diff --git a/.gitignore b/.gitignore
deleted file mode 100644
index 3f139f8..0000000
--- a/.gitignore
+++ /dev/null
@@ -1,121 +0,0 @@
-# ---> Node
-# Logs
-logs
-*.log
-npm-debug.log*
-yarn-debug.log*
-yarn-error.log*
-lerna-debug.log*
-
-# Diagnostic reports (https://nodejs.org/api/report.html)
-report.[0-9]*.[0-9]*.[0-9]*.[0-9]*.json
-
-# Runtime data
-pids
-*.pid
-*.seed
-*.pid.lock
-
-# Directory for instrumented libs generated by jscoverage/JSCover
-lib-cov
-
-# Coverage directory used by tools like istanbul
-coverage
-*.lcov
-
-# nyc test coverage
-.nyc_output
-
-# Grunt intermediate storage (https://gruntjs.com/creating-plugins#storing-task-files)
-.grunt
-
-# Bower dependency directory (https://bower.io/)
-bower_components
-
-# node-waf configuration
-.lock-wscript
-
-# Compiled binary addons (https://nodejs.org/api/addons.html)
-build/Release
-
-# Dependency directories
-node_modules/
-jspm_packages/
-
-# Snowpack dependency directory (https://snowpack.dev/)
-web_modules/
-
-# TypeScript cache
-*.tsbuildinfo
-
-# Optional npm cache directory
-.npm
-
-# Optional eslint cache
-.eslintcache
-
-# Microbundle cache
-.rpt2_cache/
-.rts2_cache_cjs/
-.rts2_cache_es/
-.rts2_cache_umd/
-
-# Optional REPL history
-.node_repl_history
-
-# Output of 'npm pack'
-*.tgz
-
-# Yarn Integrity file
-.yarn-integrity
-
-# dotenv environment variables file
-.env
-.env.test
-
-# parcel-bundler cache (https://parceljs.org/)
-.cache
-.parcel-cache
-
-# Next.js build output
-.next
-out
-
-# Nuxt.js build / generate output
-.nuxt
-dist
-
-# Gatsby files
-.cache/
-# Comment in the public line in if your project uses Gatsby and not Next.js
-# https://nextjs.org/blog/next-9-1#public-directory-support
-# public
-
-# vuepress build output
-.vuepress/dist
-
-# Serverless directories
-.serverless/
-
-# FuseBox cache
-.fusebox/
-
-# DynamoDB Local files
-.dynamodb/
-
-# TernJS port file
-.tern-port
-
-# Stores VSCode versions used for testing VSCode extensions
-.vscode-test
-
-# yarn v2
-.yarn/cache
-.yarn/unplugged
-.yarn/build-state.yml
-.yarn/install-state.gz
-.pnp.*
-
-
-
-config.js
\ No newline at end of file
diff --git a/node_modules/.bin/mime b/node_modules/.bin/mime
new file mode 120000
index 0000000..fbb7ee0
--- /dev/null
+++ b/node_modules/.bin/mime
@@ -0,0 +1 @@
+../mime/cli.js
\ No newline at end of file
diff --git a/node_modules/.bin/semver b/node_modules/.bin/semver
new file mode 120000
index 0000000..317eb29
--- /dev/null
+++ b/node_modules/.bin/semver
@@ -0,0 +1 @@
+../semver/bin/semver
\ No newline at end of file
diff --git a/node_modules/.bin/uuid b/node_modules/.bin/uuid
new file mode 120000
index 0000000..588f70e
--- /dev/null
+++ b/node_modules/.bin/uuid
@@ -0,0 +1 @@
+../uuid/dist/bin/uuid
\ No newline at end of file
diff --git a/node_modules/.package-lock.json b/node_modules/.package-lock.json
new file mode 100644
index 0000000..5301473
--- /dev/null
+++ b/node_modules/.package-lock.json
@@ -0,0 +1,693 @@
+{
+ "name": "msal-node-auth-code",
+ "version": "1.0.0",
+ "lockfileVersion": 2,
+ "requires": true,
+ "packages": {
+ "node_modules/@azure/msal-common": {
+ "version": "4.0.1",
+ "resolved": "https://registry.npmjs.org/@azure/msal-common/-/msal-common-4.0.1.tgz",
+ "integrity": "sha512-dHdTmLnRpqGasqAUCOzDt9Os8rke1cRk6Mo6yeI0ucis+G/CwLFQ2G08SEdPfZZnvemhTRP0l70UBPax1Gwxmw==",
+ "dependencies": {
+ "debug": "^4.1.1"
+ },
+ "engines": {
+ "node": ">=0.8.0"
+ }
+ },
+ "node_modules/@azure/msal-node": {
+ "version": "1.0.0",
+ "resolved": "https://registry.npmjs.org/@azure/msal-node/-/msal-node-1.0.0.tgz",
+ "integrity": "sha512-uc8B9n9U6IRVsCLOn1D39GhuA8CzbxP8MUl53Sr9hyAjJG4W7139dZSCnZ6VCBlgqm7VmtDSKOaOBWvbBjcJzg==",
+ "dependencies": {
+ "@azure/msal-common": "^4.0.1",
+ "axios": "^0.21.1",
+ "jsonwebtoken": "^8.5.1",
+ "uuid": "^8.3.0"
+ },
+ "engines": {
+ "node": "10 || 12 || 14"
+ }
+ },
+ "node_modules/accepts": {
+ "version": "1.3.7",
+ "resolved": "https://registry.npmjs.org/accepts/-/accepts-1.3.7.tgz",
+ "integrity": "sha512-Il80Qs2WjYlJIBNzNkK6KYqlVMTbZLXgHx2oT0pU/fjRHyEp+PEfEPY0R3WCwAGVOtauxh1hOxNgIf5bv7dQpA==",
+ "dependencies": {
+ "mime-types": "~2.1.24",
+ "negotiator": "0.6.2"
+ },
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/array-flatten": {
+ "version": "1.1.1",
+ "resolved": "https://registry.npmjs.org/array-flatten/-/array-flatten-1.1.1.tgz",
+ "integrity": "sha1-ml9pkFGx5wczKPKgCJaLZOopVdI="
+ },
+ "node_modules/axios": {
+ "version": "0.21.1",
+ "resolved": "https://registry.npmjs.org/axios/-/axios-0.21.1.tgz",
+ "integrity": "sha512-dKQiRHxGD9PPRIUNIWvZhPTPpl1rf/OxTYKsqKUDjBwYylTvV7SjSHJb9ratfyzM6wCdLCOYLzs73qpg5c4iGA==",
+ "dependencies": {
+ "follow-redirects": "^1.10.0"
+ }
+ },
+ "node_modules/body-parser": {
+ "version": "1.19.0",
+ "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.19.0.tgz",
+ "integrity": "sha512-dhEPs72UPbDnAQJ9ZKMNTP6ptJaionhP5cBb541nXPlW60Jepo9RV/a4fX4XWW9CuFNK22krhrj1+rgzifNCsw==",
+ "dependencies": {
+ "bytes": "3.1.0",
+ "content-type": "~1.0.4",
+ "debug": "2.6.9",
+ "depd": "~1.1.2",
+ "http-errors": "1.7.2",
+ "iconv-lite": "0.4.24",
+ "on-finished": "~2.3.0",
+ "qs": "6.7.0",
+ "raw-body": "2.4.0",
+ "type-is": "~1.6.17"
+ },
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/body-parser/node_modules/debug": {
+ "version": "2.6.9",
+ "resolved": "https://registry.npmjs.org/debug/-/debug-2.6.9.tgz",
+ "integrity": "sha512-bC7ElrdJaJnPbAP+1EotYvqZsb3ecl5wi6Bfi6BJTUcNowp6cvspg0jXznRTKDjm/E7AdgFBVeAPVMNcKGsHMA==",
+ "dependencies": {
+ "ms": "2.0.0"
+ }
+ },
+ "node_modules/body-parser/node_modules/ms": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/ms/-/ms-2.0.0.tgz",
+ "integrity": "sha1-VgiurfwAvmwpAd9fmGF4jeDVl8g="
+ },
+ "node_modules/buffer-equal-constant-time": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/buffer-equal-constant-time/-/buffer-equal-constant-time-1.0.1.tgz",
+ "integrity": "sha1-+OcRMvf/5uAaXJaXpMbz5I1cyBk="
+ },
+ "node_modules/bytes": {
+ "version": "3.1.0",
+ "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.0.tgz",
+ "integrity": "sha512-zauLjrfCG+xvoyaqLoV8bLVXXNGC4JqlxFCutSDWA6fJrTo2ZuvLYTqZ7aHBLZSMOopbzwv8f+wZcVzfVTI2Dg==",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/content-disposition": {
+ "version": "0.5.3",
+ "resolved": "https://registry.npmjs.org/content-disposition/-/content-disposition-0.5.3.tgz",
+ "integrity": "sha512-ExO0774ikEObIAEV9kDo50o+79VCUdEB6n6lzKgGwupcVeRlhrj3qGAfwq8G6uBJjkqLrhT0qEYFcWng8z1z0g==",
+ "dependencies": {
+ "safe-buffer": "5.1.2"
+ },
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/content-disposition/node_modules/safe-buffer": {
+ "version": "5.1.2",
+ "resolved": "https://registry.npmjs.org/safe-buffer/-/safe-buffer-5.1.2.tgz",
+ "integrity": "sha512-Gd2UZBJDkXlY7GbJxfsE8/nvKkUEU1G38c1siN6QP6a9PT9MmHB8GnpscSmMJSoF8LOIrt8ud/wPtojys4G6+g=="
+ },
+ "node_modules/content-type": {
+ "version": "1.0.4",
+ "resolved": "https://registry.npmjs.org/content-type/-/content-type-1.0.4.tgz",
+ "integrity": "sha512-hIP3EEPs8tB9AT1L+NUqtwOAps4mk2Zob89MWXMHjHWg9milF/j4osnnQLXBCBFBk/tvIG/tUc9mOUJiPBhPXA==",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/cookie": {
+ "version": "0.4.0",
+ "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.4.0.tgz",
+ "integrity": "sha512-+Hp8fLp57wnUSt0tY0tHEXh4voZRDnoIrZPqlo3DPiI4y9lwg/jqx+1Om94/W6ZaPDOUbnjOt/99w66zk+l1Xg==",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/cookie-signature": {
+ "version": "1.0.6",
+ "resolved": "https://registry.npmjs.org/cookie-signature/-/cookie-signature-1.0.6.tgz",
+ "integrity": "sha1-4wOogrNCzD7oylE6eZmXNNqzriw="
+ },
+ "node_modules/debug": {
+ "version": "4.3.1",
+ "resolved": "https://registry.npmjs.org/debug/-/debug-4.3.1.tgz",
+ "integrity": "sha512-doEwdvm4PCeK4K3RQN2ZC2BYUBaxwLARCqZmMjtF8a51J2Rb0xpVloFRnCODwqjpwnAoao4pelN8l3RJdv3gRQ==",
+ "dependencies": {
+ "ms": "2.1.2"
+ },
+ "engines": {
+ "node": ">=6.0"
+ }
+ },
+ "node_modules/depd": {
+ "version": "1.1.2",
+ "resolved": "https://registry.npmjs.org/depd/-/depd-1.1.2.tgz",
+ "integrity": "sha1-m81S4UwJd2PnSbJ0xDRu0uVgtak=",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/destroy": {
+ "version": "1.0.4",
+ "resolved": "https://registry.npmjs.org/destroy/-/destroy-1.0.4.tgz",
+ "integrity": "sha1-l4hXRCxEdJ5CBmE+N5RiBYJqvYA="
+ },
+ "node_modules/ecdsa-sig-formatter": {
+ "version": "1.0.11",
+ "resolved": "https://registry.npmjs.org/ecdsa-sig-formatter/-/ecdsa-sig-formatter-1.0.11.tgz",
+ "integrity": "sha512-nagl3RYrbNv6kQkeJIpt6NJZy8twLB/2vtz6yN9Z4vRKHN4/QZJIEbqohALSgwKdnksuY3k5Addp5lg8sVoVcQ==",
+ "dependencies": {
+ "safe-buffer": "^5.0.1"
+ }
+ },
+ "node_modules/ee-first": {
+ "version": "1.1.1",
+ "resolved": "https://registry.npmjs.org/ee-first/-/ee-first-1.1.1.tgz",
+ "integrity": "sha1-WQxhFWsK4vTwJVcyoViyZrxWsh0="
+ },
+ "node_modules/encodeurl": {
+ "version": "1.0.2",
+ "resolved": "https://registry.npmjs.org/encodeurl/-/encodeurl-1.0.2.tgz",
+ "integrity": "sha1-rT/0yG7C0CkyL1oCw6mmBslbP1k=",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/escape-html": {
+ "version": "1.0.3",
+ "resolved": "https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz",
+ "integrity": "sha1-Aljq5NPQwJdN4cFpGI7wBR0dGYg="
+ },
+ "node_modules/etag": {
+ "version": "1.8.1",
+ "resolved": "https://registry.npmjs.org/etag/-/etag-1.8.1.tgz",
+ "integrity": "sha1-Qa4u62XvpiJorr/qg6x9eSmbCIc=",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/express": {
+ "version": "4.17.1",
+ "resolved": "https://registry.npmjs.org/express/-/express-4.17.1.tgz",
+ "integrity": "sha512-mHJ9O79RqluphRrcw2X/GTh3k9tVv8YcoyY4Kkh4WDMUYKRZUq0h1o0w2rrrxBqM7VoeUVqgb27xlEMXTnYt4g==",
+ "dependencies": {
+ "accepts": "~1.3.7",
+ "array-flatten": "1.1.1",
+ "body-parser": "1.19.0",
+ "content-disposition": "0.5.3",
+ "content-type": "~1.0.4",
+ "cookie": "0.4.0",
+ "cookie-signature": "1.0.6",
+ "debug": "2.6.9",
+ "depd": "~1.1.2",
+ "encodeurl": "~1.0.2",
+ "escape-html": "~1.0.3",
+ "etag": "~1.8.1",
+ "finalhandler": "~1.1.2",
+ "fresh": "0.5.2",
+ "merge-descriptors": "1.0.1",
+ "methods": "~1.1.2",
+ "on-finished": "~2.3.0",
+ "parseurl": "~1.3.3",
+ "path-to-regexp": "0.1.7",
+ "proxy-addr": "~2.0.5",
+ "qs": "6.7.0",
+ "range-parser": "~1.2.1",
+ "safe-buffer": "5.1.2",
+ "send": "0.17.1",
+ "serve-static": "1.14.1",
+ "setprototypeof": "1.1.1",
+ "statuses": "~1.5.0",
+ "type-is": "~1.6.18",
+ "utils-merge": "1.0.1",
+ "vary": "~1.1.2"
+ },
+ "engines": {
+ "node": ">= 0.10.0"
+ }
+ },
+ "node_modules/express/node_modules/debug": {
+ "version": "2.6.9",
+ "resolved": "https://registry.npmjs.org/debug/-/debug-2.6.9.tgz",
+ "integrity": "sha512-bC7ElrdJaJnPbAP+1EotYvqZsb3ecl5wi6Bfi6BJTUcNowp6cvspg0jXznRTKDjm/E7AdgFBVeAPVMNcKGsHMA==",
+ "dependencies": {
+ "ms": "2.0.0"
+ }
+ },
+ "node_modules/express/node_modules/ms": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/ms/-/ms-2.0.0.tgz",
+ "integrity": "sha1-VgiurfwAvmwpAd9fmGF4jeDVl8g="
+ },
+ "node_modules/express/node_modules/safe-buffer": {
+ "version": "5.1.2",
+ "resolved": "https://registry.npmjs.org/safe-buffer/-/safe-buffer-5.1.2.tgz",
+ "integrity": "sha512-Gd2UZBJDkXlY7GbJxfsE8/nvKkUEU1G38c1siN6QP6a9PT9MmHB8GnpscSmMJSoF8LOIrt8ud/wPtojys4G6+g=="
+ },
+ "node_modules/finalhandler": {
+ "version": "1.1.2",
+ "resolved": "https://registry.npmjs.org/finalhandler/-/finalhandler-1.1.2.tgz",
+ "integrity": "sha512-aAWcW57uxVNrQZqFXjITpW3sIUQmHGG3qSb9mUah9MgMC4NeWhNOlNjXEYq3HjRAvL6arUviZGGJsBg6z0zsWA==",
+ "dependencies": {
+ "debug": "2.6.9",
+ "encodeurl": "~1.0.2",
+ "escape-html": "~1.0.3",
+ "on-finished": "~2.3.0",
+ "parseurl": "~1.3.3",
+ "statuses": "~1.5.0",
+ "unpipe": "~1.0.0"
+ },
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/finalhandler/node_modules/debug": {
+ "version": "2.6.9",
+ "resolved": "https://registry.npmjs.org/debug/-/debug-2.6.9.tgz",
+ "integrity": "sha512-bC7ElrdJaJnPbAP+1EotYvqZsb3ecl5wi6Bfi6BJTUcNowp6cvspg0jXznRTKDjm/E7AdgFBVeAPVMNcKGsHMA==",
+ "dependencies": {
+ "ms": "2.0.0"
+ }
+ },
+ "node_modules/finalhandler/node_modules/ms": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/ms/-/ms-2.0.0.tgz",
+ "integrity": "sha1-VgiurfwAvmwpAd9fmGF4jeDVl8g="
+ },
+ "node_modules/follow-redirects": {
+ "version": "1.13.2",
+ "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.13.2.tgz",
+ "integrity": "sha512-6mPTgLxYm3r6Bkkg0vNM0HTjfGrOEtsfbhagQvbxDEsEkpNhw582upBaoRZylzen6krEmxXJgt9Ju6HiI4O7BA==",
+ "engines": {
+ "node": ">=4.0"
+ }
+ },
+ "node_modules/forwarded": {
+ "version": "0.1.2",
+ "resolved": "https://registry.npmjs.org/forwarded/-/forwarded-0.1.2.tgz",
+ "integrity": "sha1-mMI9qxF1ZXuMBXPozszZGw/xjIQ=",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/fresh": {
+ "version": "0.5.2",
+ "resolved": "https://registry.npmjs.org/fresh/-/fresh-0.5.2.tgz",
+ "integrity": "sha1-PYyt2Q2XZWn6g1qx+OSyOhBWBac=",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/http-errors": {
+ "version": "1.7.2",
+ "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-1.7.2.tgz",
+ "integrity": "sha512-uUQBt3H/cSIVfch6i1EuPNy/YsRSOUBXTVfZ+yR7Zjez3qjBz6i9+i4zjNaoqcoFVI4lQJ5plg63TvGfRSDCRg==",
+ "dependencies": {
+ "depd": "~1.1.2",
+ "inherits": "2.0.3",
+ "setprototypeof": "1.1.1",
+ "statuses": ">= 1.5.0 < 2",
+ "toidentifier": "1.0.0"
+ },
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/iconv-lite": {
+ "version": "0.4.24",
+ "resolved": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.4.24.tgz",
+ "integrity": "sha512-v3MXnZAcvnywkTUEZomIActle7RXXeedOR31wwl7VlyoXO4Qi9arvSenNQWne1TcRwhCL1HwLI21bEqdpj8/rA==",
+ "dependencies": {
+ "safer-buffer": ">= 2.1.2 < 3"
+ },
+ "engines": {
+ "node": ">=0.10.0"
+ }
+ },
+ "node_modules/inherits": {
+ "version": "2.0.3",
+ "resolved": "https://registry.npmjs.org/inherits/-/inherits-2.0.3.tgz",
+ "integrity": "sha1-Yzwsg+PaQqUC9SRmAiSA9CCCYd4="
+ },
+ "node_modules/ipaddr.js": {
+ "version": "1.9.1",
+ "resolved": "https://registry.npmjs.org/ipaddr.js/-/ipaddr.js-1.9.1.tgz",
+ "integrity": "sha512-0KI/607xoxSToH7GjN1FfSbLoU0+btTicjsQSWQlh/hZykN8KpmMf7uYwPW3R+akZ6R/w18ZlXSHBYXiYUPO3g==",
+ "engines": {
+ "node": ">= 0.10"
+ }
+ },
+ "node_modules/jsonwebtoken": {
+ "version": "8.5.1",
+ "resolved": "https://registry.npmjs.org/jsonwebtoken/-/jsonwebtoken-8.5.1.tgz",
+ "integrity": "sha512-XjwVfRS6jTMsqYs0EsuJ4LGxXV14zQybNd4L2r0UvbVnSF9Af8x7p5MzbJ90Ioz/9TI41/hTCvznF/loiSzn8w==",
+ "dependencies": {
+ "jws": "^3.2.2",
+ "lodash.includes": "^4.3.0",
+ "lodash.isboolean": "^3.0.3",
+ "lodash.isinteger": "^4.0.4",
+ "lodash.isnumber": "^3.0.3",
+ "lodash.isplainobject": "^4.0.6",
+ "lodash.isstring": "^4.0.1",
+ "lodash.once": "^4.0.0",
+ "ms": "^2.1.1",
+ "semver": "^5.6.0"
+ },
+ "engines": {
+ "node": ">=4",
+ "npm": ">=1.4.28"
+ }
+ },
+ "node_modules/jwa": {
+ "version": "1.4.1",
+ "resolved": "https://registry.npmjs.org/jwa/-/jwa-1.4.1.tgz",
+ "integrity": "sha512-qiLX/xhEEFKUAJ6FiBMbes3w9ATzyk5W7Hvzpa/SLYdxNtng+gcurvrI7TbACjIXlsJyr05/S1oUhZrc63evQA==",
+ "dependencies": {
+ "buffer-equal-constant-time": "1.0.1",
+ "ecdsa-sig-formatter": "1.0.11",
+ "safe-buffer": "^5.0.1"
+ }
+ },
+ "node_modules/jws": {
+ "version": "3.2.2",
+ "resolved": "https://registry.npmjs.org/jws/-/jws-3.2.2.tgz",
+ "integrity": "sha512-YHlZCB6lMTllWDtSPHz/ZXTsi8S00usEV6v1tjq8tOUZzw7DpSDWVXjXDre6ed1w/pd495ODpHZYSdkRTsa0HA==",
+ "dependencies": {
+ "jwa": "^1.4.1",
+ "safe-buffer": "^5.0.1"
+ }
+ },
+ "node_modules/lodash.includes": {
+ "version": "4.3.0",
+ "resolved": "https://registry.npmjs.org/lodash.includes/-/lodash.includes-4.3.0.tgz",
+ "integrity": "sha1-YLuYqHy5I8aMoeUTJUgzFISfVT8="
+ },
+ "node_modules/lodash.isboolean": {
+ "version": "3.0.3",
+ "resolved": "https://registry.npmjs.org/lodash.isboolean/-/lodash.isboolean-3.0.3.tgz",
+ "integrity": "sha1-bC4XHbKiV82WgC/UOwGyDV9YcPY="
+ },
+ "node_modules/lodash.isinteger": {
+ "version": "4.0.4",
+ "resolved": "https://registry.npmjs.org/lodash.isinteger/-/lodash.isinteger-4.0.4.tgz",
+ "integrity": "sha1-YZwK89A/iwTDH1iChAt3sRzWg0M="
+ },
+ "node_modules/lodash.isnumber": {
+ "version": "3.0.3",
+ "resolved": "https://registry.npmjs.org/lodash.isnumber/-/lodash.isnumber-3.0.3.tgz",
+ "integrity": "sha1-POdoEMWSjQM1IwGsKHMX8RwLH/w="
+ },
+ "node_modules/lodash.isplainobject": {
+ "version": "4.0.6",
+ "resolved": "https://registry.npmjs.org/lodash.isplainobject/-/lodash.isplainobject-4.0.6.tgz",
+ "integrity": "sha1-fFJqUtibRcRcxpC4gWO+BJf1UMs="
+ },
+ "node_modules/lodash.isstring": {
+ "version": "4.0.1",
+ "resolved": "https://registry.npmjs.org/lodash.isstring/-/lodash.isstring-4.0.1.tgz",
+ "integrity": "sha1-1SfftUVuynzJu5XV2ur4i6VKVFE="
+ },
+ "node_modules/lodash.once": {
+ "version": "4.1.1",
+ "resolved": "https://registry.npmjs.org/lodash.once/-/lodash.once-4.1.1.tgz",
+ "integrity": "sha1-DdOXEhPHxW34gJd9UEyI+0cal6w="
+ },
+ "node_modules/media-typer": {
+ "version": "0.3.0",
+ "resolved": "https://registry.npmjs.org/media-typer/-/media-typer-0.3.0.tgz",
+ "integrity": "sha1-hxDXrwqmJvj/+hzgAWhUUmMlV0g=",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/merge-descriptors": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/merge-descriptors/-/merge-descriptors-1.0.1.tgz",
+ "integrity": "sha1-sAqqVW3YtEVoFQ7J0blT8/kMu2E="
+ },
+ "node_modules/methods": {
+ "version": "1.1.2",
+ "resolved": "https://registry.npmjs.org/methods/-/methods-1.1.2.tgz",
+ "integrity": "sha1-VSmk1nZUE07cxSZmVoNbD4Ua/O4=",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/mime": {
+ "version": "1.6.0",
+ "resolved": "https://registry.npmjs.org/mime/-/mime-1.6.0.tgz",
+ "integrity": "sha512-x0Vn8spI+wuJ1O6S7gnbaQg8Pxh4NNHb7KSINmEWKiPE4RKOplvijn+NkmYmmRgP68mc70j2EbeTFRsrswaQeg==",
+ "bin": {
+ "mime": "cli.js"
+ },
+ "engines": {
+ "node": ">=4"
+ }
+ },
+ "node_modules/mime-db": {
+ "version": "1.46.0",
+ "resolved": "https://registry.npmjs.org/mime-db/-/mime-db-1.46.0.tgz",
+ "integrity": "sha512-svXaP8UQRZ5K7or+ZmfNhg2xX3yKDMUzqadsSqi4NCH/KomcH75MAMYAGVlvXn4+b/xOPhS3I2uHKRUzvjY7BQ==",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/mime-types": {
+ "version": "2.1.29",
+ "resolved": "https://registry.npmjs.org/mime-types/-/mime-types-2.1.29.tgz",
+ "integrity": "sha512-Y/jMt/S5sR9OaqteJtslsFZKWOIIqMACsJSiHghlCAyhf7jfVYjKBmLiX8OgpWeW+fjJ2b+Az69aPFPkUOY6xQ==",
+ "dependencies": {
+ "mime-db": "1.46.0"
+ },
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/ms": {
+ "version": "2.1.2",
+ "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.2.tgz",
+ "integrity": "sha512-sGkPx+VjMtmA6MX27oA4FBFELFCZZ4S4XqeGOXCv68tT+jb3vk/RyaKWP0PTKyWtmLSM0b+adUTEvbs1PEaH2w=="
+ },
+ "node_modules/negotiator": {
+ "version": "0.6.2",
+ "resolved": "https://registry.npmjs.org/negotiator/-/negotiator-0.6.2.tgz",
+ "integrity": "sha512-hZXc7K2e+PgeI1eDBe/10Ard4ekbfrrqG8Ep+8Jmf4JID2bNg7NvCPOZN+kfF574pFQI7mum2AUqDidoKqcTOw==",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/on-finished": {
+ "version": "2.3.0",
+ "resolved": "https://registry.npmjs.org/on-finished/-/on-finished-2.3.0.tgz",
+ "integrity": "sha1-IPEzZIGwg811M3mSoWlxqi2QaUc=",
+ "dependencies": {
+ "ee-first": "1.1.1"
+ },
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/parseurl": {
+ "version": "1.3.3",
+ "resolved": "https://registry.npmjs.org/parseurl/-/parseurl-1.3.3.tgz",
+ "integrity": "sha512-CiyeOxFT/JZyN5m0z9PfXw4SCBJ6Sygz1Dpl0wqjlhDEGGBP1GnsUVEL0p63hoG1fcj3fHynXi9NYO4nWOL+qQ==",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/path-to-regexp": {
+ "version": "0.1.7",
+ "resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-0.1.7.tgz",
+ "integrity": "sha1-32BBeABfUi8V60SQ5yR6G/qmf4w="
+ },
+ "node_modules/proxy-addr": {
+ "version": "2.0.6",
+ "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.6.tgz",
+ "integrity": "sha512-dh/frvCBVmSsDYzw6n926jv974gddhkFPfiN8hPOi30Wax25QZyZEGveluCgliBnqmuM+UJmBErbAUFIoDbjOw==",
+ "dependencies": {
+ "forwarded": "~0.1.2",
+ "ipaddr.js": "1.9.1"
+ },
+ "engines": {
+ "node": ">= 0.10"
+ }
+ },
+ "node_modules/qs": {
+ "version": "6.7.0",
+ "resolved": "https://registry.npmjs.org/qs/-/qs-6.7.0.tgz",
+ "integrity": "sha512-VCdBRNFTX1fyE7Nb6FYoURo/SPe62QCaAyzJvUjwRaIsc+NePBEniHlvxFmmX56+HZphIGtV0XeCirBtpDrTyQ==",
+ "engines": {
+ "node": ">=0.6"
+ }
+ },
+ "node_modules/range-parser": {
+ "version": "1.2.1",
+ "resolved": "https://registry.npmjs.org/range-parser/-/range-parser-1.2.1.tgz",
+ "integrity": "sha512-Hrgsx+orqoygnmhFbKaHE6c296J+HTAQXoxEF6gNupROmmGJRoyzfG3ccAveqCBrwr/2yxQ5BVd/GTl5agOwSg==",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/raw-body": {
+ "version": "2.4.0",
+ "resolved": "https://registry.npmjs.org/raw-body/-/raw-body-2.4.0.tgz",
+ "integrity": "sha512-4Oz8DUIwdvoa5qMJelxipzi/iJIi40O5cGV1wNYp5hvZP8ZN0T+jiNkL0QepXs+EsQ9XJ8ipEDoiH70ySUJP3Q==",
+ "dependencies": {
+ "bytes": "3.1.0",
+ "http-errors": "1.7.2",
+ "iconv-lite": "0.4.24",
+ "unpipe": "1.0.0"
+ },
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/safe-buffer": {
+ "version": "5.2.1",
+ "resolved": "https://registry.npmjs.org/safe-buffer/-/safe-buffer-5.2.1.tgz",
+ "integrity": "sha512-rp3So07KcdmmKbGvgaNxQSJr7bGVSVk5S9Eq1F+ppbRo70+YeaDxkw5Dd8NPN+GD6bjnYm2VuPuCXmpuYvmCXQ=="
+ },
+ "node_modules/safer-buffer": {
+ "version": "2.1.2",
+ "resolved": "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz",
+ "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg=="
+ },
+ "node_modules/semver": {
+ "version": "5.7.1",
+ "resolved": "https://registry.npmjs.org/semver/-/semver-5.7.1.tgz",
+ "integrity": "sha512-sauaDf/PZdVgrLTNYHRtpXa1iRiKcaebiKQ1BJdpQlWH2lCvexQdX55snPFyK7QzpudqbCI0qXFfOasHdyNDGQ==",
+ "bin": {
+ "semver": "bin/semver"
+ }
+ },
+ "node_modules/send": {
+ "version": "0.17.1",
+ "resolved": "https://registry.npmjs.org/send/-/send-0.17.1.tgz",
+ "integrity": "sha512-BsVKsiGcQMFwT8UxypobUKyv7irCNRHk1T0G680vk88yf6LBByGcZJOTJCrTP2xVN6yI+XjPJcNuE3V4fT9sAg==",
+ "dependencies": {
+ "debug": "2.6.9",
+ "depd": "~1.1.2",
+ "destroy": "~1.0.4",
+ "encodeurl": "~1.0.2",
+ "escape-html": "~1.0.3",
+ "etag": "~1.8.1",
+ "fresh": "0.5.2",
+ "http-errors": "~1.7.2",
+ "mime": "1.6.0",
+ "ms": "2.1.1",
+ "on-finished": "~2.3.0",
+ "range-parser": "~1.2.1",
+ "statuses": "~1.5.0"
+ },
+ "engines": {
+ "node": ">= 0.8.0"
+ }
+ },
+ "node_modules/send/node_modules/debug": {
+ "version": "2.6.9",
+ "resolved": "https://registry.npmjs.org/debug/-/debug-2.6.9.tgz",
+ "integrity": "sha512-bC7ElrdJaJnPbAP+1EotYvqZsb3ecl5wi6Bfi6BJTUcNowp6cvspg0jXznRTKDjm/E7AdgFBVeAPVMNcKGsHMA==",
+ "dependencies": {
+ "ms": "2.0.0"
+ }
+ },
+ "node_modules/send/node_modules/debug/node_modules/ms": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/ms/-/ms-2.0.0.tgz",
+ "integrity": "sha1-VgiurfwAvmwpAd9fmGF4jeDVl8g="
+ },
+ "node_modules/send/node_modules/ms": {
+ "version": "2.1.1",
+ "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.1.tgz",
+ "integrity": "sha512-tgp+dl5cGk28utYktBsrFqA7HKgrhgPsg6Z/EfhWI4gl1Hwq8B/GmY/0oXZ6nF8hDVesS/FpnYaD/kOWhYQvyg=="
+ },
+ "node_modules/serve-static": {
+ "version": "1.14.1",
+ "resolved": "https://registry.npmjs.org/serve-static/-/serve-static-1.14.1.tgz",
+ "integrity": "sha512-JMrvUwE54emCYWlTI+hGrGv5I8dEwmco/00EvkzIIsR7MqrHonbD9pO2MOfFnpFntl7ecpZs+3mW+XbQZu9QCg==",
+ "dependencies": {
+ "encodeurl": "~1.0.2",
+ "escape-html": "~1.0.3",
+ "parseurl": "~1.3.3",
+ "send": "0.17.1"
+ },
+ "engines": {
+ "node": ">= 0.8.0"
+ }
+ },
+ "node_modules/setprototypeof": {
+ "version": "1.1.1",
+ "resolved": "https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.1.1.tgz",
+ "integrity": "sha512-JvdAWfbXeIGaZ9cILp38HntZSFSo3mWg6xGcJJsd+d4aRMOqauag1C63dJfDw7OaMYwEbHMOxEZ1lqVRYP2OAw=="
+ },
+ "node_modules/statuses": {
+ "version": "1.5.0",
+ "resolved": "https://registry.npmjs.org/statuses/-/statuses-1.5.0.tgz",
+ "integrity": "sha1-Fhx9rBd2Wf2YEfQ3cfqZOBR4Yow=",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/toidentifier": {
+ "version": "1.0.0",
+ "resolved": "https://registry.npmjs.org/toidentifier/-/toidentifier-1.0.0.tgz",
+ "integrity": "sha512-yaOH/Pk/VEhBWWTlhI+qXxDFXlejDGcQipMlyxda9nthulaxLZUNcUqFxokp0vcYnvteJln5FNQDRrxj3YcbVw==",
+ "engines": {
+ "node": ">=0.6"
+ }
+ },
+ "node_modules/type-is": {
+ "version": "1.6.18",
+ "resolved": "https://registry.npmjs.org/type-is/-/type-is-1.6.18.tgz",
+ "integrity": "sha512-TkRKr9sUTxEH8MdfuCSP7VizJyzRNMjj2J2do2Jr3Kym598JVdEksuzPQCnlFPW4ky9Q+iA+ma9BGm06XQBy8g==",
+ "dependencies": {
+ "media-typer": "0.3.0",
+ "mime-types": "~2.1.24"
+ },
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/unpipe": {
+ "version": "1.0.0",
+ "resolved": "https://registry.npmjs.org/unpipe/-/unpipe-1.0.0.tgz",
+ "integrity": "sha1-sr9O6FFKrmFltIF4KdIbLvSZBOw=",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/utils-merge": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/utils-merge/-/utils-merge-1.0.1.tgz",
+ "integrity": "sha1-n5VxD1CiZ5R7LMwSR0HBAoQn5xM=",
+ "engines": {
+ "node": ">= 0.4.0"
+ }
+ },
+ "node_modules/uuid": {
+ "version": "8.3.2",
+ "resolved": "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz",
+ "integrity": "sha512-+NYs2QeMWy+GWFOEm9xnn6HCDp0l7QBD7ml8zLUmJ+93Q5NF0NocErnwkTkXVFNiX3/fpC6afS8Dhb/gz7R7eg==",
+ "bin": {
+ "uuid": "dist/bin/uuid"
+ }
+ },
+ "node_modules/vary": {
+ "version": "1.1.2",
+ "resolved": "https://registry.npmjs.org/vary/-/vary-1.1.2.tgz",
+ "integrity": "sha1-IpnwLG3tMNSllhsLn3RSShj2NPw=",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ }
+ }
+}
diff --git a/node_modules/@azure/msal-common/CHANGELOG.json b/node_modules/@azure/msal-common/CHANGELOG.json
new file mode 100644
index 0000000..21b0d0b
--- /dev/null
+++ b/node_modules/@azure/msal-common/CHANGELOG.json
@@ -0,0 +1,684 @@
+{
+ "name": "@azure/msal-common",
+ "entries": [
+ {
+ "date": "Thu, 18 Feb 2021 00:34:32 GMT",
+ "tag": "@azure/msal-common_v4.0.1",
+ "version": "4.0.1",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Clarify Device Code Timeout units (#3031)",
+ "author": "hemoral@microsoft.com",
+ "commit": "af97180664ec257f2fdb6f04ab0921affeb9a8f3",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 09 Feb 2021 01:48:22 GMT",
+ "tag": "@azure/msal-common_v4.0.0",
+ "version": "4.0.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Fix version.json import errors (#2993)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "6dc3bc9e2148bc53b181d9f079f6e11e0159620b",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Setting postLogoutRedirectUri as null will disable post logout redirect",
+ "author": "janutter@microsoft.com",
+ "commit": "cae9fa7bdd1575067d2e823402e0725f7bf8b11e",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Ignore OIDC scopes during cache lookup or replacement (#2969)",
+ "author": "prkanher@microsoft.com",
+ "commit": "554f47e8ff576c3230c36df74cd73b6101d333ab",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "major": [
+ {
+ "comment": "Add API Extractor for msal-node",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "01747296efdf08eefe585930097d9bbbf6b00789",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 02 Feb 2021 01:56:47 GMT",
+ "tag": "@azure/msal-common_v3.1.0",
+ "version": "3.1.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Fix token timestamp calculation",
+ "author": "prkanher@microsoft.com",
+ "commit": "12f9fa2b6a9530fac5f7570ee3c49dc39232284c",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Fix B2C policy switching (#2949)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "05eb650487a800d4bb3f94ec9dacca2efa98cc82",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Get package version from version.json (#2915)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "a6f4702f9439e318a8cb6dc65d1def16351a84fd",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "Add wrapper SKU and version to current telemetry header (#2845)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "27597c148c718e3d001309349a4498a958688cbd",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Add project references (#2930)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "a836e77e372f1b4da28195d4ad8c0c75d6794875",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Typedocs Updates (#2926)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "3fd4a48143ed4fb62b9e3266338b1abda920d68a",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 21 Jan 2021 21:48:01 GMT",
+ "tag": "@azure/msal-common_v3.0.0",
+ "version": "3.0.0",
+ "comments": {
+ "major": [
+ {
+ "comment": "Authority metadata caching (#2758)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "28b3268b1385e99249c0b7a95b0b14299011ca46",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Add missing license files",
+ "author": "janutter@microsoft.com",
+ "commit": "bee8cbd1f3a22efccb83ba045231eb611e2a7f7d",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 12 Jan 2021 00:51:26 GMT",
+ "tag": "@azure/msal-common_v2.1.0",
+ "version": "2.1.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Adding account info equality check function (#2728)",
+ "author": "prkanher@microsoft.com",
+ "commit": "ca8c0d55d2abc4eefaa52c833510e313610eb424",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Adding device code timeout to the device code request(#2656)",
+ "author": "samuel.kamau@microsoft.com",
+ "commit": "4e50ca592f5a17578072be9e4ac28e05b3e6d594",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Merge angular-v2 to dev (#2709)",
+ "author": "joarroyo@microsoft.com",
+ "commit": "76a88f98fbab73fd6c0ad6d04b294814c169fc10",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Fix npm audit warnings",
+ "author": "janutter@microsoft.com",
+ "commit": "751026cdaa24dd370c50ad714bf0b1d54c71fbde",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "Add interface stubs (#2792)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "a6fae46d307d0a6101e926cb28298fd9f60d4a49",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Mon, 07 Dec 2020 22:19:03 GMT",
+ "tag": "@azure/msal-common_v2.0.0",
+ "version": "2.0.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Fix login loop with empty query string (#2707)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "307307edb3d9877caca3874d17f35faf2bae6180",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Expose idTokenClaims on AccountInfo (#2554)",
+ "author": "janutter@microsoft.com",
+ "commit": "cb2165aad7995d904ec49ade565d907dc314ce16",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Add matchPattern string util for wildcard matching for urls (#2678)",
+ "author": "janutter@microsoft.com",
+ "commit": "4642741f3def4cdb575cc0a228f88e19f84e3da5",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "fix: added missing async (AzureAD/microsoft-authentication-library-for-js#2652)",
+ "author": "patrick@ruhkopf.me",
+ "commit": "1c0df2fc1468fb094c76da04de91271ffb4461c7",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Log messages contain package name and version (#2589)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "4568c16bd425e242cdb799ec59b3508654cc2e45",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "Add clone to Logger (#2670)",
+ "author": "joarroyo@microsoft.com",
+ "commit": "9efb3ba5886eaf6f3a3cd36957ab9fcb7399278a",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Enable the instance_aware flow (#1804)",
+ "author": "prkanher@microsoft.com",
+ "commit": "3e616e162149f4e57257b70e6d481c4596d91ef9",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Support id_token_hint on logout request (#2587)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "fa9b7009f094b3c17a6d177fcec9b736320735c0",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "major": [
+ {
+ "comment": "Enable StrictNullChecks (#2602)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "ebf18c6daead16f8cfd2afb3b63cbd59fc63046a",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Rename request types and change required fields (#2512)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "5b891222d674eb5664af9187f319a61b50341f55",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Enforce triple equals in eslint",
+ "author": "janutter@microsoft.com",
+ "commit": "5975eb4077a2b4372683e68af4d748b0808134ab",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Package-lock update",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "9c029bc074ecd32483a45cfab8721f0771c31e55",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Remove console.log in unit tests (#2629)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "b89d8029a3703b2bfa1f9399456e652fe6f26e4f",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 11 Nov 2020 23:33:20 GMT",
+ "tag": "@azure/msal-common_v1.7.2",
+ "version": "1.7.2",
+ "comments": {
+ "none": [
+ {
+ "comment": "Documentation update for new account retrieval APIs (#2585)",
+ "author": "hemoral@microsoft.com",
+ "commit": "cb782967cc8f07581488de71c4509fa12a702774",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "patch": [
+ {
+ "comment": "Add getAbsolutePath helper function to UrlString class (#2560)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "12ccf0441f8735e9d2875cebac6065447ecc622d",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 10 Nov 2020 01:48:44 GMT",
+ "tag": "@azure/msal-common_v1.7.1",
+ "version": "1.7.1",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Enhance lookup for IdTokens/AppMetadata (#2530)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "e51446295f8c857f1abc7f6874a4c7fde157699e",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Add LocalAccountId for ADFS usecases (#2573)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "d8247d8e74fc8854ffdb5a6001df00b36fdddd62",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Sat, 07 Nov 2020 01:50:14 GMT",
+ "tag": "@azure/msal-common_v1.7.0",
+ "version": "1.7.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Mandate localAccount in AccountInfo",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "ee770fc1f4ed1ef9e53b28a18487e9b7686ffa64",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Filtered lookup of IdTokens, AppMetadata; Error handling in Node Storage (#2530)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "354dd86449d792b7369fb240c5e2cfd70ca73488",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Build Pipeline Changes (#2406)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "af8459c0d53a4dc2bf495017608c0bb03004d006",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "Implement Password Grant Flow (#2204)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "baf6d157e7bbeae439526aee13eb08962974925b",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Fixing a bug and adding `localAccountId` in AccountInfo interface (#2516)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "c2ec3b43f07d9c18eec14e109caddcf7941f50b4",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Mon, 26 Oct 2020 21:00:29 GMT",
+ "tag": "@azure/msal-common_v1.6.3",
+ "version": "1.6.3",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Fix ServerTelemetry maxErrorToSend bug (#2491)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "81575de28b78e7c09c5d475854e14a8bc1b7b567",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Add missing default headers to device code",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "e007d2b425c8ceaed409ed9b11a1a72bc64fa955",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "msal-browser and msal-node cache Interfaces to msal-common updated (#2415)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "9d4c4a18de10eb3d918810dc10766fbd5547165d",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 20 Oct 2020 23:47:28 GMT",
+ "tag": "@azure/msal-common_v1.6.2",
+ "version": "1.6.2",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Adds support for any OIDC-compliant authority (#2389).",
+ "author": "jamckenn@microsoft.com",
+ "commit": "2b6b9ec9033a8b829393e44c3feb7b19b163d2cd",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Updated eslint rules (#2345)",
+ "author": "janutter@microsoft.com",
+ "commit": "64a4f9e868e63346dfd711dec717abe7fd14d949",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 15 Oct 2020 00:49:18 GMT",
+ "tag": "@azure/msal-common_v1.6.1",
+ "version": "1.6.1",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Removing unused errors in msal-common and fixing possible build errors in @azure/msal-common@1.6.0 (#2432)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "c752e512993dc3a294b51fe0849c70e3cfeafa3e",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 14 Oct 2020 23:45:07 GMT",
+ "tag": "@azure/msal-common_v1.6.0",
+ "version": "1.6.0",
+ "comments": {
+ "none": [
+ {
+ "comment": "Docs updates for msal-node release",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "20718209d5d567c02223a7f1b220b4aa40ad6817",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "Add support for persistence cache plugin (#2348)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "26723689e35918c59bd6ce58ba8cb886118676c6",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "patch": [
+ {
+ "comment": "Add Telemetry header size limit (#2223)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "82b982ba38d70d9060e3cf5d9c38e0203b60d963",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Fri, 02 Oct 2020 17:42:35 GMT",
+ "tag": "@azure/msal-common_v1.5.0",
+ "version": "1.5.0",
+ "comments": {
+ "minor": [
+ {
+ "comment": "Implementation of Access Token Proof-of-Possession Flow (#2151, #2153, #2154, #2209, #2289)",
+ "author": "prkanher@microsoft.com",
+ "commit": "3cffbc99730532bbd0b35f2e3a9df17f032c0675",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 30 Sep 2020 17:58:33 GMT",
+ "tag": "@azure/msal-common_v1.4.0",
+ "version": "1.4.0",
+ "comments": {
+ "none": [
+ {
+ "comment": "Updating dependency versions(#2342)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "bc3f324edd6cf83937c31f73d3aefc6dbaf5f748",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Update changelog versions for msal-node and extensions (#2336)",
+ "author": "hectormgdev@gmail.com",
+ "commit": "323875a725e0d5049ff6742a9ca5160c2d4b7d0d",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 23 Sep 2020 21:13:48 GMT",
+ "tag": "@azure/msal-common_v1.4.0",
+ "version": "1.4.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Remove null in function return types to be compatible with ICacheManager.ts (#2335)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "aecc41e9f23b350a25bba9dd23e739627e61f8ab",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Scopes stored case sensitive, compared case insensitive (#2302)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "60fe1e6b2e4c3fdd1f7ce0dd0fbee0febed6d0d2",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "FOCI - Family of Client IDs feature (#2201)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "209789cdffdfd38087819cbb23688bcd5ce47b60",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 17 Sep 2020 23:16:22 GMT",
+ "tag": "@azure/msal-common_v1.3.0",
+ "version": "1.3.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "Add name field to AccountInfo (#2288)",
+ "author": "jamckenn@microsoft.com",
+ "commit": "d917d6a91987522f1c4390817966945ce18fa099",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Realm should fallback to an empty string for non AAD scenarios",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "d4c4b1f53e919c226b19e3fa72f42f02baa394da",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Add default scopes in all requests and ignore in cache lookups (#2267)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "3a18b100f38149a35c01cc491a9de78ea505d771",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Move refreshToken API to RefreshTokenClient (#2264)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "6923e66fc9ca44c460489b41ff6a4d104ebde864",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Track Suberrors in Telemetry (#1921)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "1872900d149b60436ef59fd41ab542c58c32e8f1",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Separate cache lookup from token refresh (#2189)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "b452afeac6bf3fc5df0535c22433709a06921b33",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Update core, browser, common to use central eslint configuration",
+ "author": "janutter@microsoft.com",
+ "commit": "fc49c6f16b3f7a62a67d249107fc484272133305",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "Add support for On-behalf-of flow",
+ "author": "sagonzal@microsoft.com",
+ "commit": "53c018c8ea0d1877c12641fc1a749e6d66e7ff78",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "ValidCacheType adds ServerTelemetryEntity",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "9760b6ff6c0ad403ac1b26968cb10d3d7e72a6fd",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Added client-side throttling to enhance server stability (#1907)",
+ "author": "jamckenn@microsoft.com",
+ "commit": "91a1dba29dbfb8f6fc329c0381767d6b6f661281",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 25 Aug 2020 00:40:45 GMT",
+ "tag": "@azure/msal-common_v1.2.0",
+ "version": "1.2.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "ignore offline_access in scopes lookup",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "ed55b106bba3d97378b8760d711b24217a7adbbf",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Adds checks for cache entities",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "282035aecb07956dca323d65275fdaa703c4a325",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Add claims request to /token calls (#2138)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "a2813a0b7dc1b6ad8fa76f1fd7444b95d380e42b",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Fix Telemetry cacheHit Bug (#2170)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "a9305a0ec3405f892ff4a1926ffb3dbca26e9a83",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Get username from emails claim in B2C scenarios (#2114)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "40b1716fec63893f57762f37b55944f6c8c86e21",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Update POST header to type Record (#2128)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "c9b65c59797cd3240aad2b4f1e0e866a90373c4a",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "minor": [
+ {
+ "comment": "Client Capabilities Support (#2169)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "0cdad1b8a3855b2414be9740862df29524897a22",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Add support for acquiring tokens with client credentials grant",
+ "author": "sagonzal@microsoft.com",
+ "commit": "98647b7a8a40e1a5f7855f0bcee4594e080a8398",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 13 Aug 2020 02:20:48 GMT",
+ "tag": "@azure/msal-common_v1.1.1",
+ "version": "1.1.1",
+ "comments": {
+ "patch": [
+ {
+ "comment": "knownAuthorities enhancements (#2106)",
+ "author": "thomas.l.norling@gmail.com",
+ "commit": "7f86c1ef455deda854fc1743e8a3f687e3f8ee76",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Update typing of IdTokenClaims (#2105)",
+ "author": "hemoral@microsoft.com",
+ "commit": "a5994b5767d36476066c86822ce49a8ba4dbd3a7",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "Fix hash parsing issue from #2118 and back button cache clearing (#2129)",
+ "author": "prkanher@microsoft.com",
+ "commit": "10ab51ecd9e4bb1ba1668972b693055310c65736",
+ "package": "@azure/msal-common"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Added documentation for client-side throttling (#2033)",
+ "author": "jamckenn@microsoft.com",
+ "commit": "4a45286aa7767a4f60aa0eadd4ed125d520034f7",
+ "package": "@azure/msal-common"
+ },
+ {
+ "comment": "updating files for automated release steps",
+ "author": "prkanher@microsoft.com",
+ "commit": "2c937a52cef36cbc84231f8868b4251529fa38c9",
+ "package": "@azure/msal-common"
+ }
+ ]
+ }
+ }
+ ]
+}
diff --git a/node_modules/@azure/msal-common/LICENSE b/node_modules/@azure/msal-common/LICENSE
new file mode 100644
index 0000000..527f8f1
--- /dev/null
+++ b/node_modules/@azure/msal-common/LICENSE
@@ -0,0 +1,21 @@
+MIT License
+
+Copyright (c) Microsoft Corporation. All rights reserved.
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in all
+copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+SOFTWARE
diff --git a/node_modules/@azure/msal-common/README.md b/node_modules/@azure/msal-common/README.md
new file mode 100644
index 0000000..6f7c1ab
--- /dev/null
+++ b/node_modules/@azure/msal-common/README.md
@@ -0,0 +1,58 @@
+# Microsoft Authentication Library for JavaScript (MSAL.js) Common Protocols Package
+[![npm version](https://img.shields.io/npm/v/@azure/msal-common.svg?style=flat)](https://www.npmjs.com/package/@azure/msal-common/)[![npm version](https://img.shields.io/npm/dm/@azure/msal-common.svg)](https://nodei.co/npm/@azure/msal-common/)[![Coverage Status](https://coveralls.io/repos/github/AzureAD/microsoft-authentication-library-for-js/badge.svg?branch=dev)](https://coveralls.io/github/AzureAD/microsoft-authentication-library-for-js?branch=dev)
+
+| Getting Started | AAD Docs | Library Reference |
+| --- | --- | --- |
+
+1. [About](#about)
+2. [FAQ](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-common/FAQ.md)
+3. [Releases](#releases)
+4. [Prerequisites and Usage](#prerequisites-and-usage)
+5. [Installation](#installation)
+6. [Security Reporting](#security-reporting)
+7. [License](#license)
+8. [Code of Conduct](#we-value-and-adhere-to-the-microsoft-open-source-code-of-conduct)
+
+## About
+
+The MSAL library for JavaScript enables client-side JavaScript applications to authenticate users using [Azure AD](https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-overview) work and school accounts (AAD), Microsoft personal accounts (MSA) and social identity providers like Facebook, Google, LinkedIn, Microsoft accounts, etc. through [Azure AD B2C](https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-overview#identity-providers) service. It also enables your app to get tokens to access [Microsoft Cloud](https://www.microsoft.com/enterprise) services such as [Microsoft Graph](https://graph.microsoft.io).
+
+The `@azure/msal-common` package described by the code in this folder serves as a common package dependency for the `@azure/msal-browser` package (and in the future, the msal-node package). Be aware that this is an internal library, and is subject to frequent change. **It is not meant for production consumption by itself.**
+
+## FAQ
+
+See [here](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-common/FAQ.md).
+
+## Releases
+
+*Expect us to detail our major and minor releases moving forward, while leaving out our patch releases. Patch release notes can be found in our change log.*
+
+| Date | Release | Announcement | Main features |
+| ------| ------- | ---------| --------- |
+| August 4, 2020 | @azure/msal-common v1.1.0 | [Release Notes](https://https://github.com/AzureAD/microsoft-authentication-library-for-js/releases/tag/msal-common-v1.1.0)
+| July 20, 2020 | @azure/msal-common v1.0.0 | [Release Notes](https://github.com/AzureAD/microsoft-authentication-library-for-js/releases/tag/msal-common-v1.0.0) | Full release version of the `@azure/msal-common` |
+| May 11, 2020 | @azure/msal-common v1.0.0-beta | Beta version of the `@azure/msal-common` package |
+| January 17, 2020 | @azure/msal-common v1.0.0-alpha | No release notes yet | Alpha version of the `@azure/msal-common` package with authorization code flow for SPAs working in dev. |
+
+## Prerequisites and Usage
+This library is not meant for production use. Please use one of these packages specific to the platform you are developing for:
+
+- [MSAL for Single Page Applications (SPAs)](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/lib/msal-browser)
+- [MSAL for Node.js](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/lib/msal-node)
+
+## Installation
+### Via NPM:
+
+ npm install @azure/msal-common
+
+## Security Reporting
+
+If you find a security issue with our libraries or services please report it to [secure@microsoft.com](mailto:secure@microsoft.com) with as much detail as possible. Your submission may be eligible for a bounty through the [Microsoft Bounty](http://aka.ms/bugbounty) program. Please do not post security issues to GitHub Issues or any other public site. We will contact you shortly upon receiving the information. We encourage you to get notifications of when security incidents occur by visiting [this page](https://technet.microsoft.com/en-us/security/dd252948) and subscribing to Security Advisory Alerts.
+
+## License
+
+Copyright (c) Microsoft Corporation. All rights reserved. Licensed under the MIT License (the "License");
+
+## We Value and Adhere to the Microsoft Open Source Code of Conduct
+
+This project has adopted the [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/). For more information see the [Code of Conduct FAQ](https://opensource.microsoft.com/codeofconduct/faq/) or contact [opencode@microsoft.com](mailto:opencode@microsoft.com) with any additional questions or comments.
diff --git a/node_modules/@azure/msal-common/changelog.md b/node_modules/@azure/msal-common/changelog.md
new file mode 100644
index 0000000..0cb6e30
--- /dev/null
+++ b/node_modules/@azure/msal-common/changelog.md
@@ -0,0 +1,297 @@
+# Change Log - @azure/msal-common
+
+This log was last generated on Thu, 18 Feb 2021 00:34:32 GMT and should not be manually modified.
+
+
+
+## 4.0.1
+
+Thu, 18 Feb 2021 00:34:32 GMT
+
+### Patches
+
+- Clarify Device Code Timeout units (#3031) (hemoral@microsoft.com)
+
+## 4.0.0
+
+Tue, 09 Feb 2021 01:48:22 GMT
+
+### Major changes
+
+- Add API Extractor for msal-node (sameera.gajjarapu@microsoft.com)
+
+### Patches
+
+- Fix version.json import errors (#2993) (thomas.norling@microsoft.com)
+- Setting postLogoutRedirectUri as null will disable post logout redirect (janutter@microsoft.com)
+- Ignore OIDC scopes during cache lookup or replacement (#2969) (prkanher@microsoft.com)
+
+## 3.1.0
+
+Tue, 02 Feb 2021 01:56:47 GMT
+
+### Minor changes
+
+- Add wrapper SKU and version to current telemetry header (#2845) (thomas.norling@microsoft.com)
+
+### Patches
+
+- Fix token timestamp calculation (prkanher@microsoft.com)
+- Fix B2C policy switching (#2949) (thomas.norling@microsoft.com)
+- Get package version from version.json (#2915) (thomas.norling@microsoft.com)
+
+## 3.0.0
+
+Thu, 21 Jan 2021 21:48:01 GMT
+
+### Major changes
+
+- Authority metadata caching (#2758) (thomas.norling@microsoft.com)
+
+## 2.1.0
+
+Tue, 12 Jan 2021 00:51:26 GMT
+
+### Minor changes
+
+- Add interface stubs (#2792) (thomas.norling@microsoft.com)
+
+### Patches
+
+- Adding account info equality check function (#2728) (prkanher@microsoft.com)
+- Adding device code timeout to the device code request(#2656) (samuel.kamau@microsoft.com)
+
+## 2.0.0
+
+Mon, 07 Dec 2020 22:19:03 GMT
+
+### Major changes
+
+- Enable StrictNullChecks (#2602) (thomas.norling@microsoft.com)
+- Rename request types and change required fields (#2512) (thomas.norling@microsoft.com)
+
+### Minor changes
+
+- Add clone to Logger (#2670) (joarroyo@microsoft.com)
+- Enable the instance_aware flow (#1804) (prkanher@microsoft.com)
+- Support id_token_hint on logout request (#2587) (thomas.norling@microsoft.com)
+
+### Patches
+
+- Fix login loop with empty query string (#2707) (thomas.norling@microsoft.com)
+- Expose idTokenClaims on AccountInfo (#2554) (janutter@microsoft.com)
+- Add matchPattern string util for wildcard matching for urls (#2678) (janutter@microsoft.com)
+- fix: added missing async (AzureAD/microsoft-authentication-library-for-js#2652) (patrick@ruhkopf.me)
+- Log messages contain package name and version (#2589) (thomas.norling@microsoft.com)
+
+## 1.7.2
+
+Wed, 11 Nov 2020 23:33:20 GMT
+
+### Patches
+
+- Add getAbsolutePath helper function to UrlString class (#2560) (thomas.norling@microsoft.com)
+
+## 1.7.1
+
+Tue, 10 Nov 2020 01:48:44 GMT
+
+### Patches
+
+- Enhance lookup for IdTokens/AppMetadata (#2530) (sameera.gajjarapu@microsoft.com)
+- Add LocalAccountId for ADFS usecases (#2573) (sameera.gajjarapu@microsoft.com)
+
+## 1.7.0
+
+Sat, 07 Nov 2020 01:50:14 GMT
+
+### Minor changes
+
+- Implement Password Grant Flow (#2204) (sameera.gajjarapu@microsoft.com)
+- Fixing a bug and adding `localAccountId` in AccountInfo interface (#2516) (sameera.gajjarapu@microsoft.com)
+
+### Patches
+
+- Mandate localAccount in AccountInfo (sameera.gajjarapu@microsoft.com)
+- Filtered lookup of IdTokens, AppMetadata; Error handling in Node Storage (#2530) (sameera.gajjarapu@microsoft.com)
+
+## 1.6.3
+
+Mon, 26 Oct 2020 21:00:29 GMT
+
+### Patches
+
+- Fix ServerTelemetry maxErrorToSend bug (#2491) (thomas.norling@microsoft.com)
+- Add missing default headers to device code (sameera.gajjarapu@microsoft.com)
+- msal-browser and msal-node cache Interfaces to msal-common updated (#2415) (sameera.gajjarapu@microsoft.com)
+
+## 1.6.2
+
+Tue, 20 Oct 2020 23:47:28 GMT
+
+### Patches
+
+- Adds support for any OIDC-compliant authority (#2389). (jamckenn@microsoft.com)
+
+## 1.6.1
+
+Thu, 15 Oct 2020 00:49:18 GMT
+
+### Patches
+
+- Removing unused errors in msal-common and fixing possible build errors in @azure/msal-common@1.6.0 (#2432) (sameera.gajjarapu@microsoft.com)
+
+## 1.6.0
+
+Wed, 14 Oct 2020 23:45:07 GMT
+
+### Minor changes
+
+- Add support for persistence cache plugin (#2348) (sameera.gajjarapu@microsoft.com)
+
+### Patches
+
+- Add Telemetry header size limit (#2223) (thomas.norling@microsoft.com)
+
+## 1.5.0
+
+Fri, 02 Oct 2020 17:42:35 GMT
+
+### Minor changes
+
+- Implementation of Access Token Proof-of-Possession Flow (#2151, #2153, #2154, #2209, #2289) (prkanher@microsoft.com)
+
+## 1.4.0
+
+Wed, 23 Sep 2020 21:13:48 GMT
+
+### Minor changes
+
+- FOCI - Family of Client IDs feature (#2201) (sameera.gajjarapu@microsoft.com)
+
+### Patches
+
+- Remove null in function return types to be compatible with ICacheManager.ts (#2335) (sameera.gajjarapu@microsoft.com)
+- Scopes stored case sensitive, compared case insensitive (#2302) (sameera.gajjarapu@microsoft.com)
+
+## 1.3.0
+
+Thu, 17 Sep 2020 23:16:22 GMT
+
+### Minor changes
+
+- Add support for On-behalf-of flow (#2157) (sagonzal@microsoft.com)
+- ValidCacheType adds ServerTelemetryEntity (sameera.gajjarapu@microsoft.com)
+- Added client-side throttling to enhance server stability (#1907) (jamckenn@microsoft.com)
+
+### Patches
+
+- Add name field to AccountInfo (#2288) (jamckenn@microsoft.com)
+- Realm should fallback to an empty string for non AAD scenarios (sameera.gajjarapu@microsoft.com)
+- Add default scopes in all requests and ignore in cache lookups (#2267) (thomas.norling@microsoft.com)
+- Move refreshToken API to RefreshTokenClient (#2264) (thomas.norling@microsoft.com)
+- Track Suberrors in Telemetry (#1921) (thomas.norling@microsoft.com)
+- Separate cache lookup from token refresh (#2189) (thomas.norling@microsoft.com)
+
+## 1.2.0
+
+Tue, 25 Aug 2020 00:40:45 GMT
+
+### Minor changes
+
+- Client Capabilities Support (#2169) (thomas.norling@microsoft.com)
+- Add support for acquiring tokens with client credentials grant (sagonzal@microsoft.com)
+
+### Patches
+
+- ignore offline_access in scopes lookup (sameera.gajjarapu@microsoft.com)
+- Adds checks for cache entities (sameera.gajjarapu@microsoft.com)
+- Add claims request to /token calls (#2138) (thomas.norling@microsoft.com)
+- Fix Telemetry cacheHit Bug (#2170) (thomas.norling@microsoft.com)
+- Get username from emails claim in B2C scenarios (#2114) (thomas.norling@microsoft.com)
+- Update POST header to type Record (#2128) (thomas.norling@microsoft.com)
+
+## 1.1.1
+
+Thu, 13 Aug 2020 02:20:48 GMT
+
+### Patches
+
+- knownAuthorities enhancements (#2106) (thomas.l.norling@gmail.com)
+- Update typing of IdTokenClaims (#2105) (hemoral@microsoft.com)
+- Fix hash parsing issue from #2118 and back button cache clearing (#2129) (prkanher@microsoft.com)
+
+# 1.1.0
+## Breaking Changes
+- None
+
+## Features and Fixes
+- Decode state from URI Encoding before comparing (#2049)
+- getAllAccounts() returns empty array instead of `null` (#2059)
+- Updated the `UrlString.canonicalizeUri()` API to be static (#2078)
+- Add sid to `AuthorizationUrlRequest` and as part of request parameters sent to server (#2030)
+- Enable server telemetry headers to be formatted and sent in every request (#1917)
+- Enable platform level state information to be sent and read through the request state (#2045)
+- Add the confidential client flow (#2023)
+
+# 1.0.0
+## Breaking Changes
+- None
+
+## Features and Fixes
+- Fixed an issue where scopes were being made lower case before being sent to the service (#1961)
+- Fix an issue where token values were replaced with undefined if not sent by server (#1946)
+- Fix an issue where cache lookup for accounts was not working correctly (#1919)
+- Removed TelemetryOptions from msal-common since they were unused (#1983)
+- Add a response handler for the device code flow (#1947)
+
+# 1.0.0-beta.4
+## Breaking Changes
+- None
+
+## Features and Fixes
+- Fix an issue where state may be encoded twice on the server-side (#1852)
+- Fix an issue where extraScopesToConsent was not appending scopes correctly (#1854)
+- Fix an issue where the expiration was not being calculated correctly (#1860)
+- Add correlationId to all requests (#1868)
+
+# 1.0.0-beta.3
+## Breaking Changes
+- `Request` update in msal-common (#1682, #1771)
+- AccountInfo interface (#1789)
+- Removal of SPA Client (#1793)
+- Unified Cache support (#1444, #1471, #1519, #1520, #1522, #1609, #1622, #1624, #1655, #1680, #1762)
+
+## Features and Fixes
+- Initialization of B2cTrustedHostList (#1646)
+- SilentFlow support (#1711)
+- Utilize `Scopeset` across all libraries (#1770)
+- `state` support in msal-common (#1790)
+- EndSessionRequest (#1802)
+
+# 1.0.0-beta.2
+- Fixed an issue where types were not being exported from the correct location (#1613)
+- Fixed an issue where system configuration values were being overwritten with `undefined` (#1631)
+- Added support for sub-error codes from the eSTS service (#1533)
+
+# 1.0.0-beta.1
+- Fixed an issue where types are not exported correctly (#1517)
+- Logger class is now exported (#1486)
+- Added knownAuthorities to support B2C authorities (#1416)
+- Refactored authority classes for B2C use cases (#1424)
+- Synced all classes and objects to work for both @azure/msal-browser and @azure/msal-node (#1552)
+- Merged configuration for node and browser classes (#1575)
+- Fixed issue with caching for multiple resources (#1553)
+- Adding support for node classes
+ - Refresh token client (#1496)
+ - Device code client (#1550, #1434)
+ - Authorization Code Client (#1434)
+
+# 1.0.0-beta.0
+- Fully functioning project completed
+- Build and test pipelines in place
+- Added bug fixes from unit testing
+- Added docs and samples
+
+# 0.0.1
+- Created library with initial files for repo structure, build and package dependencies
diff --git a/node_modules/@azure/msal-common/dist/account/AccountInfo.d.ts b/node_modules/@azure/msal-common/dist/account/AccountInfo.d.ts
new file mode 100644
index 0000000..c1df544
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/AccountInfo.d.ts
@@ -0,0 +1,21 @@
+/**
+ * Account object with the following signature:
+ * - homeAccountId - Home account identifier for this account object
+ * - environment - Entity which issued the token represented by the domain of the issuer (e.g. login.microsoftonline.com)
+ * - tenantId - Full tenant or organizational id that this account belongs to
+ * - username - preferred_username claim of the id_token that represents this account
+ * - localAccountId - Local, tenant-specific account identifer for this account object, usually used in legacy cases
+ * - name - Full name for the account, including given name and family name
+ * - idTokenClaims - Object contains claims from ID token
+ * - localAccountId - The user's account ID
+ */
+export declare type AccountInfo = {
+ homeAccountId: string;
+ environment: string;
+ tenantId: string;
+ username: string;
+ localAccountId: string;
+ name?: string;
+ idTokenClaims?: object;
+};
+//# sourceMappingURL=AccountInfo.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/AccountInfo.d.ts.map b/node_modules/@azure/msal-common/dist/account/AccountInfo.d.ts.map
new file mode 100644
index 0000000..af41bdf
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/AccountInfo.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AccountInfo.d.ts","sourceRoot":"","sources":["../../src/account/AccountInfo.ts"],"names":[],"mappings":"AAKA;;;;;;;;;;GAUG;AACH,oBAAY,WAAW,GAAG;IACtB,aAAa,EAAE,MAAM,CAAC;IACtB,WAAW,EAAE,MAAM,CAAC;IACpB,QAAQ,EAAE,MAAM,CAAC;IACjB,QAAQ,EAAE,MAAM,CAAC;IACjB,cAAc,EAAE,MAAM,CAAC;IACvB,IAAI,CAAC,EAAE,MAAM,CAAC;IACd,aAAa,CAAC,EAAE,MAAM,CAAC;CAC1B,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/AuthToken.d.ts b/node_modules/@azure/msal-common/dist/account/AuthToken.d.ts
new file mode 100644
index 0000000..56dbc5d
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/AuthToken.d.ts
@@ -0,0 +1,17 @@
+import { TokenClaims } from "./TokenClaims";
+import { ICrypto } from "../crypto/ICrypto";
+/**
+ * JWT Token representation class. Parses token string and generates claims object.
+ */
+export declare class AuthToken {
+ rawToken: string;
+ claims: TokenClaims;
+ constructor(rawToken: string, crypto: ICrypto);
+ /**
+ * Extract token by decoding the rawToken
+ *
+ * @param encodedToken
+ */
+ static extractTokenClaims(encodedToken: string, crypto: ICrypto): TokenClaims;
+}
+//# sourceMappingURL=AuthToken.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/AuthToken.d.ts.map b/node_modules/@azure/msal-common/dist/account/AuthToken.d.ts.map
new file mode 100644
index 0000000..a942dc6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/AuthToken.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthToken.d.ts","sourceRoot":"","sources":["../../src/account/AuthToken.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,WAAW,EAAE,MAAM,eAAe,CAAC;AAI5C,OAAO,EAAE,OAAO,EAAE,MAAM,mBAAmB,CAAC;AAE5C;;GAEG;AACH,qBAAa,SAAS;IAGlB,QAAQ,EAAE,MAAM,CAAC;IAEjB,MAAM,EAAE,WAAW,CAAC;gBACR,QAAQ,EAAE,MAAM,EAAE,MAAM,EAAE,OAAO;IAS7C;;;;OAIG;IACH,MAAM,CAAC,kBAAkB,CAAC,YAAY,EAAE,MAAM,EAAE,MAAM,EAAE,OAAO,GAAG,WAAW;CAehF"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/ClientInfo.d.ts b/node_modules/@azure/msal-common/dist/account/ClientInfo.d.ts
new file mode 100644
index 0000000..c1929cc
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/ClientInfo.d.ts
@@ -0,0 +1,15 @@
+import { ICrypto } from "../crypto/ICrypto";
+/**
+ * Client info object which consists of two IDs. Need to add more info here.
+ */
+export declare type ClientInfo = {
+ uid: string;
+ utid: string;
+};
+/**
+ * Function to build a client info object
+ * @param rawClientInfo
+ * @param crypto
+ */
+export declare function buildClientInfo(rawClientInfo: string, crypto: ICrypto): ClientInfo;
+//# sourceMappingURL=ClientInfo.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/ClientInfo.d.ts.map b/node_modules/@azure/msal-common/dist/account/ClientInfo.d.ts.map
new file mode 100644
index 0000000..be27025
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/ClientInfo.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ClientInfo.d.ts","sourceRoot":"","sources":["../../src/account/ClientInfo.ts"],"names":[],"mappings":"AAOA,OAAO,EAAE,OAAO,EAAE,MAAM,mBAAmB,CAAC;AAE5C;;GAEG;AACH,oBAAY,UAAU,GAAG;IACrB,GAAG,EAAE,MAAM,CAAC;IACZ,IAAI,EAAE,MAAM,CAAA;CACf,CAAC;AAEF;;;;GAIG;AACH,wBAAgB,eAAe,CAAC,aAAa,EAAE,MAAM,EAAE,MAAM,EAAE,OAAO,GAAG,UAAU,CAWlF"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/DecodedAuthToken.d.ts b/node_modules/@azure/msal-common/dist/account/DecodedAuthToken.d.ts
new file mode 100644
index 0000000..4c0cdc6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/DecodedAuthToken.d.ts
@@ -0,0 +1,9 @@
+/**
+ * Interface for Decoded JWT tokens.
+ */
+export interface DecodedAuthToken {
+ header: string;
+ JWSPayload: string;
+ JWSSig: string;
+}
+//# sourceMappingURL=DecodedAuthToken.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/DecodedAuthToken.d.ts.map b/node_modules/@azure/msal-common/dist/account/DecodedAuthToken.d.ts.map
new file mode 100644
index 0000000..bfc155c
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/DecodedAuthToken.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"DecodedAuthToken.d.ts","sourceRoot":"","sources":["../../src/account/DecodedAuthToken.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,MAAM,WAAW,gBAAgB;IAC7B,MAAM,EAAE,MAAM,CAAC;IACf,UAAU,EAAE,MAAM,CAAC;IACnB,MAAM,EAAE,MAAM,CAAA;CACjB"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/TokenClaims.d.ts b/node_modules/@azure/msal-common/dist/account/TokenClaims.d.ts
new file mode 100644
index 0000000..c438528
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/TokenClaims.d.ts
@@ -0,0 +1,23 @@
+/**
+ * Type which describes Id Token claims known by MSAL.
+ */
+export declare type TokenClaims = {
+ iss?: string;
+ oid?: string;
+ sub?: string;
+ tid?: string;
+ ver?: string;
+ upn?: string;
+ preferred_username?: string;
+ emails?: string[];
+ name?: string;
+ nonce?: string;
+ exp?: number;
+ home_oid?: string;
+ sid?: string;
+ cloud_instance_host_name?: string;
+ cnf?: {
+ kid: string;
+ };
+};
+//# sourceMappingURL=TokenClaims.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/account/TokenClaims.d.ts.map b/node_modules/@azure/msal-common/dist/account/TokenClaims.d.ts.map
new file mode 100644
index 0000000..8e7b03e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/account/TokenClaims.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"TokenClaims.d.ts","sourceRoot":"","sources":["../../src/account/TokenClaims.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,oBAAY,WAAW,GAAG;IACtB,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,kBAAkB,CAAC,EAAE,MAAM,CAAC;IAC5B,MAAM,CAAC,EAAE,MAAM,EAAE,CAAC;IAClB,IAAI,CAAC,EAAE,MAAM,CAAC;IACd,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,wBAAwB,CAAC,EAAE,MAAM,CAAC;IAClC,GAAG,CAAC,EAAE;QACF,GAAG,EAAE,MAAM,CAAC;KACf,CAAC;CACL,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/Authority.d.ts b/node_modules/@azure/msal-common/dist/authority/Authority.d.ts
new file mode 100644
index 0000000..a24a9bf
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/Authority.d.ts
@@ -0,0 +1,148 @@
+import { AuthorityType } from "./AuthorityType";
+import { IUri } from "../url/IUri";
+import { INetworkModule } from "../network/INetworkModule";
+import { ProtocolMode } from "./ProtocolMode";
+import { ICacheManager } from "../cache/interface/ICacheManager";
+import { AuthorityOptions } from "./AuthorityOptions";
+import { CloudDiscoveryMetadata } from "./CloudDiscoveryMetadata";
+/**
+ * The authority class validates the authority URIs used by the user, and retrieves the OpenID Configuration Data from the
+ * endpoint. It will store the pertinent config data in this object for use during token calls.
+ */
+export declare class Authority {
+ private _canonicalAuthority;
+ private _canonicalAuthorityUrlComponents;
+ protected networkInterface: INetworkModule;
+ protected cacheManager: ICacheManager;
+ private authorityOptions;
+ private metadata;
+ constructor(authority: string, networkInterface: INetworkModule, cacheManager: ICacheManager, authorityOptions: AuthorityOptions);
+ get authorityType(): AuthorityType;
+ /**
+ * ProtocolMode enum representing the way endpoints are constructed.
+ */
+ get protocolMode(): ProtocolMode;
+ /**
+ * Returns authorityOptions which can be used to reinstantiate a new authority instance
+ */
+ get options(): AuthorityOptions;
+ /**
+ * A URL that is the authority set by the developer
+ */
+ get canonicalAuthority(): string;
+ /**
+ * Sets canonical authority.
+ */
+ set canonicalAuthority(url: string);
+ /**
+ * Get authority components.
+ */
+ get canonicalAuthorityUrlComponents(): IUri;
+ /**
+ * Get hostname and port i.e. login.microsoftonline.com
+ */
+ get hostnameAndPort(): string;
+ /**
+ * Get tenant for authority.
+ */
+ get tenant(): string;
+ /**
+ * OAuth /authorize endpoint for requests
+ */
+ get authorizationEndpoint(): string;
+ /**
+ * OAuth /token endpoint for requests
+ */
+ get tokenEndpoint(): string;
+ get deviceCodeEndpoint(): string;
+ /**
+ * OAuth logout endpoint for requests
+ */
+ get endSessionEndpoint(): string;
+ /**
+ * OAuth issuer for requests
+ */
+ get selfSignedJwtAudience(): string;
+ /**
+ * Replaces tenant in url path with current tenant. Defaults to common.
+ * @param urlString
+ */
+ private replaceTenant;
+ /**
+ * Replaces path such as tenant or policy with the current tenant or policy.
+ * @param urlString
+ */
+ private replacePath;
+ /**
+ * The default open id configuration endpoint for any canonical authority.
+ */
+ protected get defaultOpenIdConfigurationEndpoint(): string;
+ /**
+ * Boolean that returns whethr or not tenant discovery has been completed.
+ */
+ discoveryComplete(): boolean;
+ /**
+ * Perform endpoint discovery to discover aliases, preferred_cache, preferred_network
+ * and the /authorize, /token and logout endpoints.
+ */
+ resolveEndpointsAsync(): Promise;
+ /**
+ * Update AuthorityMetadataEntity with new endpoints and return where the information came from
+ * @param metadataEntity
+ */
+ private updateEndpointMetadata;
+ /**
+ * Compares the number of url components after the domain to determine if the cached authority metadata can be used for the requested authority
+ * Protects against same domain different authority such as login.microsoftonline.com/tenant and login.microsoftonline.com/tfp/tenant/policy
+ * @param metadataEntity
+ */
+ private isAuthoritySameType;
+ /**
+ * Parse authorityMetadata config option
+ */
+ private getEndpointMetadataFromConfig;
+ /**
+ * Gets OAuth endpoints from the given OpenID configuration endpoint.
+ */
+ private getEndpointMetadataFromNetwork;
+ /**
+ * Updates the AuthorityMetadataEntity with new aliases, preferred_network and preferred_cache and returns where the information was retrived from
+ * @param cachedMetadata
+ * @param newMetadata
+ */
+ private updateCloudDiscoveryMetadata;
+ /**
+ * Parse cloudDiscoveryMetadata config or check knownAuthorities
+ */
+ private getCloudDiscoveryMetadataFromConfig;
+ /**
+ * Called to get metadata from network if CloudDiscoveryMetadata was not populated by config
+ * @param networkInterface
+ */
+ private getCloudDiscoveryMetadataFromNetwork;
+ /**
+ * Helper function to determine if this host is included in the knownAuthorities config option
+ */
+ private isInKnownAuthorities;
+ /**
+ * Creates cloud discovery metadata object from a given host
+ * @param host
+ */
+ static createCloudDiscoveryMetadataFromHost(host: string): CloudDiscoveryMetadata;
+ /**
+ * Searches instance discovery network response for the entry that contains the host in the aliases list
+ * @param response
+ * @param authority
+ */
+ static getCloudDiscoveryMetadataFromNetworkResponse(response: CloudDiscoveryMetadata[], authority: string): CloudDiscoveryMetadata | null;
+ /**
+ * helper function to generate environment from authority object
+ */
+ getPreferredCache(): string;
+ /**
+ * Returns whether or not the provided host is an alias of this authority instance
+ * @param host
+ */
+ isAlias(host: string): boolean;
+}
+//# sourceMappingURL=Authority.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/Authority.d.ts.map b/node_modules/@azure/msal-common/dist/authority/Authority.d.ts.map
new file mode 100644
index 0000000..aced203
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/Authority.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"Authority.d.ts","sourceRoot":"","sources":["../../src/authority/Authority.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,aAAa,EAAE,MAAM,iBAAiB,CAAC;AAGhD,OAAO,EAAE,IAAI,EAAE,MAAM,aAAa,CAAC;AAEnC,OAAO,EAAE,cAAc,EAAE,MAAM,2BAA2B,CAAC;AAG3D,OAAO,EAAE,YAAY,EAAE,MAAM,gBAAgB,CAAC;AAC9C,OAAO,EAAE,aAAa,EAAE,MAAM,kCAAkC,CAAC;AAEjE,OAAO,EAAE,gBAAgB,EAAE,MAAM,oBAAoB,CAAC;AAEtD,OAAO,EAAE,sBAAsB,EAAE,MAAM,0BAA0B,CAAC;AAElE;;;GAGG;AACH,qBAAa,SAAS;IAGlB,OAAO,CAAC,mBAAmB,CAAY;IAEvC,OAAO,CAAC,gCAAgC,CAAc;IAEtD,SAAS,CAAC,gBAAgB,EAAE,cAAc,CAAC;IAE3C,SAAS,CAAC,YAAY,EAAE,aAAa,CAAC;IAEtC,OAAO,CAAC,gBAAgB,CAAmB;IAE3C,OAAO,CAAC,QAAQ,CAA0B;gBAE9B,SAAS,EAAE,MAAM,EAAE,gBAAgB,EAAE,cAAc,EAAE,YAAY,EAAE,aAAa,EAAE,gBAAgB,EAAE,gBAAgB;IAShI,IAAW,aAAa,IAAI,aAAa,CAQxC;IAED;;OAEG;IACH,IAAW,YAAY,IAAI,YAAY,CAEtC;IAED;;OAEG;IACH,IAAW,OAAO,IAAI,gBAAgB,CAErC;IAED;;OAEG;IACH,IAAW,kBAAkB,IAAI,MAAM,CAEtC;IAED;;OAEG;IACH,IAAW,kBAAkB,CAAC,GAAG,EAAE,MAAM,EAIxC;IAED;;OAEG;IACH,IAAW,+BAA+B,IAAI,IAAI,CAMjD;IAED;;OAEG;IACH,IAAW,eAAe,IAAI,MAAM,CAEnC;IAED;;OAEG;IACH,IAAW,MAAM,IAAI,MAAM,CAE1B;IAED;;OAEG;IACH,IAAW,qBAAqB,IAAI,MAAM,CAOzC;IAED;;OAEG;IACH,IAAW,aAAa,IAAI,MAAM,CAOjC;IAED,IAAW,kBAAkB,IAAI,MAAM,CAOtC;IAED;;OAEG;IACH,IAAW,kBAAkB,IAAI,MAAM,CAOtC;IAED;;OAEG;IACH,IAAW,qBAAqB,IAAI,MAAM,CAOzC;IAED;;;OAGG;IACH,OAAO,CAAC,aAAa;IAIrB;;;OAGG;IACH,OAAO,CAAC,WAAW;IAgBnB;;OAEG;IACH,SAAS,KAAK,kCAAkC,IAAI,MAAM,CAKzD;IAED;;OAEG;IACH,iBAAiB,IAAI,OAAO;IAI5B;;;OAGG;IACU,qBAAqB,IAAI,OAAO,CAAC,IAAI,CAAC;IAsBnD;;;OAGG;YACW,sBAAsB;IAqBpC;;;;OAIG;IACH,OAAO,CAAC,mBAAmB;IAO3B;;OAEG;IACH,OAAO,CAAC,6BAA6B;IAYrC;;OAEG;YACW,8BAA8B;IAS5C;;;;OAIG;YACW,4BAA4B;IAuB1C;;OAEG;IACH,OAAO,CAAC,mCAAmC;IAsB3C;;;OAGG;YACW,oCAAoC;IAkBlD;;OAEG;IACH,OAAO,CAAC,oBAAoB;IAQ5B;;;OAGG;IACH,MAAM,CAAC,oCAAoC,CAAC,IAAI,EAAE,MAAM,GAAG,sBAAsB;IAQjF;;;;OAIG;IACH,MAAM,CAAC,4CAA4C,CAAC,QAAQ,EAAE,sBAAsB,EAAE,EAAE,SAAS,EAAE,MAAM,GAAG,sBAAsB,GAAG,IAAI;IAWzI;;OAEG;IACH,iBAAiB,IAAI,MAAM;IAQ3B;;;OAGG;IACH,OAAO,CAAC,IAAI,EAAE,MAAM,GAAG,OAAO;CAGjC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/AuthorityFactory.d.ts b/node_modules/@azure/msal-common/dist/authority/AuthorityFactory.d.ts
new file mode 100644
index 0000000..cc978da
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/AuthorityFactory.d.ts
@@ -0,0 +1,29 @@
+import { Authority } from "./Authority";
+import { INetworkModule } from "../network/INetworkModule";
+import { ICacheManager } from "../cache/interface/ICacheManager";
+import { AuthorityOptions } from "./AuthorityOptions";
+export declare class AuthorityFactory {
+ /**
+ * Create an authority object of the correct type based on the url
+ * Performs basic authority validation - checks to see if the authority is of a valid type (i.e. aad, b2c, adfs)
+ *
+ * Also performs endpoint discovery.
+ *
+ * @param authorityUri
+ * @param networkClient
+ * @param protocolMode
+ */
+ static createDiscoveredInstance(authorityUri: string, networkClient: INetworkModule, cacheManager: ICacheManager, authorityOptions: AuthorityOptions): Promise;
+ /**
+ * Create an authority object of the correct type based on the url
+ * Performs basic authority validation - checks to see if the authority is of a valid type (i.e. aad, b2c, adfs)
+ *
+ * Does not perform endpoint discovery.
+ *
+ * @param authorityUrl
+ * @param networkInterface
+ * @param protocolMode
+ */
+ static createInstance(authorityUrl: string, networkInterface: INetworkModule, cacheManager: ICacheManager, authorityOptions: AuthorityOptions): Authority;
+}
+//# sourceMappingURL=AuthorityFactory.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/AuthorityFactory.d.ts.map b/node_modules/@azure/msal-common/dist/authority/AuthorityFactory.d.ts.map
new file mode 100644
index 0000000..ff81c25
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/AuthorityFactory.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthorityFactory.d.ts","sourceRoot":"","sources":["../../src/authority/AuthorityFactory.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,SAAS,EAAE,MAAM,aAAa,CAAC;AAExC,OAAO,EAAE,cAAc,EAAE,MAAM,2BAA2B,CAAC;AAG3D,OAAO,EAAE,aAAa,EAAE,MAAM,kCAAkC,CAAC;AACjE,OAAO,EAAE,gBAAgB,EAAE,MAAM,oBAAoB,CAAC;AAEtD,qBAAa,gBAAgB;IAEzB;;;;;;;;;OASG;WACU,wBAAwB,CAAC,YAAY,EAAE,MAAM,EAAE,aAAa,EAAE,cAAc,EAAE,YAAY,EAAE,aAAa,EAAE,gBAAgB,EAAE,gBAAgB,GAAG,OAAO,CAAC,SAAS,CAAC;IAY/K;;;;;;;;;OASG;IACH,MAAM,CAAC,cAAc,CAAC,YAAY,EAAE,MAAM,EAAE,gBAAgB,EAAE,cAAc,EAAE,YAAY,EAAE,aAAa,EAAE,gBAAgB,EAAE,gBAAgB,GAAG,SAAS;CAQ5J"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/AuthorityOptions.d.ts b/node_modules/@azure/msal-common/dist/authority/AuthorityOptions.d.ts
new file mode 100644
index 0000000..46f2bf6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/AuthorityOptions.d.ts
@@ -0,0 +1,8 @@
+import { ProtocolMode } from "./ProtocolMode";
+export declare type AuthorityOptions = {
+ protocolMode: ProtocolMode;
+ knownAuthorities: Array;
+ cloudDiscoveryMetadata: string;
+ authorityMetadata: string;
+};
+//# sourceMappingURL=AuthorityOptions.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/AuthorityOptions.d.ts.map b/node_modules/@azure/msal-common/dist/authority/AuthorityOptions.d.ts.map
new file mode 100644
index 0000000..26b163a
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/AuthorityOptions.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthorityOptions.d.ts","sourceRoot":"","sources":["../../src/authority/AuthorityOptions.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,YAAY,EAAE,MAAM,gBAAgB,CAAC;AAE9C,oBAAY,gBAAgB,GAAG;IAC3B,YAAY,EAAE,YAAY,CAAC;IAC3B,gBAAgB,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IAChC,sBAAsB,EAAE,MAAM,CAAC;IAC/B,iBAAiB,EAAE,MAAM,CAAC;CAC7B,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/AuthorityType.d.ts b/node_modules/@azure/msal-common/dist/authority/AuthorityType.d.ts
new file mode 100644
index 0000000..e541cf6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/AuthorityType.d.ts
@@ -0,0 +1,8 @@
+/**
+ * Authority types supported by MSAL.
+ */
+export declare enum AuthorityType {
+ Default = 0,
+ Adfs = 1
+}
+//# sourceMappingURL=AuthorityType.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/AuthorityType.d.ts.map b/node_modules/@azure/msal-common/dist/authority/AuthorityType.d.ts.map
new file mode 100644
index 0000000..8b0b10f
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/AuthorityType.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthorityType.d.ts","sourceRoot":"","sources":["../../src/authority/AuthorityType.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,oBAAY,aAAa;IACrB,OAAO,IAAA;IACP,IAAI,IAAA;CACP"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/CloudDiscoveryMetadata.d.ts b/node_modules/@azure/msal-common/dist/authority/CloudDiscoveryMetadata.d.ts
new file mode 100644
index 0000000..6ae3637
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/CloudDiscoveryMetadata.d.ts
@@ -0,0 +1,6 @@
+export declare type CloudDiscoveryMetadata = {
+ preferred_network: string;
+ preferred_cache: string;
+ aliases: Array;
+};
+//# sourceMappingURL=CloudDiscoveryMetadata.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/CloudDiscoveryMetadata.d.ts.map b/node_modules/@azure/msal-common/dist/authority/CloudDiscoveryMetadata.d.ts.map
new file mode 100644
index 0000000..56de6e6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/CloudDiscoveryMetadata.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CloudDiscoveryMetadata.d.ts","sourceRoot":"","sources":["../../src/authority/CloudDiscoveryMetadata.ts"],"names":[],"mappings":"AAKA,oBAAY,sBAAsB,GAAG;IACjC,iBAAiB,EAAE,MAAM,CAAC;IAC1B,eAAe,EAAE,MAAM,CAAC;IACxB,OAAO,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;CAC1B,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/CloudInstanceDiscoveryResponse.d.ts b/node_modules/@azure/msal-common/dist/authority/CloudInstanceDiscoveryResponse.d.ts
new file mode 100644
index 0000000..3ab08c5
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/CloudInstanceDiscoveryResponse.d.ts
@@ -0,0 +1,10 @@
+import { CloudDiscoveryMetadata } from "./CloudDiscoveryMetadata";
+/**
+ * The OpenID Configuration Endpoint Response type. Used by the authority class to get relevant OAuth endpoints.
+ */
+export declare type CloudInstanceDiscoveryResponse = {
+ tenant_discovery_endpoint: string;
+ metadata: Array;
+};
+export declare function isCloudInstanceDiscoveryResponse(response: object): boolean;
+//# sourceMappingURL=CloudInstanceDiscoveryResponse.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/CloudInstanceDiscoveryResponse.d.ts.map b/node_modules/@azure/msal-common/dist/authority/CloudInstanceDiscoveryResponse.d.ts.map
new file mode 100644
index 0000000..eea050c
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/CloudInstanceDiscoveryResponse.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CloudInstanceDiscoveryResponse.d.ts","sourceRoot":"","sources":["../../src/authority/CloudInstanceDiscoveryResponse.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,sBAAsB,EAAE,MAAM,0BAA0B,CAAC;AAElE;;GAEG;AACH,oBAAY,8BAA8B,GAAG;IACzC,yBAAyB,EAAE,MAAM,CAAC;IAClC,QAAQ,EAAE,KAAK,CAAC,sBAAsB,CAAC,CAAC;CAC3C,CAAC;AAEF,wBAAgB,gCAAgC,CAAC,QAAQ,EAAE,MAAM,GAAG,OAAO,CAK1E"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/OpenIdConfigResponse.d.ts b/node_modules/@azure/msal-common/dist/authority/OpenIdConfigResponse.d.ts
new file mode 100644
index 0000000..8907bb7
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/OpenIdConfigResponse.d.ts
@@ -0,0 +1,11 @@
+/**
+ * Tenant Discovery Response which contains the relevant OAuth endpoints and data needed for authentication and authorization.
+ */
+export declare type OpenIdConfigResponse = {
+ authorization_endpoint: string;
+ token_endpoint: string;
+ end_session_endpoint: string;
+ issuer: string;
+};
+export declare function isOpenIdConfigResponse(response: object): boolean;
+//# sourceMappingURL=OpenIdConfigResponse.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/OpenIdConfigResponse.d.ts.map b/node_modules/@azure/msal-common/dist/authority/OpenIdConfigResponse.d.ts.map
new file mode 100644
index 0000000..dec4a7d
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/OpenIdConfigResponse.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"OpenIdConfigResponse.d.ts","sourceRoot":"","sources":["../../src/authority/OpenIdConfigResponse.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,oBAAY,oBAAoB,GAAG;IAC/B,sBAAsB,EAAE,MAAM,CAAC;IAC/B,cAAc,EAAE,MAAM,CAAC;IACvB,oBAAoB,EAAE,MAAM,CAAC;IAC7B,MAAM,EAAE,MAAM,CAAC;CAClB,CAAC;AAEF,wBAAgB,sBAAsB,CAAC,QAAQ,EAAE,MAAM,GAAG,OAAO,CAOhE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/ProtocolMode.d.ts b/node_modules/@azure/msal-common/dist/authority/ProtocolMode.d.ts
new file mode 100644
index 0000000..9e4f293
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/ProtocolMode.d.ts
@@ -0,0 +1,8 @@
+/**
+ * Protocol modes supported by MSAL.
+ */
+export declare enum ProtocolMode {
+ AAD = "AAD",
+ OIDC = "OIDC"
+}
+//# sourceMappingURL=ProtocolMode.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/authority/ProtocolMode.d.ts.map b/node_modules/@azure/msal-common/dist/authority/ProtocolMode.d.ts.map
new file mode 100644
index 0000000..80da692
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/authority/ProtocolMode.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ProtocolMode.d.ts","sourceRoot":"","sources":["../../src/authority/ProtocolMode.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,oBAAY,YAAY;IACpB,GAAG,QAAQ;IACX,IAAI,SAAS;CAChB"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/CacheManager.d.ts b/node_modules/@azure/msal-common/dist/cache/CacheManager.d.ts
new file mode 100644
index 0000000..f031518
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/CacheManager.d.ts
@@ -0,0 +1,360 @@
+import { AccountCache, AccountFilter, CredentialFilter, CredentialCache, AppMetadataFilter, AppMetadataCache } from "./utils/CacheTypes";
+import { CacheRecord } from "./entities/CacheRecord";
+import { CredentialEntity } from "./entities/CredentialEntity";
+import { ScopeSet } from "../request/ScopeSet";
+import { AccountEntity } from "./entities/AccountEntity";
+import { AccessTokenEntity } from "./entities/AccessTokenEntity";
+import { IdTokenEntity } from "./entities/IdTokenEntity";
+import { RefreshTokenEntity } from "./entities/RefreshTokenEntity";
+import { ICacheManager } from "./interface/ICacheManager";
+import { AccountInfo } from "../account/AccountInfo";
+import { AppMetadataEntity } from "./entities/AppMetadataEntity";
+import { ServerTelemetryEntity } from "./entities/ServerTelemetryEntity";
+import { ThrottlingEntity } from "./entities/ThrottlingEntity";
+import { ICrypto } from "../crypto/ICrypto";
+import { AuthorityMetadataEntity } from "./entities/AuthorityMetadataEntity";
+/**
+ * Interface class which implement cache storage functions used by MSAL to perform validity checks, and store tokens.
+ */
+export declare abstract class CacheManager implements ICacheManager {
+ protected clientId: string;
+ protected cryptoImpl: ICrypto;
+ constructor(clientId: string, cryptoImpl: ICrypto);
+ /**
+ * fetch the account entity from the platform cache
+ * @param accountKey
+ */
+ abstract getAccount(accountKey: string): AccountEntity | null;
+ /**
+ * set account entity in the platform cache
+ * @param account
+ */
+ abstract setAccount(account: AccountEntity): void;
+ /**
+ * fetch the idToken entity from the platform cache
+ * @param idTokenKey
+ */
+ abstract getIdTokenCredential(idTokenKey: string): IdTokenEntity | null;
+ /**
+ * set idToken entity to the platform cache
+ * @param idToken
+ */
+ abstract setIdTokenCredential(idToken: IdTokenEntity): void;
+ /**
+ * fetch the idToken entity from the platform cache
+ * @param accessTokenKey
+ */
+ abstract getAccessTokenCredential(accessTokenKey: string): AccessTokenEntity | null;
+ /**
+ * set idToken entity to the platform cache
+ * @param accessToken
+ */
+ abstract setAccessTokenCredential(accessToken: AccessTokenEntity): void;
+ /**
+ * fetch the idToken entity from the platform cache
+ * @param refreshTokenKey
+ */
+ abstract getRefreshTokenCredential(refreshTokenKey: string): RefreshTokenEntity | null;
+ /**
+ * set idToken entity to the platform cache
+ * @param refreshToken
+ */
+ abstract setRefreshTokenCredential(refreshToken: RefreshTokenEntity): void;
+ /**
+ * fetch appMetadata entity from the platform cache
+ * @param appMetadataKey
+ */
+ abstract getAppMetadata(appMetadataKey: string): AppMetadataEntity | null;
+ /**
+ * set appMetadata entity to the platform cache
+ * @param appMetadata
+ */
+ abstract setAppMetadata(appMetadata: AppMetadataEntity): void;
+ /**
+ * fetch server telemetry entity from the platform cache
+ * @param serverTelemetryKey
+ */
+ abstract getServerTelemetry(serverTelemetryKey: string): ServerTelemetryEntity | null;
+ /**
+ * set server telemetry entity to the platform cache
+ * @param serverTelemetryKey
+ * @param serverTelemetry
+ */
+ abstract setServerTelemetry(serverTelemetryKey: string, serverTelemetry: ServerTelemetryEntity): void;
+ /**
+ * fetch cloud discovery metadata entity from the platform cache
+ * @param key
+ */
+ abstract getAuthorityMetadata(key: string): AuthorityMetadataEntity | null;
+ /**
+ *
+ */
+ abstract getAuthorityMetadataKeys(): Array;
+ /**
+ * set cloud discovery metadata entity to the platform cache
+ * @param key
+ * @param value
+ */
+ abstract setAuthorityMetadata(key: string, value: AuthorityMetadataEntity): void;
+ /**
+ * fetch throttling entity from the platform cache
+ * @param throttlingCacheKey
+ */
+ abstract getThrottlingCache(throttlingCacheKey: string): ThrottlingEntity | null;
+ /**
+ * set throttling entity to the platform cache
+ * @param throttlingCacheKey
+ * @param throttlingCache
+ */
+ abstract setThrottlingCache(throttlingCacheKey: string, throttlingCache: ThrottlingEntity): void;
+ /**
+ * Function to remove an item from cache given its key.
+ * @param key
+ */
+ abstract removeItem(key: string, type?: string): boolean;
+ /**
+ * Function which returns boolean whether cache contains a specific key.
+ * @param key
+ */
+ abstract containsKey(key: string, type?: string): boolean;
+ /**
+ * Function which retrieves all current keys from the cache.
+ */
+ abstract getKeys(): string[];
+ /**
+ * Function which clears cache.
+ */
+ abstract clear(): void;
+ /**
+ * Returns all accounts in cache
+ */
+ getAllAccounts(): AccountInfo[];
+ /**
+ * saves a cache record
+ * @param cacheRecord
+ */
+ saveCacheRecord(cacheRecord: CacheRecord): void;
+ /**
+ * saves access token credential
+ * @param credential
+ */
+ private saveAccessToken;
+ /**
+ * retrieve accounts matching all provided filters; if no filter is set, get all accounts
+ * not checking for casing as keys are all generated in lower case, remember to convert to lower case if object properties are compared
+ * @param homeAccountId
+ * @param environment
+ * @param realm
+ */
+ getAccountsFilteredBy(accountFilter?: AccountFilter): AccountCache;
+ /**
+ * retrieve accounts matching all provided filters; if no filter is set, get all accounts
+ * not checking for casing as keys are all generated in lower case, remember to convert to lower case if object properties are compared
+ * @param homeAccountId
+ * @param environment
+ * @param realm
+ */
+ private getAccountsFilteredByInternal;
+ /**
+ * retrieve credentails matching all provided filters; if no filter is set, get all credentials
+ * @param homeAccountId
+ * @param environment
+ * @param credentialType
+ * @param clientId
+ * @param realm
+ * @param target
+ */
+ getCredentialsFilteredBy(filter: CredentialFilter): CredentialCache;
+ /**
+ * Support function to help match credentials
+ * @param homeAccountId
+ * @param environment
+ * @param credentialType
+ * @param clientId
+ * @param realm
+ * @param target
+ */
+ private getCredentialsFilteredByInternal;
+ /**
+ * retrieve appMetadata matching all provided filters; if no filter is set, get all appMetadata
+ * @param filter
+ */
+ getAppMetadataFilteredBy(filter: AppMetadataFilter): AppMetadataCache;
+ /**
+ * Support function to help match appMetadata
+ * @param environment
+ * @param clientId
+ */
+ private getAppMetadataFilteredByInternal;
+ /**
+ * retrieve authorityMetadata that contains a matching alias
+ * @param filter
+ */
+ getAuthorityMetadataByAlias(host: string): AuthorityMetadataEntity | null;
+ /**
+ * Removes all accounts and related tokens from cache.
+ */
+ removeAllAccounts(): boolean;
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ removeAccount(accountKey: string): boolean;
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ removeAccountContext(account: AccountEntity): boolean;
+ /**
+ * returns a boolean if the given credential is removed
+ * @param credential
+ */
+ removeCredential(credential: CredentialEntity): boolean;
+ /**
+ * Removes all app metadata objects from cache.
+ */
+ removeAppMetadata(): boolean;
+ /**
+ * Retrieve the cached credentials into a cacherecord
+ * @param account
+ * @param clientId
+ * @param scopes
+ * @param environment
+ */
+ readCacheRecord(account: AccountInfo, clientId: string, scopes: ScopeSet, environment: string): CacheRecord;
+ /**
+ * Retrieve AccountEntity from cache
+ * @param account
+ */
+ readAccountFromCache(account: AccountInfo): AccountEntity | null;
+ /**
+ * Retrieve IdTokenEntity from cache
+ * @param clientId
+ * @param account
+ * @param inputRealm
+ */
+ readIdTokenFromCache(clientId: string, account: AccountInfo): IdTokenEntity | null;
+ /**
+ * Retrieve AccessTokenEntity from cache
+ * @param clientId
+ * @param account
+ * @param scopes
+ * @param inputRealm
+ */
+ readAccessTokenFromCache(clientId: string, account: AccountInfo, scopes: ScopeSet): AccessTokenEntity | null;
+ /**
+ * Helper to retrieve the appropriate refresh token from cache
+ * @param clientId
+ * @param account
+ * @param familyRT
+ */
+ readRefreshTokenFromCache(clientId: string, account: AccountInfo, familyRT: boolean): RefreshTokenEntity | null;
+ /**
+ * Retrieve AppMetadataEntity from cache
+ */
+ readAppMetadataFromCache(environment: string, clientId: string): AppMetadataEntity | null;
+ /**
+ * Return the family_id value associated with FOCI
+ * @param environment
+ * @param clientId
+ */
+ isAppMetadataFOCI(environment: string, clientId: string): boolean;
+ /**
+ * helper to match account ids
+ * @param value
+ * @param homeAccountId
+ */
+ private matchHomeAccountId;
+ /**
+ * helper to match assertion
+ * @param value
+ * @param oboAssertion
+ */
+ private matchOboAssertion;
+ /**
+ * helper to match environment
+ * @param value
+ * @param environment
+ */
+ private matchEnvironment;
+ /**
+ * helper to match credential type
+ * @param entity
+ * @param credentialType
+ */
+ private matchCredentialType;
+ /**
+ * helper to match client ids
+ * @param entity
+ * @param clientId
+ */
+ private matchClientId;
+ /**
+ * helper to match family ids
+ * @param entity
+ * @param familyId
+ */
+ private matchFamilyId;
+ /**
+ * helper to match realm
+ * @param entity
+ * @param realm
+ */
+ private matchRealm;
+ /**
+ * Returns true if the target scopes are a subset of the current entity's scopes, false otherwise.
+ * @param entity
+ * @param target
+ */
+ private matchTarget;
+ /**
+ * returns if a given cache entity is of the type appmetadata
+ * @param key
+ */
+ private isAppMetadata;
+ /**
+ * returns if a given cache entity is of the type authoritymetadata
+ * @param key
+ */
+ protected isAuthorityMetadata(key: string): boolean;
+ /**
+ * returns cache key used for cloud instance metadata
+ */
+ generateAuthorityMetadataCacheKey(authority: string): string;
+ /**
+ * Returns the specific credential (IdToken/AccessToken/RefreshToken) from the cache
+ * @param key
+ * @param credType
+ */
+ private getSpecificCredential;
+ /**
+ * Helper to convert serialized data to object
+ * @param obj
+ * @param json
+ */
+ static toObject(obj: T, json: object): T;
+}
+export declare class DefaultStorageClass extends CacheManager {
+ setAccount(): void;
+ getAccount(): AccountEntity;
+ setIdTokenCredential(): void;
+ getIdTokenCredential(): IdTokenEntity;
+ setAccessTokenCredential(): void;
+ getAccessTokenCredential(): AccessTokenEntity;
+ setRefreshTokenCredential(): void;
+ getRefreshTokenCredential(): RefreshTokenEntity;
+ setAppMetadata(): void;
+ getAppMetadata(): AppMetadataEntity;
+ setServerTelemetry(): void;
+ getServerTelemetry(): ServerTelemetryEntity;
+ setAuthorityMetadata(): void;
+ getAuthorityMetadata(): AuthorityMetadataEntity | null;
+ getAuthorityMetadataKeys(): Array;
+ setThrottlingCache(): void;
+ getThrottlingCache(): ThrottlingEntity;
+ removeItem(): boolean;
+ containsKey(): boolean;
+ getKeys(): string[];
+ clear(): void;
+}
+//# sourceMappingURL=CacheManager.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/CacheManager.d.ts.map b/node_modules/@azure/msal-common/dist/cache/CacheManager.d.ts.map
new file mode 100644
index 0000000..335beea
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/CacheManager.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CacheManager.d.ts","sourceRoot":"","sources":["../../src/cache/CacheManager.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,YAAY,EAAE,aAAa,EAAE,gBAAgB,EAAE,eAAe,EAAuB,iBAAiB,EAAE,gBAAgB,EAAE,MAAM,oBAAoB,CAAC;AAC9J,OAAO,EAAE,WAAW,EAAE,MAAM,wBAAwB,CAAC;AAErD,OAAO,EAAE,gBAAgB,EAAE,MAAM,6BAA6B,CAAC;AAC/D,OAAO,EAAE,QAAQ,EAAE,MAAM,qBAAqB,CAAC;AAC/C,OAAO,EAAE,aAAa,EAAE,MAAM,0BAA0B,CAAC;AACzD,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,aAAa,EAAE,MAAM,0BAA0B,CAAC;AACzD,OAAO,EAAE,kBAAkB,EAAE,MAAM,+BAA+B,CAAC;AAEnE,OAAO,EAAE,aAAa,EAAE,MAAM,2BAA2B,CAAC;AAE1D,OAAO,EAAE,WAAW,EAAE,MAAM,wBAAwB,CAAC;AACrD,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,qBAAqB,EAAE,MAAM,kCAAkC,CAAC;AACzE,OAAO,EAAE,gBAAgB,EAAE,MAAM,6BAA6B,CAAC;AAE/D,OAAO,EAAE,OAAO,EAAE,MAAM,mBAAmB,CAAC;AAC5C,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAE7E;;GAEG;AACH,8BAAsB,YAAa,YAAW,aAAa;IACvD,SAAS,CAAC,QAAQ,EAAE,MAAM,CAAC;IAC3B,SAAS,CAAC,UAAU,EAAE,OAAO,CAAC;gBAElB,QAAQ,EAAE,MAAM,EAAE,UAAU,EAAE,OAAO;IAKjD;;;OAGG;IACH,QAAQ,CAAC,UAAU,CAAC,UAAU,EAAE,MAAM,GAAG,aAAa,GAAG,IAAI;IAE7D;;;OAGG;IACH,QAAQ,CAAC,UAAU,CAAC,OAAO,EAAE,aAAa,GAAG,IAAI;IAEjD;;;OAGG;IACH,QAAQ,CAAC,oBAAoB,CAAC,UAAU,EAAE,MAAM,GAAG,aAAa,GAAG,IAAI;IAEvE;;;OAGG;IACH,QAAQ,CAAC,oBAAoB,CAAC,OAAO,EAAE,aAAa,GAAG,IAAI;IAE3D;;;OAGG;IACH,QAAQ,CAAC,wBAAwB,CAAC,cAAc,EAAE,MAAM,GAAG,iBAAiB,GAAG,IAAI;IAEnF;;;OAGG;IACH,QAAQ,CAAC,wBAAwB,CAAC,WAAW,EAAE,iBAAiB,GAAG,IAAI;IAEvE;;;OAGG;IACH,QAAQ,CAAC,yBAAyB,CAAC,eAAe,EAAE,MAAM,GAAG,kBAAkB,GAAG,IAAI;IAEtF;;;OAGG;IACH,QAAQ,CAAC,yBAAyB,CAAC,YAAY,EAAE,kBAAkB,GAAG,IAAI;IAE1E;;;OAGG;IACH,QAAQ,CAAC,cAAc,CAAC,cAAc,EAAE,MAAM,GAAG,iBAAiB,GAAG,IAAI;IAEzE;;;OAGG;IACH,QAAQ,CAAC,cAAc,CAAC,WAAW,EAAE,iBAAiB,GAAG,IAAI;IAE7D;;;OAGG;IACH,QAAQ,CAAC,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,GAAG,qBAAqB,GAAG,IAAI;IAErF;;;;OAIG;IACH,QAAQ,CAAC,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,EAAE,eAAe,EAAE,qBAAqB,GAAG,IAAI;IAErG;;;OAGG;IACH,QAAQ,CAAC,oBAAoB,CAAC,GAAG,EAAE,MAAM,GAAG,uBAAuB,GAAG,IAAI;IAE1E;;OAEG;IACH,QAAQ,CAAC,wBAAwB,IAAI,KAAK,CAAC,MAAM,CAAC;IAElD;;;;OAIG;IACH,QAAQ,CAAC,oBAAoB,CAAC,GAAG,EAAE,MAAM,EAAE,KAAK,EAAE,uBAAuB,GAAG,IAAI;IAEhF;;;OAGG;IACH,QAAQ,CAAC,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,GAAG,gBAAgB,GAAG,IAAI;IAEhF;;;;OAIG;IACH,QAAQ,CAAC,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,EAAE,eAAe,EAAE,gBAAgB,GAAG,IAAI;IAEhG;;;OAGG;IACH,QAAQ,CAAC,UAAU,CAAC,GAAG,EAAE,MAAM,EAAE,IAAI,CAAC,EAAE,MAAM,GAAG,OAAO;IAExD;;;OAGG;IACH,QAAQ,CAAC,WAAW,CAAC,GAAG,EAAE,MAAM,EAAE,IAAI,CAAC,EAAE,MAAM,GAAG,OAAO;IAEzD;;OAEG;IACH,QAAQ,CAAC,OAAO,IAAI,MAAM,EAAE;IAE5B;;OAEG;IACH,QAAQ,CAAC,KAAK,IAAI,IAAI;IAEtB;;OAEG;IACH,cAAc,IAAI,WAAW,EAAE;IAsB/B;;;OAGG;IACH,eAAe,CAAC,WAAW,EAAE,WAAW,GAAG,IAAI;IA0B/C;;;OAGG;IACH,OAAO,CAAC,eAAe;IAqBvB;;;;;;OAMG;IACH,qBAAqB,CAAC,aAAa,CAAC,EAAE,aAAa,GAAG,YAAY;IAQlE;;;;;;OAMG;IACH,OAAO,CAAC,6BAA6B;IAiCrC;;;;;;;;OAQG;IACH,wBAAwB,CAAC,MAAM,EAAE,gBAAgB,GAAG,eAAe;IAanE;;;;;;;;OAQG;IACH,OAAO,CAAC,gCAAgC;IAkFxC;;;OAGG;IACH,wBAAwB,CAAC,MAAM,EAAE,iBAAiB,GAAG,gBAAgB;IAOrE;;;;OAIG;IACH,OAAO,CAAC,gCAAgC;IAoCxC;;;OAGG;IACH,2BAA2B,CAAC,IAAI,EAAE,MAAM,GAAG,uBAAuB,GAAG,IAAI;IA4BzE;;OAEG;IACH,iBAAiB,IAAI,OAAO;IAa5B;;;OAGG;IACH,aAAa,CAAC,UAAU,EAAE,MAAM,GAAG,OAAO;IAQ1C;;;OAGG;IACH,oBAAoB,CAAC,OAAO,EAAE,aAAa,GAAG,OAAO;IAoBrD;;;OAGG;IACH,gBAAgB,CAAC,UAAU,EAAE,gBAAgB,GAAG,OAAO;IAKvD;;OAEG;IACH,iBAAiB,IAAI,OAAO;IAW5B;;;;;;OAMG;IACH,eAAe,CAAC,OAAO,EAAE,WAAW,EAAE,QAAQ,EAAE,MAAM,EAAE,MAAM,EAAE,QAAQ,EAAE,WAAW,EAAE,MAAM,GAAG,WAAW;IAoB3G;;;OAGG;IACH,oBAAoB,CAAC,OAAO,EAAE,WAAW,GAAG,aAAa,GAAG,IAAI;IAKhE;;;;;OAKG;IACH,oBAAoB,CAAC,QAAQ,EAAE,MAAM,EAAE,OAAO,EAAE,WAAW,GAAG,aAAa,GAAG,IAAI;IAsBlF;;;;;;OAMG;IACH,wBAAwB,CAAC,QAAQ,EAAE,MAAM,EAAE,OAAO,EAAE,WAAW,EAAE,MAAM,EAAE,QAAQ,GAAG,iBAAiB,GAAG,IAAI;IAuB5G;;;;;OAKG;IACH,yBAAyB,CAAC,QAAQ,EAAE,MAAM,EAAE,OAAO,EAAE,WAAW,EAAE,QAAQ,EAAE,OAAO,GAAG,kBAAkB,GAAG,IAAI;IAsB/G;;OAEG;IACH,wBAAwB,CAAC,WAAW,EAAE,MAAM,EAAE,QAAQ,EAAE,MAAM,GAAG,iBAAiB,GAAG,IAAI;IAmBzF;;;;OAIG;IACH,iBAAiB,CAAC,WAAW,EAAE,MAAM,EAAE,QAAQ,EAAE,MAAM,GAAG,OAAO;IAKjE;;;;OAIG;IACH,OAAO,CAAC,kBAAkB;IAI1B;;;;OAIG;IACH,OAAO,CAAC,iBAAiB;IAIzB;;;;OAIG;IACH,OAAO,CAAC,gBAAgB;IASxB;;;;OAIG;IACH,OAAO,CAAC,mBAAmB;IAI3B;;;;OAIG;IACH,OAAO,CAAC,aAAa;IAIrB;;;;OAIG;IACH,OAAO,CAAC,aAAa;IAIrB;;;;OAIG;IACH,OAAO,CAAC,UAAU;IAIlB;;;;OAIG;IACH,OAAO,CAAC,WAAW;IAcnB;;;OAGG;IACH,OAAO,CAAC,aAAa;IAIrB;;;OAGG;IACH,SAAS,CAAC,mBAAmB,CAAC,GAAG,EAAE,MAAM,GAAG,OAAO;IAInD;;OAEG;IACH,iCAAiC,CAAC,SAAS,EAAE,MAAM,GAAG,MAAM;IAI5D;;;;OAIG;IACH,OAAO,CAAC,qBAAqB;IAgB7B;;;;OAIG;IACH,MAAM,CAAC,QAAQ,CAAC,CAAC,EAAE,GAAG,EAAE,CAAC,EAAE,IAAI,EAAE,MAAM,GAAG,CAAC;CAM9C;AAED,qBAAa,mBAAoB,SAAQ,YAAY;IACjD,UAAU,IAAI,IAAI;IAIlB,UAAU,IAAI,aAAa;IAI3B,oBAAoB,IAAI,IAAI;IAI5B,oBAAoB,IAAI,aAAa;IAIrC,wBAAwB,IAAI,IAAI;IAIhC,wBAAwB,IAAI,iBAAiB;IAI7C,yBAAyB,IAAI,IAAI;IAIjC,yBAAyB,IAAI,kBAAkB;IAI/C,cAAc,IAAI,IAAI;IAItB,cAAc,IAAI,iBAAiB;IAInC,kBAAkB,IAAI,IAAI;IAI1B,kBAAkB,IAAI,qBAAqB;IAI3C,oBAAoB,IAAI,IAAI;IAI5B,oBAAoB,IAAI,uBAAuB,GAAG,IAAI;IAItD,wBAAwB,IAAI,KAAK,CAAC,MAAM,CAAC;IAIzC,kBAAkB,IAAI,IAAI;IAI1B,kBAAkB,IAAI,gBAAgB;IAItC,UAAU,IAAI,OAAO;IAIrB,WAAW,IAAI,OAAO;IAItB,OAAO,IAAI,MAAM,EAAE;IAInB,KAAK,IAAI,IAAI;CAIhB"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AccessTokenEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/AccessTokenEntity.d.ts
new file mode 100644
index 0000000..f04b500
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AccessTokenEntity.d.ts
@@ -0,0 +1,53 @@
+import { CredentialEntity } from "./CredentialEntity";
+/**
+ * ACCESS_TOKEN Credential Type
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-accesstoken-clientId-contoso.com-user.read
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, usually only used for refresh tokens
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * cachedAt: Absolute device time when entry was created in the cache.
+ * expiresOn: Token expiry time, calculated based on current UTC time in seconds. Represented as a string.
+ * extendedExpiresOn: Additional extended expiry time until when token is valid in case of server-side outage. Represented as string in UTC seconds.
+ * keyId: used for POP and SSH tokenTypes
+ * tokenType: Type of the token issued. Usually "Bearer"
+ * }
+ */
+export declare class AccessTokenEntity extends CredentialEntity {
+ realm: string;
+ target: string;
+ cachedAt: string;
+ expiresOn: string;
+ extendedExpiresOn?: string;
+ refreshOn?: string;
+ keyId?: string;
+ tokenType?: string;
+ /**
+ * Create AccessTokenEntity
+ * @param homeAccountId
+ * @param environment
+ * @param accessToken
+ * @param clientId
+ * @param tenantId
+ * @param scopes
+ * @param expiresOn
+ * @param extExpiresOn
+ */
+ static createAccessTokenEntity(homeAccountId: string, environment: string, accessToken: string, clientId: string, tenantId: string, scopes: string, expiresOn: number, extExpiresOn: number, tokenType?: string, oboAssertion?: string): AccessTokenEntity;
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ static isAccessTokenEntity(entity: object): boolean;
+}
+//# sourceMappingURL=AccessTokenEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AccessTokenEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/AccessTokenEntity.d.ts.map
new file mode 100644
index 0000000..9fdee6c
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AccessTokenEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AccessTokenEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/AccessTokenEntity.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,gBAAgB,EAAE,MAAM,oBAAoB,CAAC;AAKtD;;;;;;;;;;;;;;;;;;;;;;;GAuBG;AACH,qBAAa,iBAAkB,SAAQ,gBAAgB;IACnD,KAAK,EAAE,MAAM,CAAC;IACd,MAAM,EAAE,MAAM,CAAC;IACf,QAAQ,EAAE,MAAM,CAAC;IACjB,SAAS,EAAE,MAAM,CAAC;IAClB,iBAAiB,CAAC,EAAE,MAAM,CAAC;IAC3B,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,SAAS,CAAC,EAAE,MAAM,CAAC;IAEnB;;;;;;;;;;OAUG;IACH,MAAM,CAAC,uBAAuB,CAC1B,aAAa,EAAE,MAAM,EACrB,WAAW,EAAE,MAAM,EACnB,WAAW,EAAE,MAAM,EACnB,QAAQ,EAAE,MAAM,EAChB,QAAQ,EAAE,MAAM,EAChB,MAAM,EAAE,MAAM,EACd,SAAS,EAAE,MAAM,EACjB,YAAY,EAAE,MAAM,EACpB,SAAS,CAAC,EAAE,MAAM,EAClB,YAAY,CAAC,EAAE,MAAM,GACtB,iBAAiB;IA2BpB;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,MAAM,EAAE,MAAM,GAAG,OAAO;CAiBtD"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AccountEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/AccountEntity.d.ts
new file mode 100644
index 0000000..e214d28
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AccountEntity.d.ts
@@ -0,0 +1,100 @@
+import { Authority } from "../../authority/Authority";
+import { AuthToken } from "../../account/AuthToken";
+import { ICrypto } from "../../crypto/ICrypto";
+import { AccountInfo } from "../../account/AccountInfo";
+import { AuthorityType } from "../../authority/AuthorityType";
+import { Logger } from "../../logger/Logger";
+import { TokenClaims } from "../../account/TokenClaims";
+/**
+ * Type that defines required and optional parameters for an Account field (based on universal cache schema implemented by all MSALs).
+ *
+ * Key : Value Schema
+ *
+ * Key: --
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * localAccountId: Original tenant-specific accountID, usually used for legacy cases
+ * username: primary username that represents the user, usually corresponds to preferred_username in the v2 endpt
+ * authorityType: Accounts authority type as a string
+ * name: Full name for the account, including given name and family name,
+ * clientInfo: Full base64 encoded client info received from ESTS
+ * lastModificationTime: last time this entity was modified in the cache
+ * lastModificationApp:
+ * oboAssertion: access token passed in as part of OBO request
+ * idTokenClaims: Object containing claims parsed from ID token
+ * }
+ */
+export declare class AccountEntity {
+ homeAccountId: string;
+ environment: string;
+ realm: string;
+ localAccountId: string;
+ username: string;
+ authorityType: string;
+ name?: string;
+ clientInfo?: string;
+ lastModificationTime?: string;
+ lastModificationApp?: string;
+ oboAssertion?: string;
+ cloudGraphHostName?: string;
+ msGraphHost?: string;
+ idTokenClaims?: TokenClaims;
+ /**
+ * Generate Account Id key component as per the schema: -
+ */
+ generateAccountId(): string;
+ /**
+ * Generate Account Cache Key as per the schema: --
+ */
+ generateAccountKey(): string;
+ /**
+ * returns the type of the cache (in this case account)
+ */
+ generateType(): number;
+ /**
+ * Returns the AccountInfo interface for this account.
+ */
+ getAccountInfo(): AccountInfo;
+ /**
+ * Generates account key from interface
+ * @param accountInterface
+ */
+ static generateAccountCacheKey(accountInterface: AccountInfo): string;
+ /**
+ * Build Account cache from IdToken, clientInfo and authority/policy. Associated with AAD.
+ * @param clientInfo
+ * @param authority
+ * @param idToken
+ * @param policy
+ */
+ static createAccount(clientInfo: string, homeAccountId: string, authority: Authority, idToken: AuthToken, oboAssertion?: string, cloudGraphHostName?: string, msGraphHost?: string): AccountEntity;
+ /**
+ * Builds non-AAD/ADFS account.
