJ,GACjBvV,KAAKsV,gBAAkBC,CACxB,CAMDpK,SAASe,GACPlM,KAAKsV,iBAAmBtV,KAAKsV,gBAAgBtV,KAAMuE,EAAS6G,MAAO,GAAGc,CAAI,EAC1ElM,KAAKqV,YAAYrV,KAAMuE,EAAS6G,MAAO,GAAGc,CAAI,CAC/C,CACD0J,OAAO1J,GACLlM,KAAKsV,iBACHtV,KAAKsV,gBAAgBtV,KAAMuE,EAAS+G,QAAS,GAAGY,CAAI,EACtDlM,KAAKqV,YAAYrV,KAAMuE,EAAS+G,QAAS,GAAGY,CAAI,CACjD,CACD5H,QAAQ4H,GACNlM,KAAKsV,iBAAmBtV,KAAKsV,gBAAgBtV,KAAMuE,EAASgH,KAAM,GAAGW,CAAI,EACzElM,KAAKqV,YAAYrV,KAAMuE,EAASgH,KAAM,GAAGW,CAAI,CAC9C,CACDV,QAAQU,GACNlM,KAAKsV,iBAAmBtV,KAAKsV,gBAAgBtV,KAAMuE,EAASkH,KAAM,GAAGS,CAAI,EACzElM,KAAKqV,YAAYrV,KAAMuE,EAASkH,KAAM,GAAGS,CAAI,CAC9C,CACD9I,SAAS8I,GACPlM,KAAKsV,iBAAmBtV,KAAKsV,gBAAgBtV,KAAMuE,EAASmH,MAAO,GAAGQ,CAAI,EAC1ElM,KAAKqV,YAAYrV,KAAMuE,EAASmH,MAAO,GAAGQ,CAAI,CAC/C,CACF,EW7L4B,gBAAgB,EAuB7B,SAAA2J,GAAUC,KAAgB5J,GACpCiJ,GAAUhJ,UAAY5H,EAASmH,OACjCyJ,GAAU/R,eAAe2S,GAAWA,iBAAMD,EAAO,GAAG5J,CAAI,CAE5D,CCWgB,SAAA8J,EACdC,KACGC,GAEH,MAAMC,GAAoBF,EAAY,GAAGC,CAAI,CAC/C,CAagB,SAAAE,EACdH,KACGC,GAEH,OAAOC,GAAoBF,EAAY,GAAGC,CAAI,CAChD,CAEgB,SAAAG,GACdC,EACAzQ,EACAC,GAEA,IAAMyQ,EAAW,CACf,GAAItB,GAAoC,GACvCpP,GAAOC,GAOV,OALgB,IAAIK,EAClB,OACA,WACAoQ,CAAQ,EAEKnQ,OAAOP,EAAM,CAC1B2Q,QAASF,EAAKtT,IACf,CAAA,CACH,CAEM,SAAUyT,EACdH,GAEA,OAAOD,GACLC,EAEA,8CAAA,gGAAgG,CAEpG,CAEgB,SAAAI,GACdJ,EACAK,EACA3K,GAEA,IAAM4K,EAAsB5K,EAC5B,GAAI,EAAE2K,aAAkBC,GAKtB,MAJIA,EAAoB5T,OAAS2T,EAAO5T,YAAYC,MAClDgT,EAAMM,EAAI,kBAGND,GACJC,EAEA,4BAAWK,EAAO5T,YAAYC,yCAC5B,qDAAqD,CAG7D,CAEA,SAASmT,GACPF,KACGC,GAEH,IACQrQ,EACAgR,EAFR,MAA0B,UAAtB,OAAOZ,GACHpQ,EAAOqQ,EAAK,IACZW,EAAa,CAAC,GAAGX,EAAKY,MAAM,CAAC,IACpB,KACbD,EAAW,GAAGL,QAAUP,EAAWjT,MAG7BiT,EAA4Bc,cAAc3Q,OAChDP,EACA,GAAGgR,CAAU,GAIV3B,GAA4B9O,OACjC6P,EACA,GAAIC,CAA+B,CAEvC,CAeM,SAAUc,EACdC,EACAhB,KACGC,GAEH,GAAI,CAACe,EACH,MAAMd,GAAoBF,EAAY,GAAGC,CAAI,CAEjD,CA4FM,SAAUgB,EAAUC,GAGxB,IAAMrR,EAAU,8BAAgCqR,EAMhD,MALAtB,GAAU/P,CAAO,EAKX,IAAIrF,MAAMqF,CAAO,CACzB,CASgB,SAAAsR,EACdH,EACAnR,GAEKmR,GACHC,EAAUpR,CAAO,CAErB,CCvRgB,SAAAuR,KACd,MAAwB,aAAhB,OAAO/T,MAAwBA,KAAKgU,UAAUC,MAAS,EACjE,CAEgB,SAAAC,KACd,MAA+B,UAAxBC,GAAiB,GAA0C,WAAxBA,GAAiB,CAC7D,CAEgB,SAAAA,KACd,MAAwB,aAAhB,OAAOnU,MAAwBA,KAAKgU,UAAUI,UAAa,IACrE,OCGaC,GAIX5U,YACmB6U,EACAC,GAGjBT,GAJiBpX,KAAU4X,WAAVA,IACA5X,KAAS6X,UAATA,GAKf,6CAA6C,EAE/C7X,KAAK8X,SbMa,aAAlB,OAAOvU,QAGP,CAAC,EAAEA,OAAgB,SAAKA,OAAiB,UAAKA,OAAiB,WAC/D,oDAAoDwU,KAAKvT,EAAK,CAAE,GaV3Bc,EAAa,CACnD,CAED0S,MACE,MCtBqB,aAArB,OAAOvT,WACPA,WACA,WAAYA,WACgB,WAA5B,OAAOA,UAAUwT,SAMhBT,GAAgB,GAAIxS,EAAkB,GAAM,eAAgBP,YAEtDA,CAAAA,UAAUwT,ODaRC,KAAKC,IAAG,IAAmBnY,KAAK4X,UAAU,EAM5C5X,KAAK8X,SAAW9X,KAAK6X,UAAY7X,KAAK4X,UAC9C,CACF,CErCe,SAAAQ,GAAaC,EAAwBC,GACnDlB,EAAYiB,EAAOE,SAAU,oCAAoC,EACjE,IAAQ7P,EAAQ2P,EAAOE,SAAZ,IAEX,OAAKD,EAIE,GAAG5P,GAAM4P,EAAKxN,WAAW,GAAG,EAAIwN,EAAKxB,MAAM,CAAC,EAAIwB,GAH9C5P,CAIX,OCVa8P,GAKXC,kBACEC,EACAC,EACAC,GAEA5Y,KAAK0Y,UAAYA,EACbC,IACF3Y,KAAK2Y,YAAcA,GAEjBC,IACF5Y,KAAK4Y,aAAeA,EAEvB,CAEDC,eACE,OAAI7Y,KAAK0Y,YAGW,aAAhB,OAAOpV,MAAwB,UAAWA,KACrCA,KAAKuV,MAEY,aAAtB,OAAOC,YAA8BA,WAAWD,MAC3CC,WAAWD,MAEC,aAAjB,OAAOA,MACFA,MAET3B,KAAAA,EACE,iHAAiH,EAEpH,CAED6B,iBACE,OAAI/Y,KAAK2Y,cAGW,aAAhB,OAAOrV,MAAwB,YAAaA,KACvCA,KAAK0V,QAEY,aAAtB,OAAOF,YAA8BA,WAAWE,QAC3CF,WAAWE,QAEG,aAAnB,OAAOA,QACFA,QAET9B,KAAAA,EACE,mHAAmH,EAEtH,CAED+B,kBACE,OAAIjZ,KAAK4Y,eAGW,aAAhB,OAAOtV,MAAwB,aAAcA,KACxCA,KAAK4V,SAEY,aAAtB,OAAOJ,YAA8BA,WAAWI,SAC3CJ,WAAWI,SAEI,aAApB,OAAOA,SACFA,SAEThC,KAAAA,EACE,oHAAoH,EAEvH,CACF,CC0CM,IAAMiC,GAAyD,CAEpEC,oBAAoE,wBAEpEC,qBAAgE,iBAGhEC,mBAA6D,gBAE7DC,qBAAgE,iBAGhEC,iBAA8D,iBAE9DC,iBAA8D,mBAG9DC,0BAAyE,qBAGzEC,aAAsD,uBACtDC,wBAA0E,wBAG1EC,qBAAoE,qBACpEC,sBAAqE,qBACrEC,iCACyC,4BAGzCC,iBAA4D,iBAG5DC,gBAAyD,iBACzDC,4BAC2C,oBAE3CC,iBAA8D,sBAC9DC,iBAA8D,sBAE9DC,iBAA4D,iBAG5DC,+BAC8C,wBAC9CC,iBAA0D,qBAC1DC,cAAwD,qBACxDC,eAAyD,qBAGzDC,4BAC2C,oBAC3CC,oCACmD,sCAGnDC,aAAsD,4BACtDC,qBAAsE,0BACtEC,wBAAuE,qBACvEC,qBAAsE,0BACtEC,gBAAyD,eAKzDC,6BAC4C,2BAC5CC,oBAAoE,4BAGpEC,wBAA4E,0BAG5EC,qBAAsE,6BAGtEC,+BACmC,+BACnCC,yBAAwE,8BACxEC,0BAAuE,4BACvEC,+BACmC,+BACnCC,qBAC8C,+BAC9CC,6BAC4C,uCAG5CC,iCAA4E,iBAG5EC,sBAAwE,wBACxEC,wBAA4E,0BAC5EC,wBAA4E,0BAC5EC,yBACwC,2BACxCC,oBAAoE,sBACpEC,0BACyC,4BACzCC,0BACyC,4BACzCC,iBAA8D,kBAC/D,ECzJKC,GAAuC,0LAyChCC,GAAyB,IAAI1E,GAAM,IAAQ,GAAM,EAE9C,SAAA2E,EACdhG,EACAiG,GAEA,OAAIjG,EAAKkG,UAAY,CAACD,EAAQC,SACrB,CACL,GAAGD,EACHC,SAAUlG,EAAKkG,UAGZD,CACT,CAEOE,eAAeC,EACpBpG,EACApM,EACAoO,EACAiE,EACAI,EAAuD,IAEvD,OAAOC,GAA+BtG,EAAMqG,EAAgBF,UAC1D5b,IAAIgc,EAAO,GACP9U,EAAS,GACTwU,IAC2B,QAAzBrS,EACFnC,EAASwU,EAETM,EAAO,CACLA,KAAM/Y,KAAKgZ,UAAUP,CAAO,IAKlC,IAAMQ,EAAQlV,GAAY,CACxBf,IAAKwP,EAAK+B,OAAO2E,OACjB,GAAGjV,CACJ,CAAA,EAAE+O,MAAM,CAAC,EAEJiC,EAAUkE,MAAO3G,EAAsB4G,wBAOvCC,GANNpE,EAAO,gBAA4B,mBAE/BzC,EAAK8G,eACPrE,EAAqC,qBAAGzC,EAAK8G,cAGhB,CAC7BlT,OAAAA,EACA6O,QAAAA,EACA,GAAG8D,IAeL,MlBlFqB,aAArB,OAAOpY,WACiB,uBAAxBA,UAAU4Y,YkB0ERF,EAAUG,eAAiB,eAGzBhH,EAAKiH,gBAAkB1S,GAAmByL,EAAKiH,eAAeC,IAAI,IACpEL,EAAUM,YAAc,WAGnBjF,GAAcK,MAAK,EACxBoE,MAAMS,GAAgBpH,EAAMA,EAAK+B,OAAOsF,QAASrF,EAAMyE,CAAK,EAC5DI,CAAS,CAEb,CAAC,CACH,CAEOV,eAAeG,GACpBtG,EACAqG,EACAiB,GAECtH,EAAsBuH,iBAAmB,CAAA,EAC1C,IAAMtH,EAAW,CAAE,GAAG4C,GAAkB,GAAGwD,CAAc,EACzD,IACE,IAAMmB,EAAiB,IAAIC,GAAyBzH,CAAI,EAClD2C,EAAqBgE,MAAM5T,QAAQ2U,KAAwB,CAC/DJ,EAAS,EACTE,EAAeG,QAChB,EAMKC,GAFNJ,EAAeK,oBAAmB,EAErBlB,MAAMhE,EAASiF,QAC5B,GAAI,qBAAsBA,EACxB,MAAME,GAAiB9H,EAAuC,2CAAA4H,CAAI,EAGpE,GAAIjF,EAASoF,MAAQ,iBAAkBH,GACrC,OAAOA,EAEP,GACM,CAACI,EAAiBC,IADHtF,EAASoF,GAAKH,EAAKM,aAAeN,EAAK9a,MAAM0C,SACPwC,MAAM,KAAK,EACtE,GAAoE,qCAAhEgW,EACF,MAAMF,GACJ9H,EAEA,4BAAA4H,CAAI,EAED,GAAgD,iBAA5CI,EACT,MAAMF,GAAiB9H,EAAkC,uBAAA4H,CAAI,EACxD,GAAiD,kBAA7CI,EACT,MAAMF,GAAiB9H,EAAmC,gBAAA4H,CAAI,EAEhE,IAAMO,EACJlI,EAAS+H,IACRA,EACEI,YAAa,EACb/X,QAAQ,UAAW,GAAG,EAC3B,GAAI4X,EACF,MAAMlI,GAAwBC,EAAMmI,EAAWF,CAAkB,EAEjEvI,EAAMM,EAAMmI,CAAS,CAW1B,CARC,MAAOvb,GACP,GAAIA,aAAa0C,EACf,MAAM1C,EAKR8S,EAAMM,EAA4C,yBAAA,CAAExQ,QAAWrD,OAAOS,CAAC,CAAC,CAAE,CAC3E,CACH,CAEOuZ,eAAekC,EACpBrI,EACApM,EACAoO,EACAiE,EACAI,EAAuD,IAEvD,IAAMiC,EAAiB3B,MAAMP,EAC3BpG,EACApM,EACAoO,EACAiE,EACAI,CAAc,EAQhB,MANI,yBAA0BiC,GAC5B5I,EAAMM,EAAkC,6BAAA,CACtCuI,gBAAiBD,CAClB,CAAA,EAGIA,CACT,CAEOnC,eAAeiB,GACpBpH,EACAkH,EACAlF,EACAyE,GAEA,IAAM+B,EAAO,GAAGtB,EAAOlF,EAAV,IAAkByE,EAEzBgC,EAAezI,EACf0I,EAAcD,EAAa1G,OAAOE,SACpCH,GAAa9B,EAAK+B,OAA0ByG,CAAI,EAC7CxI,EAAK+B,OAAO4G,UAAf,MAA8BH,EAKlC,GAAI1C,GAA2B5U,SAAS8Q,CAAI,IAG1C2E,MAAM8B,EAAaG,6BACmB,WAAlCH,EAAaI,oBAAqB,GAGpC,OADEJ,EAAaK,kBACU1B,gBAAgBsB,CAAW,EAAEla,SAAQ,EAIlE,OAAOka,CACT,OAiBMjB,GAaJI,sBACEkB,aAAarf,KAAKsf,KAAK,CACxB,CAEDvc,YAA6BuT,GAAAtW,KAAIsW,KAAJA,EAbrBtW,KAAKsf,MAAe,KACnBtf,KAAOie,QAAG,IAAI5U,QAAW,CAACxC,EAAG0Y,KACpCvf,KAAKsf,MAAQE,WAAW,IACfD,EACLnJ,EAAapW,KAAKsW,KAA2C,wBAAA,CAAA,EAE9D+F,GAAuBrE,IAAG,CAAE,CACjC,CAAC,CAM0C,CAC5C,CAOe,SAAAoG,GACd9H,EACAzQ,EACAoT,GAEA,IAAMwG,EAAgC,CACpCjJ,QAASF,EAAKtT,MAUVI,GAPF6V,EAASyG,QACXD,EAAYC,MAAQzG,EAASyG,OAE3BzG,EAAS0G,cACXF,EAAYE,YAAc1G,EAAS0G,aAGvBvJ,EAAaE,EAAMzQ,EAAM4Z,CAAW,GAIlD,OADCrc,EAAM2C,WAAwC6Z,eAAiB3G,EACzD7V,CACT,CC9UM,SAAUyc,GACdC,GAEA,OACiB1a,KAAAA,IAAf0a,GAC0C1a,KAAAA,IAAzC0a,EAAyBC,WAE9B,CAsBM,SAAUC,GACdF,GAEA,OACiB1a,KAAAA,IAAf0a,GACkD1a,KAAAA,IAAjD0a,EAAkCG,UAEvC,OASaC,GAWXnd,YAAYkW,GACV,GARFjZ,KAAOmgB,QAAW,GAKlBngB,KAAyBogB,0BAAwC,GAGjChb,KAAAA,IAA1B6T,EAASoH,aACX,MAAM,IAAI5f,MAAM,wBAAwB,EAG1CT,KAAKmgB,QAAUlH,EAASoH,aAAa/X,MAAM,GAAG,EAAE,GAChDtI,KAAKogB,0BAA4BnH,EAASmH,yBAC3C,CAQDE,4BAA4BC,GAC1B,GACGvgB,KAAKogB,2BACoC,IAA1CpgB,KAAKogB,0BAA0Brf,OAKjC,IAAK,IAAMqf,KAA6BpgB,KAAKogB,0BAC3C,GACEA,EAA0BI,UAC1BJ,EAA0BI,WAAaD,EACvC,CDiMN,OC/LQH,EAA0BK,kBDgMhC,IAAK,UACH,MAAgC,UAClC,IAAK,QACH,MAA8B,QAChC,IAAK,MACH,MAA4B,MAC9B,QACE,MAAsD,+BACzD,CCzMYC,MAGR,CAEH,OAAO,IACR,CAQDC,kBAAkBJ,GAChB,MAE4B,YAD1BvgB,KAAKsgB,4BAA4BC,CAAW,GAEC,UAA7CvgB,KAAKsgB,4BAA4BC,CAAW,CAE/C,CAQDK,uBACE,OACE5gB,KAAK2gB,kBAAgE,yBAAA,GACrE3gB,KAAK2gB,kBAAuD,iBAE/D,CACF,CC9FMlE,eAAeoE,GACpBvK,EACAiG,GAEA,OAAOG,EAILpG,EAGA,MAAA,sBAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,CCeOE,eAAeqE,GACpBxK,EACAiG,GAEA,OAAOG,EACLpG,EAGA,OAAA,sBAAAiG,CAAO,CAEX,CCjFM,SAAUwE,GACdC,GAEA,GAAKA,EAGL,IAEE,IAAMC,EAAO,IAAI5U,KAAK6U,OAAOF,CAAY,CAAC,EAE1C,GAAI,CAACG,MAAMF,EAAKG,QAAS,CAAA,EAEvB,OAAOH,EAAKI,aAIf,CAFC,MAAOne,IAIX,CCsDA,SAASoe,GAA4BC,GACnC,OAAyB,IAAlBL,OAAOK,CAAO,CACvB,CAEM,SAAUC,GAAYjZ,GAC1B,GAAM,CAACkZ,EAAWC,EAASC,GAAapZ,EAAMD,MAAM,GAAG,EACvD,GACgBlD,KAAAA,IAAdqc,GACYrc,KAAAA,IAAZsc,GACctc,KAAAA,IAAduc,EAGA,OADA9L,GAAU,gDAAgD,EACnD,KAGT,IACE,IAAMzR,EAAUnB,EAAaye,CAAO,EACpC,OAAKtd,EAIEN,KAAKC,MAAMK,CAAO,GAHvByR,GAAU,qCAAqC,EACxC,KASV,CANC,MAAO3S,GAKP,OAJA2S,GACE,2CACC3S,GAAa4B,SAAU,CAAA,EAEnB,IACR,CACH,CAKM,SAAU8c,GAAgBrZ,GAC9B,IAAMsZ,EAAcL,GAAYjZ,CAAK,EAIrC,OAHAyO,EAAQ6K,EAAW,kBACnB7K,EAAmC,KAAA,IAApB6K,EAAYC,sBAC3B9K,EAAmC,KAAA,IAApB6K,EAAYE,sBACpBb,OAAOW,EAAYC,GAAG,EAAIZ,OAAOW,EAAYE,GAAG,CACzD,CC3GOtF,eAAeuF,EACpBC,EACAhE,EACAiE,EAAkB,CAAA,GAElB,GAAIA,EACF,OAAOjE,EAET,IACE,OAAOhB,MAAMgB,CASd,CARC,MAAO/a,GAOP,MANIA,aAAa0C,IAUQC,EAVSsc,CAAkBjf,QAAlBif,GAYzB,uBAATtc,GACS,4BAATA,KAZMoc,EAAK3L,KAAK8L,cAAgBH,GAC5BhF,MAAMgF,EAAK3L,KAAK+L,WAIdnf,CACP,CACH,OCbaof,GAUXvf,YAA6Bkf,GAAAjiB,KAAIiiB,KAAJA,EATrBjiB,KAASuiB,UAAG,CAAA,EAMZviB,KAAOwiB,QAAe,KACtBxiB,KAAAyiB,aAA0C,GAEC,CAEnDC,SACM1iB,KAAKuiB,YAITviB,KAAKuiB,UAAY,CAAA,EACjBviB,KAAK2iB,SAAQ,EACd,CAEDC,QACO5iB,KAAKuiB,YAIVviB,KAAKuiB,UAAY,CAAA,EACI,OAAjBviB,KAAKwiB,UACPnD,aAAarf,KAAKwiB,OAAO,CAE5B,CAEOK,YAAYC,GAClB,IAWQC,EAXR,OAAID,GACIC,EAAW/iB,KAAKyiB,aACtBziB,KAAKyiB,aAAevK,KAAKC,IACH,EAApBnY,KAAKyiB,mBAGAM,IAGP/iB,KAAKyiB,aAAY,IAEXM,GADU/iB,KAAKiiB,KAAKe,gBAAgBC,gBAAkB,GACjC5W,KAAKD,IAAG,EAAE,IAE9B8L,KAAKgL,IAAI,EAAGH,CAAQ,EAE9B,CAEOJ,SAASG,EAAW,CAAA,GAC1B,IAKMC,EALD/iB,KAAKuiB,YAKJQ,EAAW/iB,KAAK6iB,YAAYC,CAAQ,EAC1C9iB,KAAKwiB,QAAUhD,WAAW/C,UACxBQ,MAAMjd,KAAKmjB,WACZ,EAAEJ,CAAQ,EACZ,CAEOI,kBACN,IACElG,MAAMjd,KAAKiiB,KAAKmB,WAAW,CAAA,CAAI,CAWhC,CAVC,MAAOlgB,GASP,OAPA,KAEE,gCADCA,GAAqB2C,MAGtB7F,KAAK2iB,SAAwB,CAAA,CAAI,EAIpC,CACD3iB,KAAK2iB,SAAQ,CACd,CACF,OCrFYU,GAIXtgB,YACUugB,EACAC,GADAvjB,KAASsjB,UAATA,EACAtjB,KAAWujB,YAAXA,EAERvjB,KAAKwjB,gBAAe,CACrB,CAEOA,kBACNxjB,KAAKyjB,eAAiB1C,GAAyB/gB,KAAKujB,WAAW,EAC/DvjB,KAAK0jB,aAAe3C,GAAyB/gB,KAAKsjB,SAAS,CAC5D,CAEDK,MAAMC,GACJ5jB,KAAKsjB,UAAYM,EAASN,UAC1BtjB,KAAKujB,YAAcK,EAASL,YAC5BvjB,KAAKwjB,gBAAe,CACrB,CAEDK,SACE,MAAO,CACLP,UAAWtjB,KAAKsjB,UAChBC,YAAavjB,KAAKujB,YAErB,CACF,CCnBM9G,eAAeqH,GAAqB7B,GACzC,IAgEA8B,EACAC,EAjEM1N,EAAO2L,EAAK3L,KACZ2N,EAAUhH,MAAMgF,EAAKmB,aACrBnK,EAAWgE,MAAM+E,EACrBC,EACAnB,GAAexK,EAAM,CAAE2N,QAAAA,CAAS,CAAA,CAAC,EAK7BC,GAFNlN,EAAQiC,GAAUkL,MAAMpjB,OAAQuV,EAAI,gBAAA,EAEhB2C,EAASkL,MAAM,IAI7BC,GAFNnC,EAAKoC,sBAAsBH,CAAW,EAEdA,EAAYI,kBAAkBvjB,OAClDwjB,GAAoBL,EAAYI,gBAAgB,EAChD,IAEEE,GA+CNT,EA/CuC9B,EAAKuC,aAgD5CR,EAhD0DI,EAqDnD,CAAC,GAHQL,EAASU,OACvBC,GAAK,CAACV,EAAQW,KAAKC,GAAKA,EAAEC,aAAeH,EAAEG,UAAU,CAAC,EAEpC,GAAGb,IA7CjBc,EACJ,EAAE7C,EAAKvC,OAASwE,EAAYa,cAAkBP,EAAczjB,QACxDikB,EAAeC,CAAAA,CAHEhD,EAAK+C,aAGkBF,EAExCI,EAAiC,CACrCC,IAAKjB,EAAYkB,QACjBC,YAAanB,EAAYmB,aAAe,KACxCC,SAAUpB,EAAYqB,UAAY,KAClC7F,MAAOwE,EAAYxE,OAAS,KAC5B8F,cAAetB,EAAYsB,eAAiB,CAAA,EAC5C7F,YAAauE,EAAYvE,aAAe,KACxCnD,SAAU0H,EAAY1H,UAAY,KAClCgI,aAAAA,EACAZ,SAAU,IAAIP,GAAaa,EAAYZ,UAAWY,EAAYX,WAAW,EACzEyB,YAAAA,GAGFpgB,OAAO6gB,OAAOxD,EAAMiD,CAAO,CAC7B,CA8BM,SAAUX,GAAoBmB,GAClC,OAAOA,EAAUC,IAAI,CAAA,CAAGd,WAAAA,KAAerE,CAAU,KACxC,CACLqE,WAAAA,EACAM,IAAK3E,EAASoF,OAAS,GACvBP,YAAa7E,EAAS6E,aAAe,KACrC3F,MAAOc,EAASd,OAAS,KACzBC,YAAaa,EAASb,aAAe,KACrC2F,SAAU9E,EAAS+E,UAAY,MAElC,CACH,OC3EaM,GAAb9iB,cACE/C,KAAY8lB,aAAkB,KAC9B9lB,KAAW+lB,YAAkB,KAC7B/lB,KAAcijB,eAAkB,IAoIjC,CAlIC+C,gBACE,MACE,CAAChmB,KAAKijB,gBACN5W,KAAKD,IAAK,EAAGpM,KAAKijB,eAAqC,GAE1D,CAEDgD,yBACEhN,GAEAjC,EAAQiC,EAASgL,0BACjBjN,EAC8B,KAAA,IAArBiC,EAASgL,0BAGlBjN,EACmC,KAAA,IAA1BiC,EAAS6M,+BAGlB,IAAMI,EACJ,cAAejN,GAA0C,KAAA,IAAvBA,EAASiN,UACvChF,OAAOjI,EAASiN,SAAS,EACzBtE,GAAgB3I,EAASgL,OAAO,EACtCjkB,KAAKmmB,0BACHlN,EAASgL,QACThL,EAAS6M,aACTI,CAAS,CAEZ,CAEDE,kBAAkBnC,GAChBjN,EAA2B,IAAnBiN,EAAQljB,yBAChB,IAAMmlB,EAAYtE,GAAgBqC,CAAO,EACzCjkB,KAAKmmB,0BAA0BlC,EAAS,KAAMiC,CAAS,CACxD,CAEDG,eACE/P,EACAgQ,EAAe,CAAA,GAEf,OAAKA,GAAgBtmB,CAAAA,KAAK+lB,aAAgB/lB,KAAKgmB,WAI/ChP,EAAQhX,KAAK8lB,aAAcxP,wBAEvBtW,KAAK8lB,cACP7I,MAAMjd,KAAKumB,QAAQjQ,EAAMtW,KAAK8lB,YAAa,EACpC9lB,KAAK+lB,aAGP,MAVE/lB,KAAK+lB,WAWf,CAEDS,oBACExmB,KAAK8lB,aAAe,IACrB,CAEOS,cAAcjQ,EAAoBmQ,GCvC1CX,ED0CIW,EAFF,ICzCFnQ,EACAwP,EDwCQ,CAAEC,YAAAA,EAAaD,aAAAA,EAAcI,UAAAA,CAAS,EAAKjJ,KCF5C,CACL8I,aArCI9M,EACJgE,MAAML,GAJRtG,ED0CIA,ECpCA,GACAmG,UACE,IAAMI,EAAOhV,GAAY,CACvB6e,WAAc,gBACdC,cAAiBb,CAClB,CAAA,EAAEhP,MAAM,CAAC,EACJ,CAAE8P,aAAAA,EAAc5J,OAAAA,GAAW1G,EAAK+B,OAChC3P,EAAMuU,MAAMS,GAChBpH,EACAsQ,EAEA,YAAA,OAAO5J,CAAQ,EAGXjE,EAAUkE,MAAO3G,EAAsB4G,wBAGvC2J,GAFN9N,EAAO,gBAA4B,oCAEN,CAC3B7O,OAAuB,OACvB6O,QAAAA,EACA8D,KAAAA,IAQF,OALEvG,EAAKiH,gBACL1S,GAAmByL,EAAKiH,eAAeC,IAAI,IAE3CqJ,EAAQpJ,YAAc,WAEjBjF,GAAcK,MAAK,EAAGnQ,EAAKme,CAAO,CAC3C,CAAC,GAKmBC,aACtBZ,UAAWjN,EAAS8N,WACpBjB,aAAc7M,EAAS0N,eDGvB3mB,KAAKmmB,0BACHJ,EACAD,EACA5E,OAAOgF,CAAS,CAAC,CAEpB,CAEOC,0BACNJ,EACAD,EACAkB,GAEAhnB,KAAK8lB,aAAeA,GAAgB,KACpC9lB,KAAK+lB,YAAcA,GAAe,KAClC/lB,KAAKijB,eAAiB5W,KAAKD,IAAG,EAAoB,IAAf4a,CACpC,CAEDC,gBAAgBzQ,EAAiBG,GAC/B,GAAM,CAAEmP,aAAAA,EAAcC,YAAAA,EAAa9C,eAAAA,CAAc,EAAKtM,EAEhDuQ,EAAU,IAAIrB,GAuBpB,OAtBIC,IACF9O,EAAgC,UAAxB,OAAO8O,EAAyD,iBAAA,CACtEtP,QAAAA,CACD,CAAA,EACD0Q,EAAQpB,aAAeA,GAErBC,IACF/O,EAA+B,UAAvB,OAAO+O,EAAwD,iBAAA,CACrEvP,QAAAA,CACD,CAAA,EACD0Q,EAAQnB,YAAcA,GAEpB9C,IACFjM,EAC4B,UAA1B,OAAOiM,EAEP,iBAAA,CACEzM,QAAAA,CACD,CAAA,EAEH0Q,EAAQjE,eAAiBA,GAEpBiE,CACR,CAEDrD,SACE,MAAO,CACLiC,aAAc9lB,KAAK8lB,aACnBC,YAAa/lB,KAAK+lB,YAClB9C,eAAgBjjB,KAAKijB,eAExB,CAEDkE,QAAQnE,GACNhjB,KAAK+lB,YAAc/C,EAAgB+C,YACnC/lB,KAAK8lB,aAAe9C,EAAgB8C,aACpC9lB,KAAKijB,eAAiBD,EAAgBC,cACvC,CAEDmE,SACE,OAAOxiB,OAAO6gB,OAAO,IAAII,GAAmB7lB,KAAK6jB,OAAM,CAAE,CAC1D,CAEDwD,kBACE,OAAOnQ,EAAU,iBAAiB,CACnC,CACF,CEhID,SAASoQ,EACPrQ,EACAT,GAEAQ,EACuB,UAArB,OAAOC,GAA+C,KAAA,IAAdA,EAExC,iBAAA,CAAET,QAAAA,CAAO,CAAE,CAEf,OAEa+Q,EAwBXxkB,YAAY,CAAEoiB,IAAAA,EAAK7O,KAAAA,EAAM0M,gBAAAA,KAAoBwE,CAAG,GAtBvCxnB,KAAA6kB,WAAiC,WAoBzB7kB,KAAAynB,iBAAmB,IAAInF,GAAiBtiB,IAAI,EA6CrDA,KAAc0nB,eAAuB,KACrC1nB,KAAc2nB,eAA+B,KA3CnD3nB,KAAKmlB,IAAMA,EACXnlB,KAAKsW,KAAOA,EACZtW,KAAKgjB,gBAAkBA,EACvBhjB,KAAK+lB,YAAc/C,EAAgB+C,YACnC/lB,KAAKqlB,YAAcmC,EAAInC,aAAe,KACtCrlB,KAAK0f,MAAQ8H,EAAI9H,OAAS,KAC1B1f,KAAKwlB,cAAgBgC,EAAIhC,eAAiB,CAAA,EAC1CxlB,KAAK2f,YAAc6H,EAAI7H,aAAe,KACtC3f,KAAKslB,SAAWkC,EAAIlC,UAAY,KAChCtlB,KAAKglB,YAAcwC,EAAIxC,aAAe,CAAA,EACtChlB,KAAKwc,SAAWgL,EAAIhL,UAAY,KAChCxc,KAAKwkB,aAAegD,EAAIhD,aAAe,CAAC,GAAGgD,EAAIhD,cAAgB,GAC/DxkB,KAAK4jB,SAAW,IAAIP,GAClBmE,EAAIlE,WAAale,KAAAA,EACjBoiB,EAAIjE,aAAene,KAAAA,CAAS,CAE/B,CAEDge,iBAAiBkD,GACf,IAAMP,EAAc9I,MAAM+E,EACxBhiB,KACAA,KAAKgjB,gBAAgBqD,SAASrmB,KAAKsW,KAAMgQ,CAAY,CAAC,EAUxD,OARAtP,EAAQ+O,EAAa/lB,KAAKsW,uBAEtBtW,KAAK+lB,cAAgBA,IACvB/lB,KAAK+lB,YAAcA,EACnB9I,MAAMjd,KAAKsW,KAAKsR,sBAAsB5nB,IAAI,EAC1CA,KAAKsW,KAAKuR,0BAA0B7nB,IAAI,GAGnC+lB,CACR,CAED+B,iBAAiBxB,GACf,OPhEG7J,MACLwF,EACAqE,EAAe,CAAA,KAEf,IAAMyB,EAAepd,EAAmBsX,CAAI,EACtC1Z,EAAQ0U,MAAM8K,EAAa3E,WAAWkD,CAAY,EAClD0B,EAASxG,GAAYjZ,CAAK,EAU1B0f,GARNjR,EACEgR,GAAUA,EAAOlG,KAAOkG,EAAOE,WAAaF,EAAOjG,IACnDgG,EAAazR,wBAM4B6R,EAFd,UAA3B,OAAOH,EAAOG,SAAwBH,EAAOG,SAAW/iB,KAAAA,IAEc,kBAExE,MAAO,CACL4iB,OAAAA,EACAzf,MAAAA,EACA6f,SAAUrH,GACRO,GAA4B0G,EAAOE,SAAS,CAAC,EAE/CG,aAActH,GACZO,GAA4B0G,EAAOjG,GAAG,CAAC,EAEzCkB,eAAgBlC,GACdO,GAA4B0G,EAAOlG,GAAG,CAAC,EAEzCmG,eAAgBA,GAAkB,KAClCK,mBAAoBH,GAAkC,uBAAK,KAE/D,GO+B4BnoB,KAAMsmB,CAAY,CAC3C,CAEDiC,SACE,OHvCG9L,MAAsBwF,IAC3B,IAAM8F,EAA6Bpd,EAAmBsX,CAAI,EAC1DhF,MAAM6G,GAAqBiE,CAAY,EAKvC9K,MAAM8K,EAAazR,KAAKsR,sBAAsBG,CAAY,EAC1DA,EAAazR,KAAKuR,0BAA0BE,CAAY,CAC1D,GG8BkB/nB,IAAI,CACnB,CAKDmnB,QAAQlF,GACFjiB,OAASiiB,IAGbjL,EAAQhX,KAAKmlB,MAAQlD,EAAKkD,IAAKnlB,KAAKsW,uBACpCtW,KAAKqlB,YAAcpD,EAAKoD,YACxBrlB,KAAKslB,SAAWrD,EAAKqD,SACrBtlB,KAAK0f,MAAQuC,EAAKvC,MAClB1f,KAAKwlB,cAAgBvD,EAAKuD,cAC1BxlB,KAAK2f,YAAcsC,EAAKtC,YACxB3f,KAAKglB,YAAc/C,EAAK+C,YACxBhlB,KAAKwc,SAAWyF,EAAKzF,SACrBxc,KAAKwkB,aAAevC,EAAKuC,aAAamB,IAAI6C,KAAe,GAAGA,CAAU,EAAC,EACvExoB,KAAK4jB,SAASD,MAAM1B,EAAK2B,QAAQ,EACjC5jB,KAAKgjB,gBAAgBmE,QAAQlF,EAAKe,eAAe,EAClD,CAEDoE,OAAO9Q,GACL,IAAMmS,EAAU,IAAIlB,EAAS,CAC3B,GAAGvnB,KACHsW,KAAAA,EACA0M,gBAAiBhjB,KAAKgjB,gBAAgBoE,OAAQ,CAC/C,CAAA,EAED,OADAqB,EAAQ7E,SAASD,MAAM3jB,KAAK4jB,QAAQ,EAC7B6E,CACR,CAEDC,UAAUtb,GAER4J,EAAQ,CAAChX,KAAK2nB,eAAgB3nB,KAAKsW,KAAI,kBACvCtW,KAAK2nB,eAAiBva,EAClBpN,KAAK0nB,iBACP1nB,KAAKqkB,sBAAsBrkB,KAAK0nB,cAAc,EAC9C1nB,KAAK0nB,eAAiB,KAEzB,CAEDrD,sBAAsBmE,GAChBxoB,KAAK2nB,eACP3nB,KAAK2nB,eAAea,CAAQ,EAG5BxoB,KAAK0nB,eAAiBc,CAEzB,CAEDG,yBACE3oB,KAAKynB,iBAAiB/E,QACvB,CAEDkG,wBACE5oB,KAAKynB,iBAAiB7E,OACvB,CAEDiG,+BACE5P,EACAsP,EAAS,CAAA,GAET1nB,IAAIioB,EAAkB,CAAA,EAEpB7P,EAASgL,SACThL,EAASgL,UAAYjkB,KAAKgjB,gBAAgB+C,cAE1C/lB,KAAKgjB,gBAAgBiD,yBAAyBhN,CAAQ,EACtD6P,EAAkB,CAAA,GAGhBP,GACFtL,MAAM6G,GAAqB9jB,IAAI,EAGjCid,MAAMjd,KAAKsW,KAAKsR,sBAAsB5nB,IAAI,EACtC8oB,GACF9oB,KAAKsW,KAAKuR,0BAA0B7nB,IAAI,CAE3C,CAED+oB,eACE,IAKM9E,EALN,OAAI+E,wBAAqBhpB,KAAKsW,KAAK2S,GAAG,EAC7B5f,QAAQkW,OACb9I,EAAgDzW,KAAKsW,IAAI,CAAC,GAGxD2N,EAAUhH,MAAMjd,KAAKojB,aAC3BnG,MAAM+E,EAAqBhiB,MT3LxByc,MACLnG,EACAiG,IAEOG,EACLpG,EAGA,OAAA,sBAAAiG,CAAO,GSmLwCvc,KAAKsW,KAAM,CAAE2N,QAAAA,CAAS,CAAA,CAAC,EACtEjkB,KAAKgjB,gBAAgBwD,oBAKdxmB,KAAKsW,KAAK+L,UAClB,CAEDwB,SACE,MAAO,CACLsB,IAAKnlB,KAAKmlB,IACVzF,MAAO1f,KAAK0f,OAASta,KAAAA,EACrBogB,cAAexlB,KAAKwlB,cACpBH,YAAarlB,KAAKqlB,aAAejgB,KAAAA,EACjC4f,YAAahlB,KAAKglB,YAClBM,SAAUtlB,KAAKslB,UAAYlgB,KAAAA,EAC3Bua,YAAa3f,KAAK2f,aAAeva,KAAAA,EACjCoX,SAAUxc,KAAKwc,UAAYpX,KAAAA,EAC3Bof,aAAcxkB,KAAKwkB,aAAamB,IAAI6C,KAAe,GAAGA,CAAU,EAAC,EACjExF,gBAAiBhjB,KAAKgjB,gBAAgBa,OAAQ,EAG9CqF,iBAAkBlpB,KAAKkpB,iBACvB,GAAGlpB,KAAK4jB,SAASC,OAAQ,EAGzB7G,OAAQhd,KAAKsW,KAAK+B,OAAO2E,OACzBxG,QAASxW,KAAKsW,KAAKtT,KAItB,CAED8iB,mBACE,OAAO9lB,KAAKgjB,gBAAgB8C,cAAgB,EAC7C,CAEDqD,iBAAiB7S,EAAoBK,GACnC,IAAM0O,EAAc1O,EAAO0O,aAAejgB,KAAAA,EACpCsa,EAAQ/I,EAAO+I,OAASta,KAAAA,EACxBua,EAAchJ,EAAOgJ,aAAeva,KAAAA,EACpCkgB,EAAW3O,EAAO2O,UAAYlgB,KAAAA,EAC9BoX,EAAW7F,EAAO6F,UAAYpX,KAAAA,EAC9B8jB,EAAmBvS,EAAOuS,kBAAoB9jB,KAAAA,EAC9Cke,EAAY3M,EAAO2M,WAAale,KAAAA,EAChCme,EAAc5M,EAAO4M,aAAene,KAAAA,EACpC,CACJ+f,IAAAA,EACAK,cAAAA,EACAR,YAAAA,EACAR,aAAAA,EACAxB,gBAAiBoG,CAClB,EAAGzS,EAIEqM,GAFNhM,EAAQmO,GAAOiE,EAAyB9S,oBAEhBuP,GAAgBoB,SACtCjnB,KAAKgD,KACLomB,CAAwC,GAsBpCnH,GAnBNjL,EAAuB,UAAf,OAAOmO,EAAkB7O,oBACjCgR,EAAwBjC,EAAa/O,EAAKtT,IAAI,EAC9CskB,EAAwB5H,EAAOpJ,EAAKtT,IAAI,EACxCgU,EAC2B,WAAzB,OAAOwO,EACPlP,oBAGFU,EACyB,WAAvB,OAAOgO,EACP1O,oBAGFgR,EAAwB3H,EAAarJ,EAAKtT,IAAI,EAC9CskB,EAAwBhC,EAAUhP,EAAKtT,IAAI,EAC3CskB,EAAwB9K,EAAUlG,EAAKtT,IAAI,EAC3CskB,EAAwB4B,EAAkB5S,EAAKtT,IAAI,EACnDskB,EAAwBhE,EAAWhN,EAAKtT,IAAI,EAC5CskB,EAAwB/D,EAAajN,EAAKtT,IAAI,EACjC,IAAIukB,EAAS,CACxBpC,IAAAA,EACA7O,KAAAA,EACAoJ,MAAAA,EACA8F,cAAAA,EACAH,YAAAA,EACAL,YAAAA,EACAM,SAAAA,EACA3F,YAAAA,EACAnD,SAAAA,EACAwG,gBAAAA,EACAM,UAAAA,EACAC,YAAAA,CACD,CAAA,GAUD,OARIiB,GAAgBjkB,MAAMC,QAAQgkB,CAAY,IAC5CvC,EAAKuC,aAAeA,EAAamB,IAAI6C,IAAQ,CAAO,GAAGA,CAAU,EAAC,GAGhEU,IACFjH,EAAKiH,iBAAmBA,GAGnBjH,CACR,CAODoH,kCACE/S,EACAgT,EACAtE,EAAuB,CAAA,GAEvB,IAAMhC,EAAkB,IAAI6C,GAItB5D,GAHNe,EAAgBiD,yBAAyBqD,CAAe,EAG3C,IAAI/B,EAAS,CACxBpC,IAAKmE,EAAgBlE,QACrB9O,KAAAA,EACA0M,gBAAAA,EACAgC,YAAAA,CACD,CAAA,GAID,OADA/H,MAAM6G,GAAqB7B,CAAI,EACxBA,CACR,CAODsH,yCACEjT,EACA2C,EACAgL,GAEA,IAAMC,EAAcjL,EAASkL,MAAM,GAG7BK,GAFNxN,EAAgC5R,KAAAA,IAAxB8e,EAAYkB,0BAGehgB,KAAAA,IAAjC8e,EAAYI,iBACRC,GAAoBL,EAAYI,gBAAgB,EAChD,IAEAU,EACJ,EAAEd,EAAYxE,OAASwE,EAAYa,cAAkBP,GAAczjB,QAE/DiiB,EAAkB,IAAI6C,GAItB5D,GAHNe,EAAgBoD,kBAAkBnC,CAAO,EAG5B,IAAIsD,EAAS,CACxBpC,IAAKjB,EAAYkB,QACjB9O,KAAAA,EACA0M,gBAAAA,EACAgC,YAAAA,CACD,CAAA,GAGKE,EAAiC,CACrCC,IAAKjB,EAAYkB,QACjBC,YAAanB,EAAYmB,aAAe,KACxCC,SAAUpB,EAAYqB,UAAY,KAClC7F,MAAOwE,EAAYxE,OAAS,KAC5B8F,cAAetB,EAAYsB,eAAiB,CAAA,EAC5C7F,YAAauE,EAAYvE,aAAe,KACxCnD,SAAU0H,EAAY1H,UAAY,KAClCgI,aAAAA,EACAZ,SAAU,IAAIP,GACZa,EAAYZ,UACZY,EAAYX,WAAW,EAEzByB,YACE,EAAEd,EAAYxE,OAASwE,EAAYa,cAClCP,GAAczjB,SAInB,OADA6D,OAAO6gB,OAAOxD,EAAMiD,CAAO,EACpBjD,CACR,CACF,CCjXD,IAAMuH,GAAuC,IAAIC,IAE3C,SAAUC,EAAgBC,GAC9BvS,EAAYuS,aAAeC,SAAU,6BAA6B,EAClE/oB,IAAImL,EAAWwd,GAAcxR,IAAI2R,CAAG,EAYpC,OAVI3d,EACFoL,EACEpL,aAAoB2d,EACpB,gDAAgD,GAKpD3d,EAAW,IAAK2d,EAChBH,GAAcK,IAAIF,EAAK3d,CAAQ,GACxBA,CACT,OCrBa8d,GAAb/mB,cAEW/C,KAAAyM,KAA4B,OACrCzM,KAAO+pB,QAAqC,EA4B7C,CA1BCC,qBACE,MAAO,CAAA,CACR,CAEDC,WAAWnjB,EAAaC,GACtB/G,KAAK+pB,QAAQjjB,GAAOC,CACrB,CAEDmjB,WAAuCpjB,GACrC,IAAMC,EAAQ/G,KAAK+pB,QAAQjjB,GAC3B,OAAiB1B,KAAAA,IAAV2B,EAAsB,KAAQA,CACtC,CAEDojB,cAAcrjB,GACZ,OAAO9G,KAAK+pB,QAAQjjB,EACrB,CAEDsjB,aAAaC,EAAcC,IAK3BC,gBAAgBF,EAAcC,KA1BvBR,GAAIrd,KAAW,OAqCjB,IAAM+d,GAAmCV,GC7BhC,SAAAW,EACd3jB,EACAkW,EACAxG,GAEA,kBAAmC1P,KAAOkW,KAAUxG,CACtD,OAEakU,GAKX3nB,YACS4nB,EACUrU,EACAsU,GAFV5qB,KAAW2qB,YAAXA,EACU3qB,KAAIsW,KAAJA,EACAtW,KAAO4qB,QAAPA,EAEjB,GAAM,CAAEvS,OAAAA,EAAQrV,KAAAA,GAAShD,KAAKsW,KAC9BtW,KAAK6qB,YAAcJ,EAAoBzqB,KAAK4qB,QAASvS,EAAO2E,OAAQha,CAAI,EACxEhD,KAAK8qB,mBAAqBL,EAAmB,cAE3CpS,EAAO2E,OACPha,CAAI,EAENhD,KAAK+qB,kBAAoBzU,EAAK0U,gBAAgB1gB,KAAKgM,CAAI,EACvDtW,KAAK2qB,YAAYP,aAAapqB,KAAK6qB,YAAa7qB,KAAK+qB,iBAAiB,CACvE,CAEDE,eAAehJ,GACb,OAAOjiB,KAAK2qB,YAAYV,KAAKjqB,KAAK6qB,YAAa5I,EAAK4B,OAAM,CAAE,CAC7D,CAEDqH,uBACE,IAOQjS,EAPFkS,EAAOlO,MAAMjd,KAAK2qB,YAAYT,KAClClqB,KAAK6qB,WAAW,EAElB,OAAKM,EAGe,UAAhB,OAAOA,GACHlS,EAAWgE,MAAM6D,GAAe9gB,KAAKsW,KAAM,CAAE2N,QAASkH,EAAM,EAAE1hB,MAClE,MAAe,GAKV8d,EAASgC,4BAA4BvpB,KAAKsW,KAAM2C,EAAUkS,CAAI,EAF5D,KAIJ5D,EAAS4B,UAAUnpB,KAAKsW,KAAM6U,CAAI,EAXhC,IAYV,CAEDC,oBACE,OAAOprB,KAAK2qB,YAAYR,QAAQnqB,KAAK6qB,WAAW,CACjD,CAEDQ,6BACE,OAAOrrB,KAAK2qB,YAAYV,KACtBjqB,KAAK8qB,mBACL9qB,KAAK2qB,YAAYle,IAAI,CAExB,CAED6e,qBAAqBC,GACnB,IAIMnJ,EAJN,GAAIpiB,KAAK2qB,cAAgBY,EASzB,OALMnJ,EAAcnF,MAAMjd,KAAKkrB,iBAC/BjO,MAAMjd,KAAKorB,oBAEXprB,KAAK2qB,YAAcY,EAEfnJ,EACKpiB,KAAKirB,eAAe7I,CAAW,EADxC,KAAA,CAGD,CAED2G,SACE/oB,KAAK2qB,YAAYJ,gBAAgBvqB,KAAK6qB,YAAa7qB,KAAK+qB,iBAAiB,CAC1E,CAED3kB,oBACEkQ,EACAkV,EACAZ,EAA2B,YAE3B,GAAI,CAACY,EAAqBzqB,OACxB,OAAO,IAAI2pB,GACThB,EAAac,EAAmB,EAChClU,EACAsU,CAAO,EAKX,IAwBWD,EAxBLc,GAAwB,MACtBpiB,QAAQqiB,IACZF,EAAqB7F,IAAIlJ,MAAMkO,IAC7B,GAAI1N,MAAM0N,EAAYX,eACpB,OAAOW,CAGV,CAAA,CAAC,GAEJlG,OAAOkG,GAAeA,CAAW,EAGnC9pB,IAAI8qB,EACFF,EAAsB,IACtB/B,EAAkCc,EAAmB,EAEjD1jB,EAAM2jB,EAAoBG,EAAStU,EAAK+B,OAAO2E,OAAQ1G,EAAKtT,IAAI,EAIlE4oB,EAAqC,KAIzC,IAAWjB,KAAea,EACxB,IACE,IAAML,EAAOlO,MAAM0N,EAAYT,KAA6BpjB,CAAG,EAC/D,GAAIqkB,EAAM,CACRtqB,IAAIohB,EACJ,GAAoB,UAAhB,OAAOkJ,EAAmB,CAC5B,IAAMlS,EAAWgE,MAAM6D,GAAexK,EAAM,CAC1C2N,QAASkH,CACV,CAAA,EAAE1hB,MAAM,MAAe,EACxB,GAAI,CAACwP,EACH,MAEFgJ,EAAOhF,MAAMsK,EAASgC,4BACpBjT,EACA2C,EACAkS,CAAI,CAEP,MACClJ,EAAOsF,EAAS4B,UAAU7S,EAAM6U,CAAI,EAElCR,IAAgBgB,IAClBC,EAAgB3J,GAElB0J,EAAsBhB,EACtB,KACD,CACO,CAAR,OAKEkB,EAAqBJ,EAAsBhH,OAC/C5iB,GAAKA,EAAEiqB,qBAAqB,EA6B9B,OAxBGH,EAAoBG,uBACpBD,EAAmB9qB,SAKtB4qB,EAAsBE,EAAmB,GACrCD,GAGF3O,MAAM0O,EAAoB1B,KAAKnjB,EAAK8kB,EAAc/H,OAAQ,CAAA,EAK5D5G,MAAM5T,QAAQqiB,IACZF,EAAqB7F,IAAIlJ,MAAMkO,IAC7B,GAAIA,IAAgBgB,EAClB,IACE1O,MAAM0N,EAAYR,QAAQrjB,CAAG,CACrB,CAAR,OAEL,CAAA,CAAC,GAEG,IAAI4jB,GAAuBiB,EAAqBrV,EAAMsU,CAAO,CACrE,CACF,CC1KK,SAAUmB,GAAgB1O,GAC9B,IAAM7X,EAAK6X,EAAUqB,cACrB,OAAIlZ,EAAGgC,SAAS,QAAQ,GAAKhC,EAAGgC,SAAS,MAAM,GAAKhC,EAAGgC,SAAS,QAAQ,EAC7C,QAChBwkB,GAAYxmB,CAAE,EAEK,WACnBA,EAAGgC,SAAS,MAAM,GAAKhC,EAAGgC,SAAS,UAAU,EAChC,KACbhC,EAAGgC,SAAS,OAAO,EACJ,OACfykB,GAAWzmB,CAAE,EACK,UAClBA,EAAGgC,SAAS,OAAO,EACJ,OACf0kB,GAAc1mB,CAAE,EAEK,aACrB2mB,GAAS3mB,CAAE,EAEK,QAChB4mB,GAAU5mB,CAAE,EACK,SAEzBA,CAAAA,EAAGgC,SAAS,SAAS,GAAK6kB,CAAAA,GAAa7mB,CAAE,GACzCA,EAAGgC,SAAS,OAAO,EAGX8kB,GAAW9mB,CAAE,EAEK,UAKH,KADlB+mB,EAAUlP,EAAUnZ,MADf,iCACuB,IACrBnD,OACJwrB,EAAQ,GAGM,QAZG,QAa9B,CAEgB,SAAAN,GAAWzmB,EAAKhB,KAC9B,MAAO,aAAauT,KAAKvS,CAAE,CAC7B,CAEgB,SAAA4mB,GAAU/O,EAAY7Y,KACpC,IAAMgB,EAAK6X,EAAUqB,cACrB,OACElZ,EAAGgC,SAAS,SAAS,GACrB,CAAChC,EAAGgC,SAAS,SAAS,GACtB,CAAChC,EAAGgC,SAAS,QAAQ,GACrB,CAAChC,EAAGgC,SAAS,SAAS,CAE1B,CAEgB,SAAA6kB,GAAa7mB,EAAKhB,KAChC,MAAO,WAAWuT,KAAKvS,CAAE,CAC3B,CAEgB,SAAAwmB,GAAYxmB,EAAKhB,KAC/B,MAAO,YAAYuT,KAAKvS,CAAE,CAC5B,CAEgB,SAAA8mB,GAAW9mB,EAAKhB,KAC9B,MAAO,WAAWuT,KAAKvS,CAAE,CAC3B,CAEgB,SAAA0mB,GAAc1mB,EAAKhB,KACjC,MAAO,cAAcuT,KAAKvS,CAAE,CAC9B,CAEgB,SAAA2mB,GAAS3mB,EAAKhB,KAC5B,MAAO,SAASuT,KAAKvS,CAAE,CACzB,CAEgB,SAAAgnB,GAAOhnB,EAAKhB,KAC1B,MACE,oBAAoBuT,KAAKvS,CAAE,GAC1B,aAAauS,KAAKvS,CAAE,GAAK,UAAUuS,KAAKvS,CAAE,CAE/C,CAiBgB,SAAAinB,GAAiBjnB,EAAahB,KAE5C,OACEgoB,GAAOhnB,CAAE,GACT8mB,GAAW9mB,CAAE,GACb2mB,GAAS3mB,CAAE,GACX0mB,GAAc1mB,CAAE,GAChB,iBAAiBuS,KAAKvS,CAAE,GACxBwmB,GAAYxmB,CAAE,CAElB,CCpHgB,SAAAknB,GACdC,EACAC,EAAgC,IAEhC/rB,IAAIgsB,EACJ,OAAQF,GACN,IAAA,UAEEE,EAAmBd,GAAgBvnB,EAAK,CAAE,EAC1C,MACF,IAAA,SAIEqoB,EAAsBd,GAAgBvnB,EAAO,CAAA,EAA1B,IAA+BmoB,EAClD,MACF,QACEE,EAAmBF,CACtB,CACD,IAAMG,EAAqBF,EAAW7rB,OAClC6rB,EAAWprB,KAAK,GAAG,EACnB,mBACJ,SAAUqrB,YAAiD9W,kBAAe+W,CAC5E,OCrCaC,GAGXhqB,YAA6BuT,GAAAtW,KAAIsW,KAAJA,EAFZtW,KAAKgtB,MAAsB,EAEO,CAEnDC,aACE7f,EACA8f,GAIA,IAAMC,EAAmC,GAGvC,IAAI9jB,QAAQ,CAACC,EAASiW,KACpB,IAIEjW,EAHe8D,EAAS6U,CAAI,CAGd,CAIf,CAHC,MAAO/e,GAEPqc,EAAOrc,CAAC,CACT,CACH,CAAC,EAEHiqB,EAAgBD,QAAUA,EAC1BltB,KAAKgtB,MAAMzrB,KAAK4rB,CAAe,EAE/B,IAAMC,EAAQptB,KAAKgtB,MAAMjsB,OAAS,EAClC,MAAO,KAGLf,KAAKgtB,MAAMI,GAAS,IAAM/jB,QAAQC,QAAO,CAC3C,CACD,CAED+jB,oBAAoBC,GAClB,GAAIttB,KAAKsW,KAAK8L,cAAgBkL,EAA9B,CAOA,IAAMC,EAAkC,GACxC,IACE,IAAK,IAAMC,KAAuBxtB,KAAKgtB,MACrC/P,MAAMuQ,EAAoBF,CAAQ,EAG9BE,EAAoBN,SACtBK,EAAahsB,KAAKisB,EAAoBN,OAAO,CAkBlD,CAfC,MAAOhqB,GAGPqqB,EAAaE,QAAO,EACpB,IAAK,IAAMP,KAAWK,EACpB,IACEL,GAGD,CAFC,MAAOrmB,IAKX,MAAM7G,KAAKsW,KAAKS,cAAc3Q,OAAoC,gBAAA,CAChEsnB,gBAAkBxqB,GAAa4C,OAChC,CAAA,CACF,CA9BA,CA+BF,CACF,OCjEY6nB,GAOX5qB,YAAYkW,GAEV,IAAM2U,EAAkB3U,EAAS4U,sBACjC7tB,KAAK6tB,sBAAwB,GAE7B7tB,KAAK6tB,sBAAsBC,kBACzBF,EAAgBE,mBApBc,EAqB5BF,EAAgBG,oBAClB/tB,KAAK6tB,sBAAsBE,kBACzBH,EAAgBG,mBAE+B3oB,KAAAA,IAA/CwoB,EAAgBI,6BAClBhuB,KAAK6tB,sBAAsBI,wBACzBL,EAAgBI,4BAE+B5oB,KAAAA,IAA/CwoB,EAAgBM,6BAClBluB,KAAK6tB,sBAAsBM,wBACzBP,EAAgBM,4BAE6B9oB,KAAAA,IAA7CwoB,EAAgBQ,2BAClBpuB,KAAK6tB,sBAAsBO,yBACzBR,EAAgBQ,0BAEqChpB,KAAAA,IAArDwoB,EAAgBS,mCAClBruB,KAAK6tB,sBAAsBQ,iCACzBT,EAAgBS,kCAGpBruB,KAAKygB,iBAAmBxH,EAASwH,iBACH,kCAA1BzgB,KAAKygB,mBACPzgB,KAAKygB,iBAAmB,OAI1BzgB,KAAKsuB,iCACHrV,EAASqV,kCAAkC9sB,KAAK,EAAE,GAAK,GAEzDxB,KAAKuuB,qBAAuBtV,EAASsV,sBAAwB,CAAA,EAC7DvuB,KAAKwuB,cAAgBvV,EAASuV,aAC/B,CAEDC,iBAAiBC,GACf,IAAMC,EAA2C,CAC/CC,QAAS,CAAA,EACTC,eAAgB7uB,MAelB,OAXAA,KAAK8uB,8BAA8BJ,EAAUC,CAAM,EACnD3uB,KAAK+uB,iCAAiCL,EAAUC,CAAM,EAGtDA,EAAOC,UAAPD,EAAOC,QAAYD,EAAOK,wBAA0B,CAAA,GACpDL,EAAOC,UAAPD,EAAOC,QAAYD,EAAOM,wBAA0B,CAAA,GACpDN,EAAOC,UAAPD,EAAOC,QAAYD,EAAOV,yBAA2B,CAAA,GACrDU,EAAOC,UAAPD,EAAOC,QAAYD,EAAOR,yBAA2B,CAAA,GACrDQ,EAAOC,UAAPD,EAAOC,QAAYD,EAAOP,0BAA4B,CAAA,GACtDO,EAAOC,UAAPD,EAAOC,QAAYD,EAAON,kCAAoC,CAAA,GAEvDM,CACR,CAQOG,8BACNJ,EACAC,GAEA,IAAMb,EAAoB9tB,KAAK6tB,sBAAsBC,kBAC/CC,EAAoB/tB,KAAK6tB,sBAAsBE,kBACjDD,IACFa,EAAOK,uBAAyBN,EAAS3tB,QAAU+sB,GAEjDC,IACFY,EAAOM,uBAAyBP,EAAS3tB,QAAUgtB,EAEtD,CAQOgB,iCACNL,EACAC,GAWA9tB,IAAIquB,EARJlvB,KAAKmvB,uCACHR,EACkC,CAAA,EACA,CAAA,EACF,CAAA,EACQ,CAAA,CAAK,EAI/C,IAAK9tB,IAAIC,EAAI,EAAGA,EAAI4tB,EAAS3tB,OAAQD,CAAC,GACpCouB,EAAeR,EAAS9rB,OAAO9B,CAAC,EAChCd,KAAKmvB,uCACHR,EACkD,KAAhBO,GAChCA,GAAgB,IACgC,KAAhBA,GAChCA,GAAgB,IAC8B,KAAhBA,GAC9BA,GAAgB,IACsBlvB,KAAKsuB,iCAAiC9mB,SAC5E0nB,CAAY,CACb,CAGN,CAaOC,uCACNR,EACAX,EACAE,EACAE,EACAC,GAEIruB,KAAK6tB,sBAAsBI,yBAC7BU,CAAAA,EAAOV,0BAAPU,EAAOV,wBAA4BD,GAEjChuB,KAAK6tB,sBAAsBM,yBAC7BQ,CAAAA,EAAOR,0BAAPQ,EAAOR,wBAA4BD,GAEjCluB,KAAK6tB,sBAAsBO,0BAC7BO,CAAAA,EAAOP,2BAAPO,EAAOP,yBAA6BA,GAElCpuB,KAAK6tB,sBAAsBQ,kCAC7BM,CAAAA,EAAON,mCAAPM,EAAON,iCACLA,EAEL,CACF,OC/FYe,GAyCXrsB,YACkBkmB,EACCoG,EACAC,EACDjX,GAHArY,KAAGipB,IAAHA,EACCjpB,KAAwBqvB,yBAAxBA,EACArvB,KAAuBsvB,wBAAvBA,EACDtvB,KAAMqY,OAANA,EA5ClBrY,KAAWoiB,YAAgB,KAC3BpiB,KAAcud,eAA0B,KAChCvd,KAAAuvB,WAAalmB,QAAQC,UAGrBtJ,KAAAwvB,sBAAwB,IAAIC,GAAmBzvB,IAAI,EACnDA,KAAA0vB,oBAAsB,IAAID,GAAmBzvB,IAAI,EACxCA,KAAA2vB,iBAAmB,IAAI5C,GAAoB/sB,IAAI,EACxDA,KAAY4vB,aAAwB,KACpC5vB,KAAyB6vB,0BAAG,CAAA,EACnB7vB,KAAuC8vB,wCAAW,EAInE9vB,KAAgB6d,iBAAG,CAAA,EACnB7d,KAAc+vB,eAAG,CAAA,EACjB/vB,KAAQgwB,SAAG,CAAA,EACXhwB,KAAsBiwB,uBAAyB,KAC/CjwB,KAAsBkwB,uBAAyC,KAC/DlwB,KAAa+W,cACX7B,GACFlV,KAAqBmwB,sBAA2B,KAChDnwB,KAAuBowB,wBAAoC,GAC3DpwB,KAAsBqwB,uBAAkC,KACxDrwB,KAAuBswB,wBAA2C,GAClEtwB,KAAmCuwB,oCAEnBnrB,KAAAA,EAORpF,KAAewwB,gBAA8BprB,KAAAA,EAErDpF,KAAYod,aAAkB,KAC9Bpd,KAAQwc,SAAkB,KAC1Bxc,KAAAywB,SAAyB,CAAEC,kCAAmC,CAAA,CAAK,EAqqB3D1wB,KAAU4sB,WAAa,GA7pB7B5sB,KAAKgD,KAAOimB,EAAIjmB,KAChBhD,KAAK2wB,cAAgBtY,EAAOuY,iBAG5B5wB,KAAKkf,6BAA+B,IAAI7V,QACtCC,GAAYtJ,KAAKuwB,oCAAsCjnB,CAAQ,CAElE,CAEDunB,2BACErF,EACAsF,GA6CA,OA3CIA,IACF9wB,KAAKkwB,uBAAyBxG,EAAaoH,CAAqB,GAKlE9wB,KAAKiwB,uBAAyBjwB,KAAKgtB,MAAMvQ,UACvC,GAAIzc,CAAAA,KAAKgwB,WAIThwB,KAAK+wB,mBAAqB9T,MAAMyN,GAAuBtkB,OACrDpG,KACAwrB,CAAoB,EAEtBxrB,KAAKuwB,sCAAmC,EAEpCvwB,CAAAA,KAAKgwB,UAAT,CAMA,GAAIhwB,KAAKkwB,wBAAwBc,uBAE/B,IACE/T,MAAMjd,KAAKkwB,uBAAuBe,YAAYjxB,IAAI,CAGnD,CAFC,MAAOkD,IAKX+Z,MAAMjd,KAAKkxB,sBAAsBJ,CAAqB,EAEtD9wB,KAAKwwB,gBAAkBxwB,KAAKoiB,aAAa+C,KAAO,KAE5CnlB,KAAKgwB,WAIThwB,KAAK+vB,eAAiB,CAAA,EArBrB,CAsBH,CAAC,EAEM/vB,KAAKiwB,sBACb,CAKDjF,wBACE,IAIM/I,EAJFjiB,CAAAA,KAAKgwB,WAIH/N,EAAOhF,MAAMjd,KAAKmxB,oBAAoBjG,eAAc,EAErDlrB,KAAKoiB,aAAgBH,KAMtBjiB,KAAKoiB,aAAeH,GAAQjiB,KAAKoiB,YAAY+C,MAAQlD,EAAKkD,KAE5DnlB,KAAKoxB,aAAajK,QAAQlF,CAAI,EAG9BhF,MAAMjd,KAAKoiB,YAAYgB,cAMzBnG,MAAMjd,KAAKqxB,mBAAmBpP,EAAqC,CAAA,CAAI,EACxE,CAEOqP,uCACNrN,GAEA,IACE,IAAMhL,EAAWgE,MAAM6D,GAAe9gB,KAAM,CAAEikB,QAAAA,CAAS,CAAA,EACjDhC,EAAOhF,MAAMsK,EAASgC,4BAC1BvpB,KACAiZ,EACAgL,CAAO,EAEThH,MAAMjd,KAAKuxB,uBAAuBtP,CAAI,CAOvC,CANC,MAAOvX,GACPvH,QAAQqI,KACN,qEACAd,CAAG,EAELuS,MAAMjd,KAAKuxB,uBAAuB,IAAI,CACvC,CACF,CAEOL,4BACNJ,GAEA,GAAI9H,GAAoBA,qBAAChpB,KAAKipB,GAAG,EAAG,CAClC,IAAMhF,EAAUjkB,KAAKipB,IAAIwH,SAASe,YAClC,OAAIvN,EAGK,IAAI5a,QAAcC,IACvBkW,WAAW,IACTxf,KAAKsxB,iCAAiCrN,CAAO,EAAEza,KAC7CF,EACAA,CAAO,CACR,CAEL,CAAC,EAEMtJ,KAAKuxB,uBAAuB,IAAI,CAE1C,CAGD,IAMQE,EACAC,EACAC,EARFC,EAAoB,MACjB5xB,KAAKmxB,oBAAoBjG,eAAgB,EAClDrqB,IAAIgxB,EAAoBD,EACpBE,EAAyB,CAAA,EAqB7B,GApBIhB,GAAyB9wB,KAAKqY,OAAO0Z,aACvC9U,MAAMjd,KAAKgyB,sCACLP,EAAsBzxB,KAAK4vB,cAAc1G,iBACzCwI,EAAoBG,GAAmB3I,iBACvCyI,EAAS1U,MAAMjd,KAAKiyB,kBAAkBnB,CAAqB,EAO7DW,GAAuBA,IAAwBC,GACjDC,CAAAA,GAAQ1P,OAER4P,EAAoBF,EAAO1P,KAC3B6P,EAAyB,CAAA,IAKzB,CAACD,EACH,OAAO7xB,KAAKuxB,uBAAuB,IAAI,EAGzC,GAAKM,EAAkB3I,iBA6BvB,OANAlS,EAAQhX,KAAKkwB,uBAAwBlwB,uBACrCid,MAAMjd,KAAKgyB,sCAMThyB,KAAK4vB,cACL5vB,KAAK4vB,aAAa1G,mBAAqB2I,EAAkB3I,iBAElDlpB,KAAKuxB,uBAAuBM,CAAiB,EAG/C7xB,KAAKkyB,+BAA+BL,CAAiB,EAjC1D,GAAIC,EACF,IACE7U,MAAMjd,KAAK2vB,iBAAiBtC,cAAcwE,CAAiB,CAQ5D,CAPC,MAAO3uB,GACP2uB,EAAoBD,EAGpB5xB,KAAKkwB,uBAAwBiC,wBAAwBnyB,KAAM,IACzDqJ,QAAQkW,OAAOrc,CAAC,CAAC,CAEpB,CAGH,OAAI2uB,EACK7xB,KAAKkyB,+BAA+BL,CAAiB,EAErD7xB,KAAKuxB,uBAAuB,IAAI,CAkB5C,CAEOU,wBACNG,GAkBAvxB,IAAI8wB,EAAgC,KACpC,IAGEA,EAAS1U,MAAMjd,KAAKkwB,uBAAwBmC,oBAC1CryB,KACAoyB,EACA,CAAA,CAAI,CAMP,CAJC,MAAOlvB,GAGP+Z,MAAMjd,KAAKsyB,iBAAiB,IAAI,CACjC,CAED,OAAOX,CACR,CAEOO,qCACNjQ,GAEA,IACEhF,MAAM6G,GAAqB7B,CAAI,CAUhC,CATC,MAAO/e,GACP,GAEE,gCADCA,GAAqB2C,KAKtB,OAAO7F,KAAKuxB,uBAAuB,IAAI,CAE1C,CAED,OAAOvxB,KAAKuxB,uBAAuBtP,CAAI,CACxC,CAEDsQ,oBxBnWc,IAIRC,EwBgWJxyB,KAAKod,axBnWkB,aAArB,OAAO3Y,aAGL+tB,EAAuC/tB,WAGxBguB,WAAaD,EAAkBC,UAAU,IAG5DD,EAAkBE,WAElB,IwByVD,CAEDC,gBACE3yB,KAAKgwB,SAAW,CAAA,CACjB,CAED4C,wBAAwBC,GACtB,IAOM5Q,EAPN,OAAI+G,GAAoBA,qBAAChpB,KAAKipB,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDzW,IAAI,CAAC,IAKnDiiB,EAAO4Q,EACRloB,EAAmBkoB,CAAU,EAC9B,OAEF7b,EACEiL,EAAK3L,KAAK+B,OAAO2E,SAAWhd,KAAKqY,OAAO2E,OACxChd,2BAIGA,KAAKqxB,mBAAmBpP,GAAQA,EAAKmF,OAAOpnB,IAAI,CAAC,EACzD,CAEDqxB,yBACEpP,EACA6Q,EAAoC,CAAA,GAEpC,GAAI9yB,CAAAA,KAAKgwB,SAeT,OAZI/N,GACFjL,EACEhX,KAAKwc,WAAayF,EAAKzF,SACvBxc,KAAI,sBAKH8yB,GACH7V,MAAMjd,KAAK2vB,iBAAiBtC,cAAcpL,CAAI,EAGzCjiB,KAAKgtB,MAAMvQ,UAChBQ,MAAMjd,KAAKuxB,uBAAuBtP,CAA2B,EAC7DjiB,KAAK+yB,oBAAmB,CAC1B,CAAC,CACF,CAED1Q,gBACE,OAAI2G,GAAoBA,qBAAChpB,KAAKipB,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDzW,IAAI,CAAC,GAIzDid,MAAMjd,KAAK2vB,iBAAiBtC,cAAc,IAAI,GAE1CrtB,KAAKgzB,4BAA8BhzB,KAAKkwB,yBAC1CjT,MAAMjd,KAAKsyB,iBAAiB,IAAI,EAK3BtyB,KAAKqxB,mBAAmB,KAAqC,CAAA,CAAI,EACzE,CAED/F,eAAeX,GACb,OAAI3B,GAAoBA,qBAAChpB,KAAKipB,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDzW,IAAI,CAAC,EAGlDA,KAAKgtB,MAAMvQ,UAChBQ,MAAMjd,KAAKmxB,oBAAoB7F,eAAe5B,EAAaiB,CAAW,CAAC,CACzE,CAAC,CACF,CAEDsI,sBACE,OAAqB,MAAjBjzB,KAAKwc,SACAxc,KAAKmwB,sBAELnwB,KAAKowB,wBAAwBpwB,KAAKwc,SAE5C,CAEDiS,uBAAuBC,GAChB1uB,KAAKkzB,8BACRjW,MAAMjd,KAAKmzB,wBAIb,IAAMtE,EACJ7uB,KAAKkzB,6BAIP,OACErE,EAAeL,gBACfxuB,KAAK8vB,wCAEEzmB,QAAQkW,OACbvf,KAAK+W,cAAc3Q,OAAM,6CAEvB,EAAE,CACH,EAIEyoB,EAAeJ,iBAAiBC,CAAQ,CAChD,CAEDwE,6BACE,OAAsB,OAAlBlzB,KAAKwc,SACAxc,KAAKqwB,uBAELrwB,KAAKswB,wBAAwBtwB,KAAKwc,SAE5C,CAED2W,8BACE,ICjdF7c,EDidQ2C,EAAWgE,MC9cZP,EAHPpG,EDid4CtW,KCvc1C,MAAA,qBAAAsc,EAAmBhG,EATe,EASF,CAAC,EDyc3BuY,EAAyC,IAAIlB,GACjD1U,CAAQ,EAGY,OAAlBjZ,KAAKwc,SACPxc,KAAKqwB,uBAAyBxB,EAE9B7uB,KAAKswB,wBAAwBtwB,KAAKwc,UAAYqS,CAEjD,CAED1P,sBACE,OAAOnf,KAAKmxB,oBAAoBxG,YAAYle,IAC7C,CAED2S,kBACE,OAAOpf,KAAKmxB,oBAAoBxG,WACjC,CAEDyI,gBAAgB7c,GACdvW,KAAK+W,cAAgB,IAAI5Q,EACvB,OACA,WACCoQ,EAA8B,CAAE,CAEpC,CAED8c,mBACErpB,EACA5G,EACAkwB,GAEA,OAAOtzB,KAAKuzB,sBACVvzB,KAAKwvB,sBACLxlB,EACA5G,EACAkwB,CAAS,CAEZ,CAEDE,uBACEpmB,EACA8f,GAEA,OAAOltB,KAAK2vB,iBAAiB1C,aAAa7f,EAAU8f,CAAO,CAC5D,CAEDuG,iBACEzpB,EACA5G,EACAkwB,GAEA,OAAOtzB,KAAKuzB,sBACVvzB,KAAK0vB,oBACL1lB,EACA5G,EACAkwB,CAAS,CAEZ,CAEDI,iBACE,OAAO,IAAIrqB,QAAQ,CAACC,EAASiW,KAC3B,GAAIvf,KAAKoiB,YACP9Y,QACK,CACL,IAAMqqB,EAAc3zB,KAAKqzB,mBAAmB,KAC1CM,IACArqB,GACD,EAAEiW,CAAM,CACV,CACH,CAAC,CACF,CAKDqU,wBAAwBrrB,GACtB,IAGQgU,EAHJvc,KAAKoiB,cAGD7F,EAA8B,CAClCsI,WAAY,YACZgP,UAAiC,eACjCtrB,MAAAA,EACA0b,QANchH,MAAMjd,KAAKoiB,YAAYgB,WAAU,GAQ5B,MAAjBpjB,KAAKwc,WACPD,EAAQC,SAAWxc,KAAKwc,UAE1BS,MTrfGP,EAHPpG,ESwfsBtW,KTjfpB,OAAA,2BAAAsc,EAAmBhG,ESifOiG,CTjfM,CAAC,ESmflC,CAEDsH,SACE,MAAO,CACL7G,OAAQhd,KAAKqY,OAAO2E,OACpB+U,WAAY/xB,KAAKqY,OAAO0Z,WACxBvb,QAASxW,KAAKgD,KACdof,YAAapiB,KAAKoxB,cAAcvN,OAAQ,EAE3C,CAEDyO,uBACErQ,EACA6O,GAEA,IAAMgD,EAAkB7W,MAAMjd,KAAKgyB,oCACjClB,CAAqB,EAEvB,OAAgB,OAAT7O,EACH6R,EAAgB1I,kBAAmB,EACnC0I,EAAgB7I,eAAehJ,CAAI,CACxC,CAEO+P,0CACNlB,GAEA,IACQiD,EAaR,OAdK/zB,KAAKgzB,6BAIRhc,EAHM+c,EACHjD,GAAyBpH,EAAaoH,CAAqB,GAC5D9wB,KAAKkwB,uBACWlwB,uBAClBA,KAAKgzB,2BAA6B/V,MAAMyN,GAAuBtkB,OAC7DpG,KACA,CAAC0pB,EAAaqK,EAASC,oBAAoB,mBAG7Ch0B,KAAK4