{"version":3,"sources":["../src/profile/types.ts","../src/shared/auth-bridge.ts","../src/profile/web-component.ts"],"names":[],"mappings":";AAiIO,IAAM,6BAAA,GAGT;AAAA,EACF,sBAAA,EAAwB,0BAAA;AAAA,EACxB,gBAAA,EAAkB,oBAAA;AAAA,EAClB,yBAAA,EAA2B,8BAAA;AAAA,EAC3B,kBAAA,EAAoB,sBAAA;AAAA,EACpB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,cAAA,EAAgB,iBAAA;AAAA,EAChB,aAAA,EAAe,gBAAA;AAAA,EACf,mBAAA,EAAqB,uBAAA;AAAA,EACrB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,kBAAA,EAAoB,sBAAA;AAAA,EACpB,aAAA,EAAe,iBAAA;AAAA,EACf,iBAAA,EAAmB,qBAAA;AAAA,EACnB,iBAAA,EAAmB,qBAAA;AAAA,EACnB,iBAAA,EAAmB,qBAAA;AAAA,EACnB,kBAAA,EAAoB,sBAAA;AAAA,EACpB,iBAAA,EAAmB,qBAAA;AAAA,EACnB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,eAAA,EAAiB,mBAAA;AAAA,EACjB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,cAAA,EAAgB,kBAAA;AAAA,EAChB,iBAAA,EAAmB,qBAAA;AAAA,EACnB,kBAAA,EAAoB,sBAAA;AAAA,EACpB,aAAA,EAAe,iBAAA;AAAA,EACf,iBAAA,EAAmB,qBAAA;AAAA,EACnB,qBAAA,EAAuB,0BAAA;AAAA,EACvB,qBAAA,EAAuB,0BAAA;AAAA,EACvB,kBAAA,EAAoB,uBAAA;AAAA,EACpB,qBAAA,EAAuB,0BAAA;AAAA,EACvB,eAAA,EAAiB,mBAAA;AAAA,EACjB,iBAAA,EAAmB,sBAAA;AAAA,EACnB,gBAAA,EAAkB,oBAAA;AAAA,EAClB,eAAA,EAAiB,mBAAA;AAAA,EACjB,oBAAA,EAAsB,yBAAA;AAAA,EACtB,kBAAA,EAAoB,sBAAA;AAAA,EACpB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,iBAAA,EAAmB,qBAAA;AAAA,EACnB,eAAA,EAAiB,mBAAA;AAAA,EACjB,iBAAA,EAAmB,qBAAA;AAAA,EACnB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,cAAA,EAAgB,kBAAA;AAAA,EAChB,eAAA,EAAiB,mBAAA;AAAA,EACjB,gBAAA,EAAkB,oBAAA;AAAA,EAClB,mBAAA,EAAqB,uBAAA;AAAA,EACrB,yBAAA,EAA2B,6BAAA;AAAA,EAC3B,iBAAA,EAAmB;AACrB,CAAA;;;AC/IA,IAAM,kBAAA,GAAqB,YAAA;AAC3B,IAAM,mBAAA,GAAsB,aAAA;AAC5B,IAAM,sBAAA,GAAyB,qBAAA;AAE/B,SAAS,oBAAoB,IAAA,EAA6B;AACxD,EAAA,MAAM,GAAA,GAAM,IAAA,CAAK,YAAA,CAAa,wBAAwB,CAAA,IAAK,EAAA;AAC3D,EAAA,OAAO,GAAA,CACJ,KAAA,CAAM,GAAG,CAAA,CACT,GAAA,CAAI,CAAC,CAAA,KAAM,CAAA,CAAE,IAAA,EAAM,CAAA,CACnB,MAAA,CAAO,OAAO,CAAA;AACnB;AAEA,SAAS,qBAAA,CAAsB,MAAmB,MAAA,EAAyB;AAEzE,EAAA,IAAI,MAAA,KAAW,MAAA,CAAO,QAAA,CAAS,MAAA,EAAQ,OAAO,IAAA;AAC9C,EAAA,MAAM,OAAA,GAAU,oBAAoB,IAAI,CAAA;AACxC,EAAA,OAAO,OAAA,CAAQ,SAAS,MAAM,CAAA;AAChC;AAEO,SAAS,gBAAA,CACd,MACA,IAAA,EACkB;AAElB,EAAA,IAAI,WAAA,GAA6B,IAAA;AAEjC,EAAA,MAAM,eAAe,MAAqB;AACxC,IAAA,IAAI,aAAa,OAAO,WAAA;AACxB,IAAA,OAAO,KAAK,YAAA,CAAa,YAAY,CAAA,IAAK,IAAA,CAAK,aAAa,SAAS,CAAA;AAAA,EACvE,CAAA;AAEA,EAAA,MAAM,mBAAmB,MAAY;AACnC,IAAA,MAAM,MAAA,GAAS,KAAK,cAAA,EAAe;AACnC,IAAA,MAAM,QAAQ,YAAA,EAAa;AAC3B,IAAA,IAAI,CAAC,MAAA,IAAU,CAAC,MAAA,CAAO,aAAA,IAAiB,CAAC,KAAA,EAAO;AAChD,IAAA,MAAA,CAAO,aAAA,CAAc,WAAA;AAAA,MACnB,EAAE,IAAA,EAAM,kBAAA,EAAoB,KAAA,EAAM;AAAA,MAClC,IAAA,CAAK;AAAA,KACP;AAAA,EACF,CAAA;AAEA,EAAA,MAAM,SAAA,GAAY,CAAC,KAAA,KAA8B;AAC/C,IAAA,IAAI,CAAC,SAAS,OAAO,KAAA,CAAM,SAAS,QAAA,IAAY,KAAA