"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[5],{64775:(e,t,o)=>{o.d(t,{Z:()=>i});const r="application/json";class i{#e=[];#t;#o=!0;#r;#i=this.#s(console.info);#n=this.#s(console.warn);#a={enable:!0,callbackList:[],interval:5};#c;didInitialize=!1;authenticated=!1;loginRequired=!1;responseMode="fragment";responseType="code";flow="standard";timeSkew=null;redirectUri;silentCheckSsoRedirectUri;silentCheckSsoFallback=!0;pkceMethod="S256";enableLogging=!1;logoutMethod="GET";scope;messageReceiveTimeout=1e4;idToken;idTokenParsed;token;tokenParsed;refreshToken;refreshTokenParsed;clientId;sessionId;subject;authServerUrl;realm;realmAccess;resourceAccess;profile;userInfo;endpoints;tokenTimeoutHandle;onAuthSuccess;onAuthError;onAuthRefreshSuccess;onAuthRefreshError;onTokenExpired;onAuthLogout;onReady;onActionUpdate;constructor(e){if("string"!=typeof e&&!h(e))throw new Error("The 'Keycloak' constructor must be provided with a configuration object, or a URL to a JSON configuration file.");if(h(e)){const t="oidcProvider"in e?["clientId"]:["url","realm","clientId"];for(const o of t)if(!(o in e))throw new Error(`The configuration object is missing the required '${o}' property.`)}globalThis.isSecureContext||this.#n("[KEYCLOAK] Keycloak JS must be used in a 'secure context' to function properly as it relies on browser APIs that are otherwise not available.\nContinuing to run your application insecurely will lead to unexpected behavior and breakage.\n\nFor more information see: https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts"),this.#c=e}init=async(e={})=>{if(this.didInitialize)throw new Error("A 'Keycloak' instance can only be initialized once.");this.didInitialize=!0,this.#r=function(){try{return new a}catch(e){return new c}}();if("string"==typeof e.adapter&&["default","cordova","cordova-native"].includes(e.adapter)?this.#t=this.#l(e.adapter):"object"==typeof e.adapter?this.#t=e.adapter:"Cordova"in window||"cordova"in window?this.#t=this.#l("cordova"):this.#t=this.#l("default"),void 0!==e.useNonce&&(this.#o=e.useNonce),void 0!==e.checkLoginIframe&&(this.#a.enable=e.checkLoginIframe),e.checkLoginIframeInterval&&(this.#a.interval=e.checkLoginIframeInterval),"login-required"===e.onLoad&&(this.loginRequired=!0),e.responseMode){if("query"!==e.responseMode&&"fragment"!==e.responseMode)throw new Error("Invalid value for responseMode");this.responseMode=e.responseMode}if(e.flow){switch(e.flow){case"standard":this.responseType="code";break;case"implicit":this.responseType="id_token token";break;case"hybrid":this.responseType="code id_token token";break;default:throw new Error("Invalid value for flow")}this.flow=e.flow}if("number"==typeof e.timeSkew&&(this.timeSkew=e.timeSkew),e.redirectUri&&(this.redirectUri=e.redirectUri),e.silentCheckSsoRedirectUri&&(this.silentCheckSsoRedirectUri=e.silentCheckSsoRedirectUri),"boolean"==typeof e.silentCheckSsoFallback&&(this.silentCheckSsoFallback=e.silentCheckSsoFallback),void 0!==e.pkceMethod){if("S256"!==e.pkceMethod&&!1!==e.pkceMethod)throw new TypeError(`Invalid value for pkceMethod', expected 'S256' or false but got ${e.pkceMethod}.`);this.pkceMethod=e.pkceMethod}return"boolean"==typeof e.enableLogging&&(this.enableLogging=e.enableLogging),"POST"===e.logoutMethod&&(this.logoutMethod="POST"),"string"==typeof e.scope&&(this.scope=e.scope),"number"==typeof e.messageReceiveTimeout&&e.messageReceiveTimeout>0&&(this.messageReceiveTimeout=e.messageReceiveTimeout),await this.#h(),await this.#d(),await this.#u(e),this.onReady?.