vB,aACH3S,MAAMjd,KAAKgzB,2BAA2B9H,kBAGnClrB,KAAKgzB,0BACb,CAEDiB,yBAAyB5uB,GAOvB,OAJIrF,KAAK+vB,gBACP9S,MAAMjd,KAAKgtB,MAAMvQ,WAAc,EAG7Bzc,KAAKoxB,cAAclI,mBAAqB7jB,EACnCrF,KAAKoxB,aAGVpxB,KAAK4vB,cAAc1G,mBAAqB7jB,EACnCrF,KAAK4vB,aAGP,IACR,CAEDhI,4BAA4B3F,GAC1B,GAAIA,IAASjiB,KAAKoiB,YAChB,OAAOpiB,KAAKgtB,MAAMvQ,SAAYzc,KAAKuxB,uBAAuBtP,CAAI,CAAC,CAElE,CAGD4F,0BAA0B5F,GACpBA,IAASjiB,KAAKoiB,aAChBpiB,KAAK+yB,oBAAmB,CAE3B,CAED1I,OACE,SAAUrqB,KAAKqY,OAAO0Z,cAAc/xB,KAAKqY,OAAO2E,UAAUhd,KAAKgD,IAChE,CAED2lB,yBACE3oB,KAAK6vB,0BAA4B,CAAA,EAC7B7vB,KAAKoiB,aACPpiB,KAAKoxB,aAAazI,wBAErB,CAEDC,wBACE5oB,KAAK6vB,0BAA4B,CAAA,EAC7B7vB,KAAKoiB,aACPpiB,KAAKoxB,aAAaxI,uBAErB,CAGDwI,mBACE,OAAOpxB,KAAKoiB,WACb,CAEO2Q,sBACN,IAMMmB,EANDl0B,KAAK+vB,iBAIV/vB,KAAK0vB,oBAAoBhmB,KAAK1J,KAAKoiB,WAAW,EAExC8R,EAAal0B,KAAKoiB,aAAa+C,KAAO,KACxCnlB,KAAKwwB,kBAAoB0D,KAC3Bl0B,KAAKwwB,gBAAkB0D,EACvBl0B,KAAKwvB,sBAAsB9lB,KAAK1J,KAAKoiB,WAAW,EAEnD,CAEOmR,sBACNY,EACAnqB,EACA5G,EACAkwB,GAEA,GAAItzB,KAAKgwB,SACP,MAAO,OAGT,IAAMoE,EACsB,YAA1B,OAAOpqB,EACHA,EACAA,EAAeN,KAAKY,KAAKN,CAAc,EAEzCqqB,EAAiB,CAAA,EAErB,IAAMpW,EAAUje,KAAK+vB,eACjB1mB,QAAQC,QAAS,EACjBtJ,KAAKiwB,uBAWT,GAVAjZ,EAAQiH,EAASje,uBAGjBie,EAAQzU,KAAK,KACP6qB,GAGJD,EAAGp0B,KAAKoiB,WAAW,CACrB,CAAC,EAE6B,YAA1B,OAAOpY,EAA+B,CACxC,IAAM2pB,EAAcQ,EAAaG,YAC/BtqB,EACA5G,EACAkwB,CAAS,EAEX,MAAO,KACLe,EAAiB,CAAA,EACjBV,GACF,CACD,CAAM,CACL,IAAMA,EAAcQ,EAAaG,YAAYtqB,CAAc,EAC3D,MAAO,KACLqqB,EAAiB,CAAA,EACjBV,GACF,CACD,CACF,CAOOpC,6BACNtP,GAEIjiB,KAAKoiB,aAAepiB,KAAKoiB,cAAgBH,GAC3CjiB,KAAKoxB,aAAaxI,wBAEhB3G,GAAQjiB,KAAK6vB,2BACf5N,EAAK0G,uBAAsB,GAG7B3oB,KAAKoiB,YAAcH,GAGjBhF,MAAMjd,KAAKmxB,oBAAoBlG,eAAehJ,CAAI,EAElDhF,MAAMjd,KAAKmxB,oBAAoB/F,mBAElC,CAEO4B,MAAMuH,GAIZ,OADAv0B,KAAKuvB,WAAavvB,KAAKuvB,WAAW/lB,KAAK+qB,EAAQA,CAAM,EAC9Cv0B,KAAKuvB,UACb,CAED4B,0BAEE,OADAna,EAAQhX,KAAK+wB,mBAAoB/wB,uBAC1BA,KAAK+wB,kBACb,CAIDyD,cAAcC,GACPA,GAAaz0B,CAAAA,KAAK4sB,WAAWplB,SAASitB,CAAS,IAGpDz0B,KAAK4sB,WAAWrrB,KAAKkzB,CAAS,EAI9Bz0B,KAAK4sB,WAAW8H,OAChB10B,KAAK2wB,cAAgBjE,GACnB1sB,KAAKqY,OAAOsU,eACZ3sB,KAAK20B,eAAc,CAAE,EAExB,CACDA,iBACE,OAAO30B,KAAK4sB,UACb,CACD1P,8BAEE,IAAMnE,EAAkC,CACtC6b,mBAA+B50B,KAAK2wB,eAQhCkE,GALF70B,KAAKipB,IAAIpC,QAAQiO,QACnB/b,EAAO,oBAAgC/Y,KAAKipB,IAAIpC,QAAQiO,OAIjC7X,MAAMjd,KAAKqvB,yBACjC0F,aAAa,CACZC,SAAU,CAAA,EACX,GACCC,uBAMEC,GALFL,IACF9b,EAAO,qBAAiC8b,GAIpB5X,MAAMjd,KAAKm1B,qBAKjC,OAJID,IACFnc,EAAO,uBAAoCmc,GAGtCnc,CACR,CAEDoc,0BACE,IAGMC,E5BzzBetf,EAAgB5J,E4BszBrC,OAAI8c,GAAAA,qBAAqBhpB,KAAKipB,GAAG,GAAKjpB,KAAKipB,IAAIwH,SAASyE,cAC/Cl1B,KAAKipB,IAAIwH,SAASyE,gBAErBE,EAAsBnY,MAAMjd,KAAKsvB,wBACpCyF,aAAa,CAAEC,SAAU,CAAA,EAAM,GAC9B3O,aACqBjjB,Q5B5zBJ0S,E4Bk0BjB,2CAA2Csf,EAAoBhyB,M5Bl0B9B8I,E4Bi0BnCmpB,G5Bh0BAlgB,GAAUhJ,UAAY5H,EAASkH,OACjC0J,GAAU3J,cAAcuK,GAAWA,iBAAMD,EAAO,GAAG5J,CAAI,E4Bm0BhDkpB,GAAqB7sB,MAC7B,CACF,CAQK,SAAU+sB,EAAUhf,GACxB,OAAO3L,EAAmB2L,CAAI,CAChC,OAGMmZ,GAMJ1sB,YAAqBuT,GlCr0BP,IAEdtN,EAEMusB,EkCi0Bev1B,KAAIsW,KAAJA,EALbtW,KAAQ4J,SAA8B,KACrC5J,KAAAs0B,alCh0BTvrB,EkCi0BEa,GAAa5J,KAAK4J,SAAWA,GlC9zBzB2rB,EAAQ,IAAIzsB,GAAiBC,EAAUC,CAAa,GAC7Ce,UAAUO,KAAKirB,CAAK,EkCg0BU,CAE3C7rB,WAEE,OADAsN,EAAQhX,KAAK4J,SAAU5J,KAAKsW,KAAI,gBAAA,EACzBtW,KAAK4J,SAASF,KAAKY,KAAKtK,KAAK4J,QAAQ,CAC7C,CACF,CE/2BD/I,IAAI20B,GAAyC,CAC3CC,eACE,MAAM,IAAIh1B,MAAM,iCAAiC,CAClD,EAEDi1B,kBAAmB,GACnBC,0BAA2B,GAC3BC,WAAY,IAOR,SAAUC,GAAQntB,GACtB,OAAO8sB,GAAmBC,OAAO/sB,CAAG,CACtC,CAcM,SAAUotB,GAAsBC,GACpC,MAAO,KAAKA,EAAS7d,KAAK8d,MAAsB,IAAhB9d,KAAK+d,OAAQ,CAAU,CACzD,OClBaC,GAIXnzB,YAA6BuT,GAAAtW,KAAIsW,KAAJA,EAHrBtW,KAAOm2B,QATe,KAU9Bn2B,KAAAo2B,SAAW,IAAI3M,GAEoC,CAEnD4M,OACEC,EACAC,GAEA,IAAMlxB,EAAKrF,KAAKm2B,QAMhB,OALAn2B,KAAKo2B,SAASvM,IACZxkB,EACA,IAAImxB,GAAWF,EAAWt2B,KAAKsW,KAAKtT,KAAMuzB,GAAc,EAAE,CAAC,EAE7Dv2B,KAAKm2B,OAAO,GACL9wB,CACR,CAEDoxB,MAAMC,GACJ,IAAMrxB,EAAKqxB,GA5BiB,KA6BvB12B,KAAKo2B,SAASpe,IAAI3S,CAAE,GAAG0jB,OAAM,EAClC/oB,KAAKo2B,SAASrN,OAAO1jB,CAAE,CACxB,CAED0a,YAAY2W,GAEV,OAAO12B,KAAKo2B,SAASpe,IADV0e,GAlCiB,IAmCD,GAAG3W,YAAa,GAAI,EAChD,CAED4W,cAAcD,GAGZ,OADK12B,KAAKo2B,SAASpe,IADC0e,GAvCQ,IAwCH,GAAGC,QAAO,EAC5B,EACR,CACF,OAEYC,GAAb7zB,cACE/C,KAAAigB,WAAyB,IAAI4W,EAmB9B,CAlBCC,MAAM1pB,GACJA,GACD,CAEDupB,QAEEI,EACAC,GAEA,OAAO3tB,QAAQC,QAAQ,OAAO,CAC/B,CACD+sB,OAEEY,EACAC,GAEA,MAAO,EACR,CACF,OAEYL,GACXC,MAAM1pB,GACJA,GACD,CAEDupB,QAEEI,EACAC,GAEA,OAAO3tB,QAAQC,QAAQ,OAAO,CAC/B,CACD+sB,OAEEY,EACAC,GAEA,MAAO,EACR,CACF,OAEYV,GAUXzzB,YACEo0B,EACA3gB,EACiBzO,GAAA/H,KAAM+H,OAANA,EAVX/H,KAAOwiB,QAAkB,KACzBxiB,KAAOo3B,QAAG,CAAA,EACVp3B,KAAaq3B,cAAkB,KACtBr3B,KAAYs3B,aAAG,KAC9Bt3B,KAAK22B,QAAO,CACd,EAOE,IAAML,EACqB,UAAzB,OAAOa,EACHlzB,SAASszB,eAAeJ,CAAa,EACrCA,EACNngB,EAAQsf,EAAS,iBAAgC,CAAE9f,QAAAA,CAAS,CAAA,EAE5DxW,KAAKs2B,UAAYA,EACjBt2B,KAAKw3B,UAAiC,cAArBx3B,KAAK+H,OAAO0vB,KACzBz3B,KAAKw3B,UACPx3B,KAAK22B,QAAO,EAEZ32B,KAAKs2B,UAAUoB,iBAAiB,QAAS13B,KAAKs3B,YAAY,CAE7D,CAEDvX,cAEE,OADA/f,KAAK23B,eAAc,EACZ33B,KAAKq3B,aACb,CAEDtO,SACE/oB,KAAK23B,eAAc,EACnB33B,KAAKo3B,QAAU,CAAA,EACXp3B,KAAKwiB,UACPnD,aAAarf,KAAKwiB,OAAO,EACzBxiB,KAAKwiB,QAAU,MAEjBxiB,KAAKs2B,UAAUsB,oBAAoB,QAAS53B,KAAKs3B,YAAY,CAC9D,CAEDX,UACE32B,KAAK23B,eAAc,EACf33B,KAAKwiB,UAITxiB,KAAKwiB,QAAUjf,OAAOic,WAAW,KAC/Bxf,KAAKq3B,eA+B+BQ,IACxC,IAAMC,EAAQ,GACRC,EACJ,iEACF,IAAKl3B,IAAIC,EAAI,EAAGA,EAAI+2B,EAAK/2B,CAAC,GACxBg3B,EAAMv2B,KACJw2B,EAAan1B,OAAOsV,KAAK8d,MAAM9d,KAAK+d,OAAM,EAAK8B,EAAah3B,MAAM,CAAC,CAAC,EAGxE,OAAO+2B,EAAMt2B,KAAK,EAAE,CACtB,GAzC4D,EAAE,EACxD,GAAM,CAAE4L,SAAAA,EAAU4qB,mBAAoBC,CAAe,EAAKj4B,KAAK+H,OAC/D,GAAIqF,EACF,IACEA,EAASpN,KAAKq3B,aAAa,CACf,CAAZ,MAAOn0B,IAGXlD,KAAKwiB,QAAUjf,OAAOic,WAAW,KAG/B,GAFAxf,KAAKwiB,QAAU,KACfxiB,KAAKq3B,cAAgB,KACjBY,EACF,IACEA,GACY,CAAZ,MAAO/0B,IAGPlD,KAAKw3B,WACPx3B,KAAK22B,QAAO,CAEf,EAjK4B,GAiKP,CACvB,EAnKyB,GAmKT,EAClB,CAEOgB,iBACN,GAAI33B,KAAKo3B,QACP,MAAM,IAAI32B,MAAM,qCAAqC,CAExD,CACF,CClKM,IACMy3B,GAAa,qBAEbC,GAaXp1B,YAAYq1B,GATHp4B,KAAIyM,KAPmC,uBAiB9CzM,KAAKsW,KAAOgf,EAAU8C,CAAU,CACjC,CAODC,aACE9D,EAAiB,SACjBjO,EAAe,CAAA,GAuCf,SAASgS,EACPnY,EACA7W,EACAiW,GAEA,IAAMO,EAAavc,OAAOuc,WACtBE,GAAaF,CAAU,EACzBA,EAAWG,WAAW6W,MAAM,KAC1BhX,EAAWG,WACR0W,QAAQxW,EAAS,CAAEoU,OAAAA,EAAQ,EAC3B/qB,KAAKjB,IACJe,EAAQf,CAAK,CACf,CAAC,EACAkB,MAAM,KACLH,EAAQ4uB,EAAU,CACpB,CAAC,CACL,CAAC,EAED3Y,EAAO9e,MAAM,wCAAwC,CAAC,CAEzD,CAGD,OAAIT,KAAKsW,KAAKma,SAASC,mCACC,IAAIkG,IACLD,QAAQ,UAAW,CAAEpC,OAAQ,QAAQ,CAAE,EAGvD,IAAIlrB,QAAgB,CAACC,EAASiW,MAjErC9C,MAA+BnG,IAC7B,GAAI,CAACgQ,EAAc,CACjB,GAAqB,MAAjBhQ,EAAKkG,UAAkD,MAA9BlG,EAAK6Z,sBAChC,OAAO7Z,EAAK6Z,sBAAsBhQ,QAEpC,GACmB,MAAjB7J,EAAKkG,UAC2CpX,KAAAA,IAAhDkR,EAAK8Z,wBAAwB9Z,EAAKkG,UAElC,OAAOlG,EAAK8Z,wBAAwB9Z,EAAKkG,UAAU2D,OAEtD,CAED,OAAO,IAAI9W,QAAgBoT,MAAOnT,EAASiW,KACzCsB,GAAmBvK,EAAM,CACvBiiB,WAAmC,kBACnCC,QAAoC,uBACrC,EACEhvB,KAAKyP,IACJ,IAGQZ,EAHR,GAA8BjT,KAAAA,IAA1B6T,EAASoH,aASX,OANMhI,EAAS,IAAI6H,GAAgBjH,CAAQ,EACtB,MAAjB3C,EAAKkG,SACPlG,EAAK6Z,sBAAwB9X,EAE7B/B,EAAK8Z,wBAAwB9Z,EAAKkG,UAAYnE,EAEzC/O,EAAQ+O,EAAO8H,OAAO,EAR7BZ,EAAO,IAAI9e,MAAM,yCAAyC,CAAC,CAU/D,CAAC,EACAgJ,MAAMrG,IACLmc,EAAOnc,CAAK,CACd,CAAC,CACL,CAAC,CACF,GA+BiBpD,KAAKsW,IAAI,EACtB9M,KAAK2W,IACJ,GAAI,CAACmG,GAAgBtG,GAAazc,OAAOuc,UAAU,EACjDwY,EAAuBnY,EAAS7W,EAASiW,CAAM,OAE/C,GAAsB,aAAlB,OAAOhc,OACTgc,EACE,IAAI9e,MAAM,gDAAgD,CAAC,MAF/D,CAMAI,IAAI6H,EFhGP8sB,GAAmBG,0BEiGG,IAAfjtB,EAAI3H,SACN2H,GAAOyX,GAETsY,GACW/vB,CAAG,EACXc,KAAK,KACJ8uB,EAAuBnY,EAAS7W,EAASiW,CAAM,CACjD,CAAC,EACA9V,MAAMrG,IACLmc,EAAOnc,CAAK,CACd,CAAC,CAZF,CAcL,CAAC,EACAqG,MAAMrG,IACLmc,EAAOnc,CAAK,CACd,CAAC,CACL,CAAC,CACF,CACF,CAEMqZ,eAAeic,GACpBpiB,EACAiG,EACAgY,EACAoE,EAAgB,CAAA,EAChBC,EAAc,CAAA,GAEd,IAAMC,EAAW,IAAIV,GAA4B7hB,CAAI,EACrDzV,IAAIi4B,EAEJ,GAAIF,EACFE,EAAkBZ,QAElB,IACEY,EAAkB7b,MAAM4b,EAASR,OAAO9D,CAAM,CAG/C,CAFC,MAAOnxB,GACP01B,EAAkB7b,MAAM4b,EAASR,OAAO9D,EAAQ,CAAA,CAAI,CACrD,CAGH,IASUwE,EAcAA,EAvBJC,EAAa,CAAE,GAAGzc,GAgDxB,MA9CmD,qBAAjDgY,GACM,iBAANA,EAEI,wBAAyByE,GACrBrZ,EACJqZ,EACAC,oBAAoBtZ,YAChBoZ,EACJC,EACAC,oBAAoBF,eAEtBn0B,OAAO6gB,OAAOuT,EAAY,CACxBC,oBAAuB,CACrBtZ,YAAAA,EACAoZ,eAAAA,EACAD,gBAAAA,EACAP,WAAqC,kBACrCW,iBAA+C,sBAChD,CACF,CAAA,GACQ,oBAAqBF,IACxBD,EACJC,EACAG,gBAAgBJ,eAElBn0B,OAAO6gB,OAAOuT,EAAY,CACxBG,gBAAmB,CACjBJ,eAAAA,EACAD,gBAAAA,EACAP,WAAqC,kBACrCW,iBAA+C,sBAChD,CACF,CAAA,IAKAP,EAGH/zB,OAAO6gB,OAAOuT,EAAY,CAAEI,YAAeN,CAAiB,CAAA,EAF5Dl0B,OAAO6gB,OAAOuT,EAAY,CAAEF,gBAAAA,CAAiB,CAAA,EAI/Cl0B,OAAO6gB,OAAOuT,EAAY,CAAET,WAAY,iBAA2B,CAAA,EACnE3zB,OAAO6gB,OAAOuT,EAAY,CACxBE,iBAA+C,sBAChD,CAAA,GACMF,CACT,CAOOvc,eAAe4c,EACpBC,EACA/c,EACAgd,EACAC,EACAC,GAEA,IAgFUC,EAhFV,MAA2E,4BAAvED,EAEAH,EACGrG,oBAAqB,GACpBtS,kBAAgE,yBAAA,GAE9DgZ,EAAuB1c,MAAMyb,GACjCY,EACA/c,EACAgd,EACU,eAAVA,GAEKC,EAAaF,EAAcK,CAAoB,GAE/CH,EAAaF,EAAc/c,CAAO,EAAE9S,MAAMgT,MAAMrZ,IACrD,IAIQu2B,EAJR,MAAmB,iCAAfv2B,EAAMyC,MACR1C,QAAQyS,IACH2jB,EAAH,8HAA2I,EAEvII,EAAuB1c,MAAMyb,GACjCY,EACA/c,EACAgd,EACU,eAAVA,GAEKC,EAAaF,EAAcK,CAAoB,GAE/CtwB,QAAQkW,OAAOnc,CAAK,CAE/B,CAAC,EAEoE,mBAA9Dq2B,EAEPH,EACGrG,oBAAqB,GACpBtS,kBAAuD,gBAAA,GAErDgZ,EAAuB1c,MAAMyb,GACjCY,EACA/c,EACAgd,CAAU,EAGLC,EAAaF,EAAcK,CAAoB,EAAElwB,MACtDgT,MAAMrZ,IASF,IAUQs2B,EAlBV,GAKgC,UAJ9BJ,EACGrG,oBAAqB,GACpB3S,4BAA2B,gBAE5B,IAIc,iCAAfld,EAAMyC,MACS,gCAAfzC,EAAMyC,MAgBN,OAdA1C,QAAQyS,kHACwG2jB,SAAkB,EAK5HG,EAA6Bzc,MAAMyb,GACvCY,EACA/c,EACAgd,EACA,CAAA,EACA,CAAA,GAGKC,EAAaF,EAAcI,CAA0B,EAIhE,OAAOrwB,QAAQkW,OAAOnc,CAAK,CAC7B,CAAC,IAIGs2B,EAA6Bzc,MAAMyb,GACvCY,EACA/c,EACAgd,EACA,CAAA,EACA,CAAA,GAIKC,EAAaF,EAAcI,CAA0B,GAGvDrwB,QAAQkW,OACbka,EAAwB,6BAA6B,CAG3D,CC3SgB,SAAAG,GACdtjB,EACA5N,EACAme,GAEA,IAAM9H,EAAeuW,EAAUhf,CAAI,EAO7BujB,GANN7iB,EACE,eAAee,KAAKrP,CAAG,EACvBqW,EAAY,2BAIU,CAAC,CAAC8H,GAASgT,iBAE7BniB,EAAWoiB,GAAgBpxB,CAAG,EAC9B,CAAE8U,KAAAA,EAAMuc,KAAAA,CAAM,GAqDMrxB,IAI1B,IAMMsxB,EANAtiB,EAAWoiB,GAAgBpxB,CAAG,EAEpC,OAAKuxB,EADa,mBAAmBC,KAAKxxB,EAAIyxB,OAAOziB,EAAS3W,MAAM,CAAC,IAI/Dq5B,EAAcH,EAAU,GAAG3xB,MAAM,GAAG,EAAE+xB,IAAK,GAAI,IAC/CL,EAAgB,qBAAqBE,KAAKE,CAAW,GAGlD,CAAE5c,KADHA,EAAOwc,EAAc,GACZD,KAAMO,GAAUF,EAAYD,OAAO3c,EAAKzc,OAAS,CAAC,CAAC,IAE5D,CAACyc,EAAMuc,GAAQK,EAAY9xB,MAAM,GAAG,EACnC,CAAEkV,KAAAA,EAAMuc,KAAMO,GAAUP,CAAI,CAAC,IAT7B,CAAEvc,KAAM,GAAIuc,KAAM,IAAI,CAWjC,GAvE4CrxB,CAAG,EACvC6xB,EAAmB,OAATR,EAAgB,GAAK,IAAIA,EAGnCxhB,EAAW,CAAE7P,IAAQgP,OAAa8F,IAAO+c,MACzChd,EAAiB3Y,OAAO41B,OAAO,CACnChd,KAAAA,EACAuc,KAAAA,EACAriB,SAAUA,EAAS/Q,QAAQ,IAAK,EAAE,EAClCkgB,QAASjiB,OAAO41B,OAAO,CAAEX,gBAAAA,CAAe,CAAE,CAC3C,CAAA,EA2ED,SAASY,IACP,IAAMC,EAAKz2B,SAAS02B,cAAc,GAAG,EAC/BC,EAAMF,EAAGG,MACfH,EAAGI,UACD,oEACFF,EAAIG,SAAW,QACfH,EAAII,MAAQ,OACZJ,EAAIK,gBAAkB,UACtBL,EAAIM,OAAS,qBACbN,EAAIO,MAAQ,UACZP,EAAIQ,OAAS,MACbR,EAAIS,KAAO,MACXT,EAAIU,OAAS,MACbV,EAAIW,OAAS,QACbX,EAAIY,UAAY,SAChBd,EAAGe,UAAUC,IAAI,2BAA2B,EAC5Cz3B,SAAS4Y,KAAK8e,YAAYjB,CAAE,CAC7B,CAzFI3b,EAAalB,kBAuBlBkB,EAAa1G,OAAOE,SAAWA,EAC/BwG,EAAaxB,eAAiBA,EAC9BwB,EAAa0R,SAASC,kCAAoC,CAAA,EAGtD7lB,GAAmB2S,CAAI,GrC1DtBf,MAA0Bmf,IAChB3e,MAAMpE,MAAM+iB,EAAU,CACnCne,YAAa,SACd,CAAA,GACaY,IqCuDO3G,EAAH,KAAgB8F,EAAO+c,CAAS,EACtCV,IA6DW,aAAnB,OAAO12B,SAAmD,YAAxB,OAAOA,QAAQmB,MACnDnB,QAAQmB,KACN,8HAE4B,EAGV,aAAlB,OAAOf,QAA8C,aAApB,OAAOU,WACd,YAAxBA,SAAS43B,WACXt4B,OAAOm0B,iBAAiB,mBAAoB+C,CAAY,EAExDA,QAnGFzjB,EACE+H,EAAa1G,OAAOE,UAAYwG,EAAaxB,eAC7CwB,4BAMF/H,EACE/P,EAAUsR,EAAUwG,EAAa1G,OAAOE,QAAQ,GAC9CtR,EAAUsW,EAAgBwB,EAAaxB,cAAc,EACvDwB,EAAY,0BAmBlB,CAEA,SAAS+a,GAAgBpxB,GACvB,IAAMozB,EAAcpzB,EAAIjD,QAAQ,GAAG,EACnC,OAAOq2B,EAAc,EAAI,GAAKpzB,EAAIyxB,OAAO,EAAG2B,EAAc,CAAC,CAC7D,CAsBA,SAASxB,GAAUC,GACjB,IAGMR,EAHN,MAAKQ,CAAAA,IAGCR,EAAO7Y,OAAOqZ,CAAO,EACvBpZ,MAAM4Y,CAAI,GAHL,KAMFA,CACT,OC/GagC,GAEXh5B,YAOW8hB,EASAmX,GATAh8B,KAAU6kB,WAAVA,EASA7kB,KAAYg8B,aAAZA,CACP,CAOJnY,SACE,OAAO3M,EAAU,iBAAiB,CACnC,CAGD+kB,oBAAoBC,GAClB,OAAOhlB,EAAU,iBAAiB,CACnC,CAEDilB,eACED,EACAE,GAEA,OAAOllB,EAAU,iBAAiB,CACnC,CAEDmlB,6BAA6BH,GAC3B,OAAOhlB,EAAU,iBAAiB,CACnC,CACF,CCjCMuF,eAAe6f,GACpBhmB,EACAiG,GAEA,OAAOG,EACLpG,EAGA,OAAA,6BAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,CAsBOE,eAAe8f,GACpBjmB,EACAiG,GAEA,OAAOG,EACLpG,EAGA,OAAA,sBAAAiG,CAAO,CAEX,CCvCOE,eAAe+f,GACpBlmB,EACAiG,GAEA,OAAOoC,EAILrI,EAGA,OAAA,kCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,CAqDAE,eAAeggB,GACbnmB,EACAiG,GAEA,OAAOG,EACLpG,EAGA,OAAA,2BAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,CASOE,eAAeigB,GACpBpmB,EACAiG,GAEA,OAAOkgB,GAAYnmB,EAAMiG,CAAO,CAClC,CAEOE,eAAekgB,GACpBrmB,EACAiG,GAEA,OAAOkgB,GAAYnmB,EAAMiG,CAAO,CAClC,OC5FaqgB,WAA4Bb,GAEvCh5B,YAEW85B,EAEAC,EACTd,EAESe,EAA2B,MAEpC/2B,MAAK,WAAsBg2B,CAAY,EAP9Bh8B,KAAM68B,OAANA,EAEA78B,KAAS88B,UAATA,EAGA98B,KAAS+8B,UAATA,CAGV,CAGDC,6BACEtd,EACAgP,GAEA,OAAO,IAAIkO,GACTld,EACAgP,aAGH,CAGDuO,yBACEvd,EACAwd,EACA1gB,EAA0B,MAE1B,OAAO,IAAIogB,GACTld,EACAwd,EAAO,YAEP1gB,CAAQ,CAEX,CAGDqH,SACE,MAAO,CACLnE,MAAO1f,KAAK68B,OACZnO,SAAU1uB,KAAK88B,UACfd,aAAch8B,KAAKg8B,aACnBxf,SAAUxc,KAAK+8B,UAElB,CAUD9V,gBAAgB/I,GACd,IAAM7V,EAAsB,UAAhB,OAAO6V,EAAoBpa,KAAKC,MAAMma,CAAI,EAAIA,EAC1D,GAAI7V,GAAKqX,OAASrX,GAAKqmB,SAAU,CAC/B,GAAoB,aAAhBrmB,EAAI2zB,aACN,OAAOh8B,KAAKg9B,sBAAsB30B,EAAIqX,MAAOrX,EAAIqmB,QAAQ,EACpD,GAAoB,cAAhBrmB,EAAI2zB,aACb,OAAOh8B,KAAKi9B,kBAAkB50B,EAAIqX,MAAOrX,EAAIqmB,SAAUrmB,EAAImU,QAAQ,CAEtE,CACD,OAAO,IACR,CAGDyf,0BAA0B3lB,GACxB,OAAQtW,KAAKg8B,cACX,IAAA,WAOE,OAAO3C,EACL/iB,EAPyC,CACzC6mB,kBAAmB,CAAA,EACnBzd,MAAO1f,KAAK68B,OACZnO,SAAU1uB,KAAK88B,UACfvE,WAAmC,mBAMnC,qBAAAiE,GAAkB,2BAGtB,IAAA,YACE,OCrGD/f,MACLnG,EACAiG,IAEOoC,EAILrI,EAGA,OAAA,mCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,GD0FFjG,EAAM,CAC/BoJ,MAAO1f,KAAK68B,OACZK,QAASl9B,KAAK88B,SACf,CAAA,EACH,QACE9mB,EAAMM,EAAI,iBACb,CACF,CAGD6lB,qBACE7lB,EACA2N,GAEA,OAAQjkB,KAAKg8B,cACX,IAAA,WAQE,OAAO3C,EACL/iB,EAR6B,CAC7B2N,QAAAA,EACAkZ,kBAAmB,CAAA,EACnBzd,MAAO1f,KAAK68B,OACZnO,SAAU1uB,KAAK88B,UACfvE,WAAmC,mBAMnC,iBAAAgE,GAAiB,2BAGrB,IAAA,YACE,OChHD9f,MACLnG,EACAiG,IAEOoC,EAILrI,EAGA,OAAA,mCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,GDqGQjG,EAAM,CACzC2N,QAAAA,EACAvE,MAAO1f,KAAK68B,OACZK,QAASl9B,KAAK88B,SACf,CAAA,EACH,QACE9mB,EAAMM,EAAI,iBACb,CACF,CAGD+lB,6BAA6B/lB,GAC3B,OAAOtW,KAAKi8B,oBAAoB3lB,CAAI,CACrC,CACF,CEtIMmG,eAAe2gB,EACpB9mB,EACAiG,GAEA,OAAOoC,EACLrI,EAGA,OAAA,6BAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,OCDa8gB,UAAwBtB,GAArCh5B,kCAqBU/C,KAAYs9B,aAAkB,IA8HvC,CA3HCC,mBAAmBx1B,GACjB,IAAMy1B,EAAO,IAAIH,EAAgBt1B,EAAO8c,WAAY9c,EAAOi0B,YAAY,EA4BvE,OA1BIj0B,EAAOkc,SAAWlc,EAAOge,aAEvBhe,EAAOkc,UACTuZ,EAAKvZ,QAAUlc,EAAOkc,SAGpBlc,EAAOge,cACTyX,EAAKzX,YAAche,EAAOge,aAIxBhe,EAAO01B,OAAS,CAAC11B,EAAOu1B,eAC1BE,EAAKC,MAAQ11B,EAAO01B,OAGlB11B,EAAOu1B,eACTE,EAAKF,aAAev1B,EAAOu1B,eAEpBv1B,EAAO21B,YAAc31B,EAAO41B,kBAErCH,EAAKzX,YAAche,EAAO21B,WAC1BF,EAAKI,OAAS71B,EAAO41B,kBAErB3nB,oBAGKwnB,CACR,CAGD3Z,SACE,MAAO,CACLI,QAASjkB,KAAKikB,QACd8B,YAAa/lB,KAAK+lB,YAClB6X,OAAQ59B,KAAK49B,OACbH,MAAOz9B,KAAKy9B,MACZH,aAAct9B,KAAKs9B,aACnBzY,WAAY7kB,KAAK6kB,WACjBmX,aAAch8B,KAAKg8B,aAEtB,CAWD/U,gBAAgB/I,GACd,IAMMsf,EALN,GAAM,CAAE3Y,WAAAA,EAAYmX,aAAAA,KAAiB9lB,CAAI,EADb,UAAhB,OAAOgI,EAAoBpa,KAAKC,MAAMma,CAAI,EAAIA,EAE1D,OAAK2G,GAAemX,IAIdwB,EAAO,IAAIH,EAAgBxY,EAAYmX,CAAY,GACpD/X,QAAU/N,EAAK+N,SAAW7e,KAAAA,EAC/Bo4B,EAAKzX,YAAc7P,EAAK6P,aAAe3gB,KAAAA,EACvCo4B,EAAKI,OAAS1nB,EAAK0nB,OACnBJ,EAAKC,MAAQvnB,EAAKunB,MAClBD,EAAKF,aAAepnB,EAAKonB,cAAgB,KAClCE,GATE,IAUV,CAGDvB,oBAAoB3lB,GAElB,OAAO8mB,EAAc9mB,EADLtW,KAAK69B,cACa,CACnC,CAGD1B,eACE7lB,EACA2N,GAEA,IAAM1H,EAAUvc,KAAK69B,eAErB,OADAthB,EAAQ0H,QAAUA,EACXmZ,EAAc9mB,EAAMiG,CAAO,CACnC,CAGD8f,6BAA6B/lB,GAC3B,IAAMiG,EAAUvc,KAAK69B,eAErB,OADAthB,EAAQuhB,WAAa,CAAA,EACdV,EAAc9mB,EAAMiG,CAAO,CACnC,CAEOshB,eACN,IAQQE,EARFxhB,EAAgC,CACpCyhB,WApJkB,mBAqJlBb,kBAAmB,CAAA,GAyBrB,OAtBIn9B,KAAKs9B,aACP/gB,EAAQ+gB,aAAet9B,KAAKs9B,cAEtBS,EAAmC,GACrC/9B,KAAKikB,UACP8Z,EAAmB,SAAI/9B,KAAKikB,SAE1BjkB,KAAK+lB,cACPgY,EAAuB,aAAI/9B,KAAK+lB,aAE9B/lB,KAAK49B,SACPG,EAA6B,mBAAI/9B,KAAK49B,QAGxCG,EAAqB,WAAI/9B,KAAK6kB,WAC1B7kB,KAAKy9B,OAAS,CAACz9B,KAAKs9B,eACtBS,EAAgB,MAAI/9B,KAAKy9B,OAG3BlhB,EAAQwhB,SAAWl2B,GAAYk2B,CAAQ,GAGlCxhB,CACR,CACF,CC9JME,eAAewhB,GACpB3nB,EACAiG,GAEA,OAAOG,EAILpG,EAGA,OAAA,oCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,CAiEA,IAAM2hB,GAEF,CACFzjB,eAAwD,wBCtF7C0jB,WAA4BpC,GACvCh5B,YAAqCgF,GACnC/B,uBADmChG,KAAM+H,OAANA,CAEpC,CAGDq2B,yBACEC,EACAC,GAEA,OAAO,IAAIH,GAAoB,CAAEE,eAAAA,EAAgBC,iBAAAA,CAAkB,CAAA,CACpE,CAGDC,0BACE5e,EACA6e,GAEA,OAAO,IAAIL,GAAoB,CAAExe,YAAAA,EAAa6e,eAAAA,CAAgB,CAAA,CAC/D,CAGDvC,oBAAoB3lB,GAClB,ODqBGmG,MACLnG,EACAiG,IAEOoC,EAILrI,EAGA,OAAA,qCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,GChCJjG,EAAMtW,KAAKy+B,yBAA0B,CAAA,CACnE,CAGDtC,eACE7lB,EACA2N,GAEA,OD4BGxH,MACLnG,EACAiG,KAEA,IAAMtD,EAAWgE,MAAM0B,EAIrBrI,EAAI,OAAA,qCAGJgG,EAAmBhG,EAAMiG,CAAO,CAAC,EAEnC,GAAItD,EAASulB,eACX,MAAMpgB,GAAiB9H,EAAuC,2CAAA2C,CAAQ,EAExE,OAAOA,CACT,GC7C+B3C,EAAM,CAC/B2N,QAAAA,EACA,GAAGjkB,KAAKy+B,yBAA0B,CACnC,CAAA,CACF,CAGDpC,6BAA6B/lB,GAC3B,ODkDGmG,MACLnG,EACAiG,IAMOoC,EAILrI,EAAI,OAAA,qCAGJgG,EAAmBhG,EAXmC,CACtD,GAAGiG,EACHmiB,UAAW,SASwB,EACnCR,EAA2C,GClEP5nB,EAAMtW,KAAKy+B,yBAA0B,CAAA,CAC1E,CAGDA,2BACE,GAAM,CAAED,eAAAA,EAAgB7e,YAAAA,EAAa0e,eAAAA,EAAgBC,iBAAAA,CAAkB,EACrEt+B,KAAK+H,OACP,OAAIy2B,GAAkB7e,EACb,CAAE6e,eAAAA,EAAgB7e,YAAAA,GAGpB,CACLgf,YAAaN,EACbx4B,KAAMy4B,EAET,CAGDza,SACE,IAAMxb,EAA8B,CAClCwc,WAAY7kB,KAAK6kB,YAenB,OAbI7kB,KAAK+H,OAAO4X,cACdtX,EAAIsX,YAAc3f,KAAK+H,OAAO4X,aAE5B3f,KAAK+H,OAAOy2B,iBACdn2B,EAAIm2B,eAAiBx+B,KAAK+H,OAAOy2B,gBAE/Bx+B,KAAK+H,OAAOu2B,mBACdj2B,EAAIi2B,iBAAmBt+B,KAAK+H,OAAOu2B,kBAEjCt+B,KAAK+H,OAAOs2B,iBACdh2B,EAAIg2B,eAAiBr+B,KAAK+H,OAAOs2B,gBAG5Bh2B,CACR,CAGD4e,gBAAgB/I,GAKd,GAAM,CAAEmgB,eAAAA,EAAgBC,iBAAAA,EAAkB3e,YAAAA,EAAa6e,eAAAA,CAAc,EAHnEtgB,EADkB,UAAhB,OAAOA,EACFpa,KAAKC,MAAMma,CAAI,EAItBA,EACF,OACGogB,GACAD,GACA1e,GACA6e,EAKI,IAAIL,GAAoB,CAC7BE,eAAAA,EACAC,iBAAAA,EACA3e,YAAAA,EACA6e,eAAAA,CACD,CAAA,EARQ,IASV,CACF,OCvDYI,GAiCX77B,YAAY87B,GACV,IAAMC,EAAe12B,GAAkBK,GAAmBo2B,CAAU,CAAC,EAC/D7hB,EAAS8hB,EAAgC,QAAI,KAC7Cj5B,EAAOi5B,EAA6B,SAAI,KACxCJ,GApFS3xB,IACjB,OAAQA,GACN,IAAK,eACH,MAAyC,gBAC3C,IAAK,gBACH,MAA0C,iBAC5C,IAAK,SACH,MAAwC,eAC1C,IAAK,cACH,MAAwC,eAC1C,IAAK,uBACH,MAAmD,0BACrD,IAAK,6BACH,MAAyD,gCAC3D,QACE,OAAO,IACV,CACH,GAmEgC+xB,EAA6B,MAAI,IAAI,EAEjE9nB,EAAQgG,GAAUnX,GAAQ64B,oBAC1B1+B,KAAKgd,OAASA,EACdhd,KAAK0+B,UAAYA,EACjB1+B,KAAK6F,KAAOA,EACZ7F,KAAK++B,YAAcD,EAAqC,aAAI,KAC5D9+B,KAAKod,aAAe0hB,EAAsC,MAAI,KAC9D9+B,KAAKwc,SAAWsiB,EAAkC,UAAI,IACvD,CAWDE,iBAAiBC,GA/EXA,EAAO72B,GAAkBK,GADVC,EAiFcu2B,CAhFkB,CAAC,EAAQ,KAGxDC,EAAiBD,EACnB72B,GAAkBK,GAAmBw2B,CAAI,CAAC,EAAgB,aAC1D,KA2EF,IAhFIA,EAGAC,EA6EEL,IAzEFM,EAAc/2B,GAAkBK,GAAmBC,CAAG,CAAC,EAC7C,cAGZN,GAAkBK,GAAmB02B,CAAW,CAAC,EAAQ,KACzD,OACwBA,GAAeD,GAAkBD,GAAQv2B,EAoEnE,IACE,OAAO,IAAIk2B,GAAcC,CAAU,CAGpC,CAFC,MACA,OAAO,IACR,CACF,CACF,OC3HYO,GAAbr8B,cAkBW/C,KAAA6kB,WAAaua,GAAkBC,WA2DzC,CAvCCC,kBAAkB5f,EAAegP,GAC/B,OAAOkO,GAAoBI,sBAAsBtd,EAAOgP,CAAQ,CACjE,CAwBD6Q,0BACE7f,EACA8f,GAEA,IAAMC,EAAgBb,GAAcI,UAAUQ,CAAS,EAGvD,OAFAxoB,EAAQyoB,EAAa,kBAEd7C,GAAoBK,kBACzBvd,EACA+f,EAAc55B,KACd45B,EAAcjjB,QAAQ,CAEzB,EAxEe4iB,GAAAC,YAA8C,WAI9CD,GAAAM,8BACc,WAIdN,GAAAO,0BAAyB,kBCVrBC,EAWpB78B,YAAqB8hB,GAAA7kB,KAAU6kB,WAAVA,EATrB7kB,KAAmB6/B,oBAAkB,KAE7B7/B,KAAgB8/B,iBAAqB,EAOF,CAO3CC,mBAAmB3iB,GACjBpd,KAAK6/B,oBAAsBziB,CAC5B,CAYD4iB,oBAAoBC,GAElB,OADAjgC,KAAK8/B,iBAAmBG,EACjBjgC,IACR,CAKDkgC,sBACE,OAAOlgC,KAAK8/B,gBACb,CACF,OCdqBK,WACZP,EADV78B,kCAKU/C,KAAMogC,OAAa,EAqB5B,CAdCC,SAASC,GAKP,OAHKtgC,KAAKogC,OAAO54B,SAAS84B,CAAK,GAC7BtgC,KAAKogC,OAAO7+B,KAAK++B,CAAK,EAEjBtgC,IACR,CAKDugC,YACE,MAAO,CAAC,GAAGvgC,KAAKogC,OACjB,CACF,OA0CYI,WAAsBL,GAKjCM,0BAA0BviB,GACxB,IAAM7V,EAAsB,UAAhB,OAAO6V,EAAoBpa,KAAKC,MAAMma,CAAI,EAAIA,EAK1D,OAJAlH,EACE,eAAgB3O,GAAO,iBAAkBA,EAAG,gBAAA,EAGvCg1B,EAAgBE,YAAYl1B,CAAG,CACvC,CAuBDi3B,WAAWv3B,GACT,OAAO/H,KAAK0gC,YAAY,CAAE,GAAG34B,EAAQ01B,MAAO11B,EAAO44B,QAAQ,CAAE,CAC9D,CAGOD,YACN34B,GAIA,OAFAiP,EAAQjP,EAAOkc,SAAWlc,EAAOge,YAAW,gBAAA,EAErCsX,EAAgBE,YAAY,CACjC,GAAGx1B,EACH8c,WAAY7kB,KAAK6kB,WACjBmX,aAAch8B,KAAK6kB,UACpB,CAAA,CACF,CAOD+b,4BACEC,GAEA,OAAOL,GAAcM,gCACnBD,CAAwC,CAE3C,CAODE,2BAA2B39B,GACzB,OAAOo9B,GAAcM,gCAClB19B,EAAM2C,YAAc,EAAE,CAE1B,CAEO+6B,uCAAuC,CAC7ClhB,eAAgBohB,IAEhB,GAAI,CAACA,EACH,OAAO,KAGT,GAAM,CACJC,aAAAA,EACAC,iBAAAA,EACAvD,iBAAAA,EACAL,aAAAA,EACAG,MAAAA,EACA5Y,WAAAA,CACD,EAAGmc,EACJ,GACE,EAACE,GACAvD,GACAsD,GACA3D,GAED,OAAO,KAGT,GAAI,CAACzY,EACH,OAAO,KAGT,IACE,OAAO,IAAI2b,GAAc3b,CAAU,EAAE6b,YAAY,CAC/Czc,QAASgd,EACTlb,YAAamb,EACbzD,MAAAA,EACAH,aAAAA,CACD,CAAA,CAGF,CAFC,MAAOp6B,GACP,OAAO,IACR,CACF,CACF,OCpLYi+B,UAA6BhB,GAOxCp9B,cACEiD,qBACD,CAcDs5B,kBAAkBvZ,GAChB,OAAOsX,EAAgBE,YAAY,CACjC1Y,WAAYsc,EAAqB9B,YACjCrD,aAAcmF,EAAqBC,wBACnCrb,YAAAA,CACD,CAAA,CACF,CAOD6a,4BACEC,GAEA,OAAOM,EAAqBE,2BAC1BR,CAAwC,CAE3C,CAQDE,2BAA2B39B,GACzB,OAAO+9B,EAAqBE,2BACzBj+B,EAAM2C,YAAc,EAAE,CAE1B,CAEOs7B,kCAAkC,CACxCzhB,eAAgBohB,IAEhB,GAAI,EAACA,GAAmB,qBAAsBA,GAC5C,OAAO,KAGT,GAAI,CAACA,EAAcE,iBACjB,OAAO,KAGT,IACE,OAAOC,EAAqB7B,WAAW0B,EAAcE,gBAAgB,CAGtE,CAFC,MACA,OAAO,IACR,CACF,EAtEeC,EAAAC,wBACQ,eAERD,EAAA9B,YAAkD,qBCFvDiC,UAA2BnB,GAMtCp9B,cACEiD,oBACAhG,KAAKqgC,SAAS,SAAS,CACxB,CAeDf,kBACErb,EACA8B,GAEA,OAAOsX,EAAgBE,YAAY,CACjC1Y,WAAYyc,EAAmBjC,YAC/BrD,aAAcsF,EAAmBC,sBACjCtd,QAAAA,EACA8B,YAAAA,CACD,CAAA,CACF,CAOD6a,4BACEC,GAEA,OAAOS,EAAmBD,2BACxBR,CAAwC,CAE3C,CAODE,2BAA2B39B,GACzB,OAAOk+B,EAAmBD,2BACvBj+B,EAAM2C,YAAc,EAAE,CAE1B,CAEOs7B,kCAAkC,CACxCzhB,eAAgBohB,IAEhB,GAAI,CAACA,EACH,OAAO,KAGT,GAAM,CAAEC,aAAAA,EAAcC,iBAAAA,CAAkB,EACtCF,EACF,GAAI,CAACC,GAAgB,CAACC,EAEpB,OAAO,KAGT,IACE,OAAOI,EAAmBhC,WAAW2B,EAAcC,CAAgB,CAGpE,CAFC,MACA,OAAO,IACR,CACF,EA7EeI,EAAAC,sBAA0D,aAE1DD,EAAAjC,YAA8C,mBCJnDmC,UAA2BrB,GAMtCp9B,cACEiD,mBACD,CAODs5B,kBAAkBvZ,GAChB,OAAOsX,EAAgBE,YAAY,CACjC1Y,WAAY2c,EAAmBnC,YAC/BrD,aAAcwF,EAAmBC,sBACjC1b,YAAAA,CACD,CAAA,CACF,CAOD6a,4BACEC,GAEA,OAAOW,EAAmBH,2BACxBR,CAAwC,CAE3C,CAQDE,2BAA2B39B,GACzB,OAAOo+B,EAAmBH,2BACvBj+B,EAAM2C,YAAc,EAAE,CAE1B,CAEOs7B,kCAAkC,CACxCzhB,eAAgBohB,IAEhB,GAAI,EAACA,GAAmB,qBAAsBA,GAC5C,OAAO,KAGT,GAAI,CAACA,EAAcE,iBACjB,OAAO,KAGT,IACE,OAAOM,EAAmBlC,WAAW0B,EAAcE,gBAAgB,CAGpE,CAFC,MACA,OAAO,IACR,CACF,EA9DeM,EAAAC,sBAA0D,aAE1DD,EAAAnC,YAA8C,mBCpCnDqC,WAA2B3F,GAEtCh5B,YACE8hB,EACiByY,GAEjBt3B,MAAM6e,EAAYA,CAAU,EAFX7kB,KAAYs9B,aAAZA,CAGlB,CAGDrB,oBAAoB3lB,GAElB,OAAO8mB,EAAc9mB,EADLtW,KAAK69B,cACa,CACnC,CAGD1B,eACE7lB,EACA2N,GAEA,IAAM1H,EAAUvc,KAAK69B,eAErB,OADAthB,EAAQ0H,QAAUA,EACXmZ,EAAc9mB,EAAMiG,CAAO,CACnC,CAGD8f,6BAA6B/lB,GAC3B,IAAMiG,EAAUvc,KAAK69B,eAErB,OADAthB,EAAQuhB,WAAa,CAAA,EACdV,EAAc9mB,EAAMiG,CAAO,CACnC,CAGDsH,SACE,MAAO,CACLmY,aAAch8B,KAAKg8B,aACnBnX,WAAY7kB,KAAK6kB,WACjByY,aAAct9B,KAAKs9B,aAEtB,CAWDrW,gBAAgB/I,GACd,GACM,CAAE2G,WAAAA,EAAYmX,aAAAA,EAAcsB,aAAAA,CAAY,EADlB,UAAhB,OAAOpf,EAAoBpa,KAAKC,MAAMma,CAAI,EAAIA,EAG1D,OACG2G,GACAmX,GACAsB,GACDzY,IAAemX,EAKV,IAAI0F,GAAmB7c,EAAYyY,CAAY,EAH7C,IAIV,CAODqE,eAAe9c,EAAoByY,GACjC,OAAO,IAAIoE,GAAmB7c,EAAYyY,CAAY,CACvD,CAEOO,eACN,MAAO,CACLG,WAlFkB,mBAmFlBb,kBAAmB,CAAA,EACnBG,aAAct9B,KAAKs9B,aAEtB,CACF,OCnFYsE,WAAyBhC,EAKpC78B,YAAY8hB,GACV7N,EACE6N,EAAW/Z,WAdY,OAcmB,oBAG5C9E,MAAM6e,CAAU,CACjB,CAkBD+b,4BACEC,GAEA,OAAOe,GAAiBC,+BACtBhB,CAAwC,CAE3C,CAQDE,2BAA2B39B,GACzB,OAAOw+B,GAAiBC,+BACrBz+B,EAAM2C,YAAc,EAAE,CAE1B,CAMD06B,0BAA0BviB,GACxB,IAAMohB,EAAaoC,GAAmBza,SAAS/I,CAAI,EAEnD,OADAlH,EAAQsoB,EAAU,kBACXA,CACR,CAEOuC,sCAAsC,CAC5CjiB,eAAgBohB,IAEhB,GAAI,CAACA,EACH,OAAO,KAGT,GAAM,CAAE1D,aAAAA,EAAczY,WAAAA,CAAY,EAAGmc,EAErC,GAAI,CAAC1D,GAAgB,CAACzY,EACpB,OAAO,KAGT,IACE,OAAO6c,GAAmBC,QAAQ9c,EAAYyY,CAAY,CAG3D,CAFC,MAAOp6B,GACP,OAAO,IACR,CACF,CACF,OC9BY4+B,UAA4B3B,GAMvCp9B,cACEiD,oBACD,CAQDs5B,kBAAkB/2B,EAAeq1B,GAC/B,OAAOP,EAAgBE,YAAY,CACjC1Y,WAAYid,EAAoBzC,YAChCrD,aAAc8F,EAAoBC,uBAClCrE,WAAYn1B,EACZo1B,iBAAkBC,CACnB,CAAA,CACF,CAODgD,4BACEC,GAEA,OAAOiB,EAAoBT,2BACzBR,CAAwC,CAE3C,CAQDE,2BAA2B39B,GACzB,OAAO0+B,EAAoBT,2BACxBj+B,EAAM2C,YAAc,EAAE,CAE1B,CAEOs7B,kCAAkC,CACxCzhB,eAAgBohB,IAEhB,GAAI,CAACA,EACH,OAAO,KAET,GAAM,CAAEE,iBAAAA,EAAkBvD,iBAAAA,CAAkB,EAC1CqD,EACF,GAAI,CAACE,GAAoB,CAACvD,EACxB,OAAO,KAGT,IACE,OAAOmE,EAAoBxC,WAAW4B,EAAkBvD,CAAgB,CAGzE,CAFC,MACA,OAAO,IACR,CACF,EC1GIlhB,eAAeulB,GACpB1rB,EACAiG,GAEA,OAAOoC,EACLrI,EAGA,OAAA,sBAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,CD+BkBulB,EAAAC,uBAA6D,cAE7DD,EAAAzC,YAAgD,oBExDrD4C,EAQXl/B,YAAYgF,GACV/H,KAAKiiB,KAAOla,EAAOka,KACnBjiB,KAAK6kB,WAAa9c,EAAO8c,WACzB7kB,KAAK4f,eAAiB7X,EAAO6X,eAC7B5f,KAAKkiC,cAAgBn6B,EAAOm6B,aAC7B,CAED7Y,kCACE/S,EACA4rB,EACA5Y,EACAtE,EAAuB,CAAA,GAEvB,IAAM/C,EAAOhF,MAAMsK,EAAS8B,qBAC1B/S,EACAgT,EACAtE,CAAW,EAEPH,EAAasd,GAAsB7Y,CAAe,EAOxD,OANiB,IAAI2Y,EAAmB,CACtChgB,KAAAA,EACA4C,WAAAA,EACAjF,eAAgB0J,EAChB4Y,cAAAA,CACD,CAAA,CAEF,CAEDE,2BACEngB,EACAigB,EACAjpB,GAEAgE,MAAMgF,EAAK4G,yBAAyB5P,EAAuB,CAAA,CAAI,EAC/D,IAAM4L,EAAasd,GAAsBlpB,CAAQ,EACjD,OAAO,IAAIgpB,EAAmB,CAC5BhgB,KAAAA,EACA4C,WAAAA,EACAjF,eAAgB3G,EAChBipB,cAAAA,CACD,CAAA,CACF,CACF,CAED,SAASC,GACPlpB,GAEA,OAAIA,EAAS4L,aAIT,gBAAiB5L,EACK,QAGnB,KACT,OChEaopB,WACHz8B,EAKR7C,YACEuT,EACAlT,EACS8+B,EACAjgB,GAETjc,MAAM5C,EAAMyC,KAAMzC,EAAM0C,OAAO,EAHtB9F,KAAakiC,cAAbA,EACAliC,KAAIiiB,KAAJA,EAITrd,OAAOqB,eAAejG,KAAMqiC,GAAiBx9B,SAAS,EACtD7E,KAAK+F,WAAa,CAChByQ,QAASF,EAAKtT,KACdwZ,SAAUlG,EAAKkG,UAAYpX,KAAAA,EAC3ByZ,gBAAiBzb,EAAM2C,WAAY8Y,gBACnCqjB,cAAAA,EAEH,CAEDI,8BACEhsB,EACAlT,EACA8+B,EACAjgB,GAEA,OAAO,IAAIogB,GAAiB/rB,EAAMlT,EAAO8+B,EAAejgB,CAAI,CAC7D,CACF,CAEK,SAAUsgB,GACdjsB,EACA4rB,EACA5C,EACArd,GAOA,OAJgD,mBAA9CigB,EACI5C,EAAWjD,6BAA6B/lB,CAAI,EAC5CgpB,EAAWrD,oBAAoB3lB,CAAI,GAElB7M,MAAMrG,IAC3B,GAAmB,oCAAfA,EAAMyC,KACR,MAAMw8B,GAAiBC,uBACrBhsB,EACAlT,EACA8+B,EACAjgB,CAAI,EAIR,MAAM7e,CACR,CAAC,CACH,CC/DM,SAAUo/B,GACdhe,GAEA,OAAO,IAAIie,IACTje,EACGmB,IAAI,CAAA,CAAGd,WAAAA,CAAY,IAAKA,CAAU,EAClCJ,OAAOie,GAAO,CAAC,CAACA,CAAG,CAAa,CAEvC,CCOOjmB,eAAekmB,GAAO1gB,EAAY4C,GACvC,IAAMkD,EAAepd,EAAmBsX,CAAI,EAEpCqC,GADRrH,MAAM2lB,GAAoB,CAAA,EAAM7a,EAAclD,CAAU,E9CexDvO,E8CdwDyR,EAAazR,K9CerEiG,E8Cf2E,CACzE0H,QAAShH,MAAM8K,EAAa3E,WAAY,EACxCyf,eAAgB,CAAChe,EAClB,EAH4B5H,M9CiBtBP,EAGLpG,EAAkD,OAAA,sBAAAiG,CAAO,G8CpBjC,iBAK1B,IAAMumB,EAAgBN,GAAoBle,GAAoB,EAAE,EAUhE,OARAyD,EAAavD,aAAeuD,EAAavD,aAAaC,OAAOse,GAC3DD,EAAcE,IAAID,EAAGle,UAAU,CAAC,EAE7Bie,EAAcE,IAAG,WACpBjb,EAAapI,YAAc,MAG7B1C,MAAM8K,EAAazR,KAAKsR,sBAAsBG,CAAY,EACnDA,CACT,CAEOtL,eAAewmB,GACpBhhB,EACAqd,EACApd,EAAkB,CAAA,GAElB,IAAMjJ,EAAWgE,MAAM+E,EACrBC,EACAqd,EAAWnD,eAAela,EAAK3L,KAAM2G,MAAMgF,EAAKmB,WAAU,CAAE,EAC5DlB,CAAe,EAEjB,OAAO+f,EAAmBG,cAAcngB,EAA0B,OAAAhJ,CAAQ,CAC5E,CAEOwD,eAAemmB,GACpBM,EACAjhB,EACAzB,GAEAvD,MAAM6G,GAAqB7B,CAAI,EAC/B,IAEMpc,EACS,CAAA,IAAbq9B,EACG,0BACgC,mBACrClsB,EANoBwrB,GAAoBvgB,EAAKuC,YAAY,EAMrCwe,IAAIxiB,CAAQ,IAAM0iB,EAAUjhB,EAAK3L,KAAMzQ,CAAI,CACjE,CCxDO4W,eAAe0mB,GACpBlhB,EACAqd,EACApd,EAAkB,CAAA,GAElB,IAAQ5L,EAAS2L,EAAH,KACd,GAAI+G,GAAoBA,qBAAC1S,EAAK2S,GAAG,EAC/B,OAAO5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,EAGzD,IAAM4rB,EAA6C,iBAEnD,IACE,IAAMjpB,EAAWgE,MAAM+E,EACrBC,EACAsgB,GACEjsB,EACA4rB,EACA5C,EACArd,CAAI,EAENC,CAAe,EAGXkhB,GADNpsB,EAAQiC,EAASgL,QAAS3N,oBACXkL,GAAYvI,EAASgL,OAAO,GAG9BmB,GAFbpO,EAAQosB,EAAQ9sB,oBAES8sB,GAAH,IAGtB,OAFApsB,EAAQiL,EAAKkD,MAAQC,EAAS9O,EAAI,eAAA,EAE3B2rB,EAAmBG,cAAcngB,EAAMigB,EAAejpB,CAAQ,CAOtE,CANC,MAAO/V,GAKP,KAHmC,wBAA9BA,GAAqB2C,MACxBmQ,EAAMM,EAAI,iBAENpT,CACP,CACH,CCrCOuZ,eAAe4mB,GACpB/sB,EACAgpB,EACApd,EAAkB,CAAA,GAElB,IAWM2e,EAXN,OAAI7X,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,GAInD2C,EAAWgE,MAAMslB,GACrBjsB,EAF0C,SAI1CgpB,CAAU,EAENuB,EAAiB5jB,MAAMglB,EAAmB5Y,qBAC9C/S,EAP0C,SAS1C2C,CAAQ,EAGLiJ,GACHjF,MAAM3G,EAAK+a,mBAAmBwP,EAAe5e,IAAI,EAE5C4e,EACT,CAgBOpkB,eAAe6mB,GACpBhtB,EACAgpB,GAEA,OAAO+D,GAAsB/N,EAAUhf,CAAI,EAAGgpB,CAAU,CAC1D,CAaO7iB,eAAe8mB,GACpBthB,EACAqd,GAEA,IAAMvX,EAAepd,EAAmBsX,CAAI,EAI5C,OAFAhF,MAAM2lB,GAAoB,CAAA,EAAO7a,EAAcuX,EAAWza,UAAU,EAE7Doe,GAAMlb,EAAcuX,CAAU,CACvC,CAkBO7iB,eAAe+mB,GACpBvhB,EACAqd,GAEA,OAAO6D,GAAgBx4B,EAAmBsX,CAAI,EAAmBqd,CAAU,CAC7E,CC/EO7iB,eAAegnB,GACpBntB,EACAotB,GAEA,IAKM3kB,EAKAye,EAVN,OAAIxU,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,GAInD2C,EAA4BgE,MCjB3B0B,EDgBDI,EAAeuW,EAAUhf,CAAI,ECTjC,OAAA,qCAAAgG,EDUyDyC,EAAc,CACvExW,MAAOm7B,EACPvG,kBAAmB,CAAA,CACpB,CCbiC,CAAC,EDc7BK,EAAOvgB,MAAMglB,EAAmB5Y,qBACpCtK,EAAY,SAEZ9F,CAAQ,EAEVgE,MAAM8B,EAAasS,mBAAmBmM,EAAKvb,IAAI,EACxCub,EACT,OElCsBmG,GAKpB5gC,YAA+B6gC,EAAoB3qB,GAApBjZ,KAAQ4jC,SAARA,EAC7B5jC,KAAKmlB,IAAMlM,EAAS4qB,gBACpB7jC,KAAK8jC,eAAiB,IAAIz3B,KAAK4M,EAAS8qB,UAAU,EAAE1iB,cACpDrhB,KAAKqlB,YAAcpM,EAASoM,WAC7B,CAED2e,2BACE1tB,EACA2tB,GAEA,MAAI,cAAeA,EACVC,GAAyBF,oBAAoB1tB,EAAM2tB,CAAU,EAC3D,aAAcA,EAChBE,GAAwBH,oBAAoB1tB,EAAM2tB,CAAU,EAE9DjuB,EAAMM,EAAI,iBAClB,CACF,OAEY4tB,WACHP,GAKR5gC,YAAoBkW,GAClBjT,MAAK,QAAiBiT,CAAQ,EAC9BjZ,KAAK2f,YAAc1G,EAASmrB,SAC7B,CAEDJ,2BACE9H,EACA+H,GAEA,OAAO,IAAIC,GAAyBD,CAAgC,CACrE,CACF,OACYE,WACHR,GAGR5gC,YAAoBkW,GAClBjT,MAAK,OAAgBiT,CAAQ,CAC9B,CAED+qB,2BACE9H,EACA+H,GAEA,OAAO,IAAIE,GAAwBF,CAA+B,CACnE,CACF,CCjEe,SAAAI,GACd/tB,EACAiG,EACA+nB,GAEAttB,EACmC,EAAjCstB,EAAmB57B,KAAK3H,OACxBuV,EAAI,wBAGNU,EACkD,KAAA,IAAzCstB,EAAmBC,mBACsB,EAA9CD,EAAmBC,kBAAkBxjC,OACvCuV,EAAI,6BAAA,EAGNU,EAC2C,KAAA,IAAlCstB,EAAmBE,YACe,EAAvCF,EAAmBE,WAAWzjC,OAChCuV,EAAI,6BAAA,EAINiG,EAAQwiB,YAAcuF,EAAmB57B,IACzC6T,EAAQgoB,kBAAoBD,EAAmBC,kBAC/ChoB,EAAQioB,WAAaF,EAAmBE,WACxCjoB,EAAQkoB,mBAAqBH,EAAmBI,gBAE5CJ,EAAmBK,MACrB3tB,EAC2C,EAAzCstB,EAAmBK,IAAIC,SAAS7jC,OAChCuV,2BAGFiG,EAAQsoB,YAAcP,EAAmBK,IAAIC,UAG3CN,EAAmBQ,UACrB9tB,EACkD,EAAhDstB,EAAmBQ,QAAQC,YAAYhkC,OACvCuV,8BAGFiG,EAAQyoB,kBAAoBV,EAAmBQ,QAAQG,WACvD1oB,EAAQ2oB,0BACNZ,EAAmBQ,QAAQK,eAC7B5oB,EAAQ6oB,mBAAqBd,EAAmBQ,QAAQC,YAE5D,CCRAtoB,eAAe4oB,GAAsB/uB,GACnC,IAAMyI,EAAeuW,EAAUhf,CAAI,EAC/ByI,EAAamU,8BACfjW,MAAM8B,EAAaoU,uBAEvB,CAoGO1W,eAAe6oB,GACpBhvB,EACA4mB,GAEAjgB,M7B3EOP,EAHPpG,E6B8E8B3L,EAAmB2L,CAAI,E7BvEnD,OAAA,sBAAAgG,EAAmBhG,E6BuEmC,CAAE4mB,QAAAA,CAAS,C7BvEjC,CAAC,C6BwErC,CAYOzgB,eAAe8oB,GACpBjvB,EACA4mB,GAEA,IAAMsI,EAAc76B,EAAmB2L,CAAI,EACrC2C,EAAWgE,MAAMwoB,GAAsBD,EAAa,CAAEtI,QAAAA,CAAS,CAAA,EAQ/DwB,EAAYzlB,EAASysB,YAE3B,OADA1uB,EAAQ0nB,EAAW8G,oBACX9G,GACN,IAAA,eACE,MACF,IAAA,0BACE1nB,EAAQiC,EAAS0sB,SAAUH,oBAC3B,MACF,IAAA,gCACExuB,EAAQiC,EAAS2sB,QAASJ,oBAE5B,QACExuB,EAAQiC,EAASyG,MAAO8lB,mBAC3B,CAGD3kC,IAAIglC,EAA8C,KAQlD,OAPI5sB,EAAS2sB,UACXC,EAAkBlC,GAAoBK,oBACpC1O,EAAUkQ,CAAW,EACrBvsB,EAAS2sB,OAAO,GAIb,CACLp/B,KAAM,CACJkZ,OACuE,4BAApEzG,EAASysB,YACNzsB,EAAS0sB,SACT1sB,EAASyG,QAAU,KACzBomB,eACuE,4BAApE7sB,EAASysB,YACNzsB,EAASyG,MACTzG,EAAS0sB,WAAa,KAC5BE,gBAAAA,CACD,EACDnH,UAAAA,EAEJ,CCtLOjiB,eAAespB,GACpBzvB,EACAoJ,GAKA,IAAMsmB,EAAcxuB,GAAc,EAAKH,GAAc,EAAK,mBAMlD4uB,GAAkBhpB,MC5BnBP,EAHPpG,EDgCE3L,EAAmB2L,CAAI,ECzBvB,OAAA,6BAAAgG,EAAmBhG,EDmBiB,CACpC4vB,WAAYxmB,EACZsmB,YAAAA,ECrBgC,CAAC,GDwBd,cAKrB,OAAOC,GAAiB,EAC1B,CAgCOxpB,eAAe0pB,GACpBlkB,EACAqiB,GAEA,IAAMvc,EAAepd,EAAmBsX,CAAI,EAEtC1F,EAAkC,CACtCmpB,YAA6C,eAC7CzhB,QAHchH,MAAMgF,EAAKmB,cAanB1D,GARJ4kB,GACFD,GACEtc,EAAazR,KACbiG,EACA+nB,CAAkB,EAIJrnB,M7BIXwf,G6BJ2C1U,EAAazR,KAAMiG,C7BIrC,G6BJnB,MAETmD,IAAUuC,EAAKvC,OACjBzC,MAAMgF,EAAKsG,QAEf,CAoCO9L,eAAe2pB,GACpBnkB,EACA0jB,EACArB,GAEA,IAAMvc,EAAepd,EAAmBsX,CAAI,EAEtC1F,EAA2C,CAC/CmpB,YAAwD,0BACxDzhB,QAHchH,MAAMgF,EAAKmB,aAIzBuiB,SAAAA,GAUMjmB,GARJ4kB,GACFD,GACEtc,EAAazR,KACbiG,EACA+nB,CAAkB,EAIJrnB,M7BpCXwf,G6BoC0C1U,EAAazR,KAAMiG,C7BpCpC,G6BoCnB,MAETmD,IAAUuC,EAAKvC,OAGjBzC,MAAMgF,EAAKsG,QAEf,CExJO9L,eAAe4pB,GACpBpkB,EACA,CACEoD,YAAAA,EACAC,SAAUC,CAAQ,GAGpB,IAIMwC,EAQA9O,EASAqtB,EArBclhC,KAAAA,IAAhBigB,GAA0CjgB,KAAAA,IAAbmgB,IAK3BtB,EAAUhH,MADV8K,EAAepd,EAAmBsX,CAAI,GACTmB,aAO7BnK,EAAWgE,MAAM+E,EACrB+F,GC1BGtL,MACLnG,EACAiG,IAEOG,EACLpG,EAGA,OAAA,sBAAAiG,CAAO,GDmBUwL,EAAazR,KART,CACrB2N,QAAAA,EACAoB,YAAAA,EACAE,SAAAA,EACA4X,kBAAmB,CAAA,EAI+B,CAAC,EAGrDpV,EAAa1C,YAAcpM,EAASoM,aAAe,KACnD0C,EAAazC,SAAWrM,EAASsM,UAAY,MAGvC+gB,EAAmBve,EAAavD,aAAa+hB,KACjD,CAAA,CAAG1hB,WAAAA,CAAY,IAAe,aAAVA,MAGpByhB,EAAiBjhB,YAAc0C,EAAa1C,YAC5CihB,EAAiBhhB,SAAWyC,EAAazC,UAG3CrI,MAAM8K,EAAac,yBAAyB5P,CAAQ,EACtD,CAyDAwD,eAAe+pB,GACbvkB,EACAvC,EACAgP,GAEA,IAAQpY,EAAS2L,EAAH,KAER1F,EAAsC,CAC1C0H,QAFchH,MAAMgF,EAAKmB,aAGzB+Z,kBAAmB,CAAA,GAWflkB,GARFyG,IACFnD,EAAQmD,MAAQA,GAGdgP,IACFnS,EAAQmS,SAAWA,GAGJzR,MAAM+E,EACrBC,GhC5FGxF,MACLnG,EACAiG,IAEOG,EAGLpG,EAAkD,OAAA,sBAAAiG,CAAO,GgCsFlCjG,EAAMiG,CAAO,CAAC,GAEvCU,MAAMgF,EAAK4G,yBAAyB5P,EAAuB,CAAA,CAAI,CACjE,OEhFMwtB,GACJ1jC,YACW2jC,EACA7hB,EACA8hB,EAAmC,IAFnC3mC,KAAS0mC,UAATA,EACA1mC,KAAU6kB,WAAVA,EACA7kB,KAAO2mC,QAAPA,CACP,CACL,OAEKC,WAAgDH,GACpD1jC,YACE2jC,EACA7hB,EACA8hB,EACSE,GAET7gC,MAAM0gC,EAAW7hB,EAAY8hB,CAAO,EAF3B3mC,KAAQ6mC,SAARA,CAGV,CACF,OAEKC,WAAmCL,GACvC1jC,YAAY2jC,EAAoBC,GAC9B3gC,MAAM0gC,EAAgC,eAAAC,CAAO,CAC9C,CACF,OAEKI,WAAiCH,GACrC7jC,YAAY2jC,EAAoBC,GAC9B3gC,MACE0gC,EAEA,aAAAC,EAC0B,UAA1B,OAAOA,GAASK,MAAqBL,GAASK,MAAQ,IAAI,CAE7D,CACF,OAEKC,WAAiCR,GACrC1jC,YAAY2jC,EAAoBC,GAC9B3gC,MAAM0gC,EAA8B,aAAAC,CAAO,CAC5C,CACF,OAEKO,WAAkCN,GACtC7jC,YACE2jC,EACAC,EACAQ,GAEAnhC,MAAM0gC,EAAS,cAAsBC,EAASQ,CAAU,CACzD,CACF,CASK,SAAUC,GACdvG,GAEA,GAAM,CAAE5e,KAAAA,EAAMrC,eAAAA,CAAgB,EAAGihB,EACjC,GAAI5e,EAAK+C,aAAe,CAACpF,EAGvB,MAAO,CACLiF,WAAY,KACZ6hB,UAAW,CAAA,EACXC,QAAS,MAINtd,IA3HPC,EA2H4B1J,EAzH5B,GAAI,CAAC0J,EACH,OAAO,KAET,IAAQzE,EAAeyE,EAAH,WACdqd,EAAUrd,EAAgB+d,YAC5BvjC,KAAKC,MAAMulB,EAAgB+d,WAAW,EACtC,GACEX,EACJpd,EAAgBod,WACI,0CAApBpd,EAAgBge,KAClB,GAAI,CAACziB,GAAcyE,GAAiBrF,QAAS,CACrCgE,EAAiBzG,GAAY8H,EAAgBrF,OAAO,GAAGkE,UACzC,iBAEpB,GAAIF,EAOF,OANMsf,EACmC,cAAvCtf,GACoC,WAApCA,EACKA,EACD,KAEC,IAAIwe,GAA0BC,EAAWa,CAAkB,CAErE,CACD,GAAI,CAAC1iB,EACH,OAAO,KAET,OAAQA,GACN,IAAA,eACE,OAAO,IAAIiiB,GAA2BJ,EAAWC,CAAO,EAC1D,IAAA,aACE,OAAO,IAAII,GAAyBL,EAAWC,CAAO,EACxD,IAAA,aACE,OAAO,IAAIM,GAAyBP,EAAWC,CAAO,EACxD,IAAA,cACE,OAAO,IAAIO,GACTR,EACAC,EACArd,EAAgB6d,YAAc,IAAI,EAEtC,IAAuB,SACvB,IAAA,YACE,OAAO,IAAIV,GAA0BC,EAAW,IAAI,EACtD,QACE,OAAO,IAAID,GAA0BC,EAAW7hB,EAAY8hB,CAAO,CACtE,CA6EH,OCxHaa,GACXzkC,YACW0J,EACA6yB,EACArd,GAFAjiB,KAAIyM,KAAJA,EACAzM,KAAUs/B,WAAVA,EACAt/B,KAAIiiB,KAAJA,CACP,CAEJwlB,oBACExjB,EACAhC,GAEA,OAAO,IAAIulB,GAAsB,SAE/BvjB,EACAhC,CAAI,CAEP,CAEDylB,iCACEC,GAEA,OAAO,IAAIH,GAET,SAAAG,CAAoB,CAEvB,CAED9jB,SAKE,MAAO,CACL+jB,mBAAoB,EAJuB,WAA3C5nC,KAAKyM,KACD,UACA,qBAGKzM,KAAKs/B,UACb,EAEJ,CAEDrY,gBACE5e,GAEA,GAAIA,GAAKu/B,mBAAoB,CAC3B,GAAIv/B,EAAIu/B,oBAAoBC,kBAC1B,OAAOL,GAAuBE,0BAC5Br/B,EAAIu/B,mBAAmBC,iBAAiB,EAErC,GAAIx/B,EAAIu/B,oBAAoB3jB,QACjC,OAAOujB,GAAuBC,aAC5Bp/B,EAAIu/B,mBAAmB3jB,OAAO,CAGnC,CACD,OAAO,IACR,CACF,OCnDY6jB,GACX/kC,YACWglC,EACAC,EACQC,GAFRjoC,KAAO+nC,QAAPA,EACA/nC,KAAKgoC,MAALA,EACQhoC,KAAcioC,eAAdA,CAGf,CAGJC,kBACE9P,EACAh1B,GAEA,IAAMkT,EAAOgf,EAAU8C,CAAU,EAC3BxZ,EAAiBxb,EAAM2C,WAAW8Y,gBACxC,IAAMmpB,GAASppB,EAAegnB,SAAW,IAAIjgB,IAAIse,GAC/CN,GAAoBK,oBAAoB1tB,EAAM2tB,CAAU,CAAC,EAG3DjtB,EACE4H,EAAe+oB,qBACfrxB,oBAGF,IAAMyxB,EAAUP,GAAuBE,0BACrC9oB,EAAe+oB,oBAAoB,