,CAAM,SAAS,IAAA,EAAM;AACnE,MAAA;AAAA,IACF;AACA,IAAA,MAAM,OAAO,KAAA,CAAM,IAAA;AAGnB,IAAA,IAAI,IAAA,CAAK,SAAS,mBAAA,EAAqB;AACrC,MAAA,IAAI,CAAC,qBAAA,CAAsB,IAAA,EAAM,KAAA,CAAM,MAAM,CAAA,EAAG;AAChD,MAAA,IAAI,OAAO,IAAA,CAAK,KAAA,KAAU,QAAA,IAAY,CAAC,KAAK,KAAA,EAAO;AACnD,MAAA,WAAA,GAAc,IAAA,CAAK,KAAA;AACnB,MAAA,gBAAA,EAAiB;AACjB,MAAA;AAAA,IACF;AAIA,IAAA,IAAI,IAAA,CAAK,SAAS,sBAAA,EAAwB;AACxC,MAAA,MAAM,MAAA,GAAS,KAAK,cAAA,EAAe;AACnC,MAAA,IAAI,CAAC,MAAA,IAAU,KAAA,CAAM,MAAA,KAAW,OAAO,aAAA,EAAe;AACtD,MAAA,IAAA,CAAK,aAAA;AAAA,QACH,IAAI,YAAY,sBAAA,EAAwB;AAAA,UACtC,OAAA,EAAS,IAAA;AAAA,UACT,QAAA,EAAU;AAAA,SACX;AAAA,OACH;AAAA,IACF;AAAA,EACF,CAAA;AAEA,EAAA,MAAA,CAAO,gBAAA,CAAiB,WAAW,SAAS,CAAA;AAE5C,EAAA,OAAO;AAAA,IACL,MAAA,GAAS;AACP,MAAA,MAAA,CAAO,mBAAA,CAAoB,WAAW,SAAS,CAAA;AAAA,IACjD,CAAA;AAAA,IACA,gBAAA;AAAA,IACA;AAAA,GACF;AACF;AAGO,IAAM,0BAAA,GAA6B;AAAA,EACxC,YAAA;AAAA,EACA,SAAA;AAAA,EACA;AACF,CAAA;;;ACzGA,IAAM,sBAAA,GAAyB,MAAA,CAAO,MAAA,CAAO,6BAA6B,CAAA;AAE1E,IAAM,oBAAA,GAAN,cAAmC,WAAA,CAAY;AAAA,EAI7C,WAAA,GAAc;AACZ,IAAA,KAAA,EAAM;AAJR,IAAA,IAAA,CAAO,MAAA,GAAmC,IAAA;AAC1C,IAAA,IAAA,CAAQ,UAAA,GAAsC,IAAA;AAI5C,IAAA,IAAA,CAAK,YAAA,CAAa,EAAE,IAAA,EAAM,MAAA,EAAQ,CAAA;AAAA,EACpC;AAAA,EAEA,WAAW,kBAAA,GAA+B;AACxC,IAAA,OAAO;AAAA,MACL,SAAA;AAAA,MAEA,OAAA;AAAA,MACA,QAAA;AAAA,MACA,OAAA;AAAA,MACA,GAAG,sBAAA;AAAA,MAEH,GAAG;AAAA,KACL;AAAA,EACF;AAAA,EAEA,iBAAA,GAA0B;AACxB,IAAA,IAAA,CAAK,UAAA,GAAa,iBAAiB,IAAA,EAAM;AAAA,MACvC,cAAA,EAAgB,MAAM,IAAA,CAAK,MAAA;AAAA,MAC3B,SAAS,IAAA,CAAK;AAAA,KACf,CAAA;AACD,IAAA,IAAA,CAAK,MAAA,EAAO;AAAA,EACd;AAAA,EAEA,oBAAA,GAA6B;AAlD/B,IAAA,IAAA,EAAA;AAmDI,IAAA,CAAA,EAAA,GAAA,IAAA,CAAK,eAAL,IAAA,GAAA,MAAA,GAAA,EAAA,CAAiB,MAAA,EAAA;AACjB,IAAA,IAAA,CAAK,UAAA,GAAa,IAAA;AAAA,EACpB;AAAA,EAEA,wBAAA,CACE,KAAA,EACA,QAAA,EACA,QAAA,EACM;AACN,IAAA,IAAI,aAAa,QAAA,EAAU;AACzB,MAAA,IAAA,CAAK,MAAA,EAAO;AAAA,IACd;AAAA,EACF;AAAA,EAEA,IAAY,MAAA,GAAiB;AAC3B,IAAA,OAAO,IAAA,CAAK,YAAA,CAAa,SAAS,CAAA,IAAK,OAAO,QAAA,CAAS,MAAA;AAAA,EACzD;AAAA,EAEA,IAAY,WAAA,GAAsB;AAChC,IAAA,OAAO,IAAA,CAAK,YAAA,CAAa,OAAO,CAAA,IAAK,KAAA;AAAA,EACvC;AAAA,EAEA,IAAY,YAAA,GAAuB;AACjC,IAAA,OAAO,IAAA,CAAK,YAAA,CAAa,QAAQ,CAAA,IAAK,KAAA;AAAA,EACxC;AAAA,EAEA,IAAY,KAAA,GAAgB;AAC1B,IAAA,OAAO,IAAA,CAAK,YAAA,CAAa,OAAO,CAAA,IAAK,OAAA;AAAA,EACvC;AAAA,EAEA,MAAA,GAAe;AACb,IAAA,IAAI,CAAC,KAAK,UAAA,EAAY;AAEtB,IAAA,MAAM,MAAA,GAAS,QAAA,CAAS,aAAA,CAAc,QAAQ,CAAA;AAC9C,IAAA,MAAM,GAAA,GAAM,IAAI,GAAA,CAAI,iBAAA,EAAmB,KAAK,MAAM,CAAA;AAElD,IAAA,GAAA,CAAI,YAAA,CAAa,GAAA,CAAI,OAAA,EAAS,IAAA,CAAK,KAAK,CAAA;AAExC,IAAA,sBAAA,CAAuB,OAAA,CAAQ,CAAC,IAAA,KAAS;AACvC,MAAA,MAAM,GAAA,GAAM,IAAA,CAAK,YAAA,CAAa,IAAI,CAAA;AAClC,MAAA,IAAI,GAAA,KAAQ,QAAQ,GAAA,KAAQ,MAAA,IAAa,OAAO,GAAG,CAAA,CAAE,SAAS,CAAA,EAAG;AAC/D,QAAA,GAAA,CAAI,YAAA,CAAa,GAAA,CAAI,IAAA,EAAM,GAAG,CAAA;AAAA