diff --git a/.DS_Store b/.DS_Store new file mode 100644 index 00000000..bbce90eb Binary files /dev/null and b/.DS_Store differ diff --git a/docs/app/age-derive.html b/docs/app/age-derive.html index ab13191e..cbb6aa60 100644 --- a/docs/app/age-derive.html +++ b/docs/app/age-derive.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- OnlyAgent - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser
OnlyAgent

Loading...

\ No newline at end of file diff --git a/docs/app/bundle.25696c3cb9729a3b4dad.js b/docs/app/bundle.25696c3cb9729a3b4dad.js new file mode 100644 index 00000000..8c870700 --- /dev/null +++ b/docs/app/bundle.25696c3cb9729a3b4dad.js @@ -0,0 +1,180 @@ +!function(e){var t={};function r(n){if(t[n])return t[n].exports;var i=t[n]={i:n,l:!1,exports:{}};return e[n].call(i.exports,i,i.exports,r),i.l=!0,i.exports}r.m=e,r.c=t,r.d=function(e,t,n){r.o(e,t)||Object.defineProperty(e,t,{enumerable:!0,get:n})},r.r=function(e){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})},r.t=function(e,t){if(1&t&&(e=r(e)),8&t)return e;if(4&t&&"object"==typeof e&&e&&e.__esModule)return e;var n=Object.create(null);if(r.r(n),Object.defineProperty(n,"default",{enumerable:!0,value:e}),2&t&&"string"!=typeof e)for(var i in e)r.d(n,i,function(t){return e[t]}.bind(null,i));return n},r.n=function(e){var t=e&&e.__esModule?function(){return e.default}:function(){return e};return r.d(t,"a",t),t},r.o=function(e,t){return Object.prototype.hasOwnProperty.call(e,t)},r.p="",r(r.s=114)}([function(e,t,r){"use strict";function n(e){return e instanceof Uint8Array||ArrayBuffer.isView(e)&&"Uint8Array"===e.constructor.name&&"BYTES_PER_ELEMENT"in e&&1===e.BYTES_PER_ELEMENT}function i(e){var t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:"";if("number"!=typeof e){var r=t&&'"'.concat(t,'" ');throw new TypeError("".concat(r,"expected number, got ").concat(typeof e))}if(!Number.isSafeInteger(e)||e<0){var n=t&&'"'.concat(t,'" ');throw new RangeError("".concat(n,"expected integer >= 0, got ").concat(e))}}function a(e,t){var r=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"",i=n(e),a=null==e?void 0:e.length,s=void 0!==t;if(!i||s&&a!==t){var o=r&&'"'.concat(r,'" '),u=s?" of length ".concat(t):"",c=i?"length=".concat(a):"type=".concat(typeof e),l=o+"expected Uint8Array"+u+", got "+c;if(!i)throw new TypeError(l);throw new RangeError(l)}return e}function s(e){if("function"!=typeof e||"function"!=typeof e.create)throw new TypeError("Hash must wrapped by utils.createHasher");if(i(e.outputLen),i(e.blockLen),e.outputLen<1)throw new Error('"outputLen" must be >= 1');if(e.blockLen<1)throw new Error('"blockLen" must be >= 1')}function o(e){var t=!(arguments.length>1&&void 0!==arguments[1])||arguments[1];if(e.destroyed)throw new Error("Hash instance has been destroyed");if(t&&e.finished)throw new Error("Hash#digest() has already been called")}function u(e,t){a(e,void 0,"digestInto() output");var r=t.outputLen;if(e.length='+r)}function c(e){return new Uint32Array(e.buffer,e.byteOffset,Math.floor(e.byteLength/4))}function l(){for(var e=arguments.length,t=new Array(e),r=0;r>>t}r.d(t,"l",(function(){return n})),r.d(t,"d",(function(){return i})),r.d(t,"a",(function(){return a})),r.d(t,"c",(function(){return s})),r.d(t,"b",(function(){return o})),r.d(t,"e",(function(){return u})),r.d(t,"r",(function(){return c})),r.d(t,"g",(function(){return l})),r.d(t,"j",(function(){return f})),r.d(t,"p",(function(){return h})),r.d(t,"m",(function(){return d})),r.d(t,"q",(function(){return y})),r.d(t,"f",(function(){return b})),r.d(t,"k",(function(){return E})),r.d(t,"s",(function(){return C})),r.d(t,"h",(function(){return D})),r.d(t,"i",(function(){return P})),r.d(t,"o",(function(){return B})),r.d(t,"n",(function(){return T}));var d=(()=>68===new Uint8Array(new Uint32Array([287454020]).buffer)[0])();function p(e){return e<<24&4278190080|e<<8&16711680|e>>>8&65280|e>>>24&255}var y=d?e=>e:function(e){for(var t=0;t"function"==typeof Uint8Array.from([]).toHex&&"function"==typeof Uint8Array.fromHex)(),m=Array.from({length:256},(e,t)=>t.toString(16).padStart(2,"0"));function b(e){if(a(e),g)return e.toHex();for(var t="",r=0;r=v&&e<=_?e-v:e>=w&&e<=k?e-(w-10):e>=x&&e<=S?e-(x-10):void 0}function E(e){if("string"!=typeof e)throw new TypeError("hex string expected, got "+typeof e);if(g)try{return Uint8Array.fromHex(e)}catch(e){if(e instanceof SyntaxError)throw new RangeError(e.message);throw e}var t=e.length,r=t/2;if(t%2)throw new RangeError("hex string expected, got unpadded hex of length "+t);for(var n=new Uint8Array(r),i=0,a=0;i1&&void 0!==arguments[1]?arguments[1]:{},r=(t,r)=>e(r).update(t).digest(),n=e(void 0);return r.outputLen=n.outputLen,r.blockLen=n.blockLen,r.canXOF=n.canXOF,r.create=t=>e(t),Object.assign(r,t),Object.freeze(r)}function B(){var e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:32;i(e,"bytesLength");var t="object"==typeof globalThis?globalThis.crypto:null;if("function"!=typeof(null==t?void 0:t.getRandomValues))throw new Error("crypto.getRandomValues must be defined");if(e>65536)throw new RangeError('"bytesLength" expected <= 65536, got '.concat(e));return t.getRandomValues(new Uint8Array(e))}var T=e=>({oid:Uint8Array.from([6,9,96,134,72,1,101,3,4,2,e])})},function(e,t,r){"use strict"; +/*! noble-ciphers - MIT License (c) 2023 Paul Miller (paulmillr.com) */ +function n(e){return e instanceof Uint8Array||ArrayBuffer.isView(e)&&"Uint8Array"===e.constructor.name&&"BYTES_PER_ELEMENT"in e&&1===e.BYTES_PER_ELEMENT}function i(e){if("boolean"!=typeof e)throw new TypeError("boolean expected, not ".concat(e))}function a(e){if("number"!=typeof e)throw new TypeError("number expected, got "+typeof e);if(!Number.isSafeInteger(e)||e<0)throw new RangeError("positive integer expected, got "+e)}function s(e,t){var r=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"",i=n(e),a=null==e?void 0:e.length,s=void 0!==t;if(!i||s&&a!==t){var o=r&&'"'.concat(r,'" '),u=s?" of length ".concat(t):"",c=i?"length=".concat(a):"type=".concat(typeof e),l=o+"expected Uint8Array"+u+", got "+c;if(!i)throw new TypeError(l);throw new RangeError(l)}return e}function o(e){var t=!(arguments.length>1&&void 0!==arguments[1])||arguments[1];if(e.destroyed)throw new Error("Hash instance has been destroyed");if(t&&e.finished)throw new Error("Hash#digest() has already been called")}function u(e,t){var r=arguments.length>2&&void 0!==arguments[2]&&arguments[2];s(e,void 0,"output");var n=t.outputLen;if(e.length68===new Uint8Array(new Uint32Array([287454020]).buffer)[0])(),p=e=>e<<24&4278190080|e<<8&16711680|e>>>8&65280|e>>>24&255,y=d?e=>e:e=>p(e)>>>0,g=e=>{for(var t=0;te:g,b=(()=>"function"==typeof Uint8Array.from([]).toHex&&"function"==typeof Uint8Array.fromHex)(),v=Array.from({length:256},(e,t)=>t.toString(16).padStart(2,"0"));function _(e){if(s(e),b)return e.toHex();for(var t="",r=0;r=w&&e<=k?e-w:e>=x&&e<=S?e-(x-10):e>=A&&e<=E?e-(A-10):void 0}function D(e){if("string"!=typeof e)throw new TypeError("hex string expected, got "+typeof e);if(b)try{return Uint8Array.fromHex(e)}catch(e){if(e instanceof SyntaxError)throw new RangeError(e.message);throw e}var t=e.length,r=t/2;if(t%2)throw new RangeError("hex string expected, got unpadded hex of length "+t);for(var n=new Uint8Array(r),i=0,a=0;i[]),a=(e,t)=>n(t,...i(e)).update(e).digest(),s=n(new Uint8Array(e),...i(new Uint8Array(0)));return a.outputLen=s.outputLen,a.blockLen=s.blockLen,a.create=function(e){for(var t=arguments.length,r=new Array(t>1?t-1:0),i=1;i{function r(r){s(r,void 0,"key");for(var n=arguments.length,i=new Array(n>1?n-1:0),a=1;a{if(void 0!==t){if(2!==e)throw new Error("cipher output not supported");s(t,void 0,"output")}},f=!1,h={encrypt(e,t){if(f)throw new Error("cannot encrypt() twice with same key + nonce");return f=!0,s(e),l(c.encrypt.length,t),c.encrypt(e,t)},decrypt(e,t){if(s(e),u&&e.length0&&void 0!==arguments[0]?arguments[0]:32;a(e);var t="object"==typeof globalThis?globalThis.crypto:null;if("function"!=typeof(null==t?void 0:t.getRandomValues))throw new Error("crypto.getRandomValues must be defined");return t.getRandomValues(new Uint8Array(e))}function q(e){var t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:G,r=e.nonceLength;a(r);var n=(e,t,r)=>{var n=O(e,t);return R(r,t)||t.fill(0),n},i=function(i){for(var a=arguments.length,o=new Array(a>1?a-1:0),u=1;un(u,e,a)):n(u,c,a)},decrypt(t){s(t);var n=t.subarray(0,r),a=t.subarray(r);return e(i,n,...o).decrypt(a)}}};return"blockSize"in e&&(i.blockSize=e.blockSize),"tagLength"in e&&(i.tagLength=e.tagLength),i}},function(e,t,r){"use strict";r.d(t,"a",(function(){return m})),r.d(t,"b",(function(){return v})),r.d(t,"c",(function(){return b})),r.d(t,"d",(function(){return w})),r.d(t,"e",(function(){return _})),r.d(t,"f",(function(){return x})),r.d(t,"g",(function(){return k})),r.d(t,"h",(function(){return y})),r.d(t,"i",(function(){return g})),r.d(t,"j",(function(){return d})),r.d(t,"k",(function(){return p})),r.d(t,"l",(function(){return f})),r.d(t,"m",(function(){return h})),r.d(t,"n",(function(){return c})),r.d(t,"o",(function(){return l})),r.d(t,"p",(function(){return o})),r.d(t,"q",(function(){return u})),r.d(t,"r",(function(){return s}));var n=BigInt(2**32-1),i=BigInt(32);function a(e){var t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return t?{h:Number(e&n),l:Number(e>>i&n)}:{h:0|Number(e>>i&n),l:0|Number(e&n)}}function s(e){for(var t=arguments.length>1&&void 0!==arguments[1]&&arguments[1],r=e.length,n=new Uint32Array(r),i=new Uint32Array(r),s=0;se>>>r,u=(e,t,r)=>e<<32-r|t>>>r,c=(e,t,r)=>e>>>r|t<<32-r,l=(e,t,r)=>e<<32-r|t>>>r,f=(e,t,r)=>e<<64-r|t>>>r-32,h=(e,t,r)=>e>>>r-32|t<<64-r,d=(e,t,r)=>e<>>32-r,p=(e,t,r)=>t<>>32-r,y=(e,t,r)=>t<>>64-r,g=(e,t,r)=>e<>>64-r;function m(e,t,r,n){var i=(t>>>0)+(n>>>0);return{h:e+r+(i/2**32|0)|0,l:0|i}}var b=(e,t,r)=>(e>>>0)+(t>>>0)+(r>>>0),v=(e,t,r,n)=>t+r+n+(e/2**32|0)|0,_=(e,t,r,n)=>(e>>>0)+(t>>>0)+(r>>>0)+(n>>>0),w=(e,t,r,n,i)=>t+r+n+i+(e/2**32|0)|0,k=(e,t,r,n,i)=>(e>>>0)+(t>>>0)+(r>>>0)+(n>>>0)+(i>>>0),x=(e,t,r,n,i,a)=>t+r+n+i+a+(e/2**32|0)|0},function(e,t,r){ +/*! safe-buffer. MIT License. Feross Aboukhadijeh */ +var n=r(5),i=n.Buffer;function a(e,t){for(var r in e)t[r]=e[r]}function s(e,t,r){return i(e,t,r)}i.from&&i.alloc&&i.allocUnsafe&&i.allocUnsafeSlow?e.exports=n:(a(n,t),t.Buffer=s),s.prototype=Object.create(i.prototype),a(i,s),s.from=function(e,t,r){if("number"==typeof e)throw new TypeError("Argument must not be a number");return i(e,t,r)},s.alloc=function(e,t,r){if("number"!=typeof e)throw new TypeError("Argument must be a number");var n=i(e);return void 0!==t?"string"==typeof r?n.fill(t,r):n.fill(t):n.fill(0),n},s.allocUnsafe=function(e){if("number"!=typeof e)throw new TypeError("Argument must be a number");return i(e)},s.allocUnsafeSlow=function(e){if("number"!=typeof e)throw new TypeError("Argument must be a number");return n.SlowBuffer(e)}},function(e,t){"function"==typeof Object.create?e.exports=function(e,t){t&&(e.super_=t,e.prototype=Object.create(t.prototype,{constructor:{value:e,enumerable:!1,writable:!0,configurable:!0}}))}:e.exports=function(e,t){if(t){e.super_=t;var r=function(){};r.prototype=t.prototype,e.prototype=new r,e.prototype.constructor=e}}},function(e,t,r){"use strict";(function(e){ +/*! + * The buffer module from node.js, for the browser. + * + * @author Feross Aboukhadijeh + * @license MIT + */ +var n=r(134),i=r(135),a=r(64);function s(){return u.TYPED_ARRAY_SUPPORT?2147483647:1073741823}function o(e,t){if(s()=s())throw new RangeError("Attempt to allocate Buffer larger than maximum size: 0x"+s().toString(16)+" bytes");return 0|e}function p(e,t){if(u.isBuffer(e))return e.length;if("undefined"!=typeof ArrayBuffer&&"function"==typeof ArrayBuffer.isView&&(ArrayBuffer.isView(e)||e instanceof ArrayBuffer))return e.byteLength;"string"!=typeof e&&(e=""+e);var r=e.length;if(0===r)return 0;for(var n=!1;;)switch(t){case"ascii":case"latin1":case"binary":return r;case"utf8":case"utf-8":case void 0:return N(e).length;case"ucs2":case"ucs-2":case"utf16le":case"utf-16le":return 2*r;case"hex":return r>>>1;case"base64":return j(e).length;default:if(n)return N(e).length;t=(""+t).toLowerCase(),n=!0}}function y(e,t,r){var n=!1;if((void 0===t||t<0)&&(t=0),t>this.length)return"";if((void 0===r||r>this.length)&&(r=this.length),r<=0)return"";if((r>>>=0)<=(t>>>=0))return"";for(e||(e="utf8");;)switch(e){case"hex":return P(this,t,r);case"utf8":case"utf-8":return E(this,t,r);case"ascii":return C(this,t,r);case"latin1":case"binary":return D(this,t,r);case"base64":return A(this,t,r);case"ucs2":case"ucs-2":case"utf16le":case"utf-16le":return B(this,t,r);default:if(n)throw new TypeError("Unknown encoding: "+e);e=(e+"").toLowerCase(),n=!0}}function g(e,t,r){var n=e[t];e[t]=e[r],e[r]=n}function m(e,t,r,n,i){if(0===e.length)return-1;if("string"==typeof r?(n=r,r=0):r>2147483647?r=2147483647:r<-2147483648&&(r=-2147483648),r=+r,isNaN(r)&&(r=i?0:e.length-1),r<0&&(r=e.length+r),r>=e.length){if(i)return-1;r=e.length-1}else if(r<0){if(!i)return-1;r=0}if("string"==typeof t&&(t=u.from(t,n)),u.isBuffer(t))return 0===t.length?-1:b(e,t,r,n,i);if("number"==typeof t)return t&=255,u.TYPED_ARRAY_SUPPORT&&"function"==typeof Uint8Array.prototype.indexOf?i?Uint8Array.prototype.indexOf.call(e,t,r):Uint8Array.prototype.lastIndexOf.call(e,t,r):b(e,[t],r,n,i);throw new TypeError("val must be string, number or Buffer")}function b(e,t,r,n,i){var a,s=1,o=e.length,u=t.length;if(void 0!==n&&("ucs2"===(n=String(n).toLowerCase())||"ucs-2"===n||"utf16le"===n||"utf-16le"===n)){if(e.length<2||t.length<2)return-1;s=2,o/=2,u/=2,r/=2}function c(e,t){return 1===s?e[t]:e.readUInt16BE(t*s)}if(i){var l=-1;for(a=r;ao&&(r=o-u),a=r;a>=0;a--){for(var f=!0,h=0;hi&&(n=i):n=i;var a=t.length;if(a%2!=0)throw new TypeError("Invalid hex string");n>a/2&&(n=a/2);for(var s=0;s>8,i=r%256,a.push(i),a.push(n);return a}(t,e.length-r),e,r,n)}function A(e,t,r){return 0===t&&r===e.length?n.fromByteArray(e):n.fromByteArray(e.slice(t,r))}function E(e,t,r){r=Math.min(e.length,r);for(var n=[],i=t;i239?4:c>223?3:c>191?2:1;if(i+f<=r)switch(f){case 1:c<128&&(l=c);break;case 2:128==(192&(a=e[i+1]))&&(u=(31&c)<<6|63&a)>127&&(l=u);break;case 3:a=e[i+1],s=e[i+2],128==(192&a)&&128==(192&s)&&(u=(15&c)<<12|(63&a)<<6|63&s)>2047&&(u<55296||u>57343)&&(l=u);break;case 4:a=e[i+1],s=e[i+2],o=e[i+3],128==(192&a)&&128==(192&s)&&128==(192&o)&&(u=(15&c)<<18|(63&a)<<12|(63&s)<<6|63&o)>65535&&u<1114112&&(l=u)}null===l?(l=65533,f=1):l>65535&&(l-=65536,n.push(l>>>10&1023|55296),l=56320|1023&l),n.push(l),i+=f}return function(e){var t=e.length;if(t<=4096)return String.fromCharCode.apply(String,e);var r="",n=0;for(;n0&&(e=this.toString("hex",0,r).match(/.{2}/g).join(" "),this.length>r&&(e+=" ... ")),""},u.prototype.compare=function(e,t,r,n,i){if(!u.isBuffer(e))throw new TypeError("Argument must be a Buffer");if(void 0===t&&(t=0),void 0===r&&(r=e?e.length:0),void 0===n&&(n=0),void 0===i&&(i=this.length),t<0||r>e.length||n<0||i>this.length)throw new RangeError("out of range index");if(n>=i&&t>=r)return 0;if(n>=i)return-1;if(t>=r)return 1;if(this===e)return 0;for(var a=(i>>>=0)-(n>>>=0),s=(r>>>=0)-(t>>>=0),o=Math.min(a,s),c=this.slice(n,i),l=e.slice(t,r),f=0;fi)&&(r=i),e.length>0&&(r<0||t<0)||t>this.length)throw new RangeError("Attempt to write outside buffer bounds");n||(n="utf8");for(var a=!1;;)switch(n){case"hex":return v(this,e,t,r);case"utf8":case"utf-8":return _(this,e,t,r);case"ascii":return w(this,e,t,r);case"latin1":case"binary":return k(this,e,t,r);case"base64":return x(this,e,t,r);case"ucs2":case"ucs-2":case"utf16le":case"utf-16le":return S(this,e,t,r);default:if(a)throw new TypeError("Unknown encoding: "+n);n=(""+n).toLowerCase(),a=!0}},u.prototype.toJSON=function(){return{type:"Buffer",data:Array.prototype.slice.call(this._arr||this,0)}};function C(e,t,r){var n="";r=Math.min(e.length,r);for(var i=t;in)&&(r=n);for(var i="",a=t;ar)throw new RangeError("Trying to access beyond buffer length")}function I(e,t,r,n,i,a){if(!u.isBuffer(e))throw new TypeError('"buffer" argument must be a Buffer instance');if(t>i||te.length)throw new RangeError("Index out of range")}function M(e,t,r,n){t<0&&(t=65535+t+1);for(var i=0,a=Math.min(e.length-r,2);i>>8*(n?i:1-i)}function R(e,t,r,n){t<0&&(t=4294967295+t+1);for(var i=0,a=Math.min(e.length-r,4);i>>8*(n?i:3-i)&255}function L(e,t,r,n,i,a){if(r+n>e.length)throw new RangeError("Index out of range");if(r<0)throw new RangeError("Index out of range")}function O(e,t,r,n,a){return a||L(e,0,r,4),i.write(e,t,r,n,23,4),r+4}function U(e,t,r,n,a){return a||L(e,0,r,8),i.write(e,t,r,n,52,8),r+8}u.prototype.slice=function(e,t){var r,n=this.length;if((e=~~e)<0?(e+=n)<0&&(e=0):e>n&&(e=n),(t=void 0===t?n:~~t)<0?(t+=n)<0&&(t=0):t>n&&(t=n),t0&&(i*=256);)n+=this[e+--t]*i;return n},u.prototype.readUInt8=function(e,t){return t||T(e,1,this.length),this[e]},u.prototype.readUInt16LE=function(e,t){return t||T(e,2,this.length),this[e]|this[e+1]<<8},u.prototype.readUInt16BE=function(e,t){return t||T(e,2,this.length),this[e]<<8|this[e+1]},u.prototype.readUInt32LE=function(e,t){return t||T(e,4,this.length),(this[e]|this[e+1]<<8|this[e+2]<<16)+16777216*this[e+3]},u.prototype.readUInt32BE=function(e,t){return t||T(e,4,this.length),16777216*this[e]+(this[e+1]<<16|this[e+2]<<8|this[e+3])},u.prototype.readIntLE=function(e,t,r){e|=0,t|=0,r||T(e,t,this.length);for(var n=this[e],i=1,a=0;++a=(i*=128)&&(n-=Math.pow(2,8*t)),n},u.prototype.readIntBE=function(e,t,r){e|=0,t|=0,r||T(e,t,this.length);for(var n=t,i=1,a=this[e+--n];n>0&&(i*=256);)a+=this[e+--n]*i;return a>=(i*=128)&&(a-=Math.pow(2,8*t)),a},u.prototype.readInt8=function(e,t){return t||T(e,1,this.length),128&this[e]?-1*(255-this[e]+1):this[e]},u.prototype.readInt16LE=function(e,t){t||T(e,2,this.length);var r=this[e]|this[e+1]<<8;return 32768&r?4294901760|r:r},u.prototype.readInt16BE=function(e,t){t||T(e,2,this.length);var r=this[e+1]|this[e]<<8;return 32768&r?4294901760|r:r},u.prototype.readInt32LE=function(e,t){return t||T(e,4,this.length),this[e]|this[e+1]<<8|this[e+2]<<16|this[e+3]<<24},u.prototype.readInt32BE=function(e,t){return t||T(e,4,this.length),this[e]<<24|this[e+1]<<16|this[e+2]<<8|this[e+3]},u.prototype.readFloatLE=function(e,t){return t||T(e,4,this.length),i.read(this,e,!0,23,4)},u.prototype.readFloatBE=function(e,t){return t||T(e,4,this.length),i.read(this,e,!1,23,4)},u.prototype.readDoubleLE=function(e,t){return t||T(e,8,this.length),i.read(this,e,!0,52,8)},u.prototype.readDoubleBE=function(e,t){return t||T(e,8,this.length),i.read(this,e,!1,52,8)},u.prototype.writeUIntLE=function(e,t,r,n){(e=+e,t|=0,r|=0,n)||I(this,e,t,r,Math.pow(2,8*r)-1,0);var i=1,a=0;for(this[t]=255&e;++a=0&&(a*=256);)this[t+i]=e/a&255;return t+r},u.prototype.writeUInt8=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,1,255,0),u.TYPED_ARRAY_SUPPORT||(e=Math.floor(e)),this[t]=255&e,t+1},u.prototype.writeUInt16LE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,2,65535,0),u.TYPED_ARRAY_SUPPORT?(this[t]=255&e,this[t+1]=e>>>8):M(this,e,t,!0),t+2},u.prototype.writeUInt16BE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,2,65535,0),u.TYPED_ARRAY_SUPPORT?(this[t]=e>>>8,this[t+1]=255&e):M(this,e,t,!1),t+2},u.prototype.writeUInt32LE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,4,4294967295,0),u.TYPED_ARRAY_SUPPORT?(this[t+3]=e>>>24,this[t+2]=e>>>16,this[t+1]=e>>>8,this[t]=255&e):R(this,e,t,!0),t+4},u.prototype.writeUInt32BE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,4,4294967295,0),u.TYPED_ARRAY_SUPPORT?(this[t]=e>>>24,this[t+1]=e>>>16,this[t+2]=e>>>8,this[t+3]=255&e):R(this,e,t,!1),t+4},u.prototype.writeIntLE=function(e,t,r,n){if(e=+e,t|=0,!n){var i=Math.pow(2,8*r-1);I(this,e,t,r,i-1,-i)}var a=0,s=1,o=0;for(this[t]=255&e;++a>0)-o&255;return t+r},u.prototype.writeIntBE=function(e,t,r,n){if(e=+e,t|=0,!n){var i=Math.pow(2,8*r-1);I(this,e,t,r,i-1,-i)}var a=r-1,s=1,o=0;for(this[t+a]=255&e;--a>=0&&(s*=256);)e<0&&0===o&&0!==this[t+a+1]&&(o=1),this[t+a]=(e/s>>0)-o&255;return t+r},u.prototype.writeInt8=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,1,127,-128),u.TYPED_ARRAY_SUPPORT||(e=Math.floor(e)),e<0&&(e=255+e+1),this[t]=255&e,t+1},u.prototype.writeInt16LE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,2,32767,-32768),u.TYPED_ARRAY_SUPPORT?(this[t]=255&e,this[t+1]=e>>>8):M(this,e,t,!0),t+2},u.prototype.writeInt16BE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,2,32767,-32768),u.TYPED_ARRAY_SUPPORT?(this[t]=e>>>8,this[t+1]=255&e):M(this,e,t,!1),t+2},u.prototype.writeInt32LE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,4,2147483647,-2147483648),u.TYPED_ARRAY_SUPPORT?(this[t]=255&e,this[t+1]=e>>>8,this[t+2]=e>>>16,this[t+3]=e>>>24):R(this,e,t,!0),t+4},u.prototype.writeInt32BE=function(e,t,r){return e=+e,t|=0,r||I(this,e,t,4,2147483647,-2147483648),e<0&&(e=4294967295+e+1),u.TYPED_ARRAY_SUPPORT?