+ * @param authority
+ * @param idToken
+ */
+ static createGenericAccount(authority: Authority, homeAccountId: string, idToken: AuthToken, oboAssertion?: string, cloudGraphHostName?: string, msGraphHost?: string): AccountEntity;
+ /**
+ * Generate HomeAccountId from server response
+ * @param serverClientInfo
+ * @param authType
+ */
+ static generateHomeAccountId(serverClientInfo: string, authType: AuthorityType, logger: Logger, cryptoObj: ICrypto, idToken?: AuthToken): string;
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ static isAccountEntity(entity: object): boolean;
+ /**
+ * Helper function to determine whether 2 accounts are equal
+ * Used to avoid unnecessary state updates
+ * @param arrayA
+ * @param arrayB
+ */
+ static accountInfoIsEqual(accountA: AccountInfo | null, accountB: AccountInfo | null): boolean;
+}
+//# sourceMappingURL=AccountEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AccountEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/AccountEntity.d.ts.map
new file mode 100644
index 0000000..7ec87dd
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AccountEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AccountEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/AccountEntity.ts"],"names":[],"mappings":"AAWA,OAAO,EAAE,SAAS,EAAE,MAAM,2BAA2B,CAAC;AACtD,OAAO,EAAE,SAAS,EAAE,MAAM,yBAAyB,CAAC;AACpD,OAAO,EAAE,OAAO,EAAE,MAAM,sBAAsB,CAAC;AAG/C,OAAO,EAAE,WAAW,EAAE,MAAM,2BAA2B,CAAC;AAExD,OAAO,EAAE,aAAa,EAAE,MAAM,+BAA+B,CAAC;AAC9D,OAAO,EAAE,MAAM,EAAE,MAAM,qBAAqB,CAAC;AAC7C,OAAO,EAAE,WAAW,EAAE,MAAM,2BAA2B,CAAC;AAExD;;;;;;;;;;;;;;;;;;;;;;GAsBG;AACH,qBAAa,aAAa;IACtB,aAAa,EAAE,MAAM,CAAC;IACtB,WAAW,EAAE,MAAM,CAAC;IACpB,KAAK,EAAE,MAAM,CAAC;IACd,cAAc,EAAE,MAAM,CAAC;IACvB,QAAQ,EAAE,MAAM,CAAC;IACjB,aAAa,EAAE,MAAM,CAAC;IACtB,IAAI,CAAC,EAAE,MAAM,CAAC;IACd,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,oBAAoB,CAAC,EAAE,MAAM,CAAC;IAC9B,mBAAmB,CAAC,EAAE,MAAM,CAAC;IAC7B,YAAY,CAAC,EAAE,MAAM,CAAC;IACtB,kBAAkB,CAAC,EAAE,MAAM,CAAC;IAC5B,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,aAAa,CAAC,EAAE,WAAW,CAAC;IAE5B;;OAEG;IACH,iBAAiB,IAAI,MAAM;IAK3B;;OAEG;IACH,kBAAkB,IAAI,MAAM;IAU5B;;OAEG;IACH,YAAY,IAAI,MAAM;IAgBtB;;OAEG;IACH,cAAc,IAAI,WAAW;IAY7B;;;OAGG;IACH,MAAM,CAAC,uBAAuB,CAAC,gBAAgB,EAAE,WAAW,GAAG,MAAM;IAUrE;;;;;;OAMG;IACH,MAAM,CAAC,aAAa,CAChB,UAAU,EAAE,MAAM,EAClB,aAAa,EAAE,MAAM,EACrB,SAAS,EAAE,SAAS,EACpB,OAAO,EAAE,SAAS,EAClB,YAAY,CAAC,EAAE,MAAM,EACrB,kBAAkB,CAAC,EAAE,MAAM,EAC3B,WAAW,CAAC,EAAE,MAAM,GACrB,aAAa;IAqChB;;;;OAIG;IACH,MAAM,CAAC,oBAAoB,CACvB,SAAS,EAAE,SAAS,EACpB,aAAa,EAAE,MAAM,EACrB,OAAO,EAAE,SAAS,EAClB,YAAY,CAAC,EAAE,MAAM,EACrB,kBAAkB,CAAC,EAAE,MAAM,EAC3B,WAAW,CAAC,EAAE,MAAM,GACrB,aAAa;IAqChB;;;;OAIG;IACH,MAAM,CAAC,qBAAqB,CAAC,gBAAgB,EAAE,MAAM,EAAE,QAAQ,EAAE,aAAa,EAAE,MAAM,EAAE,MAAM,EAAE,SAAS,EAAE,OAAO,EAAE,OAAO,CAAC,EAAE,SAAS,GAAG,MAAM;IAsBhJ;;;OAGG;IACH,MAAM,CAAC,eAAe,CAAC,MAAM,EAAE,MAAM,GAAG,OAAO;IAgB/C;;;;;OAKG;IACH,MAAM,CAAC,kBAAkB,CAAC,QAAQ,EAAE,WAAW,GAAG,IAAI,EAAE,QAAQ,EAAE,WAAW,GAAG,IAAI,GAAG,OAAO;CAUjG"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AppMetadataEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/AppMetadataEntity.d.ts
new file mode 100644
index 0000000..9433d94
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AppMetadataEntity.d.ts
@@ -0,0 +1,40 @@
+/**
+ * APP_METADATA Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key: appmetadata--
+ *
+ * Value:
+ * {
+ * clientId: client ID of the application
+ * environment: entity that issued the token, represented as a full host
+ * familyId: Family ID identifier, '1' represents Microsoft Family
+ * }
+ */
+export declare class AppMetadataEntity {
+ clientId: string;
+ environment: string;
+ familyId?: string;
+ /**
+ * Generate AppMetadata Cache Key as per the schema: appmetadata--
+ */
+ generateAppMetadataKey(): string;
+ /**
+ * Generate AppMetadata Cache Key
+ */
+ static generateAppMetadataCacheKey(environment: string, clientId: string): string;
+ /**
+ * Creates AppMetadataEntity
+ * @param clientId
+ * @param environment
+ * @param familyId
+ */
+ static createAppMetadataEntity(clientId: string, environment: string, familyId?: string): AppMetadataEntity;
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ static isAppMetadataEntity(key: string, entity: object): boolean;
+}
+//# sourceMappingURL=AppMetadataEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AppMetadataEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/AppMetadataEntity.d.ts.map
new file mode 100644
index 0000000..95884b4
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AppMetadataEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AppMetadataEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/AppMetadataEntity.ts"],"names":[],"mappings":"AAOA;;;;;;;;;;;;;GAaG;AACH,qBAAa,iBAAiB;IAC1B,QAAQ,EAAE,MAAM,CAAC;IACjB,WAAW,EAAE,MAAM,CAAC;IACpB,QAAQ,CAAC,EAAE,MAAM,CAAC;IAElB;;OAEG;IACH,sBAAsB,IAAI,MAAM;IAIhC;;OAEG;IACH,MAAM,CAAC,2BAA2B,CAAC,WAAW,EAAE,MAAM,EAAE,QAAQ,EAAE,MAAM,GAAG,MAAM;IASjF;;;;;OAKG;IACH,MAAM,CAAC,uBAAuB,CAAC,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,MAAM,EAAE,QAAQ,CAAC,EAAE,MAAM,GAAG,iBAAiB;IAY3G;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,GAAG,EAAE,MAAM,EAAE,MAAM,EAAE,MAAM,GAAG,OAAO;CAYnE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AuthorityMetadataEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/AuthorityMetadataEntity.d.ts
new file mode 100644
index 0000000..cffcb2e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AuthorityMetadataEntity.d.ts
@@ -0,0 +1,47 @@
+import { CloudDiscoveryMetadata } from "../../authority/CloudDiscoveryMetadata";
+import { OpenIdConfigResponse } from "../../authority/OpenIdConfigResponse";
+export declare class AuthorityMetadataEntity {
+ aliases: Array;
+ preferred_cache: string;
+ preferred_network: string;
+ canonical_authority: string;
+ authorization_endpoint: string;
+ token_endpoint: string;
+ end_session_endpoint: string;
+ issuer: string;
+ aliasesFromNetwork: boolean;
+ endpointsFromNetwork: boolean;
+ expiresAt: number;
+ constructor();
+ /**
+ * Update the entity with new aliases, preferred_cache and preferred_network values
+ * @param metadata
+ * @param fromNetwork
+ */
+ updateCloudDiscoveryMetadata(metadata: CloudDiscoveryMetadata, fromNetwork: boolean): void;
+ /**
+ * Update the entity with new endpoints
+ * @param metadata
+ * @param fromNetwork
+ */
+ updateEndpointMetadata(metadata: OpenIdConfigResponse, fromNetwork: boolean): void;
+ /**
+ * Save the authority that was used to create this cache entry
+ * @param authority
+ */
+ updateCanonicalAuthority(authority: string): void;
+ /**
+ * Reset the exiresAt value
+ */
+ resetExpiresAt(): void;
+ /**
+ * Returns whether or not the data needs to be refreshed
+ */
+ isExpired(): boolean;
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ static isAuthorityMetadataEntity(key: string, entity: object): boolean;
+}
+//# sourceMappingURL=AuthorityMetadataEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/AuthorityMetadataEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/AuthorityMetadataEntity.d.ts.map
new file mode 100644
index 0000000..f719245
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/AuthorityMetadataEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthorityMetadataEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/AuthorityMetadataEntity.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,sBAAsB,EAAE,MAAM,wCAAwC,CAAC;AAChF,OAAO,EAAE,oBAAoB,EAAE,MAAM,sCAAsC,CAAC;AAI5E,qBAAa,uBAAuB;IAChC,OAAO,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IACvB,eAAe,EAAE,MAAM,CAAC;IACxB,iBAAiB,EAAE,MAAM,CAAC;IAC1B,mBAAmB,EAAE,MAAM,CAAC;IAC5B,sBAAsB,EAAE,MAAM,CAAC;IAC/B,cAAc,EAAE,MAAM,CAAC;IACvB,oBAAoB,EAAE,MAAM,CAAC;IAC7B,MAAM,EAAE,MAAM,CAAC;IACf,kBAAkB,EAAE,OAAO,CAAC;IAC5B,oBAAoB,EAAE,OAAO,CAAC;IAC9B,SAAS,EAAE,MAAM,CAAC;;IAMlB;;;;OAIG;IACH,4BAA4B,CAAC,QAAQ,EAAE,sBAAsB,EAAE,WAAW,EAAE,OAAO;IAOnF;;;;OAIG;IACH,sBAAsB,CAAC,QAAQ,EAAE,oBAAoB,EAAE,WAAW,EAAE,OAAO;IAQ3E;;;OAGG;IACH,wBAAwB,CAAC,SAAS,EAAE,MAAM;IAI1C;;OAEG;IACH,cAAc;IAId;;OAEG;IACH,SAAS,IAAI,OAAO;IAIpB;;;OAGG;IACH,MAAM,CAAC,yBAAyB,CAAC,GAAG,EAAE,MAAM,EAAE,MAAM,EAAE,MAAM,GAAG,OAAO;CAqBzE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/CacheRecord.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/CacheRecord.d.ts
new file mode 100644
index 0000000..830247c
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/CacheRecord.d.ts
@@ -0,0 +1,14 @@
+import { IdTokenEntity } from "./IdTokenEntity";
+import { AccessTokenEntity } from "./AccessTokenEntity";
+import { RefreshTokenEntity } from "./RefreshTokenEntity";
+import { AccountEntity } from "./AccountEntity";
+import { AppMetadataEntity } from "./AppMetadataEntity";
+export declare class CacheRecord {
+ account: AccountEntity | null;
+ idToken: IdTokenEntity | null;
+ accessToken: AccessTokenEntity | null;
+ refreshToken: RefreshTokenEntity | null;
+ appMetadata: AppMetadataEntity | null;
+ constructor(accountEntity?: AccountEntity | null, idTokenEntity?: IdTokenEntity | null, accessTokenEntity?: AccessTokenEntity | null, refreshTokenEntity?: RefreshTokenEntity | null, appMetadataEntity?: AppMetadataEntity | null);
+}
+//# sourceMappingURL=CacheRecord.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/CacheRecord.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/CacheRecord.d.ts.map
new file mode 100644
index 0000000..d057f5f
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/CacheRecord.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CacheRecord.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/CacheRecord.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,aAAa,EAAE,MAAM,iBAAiB,CAAC;AAChD,OAAO,EAAE,iBAAiB,EAAE,MAAM,qBAAqB,CAAC;AACxD,OAAO,EAAE,kBAAkB,EAAE,MAAM,sBAAsB,CAAC;AAC1D,OAAO,EAAE,aAAa,EAAE,MAAM,iBAAiB,CAAC;AAChD,OAAO,EAAE,iBAAiB,EAAE,MAAM,qBAAqB,CAAC;AAExD,qBAAa,WAAW;IACpB,OAAO,EAAE,aAAa,GAAG,IAAI,CAAC;IAC9B,OAAO,EAAE,aAAa,GAAG,IAAI,CAAC;IAC9B,WAAW,EAAE,iBAAiB,GAAG,IAAI,CAAC;IACtC,YAAY,EAAE,kBAAkB,GAAG,IAAI,CAAC;IACxC,WAAW,EAAE,iBAAiB,GAAG,IAAI,CAAC;gBAE1B,aAAa,CAAC,EAAE,aAAa,GAAG,IAAI,EAAE,aAAa,CAAC,EAAE,aAAa,GAAG,IAAI,EAAE,iBAAiB,CAAC,EAAE,iBAAiB,GAAG,IAAI,EAAE,kBAAkB,CAAC,EAAE,kBAAkB,GAAG,IAAI,EAAE,iBAAiB,CAAC,EAAE,iBAAiB,GAAG,IAAI;CAOrO"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/CredentialEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/CredentialEntity.d.ts
new file mode 100644
index 0000000..45a0e3c
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/CredentialEntity.d.ts
@@ -0,0 +1,80 @@
+import { CredentialType } from "../../utils/Constants";
+/**
+ * Base type for credentials to be stored in the cache: eg: ACCESS_TOKEN, ID_TOKEN etc
+ *
+ * Key:Value Schema:
+ *
+ * Key: -----
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, usually only used for refresh tokens
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * oboAssertion: access token passed in as part of OBO request
+ * }
+ */
+export declare class CredentialEntity {
+ homeAccountId: string;
+ environment: string;
+ credentialType: CredentialType;
+ clientId: string;
+ secret: string;
+ familyId?: string;
+ realm?: string;
+ target?: string;
+ oboAssertion?: string;
+ /**
+ * Generate Account Id key component as per the schema: -
+ */
+ generateAccountId(): string;
+ /**
+ * Generate Credential Id key component as per the schema: --
+ */
+ generateCredentialId(): string;
+ /**
+ * Generate target key component as per schema:
+ */
+ generateTarget(): string;
+ /**
+ * generates credential key
+ */
+ generateCredentialKey(): string;
+ /**
+ * returns the type of the cache (in this case credential)
+ */
+ generateType(): number;
+ /**
+ * helper function to return `CredentialType`
+ * @param key
+ */
+ static getCredentialType(key: string): string;
+ /**
+ * generates credential key
+ */
+ static generateCredentialCacheKey(homeAccountId: string, environment: string, credentialType: CredentialType, clientId: string, realm?: string, target?: string, familyId?: string): string;
+ /**
+ * generates Account Id for keys
+ * @param homeAccountId
+ * @param environment
+ */
+ private static generateAccountIdForCacheKey;
+ /**
+ * Generates Credential Id for keys
+ * @param credentialType
+ * @param realm
+ * @param clientId
+ * @param familyId
+ */
+ private static generateCredentialIdForCacheKey;
+ /**
+ * Generate target key component as per schema:
+ */
+ private static generateTargetForCacheKey;
+}
+//# sourceMappingURL=CredentialEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/CredentialEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/CredentialEntity.d.ts.map
new file mode 100644
index 0000000..24451e6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/CredentialEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CredentialEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/CredentialEntity.ts"],"names":[],"mappings":"AAKA,OAAO,EAAc,cAAc,EAAwB,MAAM,uBAAuB,CAAC;AAGzF;;;;;;;;;;;;;;;;;;;GAmBG;AACH,qBAAa,gBAAgB;IACzB,aAAa,EAAE,MAAM,CAAC;IACtB,WAAW,EAAE,MAAM,CAAC;IACpB,cAAc,EAAE,cAAc,CAAC;IAC/B,QAAQ,EAAE,MAAM,CAAC;IACjB,MAAM,EAAE,MAAM,CAAC;IACf,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,YAAY,CAAC,EAAE,MAAM,CAAC;IAEtB;;OAEG;IACH,iBAAiB,IAAI,MAAM;IAI3B;;OAEG;IACH,oBAAoB,IAAI,MAAM;IAS9B;;OAEG;IACH,cAAc,IAAI,MAAM;IAIxB;;OAEG;IACH,qBAAqB,IAAI,MAAM;IAY/B;;OAEG;IACH,YAAY,IAAI,MAAM;IActB;;;OAGG;IACH,MAAM,CAAC,iBAAiB,CAAC,GAAG,EAAE,MAAM,GAAG,MAAM;IAY7C;;OAEG;IACH,MAAM,CAAC,0BAA0B,CAC7B,aAAa,EAAE,MAAM,EACrB,WAAW,EAAE,MAAM,EACnB,cAAc,EAAE,cAAc,EAC9B,QAAQ,EAAE,MAAM,EAChB,KAAK,CAAC,EAAE,MAAM,EACd,MAAM,CAAC,EAAE,MAAM,EACf,QAAQ,CAAC,EAAE,MAAM,GAClB,MAAM;IAUT;;;;OAIG;IACH,OAAO,CAAC,MAAM,CAAC,4BAA4B;IAQ3C;;;;;;OAMG;IACH,OAAO,CAAC,MAAM,CAAC,+BAA+B;IAmB9C;;OAEG;IACH,OAAO,CAAC,MAAM,CAAC,yBAAyB;CAG3C"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/IdTokenEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/IdTokenEntity.d.ts
new file mode 100644
index 0000000..04332b3
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/IdTokenEntity.d.ts
@@ -0,0 +1,35 @@
+import { CredentialEntity } from "./CredentialEntity";
+/**
+ * ID_TOKEN Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-idtoken-clientId-contoso.com-
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * }
+ */
+export declare class IdTokenEntity extends CredentialEntity {
+ realm: string;
+ /**
+ * Create IdTokenEntity
+ * @param homeAccountId
+ * @param authenticationResult
+ * @param clientId
+ * @param authority
+ */
+ static createIdTokenEntity(homeAccountId: string, environment: string, idToken: string, clientId: string, tenantId: string, oboAssertion?: string): IdTokenEntity;
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ static isIdTokenEntity(entity: object): boolean;
+}
+//# sourceMappingURL=IdTokenEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/IdTokenEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/IdTokenEntity.d.ts.map
new file mode 100644
index 0000000..e09e599
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/IdTokenEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"IdTokenEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/IdTokenEntity.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,gBAAgB,EAAE,MAAM,oBAAoB,CAAC;AAGtD;;;;;;;;;;;;;;;;GAgBG;AACH,qBAAa,aAAc,SAAQ,gBAAgB;IAC/C,KAAK,EAAE,MAAM,CAAC;IAEd;;;;;;OAMG;IACH,MAAM,CAAC,mBAAmB,CACtB,aAAa,EAAE,MAAM,EACrB,WAAW,EAAE,MAAM,EACnB,OAAO,EAAE,MAAM,EACf,QAAQ,EAAE,MAAM,EAChB,QAAQ,EAAE,MAAM,EAChB,YAAY,CAAC,EAAE,MAAM,GACtB,aAAa;IAchB;;;OAGG;IACH,MAAM,CAAC,eAAe,CAAC,MAAM,EAAE,MAAM,GAAG,OAAO;CAgBlD"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/RefreshTokenEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/RefreshTokenEntity.d.ts
new file mode 100644
index 0000000..9669bd9
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/RefreshTokenEntity.d.ts
@@ -0,0 +1,37 @@
+import { CredentialEntity } from "./CredentialEntity";
+/**
+ * REFRESH_TOKEN Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-refreshtoken-clientId--
+ *
+ * Value:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, '1' represents Microsoft Family
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * }
+ */
+export declare class RefreshTokenEntity extends CredentialEntity {
+ familyId?: string;
+ /**
+ * Create RefreshTokenEntity
+ * @param homeAccountId
+ * @param authenticationResult
+ * @param clientId
+ * @param authority
+ */
+ static createRefreshTokenEntity(homeAccountId: string, environment: string, refreshToken: string, clientId: string, familyId?: string, oboAssertion?: string): RefreshTokenEntity;
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ static isRefreshTokenEntity(entity: object): boolean;
+}
+//# sourceMappingURL=RefreshTokenEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/RefreshTokenEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/RefreshTokenEntity.d.ts.map
new file mode 100644
index 0000000..57453a7
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/RefreshTokenEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"RefreshTokenEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/RefreshTokenEntity.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,gBAAgB,EAAE,MAAM,oBAAoB,CAAC;AAGtD;;;;;;;;;;;;;;;;;;GAkBG;AACH,qBAAa,kBAAmB,SAAQ,gBAAgB;IACpD,QAAQ,CAAC,EAAE,MAAM,CAAC;IAElB;;;;;;OAMG;IACH,MAAM,CAAC,wBAAwB,CAC3B,aAAa,EAAE,MAAM,EACrB,WAAW,EAAE,MAAM,EACnB,YAAY,EAAE,MAAM,EACpB,QAAQ,EAAE,MAAM,EAChB,QAAQ,CAAC,EAAE,MAAM,EACjB,YAAY,CAAC,EAAE,MAAM,GACtB,kBAAkB;IAgBrB;;;OAGG;IACH,MAAM,CAAC,oBAAoB,CAAC,MAAM,EAAE,MAAM,GAAG,OAAO;CAevD"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/ServerTelemetryEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/ServerTelemetryEntity.d.ts
new file mode 100644
index 0000000..8b8b5b0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/ServerTelemetryEntity.d.ts
@@ -0,0 +1,13 @@
+export declare class ServerTelemetryEntity {
+ failedRequests: Array;
+ errors: string[];
+ cacheHits: number;
+ constructor();
+ /**
+ * validates if a given cache entry is "Telemetry", parses
+ * @param key
+ * @param entity
+ */
+ static isServerTelemetryEntity(key: string, entity?: object): boolean;
+}
+//# sourceMappingURL=ServerTelemetryEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/ServerTelemetryEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/ServerTelemetryEntity.d.ts.map
new file mode 100644
index 0000000..41504ac
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/ServerTelemetryEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ServerTelemetryEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/ServerTelemetryEntity.ts"],"names":[],"mappings":"AAOA,qBAAa,qBAAqB;IAC9B,cAAc,EAAE,KAAK,CAAC,MAAM,GAAC,MAAM,CAAC,CAAC;IACrC,MAAM,EAAE,MAAM,EAAE,CAAC;IACjB,SAAS,EAAE,MAAM,CAAC;;IAQlB;;;;OAIG;IACH,MAAM,CAAC,uBAAuB,CAAC,GAAG,EAAE,MAAM,EAAE,MAAM,CAAC,EAAE,MAAM,GAAG,OAAO;CAcxE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/ThrottlingEntity.d.ts b/node_modules/@azure/msal-common/dist/cache/entities/ThrottlingEntity.d.ts
new file mode 100644
index 0000000..c8a31de
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/ThrottlingEntity.d.ts
@@ -0,0 +1,14 @@
+export declare class ThrottlingEntity {
+ throttleTime: number;
+ error?: string;
+ errorCodes?: Array;
+ errorMessage?: string;
+ subError?: string;
+ /**
+ * validates if a given cache entry is "Throttling", parses
+ * @param key
+ * @param entity
+ */
+ static isThrottlingEntity(key: string, entity?: object): boolean;
+}
+//# sourceMappingURL=ThrottlingEntity.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/entities/ThrottlingEntity.d.ts.map b/node_modules/@azure/msal-common/dist/cache/entities/ThrottlingEntity.d.ts.map
new file mode 100644
index 0000000..435d716
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/entities/ThrottlingEntity.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ThrottlingEntity.d.ts","sourceRoot":"","sources":["../../../src/cache/entities/ThrottlingEntity.ts"],"names":[],"mappings":"AAOA,qBAAa,gBAAgB;IAEzB,YAAY,EAAE,MAAM,CAAC;IAErB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,UAAU,CAAC,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IAC3B,YAAY,CAAC,EAAE,MAAM,CAAC;IACtB,QAAQ,CAAC,EAAE,MAAM,CAAC;IAElB;;;;OAIG;IACH,MAAM,CAAC,kBAAkB,CAAC,GAAG,EAAE,MAAM,EAAE,MAAM,CAAC,EAAE,MAAM,GAAG,OAAO;CAcnE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/interface/ICacheManager.d.ts b/node_modules/@azure/msal-common/dist/cache/interface/ICacheManager.d.ts
new file mode 100644
index 0000000..0697620
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/interface/ICacheManager.d.ts
@@ -0,0 +1,157 @@
+import { CredentialEntity } from "../entities/CredentialEntity";
+import { AccountCache, CredentialCache, AccountFilter, CredentialFilter } from "../utils/CacheTypes";
+import { CacheRecord } from "../entities/CacheRecord";
+import { AccountEntity } from "../entities/AccountEntity";
+import { AccountInfo } from "../../account/AccountInfo";
+import { AppMetadataEntity } from "../entities/AppMetadataEntity";
+import { ServerTelemetryEntity } from "../entities/ServerTelemetryEntity";
+import { ThrottlingEntity } from "../entities/ThrottlingEntity";
+import { IdTokenEntity } from "../entities/IdTokenEntity";
+import { AccessTokenEntity } from "../entities/AccessTokenEntity";
+import { RefreshTokenEntity } from "../entities/RefreshTokenEntity";
+import { AuthorityMetadataEntity } from "../entities/AuthorityMetadataEntity";
+export interface ICacheManager {
+ /**
+ * fetch the account entity from the platform cache
+ * @param accountKey
+ */
+ getAccount(accountKey: string): AccountEntity | null;
+ /**
+ * set account entity in the platform cache
+ * @param account
+ */
+ setAccount(account: AccountEntity): void;
+ /**
+ * fetch the idToken entity from the platform cache
+ * @param idTokenKey
+ */
+ getIdTokenCredential(idTokenKey: string): IdTokenEntity | null;
+ /**
+ * set idToken entity to the platform cache
+ * @param idToken
+ */
+ setIdTokenCredential(idToken: IdTokenEntity): void;
+ /**
+ * fetch the idToken entity from the platform cache
+ * @param accessTokenKey
+ */
+ getAccessTokenCredential(accessTokenKey: string): AccessTokenEntity | null;
+ /**
+ * set idToken entity to the platform cache
+ * @param accessToken
+ */
+ setAccessTokenCredential(accessToken: AccessTokenEntity): void;
+ /**
+ * fetch the idToken entity from the platform cache
+ * @param refreshTokenKey
+ */
+ getRefreshTokenCredential(refreshTokenKey: string): RefreshTokenEntity | null;
+ /**
+ * set idToken entity to the platform cache
+ * @param refreshToken
+ */
+ setRefreshTokenCredential(refreshToken: RefreshTokenEntity): void;
+ /**
+ * fetch appMetadata entity from the platform cache
+ * @param appMetadataKey
+ */
+ getAppMetadata(appMetadataKey: string): AppMetadataEntity | null;
+ /**
+ * set appMetadata entity to the platform cache
+ * @param appMetadata
+ */
+ setAppMetadata(appMetadata: AppMetadataEntity): void;
+ /**
+ * fetch server telemetry entity from the platform cache
+ * @param serverTelemetryKey
+ */
+ getServerTelemetry(serverTelemetryKey: string): ServerTelemetryEntity | null;
+ /**
+ * set server telemetry entity to the platform cache
+ * @param serverTelemetryKey
+ * @param serverTelemetry
+ */
+ setServerTelemetry(serverTelemetryKey: string, serverTelemetry: ServerTelemetryEntity): void;
+ /**
+ * fetch cloud discovery metadata entity from the platform cache
+ * @param key
+ */
+ getAuthorityMetadata(key: string): AuthorityMetadataEntity | null;
+ /**
+ * Get cache keys for authority metadata
+ */
+ getAuthorityMetadataKeys(): Array;
+ /**
+ * set cloud discovery metadata entity to the platform cache
+ * @param key
+ * @param value
+ */
+ setAuthorityMetadata(key: string, value: AuthorityMetadataEntity): void;
+ /**
+ * Provide an alias to find a matching AuthorityMetadataEntity in cache
+ * @param host
+ */
+ getAuthorityMetadataByAlias(host: string): AuthorityMetadataEntity | null;
+ /**
+ * given an authority generates the cache key for authorityMetadata
+ * @param authority
+ */
+ generateAuthorityMetadataCacheKey(authority: string): string;
+ /**
+ * fetch throttling entity from the platform cache
+ * @param throttlingCacheKey
+ */
+ getThrottlingCache(throttlingCacheKey: string): ThrottlingEntity | null;
+ /**
+ * set throttling entity to the platform cache
+ * @param throttlingCacheKey
+ * @param throttlingCache
+ */
+ setThrottlingCache(throttlingCacheKey: string, throttlingCache: ThrottlingEntity): void;
+ /**
+ * Returns all accounts in cache
+ */
+ getAllAccounts(): AccountInfo[];
+ /**
+ * saves a cache record
+ * @param cacheRecord
+ */
+ saveCacheRecord(cacheRecord: CacheRecord): void;
+ /**
+ * retrieve accounts matching all provided filters; if no filter is set, get all accounts
+ * @param homeAccountId
+ * @param environment
+ * @param realm
+ */
+ getAccountsFilteredBy(filter: AccountFilter): AccountCache;
+ /**
+ * retrieve credentials matching all provided filters; if no filter is set, get all credentials
+ * @param homeAccountId
+ * @param environment
+ * @param credentialType
+ * @param clientId
+ * @param realm
+ * @param target
+ */
+ getCredentialsFilteredBy(filter: CredentialFilter): CredentialCache;
+ /**
+ * Removes all accounts and related tokens from cache.
+ */
+ removeAllAccounts(): boolean;
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ removeAccount(accountKey: string): boolean;
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ removeAccountContext(account: AccountEntity): boolean;
+ /**
+ * returns a boolean if the given credential is removed
+ * @param credential
+ */
+ removeCredential(credential: CredentialEntity): boolean;
+}
+//# sourceMappingURL=ICacheManager.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/interface/ICacheManager.d.ts.map b/node_modules/@azure/msal-common/dist/cache/interface/ICacheManager.d.ts.map
new file mode 100644
index 0000000..8f9d30e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/interface/ICacheManager.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ICacheManager.d.ts","sourceRoot":"","sources":["../../../src/cache/interface/ICacheManager.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,gBAAgB,EAAE,MAAM,8BAA8B,CAAC;AAChE,OAAO,EACH,YAAY,EACZ,eAAe,EACf,aAAa,EACb,gBAAgB,EACnB,MAAM,qBAAqB,CAAC;AAC7B,OAAO,EAAE,WAAW,EAAE,MAAM,yBAAyB,CAAC;AACtD,OAAO,EAAE,aAAa,EAAE,MAAM,2BAA2B,CAAC;AAC1D,OAAO,EAAE,WAAW,EAAE,MAAM,2BAA2B,CAAC;AACxD,OAAO,EAAE,iBAAiB,EAAE,MAAM,+BAA+B,CAAC;AAClE,OAAO,EAAE,qBAAqB,EAAE,MAAM,mCAAmC,CAAC;AAC1E,OAAO,EAAE,gBAAgB,EAAE,MAAM,8BAA8B,CAAC;AAChE,OAAO,EAAE,aAAa,EAAE,MAAM,2BAA2B,CAAC;AAC1D,OAAO,EAAE,iBAAiB,EAAE,MAAM,+BAA+B,CAAC;AAClE,OAAO,EAAE,kBAAkB,EAAE,MAAM,gCAAgC,CAAC;AACpE,OAAO,EAAE,uBAAuB,EAAE,MAAM,qCAAqC,CAAC;AAE9E,MAAM,WAAW,aAAa;IAE1B;;;OAGG;IACH,UAAU,CAAC,UAAU,EAAE,MAAM,GAAG,aAAa,GAAG,IAAI,CAAC;IAErD;;;OAGG;IACH,UAAU,CAAC,OAAO,EAAE,aAAa,GAAG,IAAI,CAAC;IAEzC;;;OAGG;IACH,oBAAoB,CAAC,UAAU,EAAE,MAAM,GAAG,aAAa,GAAG,IAAI,CAAC;IAE/D;;;OAGG;IACH,oBAAoB,CAAC,OAAO,EAAE,aAAa,GAAG,IAAI,CAAC;IAEnD;;;OAGG;IACH,wBAAwB,CAAC,cAAc,EAAE,MAAM,GAAG,iBAAiB,GAAG,IAAI,CAAC;IAE3E;;;OAGG;IACH,wBAAwB,CAAC,WAAW,EAAE,iBAAiB,GAAG,IAAI,CAAC;IAE/D;;;OAGG;IACH,yBAAyB,CAAC,eAAe,EAAE,MAAM,GAAG,kBAAkB,GAAG,IAAI,CAAC;IAE9E;;;OAGG;IACH,yBAAyB,CAAC,YAAY,EAAE,kBAAkB,GAAG,IAAI,CAAC;IAElE;;;OAGG;IACH,cAAc,CAAC,cAAc,EAAE,MAAM,GAAG,iBAAiB,GAAG,IAAI,CAAC;IAEjE;;;OAGG;IACH,cAAc,CAAC,WAAW,EAAE,iBAAiB,GAAG,IAAI,CAAC;IAErD;;;OAGG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,GAAG,qBAAqB,GAAG,IAAI,CAAC;IAE7E;;;;OAIG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,EAAE,eAAe,EAAE,qBAAqB,GAAG,IAAI,CAAC;IAE7F;;;OAGG;IACH,oBAAoB,CAAC,GAAG,EAAE,MAAM,GAAG,uBAAuB,GAAG,IAAI,CAAC;IAElE;;OAEG;IACH,wBAAwB,IAAI,KAAK,CAAC,MAAM,CAAC,CAAC;IAE1C;;;;OAIG;IACH,oBAAoB,CAAC,GAAG,EAAE,MAAM,EAAE,KAAK,EAAE,uBAAuB,GAAG,IAAI,CAAC;IAExE;;;OAGG;IACH,2BAA2B,CAAC,IAAI,EAAE,MAAM,GAAG,uBAAuB,GAAG,IAAI,CAAC;IAE1E;;;OAGG;IACH,iCAAiC,CAAC,SAAS,EAAE,MAAM,GAAG,MAAM,CAAC;IAE7D;;;OAGG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,GAAG,gBAAgB,GAAG,IAAI,CAAC;IAExE;;;;OAIG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,EAAE,eAAe,EAAE,gBAAgB,GAAG,IAAI,CAAC;IAExF;;OAEG;IACH,cAAc,IAAI,WAAW,EAAE,CAAC;IAEhC;;;OAGG;IACH,eAAe,CAAC,WAAW,EAAE,WAAW,GAAG,IAAI,CAAC;IAEhD;;;;;OAKG;IACH,qBAAqB,CAAC,MAAM,EAAE,aAAa,GAAG,YAAY,CAAC;IAE3D;;;;;;;;OAQG;IACH,wBAAwB,CAAC,MAAM,EAAE,gBAAgB,GAAG,eAAe,CAAC;IAEpE;;OAEG;IACH,iBAAiB,IAAI,OAAO,CAAC;IAE7B;;;OAGG;IACH,aAAa,CAAC,UAAU,EAAE,MAAM,GAAG,OAAO,CAAC;IAE3C;;;OAGG;IACH,oBAAoB,CAAC,OAAO,EAAE,aAAa,GAAG,OAAO,CAAC;IAEtD;;;OAGG;IACH,gBAAgB,CAAC,UAAU,EAAE,gBAAgB,GAAG,OAAO,CAAC;CAC3D"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/interface/ICachePlugin.d.ts b/node_modules/@azure/msal-common/dist/cache/interface/ICachePlugin.d.ts
new file mode 100644
index 0000000..a44accf
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/interface/ICachePlugin.d.ts
@@ -0,0 +1,6 @@
+import { TokenCacheContext } from "../persistence/TokenCacheContext";
+export interface ICachePlugin {
+ beforeCacheAccess: (tokenCacheContext: TokenCacheContext) => Promise;
+ afterCacheAccess: (tokenCacheContext: TokenCacheContext) => Promise;
+}
+//# sourceMappingURL=ICachePlugin.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/interface/ICachePlugin.d.ts.map b/node_modules/@azure/msal-common/dist/cache/interface/ICachePlugin.d.ts.map
new file mode 100644
index 0000000..8db4069
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/interface/ICachePlugin.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ICachePlugin.d.ts","sourceRoot":"","sources":["../../../src/cache/interface/ICachePlugin.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,iBAAiB,EAAE,MAAM,kCAAkC,CAAC;AAErE,MAAM,WAAW,YAAY;IACzB,iBAAiB,EAAE,CAAC,iBAAiB,EAAE,iBAAiB,KAAK,OAAO,CAAC,IAAI,CAAC,CAAC;IAC3E,gBAAgB,EAAE,CAAC,iBAAiB,EAAE,iBAAiB,KAAK,OAAO,CAAC,IAAI,CAAC,CAAC;CAC7E"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/interface/ISerializableTokenCache.d.ts b/node_modules/@azure/msal-common/dist/cache/interface/ISerializableTokenCache.d.ts
new file mode 100644
index 0000000..6701784
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/interface/ISerializableTokenCache.d.ts
@@ -0,0 +1,5 @@
+export interface ISerializableTokenCache {
+ deserialize: (cache: string) => void;
+ serialize: () => string;
+}
+//# sourceMappingURL=ISerializableTokenCache.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/interface/ISerializableTokenCache.d.ts.map b/node_modules/@azure/msal-common/dist/cache/interface/ISerializableTokenCache.d.ts.map
new file mode 100644
index 0000000..41a6d84
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/interface/ISerializableTokenCache.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ISerializableTokenCache.d.ts","sourceRoot":"","sources":["../../../src/cache/interface/ISerializableTokenCache.ts"],"names":[],"mappings":"AAKA,MAAM,WAAW,uBAAuB;IACpC,WAAW,EAAE,CAAC,KAAK,EAAE,MAAM,KAAK,IAAI,CAAC;IACrC,SAAS,EAAE,MAAM,MAAM,CAAC;CAC3B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/persistence/TokenCacheContext.d.ts b/node_modules/@azure/msal-common/dist/cache/persistence/TokenCacheContext.d.ts
new file mode 100644
index 0000000..3235437
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/persistence/TokenCacheContext.d.ts
@@ -0,0 +1,24 @@
+import { ISerializableTokenCache } from "../interface/ISerializableTokenCache";
+/**
+ * This class instance helps track the memory changes facilitating
+ * decisions to read from and write to the persistent cache
+ */ export declare class TokenCacheContext {
+ /**
+ * boolean indicating cache change
+ */
+ hasChanged: boolean;
+ /**
+ * serializable token cache interface
+ */
+ cache: ISerializableTokenCache;
+ constructor(tokenCache: ISerializableTokenCache, hasChanged: boolean);
+ /**
+ * boolean which indicates the changes in cache
+ */
+ get cacheHasChanged(): boolean;
+ /**
+ * function to retrieve the token cache
+ */
+ get tokenCache(): ISerializableTokenCache;
+}
+//# sourceMappingURL=TokenCacheContext.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/persistence/TokenCacheContext.d.ts.map b/node_modules/@azure/msal-common/dist/cache/persistence/TokenCacheContext.d.ts.map
new file mode 100644
index 0000000..1d6d911
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/persistence/TokenCacheContext.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"TokenCacheContext.d.ts","sourceRoot":"","sources":["../../../src/cache/persistence/TokenCacheContext.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,uBAAuB,EAAE,MAAM,sCAAsC,CAAC;AAE/E;;;GAGG,CAAA,qBAAa,iBAAiB;IAC7B;;OAEG;IACH,UAAU,EAAE,OAAO,CAAC;IACpB;;OAEG;IACH,KAAK,EAAE,uBAAuB,CAAC;gBAEnB,UAAU,EAAE,uBAAuB,EAAE,UAAU,EAAE,OAAO;IAKpE;;OAEG;IACH,IAAI,eAAe,IAAI,OAAO,CAE7B;IAED;;OAEG;IACH,IAAI,UAAU,IAAI,uBAAuB,CAExC;CACJ"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/utils/CacheTypes.d.ts b/node_modules/@azure/msal-common/dist/cache/utils/CacheTypes.d.ts
new file mode 100644
index 0000000..bcde839
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/utils/CacheTypes.d.ts
@@ -0,0 +1,55 @@
+import { AccountEntity } from "../entities/AccountEntity";
+import { IdTokenEntity } from "../entities/IdTokenEntity";
+import { AccessTokenEntity } from "../entities/AccessTokenEntity";
+import { RefreshTokenEntity } from "../entities/RefreshTokenEntity";
+import { AppMetadataEntity } from "../entities/AppMetadataEntity";
+import { ServerTelemetryEntity } from "../entities/ServerTelemetryEntity";
+import { ThrottlingEntity } from "../entities/ThrottlingEntity";
+import { AuthorityMetadataEntity } from "../entities/AuthorityMetadataEntity";
+export declare type AccountCache = Record;
+export declare type IdTokenCache = Record;
+export declare type AccessTokenCache = Record;
+export declare type RefreshTokenCache = Record;
+export declare type AppMetadataCache = Record;
+export declare type CredentialCache = {
+ idTokens: IdTokenCache;
+ accessTokens: AccessTokenCache;
+ refreshTokens: RefreshTokenCache;
+};
+/**
+ * Object type of all accepted cache types
+ */
+export declare type ValidCacheType = AccountEntity | IdTokenEntity | AccessTokenEntity | RefreshTokenEntity | AppMetadataEntity | AuthorityMetadataEntity | ServerTelemetryEntity | ThrottlingEntity | string;
+/**
+ * Object type of all credential types
+ */
+export declare type ValidCredentialType = IdTokenEntity | AccessTokenEntity | RefreshTokenEntity;
+/**
+ * Account: --
+ */
+export declare type AccountFilter = {
+ homeAccountId?: string;
+ environment?: string;
+ realm?: string;
+};
+/**
+ * Credential: -----
+ */
+export declare type CredentialFilter = {
+ homeAccountId?: string;
+ environment?: string;
+ credentialType?: string;
+ clientId?: string;
+ familyId?: string;
+ realm?: string;
+ target?: string;
+ oboAssertion?: string;
+};
+/**
+ * AppMetadata: appmetadata--
+ */
+export declare type AppMetadataFilter = {
+ environment?: string;
+ clientId?: string;
+};
+//# sourceMappingURL=CacheTypes.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/cache/utils/CacheTypes.d.ts.map b/node_modules/@azure/msal-common/dist/cache/utils/CacheTypes.d.ts.map
new file mode 100644
index 0000000..ab02501
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/cache/utils/CacheTypes.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CacheTypes.d.ts","sourceRoot":"","sources":["../../../src/cache/utils/CacheTypes.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,aAAa,EAAE,MAAM,2BAA2B,CAAC;AAC1D,OAAO,EAAE,aAAa,EAAE,MAAM,2BAA2B,CAAC;AAC1D,OAAO,EAAE,iBAAiB,EAAE,MAAM,+BAA+B,CAAC;AAClE,OAAO,EAAE,kBAAkB,EAAE,MAAM,gCAAgC,CAAC;AACpE,OAAO,EAAE,iBAAiB,EAAE,MAAM,+BAA+B,CAAC;AAClE,OAAO,EAAE,qBAAqB,EAAE,MAAM,mCAAmC,CAAC;AAC1E,OAAO,EAAE,gBAAgB,EAAE,MAAM,8BAA8B,CAAC;AAChE,OAAO,EAAE,uBAAuB,EAAE,MAAM,qCAAqC,CAAC;AAE9E,oBAAY,YAAY,GAAG,MAAM,CAAC,MAAM,EAAE,aAAa,CAAC,CAAC;AACzD,oBAAY,YAAY,GAAG,MAAM,CAAC,MAAM,EAAE,aAAa,CAAC,CAAC;AACzD,oBAAY,gBAAgB,GAAG,MAAM,CAAC,MAAM,EAAE,iBAAiB,CAAC,CAAC;AACjE,oBAAY,iBAAiB,GAAG,MAAM,CAAC,MAAM,EAAE,kBAAkB,CAAC,CAAC;AACnE,oBAAY,gBAAgB,GAAG,MAAM,CAAC,MAAM,EAAE,iBAAiB,CAAC,CAAC;AACjE,oBAAY,eAAe,GAAG;IAC1B,QAAQ,EAAE,YAAY,CAAC;IACvB,YAAY,EAAE,gBAAgB,CAAC;IAC/B,aAAa,EAAE,iBAAiB,CAAC;CACpC,CAAC;AAEF;;GAEG;AACH,oBAAY,cAAc,GAAG,aAAa,GAAG,aAAa,GAAG,iBAAiB,GAAG,kBAAkB,GAAG,iBAAiB,GAAG,uBAAuB,GAAG,qBAAqB,GAAG,gBAAgB,GAAG,MAAM,CAAC;AAEtM;;GAEG;AACH,oBAAY,mBAAmB,GAAG,aAAa,GAAG,iBAAiB,GAAG,kBAAkB,CAAC;AAEzF;;GAEG;AACH,oBAAY,aAAa,GAAG;IACxB,aAAa,CAAC,EAAE,MAAM,CAAC;IACvB,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,KAAK,CAAC,EAAE,MAAM,CAAC;CAClB,CAAC;AAEF;;GAEG;AACH,oBAAY,gBAAgB,GAAG;IAC3B,aAAa,CAAC,EAAE,MAAM,CAAC;IACvB,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,cAAc,CAAC,EAAE,MAAM,CAAC;IACxB,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,YAAY,CAAC,EAAE,MAAM,CAAC;CACzB,CAAC;AAEF;;GAEG;AACH,oBAAY,iBAAiB,GAAG;IAC5B,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,QAAQ,CAAC,EAAE,MAAM,CAAC;CACrB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/AuthorizationCodeClient.d.ts b/node_modules/@azure/msal-common/dist/client/AuthorizationCodeClient.d.ts
new file mode 100644
index 0000000..17070e9
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/AuthorizationCodeClient.d.ts
@@ -0,0 +1,64 @@
+import { BaseClient } from "./BaseClient";
+import { CommonAuthorizationUrlRequest } from "../request/CommonAuthorizationUrlRequest";
+import { CommonAuthorizationCodeRequest } from "../request/CommonAuthorizationCodeRequest";
+import { ClientConfiguration } from "../config/ClientConfiguration";
+import { AuthenticationResult } from "../response/AuthenticationResult";
+import { CommonEndSessionRequest } from "../request/CommonEndSessionRequest";
+import { AuthorizationCodePayload } from "../response/AuthorizationCodePayload";
+/**
+ * Oauth2.0 Authorization Code client
+ */
+export declare class AuthorizationCodeClient extends BaseClient {
+ constructor(configuration: ClientConfiguration);
+ /**
+ * Creates the URL of the authorization request letting the user input credentials and consent to the
+ * application. The URL target the /authorize endpoint of the authority configured in the
+ * application object.
+ *
+ * Once the user inputs their credentials and consents, the authority will send a response to the redirect URI
+ * sent in the request and should contain an authorization code, which can then be used to acquire tokens via
+ * acquireToken(AuthorizationCodeRequest)
+ * @param request
+ */
+ getAuthCodeUrl(request: CommonAuthorizationUrlRequest): Promise;
+ /**
+ * API to acquire a token in exchange of 'authorization_code` acquired by the user in the first leg of the
+ * authorization_code_grant
+ * @param request
+ */
+ acquireToken(request: CommonAuthorizationCodeRequest, authCodePayload?: AuthorizationCodePayload): Promise;
+ /**
+ * Handles the hash fragment response from public client code request. Returns a code response used by
+ * the client to exchange for a token in acquireToken.
+ * @param hashFragment
+ */
+ handleFragmentResponse(hashFragment: string, cachedState: string): AuthorizationCodePayload;
+ /**
+ * Use to log out the current user, and redirect the user to the postLogoutRedirectUri.
+ * Default behaviour is to redirect the user to `window.location.href`.
+ * @param authorityUri
+ */
+ getLogoutUri(logoutRequest: CommonEndSessionRequest): string;
+ /**
+ * Executes POST request to token endpoint
+ * @param authority
+ * @param request
+ */
+ private executeTokenRequest;
+ /**
+ * Generates a map for all the params to be sent to the service
+ * @param request
+ */
+ private createTokenRequestBody;
+ /**
+ * This API validates the `AuthorizationCodeUrlRequest` and creates a URL
+ * @param request
+ */
+ private createAuthCodeUrlQueryString;
+ /**
+ * This API validates the `EndSessionRequest` and creates a URL
+ * @param request
+ */
+ private createLogoutUrlQueryString;
+}
+//# sourceMappingURL=AuthorizationCodeClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/AuthorizationCodeClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/AuthorizationCodeClient.d.ts.map
new file mode 100644
index 0000000..943e59e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/AuthorizationCodeClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthorizationCodeClient.d.ts","sourceRoot":"","sources":["../../src/client/AuthorizationCodeClient.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,UAAU,EAAE,MAAM,cAAc,CAAC;AAC1C,OAAO,EAAE,6BAA6B,EAAE,MAAM,0CAA0C,CAAC;AACzF,OAAO,EAAE,8BAA8B,EAAE,MAAM,2CAA2C,CAAC;AAI3F,OAAO,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AAIpE,OAAO,EAAE,oBAAoB,EAAE,MAAM,kCAAkC,CAAC;AAMxE,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAI7E,OAAO,EAAE,wBAAwB,EAAE,MAAM,sCAAsC,CAAC;AAGhF;;GAEG;AACH,qBAAa,uBAAwB,SAAQ,UAAU;gBAEvC,aAAa,EAAE,mBAAmB;IAI9C;;;;;;;;;OASG;IACG,cAAc,CAAC,OAAO,EAAE,6BAA6B,GAAG,OAAO,CAAC,MAAM,CAAC;IAK7E;;;;OAIG;IACG,YAAY,CAAC,OAAO,EAAE,8BAA8B,EAAE,eAAe,CAAC,EAAE,wBAAwB,GAAG,OAAO,CAAC,oBAAoB,CAAC;IAuBtI;;;;OAIG;IACH,sBAAsB,CAAC,YAAY,EAAE,MAAM,EAAE,WAAW,EAAE,MAAM,GAAG,wBAAwB;IAwB3F;;;;OAIG;IACH,YAAY,CAAC,aAAa,EAAE,uBAAuB,GAAG,MAAM;IAoB5D;;;;OAIG;YACW,mBAAmB;IAajC;;;OAGG;YACW,sBAAsB;IAgDpC;;;OAGG;IACH,OAAO,CAAC,4BAA4B;IAmEpC;;;OAGG;IACH,OAAO,CAAC,0BAA0B;CAiBrC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/BaseClient.d.ts b/node_modules/@azure/msal-common/dist/client/BaseClient.d.ts
new file mode 100644
index 0000000..f0b46c6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/BaseClient.d.ts
@@ -0,0 +1,46 @@
+import { ClientConfiguration, CommonClientConfiguration } from "../config/ClientConfiguration";
+import { INetworkModule } from "../network/INetworkModule";
+import { NetworkManager, NetworkResponse } from "../network/NetworkManager";
+import { ICrypto } from "../crypto/ICrypto";
+import { Authority } from "../authority/Authority";
+import { Logger } from "../logger/Logger";
+import { ServerAuthorizationTokenResponse } from "../response/ServerAuthorizationTokenResponse";
+import { CacheManager } from "../cache/CacheManager";
+import { ServerTelemetryManager } from "../telemetry/server/ServerTelemetryManager";
+import { RequestThumbprint } from "../network/RequestThumbprint";
+/**
+ * Base application class which will construct requests to send to and handle responses from the Microsoft STS using the authorization code flow.
+ */
+export declare abstract class BaseClient {
+ logger: Logger;
+ protected config: CommonClientConfiguration;
+ protected cryptoUtils: ICrypto;
+ protected cacheManager: CacheManager;
+ protected networkClient: INetworkModule;
+ protected serverTelemetryManager: ServerTelemetryManager | null;
+ protected networkManager: NetworkManager;
+ authority: Authority;
+ protected constructor(configuration: ClientConfiguration);
+ /**
+ * Creates default headers for requests to token endpoint
+ */
+ protected createDefaultTokenRequestHeaders(): Record;
+ /**
+ * addLibraryData
+ */
+ protected createDefaultLibraryHeaders(): Record;
+ /**
+ * Http post to token endpoint
+ * @param tokenEndpoint
+ * @param queryString
+ * @param headers
+ * @param thumbprint
+ */
+ protected executePostToTokenEndpoint(tokenEndpoint: string, queryString: string, headers: Record, thumbprint: RequestThumbprint): Promise>;
+ /**
+ * Updates the authority object of the client. Endpoint discovery must be completed.
+ * @param updatedAuthority
+ */
+ updateAuthority(updatedAuthority: Authority): void;
+}
+//# sourceMappingURL=BaseClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/BaseClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/BaseClient.d.ts.map
new file mode 100644
index 0000000..f25184b
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/BaseClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"BaseClient.d.ts","sourceRoot":"","sources":["../../src/client/BaseClient.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,mBAAmB,EAA4B,yBAAyB,EAAE,MAAM,+BAA+B,CAAC;AACzH,OAAO,EAAE,cAAc,EAAE,MAAM,2BAA2B,CAAC;AAC3D,OAAO,EAAE,cAAc,EAAE,eAAe,EAAE,MAAM,2BAA2B,CAAC;AAC5E,OAAO,EAAE,OAAO,EAAE,MAAM,mBAAmB,CAAC;AAC5C,OAAO,EAAE,SAAS,EAAE,MAAM,wBAAwB,CAAC;AACnD,OAAO,EAAE,MAAM,EAAE,MAAM,kBAAkB,CAAC;AAE1C,OAAO,EAAE,gCAAgC,EAAE,MAAM,8CAA8C,CAAC;AAChG,OAAO,EAAE,YAAY,EAAE,MAAM,uBAAuB,CAAC;AACrD,OAAO,EAAE,sBAAsB,EAAE,MAAM,4CAA4C,CAAC;AACpF,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AAIjE;;GAEG;AACH,8BAAsB,UAAU;IAErB,MAAM,EAAE,MAAM,CAAC;IAGtB,SAAS,CAAC,MAAM,EAAE,yBAAyB,CAAC;IAG5C,SAAS,CAAC,WAAW,EAAE,OAAO,CAAC;IAG/B,SAAS,CAAC,YAAY,EAAE,YAAY,CAAC;IAGrC,SAAS,CAAC,aAAa,EAAE,cAAc,CAAC;IAGxC,SAAS,CAAC,sBAAsB,EAAE,sBAAsB,GAAG,IAAI,CAAC;IAGhE,SAAS,CAAC,cAAc,EAAE,cAAc,CAAC;IAGlC,SAAS,EAAE,SAAS,CAAC;IAE5B,SAAS,aAAa,aAAa,EAAE,mBAAmB;IA0BxD;;OAEG;IACH,SAAS,CAAC,gCAAgC,IAAI,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC;IAapE;;OAEG;IACH,SAAS,CAAC,2BAA2B,IAAI,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC;IAY/D;;;;;;OAMG;cACa,0BAA0B,CAAC,aAAa,EAAE,MAAM,EAAE,WAAW,EAAE,MAAM,EAAE,OAAO,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,EAAE,UAAU,EAAE,iBAAiB,GAAG,OAAO,CAAC,eAAe,CAAC,gCAAgC,CAAC,CAAC;IAelN;;;OAGG;IACH,eAAe,CAAC,gBAAgB,EAAE,SAAS,GAAG,IAAI;CAMrD"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/ClientCredentialClient.d.ts b/node_modules/@azure/msal-common/dist/client/ClientCredentialClient.d.ts
new file mode 100644
index 0000000..aee8de6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/ClientCredentialClient.d.ts
@@ -0,0 +1,37 @@
+import { ClientConfiguration } from "../config/ClientConfiguration";
+import { BaseClient } from "./BaseClient";
+import { AuthenticationResult } from "../response/AuthenticationResult";
+import { CommonClientCredentialRequest } from "../request/CommonClientCredentialRequest";
+/**
+ * OAuth2.0 client credential grant
+ */
+export declare class ClientCredentialClient extends BaseClient {
+ private scopeSet;
+ constructor(configuration: ClientConfiguration);
+ /**
+ * Public API to acquire a token with ClientCredential Flow for Confidential clients
+ * @param request
+ */
+ acquireToken(request: CommonClientCredentialRequest): Promise;
+ /**
+ * looks up cache if the tokens are cached already
+ */
+ private getCachedAuthenticationResult;
+ /**
+ * Reads access token from the cache
+ * TODO: Move this call to cacheManager instead
+ */
+ private readAccessTokenFromCache;
+ /**
+ * Makes a network call to request the token from the service
+ * @param request
+ * @param authority
+ */
+ private executeTokenRequest;
+ /**
+ * generate the request to the server in the acceptable format
+ * @param request
+ */
+ private createTokenRequestBody;
+}
+//# sourceMappingURL=ClientCredentialClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/ClientCredentialClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/ClientCredentialClient.d.ts.map
new file mode 100644
index 0000000..da4e392
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/ClientCredentialClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ClientCredentialClient.d.ts","sourceRoot":"","sources":["../../src/client/ClientCredentialClient.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AACpE,OAAO,EAAE,UAAU,EAAE,MAAM,cAAc,CAAC;AAM1C,OAAO,EAAE,oBAAoB,EAAE,MAAM,kCAAkC,CAAC;AACxE,OAAO,EAAE,6BAA6B,EAAE,MAAM,0CAA0C,CAAC;AAQzF;;GAEG;AACH,qBAAa,sBAAuB,SAAQ,UAAU;IAElD,OAAO,CAAC,QAAQ,CAAW;gBAEf,aAAa,EAAE,mBAAmB;IAI9C;;;OAGG;IACU,YAAY,CAAC,OAAO,EAAE,6BAA6B,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAgBvG;;OAEG;YACW,6BAA6B;IAqB3C;;;OAGG;IACH,OAAO,CAAC,wBAAwB;IAmBhC;;;;OAIG;YACW,mBAAmB;IAqCjC;;;OAGG;IACH,OAAO,CAAC,sBAAsB;CA4BjC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/DeviceCodeClient.d.ts b/node_modules/@azure/msal-common/dist/client/DeviceCodeClient.d.ts
new file mode 100644
index 0000000..2178d3b
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/DeviceCodeClient.d.ts
@@ -0,0 +1,46 @@
+import { BaseClient } from "./BaseClient";
+import { CommonDeviceCodeRequest } from "../request/CommonDeviceCodeRequest";
+import { ClientConfiguration } from "../config/ClientConfiguration";
+import { AuthenticationResult } from "../response/AuthenticationResult";
+/**
+ * OAuth2.0 Device code client
+ */
+export declare class DeviceCodeClient extends BaseClient {
+ constructor(configuration: ClientConfiguration);
+ /**
+ * Gets device code from device code endpoint, calls back to with device code response, and
+ * polls token endpoint to exchange device code for tokens
+ * @param request
+ */
+ acquireToken(request: CommonDeviceCodeRequest): Promise;
+ /**
+ * Creates device code request and executes http GET
+ * @param request
+ */
+ private getDeviceCode;
+ /**
+ * Executes POST request to device code endpoint
+ * @param deviceCodeEndpoint
+ * @param queryString
+ * @param headers
+ */
+ private executePostRequestToDeviceCodeEndpoint;
+ /**
+ * Create device code endpoint query parameters and returns string
+ */
+ private createQueryString;
+ /**
+ * Creates token request with device code response and polls token endpoint at interval set by the device code
+ * response
+ * @param request
+ * @param deviceCodeResponse
+ */
+ private acquireTokenWithDeviceCode;
+ /**
+ * Creates query parameters and converts to string.
+ * @param request
+ * @param deviceCodeResponse
+ */
+ private createTokenRequestBody;
+}
+//# sourceMappingURL=DeviceCodeClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/DeviceCodeClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/DeviceCodeClient.d.ts.map
new file mode 100644
index 0000000..8439489
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/DeviceCodeClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"DeviceCodeClient.d.ts","sourceRoot":"","sources":["../../src/client/DeviceCodeClient.ts"],"names":[],"mappings":"AAMA,OAAO,EAAE,UAAU,EAAE,MAAM,cAAc,CAAC;AAC1C,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAI7E,OAAO,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AAIpE,OAAO,EAAE,oBAAoB,EAAE,MAAM,kCAAkC,CAAC;AAIxE;;GAEG;AACH,qBAAa,gBAAiB,SAAQ,UAAU;gBAEhC,aAAa,EAAE,mBAAmB;IAI9C;;;;OAIG;IACU,YAAY,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IA4BjG;;;OAGG;YACW,aAAa;IAY3B;;;;;OAKG;YACW,sCAAsC;IAiCpD;;OAEG;IACH,OAAO,CAAC,iBAAiB;IAczB;;;;;OAKG;YACW,0BAA0B;IAqExC;;;;OAIG;IACH,OAAO,CAAC,sBAAsB;CAiBjC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/OnBehalfOfClient.d.ts b/node_modules/@azure/msal-common/dist/client/OnBehalfOfClient.d.ts
new file mode 100644
index 0000000..b9d52bb
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/OnBehalfOfClient.d.ts
@@ -0,0 +1,48 @@
+import { ClientConfiguration } from "../config/ClientConfiguration";
+import { BaseClient } from "./BaseClient";
+import { AuthenticationResult } from "../response/AuthenticationResult";
+import { CommonOnBehalfOfRequest } from "../request/CommonOnBehalfOfRequest";
+/**
+ * On-Behalf-Of client
+ */
+export declare class OnBehalfOfClient extends BaseClient {
+ private scopeSet;
+ constructor(configuration: ClientConfiguration);
+ /**
+ * Public API to acquire tokens with on behalf of flow
+ * @param request
+ */
+ acquireToken(request: CommonOnBehalfOfRequest): Promise;
+ /**
+ * look up cache for tokens
+ * @param request
+ */
+ private getCachedAuthenticationResult;
+ /**
+ * read access token from cache TODO: CacheManager API should be used here
+ * @param request
+ */
+ private readAccessTokenFromCache;
+ /**
+ * read idtoken from cache TODO: CacheManager API should be used here instead
+ * @param request
+ */
+ private readIdTokenFromCache;
+ /**
+ * read account from cache, TODO: CacheManager API should be used here instead
+ * @param account
+ */
+ private readAccountFromCache;
+ /**
+ * Make a network call to the server requesting credentials
+ * @param request
+ * @param authority
+ */
+ private executeTokenRequest;
+ /**
+ * generate a server request in accepable format
+ * @param request
+ */
+ private createTokenRequestBody;
+}
+//# sourceMappingURL=OnBehalfOfClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/OnBehalfOfClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/OnBehalfOfClient.d.ts.map
new file mode 100644
index 0000000..335e4f0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/OnBehalfOfClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"OnBehalfOfClient.d.ts","sourceRoot":"","sources":["../../src/client/OnBehalfOfClient.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AACpE,OAAO,EAAE,UAAU,EAAE,MAAM,cAAc,CAAC;AAM1C,OAAO,EAAE,oBAAoB,EAAE,MAAM,kCAAkC,CAAC;AACxE,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAW7E;;GAEG;AACH,qBAAa,gBAAiB,SAAQ,UAAU;IAE5C,OAAO,CAAC,QAAQ,CAAW;gBAEf,aAAa,EAAE,mBAAmB;IAI9C;;;OAGG;IACU,YAAY,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAejG;;;OAGG;YACW,6BAA6B;IAoC3C;;;OAGG;IACH,OAAO,CAAC,wBAAwB;IAsBhC;;;OAGG;IACH,OAAO,CAAC,oBAAoB;IAkB5B;;;OAGG;IACH,OAAO,CAAC,oBAAoB;IAI5B;;;;OAIG;YACW,mBAAmB;IAsCjC;;;OAGG;IACH,OAAO,CAAC,sBAAsB;CA8BjC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/RefreshTokenClient.d.ts b/node_modules/@azure/msal-common/dist/client/RefreshTokenClient.d.ts
new file mode 100644
index 0000000..cef8be9
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/RefreshTokenClient.d.ts
@@ -0,0 +1,34 @@
+import { ClientConfiguration } from "../config/ClientConfiguration";
+import { BaseClient } from "./BaseClient";
+import { CommonRefreshTokenRequest } from "../request/CommonRefreshTokenRequest";
+import { AuthenticationResult } from "../response/AuthenticationResult";
+import { CommonSilentFlowRequest } from "../request/CommonSilentFlowRequest";
+/**
+ * OAuth2.0 refresh token client
+ */
+export declare class RefreshTokenClient extends BaseClient {
+ constructor(configuration: ClientConfiguration);
+ acquireToken(request: CommonRefreshTokenRequest): Promise;
+ /**
+ * Gets cached refresh token and attaches to request, then calls acquireToken API
+ * @param request
+ */
+ acquireTokenByRefreshToken(request: CommonSilentFlowRequest): Promise;
+ /**
+ * makes a network call to acquire tokens by exchanging RefreshToken available in userCache; throws if refresh token is not cached
+ * @param request
+ */
+ private acquireTokenWithCachedRefreshToken;
+ /**
+ * Constructs the network message and makes a NW call to the underlying secure token service
+ * @param request
+ * @param authority
+ */
+ private executeTokenRequest;
+ /**
+ * Helper function to create the token request body
+ * @param request
+ */
+ private createTokenRequestBody;
+}
+//# sourceMappingURL=RefreshTokenClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/RefreshTokenClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/RefreshTokenClient.d.ts.map
new file mode 100644
index 0000000..0ecb090
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/RefreshTokenClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"RefreshTokenClient.d.ts","sourceRoot":"","sources":["../../src/client/RefreshTokenClient.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AACpE,OAAO,EAAE,UAAU,EAAE,MAAM,cAAc,CAAC;AAC1C,OAAO,EAAE,yBAAyB,EAAE,MAAM,sCAAsC,CAAC;AAMjF,OAAO,EAAE,oBAAoB,EAAE,MAAM,kCAAkC,CAAC;AAKxE,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAM7E;;GAEG;AACH,qBAAa,kBAAmB,SAAQ,UAAU;gBAElC,aAAa,EAAE,mBAAmB;IAIjC,YAAY,CAAC,OAAO,EAAE,yBAAyB,GAAG,OAAO,CAAC,oBAAoB,CAAC;IA2B5F;;;OAGG;IACU,0BAA0B,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,CAAC;IAqCxG;;;OAGG;YACW,kCAAkC;IAkBhD;;;;OAIG;YACW,mBAAmB;IAcjC;;;OAGG;YACW,sBAAsB;CAyCvC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/SilentFlowClient.d.ts b/node_modules/@azure/msal-common/dist/client/SilentFlowClient.d.ts
new file mode 100644
index 0000000..00f1023
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/SilentFlowClient.d.ts
@@ -0,0 +1,30 @@
+import { BaseClient } from "./BaseClient";
+import { ClientConfiguration } from "../config/ClientConfiguration";
+import { CommonSilentFlowRequest } from "../request/CommonSilentFlowRequest";
+import { AuthenticationResult } from "../response/AuthenticationResult";
+export declare class SilentFlowClient extends BaseClient {
+ constructor(configuration: ClientConfiguration);
+ /**
+ * Retrieves a token from cache if it is still valid, or uses the cached refresh token to renew
+ * the given token and returns the renewed token
+ * @param request
+ */
+ acquireToken(request: CommonSilentFlowRequest): Promise;
+ /**
+ * Retrieves token from cache or throws an error if it must be refreshed.
+ * @param request
+ */
+ acquireCachedToken(request: CommonSilentFlowRequest): Promise;
+ /**
+ * Helper function to build response object from the CacheRecord
+ * @param cacheRecord
+ */
+ private generateResultFromCacheRecord;
+ /**
+ * Given a request object and an accessTokenEntity determine if the accessToken needs to be refreshed
+ * @param request
+ * @param cachedAccessToken
+ */
+ private isRefreshRequired;
+}
+//# sourceMappingURL=SilentFlowClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/SilentFlowClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/SilentFlowClient.d.ts.map
new file mode 100644
index 0000000..33bc37f
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/SilentFlowClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"SilentFlowClient.d.ts","sourceRoot":"","sources":["../../src/client/SilentFlowClient.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,UAAU,EAAE,MAAM,cAAc,CAAC;AAC1C,OAAO,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AACpE,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAC7E,OAAO,EAAE,oBAAoB,EAAE,MAAM,kCAAkC,CAAC;AAWxE,qBAAa,gBAAiB,SAAQ,UAAU;gBAEhC,aAAa,EAAE,mBAAmB;IAI9C;;;;OAIG;IACG,YAAY,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,CAAC;IAanF;;;OAGG;IACG,kBAAkB,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,CAAC;IAyBzF;;;OAGG;YACW,6BAA6B;IAiB3C;;;;OAIG;IACH,OAAO,CAAC,iBAAiB;CAW5B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/UsernamePasswordClient.d.ts b/node_modules/@azure/msal-common/dist/client/UsernamePasswordClient.d.ts
new file mode 100644
index 0000000..67118ca
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/UsernamePasswordClient.d.ts
@@ -0,0 +1,29 @@
+import { BaseClient } from "./BaseClient";
+import { ClientConfiguration } from "../config/ClientConfiguration";
+import { CommonUsernamePasswordRequest } from "../request/CommonUsernamePasswordRequest";
+import { AuthenticationResult } from "../response/AuthenticationResult";
+/**
+ * Oauth2.0 Password grant client
+ * Note: We are only supporting public clients for password grant and for purely testing purposes
+ */
+export declare class UsernamePasswordClient extends BaseClient {
+ constructor(configuration: ClientConfiguration);
+ /**
+ * API to acquire a token by passing the username and password to the service in exchage of credentials
+ * password_grant
+ * @param request
+ */
+ acquireToken(request: CommonUsernamePasswordRequest): Promise;
+ /**
+ * Executes POST request to token endpoint
+ * @param authority
+ * @param request
+ */
+ private executeTokenRequest;
+ /**
+ * Generates a map for all the params to be sent to the service
+ * @param request
+ */
+ private createTokenRequestBody;
+}
+//# sourceMappingURL=UsernamePasswordClient.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/client/UsernamePasswordClient.d.ts.map b/node_modules/@azure/msal-common/dist/client/UsernamePasswordClient.d.ts.map
new file mode 100644
index 0000000..2872c80
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/client/UsernamePasswordClient.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"UsernamePasswordClient.d.ts","sourceRoot":"","sources":["../../src/client/UsernamePasswordClient.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,UAAU,EAAE,MAAM,cAAc,CAAC;AAC1C,OAAO,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AACpE,OAAO,EAAE,6BAA6B,EAAE,MAAM,0CAA0C,CAAC;AACzF,OAAO,EAAE,oBAAoB,EAAE,MAAM,kCAAkC,CAAC;AAWxE;;;GAGG;AACH,qBAAa,sBAAuB,SAAQ,UAAU;gBAEtC,aAAa,EAAE,mBAAmB;IAI9C;;;;OAIG;IACG,YAAY,CAAC,OAAO,EAAE,6BAA6B,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAsBhG;;;;OAIG;YACW,mBAAmB;IAYjC;;;OAGG;IACH,OAAO,CAAC,sBAAsB;CAqBjC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/config/ClientConfiguration.d.ts b/node_modules/@azure/msal-common/dist/config/ClientConfiguration.d.ts
new file mode 100644
index 0000000..53e3400
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/config/ClientConfiguration.d.ts
@@ -0,0 +1,111 @@
+import { INetworkModule } from "../network/INetworkModule";
+import { ICrypto } from "../crypto/ICrypto";
+import { ILoggerCallback, LogLevel } from "../logger/Logger";
+import { Authority } from "../authority/Authority";
+import { CacheManager } from "../cache/CacheManager";
+import { ServerTelemetryManager } from "../telemetry/server/ServerTelemetryManager";
+import { ICachePlugin } from "../cache/interface/ICachePlugin";
+import { ISerializableTokenCache } from "../cache/interface/ISerializableTokenCache";
+/**
+ * Use the configuration object to configure MSAL Modules and initialize the base interfaces for MSAL.
+ *
+ * This object allows you to configure important elements of MSAL functionality:
+ * - authOptions - Authentication for application
+ * - cryptoInterface - Implementation of crypto functions
+ * - libraryInfo - Library metadata
+ * - loggerOptions - Logging for application
+ * - networkInterface - Network implementation
+ * - storageInterface - Storage implementation
+ * - systemOptions - Additional library options
+ * - clientCredentials - Credentials options for confidential clients
+ */
+export declare type ClientConfiguration = {
+ authOptions: AuthOptions;
+ systemOptions?: SystemOptions;
+ loggerOptions?: LoggerOptions;
+ storageInterface?: CacheManager;
+ networkInterface?: INetworkModule;
+ cryptoInterface?: ICrypto;
+ clientCredentials?: ClientCredentials;
+ libraryInfo?: LibraryInfo;
+ serverTelemetryManager?: ServerTelemetryManager | null;
+ persistencePlugin?: ICachePlugin | null;
+ serializableCache?: ISerializableTokenCache | null;
+};
+export declare type CommonClientConfiguration = {
+ authOptions: Required;
+ systemOptions: Required;
+ loggerOptions: Required;
+ storageInterface: CacheManager;
+ networkInterface: INetworkModule;
+ cryptoInterface: Required;
+ libraryInfo: LibraryInfo;
+ serverTelemetryManager: ServerTelemetryManager | null;
+ clientCredentials: ClientCredentials;
+ persistencePlugin: ICachePlugin | null;
+ serializableCache: ISerializableTokenCache | null;
+};
+/**
+ * Use this to configure the auth options in the ClientConfiguration object
+ *
+ * - clientId - Client ID of your app registered with our Application registration portal : https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/RegisteredAppsPreview in Microsoft Identity Platform
+ * - authority - You can configure a specific authority, defaults to " " or "https://login.microsoftonline.com/common"
+ * - knownAuthorities - An array of URIs that are known to be valid. Used in B2C scenarios.
+ * - cloudDiscoveryMetadata - A string containing the cloud discovery response. Used in AAD scenarios.
+ * - clientCapabilities - Array of capabilities which will be added to the claims.access_token.xms_cc request property on every network request.
+ * - protocolMode - Enum that represents the protocol that msal follows. Used for configuring proper endpoints.
+ */
+export declare type AuthOptions = {
+ clientId: string;
+ authority: Authority;
+ clientCapabilities?: Array;
+};
+/**
+ * Use this to configure token renewal info in the Configuration object
+ *
+ * - tokenRenewalOffsetSeconds - Sets the window of offset needed to renew the token before expiry
+ */
+export declare type SystemOptions = {
+ tokenRenewalOffsetSeconds?: number;
+};
+/**
+ * Use this to configure the logging that MSAL does, by configuring logger options in the Configuration object
+ *
+ * - loggerCallback - Callback for logger
+ * - piiLoggingEnabled - Sets whether pii logging is enabled
+ * - logLevel - Sets the level at which logging happens
+ */
+export declare type LoggerOptions = {
+ loggerCallback?: ILoggerCallback;
+ piiLoggingEnabled?: boolean;
+ logLevel?: LogLevel;
+};
+/**
+ * Library-specific options
+ */
+export declare type LibraryInfo = {
+ sku: string;
+ version: string;
+ cpu: string;
+ os: string;
+};
+/**
+ * Credentials for confidential clients
+ */
+export declare type ClientCredentials = {
+ clientSecret?: string;
+ clientAssertion?: {
+ assertion: string;
+ assertionType: string;
+ };
+};
+export declare const DEFAULT_SYSTEM_OPTIONS: Required;
+/**
+ * Function that sets the default options when not explicitly configured from app developer
+ *
+ * @param Configuration
+ *
+ * @returns Configuration
+ */
+export declare function buildClientConfiguration({ authOptions: userAuthOptions, systemOptions: userSystemOptions, loggerOptions: userLoggerOption, storageInterface: storageImplementation, networkInterface: networkImplementation, cryptoInterface: cryptoImplementation, clientCredentials: clientCredentials, libraryInfo: libraryInfo, serverTelemetryManager: serverTelemetryManager, persistencePlugin: persistencePlugin, serializableCache: serializableCache }: ClientConfiguration): CommonClientConfiguration;
+//# sourceMappingURL=ClientConfiguration.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/config/ClientConfiguration.d.ts.map b/node_modules/@azure/msal-common/dist/config/ClientConfiguration.d.ts.map
new file mode 100644
index 0000000..9239876
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/config/ClientConfiguration.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ClientConfiguration.d.ts","sourceRoot":"","sources":["../../src/config/ClientConfiguration.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,cAAc,EAAE,MAAM,2BAA2B,CAAC;AAC3D,OAAO,EAAiC,OAAO,EAAE,MAAM,mBAAmB,CAAC;AAE3E,OAAO,EAAE,eAAe,EAAE,QAAQ,EAAE,MAAM,kBAAkB,CAAC;AAG7D,OAAO,EAAE,SAAS,EAAE,MAAM,wBAAwB,CAAC;AACnD,OAAO,EAAE,YAAY,EAAuB,MAAM,uBAAuB,CAAC;AAC1E,OAAO,EAAE,sBAAsB,EAAE,MAAM,4CAA4C,CAAC;AACpF,OAAO,EAAE,YAAY,EAAE,MAAM,iCAAiC,CAAC;AAC/D,OAAO,EAAE,uBAAuB,EAAE,MAAM,4CAA4C,CAAC;AAKrF;;;;;;;;;;;;GAYG;AACH,oBAAY,mBAAmB,GAAG;IAC9B,WAAW,EAAE,WAAW,CAAC;IACzB,aAAa,CAAC,EAAE,aAAa,CAAC;IAC9B,aAAa,CAAC,EAAE,aAAa,CAAC;IAC9B,gBAAgB,CAAC,EAAE,YAAY,CAAC;IAChC,gBAAgB,CAAC,EAAE,cAAc,CAAC;IAClC,eAAe,CAAC,EAAE,OAAO,CAAC;IAC1B,iBAAiB,CAAC,EAAE,iBAAiB,CAAC;IACtC,WAAW,CAAC,EAAE,WAAW,CAAA;IACzB,sBAAsB,CAAC,EAAE,sBAAsB,GAAG,IAAI,CAAC;IACvD,iBAAiB,CAAC,EAAE,YAAY,GAAG,IAAI,CAAC;IACxC,iBAAiB,CAAC,EAAE,uBAAuB,GAAG,IAAI,CAAA;CACrD,CAAC;AAEF,oBAAY,yBAAyB,GAAG;IACpC,WAAW,EAAE,QAAQ,CAAC,WAAW,CAAC,CAAC;IACnC,aAAa,EAAE,QAAQ,CAAC,aAAa,CAAC,CAAC;IACvC,aAAa,EAAG,QAAQ,CAAC,aAAa,CAAC,CAAC;IACxC,gBAAgB,EAAE,YAAY,CAAC;IAC/B,gBAAgB,EAAG,cAAc,CAAC;IAClC,eAAe,EAAG,QAAQ,CAAC,OAAO,CAAC,CAAC;IACpC,WAAW,EAAG,WAAW,CAAC;IAC1B,sBAAsB,EAAE,sBAAsB,GAAG,IAAI,CAAC;IACtD,iBAAiB,EAAE,iBAAiB,CAAC;IACrC,iBAAiB,EAAE,YAAY,GAAG,IAAI,CAAC;IACvC,iBAAiB,EAAE,uBAAuB,GAAG,IAAI,CAAA;CACpD,CAAC;AAEF;;;;;;;;;GASG;AACH,oBAAY,WAAW,GAAG;IACtB,QAAQ,EAAE,MAAM,CAAC;IACjB,SAAS,EAAE,SAAS,CAAC;IACrB,kBAAkB,CAAC,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;CACtC,CAAC;AAEF;;;;GAIG;AACH,oBAAY,aAAa,GAAG;IACxB,yBAAyB,CAAC,EAAE,MAAM,CAAC;CACtC,CAAC;AAEF;;;;;;GAMG;AACH,oBAAY,aAAa,GAAG;IACxB,cAAc,CAAC,EAAE,eAAe,CAAC;IACjC,iBAAiB,CAAC,EAAE,OAAO,CAAC;IAC5B,QAAQ,CAAC,EAAE,QAAQ,CAAA;CACtB,CAAC;AAEF;;GAEG;AACH,oBAAY,WAAW,GAAG;IACtB,GAAG,EAAE,MAAM,CAAC;IACZ,OAAO,EAAE,MAAM,CAAC;IAChB,GAAG,EAAE,MAAM,CAAC;IACZ,EAAE,EAAE,MAAM,CAAA;CACb,CAAC;AAEF;;GAEG;AACH,oBAAY,iBAAiB,GAAG;IAC5B,YAAY,CAAC,EAAE,MAAM,CAAC;IACtB,eAAe,CAAC,EAAG;QACf,SAAS,EAAE,MAAM,CAAC;QAClB,aAAa,EAAE,MAAM,CAAA;KACxB,CAAC;CACL,CAAC;AAEF,eAAO,MAAM,sBAAsB,EAAE,QAAQ,CAAC,aAAa,CAE1D,CAAC;AAiCF;;;;;;GAMG;AACH,wBAAgB,wBAAwB,CACpC,EACI,WAAW,EAAE,eAAe,EAC5B,aAAa,EAAE,iBAAiB,EAChC,aAAa,EAAE,gBAAgB,EAC/B,gBAAgB,EAAE,qBAAqB,EACvC,gBAAgB,EAAE,qBAAqB,EACvC,eAAe,EAAE,oBAAoB,EACrC,iBAAiB,EAAE,iBAAiB,EACpC,WAAW,EAAE,WAAW,EACxB,sBAAsB,EAAE,sBAAsB,EAC9C,iBAAiB,EAAE,iBAAiB,EACpC,iBAAiB,EAAE,iBAAiB,EACvC,EAAE,mBAAmB,GAAG,yBAAyB,CAerD"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/crypto/ICrypto.d.ts b/node_modules/@azure/msal-common/dist/crypto/ICrypto.d.ts
new file mode 100644
index 0000000..f72b637
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/crypto/ICrypto.d.ts
@@ -0,0 +1,46 @@
+import { SignedHttpRequest } from "./SignedHttpRequest";
+/**
+ * The PkceCodes type describes the structure
+ * of objects that contain PKCE code
+ * challenge and verifier pairs
+ */
+export declare type PkceCodes = {
+ verifier: string;
+ challenge: string;
+};
+/**
+ * Interface for crypto functions used by library
+ */
+export interface ICrypto {
+ /**
+ * Creates a guid randomly.
+ */
+ createNewGuid(): string;
+ /**
+ * base64 Encode string
+ * @param input
+ */
+ base64Encode(input: string): string;
+ /**
+ * base64 decode string
+ * @param input
+ */
+ base64Decode(input: string): string;
+ /**
+ * Generate PKCE codes for OAuth. See RFC here: https://tools.ietf.org/html/rfc7636
+ */
+ generatePkceCodes(): Promise;
+ /**
+ * Generates an JWK RSA S256 Thumbprint
+ * @param resourceRequestMethod
+ * @param resourceRequestUri
+ */
+ getPublicKeyThumbprint(resourceRequestMethod: string, resourceRequestUri: string): Promise;
+ /**
+ * Returns a signed proof-of-possession token with a given acces token that contains a cnf claim with the required kid.
+ * @param accessToken
+ */
+ signJwt(payload: SignedHttpRequest, kid: string): Promise;
+}
+export declare const DEFAULT_CRYPTO_IMPLEMENTATION: ICrypto;
+//# sourceMappingURL=ICrypto.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/crypto/ICrypto.d.ts.map b/node_modules/@azure/msal-common/dist/crypto/ICrypto.d.ts.map
new file mode 100644
index 0000000..5948b13
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/crypto/ICrypto.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ICrypto.d.ts","sourceRoot":"","sources":["../../src/crypto/ICrypto.ts"],"names":[],"mappings":"AAMA,OAAO,EAAE,iBAAiB,EAAE,MAAM,qBAAqB,CAAC;AAExD;;;;GAIG;AACH,oBAAY,SAAS,GAAG;IACpB,QAAQ,EAAE,MAAM,CAAC;IACjB,SAAS,EAAE,MAAM,CAAA;CACpB,CAAC;AAEF;;GAEG;AACH,MAAM,WAAW,OAAO;IACpB;;OAEG;IACH,aAAa,IAAI,MAAM,CAAC;IACxB;;;OAGG;IACH,YAAY,CAAC,KAAK,EAAE,MAAM,GAAG,MAAM,CAAC;IACpC;;;OAGG;IACH,YAAY,CAAC,KAAK,EAAE,MAAM,GAAG,MAAM,CAAC;IACpC;;OAEG;IACH,iBAAiB,IAAI,OAAO,CAAC,SAAS,CAAC,CAAC;IACxC;;;;OAIG;IACH,sBAAsB,CAAC,qBAAqB,EAAE,MAAM,EAAE,kBAAkB,EAAE,MAAM,GAAG,OAAO,CAAC,MAAM,CAAC,CAAC;IACnG;;;OAGG;IACH,OAAO,CAAC,OAAO,EAAE,iBAAiB,EAAE,GAAG,EAAE,MAAM,GAAG,OAAO,CAAC,MAAM,CAAC,CAAC;CACrE;AAED,eAAO,MAAM,6BAA6B,EAAE,OAyB3C,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/crypto/PopTokenGenerator.d.ts b/node_modules/@azure/msal-common/dist/crypto/PopTokenGenerator.d.ts
new file mode 100644
index 0000000..81840a8
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/crypto/PopTokenGenerator.d.ts
@@ -0,0 +1,8 @@
+import { ICrypto } from "./ICrypto";
+export declare class PopTokenGenerator {
+ private cryptoUtils;
+ constructor(cryptoUtils: ICrypto);
+ generateCnf(resourceRequestMethod: string, resourceRequestUri: string): Promise;
+ signPopToken(accessToken: string, resourceRequestMethod: string, resourceRequestUri: string): Promise;
+}
+//# sourceMappingURL=PopTokenGenerator.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/crypto/PopTokenGenerator.d.ts.map b/node_modules/@azure/msal-common/dist/crypto/PopTokenGenerator.d.ts.map
new file mode 100644
index 0000000..bd55168
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/crypto/PopTokenGenerator.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"PopTokenGenerator.d.ts","sourceRoot":"","sources":["../../src/crypto/PopTokenGenerator.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,OAAO,EAAE,MAAM,WAAW,CAAC;AAyBpC,qBAAa,iBAAiB;IAE1B,OAAO,CAAC,WAAW,CAAU;gBAEjB,WAAW,EAAE,OAAO;IAI1B,WAAW,CAAC,qBAAqB,EAAE,MAAM,EAAE,kBAAkB,EAAE,MAAM,GAAG,OAAO,CAAC,MAAM,CAAC;IASvF,YAAY,CAAC,WAAW,EAAE,MAAM,EAAE,qBAAqB,EAAE,MAAM,EAAE,kBAAkB,EAAE,MAAM,GAAG,OAAO,CAAC,MAAM,CAAC;CAmBtH"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/crypto/SignedHttpRequest.d.ts b/node_modules/@azure/msal-common/dist/crypto/SignedHttpRequest.d.ts
new file mode 100644
index 0000000..ce35800
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/crypto/SignedHttpRequest.d.ts
@@ -0,0 +1,11 @@
+export declare type SignedHttpRequest = {
+ at?: string;
+ cnf?: object;
+ m?: string;
+ u?: string;
+ p?: string;
+ q?: [Array, string];
+ ts?: string;
+ nonce?: string;
+};
+//# sourceMappingURL=SignedHttpRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/crypto/SignedHttpRequest.d.ts.map b/node_modules/@azure/msal-common/dist/crypto/SignedHttpRequest.d.ts.map
new file mode 100644
index 0000000..bd55f76
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/crypto/SignedHttpRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"SignedHttpRequest.d.ts","sourceRoot":"","sources":["../../src/crypto/SignedHttpRequest.ts"],"names":[],"mappings":"AAKA,oBAAY,iBAAiB,GAAG;IAC5B,EAAE,CAAC,EAAE,MAAM,CAAC;IACZ,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,CAAC,CAAC,EAAE,MAAM,CAAC;IACX,CAAC,CAAC,EAAE,MAAM,CAAC;IACX,CAAC,CAAC,EAAE,MAAM,CAAC;IACX,CAAC,CAAC,EAAE,CAAC,KAAK,CAAC,MAAM,CAAC,EAAE,MAAM,CAAC,CAAC;IAC5B,EAAE,CAAC,EAAE,MAAM,CAAC;IACZ,KAAK,CAAC,EAAE,MAAM,CAAC;CAClB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/AuthError.d.ts b/node_modules/@azure/msal-common/dist/error/AuthError.d.ts
new file mode 100644
index 0000000..443ad12
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/AuthError.d.ts
@@ -0,0 +1,33 @@
+/**
+ * AuthErrorMessage class containing string constants used by error codes and messages.
+ */
+export declare const AuthErrorMessage: {
+ unexpectedError: {
+ code: string;
+ desc: string;
+ };
+};
+/**
+ * General error class thrown by the MSAL.js library.
+ */
+export declare class AuthError extends Error {
+ /**
+ * Short string denoting error
+ */
+ errorCode: string;
+ /**
+ * Detailed description of error
+ */
+ errorMessage: string;
+ /**
+ * Describes the subclass of an error
+ */
+ subError: string;
+ constructor(errorCode?: string, errorMessage?: string, suberror?: string);
+ /**
+ * Creates an error that is thrown when something unexpected happens in the library.
+ * @param errDesc
+ */
+ static createUnexpectedError(errDesc: string): AuthError;
+}
+//# sourceMappingURL=AuthError.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/AuthError.d.ts.map b/node_modules/@azure/msal-common/dist/error/AuthError.d.ts.map
new file mode 100644
index 0000000..06acad7
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/AuthError.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthError.d.ts","sourceRoot":"","sources":["../../src/error/AuthError.ts"],"names":[],"mappings":"AAOA;;GAEG;AACH,eAAO,MAAM,gBAAgB;;;;;CAK5B,CAAC;AAEF;;GAEG;AACH,qBAAa,SAAU,SAAQ,KAAK;IAEhC;;OAEG;IACH,SAAS,EAAE,MAAM,CAAC;IAElB;;OAEG;IACH,YAAY,EAAE,MAAM,CAAC;IAErB;;OAEG;IACH,QAAQ,EAAE,MAAM,CAAC;gBAEL,SAAS,CAAC,EAAE,MAAM,EAAE,YAAY,CAAC,EAAE,MAAM,EAAE,QAAQ,CAAC,EAAE,MAAM;IAWxE;;;OAGG;IACH,MAAM,CAAC,qBAAqB,CAAC,OAAO,EAAE,MAAM,GAAG,SAAS;CAG3D"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/ClientAuthError.d.ts b/node_modules/@azure/msal-common/dist/error/ClientAuthError.d.ts
new file mode 100644
index 0000000..ae36b0a
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/ClientAuthError.d.ts
@@ -0,0 +1,332 @@
+import { AuthError } from "./AuthError";
+import { ScopeSet } from "../request/ScopeSet";
+/**
+ * ClientAuthErrorMessage class containing string constants used by error codes and messages.
+ */
+export declare const ClientAuthErrorMessage: {
+ clientInfoDecodingError: {
+ code: string;
+ desc: string;
+ };
+ clientInfoEmptyError: {
+ code: string;
+ desc: string;
+ };
+ tokenParsingError: {
+ code: string;
+ desc: string;
+ };
+ nullOrEmptyToken: {
+ code: string;
+ desc: string;
+ };
+ endpointResolutionError: {
+ code: string;
+ desc: string;
+ };
+ unableToGetOpenidConfigError: {
+ code: string;
+ desc: string;
+ };
+ hashNotDeserialized: {
+ code: string;
+ desc: string;
+ };
+ blankGuidGenerated: {
+ code: string;
+ desc: string;
+ };
+ invalidStateError: {
+ code: string;
+ desc: string;
+ };
+ stateMismatchError: {
+ code: string;
+ desc: string;
+ };
+ stateNotFoundError: {
+ code: string;
+ desc: string;
+ };
+ nonceMismatchError: {
+ code: string;
+ desc: string;
+ };
+ nonceNotFoundError: {
+ code: string;
+ desc: string;
+ };
+ noTokensFoundError: {
+ code: string;
+ desc: string;
+ };
+ multipleMatchingTokens: {
+ code: string;
+ desc: string;
+ };
+ multipleMatchingAccounts: {
+ code: string;
+ desc: string;
+ };
+ multipleMatchingAppMetadata: {
+ code: string;
+ desc: string;
+ };
+ tokenRequestCannotBeMade: {
+ code: string;
+ desc: string;
+ };
+ appendEmptyScopeError: {
+ code: string;
+ desc: string;
+ };
+ removeEmptyScopeError: {
+ code: string;
+ desc: string;
+ };
+ appendScopeSetError: {
+ code: string;
+ desc: string;
+ };
+ emptyInputScopeSetError: {
+ code: string;
+ desc: string;
+ };
+ DeviceCodePollingCancelled: {
+ code: string;
+ desc: string;
+ };
+ DeviceCodeExpired: {
+ code: string;
+ desc: string;
+ };
+ NoAccountInSilentRequest: {
+ code: string;
+ desc: string;
+ };
+ invalidCacheRecord: {
+ code: string;
+ desc: string;
+ };
+ invalidCacheEnvironment: {
+ code: string;
+ desc: string;
+ };
+ noAccountFound: {
+ code: string;
+ desc: string;
+ };
+ CachePluginError: {
+ code: string;
+ desc: string;
+ };
+ noCryptoObj: {
+ code: string;
+ desc: string;
+ };
+ invalidCacheType: {
+ code: string;
+ desc: string;
+ };
+ unexpectedAccountType: {
+ code: string;
+ desc: string;
+ };
+ unexpectedCredentialType: {
+ code: string;
+ desc: string;
+ };
+ invalidAssertion: {
+ code: string;
+ desc: string;
+ };
+ invalidClientCredential: {
+ code: string;
+ desc: string;
+ };
+ tokenRefreshRequired: {
+ code: string;
+ desc: string;
+ };
+ userTimeoutReached: {
+ code: string;
+ desc: string;
+ };
+ tokenClaimsRequired: {
+ code: string;
+ desc: string;
+ };
+ noAuthorizationCodeFromServer: {
+ code: string;
+ desc: string;
+ };
+};
+/**
+ * Error thrown when there is an error in the client code running on the browser.
+ */
+export declare class ClientAuthError extends AuthError {
+ constructor(errorCode: string, errorMessage?: string);
+ /**
+ * Creates an error thrown when client info object doesn't decode correctly.
+ * @param caughtError
+ */
+ static createClientInfoDecodingError(caughtError: string): ClientAuthError;
+ /**
+ * Creates an error thrown if the client info is empty.
+ * @param rawClientInfo
+ */
+ static createClientInfoEmptyError(): ClientAuthError;
+ /**
+ * Creates an error thrown when the id token extraction errors out.
+ * @param err
+ */
+ static createTokenParsingError(caughtExtractionError: string): ClientAuthError;
+ /**
+ * Creates an error thrown when the id token string is null or empty.
+ * @param invalidRawTokenString
+ */
+ static createTokenNullOrEmptyError(invalidRawTokenString: string): ClientAuthError;
+ /**
+ * Creates an error thrown when the endpoint discovery doesn't complete correctly.
+ */
+ static createEndpointDiscoveryIncompleteError(errDetail: string): ClientAuthError;
+ /**
+ * Creates an error thrown when the openid-configuration endpoint cannot be reached or does not contain the required data
+ */
+ static createUnableToGetOpenidConfigError(errDetail: string): ClientAuthError;
+ /**
+ * Creates an error thrown when the hash cannot be deserialized.
+ * @param hashParamObj
+ */
+ static createHashNotDeserializedError(hashParamObj: string): ClientAuthError;
+ /**
+ * Creates an error thrown when the state cannot be parsed.
+ * @param invalidState
+ */
+ static createInvalidStateError(invalidState: string, errorString?: string): ClientAuthError;
+ /**
+ * Creates an error thrown when two states do not match.
+ */
+ static createStateMismatchError(): ClientAuthError;
+ /**
+ * Creates an error thrown when the state is not present
+ * @param missingState
+ */
+ static createStateNotFoundError(missingState: string): ClientAuthError;
+ /**
+ * Creates an error thrown when the nonce does not match.
+ */
+ static createNonceMismatchError(): ClientAuthError;
+ /**
+ * Creates an error thrown when the mnonce is not present
+ * @param missingNonce
+ */
+ static createNonceNotFoundError(missingNonce: string): ClientAuthError;
+ /**
+ * Creates an error thrown when the authorization code required for a token request is null or empty.
+ */
+ static createNoTokensFoundError(): ClientAuthError;
+ /**
+ * Throws error when multiple tokens are in cache.
+ */
+ static createMultipleMatchingTokensInCacheError(): ClientAuthError;
+ /**
+ * Throws error when multiple accounts are in cache for the given params
+ */
+ static createMultipleMatchingAccountsInCacheError(): ClientAuthError;
+ /**
+ * Throws error when multiple appMetada are in cache for the given clientId.
+ */
+ static createMultipleMatchingAppMetadataInCacheError(): ClientAuthError;
+ /**
+ * Throws error when no auth code or refresh token is given to ServerTokenRequestParameters.
+ */
+ static createTokenRequestCannotBeMadeError(): ClientAuthError;
+ /**
+ * Throws error when attempting to append a null, undefined or empty scope to a set
+ * @param givenScope
+ */
+ static createAppendEmptyScopeToSetError(givenScope: string): ClientAuthError;
+ /**
+ * Throws error when attempting to append a null, undefined or empty scope to a set
+ * @param givenScope
+ */
+ static createRemoveEmptyScopeFromSetError(givenScope: string): ClientAuthError;
+ /**
+ * Throws error when attempting to append null or empty ScopeSet.
+ * @param appendError
+ */
+ static createAppendScopeSetError(appendError: string): ClientAuthError;
+ /**
+ * Throws error if ScopeSet is null or undefined.
+ * @param givenScopeSet
+ */
+ static createEmptyInputScopeSetError(givenScopeSet: ScopeSet): ClientAuthError;
+ /**
+ * Throws error if user sets CancellationToken.cancel = true during polling of token endpoint during device code flow
+ */
+ static createDeviceCodeCancelledError(): ClientAuthError;
+ /**
+ * Throws error if device code is expired
+ */
+ static createDeviceCodeExpiredError(): ClientAuthError;
+ /**
+ * Throws error when silent requests are made without an account object
+ */
+ static createNoAccountInSilentRequestError(): ClientAuthError;
+ /**
+ * Throws error when cache record is null or undefined.
+ */
+ static createNullOrUndefinedCacheRecord(): ClientAuthError;
+ /**
+ * Throws error when provided environment is not part of the CloudDiscoveryMetadata object
+ */
+ static createInvalidCacheEnvironmentError(): ClientAuthError;
+ /**
+ * Throws error when account is not found in cache.
+ */
+ static createNoAccountFoundError(): ClientAuthError;
+ /**
+ * Throws error if ICachePlugin not set on CacheManager.
+ */
+ static createCachePluginError(): ClientAuthError;
+ /**
+ * Throws error if crypto object not found.
+ * @param operationName
+ */
+ static createNoCryptoObjectError(operationName: string): ClientAuthError;
+ /**
+ * Throws error if cache type is invalid.
+ */
+ static createInvalidCacheTypeError(): ClientAuthError;
+ /**
+ * Throws error if unexpected account type.
+ */
+ static createUnexpectedAccountTypeError(): ClientAuthError;
+ /**
+ * Throws error if unexpected credential type.
+ */
+ static createUnexpectedCredentialTypeError(): ClientAuthError;
+ /**
+ * Throws error if client assertion is not valid.
+ */
+ static createInvalidAssertionError(): ClientAuthError;
+ /**
+ * Throws error if client assertion is not valid.
+ */
+ static createInvalidCredentialError(): ClientAuthError;
+ /**
+ * Throws error if token cannot be retrieved from cache due to refresh being required.
+ */
+ static createRefreshRequiredError(): ClientAuthError;
+ /**
+ * Throws error if the user defined timeout is reached.
+ */
+ static createUserTimeoutReachedError(): ClientAuthError;
+ static createTokenClaimsRequiredError(): ClientAuthError;
+ /**
+ * Throws error when the authorization code is missing from the server response
+ */
+ static createNoAuthCodeInServerResponseError(): ClientAuthError;
+}
+//# sourceMappingURL=ClientAuthError.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/ClientAuthError.d.ts.map b/node_modules/@azure/msal-common/dist/error/ClientAuthError.d.ts.map
new file mode 100644
index 0000000..d2a38ad
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/ClientAuthError.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ClientAuthError.d.ts","sourceRoot":"","sources":["../../src/error/ClientAuthError.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,SAAS,EAAE,MAAM,aAAa,CAAC;AACxC,OAAO,EAAE,QAAQ,EAAE,MAAM,qBAAqB,CAAC;AAE/C;;GAEG;AACH,eAAO,MAAM,sBAAsB;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;CA8JlC,CAAC;AAEF;;GAEG;AACH,qBAAa,eAAgB,SAAQ,SAAS;gBAE9B,SAAS,EAAE,MAAM,EAAE,YAAY,CAAC,EAAE,MAAM;IAOpD;;;OAGG;IACH,MAAM,CAAC,6BAA6B,CAAC,WAAW,EAAE,MAAM,GAAG,eAAe;IAK1E;;;OAGG;IACH,MAAM,CAAC,0BAA0B,IAAI,eAAe;IAKpD;;;OAGG;IACH,MAAM,CAAC,uBAAuB,CAAC,qBAAqB,EAAE,MAAM,GAAG,eAAe;IAK9E;;;OAGG;IACH,MAAM,CAAC,2BAA2B,CAAC,qBAAqB,EAAE,MAAM,GAAI,eAAe;IAKnF;;OAEG;IACH,MAAM,CAAC,sCAAsC,CAAC,SAAS,EAAE,MAAM,GAAG,eAAe;IAKjF;;OAEG;IACH,MAAM,CAAC,kCAAkC,CAAC,SAAS,EAAE,MAAM,GAAG,eAAe;IAK7E;;;OAGG;IACH,MAAM,CAAC,8BAA8B,CAAC,YAAY,EAAE,MAAM,GAAG,eAAe;IAK5E;;;OAGG;IACH,MAAM,CAAC,uBAAuB,CAAC,YAAY,EAAE,MAAM,EAAE,WAAW,CAAC,EAAE,MAAM,GAAG,eAAe;IAK3F;;OAEG;IACH,MAAM,CAAC,wBAAwB,IAAI,eAAe;IAKlD;;;OAGG;IACH,MAAM,CAAC,wBAAwB,CAAC,YAAY,EAAE,MAAM,GAAG,eAAe;IAKtE;;OAEG;IACH,MAAM,CAAC,wBAAwB,IAAI,eAAe;IAKlD;;;OAGG;IACH,MAAM,CAAC,wBAAwB,CAAC,YAAY,EAAE,MAAM,GAAG,eAAe;IAKtE;;OAEG;IACH,MAAM,CAAC,wBAAwB,IAAI,eAAe;IAIlD;;OAEG;IACH,MAAM,CAAC,wCAAwC,IAAI,eAAe;IAKlE;;OAEG;IACH,MAAM,CAAC,0CAA0C,IAAI,eAAe;IAKpE;;OAEG;IACH,MAAM,CAAC,6CAA6C,IAAI,eAAe;IAKvE;;OAEG;IACH,MAAM,CAAC,mCAAmC,IAAI,eAAe;IAI7D;;;OAGG;IACH,MAAM,CAAC,gCAAgC,CAAC,UAAU,EAAE,MAAM,GAAG,eAAe;IAI5E;;;OAGG;IACH,MAAM,CAAC,kCAAkC,CAAC,UAAU,EAAE,MAAM,GAAG,eAAe;IAI9E;;;OAGG;IACH,MAAM,CAAC,yBAAyB,CAAC,WAAW,EAAE,MAAM,GAAG,eAAe;IAItE;;;OAGG;IACH,MAAM,CAAC,6BAA6B,CAAC,aAAa,EAAE,QAAQ,GAAG,eAAe;IAI9E;;OAEG;IACH,MAAM,CAAC,8BAA8B,IAAI,eAAe;IAIxD;;OAEG;IACH,MAAM,CAAC,4BAA4B,IAAI,eAAe;IAItD;;OAEG;IACH,MAAM,CAAC,mCAAmC,IAAI,eAAe;IAI7D;;OAEG;IACH,MAAM,CAAC,gCAAgC,IAAI,eAAe;IAI1D;;OAEG;IACH,MAAM,CAAC,kCAAkC,IAAI,eAAe;IAI5D;;OAEG;IACH,MAAM,CAAC,yBAAyB,IAAI,eAAe;IAInD;;OAEG;IACH,MAAM,CAAC,sBAAsB,IAAI,eAAe;IAIhD;;;OAGG;IACH,MAAM,CAAC,yBAAyB,CAAC,aAAa,EAAE,MAAM,GAAG,eAAe;IAIxE;;OAEG;IACH,MAAM,CAAC,2BAA2B,IAAI,eAAe;IAIrD;;OAEG;IACH,MAAM,CAAC,gCAAgC,IAAI,eAAe;IAI1D;;OAEG;IACH,MAAM,CAAC,mCAAmC,IAAI,eAAe;IAI7D;;OAEG;IACH,MAAM,CAAC,2BAA2B,IAAI,eAAe;IAIrD;;OAEG;IACH,MAAM,CAAC,4BAA4B,IAAI,eAAe;IAItD;;OAEG;IACH,MAAM,CAAC,0BAA0B,IAAI,eAAe;IAIpD;;OAEG;IACH,MAAM,CAAC,6BAA6B,IAAI,eAAe;IAOvD,MAAM,CAAC,8BAA8B,IAAI,eAAe;IAIxD;;OAEG;IACH,MAAM,CAAC,qCAAqC,IAAI,eAAe;CAGlE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/ClientConfigurationError.d.ts b/node_modules/@azure/msal-common/dist/error/ClientConfigurationError.d.ts
new file mode 100644
index 0000000..fdc6bd2
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/ClientConfigurationError.d.ts
@@ -0,0 +1,172 @@
+import { ClientAuthError } from "./ClientAuthError";
+/**
+ * ClientConfigurationErrorMessage class containing string constants used by error codes and messages.
+ */
+export declare const ClientConfigurationErrorMessage: {
+ redirectUriNotSet: {
+ code: string;
+ desc: string;
+ };
+ postLogoutUriNotSet: {
+ code: string;
+ desc: string;
+ };
+ claimsRequestParsingError: {
+ code: string;
+ desc: string;
+ };
+ authorityUriInsecure: {
+ code: string;
+ desc: string;
+ };
+ urlParseError: {
+ code: string;
+ desc: string;
+ };
+ urlEmptyError: {
+ code: string;
+ desc: string;
+ };
+ emptyScopesError: {
+ code: string;
+ desc: string;
+ };
+ nonArrayScopesError: {
+ code: string;
+ desc: string;
+ };
+ clientIdSingleScopeError: {
+ code: string;
+ desc: string;
+ };
+ invalidPrompt: {
+ code: string;
+ desc: string;
+ };
+ invalidClaimsRequest: {
+ code: string;
+ desc: string;
+ };
+ tokenRequestEmptyError: {
+ code: string;
+ desc: string;
+ };
+ logoutRequestEmptyError: {
+ code: string;
+ desc: string;
+ };
+ invalidCodeChallengeMethod: {
+ code: string;
+ desc: string;
+ };
+ invalidCodeChallengeParams: {
+ code: string;
+ desc: string;
+ };
+ invalidCloudDiscoveryMetadata: {
+ code: string;
+ desc: string;
+ };
+ invalidAuthorityMetadata: {
+ code: string;
+ desc: string;
+ };
+ untrustedAuthority: {
+ code: string;
+ desc: string;
+ };
+ resourceRequestParametersRequired: {
+ code: string;
+ desc: string;
+ };
+};
+/**
+ * Error thrown when there is an error in configuration of the MSAL.js library.
+ */
+export declare class ClientConfigurationError extends ClientAuthError {
+ constructor(errorCode: string, errorMessage?: string);
+ /**
+ * Creates an error thrown when the redirect uri is empty (not set by caller)
+ */
+ static createRedirectUriEmptyError(): ClientConfigurationError;
+ /**
+ * Creates an error thrown when the post-logout redirect uri is empty (not set by caller)
+ */
+ static createPostLogoutRedirectUriEmptyError(): ClientConfigurationError;
+ /**
+ * Creates an error thrown when the claims request could not be successfully parsed
+ */
+ static createClaimsRequestParsingError(claimsRequestParseError: string): ClientConfigurationError;
+ /**
+ * Creates an error thrown if authority uri is given an insecure protocol.
+ * @param urlString
+ */
+ static createInsecureAuthorityUriError(urlString: string): ClientConfigurationError;
+ /**
+ * Creates an error thrown if URL string does not parse into separate segments.
+ * @param urlString
+ */
+ static createUrlParseError(urlParseError: string): ClientConfigurationError;
+ /**
+ * Creates an error thrown if URL string is empty or null.
+ * @param urlString
+ */
+ static createUrlEmptyError(): ClientConfigurationError;
+ /**
+ * Error thrown when scopes are not an array
+ * @param inputScopes
+ */
+ static createScopesNonArrayError(inputScopes: Array): ClientConfigurationError;
+ /**
+ * Error thrown when scopes are empty.
+ * @param scopesValue
+ */
+ static createEmptyScopesArrayError(inputScopes: Array): ClientConfigurationError;
+ /**
+ * Error thrown when client id scope is not provided as single scope.
+ * @param inputScopes
+ */
+ static createClientIdSingleScopeError(inputScopes: Array): ClientConfigurationError;
+ /**
+ * Error thrown when prompt is not an allowed type.
+ * @param promptValue
+ */
+ static createInvalidPromptError(promptValue: string): ClientConfigurationError;
+ /**
+ * Creates error thrown when claims parameter is not a stringified JSON object
+ */
+ static createInvalidClaimsRequestError(): ClientConfigurationError;
+ /**
+ * Throws error when token request is empty and nothing cached in storage.
+ */
+ static createEmptyLogoutRequestError(): ClientConfigurationError;
+ /**
+ * Throws error when token request is empty and nothing cached in storage.
+ */
+ static createEmptyTokenRequestError(): ClientConfigurationError;
+ /**
+ * Throws error when an invalid code_challenge_method is passed by the user
+ */
+ static createInvalidCodeChallengeMethodError(): ClientConfigurationError;
+ /**
+ * Throws error when both params: code_challenge and code_challenge_method are not passed together
+ */
+ static createInvalidCodeChallengeParamsError(): ClientConfigurationError;
+ /**
+ * Throws an error when the user passes invalid cloudDiscoveryMetadata
+ */
+ static createInvalidCloudDiscoveryMetadataError(): ClientConfigurationError;
+ /**
+ * Throws an error when the user passes invalid cloudDiscoveryMetadata
+ */
+ static createInvalidAuthorityMetadataError(): ClientConfigurationError;
+ /**
+ * Throws error when provided authority is not a member of the trusted host list
+ */
+ static createUntrustedAuthorityError(): ClientConfigurationError;
+ /**
+ * Throws error when resourceRequestMethod or resourceRequestUri is missing
+ */
+ static createResourceRequestParametersRequiredError(): ClientConfigurationError;
+}
+//# sourceMappingURL=ClientConfigurationError.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/ClientConfigurationError.d.ts.map b/node_modules/@azure/msal-common/dist/error/ClientConfigurationError.d.ts.map
new file mode 100644
index 0000000..48b0681
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/ClientConfigurationError.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ClientConfigurationError.d.ts","sourceRoot":"","sources":["../../src/error/ClientConfigurationError.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AAEpD;;GAEG;AACH,eAAO,MAAM,+BAA+B;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;CA6E3C,CAAC;AAEF;;GAEG;AACH,qBAAa,wBAAyB,SAAQ,eAAe;gBAE7C,SAAS,EAAE,MAAM,EAAE,YAAY,CAAC,EAAE,MAAM;IAMpD;;OAEG;IACH,MAAM,CAAC,2BAA2B,IAAI,wBAAwB;IAK9D;;OAEG;IACH,MAAM,CAAC,qCAAqC,IAAI,wBAAwB;IAKxE;;OAEG;IACH,MAAM,CAAC,+BAA+B,CAAC,uBAAuB,EAAE,MAAM,GAAG,wBAAwB;IAKjG;;;OAGG;IACH,MAAM,CAAC,+BAA+B,CAAC,SAAS,EAAE,MAAM,GAAG,wBAAwB;IAKnF;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,aAAa,EAAE,MAAM,GAAG,wBAAwB;IAK3E;;;OAGG;IACH,MAAM,CAAC,mBAAmB,IAAI,wBAAwB;IAKtD;;;OAGG;IACH,MAAM,CAAC,yBAAyB,CAAC,WAAW,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,wBAAwB;IAKtF;;;OAGG;IACH,MAAM,CAAC,2BAA2B,CAAC,WAAW,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,wBAAwB;IAKxF;;;OAGG;IACH,MAAM,CAAC,8BAA8B,CAAC,WAAW,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,wBAAwB;IAK3F;;;OAGG;IACH,MAAM,CAAC,wBAAwB,CAAC,WAAW,EAAE,MAAM,GAAG,wBAAwB;IAK9E;;OAEG;IACH,MAAM,CAAC,+BAA+B,IAAI,wBAAwB;IAKlE;;OAEG;IACH,MAAM,CAAC,6BAA6B,IAAI,wBAAwB;IAOhE;;OAEG;IACH,MAAM,CAAC,4BAA4B,IAAI,wBAAwB;IAO/D;;OAEG;IACH,MAAM,CAAC,qCAAqC,IAAI,wBAAwB;IAOxE;;OAEG;IACH,MAAM,CAAC,qCAAqC,IAAI,wBAAwB;IAOxE;;OAEG;IACH,MAAM,CAAC,wCAAwC,IAAI,wBAAwB;IAK3E;;OAEG;IACH,MAAM,CAAC,mCAAmC,IAAI,wBAAwB;IAKtE;;OAEG;IACH,MAAM,CAAC,6BAA6B,IAAI,wBAAwB;IAKhE;;OAEG;IACH,MAAM,CAAC,4CAA4C,IAAI,wBAAwB;CAIlF"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/InteractionRequiredAuthError.d.ts b/node_modules/@azure/msal-common/dist/error/InteractionRequiredAuthError.d.ts
new file mode 100644
index 0000000..728e168
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/InteractionRequiredAuthError.d.ts
@@ -0,0 +1,14 @@
+import { ServerError } from "./ServerError";
+/**
+ * InteractionRequiredAuthErrorMessage class containing string constants used by error codes and messages.
+ */
+export declare const InteractionRequiredAuthErrorMessage: string[];
+export declare const InteractionRequiredAuthSubErrorMessage: string[];
+/**
+ * Error thrown when user interaction is required at the auth server.
+ */
+export declare class InteractionRequiredAuthError extends ServerError {
+ constructor(errorCode?: string, errorMessage?: string, subError?: string);
+ static isInteractionRequiredError(errorCode?: string, errorString?: string, subError?: string): boolean;
+}
+//# sourceMappingURL=InteractionRequiredAuthError.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/InteractionRequiredAuthError.d.ts.map b/node_modules/@azure/msal-common/dist/error/InteractionRequiredAuthError.d.ts.map
new file mode 100644
index 0000000..d3eda97
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/InteractionRequiredAuthError.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"InteractionRequiredAuthError.d.ts","sourceRoot":"","sources":["../../src/error/InteractionRequiredAuthError.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,WAAW,EAAE,MAAM,eAAe,CAAC;AAE5C;;GAEG;AACH,eAAO,MAAM,mCAAmC,UAI/C,CAAC;AAEF,eAAO,MAAM,sCAAsC,UAMlD,CAAC;AAEF;;GAEG;AACH,qBAAa,4BAA6B,SAAQ,WAAW;gBAE7C,SAAS,CAAC,EAAE,MAAM,EAAE,YAAY,CAAC,EAAE,MAAM,EAAE,QAAQ,CAAC,EAAE,MAAM;IAOxE,MAAM,CAAC,0BAA0B,CAAC,SAAS,CAAC,EAAE,MAAM,EAAE,WAAW,CAAC,EAAE,MAAM,EAAE,QAAQ,CAAC,EAAE,MAAM,GAAI,OAAO;CAS3G"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/ServerError.d.ts b/node_modules/@azure/msal-common/dist/error/ServerError.d.ts
new file mode 100644
index 0000000..ddd3df7
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/ServerError.d.ts
@@ -0,0 +1,8 @@
+import { AuthError } from "./AuthError";
+/**
+ * Error thrown when there is an error with the server code, for example, unavailability.
+ */
+export declare class ServerError extends AuthError {
+ constructor(errorCode?: string, errorMessage?: string, subError?: string);
+}
+//# sourceMappingURL=ServerError.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/error/ServerError.d.ts.map b/node_modules/@azure/msal-common/dist/error/ServerError.d.ts.map
new file mode 100644
index 0000000..82aea49
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/error/ServerError.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ServerError.d.ts","sourceRoot":"","sources":["../../src/error/ServerError.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,SAAS,EAAE,MAAM,aAAa,CAAC;AAExC;;GAEG;AACH,qBAAa,WAAY,SAAQ,SAAS;gBAE1B,SAAS,CAAC,EAAE,MAAM,EAAE,YAAY,CAAC,EAAE,MAAM,EAAE,QAAQ,CAAC,EAAE,MAAM;CAM3E"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/index.d.ts b/node_modules/@azure/msal-common/dist/index.d.ts
new file mode 100644
index 0000000..ef79c16
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/index.d.ts
@@ -0,0 +1,73 @@
+/**
+ * @packageDocumentation
+ * @module @azure/msal-common
+ */
+export { AuthorizationCodeClient } from "./client/AuthorizationCodeClient";
+export { DeviceCodeClient } from "./client/DeviceCodeClient";
+export { RefreshTokenClient } from "./client/RefreshTokenClient";
+export { ClientCredentialClient } from "./client/ClientCredentialClient";
+export { OnBehalfOfClient } from "./client/OnBehalfOfClient";
+export { SilentFlowClient } from "./client/SilentFlowClient";
+export { UsernamePasswordClient } from "./client/UsernamePasswordClient";
+export { AuthOptions, SystemOptions, LoggerOptions, DEFAULT_SYSTEM_OPTIONS } from "./config/ClientConfiguration";
+export { ClientConfiguration } from "./config/ClientConfiguration";
+export { AccountInfo } from "./account/AccountInfo";
+export { AuthToken } from "./account/AuthToken";
+export { AuthToken as IdToken } from "./account/AuthToken";
+export { TokenClaims } from "./account/TokenClaims";
+export { TokenClaims as IdTokenClaims } from "./account/TokenClaims";
+export { Authority } from "./authority/Authority";
+export { AuthorityOptions } from "./authority/AuthorityOptions";
+export { AuthorityFactory } from "./authority/AuthorityFactory";
+export { AuthorityType } from "./authority/AuthorityType";
+export { ProtocolMode } from "./authority/ProtocolMode";
+export { CacheManager, DefaultStorageClass } from "./cache/CacheManager";
+export { AccountCache, AccessTokenCache, IdTokenCache, RefreshTokenCache, AppMetadataCache, ValidCacheType, ValidCredentialType } from "./cache/utils/CacheTypes";
+export { CredentialEntity } from "./cache/entities/CredentialEntity";
+export { AppMetadataEntity } from "./cache/entities/AppMetadataEntity";
+export { AccountEntity } from "./cache/entities/AccountEntity";
+export { IdTokenEntity } from "./cache/entities/IdTokenEntity";
+export { AccessTokenEntity } from "./cache/entities/AccessTokenEntity";
+export { RefreshTokenEntity } from "./cache/entities/RefreshTokenEntity";
+export { ServerTelemetryEntity } from "./cache/entities/ServerTelemetryEntity";
+export { AuthorityMetadataEntity } from "./cache/entities/AuthorityMetadataEntity";
+export { ThrottlingEntity } from "./cache/entities/ThrottlingEntity";
+export { ICachePlugin } from "./cache/interface/ICachePlugin";
+export { TokenCacheContext } from "./cache/persistence/TokenCacheContext";
+export { ISerializableTokenCache } from "./cache/interface/ISerializableTokenCache";
+export { INetworkModule, NetworkRequestOptions, StubbedNetworkModule } from "./network/INetworkModule";
+export { NetworkManager, NetworkResponse } from "./network/NetworkManager";
+export { ThrottlingUtils } from "./network/ThrottlingUtils";
+export { RequestThumbprint } from "./network/RequestThumbprint";
+export { IUri } from "./url/IUri";
+export { UrlString } from "./url/UrlString";
+export { ICrypto, PkceCodes, DEFAULT_CRYPTO_IMPLEMENTATION } from "./crypto/ICrypto";
+export { SignedHttpRequest } from "./crypto/SignedHttpRequest";
+export { BaseAuthRequest } from "./request/BaseAuthRequest";
+export { CommonAuthorizationUrlRequest } from "./request/CommonAuthorizationUrlRequest";
+export { CommonAuthorizationCodeRequest } from "./request/CommonAuthorizationCodeRequest";
+export { CommonRefreshTokenRequest } from "./request/CommonRefreshTokenRequest";
+export { CommonClientCredentialRequest } from "./request/CommonClientCredentialRequest";
+export { CommonOnBehalfOfRequest } from "./request/CommonOnBehalfOfRequest";
+export { CommonSilentFlowRequest } from "./request/CommonSilentFlowRequest";
+export { CommonDeviceCodeRequest } from "./request/CommonDeviceCodeRequest";
+export { CommonEndSessionRequest } from "./request/CommonEndSessionRequest";
+export { CommonUsernamePasswordRequest } from "./request/CommonUsernamePasswordRequest";
+export { AuthenticationResult } from "./response/AuthenticationResult";
+export { AuthorizationCodePayload } from "./response/AuthorizationCodePayload";
+export { ServerAuthorizationCodeResponse } from "./response/ServerAuthorizationCodeResponse";
+export { DeviceCodeResponse } from "./response/DeviceCodeResponse";
+export { ILoggerCallback, LogLevel, Logger } from "./logger/Logger";
+export { InteractionRequiredAuthError } from "./error/InteractionRequiredAuthError";
+export { AuthError, AuthErrorMessage } from "./error/AuthError";
+export { ServerError } from "./error/ServerError";
+export { ClientAuthError, ClientAuthErrorMessage } from "./error/ClientAuthError";
+export { ClientConfigurationError, ClientConfigurationErrorMessage } from "./error/ClientConfigurationError";
+export { Constants, OIDC_DEFAULT_SCOPES, PromptValue, PersistentCacheKeys, ResponseMode, CacheSchemaType, CredentialType, CacheType, CacheAccountType, AuthenticationScheme } from "./utils/Constants";
+export { StringUtils } from "./utils/StringUtils";
+export { StringDict } from "./utils/MsalTypes";
+export { ProtocolUtils, RequestStateObject, LibraryStateObject } from "./utils/ProtocolUtils";
+export { TimeUtils } from "./utils/TimeUtils";
+export { ServerTelemetryManager } from "./telemetry/server/ServerTelemetryManager";
+export { ServerTelemetryRequest } from "./telemetry/server/ServerTelemetryRequest";
+//# sourceMappingURL=index.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/index.d.ts.map b/node_modules/@azure/msal-common/dist/index.d.ts.map
new file mode 100644
index 0000000..ea65cca
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/index.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"index.d.ts","sourceRoot":"","sources":["../src/index.ts"],"names":[],"mappings":"AAKA;;;GAGG;AAEH,OAAO,EAAE,uBAAuB,EAAC,MAAM,kCAAkC,CAAC;AAC1E,OAAO,EAAE,gBAAgB,EAAE,MAAM,2BAA2B,CAAC;AAC7D,OAAO,EAAE,kBAAkB,EAAE,MAAM,6BAA6B,CAAC;AACjE,OAAO,EAAE,sBAAsB,EAAE,MAAM,iCAAiC,CAAC;AACzE,OAAO,EAAE,gBAAgB,EAAE,MAAM,2BAA2B,CAAC;AAC7D,OAAO,EAAE,gBAAgB,EAAE,MAAM,2BAA2B,CAAC;AAC7D,OAAO,EAAE,sBAAsB,EAAE,MAAM,iCAAiC,CAAC;AACzE,OAAO,EAAE,WAAW,EAAE,aAAa,EAAE,aAAa,EAAE,sBAAsB,EAAE,MAAM,8BAA8B,CAAC;AACjH,OAAO,EAAE,mBAAmB,EAAE,MAAM,8BAA8B,CAAC;AAEnE,OAAO,EAAE,WAAW,EAAE,MAAM,uBAAuB,CAAC;AACpD,OAAO,EAAE,SAAS,EAAE,MAAM,qBAAqB,CAAC;AAChD,OAAO,EAAE,SAAS,IAAI,OAAO,EAAE,MAAM,qBAAqB,CAAC;AAC3D,OAAO,EAAE,WAAW,EAAE,MAAM,uBAAuB,CAAC;AACpD,OAAO,EAAE,WAAW,IAAI,aAAa,EAAE,MAAM,uBAAuB,CAAC;AAErE,OAAO,EAAE,SAAS,EAAE,MAAM,uBAAuB,CAAC;AAClD,OAAO,EAAE,gBAAgB,EAAE,MAAM,8BAA8B,CAAC;AAChE,OAAO,EAAE,gBAAgB,EAAE,MAAM,8BAA8B,CAAC;AAChE,OAAO,EAAE,aAAa,EAAE,MAAM,2BAA2B,CAAC;AAC1D,OAAO,EAAE,YAAY,EAAE,MAAM,0BAA0B,CAAC;AAExD,OAAO,EAAE,YAAY,EAAE,mBAAmB,EAAE,MAAM,sBAAsB,CAAC;AACzE,OAAO,EAAE,YAAY,EAAE,gBAAgB,EAAE,YAAY,EAAE,iBAAiB,EAAE,gBAAgB,EAAE,cAAc,EAAE,mBAAmB,EAAE,MAAM,0BAA0B,CAAC;AAClK,OAAO,EAAE,gBAAgB,EAAE,MAAM,mCAAmC,CAAC;AACrE,OAAO,EAAE,iBAAiB,EAAE,MAAM,oCAAoC,CAAC;AACvE,OAAO,EAAE,aAAa,EAAE,MAAM,gCAAgC,CAAC;AAC/D,OAAO,EAAE,aAAa,EAAE,MAAM,gCAAgC,CAAC;AAC/D,OAAO,EAAE,iBAAiB,EAAE,MAAM,oCAAoC,CAAC;AACvE,OAAO,EAAE,kBAAkB,EAAE,MAAM,qCAAqC,CAAC;AACzE,OAAO,EAAE,qBAAqB,EAAE,MAAM,wCAAwC,CAAC;AAC/E,OAAO,EAAE,uBAAuB,EAAE,MAAM,0CAA0C,CAAC;AACnF,OAAO,EAAE,gBAAgB,EAAE,MAAM,mCAAmC,CAAC;AACrE,OAAO,EAAE,YAAY,EAAE,MAAM,gCAAgC,CAAC;AAC9D,OAAO,EAAE,iBAAiB,EAAE,MAAM,uCAAuC,CAAC;AAC1E,OAAO,EAAE,uBAAuB,EAAE,MAAM,2CAA2C,CAAC;AAEpF,OAAO,EAAE,cAAc,EAAE,qBAAqB,EAAE,oBAAoB,EAAE,MAAM,0BAA0B,CAAC;AACvG,OAAO,EAAE,cAAc,EAAE,eAAe,EAAE,MAAM,0BAA0B,CAAC;AAC3E,OAAO,EAAE,eAAe,EAAE,MAAM,2BAA2B,CAAC;AAC5D,OAAO,EAAE,iBAAiB,EAAE,MAAM,6BAA6B,CAAC;AAChE,OAAO,EAAE,IAAI,EAAE,MAAM,YAAY,CAAC;AAClC,OAAO,EAAE,SAAS,EAAE,MAAM,iBAAiB,CAAC;AAE5C,OAAO,EAAE,OAAO,EAAE,SAAS,EAAE,6BAA6B,EAAE,MAAM,kBAAkB,CAAC;AACrF,OAAO,EAAE,iBAAiB,EAAE,MAAM,4BAA4B,CAAC;AAE/D,OAAO,EAAE,eAAe,EAAE,MAAM,2BAA2B,CAAC;AAC5D,OAAO,EAAE,6BAA6B,EAAE,MAAM,yCAAyC,CAAC;AACxF,OAAO,EAAE,8BAA8B,EAAE,MAAM,0CAA0C,CAAC;AAC1F,OAAO,EAAE,yBAAyB,EAAE,MAAM,qCAAqC,CAAC;AAChF,OAAO,EAAE,6BAA6B,EAAE,MAAM,yCAAyC,CAAC;AACxF,OAAO,EAAE,uBAAuB,EAAE,MAAM,mCAAmC,CAAC;AAC5E,OAAO,EAAE,uBAAuB,EAAE,MAAM,mCAAmC,CAAC;AAC5E,OAAO,EAAE,uBAAuB,EAAE,MAAM,mCAAmC,CAAC;AAC5E,OAAO,EAAE,uBAAuB,EAAE,MAAM,mCAAmC,CAAC;AAC5E,OAAO,EAAE,6BAA6B,EAAE,MAAM,yCAAyC,CAAC;AACxF,OAAO,EAAE,oBAAoB,EAAE,MAAM,iCAAiC,CAAC;AACvE,OAAO,EAAE,wBAAwB,EAAE,MAAM,qCAAqC,CAAC;AAC/E,OAAO,EAAE,+BAA+B,EAAE,MAAM,4CAA4C,CAAC;AAC7F,OAAO,EAAE,kBAAkB,EAAE,MAAM,+BAA+B,CAAC;AAEnE,OAAO,EAAE,eAAe,EAAE,QAAQ,EAAE,MAAM,EAAE,MAAM,iBAAiB,CAAC;AAEpE,OAAO,EAAE,4BAA4B,EAAE,MAAM,sCAAsC,CAAC;AACpF,OAAO,EAAE,SAAS,EAAE,gBAAgB,EAAE,MAAM,mBAAmB,CAAC;AAChE,OAAO,EAAE,WAAW,EAAE,MAAM,qBAAqB,CAAC;AAClD,OAAO,EAAE,eAAe,EAAE,sBAAsB,EAAE,MAAM,yBAAyB,CAAC;AAClF,OAAO,EAAE,wBAAwB,EAAE,+BAA+B,EAAE,MAAM,kCAAkC,CAAC;AAE7G,OAAO,EAAE,SAAS,EAAE,mBAAmB,EAAE,WAAW,EAAE,mBAAmB,EAAE,YAAY,EAAE,eAAe,EAAE,cAAc,EAAE,SAAS,EAAE,gBAAgB,EAAE,oBAAoB,EAAE,MAAM,mBAAmB,CAAC;AACvM,OAAO,EAAE,WAAW,EAAE,MAAM,qBAAqB,CAAC;AAClD,OAAO,EAAE,UAAU,EAAE,MAAM,mBAAmB,CAAC;AAC/C,OAAO,EAAE,aAAa,EAAE,kBAAkB,EAAE,kBAAkB,EAAE,MAAM,uBAAuB,CAAC;AAC9F,OAAO,EAAE,SAAS,EAAE,MAAM,mBAAmB,CAAC;AAE9C,OAAO,EAAE,sBAAsB,EAAE,MAAM,2CAA2C,CAAC;AACnF,OAAO,EAAE,sBAAsB,EAAE,MAAM,2CAA2C,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/index.es.js b/node_modules/@azure/msal-common/dist/index.es.js
new file mode 100644
index 0000000..4991bbe
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/index.es.js
@@ -0,0 +1,6328 @@
+/*! @azure/msal-common v4.0.1 2021-02-18 */
+'use strict';
+/*! *****************************************************************************
+Copyright (c) Microsoft Corporation.
+
+Permission to use, copy, modify, and/or distribute this software for any
+purpose with or without fee is hereby granted.
+
+THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
+REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
+AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
+INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
+LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
+OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
+PERFORMANCE OF THIS SOFTWARE.