,MAChC;AAAA,IACF,CAAC,CAAA;AAED,IAAA,MAAA,CAAO,GAAA,GAAM,IAAI,QAAA,EAAS;AAC1B,IAAA,MAAA,CAAO,QAAQ,IAAA,CAAK,WAAA;AACpB,IAAA,MAAA,CAAO,SAAS,IAAA,CAAK,YAAA;AACrB,IAAA,MAAA,CAAO,WAAA,GAAc,GAAA;AACrB,IAAA,MAAA,CAAO,SAAA,GAAY,IAAA;AACnB,IAAA,MAAA,CAAO,KAAA,GAAQ,gBAAA;AAEf,IAAA,MAAA,CAAO,SAAS,MAAM;AAvG1B,MAAA,IAAA,EAAA;AAwGM,MAAA,CAAA,EAAA,GAAA,IAAA,CAAK,eAAL,IAAA,GAAA,MAAA,GAAA,EAAA,CAAiB,gBAAA,EAAA;AACjB,MAAA,IAAA,CAAK,aAAA;AAAA,QACH,IAAI,YAAY,MAAA,EAAQ;AAAA,UACtB,QAAQ,EAAE,MAAA,EAAQ,SAAA,EAAW,KAAA,EAAO,KAAK,KAAA;AAAM,SAChD;AAAA,OACH;AAAA,IACF,CAAA;AAEA,IAAA,MAAA,CAAO,UAAU,MAAM;AACrB,MAAA,IAAI,CAAC,KAAK,UAAA,EAAY;AACtB,MAAA,IAAA,CAAK,WAAW,SAAA,GAAY,CAAA,4JAAA,CAAA;AAAA,IAC9B,CAAA;AAEA,IAAA,MAAM,KAAA,GAAQ,QAAA,CAAS,aAAA,CAAc,OAAO,CAAA;AAC5C,IAAA,KAAA,CAAM,WAAA,GAAc;AAAA;AAAA;AAAA,eAAA,EAGP,KAAK,WAAW,CAAA;AAAA,gBAAA,EACf,KAAK,YAAY,CAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,oBAAA,EAQb,IAAA,CAAK,KAAA,KAAU,MAAA,GAAS,SAAA,GAAY,OAAO,CAAA;AAAA;AAAA,IAAA,CAAA;AAI7D,IAAA,IAAA,CAAK,WAAW,SAAA,GAAY,EAAA;AAC5B,IAAA,IAAA,CAAK,UAAA,CAAW,YAAY,KAAK,CAAA;AACjC,IAAA,IAAA,CAAK,UAAA,CAAW,YAAY,MAAM,CAAA;AAClC,IAAA,IAAA,CAAK,MAAA,GAAS,MAAA;AAAA,EAChB;AAAA,EAEA,IAAY,aAAA,GAAwB;AAClC,IAAA,OAAO,IAAA,CAAK,MAAA;AAAA,EACd;AACF;AAEA,IACE,OAAO,cAAA,KAAmB,WAAA,IAC1B,CAAC,cAAA,CAAe,GAAA,CAAI,gBAAgB,CAAA,EACpC;AACA,EAAA,cAAA,CAAe,MAAA,CAAO,kBAAkB,oBAAoB,CAAA;AAC9D","file":"profile-web-component.mjs","sourcesContent":["/**\n * Theming props for the Profile Widget.\n * These map to CSS custom properties used internally.\n */\nexport interface ProfileThemingProps {\n  /** Container background color */\n  profileBackgroundColor?: string;\n  /** Primary text color */\n  profileTextColor?: string;\n  /** Secondary text color */\n  profileSecondaryTextColor?: string;\n  /** Border color */\n  profileBorderColor?: string;\n  /** Container border radius, e.g. \"12px\" */\n  profileBorderRadius?: string;\n  /** Container padding */\n  profilePadding?: string;\n  /** Container box shadow */\n  profileShadow?: string;\n  /** Primary accent color */\n  profilePrimaryColor?: string;\n  /** Primary hover color */\n  profilePrimaryHover?: string;\n  /** Accent color */\n  profileAccentColor?: string;\n  /** Card background */\n  profileCardBg?: string;\n  /** Card border */\n  profileCardBorder?: string;\n  /** Card border radius */\n  profileCardRadius?: string;\n  /** Card box shadow */\n  profileCardShadow?: string;\n  /** Card padding */\n  profileCardPadding?: string;\n  /** Avatar size, e.g. \"80px\" */\n  profileAvatarSize?: string;\n  /** Avatar border radius */\n  profileAvatarRadius?: string;\n  /** Avatar border */\n  profileAvatarBorder?: string;\n  /** Avatar box shadow */\n  profileAvatarShadow?: string;\n  /** Header background */\n  profileHeaderBg?: string;\n  /** Header height */\n  profileHeaderHeight?: string;\n  /** Badge background */\n  profileBadgeBg?: string;\n  /** Badge text color */\n  profileBadgeColor?: string;\n  /** Badge border radius */\n  profileBadgeRadius?: string;\n  /** Stat background */\n  profileStatBg?: string;\n  /** Stat border */\n  profileStatBorder?: string;\n  /** Stat value text color */\n  profileStatValueColor?: string;\n  /** Stat label text color */\n  profileStatLabelColor?: string;\n  /** Tab active background */\n  profileTabActiveBg?: string;\n  /** Tab active text color */\n  profileTabActiveColor?: string;\n  /** Tab text color */\n  profileTabColor?: string;\n  /** Tab hover background */\n  profileTabHoverBg?: string;\n  /** Tab border radius */\n  profileTabRadius?: string;\n  /** Button background */\n  profileButtonBg?: string;\n  /** Button hover background */\n  profileButtonHoverBg?: string;\n  /** Button text color */\n  profileButtonColor?: string;\n  /** Button border radius */\n  profileButtonRadius?: string;\n  /** Font family */\n  profileFontFamily?: string;\n  /** Name font size */\n  profileNameSize?: string;\n  /** Name font weight */\n  profileNameWeight?: string;\n  /** Username font size */\n  profileUsernameSize?: string;\n  /** Bio font size */\n  profileBioSize?: string;\n  /** Stat font size */\n  profileStatSize?: string;\n  /** Label font size */\n  profileLabelSize?: string;\n  /** Divider color */\n  profileDividerColor?: string;\n  /** Transition duration, e.g. \"0.2s\" */\n  profileTransitionDuration?: string;\n  /** Hover scale factor, e.g. \"1.02\" */\n  profileHoverScale?: string;\n}\n\n/**\n * Core configuration props for the Profile Widget.\n */\nexport interface ProfileWidgetProps extends ProfileThemingProps {\n  /** Base URL of the Legion application (required) */\n  baseUrl: string;\n  /** JWT auth token for authenticated profile viewing */\n  authToken?: string;\n  /** Theme preset. Default: \"light\" */\n  theme?: \"light\" | \"dark\";\n  /** Widget width CSS value. Default: \"400px\" */\n  width?: string;\n  /** Widget height CSS value. Default: \"400px\" */\n  height?: string;\n  /** Additional CSS class name for the container */\n  className?: string;\n  /** Additional inline styles for the container */\n  style?: React.CSSProperties;\n  /** Callback when the widget iframe has loaded */\n  onLoad?: (detail: { widget: string; theme: string }) => void;\n  /** Callback when the widget iframe fails to load */\n  onError?: (message: string) => void;\n}\n\n/**\n * Mapping from camelCase theming prop names to the kebab-case query\n * parameter names used by the profile widget iframe URL.