{"version":3,"file":"irs-BCDd_qeK-UYf1d0bg.cjs","names":["createEvmPublicClient","KEY_HAS_PURPOSE_ABI","CREATE_IDENTITY_WITH_MANAGEMENT_KEYS_ABI","ADD_KEY_ABI","ADD_TRUSTED_ISSUER_ABI","ADD_CLAIM_ABI","REGISTER_IDENTITY_ABI","isValidEvmAddress","IDENTITY_ABI","IdentityOperationFailed","IS_VERIFIED_ABI","INVESTOR_COUNTRY_ABI","IS_TRUSTED_ISSUER_ABI","GET_IDENTITY_ABI","ID_FACTORY_EVENTS_ABI","IdentityAlreadyRegistered","resolveRpcUrl","runCapabilityWrite","asTypedEvmNetworkConfig","adaptSignAndBroadcast","guardRuntimeCapability"],"sources":["../../adapter-evm-core/dist/irs-BCDd_qeK.mjs"],"sourcesContent":["import { t as createEvmPublicClient } from \"./public-client-DtJS2A20.mjs\";\nimport { t as isValidEvmAddress } from \"./validation--Y5v5XOf.mjs\";\nimport { i as resolveRpcUrl } from \"./rpc-BMyYpWRW.mjs\";\nimport { c as guardRuntimeCapability, n as asTypedEvmNetworkConfig, r as assertValidAddress, t as adaptSignAndBroadcast } from \"./helpers-CYDHdjrw.mjs\";\nimport { a as GET_IDENTITY_ABI, c as INVESTOR_COUNTRY_ABI, d as KEY_HAS_PURPOSE_ABI, f as REGISTER_IDENTITY_ABI, i as CREATE_IDENTITY_WITH_MANAGEMENT_KEYS_ABI, l as IS_TRUSTED_ISSUER_ABI, n as ADD_KEY_ABI, o as IDENTITY_ABI, r as ADD_TRUSTED_ISSUER_ABI, s as ID_FACTORY_EVENTS_ABI, t as ADD_CLAIM_ABI, u as IS_VERIFIED_ABI } from \"./abis-Dh-YTBuo.mjs\";\nimport { t as runCapabilityWrite } from \"./executor-CEYC5o85.mjs\";\nimport { logger } from \"@openzeppelin/ui-utils\";\nimport { encodeAbiParameters, getAddress, isAddressEqual, keccak256, parseEventLogs } from \"viem\";\nimport { IdentityAlreadyRegistered, IdentityOperationFailed } from \"@openzeppelin/ui-types\";\n\n//#region src/irs/identity-keys.ts\n/**\n* ONCHAINID ERC-734 key helpers (pinned to `@onchain-id/solidity@2.2.1`).\n*\n* @module irs/identity-keys\n*/\nconst LOG_SYSTEM$2 = \"EvmIrsIdentityKeys\";\n/** ERC-734 purpose: MANAGEMENT key (can manage the identity, including `addKey`). */\nconst IDENTITY_KEY_PURPOSE_MANAGEMENT = 1;\n/** ERC-734 key type: ECDSA (standard for Ethereum addresses). */\nconst IDENTITY_KEY_TYPE_ECDSA = 1;\n/**\n* The bytes32 key hash IdFactory / Identity use for an Ethereum address:\n* `keccak256(abi.encode(address))`.\n*/\nfunction addressToIdentityKeyHash(address) {\n\treturn keccak256(encodeAbiParameters([{ type: \"address\" }], [address]));\n}\n/** Read `keyHasPurpose` on an ONCHAINID identity contract without collapsing RPC errors. */\nasync function lookupIdentityKeyPurpose(rpcUrl, onchainId, address, purpose, viemChain) {\n\tconst client = createEvmPublicClient(rpcUrl, viemChain);\n\ttry {\n\t\treturn await client.readContract({\n\t\t\taddress: onchainId,\n\t\t\tabi: KEY_HAS_PURPOSE_ABI,\n\t\t\tfunctionName: \"keyHasPurpose\",\n\t\t\targs: [addressToIdentityKeyHash(address), BigInt(purpose)]\n\t\t}) ? { status: \"has\" } : { status: \"lacks\" };\n\t} catch (error) {\n\t\tconst cause = error instanceof Error ? error : new Error(String(error));\n\t\tlogger.error(LOG_SYSTEM$2, `lookupIdentityKeyPurpose failed for ${address} on ${onchainId}:`, cause);\n\t\treturn {\n\t\t\tstatus: \"read_failed\",\n\t\t\tcause\n\t\t};\n\t}\n}\n\n//#endregion\n//#region src/irs/actions.ts\n/**\n* Assembles `createIdentityWithManagementKeys` on the identity factory.\n*\n* Grants MANAGEMENT to `operatorManagementKey` only; the holder is linked as a wallet but\n* cannot manage the identity until {@link assembleGrantHolderManagementKeyAction} runs.\n*/\nfunction assembleDeployOnchainIdAction(factoryAddress, holder, salt, operatorManagementKey) {\n\treturn {\n\t\taddress: factoryAddress,\n\t\tabi: CREATE_IDENTITY_WITH_MANAGEMENT_KEYS_ABI,\n\t\tfunctionName: \"createIdentityWithManagementKeys\",\n\t\targs: [\n\t\t\tholder,\n\t\t\tsalt,\n\t\t\t[addressToIdentityKeyHash(operatorManagementKey)]\n\t\t]\n\t};\n}\n/** Assembles `addKey(holderKey, MANAGEMENT, ECDSA)` on an ONCHAINID identity. */\nfunction assembleGrantHolderManagementKeyAction(onchainId, holder) {\n\treturn {\n\t\taddress: onchainId,\n\t\tabi: ADD_KEY_ABI,\n\t\tfunctionName: \"addKey\",\n\t\targs: [\n\t\t\taddressToIdentityKeyHash(holder),\n\t\t\tBigInt(IDENTITY_KEY_PURPOSE_MANAGEMENT),\n\t\t\tBigInt(IDENTITY_KEY_TYPE_ECDSA)\n\t\t]\n\t};\n}\n/** Assembles `addTrustedIssuer(address _trustedIssuer, uint256[] _claimTopics)`. */\nfunction assembleAddTrustedIssuerAction(trustedIssuersRegistry, issuer, topics) {\n\treturn {\n\t\taddress: trustedIssuersRegistry,\n\t\tabi: ADD_TRUSTED_ISSUER_ABI,\n\t\tfunctionName: \"addTrustedIssuer\",\n\t\targs: [issuer, topics.map((topic) => BigInt(topic))]\n\t};\n}\n/**\n* Assembles `addClaim(...)` on an ONCHAINID from a **pre-signed** claim.\n* The issuer key never enters this module — only the issuer's signature is relayed.\n*/\nfunction assembleAttachClaimAction(onchainId, claim, issuerAddress) {\n\treturn {\n\t\taddress: onchainId,\n\t\tabi: ADD_CLAIM_ABI,\n\t\tfunctionName: \"addClaim\",\n\t\targs: [\n\t\t\tBigInt(claim.topic),\n\t\t\tBigInt(claim.scheme),\n\t\t\tclaim.issuer ?? issuerAddress,\n\t\t\tclaim.signature,\n\t\t\tclaim.data,\n\t\t\t\"\"\n\t\t]\n\t};\n}\n/** Assembles `registerIdentity(address _userAddress, address _identity, uint16 _country)`. */\nfunction assembleRegisterIdentityAction(registryAddress, holder, onchainId, country) {\n\treturn {\n\t\taddress: registryAddress,\n\t\tabi: REGISTER_IDENTITY_ABI,\n\t\tfunctionName: \"registerIdentity\",\n\t\targs: [\n\t\t\tholder,\n\t\t\tonchainId,\n\t\t\tcountry\n\t\t]\n\t};\n}\n\n//#endregion\n//#region src/irs/claim-payload.ts\n/**\n* Pure, key-free claim payload builder (FR-008a).