{"version":3,"sources":["../src/types.ts","../src/tab-session.ts","../src/provider.tsx","../src/components.tsx","../src/sudo.tsx","../src/linked-identities.tsx","../src/signin.tsx","../src/webauthn.tsx"],"names":["React","React2","jsx","OcAddressInput","jsxs","React4","Fragment","inputStyle","ErrorLine","React5"],"mappings":";;;;;;;AAMO,IAAM,sBAAA,GAAyB,CAAC,KAAA,EAAO,KAAA,EAAO,SAAS,OAAO;AA8N9D,IAAM,cAAA,GAAyC;AAAA,EAClD,UAAA,EAAY,iBAAA;AAAA,EACZ,UAAA,EAAY,SAAA;AAAA,EACZ,MAAA,EAAQ,cAAA;AAAA,EACR,UAAA,EAAY;AAChB;AAEO,SAAS,cAAc,GAAA,EAAuD;AACjF,EAAA,OAAO,EAAE,GAAG,cAAA,EAAgB,GAAI,GAAA,IAAO,EAAC,EAAG;AAC/C;AAEO,SAAS,cAAA,CAAe,KAA6B,QAAA,EAA2B;AACnF,EAAA,MAAM,OAAO,CAAA,EAAG,GAAA,CAAI,UAAU,CAAA,EAAG,IAAI,UAAU,CAAA,CAAA;AAC/C,EAAA,IAAI,CAAC,UAAU,OAAO,IAAA;AACtB,EAAA,MAAM,CAAA,GAAI,IAAI,GAAA,CAAI,IAAI,CAAA;AACtB,EAAA,CAAA,CAAE,YAAA,CAAa,GAAA,CAAI,WAAA,EAAa,QAAQ,CAAA;AACxC,EAAA,OAAO,EAAE,QAAA,EAAS;AACtB;AASO,SAAS,kBAAA,CAAmB,KAA6B,QAAA,EAA2B;AACvF,EAAA,MAAM,IAAI,IAAI,GAAA,CAAI,cAAA,CAAe,GAAA,EAAK,QAAQ,CAAC,CAAA;AAC/C,EAAA,CAAA,CAAE,YAAA,CAAa,GAAA,CAAI,KAAA,EAAO,GAAG,CAAA;AAC7B,EAAA,OAAO,EAAE,QAAA,EAAS;AACtB;;;AC5OO,IAAM,kBAAA,GAAqB;AAE3B,IAAM,uBAAA,GAA0B;AAchC,IAAM,oBAAA,GAAuB;AAQ7B,IAAM,cAAA,GAAiB;AAOvB,SAAS,cAAA,GAAsC;AAClD,EAAA,IAAI,OAAO,MAAA,KAAW,WAAA,EAAa,OAAO,IAAA;AAC1C,EAAA,IAAI;AACA,IAAA,MAAM,GAAA,GAAM,MAAA,CAAO,cAAA,CAAe,OAAA,CAAQ,uBAAuB,CAAA;AACjE,IAAA,IAAI,CAAC,KAAK,OAAO,IAAA;AACjB,IAAA,MAAM,MAAA,GAAS,IAAA,CAAK,KAAA,CAAM,GAAG,CAAA;AAC7B,IAAA,IAAI,OAAO,OAAO,KAAA,KAAU,QAAA,IAAY,OAAO,KAAA,CAAM,MAAA,KAAW,GAAG,OAAO,IAAA;AAC1E,IAAA,IAAI,OAAO,OAAO,KAAA,KAAU,QAAA,IAAY,OAAO,KAAA,CAAM,MAAA,KAAW,GAAG,OAAO,IAAA;AAC1E,IAAA,OAAO,EAAE,KAAA,EAAO,MAAA,CAAO,KAAA,EAAO,KAAA,EAAO,OAAO,KAAA,EAAM;AAAA,EACtD,CAAA,CAAA,MAAQ;AAEJ,IAAA,OAAO,IAAA;AAAA,EACX;AACJ;AAEO,SAAS,gBAAgB,OAAA,EAA6B;AACzD,EAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,EAAA,IAAI;AACA,IAAA,MAAA,CAAO,eAAe,OAAA,CAAQ,uBAAA,EAAyB,IAAA,CAAK,SAAA,CAAU,OAAO,CAAC,CAAA;AAAA,EAClF,CAAA,CAAA,MAAQ;AAAA,EAER;AACJ;AAEO,SAAS,eAAA,GAAwB;AACpC,EAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,EAAA,IAAI;AACA,IAAA,MAAA,CAAO,cAAA,CAAe,WAAW,uBAAuB,CAAA;AAAA,EAC5D,CAAA,CAAA,MAAQ;AAAA,EAER;AACJ;AAGO,SAAS,gBAAA,GAA2C;AACvD,EAAA,MAAM,MAAM,cAAA,EAAe;AAC3B,EAAA,OAAO,GAAA,GAAM,EAAE,CAAC,kBAAkB,GAAG,GAAA,CAAI,KAAA,KAAU,EAAC;AACxD;AAOA,SAAS,aAAA,CAAc,KAAa,UAAA,EAA6B;AAC7D,EAAA,IAAI,OAAO,MAAA,KAAW,WAAA,EAAa,OAAO,KAAA;AAC1C,EAAA,IAAI;AACA,IAAA,MAAM,IAAI,IAAI,GAAA,CAAI,GAAA,EAAK,MAAA,CAAO,SAAS,IAAI,CAAA;AAC3C,IAAA,OAAO,EAAE,MAAA,KAAW,MAAA,CAAO,QAAA,CAAS,MAAA,IAAU,EAAE,MAAA,KAAW,UAAA;AAAA,EAC/D,CAAA,CAAA,MAAQ;AACJ,IAAA,OAAO,KAAA;AAAA,EACX;AACJ;AAgBO,SAAS,2BAA2B,UAAA,EAAgC;AACvE,EAAA,IAAI,OAAO,MAAA,KAAW,WAAA,EAAa,OAAO,MAAM;AAAA,EAAC,CAAA;AACjD,EAAA,MAAM,WAAW,MAAA,CAAO,KAAA;AACxB,EAAA,MAAM,OAAA,GAA+B,CAAC,KAAA,EAAO,IAAA,KAAS;AAClD,IAAA,IAAI;AACA,MAAA,MAAM,MAAM,cAAA,EAAe;AAC3B,MAAA,IAAI,GAAA,EAAK;AACL,QAAA,MAAM,GAAA,GACF,OAAO,KAAA,KAAU,QAAA,GACX,QACA,KAAA,YAAiB,GAAA,GACf,KAAA,CAAM,IAAA,GACN,KAAA,CAAM,GAAA;AAClB,QAAA,IAAI,aAAA,CAAc,GAAA,EAAK,UAAU,CAAA,EAAG;AAChC,UAAA,MAAM,UAAU,IAAI,OAAA;AAAA,YAChB,IAAA,EAAM,OAAA,KAAY,KAAA,YAAiB,OAAA,GAAU,MAAM,OAAA,GAAU,KAAA,CAAA;AAAA,WACjE;AACA,UAAA,IAAI,CAAC,QAAQ,GAAA,CAAI,eAAe,KAAK,CAAC,OAAA,CAAQ,GAAA,CAAI,kBAAkB,CAAA,EAAG;AACnE,YAAA,OAAA,CAAQ,GAAA,CAAI,kBAAA,EAAoB,GAAA,CAAI,KAAK,CAAA;AACzC,YAAA,IAAA,GAAO,EAAE,GAAG,IAAA,EAAM,OAAA,EAAQ;AAAA,UAC9B;AAAA,QACJ;AAAA,MACJ;AAAA,IACJ,CAAA,CAAA,MAAQ;AAAA,IAER;AACA,IAAA,OAAO,QAAA,CAAS,IAAA,CAAK,MAAA,EAAQ,KAAA,EAA4B,IAAI,CAAA;AAAA,EACjE,CAAA;AACA,EAAA,MAAA,CAAO,KAAA,GAAQ,OAAA;AACf,EAAA,OAAO,MAAM;AAET,IAAA,IAAI,MAAA,CAAO,KAAA,KAAU,OAAA,EAAS,MAAA,CAAO,KAAA,GAAQ,QAAA;AAAA,EACjD,CAAA;AACJ;AAOO,SAAS,qBAAA,GAAiC;AAC7C,EAAA,IAAI,OAAO,MAAA,KAAW,WAAA,EAAa,OAAO,KAAA;AAC1C,EAAA,IAAI,CAAC,MAAA,CAAO,QAAA,CAAS,IAAA,CAAK,QAAA,CAAS,eAAe,KAAA,CAAM,CAAC,CAAC,CAAA,EAAG,OAAO,KAAA;AACpE,EAAA,eAAA,EAAgB;AAChB,EAAA,IAAI;AACA,IAAA,MAAM,GAAA,GAAM,IAAI,GAAA,CAAI,MAAA,CAAO,SAAS,IAAI,CAAA;AACxC,IAAA,GAAA,CAAI,IAAA,GAAO,EAAA;AACX,IAAA,MAAA,CAAO,OAAA,CAAQ,aAAa,MAAA,CAAO,OAAA,CAAQ,OAAO,EAAA,EAAI,GAAA,CAAI,UAAU,CAAA;AAAA,EACxE,CAAA,CAAA,MAAQ;AAAA,EAGR;AACA,EAAA,OAAO,IAAA;AACX;AAcA,IAAM,aAAA,GAAgB,+BAAA;AAGtB,SAAS,WAAW,UAAA,EAAmC;AACnD,EAAA,IAAI;AACA,IAAA,OAAO,IAAI,GAAA,CAAI,UAAU,CAAA,CAAE,SAAS,WAAA,EAAY;AAAA,EACpD,CAAA,CAAA,MAAQ;AACJ,IAAA,OAAO,IAAA;AAAA,EACX;AACJ;AAQA,SAAS,WAAA,CAAY,GAAQ,UAAA,EAA6B;AACtD,EAAA,IAAI,EAAE,QAAA,KAAa,OAAA,IAAW,CAAA,CAAE,QAAA,KAAa,UAAU,OAAO,KAAA;AAC9D,EAAA,IAAI,OAAO,WAAW,WAAA,IAAe,CAAA,CAAE,WAAW,MAAA,CAAO,QAAA,CAAS,QAAQ,OAAO,IAAA;AACjF,EAAA,MAAM,IAAA,GAAO,WAAW,UAAU,CAAA;AAClC,EAAA,IAAI,CAAC,MAAM,OAAO,KAAA;AAClB,EAAA,MAAM,IAAA,GAAO,CAAA,CAAE,QAAA,CAAS,WAAA,EAAY;AACpC,EAAA,OAAO,SAAS,IAAA,IAAQ,IAAA,CAAK,QAAA,CAAS,CAAA,CAAA,EAAI,IAAI,CAAA,CAAE,CAAA;AACpD;AAGA,SAAS,kBAAA,CAAmB,CAAA,EAAe,MAAA,EAA2B,IAAA,EAAoB;AAEtF,EAAA,IAAI,OAAO,WAAW,WAAA,IAAe,IAAA,CAAK,WAAW,MAAA,CAAO,QAAA,CAAS,QAAQ,OAAO,IAAA;AAIpF,EAAA,MAAM,UAAU,MAAA,CAAO,YAAA,CAAa,QAAQ,CAAA,IAAK,IAAI,WAAA,EAAY;AACjE,EAAA,OACI,EAAE,MAAA,KAAW,CAAA;AAAA,EACb,EAAE,OAAA,IACF,CAAA,CAAE,OAAA,IACF,CAAA,CAAE,YACF,MAAA,KAAW,QAAA;AAEnB;AAsBO,SAAS,wBAAwB,UAAA,EAAgC;AACpE,EAAA,IAAI,OAAO,MAAA,KAAW,WAAA,IAAe,OAAO,QAAA,KAAa,WAAA,SAAoB,MAAM;AAAA,EAAC,CAAA;AACpF,EAAA,MAAM,UAAA,GAAa,CAAC,CAAA,KAAkB;AAClC,IAAA,IAAI;AACA,MAAA,MAAM,MAAM,cAAA,EAAe;AAC3B,MAAA,IAAI,CAAC,GAAA,EAAK;AACV,MAAA,MAAM,SAAS,CAAA,CAAE,MAAA;AACjB,MAAA,IAAI,EAAE,kBAAkB,OAAA,CAAA,EAAU;AAClC,MAAA,MAAM,MAAA,GAAS,MAAA,CAAO,OAAA,CAAQ,SAAS,CAAA;AACvC,MAAA,IAAI,CAAC,MAAA,IAAU,MAAA,CAAO,YAAA,CAAa,UAAU,CAAA,EAAG;AAChD,MAAA,MAAM,GAAA,GAAM,MAAA,CAAO,YAAA,CAAa,MAAM,CAAA;AACtC,MAAA,IAAI,CAAC,GAAA,IAAO,GAAA,CAAI,SAAS,CAAA,EAAG,oBAAoB,GAAG,CAAA,EAAG;AACtD,MAAA,IAAI,IAAA;AACJ,MAAA,IAAI;AACA,QAAA,IAAA,GAAO,IAAI,GAAA,CAAI,MAAA,CAAO,IAAI,CAAA;AAAA,MAC9B,CAAA,CAAA,MAAQ;AACJ,QAAA;AAAA,MACJ;AACA,MAAA,IAAI,KAAK,IAAA,EAAM;AACf,MAAA,IAAI,CAAC,WAAA,CAAY,IAAA,EAAM,UAAU,CAAA,EAAG;AACpC,MAAA,IAAI,CAAC,kBAAA,CAAmB,CAAA,EAAG,MAAA,EAAQ,IAAI,CAAA,EAAG;AAC1C,MAAA,MAAA,CAAO,YAAA,CAAa,QAAQ,CAAA,EAAG,GAAG,IAAI,oBAAoB,CAAA,CAAA,EAAI,GAAA,CAAI,KAAK,CAAA,CAAE,CAAA;AAAA,IAC7E,CAAA,CAAA,MAAQ;AAAA,IAER;AAAA,EACJ,CAAA;AACA,EAAA,MAAA,CAAO,gBAAA,CAAiB,OAAA,EAAS,UAAA,EAAY,IAAI,CAAA;AACjD,EAAA,MAAA,CAAO,gBAAA,CAAiB,UAAA,EAAY,UAAA,EAAY,IAAI,CAAA;AACpD,EAAA,OAAO,MAAM;AACT,IAAA,MAAA,CAAO,mBAAA,CAAoB,OAAA,EAAS,UAAA,EAAY,IAAI,CAAA;AACpD,IAAA,MAAA,CAAO,mBAAA,CAAoB,UAAA,EAAY,UAAA,EAAY,IAAI,CAAA;AAAA,EAC3D,CAAA;AACJ;AAgBA,eAAsB,sBAAsB,UAAA,EAA4C;AACpF,EAAA,IAAI,OAAO,MAAA,KAAW,WAAA,EAAa,OAAO,IAAA;AAC1C,EAAA,MAAM,OAAO,MAAA,CAAO,QAAA,CAAS,IAAA,CAAK,OAAA,CAAQ,MAAM,EAAE,CAAA;AAClD,EAAA,MAAM,CAAA,GAAI,aAAA,CAAc,IAAA,CAAK,IAAI,CAAA;AACjC,EAAA,IAAI,CAAC,GAAG,OAAO,IAAA;AACf,EAAA,MAAM,GAAA,GAAM,EAAE,CAAC,CAAA;AAEf,EAAA,IAAI;AACA,IAAA,MAAM,GAAA,GAAM,IAAI,GAAA,CAAI,MAAA,CAAO,SAAS,IAAI,CAAA;AACxC,IAAA,GAAA,CAAI,IAAA,GAAO,EAAA;AACX,IAAA,MAAA,CAAO,OAAA,CAAQ,aAAa,MAAA,CAAO,OAAA,CAAQ,OAAO,EAAA,EAAI,GAAA,CAAI,UAAU,CAAA;AAAA,EACxE,CAAA,CAAA,MAAQ;AAAA,EAER;AAGA,EAAA,MAAM,WAAW,cAAA,EAAe;AAChC,EAAA,IAAI,QAAA,IAAY,QAAA,CAAS,KAAA,KAAU,GAAA,EAAK,OAAO,GAAA;AAC/C,EAAA,IAAI;AACA,IAAA,MAAM,GAAA,GAAM,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,aAAA,CAAA,EAAiB;AAAA,MAClD,MAAA,EAAQ,MAAA;AAAA,MACR,WAAA,EAAa,SAAA;AAAA,MACb,OAAA,EAAS,EAAE,MAAA,EAAQ,kBAAA,EAAoB,gBAAgB,kBAAA,EAAmB;AAAA,MAC1E,MAAM,IAAA,CAAK,SAAA,CAAU,EAAE,MAAA,EAAQ,KAAK;AAAA,KACvC,CAAA;AACD,IAAA,IAAI,CAAC,GAAA,CAAI,EAAA,EAAI,OAAO,IAAA;AACpB,IAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAQ7B,IAAA,IAAI,IAAA,CAAK,MAAM,OAAO,IAAA,CAAK,UAAU,QAAA,IAAY,IAAA,CAAK,OAAA,EAAS,MAAA,KAAW,GAAA,EAAK;AAC3E,MAAA,eAAA,CAAgB,EAAE,KAAA,EAAO,IAAA,CAAK,KAAA,EAAO,KAAA,EAAO,KAAK,CAAA;AACjD,MAAA,OAAO,GAAA;AAAA,IACX;AAAA,EACJ,CAAA,CAAA,MAAQ;AAAA,EAER;AACA,EAAA,OAAO,IAAA;AACX;AC1TA,IAAM,cAAA,GAAuBA,qBAAqC,IAAI,CAAA;AAqDtE,SAAS,wBAAA,CACL,KACA,KAAA,EACe;AACf,EAAA,MAAM,EAAA,GAAK,GAAA,CAAI,gBAAA,IAAoB,GAAA,CAAI,eAAA;AACvC,EAAA,IACI,EAAA,IACA,OAAO,EAAA,KAAO,QAAA,IACd,OAAO,EAAA,CAAG,KAAA,KAAU,YACpB,EAAA,CAAG,KAAA,CAAM,SAAS,CAAA,IAClB,OAAO,GAAG,IAAA,KAAS,QAAA,IAClB,uBAA6C,QAAA,CAAS,EAAA,CAAG,IAAI,CAAA,EAChE;AACE,IAAA,OAAO,EAAE,IAAA,EAAM,EAAA,CAAG,IAAA,EAA6B,KAAA,EAAO,GAAG,KAAA,EAAM;AAAA,EACnE;AACA,EAAA,OAAO,EAAE,IAAA,EAAM,KAAA,EAAO,KAAA,EAAO,KAAA,EAAM;AACvC;AAMA,SAAS,qBAAqB,GAAA,EAA8C;AACxE,EAAA,MAAM,KAAA,GAAQ,GAAA,CAAI,MAAA,IAAU,GAAA,CAAI,KAAA;AAChC,EAAA,IAAI,CAAC,OAAO,OAAO,IAAA;AACnB,EAAA,MAAM,EAAA,GAAK,GAAA,CAAI,gBAAA,IAAoB,GAAA,CAAI,eAAA;AACvC,EAAA,MAAM,eAAA,GACF,EAAA,IACA,OAAO,EAAA,KAAO,YACd,OAAO,EAAA,CAAG,KAAA,KAAU,QAAA,IACpB,GAAG,KAAA,CAAM,MAAA,GAAS,CAAA,IAClB,OAAO,GAAG,IAAA,KAAS,QAAA,IAClB,sBAAA,CAA6C,QAAA,CAAS,EAAA,CAAG,IAAI,CAAA,GACxD,EAAE,MAAM,EAAA,CAAG,IAAA,EAA6B,KAAA,EAAO,EAAA,CAAG,OAAM,GACxD,EAAE,IAAA,EAAM,KAAA,EAAO,OAAO,KAAA,EAAM;AACtC,EAAA,OAAO;AAAA,IACH,KAAA;AAAA,IACA,WAAA,EAAa,GAAA,CAAI,YAAA,IAAgB,GAAA,CAAI,WAAA,IAAe,IAAA;AAAA,IACpD,UAAA,EAAY,GAAA,CAAI,WAAA,IAAe,GAAA,CAAI,UAAA,IAAc,IAAA;AAAA,IACjD,eAAA;AAAA,IACA,UAAA,EAAY,GAAA,CAAI,YAAA,IAAgB,GAAA,CAAI,UAAA,IAAc;AAAA,GACtD;AACJ;AAeA,eAAe,gBAAgB,GAAA,EAA0D;AACrF,EAAA,IAAI;AAGA,IAAA,MAAM,GAAA,GAAM,MAAM,KAAA,CAAM,CAAA,EAAG,IAAI,UAAU,CAAA,EAAG,GAAA,CAAI,MAAM,CAAA,CAAA,EAAI;AAAA,MACtD,MAAA,EAAQ,KAAA;AAAA,MACR,WAAA,EAAa,SAAA;AAAA,MACb,SAAS,EAAE,MAAA,EAAQ,kBAAA,EAAoB,GAAG,kBAAiB;AAAE,KAChE,CAAA;AACD,IAAA,IAAI,CAAC,GAAA,CAAI,EAAA,EAAI,OAAO,EAAC;AACrB,IAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAC7B,IAAA,OAAO,MAAM,OAAA,CAAQ,IAAA,CAAK,MAAM,CAAA,GAC1B,KAAK,MAAA,CACA,GAAA,CAAI,oBAAoB,CAAA,CACxB,OAAO,CAAC,CAAA,KAA6B,CAAA,KAAM,IAAI,IACpD,EAAC;AAAA,EACX,CAAA,CAAA,MAAQ;AACJ,IAAA,OAAO,EAAC;AAAA,EACZ;AACJ;AAEA,SAAS,iBAAiB,GAAA,EAA8C;AACpE,EAAA,IAAI,CAAC,KAAK,OAAO,IAAA;AACjB,EAAA,MAAM,KAAA,GAAQ,GAAA,CAAI,MAAA,IAAU,GAAA,CAAI,KAAA;AAChC,EAAA,MAAM,SAAA,GAAY,GAAA,CAAI,EAAA,IAAM,GAAA,CAAI,cAAc,GAAA,CAAI,SAAA;AAClD,EAAA,IAAI,CAAC,KAAA,IAAS,CAAC,SAAA,EAAW,OAAO,IAAA;AACjC,EAAA,OAAO;AAAA,IACH,SAAA;AAAA,IACA,KAAA;AAAA,IACA,UAAA,EAAY,GAAA,CAAI,WAAA,IAAe,GAAA,CAAI,UAAA,IAAc,IAAA;AAAA,IACjD,QAAA,EAAU,GAAA,CAAI,SAAA,IAAa,GAAA,CAAI,QAAA,IAAY,KAAA;AAAA,IAC3C,WAAA,EAAa,GAAA,CAAI,YAAA,IAAgB,GAAA,CAAI,WAAA,IAAe,IAAA;AAAA,IACpD,SAAA,EAAW,GAAA,CAAI,UAAA,IAAc,GAAA,CAAI,SAAA,IAAa,IAAA;AAAA,IAC9C,cAAA,EAAgB,GAAA,CAAI,oBAAA,IAAwB,GAAA,CAAI,cAAA,IAAkB,IAAA;AAAA,IAClE,aAAA,EAAe,GAAA,CAAI,cAAA,IAAkB,GAAA,CAAI,aAAA,IAAiB,IAAA;AAAA,IAC1D,SAAS,OAAA,CAAQ,GAAA,CAAI,QAAA,IAAY,GAAA,CAAI,WAAW,KAAK,CAAA;AAAA,IACrD,eAAA,EAAiB,wBAAA,CAAyB,GAAA,EAAK,KAAK;AAAA,GACxD;AACJ;AAgBO,SAAS,iBAAA,CAAkB;AAAA,EAC9B,QAAA;AAAA,EACA,MAAA;AAAA,EACA;AACJ,CAAA,EAA+C;AAC3C,EAAA,MAAM,GAAA,GAAYA,eAAQ,MAAM,aAAA,CAAc,MAAM,CAAA,EAAG,CAAC,MAAM,CAAC,CAAA;AAC/D,EAAA,MAAM,CAAC,OAAA,EAAS,UAAU,CAAA,GAAUA,gBAA2B,IAAI,CAAA;AACnE,EAAA,MAAM,CAAC,MAAA,EAAQ,SAAS,CAAA,GAAUA,MAAA,CAAA,QAAA,CAA6B,EAAE,CAAA;AACjE,EAAA,MAAM,CAAC,MAAA,EAAQ,SAAS,CAAA,GAAUA,gBAAmC,SAAS,CAAA;AAC9E,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAAuB,IAAI,CAAA;AAC3D,EAAA,MAAM,CAAC,SAAA,EAAW,YAAY,CAAA,GAAUA,gBAAS,KAAK,CAAA;AAQtD,EAAA,MAAM,cAAA,GAAuBA,cAAO,KAAK,CAAA;AACzC,EAAA,MAAM,UAAA,GAAmBA,MAAA,CAAA,WAAA;AAAA,IACrB,OAAO,KAAA,KAAkB;AACrB,MAAA,IAAI,cAAA,CAAe,OAAA,IAAW,cAAA,EAAe,EAAG;AAChD,MAAA,cAAA,CAAe,OAAA,GAAU,IAAA;AACzB,MAAA,IAAI;AACA,QAAA,MAAM,MAAM,MAAM,KAAA,CAAM,CAAA,EAAG,GAAA,CAAI,UAAU,CAAA,aAAA,CAAA,EAAiB;AAAA,UACtD,MAAA,EAAQ,MAAA;AAAA,UACR,WAAA,EAAa,SAAA;AAAA,UACb,OAAA,EAAS,EAAE,MAAA,EAAQ,kBAAA;AAAmB,SACzC,CAAA;AACD,QAAA,IAAI,CAAC,IAAI,EAAA,EAAI;AACb,QAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAQ7B,QAAA,IACI,IAAA,CAAK,MACL,OAAO,IAAA,CAAK,UAAU,QAAA,IACtB,IAAA,CAAK,OAAA,EAAS,MAAA,KAAW,KAAA,EAC3B;AACE,UAAA,eAAA,CAAgB,EAAE,KAAA,EAAO,IAAA,CAAK,KAAA,EAAO,OAAO,CAAA;AAC5C,UAAA,YAAA,CAAa,IAAI,CAAA;AAAA,QACrB;AAAA,MACJ,CAAA,CAAA,MAAQ;AAAA,MAER,CAAA,SAAE;AACE,QAAA,cAAA,CAAe,OAAA,GAAU,KAAA;AAAA,MAC7B;AAAA,IACJ,CAAA;AAAA,IACA,CAAC,IAAI,UAAU;AAAA,GACnB;AAEA,EAAA,MAAM,OAAA,GAAgBA,mBAAY,YAAY;AAC1C,IAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,IAAA,IAAI;AACA,MAAA,IAAI,MAAM,cAAA,EAAe;AACzB,MAAA,IAAI,GAAA,GAAM,MAAM,KAAA,CAAM,GAAA,CAAI,MAAA,EAAQ;AAAA,QAC9B,MAAA,EAAQ,KAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,SAAS,EAAE,MAAA,EAAQ,kBAAA,EAAoB,GAAG,kBAAiB;AAAE,OAChE,CAAA;AAID,MAAA,IAAI,GAAA,CAAI,MAAA,KAAW,GAAA,IAAO,GAAA,EAAK;AAC3B,QAAA,eAAA,EAAgB;AAChB,QAAA,GAAA,GAAM,IAAA;AACN,QAAA,YAAA,CAAa,KAAK,CAAA;AAClB,QAAA,GAAA,GAAM,MAAM,KAAA,CAAM,GAAA,CAAI,MAAA,EAAQ;AAAA,UAC1B,MAAA,EAAQ,KAAA;AAAA,UACR,WAAA,EAAa,SAAA;AAAA,UACb,OAAA,EAAS,EAAE,MAAA,EAAQ,kBAAA;AAAmB,SACzC,CAAA;AAAA,MACL;AACA,MAAA,IAAI,GAAA,CAAI,WAAW,GAAA,EAAK;AACpB,QAAA,UAAA,CAAW,IAAI,CAAA;AACf,QAAA,SAAA,CAAU,EAAE,CAAA;AACZ,QAAA,SAAA,CAAU,WAAW,CAAA;AACrB,QAAA,QAAA,CAAS,IAAI,CAAA;AACb,QAAA;AAAA,MACJ;AACA,MAAA,IAAI,CAAC,IAAI,EAAA,EAAI;AACT,QAAA,SAAA,CAAU,OAAO,CAAA;AACjB,QAAA,QAAA,CAAS,IAAI,KAAA,CAAM,CAAA,qBAAA,EAAwB,GAAA,CAAI,MAAM,EAAE,CAAC,CAAA;AACxD,QAAA;AAAA,MACJ;AACA,MAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAC7B,MAAA,MAAM,IAAA,GAAO,gBAAA,CAAiB,IAAA,CAAK,OAAO,CAAA;AAK1C,MAAA,IAAI,IAAA,IAAQ,GAAA,IAAO,IAAA,CAAK,KAAA,KAAU,IAAI,KAAA,EAAO;AACzC,QAAA,eAAA,EAAgB;AAChB,QAAA,GAAA,GAAM,IAAA;AAAA,MACV;AACA,MAAA,YAAA,CAAa,QAAQ,IAAI,CAAA;AACzB,MAAA,MAAM,gBAAgB,KAAA,CAAM,OAAA,CAAQ,IAAA,CAAK,MAAM,IACzC,IAAA,CAAK,MAAA,CACA,GAAA,CAAI,oBAAoB,EACxB,MAAA,CAAO,CAAC,MAA6B,CAAA,KAAM,IAAI,IACpD,EAAC;AACP,MAAA,UAAA,CAAW,IAAI,CAAA;AACf,MAAA,SAAA,CAAU,aAAa,CAAA;AACvB,MAAA,SAAA,CAAU,IAAA,GAAO,kBAAkB,WAAW,CAAA;AAC9C,MAAA,QAAA,CAAS,IAAI,CAAA;AAIb,MAAA,IAAI,QAAQ,CAAC,GAAA,EAAK,KAAK,UAAA,CAAW,KAAK,KAAK,CAAA;AAO5C,MAAA,MAAM,gBACF,OAAO,MAAA,KAAW,WAAA,GAAc,MAAA,CAAO,SAAS,MAAA,GAAS,IAAA;AAC7D,MAAA,IACI,IAAA,IACA,aAAA,CAAc,MAAA,KAAW,CAAA,IACzB,aAAA,KAAkB,IAAA,IAClB,CAAC,GAAA,CAAI,UAAA,CAAW,UAAA,CAAW,aAAa,CAAA,EAC1C;AACE,QAAA,MAAM,KAAA,GAAQ,MAAM,eAAA,CAAgB,GAAG,CAAA;AACvC,QAAA,IAAI,KAAA,CAAM,MAAA,GAAS,CAAA,EAAG,SAAA,CAAU,KAAK,CAAA;AAAA,MACzC;AAAA,IACJ,SAAS,GAAA,EAAK;AACV,MAAA,SAAA,CAAU,OAAO,CAAA;AACjB,MAAA,QAAA,CAAS,GAAA,YAAe,QAAQ,GAAA,GAAM,IAAI,MAAM,MAAA,CAAO,GAAG,CAAC,CAAC,CAAA;AAAA,IAChE;AAAA,EACJ,CAAA,EAAG,CAAC,GAAA,EAAK,UAAU,CAAC,CAAA;AAEpB,EAAMA,iBAAU,MAAM;AAClB,IAAA,IAAI,SAAA,GAAY,KAAA;AAKhB,IAAA,qBAAA,EAAsB;AACtB,IAAA,KAAA,CAAM,YAAY;AAId,MAAA,MAAM,qBAAA,CAAsB,IAAI,UAAU,CAAA;AAC1C,MAAA,IAAI,CAAC,SAAA,EAAW,KAAK,OAAA,EAAQ;AAAA,IACjC,CAAA,GAAG;AACH,IAAA,OAAO,MAAM;AACT,MAAA,SAAA,GAAY,IAAA;AAAA,IAChB,CAAA;AAAA,EACJ,CAAA,EAAG,CAAC,OAAA,EAAS,GAAA,CAAI,UAAU,CAAC,CAAA;AAK5B,EAAMA,MAAA,CAAA,SAAA,CAAU,MAAM,0BAAA,CAA2B,GAAA,CAAI,UAAU,CAAA,EAAG,CAAC,GAAA,CAAI,UAAU,CAAC,CAAA;AAKlF,EAAMA,MAAA,CAAA,SAAA,CAAU,MAAM,uBAAA,CAAwB,GAAA,CAAI,UAAU,CAAA,EAAG,CAAC,GAAA,CAAI,UAAU,CAAC,CAAA;AAE/E,EAAA,MAAM,OAAA,GAAgBA,MAAA,CAAA,WAAA;AAAA,IAClB,OAAO,IAAA,KAAsC;AACzC,MAAA,MAAM,KAAA,GAAwB,MAAM,KAAA,IAAS,KAAA;AAC7C,MAAA,IAAI;AACA,QAAA,MAAM,GAAA,GAAM,IAAI,GAAA,CAAI,CAAA,EAAG,IAAI,UAAU,CAAA,EAAG,GAAA,CAAI,UAAU,CAAA,CAAE,CAAA;AACxD,QAAA,IAAI,UAAU,SAAA,EAAW,GAAA,CAAI,YAAA,CAAa,GAAA,CAAI,SAAS,SAAS,CAAA;AAChE,QAAA,MAAM,GAAA,GAAM,MAAM,KAAA,CAAM,GAAA,CAAI,UAAS,EAAG;AAAA,UACpC,MAAA,EAAQ,MAAA;AAAA,UACR,WAAA,EAAa,SAAA;AAAA;AAAA;AAAA;AAAA,UAIb,OAAA,EAAS,EAAE,GAAG,gBAAA,EAAiB,EAAE;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,UAMjC,SAAA,EAAW;AAAA,SACd,CAAA;AAGD,QAAA,eAAA,EAAgB;AAChB,QAAA,YAAA,CAAa,KAAK,CAAA;AAQlB,QAAA,IAAI,KAAA,KAAU,SAAA,IAAa,GAAA,CAAI,EAAA,EAAI;AAC/B,UAAA,MAAM,OAAA,EAAQ;AACd,UAAA;AAAA,QACJ;AAAA,MACJ,CAAA,CAAA,MAAQ;AAGJ,QAAA,eAAA,EAAgB;AAChB,QAAA,YAAA,CAAa,KAAK,CAAA;AAAA,MACtB;AACA,MAAA,UAAA,CAAW,IAAI,CAAA;AACf,MAAA,SAAA,CAAU,EAAE,CAAA;AACZ,MAAA,SAAA,CAAU,WAAW,CAAA;AAAA,IACzB,CAAA;AAAA,IACA,CAAC,GAAA,CAAI,UAAA,EAAY,GAAA,CAAI,YAAY,OAAO;AAAA,GAC5C;AAEA,EAAA,MAAM,aAAA,GAAsBA,MAAA,CAAA,WAAA;AAAA,IACxB,OAAO,KAAA,KAAkB;AACrB,MAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,MAAA,MAAM,MAAM,MAAM,KAAA,CAAM,CAAA,EAAG,GAAA,CAAI,UAAU,CAAA,gBAAA,CAAA,EAAoB;AAAA,QACzD,MAAA,EAAQ,MAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,SAAS,EAAE,cAAA,EAAgB,kBAAA,EAAoB,GAAG,kBAAiB,EAAE;AAAA,QACrE,MAAM,IAAA,CAAK,SAAA,CAAU,EAAE,MAAA,EAAQ,OAAO;AAAA,OACzC,CAAA;AACD,MAAA,IAAI,CAAC,IAAI,EAAA,EAAI;AACT,QAAA,IAAI,MAAA,GAAS,CAAA,KAAA,EAAQ,GAAA,CAAI,MAAM,CAAA,CAAA;AAC/B,QAAA,IAAI;AACA,UAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAC7B,UAAA,IAAI,IAAA,CAAK,MAAA,EAAQ,MAAA,GAAS,IAAA,CAAK,MAAA;AAAA,QACnC,CAAA,CAAA,MAAQ;AAAA,QAER;AACA,QAAA,MAAM,IAAI,KAAA,CAAM,CAAA,iDAAA,EAAoD,MAAM,CAAA,CAAE,CAAA;AAAA,MAChF;AAOA,MAAA,IAAI;AACA,QAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAI7B,QAAA,IAAI,OAAO,IAAA,CAAK,KAAA,KAAU,QAAA,IAAY,IAAA,CAAK,SAAS,MAAA,EAAQ;AACxD,UAAA,eAAA,CAAgB,EAAE,OAAO,IAAA,CAAK,KAAA,EAAO,OAAO,IAAA,CAAK,OAAA,CAAQ,QAAQ,CAAA;AACjE,UAAA,YAAA,CAAa,IAAI,CAAA;AAAA,QACrB;AAAA,MACJ,CAAA,CAAA,MAAQ;AAAA,MAER;AAIA,MAAA,MAAM,OAAA,EAAQ;AAAA,IAClB,CAAA;AAAA,IACA,CAAC,GAAA,CAAI,UAAA,EAAY,OAAO;AAAA,GAC5B;AAEA,EAAA,MAAM,aAAA,GAAsBA,MAAA,CAAA,WAAA;AAAA,IACxB,CAAC,QAAA,KAAsB;AACnB,MAAA,MAAM,KACF,QAAA,KAAa,OAAO,WAAW,WAAA,GAAc,MAAA,CAAO,SAAS,IAAA,GAAO,MAAA,CAAA;AACxE,MAAA,OAAO,kBAAA,CAAmB,KAAK,EAAE,CAAA;AAAA,IACrC,CAAA;AAAA,IACA,CAAC,GAAG;AAAA,GACR;AAEA,EAAA,MAAM,kBAAA,GAA2BA,MAAA,CAAA,WAAA;AAAA,IAC7B,OAAO,IAAA,KAA8B;AACjC,MAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AAMnC,MAAA,MAAM,MAAM,MAAM,KAAA,CAAM,CAAA,EAAG,GAAA,CAAI,UAAU,CAAA,iBAAA,CAAA,EAAqB;AAAA,QAC1D,MAAA,EAAQ,OAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,SAAS,EAAE,cAAA,EAAgB,kBAAA,EAAoB,GAAG,kBAAiB,EAAE;AAAA,QACrE,MAAM,IAAA,CAAK,SAAA,CAAU,EAAE,gBAAA,EAAkB,MAAM;AAAA,OAClD,CAAA;AACD,MAAA,IAAI,CAAC,IAAI,EAAA,EAAI;AACT,QAAA,IAAI,MAAA,GAAS,CAAA,KAAA,EAAQ,GAAA,CAAI,MAAM,CAAA,CAAA;AAC/B,QAAA,IAAI;AACA,UAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAC7B,UAAA,IAAI,IAAA,CAAK,MAAA,EAAQ,MAAA,GAAS,IAAA,CAAK,MAAA;AAAA,QACnC,CAAA,CAAA,MAAQ;AAAA,QAER;AACA,QAAA,MAAM,IAAI,KAAA,CAAM,CAAA,sDAAA,EAAyD,MAAM,CAAA,CAAE,CAAA;AAAA,MACrF;AAKA,MAAA,IAAI;AACA,QAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAI7B,QAAA,MAAM,MAAM,cAAA,EAAe;AAC3B,QAAA,IACI,GAAA,IACA,OAAO,IAAA,CAAK,KAAA,KAAU,YACtB,IAAA,CAAK,OAAA,EAAS,MAAA,KAAW,GAAA,CAAI,KAAA,EAC/B;AACE,UAAA,eAAA,CAAgB,EAAE,KAAA,EAAO,IAAA,CAAK,OAAO,KAAA,EAAO,GAAA,CAAI,OAAO,CAAA;AAAA,QAC3D;AAAA,MACJ,CAAA,CAAA,MAAQ;AAAA,MAER;AACA,MAAA,MAAM,OAAA,EAAQ;AAAA,IAClB,CAAA;AAAA,IACA,CAAC,GAAA,CAAI,UAAA,EAAY,OAAO;AAAA,GAC5B;AAEA,EAAA,MAAM,KAAA,GAAcA,eAAwB,MAAM;AAC9C,IAAA,MAAM,WACF,eAAA,KAAoB,OAAO,WAAW,WAAA,GAAc,MAAA,CAAO,SAAS,IAAA,GAAO,MAAA,CAAA;AAC/E,IAAA,OAAO;AAAA,MACH,MAAA;AAAA,MACA,OAAA;AAAA,MACA,MAAA;AAAA,MACA,SAAA;AAAA,MACA,KAAA;AAAA,MACA,OAAA;AAAA,MACA,OAAA;AAAA,MACA,aAAA;AAAA,MACA,aAAA;AAAA,MACA,kBAAA;AAAA,MACA,SAAA,EAAW,cAAA,CAAe,GAAA,EAAK,QAAQ;AAAA,KAC3C;AAAA,EACJ,CAAA,EAAG;AAAA,IACC,MAAA;AAAA,IACA,OAAA;AAAA,IACA,MAAA;AAAA,IACA,SAAA;AAAA,IACA,KAAA;AAAA,IACA,OAAA;AAAA,IACA,OAAA;AAAA,IACA,aAAA;AAAA,IACA,aAAA;AAAA,IACA,kBAAA;AAAA,IACA,GAAA;AAAA,IACA;AAAA,GACH,CAAA;AAED,EAAA,uBAAO,GAAA,CAAC,cAAA,CAAe,QAAA,EAAf,EAAwB,OAAe,QAAA,EAAS,CAAA;AAC5D;AAMO,SAAS,YAAA,GAA+B;AAC3C,EAAA,MAAM,GAAA,GAAYA,kBAAW,cAAc,CAAA;AAC3C,EAAA,IAAI,CAAC,GAAA,EAAK;AACN,IAAA,MAAM,IAAI,KAAA;AAAA,MACN;AAAA,KACJ;AAAA,EACJ;AACA,EAAA,OAAO,GAAA;AACX;AAOO,SAAS,oBAAA,GAA8C;AAC1D,EAAA,OAAaA,kBAAW,cAAc,CAAA;AAC1C;AC9iBA,SAAS,eAAe,IAAA,EAAsB;AAC1C,EAAA,IAAI,IAAA,CAAK,MAAA,IAAU,EAAA,EAAI,OAAO,IAAA;AAC9B,EAAA,OAAO,CAAA,EAAG,IAAA,CAAK,KAAA,CAAM,CAAA,EAAG,CAAC,CAAC,CAAA,MAAA,EAAI,IAAA,CAAK,KAAA,CAAM,EAAE,CAAC,CAAA,CAAA;AAChD;AAEA,SAAS,kBAAkB,IAAA,EAAsB;AAC7C,EAAA,IAAI,IAAA,CAAK,MAAA,IAAU,EAAA,EAAI,OAAO,IAAA;AAC9B,EAAA,OAAO,CAAA,EAAG,IAAA,CAAK,KAAA,CAAM,CAAA,EAAG,CAAC,CAAC,CAAA,MAAA,EAAI,IAAA,CAAK,KAAA,CAAM,EAAE,CAAC,CAAA,CAAA;AAChD;AAEA,SAAS,UAAA,CAAW,OAAe,MAAA,EAAyB;AACxD,EAAA,OAAO,OAAO,WAAA,EAAY,CAAE,UAAA,CAAW,KAAA,CAAM,aAAa,CAAA;AAC9D;AAEA,IAAI,gBAAA,GAAmB,CAAA;AACvB,SAAS,YAAY,MAAA,EAAwB;AACzC,EAAA,MAAM,CAAC,EAAE,CAAA,GAAUC,MAAA,CAAA,QAAA,CAAS,MAAM,GAAG,MAAM,CAAA,CAAA,EAAI,EAAE,gBAAgB,CAAA,CAAE,CAAA;AACnE,EAAA,OAAO,EAAA;AACX;AA6CO,SAAS,aAAA,CAAc;AAAA,EAC1B,YAAA,GAAe,2BAAA;AAAA,EACf,SAAA,EAAW,iBAAA;AAAA,EACX,WAAA,GAAc,SAAA;AAAA,EACd,SAAA;AAAA,EACA,gBAAA;AAAA,EACA,gBAAA;AAAA,EACA;AACJ,CAAA,EAAkD;AAC9C,EAAA,MAAM,EAAE,MAAA,EAAQ,OAAA,EAAS,WAAW,gBAAA,EAAkB,OAAA,KAAY,YAAA,EAAa;AAC/E,EAAA,MAAM,YAAY,iBAAA,IAAqB,gBAAA;AACvC,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAUA,gBAAS,KAAK,CAAA;AAC5C,EAAA,MAAM,OAAA,GAAgBA,cAA8B,IAAI,CAAA;AAExD,EAAMA,iBAAU,MAAM;AAClB,IAAA,IAAI,CAAC,IAAA,EAAM;AACX,IAAA,SAAS,mBAAmB,CAAA,EAAe;AACvC,MAAA,IAAI,OAAA,CAAQ,WAAW,CAAC,OAAA,CAAQ,QAAQ,QAAA,CAAS,CAAA,CAAE,MAAc,CAAA,EAAG;AAChE,QAAA,OAAA,CAAQ,KAAK,CAAA;AAAA,MACjB;AAAA,IACJ;AACA,IAAA,SAAS,aAAa,CAAA,EAAkB;AACpC,MAAA,IAAI,CAAA,CAAE,GAAA,KAAQ,QAAA,EAAU,OAAA,CAAQ,KAAK,CAAA;AAAA,IACzC;AACA,IAAA,QAAA,CAAS,gBAAA,CAAiB,aAAa,kBAAkB,CAAA;AACzD,IAAA,QAAA,CAAS,gBAAA,CAAiB,WAAW,YAAY,CAAA;AACjD,IAAA,OAAO,MAAM;AACT,MAAA,QAAA,CAAS,mBAAA,CAAoB,aAAa,kBAAkB,CAAA;AAC5D,MAAA,QAAA,CAAS,mBAAA,CAAoB,WAAW,YAAY,CAAA;AAAA,IACxD,CAAA;AAAA,EACJ,CAAA,EAAG,CAAC,IAAI,CAAC,CAAA;AAET,EAAA,IAAI,MAAA,KAAW,WAAW,OAAO,IAAA;AAEjC,EAAA,IAAI,MAAA,KAAW,eAAA,IAAmB,CAAC,OAAA,EAAS;AACxC,IAAA,uBACIC,GAAAA;AAAA,MAAC,GAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAM,SAAA;AAAA,QACN,WAAW,gBAAA,IAAoB,SAAA;AAAA,QAC/B,6BAAA,EAA4B,EAAA;AAAA,QAE3B,QAAA,EAAA;AAAA;AAAA,KACL;AAAA,EAER;AAEA,EAAA,uBACI,IAAA;AAAA,IAAC,KAAA;AAAA,IAAA;AAAA,MACG,GAAA,EAAK,OAAA;AAAA,MACL,SAAA;AAAA,MACA,sBAAA,EAAqB,EAAA;AAAA,MACrB,KAAA,EAAO,EAAE,QAAA,EAAU,UAAA,EAAY,SAAS,cAAA,EAAe;AAAA,MAEvD,QAAA,EAAA;AAAA,wBAAA,IAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,SAAS,MAAM,OAAA,CAAQ,CAAC,CAAA,KAAM,CAAC,CAAC,CAAA;AAAA,YAChC,eAAA,EAAc,MAAA;AAAA,YACd,eAAA,EAAe,IAAA;AAAA,YACf,YAAA,EAAY,CAAA,aAAA,EAAgB,OAAA,CAAQ,KAAK,CAAA,oBAAA,CAAA;AAAA,YACzC,SAAA,EAAW,gBAAA;AAAA,YACX,8BAAA,EAA6B,EAAA;AAAA,YAC7B,KAAA,EACI,mBACM,MAAA,GACA;AAAA,cACI,OAAA,EAAS,aAAA;AAAA,cACT,UAAA,EAAY,QAAA;AAAA,cACZ,GAAA,EAAK,QAAA;AAAA,cACL,OAAA,EAAS,kBAAA;AAAA,cACT,YAAA,EAAc,QAAA;AAAA,cACd,MAAA,EAAQ,kCAAA;AAAA,cACR,UAAA,EACI,6DAAA;AAAA,cACJ,KAAA,EAAO,4BAAA;AAAA,cACP,UAAA,EAAY,yCAAA;AAAA,cACZ,QAAA,EAAU,EAAA;AAAA,cACV,MAAA,EAAQ;AAAA,aACZ;AAAA,YAGV,QAAA,EAAA;AAAA,8BAAAA,GAAAA,CAAC,MAAA,EAAA,EAAK,aAAA,EAAY,MAAA,EAAO,KAAA,EAAO,EAAE,KAAA,EAAO,SAAA,EAAW,QAAA,EAAU,CAAA,EAAE,EAAG,QAAA,EAAA,QAAA,EAEnE,CAAA;AAAA,8BACAA,IAAC,MAAA,EAAA,EAAM,QAAA,EAAA,OAAA,CAAQ,eAAe,cAAA,CAAe,OAAA,CAAQ,KAAK,CAAA,EAAE,CAAA;AAAA,8BAC5DA,GAAAA;AAAA,gBAAC,KAAA;AAAA,gBAAA;AAAA,kBACG,KAAA,EAAM,GAAA;AAAA,kBACN,MAAA,EAAO,GAAA;AAAA,kBACP,OAAA,EAAQ,WAAA;AAAA,kBACR,aAAA,EAAY,MAAA;AAAA,kBACZ,KAAA,EAAO;AAAA,oBACH,UAAA,EAAY,iBAAA;AAAA,oBACZ,SAAA,EAAW,OAAO,gBAAA,GAAmB,WAAA;AAAA,oBACrC,OAAA,EAAS;AAAA,mBACb;AAAA,kBAEA,QAAA,kBAAAA,GAAAA;AAAA,oBAAC,MAAA;AAAA,oBAAA;AAAA,sBACG,CAAA,EAAE,gBAAA;AAAA,sBACF,MAAA,EAAO,cAAA;AAAA,sBACP,WAAA,EAAY,KAAA;AAAA,sBACZ,IAAA,EAAK,MAAA;AAAA,sBACL,aAAA,EAAc;AAAA;AAAA;AAClB;AAAA;AACJ;AAAA;AAAA,SACJ;AAAA,QAEC,IAAA,oBACG,IAAA;AAAA,UAAC,KAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,MAAA;AAAA,YACL,YAAA,EAAW,cAAA;AAAA,YACX,SAAA,EAAW,gBAAA;AAAA,YACX,8BAAA,EAA6B,EAAA;AAAA,YAC7B,KAAA,EACI,gBAAA,GACM,EAAE,QAAA,EAAU,UAAA,EAAY,MAAA,EAAQ,EAAA,EAAI,GAAA,EAAK,kBAAA,EAAoB,KAAA,EAAO,CAAA,EAAE,GACtE;AAAA,cACI,QAAA,EAAU,UAAA;AAAA,cACV,MAAA,EAAQ,EAAA;AAAA,cACR,GAAA,EAAK,kBAAA;AAAA,cACL,KAAA,EAAO,CAAA;AAAA,cACP,QAAA,EAAU,GAAA;AAAA,cACV,UAAA,EAAY,yBAAA;AAAA,cACZ,KAAA,EAAO,oCAAA;AAAA,cACP,MAAA,EAAQ,kCAAA;AAAA,cACR,SAAA,EAAW,mCAAA;AAAA,cACX,UAAA,EAAY;AAAA,aAChB;AAAA,YAGV,QAAA,EAAA;AAAA,8BAAA,IAAA;AAAA,gBAAC,KAAA;AAAA,gBAAA;AAAA,kBACG,6BAAA,EAA4B,EAAA;AAAA,kBAC5B,KAAA,EAAO;AAAA,oBACH,OAAA,EAAS,0BAAA;AAAA,oBACT,YAAA,EAAc;AAAA,mBAClB;AAAA,kBAEA,QAAA,EAAA;AAAA,oCAAAA,GAAAA;AAAA,sBAAC,KAAA;AAAA,sBAAA;AAAA,wBACG,4BAAA,EAA2B,EAAA;AAAA,wBAC3B,KAAA,EAAO;AAAA,0BACH,KAAA,EAAO,yBAAA;AAAA,0BACP,QAAA,EAAU,EAAA;AAAA,0BACV,aAAA,EAAe,QAAA;AAAA,0BACf,aAAA,EAAe,WAAA;AAAA,0BACf,YAAA,EAAc;AAAA,yBAClB;AAAA,wBACH,QAAA,EAAA;AAAA;AAAA,qBAED;AAAA,oCACAA,GAAAA;AAAA,sBAAC,KAAA;AAAA,sBAAA;AAAA,wBACG,8BAAA,EAA6B,EAAA;AAAA,wBAC7B,KAAA,EAAO;AAAA,0BACH,KAAA,EAAO,oCAAA;AAAA,0BACP,QAAA,EAAU,EAAA;AAAA,0BACV,SAAA,EAAW,WAAA;AAAA,0BACX,UAAA,EAAY;AAAA,yBAChB;AAAA,wBAEC,QAAA,EAAA,OAAA,CAAQ;AAAA;AAAA,qBACb;AAAA,oBACC,OAAA,CAAQ,8BACLA,GAAAA;AAAA,sBAAC,KAAA;AAAA,sBAAA;AAAA,wBACG,KAAA,EAAO;AAAA,0BACH,KAAA,EAAO,kCAAA;AAAA,0BACP,QAAA,EAAU,EAAA;AAAA,0BACV,SAAA,EAAW,CAAA;AAAA,0BACX,aAAA,EAAe;AAAA,yBACnB;AAAA,wBAEC,QAAA,EAAA,OAAA,CAAQ;AAAA;AAAA,qBACb,GACA;AAAA;AAAA;AAAA,eACR;AAAA,8BACA,IAAA,CAAC,SAAI,IAAA,EAAK,MAAA,EAAO,OAAO,EAAE,OAAA,EAAS,WAAU,EACxC,QAAA,EAAA;AAAA,gBAAA,YAAA,mBACG,IAAA;AAAA,kBAAC,GAAA;AAAA,kBAAA;AAAA,oBACG,IAAA,EAAK,UAAA;AAAA,oBACL,IAAA,EAAM,YAAA;AAAA,oBACN,OAAA,EAAS,MAAM,OAAA,CAAQ,KAAK,CAAA;AAAA,oBAC5B,SAAA,EAAW,iBAAA;AAAA,oBACX,2BAAA,EAA0B,EAAA;AAAA,oBAC1B,KAAA,EACI,oBACM,MAAA,GACA;AAAA,sBACI,OAAA,EAAS,MAAA;AAAA,sBACT,UAAA,EAAY,QAAA;AAAA,sBACZ,GAAA,EAAK,QAAA;AAAA,sBACL,OAAA,EAAS,iBAAA;AAAA,sBACT,QAAA,EAAU,EAAA;AAAA,sBACV,KAAA,EAAO,oCAAA;AAAA,sBACP,cAAA,EAAgB,MAAA;AAAA,sBAChB,MAAA,EAAQ;AAAA,qBACZ;AAAA,oBAGV,QAAA,EAAA;AAAA,sCAAAA,GAAAA;AAAA,wBAAC,MAAA;AAAA,wBAAA;AAAA,0BACG,aAAA,EAAY,MAAA;AAAA,0BACZ,KAAA,EAAO,EAAE,KAAA,EAAO,kCAAA,EAAmC;AAAA,0BACtD,QAAA,EAAA;AAAA;AAAA,uBAED;AAAA,sCACAA,IAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,IAAA,EAAM,CAAA,IAAK,QAAA,EAAA,WAAA,EAAS,CAAA;AAAA,sCACnCA,GAAAA;AAAA,wBAAC,MAAA;AAAA,wBAAA;AAAA,0BACG,KAAA,EAAO;AAAA,4BACH,KAAA,EAAO,kCAAA;AAAA,4BACP,QAAA,EAAU;AAAA,2BACd;AAAA,0BACH,QAAA,EAAA;AAAA;AAAA;AAED;AAAA;AAAA,iBACJ,GACA,IAAA;AAAA,gCACJ,IAAA;AAAA,kBAAC,QAAA;AAAA,kBAAA;AAAA,oBACG,IAAA,EAAK,QAAA;AAAA,oBACL,IAAA,EAAK,UAAA;AAAA,oBACL,SAAS,MAAM;AACX,sBAAA,OAAA,CAAQ,KAAK,CAAA;AACb,sBAAA,KAAK,OAAA,EAAQ;AAAA,oBACjB,CAAA;AAAA,oBACA,SAAA,EAAW,iBAAA;AAAA,oBACX,2BAAA,EAA0B,EAAA;AAAA,oBAC1B,8BAAA,EAA6B,EAAA;AAAA,oBAC7B,KAAA,EACI,oBACM,MAAA,GACA;AAAA,sBACI,OAAA,EAAS,MAAA;AAAA,sBACT,UAAA,EAAY,QAAA;AAAA,sBACZ,GAAA,EAAK,QAAA;AAAA,sBACL,KAAA,EAAO,MAAA;AAAA,sBACP,OAAA,EAAS,iBAAA;AAAA,sBACT,QAAA,EAAU,EAAA;AAAA,sBACV,KAAA,EAAO,oCAAA;AAAA,sBACP,UAAA,EAAY,aAAA;AAAA,sBACZ,MAAA,EAAQ,CAAA;AAAA,sBACR,UAAA,EAAY,SAAA;AAAA,sBACZ,SAAA,EAAW,MAAA;AAAA,sBACX,MAAA,EAAQ;AAAA,qBACZ;AAAA,oBAGV,QAAA,EAAA;AAAA,sCAAAA,GAAAA;AAAA,wBAAC,MAAA;AAAA,wBAAA;AAAA,0BACG,aAAA,EAAY,MAAA;AAAA,0BACZ,KAAA,EAAO,EAAE,KAAA,EAAO,kCAAA,EAAmC;AAAA,0BACtD,QAAA,EAAA;AAAA;AAAA,uBAED;AAAA,sCACAA,IAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,IAAA,EAAM,CAAA,IAAK,QAAA,EAAA,UAAA,EAAQ;AAAA;AAAA;AAAA;AACtC,eAAA,EACJ;AAAA;AAAA;AAAA;AACJ;AAAA;AAAA,GAER;AAER;AA4BO,SAAS,cAAA,CAAe;AAAA,EAC3B,KAAA,GAAQ,sBAAA;AAAA,EACR,KAAA,GAAQ,KAAA;AAAA,EACR,SAAA;AAAA,EACA,SAAA,EAAW,iBAAA;AAAA,EACX,GAAG;AACP,CAAA,EAAmD;AAC/C,EAAA,MAAM,EAAE,MAAA,EAAQ,SAAA,EAAW,gBAAA,KAAqB,YAAA,EAAa;AAC7D,EAAA,MAAM,OAAO,iBAAA,IAAqB,gBAAA;AAClC,EAAA,IAAI,MAAA,KAAW,iBAAiB,OAAO,IAAA;AACvC,EAAA,IAAI,CAAC,KAAA,IAAS,MAAA,KAAW,SAAA,EAAW,OAAO,IAAA;AAE3C,EAAA,uBACIA,GAAAA;AAAA,IAAC,GAAA;AAAA,IAAA;AAAA,MACI,GAAG,IAAA;AAAA,MACJ,IAAA;AAAA,MACA,SAAA;AAAA,MACA,wBAAA,EAAuB,EAAA;AAAA,MAEtB,QAAA,EAAA;AAAA;AAAA,GACL;AAER;AAeO,SAAS,aAAA,CAAc;AAAA,EAC1B,YAAA;AAAA,EACA,MAAA;AAAA,EACA,SAAA;AAAA,EACA,GAAG;AACP,CAAA,EAAkD;AAC9C,EAAA,MAAM,EAAE,MAAA,EAAQ,OAAA,EAAS,OAAA,KAAY,YAAA,EAAa;AAElD,EAAA,IAAI,MAAA,KAAW,eAAA,IAAmB,CAAC,OAAA,EAAS,OAAO,IAAA;AAEnD,EAAA,MAAM,QAAQ,MAAA,GACR,MAAA,CAAO,EAAE,OAAA,EAAS,QAAQ,KAAA,EAAO,WAAA,EAAa,OAAA,CAAQ,WAAA,EAAa,CAAA,GAClE,OAAA,CAAQ,WAAA,IAAe,cAAA,CAAe,QAAQ,KAAK,CAAA;AAE1D,EAAA,uBACI,IAAA;AAAA,IAAC,KAAA;AAAA,IAAA;AAAA,MACI,GAAG,IAAA;AAAA,MACJ,SAAA;AAAA,MACA,sBAAA,EAAqB,EAAA;AAAA,MACrB,KAAA,EAAO,EAAE,OAAA,EAAS,aAAA,EAAe,UAAA,EAAY,QAAA,EAAU,GAAA,EAAK,QAAA,EAAU,GAAI,IAAA,CAAK,KAAA,IAAS,EAAC,EAAG;AAAA,MAE3F,QAAA,EAAA;AAAA,QAAA,YAAA,mBACGA,GAAAA,CAAC,GAAA,EAAA,EAAE,IAAA,EAAM,YAAA,EAAe,iBAAM,CAAA,mBAE9BA,GAAAA,CAAC,MAAA,EAAA,EAAM,QAAA,EAAA,KAAA,EAAM,CAAA;AAAA,wBAEjBA,GAAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,SAAS,MAAM;AACX,cAAA,KAAK,OAAA,EAAQ;AAAA,YACjB,CAAA;AAAA,YACA,YAAA,EAAW,UAAA;AAAA,YACX,KAAA,EAAO;AAAA,cACH,UAAA,EAAY,MAAA;AAAA,cACZ,MAAA,EAAQ,MAAA;AAAA,cACR,MAAA,EAAQ,SAAA;AAAA,cACR,KAAA,EAAO,SAAA;AAAA,cACP,IAAA,EAAM,SAAA;AAAA,cACN,OAAA,EAAS;AAAA,aACb;AAAA,YACH,QAAA,EAAA;AAAA;AAAA;AAED;AAAA;AAAA,GACJ;AAER;AA2GO,SAAS,uBACZ,OAAA,EAC4B;AAC5B,EAAA,MAAM;AAAA,IACF,KAAA;AAAA,IACA,aAAA;AAAA,IACA,eAAA,GAAkB,kBAAA;AAAA,IAClB,gBAAA;AAAA,IACA;AAAA,GACJ,GAAI,OAAA;AAEJ,EAAA,MAAM,EAAE,MAAA,EAAQ,OAAA,EAAQ,GAAI,YAAA,EAAa;AACzC,EAAA,MAAM,cAAA,GAAiB,MAAA,KAAW,eAAA,GAAmB,OAAA,EAAS,cAAc,IAAA,GAAQ,IAAA;AAEpF,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAUD,gBAAS,KAAK,CAAA;AAC5C,EAAA,MAAM,CAAC,WAAA,EAAa,cAAc,CAAA,GAAUA,gBAAS,KAAK,CAAA;AAC1D,EAAA,MAAM,SAAA,GAAkBA,cAAsB,IAAI,CAAA;AAElD,EAAA,MAAM,SAAA,GAAY,YAAY,iBAAiB,CAAA;AAC/C,EAAA,MAAM,QAAA,GAAW,GAAG,SAAS,CAAA,IAAA,CAAA;AAE7B,EAAA,MAAM,sBACF,cAAA,IAAkB,IAAA,IAAQ,MAAM,WAAA,EAAY,KAAM,eAAe,WAAA,EAAY;AACjF,EAAA,MAAM,UAAA,GACF,cAAA,IAAkB,IAAA,IAClB,cAAA,CAAe,MAAA,GAAS,KACxB,CAAC,mBAAA,IACD,UAAA,CAAW,KAAA,EAAO,cAAc,CAAA;AACpC,EAAA,MAAM,cAAc,IAAA,IAAQ,UAAA;AAE5B,EAAA,SAAS,gBAAA,GAAmB;AACxB,IAAA,IAAI,CAAC,cAAA,EAAgB;AACrB,IAAA,aAAA,CAAc,cAAc,CAAA;AAC5B,IAAA,OAAA,CAAQ,KAAK,CAAA;AACb,IAAA,cAAA,CAAe,KAAK,CAAA;AAAA,EACxB;AAEA,EAAMA,iBAAU,MAAM;AAClB,IAAA,OAAO,MAAM;AACT,MAAA,IAAI,UAAU,OAAA,IAAW,IAAA,EAAM,MAAA,CAAO,YAAA,CAAa,UAAU,OAAO,CAAA;AAAA,IACxE,CAAA;AAAA,EACJ,CAAA,EAAG,EAAE,CAAA;AAEL,EAAA,MAAM,UAAA,GAAyD;AAAA,IAC3D,SAAS,MAAM;AACX,MAAA,IAAI,SAAA,CAAU,WAAW,IAAA,EAAM;AAC3B,QAAA,MAAA,CAAO,YAAA,CAAa,UAAU,OAAO,CAAA;AACrC,QAAA,SAAA,CAAU,OAAA,GAAU,IAAA;AAAA,MACxB;AACA,MAAA,OAAA,CAAQ,IAAI,CAAA;AAAA,IAChB,CAAA;AAAA,IACA,QAAQ,MAAM;AACV,MAAA,SAAA,CAAU,OAAA,GAAU,MAAA,CAAO,UAAA,CAAW,MAAM;AACxC,QAAA,OAAA,CAAQ,KAAK,CAAA;AACb,QAAA,cAAA,CAAe,KAAK,CAAA;AAAA,MACxB,GAAG,GAAG,CAAA;AAAA,IACV,CAAA;AAAA,IACA,SAAA,EAAW,CAAC,CAAA,KAA6C;AACrD,MAAA,IAAI,CAAC,WAAA,EAAa;AAClB,MAAA,IAAI,CAAA,CAAE,QAAQ,WAAA,EAAa;AACvB,QAAA,CAAA,CAAE,cAAA,EAAe;AACjB,QAAA,cAAA,CAAe,IAAI,CAAA;AAAA,MACvB,CAAA,MAAA,IAAW,CAAA,CAAE,GAAA,KAAQ,SAAA,EAAW;AAC5B,QAAA,CAAA,CAAE,cAAA,EAAe;AACjB,QAAA,cAAA,CAAe,KAAK,CAAA;AAAA,MACxB,CAAA,MAAA,IAAW,CAAA,CAAE,GAAA,KAAQ,QAAA,EAAU;AAC3B,QAAA,CAAA,CAAE,cAAA,EAAe;AACjB,QAAA,OAAA,CAAQ,KAAK,CAAA;AACb,QAAA,cAAA,CAAe,KAAK,CAAA;AAAA,MACxB,CAAA,MAAA,IAAW,CAAA,CAAE,GAAA,KAAQ,OAAA,IAAW,WAAA,EAAa;AACzC,QAAA,CAAA,CAAE,cAAA,EAAe;AACjB,QAAA,gBAAA,EAAiB;AAAA,MACrB;AAAA,IACJ,CAAA;AAAA,IACA,IAAA,EAAM,UAAA;AAAA,IACN,eAAA,EAAiB,SAAA;AAAA,IACjB,eAAA,EAAiB,WAAA;AAAA,IACjB,eAAA,EAAiB,cAAc,SAAA,GAAY,MAAA;AAAA,IAC3C,uBAAA,EAAyB,cAAc,QAAA,GAAW,MAAA;AAAA,IAClD,YAAA,EAAc,KAAA;AAAA,IACd,UAAA,EAAY;AAAA,GAChB;AAEA,EAAA,MAAM,OAAA,GAAU,WAAA,IAAe,cAAA,mBAC3BC,GAAAA;AAAA,IAAC,KAAA;AAAA,IAAA;AAAA,MACG,EAAA,EAAI,SAAA;AAAA,MACJ,IAAA,EAAK,SAAA;AAAA,MACL,yBAAA,EAAwB,EAAA;AAAA,MACxB,SAAA,EAAW,gBAAA;AAAA,MACX,KAAA,EAAO;AAAA,QACH,QAAA,EAAU,UAAA;AAAA,QACV,MAAA,EAAQ,EAAA;AAAA,QACR,GAAA,EAAK,kBAAA;AAAA,QACL,IAAA,EAAM,CAAA;AAAA,QACN,KAAA,EAAO;AAAA,OACX;AAAA,MACA,WAAA,EAAa,CAAC,CAAA,KAAM,CAAA,CAAE,cAAA,EAAe;AAAA,MAErC,QAAA,kBAAA,IAAA;AAAA,QAAC,QAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,QAAA;AAAA,UACL,EAAA,EAAI,QAAA;AAAA,UACJ,IAAA,EAAK,QAAA;AAAA,UACL,eAAA,EAAe,WAAA;AAAA,UACf,4BAAA,EAA2B,EAAA;AAAA,UAC3B,kBAAA,EAAkB,cAAc,EAAA,GAAK,MAAA;AAAA,UACrC,SAAA,EAAW,mBAAA;AAAA,UACX,OAAA,EAAS,gBAAA;AAAA,UACT,YAAA,EAAc,MAAM,cAAA,CAAe,IAAI,CAAA;AAAA,UACvC,YAAA,EAAc,MAAM,cAAA,CAAe,KAAK,CAAA;AAAA,UACxC,KAAA,EAAO;AAAA,YACH,OAAA,EAAS,MAAA;AAAA,YACT,UAAA,EAAY,QAAA;AAAA,YACZ,cAAA,EAAgB,eAAA;AAAA,YAChB,GAAA,EAAK,SAAA;AAAA,YACL,KAAA,EAAO,MAAA;AAAA,YACP,SAAA,EAAW,MAAA;AAAA,YACX,MAAA,EAAQ,SAAA;AAAA,YACR,IAAA,EAAM,SAAA;AAAA,YACN,UAAA,EAAY,SAAA;AAAA,YACZ,KAAA,EAAO,SAAA;AAAA,YACP,MAAA,EAAQ,CAAA;AAAA,YACR,OAAA,EAAS;AAAA,WACb;AAAA,UAEA,QAAA,EAAA;AAAA,4BAAAA,GAAAA,CAAC,MAAA,EAAA,EAAK,kCAAA,EAAiC,EAAA,EAAI,QAAA,EAAA,eAAA,EAAgB,CAAA;AAAA,4BAC3DA,GAAAA;AAAA,cAAC,MAAA;AAAA,cAAA;AAAA,gBACG,kCAAA,EAAiC,EAAA;AAAA,gBACjC,KAAA,EAAO,EAAE,UAAA,EAAY,yBAAA,EAA0B;AAAA,gBAE9C,4BAAkB,cAAc;AAAA;AAAA;AACrC;AAAA;AAAA;AACJ;AAAA,GACJ,GACA,IAAA;AAEJ,EAAA,OAAO,EAAE,YAAY,OAAA,EAAQ;AACjC;AAEO,IAAM,cAAA,GAAuBD,MAAA,CAAA,UAAA;AAAA,EAChC,SAASE,eAAAA,CACL;AAAA,IACI,KAAA;AAAA,IACA,aAAA;AAAA,IACA,eAAA,GAAkB,kBAAA;AAAA,IAClB,gBAAA;AAAA,IACA,gBAAA;AAAA,IACA,mBAAA;AAAA,IACA,OAAA;AAAA,IACA,MAAA;AAAA,IACA,SAAA;AAAA,IACA,GAAG;AAAA,KAEP,YAAA,EACkB;AAClB,IAAA,MAAM,EAAE,MAAA,EAAQ,OAAA,EAAQ,GAAI,YAAA,EAAa;AACzC,IAAA,MAAM,cAAA,GAAiB,MAAA,KAAW,eAAA,GAAmB,OAAA,EAAS,cAAc,IAAA,GAAQ,IAAA;AAEpF,IAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAUF,gBAAS,KAAK,CAAA;AAC5C,IAAA,MAAM,CAAC,WAAA,EAAa,cAAc,CAAA,GAAUA,gBAAS,KAAK,CAAA;AAE1D,IAAA,MAAM,QAAA,GAAiBA,cAAgC,IAAI,CAAA;AAC3D,IAAA,MAAM,MAAA,GAAS,CAAC,IAAA,KAAkC;AAC9C,MAAA,QAAA,CAAS,OAAA,GAAU,IAAA;AACnB,MAAA,IAAI,OAAO,YAAA,KAAiB,UAAA,EAAY,YAAA,CAAa,IAAI,CAAA;AAAA,WAAA,IAChD,YAAA,eAA2B,OAAA,GAAU,IAAA;AAAA,IAClD,CAAA;AACA,IAAA,MAAM,SAAA,GAAkBA,cAAsB,IAAI,CAAA;AAElD,IAAA,MAAM,SAAA,GAAY,YAAY,iBAAiB,CAAA;AAC/C,IAAA,MAAM,QAAA,GAAW,GAAG,SAAS,CAAA,IAAA,CAAA;AAE7B,IAAA,MAAM,sBACF,cAAA,IAAkB,IAAA,IAAQ,MAAM,WAAA,EAAY,KAAM,eAAe,WAAA,EAAY;AACjF,IAAA,MAAM,UAAA,GACF,cAAA,IAAkB,IAAA,IAClB,cAAA,CAAe,MAAA,GAAS,KACxB,CAAC,mBAAA,IACD,UAAA,CAAW,KAAA,EAAO,cAAc,CAAA;AACpC,IAAA,MAAM,cAAc,IAAA,IAAQ,UAAA;AAE5B,IAAA,SAAS,gBAAA,GAAmB;AACxB,MAAA,IAAI,CAAC,cAAA,EAAgB;AACrB,MAAA,aAAA,CAAc,cAAc,CAAA;AAC5B,MAAA,OAAA,CAAQ,KAAK,CAAA;AACb,MAAA,cAAA,CAAe,KAAK,CAAA;AAEpB,MAAA,QAAA,CAAS,SAAS,KAAA,EAAM;AAAA,IAC5B;AAEA,IAAA,SAAS,YAAY,CAAA,EAAuC;AACxD,MAAA,IAAI,SAAA,CAAU,WAAW,IAAA,EAAM;AAC3B,QAAA,MAAA,CAAO,YAAA,CAAa,UAAU,OAAO,CAAA;AACrC,QAAA,SAAA,CAAU,OAAA,GAAU,IAAA;AAAA,MACxB;AACA,MAAA,OAAA,CAAQ,IAAI,CAAA;AACZ,MAAA,OAAA,GAAU,CAAC,CAAA;AAAA,IACf;AAEA,IAAA,SAAS,WAAW,CAAA,EAAuC;AAEvD,MAAA,SAAA,CAAU,OAAA,GAAU,MAAA,CAAO,UAAA,CAAW,MAAM;AACxC,QAAA,OAAA,CAAQ,KAAK,CAAA;AACb,QAAA,cAAA,CAAe,KAAK,CAAA;AAAA,MACxB,GAAG,GAAG,CAAA;AACN,MAAA,MAAA,GAAS,CAAC,CAAA;AAAA,IACd;AAEA,IAAA,SAAS,cAAc,CAAA,EAA0C;AAC7D,MAAA,IAAI,WAAA,EAAa;AACb,QAAA,IAAI,CAAA,CAAE,QAAQ,WAAA,EAAa;AACvB,UAAA,CAAA,CAAE,cAAA,EAAe;AACjB,UAAA,cAAA,CAAe,IAAI,CAAA;AAAA,QACvB,CAAA,MAAA,IAAW,CAAA,CAAE,GAAA,KAAQ,SAAA,EAAW;AAC5B,UAAA,CAAA,CAAE,cAAA,EAAe;AACjB,UAAA,cAAA,CAAe,KAAK,CAAA;AAAA,QACxB,CAAA,MAAA,IAAW,CAAA,CAAE,GAAA,KAAQ,QAAA,EAAU;AAC3B,UAAA,CAAA,CAAE,cAAA,EAAe;AACjB,UAAA,OAAA,CAAQ,KAAK,CAAA;AACb,UAAA,cAAA,CAAe,KAAK,CAAA;AAAA,QACxB,CAAA,MAAA,IAAW,CAAA,CAAE,GAAA,KAAQ,OAAA,IAAW,WAAA,EAAa;AACzC,UAAA,CAAA,CAAE,cAAA,EAAe;AACjB,UAAA,gBAAA,EAAiB;AAAA,QACrB;AAAA,MACJ;AACA,MAAA,SAAA,GAAY,CAAC,CAAA;AAAA,IACjB;AAEA,IAAMA,iBAAU,MAAM;AAClB,MAAA,OAAO,MAAM;AACT,QAAA,IAAI,UAAU,OAAA,IAAW,IAAA,EAAM,MAAA,CAAO,YAAA,CAAa,UAAU,OAAO,CAAA;AAAA,MACxE,CAAA;AAAA,IACJ,CAAA,EAAG,EAAE,CAAA;AAEL,IAAA,uBACI,IAAA;AAAA,MAAC,KAAA;AAAA,MAAA;AAAA,QACG,uBAAA,EAAsB,EAAA;AAAA,QACtB,SAAA,EAAW,gBAAA;AAAA,QACX,KAAA,EAAO,EAAE,QAAA,EAAU,UAAA,EAAW;AAAA,QAE9B,QAAA,EAAA;AAAA,0BAAAC,GAAAA;AAAA,YAAC,OAAA;AAAA,YAAA;AAAA,cACI,GAAG,IAAA;AAAA,cACJ,GAAA,EAAK,MAAA;AAAA,cACL,KAAA;AAAA,cACA,UAAU,CAAC,CAAA,KAAM,aAAA,CAAc,CAAA,CAAE,OAAO,KAAK,CAAA;AAAA,cAC7C,OAAA,EAAS,WAAA;AAAA,cACT,MAAA,EAAQ,UAAA;AAAA,cACR,SAAA,EAAW,aAAA;AAAA,cACX,IAAA,EAAK,UAAA;AAAA,cACL,eAAA,EAAc,SAAA;AAAA,cACd,eAAA,EAAe,WAAA;AAAA,cACf,eAAA,EAAe,cAAc,SAAA,GAAY,MAAA;AAAA,cACzC,uBAAA,EAAuB,cAAc,QAAA,GAAW,MAAA;AAAA,cAChD,YAAA,EAAa,KAAA;AAAA,cACb,UAAA,EAAY;AAAA;AAAA,WAChB;AAAA,UACC,WAAA,IAAe,kCACZA,GAAAA;AAAA,YAAC,KAAA;AAAA,YAAA;AAAA,cACG,EAAA,EAAI,SAAA;AAAA,cACJ,IAAA,EAAK,SAAA;AAAA,cACL,yBAAA,EAAwB,EAAA;AAAA,cACxB,SAAA,EAAW,gBAAA;AAAA,cACX,KAAA,EAAO;AAAA,gBACH,QAAA,EAAU,UAAA;AAAA,gBACV,MAAA,EAAQ,EAAA;AAAA,gBACR,GAAA,EAAK,kBAAA;AAAA,gBACL,IAAA,EAAM,CAAA;AAAA,gBACN,KAAA,EAAO;AAAA,eACX;AAAA,cAEA,WAAA,EAAa,CAAC,CAAA,KAAM,CAAA,CAAE,cAAA,EAAe;AAAA,cAErC,QAAA,kBAAA,IAAA;AAAA,gBAAC,QAAA;AAAA,gBAAA;AAAA,kBACG,IAAA,EAAK,QAAA;AAAA,kBACL,EAAA,EAAI,QAAA;AAAA,kBACJ,IAAA,EAAK,QAAA;AAAA,kBACL,eAAA,EAAe,WAAA;AAAA,kBACf,4BAAA,EAA2B,EAAA;AAAA,kBAC3B,kBAAA,EAAkB,cAAc,EAAA,GAAK,MAAA;AAAA,kBACrC,SAAA,EAAW,mBAAA;AAAA,kBACX,OAAA,EAAS,gBAAA;AAAA,kBACT,YAAA,EAAc,MAAM,cAAA,CAAe,IAAI,CAAA;AAAA,kBACvC,YAAA,EAAc,MAAM,cAAA,CAAe,KAAK,CAAA;AAAA,kBACxC,KAAA,EAAO;AAAA,oBACH,OAAA,EAAS,MAAA;AAAA,oBACT,UAAA,EAAY,QAAA;AAAA,oBACZ,cAAA,EAAgB,eAAA;AAAA,oBAChB,GAAA,EAAK,SAAA;AAAA,oBACL,KAAA,EAAO,MAAA;AAAA,oBACP,SAAA,EAAW,MAAA;AAAA,oBACX,MAAA,EAAQ,SAAA;AAAA,oBACR,IAAA,EAAM,SAAA;AAAA,oBACN,UAAA,EAAY,SAAA;AAAA,oBACZ,KAAA,EAAO,SAAA;AAAA,oBACP,MAAA,EAAQ,SAAA;AAAA,oBACR,OAAA,EAAS;AAAA,mBACb;AAAA,kBAEA,QAAA,EAAA;AAAA,oCAAAA,GAAAA,CAAC,MAAA,EAAA,EAAK,kCAAA,EAAiC,EAAA,EAAI,QAAA,EAAA,eAAA,EAAgB,CAAA;AAAA,oCAC3DA,GAAAA;AAAA,sBAAC,MAAA;AAAA,sBAAA;AAAA,wBACG,kCAAA,EAAiC,EAAA;AAAA,wBACjC,KAAA,EAAO,EAAE,UAAA,EAAY,yBAAA,EAA0B;AAAA,wBAE9C,4BAAkB,cAAc;AAAA;AAAA;AACrC;AAAA;AAAA;AACJ;AAAA;AACJ;AAAA;AAAA,KAER;AAAA,EAER;AACJ;;;AC/xBO,SAAS,cAAA,CAAe,IAAA,GAA2B,EAAC,EAAS;AAChE,EAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AAC/B,IAAA,MAAM,IAAI,KAAA;AAAA,MACN;AAAA,KACJ;AAAA,EACJ;AACA,EAAA,MAAM,GAAA,GAAM,aAAA,CAAc,IAAA,CAAK,MAAM,CAAA;AACrC,EAAA,MAAM,GAAA,GAAM,IAAI,GAAA,CAAI,OAAA,EAAS,IAAI,UAAU,CAAA;AAC3C,EAAA,MAAM,QAAA,GAAW,IAAA,CAAK,QAAA,IAAY,MAAA,CAAO,QAAA,CAAS,IAAA;AAClD,EAAA,IAAI,QAAA,EAAU,GAAA,CAAI,YAAA,CAAa,GAAA,CAAI,aAAa,QAAQ,CAAA;AACxD,EAAA,IAAI,KAAK,OAAA,EAAS,GAAA,CAAI,aAAa,GAAA,CAAI,SAAA,EAAW,KAAK,OAAO,CAAA;AAC9D,EAAA,MAAA,CAAO,QAAA,CAAS,MAAA,CAAO,GAAA,CAAI,QAAA,EAAU,CAAA;AACzC;AAcO,SAAS,kBAAA,CACZ,IAAA,EACA,IAAA,GAAqE,EAAC,EAC/D;AACP,EAAA,IAAI,IAAA,IAAQ,IAAA,CAAK,MAAA,KAAW,eAAA,EAAiB;AACzC,IAAA,cAAA,CAAe,IAAI,CAAA;AACnB,IAAA,OAAO,IAAA;AAAA,EACX;AACA,EAAA,OAAO,KAAA;AACX;AAUO,IAAM,6BAAA,GACT;AAMG,SAAS,sBAAsB,IAAA,EAAuD;AACzF,EAAA,OAAO,MAAM,MAAA,KAAW,uBAAA;AAC5B;AChEA,IAAM,mBAAA,GAAsB,iBAAA;AAsC5B,eAAsB,wBAAwB,IAAA,EAEd;AAC5B,EAAA,MAAM,UAAA,GAAa,MAAM,UAAA,IAAc,mBAAA;AAMvC,EAAA,MAAM,CAAA,GAAI,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,oBAAA,CAAA,EAAwB;AAAA,IACvD,WAAA,EAAa,SAAA;AAAA,IACb,OAAA,EAAS,EAAE,GAAG,gBAAA,EAAiB;AAAE,GACpC,CAAA;AACD,EAAA,IAAI,CAAA,CAAE,MAAA,KAAW,GAAA,EAAK,OAAO,EAAC;AAC9B,EAAA,IAAI,CAAC,EAAE,EAAA,EAAI,MAAM,IAAI,KAAA,CAAM,CAAA,8BAAA,EAAiC,CAAA,CAAE,MAAM,CAAA,CAAE,CAAA;AACtE,EAAA,MAAM,IAAA,GAAQ,MAAM,CAAA,CAAE,IAAA,EAAK;AAC3B,EAAA,OAAO,IAAA,CAAK,UAAU,EAAC;AAC3B;AAaO,SAAS,kBAAA,CAAmB;AAAA,EAC/B,UAAA,GAAa,mBAAA;AAAA,EACb,SAAA;AAAA,EACA;AACJ,CAAA,EAAgD;AAC5C,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAAgC,IAAI,CAAA;AAClE,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAU,gBAAwB,IAAI,CAAA;AAC5D,EAAA,MAAM,CAAC,aAAA,EAAe,gBAAgB,CAAA,GAAU,gBAAS,KAAK,CAAA;AAC9D,EAAA,MAAM,CAAC,WAAA,EAAa,cAAc,CAAA,GAAU,gBAAS,KAAK,CAAA;AAE1D,EAAA,MAAM,OAAA,GAAgB,mBAAY,YAAY;AAC1C,IAAA,QAAA,CAAS,IAAI,CAAA;AACb,IAAA,IAAI;AACA,MAAA,MAAM,CAAA,GAAI,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,oBAAA,CAAA,EAAwB;AAAA,QACvD,WAAA,EAAa,SAAA;AAAA,QACb,OAAA,EAAS,EAAE,GAAG,gBAAA,EAAiB;AAAE,OACpC,CAAA;AACD,MAAA,IAAI,CAAC,EAAE,EAAA,EAAI;AACP,QAAA,IAAI,CAAA,CAAE,WAAW,GAAA,EAAK;AAClB,UAAA,QAAA,CAAS,eAAe,CAAA;AACxB,UAAA;AAAA,QACJ;AACA,QAAA,MAAM,IAAI,KAAA,CAAM,CAAA,KAAA,EAAQ,CAAA,CAAE,MAAM,CAAA,CAAE,CAAA;AAAA,MACtC;AACA,MAAA,OAAA,CAAS,MAAM,CAAA,CAAE,IAAA,EAAyB,CAAA;AAAA,IAC9C,SAAS,CAAA,EAAG;AACR,MAAA,QAAA,CAAS,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,aAAa,CAAA;AAAA,IAC3D;AAAA,EACJ,CAAA,EAAG,CAAC,UAAU,CAAC,CAAA;AAEf,EAAM,iBAAU,MAAM;AAClB,IAAA,KAAK,OAAA,EAAQ;AAAA,EACjB,CAAA,EAAG,CAAC,OAAO,CAAC,CAAA;AAEZ,EAAA,MAAM,WAAA,GAAoB,mBAAY,MAAM;AACxC,IAAA,gBAAA,CAAiB,KAAK,CAAA;AACtB,IAAA,cAAA,CAAe,KAAK,CAAA;AACpB,IAAA,KAAK,OAAA,EAAQ;AACb,IAAA,QAAA,IAAW;AAAA,EACf,CAAA,EAAG,CAAC,OAAA,EAAS,QAAQ,CAAC,CAAA;AAEtB,EAAA,IAAI,KAAA,EAAO;AACP,IAAA,uBACIE,IAAAA,CAAC,KAAA,EAAA,EAAI,SAAA,EAAsB,YAAA,EAAW,EAAA,EAAG,KAAA,EAAO,UAAA,CAAW,MAAM,CAAA,EAAG,IAAA,EAAK,OAAA,EACrE,QAAA,EAAA;AAAA,sBAAAF,GAAAA,CAAC,YAAA,EAAA,EAAa,IAAA,EAAK,MAAA,EAAO,QAAA,EAAA,oCAAA,EAA4B,CAAA;AAAA,sBACtDE,IAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,SAAA,EAAW,QAAA,EAAA;AAAA,QAAA,gCAAA;AAAA,QACmB,KAAA;AAAA,QAAM;AAAA,OAAA,EAE9C,CAAA;AAAA,sBACAF,GAAAA,CAAC,QAAA,EAAA,EAAO,IAAA,EAAK,UAAS,OAAA,EAAS,MAAM,KAAK,OAAA,EAAQ,EAAG,KAAA,EAAO,aAAA,CAAc,KAAK,GAAG,QAAA,EAAA,OAAA,EAElF;AAAA,KAAA,EACJ,CAAA;AAAA,EAER;AAEA,EAAA,IAAI,CAAC,IAAA,EAAM;AACP,IAAA,uBACIA,GAAAA,CAAC,KAAA,EAAA,EAAI,SAAA,EAAsB,YAAA,EAAW,EAAA,EAAG,KAAA,EAAO,UAAA,EAAW,EACvD,QAAA,kBAAAE,IAAAA,CAAC,MAAA,EAAA,EAAK,OAAO,SAAA,EAAY,QAAA,EAAA;AAAA,MAAA,IAAA;AAAA,MAAK;AAAA,KAAA,EAAQ,CAAA,EAC1C,CAAA;AAAA,EAER;AAEA,EAAA,MAAM,MAAA,GAAS,IAAA,CAAK,MAAA,IAAU,EAAC;AAC/B,EAAA,MAAM,YAAY,MAAA,CAAO,MAAA,CAAO,CAAC,CAAA,KAAM,CAAA,CAAE,SAAS,OAAO,CAAA;AACzD,EAAA,MAAM,UAAU,MAAA,CAAO,MAAA,CAAO,CAAC,CAAA,KAAM,CAAA,CAAE,SAAS,KAAK,CAAA;AACrD,EAAA,MAAM,WAAW,SAAA,CAAU,IAAA,CAAK,CAAC,CAAA,KAAM,EAAE,KAAK,CAAA;AAC9C,EAAA,MAAM,SAAS,OAAA,CAAQ,IAAA,CAAK,CAAC,CAAA,KAAM,EAAE,KAAK,CAAA;AAC1C,EAAA,MAAM,UAAA,GAAa,IAAA,CAAK,WAAA,IAAe,EAAC;AAExC,EAAA,uBACIA,IAAAA,CAAC,KAAA,EAAA,EAAI,SAAA,EAAsB,YAAA,EAAW,EAAA,EAAG,KAAA,EAAO,EAAE,OAAA,EAAS,MAAA,EAAQ,GAAA,EAAK,EAAA,EAAG,EACvE,QAAA,EAAA;AAAA,oBAAAA,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,UAAA,EAAW,EACnB,QAAA,EAAA;AAAA,sBAAAF,GAAAA,CAAC,gBAAa,QAAA,EAAA,mBAAA,EAAc,CAAA;AAAA,sBAC5BE,IAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,SAAA,EAAW,QAAA,EAAA;AAAA,QAAA,qCAAA;AAAA,wBACkBF,GAAAA,CAAC,MAAA,EAAA,EAAK,KAAA,EAAO,WAAW,QAAA,EAAA,SAAA,EAAO,CAAA;AAAA,QAAO;AAAA,OAAA,EAK7E;AAAA,KAAA,EACJ,CAAA;AAAA,IAEC,WAAW,MAAA,GAAS,CAAA,oBAAKA,GAAAA,CAAC,kBAAA,EAAA,EAAmB,SAAS,UAAA,EAAY,CAAA;AAAA,oBAEnEE,KAAC,KAAA,EAAA,EAAI,KAAA,EAAO,WAAW,OAAO,CAAA,EAAG,mBAAgB,EAAA,EAC7C,QAAA,EAAA;AAAA,sBAAAF,GAAAA;AAAA,QAAC,aAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,OAAA;AAAA,UACL,KAAA,EAAM,OAAA;AAAA,UACN,IAAA,EAAM,SAAA;AAAA,UACN,UAAA;AAAA,UACA,QAAA,EAAU,WAAA;AAAA,UACV,MAAA,EAAQ,WAAW,IAAA,GAAO,eAAA;AAAA,UAC1B,OAAO,MAAM;AACT,YAAA,gBAAA,CAAiB,CAAC,CAAA,KAAM,CAAC,CAAC,CAAA;AAC1B,YAAA,cAAA,CAAe,KAAK,CAAA;AAAA,UACxB;AAAA;AAAA,OACJ;AAAA,sBACAA,GAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,EAAE,WAAW,CAAA,UAAA,EAAa,CAAA,CAAE,MAAM,CAAA,CAAA,EAAG,EAAG,CAAA;AAAA,sBACpDA,GAAAA;AAAA,QAAC,aAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,KAAA;AAAA,UACL,KAAA,EAAM,iBAAA;AAAA,UACN,IAAA,EAAM,OAAA;AAAA,UACN,UAAA;AAAA,UACA,QAAA,EAAU,WAAA;AAAA,UACV,MAAA,EAAQ,SAAS,IAAA,GAAO,wBAAA;AAAA,UACxB,OAAO,MAAM;AACT,YAAA,cAAA,CAAe,CAAC,CAAA,KAAM,CAAC,CAAC,CAAA;AACxB,YAAA,gBAAA,CAAiB,KAAK,CAAA;AAAA,UAC1B;AAAA;AAAA;AACJ,KAAA,EACJ,CAAA;AAAA,IAEC,iCACGA,GAAAA;AAAA,MAAC,aAAA;AAAA,MAAA;AAAA,QACG,UAAA;AAAA,QACA,MAAA,EAAQ,WAAA;AAAA,QACR,QAAA,EAAU,MAAM,gBAAA,CAAiB,KAAK;AAAA;AAAA,KAC1C;AAAA,IAEH,+BACGA,GAAAA;AAAA,MAAC,WAAA;AAAA,MAAA;AAAA,QACG,UAAA;AAAA,QACA,KAAA,EAAO,KAAK,MAAA,IAAU,IAAA;AAAA,QACtB,MAAA,EAAQ,WAAA;AAAA,QACR,QAAA,EAAU,MAAM,cAAA,CAAe,KAAK;AAAA;AAAA,KACxC;AAAA,IAGH,MAAA,oBAAUA,GAAAA,CAAC,eAAA,EAAA,EAAgB;AAAA,GAAA,EAChC,CAAA;AAER;AAIA,SAAS,aAAA,CAAc;AAAA,EACnB,IAAA;AAAA,EACA,KAAA;AAAA,EACA,IAAA;AAAA,EACA,UAAA;AAAA,EACA,QAAA;AAAA,EACA,MAAA;AAAA,EACA;AACJ,CAAA,EAQuB;AACnB,EAAA,IAAI,IAAA,CAAK,WAAW,CAAA,EAAG;AACnB,IAAA,uBACIE,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,QAAA,EACR,QAAA,EAAA;AAAA,sBAAAA,KAAC,KAAA,EAAA,EACG,QAAA,EAAA;AAAA,wBAAAA,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,aAAA,EAAe,QAAA,EAAA;AAAA,UAAA,OAAA;AAAA,UAAG;AAAA,SAAA,EAAM,CAAA;AAAA,wBACpCF,GAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,EAAE,GAAG,SAAA,EAAW,SAAA,EAAW,CAAA,EAAE,EAAG,QAAA,EAAA,aAAA,EAAW;AAAA,OAAA,EAC3D,CAAA;AAAA,MACC,MAAA,oBACGE,IAAAA,CAAC,QAAA,EAAA,EAAO,MAAK,QAAA,EAAS,OAAA,EAAS,KAAA,EAAO,KAAA,EAAO,gBAAA,EAAkB,QAAA,EAAA;AAAA,QAAA,IAAA;AAAA,QACxD;AAAA,OAAA,EACP;AAAA,KAAA,EAER,CAAA;AAAA,EAER;AACA,EAAA,uBACIF,GAAAA,CAAA,QAAA,EAAA,EACK,eAAK,GAAA,CAAI,CAAC,sBACPA,GAAAA;AAAA,IAAC,WAAA;AAAA,IAAA;AAAA,MAEG,GAAA,EAAK,CAAA;AAAA,MACL,IAAA;AAAA,MACA,UAAA;AAAA,MACA;AAAA,KAAA;AAAA,IAJK,CAAA,CAAE;AAAA,GAMd,CAAA,EACL,CAAA;AAER;AAIA,SAAS,WAAA,CAAY;AAAA,EACjB,GAAA;AAAA,EACA,IAAA;AAAA,EACA,UAAA;AAAA,EACA;AACJ,CAAA,EAKuB;AACnB,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAU,gBAAS,KAAK,CAAA;AAC9C,EAAA,MAAM,CAAC,UAAA,EAAY,aAAa,CAAA,GAAU,gBAAS,KAAK,CAAA;AACxD,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAAS,KAAK,CAAA;AAC5C,EAAA,MAAM,CAAC,GAAA,EAAK,MAAM,CAAA,GAAU,gBAAwB,IAAI,CAAA;AAExD,EAAA,MAAM,SAAS,GAAA,CAAI,KAAA,GAAQ,KAAK,GAAA,CAAI,KAAA,EAAO,IAAI,CAAA,GAAI,gCAAA;AACnD,EAAA,MAAM,OAAA,GAAU,KAAA,IAAS,GAAA,CAAI,KAAA,GAAQ,IAAI,KAAA,GAAQ,MAAA;AAEjD,EAAA,eAAe,MAAA,GAAwB;AACnC,IAAA,IAAI,IAAI,UAAA,EAAY;AACpB,IAAA,OAAA,CAAQ,IAAI,CAAA;AACZ,IAAA,MAAA,CAAO,IAAI,CAAA;AACX,IAAA,IAAI;AACA,MAAA,MAAM,IAAI,MAAM,KAAA;AAAA,QACZ,GAAG,UAAU,CAAA,wBAAA,EAA2B,kBAAA,CAAmB,GAAA,CAAI,EAAE,CAAC,CAAA,CAAA;AAAA,QAClE,EAAE,MAAA,EAAQ,QAAA,EAAU,WAAA,EAAa,SAAA;AAAU,OAC/C;AACA,MAAA,IAAI,CAAC,EAAE,EAAA,EAAI;AACP,QAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,GAAO,KAAA,CAAM,OAAO,EAAC,CAAE,CAAA;AAC1C,QAAA,MAAM,IAAI,KAAA,CAAM,CAAA,CAAE,UAAU,CAAA,KAAA,EAAQ,CAAA,CAAE,MAAM,CAAA,CAAE,CAAA;AAAA,MAClD;AACA,MAAA,QAAA,EAAS;AAAA,IACb,SAAS,CAAA,EAAG;AACR,MAAA,MAAA,CAAO,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,eAAe,CAAA;AACvD,MAAA,OAAA,CAAQ,KAAK,CAAA;AACb,MAAA,aAAA,CAAc,KAAK,CAAA;AAAA,IACvB;AAAA,EACJ;AAEA,EAAA,uBACIE,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,QAAA,EAAU,kBAAgB,IAAA,EAClC,QAAA,EAAA;AAAA,oBAAAA,IAAAA,CAAC,SAAI,KAAA,EAAO,EAAE,UAAU,CAAA,EAAG,IAAA,EAAM,GAAE,EAC/B,QAAA,EAAA;AAAA,sBAAAA,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,EAAE,OAAA,EAAS,QAAQ,QAAA,EAAU,MAAA,EAAQ,GAAA,EAAK,UAAA,EAAW,EAC7D,QAAA,EAAA;AAAA,wBAAAA,IAAAA,CAAC,MAAA,EAAA,EAAK,KAAA,EAAO,aAAA,EAAe,QAAA,EAAA;AAAA,UAAA,OAAA;AAAA,UACrB,IAAA,KAAS,UAAU,OAAA,GAAU;AAAA,SAAA,EACpC,CAAA;AAAA,QACC,GAAA,CAAI,UAAA,oBACDF,GAAAA,CAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,GAAG,aAAA,EAAe,KAAA,EAAO,CAAA,CAAE,OAAA,IAAW,QAAA,EAAA,0BAAA,EAErD;AAAA,OAAA,EAER,CAAA;AAAA,sBACAA,GAAAA;AAAA,QAAC,KAAA;AAAA,QAAA;AAAA,UACG,KAAA,EAAO;AAAA,YACH,SAAA,EAAW,CAAA;AAAA,YACX,OAAO,CAAA,CAAE,UAAA;AAAA,YACT,UAAA,EAAY,IAAA;AAAA,YACZ,QAAA,EAAU,EAAA;AAAA,YACV,SAAA,EAAW;AAAA,WACf;AAAA,UAEC,QAAA,EAAA;AAAA;AAAA,OACL;AAAA,MACC,GAAA,CAAI,WAAA,oBACDE,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,EAAE,GAAG,SAAA,EAAW,SAAA,EAAW,CAAA,EAAE,EAAG,QAAA,EAAA;AAAA,QAAA,gBAAA;AAAA,QAC5B,IAAI,IAAA,CAAK,GAAA,CAAI,WAAW,EAAE,WAAA;AAAY,OAAA,EACtD,CAAA;AAAA,MAEH,GAAA,oBAAOF,GAAAA,CAAC,SAAA,EAAA,EAAW,QAAA,EAAA,GAAA,EAAI;AAAA,KAAA,EAC5B,CAAA;AAAA,oBACAE,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,EAAE,OAAA,EAAS,MAAA,EAAQ,UAAA,EAAY,CAAA,EAAG,GAAA,EAAK,CAAA,EAAG,QAAA,EAAU,QAAO,EAClE,QAAA,EAAA;AAAA,MAAA,GAAA,CAAI,yBACDF,GAAAA;AAAA,QAAC,QAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,QAAA;AAAA,UACL,SAAS,MAAM,QAAA,CAAS,CAAC,CAAA,KAAM,CAAC,CAAC,CAAA;AAAA,UACjC,KAAA,EAAO,cAAc,KAAK,CAAA;AAAA,UAEzB,kBAAQ,MAAA,GAAS;AAAA;AAAA,OACtB;AAAA,MAEH,CAAC,GAAA,CAAI,UAAA,IAAc,CAAC,8BACjBA,GAAAA;AAAA,QAAC,QAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,QAAA;AAAA,UACL,OAAA,EAAS,MAAM,aAAA,CAAc,IAAI,CAAA;AAAA,UACjC,KAAA,EAAO,eAAe,KAAK,CAAA;AAAA,UAC9B,QAAA,EAAA;AAAA;AAAA,OAED;AAAA,MAEH,CAAC,GAAA,CAAI,UAAA,IAAc,UAAA,oBAChBE,KAAA,QAAA,EAAA,EACI,QAAA,EAAA;AAAA,wBAAAF,GAAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,OAAA,EAAS,MAAM,KAAK,MAAA,EAAO;AAAA,YAC3B,QAAA,EAAU,IAAA;AAAA,YACV,KAAA,EAAO,eAAe,IAAI,CAAA;AAAA,YAEzB,iBAAO,iBAAA,GAAe;AAAA;AAAA,SAC3B;AAAA,wBACAA,GAAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,OAAA,EAAS,MAAM,aAAA,CAAc,KAAK,CAAA;AAAA,YAClC,QAAA,EAAU,IAAA;AAAA,YACV,KAAA,EAAO,cAAc,IAAI,CAAA;AAAA,YAC5B,QAAA,EAAA;AAAA;AAAA;AAED,OAAA,EACJ;AAAA,KAAA,EAER;AAAA,GAAA,EACJ,CAAA;AAER;AAIA,SAAS,kBAAA,CAAmB,EAAE,OAAA,EAAQ,EAAuD;AACzF,EAAA,uBACIE,KAAC,KAAA,EAAA,EAAI,KAAA,EAAO,WAAW,SAAS,CAAA,EAAG,2BAAwB,EAAA,EACvD,QAAA,EAAA;AAAA,oBAAAA,IAAAA,CAAC,YAAA,EAAA,EAAa,IAAA,EAAK,SAAA,EAAU,QAAA,EAAA;AAAA,MAAA,kCAAA;AAAA,MACE,OAAA,CAAQ;AAAA,KAAA,EACvC,CAAA;AAAA,oBACAA,IAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,SAAA,EACL,QAAA,EAAA;AAAA,MAAA,OAAA,CAAQ,MAAA,KAAW,IAAI,uBAAA,GAA0B,sBAAA;AAAA,MAAuB,wIAAA;AAAA,MAEpB,GAAA;AAAA,MACpD,OAAA,CAAQ,MAAA,KAAW,CAAA,GAAI,IAAA,GAAO,MAAA;AAAA,MAAO;AAAA,KAAA,EAC1C,CAAA;AAAA,oBACAF,GAAAA,CAAC,IAAA,EAAA,EAAG,KAAA,EAAO,EAAE,WAAW,MAAA,EAAQ,MAAA,EAAQ,UAAA,EAAY,OAAA,EAAS,GAAE,EAC1D,QAAA,EAAA,OAAA,CAAQ,GAAA,CAAI,CAAC,sBACVE,IAAAA;AAAA,MAAC,IAAA;AAAA,MAAA;AAAA,QAEG,KAAA,EAAO;AAAA,UACH,OAAA,EAAS,MAAA;AAAA,UACT,QAAA,EAAU,MAAA;AAAA,UACV,GAAA,EAAK,CAAA;AAAA,UACL,OAAA,EAAS,OAAA;AAAA,UACT,SAAA,EAAW,CAAA,UAAA,EAAa,CAAA,CAAE,MAAM,CAAA,CAAA;AAAA,UAChC,UAAA,EAAY,IAAA;AAAA,UACZ,QAAA,EAAU;AAAA,SACd;AAAA,QAEA,QAAA,EAAA;AAAA,0BAAAF,GAAAA,CAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,KAAA,EAAO,CAAA,CAAE,UAAA,EAAY,SAAA,EAAW,WAAA,EAAY,EACtD,QAAA,EAAA,CAAA,CAAE,MAAA,EACP,CAAA;AAAA,0BACAE,KAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,GAAG,SAAA,EAAW,UAAA,EAAY,MAAA,EAAO,EAAG,QAAA,EAAA;AAAA,YAAA,UAAA;AAAA,YACtC,IAAI,IAAA,CAAK,CAAA,CAAE,UAAU,EAAE,kBAAA;AAAmB,WAAA,EACvD;AAAA;AAAA,OAAA;AAAA,MAhBK,CAAA,CAAE;AAAA,KAkBd,CAAA,EACL;AAAA,GAAA,EACJ,CAAA;AAER;AAaA,SAAS,eAAA,GAAsC;AAC3C,EAAA,uBACIA,IAAAA,CAAC,KAAA,EAAA,EAAI,OAAO,UAAA,EAAW,EAAG,qBAAkB,EAAA,EACxC,QAAA,EAAA;AAAA,oBAAAF,GAAAA,CAAC,gBAAa,QAAA,EAAA,2BAAA,EAAsB,CAAA;AAAA,oBACpCA,GAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,WAAW,QAAA,EAAA,oSAAA,EAKrB,CAAA;AAAA,oBACAA,GAAAA;AAAA,MAAC,GAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,+BAAA;AAAA,QACL,MAAA,EAAO,QAAA;AAAA,QACP,GAAA,EAAI,YAAA;AAAA,QACJ,OAAO,EAAE,GAAG,kBAAkB,cAAA,EAAgB,MAAA,EAAQ,SAAS,cAAA,EAAe;AAAA,QAC9E,wBAAA,EAAuB,EAAA;AAAA,QAC1B,QAAA,EAAA;AAAA;AAAA;AAED,GAAA,EACJ,CAAA;AAER;AAgBO,SAAS,cAAA,CAAe;AAAA,EAC3B,MAAA;AAAA,EACA,KAAA;AAAA,EACA,UAAA;AAAA,EACA;AACJ,CAAA,EAOuB;AACnB,EAAA,MAAM,IAAA,GAAO,MAAA,KAAW,KAAA,GAAQ,mBAAA,GAAsB,UAAA;AACtD,EAAA,uBACIE,IAAAA,CAAC,KAAA,EAAA,EAAI,oBAAA,EAAoB,MAAA,EACrB,QAAA,EAAA;AAAA,oBAAAA,IAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,EAAE,GAAG,WAAW,SAAS,CAAA,EAAG,YAAA,EAAc,EAAA,EAAG,EACrD,QAAA,EAAA;AAAA,sBAAAF,GAAAA,CAAC,YAAA,EAAA,EAAa,IAAA,EAAK,SAAA,EAAU,QAAA,EAAA,gBAAA,EAAW,CAAA;AAAA,sBACxCE,KAAC,GAAA,EAAA,EAAE,KAAA,EAAO,EAAE,GAAG,SAAA,EAAW,MAAA,EAAQ,CAAA,EAAE,EAAG,QAAA,EAAA;AAAA,QAAA,yBAAA;AAAA,QACX,IAAA;AAAA,QAAK;AAAA,OAAA,EAEjC;AAAA,KAAA,EACJ,CAAA;AAAA,IACC,MAAA,KAAW,wBACRF,GAAAA;AAAA,MAAC,WAAA;AAAA,MAAA;AAAA,QACG,UAAA;AAAA,QACA,KAAA;AAAA,QACA,MAAA,EAAQ,UAAA;AAAA,QACR,QAAA,EAAU;AAAA;AAAA,KACd,mBAEAA,GAAAA,CAAC,aAAA,EAAA,EAAc,YAAwB,MAAA,EAAQ,UAAA,EAAY,UAAU,UAAA,EAAY,CAAA;AAAA,oBAErFE,IAAAA;AAAA,MAAC,KAAA;AAAA,MAAA;AAAA,QACG,yBAAA,EAAwB,EAAA;AAAA,QACxB,KAAA,EAAO,EAAE,SAAA,EAAW,EAAA,EAAI,UAAA,EAAY,IAAI,SAAA,EAAW,CAAA,UAAA,EAAa,CAAA,CAAE,MAAM,CAAA,CAAA,EAAG;AAAA,QAE3E,QAAA,EAAA;AAAA,0BAAAF,GAAAA,CAAC,QAAA,EAAA,EAAO,IAAA,EAAK,QAAA,EAAS,OAAA,EAAS,YAAY,KAAA,EAAO,aAAA,CAAc,KAAK,CAAA,EAAG,QAAA,EAAA,gCAAA,EAExE,CAAA;AAAA,0BACAE,KAAC,GAAA,EAAA,EAAE,KAAA,EAAO,EAAE,GAAG,SAAA,EAAW,SAAA,EAAW,CAAA,EAAE,EAClC,QAAA,EAAA;AAAA,YAAA,IAAA;AAAA,YAAK,wGAAA;AAAA,YACoB,IAAA;AAAA,YAAK,yCAAA;AAAA,YAAwC,GAAA;AAAA,YAAI;AAAA,WAAA,EAE/E;AAAA;AAAA;AAAA;AACJ,GAAA,EACJ,CAAA;AAER;AAIA,SAAS,aAAA,CAAc;AAAA,EACnB,UAAA;AAAA,EACA,MAAA;AAAA,EACA;AACJ,CAAA,EAIuB;AACnB,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAA2B,OAAO,CAAA;AAChE,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAU,gBAAS,EAAE,CAAA;AAC3C,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAAS,EAAE,CAAA;AACzC,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAU,gBAAS,EAAE,CAAA;AAC3C,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAAS,KAAK,CAAA;AAC5C,EAAA,MAAM,CAAC,GAAA,EAAK,MAAM,CAAA,GAAU,gBAAwB,IAAI,CAAA;AAGxD,EAAA,MAAM,CAAC,QAAA,EAAU,WAAW,CAAA,GAAU,gBAAS,KAAK,CAAA;AAEpD,EAAA,eAAe,KAAA,GAAuB;AAClC,IAAA,OAAA,CAAQ,IAAI,CAAA;AACZ,IAAA,MAAA,CAAO,IAAI,CAAA;AACX,IAAA,IAAI;AACA,MAAA,MAAM,CAAA,GAAI,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,yBAAA,CAAA,EAA6B;AAAA,QAC5D,MAAA,EAAQ,MAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,QAC9C,IAAA,EAAM,IAAA,CAAK,SAAA,CAAU,EAAE,KAAA,EAAO,MAAM,IAAA,EAAK,CAAE,WAAA,EAAY,EAAG;AAAA,OAC7D,CAAA;AACD,MAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,EAAK;AACxB,MAAA,IAAI,CAAC,CAAA,CAAE,EAAA,IAAM,CAAC,EAAE,KAAA,EAAO,MAAM,IAAI,KAAA,CAAM,CAAA,CAAE,MAAA,IAAU,CAAA,KAAA,EAAQ,CAAA,CAAE,MAAM,CAAA,CAAE,CAAA;AACrE,MAAA,QAAA,CAAS,EAAE,KAAK,CAAA;AAChB,MAAA,OAAA,CAAQ,MAAM,CAAA;AAAA,IAClB,SAAS,CAAA,EAAG;AACR,MAAA,MAAA,CAAO,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,qBAAqB,CAAA;AAAA,IACjE,CAAA,SAAE;AACE,MAAA,OAAA,CAAQ,KAAK,CAAA;AAAA,IACjB;AAAA,EACJ;AAEA,EAAA,eAAe,OAAO,eAAA,EAAyC;AAC3D,IAAA,OAAA,CAAQ,IAAI,CAAA;AACZ,IAAA,MAAA,CAAO,IAAI,CAAA;AACX,IAAA,IAAI;AACA,MAAA,MAAM,CAAA,GAAI,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,oBAAA,CAAA,EAAwB;AAAA,QACvD,MAAA,EAAQ,MAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,QAC9C,IAAA,EAAM,KAAK,SAAA,CAAU;AAAA,UACjB,KAAA,EAAO,KAAA,CAAM,IAAA,EAAK,CAAE,WAAA,EAAY;AAAA,UAChC,IAAA,EAAM,KAAK,IAAA,EAAK;AAAA,UAChB,KAAA;AAAA,UACA,GAAI,eAAA,GAAkB,EAAE,gBAAA,EAAkB,IAAA,KAAS;AAAC,SACvD;AAAA,OACJ,CAAA;AACD,MAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,EAAK;AACxB,MAAA,IAAI,CAAA,CAAE,MAAA,KAAW,GAAA,IAAO,CAAA,CAAE,WAAW,wBAAA,EAA0B;AAC3D,QAAA,WAAA,CAAY,IAAI,CAAA;AAChB,QAAA,OAAA,CAAQ,KAAK,CAAA;AACb,QAAA;AAAA,MACJ;AACA,MAAA,IAAI,mBAAmB,CAAA,EAAG,EAAE,OAAA,EAAS,eAAA,EAAiB,CAAA,EAAG;AACzD,MAAA,IAAI,qBAAA,CAAsB,CAAC,CAAA,EAAG;AAC1B,QAAA,MAAA,CAAO,6BAA6B,CAAA;AACpC,QAAA,OAAA,CAAQ,KAAK,CAAA;AACb,QAAA;AAAA,MACJ;AACA,MAAA,IAAI,CAAC,CAAA,CAAE,EAAA,IAAM,CAAC,EAAE,EAAA,EAAI,MAAM,IAAI,KAAA,CAAM,CAAA,CAAE,MAAA,IAAU,CAAA,KAAA,EAAQ,CAAA,CAAE,MAAM,CAAA,CAAE,CAAA;AAClE,MAAA,MAAA,EAAO;AAAA,IACX,SAAS,CAAA,EAAG;AACR,MAAA,MAAA,CAAO,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,aAAa,CAAA;AACrD,MAAA,OAAA,CAAQ,KAAK,CAAA;AAAA,IACjB;AAAA,EACJ;AAEA,EAAA,uBACIA,KAAC,KAAA,EAAA,EAAI,KAAA,EAAO,WAAW,QAAQ,CAAA,EAAG,mBAAgB,OAAA,EAC9C,QAAA,EAAA;AAAA,oBAAAF,GAAAA,CAAC,gBAAa,QAAA,EAAA,oBAAA,EAAe,CAAA;AAAA,IAC5B,IAAA,KAAS,OAAA,mBACNE,IAAAA,CAAA,QAAA,EAAA,EACI,QAAA,EAAA;AAAA,sBAAAF,GAAAA;AAAA,QAAC,OAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,OAAA;AAAA,UACL,YAAA,EAAa,OAAA;AAAA,UACb,KAAA,EAAO,KAAA;AAAA,UACP,UAAU,CAAC,CAAA,KAAM,QAAA,CAAS,CAAA,CAAE,OAAO,KAAK,CAAA;AAAA,UACxC,WAAA,EAAY,iBAAA;AAAA,UACZ,KAAA,EAAO;AAAA;AAAA,OACX;AAAA,MACC,GAAA,oBAAOA,GAAAA,CAAC,SAAA,EAAA,EAAW,QAAA,EAAA,GAAA,EAAI,CAAA;AAAA,sBACxBE,KAAC,WAAA,EAAA,EACG,QAAA,EAAA;AAAA,wBAAAF,GAAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,OAAA,EAAS,MAAM,KAAK,KAAA,EAAM;AAAA,YAC1B,QAAA,EAAU,IAAA,IAAQ,KAAA,CAAM,IAAA,GAAO,MAAA,GAAS,CAAA;AAAA,YACxC,OAAO,eAAA,CAAgB,IAAA,IAAQ,MAAM,IAAA,EAAK,CAAE,SAAS,CAAC,CAAA;AAAA,YAErD,iBAAO,eAAA,GAAa;AAAA;AAAA,SACzB;AAAA,wBACAA,GAAAA,CAAC,QAAA,EAAA,EAAO,IAAA,EAAK,QAAA,EAAS,OAAA,EAAS,QAAA,EAAU,KAAA,EAAO,aAAA,CAAc,IAAI,CAAA,EAAG,QAAA,EAAA,QAAA,EAErE;AAAA,OAAA,EACJ;AAAA,KAAA,EACJ,CAAA,GACA,2BACAA,GAAAA;AAAA,MAAC,eAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,OAAA;AAAA,QACL,IAAA;AAAA,QACA,SAAA,EAAW,MAAM,KAAK,MAAA,CAAO,IAAI,CAAA;AAAA,QACjC,QAAA;AAAA,QACA;AAAA;AAAA,KACJ,mBAEAE,IAAAA,CAAA,QAAA,EAAA,EACI,QAAA,EAAA;AAAA,sBAAAA,IAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,SAAA,EAAW,QAAA,EAAA;AAAA,QAAA,iCAAA;AAAA,QAAgC,KAAA;AAAA,QAAM;AAAA,OAAA,EAAC,CAAA;AAAA,sBAC5DF,GAAAA;AAAA,QAAC,OAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,MAAA;AAAA,UACL,SAAA,EAAU,SAAA;AAAA,UACV,YAAA,EAAa,eAAA;AAAA,UACb,SAAA,EAAW,CAAA;AAAA,UACX,KAAA,EAAO,IAAA;AAAA,UACP,QAAA,EAAU,CAAC,CAAA,KAAM,OAAA,CAAQ,EAAE,MAAA,CAAO,KAAA,CAAM,OAAA,CAAQ,KAAA,EAAO,EAAE,CAAA,CAAE,KAAA,CAAM,CAAA,EAAG,CAAC,CAAC,CAAA;AAAA,UACtE,WAAA,EAAY,QAAA;AAAA,UACZ,KAAA,EAAO,EAAE,GAAG,UAAA,EAAY,eAAe,OAAA;AAAQ;AAAA,OACnD;AAAA,MACC,GAAA,oBAAOA,GAAAA,CAAC,SAAA,EAAA,EAAW,QAAA,EAAA,GAAA,EAAI,CAAA;AAAA,sBACxBE,KAAC,WAAA,EAAA,EACG,QAAA,EAAA;AAAA,wBAAAF,GAAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,OAAA,EAAS,MAAM,KAAK,MAAA,CAAO,KAAK,CAAA;AAAA,YAChC,QAAA,EAAU,IAAA,IAAQ,IAAA,CAAK,MAAA,KAAW,CAAA;AAAA,YAClC,KAAA,EAAO,eAAA,CAAgB,IAAA,IAAQ,IAAA,CAAK,WAAW,CAAC,CAAA;AAAA,YAE/C,iBAAO,eAAA,GAAa;AAAA;AAAA,SACzB;AAAA,wBACAA,GAAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,OAAA,EAAS,MAAM,OAAA,CAAQ,OAAO,CAAA;AAAA,YAC9B,QAAA,EAAU,IAAA;AAAA,YACV,KAAA,EAAO,cAAc,IAAI,CAAA;AAAA,YAC5B,QAAA,EAAA;AAAA;AAAA;AAED,OAAA,EACJ;AAAA,KAAA,EACJ;AAAA,GAAA,EAER,CAAA;AAER;AAIA,SAAS,WAAA,CAAY;AAAA,EACjB,UAAA;AAAA,EACA,KAAA;AAAA,EACA,MAAA;AAAA,EACA;AACJ,CAAA,EAKuB;AACnB,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAA6B,SAAS,CAAA;AACpE,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAAS,EAAE,CAAA;AACzC,EAAA,MAAM,CAAC,SAAA,EAAW,YAAY,CAAA,GAAU,gBAAS,EAAE,CAAA;AACnD,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAAS,KAAK,CAAA;AAC5C,EAAA,MAAM,CAAC,GAAA,EAAK,MAAM,CAAA,GAAU,gBAAwB,IAAI,CAAA;AAGxD,EAAA,MAAM,CAAC,UAAA,EAAY,aAAa,CAAA,GAAU,gBAAwB,IAAI,CAAA;AAEtE,EAAA,eAAe,YAAA,GAA8B;AACzC,IAAA,IAAI,CAAC,KAAA,EAAO;AACR,MAAA,MAAA,CAAO,+CAA4C,CAAA;AACnD,MAAA;AAAA,IACJ;AACA,IAAA,OAAA,CAAQ,IAAI,CAAA;AACZ,IAAA,MAAA,CAAO,IAAI,CAAA;AACX,IAAA,IAAI;AAKA,MAAA,MAAM,IAAI,MAAM,KAAA;AAAA,QACZ,CAAA,EAAG,UAAU,CAAA,oBAAA,EAAuB,kBAAA,CAAmB,IAAI,CAAC,CAAA,uBAAA,EAC9B,kBAAA,CAAmB,KAAK,CAAC,CAAA;AAAA,OAC3D;AACA,MAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,EAAK;AACxB,MAAA,IAAI,CAAC,CAAA,CAAE,EAAA,IAAM,CAAC,EAAE,OAAA,EAAS,MAAM,IAAI,KAAA,CAAM,CAAA,CAAE,MAAA,IAAU,CAAA,KAAA,EAAQ,CAAA,CAAE,MAAM,CAAA,CAAE,CAAA;AACvE,MAAA,YAAA,CAAa,EAAE,OAAO,CAAA;AACtB,MAAA,OAAA,CAAQ,MAAM,CAAA;AAAA,IAClB,SAAS,CAAA,EAAG;AACR,MAAA,MAAA,CAAO,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,kBAAkB,CAAA;AAAA,IAC9D,CAAA,SAAE;AACE,MAAA,OAAA,CAAQ,KAAK,CAAA;AAAA,IACjB;AAAA,EACJ;AAEA,EAAA,eAAe,QAAA,CAAS,KAAa,eAAA,EAAyC;AAC1E,IAAA,OAAA,CAAQ,IAAI,CAAA;AACZ,IAAA,MAAA,CAAO,IAAI,CAAA;AACX,IAAA,IAAI;AACA,MAAA,MAAM,CAAA,GAAI,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,kBAAA,CAAA,EAAsB;AAAA,QACrD,MAAA,EAAQ,MAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,QAC9C,IAAA,EAAM,KAAK,SAAA,CAAU;AAAA,UACjB,OAAA,EAAS,SAAA;AAAA,UACT,SAAA,EAAW,GAAA;AAAA,UACX,GAAI,eAAA,GAAkB,EAAE,gBAAA,EAAkB,IAAA,KAAS;AAAC,SACvD;AAAA,OACJ,CAAA;AACD,MAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,EAAK;AACxB,MAAA,IAAI,CAAA,CAAE,MAAA,KAAW,GAAA,IAAO,CAAA,CAAE,WAAW,0BAAA,EAA4B;AAC7D,QAAA,aAAA,CAAc,GAAG,CAAA;AACjB,QAAA,OAAA,CAAQ,KAAK,CAAA;AACb,QAAA;AAAA,MACJ;AACA,MAAA,IAAI,mBAAmB,CAAA,EAAG,EAAE,OAAA,EAAS,wBAAA,EAA0B,CAAA,EAAG;AAClE,MAAA,IAAI,qBAAA,CAAsB,CAAC,CAAA,EAAG;AAC1B,QAAA,MAAA,CAAO,6BAA6B,CAAA;AACpC,QAAA,OAAA,CAAQ,KAAK,CAAA;AACb,QAAA;AAAA,MACJ;AACA,MAAA,IAAI,CAAC,CAAA,CAAE,EAAA,IAAM,CAAC,EAAE,EAAA,EAAI,MAAM,IAAI,KAAA,CAAM,CAAA,CAAE,MAAA,IAAU,CAAA,KAAA,EAAQ,CAAA,CAAE,MAAM,CAAA,CAAE,CAAA;AAClE,MAAA,MAAA,EAAO;AAAA,IACX,SAAS,CAAA,EAAG;AACR,MAAA,MAAA,CAAO,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,aAAa,CAAA;AACrD,MAAA,OAAA,CAAQ,KAAK,CAAA;AAAA,IACjB;AAAA,EACJ;AAEA,EAAA,uBACIE,KAAC,KAAA,EAAA,EAAI,KAAA,EAAO,WAAW,QAAQ,CAAA,EAAG,mBAAgB,KAAA,EAC9C,QAAA,EAAA;AAAA,oBAAAF,GAAAA,CAAC,gBAAa,QAAA,EAAA,6BAAA,EAAwB,CAAA;AAAA,IACrC,IAAA,KAAS,SAAA,mBACNE,IAAAA,CAAA,QAAA,EAAA,EACI,QAAA,EAAA;AAAA,sBAAAF,GAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,SAAA,EAAW,QAAA,EAAA,kGAAA,EAGrB,CAAA;AAAA,sBACAA,GAAAA;AAAA,QAAC,OAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,MAAA;AAAA,UACL,KAAA,EAAO,IAAA;AAAA,UACP,QAAA,EAAU,CAAC,CAAA,KAAM,OAAA,CAAQ,EAAE,MAAA,CAAO,KAAA,CAAM,MAAM,CAAA;AAAA,UAC9C,WAAA,EAAY,YAAA;AAAA,UACZ,cAAA,EAAe,MAAA;AAAA,UACf,UAAA,EAAY,KAAA;AAAA,UACZ,KAAA,EAAO,EAAE,GAAG,UAAA,EAAY,YAAY,IAAA;AAAK;AAAA,OAC7C;AAAA,MACC,GAAA,oBAAOA,GAAAA,CAAC,SAAA,EAAA,EAAW,QAAA,EAAA,GAAA,EAAI,CAAA;AAAA,sBACxBE,KAAC,WAAA,EAAA,EACG,QAAA,EAAA;AAAA,wBAAAF,GAAAA;AAAA,UAAC,QAAA;AAAA,UAAA;AAAA,YACG,IAAA,EAAK,QAAA;AAAA,YACL,OAAA,EAAS,MAAM,KAAK,YAAA,EAAa;AAAA,YACjC,QAAA,EAAU,IAAA,IAAQ,IAAA,CAAK,MAAA,GAAS,EAAA;AAAA,YAChC,KAAA,EAAO,eAAA,CAAgB,IAAA,IAAQ,IAAA,CAAK,SAAS,EAAE,CAAA;AAAA,YAE9C,iBAAO,kBAAA,GAAgB;AAAA;AAAA,SAC5B;AAAA,wBACAA,GAAAA,CAAC,QAAA,EAAA,EAAO,IAAA,EAAK,QAAA,EAAS,OAAA,EAAS,QAAA,EAAU,KAAA,EAAO,aAAA,CAAc,IAAI,CAAA,EAAG,QAAA,EAAA,QAAA,EAErE;AAAA,OAAA,EACJ;AAAA,KAAA,EACJ,CAAA,GACA,6BACAA,GAAAA;AAAA,MAAC,eAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,iBAAA;AAAA,QACL,IAAA;AAAA,QACA,SAAA,EAAW,MAAM,KAAK,QAAA,CAAS,YAAY,IAAI,CAAA;AAAA,QAC/C,QAAA;AAAA,QACA;AAAA;AAAA,KACJ,mBAEAE,IAAAA,CAAA,QAAA,EAAA,EACI,QAAA,EAAA;AAAA,sBAAAA,IAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,SAAA,EAAW,QAAA,EAAA;AAAA,QAAA,kDAAA;AAAA,QACgC,GAAA;AAAA,wBACjDF,GAAAA,CAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,YAAY,IAAA,EAAM,SAAA,EAAW,WAAA,EAAY,EAAI,QAAA,EAAA,IAAA,EAAK,CAAA;AAAA,QAAO;AAAA,OAAA,EAC5E,CAAA;AAAA,sBACAA,GAAAA;AAAA,QAAC,gBAAA;AAAA,QAAA;AAAA,UACG,OAAA,EAAS,IAAA;AAAA,UACT,OAAA,EAAS,SAAA;AAAA,UACT,UAAA,EAAU,IAAA;AAAA,UACV,MAAA,EAAO,MAAA;AAAA,UACP,OAAA,EAAS,IAAA;AAAA,UACT,UAAU,CAAC,GAAA,KAAgB,KAAK,QAAA,CAAS,KAAK,KAAK,CAAA;AAAA,UACnD,SAAS,CAAC,CAAA,KACN,MAAA,CAAO,CAAA,EAAG,WAAW,iBAAiB;AAAA;AAAA,OAE9C;AAAA,MACC,GAAA,oBAAOA,GAAAA,CAAC,SAAA,EAAA,EAAW,QAAA,EAAA,GAAA,EAAI,CAAA;AAAA,sBACxBA,GAAAA,CAAC,WAAA,EAAA,EACG,QAAA,kBAAAA,GAAAA;AAAA,QAAC,QAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,QAAA;AAAA,UACL,SAAS,MAAM;AACX,YAAA,OAAA,CAAQ,SAAS,CAAA;AACjB,YAAA,MAAA,CAAO,IAAI,CAAA;AAAA,UACf,CAAA;AAAA,UACA,QAAA,EAAU,IAAA;AAAA,UACV,KAAA,EAAO,cAAc,IAAI,CAAA;AAAA,UAC5B,QAAA,EAAA;AAAA;AAAA,OAED,EACJ;AAAA,KAAA,EACJ;AAAA,GAAA,EAER,CAAA;AAER;AAIA,SAAS,eAAA,CAAgB;AAAA,EACrB,IAAA;AAAA,EACA,IAAA;AAAA,EACA,SAAA;AAAA,EACA,QAAA;AAAA,EACA;AACJ,CAAA,EAMuB;AACnB,EAAA,uBACIE,KAAA,QAAA,EAAA,EACI,QAAA,EAAA;AAAA,oBAAAA,IAAAA,CAAC,GAAA,EAAA,EAAE,KAAA,EAAO,SAAA,EAAW,QAAA,EAAA;AAAA,MAAA,OAAA;AAAA,MACX,IAAA;AAAA,MAAK;AAAA,KAAA,EAIf,CAAA;AAAA,IACC,GAAA,oBAAOF,GAAAA,CAAC,SAAA,EAAA,EAAW,QAAA,EAAA,GAAA,EAAI,CAAA;AAAA,oBACxBE,KAAC,WAAA,EAAA,EACG,QAAA,EAAA;AAAA,sBAAAF,GAAAA;AAAA,QAAC,QAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,QAAA;AAAA,UACL,OAAA,EAAS,SAAA;AAAA,UACT,QAAA,EAAU,IAAA;AAAA,UACV,KAAA,EAAO,eAAe,IAAI,CAAA;AAAA,UAEzB,iBAAO,oBAAA,GAAkB;AAAA;AAAA,OAC9B;AAAA,sBACAA,GAAAA,CAAC,QAAA,EAAA,EAAO,IAAA,EAAK,QAAA,EAAS,OAAA,EAAS,QAAA,EAAU,QAAA,EAAU,IAAA,EAAM,KAAA,EAAO,aAAA,CAAc,IAAI,GAAG,QAAA,EAAA,QAAA,EAErF;AAAA,KAAA,EACJ;AAAA,GAAA,EACJ,CAAA;AAER;AAcA,SAAS,iBAAiB,KAAA,EAA8C;AACpE,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAU,gBAAwD,IAAI,CAAA;AAC1F,EAAA,MAAM,CAAC,MAAA,EAAQ,SAAS,CAAA,GAAU,gBAAS,KAAK,CAAA;AAEhD,EAAM,iBAAU,MAAM;AAClB,IAAA,IAAI,KAAA,GAAQ,IAAA;AAGZ,IAAA,OAAO,mCAAmC,CAAA,CACrC,IAAA,CAAK,CAAC,CAAA,KAAM;AACT,MAAA,IAAI,KAAA,EAAO;AACP,QAAA,OAAA;AAAA,UACI,MAAO,CAAA,CACF;AAAA,SACT;AAAA,MACJ;AAAA,IACJ,CAAC,CAAA,CACA,KAAA,CAAM,MAAM;AACT,MAAA,IAAI,KAAA,YAAiB,IAAI,CAAA;AAAA,IAC7B,CAAC,CAAA;AACL,IAAA,OAAO,MAAM;AACT,MAAA,KAAA,GAAQ,KAAA;AAAA,IACZ,CAAA;AAAA,EACJ,CAAA,EAAG,EAAE,CAAA;AAEL,EAAA,IAAI,MAAA,EAAQ;AACR,IAAA,uBACIA,GAAAA,CAAC,SAAA,EAAA,EAAU,QAAA,EAAA,yDAAA,EAEX,CAAA;AAAA,EAER;AACA,EAAA,IAAI,CAAC,IAAA,EAAM,uBAAOE,IAAAA,CAAC,MAAA,EAAA,EAAK,OAAO,SAAA,EAAY,QAAA,EAAA;AAAA,IAAA,IAAA;AAAA,IAAK;AAAA,GAAA,EAAuB,CAAA;AACvE,EAAA,uBAAOF,GAAAA,CAAC,IAAA,EAAA,EAAM,GAAG,KAAA,EAAO,CAAA;AAC5B;AAIA,SAAS,IAAA,CAAK,OAAe,IAAA,EAA+B;AACxD,EAAA,IAAI,SAAS,OAAA,EAAS;AAClB,IAAA,MAAM,CAAC,IAAA,EAAM,IAAI,CAAA,GAAI,KAAA,CAAM,MAAM,GAAG,CAAA;AACpC,IAAA,IAAI,CAAC,IAAA,IAAQ,CAAC,IAAA,EAAM,OAAO,0BAAA;AAC3B,IAAA,MAAM,CAAA,GACF,KAAK,MAAA,IAAU,CAAA,GACT,SAAI,MAAA,CAAO,IAAA,CAAK,MAAM,CAAA,GACtB,IAAA,CAAK,CAAC,CAAA,GAAI,QAAA,CAAI,OAAO,IAAA,CAAK,MAAA,GAAS,CAAC,CAAA,GAAI,IAAA,CAAK,MAAM,EAAE,CAAA;AAC/D,IAAA,OAAO,CAAA,EAAG,CAAC,CAAA,CAAA,EAAI,IAAI,CAAA,CAAA;AAAA,EACvB;AACA,EAAA,IAAI,MAAM,MAAA,IAAU,EAAA,SAAW,QAAA,CAAI,MAAA,CAAO,MAAM,MAAM,CAAA;AACtD,EAAA,OAAO,CAAA,EAAG,KAAA,CAAM,KAAA,CAAM,CAAA,EAAG,CAAC,CAAC,CAAA,MAAA,EAAI,KAAA,CAAM,KAAA,CAAM,EAAE,CAAC,CAAA,CAAA;AAClD;AAIA,SAAS,YAAA,CAAa;AAAA,EAClB,QAAA;AAAA,EACA,IAAA,GAAO;AACX,CAAA,EAGuB;AACnB,EAAA,MAAM,KAAA,GAAQ,SAAS,SAAA,GAAY,CAAA,CAAE,UAAU,IAAA,KAAS,MAAA,GAAS,CAAA,CAAE,IAAA,GAAO,CAAA,CAAE,OAAA;AAC5E,EAAA,uBACIA,GAAAA;AAAA,IAAC,KAAA;AAAA,IAAA;AAAA,MACG,KAAA,EAAO;AAAA,QACH,KAAA;AAAA,QACA,UAAA,EAAY,IAAA;AAAA,QACZ,QAAA,EAAU,EAAA;AAAA,QACV,aAAA,EAAe,QAAA;AAAA,QACf,aAAA,EAAe,WAAA;AAAA,QACf,YAAA,EAAc;AAAA,OAClB;AAAA,MAEC;AAAA;AAAA,GACL;AAER;AAEA,SAAS,SAAA,CAAU,EAAE,QAAA,EAAS,EAAsD;AAChF,EAAA,uBACIA,GAAAA;AAAA,IAAC,GAAA;AAAA,IAAA;AAAA,MACG,IAAA,EAAK,OAAA;AAAA,MACL,KAAA,EAAO;AAAA,QACH,MAAA,EAAQ,SAAA;AAAA,QACR,OAAO,CAAA,CAAE,WAAA;AAAA,QACT,UAAA,EAAY,IAAA;AAAA,QACZ,QAAA,EAAU;AAAA,OACd;AAAA,MAEC;AAAA;AAAA,GACL;AAER;AAEA,SAAS,WAAA,CAAY,EAAE,QAAA,EAAS,EAAsD;AAClF,EAAA,uBACIA,GAAAA,CAAC,KAAA,EAAA,EAAI,KAAA,EAAO,EAAE,OAAA,EAAS,MAAA,EAAQ,QAAA,EAAU,MAAA,EAAQ,GAAA,EAAK,CAAA,EAAG,SAAA,EAAW,EAAA,IAAO,QAAA,EAAS,CAAA;AAE5F;AAIA,IAAM,IAAA,GAAO,yCAAA;AAEb,IAAM,CAAA,GAAI;AAAA,EACN,OAAA,EAAS,yBAAA;AAAA,EACT,UAAA,EAAY,4BAAA;AAAA,EACZ,KAAA,EAAO,kCAAA;AAAA,EACP,UAAA,EAAY,4BAAA;AAAA,EACZ,IAAA,EAAM,sBAAA;AAAA,EACN,MAAA,EAAQ,wBAAA;AAAA,EACR,WAAA,EAAa,6BAAA;AAAA,EACb,OAAA,EAAS,yBAAA;AAAA,EACT,IAAA,EAAM;AACV,CAAA;AAEA,SAAS,UAAA,CAAW,OAA4D,SAAA,EAAgC;AAC5G,EAAA,MAAM,IAAA,GAA4B;AAAA,IAC9B,YAAY,CAAA,CAAE,IAAA;AAAA,IACd,MAAA,EAAQ,CAAA,UAAA,EAAa,CAAA,CAAE,MAAM,CAAA,CAAA;AAAA,IAC7B,OAAA,EAAS;AAAA,GACb;AACA,EAAA,IAAI,SAAS,OAAA,EAAS,OAAO,EAAE,GAAG,IAAA,EAAM,SAAS,CAAA,EAAE;AACnD,EAAA,IAAI,IAAA,KAAS,QAAA,EAAU,OAAO,EAAE,GAAG,MAAM,WAAA,EAAa,CAAA,CAAE,OAAA,EAAS,UAAA,EAAY,sBAAA,EAAuB;AACpG,EAAA,IAAI,IAAA,KAAS,WAAW,OAAO,EAAE,GAAG,IAAA,EAAM,WAAA,EAAa,EAAE,OAAA,EAAQ;AACjE,EAAA,IAAI,IAAA,KAAS,QAAQ,OAAO,EAAE,GAAG,IAAA,EAAM,WAAA,EAAa,EAAE,IAAA,EAAK;AAC3D,EAAA,OAAO,IAAA;AACX;AAEA,IAAM,SAAA,GAAiC;AAAA,EACnC,OAAO,CAAA,CAAE,KAAA;AAAA,EACT,QAAA,EAAU,EAAA;AAAA,EACV,UAAA,EAAY,IAAA;AAAA,EACZ,MAAA,EAAQ;AACZ,CAAA;AAEA,IAAM,SAAA,GAAiC;AAAA,EACnC,OAAO,CAAA,CAAE,KAAA;AAAA,EACT,UAAA,EAAY,IAAA;AAAA,EACZ,QAAA,EAAU,IAAA;AAAA,EACV,OAAA,EAAS;AACb,CAAA;AAEA,IAAM,SAAA,GAAiC;AAAA,EACnC,UAAA,EAAY,IAAA;AAAA,EACZ,OAAO,CAAA,CAAE;AACb,CAAA;AAEA,IAAM,QAAA,GAAgC;AAAA,EAClC,OAAA,EAAS,MAAA;AAAA,EACT,QAAA,EAAU,MAAA;AAAA,EACV,UAAA,EAAY,QAAA;AAAA,EACZ,cAAA,EAAgB,eAAA;AAAA,EAChB,GAAA,EAAK,EAAA;AAAA,EACL,OAAA,EAAS;AACb,CAAA;AAEA,IAAM,aAAA,GAAqC;AAAA,EACvC,OAAO,CAAA,CAAE,UAAA;AAAA,EACT,UAAA,EAAY,IAAA;AAAA,EACZ,QAAA,EAAU,IAAA;AAAA,EACV,aAAA,EAAe,QAAA;AAAA,EACf,aAAA,EAAe,WAAA;AAAA,EACf,OAAA,EAAS;AACb,CAAA;AAEA,IAAM,UAAA,GAAkC;AAAA,EACpC,KAAA,EAAO,MAAA;AAAA,EACP,OAAA,EAAS,iBAAA;AAAA,EACT,YAAY,CAAA,CAAE,UAAA;AAAA,EACd,OAAO,CAAA,CAAE,UAAA;AAAA,EACT,MAAA,EAAQ,CAAA,UAAA,EAAa,CAAA,CAAE,MAAM,CAAA,CAAA;AAAA,EAC7B,YAAA,EAAc,CAAA;AAAA,EACd,UAAA,EAAY,IAAA;AAAA;AAAA,EAEZ,QAAA,EAAU,EAAA;AAAA,EACV,OAAA,EAAS,MAAA;AAAA,EACT,SAAA,EAAW;AACf,CAAA;AAEA,SAAS,QAAQ,QAAA,EAAwC;AACrD,EAAA,OAAO;AAAA,IACH,OAAA,EAAS,iBAAA;AAAA,IACT,YAAA,EAAc,CAAA;AAAA,IACd,UAAA,EAAY,IAAA;AAAA,IACZ,QAAA,EAAU,IAAA;AAAA,IACV,aAAA,EAAe,QAAA;AAAA,IACf,aAAA,EAAe,WAAA;AAAA,IACf,MAAA,EAAQ,WAAW,aAAA,GAAgB,SAAA;AAAA,IACnC,OAAA,EAAS,WAAW,GAAA,GAAM;AAAA,GAC9B;AACJ;AAEA,SAAS,gBAAgB,QAAA,EAAwC;AAC7D,EAAA,OAAO;AAAA,IACH,GAAG,QAAQ,QAAQ,CAAA;AAAA,IACnB,YAAY,CAAA,CAAE,OAAA;AAAA,IACd,KAAA,EAAO,oCAAA;AAAA,IACP,MAAA,EAAQ,CAAA,UAAA,EAAa,CAAA,CAAE,OAAO,CAAA,CAAA;AAAA,IAC9B,UAAA,EAAY;AAAA,GAChB;AACJ;AAEA,SAAS,cAAc,QAAA,EAAwC;AAC3D,EAAA,OAAO;AAAA,IACH,GAAG,QAAQ,QAAQ,CAAA;AAAA,IACnB,YAAY,CAAA,CAAE,UAAA;AAAA,IACd,OAAO,CAAA,CAAE,UAAA;AAAA,IACT,MAAA,EAAQ,CAAA,UAAA,EAAa,CAAA,CAAE,MAAM,CAAA;AAAA,GACjC;AACJ;AAEA,SAAS,eAAe,QAAA,EAAwC;AAC5D,EAAA,OAAO;AAAA,IACH,GAAG,QAAQ,QAAQ,CAAA;AAAA,IACnB,UAAA,EAAY,aAAA;AAAA,IACZ,OAAO,CAAA,CAAE,WAAA;AAAA,IACT,MAAA,EAAQ,CAAA,UAAA,EAAa,CAAA,CAAE,WAAW,CAAA;AAAA,GACtC;AACJ;AAEA,IAAM,gBAAA,GAAwC;AAAA,EAC1C,GAAG,QAAQ,KAAK,CAAA;AAAA,EAChB,UAAA,EAAY,aAAA;AAAA,EACZ,OAAO,CAAA,CAAE,OAAA;AAAA,EACT,MAAA,EAAQ,CAAA,UAAA,EAAa,CAAA,CAAE,OAAO,CAAA;AAClC,CAAA;AC/6BA,SAAS,gBAAA,CAAiB,WAAmB,MAAA,EAAyB;AAClE,EAAA,IAAI;AACA,IAAA,OAAO,IAAI,GAAA,CAAI,SAAA,EAAW,MAAM,EAAE,MAAA,KAAW,MAAA;AAAA,EACjD,CAAA,CAAA,MAAQ;AACJ,IAAA,OAAO,KAAA;AAAA,EACX;AACJ;AAIA,SAAS,gBAAA,GAA2B;AAChC,EAAA,OAAO,OAAO,MAAA,KAAW,WAAA,GAAc,iBAAA,GAAoB,OAAO,QAAA,CAAS,MAAA;AAC/E;AAEO,SAAS,aAAa,KAAA,EAAmC;AAC5D,EAAA,MAAM,YAAY,KAAA,IAAS,GAAA;AAC3B,EAAA,IAAI,OAAO,SAAA,KAAc,QAAA,EAAU,OAAO,GAAA;AAC1C,EAAA,IAAI,CAAC,SAAA,CAAU,UAAA,CAAW,GAAG,GAAG,OAAO,GAAA;AACvC,EAAA,OAAO,gBAAA,CAAiB,SAAA,EAAW,gBAAA,EAAkB,IAAI,SAAA,GAAY,GAAA;AACzE;AASO,SAAS,mBAAmB,KAAA,EAAsD;AACrF,EAAA,IAAI,OAAO,KAAA,KAAU,QAAA,IAAY,KAAA,CAAM,MAAA,KAAW,GAAG,OAAO,MAAA;AAG5D,EAAA,IAAI,KAAA,CAAM,WAAW,GAAG,CAAA,IAAK,iBAAiB,KAAA,EAAO,gBAAA,EAAkB,CAAA,EAAG;AACtE,IAAA,OAAO,KAAA;AAAA,EACX;AACA,EAAA,IAAI;AACA,IAAA,MAAM,CAAA,GAAI,IAAI,GAAA,CAAI,KAAK,CAAA;AACvB,IAAA,IAAI,CAAA,CAAE,QAAA,KAAa,QAAA,EAAU,OAAO,KAAA,CAAA;AACpC,IAAA,MAAM,IAAA,GAAO,CAAA,CAAE,QAAA,CAAS,WAAA,EAAY;AACpC,IAAA,IAAI,IAAA,KAAS,aAAa,IAAA,CAAK,QAAA,CAAS,UAAU,CAAA,EAAG,OAAO,EAAE,QAAA,EAAS;AAAA,EAC3E,CAAA,CAAA,MAAQ;AAAA,EAER;AACA,EAAA,OAAO,MAAA;AACX;AAEA,SAAS,aAAa,MAAA,EAAsB;AACxC,EAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,EAAA,MAAA,CAAO,QAAA,CAAS,OAAO,MAAM,CAAA;AACjC;AAIO,SAAS,QAAA,CAAS;AAAA,EACrB,QAAA;AAAA,EACA,QAAA;AAAA,EACA,SAAA;AAAA,EACA,eAAA;AAAA,EACA,UAAA,GAAa,IAAA;AAAA,EACb,GAAA,EAAK,OAAA;AAAA,EACL,UAAA,GAAa,iBAAA;AAAA,EACb,WAAA;AAAA,EACA,cAAA,GAAiB,IAAA;AAAA,EACjB,KAAA;AAAA,EACA;AACJ,CAAA,EAAsC;AAClC,EAAA,MAAM,aAAA,GAAgB,OAAO,MAAA,IAAU,IAAA;AACvC,EAAA,MAAM,YAAA,GAAe,OAAO,KAAA,IAAS,IAAA;AASrC,EAAA,MAAM,CAAC,cAAA,EAAgB,iBAAiB,CAAA,GAAUG,MAAA,CAAA,QAAA;AAAA,IAC9C,MAAM,kBAAA,CAAmB,QAAQ,CAAA,IAAK,aAAa,QAAQ;AAAA,GAC/D;AACA,EAAMA,iBAAU,MAAM;AAClB,IAAA,MAAM,QAAA,GAAW,mBAAmB,QAAQ,CAAA;AAC5C,IAAA,IAAI,QAAA,EAAU;AACV,MAAA,iBAAA,CAAkB,QAAQ,CAAA;AAC1B,MAAA;AAAA,IACJ;AACA,IAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,IAAA,MAAM,CAAA,GAAI,IAAI,eAAA,CAAgB,MAAA,CAAO,SAAS,MAAM,CAAA;AACpD,IAAA,MAAM,SAAA,GACF,kBAAA,CAAmB,CAAA,CAAE,GAAA,CAAI,WAAW,CAAC,CAAA,IAAK,kBAAA,CAAmB,CAAA,CAAE,GAAA,CAAI,MAAM,CAAC,CAAA;AAC9E,IAAA,iBAAA,CAAkB,aAAa,GAAG,CAAA;AAAA,EACtC,CAAA,EAAG,CAAC,QAAQ,CAAC,CAAA;AAKb,EAAA,MAAM,CAAC,OAAA,EAAS,UAAU,IAAUA,MAAA,CAAA,QAAA,CAAkB,OAAA,CAAQ,OAAO,CAAC,CAAA;AACtE,EAAMA,iBAAU,MAAM;AAClB,IAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,IAAA,IAAI,YAAY,MAAA,EAAW;AACvB,MAAA,UAAA,CAAW,OAAA,CAAQ,OAAO,CAAC,CAAA;AAC3B,MAAA;AAAA,IACJ;AACA,IAAA,UAAA,CAAW,IAAI,gBAAgB,MAAA,CAAO,QAAA,CAAS,MAAM,CAAA,CAAE,GAAA,CAAI,KAAK,CAAA,KAAM,GAAG,CAAA;AAAA,EAC7E,CAAA,EAAG,CAAC,OAAO,CAAC,CAAA;AAKZ,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAUA,MAAA,CAAA,QAAA;AAAA,IAC1B,WAAA,KAAgB,iBAAiB,OAAA,GAAU,QAAA;AAAA,GAC/C;AAIA,EAAA,MAAM,CAAC,QAAA,EAAU,WAAW,CAAA,GAAUA,gBAI5B,IAAI,CAAA;AAEd,EAAA,MAAM,CAAC,QAAA,EAAU,WAAW,CAAA,GAAUA,gBAAS,KAAK,CAAA;AAIpD,EAAA,MAAM,CAAC,UAAA,EAAY,aAAa,CAAA,GAAUA,gBAAS,KAAK,CAAA;AACxD,EAAMA,iBAAU,MAAM;AAClB,IAAA,IAAI,OAAO,WAAW,WAAA,EAAa;AACnC,IAAA,IAAI,IAAI,gBAAgB,MAAA,CAAO,QAAA,CAAS,MAAM,CAAA,CAAE,GAAA,CAAI,aAAa,CAAA,EAAG;AAChE,MAAA,aAAA,CAAc,IAAI,CAAA;AAAA,IACtB;AAAA,EACJ,CAAA,EAAG,EAAE,CAAA;AAEL,EAAA,MAAM,QAAA,GAAiBA,MAAA,CAAA,WAAA;AAAA,IACnB,OAAO,OAAA,KAAuB;AAC1B,MAAA,IAAI,eAAA,EAAiB;AACjB,QAAA,IAAI;AACA,UAAA,MAAM,QAAA,GAAW,kBAAA,CAAmB,MAAM,eAAA,CAAgB,OAAO,CAAC,CAAA;AAClE,UAAA,YAAA,CAAa,YAAY,cAAc,CAAA;AACvC,UAAA;AAAA,QACJ,CAAA,CAAA,MAAQ;AAAA,QAER;AAAA,MACJ;AACA,MAAA,YAAA,CAAa,cAAc,CAAA;AAAA,IAC/B,CAAA;AAAA,IACA,CAAC,iBAAiB,cAAc;AAAA,GACpC;AAEA,EAAA,MAAM,aAAA,GAAsBA,MAAA,CAAA,WAAA;AAAA,IACxB,OAAO,OAAA,EAAoB,KAAA,EAA2B,GAAA,KAA4B;AAE9E,MAAA,MAAM,UAAU,MAAM;AAGlB,QAAA,eAAA,EAAgB;AAChB,QAAA,IAAI,SAAA,EAAW,SAAA,CAAU,OAAA,EAAS,KAAK,CAAA;AAAA,aAClC,KAAK,SAAS,OAAO,CAAA;AAAA,MAC9B,CAAA;AAIA,MAAA,IAAI,CAAC,UAAA,IAAc,CAAC,QAAA,EAAU;AAC1B,QAAA,OAAA,EAAQ;AACR,QAAA;AAAA,MACJ;AAKA,MAAA,IAAI;AACA,QAAA,MAAM,KAAA,GAAQ,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,YAAA,CAAA,EAAgB;AAAA,UACnD,WAAA,EAAa,SAAA;AAAA,UACb,OAAA,EAAS,EAAE,MAAA,EAAQ,kBAAA;AAAmB,SACzC,CAAA;AACD,QAAA,MAAM,KAAK,KAAA,CAAM,EAAA,GACT,MAAM,KAAA,CAAM,MAAK,GACnB,IAAA;AACN,QAAA,MAAM,KAAA,GAAQ,IAAI,OAAA,EAAS,MAAA;AAC3B,QAAA,IAAI,KAAA,EAAO;AACP,UAAA,WAAA,CAAY;AAAA,YACR,MAAA,EAAQ,GAAA,KAAQ,OAAA,GAAU,KAAA,GAAQ,OAAA;AAAA,YAClC,KAAA;AAAA,YACA;AAAA,WACH,CAAA;AACD,UAAA;AAAA,QACJ;AAAA,MACJ,CAAA,CAAA,MAAQ;AAAA,MAER;AACA,MAAA,OAAA,EAAQ;AAAA,IACZ,CAAA;AAAA,IACA,CAAC,SAAA,EAAW,UAAA,EAAY,QAAA,EAAU,UAAU,UAAU;AAAA,GAC1D;AAEA,EAAA,IAAI,CAAC,aAAA,IAAiB,CAAC,YAAA,EAAc;AACjC,IAAA,uBACID,IAAAA;AAAA,MAAC,KAAA;AAAA,MAAA;AAAA,QACG,SAAA;AAAA,QACA,gBAAA,EAAe,EAAA;AAAA,QACf,KAAA,EAAO;AAAA,UACH,OAAA,EAAS,MAAA;AAAA,UACT,MAAA,EAAQ,kCAAA;AAAA,UACR,KAAA,EAAO,4BAAA;AAAA,UACP,UAAA,EAAY,yCAAA;AAAA,UACZ,QAAA,EAAU;AAAA,SACd;AAAA,QACH,QAAA,EAAA;AAAA,UAAA,qCAAA;AAAA,0BACiCF,GAAAA,CAAC,MAAA,EAAA,EAAK,QAAA,EAAA,cAAA,EAAY,CAAA;AAAA,UAAO,KAAA;AAAA,UAAI,GAAA;AAAA,0BAC3DA,GAAAA,CAAC,MAAA,EAAA,EAAK,QAAA,EAAA,aAAA,EAAW,CAAA;AAAA,UAAO,MAAA;AAAA,0BAAIA,GAAAA,CAAC,MAAA,EAAA,EAAK,QAAA,EAAA,MAAA,EAAI;AAAA;AAAA;AAAA,KAC1C;AAAA,EAER;AAEA,EAAA,IAAI,QAAA,EAAU;AACV,IAAA,uBACIA,GAAAA,CAAC,KAAA,EAAA,EAAI,SAAA,EAAsB,gBAAA,EAAe,IACtC,QAAA,kBAAAA,GAAAA;AAAA,MAAC,cAAA;AAAA,MAAA;AAAA,QACG,QAAQ,QAAA,CAAS,MAAA;AAAA,QACjB,OAAO,QAAA,CAAS,KAAA;AAAA,QAChB,UAAA;AAAA,QACA,YAAY,QAAA,CAAS;AAAA;AAAA,KACzB,EACJ,CAAA;AAAA,EAER;AAEA,EAAA,MAAM,UAAA,GAAa,aAAA,KAAkB,IAAA,KAAS,QAAA,IAAY,CAAC,YAAA,CAAA;AAC3D,EAAA,MAAM,SAAA,GAAY,YAAA,KAAiB,IAAA,KAAS,OAAA,IAAW,CAAC,aAAA,CAAA;AACxD,EAAA,MAAM,cAAc,aAAA,IAAiB,YAAA;AAGrC,EAAA,MAAM,eAAmC,CAAC,YAAA,GACpC,QAAA,GACA,CAAC,gBACC,OAAA,GACA,IAAA;AAER,EAAA,uBACIE,IAAAA,CAAC,KAAA,EAAA,EAAI,SAAA,EAAsB,kBAAe,EAAA,EACrC,QAAA,EAAA;AAAA,IAAA,UAAA,oBACGF,GAAAA;AAAA,MAAC,KAAA;AAAA,MAAA;AAAA,QACG,4BAAA,EAA2B,EAAA;AAAA,QAC3B,KAAA,EAAO;AAAA,UACH,YAAA,EAAc,EAAA;AAAA,UACd,OAAA,EAAS,gBAAA;AAAA,UACT,MAAA,EAAQ,uCAAA;AAAA,UACR,YAAA,EAAc,CAAA;AAAA,UACd,KAAA,EAAO,6BAAA;AAAA,UACP,UAAA,EAAY,yCAAA;AAAA,UACZ,QAAA,EAAU;AAAA,SACd;AAAA,QACH,QAAA,EAAA;AAAA;AAAA,KAED;AAAA,IAEH,2BACGE,IAAAA;AAAA,MAAC,KAAA;AAAA,MAAA;AAAA,QACG,yBAAA,EAAwB,EAAA;AAAA,QACxB,KAAA,EAAO;AAAA,UACH,YAAA,EAAc,EAAA;AAAA,UACd,OAAA,EAAS,gBAAA;AAAA,UACT,MAAA,EAAQ,mCAAA;AAAA,UACR,eAAA,EAAiB,CAAA;AAAA,UACjB,YAAA,EAAc,CAAA;AAAA,UACd,UAAA,EAAY,6DAAA;AAAA,UACZ,KAAA,EAAO,4BAAA;AAAA,UACP,UAAA,EAAY,yCAAA;AAAA,UACZ,QAAA,EAAU,EAAA;AAAA,UACV,UAAA,EAAY;AAAA,SAChB;AAAA,QAEA,QAAA,EAAA;AAAA,0BAAAF,GAAAA;AAAA,YAAC,QAAA;AAAA,YAAA;AAAA,cACG,KAAA,EAAO;AAAA,gBACH,KAAA,EAAO,yBAAA;AAAA,gBACP,aAAA,EAAe,QAAA;AAAA,gBACf,aAAA,EAAe,WAAA;AAAA,gBACf,QAAA,EAAU,EAAA;AAAA,gBACV,OAAA,EAAS,OAAA;AAAA,gBACT,YAAA,EAAc;AAAA,eAClB;AAAA,cACH,QAAA,EAAA;AAAA;AAAA,WAED;AAAA,UAAS;AAAA;AAAA;AAAA,KAIb;AAAA,IAKH,kCACGA,GAAAA;AAAA,MAAC,cAAA;AAAA,MAAA;AAAA,QACG,UAAA;AAAA,QACA,QAAA,EAAU,cAAA;AAAA,QACV,GAAA,EAAK,OAAA;AAAA,QACL,KAAA,EAAK;AAAA;AAAA,KACT;AAAA,IAEH,+BACGA,GAAAA;AAAA,MAAC,KAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,SAAA;AAAA,QACL,YAAA,EAAW,eAAA;AAAA,QACX,qBAAA,EAAoB,EAAA;AAAA,QACpB,KAAA,EAAO;AAAA,UACH,OAAA,EAAS,MAAA;AAAA,UACT,GAAA,EAAK,CAAA;AAAA,UACL,YAAA,EAAc,EAAA;AAAA,UACd,YAAA,EAAc;AAAA,SAClB;AAAA,QAIC,QAAA,EAAA,cAAA,mBACGE,IAAAA,CAAAE,QAAAA,EAAA,EACI,QAAA,EAAA;AAAA,0BAAAJ,GAAAA;AAAA,YAAC,SAAA;AAAA,YAAA;AAAA,cACG,QAAQ,IAAA,KAAS,OAAA;AAAA,cACjB,OAAA,EAAS,MAAM,OAAA,CAAQ,OAAO,CAAA;AAAA,cACjC,QAAA,EAAA;AAAA;AAAA,WAED;AAAA,0BACAA,GAAAA;AAAA,YAAC,SAAA;AAAA,YAAA;AAAA,cACG,QAAQ,IAAA,KAAS,QAAA;AAAA,cACjB,OAAA,EAAS,MAAM,OAAA,CAAQ,QAAQ,CAAA;AAAA,cAClC,QAAA,EAAA;AAAA;AAAA;AAED,SAAA,EACJ,CAAA,mBAEAE,IAAAA,CAAAE,QAAAA,EAAA,EACI,QAAA,EAAA;AAAA,0BAAAJ,GAAAA;AAAA,YAAC,SAAA;AAAA,YAAA;AAAA,cACG,QAAQ,IAAA,KAAS,QAAA;AAAA,cACjB,OAAA,EAAS,MAAM,OAAA,CAAQ,QAAQ,CAAA;AAAA,cAClC,QAAA,EAAA;AAAA;AAAA,WAED;AAAA,0BACAA,GAAAA;AAAA,YAAC,SAAA;AAAA,YAAA;AAAA,cACG,QAAQ,IAAA,KAAS,OAAA;AAAA,cACjB,OAAA,EAAS,MAAM,OAAA,CAAQ,OAAO,CAAA;AAAA,cACjC,QAAA,EAAA;AAAA;AAAA;AAED,SAAA,EACJ;AAAA;AAAA,KAER;AAAA,oBAGJE,IAAAA,CAAC,KAAA,EAAA,EAAI,sBAAA,EAAqB,EAAA,EAAG,MAAK,UAAA,EAC7B,QAAA,EAAA;AAAA,MAAA,UAAA,oBACGF,GAAAA;AAAA,QAAC,UAAA;AAAA,QAAA;AAAA,UACG,UAAA;AAAA,UACA,QAAA;AAAA,UACA,GAAA,EAAK,OAAA;AAAA,UACL,SAAA,EAAW,CAAC,CAAA,EAAG,CAAA,KAAM,KAAK,aAAA,CAAc,CAAA,EAAG,GAAG,QAAQ;AAAA;AAAA,OAC1D;AAAA,MAEH,6BACGA,GAAAA;AAAA,QAAC,SAAA;AAAA,QAAA;AAAA,UACG,UAAA;AAAA,UACA,GAAA,EAAK,OAAA;AAAA,UACL,SAAA,EAAW,CAAC,CAAA,EAAG,CAAA,KAAM,KAAK,aAAA,CAAc,CAAA,EAAG,GAAG,OAAO;AAAA;AAAA;AACzD,KAAA,EAER,CAAA;AAAA,IAEC,CAAC,kCACEA,GAAAA,CAAC,kBAAe,UAAA,EAAwB,QAAA,EAAU,cAAA,EAAgB,GAAA,EAAK,OAAA,EAAS,CAAA;AAAA,IAGnF,8BACGE,IAAAA,CAAC,WAAM,yBAAA,EAAwB,EAAA,EAAG,OAAO,aAAA,EACrC,QAAA,EAAA;AAAA,sBAAAF,GAAAA;AAAA,QAAC,OAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,UAAA;AAAA,UACL,OAAA,EAAS,QAAA;AAAA,UACT,UAAU,CAAC,CAAA,KAAM,WAAA,CAAY,CAAA,CAAE,OAAO,OAAO,CAAA;AAAA,UAC7C,KAAA,EAAO,EAAE,SAAA,EAAW,CAAA,EAAG,aAAa,yBAAA;AAA0B;AAAA,OAClE;AAAA,sBACAE,KAAC,MAAA,EAAA,EAAK,QAAA,EAAA;AAAA,QAAA,6BAAA;AAAA,QAC0B,GAAA;AAAA,QAC3B,YAAA,KAAiB,UAAU,kBAAA,GAAqB,UAAA;AAAA,QAAY,GAAA;AAAA,wBAC7DF,IAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,OAAA,EAAS,IAAA,IAAQ,QAAA,EAAA,sCAAA,EAA+B;AAAA,OAAA,EACnE;AAAA,KAAA,EACJ;AAAA,GAAA,EAER,CAAA;AAER;AAIA,SAAS,SAAA,CAAU;AAAA,EACf,MAAA;AAAA,EACA,OAAA;AAAA,EACA;AACJ,CAAA,EAIuB;AACnB,EAAA,uBACIA,GAAAA;AAAA,IAAC,QAAA;AAAA,IAAA;AAAA,MACG,IAAA,EAAK,QAAA;AAAA,MACL,IAAA,EAAK,KAAA;AAAA,MACL,eAAA,EAAe,MAAA;AAAA,MACf,OAAA;AAAA,MACA,oBAAA,EAAoB,SAAS,QAAA,GAAW,UAAA;AAAA,MACxC,KAAA,EAAO;AAAA,QACH,OAAA,EAAS,iBAAA;AAAA,QACT,UAAA,EAAY,aAAA;AAAA,QACZ,MAAA,EAAQ,MAAA;AAAA,QACR,YAAA,EAAc,SACR,mCAAA,GACA,uBAAA;AAAA,QACN,KAAA,EAAO,SACD,4BAAA,GACA,kCAAA;AAAA,QACN,UAAA,EAAY,yCAAA;AAAA,QACZ,QAAA,EAAU,EAAA;AAAA,QACV,aAAA,EAAe,QAAA;AAAA,QACf,aAAA,EAAe,WAAA;AAAA,QACf,MAAA,EAAQ,SAAA;AAAA,QACR,YAAA,EAAc;AAAA,OAClB;AAAA,MAEC;AAAA;AAAA,GACL;AAER;AAiBA,SAAS,YAAA,CAAa,EAAE,EAAA,EAAG,EAA8C;AACrE,EAAA,MAAM,MAAA,GAAS;AAAA,IACX,KAAA,EAAO,EAAA;AAAA,IACP,MAAA,EAAQ,EAAA;AAAA,IACR,OAAA,EAAS,WAAA;AAAA,IACT,IAAA,EAAM,cAAA;AAAA,IACN,aAAA,EAAe,IAAA;AAAA,IACf,KAAA,EAAO,EAAE,IAAA,EAAM,UAAA;AAAW,GAC9B;AACA,EAAA,IAAI,OAAO,QAAA,EAAU;AACjB,IAAA,uBACIA,GAAAA,CAAC,KAAA,EAAA,EAAK,GAAG,MAAA,EACL,0BAAAA,GAAAA,CAAC,MAAA,EAAA,EAAK,CAAA,EAAE,6VAAA,EAA8V,CAAA,EAC1W,CAAA;AAAA,EAER;AACA,EAAA,IAAI,OAAO,QAAA,EAAU;AACjB,IAAA,uBACIA,GAAAA,CAAC,KAAA,EAAA,EAAK,GAAG,MAAA,EACL,0BAAAA,GAAAA,CAAC,MAAA,EAAA,EAAK,CAAA,EAAE,0sBAAA,EAA2sB,CAAA,EACvtB,CAAA;AAAA,EAER;AACA,EAAA,OAAO,IAAA;AACX;AAcA,SAAS,cAAA,CAAe;AAAA,EACpB,UAAA;AAAA,EACA,QAAA;AAAA,EACA,GAAA;AAAA,EACA,KAAA,GAAQ;AACZ,CAAA,EAY8B;AAC1B,EAAA,MAAM,CAAC,SAAA,EAAW,YAAY,CAAA,GAAUG,MAAA,CAAA,QAAA,CAA+B,EAAE,CAAA;AAKzE,EAAA,MAAM,CAAC,MAAA,EAAQ,SAAS,CAAA,GAAUA,gBAAS,EAAE,CAAA;AAE7C,EAAMA,iBAAU,MAAM;AAClB,IAAA,SAAA,CAAU,MAAA,CAAO,SAAS,MAAM,CAAA;AAChC,IAAA,IAAI,SAAA,GAAY,KAAA;AAChB,IAAA,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,mBAAA,CAAA,EAAuB,EAAE,aAAa,SAAA,EAAW,EAC/D,IAAA,CAAK,CAAC,MAAO,CAAA,CAAE,EAAA,GAAM,EAAE,IAAA,EAAK,GAAsD,IAAK,CAAA,CACvF,IAAA,CAAK,CAAC,IAAA,KAAS;AACZ,MAAA,IAAI,CAAC,SAAA,IAAa,IAAA,EAAM,SAAA,EAAW,YAAA,CAAa,KAAK,SAAS,CAAA;AAAA,IAClE,CAAC,CAAA,CACA,KAAA,CAAM,MAAM;AAAA,IAGb,CAAC,CAAA;AACL,IAAA,OAAO,MAAM;AACT,MAAA,SAAA,GAAY,IAAA;AAAA,IAChB,CAAA;AAAA,EACJ,CAAA,EAAG,CAAC,UAAU,CAAC,CAAA;AAEf,EAAA,IAAI,SAAA,CAAU,MAAA,KAAW,CAAA,EAAG,OAAO,IAAA;AAKnC,EAAA,MAAM,gBAAA,GAAmB,QAAA,CAAS,UAAA,CAAW,GAAG,CAAA,GAC1C,MAAA,GACI,CAAA,EAAG,MAAM,CAAA,EAAG,QAAQ,CAAA,CAAA,GACpB,QAAA,GACJ,QAAA;AACN,EAAA,MAAM,OAAO,EAAE,IAAA,EAAM,GAAG,MAAA,EAAQ,CAAA,EAAG,YAAY,wBAAA,EAAyB;AASxE,EAAA,MAAM,SAAA,GAAY,EAAA;AAClB,EAAA,MAAM,UAAA,GAAa,CAAA;AACnB,EAAA,MAAM,0BACFD,IAAAA;AAAA,IAAC,KAAA;AAAA,IAAA;AAAA,MACG,KAAA,EAAO;AAAA,QACH,OAAA,EAAS,MAAA;AAAA,QACT,UAAA,EAAY,QAAA;AAAA,QACZ,GAAA,EAAK,EAAA;AAAA;AAAA;AAAA;AAAA,QAIL,QAAQ,KAAA,GAAQ,CAAA,EAAG,SAAS,CAAA,IAAA,CAAA,GAAS,OAAO,SAAS,CAAA,EAAA,CAAA;AAAA,QACrD,KAAA,EAAO,kCAAA;AAAA,QACP,UAAA,EAAY,yCAAA;AAAA,QACZ,QAAA,EAAU,EAAA;AAAA,QACV,aAAA,EAAe,QAAA;AAAA,QACf,aAAA,EAAe;AAAA,OACnB;AAAA,MAEA,QAAA,EAAA;AAAA,wBAAAF,GAAAA,CAAC,MAAA,EAAA,EAAK,KAAA,EAAO,IAAA,EAAM,CAAA;AAAA,QAAE,IAAA;AAAA,wBAErBA,GAAAA,CAAC,MAAA,EAAA,EAAK,KAAA,EAAO,IAAA,EAAM;AAAA;AAAA;AAAA,GACvB;AAEJ,EAAA,MAAM,UAAU,SAAA,CAAU,GAAA,CAAI,CAAC,CAAA,EAAG,sBAC9BE,IAAAA;AAAA,IAAC,GAAA;AAAA,IAAA;AAAA,MAEG,MAAM,CAAA,EAAG,UAAU,CAAA,UAAA,EAAa,CAAA,CAAE,EAAE,CAAA,iBAAA,EAAoB,kBAAA;AAAA,QACpD;AAAA,OACH,CAAA,EAAG,GAAA,GAAM,QAAA,GAAW,EAAE,CAAA,CAAA;AAAA,MACvB,2BAAyB,CAAA,CAAE,EAAA;AAAA,MAC3B,KAAA,EAAO;AAAA,QACH,OAAA,EAAS,MAAA;AAAA,QACT,UAAA,EAAY,QAAA;AAAA,QACZ,cAAA,EAAgB,QAAA;AAAA,QAChB,GAAA,EAAK,EAAA;AAAA,QACL,SAAA,EAAW,YAAA;AAAA,QACX,KAAA,EAAO,MAAA;AAAA,QACP,SAAA,EAAW,CAAA,KAAM,CAAA,GAAI,CAAA,GAAI,UAAA;AAAA,QACzB,OAAA,EAAS,iBAAA;AAAA,QACT,MAAA,EAAQ,kCAAA;AAAA,QACR,YAAA,EAAc,CAAA;AAAA,QACd,UAAA,EAAY,aAAA;AAAA,QACZ,KAAA,EAAO,kCAAA;AAAA,QACP,UAAA,EAAY,yCAAA;AAAA,QACZ,QAAA,EAAU,EAAA;AAAA,QACV,cAAA,EAAgB;AAAA,OACpB;AAAA,MAEA,QAAA,EAAA;AAAA,wBAAAF,GAAAA,CAAC,YAAA,EAAA,EAAa,EAAA,EAAI,CAAA,CAAE,EAAA,EAAI,CAAA;AAAA,wBACxBA,GAAAA,CAAC,MAAA,EAAA,EAAM,QAAA,EAAA,CAAA,CAAE,KAAA,EAAM;AAAA;AAAA,KAAA;AAAA,IAxBV,CAAA,CAAE;AAAA,GA0Bd,CAAA;AAID,EAAA,uBACIA,GAAAA;AAAA,IAAC,KAAA;AAAA,IAAA;AAAA,MACG,0BAAA,EAAyB,EAAA;AAAA,MACzB,KAAA,EAAO,QAAQ,EAAE,YAAA,EAAc,GAAE,GAAI,EAAE,WAAW,SAAA,EAAU;AAAA,MAE3D,QAAA,EAAA,KAAA,mBACGE,IAAAA,CAAAE,QAAAA,EAAA,EACK,QAAA,EAAA;AAAA,QAAA,OAAA;AAAA,QACA;AAAA,OAAA,EACL,CAAA,mBAEAF,IAAAA,CAAAE,QAAAA,EAAA,EACK,QAAA,EAAA;AAAA,QAAA,OAAA;AAAA,QACA;AAAA,OAAA,EACL;AAAA;AAAA,GAER;AAER;AAeA,SAAS,WAAW,EAAE,UAAA,EAAY,QAAA,EAAU,GAAA,EAAK,WAAU,EAAwC;AAC/F,EAAA,MAAM,CAAC,OAAA,EAAS,UAAU,CAAA,GAAUD,gBAAS,EAAE,CAAA;AAC/C,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAAwB,IAAI,CAAA;AAC5D,EAAA,MAAM,CAAC,UAAA,EAAY,aAAa,CAAA,GAAUA,gBAAS,KAAK,CAAA;AACxD,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAA8B,OAAO,CAAA;AAErE,EAAA,eAAe,OAAO,CAAA,EAAmC;AACrD,IAAA,CAAA,CAAE,cAAA,EAAe;AACjB,IAAA,MAAM,IAAA,GAAO,QAAQ,IAAA,EAAK;AAC1B,IAAA,IAAI,CAAC,IAAA,EAAM;AACP,MAAA,QAAA,CAAS,yBAAyB,CAAA;AAClC,MAAA;AAAA,IACJ;AACA,IAAA,QAAA,CAAS,IAAI,CAAA;AACb,IAAA,aAAA,CAAc,IAAI,CAAA;AAClB,IAAA,QAAA,CAAS,SAAS,CAAA;AAClB,IAAA,IAAI;AAEA,MAAA,MAAM,eAAe,MAAM,KAAA;AAAA,QACvB,CAAA,EAAG,UAAU,CAAA,oBAAA,EAAuB,kBAAA,CAAmB,IAAI,CAAC,CAAA,UAAA,EAAa,kBAAA,CAAmB,QAAQ,CAAC,CAAA,cAAA;AAAA,OACzG;AACA,MAAA,MAAM,SAAA,GAAa,MAAM,YAAA,CAAa,IAAA,EAAK;AAK3C,MAAA,IAAI,CAAC,aAAa,EAAA,IAAM,CAAC,UAAU,OAAA,IAAW,CAAC,UAAU,KAAA,EAAO;AAC5D,QAAA,MAAM,IAAI,KAAA,CAAM,SAAA,CAAU,KAAA,IAAS,kBAAkB,CAAA;AAAA,MACzD;AAWA,MAAA,IAAI,OAAA;AACJ,MAAA,IAAI;AAOA,QAAA,OAAA,GAAW,MAAM,OACb,6BACJ,CAAA;AAAA,MACJ,CAAA,CAAA,MAAQ;AACJ,QAAA,MAAM,IAAI,KAAA;AAAA,UACN;AAAA,SACJ;AAAA,MACJ;AACA,MAAA,MAAM,OAAA,GAAU,OAAA,CACX,aAAA,EAAc,CACd,MAAA,CAAO,CAAC,CAAA,KAAM,CAAA,CAAE,QAAA,IAAY,CAAA,CAAE,EAAA,KAAO,QAAQ,CAAA;AAClD,MAAA,IAAI,OAAA,CAAQ,WAAW,CAAA,EAAG;AACtB,QAAA,MAAM,IAAI,MAAM,mEAAgE,CAAA;AAAA,MACpF;AACA,MAAA,MAAM,MAAA,GAAS,QAAQ,CAAC,CAAA;AACxB,MAAA,MAAM,MAAA,GAAS,QAAQ,SAAA,CAAU,MAAA,CAAO,IAAI,EAAE,OAAA,EAAS,MAAM,CAAA;AAC7D,MAAA,MAAM,SAAA,GAAY,MAAM,MAAA,CAAO,SAAA,CAAU,OAAO,CAAA;AAIhD,MAAA,MAAM,GAAA,GAAM,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,gBAAA,CAAA,EAAoB;AAAA,QACrD,MAAA,EAAQ,MAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,QAC9C,IAAA,EAAM,KAAK,SAAA,CAAU;AAAA,UACjB,SAAS,SAAA,CAAU,OAAA;AAAA,UACnB,SAAA;AAAA,UACA,MAAA,EAAQ,QAAA;AAAA,UACR,eAAe,SAAA,CAAU,KAAA;AAAA,UACzB,gBAAA,EAAkB,QAAA;AAAA,UAClB,eAAA,EAAiB,OAAA;AAAA;AAAA;AAAA;AAAA;AAAA,UAKjB,GAAI,GAAA,GAAM,EAAE,GAAA,EAAK,IAAA,KAAS;AAAC,SAC9B;AAAA,OACJ,CAAA;AACD,MAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAC7B,MAAA,IAAI,CAAC,GAAA,CAAI,EAAA,IAAM,EAAE,IAAA,IAAQ,IAAA,CAAA,IAAS,CAAC,IAAA,CAAK,EAAA,IAAM,CAAC,IAAA,CAAK,OAAA,EAAS;AACzD,QAAA,MAAM,IAAI,KAAA;AAAA,UACL,QAAA,IAAY,IAAA,IAAQ,IAAA,CAAK,MAAA,IACrB,OAAA,IAAW,QAAQ,IAAA,CAAK,KAAA,IACzB,CAAA,cAAA,EAAiB,GAAA,CAAI,MAAM,CAAA;AAAA,SACnC;AAAA,MACJ;AACA,MAAA,SAAA,CAAU,IAAA,CAAK,OAAA,EAAS,IAAA,CAAK,KAAK,CAAA;AAAA,IACtC,SAAS,GAAA,EAAK;AACV,MAAA,MAAM,GAAA,GAAM,GAAA,YAAe,KAAA,GAAQ,GAAA,CAAI,OAAA,GAAU,gBAAA;AACjD,MAAA,QAAA,CAAS,GAAG,CAAA;AACZ,MAAA,aAAA,CAAc,KAAK,CAAA;AACnB,MAAA,QAAA,CAAS,OAAO,CAAA;AAAA,IACpB;AAAA,EACJ;AAEA,EAAA,uBACID,IAAAA,CAAC,MAAA,EAAA,EAAK,QAAA,EAAU,MAAA,EAAQ,yBAAsB,EAAA,EAC1C,QAAA,EAAA;AAAA,oBAAAF,GAAAA,CAAC,UAAA,EAAA,EAAW,KAAA,EAAM,qBAAA,EAAmB,QAAA,EAAA,iTAAA,EAKrC,CAAA;AAAA,oBACAA,GAAAA,CAAC,KAAA,EAAA,EAAM,QAAA,EAAA,iBAAA,EAAe,CAAA;AAAA,oBACtBA,GAAAA;AAAA,MAAC,OAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,MAAA;AAAA,QACL,KAAA,EAAO,OAAA;AAAA,QACP,QAAA,EAAU,CAAC,CAAA,KAAM;AACb,UAAA,UAAA,CAAW,CAAA,CAAE,OAAO,KAAK,CAAA;AACzB,UAAA,IAAI,KAAA,WAAgB,IAAI,CAAA;AAAA,QAC5B,CAAA;AAAA,QACA,WAAA,EAAY,sCAAA;AAAA,QACZ,YAAA,EAAa,KAAA;AAAA,QACb,cAAA,EAAe,MAAA;AAAA,QACf,UAAA,EAAY,KAAA;AAAA,QACZ,QAAA,EAAQ,IAAA;AAAA,QACR,cAAA,EAAc,QAAQ,IAAA,GAAO,MAAA;AAAA,QAC7B,KAAA,EAAOK;AAAA;AAAA,KACX;AAAA,IACC,KAAA,oBAASL,GAAAA,CAACM,UAAAA,EAAA,EAAW,QAAA,EAAA,KAAA,EAAM,CAAA;AAAA,oBAC5BN,GAAAA;AAAA,MAAC,QAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,QAAA;AAAA,QACL,QAAA,EAAU,UAAA,IAAc,CAAC,OAAA,CAAQ,IAAA,EAAK;AAAA,QACtC,OAAO,WAAA,CAAY,UAAA,IAAc,CAAC,OAAA,CAAQ,MAAM,CAAA;AAAA,QAE/C,QAAA,EAAA,KAAA,KAAU,SAAA,IAAa,UAAA,GAClB,0BAAA,GACA;AAAA;AAAA,KACV;AAAA,oBACAA,GAAAA,CAAC,IAAA,EAAA,EAAK,QAAA,EAAA,8GAAA,EAGN;AAAA,GAAA,EACJ,CAAA;AAER;AAMA,SAAS,SAAA,CAAU,EAAE,UAAA,EAAY,GAAA,EAAK,WAAU,EAAkC;AAC9E,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUG,gBAAqB,OAAO,CAAA;AAC5D,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAAS,EAAE,CAAA;AAC3C,EAAA,MAAM,CAAC,UAAA,EAAY,aAAa,CAAA,GAAUA,gBAAwB,IAAI,CAAA;AACtE,EAAA,MAAM,CAAC,IAAA,EAAM,OAAO,CAAA,GAAUA,gBAAS,EAAE,CAAA;AACzC,EAAA,MAAM,CAAC,SAAA,EAAW,YAAY,CAAA,GAAUA,gBAAwB,IAAI,CAAA;AACpE,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAAwB,IAAI,CAAA;AAC5D,EAAA,MAAM,CAAC,UAAA,EAAY,aAAa,CAAA,GAAUA,gBAAS,KAAK,CAAA;AAExD,EAAA,eAAe,MAAM,CAAA,EAAmC;AACpD,IAAA,CAAA,CAAE,cAAA,EAAe;AACjB,IAAA,MAAM,OAAA,GAAU,KAAA,CAAM,IAAA,EAAK,CAAE,WAAA,EAAY;AACzC,IAAA,IAAI,CAAC,OAAA,IAAW,CAAC,WAAA,CAAY,IAAA,CAAK,OAAO,CAAA,EAAG;AACxC,MAAA,aAAA,CAAc,qBAAqB,CAAA;AACnC,MAAA;AAAA,IACJ;AACA,IAAA,aAAA,CAAc,IAAI,CAAA;AAClB,IAAA,aAAA,CAAc,IAAI,CAAA;AAClB,IAAA,IAAI;AACA,MAAA,MAAM,GAAA,GAAM,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,yBAAA,CAAA,EAA6B;AAAA,QAC9D,MAAA,EAAQ,MAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,QAC9C,MAAM,IAAA,CAAK,SAAA,CAAU,EAAE,KAAA,EAAO,SAAS;AAAA,OAC1C,CAAA;AACD,MAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAC7B,MAAA,IAAI,CAAC,GAAA,CAAI,EAAA,IAAM,CAAC,KAAK,KAAA,EAAO;AACxB,QAAA,MAAM,IAAI,KAAA,CAAM,IAAA,CAAK,UAAU,CAAA,cAAA,EAAiB,GAAA,CAAI,MAAM,CAAA,CAAA,CAAG,CAAA;AAAA,MACjE;AACA,MAAA,QAAA,CAAS,KAAK,KAAK,CAAA;AACnB,MAAA,QAAA,CAAS,OAAO,CAAA;AAChB,MAAA,QAAA,CAAS,MAAM,CAAA;AAAA,IACnB,SAAS,GAAA,EAAK;AACV,MAAA,aAAA,CAAc,GAAA,YAAe,KAAA,GAAQ,GAAA,CAAI,OAAA,GAAU,qBAAqB,CAAA;AAAA,IAC5E,CAAA,SAAE;AACE,MAAA,aAAA,CAAc,KAAK,CAAA;AAAA,IACvB;AAAA,EACJ;AAEA,EAAA,eAAe,OAAO,CAAA,EAAmC;AACrD,IAAA,CAAA,CAAE,cAAA,EAAe;AACjB,IAAA,IAAI,CAAC,KAAA,EAAO;AACZ,IAAA,IAAI,IAAA,CAAK,WAAW,CAAA,EAAG;AACnB,MAAA,YAAA,CAAa,UAAU,CAAA;AACvB,MAAA;AAAA,IACJ;AACA,IAAA,YAAA,CAAa,IAAI,CAAA;AACjB,IAAA,aAAA,CAAc,IAAI,CAAA;AAClB,IAAA,IAAI;AACA,MAAA,MAAM,GAAA,GAAM,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,0BAAA,CAAA,EAA8B;AAAA,QAC/D,MAAA,EAAQ,MAAA;AAAA,QACR,WAAA,EAAa,SAAA;AAAA,QACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,QAC9C,IAAA,EAAM,KAAK,SAAA,CAAU;AAAA,UACjB,KAAA;AAAA,UACA,IAAA;AAAA,UACA,KAAA;AAAA;AAAA,UAEA,GAAI,GAAA,GAAM,EAAE,GAAA,EAAK,IAAA,KAAS;AAAC,SAC9B;AAAA,OACJ,CAAA;AACD,MAAA,MAAM,IAAA,GAAQ,MAAM,GAAA,CAAI,IAAA,EAAK;AAC7B,MAAA,IAAI,CAAC,GAAA,CAAI,EAAA,IAAM,EAAE,IAAA,IAAQ,IAAA,CAAA,IAAS,CAAC,IAAA,CAAK,EAAA,IAAM,CAAC,IAAA,CAAK,OAAA,EAAS;AACzD,QAAA,MAAM,IAAI,KAAA;AAAA,UACL,QAAA,IAAY,IAAA,IAAQ,IAAA,CAAK,MAAA,IACrB,OAAA,IAAW,QAAQ,IAAA,CAAK,KAAA,IACzB,CAAA,eAAA,EAAkB,GAAA,CAAI,MAAM,CAAA,CAAA;AAAA,SACpC;AAAA,MACJ;AACA,MAAA,SAAA,CAAU,IAAA,CAAK,OAAA,EAAS,IAAA,CAAK,KAAK,CAAA;AAAA,IACtC,SAAS,GAAA,EAAK;AACV,MAAA,YAAA,CAAa,GAAA,YAAe,KAAA,GAAQ,GAAA,CAAI,OAAA,GAAU,eAAe,CAAA;AAAA,IACrE,CAAA,SAAE;AACE,MAAA,aAAA,CAAc,KAAK,CAAA;AAAA,IACvB;AAAA,EACJ;AAEA,EAAA,IAAI,UAAU,OAAA,EAAS;AACnB,IAAA,uBACID,IAAAA,CAAC,MAAA,EAAA,EAAK,QAAA,EAAU,KAAA,EAAO,wBAAqB,EAAA,EACxC,QAAA,EAAA;AAAA,sBAAAF,GAAAA,CAAC,UAAA,EAAA,EAAW,KAAA,EAAM,kBAAA,EAAgB,QAAA,EAAA,yJAAA,EAGlC,CAAA;AAAA,sBACAA,GAAAA,CAAC,KAAA,EAAA,EAAM,QAAA,EAAA,OAAA,EAAK,CAAA;AAAA,sBACZA,GAAAA;AAAA,QAAC,OAAA;AAAA,QAAA;AAAA,UACG,IAAA,EAAK,OAAA;AAAA,UACL,YAAA,EAAa,OAAA;AAAA,UACb,KAAA,EAAO,KAAA;AAAA,UACP,QAAA,EAAU,CAAC,CAAA,KAAM;AACb,YAAA,QAAA,CAAS,CAAA,CAAE,OAAO,KAAK,CAAA;AACvB,YAAA,IAAI,UAAA,gBAA0B,IAAI,CAAA;AAAA,UACtC,CAAA;AAAA,UACA,WAAA,EAAY,iBAAA;AAAA,UACZ,QAAA,EAAQ,IAAA;AAAA,UACR,cAAA,EAAc,aAAa,IAAA,GAAO,MAAA;AAAA,UAClC,KAAA,EAAOK;AAAA;AAAA,OACX;AAAA,MACC,UAAA,oBAAcL,GAAAA,CAACM,UAAAA,EAAA,EAAW,QAAA,EAAA,UAAA,EAAW,CAAA;AAAA,sBACtCN,GAAAA,CAAC,QAAA,EAAA,EAAO,IAAA,EAAK,QAAA,EAAS,QAAA,EAAU,UAAA,EAAY,KAAA,EAAO,WAAA,CAAY,UAAU,CAAA,EACpE,QAAA,EAAA,UAAA,GAAa,kBAAa,2BAAA,EAC/B,CAAA;AAAA,sBACAA,GAAAA,CAAC,IAAA,EAAA,EAAK,QAAA,EAAA,qEAAA,EAEN;AAAA,KAAA,EACJ,CAAA;AAAA,EAER;AAEA,EAAA,uBACIE,IAAAA,CAAC,MAAA,EAAA,EAAK,QAAA,EAAU,MAAA,EAAQ,+BAA4B,EAAA,EAChD,QAAA,EAAA;AAAA,oBAAAA,IAAAA,CAAC,UAAA,EAAA,EAAW,KAAA,EAAM,qBAAA,EAAmB,QAAA,EAAA;AAAA,MAAA,yBAAA;AAAA,sBACVF,IAAC,MAAA,EAAA,EAAK,KAAA,EAAO,EAAE,KAAA,EAAO,4BAAA,IAAiC,QAAA,EAAA,KAAA,EAAM,CAAA;AAAA,MAAO;AAAA,KAAA,EAE/F,CAAA;AAAA,oBACAA,GAAAA,CAAC,KAAA,EAAA,EAAM,QAAA,EAAA,eAAA,EAAa,CAAA;AAAA,oBACpBA,GAAAA;AAAA,MAAC,OAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,MAAA;AAAA,QACL,SAAA,EAAU,SAAA;AAAA,QACV,OAAA,EAAQ,QAAA;AAAA,QACR,SAAA,EAAW,CAAA;AAAA,QACX,YAAA,EAAa,eAAA;AAAA,QACb,KAAA,EAAO,IAAA;AAAA,QACP,QAAA,EAAU,CAAC,CAAA,KAAM;AACb,UAAA,OAAA,CAAQ,CAAA,CAAE,MAAA,CAAO,KAAA,CAAM,OAAA,CAAQ,KAAA,EAAO,EAAE,CAAA,CAAE,KAAA,CAAM,CAAA,EAAG,CAAC,CAAC,CAAA;AACrD,UAAA,IAAI,SAAA,eAAwB,IAAI,CAAA;AAAA,QACpC,CAAA;AAAA,QACA,WAAA,EAAY,UAAA;AAAA,QACZ,QAAA,EAAQ,IAAA;AAAA,QACR,SAAA,EAAS,IAAA;AAAA,QACT,cAAA,EAAc,YAAY,IAAA,GAAO,MAAA;AAAA,QACjC,OAAO,EAAE,GAAGK,aAAY,aAAA,EAAe,OAAA,EAAS,UAAU,EAAA;AAAG;AAAA,KACjE;AAAA,IACC,SAAA,oBAAaL,GAAAA,CAACM,UAAAA,EAAA,EAAW,QAAA,EAAA,SAAA,EAAU,CAAA;AAAA,oBACpCN,GAAAA;AAAA,MAAC,QAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,QAAA;AAAA,QACL,QAAA,EAAU,UAAA,IAAc,IAAA,CAAK,MAAA,KAAW,CAAA;AAAA,QACxC,KAAA,EAAO,WAAA,CAAY,UAAA,IAAc,IAAA,CAAK,WAAW,CAAC,CAAA;AAAA,QAEjD,uBAAa,iBAAA,GAAe;AAAA;AAAA,KACjC;AAAA,oBACAA,GAAAA;AAAA,MAAC,QAAA;AAAA,MAAA;AAAA,QACG,IAAA,EAAK,QAAA;AAAA,QACL,SAAS,MAAM;AACX,UAAA,QAAA,CAAS,OAAO,CAAA;AAChB,UAAA,OAAA,CAAQ,EAAE,CAAA;AACV,UAAA,QAAA,CAAS,IAAI,CAAA;AAAA,QACjB,CAAA;AAAA,QACA,KAAA,EAAO;AAAA,UACH,SAAA,EAAW,EAAA;AAAA,UACX,UAAA,EAAY,aAAA;AAAA,UACZ,MAAA,EAAQ,MAAA;AAAA,UACR,KAAA,EAAO,kCAAA;AAAA,UACP,UAAA,EAAY,yCAAA;AAAA,UACZ,QAAA,EAAU,EAAA;AAAA,UACV,aAAA,EAAe,QAAA;AAAA,UACf,aAAA,EAAe,WAAA;AAAA,UACf,MAAA,EAAQ,SAAA;AAAA,UACR,OAAA,EAAS;AAAA,SACb;AAAA,QACH,QAAA,EAAA;AAAA;AAAA,KAED;AAAA,oBACAA,GAAAA,CAAC,IAAA,EAAA,EAAK,QAAA,EAAA,8DAAA,EAA4D;AAAA,GAAA,EACtE,CAAA;AAER;AAIA,SAAS,UAAA,CAAW;AAAA,EAChB,KAAA;AAAA,EACA;AACJ,CAAA,EAGuB;AACnB,EAAA,uBACIE,IAAAA,CAAC,KAAA,EAAA,EAAI,OAAO,EAAE,YAAA,EAAc,IAAG,EAC3B,QAAA,EAAA;AAAA,oBAAAF,GAAAA;AAAA,MAAC,KAAA;AAAA,MAAA;AAAA,QACG,KAAA,EAAO;AAAA,UACH,KAAA,EAAO,yBAAA;AAAA,UACP,UAAA,EAAY,yCAAA;AAAA,UACZ,QAAA,EAAU,EAAA;AAAA,UACV,aAAA,EAAe,QAAA;AAAA,UACf,aAAA,EAAe,WAAA;AAAA,UACf,YAAA,EAAc;AAAA,SAClB;AAAA,QAEC,QAAA,EAAA;AAAA;AAAA,KACL;AAAA,oBACAA,GAAAA;AAAA,MAAC,GAAA;AAAA,MAAA;AAAA,QACG,KAAA,EAAO;AAAA,UACH,KAAA,EAAO,kCAAA;AAAA,UACP,QAAA,EAAU,EAAA;AAAA,UACV,UAAA,EAAY,IAAA;AAAA,UACZ,MAAA,EAAQ;AAAA,SACZ;AAAA,QAEC;AAAA;AAAA;AACL,GAAA,EACJ,CAAA;AAER;AAEA,SAAS,KAAA,CAAM,EAAE,QAAA,EAAS,EAAsD;AAC5E,EAAA,uBACIA,GAAAA;AAAA,IAAC,OAAA;AAAA,IAAA;AAAA,MACG,KAAA,EAAO;AAAA,QACH,OAAA,EAAS,OAAA;AAAA,QACT,KAAA,EAAO,4BAAA;AAAA,QACP,UAAA,EAAY,yCAAA;AAAA,QACZ,QAAA,EAAU,EAAA;AAAA,QACV,aAAA,EAAe,QAAA;AAAA,QACf,aAAA,EAAe,WAAA;AAAA,QACf,YAAA,EAAc;AAAA,OAClB;AAAA,MAEC;AAAA;AAAA,GACL;AAER;AAEA,IAAMK,WAAAA,GAAkC;AAAA,EACpC,KAAA,EAAO,MAAA;AAAA,EACP,OAAA,EAAS,iBAAA;AAAA,EACT,UAAA,EAAY,4BAAA;AAAA,EACZ,KAAA,EAAO,4BAAA;AAAA,EACP,MAAA,EAAQ,iCAAA;AAAA,EACR,YAAA,EAAc,CAAA;AAAA,EACd,UAAA,EAAY,yCAAA;AAAA;AAAA;AAAA;AAAA,EAIZ,QAAA,EAAU,EAAA;AAAA,EACV,OAAA,EAAS;AACb,CAAA;AAEA,IAAM,aAAA,GAAqC;AAAA,EACvC,OAAA,EAAS,MAAA;AAAA,EACT,UAAA,EAAY,YAAA;AAAA,EACZ,GAAA,EAAK,CAAA;AAAA,EACL,SAAA,EAAW,EAAA;AAAA,EACX,UAAA,EAAY,EAAA;AAAA,EACZ,SAAA,EAAW,kCAAA;AAAA,EACX,KAAA,EAAO,kCAAA;AAAA,EACP,UAAA,EAAY,yCAAA;AAAA,EACZ,QAAA,EAAU,EAAA;AAAA,EACV,UAAA,EAAY,GAAA;AAAA,EACZ,MAAA,EAAQ;AACZ,CAAA;AAEA,SAAS,YAAY,QAAA,EAAwC;AACzD,EAAA,OAAO;AAAA,IACH,SAAA,EAAW,EAAA;AAAA,IACX,OAAA,EAAS,aAAA;AAAA,IACT,UAAA,EAAY,yBAAA;AAAA,IACZ,KAAA,EAAO,oCAAA;AAAA,IACP,MAAA,EAAQ,MAAA;AAAA,IACR,YAAA,EAAc,CAAA;AAAA,IACd,UAAA,EAAY,yCAAA;AAAA,IACZ,QAAA,EAAU,EAAA;AAAA,IACV,aAAA,EAAe,QAAA;AAAA,IACf,aAAA,EAAe,WAAA;AAAA,IACf,UAAA,EAAY,GAAA;AAAA,IACZ,MAAA,EAAQ,WAAW,aAAA,GAAgB,SAAA;AAAA,IACnC,OAAA,EAAS,WAAW,GAAA,GAAM,CAAA;AAAA,IAC1B,KAAA,EAAO;AAAA,GACX;AACJ;AAEA,SAASC,UAAAA,CAAU,EAAE,QAAA,EAAS,EAAsD;AAChF,EAAA,uBACIN,GAAAA;AAAA,IAAC,GAAA;AAAA,IAAA;AAAA,MACG,IAAA,EAAK,OAAA;AAAA,MACL,KAAA,EAAO;AAAA,QACH,SAAA,EAAW,CAAA;AAAA,QACX,YAAA,EAAc,CAAA;AAAA,QACd,KAAA,EAAO,6BAAA;AAAA,QACP,UAAA,EAAY,yCAAA;AAAA,QACZ,QAAA,EAAU,EAAA;AAAA,QACV,aAAA,EAAe;AAAA,OACnB;AAAA,MAEC;AAAA;AAAA,GACL;AAER;AAEA,SAAS,IAAA,CAAK,EAAE,QAAA,EAAS,EAAsD;AAC3E,EAAA,uBACIE,IAAAA;AAAA,IAAC,GAAA;AAAA,IAAA;AAAA,MACG,KAAA,EAAO;AAAA,QACH,SAAA,EAAW,EAAA;AAAA,QACX,YAAA,EAAc,CAAA;AAAA,QACd,KAAA,EAAO,kCAAA;AAAA,QACP,UAAA,EAAY,yCAAA;AAAA,QACZ,QAAA,EAAU,IAAA;AAAA,QACV,UAAA,EAAY,IAAA;AAAA,QACZ,OAAA,EAAS;AAAA,OACb;AAAA,MAEC,QAAA,EAAA;AAAA,QAAA,IAAA;AAAA,QACA;AAAA;AAAA;AAAA,GACL;AAER;ACnsCA,SAAS,kBAAkB,IAAA,EAA8C;AACrE,EAAA,IAAI,CAAC,IAAA,EAAM,OAAO,aAAA,CAAc,MAAS,CAAA,CAAE,UAAA;AAC3C,EAAA,OAAO,aAAA,CAAc,IAAoB,CAAA,CAAE,UAAA;AAC/C;AASA,SAAS,aAAa,GAAA,EAAuB;AACzC,EAAA,IAAI,EAAE,GAAA,YAAe,KAAA,CAAA,EAAQ,OAAO,KAAA;AACpC,EAAA,OAAO,2CAAA,CAA4C,IAAA,CAAK,GAAA,CAAI,OAAO,CAAA;AACvE;AAeO,SAAS,oBAAoB,IAAA,EAAkD;AAClF,EAAA,MAAM,UAAA,GAAa,kBAAkB,IAAI,CAAA;AACzC,EAAA,MAAM,CAAC,MAAA,EAAQ,SAAS,CAAA,GAAUK,gBAAiC,MAAM,CAAA;AACzE,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAAuB,IAAI,CAAA;AAE3D,EAAA,MAAM,KAAA,GAAcA,mBAAY,MAAM;AAClC,IAAA,SAAA,CAAU,MAAM,CAAA;AAChB,IAAA,QAAA,CAAS,IAAI,CAAA;AAAA,EACjB,CAAA,EAAG,EAAE,CAAA;AAEL,EAAA,MAAM,QAAA,GAAiBA,MAAA,CAAA,WAAA;AAAA,IACnB,OAAO,IAAA,KAA+D;AAClE,MAAA,QAAA,CAAS,IAAI,CAAA;AACb,MAAA,SAAA,CAAU,oBAAoB,CAAA;AAC9B,MAAA,IAAI;AACA,QAAA,MAAM,OAAA,GAAU,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,mCAAA,CAAA,EAAuC;AAAA,UAC5E,MAAA,EAAQ,MAAA;AAAA,UACR,WAAA,EAAa,SAAA;AAAA,UACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,UAC9C,MAAM,IAAA,CAAK,SAAA,CAAU,EAAE,KAAA,EAAO,IAAA,EAAM,OAAO;AAAA,SAC9C,CAAA;AACD,QAAA,MAAM,QAAA,GAAY,MAAM,OAAA,CAAQ,IAAA,EAAK;AACrC,QAAA,IAAI,CAAC,OAAA,CAAQ,EAAA,IAAM,CAAC,QAAA,CAAS,EAAA,IAAM,CAAC,QAAA,CAAS,OAAA,IAAW,CAAC,QAAA,CAAS,eAAA,EAAiB;AAC/E,UAAA,MAAM,MAAA,GAAS,QAAA,CAAS,MAAA,IAAU,CAAA,eAAA,EAAkB,QAAQ,MAAM,CAAA,CAAA;AAClE,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,SAAA,CAAU,OAAO,CAAA;AACjB,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AACA,QAAA,SAAA,CAAU,gBAAgB,CAAA;AAC1B,QAAA,IAAI,WAAA;AACJ,QAAA,IAAI;AACA,UAAA,WAAA,GAAc,MAAM,iBAAA,CAAkB,EAAE,WAAA,EAAa,QAAA,CAAS,SAAS,CAAA;AAAA,QAC3E,SAAS,CAAA,EAAG;AACR,UAAA,MAAM,MAAA,GAAS,YAAA,CAAa,CAAC,CAAA,GAAI,cAAe,CAAA,CAAY,OAAA;AAC5D,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,SAAA,CAAU,OAAO,CAAA;AACjB,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AACA,QAAA,SAAA,CAAU,WAAW,CAAA;AACrB,QAAA,MAAM,SAAA,GAAY,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,kCAAA,CAAA,EAAsC;AAAA,UAC7E,MAAA,EAAQ,MAAA;AAAA,UACR,WAAA,EAAa,SAAA;AAAA,UACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,UAC9C,IAAA,EAAM,KAAK,SAAA,CAAU;AAAA,YACjB,iBAAiB,QAAA,CAAS,eAAA;AAAA,YAC1B,QAAA,EAAU,WAAA;AAAA,YACV,OAAO,IAAA,EAAM;AAAA,WAChB;AAAA,SACJ,CAAA;AACD,QAAA,MAAM,UAAA,GAAc,MAAM,SAAA,CAAU,IAAA,EAAK;AAKzC,QAAA,IAAI,CAAC,UAAU,EAAA,IAAM,CAAC,WAAW,EAAA,IAAM,CAAC,WAAW,UAAA,EAAY;AAC3D,UAAA,MAAM,MAAA,GAAS,UAAA,CAAW,MAAA,IAAU,CAAA,cAAA,EAAiB,UAAU,MAAM,CAAA,CAAA;AACrE,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,SAAA,CAAU,OAAO,CAAA;AACjB,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AACA,QAAA,SAAA,CAAU,SAAS,CAAA;AACnB,QAAA,OAAO,EAAE,EAAA,EAAI,IAAA,EAAM,UAAA,EAAY,WAAW,UAAA,EAAW;AAAA,MACzD,SAAS,CAAA,EAAG;AACR,QAAA,MAAM,SAAS,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,OAAO,CAAC,CAAA;AACxD,QAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,QAAA,SAAA,CAAU,OAAO,CAAA;AACjB,QAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,MAC/B;AAAA,IACJ,CAAA;AAAA,IACA,CAAC,UAAU;AAAA,GACf;AAEA,EAAA,OAAO,EAAE,MAAA,EAAQ,KAAA,EAAO,QAAA,EAAU,KAAA,EAAM;AAC5C;AAqBO,SAAS,gBAAgB,IAAA,EAA8C;AAC1E,EAAA,MAAM,UAAA,GAAa,kBAAkB,IAAI,CAAA;AACzC,EAAA,MAAM,EAAE,MAAA,EAAQ,aAAA,EAAc,GAAI,YAAA,EAAa;AAC/C,EAAA,MAAM,CAAC,WAAA,EAAa,cAAc,CAAA,GAAUA,MAAA,CAAA,QAAA,CAAqC,EAAE,CAAA;AACnF,EAAA,MAAM,CAAC,MAAA,EAAQ,SAAS,CAAA,GAAUA,gBAA6B,SAAS,CAAA;AACxE,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAAuB,IAAI,CAAA;AAE3D,EAAA,MAAM,OAAA,GAAgBA,mBAAY,YAAY;AAC1C,IAAA,QAAA,CAAS,IAAI,CAAA;AACb,IAAA,IAAI,kBAAkB,eAAA,EAAiB;AACnC,MAAA,cAAA,CAAe,EAAE,CAAA;AACjB,MAAA,SAAA,CAAU,OAAO,CAAA;AACjB,MAAA;AAAA,IACJ;AACA,IAAA,SAAA,CAAU,SAAS,CAAA;AACnB,IAAA,IAAI;AACA,MAAA,MAAM,CAAA,GAAI,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,8BAAA,CAAA,EAAkC;AAAA,QACjE,WAAA,EAAa;AAAA,OAChB,CAAA;AACD,MAAA,IAAI,CAAA,CAAE,WAAW,GAAA,EAAK;AAClB,QAAA,cAAA,CAAe,EAAE,CAAA;AACjB,QAAA,SAAA,CAAU,OAAO,CAAA;AACjB,QAAA;AAAA,MACJ;AACA,MAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,EAAK;AAKxB,MAAA,IAAI,CAAC,CAAA,CAAE,EAAA,IAAM,CAAC,EAAE,WAAA,EAAa;AACzB,QAAA,MAAM,IAAI,KAAA,CAAM,CAAA,CAAE,MAAA,IAAU,aAAa,CAAA;AAAA,MAC7C;AACA,MAAA,cAAA,CAAe,EAAE,WAAW,CAAA;AAC5B,MAAA,SAAA,CAAU,OAAO,CAAA;AAAA,IACrB,SAAS,CAAA,EAAG;AACR,MAAA,QAAA,CAAS,CAAA,YAAa,QAAQ,CAAA,GAAI,IAAI,MAAM,MAAA,CAAO,CAAC,CAAC,CAAC,CAAA;AACtD,MAAA,SAAA,CAAU,OAAO,CAAA;AAAA,IACrB;AAAA,EACJ,CAAA,EAAG,CAAC,UAAA,EAAY,aAAa,CAAC,CAAA;AAE9B,EAAMA,iBAAU,MAAM;AAClB,IAAA,KAAK,OAAA,EAAQ;AAAA,EACjB,CAAA,EAAG,CAAC,OAAO,CAAC,CAAA;AAEZ,EAAA,MAAM,MAAA,GAAeA,MAAA,CAAA,WAAA;AAAA,IACjB,OAAO,IAAY,KAAA,KAAiD;AAChE,MAAA,IAAI;AACA,QAAA,MAAM,IAAI,MAAM,KAAA,CAAM,GAAG,UAAU,CAAA,+BAAA,EAAkC,EAAE,CAAA,CAAA,EAAI;AAAA,UACvE,MAAA,EAAQ,OAAA;AAAA,UACR,WAAA,EAAa,SAAA;AAAA,UACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,UAC9C,IAAA,EAAM,IAAA,CAAK,SAAA,CAAU,EAAE,OAAO;AAAA,SACjC,CAAA;AACD,QAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,EAAK;AAKxB,QAAA,IAAI,CAAC,CAAA,CAAE,EAAA,IAAM,CAAC,EAAE,UAAA,EAAY;AACxB,UAAA,MAAM,MAAA,GAAS,CAAA,CAAE,MAAA,IAAU,CAAA,cAAA,EAAiB,EAAE,MAAM,CAAA,CAAA;AACpD,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AACA,QAAA,MAAM,OAAA,EAAQ;AACd,QAAA,OAAO,EAAE,EAAA,EAAI,IAAA,EAAM,UAAA,EAAY,EAAE,UAAA,EAAW;AAAA,MAChD,SAAS,CAAA,EAAG;AACR,QAAA,MAAM,SAAS,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,OAAO,CAAC,CAAA;AACxD,QAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,QAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,MAC/B;AAAA,IACJ,CAAA;AAAA,IACA,CAAC,YAAY,OAAO;AAAA,GACxB;AAEA,EAAA,MAAM,MAAA,GAAeA,MAAA,CAAA,WAAA;AAAA,IACjB,OAAO,EAAA,KAA8C;AACjD,MAAA,IAAI;AACA,QAAA,MAAM,IAAI,MAAM,KAAA,CAAM,GAAG,UAAU,CAAA,+BAAA,EAAkC,EAAE,CAAA,CAAA,EAAI;AAAA,UACvE,MAAA,EAAQ,QAAA;AAAA,UACR,WAAA,EAAa;AAAA,SAChB,CAAA;AACD,QAAA,MAAM,CAAA,GAAK,MAAM,CAAA,CAAE,IAAA,EAAK;AACxB,QAAA,IAAI,CAAC,EAAE,EAAA,EAAI;AACP,UAAA,MAAM,MAAA,GAAS,CAAA,CAAE,MAAA,IAAU,CAAA,cAAA,EAAiB,EAAE,MAAM,CAAA,CAAA;AACpD,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AACA,QAAA,MAAM,OAAA,EAAQ;AACd,QAAA,OAAO,EAAE,IAAI,IAAA,EAAK;AAAA,MACtB,SAAS,CAAA,EAAG;AACR,QAAA,MAAM,SAAS,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,OAAO,CAAC,CAAA;AACxD,QAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,QAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,MAC/B;AAAA,IACJ,CAAA;AAAA,IACA,CAAC,YAAY,OAAO;AAAA,GACxB;AAEA,EAAA,OAAO,EAAE,MAAA,EAAQ,WAAA,EAAa,KAAA,EAAO,OAAA,EAAS,QAAQ,MAAA,EAAO;AACjE;AAoCO,SAAS,cAAc,IAAA,EAA4C;AACtE,EAAA,MAAM,UAAA,GAAa,kBAAkB,IAAI,CAAA;AACzC,EAAA,MAAM,EAAE,OAAA,EAAQ,GAAI,YAAA,EAAa;AACjC,EAAA,MAAM,CAAC,MAAA,EAAQ,SAAS,CAAA,GAAUA,gBAAkC,MAAM,CAAA;AAC1E,EAAA,MAAM,CAAC,KAAA,EAAO,QAAQ,CAAA,GAAUA,gBAAuB,IAAI,CAAA;AAE3D,EAAA,MAAM,KAAA,GAAcA,mBAAY,MAAM;AAClC,IAAA,SAAA,CAAU,MAAM,CAAA;AAChB,IAAA,QAAA,CAAS,IAAI,CAAA;AAAA,EACjB,CAAA,EAAG,EAAE,CAAA;AAEL,EAAA,MAAM,MAAA,GAAeA,MAAA,CAAA,WAAA;AAAA,IACjB,OAAO,IAAA,KAA6D;AAChE,MAAA,QAAA,CAAS,IAAI,CAAA;AACb,MAAA,SAAA,CAAU,oBAAoB,CAAA;AAC9B,MAAA,IAAI;AACA,QAAA,MAAM,OAAA,GAAU,MAAM,KAAA,CAAM,CAAA,EAAG,UAAU,CAAA,oCAAA,CAAA,EAAwC;AAAA,UAC7E,MAAA,EAAQ,MAAA;AAAA,UACR,WAAA,EAAa,SAAA;AAAA,UACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,UAC9C,MAAM,IAAA,CAAK,SAAA,CAAU,EAAE,OAAA,EAAS,IAAA,CAAK,SAAS;AAAA,SACjD,CAAA;AACD,QAAA,MAAM,QAAA,GAAY,MAAM,OAAA,CAAQ,IAAA,EAAK;AACrC,QAAA,IAAI,CAAC,OAAA,CAAQ,EAAA,IAAM,CAAC,QAAA,CAAS,EAAA,IAAM,CAAC,QAAA,CAAS,OAAA,IAAW,CAAC,QAAA,CAAS,eAAA,EAAiB;AAC/E,UAAA,MAAM,MAAA,GAAS,QAAA,CAAS,MAAA,IAAU,CAAA,eAAA,EAAkB,QAAQ,MAAM,CAAA,CAAA;AAClE,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,SAAA,CAAU,OAAO,CAAA;AACjB,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AACA,QAAA,SAAA,CAAU,gBAAgB,CAAA;AAC1B,QAAA,IAAI,SAAA;AACJ,QAAA,IAAI;AACA,UAAA,SAAA,GAAY,MAAM,mBAAA,CAAoB,EAAE,WAAA,EAAa,QAAA,CAAS,SAAS,CAAA;AAAA,QAC3E,SAAS,CAAA,EAAG;AACR,UAAA,MAAM,MAAA,GAAS,YAAA,CAAa,CAAC,CAAA,GAAI,cAAe,CAAA,CAAY,OAAA;AAC5D,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,SAAA,CAAU,OAAO,CAAA;AACjB,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AACA,QAAA,SAAA,CAAU,WAAW,CAAA;AACrB,QAAA,MAAM,YAAY,MAAM,KAAA;AAAA,UACpB,GAAG,UAAU,CAAA,mCAAA,CAAA;AAAA,UACb;AAAA,YACI,MAAA,EAAQ,MAAA;AAAA,YACR,WAAA,EAAa,SAAA;AAAA,YACb,OAAA,EAAS,EAAE,cAAA,EAAgB,kBAAA,EAAmB;AAAA,YAC9C,IAAA,EAAM,KAAK,SAAA,CAAU;AAAA,cACjB,iBAAiB,QAAA,CAAS,eAAA;AAAA,cAC1B,QAAA,EAAU;AAAA,aACb;AAAA;AACL,SACJ;AACA,QAAA,MAAM,UAAA,GAAc,MAAM,SAAA,CAAU,IAAA,EAAK;AAKzC,QAAA,IAAI,CAAC,UAAU,EAAA,IAAM,CAAC,WAAW,EAAA,IAAM,OAAO,UAAA,CAAW,UAAA,KAAe,QAAA,EAAU;AAC9E,UAAA,MAAM,MAAA,GAAS,UAAA,CAAW,MAAA,IAAU,CAAA,cAAA,EAAiB,UAAU,MAAM,CAAA,CAAA;AACrE,UAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,UAAA,SAAA,CAAU,OAAO,CAAA;AACjB,UAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,QAC/B;AAGA,QAAA,MAAM,OAAA,EAAQ;AACd,QAAA,SAAA,CAAU,SAAS,CAAA;AACnB,QAAA,OAAO,EAAE,EAAA,EAAI,IAAA,EAAM,UAAA,EAAY,WAAW,UAAA,EAAW;AAAA,MACzD,SAAS,CAAA,EAAG;AACR,QAAA,MAAM,SAAS,CAAA,YAAa,KAAA,GAAQ,CAAA,CAAE,OAAA,GAAU,OAAO,CAAC,CAAA;AACxD,QAAA,QAAA,CAAS,IAAI,KAAA,CAAM,MAAM,CAAC,CAAA;AAC1B,QAAA,SAAA,CAAU,OAAO,CAAA;AACjB,QAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,MAC/B;AAAA,IACJ,CAAA;AAAA,IACA,CAAC,YAAY,OAAO;AAAA,GACxB;AAEA,EAAA,OAAO,EAAE,MAAA,EAAQ,KAAA,EAAO,MAAA,EAAQ,KAAA,EAAM;AAC1C","file":"index.mjs","sourcesContent":["/**\n * The kinds of identity a user can surface as their account-badge\n * label. `did` is the canonical `did:oc` identifier — always available\n * and the ultimate fallback; the other three are linked identities a\n * user may or may not have.\n */\nexport const DISPLAY_IDENTITY_KINDS = ['did', 'btc', 'email', 'nostr'] as const;\nexport type DisplayIdentityKind = (typeof DISPLAY_IDENTITY_KINDS)[number];\n\n/**\n * The identity a user has chosen to show in their account badge — the\n * collapsed label every family site renders instead of the raw\n * `did:oc`. Carried as a JWT claim by the auth host, so the choice is\n * consistent across every `.ochk.io` subdomain with no round-trip.\n *\n * `kind` is which identity; `value` is the full, renderable value (the\n * `did:oc`, the Bitcoin address, the email, or the npub). Integrators\n * rendering their own chip read `useOcSession().account.displayIdentity`\n * — it is always populated (it defaults to the `did`).\n */\nexport interface DisplayIdentity {\n    kind: DisplayIdentityKind;\n    value: string;\n}\n\nexport interface OcAccount {\n    accountId: string;\n    /**\n     * Opaque public-facing identifier · `did:oc:<32-hex>`. The sole\n     * user identifier post auth-refactor. Stable across linking\n     * events. Per AUTH-REFACTOR-PLAN.md §2.1.\n     */\n    didOc: string;\n    /**\n     * Primary linked Bitcoin address, plaintext, when the user has\n     * one — null for email-OTP users until they link a btc address.\n     * Surfaced inline by the auth host's /api/auth/me so consumer\n     * dashboards can render the user's own footprint without a\n     * second round-trip through /api/auth/identities.\n     */\n    primaryBtc?: string | null;\n    /**\n     * True when the user has a primary email linked. Plaintext is\n     * fetchable on demand via /api/auth/identities; not surfaced\n     * here.\n     */\n    hasEmail?: boolean;\n    displayName?: string | null;\n    nostrNpub?: string | null;\n    /**\n     * Slug of the federation this user is bound to (their \"home\"\n     * federation). Multi-federation routing reads this; null/undefined\n     * means \"not yet bound — fall back to the directory default at\n     * /api/federations\". v1 has one live federation, so this is set on\n     * first signin and rarely changes.\n     */\n    homeFederation?: string | null;\n    /**\n     * Where this user is on the custody-state graph:\n     *\n     *   - 'fedimint_threshold' — federation custody (OC-introduced)\n     *   - 'fedimint_client'    — federation custody (user-picked)\n     *   - 'bip322'             — full self-custody\n     *\n     * Graduation is the product thesis. Treat undefined as\n     * 'fedimint_threshold' for `did:email:` addresses and 'bip322' for\n     * Bitcoin addresses (the default-by-construction mapping for\n     * tokens minted before this field shipped).\n     */\n    signingMethod?: 'fedimint_threshold' | 'fedimint_client' | 'bip322' | null;\n    /**\n     * Best-effort owner-flag · true when the user's `did_oc` was on\n     * the auth host's `OWNER_OC_ADDRESSES` env at the time the JWT\n     * was minted. Surfaced so the family-switcher and other low-\n     * stakes UX can render owner-only affordances (e.g. an\n     * analytics.ochk.io entry visible only to owners).\n     *\n     * **NOT A SECURITY BOUNDARY.** Sensitive surfaces — including\n     * analytics.ochk.io itself — re-check the live env against\n     * `session.did_oc` server-side on every request. If an owner is\n     * removed from the env, their JWT may keep `isOwner: true` for\n     * up to the JWT lifetime (~30d) but every gated action they\n     * attempt re-fails. The flag exists purely so we can show or\n     * hide UX hints without an extra round-trip on every page load.\n     *\n     * Treat absence as `false`.\n     */\n    isOwner?: boolean;\n    /**\n     * The identity the user has chosen to show as their account-badge\n     * label — `{ kind, value }`. **Always populated**: when the user\n     * has never promoted an identity (and on sessions minted before\n     * the feature shipped) this is `{ kind:'did', value:didOc }`.\n     *\n     * `<OcAccountMenu>` renders `value` (shortened) as the collapsed\n     * badge label. Integrators rendering their own chip read this\n     * directly; change it with `useOcSession().setDisplayIdentity()`.\n     */\n    displayIdentity: DisplayIdentity;\n}\n\nexport type OcSessionStatus = 'loading' | 'authenticated' | 'anonymous' | 'error';\n\n/**\n * Multi-account roster · summary of another account this browser has\n * signed into and can switch to without re-authenticating. Surfaced by\n * `<OcAccountMenu>` in the `§ accounts` section. Returned by the auth\n * host's `/api/auth/me` as `roster: [...]` (an empty array on single-\n * account or pre-multi-account sessions).\n *\n * Sessions for peer accounts stay alive in the auth host's DB for the\n * normal 30-day window; once expired, the peer falls out of the roster\n * and the user must re-authenticate to bring it back in.\n */\nexport interface OcAccountSummary {\n    didOc: string;\n    displayName: string | null;\n    primaryBtc: string | null;\n    displayIdentity: DisplayIdentity;\n    /** ISO timestamp of the last verified request on this account's\n     *  session row, or null if never touched. */\n    lastSeenAt: string | null;\n}\n\n/**\n * Scope hint for `signOut()` in a multi-account browser.\n *\n *   - 'all'     · sign out of every account in this browser's roster\n *                  (the default; matches the historical single-account\n *                  behavior of \"clear the cookie\").\n *   - 'current' · sign out of just the active account; if the roster\n *                  has other accounts, the auth host hands you off to\n *                  the next-most-recent one without a re-auth.\n */\nexport type OcSignOutScope = 'all' | 'current';\n\nexport interface OcSessionState {\n    status: OcSessionStatus;\n    account: OcAccount | null;\n    /**\n     * Multi-account · other accounts the user has signed into in this\n     * browser. `[]` for single-account sessions and for tokens minted\n     * before multi-account shipped. The active account (`account`\n     * above) is NOT included — these are the *switch targets*.\n     */\n    roster: OcAccountSummary[];\n    /**\n     * Per-tab pinning · `true` when this tab holds its own session\n     * token (sessionStorage) and operates as `account` independently of\n     * the shared `.ochk.io` cookie — i.e. switching accounts in another\n     * tab will NOT change this tab's identity. `false` on hosts that\n     * predate `/api/auth/tab`, in privacy modes without sessionStorage,\n     * and while anonymous.\n     */\n    tabPinned: boolean;\n    /** `null` while loading; an `Error` instance when `status === 'error'`. */\n    error: Error | null;\n    /** Re-fetch the session. Useful after sign-in/sign-out happens elsewhere. */\n    refresh: () => Promise<void>;\n    /**\n     * Trigger a sign-out. By default signs out of EVERY account in the\n     * roster (back-compat); pass `{ scope: 'current' }` to sign out of\n     * just the active account and stay logged into the next peer.\n     */\n    signOut: (opts?: { scope?: OcSignOutScope }) => Promise<void>;\n    /**\n     * Multi-account · flip the active session to a different account\n     * in the roster. Resolves once the new cookie has been set and\n     * the session has been re-fetched. Throws if the target `did_oc`\n     * isn't in the current roster (the user must add it via\n     * {@link addAccount} first) or if the auth host is unreachable.\n     */\n    switchAccount: (didOc: string) => Promise<void>;\n    /**\n     * Multi-account · open the sign-in flow in \"add\" mode — the new\n     * account joins the current browser's roster instead of replacing\n     * it. Returns the URL to navigate to (so callers can mount it in\n     * a popup or hard-navigate as they prefer); pass `returnTo` to\n     * route back to a specific page after the add completes.\n     */\n    addAccountUrl: (returnTo?: string) => string;\n    /**\n     * Promote a linked identity to be the account-badge label across\n     * every `.ochk.io` site. PATCHes the auth host, which re-mints the\n     * session cookie with the new `display_identity` claim, then\n     * `refresh()`es this session. Rejects if the chosen kind is not a\n     * verified identity on the account (`btc` / `email` / `nostr` must\n     * actually be linked; `did` is always valid).\n     */\n    setDisplayIdentity: (kind: DisplayIdentityKind) => Promise<void>;\n    /** URL to navigate to for sign-in on the auth host. */\n    signInUrl: string;\n}\n\nexport interface OcAuthConfig {\n    /**\n     * Origin of the auth host — the subdomain that runs the sign-in UI,\n     * issues session cookies, and exposes `/api/auth/me` + `/api/auth/logout`.\n     *\n     * Defaults to `https://ochk.io`. Override in preview/dev.\n     */\n    authOrigin?: string;\n    /**\n     * Path on the auth host that accepts `?return_to=<url>` and drives the\n     * sign-in flow. The page offers two paths in-place:\n     *\n     *   - email + OTP (default — no wallet and no key of the user's own;\n     *     identity is `did:email:<sha256(email)>`)\n     *   - BIP-322 wallet sign (paste address → in-page wallet sign;\n     *     identity is the Bitcoin address itself)\n     *\n     * Defaults to `/signin`.\n     */\n    signInPath?: string;\n    /**\n     * Local path (same origin as the current app) that exposes the\n     * crypto-verified session. If your app ships one at `/api/auth/me`,\n     * leave as default. Returns 200 `{ account }` or 401.\n     */\n    mePath?: string;\n    /**\n     * Path on the auth host to hit to clear the session cookie.\n     * Defaults to `/api/auth/logout`. Called with `credentials: 'include'`\n     * so the `.ochk.io` cookie is sent along.\n     */\n    logoutPath?: string;\n}\n\nexport const DEFAULT_CONFIG: Required<OcAuthConfig> = {\n    authOrigin: 'https://ochk.io',\n    signInPath: '/signin',\n    mePath: '/api/auth/me',\n    logoutPath: '/api/auth/logout',\n};\n\nexport function resolveConfig(cfg: OcAuthConfig | undefined): Required<OcAuthConfig> {\n    return { ...DEFAULT_CONFIG, ...