\n */\nexport const PROFILE_THEMING_PROP_TO_PARAM: Record<\n  keyof ProfileThemingProps,\n  string\n> = {\n  profileBackgroundColor: \"profile-background-color\",\n  profileTextColor: \"profile-text-color\",\n  profileSecondaryTextColor: \"profile-secondary-text-color\",\n  profileBorderColor: \"profile-border-color\",\n  profileBorderRadius: \"profile-border-radius\",\n  profilePadding: \"profile-padding\",\n  profileShadow: \"profile-shadow\",\n  profilePrimaryColor: \"profile-primary-color\",\n  profilePrimaryHover: \"profile-primary-hover\",\n  profileAccentColor: \"profile-accent-color\",\n  profileCardBg: \"profile-card-bg\",\n  profileCardBorder: \"profile-card-border\",\n  profileCardRadius: \"profile-card-radius\",\n  profileCardShadow: \"profile-card-shadow\",\n  profileCardPadding: \"profile-card-padding\",\n  profileAvatarSize: \"profile-avatar-size\",\n  profileAvatarRadius: \"profile-avatar-radius\",\n  profileAvatarBorder: \"profile-avatar-border\",\n  profileAvatarShadow: \"profile-avatar-shadow\",\n  profileHeaderBg: \"profile-header-bg\",\n  profileHeaderHeight: \"profile-header-height\",\n  profileBadgeBg: \"profile-badge-bg\",\n  profileBadgeColor: \"profile-badge-color\",\n  profileBadgeRadius: \"profile-badge-radius\",\n  profileStatBg: \"profile-stat-bg\",\n  profileStatBorder: \"profile-stat-border\",\n  profileStatValueColor: \"profile-stat-value-color\",\n  profileStatLabelColor: \"profile-stat-label-color\",\n  profileTabActiveBg: \"profile-tab-active-bg\",\n  profileTabActiveColor: \"profile-tab-active-color\",\n  profileTabColor: \"profile-tab-color\",\n  profileTabHoverBg: \"profile-tab-hover-bg\",\n  profileTabRadius: \"profile-tab-radius\",\n  profileButtonBg: \"profile-button-bg\",\n  profileButtonHoverBg: \"profile-button-hover-bg\",\n  profileButtonColor: \"profile-button-color\",\n  profileButtonRadius: \"profile-button-radius\",\n  profileFontFamily: \"profile-font-family\",\n  profileNameSize: \"profile-name-size\",\n  profileNameWeight: \"profile-name-weight\",\n  profileUsernameSize: \"profile-username-size\",\n  profileBioSize: \"profile-bio-size\",\n  profileStatSize: \"profile-stat-size\",\n  profileLabelSize: \"profile-label-size\",\n  profileDividerColor: \"profile-divider-color\",\n  profileTransitionDuration: \"profile-transition-duration\",\n  profileHoverScale: \"profile-hover-scale\",\n};\n\n","/**\n * Auth bridge for `<legion-*>` web components (plan §4.2, LEG-444).