\n*\n* Computes the canonical digest a trusted issuer signs out-of-band to produce an\n* {@link OnboardingClaim}. This module performs **no RPC and holds no signing key** —\n* it is a deterministic function of its inputs.\n*\n* The digest matches the ONCHAINID / ERC-735 claim-signature convention used by\n* `IClaimIssuer.isClaimValid`:\n*\n* ```solidity\n* dataHash = keccak256(abi.encode(identityHolder, topic, data))\n* ```\n*\n* The issuer signs `dataHash` (the wallet applies the EIP-191 personal-sign prefix),\n* yielding the `signature` carried by {@link OnboardingClaim}.\n*\n* @module irs/claim-payload\n* @see https://docs.onchainid.com/docs/developers/contracts/ (addClaim signature structure)\n*/\n/**\n* Build the canonical, signable claim digest for an ONCHAINID claim.\n*\n* Pure and key-free: identical inputs always yield identical output, with no RPC\n* and no signing.\n*\n* @param input - The ONCHAINID address, topic, scheme, and hex-encoded data.\n* @returns The {@link ClaimPayload} with the digest to sign and the echoed fields.\n*/\nfunction buildClaimPayload(input) {\n\tconst { onchainId, topic, scheme, data } = input;\n\treturn {\n\t\tdigest: keccak256(encodeAbiParameters([\n\t\t\t{ type: \"address\" },\n\t\t\t{ type: \"uint256\" },\n\t\t\t{ type: \"bytes\" }\n\t\t], [\n\t\t\tonchainId,\n\t\t\tBigInt(topic),\n\t\t\tdata\n\t\t])),\n\t\ttopic,\n\t\tscheme,\n\t\tdata\n\t};\n}\n\n//#endregion\n//#region src/irs/management-key.ts\n/**\n* Validation for the operator management key configured on IRS construction.\n*\n* The key MUST be the address that will later call `attachClaim` — never inferred from the\n* transaction signer, because the factory `onlyOwner` may be a relayer contract.\n*\n* @module irs/management-key\n*/\n/** Thrown when `operatorManagementKey` is missing or not a valid EVM address. */\nvar InvalidOperatorManagementKeyError = class extends Error {\n\tconstructor(message) {\n\t\tsuper(message);\n\t\tthis.name = \"InvalidOperatorManagementKeyError\";\n\t}\n};\n/**\n* Validate the operator management key at capability construction.\n*\n* @throws {InvalidOperatorManagementKeyError} when absent or malformed.\n*/\nfunction assertValidOperatorManagementKey(operatorManagementKey) {\n\tif (operatorManagementKey === void 0 || operatorManagementKey === \"\") throw new InvalidOperatorManagementKeyError(\"operatorManagementKey is required: pass the address that will execute attachClaim (the saga operator EOA). Do not infer it from the transaction signer — the IdFactory owner may be a relayer contract.\");\n\tif (!isValidEvmAddress(operatorManagementKey)) throw new InvalidOperatorManagementKeyError(`Invalid operatorManagementKey: '${operatorManagementKey}' is not a valid EVM address.`);\n}\n\n//#endregion\n//#region src/irs/onchain-reader.ts\nconst LOG_SYSTEM$1 = \"EvmIrsReader\";\nconst ZERO_ADDRESS = \"0x0000000000000000000000000000000000000000\";\nfunction isZeroAddress(address) {\n\treturn address.toLowerCase() === ZERO_ADDRESS;\n}\n/**\n* Look up the ONCHAINID registered for `holder` in the identity registry.\n*\n* @returns `{ found: true, onchainId }` when registered, `{ found: false }` otherwise.\n* @throws {IdentityOperationFailed} On RPC failure (not for the expected-negative case).\n*/\nasync function getOnchainId(rpcUrl, registryAddress, holder, viemChain) {\n\tconst client = createEvmPublicClient(rpcUrl, viemChain);\n\ttry {\n\t\tconst onchainId = await client.readContract({\n\t\t\taddress: registryAddress,\n\t\t\tabi: IDENTITY_ABI,\n\t\t\tfunctionName: \"identity\",\n\t\t\targs: [holder]\n\t\t});\n\t\tif (isZeroAddress(onchainId)) return { found: false };\n\t\treturn {\n\t\t\tfound: true,\n\t\t\tonchainId\n\t\t};\n\t} catch (error) {\n\t\tlogger.error(LOG_SYSTEM$1, `getOnchainId failed for ${holder}:`, error);\n\t\tthrow new IdentityOperationFailed(`Failed to read ONCHAINID for ${holder}: ${error.message}`, \"getOnchainId\", error, registryAddress);\n\t}\n}\n/**\n* The IRS verification pre-check. Returns `false` (never throws) for an unregistered\n* or unverifiable holder.\n*/\nasync function isVerified(rpcUrl, registryAddress, holder, viemChain) {\n\tconst client = createEvmPublicClient(rpcUrl, viemChain);\n\ttry {\n\t\treturn await client.readContract({\n\t\t\taddress: registryAddress,\n\t\t\tabi: IS_VERIFIED_ABI,\n\t\t\tfunctionName: \"isVerified\",\n\t\t\targs: [holder]\n\t\t});\n\t} catch {\n\t\tlogger.debug(LOG_SYSTEM$1, `isVerified read returned negative for ${holder}`);\n\t\treturn false;\n\t}\n}\n/**\n* Read the holder's jurisdiction (ISO-3166 numeric country code) as a string.\n* Returns `undefined` when unavailable (e.g. unregistered holder).\n*/\nasync function getJurisdiction(rpcUrl, registryAddress, holder, viemChain) {\n\tconst client = createEvmPublicClient(rpcUrl, viemChain);\n\ttry {\n\t\treturn (await client.readContract({\n\t\t\taddress: registryAddress,\n\t\t\tabi: INVESTOR_COUNTRY_ABI,\n\t\t\tfunctionName: \"investorCountry\",\n\t\t\targs: [holder]\n\t\t})).toString();\n\t} catch {\n\t\tlogger.debug(LOG_SYSTEM$1, `getJurisdiction unavailable for ${holder}`);\n\t\treturn;\n\t}\n}\n/**\n* Whether `issuer` is already registered in the Trusted Issuers Registry.\n* Returns `false` (never throws) when the read is unavailable, enabling idempotent writes.