+***************************************************************************** */
+/* global Reflect, Promise */
+
+var extendStatics = function(d, b) {
+ extendStatics = Object.setPrototypeOf ||
+ ({ __proto__: [] } instanceof Array && function (d, b) { d.__proto__ = b; }) ||
+ function (d, b) { for (var p in b) if (Object.prototype.hasOwnProperty.call(b, p)) d[p] = b[p]; };
+ return extendStatics(d, b);
+};
+
+function __extends(d, b) {
+ extendStatics(d, b);
+ function __() { this.constructor = d; }
+ d.prototype = b === null ? Object.create(b) : (__.prototype = b.prototype, new __());
+}
+
+var __assign = function() {
+ __assign = Object.assign || function __assign(t) {
+ for (var s, i = 1, n = arguments.length; i < n; i++) {
+ s = arguments[i];
+ for (var p in s) if (Object.prototype.hasOwnProperty.call(s, p)) t[p] = s[p];
+ }
+ return t;
+ };
+ return __assign.apply(this, arguments);
+};
+
+function __awaiter(thisArg, _arguments, P, generator) {
+ function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }
+ return new (P || (P = Promise))(function (resolve, reject) {
+ function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }
+ function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
+ function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }
+ step((generator = generator.apply(thisArg, _arguments || [])).next());
+ });
+}
+
+function __generator(thisArg, body) {
+ var _ = { label: 0, sent: function() { if (t[0] & 1) throw t[1]; return t[1]; }, trys: [], ops: [] }, f, y, t, g;
+ return g = { next: verb(0), "throw": verb(1), "return": verb(2) }, typeof Symbol === "function" && (g[Symbol.iterator] = function() { return this; }), g;
+ function verb(n) { return function (v) { return step([n, v]); }; }
+ function step(op) {
+ if (f) throw new TypeError("Generator is already executing.");
+ while (_) try {
+ if (f = 1, y && (t = op[0] & 2 ? y["return"] : op[0] ? y["throw"] || ((t = y["return"]) && t.call(y), 0) : y.next) && !(t = t.call(y, op[1])).done) return t;
+ if (y = 0, t) op = [op[0] & 2, t.value];
+ switch (op[0]) {
+ case 0: case 1: t = op; break;
+ case 4: _.label++; return { value: op[1], done: false };
+ case 5: _.label++; y = op[1]; op = [0]; continue;
+ case 7: op = _.ops.pop(); _.trys.pop(); continue;
+ default:
+ if (!(t = _.trys, t = t.length > 0 && t[t.length - 1]) && (op[0] === 6 || op[0] === 2)) { _ = 0; continue; }
+ if (op[0] === 3 && (!t || (op[1] > t[0] && op[1] < t[3]))) { _.label = op[1]; break; }
+ if (op[0] === 6 && _.label < t[1]) { _.label = t[1]; t = op; break; }
+ if (t && _.label < t[2]) { _.label = t[2]; _.ops.push(op); break; }
+ if (t[2]) _.ops.pop();
+ _.trys.pop(); continue;
+ }
+ op = body.call(thisArg, _);
+ } catch (e) { op = [6, e]; y = 0; } finally { f = t = 0; }
+ if (op[0] & 5) throw op[1]; return { value: op[0] ? op[1] : void 0, done: true };
+ }
+}
+
+function __spreadArrays() {
+ for (var s = 0, i = 0, il = arguments.length; i < il; i++) s += arguments[i].length;
+ for (var r = Array(s), k = 0, i = 0; i < il; i++)
+ for (var a = arguments[i], j = 0, jl = a.length; j < jl; j++, k++)
+ r[k] = a[j];
+ return r;
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var Constants = {
+ LIBRARY_NAME: "MSAL.JS",
+ SKU: "msal.js.common",
+ // Prefix for all library cache entries
+ CACHE_PREFIX: "msal",
+ // default authority
+ DEFAULT_AUTHORITY: "https://login.microsoftonline.com/common/",
+ DEFAULT_AUTHORITY_HOST: "login.microsoftonline.com",
+ // ADFS String
+ ADFS: "adfs",
+ // Default AAD Instance Discovery Endpoint
+ AAD_INSTANCE_DISCOVERY_ENDPT: "https://login.microsoftonline.com/common/discovery/instance?api-version=1.1&authorization_endpoint=",
+ // Resource delimiter - used for certain cache entries
+ RESOURCE_DELIM: "|",
+ // Placeholder for non-existent account ids/objects
+ NO_ACCOUNT: "NO_ACCOUNT",
+ // Claims
+ CLAIMS: "claims",
+ // Consumer UTID
+ CONSUMER_UTID: "9188040d-6c67-4c5b-b112-36a304b66dad",
+ // Default scopes
+ OPENID_SCOPE: "openid",
+ PROFILE_SCOPE: "profile",
+ OFFLINE_ACCESS_SCOPE: "offline_access",
+ EMAIL_SCOPE: "email",
+ // Default response type for authorization code flow
+ CODE_RESPONSE_TYPE: "code",
+ CODE_GRANT_TYPE: "authorization_code",
+ RT_GRANT_TYPE: "refresh_token",
+ FRAGMENT_RESPONSE_MODE: "fragment",
+ S256_CODE_CHALLENGE_METHOD: "S256",
+ URL_FORM_CONTENT_TYPE: "application/x-www-form-urlencoded;charset=utf-8",
+ AUTHORIZATION_PENDING: "authorization_pending",
+ NOT_DEFINED: "not_defined",
+ EMPTY_STRING: "",
+ FORWARD_SLASH: "/"
+};
+var OIDC_DEFAULT_SCOPES = [
+ Constants.OPENID_SCOPE,
+ Constants.PROFILE_SCOPE,
+ Constants.OFFLINE_ACCESS_SCOPE
+];
+var OIDC_SCOPES = __spreadArrays(OIDC_DEFAULT_SCOPES, [
+ Constants.EMAIL_SCOPE
+]);
+/**
+ * Request header names
+ */
+var HeaderNames;
+(function (HeaderNames) {
+ HeaderNames["CONTENT_TYPE"] = "Content-Type";
+ HeaderNames["X_CLIENT_CURR_TELEM"] = "x-client-current-telemetry";
+ HeaderNames["X_CLIENT_LAST_TELEM"] = "x-client-last-telemetry";
+ HeaderNames["RETRY_AFTER"] = "Retry-After";
+ HeaderNames["X_MS_LIB_CAPABILITY"] = "x-ms-lib-capability";
+ HeaderNames["X_MS_LIB_CAPABILITY_VALUE"] = "retry-after, h429";
+})(HeaderNames || (HeaderNames = {}));
+/**
+ * Persistent cache keys MSAL which stay while user is logged in.
+ */
+var PersistentCacheKeys;
+(function (PersistentCacheKeys) {
+ PersistentCacheKeys["ID_TOKEN"] = "idtoken";
+ PersistentCacheKeys["CLIENT_INFO"] = "client.info";
+ PersistentCacheKeys["ADAL_ID_TOKEN"] = "adal.idtoken";
+ PersistentCacheKeys["ERROR"] = "error";
+ PersistentCacheKeys["ERROR_DESC"] = "error.description";
+})(PersistentCacheKeys || (PersistentCacheKeys = {}));
+/**
+ * String constants related to AAD Authority
+ */
+var AADAuthorityConstants;
+(function (AADAuthorityConstants) {
+ AADAuthorityConstants["COMMON"] = "common";
+ AADAuthorityConstants["ORGANIZATIONS"] = "organizations";
+ AADAuthorityConstants["CONSUMERS"] = "consumers";
+})(AADAuthorityConstants || (AADAuthorityConstants = {}));
+/**
+ * Keys in the hashParams sent by AAD Server
+ */
+var AADServerParamKeys;
+(function (AADServerParamKeys) {
+ AADServerParamKeys["CLIENT_ID"] = "client_id";
+ AADServerParamKeys["REDIRECT_URI"] = "redirect_uri";
+ AADServerParamKeys["RESPONSE_TYPE"] = "response_type";
+ AADServerParamKeys["RESPONSE_MODE"] = "response_mode";
+ AADServerParamKeys["GRANT_TYPE"] = "grant_type";
+ AADServerParamKeys["CLAIMS"] = "claims";
+ AADServerParamKeys["SCOPE"] = "scope";
+ AADServerParamKeys["ERROR"] = "error";
+ AADServerParamKeys["ERROR_DESCRIPTION"] = "error_description";
+ AADServerParamKeys["ACCESS_TOKEN"] = "access_token";
+ AADServerParamKeys["ID_TOKEN"] = "id_token";
+ AADServerParamKeys["REFRESH_TOKEN"] = "refresh_token";
+ AADServerParamKeys["EXPIRES_IN"] = "expires_in";
+ AADServerParamKeys["STATE"] = "state";
+ AADServerParamKeys["NONCE"] = "nonce";
+ AADServerParamKeys["PROMPT"] = "prompt";
+ AADServerParamKeys["SESSION_STATE"] = "session_state";
+ AADServerParamKeys["CLIENT_INFO"] = "client_info";
+ AADServerParamKeys["CODE"] = "code";
+ AADServerParamKeys["CODE_CHALLENGE"] = "code_challenge";
+ AADServerParamKeys["CODE_CHALLENGE_METHOD"] = "code_challenge_method";
+ AADServerParamKeys["CODE_VERIFIER"] = "code_verifier";
+ AADServerParamKeys["CLIENT_REQUEST_ID"] = "client-request-id";
+ AADServerParamKeys["X_CLIENT_SKU"] = "x-client-SKU";
+ AADServerParamKeys["X_CLIENT_VER"] = "x-client-VER";
+ AADServerParamKeys["X_CLIENT_OS"] = "x-client-OS";
+ AADServerParamKeys["X_CLIENT_CPU"] = "x-client-CPU";
+ AADServerParamKeys["POST_LOGOUT_URI"] = "post_logout_redirect_uri";
+ AADServerParamKeys["ID_TOKEN_HINT"] = "id_token_hint";
+ AADServerParamKeys["DEVICE_CODE"] = "device_code";
+ AADServerParamKeys["CLIENT_SECRET"] = "client_secret";
+ AADServerParamKeys["CLIENT_ASSERTION"] = "client_assertion";
+ AADServerParamKeys["CLIENT_ASSERTION_TYPE"] = "client_assertion_type";
+ AADServerParamKeys["TOKEN_TYPE"] = "token_type";
+ AADServerParamKeys["REQ_CNF"] = "req_cnf";
+ AADServerParamKeys["OBO_ASSERTION"] = "assertion";
+ AADServerParamKeys["REQUESTED_TOKEN_USE"] = "requested_token_use";
+ AADServerParamKeys["ON_BEHALF_OF"] = "on_behalf_of";
+ AADServerParamKeys["FOCI"] = "foci";
+})(AADServerParamKeys || (AADServerParamKeys = {}));
+/**
+ * Claims request keys
+ */
+var ClaimsRequestKeys;
+(function (ClaimsRequestKeys) {
+ ClaimsRequestKeys["ACCESS_TOKEN"] = "access_token";
+ ClaimsRequestKeys["XMS_CC"] = "xms_cc";
+})(ClaimsRequestKeys || (ClaimsRequestKeys = {}));
+/**
+ * we considered making this "enum" in the request instead of string, however it looks like the allowed list of
+ * prompt values kept changing over past couple of years. There are some undocumented prompt values for some
+ * internal partners too, hence the choice of generic "string" type instead of the "enum"
+ */
+var PromptValue = {
+ LOGIN: "login",
+ SELECT_ACCOUNT: "select_account",
+ CONSENT: "consent",
+ NONE: "none",
+};
+/**
+ * SSO Types - generated to populate hints
+ */
+var SSOTypes;
+(function (SSOTypes) {
+ SSOTypes["ACCOUNT"] = "account";
+ SSOTypes["SID"] = "sid";
+ SSOTypes["LOGIN_HINT"] = "login_hint";
+ SSOTypes["ID_TOKEN"] = "id_token";
+ SSOTypes["DOMAIN_HINT"] = "domain_hint";
+ SSOTypes["ORGANIZATIONS"] = "organizations";
+ SSOTypes["CONSUMERS"] = "consumers";
+ SSOTypes["ACCOUNT_ID"] = "accountIdentifier";
+ SSOTypes["HOMEACCOUNT_ID"] = "homeAccountIdentifier";
+})(SSOTypes || (SSOTypes = {}));
+/**
+ * Disallowed extra query parameters.
+ */
+var BlacklistedEQParams = [
+ SSOTypes.SID,
+ SSOTypes.LOGIN_HINT
+];
+/**
+ * allowed values for codeVerifier
+ */
+var CodeChallengeMethodValues = {
+ PLAIN: "plain",
+ S256: "S256"
+};
+/**
+ * allowed values for response_mode
+ */
+var ResponseMode;
+(function (ResponseMode) {
+ ResponseMode["QUERY"] = "query";
+ ResponseMode["FRAGMENT"] = "fragment";
+ ResponseMode["FORM_POST"] = "form_post";
+})(ResponseMode || (ResponseMode = {}));
+/**
+ * allowed grant_type
+ */
+var GrantType;
+(function (GrantType) {
+ GrantType["IMPLICIT_GRANT"] = "implicit";
+ GrantType["AUTHORIZATION_CODE_GRANT"] = "authorization_code";
+ GrantType["CLIENT_CREDENTIALS_GRANT"] = "client_credentials";
+ GrantType["RESOURCE_OWNER_PASSWORD_GRANT"] = "password";
+ GrantType["REFRESH_TOKEN_GRANT"] = "refresh_token";
+ GrantType["DEVICE_CODE_GRANT"] = "device_code";
+ GrantType["JWT_BEARER"] = "urn:ietf:params:oauth:grant-type:jwt-bearer";
+})(GrantType || (GrantType = {}));
+/**
+ * Account types in Cache
+ */
+var CacheAccountType;
+(function (CacheAccountType) {
+ CacheAccountType["MSSTS_ACCOUNT_TYPE"] = "MSSTS";
+ CacheAccountType["ADFS_ACCOUNT_TYPE"] = "ADFS";
+ CacheAccountType["MSAV1_ACCOUNT_TYPE"] = "MSA";
+ CacheAccountType["GENERIC_ACCOUNT_TYPE"] = "Generic"; // NTLM, Kerberos, FBA, Basic etc
+})(CacheAccountType || (CacheAccountType = {}));
+/**
+ * Separators used in cache
+ */
+var Separators;
+(function (Separators) {
+ Separators["CACHE_KEY_SEPARATOR"] = "-";
+ Separators["CLIENT_INFO_SEPARATOR"] = ".";
+})(Separators || (Separators = {}));
+/**
+ * Credential Type stored in the cache
+ */
+var CredentialType;
+(function (CredentialType) {
+ CredentialType["ID_TOKEN"] = "IdToken";
+ CredentialType["ACCESS_TOKEN"] = "AccessToken";
+ CredentialType["REFRESH_TOKEN"] = "RefreshToken";
+})(CredentialType || (CredentialType = {}));
+/**
+ * Credential Type stored in the cache
+ */
+var CacheSchemaType;
+(function (CacheSchemaType) {
+ CacheSchemaType["ACCOUNT"] = "Account";
+ CacheSchemaType["CREDENTIAL"] = "Credential";
+ CacheSchemaType["ID_TOKEN"] = "IdToken";
+ CacheSchemaType["ACCESS_TOKEN"] = "AccessToken";
+ CacheSchemaType["REFRESH_TOKEN"] = "RefreshToken";
+ CacheSchemaType["APP_METADATA"] = "AppMetadata";
+ CacheSchemaType["TEMPORARY"] = "TempCache";
+ CacheSchemaType["TELEMETRY"] = "Telemetry";
+ CacheSchemaType["UNDEFINED"] = "Undefined";
+ CacheSchemaType["THROTTLING"] = "Throttling";
+})(CacheSchemaType || (CacheSchemaType = {}));
+/**
+ * Combine all cache types
+ */
+var CacheType;
+(function (CacheType) {
+ CacheType[CacheType["ADFS"] = 1001] = "ADFS";
+ CacheType[CacheType["MSA"] = 1002] = "MSA";
+ CacheType[CacheType["MSSTS"] = 1003] = "MSSTS";
+ CacheType[CacheType["GENERIC"] = 1004] = "GENERIC";
+ CacheType[CacheType["ACCESS_TOKEN"] = 2001] = "ACCESS_TOKEN";
+ CacheType[CacheType["REFRESH_TOKEN"] = 2002] = "REFRESH_TOKEN";
+ CacheType[CacheType["ID_TOKEN"] = 2003] = "ID_TOKEN";
+ CacheType[CacheType["APP_METADATA"] = 3001] = "APP_METADATA";
+ CacheType[CacheType["UNDEFINED"] = 9999] = "UNDEFINED";
+})(CacheType || (CacheType = {}));
+/**
+ * More Cache related constants
+ */
+var APP_METADATA = "appmetadata";
+var ClientInfo = "client_info";
+var THE_FAMILY_ID = "1";
+var AUTHORITY_METADATA_CONSTANTS = {
+ CACHE_KEY: "authority-metadata",
+ REFRESH_TIME_SECONDS: 3600 * 24 // 24 Hours
+};
+var AuthorityMetadataSource;
+(function (AuthorityMetadataSource) {
+ AuthorityMetadataSource["CONFIG"] = "config";
+ AuthorityMetadataSource["CACHE"] = "cache";
+ AuthorityMetadataSource["NETWORK"] = "network";
+})(AuthorityMetadataSource || (AuthorityMetadataSource = {}));
+var SERVER_TELEM_CONSTANTS = {
+ SCHEMA_VERSION: 2,
+ MAX_HEADER_BYTES: 4000,
+ CACHE_KEY: "server-telemetry",
+ CATEGORY_SEPARATOR: "|",
+ VALUE_SEPARATOR: ",",
+ OVERFLOW_TRUE: "1",
+ OVERFLOW_FALSE: "0",
+ UNKNOWN_ERROR: "unknown_error"
+};
+/**
+ * Type of the authentication request
+ */
+var AuthenticationScheme;
+(function (AuthenticationScheme) {
+ AuthenticationScheme["POP"] = "pop";
+ AuthenticationScheme["BEARER"] = "Bearer";
+})(AuthenticationScheme || (AuthenticationScheme = {}));
+/**
+ * Constants related to throttling
+ */
+var ThrottlingConstants = {
+ // Default time to throttle RequestThumbprint in seconds
+ DEFAULT_THROTTLE_TIME_SECONDS: 60,
+ // Default maximum time to throttle in seconds, overrides what the server sends back
+ DEFAULT_MAX_THROTTLE_TIME_SECONDS: 3600,
+ // Prefix for storing throttling entries
+ THROTTLING_PREFIX: "throttling"
+};
+var Errors = {
+ INVALID_GRANT_ERROR: "invalid_grant",
+ CLIENT_MISMATCH_ERROR: "client_mismatch",
+};
+/**
+ * Password grant parameters
+ */
+var PasswordGrantConstants;
+(function (PasswordGrantConstants) {
+ PasswordGrantConstants["username"] = "username";
+ PasswordGrantConstants["password"] = "password";
+})(PasswordGrantConstants || (PasswordGrantConstants = {}));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * AuthErrorMessage class containing string constants used by error codes and messages.
+ */
+var AuthErrorMessage = {
+ unexpectedError: {
+ code: "unexpected_error",
+ desc: "Unexpected error in authentication."
+ }
+};
+/**
+ * General error class thrown by the MSAL.js library.
+ */
+var AuthError = /** @class */ (function (_super) {
+ __extends(AuthError, _super);
+ function AuthError(errorCode, errorMessage, suberror) {
+ var _this = this;
+ var errorString = errorMessage ? errorCode + ": " + errorMessage : errorCode;
+ _this = _super.call(this, errorString) || this;
+ Object.setPrototypeOf(_this, AuthError.prototype);
+ _this.errorCode = errorCode || Constants.EMPTY_STRING;
+ _this.errorMessage = errorMessage || "";
+ _this.subError = suberror || "";
+ _this.name = "AuthError";
+ return _this;
+ }
+ /**
+ * Creates an error that is thrown when something unexpected happens in the library.
+ * @param errDesc
+ */
+ AuthError.createUnexpectedError = function (errDesc) {
+ return new AuthError(AuthErrorMessage.unexpectedError.code, AuthErrorMessage.unexpectedError.desc + ": " + errDesc);
+ };
+ return AuthError;
+}(Error));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var DEFAULT_CRYPTO_IMPLEMENTATION = {
+ createNewGuid: function () {
+ var notImplErr = "Crypto interface - createNewGuid() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ },
+ base64Decode: function () {
+ var notImplErr = "Crypto interface - base64Decode() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ },
+ base64Encode: function () {
+ var notImplErr = "Crypto interface - base64Encode() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ },
+ generatePkceCodes: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Crypto interface - generatePkceCodes() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ },
+ getPublicKeyThumbprint: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Crypto interface - getPublicKeyThumbprint() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ },
+ signJwt: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Crypto interface - signJwt() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ }
+};
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ClientAuthErrorMessage class containing string constants used by error codes and messages.
+ */
+var ClientAuthErrorMessage = {
+ clientInfoDecodingError: {
+ code: "client_info_decoding_error",
+ desc: "The client info could not be parsed/decoded correctly. Please review the trace to determine the root cause."
+ },
+ clientInfoEmptyError: {
+ code: "client_info_empty_error",
+ desc: "The client info was empty. Please review the trace to determine the root cause."
+ },
+ tokenParsingError: {
+ code: "token_parsing_error",
+ desc: "Token cannot be parsed. Please review stack trace to determine root cause."
+ },
+ nullOrEmptyToken: {
+ code: "null_or_empty_token",
+ desc: "The token is null or empty. Please review the trace to determine the root cause."
+ },
+ endpointResolutionError: {
+ code: "endpoints_resolution_error",
+ desc: "Error: could not resolve endpoints. Please check network and try again."
+ },
+ unableToGetOpenidConfigError: {
+ code: "openid_config_error",
+ desc: "Could not retrieve endpoints. Check your authority and verify the .well-known/openid-configuration endpoint returns the required endpoints."
+ },
+ hashNotDeserialized: {
+ code: "hash_not_deserialized",
+ desc: "The hash parameters could not be deserialized. Please review the trace to determine the root cause."
+ },
+ blankGuidGenerated: {
+ code: "blank_guid_generated",
+ desc: "The guid generated was blank. Please review the trace to determine the root cause."
+ },
+ invalidStateError: {
+ code: "invalid_state",
+ desc: "State was not the expected format. Please check the logs to determine whether the request was sent using ProtocolUtils.setRequestState()."
+ },
+ stateMismatchError: {
+ code: "state_mismatch",
+ desc: "State mismatch error. Please check your network. Continued requests may cause cache overflow."
+ },
+ stateNotFoundError: {
+ code: "state_not_found",
+ desc: "State not found"
+ },
+ nonceMismatchError: {
+ code: "nonce_mismatch",
+ desc: "Nonce mismatch error. This may be caused by a race condition in concurrent requests."
+ },
+ nonceNotFoundError: {
+ code: "nonce_not_found",
+ desc: "nonce not found"
+ },
+ noTokensFoundError: {
+ code: "no_tokens_found",
+ desc: "No tokens were found for the given scopes, and no authorization code was passed to acquireToken. You must retrieve an authorization code before making a call to acquireToken()."
+ },
+ multipleMatchingTokens: {
+ code: "multiple_matching_tokens",
+ desc: "The cache contains multiple tokens satisfying the requirements. " +
+ "Call AcquireToken again providing more requirements such as authority or account."
+ },
+ multipleMatchingAccounts: {
+ code: "multiple_matching_accounts",
+ desc: "The cache contains multiple accounts satisfying the given parameters. Please pass more info to obtain the correct account"
+ },
+ multipleMatchingAppMetadata: {
+ code: "multiple_matching_appMetadata",
+ desc: "The cache contains multiple appMetadata satisfying the given parameters. Please pass more info to obtain the correct appMetadata"
+ },
+ tokenRequestCannotBeMade: {
+ code: "request_cannot_be_made",
+ desc: "Token request cannot be made without authorization code or refresh token."
+ },
+ appendEmptyScopeError: {
+ code: "cannot_append_empty_scope",
+ desc: "Cannot append null or empty scope to ScopeSet. Please check the stack trace for more info."
+ },
+ removeEmptyScopeError: {
+ code: "cannot_remove_empty_scope",
+ desc: "Cannot remove null or empty scope from ScopeSet. Please check the stack trace for more info."
+ },
+ appendScopeSetError: {
+ code: "cannot_append_scopeset",
+ desc: "Cannot append ScopeSet due to error."
+ },
+ emptyInputScopeSetError: {
+ code: "empty_input_scopeset",
+ desc: "Empty input ScopeSet cannot be processed."
+ },
+ DeviceCodePollingCancelled: {
+ code: "device_code_polling_cancelled",
+ desc: "Caller has cancelled token endpoint polling during device code flow by setting DeviceCodeRequest.cancel = true."
+ },
+ DeviceCodeExpired: {
+ code: "device_code_expired",
+ desc: "Device code is expired."
+ },
+ NoAccountInSilentRequest: {
+ code: "no_account_in_silent_request",
+ desc: "Please pass an account object, silent flow is not supported without account information"
+ },
+ invalidCacheRecord: {
+ code: "invalid_cache_record",
+ desc: "Cache record object was null or undefined."
+ },
+ invalidCacheEnvironment: {
+ code: "invalid_cache_environment",
+ desc: "Invalid environment when attempting to create cache entry"
+ },
+ noAccountFound: {
+ code: "no_account_found",
+ desc: "No account found in cache for given key."
+ },
+ CachePluginError: {
+ code: "no cache plugin set on CacheManager",
+ desc: "ICachePlugin needs to be set before using readFromStorage or writeFromStorage"
+ },
+ noCryptoObj: {
+ code: "no_crypto_object",
+ desc: "No crypto object detected. This is required for the following operation: "
+ },
+ invalidCacheType: {
+ code: "invalid_cache_type",
+ desc: "Invalid cache type"
+ },
+ unexpectedAccountType: {
+ code: "unexpected_account_type",
+ desc: "Unexpected account type."
+ },
+ unexpectedCredentialType: {
+ code: "unexpected_credential_type",
+ desc: "Unexpected credential type."
+ },
+ invalidAssertion: {
+ code: "invalid_assertion",
+ desc: "Client assertion must meet requirements described in https://tools.ietf.org/html/rfc7515"
+ },
+ invalidClientCredential: {
+ code: "invalid_client_credential",
+ desc: "Client credential (secret, certificate, or assertion) must not be empty when creating a confidential client. An application should at most have one credential"
+ },
+ tokenRefreshRequired: {
+ code: "token_refresh_required",
+ desc: "Cannot return token from cache because it must be refreshed. This may be due to one of the following reasons: forceRefresh parameter is set to true, claims have been requested, there is no cached access token or it is expired."
+ },
+ userTimeoutReached: {
+ code: "user_timeout_reached",
+ desc: "User defined timeout for device code polling reached",
+ },
+ tokenClaimsRequired: {
+ code: "token_claims_cnf_required_for_signedjwt",
+ desc: "Cannot generate a POP jwt if the token_claims are not populated"
+ },
+ noAuthorizationCodeFromServer: {
+ code: "authorization_code_missing_from_server_response",
+ desc: "Srver response does not contain an authorization code to proceed"
+ }
+};
+/**
+ * Error thrown when there is an error in the client code running on the browser.
+ */
+var ClientAuthError = /** @class */ (function (_super) {
+ __extends(ClientAuthError, _super);
+ function ClientAuthError(errorCode, errorMessage) {
+ var _this = _super.call(this, errorCode, errorMessage) || this;
+ _this.name = "ClientAuthError";
+ Object.setPrototypeOf(_this, ClientAuthError.prototype);
+ return _this;
+ }
+ /**
+ * Creates an error thrown when client info object doesn't decode correctly.
+ * @param caughtError
+ */
+ ClientAuthError.createClientInfoDecodingError = function (caughtError) {
+ return new ClientAuthError(ClientAuthErrorMessage.clientInfoDecodingError.code, ClientAuthErrorMessage.clientInfoDecodingError.desc + " Failed with error: " + caughtError);
+ };
+ /**
+ * Creates an error thrown if the client info is empty.
+ * @param rawClientInfo
+ */
+ ClientAuthError.createClientInfoEmptyError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.clientInfoEmptyError.code, "" + ClientAuthErrorMessage.clientInfoEmptyError.desc);
+ };
+ /**
+ * Creates an error thrown when the id token extraction errors out.
+ * @param err
+ */
+ ClientAuthError.createTokenParsingError = function (caughtExtractionError) {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenParsingError.code, ClientAuthErrorMessage.tokenParsingError.desc + " Failed with error: " + caughtExtractionError);
+ };
+ /**
+ * Creates an error thrown when the id token string is null or empty.
+ * @param invalidRawTokenString
+ */
+ ClientAuthError.createTokenNullOrEmptyError = function (invalidRawTokenString) {
+ return new ClientAuthError(ClientAuthErrorMessage.nullOrEmptyToken.code, ClientAuthErrorMessage.nullOrEmptyToken.desc + " Raw Token Value: " + invalidRawTokenString);
+ };
+ /**
+ * Creates an error thrown when the endpoint discovery doesn't complete correctly.
+ */
+ ClientAuthError.createEndpointDiscoveryIncompleteError = function (errDetail) {
+ return new ClientAuthError(ClientAuthErrorMessage.endpointResolutionError.code, ClientAuthErrorMessage.endpointResolutionError.desc + " Detail: " + errDetail);
+ };
+ /**
+ * Creates an error thrown when the openid-configuration endpoint cannot be reached or does not contain the required data
+ */
+ ClientAuthError.createUnableToGetOpenidConfigError = function (errDetail) {
+ return new ClientAuthError(ClientAuthErrorMessage.unableToGetOpenidConfigError.code, ClientAuthErrorMessage.unableToGetOpenidConfigError.desc + " Attempted to retrieve endpoints from: " + errDetail);
+ };
+ /**
+ * Creates an error thrown when the hash cannot be deserialized.
+ * @param hashParamObj
+ */
+ ClientAuthError.createHashNotDeserializedError = function (hashParamObj) {
+ return new ClientAuthError(ClientAuthErrorMessage.hashNotDeserialized.code, ClientAuthErrorMessage.hashNotDeserialized.desc + " Given Object: " + hashParamObj);
+ };
+ /**
+ * Creates an error thrown when the state cannot be parsed.
+ * @param invalidState
+ */
+ ClientAuthError.createInvalidStateError = function (invalidState, errorString) {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidStateError.code, ClientAuthErrorMessage.invalidStateError.desc + " Invalid State: " + invalidState + ", Root Err: " + errorString);
+ };
+ /**
+ * Creates an error thrown when two states do not match.
+ */
+ ClientAuthError.createStateMismatchError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.stateMismatchError.code, ClientAuthErrorMessage.stateMismatchError.desc);
+ };
+ /**
+ * Creates an error thrown when the state is not present
+ * @param missingState
+ */
+ ClientAuthError.createStateNotFoundError = function (missingState) {
+ return new ClientAuthError(ClientAuthErrorMessage.stateNotFoundError.code, ClientAuthErrorMessage.stateNotFoundError.desc + ": " + missingState);
+ };
+ /**
+ * Creates an error thrown when the nonce does not match.
+ */
+ ClientAuthError.createNonceMismatchError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.nonceMismatchError.code, ClientAuthErrorMessage.nonceMismatchError.desc);
+ };
+ /**
+ * Creates an error thrown when the mnonce is not present
+ * @param missingNonce
+ */
+ ClientAuthError.createNonceNotFoundError = function (missingNonce) {
+ return new ClientAuthError(ClientAuthErrorMessage.nonceNotFoundError.code, ClientAuthErrorMessage.nonceNotFoundError.desc + ": " + missingNonce);
+ };
+ /**
+ * Creates an error thrown when the authorization code required for a token request is null or empty.
+ */
+ ClientAuthError.createNoTokensFoundError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.noTokensFoundError.code, ClientAuthErrorMessage.noTokensFoundError.desc);
+ };
+ /**
+ * Throws error when multiple tokens are in cache.
+ */
+ ClientAuthError.createMultipleMatchingTokensInCacheError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.multipleMatchingTokens.code, ClientAuthErrorMessage.multipleMatchingTokens.desc + ".");
+ };
+ /**
+ * Throws error when multiple accounts are in cache for the given params
+ */
+ ClientAuthError.createMultipleMatchingAccountsInCacheError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.multipleMatchingAccounts.code, ClientAuthErrorMessage.multipleMatchingAccounts.desc);
+ };
+ /**
+ * Throws error when multiple appMetada are in cache for the given clientId.
+ */
+ ClientAuthError.createMultipleMatchingAppMetadataInCacheError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.multipleMatchingAppMetadata.code, ClientAuthErrorMessage.multipleMatchingAppMetadata.desc);
+ };
+ /**
+ * Throws error when no auth code or refresh token is given to ServerTokenRequestParameters.
+ */
+ ClientAuthError.createTokenRequestCannotBeMadeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenRequestCannotBeMade.code, ClientAuthErrorMessage.tokenRequestCannotBeMade.desc);
+ };
+ /**
+ * Throws error when attempting to append a null, undefined or empty scope to a set
+ * @param givenScope
+ */
+ ClientAuthError.createAppendEmptyScopeToSetError = function (givenScope) {
+ return new ClientAuthError(ClientAuthErrorMessage.appendEmptyScopeError.code, ClientAuthErrorMessage.appendEmptyScopeError.desc + " Given Scope: " + givenScope);
+ };
+ /**
+ * Throws error when attempting to append a null, undefined or empty scope to a set
+ * @param givenScope
+ */
+ ClientAuthError.createRemoveEmptyScopeFromSetError = function (givenScope) {
+ return new ClientAuthError(ClientAuthErrorMessage.removeEmptyScopeError.code, ClientAuthErrorMessage.removeEmptyScopeError.desc + " Given Scope: " + givenScope);
+ };
+ /**
+ * Throws error when attempting to append null or empty ScopeSet.
+ * @param appendError
+ */
+ ClientAuthError.createAppendScopeSetError = function (appendError) {
+ return new ClientAuthError(ClientAuthErrorMessage.appendScopeSetError.code, ClientAuthErrorMessage.appendScopeSetError.desc + " Detail Error: " + appendError);
+ };
+ /**
+ * Throws error if ScopeSet is null or undefined.
+ * @param givenScopeSet
+ */
+ ClientAuthError.createEmptyInputScopeSetError = function (givenScopeSet) {
+ return new ClientAuthError(ClientAuthErrorMessage.emptyInputScopeSetError.code, ClientAuthErrorMessage.emptyInputScopeSetError.desc + " Given ScopeSet: " + givenScopeSet);
+ };
+ /**
+ * Throws error if user sets CancellationToken.cancel = true during polling of token endpoint during device code flow
+ */
+ ClientAuthError.createDeviceCodeCancelledError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.DeviceCodePollingCancelled.code, "" + ClientAuthErrorMessage.DeviceCodePollingCancelled.desc);
+ };
+ /**
+ * Throws error if device code is expired
+ */
+ ClientAuthError.createDeviceCodeExpiredError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.DeviceCodeExpired.code, "" + ClientAuthErrorMessage.DeviceCodeExpired.desc);
+ };
+ /**
+ * Throws error when silent requests are made without an account object
+ */
+ ClientAuthError.createNoAccountInSilentRequestError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.NoAccountInSilentRequest.code, "" + ClientAuthErrorMessage.NoAccountInSilentRequest.desc);
+ };
+ /**
+ * Throws error when cache record is null or undefined.
+ */
+ ClientAuthError.createNullOrUndefinedCacheRecord = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidCacheRecord.code, ClientAuthErrorMessage.invalidCacheRecord.desc);
+ };
+ /**
+ * Throws error when provided environment is not part of the CloudDiscoveryMetadata object
+ */
+ ClientAuthError.createInvalidCacheEnvironmentError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidCacheEnvironment.code, ClientAuthErrorMessage.invalidCacheEnvironment.desc);
+ };
+ /**
+ * Throws error when account is not found in cache.
+ */
+ ClientAuthError.createNoAccountFoundError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.noAccountFound.code, ClientAuthErrorMessage.noAccountFound.desc);
+ };
+ /**
+ * Throws error if ICachePlugin not set on CacheManager.
+ */
+ ClientAuthError.createCachePluginError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.CachePluginError.code, "" + ClientAuthErrorMessage.CachePluginError.desc);
+ };
+ /**
+ * Throws error if crypto object not found.
+ * @param operationName
+ */
+ ClientAuthError.createNoCryptoObjectError = function (operationName) {
+ return new ClientAuthError(ClientAuthErrorMessage.noCryptoObj.code, "" + ClientAuthErrorMessage.noCryptoObj.desc + operationName);
+ };
+ /**
+ * Throws error if cache type is invalid.
+ */
+ ClientAuthError.createInvalidCacheTypeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidCacheType.code, "" + ClientAuthErrorMessage.invalidCacheType.desc);
+ };
+ /**
+ * Throws error if unexpected account type.
+ */
+ ClientAuthError.createUnexpectedAccountTypeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.unexpectedAccountType.code, "" + ClientAuthErrorMessage.unexpectedAccountType.desc);
+ };
+ /**
+ * Throws error if unexpected credential type.
+ */
+ ClientAuthError.createUnexpectedCredentialTypeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.unexpectedCredentialType.code, "" + ClientAuthErrorMessage.unexpectedCredentialType.desc);
+ };
+ /**
+ * Throws error if client assertion is not valid.
+ */
+ ClientAuthError.createInvalidAssertionError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidAssertion.code, "" + ClientAuthErrorMessage.invalidAssertion.desc);
+ };
+ /**
+ * Throws error if client assertion is not valid.
+ */
+ ClientAuthError.createInvalidCredentialError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidClientCredential.code, "" + ClientAuthErrorMessage.invalidClientCredential.desc);
+ };
+ /**
+ * Throws error if token cannot be retrieved from cache due to refresh being required.
+ */
+ ClientAuthError.createRefreshRequiredError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenRefreshRequired.code, ClientAuthErrorMessage.tokenRefreshRequired.desc);
+ };
+ /**
+ * Throws error if the user defined timeout is reached.
+ */
+ ClientAuthError.createUserTimeoutReachedError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.userTimeoutReached.code, ClientAuthErrorMessage.userTimeoutReached.desc);
+ };
+ /*
+ * Throws error if token claims are not populated for a signed jwt generation
+ */
+ ClientAuthError.createTokenClaimsRequiredError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenClaimsRequired.code, ClientAuthErrorMessage.tokenClaimsRequired.desc);
+ };
+ /**
+ * Throws error when the authorization code is missing from the server response
+ */
+ ClientAuthError.createNoAuthCodeInServerResponseError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.noAuthorizationCodeFromServer.code, ClientAuthErrorMessage.noAuthorizationCodeFromServer.desc);
+ };
+ return ClientAuthError;
+}(AuthError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * @hidden
+ */
+var StringUtils = /** @class */ (function () {
+ function StringUtils() {
+ }
+ /**
+ * decode a JWT
+ *
+ * @param authToken
+ */
+ StringUtils.decodeAuthToken = function (authToken) {
+ if (StringUtils.isEmpty(authToken)) {
+ throw ClientAuthError.createTokenNullOrEmptyError(authToken);
+ }
+ var tokenPartsRegex = /^([^\.\s]*)\.([^\.\s]+)\.([^\.\s]*)$/;
+ var matches = tokenPartsRegex.exec(authToken);
+ if (!matches || matches.length < 4) {
+ throw ClientAuthError.createTokenParsingError("Given token is malformed: " + JSON.stringify(authToken));
+ }
+ var crackedToken = {
+ header: matches[1],
+ JWSPayload: matches[2],
+ JWSSig: matches[3]
+ };
+ return crackedToken;
+ };
+ /**
+ * Check if a string is empty.
+ *
+ * @param str
+ */
+ StringUtils.isEmpty = function (str) {
+ return (typeof str === "undefined" || !str || 0 === str.length);
+ };
+ StringUtils.startsWith = function (str, search) {
+ return str.indexOf(search) === 0;
+ };
+ StringUtils.endsWith = function (str, search) {
+ return (str.length >= search.length) && (str.lastIndexOf(search) === (str.length - search.length));
+ };
+ /**
+ * Parses string into an object.
+ *
+ * @param query
+ */
+ StringUtils.queryStringToObject = function (query) {
+ var match; // Regex for replacing addition symbol with a space
+ var pl = /\+/g;
+ var search = /([^&=]+)=([^&]*)/g;
+ var decode = function (s) { return decodeURIComponent(decodeURIComponent(s.replace(pl, " "))); };
+ var obj = {};
+ match = search.exec(query);
+ while (match) {
+ obj[decode(match[1])] = decode(match[2]);
+ match = search.exec(query);
+ }
+ return obj;
+ };
+ /**
+ * Trims entries in an array.
+ *
+ * @param arr
+ */
+ StringUtils.trimArrayEntries = function (arr) {
+ return arr.map(function (entry) { return entry.trim(); });
+ };
+ /**
+ * Removes empty strings from array
+ * @param arr
+ */
+ StringUtils.removeEmptyStringsFromArray = function (arr) {
+ return arr.filter(function (entry) {
+ return !StringUtils.isEmpty(entry);
+ });
+ };
+ /**
+ * Attempts to parse a string into JSON
+ * @param str
+ */
+ StringUtils.jsonParseHelper = function (str) {
+ try {
+ return JSON.parse(str);
+ }
+ catch (e) {
+ return null;
+ }
+ };
+ /**
+ * Tests if a given string matches a given pattern, with support for wildcards.
+ * @param pattern Wildcard pattern to string match. Supports "*" for wildcards
+ * @param input String to match against
+ */
+ StringUtils.matchPattern = function (pattern, input) {
+ // https://stackoverflow.com/a/3117248/4888559
+ var regex = new RegExp(pattern.replace(/\*/g, "[^ ]*"));
+ return regex.test(input);
+ };
+ return StringUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Log message level.
+ */
+var LogLevel;
+(function (LogLevel) {
+ LogLevel[LogLevel["Error"] = 0] = "Error";
+ LogLevel[LogLevel["Warning"] = 1] = "Warning";
+ LogLevel[LogLevel["Info"] = 2] = "Info";
+ LogLevel[LogLevel["Verbose"] = 3] = "Verbose";
+})(LogLevel || (LogLevel = {}));
+/**
+ * Class which facilitates logging of messages to a specific place.
+ */
+var Logger = /** @class */ (function () {
+ function Logger(loggerOptions, packageName, packageVersion) {
+ // Current log level, defaults to info.
+ this.level = LogLevel.Info;
+ var defaultLoggerCallback = function () { };
+ this.localCallback = loggerOptions.loggerCallback || defaultLoggerCallback;
+ this.piiLoggingEnabled = loggerOptions.piiLoggingEnabled || false;
+ this.level = loggerOptions.logLevel || LogLevel.Info;
+ this.packageName = packageName || Constants.EMPTY_STRING;
+ this.packageVersion = packageVersion || Constants.EMPTY_STRING;
+ }
+ /**
+ * Create new Logger with existing configurations.
+ */
+ Logger.prototype.clone = function (packageName, packageVersion) {
+ return new Logger({ loggerCallback: this.localCallback, piiLoggingEnabled: this.piiLoggingEnabled, logLevel: this.level }, packageName, packageVersion);
+ };
+ /**
+ * Log message with required options.
+ */
+ Logger.prototype.logMessage = function (logMessage, options) {
+ if ((options.logLevel > this.level) || (!this.piiLoggingEnabled && options.containsPii)) {
+ return;
+ }
+ var timestamp = new Date().toUTCString();
+ var logHeader = StringUtils.isEmpty(this.correlationId) ? "[" + timestamp + "] : " : "[" + timestamp + "] : [" + this.correlationId + "]";
+ var log = logHeader + " : " + this.packageName + "@" + this.packageVersion + " : " + LogLevel[options.logLevel] + " - " + logMessage;
+ // debug(`msal:${LogLevel[options.logLevel]}${options.containsPii ? "-Pii": ""}${options.context ? `:${options.context}` : ""}`)(logMessage);
+ this.executeCallback(options.logLevel, log, options.containsPii || false);
+ };
+ /**
+ * Execute callback with message.
+ */
+ Logger.prototype.executeCallback = function (level, message, containsPii) {
+ if (this.localCallback) {
+ this.localCallback(level, message, containsPii);
+ }
+ };
+ /**
+ * Logs error messages.
+ */
+ Logger.prototype.error = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Error,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs error messages with PII.
+ */
+ Logger.prototype.errorPii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Error,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs warning messages.
+ */
+ Logger.prototype.warning = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Warning,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs warning messages with PII.
+ */
+ Logger.prototype.warningPii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Warning,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs info messages.
+ */
+ Logger.prototype.info = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Info,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs info messages with PII.
+ */
+ Logger.prototype.infoPii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Info,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs verbose messages.
+ */
+ Logger.prototype.verbose = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Verbose,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs verbose messages with PII.
+ */
+ Logger.prototype.verbosePii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: LogLevel.Verbose,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Returns whether PII Logging is enabled or not.
+ */
+ Logger.prototype.isPiiLoggingEnabled = function () {
+ return this.piiLoggingEnabled || false;
+ };
+ return Logger;
+}());
+
+/* eslint-disable header/header */
+var name = "@azure/msal-common";
+var version = "4.0.1";
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Base type for credentials to be stored in the cache: eg: ACCESS_TOKEN, ID_TOKEN etc
+ *
+ * Key:Value Schema:
+ *
+ * Key: -----
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, usually only used for refresh tokens
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * oboAssertion: access token passed in as part of OBO request
+ * }
+ */
+var CredentialEntity = /** @class */ (function () {
+ function CredentialEntity() {
+ }
+ /**
+ * Generate Account Id key component as per the schema: -
+ */
+ CredentialEntity.prototype.generateAccountId = function () {
+ return CredentialEntity.generateAccountIdForCacheKey(this.homeAccountId, this.environment);
+ };
+ /**
+ * Generate Credential Id key component as per the schema: --
+ */
+ CredentialEntity.prototype.generateCredentialId = function () {
+ return CredentialEntity.generateCredentialIdForCacheKey(this.credentialType, this.clientId, this.realm, this.familyId);
+ };
+ /**
+ * Generate target key component as per schema:
+ */
+ CredentialEntity.prototype.generateTarget = function () {
+ return CredentialEntity.generateTargetForCacheKey(this.target);
+ };
+ /**
+ * generates credential key
+ */
+ CredentialEntity.prototype.generateCredentialKey = function () {
+ return CredentialEntity.generateCredentialCacheKey(this.homeAccountId, this.environment, this.credentialType, this.clientId, this.realm, this.target, this.familyId);
+ };
+ /**
+ * returns the type of the cache (in this case credential)
+ */
+ CredentialEntity.prototype.generateType = function () {
+ switch (this.credentialType) {
+ case CredentialType.ID_TOKEN:
+ return CacheType.ID_TOKEN;
+ case CredentialType.ACCESS_TOKEN:
+ return CacheType.ACCESS_TOKEN;
+ case CredentialType.REFRESH_TOKEN:
+ return CacheType.REFRESH_TOKEN;
+ default: {
+ throw ClientAuthError.createUnexpectedCredentialTypeError();
+ }
+ }
+ };
+ /**
+ * helper function to return `CredentialType`
+ * @param key
+ */
+ CredentialEntity.getCredentialType = function (key) {
+ if (key.indexOf(CredentialType.ACCESS_TOKEN.toLowerCase()) !== -1) {
+ return CredentialType.ACCESS_TOKEN;
+ }
+ else if (key.indexOf(CredentialType.ID_TOKEN.toLowerCase()) !== -1) {
+ return CredentialType.ID_TOKEN;
+ }
+ else if (key.indexOf(CredentialType.REFRESH_TOKEN.toLowerCase()) !== -1) {
+ return CredentialType.REFRESH_TOKEN;
+ }
+ return Constants.NOT_DEFINED;
+ };
+ /**
+ * generates credential key
+ */
+ CredentialEntity.generateCredentialCacheKey = function (homeAccountId, environment, credentialType, clientId, realm, target, familyId) {
+ var credentialKey = [
+ this.generateAccountIdForCacheKey(homeAccountId, environment),
+ this.generateCredentialIdForCacheKey(credentialType, clientId, realm, familyId),
+ this.generateTargetForCacheKey(target),
+ ];
+ return credentialKey.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * generates Account Id for keys
+ * @param homeAccountId
+ * @param environment
+ */
+ CredentialEntity.generateAccountIdForCacheKey = function (homeAccountId, environment) {
+ var accountId = [homeAccountId, environment];
+ return accountId.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Generates Credential Id for keys
+ * @param credentialType
+ * @param realm
+ * @param clientId
+ * @param familyId
+ */
+ CredentialEntity.generateCredentialIdForCacheKey = function (credentialType, clientId, realm, familyId) {
+ var clientOrFamilyId = credentialType === CredentialType.REFRESH_TOKEN
+ ? familyId || clientId
+ : clientId;
+ var credentialId = [
+ credentialType,
+ clientOrFamilyId,
+ realm || "",
+ ];
+ return credentialId.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Generate target key component as per schema:
+ */
+ CredentialEntity.generateTargetForCacheKey = function (scopes) {
+ return (scopes || "").toLowerCase();
+ };
+ return CredentialEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ClientConfigurationErrorMessage class containing string constants used by error codes and messages.
+ */
+var ClientConfigurationErrorMessage = {
+ redirectUriNotSet: {
+ code: "redirect_uri_empty",
+ desc: "A redirect URI is required for all calls, and none has been set."
+ },
+ postLogoutUriNotSet: {
+ code: "post_logout_uri_empty",
+ desc: "A post logout redirect has not been set."
+ },
+ claimsRequestParsingError: {
+ code: "claims_request_parsing_error",
+ desc: "Could not parse the given claims request object."
+ },
+ authorityUriInsecure: {
+ code: "authority_uri_insecure",
+ desc: "Authority URIs must use https. Please see here for valid authority configuration options: https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-js-initializing-client-applications#configuration-options"
+ },
+ urlParseError: {
+ code: "url_parse_error",
+ desc: "URL could not be parsed into appropriate segments."
+ },
+ urlEmptyError: {
+ code: "empty_url_error",
+ desc: "URL was empty or null."
+ },
+ emptyScopesError: {
+ code: "empty_input_scopes_error",
+ desc: "Scopes cannot be passed as null, undefined or empty array because they are required to obtain an access token."
+ },
+ nonArrayScopesError: {
+ code: "nonarray_input_scopes_error",
+ desc: "Scopes cannot be passed as non-array."
+ },
+ clientIdSingleScopeError: {
+ code: "clientid_input_scopes_error",
+ desc: "Client ID can only be provided as a single scope."
+ },
+ invalidPrompt: {
+ code: "invalid_prompt_value",
+ desc: "Supported prompt values are 'login', 'select_account', 'consent' and 'none'. Please see here for valid configuration options: https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-js-initializing-client-applications#configuration-options",
+ },
+ invalidClaimsRequest: {
+ code: "invalid_claims",
+ desc: "Given claims parameter must be a stringified JSON object."
+ },
+ tokenRequestEmptyError: {
+ code: "token_request_empty",
+ desc: "Token request was empty and not found in cache."
+ },
+ logoutRequestEmptyError: {
+ code: "logout_request_empty",
+ desc: "The logout request was null or undefined."
+ },
+ invalidCodeChallengeMethod: {
+ code: "invalid_code_challenge_method",
+ desc: "code_challenge_method passed is invalid. Valid values are \"plain\" and \"S256\"."
+ },
+ invalidCodeChallengeParams: {
+ code: "pkce_params_missing",
+ desc: "Both params: code_challenge and code_challenge_method are to be passed if to be sent in the request"
+ },
+ invalidCloudDiscoveryMetadata: {
+ code: "invalid_cloud_discovery_metadata",
+ desc: "Invalid cloudDiscoveryMetadata provided. Must be a JSON object containing tenant_discovery_endpoint and metadata fields"
+ },
+ invalidAuthorityMetadata: {
+ code: "invalid_authority_metadata",
+ desc: "Invalid authorityMetadata provided. Must by a JSON object containing authorization_endpoint, token_endpoint, end_session_endpoint, issuer fields."
+ },
+ untrustedAuthority: {
+ code: "untrusted_authority",
+ desc: "The provided authority is not a trusted authority. Please include this authority in the knownAuthorities config parameter."
+ },
+ resourceRequestParametersRequired: {
+ code: "resourceRequest_parameters_required",
+ desc: "resourceRequestMethod and resourceRequestUri are required"
+ }
+};
+/**
+ * Error thrown when there is an error in configuration of the MSAL.js library.
+ */
+var ClientConfigurationError = /** @class */ (function (_super) {
+ __extends(ClientConfigurationError, _super);
+ function ClientConfigurationError(errorCode, errorMessage) {
+ var _this = _super.call(this, errorCode, errorMessage) || this;
+ _this.name = "ClientConfigurationError";
+ Object.setPrototypeOf(_this, ClientConfigurationError.prototype);
+ return _this;
+ }
+ /**
+ * Creates an error thrown when the redirect uri is empty (not set by caller)
+ */
+ ClientConfigurationError.createRedirectUriEmptyError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.redirectUriNotSet.code, ClientConfigurationErrorMessage.redirectUriNotSet.desc);
+ };
+ /**
+ * Creates an error thrown when the post-logout redirect uri is empty (not set by caller)
+ */
+ ClientConfigurationError.createPostLogoutRedirectUriEmptyError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.postLogoutUriNotSet.code, ClientConfigurationErrorMessage.postLogoutUriNotSet.desc);
+ };
+ /**
+ * Creates an error thrown when the claims request could not be successfully parsed
+ */
+ ClientConfigurationError.createClaimsRequestParsingError = function (claimsRequestParseError) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.claimsRequestParsingError.code, ClientConfigurationErrorMessage.claimsRequestParsingError.desc + " Given value: " + claimsRequestParseError);
+ };
+ /**
+ * Creates an error thrown if authority uri is given an insecure protocol.
+ * @param urlString
+ */
+ ClientConfigurationError.createInsecureAuthorityUriError = function (urlString) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.authorityUriInsecure.code, ClientConfigurationErrorMessage.authorityUriInsecure.desc + " Given URI: " + urlString);
+ };
+ /**
+ * Creates an error thrown if URL string does not parse into separate segments.
+ * @param urlString
+ */
+ ClientConfigurationError.createUrlParseError = function (urlParseError) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.urlParseError.code, ClientConfigurationErrorMessage.urlParseError.desc + " Given Error: " + urlParseError);
+ };
+ /**
+ * Creates an error thrown if URL string is empty or null.
+ * @param urlString
+ */
+ ClientConfigurationError.createUrlEmptyError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.urlEmptyError.code, ClientConfigurationErrorMessage.urlEmptyError.desc);
+ };
+ /**
+ * Error thrown when scopes are not an array
+ * @param inputScopes
+ */
+ ClientConfigurationError.createScopesNonArrayError = function (inputScopes) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.nonArrayScopesError.code, ClientConfigurationErrorMessage.nonArrayScopesError.desc + " Given Scopes: " + inputScopes);
+ };
+ /**
+ * Error thrown when scopes are empty.
+ * @param scopesValue
+ */
+ ClientConfigurationError.createEmptyScopesArrayError = function (inputScopes) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.emptyScopesError.code, ClientConfigurationErrorMessage.emptyScopesError.desc + " Given Scopes: " + inputScopes);
+ };
+ /**
+ * Error thrown when client id scope is not provided as single scope.
+ * @param inputScopes
+ */
+ ClientConfigurationError.createClientIdSingleScopeError = function (inputScopes) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.clientIdSingleScopeError.code, ClientConfigurationErrorMessage.clientIdSingleScopeError.desc + " Given Scopes: " + inputScopes);
+ };
+ /**
+ * Error thrown when prompt is not an allowed type.
+ * @param promptValue
+ */
+ ClientConfigurationError.createInvalidPromptError = function (promptValue) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidPrompt.code, ClientConfigurationErrorMessage.invalidPrompt.desc + " Given value: " + promptValue);
+ };
+ /**
+ * Creates error thrown when claims parameter is not a stringified JSON object
+ */
+ ClientConfigurationError.createInvalidClaimsRequestError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidClaimsRequest.code, ClientConfigurationErrorMessage.invalidClaimsRequest.desc);
+ };
+ /**
+ * Throws error when token request is empty and nothing cached in storage.
+ */
+ ClientConfigurationError.createEmptyLogoutRequestError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.logoutRequestEmptyError.code, ClientConfigurationErrorMessage.logoutRequestEmptyError.desc);
+ };
+ /**
+ * Throws error when token request is empty and nothing cached in storage.
+ */
+ ClientConfigurationError.createEmptyTokenRequestError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.tokenRequestEmptyError.code, ClientConfigurationErrorMessage.tokenRequestEmptyError.desc);
+ };
+ /**
+ * Throws error when an invalid code_challenge_method is passed by the user
+ */
+ ClientConfigurationError.createInvalidCodeChallengeMethodError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidCodeChallengeMethod.code, ClientConfigurationErrorMessage.invalidCodeChallengeMethod.desc);
+ };
+ /**
+ * Throws error when both params: code_challenge and code_challenge_method are not passed together
+ */
+ ClientConfigurationError.createInvalidCodeChallengeParamsError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidCodeChallengeParams.code, ClientConfigurationErrorMessage.invalidCodeChallengeParams.desc);
+ };
+ /**
+ * Throws an error when the user passes invalid cloudDiscoveryMetadata
+ */
+ ClientConfigurationError.createInvalidCloudDiscoveryMetadataError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidCloudDiscoveryMetadata.code, ClientConfigurationErrorMessage.invalidCloudDiscoveryMetadata.desc);
+ };
+ /**
+ * Throws an error when the user passes invalid cloudDiscoveryMetadata
+ */
+ ClientConfigurationError.createInvalidAuthorityMetadataError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidAuthorityMetadata.code, ClientConfigurationErrorMessage.invalidAuthorityMetadata.desc);
+ };
+ /**
+ * Throws error when provided authority is not a member of the trusted host list
+ */
+ ClientConfigurationError.createUntrustedAuthorityError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.untrustedAuthority.code, ClientConfigurationErrorMessage.untrustedAuthority.desc);
+ };
+ /**
+ * Throws error when resourceRequestMethod or resourceRequestUri is missing
+ */
+ ClientConfigurationError.createResourceRequestParametersRequiredError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.resourceRequestParametersRequired.code, ClientConfigurationErrorMessage.resourceRequestParametersRequired.desc);
+ };
+ return ClientConfigurationError;
+}(ClientAuthError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * The ScopeSet class creates a set of scopes. Scopes are case-insensitive, unique values, so the Set object in JS makes
+ * the most sense to implement for this class. All scopes are trimmed and converted to lower case strings in intersection and union functions
+ * to ensure uniqueness of strings.
+ */
+var ScopeSet = /** @class */ (function () {
+ function ScopeSet(inputScopes) {
+ var _this = this;
+ // Filter empty string and null/undefined array items
+ var scopeArr = inputScopes ? StringUtils.trimArrayEntries(__spreadArrays(inputScopes)) : [];
+ var filteredInput = scopeArr ? StringUtils.removeEmptyStringsFromArray(scopeArr) : [];
+ // Validate and filter scopes (validate function throws if validation fails)
+ this.validateInputScopes(filteredInput);
+ this.scopes = new Set(); // Iterator in constructor not supported by IE11
+ filteredInput.forEach(function (scope) { return _this.scopes.add(scope); });
+ }
+ /**
+ * Factory method to create ScopeSet from space-delimited string
+ * @param inputScopeString
+ * @param appClientId
+ * @param scopesRequired
+ */
+ ScopeSet.fromString = function (inputScopeString) {
+ inputScopeString = inputScopeString || "";
+ var inputScopes = inputScopeString.split(" ");
+ return new ScopeSet(inputScopes);
+ };
+ /**
+ * Used to validate the scopes input parameter requested by the developer.
+ * @param {Array} inputScopes - Developer requested permissions. Not all scopes are guaranteed to be included in the access token returned.
+ * @param {boolean} scopesRequired - Boolean indicating whether the scopes array is required or not
+ */
+ ScopeSet.prototype.validateInputScopes = function (inputScopes) {
+ // Check if scopes are required but not given or is an empty array
+ if (!inputScopes || inputScopes.length < 1) {
+ throw ClientConfigurationError.createEmptyScopesArrayError(inputScopes);
+ }
+ };
+ /**
+ * Check if a given scope is present in this set of scopes.
+ * @param scope
+ */
+ ScopeSet.prototype.containsScope = function (scope) {
+ var lowerCaseScopes = this.printScopesLowerCase().split(" ");
+ var lowerCaseScopesSet = new ScopeSet(lowerCaseScopes);
+ // compare lowercase scopes
+ return !StringUtils.isEmpty(scope) ? lowerCaseScopesSet.scopes.has(scope.toLowerCase()) : false;
+ };
+ /**
+ * Check if a set of scopes is present in this set of scopes.
+ * @param scopeSet
+ */
+ ScopeSet.prototype.containsScopeSet = function (scopeSet) {
+ var _this = this;
+ if (!scopeSet || scopeSet.scopes.size <= 0) {
+ return false;
+ }
+ return (this.scopes.size >= scopeSet.scopes.size && scopeSet.asArray().every(function (scope) { return _this.containsScope(scope); }));
+ };
+ /**
+ * Check if set of scopes contains only the defaults
+ */
+ ScopeSet.prototype.containsOnlyOIDCScopes = function () {
+ var _this = this;
+ var defaultScopeCount = 0;
+ OIDC_SCOPES.forEach(function (defaultScope) {
+ if (_this.containsScope(defaultScope)) {
+ defaultScopeCount += 1;
+ }
+ });
+ return this.scopes.size === defaultScopeCount;
+ };
+ /**
+ * Appends single scope if passed
+ * @param newScope
+ */
+ ScopeSet.prototype.appendScope = function (newScope) {
+ if (!StringUtils.isEmpty(newScope)) {
+ this.scopes.add(newScope.trim());
+ }
+ };
+ /**
+ * Appends multiple scopes if passed
+ * @param newScopes
+ */
+ ScopeSet.prototype.appendScopes = function (newScopes) {
+ var _this = this;
+ try {
+ newScopes.forEach(function (newScope) { return _this.appendScope(newScope); });
+ }
+ catch (e) {
+ throw ClientAuthError.createAppendScopeSetError(e);
+ }
+ };
+ /**
+ * Removes element from set of scopes.
+ * @param scope
+ */
+ ScopeSet.prototype.removeScope = function (scope) {
+ if (StringUtils.isEmpty(scope)) {
+ throw ClientAuthError.createRemoveEmptyScopeFromSetError(scope);
+ }
+ this.scopes.delete(scope.trim());
+ };
+ /**
+ * Removes default scopes from set of scopes
+ * Primarily used to prevent cache misses if the default scopes are not returned from the server
+ */
+ ScopeSet.prototype.removeOIDCScopes = function () {
+ var _this = this;
+ OIDC_SCOPES.forEach(function (defaultScope) {
+ _this.scopes.delete(defaultScope);
+ });
+ };
+ /**
+ * Combines an array of scopes with the current set of scopes.
+ * @param otherScopes
+ */
+ ScopeSet.prototype.unionScopeSets = function (otherScopes) {
+ if (!otherScopes) {
+ throw ClientAuthError.createEmptyInputScopeSetError(otherScopes);
+ }
+ var unionScopes = new Set(); // Iterator in constructor not supported in IE11
+ otherScopes.scopes.forEach(function (scope) { return unionScopes.add(scope.toLowerCase()); });
+ this.scopes.forEach(function (scope) { return unionScopes.add(scope.toLowerCase()); });
+ return unionScopes;
+ };
+ /**
+ * Check if scopes intersect between this set and another.
+ * @param otherScopes
+ */
+ ScopeSet.prototype.intersectingScopeSets = function (otherScopes) {
+ if (!otherScopes) {
+ throw ClientAuthError.createEmptyInputScopeSetError(otherScopes);
+ }
+ // Do not allow OIDC scopes to be the only intersecting scopes
+ if (!otherScopes.containsOnlyOIDCScopes()) {
+ otherScopes.removeOIDCScopes();
+ }
+ var unionScopes = this.unionScopeSets(otherScopes);
+ var sizeOtherScopes = otherScopes.getScopeCount();
+ var sizeThisScopes = this.getScopeCount();
+ var sizeUnionScopes = unionScopes.size;
+ return sizeUnionScopes < (sizeThisScopes + sizeOtherScopes);
+ };
+ /**
+ * Returns size of set of scopes.
+ */
+ ScopeSet.prototype.getScopeCount = function () {
+ return this.scopes.size;
+ };
+ /**
+ * Returns the scopes as an array of string values
+ */
+ ScopeSet.prototype.asArray = function () {
+ var array = [];
+ this.scopes.forEach(function (val) { return array.push(val); });
+ return array;
+ };
+ /**
+ * Prints scopes into a space-delimited string
+ */
+ ScopeSet.prototype.printScopes = function () {
+ if (this.scopes) {
+ var scopeArr = this.asArray();
+ return scopeArr.join(" ");
+ }
+ return "";
+ };
+ /**
+ * Prints scopes into a space-delimited lower-case string (used for caching)
+ */
+ ScopeSet.prototype.printScopesLowerCase = function () {
+ return this.printScopes().toLowerCase();
+ };
+ return ScopeSet;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Function to build a client info object
+ * @param rawClientInfo
+ * @param crypto
+ */
+function buildClientInfo(rawClientInfo, crypto) {
+ if (StringUtils.isEmpty(rawClientInfo)) {
+ throw ClientAuthError.createClientInfoEmptyError();
+ }
+ try {
+ var decodedClientInfo = crypto.base64Decode(rawClientInfo);
+ return JSON.parse(decodedClientInfo);
+ }
+ catch (e) {
+ throw ClientAuthError.createClientInfoDecodingError(e);
+ }
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Authority types supported by MSAL.
+ */
+var AuthorityType;
+(function (AuthorityType) {
+ AuthorityType[AuthorityType["Default"] = 0] = "Default";
+ AuthorityType[AuthorityType["Adfs"] = 1] = "Adfs";
+})(AuthorityType || (AuthorityType = {}));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Type that defines required and optional parameters for an Account field (based on universal cache schema implemented by all MSALs).
+ *
+ * Key : Value Schema
+ *
+ * Key: --
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * localAccountId: Original tenant-specific accountID, usually used for legacy cases
+ * username: primary username that represents the user, usually corresponds to preferred_username in the v2 endpt
+ * authorityType: Accounts authority type as a string
+ * name: Full name for the account, including given name and family name,
+ * clientInfo: Full base64 encoded client info received from ESTS
+ * lastModificationTime: last time this entity was modified in the cache
+ * lastModificationApp:
+ * oboAssertion: access token passed in as part of OBO request
+ * idTokenClaims: Object containing claims parsed from ID token
+ * }
+ */
+var AccountEntity = /** @class */ (function () {
+ function AccountEntity() {
+ }
+ /**
+ * Generate Account Id key component as per the schema: -
+ */
+ AccountEntity.prototype.generateAccountId = function () {
+ var accountId = [this.homeAccountId, this.environment];
+ return accountId.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Generate Account Cache Key as per the schema: --
+ */
+ AccountEntity.prototype.generateAccountKey = function () {
+ return AccountEntity.generateAccountCacheKey({
+ homeAccountId: this.homeAccountId,
+ environment: this.environment,
+ tenantId: this.realm,
+ username: this.username,
+ localAccountId: this.localAccountId
+ });
+ };
+ /**
+ * returns the type of the cache (in this case account)
+ */
+ AccountEntity.prototype.generateType = function () {
+ switch (this.authorityType) {
+ case CacheAccountType.ADFS_ACCOUNT_TYPE:
+ return CacheType.ADFS;
+ case CacheAccountType.MSAV1_ACCOUNT_TYPE:
+ return CacheType.MSA;
+ case CacheAccountType.MSSTS_ACCOUNT_TYPE:
+ return CacheType.MSSTS;
+ case CacheAccountType.GENERIC_ACCOUNT_TYPE:
+ return CacheType.GENERIC;
+ default: {
+ throw ClientAuthError.createUnexpectedAccountTypeError();
+ }
+ }
+ };
+ /**
+ * Returns the AccountInfo interface for this account.
+ */
+ AccountEntity.prototype.getAccountInfo = function () {
+ return {
+ homeAccountId: this.homeAccountId,
+ environment: this.environment,
+ tenantId: this.realm,
+ username: this.username,
+ localAccountId: this.localAccountId,
+ name: this.name,
+ idTokenClaims: this.idTokenClaims
+ };
+ };
+ /**
+ * Generates account key from interface
+ * @param accountInterface
+ */
+ AccountEntity.generateAccountCacheKey = function (accountInterface) {
+ var accountKey = [
+ accountInterface.homeAccountId,
+ accountInterface.environment || "",
+ accountInterface.tenantId || "",
+ ];
+ return accountKey.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Build Account cache from IdToken, clientInfo and authority/policy. Associated with AAD.
+ * @param clientInfo
+ * @param authority
+ * @param idToken
+ * @param policy
+ */
+ AccountEntity.createAccount = function (clientInfo, homeAccountId, authority, idToken, oboAssertion, cloudGraphHostName, msGraphHost) {
+ var _a, _b, _c, _d, _e, _f;
+ var account = new AccountEntity();
+ account.authorityType = CacheAccountType.MSSTS_ACCOUNT_TYPE;
+ account.clientInfo = clientInfo;
+ account.homeAccountId = homeAccountId;
+ var env = authority.getPreferredCache();
+ if (StringUtils.isEmpty(env)) {
+ throw ClientAuthError.createInvalidCacheEnvironmentError();
+ }
+ account.environment = env;
+ // non AAD scenarios can have empty realm
+ account.realm = ((_a = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _a === void 0 ? void 0 : _a.tid) || "";
+ account.oboAssertion = oboAssertion;
+ if (idToken) {
+ account.idTokenClaims = idToken.claims;
+ // How do you account for MSA CID here?
+ account.localAccountId = ((_b = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _b === void 0 ? void 0 : _b.oid) || ((_c = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _c === void 0 ? void 0 : _c.sub) || "";
+ /*
+ * In B2C scenarios the emails claim is used instead of preferred_username and it is an array. In most cases it will contain a single email.
+ * This field should not be relied upon if a custom policy is configured to return more than 1 email.
+ */
+ account.username = ((_d = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _d === void 0 ? void 0 : _d.preferred_username) || (((_e = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _e === void 0 ? void 0 : _e.emails) ? idToken.claims.emails[0] : "");
+ account.name = (_f = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _f === void 0 ? void 0 : _f.name;
+ }
+ account.cloudGraphHostName = cloudGraphHostName;
+ account.msGraphHost = msGraphHost;
+ return account;
+ };
+ /**
+ * Builds non-AAD/ADFS account.
+ * @param authority
+ * @param idToken
+ */
+ AccountEntity.createGenericAccount = function (authority, homeAccountId, idToken, oboAssertion, cloudGraphHostName, msGraphHost) {
+ var _a, _b, _c, _d;
+ var account = new AccountEntity();
+ account.authorityType = (authority.authorityType === AuthorityType.Adfs) ? CacheAccountType.ADFS_ACCOUNT_TYPE : CacheAccountType.GENERIC_ACCOUNT_TYPE;
+ account.homeAccountId = homeAccountId;
+ // non AAD scenarios can have empty realm
+ account.realm = "";
+ account.oboAssertion = oboAssertion;
+ var env = authority.getPreferredCache();
+ if (StringUtils.isEmpty(env)) {
+ throw ClientAuthError.createInvalidCacheEnvironmentError();
+ }
+ if (idToken) {
+ // How do you account for MSA CID here?
+ account.localAccountId = ((_a = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _a === void 0 ? void 0 : _a.oid) || ((_b = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _b === void 0 ? void 0 : _b.sub) || "";
+ // upn claim for most ADFS scenarios
+ account.username = ((_c = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _c === void 0 ? void 0 : _c.upn) || "";
+ account.name = ((_d = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _d === void 0 ? void 0 : _d.name) || "";
+ account.idTokenClaims = idToken === null || idToken === void 0 ? void 0 : idToken.claims;
+ }
+ account.environment = env;
+ account.cloudGraphHostName = cloudGraphHostName;
+ account.msGraphHost = msGraphHost;
+ /*
+ * add uniqueName to claims
+ * account.name = idToken.claims.uniqueName;
+ */
+ return account;
+ };
+ /**
+ * Generate HomeAccountId from server response
+ * @param serverClientInfo
+ * @param authType
+ */
+ AccountEntity.generateHomeAccountId = function (serverClientInfo, authType, logger, cryptoObj, idToken) {
+ var _a;
+ var accountId = ((_a = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _a === void 0 ? void 0 : _a.sub) ? idToken.claims.sub : Constants.EMPTY_STRING;
+ // since ADFS does not have tid and does not set client_info
+ if (authType === AuthorityType.Adfs) {
+ return accountId;
+ }
+ // for cases where there is clientInfo
+ if (serverClientInfo) {
+ var clientInfo = buildClientInfo(serverClientInfo, cryptoObj);
+ if (!StringUtils.isEmpty(clientInfo.uid) && !StringUtils.isEmpty(clientInfo.utid)) {
+ return "" + clientInfo.uid + Separators.CLIENT_INFO_SEPARATOR + clientInfo.utid;
+ }
+ }
+ // default to "sub" claim
+ logger.verbose("No client info in response");
+ return accountId;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AccountEntity.isAccountEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("realm") &&
+ entity.hasOwnProperty("localAccountId") &&
+ entity.hasOwnProperty("username") &&
+ entity.hasOwnProperty("authorityType"));
+ };
+ /**
+ * Helper function to determine whether 2 accounts are equal
+ * Used to avoid unnecessary state updates
+ * @param arrayA
+ * @param arrayB
+ */
+ AccountEntity.accountInfoIsEqual = function (accountA, accountB) {
+ if (!accountA || !accountB) {
+ return false;
+ }
+ return (accountA.homeAccountId === accountB.homeAccountId) &&
+ (accountA.localAccountId === accountB.localAccountId) &&
+ (accountA.username === accountB.username) &&
+ (accountA.tenantId === accountB.tenantId) &&
+ (accountA.environment === accountB.environment);
+ };
+ return AccountEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * JWT Token representation class. Parses token string and generates claims object.
+ */
+var AuthToken = /** @class */ (function () {
+ function AuthToken(rawToken, crypto) {
+ if (StringUtils.isEmpty(rawToken)) {
+ throw ClientAuthError.createTokenNullOrEmptyError(rawToken);
+ }
+ this.rawToken = rawToken;
+ this.claims = AuthToken.extractTokenClaims(rawToken, crypto);
+ }
+ /**
+ * Extract token by decoding the rawToken
+ *
+ * @param encodedToken
+ */
+ AuthToken.extractTokenClaims = function (encodedToken, crypto) {
+ var decodedToken = StringUtils.decodeAuthToken(encodedToken);
+ // token will be decoded to get the username
+ try {
+ var base64TokenPayload = decodedToken.JWSPayload;
+ // base64Decode() should throw an error if there is an issue
+ var base64Decoded = crypto.base64Decode(base64TokenPayload);
+ return JSON.parse(base64Decoded);
+ }
+ catch (err) {
+ throw ClientAuthError.createTokenParsingError(err);
+ }
+ };
+ return AuthToken;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Interface class which implement cache storage functions used by MSAL to perform validity checks, and store tokens.
+ */
+var CacheManager = /** @class */ (function () {
+ function CacheManager(clientId, cryptoImpl) {
+ this.clientId = clientId;
+ this.cryptoImpl = cryptoImpl;
+ }
+ /**
+ * Returns all accounts in cache
+ */
+ CacheManager.prototype.getAllAccounts = function () {
+ var _this = this;
+ var currentAccounts = this.getAccountsFilteredBy();
+ var accountValues = Object.keys(currentAccounts).map(function (accountKey) { return currentAccounts[accountKey]; });
+ var numAccounts = accountValues.length;
+ if (numAccounts < 1) {
+ return [];
+ }
+ else {
+ var allAccounts = accountValues.map(function (value) {
+ var accountEntity = CacheManager.toObject(new AccountEntity(), value);
+ var accountInfo = accountEntity.getAccountInfo();
+ var idToken = _this.readIdTokenFromCache(_this.clientId, accountInfo);
+ if (idToken && !accountInfo.idTokenClaims) {
+ accountInfo.idTokenClaims = new AuthToken(idToken.secret, _this.cryptoImpl).claims;
+ }
+ return accountInfo;
+ });
+ return allAccounts;
+ }
+ };
+ /**
+ * saves a cache record
+ * @param cacheRecord
+ */
+ CacheManager.prototype.saveCacheRecord = function (cacheRecord) {
+ if (!cacheRecord) {
+ throw ClientAuthError.createNullOrUndefinedCacheRecord();
+ }
+ if (!!cacheRecord.account) {
+ this.setAccount(cacheRecord.account);
+ }
+ if (!!cacheRecord.idToken) {
+ this.setIdTokenCredential(cacheRecord.idToken);
+ }
+ if (!!cacheRecord.accessToken) {
+ this.saveAccessToken(cacheRecord.accessToken);
+ }
+ if (!!cacheRecord.refreshToken) {
+ this.setRefreshTokenCredential(cacheRecord.refreshToken);
+ }
+ if (!!cacheRecord.appMetadata) {
+ this.setAppMetadata(cacheRecord.appMetadata);
+ }
+ };
+ /**
+ * saves access token credential
+ * @param credential
+ */
+ CacheManager.prototype.saveAccessToken = function (credential) {
+ var _this = this;
+ var currentTokenCache = this.getCredentialsFilteredBy({
+ clientId: credential.clientId,
+ credentialType: CredentialType.ACCESS_TOKEN,
+ environment: credential.environment,
+ homeAccountId: credential.homeAccountId,
+ realm: credential.realm,
+ });
+ var currentScopes = ScopeSet.fromString(credential.target);
+ var currentAccessTokens = Object.keys(currentTokenCache.accessTokens).map(function (key) { return currentTokenCache.accessTokens[key]; });
+ if (currentAccessTokens) {
+ currentAccessTokens.forEach(function (tokenEntity) {
+ var tokenScopeSet = ScopeSet.fromString(tokenEntity.target);
+ if (tokenScopeSet.intersectingScopeSets(currentScopes)) {
+ _this.removeCredential(tokenEntity);
+ }
+ });
+ }
+ this.setAccessTokenCredential(credential);
+ };
+ /**
+ * retrieve accounts matching all provided filters; if no filter is set, get all accounts
+ * not checking for casing as keys are all generated in lower case, remember to convert to lower case if object properties are compared
+ * @param homeAccountId
+ * @param environment
+ * @param realm
+ */
+ CacheManager.prototype.getAccountsFilteredBy = function (accountFilter) {
+ return this.getAccountsFilteredByInternal(accountFilter ? accountFilter.homeAccountId : "", accountFilter ? accountFilter.environment : "", accountFilter ? accountFilter.realm : "");
+ };
+ /**
+ * retrieve accounts matching all provided filters; if no filter is set, get all accounts
+ * not checking for casing as keys are all generated in lower case, remember to convert to lower case if object properties are compared
+ * @param homeAccountId
+ * @param environment
+ * @param realm
+ */
+ CacheManager.prototype.getAccountsFilteredByInternal = function (homeAccountId, environment, realm) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var matchingAccounts = {};
+ allCacheKeys.forEach(function (cacheKey) {
+ var entity = _this.getAccount(cacheKey);
+ if (!entity) {
+ return;
+ }
+ if (!!homeAccountId && !_this.matchHomeAccountId(entity, homeAccountId)) {
+ return;
+ }
+ if (!!environment && !_this.matchEnvironment(entity, environment)) {
+ return;
+ }
+ if (!!realm && !_this.matchRealm(entity, realm)) {
+ return;
+ }
+ matchingAccounts[cacheKey] = entity;
+ });
+ return matchingAccounts;
+ };
+ /**
+ * retrieve credentails matching all provided filters; if no filter is set, get all credentials
+ * @param homeAccountId
+ * @param environment
+ * @param credentialType
+ * @param clientId
+ * @param realm
+ * @param target
+ */
+ CacheManager.prototype.getCredentialsFilteredBy = function (filter) {
+ return this.getCredentialsFilteredByInternal(filter.homeAccountId, filter.environment, filter.credentialType, filter.clientId, filter.familyId, filter.realm, filter.target, filter.oboAssertion);
+ };
+ /**
+ * Support function to help match credentials
+ * @param homeAccountId
+ * @param environment
+ * @param credentialType
+ * @param clientId
+ * @param realm
+ * @param target
+ */
+ CacheManager.prototype.getCredentialsFilteredByInternal = function (homeAccountId, environment, credentialType, clientId, familyId, realm, target, oboAssertion) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var matchingCredentials = {
+ idTokens: {},
+ accessTokens: {},
+ refreshTokens: {},
+ };
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-credential type cache entities
+ var credType = CredentialEntity.getCredentialType(cacheKey);
+ if (credType === Constants.NOT_DEFINED) {
+ return;
+ }
+ // Attempt retrieval
+ var entity = _this.getSpecificCredential(cacheKey, credType);
+ if (!entity) {
+ return;
+ }
+ if (!!oboAssertion && !_this.matchOboAssertion(entity, oboAssertion)) {
+ return;
+ }
+ if (!!homeAccountId && !_this.matchHomeAccountId(entity, homeAccountId)) {
+ return;
+ }
+ if (!!environment && !_this.matchEnvironment(entity, environment)) {
+ return;
+ }
+ if (!!realm && !_this.matchRealm(entity, realm)) {
+ return;
+ }
+ if (!!credentialType && !_this.matchCredentialType(entity, credentialType)) {
+ return;
+ }
+ if (!!clientId && !_this.matchClientId(entity, clientId)) {
+ return;
+ }
+ if (!!familyId && !_this.matchFamilyId(entity, familyId)) {
+ return;
+ }
+ /*
+ * idTokens do not have "target", target specific refreshTokens do exist for some types of authentication
+ * Resource specific refresh tokens case will be added when the support is deemed necessary
+ */
+ if (!!target && !_this.matchTarget(entity, target)) {
+ return;
+ }
+ switch (credType) {
+ case CredentialType.ID_TOKEN:
+ matchingCredentials.idTokens[cacheKey] = entity;
+ break;
+ case CredentialType.ACCESS_TOKEN:
+ matchingCredentials.accessTokens[cacheKey] = entity;
+ break;
+ case CredentialType.REFRESH_TOKEN:
+ matchingCredentials.refreshTokens[cacheKey] = entity;
+ break;
+ }
+ });
+ return matchingCredentials;
+ };
+ /**
+ * retrieve appMetadata matching all provided filters; if no filter is set, get all appMetadata
+ * @param filter
+ */
+ CacheManager.prototype.getAppMetadataFilteredBy = function (filter) {
+ return this.getAppMetadataFilteredByInternal(filter.environment, filter.clientId);
+ };
+ /**
+ * Support function to help match appMetadata
+ * @param environment
+ * @param clientId
+ */
+ CacheManager.prototype.getAppMetadataFilteredByInternal = function (environment, clientId) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var matchingAppMetadata = {};
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-appMetadata type cache entities
+ if (!_this.isAppMetadata(cacheKey)) {
+ return;
+ }
+ // Attempt retrieval
+ var entity = _this.getAppMetadata(cacheKey);
+ if (!entity) {
+ return;
+ }
+ if (!!environment && !_this.matchEnvironment(entity, environment)) {
+ return;
+ }
+ if (!!clientId && !_this.matchClientId(entity, clientId)) {
+ return;
+ }
+ matchingAppMetadata[cacheKey] = entity;
+ });
+ return matchingAppMetadata;
+ };
+ /**
+ * retrieve authorityMetadata that contains a matching alias
+ * @param filter
+ */
+ CacheManager.prototype.getAuthorityMetadataByAlias = function (host) {
+ var _this = this;
+ var allCacheKeys = this.getAuthorityMetadataKeys();
+ var matchedEntity = null;
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-authorityMetadata type cache entities
+ if (!_this.isAuthorityMetadata(cacheKey) || cacheKey.indexOf(_this.clientId) === -1) {
+ return;
+ }
+ // Attempt retrieval
+ var entity = _this.getAuthorityMetadata(cacheKey);
+ if (!entity) {
+ return;
+ }
+ if (entity.aliases.indexOf(host) === -1) {
+ return;
+ }
+ matchedEntity = entity;
+ });
+ return matchedEntity;
+ };
+ /**
+ * Removes all accounts and related tokens from cache.
+ */
+ CacheManager.prototype.removeAllAccounts = function () {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ allCacheKeys.forEach(function (cacheKey) {
+ var entity = _this.getAccount(cacheKey);
+ if (!entity) {
+ return;
+ }
+ _this.removeAccount(cacheKey);
+ });
+ return true;
+ };
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ CacheManager.prototype.removeAccount = function (accountKey) {
+ var account = this.getAccount(accountKey);
+ if (!account) {
+ throw ClientAuthError.createNoAccountFoundError();
+ }
+ return (this.removeAccountContext(account) && this.removeItem(accountKey, CacheSchemaType.ACCOUNT));
+ };
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ CacheManager.prototype.removeAccountContext = function (account) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var accountId = account.generateAccountId();
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-credential type cache entities
+ var credType = CredentialEntity.getCredentialType(cacheKey);
+ if (credType === Constants.NOT_DEFINED) {
+ return;
+ }
+ var cacheEntity = _this.getSpecificCredential(cacheKey, credType);
+ if (!!cacheEntity && accountId === cacheEntity.generateAccountId()) {
+ _this.removeCredential(cacheEntity);
+ }
+ });
+ return true;
+ };
+ /**
+ * returns a boolean if the given credential is removed
+ * @param credential
+ */
+ CacheManager.prototype.removeCredential = function (credential) {
+ var key = credential.generateCredentialKey();
+ return this.removeItem(key, CacheSchemaType.CREDENTIAL);
+ };
+ /**
+ * Removes all app metadata objects from cache.
+ */
+ CacheManager.prototype.removeAppMetadata = function () {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ allCacheKeys.forEach(function (cacheKey) {
+ if (_this.isAppMetadata(cacheKey)) {
+ _this.removeItem(cacheKey, CacheSchemaType.APP_METADATA);
+ }
+ });
+ return true;
+ };
+ /**
+ * Retrieve the cached credentials into a cacherecord
+ * @param account
+ * @param clientId
+ * @param scopes
+ * @param environment
+ */
+ CacheManager.prototype.readCacheRecord = function (account, clientId, scopes, environment) {
+ var cachedAccount = this.readAccountFromCache(account);
+ var cachedIdToken = this.readIdTokenFromCache(clientId, account);
+ var cachedAccessToken = this.readAccessTokenFromCache(clientId, account, scopes);
+ var cachedRefreshToken = this.readRefreshTokenFromCache(clientId, account, false);
+ var cachedAppMetadata = this.readAppMetadataFromCache(environment, clientId);
+ if (cachedAccount && cachedIdToken) {
+ cachedAccount.idTokenClaims = new AuthToken(cachedIdToken.secret, this.cryptoImpl).claims;
+ }
+ return {
+ account: cachedAccount,
+ idToken: cachedIdToken,
+ accessToken: cachedAccessToken,
+ refreshToken: cachedRefreshToken,
+ appMetadata: cachedAppMetadata,
+ };
+ };
+ /**
+ * Retrieve AccountEntity from cache
+ * @param account
+ */
+ CacheManager.prototype.readAccountFromCache = function (account) {
+ var accountKey = AccountEntity.generateAccountCacheKey(account);
+ return this.getAccount(accountKey);
+ };
+ /**
+ * Retrieve IdTokenEntity from cache
+ * @param clientId
+ * @param account
+ * @param inputRealm
+ */
+ CacheManager.prototype.readIdTokenFromCache = function (clientId, account) {
+ var idTokenFilter = {
+ homeAccountId: account.homeAccountId,
+ environment: account.environment,
+ credentialType: CredentialType.ID_TOKEN,
+ clientId: clientId,
+ realm: account.tenantId,
+ };
+ var credentialCache = this.getCredentialsFilteredBy(idTokenFilter);
+ var idTokens = Object.keys(credentialCache.idTokens).map(function (key) { return credentialCache.idTokens[key]; });
+ var numIdTokens = idTokens.length;
+ if (numIdTokens < 1) {
+ return null;
+ }
+ else if (numIdTokens > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return idTokens[0];
+ };
+ /**
+ * Retrieve AccessTokenEntity from cache
+ * @param clientId
+ * @param account
+ * @param scopes
+ * @param inputRealm
+ */
+ CacheManager.prototype.readAccessTokenFromCache = function (clientId, account, scopes) {
+ var accessTokenFilter = {
+ homeAccountId: account.homeAccountId,
+ environment: account.environment,
+ credentialType: CredentialType.ACCESS_TOKEN,
+ clientId: clientId,
+ realm: account.tenantId,
+ target: scopes.printScopesLowerCase(),
+ };
+ var credentialCache = this.getCredentialsFilteredBy(accessTokenFilter);
+ var accessTokens = Object.keys(credentialCache.accessTokens).map(function (key) { return credentialCache.accessTokens[key]; });
+ var numAccessTokens = accessTokens.length;
+ if (numAccessTokens < 1) {
+ return null;
+ }
+ else if (numAccessTokens > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return accessTokens[0];
+ };
+ /**
+ * Helper to retrieve the appropriate refresh token from cache
+ * @param clientId
+ * @param account
+ * @param familyRT
+ */
+ CacheManager.prototype.readRefreshTokenFromCache = function (clientId, account, familyRT) {
+ var id = familyRT ? THE_FAMILY_ID : undefined;
+ var refreshTokenFilter = {
+ homeAccountId: account.homeAccountId,
+ environment: account.environment,
+ credentialType: CredentialType.REFRESH_TOKEN,
+ clientId: clientId,
+ familyId: id
+ };
+ var credentialCache = this.getCredentialsFilteredBy(refreshTokenFilter);
+ var refreshTokens = Object.keys(credentialCache.refreshTokens).map(function (key) { return credentialCache.refreshTokens[key]; });
+ var numRefreshTokens = refreshTokens.length;
+ if (numRefreshTokens < 1) {
+ return null;
+ }
+ // address the else case after remove functions address environment aliases
+ return refreshTokens[0];
+ };
+ /**
+ * Retrieve AppMetadataEntity from cache
+ */
+ CacheManager.prototype.readAppMetadataFromCache = function (environment, clientId) {
+ var appMetadataFilter = {
+ environment: environment,
+ clientId: clientId,
+ };
+ var appMetadata = this.getAppMetadataFilteredBy(appMetadataFilter);
+ var appMetadataEntries = Object.keys(appMetadata).map(function (key) { return appMetadata[key]; });
+ var numAppMetadata = appMetadataEntries.length;
+ if (numAppMetadata < 1) {
+ return null;
+ }
+ else if (numAppMetadata > 1) {
+ throw ClientAuthError.createMultipleMatchingAppMetadataInCacheError();
+ }
+ return appMetadataEntries[0];
+ };
+ /**
+ * Return the family_id value associated with FOCI
+ * @param environment
+ * @param clientId
+ */
+ CacheManager.prototype.isAppMetadataFOCI = function (environment, clientId) {
+ var appMetadata = this.readAppMetadataFromCache(environment, clientId);
+ return !!(appMetadata && appMetadata.familyId === THE_FAMILY_ID);
+ };
+ /**
+ * helper to match account ids
+ * @param value
+ * @param homeAccountId
+ */
+ CacheManager.prototype.matchHomeAccountId = function (entity, homeAccountId) {
+ return !!(entity.homeAccountId && homeAccountId === entity.homeAccountId);
+ };
+ /**
+ * helper to match assertion
+ * @param value
+ * @param oboAssertion
+ */
+ CacheManager.prototype.matchOboAssertion = function (entity, oboAssertion) {
+ return !!(entity.oboAssertion && oboAssertion === entity.oboAssertion);
+ };
+ /**
+ * helper to match environment
+ * @param value
+ * @param environment
+ */
+ CacheManager.prototype.matchEnvironment = function (entity, environment) {
+ var cloudMetadata = this.getAuthorityMetadataByAlias(environment);
+ if (cloudMetadata && cloudMetadata.aliases.indexOf(entity.environment) > -1) {
+ return true;
+ }
+ return false;
+ };
+ /**
+ * helper to match credential type
+ * @param entity
+ * @param credentialType
+ */
+ CacheManager.prototype.matchCredentialType = function (entity, credentialType) {
+ return (entity.credentialType && credentialType.toLowerCase() === entity.credentialType.toLowerCase());
+ };
+ /**
+ * helper to match client ids
+ * @param entity
+ * @param clientId
+ */
+ CacheManager.prototype.matchClientId = function (entity, clientId) {
+ return !!(entity.clientId && clientId === entity.clientId);
+ };
+ /**
+ * helper to match family ids
+ * @param entity
+ * @param familyId
+ */
+ CacheManager.prototype.matchFamilyId = function (entity, familyId) {
+ return !!(entity.familyId && familyId === entity.familyId);
+ };
+ /**
+ * helper to match realm
+ * @param entity
+ * @param realm
+ */
+ CacheManager.prototype.matchRealm = function (entity, realm) {
+ return !!(entity.realm && realm === entity.realm);
+ };
+ /**
+ * Returns true if the target scopes are a subset of the current entity's scopes, false otherwise.
+ * @param entity
+ * @param target
+ */
+ CacheManager.prototype.matchTarget = function (entity, target) {
+ if (entity.credentialType !== CredentialType.ACCESS_TOKEN || !entity.target) {
+ return false;
+ }
+ var entityScopeSet = ScopeSet.fromString(entity.target);
+ var requestTargetScopeSet = ScopeSet.fromString(target);
+ if (!requestTargetScopeSet.containsOnlyOIDCScopes()) {
+ requestTargetScopeSet.removeOIDCScopes(); // ignore OIDC scopes
+ }
+ return entityScopeSet.containsScopeSet(requestTargetScopeSet);
+ };
+ /**
+ * returns if a given cache entity is of the type appmetadata
+ * @param key
+ */
+ CacheManager.prototype.isAppMetadata = function (key) {
+ return key.indexOf(APP_METADATA) !== -1;
+ };
+ /**
+ * returns if a given cache entity is of the type authoritymetadata
+ * @param key
+ */
+ CacheManager.prototype.isAuthorityMetadata = function (key) {
+ return key.indexOf(AUTHORITY_METADATA_CONSTANTS.CACHE_KEY) !== -1;
+ };
+ /**
+ * returns cache key used for cloud instance metadata
+ */
+ CacheManager.prototype.generateAuthorityMetadataCacheKey = function (authority) {
+ return AUTHORITY_METADATA_CONSTANTS.CACHE_KEY + "-" + this.clientId + "-" + authority;
+ };
+ /**
+ * Returns the specific credential (IdToken/AccessToken/RefreshToken) from the cache
+ * @param key
+ * @param credType
+ */
+ CacheManager.prototype.getSpecificCredential = function (key, credType) {
+ switch (credType) {
+ case CredentialType.ID_TOKEN: {
+ return this.getIdTokenCredential(key);
+ }
+ case CredentialType.ACCESS_TOKEN: {
+ return this.getAccessTokenCredential(key);
+ }
+ case CredentialType.REFRESH_TOKEN: {
+ return this.getRefreshTokenCredential(key);
+ }
+ default:
+ return null;
+ }
+ };
+ /**
+ * Helper to convert serialized data to object
+ * @param obj
+ * @param json
+ */
+ CacheManager.toObject = function (obj, json) {
+ for (var propertyName in json) {
+ obj[propertyName] = json[propertyName];
+ }
+ return obj;
+ };
+ return CacheManager;
+}());
+var DefaultStorageClass = /** @class */ (function (_super) {
+ __extends(DefaultStorageClass, _super);
+ function DefaultStorageClass() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ DefaultStorageClass.prototype.setAccount = function () {
+ var notImplErr = "Storage interface - setAccount() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAccount = function () {
+ var notImplErr = "Storage interface - getAccount() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setIdTokenCredential = function () {
+ var notImplErr = "Storage interface - setIdTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getIdTokenCredential = function () {
+ var notImplErr = "Storage interface - getIdTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setAccessTokenCredential = function () {
+ var notImplErr = "Storage interface - setAccessTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAccessTokenCredential = function () {
+ var notImplErr = "Storage interface - getAccessTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setRefreshTokenCredential = function () {
+ var notImplErr = "Storage interface - setRefreshTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getRefreshTokenCredential = function () {
+ var notImplErr = "Storage interface - getRefreshTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setAppMetadata = function () {
+ var notImplErr = "Storage interface - setAppMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAppMetadata = function () {
+ var notImplErr = "Storage interface - getAppMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setServerTelemetry = function () {
+ var notImplErr = "Storage interface - setServerTelemetry() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getServerTelemetry = function () {
+ var notImplErr = "Storage interface - getServerTelemetry() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setAuthorityMetadata = function () {
+ var notImplErr = "Storage interface - setAuthorityMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAuthorityMetadata = function () {
+ var notImplErr = "Storage interface - getAuthorityMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAuthorityMetadataKeys = function () {
+ var notImplErr = "Storage interface - getAuthorityMetadataKeys() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setThrottlingCache = function () {
+ var notImplErr = "Storage interface - setThrottlingCache() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getThrottlingCache = function () {
+ var notImplErr = "Storage interface - getThrottlingCache() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.removeItem = function () {
+ var notImplErr = "Storage interface - removeItem() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.containsKey = function () {
+ var notImplErr = "Storage interface - containsKey() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getKeys = function () {
+ var notImplErr = "Storage interface - getKeys() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.clear = function () {
+ var notImplErr = "Storage interface - clear() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ return DefaultStorageClass;
+}(CacheManager));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+// Token renewal offset default in seconds
+var DEFAULT_TOKEN_RENEWAL_OFFSET_SEC = 300;
+var DEFAULT_SYSTEM_OPTIONS = {
+ tokenRenewalOffsetSeconds: DEFAULT_TOKEN_RENEWAL_OFFSET_SEC
+};
+var DEFAULT_LOGGER_IMPLEMENTATION = {
+ loggerCallback: function () {
+ // allow users to not set loggerCallback
+ },
+ piiLoggingEnabled: false,
+ logLevel: LogLevel.Info
+};
+var DEFAULT_NETWORK_IMPLEMENTATION = {
+ sendGetRequestAsync: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Network interface - sendGetRequestAsync() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ },
+ sendPostRequestAsync: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Network interface - sendPostRequestAsync() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ }
+};
+var DEFAULT_LIBRARY_INFO = {
+ sku: Constants.SKU,
+ version: version,
+ cpu: "",
+ os: ""
+};
+var DEFAULT_CLIENT_CREDENTIALS = {
+ clientSecret: "",
+ clientAssertion: undefined
+};
+/**
+ * Function that sets the default options when not explicitly configured from app developer
+ *
+ * @param Configuration
+ *
+ * @returns Configuration
+ */
+function buildClientConfiguration(_a) {
+ var userAuthOptions = _a.authOptions, userSystemOptions = _a.systemOptions, userLoggerOption = _a.loggerOptions, storageImplementation = _a.storageInterface, networkImplementation = _a.networkInterface, cryptoImplementation = _a.cryptoInterface, clientCredentials = _a.clientCredentials, libraryInfo = _a.libraryInfo, serverTelemetryManager = _a.serverTelemetryManager, persistencePlugin = _a.persistencePlugin, serializableCache = _a.serializableCache;
+ return {
+ authOptions: buildAuthOptions(userAuthOptions),
+ systemOptions: __assign(__assign({}, DEFAULT_SYSTEM_OPTIONS), userSystemOptions),
+ loggerOptions: __assign(__assign({}, DEFAULT_LOGGER_IMPLEMENTATION), userLoggerOption),
+ storageInterface: storageImplementation || new DefaultStorageClass(userAuthOptions.clientId, DEFAULT_CRYPTO_IMPLEMENTATION),
+ networkInterface: networkImplementation || DEFAULT_NETWORK_IMPLEMENTATION,
+ cryptoInterface: cryptoImplementation || DEFAULT_CRYPTO_IMPLEMENTATION,
+ clientCredentials: clientCredentials || DEFAULT_CLIENT_CREDENTIALS,
+ libraryInfo: __assign(__assign({}, DEFAULT_LIBRARY_INFO), libraryInfo),
+ serverTelemetryManager: serverTelemetryManager || null,
+ persistencePlugin: persistencePlugin || null,
+ serializableCache: serializableCache || null
+ };
+}
+/**
+ * Construct authoptions from the client and platform passed values
+ * @param authOptions
+ */
+function buildAuthOptions(authOptions) {
+ return __assign({ clientCapabilities: [] }, authOptions);
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Error thrown when there is an error with the server code, for example, unavailability.
+ */
+var ServerError = /** @class */ (function (_super) {
+ __extends(ServerError, _super);
+ function ServerError(errorCode, errorMessage, subError) {
+ var _this = _super.call(this, errorCode, errorMessage, subError) || this;
+ _this.name = "ServerError";
+ Object.setPrototypeOf(_this, ServerError.prototype);
+ return _this;
+ }
+ return ServerError;
+}(AuthError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ThrottlingUtils = /** @class */ (function () {
+ function ThrottlingUtils() {
+ }
+ /**
+ * Prepares a RequestThumbprint to be stored as a key.
+ * @param thumbprint
+ */
+ ThrottlingUtils.generateThrottlingStorageKey = function (thumbprint) {
+ return ThrottlingConstants.THROTTLING_PREFIX + "." + JSON.stringify(thumbprint);
+ };
+ /**
+ * Performs necessary throttling checks before a network request.
+ * @param cacheManager
+ * @param thumbprint
+ */
+ ThrottlingUtils.preProcess = function (cacheManager, thumbprint) {
+ var _a;
+ var key = ThrottlingUtils.generateThrottlingStorageKey(thumbprint);
+ var value = cacheManager.getThrottlingCache(key);
+ if (value) {
+ if (value.throttleTime < Date.now()) {
+ cacheManager.removeItem(key, CacheSchemaType.THROTTLING);
+ return;
+ }
+ throw new ServerError(((_a = value.errorCodes) === null || _a === void 0 ? void 0 : _a.join(" ")) || Constants.EMPTY_STRING, value.errorMessage, value.subError);
+ }
+ };
+ /**
+ * Performs necessary throttling checks after a network request.
+ * @param cacheManager
+ * @param thumbprint
+ * @param response
+ */
+ ThrottlingUtils.postProcess = function (cacheManager, thumbprint, response) {
+ if (ThrottlingUtils.checkResponseStatus(response) || ThrottlingUtils.checkResponseForRetryAfter(response)) {
+ var thumbprintValue = {
+ throttleTime: ThrottlingUtils.calculateThrottleTime(parseInt(response.headers[HeaderNames.RETRY_AFTER])),
+ error: response.body.error,
+ errorCodes: response.body.error_codes,
+ errorMessage: response.body.error_description,
+ subError: response.body.suberror
+ };
+ cacheManager.setThrottlingCache(ThrottlingUtils.generateThrottlingStorageKey(thumbprint), thumbprintValue);
+ }
+ };
+ /**
+ * Checks a NetworkResponse object's status codes against 429 or 5xx
+ * @param response
+ */
+ ThrottlingUtils.checkResponseStatus = function (response) {
+ return response.status === 429 || response.status >= 500 && response.status < 600;
+ };
+ /**
+ * Checks a NetworkResponse object's RetryAfter header
+ * @param response
+ */
+ ThrottlingUtils.checkResponseForRetryAfter = function (response) {
+ if (response.headers) {
+ return response.headers.hasOwnProperty(HeaderNames.RETRY_AFTER) && (response.status < 200 || response.status >= 300);
+ }
+ return false;
+ };
+ /**
+ * Calculates the Unix-time value for a throttle to expire given throttleTime in seconds.
+ * @param throttleTime
+ */
+ ThrottlingUtils.calculateThrottleTime = function (throttleTime) {
+ if (throttleTime <= 0) {
+ throttleTime = 0;
+ }
+ var currentSeconds = Date.now() / 1000;
+ return Math.floor(Math.min(currentSeconds + (throttleTime || ThrottlingConstants.DEFAULT_THROTTLE_TIME_SECONDS), currentSeconds + ThrottlingConstants.DEFAULT_MAX_THROTTLE_TIME_SECONDS) * 1000);
+ };
+ ThrottlingUtils.removeThrottle = function (cacheManager, clientId, authority, scopes, homeAccountIdentifier) {
+ var thumbprint = {
+ clientId: clientId,
+ authority: authority,
+ scopes: scopes,
+ homeAccountIdentifier: homeAccountIdentifier
+ };
+ var key = this.generateThrottlingStorageKey(thumbprint);
+ return cacheManager.removeItem(key, CacheSchemaType.THROTTLING);
+ };
+ return ThrottlingUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var NetworkManager = /** @class */ (function () {
+ function NetworkManager(networkClient, cacheManager) {
+ this.networkClient = networkClient;
+ this.cacheManager = cacheManager;
+ }
+ /**
+ * Wraps sendPostRequestAsync with necessary preflight and postflight logic
+ * @param thumbprint
+ * @param tokenEndpoint
+ * @param options
+ */
+ NetworkManager.prototype.sendPostRequest = function (thumbprint, tokenEndpoint, options) {
+ return __awaiter(this, void 0, void 0, function () {
+ var response;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ ThrottlingUtils.preProcess(this.cacheManager, thumbprint);
+ return [4 /*yield*/, this.networkClient.sendPostRequestAsync(tokenEndpoint, options)];
+ case 1:
+ response = _a.sent();
+ ThrottlingUtils.postProcess(this.cacheManager, thumbprint, response);
+ // Placeholder for Telemetry hook
+ return [2 /*return*/, response];
+ }
+ });
+ });
+ };
+ return NetworkManager;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Base application class which will construct requests to send to and handle responses from the Microsoft STS using the authorization code flow.
+ */
+var BaseClient = /** @class */ (function () {
+ function BaseClient(configuration) {
+ // Set the configuration
+ this.config = buildClientConfiguration(configuration);
+ // Initialize the logger
+ this.logger = new Logger(this.config.loggerOptions, name, version);
+ // Initialize crypto
+ this.cryptoUtils = this.config.cryptoInterface;
+ // Initialize storage interface
+ this.cacheManager = this.config.storageInterface;
+ // Set the network interface
+ this.networkClient = this.config.networkInterface;
+ // Set the NetworkManager
+ this.networkManager = new NetworkManager(this.networkClient, this.cacheManager);
+ // Set TelemetryManager
+ this.serverTelemetryManager = this.config.serverTelemetryManager;
+ // set Authority
+ this.authority = this.config.authOptions.authority;
+ }
+ /**
+ * Creates default headers for requests to token endpoint
+ */
+ BaseClient.prototype.createDefaultTokenRequestHeaders = function () {
+ var headers = this.createDefaultLibraryHeaders();
+ headers[HeaderNames.CONTENT_TYPE] = Constants.URL_FORM_CONTENT_TYPE;
+ headers[HeaderNames.X_MS_LIB_CAPABILITY] = HeaderNames.X_MS_LIB_CAPABILITY_VALUE;
+ if (this.serverTelemetryManager) {
+ headers[HeaderNames.X_CLIENT_CURR_TELEM] = this.serverTelemetryManager.generateCurrentRequestHeaderValue();
+ headers[HeaderNames.X_CLIENT_LAST_TELEM] = this.serverTelemetryManager.generateLastRequestHeaderValue();
+ }
+ return headers;
+ };
+ /**
+ * addLibraryData
+ */
+ BaseClient.prototype.createDefaultLibraryHeaders = function () {
+ var headers = {};
+ // client info headers
+ headers[AADServerParamKeys.X_CLIENT_SKU] = this.config.libraryInfo.sku;
+ headers[AADServerParamKeys.X_CLIENT_VER] = this.config.libraryInfo.version;
+ headers[AADServerParamKeys.X_CLIENT_OS] = this.config.libraryInfo.os;
+ headers[AADServerParamKeys.X_CLIENT_CPU] = this.config.libraryInfo.cpu;
+ return headers;
+ };
+ /**
+ * Http post to token endpoint
+ * @param tokenEndpoint
+ * @param queryString
+ * @param headers
+ * @param thumbprint
+ */
+ BaseClient.prototype.executePostToTokenEndpoint = function (tokenEndpoint, queryString, headers, thumbprint) {
+ return __awaiter(this, void 0, void 0, function () {
+ var response;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.networkManager.sendPostRequest(thumbprint, tokenEndpoint, { body: queryString, headers: headers })];
+ case 1:
+ response = _a.sent();
+ if (this.config.serverTelemetryManager && response.status < 500 && response.status !== 429) {
+ // Telemetry data successfully logged by server, clear Telemetry cache
+ this.config.serverTelemetryManager.clearTelemetryCache();
+ }
+ return [2 /*return*/, response];
+ }
+ });
+ });
+ };
+ /**
+ * Updates the authority object of the client. Endpoint discovery must be completed.
+ * @param updatedAuthority
+ */
+ BaseClient.prototype.updateAuthority = function (updatedAuthority) {
+ if (!updatedAuthority.discoveryComplete()) {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Updated authority has not completed endpoint discovery.");
+ }
+ this.authority = updatedAuthority;
+ };
+ return BaseClient;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Validates server consumable params from the "request" objects
+ */
+var RequestValidator = /** @class */ (function () {
+ function RequestValidator() {
+ }
+ /**
+ * Utility to check if the `redirectUri` in the request is a non-null value
+ * @param redirectUri
+ */
+ RequestValidator.validateRedirectUri = function (redirectUri) {
+ if (StringUtils.isEmpty(redirectUri)) {
+ throw ClientConfigurationError.createRedirectUriEmptyError();
+ }
+ };
+ /**
+ * Utility to validate prompt sent by the user in the request
+ * @param prompt
+ */
+ RequestValidator.validatePrompt = function (prompt) {
+ if ([
+ PromptValue.LOGIN,
+ PromptValue.SELECT_ACCOUNT,
+ PromptValue.CONSENT,
+ PromptValue.NONE
+ ].indexOf(prompt) < 0) {
+ throw ClientConfigurationError.createInvalidPromptError(prompt);
+ }
+ };
+ RequestValidator.validateClaims = function (claims) {
+ try {
+ JSON.parse(claims);
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidClaimsRequestError();
+ }
+ };
+ /**
+ * Utility to validate code_challenge and code_challenge_method
+ * @param codeChallenge
+ * @param codeChallengeMethod
+ */
+ RequestValidator.validateCodeChallengeParams = function (codeChallenge, codeChallengeMethod) {
+ if (StringUtils.isEmpty(codeChallenge) || StringUtils.isEmpty(codeChallengeMethod)) {
+ throw ClientConfigurationError.createInvalidCodeChallengeParamsError();
+ }
+ else {
+ this.validateCodeChallengeMethod(codeChallengeMethod);
+ }
+ };
+ /**
+ * Utility to validate code_challenge_method
+ * @param codeChallengeMethod
+ */
+ RequestValidator.validateCodeChallengeMethod = function (codeChallengeMethod) {
+ if ([
+ CodeChallengeMethodValues.PLAIN,
+ CodeChallengeMethodValues.S256
+ ].indexOf(codeChallengeMethod) < 0) {
+ throw ClientConfigurationError.createInvalidCodeChallengeMethodError();
+ }
+ };
+ /**
+ * Removes unnecessary or duplicate query parameters from extraQueryParameters
+ * @param request
+ */
+ RequestValidator.sanitizeEQParams = function (eQParams, queryParams) {
+ if (!eQParams) {
+ return {};
+ }
+ // Remove any query parameters already included in SSO params
+ queryParams.forEach(function (value, key) {
+ if (eQParams[key]) {
+ delete eQParams[key];
+ }
+ });
+ return eQParams;
+ };
+ return RequestValidator;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var RequestParameterBuilder = /** @class */ (function () {
+ function RequestParameterBuilder() {
+ this.parameters = new Map();
+ }
+ /**
+ * add response_type = code
+ */
+ RequestParameterBuilder.prototype.addResponseTypeCode = function () {
+ this.parameters.set(AADServerParamKeys.RESPONSE_TYPE, encodeURIComponent(Constants.CODE_RESPONSE_TYPE));
+ };
+ /**
+ * add response_mode. defaults to query.
+ * @param responseMode
+ */
+ RequestParameterBuilder.prototype.addResponseMode = function (responseMode) {
+ this.parameters.set(AADServerParamKeys.RESPONSE_MODE, encodeURIComponent((responseMode) ? responseMode : ResponseMode.QUERY));
+ };
+ /**
+ * add scopes. set addOidcScopes to false to prevent default scopes in non-user scenarios
+ * @param scopeSet
+ * @param addOidcScopes
+ */
+ RequestParameterBuilder.prototype.addScopes = function (scopes, addOidcScopes) {
+ if (addOidcScopes === void 0) { addOidcScopes = true; }
+ var requestScopes = addOidcScopes ? __spreadArrays(scopes || [], OIDC_DEFAULT_SCOPES) : scopes || [];
+ var scopeSet = new ScopeSet(requestScopes);
+ this.parameters.set(AADServerParamKeys.SCOPE, encodeURIComponent(scopeSet.printScopes()));
+ };
+ /**
+ * add clientId
+ * @param clientId
+ */
+ RequestParameterBuilder.prototype.addClientId = function (clientId) {
+ this.parameters.set(AADServerParamKeys.CLIENT_ID, encodeURIComponent(clientId));
+ };
+ /**
+ * add redirect_uri
+ * @param redirectUri
+ */
+ RequestParameterBuilder.prototype.addRedirectUri = function (redirectUri) {
+ RequestValidator.validateRedirectUri(redirectUri);
+ this.parameters.set(AADServerParamKeys.REDIRECT_URI, encodeURIComponent(redirectUri));
+ };
+ /**
+ * add post logout redirectUri
+ * @param redirectUri
+ */
+ RequestParameterBuilder.prototype.addPostLogoutRedirectUri = function (redirectUri) {
+ RequestValidator.validateRedirectUri(redirectUri);
+ this.parameters.set(AADServerParamKeys.POST_LOGOUT_URI, encodeURIComponent(redirectUri));
+ };
+ /**
+ * add id_token_hint to logout request
+ * @param idTokenHint
+ */
+ RequestParameterBuilder.prototype.addIdTokenHint = function (idTokenHint) {
+ this.parameters.set(AADServerParamKeys.ID_TOKEN_HINT, encodeURIComponent(idTokenHint));
+ };
+ /**
+ * add domain_hint
+ * @param domainHint
+ */
+ RequestParameterBuilder.prototype.addDomainHint = function (domainHint) {
+ this.parameters.set(SSOTypes.DOMAIN_HINT, encodeURIComponent(domainHint));
+ };
+ /**
+ * add login_hint
+ * @param loginHint
+ */
+ RequestParameterBuilder.prototype.addLoginHint = function (loginHint) {
+ this.parameters.set(SSOTypes.LOGIN_HINT, encodeURIComponent(loginHint));
+ };
+ /**
+ * add sid
+ * @param sid
+ */
+ RequestParameterBuilder.prototype.addSid = function (sid) {
+ this.parameters.set(SSOTypes.SID, encodeURIComponent(sid));
+ };
+ /**
+ * add claims
+ * @param claims
+ */
+ RequestParameterBuilder.prototype.addClaims = function (claims, clientCapabilities) {
+ var mergedClaims = this.addClientCapabilitiesToClaims(claims, clientCapabilities);
+ RequestValidator.validateClaims(mergedClaims);
+ this.parameters.set(AADServerParamKeys.CLAIMS, encodeURIComponent(mergedClaims));
+ };
+ /**
+ * add correlationId
+ * @param correlationId
+ */
+ RequestParameterBuilder.prototype.addCorrelationId = function (correlationId) {
+ this.parameters.set(AADServerParamKeys.CLIENT_REQUEST_ID, encodeURIComponent(correlationId));
+ };
+ /**
+ * add library info query params
+ * @param libraryInfo
+ */
+ RequestParameterBuilder.prototype.addLibraryInfo = function (libraryInfo) {
+ // Telemetry Info
+ this.parameters.set(AADServerParamKeys.X_CLIENT_SKU, libraryInfo.sku);
+ this.parameters.set(AADServerParamKeys.X_CLIENT_VER, libraryInfo.version);
+ this.parameters.set(AADServerParamKeys.X_CLIENT_OS, libraryInfo.os);
+ this.parameters.set(AADServerParamKeys.X_CLIENT_CPU, libraryInfo.cpu);
+ };
+ /**
+ * add prompt
+ * @param prompt
+ */
+ RequestParameterBuilder.prototype.addPrompt = function (prompt) {
+ RequestValidator.validatePrompt(prompt);
+ this.parameters.set("" + AADServerParamKeys.PROMPT, encodeURIComponent(prompt));
+ };
+ /**
+ * add state
+ * @param state
+ */
+ RequestParameterBuilder.prototype.addState = function (state) {
+ if (!StringUtils.isEmpty(state)) {
+ this.parameters.set(AADServerParamKeys.STATE, encodeURIComponent(state));
+ }
+ };
+ /**
+ * add nonce
+ * @param nonce
+ */
+ RequestParameterBuilder.prototype.addNonce = function (nonce) {
+ this.parameters.set(AADServerParamKeys.NONCE, encodeURIComponent(nonce));
+ };
+ /**
+ * add code_challenge and code_challenge_method
+ * - throw if either of them are not passed
+ * @param codeChallenge
+ * @param codeChallengeMethod
+ */
+ RequestParameterBuilder.prototype.addCodeChallengeParams = function (codeChallenge, codeChallengeMethod) {
+ RequestValidator.validateCodeChallengeParams(codeChallenge, codeChallengeMethod);
+ if (codeChallenge && codeChallengeMethod) {
+ this.parameters.set(AADServerParamKeys.CODE_CHALLENGE, encodeURIComponent(codeChallenge));
+ this.parameters.set(AADServerParamKeys.CODE_CHALLENGE_METHOD, encodeURIComponent(codeChallengeMethod));
+ }
+ else {
+ throw ClientConfigurationError.createInvalidCodeChallengeParamsError();
+ }
+ };
+ /**
+ * add the `authorization_code` passed by the user to exchange for a token
+ * @param code
+ */
+ RequestParameterBuilder.prototype.addAuthorizationCode = function (code) {
+ this.parameters.set(AADServerParamKeys.CODE, encodeURIComponent(code));
+ };
+ /**
+ * add the `authorization_code` passed by the user to exchange for a token
+ * @param code
+ */
+ RequestParameterBuilder.prototype.addDeviceCode = function (code) {
+ this.parameters.set(AADServerParamKeys.DEVICE_CODE, encodeURIComponent(code));
+ };
+ /**
+ * add the `refreshToken` passed by the user
+ * @param refreshToken
+ */
+ RequestParameterBuilder.prototype.addRefreshToken = function (refreshToken) {
+ this.parameters.set(AADServerParamKeys.REFRESH_TOKEN, encodeURIComponent(refreshToken));
+ };
+ /**
+ * add the `code_verifier` passed by the user to exchange for a token
+ * @param codeVerifier
+ */
+ RequestParameterBuilder.prototype.addCodeVerifier = function (codeVerifier) {
+ this.parameters.set(AADServerParamKeys.CODE_VERIFIER, encodeURIComponent(codeVerifier));
+ };
+ /**
+ * add client_secret
+ * @param clientSecret
+ */
+ RequestParameterBuilder.prototype.addClientSecret = function (clientSecret) {
+ this.parameters.set(AADServerParamKeys.CLIENT_SECRET, encodeURIComponent(clientSecret));
+ };
+ /**
+ * add clientAssertion for confidential client flows
+ * @param clientAssertion
+ */
+ RequestParameterBuilder.prototype.addClientAssertion = function (clientAssertion) {
+ this.parameters.set(AADServerParamKeys.CLIENT_ASSERTION, encodeURIComponent(clientAssertion));
+ };
+ /**
+ * add clientAssertionType for confidential client flows
+ * @param clientAssertionType
+ */
+ RequestParameterBuilder.prototype.addClientAssertionType = function (clientAssertionType) {
+ this.parameters.set(AADServerParamKeys.CLIENT_ASSERTION_TYPE, encodeURIComponent(clientAssertionType));
+ };
+ /**
+ * add OBO assertion for confidential client flows
+ * @param clientAssertion
+ */
+ RequestParameterBuilder.prototype.addOboAssertion = function (oboAssertion) {
+ this.parameters.set(AADServerParamKeys.OBO_ASSERTION, encodeURIComponent(oboAssertion));
+ };
+ /**
+ * add grant type
+ * @param grantType
+ */
+ RequestParameterBuilder.prototype.addRequestTokenUse = function (tokenUse) {
+ this.parameters.set(AADServerParamKeys.REQUESTED_TOKEN_USE, encodeURIComponent(tokenUse));
+ };
+ /**
+ * add grant type
+ * @param grantType
+ */
+ RequestParameterBuilder.prototype.addGrantType = function (grantType) {
+ this.parameters.set(AADServerParamKeys.GRANT_TYPE, encodeURIComponent(grantType));
+ };
+ /**
+ * add client info
+ *
+ */
+ RequestParameterBuilder.prototype.addClientInfo = function () {
+ this.parameters.set(ClientInfo, "1");
+ };
+ /**
+ * add extraQueryParams
+ * @param eQparams
+ */
+ RequestParameterBuilder.prototype.addExtraQueryParameters = function (eQparams) {
+ var _this = this;
+ RequestValidator.sanitizeEQParams(eQparams, this.parameters);
+ Object.keys(eQparams).forEach(function (key) {
+ _this.parameters.set(key, eQparams[key]);
+ });
+ };
+ RequestParameterBuilder.prototype.addClientCapabilitiesToClaims = function (claims, clientCapabilities) {
+ var mergedClaims;
+ // Parse provided claims into JSON object or initialize empty object
+ if (!claims) {
+ mergedClaims = {};
+ }
+ else {
+ try {
+ mergedClaims = JSON.parse(claims);
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidClaimsRequestError();
+ }
+ }
+ if (clientCapabilities && clientCapabilities.length > 0) {
+ if (!mergedClaims.hasOwnProperty(ClaimsRequestKeys.ACCESS_TOKEN)) {
+ // Add access_token key to claims object
+ mergedClaims[ClaimsRequestKeys.ACCESS_TOKEN] = {};
+ }
+ // Add xms_cc claim with provided clientCapabilities to access_token key
+ mergedClaims[ClaimsRequestKeys.ACCESS_TOKEN][ClaimsRequestKeys.XMS_CC] = {
+ values: clientCapabilities
+ };
+ }
+ return JSON.stringify(mergedClaims);
+ };
+ /**
+ * adds `username` for Password Grant flow
+ * @param username
+ */
+ RequestParameterBuilder.prototype.addUsername = function (username) {
+ this.parameters.set(PasswordGrantConstants.username, username);
+ };
+ /**
+ * adds `password` for Password Grant flow
+ * @param password
+ */
+ RequestParameterBuilder.prototype.addPassword = function (password) {
+ this.parameters.set(PasswordGrantConstants.password, password);
+ };
+ /**
+ * add pop_jwk to query params
+ * @param cnfString
+ */
+ RequestParameterBuilder.prototype.addPopToken = function (cnfString) {
+ if (!StringUtils.isEmpty(cnfString)) {
+ this.parameters.set(AADServerParamKeys.TOKEN_TYPE, AuthenticationScheme.POP);
+ this.parameters.set(AADServerParamKeys.REQ_CNF, encodeURIComponent(cnfString));
+ }
+ };
+ /**
+ * Utility to create a URL from the params map
+ */
+ RequestParameterBuilder.prototype.createQueryString = function () {
+ var queryParameterArray = new Array();
+ this.parameters.forEach(function (value, key) {
+ queryParameterArray.push(key + "=" + value);
+ });
+ return queryParameterArray.join("&");
+ };
+ return RequestParameterBuilder;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ID_TOKEN Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-idtoken-clientId-contoso.com-
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * }
+ */
+var IdTokenEntity = /** @class */ (function (_super) {
+ __extends(IdTokenEntity, _super);
+ function IdTokenEntity() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ /**
+ * Create IdTokenEntity
+ * @param homeAccountId
+ * @param authenticationResult
+ * @param clientId
+ * @param authority
+ */
+ IdTokenEntity.createIdTokenEntity = function (homeAccountId, environment, idToken, clientId, tenantId, oboAssertion) {
+ var idTokenEntity = new IdTokenEntity();
+ idTokenEntity.credentialType = CredentialType.ID_TOKEN;
+ idTokenEntity.homeAccountId = homeAccountId;
+ idTokenEntity.environment = environment;
+ idTokenEntity.clientId = clientId;
+ idTokenEntity.secret = idToken;
+ idTokenEntity.realm = tenantId;
+ idTokenEntity.oboAssertion = oboAssertion;
+ return idTokenEntity;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ IdTokenEntity.isIdTokenEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("credentialType") &&
+ entity.hasOwnProperty("realm") &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("secret") &&
+ entity["credentialType"] === CredentialType.ID_TOKEN);
+ };
+ return IdTokenEntity;
+}(CredentialEntity));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Utility class which exposes functions for managing date and time operations.
+ */
+var TimeUtils = /** @class */ (function () {
+ function TimeUtils() {
+ }
+ /**
+ * return the current time in Unix time (seconds).
+ */
+ TimeUtils.nowSeconds = function () {
+ // Date.getTime() returns in milliseconds.
+ return Math.round(new Date().getTime() / 1000.0);
+ };
+ /**
+ * check if a token is expired based on given UTC time in seconds.
+ * @param expiresOn
+ */
+ TimeUtils.isTokenExpired = function (expiresOn, offset) {
+ // check for access token expiry
+ var expirationSec = Number(expiresOn) || 0;
+ var offsetCurrentTimeSec = TimeUtils.nowSeconds() + offset;
+ // If current time + offset is greater than token expiration time, then token is expired.
+ return (offsetCurrentTimeSec > expirationSec);
+ };
+ return TimeUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ACCESS_TOKEN Credential Type
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-accesstoken-clientId-contoso.com-user.read
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, usually only used for refresh tokens
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * cachedAt: Absolute device time when entry was created in the cache.
+ * expiresOn: Token expiry time, calculated based on current UTC time in seconds. Represented as a string.
+ * extendedExpiresOn: Additional extended expiry time until when token is valid in case of server-side outage. Represented as string in UTC seconds.
+ * keyId: used for POP and SSH tokenTypes
+ * tokenType: Type of the token issued. Usually "Bearer"
+ * }
+ */
+var AccessTokenEntity = /** @class */ (function (_super) {
+ __extends(AccessTokenEntity, _super);
+ function AccessTokenEntity() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ /**
+ * Create AccessTokenEntity
+ * @param homeAccountId
+ * @param environment
+ * @param accessToken
+ * @param clientId
+ * @param tenantId
+ * @param scopes
+ * @param expiresOn
+ * @param extExpiresOn
+ */
+ AccessTokenEntity.createAccessTokenEntity = function (homeAccountId, environment, accessToken, clientId, tenantId, scopes, expiresOn, extExpiresOn, tokenType, oboAssertion) {
+ var atEntity = new AccessTokenEntity();
+ atEntity.homeAccountId = homeAccountId;
+ atEntity.credentialType = CredentialType.ACCESS_TOKEN;
+ atEntity.secret = accessToken;
+ var currentTime = TimeUtils.nowSeconds();
+ atEntity.cachedAt = currentTime.toString();
+ /*
+ * Token expiry time.
+ * This value should be calculated based on the current UTC time measured locally and the value expires_in Represented as a string in JSON.
+ */
+ atEntity.expiresOn = expiresOn.toString();
+ atEntity.extendedExpiresOn = extExpiresOn.toString();
+ atEntity.environment = environment;
+ atEntity.clientId = clientId;
+ atEntity.realm = tenantId;
+ atEntity.target = scopes;
+ atEntity.oboAssertion = oboAssertion;
+ atEntity.tokenType = StringUtils.isEmpty(tokenType) ? AuthenticationScheme.BEARER : tokenType;
+ return atEntity;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AccessTokenEntity.isAccessTokenEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("credentialType") &&
+ entity.hasOwnProperty("realm") &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("secret") &&
+ entity.hasOwnProperty("target") &&
+ entity["credentialType"] === CredentialType.ACCESS_TOKEN);
+ };
+ return AccessTokenEntity;
+}(CredentialEntity));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * REFRESH_TOKEN Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-refreshtoken-clientId--
+ *
+ * Value:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, '1' represents Microsoft Family
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * }
+ */
+var RefreshTokenEntity = /** @class */ (function (_super) {
+ __extends(RefreshTokenEntity, _super);
+ function RefreshTokenEntity() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ /**
+ * Create RefreshTokenEntity
+ * @param homeAccountId
+ * @param authenticationResult
+ * @param clientId
+ * @param authority
+ */
+ RefreshTokenEntity.createRefreshTokenEntity = function (homeAccountId, environment, refreshToken, clientId, familyId, oboAssertion) {
+ var rtEntity = new RefreshTokenEntity();
+ rtEntity.clientId = clientId;
+ rtEntity.credentialType = CredentialType.REFRESH_TOKEN;
+ rtEntity.environment = environment;
+ rtEntity.homeAccountId = homeAccountId;
+ rtEntity.secret = refreshToken;
+ rtEntity.oboAssertion = oboAssertion;
+ if (familyId)
+ rtEntity.familyId = familyId;
+ return rtEntity;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ RefreshTokenEntity.isRefreshTokenEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("credentialType") &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("secret") &&
+ entity["credentialType"] === CredentialType.REFRESH_TOKEN);
+ };
+ return RefreshTokenEntity;
+}(CredentialEntity));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * InteractionRequiredAuthErrorMessage class containing string constants used by error codes and messages.
+ */
+var InteractionRequiredAuthErrorMessage = [
+ "interaction_required",
+ "consent_required",
+ "login_required"
+];
+var InteractionRequiredAuthSubErrorMessage = [
+ "message_only",
+ "additional_action",
+ "basic_action",
+ "user_password_expired",
+ "consent_required"
+];
+/**
+ * Error thrown when user interaction is required at the auth server.
+ */
+var InteractionRequiredAuthError = /** @class */ (function (_super) {
+ __extends(InteractionRequiredAuthError, _super);
+ function InteractionRequiredAuthError(errorCode, errorMessage, subError) {
+ var _this = _super.call(this, errorCode, errorMessage, subError) || this;
+ _this.name = "InteractionRequiredAuthError";
+ Object.setPrototypeOf(_this, InteractionRequiredAuthError.prototype);
+ return _this;
+ }
+ InteractionRequiredAuthError.isInteractionRequiredError = function (errorCode, errorString, subError) {
+ var isInteractionRequiredErrorCode = !!errorCode && InteractionRequiredAuthErrorMessage.indexOf(errorCode) > -1;
+ var isInteractionRequiredSubError = !!subError && InteractionRequiredAuthSubErrorMessage.indexOf(subError) > -1;
+ var isInteractionRequiredErrorDesc = !!errorString && InteractionRequiredAuthErrorMessage.some(function (irErrorCode) {
+ return errorString.indexOf(irErrorCode) > -1;
+ });
+ return isInteractionRequiredErrorCode || isInteractionRequiredErrorDesc || isInteractionRequiredSubError;
+ };
+ return InteractionRequiredAuthError;
+}(ServerError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var CacheRecord = /** @class */ (function () {
+ function CacheRecord(accountEntity, idTokenEntity, accessTokenEntity, refreshTokenEntity, appMetadataEntity) {
+ this.account = accountEntity || null;
+ this.idToken = idTokenEntity || null;
+ this.accessToken = accessTokenEntity || null;
+ this.refreshToken = refreshTokenEntity || null;
+ this.appMetadata = appMetadataEntity || null;
+ }
+ return CacheRecord;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Class which provides helpers for OAuth 2.0 protocol specific values
+ */
+var ProtocolUtils = /** @class */ (function () {
+ function ProtocolUtils() {
+ }
+ /**
+ * Appends user state with random guid, or returns random guid.