\n *\n * Wires three message paths around an iframe-backed widget:\n *\n *   parent page  --(window.postMessage 'legion:auth')-->  host component\n *   host         --(iframe.postMessage 'AUTH_TOKEN')---->  iframe\n *   iframe       --(window.postMessage 'legion:auth-expired')->  host component\n *                                                                      └─ re-emitted as\n *                                                                         CustomEvent('legion:auth-expired')\n *\n * Token sources, highest to lowest precedence:\n *   1. parent postMessage `{ type: \"legion:auth\", token }`\n *   2. `auth-token` attribute (canonical, plan §4.2)\n *   3. `api-key` attribute  (legacy alias, kept for backwards-compat)\n *\n * Parent → host messages are filtered against the comma-separated\n * `allowed-parent-origins` attribute. If unset, only `window.parent === self`\n * (top-level page) and same-origin parents are accepted.\n */\n\nexport interface AuthBridgeOptions {\n  /** Returns the live iframe element if mounted. */\n  iframeAccessor: () => HTMLIFrameElement | null;\n  /** Used as the targetOrigin when posting to the iframe. */\n  baseUrl: string;\n}\n\nexport interface AuthBridgeHandle {\n  /** Tear down listeners. Call from `disconnectedCallback`. */\n  detach(): void;\n  /** Push the current token to the iframe. Call after `iframe.onload`. */\n  postCurrentToken(): void;\n  /** Resolve the active token (parent override → auth-token → api-key). */\n  currentToken(): string | null;\n}\n\nconst AUTH_TOKEN_MESSAGE = \"AUTH_TOKEN\";\nconst PARENT_AUTH_MESSAGE = \"legion:auth\";\nconst IFRAME_EXPIRED_MESSAGE = \"legion:auth-expired\";\n\nfunction parseAllowedOrigins(host: HTMLElement): string[] {\n  const raw = host.getAttribute(\"allowed-parent-origins\") || \"\";\n  return raw\n    .split(\",\")\n    .map((s) => s.trim())\n    .filter(Boolean);\n}\n\nfunction isAllowedParentOrigin(host: HTMLElement, origin: string): boolean {\n  // Same-origin is always trusted.\n  if (origin === window.location.origin) return true;\n  const allowed = parseAllowedOrigins(host);\n  return allowed.includes(origin);\n}\n\nexport function attachAuthBridge(\n  host: HTMLElement,\n  opts: AuthBridgeOptions\n): AuthBridgeHandle {\n  // Token override pushed by the parent via postMessage. Wins over attrs.\n  let parentToken: string | null = null;\n\n  const currentToken = (): string | null => {\n    if (parentToken) return parentToken;\n    return host.getAttribute(\"auth-token\") || host.getAttribute(\"api-key\");\n  };\n\n  const postCurrentToken = (): void => {\n    const iframe = opts.iframeAccessor();\n    const token = currentToken();\n    if (!iframe || !iframe.contentWindow || !token) return;\n    iframe.contentWindow.postMessage(\n      { type: AUTH_TOKEN_MESSAGE, token },\n      opts.baseUrl\n    );\n  };\n\n  const onMessage = (event: MessageEvent): void => {\n    if (!event || typeof event.data !