(this.authenticated),this.authenticated};#l(e){if("default"===e)return this.#p();if("cordova"===e)return this.#a.enable=!1,this.#f();if("cordova-native"===e)return this.#a.enable=!1,this.#g();throw new Error("invalid adapter type: "+e)}#p(){const e=e=>e?.redirectUri||this.redirectUri||globalThis.location.href;return{login:async e=>(window.location.assign(await this.createLoginUrl(e)),await new Promise((()=>{}))),logout:async t=>{if("GET"===(t?.logoutMethod??this.logoutMethod))return void window.location.replace(this.createLogoutUrl(t));const o=document.createElement("form");o.setAttribute("method","POST"),o.setAttribute("action",this.createLogoutUrl(t)),o.style.display="none";const r={id_token_hint:this.idToken,client_id:this.clientId,post_logout_redirect_uri:e(t)};for(const[e,t]of Object.entries(r)){const r=document.createElement("input");r.setAttribute("type","hidden"),r.setAttribute("name",e),r.setAttribute("value",t),o.appendChild(r)}document.body.appendChild(o),o.submit()},register:async e=>(window.location.assign(await this.createRegisterUrl(e)),await new Promise((()=>{}))),accountManagement:async()=>{const e=this.createAccountUrl();if(void 0===e)throw new Error("Not supported by the OIDC server");return window.location.href=e,await new Promise((()=>{}))},redirectUri:e}}#f(){const e=(e,t,o)=>window.cordova&&window.cordova.InAppBrowser?window.cordova.InAppBrowser.open(e,t,o):window.open(e,t,o),t=e=>{const t=(e=>e&&e.cordovaOptions?Object.keys(e.cordovaOptions).reduce(((t,o)=>(t[o]=e.cordovaOptions[o],t)),{}):{})(e);return t.location="no",e&&"none"===e.prompt&&(t.hidden="yes"),(e=>Object.keys(e).reduce(((t,o)=>(t.push(o+"="+e[o]),t)),[]).join(","))(t)},o=()=>this.redirectUri||"http://localhost";return{login:async r=>{const i=t(r),s=await this.createLoginUrl(r),n=e(s,"_blank",i);let a=!1,c=!1;function l(){c=!0,n.close()}return await new Promise(((e,t)=>{n.addEventListener("loadstart",(async r=>{if(0===r.url.indexOf(o())){const o=this.#w(r.url);a=!0,l();try{await this.#k(o),e()}catch(e){t(e)}}})),n.addEventListener("loaderror",(async r=>{if(!a)if(0===r.url.indexOf(o())){const o=this.#w(r.url);a=!0,l();try{await this.#k(o),e()}catch(e){t(e)}}else t(new Error("Unable to process login.")),l()})),n.addEventListener("exit",(function(e){c||t(new Error("User closed the login window."))}))}))},logout:async t=>{const r=this.createLogoutUrl(t),i=e(r,"_blank","location=no,hidden=yes,clearcache=yes");let s=!1;i.addEventListener("loadstart",(e=>{0===e.url.indexOf(o())&&i.close()})),i.addEventListener("loaderror",(e=>{0===e.url.indexOf(o())||(s=!0),i.close()})),await new Promise(((e,t)=>{i.addEventListener("exit",(()=>{s?t(new Error("User closed the login window.")):(this.clearToken(),e())}))}))},register:async r=>{const i=await this.createRegisterUrl(),s=t(r),n=e(i,"_blank",s),a=new Promise(((e,t)=>{n.addEventListener("loadstart",(async r=>{if(0===r.url.indexOf(o())){n.close();const o=this.#w(r.url);try{await this.#k(o),e()}catch(e){t(e)}}}))}));await a},accountManagement:async()=>{const t=this.createAccountUrl();if(void 0===t)throw new Error("Not supported by the OIDC server");{const r=e(t,"_blank","location=no");r.addEventListener("loadstart",(function(e){0===e.url.indexOf(o())&&r.close()}))}},redirectUri:()=>o()}}#g(){return{login:async e=>{const t=await this.createLoginUrl(e);await new Promise(((e,o)=>{universalLinks.subscribe("keycloak",(async t=>{universalLinks.unsubscribe("keycloak"),window.cordova.plugins.browsertab.close();const r=this.#w(t.url);try{await this.