+ * @param userState
+ * @param randomGuid
+ */
+ ProtocolUtils.setRequestState = function (cryptoObj, userState, meta) {
+ var libraryState = ProtocolUtils.generateLibraryState(cryptoObj, meta);
+ return !StringUtils.isEmpty(userState) ? "" + libraryState + Constants.RESOURCE_DELIM + userState : libraryState;
+ };
+ /**
+ * Generates the state value used by the common library.
+ * @param randomGuid
+ * @param cryptoObj
+ */
+ ProtocolUtils.generateLibraryState = function (cryptoObj, meta) {
+ if (!cryptoObj) {
+ throw ClientAuthError.createNoCryptoObjectError("generateLibraryState");
+ }
+ // Create a state object containing a unique id and the timestamp of the request creation
+ var stateObj = {
+ id: cryptoObj.createNewGuid()
+ };
+ if (meta) {
+ stateObj.meta = meta;
+ }
+ var stateString = JSON.stringify(stateObj);
+ return cryptoObj.base64Encode(stateString);
+ };
+ /**
+ * Parses the state into the RequestStateObject, which contains the LibraryState info and the state passed by the user.
+ * @param state
+ * @param cryptoObj
+ */
+ ProtocolUtils.parseRequestState = function (cryptoObj, state) {
+ if (!cryptoObj) {
+ throw ClientAuthError.createNoCryptoObjectError("parseRequestState");
+ }
+ if (StringUtils.isEmpty(state)) {
+ throw ClientAuthError.createInvalidStateError(state, "Null, undefined or empty state");
+ }
+ try {
+ // Split the state between library state and user passed state and decode them separately
+ var splitState = decodeURIComponent(state).split(Constants.RESOURCE_DELIM);
+ var libraryState = splitState[0];
+ var userState = splitState.length > 1 ? splitState.slice(1).join(Constants.RESOURCE_DELIM) : "";
+ var libraryStateString = cryptoObj.base64Decode(libraryState);
+ var libraryStateObj = JSON.parse(libraryStateString);
+ return {
+ userRequestState: !StringUtils.isEmpty(userState) ? userState : "",
+ libraryState: libraryStateObj
+ };
+ }
+ catch (e) {
+ throw ClientAuthError.createInvalidStateError(state, e);
+ }
+ };
+ return ProtocolUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Url object class which can perform various transformations on url strings.
+ */
+var UrlString = /** @class */ (function () {
+ function UrlString(url) {
+ this._urlString = url;
+ if (StringUtils.isEmpty(this._urlString)) {
+ // Throws error if url is empty
+ throw ClientConfigurationError.createUrlEmptyError();
+ }
+ if (StringUtils.isEmpty(this.getHash())) {
+ this._urlString = UrlString.canonicalizeUri(url);
+ }
+ }
+ Object.defineProperty(UrlString.prototype, "urlString", {
+ get: function () {
+ return this._urlString;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ /**
+ * Ensure urls are lower case and end with a / character.
+ * @param url
+ */
+ UrlString.canonicalizeUri = function (url) {
+ if (url) {
+ url = url.toLowerCase();
+ if (StringUtils.endsWith(url, "?")) {
+ url = url.slice(0, -1);
+ }
+ else if (StringUtils.endsWith(url, "?/")) {
+ url = url.slice(0, -2);
+ }
+ if (!StringUtils.endsWith(url, "/")) {
+ url += "/";
+ }
+ }
+ return url;
+ };
+ /**
+ * Throws if urlString passed is not a valid authority URI string.
+ */
+ UrlString.prototype.validateAsUri = function () {
+ // Attempts to parse url for uri components
+ var components;
+ try {
+ components = this.getUrlComponents();
+ }
+ catch (e) {
+ throw ClientConfigurationError.createUrlParseError(e);
+ }
+ // Throw error if URI or path segments are not parseable.
+ if (!components.HostNameAndPort || !components.PathSegments) {
+ throw ClientConfigurationError.createUrlParseError("Given url string: " + this.urlString);
+ }
+ // Throw error if uri is insecure.
+ if (!components.Protocol || components.Protocol.toLowerCase() !== "https:") {
+ throw ClientConfigurationError.createInsecureAuthorityUriError(this.urlString);
+ }
+ };
+ /**
+ * Function to remove query string params from url. Returns the new url.
+ * @param url
+ * @param name
+ */
+ UrlString.prototype.urlRemoveQueryStringParameter = function (name) {
+ var regex = new RegExp("(\\&" + name + "=)[^\&]+");
+ this._urlString = this.urlString.replace(regex, "");
+ // name=value&
+ regex = new RegExp("(" + name + "=)[^\&]+&");
+ this._urlString = this.urlString.replace(regex, "");
+ // name=value
+ regex = new RegExp("(" + name + "=)[^\&]+");
+ this._urlString = this.urlString.replace(regex, "");
+ return this.urlString;
+ };
+ UrlString.removeHashFromUrl = function (url) {
+ return UrlString.canonicalizeUri(url.split("#")[0]);
+ };
+ /**
+ * Given a url like https://a:b/common/d?e=f#g, and a tenantId, returns https://a:b/tenantId/d
+ * @param href The url
+ * @param tenantId The tenant id to replace
+ */
+ UrlString.prototype.replaceTenantPath = function (tenantId) {
+ var urlObject = this.getUrlComponents();
+ var pathArray = urlObject.PathSegments;
+ if (tenantId && (pathArray.length !== 0 && (pathArray[0] === AADAuthorityConstants.COMMON || pathArray[0] === AADAuthorityConstants.ORGANIZATIONS))) {
+ pathArray[0] = tenantId;
+ }
+ return UrlString.constructAuthorityUriFromObject(urlObject);
+ };
+ /**
+ * Returns the anchor part(#) of the URL
+ */
+ UrlString.prototype.getHash = function () {
+ return UrlString.parseHash(this.urlString);
+ };
+ /**
+ * Parses out the components from a url string.
+ * @returns An object with the various components. Please cache this value insted of calling this multiple times on the same url.
+ */
+ UrlString.prototype.getUrlComponents = function () {
+ // https://gist.github.com/curtisz/11139b2cfcaef4a261e0
+ var regEx = RegExp("^(([^:/?#]+):)?(//([^/?#]*))?([^?#]*)(\\?([^#]*))?(#(.*))?");
+ // If url string does not match regEx, we throw an error
+ var match = this.urlString.match(regEx);
+ if (!match) {
+ throw ClientConfigurationError.createUrlParseError("Given url string: " + this.urlString);
+ }
+ // Url component object
+ var urlComponents = {
+ Protocol: match[1],
+ HostNameAndPort: match[4],
+ AbsolutePath: match[5],
+ QueryString: match[7]
+ };
+ var pathSegments = urlComponents.AbsolutePath.split("/");
+ pathSegments = pathSegments.filter(function (val) { return val && val.length > 0; }); // remove empty elements
+ urlComponents.PathSegments = pathSegments;
+ if (!StringUtils.isEmpty(urlComponents.QueryString) && urlComponents.QueryString.endsWith("/")) {
+ urlComponents.QueryString = urlComponents.QueryString.substring(0, urlComponents.QueryString.length - 1);
+ }
+ return urlComponents;
+ };
+ UrlString.getDomainFromUrl = function (url) {
+ var regEx = RegExp("^([^:/?#]+://)?([^/?#]*)");
+ var match = url.match(regEx);
+ if (!match) {
+ throw ClientConfigurationError.createUrlParseError("Given url string: " + url);
+ }
+ return match[2];
+ };
+ UrlString.getAbsoluteUrl = function (relativeUrl, baseUrl) {
+ if (relativeUrl[0] === Constants.FORWARD_SLASH) {
+ var url = new UrlString(baseUrl);
+ var baseComponents = url.getUrlComponents();
+ return baseComponents.Protocol + "//" + baseComponents.HostNameAndPort + relativeUrl;
+ }
+ return relativeUrl;
+ };
+ /**
+ * Parses hash string from given string. Returns empty string if no hash symbol is found.
+ * @param hashString
+ */
+ UrlString.parseHash = function (hashString) {
+ var hashIndex1 = hashString.indexOf("#");
+ var hashIndex2 = hashString.indexOf("#/");
+ if (hashIndex2 > -1) {
+ return hashString.substring(hashIndex2 + 2);
+ }
+ else if (hashIndex1 > -1) {
+ return hashString.substring(hashIndex1 + 1);
+ }
+ return "";
+ };
+ UrlString.constructAuthorityUriFromObject = function (urlObject) {
+ return new UrlString(urlObject.Protocol + "//" + urlObject.HostNameAndPort + "/" + urlObject.PathSegments.join("/"));
+ };
+ /**
+ * Returns URL hash as server auth code response object.
+ */
+ UrlString.getDeserializedHash = function (hash) {
+ // Check if given hash is empty
+ if (StringUtils.isEmpty(hash)) {
+ return {};
+ }
+ // Strip the # symbol if present
+ var parsedHash = UrlString.parseHash(hash);
+ // If # symbol was not present, above will return empty string, so give original hash value
+ var deserializedHash = StringUtils.queryStringToObject(StringUtils.isEmpty(parsedHash) ? hash : parsedHash);
+ // Check if deserialization didn't work
+ if (!deserializedHash) {
+ throw ClientAuthError.createHashNotDeserializedError(JSON.stringify(deserializedHash));
+ }
+ return deserializedHash;
+ };
+ /**
+ * Check if the hash of the URL string contains known properties
+ */
+ UrlString.hashContainsKnownProperties = function (hash) {
+ if (StringUtils.isEmpty(hash)) {
+ return false;
+ }
+ var parameters = UrlString.getDeserializedHash(hash);
+ return !!(parameters.code ||
+ parameters.error_description ||
+ parameters.error ||
+ parameters.state);
+ };
+ return UrlString;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var KeyLocation;
+(function (KeyLocation) {
+ KeyLocation["SW"] = "sw";
+ KeyLocation["UHW"] = "uhw";
+})(KeyLocation || (KeyLocation = {}));
+var PopTokenGenerator = /** @class */ (function () {
+ function PopTokenGenerator(cryptoUtils) {
+ this.cryptoUtils = cryptoUtils;
+ }
+ PopTokenGenerator.prototype.generateCnf = function (resourceRequestMethod, resourceRequestUri) {
+ return __awaiter(this, void 0, void 0, function () {
+ var kidThumbprint, reqCnf;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.cryptoUtils.getPublicKeyThumbprint(resourceRequestMethod, resourceRequestUri)];
+ case 1:
+ kidThumbprint = _a.sent();
+ reqCnf = {
+ kid: kidThumbprint,
+ xms_ksl: KeyLocation.SW
+ };
+ return [2 /*return*/, this.cryptoUtils.base64Encode(JSON.stringify(reqCnf))];
+ }
+ });
+ });
+ };
+ PopTokenGenerator.prototype.signPopToken = function (accessToken, resourceRequestMethod, resourceRequestUri) {
+ var _a;
+ return __awaiter(this, void 0, void 0, function () {
+ var tokenClaims, resourceUrlString, resourceUrlComponents;
+ return __generator(this, function (_b) {
+ switch (_b.label) {
+ case 0:
+ tokenClaims = AuthToken.extractTokenClaims(accessToken, this.cryptoUtils);
+ resourceUrlString = new UrlString(resourceRequestUri);
+ resourceUrlComponents = resourceUrlString.getUrlComponents();
+ if (!((_a = tokenClaims === null || tokenClaims === void 0 ? void 0 : tokenClaims.cnf) === null || _a === void 0 ? void 0 : _a.kid)) {
+ throw ClientAuthError.createTokenClaimsRequiredError();
+ }
+ return [4 /*yield*/, this.cryptoUtils.signJwt({
+ at: accessToken,
+ ts: "" + TimeUtils.nowSeconds(),
+ m: resourceRequestMethod.toUpperCase(),
+ u: resourceUrlComponents.HostNameAndPort || "",
+ nonce: this.cryptoUtils.createNewGuid(),
+ p: resourceUrlComponents.AbsolutePath,
+ q: [[], resourceUrlComponents.QueryString],
+ }, tokenClaims.cnf.kid)];
+ case 1: return [2 /*return*/, _b.sent()];
+ }
+ });
+ });
+ };
+ return PopTokenGenerator;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * APP_METADATA Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key: appmetadata--
+ *
+ * Value:
+ * {
+ * clientId: client ID of the application
+ * environment: entity that issued the token, represented as a full host
+ * familyId: Family ID identifier, '1' represents Microsoft Family
+ * }
+ */
+var AppMetadataEntity = /** @class */ (function () {
+ function AppMetadataEntity() {
+ }
+ /**
+ * Generate AppMetadata Cache Key as per the schema: appmetadata--
+ */
+ AppMetadataEntity.prototype.generateAppMetadataKey = function () {
+ return AppMetadataEntity.generateAppMetadataCacheKey(this.environment, this.clientId);
+ };
+ /**
+ * Generate AppMetadata Cache Key
+ */
+ AppMetadataEntity.generateAppMetadataCacheKey = function (environment, clientId) {
+ var appMetaDataKeyArray = [
+ APP_METADATA,
+ environment,
+ clientId,
+ ];
+ return appMetaDataKeyArray.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Creates AppMetadataEntity
+ * @param clientId
+ * @param environment
+ * @param familyId
+ */
+ AppMetadataEntity.createAppMetadataEntity = function (clientId, environment, familyId) {
+ var appMetadata = new AppMetadataEntity();
+ appMetadata.clientId = clientId;
+ appMetadata.environment = environment;
+ if (familyId) {
+ appMetadata.familyId = familyId;
+ }
+ return appMetadata;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AppMetadataEntity.isAppMetadataEntity = function (key, entity) {
+ if (!entity) {
+ return false;
+ }
+ return (key.indexOf(APP_METADATA) === 0 &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("environment"));
+ };
+ return AppMetadataEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * This class instance helps track the memory changes facilitating
+ * decisions to read from and write to the persistent cache
+ */ var TokenCacheContext = /** @class */ (function () {
+ function TokenCacheContext(tokenCache, hasChanged) {
+ this.cache = tokenCache;
+ this.hasChanged = hasChanged;
+ }
+ Object.defineProperty(TokenCacheContext.prototype, "cacheHasChanged", {
+ /**
+ * boolean which indicates the changes in cache
+ */
+ get: function () {
+ return this.hasChanged;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(TokenCacheContext.prototype, "tokenCache", {
+ /**
+ * function to retrieve the token cache
+ */
+ get: function () {
+ return this.cache;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ return TokenCacheContext;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Class that handles response parsing.
+ */
+var ResponseHandler = /** @class */ (function () {
+ function ResponseHandler(clientId, cacheStorage, cryptoObj, logger, serializableCache, persistencePlugin) {
+ this.clientId = clientId;
+ this.cacheStorage = cacheStorage;
+ this.cryptoObj = cryptoObj;
+ this.logger = logger;
+ this.serializableCache = serializableCache;
+ this.persistencePlugin = persistencePlugin;
+ }
+ /**
+ * Function which validates server authorization code response.
+ * @param serverResponseHash
+ * @param cachedState
+ * @param cryptoObj
+ */
+ ResponseHandler.prototype.validateServerAuthorizationCodeResponse = function (serverResponseHash, cachedState, cryptoObj) {
+ if (!serverResponseHash.state || !cachedState) {
+ throw !serverResponseHash.state ? ClientAuthError.createStateNotFoundError("Server State") : ClientAuthError.createStateNotFoundError("Cached State");
+ }
+ if (decodeURIComponent(serverResponseHash.state) !== decodeURIComponent(cachedState)) {
+ throw ClientAuthError.createStateMismatchError();
+ }
+ // Check for error
+ if (serverResponseHash.error || serverResponseHash.error_description || serverResponseHash.suberror) {
+ if (InteractionRequiredAuthError.isInteractionRequiredError(serverResponseHash.error, serverResponseHash.error_description, serverResponseHash.suberror)) {
+ throw new InteractionRequiredAuthError(serverResponseHash.error || Constants.EMPTY_STRING, serverResponseHash.error_description, serverResponseHash.suberror);
+ }
+ throw new ServerError(serverResponseHash.error || Constants.EMPTY_STRING, serverResponseHash.error_description, serverResponseHash.suberror);
+ }
+ if (serverResponseHash.client_info) {
+ buildClientInfo(serverResponseHash.client_info, cryptoObj);
+ }
+ };
+ /**
+ * Function which validates server authorization token response.
+ * @param serverResponse
+ */
+ ResponseHandler.prototype.validateTokenResponse = function (serverResponse) {
+ // Check for error
+ if (serverResponse.error || serverResponse.error_description || serverResponse.suberror) {
+ if (InteractionRequiredAuthError.isInteractionRequiredError(serverResponse.error, serverResponse.error_description, serverResponse.suberror)) {
+ throw new InteractionRequiredAuthError(serverResponse.error, serverResponse.error_description, serverResponse.suberror);
+ }
+ var errString = serverResponse.error_codes + " - [" + serverResponse.timestamp + "]: " + serverResponse.error_description + " - Correlation ID: " + serverResponse.correlation_id + " - Trace ID: " + serverResponse.trace_id;
+ throw new ServerError(serverResponse.error, errString);
+ }
+ };
+ /**
+ * Returns a constructed token response based on given string. Also manages the cache updates and cleanups.
+ * @param serverTokenResponse
+ * @param authority
+ */
+ ResponseHandler.prototype.handleServerTokenResponse = function (serverTokenResponse, authority, reqTimestamp, resourceRequestMethod, resourceRequestUri, authCodePayload, requestScopes, oboAssertion, handlingRefreshTokenResponse) {
+ return __awaiter(this, void 0, void 0, function () {
+ var idTokenObj, requestStateObj, cacheRecord, cacheContext, key, account;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ if (serverTokenResponse.id_token) {
+ idTokenObj = new AuthToken(serverTokenResponse.id_token || Constants.EMPTY_STRING, this.cryptoObj);
+ // token nonce check (TODO: Add a warning if no nonce is given?)
+ if (authCodePayload && !StringUtils.isEmpty(authCodePayload.nonce)) {
+ if (idTokenObj.claims.nonce !== authCodePayload.nonce) {
+ throw ClientAuthError.createNonceMismatchError();
+ }
+ }
+ }
+ // generate homeAccountId
+ this.homeAccountIdentifier = AccountEntity.generateHomeAccountId(serverTokenResponse.client_info || Constants.EMPTY_STRING, authority.authorityType, this.logger, this.cryptoObj, idTokenObj);
+ if (!!authCodePayload && !!authCodePayload.state) {
+ requestStateObj = ProtocolUtils.parseRequestState(this.cryptoObj, authCodePayload.state);
+ }
+ cacheRecord = this.generateCacheRecord(serverTokenResponse, authority, reqTimestamp, idTokenObj, requestScopes, oboAssertion, authCodePayload);
+ _a.label = 1;
+ case 1:
+ _a.trys.push([1, , 4, 7]);
+ if (!(this.persistencePlugin && this.serializableCache)) return [3 /*break*/, 3];
+ this.logger.verbose("Persistence enabled, calling beforeCacheAccess");
+ cacheContext = new TokenCacheContext(this.serializableCache, true);
+ return [4 /*yield*/, this.persistencePlugin.beforeCacheAccess(cacheContext)];
+ case 2:
+ _a.sent();
+ _a.label = 3;
+ case 3:
+ /*
+ * When saving a refreshed tokens to the cache, it is expected that the account that was used is present in the cache.
+ * If not present, we should return null, as it's the case that another application called removeAccount in between
+ * the calls to getAllAccounts and acquireTokenSilent. We should not overwrite that removal.
+ */
+ if (handlingRefreshTokenResponse && cacheRecord.account) {
+ key = cacheRecord.account.generateAccountKey();
+ account = this.cacheStorage.getAccount(key);
+ if (!account) {
+ this.logger.warning("Account used to refresh tokens not in persistence, refreshed tokens will not be stored in the cache");
+ return [2 /*return*/, ResponseHandler.generateAuthenticationResult(this.cryptoObj, authority, cacheRecord, false, idTokenObj, requestStateObj, resourceRequestMethod, resourceRequestUri)];
+ }
+ }
+ this.cacheStorage.saveCacheRecord(cacheRecord);
+ return [3 /*break*/, 7];
+ case 4:
+ if (!(this.persistencePlugin && this.serializableCache && cacheContext)) return [3 /*break*/, 6];
+ this.logger.verbose("Persistence enabled, calling afterCacheAccess");
+ return [4 /*yield*/, this.persistencePlugin.afterCacheAccess(cacheContext)];
+ case 5:
+ _a.sent();
+ _a.label = 6;
+ case 6: return [7 /*endfinally*/];
+ case 7: return [2 /*return*/, ResponseHandler.generateAuthenticationResult(this.cryptoObj, authority, cacheRecord, false, idTokenObj, requestStateObj, resourceRequestMethod, resourceRequestUri)];
+ }
+ });
+ });
+ };
+ /**
+ * Generates CacheRecord
+ * @param serverTokenResponse
+ * @param idTokenObj
+ * @param authority
+ */
+ ResponseHandler.prototype.generateCacheRecord = function (serverTokenResponse, authority, reqTimestamp, idTokenObj, requestScopes, oboAssertion, authCodePayload) {
+ var env = authority.getPreferredCache();
+ if (StringUtils.isEmpty(env)) {
+ throw ClientAuthError.createInvalidCacheEnvironmentError();
+ }
+ // IdToken: non AAD scenarios can have empty realm
+ var cachedIdToken;
+ var cachedAccount;
+ if (!StringUtils.isEmpty(serverTokenResponse.id_token) && !!idTokenObj) {
+ cachedIdToken = IdTokenEntity.createIdTokenEntity(this.homeAccountIdentifier, env, serverTokenResponse.id_token || Constants.EMPTY_STRING, this.clientId, idTokenObj.claims.tid || Constants.EMPTY_STRING, oboAssertion);
+ cachedAccount = this.generateAccountEntity(serverTokenResponse, idTokenObj, authority, oboAssertion, authCodePayload);
+ }
+ // AccessToken
+ var cachedAccessToken = null;
+ if (!StringUtils.isEmpty(serverTokenResponse.access_token)) {
+ // If scopes not returned in server response, use request scopes
+ var responseScopes = serverTokenResponse.scope ? ScopeSet.fromString(serverTokenResponse.scope) : new ScopeSet(requestScopes || []);
+ // Use timestamp calculated before request
+ var tokenExpirationSeconds = reqTimestamp + (serverTokenResponse.expires_in || 0);
+ var extendedTokenExpirationSeconds = tokenExpirationSeconds + (serverTokenResponse.ext_expires_in || 0);
+ // non AAD scenarios can have empty realm
+ cachedAccessToken = AccessTokenEntity.createAccessTokenEntity(this.homeAccountIdentifier, env, serverTokenResponse.access_token || Constants.EMPTY_STRING, this.clientId, idTokenObj ? idTokenObj.claims.tid || Constants.EMPTY_STRING : authority.tenant, responseScopes.printScopes(), tokenExpirationSeconds, extendedTokenExpirationSeconds, serverTokenResponse.token_type, oboAssertion);
+ }
+ // refreshToken
+ var cachedRefreshToken = null;
+ if (!StringUtils.isEmpty(serverTokenResponse.refresh_token)) {
+ cachedRefreshToken = RefreshTokenEntity.createRefreshTokenEntity(this.homeAccountIdentifier, env, serverTokenResponse.refresh_token || Constants.EMPTY_STRING, this.clientId, serverTokenResponse.foci, oboAssertion);
+ }
+ // appMetadata
+ var cachedAppMetadata = null;
+ if (!StringUtils.isEmpty(serverTokenResponse.foci)) {
+ cachedAppMetadata = AppMetadataEntity.createAppMetadataEntity(this.clientId, env, serverTokenResponse.foci);
+ }
+ return new CacheRecord(cachedAccount, cachedIdToken, cachedAccessToken, cachedRefreshToken, cachedAppMetadata);
+ };
+ /**
+ * Generate Account
+ * @param serverTokenResponse
+ * @param idToken
+ * @param authority
+ */
+ ResponseHandler.prototype.generateAccountEntity = function (serverTokenResponse, idToken, authority, oboAssertion, authCodePayload) {
+ var authorityType = authority.authorityType;
+ var cloudGraphHostName = authCodePayload ? authCodePayload.cloud_graph_host_name : "";
+ var msGraphhost = authCodePayload ? authCodePayload.msgraph_host : "";
+ // ADFS does not require client_info in the response
+ if (authorityType === AuthorityType.Adfs) {
+ this.logger.verbose("Authority type is ADFS, creating ADFS account");
+ return AccountEntity.createGenericAccount(authority, this.homeAccountIdentifier, idToken, oboAssertion, cloudGraphHostName, msGraphhost);
+ }
+ // This fallback applies to B2C as well as they fall under an AAD account type.
+ if (StringUtils.isEmpty(serverTokenResponse.client_info) && authority.protocolMode === "AAD") {
+ throw ClientAuthError.createClientInfoEmptyError();
+ }
+ return serverTokenResponse.client_info ?
+ AccountEntity.createAccount(serverTokenResponse.client_info, this.homeAccountIdentifier, authority, idToken, oboAssertion, cloudGraphHostName, msGraphhost) :
+ AccountEntity.createGenericAccount(authority, this.homeAccountIdentifier, idToken, oboAssertion, cloudGraphHostName, msGraphhost);
+ };
+ /**
+ * Creates an @AuthenticationResult from @CacheRecord , @IdToken , and a boolean that states whether or not the result is from cache.
+ *
+ * Optionally takes a state string that is set as-is in the response.
+ *
+ * @param cacheRecord
+ * @param idTokenObj
+ * @param fromTokenCache
+ * @param stateString
+ */
+ ResponseHandler.generateAuthenticationResult = function (cryptoObj, authority, cacheRecord, fromTokenCache, idTokenObj, requestState, resourceRequestMethod, resourceRequestUri) {
+ var _a, _b, _c;
+ return __awaiter(this, void 0, void 0, function () {
+ var accessToken, responseScopes, expiresOn, extExpiresOn, familyId, popTokenGenerator, uid, tid;
+ return __generator(this, function (_d) {
+ switch (_d.label) {
+ case 0:
+ accessToken = "";
+ responseScopes = [];
+ expiresOn = null;
+ familyId = Constants.EMPTY_STRING;
+ if (!cacheRecord.accessToken) return [3 /*break*/, 4];
+ if (!(cacheRecord.accessToken.tokenType === AuthenticationScheme.POP)) return [3 /*break*/, 2];
+ popTokenGenerator = new PopTokenGenerator(cryptoObj);
+ if (!resourceRequestMethod || !resourceRequestUri) {
+ throw ClientConfigurationError.createResourceRequestParametersRequiredError();
+ }
+ return [4 /*yield*/, popTokenGenerator.signPopToken(cacheRecord.accessToken.secret, resourceRequestMethod, resourceRequestUri)];
+ case 1:
+ accessToken = _d.sent();
+ return [3 /*break*/, 3];
+ case 2:
+ accessToken = cacheRecord.accessToken.secret;
+ _d.label = 3;
+ case 3:
+ responseScopes = ScopeSet.fromString(cacheRecord.accessToken.target).asArray();
+ expiresOn = new Date(Number(cacheRecord.accessToken.expiresOn) * 1000);
+ extExpiresOn = new Date(Number(cacheRecord.accessToken.extendedExpiresOn) * 1000);
+ _d.label = 4;
+ case 4:
+ if (cacheRecord.appMetadata) {
+ familyId = cacheRecord.appMetadata.familyId === THE_FAMILY_ID ? THE_FAMILY_ID : Constants.EMPTY_STRING;
+ }
+ uid = (idTokenObj === null || idTokenObj === void 0 ? void 0 : idTokenObj.claims.oid) || (idTokenObj === null || idTokenObj === void 0 ? void 0 : idTokenObj.claims.sub) || Constants.EMPTY_STRING;
+ tid = (idTokenObj === null || idTokenObj === void 0 ? void 0 : idTokenObj.claims.tid) || Constants.EMPTY_STRING;
+ return [2 /*return*/, {
+ authority: authority.canonicalAuthority,
+ uniqueId: uid,
+ tenantId: tid,
+ scopes: responseScopes,
+ account: cacheRecord.account ? cacheRecord.account.getAccountInfo() : null,
+ idToken: idTokenObj ? idTokenObj.rawToken : Constants.EMPTY_STRING,
+ idTokenClaims: idTokenObj ? idTokenObj.claims : {},
+ accessToken: accessToken,
+ fromCache: fromTokenCache,
+ expiresOn: expiresOn,
+ extExpiresOn: extExpiresOn,
+ familyId: familyId,
+ tokenType: ((_a = cacheRecord.accessToken) === null || _a === void 0 ? void 0 : _a.tokenType) || Constants.EMPTY_STRING,
+ state: requestState ? requestState.userRequestState : Constants.EMPTY_STRING,
+ cloudGraphHostName: ((_b = cacheRecord.account) === null || _b === void 0 ? void 0 : _b.cloudGraphHostName) || Constants.EMPTY_STRING,
+ msGraphHost: ((_c = cacheRecord.account) === null || _c === void 0 ? void 0 : _c.msGraphHost) || Constants.EMPTY_STRING
+ }];
+ }
+ });
+ });
+ };
+ return ResponseHandler;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Oauth2.0 Authorization Code client
+ */
+var AuthorizationCodeClient = /** @class */ (function (_super) {
+ __extends(AuthorizationCodeClient, _super);
+ function AuthorizationCodeClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Creates the URL of the authorization request letting the user input credentials and consent to the
+ * application. The URL target the /authorize endpoint of the authority configured in the
+ * application object.
+ *
+ * Once the user inputs their credentials and consents, the authority will send a response to the redirect URI
+ * sent in the request and should contain an authorization code, which can then be used to acquire tokens via
+ * acquireToken(AuthorizationCodeRequest)
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.getAuthCodeUrl = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var queryString;
+ return __generator(this, function (_a) {
+ queryString = this.createAuthCodeUrlQueryString(request);
+ return [2 /*return*/, this.authority.authorizationEndpoint + "?" + queryString];
+ });
+ });
+ };
+ /**
+ * API to acquire a token in exchange of 'authorization_code` acquired by the user in the first leg of the
+ * authorization_code_grant
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.acquireToken = function (request, authCodePayload) {
+ return __awaiter(this, void 0, void 0, function () {
+ var reqTimestamp, response, responseHandler;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.logger.info("in acquireToken call");
+ if (!request || StringUtils.isEmpty(request.code)) {
+ throw ClientAuthError.createTokenRequestCannotBeMadeError();
+ }
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executeTokenRequest(this.authority, request)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ // Validate response. This function throws a server error if an error is returned by the server.
+ responseHandler.validateTokenResponse(response.body);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, authCodePayload)];
+ case 2: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Handles the hash fragment response from public client code request. Returns a code response used by
+ * the client to exchange for a token in acquireToken.
+ * @param hashFragment
+ */
+ AuthorizationCodeClient.prototype.handleFragmentResponse = function (hashFragment, cachedState) {
+ // Handle responses.
+ var responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, null, null);
+ // Deserialize hash fragment response parameters.
+ var hashUrlString = new UrlString(hashFragment);
+ // Deserialize hash fragment response parameters.
+ var serverParams = UrlString.getDeserializedHash(hashUrlString.getHash());
+ // Get code response
+ responseHandler.validateServerAuthorizationCodeResponse(serverParams, cachedState, this.cryptoUtils);
+ // throw when there is no auth code in the response
+ if (!serverParams.code) {
+ throw ClientAuthError.createNoAuthCodeInServerResponseError();
+ }
+ return __assign(__assign({}, serverParams), {
+ // Code param is optional in ServerAuthorizationCodeResponse but required in AuthorizationCodePaylod
+ code: serverParams.code });
+ };
+ /**
+ * Use to log out the current user, and redirect the user to the postLogoutRedirectUri.
+ * Default behaviour is to redirect the user to `window.location.href`.
+ * @param authorityUri
+ */
+ AuthorizationCodeClient.prototype.getLogoutUri = function (logoutRequest) {
+ // Throw error if logoutRequest is null/undefined
+ if (!logoutRequest) {
+ throw ClientConfigurationError.createEmptyLogoutRequestError();
+ }
+ if (logoutRequest.account) {
+ // Clear given account.
+ this.cacheManager.removeAccount(AccountEntity.generateAccountCacheKey(logoutRequest.account));
+ }
+ else {
+ // Clear all accounts and tokens
+ this.cacheManager.clear();
+ }
+ var queryString = this.createLogoutUrlQueryString(logoutRequest);
+ // Construct logout URI.
+ return StringUtils.isEmpty(queryString) ? this.authority.endSessionEndpoint : this.authority.endSessionEndpoint + "?" + queryString;
+ };
+ /**
+ * Executes POST request to token endpoint
+ * @param authority
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.executeTokenRequest = function (authority, request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var thumbprint, requestBody, headers;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: authority.canonicalAuthority,
+ scopes: request.scopes
+ };
+ return [4 /*yield*/, this.createTokenRequestBody(request)];
+ case 1:
+ requestBody = _a.sent();
+ headers = this.createDefaultTokenRequestHeaders();
+ return [2 /*return*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ }
+ });
+ });
+ };
+ /**
+ * Generates a map for all the params to be sent to the service
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.createTokenRequestBody = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var parameterBuilder, clientAssertion, popTokenGenerator, cnfString, correlationId;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ // validate the redirectUri (to be a non null value)
+ parameterBuilder.addRedirectUri(request.redirectUri);
+ // Add scope array, parameter builder will add default scopes and dedupe
+ parameterBuilder.addScopes(request.scopes);
+ // add code: user set, not validated
+ parameterBuilder.addAuthorizationCode(request.code);
+ // add code_verifier if passed
+ if (request.codeVerifier) {
+ parameterBuilder.addCodeVerifier(request.codeVerifier);
+ }
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ parameterBuilder.addGrantType(GrantType.AUTHORIZATION_CODE_GRANT);
+ parameterBuilder.addClientInfo();
+ if (!(request.authenticationScheme === AuthenticationScheme.POP && !!request.resourceRequestMethod && !!request.resourceRequestUri)) return [3 /*break*/, 2];
+ popTokenGenerator = new PopTokenGenerator(this.cryptoUtils);
+ return [4 /*yield*/, popTokenGenerator.generateCnf(request.resourceRequestMethod, request.resourceRequestUri)];
+ case 1:
+ cnfString = _a.sent();
+ parameterBuilder.addPopToken(cnfString);
+ _a.label = 2;
+ case 2:
+ correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return [2 /*return*/, parameterBuilder.createQueryString()];
+ }
+ });
+ });
+ };
+ /**
+ * This API validates the `AuthorizationCodeUrlRequest` and creates a URL
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.createAuthCodeUrlQueryString = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ var requestScopes = __spreadArrays(request.scopes || [], request.extraScopesToConsent || []);
+ parameterBuilder.addScopes(requestScopes);
+ // validate the redirectUri (to be a non null value)
+ parameterBuilder.addRedirectUri(request.redirectUri);
+ // generate the correlationId if not set by the user and add
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ // add response_mode. If not passed in it defaults to query.
+ parameterBuilder.addResponseMode(request.responseMode);
+ // add response_type = code
+ parameterBuilder.addResponseTypeCode();
+ // add library info parameters
+ parameterBuilder.addLibraryInfo(this.config.libraryInfo);
+ // add client_info=1
+ parameterBuilder.addClientInfo();
+ if (request.codeChallenge && request.codeChallengeMethod) {
+ parameterBuilder.addCodeChallengeParams(request.codeChallenge, request.codeChallengeMethod);
+ }
+ if (request.prompt) {
+ parameterBuilder.addPrompt(request.prompt);
+ }
+ if (request.domainHint) {
+ parameterBuilder.addDomainHint(request.domainHint);
+ }
+ // Add sid or loginHint with preference for sid -> loginHint -> username of AccountInfo object
+ if (request.sid) {
+ parameterBuilder.addSid(request.sid);
+ }
+ else if (request.loginHint) {
+ parameterBuilder.addLoginHint(request.loginHint);
+ }
+ else if (request.account && request.account.username) {
+ parameterBuilder.addLoginHint(request.account.username);
+ }
+ if (request.nonce) {
+ parameterBuilder.addNonce(request.nonce);
+ }
+ if (request.state) {
+ parameterBuilder.addState(request.state);
+ }
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ if (request.extraQueryParameters) {
+ parameterBuilder.addExtraQueryParameters(request.extraQueryParameters);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ /**
+ * This API validates the `EndSessionRequest` and creates a URL
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.createLogoutUrlQueryString = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ if (request.postLogoutRedirectUri) {
+ parameterBuilder.addPostLogoutRedirectUri(request.postLogoutRedirectUri);
+ }
+ if (request.correlationId) {
+ parameterBuilder.addCorrelationId(request.correlationId);
+ }
+ if (request.idTokenHint) {
+ parameterBuilder.addIdTokenHint(request.idTokenHint);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return AuthorizationCodeClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * OAuth2.0 Device code client
+ */
+var DeviceCodeClient = /** @class */ (function (_super) {
+ __extends(DeviceCodeClient, _super);
+ function DeviceCodeClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Gets device code from device code endpoint, calls back to with device code response, and
+ * polls token endpoint to exchange device code for tokens
+ * @param request
+ */
+ DeviceCodeClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var deviceCodeResponse, reqTimestamp, response, responseHandler;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.getDeviceCode(request)];
+ case 1:
+ deviceCodeResponse = _a.sent();
+ request.deviceCodeCallback(deviceCodeResponse);
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.acquireTokenWithDeviceCode(request, deviceCodeResponse)];
+ case 2:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ // Validate response. This function throws a server error if an error is returned by the server.
+ responseHandler.validateTokenResponse(response);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri)];
+ case 3: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Creates device code request and executes http GET
+ * @param request
+ */
+ DeviceCodeClient.prototype.getDeviceCode = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var queryString, headers, thumbprint;
+ return __generator(this, function (_a) {
+ queryString = this.createQueryString(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ return [2 /*return*/, this.executePostRequestToDeviceCodeEndpoint(this.authority.deviceCodeEndpoint, queryString, headers, thumbprint)];
+ });
+ });
+ };
+ /**
+ * Executes POST request to device code endpoint
+ * @param deviceCodeEndpoint
+ * @param queryString
+ * @param headers
+ */
+ DeviceCodeClient.prototype.executePostRequestToDeviceCodeEndpoint = function (deviceCodeEndpoint, queryString, headers, thumbprint) {
+ return __awaiter(this, void 0, void 0, function () {
+ var _a, userCode, deviceCode, verificationUri, expiresIn, interval, message;
+ return __generator(this, function (_b) {
+ switch (_b.label) {
+ case 0: return [4 /*yield*/, this.networkManager.sendPostRequest(thumbprint, deviceCodeEndpoint, {
+ body: queryString,
+ headers: headers
+ })];
+ case 1:
+ _a = (_b.sent()).body, userCode = _a.user_code, deviceCode = _a.device_code, verificationUri = _a.verification_uri, expiresIn = _a.expires_in, interval = _a.interval, message = _a.message;
+ return [2 /*return*/, {
+ userCode: userCode,
+ deviceCode: deviceCode,
+ verificationUri: verificationUri,
+ expiresIn: expiresIn,
+ interval: interval,
+ message: message
+ }];
+ }
+ });
+ });
+ };
+ /**
+ * Create device code endpoint query parameters and returns string
+ */
+ DeviceCodeClient.prototype.createQueryString = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ /**
+ * Creates token request with device code response and polls token endpoint at interval set by the device code
+ * response
+ * @param request
+ * @param deviceCodeResponse
+ */
+ DeviceCodeClient.prototype.acquireTokenWithDeviceCode = function (request, deviceCodeResponse) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, userSpecifiedTimeout, deviceCodeExpirationTime, pollingIntervalMilli;
+ var _this = this;
+ return __generator(this, function (_a) {
+ requestBody = this.createTokenRequestBody(request, deviceCodeResponse);
+ headers = this.createDefaultTokenRequestHeaders();
+ userSpecifiedTimeout = request.timeout ? TimeUtils.nowSeconds() + request.timeout : undefined;
+ deviceCodeExpirationTime = TimeUtils.nowSeconds() + deviceCodeResponse.expiresIn;
+ pollingIntervalMilli = deviceCodeResponse.interval * 1000;
+ /*
+ * Poll token endpoint while (device code is not expired AND operation has not been cancelled by
+ * setting CancellationToken.cancel = true). POST request is sent at interval set by pollingIntervalMilli
+ */
+ return [2 /*return*/, new Promise(function (resolve, reject) {
+ var intervalId = setInterval(function () { return __awaiter(_this, void 0, void 0, function () {
+ var thumbprint, response, error_1;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ _a.trys.push([0, 6, , 7]);
+ if (!request.cancel) return [3 /*break*/, 1];
+ this.logger.error("Token request cancelled by setting DeviceCodeRequest.cancel = true");
+ clearInterval(intervalId);
+ reject(ClientAuthError.createDeviceCodeCancelledError());
+ return [3 /*break*/, 5];
+ case 1:
+ if (!(userSpecifiedTimeout && userSpecifiedTimeout < deviceCodeExpirationTime && TimeUtils.nowSeconds() > userSpecifiedTimeout)) return [3 /*break*/, 2];
+ this.logger.error("User defined timeout for device code polling reached. The timeout was set for " + userSpecifiedTimeout);
+ clearInterval(intervalId);
+ reject(ClientAuthError.createUserTimeoutReachedError());
+ return [3 /*break*/, 5];
+ case 2:
+ if (!(TimeUtils.nowSeconds() > deviceCodeExpirationTime)) return [3 /*break*/, 3];
+ if (userSpecifiedTimeout) {
+ this.logger.verbose("User specified timeout ignored as the device code has expired before the timeout elapsed. The user specified timeout was set for " + userSpecifiedTimeout);
+ }
+ this.logger.error("Device code expired. Expiration time of device code was " + deviceCodeExpirationTime);
+ clearInterval(intervalId);
+ reject(ClientAuthError.createDeviceCodeExpiredError());
+ return [3 /*break*/, 5];
+ case 3:
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ return [4 /*yield*/, this.executePostToTokenEndpoint(this.authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ case 4:
+ response = _a.sent();
+ if (response.body && response.body.error === Constants.AUTHORIZATION_PENDING) {
+ // user authorization is pending. Sleep for polling interval and try again
+ this.logger.info(response.body.error_description || "no_error_description");
+ }
+ else {
+ clearInterval(intervalId);
+ resolve(response.body);
+ }
+ _a.label = 5;
+ case 5: return [3 /*break*/, 7];
+ case 6:
+ error_1 = _a.sent();
+ clearInterval(intervalId);
+ reject(error_1);
+ return [3 /*break*/, 7];
+ case 7: return [2 /*return*/];
+ }
+ });
+ }); }, pollingIntervalMilli);
+ })];
+ });
+ });
+ };
+ /**
+ * Creates query parameters and converts to string.
+ * @param request
+ * @param deviceCodeResponse
+ */
+ DeviceCodeClient.prototype.createTokenRequestBody = function (request, deviceCodeResponse) {
+ var requestParameters = new RequestParameterBuilder();
+ requestParameters.addScopes(request.scopes);
+ requestParameters.addClientId(this.config.authOptions.clientId);
+ requestParameters.addGrantType(GrantType.DEVICE_CODE_GRANT);
+ requestParameters.addDeviceCode(deviceCodeResponse.deviceCode);
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ requestParameters.addCorrelationId(correlationId);
+ requestParameters.addClientInfo();
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ requestParameters.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return requestParameters.createQueryString();
+ };
+ return DeviceCodeClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * OAuth2.0 refresh token client
+ */
+var RefreshTokenClient = /** @class */ (function (_super) {
+ __extends(RefreshTokenClient, _super);
+ function RefreshTokenClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ RefreshTokenClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var reqTimestamp, response, responseHandler;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ responseHandler.validateTokenResponse(response.body);
+ return [2 /*return*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, undefined, [], undefined, true)];
+ }
+ });
+ });
+ };
+ /**
+ * Gets cached refresh token and attaches to request, then calls acquireToken API
+ * @param request
+ */
+ RefreshTokenClient.prototype.acquireTokenByRefreshToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var isFOCI, noFamilyRTInCache, clientMismatchErrorWithFamilyRT;
+ return __generator(this, function (_a) {
+ // Cannot renew token if no request object is given.
+ if (!request) {
+ throw ClientConfigurationError.createEmptyTokenRequestError();
+ }
+ // We currently do not support silent flow for account === null use cases; This will be revisited for confidential flow usecases
+ if (!request.account) {
+ throw ClientAuthError.createNoAccountInSilentRequestError();
+ }
+ isFOCI = this.cacheManager.isAppMetadataFOCI(request.account.environment, this.config.authOptions.clientId);
+ // if the app is part of the family, retrive a Family refresh token if present and make a refreshTokenRequest
+ if (isFOCI) {
+ try {
+ return [2 /*return*/, this.acquireTokenWithCachedRefreshToken(request, true)];
+ }
+ catch (e) {
+ noFamilyRTInCache = e instanceof ClientAuthError && e.errorCode === ClientAuthErrorMessage.noTokensFoundError.code;
+ clientMismatchErrorWithFamilyRT = e instanceof ServerError && e.errorCode === Errors.INVALID_GRANT_ERROR && e.subError === Errors.CLIENT_MISMATCH_ERROR;
+ // if family Refresh Token (FRT) cache acquisition fails or if client_mismatch error is seen with FRT, reattempt with application Refresh Token (ART)
+ if (noFamilyRTInCache || clientMismatchErrorWithFamilyRT) {
+ return [2 /*return*/, this.acquireTokenWithCachedRefreshToken(request, false)];
+ // throw in all other cases
+ }
+ else {
+ throw e;
+ }
+ }
+ }
+ // fall back to application refresh token acquisition
+ return [2 /*return*/, this.acquireTokenWithCachedRefreshToken(request, false)];
+ });
+ });
+ };
+ /**
+ * makes a network call to acquire tokens by exchanging RefreshToken available in userCache; throws if refresh token is not cached
+ * @param request
+ */
+ RefreshTokenClient.prototype.acquireTokenWithCachedRefreshToken = function (request, foci) {
+ return __awaiter(this, void 0, void 0, function () {
+ var refreshToken, refreshTokenRequest;
+ return __generator(this, function (_a) {
+ refreshToken = this.cacheManager.readRefreshTokenFromCache(this.config.authOptions.clientId, request.account, foci);
+ // no refresh Token
+ if (!refreshToken) {
+ throw ClientAuthError.createNoTokensFoundError();
+ }
+ refreshTokenRequest = __assign(__assign({}, request), { refreshToken: refreshToken.secret, authenticationScheme: AuthenticationScheme.BEARER });
+ return [2 /*return*/, this.acquireToken(refreshTokenRequest)];
+ });
+ });
+ };
+ /**
+ * Constructs the network message and makes a NW call to the underlying secure token service
+ * @param request
+ * @param authority
+ */
+ RefreshTokenClient.prototype.executeTokenRequest = function (request, authority) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, thumbprint;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.createTokenRequestBody(request)];
+ case 1:
+ requestBody = _a.sent();
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: authority.canonicalAuthority,
+ scopes: request.scopes
+ };
+ return [2 /*return*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ }
+ });
+ });
+ };
+ /**
+ * Helper function to create the token request body
+ * @param request
+ */
+ RefreshTokenClient.prototype.createTokenRequestBody = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var parameterBuilder, correlationId, clientAssertion, popTokenGenerator, _a, _b;
+ return __generator(this, function (_c) {
+ switch (_c.label) {
+ case 0:
+ parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addGrantType(GrantType.REFRESH_TOKEN_GRANT);
+ parameterBuilder.addClientInfo();
+ correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ parameterBuilder.addRefreshToken(request.refreshToken);
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ if (!(request.authenticationScheme === AuthenticationScheme.POP)) return [3 /*break*/, 2];
+ popTokenGenerator = new PopTokenGenerator(this.cryptoUtils);
+ if (!request.resourceRequestMethod || !request.resourceRequestUri) {
+ throw ClientConfigurationError.createResourceRequestParametersRequiredError();
+ }
+ _b = (_a = parameterBuilder).addPopToken;
+ return [4 /*yield*/, popTokenGenerator.generateCnf(request.resourceRequestMethod, request.resourceRequestUri)];
+ case 1:
+ _b.apply(_a, [_c.sent()]);
+ _c.label = 2;
+ case 2:
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return [2 /*return*/, parameterBuilder.createQueryString()];
+ }
+ });
+ });
+ };
+ return RefreshTokenClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * OAuth2.0 client credential grant
+ */
+var ClientCredentialClient = /** @class */ (function (_super) {
+ __extends(ClientCredentialClient, _super);
+ function ClientCredentialClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Public API to acquire a token with ClientCredential Flow for Confidential clients
+ * @param request
+ */
+ ClientCredentialClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAuthenticationResult;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.scopeSet = new ScopeSet(request.scopes || []);
+ if (!request.skipCache) return [3 /*break*/, 2];
+ return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 1: return [2 /*return*/, _a.sent()];
+ case 2: return [4 /*yield*/, this.getCachedAuthenticationResult()];
+ case 3:
+ cachedAuthenticationResult = _a.sent();
+ if (!cachedAuthenticationResult) return [3 /*break*/, 4];
+ return [2 /*return*/, cachedAuthenticationResult];
+ case 4: return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 5: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * looks up cache if the tokens are cached already
+ */
+ ClientCredentialClient.prototype.getCachedAuthenticationResult = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAccessToken;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ cachedAccessToken = this.readAccessTokenFromCache();
+ if (!cachedAccessToken ||
+ TimeUtils.isTokenExpired(cachedAccessToken.expiresOn, this.config.systemOptions.tokenRenewalOffsetSeconds)) {
+ return [2 /*return*/, null];
+ }
+ return [4 /*yield*/, ResponseHandler.generateAuthenticationResult(this.cryptoUtils, this.authority, {
+ account: null,
+ idToken: null,
+ accessToken: cachedAccessToken,
+ refreshToken: null,
+ appMetadata: null
+ }, true)];
+ case 1: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Reads access token from the cache
+ * TODO: Move this call to cacheManager instead
+ */
+ ClientCredentialClient.prototype.readAccessTokenFromCache = function () {
+ var accessTokenFilter = {
+ homeAccountId: "",
+ environment: this.authority.canonicalAuthorityUrlComponents.HostNameAndPort,
+ credentialType: CredentialType.ACCESS_TOKEN,
+ clientId: this.config.authOptions.clientId,
+ realm: this.authority.tenant,
+ target: this.scopeSet.printScopesLowerCase()
+ };
+ var credentialCache = this.cacheManager.getCredentialsFilteredBy(accessTokenFilter);
+ var accessTokens = Object.keys(credentialCache.accessTokens).map(function (key) { return credentialCache.accessTokens[key]; });
+ if (accessTokens.length < 1) {
+ return null;
+ }
+ else if (accessTokens.length > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return accessTokens[0];
+ };
+ /**
+ * Makes a network call to request the token from the service
+ * @param request
+ * @param authority
+ */
+ ClientCredentialClient.prototype.executeTokenRequest = function (request, authority) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, thumbprint, reqTimestamp, response, responseHandler, tokenResponse;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ requestBody = this.createTokenRequestBody(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ responseHandler.validateTokenResponse(response.body);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, undefined, request.scopes)];
+ case 2:
+ tokenResponse = _a.sent();
+ return [2 /*return*/, tokenResponse];
+ }
+ });
+ });
+ };
+ /**
+ * generate the request to the server in the acceptable format
+ * @param request
+ */
+ ClientCredentialClient.prototype.createTokenRequestBody = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addScopes(request.scopes, false);
+ parameterBuilder.addGrantType(GrantType.CLIENT_CREDENTIALS_GRANT);
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ var clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return ClientCredentialClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * On-Behalf-Of client
+ */
+var OnBehalfOfClient = /** @class */ (function (_super) {
+ __extends(OnBehalfOfClient, _super);
+ function OnBehalfOfClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Public API to acquire tokens with on behalf of flow
+ * @param request
+ */
+ OnBehalfOfClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAuthenticationResult;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.scopeSet = new ScopeSet(request.scopes || []);
+ if (!request.skipCache) return [3 /*break*/, 2];
+ return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 1: return [2 /*return*/, _a.sent()];
+ case 2: return [4 /*yield*/, this.getCachedAuthenticationResult(request)];
+ case 3:
+ cachedAuthenticationResult = _a.sent();
+ if (!cachedAuthenticationResult) return [3 /*break*/, 4];
+ return [2 /*return*/, cachedAuthenticationResult];
+ case 4: return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 5: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * look up cache for tokens
+ * @param request
+ */
+ OnBehalfOfClient.prototype.getCachedAuthenticationResult = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAccessToken, cachedIdToken, idTokenObject, cachedAccount, localAccountId, accountInfo;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ cachedAccessToken = this.readAccessTokenFromCache(request);
+ if (!cachedAccessToken ||
+ TimeUtils.isTokenExpired(cachedAccessToken.expiresOn, this.config.systemOptions.tokenRenewalOffsetSeconds)) {
+ return [2 /*return*/, null];
+ }
+ cachedIdToken = this.readIdTokenFromCache(request);
+ cachedAccount = null;
+ if (cachedIdToken) {
+ idTokenObject = new AuthToken(cachedIdToken.secret, this.config.cryptoInterface);
+ localAccountId = idTokenObject.claims.oid ? idTokenObject.claims.oid : idTokenObject.claims.sub;
+ accountInfo = {
+ homeAccountId: cachedIdToken.homeAccountId,
+ environment: cachedIdToken.environment,
+ tenantId: cachedIdToken.realm,
+ username: Constants.EMPTY_STRING,
+ localAccountId: localAccountId || ""
+ };
+ cachedAccount = this.readAccountFromCache(accountInfo);
+ }
+ return [4 /*yield*/, ResponseHandler.generateAuthenticationResult(this.cryptoUtils, this.authority, {
+ account: cachedAccount,
+ accessToken: cachedAccessToken,
+ idToken: cachedIdToken,
+ refreshToken: null,
+ appMetadata: null
+ }, true, idTokenObject)];
+ case 1: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * read access token from cache TODO: CacheManager API should be used here
+ * @param request
+ */
+ OnBehalfOfClient.prototype.readAccessTokenFromCache = function (request) {
+ var accessTokenFilter = {
+ environment: this.authority.canonicalAuthorityUrlComponents.HostNameAndPort,
+ credentialType: CredentialType.ACCESS_TOKEN,
+ clientId: this.config.authOptions.clientId,
+ realm: this.authority.tenant,
+ target: this.scopeSet.printScopesLowerCase(),
+ oboAssertion: request.oboAssertion
+ };
+ var credentialCache = this.cacheManager.getCredentialsFilteredBy(accessTokenFilter);
+ var accessTokens = Object.keys(credentialCache.accessTokens).map(function (key) { return credentialCache.accessTokens[key]; });
+ var numAccessTokens = accessTokens.length;
+ if (numAccessTokens < 1) {
+ return null;
+ }
+ else if (numAccessTokens > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return accessTokens[0];
+ };
+ /**
+ * read idtoken from cache TODO: CacheManager API should be used here instead
+ * @param request
+ */
+ OnBehalfOfClient.prototype.readIdTokenFromCache = function (request) {
+ var idTokenFilter = {
+ environment: this.authority.canonicalAuthorityUrlComponents.HostNameAndPort,
+ credentialType: CredentialType.ID_TOKEN,
+ clientId: this.config.authOptions.clientId,
+ realm: this.authority.tenant,
+ oboAssertion: request.oboAssertion
+ };
+ var credentialCache = this.cacheManager.getCredentialsFilteredBy(idTokenFilter);
+ var idTokens = Object.keys(credentialCache.idTokens).map(function (key) { return credentialCache.idTokens[key]; });
+ // When acquiring a token on behalf of an application, there might not be an id token in the cache
+ if (idTokens.length < 1) {
+ return null;
+ }
+ return idTokens[0];
+ };
+ /**
+ * read account from cache, TODO: CacheManager API should be used here instead
+ * @param account
+ */
+ OnBehalfOfClient.prototype.readAccountFromCache = function (account) {
+ return this.cacheManager.readAccountFromCache(account);
+ };
+ /**
+ * Make a network call to the server requesting credentials
+ * @param request
+ * @param authority
+ */
+ OnBehalfOfClient.prototype.executeTokenRequest = function (request, authority) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, thumbprint, reqTimestamp, response, responseHandler, tokenResponse;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ requestBody = this.createTokenRequestBody(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ responseHandler.validateTokenResponse(response.body);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, undefined, request.scopes, request.oboAssertion)];
+ case 2:
+ tokenResponse = _a.sent();
+ return [2 /*return*/, tokenResponse];
+ }
+ });
+ });
+ };
+ /**
+ * generate a server request in accepable format
+ * @param request
+ */
+ OnBehalfOfClient.prototype.createTokenRequestBody = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addGrantType(GrantType.JWT_BEARER);
+ parameterBuilder.addClientInfo();
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ parameterBuilder.addRequestTokenUse(AADServerParamKeys.ON_BEHALF_OF);
+ parameterBuilder.addOboAssertion(request.oboAssertion);
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ var clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return OnBehalfOfClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var SilentFlowClient = /** @class */ (function (_super) {
+ __extends(SilentFlowClient, _super);
+ function SilentFlowClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Retrieves a token from cache if it is still valid, or uses the cached refresh token to renew
+ * the given token and returns the renewed token
+ * @param request
+ */
+ SilentFlowClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var e_1, refreshTokenClient;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ _a.trys.push([0, 2, , 3]);
+ return [4 /*yield*/, this.acquireCachedToken(request)];
+ case 1: return [2 /*return*/, _a.sent()];
+ case 2:
+ e_1 = _a.sent();
+ if (e_1 instanceof ClientAuthError && e_1.errorCode === ClientAuthErrorMessage.tokenRefreshRequired.code) {
+ refreshTokenClient = new RefreshTokenClient(this.config);
+ return [2 /*return*/, refreshTokenClient.acquireTokenByRefreshToken(request)];
+ }
+ else {
+ throw e_1;
+ }
+ case 3: return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Retrieves token from cache or throws an error if it must be refreshed.
+ * @param request
+ */
+ SilentFlowClient.prototype.acquireCachedToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestScopes, environment, cacheRecord;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ // Cannot renew token if no request object is given.
+ if (!request) {
+ throw ClientConfigurationError.createEmptyTokenRequestError();
+ }
+ // We currently do not support silent flow for account === null use cases; This will be revisited for confidential flow usecases
+ if (!request.account) {
+ throw ClientAuthError.createNoAccountInSilentRequestError();
+ }
+ requestScopes = new ScopeSet(request.scopes || []);
+ environment = request.authority || this.authority.getPreferredCache();
+ cacheRecord = this.cacheManager.readCacheRecord(request.account, this.config.authOptions.clientId, requestScopes, environment);
+ if (!this.isRefreshRequired(request, cacheRecord.accessToken)) return [3 /*break*/, 1];
+ throw ClientAuthError.createRefreshRequiredError();
+ case 1:
+ if (this.config.serverTelemetryManager) {
+ this.config.serverTelemetryManager.incrementCacheHits();
+ }
+ return [4 /*yield*/, this.generateResultFromCacheRecord(cacheRecord, request.resourceRequestMethod, request.resourceRequestUri)];
+ case 2: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Helper function to build response object from the CacheRecord
+ * @param cacheRecord
+ */
+ SilentFlowClient.prototype.generateResultFromCacheRecord = function (cacheRecord, resourceRequestMethod, resourceRequestUri) {
+ return __awaiter(this, void 0, void 0, function () {
+ var idTokenObj;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ if (cacheRecord.idToken) {
+ idTokenObj = new AuthToken(cacheRecord.idToken.secret, this.config.cryptoInterface);
+ }
+ return [4 /*yield*/, ResponseHandler.generateAuthenticationResult(this.cryptoUtils, this.authority, cacheRecord, true, idTokenObj, undefined, resourceRequestMethod, resourceRequestUri)];
+ case 1: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Given a request object and an accessTokenEntity determine if the accessToken needs to be refreshed
+ * @param request
+ * @param cachedAccessToken
+ */
+ SilentFlowClient.prototype.isRefreshRequired = function (request, cachedAccessToken) {
+ if (request.forceRefresh || request.claims) {
+ // Must refresh due to request parameters
+ return true;
+ }
+ else if (!cachedAccessToken || TimeUtils.isTokenExpired(cachedAccessToken.expiresOn, this.config.systemOptions.tokenRenewalOffsetSeconds)) {
+ // Must refresh due to expired or non-existent access_token
+ return true;
+ }
+ return false;
+ };
+ return SilentFlowClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Oauth2.0 Password grant client
+ * Note: We are only supporting public clients for password grant and for purely testing purposes
+ */
+var UsernamePasswordClient = /** @class */ (function (_super) {
+ __extends(UsernamePasswordClient, _super);
+ function UsernamePasswordClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * API to acquire a token by passing the username and password to the service in exchage of credentials
+ * password_grant
+ * @param request
+ */
+ UsernamePasswordClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var reqTimestamp, response, responseHandler, tokenResponse;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.logger.info("in acquireToken call");
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executeTokenRequest(this.authority, request)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ // Validate response. This function throws a server error if an error is returned by the server.
+ responseHandler.validateTokenResponse(response.body);
+ tokenResponse = responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp);
+ return [2 /*return*/, tokenResponse];
+ }
+ });
+ });
+ };
+ /**
+ * Executes POST request to token endpoint
+ * @param authority
+ * @param request
+ */
+ UsernamePasswordClient.prototype.executeTokenRequest = function (authority, request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var thumbprint, requestBody, headers;
+ return __generator(this, function (_a) {
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: authority.canonicalAuthority,
+ scopes: request.scopes
+ };
+ requestBody = this.createTokenRequestBody(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ return [2 /*return*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ });
+ });
+ };
+ /**
+ * Generates a map for all the params to be sent to the service
+ * @param request
+ */
+ UsernamePasswordClient.prototype.createTokenRequestBody = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addUsername(request.username);
+ parameterBuilder.addPassword(request.password);
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addGrantType(GrantType.RESOURCE_OWNER_PASSWORD_GRANT);
+ parameterBuilder.addClientInfo();
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return UsernamePasswordClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+function isOpenIdConfigResponse(response) {
+ return (response.hasOwnProperty("authorization_endpoint") &&
+ response.hasOwnProperty("token_endpoint") &&
+ response.hasOwnProperty("end_session_endpoint") &&
+ response.hasOwnProperty("issuer"));
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Protocol modes supported by MSAL.
+ */
+var ProtocolMode;
+(function (ProtocolMode) {
+ ProtocolMode["AAD"] = "AAD";
+ ProtocolMode["OIDC"] = "OIDC";
+})(ProtocolMode || (ProtocolMode = {}));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var AuthorityMetadataEntity = /** @class */ (function () {
+ function AuthorityMetadataEntity() {
+ this.expiresAt = TimeUtils.nowSeconds() + AUTHORITY_METADATA_CONSTANTS.REFRESH_TIME_SECONDS;
+ }
+ /**
+ * Update the entity with new aliases, preferred_cache and preferred_network values
+ * @param metadata
+ * @param fromNetwork
+ */
+ AuthorityMetadataEntity.prototype.updateCloudDiscoveryMetadata = function (metadata, fromNetwork) {
+ this.aliases = metadata.aliases;
+ this.preferred_cache = metadata.preferred_cache;
+ this.preferred_network = metadata.preferred_network;
+ this.aliasesFromNetwork = fromNetwork;
+ };
+ /**
+ * Update the entity with new endpoints
+ * @param metadata
+ * @param fromNetwork
+ */
+ AuthorityMetadataEntity.prototype.updateEndpointMetadata = function (metadata, fromNetwork) {
+ this.authorization_endpoint = metadata.authorization_endpoint;
+ this.token_endpoint = metadata.token_endpoint;
+ this.end_session_endpoint = metadata.end_session_endpoint;
+ this.issuer = metadata.issuer;
+ this.endpointsFromNetwork = fromNetwork;
+ };
+ /**
+ * Save the authority that was used to create this cache entry
+ * @param authority
+ */
+ AuthorityMetadataEntity.prototype.updateCanonicalAuthority = function (authority) {
+ this.canonical_authority = authority;
+ };
+ /**
+ * Reset the exiresAt value
+ */
+ AuthorityMetadataEntity.prototype.resetExpiresAt = function () {
+ this.expiresAt = TimeUtils.nowSeconds() + AUTHORITY_METADATA_CONSTANTS.REFRESH_TIME_SECONDS;
+ };
+ /**
+ * Returns whether or not the data needs to be refreshed
+ */
+ AuthorityMetadataEntity.prototype.isExpired = function () {
+ return this.expiresAt <= TimeUtils.nowSeconds();
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AuthorityMetadataEntity.isAuthorityMetadataEntity = function (key, entity) {
+ if (!entity) {
+ return false;
+ }
+ return (key.indexOf(AUTHORITY_METADATA_CONSTANTS.CACHE_KEY) === 0 &&
+ entity.hasOwnProperty("aliases") &&
+ entity.hasOwnProperty("preferred_cache") &&
+ entity.hasOwnProperty("preferred_network") &&
+ entity.hasOwnProperty("canonical_authority") &&
+ entity.hasOwnProperty("authorization_endpoint") &&
+ entity.hasOwnProperty("token_endpoint") &&
+ entity.hasOwnProperty("end_session_endpoint") &&
+ entity.hasOwnProperty("issuer") &&
+ entity.hasOwnProperty("aliasesFromNetwork") &&
+ entity.hasOwnProperty("endpointsFromNetwork") &&
+ entity.hasOwnProperty("expiresAt"));
+ };
+ return AuthorityMetadataEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+function isCloudInstanceDiscoveryResponse(response) {
+ return (response.hasOwnProperty("tenant_discovery_endpoint") &&
+ response.hasOwnProperty("metadata"));
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * The authority class validates the authority URIs used by the user, and retrieves the OpenID Configuration Data from the
+ * endpoint. It will store the pertinent config data in this object for use during token calls.
+ */
+var Authority = /** @class */ (function () {
+ function Authority(authority, networkInterface, cacheManager, authorityOptions) {
+ this.canonicalAuthority = authority;
+ this._canonicalAuthority.validateAsUri();
+ this.networkInterface = networkInterface;
+ this.cacheManager = cacheManager;
+ this.authorityOptions = authorityOptions;
+ }
+ Object.defineProperty(Authority.prototype, "authorityType", {
+ // See above for AuthorityType
+ get: function () {
+ var pathSegments = this.canonicalAuthorityUrlComponents.PathSegments;
+ if (pathSegments.length && pathSegments[0].toLowerCase() === Constants.ADFS) {
+ return AuthorityType.Adfs;
+ }
+ return AuthorityType.Default;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "protocolMode", {
+ /**
+ * ProtocolMode enum representing the way endpoints are constructed.
+ */
+ get: function () {
+ return this.authorityOptions.protocolMode;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "options", {
+ /**
+ * Returns authorityOptions which can be used to reinstantiate a new authority instance
+ */
+ get: function () {
+ return this.authorityOptions;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "canonicalAuthority", {
+ /**
+ * A URL that is the authority set by the developer
+ */
+ get: function () {
+ return this._canonicalAuthority.urlString;
+ },
+ /**
+ * Sets canonical authority.
+ */
+ set: function (url) {
+ this._canonicalAuthority = new UrlString(url);
+ this._canonicalAuthority.validateAsUri();
+ this._canonicalAuthorityUrlComponents = null;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "canonicalAuthorityUrlComponents", {
+ /**
+ * Get authority components.
+ */
+ get: function () {
+ if (!this._canonicalAuthorityUrlComponents) {
+ this._canonicalAuthorityUrlComponents = this._canonicalAuthority.getUrlComponents();
+ }
+ return this._canonicalAuthorityUrlComponents;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "hostnameAndPort", {
+ /**
+ * Get hostname and port i.e. login.microsoftonline.com
+ */
+ get: function () {
+ return this.canonicalAuthorityUrlComponents.HostNameAndPort.toLowerCase();
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "tenant", {
+ /**
+ * Get tenant for authority.
+ */
+ get: function () {
+ return this.canonicalAuthorityUrlComponents.PathSegments[0];
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "authorizationEndpoint", {
+ /**
+ * OAuth /authorize endpoint for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.authorization_endpoint);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "tokenEndpoint", {
+ /**
+ * OAuth /token endpoint for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.token_endpoint);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "deviceCodeEndpoint", {
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.token_endpoint.replace("/token", "/devicecode"));
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "endSessionEndpoint", {
+ /**
+ * OAuth logout endpoint for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.end_session_endpoint);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "selfSignedJwtAudience", {
+ /**
+ * OAuth issuer for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.issuer);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ /**
+ * Replaces tenant in url path with current tenant. Defaults to common.
+ * @param urlString
+ */
+ Authority.prototype.replaceTenant = function (urlString) {
+ return urlString.replace(/{tenant}|{tenantid}/g, this.tenant);
+ };
+ /**
+ * Replaces path such as tenant or policy with the current tenant or policy.
+ * @param urlString
+ */
+ Authority.prototype.replacePath = function (urlString) {
+ var endpoint = urlString;
+ var cachedAuthorityUrl = new UrlString(this.metadata.canonical_authority);
+ var cachedAuthorityParts = cachedAuthorityUrl.getUrlComponents().PathSegments;
+ var currentAuthorityParts = this.canonicalAuthorityUrlComponents.PathSegments;
+ currentAuthorityParts.forEach(function (currentPart, index) {
+ var cachedPart = cachedAuthorityParts[index];
+ if (currentPart !== cachedPart) {
+ endpoint = endpoint.replace("/" + cachedPart + "/", "/" + currentPart + "/");
+ }
+ });
+ return endpoint;
+ };
+ Object.defineProperty(Authority.prototype, "defaultOpenIdConfigurationEndpoint", {
+ /**
+ * The default open id configuration endpoint for any canonical authority.
+ */
+ get: function () {
+ if (this.authorityType === AuthorityType.Adfs || this.protocolMode === ProtocolMode.OIDC) {
+ return this.canonicalAuthority + ".well-known/openid-configuration";
+ }
+ return this.canonicalAuthority + "v2.0/.well-known/openid-configuration";
+ },
+ enumerable: true,
+ configurable: true
+ });
+ /**
+ * Boolean that returns whethr or not tenant discovery has been completed.
+ */
+ Authority.prototype.discoveryComplete = function () {
+ return !!this.metadata;
+ };
+ /**
+ * Perform endpoint discovery to discover aliases, preferred_cache, preferred_network
+ * and the /authorize, /token and logout endpoints.
+ */
+ Authority.prototype.resolveEndpointsAsync = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var metadataEntity, cloudDiscoverySource, endpointSource, cacheKey;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ metadataEntity = this.cacheManager.getAuthorityMetadataByAlias(this.hostnameAndPort);
+ if (!metadataEntity) {
+ metadataEntity = new AuthorityMetadataEntity();
+ metadataEntity.updateCanonicalAuthority(this.canonicalAuthority);
+ }
+ return [4 /*yield*/, this.updateCloudDiscoveryMetadata(metadataEntity)];
+ case 1:
+ cloudDiscoverySource = _a.sent();
+ this.canonicalAuthority = this.canonicalAuthority.replace(this.hostnameAndPort, metadataEntity.preferred_network);
+ return [4 /*yield*/, this.updateEndpointMetadata(metadataEntity)];
+ case 2:
+ endpointSource = _a.sent();
+ if (cloudDiscoverySource !== AuthorityMetadataSource.CACHE && endpointSource !== AuthorityMetadataSource.CACHE) {
+ // Reset the expiration time unless both values came from a successful cache lookup
+ metadataEntity.resetExpiresAt();
+ metadataEntity.updateCanonicalAuthority(this.canonicalAuthority);
+ }
+ cacheKey = this.cacheManager.generateAuthorityMetadataCacheKey(metadataEntity.preferred_cache);
+ this.cacheManager.setAuthorityMetadata(cacheKey, metadataEntity);
+ this.metadata = metadataEntity;
+ return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Update AuthorityMetadataEntity with new endpoints and return where the information came from
+ * @param metadataEntity
+ */
+ Authority.prototype.updateEndpointMetadata = function (metadataEntity) {
+ return __awaiter(this, void 0, void 0, function () {
+ var metadata;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ metadata = this.getEndpointMetadataFromConfig();
+ if (metadata) {
+ metadataEntity.updateEndpointMetadata(metadata, false);
+ return [2 /*return*/, AuthorityMetadataSource.CONFIG];
+ }
+ if (this.isAuthoritySameType(metadataEntity) && metadataEntity.endpointsFromNetwork && !metadataEntity.isExpired()) {
+ // No need to update
+ return [2 /*return*/, AuthorityMetadataSource.CACHE];
+ }
+ return [4 /*yield*/, this.getEndpointMetadataFromNetwork()];
+ case 1:
+ metadata = _a.sent();
+ if (metadata) {
+ metadataEntity.updateEndpointMetadata(metadata, true);
+ return [2 /*return*/, AuthorityMetadataSource.NETWORK];
+ }
+ else {
+ throw ClientAuthError.createUnableToGetOpenidConfigError(this.defaultOpenIdConfigurationEndpoint);
+ }
+ }
+ });
+ });
+ };
+ /**
+ * Compares the number of url components after the domain to determine if the cached authority metadata can be used for the requested authority
+ * Protects against same domain different authority such as login.microsoftonline.com/tenant and login.microsoftonline.com/tfp/tenant/policy
+ * @param metadataEntity
+ */
+ Authority.prototype.isAuthoritySameType = function (metadataEntity) {
+ var cachedAuthorityUrl = new UrlString(metadataEntity.canonical_authority);
+ var cachedParts = cachedAuthorityUrl.getUrlComponents().PathSegments;
+ return cachedParts.length === this.canonicalAuthorityUrlComponents.PathSegments.length;
+ };
+ /**
+ * Parse authorityMetadata config option
+ */
+ Authority.prototype.getEndpointMetadataFromConfig = function () {
+ if (this.authorityOptions.authorityMetadata) {
+ try {
+ return JSON.parse(this.authorityOptions.authorityMetadata);
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidAuthorityMetadataError();
+ }
+ }
+ return null;
+ };
+ /**
+ * Gets OAuth endpoints from the given OpenID configuration endpoint.
+ */
+ Authority.prototype.getEndpointMetadataFromNetwork = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var response, e_1;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ _a.trys.push([0, 2, , 3]);
+ return [4 /*yield*/, this.networkInterface.sendGetRequestAsync(this.defaultOpenIdConfigurationEndpoint)];
+ case 1:
+ response = _a.sent();
+ return [2 /*return*/, isOpenIdConfigResponse(response.body) ? response.body : null];
+ case 2:
+ e_1 = _a.sent();
+ return [2 /*return*/, null];
+ case 3: return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Updates the AuthorityMetadataEntity with new aliases, preferred_network and preferred_cache and returns where the information was retrived from
+ * @param cachedMetadata
+ * @param newMetadata
+ */
+ Authority.prototype.updateCloudDiscoveryMetadata = function (metadataEntity) {
+ return __awaiter(this, void 0, void 0, function () {
+ var metadata;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ metadata = this.getCloudDiscoveryMetadataFromConfig();
+ if (metadata) {
+ metadataEntity.updateCloudDiscoveryMetadata(metadata, false);
+ return [2 /*return*/, AuthorityMetadataSource.CONFIG];
+ }
+ // If The cached metadata came from config but that config was not passed to this instance, we must go to the network
+ if (this.isAuthoritySameType(metadataEntity) && metadataEntity.aliasesFromNetwork && !metadataEntity.isExpired()) {
+ // No need to update
+ return [2 /*return*/, AuthorityMetadataSource.CACHE];
+ }
+ return [4 /*yield*/, this.getCloudDiscoveryMetadataFromNetwork()];
+ case 1:
+ metadata = _a.sent();
+ if (metadata) {
+ metadataEntity.updateCloudDiscoveryMetadata(metadata, true);
+ return [2 /*return*/, AuthorityMetadataSource.NETWORK];
+ }
+ else {
+ // Metadata could not be obtained from config, cache or network
+ throw ClientConfigurationError.createUntrustedAuthorityError();
+ }
+ }
+ });
+ });
+ };
+ /**
+ * Parse cloudDiscoveryMetadata config or check knownAuthorities
+ */
+ Authority.prototype.getCloudDiscoveryMetadataFromConfig = function () {
+ // Check if network response was provided in config
+ if (this.authorityOptions.cloudDiscoveryMetadata) {
+ try {
+ var parsedResponse = JSON.parse(this.authorityOptions.cloudDiscoveryMetadata);
+ var metadata = Authority.getCloudDiscoveryMetadataFromNetworkResponse(parsedResponse.metadata, this.hostnameAndPort);
+ if (metadata) {
+ return metadata;
+ }
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidCloudDiscoveryMetadataError();
+ }
+ }
+ // If cloudDiscoveryMetadata is empty or does not contain the host, check knownAuthorities
+ if (this.isInKnownAuthorities()) {
+ return Authority.createCloudDiscoveryMetadataFromHost(this.hostnameAndPort);
+ }
+ return null;
+ };
+ /**
+ * Called to get metadata from network if CloudDiscoveryMetadata was not populated by config
+ * @param networkInterface
+ */
+ Authority.prototype.getCloudDiscoveryMetadataFromNetwork = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var instanceDiscoveryEndpoint, match, response, metadata, e_2;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ instanceDiscoveryEndpoint = "" + Constants.AAD_INSTANCE_DISCOVERY_ENDPT + this.canonicalAuthority + "oauth2/v2.0/authorize";
+ match = null;
+ _a.label = 1;
+ case 1:
+ _a.trys.push([1, 3, , 4]);
+ return [4 /*yield*/, this.networkInterface.sendGetRequestAsync(instanceDiscoveryEndpoint)];
+ case 2:
+ response = _a.sent();
+ metadata = isCloudInstanceDiscoveryResponse(response.body) ? response.body.metadata : [];
+ match = Authority.getCloudDiscoveryMetadataFromNetworkResponse(metadata, this.hostnameAndPort);
+ return [3 /*break*/, 4];
+ case 3:
+ e_2 = _a.sent();
+ return [2 /*return*/, null];
+ case 4:
+ if (!match) {
+ // Custom Domain scenario, host is trusted because Instance Discovery call succeeded
+ match = Authority.createCloudDiscoveryMetadataFromHost(this.hostnameAndPort);
+ }
+ return [2 /*return*/, match];
+ }
+ });
+ });
+ };
+ /**
+ * Helper function to determine if this host is included in the knownAuthorities config option
+ */
+ Authority.prototype.isInKnownAuthorities = function () {
+ var _this = this;
+ var matches = this.authorityOptions.knownAuthorities.filter(function (authority) {
+ return UrlString.getDomainFromUrl(authority).toLowerCase() === _this.hostnameAndPort;
+ });
+ return matches.length > 0;
+ };
+ /**
+ * Creates cloud discovery metadata object from a given host
+ * @param host
+ */
+ Authority.createCloudDiscoveryMetadataFromHost = function (host) {
+ return {
+ preferred_network: host,
+ preferred_cache: host,
+ aliases: [host]
+ };
+ };
+ /**
+ * Searches instance discovery network response for the entry that contains the host in the aliases list
+ * @param response
+ * @param authority
+ */
+ Authority.getCloudDiscoveryMetadataFromNetworkResponse = function (response, authority) {
+ for (var i = 0; i < response.length; i++) {
+ var metadata = response[i];
+ if (metadata.aliases.indexOf(authority) > -1) {
+ return metadata;
+ }
+ }
+ return null;
+ };
+ /**
+ * helper function to generate environment from authority object
+ */
+ Authority.prototype.getPreferredCache = function () {
+ if (this.discoveryComplete()) {
+ return this.metadata.preferred_cache;
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ };
+ /**
+ * Returns whether or not the provided host is an alias of this authority instance
+ * @param host
+ */
+ Authority.prototype.isAlias = function (host) {
+ return this.metadata.aliases.indexOf(host) > -1;
+ };
+ return Authority;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var AuthorityFactory = /** @class */ (function () {
+ function AuthorityFactory() {
+ }
+ /**
+ * Create an authority object of the correct type based on the url
+ * Performs basic authority validation - checks to see if the authority is of a valid type (i.e. aad, b2c, adfs)
+ *
+ * Also performs endpoint discovery.
+ *
+ * @param authorityUri
+ * @param networkClient
+ * @param protocolMode
+ */
+ AuthorityFactory.createDiscoveredInstance = function (authorityUri, networkClient, cacheManager, authorityOptions) {
+ return __awaiter(this, void 0, void 0, function () {
+ var acquireTokenAuthority, e_1;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ acquireTokenAuthority = AuthorityFactory.createInstance(authorityUri, networkClient, cacheManager, authorityOptions);
+ _a.label = 1;
+ case 1:
+ _a.trys.push([1, 3, , 4]);
+ return [4 /*yield*/, acquireTokenAuthority.resolveEndpointsAsync()];
+ case 2:
+ _a.sent();
+ return [2 /*return*/, acquireTokenAuthority];
+ case 3:
+ e_1 = _a.sent();
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError(e_1);
+ case 4: return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Create an authority object of the correct type based on the url
+ * Performs basic authority validation - checks to see if the authority is of a valid type (i.e. aad, b2c, adfs)
+ *
+ * Does not perform endpoint discovery.
+ *
+ * @param authorityUrl
+ * @param networkInterface
+ * @param protocolMode
+ */
+ AuthorityFactory.createInstance = function (authorityUrl, networkInterface, cacheManager, authorityOptions) {
+ // Throw error if authority url is empty
+ if (StringUtils.isEmpty(authorityUrl)) {
+ throw ClientConfigurationError.createUrlEmptyError();
+ }
+ return new Authority(authorityUrl, networkInterface, cacheManager, authorityOptions);
+ };
+ return AuthorityFactory;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ServerTelemetryEntity = /** @class */ (function () {
+ function ServerTelemetryEntity() {
+ this.failedRequests = [];
+ this.errors = [];
+ this.cacheHits = 0;
+ }
+ /**
+ * validates if a given cache entry is "Telemetry", parses
+ * @param key
+ * @param entity
+ */
+ ServerTelemetryEntity.isServerTelemetryEntity = function (key, entity) {
+ var validateKey = key.indexOf(SERVER_TELEM_CONSTANTS.CACHE_KEY) === 0;
+ var validateEntity = true;
+ if (entity) {
+ validateEntity =
+ entity.hasOwnProperty("failedRequests") &&
+ entity.hasOwnProperty("errors") &&
+ entity.hasOwnProperty("cacheHits");
+ }
+ return validateKey && validateEntity;
+ };
+ return ServerTelemetryEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ThrottlingEntity = /** @class */ (function () {
+ function ThrottlingEntity() {
+ }
+ /**
+ * validates if a given cache entry is "Throttling", parses
+ * @param key
+ * @param entity
+ */
+ ThrottlingEntity.isThrottlingEntity = function (key, entity) {
+ var validateKey = false;
+ if (key) {
+ validateKey = key.indexOf(ThrottlingConstants.THROTTLING_PREFIX) === 0;
+ }
+ var validateEntity = true;
+ if (entity) {
+ validateEntity = entity.hasOwnProperty("throttleTime");
+ }
+ return validateKey && validateEntity;
+ };
+ return ThrottlingEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var StubbedNetworkModule = {
+ sendGetRequestAsync: function () {
+ var notImplErr = "Network interface - sendGetRequestAsync() has not been implemented for the Network interface.";
+ return Promise.reject(AuthError.createUnexpectedError(notImplErr));
+ },
+ sendPostRequestAsync: function () {
+ var notImplErr = "Network interface - sendPostRequestAsync() has not been implemented for the Network interface.";
+ return Promise.reject(AuthError.createUnexpectedError(notImplErr));
+ }
+};
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ServerTelemetryManager = /** @class */ (function () {
+ function ServerTelemetryManager(telemetryRequest, cacheManager) {
+ this.cacheManager = cacheManager;
+ this.apiId = telemetryRequest.apiId;
+ this.correlationId = telemetryRequest.correlationId;
+ this.forceRefresh = telemetryRequest.forceRefresh || false;
+ this.wrapperSKU = telemetryRequest.wrapperSKU || Constants.EMPTY_STRING;
+ this.wrapperVer = telemetryRequest.wrapperVer || Constants.EMPTY_STRING;
+ this.telemetryCacheKey = SERVER_TELEM_CONSTANTS.CACHE_KEY + Separators.CACHE_KEY_SEPARATOR + telemetryRequest.clientId;
+ }
+ /**
+ * API to add MSER Telemetry to request
+ */
+ ServerTelemetryManager.prototype.generateCurrentRequestHeaderValue = function () {
+ var forceRefreshInt = this.forceRefresh ? 1 : 0;
+ var request = "" + this.apiId + SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR + forceRefreshInt;
+ var platformFields = [this.wrapperSKU, this.wrapperVer].join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ return [SERVER_TELEM_CONSTANTS.SCHEMA_VERSION, request, platformFields].join(SERVER_TELEM_CONSTANTS.CATEGORY_SEPARATOR);
+ };
+ /**
+ * API to add MSER Telemetry for the last failed request
+ */
+ ServerTelemetryManager.prototype.generateLastRequestHeaderValue = function () {
+ var lastRequests = this.getLastRequests();
+ var maxErrors = ServerTelemetryManager.maxErrorsToSend(lastRequests);
+ var failedRequests = lastRequests.failedRequests.slice(0, 2 * maxErrors).join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ var errors = lastRequests.errors.slice(0, maxErrors).join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ var errorCount = lastRequests.errors.length;
+ // Indicate whether this header contains all data or partial data
+ var overflow = maxErrors < errorCount ? SERVER_TELEM_CONSTANTS.OVERFLOW_TRUE : SERVER_TELEM_CONSTANTS.OVERFLOW_FALSE;
+ var platformFields = [errorCount, overflow].join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ return [SERVER_TELEM_CONSTANTS.SCHEMA_VERSION, lastRequests.cacheHits, failedRequests, errors, platformFields].join(SERVER_TELEM_CONSTANTS.CATEGORY_SEPARATOR);
+ };
+ /**
+ * API to cache token failures for MSER data capture
+ * @param error
+ */
+ ServerTelemetryManager.prototype.cacheFailedRequest = function (error) {
+ var lastRequests = this.getLastRequests();
+ lastRequests.failedRequests.push(this.apiId, this.correlationId);
+ if (!StringUtils.isEmpty(error.subError)) {
+ lastRequests.errors.push(error.subError);
+ }
+ else if (!StringUtils.isEmpty(error.errorCode)) {
+ lastRequests.errors.push(error.errorCode);
+ }
+ else if (!!error && error.toString()) {
+ lastRequests.errors.push(error.toString());
+ }
+ else {
+ lastRequests.errors.push(SERVER_TELEM_CONSTANTS.UNKNOWN_ERROR);
+ }
+ this.cacheManager.setServerTelemetry(this.telemetryCacheKey, lastRequests);
+ return;
+ };
+ /**
+ * Update server telemetry cache entry by incrementing cache hit counter
+ */
+ ServerTelemetryManager.prototype.incrementCacheHits = function () {
+ var lastRequests = this.getLastRequests();
+ lastRequests.cacheHits += 1;
+ this.cacheManager.setServerTelemetry(this.telemetryCacheKey, lastRequests);
+ return lastRequests.cacheHits;
+ };
+ /**
+ * Get the server telemetry entity from cache or initialize a new one
+ */
+ ServerTelemetryManager.prototype.getLastRequests = function () {
+ var initialValue = new ServerTelemetryEntity();
+ var lastRequests = this.cacheManager.getServerTelemetry(this.telemetryCacheKey);
+ return lastRequests || initialValue;
+ };
+ /**
+ * Remove server telemetry cache entry
+ */
+ ServerTelemetryManager.prototype.clearTelemetryCache = function () {
+ var lastRequests = this.getLastRequests();
+ var numErrorsFlushed = ServerTelemetryManager.maxErrorsToSend(lastRequests);
+ var errorCount = lastRequests.errors.length;
+ if (numErrorsFlushed === errorCount) {
+ // All errors were sent on last request, clear Telemetry cache
+ this.cacheManager.removeItem(this.telemetryCacheKey);
+ }
+ else {
+ // Partial data was flushed to server, construct a new telemetry cache item with errors that were not flushed
+ var serverTelemEntity = new ServerTelemetryEntity();
+ serverTelemEntity.failedRequests = lastRequests.failedRequests.slice(numErrorsFlushed * 2); // failedRequests contains 2 items for each error
+ serverTelemEntity.errors = lastRequests.errors.slice(numErrorsFlushed);
+ this.cacheManager.setServerTelemetry(this.telemetryCacheKey, serverTelemEntity);
+ }
+ };
+ /**
+ * Returns the maximum number of errors that can be flushed to the server in the next network request
+ * @param serverTelemetryEntity
+ */
+ ServerTelemetryManager.maxErrorsToSend = function (serverTelemetryEntity) {
+ var i;
+ var maxErrors = 0;
+ var dataSize = 0;
+ var errorCount = serverTelemetryEntity.errors.length;
+ for (i = 0; i < errorCount; i++) {
+ // failedRequests parameter contains pairs of apiId and correlationId, multiply index by 2 to preserve pairs
+ var apiId = serverTelemetryEntity.failedRequests[2 * i] || Constants.EMPTY_STRING;
+ var correlationId = serverTelemetryEntity.failedRequests[2 * i + 1] || Constants.EMPTY_STRING;
+ var errorCode = serverTelemetryEntity.errors[i] || Constants.EMPTY_STRING;
+ // Count number of characters that would be added to header, each character is 1 byte. Add 3 at the end to account for separators
+ dataSize += apiId.toString().length + correlationId.toString().length + errorCode.length + 3;
+ if (dataSize < SERVER_TELEM_CONSTANTS.MAX_HEADER_BYTES) {
+ // Adding this entry to the header would still keep header size below the limit
+ maxErrors += 1;
+ }
+ else {
+ break;
+ }
+ }
+ return maxErrors;
+ };
+ return ServerTelemetryManager;
+}());
+
+export { AccessTokenEntity, AccountEntity, AppMetadataEntity, AuthError, AuthErrorMessage, AuthToken, AuthenticationScheme, Authority, AuthorityFactory, AuthorityMetadataEntity, AuthorityType, AuthorizationCodeClient, CacheAccountType, CacheManager, CacheSchemaType, CacheType, ClientAuthError, ClientAuthErrorMessage, ClientConfigurationError, ClientConfigurationErrorMessage, ClientCredentialClient, Constants, CredentialEntity, CredentialType, DEFAULT_CRYPTO_IMPLEMENTATION, DEFAULT_SYSTEM_OPTIONS, DefaultStorageClass, DeviceCodeClient, AuthToken as IdToken, IdTokenEntity, InteractionRequiredAuthError, LogLevel, Logger, NetworkManager, OIDC_DEFAULT_SCOPES, OnBehalfOfClient, PersistentCacheKeys, PromptValue, ProtocolMode, ProtocolUtils, RefreshTokenClient, RefreshTokenEntity, ResponseMode, ServerError, ServerTelemetryEntity, ServerTelemetryManager, SilentFlowClient, StringUtils, StubbedNetworkModule, ThrottlingEntity, ThrottlingUtils, TimeUtils, TokenCacheContext, UrlString, UsernamePasswordClient };
+//# sourceMappingURL=data:application/json;charset=utf-8;base64,
diff --git a/node_modules/@azure/msal-common/dist/index.js b/node_modules/@azure/msal-common/dist/index.js
new file mode 100644
index 0000000..62c3db0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/index.js
@@ -0,0 +1,6336 @@
+/*! @azure/msal-common v4.0.1 2021-02-18 */
+'use strict';
+'use strict';
+
+Object.defineProperty(exports, '__esModule', { value: true });
+
+/*! *****************************************************************************
+Copyright (c) Microsoft Corporation.
+
+Permission to use, copy, modify, and/or distribute this software for any
+purpose with or without fee is hereby granted.
+
+THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
+REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
+AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
+INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
+LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
+OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
+PERFORMANCE OF THIS SOFTWARE.
+***************************************************************************** */
+/* global Reflect, Promise */
+
+var extendStatics = function(d, b) {
+ extendStatics = Object.setPrototypeOf ||
+ ({ __proto__: [] } instanceof Array && function (d, b) { d.__proto__ = b; }) ||
+ function (d, b) { for (var p in b) if (Object.prototype.hasOwnProperty.call(b, p)) d[p] = b[p]; };
+ return extendStatics(d, b);
+};
+
+function __extends(d, b) {
+ extendStatics(d, b);
+ function __() { this.constructor = d; }
+ d.prototype = b === null ? Object.create(b) : (__.prototype = b.prototype, new __());
+}
+
+var __assign = function() {
+ __assign = Object.assign || function __assign(t) {
+ for (var s, i = 1, n = arguments.length; i < n; i++) {
+ s = arguments[i];
+ for (var p in s) if (Object.prototype.hasOwnProperty.call(s, p)) t[p] = s[p];
+ }
+ return t;
+ };
+ return __assign.apply(this, arguments);
+};
+
+function __awaiter(thisArg, _arguments, P, generator) {
+ function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }
+ return new (P || (P = Promise))(function (resolve, reject) {
+ function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }
+ function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
+ function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }
+ step((generator = generator.apply(thisArg, _arguments || [])).next());
+ });
+}
+
+function __generator(thisArg, body) {
+ var _ = { label: 0, sent: function() { if (t[0] & 1) throw t[1]; return t[1]; }, trys: [], ops: [] }, f, y, t, g;
+ return g = { next: verb(0), "throw": verb(1), "return": verb(2) }, typeof Symbol === "function" && (g[Symbol.iterator] = function() { return this; }), g;
+ function verb(n) { return function (v) { return step([n, v]); }; }
+ function step(op) {
+ if (f) throw new TypeError("Generator is already executing.");
+ while (_) try {
+ if (f = 1, y && (t = op[0] & 2 ? y["return"] : op[0] ? y["throw"] || ((t = y["return"]) && t.call(y), 0) : y.next) && !(t = t.call(y, op[1])).done) return t;
+ if (y = 0, t) op = [op[0] & 2, t.value];
+ switch (op[0]) {
+ case 0: case 1: t = op; break;
+ case 4: _.label++; return { value: op[1], done: false };
+ case 5: _.label++; y = op[1]; op = [0]; continue;
+ case 7: op = _.ops.pop(); _.trys.pop(); continue;
+ default:
+ if (!(t = _.trys, t = t.length > 0 && t[t.length - 1]) && (op[0] === 6 || op[0] === 2)) { _ = 0; continue; }
+ if (op[0] === 3 && (!t || (op[1] > t[0] && op[1] < t[3]))) { _.label = op[1]; break; }
+ if (op[0] === 6 && _.label < t[1]) { _.label = t[1]; t = op; break; }
+ if (t && _.label < t[2]) { _.label = t[2]; _.ops.push(op); break; }
+ if (t[2]) _.ops.pop();
+ _.trys.pop(); continue;
+ }
+ op = body.call(thisArg, _);
+ } catch (e) { op = [6, e]; y = 0; } finally { f = t = 0; }
+ if (op[0] & 5) throw op[1]; return { value: op[0] ? op[1] : void 0, done: true };
+ }
+}
+
+function __spreadArrays() {
+ for (var s = 0, i = 0, il = arguments.length; i < il; i++) s += arguments[i].length;
+ for (var r = Array(s), k = 0, i = 0; i < il; i++)
+ for (var a = arguments[i], j = 0, jl = a.length; j < jl; j++, k++)
+ r[k] = a[j];
+ return r;
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var Constants = {
+ LIBRARY_NAME: "MSAL.JS",
+ SKU: "msal.js.common",
+ // Prefix for all library cache entries
+ CACHE_PREFIX: "msal",
+ // default authority
+ DEFAULT_AUTHORITY: "https://login.microsoftonline.com/common/",
+ DEFAULT_AUTHORITY_HOST: "login.microsoftonline.com",
+ // ADFS String
+ ADFS: "adfs",
+ // Default AAD Instance Discovery Endpoint
+ AAD_INSTANCE_DISCOVERY_ENDPT: "https://login.microsoftonline.com/common/discovery/instance?api-version=1.1&authorization_endpoint=",
+ // Resource delimiter - used for certain cache entries
+ RESOURCE_DELIM: "|",
+ // Placeholder for non-existent account ids/objects
+ NO_ACCOUNT: "NO_ACCOUNT",
+ // Claims
+ CLAIMS: "claims",
+ // Consumer UTID
+ CONSUMER_UTID: "9188040d-6c67-4c5b-b112-36a304b66dad",
+ // Default scopes
+ OPENID_SCOPE: "openid",
+ PROFILE_SCOPE: "profile",
+ OFFLINE_ACCESS_SCOPE: "offline_access",
+ EMAIL_SCOPE: "email",
+ // Default response type for authorization code flow
+ CODE_RESPONSE_TYPE: "code",
+ CODE_GRANT_TYPE: "authorization_code",
+ RT_GRANT_TYPE: "refresh_token",
+ FRAGMENT_RESPONSE_MODE: "fragment",
+ S256_CODE_CHALLENGE_METHOD: "S256",
+ URL_FORM_CONTENT_TYPE: "application/x-www-form-urlencoded;charset=utf-8",
+ AUTHORIZATION_PENDING: "authorization_pending",
+ NOT_DEFINED: "not_defined",
+ EMPTY_STRING: "",
+ FORWARD_SLASH: "/"
+};
+var OIDC_DEFAULT_SCOPES = [
+ Constants.OPENID_SCOPE,
+ Constants.PROFILE_SCOPE,
+ Constants.OFFLINE_ACCESS_SCOPE
+];
+var OIDC_SCOPES = __spreadArrays(OIDC_DEFAULT_SCOPES, [
+ Constants.EMAIL_SCOPE
+]);
+/**
+ * Request header names
+ */
+var HeaderNames;
+(function (HeaderNames) {
+ HeaderNames["CONTENT_TYPE"] = "Content-Type";
+ HeaderNames["X_CLIENT_CURR_TELEM"] = "x-client-current-telemetry";
+ HeaderNames["X_CLIENT_LAST_TELEM"] = "x-client-last-telemetry";
+ HeaderNames["RETRY_AFTER"] = "Retry-After";
+ HeaderNames["X_MS_LIB_CAPABILITY"] = "x-ms-lib-capability";
+ HeaderNames["X_MS_LIB_CAPABILITY_VALUE"] = "retry-after, h429";
+})(HeaderNames || (HeaderNames = {}));
+(function (PersistentCacheKeys) {
+ PersistentCacheKeys["ID_TOKEN"] = "idtoken";
+ PersistentCacheKeys["CLIENT_INFO"] = "client.info";
+ PersistentCacheKeys["ADAL_ID_TOKEN"] = "adal.idtoken";
+ PersistentCacheKeys["ERROR"] = "error";
+ PersistentCacheKeys["ERROR_DESC"] = "error.description";
+})(exports.PersistentCacheKeys || (exports.PersistentCacheKeys = {}));
+/**
+ * String constants related to AAD Authority
+ */
+var AADAuthorityConstants;
+(function (AADAuthorityConstants) {
+ AADAuthorityConstants["COMMON"] = "common";
+ AADAuthorityConstants["ORGANIZATIONS"] = "organizations";
+ AADAuthorityConstants["CONSUMERS"] = "consumers";
+})(AADAuthorityConstants || (AADAuthorityConstants = {}));
+/**
+ * Keys in the hashParams sent by AAD Server
+ */
+var AADServerParamKeys;
+(function (AADServerParamKeys) {
+ AADServerParamKeys["CLIENT_ID"] = "client_id";
+ AADServerParamKeys["REDIRECT_URI"] = "redirect_uri";
+ AADServerParamKeys["RESPONSE_TYPE"] = "response_type";
+ AADServerParamKeys["RESPONSE_MODE"] = "response_mode";
+ AADServerParamKeys["GRANT_TYPE"] = "grant_type";
+ AADServerParamKeys["CLAIMS"] = "claims";
+ AADServerParamKeys["SCOPE"] = "scope";
+ AADServerParamKeys["ERROR"] = "error";
+ AADServerParamKeys["ERROR_DESCRIPTION"] = "error_description";
+ AADServerParamKeys["ACCESS_TOKEN"] = "access_token";
+ AADServerParamKeys["ID_TOKEN"] = "id_token";
+ AADServerParamKeys["REFRESH_TOKEN"] = "refresh_token";
+ AADServerParamKeys["EXPIRES_IN"] = "expires_in";
+ AADServerParamKeys["STATE"] = "state";
+ AADServerParamKeys["NONCE"] = "nonce";
+ AADServerParamKeys["PROMPT"] = "prompt";
+ AADServerParamKeys["SESSION_STATE"] = "session_state";
+ AADServerParamKeys["CLIENT_INFO"] = "client_info";
+ AADServerParamKeys["CODE"] = "code";
+ AADServerParamKeys["CODE_CHALLENGE"] = "code_challenge";
+ AADServerParamKeys["CODE_CHALLENGE_METHOD"] = "code_challenge_method";
+ AADServerParamKeys["CODE_VERIFIER"] = "code_verifier";
+ AADServerParamKeys["CLIENT_REQUEST_ID"] = "client-request-id";
+ AADServerParamKeys["X_CLIENT_SKU"] = "x-client-SKU";
+ AADServerParamKeys["X_CLIENT_VER"] = "x-client-VER";
+ AADServerParamKeys["X_CLIENT_OS"] = "x-client-OS";
+ AADServerParamKeys["X_CLIENT_CPU"] = "x-client-CPU";
+ AADServerParamKeys["POST_LOGOUT_URI"] = "post_logout_redirect_uri";
+ AADServerParamKeys["ID_TOKEN_HINT"] = "id_token_hint";
+ AADServerParamKeys["DEVICE_CODE"] = "device_code";
+ AADServerParamKeys["CLIENT_SECRET"] = "client_secret";
+ AADServerParamKeys["CLIENT_ASSERTION"] = "client_assertion";
+ AADServerParamKeys["CLIENT_ASSERTION_TYPE"] = "client_assertion_type";
+ AADServerParamKeys["TOKEN_TYPE"] = "token_type";
+ AADServerParamKeys["REQ_CNF"] = "req_cnf";
+ AADServerParamKeys["OBO_ASSERTION"] = "assertion";
+ AADServerParamKeys["REQUESTED_TOKEN_USE"] = "requested_token_use";
+ AADServerParamKeys["ON_BEHALF_OF"] = "on_behalf_of";
+ AADServerParamKeys["FOCI"] = "foci";
+})(AADServerParamKeys || (AADServerParamKeys = {}));
+/**
+ * Claims request keys
+ */
+var ClaimsRequestKeys;
+(function (ClaimsRequestKeys) {
+ ClaimsRequestKeys["ACCESS_TOKEN"] = "access_token";
+ ClaimsRequestKeys["XMS_CC"] = "xms_cc";
+})(ClaimsRequestKeys || (ClaimsRequestKeys = {}));
+/**
+ * we considered making this "enum" in the request instead of string, however it looks like the allowed list of
+ * prompt values kept changing over past couple of years. There are some undocumented prompt values for some
+ * internal partners too, hence the choice of generic "string" type instead of the "enum"
+ */
+var PromptValue = {
+ LOGIN: "login",
+ SELECT_ACCOUNT: "select_account",
+ CONSENT: "consent",
+ NONE: "none",
+};
+/**
+ * SSO Types - generated to populate hints
+ */
+var SSOTypes;
+(function (SSOTypes) {
+ SSOTypes["ACCOUNT"] = "account";
+ SSOTypes["SID"] = "sid";
+ SSOTypes["LOGIN_HINT"] = "login_hint";
+ SSOTypes["ID_TOKEN"] = "id_token";
+ SSOTypes["DOMAIN_HINT"] = "domain_hint";
+ SSOTypes["ORGANIZATIONS"] = "organizations";
+ SSOTypes["CONSUMERS"] = "consumers";
+ SSOTypes["ACCOUNT_ID"] = "accountIdentifier";
+ SSOTypes["HOMEACCOUNT_ID"] = "homeAccountIdentifier";
+})(SSOTypes || (SSOTypes = {}));
+/**
+ * Disallowed extra query parameters.
+ */
+var BlacklistedEQParams = [
+ SSOTypes.SID,
+ SSOTypes.LOGIN_HINT
+];
+/**
+ * allowed values for codeVerifier
+ */
+var CodeChallengeMethodValues = {
+ PLAIN: "plain",
+ S256: "S256"
+};
+(function (ResponseMode) {
+ ResponseMode["QUERY"] = "query";
+ ResponseMode["FRAGMENT"] = "fragment";
+ ResponseMode["FORM_POST"] = "form_post";
+})(exports.ResponseMode || (exports.ResponseMode = {}));
+/**
+ * allowed grant_type
+ */
+var GrantType;
+(function (GrantType) {
+ GrantType["IMPLICIT_GRANT"] = "implicit";
+ GrantType["AUTHORIZATION_CODE_GRANT"] = "authorization_code";
+ GrantType["CLIENT_CREDENTIALS_GRANT"] = "client_credentials";
+ GrantType["RESOURCE_OWNER_PASSWORD_GRANT"] = "password";
+ GrantType["REFRESH_TOKEN_GRANT"] = "refresh_token";
+ GrantType["DEVICE_CODE_GRANT"] = "device_code";
+ GrantType["JWT_BEARER"] = "urn:ietf:params:oauth:grant-type:jwt-bearer";
+})(GrantType || (GrantType = {}));
+(function (CacheAccountType) {
+ CacheAccountType["MSSTS_ACCOUNT_TYPE"] = "MSSTS";
+ CacheAccountType["ADFS_ACCOUNT_TYPE"] = "ADFS";
+ CacheAccountType["MSAV1_ACCOUNT_TYPE"] = "MSA";
+ CacheAccountType["GENERIC_ACCOUNT_TYPE"] = "Generic"; // NTLM, Kerberos, FBA, Basic etc
+})(exports.CacheAccountType || (exports.CacheAccountType = {}));
+/**
+ * Separators used in cache
+ */
+var Separators;
+(function (Separators) {
+ Separators["CACHE_KEY_SEPARATOR"] = "-";
+ Separators["CLIENT_INFO_SEPARATOR"] = ".";
+})(Separators || (Separators = {}));
+(function (CredentialType) {
+ CredentialType["ID_TOKEN"] = "IdToken";
+ CredentialType["ACCESS_TOKEN"] = "AccessToken";
+ CredentialType["REFRESH_TOKEN"] = "RefreshToken";
+})(exports.CredentialType || (exports.CredentialType = {}));
+(function (CacheSchemaType) {
+ CacheSchemaType["ACCOUNT"] = "Account";
+ CacheSchemaType["CREDENTIAL"] = "Credential";
+ CacheSchemaType["ID_TOKEN"] = "IdToken";
+ CacheSchemaType["ACCESS_TOKEN"] = "AccessToken";
+ CacheSchemaType["REFRESH_TOKEN"] = "RefreshToken";
+ CacheSchemaType["APP_METADATA"] = "AppMetadata";
+ CacheSchemaType["TEMPORARY"] = "TempCache";
+ CacheSchemaType["TELEMETRY"] = "Telemetry";
+ CacheSchemaType["UNDEFINED"] = "Undefined";
+ CacheSchemaType["THROTTLING"] = "Throttling";
+})(exports.CacheSchemaType || (exports.CacheSchemaType = {}));
+(function (CacheType) {
+ CacheType[CacheType["ADFS"] = 1001] = "ADFS";
+ CacheType[CacheType["MSA"] = 1002] = "MSA";
+ CacheType[CacheType["MSSTS"] = 1003] = "MSSTS";
+ CacheType[CacheType["GENERIC"] = 1004] = "GENERIC";
+ CacheType[CacheType["ACCESS_TOKEN"] = 2001] = "ACCESS_TOKEN";
+ CacheType[CacheType["REFRESH_TOKEN"] = 2002] = "REFRESH_TOKEN";
+ CacheType[CacheType["ID_TOKEN"] = 2003] = "ID_TOKEN";
+ CacheType[CacheType["APP_METADATA"] = 3001] = "APP_METADATA";
+ CacheType[CacheType["UNDEFINED"] = 9999] = "UNDEFINED";
+})(exports.CacheType || (exports.CacheType = {}));
+/**
+ * More Cache related constants
+ */
+var APP_METADATA = "appmetadata";
+var ClientInfo = "client_info";
+var THE_FAMILY_ID = "1";
+var AUTHORITY_METADATA_CONSTANTS = {
+ CACHE_KEY: "authority-metadata",
+ REFRESH_TIME_SECONDS: 3600 * 24 // 24 Hours
+};
+var AuthorityMetadataSource;
+(function (AuthorityMetadataSource) {
+ AuthorityMetadataSource["CONFIG"] = "config";
+ AuthorityMetadataSource["CACHE"] = "cache";
+ AuthorityMetadataSource["NETWORK"] = "network";
+})(AuthorityMetadataSource || (AuthorityMetadataSource = {}));
+var SERVER_TELEM_CONSTANTS = {
+ SCHEMA_VERSION: 2,
+ MAX_HEADER_BYTES: 4000,
+ CACHE_KEY: "server-telemetry",
+ CATEGORY_SEPARATOR: "|",
+ VALUE_SEPARATOR: ",",
+ OVERFLOW_TRUE: "1",
+ OVERFLOW_FALSE: "0",
+ UNKNOWN_ERROR: "unknown_error"
+};
+(function (AuthenticationScheme) {
+ AuthenticationScheme["POP"] = "pop";
+ AuthenticationScheme["BEARER"] = "Bearer";
+})(exports.AuthenticationScheme || (exports.AuthenticationScheme = {}));
+/**
+ * Constants related to throttling
+ */
+var ThrottlingConstants = {
+ // Default time to throttle RequestThumbprint in seconds
+ DEFAULT_THROTTLE_TIME_SECONDS: 60,
+ // Default maximum time to throttle in seconds, overrides what the server sends back
+ DEFAULT_MAX_THROTTLE_TIME_SECONDS: 3600,
+ // Prefix for storing throttling entries
+ THROTTLING_PREFIX: "throttling"
+};
+var Errors = {
+ INVALID_GRANT_ERROR: "invalid_grant",
+ CLIENT_MISMATCH_ERROR: "client_mismatch",
+};
+/**
+ * Password grant parameters
+ */
+var PasswordGrantConstants;
+(function (PasswordGrantConstants) {
+ PasswordGrantConstants["username"] = "username";
+ PasswordGrantConstants["password"] = "password";
+})(PasswordGrantConstants || (PasswordGrantConstants = {}));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * AuthErrorMessage class containing string constants used by error codes and messages.
+ */
+var AuthErrorMessage = {
+ unexpectedError: {
+ code: "unexpected_error",
+ desc: "Unexpected error in authentication."
+ }
+};
+/**
+ * General error class thrown by the MSAL.js library.
+ */
+var AuthError = /** @class */ (function (_super) {
+ __extends(AuthError, _super);
+ function AuthError(errorCode, errorMessage, suberror) {
+ var _this = this;
+ var errorString = errorMessage ? errorCode + ": " + errorMessage : errorCode;
+ _this = _super.call(this, errorString) || this;
+ Object.setPrototypeOf(_this, AuthError.prototype);
+ _this.errorCode = errorCode || Constants.EMPTY_STRING;
+ _this.errorMessage = errorMessage || "";
+ _this.subError = suberror || "";
+ _this.name = "AuthError";
+ return _this;
+ }
+ /**
+ * Creates an error that is thrown when something unexpected happens in the library.
+ * @param errDesc
+ */
+ AuthError.createUnexpectedError = function (errDesc) {
+ return new AuthError(AuthErrorMessage.unexpectedError.code, AuthErrorMessage.unexpectedError.desc + ": " + errDesc);
+ };
+ return AuthError;
+}(Error));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var DEFAULT_CRYPTO_IMPLEMENTATION = {
+ createNewGuid: function () {
+ var notImplErr = "Crypto interface - createNewGuid() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ },
+ base64Decode: function () {
+ var notImplErr = "Crypto interface - base64Decode() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ },
+ base64Encode: function () {
+ var notImplErr = "Crypto interface - base64Encode() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ },
+ generatePkceCodes: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Crypto interface - generatePkceCodes() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ },
+ getPublicKeyThumbprint: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Crypto interface - getPublicKeyThumbprint() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ },
+ signJwt: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Crypto interface - signJwt() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ }
+};
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ClientAuthErrorMessage class containing string constants used by error codes and messages.
+ */
+var ClientAuthErrorMessage = {
+ clientInfoDecodingError: {
+ code: "client_info_decoding_error",
+ desc: "The client info could not be parsed/decoded correctly. Please review the trace to determine the root cause."
+ },
+ clientInfoEmptyError: {
+ code: "client_info_empty_error",
+ desc: "The client info was empty. Please review the trace to determine the root cause."
+ },
+ tokenParsingError: {
+ code: "token_parsing_error",
+ desc: "Token cannot be parsed. Please review stack trace to determine root cause."
+ },
+ nullOrEmptyToken: {
+ code: "null_or_empty_token",
+ desc: "The token is null or empty. Please review the trace to determine the root cause."
+ },
+ endpointResolutionError: {
+ code: "endpoints_resolution_error",
+ desc: "Error: could not resolve endpoints. Please check network and try again."
+ },
+ unableToGetOpenidConfigError: {
+ code: "openid_config_error",
+ desc: "Could not retrieve endpoints. Check your authority and verify the .well-known/openid-configuration endpoint returns the required endpoints."
+ },
+ hashNotDeserialized: {
+ code: "hash_not_deserialized",
+ desc: "The hash parameters could not be deserialized. Please review the trace to determine the root cause."
+ },
+ blankGuidGenerated: {
+ code: "blank_guid_generated",
+ desc: "The guid generated was blank. Please review the trace to determine the root cause."
+ },
+ invalidStateError: {
+ code: "invalid_state",
+ desc: "State was not the expected format. Please check the logs to determine whether the request was sent using ProtocolUtils.setRequestState()."
+ },
+ stateMismatchError: {
+ code: "state_mismatch",
+ desc: "State mismatch error. Please check your network. Continued requests may cause cache overflow."
+ },
+ stateNotFoundError: {
+ code: "state_not_found",
+ desc: "State not found"
+ },
+ nonceMismatchError: {
+ code: "nonce_mismatch",
+ desc: "Nonce mismatch error. This may be caused by a race condition in concurrent requests."
+ },
+ nonceNotFoundError: {
+ code: "nonce_not_found",
+ desc: "nonce not found"
+ },
+ noTokensFoundError: {
+ code: "no_tokens_found",
+ desc: "No tokens were found for the given scopes, and no authorization code was passed to acquireToken. You must retrieve an authorization code before making a call to acquireToken()."
+ },
+ multipleMatchingTokens: {
+ code: "multiple_matching_tokens",
+ desc: "The cache contains multiple tokens satisfying the requirements. " +
+ "Call AcquireToken again providing more requirements such as authority or account."
+ },
+ multipleMatchingAccounts: {
+ code: "multiple_matching_accounts",
+ desc: "The cache contains multiple accounts satisfying the given parameters. Please pass more info to obtain the correct account"
+ },
+ multipleMatchingAppMetadata: {
+ code: "multiple_matching_appMetadata",
+ desc: "The cache contains multiple appMetadata satisfying the given parameters. Please pass more info to obtain the correct appMetadata"
+ },
+ tokenRequestCannotBeMade: {
+ code: "request_cannot_be_made",
+ desc: "Token request cannot be made without authorization code or refresh token."
+ },
+ appendEmptyScopeError: {
+ code: "cannot_append_empty_scope",
+ desc: "Cannot append null or empty scope to ScopeSet. Please check the stack trace for more info."
+ },
+ removeEmptyScopeError: {
+ code: "cannot_remove_empty_scope",
+ desc: "Cannot remove null or empty scope from ScopeSet. Please check the stack trace for more info."
+ },
+ appendScopeSetError: {
+ code: "cannot_append_scopeset",
+ desc: "Cannot append ScopeSet due to error."
+ },
+ emptyInputScopeSetError: {
+ code: "empty_input_scopeset",
+ desc: "Empty input ScopeSet cannot be processed."
+ },
+ DeviceCodePollingCancelled: {
+ code: "device_code_polling_cancelled",
+ desc: "Caller has cancelled token endpoint polling during device code flow by setting DeviceCodeRequest.cancel = true."
+ },
+ DeviceCodeExpired: {
+ code: "device_code_expired",
+ desc: "Device code is expired."
+ },
+ NoAccountInSilentRequest: {
+ code: "no_account_in_silent_request",
+ desc: "Please pass an account object, silent flow is not supported without account information"
+ },
+ invalidCacheRecord: {
+ code: "invalid_cache_record",
+ desc: "Cache record object was null or undefined."
+ },
+ invalidCacheEnvironment: {
+ code: "invalid_cache_environment",
+ desc: "Invalid environment when attempting to create cache entry"
+ },
+ noAccountFound: {
+ code: "no_account_found",
+ desc: "No account found in cache for given key."
+ },
+ CachePluginError: {
+ code: "no cache plugin set on CacheManager",
+ desc: "ICachePlugin needs to be set before using readFromStorage or writeFromStorage"
+ },
+ noCryptoObj: {
+ code: "no_crypto_object",
+ desc: "No crypto object detected. This is required for the following operation: "
+ },
+ invalidCacheType: {
+ code: "invalid_cache_type",
+ desc: "Invalid cache type"
+ },
+ unexpectedAccountType: {
+ code: "unexpected_account_type",
+ desc: "Unexpected account type."
+ },
+ unexpectedCredentialType: {
+ code: "unexpected_credential_type",
+ desc: "Unexpected credential type."
+ },
+ invalidAssertion: {
+ code: "invalid_assertion",
+ desc: "Client assertion must meet requirements described in https://tools.ietf.org/html/rfc7515"
+ },
+ invalidClientCredential: {
+ code: "invalid_client_credential",
+ desc: "Client credential (secret, certificate, or assertion) must not be empty when creating a confidential client. An application should at most have one credential"
+ },
+ tokenRefreshRequired: {
+ code: "token_refresh_required",
+ desc: "Cannot return token from cache because it must be refreshed. This may be due to one of the following reasons: forceRefresh parameter is set to true, claims have been requested, there is no cached access token or it is expired."
+ },
+ userTimeoutReached: {
+ code: "user_timeout_reached",
+ desc: "User defined timeout for device code polling reached",
+ },
+ tokenClaimsRequired: {
+ code: "token_claims_cnf_required_for_signedjwt",
+ desc: "Cannot generate a POP jwt if the token_claims are not populated"
+ },
+ noAuthorizationCodeFromServer: {
+ code: "authorization_code_missing_from_server_response",
+ desc: "Srver response does not contain an authorization code to proceed"
+ }
+};
+/**
+ * Error thrown when there is an error in the client code running on the browser.
+ */
+var ClientAuthError = /** @class */ (function (_super) {
+ __extends(ClientAuthError, _super);
+ function ClientAuthError(errorCode, errorMessage) {
+ var _this = _super.call(this, errorCode, errorMessage) || this;
+ _this.name = "ClientAuthError";
+ Object.setPrototypeOf(_this, ClientAuthError.prototype);
+ return _this;
+ }
+ /**
+ * Creates an error thrown when client info object doesn't decode correctly.
+ * @param caughtError
+ */
+ ClientAuthError.createClientInfoDecodingError = function (caughtError) {
+ return new ClientAuthError(ClientAuthErrorMessage.clientInfoDecodingError.code, ClientAuthErrorMessage.clientInfoDecodingError.desc + " Failed with error: " + caughtError);
+ };
+ /**
+ * Creates an error thrown if the client info is empty.
+ * @param rawClientInfo
+ */
+ ClientAuthError.createClientInfoEmptyError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.clientInfoEmptyError.code, "" + ClientAuthErrorMessage.clientInfoEmptyError.desc);
+ };
+ /**
+ * Creates an error thrown when the id token extraction errors out.
+ * @param err
+ */
+ ClientAuthError.createTokenParsingError = function (caughtExtractionError) {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenParsingError.code, ClientAuthErrorMessage.tokenParsingError.desc + " Failed with error: " + caughtExtractionError);
+ };
+ /**
+ * Creates an error thrown when the id token string is null or empty.
+ * @param invalidRawTokenString
+ */
+ ClientAuthError.createTokenNullOrEmptyError = function (invalidRawTokenString) {
+ return new ClientAuthError(ClientAuthErrorMessage.nullOrEmptyToken.code, ClientAuthErrorMessage.nullOrEmptyToken.desc + " Raw Token Value: " + invalidRawTokenString);
+ };
+ /**
+ * Creates an error thrown when the endpoint discovery doesn't complete correctly.
+ */
+ ClientAuthError.createEndpointDiscoveryIncompleteError = function (errDetail) {
+ return new ClientAuthError(ClientAuthErrorMessage.endpointResolutionError.code, ClientAuthErrorMessage.endpointResolutionError.desc + " Detail: " + errDetail);
+ };
+ /**
+ * Creates an error thrown when the openid-configuration endpoint cannot be reached or does not contain the required data
+ */
+ ClientAuthError.createUnableToGetOpenidConfigError = function (errDetail) {
+ return new ClientAuthError(ClientAuthErrorMessage.unableToGetOpenidConfigError.code, ClientAuthErrorMessage.unableToGetOpenidConfigError.desc + " Attempted to retrieve endpoints from: " + errDetail);
+ };
+ /**
+ * Creates an error thrown when the hash cannot be deserialized.
+ * @param hashParamObj
+ */
+ ClientAuthError.createHashNotDeserializedError = function (hashParamObj) {
+ return new ClientAuthError(ClientAuthErrorMessage.hashNotDeserialized.code, ClientAuthErrorMessage.hashNotDeserialized.desc + " Given Object: " + hashParamObj);
+ };
+ /**
+ * Creates an error thrown when the state cannot be parsed.
+ * @param invalidState
+ */
+ ClientAuthError.createInvalidStateError = function (invalidState, errorString) {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidStateError.code, ClientAuthErrorMessage.invalidStateError.desc + " Invalid State: " + invalidState + ", Root Err: " + errorString);
+ };
+ /**
+ * Creates an error thrown when two states do not match.
+ */
+ ClientAuthError.createStateMismatchError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.stateMismatchError.code, ClientAuthErrorMessage.stateMismatchError.desc);
+ };
+ /**
+ * Creates an error thrown when the state is not present
+ * @param missingState
+ */
+ ClientAuthError.createStateNotFoundError = function (missingState) {
+ return new ClientAuthError(ClientAuthErrorMessage.stateNotFoundError.code, ClientAuthErrorMessage.stateNotFoundError.desc + ": " + missingState);
+ };
+ /**
+ * Creates an error thrown when the nonce does not match.
+ */
+ ClientAuthError.createNonceMismatchError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.nonceMismatchError.code, ClientAuthErrorMessage.nonceMismatchError.desc);
+ };
+ /**
+ * Creates an error thrown when the mnonce is not present
+ * @param missingNonce
+ */
+ ClientAuthError.createNonceNotFoundError = function (missingNonce) {
+ return new ClientAuthError(ClientAuthErrorMessage.nonceNotFoundError.code, ClientAuthErrorMessage.nonceNotFoundError.desc + ": " + missingNonce);
+ };
+ /**
+ * Creates an error thrown when the authorization code required for a token request is null or empty.
+ */
+ ClientAuthError.createNoTokensFoundError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.noTokensFoundError.code, ClientAuthErrorMessage.noTokensFoundError.desc);
+ };
+ /**
+ * Throws error when multiple tokens are in cache.
+ */
+ ClientAuthError.createMultipleMatchingTokensInCacheError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.multipleMatchingTokens.code, ClientAuthErrorMessage.multipleMatchingTokens.desc + ".");
+ };
+ /**
+ * Throws error when multiple accounts are in cache for the given params
+ */
+ ClientAuthError.createMultipleMatchingAccountsInCacheError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.multipleMatchingAccounts.code, ClientAuthErrorMessage.multipleMatchingAccounts.desc);
+ };
+ /**
+ * Throws error when multiple appMetada are in cache for the given clientId.
+ */
+ ClientAuthError.createMultipleMatchingAppMetadataInCacheError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.multipleMatchingAppMetadata.code, ClientAuthErrorMessage.multipleMatchingAppMetadata.desc);
+ };
+ /**
+ * Throws error when no auth code or refresh token is given to ServerTokenRequestParameters.
+ */
+ ClientAuthError.createTokenRequestCannotBeMadeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenRequestCannotBeMade.code, ClientAuthErrorMessage.tokenRequestCannotBeMade.desc);
+ };
+ /**
+ * Throws error when attempting to append a null, undefined or empty scope to a set
+ * @param givenScope
+ */
+ ClientAuthError.createAppendEmptyScopeToSetError = function (givenScope) {
+ return new ClientAuthError(ClientAuthErrorMessage.appendEmptyScopeError.code, ClientAuthErrorMessage.appendEmptyScopeError.desc + " Given Scope: " + givenScope);
+ };
+ /**
+ * Throws error when attempting to append a null, undefined or empty scope to a set
+ * @param givenScope
+ */
+ ClientAuthError.createRemoveEmptyScopeFromSetError = function (givenScope) {
+ return new ClientAuthError(ClientAuthErrorMessage.removeEmptyScopeError.code, ClientAuthErrorMessage.removeEmptyScopeError.desc + " Given Scope: " + givenScope);
+ };
+ /**
+ * Throws error when attempting to append null or empty ScopeSet.
+ * @param appendError
+ */
+ ClientAuthError.createAppendScopeSetError = function (appendError) {
+ return new ClientAuthError(ClientAuthErrorMessage.appendScopeSetError.code, ClientAuthErrorMessage.appendScopeSetError.desc + " Detail Error: " + appendError);
+ };
+ /**
+ * Throws error if ScopeSet is null or undefined.
+ * @param givenScopeSet
+ */
+ ClientAuthError.createEmptyInputScopeSetError = function (givenScopeSet) {
+ return new ClientAuthError(ClientAuthErrorMessage.emptyInputScopeSetError.code, ClientAuthErrorMessage.emptyInputScopeSetError.desc + " Given ScopeSet: " + givenScopeSet);
+ };
+ /**
+ * Throws error if user sets CancellationToken.cancel = true during polling of token endpoint during device code flow
+ */
+ ClientAuthError.createDeviceCodeCancelledError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.DeviceCodePollingCancelled.code, "" + ClientAuthErrorMessage.DeviceCodePollingCancelled.desc);
+ };
+ /**
+ * Throws error if device code is expired
+ */
+ ClientAuthError.createDeviceCodeExpiredError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.DeviceCodeExpired.code, "" + ClientAuthErrorMessage.DeviceCodeExpired.desc);
+ };
+ /**
+ * Throws error when silent requests are made without an account object
+ */
+ ClientAuthError.createNoAccountInSilentRequestError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.NoAccountInSilentRequest.code, "" + ClientAuthErrorMessage.NoAccountInSilentRequest.desc);
+ };
+ /**
+ * Throws error when cache record is null or undefined.
+ */
+ ClientAuthError.createNullOrUndefinedCacheRecord = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidCacheRecord.code, ClientAuthErrorMessage.invalidCacheRecord.desc);
+ };
+ /**
+ * Throws error when provided environment is not part of the CloudDiscoveryMetadata object
+ */
+ ClientAuthError.createInvalidCacheEnvironmentError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidCacheEnvironment.code, ClientAuthErrorMessage.invalidCacheEnvironment.desc);
+ };
+ /**
+ * Throws error when account is not found in cache.
+ */
+ ClientAuthError.createNoAccountFoundError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.noAccountFound.code, ClientAuthErrorMessage.noAccountFound.desc);
+ };
+ /**
+ * Throws error if ICachePlugin not set on CacheManager.
+ */
+ ClientAuthError.createCachePluginError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.CachePluginError.code, "" + ClientAuthErrorMessage.CachePluginError.desc);
+ };
+ /**
+ * Throws error if crypto object not found.
+ * @param operationName
+ */
+ ClientAuthError.createNoCryptoObjectError = function (operationName) {
+ return new ClientAuthError(ClientAuthErrorMessage.noCryptoObj.code, "" + ClientAuthErrorMessage.noCryptoObj.desc + operationName);
+ };
+ /**
+ * Throws error if cache type is invalid.
+ */
+ ClientAuthError.createInvalidCacheTypeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidCacheType.code, "" + ClientAuthErrorMessage.invalidCacheType.desc);
+ };
+ /**
+ * Throws error if unexpected account type.
+ */
+ ClientAuthError.createUnexpectedAccountTypeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.unexpectedAccountType.code, "" + ClientAuthErrorMessage.unexpectedAccountType.desc);
+ };
+ /**
+ * Throws error if unexpected credential type.
+ */
+ ClientAuthError.createUnexpectedCredentialTypeError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.unexpectedCredentialType.code, "" + ClientAuthErrorMessage.unexpectedCredentialType.desc);
+ };
+ /**
+ * Throws error if client assertion is not valid.
+ */
+ ClientAuthError.createInvalidAssertionError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidAssertion.code, "" + ClientAuthErrorMessage.invalidAssertion.desc);
+ };
+ /**
+ * Throws error if client assertion is not valid.