\n*/\nasync function isTrustedIssuer(rpcUrl, trustedIssuersRegistry, issuer, viemChain) {\n\tconst client = createEvmPublicClient(rpcUrl, viemChain);\n\ttry {\n\t\treturn await client.readContract({\n\t\t\taddress: trustedIssuersRegistry,\n\t\t\tabi: IS_TRUSTED_ISSUER_ABI,\n\t\t\tfunctionName: \"isTrustedIssuer\",\n\t\t\targs: [issuer]\n\t\t});\n\t} catch {\n\t\tlogger.debug(LOG_SYSTEM$1, `isTrustedIssuer read unavailable for ${issuer}`);\n\t\treturn false;\n\t}\n}\nasync function getIdentityFromFactory(rpcUrl, factoryAddress, wallet, viemChain) {\n\tconst client = createEvmPublicClient(rpcUrl, viemChain);\n\ttry {\n\t\tconst identity = await client.readContract({\n\t\t\taddress: factoryAddress,\n\t\t\tabi: GET_IDENTITY_ABI,\n\t\t\tfunctionName: \"getIdentity\",\n\t\t\targs: [wallet]\n\t\t});\n\t\treturn isZeroAddress(identity) ? { status: \"not_found\" } : {\n\t\t\tstatus: \"found\",\n\t\t\tonchainId: identity\n\t\t};\n\t} catch (error) {\n\t\tconst cause = error instanceof Error ? error : new Error(String(error));\n\t\tlogger.error(LOG_SYSTEM$1, `getIdentityFromFactory failed for ${wallet}:`, cause);\n\t\treturn {\n\t\t\tstatus: \"read_failed\",\n\t\t\tcause\n\t\t};\n\t}\n}\n\n//#endregion\n//#region src/irs/receipt-identity.ts\n/**\n* Resolve a deployed ONCHAINID from an IdFactory transaction receipt.\n*\n* A receipt only exists once the transaction is mined, so this is the confirmation gate\n* `deployOnchainId` must use instead of a follow-up `getIdentity` eth_call.\n*\n* @module irs/receipt-identity\n*/\nfunction factoryLogs(receipt, factoryAddress) {\n\tconst factory = getAddress(factoryAddress);\n\treturn receipt.logs.filter((log) => isAddressEqual(getAddress(log.address), factory));\n}\n/**\n* Parse `WalletLinked(wallet, identity)` from a successful deploy receipt.\n* Falls back to `Deployed(identity)` when WalletLinked is absent (defense-in-depth).\n*/\nfunction parseIdentityFromDeployReceipt(receipt, factoryAddress, holder) {\n\tif (receipt.status !== \"success\") return;\n\tconst wallet = getAddress(holder);\n\tconst logs = factoryLogs(receipt, factoryAddress);\n\tconst walletLinked = parseEventLogs({\n\t\tabi: ID_FACTORY_EVENTS_ABI,\n\t\tlogs,\n\t\teventName: \"WalletLinked\"\n\t}).find((entry) => isAddressEqual(entry.args.wallet, wallet));\n\tif (walletLinked !== void 0) return getAddress(walletLinked.args.identity);\n\tconst deployed = parseEventLogs({\n\t\tabi: ID_FACTORY_EVENTS_ABI,\n\t\tlogs,\n\t\teventName: \"Deployed\"\n\t})[0];\n\treturn deployed === void 0 ? void 0 : getAddress(deployed.args.identity);\n}\n/** Confirmations required before the deploy receipt is accepted. */\nconst DEFAULT_DEPLOY_CONFIRMATIONS = 1;\n/**\n* Upper bound on the confirmation wait. The wait MUST be bounded: an unbounded wait inside a\n* server-side route (such as a relayer plugin route) is an outage rather than a slow response.\n*/\nconst DEFAULT_DEPLOY_RECEIPT_TIMEOUT_MS = 12e4;\n/** Thrown for a `deployReceiptWait` that cannot uphold the bounded-wait guarantee. */\nvar InvalidDeployReceiptWaitError = class extends Error {\n\tconstructor(message) {\n\t\tsuper(message);\n\t\tthis.name = \"InvalidDeployReceiptWaitError\";\n\t}\n};\n/**\n* Resolve AND VALIDATE the effective wait bounds, so the call, the log line, and the timeout\n* message all quote the same numbers.\n*\n* ## Why this throws rather than clamping\n*\n* `??` only substitutes for `null` / `undefined`, so a bare `?? default` lets `0`, `NaN`,\n* `Infinity` and negatives through to viem — and each is actively harmful, verified against\n* viem 2.44.4 `actions/public/waitForTransactionReceipt.ts`:\n*\n* - `timeout: 0` — `const timer = timeout ? setTimeout(...) : undefined` (L175). A falsy timeout\n*   disables the timer entirely, producing exactly the UNBOUNDED wait this module's own docstring\n*   forbids: an outage inside a server-side route, not a slow response.\n* - `timeout: Infinity` / `NaN` — passed to `setTimeout`, which Node coerces to 1 ms. Every deploy\n*   would then time out almost immediately and report INDETERMINATE — the \"may still land, do not\n*   retry blind\" path — so every holder looks stuck.\n* - `confirmations: 0` — viem short-circuits on `confirmations <= 1` (L193), so 0 is\n*   behaviourally IDENTICAL to 1. Rejecting it removes no capability; it only removes ambiguity.\n*\n* Clamping was the alternative, and was rejected: silently rewriting a caller's safety bound would\n* hide a misconfiguration whose consequences are money-adjacent, and the only channel for saying\n* so would be a warning log — a channel this codebase has already been bitten by treating as\n* reliable. A throw is loud, and because {@link EvmIRSService} resolves these options in its\n* CONSTRUCTOR, it fires at boot rather than at the first deploy.\n*\n* @throws {InvalidDeployReceiptWaitError} for any value that cannot uphold a bounded wait.\n*/\nfunction resolveDeployReceiptWait(options) {\n\tconst confirmations = options?.confirmations ?? DEFAULT_DEPLOY_CONFIRMATIONS;\n\tconst timeoutMs = options?.timeoutMs ?? DEFAULT_DEPLOY_RECEIPT_TIMEOUT_MS;\n\tif (!Number.isInteger(confirmations) || confirmations < 1) throw new InvalidDeployReceiptWaitError(`deployReceiptWait.confirmations must be an integer >= 1, received ${String(confirmations)}. viem treats confirmations <= 1 identically, so use 1 for the fastest safe setting.`);\n\tif (!Number.isInteger(timeoutMs) || timeoutMs <= 0) throw new InvalidDeployReceiptWaitError(`deployReceiptWait.timeoutMs must be a finite integer > 0 (milliseconds), received ${String(timeoutMs)}. The deploy wait must stay bounded: viem disables its timeout timer for a falsy value, and Node coerces Infinity/NaN to 1 ms, so neither yields a usable bound.