(cfg ?? {}) };\n}\n\nexport function buildSignInUrl(cfg: Required<OcAuthConfig>, returnTo?: string): string {\n    const base = `${cfg.authOrigin}${cfg.signInPath}`;\n    if (!returnTo) return base;\n    const u = new URL(base);\n    u.searchParams.set('return_to', returnTo);\n    return u.toString();\n}\n\n/**\n * Multi-account · build the URL for the \"add another account\" entry\n * point. Same as {@link buildSignInUrl} but appends `?add=1` so the\n * sign-in page knows to preserve the current roster (the new account\n * is appended; the previously-active account stays signed in too and\n * remains switch-target reachable).\n */\nexport function buildAddAccountUrl(cfg: Required<OcAuthConfig>, returnTo?: string): string {\n    const u = new URL(buildSignInUrl(cfg, returnTo));\n    u.searchParams.set('add', '1');\n    return u.toString();\n}\n","/**\n * Per-tab account pinning · sessionStorage-backed.\n *\n * One browser holds ONE shared `oc_session` cookie (the browser-wide\n * default account) but may be signed into N roster accounts at once. A\n * tab pins itself to one account by holding that account's session JWT\n * here — sessionStorage is per-tab by nature — and sending it on every\n * same-site API call as the `x-oc-tab-session` header. Servers verify\n * the header exactly like the cookie token (it IS a session JWT, a\n * credential, never a bare account selector), so switching accounts in\n * one tab no longer yanks the identity out from under every other tab.\n *\n * Trade-off, named: a pinned token is readable by same-origin script,\n * unlike the HttpOnly cookie. An XSS on a family site can already act\n * as the user via `credentials: 'include'`; the marginal exposure is\n * token exfiltration for offline use, bounded by the token's TTL and\n * the host's per-row revocation. The host has echoed session JWTs in\n * `/api/auth/signin` / `/api/auth/switch` response bodies since the\n * multi-account migration, so this channel is not new.\n */\n\n/** Header carrying the tab-pinned session JWT. Mirrors `@orangecheck/auth-core`'s `TAB_SESSION_HEADER`. */\nexport const TAB_SESSION_HEADER = 'x-oc-tab-session';\n\nexport const TAB_SESSION_STORAGE_KEY = 'oc_tab_session';\n\n/**\n * URL-fragment key the link decorator stamps onto family-origin\n * navigations so a NEW tab (or a cross-subdomain document GET) inherits\n * the OPENER tab's effective account instead of falling back to the\n * shared cookie's default account.\n *\n * The value is the account's `did:oc` — a PUBLIC identifier, never the\n * session JWT. It rides a fragment (`#oc-as=<did>`), which is never sent\n * to any server, and the host re-validates roster membership before\n * minting a tab token for it, so a hand-crafted link grants nothing the\n * visitor's own cookie/roster doesn't already authorize.\n */\nexport const TAB_ACCOUNT_HINT_KEY = 'oc-as';\n\n/**\n * Hash marker the auth host appends to a post-ceremony redirect so the\n * landing tab adopts the cookie account instead of keeping a stale pin\n * (the user just completed a sign-in/add ceremony and expects to BE the\n * new account in that tab). Never sent to any server (it's a fragment).\n */\nexport const TAB_ADOPT_HASH = '#oc-adopt';\n\nexport interface OcTabSession {\n    token: string;\n    didOc: string;\n}\n\nexport function readTabSession(): OcTabSession | null {\n    if (typeof window === 'undefined') return null;\n    try {\n        const raw = window.sessionStorage.getItem(TAB_SESSION_STORAGE_KEY);\n        if (!raw) return null;\n        const parsed = JSON.parse(raw) as { token?: unknown; didOc?: unknown };\n        if (typeof parsed.token !== 'string' || parsed.token.length === 0) return null;\n        if (typeof parsed.didOc !== 'string' || parsed.didOc.length === 0) return null;\n        return { token: parsed.token, didOc: parsed.didOc };\n    } catch {\n        // sessionStorage can throw (privacy modes) · malformed JSON → unpinned\n        return null;\n    }\n}\n\nexport function writeTabSession(session: OcTabSession): void {\n    if (typeof window === 'undefined') return;\n    try {\n        window.sessionStorage.setItem(TAB_SESSION_STORAGE_KEY, JSON.stringify(session));\n    } catch {\n        // quota / privacy mode — degrade to unpinned (cookie-default) behavior\n    }\n}\n\nexport function clearTabSession(): void {\n    if (typeof window === 'undefined') return;\n    try {\n        window.sessionStorage.removeItem(TAB_SESSION_STORAGE_KEY);\n    } catch {\n        // nothing to clear\n    }\n}\n\n/** `{ 'x-oc-tab-session': <jwt> }` when this tab is pinned, else `{}`. */\nexport function tabSessionHeader(): Record<string, string> {\n    const pin = readTabSession();\n    return pin ? { [TAB_SESSION_HEADER]: pin.token } : {};\n}\n\n/**\n * Should this request carry the tab pin? Same-origin requests (relative\n * URLs or the page's own origin) and requests to the auth host — never\n * third parties.\n */\nfunction isPinnableUrl(url: string, authOrigin: string): boolean {\n    if (typeof window === 'undefined') return false;\n    try {\n        const u = new URL(url, window.location.href);\n        return u.origin === window.location.origin || u.origin === authOrigin;\n    } catch {\n        return false;\n    }\n}\n\n/**\n * Install a scoped `window.fetch` wrapper that attaches the tab pin to\n * every same-site request, so app-level data fetches (vault shares, me\n * wallet, projects, …) execute as the account this tab displays —\n * without touching any call site. Returns an uninstaller.\n *\n * Conservative by design:\n *   - no pin → pass-through (zero behavior change)\n *   - only same-origin + auth-host URLs (see {@link isPinnableUrl})\n *   - never overrides an existing `Authorization` or `x-oc-tab-session`\n *     header (programmatic Bearer / integrator-token paths keep their\n *     own credential semantics)\n *   - any internal error → original fetch, untouched\n */\nexport function installTabFetchInterceptor(authOrigin: string): () => void {\n    if (typeof window === 'undefined') return () => {};\n    const original = window.fetch;\n    const wrapped: typeof window.fetch = (input, init) => {\n        try {\n            const pin = readTabSession();\n            if (pin) {\n                const url =\n                    typeof input === 'string'\n                        ? input\n                        : input instanceof URL\n                          ? input.href\n                          : input.url;\n                if (isPinnableUrl(url, authOrigin)) {\n                    const headers = new Headers(\n                        init?.headers ?? (input instanceof Request ? input.headers : undefined)\n                    );\n                    if (!headers.has('authorization') && !headers.has(TAB_SESSION_HEADER)) {\n                        headers.set(TAB_SESSION_HEADER, pin.token);\n                        init = { ...init, headers };\n                    }\n                }\n            }\n        } catch {\n            // never break a fetch over pinning\n        }\n        return original.call(window, input as RequestInfo | URL, init);\n    };\n    window.fetch = wrapped;\n    return () => {\n        // only restore if nobody else wrapped on top of us in the meantime\n        if (window.fetch === wrapped) window.fetch = original;\n    };\n}\n\n/**\n * If the URL carries the {@link TAB_ADOPT_HASH} marker, clear the pin\n * (so the tab adopts the cookie account) and strip the marker from the\n * address bar. Returns `true` when adoption happened.\n */\nexport function consumeTabAdoptMarker(): boolean {\n    if (typeof window === 'undefined') return false;\n    if (!window.location.hash.includes(TAB_ADOPT_HASH.slice(1))) return false;\n    clearTabSession();\n    try {\n        const url = new URL(window.location.href);\n        url.hash = '';\n        window.history.replaceState(window.history.state, '', url.toString());\n    } catch {\n        // cosmetic only — a lingering #oc-adopt re-adopts on reload, which\n        // is idempotent (the pin is already cleared).\n    }\n    return true;\n}\n\n// ─── Cross-tab account inheritance (the new-tab pin handoff) ────────────\n//\n// The pin lives in sessionStorage, which a NEW tab does not inherit\n// cross-origin (and not at all on Safari). So a CTRL/⌘/middle-click on a\n// family link — or a same-tab navigation to a sibling subdomain — would\n// land unpinned and resolve to the shared cookie's DEFAULT account, i.e.\n// \"the other account.\" We bridge the gap WITHOUT putting a credential in\n// a URL: the opener tab stamps the destination link with the public\n// `did:oc` of its effective account (`#oc-as=<did>`), and the landing\n// tab mints its own pin for that account via the host (which re-checks\n// roster membership). The did is a selector, not a credential.\n\nconst OC_AS_HINT_RE = /^oc-as=(did:oc:[0-9a-f]{32})$/;\n\n/** Apex hostname of the auth host, e.g. `ochk.io`. Null if unparseable. */\nfunction familyApex(authOrigin: string): string | null {\n    try {\n        return new URL(authOrigin).hostname.toLowerCase();\n    } catch {\n        return null;\n    }\n}\n\n/**\n * Is `u` a family destination worth stamping — current origin or any\n * host at/under the auth host's apex (so `stamp.ochk.io`, `ochk.io`,\n * etc. match, but `example.com` never does)? http(s) only — `mailto:`,\n * `tel:`, `javascript:`, `blob:` are excluded by construction.\n */\nfunction isFamilyUrl(u: URL, authOrigin: string): boolean {\n    if (u.protocol !== 'http:' && u.protocol !== 'https:') return false;\n    if (typeof window !== 'undefined' && u.origin === window.location.origin) return true;\n    const apex = familyApex(authOrigin);\n    if (!apex) return false;\n    const host = u.hostname.toLowerCase();\n    return host === apex || host.endsWith(`.${apex}`);\n}\n\n/** Would following this link land in a context that can't see this tab's pin? */\nfunction opensWithoutTabPin(e: MouseEvent, anchor: HTMLAnchorElement, dest: URL): boolean {\n    // Cross-origin always loses the pin (sessionStorage is per-origin).\n    if (typeof window !== 'undefined' && dest.origin !== window.location.origin) return true;\n    // Same-origin: only a NEW tab/window risks losing it (Safari doesn't\n    // clone sessionStorage); a same-tab navigation keeps it, so leave\n    // those links untouched to avoid needless URL noise.\n    const target = (anchor.getAttribute('target') ?? '').toLowerCase();\n    return (\n        e.button === 1 || // middle-click\n        e.metaKey ||\n        e.ctrlKey ||\n        e.shiftKey ||\n        target === '_blank'\n    );\n}\n\n/**\n * Install a capture-phase listener that stamps the tab's effective\n * `did:oc` onto outgoing family-origin links the instant they're\n * activated, so a new/cross-subdomain tab adopts THIS tab's account.\n * Returns an uninstaller. Mirrors {@link installTabFetchInterceptor}'s\n * conservatism:\n *   - no pin → never stamps (zero behavior change)\n *   - family origins only → never leaks the did to third parties\n *   - reads the pin FRESH per event (no install-time capture)\n *   - never clobbers an existing `#fragment`, a download, or a\n *     non-http(s) scheme\n *   - any internal error → leaves the link alone\n *\n * It mutates `a.href` in place rather than calling `window.open`, so it\n * never trips a popup blocker and the browser's own ctrl/⌘/middle-click\n * handling (and the context menu's \"open in new tab\") all carry the\n * stamp. The stamp is idempotent and self-healing — React resets the\n * href on the next render, and the destination strips the fragment via\n * {@link consumeTabAccountHint}.\n */\nexport function installTabLinkDecorator(authOrigin: string): () => void {\n    if (typeof window === 'undefined' || typeof document === 'undefined') return () => {};\n    const onActivate = (e: MouseEvent) => {\n        try {\n            const pin = readTabSession();\n            if (!pin) return;\n            const target = e.target;\n            if (!(target instanceof Element)) return;\n            const anchor = target.closest('a[href]') as HTMLAnchorElement | null;\n            if (!anchor || anchor.hasAttribute('download')) return;\n            const raw = anchor.getAttribute('href');\n            if (!raw || raw.includes(`${TAB_ACCOUNT_HINT_KEY}=`)) return;\n            let dest: URL;\n            try {\n                dest = new URL(anchor.href);\n            } catch {\n                return;\n            }\n            if (dest.hash) return; // don't clobber a real #anchor deep-link\n            if (!isFamilyUrl(dest, authOrigin)) return;\n            if (!opensWithoutTabPin(e, anchor, dest)) return;\n            anchor.setAttribute('href', `${raw}#${TAB_ACCOUNT_HINT_KEY}=${pin.didOc}`);\n        } catch {\n            // never break a navigation over decoration\n        }\n    };\n    window.addEventListener('click', onActivate, true);\n    window.addEventListener('auxclick', onActivate, true);\n    return () => {\n        window.removeEventListener('click', onActivate, true);\n        window.removeEventListener('auxclick', onActivate, true);\n    };\n}\n\n/**\n * On load, if the URL carries `#oc-as=<did>`, adopt that account for\n * THIS tab: mint a pin for it via the host's `/api/auth/tab` (which\n * re-validates the did is in this browser's roster) and stash it in\n * sessionStorage, then strip the fragment from the address bar. Must run\n * BEFORE the provider's first `/api/auth/me` fetch so that fetch carries\n * the right pin.\n *\n * Returns the adopted `did:oc` on success, else null. Best-effort and\n * fail-safe: a stale host (no targeted minting), a roster miss (403), or\n * a network error leaves the tab unpinned — exactly the legacy\n * cookie-following behavior. The fragment is always stripped so it never\n * lingers in history/bookmarks or re-fires on reload.\n */\nexport async function consumeTabAccountHint(authOrigin: string): Promise<string | null> {\n    if (typeof window === 'undefined') return null;\n    const frag = window.location.hash.replace(/^#/, '');\n    const m = OC_AS_HINT_RE.exec(frag);\n    if (!m) return null;\n    const did = m[1]!;\n    // Strip the fragment regardless of what happens next.\n    try {\n        const url = new URL(window.location.href);\n        url.hash = '';\n        window.history.replaceState(window.history.state, '', url.toString());\n    } catch {\n        // cosmetic only\n    }\n    // Already pinned to the hinted account (same-tab nav, or a same-origin\n    // new tab that cloned sessionStorage) → nothing to mint.\n    const existing = readTabSession();\n    if (existing && existing.didOc === did) return did;\n    try {\n        const res = await fetch(`${authOrigin}/api/auth/tab`, {\n            method: 'POST',\n            credentials: 'include',\n            headers: { Accept: 'application/json', 'Content-Type': 'application/json' },\n            body: JSON.stringify({ did_oc: did }),\n        });\n        if (!res.ok) return null;\n        const body = (await res.json()) as {\n            ok?: boolean;\n            token?: string;\n            account?: { did_oc?: string };\n        };\n        // Only pin when the host minted for the hinted account — a stale\n        // host that ignores the body mints for the cookie account, which\n        // we must NOT adopt (it's the wrong-account bug we're fixing).\n        if (body.ok && typeof body.token === 'string' && body.account?.did_oc === did) {\n            writeTabSession({ token: body.token, didOc: did });\n            return did;\n        }\n    } catch {\n        // best-effort by construction\n    }\n    return null;\n}\n","import * as React from 'react';\n\nimport {\n    buildAddAccountUrl,\n    buildSignInUrl,\n    DEFAULT_CONFIG,\n    DISPLAY_IDENTITY_KINDS,\n    resolveConfig,\n    type DisplayIdentity,\n    type DisplayIdentityKind,\n    type OcAccount,\n    type OcAccountSummary,\n    type OcAuthConfig,\n    type OcSessionState,\n    type OcSignOutScope,\n} from './types';\nimport {\n    clearTabSession,\n    consumeTabAccountHint,\n    consumeTabAdoptMarker,\n    installTabFetchInterceptor,\n    installTabLinkDecorator,\n    readTabSession,\n    tabSessionHeader,\n    writeTabSession,\n} from './tab-session';\n\nconst SessionContext = React.createContext<OcSessionState | null>(null);\n\ntype RawSigningMethod = 'fedimint_threshold' | 'fedimint_client' | 'bip322';\n\ninterface RawRosterEntry {\n    did_oc?: string;\n    didOc?: string;\n    display_name?: string | null;\n    displayName?: string | null;\n    primary_btc?: string | null;\n    primaryBtc?: string | null;\n    display_identity?: { kind?: string; value?: string } | null;\n    displayIdentity?: { kind?: string; value?: string } | null;\n    last_seen_at?: string | null;\n    lastSeenAt?: string | null;\n}\n\ninterface MeResponse {\n    account?: {\n        id?: string;\n        account_id?: string;\n        accountId?: string;\n        did_oc?: string;\n        didOc?: string;\n        primary_btc?: string | null;\n        primaryBtc?: string | null;\n        has_email?: boolean;\n        hasEmail?: boolean;\n        display_name?: string | null;\n        displayName?: string | null;\n        nostr_npub?: string | null;\n        nostrNpub?: string | null;\n        home_federation_slug?: string | null;\n        homeFederation?: string | null;\n        signing_method?: RawSigningMethod | null;\n        signingMethod?: RawSigningMethod | null;\n        is_owner?: boolean;\n        isOwner?: boolean;\n        display_identity?: { kind?: string; value?: string } | null;\n        displayIdentity?: { kind?: string; value?: string } | null;\n    };\n    /** Multi-account roster · other accounts in this browser. Absent\n     *  on hosts that haven't deployed the multi-account migration yet\n     *  — treated as `[]` (single-account fallback). */\n    roster?: RawRosterEntry[];\n}\n\n/**\n * Resolve the badge identity from a `/api/auth/me` account payload.\n * Total: returns the carried `{kind,value}` when well-formed, else\n * `{kind:'did',value:didOc}` — so accounts that never promoted, and\n * sessions minted before the field shipped, degrade cleanly.\n */\nfunction normalizeDisplayIdentity(\n    raw: NonNullable<MeResponse['account']>,\n    didOc: string\n): DisplayIdentity {\n    const di = raw.display_identity ?? raw.displayIdentity;\n    if (\n        di &&\n        typeof di === 'object' &&\n        typeof di.value === 'string' &&\n        di.value.length > 0 &&\n        typeof di.kind === 'string' &&\n        (DISPLAY_IDENTITY_KINDS as readonly string[]).includes(di.kind)\n    ) {\n        return { kind: di.kind as DisplayIdentityKind, value: di.value };\n    }\n    return { kind: 'did', value: didOc };\n}\n\n/**\n * Multi-account · normalize one roster entry from /api/auth/me. Drops\n * entries with no did_oc (defensive — the host shouldn't emit those).\n */\nfunction normalizeRosterEntry(raw: RawRosterEntry): OcAccountSummary | null {\n    const didOc = raw.did_oc ?? raw.didOc;\n    if (!didOc) return null;\n    const di = raw.display_identity ?? raw.displayIdentity;\n    const displayIdentity: DisplayIdentity =\n        di &&\n        typeof di === 'object' &&\n        typeof di.value === 'string' &&\n        di.value.length > 0 &&\n        typeof di.kind === 'string' &&\n        (DISPLAY_IDENTITY_KINDS as readonly string[]).includes(di.kind)\n            ? { kind: di.kind as DisplayIdentityKind, value: di.value }\n            : { kind: 'did', value: didOc };\n    return {\n        didOc,\n        displayName: raw.display_name ?? raw.displayName ?? null,\n        primaryBtc: raw.primary_btc ?? raw.primaryBtc ?? null,\n        displayIdentity,\n        lastSeenAt: raw.last_seen_at ?? raw.lastSeenAt ?? null,\n    };\n}\n\n/**\n * Multi-account · fetch the roster from the AUTH HOST cross-origin.\n *\n * Consumer subdomains expose a LOCAL `/api/auth/me` that verifies the JWT\n * but has no database, so it never carries the `roster` (which is host DB\n * state). When the local /me comes back authenticated with an empty roster,\n * we source it from the host directly — the same credentialed cross-origin\n * pattern this provider already uses for logout + account PATCH, and the\n * host already serves `.ochk.io` consumers via CORS.\n *\n * Best-effort by construction: any failure resolves to `[]`, so a roster\n * fetch can never change the authenticated state derived from the local /me.\n */\nasync function fetchHostRoster(cfg: Required<OcAuthConfig>): Promise<OcAccountSummary[]> {\n    try {\n        // Per-tab · carry the pin so the host computes \"peers\" relative\n        // to THIS tab's effective account, not the cookie default.\n        const res = await fetch(`${cfg.authOrigin}${cfg.mePath}`, {\n            method: 'GET',\n            credentials: 'include',\n            headers: { Accept: 'application/json', ...tabSessionHeader() },\n        });\n        if (!res.ok) return [];\n        const body = (await res.json()) as MeResponse;\n        return Array.isArray(body.roster)\n            ? body.roster\n                  .map(normalizeRosterEntry)\n                  .filter((r): r is OcAccountSummary => r !== null)\n            : [];\n    } catch {\n        return [];\n    }\n}\n\nfunction normalizeAccount(raw: MeResponse['account']): OcAccount | null {\n    if (!raw) return null;\n    const didOc = raw.did_oc ?? raw.didOc;\n    const accountId = raw.id ?? raw.account_id ?? raw.accountId;\n    if (!didOc || !accountId) return null;\n    return {\n        accountId,\n        didOc,\n        primaryBtc: raw.primary_btc ?? raw.primaryBtc ?? null,\n        hasEmail: raw.has_email ?? raw.hasEmail ?? false,\n        displayName: raw.display_name ?? raw.displayName ?? null,\n        nostrNpub: raw.nostr_npub ?? raw.nostrNpub ?? null,\n        homeFederation: raw.home_federation_slug ?? raw.homeFederation ?? null,\n        signingMethod: raw.signing_method ?? raw.signingMethod ?? null,\n        isOwner: Boolean(raw.is_owner ?? raw.isOwner ?? false),\n        displayIdentity: normalizeDisplayIdentity(raw, didOc),\n    };\n}\n\nexport interface OcSessionProviderProps {\n    children: React.ReactNode;\n    config?: OcAuthConfig;\n    /**\n     * Optional return URL passed to the sign-in page. Defaults to the\n     * current `window.location.href` at click-time.\n     */\n    defaultReturnTo?: string;\n}\n\n/**\n * Top-level provider that exposes the cross-subdomain oc_session to every\n * component below it. Mount once, near the root of your tree.\n */\nexport function OcSessionProvider({\n    children,\n    config,\n    defaultReturnTo,\n}: OcSessionProviderProps): React.ReactElement {\n    const cfg = React.useMemo(() => resolveConfig(config), [config]);\n    const [account, setAccount] = React.useState<OcAccount | null>(null);\n    const [roster, setRoster] = React.useState<OcAccountSummary[]>([]);\n    const [status, setStatus] = React.useState<OcSessionState['status']>('loading');\n    const [error, setError] = React.useState<Error | null>(null);\n    const [tabPinned, setTabPinned] = React.useState(false);\n\n    // Per-tab · mint a pin for this tab via the host. Called once per\n    // tab on first authenticated resolve, so a later switch in ANOTHER\n    // tab can't yank this one — it keeps presenting its own token.\n    // Best-effort: a host that predates `/api/auth/tab` (or a network\n    // failure) leaves the tab unpinned, which is exactly the legacy\n    // cookie-following behavior.\n    const pinInFlightRef = React.useRef(false);\n    const pinThisTab = React.useCallback(\n        async (didOc: string) => {\n            if (pinInFlightRef.current || readTabSession()) return;\n            pinInFlightRef.current = true;\n            try {\n                const res = await fetch(`${cfg.authOrigin}/api/auth/tab`, {\n                    method: 'POST',\n                    credentials: 'include',\n                    headers: { Accept: 'application/json' },\n                });\n                if (!res.ok) return;\n                const body = (await res.json()) as {\n                    ok?: boolean;\n                    token?: string;\n                    account?: { did_oc?: string };\n                };\n                // Only pin when the host minted for the account this tab\n                // just resolved — a cookie flip racing between our /me and\n                // /tab calls must not pin the WRONG account.\n                if (\n                    body.ok &&\n                    typeof body.token === 'string' &&\n                    body.account?.did_oc === didOc\n                ) {\n                    writeTabSession({ token: body.token, didOc });\n                    setTabPinned(true);\n                }\n            } catch {\n                // best-effort by construction\n            } finally {\n                pinInFlightRef.current = false;\n            }\n        },\n        [cfg.authOrigin]\n    );\n\n    const refresh = React.useCallback(async () => {\n        if (typeof window === 'undefined') return;\n        try {\n            let pin = readTabSession();\n            let res = await fetch(cfg.mePath, {\n                method: 'GET',\n                credentials: 'include',\n                headers: { Accept: 'application/json', ...tabSessionHeader() },\n            });\n            // Per-tab · 401 with a pin present means the pinned token is\n            // dead (expired, or revoked and rejected by the host). Drop\n            // the pin and retry once as the browser-default account.\n            if (res.status === 401 && pin) {\n                clearTabSession();\n                pin = null;\n                setTabPinned(false);\n                res = await fetch(cfg.mePath, {\n                    method: 'GET',\n                    credentials: 'include',\n                    headers: { Accept: 'application/json' },\n                });\n            }\n            if (res.status === 401) {\n                setAccount(null);\n                setRoster([]);\n                setStatus('anonymous');\n                setError(null);\n                return;\n            }\n            if (!res.ok) {\n                setStatus('error');\n                setError(new Error(`me endpoint returned ${res.status}`));\n                return;\n            }\n            const body = (await res.json()) as MeResponse;\n            const acct = normalizeAccount(body.account);\n            // Per-tab reconciliation · the server answered as a different\n            // account than the pin → it doesn't honor `x-oc-tab-session`\n            // yet (pre-migration deploy). Drop the pin: the UI must never\n            // display an account the server isn't acting as.\n            if (acct && pin && acct.didOc !== pin.didOc) {\n                clearTabSession();\n                pin = null;\n            }\n            setTabPinned(pin !== null);\n            const rosterEntries = Array.isArray(body.roster)\n                ? body.roster\n                      .map(normalizeRosterEntry)\n                      .filter((r): r is OcAccountSummary => r !== null)\n                : [];\n            setAccount(acct);\n            setRoster(rosterEntries);\n            setStatus(acct ? 'authenticated' : 'anonymous');\n            setError(null);\n\n            // Per-tab · authenticated but unpinned → pin this tab to the\n            // account it just resolved (fire-and-forget).\n            if (acct && !pin) void pinThisTab(acct.didOc);\n\n            // Multi-account · the local /me carried no roster (the standard\n            // case on consumer subdomains, whose local /me has no DB). When\n            // we're authenticated and NOT already on the auth host, source\n            // the roster from the host so the §accounts switcher lights up.\n            // Best-effort: never touches account/status on failure.\n            const currentOrigin =\n                typeof window !== 'undefined' ? window.location.origin : null;\n            if (\n                acct &&\n                rosterEntries.length === 0 &&\n                currentOrigin !== null &&\n                !cfg.authOrigin.startsWith(currentOrigin)\n            ) {\n                const peers = await fetchHostRoster(cfg);\n                if (peers.length > 0) setRoster(peers);\n            }\n        } catch (err) {\n            setStatus('error');\n            setError(err instanceof Error ? err : new Error(String(err)));\n        }\n    }, [cfg, pinThisTab]);\n\n    React.useEffect(() => {\n        let cancelled = false;\n        // Post-ceremony adoption · the auth host appends `#oc-adopt` when\n        // returning from a sign-in/add ceremony: the user expects THIS tab\n        // to become the account they just authenticated, so a stale pin\n        // must not survive the round trip.\n        consumeTabAdoptMarker();\n        void (async () => {\n            // New-tab inheritance · if the opener stamped `#oc-as=<did>`,\n            // adopt that account BEFORE the first /me fetch so this tab\n            // resolves as the opener's account, not the cookie default.\n            await consumeTabAccountHint(cfg.authOrigin);\n            if (!cancelled) void refresh();\n        })();\n        return () => {\n            cancelled = true;\n        };\n    }, [refresh, cfg.authOrigin]);\n\n    // Per-tab · attach the pin to every same-site fetch so app-level data\n    // calls execute as the account this tab displays. Scoped + reversible;\n    // see installTabFetchInterceptor for the conservative rules.\n    React.useEffect(() => installTabFetchInterceptor(cfg.authOrigin), [cfg.authOrigin]);\n\n    // Per-tab · stamp this tab's effective account onto outgoing\n    // family-origin links so a new/cross-subdomain tab inherits it\n    // instead of the shared cookie default. See installTabLinkDecorator.\n    React.useEffect(() => installTabLinkDecorator(cfg.authOrigin), [cfg.authOrigin]);\n\n    const signOut = React.useCallback(\n        async (opts?: { scope?: OcSignOutScope }) => {\n            const scope: OcSignOutScope = opts?.scope ?? 'all';\n            try {\n                const url = new URL(`${cfg.authOrigin}${cfg.logoutPath}`);\n                if (scope === 'current') url.searchParams.set('scope', 'current');\n                const res = await fetch(url.toString(), {\n                    method: 'POST',\n                    credentials: 'include',\n                    // Per-tab · carry the pin so scope='current' signs out\n                    // the account THIS tab is operating as, not whichever\n                    // account the shared cookie happens to point at.\n                    headers: { ...tabSessionHeader() },\n                    // `keepalive` lets the logout round-trip complete even if\n                    // the caller hard-navigates away in the same tick (e.g.\n                    // `<OcAccountMenu>` redirects home immediately on sign-out).\n                    // Without it the in-flight request is cancelled on unload\n                    // and the `.ochk.io` cookie may never get cleared.\n                    keepalive: true,\n                });\n                // The signed-out account's token is dead either way — the\n                // pin must not outlive it.\n                clearTabSession();\n                setTabPinned(false);\n                // Multi-account: with scope='current', the server may have\n                // switched the active session to a roster peer instead of\n                // clearing the cookie. Re-fetch /api/auth/me so this\n                // provider reflects the new active account; if the body\n                // says `switched_to !== null`, refresh resolves to the\n                // peer, otherwise it resolves to anonymous and the\n                // setState below is redundant-but-harmless.\n                if (scope === 'current' && res.ok) {\n                    await refresh();\n                    return;\n                }\n            } catch {\n                // fall through — we still clear local state so the UI reflects\n                // the user's intent even if the server round-trip fails.\n                clearTabSession();\n                setTabPinned(false);\n            }\n            setAccount(null);\n            setRoster([]);\n            setStatus('anonymous');\n        },\n        [cfg.authOrigin, cfg.logoutPath, refresh]\n    );\n\n    const switchAccount = React.useCallback(\n        async (didOc: string) => {\n            if (typeof window === 'undefined') return;\n            const res = await fetch(`${cfg.authOrigin}/api/auth/switch`, {\n                method: 'POST',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json', ...tabSessionHeader() },\n                body: JSON.stringify({ did_oc: didOc }),\n            });\n            if (!res.ok) {\n                let reason = `http_${res.status}`;\n                try {\n                    const body = (await res.json()) as { reason?: string };\n                    if (body.reason) reason = body.reason;\n                } catch {\n                    // keep http_ fallback\n                }\n                throw new Error(`[@orangecheck/auth-client] switchAccount failed: ${reason}`);\n            }\n            // Per-tab · pin THIS tab to the switch target using the fresh\n            // JWT the host echoes in the body. The host has also flipped\n            // the shared cookie — the default for FUTURE tabs — but other\n            // open tabs keep their own pins and are not yanked. Pin to the\n            // did the SERVER minted for (merge-graph collapse may differ\n            // from the requested did).\n            try {\n                const body = (await res.json()) as {\n                    token?: string;\n                    account?: { did_oc?: string };\n                };\n                if (typeof body.token === 'string' && body.account?.did_oc) {\n                    writeTabSession({ token: body.token, didOc: body.account.did_oc });\n                    setTabPinned(true);\n                }\n            } catch {\n                // body unreadable — cookie still flipped; refresh resolves it\n            }\n            // Re-fetch /me to surface the new active account + freshly\n            // computed roster (the previous active account is now a peer,\n            // swap is symmetric).\n            await refresh();\n        },\n        [cfg.authOrigin, refresh]\n    );\n\n    const addAccountUrl = React.useCallback(\n        (returnTo?: string) => {\n            const rt =\n                returnTo ?? (typeof window !== 'undefined' ? window.location.href : undefined);\n            return buildAddAccountUrl(cfg, rt);\n        },\n        [cfg]\n    );\n\n    const setDisplayIdentity = React.useCallback(\n        async (kind: DisplayIdentityKind) => {\n            if (typeof window === 'undefined') return;\n            // PATCH the auth host directly (family-CORS). It writes the\n            // pref, re-mints the `.ochk.io` session cookie with the new\n            // `display_identity` claim, and Set-Cookies it back — so the\n            // choice propagates to every subdomain. Then refresh so this\n            // session reflects it immediately.\n            const res = await fetch(`${cfg.authOrigin}/api/auth/account`, {\n                method: 'PATCH',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json', ...tabSessionHeader() },\n                body: JSON.stringify({ display_identity: kind }),\n            });\n            if (!res.ok) {\n                let reason = `http_${res.status}`;\n                try {\n                    const body = (await res.json()) as { reason?: string };\n                    if (body.reason) reason = body.reason;\n                } catch {\n                    // keep the http_ fallback\n                }\n                throw new Error(`[@orangecheck/auth-client] setDisplayIdentity failed: ${reason}`);\n            }\n            // Per-tab · the PATCH re-mints; when this tab is pinned the\n            // host echoes the fresh token in the body (it only rewrites\n            // the shared cookie when the cookie account was the actor).\n            // Re-pin so the tab carries the updated claims.\n            try {\n                const body = (await res.json()) as {\n                    token?: string;\n                    account?: { did_oc?: string };\n                };\n                const pin = readTabSession();\n                if (\n                    pin &&\n                    typeof body.token === 'string' &&\n                    body.account?.did_oc === pin.didOc\n                ) {\n                    writeTabSession({ token: body.token, didOc: pin.didOc });\n                }\n            } catch {\n                // body unreadable — refresh below still reconciles state\n            }\n            await refresh();\n        },\n        [cfg.authOrigin, refresh]\n    );\n\n    const value = React.useMemo<OcSessionState>(() => {\n        const returnTo =\n            defaultReturnTo ?? (typeof window !