+ */
+ ClientAuthError.createInvalidCredentialError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.invalidClientCredential.code, "" + ClientAuthErrorMessage.invalidClientCredential.desc);
+ };
+ /**
+ * Throws error if token cannot be retrieved from cache due to refresh being required.
+ */
+ ClientAuthError.createRefreshRequiredError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenRefreshRequired.code, ClientAuthErrorMessage.tokenRefreshRequired.desc);
+ };
+ /**
+ * Throws error if the user defined timeout is reached.
+ */
+ ClientAuthError.createUserTimeoutReachedError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.userTimeoutReached.code, ClientAuthErrorMessage.userTimeoutReached.desc);
+ };
+ /*
+ * Throws error if token claims are not populated for a signed jwt generation
+ */
+ ClientAuthError.createTokenClaimsRequiredError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.tokenClaimsRequired.code, ClientAuthErrorMessage.tokenClaimsRequired.desc);
+ };
+ /**
+ * Throws error when the authorization code is missing from the server response
+ */
+ ClientAuthError.createNoAuthCodeInServerResponseError = function () {
+ return new ClientAuthError(ClientAuthErrorMessage.noAuthorizationCodeFromServer.code, ClientAuthErrorMessage.noAuthorizationCodeFromServer.desc);
+ };
+ return ClientAuthError;
+}(AuthError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * @hidden
+ */
+var StringUtils = /** @class */ (function () {
+ function StringUtils() {
+ }
+ /**
+ * decode a JWT
+ *
+ * @param authToken
+ */
+ StringUtils.decodeAuthToken = function (authToken) {
+ if (StringUtils.isEmpty(authToken)) {
+ throw ClientAuthError.createTokenNullOrEmptyError(authToken);
+ }
+ var tokenPartsRegex = /^([^\.\s]*)\.([^\.\s]+)\.([^\.\s]*)$/;
+ var matches = tokenPartsRegex.exec(authToken);
+ if (!matches || matches.length < 4) {
+ throw ClientAuthError.createTokenParsingError("Given token is malformed: " + JSON.stringify(authToken));
+ }
+ var crackedToken = {
+ header: matches[1],
+ JWSPayload: matches[2],
+ JWSSig: matches[3]
+ };
+ return crackedToken;
+ };
+ /**
+ * Check if a string is empty.
+ *
+ * @param str
+ */
+ StringUtils.isEmpty = function (str) {
+ return (typeof str === "undefined" || !str || 0 === str.length);
+ };
+ StringUtils.startsWith = function (str, search) {
+ return str.indexOf(search) === 0;
+ };
+ StringUtils.endsWith = function (str, search) {
+ return (str.length >= search.length) && (str.lastIndexOf(search) === (str.length - search.length));
+ };
+ /**
+ * Parses string into an object.
+ *
+ * @param query
+ */
+ StringUtils.queryStringToObject = function (query) {
+ var match; // Regex for replacing addition symbol with a space
+ var pl = /\+/g;
+ var search = /([^&=]+)=([^&]*)/g;
+ var decode = function (s) { return decodeURIComponent(decodeURIComponent(s.replace(pl, " "))); };
+ var obj = {};
+ match = search.exec(query);
+ while (match) {
+ obj[decode(match[1])] = decode(match[2]);
+ match = search.exec(query);
+ }
+ return obj;
+ };
+ /**
+ * Trims entries in an array.
+ *
+ * @param arr
+ */
+ StringUtils.trimArrayEntries = function (arr) {
+ return arr.map(function (entry) { return entry.trim(); });
+ };
+ /**
+ * Removes empty strings from array
+ * @param arr
+ */
+ StringUtils.removeEmptyStringsFromArray = function (arr) {
+ return arr.filter(function (entry) {
+ return !StringUtils.isEmpty(entry);
+ });
+ };
+ /**
+ * Attempts to parse a string into JSON
+ * @param str
+ */
+ StringUtils.jsonParseHelper = function (str) {
+ try {
+ return JSON.parse(str);
+ }
+ catch (e) {
+ return null;
+ }
+ };
+ /**
+ * Tests if a given string matches a given pattern, with support for wildcards.
+ * @param pattern Wildcard pattern to string match. Supports "*" for wildcards
+ * @param input String to match against
+ */
+ StringUtils.matchPattern = function (pattern, input) {
+ // https://stackoverflow.com/a/3117248/4888559
+ var regex = new RegExp(pattern.replace(/\*/g, "[^ ]*"));
+ return regex.test(input);
+ };
+ return StringUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+(function (LogLevel) {
+ LogLevel[LogLevel["Error"] = 0] = "Error";
+ LogLevel[LogLevel["Warning"] = 1] = "Warning";
+ LogLevel[LogLevel["Info"] = 2] = "Info";
+ LogLevel[LogLevel["Verbose"] = 3] = "Verbose";
+})(exports.LogLevel || (exports.LogLevel = {}));
+/**
+ * Class which facilitates logging of messages to a specific place.
+ */
+var Logger = /** @class */ (function () {
+ function Logger(loggerOptions, packageName, packageVersion) {
+ // Current log level, defaults to info.
+ this.level = exports.LogLevel.Info;
+ var defaultLoggerCallback = function () { };
+ this.localCallback = loggerOptions.loggerCallback || defaultLoggerCallback;
+ this.piiLoggingEnabled = loggerOptions.piiLoggingEnabled || false;
+ this.level = loggerOptions.logLevel || exports.LogLevel.Info;
+ this.packageName = packageName || Constants.EMPTY_STRING;
+ this.packageVersion = packageVersion || Constants.EMPTY_STRING;
+ }
+ /**
+ * Create new Logger with existing configurations.
+ */
+ Logger.prototype.clone = function (packageName, packageVersion) {
+ return new Logger({ loggerCallback: this.localCallback, piiLoggingEnabled: this.piiLoggingEnabled, logLevel: this.level }, packageName, packageVersion);
+ };
+ /**
+ * Log message with required options.
+ */
+ Logger.prototype.logMessage = function (logMessage, options) {
+ if ((options.logLevel > this.level) || (!this.piiLoggingEnabled && options.containsPii)) {
+ return;
+ }
+ var timestamp = new Date().toUTCString();
+ var logHeader = StringUtils.isEmpty(this.correlationId) ? "[" + timestamp + "] : " : "[" + timestamp + "] : [" + this.correlationId + "]";
+ var log = logHeader + " : " + this.packageName + "@" + this.packageVersion + " : " + exports.LogLevel[options.logLevel] + " - " + logMessage;
+ // debug(`msal:${LogLevel[options.logLevel]}${options.containsPii ? "-Pii": ""}${options.context ? `:${options.context}` : ""}`)(logMessage);
+ this.executeCallback(options.logLevel, log, options.containsPii || false);
+ };
+ /**
+ * Execute callback with message.
+ */
+ Logger.prototype.executeCallback = function (level, message, containsPii) {
+ if (this.localCallback) {
+ this.localCallback(level, message, containsPii);
+ }
+ };
+ /**
+ * Logs error messages.
+ */
+ Logger.prototype.error = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Error,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs error messages with PII.
+ */
+ Logger.prototype.errorPii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Error,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs warning messages.
+ */
+ Logger.prototype.warning = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Warning,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs warning messages with PII.
+ */
+ Logger.prototype.warningPii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Warning,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs info messages.
+ */
+ Logger.prototype.info = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Info,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs info messages with PII.
+ */
+ Logger.prototype.infoPii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Info,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs verbose messages.
+ */
+ Logger.prototype.verbose = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Verbose,
+ containsPii: false,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Logs verbose messages with PII.
+ */
+ Logger.prototype.verbosePii = function (message, correlationId) {
+ this.logMessage(message, {
+ logLevel: exports.LogLevel.Verbose,
+ containsPii: true,
+ correlationId: correlationId || ""
+ });
+ };
+ /**
+ * Returns whether PII Logging is enabled or not.
+ */
+ Logger.prototype.isPiiLoggingEnabled = function () {
+ return this.piiLoggingEnabled || false;
+ };
+ return Logger;
+}());
+
+/* eslint-disable header/header */
+var name = "@azure/msal-common";
+var version = "4.0.1";
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Base type for credentials to be stored in the cache: eg: ACCESS_TOKEN, ID_TOKEN etc
+ *
+ * Key:Value Schema:
+ *
+ * Key: -----
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, usually only used for refresh tokens
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * oboAssertion: access token passed in as part of OBO request
+ * }
+ */
+var CredentialEntity = /** @class */ (function () {
+ function CredentialEntity() {
+ }
+ /**
+ * Generate Account Id key component as per the schema: -
+ */
+ CredentialEntity.prototype.generateAccountId = function () {
+ return CredentialEntity.generateAccountIdForCacheKey(this.homeAccountId, this.environment);
+ };
+ /**
+ * Generate Credential Id key component as per the schema: --
+ */
+ CredentialEntity.prototype.generateCredentialId = function () {
+ return CredentialEntity.generateCredentialIdForCacheKey(this.credentialType, this.clientId, this.realm, this.familyId);
+ };
+ /**
+ * Generate target key component as per schema:
+ */
+ CredentialEntity.prototype.generateTarget = function () {
+ return CredentialEntity.generateTargetForCacheKey(this.target);
+ };
+ /**
+ * generates credential key
+ */
+ CredentialEntity.prototype.generateCredentialKey = function () {
+ return CredentialEntity.generateCredentialCacheKey(this.homeAccountId, this.environment, this.credentialType, this.clientId, this.realm, this.target, this.familyId);
+ };
+ /**
+ * returns the type of the cache (in this case credential)
+ */
+ CredentialEntity.prototype.generateType = function () {
+ switch (this.credentialType) {
+ case exports.CredentialType.ID_TOKEN:
+ return exports.CacheType.ID_TOKEN;
+ case exports.CredentialType.ACCESS_TOKEN:
+ return exports.CacheType.ACCESS_TOKEN;
+ case exports.CredentialType.REFRESH_TOKEN:
+ return exports.CacheType.REFRESH_TOKEN;
+ default: {
+ throw ClientAuthError.createUnexpectedCredentialTypeError();
+ }
+ }
+ };
+ /**
+ * helper function to return `CredentialType`
+ * @param key
+ */
+ CredentialEntity.getCredentialType = function (key) {
+ if (key.indexOf(exports.CredentialType.ACCESS_TOKEN.toLowerCase()) !== -1) {
+ return exports.CredentialType.ACCESS_TOKEN;
+ }
+ else if (key.indexOf(exports.CredentialType.ID_TOKEN.toLowerCase()) !== -1) {
+ return exports.CredentialType.ID_TOKEN;
+ }
+ else if (key.indexOf(exports.CredentialType.REFRESH_TOKEN.toLowerCase()) !== -1) {
+ return exports.CredentialType.REFRESH_TOKEN;
+ }
+ return Constants.NOT_DEFINED;
+ };
+ /**
+ * generates credential key
+ */
+ CredentialEntity.generateCredentialCacheKey = function (homeAccountId, environment, credentialType, clientId, realm, target, familyId) {
+ var credentialKey = [
+ this.generateAccountIdForCacheKey(homeAccountId, environment),
+ this.generateCredentialIdForCacheKey(credentialType, clientId, realm, familyId),
+ this.generateTargetForCacheKey(target),
+ ];
+ return credentialKey.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * generates Account Id for keys
+ * @param homeAccountId
+ * @param environment
+ */
+ CredentialEntity.generateAccountIdForCacheKey = function (homeAccountId, environment) {
+ var accountId = [homeAccountId, environment];
+ return accountId.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Generates Credential Id for keys
+ * @param credentialType
+ * @param realm
+ * @param clientId
+ * @param familyId
+ */
+ CredentialEntity.generateCredentialIdForCacheKey = function (credentialType, clientId, realm, familyId) {
+ var clientOrFamilyId = credentialType === exports.CredentialType.REFRESH_TOKEN
+ ? familyId || clientId
+ : clientId;
+ var credentialId = [
+ credentialType,
+ clientOrFamilyId,
+ realm || "",
+ ];
+ return credentialId.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Generate target key component as per schema:
+ */
+ CredentialEntity.generateTargetForCacheKey = function (scopes) {
+ return (scopes || "").toLowerCase();
+ };
+ return CredentialEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ClientConfigurationErrorMessage class containing string constants used by error codes and messages.
+ */
+var ClientConfigurationErrorMessage = {
+ redirectUriNotSet: {
+ code: "redirect_uri_empty",
+ desc: "A redirect URI is required for all calls, and none has been set."
+ },
+ postLogoutUriNotSet: {
+ code: "post_logout_uri_empty",
+ desc: "A post logout redirect has not been set."
+ },
+ claimsRequestParsingError: {
+ code: "claims_request_parsing_error",
+ desc: "Could not parse the given claims request object."
+ },
+ authorityUriInsecure: {
+ code: "authority_uri_insecure",
+ desc: "Authority URIs must use https. Please see here for valid authority configuration options: https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-js-initializing-client-applications#configuration-options"
+ },
+ urlParseError: {
+ code: "url_parse_error",
+ desc: "URL could not be parsed into appropriate segments."
+ },
+ urlEmptyError: {
+ code: "empty_url_error",
+ desc: "URL was empty or null."
+ },
+ emptyScopesError: {
+ code: "empty_input_scopes_error",
+ desc: "Scopes cannot be passed as null, undefined or empty array because they are required to obtain an access token."
+ },
+ nonArrayScopesError: {
+ code: "nonarray_input_scopes_error",
+ desc: "Scopes cannot be passed as non-array."
+ },
+ clientIdSingleScopeError: {
+ code: "clientid_input_scopes_error",
+ desc: "Client ID can only be provided as a single scope."
+ },
+ invalidPrompt: {
+ code: "invalid_prompt_value",
+ desc: "Supported prompt values are 'login', 'select_account', 'consent' and 'none'. Please see here for valid configuration options: https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-js-initializing-client-applications#configuration-options",
+ },
+ invalidClaimsRequest: {
+ code: "invalid_claims",
+ desc: "Given claims parameter must be a stringified JSON object."
+ },
+ tokenRequestEmptyError: {
+ code: "token_request_empty",
+ desc: "Token request was empty and not found in cache."
+ },
+ logoutRequestEmptyError: {
+ code: "logout_request_empty",
+ desc: "The logout request was null or undefined."
+ },
+ invalidCodeChallengeMethod: {
+ code: "invalid_code_challenge_method",
+ desc: "code_challenge_method passed is invalid. Valid values are \"plain\" and \"S256\"."
+ },
+ invalidCodeChallengeParams: {
+ code: "pkce_params_missing",
+ desc: "Both params: code_challenge and code_challenge_method are to be passed if to be sent in the request"
+ },
+ invalidCloudDiscoveryMetadata: {
+ code: "invalid_cloud_discovery_metadata",
+ desc: "Invalid cloudDiscoveryMetadata provided. Must be a JSON object containing tenant_discovery_endpoint and metadata fields"
+ },
+ invalidAuthorityMetadata: {
+ code: "invalid_authority_metadata",
+ desc: "Invalid authorityMetadata provided. Must by a JSON object containing authorization_endpoint, token_endpoint, end_session_endpoint, issuer fields."
+ },
+ untrustedAuthority: {
+ code: "untrusted_authority",
+ desc: "The provided authority is not a trusted authority. Please include this authority in the knownAuthorities config parameter."
+ },
+ resourceRequestParametersRequired: {
+ code: "resourceRequest_parameters_required",
+ desc: "resourceRequestMethod and resourceRequestUri are required"
+ }
+};
+/**
+ * Error thrown when there is an error in configuration of the MSAL.js library.
+ */
+var ClientConfigurationError = /** @class */ (function (_super) {
+ __extends(ClientConfigurationError, _super);
+ function ClientConfigurationError(errorCode, errorMessage) {
+ var _this = _super.call(this, errorCode, errorMessage) || this;
+ _this.name = "ClientConfigurationError";
+ Object.setPrototypeOf(_this, ClientConfigurationError.prototype);
+ return _this;
+ }
+ /**
+ * Creates an error thrown when the redirect uri is empty (not set by caller)
+ */
+ ClientConfigurationError.createRedirectUriEmptyError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.redirectUriNotSet.code, ClientConfigurationErrorMessage.redirectUriNotSet.desc);
+ };
+ /**
+ * Creates an error thrown when the post-logout redirect uri is empty (not set by caller)
+ */
+ ClientConfigurationError.createPostLogoutRedirectUriEmptyError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.postLogoutUriNotSet.code, ClientConfigurationErrorMessage.postLogoutUriNotSet.desc);
+ };
+ /**
+ * Creates an error thrown when the claims request could not be successfully parsed
+ */
+ ClientConfigurationError.createClaimsRequestParsingError = function (claimsRequestParseError) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.claimsRequestParsingError.code, ClientConfigurationErrorMessage.claimsRequestParsingError.desc + " Given value: " + claimsRequestParseError);
+ };
+ /**
+ * Creates an error thrown if authority uri is given an insecure protocol.
+ * @param urlString
+ */
+ ClientConfigurationError.createInsecureAuthorityUriError = function (urlString) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.authorityUriInsecure.code, ClientConfigurationErrorMessage.authorityUriInsecure.desc + " Given URI: " + urlString);
+ };
+ /**
+ * Creates an error thrown if URL string does not parse into separate segments.
+ * @param urlString
+ */
+ ClientConfigurationError.createUrlParseError = function (urlParseError) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.urlParseError.code, ClientConfigurationErrorMessage.urlParseError.desc + " Given Error: " + urlParseError);
+ };
+ /**
+ * Creates an error thrown if URL string is empty or null.
+ * @param urlString
+ */
+ ClientConfigurationError.createUrlEmptyError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.urlEmptyError.code, ClientConfigurationErrorMessage.urlEmptyError.desc);
+ };
+ /**
+ * Error thrown when scopes are not an array
+ * @param inputScopes
+ */
+ ClientConfigurationError.createScopesNonArrayError = function (inputScopes) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.nonArrayScopesError.code, ClientConfigurationErrorMessage.nonArrayScopesError.desc + " Given Scopes: " + inputScopes);
+ };
+ /**
+ * Error thrown when scopes are empty.
+ * @param scopesValue
+ */
+ ClientConfigurationError.createEmptyScopesArrayError = function (inputScopes) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.emptyScopesError.code, ClientConfigurationErrorMessage.emptyScopesError.desc + " Given Scopes: " + inputScopes);
+ };
+ /**
+ * Error thrown when client id scope is not provided as single scope.
+ * @param inputScopes
+ */
+ ClientConfigurationError.createClientIdSingleScopeError = function (inputScopes) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.clientIdSingleScopeError.code, ClientConfigurationErrorMessage.clientIdSingleScopeError.desc + " Given Scopes: " + inputScopes);
+ };
+ /**
+ * Error thrown when prompt is not an allowed type.
+ * @param promptValue
+ */
+ ClientConfigurationError.createInvalidPromptError = function (promptValue) {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidPrompt.code, ClientConfigurationErrorMessage.invalidPrompt.desc + " Given value: " + promptValue);
+ };
+ /**
+ * Creates error thrown when claims parameter is not a stringified JSON object
+ */
+ ClientConfigurationError.createInvalidClaimsRequestError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidClaimsRequest.code, ClientConfigurationErrorMessage.invalidClaimsRequest.desc);
+ };
+ /**
+ * Throws error when token request is empty and nothing cached in storage.
+ */
+ ClientConfigurationError.createEmptyLogoutRequestError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.logoutRequestEmptyError.code, ClientConfigurationErrorMessage.logoutRequestEmptyError.desc);
+ };
+ /**
+ * Throws error when token request is empty and nothing cached in storage.
+ */
+ ClientConfigurationError.createEmptyTokenRequestError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.tokenRequestEmptyError.code, ClientConfigurationErrorMessage.tokenRequestEmptyError.desc);
+ };
+ /**
+ * Throws error when an invalid code_challenge_method is passed by the user
+ */
+ ClientConfigurationError.createInvalidCodeChallengeMethodError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidCodeChallengeMethod.code, ClientConfigurationErrorMessage.invalidCodeChallengeMethod.desc);
+ };
+ /**
+ * Throws error when both params: code_challenge and code_challenge_method are not passed together
+ */
+ ClientConfigurationError.createInvalidCodeChallengeParamsError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidCodeChallengeParams.code, ClientConfigurationErrorMessage.invalidCodeChallengeParams.desc);
+ };
+ /**
+ * Throws an error when the user passes invalid cloudDiscoveryMetadata
+ */
+ ClientConfigurationError.createInvalidCloudDiscoveryMetadataError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidCloudDiscoveryMetadata.code, ClientConfigurationErrorMessage.invalidCloudDiscoveryMetadata.desc);
+ };
+ /**
+ * Throws an error when the user passes invalid cloudDiscoveryMetadata
+ */
+ ClientConfigurationError.createInvalidAuthorityMetadataError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.invalidAuthorityMetadata.code, ClientConfigurationErrorMessage.invalidAuthorityMetadata.desc);
+ };
+ /**
+ * Throws error when provided authority is not a member of the trusted host list
+ */
+ ClientConfigurationError.createUntrustedAuthorityError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.untrustedAuthority.code, ClientConfigurationErrorMessage.untrustedAuthority.desc);
+ };
+ /**
+ * Throws error when resourceRequestMethod or resourceRequestUri is missing
+ */
+ ClientConfigurationError.createResourceRequestParametersRequiredError = function () {
+ return new ClientConfigurationError(ClientConfigurationErrorMessage.resourceRequestParametersRequired.code, ClientConfigurationErrorMessage.resourceRequestParametersRequired.desc);
+ };
+ return ClientConfigurationError;
+}(ClientAuthError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * The ScopeSet class creates a set of scopes. Scopes are case-insensitive, unique values, so the Set object in JS makes
+ * the most sense to implement for this class. All scopes are trimmed and converted to lower case strings in intersection and union functions
+ * to ensure uniqueness of strings.
+ */
+var ScopeSet = /** @class */ (function () {
+ function ScopeSet(inputScopes) {
+ var _this = this;
+ // Filter empty string and null/undefined array items
+ var scopeArr = inputScopes ? StringUtils.trimArrayEntries(__spreadArrays(inputScopes)) : [];
+ var filteredInput = scopeArr ? StringUtils.removeEmptyStringsFromArray(scopeArr) : [];
+ // Validate and filter scopes (validate function throws if validation fails)
+ this.validateInputScopes(filteredInput);
+ this.scopes = new Set(); // Iterator in constructor not supported by IE11
+ filteredInput.forEach(function (scope) { return _this.scopes.add(scope); });
+ }
+ /**
+ * Factory method to create ScopeSet from space-delimited string
+ * @param inputScopeString
+ * @param appClientId
+ * @param scopesRequired
+ */
+ ScopeSet.fromString = function (inputScopeString) {
+ inputScopeString = inputScopeString || "";
+ var inputScopes = inputScopeString.split(" ");
+ return new ScopeSet(inputScopes);
+ };
+ /**
+ * Used to validate the scopes input parameter requested by the developer.
+ * @param {Array} inputScopes - Developer requested permissions. Not all scopes are guaranteed to be included in the access token returned.
+ * @param {boolean} scopesRequired - Boolean indicating whether the scopes array is required or not
+ */
+ ScopeSet.prototype.validateInputScopes = function (inputScopes) {
+ // Check if scopes are required but not given or is an empty array
+ if (!inputScopes || inputScopes.length < 1) {
+ throw ClientConfigurationError.createEmptyScopesArrayError(inputScopes);
+ }
+ };
+ /**
+ * Check if a given scope is present in this set of scopes.
+ * @param scope
+ */
+ ScopeSet.prototype.containsScope = function (scope) {
+ var lowerCaseScopes = this.printScopesLowerCase().split(" ");
+ var lowerCaseScopesSet = new ScopeSet(lowerCaseScopes);
+ // compare lowercase scopes
+ return !StringUtils.isEmpty(scope) ? lowerCaseScopesSet.scopes.has(scope.toLowerCase()) : false;
+ };
+ /**
+ * Check if a set of scopes is present in this set of scopes.
+ * @param scopeSet
+ */
+ ScopeSet.prototype.containsScopeSet = function (scopeSet) {
+ var _this = this;
+ if (!scopeSet || scopeSet.scopes.size <= 0) {
+ return false;
+ }
+ return (this.scopes.size >= scopeSet.scopes.size && scopeSet.asArray().every(function (scope) { return _this.containsScope(scope); }));
+ };
+ /**
+ * Check if set of scopes contains only the defaults
+ */
+ ScopeSet.prototype.containsOnlyOIDCScopes = function () {
+ var _this = this;
+ var defaultScopeCount = 0;
+ OIDC_SCOPES.forEach(function (defaultScope) {
+ if (_this.containsScope(defaultScope)) {
+ defaultScopeCount += 1;
+ }
+ });
+ return this.scopes.size === defaultScopeCount;
+ };
+ /**
+ * Appends single scope if passed
+ * @param newScope
+ */
+ ScopeSet.prototype.appendScope = function (newScope) {
+ if (!StringUtils.isEmpty(newScope)) {
+ this.scopes.add(newScope.trim());
+ }
+ };
+ /**
+ * Appends multiple scopes if passed
+ * @param newScopes
+ */
+ ScopeSet.prototype.appendScopes = function (newScopes) {
+ var _this = this;
+ try {
+ newScopes.forEach(function (newScope) { return _this.appendScope(newScope); });
+ }
+ catch (e) {
+ throw ClientAuthError.createAppendScopeSetError(e);
+ }
+ };
+ /**
+ * Removes element from set of scopes.
+ * @param scope
+ */
+ ScopeSet.prototype.removeScope = function (scope) {
+ if (StringUtils.isEmpty(scope)) {
+ throw ClientAuthError.createRemoveEmptyScopeFromSetError(scope);
+ }
+ this.scopes.delete(scope.trim());
+ };
+ /**
+ * Removes default scopes from set of scopes
+ * Primarily used to prevent cache misses if the default scopes are not returned from the server
+ */
+ ScopeSet.prototype.removeOIDCScopes = function () {
+ var _this = this;
+ OIDC_SCOPES.forEach(function (defaultScope) {
+ _this.scopes.delete(defaultScope);
+ });
+ };
+ /**
+ * Combines an array of scopes with the current set of scopes.
+ * @param otherScopes
+ */
+ ScopeSet.prototype.unionScopeSets = function (otherScopes) {
+ if (!otherScopes) {
+ throw ClientAuthError.createEmptyInputScopeSetError(otherScopes);
+ }
+ var unionScopes = new Set(); // Iterator in constructor not supported in IE11
+ otherScopes.scopes.forEach(function (scope) { return unionScopes.add(scope.toLowerCase()); });
+ this.scopes.forEach(function (scope) { return unionScopes.add(scope.toLowerCase()); });
+ return unionScopes;
+ };
+ /**
+ * Check if scopes intersect between this set and another.
+ * @param otherScopes
+ */
+ ScopeSet.prototype.intersectingScopeSets = function (otherScopes) {
+ if (!otherScopes) {
+ throw ClientAuthError.createEmptyInputScopeSetError(otherScopes);
+ }
+ // Do not allow OIDC scopes to be the only intersecting scopes
+ if (!otherScopes.containsOnlyOIDCScopes()) {
+ otherScopes.removeOIDCScopes();
+ }
+ var unionScopes = this.unionScopeSets(otherScopes);
+ var sizeOtherScopes = otherScopes.getScopeCount();
+ var sizeThisScopes = this.getScopeCount();
+ var sizeUnionScopes = unionScopes.size;
+ return sizeUnionScopes < (sizeThisScopes + sizeOtherScopes);
+ };
+ /**
+ * Returns size of set of scopes.
+ */
+ ScopeSet.prototype.getScopeCount = function () {
+ return this.scopes.size;
+ };
+ /**
+ * Returns the scopes as an array of string values
+ */
+ ScopeSet.prototype.asArray = function () {
+ var array = [];
+ this.scopes.forEach(function (val) { return array.push(val); });
+ return array;
+ };
+ /**
+ * Prints scopes into a space-delimited string
+ */
+ ScopeSet.prototype.printScopes = function () {
+ if (this.scopes) {
+ var scopeArr = this.asArray();
+ return scopeArr.join(" ");
+ }
+ return "";
+ };
+ /**
+ * Prints scopes into a space-delimited lower-case string (used for caching)
+ */
+ ScopeSet.prototype.printScopesLowerCase = function () {
+ return this.printScopes().toLowerCase();
+ };
+ return ScopeSet;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Function to build a client info object
+ * @param rawClientInfo
+ * @param crypto
+ */
+function buildClientInfo(rawClientInfo, crypto) {
+ if (StringUtils.isEmpty(rawClientInfo)) {
+ throw ClientAuthError.createClientInfoEmptyError();
+ }
+ try {
+ var decodedClientInfo = crypto.base64Decode(rawClientInfo);
+ return JSON.parse(decodedClientInfo);
+ }
+ catch (e) {
+ throw ClientAuthError.createClientInfoDecodingError(e);
+ }
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+(function (AuthorityType) {
+ AuthorityType[AuthorityType["Default"] = 0] = "Default";
+ AuthorityType[AuthorityType["Adfs"] = 1] = "Adfs";
+})(exports.AuthorityType || (exports.AuthorityType = {}));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Type that defines required and optional parameters for an Account field (based on universal cache schema implemented by all MSALs).
+ *
+ * Key : Value Schema
+ *
+ * Key: --
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * localAccountId: Original tenant-specific accountID, usually used for legacy cases
+ * username: primary username that represents the user, usually corresponds to preferred_username in the v2 endpt
+ * authorityType: Accounts authority type as a string
+ * name: Full name for the account, including given name and family name,
+ * clientInfo: Full base64 encoded client info received from ESTS
+ * lastModificationTime: last time this entity was modified in the cache
+ * lastModificationApp:
+ * oboAssertion: access token passed in as part of OBO request
+ * idTokenClaims: Object containing claims parsed from ID token
+ * }
+ */
+var AccountEntity = /** @class */ (function () {
+ function AccountEntity() {
+ }
+ /**
+ * Generate Account Id key component as per the schema: -
+ */
+ AccountEntity.prototype.generateAccountId = function () {
+ var accountId = [this.homeAccountId, this.environment];
+ return accountId.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Generate Account Cache Key as per the schema: --
+ */
+ AccountEntity.prototype.generateAccountKey = function () {
+ return AccountEntity.generateAccountCacheKey({
+ homeAccountId: this.homeAccountId,
+ environment: this.environment,
+ tenantId: this.realm,
+ username: this.username,
+ localAccountId: this.localAccountId
+ });
+ };
+ /**
+ * returns the type of the cache (in this case account)
+ */
+ AccountEntity.prototype.generateType = function () {
+ switch (this.authorityType) {
+ case exports.CacheAccountType.ADFS_ACCOUNT_TYPE:
+ return exports.CacheType.ADFS;
+ case exports.CacheAccountType.MSAV1_ACCOUNT_TYPE:
+ return exports.CacheType.MSA;
+ case exports.CacheAccountType.MSSTS_ACCOUNT_TYPE:
+ return exports.CacheType.MSSTS;
+ case exports.CacheAccountType.GENERIC_ACCOUNT_TYPE:
+ return exports.CacheType.GENERIC;
+ default: {
+ throw ClientAuthError.createUnexpectedAccountTypeError();
+ }
+ }
+ };
+ /**
+ * Returns the AccountInfo interface for this account.
+ */
+ AccountEntity.prototype.getAccountInfo = function () {
+ return {
+ homeAccountId: this.homeAccountId,
+ environment: this.environment,
+ tenantId: this.realm,
+ username: this.username,
+ localAccountId: this.localAccountId,
+ name: this.name,
+ idTokenClaims: this.idTokenClaims
+ };
+ };
+ /**
+ * Generates account key from interface
+ * @param accountInterface
+ */
+ AccountEntity.generateAccountCacheKey = function (accountInterface) {
+ var accountKey = [
+ accountInterface.homeAccountId,
+ accountInterface.environment || "",
+ accountInterface.tenantId || "",
+ ];
+ return accountKey.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Build Account cache from IdToken, clientInfo and authority/policy. Associated with AAD.
+ * @param clientInfo
+ * @param authority
+ * @param idToken
+ * @param policy
+ */
+ AccountEntity.createAccount = function (clientInfo, homeAccountId, authority, idToken, oboAssertion, cloudGraphHostName, msGraphHost) {
+ var _a, _b, _c, _d, _e, _f;
+ var account = new AccountEntity();
+ account.authorityType = exports.CacheAccountType.MSSTS_ACCOUNT_TYPE;
+ account.clientInfo = clientInfo;
+ account.homeAccountId = homeAccountId;
+ var env = authority.getPreferredCache();
+ if (StringUtils.isEmpty(env)) {
+ throw ClientAuthError.createInvalidCacheEnvironmentError();
+ }
+ account.environment = env;
+ // non AAD scenarios can have empty realm
+ account.realm = ((_a = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _a === void 0 ? void 0 : _a.tid) || "";
+ account.oboAssertion = oboAssertion;
+ if (idToken) {
+ account.idTokenClaims = idToken.claims;
+ // How do you account for MSA CID here?
+ account.localAccountId = ((_b = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _b === void 0 ? void 0 : _b.oid) || ((_c = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _c === void 0 ? void 0 : _c.sub) || "";
+ /*
+ * In B2C scenarios the emails claim is used instead of preferred_username and it is an array. In most cases it will contain a single email.
+ * This field should not be relied upon if a custom policy is configured to return more than 1 email.
+ */
+ account.username = ((_d = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _d === void 0 ? void 0 : _d.preferred_username) || (((_e = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _e === void 0 ? void 0 : _e.emails) ? idToken.claims.emails[0] : "");
+ account.name = (_f = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _f === void 0 ? void 0 : _f.name;
+ }
+ account.cloudGraphHostName = cloudGraphHostName;
+ account.msGraphHost = msGraphHost;
+ return account;
+ };
+ /**
+ * Builds non-AAD/ADFS account.
+ * @param authority
+ * @param idToken
+ */
+ AccountEntity.createGenericAccount = function (authority, homeAccountId, idToken, oboAssertion, cloudGraphHostName, msGraphHost) {
+ var _a, _b, _c, _d;
+ var account = new AccountEntity();
+ account.authorityType = (authority.authorityType === exports.AuthorityType.Adfs) ? exports.CacheAccountType.ADFS_ACCOUNT_TYPE : exports.CacheAccountType.GENERIC_ACCOUNT_TYPE;
+ account.homeAccountId = homeAccountId;
+ // non AAD scenarios can have empty realm
+ account.realm = "";
+ account.oboAssertion = oboAssertion;
+ var env = authority.getPreferredCache();
+ if (StringUtils.isEmpty(env)) {
+ throw ClientAuthError.createInvalidCacheEnvironmentError();
+ }
+ if (idToken) {
+ // How do you account for MSA CID here?
+ account.localAccountId = ((_a = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _a === void 0 ? void 0 : _a.oid) || ((_b = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _b === void 0 ? void 0 : _b.sub) || "";
+ // upn claim for most ADFS scenarios
+ account.username = ((_c = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _c === void 0 ? void 0 : _c.upn) || "";
+ account.name = ((_d = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _d === void 0 ? void 0 : _d.name) || "";
+ account.idTokenClaims = idToken === null || idToken === void 0 ? void 0 : idToken.claims;
+ }
+ account.environment = env;
+ account.cloudGraphHostName = cloudGraphHostName;
+ account.msGraphHost = msGraphHost;
+ /*
+ * add uniqueName to claims
+ * account.name = idToken.claims.uniqueName;
+ */
+ return account;
+ };
+ /**
+ * Generate HomeAccountId from server response
+ * @param serverClientInfo
+ * @param authType
+ */
+ AccountEntity.generateHomeAccountId = function (serverClientInfo, authType, logger, cryptoObj, idToken) {
+ var _a;
+ var accountId = ((_a = idToken === null || idToken === void 0 ? void 0 : idToken.claims) === null || _a === void 0 ? void 0 : _a.sub) ? idToken.claims.sub : Constants.EMPTY_STRING;
+ // since ADFS does not have tid and does not set client_info
+ if (authType === exports.AuthorityType.Adfs) {
+ return accountId;
+ }
+ // for cases where there is clientInfo
+ if (serverClientInfo) {
+ var clientInfo = buildClientInfo(serverClientInfo, cryptoObj);
+ if (!StringUtils.isEmpty(clientInfo.uid) && !StringUtils.isEmpty(clientInfo.utid)) {
+ return "" + clientInfo.uid + Separators.CLIENT_INFO_SEPARATOR + clientInfo.utid;
+ }
+ }
+ // default to "sub" claim
+ logger.verbose("No client info in response");
+ return accountId;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AccountEntity.isAccountEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("realm") &&
+ entity.hasOwnProperty("localAccountId") &&
+ entity.hasOwnProperty("username") &&
+ entity.hasOwnProperty("authorityType"));
+ };
+ /**
+ * Helper function to determine whether 2 accounts are equal
+ * Used to avoid unnecessary state updates
+ * @param arrayA
+ * @param arrayB
+ */
+ AccountEntity.accountInfoIsEqual = function (accountA, accountB) {
+ if (!accountA || !accountB) {
+ return false;
+ }
+ return (accountA.homeAccountId === accountB.homeAccountId) &&
+ (accountA.localAccountId === accountB.localAccountId) &&
+ (accountA.username === accountB.username) &&
+ (accountA.tenantId === accountB.tenantId) &&
+ (accountA.environment === accountB.environment);
+ };
+ return AccountEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * JWT Token representation class. Parses token string and generates claims object.
+ */
+var AuthToken = /** @class */ (function () {
+ function AuthToken(rawToken, crypto) {
+ if (StringUtils.isEmpty(rawToken)) {
+ throw ClientAuthError.createTokenNullOrEmptyError(rawToken);
+ }
+ this.rawToken = rawToken;
+ this.claims = AuthToken.extractTokenClaims(rawToken, crypto);
+ }
+ /**
+ * Extract token by decoding the rawToken
+ *
+ * @param encodedToken
+ */
+ AuthToken.extractTokenClaims = function (encodedToken, crypto) {
+ var decodedToken = StringUtils.decodeAuthToken(encodedToken);
+ // token will be decoded to get the username
+ try {
+ var base64TokenPayload = decodedToken.JWSPayload;
+ // base64Decode() should throw an error if there is an issue
+ var base64Decoded = crypto.base64Decode(base64TokenPayload);
+ return JSON.parse(base64Decoded);
+ }
+ catch (err) {
+ throw ClientAuthError.createTokenParsingError(err);
+ }
+ };
+ return AuthToken;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Interface class which implement cache storage functions used by MSAL to perform validity checks, and store tokens.
+ */
+var CacheManager = /** @class */ (function () {
+ function CacheManager(clientId, cryptoImpl) {
+ this.clientId = clientId;
+ this.cryptoImpl = cryptoImpl;
+ }
+ /**
+ * Returns all accounts in cache
+ */
+ CacheManager.prototype.getAllAccounts = function () {
+ var _this = this;
+ var currentAccounts = this.getAccountsFilteredBy();
+ var accountValues = Object.keys(currentAccounts).map(function (accountKey) { return currentAccounts[accountKey]; });
+ var numAccounts = accountValues.length;
+ if (numAccounts < 1) {
+ return [];
+ }
+ else {
+ var allAccounts = accountValues.map(function (value) {
+ var accountEntity = CacheManager.toObject(new AccountEntity(), value);
+ var accountInfo = accountEntity.getAccountInfo();
+ var idToken = _this.readIdTokenFromCache(_this.clientId, accountInfo);
+ if (idToken && !accountInfo.idTokenClaims) {
+ accountInfo.idTokenClaims = new AuthToken(idToken.secret, _this.cryptoImpl).claims;
+ }
+ return accountInfo;
+ });
+ return allAccounts;
+ }
+ };
+ /**
+ * saves a cache record
+ * @param cacheRecord
+ */
+ CacheManager.prototype.saveCacheRecord = function (cacheRecord) {
+ if (!cacheRecord) {
+ throw ClientAuthError.createNullOrUndefinedCacheRecord();
+ }
+ if (!!cacheRecord.account) {
+ this.setAccount(cacheRecord.account);
+ }
+ if (!!cacheRecord.idToken) {
+ this.setIdTokenCredential(cacheRecord.idToken);
+ }
+ if (!!cacheRecord.accessToken) {
+ this.saveAccessToken(cacheRecord.accessToken);
+ }
+ if (!!cacheRecord.refreshToken) {
+ this.setRefreshTokenCredential(cacheRecord.refreshToken);
+ }
+ if (!!cacheRecord.appMetadata) {
+ this.setAppMetadata(cacheRecord.appMetadata);
+ }
+ };
+ /**
+ * saves access token credential
+ * @param credential
+ */
+ CacheManager.prototype.saveAccessToken = function (credential) {
+ var _this = this;
+ var currentTokenCache = this.getCredentialsFilteredBy({
+ clientId: credential.clientId,
+ credentialType: exports.CredentialType.ACCESS_TOKEN,
+ environment: credential.environment,
+ homeAccountId: credential.homeAccountId,
+ realm: credential.realm,
+ });
+ var currentScopes = ScopeSet.fromString(credential.target);
+ var currentAccessTokens = Object.keys(currentTokenCache.accessTokens).map(function (key) { return currentTokenCache.accessTokens[key]; });
+ if (currentAccessTokens) {
+ currentAccessTokens.forEach(function (tokenEntity) {
+ var tokenScopeSet = ScopeSet.fromString(tokenEntity.target);
+ if (tokenScopeSet.intersectingScopeSets(currentScopes)) {
+ _this.removeCredential(tokenEntity);
+ }
+ });
+ }
+ this.setAccessTokenCredential(credential);
+ };
+ /**
+ * retrieve accounts matching all provided filters; if no filter is set, get all accounts
+ * not checking for casing as keys are all generated in lower case, remember to convert to lower case if object properties are compared
+ * @param homeAccountId
+ * @param environment
+ * @param realm
+ */
+ CacheManager.prototype.getAccountsFilteredBy = function (accountFilter) {
+ return this.getAccountsFilteredByInternal(accountFilter ? accountFilter.homeAccountId : "", accountFilter ? accountFilter.environment : "", accountFilter ? accountFilter.realm : "");
+ };
+ /**
+ * retrieve accounts matching all provided filters; if no filter is set, get all accounts
+ * not checking for casing as keys are all generated in lower case, remember to convert to lower case if object properties are compared
+ * @param homeAccountId
+ * @param environment
+ * @param realm
+ */
+ CacheManager.prototype.getAccountsFilteredByInternal = function (homeAccountId, environment, realm) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var matchingAccounts = {};
+ allCacheKeys.forEach(function (cacheKey) {
+ var entity = _this.getAccount(cacheKey);
+ if (!entity) {
+ return;
+ }
+ if (!!homeAccountId && !_this.matchHomeAccountId(entity, homeAccountId)) {
+ return;
+ }
+ if (!!environment && !_this.matchEnvironment(entity, environment)) {
+ return;
+ }
+ if (!!realm && !_this.matchRealm(entity, realm)) {
+ return;
+ }
+ matchingAccounts[cacheKey] = entity;
+ });
+ return matchingAccounts;
+ };
+ /**
+ * retrieve credentails matching all provided filters; if no filter is set, get all credentials
+ * @param homeAccountId
+ * @param environment
+ * @param credentialType
+ * @param clientId
+ * @param realm
+ * @param target
+ */
+ CacheManager.prototype.getCredentialsFilteredBy = function (filter) {
+ return this.getCredentialsFilteredByInternal(filter.homeAccountId, filter.environment, filter.credentialType, filter.clientId, filter.familyId, filter.realm, filter.target, filter.oboAssertion);
+ };
+ /**
+ * Support function to help match credentials
+ * @param homeAccountId
+ * @param environment
+ * @param credentialType
+ * @param clientId
+ * @param realm
+ * @param target
+ */
+ CacheManager.prototype.getCredentialsFilteredByInternal = function (homeAccountId, environment, credentialType, clientId, familyId, realm, target, oboAssertion) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var matchingCredentials = {
+ idTokens: {},
+ accessTokens: {},
+ refreshTokens: {},
+ };
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-credential type cache entities
+ var credType = CredentialEntity.getCredentialType(cacheKey);
+ if (credType === Constants.NOT_DEFINED) {
+ return;
+ }
+ // Attempt retrieval
+ var entity = _this.getSpecificCredential(cacheKey, credType);
+ if (!entity) {
+ return;
+ }
+ if (!!oboAssertion && !_this.matchOboAssertion(entity, oboAssertion)) {
+ return;
+ }
+ if (!!homeAccountId && !_this.matchHomeAccountId(entity, homeAccountId)) {
+ return;
+ }
+ if (!!environment && !_this.matchEnvironment(entity, environment)) {
+ return;
+ }
+ if (!!realm && !_this.matchRealm(entity, realm)) {
+ return;
+ }
+ if (!!credentialType && !_this.matchCredentialType(entity, credentialType)) {
+ return;
+ }
+ if (!!clientId && !_this.matchClientId(entity, clientId)) {
+ return;
+ }
+ if (!!familyId && !_this.matchFamilyId(entity, familyId)) {
+ return;
+ }
+ /*
+ * idTokens do not have "target", target specific refreshTokens do exist for some types of authentication
+ * Resource specific refresh tokens case will be added when the support is deemed necessary
+ */
+ if (!!target && !_this.matchTarget(entity, target)) {
+ return;
+ }
+ switch (credType) {
+ case exports.CredentialType.ID_TOKEN:
+ matchingCredentials.idTokens[cacheKey] = entity;
+ break;
+ case exports.CredentialType.ACCESS_TOKEN:
+ matchingCredentials.accessTokens[cacheKey] = entity;
+ break;
+ case exports.CredentialType.REFRESH_TOKEN:
+ matchingCredentials.refreshTokens[cacheKey] = entity;
+ break;
+ }
+ });
+ return matchingCredentials;
+ };
+ /**
+ * retrieve appMetadata matching all provided filters; if no filter is set, get all appMetadata
+ * @param filter
+ */
+ CacheManager.prototype.getAppMetadataFilteredBy = function (filter) {
+ return this.getAppMetadataFilteredByInternal(filter.environment, filter.clientId);
+ };
+ /**
+ * Support function to help match appMetadata
+ * @param environment
+ * @param clientId
+ */
+ CacheManager.prototype.getAppMetadataFilteredByInternal = function (environment, clientId) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var matchingAppMetadata = {};
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-appMetadata type cache entities
+ if (!_this.isAppMetadata(cacheKey)) {
+ return;
+ }
+ // Attempt retrieval
+ var entity = _this.getAppMetadata(cacheKey);
+ if (!entity) {
+ return;
+ }
+ if (!!environment && !_this.matchEnvironment(entity, environment)) {
+ return;
+ }
+ if (!!clientId && !_this.matchClientId(entity, clientId)) {
+ return;
+ }
+ matchingAppMetadata[cacheKey] = entity;
+ });
+ return matchingAppMetadata;
+ };
+ /**
+ * retrieve authorityMetadata that contains a matching alias
+ * @param filter
+ */
+ CacheManager.prototype.getAuthorityMetadataByAlias = function (host) {
+ var _this = this;
+ var allCacheKeys = this.getAuthorityMetadataKeys();
+ var matchedEntity = null;
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-authorityMetadata type cache entities
+ if (!_this.isAuthorityMetadata(cacheKey) || cacheKey.indexOf(_this.clientId) === -1) {
+ return;
+ }
+ // Attempt retrieval
+ var entity = _this.getAuthorityMetadata(cacheKey);
+ if (!entity) {
+ return;
+ }
+ if (entity.aliases.indexOf(host) === -1) {
+ return;
+ }
+ matchedEntity = entity;
+ });
+ return matchedEntity;
+ };
+ /**
+ * Removes all accounts and related tokens from cache.
+ */
+ CacheManager.prototype.removeAllAccounts = function () {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ allCacheKeys.forEach(function (cacheKey) {
+ var entity = _this.getAccount(cacheKey);
+ if (!entity) {
+ return;
+ }
+ _this.removeAccount(cacheKey);
+ });
+ return true;
+ };
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ CacheManager.prototype.removeAccount = function (accountKey) {
+ var account = this.getAccount(accountKey);
+ if (!account) {
+ throw ClientAuthError.createNoAccountFoundError();
+ }
+ return (this.removeAccountContext(account) && this.removeItem(accountKey, exports.CacheSchemaType.ACCOUNT));
+ };
+ /**
+ * returns a boolean if the given account is removed
+ * @param account
+ */
+ CacheManager.prototype.removeAccountContext = function (account) {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ var accountId = account.generateAccountId();
+ allCacheKeys.forEach(function (cacheKey) {
+ // don't parse any non-credential type cache entities
+ var credType = CredentialEntity.getCredentialType(cacheKey);
+ if (credType === Constants.NOT_DEFINED) {
+ return;
+ }
+ var cacheEntity = _this.getSpecificCredential(cacheKey, credType);
+ if (!!cacheEntity && accountId === cacheEntity.generateAccountId()) {
+ _this.removeCredential(cacheEntity);
+ }
+ });
+ return true;
+ };
+ /**
+ * returns a boolean if the given credential is removed
+ * @param credential
+ */
+ CacheManager.prototype.removeCredential = function (credential) {
+ var key = credential.generateCredentialKey();
+ return this.removeItem(key, exports.CacheSchemaType.CREDENTIAL);
+ };
+ /**
+ * Removes all app metadata objects from cache.
+ */
+ CacheManager.prototype.removeAppMetadata = function () {
+ var _this = this;
+ var allCacheKeys = this.getKeys();
+ allCacheKeys.forEach(function (cacheKey) {
+ if (_this.isAppMetadata(cacheKey)) {
+ _this.removeItem(cacheKey, exports.CacheSchemaType.APP_METADATA);
+ }
+ });
+ return true;
+ };
+ /**
+ * Retrieve the cached credentials into a cacherecord
+ * @param account
+ * @param clientId
+ * @param scopes
+ * @param environment
+ */
+ CacheManager.prototype.readCacheRecord = function (account, clientId, scopes, environment) {
+ var cachedAccount = this.readAccountFromCache(account);
+ var cachedIdToken = this.readIdTokenFromCache(clientId, account);
+ var cachedAccessToken = this.readAccessTokenFromCache(clientId, account, scopes);
+ var cachedRefreshToken = this.readRefreshTokenFromCache(clientId, account, false);
+ var cachedAppMetadata = this.readAppMetadataFromCache(environment, clientId);
+ if (cachedAccount && cachedIdToken) {
+ cachedAccount.idTokenClaims = new AuthToken(cachedIdToken.secret, this.cryptoImpl).claims;
+ }
+ return {
+ account: cachedAccount,
+ idToken: cachedIdToken,
+ accessToken: cachedAccessToken,
+ refreshToken: cachedRefreshToken,
+ appMetadata: cachedAppMetadata,
+ };
+ };
+ /**
+ * Retrieve AccountEntity from cache
+ * @param account
+ */
+ CacheManager.prototype.readAccountFromCache = function (account) {
+ var accountKey = AccountEntity.generateAccountCacheKey(account);
+ return this.getAccount(accountKey);
+ };
+ /**
+ * Retrieve IdTokenEntity from cache
+ * @param clientId
+ * @param account
+ * @param inputRealm
+ */
+ CacheManager.prototype.readIdTokenFromCache = function (clientId, account) {
+ var idTokenFilter = {
+ homeAccountId: account.homeAccountId,
+ environment: account.environment,
+ credentialType: exports.CredentialType.ID_TOKEN,
+ clientId: clientId,
+ realm: account.tenantId,
+ };
+ var credentialCache = this.getCredentialsFilteredBy(idTokenFilter);
+ var idTokens = Object.keys(credentialCache.idTokens).map(function (key) { return credentialCache.idTokens[key]; });
+ var numIdTokens = idTokens.length;
+ if (numIdTokens < 1) {
+ return null;
+ }
+ else if (numIdTokens > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return idTokens[0];
+ };
+ /**
+ * Retrieve AccessTokenEntity from cache
+ * @param clientId
+ * @param account
+ * @param scopes
+ * @param inputRealm
+ */
+ CacheManager.prototype.readAccessTokenFromCache = function (clientId, account, scopes) {
+ var accessTokenFilter = {
+ homeAccountId: account.homeAccountId,
+ environment: account.environment,
+ credentialType: exports.CredentialType.ACCESS_TOKEN,
+ clientId: clientId,
+ realm: account.tenantId,
+ target: scopes.printScopesLowerCase(),
+ };
+ var credentialCache = this.getCredentialsFilteredBy(accessTokenFilter);
+ var accessTokens = Object.keys(credentialCache.accessTokens).map(function (key) { return credentialCache.accessTokens[key]; });
+ var numAccessTokens = accessTokens.length;
+ if (numAccessTokens < 1) {
+ return null;
+ }
+ else if (numAccessTokens > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return accessTokens[0];
+ };
+ /**
+ * Helper to retrieve the appropriate refresh token from cache
+ * @param clientId
+ * @param account
+ * @param familyRT
+ */
+ CacheManager.prototype.readRefreshTokenFromCache = function (clientId, account, familyRT) {
+ var id = familyRT ? THE_FAMILY_ID : undefined;
+ var refreshTokenFilter = {
+ homeAccountId: account.homeAccountId,
+ environment: account.environment,
+ credentialType: exports.CredentialType.REFRESH_TOKEN,
+ clientId: clientId,
+ familyId: id
+ };
+ var credentialCache = this.getCredentialsFilteredBy(refreshTokenFilter);
+ var refreshTokens = Object.keys(credentialCache.refreshTokens).map(function (key) { return credentialCache.refreshTokens[key]; });
+ var numRefreshTokens = refreshTokens.length;
+ if (numRefreshTokens < 1) {
+ return null;
+ }
+ // address the else case after remove functions address environment aliases
+ return refreshTokens[0];
+ };
+ /**
+ * Retrieve AppMetadataEntity from cache
+ */
+ CacheManager.prototype.readAppMetadataFromCache = function (environment, clientId) {
+ var appMetadataFilter = {
+ environment: environment,
+ clientId: clientId,
+ };
+ var appMetadata = this.getAppMetadataFilteredBy(appMetadataFilter);
+ var appMetadataEntries = Object.keys(appMetadata).map(function (key) { return appMetadata[key]; });
+ var numAppMetadata = appMetadataEntries.length;
+ if (numAppMetadata < 1) {
+ return null;
+ }
+ else if (numAppMetadata > 1) {
+ throw ClientAuthError.createMultipleMatchingAppMetadataInCacheError();
+ }
+ return appMetadataEntries[0];
+ };
+ /**
+ * Return the family_id value associated with FOCI
+ * @param environment
+ * @param clientId
+ */
+ CacheManager.prototype.isAppMetadataFOCI = function (environment, clientId) {
+ var appMetadata = this.readAppMetadataFromCache(environment, clientId);
+ return !!(appMetadata && appMetadata.familyId === THE_FAMILY_ID);
+ };
+ /**
+ * helper to match account ids
+ * @param value
+ * @param homeAccountId
+ */
+ CacheManager.prototype.matchHomeAccountId = function (entity, homeAccountId) {
+ return !!(entity.homeAccountId && homeAccountId === entity.homeAccountId);
+ };
+ /**
+ * helper to match assertion
+ * @param value
+ * @param oboAssertion
+ */
+ CacheManager.prototype.matchOboAssertion = function (entity, oboAssertion) {
+ return !!(entity.oboAssertion && oboAssertion === entity.oboAssertion);
+ };
+ /**
+ * helper to match environment
+ * @param value
+ * @param environment
+ */
+ CacheManager.prototype.matchEnvironment = function (entity, environment) {
+ var cloudMetadata = this.getAuthorityMetadataByAlias(environment);
+ if (cloudMetadata && cloudMetadata.aliases.indexOf(entity.environment) > -1) {
+ return true;
+ }
+ return false;
+ };
+ /**
+ * helper to match credential type
+ * @param entity
+ * @param credentialType
+ */
+ CacheManager.prototype.matchCredentialType = function (entity, credentialType) {
+ return (entity.credentialType && credentialType.toLowerCase() === entity.credentialType.toLowerCase());
+ };
+ /**
+ * helper to match client ids
+ * @param entity
+ * @param clientId
+ */
+ CacheManager.prototype.matchClientId = function (entity, clientId) {
+ return !!(entity.clientId && clientId === entity.clientId);
+ };
+ /**
+ * helper to match family ids
+ * @param entity
+ * @param familyId
+ */
+ CacheManager.prototype.matchFamilyId = function (entity, familyId) {
+ return !!(entity.familyId && familyId === entity.familyId);
+ };
+ /**
+ * helper to match realm
+ * @param entity
+ * @param realm
+ */
+ CacheManager.prototype.matchRealm = function (entity, realm) {
+ return !!(entity.realm && realm === entity.realm);
+ };
+ /**
+ * Returns true if the target scopes are a subset of the current entity's scopes, false otherwise.
+ * @param entity
+ * @param target
+ */
+ CacheManager.prototype.matchTarget = function (entity, target) {
+ if (entity.credentialType !== exports.CredentialType.ACCESS_TOKEN || !entity.target) {
+ return false;
+ }
+ var entityScopeSet = ScopeSet.fromString(entity.target);
+ var requestTargetScopeSet = ScopeSet.fromString(target);
+ if (!requestTargetScopeSet.containsOnlyOIDCScopes()) {
+ requestTargetScopeSet.removeOIDCScopes(); // ignore OIDC scopes
+ }
+ return entityScopeSet.containsScopeSet(requestTargetScopeSet);
+ };
+ /**
+ * returns if a given cache entity is of the type appmetadata
+ * @param key
+ */
+ CacheManager.prototype.isAppMetadata = function (key) {
+ return key.indexOf(APP_METADATA) !== -1;
+ };
+ /**
+ * returns if a given cache entity is of the type authoritymetadata
+ * @param key
+ */
+ CacheManager.prototype.isAuthorityMetadata = function (key) {
+ return key.indexOf(AUTHORITY_METADATA_CONSTANTS.CACHE_KEY) !== -1;
+ };
+ /**
+ * returns cache key used for cloud instance metadata
+ */
+ CacheManager.prototype.generateAuthorityMetadataCacheKey = function (authority) {
+ return AUTHORITY_METADATA_CONSTANTS.CACHE_KEY + "-" + this.clientId + "-" + authority;
+ };
+ /**
+ * Returns the specific credential (IdToken/AccessToken/RefreshToken) from the cache
+ * @param key
+ * @param credType
+ */
+ CacheManager.prototype.getSpecificCredential = function (key, credType) {
+ switch (credType) {
+ case exports.CredentialType.ID_TOKEN: {
+ return this.getIdTokenCredential(key);
+ }
+ case exports.CredentialType.ACCESS_TOKEN: {
+ return this.getAccessTokenCredential(key);
+ }
+ case exports.CredentialType.REFRESH_TOKEN: {
+ return this.getRefreshTokenCredential(key);
+ }
+ default:
+ return null;
+ }
+ };
+ /**
+ * Helper to convert serialized data to object
+ * @param obj
+ * @param json
+ */
+ CacheManager.toObject = function (obj, json) {
+ for (var propertyName in json) {
+ obj[propertyName] = json[propertyName];
+ }
+ return obj;
+ };
+ return CacheManager;
+}());
+var DefaultStorageClass = /** @class */ (function (_super) {
+ __extends(DefaultStorageClass, _super);
+ function DefaultStorageClass() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ DefaultStorageClass.prototype.setAccount = function () {
+ var notImplErr = "Storage interface - setAccount() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAccount = function () {
+ var notImplErr = "Storage interface - getAccount() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setIdTokenCredential = function () {
+ var notImplErr = "Storage interface - setIdTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getIdTokenCredential = function () {
+ var notImplErr = "Storage interface - getIdTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setAccessTokenCredential = function () {
+ var notImplErr = "Storage interface - setAccessTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAccessTokenCredential = function () {
+ var notImplErr = "Storage interface - getAccessTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setRefreshTokenCredential = function () {
+ var notImplErr = "Storage interface - setRefreshTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getRefreshTokenCredential = function () {
+ var notImplErr = "Storage interface - getRefreshTokenCredential() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setAppMetadata = function () {
+ var notImplErr = "Storage interface - setAppMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAppMetadata = function () {
+ var notImplErr = "Storage interface - getAppMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setServerTelemetry = function () {
+ var notImplErr = "Storage interface - setServerTelemetry() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getServerTelemetry = function () {
+ var notImplErr = "Storage interface - getServerTelemetry() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setAuthorityMetadata = function () {
+ var notImplErr = "Storage interface - setAuthorityMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAuthorityMetadata = function () {
+ var notImplErr = "Storage interface - getAuthorityMetadata() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getAuthorityMetadataKeys = function () {
+ var notImplErr = "Storage interface - getAuthorityMetadataKeys() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.setThrottlingCache = function () {
+ var notImplErr = "Storage interface - setThrottlingCache() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getThrottlingCache = function () {
+ var notImplErr = "Storage interface - getThrottlingCache() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.removeItem = function () {
+ var notImplErr = "Storage interface - removeItem() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.containsKey = function () {
+ var notImplErr = "Storage interface - containsKey() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.getKeys = function () {
+ var notImplErr = "Storage interface - getKeys() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ DefaultStorageClass.prototype.clear = function () {
+ var notImplErr = "Storage interface - clear() has not been implemented for the cacheStorage interface.";
+ throw AuthError.createUnexpectedError(notImplErr);
+ };
+ return DefaultStorageClass;
+}(CacheManager));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+// Token renewal offset default in seconds
+var DEFAULT_TOKEN_RENEWAL_OFFSET_SEC = 300;
+var DEFAULT_SYSTEM_OPTIONS = {
+ tokenRenewalOffsetSeconds: DEFAULT_TOKEN_RENEWAL_OFFSET_SEC
+};
+var DEFAULT_LOGGER_IMPLEMENTATION = {
+ loggerCallback: function () {
+ // allow users to not set loggerCallback
+ },
+ piiLoggingEnabled: false,
+ logLevel: exports.LogLevel.Info
+};
+var DEFAULT_NETWORK_IMPLEMENTATION = {
+ sendGetRequestAsync: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Network interface - sendGetRequestAsync() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ },
+ sendPostRequestAsync: function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var notImplErr;
+ return __generator(this, function (_a) {
+ notImplErr = "Network interface - sendPostRequestAsync() has not been implemented";
+ throw AuthError.createUnexpectedError(notImplErr);
+ });
+ });
+ }
+};
+var DEFAULT_LIBRARY_INFO = {
+ sku: Constants.SKU,
+ version: version,
+ cpu: "",
+ os: ""
+};
+var DEFAULT_CLIENT_CREDENTIALS = {
+ clientSecret: "",
+ clientAssertion: undefined
+};
+/**
+ * Function that sets the default options when not explicitly configured from app developer
+ *
+ * @param Configuration
+ *
+ * @returns Configuration
+ */
+function buildClientConfiguration(_a) {
+ var userAuthOptions = _a.authOptions, userSystemOptions = _a.systemOptions, userLoggerOption = _a.loggerOptions, storageImplementation = _a.storageInterface, networkImplementation = _a.networkInterface, cryptoImplementation = _a.cryptoInterface, clientCredentials = _a.clientCredentials, libraryInfo = _a.libraryInfo, serverTelemetryManager = _a.serverTelemetryManager, persistencePlugin = _a.persistencePlugin, serializableCache = _a.serializableCache;
+ return {
+ authOptions: buildAuthOptions(userAuthOptions),
+ systemOptions: __assign(__assign({}, DEFAULT_SYSTEM_OPTIONS), userSystemOptions),
+ loggerOptions: __assign(__assign({}, DEFAULT_LOGGER_IMPLEMENTATION), userLoggerOption),
+ storageInterface: storageImplementation || new DefaultStorageClass(userAuthOptions.clientId, DEFAULT_CRYPTO_IMPLEMENTATION),
+ networkInterface: networkImplementation || DEFAULT_NETWORK_IMPLEMENTATION,
+ cryptoInterface: cryptoImplementation || DEFAULT_CRYPTO_IMPLEMENTATION,
+ clientCredentials: clientCredentials || DEFAULT_CLIENT_CREDENTIALS,
+ libraryInfo: __assign(__assign({}, DEFAULT_LIBRARY_INFO), libraryInfo),
+ serverTelemetryManager: serverTelemetryManager || null,
+ persistencePlugin: persistencePlugin || null,
+ serializableCache: serializableCache || null
+ };
+}
+/**
+ * Construct authoptions from the client and platform passed values
+ * @param authOptions
+ */
+function buildAuthOptions(authOptions) {
+ return __assign({ clientCapabilities: [] }, authOptions);
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Error thrown when there is an error with the server code, for example, unavailability.
+ */
+var ServerError = /** @class */ (function (_super) {
+ __extends(ServerError, _super);
+ function ServerError(errorCode, errorMessage, subError) {
+ var _this = _super.call(this, errorCode, errorMessage, subError) || this;
+ _this.name = "ServerError";
+ Object.setPrototypeOf(_this, ServerError.prototype);
+ return _this;
+ }
+ return ServerError;
+}(AuthError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ThrottlingUtils = /** @class */ (function () {
+ function ThrottlingUtils() {
+ }
+ /**
+ * Prepares a RequestThumbprint to be stored as a key.
+ * @param thumbprint
+ */
+ ThrottlingUtils.generateThrottlingStorageKey = function (thumbprint) {
+ return ThrottlingConstants.THROTTLING_PREFIX + "." + JSON.stringify(thumbprint);
+ };
+ /**
+ * Performs necessary throttling checks before a network request.
+ * @param cacheManager
+ * @param thumbprint
+ */
+ ThrottlingUtils.preProcess = function (cacheManager, thumbprint) {
+ var _a;
+ var key = ThrottlingUtils.generateThrottlingStorageKey(thumbprint);
+ var value = cacheManager.getThrottlingCache(key);
+ if (value) {
+ if (value.throttleTime < Date.now()) {
+ cacheManager.removeItem(key, exports.CacheSchemaType.THROTTLING);
+ return;
+ }
+ throw new ServerError(((_a = value.errorCodes) === null || _a === void 0 ? void 0 : _a.join(" ")) || Constants.EMPTY_STRING, value.errorMessage, value.subError);
+ }
+ };
+ /**
+ * Performs necessary throttling checks after a network request.
+ * @param cacheManager
+ * @param thumbprint
+ * @param response
+ */
+ ThrottlingUtils.postProcess = function (cacheManager, thumbprint, response) {
+ if (ThrottlingUtils.checkResponseStatus(response) || ThrottlingUtils.checkResponseForRetryAfter(response)) {
+ var thumbprintValue = {
+ throttleTime: ThrottlingUtils.calculateThrottleTime(parseInt(response.headers[HeaderNames.RETRY_AFTER])),
+ error: response.body.error,
+ errorCodes: response.body.error_codes,
+ errorMessage: response.body.error_description,
+ subError: response.body.suberror
+ };
+ cacheManager.setThrottlingCache(ThrottlingUtils.generateThrottlingStorageKey(thumbprint), thumbprintValue);
+ }
+ };
+ /**
+ * Checks a NetworkResponse object's status codes against 429 or 5xx
+ * @param response
+ */
+ ThrottlingUtils.checkResponseStatus = function (response) {
+ return response.status === 429 || response.status >= 500 && response.status < 600;
+ };
+ /**
+ * Checks a NetworkResponse object's RetryAfter header
+ * @param response
+ */
+ ThrottlingUtils.checkResponseForRetryAfter = function (response) {
+ if (response.headers) {
+ return response.headers.hasOwnProperty(HeaderNames.RETRY_AFTER) && (response.status < 200 || response.status >= 300);
+ }
+ return false;
+ };
+ /**
+ * Calculates the Unix-time value for a throttle to expire given throttleTime in seconds.
+ * @param throttleTime
+ */
+ ThrottlingUtils.calculateThrottleTime = function (throttleTime) {
+ if (throttleTime <= 0) {
+ throttleTime = 0;
+ }
+ var currentSeconds = Date.now() / 1000;
+ return Math.floor(Math.min(currentSeconds + (throttleTime || ThrottlingConstants.DEFAULT_THROTTLE_TIME_SECONDS), currentSeconds + ThrottlingConstants.DEFAULT_MAX_THROTTLE_TIME_SECONDS) * 1000);
+ };
+ ThrottlingUtils.removeThrottle = function (cacheManager, clientId, authority, scopes, homeAccountIdentifier) {
+ var thumbprint = {
+ clientId: clientId,
+ authority: authority,
+ scopes: scopes,
+ homeAccountIdentifier: homeAccountIdentifier
+ };
+ var key = this.generateThrottlingStorageKey(thumbprint);
+ return cacheManager.removeItem(key, exports.CacheSchemaType.THROTTLING);
+ };
+ return ThrottlingUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var NetworkManager = /** @class */ (function () {
+ function NetworkManager(networkClient, cacheManager) {
+ this.networkClient = networkClient;
+ this.cacheManager = cacheManager;
+ }
+ /**
+ * Wraps sendPostRequestAsync with necessary preflight and postflight logic
+ * @param thumbprint
+ * @param tokenEndpoint
+ * @param options
+ */
+ NetworkManager.prototype.sendPostRequest = function (thumbprint, tokenEndpoint, options) {
+ return __awaiter(this, void 0, void 0, function () {
+ var response;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ ThrottlingUtils.preProcess(this.cacheManager, thumbprint);
+ return [4 /*yield*/, this.networkClient.sendPostRequestAsync(tokenEndpoint, options)];
+ case 1:
+ response = _a.sent();
+ ThrottlingUtils.postProcess(this.cacheManager, thumbprint, response);
+ // Placeholder for Telemetry hook
+ return [2 /*return*/, response];
+ }
+ });
+ });
+ };
+ return NetworkManager;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Base application class which will construct requests to send to and handle responses from the Microsoft STS using the authorization code flow.
+ */
+var BaseClient = /** @class */ (function () {
+ function BaseClient(configuration) {
+ // Set the configuration
+ this.config = buildClientConfiguration(configuration);
+ // Initialize the logger
+ this.logger = new Logger(this.config.loggerOptions, name, version);
+ // Initialize crypto
+ this.cryptoUtils = this.config.cryptoInterface;
+ // Initialize storage interface
+ this.cacheManager = this.config.storageInterface;
+ // Set the network interface
+ this.networkClient = this.config.networkInterface;
+ // Set the NetworkManager
+ this.networkManager = new NetworkManager(this.networkClient, this.cacheManager);
+ // Set TelemetryManager
+ this.serverTelemetryManager = this.config.serverTelemetryManager;
+ // set Authority
+ this.authority = this.config.authOptions.authority;
+ }
+ /**
+ * Creates default headers for requests to token endpoint
+ */
+ BaseClient.prototype.createDefaultTokenRequestHeaders = function () {
+ var headers = this.createDefaultLibraryHeaders();
+ headers[HeaderNames.CONTENT_TYPE] = Constants.URL_FORM_CONTENT_TYPE;
+ headers[HeaderNames.X_MS_LIB_CAPABILITY] = HeaderNames.X_MS_LIB_CAPABILITY_VALUE;
+ if (this.serverTelemetryManager) {
+ headers[HeaderNames.X_CLIENT_CURR_TELEM] = this.serverTelemetryManager.generateCurrentRequestHeaderValue();
+ headers[HeaderNames.X_CLIENT_LAST_TELEM] = this.serverTelemetryManager.generateLastRequestHeaderValue();
+ }
+ return headers;
+ };
+ /**
+ * addLibraryData
+ */
+ BaseClient.prototype.createDefaultLibraryHeaders = function () {
+ var headers = {};
+ // client info headers
+ headers[AADServerParamKeys.X_CLIENT_SKU] = this.config.libraryInfo.sku;
+ headers[AADServerParamKeys.X_CLIENT_VER] = this.config.libraryInfo.version;
+ headers[AADServerParamKeys.X_CLIENT_OS] = this.config.libraryInfo.os;
+ headers[AADServerParamKeys.X_CLIENT_CPU] = this.config.libraryInfo.cpu;
+ return headers;
+ };
+ /**
+ * Http post to token endpoint
+ * @param tokenEndpoint
+ * @param queryString
+ * @param headers
+ * @param thumbprint
+ */
+ BaseClient.prototype.executePostToTokenEndpoint = function (tokenEndpoint, queryString, headers, thumbprint) {
+ return __awaiter(this, void 0, void 0, function () {
+ var response;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.networkManager.sendPostRequest(thumbprint, tokenEndpoint, { body: queryString, headers: headers })];
+ case 1:
+ response = _a.sent();
+ if (this.config.serverTelemetryManager && response.status < 500 && response.status !== 429) {
+ // Telemetry data successfully logged by server, clear Telemetry cache
+ this.config.serverTelemetryManager.clearTelemetryCache();
+ }
+ return [2 /*return*/, response];
+ }
+ });
+ });
+ };
+ /**
+ * Updates the authority object of the client. Endpoint discovery must be completed.
+ * @param updatedAuthority
+ */
+ BaseClient.prototype.updateAuthority = function (updatedAuthority) {
+ if (!updatedAuthority.discoveryComplete()) {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Updated authority has not completed endpoint discovery.");
+ }
+ this.authority = updatedAuthority;
+ };
+ return BaseClient;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Validates server consumable params from the "request" objects
+ */
+var RequestValidator = /** @class */ (function () {
+ function RequestValidator() {
+ }
+ /**
+ * Utility to check if the `redirectUri` in the request is a non-null value
+ * @param redirectUri
+ */
+ RequestValidator.validateRedirectUri = function (redirectUri) {
+ if (StringUtils.isEmpty(redirectUri)) {
+ throw ClientConfigurationError.createRedirectUriEmptyError();
+ }
+ };
+ /**
+ * Utility to validate prompt sent by the user in the request
+ * @param prompt
+ */
+ RequestValidator.validatePrompt = function (prompt) {
+ if ([
+ PromptValue.LOGIN,
+ PromptValue.SELECT_ACCOUNT,
+ PromptValue.CONSENT,
+ PromptValue.NONE
+ ].indexOf(prompt) < 0) {
+ throw ClientConfigurationError.createInvalidPromptError(prompt);
+ }
+ };
+ RequestValidator.validateClaims = function (claims) {
+ try {
+ JSON.parse(claims);
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidClaimsRequestError();
+ }
+ };
+ /**
+ * Utility to validate code_challenge and code_challenge_method
+ * @param codeChallenge
+ * @param codeChallengeMethod
+ */
+ RequestValidator.validateCodeChallengeParams = function (codeChallenge, codeChallengeMethod) {
+ if (StringUtils.isEmpty(codeChallenge) || StringUtils.isEmpty(codeChallengeMethod)) {
+ throw ClientConfigurationError.createInvalidCodeChallengeParamsError();
+ }
+ else {
+ this.validateCodeChallengeMethod(codeChallengeMethod);
+ }
+ };
+ /**
+ * Utility to validate code_challenge_method
+ * @param codeChallengeMethod
+ */
+ RequestValidator.validateCodeChallengeMethod = function (codeChallengeMethod) {
+ if ([
+ CodeChallengeMethodValues.PLAIN,
+ CodeChallengeMethodValues.S256
+ ].indexOf(codeChallengeMethod) < 0) {
+ throw ClientConfigurationError.createInvalidCodeChallengeMethodError();
+ }
+ };
+ /**
+ * Removes unnecessary or duplicate query parameters from extraQueryParameters
+ * @param request
+ */
+ RequestValidator.sanitizeEQParams = function (eQParams, queryParams) {
+ if (!eQParams) {
+ return {};
+ }
+ // Remove any query parameters already included in SSO params
+ queryParams.forEach(function (value, key) {
+ if (eQParams[key]) {
+ delete eQParams[key];
+ }
+ });
+ return eQParams;
+ };
+ return RequestValidator;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var RequestParameterBuilder = /** @class */ (function () {
+ function RequestParameterBuilder() {
+ this.parameters = new Map();
+ }
+ /**
+ * add response_type = code
+ */
+ RequestParameterBuilder.prototype.addResponseTypeCode = function () {
+ this.parameters.set(AADServerParamKeys.RESPONSE_TYPE, encodeURIComponent(Constants.CODE_RESPONSE_TYPE));
+ };
+ /**
+ * add response_mode. defaults to query.
+ * @param responseMode
+ */
+ RequestParameterBuilder.prototype.addResponseMode = function (responseMode) {
+ this.parameters.set(AADServerParamKeys.RESPONSE_MODE, encodeURIComponent((responseMode) ? responseMode : exports.ResponseMode.QUERY));
+ };
+ /**
+ * add scopes. set addOidcScopes to false to prevent default scopes in non-user scenarios
+ * @param scopeSet
+ * @param addOidcScopes
+ */
+ RequestParameterBuilder.prototype.addScopes = function (scopes, addOidcScopes) {
+ if (addOidcScopes === void 0) { addOidcScopes = true; }
+ var requestScopes = addOidcScopes ? __spreadArrays(scopes || [], OIDC_DEFAULT_SCOPES) : scopes || [];
+ var scopeSet = new ScopeSet(requestScopes);
+ this.parameters.set(AADServerParamKeys.SCOPE, encodeURIComponent(scopeSet.printScopes()));
+ };
+ /**
+ * add clientId
+ * @param clientId
+ */
+ RequestParameterBuilder.prototype.addClientId = function (clientId) {
+ this.parameters.set(AADServerParamKeys.CLIENT_ID, encodeURIComponent(clientId));
+ };
+ /**
+ * add redirect_uri
+ * @param redirectUri
+ */
+ RequestParameterBuilder.prototype.addRedirectUri = function (redirectUri) {
+ RequestValidator.validateRedirectUri(redirectUri);
+ this.parameters.set(AADServerParamKeys.REDIRECT_URI, encodeURIComponent(redirectUri));
+ };
+ /**
+ * add post logout redirectUri
+ * @param redirectUri
+ */
+ RequestParameterBuilder.prototype.addPostLogoutRedirectUri = function (redirectUri) {
+ RequestValidator.validateRedirectUri(redirectUri);
+ this.parameters.set(AADServerParamKeys.POST_LOGOUT_URI, encodeURIComponent(redirectUri));
+ };
+ /**
+ * add id_token_hint to logout request
+ * @param idTokenHint
+ */
+ RequestParameterBuilder.prototype.addIdTokenHint = function (idTokenHint) {
+ this.parameters.set(AADServerParamKeys.ID_TOKEN_HINT, encodeURIComponent(idTokenHint));
+ };
+ /**
+ * add domain_hint
+ * @param domainHint
+ */
+ RequestParameterBuilder.prototype.addDomainHint = function (domainHint) {
+ this.parameters.set(SSOTypes.DOMAIN_HINT, encodeURIComponent(domainHint));
+ };
+ /**
+ * add login_hint
+ * @param loginHint
+ */
+ RequestParameterBuilder.prototype.addLoginHint = function (loginHint) {
+ this.parameters.set(SSOTypes.LOGIN_HINT, encodeURIComponent(loginHint));
+ };
+ /**
+ * add sid
+ * @param sid
+ */
+ RequestParameterBuilder.prototype.addSid = function (sid) {
+ this.parameters.set(SSOTypes.SID, encodeURIComponent(sid));
+ };
+ /**
+ * add claims
+ * @param claims
+ */
+ RequestParameterBuilder.prototype.addClaims = function (claims, clientCapabilities) {
+ var mergedClaims = this.addClientCapabilitiesToClaims(claims, clientCapabilities);
+ RequestValidator.validateClaims(mergedClaims);
+ this.parameters.set(AADServerParamKeys.CLAIMS, encodeURIComponent(mergedClaims));
+ };
+ /**
+ * add correlationId
+ * @param correlationId
+ */
+ RequestParameterBuilder.prototype.addCorrelationId = function (correlationId) {
+ this.parameters.set(AADServerParamKeys.CLIENT_REQUEST_ID, encodeURIComponent(correlationId));
+ };
+ /**
+ * add library info query params
+ * @param libraryInfo
+ */
+ RequestParameterBuilder.prototype.addLibraryInfo = function (libraryInfo) {
+ // Telemetry Info
+ this.parameters.set(AADServerParamKeys.X_CLIENT_SKU, libraryInfo.sku);
+ this.parameters.set(AADServerParamKeys.X_CLIENT_VER, libraryInfo.version);
+ this.parameters.set(AADServerParamKeys.X_CLIENT_OS, libraryInfo.os);
+ this.parameters.set(AADServerParamKeys.X_CLIENT_CPU, libraryInfo.cpu);
+ };
+ /**
+ * add prompt
+ * @param prompt
+ */
+ RequestParameterBuilder.prototype.addPrompt = function (prompt) {
+ RequestValidator.validatePrompt(prompt);
+ this.parameters.set("" + AADServerParamKeys.PROMPT, encodeURIComponent(prompt));
+ };
+ /**
+ * add state
+ * @param state
+ */
+ RequestParameterBuilder.prototype.addState = function (state) {
+ if (!StringUtils.isEmpty(state)) {
+ this.parameters.set(AADServerParamKeys.STATE, encodeURIComponent(state));
+ }
+ };
+ /**
+ * add nonce
+ * @param nonce
+ */
+ RequestParameterBuilder.prototype.addNonce = function (nonce) {
+ this.parameters.set(AADServerParamKeys.NONCE, encodeURIComponent(nonce));
+ };
+ /**
+ * add code_challenge and code_challenge_method
+ * - throw if either of them are not passed
+ * @param codeChallenge
+ * @param codeChallengeMethod
+ */
+ RequestParameterBuilder.prototype.addCodeChallengeParams = function (codeChallenge, codeChallengeMethod) {
+ RequestValidator.validateCodeChallengeParams(codeChallenge, codeChallengeMethod);
+ if (codeChallenge && codeChallengeMethod) {
+ this.parameters.set(AADServerParamKeys.CODE_CHALLENGE, encodeURIComponent(codeChallenge));
+ this.parameters.set(AADServerParamKeys.CODE_CHALLENGE_METHOD, encodeURIComponent(codeChallengeMethod));
+ }
+ else {
+ throw ClientConfigurationError.createInvalidCodeChallengeParamsError();
+ }
+ };
+ /**
+ * add the `authorization_code` passed by the user to exchange for a token
+ * @param code
+ */
+ RequestParameterBuilder.prototype.addAuthorizationCode = function (code) {
+ this.parameters.set(AADServerParamKeys.CODE, encodeURIComponent(code));
+ };
+ /**
+ * add the `authorization_code` passed by the user to exchange for a token
+ * @param code
+ */
+ RequestParameterBuilder.prototype.addDeviceCode = function (code) {
+ this.parameters.set(AADServerParamKeys.DEVICE_CODE, encodeURIComponent(code));
+ };
+ /**
+ * add the `refreshToken` passed by the user
+ * @param refreshToken
+ */
+ RequestParameterBuilder.prototype.addRefreshToken = function (refreshToken) {
+ this.parameters.set(AADServerParamKeys.REFRESH_TOKEN, encodeURIComponent(refreshToken));
+ };
+ /**
+ * add the `code_verifier` passed by the user to exchange for a token
+ * @param codeVerifier
+ */
+ RequestParameterBuilder.prototype.addCodeVerifier = function (codeVerifier) {
+ this.parameters.set(AADServerParamKeys.CODE_VERIFIER, encodeURIComponent(codeVerifier));
+ };
+ /**
+ * add client_secret
+ * @param clientSecret
+ */
+ RequestParameterBuilder.prototype.addClientSecret = function (clientSecret) {
+ this.parameters.set(AADServerParamKeys.CLIENT_SECRET, encodeURIComponent(clientSecret));
+ };
+ /**
+ * add clientAssertion for confidential client flows
+ * @param clientAssertion
+ */
+ RequestParameterBuilder.prototype.addClientAssertion = function (clientAssertion) {
+ this.parameters.set(AADServerParamKeys.CLIENT_ASSERTION, encodeURIComponent(clientAssertion));
+ };
+ /**
+ * add clientAssertionType for confidential client flows
+ * @param clientAssertionType
+ */
+ RequestParameterBuilder.prototype.addClientAssertionType = function (clientAssertionType) {
+ this.parameters.set(AADServerParamKeys.CLIENT_ASSERTION_TYPE, encodeURIComponent(clientAssertionType));
+ };
+ /**
+ * add OBO assertion for confidential client flows
+ * @param clientAssertion
+ */
+ RequestParameterBuilder.prototype.addOboAssertion = function (oboAssertion) {
+ this.parameters.set(AADServerParamKeys.OBO_ASSERTION, encodeURIComponent(oboAssertion));
+ };
+ /**
+ * add grant type
+ * @param grantType
+ */
+ RequestParameterBuilder.prototype.addRequestTokenUse = function (tokenUse) {
+ this.parameters.set(AADServerParamKeys.REQUESTED_TOKEN_USE, encodeURIComponent(tokenUse));
+ };
+ /**
+ * add grant type
+ * @param grantType
+ */
+ RequestParameterBuilder.prototype.addGrantType = function (grantType) {
+ this.parameters.set(AADServerParamKeys.GRANT_TYPE, encodeURIComponent(grantType));
+ };
+ /**
+ * add client info
+ *
+ */
+ RequestParameterBuilder.prototype.addClientInfo = function () {
+ this.parameters.set(ClientInfo, "1");
+ };
+ /**
+ * add extraQueryParams
+ * @param eQparams
+ */
+ RequestParameterBuilder.prototype.addExtraQueryParameters = function (eQparams) {
+ var _this = this;
+ RequestValidator.sanitizeEQParams(eQparams, this.parameters);
+ Object.keys(eQparams).forEach(function (key) {
+ _this.parameters.set(key, eQparams[key]);
+ });
+ };
+ RequestParameterBuilder.prototype.addClientCapabilitiesToClaims = function (claims, clientCapabilities) {
+ var mergedClaims;
+ // Parse provided claims into JSON object or initialize empty object
+ if (!claims) {
+ mergedClaims = {};
+ }
+ else {
+ try {
+ mergedClaims = JSON.parse(claims);
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidClaimsRequestError();
+ }
+ }
+ if (clientCapabilities && clientCapabilities.length > 0) {
+ if (!mergedClaims.hasOwnProperty(ClaimsRequestKeys.ACCESS_TOKEN)) {
+ // Add access_token key to claims object
+ mergedClaims[ClaimsRequestKeys.ACCESS_TOKEN] = {};
+ }
+ // Add xms_cc claim with provided clientCapabilities to access_token key
+ mergedClaims[ClaimsRequestKeys.ACCESS_TOKEN][ClaimsRequestKeys.XMS_CC] = {
+ values: clientCapabilities
+ };
+ }
+ return JSON.stringify(mergedClaims);
+ };
+ /**
+ * adds `username` for Password Grant flow
+ * @param username
+ */
+ RequestParameterBuilder.prototype.addUsername = function (username) {
+ this.parameters.set(PasswordGrantConstants.username, username);
+ };
+ /**
+ * adds `password` for Password Grant flow
+ * @param password
+ */
+ RequestParameterBuilder.prototype.addPassword = function (password) {
+ this.parameters.set(PasswordGrantConstants.password, password);
+ };
+ /**
+ * add pop_jwk to query params
+ * @param cnfString
+ */
+ RequestParameterBuilder.prototype.addPopToken = function (cnfString) {
+ if (!StringUtils.isEmpty(cnfString)) {
+ this.parameters.set(AADServerParamKeys.TOKEN_TYPE, exports.AuthenticationScheme.POP);
+ this.parameters.set(AADServerParamKeys.REQ_CNF, encodeURIComponent(cnfString));
+ }
+ };
+ /**
+ * Utility to create a URL from the params map
+ */
+ RequestParameterBuilder.prototype.createQueryString = function () {
+ var queryParameterArray = new Array();
+ this.parameters.forEach(function (value, key) {
+ queryParameterArray.push(key + "=" + value);
+ });
+ return queryParameterArray.join("&");
+ };
+ return RequestParameterBuilder;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ID_TOKEN Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-idtoken-clientId-contoso.com-
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * }
+ */
+var IdTokenEntity = /** @class */ (function (_super) {
+ __extends(IdTokenEntity, _super);
+ function IdTokenEntity() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ /**
+ * Create IdTokenEntity
+ * @param homeAccountId
+ * @param authenticationResult
+ * @param clientId
+ * @param authority
+ */
+ IdTokenEntity.createIdTokenEntity = function (homeAccountId, environment, idToken, clientId, tenantId, oboAssertion) {
+ var idTokenEntity = new IdTokenEntity();
+ idTokenEntity.credentialType = exports.CredentialType.ID_TOKEN;
+ idTokenEntity.homeAccountId = homeAccountId;
+ idTokenEntity.environment = environment;
+ idTokenEntity.clientId = clientId;
+ idTokenEntity.secret = idToken;
+ idTokenEntity.realm = tenantId;
+ idTokenEntity.oboAssertion = oboAssertion;
+ return idTokenEntity;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ IdTokenEntity.isIdTokenEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("credentialType") &&
+ entity.hasOwnProperty("realm") &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("secret") &&
+ entity["credentialType"] === exports.CredentialType.ID_TOKEN);
+ };
+ return IdTokenEntity;
+}(CredentialEntity));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Utility class which exposes functions for managing date and time operations.
+ */
+var TimeUtils = /** @class */ (function () {
+ function TimeUtils() {
+ }
+ /**
+ * return the current time in Unix time (seconds).
+ */
+ TimeUtils.nowSeconds = function () {
+ // Date.getTime() returns in milliseconds.
+ return Math.round(new Date().getTime() / 1000.0);
+ };
+ /**
+ * check if a token is expired based on given UTC time in seconds.
+ * @param expiresOn
+ */
+ TimeUtils.isTokenExpired = function (expiresOn, offset) {
+ // check for access token expiry
+ var expirationSec = Number(expiresOn) || 0;
+ var offsetCurrentTimeSec = TimeUtils.nowSeconds() + offset;
+ // If current time + offset is greater than token expiration time, then token is expired.
+ return (offsetCurrentTimeSec > expirationSec);
+ };
+ return TimeUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * ACCESS_TOKEN Credential Type
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-accesstoken-clientId-contoso.com-user.read
+ *
+ * Value Schema:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, usually only used for refresh tokens
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * cachedAt: Absolute device time when entry was created in the cache.
+ * expiresOn: Token expiry time, calculated based on current UTC time in seconds. Represented as a string.
+ * extendedExpiresOn: Additional extended expiry time until when token is valid in case of server-side outage. Represented as string in UTC seconds.
+ * keyId: used for POP and SSH tokenTypes
+ * tokenType: Type of the token issued. Usually "Bearer"
+ * }
+ */
+var AccessTokenEntity = /** @class */ (function (_super) {
+ __extends(AccessTokenEntity, _super);
+ function AccessTokenEntity() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ /**
+ * Create AccessTokenEntity
+ * @param homeAccountId
+ * @param environment
+ * @param accessToken
+ * @param clientId
+ * @param tenantId
+ * @param scopes
+ * @param expiresOn
+ * @param extExpiresOn
+ */
+ AccessTokenEntity.createAccessTokenEntity = function (homeAccountId, environment, accessToken, clientId, tenantId, scopes, expiresOn, extExpiresOn, tokenType, oboAssertion) {
+ var atEntity = new AccessTokenEntity();
+ atEntity.homeAccountId = homeAccountId;
+ atEntity.credentialType = exports.CredentialType.ACCESS_TOKEN;
+ atEntity.secret = accessToken;
+ var currentTime = TimeUtils.nowSeconds();
+ atEntity.cachedAt = currentTime.toString();
+ /*
+ * Token expiry time.
+ * This value should be calculated based on the current UTC time measured locally and the value expires_in Represented as a string in JSON.
+ */
+ atEntity.expiresOn = expiresOn.toString();
+ atEntity.extendedExpiresOn = extExpiresOn.toString();
+ atEntity.environment = environment;
+ atEntity.clientId = clientId;
+ atEntity.realm = tenantId;
+ atEntity.target = scopes;
+ atEntity.oboAssertion = oboAssertion;
+ atEntity.tokenType = StringUtils.isEmpty(tokenType) ? exports.AuthenticationScheme.BEARER : tokenType;
+ return atEntity;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AccessTokenEntity.isAccessTokenEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("credentialType") &&
+ entity.hasOwnProperty("realm") &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("secret") &&
+ entity.hasOwnProperty("target") &&
+ entity["credentialType"] === exports.CredentialType.ACCESS_TOKEN);
+ };
+ return AccessTokenEntity;
+}(CredentialEntity));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * REFRESH_TOKEN Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key Example: uid.utid-login.microsoftonline.com-refreshtoken-clientId--
+ *
+ * Value:
+ * {
+ * homeAccountId: home account identifier for the auth scheme,
+ * environment: entity that issued the token, represented as a full host
+ * credentialType: Type of credential as a string, can be one of the following: RefreshToken, AccessToken, IdToken, Password, Cookie, Certificate, Other
+ * clientId: client ID of the application
+ * secret: Actual credential as a string
+ * familyId: Family ID identifier, '1' represents Microsoft Family
+ * realm: Full tenant or organizational identifier that the account belongs to
+ * target: Permissions that are included in the token, or for refresh tokens, the resource identifier.
+ * }
+ */
+var RefreshTokenEntity = /** @class */ (function (_super) {
+ __extends(RefreshTokenEntity, _super);
+ function RefreshTokenEntity() {
+ return _super !== null && _super.apply(this, arguments) || this;
+ }
+ /**
+ * Create RefreshTokenEntity
+ * @param homeAccountId
+ * @param authenticationResult
+ * @param clientId
+ * @param authority
+ */
+ RefreshTokenEntity.createRefreshTokenEntity = function (homeAccountId, environment, refreshToken, clientId, familyId, oboAssertion) {
+ var rtEntity = new RefreshTokenEntity();
+ rtEntity.clientId = clientId;
+ rtEntity.credentialType = exports.CredentialType.REFRESH_TOKEN;
+ rtEntity.environment = environment;
+ rtEntity.homeAccountId = homeAccountId;
+ rtEntity.secret = refreshToken;
+ rtEntity.oboAssertion = oboAssertion;
+ if (familyId)
+ rtEntity.familyId = familyId;
+ return rtEntity;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ RefreshTokenEntity.isRefreshTokenEntity = function (entity) {
+ if (!entity) {
+ return false;
+ }
+ return (entity.hasOwnProperty("homeAccountId") &&
+ entity.hasOwnProperty("environment") &&
+ entity.hasOwnProperty("credentialType") &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("secret") &&
+ entity["credentialType"] === exports.CredentialType.REFRESH_TOKEN);
+ };
+ return RefreshTokenEntity;
+}(CredentialEntity));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * InteractionRequiredAuthErrorMessage class containing string constants used by error codes and messages.
+ */
+var InteractionRequiredAuthErrorMessage = [
+ "interaction_required",
+ "consent_required",
+ "login_required"
+];
+var InteractionRequiredAuthSubErrorMessage = [
+ "message_only",
+ "additional_action",
+ "basic_action",
+ "user_password_expired",
+ "consent_required"
+];
+/**
+ * Error thrown when user interaction is required at the auth server.
+ */
+var InteractionRequiredAuthError = /** @class */ (function (_super) {
+ __extends(InteractionRequiredAuthError, _super);
+ function InteractionRequiredAuthError(errorCode, errorMessage, subError) {
+ var _this = _super.call(this, errorCode, errorMessage, subError) || this;
+ _this.name = "InteractionRequiredAuthError";
+ Object.setPrototypeOf(_this, InteractionRequiredAuthError.prototype);
+ return _this;
+ }
+ InteractionRequiredAuthError.isInteractionRequiredError = function (errorCode, errorString, subError) {
+ var isInteractionRequiredErrorCode = !!errorCode && InteractionRequiredAuthErrorMessage.indexOf(errorCode) > -1;
+ var isInteractionRequiredSubError = !!subError && InteractionRequiredAuthSubErrorMessage.indexOf(subError) > -1;
+ var isInteractionRequiredErrorDesc = !!errorString && InteractionRequiredAuthErrorMessage.some(function (irErrorCode) {
+ return errorString.indexOf(irErrorCode) > -1;
+ });
+ return isInteractionRequiredErrorCode || isInteractionRequiredErrorDesc || isInteractionRequiredSubError;
+ };
+ return InteractionRequiredAuthError;
+}(ServerError));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var CacheRecord = /** @class */ (function () {
+ function CacheRecord(accountEntity, idTokenEntity, accessTokenEntity, refreshTokenEntity, appMetadataEntity) {
+ this.account = accountEntity || null;
+ this.idToken = idTokenEntity || null;
+ this.accessToken = accessTokenEntity || null;
+ this.refreshToken = refreshTokenEntity || null;
+ this.appMetadata = appMetadataEntity || null;
+ }
+ return CacheRecord;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Class which provides helpers for OAuth 2.0 protocol specific values
+ */
+var ProtocolUtils = /** @class */ (function () {
+ function ProtocolUtils() {
+ }
+ /**
+ * Appends user state with random guid, or returns random guid.
+ * @param userState
+ * @param randomGuid
+ */
+ ProtocolUtils.setRequestState = function (cryptoObj, userState, meta) {
+ var libraryState = ProtocolUtils.generateLibraryState(cryptoObj, meta);
+ return !StringUtils.isEmpty(userState) ? "" + libraryState + Constants.RESOURCE_DELIM + userState : libraryState;
+ };
+ /**
+ * Generates the state value used by the common library.
+ * @param randomGuid
+ * @param cryptoObj
+ */
+ ProtocolUtils.generateLibraryState = function (cryptoObj, meta) {
+ if (!cryptoObj) {
+ throw ClientAuthError.createNoCryptoObjectError("generateLibraryState");
+ }
+ // Create a state object containing a unique id and the timestamp of the request creation
+ var stateObj = {
+ id: cryptoObj.createNewGuid()
+ };
+ if (meta) {
+ stateObj.meta = meta;
+ }
+ var stateString = JSON.stringify(stateObj);
+ return cryptoObj.base64Encode(stateString);
+ };
+ /**
+ * Parses the state into the RequestStateObject, which contains the LibraryState info and the state passed by the user.
+ * @param state
+ * @param cryptoObj
+ */
+ ProtocolUtils.parseRequestState = function (cryptoObj, state) {
+ if (!cryptoObj) {
+ throw ClientAuthError.createNoCryptoObjectError("parseRequestState");
+ }
+ if (StringUtils.isEmpty(state)) {
+ throw ClientAuthError.createInvalidStateError(state, "Null, undefined or empty state");
+ }
+ try {
+ // Split the state between library state and user passed state and decode them separately
+ var splitState = decodeURIComponent(state).split(Constants.RESOURCE_DELIM);
+ var libraryState = splitState[0];
+ var userState = splitState.length > 1 ? splitState.slice(1).join(Constants.RESOURCE_DELIM) : "";
+ var libraryStateString = cryptoObj.base64Decode(libraryState);
+ var libraryStateObj = JSON.parse(libraryStateString);
+ return {
+ userRequestState: !StringUtils.isEmpty(userState) ? userState : "",
+ libraryState: libraryStateObj
+ };
+ }
+ catch (e) {
+ throw ClientAuthError.createInvalidStateError(state, e);
+ }
+ };
+ return ProtocolUtils;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Url object class which can perform various transformations on url strings.
+ */
+var UrlString = /** @class */ (function () {
+ function UrlString(url) {
+ this._urlString = url;
+ if (StringUtils.isEmpty(this._urlString)) {
+ // Throws error if url is empty
+ throw ClientConfigurationError.createUrlEmptyError();
+ }
+ if (StringUtils.isEmpty(this.getHash())) {
+ this._urlString = UrlString.canonicalizeUri(url);
+ }
+ }
+ Object.defineProperty(UrlString.prototype, "urlString", {
+ get: function () {
+ return this._urlString;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ /**
+ * Ensure urls are lower case and end with a / character.
+ * @param url
+ */
+ UrlString.canonicalizeUri = function (url) {
+ if (url) {
+ url = url.toLowerCase();
+ if (StringUtils.endsWith(url, "?")) {
+ url = url.slice(0, -1);
+ }
+ else if (StringUtils.endsWith(url, "?/")) {
+ url = url.slice(0, -2);
+ }
+ if (!StringUtils.endsWith(url, "/")) {
+ url += "/";
+ }
+ }
+ return url;
+ };
+ /**
+ * Throws if urlString passed is not a valid authority URI string.
+ */
+ UrlString.prototype.validateAsUri = function () {
+ // Attempts to parse url for uri components
+ var components;
+ try {
+ components = this.getUrlComponents();
+ }
+ catch (e) {
+ throw ClientConfigurationError.createUrlParseError(e);
+ }
+ // Throw error if URI or path segments are not parseable.
+ if (!components.HostNameAndPort || !components.PathSegments) {
+ throw ClientConfigurationError.createUrlParseError("Given url string: " + this.urlString);
+ }
+ // Throw error if uri is insecure.
+ if (!components.Protocol || components.Protocol.toLowerCase() !== "https:") {
+ throw ClientConfigurationError.createInsecureAuthorityUriError(this.urlString);
+ }
+ };
+ /**
+ * Function to remove query string params from url. Returns the new url.
+ * @param url
+ * @param name
+ */
+ UrlString.prototype.urlRemoveQueryStringParameter = function (name) {
+ var regex = new RegExp("(\\&" + name + "=)[^\&]+");
+ this._urlString = this.urlString.replace(regex, "");
+ // name=value&
+ regex = new RegExp("(" + name + "=)[^\&]+&");
+ this._urlString = this.urlString.replace(regex, "");
+ // name=value
+ regex = new RegExp("(" + name + "=)[^\&]+");
+ this._urlString = this.urlString.replace(regex, "");
+ return this.urlString;
+ };
+ UrlString.removeHashFromUrl = function (url) {
+ return UrlString.canonicalizeUri(url.split("#")[0]);
+ };
+ /**
+ * Given a url like https://a:b/common/d?e=f#g, and a tenantId, returns https://a:b/tenantId/d
+ * @param href The url
+ * @param tenantId The tenant id to replace
+ */
+ UrlString.prototype.replaceTenantPath = function (tenantId) {
+ var urlObject = this.getUrlComponents();
+ var pathArray = urlObject.PathSegments;
+ if (tenantId && (pathArray.length !== 0 && (pathArray[0] === AADAuthorityConstants.COMMON || pathArray[0] === AADAuthorityConstants.ORGANIZATIONS))) {
+ pathArray[0] = tenantId;
+ }
+ return UrlString.constructAuthorityUriFromObject(urlObject);
+ };
+ /**
+ * Returns the anchor part(#) of the URL
+ */
+ UrlString.prototype.getHash = function () {
+ return UrlString.parseHash(this.urlString);
+ };
+ /**
+ * Parses out the components from a url string.
+ * @returns An object with the various components. Please cache this value insted of calling this multiple times on the same url.
+ */
+ UrlString.prototype.getUrlComponents = function () {
+ // https://gist.github.com/curtisz/11139b2cfcaef4a261e0
+ var regEx = RegExp("^(([^:/?#]+):)?(//([^/?#]*))?([^?#]*)(\\?([^#]*))?(#(.*))?");
+ // If url string does not match regEx, we throw an error
+ var match = this.urlString.match(regEx);
+ if (!match) {
+ throw ClientConfigurationError.createUrlParseError("Given url string: " + this.urlString);
+ }
+ // Url component object
+ var urlComponents = {
+ Protocol: match[1],
+ HostNameAndPort: match[4],
+ AbsolutePath: match[5],
+ QueryString: match[7]
+ };
+ var pathSegments = urlComponents.AbsolutePath.split("/");
+ pathSegments = pathSegments.filter(function (val) { return val && val.length > 0; }); // remove empty elements
+ urlComponents.PathSegments = pathSegments;
+ if (!StringUtils.isEmpty(urlComponents.QueryString) && urlComponents.QueryString.endsWith("/")) {
+ urlComponents.QueryString = urlComponents.QueryString.substring(0, urlComponents.QueryString.length - 1);
+ }
+ return urlComponents;
+ };
+ UrlString.getDomainFromUrl = function (url) {
+ var regEx = RegExp("^([^:/?#]+://)?([^/?#]*)");
+ var match = url.match(regEx);
+ if (!match) {
+ throw ClientConfigurationError.createUrlParseError("Given url string: " + url);
+ }
+ return match[2];
+ };
+ UrlString.getAbsoluteUrl = function (relativeUrl, baseUrl) {
+ if (relativeUrl[0] === Constants.FORWARD_SLASH) {
+ var url = new UrlString(baseUrl);
+ var baseComponents = url.getUrlComponents();
+ return baseComponents.Protocol + "//" + baseComponents.HostNameAndPort + relativeUrl;
+ }
+ return relativeUrl;
+ };
+ /**
+ * Parses hash string from given string. Returns empty string if no hash symbol is found.
+ * @param hashString
+ */
+ UrlString.parseHash = function (hashString) {
+ var hashIndex1 = hashString.indexOf("#");
+ var hashIndex2 = hashString.indexOf("#/");
+ if (hashIndex2 > -1) {
+ return hashString.substring(hashIndex2 + 2);
+ }
+ else if (hashIndex1 > -1) {
+ return hashString.substring(hashIndex1 + 1);
+ }
+ return "";
+ };
+ UrlString.constructAuthorityUriFromObject = function (urlObject) {
+ return new UrlString(urlObject.Protocol + "//" + urlObject.HostNameAndPort + "/" + urlObject.PathSegments.join("/"));
+ };
+ /**
+ * Returns URL hash as server auth code response object.
+ */
+ UrlString.getDeserializedHash = function (hash) {
+ // Check if given hash is empty
+ if (StringUtils.isEmpty(hash)) {
+ return {};
+ }
+ // Strip the # symbol if present
+ var parsedHash = UrlString.parseHash(hash);
+ // If # symbol was not present, above will return empty string, so give original hash value
+ var deserializedHash = StringUtils.queryStringToObject(StringUtils.isEmpty(parsedHash) ? hash : parsedHash);
+ // Check if deserialization didn't work
+ if (!deserializedHash) {
+ throw ClientAuthError.createHashNotDeserializedError(JSON.stringify(deserializedHash));
+ }
+ return deserializedHash;
+ };
+ /**
+ * Check if the hash of the URL string contains known properties
+ */
+ UrlString.hashContainsKnownProperties = function (hash) {
+ if (StringUtils.isEmpty(hash)) {
+ return false;
+ }
+ var parameters = UrlString.getDeserializedHash(hash);
+ return !!(parameters.code ||
+ parameters.error_description ||
+ parameters.error ||
+ parameters.state);
+ };
+ return UrlString;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var KeyLocation;
+(function (KeyLocation) {
+ KeyLocation["SW"] = "sw";
+ KeyLocation["UHW"] = "uhw";
+})(KeyLocation || (KeyLocation = {}));
+var PopTokenGenerator = /** @class */ (function () {
+ function PopTokenGenerator(cryptoUtils) {
+ this.cryptoUtils = cryptoUtils;
+ }
+ PopTokenGenerator.prototype.generateCnf = function (resourceRequestMethod, resourceRequestUri) {
+ return __awaiter(this, void 0, void 0, function () {
+ var kidThumbprint, reqCnf;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.cryptoUtils.getPublicKeyThumbprint(resourceRequestMethod, resourceRequestUri)];
+ case 1:
+ kidThumbprint = _a.sent();
+ reqCnf = {
+ kid: kidThumbprint,
+ xms_ksl: KeyLocation.SW
+ };
+ return [2 /*return*/, this.cryptoUtils.base64Encode(JSON.stringify(reqCnf))];
+ }
+ });
+ });
+ };
+ PopTokenGenerator.prototype.signPopToken = function (accessToken, resourceRequestMethod, resourceRequestUri) {
+ var _a;
+ return __awaiter(this, void 0, void 0, function () {
+ var tokenClaims, resourceUrlString, resourceUrlComponents;
+ return __generator(this, function (_b) {
+ switch (_b.label) {
+ case 0:
+ tokenClaims = AuthToken.extractTokenClaims(accessToken, this.cryptoUtils);
+ resourceUrlString = new UrlString(resourceRequestUri);
+ resourceUrlComponents = resourceUrlString.getUrlComponents();
+ if (!((_a = tokenClaims === null || tokenClaims === void 0 ? void 0 : tokenClaims.cnf) === null || _a === void 0 ? void 0 : _a.kid)) {
+ throw ClientAuthError.createTokenClaimsRequiredError();
+ }
+ return [4 /*yield*/, this.cryptoUtils.signJwt({
+ at: accessToken,
+ ts: "" + TimeUtils.nowSeconds(),
+ m: resourceRequestMethod.toUpperCase(),
+ u: resourceUrlComponents.HostNameAndPort || "",
+ nonce: this.cryptoUtils.createNewGuid(),
+ p: resourceUrlComponents.AbsolutePath,
+ q: [[], resourceUrlComponents.QueryString],
+ }, tokenClaims.cnf.kid)];
+ case 1: return [2 /*return*/, _b.sent()];
+ }
+ });
+ });
+ };
+ return PopTokenGenerator;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * APP_METADATA Cache
+ *
+ * Key:Value Schema:
+ *
+ * Key: appmetadata--
+ *
+ * Value:
+ * {
+ * clientId: client ID of the application
+ * environment: entity that issued the token, represented as a full host
+ * familyId: Family ID identifier, '1' represents Microsoft Family
+ * }
+ */
+var AppMetadataEntity = /** @class */ (function () {
+ function AppMetadataEntity() {
+ }
+ /**
+ * Generate AppMetadata Cache Key as per the schema: appmetadata--
+ */
+ AppMetadataEntity.prototype.generateAppMetadataKey = function () {
+ return AppMetadataEntity.generateAppMetadataCacheKey(this.environment, this.clientId);
+ };
+ /**
+ * Generate AppMetadata Cache Key
+ */
+ AppMetadataEntity.generateAppMetadataCacheKey = function (environment, clientId) {
+ var appMetaDataKeyArray = [
+ APP_METADATA,
+ environment,
+ clientId,
+ ];
+ return appMetaDataKeyArray.join(Separators.CACHE_KEY_SEPARATOR).toLowerCase();
+ };
+ /**
+ * Creates AppMetadataEntity
+ * @param clientId
+ * @param environment
+ * @param familyId
+ */
+ AppMetadataEntity.createAppMetadataEntity = function (clientId, environment, familyId) {
+ var appMetadata = new AppMetadataEntity();
+ appMetadata.clientId = clientId;
+ appMetadata.environment = environment;
+ if (familyId) {
+ appMetadata.familyId = familyId;
+ }
+ return appMetadata;
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AppMetadataEntity.isAppMetadataEntity = function (key, entity) {
+ if (!entity) {
+ return false;
+ }
+ return (key.indexOf(APP_METADATA) === 0 &&
+ entity.hasOwnProperty("clientId") &&
+ entity.hasOwnProperty("environment"));
+ };
+ return AppMetadataEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * This class instance helps track the memory changes facilitating
+ * decisions to read from and write to the persistent cache
+ */ var TokenCacheContext = /** @class */ (function () {
+ function TokenCacheContext(tokenCache, hasChanged) {
+ this.cache = tokenCache;
+ this.hasChanged = hasChanged;
+ }
+ Object.defineProperty(TokenCacheContext.prototype, "cacheHasChanged", {
+ /**
+ * boolean which indicates the changes in cache
+ */
+ get: function () {
+ return this.hasChanged;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(TokenCacheContext.prototype, "tokenCache", {
+ /**
+ * function to retrieve the token cache
+ */
+ get: function () {
+ return this.cache;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ return TokenCacheContext;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Class that handles response parsing.
+ */
+var ResponseHandler = /** @class */ (function () {
+ function ResponseHandler(clientId, cacheStorage, cryptoObj, logger, serializableCache, persistencePlugin) {
+ this.clientId = clientId;
+ this.cacheStorage = cacheStorage;
+ this.cryptoObj = cryptoObj;
+ this.logger = logger;
+ this.serializableCache = serializableCache;
+ this.persistencePlugin = persistencePlugin;
+ }
+ /**
+ * Function which validates server authorization code response.
+ * @param serverResponseHash
+ * @param cachedState
+ * @param cryptoObj
+ */
+ ResponseHandler.prototype.validateServerAuthorizationCodeResponse = function (serverResponseHash, cachedState, cryptoObj) {
+ if (!serverResponseHash.state || !cachedState) {
+ throw !serverResponseHash.state ? ClientAuthError.createStateNotFoundError("Server State") : ClientAuthError.createStateNotFoundError("Cached State");
+ }
+ if (decodeURIComponent(serverResponseHash.state) !== decodeURIComponent(cachedState)) {
+ throw ClientAuthError.createStateMismatchError();
+ }
+ // Check for error
+ if (serverResponseHash.error || serverResponseHash.error_description || serverResponseHash.suberror) {
+ if (InteractionRequiredAuthError.isInteractionRequiredError(serverResponseHash.error, serverResponseHash.error_description, serverResponseHash.suberror)) {
+ throw new InteractionRequiredAuthError(serverResponseHash.error || Constants.EMPTY_STRING, serverResponseHash.error_description, serverResponseHash.suberror);
+ }
+ throw new ServerError(serverResponseHash.error || Constants.EMPTY_STRING, serverResponseHash.error_description, serverResponseHash.suberror);
+ }
+ if (serverResponseHash.client_info) {
+ buildClientInfo(serverResponseHash.client_info, cryptoObj);
+ }
+ };
+ /**
+ * Function which validates server authorization token response.
+ * @param serverResponse
+ */
+ ResponseHandler.prototype.validateTokenResponse = function (serverResponse) {
+ // Check for error
+ if (serverResponse.error || serverResponse.error_description || serverResponse.suberror) {
+ if (InteractionRequiredAuthError.isInteractionRequiredError(serverResponse.error, serverResponse.error_description, serverResponse.suberror)) {
+ throw new InteractionRequiredAuthError(serverResponse.error, serverResponse.error_description, serverResponse.suberror);
+ }
+ var errString = serverResponse.error_codes + " - [" + serverResponse.timestamp + "]: " + serverResponse.error_description + " - Correlation ID: " + serverResponse.correlation_id + " - Trace ID: " + serverResponse.trace_id;
+ throw new ServerError(serverResponse.error, errString);
+ }
+ };
+ /**
+ * Returns a constructed token response based on given string. Also manages the cache updates and cleanups.
+ * @param serverTokenResponse
+ * @param authority
+ */
+ ResponseHandler.prototype.handleServerTokenResponse = function (serverTokenResponse, authority, reqTimestamp, resourceRequestMethod, resourceRequestUri, authCodePayload, requestScopes, oboAssertion, handlingRefreshTokenResponse) {
+ return __awaiter(this, void 0, void 0, function () {
+ var idTokenObj, requestStateObj, cacheRecord, cacheContext, key, account;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ if (serverTokenResponse.id_token) {
+ idTokenObj = new AuthToken(serverTokenResponse.id_token || Constants.EMPTY_STRING, this.cryptoObj);
+ // token nonce check (TODO: Add a warning if no nonce is given?)
+ if (authCodePayload && !StringUtils.isEmpty(authCodePayload.nonce)) {
+ if (idTokenObj.claims.nonce !== authCodePayload.nonce) {
+ throw ClientAuthError.createNonceMismatchError();
+ }
+ }
+ }
+ // generate homeAccountId
+ this.homeAccountIdentifier = AccountEntity.generateHomeAccountId(serverTokenResponse.client_info || Constants.EMPTY_STRING, authority.authorityType, this.logger, this.cryptoObj, idTokenObj);
+ if (!!authCodePayload && !!authCodePayload.state) {
+ requestStateObj = ProtocolUtils.parseRequestState(this.cryptoObj, authCodePayload.state);
+ }
+ cacheRecord = this.generateCacheRecord(serverTokenResponse, authority, reqTimestamp, idTokenObj, requestScopes, oboAssertion, authCodePayload);
+ _a.label = 1;
+ case 1:
+ _a.trys.push([1, , 4, 7]);
+ if (!(this.persistencePlugin && this.serializableCache)) return [3 /*break*/, 3];
+ this.logger.verbose("Persistence enabled, calling beforeCacheAccess");
+ cacheContext = new TokenCacheContext(this.serializableCache, true);
+ return [4 /*yield*/, this.persistencePlugin.beforeCacheAccess(cacheContext)];
+ case 2:
+ _a.sent();
+ _a.label = 3;
+ case 3:
+ /*
+ * When saving a refreshed tokens to the cache, it is expected that the account that was used is present in the cache.
+ * If not present, we should return null, as it's the case that another application called removeAccount in between
+ * the calls to getAllAccounts and acquireTokenSilent. We should not overwrite that removal.
+ */
+ if (handlingRefreshTokenResponse && cacheRecord.account) {
+ key = cacheRecord.account.generateAccountKey();
+ account = this.cacheStorage.getAccount(key);
+ if (!account) {
+ this.logger.warning("Account used to refresh tokens not in persistence, refreshed tokens will not be stored in the cache");
+ return [2 /*return*/, ResponseHandler.generateAuthenticationResult(this.cryptoObj, authority, cacheRecord, false, idTokenObj, requestStateObj, resourceRequestMethod, resourceRequestUri)];
+ }
+ }
+ this.cacheStorage.saveCacheRecord(cacheRecord);
+ return [3 /*break*/, 7];
+ case 4:
+ if (!(this.persistencePlugin && this.serializableCache && cacheContext)) return [3 /*break*/, 6];
+ this.logger.verbose("Persistence enabled, calling afterCacheAccess");
+ return [4 /*yield*/, this.persistencePlugin.afterCacheAccess(cacheContext)];
+ case 5:
+ _a.sent();
+ _a.label = 6;
+ case 6: return [7 /*endfinally*/];
+ case 7: return [2 /*return*/, ResponseHandler.generateAuthenticationResult(this.cryptoObj, authority, cacheRecord, false, idTokenObj, requestStateObj, resourceRequestMethod, resourceRequestUri)];
+ }
+ });
+ });
+ };
+ /**
+ * Generates CacheRecord
+ * @param serverTokenResponse
+ * @param idTokenObj
+ * @param authority
+ */
+ ResponseHandler.prototype.generateCacheRecord = function (serverTokenResponse, authority, reqTimestamp, idTokenObj, requestScopes, oboAssertion, authCodePayload) {
+ var env = authority.getPreferredCache();
+ if (StringUtils.isEmpty(env)) {
+ throw ClientAuthError.createInvalidCacheEnvironmentError();
+ }
+ // IdToken: non AAD scenarios can have empty realm
+ var cachedIdToken;
+ var cachedAccount;
+ if (!StringUtils.isEmpty(serverTokenResponse.id_token) && !!idTokenObj) {
+ cachedIdToken = IdTokenEntity.createIdTokenEntity(this.homeAccountIdentifier, env, serverTokenResponse.id_token || Constants.EMPTY_STRING, this.clientId, idTokenObj.claims.tid || Constants.EMPTY_STRING, oboAssertion);
+ cachedAccount = this.generateAccountEntity(serverTokenResponse, idTokenObj, authority, oboAssertion, authCodePayload);
+ }
+ // AccessToken
+ var cachedAccessToken = null;
+ if (!StringUtils.isEmpty(serverTokenResponse.access_token)) {
+ // If scopes not returned in server response, use request scopes
+ var responseScopes = serverTokenResponse.scope ? ScopeSet.fromString(serverTokenResponse.scope) : new ScopeSet(requestScopes || []);
+ // Use timestamp calculated before request
+ var tokenExpirationSeconds = reqTimestamp + (serverTokenResponse.expires_in || 0);
+ var extendedTokenExpirationSeconds = tokenExpirationSeconds + (serverTokenResponse.ext_expires_in || 0);
+ // non AAD scenarios can have empty realm
+ cachedAccessToken = AccessTokenEntity.createAccessTokenEntity(this.homeAccountIdentifier, env, serverTokenResponse.access_token || Constants.EMPTY_STRING, this.clientId, idTokenObj ? idTokenObj.claims.tid || Constants.EMPTY_STRING : authority.tenant, responseScopes.printScopes(), tokenExpirationSeconds, extendedTokenExpirationSeconds, serverTokenResponse.token_type, oboAssertion);
+ }
+ // refreshToken
+ var cachedRefreshToken = null;
+ if (!StringUtils.isEmpty(serverTokenResponse.refresh_token)) {
+ cachedRefreshToken = RefreshTokenEntity.createRefreshTokenEntity(this.homeAccountIdentifier, env, serverTokenResponse.refresh_token || Constants.EMPTY_STRING, this.clientId, serverTokenResponse.foci, oboAssertion);
+ }
+ // appMetadata
+ var cachedAppMetadata = null;
+ if (!StringUtils.isEmpty(serverTokenResponse.foci)) {
+ cachedAppMetadata = AppMetadataEntity.createAppMetadataEntity(this.clientId, env, serverTokenResponse.foci);
+ }
+ return new CacheRecord(cachedAccount, cachedIdToken, cachedAccessToken, cachedRefreshToken, cachedAppMetadata);
+ };
+ /**
+ * Generate Account
+ * @param serverTokenResponse
+ * @param idToken
+ * @param authority
+ */
+ ResponseHandler.prototype.generateAccountEntity = function (serverTokenResponse, idToken, authority, oboAssertion, authCodePayload) {
+ var authorityType = authority.authorityType;
+ var cloudGraphHostName = authCodePayload ? authCodePayload.cloud_graph_host_name : "";
+ var msGraphhost = authCodePayload ? authCodePayload.msgraph_host : "";
+ // ADFS does not require client_info in the response
+ if (authorityType === exports.AuthorityType.Adfs) {
+ this.logger.verbose("Authority type is ADFS, creating ADFS account");
+ return AccountEntity.createGenericAccount(authority, this.homeAccountIdentifier, idToken, oboAssertion, cloudGraphHostName, msGraphhost);
+ }
+ // This fallback applies to B2C as well as they fall under an AAD account type.
+ if (StringUtils.isEmpty(serverTokenResponse.client_info) && authority.protocolMode === "AAD") {
+ throw ClientAuthError.createClientInfoEmptyError();
+ }
+ return serverTokenResponse.client_info ?
+ AccountEntity.createAccount(serverTokenResponse.client_info, this.homeAccountIdentifier, authority, idToken, oboAssertion, cloudGraphHostName, msGraphhost) :
+ AccountEntity.createGenericAccount(authority, this.homeAccountIdentifier, idToken, oboAssertion, cloudGraphHostName, msGraphhost);
+ };
+ /**
+ * Creates an @AuthenticationResult from @CacheRecord , @IdToken , and a boolean that states whether or not the result is from cache.
+ *
+ * Optionally takes a state string that is set as-is in the response.
+ *
+ * @param cacheRecord
+ * @param idTokenObj
+ * @param fromTokenCache
+ * @param stateString
+ */
+ ResponseHandler.generateAuthenticationResult = function (cryptoObj, authority, cacheRecord, fromTokenCache, idTokenObj, requestState, resourceRequestMethod, resourceRequestUri) {
+ var _a, _b, _c;
+ return __awaiter(this, void 0, void 0, function () {
+ var accessToken, responseScopes, expiresOn, extExpiresOn, familyId, popTokenGenerator, uid, tid;
+ return __generator(this, function (_d) {
+ switch (_d.label) {
+ case 0:
+ accessToken = "";
+ responseScopes = [];
+ expiresOn = null;
+ familyId = Constants.EMPTY_STRING;
+ if (!cacheRecord.accessToken) return [3 /*break*/, 4];
+ if (!(cacheRecord.accessToken.tokenType === exports.AuthenticationScheme.POP)) return [3 /*break*/, 2];
+ popTokenGenerator = new PopTokenGenerator(cryptoObj);
+ if (!resourceRequestMethod || !resourceRequestUri) {
+ throw ClientConfigurationError.createResourceRequestParametersRequiredError();
+ }
+ return [4 /*yield*/, popTokenGenerator.signPopToken(cacheRecord.accessToken.secret, resourceRequestMethod, resourceRequestUri)];
+ case 1:
+ accessToken = _d.sent();
+ return [3 /*break*/, 3];
+ case 2:
+ accessToken = cacheRecord.accessToken.secret;
+ _d.label = 3;
+ case 3:
+ responseScopes = ScopeSet.fromString(cacheRecord.accessToken.target).asArray();
+ expiresOn = new Date(Number(cacheRecord.accessToken.expiresOn) * 1000);
+ extExpiresOn = new Date(Number(cacheRecord.accessToken.extendedExpiresOn) * 1000);
+ _d.label = 4;
+ case 4:
+ if (cacheRecord.appMetadata) {
+ familyId = cacheRecord.appMetadata.familyId === THE_FAMILY_ID ? THE_FAMILY_ID : Constants.EMPTY_STRING;
+ }
+ uid = (idTokenObj === null || idTokenObj === void 0 ? void 0 : idTokenObj.claims.oid) || (idTokenObj === null || idTokenObj === void 0 ? void 0 : idTokenObj.claims.sub) || Constants.EMPTY_STRING;
+ tid = (idTokenObj === null || idTokenObj === void 0 ? void 0 : idTokenObj.claims.tid) || Constants.EMPTY_STRING;
+ return [2 /*return*/, {
+ authority: authority.canonicalAuthority,
+ uniqueId: uid,
+ tenantId: tid,
+ scopes: responseScopes,
+ account: cacheRecord.account ? cacheRecord.account.getAccountInfo() : null,
+ idToken: idTokenObj ? idTokenObj.rawToken : Constants.EMPTY_STRING,
+ idTokenClaims: idTokenObj ? idTokenObj.claims : {},
+ accessToken: accessToken,
+ fromCache: fromTokenCache,
+ expiresOn: expiresOn,
+ extExpiresOn: extExpiresOn,
+ familyId: familyId,
+ tokenType: ((_a = cacheRecord.accessToken) === null || _a === void 0 ? void 0 : _a.tokenType) || Constants.EMPTY_STRING,
+ state: requestState ? requestState.userRequestState : Constants.EMPTY_STRING,
+ cloudGraphHostName: ((_b = cacheRecord.account) === null || _b === void 0 ? void 0 : _b.cloudGraphHostName) || Constants.EMPTY_STRING,
+ msGraphHost: ((_c = cacheRecord.account) === null || _c === void 0 ? void 0 : _c.msGraphHost) || Constants.EMPTY_STRING
+ }];
+ }
+ });
+ });
+ };
+ return ResponseHandler;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Oauth2.0 Authorization Code client
+ */
+var AuthorizationCodeClient = /** @class */ (function (_super) {
+ __extends(AuthorizationCodeClient, _super);
+ function AuthorizationCodeClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Creates the URL of the authorization request letting the user input credentials and consent to the
+ * application. The URL target the /authorize endpoint of the authority configured in the
+ * application object.
+ *
+ * Once the user inputs their credentials and consents, the authority will send a response to the redirect URI
+ * sent in the request and should contain an authorization code, which can then be used to acquire tokens via
+ * acquireToken(AuthorizationCodeRequest)
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.getAuthCodeUrl = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var queryString;
+ return __generator(this, function (_a) {
+ queryString = this.createAuthCodeUrlQueryString(request);
+ return [2 /*return*/, this.authority.authorizationEndpoint + "?" + queryString];
+ });
+ });
+ };
+ /**
+ * API to acquire a token in exchange of 'authorization_code` acquired by the user in the first leg of the
+ * authorization_code_grant
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.acquireToken = function (request, authCodePayload) {
+ return __awaiter(this, void 0, void 0, function () {
+ var reqTimestamp, response, responseHandler;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.logger.info("in acquireToken call");
+ if (!request || StringUtils.isEmpty(request.code)) {
+ throw ClientAuthError.createTokenRequestCannotBeMadeError();
+ }
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executeTokenRequest(this.authority, request)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ // Validate response. This function throws a server error if an error is returned by the server.
+ responseHandler.validateTokenResponse(response.body);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, authCodePayload)];
+ case 2: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Handles the hash fragment response from public client code request. Returns a code response used by
+ * the client to exchange for a token in acquireToken.
+ * @param hashFragment
+ */
+ AuthorizationCodeClient.prototype.handleFragmentResponse = function (hashFragment, cachedState) {
+ // Handle responses.
+ var responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, null, null);
+ // Deserialize hash fragment response parameters.
+ var hashUrlString = new UrlString(hashFragment);
+ // Deserialize hash fragment response parameters.
+ var serverParams = UrlString.getDeserializedHash(hashUrlString.getHash());
+ // Get code response
+ responseHandler.validateServerAuthorizationCodeResponse(serverParams, cachedState, this.cryptoUtils);
+ // throw when there is no auth code in the response
+ if (!serverParams.code) {
+ throw ClientAuthError.createNoAuthCodeInServerResponseError();
+ }
+ return __assign(__assign({}, serverParams), {
+ // Code param is optional in ServerAuthorizationCodeResponse but required in AuthorizationCodePaylod
+ code: serverParams.code });
+ };
+ /**
+ * Use to log out the current user, and redirect the user to the postLogoutRedirectUri.
+ * Default behaviour is to redirect the user to `window.location.href`.
+ * @param authorityUri
+ */
+ AuthorizationCodeClient.prototype.getLogoutUri = function (logoutRequest) {
+ // Throw error if logoutRequest is null/undefined
+ if (!logoutRequest) {
+ throw ClientConfigurationError.createEmptyLogoutRequestError();
+ }
+ if (logoutRequest.account) {
+ // Clear given account.
+ this.cacheManager.removeAccount(AccountEntity.generateAccountCacheKey(logoutRequest.account));
+ }
+ else {
+ // Clear all accounts and tokens
+ this.cacheManager.clear();
+ }
+ var queryString = this.createLogoutUrlQueryString(logoutRequest);
+ // Construct logout URI.