EAGrC,OAAO,IAAIG,GACTC,EACAC,EACAvrB,MACExF,IAEA,IAAMkxB,EAAclrB,MAAMhG,EAAUmxB,SAAS9xB,EAAMyxB,CAAO,EAMpDze,GAJN,OAAO1K,EAAegnB,QACtB,OAAOhnB,EAAe+oB,qBAGE,CACtB,GAAG/oB,EACHqF,QAASkkB,EAAYlkB,QACrB6B,aAAcqiB,EAAYriB,eAI5B,OAAQ1iB,EAAM8+B,eACZ,IAAA,SACE,IAAMrB,EACJ5jB,MAAMglB,EAAmB5Y,qBACvB/S,EACAlT,EAAM8+B,cACN5Y,CAAe,EAGnB,OADArM,MAAM3G,EAAK+a,mBAAmBwP,EAAe5e,IAAI,EAC1C4e,EACT,IAAA,iBAEE,OADA7pB,EAAQ5T,EAAM6e,KAAM3L,oBACb2rB,EAAmBG,cACxBh/B,EAAM6e,KACN7e,EAAM8+B,cACN5Y,CAAe,EAEnB,QACEtT,EAAMM,EAAI,iBACb,CACH,CAAC,CAEJ,CAED+xB,oBACEC,GAGA,OAAOtoC,KAAKioC,eADMK,CACkB,CACrC,CACF,CCvCe,SAAAC,GACdjyB,EACAiG,GAEA,OAAOG,EAILpG,EAGA,OAAA,mCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,OCxDaisB,GAGXzlC,YAA6Bkf,GAAAjiB,KAAIiiB,KAAJA,EAF7BjiB,KAAeyoC,gBAAsB,GAGnCxmB,EAAKyG,UAAUF,IACTA,EAASod,UACX5lC,KAAKyoC,gBAAkBjgB,EAASod,QAAQjgB,IAAIse,GAC1CN,GAAoBK,oBAAoB/hB,EAAK3L,KAAM2tB,CAAU,CAAC,EAGpE,CAAC,CACF,CAEDyE,iBAAiBzmB,GACf,OAAO,IAAIumB,GAAoBvmB,CAAI,CACpC,CAED0mB,mBACE,OAAOnB,GAAuBC,aAC5BxqB,MAAMjd,KAAKiiB,KAAKmB,WAAY,EAC5BpjB,KAAKiiB,IAAI,CAEZ,CAED2mB,aACEN,EACAjjB,GAEA,IAAMpO,EAAYqxB,EACZP,EAAW,MAAM/nC,KAAK2oC,WAAY,EAClCE,EAAsB5rB,MAAM+E,EAChChiB,KAAKiiB,KACLhL,EAAUmxB,SAASpoC,KAAKiiB,KAAK3L,KAAMyxB,EAAS1iB,CAAW,CAAC,EAQ1D,OAJApI,MAAMjd,KAAKiiB,KAAK4G,yBAAyBggB,CAAmB,EAIrD7oC,KAAKiiB,KAAKsG,QAClB,CAEDugB,eAAeC,GACb,IAAMlF,EACiB,UAArB,OAAOkF,EAAyBA,EAAYA,EAAU5jB,IACxD,ID0GF7O,EACAiG,EC3GQ0H,EAAUhH,MAAMjd,KAAKiiB,KAAKmB,WAAU,EAC1C,IACE,IAAMkG,EAAkBrM,MAAM+E,EAC5BhiB,KAAKiiB,MDuGX3L,ECtGkBtW,KAAKiiB,KAAK3L,KDuG5BiG,ECvGkC,CAC1B0H,QAAAA,EACA4f,gBAAAA,CACD,EDsGAnnB,EACLpG,EAGA,OAAA,sCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,EC1G3B,EAGJvc,KAAKyoC,gBAAkBzoC,KAAKyoC,gBAAgBhkB,OAC1C,CAAA,CAAGU,IAAAA,CAAK,IAAKA,IAAQ0e,CAAe,EAMtC5mB,MAAMjd,KAAKiiB,KAAK4G,yBAAyBS,CAAe,EACxDrM,MAAMjd,KAAKiiB,KAAKsG,QAGjB,CAFC,MAAOrlB,GACP,MAAMA,CACP,CACF,CACF,CAED,IAAM8lC,GAAuB,IAAIC,QCtE1B,IAAMC,GAAwB,cCNfC,GACpBpmC,YACqBqmC,EACV38B,GADUzM,KAAgBopC,iBAAhBA,EACVppC,KAAIyM,KAAJA,CACP,CAEJud,eACE,IACE,OAAKhqB,KAAK+pB,SAGV/pB,KAAK+pB,QAAQsf,QAAQH,GAAuB,GAAG,EAC/ClpC,KAAK+pB,QAAQuf,WAAWJ,EAAqB,EACtC7/B,QAAQC,QAAQ,CAAA,CAAI,GAJlBD,QAAQC,QAAQ,CAAA,CAAK,CAO/B,CAFC,MACA,OAAOD,QAAQC,QAAQ,CAAA,CAAK,CAC7B,CACF,CAED2gB,KAAKnjB,EAAaC,GAEhB,OADA/G,KAAK+pB,QAAQsf,QAAQviC,EAAKhD,KAAKgZ,UAAU/V,CAAK,CAAC,EACxCsC,QAAQC,SAChB,CAED4gB,KAAiCpjB,GAC/B,IAAMoX,EAAOle,KAAK+pB,QAAQwf,QAAQziC,CAAG,EACrC,OAAOuC,QAAQC,QAAQ4U,EAAOpa,KAAKC,MAAMma,CAAI,EAAI,IAAI,CACtD,CAEDiM,QAAQrjB,GAEN,OADA9G,KAAK+pB,QAAQuf,WAAWxiC,CAAG,EACpBuC,QAAQC,SAChB,CAEDygB,cACE,OAAO/pB,KAAKopC,kBACb,CACF,OC9BKI,WACIL,GAKRpmC,cACEiD,MAAM,IAAMzC,OAAOkmC,sBAGJzpC,KAAA+qB,kBAAoB,CACnC2e,EACAC,IACS3pC,KAAK4pC,eAAeF,EAAOC,CAAI,EACzB3pC,KAAS6pC,UAA8C,GACvD7pC,KAAU8pC,WAAkC,GAGrD9pC,KAAS+pC,UAAe,KAGf/pC,KAAiBgqC,kBAAGvd,KAC5BzsB,KAAqB8rB,sBAAG,CAAA,CAdhC,CAgBOme,kBACN7V,GAGA,IAAK,IAAMttB,KAAOlC,OAAO0C,KAAKtH,KAAK6pC,SAAS,EAAG,CAE7C,IAAMK,EAAWlqC,KAAK+pB,QAAQwf,QAAQziC,CAAG,EACnCqjC,EAAWnqC,KAAK8pC,WAAWhjC,GAG7BojC,IAAaC,GACf/V,EAAGttB,EAAKqjC,EAAUD,CAAQ,CAE7B,CACF,CAEON,eAAeF,EAAqBC,EAAO,CAAA,GAEjD,GAAKD,EAAM5iC,IAAX,CASA,IAAMA,EAAM4iC,EAAM5iC,IAId6iC,EAGF3pC,KAAKoqC,eAAc,EAInBpqC,KAAKqqC,YAAW,EAGlB,IAAMC,EAAmB,KAGvB,IAAMC,EAAcvqC,KAAK+pB,QAAQwf,QAAQziC,CAAG,EACvC6iC,CAAAA,GAAQ3pC,KAAK8pC,WAAWhjC,KAASyjC,GAKtCvqC,KAAKwqC,gBAAgB1jC,EAAKyjC,CAAW,CACvC,EAEMA,EAAcvqC,KAAK+pB,QAAQwf,QAAQziC,CAAG,EpDgCvCvB,EAAM,GAA4C,KAAvCtB,SAAsBwmC,coD7BpCF,IAAgBb,EAAMQ,UACtBR,EAAMQ,WAAaR,EAAMS,SAMzB3qB,WAAW8qB,EAzFqB,EAyF0B,EAE1DA,GAxCD,MANCtqC,KAAKiqC,kBACH,CAACnjC,EAAa4jC,EAA0BR,KACtClqC,KAAKwqC,gBAAgB1jC,EAAKojC,CAAQ,CACpC,CAAC,CA6CN,CAEOM,gBAAgB1jC,EAAaC,GACnC/G,KAAK8pC,WAAWhjC,GAAOC,EACvB,IAAM8iC,EAAY7pC,KAAK6pC,UAAU/iC,GACjC,GAAI+iC,EACF,IAAK,IAAMc,KAAYpqC,MAAMqqC,KAAKf,CAAS,EACzCc,EAAS5jC,GAAQjD,KAAKC,MAAMgD,CAAK,CAAS,CAG/C,CAEO8jC,eACN7qC,KAAKqqC,YAAW,EAEhBrqC,KAAK+pC,UAAYe,YAAY,KAC3B9qC,KAAKiqC,kBACH,CAACnjC,EAAaqjC,EAAyBD,KACrClqC,KAAK4pC,eACH,IAAImB,aAAa,UAAW,CAC1BjkC,IAAAA,EACAqjC,SAAAA,EACAD,SAAAA,EACD,EACU,CAAA,CAAI,CAEnB,CAAC,CAEJ,EA5H+B,GA4HT,CACxB,CAEOG,cACFrqC,KAAK+pC,YACPiB,cAAchrC,KAAK+pC,SAAS,EAC5B/pC,KAAK+pC,UAAY,KAEpB,CAEOkB,iBACN1nC,OAAOm0B,iBAAiB,UAAW13B,KAAK+qB,iBAAiB,CAC1D,CAEOqf,iBACN7mC,OAAOq0B,oBAAoB,UAAW53B,KAAK+qB,iBAAiB,CAC7D,CAEDX,aAAatjB,EAAa6jC,GACmB,IAAvC/lC,OAAO0C,KAAKtH,KAAK6pC,SAAS,EAAE9oC,SAK1Bf,KAAKgqC,kBACPhqC,KAAK6qC,aAAY,EAEjB7qC,KAAKirC,eAAc,GAGlBjrC,KAAK6pC,UAAU/iC,KAClB9G,KAAK6pC,UAAU/iC,GAAO,IAAI27B,IAE1BziC,KAAK8pC,WAAWhjC,GAAO9G,KAAK+pB,QAAQwf,QAAQziC,CAAG,GAEjD9G,KAAK6pC,UAAU/iC,GAAK40B,IAAIiP,CAAQ,CACjC,CAEDpgB,gBAAgBzjB,EAAa6jC,GACvB3qC,KAAK6pC,UAAU/iC,KACjB9G,KAAK6pC,UAAU/iC,GAAKiiB,OAAO4hB,CAAQ,EAEF,IAA7B3qC,KAAK6pC,UAAU/iC,GAAK2wB,OACtB,OAAOz3B,KAAK6pC,UAAU/iC,GAIiB,IAAvClC,OAAO0C,KAAKtH,KAAK6pC,SAAS,EAAE9oC,SAC9Bf,KAAKoqC,eAAc,EACnBpqC,KAAKqqC,YAAW,EAEnB,CAIDpgB,WAAWnjB,EAAaC,GACtBkW,MAAMjX,MAAMikB,KAAKnjB,EAAKC,CAAK,EAC3B/G,KAAK8pC,WAAWhjC,GAAOhD,KAAKgZ,UAAU/V,CAAK,CAC5C,CAEDmjB,WAAuCpjB,GACrC,IAAMC,EAAQkW,MAAMjX,MAAMkkB,KAAQpjB,CAAG,EAErC,OADA9G,KAAK8pC,WAAWhjC,GAAOhD,KAAKgZ,UAAU/V,CAAK,EACpCA,CACR,CAEDojB,cAAcrjB,GACZmW,MAAMjX,MAAMmkB,QAAQrjB,CAAG,EACvB,OAAO9G,KAAK8pC,WAAWhjC,EACxB,EAxLM0iC,GAAI/8B,KAAY,QAiMlB,IAAMy+B,GAAuC1B,SC7M9C2B,WACIhC,GAKRpmC,cACEiD,MAAM,IAAMzC,OAAO6nC,yBACpB,CAEDhhB,aAAaC,EAAcC,IAK3BC,gBAAgBF,EAAcC,KAXvB6gB,GAAI1+B,KAAc,UAuBpB,IAAM4+B,GAAyCF,SCtBzCG,GAUXvoC,YAA6BwoC,GAAAvrC,KAAWurC,YAAXA,EANZvrC,KAAWwrC,YAIxB,GAGFxrC,KAAK+qB,kBAAoB/qB,KAAKyrC,YAAYnhC,KAAKtK,IAAI,CACpD,CAQD0pB,oBAAoB6hB,GAIlB,IAAMG,EAAmB1rC,KAAK2rC,UAAUpF,KAAKqF,GAC3CA,EAASC,cAAcN,CAAW,CAAC,EAErC,OAAIG,IAGEI,EAAc,IAAIR,GAASC,CAAW,EAC5CvrC,KAAK2rC,UAAUpqC,KAAKuqC,CAAW,EACxBA,EACR,CAEOD,cAAcN,GACpB,OAAOvrC,KAAKurC,cAAgBA,CAC7B,CAYOE,kBAGN/B,GACA,IAAMqC,EAAerC,EACf,CAAEsC,QAAAA,EAASC,UAAAA,EAAWzlC,KAAAA,CAAI,EAAKulC,EAAavlC,KAElD,IAAM0lC,EACJlsC,KAAKwrC,YAAYS,GACdC,GAAUzU,OAIfsU,EAAaI,MAAM,GAAGC,YAAY,CAChCzd,OAAmB,MACnBqd,QAAAA,EACAC,UAAAA,CACD,CAAA,EAEKI,EAAW9rC,MAAMqqC,KAAKsB,CAAQ,EAAEvmB,IAAIlJ,MAAM6vB,GAC9CA,EAAQP,EAAaQ,OAAQ/lC,CAAI,CAAC,EAE9ByS,EAAWgE,MC7DZ5T,QAAQqiB,ID6DsB2gB,EC5D1B1mB,IAAIlJ,MAAMwB,IACjB,IAEE,MAAO,CACLuuB,UAAW,CAAA,EACXzlC,MAHYkW,MAAMgB,EAUrB,CALC,MAAOwuB,GACP,MAAO,CACLD,UAAW,CAAA,EACXC,OAAAA,EAEH,CACF,CAAA,CAAC,EDgDFV,EAAaI,MAAM,GAAGC,YAAY,CAChCzd,OAAoB,OACpBqd,QAAAA,EACAC,UAAAA,EACAhzB,SAAAA,CACD,CAAA,EACF,CASDyzB,WACET,EACAU,GAE6C,IAAzC/nC,OAAO0C,KAAKtH,KAAKwrC,WAAW,EAAEzqC,QAChCf,KAAKurC,YAAY7T,iBAAiB,UAAW13B,KAAK+qB,iBAAiB,EAGhE/qB,KAAKwrC,YAAYS,KACpBjsC,KAAKwrC,YAAYS,GAAa,IAAIxJ,KAGpCziC,KAAKwrC,YAAYS,GAAWvQ,IAAIiR,CAAY,CAC7C,CASDC,aACEX,EACAU,GAEI3sC,KAAKwrC,YAAYS,IAAcU,GACjC3sC,KAAKwrC,YAAYS,GAAWljB,OAAO4jB,CAAY,EAE5CA,GAAqD,IAArC3sC,KAAKwrC,YAAYS,GAAWxU,MAC/C,OAAOz3B,KAAKwrC,YAAYS,GAGmB,IAAzCrnC,OAAO0C,KAAKtH,KAAKwrC,WAAW,EAAEzqC,QAChCf,KAAKurC,YAAY3T,oBAAoB,UAAW53B,KAAK+qB,iBAAiB,CAEzE,EEzIG,SAAU8hB,GAAiB9W,EAAS,GAAI+W,EAAS,IACrDjsC,IAAIo1B,EAAS,GACb,IAAKp1B,IAAIC,EAAI,EAAGA,EAAIgsC,EAAQhsC,CAAC,GAC3Bm1B,GAAU/d,KAAK8d,MAAsB,GAAhB9d,KAAK+d,OAAM,CAAO,EAEzC,OAAOF,EAASE,CAClB,CFS0BqV,GAASK,UAAe,SGOrCoB,GAGXhqC,YAA6BiqC,GAAAhtC,KAAMgtC,OAANA,EAFZhtC,KAAAksC,SAAW,IAAIzJ,GAEsB,CAO9CwK,qBAAqBX,GACvBA,EAAQY,iBACVZ,EAAQY,eAAeC,MAAMvV,oBAC3B,UACA0U,EAAQc,SAAS,EAEnBd,EAAQY,eAAeC,MAAMtjC,SAE/B7J,KAAKksC,SAASnjB,OAAOujB,CAAO,CAC7B,CAeDe,YACEpB,EACAzlC,EACA8M,EAA8B,IAE9B,IAAM45B,EACsB,aAA1B,OAAOI,eAAiC,IAAIA,eAAmB,KACjE,GAAI,CAACJ,EACH,MAAM,IAAIzsC,MAAK,0BAMjBI,IAAI0sC,EACAjB,EACJ,OAAO,IAAIjjC,QAAqC,CAACC,EAASiW,KACxD,IAAMysB,EAAUa,GAAiB,GAAI,EAAE,EAEjCW,GADNN,EAAeC,MAAMM,QACJjuB,WAAW,KAC1BD,EAAO,IAAI9e,MAAK,mBAAA,CAAiC,CAClD,EAAE6S,CAAO,GACVg5B,EAAU,CACRY,eAAAA,EACAE,UAAU1D,GACR,IAAMqC,EAAerC,EACrB,GAAIqC,EAAavlC,KAAKwlC,UAAYA,EAGlC,OAAQD,EAAavlC,KAAKmoB,QACxB,IAAA,MAEEtP,aAAamuB,CAAQ,EACrBD,EAAkB/tB,WAAW,KAC3BD,EAAO,IAAI9e,MAAK,SAAA,CAAuB,CACxC,OACD,MACF,IAAA,OAEE4e,aAAakuB,CAAe,EAC5BjkC,EAAQyiC,EAAavlC,KAAKyS,QAAQ,EAClC,MACF,QACEoG,aAAamuB,CAAQ,EACrBnuB,aAAakuB,CAAe,EAC5BhuB,EAAO,IAAI9e,MAAK,kBAAA,CAAgC,CAEnD,CACF,GAEHT,KAAKksC,SAASxQ,IAAI4Q,CAAO,EACzBY,EAAeC,MAAMzV,iBAAiB,UAAW4U,EAAQc,SAAS,EAClEptC,KAAKgtC,OAAOZ,YACV,CACEH,UAAAA,EACAD,QAAAA,EACAxlC,KAAAA,CACwB,EAC1B,CAAC0mC,EAAeQ,MAAM,CAE1B,CAAC,EAAEC,QAAQ,KACLrB,GACFtsC,KAAKitC,qBAAqBX,CAAO,CAErC,CAAC,CACF,CACF,CChGe,SAAAsB,IACd,OAAOrqC,MACT,CC1BgB,SAAAsqC,KACd,OAC4C,KAAA,IAAnCD,EAAO,EAAsB,mBACE,YAAtC,OAAOA,EAAS,EAAgB,aAEpC,CCmBO,IAAME,GAAU,yBAEjBC,GAAsB,uBACtBC,GAAkB,kBAalBC,GACJlrC,YAA6BwZ,GAAAvc,KAAOuc,QAAPA,CAAuB,CAEpD2xB,YACE,OAAO,IAAI7kC,QAAW,CAACC,EAASiW,KAC9Bvf,KAAKuc,QAAQmb,iBAAiB,UAAW,KACvCpuB,EAAQtJ,KAAKuc,QAAQoV,MAAM,CAC7B,CAAC,EACD3xB,KAAKuc,QAAQmb,iBAAiB,QAAS,KACrCnY,EAAOvf,KAAKuc,QAAQnZ,KAAK,CAC3B,CAAC,CACH,CAAC,CACF,CACF,CAED,SAAS+qC,GAAeC,EAAiBC,GACvC,OAAOD,EACJE,YAAY,CAACP,IAAsBM,EAAc,YAAc,UAAU,EACzEE,YAAYR,EAAmB,CACpC,CAYgB,SAAAS,KACd,IAAMjyB,EAAU5W,UAAU8oC,KAAKX,GA/Cd,CA+CiC,EAClD,OAAO,IAAIzkC,QAAQ,CAACC,EAASiW,KAC3BhD,EAAQmb,iBAAiB,QAAS,KAChCnY,EAAOhD,EAAQnZ,KAAK,CACtB,CAAC,EAEDmZ,EAAQmb,iBAAiB,gBAAiB,KACxC,IAAM0W,EAAK7xB,EAAQoV,OAEnB,IACEyc,EAAGM,kBAAkBX,GAAqB,CAAEY,QAASX,EAAiB,CAAA,CAGvE,CAFC,MAAO9qC,GACPqc,EAAOrc,CAAC,CACT,CACH,CAAC,EAEDqZ,EAAQmb,iBAAiB,UAAWjb,UAClC,IAAM2xB,EAAkB7xB,EAAQoV,OAM3Byc,EAAGQ,iBAAiBC,SAASd,EAAmB,EAMnDzkC,EAAQ8kC,CAAE,GAJVA,EAAGvkC,MAAK,EA9BR0S,EAAU5W,UAAUmpC,eAAehB,EAAO,EA+B1C7wB,MA9BC,IAAIgxB,GAAgB1xB,CAAO,EAAE2xB,UAAS,EA+BvC5kC,EAAQ2T,MAAMuxB,GAAa,CAAE,EAIjC,CAAC,CACH,CAAC,CACH,CAEO/xB,eAAesyB,GACpBX,EACAtnC,EACAC,GAEA,IAAMwV,EAAU4xB,GAAeC,EAAI,CAAA,CAAI,EAAEY,IAAI,CAC3CC,UAAmBnoC,EACnBC,MAAAA,CACD,CAAA,EACD,OAAO,IAAIknC,GAAgB1xB,CAAO,EAAE2xB,UAAS,CAC/C,CAWgB,SAAAgB,GAAcd,EAAiBtnC,GAC7C,IAAMyV,EAAU4xB,GAAeC,EAAI,CAAA,CAAI,EAAErlB,OAAOjiB,CAAG,EACnD,OAAO,IAAImnC,GAAgB1xB,CAAO,EAAE2xB,UAAS,CAC/C,OAKMiB,GAqBJpsC,cAlBA/C,KAAAyM,KAA6B,QAEpBzM,KAAqB8rB,sBAAG,CAAA,EAEhB9rB,KAAS6pC,UAA8C,GACvD7pC,KAAU8pC,WAA4C,GAG/D9pC,KAAS+pC,UAAe,KACxB/pC,KAAaovC,cAAG,EAEhBpvC,KAAQ4rC,SAAoB,KAC5B5rC,KAAMqvC,OAAkB,KACxBrvC,KAA8BsvC,+BAAG,CAAA,EACjCtvC,KAAmBuvC,oBAAyB,KAMlDvvC,KAAKwvC,6BACHxvC,KAAKyvC,iCAAgC,EAAGjmC,KACtC,OACA,MAAQ,CAEb,CAEDkmC,gBAKE,OAJI1vC,KAAKouC,KAGTpuC,KAAKouC,GAAKnxB,MAAMuxB,MACTxuC,KAAKouC,EACb,CAEDuB,mBAAsBC,GACpB/uC,IAAIgvC,EAAc,EAElB,OACE,IAEE,OAAO5yB,MAAM2yB,EADF3yB,MAAMjd,KAAK0vC,SACJ,CAUnB,CATC,MAAOxsC,GACP,GAhDgC,EAgD5B2sC,CAAW,GACb,MAAM3sC,EAEJlD,KAAKouC,KACPpuC,KAAKouC,GAAGvkC,QACR7J,KAAKouC,GAAKhpC,KAAAA,EAGb,CAEJ,CAMOqqC,yCACN,OAAO5B,GAAW,EAAG7tC,KAAK8vC,mBAAkB,EAAK9vC,KAAK+vC,kBACvD,CAKOD,2BACN9vC,KAAK4rC,SAAWN,GAAS5hB,aDtLpBmkB,GAAS,EAAMvqC,KAAoC,ICsLM,EAE9DtD,KAAK4rC,SAASc,WAAU,aAEtBjwB,MAAOuzB,EAAiBxpC,KAEf,CACLypC,cAFWhzB,MAAMjd,KAAKkwC,SAEH1oC,SAAShB,EAAKM,GAAG,GAEvC,EAGH9G,KAAK4rC,SAASc,WAAU,OAEtBjwB,MAAOuzB,EAAiBG,IACf,cACR,CAEJ,CASOJ,yBAGN,IAKMK,EANNpwC,KAAKuvC,oBAAsBtyB,MDpOxBR,UACL,GAAI,CAAChY,WAAW4rC,cACd,OAAO,KAET,IAEE,OADqBpzB,MAAMxY,UAAU4rC,cAAcvZ,OAC/BwZ,MAGrB,CAFC,MACA,OAAO,IACR,CACH,KC2NStwC,KAAKuvC,sBAGVvvC,KAAKqvC,OAAS,IAAItC,GAAO/sC,KAAKuvC,mBAAmB,EAE3Ca,EAAUnzB,MAAMjd,KAAKqvC,OAAOhC,MAAK,OAErC,GAAE,OAOF+C,EAAQ,IAAI5D,WACZ4D,EAAQ,IAAIrpC,MAAMS,SAAgC,YAAA,IAElDxH,KAAKsvC,+BAAiC,CAAA,EAEzC,CAWOiB,0BAA0BzpC,GAChC,GACG9G,KAAKqvC,QACLrvC,KAAKuvC,sBDzPH9qC,WAAW4rC,eAAeG,YAAc,QC0PTxwC,KAAKuvC,oBAIzC,IACEtyB,MAAMjd,KAAKqvC,OAAOhC,MAEhB,aAAA,CAAEvmC,IAAAA,CAAK,EAEP9G,KAAKsvC,+BACF,IACA,GAIN,CAFC,OAGH,CAEDtlB,qBACE,IACE,IAGMokB,EAHN,OAAKzoC,WAILsX,MAAM8xB,GADAX,EAAKnxB,MAAMuxB,KACItF,GAAuB,GAAG,EAC/CjsB,MAAMiyB,GAAcd,EAAIlF,EAAqB,EACtC,CAAA,GALE,CAAA,CAMD,CAAR,OACF,MAAO,CAAA,CACR,CAEOuH,wBAAwBC,GAC9B1wC,KAAKovC,aAAa,GAClB,IACEnyB,MAAMyzB,EAAK,CAGZ,CAFS,QACR1wC,KAAKovC,aAAa,EACnB,CACF,CAEDnlB,WAAWnjB,EAAaC,GACtB,OAAO/G,KAAKywC,kBAAkBh0B,UAC5BQ,MAAMjd,KAAK2vC,aAAa,GAAqBZ,GAAWX,EAAItnC,EAAKC,CAAK,CAAC,EACvE/G,KAAK8pC,WAAWhjC,GAAOC,EAChB/G,KAAKuwC,oBAAoBzpC,CAAG,EACpC,CACF,CAEDojB,WAAuCpjB,GACrC,IAAMuB,EAAG,MAAUrI,KAAK2vC,aAAa,IAxMzClzB,MACE2xB,EACAtnC,KAEA,IAAMyV,EAAU4xB,GAAeC,EAAI,CAAA,CAAK,EAAEp2B,IAAIlR,CAAG,EAEjD,OAAgB1B,KAAAA,KAAToB,EADMyW,MAAM,IAAIgxB,GAAgC1xB,CAAO,EAAE2xB,UAAS,GAC7C,KAAO1nC,EAAKO,KAC1C,GAkMgBqnC,EAAItnC,CAAG,CAAC,EAGpB,OADA9G,KAAK8pC,WAAWhjC,GAAOuB,CAExB,CAED8hB,cAAcrjB,GACZ,OAAO9G,KAAKywC,kBAAkBh0B,UAC5BQ,MAAMjd,KAAK2vC,aAAa,GAAqBT,GAAcd,EAAItnC,CAAG,CAAC,EACnE,OAAO9G,KAAK8pC,WAAWhjC,GAChB9G,KAAKuwC,oBAAoBzpC,CAAG,EACpC,CACF,CAEOopC,cAEN,IAAMve,EAAS1U,MAAMjd,KAAK2vC,aAAa,IACrC,IAAMgB,EAAgBxC,GAAeC,EAAI,CAAA,CAAK,EAAEwC,OAAM,EACtD,OAAO,IAAI3C,GAA6B0C,CAAa,EAAEzC,UAAS,CAClE,CAAC,EAED,GAAI,CAACvc,EACH,MAAO,GAIT,GAA2B,IAAvB3xB,KAAKovC,cACP,MAAO,GAGT,IAYWyB,EAZLvpC,EAAO,GACPwpC,EAAe,IAAIrO,IACzB,GAAsB,IAAlB9Q,EAAO5wB,OACT,IAAK,GAAM,CAAEkuC,UAAWnoC,EAAKC,MAAAA,CAAK,IAAM4qB,EACtCmf,EAAapV,IAAI50B,CAAG,EAChBhD,KAAKgZ,UAAU9c,KAAK8pC,WAAWhjC,EAAI,IAAMhD,KAAKgZ,UAAU/V,CAAK,IAC/D/G,KAAKwqC,gBAAgB1jC,EAAKC,CAAyB,EACnDO,EAAK/F,KAAKuF,CAAG,GAKnB,IAAW+pC,KAAYjsC,OAAO0C,KAAKtH,KAAK8pC,UAAU,EAC5C9pC,KAAK8pC,WAAW+G,IAAa,CAACC,EAAa9N,IAAI6N,CAAQ,IAEzD7wC,KAAKwqC,gBAAgBqG,EAAU,IAAI,EACnCvpC,EAAK/F,KAAKsvC,CAAQ,GAGtB,OAAOvpC,CACR,CAEOkjC,gBACN1jC,EACAojC,GAEAlqC,KAAK8pC,WAAWhjC,GAAOojC,EACvB,IAAML,EAAY7pC,KAAK6pC,UAAU/iC,GACjC,GAAI+iC,EACF,IAAK,IAAMc,KAAYpqC,MAAMqqC,KAAKf,CAAS,EACzCc,EAAST,CAAQ,CAGtB,CAEOW,eACN7qC,KAAKqqC,YAAW,EAEhBrqC,KAAK+pC,UAAYe,YACfruB,SAAYzc,KAAKkwC,MAAK,EAhQQ,GAiQV,CAEvB,CAEO7F,cACFrqC,KAAK+pC,YACPiB,cAAchrC,KAAK+pC,SAAS,EAC5B/pC,KAAK+pC,UAAY,KAEpB,CAED3f,aAAatjB,EAAa6jC,GACmB,IAAvC/lC,OAAO0C,KAAKtH,KAAK6pC,SAAS,EAAE9oC,QAC9Bf,KAAK6qC,aAAY,EAEd7qC,KAAK6pC,UAAU/iC,KAClB9G,KAAK6pC,UAAU/iC,GAAO,IAAI27B,IAErBziC,KAAKkqB,KAAKpjB,CAAG,GAEpB9G,KAAK6pC,UAAU/iC,GAAK40B,IAAIiP,CAAQ,CACjC,CAEDpgB,gBAAgBzjB,EAAa6jC,GACvB3qC,KAAK6pC,UAAU/iC,KACjB9G,KAAK6pC,UAAU/iC,GAAKiiB,OAAO4hB,CAAQ,EAEF,IAA7B3qC,KAAK6pC,UAAU/iC,GAAK2wB,OACtB,OAAOz3B,KAAK6pC,UAAU/iC,GAIiB,IAAvClC,OAAO0C,KAAKtH,KAAK6pC,SAAS,EAAE9oC,QAC9Bf,KAAKqqC,YAAW,CAEnB,EAhSM8E,GAAI1iC,KAAY,QAySlB,IAAMskC,GAAyC5B,GClYtC,SAAA6B,GACd16B,EACAiG,GAEA,OAAOG,EAILpG,EAGA,OAAA,+BAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CAErC,CClDO,IAAM00B,GAAmBC,GAAgC,KAAK,EAC/DC,GAAwB,IAAIx5B,GAAM,IAAO,GAAK,QAgBvCy5B,GAAbruC,cACU/C,KAAYqxC,aAAG,GACfrxC,KAAOm2B,QAAG,EAMDn2B,KAAuBsxC,wBAAG,CAAC,CAAC1D,EAAO,EAAG9tB,YAAYuW,MAqEpE,CAnECkb,KAAKj7B,EAAoBk7B,EAAK,IAqEhC,IAA6BA,EAlEzB,OAFAx6B,GAoEyBw6B,EApEGA,GAqEpBzwC,QAAU,GAAK,yBAAyBgX,KAAKy5B,CAAE,EArEtBl7B,oBAE7BtW,KAAKyxC,yBAAyBD,CAAE,GAAK3xB,GAAK+tB,EAAO,EAAG9tB,UAAU,EACzDzW,QAAQC,QAAQskC,EAAS,EAAC9tB,UAAwB,EAEpD,IAAIzW,QAAmB,CAACC,EAASiW,KACtC,IAAMzB,EAAiB8vB,IAAUpuB,WAAW,KAC1CD,EAAOnJ,EAAaE,EAAI,wBAAuC,CAAA,CACjE,EAAG66B,GAAsBn5B,IAAG,CAAE,EAE9B41B,EAAS,EAACqD,IAAoB,KAC5BrD,EAAS,EAACvuB,aAAavB,CAAc,EACrC,OAAO8vB,EAAO,EAAGqD,IAEjB,IAAMS,EAAY9D,EAAS,EAAC9tB,WAE5B,GAAK4xB,GAAc7xB,GAAK6xB,CAAS,EAAjC,CAOA,IAAMrb,EAASqb,EAAUrb,OACzBqb,EAAUrb,OAAS,CAACC,EAAWvuB,KAC7B,IAAM4pC,EAAWtb,EAAOC,EAAWvuB,CAAM,EAEzC,OADA/H,KAAKm2B,OAAO,GACLwb,CACT,EAEA3xC,KAAKqxC,aAAeG,EACpBloC,EAAQooC,CAAS,CAZhB,MAFCnyB,EAAOnJ,EAAaE,EAAI,gBAA+B,CAAA,CAe3D,EAQAs7B,GxDvDGpc,GAAmBE,kBwDiDV,IAAwC7tB,GAAY,CAC9DgqC,OAAQZ,GACR5a,OAAQ,WACRmb,GAAAA,CACD,CAAA,CAEoB,EAAE/nC,MAAM,KAC3B4V,aAAavB,CAAc,EAC3ByB,EAAOnJ,EAAaE,EAAI,gBAA+B,CAAA,CACzD,CAAC,CACH,CAAC,CACF,CAEDw7B,qBACE9xC,KAAKm2B,OAAO,EACb,CAEOsb,yBAAyBD,GAQ/B,MACE,CAAC,CAAC5D,IAAU9tB,YAAYuW,SACvBmb,IAAOxxC,KAAKqxC,cACI,EAAfrxC,KAAKm2B,SACLn2B,KAAKsxC,wBAEV,CACF,OAMYS,GACXR,WAAWj7B,GACT,OAAO,IAAI4f,GAAc5f,CAAI,CAC9B,CAEDw7B,sBACD,CCtGM,IAAME,GAA0B,YAEjCC,GAAsC,CAC1CC,MAAO,QACPzlC,KAAM,eAaK0lC,GAuCXpvC,YACEq1B,EACAjB,EACiBZ,EAAkC,CACjD,GAAG0b,EACJ,GAFgBjyC,KAAUu2B,WAAVA,EAnCVv2B,KAAIyM,KAAGulC,GACRhyC,KAASoyC,UAAG,CAAA,EACZpyC,KAAQ2xC,SAAkB,KAGjB3xC,KAAAqyC,qBAAuB,IAAI5P,IACpCziC,KAAasyC,cAA2B,KAKxCtyC,KAAS0xC,UAAqB,KA4BpC1xC,KAAKsW,KAAOgf,EAAU8C,CAAU,EAChCp4B,KAAKuyC,YAAuC,cAAzBvyC,KAAKu2B,WAAWkB,KACnCzgB,EACsB,aAApB,OAAO/S,SACPjE,KAAKsW,KAAI,+CAGX,IAAMggB,EACqB,UAAzB,OAAOa,EACHlzB,SAASszB,eAAeJ,CAAa,EACrCA,EACNngB,EAAQsf,EAAWt2B,KAAKsW,uBAExBtW,KAAKs2B,UAAYA,EACjBt2B,KAAKu2B,WAAWnpB,SAAWpN,KAAKwyC,kBAAkBxyC,KAAKu2B,WAAWnpB,QAAQ,EAE1EpN,KAAKyyC,iBACD,IADoBzyC,KAAKsW,KAAKma,SAASC,kCACnCqhB,GACAX,IAERpxC,KAAK0yC,sBAAqB,CAE3B,CAODra,eACEr4B,KAAK2yC,mBAAkB,EACvB,IAAMttC,EAAK4X,MAAMjd,KAAKq2B,SAChBqb,EAAY1xC,KAAK4yC,uBAEvB,IAAM35B,EAAWy4B,EAAU3xB,YAAY1a,CAAE,EACzC,OAAI4T,GAIG,IAAI5P,QAAgBC,IACzB,IAAMupC,EAAc,IACbtqC,IAGLvI,KAAKqyC,qBAAqBtpB,OAAO8pB,CAAW,EAC5CvpC,EAAQf,CAAK,EACf,EAEAvI,KAAKqyC,qBAAqB3W,IAAImX,CAAW,EACrC7yC,KAAKuyC,aACPb,EAAU/a,QAAQtxB,CAAE,CAExB,CAAC,CACF,CAODgxB,SACE,IACEr2B,KAAK2yC,mBAAkB,CAMxB,CALC,MAAOzvC,GAIP,OAAOmG,QAAQkW,OAAOrc,CAAC,CACxB,CAWD,OATIlD,KAAKsyC,gBAITtyC,KAAKsyC,cAAgBtyC,KAAK8yC,kBAAiB,EAAGrpC,MAAMvG,IAElD,MADAlD,KAAKsyC,cAAgB,KACfpvC,CACR,CAAC,GAEMlD,KAAKsyC,aACb,CAGDS,SACE/yC,KAAK2yC,mBAAkB,EACD,OAAlB3yC,KAAK2xC,UACP3xC,KAAK4yC,qBAAsB,EAACnc,MAAMz2B,KAAK2xC,QAAQ,CAElD,CAKDqB,QACEhzC,KAAK2yC,mBAAkB,EACvB3yC,KAAKoyC,UAAY,CAAA,EACjBpyC,KAAKyyC,iBAAiBX,qBACjB9xC,KAAKuyC,aACRvyC,KAAKs2B,UAAU2c,WAAWhrC,QAAQirC,IAChClzC,KAAKs2B,UAAU6c,YAAYD,CAAI,CACjC,CAAC,CAEJ,CAEOR,wBACN17B,EAAQ,CAAChX,KAAKu2B,WAAW6c,QAASpzC,KAAKsW,KAAI,kBAC3CU,EACEhX,KAAKuyC,aAAe,CAACvyC,KAAKs2B,UAAU+c,cAAa,EACjDrzC,KAAKsW,uBAGPU,EACsB,aAApB,OAAO/S,SACPjE,KAAKsW,KAAI,8CAGZ,CAEOk8B,kBACNc,GAEA,OAAO/qC,IAEL,IAGQgrC,EAJRvzC,KAAKqyC,qBAAqBpqC,QAAQ0iC,GAAYA,EAASpiC,CAAK,CAAC,EACrC,YAApB,OAAO+qC,EACTA,EAAS/qC,CAAK,EACe,UAApB,OAAO+qC,GAEU,YAAtB,OADEC,EAAa3F,IAAU0F,KAE3BC,EAAWhrC,CAAK,CAGtB,CACD,CAEOoqC,qBACN37B,EAAQ,CAAChX,KAAKoyC,UAAWpyC,KAAKsW,KAAI,iBACnC,CAEOw8B,0BAEN,GADA71B,MAAMjd,KAAKwzC,OACP,CAACxzC,KAAK2xC,SAAU,CAClB9wC,IAAIy1B,EAAYt2B,KAAKs2B,UACrB,IACQmd,EADHzzC,KAAKuyC,cACFkB,EAAkBxvC,SAAS02B,cAAc,KAAK,EACpDrE,EAAUqF,YAAY8X,CAAe,EACrCnd,EAAYmd,GAGdzzC,KAAK2xC,SAAW3xC,KAAK4yC,qBAAoB,EAAGvc,OAC1CC,EACAt2B,KAAKu2B,UAAU,CAElB,CAED,OAAOv2B,KAAK2xC,QACb,CAEO6B,aACNx8B,EACEQ,GAAc,GAAM,CAACq2B,GAAW,EAChC7tC,KAAKsW,KAAI,kBAIX2G,MAiBJ,KACEpc,IAAIkzB,EAAgC,KACpC,OAAO,IAAI1qB,QAAcC,IACK,aAAxBrF,SAAS43B,WACXvyB,KAOFyqB,EAAW,IAAMzqB,IACjB/F,OAAOm0B,iBAAiB,OAAQ3D,CAAQ,EAC1C,CAAC,EAAEtqB,MAAMvG,IAKP,MAJI6wB,GACFxwB,OAAOq0B,oBAAoB,OAAQ7D,CAAQ,EAGvC7wB,CACR,CAAC,CACH,GArCkB,EACdlD,KAAK0xC,UAAYz0B,MAAMjd,KAAKyyC,iBAAiBlB,KAC3CvxC,KAAKsW,KACLtW,KAAKsW,KAAK8G,cAAgBhY,KAAAA,CAAS,EAGrC,IAAM+a,EAAUlD,O7E1OhB,MACQP,E6EyOiC1c,KAAKsW,K7ErO3C,MAAA,qBAAA,GACDo9B,kBAAoB,I6EqOtB18B,EAAQmJ,EAASngB,KAAKsW,uBACtBtW,KAAKu2B,WAAW6c,QAAUjzB,CAC3B,CAEOyyB,uBAEN,OADA57B,EAAQhX,KAAK0xC,UAAW1xC,KAAKsW,KAAI,gBAAA,EAC1BtW,KAAK0xC,SACb,CACF,OCpMKiC,GACJ5wC,YACWs7B,EACQuV,GADR5zC,KAAcq+B,eAAdA,EACQr+B,KAAc4zC,eAAdA,CACf,CAEJC,QAAQvV,GACN,IAAMwV,EAAiB3V,GAAoBC,kBACzCp+B,KAAKq+B,eACLC,CAAgB,EAElB,OAAOt+B,KAAK4zC,eAAeE,CAAc,CAC1C,CACF,CAqIMr3B,eAAes3B,GACpBz9B,EACAuQ,EACAgS,GAEA,GAAI,CAACviB,EAAK2c,sBACR,IxDkHIlU,EAAeuW,EwDjHgBhf,CxDiHF,EAE7B2C,EAAWgE,MAAM4D,GAAmB9B,EAAc,CACtDwZ,WAAmC,kBACnCC,QAAoC,sBACrC,CAAA,EAEKngB,EAAS,IAAI6H,GAAgBjH,CAAQ,EACd,MAAzB8F,EAAavC,SACfuC,EAAaoR,sBAAwB9X,EAErC0G,EAAaqR,wBAAwBrR,EAAavC,UAAYnE,EwD5H5D4E,MxD+HA5E,CAAAA,EAAOuI,wBAEJiY,CADY,IAAIV,GAA4BpZ,CAAY,EAC/CsZ,SwDxHb,CARC,MAAOj1B,GAKPD,QAAQyS,IACN,6FAA6F,CAEhG,CxDuGE6G,IACCsC,EAEA9F,EwD3FI8uB,EASEiM,EAqDAnQ,EAKAoQ,EAiDFC,EAhIV,IACErzC,IAAIszC,EAUJ,OAAI,YAPFA,EADqB,UAAnB,OAAOttB,EACU,CACjBlH,YAAakH,GAGIA,IAIbkhB,EAAUoM,EAAiBpM,QAE7B,gBAAiBoM,GACnBn9B,EAEE,WADA+wB,EAAQt7B,KACR6J,oBAII09B,EAAiE,CACrE/vB,QAAS8jB,EAAQzI,WACjBrG,oBAAqB,CACnBtZ,YAAaw0B,EAAiBx0B,YAC9B4Y,WAAmC,iBACpC,IAqCctb,MARfoc,EACE/iB,EACA09B,EAA8B,mBAzB9Bv3B,MACF6c,EACA/c,IAGIA,EAAQ0c,oBAAoBH,kBAAoBZ,IAClDlhB,EACE6hB,GAAUpsB,OAASulC,GACnB1Y,EAAY,gBAAA,EASPiP,GAAoBjP,EALIrc,MAAMm3B,GACnC9a,EACA/c,EACAsc,CAAQ,CAEqD,GAE1D0P,GAAoBjP,EAAc/c,CAAO,EAQb,kBAIkB9S,MAAMrG,GACpDiG,QAAQkW,OAAOnc,CAAK,CAC5B,GAEeixC,mBAEhBr9B,EAEE,WADA+wB,EAAQt7B,KACR6J,oBAMFU,EAHM6sB,EACJsQ,EAAiBG,iBAAiBnvB,KAClCgvB,EAAiBI,eACMj+B,+BAEnB29B,EAAyD,CAC7DtM,qBAAsBI,EAAQzI,WAC9BuE,gBAAAA,EACA1K,gBAAiB,CACfZ,WAAmC,iBACpC,IAqCctb,MARfoc,EACE/iB,EACA29B,EAA0B,eAzB1Bx3B,MACF6c,EACA/c,IAGIA,EAAQ4c,gBAAgBL,kBAAoBZ,IAC9ClhB,EACE6hB,GAAUpsB,OAASulC,GACnB1Y,EAAY,gBAAA,EASP0X,GAAoB1X,EALIrc,MAAMm3B,GACnC9a,EACA/c,EACAsc,CAAQ,CAEqD,GAE1DmY,GAAoB1X,EAAc/c,CAAO,EAQb,kBAIc9S,MAAMrG,GAChDiG,QAAQkW,OAAOnc,CAAK,CAC5B,GAEeoxC,qBAGZN,EACJ,CACEv0B,YAAaw0B,EAAiBx0B,YAC9B4Y,WAAmC,mBAwCtBtb,MARfoc,EACE/iB,EACA49B,EAAgC,uBA5BhCz3B,MACF6c,EACA/c,IAGIA,EAAQuc,kBAAoBZ,IAC9BlhB,EACE6hB,GAAUpsB,OAASulC,GACnB1Y,EAAY,gBAAA,EASP2E,GACL3E,EAN6Brc,MAAMm3B,GACnC9a,EACA/c,EACAsc,CAAQ,CAIc,GAGnBoF,GAA0B3E,EAAc/c,CAAO,EAQb,kBAIc9S,MAAMrG,GACtDiG,QAAQkW,OAAOnc,CAAK,CAC5B,IA1GkCu7B,WAgHtC,CAFS,QACR9F,GAAUka,OAAM,CACjB,CACH,CAuCOt2B,eAAe23B,GACpB99B,EACAiG,EACAk4B,GAEAz9B,EACEy9B,EAAoBhoC,OAASulC,GAC7B17B,EAAI,gBAAA,EAIN,IAmBQ4iB,EAgBAJ,EAGAP,EAEAW,EAxCFwb,EAAmBz3B,MAAMw3B,EAAoBpc,SAQ7CW,GANNhiB,EAC8B,UAA5B,OAAO09B,EACPp+B,oBAIiB,CAAE,GAAGiG,IAExB,MAAI,wBAAyByc,GACrBrZ,EACJqZ,EACAC,oBAAoBtZ,YAChBmZ,EACJE,EACAC,oBAAoBH,gBAChBP,EAAcS,EACjBC,oBAAoBV,WACjBW,EACJF,EACAC,oBAAoBC,iBAEtBt0B,OAAO6gB,OAAOuT,EAAY,CACxBC,oBAAuB,CACrBtZ,YAAAA,EACAoZ,eAAgB2b,EAChB5b,gBAAAA,EACAP,WAAAA,EACAW,iBAAAA,CACD,CACF,CAAA,GAGQ,oBAAqBF,GACxBF,EACJE,EACAG,gBAAgBL,gBACZP,EAAcS,EACjBG,gBAAgBZ,WACbW,EACJF,EACAG,gBAAgBD,iBAElBt0B,OAAO6gB,OAAOuT,EAAY,CACxBG,gBAAmB,CACjBJ,eAAgB2b,EAChB5b,gBAAAA,EACAP,WAAAA,EACAW,iBAAAA,CACD,CACF,CAAA,GAIDt0B,OAAO6gB,OAAOuT,EAAY,CAAED,eAAkB2b,CAAkB,CAAA,EACzD1b,CAEX,OC9da2b,EAcX5xC,YAAYuT,GAPHtW,KAAA6kB,WAAa8vB,EAAkBtV,YAQtCr/B,KAAKsW,KAAOgf,EAAUhf,CAAI,CAC3B,CAmCDs+B,kBACEC,EACAC,GAEA,OAAOf,GACL/zC,KAAKsW,KACLu+B,EACAlqC,EAAmBmqC,CAAkD,CAAC,CAEzE,CA6BDxV,kBACEjB,EACAC,GAEA,OAAOH,GAAoBC,kBACzBC,EACAC,CAAgB,CAEnB,CAMDsC,4BACEC,GAEA,IAAMvB,EAAauB,EACnB,OAAO8T,EAAkBtT,2BAA2B/B,CAAU,CAC/D,CAkCDyB,2BAA2B39B,GACzB,OAAOuxC,EAAkBtT,2BACtBj+B,EAAM2C,YAAc,EAAE,CAE1B,CAEOs7B,kCAAkC,CACxCzhB,eAAgBohB,IAEhB,IAGQrhB,EAAa6e,EAHrB,OAAKwC,IAGC,CAAErhB,YAAAA,EAAa6e,eAAAA,CAAgB,EACnCwC,EACErhB,IAAe6e,EACVL,GAAoBI,mBACzB5e,EACA6e,CAAc,EAPT,IAWV,EC7La,SAAAuW,GACdz+B,EACA0+B,GAEA,OAAIA,EACKtrB,EAAasrB,CAAgB,GAGtCh+B,EAAQV,EAAK4Z,uBAAwB5Z,oBAE9BA,EAAK4Z,uBACd,CDiBkBykB,EAAAtV,YAAwC,QAExCsV,EAAAM,qBAAoB,cEXhCC,WAAsBnZ,GAC1Bh5B,YAAqBgF,GACnB/B,yBADmBhG,KAAM+H,OAANA,CAEpB,CAEDk0B,oBAAoB3lB,GAClB,OAAO8mB,EAAc9mB,EAAMtW,KAAKm1C,iBAAkB,CAAA,CACnD,CAEDhZ,eACE7lB,EACA2N,GAEA,OAAOmZ,EAAc9mB,EAAMtW,KAAKm1C,iBAAiBlxB,CAAO,CAAC,CAC1D,CAEDoY,6BAA6B/lB,GAC3B,OAAO8mB,EAAc9mB,EAAMtW,KAAKm1C,iBAAkB,CAAA,CACnD,CAEOA,iBAAiBlxB,GACvB,IAAM1H,EAAgC,CACpCyhB,WAAYh+B,KAAK+H,OAAOi2B,WACxBoX,UAAWp1C,KAAK+H,OAAOqtC,UACvBrX,SAAU/9B,KAAK+H,OAAOg2B,SACtBvhB,SAAUxc,KAAK+H,OAAOyU,SACtB8gB,aAAct9B,KAAK+H,OAAOu1B,aAC1BH,kBAAmB,CAAA,EACnBkY,oBAAqB,CAAA,GAOvB,OAJIpxB,IACF1H,EAAQ0H,QAAUA,GAGb1H,CACR,CACF,CAEK,SAAU+4B,GACdvtC,GAEA,OAAOs7B,GACLt7B,EAAOuO,KACP,IAAI4+B,GAAcntC,CAAM,EACxBA,EAAOma,eAAe,CAE1B,CAEM,SAAUqzB,GACdxtC,GAEA,GAAM,CAAEuO,KAAAA,EAAM2L,KAAAA,CAAM,EAAGla,EAEvB,OADAiP,EAAQiL,EAAM3L,oBACP6sB,GACLlhB,EACA,IAAIizB,GAAcntC,CAAM,EACxBA,EAAOma,eAAe,CAE1B,CAEOzF,eAAewmB,GACpBl7B,GAEA,GAAM,CAAEuO,KAAAA,EAAM2L,KAAAA,CAAM,EAAGla,EAEvB,OADAiP,EAAQiL,EAAM3L,oBACPk/B,GAAUvzB,EAAM,IAAIizB,GAAcntC,CAAM,EAAGA,EAAOma,eAAe,CAC1E,OCpEsBuzB,GASpB1yC,YACqBuT,EACnBmO,EACmBsP,EACT9R,EACSC,EAAkB,CAAA,GAJlBliB,KAAIsW,KAAJA,EAEAtW,KAAQ+zB,SAARA,EACT/zB,KAAIiiB,KAAJA,EACSjiB,KAAekiB,gBAAfA,EAXbliB,KAAc01C,eAA0B,KACxC11C,KAAY21C,aAAwB,KAY1C31C,KAAKykB,OAASlkB,MAAMC,QAAQikB,CAAM,EAAIA,EAAS,CAACA,EACjD,CAIDkS,UACE,OAAO,IAAIttB,QACToT,MAAOnT,EAASiW,KACdvf,KAAK01C,eAAiB,CAAEpsC,QAAAA,EAASiW,OAAAA,CAAM,EAEvC,IACEvf,KAAK21C,aAAe14B,MAAMjd,KAAK+zB,SAAS9C,YAAYjxB,KAAKsW,IAAI,EAC7D2G,MAAMjd,KAAK41C,cACX51C,KAAK21C,aAAaE,iBAAiB71C,IAAI,CAGxC,CAFC,MAAOkD,GACPlD,KAAKuf,OAAOrc,CAAU,CACvB,CACH,CAAC,CAEJ,CAED4yC,kBAAkBpM,GAChB,GAAM,CAAEqM,YAAAA,EAAaX,UAAAA,EAAWrX,SAAAA,EAAUvhB,SAAAA,EAAUpZ,MAAAA,EAAOqJ,KAAAA,CAAM,EAAGi9B,EACpE,GAAItmC,EACFpD,KAAKuf,OAAOnc,CAAK,MADnB,CAKM2E,EAAwB,CAC5BuO,KAAMtW,KAAKsW,KACX0nB,WAAY+X,EACZX,UAAWA,EACX54B,SAAUA,GAAYpX,KAAAA,EACtB24B,SAAUA,GAAY34B,KAAAA,EACtB6c,KAAMjiB,KAAKiiB,KACXC,gBAAiBliB,KAAKkiB,iBAGxB,IACEliB,KAAKsJ,QAAQ2T,MAAMjd,KAAKg2C,WAAWvpC,CAAI,EAAE1E,CAAM,CAAC,CAGjD,CAFC,MAAO7E,GACPlD,KAAKuf,OAAOrc,CAAU,CACvB,CAhBA,CAiBF,CAED+yC,QAAQ7yC,GACNpD,KAAKuf,OAAOnc,CAAK,CAClB,CAEO4yC,WAAWvpC,GACjB,OAAQA,GACN,IAAqC,iBACrC,IAAA,oBACE,OAAO6oC,GACT,IAAkC,eAClC,IAAA,kBACE,OAAOrS,GACT,IAAoC,iBACpC,IAAA,oBACE,OAAOsS,GACT,QACEv/B,EAAMhW,KAAKsW,sBACd,CACF,CAEShN,QAAQk0B,GAChBpmB,EAAYpX,KAAK01C,eAAgB,+BAA+B,EAChE11C,KAAK01C,eAAepsC,QAAQk0B,CAAI,EAChCx9B,KAAKk2C,qBAAoB,CAC1B,CAES32B,OAAOnc,GACfgU,EAAYpX,KAAK01C,eAAgB,+BAA+B,EAChE11C,KAAK01C,eAAen2B,OAAOnc,CAAK,EAChCpD,KAAKk2C,qBAAoB,CAC1B,CAEOA,uBACFl2C,KAAK21C,cACP31C,KAAK21C,aAAaQ,mBAAmBn2C,IAAI,EAG3CA,KAAK01C,eAAiB,KACtB11C,KAAKo2C,QAAO,CACb,CAGF,CC7FM,IAAMC,GAA6B,IAAI1+B,GAAM,IAAM,GAAK,QA2JzD2+B,UAAuBb,GAO3B1yC,YACEuT,EACAmO,EACiBjE,EACjBuT,EACA9R,GAEAjc,MAAMsQ,EAAMmO,EAAQsP,EAAU9R,CAAI,EAJjBjiB,KAAQwgB,SAARA,EANXxgB,KAAUu2C,WAAqB,KAC/Bv2C,KAAMw2C,OAAkB,KAU1BF,EAAeG,oBACjBH,EAAeG,mBAAmBC,SAGpCJ,EAAeG,mBAAqBz2C,IACrC,CAED22C,uBACE,IAAMhlB,EAAS1U,MAAMjd,KAAK22B,UAE1B,OADA3f,EAAQ2a,EAAQ3xB,KAAKsW,uBACdqb,CACR,CAEDikB,oBACEx+B,EACyB,IAAvBpX,KAAKykB,OAAO1jB,OACZ,wCAAwC,EAE1C,IAAMirC,EAAUa,KAChB7sC,KAAKu2C,WAAat5B,MAAMjd,KAAK+zB,SAAS6iB,WACpC52C,KAAKsW,KACLtW,KAAKwgB,SACLxgB,KAAKykB,OAAO,GACZunB,CAAO,EAEThsC,KAAKu2C,WAAWM,gBAAkB7K,EASlChsC,KAAK+zB,SAAS+iB,kBAAkB92C,KAAKsW,IAAI,EAAE7M,MAAMvG,IAC/ClD,KAAKuf,OAAOrc,CAAC,CACf,CAAC,EAEDlD,KAAK+zB,SAASgjB,6BAA6B/2C,KAAKsW,KAAM0gC,IAC/CA,GACHh3C,KAAKuf,OACHnJ,EAAapW,KAAKsW,KAA4C,yBAAA,CAAA,CAGpE,CAAC,EAGDtW,KAAKi3C,qBAAoB,CAC1B,CAEDjL,cACE,OAAOhsC,KAAKu2C,YAAYM,iBAAmB,IAC5C,CAEDH,SACE12C,KAAKuf,OAAOnJ,EAAapW,KAAKsW,KAA0C,yBAAA,CAAA,CACzE,CAED8/B,UACMp2C,KAAKu2C,YACPv2C,KAAKu2C,WAAW1sC,QAGd7J,KAAKw2C,QACPjzC,OAAO8b,aAAarf,KAAKw2C,MAAM,EAGjCx2C,KAAKu2C,WAAa,KAClBv2C,KAAKw2C,OAAS,KACdF,EAAeG,mBAAqB,IACrC,CAEOQ,uBACN,IAAMtN,EAAO,KACP3pC,KAAKu2C,YAAYhzC,QAAQ2zC,OAM3Bl3C,KAAKw2C,OAASjzC,OAAOic,WAAW,KAC9Bxf,KAAKw2C,OAAS,KACdx2C,KAAKuf,OACHnJ,EAAapW,KAAKsW,KAAyC,sBAAA,CAAA,CAE9D,OAIHtW,KAAKw2C,OAASjzC,OAAOic,WAAWmqB,EAAM0M,GAA2Br+B,IAAG,CAAE,CACxE,EAEA2xB,GACD,EAzGc2M,EAAkBG,mBAA0B,KC1L7D,IAAMU,GAAuB,kBAIvBC,GAGF,IAAI3tB,UAEK4tB,WAAuB5B,GAGlC1yC,YACEuT,EACAyd,EACA7R,EAAkB,CAAA,GAElBlc,MACEsQ,EACA,sEAMAyd,EACA3uB,KAAAA,EACA8c,CAAe,EAjBnBliB,KAAOgsC,QAAG,IAmBT,CAMDrV,gBACE91B,IAAIy2C,EAAeF,GAAmBp/B,IAAIhY,KAAKsW,KAAK+T,KAAI,CAAE,EAC1D,GAAI,CAACitB,EAAc,CACjB,IAKE,IAAM3lB,EAJqB1U,MA+C5BR,MACLsX,EACAzd,KAEA,IAKMihC,EALAzwC,EAAM0wC,GAAmBlhC,CAAI,EAC7BqU,EAAc8sB,GAAoB1jB,CAAQ,EAChD,cAAYpJ,EAAYX,aAAY,IAG9ButB,EAAuD,SAAlC,MAAO5sB,EAAYT,KAAKpjB,CAAG,EACtDmW,MAAM0N,EAAYR,QAAQrjB,CAAG,EACtBywC,EACT,GA1DUv3C,KAAK+zB,SACL/zB,KAAKsW,IAAI,EAEyB2G,MAAMjX,MAAM2wB,QAAO,EAAK,KAC5D2gB,EAAe,IAAMjuC,QAAQC,QAAQqoB,CAAM,CAG5C,CAFC,MAAOzuB,GACPo0C,EAAe,IAAMjuC,QAAQkW,OAAOrc,CAAC,CACtC,CAEDk0C,GAAmBvtB,IAAI7pB,KAAKsW,KAAK+T,KAAI,EAAIitB,CAAY,CACtD,CAQD,OAJKt3C,KAAKkiB,iBACRk1B,GAAmBvtB,IAAI7pB,KAAKsW,KAAK+T,OAAQ,IAAMhhB,QAAQC,QAAQ,IAAI,CAAC,EAG/DguC,EAAY,CACpB,CAEDxB,kBAAkBpM,GAChB,GAAc,sBAAVA,EAAMj9B,KACR,OAAOzG,MAAM8vC,YAAYpM,CAAK,EACzB,GAAc,YAAVA,EAAMj9B,KAEfzM,KAAKsJ,QAAQ,IAAI,OAInB,GAAIogC,EAAMsC,QAAS,CACjB,IAAM/pB,EAAOhF,MAAMjd,KAAKsW,KAAK2d,mBAAmByV,EAAMsC,OAAO,EAC7D,GAAI/pB,EAEF,OADAjiB,KAAKiiB,KAAOA,EACLjc,MAAM8vC,YAAYpM,CAAK,EAE9B1pC,KAAKsJ,QAAQ,IAAI,CAEpB,CACF,CAEDssC,qBAEAQ,WACD,CAgBM35B,eAAei7B,GACpB3jB,EACAzd,GAEA,OAAOmhC,GAAoB1jB,CAAQ,EAAE9J,KAAKutB,GAAmBlhC,CAAI,EAAG,MAAM,CAC5E,CAMgB,SAAA6b,GACd7b,EACAqb,GAEAylB,GAAmBvtB,IAAIvT,EAAK+T,KAAM,EAAEsH,CAAM,CAC5C,CAEA,SAAS8lB,GACP1jB,GAEA,OAAOrK,EAAaqK,EAASC,oBAAoB,CACnD,CAEA,SAASwjB,GAAmBlhC,GAC1B,OAAOmU,EACL0sB,GACA7gC,EAAK+B,OAAO2E,OACZ1G,EAAKtT,IAAI,CAEb,CCxEgB,SAAA20C,GACdrhC,EACAkK,EACAuT,GAEA,OAGKtX,MACLnG,EACAkK,EACAuT,KAEA,IAKMhV,EAMA64B,EAXN,OAAI5uB,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,GAGnDyI,EAAeuW,EAAUhf,CAAI,EACnCI,GAAkBJ,EAAMkK,EAAUof,CAAqB,EAIvD3iB,MAAM8B,EAAakR,uBAEnBhT,MAAMy6B,GADAE,EAAmB7C,GAAqBh2B,EAAcgV,CAAQ,EAClBhV,CAAY,EAEvD64B,EAAiBC,cACtB94B,EACAyB,uBAGJ,GA3B6BlK,EAAMkK,EAAUuT,CAAQ,CACrD,CA+DgB,SAAA+jB,GACd71B,EACAzB,EACAuT,GAEA,OAMKtX,MACLwF,EACAzB,EACAuT,KAEA,IAAMhM,EAAepd,EAAmBsX,CAAI,EAE5C,GADAvL,GAAkBqR,EAAazR,KAAMkK,EAAUof,CAAqB,EAChE5W,wBAAqBjB,EAAazR,KAAK2S,GAAG,EAC5C,OAAO5f,QAAQkW,OACb9I,EAAgDsR,EAAazR,IAAI,CAAC,EAMtE2G,MAAM8K,EAAazR,KAAK2Z,uBAExB,IAAM2nB,EAAmB7C,GAAqBhtB,EAAazR,KAAMyd,CAAQ,EAGnEiY,GAFN/uB,MAAMy6B,GAA0BE,EAAkB7vB,EAAazR,IAAI,EAEnD2G,MAAM86B,GAAuBhwB,CAAY,GACzD,OAAO6vB,EAAiBC,cACtB9vB,EAAazR,KACbkK,EAAQ,oBAERwrB,CAAO,CAEX,GAhCI/pB,EACAzB,EACAuT,CAAQ,CAEZ,CA6DgB,SAAAikB,GACd/1B,EACAzB,EACAuT,GAEA,OAEKtX,MACLwF,EACAzB,EACAuT,KAEA,IAAMhM,EAAepd,EAAmBsX,CAAI,EAOtC21B,GANNlhC,GAAkBqR,EAAazR,KAAMkK,EAAUof,CAAqB,EAIpE3iB,MAAM8K,EAAazR,KAAK2Z,uBAEC8kB,GAAqBhtB,EAAazR,KAAMyd,CAAQ,GAInEiY,GAHN/uB,MAAM2lB,GAAoB,CAAA,EAAO7a,EAAcvH,EAASqE,UAAU,EAClE5H,MAAMy6B,GAA0BE,EAAkB7vB,EAAazR,IAAI,EAEnD2G,MAAM86B,GAAuBhwB,CAAY,GACzD,OAAO6vB,EAAiBC,cACtB9vB,EAAazR,KACbkK,EAAQ,kBAERwrB,CAAO,CAEX,GAzB2B/pB,EAAMzB,EAAUuT,CAAQ,CACnD,CA2EOtX,eAAew7B,GACpB3hC,EACA4hC,EACAh2B,EAAkB,CAAA,GAElB,IAKMnD,EAGA4S,EARN,OAAI3I,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,GAInDyd,EAAWghB,GADXh2B,EAAeuW,EAAUhf,CAAI,EACiB4hC,CAAc,GAE5DvmB,EAAS1U,MADA,IAAIo6B,GAAet4B,EAAcgV,EAAU7R,CAAe,EAC7CyU,YAEd,CAACzU,IACb,OAAOyP,EAAO1P,KAAKiH,iBACnBjM,MAAM8B,EAAa6I,sBAAsB+J,EAAO1P,IAAoB,EACpEhF,MAAM8B,EAAauT,iBAAiB,KAAM4lB,CAAc,GAGnDvmB,EACT,CAEAlV,eAAes7B,GAAuB91B,GACpC,IAAM+pB,EAAUa,GAAoB5qB,EAAKkD,IAAR,KAAgB,EAIjD,OAHAlD,EAAKiH,iBAAmB8iB,EACxB/uB,MAAMgF,EAAK3L,KAAKgc,iBAAiBrQ,CAAI,EACrChF,MAAMgF,EAAK3L,KAAKsR,sBAAsB3F,CAAI,EACnC+pB,CACT,OCnTamM,GAOXp1C,YAA6BuT,GAAAtW,KAAIsW,KAAJA,EANZtW,KAAAo4C,gBAA+B,IAAI3V,IACnCziC,KAAAq4C,UAAoC,IAAI5V,IAC/CziC,KAAmBs4C,oBAAqB,KACxCt4C,KAA2Bu4C,4BAAG,CAAA,EAChCv4C,KAAAw4C,uBAAyBnsC,KAAKD,KAEa,CAEnDypC,iBAAiB4C,GACfz4C,KAAKq4C,UAAU3c,IAAI+c,CAAiB,EAGlCz4C,KAAKs4C,qBACLt4C,KAAK04C,mBAAmB14C,KAAKs4C,oBAAqBG,CAAiB,IAEnEz4C,KAAK24C,eAAe34C,KAAKs4C,oBAAqBG,CAAiB,EAC/Dz4C,KAAK44C,iBAAiB54C,KAAKs4C,mBAAmB,EAC9Ct4C,KAAKs4C,oBAAsB,KAE9B,CAEDnC,mBAAmBsC,GACjBz4C,KAAKq4C,UAAUtvB,OAAO0vB,CAAiB,CACxC,CAEDI,QAAQnP,GAEN,GAAI1pC,KAAK84C,oBAAoBpP,CAAK,EAChC,MAAO,CAAA,EAGT7oC,IAAIk4C,EAAU,CAAA,EAuBd,OAtBA/4C,KAAKq4C,UAAUpwC,QAAQ+wC,IACjBh5C,KAAK04C,mBAAmBhP,EAAOsP,CAAQ,IACzCD,EAAU,CAAA,EACV/4C,KAAK24C,eAAejP,EAAOsP,CAAQ,EACnCh5C,KAAK44C,iBAAiBlP,CAAK,EAE/B,CAAC,EAEG1pC,KAAKu4C,6BAA+B,EAkEnB7O,IACvB,OAAQA,EAAMj9B,MACZ,IAAwC,oBACxC,IAAqC,kBACrC,IAAA,oBACE,OAAO,EACT,IAAA,UACE,OAAOwsC,GAAoBvP,CAAK,EAClC,QACE,MACH,CACH,GA7E6DA,CAAK,IAM9D1pC,KAAKu4C,4BAA8B,CAAA,EAG9BQ,KACH/4C,KAAKs4C,oBAAsB5O,EAC3BqP,EAAU,CAAA,GAGLA,CACR,CAEOJ,eAAejP,EAAkBsP,GACvC,IACQnzC,EADJ6jC,EAAMtmC,OAAS,CAAC61C,GAAoBvP,CAAK,GACrC7jC,EACH6jC,EAAMtmC,MAAMyC,MAAMyC,MAAM,OAAO,EAAE,IACL,iBAC/B0wC,EAAS/C,QAAQ7/B,EAAapW,KAAKsW,KAAMzQ,CAAI,CAAC,GAE9CmzC,EAASlD,YAAYpM,CAAK,CAE7B,CAEOgP,mBACNhP,EACAsP,GAEA,IAAME,EACiB,OAArBF,EAAShN,SACR,CAAC,CAACtC,EAAMsC,SAAWtC,EAAMsC,UAAYgN,EAAShN,QACjD,OAAOgN,EAASv0B,OAAOjd,SAASkiC,EAAMj9B,IAAI,GAAKysC,CAChD,CAEOJ,oBAAoBpP,GAQ1B,OAzFwC,KAmFtCr9B,KAAKD,MAAQpM,KAAKw4C,wBAGlBx4C,KAAKo4C,gBAAgBpF,QAGhBhzC,KAAKo4C,gBAAgBpV,IAAImW,GAASzP,CAAK,CAAC,CAChD,CAEOkP,iBAAiBlP,GACvB1pC,KAAKo4C,gBAAgB1c,IAAIyd,GAASzP,CAAK,CAAC,EACxC1pC,KAAKw4C,uBAAyBnsC,KAAKD,KACpC,CACF,CAED,SAAS+sC,GAASj2C,GAChB,MAAO,CAACA,EAAEuJ,KAAMvJ,EAAE8oC,QAAS9oC,EAAEkyC,UAAWlyC,EAAEsZ,UAAUiI,OAAO20B,GAAKA,CAAC,EAAE53C,KAAK,GAAG,CAC7E,CAEA,SAASy3C,GAAoB,CAAExsC,KAAAA,EAAMrJ,MAAAA,IACnC,MACgC,YAA9BqJ,GACgB,uBAAhBrJ,GAAOyC,IAEX,CC3GO4W,eAAe48B,GACpB/iC,EACAiG,EAAmC,IAEnC,OAAOG,EACLpG,EAGA,MAAA,eAAAiG,CAAO,CAEX,CChBA,IAAM+8B,GAAmB,uCACnBC,GAAa,UAEZ98B,eAAe+8B,GAAgBljC,GAEpC,GAAIA,CAAAA,EAAK+B,OAAOE,SAAhB,CAIA,IAEWkhC,EAFHC,GAAsBz8B,MAAMo8B,GAAkB/iC,CAAI,GAA/B,kBAE3B,IAAWmjC,KAAUC,EACnB,IACE,IAYexW,IACnB,IA+BMyW,EA/BAC,EAAaviC,KACb,CAAEK,SAAAA,EAAU1M,SAAAA,CAAQ,EAAK,IAAID,IAAI6uC,CAAU,EACjD,OAAI1W,EAASp4B,WAAW,qBAAqB,EAGpB,MAFjB+uC,EAAQ,IAAI9uC,IAAIm4B,CAAQ,GAEpBl4B,UAAgC,KAAbA,EAGZ,sBAAb0M,GACAwrB,EAASv8B,QAAQ,sBAAuB,EAAE,IACxCizC,EAAWjzC,QAAQ,sBAAuB,EAAE,EAI9B,sBAAb+Q,GAAoCmiC,EAAM7uC,WAAaA,EAG3DuuC,GAAWxhC,KAAKL,CAAQ,IAIzB4hC,GAAiBvhC,KAAKmrB,CAAQ,EAGzBl4B,IAAak4B,GAIhB4W,EAAuB5W,EAASv8B,QAAQ,MAAO,KAAK,GAGpDgzC,EAAK,IAAII,OACb,UAAYD,EAAuB,IAAMA,EAAuB,KAChE,GAAG,GAEK/hC,KAAK/M,CAAQ,GACzB,GAjDsByuC,CAAM,EACpB,MAIH,CAFC,OAMJzjC,EAAMM,EAAI,sBAfT,CAgBH,CCtBA,IAAM0jC,GAAkB,IAAIriC,GAAM,IAAO,GAAK,EAM9C,SAASsiC,KAIP,IAAMC,EAAStM,EAAS,EAACuM,OAEzB,GAAID,GAAQE,EAEV,IAAK,IAAMC,KAAQz1C,OAAO0C,KAAK4yC,EAAOE,CAAC,EAQrC,GANAF,EAAOE,EAAEC,GAAMC,EAAIJ,EAAOE,EAAEC,GAAMC,GAAK,GAEvCJ,EAAOE,EAAEC,GAAME,EAAIL,EAAOE,EAAEC,GAAME,GAAK,GAEvCL,EAAOE,EAAEC,GAAMC,EAAI,CAAC,GAAGJ,EAAOE,EAAEC,GAAME,GAElCL,EAAOM,GACT,IAAK35C,IAAIC,EAAI,EAAGA,EAAIo5C,EAAOM,GAAGz5C,OAAQD,CAAC,GAErCo5C,EAAOM,GAAG15C,GAAK,IAKzB,CAEA,SAAS25C,GAASnkC,GAChB,OAAO,IAAIjN,QAA8B,CAACC,EAASiW,KAEjD,SAASm7B,IAGPT,KACAU,KAAKpJ,KAAK,eAAgB,CACxBnkC,SAAU,KACR9D,EAAQqxC,KAAKC,QAAQC,WAAY,CAAA,CAClC,EACDC,UAAW,KAOTb,KACA16B,EAAOnJ,EAAaE,EAAI,wBAAuC,CAAA,CAChE,EACDhD,QAAS0mC,GAAgBhiC,IAAK,CAC/B,CAAA,CACF,CAED,GAAI41B,EAAS,EAAC+M,MAAMC,SAASG,OAE3BzxC,EAAQqxC,KAAKC,QAAQC,WAAY,CAAA,MAC5B,CAAA,IASCG,EATD,GAAMpN,CAAAA,IAAU+M,MAAMpJ,KAqB3B,OAZMyJ,EAASC,GAAyB,WAAW,EAEnDrN,EAAS,EAACoN,GAAU,KAEZL,KAAKpJ,KACTmJ,IAGAn7B,EAAOnJ,EAAaE,EAAI,wBAAuC,CAAA,CAEnE,EAEO4kC,GrEtDJ1lB,GAAmBI,WqEuDX,WAAiColB,CAAQ,EACjDvxC,MAAMvG,GAAKqc,EAAOrc,CAAC,CAAC,EArBvBw3C,GAsBD,CACH,CAAC,EAAEjxC,MAAMrG,IAGP,MADA+3C,GAAmB,KACb/3C,CACR,CAAC,CACH,CAEAvC,IAAIs6C,GAAyD,KCvF7D,IAAMC,GAAe,IAAIzjC,GAAM,IAAM,IAAK,EACpC0jC,GAAc,iBACdC,GAAuB,uBAEvBC,GAAoB,CACxB1gB,MAAO,CACLE,SAAU,WACVygB,IAAK,SACLxgB,MAAO,MACPygB,OAAQ,KACT,EACDC,cAAe,OACfC,SAAU,MAKNC,GAAmB,IAAInyB,IAAI,CAC/B,CAAyB,iCAAA,KACzB,CAAC,iDAAkD,KACnD,CAAC,8CAA+C,KACjD,EAyBMhN,eAAeo/B,GACpBvlC,GDyCwBA,ECvCmBA,EAA3C,IA1BoBA,EAGd5N,EASAozC,EAcAC,EAAU9+B,MDwChBk+B,GAAmBA,IAAoBV,GAASnkC,CAAI,GCvC9CqkC,EAAO/M,EAAS,EAAC+M,KAEvB,OADA3jC,EAAQ2jC,EAAMrkC,oBACPylC,EAAQtN,KACb,CACEuN,MAAO/3C,SAAS4Y,KAChBnU,KA9BJsO,GAAQqB,GAFY/B,EAgCEA,GA/BF+B,QACL0Z,WAAYzb,iCACrB5N,EAAM2P,EAAOE,SACfH,GAAaC,EAAQijC,EAAoB,aAC9BhlC,EAAK+B,OAAO0Z,cAAcspB,GAEnCtzC,EAAiC,CACrCiV,OAAQ3E,EAAO2E,OACfxG,QAASF,EAAKtT,KACdo2C,EAAGrjC,GAAWA,cAEV+lC,EAAMF,GAAiB5jC,IAAI1B,EAAK+B,OAAOsF,OAAO,KAElD5V,EAAO+zC,IAAMA,IAGXlvB,EADetW,EAAKqe,kBACT5zB,SACbgH,EAAOk0C,GAAKrvB,EAAWprB,KAAK,GAAG,GAEvBkH,EAAH,IAAUb,GAAYE