== 'undefined' ? window.location.href : undefined);\n        return {\n            status,\n            account,\n            roster,\n            tabPinned,\n            error,\n            refresh,\n            signOut,\n            switchAccount,\n            addAccountUrl,\n            setDisplayIdentity,\n            signInUrl: buildSignInUrl(cfg, returnTo),\n        };\n    }, [\n        status,\n        account,\n        roster,\n        tabPinned,\n        error,\n        refresh,\n        signOut,\n        switchAccount,\n        addAccountUrl,\n        setDisplayIdentity,\n        cfg,\n        defaultReturnTo,\n    ]);\n\n    return <SessionContext.Provider value={value}>{children}</SessionContext.Provider>;\n}\n\n/**\n * Access the current cross-subdomain oc_session. Must be called inside\n * an `<OcSessionProvider>`.\n */\nexport function useOcSession(): OcSessionState {\n    const ctx = React.useContext(SessionContext);\n    if (!ctx) {\n        throw new Error(\n            '[@orangecheck/auth-client] useOcSession() must be called inside <OcSessionProvider>'\n        );\n    }\n    return ctx;\n}\n\n/**\n * Non-throwing variant — returns `null` if called outside a provider.\n * Useful for libraries that want to read the session *if it exists* but\n * shouldn't crash on apps that haven't opted in.\n */\nexport function useOptionalOcSession(): OcSessionState | null {\n    return React.useContext(SessionContext);\n}\n\nexport { DEFAULT_CONFIG };\n","import * as React from 'react';\n\nimport { useOcSession } from './provider';\n\nfunction shortenAddress(addr: string): string {\n    if (addr.length <= 12) return addr;\n    return `${addr.slice(0, 6)}…${addr.slice(-4)}`;\n}\n\nfunction shortenAddressMid(addr: string): string {\n    if (addr.length <= 16) return addr;\n    return `${addr.slice(0, 8)}…${addr.slice(-6)}`;\n}\n\nfunction isPrefixOf(value: string, target: string): boolean {\n    return target.toLowerCase().startsWith(value.toLowerCase());\n}\n\nlet listboxIdCounter = 0;\nfunction useUniqueId(prefix: string): string {\n    const [id] = React.useState(() => `${prefix}-${++listboxIdCounter}`);\n    return id;\n}\n\nexport interface OcAccountChipProps {\n    /**\n     * URL to the user's account dashboard. Defaults to `https://ochk.io/dashboard`,\n     * the canonical family target.\n     */\n    dashboardUrl?: string;\n    /**\n     * Override the sign-in URL shown to anonymous visitors. Defaults to\n     * the session's `signInUrl` (which points at the auth host's\n     * /signin?return_to=… page). Set this to a local path like `'/signin'`\n     * when the consumer site mounts its own in-place `<OcSignIn />` —\n     * skips the redirect-bounce entirely.\n     */\n    signInUrl?: string;\n    /**\n     * Label for the sign-in link shown to anonymous visitors.\n     * Defaults to `sign in`.\n     */\n    signInLabel?: string;\n    /** className for the wrapper `<div>`. */\n    className?: string;\n    /** className for the trigger pill button. */\n    triggerClassName?: string;\n    /** className for the dropdown popover. */\n    popoverClassName?: string;\n    /** className for menu items (dashboard link + sign-out button). */\n    menuItemClassName?: string;\n}\n\n/**\n * Single header-account affordance for every ochk.io subdomain.\n *\n *   anonymous → \"sign in\" link\n *   signed in → pill `bc1q…7ke3 ▾` that opens a popover with:\n *               • § signed in  (label)\n *               • full address (monospace, break-all)\n *               • → dashboard\n *               • → sign out\n *\n * The popover closes on outside click or Escape. Reasonable inline styles\n * cover the dark-mode default; override per-part via the className props\n * or via the `[data-oc-account-chip-*]` data attributes.\n */\nexport function OcAccountChip({\n    dashboardUrl = 'https://ochk.io/dashboard',\n    signInUrl: signInUrlOverride,\n    signInLabel = 'sign in',\n    className,\n    triggerClassName,\n    popoverClassName,\n    menuItemClassName,\n}: OcAccountChipProps): React.ReactElement | null {\n    const { status, account, signInUrl: sessionSignInUrl, signOut } = useOcSession();\n    const signInUrl = signInUrlOverride ?? sessionSignInUrl;\n    const [open, setOpen] = React.useState(false);\n    const wrapRef = React.useRef<HTMLDivElement | null>(null);\n\n    React.useEffect(() => {\n        if (!open) return;\n        function handleClickOutside(e: MouseEvent) {\n            if (wrapRef.current && !wrapRef.current.contains(e.target as Node)) {\n                setOpen(false);\n            }\n        }\n        function handleEscape(e: KeyboardEvent) {\n            if (e.key === 'Escape') setOpen(false);\n        }\n        document.addEventListener('mousedown', handleClickOutside);\n        document.addEventListener('keydown', handleEscape);\n        return () => {\n            document.removeEventListener('mousedown', handleClickOutside);\n            document.removeEventListener('keydown', handleEscape);\n        };\n    }, [open]);\n\n    if (status === 'loading') return null;\n\n    if (status !== 'authenticated' || !account) {\n        return (\n            <a\n                href={signInUrl}\n                className={triggerClassName ?? className}\n                data-oc-account-chip-signin=\"\"\n            >\n                {signInLabel}\n            </a>\n        );\n    }\n\n    return (\n        <div\n            ref={wrapRef}\n            className={className}\n            data-oc-account-chip=\"\"\n            style={{ position: 'relative', display: 'inline-block' }}\n        >\n            <button\n                type=\"button\"\n                onClick={() => setOpen((v) => !v)}\n                aria-haspopup=\"menu\"\n                aria-expanded={open}\n                aria-label={`Signed in as ${account.didOc}. Open account menu.`}\n                className={triggerClassName}\n                data-oc-account-chip-trigger=\"\"\n                style={\n                    triggerClassName\n                        ? undefined\n                        : {\n                              display: 'inline-flex',\n                              alignItems: 'center',\n                              gap: '0.4rem',\n                              padding: '0.25rem 0.625rem',\n                              borderRadius: '9999px',\n                              border: '1px solid var(--border, #27272a)',\n                              background:\n                                  'color-mix(in oklch, var(--muted, #27272a) 40%, transparent)',\n                              color: 'var(--foreground, #fafafa)',\n                              fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                              fontSize: 12,\n                              cursor: 'pointer',\n                          }\n                }\n            >\n                <span aria-hidden=\"true\" style={{ color: '#22c55e', fontSize: 8 }}>\n                    ●\n                </span>\n                <span>{account.displayName ?? shortenAddress(account.didOc)}</span>\n                <svg\n                    width=\"9\"\n                    height=\"9\"\n                    viewBox=\"0 0 10 10\"\n                    aria-hidden=\"true\"\n                    style={{\n                        transition: 'transform 120ms',\n                        transform: open ? 'rotate(180deg)' : 'rotate(0)',\n                        opacity: 0.6,\n                    }}\n                >\n                    <path\n                        d=\"M2 4 L5 7 L8 4\"\n                        stroke=\"currentColor\"\n                        strokeWidth=\"1.5\"\n                        fill=\"none\"\n                        strokeLinecap=\"round\"\n                    />\n                </svg>\n            </button>\n\n            {open && (\n                <div\n                    role=\"menu\"\n                    aria-label=\"Account menu\"\n                    className={popoverClassName}\n                    data-oc-account-chip-popover=\"\"\n                    style={\n                        popoverClassName\n                            ? { position: 'absolute', zIndex: 50, top: 'calc(100% + 6px)', right: 0 }\n                            : {\n                                  position: 'absolute',\n                                  zIndex: 50,\n                                  top: 'calc(100% + 6px)',\n                                  right: 0,\n                                  minWidth: 240,\n                                  background: 'var(--popover, #0a0a0a)',\n                                  color: 'var(--popover-foreground, #fafafa)',\n                                  border: '1px solid var(--border, #27272a)',\n                                  boxShadow: '0 10px 32px -4px rgba(0,0,0,0.35)',\n                                  fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                              }\n                    }\n                >\n                    <div\n                        data-oc-account-chip-header=\"\"\n                        style={{\n                            padding: '0.75rem 0.75rem 0.625rem',\n                            borderBottom: '1px solid var(--border, #27272a)',\n                        }}\n                    >\n                        <div\n                            data-oc-account-chip-label=\"\"\n                            style={{\n                                color: 'var(--primary, #f97316)',\n                                fontSize: 10,\n                                letterSpacing: '0.18em',\n                                textTransform: 'uppercase',\n                                marginBottom: 4,\n                            }}\n                        >\n                            § signed in\n                        </div>\n                        <div\n                            data-oc-account-chip-address=\"\"\n                            style={{\n                                color: 'var(--popover-foreground, #fafafa)',\n                                fontSize: 11,\n                                wordBreak: 'break-all',\n                                lineHeight: 1.35,\n                            }}\n                        >\n                            {account.didOc}\n                        </div>\n                        {account.displayName ? (\n                            <div\n                                style={{\n                                    color: 'var(--muted-foreground, #a1a1aa)',\n                                    fontSize: 10,\n                                    marginTop: 4,\n                                    letterSpacing: '0.06em',\n                                }}\n                            >\n                                {account.displayName}\n                            </div>\n                        ) : null}\n                    </div>\n                    <div role=\"none\" style={{ padding: '0.25rem' }}>\n                        {dashboardUrl ? (\n                            <a\n                                role=\"menuitem\"\n                                href={dashboardUrl}\n                                onClick={() => setOpen(false)}\n                                className={menuItemClassName}\n                                data-oc-account-chip-item=\"\"\n                                style={\n                                    menuItemClassName\n                                        ? undefined\n                                        : {\n                                              display: 'flex',\n                                              alignItems: 'center',\n                                              gap: '0.5rem',\n                                              padding: '0.5rem 0.625rem',\n                                              fontSize: 12,\n                                              color: 'var(--popover-foreground, #fafafa)',\n                                              textDecoration: 'none',\n                                              cursor: 'pointer',\n                                          }\n                                }\n                            >\n                                <span\n                                    aria-hidden=\"true\"\n                                    style={{ color: 'var(--muted-foreground, #a1a1aa)' }}\n                                >\n                                    →\n                                </span>\n                                <span style={{ flex: 1 }}>dashboard</span>\n                                <span\n                                    style={{\n                                        color: 'var(--muted-foreground, #a1a1aa)',\n                                        fontSize: 10,\n                                    }}\n                                >\n                                    ↗\n                                </span>\n                            </a>\n                        ) : null}\n                        <button\n                            type=\"button\"\n                            role=\"menuitem\"\n                            onClick={() => {\n                                setOpen(false);\n                                void signOut();\n                            }}\n                            className={menuItemClassName}\n                            data-oc-account-chip-item=\"\"\n                            data-oc-account-chip-signout=\"\"\n                            style={\n                                menuItemClassName\n                                    ? undefined\n                                    : {\n                                          display: 'flex',\n                                          alignItems: 'center',\n                                          gap: '0.5rem',\n                                          width: '100%',\n                                          padding: '0.5rem 0.625rem',\n                                          fontSize: 12,\n                                          color: 'var(--popover-foreground, #fafafa)',\n                                          background: 'transparent',\n                                          border: 0,\n                                          fontFamily: 'inherit',\n                                          textAlign: 'left',\n                                          cursor: 'pointer',\n                                      }\n                            }\n                        >\n                            <span\n                                aria-hidden=\"true\"\n                                style={{ color: 'var(--muted-foreground, #a1a1aa)' }}\n                            >\n                                →\n                            </span>\n                            <span style={{ flex: 1 }}>sign out</span>\n                        </button>\n                    </div>\n                </div>\n            )}\n        </div>\n    );\n}\n\nexport interface OcSignInButtonProps extends React.AnchorHTMLAttributes<HTMLAnchorElement> {\n    /** Label shown when no user is signed in. Defaults to `sign in with bitcoin`. */\n    label?: string;\n    /**\n     * When `true`, render an `<a>` even while the session is loading, to\n     * avoid layout shift. Defaults to `false` (renders nothing while loading).\n     */\n    eager?: boolean;\n    /**\n     * Override the destination URL. Defaults to the session's `signInUrl`\n     * (the auth host's redirect-style /signin). Set this to a local path\n     * like `'/signin'` when the consumer site has its own in-place\n     * `<OcSignIn />` page — keeps the user in-tab.\n     */\n    signInUrl?: string;\n}\n\n/**\n * Drop-in sign-in button. Renders an anchor that points at either:\n *\n *   - the consumer's local `/signin` page (when `signInUrl` prop is set\n *     — recommended; works with `<OcSignIn />`), or\n *   - the auth host's `/signin?return_to=…` (default fallback)\n *\n * When the user is already authenticated it renders nothing.\n */\nexport function OcSignInButton({\n    label = 'sign in with bitcoin',\n    eager = false,\n    className,\n    signInUrl: signInUrlOverride,\n    ...rest\n}: OcSignInButtonProps): React.ReactElement | null {\n    const { status, signInUrl: sessionSignInUrl } = useOcSession();\n    const href = signInUrlOverride ?? sessionSignInUrl;\n    if (status === 'authenticated') return null;\n    if (!eager && status === 'loading') return null;\n\n    return (\n        <a\n            {...rest}\n            href={href}\n            className={className}\n            data-oc-sign-in-button=\"\"\n        >\n            {label}\n        </a>\n    );\n}\n\nexport interface OcAccountPillProps extends React.HTMLAttributes<HTMLDivElement> {\n    /** URL to link the address to. Defaults to the auth origin's `/dashboard`. */\n    dashboardUrl?: string;\n    /** Override the display text. Defaults to the shortened address. */\n    render?: (account: { address: string; displayName?: string | null }) => React.ReactNode;\n}\n\n/**\n * Shows the signed-in user as a short pill: `bc1q…abcd  sign out`.\n *\n * Renders nothing while loading or when no user is signed in — pair with\n * `<OcSignInButton>` for the anonymous case.\n */\nexport function OcAccountPill({\n    dashboardUrl,\n    render,\n    className,\n    ...rest\n}: OcAccountPillProps): React.ReactElement | null {\n    const { status, account, signOut } = useOcSession();\n\n    if (status !== 'authenticated' || !account) return null;\n\n    const label = render\n        ? render({ address: account.didOc, displayName: account.displayName })\n        : (account.displayName ?? shortenAddress(account.didOc));\n\n    return (\n        <div\n            {...rest}\n            className={className}\n            data-oc-account-pill=\"\"\n            style={{ display: 'inline-flex', alignItems: 'center', gap: '0.5rem', ...(rest.style ?? {}) }}\n        >\n            {dashboardUrl ? (\n                <a href={dashboardUrl}>{label}</a>\n            ) : (\n                <span>{label}</span>\n            )}\n            <button\n                type=\"button\"\n                onClick={() => {\n                    void signOut();\n                }}\n                aria-label=\"Sign out\"\n                style={{\n                    background: 'none',\n                    border: 'none',\n                    cursor: 'pointer',\n                    color: 'inherit',\n                    font: 'inherit',\n                    padding: 0,\n                }}\n            >\n                sign out\n            </button>\n        </div>\n    );\n}\n\nexport interface OcAddressInputProps\n    extends Omit<React.InputHTMLAttributes<HTMLInputElement>, 'value' | 'onChange'> {\n    /** Controlled value. */\n    value: string;\n    /** Called when value changes — typed by the user OR selected from the popover. */\n    onValueChange: (value: string) => void;\n    /** Label shown above the suggested address in the popover. Defaults to `use your address`. */\n    suggestionLabel?: string;\n    /** className applied to the wrapper `<div>`. */\n    wrapperClassName?: string;\n    /** className applied to the suggestion popover. Style with `[data-oc-address-popover]` otherwise. */\n    popoverClassName?: string;\n    /** className applied to the suggestion button. Style with `[data-oc-address-suggestion]` otherwise. */\n    suggestionClassName?: string;\n}\n\n/**\n * Bitcoin-address `<input>` that, when the user is signed in via `oc_session`,\n * surfaces their address as a one-click suggestion on focus.\n *\n * Behaviour:\n * - On focus, if logged-in AND the typed value is a prefix of the session\n *   address (or empty), show a small popover with `bc1q…7ke3` as a clickable\n *   suggestion.\n * - Click / Enter on the suggestion fills the field with the full address.\n * - Down-arrow from the input highlights the suggestion; Up-arrow clears the\n *   highlight; Escape closes the popover; clicking outside closes the popover.\n * - When the user types something that's no longer a prefix of the session\n *   address, the popover hides itself out of the way.\n * - When the field already contains the session address exactly, no popover.\n *\n * Style-agnostic: minimal inline styles for positioning only. Style the parts\n * via `wrapperClassName` / `popoverClassName` / `suggestionClassName`, or via\n * the `[data-oc-address-input]`, `[data-oc-address-popover]`, and\n * `[data-oc-address-suggestion]` data attributes.\n */\nexport interface UseOcAddressSuggestionOptions {\n    /** Current value of the input. */\n    value: string;\n    /** Called when the user selects the suggestion (or you may also call it from the input's onChange). */\n    onValueChange: (value: string) => void;\n    /** Label shown above the suggested address in the popover. Defaults to `use your address`. */\n    suggestionLabel?: string;\n    /** className applied to the suggestion popover. Style with `[data-oc-address-popover]` otherwise. */\n    popoverClassName?: string;\n    /** className applied to the suggestion button. Style with `[data-oc-address-suggestion]` otherwise. */\n    suggestionClassName?: string;\n}\n\nexport interface UseOcAddressSuggestionReturn {\n    /**\n     * Props to spread onto your `<input>` element. Adds focus/blur/keydown\n     * handlers and the combobox ARIA attributes. Combine with your existing\n     * `value`/`onChange` props — this hook does NOT control them.\n     */\n    inputProps: {\n        onFocus: (e: React.FocusEvent<HTMLInputElement>) => void;\n        onBlur: (e: React.FocusEvent<HTMLInputElement>) => void;\n        onKeyDown: (e: React.KeyboardEvent<HTMLInputElement>) => void;\n        role: 'combobox';\n        'aria-haspopup': 'listbox';\n        'aria-expanded': boolean;\n        'aria-controls': string | undefined;\n        'aria-activedescendant': string | undefined;\n        autoComplete: 'off';\n        spellCheck: false;\n    };\n    /**\n     * The suggestion popover. Render directly after your `<input>`, inside a\n     * `position: relative` container so the popover anchors below the input.\n     * Returns `null` when there's no suggestion to show.\n     */\n    popover: React.ReactNode;\n}\n\n/**\n * Hook variant of `OcAddressInput`. Use when you want to keep your existing\n * styled `<input>` (e.g. shadcn `<Input>`) and just bolt on the\n * session-address suggestion behaviour.\n *\n * Wrap your input in a `position: relative` container, spread `inputProps`\n * onto the input, and render `{popover}` immediately after. The hook's\n * focus / blur / keydown handlers are composed via `inputProps` — they call\n * any handlers you've already passed to your input only when you wire them\n * yourself in addition to spreading `inputProps`.\n *\n * Example:\n * ```tsx\n * const { inputProps, popover } = useOcAddressSuggestion({\n *     value: addr,\n *     onValueChange: setAddr,\n * });\n * return (\n *     <div className=\"relative\">\n *         <Input\n *             value={addr}\n *             onChange={(e) => setAddr(e.target.value)}\n *             {...inputProps}\n *             placeholder=\"bc1q…\"\n *         />\n *         {popover}\n *     </div>\n * );\n * ```\n */\nexport function useOcAddressSuggestion(\n    options: UseOcAddressSuggestionOptions\n): UseOcAddressSuggestionReturn {\n    const {\n        value,\n        onValueChange,\n        suggestionLabel = 'use your address',\n        popoverClassName,\n        suggestionClassName,\n    } = options;\n\n    const { status, account } = useOcSession();\n    const sessionAddress = status === 'authenticated' ? (account?.primaryBtc ?? null) : null;\n\n    const [open, setOpen] = React.useState(false);\n    const [highlighted, setHighlighted] = React.useState(false);\n    const blurTimer = React.useRef<number | null>(null);\n\n    const listboxId = useUniqueId('oc-addr-listbox');\n    const optionId = `${listboxId}-opt`;\n\n    const valueMatchesSession =\n        sessionAddress != null && value.toLowerCase() === sessionAddress.toLowerCase();\n    const canSuggest =\n        sessionAddress != null &&\n        sessionAddress.length > 0 &&\n        !valueMatchesSession &&\n        isPrefixOf(value, sessionAddress);\n    const showPopover = open && canSuggest;\n\n    function selectSuggestion() {\n        if (!sessionAddress) return;\n        onValueChange(sessionAddress);\n        setOpen(false);\n        setHighlighted(false);\n    }\n\n    React.useEffect(() => {\n        return () => {\n            if (blurTimer.current != null) window.clearTimeout(blurTimer.current);\n        };\n    }, []);\n\n    const inputProps: UseOcAddressSuggestionReturn['inputProps'] = {\n        onFocus: () => {\n            if (blurTimer.current != null) {\n                window.clearTimeout(blurTimer.current);\n                blurTimer.current = null;\n            }\n            setOpen(true);\n        },\n        onBlur: () => {\n            blurTimer.current = window.setTimeout(() => {\n                setOpen(false);\n                setHighlighted(false);\n            }, 120);\n        },\n        onKeyDown: (e: React.KeyboardEvent<HTMLInputElement>) => {\n            if (!showPopover) return;\n            if (e.key === 'ArrowDown') {\n                e.preventDefault();\n                setHighlighted(true);\n            } else if (e.key === 'ArrowUp') {\n                e.preventDefault();\n                setHighlighted(false);\n            } else if (e.key === 'Escape') {\n                e.preventDefault();\n                setOpen(false);\n                setHighlighted(false);\n            } else if (e.key === 'Enter' && highlighted) {\n                e.preventDefault();\n                selectSuggestion();\n            }\n        },\n        role: 'combobox',\n        'aria-haspopup': 'listbox',\n        'aria-expanded': showPopover,\n        'aria-controls': showPopover ? listboxId : undefined,\n        'aria-activedescendant': highlighted ? optionId : undefined,\n        autoComplete: 'off',\n        spellCheck: false,\n    };\n\n    const popover = showPopover && sessionAddress ? (\n        <div\n            id={listboxId}\n            role=\"listbox\"\n            data-oc-address-popover=\"\"\n            className={popoverClassName}\n            style={{\n                position: 'absolute',\n                zIndex: 50,\n                top: 'calc(100% + 4px)',\n                left: 0,\n                right: 0,\n            }}\n            onMouseDown={(e) => e.preventDefault()}\n        >\n            <button\n                type=\"button\"\n                id={optionId}\n                role=\"option\"\n                aria-selected={highlighted}\n                data-oc-address-suggestion=\"\"\n                data-highlighted={highlighted ? '' : undefined}\n                className={suggestionClassName}\n                onClick={selectSuggestion}\n                onMouseEnter={() => setHighlighted(true)}\n                onMouseLeave={() => setHighlighted(false)}\n                style={{\n                    display: 'flex',\n                    alignItems: 'center',\n                    justifyContent: 'space-between',\n                    gap: '0.75rem',\n                    width: '100%',\n                    textAlign: 'left',\n                    cursor: 'pointer',\n                    font: 'inherit',\n                    background: 'inherit',\n                    color: 'inherit',\n                    border: 0,\n                    padding: 'inherit',\n                }}\n            >\n                <span data-oc-address-suggestion-label=\"\">{suggestionLabel}</span>\n                <span\n                    data-oc-address-suggestion-value=\"\"\n                    style={{ fontFamily: 'ui-monospace, monospace' }}\n                >\n                    {shortenAddressMid(sessionAddress)}\n                </span>\n            </button>\n        </div>\n    ) : null;\n\n    return { inputProps, popover };\n}\n\nexport const OcAddressInput = React.forwardRef<HTMLInputElement, OcAddressInputProps>(\n    function OcAddressInput(\n        {\n            value,\n            onValueChange,\n            suggestionLabel = 'use your address',\n            wrapperClassName,\n            popoverClassName,\n            suggestionClassName,\n            onFocus,\n            onBlur,\n            onKeyDown,\n            ...rest\n        },\n        forwardedRef\n    ): React.ReactElement {\n        const { status, account } = useOcSession();\n        const sessionAddress = status === 'authenticated' ? (account?.primaryBtc ?? null) : null;\n\n        const [open, setOpen] = React.useState(false);\n        const [highlighted, setHighlighted] = React.useState(false);\n\n        const innerRef = React.useRef<HTMLInputElement | null>(null);\n        const setRef = (node: HTMLInputElement | null) => {\n            innerRef.current = node;\n            if (typeof forwardedRef === 'function') forwardedRef(node);\n            else if (forwardedRef) forwardedRef.current = node;\n        };\n        const blurTimer = React.useRef<number | null>(null);\n\n        const listboxId = useUniqueId('oc-addr-listbox');\n        const optionId = `${listboxId}-opt`;\n\n        const valueMatchesSession =\n            sessionAddress != null && value.toLowerCase() === sessionAddress.toLowerCase();\n        const canSuggest =\n            sessionAddress != null &&\n            sessionAddress.length > 0 &&\n            !valueMatchesSession &&\n            isPrefixOf(value, sessionAddress);\n        const showPopover = open && canSuggest;\n\n        function selectSuggestion() {\n            if (!sessionAddress) return;\n            onValueChange(sessionAddress);\n            setOpen(false);\n            setHighlighted(false);\n            // Re-focus so the next Tab moves on naturally.\n            innerRef.current?.focus();\n        }\n\n        function handleFocus(e: React.FocusEvent<HTMLInputElement>) {\n            if (blurTimer.current != null) {\n                window.clearTimeout(blurTimer.current);\n                blurTimer.current = null;\n            }\n            setOpen(true);\n            onFocus?.(e);\n        }\n\n        function handleBlur(e: React.FocusEvent<HTMLInputElement>) {\n            // Defer close so a click on the suggestion can register first.\n            blurTimer.current = window.setTimeout(() => {\n                setOpen(false);\n                setHighlighted(false);\n            }, 120);\n            onBlur?.(e);\n        }\n\n        function handleKeyDown(e: React.KeyboardEvent<HTMLInputElement>) {\n            if (showPopover) {\n                if (e.key === 'ArrowDown') {\n                    e.preventDefault();\n                    setHighlighted(true);\n                } else if (e.key === 'ArrowUp') {\n                    e.preventDefault();\n                    setHighlighted(false);\n                } else if (e.key === 'Escape') {\n                    e.preventDefault();\n                    setOpen(false);\n                    setHighlighted(false);\n                } else if (e.key === 'Enter' && highlighted) {\n                    e.preventDefault();\n                    selectSuggestion();\n                }\n            }\n            onKeyDown?.(e);\n        }\n\n        React.useEffect(() => {\n            return () => {\n                if (blurTimer.current != null) window.clearTimeout(blurTimer.current);\n            };\n        }, []);\n\n        return (\n            <div\n                data-oc-address-input=\"\"\n                className={wrapperClassName}\n                style={{ position: 'relative' }}\n            >\n                <input\n                    {...rest}\n                    ref={setRef}\n                    value={value}\n                    onChange={(e) => onValueChange(e.target.value)}\n                    onFocus={handleFocus}\n                    onBlur={handleBlur}\n                    onKeyDown={handleKeyDown}\n                    role=\"combobox\"\n                    aria-haspopup=\"listbox\"\n                    aria-expanded={showPopover}\n                    aria-controls={showPopover ? listboxId : undefined}\n                    aria-activedescendant={highlighted ? optionId : undefined}\n                    autoComplete=\"off\"\n                    spellCheck={false}\n                />\n                {showPopover && sessionAddress && (\n                    <div\n                        id={listboxId}\n                        role=\"listbox\"\n                        data-oc-address-popover=\"\"\n                        className={popoverClassName}\n                        style={{\n                            position: 'absolute',\n                            zIndex: 50,\n                            top: 'calc(100% + 4px)',\n                            left: 0,\n                            right: 0,\n                        }}\n                        // Prevent the input from blurring before the click on the suggestion lands.\n                        onMouseDown={(e) => e.preventDefault()}\n                    >\n                        <button\n                            type=\"button\"\n                            id={optionId}\n                            role=\"option\"\n                            aria-selected={highlighted}\n                            data-oc-address-suggestion=\"\"\n                            data-highlighted={highlighted ? '' : undefined}\n                            className={suggestionClassName}\n                            onClick={selectSuggestion}\n                            onMouseEnter={() => setHighlighted(true)}\n                            onMouseLeave={() => setHighlighted(false)}\n                            style={{\n                                display: 'flex',\n                                alignItems: 'center',\n                                justifyContent: 'space-between',\n                                gap: '0.75rem',\n                                width: '100%',\n                                textAlign: 'left',\n                                cursor: 'pointer',\n                                font: 'inherit',\n                                background: 'inherit',\n                                color: 'inherit',\n                                border: 'inherit',\n                                padding: 'inherit',\n                            }}\n                        >\n                            <span data-oc-address-suggestion-label=\"\">{suggestionLabel}</span>\n                            <span\n                                data-oc-address-suggestion-value=\"\"\n                                style={{ fontFamily: 'ui-monospace, monospace' }}\n                            >\n                                {shortenAddressMid(sessionAddress)}\n                            </span>\n                        </button>\n                    </div>\n                )}\n            </div>\n        );\n    }\n);\n","/**\n * Inline sudo-mode helpers · the consumer-side counterpart to the\n * ochk.io `/sudo` page.\n *\n * Pattern: when a consumer-side action hits a `401 sudo_required`\n * response from the auth host, call `redirectToSudo()` to bounce the\n * user to `https://ochk.io/sudo?return_to=<current>&purpose=<tag>`.\n * The user completes the email-OTP or BIP-322 re-authentication\n * inline on ochk.io; ochk.io re-issues the session JWT with a fresh\n * `sudo_at` claim; the browser is redirected back; the consumer's\n * original action succeeds on retry.\n *\n * No React hook needed for v1 · this is a one-shot navigation. A\n * future inline-modal version (no redirect) lives behind the same\n * function name so consumers don't have to change call-sites when we\n * upgrade.\n *\n * Server-side, gate sensitive endpoints with `verifySudoClaim()` from\n * @orangecheck/auth-core@^2.2.0.\n */\n\nimport { resolveConfig, type OcAuthConfig } from './types';\n\nexport interface RedirectToSudoArgs {\n    /** Where to send the browser after the user finishes the sudo\n     *  ceremony. Defaults to `window.location.href` at call-time.\n     *  Must be a family origin (`*.ochk.io`) or a relative path; the\n     *  /sudo page coerces unsafe values to /dashboard. */\n    returnTo?: string;\n    /** Free-form tag echoed in the /sudo page UI — e.g. `\"register a\n     *  hardware key\"`. The user sees \"To <purpose>, confirm with the\n     *  one-time code…\" so the prompt is framed by the action that\n     *  triggered it. Not security-relevant. */\n    purpose?: string;\n    /** Optional auth-client config override · same shape as\n     *  `<OcSessionProvider config={…} />`. Defaults to\n     *  `authOrigin: 'https://ochk.io'`. */\n    config?: OcAuthConfig;\n}\n\n/**\n * Redirect the current browser to the auth host's `/sudo` page,\n * preserving `return_to` and `purpose` query parameters. The auth\n * host runs the ceremony and bounces back on success.