`);\n\treturn {\n\t\tconfirmations,\n\t\ttimeoutMs\n\t};\n}\n\n//#endregion\n//#region src/irs/service.ts\nconst LOG_SYSTEM = \"EvmIrsService\";\n/**\n* Sentinel `OperationResult.id` returned by the idempotent `registerTrustedIssuer` no-op path\n* (issuer already trusted, no transaction sent). Intentionally not a `0x` tx hash so consumers\n* never treat it as one.\n*/\nconst TRUSTED_ISSUER_NOOP_ID = \"noop:trusted-issuer-already-registered\";\n/**\n* EVM implementation of the IRS capability surface (sans the `RuntimeCapability` mixin).\n*/\nvar EvmIRSService = class {\n\taddresses;\n\ttrustedIssuer;\n\toperatorManagementKey;\n\t/**\n\t* Wait bounds, resolved AND VALIDATED at construction so a misconfiguration fails at boot\n\t* rather than at the first deploy — where the failure would land on a real holder.\n\t*/\n\tdeployReceiptWait;\n\tconstructor(networkConfig, executeTransaction, options) {\n\t\tthis.networkConfig = networkConfig;\n\t\tthis.executeTransaction = executeTransaction;\n\t\tthis.addresses = options.addresses;\n\t\tthis.trustedIssuer = options.trustedIssuer;\n\t\tthis.operatorManagementKey = options.operatorManagementKey;\n\t\tthis.deployReceiptWait = resolveDeployReceiptWait(options.deployReceiptWait);\n\t}\n\tgetOnchainId(holder) {\n\t\treturn getOnchainId(this.rpcUrl(), this.addresses.identityRegistry, holder);\n\t}\n\t/**\n\t* Factory linkage probe — distinct from registry `getOnchainId`.\n\t* Used by resume/idempotency paths that must detect deployed-but-unregistered holders.\n\t*/\n\tgetFactoryIdentity(holder) {\n\t\treturn getIdentityFromFactory(this.rpcUrl(), this.addresses.identityFactory, holder);\n\t}\n\t/**\n\t* Probe whether `address` holds `purpose` on an ONCHAINID identity.\n\t*\n\t* Used by resume/idempotency paths that must detect whether `grantHolderManagementKey`\n\t* already ran — `read_failed` must not be treated as `lacks`.\n\t*/\n\thasIdentityKeyPurpose(input) {\n\t\tconst { onchainId, address, purpose } = input;\n\t\treturn lookupIdentityKeyPurpose(this.rpcUrl(), onchainId, address, purpose);\n\t}\n\tisVerified(holder) {\n\t\treturn isVerified(this.rpcUrl(), this.addresses.identityRegistry, holder);\n\t}\n\tgetJurisdiction(holder) {\n\t\treturn getJurisdiction(this.rpcUrl(), this.addresses.identityRegistry, holder);\n\t}\n\tbuildClaimPayload(input) {\n\t\treturn buildClaimPayload(input);\n\t}\n\t/**\n\t* Deploy a fresh ONCHAINID for `holder`.\n\t*\n\t* Uses `createIdentityWithManagementKeys` so the configured {@link operatorManagementKey}\n\t* receives MANAGEMENT and can execute the subsequent saga steps (`attachClaim`, etc.).\n\t* The holder is wallet-linked but does **not** receive MANAGEMENT until\n\t* {@link grantHolderManagementKey} runs — that ordering is deliberate (see that method).\n\t*\n\t* **Pre-submit fidelity (SF-5):** probes {@link getFactoryIdentity} **before** execute\n\t* (both completion modes). `found` → {@link IdentityAlreadyRegistered} (no submit);\n\t* `read_failed` → {@link IdentityOperationFailed} ambiguous (no submit; never already-onboarded);\n\t* `not_found` → today's path below.\n\t*\n\t* **Completion (SF-2):** trusts SF-1 `WriteExecutionResult.completion` from {@link execute}.\n\t* - `completion === 'submitted'`: return `{ id, completion: 'submitted' }` with **no**\n\t*   `onchainId`. Skips receipt wait, log parse, and operator MANAGEMENT assert. Caller owns\n\t*   Relayer poll + {@link getFactoryIdentity} resume — submit-only `{ id }` is not proof the\n\t*   identity deployed.\n\t* - absent / `'confirmed'`: wait → parse → assert (byte-identical). Identity resolution parses\n\t*   `WalletLinked` (falling back to `Deployed`) out of the receipt obtained by **waiting** for\n\t*   confirmation — `waitForTransactionReceipt`, bounded by `deployReceiptWait`. Returns\n\t*   `{ id, onchainId, completion: 'confirmed' }` with required `onchainId`.\n\t*\n\t* Confirmed-path terminal outcomes (unchanged retry semantics):\n\t*  - confirmed + identity parsed  -> success\n\t*  - confirmed + reverted         -> nothing created, retry is SAFE\n\t*  - wait timed out               -> INDETERMINATE, may still land, DO NOT retry blind\n\t*    (never mapped to already-onboarded — typed indeterminate OUT of SF-5)\n\t*\n\t* On the confirmed arm this method makes no assumption about whether the injected executor\n\t* awaits confirmation; it establishes confirmation itself.\n\t*/\n\tasync deployOnchainId(input, executionConfig, onStatusChange, runtimeApiKey) {\n\t\tconst { holder } = input;\n\t\tconst factory = await this.getFactoryIdentity(holder);\n\t\tif (factory.status === \"found\") {\n\t\t\tlogger.info(LOG_SYSTEM, \"deployOnchainId: already-linked factory pre-submit\", {\n\t\t\t\tholder,\n\t\t\t\tonchainId: factory.onchainId\n\t\t\t});\n\t\t\tthrow new IdentityAlreadyRegistered(`Holder ${holder} already has a factory-linked identity ${factory.onchainId}.`, holder, factory.onchainId, this.addresses.identityFactory);\n\t\t}\n\t\tif (factory.status === \"read_failed\") {\n\t\t\tlogger.info(LOG_SYSTEM, \"deployOnchainId: pre-submit factory read_failed\", {\n\t\t\t\tholder,\n\t\t\t\tcause: factory.cause\n\t\t\t});\n\t\t\tthrow new IdentityOperationFailed(`deployOnchainId for ${holder}: factory identity probe failed via RPC before submit (ambiguous — not already-linked, not not_found). Do not retry blind.