#k(r),e()}catch(e){o(e)}})),window.cordova.plugins.browsertab.openUrl(t)}))},logout:async e=>{const t=this.createLogoutUrl(e);await new Promise((e=>{universalLinks.subscribe("keycloak",(()=>{universalLinks.unsubscribe("keycloak"),window.cordova.plugins.browsertab.close(),this.clearToken(),e()})),window.cordova.plugins.browsertab.openUrl(t)}))},register:async e=>{const t=await this.createRegisterUrl(e);await new Promise(((e,o)=>{universalLinks.subscribe("keycloak",(async t=>{universalLinks.unsubscribe("keycloak"),window.cordova.plugins.browsertab.close();const r=this.#w(t.url);try{await this.#k(r),e()}catch(e){o(e)}})),window.cordova.plugins.browsertab.openUrl(t)}))},accountManagement:async()=>{const e=this.createAccountUrl();if(void 0===e)throw new Error("Not supported by the OIDC server");window.cordova.plugins.browsertab.openUrl(e)},redirectUri:e=>e&&e.redirectUri?e.redirectUri:this.redirectUri?this.redirectUri:"http://localhost"}}async#h(){if("string"==typeof this.#c){const e=await async function(e){return await d(e)}(this.#c);this.authServerUrl=e["auth-server-url"],this.realm=e.realm,this.clientId=e.resource,this.#m()}else this.clientId=this.#c.clientId,"oidcProvider"in this.#c?await this.#b(this.#c.oidcProvider):(this.authServerUrl=this.#c.url,this.realm=this.#c.realm,this.#m())}#m(){this.endpoints={authorize:()=>this.#y()+"/protocol/openid-connect/auth",token:()=>this.#y()+"/protocol/openid-connect/token",logout:()=>this.#y()+"/protocol/openid-connect/logout",checkSessionIframe:()=>this.#y()+"/protocol/openid-connect/login-status-iframe.html",thirdPartyCookiesIframe:()=>this.#y()+"/protocol/openid-connect/3p-cookies/step1.html",register:()=>this.#y()+"/protocol/openid-connect/registrations",userinfo:()=>this.#y()+"/protocol/openid-connect/userinfo"}}async#b(e){if("string"==typeof e){const t=`${p(e)}/.well-known/openid-configuration`,o=await async function(e){return await d(e)}(t);this.#v(o)}else this.#v(e)}#v(e){this.endpoints={authorize:()=>e.authorization_endpoint,token:()=>e.token_endpoint,logout(){if(!e.end_session_endpoint)throw new Error("Not supported by the OIDC server");return e.end_session_endpoint},checkSessionIframe(){if(!e.check_session_iframe)throw new Error("Not supported by the OIDC server");return e.check_session_iframe},register(){throw new Error('Redirection to "Register user" page not supported in standard OIDC mode')},userinfo(){if(!e.userinfo_endpoint)throw new Error("Not supported by the OIDC server");return e.userinfo_endpoint}}}async#d(){if(!this.#a.enable&&!this.silentCheckSsoRedirectUri||"function"!=typeof this.endpoints.thirdPartyCookiesIframe)return;const e=document.createElement("iframe");e.setAttribute("src",this.endpoints.thirdPartyCookiesIframe()),e.setAttribute("sandbox","allow-storage-access-by-user-activation allow-scripts allow-same-origin"),e.setAttribute("title","keycloak-3p-check-iframe"),e.style.display="none",document.body.appendChild(e);const t=new Promise((t=>{const o=r=>{e.contentWindow===r.source&&("supported"!==r.data&&"unsupported"!==r.data||("unsupported"===r.data&&(this.#n("[KEYCLOAK] Your browser is blocking access to 3rd-party cookies, this means:\n\n - It is not possible to retrieve tokens without redirecting to the Keycloak server (a.k.a. no support for silent authentication).\n - It is not possible to automatically detect changes to the session status (such as the user logging out in another tab).\n\nFor more information see: https://www.keycloak.org/securing-apps/javascript-adapter#_modern_browsers"),this.