+ return StringUtils.isEmpty(queryString) ? this.authority.endSessionEndpoint : this.authority.endSessionEndpoint + "?" + queryString;
+ };
+ /**
+ * Executes POST request to token endpoint
+ * @param authority
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.executeTokenRequest = function (authority, request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var thumbprint, requestBody, headers;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: authority.canonicalAuthority,
+ scopes: request.scopes
+ };
+ return [4 /*yield*/, this.createTokenRequestBody(request)];
+ case 1:
+ requestBody = _a.sent();
+ headers = this.createDefaultTokenRequestHeaders();
+ return [2 /*return*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ }
+ });
+ });
+ };
+ /**
+ * Generates a map for all the params to be sent to the service
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.createTokenRequestBody = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var parameterBuilder, clientAssertion, popTokenGenerator, cnfString, correlationId;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ // validate the redirectUri (to be a non null value)
+ parameterBuilder.addRedirectUri(request.redirectUri);
+ // Add scope array, parameter builder will add default scopes and dedupe
+ parameterBuilder.addScopes(request.scopes);
+ // add code: user set, not validated
+ parameterBuilder.addAuthorizationCode(request.code);
+ // add code_verifier if passed
+ if (request.codeVerifier) {
+ parameterBuilder.addCodeVerifier(request.codeVerifier);
+ }
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ parameterBuilder.addGrantType(GrantType.AUTHORIZATION_CODE_GRANT);
+ parameterBuilder.addClientInfo();
+ if (!(request.authenticationScheme === exports.AuthenticationScheme.POP && !!request.resourceRequestMethod && !!request.resourceRequestUri)) return [3 /*break*/, 2];
+ popTokenGenerator = new PopTokenGenerator(this.cryptoUtils);
+ return [4 /*yield*/, popTokenGenerator.generateCnf(request.resourceRequestMethod, request.resourceRequestUri)];
+ case 1:
+ cnfString = _a.sent();
+ parameterBuilder.addPopToken(cnfString);
+ _a.label = 2;
+ case 2:
+ correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return [2 /*return*/, parameterBuilder.createQueryString()];
+ }
+ });
+ });
+ };
+ /**
+ * This API validates the `AuthorizationCodeUrlRequest` and creates a URL
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.createAuthCodeUrlQueryString = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ var requestScopes = __spreadArrays(request.scopes || [], request.extraScopesToConsent || []);
+ parameterBuilder.addScopes(requestScopes);
+ // validate the redirectUri (to be a non null value)
+ parameterBuilder.addRedirectUri(request.redirectUri);
+ // generate the correlationId if not set by the user and add
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ // add response_mode. If not passed in it defaults to query.
+ parameterBuilder.addResponseMode(request.responseMode);
+ // add response_type = code
+ parameterBuilder.addResponseTypeCode();
+ // add library info parameters
+ parameterBuilder.addLibraryInfo(this.config.libraryInfo);
+ // add client_info=1
+ parameterBuilder.addClientInfo();
+ if (request.codeChallenge && request.codeChallengeMethod) {
+ parameterBuilder.addCodeChallengeParams(request.codeChallenge, request.codeChallengeMethod);
+ }
+ if (request.prompt) {
+ parameterBuilder.addPrompt(request.prompt);
+ }
+ if (request.domainHint) {
+ parameterBuilder.addDomainHint(request.domainHint);
+ }
+ // Add sid or loginHint with preference for sid -> loginHint -> username of AccountInfo object
+ if (request.sid) {
+ parameterBuilder.addSid(request.sid);
+ }
+ else if (request.loginHint) {
+ parameterBuilder.addLoginHint(request.loginHint);
+ }
+ else if (request.account && request.account.username) {
+ parameterBuilder.addLoginHint(request.account.username);
+ }
+ if (request.nonce) {
+ parameterBuilder.addNonce(request.nonce);
+ }
+ if (request.state) {
+ parameterBuilder.addState(request.state);
+ }
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ if (request.extraQueryParameters) {
+ parameterBuilder.addExtraQueryParameters(request.extraQueryParameters);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ /**
+ * This API validates the `EndSessionRequest` and creates a URL
+ * @param request
+ */
+ AuthorizationCodeClient.prototype.createLogoutUrlQueryString = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ if (request.postLogoutRedirectUri) {
+ parameterBuilder.addPostLogoutRedirectUri(request.postLogoutRedirectUri);
+ }
+ if (request.correlationId) {
+ parameterBuilder.addCorrelationId(request.correlationId);
+ }
+ if (request.idTokenHint) {
+ parameterBuilder.addIdTokenHint(request.idTokenHint);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return AuthorizationCodeClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * OAuth2.0 Device code client
+ */
+var DeviceCodeClient = /** @class */ (function (_super) {
+ __extends(DeviceCodeClient, _super);
+ function DeviceCodeClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Gets device code from device code endpoint, calls back to with device code response, and
+ * polls token endpoint to exchange device code for tokens
+ * @param request
+ */
+ DeviceCodeClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var deviceCodeResponse, reqTimestamp, response, responseHandler;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.getDeviceCode(request)];
+ case 1:
+ deviceCodeResponse = _a.sent();
+ request.deviceCodeCallback(deviceCodeResponse);
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.acquireTokenWithDeviceCode(request, deviceCodeResponse)];
+ case 2:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ // Validate response. This function throws a server error if an error is returned by the server.
+ responseHandler.validateTokenResponse(response);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri)];
+ case 3: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Creates device code request and executes http GET
+ * @param request
+ */
+ DeviceCodeClient.prototype.getDeviceCode = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var queryString, headers, thumbprint;
+ return __generator(this, function (_a) {
+ queryString = this.createQueryString(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ return [2 /*return*/, this.executePostRequestToDeviceCodeEndpoint(this.authority.deviceCodeEndpoint, queryString, headers, thumbprint)];
+ });
+ });
+ };
+ /**
+ * Executes POST request to device code endpoint
+ * @param deviceCodeEndpoint
+ * @param queryString
+ * @param headers
+ */
+ DeviceCodeClient.prototype.executePostRequestToDeviceCodeEndpoint = function (deviceCodeEndpoint, queryString, headers, thumbprint) {
+ return __awaiter(this, void 0, void 0, function () {
+ var _a, userCode, deviceCode, verificationUri, expiresIn, interval, message;
+ return __generator(this, function (_b) {
+ switch (_b.label) {
+ case 0: return [4 /*yield*/, this.networkManager.sendPostRequest(thumbprint, deviceCodeEndpoint, {
+ body: queryString,
+ headers: headers
+ })];
+ case 1:
+ _a = (_b.sent()).body, userCode = _a.user_code, deviceCode = _a.device_code, verificationUri = _a.verification_uri, expiresIn = _a.expires_in, interval = _a.interval, message = _a.message;
+ return [2 /*return*/, {
+ userCode: userCode,
+ deviceCode: deviceCode,
+ verificationUri: verificationUri,
+ expiresIn: expiresIn,
+ interval: interval,
+ message: message
+ }];
+ }
+ });
+ });
+ };
+ /**
+ * Create device code endpoint query parameters and returns string
+ */
+ DeviceCodeClient.prototype.createQueryString = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ /**
+ * Creates token request with device code response and polls token endpoint at interval set by the device code
+ * response
+ * @param request
+ * @param deviceCodeResponse
+ */
+ DeviceCodeClient.prototype.acquireTokenWithDeviceCode = function (request, deviceCodeResponse) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, userSpecifiedTimeout, deviceCodeExpirationTime, pollingIntervalMilli;
+ var _this = this;
+ return __generator(this, function (_a) {
+ requestBody = this.createTokenRequestBody(request, deviceCodeResponse);
+ headers = this.createDefaultTokenRequestHeaders();
+ userSpecifiedTimeout = request.timeout ? TimeUtils.nowSeconds() + request.timeout : undefined;
+ deviceCodeExpirationTime = TimeUtils.nowSeconds() + deviceCodeResponse.expiresIn;
+ pollingIntervalMilli = deviceCodeResponse.interval * 1000;
+ /*
+ * Poll token endpoint while (device code is not expired AND operation has not been cancelled by
+ * setting CancellationToken.cancel = true). POST request is sent at interval set by pollingIntervalMilli
+ */
+ return [2 /*return*/, new Promise(function (resolve, reject) {
+ var intervalId = setInterval(function () { return __awaiter(_this, void 0, void 0, function () {
+ var thumbprint, response, error_1;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ _a.trys.push([0, 6, , 7]);
+ if (!request.cancel) return [3 /*break*/, 1];
+ this.logger.error("Token request cancelled by setting DeviceCodeRequest.cancel = true");
+ clearInterval(intervalId);
+ reject(ClientAuthError.createDeviceCodeCancelledError());
+ return [3 /*break*/, 5];
+ case 1:
+ if (!(userSpecifiedTimeout && userSpecifiedTimeout < deviceCodeExpirationTime && TimeUtils.nowSeconds() > userSpecifiedTimeout)) return [3 /*break*/, 2];
+ this.logger.error("User defined timeout for device code polling reached. The timeout was set for " + userSpecifiedTimeout);
+ clearInterval(intervalId);
+ reject(ClientAuthError.createUserTimeoutReachedError());
+ return [3 /*break*/, 5];
+ case 2:
+ if (!(TimeUtils.nowSeconds() > deviceCodeExpirationTime)) return [3 /*break*/, 3];
+ if (userSpecifiedTimeout) {
+ this.logger.verbose("User specified timeout ignored as the device code has expired before the timeout elapsed. The user specified timeout was set for " + userSpecifiedTimeout);
+ }
+ this.logger.error("Device code expired. Expiration time of device code was " + deviceCodeExpirationTime);
+ clearInterval(intervalId);
+ reject(ClientAuthError.createDeviceCodeExpiredError());
+ return [3 /*break*/, 5];
+ case 3:
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ return [4 /*yield*/, this.executePostToTokenEndpoint(this.authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ case 4:
+ response = _a.sent();
+ if (response.body && response.body.error === Constants.AUTHORIZATION_PENDING) {
+ // user authorization is pending. Sleep for polling interval and try again
+ this.logger.info(response.body.error_description || "no_error_description");
+ }
+ else {
+ clearInterval(intervalId);
+ resolve(response.body);
+ }
+ _a.label = 5;
+ case 5: return [3 /*break*/, 7];
+ case 6:
+ error_1 = _a.sent();
+ clearInterval(intervalId);
+ reject(error_1);
+ return [3 /*break*/, 7];
+ case 7: return [2 /*return*/];
+ }
+ });
+ }); }, pollingIntervalMilli);
+ })];
+ });
+ });
+ };
+ /**
+ * Creates query parameters and converts to string.
+ * @param request
+ * @param deviceCodeResponse
+ */
+ DeviceCodeClient.prototype.createTokenRequestBody = function (request, deviceCodeResponse) {
+ var requestParameters = new RequestParameterBuilder();
+ requestParameters.addScopes(request.scopes);
+ requestParameters.addClientId(this.config.authOptions.clientId);
+ requestParameters.addGrantType(GrantType.DEVICE_CODE_GRANT);
+ requestParameters.addDeviceCode(deviceCodeResponse.deviceCode);
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ requestParameters.addCorrelationId(correlationId);
+ requestParameters.addClientInfo();
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ requestParameters.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return requestParameters.createQueryString();
+ };
+ return DeviceCodeClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * OAuth2.0 refresh token client
+ */
+var RefreshTokenClient = /** @class */ (function (_super) {
+ __extends(RefreshTokenClient, _super);
+ function RefreshTokenClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ RefreshTokenClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var reqTimestamp, response, responseHandler;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ responseHandler.validateTokenResponse(response.body);
+ return [2 /*return*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, undefined, [], undefined, true)];
+ }
+ });
+ });
+ };
+ /**
+ * Gets cached refresh token and attaches to request, then calls acquireToken API
+ * @param request
+ */
+ RefreshTokenClient.prototype.acquireTokenByRefreshToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var isFOCI, noFamilyRTInCache, clientMismatchErrorWithFamilyRT;
+ return __generator(this, function (_a) {
+ // Cannot renew token if no request object is given.
+ if (!request) {
+ throw ClientConfigurationError.createEmptyTokenRequestError();
+ }
+ // We currently do not support silent flow for account === null use cases; This will be revisited for confidential flow usecases
+ if (!request.account) {
+ throw ClientAuthError.createNoAccountInSilentRequestError();
+ }
+ isFOCI = this.cacheManager.isAppMetadataFOCI(request.account.environment, this.config.authOptions.clientId);
+ // if the app is part of the family, retrive a Family refresh token if present and make a refreshTokenRequest
+ if (isFOCI) {
+ try {
+ return [2 /*return*/, this.acquireTokenWithCachedRefreshToken(request, true)];
+ }
+ catch (e) {
+ noFamilyRTInCache = e instanceof ClientAuthError && e.errorCode === ClientAuthErrorMessage.noTokensFoundError.code;
+ clientMismatchErrorWithFamilyRT = e instanceof ServerError && e.errorCode === Errors.INVALID_GRANT_ERROR && e.subError === Errors.CLIENT_MISMATCH_ERROR;
+ // if family Refresh Token (FRT) cache acquisition fails or if client_mismatch error is seen with FRT, reattempt with application Refresh Token (ART)
+ if (noFamilyRTInCache || clientMismatchErrorWithFamilyRT) {
+ return [2 /*return*/, this.acquireTokenWithCachedRefreshToken(request, false)];
+ // throw in all other cases
+ }
+ else {
+ throw e;
+ }
+ }
+ }
+ // fall back to application refresh token acquisition
+ return [2 /*return*/, this.acquireTokenWithCachedRefreshToken(request, false)];
+ });
+ });
+ };
+ /**
+ * makes a network call to acquire tokens by exchanging RefreshToken available in userCache; throws if refresh token is not cached
+ * @param request
+ */
+ RefreshTokenClient.prototype.acquireTokenWithCachedRefreshToken = function (request, foci) {
+ return __awaiter(this, void 0, void 0, function () {
+ var refreshToken, refreshTokenRequest;
+ return __generator(this, function (_a) {
+ refreshToken = this.cacheManager.readRefreshTokenFromCache(this.config.authOptions.clientId, request.account, foci);
+ // no refresh Token
+ if (!refreshToken) {
+ throw ClientAuthError.createNoTokensFoundError();
+ }
+ refreshTokenRequest = __assign(__assign({}, request), { refreshToken: refreshToken.secret, authenticationScheme: exports.AuthenticationScheme.BEARER });
+ return [2 /*return*/, this.acquireToken(refreshTokenRequest)];
+ });
+ });
+ };
+ /**
+ * Constructs the network message and makes a NW call to the underlying secure token service
+ * @param request
+ * @param authority
+ */
+ RefreshTokenClient.prototype.executeTokenRequest = function (request, authority) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, thumbprint;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0: return [4 /*yield*/, this.createTokenRequestBody(request)];
+ case 1:
+ requestBody = _a.sent();
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: authority.canonicalAuthority,
+ scopes: request.scopes
+ };
+ return [2 /*return*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ }
+ });
+ });
+ };
+ /**
+ * Helper function to create the token request body
+ * @param request
+ */
+ RefreshTokenClient.prototype.createTokenRequestBody = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var parameterBuilder, correlationId, clientAssertion, popTokenGenerator, _a, _b;
+ return __generator(this, function (_c) {
+ switch (_c.label) {
+ case 0:
+ parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addGrantType(GrantType.REFRESH_TOKEN_GRANT);
+ parameterBuilder.addClientInfo();
+ correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ parameterBuilder.addRefreshToken(request.refreshToken);
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ if (!(request.authenticationScheme === exports.AuthenticationScheme.POP)) return [3 /*break*/, 2];
+ popTokenGenerator = new PopTokenGenerator(this.cryptoUtils);
+ if (!request.resourceRequestMethod || !request.resourceRequestUri) {
+ throw ClientConfigurationError.createResourceRequestParametersRequiredError();
+ }
+ _b = (_a = parameterBuilder).addPopToken;
+ return [4 /*yield*/, popTokenGenerator.generateCnf(request.resourceRequestMethod, request.resourceRequestUri)];
+ case 1:
+ _b.apply(_a, [_c.sent()]);
+ _c.label = 2;
+ case 2:
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return [2 /*return*/, parameterBuilder.createQueryString()];
+ }
+ });
+ });
+ };
+ return RefreshTokenClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * OAuth2.0 client credential grant
+ */
+var ClientCredentialClient = /** @class */ (function (_super) {
+ __extends(ClientCredentialClient, _super);
+ function ClientCredentialClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Public API to acquire a token with ClientCredential Flow for Confidential clients
+ * @param request
+ */
+ ClientCredentialClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAuthenticationResult;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.scopeSet = new ScopeSet(request.scopes || []);
+ if (!request.skipCache) return [3 /*break*/, 2];
+ return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 1: return [2 /*return*/, _a.sent()];
+ case 2: return [4 /*yield*/, this.getCachedAuthenticationResult()];
+ case 3:
+ cachedAuthenticationResult = _a.sent();
+ if (!cachedAuthenticationResult) return [3 /*break*/, 4];
+ return [2 /*return*/, cachedAuthenticationResult];
+ case 4: return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 5: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * looks up cache if the tokens are cached already
+ */
+ ClientCredentialClient.prototype.getCachedAuthenticationResult = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAccessToken;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ cachedAccessToken = this.readAccessTokenFromCache();
+ if (!cachedAccessToken ||
+ TimeUtils.isTokenExpired(cachedAccessToken.expiresOn, this.config.systemOptions.tokenRenewalOffsetSeconds)) {
+ return [2 /*return*/, null];
+ }
+ return [4 /*yield*/, ResponseHandler.generateAuthenticationResult(this.cryptoUtils, this.authority, {
+ account: null,
+ idToken: null,
+ accessToken: cachedAccessToken,
+ refreshToken: null,
+ appMetadata: null
+ }, true)];
+ case 1: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Reads access token from the cache
+ * TODO: Move this call to cacheManager instead
+ */
+ ClientCredentialClient.prototype.readAccessTokenFromCache = function () {
+ var accessTokenFilter = {
+ homeAccountId: "",
+ environment: this.authority.canonicalAuthorityUrlComponents.HostNameAndPort,
+ credentialType: exports.CredentialType.ACCESS_TOKEN,
+ clientId: this.config.authOptions.clientId,
+ realm: this.authority.tenant,
+ target: this.scopeSet.printScopesLowerCase()
+ };
+ var credentialCache = this.cacheManager.getCredentialsFilteredBy(accessTokenFilter);
+ var accessTokens = Object.keys(credentialCache.accessTokens).map(function (key) { return credentialCache.accessTokens[key]; });
+ if (accessTokens.length < 1) {
+ return null;
+ }
+ else if (accessTokens.length > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return accessTokens[0];
+ };
+ /**
+ * Makes a network call to request the token from the service
+ * @param request
+ * @param authority
+ */
+ ClientCredentialClient.prototype.executeTokenRequest = function (request, authority) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, thumbprint, reqTimestamp, response, responseHandler, tokenResponse;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ requestBody = this.createTokenRequestBody(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ responseHandler.validateTokenResponse(response.body);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, undefined, request.scopes)];
+ case 2:
+ tokenResponse = _a.sent();
+ return [2 /*return*/, tokenResponse];
+ }
+ });
+ });
+ };
+ /**
+ * generate the request to the server in the acceptable format
+ * @param request
+ */
+ ClientCredentialClient.prototype.createTokenRequestBody = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addScopes(request.scopes, false);
+ parameterBuilder.addGrantType(GrantType.CLIENT_CREDENTIALS_GRANT);
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ var clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return ClientCredentialClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * On-Behalf-Of client
+ */
+var OnBehalfOfClient = /** @class */ (function (_super) {
+ __extends(OnBehalfOfClient, _super);
+ function OnBehalfOfClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Public API to acquire tokens with on behalf of flow
+ * @param request
+ */
+ OnBehalfOfClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAuthenticationResult;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.scopeSet = new ScopeSet(request.scopes || []);
+ if (!request.skipCache) return [3 /*break*/, 2];
+ return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 1: return [2 /*return*/, _a.sent()];
+ case 2: return [4 /*yield*/, this.getCachedAuthenticationResult(request)];
+ case 3:
+ cachedAuthenticationResult = _a.sent();
+ if (!cachedAuthenticationResult) return [3 /*break*/, 4];
+ return [2 /*return*/, cachedAuthenticationResult];
+ case 4: return [4 /*yield*/, this.executeTokenRequest(request, this.authority)];
+ case 5: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * look up cache for tokens
+ * @param request
+ */
+ OnBehalfOfClient.prototype.getCachedAuthenticationResult = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var cachedAccessToken, cachedIdToken, idTokenObject, cachedAccount, localAccountId, accountInfo;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ cachedAccessToken = this.readAccessTokenFromCache(request);
+ if (!cachedAccessToken ||
+ TimeUtils.isTokenExpired(cachedAccessToken.expiresOn, this.config.systemOptions.tokenRenewalOffsetSeconds)) {
+ return [2 /*return*/, null];
+ }
+ cachedIdToken = this.readIdTokenFromCache(request);
+ cachedAccount = null;
+ if (cachedIdToken) {
+ idTokenObject = new AuthToken(cachedIdToken.secret, this.config.cryptoInterface);
+ localAccountId = idTokenObject.claims.oid ? idTokenObject.claims.oid : idTokenObject.claims.sub;
+ accountInfo = {
+ homeAccountId: cachedIdToken.homeAccountId,
+ environment: cachedIdToken.environment,
+ tenantId: cachedIdToken.realm,
+ username: Constants.EMPTY_STRING,
+ localAccountId: localAccountId || ""
+ };
+ cachedAccount = this.readAccountFromCache(accountInfo);
+ }
+ return [4 /*yield*/, ResponseHandler.generateAuthenticationResult(this.cryptoUtils, this.authority, {
+ account: cachedAccount,
+ accessToken: cachedAccessToken,
+ idToken: cachedIdToken,
+ refreshToken: null,
+ appMetadata: null
+ }, true, idTokenObject)];
+ case 1: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * read access token from cache TODO: CacheManager API should be used here
+ * @param request
+ */
+ OnBehalfOfClient.prototype.readAccessTokenFromCache = function (request) {
+ var accessTokenFilter = {
+ environment: this.authority.canonicalAuthorityUrlComponents.HostNameAndPort,
+ credentialType: exports.CredentialType.ACCESS_TOKEN,
+ clientId: this.config.authOptions.clientId,
+ realm: this.authority.tenant,
+ target: this.scopeSet.printScopesLowerCase(),
+ oboAssertion: request.oboAssertion
+ };
+ var credentialCache = this.cacheManager.getCredentialsFilteredBy(accessTokenFilter);
+ var accessTokens = Object.keys(credentialCache.accessTokens).map(function (key) { return credentialCache.accessTokens[key]; });
+ var numAccessTokens = accessTokens.length;
+ if (numAccessTokens < 1) {
+ return null;
+ }
+ else if (numAccessTokens > 1) {
+ throw ClientAuthError.createMultipleMatchingTokensInCacheError();
+ }
+ return accessTokens[0];
+ };
+ /**
+ * read idtoken from cache TODO: CacheManager API should be used here instead
+ * @param request
+ */
+ OnBehalfOfClient.prototype.readIdTokenFromCache = function (request) {
+ var idTokenFilter = {
+ environment: this.authority.canonicalAuthorityUrlComponents.HostNameAndPort,
+ credentialType: exports.CredentialType.ID_TOKEN,
+ clientId: this.config.authOptions.clientId,
+ realm: this.authority.tenant,
+ oboAssertion: request.oboAssertion
+ };
+ var credentialCache = this.cacheManager.getCredentialsFilteredBy(idTokenFilter);
+ var idTokens = Object.keys(credentialCache.idTokens).map(function (key) { return credentialCache.idTokens[key]; });
+ // When acquiring a token on behalf of an application, there might not be an id token in the cache
+ if (idTokens.length < 1) {
+ return null;
+ }
+ return idTokens[0];
+ };
+ /**
+ * read account from cache, TODO: CacheManager API should be used here instead
+ * @param account
+ */
+ OnBehalfOfClient.prototype.readAccountFromCache = function (account) {
+ return this.cacheManager.readAccountFromCache(account);
+ };
+ /**
+ * Make a network call to the server requesting credentials
+ * @param request
+ * @param authority
+ */
+ OnBehalfOfClient.prototype.executeTokenRequest = function (request, authority) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestBody, headers, thumbprint, reqTimestamp, response, responseHandler, tokenResponse;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ requestBody = this.createTokenRequestBody(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: request.authority,
+ scopes: request.scopes
+ };
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ responseHandler.validateTokenResponse(response.body);
+ return [4 /*yield*/, responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp, request.resourceRequestMethod, request.resourceRequestUri, undefined, request.scopes, request.oboAssertion)];
+ case 2:
+ tokenResponse = _a.sent();
+ return [2 /*return*/, tokenResponse];
+ }
+ });
+ });
+ };
+ /**
+ * generate a server request in accepable format
+ * @param request
+ */
+ OnBehalfOfClient.prototype.createTokenRequestBody = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addGrantType(GrantType.JWT_BEARER);
+ parameterBuilder.addClientInfo();
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ parameterBuilder.addRequestTokenUse(AADServerParamKeys.ON_BEHALF_OF);
+ parameterBuilder.addOboAssertion(request.oboAssertion);
+ if (this.config.clientCredentials.clientSecret) {
+ parameterBuilder.addClientSecret(this.config.clientCredentials.clientSecret);
+ }
+ if (this.config.clientCredentials.clientAssertion) {
+ var clientAssertion = this.config.clientCredentials.clientAssertion;
+ parameterBuilder.addClientAssertion(clientAssertion.assertion);
+ parameterBuilder.addClientAssertionType(clientAssertion.assertionType);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return OnBehalfOfClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var SilentFlowClient = /** @class */ (function (_super) {
+ __extends(SilentFlowClient, _super);
+ function SilentFlowClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * Retrieves a token from cache if it is still valid, or uses the cached refresh token to renew
+ * the given token and returns the renewed token
+ * @param request
+ */
+ SilentFlowClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var e_1, refreshTokenClient;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ _a.trys.push([0, 2, , 3]);
+ return [4 /*yield*/, this.acquireCachedToken(request)];
+ case 1: return [2 /*return*/, _a.sent()];
+ case 2:
+ e_1 = _a.sent();
+ if (e_1 instanceof ClientAuthError && e_1.errorCode === ClientAuthErrorMessage.tokenRefreshRequired.code) {
+ refreshTokenClient = new RefreshTokenClient(this.config);
+ return [2 /*return*/, refreshTokenClient.acquireTokenByRefreshToken(request)];
+ }
+ else {
+ throw e_1;
+ }
+ case 3: return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Retrieves token from cache or throws an error if it must be refreshed.
+ * @param request
+ */
+ SilentFlowClient.prototype.acquireCachedToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var requestScopes, environment, cacheRecord;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ // Cannot renew token if no request object is given.
+ if (!request) {
+ throw ClientConfigurationError.createEmptyTokenRequestError();
+ }
+ // We currently do not support silent flow for account === null use cases; This will be revisited for confidential flow usecases
+ if (!request.account) {
+ throw ClientAuthError.createNoAccountInSilentRequestError();
+ }
+ requestScopes = new ScopeSet(request.scopes || []);
+ environment = request.authority || this.authority.getPreferredCache();
+ cacheRecord = this.cacheManager.readCacheRecord(request.account, this.config.authOptions.clientId, requestScopes, environment);
+ if (!this.isRefreshRequired(request, cacheRecord.accessToken)) return [3 /*break*/, 1];
+ throw ClientAuthError.createRefreshRequiredError();
+ case 1:
+ if (this.config.serverTelemetryManager) {
+ this.config.serverTelemetryManager.incrementCacheHits();
+ }
+ return [4 /*yield*/, this.generateResultFromCacheRecord(cacheRecord, request.resourceRequestMethod, request.resourceRequestUri)];
+ case 2: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Helper function to build response object from the CacheRecord
+ * @param cacheRecord
+ */
+ SilentFlowClient.prototype.generateResultFromCacheRecord = function (cacheRecord, resourceRequestMethod, resourceRequestUri) {
+ return __awaiter(this, void 0, void 0, function () {
+ var idTokenObj;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ if (cacheRecord.idToken) {
+ idTokenObj = new AuthToken(cacheRecord.idToken.secret, this.config.cryptoInterface);
+ }
+ return [4 /*yield*/, ResponseHandler.generateAuthenticationResult(this.cryptoUtils, this.authority, cacheRecord, true, idTokenObj, undefined, resourceRequestMethod, resourceRequestUri)];
+ case 1: return [2 /*return*/, _a.sent()];
+ }
+ });
+ });
+ };
+ /**
+ * Given a request object and an accessTokenEntity determine if the accessToken needs to be refreshed
+ * @param request
+ * @param cachedAccessToken
+ */
+ SilentFlowClient.prototype.isRefreshRequired = function (request, cachedAccessToken) {
+ if (request.forceRefresh || request.claims) {
+ // Must refresh due to request parameters
+ return true;
+ }
+ else if (!cachedAccessToken || TimeUtils.isTokenExpired(cachedAccessToken.expiresOn, this.config.systemOptions.tokenRenewalOffsetSeconds)) {
+ // Must refresh due to expired or non-existent access_token
+ return true;
+ }
+ return false;
+ };
+ return SilentFlowClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Oauth2.0 Password grant client
+ * Note: We are only supporting public clients for password grant and for purely testing purposes
+ */
+var UsernamePasswordClient = /** @class */ (function (_super) {
+ __extends(UsernamePasswordClient, _super);
+ function UsernamePasswordClient(configuration) {
+ return _super.call(this, configuration) || this;
+ }
+ /**
+ * API to acquire a token by passing the username and password to the service in exchage of credentials
+ * password_grant
+ * @param request
+ */
+ UsernamePasswordClient.prototype.acquireToken = function (request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var reqTimestamp, response, responseHandler, tokenResponse;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ this.logger.info("in acquireToken call");
+ reqTimestamp = TimeUtils.nowSeconds();
+ return [4 /*yield*/, this.executeTokenRequest(this.authority, request)];
+ case 1:
+ response = _a.sent();
+ responseHandler = new ResponseHandler(this.config.authOptions.clientId, this.cacheManager, this.cryptoUtils, this.logger, this.config.serializableCache, this.config.persistencePlugin);
+ // Validate response. This function throws a server error if an error is returned by the server.
+ responseHandler.validateTokenResponse(response.body);
+ tokenResponse = responseHandler.handleServerTokenResponse(response.body, this.authority, reqTimestamp);
+ return [2 /*return*/, tokenResponse];
+ }
+ });
+ });
+ };
+ /**
+ * Executes POST request to token endpoint
+ * @param authority
+ * @param request
+ */
+ UsernamePasswordClient.prototype.executeTokenRequest = function (authority, request) {
+ return __awaiter(this, void 0, void 0, function () {
+ var thumbprint, requestBody, headers;
+ return __generator(this, function (_a) {
+ thumbprint = {
+ clientId: this.config.authOptions.clientId,
+ authority: authority.canonicalAuthority,
+ scopes: request.scopes
+ };
+ requestBody = this.createTokenRequestBody(request);
+ headers = this.createDefaultTokenRequestHeaders();
+ return [2 /*return*/, this.executePostToTokenEndpoint(authority.tokenEndpoint, requestBody, headers, thumbprint)];
+ });
+ });
+ };
+ /**
+ * Generates a map for all the params to be sent to the service
+ * @param request
+ */
+ UsernamePasswordClient.prototype.createTokenRequestBody = function (request) {
+ var parameterBuilder = new RequestParameterBuilder();
+ parameterBuilder.addClientId(this.config.authOptions.clientId);
+ parameterBuilder.addUsername(request.username);
+ parameterBuilder.addPassword(request.password);
+ parameterBuilder.addScopes(request.scopes);
+ parameterBuilder.addGrantType(GrantType.RESOURCE_OWNER_PASSWORD_GRANT);
+ parameterBuilder.addClientInfo();
+ var correlationId = request.correlationId || this.config.cryptoInterface.createNewGuid();
+ parameterBuilder.addCorrelationId(correlationId);
+ if (!StringUtils.isEmpty(request.claims) || this.config.authOptions.clientCapabilities && this.config.authOptions.clientCapabilities.length > 0) {
+ parameterBuilder.addClaims(request.claims, this.config.authOptions.clientCapabilities);
+ }
+ return parameterBuilder.createQueryString();
+ };
+ return UsernamePasswordClient;
+}(BaseClient));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+function isOpenIdConfigResponse(response) {
+ return (response.hasOwnProperty("authorization_endpoint") &&
+ response.hasOwnProperty("token_endpoint") &&
+ response.hasOwnProperty("end_session_endpoint") &&
+ response.hasOwnProperty("issuer"));
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+(function (ProtocolMode) {
+ ProtocolMode["AAD"] = "AAD";
+ ProtocolMode["OIDC"] = "OIDC";
+})(exports.ProtocolMode || (exports.ProtocolMode = {}));
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var AuthorityMetadataEntity = /** @class */ (function () {
+ function AuthorityMetadataEntity() {
+ this.expiresAt = TimeUtils.nowSeconds() + AUTHORITY_METADATA_CONSTANTS.REFRESH_TIME_SECONDS;
+ }
+ /**
+ * Update the entity with new aliases, preferred_cache and preferred_network values
+ * @param metadata
+ * @param fromNetwork
+ */
+ AuthorityMetadataEntity.prototype.updateCloudDiscoveryMetadata = function (metadata, fromNetwork) {
+ this.aliases = metadata.aliases;
+ this.preferred_cache = metadata.preferred_cache;
+ this.preferred_network = metadata.preferred_network;
+ this.aliasesFromNetwork = fromNetwork;
+ };
+ /**
+ * Update the entity with new endpoints
+ * @param metadata
+ * @param fromNetwork
+ */
+ AuthorityMetadataEntity.prototype.updateEndpointMetadata = function (metadata, fromNetwork) {
+ this.authorization_endpoint = metadata.authorization_endpoint;
+ this.token_endpoint = metadata.token_endpoint;
+ this.end_session_endpoint = metadata.end_session_endpoint;
+ this.issuer = metadata.issuer;
+ this.endpointsFromNetwork = fromNetwork;
+ };
+ /**
+ * Save the authority that was used to create this cache entry
+ * @param authority
+ */
+ AuthorityMetadataEntity.prototype.updateCanonicalAuthority = function (authority) {
+ this.canonical_authority = authority;
+ };
+ /**
+ * Reset the exiresAt value
+ */
+ AuthorityMetadataEntity.prototype.resetExpiresAt = function () {
+ this.expiresAt = TimeUtils.nowSeconds() + AUTHORITY_METADATA_CONSTANTS.REFRESH_TIME_SECONDS;
+ };
+ /**
+ * Returns whether or not the data needs to be refreshed
+ */
+ AuthorityMetadataEntity.prototype.isExpired = function () {
+ return this.expiresAt <= TimeUtils.nowSeconds();
+ };
+ /**
+ * Validates an entity: checks for all expected params
+ * @param entity
+ */
+ AuthorityMetadataEntity.isAuthorityMetadataEntity = function (key, entity) {
+ if (!entity) {
+ return false;
+ }
+ return (key.indexOf(AUTHORITY_METADATA_CONSTANTS.CACHE_KEY) === 0 &&
+ entity.hasOwnProperty("aliases") &&
+ entity.hasOwnProperty("preferred_cache") &&
+ entity.hasOwnProperty("preferred_network") &&
+ entity.hasOwnProperty("canonical_authority") &&
+ entity.hasOwnProperty("authorization_endpoint") &&
+ entity.hasOwnProperty("token_endpoint") &&
+ entity.hasOwnProperty("end_session_endpoint") &&
+ entity.hasOwnProperty("issuer") &&
+ entity.hasOwnProperty("aliasesFromNetwork") &&
+ entity.hasOwnProperty("endpointsFromNetwork") &&
+ entity.hasOwnProperty("expiresAt"));
+ };
+ return AuthorityMetadataEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+function isCloudInstanceDiscoveryResponse(response) {
+ return (response.hasOwnProperty("tenant_discovery_endpoint") &&
+ response.hasOwnProperty("metadata"));
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * The authority class validates the authority URIs used by the user, and retrieves the OpenID Configuration Data from the
+ * endpoint. It will store the pertinent config data in this object for use during token calls.
+ */
+var Authority = /** @class */ (function () {
+ function Authority(authority, networkInterface, cacheManager, authorityOptions) {
+ this.canonicalAuthority = authority;
+ this._canonicalAuthority.validateAsUri();
+ this.networkInterface = networkInterface;
+ this.cacheManager = cacheManager;
+ this.authorityOptions = authorityOptions;
+ }
+ Object.defineProperty(Authority.prototype, "authorityType", {
+ // See above for AuthorityType
+ get: function () {
+ var pathSegments = this.canonicalAuthorityUrlComponents.PathSegments;
+ if (pathSegments.length && pathSegments[0].toLowerCase() === Constants.ADFS) {
+ return exports.AuthorityType.Adfs;
+ }
+ return exports.AuthorityType.Default;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "protocolMode", {
+ /**
+ * ProtocolMode enum representing the way endpoints are constructed.
+ */
+ get: function () {
+ return this.authorityOptions.protocolMode;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "options", {
+ /**
+ * Returns authorityOptions which can be used to reinstantiate a new authority instance
+ */
+ get: function () {
+ return this.authorityOptions;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "canonicalAuthority", {
+ /**
+ * A URL that is the authority set by the developer
+ */
+ get: function () {
+ return this._canonicalAuthority.urlString;
+ },
+ /**
+ * Sets canonical authority.
+ */
+ set: function (url) {
+ this._canonicalAuthority = new UrlString(url);
+ this._canonicalAuthority.validateAsUri();
+ this._canonicalAuthorityUrlComponents = null;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "canonicalAuthorityUrlComponents", {
+ /**
+ * Get authority components.
+ */
+ get: function () {
+ if (!this._canonicalAuthorityUrlComponents) {
+ this._canonicalAuthorityUrlComponents = this._canonicalAuthority.getUrlComponents();
+ }
+ return this._canonicalAuthorityUrlComponents;
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "hostnameAndPort", {
+ /**
+ * Get hostname and port i.e. login.microsoftonline.com
+ */
+ get: function () {
+ return this.canonicalAuthorityUrlComponents.HostNameAndPort.toLowerCase();
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "tenant", {
+ /**
+ * Get tenant for authority.
+ */
+ get: function () {
+ return this.canonicalAuthorityUrlComponents.PathSegments[0];
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "authorizationEndpoint", {
+ /**
+ * OAuth /authorize endpoint for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.authorization_endpoint);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "tokenEndpoint", {
+ /**
+ * OAuth /token endpoint for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.token_endpoint);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "deviceCodeEndpoint", {
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.token_endpoint.replace("/token", "/devicecode"));
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "endSessionEndpoint", {
+ /**
+ * OAuth logout endpoint for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.end_session_endpoint);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ Object.defineProperty(Authority.prototype, "selfSignedJwtAudience", {
+ /**
+ * OAuth issuer for requests
+ */
+ get: function () {
+ if (this.discoveryComplete()) {
+ var endpoint = this.replacePath(this.metadata.issuer);
+ return this.replaceTenant(endpoint);
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ },
+ enumerable: true,
+ configurable: true
+ });
+ /**
+ * Replaces tenant in url path with current tenant. Defaults to common.
+ * @param urlString
+ */
+ Authority.prototype.replaceTenant = function (urlString) {
+ return urlString.replace(/{tenant}|{tenantid}/g, this.tenant);
+ };
+ /**
+ * Replaces path such as tenant or policy with the current tenant or policy.
+ * @param urlString
+ */
+ Authority.prototype.replacePath = function (urlString) {
+ var endpoint = urlString;
+ var cachedAuthorityUrl = new UrlString(this.metadata.canonical_authority);
+ var cachedAuthorityParts = cachedAuthorityUrl.getUrlComponents().PathSegments;
+ var currentAuthorityParts = this.canonicalAuthorityUrlComponents.PathSegments;
+ currentAuthorityParts.forEach(function (currentPart, index) {
+ var cachedPart = cachedAuthorityParts[index];
+ if (currentPart !== cachedPart) {
+ endpoint = endpoint.replace("/" + cachedPart + "/", "/" + currentPart + "/");
+ }
+ });
+ return endpoint;
+ };
+ Object.defineProperty(Authority.prototype, "defaultOpenIdConfigurationEndpoint", {
+ /**
+ * The default open id configuration endpoint for any canonical authority.
+ */
+ get: function () {
+ if (this.authorityType === exports.AuthorityType.Adfs || this.protocolMode === exports.ProtocolMode.OIDC) {
+ return this.canonicalAuthority + ".well-known/openid-configuration";
+ }
+ return this.canonicalAuthority + "v2.0/.well-known/openid-configuration";
+ },
+ enumerable: true,
+ configurable: true
+ });
+ /**
+ * Boolean that returns whethr or not tenant discovery has been completed.
+ */
+ Authority.prototype.discoveryComplete = function () {
+ return !!this.metadata;
+ };
+ /**
+ * Perform endpoint discovery to discover aliases, preferred_cache, preferred_network
+ * and the /authorize, /token and logout endpoints.
+ */
+ Authority.prototype.resolveEndpointsAsync = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var metadataEntity, cloudDiscoverySource, endpointSource, cacheKey;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ metadataEntity = this.cacheManager.getAuthorityMetadataByAlias(this.hostnameAndPort);
+ if (!metadataEntity) {
+ metadataEntity = new AuthorityMetadataEntity();
+ metadataEntity.updateCanonicalAuthority(this.canonicalAuthority);
+ }
+ return [4 /*yield*/, this.updateCloudDiscoveryMetadata(metadataEntity)];
+ case 1:
+ cloudDiscoverySource = _a.sent();
+ this.canonicalAuthority = this.canonicalAuthority.replace(this.hostnameAndPort, metadataEntity.preferred_network);
+ return [4 /*yield*/, this.updateEndpointMetadata(metadataEntity)];
+ case 2:
+ endpointSource = _a.sent();
+ if (cloudDiscoverySource !== AuthorityMetadataSource.CACHE && endpointSource !== AuthorityMetadataSource.CACHE) {
+ // Reset the expiration time unless both values came from a successful cache lookup
+ metadataEntity.resetExpiresAt();
+ metadataEntity.updateCanonicalAuthority(this.canonicalAuthority);
+ }
+ cacheKey = this.cacheManager.generateAuthorityMetadataCacheKey(metadataEntity.preferred_cache);
+ this.cacheManager.setAuthorityMetadata(cacheKey, metadataEntity);
+ this.metadata = metadataEntity;
+ return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Update AuthorityMetadataEntity with new endpoints and return where the information came from
+ * @param metadataEntity
+ */
+ Authority.prototype.updateEndpointMetadata = function (metadataEntity) {
+ return __awaiter(this, void 0, void 0, function () {
+ var metadata;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ metadata = this.getEndpointMetadataFromConfig();
+ if (metadata) {
+ metadataEntity.updateEndpointMetadata(metadata, false);
+ return [2 /*return*/, AuthorityMetadataSource.CONFIG];
+ }
+ if (this.isAuthoritySameType(metadataEntity) && metadataEntity.endpointsFromNetwork && !metadataEntity.isExpired()) {
+ // No need to update
+ return [2 /*return*/, AuthorityMetadataSource.CACHE];
+ }
+ return [4 /*yield*/, this.getEndpointMetadataFromNetwork()];
+ case 1:
+ metadata = _a.sent();
+ if (metadata) {
+ metadataEntity.updateEndpointMetadata(metadata, true);
+ return [2 /*return*/, AuthorityMetadataSource.NETWORK];
+ }
+ else {
+ throw ClientAuthError.createUnableToGetOpenidConfigError(this.defaultOpenIdConfigurationEndpoint);
+ }
+ }
+ });
+ });
+ };
+ /**
+ * Compares the number of url components after the domain to determine if the cached authority metadata can be used for the requested authority
+ * Protects against same domain different authority such as login.microsoftonline.com/tenant and login.microsoftonline.com/tfp/tenant/policy
+ * @param metadataEntity
+ */
+ Authority.prototype.isAuthoritySameType = function (metadataEntity) {
+ var cachedAuthorityUrl = new UrlString(metadataEntity.canonical_authority);
+ var cachedParts = cachedAuthorityUrl.getUrlComponents().PathSegments;
+ return cachedParts.length === this.canonicalAuthorityUrlComponents.PathSegments.length;
+ };
+ /**
+ * Parse authorityMetadata config option
+ */
+ Authority.prototype.getEndpointMetadataFromConfig = function () {
+ if (this.authorityOptions.authorityMetadata) {
+ try {
+ return JSON.parse(this.authorityOptions.authorityMetadata);
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidAuthorityMetadataError();
+ }
+ }
+ return null;
+ };
+ /**
+ * Gets OAuth endpoints from the given OpenID configuration endpoint.
+ */
+ Authority.prototype.getEndpointMetadataFromNetwork = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var response, e_1;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ _a.trys.push([0, 2, , 3]);
+ return [4 /*yield*/, this.networkInterface.sendGetRequestAsync(this.defaultOpenIdConfigurationEndpoint)];
+ case 1:
+ response = _a.sent();
+ return [2 /*return*/, isOpenIdConfigResponse(response.body) ? response.body : null];
+ case 2:
+ e_1 = _a.sent();
+ return [2 /*return*/, null];
+ case 3: return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Updates the AuthorityMetadataEntity with new aliases, preferred_network and preferred_cache and returns where the information was retrived from
+ * @param cachedMetadata
+ * @param newMetadata
+ */
+ Authority.prototype.updateCloudDiscoveryMetadata = function (metadataEntity) {
+ return __awaiter(this, void 0, void 0, function () {
+ var metadata;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ metadata = this.getCloudDiscoveryMetadataFromConfig();
+ if (metadata) {
+ metadataEntity.updateCloudDiscoveryMetadata(metadata, false);
+ return [2 /*return*/, AuthorityMetadataSource.CONFIG];
+ }
+ // If The cached metadata came from config but that config was not passed to this instance, we must go to the network
+ if (this.isAuthoritySameType(metadataEntity) && metadataEntity.aliasesFromNetwork && !metadataEntity.isExpired()) {
+ // No need to update
+ return [2 /*return*/, AuthorityMetadataSource.CACHE];
+ }
+ return [4 /*yield*/, this.getCloudDiscoveryMetadataFromNetwork()];
+ case 1:
+ metadata = _a.sent();
+ if (metadata) {
+ metadataEntity.updateCloudDiscoveryMetadata(metadata, true);
+ return [2 /*return*/, AuthorityMetadataSource.NETWORK];
+ }
+ else {
+ // Metadata could not be obtained from config, cache or network
+ throw ClientConfigurationError.createUntrustedAuthorityError();
+ }
+ }
+ });
+ });
+ };
+ /**
+ * Parse cloudDiscoveryMetadata config or check knownAuthorities
+ */
+ Authority.prototype.getCloudDiscoveryMetadataFromConfig = function () {
+ // Check if network response was provided in config
+ if (this.authorityOptions.cloudDiscoveryMetadata) {
+ try {
+ var parsedResponse = JSON.parse(this.authorityOptions.cloudDiscoveryMetadata);
+ var metadata = Authority.getCloudDiscoveryMetadataFromNetworkResponse(parsedResponse.metadata, this.hostnameAndPort);
+ if (metadata) {
+ return metadata;
+ }
+ }
+ catch (e) {
+ throw ClientConfigurationError.createInvalidCloudDiscoveryMetadataError();
+ }
+ }
+ // If cloudDiscoveryMetadata is empty or does not contain the host, check knownAuthorities
+ if (this.isInKnownAuthorities()) {
+ return Authority.createCloudDiscoveryMetadataFromHost(this.hostnameAndPort);
+ }
+ return null;
+ };
+ /**
+ * Called to get metadata from network if CloudDiscoveryMetadata was not populated by config
+ * @param networkInterface
+ */
+ Authority.prototype.getCloudDiscoveryMetadataFromNetwork = function () {
+ return __awaiter(this, void 0, void 0, function () {
+ var instanceDiscoveryEndpoint, match, response, metadata, e_2;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ instanceDiscoveryEndpoint = "" + Constants.AAD_INSTANCE_DISCOVERY_ENDPT + this.canonicalAuthority + "oauth2/v2.0/authorize";
+ match = null;
+ _a.label = 1;
+ case 1:
+ _a.trys.push([1, 3, , 4]);
+ return [4 /*yield*/, this.networkInterface.sendGetRequestAsync(instanceDiscoveryEndpoint)];
+ case 2:
+ response = _a.sent();
+ metadata = isCloudInstanceDiscoveryResponse(response.body) ? response.body.metadata : [];
+ match = Authority.getCloudDiscoveryMetadataFromNetworkResponse(metadata, this.hostnameAndPort);
+ return [3 /*break*/, 4];
+ case 3:
+ e_2 = _a.sent();
+ return [2 /*return*/, null];
+ case 4:
+ if (!match) {
+ // Custom Domain scenario, host is trusted because Instance Discovery call succeeded
+ match = Authority.createCloudDiscoveryMetadataFromHost(this.hostnameAndPort);
+ }
+ return [2 /*return*/, match];
+ }
+ });
+ });
+ };
+ /**
+ * Helper function to determine if this host is included in the knownAuthorities config option
+ */
+ Authority.prototype.isInKnownAuthorities = function () {
+ var _this = this;
+ var matches = this.authorityOptions.knownAuthorities.filter(function (authority) {
+ return UrlString.getDomainFromUrl(authority).toLowerCase() === _this.hostnameAndPort;
+ });
+ return matches.length > 0;
+ };
+ /**
+ * Creates cloud discovery metadata object from a given host
+ * @param host
+ */
+ Authority.createCloudDiscoveryMetadataFromHost = function (host) {
+ return {
+ preferred_network: host,
+ preferred_cache: host,
+ aliases: [host]
+ };
+ };
+ /**
+ * Searches instance discovery network response for the entry that contains the host in the aliases list
+ * @param response
+ * @param authority
+ */
+ Authority.getCloudDiscoveryMetadataFromNetworkResponse = function (response, authority) {
+ for (var i = 0; i < response.length; i++) {
+ var metadata = response[i];
+ if (metadata.aliases.indexOf(authority) > -1) {
+ return metadata;
+ }
+ }
+ return null;
+ };
+ /**
+ * helper function to generate environment from authority object
+ */
+ Authority.prototype.getPreferredCache = function () {
+ if (this.discoveryComplete()) {
+ return this.metadata.preferred_cache;
+ }
+ else {
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError("Discovery incomplete.");
+ }
+ };
+ /**
+ * Returns whether or not the provided host is an alias of this authority instance
+ * @param host
+ */
+ Authority.prototype.isAlias = function (host) {
+ return this.metadata.aliases.indexOf(host) > -1;
+ };
+ return Authority;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var AuthorityFactory = /** @class */ (function () {
+ function AuthorityFactory() {
+ }
+ /**
+ * Create an authority object of the correct type based on the url
+ * Performs basic authority validation - checks to see if the authority is of a valid type (i.e. aad, b2c, adfs)
+ *
+ * Also performs endpoint discovery.
+ *
+ * @param authorityUri
+ * @param networkClient
+ * @param protocolMode
+ */
+ AuthorityFactory.createDiscoveredInstance = function (authorityUri, networkClient, cacheManager, authorityOptions) {
+ return __awaiter(this, void 0, void 0, function () {
+ var acquireTokenAuthority, e_1;
+ return __generator(this, function (_a) {
+ switch (_a.label) {
+ case 0:
+ acquireTokenAuthority = AuthorityFactory.createInstance(authorityUri, networkClient, cacheManager, authorityOptions);
+ _a.label = 1;
+ case 1:
+ _a.trys.push([1, 3, , 4]);
+ return [4 /*yield*/, acquireTokenAuthority.resolveEndpointsAsync()];
+ case 2:
+ _a.sent();
+ return [2 /*return*/, acquireTokenAuthority];
+ case 3:
+ e_1 = _a.sent();
+ throw ClientAuthError.createEndpointDiscoveryIncompleteError(e_1);
+ case 4: return [2 /*return*/];
+ }
+ });
+ });
+ };
+ /**
+ * Create an authority object of the correct type based on the url
+ * Performs basic authority validation - checks to see if the authority is of a valid type (i.e. aad, b2c, adfs)
+ *
+ * Does not perform endpoint discovery.
+ *
+ * @param authorityUrl
+ * @param networkInterface
+ * @param protocolMode
+ */
+ AuthorityFactory.createInstance = function (authorityUrl, networkInterface, cacheManager, authorityOptions) {
+ // Throw error if authority url is empty
+ if (StringUtils.isEmpty(authorityUrl)) {
+ throw ClientConfigurationError.createUrlEmptyError();
+ }
+ return new Authority(authorityUrl, networkInterface, cacheManager, authorityOptions);
+ };
+ return AuthorityFactory;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ServerTelemetryEntity = /** @class */ (function () {
+ function ServerTelemetryEntity() {
+ this.failedRequests = [];
+ this.errors = [];
+ this.cacheHits = 0;
+ }
+ /**
+ * validates if a given cache entry is "Telemetry", parses
+ * @param key
+ * @param entity
+ */
+ ServerTelemetryEntity.isServerTelemetryEntity = function (key, entity) {
+ var validateKey = key.indexOf(SERVER_TELEM_CONSTANTS.CACHE_KEY) === 0;
+ var validateEntity = true;
+ if (entity) {
+ validateEntity =
+ entity.hasOwnProperty("failedRequests") &&
+ entity.hasOwnProperty("errors") &&
+ entity.hasOwnProperty("cacheHits");
+ }
+ return validateKey && validateEntity;
+ };
+ return ServerTelemetryEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ThrottlingEntity = /** @class */ (function () {
+ function ThrottlingEntity() {
+ }
+ /**
+ * validates if a given cache entry is "Throttling", parses
+ * @param key
+ * @param entity
+ */
+ ThrottlingEntity.isThrottlingEntity = function (key, entity) {
+ var validateKey = false;
+ if (key) {
+ validateKey = key.indexOf(ThrottlingConstants.THROTTLING_PREFIX) === 0;
+ }
+ var validateEntity = true;
+ if (entity) {
+ validateEntity = entity.hasOwnProperty("throttleTime");
+ }
+ return validateKey && validateEntity;
+ };
+ return ThrottlingEntity;
+}());
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var StubbedNetworkModule = {
+ sendGetRequestAsync: function () {
+ var notImplErr = "Network interface - sendGetRequestAsync() has not been implemented for the Network interface.";
+ return Promise.reject(AuthError.createUnexpectedError(notImplErr));
+ },
+ sendPostRequestAsync: function () {
+ var notImplErr = "Network interface - sendPostRequestAsync() has not been implemented for the Network interface.";
+ return Promise.reject(AuthError.createUnexpectedError(notImplErr));
+ }
+};
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var ServerTelemetryManager = /** @class */ (function () {
+ function ServerTelemetryManager(telemetryRequest, cacheManager) {
+ this.cacheManager = cacheManager;
+ this.apiId = telemetryRequest.apiId;
+ this.correlationId = telemetryRequest.correlationId;
+ this.forceRefresh = telemetryRequest.forceRefresh || false;
+ this.wrapperSKU = telemetryRequest.wrapperSKU || Constants.EMPTY_STRING;
+ this.wrapperVer = telemetryRequest.wrapperVer || Constants.EMPTY_STRING;
+ this.telemetryCacheKey = SERVER_TELEM_CONSTANTS.CACHE_KEY + Separators.CACHE_KEY_SEPARATOR + telemetryRequest.clientId;
+ }
+ /**
+ * API to add MSER Telemetry to request
+ */
+ ServerTelemetryManager.prototype.generateCurrentRequestHeaderValue = function () {
+ var forceRefreshInt = this.forceRefresh ? 1 : 0;
+ var request = "" + this.apiId + SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR + forceRefreshInt;
+ var platformFields = [this.wrapperSKU, this.wrapperVer].join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ return [SERVER_TELEM_CONSTANTS.SCHEMA_VERSION, request, platformFields].join(SERVER_TELEM_CONSTANTS.CATEGORY_SEPARATOR);
+ };
+ /**
+ * API to add MSER Telemetry for the last failed request
+ */
+ ServerTelemetryManager.prototype.generateLastRequestHeaderValue = function () {
+ var lastRequests = this.getLastRequests();
+ var maxErrors = ServerTelemetryManager.maxErrorsToSend(lastRequests);
+ var failedRequests = lastRequests.failedRequests.slice(0, 2 * maxErrors).join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ var errors = lastRequests.errors.slice(0, maxErrors).join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ var errorCount = lastRequests.errors.length;
+ // Indicate whether this header contains all data or partial data
+ var overflow = maxErrors < errorCount ? SERVER_TELEM_CONSTANTS.OVERFLOW_TRUE : SERVER_TELEM_CONSTANTS.OVERFLOW_FALSE;
+ var platformFields = [errorCount, overflow].join(SERVER_TELEM_CONSTANTS.VALUE_SEPARATOR);
+ return [SERVER_TELEM_CONSTANTS.SCHEMA_VERSION, lastRequests.cacheHits, failedRequests, errors, platformFields].join(SERVER_TELEM_CONSTANTS.CATEGORY_SEPARATOR);
+ };
+ /**
+ * API to cache token failures for MSER data capture
+ * @param error
+ */
+ ServerTelemetryManager.prototype.cacheFailedRequest = function (error) {
+ var lastRequests = this.getLastRequests();
+ lastRequests.failedRequests.push(this.apiId, this.correlationId);
+ if (!StringUtils.isEmpty(error.subError)) {
+ lastRequests.errors.push(error.subError);
+ }
+ else if (!StringUtils.isEmpty(error.errorCode)) {
+ lastRequests.errors.push(error.errorCode);
+ }
+ else if (!!error && error.toString()) {
+ lastRequests.errors.push(error.toString());
+ }
+ else {
+ lastRequests.errors.push(SERVER_TELEM_CONSTANTS.UNKNOWN_ERROR);
+ }
+ this.cacheManager.setServerTelemetry(this.telemetryCacheKey, lastRequests);
+ return;
+ };
+ /**
+ * Update server telemetry cache entry by incrementing cache hit counter
+ */
+ ServerTelemetryManager.prototype.incrementCacheHits = function () {
+ var lastRequests = this.getLastRequests();
+ lastRequests.cacheHits += 1;
+ this.cacheManager.setServerTelemetry(this.telemetryCacheKey, lastRequests);
+ return lastRequests.cacheHits;
+ };
+ /**
+ * Get the server telemetry entity from cache or initialize a new one
+ */
+ ServerTelemetryManager.prototype.getLastRequests = function () {
+ var initialValue = new ServerTelemetryEntity();
+ var lastRequests = this.cacheManager.getServerTelemetry(this.telemetryCacheKey);
+ return lastRequests || initialValue;
+ };
+ /**
+ * Remove server telemetry cache entry
+ */
+ ServerTelemetryManager.prototype.clearTelemetryCache = function () {
+ var lastRequests = this.getLastRequests();
+ var numErrorsFlushed = ServerTelemetryManager.maxErrorsToSend(lastRequests);
+ var errorCount = lastRequests.errors.length;
+ if (numErrorsFlushed === errorCount) {
+ // All errors were sent on last request, clear Telemetry cache
+ this.cacheManager.removeItem(this.telemetryCacheKey);
+ }
+ else {
+ // Partial data was flushed to server, construct a new telemetry cache item with errors that were not flushed
+ var serverTelemEntity = new ServerTelemetryEntity();
+ serverTelemEntity.failedRequests = lastRequests.failedRequests.slice(numErrorsFlushed * 2); // failedRequests contains 2 items for each error
+ serverTelemEntity.errors = lastRequests.errors.slice(numErrorsFlushed);
+ this.cacheManager.setServerTelemetry(this.telemetryCacheKey, serverTelemEntity);
+ }
+ };
+ /**
+ * Returns the maximum number of errors that can be flushed to the server in the next network request
+ * @param serverTelemetryEntity
+ */
+ ServerTelemetryManager.maxErrorsToSend = function (serverTelemetryEntity) {
+ var i;
+ var maxErrors = 0;
+ var dataSize = 0;
+ var errorCount = serverTelemetryEntity.errors.length;
+ for (i = 0; i < errorCount; i++) {
+ // failedRequests parameter contains pairs of apiId and correlationId, multiply index by 2 to preserve pairs
+ var apiId = serverTelemetryEntity.failedRequests[2 * i] || Constants.EMPTY_STRING;
+ var correlationId = serverTelemetryEntity.failedRequests[2 * i + 1] || Constants.EMPTY_STRING;
+ var errorCode = serverTelemetryEntity.errors[i] || Constants.EMPTY_STRING;
+ // Count number of characters that would be added to header, each character is 1 byte. Add 3 at the end to account for separators
+ dataSize += apiId.toString().length + correlationId.toString().length + errorCode.length + 3;
+ if (dataSize < SERVER_TELEM_CONSTANTS.MAX_HEADER_BYTES) {
+ // Adding this entry to the header would still keep header size below the limit
+ maxErrors += 1;
+ }
+ else {
+ break;
+ }
+ }
+ return maxErrors;
+ };
+ return ServerTelemetryManager;
+}());
+
+exports.AccessTokenEntity = AccessTokenEntity;
+exports.AccountEntity = AccountEntity;
+exports.AppMetadataEntity = AppMetadataEntity;
+exports.AuthError = AuthError;
+exports.AuthErrorMessage = AuthErrorMessage;
+exports.AuthToken = AuthToken;
+exports.Authority = Authority;
+exports.AuthorityFactory = AuthorityFactory;
+exports.AuthorityMetadataEntity = AuthorityMetadataEntity;
+exports.AuthorizationCodeClient = AuthorizationCodeClient;
+exports.CacheManager = CacheManager;
+exports.ClientAuthError = ClientAuthError;
+exports.ClientAuthErrorMessage = ClientAuthErrorMessage;
+exports.ClientConfigurationError = ClientConfigurationError;
+exports.ClientConfigurationErrorMessage = ClientConfigurationErrorMessage;
+exports.ClientCredentialClient = ClientCredentialClient;
+exports.Constants = Constants;
+exports.CredentialEntity = CredentialEntity;
+exports.DEFAULT_CRYPTO_IMPLEMENTATION = DEFAULT_CRYPTO_IMPLEMENTATION;
+exports.DEFAULT_SYSTEM_OPTIONS = DEFAULT_SYSTEM_OPTIONS;
+exports.DefaultStorageClass = DefaultStorageClass;
+exports.DeviceCodeClient = DeviceCodeClient;
+exports.IdToken = AuthToken;
+exports.IdTokenEntity = IdTokenEntity;
+exports.InteractionRequiredAuthError = InteractionRequiredAuthError;
+exports.Logger = Logger;
+exports.NetworkManager = NetworkManager;
+exports.OIDC_DEFAULT_SCOPES = OIDC_DEFAULT_SCOPES;
+exports.OnBehalfOfClient = OnBehalfOfClient;
+exports.PromptValue = PromptValue;
+exports.ProtocolUtils = ProtocolUtils;
+exports.RefreshTokenClient = RefreshTokenClient;
+exports.RefreshTokenEntity = RefreshTokenEntity;
+exports.ServerError = ServerError;
+exports.ServerTelemetryEntity = ServerTelemetryEntity;
+exports.ServerTelemetryManager = ServerTelemetryManager;
+exports.SilentFlowClient = SilentFlowClient;
+exports.StringUtils = StringUtils;
+exports.StubbedNetworkModule = StubbedNetworkModule;
+exports.ThrottlingEntity = ThrottlingEntity;
+exports.ThrottlingUtils = ThrottlingUtils;
+exports.TimeUtils = TimeUtils;
+exports.TokenCacheContext = TokenCacheContext;
+exports.UrlString = UrlString;
+exports.UsernamePasswordClient = UsernamePasswordClient;
+//# sourceMappingURL=data:application/json;charset=utf-8;base64,
diff --git a/node_modules/@azure/msal-common/dist/logger/Logger.d.ts b/node_modules/@azure/msal-common/dist/logger/Logger.d.ts
new file mode 100644
index 0000000..1fb0cb6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/logger/Logger.d.ts
@@ -0,0 +1,86 @@
+import { LoggerOptions } from "../config/ClientConfiguration";
+/**
+ * Options for logger messages.
+ */
+export declare type LoggerMessageOptions = {
+ logLevel: LogLevel;
+ correlationId?: string;
+ containsPii?: boolean;
+ context?: string;
+};
+/**
+ * Log message level.
+ */
+export declare enum LogLevel {
+ Error = 0,
+ Warning = 1,
+ Info = 2,
+ Verbose = 3
+}
+/**
+ * Callback to send the messages to.
+ */
+export interface ILoggerCallback {
+ (level: LogLevel, message: string, containsPii: boolean): void;
+}
+/**
+ * Class which facilitates logging of messages to a specific place.
+ */
+export declare class Logger {
+ private correlationId;
+ private level;
+ private piiLoggingEnabled;
+ private localCallback;
+ private packageName;
+ private packageVersion;
+ constructor(loggerOptions: LoggerOptions, packageName?: string, packageVersion?: string);
+ /**
+ * Create new Logger with existing configurations.
+ */
+ clone(packageName: string, packageVersion: string): Logger;
+ /**
+ * Log message with required options.
+ */
+ private logMessage;
+ /**
+ * Execute callback with message.
+ */
+ executeCallback(level: LogLevel, message: string, containsPii: boolean): void;
+ /**
+ * Logs error messages.
+ */
+ error(message: string, correlationId?: string): void;
+ /**
+ * Logs error messages with PII.
+ */
+ errorPii(message: string, correlationId?: string): void;
+ /**
+ * Logs warning messages.
+ */
+ warning(message: string, correlationId?: string): void;
+ /**
+ * Logs warning messages with PII.
+ */
+ warningPii(message: string, correlationId?: string): void;
+ /**
+ * Logs info messages.
+ */
+ info(message: string, correlationId?: string): void;
+ /**
+ * Logs info messages with PII.
+ */
+ infoPii(message: string, correlationId?: string): void;
+ /**
+ * Logs verbose messages.
+ */
+ verbose(message: string, correlationId?: string): void;
+ /**
+ * Logs verbose messages with PII.
+ */
+ verbosePii(message: string, correlationId?: string): void;
+ /**
+ * Returns whether PII Logging is enabled or not.
+ */
+ isPiiLoggingEnabled(): boolean;
+}
+//# sourceMappingURL=Logger.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/logger/Logger.d.ts.map b/node_modules/@azure/msal-common/dist/logger/Logger.d.ts.map
new file mode 100644
index 0000000..09973f8
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/logger/Logger.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"Logger.d.ts","sourceRoot":"","sources":["../../src/logger/Logger.ts"],"names":[],"mappings":"AAMA,OAAO,EAAE,aAAa,EAAE,MAAM,+BAA+B,CAAC;AAG9D;;GAEG;AACH,oBAAY,oBAAoB,GAAG;IAC/B,QAAQ,EAAE,QAAQ,CAAC;IACnB,aAAa,CAAC,EAAE,MAAM,CAAC;IACvB,WAAW,CAAC,EAAE,OAAO,CAAC;IACtB,OAAO,CAAC,EAAE,MAAM,CAAA;CACnB,CAAC;AAEF;;GAEG;AACH,oBAAY,QAAQ;IAChB,KAAK,IAAA;IACL,OAAO,IAAA;IACP,IAAI,IAAA;IACJ,OAAO,IAAA;CACV;AAED;;GAEG;AACH,MAAM,WAAW,eAAe;IAC5B,CAAC,KAAK,EAAE,QAAQ,EAAE,OAAO,EAAE,MAAM,EAAE,WAAW,EAAE,OAAO,GAAG,IAAI,CAAC;CAClE;AAED;;GAEG;AACH,qBAAa,MAAM;IAGf,OAAO,CAAC,aAAa,CAAS;IAG9B,OAAO,CAAC,KAAK,CAA2B;IAGxC,OAAO,CAAC,iBAAiB,CAAU;IAGnC,OAAO,CAAC,aAAa,CAAkB;IAGvC,OAAO,CAAC,WAAW,CAAS;IAG5B,OAAO,CAAC,cAAc,CAAS;gBAEnB,aAAa,EAAE,aAAa,EAAE,WAAW,CAAC,EAAE,MAAM,EAAE,cAAc,CAAC,EAAE,MAAM;IAUvF;;OAEG;IACI,KAAK,CAAC,WAAW,EAAE,MAAM,EAAE,cAAc,EAAE,MAAM,GAAG,MAAM;IAIjE;;OAEG;IACH,OAAO,CAAC,UAAU;IAWlB;;OAEG;IACH,eAAe,CAAC,KAAK,EAAE,QAAQ,EAAE,OAAO,EAAE,MAAM,EAAE,WAAW,EAAE,OAAO,GAAG,IAAI;IAM7E;;OAEG;IACH,KAAK,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQpD;;OAEG;IACH,QAAQ,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQvD;;OAEG;IACH,OAAO,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQtD;;OAEG;IACH,UAAU,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQzD;;OAEG;IACH,IAAI,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQnD;;OAEG;IACH,OAAO,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQtD;;OAEG;IACH,OAAO,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQtD;;OAEG;IACH,UAAU,CAAC,OAAO,EAAE,MAAM,EAAE,aAAa,CAAC,EAAE,MAAM,GAAG,IAAI;IAQzD;;OAEG;IACH,mBAAmB,IAAI,OAAO;CAGjC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/INetworkModule.d.ts b/node_modules/@azure/msal-common/dist/network/INetworkModule.d.ts
new file mode 100644
index 0000000..7b9222e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/INetworkModule.d.ts
@@ -0,0 +1,30 @@
+import { NetworkResponse } from "./NetworkManager";
+/**
+ * Options allowed by network request APIs.
+ */
+export declare type NetworkRequestOptions = {
+ headers?: Record;
+ body?: string;
+};
+/**
+ * Client network interface to send backend requests.
+ * @interface
+ */
+export interface INetworkModule {
+ /**
+ * Interface function for async network "GET" requests. Based on the Fetch standard: https://fetch.spec.whatwg.org/
+ * @param url
+ * @param requestParams
+ * @param enableCaching
+ */
+ sendGetRequestAsync(url: string, options?: NetworkRequestOptions): Promise>;
+ /**
+ * Interface function for async network "POST" requests. Based on the Fetch standard: https://fetch.spec.whatwg.org/
+ * @param url
+ * @param requestParams
+ * @param enableCaching
+ */
+ sendPostRequestAsync(url: string, options?: NetworkRequestOptions): Promise>;
+}
+export declare const StubbedNetworkModule: INetworkModule;
+//# sourceMappingURL=INetworkModule.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/INetworkModule.d.ts.map b/node_modules/@azure/msal-common/dist/network/INetworkModule.d.ts.map
new file mode 100644
index 0000000..fedc85e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/INetworkModule.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"INetworkModule.d.ts","sourceRoot":"","sources":["../../src/network/INetworkModule.ts"],"names":[],"mappings":"AAMA,OAAO,EAAE,eAAe,EAAE,MAAM,kBAAkB,CAAC;AAEnD;;GAEG;AACH,oBAAY,qBAAqB,GAAG;IAChC,OAAO,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,CAAC;IACjC,IAAI,CAAC,EAAE,MAAM,CAAC;CACjB,CAAC;AAEF;;;GAGG;AACH,MAAM,WAAW,cAAc;IAE3B;;;;;OAKG;IACH,mBAAmB,CAAC,CAAC,EAAE,GAAG,EAAE,MAAM,EAAE,OAAO,CAAC,EAAE,qBAAqB,GAAG,OAAO,CAAC,eAAe,CAAC,CAAC,CAAC,CAAC,CAAC;IAElG;;;;;OAKG;IACH,oBAAoB,CAAC,CAAC,EAAE,GAAG,EAAE,MAAM,EAAE,OAAO,CAAC,EAAE,qBAAqB,GAAG,OAAO,CAAC,eAAe,CAAC,CAAC,CAAC,CAAC,CAAC;CACtG;AAED,eAAO,MAAM,oBAAoB,EAAE,cASlC,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/NetworkManager.d.ts b/node_modules/@azure/msal-common/dist/network/NetworkManager.d.ts
new file mode 100644
index 0000000..b2f6b4b
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/NetworkManager.d.ts
@@ -0,0 +1,21 @@
+import { INetworkModule, NetworkRequestOptions } from "./INetworkModule";
+import { RequestThumbprint } from "./RequestThumbprint";
+import { CacheManager } from "../cache/CacheManager";
+export declare type NetworkResponse = {
+ headers: Record;
+ body: T;
+ status: number;
+};
+export declare class NetworkManager {
+ private networkClient;
+ private cacheManager;
+ constructor(networkClient: INetworkModule, cacheManager: CacheManager);
+ /**
+ * Wraps sendPostRequestAsync with necessary preflight and postflight logic
+ * @param thumbprint
+ * @param tokenEndpoint
+ * @param options
+ */
+ sendPostRequest(thumbprint: RequestThumbprint, tokenEndpoint: string, options: NetworkRequestOptions): Promise>;
+}
+//# sourceMappingURL=NetworkManager.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/NetworkManager.d.ts.map b/node_modules/@azure/msal-common/dist/network/NetworkManager.d.ts.map
new file mode 100644
index 0000000..a53cb8e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/NetworkManager.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"NetworkManager.d.ts","sourceRoot":"","sources":["../../src/network/NetworkManager.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,cAAc,EAAE,qBAAqB,EAAE,MAAM,kBAAkB,CAAC;AACzE,OAAO,EAAE,iBAAiB,EAAE,MAAM,qBAAqB,CAAC;AAExD,OAAO,EAAE,YAAY,EAAE,MAAM,uBAAuB,CAAC;AAErD,oBAAY,eAAe,CAAC,CAAC,IAAI;IAC7B,OAAO,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,CAAC;IAChC,IAAI,EAAE,CAAC,CAAC;IACR,MAAM,EAAE,MAAM,CAAC;CAClB,CAAC;AAEF,qBAAa,cAAc;IACvB,OAAO,CAAC,aAAa,CAAiB;IACtC,OAAO,CAAC,YAAY,CAAe;gBAEvB,aAAa,EAAE,cAAc,EAAE,YAAY,EAAE,YAAY;IAKrE;;;;;OAKG;IACG,eAAe,CAAC,CAAC,EAAE,UAAU,EAAE,iBAAiB,EAAE,aAAa,EAAE,MAAM,EAAE,OAAO,EAAE,qBAAqB,GAAG,OAAO,CAAC,eAAe,CAAC,CAAC,CAAC,CAAC;CAS9I"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/RequestThumbprint.d.ts b/node_modules/@azure/msal-common/dist/network/RequestThumbprint.d.ts
new file mode 100644
index 0000000..f0b9036
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/RequestThumbprint.d.ts
@@ -0,0 +1,10 @@
+/**
+ * Type representing a unique request thumbprint.
+ */
+export declare type RequestThumbprint = {
+ clientId: string;
+ authority: string;
+ scopes: Array;
+ homeAccountIdentifier?: string;
+};
+//# sourceMappingURL=RequestThumbprint.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/RequestThumbprint.d.ts.map b/node_modules/@azure/msal-common/dist/network/RequestThumbprint.d.ts.map
new file mode 100644
index 0000000..a79b7a9
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/RequestThumbprint.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"RequestThumbprint.d.ts","sourceRoot":"","sources":["../../src/network/RequestThumbprint.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,oBAAY,iBAAiB,GAAG;IAC5B,QAAQ,EAAE,MAAM,CAAC;IACjB,SAAS,EAAE,MAAM,CAAC;IAClB,MAAM,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IACtB,qBAAqB,CAAC,EAAE,MAAM,CAAC;CAClC,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/ThrottlingUtils.d.ts b/node_modules/@azure/msal-common/dist/network/ThrottlingUtils.d.ts
new file mode 100644
index 0000000..bc6b2c0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/ThrottlingUtils.d.ts
@@ -0,0 +1,41 @@
+import { NetworkResponse } from "./NetworkManager";
+import { ServerAuthorizationTokenResponse } from "../response/ServerAuthorizationTokenResponse";
+import { CacheManager } from "../cache/CacheManager";
+import { RequestThumbprint } from "./RequestThumbprint";
+export declare class ThrottlingUtils {
+ /**
+ * Prepares a RequestThumbprint to be stored as a key.
+ * @param thumbprint
+ */
+ static generateThrottlingStorageKey(thumbprint: RequestThumbprint): string;
+ /**
+ * Performs necessary throttling checks before a network request.
+ * @param cacheManager
+ * @param thumbprint
+ */
+ static preProcess(cacheManager: CacheManager, thumbprint: RequestThumbprint): void;
+ /**
+ * Performs necessary throttling checks after a network request.
+ * @param cacheManager
+ * @param thumbprint
+ * @param response
+ */
+ static postProcess(cacheManager: CacheManager, thumbprint: RequestThumbprint, response: NetworkResponse): void;
+ /**
+ * Checks a NetworkResponse object's status codes against 429 or 5xx
+ * @param response
+ */
+ static checkResponseStatus(response: NetworkResponse): boolean;
+ /**
+ * Checks a NetworkResponse object's RetryAfter header
+ * @param response
+ */
+ static checkResponseForRetryAfter(response: NetworkResponse): boolean;
+ /**
+ * Calculates the Unix-time value for a throttle to expire given throttleTime in seconds.
+ * @param throttleTime
+ */
+ static calculateThrottleTime(throttleTime: number): number;
+ static removeThrottle(cacheManager: CacheManager, clientId: string, authority: string, scopes: Array, homeAccountIdentifier?: string): boolean;
+}
+//# sourceMappingURL=ThrottlingUtils.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/network/ThrottlingUtils.d.ts.map b/node_modules/@azure/msal-common/dist/network/ThrottlingUtils.d.ts.map
new file mode 100644
index 0000000..717394e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/network/ThrottlingUtils.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ThrottlingUtils.d.ts","sourceRoot":"","sources":["../../src/network/ThrottlingUtils.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,kBAAkB,CAAC;AACnD,OAAO,EAAE,gCAAgC,EAAE,MAAM,8CAA8C,CAAC;AAEhG,OAAO,EAAE,YAAY,EAAE,MAAM,uBAAuB,CAAC;AAErD,OAAO,EAAE,iBAAiB,EAAE,MAAM,qBAAqB,CAAC;AAGxD,qBAAa,eAAe;IAExB;;;OAGG;IACH,MAAM,CAAC,4BAA4B,CAAC,UAAU,EAAE,iBAAiB,GAAG,MAAM;IAI1E;;;;OAIG;IACH,MAAM,CAAC,UAAU,CAAC,YAAY,EAAE,YAAY,EAAE,UAAU,EAAE,iBAAiB,GAAG,IAAI;IAalF;;;;;OAKG;IACH,MAAM,CAAC,WAAW,CAAC,YAAY,EAAE,YAAY,EAAE,UAAU,EAAE,iBAAiB,EAAE,QAAQ,EAAE,eAAe,CAAC,gCAAgC,CAAC,GAAG,IAAI;IAgBhJ;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,QAAQ,EAAE,eAAe,CAAC,gCAAgC,CAAC,GAAG,OAAO;IAIhG;;;OAGG;IACH,MAAM,CAAC,0BAA0B,CAAC,QAAQ,EAAE,eAAe,CAAC,gCAAgC,CAAC,GAAG,OAAO;IAOvG;;;OAGG;IACH,MAAM,CAAC,qBAAqB,CAAC,YAAY,EAAE,MAAM,GAAG,MAAM;IAW1D,MAAM,CAAC,cAAc,CAAC,YAAY,EAAE,YAAY,EAAE,QAAQ,EAAE,MAAM,EAAE,SAAS,EAAE,MAAM,EAAE,MAAM,EAAE,KAAK,CAAC,MAAM,CAAC,EAAE,qBAAqB,CAAC,EAAE,MAAM,GAAG,OAAO;CAWzJ"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/packageMetadata.d.ts b/node_modules/@azure/msal-common/dist/packageMetadata.d.ts
new file mode 100644
index 0000000..6a189d0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/packageMetadata.d.ts
@@ -0,0 +1,3 @@
+export declare const name = "@azure/msal-common";
+export declare const version = "4.0.1";
+//# sourceMappingURL=packageMetadata.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/packageMetadata.d.ts.map b/node_modules/@azure/msal-common/dist/packageMetadata.d.ts.map
new file mode 100644
index 0000000..4c27d5d
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/packageMetadata.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"packageMetadata.d.ts","sourceRoot":"","sources":["../src/packageMetadata.ts"],"names":[],"mappings":"AACA,eAAO,MAAM,IAAI,uBAAuB,CAAC;AACzC,eAAO,MAAM,OAAO,UAAU,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/BaseAuthRequest.d.ts b/node_modules/@azure/msal-common/dist/request/BaseAuthRequest.d.ts
new file mode 100644
index 0000000..89dd9be
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/BaseAuthRequest.d.ts
@@ -0,0 +1,18 @@
+/**
+ * BaseAuthRequest
+ * - scopes - Array of scopes the application is requesting access to.
+ * - claims - A stringified claims request which will be added to all /authorize and /token calls
+ * - authority - URL of the authority, the security token service (STS) from which MSAL will acquire tokens. Defaults to https://login.microsoftonline.com/common. If using the same authority for all request, authority should set on client application object and not request, to avoid resolving authority endpoints multiple times.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - resourceRequestMethod - HTTP Request type used to request data from the resource (i.e. "GET", "POST", etc.). Used for proof-of-possession flows.
+ * - resourceRequestUri - URI that token will be used for. Used for proof-of-possession flows.
+ */
+export declare type BaseAuthRequest = {
+ authority: string;
+ correlationId: string;
+ scopes: Array;
+ claims?: string;
+ resourceRequestMethod?: string;
+ resourceRequestUri?: string;
+};
+//# sourceMappingURL=BaseAuthRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/BaseAuthRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/BaseAuthRequest.d.ts.map
new file mode 100644
index 0000000..ca5afd4
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/BaseAuthRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"BaseAuthRequest.d.ts","sourceRoot":"","sources":["../../src/request/BaseAuthRequest.ts"],"names":[],"mappings":"AAKA;;;;;;;;GAQG;AACH,oBAAY,eAAe,GAAG;IAC1B,SAAS,EAAE,MAAM,CAAC;IAClB,aAAa,EAAE,MAAM,CAAC;IACtB,MAAM,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IACtB,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,qBAAqB,CAAC,EAAE,MAAM,CAAC;IAC/B,kBAAkB,CAAC,EAAE,MAAM,CAAC;CAC/B,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonAuthorizationCodeRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationCodeRequest.d.ts
new file mode 100644
index 0000000..e22590b
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationCodeRequest.d.ts
@@ -0,0 +1,23 @@
+import { BaseAuthRequest } from "./BaseAuthRequest";
+import { AuthenticationScheme } from "../utils/Constants";
+/**
+ * Request object passed by user to acquire a token from the server exchanging a valid authorization code (second leg of OAuth2.0 Authorization Code flow)
+ *
+ * - scopes - Array of scopes the application is requesting access to.
+ * - claims - A stringified claims request which will be added to all /authorize and /token calls
+ * - authority: - URL of the authority, the security token service (STS) from which MSAL will acquire tokens. If authority is set on client application object, this will override that value. Overriding the value will cause for authority validation to happen each time. If the same authority will be used for all request, set on the application object instead of the requests.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - redirectUri - The redirect URI of your app, where the authority will redirect to after the user inputs credentials and consents. It must exactly match one of the redirect URIs you registered in the portal.
+ * - authenticationScheme - The type of token retrieved. Defaults to "Bearer". Can also be type "pop".
+ * - code - The authorization_code that the user acquired in the first leg of the flow.
+ * - codeVerifier - The same code_verifier that was used to obtain the authorization_code. Required if PKCE was used in the authorization code grant request.For more information, see the PKCE RFC: https://tools.ietf.org/html/rfc7636
+ * - resourceRequestMethod - HTTP Request type used to request data from the resource (i.e. "GET", "POST", etc.). Used for proof-of-possession flows.
+ * - resourceRequestUri - URI that token will be used for. Used for proof-of-possession flows.
+ */
+export declare type CommonAuthorizationCodeRequest = BaseAuthRequest & {
+ authenticationScheme: AuthenticationScheme;
+ code: string;
+ redirectUri: string;
+ codeVerifier?: string;
+};
+//# sourceMappingURL=CommonAuthorizationCodeRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonAuthorizationCodeRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationCodeRequest.d.ts.map
new file mode 100644
index 0000000..582c831
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationCodeRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonAuthorizationCodeRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonAuthorizationCodeRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AACpD,OAAO,EAAE,oBAAoB,EAAE,MAAM,oBAAoB,CAAC;AAE1D;;;;;;;;;;;;;GAaG;AACH,oBAAY,8BAA8B,GAAG,eAAe,GAAG;IAC3D,oBAAoB,EAAE,oBAAoB,CAAC;IAC3C,IAAI,EAAE,MAAM,CAAC;IACb,WAAW,EAAE,MAAM,CAAC;IACpB,YAAY,CAAC,EAAE,MAAM,CAAC;CACzB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonAuthorizationUrlRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationUrlRequest.d.ts
new file mode 100644
index 0000000..5aa995a
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationUrlRequest.d.ts
@@ -0,0 +1,49 @@
+import { ResponseMode, AuthenticationScheme } from "../utils/Constants";
+import { StringDict } from "../utils/MsalTypes";
+import { BaseAuthRequest } from "./BaseAuthRequest";
+import { AccountInfo } from "../account/AccountInfo";
+/**
+ * Request object passed by user to retrieve a Code from the server (first leg of authorization code grant flow)
+ *
+ * - authenticationScheme - The type of token retrieved. Defaults to "Bearer". Can also be type "pop".
+ * - scopes - Array of scopes the application is requesting access to.
+ * - claims - A stringified claims request which will be added to all /authorize and /token calls
+ * - authority - Url of the authority which the application acquires tokens from.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - redirectUri - The redirect URI where authentication responses can be received by your application. It must exactly match one of the redirect URIs registered in the Azure portal.
+ * - extraScopesToConsent - Scopes for a different resource when the user needs consent upfront.
+ * - responseMode - Specifies the method that should be used to send the authentication result to your app. Can be query, form_post, or fragment. If no value is passed in, it defaults to query.
+ * - codeChallenge - Used to secure authorization code grant via Proof of Key for Code Exchange (PKCE). For more information, see the PKCE RCF:https://tools.ietf.org/html/rfc7636
+ * - codeChallengeMethod - The method used to encode the code verifier for the code challenge parameter. Can be "plain" or "S256". If excluded, code challenge is assumed to be plaintext. For more information, see the PKCE RCF: https://tools.ietf.org/html/rfc7636
+ * - state - A value included in the request that is also returned in the token response. A randomly generated unique value is typically used for preventing cross site request forgery attacks. The state is also used to encode information about the user's state in the app before the authentication request occurred.
+ * - prompt - Indicates the type of user interaction that is required.
+ * login: will force the user to enter their credentials on that request, negating single-sign on
+ * none: will ensure that the user isn't presented with any interactive prompt. if request can't be completed via single-sign on, the endpoint will return an interaction_required error
+ * consent: will the trigger the OAuth consent dialog after the user signs in, asking the user to grant permissions to the app
+ * select_account: will interrupt single sign-=on providing account selection experience listing all the accounts in session or any remembered accounts or an option to choose to use a different account
+ * - account - AccountInfo obtained from a getAccount API. Will be used in certain scenarios to generate login_hint if both loginHint and sid params are not provided.
+ * - loginHint - Can be used to pre-fill the username/email address field of the sign-in page for the user, if you know the username/email address ahead of time. Often apps use this parameter during re-authentication, having already extracted the username from a previous sign-in using the preferred_username claim.
+ * - sid - Session ID, unique identifier for the session. Available as an optional claim on ID tokens.
+ * - domainHint - Provides a hint about the tenant or domain that the user should use to sign in. The value of the domain hint is a registered domain for the tenant.
+ * - extraQueryParameters - String to string map of custom query parameters.
+ * - nonce - A value included in the request that is returned in the id token. A randomly generated unique value is typically used to mitigate replay attacks.
+ * - resourceRequestMethod - HTTP Request type used to request data from the resource (i.e. "GET", "POST", etc.). Used for proof-of-possession flows.
+ * - resourceRequestUri - URI that token will be used for. Used for proof-of-possession flows.
+ */
+export declare type CommonAuthorizationUrlRequest = BaseAuthRequest & {
+ authenticationScheme: AuthenticationScheme;
+ redirectUri: string;
+ responseMode: ResponseMode;
+ account?: AccountInfo;
+ codeChallenge?: string;
+ codeChallengeMethod?: string;
+ domainHint?: string;
+ extraQueryParameters?: StringDict;
+ extraScopesToConsent?: Array;
+ loginHint?: string;
+ nonce?: string;
+ prompt?: string;
+ sid?: string;
+ state?: string;
+};
+//# sourceMappingURL=CommonAuthorizationUrlRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonAuthorizationUrlRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationUrlRequest.d.ts.map
new file mode 100644
index 0000000..32bc081
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonAuthorizationUrlRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonAuthorizationUrlRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonAuthorizationUrlRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,YAAY,EAAE,oBAAoB,EAAE,MAAM,oBAAoB,CAAC;AACxE,OAAO,EAAE,UAAU,EAAE,MAAM,oBAAoB,CAAC;AAChD,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AACpD,OAAO,EAAE,WAAW,EAAE,MAAM,wBAAwB,CAAC;AAErD;;;;;;;;;;;;;;;;;;;;;;;;;;;GA2BG;AACH,oBAAY,6BAA6B,GAAG,eAAe,GAAG;IAC1D,oBAAoB,EAAE,oBAAoB,CAAC;IAC3C,WAAW,EAAE,MAAM,CAAC;IACpB,YAAY,EAAE,YAAY,CAAC;IAC3B,OAAO,CAAC,EAAE,WAAW,CAAC;IACtB,aAAa,CAAC,EAAE,MAAM,CAAC;IACvB,mBAAmB,CAAC,EAAE,MAAM,CAAC;IAC7B,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,oBAAoB,CAAC,EAAE,UAAU,CAAC;IAClC,oBAAoB,CAAC,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IACrC,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,KAAK,CAAC,EAAE,MAAM,CAAC;CAClB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonClientCredentialRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonClientCredentialRequest.d.ts
new file mode 100644
index 0000000..030a59e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonClientCredentialRequest.d.ts
@@ -0,0 +1,12 @@
+import { BaseAuthRequest } from "./BaseAuthRequest";
+/**
+ * CommonClientCredentialRequest
+ * - scopes - Array of scopes the application is requesting access to.
+ * - authority - URL of the authority, the security token service (STS) from which MSAL will acquire tokens.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - skipCache - Skip token cache lookup and force request to authority to get a a new token. Defaults to false.
+ */
+export declare type CommonClientCredentialRequest = BaseAuthRequest & {
+ skipCache?: boolean;
+};
+//# sourceMappingURL=CommonClientCredentialRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonClientCredentialRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonClientCredentialRequest.d.ts.map
new file mode 100644
index 0000000..816455a
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonClientCredentialRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonClientCredentialRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonClientCredentialRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AAEpD;;;;;;GAMG;AACH,oBAAY,6BAA6B,GAAG,eAAe,GAAG;IAC1D,SAAS,CAAC,EAAE,OAAO,CAAC;CACvB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonDeviceCodeRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonDeviceCodeRequest.d.ts
new file mode 100644
index 0000000..8324006
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonDeviceCodeRequest.d.ts
@@ -0,0 +1,19 @@
+import { DeviceCodeResponse } from "../response/DeviceCodeResponse";
+import { BaseAuthRequest } from "./BaseAuthRequest";
+/**
+ * Parameters for Oauth2 device code flow.
+ * - scopes - Array of scopes the application is requesting access to.
+ * - authority: - URL of the authority, the security token service (STS) from which MSAL will acquire tokens. If authority is set on client application object, this will override that value. Overriding the value will cause for authority validation to happen each time. If the same authority will be used for all request, set on the application object instead of the requests.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - deviceCodeCallback - Callback containing device code response. Message should be shown to end user. End user can then navigate to the verification_uri, input the user_code, and input credentials.
+ * - cancel - Boolean to cancel polling of device code endpoint. While the user authenticates on a separate device, MSAL polls the the token endpoint of security token service for the interval specified in the device code response (usually 15 minutes). To stop polling and cancel the request, set cancel=true.
+ * - resourceRequestMethod - HTTP Request type used to request data from the resource (i.e. "GET", "POST", etc.). Used for proof-of-possession flows.
+ * - resourceRequestUri - URI that token will be used for. Used for proof-of-possession flows.
+ * - timeout - Timeout period in seconds which the user explicitly configures for the polling of the device code endpoint. At the end of this period; assuming the device code has not expired yet; the device code polling is stopped and the request cancelled. The device code expiration window will always take precedence over this set period.
+ */
+export declare type CommonDeviceCodeRequest = BaseAuthRequest & {
+ deviceCodeCallback: (response: DeviceCodeResponse) => void;
+ cancel?: boolean;
+ timeout?: number;
+};
+//# sourceMappingURL=CommonDeviceCodeRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonDeviceCodeRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonDeviceCodeRequest.d.ts.map
new file mode 100644
index 0000000..b07ad16
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonDeviceCodeRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonDeviceCodeRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonDeviceCodeRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,kBAAkB,EAAE,MAAM,gCAAgC,CAAC;AACpE,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AAEpD;;;;;;;;;;GAUG;AACH,oBAAY,uBAAuB,GAAG,eAAe,GAAI;IACrD,kBAAkB,EAAE,CAAC,QAAQ,EAAE,kBAAkB,KAAK,IAAI,CAAC;IAC3D,MAAM,CAAC,EAAE,OAAO,CAAC;IACjB,OAAO,CAAC,EAAE,MAAM,CAAC;CACpB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonEndSessionRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonEndSessionRequest.d.ts
new file mode 100644
index 0000000..aff0056
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonEndSessionRequest.d.ts
@@ -0,0 +1,15 @@
+import { AccountInfo } from "../account/AccountInfo";
+/**
+ * CommonEndSessionRequest
+ * - account - Account object that will be logged out of. All tokens tied to this account will be cleared.
+ * - postLogoutRedirectUri - URI to navigate to after logout page.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - idTokenHint - ID Token used by B2C to validate logout if required by the policy
+ */
+export declare type CommonEndSessionRequest = {
+ correlationId: string;
+ account?: AccountInfo;
+ postLogoutRedirectUri?: string | null;
+ idTokenHint?: string;
+};
+//# sourceMappingURL=CommonEndSessionRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonEndSessionRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonEndSessionRequest.d.ts.map
new file mode 100644
index 0000000..7fa72d6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonEndSessionRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonEndSessionRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonEndSessionRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,WAAW,EAAE,MAAM,wBAAwB,CAAC;AAErD;;;;;;GAMG;AACH,oBAAY,uBAAuB,GAAG;IAClC,aAAa,EAAE,MAAM,CAAA;IACrB,OAAO,CAAC,EAAE,WAAW,CAAC;IACtB,qBAAqB,CAAC,EAAE,MAAM,GAAG,IAAI,CAAC;IACtC,WAAW,CAAC,EAAE,MAAM,CAAA;CACvB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonOnBehalfOfRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonOnBehalfOfRequest.d.ts
new file mode 100644
index 0000000..7d67e5e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonOnBehalfOfRequest.d.ts
@@ -0,0 +1,13 @@
+import { BaseAuthRequest } from "./BaseAuthRequest";
+/**
+ * - scopes - Array of scopes the application is requesting access to.
+ * - authority - URL of the authority, the security token service (STS) from which MSAL will acquire tokens.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - oboAssertion - The access token that was sent to the middle-tier API. This token must have an audience of the app making this OBO request.
+ * - skipCache - Skip token cache lookup and force request to authority to get a a new token. Defaults to false.
+ */
+export declare type CommonOnBehalfOfRequest = BaseAuthRequest & {
+ oboAssertion: string;
+ skipCache?: boolean;
+};
+//# sourceMappingURL=CommonOnBehalfOfRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonOnBehalfOfRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonOnBehalfOfRequest.d.ts.map
new file mode 100644
index 0000000..dc6ac6d
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonOnBehalfOfRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonOnBehalfOfRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonOnBehalfOfRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AAEpD;;;;;;GAMG;AACH,oBAAY,uBAAuB,GAAG,eAAe,GAAG;IACpD,YAAY,EAAE,MAAM,CAAC;IACrB,SAAS,CAAC,EAAE,OAAO,CAAC;CACvB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonRefreshTokenRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonRefreshTokenRequest.d.ts
new file mode 100644
index 0000000..d621a46
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonRefreshTokenRequest.d.ts
@@ -0,0 +1,17 @@
+import { BaseAuthRequest } from "./BaseAuthRequest";
+import { AuthenticationScheme } from "../utils/Constants";
+/**
+ * CommonRefreshTokenRequest
+ * - scopes - Array of scopes the application is requesting access to.
+ * - claims - A stringified claims request which will be added to all /authorize and /token calls
+ * - authority - URL of the authority, the security token service (STS) from which MSAL will acquire tokens.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - refreshToken - A refresh token returned from a previous request to the Identity provider.
+ * - resourceRequestMethod - HTTP Request type used to request data from the resource (i.e. "GET", "POST", etc.). Used for proof-of-possession flows.
+ * - resourceRequestUri - URI that token will be used for. Used for proof-of-possession flows.
+ */
+export declare type CommonRefreshTokenRequest = BaseAuthRequest & {
+ refreshToken: string;
+ authenticationScheme: AuthenticationScheme;
+};
+//# sourceMappingURL=CommonRefreshTokenRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonRefreshTokenRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonRefreshTokenRequest.d.ts.map
new file mode 100644
index 0000000..d5867bf
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonRefreshTokenRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonRefreshTokenRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonRefreshTokenRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AACpD,OAAO,EAAE,oBAAoB,EAAE,MAAM,oBAAoB,CAAC;AAE1D;;;;;;;;;GASG;AACH,oBAAY,yBAAyB,GAAG,eAAe,GAAG;IACtD,YAAY,EAAE,MAAM,CAAC;IACrB,oBAAoB,EAAE,oBAAoB,CAAC;CAC9C,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonSilentFlowRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonSilentFlowRequest.d.ts
new file mode 100644
index 0000000..0215abb
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonSilentFlowRequest.d.ts
@@ -0,0 +1,18 @@
+import { AccountInfo } from "../account/AccountInfo";
+import { BaseAuthRequest } from "./BaseAuthRequest";
+/**
+ * SilentFlow parameters passed by the user to retrieve credentials silently
+ * - scopes - Array of scopes the application is requesting access to.
+ * - claims - A stringified claims request which will be added to all /authorize and /token calls. When included on a silent request, cache lookup will be skipped and token will be refreshed.
+ * - authority - Url of the authority which the application acquires tokens from.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - account - Account entity to lookup the credentials.
+ * - forceRefresh - Forces silent requests to make network calls if true.
+ * - resourceRequestMethod - HTTP Request type used to request data from the resource (i.e. "GET", "POST", etc.). Used for proof-of-possession flows.
+ * - resourceRequestUri - URI that token will be used for. Used for proof-of-possession flows.
+ */
+export declare type CommonSilentFlowRequest = BaseAuthRequest & {
+ account: AccountInfo;
+ forceRefresh: boolean;
+};
+//# sourceMappingURL=CommonSilentFlowRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonSilentFlowRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonSilentFlowRequest.d.ts.map
new file mode 100644
index 0000000..5fa68a3
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonSilentFlowRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonSilentFlowRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonSilentFlowRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,WAAW,EAAE,MAAM,wBAAwB,CAAC;AACrD,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AAEpD;;;;;;;;;;GAUG;AACH,oBAAY,uBAAuB,GAAG,eAAe,GAAG;IACpD,OAAO,EAAE,WAAW,CAAC;IACrB,YAAY,EAAE,OAAO,CAAC;CACzB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonUsernamePasswordRequest.d.ts b/node_modules/@azure/msal-common/dist/request/CommonUsernamePasswordRequest.d.ts
new file mode 100644
index 0000000..5436e8e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonUsernamePasswordRequest.d.ts
@@ -0,0 +1,17 @@
+import { BaseAuthRequest } from "./BaseAuthRequest";
+/**
+ * CommonUsernamePassword parameters passed by the user to retrieve credentials
+ * Note: The latest OAuth 2.0 Security Best Current Practice disallows the password grant entirely. This flow is added for internal testing.
+ *
+ * - scopes - Array of scopes the application is requesting access to.
+ * - claims - A stringified claims request which will be added to all /authorize and /token calls. When included on a silent request, cache lookup will be skipped and token will be refreshed.
+ * - authority - Url of the authority which the application acquires tokens from.
+ * - correlationId - Unique GUID set per request to trace a request end-to-end for telemetry purposes.
+ * - username - username of the client
+ * - password - credentials
+ */
+export declare type CommonUsernamePasswordRequest = BaseAuthRequest & {
+ username: string;
+ password: string;
+};
+//# sourceMappingURL=CommonUsernamePasswordRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/CommonUsernamePasswordRequest.d.ts.map b/node_modules/@azure/msal-common/dist/request/CommonUsernamePasswordRequest.d.ts.map
new file mode 100644
index 0000000..81b7b38
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/CommonUsernamePasswordRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CommonUsernamePasswordRequest.d.ts","sourceRoot":"","sources":["../../src/request/CommonUsernamePasswordRequest.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AAEpD;;;;;;;;;;GAUG;AACH,oBAAY,6BAA6B,GAAG,eAAe,GAAG;IAC1D,QAAQ,EAAE,MAAM,CAAC;IACjB,QAAQ,EAAE,MAAM,CAAC;CACpB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/RequestParameterBuilder.d.ts b/node_modules/@azure/msal-common/dist/request/RequestParameterBuilder.d.ts
new file mode 100644
index 0000000..252142b
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/RequestParameterBuilder.d.ts
@@ -0,0 +1,175 @@
+import { ResponseMode } from "../utils/Constants";
+import { StringDict } from "../utils/MsalTypes";
+import { LibraryInfo } from "../config/ClientConfiguration";
+export declare class RequestParameterBuilder {
+ private parameters;
+ constructor();
+ /**
+ * add response_type = code
+ */
+ addResponseTypeCode(): void;
+ /**
+ * add response_mode. defaults to query.
+ * @param responseMode
+ */
+ addResponseMode(responseMode?: ResponseMode): void;
+ /**
+ * add scopes. set addOidcScopes to false to prevent default scopes in non-user scenarios
+ * @param scopeSet
+ * @param addOidcScopes
+ */
+ addScopes(scopes: string[], addOidcScopes?: boolean): void;
+ /**
+ * add clientId
+ * @param clientId
+ */
+ addClientId(clientId: string): void;
+ /**
+ * add redirect_uri
+ * @param redirectUri
+ */
+ addRedirectUri(redirectUri: string): void;
+ /**
+ * add post logout redirectUri
+ * @param redirectUri
+ */
+ addPostLogoutRedirectUri(redirectUri: string): void;
+ /**
+ * add id_token_hint to logout request
+ * @param idTokenHint
+ */
+ addIdTokenHint(idTokenHint: string): void;
+ /**
+ * add domain_hint
+ * @param domainHint
+ */
+ addDomainHint(domainHint: string): void;
+ /**
+ * add login_hint
+ * @param loginHint
+ */
+ addLoginHint(loginHint: string): void;
+ /**
+ * add sid
+ * @param sid
+ */
+ addSid(sid: string): void;
+ /**
+ * add claims
+ * @param claims
+ */
+ addClaims(claims?: string, clientCapabilities?: Array): void;
+ /**
+ * add correlationId
+ * @param correlationId
+ */
+ addCorrelationId(correlationId: string): void;
+ /**
+ * add library info query params
+ * @param libraryInfo
+ */
+ addLibraryInfo(libraryInfo: LibraryInfo): void;
+ /**
+ * add prompt
+ * @param prompt
+ */
+ addPrompt(prompt: string): void;
+ /**
+ * add state
+ * @param state
+ */
+ addState(state: string): void;
+ /**
+ * add nonce
+ * @param nonce
+ */
+ addNonce(nonce: string): void;
+ /**
+ * add code_challenge and code_challenge_method
+ * - throw if either of them are not passed
+ * @param codeChallenge
+ * @param codeChallengeMethod
+ */
+ addCodeChallengeParams(codeChallenge: string, codeChallengeMethod: string): void;
+ /**
+ * add the `authorization_code` passed by the user to exchange for a token
+ * @param code
+ */
+ addAuthorizationCode(code: string): void;
+ /**
+ * add the `authorization_code` passed by the user to exchange for a token
+ * @param code
+ */
+ addDeviceCode(code: string): void;
+ /**
+ * add the `refreshToken` passed by the user
+ * @param refreshToken
+ */
+ addRefreshToken(refreshToken: string): void;
+ /**
+ * add the `code_verifier` passed by the user to exchange for a token
+ * @param codeVerifier
+ */
+ addCodeVerifier(codeVerifier: string): void;
+ /**
+ * add client_secret
+ * @param clientSecret
+ */
+ addClientSecret(clientSecret: string): void;
+ /**
+ * add clientAssertion for confidential client flows
+ * @param clientAssertion
+ */
+ addClientAssertion(clientAssertion: string): void;
+ /**
+ * add clientAssertionType for confidential client flows
+ * @param clientAssertionType
+ */
+ addClientAssertionType(clientAssertionType: string): void;
+ /**
+ * add OBO assertion for confidential client flows
+ * @param clientAssertion
+ */
+ addOboAssertion(oboAssertion: string): void;
+ /**
+ * add grant type
+ * @param grantType
+ */
+ addRequestTokenUse(tokenUse: string): void;
+ /**
+ * add grant type
+ * @param grantType
+ */
+ addGrantType(grantType: string): void;
+ /**
+ * add client info
+ *
+ */
+ addClientInfo(): void;
+ /**
+ * add extraQueryParams
+ * @param eQparams
+ */
+ addExtraQueryParameters(eQparams: StringDict): void;
+ addClientCapabilitiesToClaims(claims?: string, clientCapabilities?: Array): string;
+ /**
+ * adds `username` for Password Grant flow
+ * @param username
+ */
+ addUsername(username: string): void;
+ /**
+ * adds `password` for Password Grant flow
+ * @param password
+ */
+ addPassword(password: string): void;
+ /**
+ * add pop_jwk to query params
+ * @param cnfString
+ */
+ addPopToken(cnfString: string): void;
+ /**
+ * Utility to create a URL from the params map
+ */
+ createQueryString(): string;
+}
+//# sourceMappingURL=RequestParameterBuilder.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/RequestParameterBuilder.d.ts.map b/node_modules/@azure/msal-common/dist/request/RequestParameterBuilder.d.ts.map
new file mode 100644
index 0000000..05ea97f
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/RequestParameterBuilder.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"RequestParameterBuilder.d.ts","sourceRoot":"","sources":["../../src/request/RequestParameterBuilder.ts"],"names":[],"mappings":"AAKA,OAAO,EAAiC,YAAY,EAA6G,MAAM,oBAAoB,CAAC;AAG5L,OAAO,EAAE,UAAU,EAAE,MAAM,oBAAoB,CAAC;AAEhD,OAAO,EAAE,WAAW,EAAE,MAAM,+BAA+B,CAAC;AAG5D,qBAAa,uBAAuB;IAEhC,OAAO,CAAC,UAAU,CAAsB;;IAMxC;;OAEG;IACH,mBAAmB,IAAI,IAAI;IAM3B;;;OAGG;IACH,eAAe,CAAC,YAAY,CAAC,EAAE,YAAY,GAAG,IAAI;IAOlD;;;;OAIG;IACH,SAAS,CAAC,MAAM,EAAE,MAAM,EAAE,EAAE,aAAa,GAAE,OAAc,GAAG,IAAI;IAMhE;;;OAGG;IACH,WAAW,CAAC,QAAQ,EAAE,MAAM,GAAG,IAAI;IAInC;;;OAGG;IACH,cAAc,CAAC,WAAW,EAAE,MAAM,GAAG,IAAI;IAKzC;;;OAGG;IACH,wBAAwB,CAAC,WAAW,EAAE,MAAM,GAAG,IAAI;IAKnD;;;OAGG;IACH,cAAc,CAAC,WAAW,EAAE,MAAM,GAAG,IAAI;IAIzC;;;OAGG;IACH,aAAa,CAAC,UAAU,EAAE,MAAM,GAAG,IAAI;IAIvC;;;OAGG;IACH,YAAY,CAAC,SAAS,EAAE,MAAM,GAAG,IAAI;IAIrC;;;OAGG;IACH,MAAM,CAAC,GAAG,EAAE,MAAM,GAAG,IAAI;IAIzB;;;OAGG;IACH,SAAS,CAAC,MAAM,CAAC,EAAE,MAAM,EAAE,kBAAkB,CAAC,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,IAAI;IAMpE;;;OAGG;IACH,gBAAgB,CAAC,aAAa,EAAE,MAAM,GAAG,IAAI;IAI7C;;;OAGG;IACH,cAAc,CAAC,WAAW,EAAE,WAAW,GAAG,IAAI;IAQ9C;;;OAGG;IACH,SAAS,CAAC,MAAM,EAAE,MAAM,GAAG,IAAI;IAK/B;;;OAGG;IACH,QAAQ,CAAC,KAAK,EAAE,MAAM,GAAG,IAAI;IAM7B;;;OAGG;IACH,QAAQ,CAAC,KAAK,EAAE,MAAM,GAAG,IAAI;IAI7B;;;;;OAKG;IACH,sBAAsB,CAClB,aAAa,EAAE,MAAM,EACrB,mBAAmB,EAAE,MAAM,GAC5B,IAAI;IAUP;;;OAGG;IACH,oBAAoB,CAAC,IAAI,EAAE,MAAM,GAAG,IAAI;IAIxC;;;OAGG;IACH,aAAa,CAAC,IAAI,EAAE,MAAM,GAAG,IAAI;IAIjC;;;OAGG;IACH,eAAe,CAAC,YAAY,EAAE,MAAM,GAAG,IAAI;IAI3C;;;OAGG;IACH,eAAe,CAAC,YAAY,EAAE,MAAM,GAAG,IAAI;IAI3C;;;OAGG;IACH,eAAe,CAAC,YAAY,EAAE,MAAM,GAAG,IAAI;IAI3C;;;OAGG;IACH,kBAAkB,CAAC,eAAe,EAAE,MAAM,GAAG,IAAI;IAIjD;;;OAGG;IACH,sBAAsB,CAAC,mBAAmB,EAAE,MAAM,GAAG,IAAI;IAIzD;;;OAGG;IACH,eAAe,CAAC,YAAY,EAAE,MAAM,GAAG,IAAI;IAI3C;;;OAGG;IACH,kBAAkB,CAAC,QAAQ,EAAE,MAAM,GAAG,IAAI;IAI1C;;;OAGG;IACH,YAAY,CAAC,SAAS,EAAE,MAAM,GAAG,IAAI;IAIrC;;;OAGG;IACH,aAAa,IAAI,IAAI;IAIrB;;;OAGG;IACH,uBAAuB,CAAC,QAAQ,EAAE,UAAU,GAAG,IAAI;IAOnD,6BAA6B,CAAC,MAAM,CAAC,EAAE,MAAM,EAAE,kBAAkB,CAAC,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,MAAM;IA6B1F;;;OAGG;IACH,WAAW,CAAC,QAAQ,EAAE,MAAM,GAAG,IAAI;IAInC;;;OAGG;IACH,WAAW,CAAC,QAAQ,EAAE,MAAM,GAAG,IAAI;IAInC;;;OAGG;IACH,WAAW,CAAC,SAAS,EAAE,MAAM,GAAG,IAAI;IAOpC;;OAEG;IACH,iBAAiB,IAAI,MAAM;CAS9B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/RequestValidator.d.ts b/node_modules/@azure/msal-common/dist/request/RequestValidator.d.ts
new file mode 100644
index 0000000..318bcfa
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/RequestValidator.d.ts
@@ -0,0 +1,34 @@
+import { StringDict } from "../utils/MsalTypes";
+/**
+ * Validates server consumable params from the "request" objects
+ */
+export declare class RequestValidator {
+ /**
+ * Utility to check if the `redirectUri` in the request is a non-null value
+ * @param redirectUri
+ */
+ static validateRedirectUri(redirectUri: string): void;
+ /**
+ * Utility to validate prompt sent by the user in the request
+ * @param prompt
+ */
+ static validatePrompt(prompt: string): void;
+ static validateClaims(claims: string): void;
+ /**
+ * Utility to validate code_challenge and code_challenge_method
+ * @param codeChallenge
+ * @param codeChallengeMethod
+ */
+ static validateCodeChallengeParams(codeChallenge: string, codeChallengeMethod: string): void;
+ /**
+ * Utility to validate code_challenge_method
+ * @param codeChallengeMethod
+ */
+ static validateCodeChallengeMethod(codeChallengeMethod: string): void;
+ /**
+ * Removes unnecessary or duplicate query parameters from extraQueryParameters
+ * @param request
+ */
+ static sanitizeEQParams(eQParams: StringDict, queryParams: Map): StringDict;
+}
+//# sourceMappingURL=RequestValidator.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/RequestValidator.d.ts.map b/node_modules/@azure/msal-common/dist/request/RequestValidator.d.ts.map
new file mode 100644
index 0000000..0bd8e40
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/RequestValidator.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"RequestValidator.d.ts","sourceRoot":"","sources":["../../src/request/RequestValidator.ts"],"names":[],"mappings":"AAQA,OAAO,EAAE,UAAU,EAAE,MAAM,oBAAoB,CAAC;AAEhD;;GAEG;AACH,qBAAa,gBAAgB;IAEzB;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,WAAW,EAAE,MAAM,GAAI,IAAI;IAMtD;;;OAGG;IACH,MAAM,CAAC,cAAc,CAAC,MAAM,EAAE,MAAM,GAAI,IAAI;IAa5C,MAAM,CAAC,cAAc,CAAC,MAAM,EAAE,MAAM,GAAI,IAAI;IAQ5C;;;;OAIG;IACH,MAAM,CAAC,2BAA2B,CAAC,aAAa,EAAE,MAAM,EAAE,mBAAmB,EAAE,MAAM,GAAI,IAAI;IAQ7F;;;OAGG;IACH,MAAM,CAAC,2BAA2B,CAAC,mBAAmB,EAAE,MAAM,GAAI,IAAI;IAWtE;;;OAGG;IACH,MAAM,CAAC,gBAAgB,CAAC,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,GAAG,CAAC,MAAM,EAAE,MAAM,CAAC,GAAI,UAAU;CAc/F"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/ScopeSet.d.ts b/node_modules/@azure/msal-common/dist/request/ScopeSet.d.ts
new file mode 100644
index 0000000..bf04a64
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/ScopeSet.d.ts
@@ -0,0 +1,83 @@
+/**
+ * The ScopeSet class creates a set of scopes. Scopes are case-insensitive, unique values, so the Set object in JS makes
+ * the most sense to implement for this class. All scopes are trimmed and converted to lower case strings in intersection and union functions
+ * to ensure uniqueness of strings.
+ */
+export declare class ScopeSet {
+ private scopes;
+ constructor(inputScopes: Array);
+ /**
+ * Factory method to create ScopeSet from space-delimited string
+ * @param inputScopeString
+ * @param appClientId
+ * @param scopesRequired
+ */
+ static fromString(inputScopeString: string): ScopeSet;
+ /**
+ * Used to validate the scopes input parameter requested by the developer.
+ * @param {Array} inputScopes - Developer requested permissions. Not all scopes are guaranteed to be included in the access token returned.
+ * @param {boolean} scopesRequired - Boolean indicating whether the scopes array is required or not
+ */
+ private validateInputScopes;
+ /**
+ * Check if a given scope is present in this set of scopes.
+ * @param scope
+ */
+ containsScope(scope: string): boolean;
+ /**
+ * Check if a set of scopes is present in this set of scopes.
+ * @param scopeSet
+ */
+ containsScopeSet(scopeSet: ScopeSet): boolean;
+ /**
+ * Check if set of scopes contains only the defaults
+ */
+ containsOnlyOIDCScopes(): boolean;
+ /**
+ * Appends single scope if passed
+ * @param newScope
+ */
+ appendScope(newScope: string): void;
+ /**
+ * Appends multiple scopes if passed
+ * @param newScopes
+ */
+ appendScopes(newScopes: Array): void;
+ /**
+ * Removes element from set of scopes.
+ * @param scope
+ */
+ removeScope(scope: string): void;
+ /**
+ * Removes default scopes from set of scopes
+ * Primarily used to prevent cache misses if the default scopes are not returned from the server
+ */
+ removeOIDCScopes(): void;
+ /**
+ * Combines an array of scopes with the current set of scopes.
+ * @param otherScopes
+ */
+ unionScopeSets(otherScopes: ScopeSet): Set;
+ /**
+ * Check if scopes intersect between this set and another.
+ * @param otherScopes
+ */
+ intersectingScopeSets(otherScopes: ScopeSet): boolean;
+ /**
+ * Returns size of set of scopes.
+ */
+ getScopeCount(): number;
+ /**
+ * Returns the scopes as an array of string values
+ */
+ asArray(): Array;
+ /**
+ * Prints scopes into a space-delimited string
+ */
+ printScopes(): string;
+ /**
+ * Prints scopes into a space-delimited lower-case string (used for caching)
+ */
+ printScopesLowerCase(): string;
+}
+//# sourceMappingURL=ScopeSet.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/request/ScopeSet.d.ts.map b/node_modules/@azure/msal-common/dist/request/ScopeSet.d.ts.map
new file mode 100644
index 0000000..e920fe2
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/request/ScopeSet.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ScopeSet.d.ts","sourceRoot":"","sources":["../../src/request/ScopeSet.ts"],"names":[],"mappings":"AAUA;;;;GAIG;AACH,qBAAa,QAAQ;IAEjB,OAAO,CAAC,MAAM,CAAc;gBAEhB,WAAW,EAAE,KAAK,CAAC,MAAM,CAAC;IAYtC;;;;;OAKG;IACH,MAAM,CAAC,UAAU,CAAC,gBAAgB,EAAE,MAAM,GAAG,QAAQ;IAMrD;;;;OAIG;IACH,OAAO,CAAC,mBAAmB;IAO3B;;;OAGG;IACH,aAAa,CAAC,KAAK,EAAE,MAAM,GAAG,OAAO;IAOrC;;;OAGG;IACH,gBAAgB,CAAC,QAAQ,EAAE,QAAQ,GAAG,OAAO;IAQ7C;;OAEG;IACH,sBAAsB,IAAI,OAAO;IAWjC;;;OAGG;IACH,WAAW,CAAC,QAAQ,EAAE,MAAM,GAAG,IAAI;IAMnC;;;OAGG;IACH,YAAY,CAAC,SAAS,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,IAAI;IAQ5C;;;OAGG;IACH,WAAW,CAAC,KAAK,EAAE,MAAM,GAAG,IAAI;IAOhC;;;OAGG;IACH,gBAAgB,IAAI,IAAI;IAMxB;;;OAGG;IACH,cAAc,CAAC,WAAW,EAAE,QAAQ,GAAG,GAAG,CAAC,MAAM,CAAC;IAUlD;;;OAGG;IACH,qBAAqB,CAAC,WAAW,EAAE,QAAQ,GAAG,OAAO;IAgBrD;;OAEG;IACH,aAAa,IAAI,MAAM;IAIvB;;OAEG;IACH,OAAO,IAAI,KAAK,CAAC,MAAM,CAAC;IAMxB;;OAEG;IACH,WAAW,IAAI,MAAM;IAQrB;;OAEG;IACH,oBAAoB,IAAI,MAAM;CAGjC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/AuthenticationResult.d.ts b/node_modules/@azure/msal-common/dist/response/AuthenticationResult.d.ts
new file mode 100644
index 0000000..73fc6d2
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/AuthenticationResult.d.ts
@@ -0,0 +1,35 @@
+import { AccountInfo } from "../account/AccountInfo";
+/**
+ * Result returned from the authority's token endpoint.
+ * - uniqueId - `oid` or `sub` claim from ID token
+ * - tenantId - `tid` claim from ID token
+ * - scopes - Scopes that are validated for the respective token
+ * - account - An account object representation of the currently signed-in user
+ * - idToken - Id token received as part of the response
+ * - idTokenClaims - MSAL-relevant ID token claims
+ * - accessToken - Access token received as part of the response
+ * - fromCache - Boolean denoting whether token came from cache
+ * - expiresOn - Javascript Date object representing relative expiration of access token
+ * - extExpiresOn - Javascript Date object representing extended relative expiration of access token in case of server outage
+ * - state - Value passed in by user in request
+ * - familyId - Family ID identifier, usually only used for refresh tokens
+ */
+export declare type AuthenticationResult = {
+ authority: string;
+ uniqueId: string;
+ tenantId: string;
+ scopes: Array;
+ account: AccountInfo | null;
+ idToken: string;
+ idTokenClaims: object;
+ accessToken: string;
+ fromCache: boolean;
+ expiresOn: Date | null;
+ tokenType: string;
+ extExpiresOn?: Date;
+ state?: string;
+ familyId?: string;
+ cloudGraphHostName?: string;
+ msGraphHost?: string;
+};
+//# sourceMappingURL=AuthenticationResult.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/AuthenticationResult.d.ts.map b/node_modules/@azure/msal-common/dist/response/AuthenticationResult.d.ts.map
new file mode 100644
index 0000000..7cc2415
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/AuthenticationResult.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthenticationResult.d.ts","sourceRoot":"","sources":["../../src/response/AuthenticationResult.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,WAAW,EAAE,MAAM,wBAAwB,CAAC;AAErD;;;;;;;;;;;;;;GAcG;AACH,oBAAY,oBAAoB,GAAG;IAC/B,SAAS,EAAE,MAAM,CAAC;IAClB,QAAQ,EAAE,MAAM,CAAC;IACjB,QAAQ,EAAE,MAAM,CAAC;IACjB,MAAM,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IACtB,OAAO,EAAE,WAAW,GAAG,IAAI,CAAC;IAC5B,OAAO,EAAE,MAAM,CAAC;IAChB,aAAa,EAAE,MAAM,CAAC;IACtB,WAAW,EAAE,MAAM,CAAC;IACpB,SAAS,EAAE,OAAO,CAAC;IACnB,SAAS,EAAE,IAAI,GAAG,IAAI,CAAC;IACvB,SAAS,EAAE,MAAM,CAAC;IAClB,YAAY,CAAC,EAAE,IAAI,CAAC;IACpB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,kBAAkB,CAAC,EAAE,MAAM,CAAC;IAC5B,WAAW,CAAC,EAAE,MAAM,CAAC;CACxB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/AuthorizationCodePayload.d.ts b/node_modules/@azure/msal-common/dist/response/AuthorizationCodePayload.d.ts
new file mode 100644
index 0000000..3790413
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/AuthorizationCodePayload.d.ts
@@ -0,0 +1,13 @@
+/**
+ * Response returned after processing the code response query string or fragment.
+ */
+export declare type AuthorizationCodePayload = {
+ code: string;
+ cloud_instance_name?: string;
+ cloud_instance_host_name?: string;
+ cloud_graph_host_name?: string;
+ msgraph_host?: string;
+ state?: string;
+ nonce?: string;
+};
+//# sourceMappingURL=AuthorizationCodePayload.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/AuthorizationCodePayload.d.ts.map b/node_modules/@azure/msal-common/dist/response/AuthorizationCodePayload.d.ts.map
new file mode 100644
index 0000000..f6eb82c
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/AuthorizationCodePayload.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"AuthorizationCodePayload.d.ts","sourceRoot":"","sources":["../../src/response/AuthorizationCodePayload.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,oBAAY,wBAAwB,GAAG;IACnC,IAAI,EAAE,MAAM,CAAC;IACb,mBAAmB,CAAC,EAAE,MAAM,CAAC;IAC7B,wBAAwB,CAAC,EAAE,MAAM,CAAC;IAClC,qBAAqB,CAAC,EAAE,MAAM,CAAC;IAC/B,YAAY,CAAC,EAAE,MAAM,CAAC;IACtB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,KAAK,CAAC,EAAE,MAAM,CAAA;CACjB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/DeviceCodeResponse.d.ts b/node_modules/@azure/msal-common/dist/response/DeviceCodeResponse.d.ts
new file mode 100644
index 0000000..6fccff7
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/DeviceCodeResponse.d.ts
@@ -0,0 +1,26 @@
+/**
+ * DeviceCode returned by the security token service device code endpoint containing information necessary for device code flow.
+ * - userCode: code which user needs to provide when authenticating at the verification URI
+ * - deviceCode: code which should be included in the request for the access token
+ * - verificationUri: URI where user can authenticate
+ * - expiresIn: expiration time of the device code in seconds
+ * - interval: interval at which the STS should be polled at
+ * - message: message which should be displayed to the user
+ */
+export declare type DeviceCodeResponse = {
+ userCode: string;
+ deviceCode: string;
+ verificationUri: string;
+ expiresIn: number;
+ interval: number;
+ message: string;
+};
+export declare type ServerDeviceCodeResponse = {
+ user_code: string;
+ device_code: string;
+ verification_uri: string;
+ expires_in: number;
+ interval: number;
+ message: string;
+};
+//# sourceMappingURL=DeviceCodeResponse.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/DeviceCodeResponse.d.ts.map b/node_modules/@azure/msal-common/dist/response/DeviceCodeResponse.d.ts.map
new file mode 100644
index 0000000..bb36dac
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/DeviceCodeResponse.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"DeviceCodeResponse.d.ts","sourceRoot":"","sources":["../../src/response/DeviceCodeResponse.ts"],"names":[],"mappings":"AAKA;;;;;;;;GAQG;AACH,oBAAY,kBAAkB,GAAG;IAC7B,QAAQ,EAAE,MAAM,CAAC;IACjB,UAAU,EAAE,MAAM,CAAC;IACnB,eAAe,EAAE,MAAM,CAAC;IACxB,SAAS,EAAE,MAAM,CAAC;IAClB,QAAQ,EAAE,MAAM,CAAC;IACjB,OAAO,EAAE,MAAM,CAAC;CACnB,CAAC;AAEF,oBAAY,wBAAwB,GAAG;IACnC,SAAS,EAAE,MAAM,CAAC;IAClB,WAAW,EAAE,MAAM,CAAC;IACpB,gBAAgB,EAAE,MAAM,CAAC;IACzB,UAAU,EAAE,MAAM,CAAC;IACnB,QAAQ,EAAE,MAAM,CAAC;IACjB,OAAO,EAAE,MAAM,CAAC;CACnB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/ResponseHandler.d.ts b/node_modules/@azure/msal-common/dist/response/ResponseHandler.d.ts
new file mode 100644
index 0000000..eca7c69
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/ResponseHandler.d.ts
@@ -0,0 +1,70 @@
+import { ServerAuthorizationTokenResponse } from "./ServerAuthorizationTokenResponse";
+import { ICrypto } from "../crypto/ICrypto";
+import { ServerAuthorizationCodeResponse } from "./ServerAuthorizationCodeResponse";
+import { Logger } from "../logger/Logger";
+import { AuthToken } from "../account/AuthToken";
+import { AuthenticationResult } from "./AuthenticationResult";
+import { Authority } from "../authority/Authority";
+import { CacheRecord } from "../cache/entities/CacheRecord";
+import { CacheManager } from "../cache/CacheManager";
+import { RequestStateObject } from "../utils/ProtocolUtils";
+import { ICachePlugin } from "../cache/interface/ICachePlugin";
+import { ISerializableTokenCache } from "../cache/interface/ISerializableTokenCache";
+import { AuthorizationCodePayload } from "./AuthorizationCodePayload";
+/**
+ * Class that handles response parsing.
+ */
+export declare class ResponseHandler {
+ private clientId;
+ private cacheStorage;
+ private cryptoObj;
+ private logger;
+ private homeAccountIdentifier;
+ private serializableCache;
+ private persistencePlugin;
+ constructor(clientId: string, cacheStorage: CacheManager, cryptoObj: ICrypto, logger: Logger, serializableCache: ISerializableTokenCache | null, persistencePlugin: ICachePlugin | null);
+ /**
+ * Function which validates server authorization code response.
+ * @param serverResponseHash
+ * @param cachedState
+ * @param cryptoObj
+ */
+ validateServerAuthorizationCodeResponse(serverResponseHash: ServerAuthorizationCodeResponse, cachedState: string, cryptoObj: ICrypto): void;
+ /**
+ * Function which validates server authorization token response.
+ * @param serverResponse
+ */
+ validateTokenResponse(serverResponse: ServerAuthorizationTokenResponse): void;
+ /**
+ * Returns a constructed token response based on given string. Also manages the cache updates and cleanups.
+ * @param serverTokenResponse
+ * @param authority
+ */
+ handleServerTokenResponse(serverTokenResponse: ServerAuthorizationTokenResponse, authority: Authority, reqTimestamp: number, resourceRequestMethod?: string, resourceRequestUri?: string, authCodePayload?: AuthorizationCodePayload, requestScopes?: string[], oboAssertion?: string, handlingRefreshTokenResponse?: boolean): Promise;
+ /**
+ * Generates CacheRecord
+ * @param serverTokenResponse
+ * @param idTokenObj
+ * @param authority
+ */
+ private generateCacheRecord;
+ /**
+ * Generate Account
+ * @param serverTokenResponse
+ * @param idToken
+ * @param authority
+ */
+ private generateAccountEntity;
+ /**
+ * Creates an @AuthenticationResult from @CacheRecord , @IdToken , and a boolean that states whether or not the result is from cache.
+ *
+ * Optionally takes a state string that is set as-is in the response.