(this[t]=e>>>24,this[t+1]=e>>>16,this[t+2]=e>>>8,this[t+3]=255&e):R(this,e,t,!1),t+4},u.prototype.writeFloatLE=function(e,t,r){return O(this,e,t,!0,r)},u.prototype.writeFloatBE=function(e,t,r){return O(this,e,t,!1,r)},u.prototype.writeDoubleLE=function(e,t,r){return U(this,e,t,!0,r)},u.prototype.writeDoubleBE=function(e,t,r){return U(this,e,t,!1,r)},u.prototype.copy=function(e,t,r,n){if(r||(r=0),n||0===n||(n=this.length),t>=e.length&&(t=e.length),t||(t=0),n>0&&n=this.length)throw new RangeError("sourceStart out of bounds");if(n<0)throw new RangeError("sourceEnd out of bounds");n>this.length&&(n=this.length),e.length-t=0;--i)e[i+t]=this[i+r];else if(a<1e3||!u.TYPED_ARRAY_SUPPORT)for(i=0;i>>=0,r=void 0===r?this.length:r>>>0,e||(e=0),"number"==typeof e)for(a=t;a55295&&r<57344){if(!i){if(r>56319){(t-=3)>-1&&a.push(239,191,189);continue}if(s+1===n){(t-=3)>-1&&a.push(239,191,189);continue}i=r;continue}if(r<56320){(t-=3)>-1&&a.push(239,191,189),i=r;continue}r=65536+(i-55296<<10|r-56320)}else i&&(t-=3)>-1&&a.push(239,191,189);if(i=null,r<128){if((t-=1)<0)break;a.push(r)}else if(r<2048){if((t-=2)<0)break;a.push(r>>6|192,63&r|128)}else if(r<65536){if((t-=3)<0)break;a.push(r>>12|224,r>>6&63|128,63&r|128)}else{if(!(r<1114112))throw new Error("Invalid code point");if((t-=4)<0)break;a.push(r>>18|240,r>>12&63|128,r>>6&63|128,63&r|128)}}return a}function j(e){return n.toByteArray(function(e){if((e=function(e){return e.trim?e.trim():e.replace(/^\s+|\s+$/g,"")}(e).replace(K,"")).length<2)return"";for(;e.length%4!=0;)e+="=";return e}(e))}function H(e,t,r,n){for(var i=0;i=t.length||i>=e.length);++i)t[i+r]=e[i];return i}}).call(this,r(6))},function(e,t){var r;r=function(){return this}();try{r=r||new Function("return this")()}catch(e){"object"==typeof window&&(r=window)}e.exports=r},function(e,t){function r(e,t){if(!e)throw new Error(t||"Assertion failed")}e.exports=r,r.equal=function(e,t,r){if(e!=t)throw new Error(r||"Assertion failed: "+e+" != "+t)}},function(e,t,r){"use strict";var n=t,i=r(15),a=r(7),s=r(99);n.assert=a,n.toArray=s.toArray,n.zero2=s.zero2,n.toHex=s.toHex,n.encode=s.encode,n.getNAF=function(e,t,r){var n,i=new Array(Math.max(e.bitLength(),r)+1);for(n=0;n(a>>1)-1?(a>>1)-u:u,s.isubn(o)):o=0,i[n]=o,s.iushrn(1)}return i},n.getJSF=function(e,t){var r=[[],[]];e=e.clone(),t=t.clone();for(var n,i=0,a=0;e.cmpn(-i)>0||t.cmpn(-a)>0;){var s,o,u=e.andln(3)+i&3,c=t.andln(3)+a&3;3===u&&(u=-1),3===c&&(c=-1),s=0==(1&u)?0:3!==(n=e.andln(7)+i&7)&&5!==n||2!==c?u:-u,r[0].push(s),o=0==(1&c)?0:3!==(n=t.andln(7)+a&7)&&5!==n||2!==u?c:-c,r[1].push(o),2*i===s+1&&(i=1-i),2*a===o+1&&(a=1-a),e.iushrn(1),t.iushrn(1)}return r},n.cachedProperty=function(e,t,r){var n="_"+t;e.prototype[t]=function(){return void 0!==this[n]?this[n]:this[n]=r.call(this)}},n.parseBytes=function(e){return"string"==typeof e?n.toArray(e,"hex"):e},n.intFromLE=function(e){return new i(e,"hex","le")}},function(e,t,r){"use strict";r.r(t),r.d(t,"_SHA256",(function(){return g})),r.d(t,"_SHA224",(function(){return m})),r.d(t,"_SHA512",(function(){return S})),r.d(t,"_SHA384",(function(){return A})),r.d(t,"_SHA512_224",(function(){return D})),r.d(t,"_SHA512_256",(function(){return P})),r.d(t,"sha256",(function(){return B})),r.d(t,"sha224",(function(){return T})),r.d(t,"sha512",(function(){return I})),r.d(t,"sha384",(function(){return M})),r.d(t,"sha512_256",(function(){return R})),r.d(t,"sha512_224",(function(){return L}));var n=r(0);function i(e,t,r){return(t=function(e){var t=function(e,t){if("object"!=typeof e||!e)return e;var r=e[Symbol.toPrimitive];if(void 0!==r){var n=r.call(e,t||"default");if("object"!=typeof n)return n;throw new TypeError("@@toPrimitive must return a primitive value.")}return("string"===t?String:Number)(e)}(e,"string");return"symbol"==typeof t?t:t+""}(t))in e?Object.defineProperty(e,t,{value:r,enumerable:!0,configurable:!0,writable:!0}):e[t]=r,e}function a(e,t,r){return e&t^e&r^t&r}class s{constructor(e,t,r,a){i(this,"blockLen",void 0),i(this,"outputLen",void 0),i(this,"canXOF",!1),i(this,"padOffset",void 0),i(this,"isLE",void 0),i(this,"buffer",void 0),i(this,"view",void 0),i(this,"finished",!1),i(this,"length",0),i(this,"pos",0),i(this,"destroyed",!1),this.blockLen=e,this.outputLen=t,this.padOffset=r,this.isLE=a,this.buffer=new Uint8Array(e),this.view=Object(n.j)(this.buffer)}update(e){Object(n.b)(this),Object(n.a)(e);for(var t=this.view,r=this.buffer,i=this.blockLen,a=e.length,s=0;si-s&&(this.process(r,0),s=0);for(var o=s;of.length)throw new Error("_sha2: outputLen bigger than state");for(var h=0;h>>3,c=Object(n.p)(o,17)^Object(n.p)(o,19)^o>>>10;p[i]=c+p[i-7]+u+p[i-16]|0}for(var l,f=this.A,h=this.B,y=this.C,g=this.D,m=this.E,b=this.F,v=this.G,_=this.H,w=0;w<64;w++){var k=_+(Object(n.p)(m,6)^Object(n.p)(m,11)^Object(n.p)(m,25))+((l=m)&b^~l&v)+d[w]+p[w]|0,x=(Object(n.p)(f,2)^Object(n.p)(f,13)^Object(n.p)(f,22))+a(f,h,y)|0;_=v,v=b,b=m,m=g+k|0,g=y,y=h,h=f,f=k+x|0}f=f+this.A|0,h=h+this.B|0,y=y+this.C|0,g=g+this.D|0,m=m+this.E|0,b=b+this.F|0,v=v+this.G|0,_=_+this.H|0,this.set(f,h,y,g,m,b,v,_)}roundClean(){Object(n.g)(p)}destroy(){this.destroyed=!0,this.set(0,0,0,0,0,0,0,0),Object(n.g)(this.buffer)}}class g extends y{constructor(){super(32),h(this,"A",0|o[0]),h(this,"B",0|o[1]),h(this,"C",0|o[2]),h(this,"D",0|o[3]),h(this,"E",0|o[4]),h(this,"F",0|o[5]),h(this,"G",0|o[6]),h(this,"H",0|o[7])}}class m extends y{constructor(){super(28),h(this,"A",0|u[0]),h(this,"B",0|u[1]),h(this,"C",0|u[2]),h(this,"D",0|u[3]),h(this,"E",0|u[4]),h(this,"F",0|u[5]),h(this,"G",0|u[6]),h(this,"H",0|u[7])}}var b=(()=>f.r(["0x428a2f98d728ae22","0x7137449123ef65cd","0xb5c0fbcfec4d3b2f","0xe9b5dba58189dbbc","0x3956c25bf348b538","0x59f111f1b605d019","0x923f82a4af194f9b","0xab1c5ed5da6d8118","0xd807aa98a3030242","0x12835b0145706fbe","0x243185be4ee4b28c","0x550c7dc3d5ffb4e2","0x72be5d74f27b896f","0x80deb1fe3b1696b1","0x9bdc06a725c71235","0xc19bf174cf692694","0xe49b69c19ef14ad2","0xefbe4786384f25e3","0x0fc19dc68b8cd5b5","0x240ca1cc77ac9c65","0x2de92c6f592b0275","0x4a7484aa6ea6e483","0x5cb0a9dcbd41fbd4","0x76f988da831153b5","0x983e5152ee66dfab","0xa831c66d2db43210","0xb00327c898fb213f","0xbf597fc7beef0ee4","0xc6e00bf33da88fc2","0xd5a79147930aa725","0x06ca6351e003826f","0x142929670a0e6e70","0x27b70a8546d22ffc","0x2e1b21385c26c926","0x4d2c6dfc5ac42aed","0x53380d139d95b3df","0x650a73548baf63de","0x766a0abb3c77b2a8","0x81c2c92e47edaee6","0x92722c851482353b","0xa2bfe8a14cf10364","0xa81a664bbc423001","0xc24b8b70d0f89791","0xc76c51a30654be30","0xd192e819d6ef5218","0xd69906245565a910","0xf40e35855771202a","0x106aa07032bbd1b8","0x19a4c116b8d2d0c8","0x1e376c085141ab53","0x2748774cdf8eeb99","0x34b0bcb5e19b48a8","0x391c0cb3c5c95a63","0x4ed8aa4ae3418acb","0x5b9cca4f7763e373","0x682e6ff3d6b2b8a3","0x748f82ee5defb2fc","0x78a5636f43172f60","0x84c87814a1f0ab72","0x8cc702081a6439ec","0x90befffa23631e28","0xa4506cebde82bde9","0xbef9a3f7b2c67915","0xc67178f2e372532b","0xca273eceea26619c","0xd186b8c721c0c207","0xeada7dd6cde0eb1e","0xf57d4f7fee6ed178","0x06f067aa72176fba","0x0a637dc5a2c898a6","0x113f9804bef90dae","0x1b710b35131c471b","0x28db77f523047d84","0x32caab7b40c72493","0x3c9ebe0a15c9bebc","0x431d67c49c100d4c","0x4cc5d4becb3e42b6","0x597f299cfc657e2a","0x5fcb6fab3ad6faec","0x6c44198c4a475817"].map(e=>BigInt(e))))(),v=(()=>b[0])(),_=(()=>b[1])(),w=new Uint32Array(80),k=new Uint32Array(80);class x extends s{constructor(e){super(128,e,16,!1)}get(){return[this.Ah,this.Al,this.Bh,this.Bl,this.Ch,this.Cl,this.Dh,this.Dl,this.Eh,this.El,this.Fh,this.Fl,this.Gh,this.Gl,this.Hh,this.Hl]}set(e,t,r,n,i,a,s,o,u,c,l,f,h,d,p,y){this.Ah=0|e,this.Al=0|t,this.Bh=0|r,this.Bl=0|n,this.Ch=0|i,this.Cl=0|a,this.Dh=0|s,this.Dl=0|o,this.Eh=0|u,this.El=0|c,this.Fh=0|l,this.Fl=0|f,this.Gh=0|h,this.Gl=0|d,this.Hh=0|p,this.Hl=0|y}process(e,t){for(var r=0;r<16;r++,t+=4)w[r]=e.getUint32(t),k[r]=e.getUint32(t+=4);for(var n=16;n<80;n++){var i=0|w[n-15],a=0|k[n-15],s=f.n(i,a,1)^f.n(i,a,8)^f.p(i,a,7),o=f.o(i,a,1)^f.o(i,a,8)^f.q(i,a,7),u=0|w[n-2],c=0|k[n-2],l=f.n(u,c,19)^f.l(u,c,61)^f.p(u,c,6),h=f.o(u,c,19)^f.m(u,c,61)^f.q(u,c,6),d=f.e(o,h,k[n-7],k[n-16]),p=f.d(d,s,l,w[n-7],w[n-16]);w[n]=0|p,k[n]=0|d}for(var y=this.Ah,g=this.Al,m=this.Bh,b=this.Bl,x=this.Ch,S=this.Cl,A=this.Dh,E=this.Dl,C=this.Eh,D=this.El,P=this.Fh,B=this.Fl,T=this.Gh,I=this.Gl,M=this.Hh,R=this.Hl,L=0;L<80;L++){var O=f.n(C,D,14)^f.n(C,D,18)^f.l(C,D,41),U=f.o(C,D,14)^f.o(C,D,18)^f.m(C,D,41),K=C&P^~C&T,F=D&B^~D&I,N=f.g(R,U,F,_[L],k[L]),j=f.f(N,M,O,K,v[L],w[L]),H=0|N,$=f.n(y,g,28)^f.l(y,g,34)^f.l(y,g,39),z=f.o(y,g,28)^f.m(y,g,34)^f.m(y,g,39),G=y&m^y&x^m&x,q=g&b^g&S^b&S;M=0|T,R=0|I,T=0|P,I=0|B,P=0|C,B=0|D;var V=f.a(0|A,0|E,0|j,0|H);C=V.h,D=V.l,A=0|x,E=0|S,x=0|m,S=0|b,m=0|y,b=0|g;var W=f.c(H,z,q);y=f.b(W,j,$,G),g=0|W}var Y=f.a(0|this.Ah,0|this.Al,0|y,0|g);y=Y.h,g=Y.l;var Q=f.a(0|this.Bh,0|this.Bl,0|m,0|b);m=Q.h,b=Q.l;var Z=f.a(0|this.Ch,0|this.Cl,0|x,0|S);x=Z.h,S=Z.l;var X=f.a(0|this.Dh,0|this.Dl,0|A,0|E);A=X.h,E=X.l;var J=f.a(0|this.Eh,0|this.El,0|C,0|D);C=J.h,D=J.l;var ee=f.a(0|this.Fh,0|this.Fl,0|P,0|B);P=ee.h,B=ee.l;var te=f.a(0|this.Gh,0|this.Gl,0|T,0|I);T=te.h,I=te.l;var re=f.a(0|this.Hh,0|this.Hl,0|M,0|R);M=re.h,R=re.l,this.set(y,g,m,b,x,S,A,E,C,D,P,B,T,I,M,R)}roundClean(){Object(n.g)(w,k)}destroy(){this.destroyed=!0,Object(n.g)(this.buffer),this.set(0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0)}}class S extends x{constructor(){super(64),h(this,"Ah",0|l[0]),h(this,"Al",0|l[1]),h(this,"Bh",0|l[2]),h(this,"Bl",0|l[3]),h(this,"Ch",0|l[4]),h(this,"Cl",0|l[5]),h(this,"Dh",0|l[6]),h(this,"Dl",0|l[7]),h(this,"Eh",0|l[8]),h(this,"El",0|l[9]),h(this,"Fh",0|l[10]),h(this,"Fl",0|l[11]),h(this,"Gh",0|l[12]),h(this,"Gl",0|l[13]),h(this,"Hh",0|l[14]),h(this,"Hl",0|l[15])}}class A extends x{constructor(){super(48),h(this,"Ah",0|c[0]),h(this,"Al",0|c[1]),h(this,"Bh",0|c[2]),h(this,"Bl",0|c[3]),h(this,"Ch",0|c[4]),h(this,"Cl",0|c[5]),h(this,"Dh",0|c[6]),h(this,"Dl",0|c[7]),h(this,"Eh",0|c[8]),h(this,"El",0|c[9]),h(this,"Fh",0|c[10]),h(this,"Fl",0|c[11]),h(this,"Gh",0|c[12]),h(this,"Gl",0|c[13]),h(this,"Hh",0|c[14]),h(this,"Hl",0|c[15])}}var E=Uint32Array.from([2352822216,424955298,1944164710,2312950998,502970286,855612546,1738396948,1479516111,258812777,2077511080,2011393907,79989058,1067287976,1780299464,286451373,2446758561]),C=Uint32Array.from([573645204,4230739756,2673172387,3360449730,596883563,1867755857,2520282905,1497426621,2519219938,2827943907,3193839141,1401305490,721525244,746961066,246885852,2177182882]);class D extends x{constructor(){super(28),h(this,"Ah",0|E[0]),h(this,"Al",0|E[1]),h(this,"Bh",0|E[2]),h(this,"Bl",0|E[3]),h(this,"Ch",0|E[4]),h(this,"Cl",0|E[5]),h(this,"Dh",0|E[6]),h(this,"Dl",0|E[7]),h(this,"Eh",0|E[8]),h(this,"El",0|E[9]),h(this,"Fh",0|E[10]),h(this,"Fl",0|E[11]),h(this,"Gh",0|E[12]),h(this,"Gl",0|E[13]),h(this,"Hh",0|E[14]),h(this,"Hl",0|E[15])}}class P extends x{constructor(){super(32),h(this,"Ah",0|C[0]),h(this,"Al",0|C[1]),h(this,"Bh",0|C[2]),h(this,"Bl",0|C[3]),h(this,"Ch",0|C[4]),h(this,"Cl",0|C[5]),h(this,"Dh",0|C[6]),h(this,"Dl",0|C[7]),h(this,"Eh",0|C[8]),h(this,"El",0|C[9]),h(this,"Fh",0|C[10]),h(this,"Fl",0|C[11]),h(this,"Gh",0|C[12]),h(this,"Gl",0|C[13]),h(this,"Hh",0|C[14]),h(this,"Hl",0|C[15])}}var B=Object(n.i)(()=>new g,Object(n.n)(1)),T=Object(n.i)(()=>new m,Object(n.n)(4)),I=Object(n.i)(()=>new S,Object(n.n)(3)),M=Object(n.i)(()=>new A,Object(n.n)(2)),R=Object(n.i)(()=>new P,Object(n.n)(6)),L=Object(n.i)(()=>new D,Object(n.n)(5))},function(e,t,r){var n; +/*! + * jQuery JavaScript Library v3.7.1 + * https://jquery.com/ + * + * Copyright OpenJS Foundation and other contributors + * Released under the MIT license + * https://jquery.org/license + * + * Date: 2023-08-28T13:37Z + */!function(t,r){"use strict";"object"==typeof e.exports?e.exports=t.document?r(t,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return r(e)}:r(t)}("undefined"!=typeof window?window:this,(function(r,i){"use strict";var a=[],s=Object.getPrototypeOf,o=a.slice,u=a.flat?function(e){return a.flat.call(e)}:function(e){return a.concat.apply([],e)},c=a.push,l=a.indexOf,f={},h=f.toString,d=f.hasOwnProperty,p=d.toString,y=p.call(Object),g={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},b=function(e){return null!=e&&e===e.window},v=r.document,_={type:!0,src:!0,nonce:!0,noModule:!0};function w(e,t,r){var n,i,a=(r=r||v).createElement("script");if(a.text=e,t)for(n in _)(i=t[n]||t.getAttribute&&t.getAttribute(n))&&a.setAttribute(n,i);r.head.appendChild(a).parentNode.removeChild(a)}function k(e){return null==e?e+"":"object"==typeof e||"function"==typeof e?f[h.call(e)]||"object":typeof e}var x=/HTML$/i,S=function(e,t){return new S.fn.init(e,t)};function A(e){var t=!!e&&"length"in e&&e.length,r=k(e);return!m(e)&&!b(e)&&("array"===r||0===t||"number"==typeof t&&t>0&&t-1 in e)}function E(e,t){return e.nodeName&&e.nodeName.toLowerCase()===t.toLowerCase()}S.fn=S.prototype={jquery:"3.7.1",constructor:S,length:0,toArray:function(){return o.call(this)},get:function(e){return null==e?o.call(this):e<0?this[e+this.length]:this[e]},pushStack:function(e){var t=S.merge(this.constructor(),e);return t.prevObject=this,t},each:function(e){return S.each(this,e)},map:function(e){return this.pushStack(S.map(this,(function(t,r){return e.call(t,r,t)})))},slice:function(){return this.pushStack(o.apply(this,arguments))},first:function(){return this.eq(0)},last:function(){return this.eq(-1)},even:function(){return this.pushStack(S.grep(this,(function(e,t){return(t+1)%2})))},odd:function(){return this.pushStack(S.grep(this,(function(e,t){return t%2})))},eq:function(e){var t=this.length,r=+e+(e<0?t:0);return this.pushStack(r>=0&&r+~]|"+B+")"+B+"*"),j=new RegExp(B+"|>"),H=new RegExp(U),$=new RegExp("^"+M+"$"),z={ID:new RegExp("^#("+M+")"),CLASS:new RegExp("^\\.("+M+")"),TAG:new RegExp("^("+M+"|[*])"),ATTR:new RegExp("^"+O),PSEUDO:new RegExp("^"+U),CHILD:new RegExp("^:(only|first|last|nth|nth-last)-(child|of-type)(?:\\("+B+"*(even|odd|(([+-]|)(\\d*)n|)"+B+"*(?:([+-]|)"+B+"*(\\d+)|))"+B+"*\\)|)","i"),bool:new RegExp("^(?:"+I+")$","i"),needsContext:new RegExp("^"+B+"*[>+~]|:(even|odd|eq|gt|lt|nth|first|last)(?:\\("+B+"*((?:-\\d)?\\d*)"+B+"*\\)|)(?=[^-]|$)","i")},G=/^(?:input|select|textarea|button)$/i,q=/^h\d$/i,V=/^(?:#([\w-]+)|(\w+)|\.([\w-]+))$/,W=/[+~]/,Y=new RegExp("\\\\[\\da-fA-F]{1,6}"+B+"?|\\\\([^\\r\\n\\f])","g"),Q=function(e,t){var r="0x"+e.slice(1)-65536;return t||(r<0?String.fromCharCode(r+65536):String.fromCharCode(r>>10|55296,1023&r|56320))},Z=function(){ue()},X=he((function(e){return!0===e.disabled&&E(e,"fieldset")}),{dir:"parentNode",next:"legend"});try{y.apply(a=o.call(R.childNodes),R.childNodes),a[R.childNodes.length].nodeType}catch(e){y={apply:function(e,t){L.apply(e,o.call(t))},call:function(e){L.apply(e,o.call(arguments,1))}}}function J(e,t,r,n){var i,a,s,o,c,l,d,p=t&&t.ownerDocument,b=t?t.nodeType:9;if(r=r||[],"string"!=typeof e||!e||1!==b&&9!==b&&11!==b)return r;if(!n&&(ue(t),t=t||u,f)){if(11!==b&&(c=V.exec(e)))if(i=c[1]){if(9===b){if(!(s=t.getElementById(i)))return r;if(s.id===i)return y.call(r,s),r}else if(p&&(s=p.getElementById(i))&&J.contains(t,s)&&s.id===i)return y.call(r,s),r}else{if(c[2])return y.apply(r,t.getElementsByTagName(e)),r;if((i=c[3])&&t.getElementsByClassName)return y.apply(r,t.getElementsByClassName(i)),r}if(!(x[e+" "]||h&&h.test(e))){if(d=e,p=t,1===b&&(j.test(e)||N.test(e))){for((p=W.test(e)&&oe(t.parentNode)||t)==t&&g.scope||((o=t.getAttribute("id"))?o=S.escapeSelector(o):t.setAttribute("id",o=m)),a=(l=le(e)).length;a--;)l[a]=(o?"#"+o:":scope")+" "+fe(l[a]);d=l.join(",")}try{return y.apply(r,p.querySelectorAll(d)),r}catch(t){x(e,!0)}finally{o===m&&t.removeAttribute("id")}}}return be(e.replace(T,"$1"),t,r,n)}function ee(){var e=[];return function r(n,i){return e.push(n+" ")>t.cacheLength&&delete r[e.shift()],r[n+" "]=i}}function te(e){return e[m]=!0,e}function re(e){var t=u.createElement("fieldset");try{return!!e(t)}catch(e){return!1}finally{t.parentNode&&t.parentNode.removeChild(t),t=null}}function ne(e){return function(t){return E(t,"input")&&t.type===e}}function ie(e){return function(t){return(E(t,"input")||E(t,"button"))&&t.type===e}}function ae(e){return function(t){return"form"in t?t.parentNode&&!1===t.disabled?"label"in t?"label"in t.parentNode?t.parentNode.disabled===e:t.disabled===e:t.isDisabled===e||t.isDisabled!==!e&&X(t)===e:t.disabled===e:"label"in t&&t.disabled===e}}function se(e){return te((function(t){return t=+t,te((function(r,n){for(var i,a=e([],r.length,t),s=a.length;s--;)r[i=a[s]]&&(r[i]=!(n[i]=r[i]))}))}))}function oe(e){return e&&void 0!==e.getElementsByTagName&&e}function ue(e){var r,n=e?e.ownerDocument||e:R;return n!=u&&9===n.nodeType&&n.documentElement?(c=(u=n).documentElement,f=!S.isXMLDoc(u),p=c.matches||c.webkitMatchesSelector||c.msMatchesSelector,c.msMatchesSelector&&R!=u&&(r=u.defaultView)&&r.top!==r&&r.addEventListener("unload",Z),g.getById=re((function(e){return c.appendChild(e).id=S.expando,!u.getElementsByName||!u.getElementsByName(S.expando).length})),g.disconnectedMatch=re((function(e){return p.call(e,"*")})),g.scope=re((function(){return u.querySelectorAll(":scope")})),g.cssHas=re((function(){try{return u.querySelector(":has(*,:jqfake)"),!1}catch(e){return!0}})),g.getById?(t.filter.ID=function(e){var t=e.replace(Y,Q);return function(e){return e.getAttribute("id")===t}},t.find.ID=function(e,t){if(void 0!==t.getElementById&&f){var r=t.getElementById(e);return r?[r]:[]}}):(t.filter.ID=function(e){var t=e.replace(Y,Q);return function(e){var r=void 0!==e.getAttributeNode&&e.getAttributeNode("id");return r&&r.value===t}},t.find.ID=function(e,t){if(void 0!==t.getElementById&&f){var r,n,i,a=t.getElementById(e);if(a){if((r=a.getAttributeNode("id"))&&r.value===e)return[a];for(i=t.getElementsByName(e),n=0;a=i[n++];)if((r=a.getAttributeNode("id"))&&r.value===e)return[a]}return[]}}),t.find.TAG=function(e,t){return void 0!==t.getElementsByTagName?t.getElementsByTagName(e):t.querySelectorAll(e)},t.find.CLASS=function(e,t){if(void 0!==t.getElementsByClassName&&f)return t.getElementsByClassName(e)},h=[],re((function(e){var t;c.appendChild(e).innerHTML="",e.querySelectorAll("[selected]").length||h.push("\\["+B+"*(?:value|"+I+")"),e.querySelectorAll("[id~="+m+"-]").length||h.push("~="),e.querySelectorAll("a#"+m+"+*").length||h.push(".#.+[+~]"),e.querySelectorAll(":checked").length||h.push(":checked"),(t=u.createElement("input")).setAttribute("type","hidden"),e.appendChild(t).setAttribute("name","D"),c.appendChild(e).disabled=!0,2!==e.querySelectorAll(":disabled").length&&h.push(":enabled",":disabled"),(t=u.createElement("input")).setAttribute("name",""),e.appendChild(t),e.querySelectorAll("[name='']").length||h.push("\\["+B+"*name"+B+"*="+B+"*(?:''|\"\")")})),g.cssHas||h.push(":has"),h=h.length&&new RegExp(h.join("|")),A=function(e,t){if(e===t)return s=!0,0;var r=!e.compareDocumentPosition-!t.compareDocumentPosition;return r||(1&(r=(e.ownerDocument||e)==(t.ownerDocument||t)?e.compareDocumentPosition(t):1)||!g.sortDetached&&t.compareDocumentPosition(e)===r?e===u||e.ownerDocument==R&&J.contains(R,e)?-1:t===u||t.ownerDocument==R&&J.contains(R,t)?1:i?l.call(i,e)-l.call(i,t):0:4&r?-1:1)},u):u}for(e in J.matches=function(e,t){return J(e,null,null,t)},J.matchesSelector=function(e,t){if(ue(e),f&&!x[t+" "]&&(!h||!h.test(t)))try{var r=p.call(e,t);if(r||g.disconnectedMatch||e.document&&11!==e.document.nodeType)return r}catch(e){x(t,!0)}return J(t,u,null,[e]).length>0},J.contains=function(e,t){return(e.ownerDocument||e)!=u&&ue(e),S.contains(e,t)},J.attr=function(e,r){(e.ownerDocument||e)!=u&&ue(e);var n=t.attrHandle[r.toLowerCase()],i=n&&d.call(t.attrHandle,r.toLowerCase())?n(e,r,!f):void 0;return void 0!==i?i:e.getAttribute(r)},J.error=function(e){throw new Error("Syntax error, unrecognized expression: "+e)},S.uniqueSort=function(e){var t,r=[],n=0,a=0;if(s=!g.sortStable,i=!g.sortStable&&o.call(e,0),D.call(e,A),s){for(;t=e[a++];)t===e[a]&&(n=r.push(a));for(;n--;)P.call(e,r[n],1)}return i=null,e},S.fn.uniqueSort=function(){return this.pushStack(S.uniqueSort(o.apply(this)))},(t=S.expr={cacheLength:50,createPseudo:te,match:z,attrHandle:{},find:{},relative:{">":{dir:"parentNode",first:!0}," ":{dir:"parentNode"},"+":{dir:"previousSibling",first:!0},"~":{dir:"previousSibling"}},preFilter:{ATTR:function(e){return e[1]=e[1].replace(Y,Q),e[3]=(e[3]||e[4]||e[5]||"").replace(Y,Q),"~="===e[2]&&(e[3]=" "+e[3]+" "),e.slice(0,4)},CHILD:function(e){return e[1]=e[1].toLowerCase(),"nth"===e[1].slice(0,3)?(e[3]||J.error(e[0]),e[4]=+(e[4]?e[5]+(e[6]||1):2*("even"===e[3]||"odd"===e[3])),e[5]=+(e[7]+e[8]||"odd"===e[3])):e[3]&&J.error(e[0]),e},PSEUDO:function(e){var t,r=!e[6]&&e[2];return z.CHILD.test(e[0])?null:(e[3]?e[2]=e[4]||e[5]||"":r&&H.test(r)&&(t=le(r,!0))&&(t=r.indexOf(")",r.length-t)-r.length)&&(e[0]=e[0].slice(0,t),e[2]=r.slice(0,t)),e.slice(0,3))}},filter:{TAG:function(e){var t=e.replace(Y,Q).toLowerCase();return"*"===e?function(){return!0}:function(e){return E(e,t)}},CLASS:function(e){var t=_[e+" "];return t||(t=new RegExp("(^|"+B+")"+e+"("+B+"|$)"))&&_(e,(function(e){return t.test("string"==typeof e.className&&e.className||void 0!==e.getAttribute&&e.getAttribute("class")||"")}))},ATTR:function(e,t,r){return function(n){var i=J.attr(n,e);return null==i?"!="===t:!t||(i+="","="===t?i===r:"!="===t?i!==r:"^="===t?r&&0===i.indexOf(r):"*="===t?r&&i.indexOf(r)>-1:"$="===t?r&&i.slice(-r.length)===r:"~="===t?(" "+i.replace(K," ")+" ").indexOf(r)>-1:"|="===t&&(i===r||i.slice(0,r.length+1)===r+"-"))}},CHILD:function(e,t,r,n,i){var a="nth"!==e.slice(0,3),s="last"!==e.slice(-4),o="of-type"===t;return 1===n&&0===i?function(e){return!!e.parentNode}:function(t,r,u){var c,l,f,h,d,p=a!