#a.enable=!1,this.silentCheckSsoFallback&&(this.silentCheckSsoRedirectUri=void 0)),document.body.removeChild(e),window.removeEventListener("message",o),t()))};window.addEventListener("message",o,!1)}));return await function(e,t,o){let r;const i=new Promise((function(e,i){r=window.setTimeout((function(){i(new Error(o||"Promise is not settled within timeout of "+t+"ms"))}),t)}));return Promise.race([e,i]).finally((function(){clearTimeout(r)}))}(t,this.messageReceiveTimeout,"Timeout when waiting for 3rd party check iframe message.")}async#u(e){const t=this.#w(window.location.href);if(t?.newUrl&&window.history.replaceState(window.history.state,"",t.newUrl),t&&t.valid)return await this.#I(),void await this.#k(t);const o=async t=>{const o={};t||(o.prompt="none"),e.locale&&(o.locale=e.locale),await this.login(o)},r=async()=>{switch(e.onLoad){case"check-sso":if(this.#a.enable){await this.#I();await this.#U()||(this.silentCheckSsoRedirectUri?await this.#C():await o(!1))}else this.silentCheckSsoRedirectUri?await this.#C():await o(!1);break;case"login-required":await o(!0);break;default:throw new Error("Invalid value for onLoad")}};if(e.token&&e.refreshToken)if(this.#S(e.token,e.refreshToken,e.idToken),this.#a.enable){await this.#I();await this.#U()&&(this.onAuthSuccess?.(),this.#_())}else try{await this.updateToken(-1),this.onAuthSuccess?.()}catch(t){if(this.onAuthError?.(),!e.onLoad)throw t;await r()}else e.onLoad&&await r()}async#I(){if(!this.#a.enable||this.#a.iframe)return;const e=document.createElement("iframe");this.#a.iframe=e,e.setAttribute("src",this.endpoints.checkSessionIframe()),e.setAttribute("sandbox","allow-storage-access-by-user-activation allow-scripts allow-same-origin"),e.setAttribute("title","keycloak-session-iframe"),e.style.display="none",document.body.appendChild(e);window.addEventListener("message",(e=>{if(e.origin!==this.#a.iframeOrigin||this.#a.iframe?.contentWindow!==e.source)return;if("unchanged"!==e.data&&"changed"!==e.data&&"error"!==e.data)return;"unchanged"!==e.data&&this.clearToken();const t=this.#a.callbackList;this.#a.callbackList=[];for(const o of t.reverse())"error"===e.data?o(new Error("Error while checking login iframe")):o(null,"unchanged"===e.data)}),!1);const t=new Promise((t=>{e.addEventListener("load",(()=>{const e=this.endpoints.authorize();e.startsWith("/")?this.#a.iframeOrigin=globalThis.location.origin:this.#a.iframeOrigin=new URL(e).origin,t()}))}));await t}async#U(){if(!this.#a.iframe||!this.#a.iframeOrigin)return;const e=`${this.clientId} ${this.sessionId?this.sessionId:""}`,t=this.#a.iframeOrigin,o=new Promise(((o,r)=>{this.#a.callbackList.push(((e,t)=>e?r(e):o(t))),1===this.#a.callbackList.length&&this.#a.iframe?.contentWindow?.postMessage(e,t)}));return await o}async#C(){const e=document.createElement("iframe"),t=await this.createLoginUrl({prompt:"none",redirectUri:this.silentCheckSsoRedirectUri});return e.setAttribute("src",t),e.setAttribute("sandbox","allow-storage-access-by-user-activation allow-scripts allow-same-origin"),e.setAttribute("title","keycloak-silent-check-sso"),e.style.display="none",document.body.appendChild(e),await new Promise(((t,o)=>{const r=async i=>{if(i.origin!==window.location.origin||e.contentWindow!==i.source)return;const s=this.#w(i.data);try{await this.#k(s),t()}catch(e){o(e)}document.body.removeChild(e),window.removeEventListener("message",r)};window.addEventListener("message",r)}))}#w(e){const t=this.#T(e);if(!t)return;const o=this.