== \"object\" || event.data === null) {\n      return;\n    }\n    const data = event.data as { type?: unknown; token?: unknown };\n\n    // 1. Parent → host: token refresh.\n    if (data.type === PARENT_AUTH_MESSAGE) {\n      if (!isAllowedParentOrigin(host, event.origin)) return;\n      if (typeof data.token !== \"string\" || !data.token) return;\n      parentToken = data.token;\n      postCurrentToken();\n      return;\n    }\n\n    // 2. Iframe → host: token expired. The iframe is mounted in the\n    // shadow DOM; messages from it carry `event.source === iframe.contentWindow`.\n    if (data.type === IFRAME_EXPIRED_MESSAGE) {\n      const iframe = opts.iframeAccessor();\n      if (!iframe || event.source !== iframe.contentWindow) return;\n      host.dispatchEvent(\n        new CustomEvent(IFRAME_EXPIRED_MESSAGE, {\n          bubbles: true,\n          composed: true,\n        })\n      );\n    }\n  };\n\n  window.addEventListener(\"message\", onMessage);\n\n  return {\n    detach() {\n      window.removeEventListener(\"message\", onMessage);\n    },\n    postCurrentToken,\n    currentToken,\n  };\n}\n\n/** Attribute names the bridge cares about; widgets must add these to `observedAttributes`. */\nexport const AUTH_BRIDGE_OBSERVED_ATTRS = [\n  \"auth-token\",\n  \"api-key\",\n  \"allowed-parent-origins\",\n] as const;\n","/**\n * Web Component entry point for the Profile widget.\n *\n * Importing this module registers the <legion-profile> custom element\n * so it can be used in any HTML page or framework that supports web components.\n *\n * @example\n * ```ts\n * import '@legionhandtech/lht-react-widgets/profile-web-component';\n *\n * // Then use in HTML:\n * // <legion-profile api-url=\"https://your-domain.com\" auth-token=\"jwt\" />\n * ```\n */\n\nimport { PROFILE_THEMING_PROP_TO_PARAM } from \"./types\";\nimport { attachAuthBridge, type AuthBridgeHandle, AUTH_BRIDGE_OBSERVED_ATTRS } from \"../shared/auth-bridge\";\n\nconst PROFILE_CSS_ATTRIBUTES = Object.values(PROFILE_THEMING_PROP_TO_PARAM);\n\nclass LegionProfileElement extends HTMLElement {\n  public iframe: HTMLIFrameElement | null = null;\n  private authBridge: AuthBridgeHandle | null = null;\n\n  constructor() {\n    super();\n    this.attachShadow({ mode: \"open\" });\n  }\n\n  static get observedAttributes(): string[] {\n    return [\n      \"api-url\",\n      \n      \"width\",\n      \"height\",\n      \"theme\",\n      ...PROFILE_CSS_ATTRIBUTES,\n    \n      ...AUTH_BRIDGE_OBSERVED_ATTRS,\n    ];\n  }\n\n  connectedCallback(): void {\n    this.authBridge = attachAuthBridge(this, {\n      iframeAccessor: () => this.iframe,\n      baseUrl: this.bridgeBaseUrl,\n    });\n    this.render();\n  }\n\n  disconnectedCallback(): void {\n    this.authBridge?.detach();\n    this.authBridge = null;\n  }\n\n  attributeChangedCallback(\n    _name: string,\n    oldValue: string | null,\n    newValue: string | null\n  ): void {\n    if (oldValue !