==s?"nextSibling":"previousSibling",y=t.parentNode,g=o&&t.nodeName.toLowerCase(),v=!u&&!o,_=!1;if(y){if(a){for(;p;){for(f=t;f=f[p];)if(o?E(f,g):1===f.nodeType)return!1;d=p="only"===e&&!d&&"nextSibling"}return!0}if(d=[s?y.firstChild:y.lastChild],s&&v){for(_=(h=(c=(l=y[m]||(y[m]={}))[e]||[])[0]===b&&c[1])&&c[2],f=h&&y.childNodes[h];f=++h&&f&&f[p]||(_=h=0)||d.pop();)if(1===f.nodeType&&++_&&f===t){l[e]=[b,h,_];break}}else if(v&&(_=h=(c=(l=t[m]||(t[m]={}))[e]||[])[0]===b&&c[1]),!1===_)for(;(f=++h&&f&&f[p]||(_=h=0)||d.pop())&&(!(o?E(f,g):1===f.nodeType)||!++_||(v&&((l=f[m]||(f[m]={}))[e]=[b,_]),f!==t)););return(_-=i)===n||_%n==0&&_/n>=0}}},PSEUDO:function(e,r){var n,i=t.pseudos[e]||t.setFilters[e.toLowerCase()]||J.error("unsupported pseudo: "+e);return i[m]?i(r):i.length>1?(n=[e,e,"",r],t.setFilters.hasOwnProperty(e.toLowerCase())?te((function(e,t){for(var n,a=i(e,r),s=a.length;s--;)e[n=l.call(e,a[s])]=!(t[n]=a[s])})):function(e){return i(e,0,n)}):i}},pseudos:{not:te((function(e){var t=[],r=[],n=me(e.replace(T,"$1"));return n[m]?te((function(e,t,r,i){for(var a,s=n(e,null,i,[]),o=e.length;o--;)(a=s[o])&&(e[o]=!(t[o]=a))})):function(e,i,a){return t[0]=e,n(t,null,a,r),t[0]=null,!r.pop()}})),has:te((function(e){return function(t){return J(e,t).length>0}})),contains:te((function(e){return e=e.replace(Y,Q),function(t){return(t.textContent||S.text(t)).indexOf(e)>-1}})),lang:te((function(e){return $.test(e||"")||J.error("unsupported lang: "+e),e=e.replace(Y,Q).toLowerCase(),function(t){var r;do{if(r=f?t.lang:t.getAttribute("xml:lang")||t.getAttribute("lang"))return(r=r.toLowerCase())===e||0===r.indexOf(e+"-")}while((t=t.parentNode)&&1===t.nodeType);return!1}})),target:function(e){var t=r.location&&r.location.hash;return t&&t.slice(1)===e.id},root:function(e){return e===c},focus:function(e){return e===function(){try{return u.activeElement}catch(e){}}()&&u.hasFocus()&&!!(e.type||e.href||~e.tabIndex)},enabled:ae(!1),disabled:ae(!0),checked:function(e){return E(e,"input")&&!!e.checked||E(e,"option")&&!!e.selected},selected:function(e){return e.parentNode&&e.parentNode.selectedIndex,!0===e.selected},empty:function(e){for(e=e.firstChild;e;e=e.nextSibling)if(e.nodeType<6)return!1;return!0},parent:function(e){return!t.pseudos.empty(e)},header:function(e){return q.test(e.nodeName)},input:function(e){return G.test(e.nodeName)},button:function(e){return E(e,"input")&&"button"===e.type||E(e,"button")},text:function(e){var t;return E(e,"input")&&"text"===e.type&&(null==(t=e.getAttribute("type"))||"text"===t.toLowerCase())},first:se((function(){return[0]})),last:se((function(e,t){return[t-1]})),eq:se((function(e,t,r){return[r<0?r+t:r]})),even:se((function(e,t){for(var r=0;rt?t:r;--n>=0;)e.push(n);return e})),gt:se((function(e,t,r){for(var n=r<0?r+t:r;++n1?function(t,r,n){for(var i=e.length;i--;)if(!e[i](t,r,n))return!1;return!0}:e[0]}function pe(e,t,r,n,i){for(var a,s=[],o=0,u=e.length,c=null!=t;o-1&&(a[c]=!(s[c]=h))}}else d=pe(d===s?d.splice(m,d.length):d),i?i(null,s,d,u):y.apply(s,d)}))}function ge(e){for(var r,i,a,s=e.length,o=t.relative[e[0].type],u=o||t.relative[" "],c=o?1:0,f=he((function(e){return e===r}),u,!0),h=he((function(e){return l.call(r,e)>-1}),u,!0),d=[function(e,t,i){var a=!o&&(i||t!=n)||((r=t).nodeType?f(e,t,i):h(e,t,i));return r=null,a}];c1&&de(d),c>1&&fe(e.slice(0,c-1).concat({value:" "===e[c-2].type?"*":""})).replace(T,"$1"),i,c0,a=e.length>0,s=function(s,o,c,l,h){var d,p,g,m=0,v="0",_=s&&[],w=[],k=n,x=s||a&&t.find.TAG("*",h),A=b+=null==k?1:Math.random()||.1,E=x.length;for(h&&(n=o==u||o||h);v!==E&&null!=(d=x[v]);v++){if(a&&d){for(p=0,o||d.ownerDocument==u||(ue(d),c=!f);g=e[p++];)if(g(d,o||u,c)){y.call(l,d);break}h&&(b=A)}i&&((d=!g&&d)&&m--,s&&_.push(d))}if(m+=v,i&&v!==m){for(p=0;g=r[p++];)g(_,w,o,c);if(s){if(m>0)for(;v--;)_[v]||w[v]||(w[v]=C.call(l));w=pe(w)}y.apply(l,w),h&&!s&&w.length>0&&m+r.length>1&&S.uniqueSort(l)}return h&&(b=A,n=k),_};return i?te(s):s}(s,a))).selector=e}return o}function be(e,r,n,i){var a,s,o,u,c,l="function"==typeof e&&e,h=!i&&le(e=l.selector||e);if(n=n||[],1===h.length){if((s=h[0]=h[0].slice(0)).length>2&&"ID"===(o=s[0]).type&&9===r.nodeType&&f&&t.relative[s[1].type]){if(!(r=(t.find.ID(o.matches[0].replace(Y,Q),r)||[])[0]))return n;l&&(r=r.parentNode),e=e.slice(s.shift().value.length)}for(a=z.needsContext.test(e)?0:s.length;a--&&(o=s[a],!t.relative[u=o.type]);)if((c=t.find[u])&&(i=c(o.matches[0].replace(Y,Q),W.test(s[0].type)&&oe(r.parentNode)||r))){if(s.splice(a,1),!(e=i.length&&fe(s)))return y.apply(n,i),n;break}}return(l||me(e,h))(i,r,!f,n,!r||W.test(e)&&oe(r.parentNode)||r),n}ce.prototype=t.filters=t.pseudos,t.setFilters=new ce,g.sortStable=m.split("").sort(A).join("")===m,ue(),g.sortDetached=re((function(e){return 1&e.compareDocumentPosition(u.createElement("fieldset"))})),S.find=J,S.expr[":"]=S.expr.pseudos,S.unique=S.uniqueSort,J.compile=me,J.select=be,J.setDocument=ue,J.tokenize=le,J.escape=S.escapeSelector,J.getText=S.text,J.isXML=S.isXMLDoc,J.selectors=S.expr,J.support=S.support,J.uniqueSort=S.uniqueSort}();var O=function(e,t,r){for(var n=[],i=void 0!==r;(e=e[t])&&9!==e.nodeType;)if(1===e.nodeType){if(i&&S(e).is(r))break;n.push(e)}return n},U=function(e,t){for(var r=[];e;e=e.nextSibling)1===e.nodeType&&e!==t&&r.push(e);return r},K=S.expr.match.needsContext,F=/^<([a-z][^\/\0>:\x20\t\r\n\f]*)[\x20\t\r\n\f]*\/?>(?:<\/\1>|)$/i;function N(e,t,r){return m(t)?S.grep(e,(function(e,n){return!!t.call(e,n,e)!==r})):t.nodeType?S.grep(e,(function(e){return e===t!==r})):"string"!=typeof t?S.grep(e,(function(e){return l.call(t,e)>-1!==r})):S.filter(t,e,r)}S.filter=function(e,t,r){var n=t[0];return r&&(e=":not("+e+")"),1===t.length&&1===n.nodeType?S.find.matchesSelector(n,e)?[n]:[]:S.find.matches(e,S.grep(t,(function(e){return 1===e.nodeType})))},S.fn.extend({find:function(e){var t,r,n=this.length,i=this;if("string"!=typeof e)return this.pushStack(S(e).filter((function(){for(t=0;t1?S.uniqueSort(r):r},filter:function(e){return this.pushStack(N(this,e||[],!1))},not:function(e){return this.pushStack(N(this,e||[],!0))},is:function(e){return!!N(this,"string"==typeof e&&K.test(e)?S(e):e||[],!1).length}});var j,H=/^(?:\s*(<[\w\W]+>)[^>]*|#([\w-]+))$/;(S.fn.init=function(e,t,r){var n,i;if(!e)return this;if(r=r||j,"string"==typeof e){if(!(n="<"===e[0]&&">"===e[e.length-1]&&e.length>=3?[null,e,null]:H.exec(e))||!n[1]&&t)return!t||t.jquery?(t||r).find(e):this.constructor(t).find(e);if(n[1]){if(t=t instanceof S?t[0]:t,S.merge(this,S.parseHTML(n[1],t&&t.nodeType?t.ownerDocument||t:v,!0)),F.test(n[1])&&S.isPlainObject(t))for(n in t)m(this[n])?this[n](t[n]):this.attr(n,t[n]);return this}return(i=v.getElementById(n[2]))&&(this[0]=i,this.length=1),this}return e.nodeType?(this[0]=e,this.length=1,this):m(e)?void 0!==r.ready?r.ready(e):e(S):S.makeArray(e,this)}).prototype=S.fn,j=S(v);var $=/^(?:parents|prev(?:Until|All))/,z={children:!0,contents:!0,next:!0,prev:!0};function G(e,t){for(;(e=e[t])&&1!==e.nodeType;);return e}S.fn.extend({has:function(e){var t=S(e,this),r=t.length;return this.filter((function(){for(var e=0;e-1:1===r.nodeType&&S.find.matchesSelector(r,e))){a.push(r);break}return this.pushStack(a.length>1?S.uniqueSort(a):a)},index:function(e){return e?"string"==typeof e?l.call(S(e),this[0]):l.call(this,e.jquery?e[0]:e):this[0]&&this[0].parentNode?this.first().prevAll().length:-1},add:function(e,t){return this.pushStack(S.uniqueSort(S.merge(this.get(),S(e,t))))},addBack:function(e){return this.add(null==e?this.prevObject:this.prevObject.filter(e))}}),S.each({parent:function(e){var t=e.parentNode;return t&&11!==t.nodeType?t:null},parents:function(e){return O(e,"parentNode")},parentsUntil:function(e,t,r){return O(e,"parentNode",r)},next:function(e){return G(e,"nextSibling")},prev:function(e){return G(e,"previousSibling")},nextAll:function(e){return O(e,"nextSibling")},prevAll:function(e){return O(e,"previousSibling")},nextUntil:function(e,t,r){return O(e,"nextSibling",r)},prevUntil:function(e,t,r){return O(e,"previousSibling",r)},siblings:function(e){return U((e.parentNode||{}).firstChild,e)},children:function(e){return U(e.firstChild)},contents:function(e){return null!=e.contentDocument&&s(e.contentDocument)?e.contentDocument:(E(e,"template")&&(e=e.content||e),S.merge([],e.childNodes))}},(function(e,t){S.fn[e]=function(r,n){var i=S.map(this,t,r);return"Until"!==e.slice(-5)&&(n=r),n&&"string"==typeof n&&(i=S.filter(n,i)),this.length>1&&(z[e]||S.uniqueSort(i),$.test(e)&&i.reverse()),this.pushStack(i)}}));var q=/[^\x20\t\r\n\f]+/g;function V(e){return e}function W(e){throw e}function Y(e,t,r,n){var i;try{e&&m(i=e.promise)?i.call(e).done(t).fail(r):e&&m(i=e.then)?i.call(e,t,r):t.apply(void 0,[e].slice(n))}catch(e){r.apply(void 0,[e])}}S.Callbacks=function(e){e="string"==typeof e?function(e){var t={};return S.each(e.match(q)||[],(function(e,r){t[r]=!0})),t}(e):S.extend({},e);var t,r,n,i,a=[],s=[],o=-1,u=function(){for(i=i||e.once,n=t=!0;s.length;o=-1)for(r=s.shift();++o-1;)a.splice(r,1),r<=o&&o--})),this},has:function(e){return e?S.inArray(e,a)>-1:a.length>0},empty:function(){return a&&(a=[]),this},disable:function(){return i=s=[],a=r="",this},disabled:function(){return!a},lock:function(){return i=s=[],r||t||(a=r=""),this},locked:function(){return!!i},fireWith:function(e,r){return i||(r=[e,(r=r||[]).slice?r.slice():r],s.push(r),t||u()),this},fire:function(){return c.fireWith(this,arguments),this},fired:function(){return!!n}};return c},S.extend({Deferred:function(e){var t=[["notify","progress",S.Callbacks("memory"),S.Callbacks("memory"),2],["resolve","done",S.Callbacks("once memory"),S.Callbacks("once memory"),0,"resolved"],["reject","fail",S.Callbacks("once memory"),S.Callbacks("once memory"),1,"rejected"]],n="pending",i={state:function(){return n},always:function(){return a.done(arguments).fail(arguments),this},catch:function(e){return i.then(null,e)},pipe:function(){var e=arguments;return S.Deferred((function(r){S.each(t,(function(t,n){var i=m(e[n[4]])&&e[n[4]];a[n[1]]((function(){var e=i&&i.apply(this,arguments);e&&m(e.promise)?e.promise().progress(r.notify).done(r.resolve).fail(r.reject):r[n[0]+"With"](this,i?[e]:arguments)}))})),e=null})).promise()},then:function(e,n,i){var a=0;function s(e,t,n,i){return function(){var o=this,u=arguments,c=function(){var r,c;if(!(e=a&&(n!==W&&(o=void 0,u=[r]),t.rejectWith(o,u))}};e?l():(S.Deferred.getErrorHook?l.error=S.Deferred.getErrorHook():S.Deferred.getStackHook&&(l.error=S.Deferred.getStackHook()),r.setTimeout(l))}}return S.Deferred((function(r){t[0][3].add(s(0,r,m(i)?i:V,r.notifyWith)),t[1][3].add(s(0,r,m(e)?e:V)),t[2][3].add(s(0,r,m(n)?n:W))})).promise()},promise:function(e){return null!=e?S.extend(e,i):i}},a={};return S.each(t,(function(e,r){var s=r[2],o=r[5];i[r[1]]=s.add,o&&s.add((function(){n=o}),t[3-e][2].disable,t[3-e][3].disable,t[0][2].lock,t[0][3].lock),s.add(r[3].fire),a[r[0]]=function(){return a[r[0]+"With"](this===a?void 0:this,arguments),this},a[r[0]+"With"]=s.fireWith})),i.promise(a),e&&e.call(a,a),a},when:function(e){var t=arguments.length,r=t,n=Array(r),i=o.call(arguments),a=S.Deferred(),s=function(e){return function(r){n[e]=this,i[e]=arguments.length>1?o.call(arguments):r,--t||a.resolveWith(n,i)}};if(t<=1&&(Y(e,a.done(s(r)).resolve,a.reject,!t),"pending"===a.state()||m(i[r]&&i[r].then)))return a.then();for(;r--;)Y(i[r],s(r),a.reject);return a.promise()}});var Q=/^(Eval|Internal|Range|Reference|Syntax|Type|URI)Error$/;S.Deferred.exceptionHook=function(e,t){r.console&&r.console.warn&&e&&Q.test(e.name)&&r.console.warn("jQuery.Deferred exception: "+e.message,e.stack,t)},S.readyException=function(e){r.setTimeout((function(){throw e}))};var Z=S.Deferred();function X(){v.removeEventListener("DOMContentLoaded",X),r.removeEventListener("load",X),S.ready()}S.fn.ready=function(e){return Z.then(e).catch((function(e){S.readyException(e)})),this},S.extend({isReady:!1,readyWait:1,ready:function(e){(!0===e?--S.readyWait:S.isReady)||(S.isReady=!0,!0!==e&&--S.readyWait>0||Z.resolveWith(v,[S]))}}),S.ready.then=Z.then,"complete"===v.readyState||"loading"!==v.readyState&&!v.documentElement.doScroll?r.setTimeout(S.ready):(v.addEventListener("DOMContentLoaded",X),r.addEventListener("load",X));var J=function(e,t,r,n,i,a,s){var o=0,u=e.length,c=null==r;if("object"===k(r))for(o in i=!0,r)J(e,t,o,r[o],!0,a,s);else if(void 0!==n&&(i=!0,m(n)||(s=!0),c&&(s?(t.call(e,n),t=null):(c=t,t=function(e,t,r){return c.call(S(e),r)})),t))for(;o1,null,!0)},removeData:function(e){return this.each((function(){oe.remove(this,e)}))}}),S.extend({queue:function(e,t,r){var n;if(e)return t=(t||"fx")+"queue",n=se.get(e,t),r&&(!n||Array.isArray(r)?n=se.access(e,t,S.makeArray(r)):n.push(r)),n||[]},dequeue:function(e,t){t=t||"fx";var r=S.queue(e,t),n=r.length,i=r.shift(),a=S._queueHooks(e,t);"inprogress"===i&&(i=r.shift(),n--),i&&("fx"===t&&r.unshift("inprogress"),delete a.stop,i.call(e,(function(){S.dequeue(e,t)}),a)),!n&&a&&a.empty.fire()},_queueHooks:function(e,t){var r=t+"queueHooks";return se.get(e,r)||se.access(e,r,{empty:S.Callbacks("once memory").add((function(){se.remove(e,[t+"queue",r])}))})}}),S.fn.extend({queue:function(e,t){var r=2;return"string"!=typeof e&&(t=e,e="fx",r--),arguments.length\x20\t\r\n\f]*)/i,Ee=/^$|^module$|\/(?:java|ecma)script/i;ke=v.createDocumentFragment().appendChild(v.createElement("div")),(xe=v.createElement("input")).setAttribute("type","radio"),xe.setAttribute("checked","checked"),xe.setAttribute("name","t"),ke.appendChild(xe),g.checkClone=ke.cloneNode(!0).cloneNode(!0).lastChild.checked,ke.innerHTML="",g.noCloneChecked=!!ke.cloneNode(!0).lastChild.defaultValue,ke.innerHTML="",g.option=!!ke.lastChild;var Ce={thead:[1,"","
"],col:[2,"","
"],tr:[2,"","
"],td:[3,"","
"],_default:[0,"",""]};function De(e,t){var r;return r=void 0!==e.getElementsByTagName?e.getElementsByTagName(t||"*"):void 0!==e.querySelectorAll?e.querySelectorAll(t||"*"):[],void 0===t||t&&E(e,t)?S.merge([e],r):r}function Pe(e,t){for(var r=0,n=e.length;r",""]);var Be=/<|&#?\w+;/;function Te(e,t,r,n,i){for(var a,s,o,u,c,l,f=t.createDocumentFragment(),h=[],d=0,p=e.length;d-1)i&&i.push(a);else if(c=ye(a),s=De(f.appendChild(a),"script"),c&&Pe(s),r)for(l=0;a=s[l++];)Ee.test(a.type||"")&&r.push(a);return f}var Ie=/^([^.]*)(?:\.(.+)|)/;function Me(){return!0}function Re(){return!1}function Le(e,t,r,n,i,a){var s,o;if("object"==typeof t){for(o in"string"!=typeof r&&(n=n||r,r=void 0),t)Le(e,o,r,n,t[o],a);return e}if(null==n&&null==i?(i=r,n=r=void 0):null==i&&("string"==typeof r?(i=n,n=void 0):(i=n,n=r,r=void 0)),!1===i)i=Re;else if(!i)return e;return 1===a&&(s=i,(i=function(e){return S().off(e),s.apply(this,arguments)}).guid=s.guid||(s.guid=S.guid++)),e.each((function(){S.event.add(this,t,i,n,r)}))}function Oe(e,t,r){r?(se.set(e,t,!1),S.event.add(e,t,{namespace:!1,handler:function(e){var r,n=se.get(this,t);if(1&e.isTrigger&&this[t]){if(n)(S.event.special[t]||{}).delegateType&&e.stopPropagation();else if(n=o.call(arguments),se.set(this,t,n),this[t](),r=se.get(this,t),se.set(this,t,!1),n!==r)return e.stopImmediatePropagation(),e.preventDefault(),r}else n&&(se.set(this,t,S.event.trigger(n[0],n.slice(1),this)),e.stopPropagation(),e.isImmediatePropagationStopped=Me)}})):void 0===se.get(e,t)&&S.event.add(e,t,Me)}S.event={global:{},add:function(e,t,r,n,i){var a,s,o,u,c,l,f,h,d,p,y,g=se.get(e);if(ie(e))for(r.handler&&(r=(a=r).handler,i=a.selector),i&&S.find.matchesSelector(pe,i),r.guid||(r.guid=S.guid++),(u=g.events)||(u=g.events=Object.create(null)),(s=g.handle)||(s=g.handle=function(t){return void 0!==S&&S.event.triggered!==t.type?S.event.dispatch.apply(e,arguments):void 0}),c=(t=(t||"").match(q)||[""]).length;c--;)d=y=(o=Ie.exec(t[c])||[])[1],p=(o[2]||"").split(".").sort(),d&&(f=S.event.special[d]||{},d=(i?f.delegateType:f.bindType)||d,f=S.event.special[d]||{},l=S.extend({type:d,origType:y,data:n,handler:r,guid:r.guid,selector:i,needsContext:i&&S.expr.match.needsContext.test(i),namespace:p.join(".")},a),(h=u[d])||((h=u[d]=[]).delegateCount=0,f.setup&&!1!==f.setup.call(e,n,p,s)||e.addEventListener&&e.addEventListener(d,s)),f.add&&(f.add.call(e,l),l.handler.guid||(l.handler.guid=r.guid)),i?h.splice(h.delegateCount++,0,l):h.push(l),S.event.global[d]=!0)},remove:function(e,t,r,n,i){var a,s,o,u,c,l,f,h,d,p,y,g=se.hasData(e)&&se.get(e);if(g&&(u=g.events)){for(c=(t=(t||"").match(q)||[""]).length;c--;)if(d=y=(o=Ie.exec(t[c])||[])[1],p=(o[2]||"").split(".").sort(),d){for(f=S.event.special[d]||{},h=u[d=(n?f.delegateType:f.bindType)||d]||[],o=o[2]&&new RegExp("(^|\\.)"+p.join("\\.(?:.*\\.|)")+"(\\.|$)"),s=a=h.length;a--;)l=h[a],!i&&y!==l.origType||r&&r.guid!==l.guid||o&&!o.test(l.namespace)||n&&n!==l.selector&&("**"!==n||!l.selector)||(h.splice(a,1),l.selector&&h.delegateCount--,f.remove&&f.remove.call(e,l));s&&!h.length&&(f.teardown&&!1!==f.teardown.call(e,p,g.handle)||S.removeEvent(e,d,g.handle),delete u[d])}else for(d in u)S.event.remove(e,d+t[c],r,n,!0);S.isEmptyObject(u)&&se.remove(e,"handle events")}},dispatch:function(e){var t,r,n,i,a,s,o=new Array(arguments.length),u=S.event.fix(e),c=(se.get(this,"events")||Object.create(null))[u.type]||[],l=S.event.special[u.type]||{};for(o[0]=u,t=1;t=1))for(;c!==this;c=c.parentNode||this)if(1===c.nodeType&&("click"!==e.type||!0!==c.disabled)){for(a=[],s={},r=0;r-1:S.find(i,this,null,[c]).length),s[i]&&a.push(n);a.length&&o.push({elem:c,handlers:a})}return c=this,u\s*$/g;function Ne(e,t){return E(e,"table")&&E(11!==t.nodeType?t:t.firstChild,"tr")&&S(e).children("tbody")[0]||e}function je(e){return e.type=(null!==e.getAttribute("type"))+"/"+e.type,e}function He(e){return"true/"===(e.type||"").slice(0,5)?e.type=e.type.slice(5):e.removeAttribute("type"),e}function $e(e,t){var r,n,i,a,s,o;if(1===t.nodeType){if(se.hasData(e)&&(o=se.get(e).events))for(i in se.remove(t,"handle events"),o)for(r=0,n=o[i].length;r1&&"string"==typeof p&&!g.checkClone&&Ke.test(p))return e.each((function(i){var a=e.eq(i);y&&(t[0]=p.call(this,i,a.html())),Ge(a,t,r,n)}));if(h&&(a=(i=Te(t,e[0].ownerDocument,!1,e,n)).firstChild,1===i.childNodes.length&&(i=a),a||n)){for(o=(s=S.map(De(i,"script"),je)).length;f0&&Pe(s,!u&&De(e,"script")),o},cleanData:function(e){for(var t,r,n,i=S.event.special,a=0;void 0!==(r=e[a]);a++)if(ie(r)){if(t=r[se.expando]){if(t.events)for(n in t.events)i[n]?S.event.remove(r,n):S.removeEvent(r,n,t.handle);r[se.expando]=void 0}r[oe.expando]&&(r[oe.expando]=void 0)}}}),S.fn.extend({detach:function(e){return qe(this,e,!0)},remove:function(e){return qe(this,e)},text:function(e){return J(this,(function(e){return void 0===e?S.text(this):this.empty().each((function(){1!==this.nodeType&&11!==this.nodeType&&9!==this.nodeType||(this.textContent=e)}))}),null,e,arguments.length)},append:function(){return Ge(this,arguments,(function(e){1!==this.nodeType&&11!==this.nodeType&&9!==this.nodeType||Ne(this,e).appendChild(e)}))},prepend:function(){return Ge(this,arguments,(function(e){if(1===this.nodeType||11===this.nodeType||9===this.nodeType){var t=Ne(this,e);t.insertBefore(e,t.firstChild)}}))},before:function(){return Ge(this,arguments,(function(e){this.parentNode&&this.parentNode.insertBefore(e,this)}))},after:function(){return Ge(this,arguments,(function(e){this.parentNode&&this.parentNode.insertBefore(e,this.nextSibling)}))},empty:function(){for(var e,t=0;null!=(e=this[t]);t++)1===e.nodeType&&(S.cleanData(De(e,!1)),e.textContent="");return this},clone:function(e,t){return e=null!=e&&e,t=null==t?e:t,this.map((function(){return S.clone(this,e,t)}))},html:function(e){return J(this,(function(e){var t=this[0]||{},r=0,n=this.length;if(void 0===e&&1===t.nodeType)return t.innerHTML;if("string"==typeof e&&!Ue.test(e)&&!Ce[(Ae.exec(e)||["",""])[1].toLowerCase()]){e=S.htmlPrefilter(e);try{for(;r=0&&(u+=Math.max(0,Math.ceil(e["offset"+t[0].toUpperCase()+t.slice(1)]-a-u-o-.5))||0),u+c}function ct(e,t,r){var n=Ye(e),i=(!g.boxSizingReliable()||r)&&"border-box"===S.css(e,"boxSizing",!1,n),a=i,s=Xe(e,t,n),o="offset"+t[0].toUpperCase()+t.slice(1);if(Ve.test(s)){if(!r)return s;s="auto"}return(!g.boxSizingReliable()&&i||!g.reliableTrDimensions()&&E(e,"tr")||"auto"===s||!parseFloat(s)&&"inline"===S.css(e,"display",!1,n))&&e.getClientRects().length&&(i="border-box"===S.css(e,"boxSizing",!1,n),(a=o in e)&&(s=e[o])),(s=parseFloat(s)||0)+ut(e,t,r||(i?"border":"content"),a,n,s)+"px"}function lt(e,t,r,n,i){return new lt.prototype.init(e,t,r,n,i)}S.extend({cssHooks:{opacity:{get:function(e,t){if(t){var r=Xe(e,"opacity");return""===r?"1":r}}}},cssNumber:{animationIterationCount:!0,aspectRatio:!0,borderImageSlice:!0,columnCount:!0,flexGrow:!0,flexShrink:!0,fontWeight:!0,gridArea:!0,gridColumn:!0,gridColumnEnd:!0,gridColumnStart:!0,gridRow:!0,gridRowEnd:!0,gridRowStart:!0,lineHeight:!0,opacity:!0,order:!0,orphans:!0,scale:!0,widows:!0,zIndex:!0,zoom:!0,fillOpacity:!0,floodOpacity:!0,stopOpacity:!0,strokeMiterlimit:!0,strokeOpacity:!0},cssProps:{},style:function(e,t,r,n){if(e&&3!==e.nodeType&&8!==e.nodeType&&e.style){var i,a,s,o=ne(t),u=We.test(t),c=e.style;if(u||(t=nt(o)),s=S.cssHooks[t]||S.cssHooks[o],void 0===r)return s&&"get"in s&&void 0!==(i=s.get(e,!1,n))?i:c[t];"string"===(a=typeof r)&&(i=he.exec(r))&&i[1]&&(r=be(e,t,i),a="number"),null!=r&&r==r&&("number"!==a||u||(r+=i&&i[3]||(S.cssNumber[o]?"":"px")),g.clearCloneStyle||""!==r||0!==t.indexOf("background")||(c[t]="inherit"),s&&"set"in s&&void 0===(r=s.set(e,r,n))||(u?c.setProperty(t,r):c[t]=r))}},css:function(e,t,r,n){var i,a,s,o=ne(t);return We.test(t)||(t=nt(o)),(s=S.cssHooks[t]||S.cssHooks[o])&&"get"in s&&(i=s.get(e,!0,r)),void 0===i&&(i=Xe(e,t,n)),"normal"===i&&t in st&&(i=st[t]),""===r||r?