,CAAM,EAAE+O,MAAM,CAAC,GAaxColC,sBAAuBvB,EAAKC,QAAQuB,4BACpCC,WAAYb,GACZc,UAAW,CAAA,CACZ,EACD,GACE,IAAIhzC,QAAQoT,MAAOnT,EAASiW,KAC1BtC,MAAMq/B,EAAOC,QAAQ,CAEnBC,eAAgB,CAAA,CACjB,CAAA,EAED,IAAMC,EAAermC,EACnBE,4BAKIomC,EAAoB9O,IAAUpuB,WAAW,KAC7CD,EAAOk9B,CAAY,CACrB,EAAGrB,GAAapjC,IAAG,CAAE,EAErB,SAAS2kC,IACP/O,EAAS,EAACvuB,aAAaq9B,CAAiB,EACxCpzC,EAAQgzC,CAAM,CACf,CAGDA,EAAOM,KAAKD,CAAoB,EAAEnzC,KAAKmzC,EAAsB,KAC3Dp9B,EAAOk9B,CAAY,CACrB,CAAC,CACF,CAAA,CAAC,CAER,CCzFA,IAAMI,GAAqB,CACzBvlC,SAAU,MACVwlC,UAAW,MACXC,UAAW,MACXC,QAAS,YASEC,GAGXl6C,YAAqBQ,GAAAvD,KAAMuD,OAANA,EAFrBvD,KAAe62C,gBAAkB,IAEa,CAE9ChtC,QACE,GAAI7J,KAAKuD,OACP,IACEvD,KAAKuD,OAAOsG,OACA,CAAZ,MAAO3G,IAEZ,CACF,CAEe,SAAAg6C,GACd5mC,EACA5N,EACA1F,EACAg4B,EAxBoB,IAyBpBygB,EAxBqB,KA0BrB,IAAMD,EAAMtjC,KAAKgL,KAAK3f,OAAO45C,OAAOC,YAAc3B,GAAU,EAAG,CAAC,EAAE32C,SAAQ,EACpEu2B,EAAOnjB,KAAKgL,KAAK3f,OAAO45C,OAAOE,WAAariB,GAAS,EAAG,CAAC,EAAEl2B,SAAQ,EACzEjE,IAAImsC,EAAS,GAEb,IAmDMsQ,EAnDAz2B,EAAqC,CACzC,GAAGg2B,GACH7hB,MAAOA,EAAMl2B,SAAU,EACvB22C,OAAQA,EAAO32C,SAAU,EACzB02C,IAAAA,EACAngB,KAAAA,GAKI71B,EAAKhB,IAAQka,cAcb6+B,GAZFv6C,IACFgqC,EAAS3gB,GAAa7mB,CAAE,EA1CP,SA0C0BxC,GAGzCipB,GAAWzmB,CAAE,IAEfkD,EAAMA,GA7CgB,mBAgDtBme,EAAQ22B,WAAa,OAGD54C,OAAOoD,QAAQ6e,CAAO,EAAE42B,OAC5C,CAACC,EAAO,CAAC52C,EAAKC,KAAW,GAAG22C,EAAQ52C,MAAOC,KAC3C,EAAE,GAGJ,GAAI42C,C7E2C2Bn4C,EAAKhB,K6E3ChCm5C,CAAiBn4C,G7E4CdgnB,GAAOhnB,CAAE,GAAQjC,OAAOkB,WAAmCm5C,Y6E5C3B,UAAX5Q,EAE1B,OAgBwBtkC,EAjBLA,GAAO,GAiBWskC,EAjBPA,GAkB1BtS,EAAKz2B,SAAS02B,cAAc,GAAG,GAClCpjB,KAAO7O,EACVgyB,EAAGsS,OAASA,GACNsQ,EAAQr5C,SAAS45C,YAAY,YAAY,GACzCC,eACJ,QACA,CAAA,EACA,CAAA,EACAv6C,OACA,EACA,EACA,EACA,EACA,EACA,CAAA,EACA,CAAA,EACA,CAAA,EACA,CAAA,EACA,EACA,IAAI,EAENm3B,EAAGqjB,cAAcT,CAAK,EAtCb,IAAIL,GAAU,IAAI,EAKrBe,EAASz6C,OAAOkrC,KAAK/lC,GAAO,GAAIskC,EAAQuQ,CAAa,EAC3DvmC,EAAQgnC,EAAQ1nC,mBAGhB,IACE0nC,EAAOC,MAAK,CACA,CAAZ,MAAO/6C,IAET,OAAO,IAAI+5C,GAAUe,CAAM,CAC7B,CC9EA,IAAME,GAAc,kBAOdC,GAAuB,wBAOvBC,GAAiCj2C,mBAAmB,KAAK,EAgBxDsU,eAAe4hC,GACpB/nC,EACAkK,EACA89B,EACAC,EACAvS,EACAwS,GAEAxnC,EAAQV,EAAK+B,OAAO0Z,WAAYzb,EAAI,6BAAA,EACpCU,EAAQV,EAAK+B,OAAO2E,OAAQ1G,EAAI,iBAAA,EAEhC,IAAMvO,EAAuB,CAC3BiV,OAAQ1G,EAAK+B,OAAO2E,OACpBxG,QAASF,EAAKtT,KACds7C,SAAAA,EACAC,YAAAA,EACAnF,EAAGrjC,GAAWA,YACdi2B,QAAAA,GAGF,GAAIxrB,aAAoBof,EAAuB,CAC7Cpf,EAASuf,mBAAmBzpB,EAAK8G,YAAY,EAC7CrV,EAAO8c,WAAarE,EAASqE,YAAc,I9GrDvBxc,IACtB,IAAK,IAAMvB,KAAOuB,EAChB,GAAIzD,OAAOC,UAAU45C,eAAe15C,KAAKsD,EAAKvB,CAAG,EAC/C,OAGJ,OAAO,CACT,G8G+CiB0Z,EAAS0f,oBAAqB,CAAA,IACzCn4B,EAAO+3B,iBAAmBh8B,KAAKgZ,UAAU0D,EAAS0f,oBAAmB,CAAE,GAIzE,IAAK,GAAM,CAACp5B,EAAKC,KAAUnC,OAAOoD,QAAQw2C,GAAoB,EAAE,EAC9Dz2C,EAAOjB,GAAOC,CAEjB,CAEGyZ,aAAoB2f,IAEF,GADdC,EAAS5f,EAAS+f,UAAW,EAAC9b,OAAO6b,GAAmB,KAAVA,CAAY,GACrDv/B,SACTgH,EAAOq4B,OAASA,EAAO5+B,KAAK,GAAG,GAI/B8U,EAAKkG,WACPzU,EAAO22C,IAAMpoC,EAAKkG,UAMpB,IACW1V,EADL63C,EAAa52C,EACnB,IAAWjB,KAAOlC,OAAO0C,KAAKq3C,CAAU,EACdv5C,KAAAA,IAApBu5C,EAAW73C,IACb,OAAO63C,EAAW73C,GAKtB,IAAMouB,EAAgBjY,MAAM3G,EAAK6e,oBAC3BypB,EAAwB1pB,MACtBkpB,MAAkCj2C,mBAAmB+sB,CAAa,EACtE,GAGJ,SAKwB7c,EALdwmC,CAAevoC,UAAfuoC,GAMLxmC,EAAOE,SAILH,GAAaC,EAAQ8lC,EAAoB,aAH5B9lC,EAAO0Z,cAAcmsB,MAPPr2C,GAAY82C,CAAU,EAAE7nC,MACxD,CAAC,EACC8nC,CACN,CCjFA,IAAME,GAA0B,0BAW1BC,GAANh8C,cACmB/C,KAAag/C,cAAqC,GAClDh/C,KAAO46C,QAAwC,GAC/C56C,KAAwBi/C,yBAAkC,GAElEj/C,KAAoBg0B,qBAAGqX,GAyHhCrrC,KAAmBqyB,oBAAG4lB,GAEtBj4C,KAAuBmyB,wBAAGA,EAC3B,CAxHCykB,iBACEtgC,EACAkK,EACA89B,EACAtS,GAcA,OAZA50B,EACEpX,KAAKg/C,cAAc1oC,EAAK+T,KAAI,IAAKnD,QACjC,8CAA8C,EAUzCg2B,GAAM5mC,EAPD2G,MAAMohC,GAChB/nC,EACAkK,EACA89B,EACAjnC,KACA20B,CAAO,EAEea,GAAkB,CAAA,CAC3C,CAEDgL,oBACEvhC,EACAkK,EACA89B,EACAtS,GAEA/uB,MAAMjd,KAAK82C,kBAAkBxgC,CAAI,EACjC,IAAM5N,EAAMuU,MAAMohC,GAChB/nC,EACAkK,EACA89B,EACAjnC,KACA20B,CAAO,EAGT,OrBtDF4B,IAAUt2B,SAASC,KqBqDE7O,EACZ,IAAIW,QAAQ,MAAQ,CAC5B,CAED4nB,YAAY3a,GACV,IAAMxP,EAAMwP,EAAK+T,OACjB,GAAIrqB,KAAKg/C,cAAcl4C,GAAM,CAC3B,GAAM,CAAEogB,QAAAA,EAASjJ,QAAAA,CAAO,EAAKje,KAAKg/C,cAAcl4C,GAChD,OAAIogB,EACK7d,QAAQC,QAAQ4d,CAAO,GAE9B9P,EAAY6G,EAAS,0CAA0C,EACxDA,EAEV,CAED,IAAMA,EAAUje,KAAKk/C,kBAAkB5oC,CAAI,EAS3C,OARAtW,KAAKg/C,cAAcl4C,GAAO,CAAEmX,QAAAA,CAAO,EAInCA,EAAQxU,MAAM,KACZ,OAAOzJ,KAAKg/C,cAAcl4C,EAC5B,CAAC,EAEMmX,CACR,CAEOihC,wBAAwB5oC,GAC9B,IAAMgmC,EAASr/B,MAAM4+B,GAAYvlC,CAAI,EACrC,IAAM4Q,EAAU,IAAIixB,GAAiB7hC,CAAI,EAezC,OAdAgmC,EAAO6C,SACL,YACA,IACEnoC,EAAQooC,GAAaC,UAAW/oC,wBAIzB,CAAEqY,OADOzH,EAAQ2xB,QAAQuG,EAAYC,SAAS,EACV,MAAmB,OAAA,GAEhE1E,KAAKC,QAAQuB,2BAA2B,EAG1Cn8C,KAAKg/C,cAAc1oC,EAAK+T,KAAI,GAAM,CAAEnD,QAAAA,GACpClnB,KAAK46C,QAAQtkC,EAAK+T,KAAM,GAAIiyB,EACrBp1B,CACR,CAED6vB,6BACEzgC,EACA8d,GAEep0B,KAAK46C,QAAQtkC,EAAK+T,KAAM,GAChCi1B,KACLR,GACA,CAAEryC,KAAMqyC,EAAyB,EACjCntB,IACE,IAAMqlB,EAAcrlB,IAAS,KAAKmtB,IACd15C,KAAAA,IAAhB4xC,GACF5iB,EAAG,CAAC,CAAC4iB,CAAW,EAGlBhhC,EAAMM,EAAI,iBACZ,EACAqkC,KAAKC,QAAQuB,2BAA2B,CAE3C,CAEDrF,kBAAkBxgC,GAChB,IAAMxP,EAAMwP,EAAK+T,OAKjB,OAJKrqB,KAAKi/C,yBAAyBn4C,KACjC9G,KAAKi/C,yBAAyBn4C,GAAO0yC,GAAgBljC,CAAI,GAGpDtW,KAAKi/C,yBAAyBn4C,EACtC,CAEDkqB,6BAEE,OAAOvE,GAAkB,GAAIL,GAAW,GAAII,GAAM,CACnD,CAKF,CAWM,IAAM+yB,GACXR,SCnKWS,iBCZXz8C,YAA+B6gC,GAAA5jC,KAAQ4jC,SAARA,CAAsB,CAErDwE,SACE9xB,EACAyxB,EACA1iB,GAEA,OAAQ0iB,EAAQt7B,MACd,IAAA,SACE,OAAOzM,KAAKy/C,gBAAgBnpC,EAAMyxB,EAAQzI,WAAYja,CAAW,EACnE,IAAA,SACE,OAAOrlB,KAAK0/C,gBAAgBppC,EAAMyxB,EAAQzI,UAAU,EACtD,QACE,OAAOpoB,EAAU,mCAAmC,CACvD,CACF,CAWF,EDVCnU,YAAqCu8B,GACnCt5B,eADmChG,KAAUs/B,WAAVA,CAEpC,CAGDqgB,uBACErgB,GAEA,OAAO,IAAIkgB,GAA8BlgB,CAAU,CACpD,CAGDmgB,gBACEnpC,EACA2N,EACAoB,GAEA,OhC6CF/O,EgC7CgCA,EhC8ChCiG,EgC9CsC,CAClC0H,QAAAA,EACAoB,YAAAA,EACAu6B,sBAAuB5/C,KAAKs/B,WAAWb,yBAA0B,CAClE,EhC4CI/hB,EAILpG,EAGA,OAAA,sCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CgClDlC,CAGDmjC,gBACEppC,EACAqxB,GAEA,OnBmCFrxB,EmBnCgCA,EnBoChCiG,EmBpCsC,CAClCorB,qBAAAA,EACAiY,sBAAuB5/C,KAAKs/B,WAAWb,yBAA0B,CAClE,EnBmCI/hB,EAILpG,EAGA,OAAA,kCAAAgG,EAAmBhG,EAAMiG,CAAO,CAAC,CmBzClC,CACF,OAOYsjC,GACX98C,eAYAkU,iBAAiBqoB,GACf,OAAOkgB,GAA8BG,gBAAgBrgB,CAAU,CAChE,EAKMugB,GAASC,UAAG,sCEvERC,GAIXh9C,YAA6BuT,GAAAtW,KAAIsW,KAAJA,EAHZtW,KAAAggD,kBACf,IAAIv2B,GAE6C,CAEnDw2B,SAEE,OADAjgD,KAAKkgD,qBAAoB,EAClBlgD,KAAKsW,KAAK8L,aAAa+C,KAAO,IACtC,CAEDkB,eACEC,GAIA,OAFAtmB,KAAKkgD,qBAAoB,EACzBjjC,MAAMjd,KAAKsW,KAAK2Z,uBACXjwB,KAAKsW,KAAK8L,YAKR,CAAE2D,YADW9I,MAAMjd,KAAKsW,KAAK8L,YAAYgB,WAAWkD,CAAY,CACnD,EAJX,IAKV,CAED65B,qBAAqBxV,GAEnB,IAIMhX,EALN3zB,KAAKkgD,qBAAoB,EACrBlgD,KAAKggD,kBAAkBhd,IAAI2H,CAAQ,IAIjChX,EAAc3zB,KAAKsW,KAAKmd,iBAAiBxR,IAC7C0oB,EACG1oB,GAA8Be,gBAAgB+C,aAAe,IAAI,CAEtE,CAAC,EACD/lB,KAAKggD,kBAAkBn2B,IAAI8gB,EAAUhX,CAAW,EAChD3zB,KAAKogD,uBAAsB,EAC5B,CAEDC,wBAAwB1V,GACtB3qC,KAAKkgD,qBAAoB,EACzB,IAAMvsB,EAAc3zB,KAAKggD,kBAAkBhoC,IAAI2yB,CAAQ,EAClDhX,IAIL3zB,KAAKggD,kBAAkBj3B,OAAO4hB,CAAQ,EACtChX,IACA3zB,KAAKogD,uBAAsB,EAC5B,CAEOF,uBACNlpC,EACEhX,KAAKsW,KAAK2Z,+DAGb,CAEOmwB,yBAC4B,EAA9BpgD,KAAKggD,kBAAkBvoB,KACzBz3B,KAAKsW,KAAKqS,yBAEV3oB,KAAKsW,KAAKsS,uBAEb,CACF,CCzDD,ICsB6B+D,GCRb,SAAA2zB,KACd,OAAO/8C,MACT,C1HuHEc,EAAW,GAAe,mB2CzI1BmxB,G6EsFqB,CACrBC,OAAO/sB,GAEL,OAAO,IAAIW,QAAQ,CAACC,EAASiW,KAC3B,IAAMmb,EAAKz2B,SAAS02B,cAAc,QAAQ,EAC1CD,EAAG6lB,aAAa,MAAO73C,CAAG,EAC1BgyB,EAAGmX,OAASvoC,EACZoxB,EAAG8lB,QAAUt9C,IACX,IAAME,EAAQgT,EAAY,kBAC1BhT,EAAM2C,WAAa7C,EACnBqc,EAAOnc,CAAK,CACd,EACAs3B,EAAGjuB,KAAO,kBACViuB,EAAG+lB,QAAU,SAhBVx8C,SAASy8C,qBAAqB,MAAM,IAAI,IAAMz8C,UAiBxB03B,YAAYjB,CAAE,CACzC,CAAC,CACF,EAED9E,WAAY,oCACZF,kBAAmB,0CACnBC,0BACE,wDACH,ECpF4BhJ,GDsFO,UCrFlCg0B,GAAkBA,mBAChB,IAAIp0C,GAAS,OAEX,CAAC+pB,EAAW,CAAEzP,QAAS+5B,MACrB,IAAM33B,EAAMqN,EAAUuqB,YAAY,KAAK,EAAE9rB,aAAY,EAC/C1F,EACJiH,EAAUuqB,YAAyB,WAAW,EAC1CvxB,EACJgH,EAAUuqB,YAAkC,oBAAoB,EAC5D,CAAE7jC,OAAAA,EAAQ+U,WAAAA,GAAe9I,EAAIpC,QAQ7BxO,GANNrB,EACEgG,GAAU,CAACA,EAAOxV,SAAS,GAAG,EAE9B,kBAAA,CAAEgP,QAASyS,EAAIjmB,IAAM,CAAA,EAGQ,CAC7Bga,OAAAA,EACA+U,WAAAA,EACApF,eAAAA,GACAhP,QAA+B,iCAC/BiJ,aAA0C,6BAC1C3H,UAAmC,QACnC2R,iBAAkBlE,GAAkBC,EAAc,IAG9C2M,EAAe,IAAIlK,GACvBnG,EACAoG,EACAC,EACAjX,CAAM,EAIR,OExBN/B,EFsB8BgjB,EEnBxB3O,GAFNi2B,EFqB4CA,IEnBlBj2B,aAAe,GACnCm2B,GACJvgD,MAAMC,QAAQmqB,CAAW,EAAIA,EAAc,CAACA,IAC5ChF,IAAyB+D,CAAY,EACnCk3B,GAAMrqC,UACRD,EAAK8c,gBAAgBwtB,EAAKrqC,QAAQ,EAMpCD,EAAKua,2BAA2BiwB,EAAWF,GAAM9vB,qBAAqB,EFUzDwI,CACR,EAEF,QAAA,EAKExsB,qBAAgD,UAAA,EAKhDK,2BACC,CAACmpB,EAAWyqB,EAAqBC,KACF1qB,EAAUuqB,6BAGlBpoC,WAAU,CAChC,CAAA,CACF,EAGLkoC,GAAAA,mBACE,IAAIp0C,GAEF,gBAAA+pB,IACE,IAAMhgB,EAAOgf,EACXgB,EAAUuqB,YAAW,MAAqB,EAAC9rB,aAAY,CAAG,EAE5D,OAAQze,EAA+BA,EAAvB,IAAIypC,GAAYzpC,CAAI,CACrC,EAEF,SAAA,EAACxJ,qBAAoB,UAA4B,CAAA,EAGpDm0C,GAAAA,gBAAgBj+C,aA3FhB2pB,IAEA,OAAQA,GACN,IAAA,OACE,MAAO,OACT,IAAA,cACE,MAAO,KACT,IAAA,SACE,MAAO,YACT,IAAA,UACE,MAAO,UACT,IAAA,eACE,MAAO,gBACT,QACE,MACH,CACH,GA2EuDA,EAAc,CAAC,EAEpEs0B,GAAAA,gBAAgBj+C,YAAe,SAAkB,EGzF5CyZ,eAAeykC,GACpB5qC,EACAozB,EACAlpB,GAGA,IAAQ2gC,EAAcb,eAEhBc,GADNhqC,EAAYsyB,EAAM0L,UAAW,wCAAwC,EAmO/DlzC,GAWqBP,IAO3B,GAJAyV,EACE,eAAeW,KAAKpW,CAAG,EACvB,wCAAwC,EAEf,aAAvB,OAAO0/C,YACT,OAAO,IAAIA,aAAcC,OAAO3/C,CAAG,EAGrC,IAAM4/C,EAAO,IAAIC,YAAY7/C,EAAIZ,MAAM,EACjC0gD,EAAO,IAAIC,WAAWH,CAAI,EAChC,IAAK1gD,IAAIC,EAAI,EAAGA,EAAIa,EAAIZ,OAAQD,CAAC,GAC/B2gD,EAAK3gD,GAAKa,EAAII,WAAWjB,CAAC,EAE5B,OAAO2gD,CACT,GA9P4C/X,EAAM0L,SAkOL,EAMrCuM,EAAM1kC,MAAM2kC,OAAOC,OAAOC,OAAO,UAAW5/C,CAAK,EAxOjC+a,MAyOhB8kC,EAAMxhD,MAAMqqC,KAAK,IAAI8W,WAAWC,CAAG,CAAC,GAC/Bh8B,IAAIq8B,GAAOA,EAAIl9C,SAAS,EAAE,EAAEm9C,SAAS,EAAG,GAAG,CAAC,EAAEzgD,KAAK,EAAE,GAxO1Dg9C,EAA2C,GAkBjD,OAjBIhyB,GAAM,EAERgyB,EAAsB,IAAI2C,EAAUpc,YAC3BzY,GAAU,EAEnBkyB,EAAsB,IAAI2C,EAAUpc,YAEpC/uB,EAAMM,EAAI,+CAIR6qC,EAAU97B,cACZm5B,EAAiC,eAAI2C,EAAU97B,aAIjDm5B,EAA4B,UAAI4C,EACzB/C,GACL/nC,EACAkK,EACAkpB,EAAMj9B,KACNrH,KAAAA,EACAskC,EAAMsC,SAAW5mC,KAAAA,EACjBo5C,CAAgB,CAEpB,CAoBM,SAAU0D,GACdC,GAGA,IAAQC,EAAY9B,aAEpB,OAAO,IAAIj3C,QAAQC,IACjB84C,EAAQC,QAAQC,WAAWC,YAAYC,IACrC3hD,IAAI4hD,EAAiC,KACjCD,EACFJ,EAAQC,QAAQC,WAAWI,QAAQP,CAAU,EAG7CM,EAASL,EAAQO,aAAalU,KAC5B0T,GvFiBiB38C,EAAKhB,IAE5B,+BAA+BuT,KAAKvS,CAAE,GACtC,+BAA+BuS,KAAKvS,CAAE,EuFnBjB,SAAW,WAC1B,cAAc,EAGlB8D,EAAQm5C,CAAM,CAChB,CAAC,CACH,CAAC,CACH,CC3FA,IAAMG,GAAoB,SAGbC,WAAgC1K,GAA7Cp1C,kCACmB/C,KAAA8iD,iBAAmB,IAAIrgB,IAEhCziC,KAAA+iD,YAAc,IAAI15C,QAAcC,IACtCtJ,KAAKgjD,mBAAqB15C,CAC5B,CAAC,CA2BF,CAzBC25C,mBAAmB7uB,GACjBp0B,KAAK8iD,iBAAiBpnB,IAAItH,CAAE,CAC7B,CAED8uB,sBAAsB9uB,GACpBp0B,KAAK8iD,iBAAiB/5B,OAAOqL,CAAE,CAChC,CAID+uB,gBACEnjD,KAAKs4C,oBAAsB,KAC3Bt4C,KAAKu4C,4BAA8B,CAAA,CACpC,CAGDM,QAAQnP,GAGN,OAFA1pC,KAAKgjD,mBAAkB,EACvBhjD,KAAK8iD,iBAAiB76C,QAAQmsB,GAAMA,EAAGsV,CAAK,CAAC,EACtC1jC,MAAM6yC,QAAQnP,CAAK,CAC3B,CAED0Z,oBACEnmC,MAAMjd,KAAK+iD,WACZ,CACF,CAKK,SAAUM,GACd/sC,EACA7J,EACAu/B,EAAyB,MAEzB,MAAO,CACLv/B,KAAAA,EACAu/B,QAAAA,EACA+J,YAAa,KACbX,WAyEJ,KACE,IAAMtd,EAAQ,GACRC,EACJ,iEACF,IAAKl3B,IAAIC,EAAI,EAAGA,EAAI8hD,GAAmB9hD,CAAC,GAAI,CAC1C,IAAMwiD,EAAMprC,KAAK8d,MAAM9d,KAAK+d,SAAW8B,EAAah3B,MAAM,EAC1D+2B,EAAMv2B,KAAKw2B,EAAan1B,OAAO0gD,CAAG,CAAC,CACpC,CACD,OAAOxrB,EAAMt2B,KAAK,EAAE,CACtB,GAlFkC,EAC9Bu8B,SAAU,KACVvhB,SAAUlG,EAAKkG,SACfpZ,MAAOgT,EAAaE,EAAkC,eAAA,EAE1D,CASOmG,eAAe8mC,GACpBjtC,GAEA,IAAMozB,EAAS,MAAM3f,GAAS,EAACG,KAC7Bs5B,GAAeltC,CAAI,CAAC,EAKtB,OAHIozB,GACFzsB,MAAM8M,GAAO,EAAGI,QAAQq5B,GAAeltC,CAAI,CAAC,EAEvCozB,CACT,CAEgB,SAAA+Z,GACdC,EACAh7C,GA0EMX,EAAS47C,GADwBj7C,EAtEMA,CAuEP,EAChCu2B,EAAOl3B,EAAa,KAAIS,mBAAmBT,EAAa,IAAC,EAAI3C,KAAAA,EAE7D85B,EAAiBykB,GAAoB1kB,CAAI,EAAQ,KAEjDE,EAAcp3B,EAAqB,aACrCS,mBAAmBT,EAAqB,YAAC,EACzC3C,KAAAA,EA9EJ,IAeQS,EACAzC,EAhBFwgD,EA+EoBD,GAAoBxkB,CAAW,EAAQ,MACrCA,GAAeD,GAAkBD,GAAQv2B,EA1ErE,OAAIk7C,EAAYp8C,SAAS,mBAAmB,GAUpCpE,GADAyC,IALAkC,EAAS47C,GAAoBC,CAAW,GAEJ,eAiDrB1lC,IACvB,IACE,OAAOpa,KAAKC,MAAMma,CAAI,CAGvB,CAFC,MAAOhb,GACP,OAAO,IACR,CACH,GAtDwBsF,mBAAmBT,EAAsB,aAAC,CAAC,EAC3D,OAC6B,MAAGO,MAAM,OAAO,IAAI,IAChC8N,EAAavQ,CAAI,EAAI,MAEjC,CACL4G,KAAMi3C,EAAaj3C,KACnBu/B,QAAS0X,EAAa1X,QACtBxvB,SAAUknC,EAAalnC,SACvBpZ,MAAAA,EACA2yC,YAAa,KACbX,UAAW,KACXrX,SAAU,MAGL,CACLtxB,KAAMi3C,EAAaj3C,KACnBu/B,QAAS0X,EAAa1X,QACtBxvB,SAAUknC,EAAalnC,SACvB44B,UAAWsO,EAAatO,UACxBW,YAAa6N,EACb7lB,SAAU,MAKT,IACT,CAaA,SAAShU,KACP,OAAOL,EAAawhB,EAAuB,CAC7C,CAEA,SAASsY,GAAeltC,GACtB,OAAOmU,EAAmB,YAAqBnU,EAAK+B,OAAO2E,OAAQ1G,EAAKtT,IAAI,CAC9E,CA4BA,SAAS2gD,GAAoBj7C,GAC3B,IAIO7B,EAAMqP,EAJb,OAAKxN,GAAKlB,SAAS,GAAG,GAIhB,CAACX,KAAMqP,GAAQxN,EAAIJ,MAAM,GAAG,EAC3BF,GAAkB8N,EAAK1U,KAAK,GAAG,CAAC,GAJ9B,EAKX,OCrJMqiD,GAAN9gD,cACW/C,KAAoBg0B,qBAAGqX,GACvBrrC,KAAAgxB,uBAAyB,CAAA,EACjBhxB,KAAAg/C,cAAgB,IAAIv1B,IACpBzpB,KAAwBi/C,yBAAkC,GAE3Ej/C,KAAmBqyB,oBAAG4lB,GACtBj4C,KAAuBmyB,wBAAGA,EAwH3B,CAtHClB,kBAAkB3a,GAChB,IAAMxP,EAAMwP,EAAK+T,OACjBxpB,IAAIqmB,EAAUlnB,KAAKg/C,cAAchnC,IAAIlR,CAAG,EAMxC,OALKogB,IACHA,EAAU,IAAI27B,GAAwBvsC,CAAI,EAC1CtW,KAAKg/C,cAAcn1B,IAAI/iB,EAAKogB,CAAO,EACnClnB,KAAK8jD,wBAAwBxtC,EAAM4Q,CAAO,GAErCA,CACR,CAED0vB,WAAWtgC,GACTN,EAAMM,EAAI,8CACX,CAEDuhC,oBACEvhC,EACAkK,EACA89B,EACAtS,GFqIuC11B,EEnIZA,EF0I7BU,EAC4C,YAA1C,OAPI+sC,EAAMzD,OAOE0D,gBAAgBj6C,UAC5BuM,EAEA,gCAAA,CACE2tC,cAAe,oCAChB,CAAA,EAIHjtC,EACyC,KAAA,IAAhC+sC,GAAK5C,WAAWpc,YACvBzuB,EAEA,gCAAA,CACE2tC,cAAe,0BAChB,CAAA,EAIHjtC,EACwD,YAAtD,OAAO+sC,GAAK3B,SAASC,SAASC,YAAYI,QAC1CpsC,EAEA,gCAAA,CACE2tC,cAAe,2BAChB,CAAA,EAEHjtC,EAC4D,YAA1D,OAAO+sC,GAAK3B,SAASC,SAASC,YAAYC,YAC1CjsC,EAEA,gCAAA,CACE2tC,cAAe,2BAChB,CAAA,EAIHjtC,EAC8C,YAA5C,OAAO+sC,GAAK3B,SAASO,cAAclU,KACnCn4B,EAEA,gCAAA,CACE2tC,cAAe,6BAChB,CAAA,EAnDC,ICjIJ3tC,ECDQ4Q,EAAUjK,MAAMjd,KAAKixB,YAAY3a,CAAI,EAWrCozB,GAVNzsB,MAAMiK,EAAQk8B,cAKdl8B,EAAQi8B,cAAa,EnB4CvB/L,GAAmBpE,MAAK,EmBzCtB/1B,MAAMjd,KAAK82C,kBAAkBxgC,CAAI,EAEnB+sC,GAAkB/sC,EAAMgoC,EAAUtS,CAAO,GAEjDtjC,GDZR4N,ECW0BA,EDV1BozB,ECUgCA,EAA9BzsB,MDRK8M,GAAS,EAACE,KAAKu5B,GAAeltC,CAAI,EAAGozB,CAAgC,ECS9DzsB,MAAMikC,GAAoB5qC,EAAMozB,EAAOlpB,CAAQ,GAE3D,OFkCG/D,MACLnG,EACA4tC,EACAzB,KAGA,IAAQL,EAAY9B,aAEhB6D,EAAU,OACd,IACElnC,MAAM,IAAI5T,QAAc,CAACC,EAASiW,KAChC1e,IAAIujD,EAA8B,KAGlC,SAASC,IAGP/6C,IACA,IAAMg7C,EAAkBlC,EAAQC,QAAQC,YAAYz4C,MACrB,YAA3B,OAAOy6C,GACTA,IAI2B,YAAzB,OAAO7B,GAAQ54C,OACjB44C,EAAO54C,MAAK,CAEf,CAED,SAAS06C,IACHH,EAAAA,GAKW7gD,OAAOic,WAAW,KAE/BD,EAAOnJ,EAAaE,EAAI,4BAA2C,CAAA,CACpE,EAvImB,GAuIE,CACvB,CAED,SAASkuC,IAC2B,YAA9BvgD,UAAUwgD,iBACZF,GAEH,CAIDL,EAAcjB,mBAAmBoB,CAAa,EAG9CpgD,SAASyzB,iBAAiB,SAAU6sB,EAAS,CAAA,CAAK,EAC9Cj4B,GAAU,GACZroB,SAASyzB,iBAAiB,mBAAoB8sB,EAAmB,CAAA,CAAK,EAIxEL,EAAU,KACRD,EAAchB,sBAAsBmB,CAAa,EACjDpgD,SAAS2zB,oBAAoB,SAAU2sB,EAAS,CAAA,CAAK,EACrDtgD,SAAS2zB,oBACP,mBACA4sB,EACA,CAAA,CAAK,EAEHJ,GACF7gD,OAAO8b,aAAa+kC,CAAY,CAEpC,CACF,CAAC,CAGF,CAFS,QACRD,GACD,CACH,GE5G6B7tC,EAAM4Q,EADhBjK,MAAMilC,GAAiBx5C,CAAG,CACK,CAC/C,CAEDquC,6BACE7a,EACAwoB,GAEA,MAAM,IAAIjkD,MAAM,yBAAyB,CAC1C,CAEDq2C,kBAAkBxgC,GAChB,IAAMxP,EAAMwP,EAAK+T,OAKjB,OAJKrqB,KAAKi/C,yBAAyBn4C,KACjC9G,KAAKi/C,yBAAyBn4C,IF9B7B2V,MAA+BnG,IACpC,IAAQ6qC,EAAcb,eAChB/jC,EAAmC,GACrCiQ,GAAM,EACRjQ,EAAQooC,YAAcxD,EAAUpc,YACvBzY,GAAU,EACnB/P,EAAQ6oB,mBAAqB+b,EAAUpc,YAEvC/uB,EAAMM,EAAI,+CAIZ2G,MAAMo8B,GAAkB/iC,EAAMiG,CAAO,CACvC,GEiB2DjG,CAAI,GAGpDtW,KAAKi/C,yBAAyBn4C,EACtC,CAEOg9C,wBACNxtC,EACA4Q,GAGA,GAAM,CAAE88B,eAAAA,EAAgBY,cAAAA,EAAezD,UAAAA,CAAW,EAAGb,GAAc,EAEnE,IAAMuE,EAAiBrlC,WAAW/C,UAGhCQ,MAAMsmC,GAAmBjtC,CAAI,EAC7B4Q,EAAQ2xB,QAAQiM,GAAe,CAAE,CAClC,EA/E4B,GA+EF,EAErBC,EAAmBtoC,MACvBuoC,IAGA3lC,aAAawlC,CAAc,EAE3B,IAAMnB,EAAezmC,MAAMsmC,GAAmBjtC,CAAI,EAClDzV,IAAIokD,EAA+B,KAC/BvB,GAAgBsB,GAAiB,MACnCC,EAAaxB,GAAwBC,EAAcsB,EAAe,GAAC,GAIrE99B,EAAQ2xB,QAAQoM,GAAcH,GAAiB,CAAA,CACjD,EAeMI,GAXsB,KAAA,IAAnBlB,GAC6B,YAApC,OAAOA,EAAej6C,WAEtBi6C,EAAej6C,UAAU,KAAMg7C,CAAgB,EAQnBH,GACxBO,EAAmBhE,EAAUpc,YAAYrmB,YAAW,EAApC,MACtB4hC,GAAgB,EAACsE,cAAgBnoC,MAAM/T,IAOrC,GANIA,EAAIgW,YAAW,EAAG5T,WAAWq6C,CAAa,GAG5CJ,EAAiB,CAAEr8C,IAAAA,CAAG,CAAE,EAGW,YAAjC,OAAOw8C,EACT,IACEA,EAAsBx8C,CAAG,CAI1B,CAHC,MAAOxF,GAEPC,QAAQC,MAAMF,CAAC,CAChB,CAEL,CACD,CACF,CAQM,IAAMkiD,GACXvB,GAEF,SAASiB,KACP,MAAO,CACLr4C,KAA2B,UAC3Bu/B,QAAS,KACToJ,UAAW,KACXW,YAAa,KACbhY,SAAU,KACVvhB,SAAU,KACVpZ,MAAOgT,EAAyC,eAAA,EAEpD,KCnI4BpK,ECtC5B,SAASyL,KACP,OAAOnU,MAAMgU,UAAUI,UAAY,IACrC,CAcgB,SAAA2tC,GAA6B7/C,EAAahB,KACxD,MAAO,EACoB,UAAxBiT,GAAiB,GACQ,WAAxBA,GAAmB,GACK,eAAxBA,GAAmB,GACrBjS,CAAAA,EAAGkZ,YAAa,EAACxa,MAAM,0BAA0B,EAErD,CAgCA,SAASohD,GAA+B9/C,EAAahB,KACnD,OAlBOe,EAAM,GAA+B,KAA3BtB,UAAUwmC,eAkBP8a,CAVL//C,EAAahB,KAUR+gD,CAAQ//C,GATrB,YAAYuS,KAAKvS,CAAE,EAU5B,CAGgB,SAAAggD,KACd,IACE,IAAMz7B,EAAUzmB,KAAKmmC,aACf3iC,EAAM2+C,KACZ,GAAI17B,EAUF,OAPAA,EAAiB,QAAEjjB,EAAK,GAAG,EAC3BijB,EAAoB,WAAEjjB,CAAG,EAMrBw+C,CAAAA,GAA8B,GAGzB5/C,EAAoB,CAQhC,CAJC,MAAOxC,GAGP,OAAO2qC,GAAS,GAAMnoC,GACvB,CACD,MAAO,CAAA,CACT,CAMgB,SAAAmoC,KAEd,MACoB,aAAlB,OAAOrqC,QACP,sBAAuBA,QACvB,kBAAmBA,MAEvB,CAEgB,SAAAkiD,KACd,OA/F+B,UAAxBjuC,GAAiB,GAA0C,WAAxBA,GAAiB,GAiGvDzS,EAAoB,GACpBqgD,GAA8B,IAGhC,EA/EK//C,EAAa,GAAMZ,MAkFxB8gD,GAAwB,GAExB,CAAC3X,GAAS,CAEd,CAGgB,SAAA8X,KACd,OAAON,GAA8B,GAAwB,aAApB,OAAOphD,QAClD,CCvIO,IAAM2hD,EAAc,CACzBC,MAAO,QACPC,KAAM,OACNC,QAAS,WAGL/uC,GAA8BgvC,EAE9BC,GAAkB,cAqDjBxpC,eAAeypC,GACpB5vC,GAEA2G,MAAM3G,EAAK2Z,uBACX,IAAM8X,EAAUoe,KACVr/C,EAAMs/C,EACVH,GACA3vC,EAAK+B,OAAO2E,OACZ1G,EAAKtT,IAAI,EAEP+kC,GACFA,EAAQsB,QAAQviC,EAAKwP,EAAK6I,oBAAqB,CAAA,CAEnD,CA2BA,SAASgnC,KACP,IACE,ODqDuB,aAAlB,OAAO5iD,OAAyBA,OAAS,OCrDrB6nC,gBAAkB,IAG5C,CAFC,MAAOloC,GACP,OAAO,IACR,CACH,CC5GA,IAAM8T,GAA8BgvC,QAGvBK,EAAbtjD,cAImB/C,KAAesmD,gBAC9BC,EAAiBC,EAAgC,EAClCxmD,KAAeymD,gBAC9BF,EAAiBG,EAAgC,EAE3C1mD,KAAkB2mD,mBAA6C,KACvE3mD,KAAAg0B,qBAAuB4yB,GAEvB5mD,KAAAqyB,oBAI0Cw0B,GAC1C7mD,KAAAmyB,wBAA0B20B,EAqE3B,CAnEC71B,kBAAkB3a,GAEhB,OADA2G,MAAMjd,KAAK+mD,2BACJ/mD,KAAKgnD,2BAA2B/1B,YAAY3a,CAAI,CACxD,CAEDsgC,iBACEtgC,EACAkK,EACA89B,EACAtS,GAGA,OADA/uB,MAAMjd,KAAK+mD,2BACJ/mD,KAAKgnD,2BAA2BpQ,WACrCtgC,EACAkK,EACA89B,EACAtS,CAAO,CAEV,CAED6L,oBACEvhC,EACAkK,EACA89B,EACAtS,GAGA,OADA/uB,MAAMjd,KAAK+mD,2BACJ/mD,KAAKgnD,2BAA2BnP,cACrCvhC,EACAkK,EACA89B,EACAtS,CAAO,CAEV,CAED+K,6BACEzgC,EACA8d,GAEAp0B,KAAKgnD,2BAA2BjQ,6BAA6BzgC,EAAM8d,CAAE,CACtE,CAED0iB,kBAAkBxgC,GAChB,OAAOtW,KAAKgnD,2BAA2BlQ,kBAAkBxgC,CAAI,CAC9D,CAED0a,6BACE,OAAO20B,GAAkB,GAAI3lD,KAAKsmD,gBAAgBt1B,sBACnD,CAEDg2B,iCAEE,OADAhwC,GAAQhX,KAAK2mD,qCACN3mD,KAAK2mD,kBACb,CAEOI,iCACN,IAMME,EANFjnD,KAAK2mD,qBAMHM,EAAYhqC,MFuDf0oC,CAAAA,CAAAA,GAAgB,GAId,IAAIt8C,QAAQC,IACjB,IAAM49C,EAAY1nC,WAAW,KAE3BlW,EAAQ,CAAA,CAAK,CACd,EAtIoC,GAsIF,EAEnCrF,SAASyzB,iBAAiB,cAAe,KACvCrY,aAAa6nC,CAAS,EACtB59C,EAAQ,CAAA,CAAI,CACd,CAAC,CACH,CAAC,GEpECtJ,KAAK2mD,mBAAqBM,EACtBjnD,KAAKymD,gBACLzmD,KAAKsmD,gBACV,CACF,CClFK,SAAUa,GAAUxwC,GACxB,OAAQA,EAAsBwwC,QAChC,CCCA,SAASC,GAAuB9wC,EAAgBpT,GAG9C,IhD+FAE,EAEMoiC,EACA6hB,EgDlGApuC,EAAY/V,EAAE6C,YAChB6Z,eAC+B,oCAA9B1c,GAAqB2C,KACT3C,EACR6wB,SAAW,IAAIuzB,GACpBhxC,GhD0FJlT,EgDzFqCF,EhD2F/BsiC,EAAc76B,EgD3FW2L,ChD2FY,EAE3CU,GADMqwC,EAAgBjkD,GAEd2C,WAAWm8B,cACjBsD,EAAW,gBAAA,EAGbxuB,EACEqwC,EAActhD,WAAW8Y,iBAAiB8oB,qBAC1CnC,EAAW,kBAINsC,GAAwBI,WAAW1C,EAAa6hB,CAAa,EgDxGL,EAEpDpuC,IACHqmB,EAAaioB,GACbC,EAAUtkD,CADyB,KAGvCskD,EAAQloB,WAAaA,EACrBkoB,EAAQhrC,SAAWvD,EAASuD,UAAYpX,KAAAA,EACxCoiD,EAAQ9nC,MAAQzG,EAASyG,OAASta,KAAAA,EAClCoiD,EAAQ7nC,YAAc1G,EAAS0G,aAAeva,KAAAA,EAGpD,CAEA,SAASmiD,GACP5wC,GAEA,IAAQiJ,GACNjJ,aAAkB/Q,EAAgB+Q,EAAO5Q,WAAa4Q,GADlC,eAGtB,GAAI,CAACiJ,EACH,OAAO,KAMT,GAAI,EAAEjJ,aAAkB/Q,IAClB,mBAAoBga,GAAkB,gBAAiBA,EACzD,OAAO6nC,EAAsB7mB,qBAAqBjqB,CAAM,EAI5D,IAAMkO,EAAajF,EAAeiF,WAIlC,GAAI,CAACA,GAAcA,IAAe6iC,GAAej6C,SAC/C,OAAO,KAGT5M,IAAI2f,EAIJ,OAAQqE,GACN,KAAK6iC,GAAel6C,OAClBgT,EAAWmnC,EACX,MACF,KAAKD,GAAep6C,SAClBkT,EAAWonC,EACX,MACF,KAAKF,GAAen6C,OAClBiT,EAAWqnC,EACX,MACF,KAAKH,GAAe/5C,QAClB6S,EAAWsnC,EACX,MACF,QACE,GAAM,CACJ7mB,aAAAA,EACAC,iBAAAA,EACAvD,iBAAAA,EACAL,aAAAA,EACAG,MAAAA,CACD,EAAG7d,EACJ,OACGshB,GACAvD,GACAsD,GACA3D,EAKCA,EACEzY,EAAW/Z,WAAW,OAAO,EACxBi9C,GAAuBpmB,QAAQ9c,EAAYyY,CAAY,EAGvD0qB,EAAoBzqB,YAAY,CACrC1Y,WAAAA,EACAmX,aAAcnX,EACdyY,aAAAA,EACArZ,QAASgd,EACTlb,YAAamb,CACd,CAAA,EAGE,IAAI+mB,GAAkBpjC,CAAU,EAAEya,WAAW,CAClDrb,QAASgd,EACTlb,YAAamb,EACbP,SAAUlD,CACX,CAAA,EArBQ,IAsBZ,CAED,OAAO9mB,aAAkB/Q,EACrB4a,EAASugB,oBAAoBpqB,CAAM,EACnC6J,EAASogB,qBAAqBjqB,CAAM,CAC1C,CAEgB,SAAAuxC,EACd5xC,EACA6xC,GAEA,OAAOA,EACJ1+C,MAAMvG,IAIL,MAHIA,aAAa0C,GACfwhD,GAAuB9wC,EAAMpT,CAAC,EAE1BA,CACR,CAAC,EACAsG,KAAK81B,IACJ,IAAM4C,EAAgB5C,EAAW4C,cAC3BjgB,EAAOqd,EAAWrd,KAExB,MAAO,CACLigB,cAAAA,EACA5C,WAlICioB,GAmICjoB,CAAwC,EAE1C8oB,mBAAoBC,GAClB/oB,CAAgC,EAElCrd,KAAMqmC,EAAKC,YAAYtmC,CAAI,EAE/B,CAAC,CACL,CAEOxF,eAAe+rC,GACpBlyC,EACAmyC,GAEA,IAAMC,EAAwBzrC,MAAMwrC,EACpC,MAAO,CACLpqB,eAAgBqqB,EAAsBrqB,eACtCwV,QAAS,GACPqU,EAAkB5xC,EAAMoyC,EAAsB7U,QAAQvV,CAAgB,CAAC,EAE7E,OAEMgpB,GAEJvkD,YACEuT,EACiByd,GAAA/zB,KAAQ+zB,SAARA,EAEjB/zB,KAAKsW,KAAeA,ED1JeqyC,SC2JpC,CAED5gB,cACE,OAAO/nC,KAAK+zB,SAASgU,OACtB,CAEDC,YACE,OAAOhoC,KAAK+zB,SAASiU,KACtB,CAEDK,cACEpxB,GAEA,OAAOixC,EACLf,GAAOnnD,KAAKsW,IAAI,EAChBtW,KAAK+zB,SAASsU,cAAcpxB,CAAqC,CAAC,CAErE,CACF,OClLYqxC,EAOXvlD,YAA6B6H,G/CiFzB,IACEg+C,E+ClFuB5oD,KAAS4K,UAATA,EAC3B5K,KAAK6oD,a/CiFDD,EAAcj+C,E+CjFiBC,C/CiFM,EACtCo+B,GAAqBhG,IAAI4lB,CAAW,GACvC5f,GAAqBnf,IACnB++B,EACApgB,GAAoBE,UAAUkgB,CAA2B,CAAC,EAGvD5f,GAAqBhxB,IAAI4wC,CAAW,E+CvF1C,CAEDL,mBAAmBtmC,GAKjB,OAJKqmC,EAAKQ,SAAS9lB,IAAI/gB,CAAI,GACzBqmC,EAAKQ,SAASj/B,IAAI5H,EAAM,IAAIqmC,EAAKrmC,CAAI,CAAC,EAGjCqmC,EAAKQ,SAAS9wC,IAAIiK,CAAI,CAC9B,CAED8G,SACE,OAAO/oB,KAAK4K,UAAUme,QACvB,CACDR,SACE,OAAOvoB,KAAK4K,UAAU2d,QACvB,CACD1E,SACE,OAAO7jB,KAAK4K,UAAUiZ,QACvB,CACDiE,iBAAiBxB,GACf,OAAOtmB,KAAK4K,UAAUkd,iBAAiBxB,CAAY,CACpD,CACDlD,WAAWkD,GACT,OAAOtmB,KAAK4K,UAAUwY,WAAWkD,CAAY,CAC9C,CACDyiC,kCACEzpB,GAEA,OAAOt/B,KAAKujC,mBAAmBjE,CAAU,CAC1C,CACDiE,yBACEjE,GAEA,OAAO4oB,EACLloD,KAAKsW,KACL0yC,GAAuBhpD,KAAK4K,UAAW00B,CAAgC,CAAC,CAE3E,CACD2pB,0BACEtpC,EACAm1B,GAEA,OAAO0T,GACLxoD,KAAKsW,MhCqFJmG,MACLwF,EACAtC,EACAupC,KAEA,IAAMnhC,EAAepd,EAAmBsX,CAAI,EAC5ChF,MAAM2lB,GAAoB,CAAA,EAAO7a,WACjC,IAAMsW,EAAiBphB,MAAM82B,GAC3BhsB,EAAazR,KACbqJ,EACAhV,EAAmBu+C,CAA0C,CAAC,EAEhE,OAAO,IAAIvV,GAAuBtV,EAAgBb,GAChD+F,GAAmBxb,EAAcyV,CAAI,CAAC,CAE1C,GgCnG8Bx9B,KAAK4K,UAAW+U,EAAam1B,CAAmB,CAAC,CAE5E,CACDqU,oBACE3oC,GAEA,OAAO0nC,EACLloD,KAAKsW,M3BqGJmG,MACLwF,EACAzB,EACAuT,KAEA,IAAMhM,EAAepd,EAAmBsX,CAAI,EAEtC21B,GADNlhC,GAAkBqR,EAAazR,KAAMkK,EAAUof,CAAqB,EAC3CmV,GAAqBhtB,EAAazR,KAAMyd,CAAQ,GASzE,OAPe,IAAIuiB,EACjBvuB,EAAazR,KAAI,eAEjBkK,EACAo3B,EACA7vB,CAAY,EAEA4uB,gBAChB,G2BpHQ32C,KAAK4K,UACL4V,EACA6lC,CAA2B,CAC5B,CAEJ,CACDrO,uBAAuBx3B,GAErB,OADAvD,MAAMipC,GAA4BkD,EAAcppD,KAAKsW,IAAI,CAAC,EACnD+yC,GACLrpD,KAAK4K,UACL4V,EACA6lC,CAA2B,CAE9B,CACDiD,4CACEhqB,GAEA,OAAOt/B,KAAKwjC,6BAA6BlE,CAAU,CACpD,CACDkE,mCACElE,GAEA,OAAO4oB,EACLloD,KAAKsW,KACLizC,GACEvpD,KAAK4K,UACL00B,CAAgC,CACjC,CAEJ,CACDkqB,8BACE7pC,EACAm1B,GAEA,OAAO0T,GACLxoD,KAAKsW,MhCwEJmG,MACLwF,EACAtC,EACAupC,KAEA,IAAMnhC,EAAepd,EAAmBsX,CAAI,EAC5C,IAKMoc,EALN,OAAIrV,wBAAqBjB,EAAazR,KAAK2S,GAAG,EACrC5f,QAAQkW,OACb9I,EAAgDsR,EAAazR,IAAI,CAAC,GAGhE+nB,EAAiBphB,MAAM82B,GAC3BhsB,EAAazR,KACbqJ,EACAhV,EAAmBu+C,CAA0C,CAAC,EAEzD,IAAIvV,GAAuBtV,EAAgBb,GAChDgG,GAA6Bzb,EAAcyV,CAAI,CAAC,EAEpD,GgCzFQx9B,KAAK4K,UACL+U,EACAm1B,CAAmB,CACpB,CAEJ,CACD2U,wBACEjpC,GAEA,OAAO0nC,EACLloD,KAAKsW,M3BIJmG,MACLwF,EACAzB,EACAuT,KAEA,IAAMhM,EAAepd,EAAmBsX,CAAI,EAC5C,GAAI+G,wBAAqBjB,EAAazR,KAAK2S,GAAG,EAC5C,OAAO5f,QAAQkW,OACbnJ,EAAa2R,EAAazR,KAA4C,6CAAA,CAAA,EAG1EI,GAAkBqR,EAAazR,KAAMkK,EAAUof,CAAqB,EACpE,IAAMgY,EAAmB7C,GAAqBhtB,EAAazR,KAAMyd,CAAQ,EAQzE,OAPe,IAAIuiB,EACjBvuB,EAAazR,KAAI,iBAEjBkK,EACAo3B,EACA7vB,CAAY,EAEA4uB,gBAChB,G2BvBQ32C,KAAK4K,UACL4V,EACA6lC,CAA2B,CAC5B,CAEJ,CACDvO,iCACEt3B,GAGA,OADAvD,MAAMipC,GAA4BkD,EAAcppD,KAAKsW,IAAI,CAAC,EACnDozC,GACL1pD,KAAK4K,UACL4V,EACA6lC,CAA2B,CAE9B,CACDlgB,sBACE7B,GAEA,OAAOqlB,GAA0B3pD,KAAK4K,UAAW05B,CAAkB,CACpE,CACD3B,aAAa9d,GAEX,OADA5H,MAAM2sC,GAAW5pD,KAAK4K,UAAWia,CAAU,EACpC7kB,IACR,CACD6pD,YAAYlkB,GACV,OrD9DwB1jB,EqD8DDjiB,KAAK4K,UrD9DQ+6B,EqD8DGA,ErD7DnC5d,EAAepd,EAAmBsX,CAAI,EACxC+G,wBAAqBjB,EAAazR,KAAK2S,GAAG,EACrC5f,QAAQkW,OACb9I,EAAgDsR,EAAazR,IAAI,CAAC,EAG/DkwB,GAAsBze,EAAc4d,EAAU,IAAI,EAP3C,IAAY1jB,EACpB8F,CqD8DL,CACD+hC,eAAeC,GACb,OrDzCKvjB,GACL77B,EqDwC0B3K,KAAK4K,SrDxCR,EACvB,KqDuC0Cm/C,CrDtC/B,CqDuCZ,CACDC,kBAAkBC,GAChB,OhCwRGxtC,MACLwF,EACAqd,KAEA,IAAMvX,EAAepd,EAAmBsX,CAAI,EAC5C,GAAI+G,wBAAqBjB,EAAazR,KAAK2S,GAAG,EAC5C,OAAO5f,QAAQkW,OACb9I,EAAgDsR,EAAazR,IAAI,CAAC,EAGtE2G,MAAMgmB,GAAMlb,EAAcuX,CAAU,CACtC,GgClSMt/B,KAAK4K,UACLq/C,CAA0C,CAE7C,CACD5jB,cAAcM,GAIZ,OAAOujB,GAAkBlqD,KAAK4K,UAAW+7B,CAAO,CACjD,CACDP,wBACET,EACArB,GAEA,OAAO6lB,GACLnqD,KAAK4K,UACL+6B,EACArB,CAAkB,CAErB,CACD9e,oBACE,OAAOxlB,KAAK4K,UAAU4a,aACvB,CACDR,kBACE,OAAOhlB,KAAK4K,UAAUoa,WACvB,CACDpB,eACE,OAAO5jB,KAAK4K,UAAUgZ,QACvB,CACDjE,kBACE,OAAO3f,KAAK4K,UAAU+U,WACvB,CACD6E,mBACE,OAAOxkB,KAAK4K,UAAU4Z,YACvB,CACDsB,mBACE,OAAO9lB,KAAK4K,UAAUkb,YACvB,CACDtJ,eACE,OAAOxc,KAAK4K,UAAU4R,QACvB,CACD6I,kBACE,OAAOrlB,KAAK4K,UAAUya,WACvB,CACD3F,YACE,OAAO1f,KAAK4K,UAAU8U,KACvB,CACD4F,eACE,OAAOtlB,KAAK4K,UAAU0a,QACvB,CACDT,iBACE,OAAO7kB,KAAK4K,UAAUia,UACvB,CACDM,UACE,OAAOnlB,KAAK4K,UAAUua,GACvB,CACD7O,WACE,OAAQtW,KAAK4K,UAA2B0L,IACzC,EAvMuBgyC,EAAAQ,SAAW,IAAI7f,QCQzC,IAAMjyB,GAA8BgvC,QAEvBoE,GAMXrnD,YAAqBkmB,EAAkBzI,GACrC,IAMQxD,EAYF+W,EAnBa/zB,KAAGipB,IAAHA,EACfzI,EAAS6pC,gBACXrqD,KAAK4K,UAAY4V,EAASuU,gBAKpB/X,EAAWiM,EAAIpC,QAAT,OAEd7P,GAAQgG,EAA2C,kBAAA,CACjDxG,QAASyS,EAAIjmB,IACd,CAAA,EAGDgU,GAAQgG,EAA2C,kBAAA,CACjDxG,QAASyS,EAAIjmB,IACd,CAAA,EAGK+wB,EACc,aAAlB,OAAOxwB,OAAyB8iD,EAA8BjhD,KAAAA,EAChEpF,KAAK4K,UAAY4V,EAAS/H,WAAW,CACnCoO,QAAS,CACP8D,aAwSR,CACE3N,EACAxG,KAMA,IAAM8zC,GLpRQ,CACdttC,EACAxG,KAEA,IAAMuxB,EAAUoe,KAChB,GAAI,CAACpe,EACH,MAAO,GAGT,IAAMjhC,EAAMs/C,EAAwBH,GAAiBjpC,EAAQxG,CAAO,EAGpE,OAFoBuxB,EAAQwB,QAAQziC,CAAG,GAGrC,KAAK8+C,EAAYE,KACf,MAAO,CAACyE,IACV,KAAK3E,EAAYC,MACf,MAAO,CAAC2E,GAA+B5D,IACzC,KAAKhB,EAAYG,QACf,MAAO,CAACa,IACV,QACE,MAAO,EACV,CACH,GK8PoD5pC,EAAQxG,CAAO,EAWjE,GAPkB,aAAhB,OAAOlT,MACNgnD,EAAa9iD,SAASgjD,EAA6B,GAEpDF,EAAa/oD,KAAKipD,EAA6B,EAI3B,aAAlB,OAAOjnD,OACT,IAAK,IAAMonB,IAAe,CACxB8/B,GACA7D,IAEK0D,EAAa9iD,SAASmjB,CAAW,GACpC2/B,EAAa/oD,KAAKopB,CAAW,EAUnC,OAJK2/B,EAAa9iD,SAAS+iD,EAAuB,GAChDD,EAAa/oD,KAAKgpD,EAAuB,EAGpCD,CACT,GA5U+CttC,EAAQiM,EAAIjmB,IAAI,EACvD8tB,sBAAuBiD,CACxB,CACF,CAAA,EAED/zB,KAAK4K,UAAUwoB,gBAAgBs3B,EAAiB,GAChD1qD,KAAK2qD,mBAAkB,CACxB,CAEDptC,qBACE,OAAOvd,KAAK4K,UAAU2S,cACvB,CAED6E,kBACE,OAAKpiB,KAAK4K,UAAUwX,YAIbkmC,EAAKC,YAAYvoD,KAAK4K,UAAUwX,WAAW,EAHzC,IAIV,CACDhF,mBACE,OAAOpd,KAAK4K,UAAUwS,YACvB,CACDA,iBAAiBA,GACfpd,KAAK4K,UAAUwS,aAAeA,CAC/B,CACDqT,eACE,OAAOzwB,KAAK4K,UAAU6lB,QACvB,CACDjU,eACE,OAAOxc,KAAK4K,UAAU4R,QACvB,CACDA,aAAakiC,GACX1+C,KAAK4K,UAAU4R,SAAWkiC,CAC3B,CACDnsB,oBACEvyB,KAAK4K,UAAU2nB,mBAChB,CACDlQ,UACE,OAAOriB,KAAK4K,UAAUyX,SACvB,CACDuoC,YAAYliD,EAAame,GACvBgkC,GAAwB7qD,KAAK4K,UAAWlC,EAAKme,CAAO,CACrD,CACDye,gBAAgBz/B,GACd,OAAOilD,GAAoB9qD,KAAK4K,UAAW/E,CAAI,CAChD,CAED0/B,gBAAgB1/B,GACd,OAAOklD,GAAoB/qD,KAAK4K,UAAW/E,CAAI,CAChD,CAEDmlD,qBAAqBnlD,EAAckkD,GACjC,OzDeGttC,MACLnG,EACA4mB,EACA6sB,KAEA9sC,MAAMguC,GACWtgD,EAAmB2L,CAAI,EAAG,CACvC4mB,QAAAA,EACA6sB,YAAAA,EACD,EACAtgD,MAAMgT,MAAMrZ,IAQX,KALE,6CADAA,EAAMyC,MAGDw/B,GAAsB/uB,CAAI,EAG3BlT,CACR,CAAC,CAEL,GyDpCoCpD,KAAK4K,UAAW/E,EAAMkkD,CAAW,CAClE,CAEDmB,qCACExrC,EACAgP,GAEA,OAAOw5B,EACLloD,KAAK4K,WzDmJJ6R,MACLnG,EACAoJ,EACAgP,KAEA,IAKM3P,EAwBA8hB,EA7BN,OAAI7X,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,GAiBnD2C,EAAWgE,MAPgCoc,EAP3Cta,EAAeuW,EAAUhf,CAAI,EACJ,CAC7B6mB,kBAAmB,CAAA,EACnBzd,MAAAA,EACAgP,SAAAA,EACA6J,WAAmC,mBAI5B,iBAEPyJ,GAAM,2BAG8Bv4B,MAAMrG,IAO1C,KALiB,6CAAfA,EAAMyC,MAEDw/B,GAAsB/uB,CAAI,EAG3BlT,CACR,CAAC,EAEKy9B,EAAiB5jB,MAAMglB,EAAmB5Y,qBAC9CtK,EAAY,SAEZ9F,CAAQ,EAEVgE,MAAM8B,EAAasS,mBAAmBwP,EAAe5e,IAAI,EAElD4e,EACT,GyD5LyC7gC,KAAK4K,UAAW8U,EAAOgP,CAAQ,CAAC,CAEtE,CACDy8B,uBAAuBzrC,GACrB,OAAO1f,KAAK+lC,2BAA2BrmB,CAAK,CAC7C,CACDqmB,2BAA2BrmB,GACzB,OAAO0rC,GAA+BprD,KAAK4K,UAAW8U,CAAK,CAC5D,CACD2rC,sBAAsB7rB,GACpB,OAAiCx/B,KAAK4K,UCdQ40B,EDcGA,ECZpB,iBADTZ,GAAcI,UAAUQ,CAAS,GACjCd,SDarB,CACD4sB,0BACEt0C,GACE0uC,GAA2B,EAC3B1lD,KAAK4K,yD1B2JT0L,E0BvJItW,KAAK4K,U1BwJTmpB,E0BvJIsyB,E1ByJJppC,MAAMqY,EAAUhf,CAAI,EAAE2Z,uB0B3JpB,I1BwJF3Z,EACAyd,E0BzJQuL,EAAariB,M1B4Jdg7B,GAAmB3hC,EAAMyd,EAAU,CAAA,CAAK,E0BxJ7C,OAAKuL,EAME4oB,EAAkBloD,KAAK4K,UAAWvB,QAAQC,QAAQg2B,CAAU,CAAC,EAL3D,CACLA,WAAY,KACZrd,KAAM,KAIX,CAKDspC,uBAAuB92B,GE7GvBa,EF8G6Bt1B,KAAK4K,SE9GpB,EAAE4pB,cF8G6BC,CE9GN,CF+GtC,CAEDpB,mBACErpB,EACAwhD,EACAl4B,GAEA,GAAM,CAAE5pB,KAAAA,EAAMtG,MAAAA,EAAO0G,SAAAA,CAAQ,EAAK2hD,GAChCzhD,EACAwhD,EACAl4B,CAAS,EAEX,OAAOtzB,KAAK4K,UAAUyoB,mBAAmB3pB,EAAOtG,EAAO0G,CAAQ,CAChE,CACD2pB,iBACEzpB,EACAwhD,EACAl4B,GAEA,GAAM,CAAE5pB,KAAAA,EAAMtG,MAAAA,EAAO0G,SAAAA,CAAQ,EAAK2hD,GAChCzhD,EACAwhD,EACAl4B,CAAS,EAEX,OAAOtzB,KAAK4K,UAAU6oB,iBAAiB/pB,EAAOtG,EAAO0G,CAAQ,CAC9D,CACD6yB,sBACEjd,EACA4kB,GAEA,OCpHG7nB,MACLnG,EACAoJ,EACA4kB,KAEA,IAAMvlB,EAAeuW,EAAUhf,CAAI,EACnC,IAAMiG,EAAkC,CACtCmpB,YAA6C,eAC7ChmB,MAAAA,EACA6Y,WAAmC,mBAGnChc,EAgBoBA,EAbpBvF,GAFAstB,EAe6BA,GAZRI,gBACnB3lB,oBAGEulB,GACFD,GACEtlB,EACAxC,EACA+nB,CAAkB,EAKxBrnB,MAAMoc,EACJta,EACAxC,eAEAmvC,GAAyB,0BAG7B,GDgFqC1rD,KAAK4K,UAAW8U,EAAO4kB,CAAkB,CAC3E,CACD5H,uBACEhd,EACA4kB,GAEA,OzDlGG7nB,MACLnG,EACAoJ,EACA4kB,KAEA,IAAMvlB,EAAeuW,EAAUhf,CAAI,EAC7BiG,EAA+C,CACnDmpB,YAA+C,iBAC/ChmB,MAAAA,EACA6Y,WAAmC,mBAEjC+L,GACFD,GAAgCtlB,EAAcxC,EAAS+nB,CAAkB,EAE3ErnB,MAAMoc,EACJta,EACAxC,eAEAovC,GAAqC,0BAGzC,GyD8EM3rD,KAAK4K,UACL8U,EACA4kB,GAAsBl/B,KAAAA,CAAS,CAElC,CACDkmB,qBAAqBX,GL9KP,IACdrU,EACAqU,EADArU,EK8K+BtW,KAAK4K,UL7KpC+f,EK6K+CA,EL3K/C3T,GACEpS,OAAOgnD,OAAOhG,CAAW,EAAEp+C,SAASmjB,CAAW,EAC/CrU,8BAIEhR,EAAa,EAEf0R,GACE2T,IAAgBi7B,EAAYG,QAC5BzvC,EAAI,8BAAA,EAKJ5R,EAAM,EAERsS,GACE2T,IAAgBi7B,EAAYE,KAC5BxvC,EAAI,8BAAA,EAKJu3B,GAAS,EAGX72B,GACE2T,IAAgBi7B,EAAYE,MACzBn7B,IAAgBi7B,EAAYC,OAASngD,EAAsB,EAC9D4Q,EAAI,gCAMRU,GACE2T,IAAgBi7B,EAAYE,MAAQN,KACpClvC,EAAI,gCKsIJzV,IAAIgrD,EACJ,OAAQlhC,GACN,KAAKi7B,EAAYG,QACf8F,EAAYjF,GACZ,MACF,KAAKhB,EAAYC,MAEf,IAAMiG,EAA4B7uC,MAAM8uC,EACCvB,EAA6B,EACnExgC,eACH6hC,EAAYC,EACRtB,GACAC,GACJ,MACF,KAAK7E,EAAYE,KACf+F,EAAYtB,GACZ,MACF,QACE,OAAOyB,EAA4C,iBAAA,CACjDx1C,QAASxW,KAAK4K,UAAU5H,IACzB,CAAA,CACJ,CAED,OAAOhD,KAAK4K,UAAU0gB,eAAeugC,CAAS,CAC/C,CAEDI,oCACE3sB,GAEA,OAAOt/B,KAAKsjC,qBAAqBhE,CAAU,CAC5C,CACD4sB,oBACE,OAAOhE,EACLloD,KAAK4K,WG5MJ6R,MAAiCnG,IACtC,IAKMyI,EAaA8hB,EAlBN,OAAI7X,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,GAIzD2G,MADM8B,EAAeuW,EAAUhf,CAAI,GAChB2Z,uBACflR,EAAaqD,aAAa4C,YAErB,IAAIid,EAAmB,CAC5BhgB,KAAMlD,EAAaqD,YACnByC,WAAY,KACZqd,cAAoC,QACrC,CAAA,GAEGjpB,EAAWgE,MAAM+kB,GAAOjjB,EAAc,CAC1Coe,kBAAmB,CAAA,CACpB,CAAA,EACK0D,EAAiB5jB,MAAMglB,EAAmB5Y,qBAC9CtK,EAEA,SAAA9F,EACA,CAAA,CAAI,EAENgE,MAAM8B,EAAasS,mBAAmBwP,EAAe5e,IAAI,EAClD4e,GACT,GHkL4B7gC,KAAK4K,SAAS,CAAC,CAExC,CACD04B,qBACEhE,GAEA,OAAO4oB,EACLloD,KAAK4K,UACLuhD,GAAyBnsD,KAAK4K,UAAW00B,CAAgC,CAAC,CAE7E,CACDmE,sBAAsBl7B,GACpB,OAAO2/C,EACLloD,KAAK4K,UACLwhD,GAA0BpsD,KAAK4K,UAAWrC,CAAK,CAAC,CAEnD,CACD8jD,2BACE3sC,EACAgP,GAEA,OAAOw5B,EACLloD,KAAK4K,WzD8ET0L,EyD7EmCtW,KAAK4K,UzD8ExC8U,EyD9EmDA,EzD+EnDgP,EyD/E0DA,EzDiFtD1F,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,EAGlDgtB,GACL34B,EAAmB2L,CAAI,EACvB8oB,GAAkBE,WAAW5f,EAAOgP,CAAQ,CAAC,EAC7CjlB,MAAMgT,MAAMrZ,IAOZ,KALiB,6CAAfA,EAAMyC,MAEDw/B,GAAsB/uB,CAAI,EAG3BlT,CACR,CAAC,EyDjGkE,EzD4ErD,IACdkT,CyD3EC,CACDg2C,oBACE5sC,EACA8f,GAEA,OAAO0oB,EACLloD,KAAK4K,WCvGJ6R,MACLnG,EACAoJ,EACA8f,KAEA,IAKMgG,EACAlG,EANN,OAAItW,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,GAGnDkvB,EAAc76B,EAAmB2L,CAAI,EAO3CU,GANMsoB,EAAaF,GAAkBG,mBACnC7f,EACA8f,GAAanoB,GAAc,CAAE,GAKlB0lB,aAAeyI,EAAYhpB,UAAY,MAClDgpB,wBAGKlC,GAAqBkC,EAAalG,CAAU,EACrD,GDiF8Bt/B,KAAK4K,UAAW8U,EAAO8f,CAAS,CAAC,CAE5D,CACD+sB,sBACE5sC,EACAm1B,GAEA,OAAO0T,GACLxoD,KAAK4K,WjC1JJ6R,MACLnG,EACAqJ,EACAupC,KAEA,GAAIlgC,GAAoBA,qBAAC1S,EAAK2S,GAAG,EAC/B,OAAO5f,QAAQkW,OACb9I,EAAgDH,CAAI,CAAC,EAGzD,IAAMyI,EAAeuW,EAAUhf,CAAI,EACnC,IAAM+nB,EAAiBphB,MAAM82B,GAC3Bh1B,EACAY,EACAhV,EAAmBu+C,CAA0C,CAAC,EAEhE,OAAO,IAAIvV,GAAuBtV,EAAgBb,GAChD8F,GAAqBvkB,EAAcye,CAAI,CAAC,CAE5C,GiCyIQx9B,KAAK4K,UACL+U,EACAm1B,CAAmB,CACpB,CAEJ,CACD0X,sBACEhsC,GAOA,OALAxJ,GACE0uC,GAA2B,EAC3B1lD,KAAK4K,yDAGAs9C,EACLloD,KAAK4K,W5BpNJ6R,MACLnG,EACAkK,EACAuT,KAEA,IAKMhV,EAEA64B,EAPN,OAAI5uB,GAAoBA,qBAAC1S,EAAK2S,GAAG,EACxB5f,QAAQkW,OACbnJ,EAAaE,EAA4C,6CAAA,CAAA,GAGvDyI,EAAeuW,EAAUhf,CAAI,EACnCI,GAAkBJ,EAAMkK,EAAUof,CAAqB,EACjDgY,EAAmB7C,GAAqBh2B,EAAcgV,CAAQ,EACrD,IAAIuiB,EACjBv3B,EAAY,iBAEZyB,EACAo3B,CAAgB,EAEJjB,iBAChB,G4BkMQ32C,KAAK4K,UACL4V,EACA6lC,CAA2B,CAC5B,CAEJ,CACD1O,yBAAyBn3B,GAQvB,OAPAxJ,GACE0uC,GAA2B,EAC3B1lD,KAAK4K,yDAIPqS,MAAMipC,GAA4BlmD,KAAK4K,SAAS,EACzC6hD,GACLzsD,KAAK4K,UACL4V,EACA6lC,CAA2B,CAE9B,CACDzzB,kBAAkB3Q,GAGhB,OAAOjiB,KAAK4K,UAAUgoB,kBAAkB3Q,CAAI,CAC7C,CACDyqC,wBAAwB7mD,GACtB,OzDlFG4W,MACLnG,EACAzQ,KAEA,IAAQW,GAASyW,MAAMsoB,GAAgB56B,EAAmB2L,CAAI,EAAGzQ,CAAI,GAAzD,KAEZ,OAAOW,EAAKkZ,KACd,GyD2EuC1f,KAAK4K,UAAW/E,CAAI,CACxD,CACDshD,SACE,OAAOnnD,KAAK4K,SACb,CACD+nB,UACE,OAAO3yB,KAAK4K,UAAU+nB,SACvB,CACOg4B,qBACL3qD,KAAK4K,UAA8C+9C,QAAU,IAAM3oD,IACrE,EAGH,SAASyrD,GACPzhD,EACA5G,EACA0G,GAEAjJ,IAAI6I,EAAOM,EAML2iD,GALwB,YAA1B,OAAO3iD,IACR,CAAEN,KAAAA,EAAMtG,MAAAA,EAAO0G,SAAAA,CAAQ,EAAKE,GAIfN,GAIhB,MAAO,CACLA,KAHc,GACdijD,EAAQ1qC,GAAQqmC,EAAKC,YAAYtmC,CAAgB,CAAC,EAGlD7e,MAAOA,EACP0G,SAAAA,EAEJ,CAhUSsgD,GAAWxE,YAAGA,QIpBVjR,GASXrV,kBACEjB,EACAC,GAEA,OAAOmpB,EAAsBnoB,WAAWjB,EAAgBC,CAAgB,CACzE,CAEDv7B,cAbA/C,KAAU6kB,WAAG,QAgBX7kB,KAAK4K,UAAY,IAAI68C,EAAsBN,GAAOh/B,UAAS7R,KAAO,CAAA,CAAC,CACpE,CAEDs+B,kBACET,EAKAW,GAEA,OAAO90C,KAAK4K,UAAUgqC,kBAGpBT,EACAW,CAAmB,CAEtB,CAEDqS,SACE,OAAOnnD,KAAK4K,SACb,EAlCM+pC,GAAAM,qBAAuBwS,EAAsBxS,qBAC7CN,GAAAtV,YAAcooB,EAAsBpoB,YCR7C,IAAMroB,GAA8BgvC,QAEvB7T,GAKXpvC,YACEuzB,EACAC,EACAtN,EAAmBd,EAAQ,QAACc,IAAG,GAG/BjS,GAAQiS,EAAIpC,SAAS7J,OAA2C,kBAAA,CAC9DxG,QAASyS,EAAIjmB,IACd,CAAA,EACDhD,KAAK4K,UAAY,IAAIgiD,GAGnB3jC,EAAI3S,KAAK,EACTggB,EAEAC,CAAiB,EAEnBv2B,KAAKyM,KAAOzM,KAAK4K,UAAU6B,IAC5B,CACDumC,QACEhzC,KAAK4K,UAAUooC,OAChB,CACD3c,SACE,OAAOr2B,KAAK4K,UAAUyrB,QACvB,CACDgC,SACE,OAAOr4B,KAAK4K,UAAUytB,QACvB,CACF,EZgB2BrsB,EA8CTmc,WA7CR0kC,SAASC,kBAChB,IAAIvgD,GAzCU,cA2CZ+pB,IAEE,IAAMrN,EAAMqN,EAAUuqB,YAAY,YAAY,EAAE9rB,aAAY,EACtDg4B,EAAez2B,EAAUuqB,YAAY,MAAM,EACjD,OAAO,IAAIuJ,GAAKnhC,EAAK8jC,CAAY,CAClC,EAEF,QAAA,EACE9/C,gBAAgB,CACf+/C,eAAgB,CACdC,UAAW,CACTp/C,aAAc43C,GAAyB53C,aACvCC,eAAgB23C,GAAyB33C,eACzCC,cAAe03C,GAAyB13C,cACxCC,8BACEy3C,GAAyBz3C,8BAC3BC,wBACEw3C,GAAyBx3C,wBAC3BC,aAAcu3C,GAAyBv3C,YACxC,CACF,EACDkxB,kBAAmBqmB,GACnBtkB,qBAAsBskB,EACtBjkB,mBAAoBikB,EACpBnkB,mBAAoBmkB,EACpBjlB,cAAeilB,GACf7jB,iBAAkB6jB,GAClB9Q,kBAAmBuY,GACnBrN,0BAA2B4F,GAC3BtT,kBAAmBgb,GACnBrrB,oBAAqB2jB,EACrB2E,KAAAA,GACAruB,eAAgB0pB,GAChBhlD,MAAOmF,EACR,EACAkH,qBAA4C,MAAA,EAC5CE,qBAAqB,CAAA,CAAK,CAAC,EAGhChB,EAASi1C,+CAA6B"}