`, \"deployOnchainId\", factory.cause, this.addresses.identityFactory);\n\t\t}\n\t\tconst action = assembleDeployOnchainIdAction(this.addresses.identityFactory, holder, holder, this.operatorManagementKey);\n\t\tconst result = await this.execute(\"deployOnchainId\", action, executionConfig, onStatusChange, runtimeApiKey);\n\t\tif (result.completion === \"submitted\") {\n\t\t\tlogger.info(LOG_SYSTEM, \"deployOnchainId: submit-only early return\", {\n\t\t\t\toperation: \"deployOnchainId\",\n\t\t\t\tcompletion: \"submitted\",\n\t\t\t\tid: result.id,\n\t\t\t\tholder\n\t\t\t});\n\t\t\treturn {\n\t\t\t\tid: result.id,\n\t\t\t\tcompletion: \"submitted\"\n\t\t\t};\n\t\t}\n\t\tconst rpcUrl = this.rpcUrl();\n\t\tconst { confirmations, timeoutMs } = this.deployReceiptWait;\n\t\tlogger.info(LOG_SYSTEM, \"deployOnchainId: awaiting receipt for identity resolution\", {\n\t\t\ttxHash: result.id,\n\t\t\treadRpcHost: safeRpcHost(rpcUrl),\n\t\t\tfactory: this.addresses.identityFactory,\n\t\t\tholder,\n\t\t\tconfirmations,\n\t\t\ttimeoutMs\n\t\t});\n\t\tconst client = createEvmPublicClient(rpcUrl);\n\t\tlet receipt;\n\t\ttry {\n\t\t\treceipt = await client.waitForTransactionReceipt({\n\t\t\t\thash: result.id,\n\t\t\t\tconfirmations,\n\t\t\t\ttimeout: timeoutMs\n\t\t\t});\n\t\t} catch (error) {\n\t\t\tconst cause = error instanceof Error ? error : new Error(String(error));\n\t\t\tlogger.error(LOG_SYSTEM, \"deployOnchainId: receipt wait failed or timed out\", {\n\t\t\t\ttxHash: result.id,\n\t\t\t\tconfirmations,\n\t\t\t\ttimeoutMs,\n\t\t\t\tcause\n\t\t\t});\n\t\t\tthrow new IdentityOperationFailed(`ONCHAINID deployment for ${holder} was submitted (tx ${result.id}) but confirmation was not observed within ${timeoutMs}ms (${confirmations} confirmation(s) required): ${cause.message}. INDETERMINATE — the transaction MAY STILL LAND. Do NOT treat this as a failed deployment and do NOT retry blind: check the factory for an identity already linked to ${holder} first, because a re-attempted createIdentity reverts with \"wallet already linked to an identity\" and leaves the holder permanently orphaned.`, \"deployOnchainId\", cause, this.addresses.identityFactory);\n\t\t}\n\t\tif (receipt.status !== \"success\") {\n\t\t\tlogger.error(LOG_SYSTEM, \"deployOnchainId: transaction reverted\", {\n\t\t\t\ttxHash: result.id,\n\t\t\t\treceiptStatus: receipt.status\n\t\t\t});\n\t\t\tthrow new IdentityOperationFailed(`ONCHAINID deployment for ${holder} REVERTED on-chain (tx ${result.id}, receipt status \"${receipt.status}\"). No identity was created, so nothing is orphaned and a retry is safe once the revert cause is addressed.`, \"deployOnchainId\", void 0, this.addresses.identityFactory);\n\t\t}\n\t\tconst onchainId = parseIdentityFromDeployReceipt(receipt, this.addresses.identityFactory, holder);\n\t\tlogger.info(LOG_SYSTEM, \"deployOnchainId: receipt identity resolution\", {\n\t\t\ttxHash: result.id,\n\t\t\treceiptStatus: receipt.status,\n\t\t\tresolvedOnchainId: onchainId ?? null\n\t\t});\n\t\tif (!onchainId) throw new IdentityOperationFailed(`ONCHAINID deployment for ${holder} SUCCEEDED on-chain (tx ${result.id}) but no identity was resolvable from the factory receipt logs. An identity LIKELY EXISTS for this holder — do NOT retry blind: probe the factory first, because a re-attempted createIdentity reverts with \"wallet already linked to an identity\".`, \"deployOnchainId\", void 0, this.addresses.identityFactory);\n\t\tawait this.assertIdentityKeyHasPurpose({\n\t\t\toperation: \"deployOnchainId\",\n\t\t\tonchainId,\n\t\t\taddress: this.operatorManagementKey,\n\t\t\tpurpose: IDENTITY_KEY_PURPOSE_MANAGEMENT,\n\t\t\tmissingPurposeMessage: `ONCHAINID deployment for ${holder} succeeded (identity ${onchainId}) but operatorManagementKey ${this.operatorManagementKey} does not hold MANAGEMENT on the identity. The configured key must be the address that will execute attachClaim.`,\n\t\t\trpcFailureMessage: `ONCHAINID deployment for ${holder} succeeded (identity ${onchainId}, tx ${result.id}) but could not verify operatorManagementKey ${this.operatorManagementKey} MANAGEMENT via RPC. The identity LIKELY EXISTS — resume the saga using onchainId ${onchainId}.`\n\t\t});\n\t\treturn {\n\t\t\tid: result.id,\n\t\t\tonchainId,\n\t\t\tcompletion: \"confirmed\"\n\t\t};\n\t}\n\t/**\n\t* Grant the holder a MANAGEMENT key on their ONCHAINID.\n\t*\n\t* **Saga ordering is load-bearing:** consumers MUST call this after `deployOnchainId` and\n\t* **before** `attachClaim`. If attach-claim or register fails partway through onboarding, the\n\t* holder already holds MANAGEMENT and can rescue their own identity. Running this after\n\t* attach-claim would leave a partial failure with an identity only the operator can touch —\n\t* a fresh orphan trap. Do not reorder for convenience.\n\t*\n\t* **Pre-submit fidelity (SF-5):** probes {@link lookupIdentityKeyPurpose} for MANAGEMENT\n\t* **before** execute (both completion modes). Mirrors {@link registerIdentity} pre-read→throw:\n\t* - `has` → {@link IdentityAlreadyRegistered} (`ALREADY_ONBOARDED`); no submit\n\t* - `read_failed` → {@link IdentityOperationFailed} ambiguous; no submit\n\t*   (never invent already-onboarded or lacks)\n\t* - `lacks` → today's path below\n\t*\n\t* **Completion (SF-3):** trusts SF-1 `WriteExecutionResult.completion` from {@link execute}.\n\t* - `completion === 'submitted'`: return `{ id }` without post-submit key-purpose assert.\n\t*   Submit-only `{ id }` is **not** proof that MANAGEMENT landed — confirm via\n\t*   {@link hasIdentityKeyPurpose} (or Relayer/WAL).\n\t* - absent / `'confirmed'`: assert holder MANAGEMENT via `keyHasPurpose`; throw\n\t*   {@link IdentityOperationFailed} on lacks / RPC fail (unchanged).