(a=parseFloat(i),!0===r||isFinite(a)?a||0:i):i}}),S.each(["height","width"],(function(e,t){S.cssHooks[t]={get:function(e,r,n){if(r)return!it.test(S.css(e,"display"))||e.getClientRects().length&&e.getBoundingClientRect().width?ct(e,t,n):Qe(e,at,(function(){return ct(e,t,n)}))},set:function(e,r,n){var i,a=Ye(e),s=!g.scrollboxSize()&&"absolute"===a.position,o=(s||n)&&"border-box"===S.css(e,"boxSizing",!1,a),u=n?ut(e,t,n,o,a):0;return o&&s&&(u-=Math.ceil(e["offset"+t[0].toUpperCase()+t.slice(1)]-parseFloat(a[t])-ut(e,t,"border",!1,a)-.5)),u&&(i=he.exec(r))&&"px"!==(i[3]||"px")&&(e.style[t]=r,r=S.css(e,t)),ot(0,r,u)}}})),S.cssHooks.marginLeft=Je(g.reliableMarginLeft,(function(e,t){if(t)return(parseFloat(Xe(e,"marginLeft"))||e.getBoundingClientRect().left-Qe(e,{marginLeft:0},(function(){return e.getBoundingClientRect().left})))+"px"})),S.each({margin:"",padding:"",border:"Width"},(function(e,t){S.cssHooks[e+t]={expand:function(r){for(var n=0,i={},a="string"==typeof r?r.split(" "):[r];n<4;n++)i[e+de[n]+t]=a[n]||a[n-2]||a[0];return i}},"margin"!==e&&(S.cssHooks[e+t].set=ot)})),S.fn.extend({css:function(e,t){return J(this,(function(e,t,r){var n,i,a={},s=0;if(Array.isArray(t)){for(n=Ye(e),i=t.length;s1)}}),S.Tween=lt,lt.prototype={constructor:lt,init:function(e,t,r,n,i,a){this.elem=e,this.prop=r,this.easing=i||S.easing._default,this.options=t,this.start=this.now=this.cur(),this.end=n,this.unit=a||(S.cssNumber[r]?"":"px")},cur:function(){var e=lt.propHooks[this.prop];return e&&e.get?e.get(this):lt.propHooks._default.get(this)},run:function(e){var t,r=lt.propHooks[this.prop];return this.options.duration?this.pos=t=S.easing[this.easing](e,this.options.duration*e,0,1,this.options.duration):this.pos=t=e,this.now=(this.end-this.start)*t+this.start,this.options.step&&this.options.step.call(this.elem,this.now,this),r&&r.set?r.set(this):lt.propHooks._default.set(this),this}},lt.prototype.init.prototype=lt.prototype,lt.propHooks={_default:{get:function(e){var t;return 1!==e.elem.nodeType||null!=e.elem[e.prop]&&null==e.elem.style[e.prop]?e.elem[e.prop]:(t=S.css(e.elem,e.prop,""))&&"auto"!==t?t:0},set:function(e){S.fx.step[e.prop]?S.fx.step[e.prop](e):1!==e.elem.nodeType||!S.cssHooks[e.prop]&&null==e.elem.style[nt(e.prop)]?e.elem[e.prop]=e.now:S.style(e.elem,e.prop,e.now+e.unit)}}},lt.propHooks.scrollTop=lt.propHooks.scrollLeft={set:function(e){e.elem.nodeType&&e.elem.parentNode&&(e.elem[e.prop]=e.now)}},S.easing={linear:function(e){return e},swing:function(e){return.5-Math.cos(e*Math.PI)/2},_default:"swing"},S.fx=lt.prototype.init,S.fx.step={};var ft,ht,dt=/^(?:toggle|show|hide)$/,pt=/queueHooks$/;function yt(){ht&&(!1===v.hidden&&r.requestAnimationFrame?r.requestAnimationFrame(yt):r.setTimeout(yt,S.fx.interval),S.fx.tick())}function gt(){return r.setTimeout((function(){ft=void 0})),ft=Date.now()}function mt(e,t){var r,n=0,i={height:e};for(t=t?1:0;n<4;n+=2-t)i["margin"+(r=de[n])]=i["padding"+r]=e;return t&&(i.opacity=i.width=e),i}function bt(e,t,r){for(var n,i=(vt.tweeners[t]||[]).concat(vt.tweeners["*"]),a=0,s=i.length;a1)},removeAttr:function(e){return this.each((function(){S.removeAttr(this,e)}))}}),S.extend({attr:function(e,t,r){var n,i,a=e.nodeType;if(3!==a&&8!==a&&2!==a)return void 0===e.getAttribute?S.prop(e,t,r):(1===a&&S.isXMLDoc(e)||(i=S.attrHooks[t.toLowerCase()]||(S.expr.match.bool.test(t)?_t:void 0)),void 0!==r?null===r?void S.removeAttr(e,t):i&&"set"in i&&void 0!==(n=i.set(e,r,t))?n:(e.setAttribute(t,r+""),r):i&&"get"in i&&null!==(n=i.get(e,t))?n:null==(n=S.find.attr(e,t))?void 0:n)},attrHooks:{type:{set:function(e,t){if(!g.radioValue&&"radio"===t&&E(e,"input")){var r=e.value;return e.setAttribute("type",t),r&&(e.value=r),t}}}},removeAttr:function(e,t){var r,n=0,i=t&&t.match(q);if(i&&1===e.nodeType)for(;r=i[n++];)e.removeAttribute(r)}}),_t={set:function(e,t,r){return!1===t?S.removeAttr(e,r):e.setAttribute(r,r),r}},S.each(S.expr.match.bool.source.match(/\w+/g),(function(e,t){var r=wt[t]||S.find.attr;wt[t]=function(e,t,n){var i,a,s=t.toLowerCase();return n||(a=wt[s],wt[s]=i,i=null!=r(e,t,n)?s:null,wt[s]=a),i}}));var kt=/^(?:input|select|textarea|button)$/i,xt=/^(?:a|area)$/i;function St(e){return(e.match(q)||[]).join(" ")}function At(e){return e.getAttribute&&e.getAttribute("class")||""}function Et(e){return Array.isArray(e)?e:"string"==typeof e&&e.match(q)||[]}S.fn.extend({prop:function(e,t){return J(this,S.prop,e,t,arguments.length>1)},removeProp:function(e){return this.each((function(){delete this[S.propFix[e]||e]}))}}),S.extend({prop:function(e,t,r){var n,i,a=e.nodeType;if(3!==a&&8!==a&&2!==a)return 1===a&&S.isXMLDoc(e)||(t=S.propFix[t]||t,i=S.propHooks[t]),void 0!==r?i&&"set"in i&&void 0!==(n=i.set(e,r,t))?n:e[t]=r:i&&"get"in i&&null!==(n=i.get(e,t))?n:e[t]},propHooks:{tabIndex:{get:function(e){var t=S.find.attr(e,"tabindex");return t?parseInt(t,10):kt.test(e.nodeName)||xt.test(e.nodeName)&&e.href?0:-1}}},propFix:{for:"htmlFor",class:"className"}}),g.optSelected||(S.propHooks.selected={get:function(e){var t=e.parentNode;return t&&t.parentNode&&t.parentNode.selectedIndex,null},set:function(e){var t=e.parentNode;t&&(t.selectedIndex,t.parentNode&&t.parentNode.selectedIndex)}}),S.each(["tabIndex","readOnly","maxLength","cellSpacing","cellPadding","rowSpan","colSpan","useMap","frameBorder","contentEditable"],(function(){S.propFix[this.toLowerCase()]=this})),S.fn.extend({addClass:function(e){var t,r,n,i,a,s;return m(e)?this.each((function(t){S(this).addClass(e.call(this,t,At(this)))})):(t=Et(e)).length?this.each((function(){if(n=At(this),r=1===this.nodeType&&" "+St(n)+" "){for(a=0;a-1;)r=r.replace(" "+i+" "," ");s=St(r),n!==s&&this.setAttribute("class",s)}})):this:this.attr("class","")},toggleClass:function(e,t){var r,n,i,a,s=typeof e,o="string"===s||Array.isArray(e);return m(e)?this.each((function(r){S(this).toggleClass(e.call(this,r,At(this),t),t)})):"boolean"==typeof t&&o?t?this.addClass(e):this.removeClass(e):(r=Et(e),this.each((function(){if(o)for(a=S(this),i=0;i-1)return!0;return!1}});var Ct=/\r/g;S.fn.extend({val:function(e){var t,r,n,i=this[0];return arguments.length?(n=m(e),this.each((function(r){var i;1===this.nodeType&&(null==(i=n?e.call(this,r,S(this).val()):e)?i="":"number"==typeof i?i+="":Array.isArray(i)&&(i=S.map(i,(function(e){return null==e?"":e+""}))),(t=S.valHooks[this.type]||S.valHooks[this.nodeName.toLowerCase()])&&"set"in t&&void 0!==t.set(this,i,"value")||(this.value=i))}))):i?(t=S.valHooks[i.type]||S.valHooks[i.nodeName.toLowerCase()])&&"get"in t&&void 0!==(r=t.get(i,"value"))?r:"string"==typeof(r=i.value)?r.replace(Ct,""):null==r?"":r:void 0}}),S.extend({valHooks:{option:{get:function(e){var t=S.find.attr(e,"value");return null!=t?t:St(S.text(e))}},select:{get:function(e){var t,r,n,i=e.options,a=e.selectedIndex,s="select-one"===e.type,o=s?null:[],u=s?a+1:i.length;for(n=a<0?u:s?a:0;n-1)&&(r=!0);return r||(e.selectedIndex=-1),a}}}}),S.each(["radio","checkbox"],(function(){S.valHooks[this]={set:function(e,t){if(Array.isArray(t))return e.checked=S.inArray(S(e).val(),t)>-1}},g.checkOn||(S.valHooks[this].get=function(e){return null===e.getAttribute("value")?"on":e.value})}));var Dt=r.location,Pt={guid:Date.now()},Bt=/\?/;S.parseXML=function(e){var t,n;if(!e||"string"!=typeof e)return null;try{t=(new r.DOMParser).parseFromString(e,"text/xml")}catch(e){}return n=t&&t.getElementsByTagName("parsererror")[0],t&&!n||S.error("Invalid XML: "+(n?S.map(n.childNodes,(function(e){return e.textContent})).join("\n"):e)),t};var Tt=/^(?:focusinfocus|focusoutblur)$/,It=function(e){e.stopPropagation()};S.extend(S.event,{trigger:function(e,t,n,i){var a,s,o,u,c,l,f,h,p=[n||v],y=d.call(e,"type")?e.type:e,g=d.call(e,"namespace")?e.namespace.split("."):[];if(s=h=o=n=n||v,3!==n.nodeType&&8!==n.nodeType&&!Tt.test(y+S.event.triggered)&&(y.indexOf(".")>-1&&(g=y.split("."),y=g.shift(),g.sort()),c=y.indexOf(":")<0&&"on"+y,(e=e[S.expando]?e:new S.Event(y,"object"==typeof e&&e)).isTrigger=i?2:3,e.namespace=g.join("."),e.rnamespace=e.namespace?new RegExp("(^|\\.)"+g.join("\\.(?:.*\\.|)")+"(\\.|$)"):null,e.result=void 0,e.target||(e.target=n),t=null==t?[e]:S.makeArray(t,[e]),f=S.event.special[y]||{},i||!f.trigger||!1!==f.trigger.apply(n,t))){if(!i&&!f.noBubble&&!b(n)){for(u=f.delegateType||y,Tt.test(u+y)||(s=s.parentNode);s;s=s.parentNode)p.push(s),o=s;o===(n.ownerDocument||v)&&p.push(o.defaultView||o.parentWindow||r)}for(a=0;(s=p[a++])&&!e.isPropagationStopped();)h=s,e.type=a>1?u:f.bindType||y,(l=(se.get(s,"events")||Object.create(null))[e.type]&&se.get(s,"handle"))&&l.apply(s,t),(l=c&&s[c])&&l.apply&&ie(s)&&(e.result=l.apply(s,t),!1===e.result&&e.preventDefault());return e.type=y,i||e.isDefaultPrevented()||f._default&&!1!==f._default.apply(p.pop(),t)||!ie(n)||c&&m(n[y])&&!b(n)&&((o=n[c])&&(n[c]=null),S.event.triggered=y,e.isPropagationStopped()&&h.addEventListener(y,It),n[y](),e.isPropagationStopped()&&h.removeEventListener(y,It),S.event.triggered=void 0,o&&(n[c]=o)),e.result}},simulate:function(e,t,r){var n=S.extend(new S.Event,r,{type:e,isSimulated:!0});S.event.trigger(n,null,t)}}),S.fn.extend({trigger:function(e,t){return this.each((function(){S.event.trigger(e,t,this)}))},triggerHandler:function(e,t){var r=this[0];if(r)return S.event.trigger(e,t,r,!0)}});var Mt=/\[\]$/,Rt=/\r?\n/g,Lt=/^(?:submit|button|image|reset|file)$/i,Ot=/^(?:input|select|textarea|keygen)/i;function Ut(e,t,r,n){var i;if(Array.isArray(t))S.each(t,(function(t,i){r||Mt.test(e)?n(e,i):Ut(e+"["+("object"==typeof i&&null!=i?t:"")+"]",i,r,n)}));else if(r||"object"!==k(t))n(e,t);else for(i in t)Ut(e+"["+i+"]",t[i],r,n)}S.param=function(e,t){var r,n=[],i=function(e,t){var r=m(t)?t():t;n[n.length]=encodeURIComponent(e)+"="+encodeURIComponent(null==r?"":r)};if(null==e)return"";if(Array.isArray(e)||e.jquery&&!S.isPlainObject(e))S.each(e,(function(){i(this.name,this.value)}));else for(r in e)Ut(r,e[r],t,i);return n.join("&")},S.fn.extend({serialize:function(){return S.param(this.serializeArray())},serializeArray:function(){return this.map((function(){var e=S.prop(this,"elements");return e?S.makeArray(e):this})).filter((function(){var e=this.type;return this.name&&!S(this).is(":disabled")&&Ot.test(this.nodeName)&&!Lt.test(e)&&(this.checked||!Se.test(e))})).map((function(e,t){var r=S(this).val();return null==r?null:Array.isArray(r)?S.map(r,(function(e){return{name:t.name,value:e.replace(Rt,"\r\n")}})):{name:t.name,value:r.replace(Rt,"\r\n")}})).get()}});var Kt=/%20/g,Ft=/#.*$/,Nt=/([?&])_=[^&]*/,jt=/^(.*?):[ \t]*([^\r\n]*)$/gm,Ht=/^(?:GET|HEAD)$/,$t=/^\/\//,zt={},Gt={},qt="*/".concat("*"),Vt=v.createElement("a");function Wt(e){return function(t,r){"string"!=typeof t&&(r=t,t="*");var n,i=0,a=t.toLowerCase().match(q)||[];if(m(r))for(;n=a[i++];)"+"===n[0]?(n=n.slice(1)||"*",(e[n]=e[n]||[]).unshift(r)):(e[n]=e[n]||[]).push(r)}}function Yt(e,t,r,n){var i={},a=e===Gt;function s(o){var u;return i[o]=!0,S.each(e[o]||[],(function(e,o){var c=o(t,r,n);return"string"!=typeof c||a||i[c]?a?!(u=c):void 0:(t.dataTypes.unshift(c),s(c),!1)})),u}return s(t.dataTypes[0])||!i["*"]&&s("*")}function Qt(e,t){var r,n,i=S.ajaxSettings.flatOptions||{};for(r in t)void 0!==t[r]&&((i[r]?e:n||(n={}))[r]=t[r]);return n&&S.extend(!0,e,n),e}Vt.href=Dt.href,S.extend({active:0,lastModified:{},etag:{},ajaxSettings:{url:Dt.href,type:"GET",isLocal:/^(?:about|app|app-storage|.+-extension|file|res|widget):$/.test(Dt.protocol),global:!0,processData:!0,async:!0,contentType:"application/x-www-form-urlencoded; charset=UTF-8",accepts:{"*":qt,text:"text/plain",html:"text/html",xml:"application/xml, text/xml",json:"application/json, text/javascript"},contents:{xml:/\bxml\b/,html:/\bhtml/,json:/\bjson\b/},responseFields:{xml:"responseXML",text:"responseText",json:"responseJSON"},converters:{"* text":String,"text html":!0,"text json":JSON.parse,"text xml":S.parseXML},flatOptions:{url:!0,context:!0}},ajaxSetup:function(e,t){return t?Qt(Qt(e,S.ajaxSettings),t):Qt(S.ajaxSettings,e)},ajaxPrefilter:Wt(zt),ajaxTransport:Wt(Gt),ajax:function(e,t){"object"==typeof e&&(t=e,e=void 0),t=t||{};var n,i,a,s,o,u,c,l,f,h,d=S.ajaxSetup({},t),p=d.context||d,y=d.context&&(p.nodeType||p.jquery)?S(p):S.event,g=S.Deferred(),m=S.Callbacks("once memory"),b=d.statusCode||{},_={},w={},k="canceled",x={readyState:0,getResponseHeader:function(e){var t;if(c){if(!s)for(s={};t=jt.exec(a);)s[t[1].toLowerCase()+" "]=(s[t[1].toLowerCase()+" "]||[]).concat(t[2]);t=s[e.toLowerCase()+" "]}return null==t?null:t.join(", ")},getAllResponseHeaders:function(){return c?a:null},setRequestHeader:function(e,t){return null==c&&(e=w[e.toLowerCase()]=w[e.toLowerCase()]||e,_[e]=t),this},overrideMimeType:function(e){return null==c&&(d.mimeType=e),this},statusCode:function(e){var t;if(e)if(c)x.always(e[x.status]);else for(t in e)b[t]=[b[t],e[t]];return this},abort:function(e){var t=e||k;return n&&n.abort(t),A(0,t),this}};if(g.promise(x),d.url=((e||d.url||Dt.href)+"").replace($t,Dt.protocol+"//"),d.type=t.method||t.type||d.method||d.type,d.dataTypes=(d.dataType||"*").toLowerCase().match(q)||[""],null==d.crossDomain){u=v.createElement("a");try{u.href=d.url,u.href=u.href,d.crossDomain=Vt.protocol+"//"+Vt.host!=u.protocol+"//"+u.host}catch(e){d.crossDomain=!0}}if(d.data&&d.processData&&"string"!=typeof d.data&&(d.data=S.param(d.data,d.traditional)),Yt(zt,d,t,x),c)return x;for(f in(l=S.event&&d.global)&&0==S.active++&&S.event.trigger("ajaxStart"),d.type=d.type.toUpperCase(),d.hasContent=!Ht.test(d.type),i=d.url.replace(Ft,""),d.hasContent?d.data&&d.processData&&0===(d.contentType||"").indexOf("application/x-www-form-urlencoded")&&(d.data=d.data.replace(Kt,"+")):(h=d.url.slice(i.length),d.data&&(d.processData||"string"==typeof d.data)&&(i+=(Bt.test(i)?"&":"?")+d.data,delete d.data),!1===d.cache&&(i=i.replace(Nt,"$1"),h=(Bt.test(i)?"&":"?")+"_="+Pt.guid+++h),d.url=i+h),d.ifModified&&(S.lastModified[i]&&x.setRequestHeader("If-Modified-Since",S.lastModified[i]),S.etag[i]&&x.setRequestHeader("If-None-Match",S.etag[i])),(d.data&&d.hasContent&&!1!==d.contentType||t.contentType)&&x.setRequestHeader("Content-Type",d.contentType),x.setRequestHeader("Accept",d.dataTypes[0]&&d.accepts[d.dataTypes[0]]?d.accepts[d.dataTypes[0]]+("*"!==d.dataTypes[0]?", "+qt+"; q=0.01":""):d.accepts["*"]),d.headers)x.setRequestHeader(f,d.headers[f]);if(d.beforeSend&&(!1===d.beforeSend.call(p,x,d)||c))return x.abort();if(k="abort",m.add(d.complete),x.done(d.success),x.fail(d.error),n=Yt(Gt,d,t,x)){if(x.readyState=1,l&&y.trigger("ajaxSend",[x,d]),c)return x;d.async&&d.timeout>0&&(o=r.setTimeout((function(){x.abort("timeout")}),d.timeout));try{c=!1,n.send(_,A)}catch(e){if(c)throw e;A(-1,e)}}else A(-1,"No Transport");function A(e,t,s,u){var f,h,v,_,w,k=t;c||(c=!0,o&&r.clearTimeout(o),n=void 0,a=u||"",x.readyState=e>0?4:0,f=e>=200&&e<300||304===e,s&&(_=function(e,t,r){for(var n,i,a,s,o=e.contents,u=e.dataTypes;"*"===u[0];)u.shift(),void 0===n&&(n=e.mimeType||t.getResponseHeader("Content-Type"));if(n)for(i in o)if(o[i]&&o[i].test(n)){u.unshift(i);break}if(u[0]in r)a=u[0];else{for(i in r){if(!u[0]||e.converters[i+" "+u[0]]){a=i;break}s||(s=i)}a=a||s}if(a)return a!==u[0]&&u.unshift(a),r[a]}(d,x,s)),!f&&S.inArray("script",d.dataTypes)>-1&&S.inArray("json",d.dataTypes)<0&&(d.converters["text script"]=function(){}),_=function(e,t,r,n){var i,a,s,o,u,c={},l=e.dataTypes.slice();if(l[1])for(s in e.converters)c[s.toLowerCase()]=e.converters[s];for(a=l.shift();a;)if(e.responseFields[a]&&(r[e.responseFields[a]]=t),!u&&n&&e.dataFilter&&(t=e.dataFilter(t,e.dataType)),u=a,a=l.shift())if("*"===a)a=u;else if("*"!==u&&u!==a){if(!(s=c[u+" "+a]||c["* "+a]))for(i in c)if((o=i.split(" "))[1]===a&&(s=c[u+" "+o[0]]||c["* "+o[0]])){!0===s?s=c[i]:!0!==c[i]&&(a=o[0],l.unshift(o[1]));break}if(!0!==s)if(s&&e.throws)t=s(t);else try{t=s(t)}catch(e){return{state:"parsererror",error:s?e:"No conversion from "+u+" to "+a}}}return{state:"success",data:t}}(d,_,x,f),f?(d.ifModified&&((w=x.getResponseHeader("Last-Modified"))&&(S.lastModified[i]=w),(w=x.getResponseHeader("etag"))&&(S.etag[i]=w)),204===e||"HEAD"===d.type?k="nocontent":304===e?k="notmodified":(k=_.state,h=_.data,f=!(v=_.error))):(v=k,!e&&k||(k="error",e<0&&(e=0))),x.status=e,x.statusText=(t||k)+"",f?g.resolveWith(p,[h,k,x]):g.rejectWith(p,[x,k,v]),x.statusCode(b),b=void 0,l&&y.trigger(f?"ajaxSuccess":"ajaxError",[x,d,f?h:v]),m.fireWith(p,[x,k]),l&&(y.trigger("ajaxComplete",[x,d]),--S.active||S.event.trigger("ajaxStop")))}return x},getJSON:function(e,t,r){return S.get(e,t,r,"json")},getScript:function(e,t){return S.get(e,void 0,t,"script")}}),S.each(["get","post"],(function(e,t){S[t]=function(e,r,n,i){return m(r)&&(i=i||n,n=r,r=void 0),S.ajax(S.extend({url:e,type:t,dataType:i,data:r,success:n},S.isPlainObject(e)&&e))}})),S.ajaxPrefilter((function(e){var t;for(t in e.headers)"content-type"===t.toLowerCase()&&(e.contentType=e.headers[t]||"")})),S._evalUrl=function(e,t,r){return S.ajax({url:e,type:"GET",dataType:"script",cache:!0,async:!1,global:!1,converters:{"text script":function(){}},dataFilter:function(e){S.globalEval(e,t,r)}})},S.fn.extend({wrapAll:function(e){var t;return this[0]&&(m(e)&&(e=e.call(this[0])),t=S(e,this[0].ownerDocument).eq(0).clone(!0),this[0].parentNode&&t.insertBefore(this[0]),t.map((function(){for(var e=this;e.firstElementChild;)e=e.firstElementChild;return e})).append(this)),this},wrapInner:function(e){return m(e)?this.each((function(t){S(this).wrapInner(e.call(this,t))})):this.each((function(){var t=S(this),r=t.contents();r.length?r.wrapAll(e):t.append(e)}))},wrap:function(e){var t=m(e);return this.each((function(r){S(this).wrapAll(t?e.call(this,r):e)}))},unwrap:function(e){return this.parent(e).not("body").each((function(){S(this).replaceWith(this.childNodes)})),this}}),S.expr.pseudos.hidden=function(e){return!S.expr.pseudos.visible(e)},S.expr.pseudos.visible=function(e){return!!(e.offsetWidth||e.offsetHeight||e.getClientRects().length)},S.ajaxSettings.xhr=function(){try{return new r.XMLHttpRequest}catch(e){}};var Zt={0:200,1223:204},Xt=S.ajaxSettings.xhr();g.cors=!!Xt&&"withCredentials"in Xt,g.ajax=Xt=!!Xt,S.ajaxTransport((function(e){var t,n;if(g.cors||Xt&&!e.crossDomain)return{send:function(i,a){var s,o=e.xhr();if(o.open(e.type,e.url,e.async,e.username,e.password),e.xhrFields)for(s in e.xhrFields)o[s]=e.xhrFields[s];for(s in e.mimeType&&o.overrideMimeType&&o.overrideMimeType(e.mimeType),e.crossDomain||i["X-Requested-With"]||(i["X-Requested-With"]="XMLHttpRequest"),i)o.setRequestHeader(s,i[s]);t=function(e){return function(){t&&(t=n=o.onload=o.onerror=o.onabort=o.ontimeout=o.onreadystatechange=null,"abort"===e?o.abort():"error"===e?"number"!=typeof o.status?a(0,"error"):a(o.status,o.statusText):a(Zt[o.status]||o.status,o.statusText,"text"!==(o.responseType||"text")||"string"!=typeof o.responseText?{binary:o.response}:{text:o.responseText},o.getAllResponseHeaders()))}},o.onload=t(),n=o.onerror=o.ontimeout=t("error"),void 0!==o.onabort?o.onabort=n:o.onreadystatechange=function(){4===o.readyState&&r.setTimeout((function(){t&&n()}))},t=t("abort");try{o.send(e.hasContent&&e.data||null)}catch(e){if(t)throw e}},abort:function(){t&&t()}}})),S.ajaxPrefilter((function(e){e.crossDomain&&(e.contents.script=!1)})),S.ajaxSetup({accepts:{script:"text/javascript, application/javascript, application/ecmascript, application/x-ecmascript"},contents:{script:/\b(?:java|ecma)script\b/},converters:{"text script":function(e){return S.globalEval(e),e}}}),S.ajaxPrefilter("script",(function(e){void 0===e.cache&&(e.cache=!1),e.crossDomain&&(e.type="GET")})),S.ajaxTransport("script",(function(e){var t,r;if(e.crossDomain||e.scriptAttrs)return{send:function(n,i){t=S(" - - - \ No newline at end of file diff --git a/docs/app/decrypt-file.html b/docs/app/decrypt-file.html index 298edf81..dbb28bd1 100644 --- a/docs/app/decrypt-file.html +++ b/docs/app/decrypt-file.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/decrypt.html b/docs/app/decrypt.html index 8cede9cb..edcbfa78 100644 --- a/docs/app/decrypt.html +++ b/docs/app/decrypt.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/encrypt-file.html b/docs/app/encrypt-file.html index aa74ff98..24501de4 100644 --- a/docs/app/encrypt-file.html +++ b/docs/app/encrypt-file.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/encrypt.html b/docs/app/encrypt.html index f88d9970..637b9f7a 100644 --- a/docs/app/encrypt.html +++ b/docs/app/encrypt.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/index.html b/docs/app/index.html index 03ead859..4b7101f2 100644 --- a/docs/app/index.html +++ b/docs/app/index.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/password-generator.html b/docs/app/password-generator.html deleted file mode 100644 index f4951083..00000000 --- a/docs/app/password-generator.html +++ /dev/null @@ -1,75 +0,0 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file diff --git a/docs/app/past_releases.html b/docs/app/past_releases.html index e259b1cc..ce0e4aaa 100644 --- a/docs/app/past_releases.html +++ b/docs/app/past_releases.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/pgp-pqc.html b/docs/app/pgp-pqc.html index ac1fcff5..5372df37 100644 --- a/docs/app/pgp-pqc.html +++ b/docs/app/pgp-pqc.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/search.html b/docs/app/search.html index c0b6f536..86af8f6c 100644 --- a/docs/app/search.html +++ b/docs/app/search.html @@ -1,75 +1 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file +OnlyAgent — Encrypt & sign in your browser