\n *\n * Throws on SSR — call this only inside a click handler or effect\n * after a `'sudo_required'` response.\n */\nexport function redirectToSudo(args: RedirectToSudoArgs = {}): void {\n    if (typeof window === 'undefined') {\n        throw new Error(\n            '[@orangecheck/auth-client] redirectToSudo() requires a browser environment'\n        );\n    }\n    const cfg = resolveConfig(args.config);\n    const url = new URL('/sudo', cfg.authOrigin);\n    const returnTo = args.returnTo ?? window.location.href;\n    if (returnTo) url.searchParams.set('return_to', returnTo);\n    if (args.purpose) url.searchParams.set('purpose', args.purpose);\n    window.location.assign(url.toString());\n}\n\n/**\n * Convenience wrapper · the most common consumer pattern is \"if the\n * fetch response's body has `reason === 'sudo_required'`, redirect.\"\n * Use this to keep that idiom one line:\n *\n *   const r = await fetch(...);\n *   const j = await r.json();\n *   if (handleSudoRequired(j, { purpose: 'register hardware key' })) return;\n *\n * Returns `true` if a redirect happened (and the caller should\n * short-circuit), `false` otherwise.\n */\nexport function handleSudoRequired(\n    body: { reason?: string } | null | undefined,\n    args: Omit<RedirectToSudoArgs, 'returnTo'> & { returnTo?: string } = {}\n): boolean {\n    if (body && body.reason === 'sudo_required') {\n        redirectToSudo(args);\n        return true;\n    }\n    return false;\n}\n\n/**\n * The message for `sudo_account_mismatch` — a fresh sudo proof exists, but for\n * a different account than this tab is acting as.\n *\n * Deliberately NOT a redirect. The ceremony runs on ochk.io for the cookie's\n * default account and cannot reach this tab's pinned account, so bouncing there\n * re-proves the wrong one forever. Callers must show this and stop.\n */\nexport const SUDO_ACCOUNT_MISMATCH_MESSAGE =\n    'Switch this tab to that account first — the confirmation on file is for a different one.';\n\n/**\n * True when the response says a sudo ceremony cannot resolve this request.\n * Pairs with {@link handleSudoRequired}: try the redirect first, then this.\n */\nexport function isSudoAccountMismatch(body: { reason?: string } | null | undefined): boolean {\n    return body?.reason === 'sudo_account_mismatch';\n}\n","'use client';\n\n/**\n * @orangecheck/auth-client · OcLinkedIdentities\n *\n * The shared linked-identities management surface for every `X.ochk.io`\n * consumer. A signed-in user sees their linked email + Bitcoin address,\n * can reveal/hide each raw value, unlink a non-primary identity, and\n * link a new one. Linking a Bitcoin address that's already on another\n * OC account offers a dual-proof transfer; the same is now true for\n * email (auth host F4). Consolidated (`merged_from`) accounts render in\n * a tombstone panel.\n *\n * This generalizes me.ochk.io's bespoke `LinkedIdentitiesPanel` so\n * linking is no longer a single-product, one-tab feature — any family\n * site can drop in `<OcLinkedIdentities />`. See AUTH-PLAN.md §5.\n *\n * All endpoints live on the auth host (`ochk.io`); calls are\n * cross-origin with `credentials: 'include'` and rely on the auth\n * host's family-CORS — the same posture `OcSignIn` uses. No local\n * proxy route is needed (AUTH-AUDIT.md F6: direct-to-host is the\n * intended design).\n *\n * Style: inline, CSS-variable-themed (same approach as `OcSignIn`), so\n * the component carries zero CSS dependency and themes to each site.\n * Every block carries a `data-oc-li-*` attribute so a site may\n * override via its own stylesheet.\n */\n\nimport * as React from 'react';\nimport {\n    handleSudoRequired,\n    isSudoAccountMismatch,\n    SUDO_ACCOUNT_MISMATCH_MESSAGE,\n} from './sudo';\n\nimport { tabSessionHeader } from './tab-session';\n\nconst DEFAULT_AUTH_ORIGIN = 'https://ochk.io';\n\n/* --- types --- */\n\nexport interface OcLinkedIdentity {\n    id: string;\n    kind: 'email' | 'btc';\n    /** Raw value · null when the identity is pending recovery. */\n    value: string | null;\n    verified_at: string | null;\n    verification_method: 'email-otp' | 'bip322' | null;\n    /** The signup-time identity for its kind · cannot be unlinked here. */\n    is_primary: boolean;\n}\n\ninterface MergedFromEntry {\n    did_oc: string;\n    created_at: string;\n    last_signed_in_at: string | null;\n}\n\ninterface IdentitiesResp {\n    ok: boolean;\n    account_id?: string;\n    did_oc?: string | null;\n    linked?: OcLinkedIdentity[];\n    merged_from?: MergedFromEntry[];\n    reason?: string;\n}\n\n/**\n * Fetch the signed-in user's linked identities from the auth host —\n * the same data `<OcLinkedIdentities>` renders, exposed as a plain\n * function for surfaces that need the list without the full\n * management UI (notably `<OcAccountMenu>`'s badge-identity promote\n * list). Returns `[]` when anonymous; throws on network / server\n * error so the caller can show a deferred state.\n */\nexport async function fetchOcLinkedIdentities(opts?: {\n    authOrigin?: string;\n}): Promise<OcLinkedIdentity[]> {\n    const authOrigin = opts?.authOrigin ?? DEFAULT_AUTH_ORIGIN;\n    // Per-tab pinning: forward the tab's session JWT so the host resolves\n    // the SAME account this tab displays (its chip reads /api/auth/me\n    // tab-aware). Without this, a pinned tab's show-as list is the shared\n    // cookie account's identities — a menu that disagrees with itself.\n    // Unpinned tabs send no header → unchanged cookie-default behavior.\n    const r = await fetch(`${authOrigin}/api/auth/identities`, {\n        credentials: 'include',\n        headers: { ...tabSessionHeader() },\n    });\n    if (r.status === 401) return [];\n    if (!r.ok) throw new Error(`identities fetch failed: http_${r.status}`);\n    const body = (await r.json()) as IdentitiesResp;\n    return body.linked ?? [];\n}\n\nexport interface OcLinkedIdentitiesProps {\n    /** Auth host origin. Defaults to `https://ochk.io`. */\n    authOrigin?: string;\n    /** Outer container className. */\n    className?: string;\n    /** Called after every successful link / unlink / transfer. */\n    onChange?: () => void;\n}\n\n/* --- main --- */\n\nexport function OcLinkedIdentities({\n    authOrigin = DEFAULT_AUTH_ORIGIN,\n    className,\n    onChange,\n}: OcLinkedIdentitiesProps): React.ReactElement {\n    const [resp, setResp] = React.useState<IdentitiesResp | null>(null);\n    const [error, setError] = React.useState<string | null>(null);\n    const [showEmailLink, setShowEmailLink] = React.useState(false);\n    const [showBtcLink, setShowBtcLink] = React.useState(false);\n\n    const refresh = React.useCallback(async () => {\n        setError(null);\n        try {\n            const r = await fetch(`${authOrigin}/api/auth/identities`, {\n                credentials: 'include',\n                headers: { ...tabSessionHeader() },\n            });\n            if (!r.ok) {\n                if (r.status === 401) {\n                    setError('not signed in');\n                    return;\n                }\n                throw new Error(`http_${r.status}`);\n            }\n            setResp((await r.json()) as IdentitiesResp);\n        } catch (e) {\n            setError(e instanceof Error ? e.message : 'load failed');\n        }\n    }, [authOrigin]);\n\n    React.useEffect(() => {\n        void refresh();\n    }, [refresh]);\n\n    const afterChange = React.useCallback(() => {\n        setShowEmailLink(false);\n        setShowBtcLink(false);\n        void refresh();\n        onChange?.();\n    }, [refresh, onChange]);\n\n    if (error) {\n        return (\n            <div className={className} data-oc-li=\"\" style={panelStyle('warn')} role=\"alert\">\n                <SectionLabel tone=\"warn\">§ identities · load deferred</SectionLabel>\n                <p style={bodyStyle}>\n                    Couldn&apos;t reach the auth host ({error}). Linking is temporarily\n                    unavailable; your signed-in identity still works as normal.\n                </p>\n                <button type=\"button\" onClick={() => void refresh()} style={ghostBtnStyle(false)}>\n                    retry\n                </button>\n            </div>\n        );\n    }\n\n    if (!resp) {\n        return (\n            <div className={className} data-oc-li=\"\" style={panelStyle()}>\n                <span style={hintStyle}>{'> '}loading…</span>\n            </div>\n        );\n    }\n\n    const linked = resp.linked ?? [];\n    const emailRows = linked.filter((i) => i.kind === 'email');\n    const btcRows = linked.filter((i) => i.kind === 'btc');\n    const hasEmail = emailRows.some((i) => i.value);\n    const hasBtc = btcRows.some((i) => i.value);\n    const mergedFrom = resp.merged_from ?? [];\n\n    return (\n        <div className={className} data-oc-li=\"\" style={{ display: 'grid', gap: 16 }}>\n            <div style={panelStyle()}>\n                <SectionLabel>§ what this is</SectionLabel>\n                <p style={bodyStyle}>\n                    Your public identity is the opaque <code style={codeStyle}>did:oc:</code> DID.\n                    Below it sit your private linked identities — your email and your Bitcoin\n                    address. They never appear in dashboard chrome and never reach an integrator\n                    unless you grant the matching scope. Linking a second identity is also your\n                    account-recovery path: if you lose one, the other still signs you in.\n                </p>\n            </div>\n\n            {mergedFrom.length > 0 && <ConsolidationPanel entries={mergedFrom} />}\n\n            <div style={panelStyle('plain')} data-oc-li-rows=\"\">\n                <IdentityGroup\n                    kind=\"email\"\n                    title=\"email\"\n                    rows={emailRows}\n                    authOrigin={authOrigin}\n                    onChange={afterChange}\n                    addCta={hasEmail ? null : 'link an email'}\n                    onAdd={() => {\n                        setShowEmailLink((v) => !v);\n                        setShowBtcLink(false);\n                    }}\n                />\n                <div style={{ borderTop: `1px solid ${V.border}` }} />\n                <IdentityGroup\n                    kind=\"btc\"\n                    title=\"bitcoin address\"\n                    rows={btcRows}\n                    authOrigin={authOrigin}\n                    onChange={afterChange}\n                    addCta={hasBtc ? null : 'link a Bitcoin address'}\n                    onAdd={() => {\n                        setShowBtcLink((v) => !v);\n                        setShowEmailLink(false);\n                    }}\n                />\n            </div>\n\n            {showEmailLink && (\n                <EmailLinkForm\n                    authOrigin={authOrigin}\n                    onDone={afterChange}\n                    onCancel={() => setShowEmailLink(false)}\n                />\n            )}\n            {showBtcLink && (\n                <BtcLinkForm\n                    authOrigin={authOrigin}\n                    didOc={resp.did_oc ?? null}\n                    onDone={afterChange}\n                    onCancel={() => setShowBtcLink(false)}\n                />\n            )}\n\n            {hasBtc && <AttestationLink />}\n        </div>\n    );\n}\n\n/* --- identity group (rows for one kind, or an empty-state add CTA) --- */\n\nfunction IdentityGroup({\n    kind,\n    title,\n    rows,\n    authOrigin,\n    onChange,\n    addCta,\n    onAdd,\n}: {\n    kind: 'email' | 'btc';\n    title: string;\n    rows: OcLinkedIdentity[];\n    authOrigin: string;\n    onChange: () => void;\n    addCta: string | null;\n    onAdd: () => void;\n}): React.ReactElement {\n    if (rows.length === 0) {\n        return (\n            <div style={rowStyle}>\n                <div>\n                    <div style={rowLabelStyle}>§ {title}</div>\n                    <div style={{ ...bodyStyle, marginTop: 4 }}>none linked</div>\n                </div>\n                {addCta && (\n                    <button type=\"button\" onClick={onAdd} style={primaryChipStyle}>\n                        + {addCta}\n                    </button>\n                )}\n            </div>\n        );\n    }\n    return (\n        <>\n            {rows.map((r) => (\n                <IdentityRow\n                    key={r.id}\n                    row={r}\n                    kind={kind}\n                    authOrigin={authOrigin}\n                    onChange={onChange}\n                />\n            ))}\n        </>\n    );\n}\n\n/* --- single identity row --- */\n\nfunction IdentityRow({\n    row,\n    kind,\n    authOrigin,\n    onChange,\n}: {\n    row: OcLinkedIdentity;\n    kind: 'email' | 'btc';\n    authOrigin: string;\n    onChange: () => void;\n}): React.ReactElement {\n    const [shown, setShown] = React.useState(false);\n    const [confirming, setConfirming] = React.useState(false);\n    const [busy, setBusy] = React.useState(false);\n    const [err, setErr] = React.useState<string | null>(null);\n\n    const masked = row.value ? mask(row.value, kind) : '— pending recovery —';\n    const display = shown && row.value ? row.value : masked;\n\n    async function unlink(): Promise<void> {\n        if (row.is_primary) return;\n        setBusy(true);\n        setErr(null);\n        try {\n            const r = await fetch(\n                `${authOrigin}/api/auth/identities?id=${encodeURIComponent(row.id)}`,\n                { method: 'DELETE', credentials: 'include' }\n            );\n            if (!r.ok) {\n                const j = (await r.json().catch(() => ({}))) as { reason?: string };\n                throw new Error(j.reason ?? `http_${r.status}`);\n            }\n            onChange();\n        } catch (e) {\n            setErr(e instanceof Error ? e.message : 'unlink failed');\n            setBusy(false);\n            setConfirming(false);\n        }\n    }\n\n    return (\n        <div style={rowStyle} data-oc-li-row={kind}>\n            <div style={{ minWidth: 0, flex: 1 }}>\n                <div style={{ display: 'flex', flexWrap: 'wrap', gap: '4px 12px' }}>\n                    <span style={rowLabelStyle}>\n                        § {kind === 'email' ? 'email' : 'bitcoin address'}\n                    </span>\n                    {row.is_primary && (\n                        <span style={{ ...rowLabelStyle, color: V.primary }}>\n                            primary · signup-time\n                        </span>\n                    )}\n                </div>\n                <div\n                    style={{\n                        marginTop: 4,\n                        color: V.foreground,\n                        fontFamily: MONO,\n                        fontSize: 12,\n                        wordBreak: 'break-all',\n                    }}\n                >\n                    {display}\n                </div>\n                {row.verified_at && (\n                    <div style={{ ...hintStyle, marginTop: 4 }}>\n                        verified · {new Date(row.verified_at).toUTCString()}\n                    </div>\n                )}\n                {err && <ErrorLine>{err}</ErrorLine>}\n            </div>\n            <div style={{ display: 'flex', flexShrink: 0, gap: 8, flexWrap: 'wrap' }}>\n                {row.value && (\n                    <button\n                        type=\"button\"\n                        onClick={() => setShown((s) => !s)}\n                        style={ghostBtnStyle(false)}\n                    >\n                        {shown ? 'hide' : 'show'}\n                    </button>\n                )}\n                {!row.is_primary && !confirming && (\n                    <button\n                        type=\"button\"\n                        onClick={() => setConfirming(true)}\n                        style={dangerBtnStyle(false)}\n                    >\n                        unlink\n                    </button>\n                )}\n                {!row.is_primary && confirming && (\n                    <>\n                        <button\n                            type=\"button\"\n                            onClick={() => void unlink()}\n                            disabled={busy}\n                            style={dangerBtnStyle(busy)}\n                        >\n                            {busy ? 'unlinking…' : 'confirm unlink'}\n                        </button>\n                        <button\n                            type=\"button\"\n                            onClick={() => setConfirming(false)}\n                            disabled={busy}\n                            style={ghostBtnStyle(busy)}\n                        >\n                            cancel\n                        </button>\n                    </>\n                )}\n            </div>\n        </div>\n    );\n}\n\n/* --- consolidated-accounts tombstone panel --- */\n\nfunction ConsolidationPanel({ entries }: { entries: MergedFromEntry[] }): React.ReactElement {\n    return (\n        <div style={panelStyle('success')} data-oc-li-consolidated=\"\">\n            <SectionLabel tone=\"success\">\n                § consolidated accounts · {entries.length}\n            </SectionLabel>\n            <p style={bodyStyle}>\n                {entries.length === 1 ? 'A previous OC account' : 'Previous OC accounts'} you\n                signed up with, folded into this one under dual proof of control. Historical\n                activity is unioned into this account automatically;{' '}\n                {entries.length === 1 ? 'it' : 'they'} can no longer sign in.\n            </p>\n            <ul style={{ listStyle: 'none', margin: '12px 0 0', padding: 0 }}>\n                {entries.map((e) => (\n                    <li\n                        key={e.did_oc}\n                        style={{\n                            display: 'flex',\n                            flexWrap: 'wrap',\n                            gap: 8,\n                            padding: '8px 0',\n                            borderTop: `1px solid ${V.border}`,\n                            fontFamily: MONO,\n                            fontSize: 11,\n                        }}\n                    >\n                        <code style={{ color: V.foreground, wordBreak: 'break-all' }}>\n                            {e.did_oc}\n                        </code>\n                        <span style={{ ...hintStyle, marginLeft: 'auto' }}>\n                            created {new Date(e.created_at).toLocaleDateString()}\n                        </span>\n                    </li>\n                ))}\n            </ul>\n        </div>\n    );\n}\n\n/* --- portable-attestation pointer --- */\n\n/**\n * A thin pointer to the OC Attest builder. The portable, self-sovereign\n * form of identity linking is a standard OrangeCheck attestation — one\n * BIP-322 signature by the Bitcoin address binding it to its handles,\n * published to Nostr. That ceremony already lives at\n * `attest.ochk.io/create` (which pre-fills the address from the signed-in\n * session); this panel routes the user there rather than re-implementing\n * it. Shown once the account has a linked Bitcoin address to attest with.\n */\nfunction AttestationLink(): React.ReactElement {\n    return (\n        <div style={panelStyle()} data-oc-li-attest=\"\">\n            <SectionLabel>§ portable attestation</SectionLabel>\n            <p style={bodyStyle}>\n                Make your identity links portable: publish a standard OrangeCheck\n                attestation — one Bitcoin-wallet signature (BIP-322) binding your address\n                to your handles (Nostr, GitHub, …). It is published to Nostr and verifies\n                with zero trust in OrangeCheck, so it outlives any single service.\n            </p>\n            <a\n                href=\"https://attest.ochk.io/create\"\n                target=\"_blank\"\n                rel=\"noreferrer\"\n                style={{ ...primaryChipStyle, textDecoration: 'none', display: 'inline-block' }}\n                data-oc-li-attest-link=\"\"\n            >\n                open the attestation builder ↗\n            </a>\n        </div>\n    );\n}\n\n/* --- post-sign-in link prompt (used by OcSignIn) --- */\n\n/**\n * Shown by `<OcSignIn>` after a successful sign-in *when the user ticked\n * the \"also link my other identity\" checkbox on the sign-in form*. It runs\n * the complementary identity's link ceremony inline — BIP-322 for a\n * Bitcoin address, OTP for an email.\n *\n * Skipping is first-class: even though the user opted in at the form, they\n * may change their mind here — an explicit \"skip, I'll do this later\"\n * control exits cleanly and tells them where to link later. `onResolved`\n * (linked, or skipped) hands control back to OcSignIn's post-sign-in\n * navigation.\n */\nexport function LinkPromptStep({\n    method,\n    didOc,\n    authOrigin,\n    onResolved,\n}: {\n    /** The complementary identity to link — the opposite of the sign-in method. */\n    method: 'btc' | 'email';\n    didOc: string;\n    authOrigin: string;\n    /** Called once the user has linked the identity, or skipped. */\n    onResolved: () => void;\n}): React.ReactElement {\n    const what = method === 'btc' ? 'a Bitcoin address' : 'an email';\n    return (\n        <div data-oc-linkprompt={method}>\n            <div style={{ ...panelStyle('success'), marginBottom: 16 }}>\n                <SectionLabel tone=\"success\">§ signed in</SectionLabel>\n                <p style={{ ...bodyStyle, margin: 0 }}>\n                    You chose to also link {what}. Complete it below — or skip for now; it is\n                    entirely optional and changes nothing about the sign-in you just completed.\n                </p>\n            </div>\n            {method === 'btc' ? (\n                <BtcLinkForm\n                    authOrigin={authOrigin}\n                    didOc={didOc}\n                    onDone={onResolved}\n                    onCancel={onResolved}\n                />\n            ) : (\n                <EmailLinkForm authOrigin={authOrigin} onDone={onResolved} onCancel={onResolved} />\n            )}\n            <div\n                data-oc-linkprompt-skip=\"\"\n                style={{ marginTop: 14, paddingTop: 14, borderTop: `1px solid ${V.border}` }}\n            >\n                <button type=\"button\" onClick={onResolved} style={ghostBtnStyle(false)}>\n                    skip — I&apos;ll do this later\n                </button>\n                <p style={{ ...hintStyle, marginTop: 8 }}>\n                    {'> '}Changed your mind? Skipping continues you straight on — your sign-in is\n                    unaffected. You can link {what} anytime later from your identity page,{' '}\n                    me.ochk.io/me/identity.\n                </p>\n            </div>\n        </div>\n    );\n}\n\n/* --- email link form --- */\n\nfunction EmailLinkForm({\n    authOrigin,\n    onDone,\n    onCancel,\n}: {\n    authOrigin: string;\n    onDone: () => void;\n    onCancel: () => void;\n}): React.ReactElement {\n    const [step, setStep] = React.useState<'email' | 'code'>('email');\n    const [email, setEmail] = React.useState('');\n    const [code, setCode] = React.useState('');\n    const [token, setToken] = React.useState('');\n    const [busy, setBusy] = React.useState(false);\n    const [err, setErr] = React.useState<string | null>(null);\n    // Set when the auth host reports the email is linked elsewhere — the\n    // user can confirm a dual-proof transfer (session + verified OTP).\n    const [transfer, setTransfer] = React.useState(false);\n\n    async function start(): Promise<void> {\n        setBusy(true);\n        setErr(null);\n        try {\n            const r = await fetch(`${authOrigin}/api/auth/email-otp/start`, {\n                method: 'POST',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json' },\n                body: JSON.stringify({ email: email.trim().toLowerCase() }),\n            });\n            const j = (await r.json()) as { ok?: boolean; token?: string; reason?: string };\n            if (!r.ok || !j.token) throw new Error(j.reason ?? `http_${r.status}`);\n            setToken(j.token);\n            setStep('code');\n        } catch (e) {\n            setErr(e instanceof Error ? e.message : 'could not send code');\n        } finally {\n            setBusy(false);\n        }\n    }\n\n    async function verify(confirmTransfer: boolean): Promise<void> {\n        setBusy(true);\n        setErr(null);\n        try {\n            const r = await fetch(`${authOrigin}/api/auth/link/email`, {\n                method: 'POST',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json' },\n                body: JSON.stringify({\n                    email: email.trim().toLowerCase(),\n                    code: code.trim(),\n                    token,\n                    ...(confirmTransfer ? { confirm_transfer: true } : {}),\n                }),\n            });\n            const j = (await r.json()) as { ok?: boolean; reason?: string };\n            if (r.status === 409 && j.reason === 'email_linked_elsewhere') {\n                setTransfer(true);\n                setBusy(false);\n                return;\n            }\n            if (handleSudoRequired(j, { purpose: 'link an email' })) return;\n            if (isSudoAccountMismatch(j)) {\n                setErr(SUDO_ACCOUNT_MISMATCH_MESSAGE);\n                setBusy(false);\n                return;\n            }\n            if (!r.ok || !j.ok) throw new Error(j.reason ?? `http_${r.status}`);\n            onDone();\n        } catch (e) {\n            setErr(e instanceof Error ? e.message : 'link failed');\n            setBusy(false);\n        }\n    }\n\n    return (\n        <div style={panelStyle('accent')} data-oc-li-form=\"email\">\n            <SectionLabel>§ link an email</SectionLabel>\n            {step === 'email' ? (\n                <>\n                    <input\n                        type=\"email\"\n                        autoComplete=\"email\"\n                        value={email}\n                        onChange={(e) => setEmail(e.target.value)}\n                        placeholder=\"you@example.com\"\n                        style={inputStyle}\n                    />\n                    {err && <ErrorLine>{err}</ErrorLine>}\n                    <FormButtons>\n                        <button\n                            type=\"button\"\n                            onClick={() => void start()}\n                            disabled={busy || email.trim().length < 5}\n                            style={primaryBtnStyle(busy || email.trim().length < 5)}\n                        >\n                            {busy ? 'sending…' : 'send code'}\n                        </button>\n                        <button type=\"button\" onClick={onCancel} style={ghostBtnStyle(busy)}>\n                            cancel\n                        </button>\n                    </FormButtons>\n                </>\n            ) : transfer ? (\n                <TransferConfirm\n                    what=\"email\"\n                    busy={busy}\n                    onConfirm={() => void verify(true)}\n                    onCancel={onCancel}\n                    err={err}\n                />\n            ) : (\n                <>\n                    <p style={bodyStyle}>Enter the 6-digit code sent to {email}.</p>\n                    <input\n                        type=\"text\"\n                        inputMode=\"numeric\"\n                        autoComplete=\"one-time-code\"\n                        maxLength={6}\n                        value={code}\n                        onChange={(e) => setCode(e.target.value.replace(/\\D/g, '').slice(0, 6))}\n                        placeholder=\"123456\"\n                        style={{ ...inputStyle, letterSpacing: '0.3em' }}\n                    />\n                    {err && <ErrorLine>{err}</ErrorLine>}\n                    <FormButtons>\n                        <button\n                            type=\"button\"\n                            onClick={() => void verify(false)}\n                            disabled={busy || code.length !== 6}\n                            style={primaryBtnStyle(busy || code.length !== 6)}\n                        >\n                            {busy ? 'linking…' : 'verify + link'}\n                        </button>\n                        <button\n                            type=\"button\"\n                            onClick={() => setStep('email')}\n                            disabled={busy}\n                            style={ghostBtnStyle(busy)}\n                        >\n                            back\n                        </button>\n                    </FormButtons>\n                </>\n            )}\n        </div>\n    );\n}\n\n/* --- btc link form --- */\n\nfunction BtcLinkForm({\n    authOrigin,\n    didOc,\n    onDone,\n    onCancel,\n}: {\n    authOrigin: string;\n    didOc: string | null;\n    onDone: () => void;\n    onCancel: () => void;\n}): React.ReactElement {\n    const [step, setStep] = React.useState<'request' | 'sign'>('request');\n    const [addr, setAddr] = React.useState('');\n    const [challenge, setChallenge] = React.useState('');\n    const [busy, setBusy] = React.useState(false);\n    const [err, setErr] = React.useState<string | null>(null);\n    // Holds the signature awaiting transfer confirmation when the\n    // address is already linked to another account.\n    const [pendingSig, setPendingSig] = React.useState<string | null>(null);\n\n    async function getChallenge(): Promise<void> {\n        if (!didOc) {\n            setErr('session not loaded yet · refresh and retry');\n            return;\n        }\n        setBusy(true);\n        setErr(null);\n        try {\n            // /api/challenge is a public primitive — no session needed.\n            // audience MUST be the caller's did_oc: the link endpoint\n            // verifies expectedAudience=session.did_oc, so a signature\n            // obtained here can't be replayed against another account.\n            const r = await fetch(\n                `${authOrigin}/api/challenge?addr=${encodeURIComponent(addr)}` +\n                    `&purpose=link&audience=${encodeURIComponent(didOc)}`\n            );\n            const j = (await r.json()) as { message?: string; reason?: string };\n            if (!r.ok || !j.message) throw new Error(j.reason ?? `http_${r.status}`);\n            setChallenge(j.message);\n            setStep('sign');\n        } catch (e) {\n            setErr(e instanceof Error ? e.message : 'challenge failed');\n        } finally {\n            setBusy(false);\n        }\n    }\n\n    async function postLink(sig: string, confirmTransfer: boolean): Promise<void> {\n        setBusy(true);\n        setErr(null);\n        try {\n            const r = await fetch(`${authOrigin}/api/auth/link/btc`, {\n                method: 'POST',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json' },\n                body: JSON.stringify({\n                    message: challenge,\n                    signature: sig,\n                    ...(confirmTransfer ? { confirm_transfer: true } : {}),\n                }),\n            });\n            const j = (await r.json()) as { ok?: boolean; reason?: string };\n            if (r.status === 409 && j.reason === 'address_linked_elsewhere') {\n                setPendingSig(sig);\n                setBusy(false);\n                return;\n            }\n            if (handleSudoRequired(j, { purpose: 'link a Bitcoin address' })) return;\n            if (isSudoAccountMismatch(j)) {\n                setErr(SUDO_ACCOUNT_MISMATCH_MESSAGE);\n                setBusy(false);\n                return;\n            }\n            if (!r.ok || !j.ok) throw new Error(j.reason ?? `http_${r.status}`);\n            onDone();\n        } catch (e) {\n            setErr(e instanceof Error ? e.message : 'link failed');\n            setBusy(false);\n        }\n    }\n\n    return (\n        <div style={panelStyle('accent')} data-oc-li-form=\"btc\">\n            <SectionLabel>§ link a Bitcoin address</SectionLabel>\n            {step === 'request' ? (\n                <>\n                    <p style={bodyStyle}>\n                        Enter a Bitcoin address you control. We generate a challenge and your\n                        wallet signs it (BIP-322).\n                    </p>\n                    <input\n                        type=\"text\"\n                        value={addr}\n                        onChange={(e) => setAddr(e.target.value.trim())}\n                        placeholder=\"bc1q…\"\n                        autoCapitalize=\"none\"\n                        spellCheck={false}\n                        style={{ ...inputStyle, fontFamily: MONO }}\n                    />\n                    {err && <ErrorLine>{err}</ErrorLine>}\n                    <FormButtons>\n                        <button\n                            type=\"button\"\n                            onClick={() => void getChallenge()}\n                            disabled={busy || addr.length < 14}\n                            style={primaryBtnStyle(busy || addr.length < 14)}\n                        >\n                            {busy ? 'requesting…' : 'get challenge'}\n                        </button>\n                        <button type=\"button\" onClick={onCancel} style={ghostBtnStyle(busy)}>\n                            cancel\n                        </button>\n                    </FormButtons>\n                </>\n            ) : pendingSig ? (\n                <TransferConfirm\n                    what=\"bitcoin address\"\n                    busy={busy}\n                    onConfirm={() => void postLink(pendingSig, true)}\n                    onCancel={onCancel}\n                    err={err}\n                />\n            ) : (\n                <>\n                    <p style={bodyStyle}>\n                        Sign the challenge with the wallet that controls{' '}\n                        <span style={{ fontFamily: MONO, wordBreak: 'break-all' }}>{addr}</span>.\n                    </p>\n                    <LazyWalletButton\n                        address={addr}\n                        message={challenge}\n                        showManual\n                        layout=\"list\"\n                        heading={null}\n                        onSigned={(sig: string) => void postLink(sig, false)}\n                        onError={(e: { message?: string }) =>\n                            setErr(e?.message ?? 'wallet rejected')\n                        }\n                    />\n                    {err && <ErrorLine>{err}</ErrorLine>}\n                    <FormButtons>\n                        <button\n                            type=\"button\"\n                            onClick={() => {\n                                setStep('request');\n                                setErr(null);\n                            }}\n                            disabled={busy}\n                            style={ghostBtnStyle(busy)}\n                        >\n                            back\n                        </button>\n                    </FormButtons>\n                </>\n            )}\n        </div>\n    );\n}\n\n/* --- transfer-under-dual-proof confirm --- */\n\nfunction TransferConfirm({\n    what,\n    busy,\n    onConfirm,\n    onCancel,\n    err,\n}: {\n    what: string;\n    busy: boolean;\n    onConfirm: () => void;\n    onCancel: () => void;\n    err: string | null;\n}): React.ReactElement {\n    return (\n        <>\n            <p style={bodyStyle}>\n                This {what} is already linked to another OrangeCheck account. You&apos;ve just\n                proven control of it — you can transfer the link to this account under dual proof\n                of control. The other account loses this sign-in path; its history stays\n                verifiable. Continue?\n            </p>\n            {err && <ErrorLine>{err}</ErrorLine>}\n            <FormButtons>\n                <button\n                    type=\"button\"\n                    onClick={onConfirm}\n                    disabled={busy}\n                    style={dangerBtnStyle(busy)}\n                >\n                    {busy ? 