\n\t*/\n\tasync grantHolderManagementKey(input, executionConfig, onStatusChange, runtimeApiKey) {\n\t\tconst { onchainId, holder } = input;\n\t\tconst probe = await lookupIdentityKeyPurpose(this.rpcUrl(), onchainId, holder, IDENTITY_KEY_PURPOSE_MANAGEMENT);\n\t\tif (probe.status === \"has\") {\n\t\t\tlogger.info(LOG_SYSTEM, \"grantHolderManagementKey: already-onboarded pre-submit\", {\n\t\t\t\tholder,\n\t\t\t\tonchainId\n\t\t\t});\n\t\t\tthrow new IdentityAlreadyRegistered(`Holder ${holder} already holds MANAGEMENT on identity ${onchainId}.`, holder, onchainId, onchainId);\n\t\t}\n\t\tif (probe.status === \"read_failed\") {\n\t\t\tlogger.info(LOG_SYSTEM, \"grantHolderManagementKey: pre-submit key-purpose read_failed\", {\n\t\t\t\tholder,\n\t\t\t\tonchainId,\n\t\t\t\tcause: probe.cause\n\t\t\t});\n\t\t\tthrow new IdentityOperationFailed(`grantHolderManagementKey for ${holder} on ${onchainId}: could not verify MANAGEMENT via RPC before submit (ambiguous — not already-onboarded, not lacks). Do not guess; retry the probe or resume after RPC recovers.`, \"grantHolderManagementKey\", probe.cause, onchainId);\n\t\t}\n\t\tconst action = assembleGrantHolderManagementKeyAction(onchainId, holder);\n\t\tconst result = await this.execute(\"grantHolderManagementKey\", action, executionConfig, onStatusChange, runtimeApiKey);\n\t\tif (result.completion === \"submitted\") return { id: result.id };\n\t\tawait this.assertIdentityKeyHasPurpose({\n\t\t\toperation: \"grantHolderManagementKey\",\n\t\t\tonchainId,\n\t\t\taddress: holder,\n\t\t\tpurpose: IDENTITY_KEY_PURPOSE_MANAGEMENT,\n\t\t\tmissingPurposeMessage: `grantHolderManagementKey for ${holder} on ${onchainId} was submitted (tx ${result.id}) but the holder does not hold MANAGEMENT on the identity.`,\n\t\t\trpcFailureMessage: `grantHolderManagementKey for ${holder} on ${onchainId} was submitted (tx ${result.id}) but could not verify holder MANAGEMENT via RPC. Resume the saga using onchainId ${onchainId}.`\n\t\t});\n\t\treturn { id: result.id };\n\t}\n\tasync registerTrustedIssuer(input, executionConfig, onStatusChange, runtimeApiKey) {\n\t\tconst { issuer, topics } = input;\n\t\tif (await isTrustedIssuer(this.rpcUrl(), this.addresses.trustedIssuersRegistry, issuer)) {\n\t\t\tlogger.debug(LOG_SYSTEM, `Trusted issuer ${issuer} already registered; skipping submission.`);\n\t\t\treturn { id: TRUSTED_ISSUER_NOOP_ID };\n\t\t}\n\t\tconst action = assembleAddTrustedIssuerAction(this.addresses.trustedIssuersRegistry, issuer, topics);\n\t\treturn { id: (await this.execute(\"registerTrustedIssuer\", action, executionConfig, onStatusChange, runtimeApiKey)).id };\n\t}\n\tasync attachClaim(input, executionConfig, onStatusChange, runtimeApiKey) {\n\t\tconst { onchainId, claim } = input;\n\t\tconst issuerAddress = claim.issuer ?? this.trustedIssuer;\n\t\tif (!issuerAddress) throw new IdentityOperationFailed(\"attachClaim requires an issuer address: provide claim.issuer or configure a trustedIssuer.\", \"attachClaim\", void 0, onchainId);\n\t\tconst action = assembleAttachClaimAction(onchainId, claim, issuerAddress);\n\t\treturn { id: (await this.execute(\"attachClaim\", action, executionConfig, onStatusChange, runtimeApiKey)).id };\n\t}\n\tasync registerIdentity(input, executionConfig, onStatusChange, runtimeApiKey) {\n\t\tconst { holder, onchainId, country = 0 } = input;\n\t\tconst existing = await this.getOnchainId(holder);\n\t\tif (existing.found) throw new IdentityAlreadyRegistered(`Holder ${holder} already has a registered identity.`, holder, existing.onchainId, this.addresses.identityRegistry);\n\t\tconst action = assembleRegisterIdentityAction(this.addresses.identityRegistry, holder, onchainId, country);\n\t\treturn { id: (await this.execute(\"registerIdentity\", action, executionConfig, onStatusChange, runtimeApiKey)).id };\n\t}\n\tdispose() {\n\t\tlogger.debug(LOG_SYSTEM, \"IRS service disposed.\");\n\t}\n\trpcUrl() {\n\t\treturn resolveRpcUrl(this.networkConfig);\n\t}\n\tasync assertIdentityKeyHasPurpose(input) {\n\t\tconst { operation, onchainId, address, purpose, missingPurposeMessage, rpcFailureMessage } = input;\n\t\tconst lookup = await lookupIdentityKeyPurpose(this.rpcUrl(), onchainId, address, purpose);\n\t\tif (lookup.status === \"read_failed\") throw new IdentityOperationFailed(rpcFailureMessage, operation, lookup.cause, onchainId);\n\t\tif (lookup.status === \"lacks\") throw new IdentityOperationFailed(missingPurposeMessage, operation, void 0, onchainId);\n\t}\n\t/**\n\t* Typing hygiene (INV-22): `runCapabilityWrite` already returns {@link WriteExecutionResult}.\n\t* Widening the annotation lets grant (and future SF-2 deploy) read `.completion` without casts.\n\t* Runtime passthrough — no wrapper that could strip `completion`.\n\t*/\n\texecute(operation, action, executionConfig, onStatusChange, runtimeApiKey) {\n\t\treturn runCapabilityWrite({\n\t\t\toperation,\n\t\t\taction,\n\t\t\texecutor: this.executeTransaction,\n\t\t\texecutionConfig,\n\t\t\tonStatusChange,\n\t\t\truntimeApiKey\n\t\t}, (error, op, contractAddress) => new IdentityOperationFailed(`IRS ${op} failed: ${error.message}`, op, error, contractAddress));\n\t}\n};\n/**\n* Factory for {@link EvmIRSService}.\n*/\nfunction createEvmIRSService(networkConfig, executeTransaction, options) {\n\treturn new EvmIRSService(networkConfig, executeTransaction, options);\n}\nfunction safeRpcHost(rpcUrl) {\n\ttry {\n\t\treturn new URL(rpcUrl).host;\n\t} catch {\n\t\treturn \"(invalid-url)\";\n\t}\n}\n\n//#endregion\n//#region src/capabilities/irs.ts\n/**\n* Create the EVM IRS / ONCHAINID capability.\n*\n* Mirrors {@link createAccessControl}: assembles the service, adapts the injected\n* `signAndBroadcast` into the service's executor, and wraps the result with\n* `guardRuntimeCapability` for the `RuntimeCapability` surface and idempotent `dispose()`.