Loading...

\ No newline at end of file diff --git a/docs/app/vault.html b/docs/app/vault.html deleted file mode 100644 index 673920b8..00000000 --- a/docs/app/vault.html +++ /dev/null @@ -1,75 +0,0 @@ - - OnlyAgent — Encrypt & sign in your browser - - - - - - - - -
- -
-
-

- - - -

-
-
- -
-
-

Loading...

- -
-
-
-
-
-
- - - - - - \ No newline at end of file diff --git a/docs/index.html b/docs/index.html index c0f1577a..a856bee6 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,56 +1 @@ - - OnlyAgent — Encrypt, decrypt & sign in your browser - - - - - - - - -
- -
-
-

Encrypt anything with your hardware key.

-

Securely encrypt, sign, decrypt and verify messages and files right in your browser. Your private keys never leave your OnlyKey.

- -
- -
-

Encrypt & Sign Messages

Compose an end-to-end encrypted, signed message for any Keybase or Protonmail user.

-

Encrypt & Sign Files

Encrypt files for a recipient — or for yourself — with your OnlyKey.

-

Decrypt & Verify Messages

Decrypt incoming PGP messages and verify the sender's signature.

-

Decrypt & Verify Files

Decrypt .gpg files and confirm they came from who you expect.

-

Find a Recipient

Search Keybase and Protonmail for someone to send encrypted messages to.

-

Password Generator

Derive strong, repeatable static passwords from your OnlyKey.

-

Credential Vault

Store API keys hardware-encrypted by your OnlyKey — each use gated by a physical touch.

-
- -
- - - - - \ No newline at end of file +OnlyAgent — Encrypt, decrypt & sign in your browser

Encrypt anything with your hardware key.

Securely encrypt, sign, decrypt and verify messages and files right in your browser. Your private keys never leave your OnlyKey.

Encrypt & Sign Messages

Compose an end-to-end encrypted, signed message for any Keybase or Protonmail user.

Encrypt & Sign Files

Encrypt files for a recipient — or for yourself — with your OnlyKey.

Decrypt & Verify Messages

Decrypt incoming PGP messages and verify the sender's signature.

Decrypt & Verify Files

Decrypt .gpg files and confirm they came from who you expect.

Find a Recipient

Search Keybase and Protonmail for someone to send encrypted messages to.

\ No newline at end of file diff --git a/docs/app/.DS_Store b/past_releases/.DS_Store similarity index 92% rename from docs/app/.DS_Store rename to past_releases/.DS_Store index 15f383eb..2c2380f8 100644 Binary files a/docs/app/.DS_Store and b/past_releases/.DS_Store differ diff --git a/src/.DS_Store b/src/.DS_Store new file mode 100644 index 00000000..55107084 Binary files /dev/null and b/src/.DS_Store differ diff --git a/src/index-src.html b/src/index-src.html index 8d835060..f706e75f 100644 --- a/src/index-src.html +++ b/src/index-src.html @@ -16,7 +16,6 @@ Encrypt Decrypt Search - Vault Docs Get OnlyAgent @@ -39,8 +38,6 @@

Encrypt anything with your hardware key.

Decrypt & Verify Messages

Decrypt incoming PGP messages and verify the sender's signature.

Decrypt & Verify Files

Decrypt .gpg files and confirm they came from who you expect.

Find a Recipient

Search Keybase and Protonmail for someone to send encrypted messages to.

-

Password Generator

Derive strong, repeatable static passwords from your OnlyKey.

-

Credential Vault

Store API keys hardware-encrypted by your OnlyKey — each use gated by a physical touch.