#r.get(t.state);return o&&(t.valid=!0,t.redirectUri=o.redirectUri,t.storedNonce=o.nonce,t.prompt=o.prompt,t.pkceCodeVerifier=o.pkceCodeVerifier,t.loginOptions=o.loginOptions),t}#T(e){let t=[];switch(this.flow){case"standard":t=["code","state","session_state","kc_action_status","kc_action","iss"];break;case"implicit":t=["access_token","token_type","id_token","state","session_state","expires_in","kc_action_status","kc_action","iss"];break;case"hybrid":t=["access_token","token_type","id_token","code","state","session_state","expires_in","kc_action_status","kc_action","iss"]}t.push("error"),t.push("error_description"),t.push("error_uri");const o=new URL(e);let r,i="";if("query"===this.responseMode&&o.searchParams.size>0?(r=this.#E(o.search,t),o.search=r.paramsString,i=o.toString()):"fragment"===this.responseMode&&o.hash.length>0&&(r=this.#E(o.hash.substring(1),t),o.hash=r.paramsString,i=o.toString()),r?.oauthParams)if("standard"===this.flow||"hybrid"===this.flow){if((r.oauthParams.code||r.oauthParams.error)&&r.oauthParams.state)return r.oauthParams.newUrl=i,r.oauthParams}else if("implicit"===this.flow&&(r.oauthParams.access_token||r.oauthParams.error)&&r.oauthParams.state)return r.oauthParams.newUrl=i,r.oauthParams}#E(e,t){const o=e.split("&"),r={};let i="";for(const e of o.reverse()){const o=new URLSearchParams(e).entries().next().value;if(!o){i="&"+i;continue}const[s,n]=o;t.includes(s)&&!(s in r)?r[s]=n:i=0===i.length?e:e+"&"+i}return{paramsString:i,oauthParams:r}}async#k(e){const{code:t,error:o,prompt:r}=e;let i=(new Date).getTime();const s=(t,o,r)=>{if(i=(i+(new Date).getTime())/2,this.#S(t,o,r,i),this.#o&&this.idTokenParsed&&this.idTokenParsed.nonce!==e.storedNonce)throw this.#i("[KEYCLOAK] Invalid nonce, clearing token"),this.clearToken(),new Error("Invalid nonce.")};if(e.kc_action_status&&this.onActionUpdate&&this.onActionUpdate(e.kc_action_status,e.kc_action),o){if("none"!==r){if(!e.error_description||"authentication_expired"!==e.error_description){const t={error:o,error_description:e.error_description};throw this.onAuthError?.(t),t}await this.login(e.loginOptions)}}else if("standard"!==this.flow&&(e.access_token||e.id_token)&&(s(e.access_token,void 0,e.id_token),this.onAuthSuccess?.()),"implicit"!==this.flow&&t)try{const o=await async function(e,t,o,r,i){const s=new URLSearchParams([["code",t],["grant_type","authorization_code"],["client_id",o],["redirect_uri",r]]);i&&s.append("code_verifier",i);return await d(e,{method:"POST",credentials:"include",body:s})}(this.endpoints.token(),t,this.clientId,e.redirectUri,e.pkceCodeVerifier);s(o.access_token,o.refresh_token,o.id_token),"standard"===this.flow&&this.onAuthSuccess?.(),this.#_()}catch(o){throw this.onAuthError?.(),o}}async#_(){if(this.#a.enable&&this.token){await g(1e3*this.#a.interval);await this.#U()&&await this.#_()}}login=e=>this.#t.login(e);createLoginUrl=async e=>{const t=s(),o=s(),r=this.#t.redirectUri(e),i={state:t,nonce:o,redirectUri:r,loginOptions:e};e?.prompt&&(i.prompt=e.prompt);const n="register"===e?.action?this.endpoints.register():this.endpoints.authorize();let a=e?.scope||this.scope;const c=a?a.split(" "):[];c.includes("openid")||c.unshift("openid"),a=c.join(" ");const l=new URLSearchParams([["client_id",this.clientId],["redirect_uri",r],["state",t],["response_mode",this.responseMode],["response_type",this.responseType],["scope",a]]);var h;if(this.#o&&l.append("nonce",o),e?.prompt&&l.append("prompt",e.prompt),"number"==typeof e?.maxAge&&l.append("max_age",e.maxAge.toString()),e?.loginHint&&l.append("login_hint",e.loginHint),e?.idpHint&&l.append("kc_idp_hint",e.idpHint),e?.action&&"register"!