== newValue) {\n      this.render();\n    }\n  }\n\n  private get apiUrl(): string {\n    return this.getAttribute(\"api-url\") || window.location.origin;\n  }\n\n  private get widgetWidth(): string {\n    return this.getAttribute(\"width\") || \"400\";\n  }\n\n  private get widgetHeight(): string {\n    return this.getAttribute(\"height\") || \"400\";\n  }\n\n  private get theme(): string {\n    return this.getAttribute(\"theme\") || \"light\";\n  }\n\n  render(): void {\n    if (!this.shadowRoot) return;\n\n    const iframe = document.createElement(\"iframe\");\n    const url = new URL(\"/widget/profile\", this.apiUrl);\n\n    url.searchParams.set(\"theme\", this.theme);\n\n    PROFILE_CSS_ATTRIBUTES.forEach((attr) => {\n      const val = this.getAttribute(attr);\n      if (val !== null && val !== undefined && String(val).length > 0) {\n        url.searchParams.set(attr, val);\n      }\n    });\n\n    iframe.src = url.toString();\n    iframe.width = this.widgetWidth;\n    iframe.height = this.widgetHeight;\n    iframe.frameBorder = \"0\";\n    iframe.scrolling = \"no\";\n    iframe.title = \"Profile Widget\";\n\n    iframe.onload = () => {\n      this.authBridge?.postCurrentToken();\n      this.dispatchEvent(\n        new CustomEvent(\"load\", {\n          detail: { widget: \"profile\", theme: this.theme },\n        })\n      );\n    };\n\n    iframe.onerror = () => {\n      if (!this.shadowRoot) return;\n      this.shadowRoot.innerHTML = `<div style=\"padding:32px;text-align:center;color:#856404;background:#fff3cd;border:1px solid #ffeaa7;border-radius:8px;\">Failed to load profile widget</div>`;\n    };\n\n    const style = document.createElement(\"style\");\n    style.textContent = `\n      :host {\n        display: block;\n        width: ${this.widgetWidth}px;\n        height: ${this.widgetHeight}px;\n      }\n      iframe {\n        width: 100%;\n        height: 100%;\n        border: none;\n        border-radius: 8px;\n        box-shadow: 0 2px 10px rgba(0, 0, 0, 0.1);\n        background: ${this.theme === \"dark\" ? \"#1a1a1a\" : \"white\"};\n      }\n    `;\n\n    this.shadowRoot.innerHTML = \"\";\n    this.shadowRoot.appendChild(style);\n    this.shadowRoot.appendChild(iframe);\n    this.iframe = iframe;\n  }\n\n  private get bridgeBaseUrl(): string {\n    return this.apiUrl;\n  }\n}\n\nif (\n  typeof customElements !== \"undefined\" &&\n  !customElements.get(\"legion-profile\")\n) {\n  customElements.define(\"legion-profile\", LegionProfileElement);\n}\n\nexport { LegionProfileElement };\n\n"]}