diff --git a/src/lib/history.js b/src/lib/history.js deleted file mode 100644 index f5ca36a3..00000000 --- a/src/lib/history.js +++ /dev/null @@ -1,114 +0,0 @@ -//change _template_ to your plugin name -module.exports = { - consumes: ["app", "onlykey3rd", "newGun", "forge", "SEA"], - provides: ["history"], - - setup: async function(options, imports, register) { - var historyAPI = {}; - - var onlykey3rd = imports.onlykey3rd; - var ok = onlykey3rd(1, 0); - var newGun = imports.newGun; - var SEA = imports.SEA; - var forge = imports.forge; - - var gun = newGun(); - - /**/ - - var disconnected_PK = window.localStorage.onlykey_has_history; - if (!disconnected_PK) { - disconnected_PK = JSON.stringify(await SEA.pair()); - window.localStorage.onlykey_has_history = disconnected_PK; - } - - disconnected_PK = JSON.parse(disconnected_PK); - - // var disconnected_PUBKEY = disconnected_PK.epub; - var disconnected_SECRET = await SEA.secret(disconnected_PK, disconnected_PK); - - historyAPI.historyEnabled = false; - - var historyPUBKEY = false; - var historySECRET = false; - - historyAPI.ready = false; - - historyAPI.init = function() { - - } - - historyAPI.setup = function() { - - } - - function doGunAuth(finished) { - var gunUID = forge.sha256.create().update(historyPUBKEY).digest().toHex(); - var gunPASS = forge.sha256.create().update(historySECRET).digest().toHex(); - gun.user().auth(gunUID, gunPASS, async function(err, res) { - if (err.err) { - gun.user().create(gunUID, gunPASS, finished); - } - else - finished(); - }); - } - - var encrypt = function(message) { - if (!historySECRET) - return ok.encrypt(message, disconnected_SECRET); - return ok.encrypt(message, historySECRET); - }; - var decrypt = function(message) { - if (!historySECRET) - return ok.decrypt(message, disconnected_SECRET); - return ok.decrypt(message, historySECRET); - }; - - - historyAPI.history = { - get: async function(key) { - var hist = gun.user().get("history"); - return decrypt(await hist.get(key)); - }, - set: async function(key, message) { - var hist = gun.user().get("history"); - return hist.get(key).put(await encrypt(message)); - } - }; - /* - - if (ok.history) { - $("#pgpkeyurl2").val(await ok.history.get("pgpkeyurl2")); - $("#pgpkeyurl2").change(function() { - ok.history.set("pgpkeyurl2", $("#pgpkeyurl2").val()); - }); - - $("#pgpkeyurl").val(await ok.history.get("pgpkeyurl")); - $("#pgpkeyurl").change(function() { - ok.history.set("pgpkeyurl", $("#pgpkeyurl").val()); - }); - }*/ - - function doConnect() { - return new Promise(async function(resolve) { - ok.connect(function() { - if (ok.derive_public_key) { - // disable_onlykey = false; - ok.derive_public_key("onlykey-gun", function(error, historyPubkey) { - ok.derive_shared_secret("onlykey-gun", historyPubkey, async function(error, historySecret) { - - }); - }); - } - }); - }); - } - - register(null, { - history: historyAPI - }); - - } - -}; \ No newline at end of file diff --git a/docs/.DS_Store b/src/onlykey-fido2/.DS_Store similarity index 74% rename from docs/.DS_Store rename to src/onlykey-fido2/.DS_Store index 6c4c21a5..0e3fd007 100644 Binary files a/docs/.DS_Store and b/src/onlykey-fido2/.DS_Store differ diff --git a/src/onlykey-fido2/onlykey/age_file.js b/src/onlykey-fido2/onlykey/age_file.js index 963d62e0..beb57113 100644 --- a/src/onlykey-fido2/onlykey/age_file.js +++ b/src/onlykey-fido2/onlykey/age_file.js @@ -273,12 +273,10 @@ function encryptAgeFile(plaintext, { ciphertext, sharedSecret }) { // Decrypts a full age v1 file containing (at least) one mlkem768x25519 // stanza. deriveSharedSecret(ciphertext) is called with the full 1120-byte // X-Wing ciphertext from the stanza and must return (sync or async) the -// 32-byte combined X-Wing shared secret for this file's recipient - the -// caller already knows pk_X/mlkem_seed for the label and is expected to -// use ctXOf(ciphertext) to get the 32 bytes the device's -// DERIVE_SHARED_SECRET call needs, then call splitDecapsulate() itself -// (it needs the *full* ciphertext too, for the ML-KEM half - not just -// ct_X). Returns the decrypted plaintext as a Uint8Array. +// 32-byte combined X-Wing shared secret for this file's recipient. The caller +// hands that whole ciphertext to the device, which decapsulates both halves +// and answers with the finished shared secret; there is no host-side ML-KEM +// step and nothing to split. Returns the decrypted plaintext as a Uint8Array. async function decryptAgeFile(fileBytes, deriveSharedSecret) { const bytes = fileBytes instanceof Uint8Array ? fileBytes : new Uint8Array(fileBytes); const { stanzas, headerNoMac, mac, headerEndOffset } = parseHeader(bytes); diff --git a/src/onlykey-fido2/onlykey/age_pqc.js b/src/onlykey-fido2/onlykey/age_pqc.js index 55767f79..eb83351d 100644 --- a/src/onlykey-fido2/onlykey/age_pqc.js +++ b/src/onlykey-fido2/onlykey/age_pqc.js @@ -6,15 +6,23 @@ // replaced by the real bech32 scheme (see derived_xwing.py/bech32.py) - the // old scheme here was stale/superseded and `age` rejects it outright. // -// Wire contract this mirrors (see okcrypto.cpp's okcrypto_xwing_web_derive, +// Wire contract this mirrors (see okcrypto.cpp's okcrypto_xwing_derive_*, // RESERVED_KEY_WEB_DERIVATION + KEYTYPE_XWING dispatch): -// DERIVE_PUBLIC_KEY -> [ pk_X(32) | mlkem_seed(32) ] -// DERIVE_SHAREDSEC -> [ ss_X(32) | mlkem_seed(32) ] -// The device never returns sk_X or the ML-KEM secret key - only a one-way -// SHA256(sk_X || tag)-derived seed the host expands locally. +// DERIVE_PUBLIC_KEY -> [ pk_M(1184) | pk_X(32) ] = the recipient +// OKDECRYPT to slot 128 with +// [ label32 | ct(1120) ] -> [ ss(32) ] = the X-Wing shared secret +// +// SPLIT CUSTODY IS GONE. The device used to return a 32-byte ML-KEM seed and +// let the host expand it, run ML-KEM decapsulation and combine the halves. The +// seed is private key material - it yields sk_M - so that was a private key +// handed out in answer to a request for a public one, and the ML-KEM half of +// a "hardware" key really lived in the browser. The device now holds both +// halves and does the whole decapsulation, so mlkemKeypairFromSeed(), +// buildRecipient(), splitDecapsulate() and ctXOf() have no callers and are +// gone with them. What remains here is host/sender-side math on public values. const { ml_kem768 } = require('@noble/post-quantum/ml-kem.js'); -const { shake256, sha3_256 } = require('@noble/hashes/sha3.js'); +const { sha3_256 } = require('@noble/hashes/sha3.js'); // shake256 went with the seed expansion const { sha256 } = require('@noble/hashes/sha2.js'); const { x25519 } = require('@noble/curves/ed25519.js'); @@ -44,58 +52,12 @@ function deriveLabelTag(label) { return sha256(Buffer.from(label, 'utf8')); } -// Expands the 32-byte device-derived seed (SHAKE256 -> 64-byte d||z) into an -// ML-KEM-768 keypair. Matches the firmware (xwing_shake256/keypair_derand) -// and python-onlykey's mlkem_keypair_from_seed() (kyber_py's -// _keygen_internal(d, z)) - @noble/post-quantum's ml_kem768.keygen(seed64) -// splits the same way internally (seed[:32]=d, seed[32:]=z; see -// createKyber() in @noble/post-quantum's ml-kem.ts). -function mlkemKeypairFromSeed(mlkemSeed) { - if (mlkemSeed.length !== SEED) { - throw new Error(`mlkem_seed must be ${SEED} bytes, got ${mlkemSeed.length}`); - } - const seed64 = shake256(mlkemSeed, { dkLen: 64 }); - return ml_kem768.keygen(seed64); // { publicKey, secretKey } -} - -// Builds the 1216-byte X-Wing recipient public key (pk_M || pk_X). -function buildRecipient(pkX, mlkemSeed) { - if (pkX.length !== 32) { - throw new Error(`pk_X must be 32 bytes, got ${pkX.length}`); - } - const { publicKey: pkM } = mlkemKeypairFromSeed(mlkemSeed); - return concatBytes(pkM, pkX); -} - // X-Wing Combiner (draft-connolly-cfrg-xwing-kem-09 Section 5.3): // SHA3-256(ss_M || ss_X || ct_X || pk_X || XWingLabel) function xwingCombiner(ssM, ssX, ctX, pkX) { return sha3_256(concatBytes(ssM, ssX, ctX, pkX, XWING_LABEL)); } -// Finishes X-Wing decapsulation given the device's ss_X and the seed. -// ssX: 32-byte X25519 shared secret from the device (sk_X stays there) -// ciphertext: 1120-byte X-Wing ct (ct_M || ct_X) from the age stanza -// pkX: recipient X25519 public key -// mlkemSeed: 32-byte ML-KEM seed from the device -// Returns the 32-byte X-Wing shared secret. ct_M never leaves the host. -function splitDecapsulate(ssX, ciphertext, pkX, mlkemSeed) { - if (ssX.length !== 32) throw new Error('ss_X must be 32 bytes'); - if (ciphertext.length !== XWING_CT) { - throw new Error(`X-Wing ct must be ${XWING_CT} bytes, got ${ciphertext.length}`); - } - const ctM = ciphertext.subarray(0, MLKEM_CT); - const ctX = ciphertext.subarray(MLKEM_CT, XWING_CT); - const { secretKey: skM } = mlkemKeypairFromSeed(mlkemSeed); - const ssM = ml_kem768.decapsulate(ctM, skM); - return xwingCombiner(ssM, ssX, ctX, pkX); -} - -// Returns ct_X (the 32 bytes the device needs) from a stanza ciphertext. -function ctXOf(ciphertext) { - return ciphertext.subarray(MLKEM_CT, XWING_CT); -} - // Standard X-Wing Encapsulation (host/sender side, for encrypt). Mirrors // xwing.py's xwing_encaps_host() exactly. Note: x25519 here comes from the // vendored @noble/curves (already an unavoidable transitive dependency of @@ -252,11 +214,7 @@ function decodeIdentity(s) { } module.exports = { - mlkemKeypairFromSeed, - buildRecipient, xwingCombiner, - splitDecapsulate, - ctXOf, xwingEncapsHost, deriveLabelTag, encodeRecipient, diff --git a/src/onlykey-fido2/onlykey/onlykey-3rd-party.js b/src/onlykey-fido2/onlykey/onlykey-3rd-party.js index a82be5b8..28d784b1 100644 --- a/src/onlykey-fido2/onlykey/onlykey-3rd-party.js +++ b/src/onlykey-fido2/onlykey/onlykey-3rd-party.js @@ -24,10 +24,14 @@ module.exports = function(imports, onlykeyApi) { // ctap_error_codes, // getAllUrlParams, aesgcm_decrypt, - // Needed by the composite_sign/composite_decrypt payload encryption - // below; was commented out while nothing in this file sent encrypted - // data to the device. - aesgcm_encrypt, + // transit_seal / transit_open are the framed (counter + tag) forms and + // are what everything here uses. aesgcm_decrypt is kept for the ONE + // call below that runs against a response the device never encrypted. + transit_seal, + transit_open, + transit_framed, + transit_select, + transit_reset, digestBuff, digestArray, arrayBufToBase64UrlDecode, @@ -47,11 +51,21 @@ module.exports = function(imports, onlykeyApi) { CURVE25519: 3 }; + // 3 and 4 (DERIVE_*_REQ_PRESS) were removed from the firmware and the + // numbers are burned, not reused - sending either now gets + // CTAP2_ERR_EXTENSION_NOT_SUPPORTED rather than being reinterpreted. + // + // The `press_required` argument these mapped to is now IGNORED, and kept + // only so existing callers still parse. Presence is decided by the device + // from what is being asked for: deriving a public key never prompts, + // deriving a shared secret always does, with no setting to turn it off. + // The suffix had also quietly become a second key domain (the firmware set + // additional_data[0] = 1 for it, changing the HKDF salt), which is how + // vault.js ended up fetching its public key in one domain and doing its + // ECDH in the other. One label now means one key. var KEYACTION = { DERIVE_PUBLIC_KEY: 1, - DERIVE_SHARED_SECRET: 2, - DERIVE_PUBLIC_KEY_REQ_PRESS: 3, - DERIVE_SHARED_SECRET_REQ_PRESS: 4 + DERIVE_SHARED_SECRET: 2 }; // Uint8Array.from() is NOT a string encoder. Given a string it treats it as @@ -195,7 +209,6 @@ module.exports = function(imports, onlykeyApi) { var OK_SEA_epub = keydata.x + '.' + keydata.y; - if (callback) callback(OK_SEA_epub); @@ -217,7 +230,6 @@ module.exports = function(imports, onlykeyApi) { api.connect = async function(cb) { var delay = 0; - console.log("-------------------------------------------"); // msg("Requesting OnlyKey Secure Connection (" + getOS() + ")"); api.emit("status", "Requesting OnlyKey Secure Connection"); @@ -264,6 +276,14 @@ module.exports = function(imports, onlykeyApi) { var FWversion = bytes2string(response.slice(32 + 8, 32 + 19)); var OKversion = response[32 + 19] == 99 ? 'Color' : 'Go'; var sharedsec = nacl.box.before(Uint8Array.from(okPub), appKey.secretKey); + // This response is NOT encrypted - a plain OKCONNECT goes out + // with opt3 = 0 - which is exactly why the version can be read + // here, before any framing has been chosen. (The aesgcm_decrypt + // above hashes an already-hashed key and decrypts cleartext; it + // has never produced anything anyone uses. Left alone rather + // than moved to transit_open(), which would refuse it for having + // no tag.) + transit_select(FWversion); //msg("message -> " + message) // msg("OnlyKey " + OKversion + " " + FWversion + " connection established\n"); @@ -274,7 +294,6 @@ module.exports = function(imports, onlykeyApi) { }); }); - } api.derive_public_key = async function(additional_d, keytype, press_required, cb) { @@ -312,7 +331,7 @@ module.exports = function(imports, onlykeyApi) { } Array.prototype.push.apply(message, dataHash); - var keyAction = press_required ? KEYACTION.DERIVE_PUBLIC_KEY_REQ_PRESS : KEYACTION.DERIVE_PUBLIC_KEY; + var keyAction = KEYACTION.DERIVE_PUBLIC_KEY; // press_required ignored, see KEYACTION var enc_resp = 1; await onlykeyApi.ctaphid_via_webauthn(cmd, keyAction, keytype, enc_resp, message, 60000).then(async(response) => { @@ -334,8 +353,16 @@ module.exports = function(imports, onlykeyApi) { // Decrypt with transit_key var transit_key = nacl.box.before(Uint8Array.from(okPub), appKey.secretKey); transit_key = Uint8Array.from(transit_key); //await digestBuff(Uint8Array.from(transit_key)); //AES256 key sha256 hash of shared secret + // This request was an OKCONNECT, so the device has REPLACED + // its transit key and restarted its counters. Adopt both, or + // the next composite request goes out under the old key and + // the wrong counter. The X-Wing path below already did this; + // it is the same bug here, and the tag now makes it fatal + // instead of silent. + onlykeyApi.sharedsec = transit_key; + transit_reset(); var encrypted = response.slice(32, response.length); - encrypted_response = await aesgcm_decrypt(encrypted, transit_key); + encrypted_response = await transit_open(encrypted, transit_key); } // OnlyKey version and model info @@ -353,7 +380,6 @@ module.exports = function(imports, onlykeyApi) { api.emit("status", "OnlyKey: Requested Derived Public Key Complete"); - if (keytype == KEYTYPE.P256R1) { //KEYTYPE_P256R1 ONLYKEY_ECDH_P256_to_EPUB(sharedPub, function(epub) { if (typeof cb === 'function') cb(null, epub); @@ -413,7 +439,7 @@ module.exports = function(imports, onlykeyApi) { //msg("input pubkey -> " + pubkey) //msg("full message -> " + message) - var keyAction = press_required ? KEYACTION.DERIVE_SHARED_SECRET_REQ_PRESS : KEYACTION.DERIVE_SHARED_SECRET; + var keyAction = KEYACTION.DERIVE_SHARED_SECRET; // press_required ignored; the device always prompts var enc_resp = 1; await onlykeyApi.ctaphid_via_webauthn(cmd, keyAction, keytype, enc_resp, message, 60000).then(async(response) => { @@ -433,8 +459,10 @@ module.exports = function(imports, onlykeyApi) { // Decrypt with transit_key var transit_key = nacl.box.before(Uint8Array.from(okPub), appKey.secretKey); transit_key = Uint8Array.from(transit_key); //await digestBuff(Uint8Array.from(transit_key)); //AES256 key sha256 hash of shared secret + onlykeyApi.sharedsec = transit_key; // see derive_public_key + transit_reset(); var encrypted = response.slice(32, response.length); - encrypted_response = await aesgcm_decrypt(encrypted, transit_key); + encrypted_response = await transit_open(encrypted, transit_key); } var FWversion = bytes2string(encrypted_response.slice(8, 19)); @@ -450,7 +478,6 @@ module.exports = function(imports, onlykeyApi) { //Private ECC key will be 32 bytes for all supported ECC key types var sharedsec = encrypted_response.slice(encrypted_response.length - 32, encrypted_response.length); - // msg("OnlyKey Shared Secret Completed\n"); api.emit("status", "OnlyKey: Shared Secret Complete"); @@ -497,6 +524,15 @@ module.exports = function(imports, onlykeyApi) { // different key with no error, surfacing much later as "no // identity matched any of the recipients". var XWING_WIRE_KEYTYPE = 5; + var XWING_PK = 1216; // okcrypto.h XWING_PK_SIZE + var XWING_CT = 1120; // okcrypto.h XWING_CT_SIZE + var XWING_SS = 32; // okcrypto.h XWING_SS_SIZE + // Slot 128 - the web AND agent derivation key. Named for both because it + // serves both: this app over FIDO2, and local tools over USB + // (onlykey-agent, python-onlykey, age). Deliberately the accessible tier - + // reachable by software with nobody in front of it, and correspondingly + // less protected than a stored slot. + var RESERVED_KEY_WEB_AGENT_DERIVATION = 128; // okcore.h // Response layout, confirmed live rather than only read off the // firmware: @@ -507,7 +543,7 @@ module.exports = function(imports, onlykeyApi) { // ok_extension.cpp forces any truthy opt3 to that mode). The status // string's length varies with the firmware version, so the NUL is // located rather than a fixed offset assumed. - async function xwing_derive(label, ctX, press_required) { + async function xwing_derive(label) { var message = [255, 255, 255, 255, OKCMD.OKCONNECT]; var currentEpochTime = Math.round(new Date().getTime() / 1000.0).toString(16); @@ -521,44 +557,24 @@ module.exports = function(imports, onlykeyApi) { var labelHash = await digestArray(derivationInputBytes(label)); Array.prototype.push.apply(message, labelHash); - if (ctX) Array.prototype.push.apply(message, Array.from(ctX)); - - var keyAction = ctX - ? (press_required ? KEYACTION.DERIVE_SHARED_SECRET_REQ_PRESS : KEYACTION.DERIVE_SHARED_SECRET) - : (press_required ? KEYACTION.DERIVE_PUBLIC_KEY_REQ_PRESS : KEYACTION.DERIVE_PUBLIC_KEY); - - // If the OnlyKey is set to "Challenge Code" for web derived keys - // (webderivemode 0), a shared-secret derive makes the device wait - // for a 3-digit code before it will answer. The device computes the - // code as SHA-256 over the exact request payload it received - the - // 32-byte label hash followed by the 32-byte ct_X (okcore.cpp's - // done_process_packets over packet_buffer, and the web_derive_gate - // in ok_extension.cpp) - taking bytes 0, 15 and 31 mod 6 (mod 3 on a - // DUO), each plus one. The device only shows a spinning light, not - // the digits, so we compute the same code here and surface it; the - // page displays it while the WebAuthn prompt is up. A key in Button - // Press or No Press mode simply ignores it. Public-key derives are - // never gated, so only ct_X (shared-secret) requests get a code. - if (ctX) { - try { - // [keytype | label32 | ct_X32]: the exact bytes both the FIDO2 gate - // and the raw-HID derived decaps hash (protocol derived_key_hid) - var codeInput = Uint8Array.from([protocol.KEYTYPE.XWING].concat(labelHash, Array.from(ctX))); - var codeHash = await digestArray(codeInput); - var challengeCode = protocol.challengeCodeFromHash(codeHash, onlykeyApi.hw === 'DUO'); - api.emit("challenge", challengeCode); - api.emit("status", "OnlyKey: if it asks for a challenge code, enter " + challengeCode.join(" ") + " (or just press the button)"); - } catch (codeErr) { - // Never let a display convenience block the actual operation. - api.emit("status", "OnlyKey: could not precompute the challenge code (" + (codeErr && codeErr.message ? codeErr.message : codeErr) + ")"); - } - } + + // Public-key derivation only. DERIVE_SHAREDSEC is no longer served + // on this path at all: decapsulation now needs the whole 1120-byte + // X-Wing ciphertext on the device, which does not fit this + // single-shot client_handle request, and the device must hold the + // ML-KEM half rather than hand the host a seed to expand. See + // derive_xwing_decap() below for where it went. + // + // Nothing here is gated, so there is no challenge code to + // precompute and display: a public key is public data and the + // caller cannot turn it into a secret. The gate lives on the + // decapsulation path - the one that decrypts. + var keyAction = KEYACTION.DERIVE_PUBLIC_KEY; var enc_resp = 1; var response = await onlykeyApi.ctaphid_via_webauthn( OKCMD.OKCONNECT, keyAction, XWING_WIRE_KEYTYPE, enc_resp, message, 60000 ); - if (!response || !response.data) { throw new Error(response && response.error ? response.error : 'no response from OnlyKey'); } @@ -566,33 +582,99 @@ module.exports = function(imports, onlykeyApi) { var okPub = data.slice(0, 32); var transit_key = Uint8Array.from(nacl.box.before(Uint8Array.from(okPub), appKey.secretKey)); - var tail = await aesgcm_decrypt(data.slice(32, data.length), transit_key); - tail = Array.from(tail); - var nulAt = tail.indexOf(0); - if (nulAt === -1) throw new Error('X-Wing derive: no NUL-terminated status string in response'); - var payload = tail.slice(nulAt + 1); - if (payload.length !== 64) { - throw new Error('X-Wing derive: expected 64 bytes after the status string, got ' + payload.length); + // This request was an OKCONNECT, so the device has just REPLACED its + // transit_key with one derived from the keypair generated above. + // transit_key is a single global on the device - the last OKCONNECT + // always wins - while onlykeyApi.sharedsec still held the key from + // the api's own connect at page load. + // + // Everything composite goes out under onlykeyApi.sharedsec + // (prime_composite -> aesgcm_encrypt), so after any derive those two + // disagreed and the device decrypted the OKDECRYPT chunks with the + // wrong key. It does not fail loudly: the chunk count is right, the + // request reassembles to 1152 bytes of garbage, the device + // decapsulates that garbage and hands back a perfectly well-formed + // 32-byte secret which simply is not the right one. age reports + // "invalid tag" - measured on hardware 2026-09-15, after a correct + // derive, a correct encrypt and a confirmed press on the key. + // + // Adopt the key the device now actually holds - and its counter + // space, which the device restarted along with the key. + onlykeyApi.sharedsec = transit_key; + transit_reset(); + + // Reassemble the CIPHERTEXT first, decrypt once at the end. + // + // Everything after the transit pubkey is ONE AES-GCM blob that the + // device encrypted in a single call over the whole staged response + // (store_FIDO_response(), encrypt == 2). The chunk boundaries are a + // transport artefact and mean nothing to the cipher. + // + // Decrypting the first chunk and then appending the polled chunks + // raw - which is what this did - splices plaintext onto ciphertext. + // It looked plausible because aesgcm_decrypt() runs with + // tagLength 0, so a prefix DOES decrypt correctly on its own and + // the first 446 bytes of the recipient were right. The remaining + // 770 were ciphertext. agePqc rejected the result with "ML-KEM. + // encapsulate: wrong publicKey modulus" - measured on hardware + // 2026-09-15, the first symptom of this that was visible at all. + var cipher = Array.from(data).slice(32); + if (cipher.length >= MAX_LARGE_RESP_CHUNK - 32) { + // untilShort: the host cannot compute the total. The staged + // response is [ transit pubkey(32) | status field | pk(1216) ] + // and the status field's width is sizeof(UNLOCKED)+1 - a + // firmware build constant that changes with the version string. + var rest = await poll_for_response(0, null, true); + cipher = cipher.concat(Array.from(rest)); } - if (ctX) api.emit("challenge", null); // clear the displayed code + var tail = Array.from(await transit_open(cipher, transit_key)); + + // Take the recipient as the LAST XWING_PK bytes rather than + // everything after the first NUL. The status field is a fixed-width + // slot, NOT a tight string: the firmware copies sizeof(UNLOCKED)+1 + // bytes into it, so short version strings leave trailing padding + // between the NUL and the recipient. Slicing at nulAt+1 prepended + // that padding to pk_M and corrupted it. + if (tail.length < XWING_PK) { + throw new Error('X-Wing derive: short response, got ' + tail.length + + ' bytes, need at least ' + XWING_PK); + } + var nulAt = tail.indexOf(0); + if (nulAt === -1) throw new Error('X-Wing derive: no NUL-terminated status string in response'); + var head = Uint8Array.from(tail.slice(tail.length - XWING_PK)); + // The recipient is XWING_PK (1216) bytes - far past what one + // WebAuthn assertion carries - so the firmware stages it in + // large_resp_buffer and serves it in MAX_LARGE_RESP_CHUNK pieces. + // Whatever rode along with this first response is its head; the + // rest is polled exactly as an ML-DSA-65 signature is. + // + // It used to be 64 bytes inline: [ pk_X(32) | mlkem_seed(32) ]. + // The seed is private key material - it yields sk_M - so that was + // a private key returned in answer to a request for a public one. + // ML-KEM has no short public key (the only 32-byte value that + // reproduces pk_M also reproduces sk_M), so the public key itself + // has to be what crosses the wire. + // head is already exactly XWING_PK bytes: the ciphertext was + // reassembled and decrypted above, and the recipient taken off the + // end of it. return { - pkOrSsX: Uint8Array.from(payload.slice(0, 32)), - mlkemSeed: Uint8Array.from(payload.slice(32, 64)), + recipient: head, status: bytes2string(tail.slice(0, nulAt)), }; } - // cb(error, pk_X, mlkemSeed) - the recipient half. age-derive.js feeds - // both straight into age_pqc.js's buildRecipient(). - api.derive_xwing_recipient = async function(label, press_required, cb) { + // cb(error, recipient) - the full 1216-byte X-Wing public key, ready + // for agePqc.xwingEncapsHost(). age-derive.js no longer builds it from + // halves, because the device no longer hands out the ML-KEM half's seed. + api.derive_xwing_recipient = async function(label, cb) { api.emit("status", "OnlyKey: Requesting Derived X-Wing Recipient"); try { - var r = await xwing_derive(label, null, press_required); + var r = await xwing_derive(label); api.emit("status", "OnlyKey: Derived X-Wing Recipient Complete"); - if (typeof cb === 'function') cb(null, r.pkOrSsX, r.mlkemSeed); + if (typeof cb === 'function') cb(null, r.recipient); } catch (e) { api.emit("status", "OnlyKey: Problem Requesting Derived X-Wing Recipient"); @@ -600,15 +682,70 @@ module.exports = function(imports, onlykeyApi) { } }; - // cb(error, ss_X) - decapsulation. Same call with ct_X appended; the - // device returns the X25519 shared secret in the slot pk_X occupies - // above, which is why both share one implementation. - api.derive_xwing_decap = async function(label, ctX, press_required, cb) { - api.emit("status", "OnlyKey: Requesting Derived X-Wing Decapsulation"); + // cb(error, ss) - the 32-byte X-Wing shared secret, fully decapsulated + // on the device. + // + // This no longer rides the DERIVE_* extension. It is a chunked + // OKDECRYPT to slot RESERVED_KEY_WEB_AGENT_DERIVATION carrying + // [ label32 | ct(1120) ] - the same tunnel composite_decrypt uses - + // because the whole X-Wing ciphertext has to reach the device now. + // Previously the host sent only ct_X (32 bytes), got back ss_X plus + // the ML-KEM seed, and finished the ML-KEM half itself; ct_M never + // reached the device and the seed always reached the host. Both are + // reversed, so the derived path custodies its whole key exactly as the + // stored path does. + // + // The confirmation is the device's, not ours: the firmware computes + // the challenge digits over the reassembled label and ciphertext and + // floors at a button press for a shared secret whatever field 30 says. + // We no longer precompute and display a code here - the previous code + // hashed [keytype | label32 | ct_X32], which is not what the device + // hashes now, and a wrong code shown confidently is worse than none. + api.derive_xwing_decap = async function(label, ciphertext, cb) { + api.emit("status", "OnlyKey: Requesting Derived X-Wing Decapsulation - confirm on the device"); try { - var r = await xwing_derive(label, ctX, press_required); + if (!ciphertext || ciphertext.length !