\n*/\nfunction createIRS(config, options) {\n\tconst networkConfig = asTypedEvmNetworkConfig(config);\n\tassertValidAddress(\"addresses.identityRegistry\", options.addresses.identityRegistry);\n\tassertValidAddress(\"addresses.identityFactory\", options.addresses.identityFactory);\n\tassertValidAddress(\"addresses.trustedIssuersRegistry\", options.addresses.trustedIssuersRegistry);\n\tif (options.trustedIssuer !== void 0) assertValidAddress(\"trustedIssuer\", options.trustedIssuer);\n\tassertValidOperatorManagementKey(options.operatorManagementKey);\n\tconst service = createEvmIRSService(networkConfig, adaptSignAndBroadcast(options.signAndBroadcast), {\n\t\taddresses: options.addresses,\n\t\ttrustedIssuer: options.trustedIssuer,\n\t\toperatorManagementKey: options.operatorManagementKey,\n\t\tdeployReceiptWait: options.deployReceiptWait\n\t});\n\treturn guardRuntimeCapability(service, networkConfig, \"irs\", () => service.dispose(), \"general\");\n}\n\n//#endregion\nexport { getOnchainId as a, buildClaimPayload as c, getJurisdiction as i, EvmIRSService as n, isTrustedIssuer as o, createEvmIRSService as r, isVerified as s, createIRS as t };\n//# sourceMappingURL=irs-BCDd_qeK.mjs.map"],"mappings":";;;;;;;;;;;;;;;;;AAgBA,MAAM,eAAe;;AAErB,MAAM,kCAAkC;;AAExC,MAAM,0BAA0B;;;;;AAKhC,SAAS,yBAAyB,SAAS;AAC1C,0DAAqC,CAAC,EAAE,MAAM,WAAW,CAAC,EAAE,CAAC,QAAQ,CAAC,CAAC;;;AAGxE,eAAe,yBAAyB,QAAQ,WAAW,SAAS,SAAS,WAAW;CACvF,MAAM,SAASA,qDAAsB,QAAQ,UAAU;AACvD,KAAI;AACH,SAAO,MAAM,OAAO,aAAa;GAChC,SAAS;GACT,KAAKC;GACL,cAAc;GACd,MAAM,CAAC,yBAAyB,QAAQ,EAAE,OAAO,QAAQ,CAAC;GAC1D,CAAC,GAAG,EAAE,QAAQ,OAAO,GAAG,EAAE,QAAQ,SAAS;UACpC,OAAO;EACf,MAAM,QAAQ,iBAAiB,QAAQ,QAAQ,IAAI,MAAM,OAAO,MAAM,CAAC;AACvE,gCAAO,MAAM,cAAc,uCAAuC,QAAQ,MAAM,UAAU,IAAI,MAAM;AACpG,SAAO;GACN,QAAQ;GACR;GACA;;;;;;;;;AAYH,SAAS,8BAA8B,gBAAgB,QAAQ,MAAM,uBAAuB;AAC3F,QAAO;EACN,SAAS;EACT,KAAKC;EACL,cAAc;EACd,MAAM;GACL;GACA;GACA,CAAC,yBAAyB,sBAAsB,CAAC;GACjD;EACD;;;AAGF,SAAS,uCAAuC,WAAW,QAAQ;AAClE,QAAO;EACN,SAAS;EACT,KAAKC;EACL,cAAc;EACd,MAAM;GACL,yBAAyB,OAAO;GAChC,OAAO,gCAAgC;GACvC,OAAO,wBAAwB;GAC/B;EACD;;;AAGF,SAAS,+BAA+B,wBAAwB,QAAQ,QAAQ;AAC/E,QAAO;EACN,SAAS;EACT,KAAKC;EACL,cAAc;EACd,MAAM,CAAC,QAAQ,OAAO,KAAK,UAAU,OAAO,MAAM,CAAC,CAAC;EACpD;;;;;;AAMF,SAAS,0BAA0B,WAAW,OAAO,eAAe;AACnE,QAAO;EACN,SAAS;EACT,KAAKC;EACL,cAAc;EACd,MAAM;GACL,OAAO,MAAM,MAAM;GACnB,OAAO,MAAM,OAAO;GACpB,MAAM,UAAU;GAChB,MAAM;GACN,MAAM;GACN;GACA;EACD;;;AAGF,SAAS,+BAA+B,iBAAiB,QAAQ,WAAW,SAAS;AACpF,QAAO;EACN,SAAS;EACT,KAAKC;EACL,cAAc;EACd,MAAM;GACL;GACA;GACA;GACA;EACD;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AAkCF,SAAS,kBAAkB,OAAO;CACjC,MAAM,EAAE,WAAW,OAAO,QAAQ,SAAS;AAC3C,QAAO;EACN,0DAAsC;GACrC,EAAE,MAAM,WAAW;GACnB,EAAE,MAAM,WAAW;GACnB,EAAE,MAAM,SAAS;GACjB,EAAE;GACF;GACA,OAAO,MAAM;GACb;GACA,CAAC,CAAC;EACH;EACA;EACA;EACA;;;;;;;;;;;AAcF,IAAI,oCAAoC,cAAc,MAAM;CAC3D,YAAY,SAAS;AACpB,QAAM,QAAQ;AACd,OAAK,OAAO;;;;;;;;AAQd,SAAS,iCAAiC,uBAAuB;AAChE,KAAI,0BAA0B,KAAK,KAAK,0BAA0B,GAAI,OAAM,IAAI,kCAAkC,0MAA0M;AAC5T,KAAI,CAACC,8CAAkB,sBAAsB,CAAE,OAAM,IAAI,kCAAkC,mCAAmC,sBAAsB,+BAA+B;;AAKpL,MAAM,eAAe;AACrB,MAAM,eAAe;AACrB,SAAS,cAAc,SAAS;AAC/B,QAAO,QAAQ,aAAa,KAAK;;;;;;;;AAQlC,eAAe,aAAa,QAAQ,iBAAiB,QAAQ,WAAW;CACvE,MAAM,SAASP,qDAAsB,QAAQ,UAAU;AACvD,KAAI;EACH,MAAM,YAAY,MAAM,OAAO,aAAa;GAC3C,SAAS;GACT,KAAKQ;GACL,cAAc;GACd,MAAM,CAAC,OAAO;GACd,CAAC;AACF,MAAI,cAAc,UAAU,CAAE,QAAO,EAAE,OAAO,OAAO;AACrD,SAAO;GACN,OAAO;GACP;GACA;UACO,OAAO;AACf,gCAAO,MAAM,cAAc,2BAA2B,OAAO,IAAI,MAAM;AACvE,QAAM,IAAIC,+CAAwB,gCAAgC,OAAO,IAAI,MAAM,WAAW,gBAAgB,OAAO,gBAAgB;;;;;;;AAOvI,eAAe,WAAW,QAAQ,iBAAiB,QAAQ,WAAW;CACrE,MAAM,SAAST,qDAAsB,QAAQ,UAAU;AACvD,KAAI;AACH,SAAO,MAAM,OAAO,aAAa;GAChC,SAAS;GACT,KAAKU;GACL,cAAc;GACd,MAAM,CAAC,OAAO;GACd,CAAC;SACK;AACP,gCAAO,MAAM,cAAc,yCAAyC,SAAS;AAC7E,SAAO;;;;;;;AAOT,eAAe,gBAAgB,QAAQ,iBAAiB,QAAQ,WAAW;CAC1E,MAAM,SAASV,qDAAsB,QAAQ,UAAU;AACvD,KAAI;AACH,UAAQ,MAAM,OAAO,aAAa;GACjC,SAAS;GACT,KAAKW;GACL,cAAc;GACd,MAAM,CAAC,OAAO;GACd,CAAC,EAAE,UAAU;SACP;AACP,gCAAO,MAAM,cAAc,mCAAmC,SAAS;AACvE;;;;;;;AAOF,eAAe,gBAAgB,QAAQ,wBAAwB,QAAQ,WAAW;CACjF,MAAM,SAASX,qDAAsB,QAAQ,UAAU;AACvD,KAAI;AACH,SAAO,MAAM,OAAO,aAAa;GAChC,SAAS;GACT,KAAKY;GACL,cAAc;GACd,MAAM,CAAC,OAAO;GACd,CAAC;SACK;AACP,gCAAO,MAAM,cAAc,wCAAwC,SAAS;AAC5E,SAAO;;;AAGT,eAAe,uBAAuB,QAAQ,gBAAgB,QAAQ,WAAW;CAChF,MAAM,SAASZ,qDAAsB,QAAQ,UAAU;AACvD,KAAI;EACH,MAAM,WAAW,MAAM,OAAO,aAAa;GAC1C,SAAS;GACT,KAAKa;GACL,cAAc;GACd,MAAM,CAAC,OAAO;GACd,CAAC;AACF,SAAO,cAAc,SAAS,GAAG,EAAE,QAAQ,aAAa,GAAG;GAC1D,QAAQ;GACR,WAAW;GACX;UACO,OAAO;EACf,MAAM,QAAQ,iBAAiB,QAAQ,QAAQ,IAAI,MAAM,OAAO,MAAM,CAAC;AACvE,gCAAO,MAAM,cAAc,qCAAqC,OAAO,IAAI,MAAM;AACjF,SAAO;GACN,QAAQ;GACR;GACA;;;;;;;;;;;AAcH,SAAS,YAAY,SAAS,gBAAgB;CAC7C,MAAM,+BAAqB,eAAe;AAC1C,QAAO,QAAQ,KAAK,QAAQ,sDAAkC,IAAI,QAAQ,EAAE,QAAQ,CAAC;;;;;;AAMtF,SAAS,+BAA+B,SAAS,gBAAgB,QAAQ;AACxE,KAAI,QAAQ,WAAW,UAAW;CAClC,MAAM,8BAAoB,OAAO;CACjC,MAAM,OAAO,YAAY,SAAS,eAAe;CACjD,MAAM,wCAA8B;EACnC,KAAKC;EACL;EACA,WAAW;EACX,CAAC,CAAC,MAAM,mCAAyB,MAAM,KAAK,QAAQ,OAAO,CAAC;AAC7D,KAAI,iBAAiB,KAAK,EAAG,6BAAkB,aAAa,KAAK,SAAS;CAC1E,MAAM,oCAA0B;EAC/B,KAAKA;EACL;EACA,WAAW;EACX,CAAC,CAAC;AACH,QAAO,aAAa,KAAK,IAAI,KAAK,yBAAe,SAAS,KAAK,SAAS;;;AAGzE,MAAM,+BAA+B;;;;;AAKrC,MAAM,oCAAoC;;AAE1C,IAAI,gCAAgC,cAAc,MAAM;CACvD,YAAY,SAAS;AACpB,QAAM,QAAQ;AACd,OAAK,OAAO;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AA8Bd,SAAS,yBAAyB,SAAS;CAC1C,MAAM,gBAAgB,SAAS,iBAAiB;CAChD,MAAM,YAAY,SAAS,aAAa;AACxC,KAAI,CAAC,OAAO,UAAU,cAAc,IAAI,gBAAgB,EAAG,OAAM,IAAI,8BAA8B,qEAAqE,OAAO,cAAc,CAAC,sFAAsF;AACpR,KAAI,CAAC,OAAO,UAAU,UAAU,IAAI,aAAa,EAAG,OAAM,IAAI,8BAA8B,qFAAqF,OAAO,UAAU,CAAC,kKAAkK;AACrW,QAAO;EACN;EACA;EACA;;AAKF,MAAM,aAAa;;;;;;AAMnB,MAAM,yBAAyB;;;;AAI/B,IAAI,gBAAgB,MAAM;CACzB;CACA;CACA;;;;;CAKA;CACA,YAAY,eAAe,oBAAoB,SAAS;AACvD,OAAK,gBAAgB;AACrB,OAAK,qBAAqB;AAC1B,OAAK,YAAY,QAAQ;AACzB,OAAK,gBAAgB,QAAQ;AAC7B,OAAK,wBAAwB,QAAQ;AACrC,OAAK,oBAAoB,yBAAyB,QAAQ,kBAAkB;;CAE7E,aAAa,QAAQ;AACpB,SAAO,aAAa,KAAK,QAAQ,EAAE,KAAK,UAAU,kBAAkB,OAAO;;;;;;CAM5E,mBAAmB,QAAQ;AAC1B,SAAO,uBAAuB,KAAK,QAAQ,EAAE,KAAK,UAAU,iBAAiB,OAAO;;;;;;;;CAQrF,sBAAsB,OAAO;EAC5B,MAAM,EAAE,WAAW,SAAS,YAAY;AACxC,SAAO,yBAAyB,KAAK,QAAQ,EAAE,WAAW,SAAS,QAAQ;;CAE5E,WAAW,QAAQ;AAClB,SAAO,WAAW,KAAK,QAAQ,EAAE,KAAK,UAAU,kBAAkB,OAAO;;CAE1E,gBAAgB,QAAQ;AACvB,SAAO,gBAAgB,KAAK,QAAQ,EAAE,KAAK,UAAU,kBAAkB,OAAO;;CAE/E,kBAAkB,OAAO;AACxB,SAAO,kBAAkB,MAAM;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;CAkChC,MAAM,gBAAgB,OAAO,iBAAiB,gBAAgB,eAAe;EAC5E,MAAM,EAAE,WAAW;EACnB,MAAM,UAAU,MAAM,KAAK,mBAAmB,OAAO;AACrD,MAAI,QAAQ,WAAW,SAAS;AAC/B,iCAAO,KAAK,YAAY,sDAAsD;IAC7E;IACA,WAAW,QAAQ;IACnB,CAAC;AACF,SAAM,IAAIC,iDAA0B,UAAU,OAAO,yCAAyC,QAAQ,UAAU,IAAI,QAAQ,QAAQ,WAAW,KAAK,UAAU,gBAAgB;;AAE/K,MAAI,QAAQ,WAAW,eAAe;AACrC,iCAAO,KAAK,YAAY,mDAAmD;IAC1E;IACA,OAAO,QAAQ;IACf,CAAC;AACF,SAAM,IAAIN,+CAAwB,uBAAuB,OAAO,6HAA6H,mBAAmB,QAAQ,OAAO,KAAK,UAAU,gBAAgB;;EAE/P,MAAM,SAAS,8BAA8B,KAAK,UAAU,iBAAiB,QAAQ,QAAQ,KAAK,sBAAsB;EACxH,MAAM,SAAS,MAAM,KAAK,QAAQ,mBAAmB,QAAQ,iBAAiB,gBAAgB,cAAc;AAC5G,MAAI,OAAO,eAAe,aAAa;AACtC,iCAAO,KAAK,YAAY,6CAA6C;IACpE,WAAW;IACX,YAAY;IACZ,IAAI,OAAO;IACX;IACA,CAAC;AACF,UAAO;IACN,IAAI,OAAO;IACX,YAAY;IACZ;;EAEF,MAAM,SAAS,KAAK,QAAQ;EAC5B,MAAM,EAAE,eAAe,cAAc,KAAK;AAC1C,gCAAO,KAAK,YAAY,6DAA6D;GACpF,QAAQ,OAAO;GACf,aAAa,YAAY,OAAO;GAChC,SAAS,KAAK,UAAU;GACxB;GACA;GACA;GACA,CAAC;EACF,MAAM,SAAST,qDAAsB,OAAO;EAC5C,IAAI;AACJ,MAAI;AACH,aAAU,MAAM,OAAO,0BAA0B;IAChD,MAAM,OAAO;IACb;IACA,SAAS;IACT,CAAC;WACM,OAAO;GACf,MAAM,QAAQ,iBAAiB,QAAQ,QAAQ,IAAI,MAAM,OAAO,MAAM,CAAC;AACvE,iCAAO,MAAM,YAAY,qDAAqD;IAC7E,QAAQ,OAAO;IACf;IACA;IACA;IACA,CAAC;AACF,SAAM,IAAIS,+CAAwB,4BAA4B,OAAO,qBAAqB,OAAO,GAAG,6CAA6C,UAAU,MAAM,cAAc,8BAA8B,MAAM,QAAQ,yKAAyK,OAAO,gJAAgJ,mBAAmB,OAAO,KAAK,UAAU,gBAAgB;;AAErlB,MAAI,QAAQ,WAAW,WAAW;AACjC,iCAAO,MAAM,YAAY,yCAAyC;IACjE,QAAQ,OAAO;IACf,eAAe,QAAQ;IACvB,CAAC;AACF,SAAM,IAAIA,+CAAwB,4BAA4B,OAAO,yBAAyB,OAAO,GAAG,oBAAoB,QAAQ,OAAO,8GAA8G,mBAAmB,KAAK,GAAG,KAAK,UAAU,gBAAgB;;EAEpT,MAAM,YAAY,+BAA+B,SAAS,KAAK,UAAU,iBAAiB,OAAO;AACjG,gCAAO,KAAK,YAAY,gDAAgD;GACvE,QAAQ,OAAO;GACf,eAAe,QAAQ;GACvB,mBAAmB,aAAa;GAChC,CAAC;AACF,MAAI,CAAC,UAAW,OAAM,IAAIA,+CAAwB,4BAA4B,OAAO,0BAA0B,OAAO,GAAG,sPAAsP,mBAAmB,KAAK,GAAG,KAAK,UAAU,gBAAgB;AACza,QAAM,KAAK,4BAA4B;GACtC,WAAW;GACX;GACA,SAAS,KAAK;GACd,SAAS;GACT,uBAAuB,4BAA4B,OAAO,uBAAuB,UAAU,8BAA8B,KAAK,sBAAsB;GACpJ,mBAAmB,4BAA4B,OAAO,uBAAuB,UAAU,OAAO,OAAO,GAAG,+CAA+C,KAAK,sBAAsB,oFAAoF,UAAU;GAChR,CAAC;AACF,SAAO;GACN,IAAI,OAAO;GACX;GACA,YAAY;GACZ;;;;;;;;;;;;;;;;;;;;;;;;;CAyBF,MAAM,yBAAyB,OAAO,iBAAiB,gBAAgB,eAAe;EACrF,MAAM,EAAE,WAAW,WAAW;EAC9B,MAAM,QAAQ,MAAM,yBAAyB,KAAK,QAAQ,EAAE,WAAW,QAAQ,gCAAgC;AAC/G,MAAI,MAAM,WAAW,OAAO;AAC3B,iCAAO,KAAK,YAAY,0DAA0D;IACjF;IACA;IACA,CAAC;AACF,SAAM,IAAIM,iDAA0B,UAAU,OAAO,wCAAwC,UAAU,IAAI,QAAQ,WAAW,UAAU;;AAEzI,MAAI,MAAM,WAAW,eAAe;AACnC,iCAAO,KAAK,YAAY,gEAAgE;IACvF;IACA;IACA,OAAO,MAAM;IACb,CAAC;AACF,SAAM,IAAIN,+CAAwB,gCAAgC,OAAO,MAAM,UAAU,kKAAkK,4BAA4B,MAAM,OAAO,UAAU;;EAE/S,MAAM,SAAS,uCAAuC,WAAW,OAAO;EACxE,MAAM,SAAS,MAAM,KAAK,QAAQ,4BAA4B,QAAQ,iBAAiB,gBAAgB,cAAc;AACrH,MAAI,OAAO,eAAe,YAAa,QAAO,EAAE,IAAI,OAAO,IAAI;AAC/D,QAAM,KAAK,4BAA4B;GACtC,WAAW;GACX;GACA,SAAS;GACT,SAAS;GACT,uBAAuB,gCAAgC,OAAO,MAAM,UAAU,qBAAqB,OAAO,GAAG;GAC7G,mBAAmB,gCAAgC,OAAO,MAAM,UAAU,qBAAqB,OAAO,GAAG,oFAAoF,UAAU;GACvM,CAAC;AACF,SAAO,EAAE,IAAI,OAAO,IAAI;;CAEzB,MAAM,sBAAsB,OAAO,iBAAiB,gBAAgB,eAAe;EAClF,MAAM,EAAE,QAAQ,WAAW;AAC3B,MAAI,MAAM,gBAAgB,KAAK,QAAQ,EAAE,KAAK,UAAU,wBAAwB,OAAO,EAAE;AACxF,iCAAO,MAAM,YAAY,kBAAkB,OAAO,2CAA2C;AAC7F,UAAO,EAAE,IAAI,wBAAwB;;EAEtC,MAAM,SAAS,+BAA+B,KAAK,UAAU,wBAAwB,QAAQ,OAAO;AACpG,SAAO,EAAE,KAAK,MAAM,KAAK,QAAQ,yBAAyB,QAAQ,iBAAiB,gBAAgB,cAAc,EAAE,IAAI;;CAExH,MAAM,YAAY,OAAO,iBAAiB,gBAAgB,eAAe;EACxE,MAAM,EAAE,WAAW,UAAU;EAC7B,MAAM,gBAAgB,MAAM,UAAU,KAAK;AAC3C,MAAI,CAAC,cAAe,OAAM,IAAIA,+CAAwB,8FAA8F,eAAe,KAAK,GAAG,UAAU;EACrL,MAAM,SAAS,0BAA0B,WAAW,OAAO,cAAc;AACzE,SAAO,EAAE,KAAK,MAAM,KAAK,QAAQ,eAAe,QAAQ,iBAAiB,gBAAgB,cAAc,EAAE,IAAI;;CAE9G,MAAM,iBAAiB,OAAO,iBAAiB,gBAAgB,eAAe;EAC7E,MAAM,EAAE,QAAQ,WAAW,UAAU,MAAM;EAC3C,MAAM,WAAW,MAAM,KAAK,aAAa,OAAO;AAChD,MAAI,SAAS,MAAO,OAAM,IAAIM,iDAA0B,UAAU,OAAO,sCAAsC,QAAQ,SAAS,WAAW,KAAK,UAAU,iBAAiB;EAC3K,MAAM,SAAS,+BAA+B,KAAK,UAAU,kBAAkB,QAAQ,WAAW,QAAQ;AAC1G,SAAO,EAAE,KAAK,MAAM,KAAK,QAAQ,oBAAoB,QAAQ,iBAAiB,gBAAgB,cAAc,EAAE,IAAI;;CAEnH,UAAU;AACT,gCAAO,MAAM,YAAY,wBAAwB;;CAElD,SAAS;AACR,SAAOC,mCAAc,KAAK,cAAc;;CAEzC,MAAM,4BAA4B,OAAO;EACxC,MAAM,EAAE,WAAW,WAAW,SAAS,SAAS,uBAAuB,sBAAsB;EAC7F,MAAM,SAAS,MAAM,yBAAyB,KAAK,QAAQ,EAAE,WAAW,SAAS,QAAQ;AACzF,MAAI,OAAO,WAAW,cAAe,OAAM,IAAIP,+CAAwB,mBAAmB,WAAW,OAAO,OAAO,UAAU;AAC7H,MAAI,OAAO,WAAW,QAAS,OAAM,IAAIA,+CAAwB,uBAAuB,WAAW,KAAK,GAAG,UAAU;;;;;;;CAOtH,QAAQ,WAAW,QAAQ,iBAAiB,gBAAgB,eAAe;AAC1E,SAAOQ,6CAAmB;GACzB;GACA;GACA,UAAU,KAAK;GACf;GACA;GACA;GACA,GAAG,OAAO,IAAI,oBAAoB,IAAIR,+CAAwB,OAAO,GAAG,WAAW,MAAM,WAAW,IAAI,OAAO,gBAAgB,CAAC;;;;;;AAMnI,SAAS,oBAAoB,eAAe,oBAAoB,SAAS;AACxE,QAAO,IAAI,cAAc,eAAe,oBAAoB,QAAQ;;AAErE,SAAS,YAAY,QAAQ;AAC5B,KAAI;AACH,SAAO,IAAI,IAAI,OAAO,CAAC;SAChB;AACP,SAAO;;;;;;;;;;AAaT,SAAS,UAAU,QAAQ,SAAS;CACnC,MAAM,gBAAgBS,iDAAwB,OAAO;AACrD,6CAAmB,8BAA8B,QAAQ,UAAU,iBAAiB;AACpF,6CAAmB,6BAA6B,QAAQ,UAAU,gBAAgB;AAClF,6CAAmB,oCAAoC,QAAQ,UAAU,uBAAuB;AAChG,KAAI,QAAQ,kBAAkB,KAAK,EAAG,6CAAmB,iBAAiB,QAAQ,cAAc;AAChG,kCAAiC,QAAQ,sBAAsB;CAC/D,MAAM,UAAU,oBAAoB,eAAeC,+CAAsB,QAAQ,iBAAiB,EAAE;EACnG,WAAW,QAAQ;EACnB,eAAe,QAAQ;EACvB,uBAAuB,QAAQ;EAC/B,mBAAmB,QAAQ;EAC3B,CAAC;AACF,QAAOC,gDAAuB,SAAS,eAAe,aAAa,QAAQ,SAAS,EAAE,UAAU"}