==e.action&&l.append("kc_action",e.action),e?.locale&&l.append("ui_locales",e.locale),e?.acr&&l.append("claims",(h=e.acr,JSON.stringify({id_token:{acr:h}}))),e?.acrValues&&l.append("acr_values",e.acrValues),this.pkceMethod)try{const e=function(e,t){const o=function(e){if("undefined"==typeof crypto||void 0===crypto.getRandomValues)throw new Error("Web Crypto API is not available.");return crypto.getRandomValues(new Uint8Array(e))}(e),r=new Array(e);for(let i=0;ithis.#t.logout(e);createLogoutUrl=e=>{const t=e?.logoutMethod??this.logoutMethod,o=this.endpoints.logout();if("POST"===t)return o;const r=new URLSearchParams([["client_id",this.clientId],["post_logout_redirect_uri",this.#t.redirectUri(e)]]);return this.idToken&&r.append("id_token_hint",this.idToken),`${o}?${r.toString()}`};register=e=>this.#t.register(e);createRegisterUrl=e=>this.createLoginUrl({...e,action:"register"});createAccountUrl=e=>{const t=this.#y();if(!t)throw new Error("Unable to create account URL, make sure the adapter is not configured using a generic OIDC provider.");return`${t}/account?${new URLSearchParams([["referrer",this.clientId],["referrer_uri",this.#t.redirectUri(e)]]).toString()}`};accountManagement=()=>this.#t.accountManagement();hasRealmRole=e=>{const t=this.realmAccess;return!!t&&t.roles.indexOf(e)>=0};hasResourceRole=(e,t)=>{if(!this.resourceAccess)return!1;const o=this.resourceAccess[t||this.clientId];return!!o&&o.roles.indexOf(e)>=0};loadUserProfile=async()=>{const e=this.#y();if(!e)throw new Error("Unable to load user profile, make sure the adapter is not configured using a generic OIDC provider.");const t=`${e}/account`,o=await d(t,{headers:[u(this.token)]});return this.profile=o};loadUserInfo=async()=>{const e=this.endpoints.userinfo(),t=await d(e,{headers:[u(this.token)]});return this.userInfo=t};isTokenExpired=e=>{if(!this.tokenParsed||!this.refreshToken&&"implicit"!==this.flow)throw new Error("Not authenticated");if(null==this.timeSkew)return this.#i("[KEYCLOAK] Unable to determine if token is expired as timeskew is not set"),!0;if("number"!=typeof this.tokenParsed.exp)return!1;let t=this.tokenParsed.exp-Math.ceil((new Date).getTime()/1e3)+this.timeSkew;if(e){if(isNaN(e))throw new Error("Invalid minValidity");t-=e}return t<0};updateToken=async e=>{if(!this.refreshToken)throw new Error("Unable to update token, no refresh token available.");e=e||5,this.#a.enable&&await this.#U();let t=!1;if(-1===e?(t=!0,this.#i("[KEYCLOAK] Refreshing token: forced refresh")):this.tokenParsed&&!this.isTokenExpired(e)||(t=!0,this.#i("[KEYCLOAK] Refreshing token: token expired")),!t)return!1;const{promise:o,resolve:r,reject:i}=Promise.withResolvers();if(this.#e.push({resolve:r,reject:i}),1===this.#e.length){const e=this.endpoints.token();let t=(new Date).getTime();try{const o=await async function(e,t,o){const r=new URLSearchParams([["grant_type","refresh_token"],["refresh_token",t],["client_id",o]]);return await d(e,{method:"POST",credentials:"include",body:r})}(e,this.refreshToken,this.clientId);this.#i("[KEYCLOAK] Token refreshed"),t=(t+(new Date).getTime())/2,this.#S(o.access_token,o.refresh_token,o.id_token,t),this.onAuthRefreshSuccess?.();for(let e=this.#e.pop();null!=e;e=this.#e.pop())e.resolve(!0)}catch(e){this.#n("[KEYCLOAK] Failed to refresh token"),e instanceof f&&400===e.response.status&&this.clearToken(),this.onAuthRefreshError?.();for(let t=this.#e.pop();null!=t;t=this.