== XWING_CT) { + throw new Error('X-Wing ct must be ' + XWING_CT + ' bytes, got ' + (ciphertext ? ciphertext.length : 0)); + } + var labelHash = await digestArray(derivationInputBytes(label)); + var payload = new Uint8Array(32 + XWING_CT); + payload.set(Uint8Array.from(labelHash), 0); + payload.set(Uint8Array.from(ciphertext), 32); + + await prime_composite(OKDECRYPT, RESERVED_KEY_WEB_AGENT_DERIVATION, payload); + var ss = await poll_for_response(transit_framed(XWING_SS)); + + // The shared secret comes back TRANSIT-ENCRYPTED and has to be + // decrypted here. + // + // okcrypto.cpp returns it with + // send_transport_response(ss, XWING_SS_SIZE, true, true) + // and that `true` only bites on this transport: + // send_transport_response() ignores the flag on the raw-HID + // branch (it memcpys straight into resp_buffer) and honours it + // on the WebAuthn branch, where store_FIDO_response() AES-GCMs + // the whole 32 bytes under the transit key. So the CLI's + // derive_decaps(), which uses the bytes raw, is right to - and + // this path was wrong to. + // + // Every okpqc composite return passes false instead + // (okpqc.cpp:251 X25519_SS, :262 MLKEM_SS), which is why + // composite_decrypt() can use its poll result directly and why + // copying that shape here produced a plausible-looking 32 bytes + // that were simply ciphertext. age reported it as "invalid + // tag" - measured on hardware 2026-09-15, after the device had + // decapsulated correctly and the user had confirmed on the key. + // + // Decrypting host-side rather than dropping the firmware's + // encryption keeps the secret covered in transit and leaves the + // CLI path untouched. + ss = await transit_open(Array.from(ss), onlykeyApi.sharedsec); + if (!ss || ss.length !== XWING_SS) { + throw new Error('X-Wing decaps: got ' + (ss ? ss.length : 0) + + ' bytes after transit decrypt, expected ' + XWING_SS); + } api.emit("status", "OnlyKey: Derived X-Wing Decapsulation Complete"); - if (typeof cb === 'function') cb(null, r.pkOrSsX); + if (typeof cb === 'function') cb(null, Uint8Array.from(ss)); } catch (e) { api.emit("status", "OnlyKey: Problem Requesting Derived X-Wing Decapsulation"); @@ -724,7 +861,7 @@ module.exports = function(imports, onlykeyApi) { // a limit being hit. Sizing a total cap for the largest possible // response would also destroy its only real job - spotting a wedged // device. - async function poll_for_response(expected, maxMs) { + async function poll_for_response(expected, maxMs, untilShort) { var deadline = Date.now() + (maxMs || POLL_BUDGET_MS); var parts = []; var total = 0; @@ -733,7 +870,21 @@ module.exports = function(imports, onlykeyApi) { var waited = 0; while (Date.now() < deadline) { - var resp = await onlykeyApi.ctaphid_via_webauthn(OKPING, 0, 0, 0, new Uint8Array(), PING_TIMEOUT_MS); + // A SEALED empty payload, not a bare empty one. + // + // Every message that reaches the device's protected branch now + // has to authenticate, and okcrypto_transit_open() rejects + // anything shorter than its 20 bytes of framing - which an empty + // keyhandle is. The poll would have been refused on arrival, and + // a refused poll is indistinguishable from "not ready yet", so a + // composite decrypt would simply have spun out its budget. + // + // Sealing nothing costs 20 bytes and yields plaintext length 0, + // which is what the OKPING branch already expects. Against v1 + // firmware transit_seal() falls through to aesgcm_encrypt(), + // which returns the same empty array as before. + var ping = await transit_seal([], onlykeyApi.sharedsec); + var resp = await onlykeyApi.ctaphid_via_webauthn(OKPING, 0, 0, 0, Uint8Array.from(ping), PING_TIMEOUT_MS); lastStatus = resp && resp.status; // Fail fast on anything that cannot improve by polling again. // The deadline is a backstop for "still working", not a @@ -798,6 +949,20 @@ module.exports = function(imports, onlykeyApi) { deadline = Date.now() + (maxMs || POLL_BUDGET_MS); // progress: re-arm api.emit("status", "OnlyKey: Receiving response (" + total + (expected ? " of " + expected : "") + " bytes)"); + // untilShort: drain the staged response without being + // told its length. send_stored_response() serves + // MAX_LARGE_RESP_CHUNK bytes per poll until the tail, so + // the first chunk SHORTER than that is the last one. + // Used by the X-Wing derive, where the host cannot + // compute the total: the staged response is + // [ transit pubkey(32) | status field | recipient(1216) ] + // and the status field's width is a firmware build + // constant (sizeof(UNLOCKED)+1) that the host has no way + // to know. + if (untilShort) { + if (resp.data.length === MAX_LARGE_RESP_CHUNK) continue; + return Uint8Array.from([].concat.apply([], parts)); + } if (!expected || total >= expected) { var out = [].concat.apply([], parts); return Uint8Array.from(expected ? out.slice(0, expected) : out); @@ -852,7 +1017,14 @@ module.exports = function(imports, onlykeyApi) { // // opt2 is what tells the device the input is complete; without it the // device keeps waiting for more and never primes the challenge. - var COMPOSITE_MAX_PACKET = 228; // 57 (OK packet size) * 4, under 255 - header + // 224, down from 228: a credential id is 255 bytes with a 10-byte + // header, so one assertion carries 245, and the transit frame costs 20 + // of those (4-byte counter + 16-byte tag). 224 + 20 = 244. + // + // No chunk count changes. An ML-KEM-768 ciphertext is 1088 bytes and + // still takes 5 chunks; a derived X-Wing [label(32) | ct(1120)] is 1152 + // and still takes 6; RSA-4096 is 512 and still takes 3. + var COMPOSITE_MAX_PACKET = 224; // 57 (OK packet size) * 4 - 4, under 255 - header - frame // opt3 must INCREASE ACROSS OPERATIONS, not restart per operation. // @@ -905,7 +1077,7 @@ module.exports = function(imports, onlykeyApi) { bytes = bytes.slice(COMPOSITE_MAX_PACKET); var finalPacket = bytes.length === 0 ? 1 : 0; var packetnum = next_packetnum(); - var encrypted = await aesgcm_encrypt(chunk, onlykeyApi.sharedsec); + var encrypted = await transit_seal(chunk, onlykeyApi.sharedsec); last = await onlykeyApi.ctaphid_via_webauthn( cmd, slot, finalPacket, packetnum, encrypted, 10000 ); @@ -925,10 +1097,15 @@ module.exports = function(imports, onlykeyApi) { payload[0] = half; payload.set(Uint8Array.from(digest), 1); await prime_composite(OKSIGN, slot, payload); - var expected = half === HALF_ECC ? ED25519_SIG_LEN : MLDSA_SIG_LEN; - var sig = await poll_for_response(expected); + // The device seals this now (okpqc.cpp sends every composite + // response with encrypt = 1, where it used to send them bare), so + // poll_for_response() is told the FRAMED length - its chunk-shape + // check compares against what is actually on the wire - and the + // frame is opened once the whole thing is reassembled. + var expected = transit_framed(half === HALF_ECC ? ED25519_SIG_LEN : MLDSA_SIG_LEN); + var sig = await transit_open(await poll_for_response(expected), onlykeyApi.sharedsec); api.emit("status", "OnlyKey: Signature complete"); - return sig; + return Uint8Array.from(sig); }; // The device half of composite decryption. okpqc_decrypt() infers @@ -942,9 +1119,15 @@ module.exports = function(imports, onlykeyApi) { // reply of any size and skipped the chunk-shape check entirely - // which is exactly how a short or off-cursor reply gets accepted as // a shared secret. Both halves answer 32 bytes. - var out = await poll_for_response(COMPOSITE_SS_LEN); + // + // Sealed since okpqc.cpp stopped sending composite results bare - + // these two 32-byte values are the shared secrets the whole + // operation exists to produce, and they used to cross the tunnel in + // the clear while the classical half encrypted the same thing. + var out = await transit_open(await poll_for_response(transit_framed(COMPOSITE_SS_LEN)), + onlykeyApi.sharedsec); api.emit("status", "OnlyKey: Decryption complete"); - return out; + return Uint8Array.from(out); }; api.encode_key = encode_key; @@ -962,7 +1145,5 @@ module.exports = function(imports, onlykeyApi) { return api; } - - return onlykey; }; diff --git a/src/onlykey-fido2/onlykey/onlykey-api.js b/src/onlykey-fido2/onlykey/onlykey-api.js index 3dc2f526..b86caafd 100644 --- a/src/onlykey-fido2/onlykey/onlykey-api.js +++ b/src/onlykey-fido2/onlykey/onlykey-api.js @@ -30,6 +30,7 @@ module.exports = function(imports) { getAllUrlParams, aesgcm_decrypt, getBrowser, + transit_select, // aesgcm_encrypt } = require("./onlykey.extra.js")(imports); onlykey_api.extra = require("./onlykey.extra.js")(imports); @@ -179,9 +180,24 @@ module.exports = function(imports) { transit_key = await digestBuff(Uint8Array.from(transit_key)); //AES256 key sha256 hash of shared secret var encrypted = response.slice(32, response.length); onlykey_api.FWversion = bytes2string(response.slice(32+8, 32+20)); + // A PLAIN OKCONNECT goes out with opt3 = 0, so the device does + // not encrypt this response - store_FIDO_response() takes the + // unencrypted branch. This aesgcm_decrypt() has therefore always + // been decrypting cleartext into noise; it survived only because + // the one value read out of it, response[32+19], lands past the + // end of the 21-byte result and reads undefined, which compares + // unequal to 99 and yields 'Go' - the same answer the raw bytes + // give. Left as v1 rather than moved to transit_open(), which + // would now (correctly) refuse it for having no tag. + // + // It is also why the version above can be read before any + // framing is chosen: the handshake response is in the clear. response = await aesgcm_decrypt(encrypted, transit_key); onlykey_api.OKversion = response[32+19] == 99 ? 'Color' : 'Go'; onlykey_api.sharedsec = nacl.box.before(Uint8Array.from(okPub), appKey.secretKey); + // New key on the device, so a new counter space here. This also + // selects the framing for the rest of the session. + transit_select(onlykey_api.FWversion); console.info("Version:",[onlykey_api.OKversion, onlykey_api.FWversion]); imports.app.emit("ok-connected"); cb(null); @@ -192,6 +208,7 @@ module.exports = function(imports) { onlykey_api.sharedsec = nacl.box.before(Uint8Array.from(okPub), appKey.secretKey); onlykey_api.OKversion = response[19] == 99 ? 'Color' : 'Original'; onlykey_api.FWversion = bytes2string(response.slice(8, 20)); + transit_select(onlykey_api.FWversion); // v0.2-beta.8c: always v1 console.info("Version:",[onlykey_api.OKversion, onlykey_api.FWversion]); imports.app.emit("ok-connected"); cb(null); diff --git a/src/onlykey-fido2/onlykey/onlykey-pgp.js b/src/onlykey-fido2/onlykey/onlykey-pgp.js index 251c8067..98e0e10d 100644 --- a/src/onlykey-fido2/onlykey/onlykey-pgp.js +++ b/src/onlykey-fido2/onlykey/onlykey-pgp.js @@ -17,8 +17,8 @@ module.exports = function(imports) { // getOS, // ctap_error_codes, // getAllUrlParams, - aesgcm_decrypt, - aesgcm_encrypt + transit_seal, + transit_open } = require("./onlykey.extra.js")(imports); @@ -144,7 +144,7 @@ module.exports = function(imports) { message = []; var ciphertext = new Uint8Array(64).fill(0); Array.prototype.push.apply(message, ciphertext); - encryptedkeyHandle = await aesgcm_encrypt(message, onlykeyApi.sharedsec); + encryptedkeyHandle = await transit_seal(message, onlykeyApi.sharedsec); _$status('waiting_ping'); cmd = OKPING; //} @@ -188,8 +188,25 @@ module.exports = function(imports) { _$status('pending_challenge'); } else { - console.log("Shared Secret", onlykeyApi.sharedsec) - data = await aesgcm_decrypt(response, onlykeyApi.sharedsec); + // The session key is NOT logged. It was, on this line, until + // this change: a console line carrying onlykeyApi.sharedsec + // hands the whole session to anything that can read the console. + try { + data = await transit_open(response, onlykeyApi.sharedsec); + } catch (e) { + // The device sends its error strings in the CLEAR - hidprint() + // goes through send_transport_response() with encrypt = 0 - so + // a failure here is usually an error message, not an attack. + // + // Accept such a response ONLY as an error, never as a result. + // Falling back to the raw bytes as `data` would mean anything + // that strips the tag off a real response gets it treated as a + // signature or a decryption, which is the hole the tag exists + // to close. + var text = bytes2string(Array.from(response).slice(0, 64)); + console.warn('OKPING response did not authenticate:', e.message); + return cb(text.indexOf('Error') === 0 ? text : (e.message || String(e)), null); + } console.log("DECODED RESPONSE:", response); console.log("DECRYPTED RESPONSE:", data); } @@ -217,7 +234,15 @@ module.exports = function(imports) { async function u2fSignBuffer(slot, cipherText, mainCallback) { // this function should recursively call itself until all bytes are sent in chunks var message = []; //Add header and message type - var maxPacketSize = 228; //57 (OK packet size) * 4, + 4 byte 0xFF header, has to be less than 255 - header + // 224, down from 228. A credential id is 255 bytes with a 10-byte + // header, so one assertion carries 245, and the transit framing costs + // 20 of those (4-byte counter + 16-byte tag): 224 + 20 = 244. + // + // This changes no chunk count. RSA-4096 is 512 bytes and still takes 3 + // chunks, an ML-KEM-768 ciphertext is 1088 and still takes 5, and a + // derived X-Wing [label(32) | ct(1120)] is 1152 and still takes 6. The + // tag is free in round trips; it only eats slack. + var maxPacketSize = 224; //57 (OK packet size) * 4 - 4, leaving room for the transit frame var finalPacket = cipherText.length - maxPacketSize <= 0; var ctChunk; packetnum++; @@ -228,7 +253,7 @@ module.exports = function(imports) { ctChunk = cipherText.slice(0, maxPacketSize); } Array.prototype.push.apply(message, ctChunk); - var encryptedmsg = await aesgcm_encrypt(message, onlykeyApi.sharedsec); + var encryptedmsg = await transit_seal(message, onlykeyApi.sharedsec); if (OKSIGN == slot) imports.app.emit("ok-signing"); if (OKDECRYPT == slot) imports.app.emit("ok-decrypting"); diff --git a/src/onlykey-fido2/onlykey/onlykey.extra.js b/src/onlykey-fido2/onlykey/onlykey.extra.js index 80b868b9..1c4a9776 100644 --- a/src/onlykey-fido2/onlykey/onlykey.extra.js +++ b/src/onlykey-fido2/onlykey/onlykey.extra.js @@ -292,7 +292,132 @@ module.exports = function(imports) { }; - var counter = 0; + // ---- FIDO2 transit framing ------------------------------------------- + // + // v1 (aesgcm_encrypt / aesgcm_decrypt below) is AES-GCM under the transit + // key with `counter` pinned at 0 - an all-zero IV on every message of a + // session, in both directions - and tagLength 0, i.e. no authentication at + // all. Same key and same IV means the same keystream, so any two messages in + // a session XOR to the XOR of their plaintexts, and the device's own status + // string is available in the clear from the plain OKCONNECT response to seed + // it. A derived X-Wing shared secret is 32 bytes and starts at keystream + // offset zero. + // + // v2 frames every message as + // + // [counter big-endian(4)][ciphertext(n)][tag(16)] + // + // with IV = [dir(1)][counter(4)][zero(7)], dir 0 device->host and 1 + // host->device so the two directions can never collide on an IV. The counter + // travels on the wire rather than being tracked on both sides: Windows 10 + // 1903 delivers every FIDO2 request twice, and a derive request rekeys the + // device mid-session, so any receiver-side counter would drift and then fail + // every message after the drift. + // + // v1 is kept because it is what older firmware speaks. transit_select() picks + // the scheme from the firmware version, which the host learns from the plain + // OKCONNECT response - that one is NOT encrypted (opt3 is 0 on that request), + // so it is readable before any of this applies. + var counter = 0; // v1 only. Deliberately never incremented; see above. + + var TRANSIT_V2_MIN = [3, 0, 5]; + var transit = { v2: false, ctrOut: 0 }; + $exports.transit = transit; + + /** Pick v1 or v2 from a firmware version string like "v3.0.5-prod". */ + $exports.transit_select = function transit_select(fwversion) { + var m = /v?(\d+)\.(\d+)\.(\d+)/.exec(String(fwversion || '')); + transit.v2 = false; + if (m) { + var got = [+m[1], +m[2], +m[3]]; + for (var i = 0; i < 3; i++) { + if (got[i] !== TRANSIT_V2_MIN[i]) { transit.v2 = got[i] > TRANSIT_V2_MIN[i]; break; } + if (i === 2) transit.v2 = true; + } + } + transit.ctrOut = 0; + console.info('Transit framing:', transit.v2 ? 'v2 (counter + tag)' : 'v1 (legacy)'); + return transit.v2; + }; + + /** Wire length of a message whose plaintext is n bytes. Callers that have to + * state an expected response size up front - poll_for_response() checks the + * chunk shape against it - need the FRAMED size, not the plaintext size. */ + $exports.transit_framed = function transit_framed(n) { + return transit.v2 ? n + 4 + 16 : n; + }; + + /** Restart the counter. MUST be called wherever the transit key is replaced - + * which includes every derive, because a derive request is itself an + * OKCONNECT and the device rolls its key on each one. */ + $exports.transit_reset = function transit_reset() { + transit.ctrOut = 0; + }; + + function transit_iv(dir, ctr) { + return Uint8Array.from([ + dir, + (ctr >>> 24) & 0xff, (ctr >>> 16) & 0xff, (ctr >>> 8) & 0xff, ctr & 0xff, + 0, 0, 0, 0, 0, 0, 0 + ]); + } + + function bytesFromHex(hex) { + if (!hex) return []; + return hex.match(/.{2}/g).map($exports.hexStrToDec); + } + + /** + * Seal a host->device message. Returns [counter(4)][ciphertext][tag(16)]. + * Falls back to v1 against older firmware. + */ + $exports.transit_seal = function transit_seal(plaintext, shared_sec) { + if (!transit.v2) return $exports.aesgcm_encrypt(plaintext, shared_sec); + return new Promise(resolve => { + forge.options.usePureJavaScript = true; + var ctr = transit.ctrOut++; + var key = $exports.sha256(shared_sec); //AES256 key sha256 hash of shared secret + var cipher = forge.cipher.createCipher('AES-GCM', key); + cipher.start({ iv: transit_iv(1, ctr), tagLength: 128 }); + cipher.update(forge.util.createBuffer(Uint8Array.from(plaintext))); + cipher.finish(); + var frame = [(ctr >>> 24) & 0xff, (ctr >>> 16) & 0xff, (ctr >>> 8) & 0xff, ctr & 0xff]; + resolve(frame.concat(bytesFromHex(cipher.output.toHex()), + bytesFromHex(cipher.mode.tag.toHex()))); + }); + }; + + /** + * Open a device->host message. Throws if the tag does not verify - the bytes + * did not come from something holding the transit key, and there is no + * partial acceptance. + */ + $exports.transit_open = function transit_open(frame, shared_sec) { + if (!transit.v2) return $exports.aesgcm_decrypt(frame, shared_sec); + return new Promise((resolve, reject) => { + forge.options.usePureJavaScript = true; + frame = Array.from(frame); + if (frame.length < 20) { + return reject(new Error('transit: frame too short (' + frame.length + ' bytes)')); + } + var ctr = ((frame[0] << 24) >>> 0) + (frame[1] << 16) + (frame[2] << 8) + frame[3]; + var ct = frame.slice(4, frame.length - 16); + var tag = frame.slice(frame.length - 16); + var key = $exports.sha256(shared_sec); + var decipher = forge.cipher.createDecipher('AES-GCM', key); + decipher.start({ + iv: transit_iv(0, ctr), + tagLength: 128, + tag: forge.util.createBuffer(Uint8Array.from(tag)) + }); + if (ct.length) decipher.update(forge.util.createBuffer(Uint8Array.from(ct))); + if (!decipher.finish()) { + return reject(new Error('transit: message failed authentication')); + } + resolve(bytesFromHex(decipher.output.toHex())); + }); + }; + /** * Perform AES_256_GCM decryption using NACL shared secret * @param {Array} encrypted diff --git a/src/plugins-devel.js b/src/plugins-devel.js index f14643ee..7e78f23b 100644 --- a/src/plugins-devel.js +++ b/src/plugins-devel.js @@ -7,23 +7,12 @@ if (!!(process.env.NODE_ENV === "production")) { //just in case this file gets included somehow in production console.log("WARNING! ------------- LOADING DEVEL PLUGINS! ------------- WARNING!"); - module.exports = []; - /* debug console emitter */ module.exports.push(require("./plugins/console/console_debug.js")); -/* chat plugin */ -module.exports.push(require("./plugins/chat/chat.js")); - -/* for encrypted data to for onlykey devices */ -module.exports.push(require("./lib/history.js")); - - -module.exports.push(require("./plugins/password-generator/password-generator.js")); - -module.exports.push(require("./plugins/age-derive/age-derive.js")); + -module.exports.push(require("./plugins/pgp-pqc/pgp-pqc.js")); - \ No newline at end of file +/* vault: prerelease, development builds only */ +module.exports.push(require("./plugins/vault/vault.js")); diff --git a/src/plugins.js b/src/plugins.js index 5b388bb7..f9d16e44 100644 --- a/src/plugins.js +++ b/src/plugins.js @@ -45,17 +45,38 @@ module.exports.push(require("./plugins/decrypt/decrypt.js")); module.exports.push(require("./plugins/search/search.js")); -module.exports.push(require("./plugins/vault/vault.js")); - module.exports.push(require("./plugins/ok-status-icon/ok-status-icon.js")); +// The PQC pages ship. They were in plugins-devel.js, which is development-only +// and throws if it ever reaches a production bundle - so `BUILD.sh 1` produced +// a site with no /app/age-derive.html and no /app/pgp-pqc.html at all, while +// the deployed site (a dev build) had them. That split meant the thing being +// released was never the thing being built for release. +module.exports.push(require("./plugins/age-derive/age-derive.js")); + +module.exports.push(require("./plugins/pgp-pqc/pgp-pqc.js")); + if (!!(process.env.NODE_ENV === "production")) {//is production //production only plugins (we should have sister plugins enabled in plugins-devel.js) - /* debug console omitter (remove console output) - you can use `window.console` to force output in production */ - module.exports.push(require("./plugins/console/console.js")); + // ------------------------------------------------------------------------ + // TODO BEFORE REAL PRODUCTION RELEASE: swap console_debug.js back to + // console.js here. + // + // Both plugins PROVIDE the "console" service that other plugins consume - + // console.js registers no-op methods (output suppressed), console_debug.js + // registers the real console. Removing the line entirely breaks the app + // with "Could not resolve dependencies / Missing services: console", so the + // swap has to be console.js <-> console_debug.js, not a deletion. + // + // onlyagent.app is a TEST deployment - real production will be a different + // host - and this build is what we test firmware against. With output + // suppressed the app reported nothing at all when the FIDO2 derived-key + // path hung on 2026-09-15: no error, no log, just a page that never + // finished, leaving only the device's (lossy) serial log to diagnose from. + module.exports.push(require("./plugins/console/console_debug.js")); + // ------------------------------------------------------------------------ }else{//is development //instead of including DEV plugins in production builds, diff --git a/src/plugins/.DS_Store b/src/plugins/.DS_Store new file mode 100644 index 00000000..191d3b91 Binary files /dev/null and b/src/plugins/.DS_Store differ diff --git a/src/plugins/age-derive/age-derive.js b/src/plugins/age-derive/age-derive.js index 5a4c7c78..2c08103f 100644 --- a/src/plugins/age-derive/age-derive.js +++ b/src/plugins/age-derive/age-derive.js @@ -42,7 +42,6 @@ module.exports = { init: function(app, $page, pathname) { init = true; - page.setup(app, $page, pathname); }, setup: function(app, $page, pathname) { @@ -56,16 +55,16 @@ module.exports = { var ok = onlykey3rd(1, 0); var $ = app.$; - // press_required=false requests the non-REQ_PRESS "derived - // keys per site without touch" path (same device setting - // password-generator.js relies on), matching this - // feature's non-interactive encrypt/decrypt flow. - var press_required = false; - - // Show the 3-digit challenge code the device will ask for when - // web derived keys are set to Challenge Code mode. onlykey-3rd- - // party.js emits it right before the WebAuthn prompt goes up and - // emits null to clear it once the derive returns. + // The REQ_PRESS opcode variants are gone - one label, one key - + // and there is no press_required argument any more. Whether a + // confirmation is required now follows from what is being + // asked for: a public key never needs one, a shared secret + // always does, and the device enforces that itself. + // + // The challenge code is no longer precomputed here either. The + // device hashes the reassembled label and ciphertext and shows + // the digits itself; this listener stays for the event, but + // nothing emits a code on the derived path now. ok.on("challenge", function(code) { var box = document.getElementById("challenge_code_box"); var out = document.getElementById("challenge_code"); @@ -91,12 +90,13 @@ module.exports = { var label = currentLabel(); var plaintext = $("#plaintext").val(); $("#age_file_out").val(""); - ok.derive_xwing_recipient(label, press_required, function(error, pkX, mlkemSeed) { + // The device returns the whole 1216-byte recipient now, + // so there is nothing to assemble from halves here. + ok.derive_xwing_recipient(label, function(error, recipientPk) { if (error) { $("#age_file_out").val("ERROR: " + error); return; } - var recipientPk = agePqc.buildRecipient(pkX, mlkemSeed); var encaps = agePqc.xwingEncapsHost(recipientPk); var fileBytes = ageFile.encryptAgeFile( new TextEncoder().encode(plaintext), @@ -120,17 +120,14 @@ module.exports = { ageFile.decryptAgeFile(fileBytes, function(ciphertext) { return new Promise(function(resolve, reject) { - ok.derive_xwing_recipient(label, press_required, function(error, pkX, mlkemSeed) { + // One call, and no host-side ML-KEM. The device + // takes the whole X-Wing ciphertext and returns the + // finished 32-byte shared secret, so the recipient + // lookup that used to be needed here (to feed pk_X + // and the seed into splitDecapsulate) is gone. + ok.derive_xwing_decap(label, ciphertext, function(error, ss) { if (error) { reject(new Error(error)); return; } - var ctX = agePqc.ctXOf(ciphertext); - ok.derive_xwing_decap(label, ctX, press_required, function(error2, ssX) { - if (error2) { reject(new Error(error2)); return; } - try { - resolve(agePqc.splitDecapsulate(ssX, ciphertext, pkX, mlkemSeed)); - } catch (e) { - reject(e); - } - }); + resolve(ss); }); }); }).then(function(plaintextBytes) { @@ -150,6 +147,5 @@ module.exports = { } }); - } }; diff --git a/src/plugins/chat/chat.js b/src/plugins/chat/chat.js deleted file mode 100644 index 29dcdedc..00000000 --- a/src/plugins/chat/chat.js +++ /dev/null @@ -1,51 +0,0 @@ - - -var pagesList = { - "chat":{ - icon:"fa-comments-o", - sort:40 - } -}; - -module.exports = { - pagesList: pagesList, - consumes: ["app"], - provides: ["plugin_chat"], - setup: function(options, imports, register) { - - var init = false; - - console.log("chat plugin") - - var page = { - view : require("./chat.page.html").default, - init:function(app, $page, pathname){ - init = true; - - page.setup(app, $page, pathname); - }, - setup:function(app, $page, pathname){ - if (!init) - return page.init(app, $page, pathname); - - app.$(".app-head").hide(); - - }, - dispose:function(app, pathname){ - app.$(".app-head").show(); - } - }; - - pagesList["chat"] = page; - - // console.log("pre-init"); - - register(null, { - plugin_chat:{ - pagesList:pagesList - } - }); - - - } -}; \ No newline at end of file diff --git a/src/plugins/chat/chat.page.html b/src/plugins/chat/chat.page.html deleted file mode 100644 index a5b570b4..00000000 --- a/src/plugins/chat/chat.page.html +++ /dev/null @@ -1 +0,0 @@ -