'transferring…' : 'transfer link here'}\n                </button>\n                <button type=\"button\" onClick={onCancel} disabled={busy} style={ghostBtnStyle(busy)}>\n                    cancel\n                </button>\n            </FormButtons>\n        </>\n    );\n}\n\n/* --- lazy wallet button · wallet-adapter loads on demand, not with the page --- */\n\ninterface WalletButtonProps {\n    address: string;\n    message: string;\n    showManual?: boolean;\n    layout?: string;\n    heading?: React.ReactNode;\n    onSigned: (sig: string) => void;\n    onError: (err: { message?: string }, walletId?: string) => void;\n}\n\nfunction LazyWalletButton(props: WalletButtonProps): React.ReactElement {\n    const [Comp, setComp] = React.useState<React.ComponentType<WalletButtonProps> | null>(null);\n    const [failed, setFailed] = React.useState(false);\n\n    React.useEffect(() => {\n        let alive = true;\n        // A bundler resolves this specifier at build time, so wallet-adapter\n        // is a real dependency; only the chunk is deferred.\n        import('@orangecheck/wallet-adapter/react')\n            .then((m) => {\n                if (alive) {\n                    setComp(\n                        () => (m as { OcWalletButton: React.ComponentType<WalletButtonProps> })\n                            .OcWalletButton\n                    );\n                }\n            })\n            .catch(() => {\n                if (alive) setFailed(true);\n            });\n        return () => {\n            alive = false;\n        };\n    }, []);\n\n    if (failed) {\n        return (\n            <ErrorLine>\n                could not load wallet support · refresh to try again\n            </ErrorLine>\n        );\n    }\n    if (!Comp) return <span style={hintStyle}>{'> '}loading wallet options…</span>;\n    return <Comp {...props} />;\n}\n\n/* --- helpers --- */\n\nfunction mask(value: string, kind: 'email' | 'btc'): string {\n    if (kind === 'email') {\n        const [user, host] = value.split('@');\n        if (!user || !host) return '••••';\n        const m =\n            user.length <= 2\n                ? '•'.repeat(user.length)\n                : user[0] + '•'.repeat(user.length - 2) + user.slice(-1);\n        return `${m}@${host}`;\n    }\n    if (value.length <= 12) return '•'.repeat(value.length);\n    return `${value.slice(0, 6)}…${value.slice(-4)}`;\n}\n\n/* --- presentational atoms --- */\n\nfunction SectionLabel({\n    children,\n    tone = 'primary',\n}: {\n    children: React.ReactNode;\n    tone?: 'primary' | 'success' | 'warn';\n}): React.ReactElement {\n    const color = tone === 'success' ? V.success : tone === 'warn' ? V.warn : V.primary;\n    return (\n        <div\n            style={{\n                color,\n                fontFamily: MONO,\n                fontSize: 10,\n                letterSpacing: '0.18em',\n                textTransform: 'uppercase',\n                marginBottom: 8,\n            }}\n        >\n            {children}\n        </div>\n    );\n}\n\nfunction ErrorLine({ children }: { children: React.ReactNode }): React.ReactElement {\n    return (\n        <p\n            role=\"alert\"\n            style={{\n                margin: '8px 0 0',\n                color: V.destructive,\n                fontFamily: MONO,\n                fontSize: 11,\n            }}\n        >\n            {children}\n        </p>\n    );\n}\n\nfunction FormButtons({ children }: { children: React.ReactNode }): React.ReactElement {\n    return (\n        <div style={{ display: 'flex', flexWrap: 'wrap', gap: 8, marginTop: 12 }}>{children}</div>\n    );\n}\n\n/* --- style tokens (CSS-variable-themed, same approach as OcSignIn) --- */\n\nconst MONO = 'ui-monospace, SFMono-Regular, monospace';\n\nconst V = {\n    primary: 'var(--primary, #f97316)',\n    foreground: 'var(--foreground, #fafafa)',\n    muted: 'var(--muted-foreground, #a1a1aa)',\n    background: 'var(--background, #0a0a0a)',\n    card: 'var(--card, #111113)',\n    border: 'var(--border, #27272a)',\n    destructive: 'var(--destructive, #ef4444)',\n    success: 'var(--success, #22c55e)',\n    warn: 'var(--warning, #eab308)',\n} as const;\n\nfunction panelStyle(tone: 'plain' | 'accent' | 'success' | 'warn' | 'default' = 'default'): React.CSSProperties {\n    const base: React.CSSProperties = {\n        background: V.card,\n        border: `1px solid ${V.border}`,\n        padding: '1.25rem',\n    };\n    if (tone === 'plain') return { ...base, padding: 0 };\n    if (tone === 'accent') return { ...base, borderColor: V.primary, background: 'var(--card, #111113)' };\n    if (tone === 'success') return { ...base, borderColor: V.success };\n    if (tone === 'warn') return { ...base, borderColor: V.warn };\n    return base;\n}\n\nconst bodyStyle: React.CSSProperties = {\n    color: V.muted,\n    fontSize: 13,\n    lineHeight: 1.55,\n    margin: '0 0 12px',\n};\n\nconst hintStyle: React.CSSProperties = {\n    color: V.muted,\n    fontFamily: MONO,\n    fontSize: 10.5,\n    opacity: 0.8,\n};\n\nconst codeStyle: React.CSSProperties = {\n    fontFamily: MONO,\n    color: V.foreground,\n};\n\nconst rowStyle: React.CSSProperties = {\n    display: 'flex',\n    flexWrap: 'wrap',\n    alignItems: 'center',\n    justifyContent: 'space-between',\n    gap: 12,\n    padding: '1rem',\n};\n\nconst rowLabelStyle: React.CSSProperties = {\n    color: V.foreground,\n    fontFamily: MONO,\n    fontSize: 10.5,\n    letterSpacing: '0.12em',\n    textTransform: 'uppercase',\n    opacity: 0.8,\n};\n\nconst inputStyle: React.CSSProperties = {\n    width: '100%',\n    padding: '0.55rem 0.75rem',\n    background: V.background,\n    color: V.foreground,\n    border: `1px solid ${V.border}`,\n    borderRadius: 6,\n    fontFamily: MONO,\n    // 16px — never lower · suppresses iOS Safari focus auto-zoom.\n    fontSize: 16,\n    outline: 'none',\n    boxSizing: 'border-box',\n};\n\nfunction btnBase(disabled: boolean): React.CSSProperties {\n    return {\n        padding: '0.5rem 0.875rem',\n        borderRadius: 6,\n        fontFamily: MONO,\n        fontSize: 10.5,\n        letterSpacing: '0.12em',\n        textTransform: 'uppercase',\n        cursor: disabled ? 'not-allowed' : 'pointer',\n        opacity: disabled ? 0.5 : 1,\n    };\n}\n\nfunction primaryBtnStyle(disabled: boolean): React.CSSProperties {\n    return {\n        ...btnBase(disabled),\n        background: V.primary,\n        color: 'var(--primary-foreground, #0a0a0a)',\n        border: `1px solid ${V.primary}`,\n        fontWeight: 600,\n    };\n}\n\nfunction ghostBtnStyle(disabled: boolean): React.CSSProperties {\n    return {\n        ...btnBase(disabled),\n        background: V.background,\n        color: V.foreground,\n        border: `1px solid ${V.border}`,\n    };\n}\n\nfunction dangerBtnStyle(disabled: boolean): React.CSSProperties {\n    return {\n        ...btnBase(disabled),\n        background: 'transparent',\n        color: V.destructive,\n        border: `1px solid ${V.destructive}`,\n    };\n}\n\nconst primaryChipStyle: React.CSSProperties = {\n    ...btnBase(false),\n    background: 'transparent',\n    color: V.primary,\n    border: `1px solid ${V.primary}`,\n};\n","/**\n * @orangecheck/auth-client · OcSignIn\n *\n * In-place dual-path signin component for every `X.ochk.io` consumer site.\n * Calls the cross-subdomain auth host (`ochk.io`) via family-CORS so the\n * `.ochk.io` session cookie lands without any redirect.\n *\n * Two paths, one component:\n *\n *   1. Bitcoin wallet · BIP-322\n *      - Paste address, in-page wallet extension signs a challenge\n *      - POSTs { message, signature, expectedNonce, expectedAudience,\n *        expectedPurpose } to ochk.io/api/auth/signin\n *      - Identity is `did:oc:<rand>` linked to the BTC address\n *\n *   2. Email · OTP\n *      - Enter email → ochk.io/api/auth/email-otp/start delivers a code\n *      - Enter code → ochk.io/api/auth/email-otp/verify lands the cookie\n *      - Identity is `did:oc:<rand>`. No wallet is created here: a Fedimint\n *        wallet is provisioned client-side on first /me visit, and its sats\n *        are held by the FEDERATION'S GUARDIANS — not by OrangeCheck, which\n *        coordinates and never custodies (see oc-www's email-otp/verify\n *        route). Naming the custodian is family invariant 8; the old wording\n *        here and in the form copy said \"a custodial wallet\" with no subject,\n *        which reads as OC holding it and contradicts the charter.\n *\n * **Both paths resolve to the same did:oc canonical identity** via the\n * auth host's account-linking logic — a user who started with email can\n * later link their BTC address (and vice versa). One identity, two doors,\n * persistent across every family subdomain.\n *\n * On success, the component **hard-navigates** (window.location.assign)\n * rather than calling onSuccess + relying on the consumer to route. This\n * is non-negotiable: OcSessionProvider does not auto-refetch /api/auth/me\n * on client-side route changes, so a soft redirect leaves it with stale\n * `status: 'anonymous'`. Hard nav forces the provider to remount with\n * the fresh cookie. Override via onSuccess if you must.\n */\n\nimport * as React from 'react';\n\nimport { LinkPromptStep } from './linked-identities';\nimport { clearTabSession } from './tab-session';\nimport type { OcAccount } from './types';\n\n/* --- props --- */\n\nexport interface OcSignInProps {\n    /**\n     * Consumer-site audience URL passed as `expectedAudience` on the\n     * BIP-322 challenge. e.g. `'https://vault.ochk.io'`. Required —\n     * the challenge nonce is bound to this audience.\n     */\n    audience: string;\n    /**\n     * Where to navigate after success. Defaults to `'/'`.\n     * Open-redirect-safe: a same-origin path (must start with `/`, NOT\n     * `//`) or an absolute `https://` URL on `ochk.io` / `*.ochk.io` —\n     * the add-another-account flow starts on a consumer subdomain and\n     * must round-trip back to it, including through the OAuth provider\n     * hop. Anything else is ignored. When omitted, the component reads\n     * `?return_to=` (or `?next=`) from the page URL — so the auth\n     * host's `/signin?add=1&return_to=…` entry point Just Works, the\n     * same way the `add` prop auto-detects `?add=1`.\n     */\n    returnTo?: string;\n    /**\n     * Override the default hard-navigation behavior. When provided,\n     * called with the account and the session JWT. The component will\n     * NOT navigate — the caller is responsible. Use for custom\n     * post-signin routing — e.g. /popup/signin postMessages\n     * `{ account, token }` to its opener so a cross-domain integrator\n     * (different eTLD+1 from .ochk.io, which the HttpOnly cookie can't\n     * reach) can verify the session via JWKS.\n     */\n    onSuccess?: (account: OcAccount, token?: string) => void;\n    /**\n     * Async post-success routing. When provided (and `onSuccess` is\n     * not), the component awaits `resolveReturnTo(account)` and\n     * hard-navigates to the result instead of the static `returnTo`.\n     *\n     * This is the seam that lets a site keep persona-aware routing\n     * without forking the ceremony — e.g. me.ochk.io resolves\n     * `/api/me/intent` and routes to `/me/developer` | `/me/operator`\n     * | `/me`. The returned value is open-redirect-checked exactly\n     * like `returnTo` (same-origin paths only); on a resolver throw\n     * the component falls back to the static `returnTo`.\n     */\n    resolveReturnTo?: (account: OcAccount) => string | Promise<string>;\n    /**\n     * Override the auth host. Defaults to `'https://ochk.io'`. For\n     * preview / dev / staging only.\n     */\n    authOrigin?: string;\n    /**\n     * Initial visible tab. Defaults to `'email'` (since {@link providersFirst}\n     * is on by default); resolves to `'wallet'` only when\n     * `providersFirst={false}` and this is left unspecified.\n     */\n    initialPath?: 'wallet' | 'email';\n    /**\n     * Re-order the ceremony so the third-party providers (Google / GitHub)\n     * render **above** the wallet + email panel, and the email path is the\n     * default active tab. **On by default — the family standard.** A\n     * first-time, non-Bitcoiner visitor sees the most familiar on-ramp\n     * (Google / GitHub / email one-time code) first; the BIP-322 wallet path\n     * stays one tab away, reframed as the most-sovereign option.\n     *\n     * Pass `providersFirst={false}` for the legacy bitcoin-first ordering.\n     * Honors family rule #3 — email / OAuth is the easy bridge, the Bitcoin\n     * address remains the canonical identity it resolves to.\n     */\n    providersFirst?: boolean;\n    /**\n     * Disable one of the two paths. Default is both enabled.\n     * Useful for B2B-only sites that don't want to expose email-OTP.\n     */\n    paths?: { wallet?: boolean; email?: boolean };\n    /**\n     * Whether to show the \"also link my other identity\" checkbox on the\n     * sign-in form. **On by default.** The checkbox is optional and\n     * unchecked by default; it is shown on both the wallet and email\n     * paths. If the user ticks it, the complementary identity's link\n     * ceremony (BIP-322 for a wallet, OTP for an email) runs inline\n     * immediately after a successful sign-in — before `onSuccess` /\n     * `returnTo`, so it composes with custom routing — because the\n     * sign-in just proved one credential and the link ceremony proves\n     * the second. Pass `linkPrompt={false}` to omit the checkbox.\n     */\n    linkPrompt?: boolean;\n    /**\n     * Multi-account · when `true`, the sign-in is performed in \"add\"\n     * mode: the resulting session is appended to the browser's existing\n     * roster instead of replacing it. The previously-active account\n     * stays signed in and remains a switch target on the auth host. Off\n     * by default (back-compat). The component also reads `?add=1` from\n     * the URL search params and treats it the same — so the auth host's\n     * `/signin?add=1` entry point Just Works without any extra prop.\n     *\n     * The `add` flag is forwarded as a body field to the host's\n     * `/api/auth/signin` and `/api/auth/email-otp/verify`; if the host\n     * hasn't deployed the multi-account migration yet it silently\n     * ignores the field and the call falls back to ordinary signin.\n     */\n    add?: boolean;\n    /** className for the outer container. */\n    className?: string;\n}\n\n/* --- shared types --- */\n\ninterface SigninJsonOk {\n    ok: true;\n    account: OcAccount;\n    /**\n     * The session JWT, echoed alongside the `Set-Cookie`. Cross-domain\n     * integrators capture this to verify the session via JWKS — the\n     * HttpOnly `.ochk.io` cookie never reaches their origin. Family\n     * `.ochk.io` sites ignore it and rely on the cookie.\n     */\n    token?: string;\n}\n\ninterface SigninJsonErr {\n    ok?: false;\n    reason?: string;\n    error?: string;\n    issues?: unknown;\n}\n\ntype SigninJson = SigninJsonOk | SigninJsonErr;\n\n/* --- helpers --- */\n\n/**\n * A relative path is same-origin only if it RESOLVES to this origin.\n *\n * Prefix checks are not enough. `startsWith('/') && !startsWith('//')` accepts\n * `/\\evil.example`, and the WHATWG URL parser treats a backslash as a slash in\n * special schemes, so the browser resolves it to `https://evil.example/`:\n *\n *     new URL('/\\evil.example', 'https://attest.ochk.io').href\n *       -> 'https://evil.example/'\n *\n * Since hardNavigate() below hands its argument to window.location.assign,\n * that was a post-authentication open redirect on every consumer of this\n * package — the user completes a real sign-in on a real ochk.io domain and\n * lands on an attacker's page. `\\t`, `\\n` and `\\r` are stripped by the parser\n * too, so `/\\t/evil.example` is the same trick with different bytes.\n *\n * So instead of blacklisting characters, resolve and compare: whatever the URL\n * parser makes of the input is what the browser will navigate to, and that is\n * the thing that has to be same-origin.\n */\nfunction isSameOriginPath(candidate: string, origin: string): boolean {\n    try {\n        return new URL(candidate, origin).origin === origin;\n    } catch {\n        return false;\n    }\n}\n\n/** Origin to resolve relative candidates against. Any absolute https origin\n *  works for the comparison; on the server there is no window to read. */\nfunction resolutionOrigin(): string {\n    return typeof window === 'undefined' ? 'https://ochk.io' : window.location.origin;\n}\n\nexport function safeReturnTo(input: string | undefined): string {\n    const candidate = input ?? '/';\n    if (typeof candidate !== 'string') return '/';\n    if (!candidate.startsWith('/')) return '/';\n    return isSameOriginPath(candidate, resolutionOrigin()) ? candidate : '/';\n}\n\n/**\n * Family-aware return target. Accepts a same-origin relative path\n * (exactly like {@link safeReturnTo}) OR an absolute `https://` URL on\n * `ochk.io` / `*.ochk.io` — mirroring the auth host's own post-signin\n * redirect allowlist. Returns `undefined` when the input is neither, so\n * callers can layer fallbacks.\n */\nexport function familyReturnTarget(input: string | undefined | null): string | undefined {\n    if (typeof input !== 'string' || input.length === 0) return undefined;\n    // Same-origin relative path — resolved, not prefix-matched. See\n    // isSameOriginPath for why `/\\evil.example` defeated the old check.\n    if (input.startsWith('/') && isSameOriginPath(input, resolutionOrigin())) {\n        return input;\n    }\n    try {\n        const u = new URL(input);\n        if (u.protocol !== 'https:') return undefined;\n        const host = u.hostname.toLowerCase();\n        if (host === 'ochk.io' || host.endsWith('.ochk.io')) return u.toString();\n    } catch {\n        // not an absolute URL either\n    }\n    return undefined;\n}\n\nfunction hardNavigate(target: string): void {\n    if (typeof window === 'undefined') return;\n    window.location.assign(target);\n}\n\n/* --- main component --- */\n\nexport function OcSignIn({\n    audience,\n    returnTo,\n    onSuccess,\n    resolveReturnTo,\n    linkPrompt = true,\n    add: addProp,\n    authOrigin = 'https://ochk.io',\n    initialPath,\n    providersFirst = true,\n    paths,\n    className,\n}: OcSignInProps): React.ReactElement {\n    const walletEnabled = paths?.wallet ?? true;\n    const emailEnabled = paths?.email ?? true;\n\n    // Return target · prop wins; otherwise honor `?return_to=` / `?next=`\n    // from the URL — the auth host's `/signin?add=1&return_to=…` entry\n    // point needs the OAuth provider hop to carry the same target the\n    // embedding page honors (the add-another-account fix: a vault user\n    // adding an account via Google must land back on vault, not on the\n    // host's homepage). Absolute https://*.ochk.io URLs are allowed;\n    // everything else clamps to `/`.\n    const [resolvedReturn, setResolvedReturn] = React.useState<string>(\n        () => familyReturnTarget(returnTo) ?? safeReturnTo(returnTo)\n    );\n    React.useEffect(() => {\n        const fromProp = familyReturnTarget(returnTo);\n        if (fromProp) {\n            setResolvedReturn(fromProp);\n            return;\n        }\n        if (typeof window === 'undefined') return;\n        const q = new URLSearchParams(window.location.search);\n        const fromQuery =\n            familyReturnTarget(q.get('return_to')) ?? familyReturnTarget(q.get('next'));\n        setResolvedReturn(fromQuery ?? '/');\n    }, [returnTo]);\n\n    // Multi-account · prop wins; otherwise honor `?add=1` from the URL\n    // so the auth host's /signin?add=1 entry point doesn't need any\n    // extra wiring on every consumer's sign-in page.\n    const [addMode, setAddMode] = React.useState<boolean>(Boolean(addProp));\n    React.useEffect(() => {\n        if (typeof window === 'undefined') return;\n        if (addProp !== undefined) {\n            setAddMode(Boolean(addProp));\n            return;\n        }\n        setAddMode(new URLSearchParams(window.location.search).get('add') === '1');\n    }, [addProp]);\n\n    // When providers lead the ceremony (ochk.io homepage), the email path\n    // is the friendlier default tab; otherwise the canonical bitcoin-first\n    // default holds. An explicit `initialPath` always wins.\n    const [path, setPath] = React.useState<'wallet' | 'email'>(\n        initialPath ?? (providersFirst ? 'email' : 'wallet')\n    );\n    // Set once sign-in succeeds and the account is missing its\n    // complementary identity — the component then renders the focused\n    // link step (LinkPromptStep) before running `proceed`.\n    const [signedIn, setSignedIn] = React.useState<{\n        method: 'btc' | 'email';\n        didOc: string;\n        proceed: () => void;\n    } | null>(null);\n    // The optional \"also link my other identity\" checkbox on the form.\n    const [linkAlso, setLinkAlso] = React.useState(false);\n    // Set when the user is bounced back here after a failed provider\n    // (e.g. Google) sign-in — the auth host redirects to\n    // `/signin?oauth_error=…`.\n    const [oauthError, setOauthError] = React.useState(false);\n    React.useEffect(() => {\n        if (typeof window === 'undefined') return;\n        if (new URLSearchParams(window.location.search).has('oauth_error')) {\n            setOauthError(true);\n        }\n    }, []);\n\n    const navigate = React.useCallback(\n        async (account: OcAccount) => {\n            if (resolveReturnTo) {\n                try {\n                    const resolved = familyReturnTarget(await resolveReturnTo(account));\n                    hardNavigate(resolved ?? resolvedReturn);\n                    return;\n                } catch {\n                    // resolver failed — fall through to the static returnTo\n                }\n            }\n            hardNavigate(resolvedReturn);\n        },\n        [resolveReturnTo, resolvedReturn]\n    );\n\n    const handleSuccess = React.useCallback(\n        async (account: OcAccount, token: string | undefined, via: 'wallet' | 'email') => {\n            // The post-sign-in handoff — custom `onSuccess`, else navigation.\n            const proceed = () => {\n                // Per-tab · the user just completed a ceremony IN this tab —\n                // it must adopt the new identity, not keep a stale pin.\n                clearTabSession();\n                if (onSuccess) onSuccess(account, token);\n                else void navigate(account);\n            };\n\n            // Linking is opt-in via the form checkbox. Unchecked (or the\n            // checkbox suppressed) → ordinary sign-in.\n            if (!linkPrompt || !linkAlso) {\n                proceed();\n                return;\n            }\n\n            // Checked: run the complementary identity's link ceremony now.\n            // /api/auth/me resolves the did:oc the BIP-322 link challenge is\n            // bound to; a failure here must not strand the signed-in user.\n            try {\n                const meRes = await fetch(`${authOrigin}/api/auth/me`, {\n                    credentials: 'include',\n                    headers: { Accept: 'application/json' },\n                });\n                const me = meRes.ok\n                    ? ((await meRes.json()) as { account?: { did_oc?: string } })\n                    : null;\n                const didOc = me?.account?.did_oc;\n                if (didOc) {\n                    setSignedIn({\n                        method: via === 'email' ? 'btc' : 'email',\n                        didOc,\n                        proceed,\n                    });\n                    return;\n                }\n            } catch {\n                // /api/auth/me unreachable — proceed without the link step.\n            }\n            proceed();\n        },\n        [onSuccess, linkPrompt, linkAlso, navigate, authOrigin]\n    );\n\n    if (!walletEnabled && !emailEnabled) {\n        return (\n            <div\n                className={className}\n                data-oc-signin=\"\"\n                style={{\n                    padding: '1rem',\n                    border: '1px solid var(--border, #27272a)',\n                    color: 'var(--foreground, #fafafa)',\n                    fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                    fontSize: 12,\n                }}\n            >\n                no signin paths enabled — set <code>paths.wallet</code> or{' '}\n                <code>paths.email</code> to <code>true</code>\n            </div>\n        );\n    }\n\n    if (signedIn) {\n        return (\n            <div className={className} data-oc-signin=\"\">\n                <LinkPromptStep\n                    method={signedIn.method}\n                    didOc={signedIn.didOc}\n                    authOrigin={authOrigin}\n                    onResolved={signedIn.proceed}\n                />\n            </div>\n        );\n    }\n\n    const showWallet = walletEnabled && (path === 'wallet' || !emailEnabled);\n    const showEmail = emailEnabled && (path === 'email' || !walletEnabled);\n    const bothEnabled = walletEnabled && emailEnabled;\n    // The method the user will actually sign in with — the active tab,\n    // clamped when only one path is enabled. Drives the checkbox wording.\n    const activeMethod: 'wallet' | 'email' = !emailEnabled\n        ? 'wallet'\n        : !walletEnabled\n          ? 'email'\n          : path;\n\n    return (\n        <div className={className} data-oc-signin=\"\">\n            {oauthError && (\n                <div\n                    data-oc-signin-oauth-error=\"\"\n                    style={{\n                        marginBottom: 14,\n                        padding: '0.6rem 0.75rem',\n                        border: '1px solid var(--destructive, #ef4444)',\n                        borderRadius: 6,\n                        color: 'var(--destructive, #ef4444)',\n                        fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                        fontSize: 11,\n                    }}\n                >\n                    That sign-in didn&apos;t complete. Please try again.\n                </div>\n            )}\n            {addMode && (\n                <div\n                    data-oc-signin-add-mode=\"\"\n                    style={{\n                        marginBottom: 14,\n                        padding: '0.6rem 0.75rem',\n                        border: '1px solid var(--primary, #f97316)',\n                        borderLeftWidth: 3,\n                        borderRadius: 4,\n                        background: 'color-mix(in srgb, var(--primary, #f97316) 8%, transparent)',\n                        color: 'var(--foreground, #fafafa)',\n                        fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                        fontSize: 11,\n                        lineHeight: 1.6,\n                    }}\n                >\n                    <strong\n                        style={{\n                            color: 'var(--primary, #f97316)',\n                            letterSpacing: '0.12em',\n                            textTransform: 'uppercase',\n                            fontSize: 10,\n                            display: 'block',\n                            marginBottom: 3,\n                        }}\n                    >\n                        § adding another account\n                    </strong>\n                    Your current OrangeCheck account stays signed in. The new account joins your\n                    browser&apos;s roster; you can switch between them anytime from the account\n                    menu.\n                </div>\n            )}\n            {/* Providers-first (ochk.io homepage): the familiar Google /\n                GitHub on-ramp leads, with the wallet/email panel below the\n                divider. Everywhere else this block stays at the bottom. */}\n            {providersFirst && (\n                <ProviderSignIn\n                    authOrigin={authOrigin}\n                    returnTo={resolvedReturn}\n                    add={addMode}\n                    first\n                />\n            )}\n            {bothEnabled && (\n                <div\n                    role=\"tablist\"\n                    aria-label=\"signin method\"\n                    data-oc-signin-tabs=\"\"\n                    style={{\n                        display: 'flex',\n                        gap: 8,\n                        marginBottom: 16,\n                        borderBottom: '1px solid var(--border, #27272a)',\n                    }}\n                >\n                    {/* When providers lead, the easy email path reads first\n                        and the wallet path sits beside it as the upgrade. */}\n                    {providersFirst ? (\n                        <>\n                            <SigninTab\n                                active={path === 'email'}\n                                onClick={() => setPath('email')}\n                            >\n                                email + otp\n                            </SigninTab>\n                            <SigninTab\n                                active={path === 'wallet'}\n                                onClick={() => setPath('wallet')}\n                            >\n                                bitcoin · self-custody\n                            </SigninTab>\n                        </>\n                    ) : (\n                        <>\n                            <SigninTab\n                                active={path === 'wallet'}\n                                onClick={() => setPath('wallet')}\n                            >\n                                bitcoin wallet\n                            </SigninTab>\n                            <SigninTab\n                                active={path === 'email'}\n                                onClick={() => setPath('email')}\n                            >\n                                email + otp\n                            </SigninTab>\n                        </>\n                    )}\n                </div>\n            )}\n\n            <div data-oc-signin-panel=\"\" role=\"tabpanel\">\n                {showWallet && (\n                    <WalletFlow\n                        authOrigin={authOrigin}\n                        audience={audience}\n                        add={addMode}\n                        onSuccess={(a, t) => void handleSuccess(a, t, 'wallet')}\n                    />\n                )}\n                {showEmail && (\n                    <EmailFlow\n                        authOrigin={authOrigin}\n                        add={addMode}\n                        onSuccess={(a, t) => void handleSuccess(a, t, 'email')}\n                    />\n                )}\n            </div>\n\n            {!providersFirst && (\n                <ProviderSignIn authOrigin={authOrigin} returnTo={resolvedReturn} add={addMode} />\n            )}\n\n            {linkPrompt && (\n                <label data-oc-signin-linkalso=\"\" style={linkAlsoStyle}>\n                    <input\n                        type=\"checkbox\"\n                        checked={linkAlso}\n                        onChange={(e) => setLinkAlso(e.target.checked)}\n                        style={{ marginTop: 2, accentColor: 'var(--primary, #f97316)' }}\n                    />\n                    <span>\n                        After signing in, also link{' '}\n                        {activeMethod === 'email' ? 'a Bitcoin wallet' : 'an email'}{' '}\n                        <span style={{ opacity: 0.65 }}>— optional, one more signature.</span>\n                    </span>\n                </label>\n            )}\n        </div>\n    );\n}\n\n/* --- tab --- */\n\nfunction SigninTab({\n    active,\n    onClick,\n    children,\n}: {\n    active: boolean;\n    onClick: () => void;\n    children: React.ReactNode;\n}): React.ReactElement {\n    return (\n        <button\n            type=\"button\"\n            role=\"tab\"\n            aria-selected={active}\n            onClick={onClick}\n            data-oc-signin-tab={active ? 'active' : 'inactive'}\n            style={{\n                padding: '0.6rem 0.875rem',\n                background: 'transparent',\n                border: 'none',\n                borderBottom: active\n                    ? '2px solid var(--primary, #f97316)'\n                    : '2px solid transparent',\n                color: active\n                    ? 'var(--foreground, #fafafa)'\n                    : 'var(--muted-foreground, #a1a1aa)',\n                fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                fontSize: 11,\n                letterSpacing: '0.12em',\n                textTransform: 'uppercase',\n                cursor: 'pointer',\n                marginBottom: -1,\n            }}\n        >\n            {children}\n        </button>\n    );\n}\n\n/* --- third-party provider sign-in --- */\n\ninterface OAuthProviderEntry {\n    id: string;\n    label: string;\n}\n\n/**\n * Brand glyph for a known OAuth provider — rendered inside the\n * provider button so each entry is visually recognisable, but drawn\n * in `currentColor` so it picks up the OC muted-foreground theme\n * (the family palette wins over each vendor's brand colours by\n * design). Unknown providers fall through to no icon — the button\n * still renders, just text-only, so the registry is forward-compatible.\n */\nfunction ProviderIcon({ id }: { id: string }): React.ReactElement | null {\n    const common = {\n        width: 14,\n        height: 14,\n        viewBox: '0 0 24 24',\n        fill: 'currentColor',\n        'aria-hidden': true,\n        style: { flex: '0 0 auto' } as React.CSSProperties,\n    } as const;\n    if (id === 'google') {\n        return (\n            <svg {...common}>\n                <path d=\"M12.48 10.92v3.28h7.84c-.24 1.84-.853 3.187-1.787 4.133-1.147 1.147-2.933 2.4-6.053 2.4-4.827 0-8.6-3.893-8.6-8.72s3.773-8.72 8.6-8.72c2.6 0 4.507 1.027 5.907 2.347l2.307-2.307C18.747 1.44 16.133 0 12.48 0 5.867 0 .307 5.387.307 12s5.56 12 12.173 12c3.573 0 6.267-1.173 8.373-3.36 2.16-2.16 2.84-5.213 2.84-7.667 0-.76-.053-1.467-.173-2.053H12.48z\" />\n            </svg>\n        );\n    }\n    if (id === 'github') {\n        return (\n            <svg {...common}>\n                <path d=\"M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12\" />\n            </svg>\n        );\n    }\n    return null;\n}\n\n/**\n * The secondary sign-in block — rendered below BIP-322 and email-OTP,\n * visibly less prominent. Each button is a plain navigation to the\n * auth host, which runs the OAuth dance and mints the family\n * `.ochk.io` session.\n *\n * The provider list is fetched from the auth host's\n * `/api/auth/providers` — a button appears only once that provider's\n * credentials are configured host-side. So enabling GitHub / Apple\n * later is a host env change, not a redeploy of every consumer site.\n * With no providers configured the whole block renders nothing.\n */\nfunction ProviderSignIn({\n    authOrigin,\n    returnTo,\n    add,\n    first = false,\n}: {\n    authOrigin: string;\n    returnTo: string;\n    add: boolean;\n    /**\n     * Render this block at the TOP of the ceremony (above the wallet/email\n     * panel) rather than the default bottom. The \"or\" divider then sits\n     * below the provider buttons, and the block reserves space beneath\n     * itself instead of above. Set by {@link OcSignIn} when\n     * `providersFirst` is on.\n     */\n    first?: boolean;\n}): React.ReactElement | null {\n    const [providers, setProviders] = React.useState<OAuthProviderEntry[]>([]);\n    // A provider sign-in redirects THROUGH the auth host, so its final\n    // redirect must carry an ABSOLUTE return target — a bare path would\n    // resolve against ochk.io and strand a subdomain user there. The\n    // origin is only knowable client-side.\n    const [origin, setOrigin] = React.useState('');\n\n    React.useEffect(() => {\n        setOrigin(window.location.origin);\n        let cancelled = false;\n        fetch(`${authOrigin}/api/auth/providers`, { credentials: 'include' })\n            .then((r) => (r.ok ? (r.json() as Promise<{ providers?: OAuthProviderEntry[] }>) : null))\n            .then((body) => {\n                if (!cancelled && body?.providers) setProviders(body.providers);\n            })\n            .catch(() => {\n                // auth host unreachable — no provider buttons; the\n                // BIP-322 / email-OTP paths are unaffected.\n            });\n        return () => {\n            cancelled = true;\n        };\n    }, [authOrigin]);\n\n    if (providers.length === 0) return null;\n\n    // An absolute family URL (the add-another-account round trip back to\n    // a consumer subdomain) is carried verbatim through the OAuth hop;\n    // a relative path is anchored to THIS page's origin.