+ *
+ * @param cacheRecord
+ * @param idTokenObj
+ * @param fromTokenCache
+ * @param stateString
+ */
+ static generateAuthenticationResult(cryptoObj: ICrypto, authority: Authority, cacheRecord: CacheRecord, fromTokenCache: boolean, idTokenObj?: AuthToken, requestState?: RequestStateObject, resourceRequestMethod?: string, resourceRequestUri?: string): Promise;
+}
+//# sourceMappingURL=ResponseHandler.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/ResponseHandler.d.ts.map b/node_modules/@azure/msal-common/dist/response/ResponseHandler.d.ts.map
new file mode 100644
index 0000000..c475779
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/ResponseHandler.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ResponseHandler.d.ts","sourceRoot":"","sources":["../../src/response/ResponseHandler.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,gCAAgC,EAAE,MAAM,oCAAoC,CAAC;AAEtF,OAAO,EAAE,OAAO,EAAE,MAAM,mBAAmB,CAAC;AAG5C,OAAO,EAAE,+BAA+B,EAAE,MAAM,mCAAmC,CAAC;AACpF,OAAO,EAAE,MAAM,EAAE,MAAM,kBAAkB,CAAC;AAE1C,OAAO,EAAE,SAAS,EAAE,MAAM,sBAAsB,CAAC;AAEjD,OAAO,EAAE,oBAAoB,EAAE,MAAM,wBAAwB,CAAC;AAE9D,OAAO,EAAE,SAAS,EAAE,MAAM,wBAAwB,CAAC;AAMnD,OAAO,EAAE,WAAW,EAAE,MAAM,+BAA+B,CAAC;AAC5D,OAAO,EAAE,YAAY,EAAE,MAAM,uBAAuB,CAAC;AACrD,OAAO,EAAiB,kBAAkB,EAAE,MAAM,wBAAwB,CAAC;AAI3E,OAAO,EAAE,YAAY,EAAE,MAAM,iCAAiC,CAAC;AAE/D,OAAO,EAAE,uBAAuB,EAAE,MAAM,4CAA4C,CAAC;AACrF,OAAO,EAAE,wBAAwB,EAAE,MAAM,4BAA4B,CAAC;AAGtE;;GAEG;AACH,qBAAa,eAAe;IACxB,OAAO,CAAC,QAAQ,CAAS;IACzB,OAAO,CAAC,YAAY,CAAe;IACnC,OAAO,CAAC,SAAS,CAAU;IAC3B,OAAO,CAAC,MAAM,CAAS;IACvB,OAAO,CAAC,qBAAqB,CAAS;IACtC,OAAO,CAAC,iBAAiB,CAAiC;IAC1D,OAAO,CAAC,iBAAiB,CAAsB;gBAEnC,QAAQ,EAAE,MAAM,EAAE,YAAY,EAAE,YAAY,EAAE,SAAS,EAAE,OAAO,EAAE,MAAM,EAAE,MAAM,EAAE,iBAAiB,EAAE,uBAAuB,GAAG,IAAI,EAAE,iBAAiB,EAAE,YAAY,GAAG,IAAI;IASvL;;;;;OAKG;IACH,uCAAuC,CAAC,kBAAkB,EAAE,+BAA+B,EAAE,WAAW,EAAE,MAAM,EAAE,SAAS,EAAE,OAAO,GAAG,IAAI;IAwB3I;;;OAGG;IACH,qBAAqB,CAAC,cAAc,EAAE,gCAAgC,GAAG,IAAI;IAY7E;;;;OAIG;IACG,yBAAyB,CAC3B,mBAAmB,EAAE,gCAAgC,EACrD,SAAS,EAAE,SAAS,EACpB,YAAY,EAAE,MAAM,EACpB,qBAAqB,CAAC,EAAE,MAAM,EAC9B,kBAAkB,CAAC,EAAE,MAAM,EAC3B,eAAe,CAAC,EAAE,wBAAwB,EAC1C,aAAa,CAAC,EAAE,MAAM,EAAE,EACxB,YAAY,CAAC,EAAE,MAAM,EACrB,4BAA4B,CAAC,EAAE,OAAO,GAAG,OAAO,CAAC,oBAAoB,CAAC;IAuD1E;;;;;OAKG;IACH,OAAO,CAAC,mBAAmB;IA4E3B;;;;;OAKG;IACH,OAAO,CAAC,qBAAqB;IAqB7B;;;;;;;;;OASG;WACU,4BAA4B,CACrC,SAAS,EAAE,OAAO,EAClB,SAAS,EAAE,SAAS,EACpB,WAAW,EAAE,WAAW,EACxB,cAAc,EAAE,OAAO,EACvB,UAAU,CAAC,EAAE,SAAS,EACtB,YAAY,CAAC,EAAE,kBAAkB,EACjC,qBAAqB,CAAC,EAAE,MAAM,EAC9B,kBAAkB,CAAC,EAAE,MAAM,GAAG,OAAO,CAAC,oBAAoB,CAAC;CA+ClE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/ServerAuthorizationCodeResponse.d.ts b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationCodeResponse.d.ts
new file mode 100644
index 0000000..84929d9
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationCodeResponse.d.ts
@@ -0,0 +1,21 @@
+/**
+ * Deserialized response object from server authorization code request.
+ * - code: authorization code from server
+ * - client_info: client info object
+ * - state: OAuth2 request state
+ * - error: error sent back in hash
+ * - error: description
+ */
+export declare type ServerAuthorizationCodeResponse = {
+ code?: string;
+ client_info?: string;
+ state?: string;
+ cloud_instance_name?: string;
+ cloud_instance_host_name?: string;
+ cloud_graph_host_name?: string;
+ msgraph_host?: string;
+ error?: string;
+ error_description?: string;
+ suberror?: string;
+};
+//# sourceMappingURL=ServerAuthorizationCodeResponse.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/ServerAuthorizationCodeResponse.d.ts.map b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationCodeResponse.d.ts.map
new file mode 100644
index 0000000..581edf0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationCodeResponse.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ServerAuthorizationCodeResponse.d.ts","sourceRoot":"","sources":["../../src/response/ServerAuthorizationCodeResponse.ts"],"names":[],"mappings":"AAKA;;;;;;;GAOG;AACH,oBAAY,+BAA+B,GAAG;IAE1C,IAAI,CAAC,EAAE,MAAM,CAAC;IACd,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,mBAAmB,CAAC,EAAE,MAAM,CAAC;IAC7B,wBAAwB,CAAC,EAAE,MAAM,CAAC;IAClC,qBAAqB,CAAC,EAAE,MAAM,CAAC;IAC/B,YAAY,CAAC,EAAE,MAAM,CAAC;IAEtB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,iBAAiB,CAAC,EAAE,MAAM,CAAC;IAC3B,QAAQ,CAAC,EAAE,MAAM,CAAC;CACrB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/ServerAuthorizationTokenResponse.d.ts b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationTokenResponse.d.ts
new file mode 100644
index 0000000..9a5be2e
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationTokenResponse.d.ts
@@ -0,0 +1,37 @@
+/**
+ * Deserialized response object from server authorization code request.
+ * - token_type: Indicates the token type value. The only type that Azure AD supports is Bearer.
+ * - scope: The scopes that the access_token is valid for.
+ * - expires_in: How long the access token is valid (in seconds).
+ * - ext_expires_in: How long the access token is valid (in seconds) if the server isn't responding.
+ * - access_token: The requested access token. The app can use this token to authenticate to the secured resource, such as a web API.
+ * - refresh_token: An OAuth 2.0 refresh token. The app can use this token acquire additional access tokens after the current access token expires.
+ * - id_token: A JSON Web Token (JWT). The app can decode the segments of this token to request information about the user who signed in.
+ *
+ * In case of error:
+ * - error: An error code string that can be used to classify types of errors that occur, and can be used to react to errors.
+ * - error_description: A specific error message that can help a developer identify the root cause of an authentication error.
+ * - error_codes: A list of STS-specific error codes that can help in diagnostics.
+ * - timestamp: The time at which the error occurred.
+ * - trace_id: A unique identifier for the request that can help in diagnostics.
+ * - correlation_id: A unique identifier for the request that can help in diagnostics across components.
+ */
+export declare type ServerAuthorizationTokenResponse = {
+ token_type?: string;
+ scope?: string;
+ expires_in?: number;
+ ext_expires_in?: number;
+ access_token?: string;
+ refresh_token?: string;
+ id_token?: string;
+ client_info?: string;
+ foci?: string;
+ error?: string;
+ error_description?: string;
+ error_codes?: Array;
+ suberror?: string;
+ timestamp?: string;
+ trace_id?: string;
+ correlation_id?: string;
+};
+//# sourceMappingURL=ServerAuthorizationTokenResponse.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/response/ServerAuthorizationTokenResponse.d.ts.map b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationTokenResponse.d.ts.map
new file mode 100644
index 0000000..d25cc68
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/response/ServerAuthorizationTokenResponse.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ServerAuthorizationTokenResponse.d.ts","sourceRoot":"","sources":["../../src/response/ServerAuthorizationTokenResponse.ts"],"names":[],"mappings":"AAKA;;;;;;;;;;;;;;;;;GAiBG;AACH,oBAAY,gCAAgC,GAAG;IAE3C,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,cAAc,CAAC,EAAE,MAAM,CAAC;IACxB,YAAY,CAAC,EAAE,MAAM,CAAC;IACtB,aAAa,CAAC,EAAE,MAAM,CAAC;IACvB,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,IAAI,CAAC,EAAE,MAAM,CAAA;IAEb,KAAK,CAAC,EAAE,MAAM,CAAC;IACf,iBAAiB,CAAC,EAAE,MAAM,CAAC;IAC3B,WAAW,CAAC,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IAC5B,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,QAAQ,CAAC,EAAE,MAAM,CAAC;IAClB,cAAc,CAAC,EAAE,MAAM,CAAC;CAC3B,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryManager.d.ts b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryManager.d.ts
new file mode 100644
index 0000000..12e7846
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryManager.d.ts
@@ -0,0 +1,45 @@
+import { CacheManager } from "../../cache/CacheManager";
+import { AuthError } from "../../error/AuthError";
+import { ServerTelemetryRequest } from "./ServerTelemetryRequest";
+import { ServerTelemetryEntity } from "../../cache/entities/ServerTelemetryEntity";
+export declare class ServerTelemetryManager {
+ private cacheManager;
+ private apiId;
+ private correlationId;
+ private forceRefresh;
+ private telemetryCacheKey;
+ private wrapperSKU;
+ private wrapperVer;
+ constructor(telemetryRequest: ServerTelemetryRequest, cacheManager: CacheManager);
+ /**
+ * API to add MSER Telemetry to request
+ */
+ generateCurrentRequestHeaderValue(): string;
+ /**
+ * API to add MSER Telemetry for the last failed request
+ */
+ generateLastRequestHeaderValue(): string;
+ /**
+ * API to cache token failures for MSER data capture
+ * @param error
+ */
+ cacheFailedRequest(error: AuthError): void;
+ /**
+ * Update server telemetry cache entry by incrementing cache hit counter
+ */
+ incrementCacheHits(): number;
+ /**
+ * Get the server telemetry entity from cache or initialize a new one
+ */
+ getLastRequests(): ServerTelemetryEntity;
+ /**
+ * Remove server telemetry cache entry
+ */
+ clearTelemetryCache(): void;
+ /**
+ * Returns the maximum number of errors that can be flushed to the server in the next network request
+ * @param serverTelemetryEntity
+ */
+ static maxErrorsToSend(serverTelemetryEntity: ServerTelemetryEntity): number;
+}
+//# sourceMappingURL=ServerTelemetryManager.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryManager.d.ts.map b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryManager.d.ts.map
new file mode 100644
index 0000000..bcf4672
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryManager.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ServerTelemetryManager.d.ts","sourceRoot":"","sources":["../../../src/telemetry/server/ServerTelemetryManager.ts"],"names":[],"mappings":"AAMA,OAAO,EAAE,YAAY,EAAE,MAAM,0BAA0B,CAAC;AACxD,OAAO,EAAE,SAAS,EAAE,MAAM,uBAAuB,CAAC;AAClD,OAAO,EAAE,sBAAsB,EAAE,MAAM,0BAA0B,CAAC;AAClE,OAAO,EAAE,qBAAqB,EAAE,MAAM,4CAA4C,CAAC;AAGnF,qBAAa,sBAAsB;IAC/B,OAAO,CAAC,YAAY,CAAe;IACnC,OAAO,CAAC,KAAK,CAAS;IACtB,OAAO,CAAC,aAAa,CAAS;IAC9B,OAAO,CAAC,YAAY,CAAU;IAC9B,OAAO,CAAC,iBAAiB,CAAS;IAClC,OAAO,CAAC,UAAU,CAAS;IAC3B,OAAO,CAAC,UAAU,CAAS;gBAEf,gBAAgB,EAAE,sBAAsB,EAAE,YAAY,EAAE,YAAY;IAWhF;;OAEG;IACH,iCAAiC,IAAI,MAAM;IAQ3C;;OAEG;IACH,8BAA8B,IAAI,MAAM;IAexC;;;OAGG;IACH,kBAAkB,CAAC,KAAK,EAAE,SAAS,GAAG,IAAI;IAmB1C;;OAEG;IACH,kBAAkB,IAAI,MAAM;IAQ5B;;OAEG;IACH,eAAe,IAAI,qBAAqB;IAOxC;;OAEG;IACH,mBAAmB,IAAI,IAAI;IAiB3B;;;OAGG;IACH,MAAM,CAAC,eAAe,CAAC,qBAAqB,EAAE,qBAAqB,GAAG,MAAM;CAwB/E"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryRequest.d.ts b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryRequest.d.ts
new file mode 100644
index 0000000..15a8ebf
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryRequest.d.ts
@@ -0,0 +1,9 @@
+export declare type ServerTelemetryRequest = {
+ clientId: string;
+ apiId: number;
+ correlationId: string;
+ forceRefresh?: boolean;
+ wrapperSKU?: string;
+ wrapperVer?: string;
+};
+//# sourceMappingURL=ServerTelemetryRequest.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryRequest.d.ts.map b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryRequest.d.ts.map
new file mode 100644
index 0000000..e99a14c
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/telemetry/server/ServerTelemetryRequest.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ServerTelemetryRequest.d.ts","sourceRoot":"","sources":["../../../src/telemetry/server/ServerTelemetryRequest.ts"],"names":[],"mappings":"AAKA,oBAAY,sBAAsB,GAAG;IACjC,QAAQ,EAAE,MAAM,CAAC;IACjB,KAAK,EAAE,MAAM,CAAC;IACd,aAAa,EAAE,MAAM,CAAC;IACtB,YAAY,CAAC,EAAE,OAAO,CAAC;IACvB,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,UAAU,CAAC,EAAE,MAAM,CAAC;CACvB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/url/IUri.d.ts b/node_modules/@azure/msal-common/dist/url/IUri.d.ts
new file mode 100644
index 0000000..b3808b0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/url/IUri.d.ts
@@ -0,0 +1,13 @@
+/**
+ * Interface which describes URI components.
+ */
+export interface IUri {
+ Protocol: string;
+ HostNameAndPort: string;
+ AbsolutePath: string;
+ Search: string;
+ Hash: string;
+ PathSegments: string[];
+ QueryString: string;
+}
+//# sourceMappingURL=IUri.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/url/IUri.d.ts.map b/node_modules/@azure/msal-common/dist/url/IUri.d.ts.map
new file mode 100644
index 0000000..f00421a
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/url/IUri.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"IUri.d.ts","sourceRoot":"","sources":["../../src/url/IUri.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,MAAM,WAAW,IAAI;IACjB,QAAQ,EAAE,MAAM,CAAC;IACjB,eAAe,EAAE,MAAM,CAAC;IACxB,YAAY,EAAE,MAAM,CAAC;IACrB,MAAM,EAAE,MAAM,CAAC;IACf,IAAI,EAAE,MAAM,CAAC;IACb,YAAY,EAAE,MAAM,EAAE,CAAC;IACvB,WAAW,EAAE,MAAM,CAAC;CACvB"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/url/UrlString.d.ts b/node_modules/@azure/msal-common/dist/url/UrlString.d.ts
new file mode 100644
index 0000000..1dd4540
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/url/UrlString.d.ts
@@ -0,0 +1,58 @@
+import { ServerAuthorizationCodeResponse } from "../response/ServerAuthorizationCodeResponse";
+import { IUri } from "./IUri";
+/**
+ * Url object class which can perform various transformations on url strings.
+ */
+export declare class UrlString {
+ private _urlString;
+ get urlString(): string;
+ constructor(url: string);
+ /**
+ * Ensure urls are lower case and end with a / character.
+ * @param url
+ */
+ static canonicalizeUri(url: string): string;
+ /**
+ * Throws if urlString passed is not a valid authority URI string.
+ */
+ validateAsUri(): void;
+ /**
+ * Function to remove query string params from url. Returns the new url.
+ * @param url
+ * @param name
+ */
+ urlRemoveQueryStringParameter(name: string): string;
+ static removeHashFromUrl(url: string): string;
+ /**
+ * Given a url like https://a:b/common/d?e=f#g, and a tenantId, returns https://a:b/tenantId/d
+ * @param href The url
+ * @param tenantId The tenant id to replace
+ */
+ replaceTenantPath(tenantId: string): UrlString;
+ /**
+ * Returns the anchor part(#) of the URL
+ */
+ getHash(): string;
+ /**
+ * Parses out the components from a url string.
+ * @returns An object with the various components. Please cache this value insted of calling this multiple times on the same url.
+ */
+ getUrlComponents(): IUri;
+ static getDomainFromUrl(url: string): string;
+ static getAbsoluteUrl(relativeUrl: string, baseUrl: string): string;
+ /**
+ * Parses hash string from given string. Returns empty string if no hash symbol is found.
+ * @param hashString
+ */
+ static parseHash(hashString: string): string;
+ static constructAuthorityUriFromObject(urlObject: IUri): UrlString;
+ /**
+ * Returns URL hash as server auth code response object.
+ */
+ static getDeserializedHash(hash: string): ServerAuthorizationCodeResponse;
+ /**
+ * Check if the hash of the URL string contains known properties
+ */
+ static hashContainsKnownProperties(hash: string): boolean;
+}
+//# sourceMappingURL=UrlString.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/url/UrlString.d.ts.map b/node_modules/@azure/msal-common/dist/url/UrlString.d.ts.map
new file mode 100644
index 0000000..3963b5f
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/url/UrlString.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"UrlString.d.ts","sourceRoot":"","sources":["../../src/url/UrlString.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,+BAA+B,EAAE,MAAM,6CAA6C,CAAC;AAI9F,OAAO,EAAE,IAAI,EAAE,MAAM,QAAQ,CAAC;AAG9B;;GAEG;AACH,qBAAa,SAAS;IAGlB,OAAO,CAAC,UAAU,CAAS;IAC3B,IAAW,SAAS,IAAI,MAAM,CAE7B;gBAEW,GAAG,EAAE,MAAM;IAYvB;;;OAGG;IACH,MAAM,CAAC,eAAe,CAAC,GAAG,EAAE,MAAM,GAAG,MAAM;IAkB3C;;OAEG;IACH,aAAa,IAAI,IAAI;IAoBrB;;;;OAIG;IACH,6BAA6B,CAAC,IAAI,EAAE,MAAM,GAAG,MAAM;IAYnD,MAAM,CAAC,iBAAiB,CAAC,GAAG,EAAE,MAAM,GAAG,MAAM;IAI7C;;;;OAIG;IACH,iBAAiB,CAAC,QAAQ,EAAE,MAAM,GAAG,SAAS;IAS9C;;OAEG;IACH,OAAO,IAAI,MAAM;IAIjB;;;OAGG;IACH,gBAAgB,IAAI,IAAI;IA4BxB,MAAM,CAAC,gBAAgB,CAAC,GAAG,EAAE,MAAM,GAAG,MAAM;IAY5C,MAAM,CAAC,cAAc,CAAC,WAAW,EAAE,MAAM,EAAE,OAAO,EAAE,MAAM,GAAG,MAAM;IAWnE;;;OAGG;IACH,MAAM,CAAC,SAAS,CAAC,UAAU,EAAE,MAAM,GAAG,MAAM;IAW5C,MAAM,CAAC,+BAA+B,CAAC,SAAS,EAAE,IAAI,GAAG,SAAS;IAIlE;;OAEG;IACH,MAAM,CAAC,mBAAmB,CAAC,IAAI,EAAE,MAAM,GAAG,+BAA+B;IAgBzE;;OAEG;IACH,MAAM,CAAC,2BAA2B,CAAC,IAAI,EAAE,MAAM,GAAG,OAAO;CAa5D"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/Constants.d.ts b/node_modules/@azure/msal-common/dist/utils/Constants.d.ts
new file mode 100644
index 0000000..e78466a
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/Constants.d.ts
@@ -0,0 +1,276 @@
+export declare const Constants: {
+ LIBRARY_NAME: string;
+ SKU: string;
+ CACHE_PREFIX: string;
+ DEFAULT_AUTHORITY: string;
+ DEFAULT_AUTHORITY_HOST: string;
+ ADFS: string;
+ AAD_INSTANCE_DISCOVERY_ENDPT: string;
+ RESOURCE_DELIM: string;
+ NO_ACCOUNT: string;
+ CLAIMS: string;
+ CONSUMER_UTID: string;
+ OPENID_SCOPE: string;
+ PROFILE_SCOPE: string;
+ OFFLINE_ACCESS_SCOPE: string;
+ EMAIL_SCOPE: string;
+ CODE_RESPONSE_TYPE: string;
+ CODE_GRANT_TYPE: string;
+ RT_GRANT_TYPE: string;
+ FRAGMENT_RESPONSE_MODE: string;
+ S256_CODE_CHALLENGE_METHOD: string;
+ URL_FORM_CONTENT_TYPE: string;
+ AUTHORIZATION_PENDING: string;
+ NOT_DEFINED: string;
+ EMPTY_STRING: string;
+ FORWARD_SLASH: string;
+};
+export declare const OIDC_DEFAULT_SCOPES: string[];
+export declare const OIDC_SCOPES: string[];
+/**
+ * Request header names
+ */
+export declare enum HeaderNames {
+ CONTENT_TYPE = "Content-Type",
+ X_CLIENT_CURR_TELEM = "x-client-current-telemetry",
+ X_CLIENT_LAST_TELEM = "x-client-last-telemetry",
+ RETRY_AFTER = "Retry-After",
+ X_MS_LIB_CAPABILITY = "x-ms-lib-capability",
+ X_MS_LIB_CAPABILITY_VALUE = "retry-after, h429"
+}
+/**
+ * Persistent cache keys MSAL which stay while user is logged in.
+ */
+export declare enum PersistentCacheKeys {
+ ID_TOKEN = "idtoken",
+ CLIENT_INFO = "client.info",
+ ADAL_ID_TOKEN = "adal.idtoken",
+ ERROR = "error",
+ ERROR_DESC = "error.description"
+}
+/**
+ * String constants related to AAD Authority
+ */
+export declare enum AADAuthorityConstants {
+ COMMON = "common",
+ ORGANIZATIONS = "organizations",
+ CONSUMERS = "consumers"
+}
+/**
+ * Keys in the hashParams sent by AAD Server
+ */
+export declare enum AADServerParamKeys {
+ CLIENT_ID = "client_id",
+ REDIRECT_URI = "redirect_uri",
+ RESPONSE_TYPE = "response_type",
+ RESPONSE_MODE = "response_mode",
+ GRANT_TYPE = "grant_type",
+ CLAIMS = "claims",
+ SCOPE = "scope",
+ ERROR = "error",
+ ERROR_DESCRIPTION = "error_description",
+ ACCESS_TOKEN = "access_token",
+ ID_TOKEN = "id_token",
+ REFRESH_TOKEN = "refresh_token",
+ EXPIRES_IN = "expires_in",
+ STATE = "state",
+ NONCE = "nonce",
+ PROMPT = "prompt",
+ SESSION_STATE = "session_state",
+ CLIENT_INFO = "client_info",
+ CODE = "code",
+ CODE_CHALLENGE = "code_challenge",
+ CODE_CHALLENGE_METHOD = "code_challenge_method",
+ CODE_VERIFIER = "code_verifier",
+ CLIENT_REQUEST_ID = "client-request-id",
+ X_CLIENT_SKU = "x-client-SKU",
+ X_CLIENT_VER = "x-client-VER",
+ X_CLIENT_OS = "x-client-OS",
+ X_CLIENT_CPU = "x-client-CPU",
+ POST_LOGOUT_URI = "post_logout_redirect_uri",
+ ID_TOKEN_HINT = "id_token_hint",
+ DEVICE_CODE = "device_code",
+ CLIENT_SECRET = "client_secret",
+ CLIENT_ASSERTION = "client_assertion",
+ CLIENT_ASSERTION_TYPE = "client_assertion_type",
+ TOKEN_TYPE = "token_type",
+ REQ_CNF = "req_cnf",
+ OBO_ASSERTION = "assertion",
+ REQUESTED_TOKEN_USE = "requested_token_use",
+ ON_BEHALF_OF = "on_behalf_of",
+ FOCI = "foci"
+}
+/**
+ * Claims request keys
+ */
+export declare enum ClaimsRequestKeys {
+ ACCESS_TOKEN = "access_token",
+ XMS_CC = "xms_cc"
+}
+/**
+ * we considered making this "enum" in the request instead of string, however it looks like the allowed list of
+ * prompt values kept changing over past couple of years. There are some undocumented prompt values for some
+ * internal partners too, hence the choice of generic "string" type instead of the "enum"
+ */
+export declare const PromptValue: {
+ LOGIN: string;
+ SELECT_ACCOUNT: string;
+ CONSENT: string;
+ NONE: string;
+};
+/**
+ * SSO Types - generated to populate hints
+ */
+export declare enum SSOTypes {
+ ACCOUNT = "account",
+ SID = "sid",
+ LOGIN_HINT = "login_hint",
+ ID_TOKEN = "id_token",
+ DOMAIN_HINT = "domain_hint",
+ ORGANIZATIONS = "organizations",
+ CONSUMERS = "consumers",
+ ACCOUNT_ID = "accountIdentifier",
+ HOMEACCOUNT_ID = "homeAccountIdentifier"
+}
+/**
+ * Disallowed extra query parameters.
+ */
+export declare const BlacklistedEQParams: SSOTypes[];
+/**
+ * allowed values for codeVerifier
+ */
+export declare const CodeChallengeMethodValues: {
+ PLAIN: string;
+ S256: string;
+};
+/**
+ * The method used to encode the code verifier for the code challenge parameter. can be one
+ * of plain or s256. if excluded, code challenge is assumed to be plaintext. for more
+ * information, see the pkce rcf: https://tools.ietf.org/html/rfc7636
+ */
+export declare const CodeChallengeMethodValuesArray: string[];
+/**
+ * allowed values for response_mode
+ */
+export declare enum ResponseMode {
+ QUERY = "query",
+ FRAGMENT = "fragment",
+ FORM_POST = "form_post"
+}
+/**
+ * allowed grant_type
+ */
+export declare enum GrantType {
+ IMPLICIT_GRANT = "implicit",
+ AUTHORIZATION_CODE_GRANT = "authorization_code",
+ CLIENT_CREDENTIALS_GRANT = "client_credentials",
+ RESOURCE_OWNER_PASSWORD_GRANT = "password",
+ REFRESH_TOKEN_GRANT = "refresh_token",
+ DEVICE_CODE_GRANT = "device_code",
+ JWT_BEARER = "urn:ietf:params:oauth:grant-type:jwt-bearer"
+}
+/**
+ * Account types in Cache
+ */
+export declare enum CacheAccountType {
+ MSSTS_ACCOUNT_TYPE = "MSSTS",
+ ADFS_ACCOUNT_TYPE = "ADFS",
+ MSAV1_ACCOUNT_TYPE = "MSA",
+ GENERIC_ACCOUNT_TYPE = "Generic"
+}
+/**
+ * Separators used in cache
+ */
+export declare enum Separators {
+ CACHE_KEY_SEPARATOR = "-",
+ CLIENT_INFO_SEPARATOR = "."
+}
+/**
+ * Credential Type stored in the cache
+ */
+export declare enum CredentialType {
+ ID_TOKEN = "IdToken",
+ ACCESS_TOKEN = "AccessToken",
+ REFRESH_TOKEN = "RefreshToken"
+}
+/**
+ * Credential Type stored in the cache
+ */
+export declare enum CacheSchemaType {
+ ACCOUNT = "Account",
+ CREDENTIAL = "Credential",
+ ID_TOKEN = "IdToken",
+ ACCESS_TOKEN = "AccessToken",
+ REFRESH_TOKEN = "RefreshToken",
+ APP_METADATA = "AppMetadata",
+ TEMPORARY = "TempCache",
+ TELEMETRY = "Telemetry",
+ UNDEFINED = "Undefined",
+ THROTTLING = "Throttling"
+}
+/**
+ * Combine all cache types
+ */
+export declare enum CacheType {
+ ADFS = 1001,
+ MSA = 1002,
+ MSSTS = 1003,
+ GENERIC = 1004,
+ ACCESS_TOKEN = 2001,
+ REFRESH_TOKEN = 2002,
+ ID_TOKEN = 2003,
+ APP_METADATA = 3001,
+ UNDEFINED = 9999
+}
+/**
+ * More Cache related constants
+ */
+export declare const APP_METADATA = "appmetadata";
+export declare const ClientInfo = "client_info";
+export declare const THE_FAMILY_ID = "1";
+export declare const AUTHORITY_METADATA_CONSTANTS: {
+ CACHE_KEY: string;
+ REFRESH_TIME_SECONDS: number;
+};
+export declare enum AuthorityMetadataSource {
+ CONFIG = "config",
+ CACHE = "cache",
+ NETWORK = "network"
+}
+export declare const SERVER_TELEM_CONSTANTS: {
+ SCHEMA_VERSION: number;
+ MAX_HEADER_BYTES: number;
+ CACHE_KEY: string;
+ CATEGORY_SEPARATOR: string;
+ VALUE_SEPARATOR: string;
+ OVERFLOW_TRUE: string;
+ OVERFLOW_FALSE: string;
+ UNKNOWN_ERROR: string;
+};
+/**
+ * Type of the authentication request
+ */
+export declare enum AuthenticationScheme {
+ POP = "pop",
+ BEARER = "Bearer"
+}
+/**
+ * Constants related to throttling
+ */
+export declare const ThrottlingConstants: {
+ DEFAULT_THROTTLE_TIME_SECONDS: number;
+ DEFAULT_MAX_THROTTLE_TIME_SECONDS: number;
+ THROTTLING_PREFIX: string;
+};
+export declare const Errors: {
+ INVALID_GRANT_ERROR: string;
+ CLIENT_MISMATCH_ERROR: string;
+};
+/**
+ * Password grant parameters
+ */
+export declare enum PasswordGrantConstants {
+ username = "username",
+ password = "password"
+}
+//# sourceMappingURL=Constants.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/Constants.d.ts.map b/node_modules/@azure/msal-common/dist/utils/Constants.d.ts.map
new file mode 100644
index 0000000..4dde3d0
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/Constants.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"Constants.d.ts","sourceRoot":"","sources":["../../src/utils/Constants.ts"],"names":[],"mappings":"AAKA,eAAO,MAAM,SAAS;;;;;;;;;;;;;;;;;;;;;;;;;;CAoCrB,CAAC;AAEF,eAAO,MAAM,mBAAmB,UAI/B,CAAC;AAEF,eAAO,MAAM,WAAW,UAGvB,CAAC;AAEF;;GAEG;AACH,oBAAY,WAAW;IACnB,YAAY,iBAAiB;IAC7B,mBAAmB,+BAA+B;IAClD,mBAAmB,4BAA4B;IAC/C,WAAW,gBAAgB;IAC3B,mBAAmB,wBAAwB;IAC3C,yBAAyB,sBAAsB;CAClD;AAED;;GAEG;AACH,oBAAY,mBAAmB;IAC3B,QAAQ,YAAY;IACpB,WAAW,gBAAgB;IAC3B,aAAa,iBAAiB;IAC9B,KAAK,UAAU;IACf,UAAU,sBAAsB;CACnC;AAED;;GAEG;AACH,oBAAY,qBAAqB;IAC7B,MAAM,WAAW;IACjB,aAAa,kBAAkB;IAC/B,SAAS,cAAc;CAC1B;AAED;;GAEG;AACH,oBAAY,kBAAkB;IAC1B,SAAS,cAAc;IACvB,YAAY,iBAAiB;IAC7B,aAAa,kBAAkB;IAC/B,aAAa,kBAAkB;IAC/B,UAAU,eAAe;IACzB,MAAM,WAAW;IACjB,KAAK,UAAU;IACf,KAAK,UAAU;IACf,iBAAiB,sBAAsB;IACvC,YAAY,iBAAiB;IAC7B,QAAQ,aAAa;IACrB,aAAa,kBAAkB;IAC/B,UAAU,eAAe;IACzB,KAAK,UAAU;IACf,KAAK,UAAU;IACf,MAAM,WAAW;IACjB,aAAa,kBAAkB;IAC/B,WAAW,gBAAgB;IAC3B,IAAI,SAAS;IACb,cAAc,mBAAmB;IACjC,qBAAqB,0BAA0B;IAC/C,aAAa,kBAAkB;IAC/B,iBAAiB,sBAAsB;IACvC,YAAY,iBAAiB;IAC7B,YAAY,iBAAiB;IAC7B,WAAW,gBAAgB;IAC3B,YAAY,iBAAiB;IAC7B,eAAe,6BAA6B;IAC5C,aAAa,kBAAiB;IAC9B,WAAW,gBAAgB;IAC3B,aAAa,kBAAkB;IAC/B,gBAAgB,qBAAqB;IACrC,qBAAqB,0BAA0B;IAC/C,UAAU,eAAe;IACzB,OAAO,YAAY;IACnB,aAAa,cAAc;IAC3B,mBAAmB,wBAAwB;IAC3C,YAAY,iBAAiB;IAC7B,IAAI,SAAS;CAChB;AAED;;GAEG;AACH,oBAAY,iBAAiB;IACzB,YAAY,iBAAiB;IAC7B,MAAM,WAAW;CACpB;AAED;;;;GAIG;AACH,eAAO,MAAM,WAAW;;;;;CAKvB,CAAC;AAEF;;GAEG;AACH,oBAAY,QAAQ;IAChB,OAAO,YAAY;IACnB,GAAG,QAAQ;IACX,UAAU,eAAe;IACzB,QAAQ,aAAa;IACrB,WAAW,gBAAgB;IAC3B,aAAa,kBAAkB;IAC/B,SAAS,cAAc;IACvB,UAAU,sBAAsB;IAChC,cAAc,0BAA0B;CAC3C;AAED;;GAEG;AACH,eAAO,MAAM,mBAAmB,YAG/B,CAAC;AAEF;;GAEG;AACH,eAAO,MAAM,yBAAyB;;;CAGrC,CAAC;AAEF;;;;GAIG;AACH,eAAO,MAAM,8BAA8B,EAAE,MAAM,EAGlD,CAAC;AAEF;;GAEG;AACH,oBAAY,YAAY;IACpB,KAAK,UAAU;IACf,QAAQ,aAAa;IACrB,SAAS,cAAc;CAC1B;AAED;;GAEG;AACH,oBAAY,SAAS;IACjB,cAAc,aAAa;IAC3B,wBAAwB,uBAAuB;IAC/C,wBAAwB,uBAAuB;IAC/C,6BAA6B,aAAa;IAC1C,mBAAmB,kBAAkB;IACrC,iBAAiB,gBAAgB;IACjC,UAAU,gDAAgD;CAC7D;AAED;;GAEG;AACH,oBAAY,gBAAgB;IACxB,kBAAkB,UAAU;IAC5B,iBAAiB,SAAS;IAC1B,kBAAkB,QAAQ;IAC1B,oBAAoB,YAAY;CACnC;AAED;;GAEG;AACH,oBAAY,UAAU;IAClB,mBAAmB,MAAM;IACzB,qBAAqB,MAAM;CAC9B;AAED;;GAEG;AACH,oBAAY,cAAc;IACtB,QAAQ,YAAY;IACpB,YAAY,gBAAgB;IAC5B,aAAa,iBAAiB;CACjC;AAED;;GAEG;AACH,oBAAY,eAAe;IACvB,OAAO,YAAY;IACnB,UAAU,eAAe;IACzB,QAAQ,YAAY;IACpB,YAAY,gBAAgB;IAC5B,aAAa,iBAAiB;IAC9B,YAAY,gBAAgB;IAC5B,SAAS,cAAc;IACvB,SAAS,cAAc;IACvB,SAAS,cAAc;IACvB,UAAU,eAAe;CAC5B;AAED;;GAEG;AACH,oBAAY,SAAS;IACjB,IAAI,OAAO;IACX,GAAG,OAAO;IACV,KAAK,OAAO;IACZ,OAAO,OAAO;IACd,YAAY,OAAO;IACnB,aAAa,OAAO;IACpB,QAAQ,OAAO;IACf,YAAY,OAAO;IACnB,SAAS,OAAO;CACnB;AAED;;GAEG;AACH,eAAO,MAAM,YAAY,gBAAgB,CAAC;AAC1C,eAAO,MAAM,UAAU,gBAAgB,CAAC;AACxC,eAAO,MAAM,aAAa,MAAM,CAAC;AAEjC,eAAO,MAAM,4BAA4B;;;CAGxC,CAAC;AAEF,oBAAY,uBAAuB;IAC/B,MAAM,WAAW;IACjB,KAAK,UAAU;IACf,OAAO,YAAY;CACtB;AAED,eAAO,MAAM,sBAAsB;;;;;;;;;CASlC,CAAC;AAEF;;GAEG;AACH,oBAAY,oBAAoB;IAC5B,GAAG,QAAQ;IACX,MAAM,WAAW;CACpB;AAED;;GAEG;AACH,eAAO,MAAM,mBAAmB;;;;CAO/B,CAAC;AAEF,eAAO,MAAM,MAAM;;;CAGlB,CAAC;AAEF;;GAEG;AACH,oBAAY,sBAAsB;IAC9B,QAAQ,aAAa;IACrB,QAAQ,aAAa;CACxB"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/MsalTypes.d.ts b/node_modules/@azure/msal-common/dist/utils/MsalTypes.d.ts
new file mode 100644
index 0000000..2ddb947
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/MsalTypes.d.ts
@@ -0,0 +1,7 @@
+/**
+ * Key-Value type to support queryParams, extraQueryParams and claims
+ */
+export declare type StringDict = {
+ [key: string]: string;
+};
+//# sourceMappingURL=MsalTypes.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/MsalTypes.d.ts.map b/node_modules/@azure/msal-common/dist/utils/MsalTypes.d.ts.map
new file mode 100644
index 0000000..97d8451
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/MsalTypes.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"MsalTypes.d.ts","sourceRoot":"","sources":["../../src/utils/MsalTypes.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,oBAAY,UAAU,GAAG;IAAE,CAAC,GAAG,EAAE,MAAM,GAAG,MAAM,CAAA;CAAE,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/ProtocolUtils.d.ts b/node_modules/@azure/msal-common/dist/utils/ProtocolUtils.d.ts
new file mode 100644
index 0000000..4e637c6
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/ProtocolUtils.d.ts
@@ -0,0 +1,43 @@
+import { ICrypto } from "../crypto/ICrypto";
+/**
+ * Type which defines the object that is stringified, encoded and sent in the state value.
+ * Contains the following:
+ * - id - unique identifier for this request
+ * - ts - timestamp for the time the request was made. Used to ensure that token expiration is not calculated incorrectly.
+ * - platformState - string value sent from the platform.
+ */
+export declare type LibraryStateObject = {
+ id: string;
+ meta?: Record;
+};
+/**
+ * Type which defines the stringified and encoded object sent to the service in the authorize request.
+ */
+export declare type RequestStateObject = {
+ userRequestState: string;
+ libraryState: LibraryStateObject;
+};
+/**
+ * Class which provides helpers for OAuth 2.0 protocol specific values
+ */
+export declare class ProtocolUtils {
+ /**
+ * Appends user state with random guid, or returns random guid.
+ * @param userState
+ * @param randomGuid
+ */
+ static setRequestState(cryptoObj: ICrypto, userState?: string, meta?: Record): string;
+ /**
+ * Generates the state value used by the common library.
+ * @param randomGuid
+ * @param cryptoObj
+ */
+ static generateLibraryState(cryptoObj: ICrypto, meta?: Record): string;
+ /**
+ * Parses the state into the RequestStateObject, which contains the LibraryState info and the state passed by the user.
+ * @param state
+ * @param cryptoObj
+ */
+ static parseRequestState(cryptoObj: ICrypto, state: string): RequestStateObject;
+}
+//# sourceMappingURL=ProtocolUtils.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/ProtocolUtils.d.ts.map b/node_modules/@azure/msal-common/dist/utils/ProtocolUtils.d.ts.map
new file mode 100644
index 0000000..5175ad7
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/ProtocolUtils.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ProtocolUtils.d.ts","sourceRoot":"","sources":["../../src/utils/ProtocolUtils.ts"],"names":[],"mappings":"AAOA,OAAO,EAAE,OAAO,EAAE,MAAM,mBAAmB,CAAC;AAG5C;;;;;;GAMG;AACH,oBAAY,kBAAkB,GAAG;IAC7B,EAAE,EAAE,MAAM,CAAC;IACX,IAAI,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,CAAA;CAChC,CAAC;AAEF;;GAEG;AACH,oBAAY,kBAAkB,GAAG;IAC7B,gBAAgB,EAAE,MAAM,CAAC;IACzB,YAAY,EAAE,kBAAkB,CAAA;CACnC,CAAC;AAEF;;GAEG;AACH,qBAAa,aAAa;IAEtB;;;;OAIG;IACH,MAAM,CAAC,eAAe,CAAC,SAAS,EAAE,OAAO,EAAE,SAAS,CAAC,EAAE,MAAM,EAAE,IAAI,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,GAAG,MAAM;IAKrG;;;;OAIG;IACH,MAAM,CAAC,oBAAoB,CAAC,SAAS,EAAE,OAAO,EAAE,IAAI,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,GAAG,MAAM;IAmBtF;;;;OAIG;IACH,MAAM,CAAC,iBAAiB,CAAC,SAAS,EAAE,OAAO,EAAE,KAAK,EAAE,MAAM,GAAG,kBAAkB;CAwBlF"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/StringUtils.d.ts b/node_modules/@azure/msal-common/dist/utils/StringUtils.d.ts
new file mode 100644
index 0000000..c1eca50
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/StringUtils.d.ts
@@ -0,0 +1,49 @@
+import { DecodedAuthToken } from "../account/DecodedAuthToken";
+/**
+ * @hidden
+ */
+export declare class StringUtils {
+ /**
+ * decode a JWT
+ *
+ * @param authToken
+ */
+ static decodeAuthToken(authToken: string): DecodedAuthToken;
+ /**
+ * Check if a string is empty.
+ *
+ * @param str
+ */
+ static isEmpty(str?: string): boolean;
+ static startsWith(str: string, search: string): boolean;
+ static endsWith(str: string, search: string): boolean;
+ /**
+ * Parses string into an object.
+ *
+ * @param query
+ */
+ static queryStringToObject(query: string): T;
+ /**
+ * Trims entries in an array.
+ *
+ * @param arr
+ */
+ static trimArrayEntries(arr: Array): Array;
+ /**
+ * Removes empty strings from array
+ * @param arr
+ */
+ static removeEmptyStringsFromArray(arr: Array): Array;
+ /**
+ * Attempts to parse a string into JSON
+ * @param str
+ */
+ static jsonParseHelper(str: string): T | null;
+ /**
+ * Tests if a given string matches a given pattern, with support for wildcards.
+ * @param pattern Wildcard pattern to string match. Supports "*" for wildcards
+ * @param input String to match against
+ */
+ static matchPattern(pattern: string, input: string): boolean;
+}
+//# sourceMappingURL=StringUtils.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/StringUtils.d.ts.map b/node_modules/@azure/msal-common/dist/utils/StringUtils.d.ts.map
new file mode 100644
index 0000000..887cc95
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/StringUtils.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"StringUtils.d.ts","sourceRoot":"","sources":["../../src/utils/StringUtils.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,gBAAgB,EAAE,MAAM,6BAA6B,CAAC;AAG/D;;GAEG;AACH,qBAAa,WAAW;IAEpB;;;;OAIG;IACH,MAAM,CAAC,eAAe,CAAC,SAAS,EAAE,MAAM,GAAG,gBAAgB;IAiB3D;;;;OAIG;IACH,MAAM,CAAC,OAAO,CAAC,GAAG,CAAC,EAAE,MAAM,GAAG,OAAO;IAIrC,MAAM,CAAC,UAAU,CAAC,GAAG,EAAE,MAAM,EAAE,MAAM,EAAE,MAAM,GAAG,OAAO;IAIvD,MAAM,CAAC,QAAQ,CAAC,GAAG,EAAE,MAAM,EAAE,MAAM,EAAE,MAAM,GAAG,OAAO;IAIrD;;;;OAIG;IACH,MAAM,CAAC,mBAAmB,CAAC,CAAC,EAAE,KAAK,EAAE,MAAM,GAAG,CAAC;IAc/C;;;;OAIG;IACH,MAAM,CAAC,gBAAgB,CAAC,GAAG,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,KAAK,CAAC,MAAM,CAAC;IAI1D;;;OAGG;IACH,MAAM,CAAC,2BAA2B,CAAC,GAAG,EAAE,KAAK,CAAC,MAAM,CAAC,GAAG,KAAK,CAAC,MAAM,CAAC;IAMrE;;;OAGG;IACH,MAAM,CAAC,eAAe,CAAC,CAAC,EAAE,GAAG,EAAE,MAAM,GAAG,CAAC,GAAG,IAAI;IAQhD;;;;OAIG;IACH,MAAM,CAAC,YAAY,CAAC,OAAO,EAAE,MAAM,EAAE,KAAK,EAAE,MAAM,GAAG,OAAO;CAM/D"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/TimeUtils.d.ts b/node_modules/@azure/msal-common/dist/utils/TimeUtils.d.ts
new file mode 100644
index 0000000..fc6ea1b
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/TimeUtils.d.ts
@@ -0,0 +1,15 @@
+/**
+ * Utility class which exposes functions for managing date and time operations.
+ */
+export declare class TimeUtils {
+ /**
+ * return the current time in Unix time (seconds).
+ */
+ static nowSeconds(): number;
+ /**
+ * check if a token is expired based on given UTC time in seconds.
+ * @param expiresOn
+ */
+ static isTokenExpired(expiresOn: string, offset: number): boolean;
+}
+//# sourceMappingURL=TimeUtils.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/dist/utils/TimeUtils.d.ts.map b/node_modules/@azure/msal-common/dist/utils/TimeUtils.d.ts.map
new file mode 100644
index 0000000..f0bfbb5
--- /dev/null
+++ b/node_modules/@azure/msal-common/dist/utils/TimeUtils.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"TimeUtils.d.ts","sourceRoot":"","sources":["../../src/utils/TimeUtils.ts"],"names":[],"mappings":"AAKA;;GAEG;AACH,qBAAa,SAAS;IAElB;;OAEG;IACH,MAAM,CAAC,UAAU,IAAI,MAAM;IAK3B;;;OAGG;IACH,MAAM,CAAC,cAAc,CAAC,SAAS,EAAE,MAAM,EAAE,MAAM,EAAE,MAAM,GAAG,OAAO;CAQpE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-common/package.json b/node_modules/@azure/msal-common/package.json
new file mode 100644
index 0000000..542cc9b
--- /dev/null
+++ b/node_modules/@azure/msal-common/package.json
@@ -0,0 +1,91 @@
+{
+ "name": "@azure/msal-common",
+ "author": {
+ "name": "Microsoft",
+ "email": "nugetaad@microsoft.com",
+ "url": "https://www.microsoft.com"
+ },
+ "license": "MIT",
+ "repository": {
+ "type": "git",
+ "url": "https://github.com/AzureAD/microsoft-authentication-library-for-js.git"
+ },
+ "version": "4.0.1",
+ "description": "Microsoft Authentication Library for js",
+ "keywords": [
+ "implicit",
+ "authorization code",
+ "PKCE",
+ "js",
+ "AAD",
+ "msal",
+ "oauth"
+ ],
+ "main": "./dist/index.js",
+ "module": "./dist/index.es.js",
+ "types": "./dist/index.d.ts",
+ "browserslist": [
+ "last 1 version",
+ "> 1%",
+ "maintained node versions",
+ "not dead"
+ ],
+ "engines": {
+ "node": ">=0.8.0"
+ },
+ "directories": {
+ "test": "test"
+ },
+ "files": [
+ "dist"
+ ],
+ "scripts": {
+ "clean": "shx rm -rf dist lib",
+ "clean:coverage": "rimraf ../../.nyc_output/*",
+ "lint": "cd ../../ && npm run lint:common",
+ "lint:fix": "npm run lint -- -- --fix",
+ "test": "mocha",
+ "test:coverage": "nyc mocha",
+ "test:coverage:only": "npm run clean:coverage && npm run test:coverage",
+ "build:modules": "rollup -c",
+ "build:modules:watch": "rollup -cw",
+ "build": "npm run clean && npm run build:modules",
+ "build:all": "npm run build",
+ "prepack": "npm run build"
+ },
+ "devDependencies": {
+ "@babel/core": "^7.7.2",
+ "@babel/plugin-proposal-class-properties": "^7.7.0",
+ "@babel/plugin-proposal-object-rest-spread": "^7.6.2",
+ "@babel/polyfill": "^7.7.0",
+ "@babel/preset-env": "^7.7.1",
+ "@babel/preset-typescript": "^7.7.2",
+ "@babel/register": "^7.7.0",
+ "@istanbuljs/nyc-config-babel": "^2.1.1",
+ "@rollup/plugin-json": "^4.0.0",
+ "@types/chai": "^4.2.5",
+ "@types/chai-as-promised": "^7.1.2",
+ "@types/debug": "^4.1.5",
+ "@types/mocha": "^5.2.7",
+ "@types/sinon": "^7.5.0",
+ "babel-plugin-istanbul": "^5.2.0",
+ "beachball": "^1.32.2",
+ "chai": "^4.2.0",
+ "chai-as-promised": "^7.1.1",
+ "husky": "^3.0.9",
+ "mocha": "^6.2.2",
+ "nyc": "^15.0.0",
+ "rimraf": "^3.0.2",
+ "rollup": "^1.24.0",
+ "rollup-plugin-terser": "^7.0.2",
+ "rollup-plugin-typescript2": "^0.29.0",
+ "shx": "^0.3.2",
+ "sinon": "^7.5.0",
+ "tslib": "^1.10.0",
+ "tslint": "^5.20.0",
+ "typescript": "^3.7.5"
+ },
+ "dependencies": {
+ "debug": "^4.1.1"
+ }
+}
diff --git a/node_modules/@azure/msal-node/CHANGELOG.json b/node_modules/@azure/msal-node/CHANGELOG.json
new file mode 100644
index 0000000..cf58c96
--- /dev/null
+++ b/node_modules/@azure/msal-node/CHANGELOG.json
@@ -0,0 +1,576 @@
+{
+ "name": "@azure/msal-node",
+ "entries": [
+ {
+ "date": "Thu, 18 Feb 2021 00:34:32 GMT",
+ "tag": "@azure/msal-node_v1.0.0",
+ "version": "1.0.0",
+ "comments": {
+ "patch": [
+ {
+ "comment": "update msal-node landing page & samples page",
+ "author": "dogan.erisen@gmail.com",
+ "commit": "c6de840d684291617012cfe444bc5759645076ea",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "prerelease": [
+ {
+ "comment": "ADD FAQs (#3038)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "20f94c3970fb14c7508aa7b61ba80e1639c50605",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Update node version support in package.json(#2998)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "09f9a00784c40b3d2ca8a60ceef7fcefe47dd215",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 09 Feb 2021 01:48:22 GMT",
+ "tag": "@azure/msal-node_v1.0.0-beta.6",
+ "version": "1.0.0-beta.6",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Fix version.json import errors (#2993)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "6dc3bc9e2148bc53b181d9f079f6e11e0159620b",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Ignore OIDC scopes during cache lookup or replacement (#2969)",
+ "author": "prkanher@microsoft.com",
+ "commit": "b113b562ffc33ad44b8d98417753db397256aadf",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Set the validateStatus locally than globally for `axios` (#2959)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "55617cb8bc5289c29fd4357a16605b6720195cbc",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Add API Extractor for msal-node",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "01747296efdf08eefe585930097d9bbbf6b00789",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 02 Feb 2021 01:56:47 GMT",
+ "tag": "@azure/msal-node_v1.0.0-beta.5",
+ "version": "1.0.0-beta.5",
+ "comments": {
+ "none": [
+ {
+ "comment": "Typedocs Updates (#2926)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "3fd4a48143ed4fb62b9e3266338b1abda920d68a",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Add project references (#2930)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "a836e77e372f1b4da28195d4ad8c0c75d6794875",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Test updates (#2949)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "cbdd4cd8ba23b5794aeb1f0788b828f1248f7236",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "prerelease": [
+ {
+ "comment": "Get package version from version.json (#2915)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "a6f4702f9439e318a8cb6dc65d1def16351a84fd",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Add interfaces to public APIs in msal-node (#2623)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "baa4aa037f90209006eb3fb1ba1263fd09690343",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 21 Jan 2021 21:48:01 GMT",
+ "tag": "@azure/msal-node_v1.0.0-beta.4",
+ "version": "1.0.0-beta.4",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Authority metadata caching (#2758)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "28b3268b1385e99249c0b7a95b0b14299011ca46",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 12 Jan 2021 00:51:26 GMT",
+ "tag": "@azure/msal-node_v1.0.0-beta.3",
+ "version": "1.0.0-beta.3",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "ClientAssertion.parseCertificate - allow newlines in cert (#2721).",
+ "author": "email not defined",
+ "commit": "199c99ef23aeb013f8dcec94e3210332fbc42ed0",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "feat: bump up the axios version on msal-node",
+ "author": "samuel.kamau@microsoft.com",
+ "commit": "0d8e60f38340cb7b9a49dc3e0be28503105b5857",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Add getKVStore to tokenCache (#2771)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "bb8ef90bcd20f111b903214c10429c1d507eafcf",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "none": [
+ {
+ "comment": "package-lock changes",
+ "author": "prkanher@microsoft.com",
+ "commit": "c092667cd997935625eafbc491ede54417d4b657",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "package.lock change",
+ "author": "samuel.kamau@microsoft.com",
+ "commit": "4e50ca592f5a17578072be9e4ac28e05b3e6d594",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Fix npm audit warnings",
+ "author": "janutter@microsoft.com",
+ "commit": "751026cdaa24dd370c50ad714bf0b1d54c71fbde",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "patch": [
+ {
+ "comment": "change the code challenge encoding to uniform base64",
+ "author": "samuel.kamau@microsoft.com",
+ "commit": "c0cce3b6f6199bf0db5d77a07c557c8cdb4e383c",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Mon, 07 Dec 2020 22:19:03 GMT",
+ "tag": "@azure/msal-node_v1.0.0-beta.2",
+ "version": "1.0.0-beta.2",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Expose idTokenClaims on AccountInfo (#2554)",
+ "author": "janutter@microsoft.com",
+ "commit": "cb2165aad7995d904ec49ade565d907dc314ce16",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Add null to API response signatures (#2602)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "ebf18c6daead16f8cfd2afb3b63cbd59fc63046a",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Enforce triple equals in eslint",
+ "author": "janutter@microsoft.com",
+ "commit": "5975eb4077a2b4372683e68af4d748b0808134ab",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Log messages contain package name and version (#2589)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "4568c16bd425e242cdb799ec59b3508654cc2e45",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Update request types (#2512)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "5b891222d674eb5664af9187f319a61b50341f55",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 11 Nov 2020 23:33:20 GMT",
+ "tag": "@azure/msal-node_v1.0.0-beta.1",
+ "version": "1.0.0-beta.1",
+ "comments": {
+ "none": [
+ {
+ "comment": "Documentation update for new account retrieval APIs (#2585)",
+ "author": "hemoral@microsoft.com",
+ "commit": "cb782967cc8f07581488de71c4509fa12a702774",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "prerelease": [
+ {
+ "comment": "Add support for SubjectName/Issuer authentication (#2471).",
+ "author": "jamckenn@microsoft.com",
+ "commit": "4e889b3f8e28b8fd46c0e63d0f142fb61b442510",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 10 Nov 2020 01:48:44 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.16",
+ "version": "1.0.0-alpha.16",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Enhance lookup for IdTokens/AppMetadata (#2530)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "e51446295f8c857f1abc7f6874a4c7fde157699e",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Sat, 07 Nov 2020 01:50:14 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.15",
+ "version": "1.0.0-alpha.15",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Fixing a bug and adding `localAccountId` in AccountInfo interface (#2516)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "98f43038608fe66a256dabfff0810476e9e6b3ab",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Filtered lookup of IdTokens, AppMetadata; Error handling in Node Storage (#2530)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "354dd86449d792b7369fb240c5e2cfd70ca73488",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Implement Password Grant Flow (#2204)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "baf6d157e7bbeae439526aee13eb08962974925b",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Build Pipeline Changes (#2406)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "af8459c0d53a4dc2bf495017608c0bb03004d006",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Mon, 02 Nov 2020 23:33:39 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.14",
+ "version": "1.0.0-alpha.14",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Add getLogger and setLogger to msal-node (#2520)",
+ "author": "joarroyo@microsoft.com",
+ "commit": "6fff8c1ed4d3dab2a74ff4b44a159645a6c2f535",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Remove `debug` from the `msal-node` library (#2496)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "e354c26ae74632943109fb9101319acf6c6a691c",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Mon, 26 Oct 2020 21:00:29 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.13",
+ "version": "1.0.0-alpha.13",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "msal-browser and msal-node cache Interfaces to msal-common updated (#2415)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "9d4c4a18de10eb3d918810dc10766fbd5547165d",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Export Node Cache Serializer for use in end-to-end testing framework (#2414)",
+ "author": "hemoral@microsoft.com",
+ "commit": "ba3fad77b2f6ea5034c423aa44096c5698cbcb3d",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Update samples path",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "971ff811cb00a3d97b8ceff32999cd80d3d5a7ac",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 20 Oct 2020 23:47:28 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.12",
+ "version": "1.0.0-alpha.12",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Adds support for any OIDC-compliant authority (#2389).",
+ "author": "jamckenn@microsoft.com",
+ "commit": "2b6b9ec9033a8b829393e44c3feb7b19b163d2cd",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Updated eslint rules (#2345)",
+ "author": "janutter@microsoft.com",
+ "commit": "64a4f9e868e63346dfd711dec717abe7fd14d949",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 15 Oct 2020 00:49:18 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.11",
+ "version": "1.0.0-alpha.11",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Export all \"Request\" types in msal-node",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "145602c7ced2c9f77a249f0abdca76f3358bd7db",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 14 Oct 2020 23:45:07 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.10",
+ "version": "1.0.0-alpha.10",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Docs update for msal-node release",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "20718209d5d567c02223a7f1b220b4aa40ad6817",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Export error types for msal-node",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "7a493ee25d80a31cbfa21f04aa952a9ac3528dfb",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Add uuid as dependency in msal-node package.json so it is installed with the library",
+ "author": "hectormgdev@gmail.com",
+ "commit": "cedeefacc09b755fc2edf59440ef7c60c4b872f8",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Update TokenCache interface (#2348)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "26723689e35918c59bd6ce58ba8cb886118676c6",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Fri, 02 Oct 2020 17:42:35 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.9",
+ "version": "1.0.0-alpha.9",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Dummy implementation of access token proof-of-possession",
+ "author": "prkanher@microsoft.com",
+ "commit": "3cffbc99730532bbd0b35f2e3a9df17f032c0675",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 30 Sep 2020 17:58:33 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.8",
+ "version": "1.0.0-alpha.8",
+ "comments": {
+ "none": [
+ {
+ "comment": "Updating the pre-release version(#2342)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "bc3f324edd6cf83937c31f73d3aefc6dbaf5f748",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Update changelog versions for msal-node and extensions (#2336)",
+ "author": "hemoral@microsoft.com",
+ "commit": "323875a725e0d5049ff6742a9ca5160c2d4b7d0d",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Wed, 23 Sep 2020 21:13:48 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.7",
+ "version": "1.0.0-alpha.7",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "Make network interface public (#2335)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "aecc41e9f23b350a25bba9dd23e739627e61f8ab",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Rename TokenCache.cacheHasChanged to TokenCache.hasChanged (#2332)",
+ "author": "sagonzal@microsoft.com",
+ "commit": "536a335dd405c5ce070461a302d9a6ed24067b2b",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "FOCI - Family of Client IDs feature (#2201)",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "209789cdffdfd38087819cbb23688bcd5ce47b60",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Fix issue with token cache not removing old cache entities (#2304)",
+ "author": "sagonzal@microsoft.com",
+ "commit": "efd00413c32c6c4ac36eaeaaf8b9de33c4839484",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 17 Sep 2020 23:16:22 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.6",
+ "version": "1.0.0-alpha.6",
+ "comments": {
+ "none": [
+ {
+ "comment": "Update msal node to use central eslint configuration",
+ "author": "janutter@microsoft.com",
+ "commit": "fc49c6f16b3f7a62a67d249107fc484272133305",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "prerelease": [
+ {
+ "comment": "Address tsdx warnings (#2202)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "d147c4053cced20f0b1964f01dba02b3eba644cd",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Implement Telemetry in msal-node (#1921)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "1872900d149b60436ef59fd41ab542c58c32e8f1",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Changes node storage: getItem(), setItem() and removeItem() simplified and no longer need a 'type'",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "9760b6ff6c0ad403ac1b26968cb10d3d7e72a6fd",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Add support for on-behalf-of flow",
+ "author": "sagonzal@microsoft.com",
+ "commit": "53c018c8ea0d1877c12641fc1a749e6d66e7ff78",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Tue, 25 Aug 2020 00:40:45 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.5",
+ "version": "1.0.0-alpha.5",
+ "comments": {
+ "prerelease": [
+ {
+ "comment": "update APP_META_DATA to APP_METADATA",
+ "author": "sameera.gajjarapu@microsoft.com",
+ "commit": "282035aecb07956dca323d65275fdaa703c4a325",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Client Capabilities Support (#2169)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "0cdad1b8a3855b2414be9740862df29524897a22",
+ "package": "@azure/msal-node"
+ },
+ {
+ "comment": "Remove log statement",
+ "author": "email not defined",
+ "commit": "9e2836306bd6efd16cfd9c825ea4797ffddb0936",
+ "package": "@azure/msal-node"
+ },
+ {
+ "author": "sagonzal@microsoft.com",
+ "commit": "98647b7a8a40e1a5f7855f0bcee4594e080a8398",
+ "package": "@azure/msal-node"
+ }
+ ],
+ "none": [
+ {
+ "comment": "Update tests (#2128)",
+ "author": "thomas.norling@microsoft.com",
+ "commit": "c9b65c59797cd3240aad2b4f1e0e866a90373c4a",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ },
+ {
+ "date": "Thu, 13 Aug 2020 02:20:48 GMT",
+ "tag": "@azure/msal-node_v1.0.0-alpha.4",
+ "version": "1.0.0-alpha.4",
+ "comments": {
+ "none": [
+ {
+ "comment": "updating files for automated release steps",
+ "author": "prkanher@microsoft.com",
+ "commit": "2c937a52cef36cbc84231f8868b4251529fa38c9",
+ "package": "@azure/msal-node"
+ }
+ ]
+ }
+ }
+ ]
+}
diff --git a/node_modules/@azure/msal-node/LICENSE b/node_modules/@azure/msal-node/LICENSE
new file mode 100644
index 0000000..d6602cf
--- /dev/null
+++ b/node_modules/@azure/msal-node/LICENSE
@@ -0,0 +1,21 @@
+MIT License
+
+Copyright (c) 2020 Microsoft
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in all
+copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+SOFTWARE.
diff --git a/node_modules/@azure/msal-node/README.md b/node_modules/@azure/msal-node/README.md
new file mode 100644
index 0000000..23c3079
--- /dev/null
+++ b/node_modules/@azure/msal-node/README.md
@@ -0,0 +1,178 @@
+# Microsoft Authentication Library for Node (msal-node)
+
+[![npm version](https://img.shields.io/npm/v/@azure/msal-node.svg?style=flat)](https://www.npmjs.com/package/@azure/msal-node/)[![npm version](https://img.shields.io/npm/dm/@azure/msal-node.svg)](https://nodei.co/npm/@azure/msal-node/)[![Coverage Status](https://coveralls.io/repos/github/AzureAD/microsoft-authentication-library-for-js/badge.svg?branch=dev)](https://coveralls.io/github/AzureAD/microsoft-authentication-library-for-js?branch=dev)
+
+| Getting Started | AAD Docs | Library Reference |
+| --- | --- | --- |
+
+1. [About](#about)
+2. [FAQ](#faq)
+3. [Releases](#releases)
+4. [Prerequisites](#prerequisites)
+5. [Installation](#installation)
+6. [Node Version Support](#node-version-support)
+7. [Usage](#usage)
+8. [Samples](#samples)
+9. [Build Library](#build-and-test)
+10. [Security Reporting](#security-reporting)
+11. [License](#license)
+12. [Code of Conduct](#we-value-and-adhere-to-the-microsoft-open-source-code-of-conduct)
+
+## About
+
+MSAL Node enables applications to authenticate users using [Azure AD](https://docs.microsoft.com/azure/active-directory/develop/v2-overview) work and school accounts (AAD), Microsoft personal accounts (MSA) and social identity providers like Facebook, Google, LinkedIn, Microsoft accounts, etc. through [Azure AD B2C](https://docs.microsoft.com/azure/active-directory-b2c/active-directory-b2c-overview#identity-providers) service. It also enables your app to get tokens to access [Microsoft Cloud](https://www.microsoft.com/enterprise) services such as [Microsoft Graph](https://graph.microsoft.io).
+
+### OAuth2.0 grant types supported:
+
+The current version supports the following ways of acquiring tokens:
+
+#### Public Client:
+- [Authorization Code Grant](https://oauth.net/2/grant-types/authorization-code/) with [PKCE](https://oauth.net/2/pkce/)
+- [Device Code Grant](https://oauth.net/2/grant-types/device-code/)
+- [Refresh Token Grant](https://oauth.net/2/grant-types/refresh-token/)
+- [Silent Flow](https://docs.microsoft.com/azure/active-directory/develop/msal-acquire-cache-tokens#acquiring-tokens-silently-from-the-cache)
+- [Username and Password flow](https://docs.microsoft.com/azure/active-directory/develop/msal-authentication-flows#usernamepassword)
+
+#### Confidential Client:
+- [Authorization Code Grant](https://oauth.net/2/grant-types/authorization-code/) with a client credential
+- [Refresh Token Grant](https://oauth.net/2/grant-types/refresh-token/)
+- [Silent Flow](https://docs.microsoft.com/azure/active-directory/develop/msal-acquire-cache-tokens#acquiring-tokens-silently-from-the-cache)
+- [Client Credential Grant](https://oauth.net/2/grant-types/client-credentials/)
+- [On-behalf-of flow](https://docs.microsoft.com/azure/active-directory/develop/v2-oauth2-on-behalf-of-flow)
+- [Username and Password flow](https://docs.microsoft.com/azure/active-directory/develop/msal-authentication-flows#usernamepassword)
+
+**[Coming Soon]** In the future we plan to add support for:
+- [Integrated Windows Authentication flow](https://docs.microsoft.com/azure/active-directory/develop/msal-authentication-flows#integrated-windows-authentication)
+
+More details on different grant types supported by Microsoft authentication libraries in general can be found [here](https://docs.microsoft.com/azure/active-directory/develop/msal-authentication-flows).
+
+### Scenarios supported:
+
+The scenarios supported with this library are:
+- Desktop app that calls web APIs
+- Web app that calls web APIs
+- Web APIs that call web APIs
+- Daemon apps
+
+More details on scenarios and the authentication flows that map to each of them can be found [here](https://docs.microsoft.com/azure/active-directory/develop/authentication-flows-app-scenarios).
+
+## FAQ
+
+See [here](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-node/docs/faq.md).
+
+## Prerequisites
+
+Before using `@azure/msal-node` you will need to register your app in the azure portal:
+
+- [App registration](https://docs.microsoft.com/graph/auth-register-app-v2)
+
+## Installation
+
+### Via NPM:
+```javascript
+npm install @azure/msal-node
+```
+## Node Version Support
+MSAL Node will follow the [Long Term Support (LTS) schedule of the Node.js project](https://nodejs.org/about/releases/). Our support plan is as follows.
+
+Any major MSAL Node release:
+- Will support stable (even-numbered) Maintenance LTS, Active LTS, and Current versions of Node
+- Will drop support for any previously supported Node versions that have reached end of life
+- Will not support prerelease/preview/pending versions until they are stable
+
+| MSAL Node version | MSAL support status | Supported Node versions |
+|-------------------|-------------------------|-------------------------|
+| 1.x.x | Active development | 10, 12, 14 |
+
+
+## Usage
+
+### MSAL basics
+- [Understand difference in between Public Client and Confidential Clients](https://docs.microsoft.com/azure/active-directory/develop/msal-client-applications)
+- [Initialize a Public Client Application](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-node/docs/initialize-public-client-application.md)
+- [Initialize a Confidential Client Application](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-node/docs/initialize-confidential-client-application.md)
+- [Configuration](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-node/docs/configuration.md)
+- [Request](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-common/docs/request.md)
+- [Response](https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-common/docs/Response.md)
+
+## Samples
+There are multiple [samples](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples) included in the repository that use MSAL Node to acquire tokens. These samples are currently used for manual testing, and are not meant to be a reference of best practices, therefore use judgement and do not blindly copy this code to any production applications.
+
+AAD samples:
+
+- [auth-code](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/auth-code): Express app using OAuth2.0 authorization code flow.
+- [auth-code-pkce](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/auth-code-pkce): Express app using OAuth2.0 authorization code flow with PKCE.
+- [device-code](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/device-code): Command line app using OAuth 2.0 device code flow.
+- [refresh-token](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/refresh-token): Command line app using OAuth 2.0 refresh flow.
+- [silent-flow](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/silent-flow): Express app using OAuth2.0 authorization code flow to acquire a token and store in the token cache, and silent flow to use tokens in the token cache.
+- [client-credentials](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/client-credentials): Daemon app using OAuth 2.0 client credential grant to acquire a token.
+- [on-behalf-of](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/on-behalf-of): Web application using OAuth 2.0 auth code flow to acquire a token for a web API. The web API validates the token, and calls Microsoft Graph on behalf of the user who authenticated in the web application.
+- [username-password](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/username-password): Web application using OAuth 2.0 resource owner password credentials (ROPC) flow to acquire a token for a web API.
+- [ElectronTestApp](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/ElectronTestApp): Electron desktop application using OAuth 2.0 auth code with PKCE flow to acquire a token for a web API such as Microsoft Graph.
+
+B2C samples:
+
+- [b2c-auth-code](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/b2c-auth-code): Express app using OAuth2.0 authorization code flow.
+- [b2c-auth-code-pkce](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/b2c-auth-code-pkce): Express app using OAuth2.0 authorization code flow with PKCE.
+- [b2c-silent-flow](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/samples/msal-node-samples/standalone-samples/b2c-silent-flow): Express app using OAuth2.0 authorization code flow to acquire a token and store in the token cache, and silent flow to use tokens in the token cache.
+
+Others:
+
+- [msal-node-extensions](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/extensions/samples/msal-node-extensions): Uses authorization code flow to acquire tokens and the [msal-extensions](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/extensions/) library to write the MSAL in-memory token cache to disk.
+
+## Build and Test
+
+- If you don't have [lerna](https://github.com/lerna/lerna) installed, run `npm install -g lerna`
+- Run `lerna bootstrap` from anywhere within `microsoft-authentication-library-for-js.git`.
+- Navigate to `microsoft-authentication-library-for-js/lib/msal-common` and run `npm run build`
+- Navigate to `microsoft-authentication-library-for-js/lib/msal-node` and run `npm run build`
+
+```javascript
+// to link msal-node and msal-common packages
+lerna bootstrap
+
+// Change to the msal-node package directory
+cd lib/msal-common/
+
+// To run build only for node package
+npm run build
+
+// Change to the msal-node package directory
+cd lib/msal-node/
+
+// To run build only for node package
+npm run build
+```
+
+### Local Development
+Below is a list of commands you will probably find useful:
+
+#### `npm run build:modules:watch`
+Runs the project in development/watch mode. Your project will be rebuilt upon changes. TSDX has a special logger for you convenience. Error messages are pretty printed and formatted for compatibility VS Code's Problems tab. The library will be rebuilt if you make edits.
+
+#### `npm run build`
+Bundles the package to the `dist` folder.
+The package is optimized and bundled with Rollup into multiple formats (CommonJS, UMD, and ES Module).
+
+#### `lerna bootstrap`
+If you are running the project in development/watch mode, or have made changes in `msal-common` and need them reflecting across the project, please run `lerna bootstrap` to link all the symbols. Please note that `npm install` will unlink all the code, hence it is advised to run `lerna bootstrap` post installation.
+
+#### `npm run lint`
+Runs eslint with Prettier
+
+#### `npm test`, `npm run test:coverage`, `npm run test:watch`
+Runs the test watcher (Jest) in an interactive mode.
+By default, runs tests related to files changed since the last commit.
+Generate code coverage by adding the flag --coverage. No additional setup needed. Jest can collect code coverage information from entire projects, including untested files.
+
+## Security Reporting
+
+If you find a security issue with our libraries or services please report it to [secure@microsoft.com](mailto:secure@microsoft.com) with as much detail as possible. Your submission may be eligible for a bounty through the [Microsoft Bounty](http://aka.ms/bugbounty) program. Please do not post security issues to GitHub Issues or any other public site. We will contact you shortly upon receiving the information. We encourage you to get notifications of when security incidents occur by visiting [this page](https://technet.microsoft.com/security/dd252948) and subscribing to Security Advisory Alerts.
+
+## License
+
+Copyright (c) Microsoft Corporation. All rights reserved. Licensed under the MIT License.
+
+## We Value and Adhere to the Microsoft Open Source Code of Conduct
+
+This project has adopted the [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/). For more information see the [Code of Conduct FAQ](https://opensource.microsoft.com/codeofconduct/faq/) or contact [opencode@microsoft.com](mailto:opencode@microsoft.com) with any additional questions or comments.
diff --git a/node_modules/@azure/msal-node/changelog.md b/node_modules/@azure/msal-node/changelog.md
new file mode 100644
index 0000000..3908336
--- /dev/null
+++ b/node_modules/@azure/msal-node/changelog.md
@@ -0,0 +1,225 @@
+# Change Log - @azure/msal-node
+
+This log was last generated on Thu, 18 Feb 2021 00:34:32 GMT and should not be manually modified.
+
+
+
+## 1.0.0
+
+Thu, 18 Feb 2021 00:34:32 GMT
+
+### Patches
+
+- update msal-node landing page & samples page (dogan.erisen@gmail.com)
+
+### Changes
+
+- ADD FAQs (#3038) (sameera.gajjarapu@microsoft.com)
+- Update node version support in package.json(#2998) (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-beta.6
+
+Tue, 09 Feb 2021 01:48:22 GMT
+
+### Changes
+
+- Fix version.json import errors (#2993) (thomas.norling@microsoft.com)
+- Ignore OIDC scopes during cache lookup or replacement (#2969) (prkanher@microsoft.com)
+- Set the validateStatus locally than globally for `axios` (#2959) (sameera.gajjarapu@microsoft.com)
+- Add API Extractor for msal-node (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-beta.5
+
+Tue, 02 Feb 2021 01:56:47 GMT
+
+### Changes
+
+- Get package version from version.json (#2915) (thomas.norling@microsoft.com)
+- Add interfaces to public APIs in msal-node (#2623) (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-beta.4
+
+Thu, 21 Jan 2021 21:48:01 GMT
+
+### Changes
+
+- Authority metadata caching (#2758) (thomas.norling@microsoft.com)
+
+## 1.0.0-beta.3
+
+Tue, 12 Jan 2021 00:51:26 GMT
+
+### Patches
+
+- change the code challenge encoding to uniform base64 (samuel.kamau@microsoft.com)
+
+### Changes
+
+- ClientAssertion.parseCertificate - allow newlines in cert (#2721). (email not defined)
+- feat: bump up the axios version on msal-node (samuel.kamau@microsoft.com)
+- Add getKVStore to tokenCache (#2771) (thomas.norling@microsoft.com)
+
+## 1.0.0-beta.2
+
+Mon, 07 Dec 2020 22:19:03 GMT
+
+### Changes
+
+- Expose idTokenClaims on AccountInfo (#2554) (janutter@microsoft.com)
+- Add null to API response signatures (#2602) (thomas.norling@microsoft.com)
+- Enforce triple equals in eslint (janutter@microsoft.com)
+- Log messages contain package name and version (#2589) (thomas.norling@microsoft.com)
+- Update request types (#2512) (thomas.norling@microsoft.com)
+
+## 1.0.0-beta.1
+
+Wed, 11 Nov 2020 23:33:20 GMT
+
+### Changes
+
+- Add support for SubjectName/Issuer authentication (#2471). (jamckenn@microsoft.com)
+
+## 1.0.0-alpha.16
+
+Tue, 10 Nov 2020 01:48:44 GMT
+
+### Changes
+
+- Enhance lookup for IdTokens/AppMetadata (#2530) (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-alpha.15
+
+Sat, 07 Nov 2020 01:50:14 GMT
+
+### Changes
+
+- Fixing a bug and adding `localAccountId` in AccountInfo interface (#2516) (sameera.gajjarapu@microsoft.com)
+- Filtered lookup of IdTokens, AppMetadata; Error handling in Node Storage (#2530) (sameera.gajjarapu@microsoft.com)
+- Implement Password Grant Flow (#2204) (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-alpha.14
+
+Mon, 02 Nov 2020 23:33:39 GMT
+
+### Changes
+
+- Add getLogger and setLogger to msal-node (#2520) (joarroyo@microsoft.com)
+- Remove `debug` from the `msal-node` library (#2496) (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-alpha.13
+
+Mon, 26 Oct 2020 21:00:29 GMT
+
+### Changes
+
+- msal-browser and msal-node cache Interfaces to msal-common updated (#2415) (sameera.gajjarapu@microsoft.com)
+- Export Node Cache Serializer for use in end-to-end testing framework (#2414) (hemoral@microsoft.com)
+
+## 1.0.0-alpha.12
+
+Tue, 20 Oct 2020 23:47:28 GMT
+
+### Changes
+
+- Adds support for any OIDC-compliant authority (#2389). (jamckenn@microsoft.com)
+
+## 1.0.0-alpha.11
+
+Thu, 15 Oct 2020 00:49:18 GMT
+
+### Changes
+
+- Export all "Request" types in msal-node (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-alpha.10
+
+Wed, 14 Oct 2020 23:45:07 GMT
+
+### Changes
+
+- Docs update for msal-node release (sameera.gajjarapu@microsoft.com)
+- Export error types for msal-node (sameera.gajjarapu@microsoft.com)
+- Add uuid as dependency in msal-node package.json so it is installed with the library (hectormgdev@gmail.com)
+- Update TokenCache interface (#2348) (sameera.gajjarapu@microsoft.com)
+
+## 1.0.0-alpha.9
+
+Fri, 02 Oct 2020 17:42:35 GMT
+
+### Changes
+
+- Dummy implementation of access token proof-of-possession (prkanher@microsoft.com)
+
+## 1.0.0-alpha.7
+
+Wed, 23 Sep 2020 21:13:48 GMT
+
+### Changes
+- Make network interface public (#2335) (sameera.gajjarapu@microsoft.com)
+- Rename TokenCache.cacheHasChanged to TokenCache.hasChanged (#2332) (sagonzal@microsoft.com)
+- FOCI - Family of Client IDs feature (#2201) (sameera.gajjarapu@microsoft.com)
+- Fix issue with token cache not removing old cache entities (#2304) (sagonzal@microsoft.com)
+
+## 1.0.0-alpha.6
+
+Thu, 17 Sep 2020 23:16:22 GMT
+
+### Changes
+
+- Address tsdx warnings (#2202) (thomas.norling@microsoft.com)
+- Implement Telemetry in msal-node (#1921) (thomas.norling@microsoft.com)
+- Changes node storage: getItem(), setItem() and removeItem() simplified and no longer need a 'type' (sameera.gajjarapu@microsoft.com)
+- Add support for on-behalf-of flow (sagonzal@microsoft.com)
+
+## 1.0.0-alpha.5
+
+Tue, 25 Aug 2020 00:40:45 GMT
+
+### Changes
+
+- update APP_META_DATA to APP_METADATA (sameera.gajjarapu@microsoft.com)
+- Client Capabilities Support (#2169) (thomas.norling@microsoft.com)
+- Remove log statement (email not defined)
+- undefined (sagonzal@microsoft.com)
+
+# 1.0.0-alpha.4
+- Add confidential client support (#2023)
+
+# 1.0.0-alpha.3
+- Fix an issue where the types were not defined correctly in the package.json (#2014)
+
+# 1.0.0-alpha.2
+- Fix an issue where the `dist` folder was not published (#2013)
+
+# 1.0.0-alpha.1
+
+- Add `response` to device code in `msal-node` (#1947)
+- `msal-node` docs update (#1948)
+- Export `AccountInfo` in `msal-node (#2005)
+
+# 1.0.0-alpha.0
+
+- scaffolding (#1328)
+- Configuration and Client (#1325)
+- Account and Authority (#1330)
+- initial compatibility with other libs (#1342)
+- `msal-node` crypto module (#1368)
+- `msal-node` network module (#1371)
+- `msal-node` lerna support (#1383)
+- `msal-common` and `msal-node` Client applications, authorization code and device code flow (#1409)
+- `msal-node` add DEBUG logging (#1423)
+- `msal-common` authority changes (#1424)
+- `msal-node` and `msal-common` unit tests for changes in #1409 (#1449)
+- `msal-node` switch `strictNullChecks:true` for msal-node (#1478)
+- `msal-node` and `msal-common` Update generation of client info headers (#1482)
+- `msal-node` and `msal-common` Support for acquiring a token with refresh token (#1496)
+- `msal-node` and `msal-common` Move authority generation from common to node (#1537)
+- `msal-node` fix casing issue (#1630)
+- `msal-node` Cache implementation (#1444, #1471, #1519, #1520, #1522, #1622, #1655, #1680)
+- `msal-node` Silent Flow support (#1711)
+- merge cache logic for all platforms (#1762)
+- Utilize ScopeSet across the library (#1770)
+- Update UnifiedCacheManager.ts (#1771)
+- Node cache interface (#1801)
+- SilentFlow node interface (#1809)
+- Update TokenCache name (#1901)
diff --git a/node_modules/@azure/msal-node/dist/cache/ITokenCache.d.ts b/node_modules/@azure/msal-node/dist/cache/ITokenCache.d.ts
new file mode 100644
index 0000000..5410de6
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/ITokenCache.d.ts
@@ -0,0 +1,16 @@
+import { AccountInfo } from "@azure/msal-common";
+/**
+ * Token cache interface for the client, giving access to cache APIs
+ * @public
+ */
+export interface ITokenCache {
+ /** API that retrieves all accounts currently in cache to the user */
+ getAllAccounts(): Promise;
+ /** Returns the signed in account matching homeAccountId */
+ getAccountByHomeId(homeAccountId: string): Promise;
+ /** Returns the signed in account matching localAccountId */
+ getAccountByLocalId(localAccountId: string): Promise;
+ /** API to remove a specific account and the relevant data from cache */
+ removeAccount(account: AccountInfo): Promise;
+}
+//# sourceMappingURL=ITokenCache.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/ITokenCache.d.ts.map b/node_modules/@azure/msal-node/dist/cache/ITokenCache.d.ts.map
new file mode 100644
index 0000000..59da601
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/ITokenCache.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ITokenCache.d.ts","sourceRoot":"","sources":["../src/cache/ITokenCache.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,WAAW,EAAE,MAAM,oBAAoB,CAAC;AAEjD;;;GAGG;AACH,MAAM,WAAW,WAAW;IAExB,qEAAqE;IACrE,cAAc,IAAI,OAAO,CAAC,WAAW,EAAE,CAAC,CAAC;IAEzC,2DAA2D;IAC3D,kBAAkB,CAAC,aAAa,EAAE,MAAM,GAAG,OAAO,CAAC,WAAW,GAAG,IAAI,CAAC,CAAC;IAEvE,4DAA4D;IAC5D,mBAAmB,CAAC,cAAc,EAAE,MAAM,GAAG,OAAO,CAAC,WAAW,GAAG,IAAI,CAAC,CAAC;IAEzE,wEAAwE;IACxE,aAAa,CAAC,OAAO,EAAE,WAAW,GAAG,OAAO,CAAC,IAAI,CAAC,CAAC;CACtD"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/NodeStorage.d.ts b/node_modules/@azure/msal-node/dist/cache/NodeStorage.d.ts
new file mode 100644
index 0000000..19769dd
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/NodeStorage.d.ts
@@ -0,0 +1,177 @@
+import { AccountEntity, IdTokenEntity, AccessTokenEntity, RefreshTokenEntity, AppMetadataEntity, ServerTelemetryEntity, ThrottlingEntity, CacheManager, Logger, ValidCacheType, ICrypto, AuthorityMetadataEntity } from "@azure/msal-common";
+import { InMemoryCache, JsonCache, CacheKVStore } from "./serializer/SerializerTypes";
+/**
+ * This class implements Storage for node, reading cache from user specified storage location or an extension library
+ * @public
+ */
+export declare class NodeStorage extends CacheManager {
+ private logger;
+ private cache;
+ private changeEmitters;
+ constructor(logger: Logger, clientId: string, cryptoImpl: ICrypto);
+ /**
+ * Queue up callbacks
+ * @param func - a callback function for cache change indication
+ */
+ registerChangeEmitter(func: () => void): void;
+ /**
+ * Invoke the callback when cache changes
+ */
+ emitChange(): void;
+ /**
+ * Converts cacheKVStore to InMemoryCache
+ * @param cache - key value store
+ */
+ cacheToInMemoryCache(cache: CacheKVStore): InMemoryCache;
+ /**
+ * converts inMemoryCache to CacheKVStore
+ * @param inMemoryCache - kvstore map for inmemory
+ */
+ inMemoryCacheToCache(inMemoryCache: InMemoryCache): CacheKVStore;
+ /**
+ * gets the current in memory cache for the client
+ */
+ getInMemoryCache(): InMemoryCache;
+ /**
+ * sets the current in memory cache for the client
+ * @param inMemoryCache - key value map in memory
+ */
+ setInMemoryCache(inMemoryCache: InMemoryCache): void;
+ /**
+ * get the current cache key-value store
+ */
+ getCache(): CacheKVStore;
+ /**
+ * sets the current cache (key value store)
+ * @param cacheMap - key value map
+ */
+ setCache(cache: CacheKVStore): void;
+ /**
+ * Gets cache item with given key.
+ * @param key - lookup key for the cache entry
+ */
+ getItem(key: string): ValidCacheType;
+ /**
+ * Gets cache item with given key-value
+ * @param key - lookup key for the cache entry
+ * @param value - value of the cache entry
+ */
+ setItem(key: string, value: ValidCacheType): void;
+ /**
+ * fetch the account entity
+ * @param accountKey - lookup key to fetch cache type AccountEntity
+ */
+ getAccount(accountKey: string): AccountEntity | null;
+ /**
+ * set account entity
+ * @param account - cache value to be set of type AccountEntity
+ */
+ setAccount(account: AccountEntity): void;
+ /**
+ * fetch the idToken credential
+ * @param idTokenKey - lookup key to fetch cache type IdTokenEntity
+ */
+ getIdTokenCredential(idTokenKey: string): IdTokenEntity | null;
+ /**
+ * set idToken credential
+ * @param idToken - cache value to be set of type IdTokenEntity
+ */
+ setIdTokenCredential(idToken: IdTokenEntity): void;
+ /**
+ * fetch the accessToken credential
+ * @param accessTokenKey - lookup key to fetch cache type AccessTokenEntity
+ */
+ getAccessTokenCredential(accessTokenKey: string): AccessTokenEntity | null;
+ /**
+ * set accessToken credential
+ * @param accessToken - cache value to be set of type AccessTokenEntity
+ */
+ setAccessTokenCredential(accessToken: AccessTokenEntity): void;
+ /**
+ * fetch the refreshToken credential
+ * @param refreshTokenKey - lookup key to fetch cache type RefreshTokenEntity
+ */
+ getRefreshTokenCredential(refreshTokenKey: string): RefreshTokenEntity | null;
+ /**
+ * set refreshToken credential
+ * @param refreshToken - cache value to be set of type RefreshTokenEntity
+ */
+ setRefreshTokenCredential(refreshToken: RefreshTokenEntity): void;
+ /**
+ * fetch appMetadata entity from the platform cache
+ * @param appMetadataKey - lookup key to fetch cache type AppMetadataEntity
+ */
+ getAppMetadata(appMetadataKey: string): AppMetadataEntity | null;
+ /**
+ * set appMetadata entity to the platform cache
+ * @param appMetadata - cache value to be set of type AppMetadataEntity
+ */
+ setAppMetadata(appMetadata: AppMetadataEntity): void;
+ /**
+ * fetch server telemetry entity from the platform cache
+ * @param serverTelemetrykey - lookup key to fetch cache type ServerTelemetryEntity
+ */
+ getServerTelemetry(serverTelemetrykey: string): ServerTelemetryEntity | null;
+ /**
+ * set server telemetry entity to the platform cache
+ * @param serverTelemetryKey - lookup key to fetch cache type ServerTelemetryEntity
+ * @param serverTelemetry - cache value to be set of type ServerTelemetryEntity
+ */
+ setServerTelemetry(serverTelemetryKey: string, serverTelemetry: ServerTelemetryEntity): void;
+ /**
+ * fetch authority metadata entity from the platform cache
+ * @param key - lookup key to fetch cache type AuthorityMetadataEntity
+ */
+ getAuthorityMetadata(key: string): AuthorityMetadataEntity | null;
+ /**
+ * Get all authority metadata keys
+ */
+ getAuthorityMetadataKeys(): Array;
+ /**
+ * set authority metadata entity to the platform cache
+ * @param key - lookup key to fetch cache type AuthorityMetadataEntity
+ * @param metadata - cache value to be set of type AuthorityMetadataEntity
+ */
+ setAuthorityMetadata(key: string, metadata: AuthorityMetadataEntity): void;
+ /**
+ * fetch throttling entity from the platform cache
+ * @param throttlingCacheKey - lookup key to fetch cache type ThrottlingEntity
+ */
+ getThrottlingCache(throttlingCacheKey: string): ThrottlingEntity | null;
+ /**
+ * set throttling entity to the platform cache
+ * @param throttlingCacheKey - lookup key to fetch cache type ThrottlingEntity
+ * @param throttlingCache - cache value to be set of type ThrottlingEntity
+ */
+ setThrottlingCache(throttlingCacheKey: string, throttlingCache: ThrottlingEntity): void;
+ /**
+ * Removes the cache item from memory with the given key.
+ * @param key - lookup key to remove a cache entity
+ * @param inMemory - key value map of the cache
+ */
+ removeItem(key: string): boolean;
+ /**
+ * Checks whether key is in cache.
+ * @param key - look up key for a cache entity
+ */
+ containsKey(key: string): boolean;
+ /**
+ * Gets all keys in window.
+ */
+ getKeys(): string[];
+ /**
+ * Clears all cache entries created by MSAL (except tokens).
+ */
+ clear(): void;
+ /**
+ * Initialize in memory cache from an exisiting cache vault
+ * @param cache - blob formatted cache (JSON)
+ */
+ static generateInMemoryCache(cache: string): InMemoryCache;
+ /**
+ * retrieves the final JSON
+ * @param inMemoryCache - itemised cache read from the JSON
+ */
+ static generateJsonCache(inMemoryCache: InMemoryCache): JsonCache;
+}
+//# sourceMappingURL=NodeStorage.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/NodeStorage.d.ts.map b/node_modules/@azure/msal-node/dist/cache/NodeStorage.d.ts.map
new file mode 100644
index 0000000..9737349
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/NodeStorage.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"NodeStorage.d.ts","sourceRoot":"","sources":["../src/cache/NodeStorage.ts"],"names":[],"mappings":"AAKA,OAAO,EACH,aAAa,EACb,aAAa,EACb,iBAAiB,EACjB,kBAAkB,EAClB,iBAAiB,EACjB,qBAAqB,EACrB,gBAAgB,EAChB,YAAY,EACZ,MAAM,EACN,cAAc,EACd,OAAO,EACP,uBAAuB,EAC1B,MAAM,oBAAoB,CAAC;AAG5B,OAAO,EAAE,aAAa,EAAE,SAAS,EAAE,YAAY,EAAE,MAAM,8BAA8B,CAAC;AAEtF;;;GAGG;AACH,qBAAa,WAAY,SAAQ,YAAY;IAEzC,OAAO,CAAC,MAAM,CAAS;IACvB,OAAO,CAAC,KAAK,CAAoB;IACjC,OAAO,CAAC,cAAc,CAAuB;gBAEjC,MAAM,EAAE,MAAM,EAAE,QAAQ,EAAE,MAAM,EAAE,UAAU,EAAE,OAAO;IAKjE;;;OAGG;IACH,qBAAqB,CAAC,IAAI,EAAE,MAAM,IAAI,GAAG,IAAI;IAI7C;;OAEG;IACH,UAAU,IAAI,IAAI;IAIlB;;;OAGG;IACH,oBAAoB,CAAC,KAAK,EAAE,YAAY,GAAG,aAAa;IA6BxD;;;OAGG;IACH,oBAAoB,CAAC,aAAa,EAAE,aAAa,GAAG,YAAY;IAchE;;OAEG;IACH,gBAAgB,IAAI,aAAa;IAQjC;;;OAGG;IACH,gBAAgB,CAAC,aAAa,EAAE,aAAa,GAAG,IAAI;IAUpD;;OAEG;IACH,QAAQ,IAAI,YAAY;IAKxB;;;OAGG;IACH,QAAQ,CAAC,KAAK,EAAE,YAAY,GAAG,IAAI;IAQnC;;;OAGG;IACH,OAAO,CAAC,GAAG,EAAE,MAAM,GAAG,cAAc;IAQpC;;;;OAIG;IACH,OAAO,CAAC,GAAG,EAAE,MAAM,EAAE,KAAK,EAAE,cAAc,GAAG,IAAI;IAWjD;;;OAGG;IACH,UAAU,CAAC,UAAU,EAAE,MAAM,GAAG,aAAa,GAAG,IAAI;IAQpD;;;OAGG;IACH,UAAU,CAAC,OAAO,EAAE,aAAa,GAAG,IAAI;IAKxC;;;OAGG;IACH,oBAAoB,CAAC,UAAU,EAAE,MAAM,GAAG,aAAa,GAAG,IAAI;IAQ9D;;;OAGG;IACH,oBAAoB,CAAC,OAAO,EAAE,aAAa,GAAG,IAAI;IAKlD;;;OAGG;IACH,wBAAwB,CAAC,cAAc,EAAE,MAAM,GAAG,iBAAiB,GAAG,IAAI;IAQ1E;;;OAGG;IACH,wBAAwB,CAAC,WAAW,EAAE,iBAAiB,GAAG,IAAI;IAK9D;;;OAGG;IACH,yBAAyB,CAAC,eAAe,EAAE,MAAM,GAAG,kBAAkB,GAAG,IAAI;IAQ7E;;;OAGG;IACH,yBAAyB,CAAC,YAAY,EAAE,kBAAkB,GAAG,IAAI;IAKjE;;;OAGG;IACH,cAAc,CAAC,cAAc,EAAE,MAAM,GAAG,iBAAiB,GAAG,IAAI;IAQhE;;;OAGG;IACH,cAAc,CAAC,WAAW,EAAE,iBAAiB,GAAG,IAAI;IAKpD;;;OAGG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,GAAG,qBAAqB,GAAG,IAAI;IAQ5E;;;;OAIG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,EAAE,eAAe,EAAE,qBAAqB,GAAG,IAAI;IAI5F;;;OAGG;IACH,oBAAoB,CAAC,GAAG,EAAE,MAAM,GAAG,uBAAuB,GAAG,IAAI;IAQjE;;OAEG;IACH,wBAAwB,IAAI,KAAK,CAAC,MAAM,CAAC;IAMzC;;;;OAIG;IACH,oBAAoB,CAAC,GAAG,EAAE,MAAM,EAAE,QAAQ,EAAE,uBAAuB,GAAG,IAAI;IAI1E;;;OAGG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,GAAG,gBAAgB,GAAG,IAAI;IAQvE;;;;OAIG;IACH,kBAAkB,CAAC,kBAAkB,EAAE,MAAM,EAAE,eAAe,EAAE,gBAAgB,GAAG,IAAI;IAIvF;;;;OAIG;IACH,UAAU,CAAC,GAAG,EAAE,MAAM,GAAG,OAAO;IAoBhC;;;OAGG;IACH,WAAW,CAAC,GAAG,EAAE,MAAM,GAAG,OAAO;IAIjC;;OAEG;IACH,OAAO,IAAI,MAAM,EAAE;IAQnB;;OAEG;IACH,KAAK,IAAI,IAAI;IAab;;;OAGG;IACH,MAAM,CAAC,qBAAqB,CAAC,KAAK,EAAE,MAAM,GAAG,aAAa;IAM1D;;;OAGG;IACH,MAAM,CAAC,iBAAiB,CAAC,aAAa,EAAE,aAAa,GAAG,SAAS;CAGpE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/TokenCache.d.ts b/node_modules/@azure/msal-node/dist/cache/TokenCache.d.ts
new file mode 100644
index 0000000..31ec902
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/TokenCache.d.ts
@@ -0,0 +1,91 @@
+import { NodeStorage } from "./NodeStorage";
+import { AccountInfo, Logger, ISerializableTokenCache, ICachePlugin } from "@azure/msal-common";
+import { CacheKVStore } from "./serializer/SerializerTypes";
+import { ITokenCache } from "./ITokenCache";
+/**
+ * In-memory token cache manager
+ * @public
+ */
+export declare class TokenCache implements ISerializableTokenCache, ITokenCache {
+ private storage;
+ private cacheHasChanged;
+ private cacheSnapshot;
+ private readonly persistence;
+ private logger;
+ constructor(storage: NodeStorage, logger: Logger, cachePlugin?: ICachePlugin);
+ /**
+ * Set to true if cache state has changed since last time serialize or writeToPersistence was called
+ */
+ hasChanged(): boolean;
+ /**
+ * Serializes in memory cache to JSON
+ */
+ serialize(): string;
+ /**
+ * Deserializes JSON to in-memory cache. JSON should be in MSAL cache schema format
+ * @param cache - blob formatted cache
+ */
+ deserialize(cache: string): void;
+ /**
+ * Fetches the cache key-value map
+ */
+ getKVStore(): CacheKVStore;
+ /**
+ * API that retrieves all accounts currently in cache to the user
+ */
+ getAllAccounts(): Promise;
+ /**
+ * Returns the signed in account matching homeAccountId.
+ * (the account object is created at the time of successful login)
+ * or null when no matching account is found
+ * @param homeAccountId - unique identifier for an account (uid.utid)
+ */
+ getAccountByHomeId(homeAccountId: string): Promise;
+ /**
+ * Returns the signed in account matching localAccountId.
+ * (the account object is created at the time of successful login)
+ * or null when no matching account is found
+ * @param localAccountId - unique identifier of an account (sub/obj when homeAccountId cannot be populated)
+ */
+ getAccountByLocalId(localAccountId: string): Promise;
+ /**
+ * API to remove a specific account and the relevant data from cache
+ * @param account - AccountInfo passed by the user
+ */
+ removeAccount(account: AccountInfo): Promise;
+ /**
+ * Called when the cache has changed state.
+ */
+ private handleChangeEvent;
+ /**
+ * Merge in memory cache with the cache snapshot.
+ * @param oldState - cache before changes
+ * @param currentState - current cache state in the library
+ */
+ private mergeState;
+ /**
+ * Deep update of oldState based on newState values
+ * @param oldState - cache before changes
+ * @param newState - updated cache
+ */
+ private mergeUpdates;
+ /**
+ * Removes entities in oldState that the were removed from newState. If there are any unknown values in root of
+ * oldState that are not recognized, they are left untouched.
+ * @param oldState - cache before changes
+ * @param newState - updated cache
+ */
+ private mergeRemovals;
+ /**
+ * Helper to merge new cache with the old one
+ * @param oldState - cache before changes
+ * @param newState - updated cache
+ */
+ private mergeRemovalsDict;
+ /**
+ * Helper to overlay as a part of cache merge
+ * @param passedInCache - cache read from the blob
+ */
+ private overlayDefaults;
+}
+//# sourceMappingURL=TokenCache.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/TokenCache.d.ts.map b/node_modules/@azure/msal-node/dist/cache/TokenCache.d.ts.map
new file mode 100644
index 0000000..59085f1
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/TokenCache.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"TokenCache.d.ts","sourceRoot":"","sources":["../src/cache/TokenCache.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,WAAW,EAAE,MAAM,eAAe,CAAC;AAC5C,OAAO,EAA8B,WAAW,EAAE,MAAM,EAAE,uBAAuB,EAAE,YAAY,EAAqB,MAAM,oBAAoB,CAAC;AAC/I,OAAO,EAAsK,YAAY,EAAE,MAAM,8BAA8B,CAAC;AAGhO,OAAO,EAAE,WAAW,EAAE,MAAM,eAAe,CAAC;AAU5C;;;GAGG;AACH,qBAAa,UAAW,YAAW,uBAAuB,EAAE,WAAW;IAEnE,OAAO,CAAC,OAAO,CAAc;IAC7B,OAAO,CAAC,eAAe,CAAU;IACjC,OAAO,CAAC,aAAa,CAAS;IAC9B,OAAO,CAAC,QAAQ,CAAC,WAAW,CAAe;IAC3C,OAAO,CAAC,MAAM,CAAS;gBAEX,OAAO,EAAE,WAAW,EAAE,MAAM,EAAE,MAAM,EAAE,WAAW,CAAC,EAAE,YAAY;IAU5E;;OAEG;IACH,UAAU,IAAI,OAAO;IAIrB;;OAEG;IACH,SAAS,IAAI,MAAM;IAqBnB;;;OAGG;IACH,WAAW,CAAC,KAAK,EAAE,MAAM,GAAG,IAAI;IAehC;;OAEG;IACH,UAAU,IAAI,YAAY;IAI1B;;OAEG;IACG,cAAc,IAAI,OAAO,CAAC,WAAW,EAAE,CAAC;IAiB9C;;;;;OAKG;IACG,kBAAkB,CAAC,aAAa,EAAE,MAAM,GAAG,OAAO,CAAC,WAAW,GAAG,IAAI,CAAC;IAS5E;;;;;OAKG;IACG,mBAAmB,CAAC,cAAc,EAAE,MAAM,GAAG,OAAO,CAAC,WAAW,GAAG,IAAI,CAAC;IAS9E;;;OAGG;IACG,aAAa,CAAC,OAAO,EAAE,WAAW,GAAG,OAAO,CAAC,IAAI,CAAC;IAgBxD;;OAEG;IACH,OAAO,CAAC,iBAAiB;IAIzB;;;;OAIG;IACH,OAAO,CAAC,UAAU;IAMlB;;;;OAIG;IACH,OAAO,CAAC,YAAY;IA2BpB;;;;;OAKG;IACH,OAAO,CAAC,aAAa;IAkBrB;;;;OAIG;IACH,OAAO,CAAC,iBAAiB;IAUzB;;;OAGG;IACH,OAAO,CAAC,eAAe;CAyB1B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/serializer/Deserializer.d.ts b/node_modules/@azure/msal-node/dist/cache/serializer/Deserializer.d.ts
new file mode 100644
index 0000000..1e52f69
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/serializer/Deserializer.d.ts
@@ -0,0 +1,43 @@
+import { AccountCache, IdTokenCache, AccessTokenCache, RefreshTokenCache, AppMetadataCache } from "@azure/msal-common";
+import { JsonCache, InMemoryCache, SerializedAccountEntity, SerializedIdTokenEntity, SerializedAccessTokenEntity, SerializedRefreshTokenEntity, SerializedAppMetadataEntity } from "./SerializerTypes";
+/**
+ * This class deserializes cache entities read from the file into in memory object types defined internally
+ */
+export declare class Deserializer {
+ /**
+ * Parse the JSON blob in memory and deserialize the content
+ * @param cachedJson
+ */
+ static deserializeJSONBlob(jsonFile: string): JsonCache;
+ /**
+ * Deserializes accounts to AccountEntity objects
+ * @param accounts
+ */
+ static deserializeAccounts(accounts: Record): AccountCache;
+ /**
+ * Deserializes id tokens to IdTokenEntity objects
+ * @param idTokens
+ */
+ static deserializeIdTokens(idTokens: Record): IdTokenCache;
+ /**
+ * Deserializes access tokens to AccessTokenEntity objects
+ * @param accessTokens
+ */
+ static deserializeAccessTokens(accessTokens: Record): AccessTokenCache;
+ /**
+ * Deserializes refresh tokens to RefreshTokenEntity objects
+ * @param refreshTokens
+ */
+ static deserializeRefreshTokens(refreshTokens: Record): RefreshTokenCache;
+ /**
+ * Deserializes appMetadata to AppMetaData objects
+ * @param appMetadata
+ */
+ static deserializeAppMetadata(appMetadata: Record): AppMetadataCache;
+ /**
+ * Deserialize an inMemory Cache
+ * @param jsonCache
+ */
+ static deserializeAllCache(jsonCache: JsonCache): InMemoryCache;
+}
+//# sourceMappingURL=Deserializer.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/serializer/Deserializer.d.ts.map b/node_modules/@azure/msal-node/dist/cache/serializer/Deserializer.d.ts.map
new file mode 100644
index 0000000..9974505
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/serializer/Deserializer.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"Deserializer.d.ts","sourceRoot":"","sources":["../../src/cache/serializer/Deserializer.ts"],"names":[],"mappings":"AAKA,OAAO,EAAe,YAAY,EAAE,YAAY,EAAE,gBAAgB,EAAE,iBAAiB,EAAE,gBAAgB,EAAwG,MAAM,oBAAoB,CAAC;AAC1O,OAAO,EAAE,SAAS,EAAE,aAAa,EAAE,uBAAuB,EAAE,uBAAuB,EAAE,2BAA2B,EAAE,4BAA4B,EAAE,2BAA2B,EAAE,MAAM,mBAAmB,CAAC;AAEvM;;GAEG;AACH,qBAAa,YAAY;IACrB;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,QAAQ,EAAE,MAAM,GAAG,SAAS;IAOvD;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,QAAQ,EAAE,MAAM,CAAC,MAAM,EAAE,uBAAuB,CAAC,GAAG,YAAY;IA0B3F;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,QAAQ,EAAE,MAAM,CAAC,MAAM,EAAE,uBAAuB,CAAC,GAAG,YAAY;IAqB3F;;;OAGG;IACH,MAAM,CAAC,uBAAuB,CAAC,YAAY,EAAE,MAAM,CAAC,MAAM,EAAE,2BAA2B,CAAC,GAAG,gBAAgB;IA6B3G;;;OAGG;IACH,MAAM,CAAC,wBAAwB,CAAC,aAAa,EAAE,MAAM,CAAC,MAAM,EAAE,4BAA4B,CAAC,GAAG,iBAAiB;IAwB/G;;;OAGG;IACH,MAAM,CAAC,sBAAsB,CAAC,WAAW,EAAE,MAAM,CAAC,MAAM,EAAE,2BAA2B,CAAC,GAAG,gBAAgB;IAmBzG;;;OAGG;IACH,MAAM,CAAC,mBAAmB,CAAC,SAAS,EAAE,SAAS,GAAG,aAAa;CAmBlE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/serializer/Serializer.d.ts b/node_modules/@azure/msal-node/dist/cache/serializer/Serializer.d.ts
new file mode 100644
index 0000000..8de99c2
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/serializer/Serializer.d.ts
@@ -0,0 +1,40 @@
+import { AccountCache, IdTokenCache, AccessTokenCache, RefreshTokenCache, AppMetadataCache } from "@azure/msal-common";
+import { InMemoryCache, JsonCache, SerializedAccountEntity, SerializedIdTokenEntity, SerializedAccessTokenEntity, SerializedRefreshTokenEntity, SerializedAppMetadataEntity } from "./SerializerTypes";
+export declare class Serializer {
+ /**
+ * serialize the JSON blob
+ * @param data
+ */
+ static serializeJSONBlob(data: JsonCache): string;
+ /**
+ * Serialize Accounts
+ * @param accCache
+ */
+ static serializeAccounts(accCache: AccountCache): Record;
+ /**
+ * Serialize IdTokens
+ * @param idTCache
+ */
+ static serializeIdTokens(idTCache: IdTokenCache): Record;
+ /**
+ * Serializes AccessTokens
+ * @param atCache
+ */
+ static serializeAccessTokens(atCache: AccessTokenCache): Record;
+ /**
+ * Serialize refreshTokens
+ * @param rtCache
+ */
+ static serializeRefreshTokens(rtCache: RefreshTokenCache): Record;
+ /**
+ * Serialize amdtCache
+ * @param amdtCache
+ */
+ static serializeAppMetadata(amdtCache: AppMetadataCache): Record;
+ /**
+ * Serialize the cache
+ * @param jsonContent
+ */
+ static serializeAllCache(inMemCache: InMemoryCache): JsonCache;
+}
+//# sourceMappingURL=Serializer.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/serializer/Serializer.d.ts.map b/node_modules/@azure/msal-node/dist/cache/serializer/Serializer.d.ts.map
new file mode 100644
index 0000000..5465736
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/serializer/Serializer.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"Serializer.d.ts","sourceRoot":"","sources":["../../src/cache/serializer/Serializer.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,YAAY,EAAE,YAAY,EAAE,gBAAgB,EAAE,iBAAiB,EAAE,gBAAgB,EAAE,MAAM,oBAAoB,CAAC;AACvH,OAAO,EAAE,aAAa,EAAE,SAAS,EAAE,uBAAuB,EAAE,uBAAuB,EAAE,2BAA2B,EAAE,4BAA4B,EAAE,2BAA2B,EAAE,MAAM,mBAAmB,CAAC;AAEvM,qBAAa,UAAU;IACnB;;;OAGG;IACH,MAAM,CAAC,iBAAiB,CAAC,IAAI,EAAE,SAAS,GAAG,MAAM;IAIjD;;;OAGG;IACH,MAAM,CAAC,iBAAiB,CAAC,QAAQ,EAAE,YAAY,GAAG,MAAM,CAAC,MAAM,EAAE,uBAAuB,CAAC;IAqBzF;;;OAGG;IACH,MAAM,CAAC,iBAAiB,CAAC,QAAQ,EAAE,YAAY,GAAG,MAAM,CAAC,MAAM,EAAE,uBAAuB,CAAC;IAiBzF;;;OAGG;IACH,MAAM,CAAC,qBAAqB,CAAC,OAAO,EAAE,gBAAgB,GAAG,MAAM,CAAC,MAAM,EAAE,2BAA2B,CAAC;IAwBpG;;;OAGG;IACH,MAAM,CAAC,sBAAsB,CAAC,OAAO,EAAE,iBAAiB,GAAG,MAAM,CAAC,MAAM,EAAE,4BAA4B,CAAC;IAmBvG;;;OAGG;IACH,MAAM,CAAC,oBAAoB,CAAC,SAAS,EAAE,gBAAgB,GAAG,MAAM,CAAC,MAAM,EAAE,2BAA2B,CAAC;IAcrG;;;OAGG;IACH,MAAM,CAAC,iBAAiB,CAAC,UAAU,EAAE,aAAa,GAAG,SAAS;CASjE"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/serializer/SerializerTypes.d.ts b/node_modules/@azure/msal-node/dist/cache/serializer/SerializerTypes.d.ts
new file mode 100644
index 0000000..3aacca0
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/serializer/SerializerTypes.d.ts
@@ -0,0 +1,99 @@
+import { AccountCache, IdTokenCache, AccessTokenCache, RefreshTokenCache, AppMetadataCache, ValidCacheType } from "@azure/msal-common";
+/**
+ * Key value store for in-memory cache
+ * @public
+ */
+export declare type CacheKVStore = Record;
+/**
+ * Cache format read from the cache blob provided to the configuration during app instantiation
+ * @public
+ */
+export declare type JsonCache = {
+ Account: Record;
+ IdToken: Record;
+ AccessToken: Record;
+ RefreshToken: Record;
+ AppMetadata: Record;
+};
+/**
+ * Intermittent type to handle in-memory data objects with defined types
+ * @public
+ */
+export declare type InMemoryCache = {
+ accounts: AccountCache;
+ idTokens: IdTokenCache;
+ accessTokens: AccessTokenCache;
+ refreshTokens: RefreshTokenCache;
+ appMetadata: AppMetadataCache;
+};
+/**
+ * Account type
+ * @public
+ */
+export declare type SerializedAccountEntity = {
+ home_account_id: string;
+ environment: string;
+ realm: string;
+ local_account_id: string;
+ username: string;
+ authority_type: string;
+ name?: string;
+ client_info?: string;
+ last_modification_time?: string;
+ last_modification_app?: string;
+};
+/**
+ * Idtoken credential type
+ * @public
+ */
+export declare type SerializedIdTokenEntity = {
+ home_account_id: string;
+ environment: string;
+ credential_type: string;
+ client_id: string;
+ secret: string;
+ realm: string;
+};
+/**
+ * Access token credential type
+ * @public
+ */
+export declare type SerializedAccessTokenEntity = {
+ home_account_id: string;
+ environment: string;
+ credential_type: string;
+ client_id: string;
+ secret: string;
+ realm: string;
+ target: string;
+ cached_at: string;
+ expires_on: string;
+ extended_expires_on?: string;
+ refresh_on?: string;
+ key_id?: string;
+ token_type?: string;
+};
+/**
+ * Refresh token credential type
+ * @public
+ */
+export declare type SerializedRefreshTokenEntity = {
+ home_account_id: string;
+ environment: string;
+ credential_type: string;
+ client_id: string;
+ secret: string;
+ family_id?: string;
+ target?: string;
+ realm?: string;
+};
+/**
+ * AppMetadata type
+ * @public
+ */
+export declare type SerializedAppMetadataEntity = {
+ client_id: string;
+ environment: string;
+ family_id?: string;
+};
+//# sourceMappingURL=SerializerTypes.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/cache/serializer/SerializerTypes.d.ts.map b/node_modules/@azure/msal-node/dist/cache/serializer/SerializerTypes.d.ts.map
new file mode 100644
index 0000000..1e8859c
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/cache/serializer/SerializerTypes.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"SerializerTypes.d.ts","sourceRoot":"","sources":["../../src/cache/serializer/SerializerTypes.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,YAAY,EAAE,YAAY,EAAE,gBAAgB,EAAE,iBAAiB,EAAE,gBAAgB,EAAE,cAAc,EAAE,MAAM,oBAAoB,CAAC;AAEvI;;;GAGG;AACH,oBAAY,YAAY,GAAG,MAAM,CAAC,MAAM,EAAE,cAAc,CAAC,CAAC;AAE1D;;;GAGG;AACH,oBAAY,SAAS,GAAG;IACpB,OAAO,EAAE,MAAM,CAAC,MAAM,EAAE,uBAAuB,CAAC,CAAC;IACjD,OAAO,EAAE,MAAM,CAAC,MAAM,EAAE,uBAAuB,CAAC,CAAC;IACjD,WAAW,EAAE,MAAM,CAAC,MAAM,EAAE,2BAA2B,CAAC,CAAC;IACzD,YAAY,EAAE,MAAM,CAAC,MAAM,EAAE,4BAA4B,CAAC,CAAC;IAC3D,WAAW,EAAE,MAAM,CAAC,MAAM,EAAE,2BAA2B,CAAC,CAAC;CAC5D,CAAC;AAEF;;;GAGG;AACH,oBAAY,aAAa,GAAG;IACxB,QAAQ,EAAE,YAAY,CAAC;IACvB,QAAQ,EAAE,YAAY,CAAC;IACvB,YAAY,EAAE,gBAAgB,CAAC;IAC/B,aAAa,EAAE,iBAAiB,CAAC;IACjC,WAAW,EAAE,gBAAgB,CAAC;CACjC,CAAC;AAEF;;;GAGG;AACH,oBAAY,uBAAuB,GAAG;IAClC,eAAe,EAAE,MAAM,CAAC;IACxB,WAAW,EAAE,MAAM,CAAC;IACpB,KAAK,EAAE,MAAM,CAAC;IACd,gBAAgB,EAAE,MAAM,CAAC;IACzB,QAAQ,EAAE,MAAM,CAAC;IACjB,cAAc,EAAE,MAAM,CAAC;IACvB,IAAI,CAAC,EAAE,MAAM,CAAC;IACd,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,sBAAsB,CAAC,EAAE,MAAM,CAAC;IAChC,qBAAqB,CAAC,EAAE,MAAM,CAAC;CAClC,CAAC;AAEF;;;GAGG;AACH,oBAAY,uBAAuB,GAAG;IAClC,eAAe,EAAE,MAAM,CAAC;IACxB,WAAW,EAAE,MAAM,CAAC;IACpB,eAAe,EAAE,MAAM,CAAC;IACxB,SAAS,EAAE,MAAM,CAAC;IAClB,MAAM,EAAE,MAAM,CAAC;IACf,KAAK,EAAE,MAAM,CAAC;CACjB,CAAC;AAEF;;;GAGG;AACH,oBAAY,2BAA2B,GAAG;IACtC,eAAe,EAAE,MAAM,CAAC;IACxB,WAAW,EAAE,MAAM,CAAC;IACpB,eAAe,EAAE,MAAM,CAAC;IACxB,SAAS,EAAE,MAAM,CAAC;IAClB,MAAM,EAAE,MAAM,CAAC;IACf,KAAK,EAAE,MAAM,CAAC;IACd,MAAM,EAAE,MAAM,CAAC;IACf,SAAS,EAAE,MAAM,CAAC;IAClB,UAAU,EAAE,MAAM,CAAC;IACnB,mBAAmB,CAAC,EAAE,MAAM,CAAC;IAC7B,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,UAAU,CAAC,EAAE,MAAM,CAAC;CACvB,CAAC;AAEF;;;GAGG;AACH,oBAAY,4BAA4B,GAAG;IACvC,eAAe,EAAE,MAAM,CAAC;IACxB,WAAW,EAAE,MAAM,CAAC;IACpB,eAAe,EAAE,MAAM,CAAC;IACxB,SAAS,EAAE,MAAM,CAAC;IAClB,MAAM,EAAE,MAAM,CAAC;IACf,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,KAAK,CAAC,EAAE,MAAM,CAAC;CAClB,CAAC;AAEF;;;GAGG;AACH,oBAAY,2BAA2B,GAAG;IACtC,SAAS,EAAE,MAAM,CAAC;IAClB,WAAW,EAAE,MAAM,CAAC;IACpB,SAAS,CAAC,EAAE,MAAM,CAAC;CACtB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/ClientApplication.d.ts b/node_modules/@azure/msal-node/dist/client/ClientApplication.d.ts
new file mode 100644
index 0000000..e3fedd7
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/ClientApplication.d.ts
@@ -0,0 +1,116 @@
+import { ClientConfiguration, AuthenticationResult, BaseAuthRequest, Logger, ServerTelemetryManager } from "@azure/msal-common";
+import { Configuration } from "../config/Configuration";
+import { NodeStorage } from "../cache/NodeStorage";
+import { TokenCache } from "../cache/TokenCache";
+import { ClientAssertion } from "./ClientAssertion";
+import { AuthorizationUrlRequest } from "../request/AuthorizationUrlRequest";
+import { AuthorizationCodeRequest } from "../request/AuthorizationCodeRequest";
+import { RefreshTokenRequest } from "../request/RefreshTokenRequest";
+import { SilentFlowRequest } from "../request/SilentFlowRequest";
+/**
+ * Base abstract class for all ClientApplications - public and confidential
+ * @public
+ */
+export declare abstract class ClientApplication {
+ private readonly cryptoProvider;
+ private tokenCache;
+ /**
+ * Platform storage object
+ */
+ protected storage: NodeStorage;
+ /**
+ * Logger object to log the application flow
+ */
+ protected logger: Logger;
+ /**
+ * Platform configuration initialized by the application
+ */
+ protected config: Configuration;
+ /**
+ * Client assertion passed by the user for confidential client flows
+ */
+ protected clientAssertion: ClientAssertion;
+ /**
+ * Client secret passed by the user for confidential client flows
+ */
+ protected clientSecret: string;
+ /**
+ * Constructor for the ClientApplication
+ */
+ protected constructor(configuration: Configuration);
+ /**
+ * Creates the URL of the authorization request, letting the user input credentials and consent to the
+ * application. The URL targets the /authorize endpoint of the authority configured in the
+ * application object.
+ *
+ * Once the user inputs their credentials and consents, the authority will send a response to the redirect URI
+ * sent in the request and should contain an authorization code, which can then be used to acquire tokens via
+ * `acquireTokenByCode(AuthorizationCodeRequest)`.
+ */
+ getAuthCodeUrl(request: AuthorizationUrlRequest): Promise;
+ /**
+ * Acquires a token by exchanging the Authorization Code received from the first step of OAuth2.0
+ * Authorization Code flow.
+ *
+ * `getAuthCodeUrl(AuthorizationCodeUrlRequest)` can be used to create the URL for the first step of OAuth2.0
+ * Authorization Code flow. Ensure that values for redirectUri and scopes in AuthorizationCodeUrlRequest and
+ * AuthorizationCodeRequest are the same.
+ */
+ acquireTokenByCode(request: AuthorizationCodeRequest): Promise;
+ /**
+ * Acquires a token by exchanging the refresh token provided for a new set of tokens.
+ *
+ * This API is provided only for scenarios where you would like to migrate from ADAL to MSAL. Otherwise, it is
+ * recommended that you use `acquireTokenSilent()` for silent scenarios. When using `acquireTokenSilent()`, MSAL will
+ * handle the caching and refreshing of tokens automatically.
+ */
+ acquireTokenByRefreshToken(request: RefreshTokenRequest): Promise;
+ /**
+ * Acquires a token silently when a user specifies the account the token is requested for.
+ *
+ * This API expects the user to provide an account object and looks into the cache to retrieve the token if present.
+ * There is also an optional "forceRefresh" boolean the user can send to bypass the cache for access_token and id_token.
+ * In case the refresh_token is expired or not found, an error is thrown
+ * and the guidance is for the user to call any interactive token acquisition API (eg: `acquireTokenByCode()`).
+ */
+ acquireTokenSilent(request: SilentFlowRequest): Promise;
+ /**
+ * Gets the token cache for the application.
+ */
+ getTokenCache(): TokenCache;
+ /**
+ * Returns the logger instance
+ */
+ getLogger(): Logger;
+ /**
+ * Replaces the default logger set in configurations with new Logger with new configurations
+ * @param logger - Logger instance
+ */
+ setLogger(logger: Logger): void;
+ /**
+ * Builds the common configuration to be passed to the common component based on the platform configurarion
+ * @param authority - user passed authority in configuration
+ * @param serverTelemetryManager - initializes servertelemetry if passed
+ */
+ protected buildOauthClientConfiguration(authority: string, serverTelemetryManager?: ServerTelemetryManager): Promise;
+ private getClientAssertion;
+ /**
+ * Generates a request with the default scopes & generates a correlationId.
+ * @param authRequest - BaseAuthRequest for initialization
+ */
+ protected initializeBaseRequest(authRequest: Partial): BaseAuthRequest;
+ /**
+ * Initializes the server telemetry payload
+ * @param apiId - Id for a specific request
+ * @param correlationId - GUID
+ * @param forceRefresh - boolean to indicate network call
+ */
+ protected initializeServerTelemetryManager(apiId: number, correlationId: string, forceRefresh?: boolean): ServerTelemetryManager;
+ /**
+ * Create authority instance. If authority not passed in request, default to authority set on the application
+ * object. If no authority set in application object, then default to common authority.
+ * @param authorityString - authority from user configuration
+ */
+ private createAuthority;
+}
+//# sourceMappingURL=ClientApplication.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/ClientApplication.d.ts.map b/node_modules/@azure/msal-node/dist/client/ClientApplication.d.ts.map
new file mode 100644
index 0000000..2bbdb4c
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/ClientApplication.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ClientApplication.d.ts","sourceRoot":"","sources":["../src/client/ClientApplication.ts"],"names":[],"mappings":"AAKA,OAAO,EAEH,mBAAmB,EAEnB,oBAAoB,EAGpB,eAAe,EAEf,MAAM,EACN,sBAAsB,EAUzB,MAAM,oBAAoB,CAAC;AAC5B,OAAO,EAAE,aAAa,EAAyB,MAAM,yBAAyB,CAAC;AAE/E,OAAO,EAAE,WAAW,EAAE,MAAM,sBAAsB,CAAC;AAEnD,OAAO,EAAE,UAAU,EAAE,MAAM,qBAAqB,CAAC;AACjD,OAAO,EAAE,eAAe,EAAE,MAAM,mBAAmB,CAAC;AACpD,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAC7E,OAAO,EAAE,wBAAwB,EAAE,MAAM,qCAAqC,CAAC;AAC/E,OAAO,EAAE,mBAAmB,EAAE,MAAM,gCAAgC,CAAC;AACrE,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AAGjE;;;GAGG;AACH,8BAAsB,iBAAiB;IAEnC,OAAO,CAAC,QAAQ,CAAC,cAAc,CAAiB;IAChD,OAAO,CAAC,UAAU,CAAa;IAE/B;;OAEG;IACH,SAAS,CAAC,OAAO,EAAE,WAAW,CAAC;IAC/B;;OAEG;IACH,SAAS,CAAC,MAAM,EAAE,MAAM,CAAC;IACzB;;OAEG;IACH,SAAS,CAAC,MAAM,EAAE,aAAa,CAAC;IAChC;;OAEG;IACH,SAAS,CAAC,eAAe,EAAE,eAAe,CAAC;IAC3C;;OAEG;IACH,SAAS,CAAC,YAAY,EAAE,MAAM,CAAC;IAE/B;;OAEG;IACH,SAAS,aAAa,aAAa,EAAE,aAAa;IAYlD;;;;;;;;OAQG;IACG,cAAc,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,MAAM,CAAC;IAkBvE;;;;;;;OAOG;IACG,kBAAkB,CAAC,OAAO,EAAE,wBAAwB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAwBjG;;;;;;OAMG;IACG,0BAA0B,CAAC,OAAO,EAAE,mBAAmB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAyBpG;;;;;;;OAOG;IACG,kBAAkB,CAAC,OAAO,EAAE,iBAAiB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAuB1F;;OAEG;IACH,aAAa,IAAI,UAAU;IAK3B;;OAEG;IACH,SAAS,IAAI,MAAM;IAInB;;;OAGG;IACH,SAAS,CAAC,MAAM,EAAE,MAAM,GAAG,IAAI;IAI/B;;;;OAIG;cACa,6BAA6B,CAAC,SAAS,EAAE,MAAM,EAAE,sBAAsB,CAAC,EAAE,sBAAsB,GAAG,OAAO,CAAC,mBAAmB,CAAC;IAqC/I,OAAO,CAAC,kBAAkB;IAO1B;;;OAGG;IACH,SAAS,CAAC,qBAAqB,CAAC,WAAW,EAAE,OAAO,CAAC,eAAe,CAAC,GAAG,eAAe;IAWvF;;;;;OAKG;IACH,SAAS,CAAC,gCAAgC,CAAC,KAAK,EAAE,MAAM,EAAE,aAAa,EAAE,MAAM,EAAE,YAAY,CAAC,EAAE,OAAO,GAAG,sBAAsB;IAWhI;;;;OAIG;YACW,eAAe;CAUhC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/ClientAssertion.d.ts b/node_modules/@azure/msal-node/dist/client/ClientAssertion.d.ts
new file mode 100644
index 0000000..8fe0e09
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/ClientAssertion.d.ts
@@ -0,0 +1,47 @@
+import { CryptoProvider } from "../crypto/CryptoProvider";
+/**
+ * Client assertion of type jwt-bearer used in confidential client flows
+ * @public
+ */
+export declare class ClientAssertion {
+ private jwt;
+ private privateKey;
+ private thumbprint;
+ private expirationTime;
+ private issuer;
+ private jwtAudience;
+ private publicCertificate;
+ /**
+ * Initialize the ClientAssertion class from the clientAssertion passed by the user
+ * @param assertion - refer https://tools.ietf.org/html/rfc7521
+ */
+ static fromAssertion(assertion: string): ClientAssertion;
+ /**
+ * Initialize the ClientAssertion class from the certificate passed by the user
+ * @param thumbprint - identifier of a certificate
+ * @param privateKey - secret key
+ * @param publicCertificate - electronic document provided to prove the ownership of the public key
+ */
+ static fromCertificate(thumbprint: string, privateKey: string, publicCertificate?: string): ClientAssertion;
+ /**
+ * Update JWT for certificate based clientAssertion, if passed by the user, uses it as is
+ * @param cryptoProvider - library's crypto helper
+ * @param issuer - iss claim
+ * @param jwtAudience - aud claim
+ */
+ getJwt(cryptoProvider: CryptoProvider, issuer: string, jwtAudience: string): string;
+ /**
+ * JWT format and required claims specified: https://tools.ietf.org/html/rfc7523#section-3
+ */
+ private createJwt;
+ /**
+ * Utility API to check expiration
+ */
+ private isExpired;
+ /**
+ * Extracts the raw certs from a given certificate string and returns them in an array.