#e.pop())t.reject(e)}}return await o};clearToken=()=>{this.token&&(this.#S(),this.onAuthLogout?.(),this.loginRequired&&this.login())};#S(e,t,o,r){if(this.tokenTimeoutHandle&&(clearTimeout(this.tokenTimeoutHandle),this.tokenTimeoutHandle=void 0),t?(this.refreshToken=t,this.refreshTokenParsed=l(t)):(delete this.refreshToken,delete this.refreshTokenParsed),o?(this.idToken=o,this.idTokenParsed=l(o)):(delete this.idToken,delete this.idTokenParsed),e){if(this.token=e,this.tokenParsed=l(e),this.sessionId=this.tokenParsed.sid,this.authenticated=!0,this.subject=this.tokenParsed.sub,this.realmAccess=this.tokenParsed.realm_access,this.resourceAccess=this.tokenParsed.resource_access,r&&(this.timeSkew=Math.floor(r/1e3)-this.tokenParsed.iat),null!==this.timeSkew&&(this.#i("[KEYCLOAK] Estimated time difference between browser and server is "+this.timeSkew+" seconds"),this.onTokenExpired)){const e=1e3*(this.tokenParsed.exp-(new Date).getTime()/1e3+this.timeSkew);this.#i("[KEYCLOAK] Token expires in "+Math.round(e/1e3)+" s"),e<=0?this.onTokenExpired():this.tokenTimeoutHandle=window.setTimeout(this.onTokenExpired,e)}}else delete this.token,delete this.tokenParsed,delete this.subject,delete this.realmAccess,delete this.resourceAccess,this.authenticated=!1}#y(){if(void 0!==this.authServerUrl)return`${p(this.authServerUrl)}/realms/${encodeURIComponent(this.realm)}`}#s(e){return t=>{this.enableLogging&&e.call(console,t)}}}function s(){if("undefined"==typeof crypto||void 0===crypto.randomUUID)throw new Error("Web Crypto API is not available.");return crypto.randomUUID()}const n="kc-callback-";class a{constructor(){globalThis.localStorage.setItem("kc-test","test"),globalThis.localStorage.removeItem("kc-test")}get(e){if(!e)return null;this.#A();const t=n+e,o=globalThis.localStorage.getItem(t);return o?(globalThis.localStorage.removeItem(t),JSON.parse(o)):null}add(e){this.#A();const t=n+e.state,o=JSON.stringify({...e,expires:Date.now()+36e5});try{globalThis.localStorage.setItem(t,o)}catch(e){this.#L(),globalThis.localStorage.setItem(t,o)}}#A(){const e=Date.now();for(const[t,o]of this.#P()){const r=this.#O(o);(null===r||re.startsWith(n)))}#O(e){let t;try{t=JSON.parse(e)}catch(e){return null}return h(t)&&"expires"in t&&"number"==typeof t.expires?t.expires:null}}class c{get(e){if(!e)return null;const t=this.#R(n+e);return this.#x(n+e,"",this.#M(-100)),t?JSON.parse(t):null}add(e){this.#x(n+e.state,JSON.stringify(e),this.#M(60))}#R(e){const t=e+"=",o=document.cookie.split(";");for(let e=0;e{let o=t.charCodeAt(0).toString(16).toUpperCase();return o.length<2&&(o="0"+o),"%"+o})))}(t)}catch(e){return atob(t)}}(t)}catch(e){throw new Error("Unable to decode token, payload is not a valid Base64URL value.",{cause:e})}try{return JSON.parse(o)}catch(e){throw new Error("Unable to decode token, payload is not a valid JSON value.",{cause:e})}}function h(e){return"object"==typeof e&&null!==e}async function d(e,t={}){const o=new Headers(t.headers);o.set("Accept",r);const i=await async function(e,t){const o=await fetch(e,t);if(!o.ok)throw new f("Server responded with an invalid status.",{response:o});return o}(e,{...t,headers:o});return await i.json()}function u(e){if(!e)throw new Error("Unable to build authorization header, token is not set, make sure the user is authenticated.");return["Authorization",`bearer ${e}`]}function p(e){return e.endsWith("/")?e.slice(0,-1):e}class f extends Error{response;constructor(e,t){super(e,t),this.response=t.response}}const g=e=>new Promise((t=>setTimeout(t,e)))}}]);