\n    const providerReturnTo = returnTo.startsWith('/')\n        ? origin\n            ? `${origin}${returnTo}`\n            : returnTo\n        : returnTo;\n    const line = { flex: 1, height: 1, background: 'var(--border, #27272a)' } as const;\n    // Vertical rhythm. The \"or\" divider is a horizontal rule between two\n    // blocks, so it must sit EQUIDISTANT from both — otherwise it reads as\n    // belonging to whichever block it is closer to. It previously ran\n    // 14px above / 4px below (plus 4px of container margin), which glued the\n    // rule to the panel beneath it and left the provider buttons floating.\n    // BLOCK_GAP matches the tab row's own 16px marginBottom so the whole\n    // ceremony sits on one 4px-scale rhythm rather than an ad-hoc\n    // 0/4/8/14/16/20 mix.\n    const BLOCK_GAP = 16;\n    const BUTTON_GAP = 8; // siblings group tighter than blocks separate\n    const divider = (\n        <div\n            style={{\n                display: 'flex',\n                alignItems: 'center',\n                gap: 10,\n                // Symmetric in both orderings: in `first` mode the divider\n                // owns the gap on both sides; at the bottom the container's\n                // marginTop owns the gap above, so the divider only pads below.\n                margin: first ? `${BLOCK_GAP}px 0` : `0 0 ${BLOCK_GAP}px`,\n                color: 'var(--muted-foreground, #a1a1aa)',\n                fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                fontSize: 10,\n                letterSpacing: '0.16em',\n                textTransform: 'uppercase',\n            }}\n        >\n            <span style={line} />\n            or\n            <span style={line} />\n        </div>\n    );\n    const buttons = providers.map((p, i) => (\n        <a\n            key={p.id}\n            href={`${authOrigin}/api/auth/${p.id}/start?return_to=${encodeURIComponent(\n                providerReturnTo\n            )}${add ? '&add=1' : ''}`}\n            data-oc-signin-provider={p.id}\n            style={{\n                display: 'flex',\n                alignItems: 'center',\n                justifyContent: 'center',\n                gap: 10,\n                boxSizing: 'border-box',\n                width: '100%',\n                marginTop: i === 0 ? 0 : BUTTON_GAP,\n                padding: '0.6rem 0.875rem',\n                border: '1px solid var(--border, #27272a)',\n                borderRadius: 6,\n                background: 'transparent',\n                color: 'var(--muted-foreground, #a1a1aa)',\n                fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                fontSize: 12,\n                textDecoration: 'none',\n            }}\n        >\n            <ProviderIcon id={p.id} />\n            <span>{p.label}</span>\n        </a>\n    ));\n    // first → providers lead: buttons, then the \"or\" divider before the\n    // wallet/email panel below. Otherwise the canonical bottom placement:\n    // divider, then buttons.\n    return (\n        <div\n            data-oc-signin-providers=\"\"\n            style={first ? { marginBottom: 0 } : { marginTop: BLOCK_GAP }}\n        >\n            {first ? (\n                <>\n                    {buttons}\n                    {divider}\n                </>\n            ) : (\n                <>\n                    {divider}\n                    {buttons}\n                </>\n            )}\n        </div>\n    );\n}\n\n/* --- wallet flow --- */\n\ninterface FlowProps {\n    authOrigin: string;\n    /** Multi-account add-mode · see OcSignIn.add. */\n    add?: boolean;\n    onSuccess: (account: OcAccount, token?: string) => void;\n}\n\ninterface WalletFlowProps extends FlowProps {\n    audience: string;\n}\n\nfunction WalletFlow({ authOrigin, audience, add, onSuccess }: WalletFlowProps): React.ReactElement {\n    const [address, setAddress] = React.useState('');\n    const [error, setError] = React.useState<string | null>(null);\n    const [submitting, setSubmitting] = React.useState(false);\n    const [stage, setStage] = React.useState<'enter' | 'signing'>('enter');\n\n    async function signIn(e: React.FormEvent): Promise<void> {\n        e.preventDefault();\n        const addr = address.trim();\n        if (!addr) {\n            setError('paste a Bitcoin address');\n            return;\n        }\n        setError(null);\n        setSubmitting(true);\n        setStage('signing');\n        try {\n            // 1. Fetch a challenge bound to (address, audience, purpose=login).\n            const challengeRes = await fetch(\n                `${authOrigin}/api/challenge?addr=${encodeURIComponent(addr)}&audience=${encodeURIComponent(audience)}&purpose=login`\n            );\n            const challenge = (await challengeRes.json()) as {\n                message?: string;\n                nonce?: string;\n                error?: string;\n            };\n            if (!challengeRes.ok || !challenge.message || !challenge.nonce) {\n                throw new Error(challenge.error ?? 'challenge_failed');\n            }\n\n            // 2. Sign the challenge via @orangecheck/wallet-adapter (loaded\n            //    on demand so it stays out of the initial bundle).\n            type AdapterShape = {\n                detectWallets: () => Array<{ id: string; detected: boolean }>;\n                getSigner: (\n                    id: string,\n                    opts: { address: string }\n                ) => (message: string) => Promise<string>;\n            };\n            let adapter: AdapterShape;\n            try {\n                // A dependency, not an optional peer: this is a *static*\n                // dynamic import, so the consumer's bundler must resolve it at\n                // build time and a missing package fails the build. The old\n                // `Function('m','return import(m)')` trick produced a runtime\n                // bare-specifier `import()` the browser cannot resolve without\n                // an import map — which is what broke sign-in everywhere.\n                adapter = (await import(\n                    '@orangecheck/wallet-adapter'\n                )) as unknown as AdapterShape;\n            } catch {\n                throw new Error(\n                    'could not load wallet support · refresh to try again'\n                );\n            }\n            const wallets = adapter\n                .detectWallets()\n                .filter((w) => w.detected && w.id !== 'manual');\n            if (wallets.length === 0) {\n                throw new Error('no BIP-322 wallet extension detected · install one and refresh');\n            }\n            const wallet = wallets[0]!;\n            const signer = adapter.getSigner(wallet.id, { address: addr });\n            const signature = await signer(challenge.message);\n\n            // 3. POST { message, signature, … } to ochk.io/api/auth/signin.\n            //    Family-CORS lets the .ochk.io session cookie land cross-origin.\n            const res = await fetch(`${authOrigin}/api/auth/signin`, {\n                method: 'POST',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json' },\n                body: JSON.stringify({\n                    message: challenge.message,\n                    signature,\n                    scheme: 'bip322',\n                    expectedNonce: challenge.nonce,\n                    expectedAudience: audience,\n                    expectedPurpose: 'login',\n                    // Multi-account add-mode · the auth host preserves\n                    // the current roster_id when set, instead of minting\n                    // a fresh one. Hosts that haven't deployed the\n                    // multi-account migration silently ignore the field.\n                    ...(add ? { add: true } : {}),\n                }),\n            });\n            const json = (await res.json()) as SigninJson;\n            if (!res.ok || !('ok' in json) || !json.ok || !json.account) {\n                throw new Error(\n                    ('reason' in json && json.reason) ||\n                        ('error' in json && json.error) ||\n                        `verify_failed_${res.status}`\n                );\n            }\n            onSuccess(json.account, json.token);\n        } catch (err) {\n            const msg = err instanceof Error ? err.message : 'sign-in failed';\n            setError(msg);\n            setSubmitting(false);\n            setStage('enter');\n        }\n    }\n\n    return (\n        <form onSubmit={signIn} data-oc-signin-wallet=\"\">\n            <FlowHeader label=\"§ bitcoin wallet\">\n                Sign in with any BIP-322-capable Bitcoin wallet (Sparrow, Xverse, Leather, UniSat,\n                Alby, OKX, Phantom). Paste your address, click sign — your wallet extension prompts\n                for a one-time signature on a short challenge. The address becomes your OC\n                identity. Private key material never leaves your wallet.\n            </FlowHeader>\n            <Label>bitcoin address</Label>\n            <input\n                type=\"text\"\n                value={address}\n                onChange={(e) => {\n                    setAddress(e.target.value);\n                    if (error) setError(null);\n                }}\n                placeholder=\"bc1q… · 3… · 1…\"\n                autoComplete=\"off\"\n                autoCapitalize=\"none\"\n                spellCheck={false}\n                required\n                aria-invalid={error ? true : undefined}\n                style={inputStyle}\n            />\n            {error && <ErrorLine>{error}</ErrorLine>}\n            <button\n                type=\"submit\"\n                disabled={submitting || !address.trim()}\n                style={submitStyle(submitting || !address.trim())}\n            >\n                {stage === 'signing' && submitting\n                    ? 'waiting for wallet…'\n                    : 'sign challenge · sign me in →'}\n            </button>\n            <Hint>\n                Detection picks the first installed BIP-322-capable extension. Address is the one\n                your wallet will sign for.\n            </Hint>\n        </form>\n    );\n}\n\n/* --- email flow --- */\n\ntype EmailStage = 'enter' | 'code';\n\nfunction EmailFlow({ authOrigin, add, onSuccess }: FlowProps): React.ReactElement {\n    const [stage, setStage] = React.useState<EmailStage>('enter');\n    const [email, setEmail] = React.useState('');\n    const [emailError, setEmailError] = React.useState<string | null>(null);\n    const [code, setCode] = React.useState('');\n    const [codeError, setCodeError] = React.useState<string | null>(null);\n    const [token, setToken] = React.useState<string | null>(null);\n    const [submitting, setSubmitting] = React.useState(false);\n\n    async function start(e: React.FormEvent): Promise<void> {\n        e.preventDefault();\n        const trimmed = email.trim().toLowerCase();\n        if (!trimmed || !/.+@.+\\..+/.test(trimmed)) {\n            setEmailError('enter a valid email');\n            return;\n        }\n        setEmailError(null);\n        setSubmitting(true);\n        try {\n            const res = await fetch(`${authOrigin}/api/auth/email-otp/start`, {\n                method: 'POST',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json' },\n                body: JSON.stringify({ email: trimmed }),\n            });\n            const json = (await res.json()) as { ok?: boolean; token?: string; reason?: string };\n            if (!res.ok || !json.token) {\n                throw new Error(json.reason ?? `start failed (${res.status})`);\n            }\n            setToken(json.token);\n            setEmail(trimmed);\n            setStage('code');\n        } catch (err) {\n            setEmailError(err instanceof Error ? err.message : 'failed to send code');\n        } finally {\n            setSubmitting(false);\n        }\n    }\n\n    async function verify(e: React.FormEvent): Promise<void> {\n        e.preventDefault();\n        if (!token) return;\n        if (code.length !== 6) {\n            setCodeError('6 digits');\n            return;\n        }\n        setCodeError(null);\n        setSubmitting(true);\n        try {\n            const res = await fetch(`${authOrigin}/api/auth/email-otp/verify`, {\n                method: 'POST',\n                credentials: 'include',\n                headers: { 'Content-Type': 'application/json' },\n                body: JSON.stringify({\n                    email,\n                    code,\n                    token,\n                    // Multi-account add-mode · see WalletFlow.\n                    ...(add ? { add: true } : {}),\n                }),\n            });\n            const json = (await res.json()) as SigninJson;\n            if (!res.ok || !('ok' in json) || !json.ok || !json.account) {\n                throw new Error(\n                    ('reason' in json && json.reason) ||\n                        ('error' in json && json.error) ||\n                        `verify failed (${res.status})`\n                );\n            }\n            onSuccess(json.account, json.token);\n        } catch (err) {\n            setCodeError(err instanceof Error ? err.message : 'verify failed');\n        } finally {\n            setSubmitting(false);\n        }\n    }\n\n    if (stage === 'enter') {\n        return (\n            <form onSubmit={start} data-oc-signin-email=\"\">\n                <FlowHeader label=\"§ email + otp\">\n                    We email you a 6-digit code. No password, and no wallet needed to start. Link a\n                    Bitcoin address any time — that is the identity you hold yourself.\n                </FlowHeader>\n                <Label>email</Label>\n                <input\n                    type=\"email\"\n                    autoComplete=\"email\"\n                    value={email}\n                    onChange={(e) => {\n                        setEmail(e.target.value);\n                        if (emailError) setEmailError(null);\n                    }}\n                    placeholder=\"you@example.com\"\n                    required\n                    aria-invalid={emailError ? true : undefined}\n                    style={inputStyle}\n                />\n                {emailError && <ErrorLine>{emailError}</ErrorLine>}\n                <button type=\"submit\" disabled={submitting} style={submitStyle(submitting)}>\n                    {submitting ? 'sending…' : 'send one-time code →'}\n                </button>\n                <Hint>\n                    Codes come from the auth host, expire in 10 minutes, and work once.\n                </Hint>\n            </form>\n        );\n    }\n\n    return (\n        <form onSubmit={verify} data-oc-signin-email-verify=\"\">\n            <FlowHeader label=\"§ enter the code\">\n                Sent a 6-digit code to <span style={{ color: 'var(--foreground, #fafafa)' }}>{email}</span>.\n                Code expires in 10 minutes.\n            </FlowHeader>\n            <Label>one-time code</Label>\n            <input\n                type=\"text\"\n                inputMode=\"numeric\"\n                pattern=\"\\d{6}\"\n                maxLength={6}\n                autoComplete=\"one-time-code\"\n                value={code}\n                onChange={(e) => {\n                    setCode(e.target.value.replace(/\\D/g, '').slice(0, 6));\n                    if (codeError) setCodeError(null);\n                }}\n                placeholder=\"6 digits\"\n                required\n                autoFocus\n                aria-invalid={codeError ? true : undefined}\n                style={{ ...inputStyle, letterSpacing: '0.4em', fontSize: 16 }}\n            />\n            {codeError && <ErrorLine>{codeError}</ErrorLine>}\n            <button\n                type=\"submit\"\n                disabled={submitting || code.length !== 6}\n                style={submitStyle(submitting || code.length !== 6)}\n            >\n                {submitting ? 'verifying…' : 'verify · sign me in →'}\n            </button>\n            <button\n                type=\"button\"\n                onClick={() => {\n                    setStage('enter');\n                    setCode('');\n                    setToken(null);\n                }}\n                style={{\n                    marginTop: 12,\n                    background: 'transparent',\n                    border: 'none',\n                    color: 'var(--muted-foreground, #a1a1aa)',\n                    fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                    fontSize: 11,\n                    letterSpacing: '0.12em',\n                    textTransform: 'uppercase',\n                    cursor: 'pointer',\n                    padding: 0,\n                }}\n            >\n                use a different email\n            </button>\n            <Hint>On verify, oc_session is set on Domain=.ochk.io family-wide.</Hint>\n        </form>\n    );\n}\n\n/* --- shared subcomponents --- */\n\nfunction FlowHeader({\n    label,\n    children,\n}: {\n    label: string;\n    children: React.ReactNode;\n}): React.ReactElement {\n    return (\n        <div style={{ marginBottom: 16 }}>\n            <div\n                style={{\n                    color: 'var(--primary, #f97316)',\n                    fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                    fontSize: 10,\n                    letterSpacing: '0.18em',\n                    textTransform: 'uppercase',\n                    marginBottom: 6,\n                }}\n            >\n                {label}\n            </div>\n            <p\n                style={{\n                    color: 'var(--muted-foreground, #a1a1aa)',\n                    fontSize: 13,\n                    lineHeight: 1.55,\n                    margin: 0,\n                }}\n            >\n                {children}\n            </p>\n        </div>\n    );\n}\n\nfunction Label({ children }: { children: React.ReactNode }): React.ReactElement {\n    return (\n        <label\n            style={{\n                display: 'block',\n                color: 'var(--foreground, #fafafa)',\n                fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                fontSize: 11,\n                letterSpacing: '0.12em',\n                textTransform: 'uppercase',\n                marginBottom: 6,\n            }}\n        >\n            {children}\n        </label>\n    );\n}\n\nconst inputStyle: React.CSSProperties = {\n    width: '100%',\n    padding: '0.55rem 0.75rem',\n    background: 'var(--background, #0a0a0a)',\n    color: 'var(--foreground, #fafafa)',\n    border: '1px solid var(--input, #27272a)',\n    borderRadius: 6,\n    fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n    // 16px — never below it. A sub-16px font-size makes iOS Safari\n    // auto-zoom the viewport on focus; the family rule is >=16px on\n    // every form field. Desktop reads fine at 16 too.\n    fontSize: 16,\n    outline: 'none',\n};\n\nconst linkAlsoStyle: React.CSSProperties = {\n    display: 'flex',\n    alignItems: 'flex-start',\n    gap: 8,\n    marginTop: 16,\n    paddingTop: 14,\n    borderTop: '1px solid var(--border, #27272a)',\n    color: 'var(--muted-foreground, #a1a1aa)',\n    fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n    fontSize: 12,\n    lineHeight: 1.5,\n    cursor: 'pointer',\n};\n\nfunction submitStyle(disabled: boolean): React.CSSProperties {\n    return {\n        marginTop: 12,\n        padding: '0.6rem 1rem',\n        background: 'var(--primary, #f97316)',\n        color: 'var(--primary-foreground, #0a0a0a)',\n        border: 'none',\n        borderRadius: 6,\n        fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n        fontSize: 11,\n        letterSpacing: '0.14em',\n        textTransform: 'uppercase',\n        fontWeight: 600,\n        cursor: disabled ? 'not-allowed' : 'pointer',\n        opacity: disabled ? 0.5 : 1,\n        width: '100%',\n    };\n}\n\nfunction ErrorLine({ children }: { children: React.ReactNode }): React.ReactElement {\n    return (\n        <p\n            role=\"alert\"\n            style={{\n                marginTop: 6,\n                marginBottom: 0,\n                color: 'var(--destructive, #ef4444)',\n                fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                fontSize: 11,\n                letterSpacing: '0.04em',\n            }}\n        >\n            {children}\n        </p>\n    );\n}\n\nfunction Hint({ children }: { children: React.ReactNode }): React.ReactElement {\n    return (\n        <p\n            style={{\n                marginTop: 12,\n                marginBottom: 0,\n                color: 'var(--muted-foreground, #a1a1aa)',\n                fontFamily: 'ui-monospace, SFMono-Regular, monospace',\n                fontSize: 10.5,\n                lineHeight: 1.55,\n                opacity: 0.7,\n            }}\n        >\n            {'> '}\n            {children}\n        </p>\n    );\n}\n","/**\n * WebAuthn / passkey hooks for OrangeCheck consumer subdomains.\n *\n * Three hooks, all routing through the auth host (rpId='ochk.io'):\n *\n *   - `useWebAuthnRegister()` — bind a hardware key to the account.\n *   - `useWebAuthnList()`     — read + rename + revoke registered keys.\n *   - `useStepUpAuth()`       — prove possession of a key before a\n *                                sensitive action; the auth host\n *                                re-issues the session cookie with a\n *                                fresh `step_up_at` claim.\n *\n * Consumers don't talk to navigator.credentials directly — these hooks\n * own the round-trip to ochk.io + the @simplewebauthn/browser ceremony.\n *\n * Server-side gating is one import away in auth-core's\n * `verifyStepUpClaim(payload, { max_age_secs })`.\n */\n\nimport * as React from 'react';\nimport {\n    startAuthentication,\n    startRegistration,\n    type AuthenticationResponseJSON,\n    type PublicKeyCredentialCreationOptionsJSON,\n    type PublicKeyCredentialRequestOptionsJSON,\n    type RegistrationResponseJSON,\n} from '@simplewebauthn/browser';\n\nimport { useOcSession } from './provider';\nimport { resolveConfig, type OcAuthConfig } from './types';\n\n// ─── Shared types ───────────────────────────────────────────────────────\n\nexport interface WebAuthnCredentialPublic {\n    id: string;\n    label: string;\n    authenticator_type: 'platform' | 'cross-platform' | 'unknown';\n    transports: string[];\n    user_verified: boolean;\n    created_at: string;\n    last_used_at: string | null;\n}\n\nexport type WebAuthnRegisterStatus =\n    | 'idle'\n    | 'requesting-options'\n    | 'authenticating'\n    | 'verifying'\n    | 'success'\n    | 'error';\n\nexport type WebAuthnAssertionStatus = WebAuthnRegisterStatus;\nexport type WebAuthnListStatus = 'loading' | 'ready' | 'error';\n\ninterface UseHostOptions {\n    /** Override the auth host origin. Defaults to https://ochk.io.\n     *  Same convention as <OcSessionProvider config={{ authOrigin }} />. */\n    authOrigin?: string;\n}\n\nfunction resolveAuthOrigin(opts?: UseHostOptions | OcAuthConfig): string {\n    if (!opts) return resolveConfig(undefined).authOrigin;\n    return resolveConfig(opts as OcAuthConfig).authOrigin;\n}\n\ninterface OptionsResponse<T> {\n    ok: boolean;\n    options?: T;\n    challenge_token?: string;\n    reason?: string;\n}\n\nfunction isAbortError(err: unknown): boolean {\n    if (!(err instanceof Error)) return false;\n    return /NotAllowed|aborted|cancel|user cancelled/i.test(err.message);\n}\n\n// ─── useWebAuthnRegister ────────────────────────────────────────────────\n\nexport type WebAuthnRegisterResult =\n    | { ok: true; credential: WebAuthnCredentialPublic }\n    | { ok: false; reason: string };\n\nexport interface UseWebAuthnRegisterReturn {\n    status: WebAuthnRegisterStatus;\n    error: Error | null;\n    register: (args?: { label?: string }) => Promise<WebAuthnRegisterResult>;\n    reset: () => void;\n}\n\nexport function useWebAuthnRegister(opts?: UseHostOptions): UseWebAuthnRegisterReturn {\n    const authOrigin = resolveAuthOrigin(opts);\n    const [status, setStatus] = React.useState<WebAuthnRegisterStatus>('idle');\n    const [error, setError] = React.useState<Error | null>(null);\n\n    const reset = React.useCallback(() => {\n        setStatus('idle');\n        setError(null);\n    }, []);\n\n    const register = React.useCallback(\n        async (args?: { label?: string }): Promise<WebAuthnRegisterResult> => {\n            setError(null);\n            setStatus('requesting-options');\n            try {\n                const optsRes = await fetch(`${authOrigin}/api/auth/webauthn/register/options`, {\n                    method: 'POST',\n                    credentials: 'include',\n                    headers: { 'Content-Type': 'application/json' },\n                    body: JSON.stringify({ label: args?.label }),\n                });\n                const optsBody = (await optsRes.json()) as OptionsResponse<PublicKeyCredentialCreationOptionsJSON>;\n                if (!optsRes.ok || !optsBody.ok || !optsBody.options || !optsBody.challenge_token) {\n                    const reason = optsBody.reason ?? `options_failed_${optsRes.status}`;\n                    setError(new Error(reason));\n                    setStatus('error');\n                    return { ok: false, reason };\n                }\n                setStatus('authenticating');\n                let attestation: RegistrationResponseJSON;\n                try {\n                    attestation = await startRegistration({ optionsJSON: optsBody.options });\n                } catch (e) {\n                    const reason = isAbortError(e) ? 'cancelled' : (e as Error).message;\n                    setError(new Error(reason));\n                    setStatus('error');\n                    return { ok: false, reason };\n                }\n                setStatus('verifying');\n                const verifyRes = await fetch(`${authOrigin}/api/auth/webauthn/register/verify`, {\n                    method: 'POST',\n                    credentials: 'include',\n                    headers: { 'Content-Type': 'application/json' },\n                    body: JSON.stringify({\n                        challenge_token: optsBody.challenge_token,\n                        response: attestation,\n                        label: args?.label,\n                    }),\n                });\n                const verifyBody = (await verifyRes.json()) as {\n                    ok: boolean;\n                    credential?: WebAuthnCredentialPublic;\n                    reason?: string;\n                };\n                if (!verifyRes.ok || !verifyBody.ok || !verifyBody.credential) {\n                    const reason = verifyBody.reason ?? `verify_failed_${verifyRes.status}`;\n                    setError(new Error(reason));\n                    setStatus('error');\n                    return { ok: false, reason };\n                }\n                setStatus('success');\n                return { ok: true, credential: verifyBody.credential };\n            } catch (e) {\n                const reason = e instanceof Error ? e.message : String(e);\n                setError(new Error(reason));\n                setStatus('error');\n                return { ok: false, reason };\n            }\n        },\n        [authOrigin]\n    );\n\n    return { status, error, register, reset };\n}\n\n// ─── useWebAuthnList ────────────────────────────────────────────────────\n\nexport type WebAuthnRenameResult =\n    | { ok: true; credential: WebAuthnCredentialPublic }\n    | { ok: false; reason: string };\n\nexport type WebAuthnRemoveResult =\n    | { ok: true }\n    | { ok: false; reason: string };\n\nexport interface UseWebAuthnListReturn {\n    status: WebAuthnListStatus;\n    credentials: WebAuthnCredentialPublic[];\n    error: Error | null;\n    refetch: () => Promise<void>;\n    rename: (id: string, label: string) => Promise<WebAuthnRenameResult>;\n    remove: (id: string) => Promise<WebAuthnRemoveResult>;\n}\n\nexport function useWebAuthnList(opts?: UseHostOptions): UseWebAuthnListReturn {\n    const authOrigin = resolveAuthOrigin(opts);\n    const { status: sessionStatus } = useOcSession();\n    const [credentials, setCredentials] = React.useState<WebAuthnCredentialPublic[]>([]);\n    const [status, setStatus] = React.useState<WebAuthnListStatus>('loading');\n    const [error, setError] = React.useState<Error | null>(null);\n\n    const refetch = React.useCallback(async () => {\n        setError(null);\n        if (sessionStatus !== 'authenticated') {\n            setCredentials([]);\n            setStatus('ready');\n            return;\n        }\n        setStatus('loading');\n        try {\n            const r = await fetch(`${authOrigin}/api/auth/webauthn/credentials`, {\n                credentials: 'include',\n            });\n            if (r.status === 401) {\n                setCredentials([]);\n                setStatus('ready');\n                return;\n            }\n            const j = (await r.json()) as {\n                ok: boolean;\n                credentials?: WebAuthnCredentialPublic[];\n                reason?: string;\n            };\n            if (!j.ok || !j.credentials) {\n                throw new Error(j.reason ?? 'list_failed');\n            }\n            setCredentials(j.credentials);\n            setStatus('ready');\n        } catch (e) {\n            setError(e instanceof Error ? e : new Error(String(e)));\n            setStatus('error');\n        }\n    }, [authOrigin, sessionStatus]);\n\n    React.useEffect(() => {\n        void refetch();\n    }, [refetch]);\n\n    const rename = React.useCallback(\n        async (id: string, label: string): Promise<WebAuthnRenameResult> => {\n            try {\n                const r = await fetch(`${authOrigin}/api/auth/webauthn/credentials/${id}`, {\n                    method: 'PATCH',\n                    credentials: 'include',\n                    headers: { 'Content-Type': 'application/json' },\n                    body: JSON.stringify({ label }),\n                });\n                const j = (await r.json()) as {\n                    ok: boolean;\n                    credential?: WebAuthnCredentialPublic;\n                    reason?: string;\n                };\n                if (!j.ok || !j.credential) {\n                    const reason = j.reason ?? `rename_failed_${r.status}`;\n                    setError(new Error(reason));\n                    return { ok: false, reason };\n                }\n                await refetch();\n                return { ok: true, credential: j.credential };\n            } catch (e) {\n                const reason = e instanceof Error ? e.message : String(e);\n                setError(new Error(reason));\n                return { ok: false, reason };\n            }\n        },\n        [authOrigin, refetch]\n    );\n\n    const remove = React.useCallback(\n        async (id: string): Promise<WebAuthnRemoveResult> => {\n            try {\n                const r = await fetch(`${authOrigin}/api/auth/webauthn/credentials/${id}`, {\n                    method: 'DELETE',\n                    credentials: 'include',\n                });\n                const j = (await r.json()) as { ok: boolean; reason?: string };\n                if (!j.ok) {\n                    const reason = j.reason ?? `delete_failed_${r.status}`;\n                    setError(new Error(reason));\n                    return { ok: false, reason };\n                }\n                await refetch();\n                return { ok: true };\n            } catch (e) {\n                const reason = e instanceof Error ? e.message : String(e);\n                setError(new Error(reason));\n                return { ok: false, reason };\n            }\n        },\n        [authOrigin, refetch]\n    );\n\n    return { status, credentials, error, refetch, rename, remove };\n}\n\n// ─── useStepUpAuth ──────────────────────────────────────────────────────\n\nexport type WebAuthnStepUpResult =\n    | { ok: true; step_up_at: number }\n    | { ok: false; reason: string };\n\nexport interface UseStepUpAuthReturn {\n    status: WebAuthnAssertionStatus;\n    error: Error | null;\n    stepUp: (args: { purpose: string }) => Promise<WebAuthnStepUpResult>;\n    reset: () => void;\n}\n\n/**\n * Prove possession of a registered hardware key before a sensitive\n * action. On success the auth host sets a fresh oc_session cookie\n * carrying `step_up_at = <unix-now>`; the provider re-fetches the\n * session so `verifyStepUpClaim(payload, …)` flips to true immediately.\n *\n * Throws via `error` (not via `throw`) when:\n *   - the user has no credentials registered (`no_credentials_registered`)\n *   - the user cancels the platform prompt (`cancelled`)\n *   - the assertion fails verification on the host (`verify_failed`,\n *     `cloned_authenticator`, `credential_outside_allowlist`, …)\n *\n * Caller pattern:\n *\n *   const { stepUp } = useStepUpAuth();\n *   const { refresh } = useOcSession();\n *   const r = await stepUp({ purpose: 'spend_over_1m' });\n *   if (!r) return; // user cancelled or step-up failed\n *   await refresh(); // pick up the new step_up_at\n *   // …proceed with the sensitive action\n */\nexport function useStepUpAuth(opts?: UseHostOptions): UseStepUpAuthReturn {\n    const authOrigin = resolveAuthOrigin(opts);\n    const { refresh } = useOcSession();\n    const [status, setStatus] = React.useState<WebAuthnAssertionStatus>('idle');\n    const [error, setError] = React.useState<Error | null>(null);\n\n    const reset = React.useCallback(() => {\n        setStatus('idle');\n        setError(null);\n    }, []);\n\n    const stepUp = React.useCallback(\n        async (args: { purpose: string }): Promise<WebAuthnStepUpResult> => {\n            setError(null);\n            setStatus('requesting-options');\n            try {\n                const optsRes = await fetch(`${authOrigin}/api/auth/webauthn/assertion/options`, {\n                    method: 'POST',\n                    credentials: 'include',\n                    headers: { 'Content-Type': 'application/json' },\n                    body: JSON.stringify({ purpose: args.purpose }),\n                });\n                const optsBody = (await optsRes.json()) as OptionsResponse<PublicKeyCredentialRequestOptionsJSON>;\n                if (!optsRes.ok || !optsBody.ok || !optsBody.options || !optsBody.challenge_token) {\n                    const reason = optsBody.reason ?? `options_failed_${optsRes.status}`;\n                    setError(new Error(reason));\n                    setStatus('error');\n                    return { ok: false, reason };\n                }\n                setStatus('authenticating');\n                let assertion: AuthenticationResponseJSON;\n                try {\n                    assertion = await startAuthentication({ optionsJSON: optsBody.options });\n                } catch (e) {\n                    const reason = isAbortError(e) ? 'cancelled' : (e as Error).message;\n                    setError(new Error(reason));\n                    setStatus('error');\n                    return { ok: false, reason };\n                }\n                setStatus('verifying');\n                const verifyRes = await fetch(\n                    `${authOrigin}/api/auth/webauthn/assertion/verify`,\n                    {\n                        method: 'POST',\n                        credentials: 'include',\n                        headers: { 'Content-Type': 'application/json' },\n                        body: JSON.stringify({\n                            challenge_token: optsBody.challenge_token,\n                            response: assertion,\n                        }),\n                    }\n                );\n                const verifyBody = (await verifyRes.json()) as {\n                    ok: boolean;\n                    step_up_at?: number;\n                    reason?: string;\n                };\n                if (!verifyRes.ok || !verifyBody.ok || typeof verifyBody.step_up_at !== 'number') {\n                    const reason = verifyBody.reason ?? `verify_failed_${verifyRes.status}`;\n                    setError(new Error(reason));\n                    setStatus('error');\n                    return { ok: false, reason };\n                }\n                // Re-fetch the session so consumers see the fresh\n                // step_up_at claim without a separate `refresh()` call.\n                await refresh();\n                setStatus('success');\n                return { ok: true, step_up_at: verifyBody.step_up_at };\n            } catch (e) {\n                const reason = e instanceof Error ? e.message : String(e);\n                setError(new Error(reason));\n                setStatus('error');\n                return { ok: false, reason };\n            }\n        },\n        [authOrigin, refresh]\n    );\n\n    return { status, error, stepUp, reset };\n}\n"]}