Chat Page

\ No newline at end of file diff --git a/src/plugins/password-generator/password-generator.js b/src/plugins/password-generator/password-generator.js deleted file mode 100644 index 551d7eab..00000000 --- a/src/plugins/password-generator/password-generator.js +++ /dev/null @@ -1,78 +0,0 @@ -//change _template_ to your plugin name - -var pagesList = { - "password-generator": { - sort:35, - icon: "fa-key", - // title: "Chat" - } -}; - - -module.exports = { - pagesList: pagesList, - consumes: ["app"], - provides: ["plugin_password-generator"], - setup: function(options, imports, register) { - - var init = false; - var page = { - view: require("./password-generator.page.html").default, - init: function(app, $page, pathname) { - init = true; - - - page.setup(app, $page, pathname); - }, - setup: function(app, $page, pathname) { - if (!init) - return page.init(app, $page, pathname); - - - // node-onlykey's onlykey3rd() constructor (function - // onlykey(), onlykey-3rd-party.js) takes no arguments in the - // currently-bundled library version - keytype/press_required - // are per-call arguments on derive_public_key/ - // derive_shared_secret themselves, not bound at construction. - // The `onlykey3rd(1, 0)` call below is a harmless no-op - // (extra args to a zero-arg function), kept only to match - // history.js's still-working call for consistency. - var onlykey3rd = app.onlykey3rd; - var ok = onlykey3rd(1, 0); - var $ = app.$; - - // KEYTYPE.P256R1 = 1 - the only keytype for which - // derive_public_key()/derive_shared_secret() do a real - // ECDH derivation (P256, via ONLYKEY_ECDH_P256_to_EPUB / - // EPUB_TO_ONLYKEY_ECDH_P256), matching this two-step - // pubkey -> shared-secret pattern. press_required=false - // requests the non-REQ_PRESS "derived keys per site - // without touch" path (device setting gated behind - // derived_key_challenge_mode bit 3). - var KEYTYPE_P256R1 = 1; - var press_required = false; - - $("#onlykey_start").click(async function() { - var phrase = $("#phrase").val(); - ok.derive_public_key(phrase, KEYTYPE_P256R1, press_required, function(error, phrasePubkey) { - if (error) return; // e.g. CTAP2_ERR_EXTENSION_NOT_SUPPORTED when blocked - ok.derive_shared_secret(phrase, phrasePubkey, KEYTYPE_P256R1, press_required, async function(error, phrasePubkeySecret) { - if (error) return; - $("#phrase_out").val(phrasePubkeySecret); - }); - }); - }); - } - }; - - pagesList["password-generator"] = page; - - register(null, { - "plugin_password-generator": { - pagesList: pagesList - } - }); - - - } -}; \ No newline at end of file diff --git a/src/plugins/password-generator/password-generator.page.html b/src/plugins/password-generator/password-generator.page.html deleted file mode 100644 index c3e13e46..00000000 --- a/src/plugins/password-generator/password-generator.page.html +++ /dev/null @@ -1,20 +0,0 @@ -

- Securely create static passwords with - OnlyKey -

-
- - - - -
-
-

Console Messages from OnlyKey Appear Below

-
-            
-                
-                    
-
-
-
-
\ No newline at end of file