+ * @param publicCertificate - electronic document provided to prove the ownership of the public key
+ */
+ static parseCertificate(publicCertificate: string): Array;
+}
+//# sourceMappingURL=ClientAssertion.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/ClientAssertion.d.ts.map b/node_modules/@azure/msal-node/dist/client/ClientAssertion.d.ts.map
new file mode 100644
index 0000000..f21dfd1
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/ClientAssertion.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ClientAssertion.d.ts","sourceRoot":"","sources":["../src/client/ClientAssertion.ts"],"names":[],"mappings":"AAOA,OAAO,EAAE,cAAc,EAAE,MAAM,0BAA0B,CAAC;AAI1D;;;GAGG;AACH,qBAAa,eAAe;IAExB,OAAO,CAAC,GAAG,CAAS;IACpB,OAAO,CAAC,UAAU,CAAS;IAC3B,OAAO,CAAC,UAAU,CAAS;IAC3B,OAAO,CAAC,cAAc,CAAS;IAC/B,OAAO,CAAC,MAAM,CAAS;IACvB,OAAO,CAAC,WAAW,CAAS;IAC5B,OAAO,CAAC,iBAAiB,CAAgB;IAEzC;;;OAGG;WACW,aAAa,CAAC,SAAS,EAAE,MAAM,GAAG,eAAe;IAM/D;;;;;OAKG;WACW,eAAe,CAAC,UAAU,EAAE,MAAM,EAAE,UAAU,EAAE,MAAM,EAAE,iBAAiB,CAAC,EAAE,MAAM,GAAG,eAAe;IAUlH;;;;;OAKG;IACI,MAAM,CAAC,cAAc,EAAE,cAAc,EAAE,MAAM,EAAE,MAAM,EAAE,WAAW,EAAE,MAAM;IAsBjF;;OAEG;IACH,OAAO,CAAC,SAAS;IA+BjB;;OAEG;IACH,OAAO,CAAC,SAAS;IAIjB;;;OAGG;WACW,gBAAgB,CAAC,iBAAiB,EAAE,MAAM,GAAG,KAAK,CAAC,MAAM,CAAC;CAmB3E"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/ConfidentialClientApplication.d.ts b/node_modules/@azure/msal-node/dist/client/ConfidentialClientApplication.d.ts
new file mode 100644
index 0000000..83a3540
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/ConfidentialClientApplication.d.ts
@@ -0,0 +1,51 @@
+import { ClientApplication } from "./ClientApplication";
+import { Configuration } from "../config/Configuration";
+import { AuthenticationResult } from "@azure/msal-common";
+import { IConfidentialClientApplication } from "./IConfidentialClientApplication";
+import { OnBehalfOfRequest } from "../request/OnBehalfOfRequest";
+import { ClientCredentialRequest } from "../request/ClientCredentialRequest";
+/**
+ * This class is to be used to acquire tokens for confidential client applications (webApp, webAPI). Confidential client applications
+ * will configure application secrets, client certificates/assertions as applicable
+ * @public
+ */
+export declare class ConfidentialClientApplication extends ClientApplication implements IConfidentialClientApplication {
+ /**
+ * Constructor for the ConfidentialClientApplication
+ *
+ * Required attributes in the Configuration object are:
+ * - clientID: the application ID of your application. You can obtain one by registering your application with our application registration portal
+ * - authority: the authority URL for your application.
+ * - client credential: Must set either client secret, certificate, or assertion for confidential clients. You can obtain a client secret from the application registration portal.
+ *
+ * In Azure AD, authority is a URL indicating of the form https://login.microsoftonline.com/\{Enter_the_Tenant_Info_Here\}.
+ * If your application supports Accounts in one organizational directory, replace "Enter_the_Tenant_Info_Here" value with the Tenant Id or Tenant name (for example, contoso.microsoft.com).
+ * If your application supports Accounts in any organizational directory, replace "Enter_the_Tenant_Info_Here" value with organizations.
+ * If your application supports Accounts in any organizational directory and personal Microsoft accounts, replace "Enter_the_Tenant_Info_Here" value with common.
+ * To restrict support to Personal Microsoft accounts only, replace "Enter_the_Tenant_Info_Here" value with consumers.
+ *
+ * In Azure B2C, authority is of the form https://\{instance\}/tfp/\{tenant\}/\{policyName\}/
+ * Full B2C functionality will be available in this library in future versions.
+ *
+ * @param Configuration - configuration object for the MSAL ConfidentialClientApplication instance
+ */
+ constructor(configuration: Configuration);
+ /**
+ * Acquires tokens from the authority for the application (not for an end user).
+ */
+ acquireTokenByClientCredential(request: ClientCredentialRequest): Promise;
+ /**
+ * Acquires tokens from the authority for the application.
+ *
+ * Used in scenarios where the current app is a middle-tier service which was called with a token
+ * representing an end user. The current app can use the token (oboAssertion) to request another
+ * token to access downstream web API, on behalf of that user.
+ *
+ * The current middle-tier app has no user interaction to obtain consent.
+ * See how to gain consent upfront for your middle-tier app from this article.
+ * https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-on-behalf-of-flow#gaining-consent-for-the-middle-tier-application
+ */
+ acquireTokenOnBehalfOf(request: OnBehalfOfRequest): Promise;
+ private setClientCredential;
+}
+//# sourceMappingURL=ConfidentialClientApplication.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/ConfidentialClientApplication.d.ts.map b/node_modules/@azure/msal-node/dist/client/ConfidentialClientApplication.d.ts.map
new file mode 100644
index 0000000..675fff8
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/ConfidentialClientApplication.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"ConfidentialClientApplication.d.ts","sourceRoot":"","sources":["../src/client/ConfidentialClientApplication.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,iBAAiB,EAAE,MAAM,qBAAqB,CAAC;AACxD,OAAO,EAAE,aAAa,EAAE,MAAM,yBAAyB,CAAC;AAGxD,OAAO,EAKH,oBAAoB,EAEH,MAAM,oBAAoB,CAAC;AAChD,OAAO,EAAE,8BAA8B,EAAE,MAAM,kCAAkC,CAAC;AAClF,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAE7E;;;;GAIG;AACH,qBAAa,6BAA8B,SAAQ,iBAAkB,YAAW,8BAA8B;IAE1G;;;;;;;;;;;;;;;;;;OAkBG;gBACS,aAAa,EAAE,aAAa;IAKxC;;OAEG;IACU,8BAA8B,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAqBnH;;;;;;;;;;OAUG;IACU,sBAAsB,CAAC,OAAO,EAAE,iBAAiB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAcrG,OAAO,CAAC,mBAAmB;CA+B9B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/IConfidentialClientApplication.d.ts b/node_modules/@azure/msal-node/dist/client/IConfidentialClientApplication.d.ts
new file mode 100644
index 0000000..6a032df
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/IConfidentialClientApplication.d.ts
@@ -0,0 +1,33 @@
+import { AuthenticationResult, Logger } from "@azure/msal-common";
+import { AuthorizationCodeRequest } from "../request/AuthorizationCodeRequest";
+import { AuthorizationUrlRequest } from "../request/AuthorizationUrlRequest";
+import { ClientCredentialRequest } from "../request/ClientCredentialRequest";
+import { OnBehalfOfRequest } from "../request/OnBehalfOfRequest";
+import { RefreshTokenRequest } from "../request/RefreshTokenRequest";
+import { SilentFlowRequest } from "../request/SilentFlowRequest";
+import { TokenCache } from "../cache/TokenCache";
+/**
+ * Interface for the ConfidentialClientApplication class defining the public API signatures
+ * @public
+ */
+export interface IConfidentialClientApplication {
+ /** Creates the URL of the authorization request */
+ getAuthCodeUrl(request: AuthorizationUrlRequest): Promise;
+ /** Acquires a token by exchanging the authorization code received from the first step of OAuth 2.0 Authorization Code Flow */
+ acquireTokenByCode(request: AuthorizationCodeRequest): Promise;
+ /** Acquires a token silently when a user specifies the account the token is requested for */
+ acquireTokenSilent(request: SilentFlowRequest): Promise;
+ /** Acquires a token by exchanging the refresh token provided for a new set of tokens */
+ acquireTokenByRefreshToken(request: RefreshTokenRequest): Promise;
+ /** Acquires tokens from the authority for the application (not for an end user) */
+ acquireTokenByClientCredential(request: ClientCredentialRequest): Promise;
+ /** Acquires tokens from the authority for the application */
+ acquireTokenOnBehalfOf(request: OnBehalfOfRequest): Promise;
+ /** Gets the token cache for the application */
+ getTokenCache(): TokenCache;
+ /** Returns the logger instance */
+ getLogger(): Logger;
+ /** Replaces the default logger set in configurations with new Logger with new configurations */
+ setLogger(logger: Logger): void;
+}
+//# sourceMappingURL=IConfidentialClientApplication.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/IConfidentialClientApplication.d.ts.map b/node_modules/@azure/msal-node/dist/client/IConfidentialClientApplication.d.ts.map
new file mode 100644
index 0000000..c139a06
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/IConfidentialClientApplication.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"IConfidentialClientApplication.d.ts","sourceRoot":"","sources":["../src/client/IConfidentialClientApplication.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,oBAAoB,EAAE,MAAM,EAAE,MAAM,oBAAoB,CAAC;AAClE,OAAO,EAAE,wBAAwB,EAAE,MAAM,qCAAqC,CAAC;AAC/E,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAC7E,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAC7E,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,mBAAmB,EAAE,MAAM,gCAAgC,CAAC;AACrE,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,UAAU,EAAE,MAAM,qBAAqB,CAAC;AAEjD;;;GAGG;AACH,MAAM,WAAW,8BAA8B;IAE3C,mDAAmD;IACnD,cAAc,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,MAAM,CAAC,CAAC;IAElE,+HAA+H;IAC/H,kBAAkB,CAAC,OAAO,EAAE,wBAAwB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAE5F,8FAA8F;IAC9F,kBAAkB,CAAC,OAAO,EAAE,iBAAiB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAErF,wFAAwF;IACxF,0BAA0B,CAAC,OAAO,EAAE,mBAAmB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAE/F,mFAAmF;IACnF,8BAA8B,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAEvG,6DAA6D;IAC7D,sBAAsB,CAAC,OAAO,EAAE,iBAAiB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAEzF,+CAA+C;IAC/C,aAAa,IAAI,UAAU,CAAC;IAE5B,kCAAkC;IAClC,SAAS,IAAI,MAAM,CAAC;IAEpB,gGAAgG;IAChG,SAAS,CAAC,MAAM,EAAE,MAAM,GAAG,IAAI,CAAC;CACnC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/IPublicClientApplication.d.ts b/node_modules/@azure/msal-node/dist/client/IPublicClientApplication.d.ts
new file mode 100644
index 0000000..913f0ff
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/IPublicClientApplication.d.ts
@@ -0,0 +1,33 @@
+import { AuthenticationResult, Logger } from "@azure/msal-common";
+import { AuthorizationCodeRequest } from "../request/AuthorizationCodeRequest";
+import { AuthorizationUrlRequest } from "../request/AuthorizationUrlRequest";
+import { DeviceCodeRequest } from "../request/DeviceCodeRequest";
+import { RefreshTokenRequest } from "../request/RefreshTokenRequest";
+import { SilentFlowRequest } from "../request/SilentFlowRequest";
+import { UsernamePasswordRequest } from "../request/UsernamePasswordRequest";
+import { TokenCache } from "../cache/TokenCache";
+/**
+ * Interface for the PublicClientApplication class defining the public API signatures
+ * @public
+ */
+export interface IPublicClientApplication {
+ /** Creates the URL of the authorization request */
+ getAuthCodeUrl(request: AuthorizationUrlRequest): Promise;
+ /** Acquires a token by exchanging the authorization code received from the first step of OAuth 2.0 Authorization Code Flow */
+ acquireTokenByCode(request: AuthorizationCodeRequest): Promise;
+ /** Acquires a token silently when a user specifies the account the token is requested for */
+ acquireTokenSilent(request: SilentFlowRequest): Promise;
+ /** Acquires a token by exchanging the refresh token provided for a new set of tokens */
+ acquireTokenByRefreshToken(request: RefreshTokenRequest): Promise;
+ /** Acquires a token from the authority using OAuth2.0 device code flow */
+ acquireTokenByDeviceCode(request: DeviceCodeRequest): Promise;
+ /** Acquires tokens with password grant by exchanging client applications username and password for credentials */
+ acquireTokenByUsernamePassword(request: UsernamePasswordRequest): Promise;
+ /** Gets the token cache for the application */
+ getTokenCache(): TokenCache;
+ /** Returns the logger instance */
+ getLogger(): Logger;
+ /** Replaces the default logger set in configurations with new Logger with new configurations */
+ setLogger(logger: Logger): void;
+}
+//# sourceMappingURL=IPublicClientApplication.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/IPublicClientApplication.d.ts.map b/node_modules/@azure/msal-node/dist/client/IPublicClientApplication.d.ts.map
new file mode 100644
index 0000000..aba485f
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/IPublicClientApplication.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"IPublicClientApplication.d.ts","sourceRoot":"","sources":["../src/client/IPublicClientApplication.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,oBAAoB,EAAE,MAAM,EAAE,MAAM,oBAAoB,CAAC;AAClE,OAAO,EAAE,wBAAwB,EAAE,MAAM,qCAAqC,CAAC;AAC/E,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAC7E,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,mBAAmB,EAAE,MAAM,gCAAgC,CAAC;AACrE,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAC7E,OAAO,EAAE,UAAU,EAAE,MAAM,qBAAqB,CAAC;AAEjD;;;GAGG;AACH,MAAM,WAAW,wBAAwB;IAErC,mDAAmD;IACnD,cAAc,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,MAAM,CAAC,CAAC;IAElE,8HAA8H;IAC9H,kBAAkB,CAAC,OAAO,EAAE,wBAAwB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAE5F,6FAA6F;IAC7F,kBAAkB,CAAC,OAAO,EAAE,iBAAiB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAErF,wFAAwF;IACxF,0BAA0B,CAAC,OAAO,EAAE,mBAAmB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAE/F,0EAA0E;IAC1E,wBAAwB,CAAC,OAAO,EAAE,iBAAiB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAE3F,kHAAkH;IAClH,8BAA8B,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC,CAAC;IAEvG,+CAA+C;IAC/C,aAAa,IAAI,UAAU,CAAC;IAE5B,kCAAkC;IAClC,SAAS,IAAI,MAAM,CAAC;IAEpB,gGAAgG;IAChG,SAAS,CAAC,MAAM,EAAE,MAAM,GAAG,IAAI,CAAC;CACnC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/PublicClientApplication.d.ts b/node_modules/@azure/msal-node/dist/client/PublicClientApplication.d.ts
new file mode 100644
index 0000000..28f763a
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/PublicClientApplication.d.ts
@@ -0,0 +1,53 @@
+import { AuthenticationResult } from "@azure/msal-common";
+import { Configuration } from "../config/Configuration";
+import { ClientApplication } from "./ClientApplication";
+import { IPublicClientApplication } from "./IPublicClientApplication";
+import { DeviceCodeRequest } from "../request/DeviceCodeRequest";
+import { UsernamePasswordRequest } from "../request/UsernamePasswordRequest";
+/**
+ * This class is to be used to acquire tokens for public client applications (desktop, mobile). Public client applications
+ * are not trusted to safely store application secrets, and therefore can only request tokens in the name of an user.
+ * @public
+ */
+export declare class PublicClientApplication extends ClientApplication implements IPublicClientApplication {
+ /**
+ * Important attributes in the Configuration object for auth are:
+ * - clientID: the application ID of your application. You can obtain one by registering your application with our Application registration portal.
+ * - authority: the authority URL for your application.
+ *
+ * AAD authorities are of the form https://login.microsoftonline.com/\{Enter_the_Tenant_Info_Here\}.
+ * - If your application supports Accounts in one organizational directory, replace "Enter_the_Tenant_Info_Here" value with the Tenant Id or Tenant name (for example, contoso.microsoft.com).
+ * - If your application supports Accounts in any organizational directory, replace "Enter_the_Tenant_Info_Here" value with organizations.
+ * - If your application supports Accounts in any organizational directory and personal Microsoft accounts, replace "Enter_the_Tenant_Info_Here" value with common.
+ * - To restrict support to Personal Microsoft accounts only, replace "Enter_the_Tenant_Info_Here" value with consumers.
+ *
+ * Azure B2C authorities are of the form https://\{instance\}/\{tenant\}/\{policy\}. Each policy is considered
+ * its own authority. You will have to set the all of the knownAuthorities at the time of the client application
+ * construction.
+ *
+ * ADFS authorities are of the form https://\{instance\}/adfs.
+ */
+ constructor(configuration: Configuration);
+ /**
+ * Acquires a token from the authority using OAuth2.0 device code flow.
+ * This flow is designed for devices that do not have access to a browser or have input constraints.
+ * The authorization server issues a DeviceCode object with a verification code, an end-user code,
+ * and the end-user verification URI. The DeviceCode object is provided through a callback, and the end-user should be
+ * instructed to use another device to navigate to the verification URI to input credentials.
+ * Since the client cannot receive incoming requests, it polls the authorization server repeatedly
+ * until the end-user completes input of credentials.
+ */
+ acquireTokenByDeviceCode(request: DeviceCodeRequest): Promise;
+ /**
+ * Acquires tokens with password grant by exchanging client applications username and password for credentials
+ *
+ * The latest OAuth 2.0 Security Best Current Practice disallows the password grant entirely.
+ * More details on this recommendation at https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13#section-3.4
+ * Microsoft's documentation and recommendations are at:
+ * https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-authentication-flows#usernamepassword
+ *
+ * @param request - UsenamePasswordRequest
+ */
+ acquireTokenByUsernamePassword(request: UsernamePasswordRequest): Promise;
+}
+//# sourceMappingURL=PublicClientApplication.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/client/PublicClientApplication.d.ts.map b/node_modules/@azure/msal-node/dist/client/PublicClientApplication.d.ts.map
new file mode 100644
index 0000000..e64996a
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/client/PublicClientApplication.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"PublicClientApplication.d.ts","sourceRoot":"","sources":["../src/client/PublicClientApplication.ts"],"names":[],"mappings":"AAMA,OAAO,EAEH,oBAAoB,EAIvB,MAAM,oBAAoB,CAAC;AAC5B,OAAO,EAAE,aAAa,EAAE,MAAM,yBAAyB,CAAC;AACxD,OAAO,EAAE,iBAAiB,EAAE,MAAM,qBAAqB,CAAC;AACxD,OAAO,EAAE,wBAAwB,EAAE,MAAM,4BAA4B,CAAC;AACtE,OAAO,EAAE,iBAAiB,EAAE,MAAM,8BAA8B,CAAC;AACjE,OAAO,EAAE,uBAAuB,EAAE,MAAM,oCAAoC,CAAC;AAE7E;;;;GAIG;AACH,qBAAa,uBAAwB,SAAQ,iBAAkB,YAAW,wBAAwB;IAC9F;;;;;;;;;;;;;;;;OAgBG;gBACS,aAAa,EAAE,aAAa;IAIxC;;;;;;;;OAQG;IACU,wBAAwB,CAAC,OAAO,EAAE,iBAAiB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;IAqBvG;;;;;;;;;OASG;IACG,8BAA8B,CAAC,OAAO,EAAE,uBAAuB,GAAG,OAAO,CAAC,oBAAoB,GAAG,IAAI,CAAC;CAoB/G"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/config/Configuration.d.ts b/node_modules/@azure/msal-node/dist/config/Configuration.d.ts
new file mode 100644
index 0000000..455ca3e
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/config/Configuration.d.ts
@@ -0,0 +1,72 @@
+import { LoggerOptions, INetworkModule, ProtocolMode, ICachePlugin } from "@azure/msal-common";
+/**
+ * - clientId - Client id of the application.
+ * - authority - Url of the authority. If no value is set, defaults to https://login.microsoftonline.com/common.
+ * - knownAuthorities - Needed for Azure B2C and ADFS. All authorities that will be used in the client application. Only the host of the authority should be passed in.
+ * - clientSecret - Secret string that the application uses when requesting a token. Only used in confidential client applications. Can be created in the Azure app registration portal.
+ * - clientAssertion - Assertion string that the application uses when requesting a token. Only used in confidential client applications. Assertion should be of type urn:ietf:params:oauth:client-assertion-type:jwt-bearer.
+ * - clientCertificate - Certificate that the application uses when requesting a token. Only used in confidential client applications. Requires hex encoded X.509 SHA-1 thumbprint of the certificiate, and the PEM encoded private key (string should contain -----BEGIN PRIVATE KEY----- ... -----END PRIVATE KEY----- )
+ * - protocolMode - Enum that represents the protocol that msal follows. Used for configuring proper endpoints.
+ * @public
+ */
+export declare type NodeAuthOptions = {
+ clientId: string;
+ authority?: string;
+ clientSecret?: string;
+ clientAssertion?: string;
+ clientCertificate?: {
+ thumbprint: string;
+ privateKey: string;
+ x5c?: string;
+ };
+ knownAuthorities?: Array;
+ cloudDiscoveryMetadata?: string;
+ authorityMetadata?: string;
+ clientCapabilities?: [];
+ protocolMode?: ProtocolMode;
+};
+/**
+ * Use this to configure the below cache configuration options:
+ *
+ * - cachePlugin - Plugin for reading and writing token cache to disk.
+ * @public
+ */
+export declare type CacheOptions = {
+ cachePlugin?: ICachePlugin;
+};
+/**
+ * Type for configuring logger and http client options
+ *
+ * - logger - Used to initialize the Logger object; TODO: Expand on logger details or link to the documentation on logger
+ * - networkClient - Http client used for all http get and post calls. Defaults to using MSAL's default http client.
+ * @public
+ */
+export declare type NodeSystemOptions = {
+ loggerOptions?: LoggerOptions;
+ networkClient?: INetworkModule;
+};
+/**
+ * Use the configuration object to configure MSAL and initialize the client application object
+ *
+ * - auth: this is where you configure auth elements like clientID, authority used for authenticating against the Microsoft Identity Platform
+ * - cache: this is where you configure cache location
+ * - system: this is where you can configure the network client, logger
+ * @public
+ */
+export declare type Configuration = {
+ auth: NodeAuthOptions;
+ cache?: CacheOptions;
+ system?: NodeSystemOptions;
+};
+/**
+ * Sets the default options when not explicitly configured from app developer
+ *
+ * @param auth - Authentication options
+ * @param cache - Cache options
+ * @param system - System options
+ *
+ * @returns Configuration
+ * @public
+ */
+export declare function buildAppConfiguration({ auth, cache, system, }: Configuration): Configuration;
+//# sourceMappingURL=Configuration.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/config/Configuration.d.ts.map b/node_modules/@azure/msal-node/dist/config/Configuration.d.ts.map
new file mode 100644
index 0000000..3bc2406
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/config/Configuration.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"Configuration.d.ts","sourceRoot":"","sources":["../src/config/Configuration.ts"],"names":[],"mappings":"AAKA,OAAO,EACH,aAAa,EACb,cAAc,EAEd,YAAY,EACZ,YAAY,EACf,MAAM,oBAAoB,CAAC;AAG5B;;;;;;;;;GASG;AACH,oBAAY,eAAe,GAAG;IAC1B,QAAQ,EAAE,MAAM,CAAC;IACjB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,YAAY,CAAC,EAAE,MAAM,CAAC;IACtB,eAAe,CAAC,EAAC,MAAM,CAAC;IACxB,iBAAiB,CAAC,EAAE;QAChB,UAAU,EAAE,MAAM,CAAC;QACnB,UAAU,EAAE,MAAM,CAAC;QACnB,GAAG,CAAC,EAAE,MAAM,CAAA;KACf,CAAC;IACF,gBAAgB,CAAC,EAAE,KAAK,CAAC,MAAM,CAAC,CAAC;IACjC,sBAAsB,CAAC,EAAE,MAAM,CAAC;IAChC,iBAAiB,CAAC,EAAE,MAAM,CAAC;IAC3B,kBAAkB,CAAC,EAAE,EAAE,CAAC;IACxB,YAAY,CAAC,EAAE,YAAY,CAAC;CAC/B,CAAC;AAEF;;;;;GAKG;AACH,oBAAY,YAAY,GAAG;IACvB,WAAW,CAAC,EAAE,YAAY,CAAC;CAC9B,CAAC;AAEF;;;;;;GAMG;AACH,oBAAY,iBAAiB,GAAG;IAC5B,aAAa,CAAC,EAAE,aAAa,CAAC;IAC9B,aAAa,CAAC,EAAE,cAAc,CAAC;CAClC,CAAC;AAEF;;;;;;;GAOG;AACH,oBAAY,aAAa,GAAG;IACxB,IAAI,EAAE,eAAe,CAAC;IACtB,KAAK,CAAC,EAAE,YAAY,CAAC;IACrB,MAAM,CAAC,EAAE,iBAAiB,CAAC;CAC9B,CAAC;AAkCF;;;;;;;;;GASG;AACH,wBAAgB,qBAAqB,CAAC,EAClC,IAAI,EACJ,KAAK,EACL,MAAM,GACT,EAAE,aAAa,GAAG,aAAa,CAM/B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/crypto/CryptoProvider.d.ts b/node_modules/@azure/msal-node/dist/crypto/CryptoProvider.d.ts
new file mode 100644
index 0000000..d02d0a0
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/crypto/CryptoProvider.d.ts
@@ -0,0 +1,38 @@
+import { ICrypto, PkceCodes } from "@azure/msal-common";
+/**
+ * This class implements MSAL node's crypto interface, which allows it to perform base64 encoding and decoding, generating cryptographically random GUIDs and
+ * implementing Proof Key for Code Exchange specs for the OAuth Authorization Code Flow using PKCE (rfc here: https://tools.ietf.org/html/rfc7636).
+ * @public
+ */
+export declare class CryptoProvider implements ICrypto {
+ private pkceGenerator;
+ constructor();
+ /**
+ * Creates a new random GUID - used to populate state and nonce.
+ * @returns string (GUID)
+ */
+ createNewGuid(): string;
+ /**
+ * Encodes input string to base64.
+ * @param input - string to be encoded
+ */
+ base64Encode(input: string): string;
+ /**
+ * Decodes input string from base64.
+ * @param input - string to be decoded
+ */
+ base64Decode(input: string): string;
+ /**
+ * Generates PKCE codes used in Authorization Code Flow.
+ */
+ generatePkceCodes(): Promise;
+ /**
+ * Generates a keypair, stores it and returns a thumbprint - not yet implemented for node
+ */
+ getPublicKeyThumbprint(): Promise;
+ /**
+ * Signs the given object as a jwt payload with private key retrieved by given kid - currently not implemented for node
+ */
+ signJwt(): Promise;
+}
+//# sourceMappingURL=CryptoProvider.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/crypto/CryptoProvider.d.ts.map b/node_modules/@azure/msal-node/dist/crypto/CryptoProvider.d.ts.map
new file mode 100644
index 0000000..64d536d
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/crypto/CryptoProvider.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"CryptoProvider.d.ts","sourceRoot":"","sources":["../src/crypto/CryptoProvider.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,OAAO,EAAE,SAAS,EAAE,MAAM,oBAAoB,CAAC;AAKxD;;;;GAIG;AACH,qBAAa,cAAe,YAAW,OAAO;IAC1C,OAAO,CAAC,aAAa,CAAgB;;IAOrC;;;OAGG;IACH,aAAa,IAAI,MAAM;IAIvB;;;OAGG;IACH,YAAY,CAAC,KAAK,EAAE,MAAM,GAAG,MAAM;IAInC;;;OAGG;IACH,YAAY,CAAC,KAAK,EAAE,MAAM,GAAG,MAAM;IAInC;;OAEG;IACH,iBAAiB,IAAI,OAAO,CAAC,SAAS,CAAC;IAIvC;;OAEG;IACH,sBAAsB,IAAI,OAAO,CAAC,MAAM,CAAC;IAIzC;;OAEG;IACH,OAAO,IAAI,OAAO,CAAC,MAAM,CAAC;CAG7B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/crypto/GuidGenerator.d.ts b/node_modules/@azure/msal-node/dist/crypto/GuidGenerator.d.ts
new file mode 100644
index 0000000..03776df
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/crypto/GuidGenerator.d.ts
@@ -0,0 +1,14 @@
+export declare class GuidGenerator {
+ /**
+ *
+ * RFC4122: The version 4 UUID is meant for generating UUIDs from truly-random or pseudo-random numbers.
+ * uuidv4 generates guids from cryprtographically-string random
+ */
+ static generateGuid(): string;
+ /**
+ * verifies if a string is GUID
+ * @param guid
+ */
+ static isGuid(guid: string): boolean;
+}
+//# sourceMappingURL=GuidGenerator.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/crypto/GuidGenerator.d.ts.map b/node_modules/@azure/msal-node/dist/crypto/GuidGenerator.d.ts.map
new file mode 100644
index 0000000..d6dea05
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/crypto/GuidGenerator.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"GuidGenerator.d.ts","sourceRoot":"","sources":["../src/crypto/GuidGenerator.ts"],"names":[],"mappings":"AAOA,qBAAa,aAAa;IACtB;;;;OAIG;IACH,MAAM,CAAC,YAAY,IAAI,MAAM;IAI7B;;;OAGG;IACH,MAAM,CAAC,MAAM,CAAC,IAAI,EAAE,MAAM;CAI7B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/crypto/PkceGenerator.d.ts b/node_modules/@azure/msal-node/dist/crypto/PkceGenerator.d.ts
new file mode 100644
index 0000000..56b6e2e
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/crypto/PkceGenerator.d.ts
@@ -0,0 +1,31 @@
+import { PkceCodes } from "@azure/msal-common";
+/**
+ * https://tools.ietf.org/html/rfc7636#page-8
+ */
+export declare class PkceGenerator {
+ /**
+ * generates the codeVerfier and the challenge from the codeVerfier
+ * reference: https://tools.ietf.org/html/rfc7636#section-4.1 and https://tools.ietf.org/html/rfc7636#section-4.2
+ */
+ generatePkceCodes(): Promise;
+ /**
+ * generates the codeVerfier; reference: https://tools.ietf.org/html/rfc7636#section-4.1
+ */
+ private generateCodeVerifier;
+ /**
+ * generate the challenge from the codeVerfier; reference: https://tools.ietf.org/html/rfc7636#section-4.2
+ * @param codeVerifier
+ */
+ private generateCodeChallengeFromVerifier;
+ /**
+ * generate 'SHA256' hash
+ * @param buffer
+ */
+ private sha256;
+ /**
+ * Accepted characters; reference: https://tools.ietf.org/html/rfc7636#section-4.1
+ * @param buffer
+ */
+ private bufferToCVString;
+}
+//# sourceMappingURL=PkceGenerator.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/crypto/PkceGenerator.d.ts.map b/node_modules/@azure/msal-node/dist/crypto/PkceGenerator.d.ts.map
new file mode 100644
index 0000000..86e2ed4
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/crypto/PkceGenerator.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"PkceGenerator.d.ts","sourceRoot":"","sources":["../src/crypto/PkceGenerator.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,SAAS,EAAE,MAAM,oBAAoB,CAAC;AAK/C;;GAEG;AACH,qBAAa,aAAa;IACtB;;;OAGG;IACG,iBAAiB,IAAI,OAAO,CAAC,SAAS,CAAC;IAM7C;;OAEG;IACH,OAAO,CAAC,oBAAoB;IAM5B;;;OAGG;IACH,OAAO,CAAC,iCAAiC;IAOzC;;;OAGG;IACH,OAAO,CAAC,MAAM;IAOd;;;OAGG;IACH,OAAO,CAAC,gBAAgB;CAQ3B"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/index.d.ts b/node_modules/@azure/msal-node/dist/index.d.ts
new file mode 100644
index 0000000..e476ca4
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/index.d.ts
@@ -0,0 +1,26 @@
+/**
+ * @packageDocumentation
+ * @module @azure/msal-node
+ */
+export { IPublicClientApplication } from "./client/IPublicClientApplication";
+export { IConfidentialClientApplication } from "./client/IConfidentialClientApplication";
+export { ITokenCache } from "./cache/ITokenCache";
+export { PublicClientApplication } from "./client/PublicClientApplication";
+export { ConfidentialClientApplication } from "./client/ConfidentialClientApplication";
+export { ClientApplication } from "./client/ClientApplication";
+export { Configuration, buildAppConfiguration, NodeAuthOptions, NodeSystemOptions, CacheOptions } from "./config/Configuration";
+export { ClientAssertion } from "./client/ClientAssertion";
+export { TokenCache } from "./cache/TokenCache";
+export { NodeStorage } from "./cache/NodeStorage";
+export { CacheKVStore, JsonCache, InMemoryCache, SerializedAccountEntity, SerializedIdTokenEntity, SerializedAccessTokenEntity, SerializedAppMetadataEntity, SerializedRefreshTokenEntity } from "./cache/serializer/SerializerTypes";
+export { CryptoProvider } from "./crypto/CryptoProvider";
+export type { AuthorizationCodeRequest } from "./request/AuthorizationCodeRequest";
+export type { AuthorizationUrlRequest } from "./request/AuthorizationUrlRequest";
+export type { ClientCredentialRequest } from "./request/ClientCredentialRequest";
+export type { DeviceCodeRequest } from "./request/DeviceCodeRequest";
+export type { OnBehalfOfRequest } from "./request/OnBehalfOfRequest";
+export type { UsernamePasswordRequest } from "./request/UsernamePasswordRequest";
+export type { RefreshTokenRequest } from "./request/RefreshTokenRequest";
+export type { SilentFlowRequest } from "./request/SilentFlowRequest";
+export { PromptValue, ResponseMode, AuthenticationResult, AccountInfo, ValidCacheType, AuthError, AuthErrorMessage, InteractionRequiredAuthError, ServerError, ClientAuthError, ClientAuthErrorMessage, ClientConfigurationError, ClientConfigurationErrorMessage, INetworkModule, NetworkRequestOptions, NetworkResponse, Logger, LogLevel, ProtocolMode, ICachePlugin, TokenCacheContext, ISerializableTokenCache } from "@azure/msal-common";
+//# sourceMappingURL=index.d.ts.map
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/index.d.ts.map b/node_modules/@azure/msal-node/dist/index.d.ts.map
new file mode 100644
index 0000000..ae6839f
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/index.d.ts.map
@@ -0,0 +1 @@
+{"version":3,"file":"index.d.ts","sourceRoot":"","sources":["src/index.ts"],"names":[],"mappings":"AAKA;;;GAGG;AAGH,OAAO,EAAE,wBAAwB,EAAE,MAAM,mCAAmC,CAAC;AAC7E,OAAO,EAAE,8BAA8B,EAAE,MAAM,yCAAyC,CAAC;AACzF,OAAO,EAAE,WAAW,EAAE,MAAM,qBAAqB,CAAC;AAGlD,OAAO,EAAE,uBAAuB,EAAE,MAAM,kCAAkC,CAAC;AAC3E,OAAO,EAAE,6BAA6B,EAAE,MAAM,wCAAwC,CAAC;AACvF,OAAO,EAAE,iBAAiB,EAAE,MAAM,4BAA4B,CAAC;AAC/D,OAAO,EAAE,aAAa,EAAE,qBAAqB,EAAE,eAAe,EAAE,iBAAiB,EAAE,YAAY,EAAE,MAAM,wBAAwB,CAAC;AAChI,OAAO,EAAE,eAAe,EAAE,MAAM,0BAA0B,CAAC;AAG3D,OAAO,EAAE,UAAU,EAAE,MAAM,oBAAoB,CAAC;AAChD,OAAO,EAAE,WAAW,EAAE,MAAM,qBAAqB,CAAC;AAClD,OAAO,EAAE,YAAY,EAAE,SAAS,EAAE,aAAa,EAAE,uBAAuB,EAAE,uBAAuB,EAAE,2BAA2B,EAAE,2BAA2B,EAAE,4BAA4B,EAAE,MAAM,oCAAoC,CAAC;AAGtO,OAAO,EAAE,cAAc,EAAE,MAAM,yBAAyB,CAAC;AAGzD,YAAY,EAAE,wBAAwB,EAAE,MAAM,oCAAoC,CAAC;AACnF,YAAY,EAAE,uBAAuB,EAAE,MAAM,mCAAmC,CAAC;AACjF,YAAY,EAAE,uBAAuB,EAAE,MAAM,mCAAmC,CAAC;AACjF,YAAY,EAAE,iBAAiB,EAAE,MAAM,6BAA6B,CAAC;AACrE,YAAY,EAAE,iBAAiB,EAAE,MAAM,6BAA6B,CAAC;AACrE,YAAY,EAAE,uBAAuB,EAAE,MAAM,mCAAmC,CAAC;AACjF,YAAY,EAAE,mBAAmB,EAAE,MAAM,+BAA+B,CAAC;AACzE,YAAY,EAAE,iBAAiB,EAAE,MAAM,6BAA6B,CAAC;AAGrE,OAAO,EAEH,WAAW,EACX,YAAY,EAEZ,oBAAoB,EAEpB,WAAW,EACX,cAAc,EAEd,SAAS,EACT,gBAAgB,EAChB,4BAA4B,EAC5B,WAAW,EACX,eAAe,EACf,sBAAsB,EACtB,wBAAwB,EACxB,+BAA+B,EAE/B,cAAc,EACd,qBAAqB,EACrB,eAAe,EAEf,MAAM,EACN,QAAQ,EAER,YAAY,EACZ,YAAY,EACZ,iBAAiB,EACjB,uBAAuB,EAC1B,MAAM,oBAAoB,CAAC"}
\ No newline at end of file
diff --git a/node_modules/@azure/msal-node/dist/index.js b/node_modules/@azure/msal-node/dist/index.js
new file mode 100644
index 0000000..4e0a220
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/index.js
@@ -0,0 +1,8 @@
+
+'use strict'
+
+if (process.env.NODE_ENV === 'production') {
+ module.exports = require('./msal-node.cjs.production.min.js')
+} else {
+ module.exports = require('./msal-node.cjs.development.js')
+}
diff --git a/node_modules/@azure/msal-node/dist/msal-node.cjs.development.js b/node_modules/@azure/msal-node/dist/msal-node.cjs.development.js
new file mode 100644
index 0000000..d00b2bf
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/msal-node.cjs.development.js
@@ -0,0 +1,3459 @@
+'use strict';
+
+Object.defineProperty(exports, '__esModule', { value: true });
+
+function _interopDefault (ex) { return (ex && (typeof ex === 'object') && 'default' in ex) ? ex['default'] : ex; }
+
+var msalCommon = require('@azure/msal-common');
+var axios = _interopDefault(require('axios'));
+var uuid = require('uuid');
+var crypto = _interopDefault(require('crypto'));
+var jsonwebtoken = require('jsonwebtoken');
+
+function asyncGeneratorStep(gen, resolve, reject, _next, _throw, key, arg) {
+ try {
+ var info = gen[key](arg);
+ var value = info.value;
+ } catch (error) {
+ reject(error);
+ return;
+ }
+
+ if (info.done) {
+ resolve(value);
+ } else {
+ Promise.resolve(value).then(_next, _throw);
+ }
+}
+
+function _asyncToGenerator(fn) {
+ return function () {
+ var self = this,
+ args = arguments;
+ return new Promise(function (resolve, reject) {
+ var gen = fn.apply(self, args);
+
+ function _next(value) {
+ asyncGeneratorStep(gen, resolve, reject, _next, _throw, "next", value);
+ }
+
+ function _throw(err) {
+ asyncGeneratorStep(gen, resolve, reject, _next, _throw, "throw", err);
+ }
+
+ _next(undefined);
+ });
+ };
+}
+
+function _extends() {
+ _extends = Object.assign || function (target) {
+ for (var i = 1; i < arguments.length; i++) {
+ var source = arguments[i];
+
+ for (var key in source) {
+ if (Object.prototype.hasOwnProperty.call(source, key)) {
+ target[key] = source[key];
+ }
+ }
+ }
+
+ return target;
+ };
+
+ return _extends.apply(this, arguments);
+}
+
+function _inheritsLoose(subClass, superClass) {
+ subClass.prototype = Object.create(superClass.prototype);
+ subClass.prototype.constructor = subClass;
+ subClass.__proto__ = superClass;
+}
+
+function createCommonjsModule(fn, module) {
+ return module = { exports: {} }, fn(module, module.exports), module.exports;
+}
+
+var runtime_1 = createCommonjsModule(function (module) {
+/**
+ * Copyright (c) 2014-present, Facebook, Inc.
+ *
+ * This source code is licensed under the MIT license found in the
+ * LICENSE file in the root directory of this source tree.
+ */
+
+var runtime = (function (exports) {
+
+ var Op = Object.prototype;
+ var hasOwn = Op.hasOwnProperty;
+ var undefined$1; // More compressible than void 0.
+ var $Symbol = typeof Symbol === "function" ? Symbol : {};
+ var iteratorSymbol = $Symbol.iterator || "@@iterator";
+ var asyncIteratorSymbol = $Symbol.asyncIterator || "@@asyncIterator";
+ var toStringTagSymbol = $Symbol.toStringTag || "@@toStringTag";
+
+ function define(obj, key, value) {
+ Object.defineProperty(obj, key, {
+ value: value,
+ enumerable: true,
+ configurable: true,
+ writable: true
+ });
+ return obj[key];
+ }
+ try {
+ // IE 8 has a broken Object.defineProperty that only works on DOM objects.
+ define({}, "");
+ } catch (err) {
+ define = function(obj, key, value) {
+ return obj[key] = value;
+ };
+ }
+
+ function wrap(innerFn, outerFn, self, tryLocsList) {
+ // If outerFn provided and outerFn.prototype is a Generator, then outerFn.prototype instanceof Generator.
+ var protoGenerator = outerFn && outerFn.prototype instanceof Generator ? outerFn : Generator;
+ var generator = Object.create(protoGenerator.prototype);
+ var context = new Context(tryLocsList || []);
+
+ // The ._invoke method unifies the implementations of the .next,
+ // .throw, and .return methods.
+ generator._invoke = makeInvokeMethod(innerFn, self, context);
+
+ return generator;
+ }
+ exports.wrap = wrap;
+
+ // Try/catch helper to minimize deoptimizations. Returns a completion
+ // record like context.tryEntries[i].completion. This interface could
+ // have been (and was previously) designed to take a closure to be
+ // invoked without arguments, but in all the cases we care about we
+ // already have an existing method we want to call, so there's no need
+ // to create a new function object. We can even get away with assuming
+ // the method takes exactly one argument, since that happens to be true
+ // in every case, so we don't have to touch the arguments object. The
+ // only additional allocation required is the completion record, which
+ // has a stable shape and so hopefully should be cheap to allocate.
+ function tryCatch(fn, obj, arg) {
+ try {
+ return { type: "normal", arg: fn.call(obj, arg) };
+ } catch (err) {
+ return { type: "throw", arg: err };
+ }
+ }
+
+ var GenStateSuspendedStart = "suspendedStart";
+ var GenStateSuspendedYield = "suspendedYield";
+ var GenStateExecuting = "executing";
+ var GenStateCompleted = "completed";
+
+ // Returning this object from the innerFn has the same effect as
+ // breaking out of the dispatch switch statement.
+ var ContinueSentinel = {};
+
+ // Dummy constructor functions that we use as the .constructor and
+ // .constructor.prototype properties for functions that return Generator
+ // objects. For full spec compliance, you may wish to configure your
+ // minifier not to mangle the names of these two functions.
+ function Generator() {}
+ function GeneratorFunction() {}
+ function GeneratorFunctionPrototype() {}
+
+ // This is a polyfill for %IteratorPrototype% for environments that
+ // don't natively support it.
+ var IteratorPrototype = {};
+ IteratorPrototype[iteratorSymbol] = function () {
+ return this;
+ };
+
+ var getProto = Object.getPrototypeOf;
+ var NativeIteratorPrototype = getProto && getProto(getProto(values([])));
+ if (NativeIteratorPrototype &&
+ NativeIteratorPrototype !== Op &&
+ hasOwn.call(NativeIteratorPrototype, iteratorSymbol)) {
+ // This environment has a native %IteratorPrototype%; use it instead
+ // of the polyfill.
+ IteratorPrototype = NativeIteratorPrototype;
+ }
+
+ var Gp = GeneratorFunctionPrototype.prototype =
+ Generator.prototype = Object.create(IteratorPrototype);
+ GeneratorFunction.prototype = Gp.constructor = GeneratorFunctionPrototype;
+ GeneratorFunctionPrototype.constructor = GeneratorFunction;
+ GeneratorFunction.displayName = define(
+ GeneratorFunctionPrototype,
+ toStringTagSymbol,
+ "GeneratorFunction"
+ );
+
+ // Helper for defining the .next, .throw, and .return methods of the
+ // Iterator interface in terms of a single ._invoke method.
+ function defineIteratorMethods(prototype) {
+ ["next", "throw", "return"].forEach(function(method) {
+ define(prototype, method, function(arg) {
+ return this._invoke(method, arg);
+ });
+ });
+ }
+
+ exports.isGeneratorFunction = function(genFun) {
+ var ctor = typeof genFun === "function" && genFun.constructor;
+ return ctor
+ ? ctor === GeneratorFunction ||
+ // For the native GeneratorFunction constructor, the best we can
+ // do is to check its .name property.
+ (ctor.displayName || ctor.name) === "GeneratorFunction"
+ : false;
+ };
+
+ exports.mark = function(genFun) {
+ if (Object.setPrototypeOf) {
+ Object.setPrototypeOf(genFun, GeneratorFunctionPrototype);
+ } else {
+ genFun.__proto__ = GeneratorFunctionPrototype;
+ define(genFun, toStringTagSymbol, "GeneratorFunction");
+ }
+ genFun.prototype = Object.create(Gp);
+ return genFun;
+ };
+
+ // Within the body of any async function, `await x` is transformed to
+ // `yield regeneratorRuntime.awrap(x)`, so that the runtime can test
+ // `hasOwn.call(value, "__await")` to determine if the yielded value is
+ // meant to be awaited.
+ exports.awrap = function(arg) {
+ return { __await: arg };
+ };
+
+ function AsyncIterator(generator, PromiseImpl) {
+ function invoke(method, arg, resolve, reject) {
+ var record = tryCatch(generator[method], generator, arg);
+ if (record.type === "throw") {
+ reject(record.arg);
+ } else {
+ var result = record.arg;
+ var value = result.value;
+ if (value &&
+ typeof value === "object" &&
+ hasOwn.call(value, "__await")) {
+ return PromiseImpl.resolve(value.__await).then(function(value) {
+ invoke("next", value, resolve, reject);
+ }, function(err) {
+ invoke("throw", err, resolve, reject);
+ });
+ }
+
+ return PromiseImpl.resolve(value).then(function(unwrapped) {
+ // When a yielded Promise is resolved, its final value becomes
+ // the .value of the Promise<{value,done}> result for the
+ // current iteration.
+ result.value = unwrapped;
+ resolve(result);
+ }, function(error) {
+ // If a rejected Promise was yielded, throw the rejection back
+ // into the async generator function so it can be handled there.
+ return invoke("throw", error, resolve, reject);
+ });
+ }
+ }
+
+ var previousPromise;
+
+ function enqueue(method, arg) {
+ function callInvokeWithMethodAndArg() {
+ return new PromiseImpl(function(resolve, reject) {
+ invoke(method, arg, resolve, reject);
+ });
+ }
+
+ return previousPromise =
+ // If enqueue has been called before, then we want to wait until
+ // all previous Promises have been resolved before calling invoke,
+ // so that results are always delivered in the correct order. If
+ // enqueue has not been called before, then it is important to
+ // call invoke immediately, without waiting on a callback to fire,
+ // so that the async generator function has the opportunity to do
+ // any necessary setup in a predictable way. This predictability
+ // is why the Promise constructor synchronously invokes its
+ // executor callback, and why async functions synchronously
+ // execute code before the first await. Since we implement simple
+ // async functions in terms of async generators, it is especially
+ // important to get this right, even though it requires care.
+ previousPromise ? previousPromise.then(
+ callInvokeWithMethodAndArg,
+ // Avoid propagating failures to Promises returned by later
+ // invocations of the iterator.
+ callInvokeWithMethodAndArg
+ ) : callInvokeWithMethodAndArg();
+ }
+
+ // Define the unified helper method that is used to implement .next,
+ // .throw, and .return (see defineIteratorMethods).
+ this._invoke = enqueue;
+ }
+
+ defineIteratorMethods(AsyncIterator.prototype);
+ AsyncIterator.prototype[asyncIteratorSymbol] = function () {
+ return this;
+ };
+ exports.AsyncIterator = AsyncIterator;
+
+ // Note that simple async functions are implemented on top of
+ // AsyncIterator objects; they just return a Promise for the value of
+ // the final result produced by the iterator.
+ exports.async = function(innerFn, outerFn, self, tryLocsList, PromiseImpl) {
+ if (PromiseImpl === void 0) PromiseImpl = Promise;
+
+ var iter = new AsyncIterator(
+ wrap(innerFn, outerFn, self, tryLocsList),
+ PromiseImpl
+ );
+
+ return exports.isGeneratorFunction(outerFn)
+ ? iter // If outerFn is a generator, return the full iterator.
+ : iter.next().then(function(result) {
+ return result.done ? result.value : iter.next();
+ });
+ };
+
+ function makeInvokeMethod(innerFn, self, context) {
+ var state = GenStateSuspendedStart;
+
+ return function invoke(method, arg) {
+ if (state === GenStateExecuting) {
+ throw new Error("Generator is already running");
+ }
+
+ if (state === GenStateCompleted) {
+ if (method === "throw") {
+ throw arg;
+ }
+
+ // Be forgiving, per 25.3.3.3.3 of the spec:
+ // https://people.mozilla.org/~jorendorff/es6-draft.html#sec-generatorresume
+ return doneResult();
+ }
+
+ context.method = method;
+ context.arg = arg;
+
+ while (true) {
+ var delegate = context.delegate;
+ if (delegate) {
+ var delegateResult = maybeInvokeDelegate(delegate, context);
+ if (delegateResult) {
+ if (delegateResult === ContinueSentinel) continue;
+ return delegateResult;
+ }
+ }
+
+ if (context.method === "next") {
+ // Setting context._sent for legacy support of Babel's
+ // function.sent implementation.
+ context.sent = context._sent = context.arg;
+
+ } else if (context.method === "throw") {
+ if (state === GenStateSuspendedStart) {
+ state = GenStateCompleted;
+ throw context.arg;
+ }
+
+ context.dispatchException(context.arg);
+
+ } else if (context.method === "return") {
+ context.abrupt("return", context.arg);
+ }
+
+ state = GenStateExecuting;
+
+ var record = tryCatch(innerFn, self, context);
+ if (record.type === "normal") {
+ // If an exception is thrown from innerFn, we leave state ===
+ // GenStateExecuting and loop back for another invocation.
+ state = context.done
+ ? GenStateCompleted
+ : GenStateSuspendedYield;
+
+ if (record.arg === ContinueSentinel) {
+ continue;
+ }
+
+ return {
+ value: record.arg,
+ done: context.done
+ };
+
+ } else if (record.type === "throw") {
+ state = GenStateCompleted;
+ // Dispatch the exception by looping back around to the
+ // context.dispatchException(context.arg) call above.
+ context.method = "throw";
+ context.arg = record.arg;
+ }
+ }
+ };
+ }
+
+ // Call delegate.iterator[context.method](context.arg) and handle the
+ // result, either by returning a { value, done } result from the
+ // delegate iterator, or by modifying context.method and context.arg,
+ // setting context.delegate to null, and returning the ContinueSentinel.
+ function maybeInvokeDelegate(delegate, context) {
+ var method = delegate.iterator[context.method];
+ if (method === undefined$1) {
+ // A .throw or .return when the delegate iterator has no .throw
+ // method always terminates the yield* loop.
+ context.delegate = null;
+
+ if (context.method === "throw") {
+ // Note: ["return"] must be used for ES3 parsing compatibility.
+ if (delegate.iterator["return"]) {
+ // If the delegate iterator has a return method, give it a
+ // chance to clean up.
+ context.method = "return";
+ context.arg = undefined$1;
+ maybeInvokeDelegate(delegate, context);
+
+ if (context.method === "throw") {
+ // If maybeInvokeDelegate(context) changed context.method from
+ // "return" to "throw", let that override the TypeError below.
+ return ContinueSentinel;
+ }
+ }
+
+ context.method = "throw";
+ context.arg = new TypeError(
+ "The iterator does not provide a 'throw' method");
+ }
+
+ return ContinueSentinel;
+ }
+
+ var record = tryCatch(method, delegate.iterator, context.arg);
+
+ if (record.type === "throw") {
+ context.method = "throw";
+ context.arg = record.arg;
+ context.delegate = null;
+ return ContinueSentinel;
+ }
+
+ var info = record.arg;
+
+ if (! info) {
+ context.method = "throw";
+ context.arg = new TypeError("iterator result is not an object");
+ context.delegate = null;
+ return ContinueSentinel;
+ }
+
+ if (info.done) {
+ // Assign the result of the finished delegate to the temporary
+ // variable specified by delegate.resultName (see delegateYield).
+ context[delegate.resultName] = info.value;
+
+ // Resume execution at the desired location (see delegateYield).
+ context.next = delegate.nextLoc;
+
+ // If context.method was "throw" but the delegate handled the
+ // exception, let the outer generator proceed normally. If
+ // context.method was "next", forget context.arg since it has been
+ // "consumed" by the delegate iterator. If context.method was
+ // "return", allow the original .return call to continue in the
+ // outer generator.
+ if (context.method !== "return") {
+ context.method = "next";
+ context.arg = undefined$1;
+ }
+
+ } else {
+ // Re-yield the result returned by the delegate method.
+ return info;
+ }
+
+ // The delegate iterator is finished, so forget it and continue with
+ // the outer generator.
+ context.delegate = null;
+ return ContinueSentinel;
+ }
+
+ // Define Generator.prototype.{next,throw,return} in terms of the
+ // unified ._invoke helper method.
+ defineIteratorMethods(Gp);
+
+ define(Gp, toStringTagSymbol, "Generator");
+
+ // A Generator should always return itself as the iterator object when the
+ // @@iterator function is called on it. Some browsers' implementations of the
+ // iterator prototype chain incorrectly implement this, causing the Generator
+ // object to not be returned from this call. This ensures that doesn't happen.
+ // See https://github.com/facebook/regenerator/issues/274 for more details.
+ Gp[iteratorSymbol] = function() {
+ return this;
+ };
+
+ Gp.toString = function() {
+ return "[object Generator]";
+ };
+
+ function pushTryEntry(locs) {
+ var entry = { tryLoc: locs[0] };
+
+ if (1 in locs) {
+ entry.catchLoc = locs[1];
+ }
+
+ if (2 in locs) {
+ entry.finallyLoc = locs[2];
+ entry.afterLoc = locs[3];
+ }
+
+ this.tryEntries.push(entry);
+ }
+
+ function resetTryEntry(entry) {
+ var record = entry.completion || {};
+ record.type = "normal";
+ delete record.arg;
+ entry.completion = record;
+ }
+
+ function Context(tryLocsList) {
+ // The root entry object (effectively a try statement without a catch
+ // or a finally block) gives us a place to store values thrown from
+ // locations where there is no enclosing try statement.
+ this.tryEntries = [{ tryLoc: "root" }];
+ tryLocsList.forEach(pushTryEntry, this);
+ this.reset(true);
+ }
+
+ exports.keys = function(object) {
+ var keys = [];
+ for (var key in object) {
+ keys.push(key);
+ }
+ keys.reverse();
+
+ // Rather than returning an object with a next method, we keep
+ // things simple and return the next function itself.
+ return function next() {
+ while (keys.length) {
+ var key = keys.pop();
+ if (key in object) {
+ next.value = key;
+ next.done = false;
+ return next;
+ }
+ }
+
+ // To avoid creating an additional object, we just hang the .value
+ // and .done properties off the next function object itself. This
+ // also ensures that the minifier will not anonymize the function.
+ next.done = true;
+ return next;
+ };
+ };
+
+ function values(iterable) {
+ if (iterable) {
+ var iteratorMethod = iterable[iteratorSymbol];
+ if (iteratorMethod) {
+ return iteratorMethod.call(iterable);
+ }
+
+ if (typeof iterable.next === "function") {
+ return iterable;
+ }
+
+ if (!isNaN(iterable.length)) {
+ var i = -1, next = function next() {
+ while (++i < iterable.length) {
+ if (hasOwn.call(iterable, i)) {
+ next.value = iterable[i];
+ next.done = false;
+ return next;
+ }
+ }
+
+ next.value = undefined$1;
+ next.done = true;
+
+ return next;
+ };
+
+ return next.next = next;
+ }
+ }
+
+ // Return an iterator with no values.
+ return { next: doneResult };
+ }
+ exports.values = values;
+
+ function doneResult() {
+ return { value: undefined$1, done: true };
+ }
+
+ Context.prototype = {
+ constructor: Context,
+
+ reset: function(skipTempReset) {
+ this.prev = 0;
+ this.next = 0;
+ // Resetting context._sent for legacy support of Babel's
+ // function.sent implementation.
+ this.sent = this._sent = undefined$1;
+ this.done = false;
+ this.delegate = null;
+
+ this.method = "next";
+ this.arg = undefined$1;
+
+ this.tryEntries.forEach(resetTryEntry);
+
+ if (!skipTempReset) {
+ for (var name in this) {
+ // Not sure about the optimal order of these conditions:
+ if (name.charAt(0) === "t" &&
+ hasOwn.call(this, name) &&
+ !isNaN(+name.slice(1))) {
+ this[name] = undefined$1;
+ }
+ }
+ }
+ },
+
+ stop: function() {
+ this.done = true;
+
+ var rootEntry = this.tryEntries[0];
+ var rootRecord = rootEntry.completion;
+ if (rootRecord.type === "throw") {
+ throw rootRecord.arg;
+ }
+
+ return this.rval;
+ },
+
+ dispatchException: function(exception) {
+ if (this.done) {
+ throw exception;
+ }
+
+ var context = this;
+ function handle(loc, caught) {
+ record.type = "throw";
+ record.arg = exception;
+ context.next = loc;
+
+ if (caught) {
+ // If the dispatched exception was caught by a catch block,
+ // then let that catch block handle the exception normally.
+ context.method = "next";
+ context.arg = undefined$1;
+ }
+
+ return !! caught;
+ }
+
+ for (var i = this.tryEntries.length - 1; i >= 0; --i) {
+ var entry = this.tryEntries[i];
+ var record = entry.completion;
+
+ if (entry.tryLoc === "root") {
+ // Exception thrown outside of any try block that could handle
+ // it, so set the completion value of the entire function to
+ // throw the exception.
+ return handle("end");
+ }
+
+ if (entry.tryLoc <= this.prev) {
+ var hasCatch = hasOwn.call(entry, "catchLoc");
+ var hasFinally = hasOwn.call(entry, "finallyLoc");
+
+ if (hasCatch && hasFinally) {
+ if (this.prev < entry.catchLoc) {
+ return handle(entry.catchLoc, true);
+ } else if (this.prev < entry.finallyLoc) {
+ return handle(entry.finallyLoc);
+ }
+
+ } else if (hasCatch) {
+ if (this.prev < entry.catchLoc) {
+ return handle(entry.catchLoc, true);
+ }
+
+ } else if (hasFinally) {
+ if (this.prev < entry.finallyLoc) {
+ return handle(entry.finallyLoc);
+ }
+
+ } else {
+ throw new Error("try statement without catch or finally");
+ }
+ }
+ }
+ },
+
+ abrupt: function(type, arg) {
+ for (var i = this.tryEntries.length - 1; i >= 0; --i) {
+ var entry = this.tryEntries[i];
+ if (entry.tryLoc <= this.prev &&
+ hasOwn.call(entry, "finallyLoc") &&
+ this.prev < entry.finallyLoc) {
+ var finallyEntry = entry;
+ break;
+ }
+ }
+
+ if (finallyEntry &&
+ (type === "break" ||
+ type === "continue") &&
+ finallyEntry.tryLoc <= arg &&
+ arg <= finallyEntry.finallyLoc) {
+ // Ignore the finally entry if control is not jumping to a
+ // location outside the try/catch block.
+ finallyEntry = null;
+ }
+
+ var record = finallyEntry ? finallyEntry.completion : {};
+ record.type = type;
+ record.arg = arg;
+
+ if (finallyEntry) {
+ this.method = "next";
+ this.next = finallyEntry.finallyLoc;
+ return ContinueSentinel;
+ }
+
+ return this.complete(record);
+ },
+
+ complete: function(record, afterLoc) {
+ if (record.type === "throw") {
+ throw record.arg;
+ }
+
+ if (record.type === "break" ||
+ record.type === "continue") {
+ this.next = record.arg;
+ } else if (record.type === "return") {
+ this.rval = this.arg = record.arg;
+ this.method = "return";
+ this.next = "end";
+ } else if (record.type === "normal" && afterLoc) {
+ this.next = afterLoc;
+ }
+
+ return ContinueSentinel;
+ },
+
+ finish: function(finallyLoc) {
+ for (var i = this.tryEntries.length - 1; i >= 0; --i) {
+ var entry = this.tryEntries[i];
+ if (entry.finallyLoc === finallyLoc) {
+ this.complete(entry.completion, entry.afterLoc);
+ resetTryEntry(entry);
+ return ContinueSentinel;
+ }
+ }
+ },
+
+ "catch": function(tryLoc) {
+ for (var i = this.tryEntries.length - 1; i >= 0; --i) {
+ var entry = this.tryEntries[i];
+ if (entry.tryLoc === tryLoc) {
+ var record = entry.completion;
+ if (record.type === "throw") {
+ var thrown = record.arg;
+ resetTryEntry(entry);
+ }
+ return thrown;
+ }
+ }
+
+ // The context.catch method must only be called with a location
+ // argument that corresponds to a known catch block.
+ throw new Error("illegal catch attempt");
+ },
+
+ delegateYield: function(iterable, resultName, nextLoc) {
+ this.delegate = {
+ iterator: values(iterable),
+ resultName: resultName,
+ nextLoc: nextLoc
+ };
+
+ if (this.method === "next") {
+ // Deliberately forget the last sent value so that we don't
+ // accidentally pass it on to the delegate.
+ this.arg = undefined$1;
+ }
+
+ return ContinueSentinel;
+ }
+ };
+
+ // Regardless of whether this script is executing as a CommonJS module
+ // or not, return the runtime object so that we can declare the variable
+ // regeneratorRuntime in the outer scope, which allows this module to be
+ // injected easily by `bin/regenerator --include-runtime script.js`.
+ return exports;
+
+}(
+ // If this script is executing as a CommonJS module, use module.exports
+ // as the regeneratorRuntime namespace. Otherwise create a new empty
+ // object. Either way, the resulting object will be used to initialize
+ // the regeneratorRuntime variable at the top of this file.
+ module.exports
+));
+
+try {
+ regeneratorRuntime = runtime;
+} catch (accidentalStrictMode) {
+ // This module should not be running in strict mode, so the above
+ // assignment should always work unless something is misconfigured. Just
+ // in case runtime.js accidentally runs in strict mode, we can escape
+ // strict mode using a global Function call. This could conceivably fail
+ // if a Content Security Policy forbids using Function, but in that case
+ // the proper solution is to fix the accidental strict mode problem. If
+ // you've misconfigured your bundler to force strict mode and applied a
+ // CSP to forbid Function, and you're not willing to fix either of those
+ // problems, please detail your unique predicament in a GitHub issue.
+ Function("r", "regeneratorRuntime = r")(runtime);
+}
+});
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+
+/**
+ * http methods
+ */
+var HttpMethod;
+
+(function (HttpMethod) {
+ HttpMethod["GET"] = "get";
+ HttpMethod["POST"] = "post";
+})(HttpMethod || (HttpMethod = {}));
+/**
+ * Constant used for PKCE
+ */
+
+
+var RANDOM_OCTET_SIZE = 32;
+/**
+ * Constants used in PKCE
+ */
+
+var Hash = {
+ SHA256: "sha256"
+};
+/**
+ * Constants for encoding schemes
+ */
+
+var CharSet = {
+ CV_CHARSET: "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-._~"
+};
+/**
+ * Constants
+ */
+
+var Constants = {
+ MSAL_SKU: "msal.js.node",
+ JWT_BEARER_ASSERTION_TYPE: "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
+};
+/**
+ * API Codes for Telemetry purposes.
+ * Before adding a new code you must claim it in the MSAL Telemetry tracker as these number spaces are shared across all MSALs
+ * 0-99 Silent Flow
+ * 600-699 Device Code Flow
+ * 800-899 Auth Code Flow
+ */
+
+var ApiId;
+
+(function (ApiId) {
+ ApiId[ApiId["acquireTokenSilent"] = 62] = "acquireTokenSilent";
+ ApiId[ApiId["acquireTokenByUsernamePassword"] = 371] = "acquireTokenByUsernamePassword";
+ ApiId[ApiId["acquireTokenByDeviceCode"] = 671] = "acquireTokenByDeviceCode";
+ ApiId[ApiId["acquireTokenByClientCredential"] = 771] = "acquireTokenByClientCredential";
+ ApiId[ApiId["acquireTokenByCode"] = 871] = "acquireTokenByCode";
+ ApiId[ApiId["acquireTokenByRefreshToken"] = 872] = "acquireTokenByRefreshToken";
+})(ApiId || (ApiId = {}));
+/**
+ * JWT constants
+ */
+
+
+var JwtConstants = {
+ ALGORITHM: "alg",
+ RSA_256: "RS256",
+ X5T: "x5t",
+ X5C: "x5c",
+ AUDIENCE: "aud",
+ EXPIRATION_TIME: "exp",
+ ISSUER: "iss",
+ SUBJECT: "sub",
+ NOT_BEFORE: "nbf",
+ JWT_ID: "jti"
+};
+
+/**
+ * This class implements the API for network requests.
+ */
+
+var HttpClient = /*#__PURE__*/function () {
+ function HttpClient() {}
+
+ var _proto = HttpClient.prototype;
+
+ /**
+ * Http Get request
+ * @param url
+ * @param options
+ */
+ _proto.sendGetRequestAsync =
+ /*#__PURE__*/
+ function () {
+ var _sendGetRequestAsync = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee(url, options) {
+ var request, response;
+ return runtime_1.wrap(function _callee$(_context) {
+ while (1) {
+ switch (_context.prev = _context.next) {
+ case 0:
+ request = {
+ method: HttpMethod.GET,
+ url: url,
+ headers: options && options.headers,
+ validateStatus: function validateStatus() {
+ return true;
+ }
+ };
+ _context.next = 3;
+ return axios(request);
+
+ case 3:
+ response = _context.sent;
+ return _context.abrupt("return", {
+ headers: response.headers,
+ body: response.data,
+ status: response.status
+ });
+
+ case 5:
+ case "end":
+ return _context.stop();
+ }
+ }
+ }, _callee);
+ }));
+
+ function sendGetRequestAsync(_x, _x2) {
+ return _sendGetRequestAsync.apply(this, arguments);
+ }
+
+ return sendGetRequestAsync;
+ }()
+ /**
+ * Http Post request
+ * @param url
+ * @param options
+ */
+ ;
+
+ _proto.sendPostRequestAsync =
+ /*#__PURE__*/
+ function () {
+ var _sendPostRequestAsync = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee2(url, options) {
+ var request, response;
+ return runtime_1.wrap(function _callee2$(_context2) {
+ while (1) {
+ switch (_context2.prev = _context2.next) {
+ case 0:
+ request = {
+ method: HttpMethod.POST,
+ url: url,
+ data: options && options.body || "",
+ headers: options && options.headers,
+ validateStatus: function validateStatus() {
+ return true;
+ }
+ };
+ _context2.next = 3;
+ return axios(request);
+
+ case 3:
+ response = _context2.sent;
+ return _context2.abrupt("return", {
+ headers: response.headers,
+ body: response.data,
+ status: response.status
+ });
+
+ case 5:
+ case "end":
+ return _context2.stop();
+ }
+ }
+ }, _callee2);
+ }));
+
+ function sendPostRequestAsync(_x3, _x4) {
+ return _sendPostRequestAsync.apply(this, arguments);
+ }
+
+ return sendPostRequestAsync;
+ }();
+
+ return HttpClient;
+}();
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var NetworkUtils = /*#__PURE__*/function () {
+ function NetworkUtils() {}
+
+ /**
+ * Returns best compatible network client object.
+ */
+ NetworkUtils.getNetworkClient = function getNetworkClient() {
+ return new HttpClient();
+ };
+
+ return NetworkUtils;
+}();
+
+var DEFAULT_AUTH_OPTIONS = {
+ clientId: "",
+ authority: msalCommon.Constants.DEFAULT_AUTHORITY,
+ clientSecret: "",
+ clientAssertion: "",
+ clientCertificate: {
+ thumbprint: "",
+ privateKey: "",
+ x5c: ""
+ },
+ knownAuthorities: [],
+ cloudDiscoveryMetadata: "",
+ authorityMetadata: "",
+ clientCapabilities: [],
+ protocolMode: msalCommon.ProtocolMode.AAD
+};
+var DEFAULT_CACHE_OPTIONS = {};
+var DEFAULT_LOGGER_OPTIONS = {
+ loggerCallback: function loggerCallback() {// allow users to not set logger call back
+ },
+ piiLoggingEnabled: false,
+ logLevel: msalCommon.LogLevel.Info
+};
+var DEFAULT_SYSTEM_OPTIONS = {
+ loggerOptions: DEFAULT_LOGGER_OPTIONS,
+ networkClient: /*#__PURE__*/NetworkUtils.getNetworkClient()
+};
+/**
+ * Sets the default options when not explicitly configured from app developer
+ *
+ * @param auth - Authentication options
+ * @param cache - Cache options
+ * @param system - System options
+ *
+ * @returns Configuration
+ * @public
+ */
+
+function buildAppConfiguration(_ref) {
+ var auth = _ref.auth,
+ cache = _ref.cache,
+ system = _ref.system;
+ return {
+ auth: _extends({}, DEFAULT_AUTH_OPTIONS, auth),
+ cache: _extends({}, DEFAULT_CACHE_OPTIONS, cache),
+ system: _extends({}, DEFAULT_SYSTEM_OPTIONS, system)
+ };
+}
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var GuidGenerator = /*#__PURE__*/function () {
+ function GuidGenerator() {}
+
+ /**
+ *
+ * RFC4122: The version 4 UUID is meant for generating UUIDs from truly-random or pseudo-random numbers.
+ * uuidv4 generates guids from cryprtographically-string random
+ */
+ GuidGenerator.generateGuid = function generateGuid() {
+ return uuid.v4();
+ }
+ /**
+ * verifies if a string is GUID
+ * @param guid
+ */
+ ;
+
+ GuidGenerator.isGuid = function isGuid(guid) {
+ var regexGuid = /^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;
+ return regexGuid.test(guid);
+ };
+
+ return GuidGenerator;
+}();
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var EncodingUtils = /*#__PURE__*/function () {
+ function EncodingUtils() {}
+
+ /**
+ * 'utf8': Multibyte encoded Unicode characters. Many web pages and other document formats use UTF-8.
+ * 'base64': Base64 encoding.
+ *
+ * @param str text
+ */
+ EncodingUtils.base64Encode = function base64Encode(str, encoding) {
+ return Buffer.from(str, encoding).toString("base64");
+ }
+ /**
+ * encode a URL
+ * @param str
+ */
+ ;
+
+ EncodingUtils.base64EncodeUrl = function base64EncodeUrl(str, encoding) {
+ return EncodingUtils.base64Encode(str, encoding).replace(/=/g, "").replace(/\+/g, "-").replace(/\//g, "_");
+ }
+ /**
+ * 'utf8': Multibyte encoded Unicode characters. Many web pages and other document formats use UTF-8.
+ * 'base64': Base64 encoding.
+ *
+ * @param base64Str Base64 encoded text
+ */
+ ;
+
+ EncodingUtils.base64Decode = function base64Decode(base64Str) {
+ return Buffer.from(base64Str, "base64").toString("utf8");
+ }
+ /**
+ * @param base64Str Base64 encoded Url
+ */
+ ;
+
+ EncodingUtils.base64DecodeUrl = function base64DecodeUrl(base64Str) {
+ var str = base64Str.replace(/-/g, "+").replace(/_/g, "/");
+
+ while (str.length % 4) {
+ str += "=";
+ }
+
+ return EncodingUtils.base64Decode(str);
+ };
+
+ return EncodingUtils;
+}();
+
+/**
+ * https://tools.ietf.org/html/rfc7636#page-8
+ */
+
+var PkceGenerator = /*#__PURE__*/function () {
+ function PkceGenerator() {}
+
+ var _proto = PkceGenerator.prototype;
+
+ /**
+ * generates the codeVerfier and the challenge from the codeVerfier
+ * reference: https://tools.ietf.org/html/rfc7636#section-4.1 and https://tools.ietf.org/html/rfc7636#section-4.2
+ */
+ _proto.generatePkceCodes =
+ /*#__PURE__*/
+ function () {
+ var _generatePkceCodes = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee() {
+ var verifier, challenge;
+ return runtime_1.wrap(function _callee$(_context) {
+ while (1) {
+ switch (_context.prev = _context.next) {
+ case 0:
+ verifier = this.generateCodeVerifier();
+ challenge = this.generateCodeChallengeFromVerifier(verifier);
+ return _context.abrupt("return", {
+ verifier: verifier,
+ challenge: challenge
+ });
+
+ case 3:
+ case "end":
+ return _context.stop();
+ }
+ }
+ }, _callee, this);
+ }));
+
+ function generatePkceCodes() {
+ return _generatePkceCodes.apply(this, arguments);
+ }
+
+ return generatePkceCodes;
+ }()
+ /**
+ * generates the codeVerfier; reference: https://tools.ietf.org/html/rfc7636#section-4.1
+ */
+ ;
+
+ _proto.generateCodeVerifier = function generateCodeVerifier() {
+ var buffer = crypto.randomBytes(RANDOM_OCTET_SIZE);
+ var verifier = this.bufferToCVString(buffer);
+ return EncodingUtils.base64EncodeUrl(verifier);
+ }
+ /**
+ * generate the challenge from the codeVerfier; reference: https://tools.ietf.org/html/rfc7636#section-4.2
+ * @param codeVerifier
+ */
+ ;
+
+ _proto.generateCodeChallengeFromVerifier = function generateCodeChallengeFromVerifier(codeVerifier) {
+ return EncodingUtils.base64EncodeUrl(this.sha256(codeVerifier).toString("base64"), "base64");
+ }
+ /**
+ * generate 'SHA256' hash
+ * @param buffer
+ */
+ ;
+
+ _proto.sha256 = function sha256(buffer) {
+ return crypto.createHash(Hash.SHA256).update(buffer).digest();
+ }
+ /**
+ * Accepted characters; reference: https://tools.ietf.org/html/rfc7636#section-4.1
+ * @param buffer
+ */
+ ;
+
+ _proto.bufferToCVString = function bufferToCVString(buffer) {
+ var charArr = [];
+
+ for (var i = 0; i < buffer.byteLength; i += 1) {
+ var index = buffer[i] % CharSet.CV_CHARSET.length;
+ charArr.push(CharSet.CV_CHARSET[index]);
+ }
+
+ return charArr.join("");
+ };
+
+ return PkceGenerator;
+}();
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * This class implements MSAL node's crypto interface, which allows it to perform base64 encoding and decoding, generating cryptographically random GUIDs and
+ * implementing Proof Key for Code Exchange specs for the OAuth Authorization Code Flow using PKCE (rfc here: https://tools.ietf.org/html/rfc7636).
+ * @public
+ */
+
+var CryptoProvider = /*#__PURE__*/function () {
+ function CryptoProvider() {
+ // Browser crypto needs to be validated first before any other classes can be set.
+ this.pkceGenerator = new PkceGenerator();
+ }
+ /**
+ * Creates a new random GUID - used to populate state and nonce.
+ * @returns string (GUID)
+ */
+
+
+ var _proto = CryptoProvider.prototype;
+
+ _proto.createNewGuid = function createNewGuid() {
+ return GuidGenerator.generateGuid();
+ }
+ /**
+ * Encodes input string to base64.
+ * @param input - string to be encoded
+ */
+ ;
+
+ _proto.base64Encode = function base64Encode(input) {
+ return EncodingUtils.base64Encode(input);
+ }
+ /**
+ * Decodes input string from base64.
+ * @param input - string to be decoded
+ */
+ ;
+
+ _proto.base64Decode = function base64Decode(input) {
+ return EncodingUtils.base64Decode(input);
+ }
+ /**
+ * Generates PKCE codes used in Authorization Code Flow.
+ */
+ ;
+
+ _proto.generatePkceCodes = function generatePkceCodes() {
+ return this.pkceGenerator.generatePkceCodes();
+ }
+ /**
+ * Generates a keypair, stores it and returns a thumbprint - not yet implemented for node
+ */
+ ;
+
+ _proto.getPublicKeyThumbprint = function getPublicKeyThumbprint() {
+ throw new Error("Method not implemented.");
+ }
+ /**
+ * Signs the given object as a jwt payload with private key retrieved by given kid - currently not implemented for node
+ */
+ ;
+
+ _proto.signJwt = function signJwt() {
+ throw new Error("Method not implemented.");
+ };
+
+ return CryptoProvider;
+}();
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * This class deserializes cache entities read from the file into in memory object types defined internally
+ */
+
+var Deserializer = /*#__PURE__*/function () {
+ function Deserializer() {}
+
+ /**
+ * Parse the JSON blob in memory and deserialize the content
+ * @param cachedJson
+ */
+ Deserializer.deserializeJSONBlob = function deserializeJSONBlob(jsonFile) {
+ var deserializedCache = msalCommon.StringUtils.isEmpty(jsonFile) ? {} : JSON.parse(jsonFile);
+ return deserializedCache;
+ }
+ /**
+ * Deserializes accounts to AccountEntity objects
+ * @param accounts
+ */
+ ;
+
+ Deserializer.deserializeAccounts = function deserializeAccounts(accounts) {
+ var accountObjects = {};
+
+ if (accounts) {
+ Object.keys(accounts).map(function (key) {
+ var serializedAcc = accounts[key];
+ var mappedAcc = {
+ homeAccountId: serializedAcc.home_account_id,
+ environment: serializedAcc.environment,
+ realm: serializedAcc.realm,
+ localAccountId: serializedAcc.local_account_id,
+ username: serializedAcc.username,
+ authorityType: serializedAcc.authority_type,
+ name: serializedAcc.name,
+ clientInfo: serializedAcc.client_info,
+ lastModificationTime: serializedAcc.last_modification_time,
+ lastModificationApp: serializedAcc.last_modification_app
+ };
+ var account = new msalCommon.AccountEntity();
+ msalCommon.CacheManager.toObject(account, mappedAcc);
+ accountObjects[key] = account;
+ });
+ }
+
+ return accountObjects;
+ }
+ /**
+ * Deserializes id tokens to IdTokenEntity objects
+ * @param idTokens
+ */
+ ;
+
+ Deserializer.deserializeIdTokens = function deserializeIdTokens(idTokens) {
+ var idObjects = {};
+
+ if (idTokens) {
+ Object.keys(idTokens).map(function (key) {
+ var serializedIdT = idTokens[key];
+ var mappedIdT = {
+ homeAccountId: serializedIdT.home_account_id,
+ environment: serializedIdT.environment,
+ credentialType: serializedIdT.credential_type,
+ clientId: serializedIdT.client_id,
+ secret: serializedIdT.secret,
+ realm: serializedIdT.realm
+ };
+ var idToken = new msalCommon.IdTokenEntity();
+ msalCommon.CacheManager.toObject(idToken, mappedIdT);
+ idObjects[key] = idToken;
+ });
+ }
+
+ return idObjects;
+ }
+ /**
+ * Deserializes access tokens to AccessTokenEntity objects
+ * @param accessTokens
+ */
+ ;
+
+ Deserializer.deserializeAccessTokens = function deserializeAccessTokens(accessTokens) {
+ var atObjects = {};
+
+ if (accessTokens) {
+ Object.keys(accessTokens).map(function (key) {
+ var serializedAT = accessTokens[key];
+ var mappedAT = {
+ homeAccountId: serializedAT.home_account_id,
+ environment: serializedAT.environment,
+ credentialType: serializedAT.credential_type,
+ clientId: serializedAT.client_id,
+ secret: serializedAT.secret,
+ realm: serializedAT.realm,
+ target: serializedAT.target,
+ cachedAt: serializedAT.cached_at,
+ expiresOn: serializedAT.expires_on,
+ extendedExpiresOn: serializedAT.extended_expires_on,
+ refreshOn: serializedAT.refresh_on,
+ keyId: serializedAT.key_id,
+ tokenType: serializedAT.token_type
+ };
+ var accessToken = new msalCommon.AccessTokenEntity();
+ msalCommon.CacheManager.toObject(accessToken, mappedAT);
+ atObjects[key] = accessToken;
+ });
+ }
+
+ return atObjects;
+ }
+ /**
+ * Deserializes refresh tokens to RefreshTokenEntity objects
+ * @param refreshTokens
+ */
+ ;
+
+ Deserializer.deserializeRefreshTokens = function deserializeRefreshTokens(refreshTokens) {
+ var rtObjects = {};
+
+ if (refreshTokens) {
+ Object.keys(refreshTokens).map(function (key) {
+ var serializedRT = refreshTokens[key];
+ var mappedRT = {
+ homeAccountId: serializedRT.home_account_id,
+ environment: serializedRT.environment,
+ credentialType: serializedRT.credential_type,
+ clientId: serializedRT.client_id,
+ secret: serializedRT.secret,
+ familyId: serializedRT.family_id,
+ target: serializedRT.target,
+ realm: serializedRT.realm
+ };
+ var refreshToken = new msalCommon.RefreshTokenEntity();
+ msalCommon.CacheManager.toObject(refreshToken, mappedRT);
+ rtObjects[key] = refreshToken;
+ });
+ }
+
+ return rtObjects;
+ }
+ /**
+ * Deserializes appMetadata to AppMetaData objects
+ * @param appMetadata
+ */
+ ;
+
+ Deserializer.deserializeAppMetadata = function deserializeAppMetadata(appMetadata) {
+ var appMetadataObjects = {};
+
+ if (appMetadata) {
+ Object.keys(appMetadata).map(function (key) {
+ var serializedAmdt = appMetadata[key];
+ var mappedAmd = {
+ clientId: serializedAmdt.client_id,
+ environment: serializedAmdt.environment,
+ familyId: serializedAmdt.family_id
+ };
+ var amd = new msalCommon.AppMetadataEntity();
+ msalCommon.CacheManager.toObject(amd, mappedAmd);
+ appMetadataObjects[key] = amd;
+ });
+ }
+
+ return appMetadataObjects;
+ }
+ /**
+ * Deserialize an inMemory Cache
+ * @param jsonCache
+ */
+ ;
+
+ Deserializer.deserializeAllCache = function deserializeAllCache(jsonCache) {
+ return {
+ accounts: jsonCache.Account ? this.deserializeAccounts(jsonCache.Account) : {},
+ idTokens: jsonCache.IdToken ? this.deserializeIdTokens(jsonCache.IdToken) : {},
+ accessTokens: jsonCache.AccessToken ? this.deserializeAccessTokens(jsonCache.AccessToken) : {},
+ refreshTokens: jsonCache.RefreshToken ? this.deserializeRefreshTokens(jsonCache.RefreshToken) : {},
+ appMetadata: jsonCache.AppMetadata ? this.deserializeAppMetadata(jsonCache.AppMetadata) : {}
+ };
+ };
+
+ return Deserializer;
+}();
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+var Serializer = /*#__PURE__*/function () {
+ function Serializer() {}
+
+ /**
+ * serialize the JSON blob
+ * @param data
+ */
+ Serializer.serializeJSONBlob = function serializeJSONBlob(data) {
+ return JSON.stringify(data);
+ }
+ /**
+ * Serialize Accounts
+ * @param accCache
+ */
+ ;
+
+ Serializer.serializeAccounts = function serializeAccounts(accCache) {
+ var accounts = {};
+ Object.keys(accCache).map(function (key) {
+ var accountEntity = accCache[key];
+ accounts[key] = {
+ home_account_id: accountEntity.homeAccountId,
+ environment: accountEntity.environment,
+ realm: accountEntity.realm,
+ local_account_id: accountEntity.localAccountId,
+ username: accountEntity.username,
+ authority_type: accountEntity.authorityType,
+ name: accountEntity.name,
+ client_info: accountEntity.clientInfo,
+ last_modification_time: accountEntity.lastModificationTime,
+ last_modification_app: accountEntity.lastModificationApp
+ };
+ });
+ return accounts;
+ }
+ /**
+ * Serialize IdTokens
+ * @param idTCache
+ */
+ ;
+
+ Serializer.serializeIdTokens = function serializeIdTokens(idTCache) {
+ var idTokens = {};
+ Object.keys(idTCache).map(function (key) {
+ var idTEntity = idTCache[key];
+ idTokens[key] = {
+ home_account_id: idTEntity.homeAccountId,
+ environment: idTEntity.environment,
+ credential_type: idTEntity.credentialType,
+ client_id: idTEntity.clientId,
+ secret: idTEntity.secret,
+ realm: idTEntity.realm
+ };
+ });
+ return idTokens;
+ }
+ /**
+ * Serializes AccessTokens
+ * @param atCache
+ */
+ ;
+
+ Serializer.serializeAccessTokens = function serializeAccessTokens(atCache) {
+ var accessTokens = {};
+ Object.keys(atCache).map(function (key) {
+ var atEntity = atCache[key];
+ accessTokens[key] = {
+ home_account_id: atEntity.homeAccountId,
+ environment: atEntity.environment,
+ credential_type: atEntity.credentialType,
+ client_id: atEntity.clientId,
+ secret: atEntity.secret,
+ realm: atEntity.realm,
+ target: atEntity.target,
+ cached_at: atEntity.cachedAt,
+ expires_on: atEntity.expiresOn,
+ extended_expires_on: atEntity.extendedExpiresOn,
+ refresh_on: atEntity.refreshOn,
+ key_id: atEntity.keyId,
+ token_type: atEntity.tokenType
+ };
+ });
+ return accessTokens;
+ }
+ /**
+ * Serialize refreshTokens
+ * @param rtCache
+ */
+ ;
+
+ Serializer.serializeRefreshTokens = function serializeRefreshTokens(rtCache) {
+ var refreshTokens = {};
+ Object.keys(rtCache).map(function (key) {
+ var rtEntity = rtCache[key];
+ refreshTokens[key] = {
+ home_account_id: rtEntity.homeAccountId,
+ environment: rtEntity.environment,
+ credential_type: rtEntity.credentialType,
+ client_id: rtEntity.clientId,
+ secret: rtEntity.secret,
+ family_id: rtEntity.familyId,
+ target: rtEntity.target,
+ realm: rtEntity.realm
+ };
+ });
+ return refreshTokens;
+ }
+ /**
+ * Serialize amdtCache
+ * @param amdtCache
+ */
+ ;
+
+ Serializer.serializeAppMetadata = function serializeAppMetadata(amdtCache) {
+ var appMetadata = {};
+ Object.keys(amdtCache).map(function (key) {
+ var amdtEntity = amdtCache[key];
+ appMetadata[key] = {
+ client_id: amdtEntity.clientId,
+ environment: amdtEntity.environment,
+ family_id: amdtEntity.familyId
+ };
+ });
+ return appMetadata;
+ }
+ /**
+ * Serialize the cache
+ * @param jsonContent
+ */
+ ;
+
+ Serializer.serializeAllCache = function serializeAllCache(inMemCache) {
+ return {
+ Account: this.serializeAccounts(inMemCache.accounts),
+ IdToken: this.serializeIdTokens(inMemCache.idTokens),
+ AccessToken: this.serializeAccessTokens(inMemCache.accessTokens),
+ RefreshToken: this.serializeRefreshTokens(inMemCache.refreshTokens),
+ AppMetadata: this.serializeAppMetadata(inMemCache.appMetadata)
+ };
+ };
+
+ return Serializer;
+}();
+
+/**
+ * This class implements Storage for node, reading cache from user specified storage location or an extension library
+ * @public
+ */
+
+var NodeStorage = /*#__PURE__*/function (_CacheManager) {
+ _inheritsLoose(NodeStorage, _CacheManager);
+
+ function NodeStorage(logger, clientId, cryptoImpl) {
+ var _this;
+
+ _this = _CacheManager.call(this, clientId, cryptoImpl) || this;
+ _this.cache = {};
+ _this.changeEmitters = [];
+ _this.logger = logger;
+ return _this;
+ }
+ /**
+ * Queue up callbacks
+ * @param func - a callback function for cache change indication
+ */
+
+
+ var _proto = NodeStorage.prototype;
+
+ _proto.registerChangeEmitter = function registerChangeEmitter(func) {
+ this.changeEmitters.push(func);
+ }
+ /**
+ * Invoke the callback when cache changes
+ */
+ ;
+
+ _proto.emitChange = function emitChange() {
+ this.changeEmitters.forEach(function (func) {
+ return func.call(null);
+ });
+ }
+ /**
+ * Converts cacheKVStore to InMemoryCache
+ * @param cache - key value store
+ */
+ ;
+
+ _proto.cacheToInMemoryCache = function cacheToInMemoryCache(cache) {
+ var inMemoryCache = {
+ accounts: {},
+ idTokens: {},
+ accessTokens: {},
+ refreshTokens: {},
+ appMetadata: {}
+ };
+
+ for (var key in cache) {
+ if (cache[key] instanceof msalCommon.AccountEntity) {
+ inMemoryCache.accounts[key] = cache[key];
+ } else if (cache[key] instanceof msalCommon.IdTokenEntity) {
+ inMemoryCache.idTokens[key] = cache[key];
+ } else if (cache[key] instanceof msalCommon.AccessTokenEntity) {
+ inMemoryCache.accessTokens[key] = cache[key];
+ } else if (cache[key] instanceof msalCommon.RefreshTokenEntity) {
+ inMemoryCache.refreshTokens[key] = cache[key];
+ } else if (cache[key] instanceof msalCommon.AppMetadataEntity) {
+ inMemoryCache.appMetadata[key] = cache[key];
+ } else {
+ continue;
+ }
+ }
+
+ return inMemoryCache;
+ }
+ /**
+ * converts inMemoryCache to CacheKVStore
+ * @param inMemoryCache - kvstore map for inmemory
+ */
+ ;
+
+ _proto.inMemoryCacheToCache = function inMemoryCacheToCache(inMemoryCache) {
+ // convert in memory cache to a flat Key-Value map
+ var cache = this.getCache();
+ cache = _extends({}, inMemoryCache.accounts, inMemoryCache.idTokens, inMemoryCache.accessTokens, inMemoryCache.refreshTokens, inMemoryCache.appMetadata);
+ return cache;
+ }
+ /**
+ * gets the current in memory cache for the client
+ */
+ ;
+
+ _proto.getInMemoryCache = function getInMemoryCache() {
+ this.logger.verbose("Getting in-memory cache"); // convert the cache key value store to inMemoryCache
+
+ var inMemoryCache = this.cacheToInMemoryCache(this.getCache());
+ return inMemoryCache;
+ }
+ /**
+ * sets the current in memory cache for the client
+ * @param inMemoryCache - key value map in memory
+ */
+ ;
+
+ _proto.setInMemoryCache = function setInMemoryCache(inMemoryCache) {
+ this.logger.verbose("Setting in-memory cache"); // convert and append the inMemoryCache to cacheKVStore
+
+ var cache = this.inMemoryCacheToCache(inMemoryCache);
+ this.setCache(cache);
+ this.emitChange();
+ }
+ /**
+ * get the current cache key-value store
+ */
+ ;
+
+ _proto.getCache = function getCache() {
+ this.logger.verbose("Getting cache key-value store");
+ return this.cache;
+ }
+ /**
+ * sets the current cache (key value store)
+ * @param cacheMap - key value map
+ */
+ ;
+
+ _proto.setCache = function setCache(cache) {
+ this.logger.verbose("Setting cache key value store");
+ this.cache = cache; // mark change in cache
+
+ this.emitChange();
+ }
+ /**
+ * Gets cache item with given key.
+ * @param key - lookup key for the cache entry
+ */
+ ;
+
+ _proto.getItem = function getItem(key) {
+ this.logger.verbosePii("Item key: " + key); // read cache
+
+ var cache = this.getCache();
+ return cache[key];
+ }
+ /**
+ * Gets cache item with given key-value
+ * @param key - lookup key for the cache entry
+ * @param value - value of the cache entry
+ */
+ ;
+
+ _proto.setItem = function setItem(key, value) {
+ this.logger.verbosePii("Item key: " + key); // read cache
+
+ var cache = this.getCache();
+ cache[key] = value; // write to cache
+
+ this.setCache(cache);
+ }
+ /**
+ * fetch the account entity
+ * @param accountKey - lookup key to fetch cache type AccountEntity
+ */
+ ;
+
+ _proto.getAccount = function getAccount(accountKey) {
+ var account = this.getItem(accountKey);
+
+ if (msalCommon.AccountEntity.isAccountEntity(account)) {
+ return account;
+ }
+
+ return null;
+ }
+ /**
+ * set account entity
+ * @param account - cache value to be set of type AccountEntity
+ */
+ ;
+
+ _proto.setAccount = function setAccount(account) {
+ var accountKey = account.generateAccountKey();
+ this.setItem(accountKey, account);
+ }
+ /**
+ * fetch the idToken credential
+ * @param idTokenKey - lookup key to fetch cache type IdTokenEntity
+ */
+ ;
+
+ _proto.getIdTokenCredential = function getIdTokenCredential(idTokenKey) {
+ var idToken = this.getItem(idTokenKey);
+
+ if (msalCommon.IdTokenEntity.isIdTokenEntity(idToken)) {
+ return idToken;
+ }
+
+ return null;
+ }
+ /**
+ * set idToken credential
+ * @param idToken - cache value to be set of type IdTokenEntity
+ */
+ ;
+
+ _proto.setIdTokenCredential = function setIdTokenCredential(idToken) {
+ var idTokenKey = idToken.generateCredentialKey();
+ this.setItem(idTokenKey, idToken);
+ }
+ /**
+ * fetch the accessToken credential
+ * @param accessTokenKey - lookup key to fetch cache type AccessTokenEntity
+ */
+ ;
+
+ _proto.getAccessTokenCredential = function getAccessTokenCredential(accessTokenKey) {
+ var accessToken = this.getItem(accessTokenKey);
+
+ if (msalCommon.AccessTokenEntity.isAccessTokenEntity(accessToken)) {
+ return accessToken;
+ }
+
+ return null;
+ }
+ /**
+ * set accessToken credential
+ * @param accessToken - cache value to be set of type AccessTokenEntity
+ */
+ ;
+
+ _proto.setAccessTokenCredential = function setAccessTokenCredential(accessToken) {
+ var accessTokenKey = accessToken.generateCredentialKey();
+ this.setItem(accessTokenKey, accessToken);
+ }
+ /**
+ * fetch the refreshToken credential
+ * @param refreshTokenKey - lookup key to fetch cache type RefreshTokenEntity
+ */
+ ;
+
+ _proto.getRefreshTokenCredential = function getRefreshTokenCredential(refreshTokenKey) {
+ var refreshToken = this.getItem(refreshTokenKey);
+
+ if (msalCommon.RefreshTokenEntity.isRefreshTokenEntity(refreshToken)) {
+ return refreshToken;
+ }
+
+ return null;
+ }
+ /**
+ * set refreshToken credential
+ * @param refreshToken - cache value to be set of type RefreshTokenEntity
+ */
+ ;
+
+ _proto.setRefreshTokenCredential = function setRefreshTokenCredential(refreshToken) {
+ var refreshTokenKey = refreshToken.generateCredentialKey();
+ this.setItem(refreshTokenKey, refreshToken);
+ }
+ /**
+ * fetch appMetadata entity from the platform cache
+ * @param appMetadataKey - lookup key to fetch cache type AppMetadataEntity
+ */
+ ;
+
+ _proto.getAppMetadata = function getAppMetadata(appMetadataKey) {
+ var appMetadata = this.getItem(appMetadataKey);
+
+ if (msalCommon.AppMetadataEntity.isAppMetadataEntity(appMetadataKey, appMetadata)) {
+ return appMetadata;
+ }
+
+ return null;
+ }
+ /**
+ * set appMetadata entity to the platform cache
+ * @param appMetadata - cache value to be set of type AppMetadataEntity
+ */
+ ;
+
+ _proto.setAppMetadata = function setAppMetadata(appMetadata) {
+ var appMetadataKey = appMetadata.generateAppMetadataKey();
+ this.setItem(appMetadataKey, appMetadata);
+ }
+ /**
+ * fetch server telemetry entity from the platform cache
+ * @param serverTelemetrykey - lookup key to fetch cache type ServerTelemetryEntity
+ */
+ ;
+
+ _proto.getServerTelemetry = function getServerTelemetry(serverTelemetrykey) {
+ var serverTelemetryEntity = this.getItem(serverTelemetrykey);
+
+ if (serverTelemetryEntity && msalCommon.ServerTelemetryEntity.isServerTelemetryEntity(serverTelemetrykey, serverTelemetryEntity)) {
+ return serverTelemetryEntity;
+ }
+
+ return null;
+ }
+ /**
+ * set server telemetry entity to the platform cache
+ * @param serverTelemetryKey - lookup key to fetch cache type ServerTelemetryEntity
+ * @param serverTelemetry - cache value to be set of type ServerTelemetryEntity
+ */
+ ;
+
+ _proto.setServerTelemetry = function setServerTelemetry(serverTelemetryKey, serverTelemetry) {
+ this.setItem(serverTelemetryKey, serverTelemetry);
+ }
+ /**
+ * fetch authority metadata entity from the platform cache
+ * @param key - lookup key to fetch cache type AuthorityMetadataEntity
+ */
+ ;
+
+ _proto.getAuthorityMetadata = function getAuthorityMetadata(key) {
+ var authorityMetadataEntity = this.getItem(key);
+
+ if (authorityMetadataEntity && msalCommon.AuthorityMetadataEntity.isAuthorityMetadataEntity(key, authorityMetadataEntity)) {
+ return authorityMetadataEntity;
+ }
+
+ return null;
+ }
+ /**
+ * Get all authority metadata keys
+ */
+ ;
+
+ _proto.getAuthorityMetadataKeys = function getAuthorityMetadataKeys() {
+ var _this2 = this;
+
+ return this.getKeys().filter(function (key) {
+ return _this2.isAuthorityMetadata(key);
+ });
+ }
+ /**
+ * set authority metadata entity to the platform cache
+ * @param key - lookup key to fetch cache type AuthorityMetadataEntity
+ * @param metadata - cache value to be set of type AuthorityMetadataEntity
+ */
+ ;
+
+ _proto.setAuthorityMetadata = function setAuthorityMetadata(key, metadata) {
+ this.setItem(key, metadata);
+ }
+ /**
+ * fetch throttling entity from the platform cache
+ * @param throttlingCacheKey - lookup key to fetch cache type ThrottlingEntity
+ */
+ ;
+
+ _proto.getThrottlingCache = function getThrottlingCache(throttlingCacheKey) {
+ var throttlingCache = this.getItem(throttlingCacheKey);
+
+ if (throttlingCache && msalCommon.ThrottlingEntity.isThrottlingEntity(throttlingCacheKey, throttlingCache)) {
+ return throttlingCache;
+ }
+
+ return null;
+ }
+ /**
+ * set throttling entity to the platform cache
+ * @param throttlingCacheKey - lookup key to fetch cache type ThrottlingEntity
+ * @param throttlingCache - cache value to be set of type ThrottlingEntity
+ */
+ ;
+
+ _proto.setThrottlingCache = function setThrottlingCache(throttlingCacheKey, throttlingCache) {
+ this.setItem(throttlingCacheKey, throttlingCache);
+ }
+ /**
+ * Removes the cache item from memory with the given key.
+ * @param key - lookup key to remove a cache entity
+ * @param inMemory - key value map of the cache
+ */
+ ;
+
+ _proto.removeItem = function removeItem(key) {
+ this.logger.verbosePii("Item key: " + key); // read inMemoryCache
+
+ var result = false;
+ var cache = this.getCache();
+
+ if (!!cache[key]) {
+ delete cache[key];
+ result = true;
+ } // write to the cache after removal
+
+
+ if (result) {
+ this.setCache(cache);
+ this.emitChange();
+ }
+
+ return result;
+ }
+ /**
+ * Checks whether key is in cache.
+ * @param key - look up key for a cache entity
+ */
+ ;
+
+ _proto.containsKey = function containsKey(key) {
+ return this.getKeys().includes(key);
+ }
+ /**
+ * Gets all keys in window.
+ */
+ ;
+
+ _proto.getKeys = function getKeys() {
+ this.logger.verbose("Retrieving all cache keys"); // read cache
+
+ var cache = this.getCache();
+ return [].concat(Object.keys(cache));
+ }
+ /**
+ * Clears all cache entries created by MSAL (except tokens).
+ */
+ ;
+
+ _proto.clear = function clear() {
+ var _this3 = this;
+
+ this.logger.verbose("Clearing cache entries created by MSAL"); // read inMemoryCache
+
+ var cacheKeys = this.getKeys(); // delete each element
+
+ cacheKeys.forEach(function (key) {
+ _this3.removeItem(key);
+ });
+ this.emitChange();
+ }
+ /**
+ * Initialize in memory cache from an exisiting cache vault
+ * @param cache - blob formatted cache (JSON)
+ */
+ ;
+
+ NodeStorage.generateInMemoryCache = function generateInMemoryCache(cache) {
+ return Deserializer.deserializeAllCache(Deserializer.deserializeJSONBlob(cache));
+ }
+ /**
+ * retrieves the final JSON
+ * @param inMemoryCache - itemised cache read from the JSON
+ */
+ ;
+
+ NodeStorage.generateJsonCache = function generateJsonCache(inMemoryCache) {
+ return Serializer.serializeAllCache(inMemoryCache);
+ };
+
+ return NodeStorage;
+}(msalCommon.CacheManager);
+
+var defaultSerializedCache = {
+ Account: {},
+ IdToken: {},
+ AccessToken: {},
+ RefreshToken: {},
+ AppMetadata: {}
+};
+/**
+ * In-memory token cache manager
+ * @public
+ */
+
+var TokenCache = /*#__PURE__*/function () {
+ function TokenCache(storage, logger, cachePlugin) {
+ this.cacheHasChanged = false;
+ this.storage = storage;
+ this.storage.registerChangeEmitter(this.handleChangeEvent.bind(this));
+
+ if (cachePlugin) {
+ this.persistence = cachePlugin;
+ }
+
+ this.logger = logger;
+ }
+ /**
+ * Set to true if cache state has changed since last time serialize or writeToPersistence was called
+ */
+
+
+ var _proto = TokenCache.prototype;
+
+ _proto.hasChanged = function hasChanged() {
+ return this.cacheHasChanged;
+ }
+ /**
+ * Serializes in memory cache to JSON
+ */
+ ;
+
+ _proto.serialize = function serialize() {
+ this.logger.verbose("Serializing in-memory cache");
+ var finalState = Serializer.serializeAllCache(this.storage.getInMemoryCache()); // if cacheSnapshot not null or empty, merge
+
+ if (!msalCommon.StringUtils.isEmpty(this.cacheSnapshot)) {
+ this.logger.verbose("Reading cache snapshot from disk");
+ finalState = this.mergeState(JSON.parse(this.cacheSnapshot), finalState);
+ } else {
+ this.logger.verbose("No cache snapshot to merge");
+ }
+
+ this.cacheHasChanged = false;
+ return JSON.stringify(finalState);
+ }
+ /**
+ * Deserializes JSON to in-memory cache. JSON should be in MSAL cache schema format
+ * @param cache - blob formatted cache
+ */
+ ;
+
+ _proto.deserialize = function deserialize(cache) {
+ this.logger.verbose("Deserializing JSON to in-memory cache");
+ this.cacheSnapshot = cache;
+
+ if (!msalCommon.StringUtils.isEmpty(this.cacheSnapshot)) {
+ this.logger.verbose("Reading cache snapshot from disk");
+ var deserializedCache = Deserializer.deserializeAllCache(this.overlayDefaults(JSON.parse(this.cacheSnapshot)));
+ this.storage.setInMemoryCache(deserializedCache);
+ } else {
+ this.logger.verbose("No cache snapshot to deserialize");
+ }
+ }
+ /**
+ * Fetches the cache key-value map
+ */
+ ;
+
+ _proto.getKVStore = function getKVStore() {
+ return this.storage.getCache();
+ }
+ /**
+ * API that retrieves all accounts currently in cache to the user
+ */
+ ;
+
+ _proto.getAllAccounts =
+ /*#__PURE__*/
+ function () {
+ var _getAllAccounts = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee() {
+ var cacheContext;
+ return runtime_1.wrap(function _callee$(_context) {
+ while (1) {
+ switch (_context.prev = _context.next) {
+ case 0:
+ this.logger.verbose("getAllAccounts called");
+ _context.prev = 1;
+
+ if (!this.persistence) {
+ _context.next = 6;
+ break;
+ }
+
+ cacheContext = new msalCommon.TokenCacheContext(this, false);
+ _context.next = 6;
+ return this.persistence.beforeCacheAccess(cacheContext);
+
+ case 6:
+ return _context.abrupt("return", this.storage.getAllAccounts());
+
+ case 7:
+ _context.prev = 7;
+
+ if (!(this.persistence && cacheContext)) {
+ _context.next = 11;
+ break;
+ }
+
+ _context.next = 11;
+ return this.persistence.afterCacheAccess(cacheContext);
+
+ case 11:
+ return _context.finish(7);
+
+ case 12:
+ case "end":
+ return _context.stop();
+ }
+ }
+ }, _callee, this, [[1,, 7, 12]]);
+ }));
+
+ function getAllAccounts() {
+ return _getAllAccounts.apply(this, arguments);
+ }
+
+ return getAllAccounts;
+ }()
+ /**
+ * Returns the signed in account matching homeAccountId.
+ * (the account object is created at the time of successful login)
+ * or null when no matching account is found
+ * @param homeAccountId - unique identifier for an account (uid.utid)
+ */
+ ;
+
+ _proto.getAccountByHomeId =
+ /*#__PURE__*/
+ function () {
+ var _getAccountByHomeId = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee2(homeAccountId) {
+ var allAccounts;
+ return runtime_1.wrap(function _callee2$(_context2) {
+ while (1) {
+ switch (_context2.prev = _context2.next) {
+ case 0:
+ _context2.next = 2;
+ return this.getAllAccounts();
+
+ case 2:
+ allAccounts = _context2.sent;
+
+ if (!(!msalCommon.StringUtils.isEmpty(homeAccountId) && allAccounts && allAccounts.length)) {
+ _context2.next = 7;
+ break;
+ }
+
+ return _context2.abrupt("return", allAccounts.filter(function (accountObj) {
+ return accountObj.homeAccountId === homeAccountId;
+ })[0] || null);
+
+ case 7:
+ return _context2.abrupt("return", null);
+
+ case 8:
+ case "end":
+ return _context2.stop();
+ }
+ }
+ }, _callee2, this);
+ }));
+
+ function getAccountByHomeId(_x) {
+ return _getAccountByHomeId.apply(this, arguments);
+ }
+
+ return getAccountByHomeId;
+ }()
+ /**
+ * Returns the signed in account matching localAccountId.
+ * (the account object is created at the time of successful login)
+ * or null when no matching account is found
+ * @param localAccountId - unique identifier of an account (sub/obj when homeAccountId cannot be populated)
+ */
+ ;
+
+ _proto.getAccountByLocalId =
+ /*#__PURE__*/
+ function () {
+ var _getAccountByLocalId = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee3(localAccountId) {
+ var allAccounts;
+ return runtime_1.wrap(function _callee3$(_context3) {
+ while (1) {
+ switch (_context3.prev = _context3.next) {
+ case 0:
+ _context3.next = 2;
+ return this.getAllAccounts();
+
+ case 2:
+ allAccounts = _context3.sent;
+
+ if (!(!msalCommon.StringUtils.isEmpty(localAccountId) && allAccounts && allAccounts.length)) {
+ _context3.next = 7;
+ break;
+ }
+
+ return _context3.abrupt("return", allAccounts.filter(function (accountObj) {
+ return accountObj.localAccountId === localAccountId;
+ })[0] || null);
+
+ case 7:
+ return _context3.abrupt("return", null);
+
+ case 8:
+ case "end":
+ return _context3.stop();
+ }
+ }
+ }, _callee3, this);
+ }));
+
+ function getAccountByLocalId(_x2) {
+ return _getAccountByLocalId.apply(this, arguments);
+ }
+
+ return getAccountByLocalId;
+ }()
+ /**
+ * API to remove a specific account and the relevant data from cache
+ * @param account - AccountInfo passed by the user
+ */
+ ;
+
+ _proto.removeAccount =
+ /*#__PURE__*/
+ function () {
+ var _removeAccount = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee4(account) {
+ var cacheContext;
+ return runtime_1.wrap(function _callee4$(_context4) {
+ while (1) {
+ switch (_context4.prev = _context4.next) {
+ case 0:
+ this.logger.verbose("removeAccount called");
+ _context4.prev = 1;
+
+ if (!this.persistence) {
+ _context4.next = 6;
+ break;
+ }
+
+ cacheContext = new msalCommon.TokenCacheContext(this, true);
+ _context4.next = 6;
+ return this.persistence.beforeCacheAccess(cacheContext);
+
+ case 6:
+ this.storage.removeAccount(msalCommon.AccountEntity.generateAccountCacheKey(account));
+
+ case 7:
+ _context4.prev = 7;
+
+ if (!(this.persistence && cacheContext)) {
+ _context4.next = 11;
+ break;
+ }
+
+ _context4.next = 11;
+ return this.persistence.afterCacheAccess(cacheContext);
+
+ case 11:
+ return _context4.finish(7);
+
+ case 12:
+ case "end":
+ return _context4.stop();
+ }
+ }
+ }, _callee4, this, [[1,, 7, 12]]);
+ }));
+
+ function removeAccount(_x3) {
+ return _removeAccount.apply(this, arguments);
+ }
+
+ return removeAccount;
+ }()
+ /**
+ * Called when the cache has changed state.
+ */
+ ;
+
+ _proto.handleChangeEvent = function handleChangeEvent() {
+ this.cacheHasChanged = true;
+ }
+ /**
+ * Merge in memory cache with the cache snapshot.
+ * @param oldState - cache before changes
+ * @param currentState - current cache state in the library
+ */
+ ;
+
+ _proto.mergeState = function mergeState(oldState, currentState) {
+ this.logger.verbose("Merging in-memory cache with cache snapshot");
+ var stateAfterRemoval = this.mergeRemovals(oldState, currentState);
+ return this.mergeUpdates(stateAfterRemoval, currentState);
+ }
+ /**
+ * Deep update of oldState based on newState values
+ * @param oldState - cache before changes
+ * @param newState - updated cache
+ */
+ ;
+
+ _proto.mergeUpdates = function mergeUpdates(oldState, newState) {
+ var _this = this;
+
+ Object.keys(newState).forEach(function (newKey) {
+ var newValue = newState[newKey]; // if oldState does not contain value but newValue does, add it
+
+ if (!oldState.hasOwnProperty(newKey)) {
+ if (newValue !== null) {
+ oldState[newKey] = newValue;
+ }
+ } else {
+ // both oldState and newState contain the key, do deep update
+ var newValueNotNull = newValue !== null;
+ var newValueIsObject = typeof newValue === "object";
+ var newValueIsNotArray = !Array.isArray(newValue);
+ var oldStateNotUndefinedOrNull = typeof oldState[newKey] !== "undefined" && oldState[newKey] !== null;
+
+ if (newValueNotNull && newValueIsObject && newValueIsNotArray && oldStateNotUndefinedOrNull) {
+ _this.mergeUpdates(oldState[newKey], newValue);
+ } else {
+ oldState[newKey] = newValue;
+ }
+ }
+ });
+ return oldState;
+ }
+ /**
+ * Removes entities in oldState that the were removed from newState. If there are any unknown values in root of
+ * oldState that are not recognized, they are left untouched.
+ * @param oldState - cache before changes
+ * @param newState - updated cache
+ */
+ ;
+
+ _proto.mergeRemovals = function mergeRemovals(oldState, newState) {
+ this.logger.verbose("Remove updated entries in cache");
+ var accounts = oldState.Account ? this.mergeRemovalsDict(oldState.Account, newState.Account) : oldState.Account;
+ var accessTokens = oldState.AccessToken ? this.mergeRemovalsDict(oldState.AccessToken, newState.AccessToken) : oldState.AccessToken;
+ var refreshTokens = oldState.RefreshToken ? this.mergeRemovalsDict(oldState.RefreshToken, newState.RefreshToken) : oldState.RefreshToken;
+ var idTokens = oldState.IdToken ? this.mergeRemovalsDict(oldState.IdToken, newState.IdToken) : oldState.IdToken;
+ var appMetadata = oldState.AppMetadata ? this.mergeRemovalsDict(oldState.AppMetadata, newState.AppMetadata) : oldState.AppMetadata;
+ return _extends({}, oldState, {
+ Account: accounts,
+ AccessToken: accessTokens,
+ RefreshToken: refreshTokens,
+ IdToken: idTokens,
+ AppMetadata: appMetadata
+ });
+ }
+ /**
+ * Helper to merge new cache with the old one
+ * @param oldState - cache before changes
+ * @param newState - updated cache
+ */
+ ;
+
+ _proto.mergeRemovalsDict = function mergeRemovalsDict(oldState, newState) {
+ var finalState = _extends({}, oldState);
+
+ Object.keys(oldState).forEach(function (oldKey) {
+ if (!newState || !newState.hasOwnProperty(oldKey)) {
+ delete finalState[oldKey];
+ }
+ });
+ return finalState;
+ }
+ /**
+ * Helper to overlay as a part of cache merge
+ * @param passedInCache - cache read from the blob
+ */
+ ;
+
+ _proto.overlayDefaults = function overlayDefaults(passedInCache) {
+ this.logger.verbose("Overlaying input cache with the default cache");
+ return {
+ Account: _extends({}, defaultSerializedCache.Account, passedInCache.Account),
+ IdToken: _extends({}, defaultSerializedCache.IdToken, passedInCache.IdToken),
+ AccessToken: _extends({}, defaultSerializedCache.AccessToken, passedInCache.AccessToken),
+ RefreshToken: _extends({}, defaultSerializedCache.RefreshToken, passedInCache.RefreshToken),
+ AppMetadata: _extends({}, defaultSerializedCache.AppMetadata, passedInCache.AppMetadata)
+ };
+ };
+
+ return TokenCache;
+}();
+
+/* eslint-disable header/header */
+var name = "@azure/msal-node";
+var version = "1.0.0";
+
+/**
+ * Base abstract class for all ClientApplications - public and confidential
+ * @public
+ */
+
+var ClientApplication = /*#__PURE__*/function () {
+ /**
+ * Constructor for the ClientApplication
+ */
+ function ClientApplication(configuration) {
+ this.config = buildAppConfiguration(configuration);
+ this.cryptoProvider = new CryptoProvider();
+ this.logger = new msalCommon.Logger(this.config.system.loggerOptions, name, version);
+ this.storage = new NodeStorage(this.logger, this.config.auth.clientId, this.cryptoProvider);
+ this.tokenCache = new TokenCache(this.storage, this.logger, this.config.cache.cachePlugin);
+ }
+ /**
+ * Creates the URL of the authorization request, letting the user input credentials and consent to the
+ * application. The URL targets the /authorize endpoint of the authority configured in the
+ * application object.
+ *
+ * Once the user inputs their credentials and consents, the authority will send a response to the redirect URI
+ * sent in the request and should contain an authorization code, which can then be used to acquire tokens via
+ * `acquireTokenByCode(AuthorizationCodeRequest)`.
+ */
+
+
+ var _proto = ClientApplication.prototype;
+
+ _proto.getAuthCodeUrl =
+ /*#__PURE__*/
+ function () {
+ var _getAuthCodeUrl = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee(request) {
+ var validRequest, authClientConfig, authorizationCodeClient;
+ return runtime_1.wrap(function _callee$(_context) {
+ while (1) {
+ switch (_context.prev = _context.next) {
+ case 0:
+ this.logger.info("getAuthCodeUrl called");
+ validRequest = _extends({}, request, this.initializeBaseRequest(request), {
+ responseMode: request.responseMode || msalCommon.ResponseMode.QUERY,
+ authenticationScheme: msalCommon.AuthenticationScheme.BEARER
+ });
+ _context.next = 4;
+ return this.buildOauthClientConfiguration(validRequest.authority);
+
+ case 4:
+ authClientConfig = _context.sent;
+ this.logger.verbose("Auth client config generated");
+ authorizationCodeClient = new msalCommon.AuthorizationCodeClient(authClientConfig);
+ return _context.abrupt("return", authorizationCodeClient.getAuthCodeUrl(validRequest));
+
+ case 8:
+ case "end":
+ return _context.stop();
+ }
+ }
+ }, _callee, this);
+ }));
+
+ function getAuthCodeUrl(_x) {
+ return _getAuthCodeUrl.apply(this, arguments);
+ }
+
+ return getAuthCodeUrl;
+ }()
+ /**
+ * Acquires a token by exchanging the Authorization Code received from the first step of OAuth2.0
+ * Authorization Code flow.
+ *
+ * `getAuthCodeUrl(AuthorizationCodeUrlRequest)` can be used to create the URL for the first step of OAuth2.0
+ * Authorization Code flow. Ensure that values for redirectUri and scopes in AuthorizationCodeUrlRequest and
+ * AuthorizationCodeRequest are the same.
+ */
+ ;
+
+ _proto.acquireTokenByCode =
+ /*#__PURE__*/
+ function () {
+ var _acquireTokenByCode = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee2(request) {
+ var validRequest, serverTelemetryManager, authClientConfig, authorizationCodeClient;
+ return runtime_1.wrap(function _callee2$(_context2) {
+ while (1) {
+ switch (_context2.prev = _context2.next) {
+ case 0:
+ this.logger.info("acquireTokenByCode called");
+ validRequest = _extends({}, request, this.initializeBaseRequest(request), {
+ authenticationScheme: msalCommon.AuthenticationScheme.BEARER
+ });
+ serverTelemetryManager = this.initializeServerTelemetryManager(ApiId.acquireTokenByCode, validRequest.correlationId);
+ _context2.prev = 3;
+ _context2.next = 6;
+ return this.buildOauthClientConfiguration(validRequest.authority, serverTelemetryManager);
+
+ case 6:
+ authClientConfig = _context2.sent;
+ this.logger.verbose("Auth client config generated");
+ authorizationCodeClient = new msalCommon.AuthorizationCodeClient(authClientConfig);
+ return _context2.abrupt("return", authorizationCodeClient.acquireToken(validRequest));
+
+ case 12:
+ _context2.prev = 12;
+ _context2.t0 = _context2["catch"](3);
+ serverTelemetryManager.cacheFailedRequest(_context2.t0);
+ throw _context2.t0;
+
+ case 16:
+ case "end":
+ return _context2.stop();
+ }
+ }
+ }, _callee2, this, [[3, 12]]);
+ }));
+
+ function acquireTokenByCode(_x2) {
+ return _acquireTokenByCode.apply(this, arguments);
+ }
+
+ return acquireTokenByCode;
+ }()
+ /**
+ * Acquires a token by exchanging the refresh token provided for a new set of tokens.
+ *
+ * This API is provided only for scenarios where you would like to migrate from ADAL to MSAL. Otherwise, it is
+ * recommended that you use `acquireTokenSilent()` for silent scenarios. When using `acquireTokenSilent()`, MSAL will
+ * handle the caching and refreshing of tokens automatically.
+ */
+ ;
+
+ _proto.acquireTokenByRefreshToken =
+ /*#__PURE__*/
+ function () {
+ var _acquireTokenByRefreshToken = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee3(request) {
+ var validRequest, serverTelemetryManager, refreshTokenClientConfig, refreshTokenClient;
+ return runtime_1.wrap(function _callee3$(_context3) {
+ while (1) {
+ switch (_context3.prev = _context3.next) {
+ case 0:
+ this.logger.info("acquireTokenByRefreshToken called");
+ validRequest = _extends({}, request, this.initializeBaseRequest(request), {
+ authenticationScheme: msalCommon.AuthenticationScheme.BEARER
+ });
+ serverTelemetryManager = this.initializeServerTelemetryManager(ApiId.acquireTokenByRefreshToken, validRequest.correlationId);
+ _context3.prev = 3;
+ _context3.next = 6;
+ return this.buildOauthClientConfiguration(validRequest.authority, serverTelemetryManager);
+
+ case 6:
+ refreshTokenClientConfig = _context3.sent;
+ this.logger.verbose("Auth client config generated");
+ refreshTokenClient = new msalCommon.RefreshTokenClient(refreshTokenClientConfig);
+ return _context3.abrupt("return", refreshTokenClient.acquireToken(validRequest));
+
+ case 12:
+ _context3.prev = 12;
+ _context3.t0 = _context3["catch"](3);
+ serverTelemetryManager.cacheFailedRequest(_context3.t0);
+ throw _context3.t0;
+
+ case 16:
+ case "end":
+ return _context3.stop();
+ }
+ }
+ }, _callee3, this, [[3, 12]]);
+ }));
+
+ function acquireTokenByRefreshToken(_x3) {
+ return _acquireTokenByRefreshToken.apply(this, arguments);
+ }
+
+ return acquireTokenByRefreshToken;
+ }()
+ /**
+ * Acquires a token silently when a user specifies the account the token is requested for.
+ *
+ * This API expects the user to provide an account object and looks into the cache to retrieve the token if present.
+ * There is also an optional "forceRefresh" boolean the user can send to bypass the cache for access_token and id_token.
+ * In case the refresh_token is expired or not found, an error is thrown
+ * and the guidance is for the user to call any interactive token acquisition API (eg: `acquireTokenByCode()`).
+ */
+ ;
+
+ _proto.acquireTokenSilent =
+ /*#__PURE__*/
+ function () {
+ var _acquireTokenSilent = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee4(request) {
+ var validRequest, serverTelemetryManager, silentFlowClientConfig, silentFlowClient;
+ return runtime_1.wrap(function _callee4$(_context4) {
+ while (1) {
+ switch (_context4.prev = _context4.next) {
+ case 0:
+ validRequest = _extends({}, request, this.initializeBaseRequest(request), {
+ forceRefresh: request.forceRefresh || false
+ });
+ serverTelemetryManager = this.initializeServerTelemetryManager(ApiId.acquireTokenSilent, validRequest.correlationId, validRequest.forceRefresh);
+ _context4.prev = 2;
+ _context4.next = 5;
+ return this.buildOauthClientConfiguration(validRequest.authority, serverTelemetryManager);
+
+ case 5:
+ silentFlowClientConfig = _context4.sent;
+ silentFlowClient = new msalCommon.SilentFlowClient(silentFlowClientConfig);
+ return _context4.abrupt("return", silentFlowClient.acquireToken(validRequest));
+
+ case 10:
+ _context4.prev = 10;
+ _context4.t0 = _context4["catch"](2);
+ serverTelemetryManager.cacheFailedRequest(_context4.t0);
+ throw _context4.t0;
+
+ case 14:
+ case "end":
+ return _context4.stop();
+ }
+ }
+ }, _callee4, this, [[2, 10]]);
+ }));
+
+ function acquireTokenSilent(_x4) {
+ return _acquireTokenSilent.apply(this, arguments);
+ }
+
+ return acquireTokenSilent;
+ }()
+ /**
+ * Gets the token cache for the application.
+ */
+ ;
+
+ _proto.getTokenCache = function getTokenCache() {
+ this.logger.info("getTokenCache called");
+ return this.tokenCache;
+ }
+ /**
+ * Returns the logger instance
+ */
+ ;
+
+ _proto.getLogger = function getLogger() {
+ return this.logger;
+ }
+ /**
+ * Replaces the default logger set in configurations with new Logger with new configurations
+ * @param logger - Logger instance
+ */
+ ;
+
+ _proto.setLogger = function setLogger(logger) {
+ this.logger = logger;
+ }
+ /**
+ * Builds the common configuration to be passed to the common component based on the platform configurarion
+ * @param authority - user passed authority in configuration
+ * @param serverTelemetryManager - initializes servertelemetry if passed
+ */
+ ;
+
+ _proto.buildOauthClientConfiguration =
+ /*#__PURE__*/
+ function () {
+ var _buildOauthClientConfiguration = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee5(authority, serverTelemetryManager) {
+ var discoveredAuthority;
+ return runtime_1.wrap(function _callee5$(_context5) {
+ while (1) {
+ switch (_context5.prev = _context5.next) {
+ case 0:
+ this.logger.verbose("buildOauthClientConfiguration called"); // using null assertion operator as we ensure that all config values have default values in buildConfiguration()
+
+ _context5.next = 3;
+ return this.createAuthority(authority);
+
+ case 3:
+ discoveredAuthority = _context5.sent;
+ return _context5.abrupt("return", {
+ authOptions: {
+ clientId: this.config.auth.clientId,
+ authority: discoveredAuthority,
+ clientCapabilities: this.config.auth.clientCapabilities
+ },
+ loggerOptions: {
+ loggerCallback: this.config.system.loggerOptions.loggerCallback,
+ piiLoggingEnabled: this.config.system.loggerOptions.piiLoggingEnabled
+ },
+ cryptoInterface: this.cryptoProvider,
+ networkInterface: this.config.system.networkClient,
+ storageInterface: this.storage,
+ serverTelemetryManager: serverTelemetryManager,
+ clientCredentials: {
+ clientSecret: this.clientSecret,
+ clientAssertion: this.clientAssertion ? this.getClientAssertion(discoveredAuthority) : undefined
+ },
+ libraryInfo: {
+ sku: Constants.MSAL_SKU,
+ version: version,
+ cpu: process.arch || "",
+ os: process.platform || ""
+ },
+ persistencePlugin: this.config.cache.cachePlugin,
+ serializableCache: this.tokenCache
+ });
+
+ case 5:
+ case "end":
+ return _context5.stop();
+ }
+ }
+ }, _callee5, this);
+ }));
+
+ function buildOauthClientConfiguration(_x5, _x6) {
+ return _buildOauthClientConfiguration.apply(this, arguments);
+ }
+
+ return buildOauthClientConfiguration;
+ }();
+
+ _proto.getClientAssertion = function getClientAssertion(authority) {
+ return {
+ assertion: this.clientAssertion.getJwt(this.cryptoProvider, this.config.auth.clientId, authority.tokenEndpoint),
+ assertionType: Constants.JWT_BEARER_ASSERTION_TYPE
+ };
+ }
+ /**
+ * Generates a request with the default scopes & generates a correlationId.
+ * @param authRequest - BaseAuthRequest for initialization
+ */
+ ;
+
+ _proto.initializeBaseRequest = function initializeBaseRequest(authRequest) {
+ this.logger.verbose("initializeRequestScopes called");
+ return _extends({}, authRequest, {
+ scopes: [].concat(authRequest && authRequest.scopes || [], msalCommon.OIDC_DEFAULT_SCOPES),
+ correlationId: authRequest && authRequest.correlationId || this.cryptoProvider.createNewGuid(),
+ authority: authRequest.authority || this.config.auth.authority
+ });
+ }
+ /**
+ * Initializes the server telemetry payload
+ * @param apiId - Id for a specific request
+ * @param correlationId - GUID
+ * @param forceRefresh - boolean to indicate network call
+ */
+ ;
+
+ _proto.initializeServerTelemetryManager = function initializeServerTelemetryManager(apiId, correlationId, forceRefresh) {
+ var telemetryPayload = {
+ clientId: this.config.auth.clientId,
+ correlationId: correlationId,
+ apiId: apiId,
+ forceRefresh: forceRefresh || false
+ };
+ return new msalCommon.ServerTelemetryManager(telemetryPayload, this.storage);
+ }
+ /**
+ * Create authority instance. If authority not passed in request, default to authority set on the application
+ * object. If no authority set in application object, then default to common authority.
+ * @param authorityString - authority from user configuration
+ */
+ ;
+
+ _proto.createAuthority =
+ /*#__PURE__*/
+ function () {
+ var _createAuthority = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee6(authorityString) {
+ var authorityOptions;
+ return runtime_1.wrap(function _callee6$(_context6) {
+ while (1) {
+ switch (_context6.prev = _context6.next) {
+ case 0:
+ this.logger.verbose("createAuthority called");
+ authorityOptions = {
+ protocolMode: this.config.auth.protocolMode,
+ knownAuthorities: this.config.auth.knownAuthorities,
+ cloudDiscoveryMetadata: this.config.auth.cloudDiscoveryMetadata,
+ authorityMetadata: this.config.auth.authorityMetadata
+ };
+ _context6.next = 4;
+ return msalCommon.AuthorityFactory.createDiscoveredInstance(authorityString, this.config.system.networkClient, this.storage, authorityOptions);
+
+ case 4:
+ return _context6.abrupt("return", _context6.sent);
+
+ case 5:
+ case "end":
+ return _context6.stop();
+ }
+ }
+ }, _callee6, this);
+ }));
+
+ function createAuthority(_x7) {
+ return _createAuthority.apply(this, arguments);
+ }
+
+ return createAuthority;
+ }();
+
+ return ClientApplication;
+}();
+
+/**
+ * This class is to be used to acquire tokens for public client applications (desktop, mobile). Public client applications
+ * are not trusted to safely store application secrets, and therefore can only request tokens in the name of an user.
+ * @public
+ */
+
+var PublicClientApplication = /*#__PURE__*/function (_ClientApplication) {
+ _inheritsLoose(PublicClientApplication, _ClientApplication);
+
+ /**
+ * Important attributes in the Configuration object for auth are:
+ * - clientID: the application ID of your application. You can obtain one by registering your application with our Application registration portal.
+ * - authority: the authority URL for your application.
+ *
+ * AAD authorities are of the form https://login.microsoftonline.com/\{Enter_the_Tenant_Info_Here\}.
+ * - If your application supports Accounts in one organizational directory, replace "Enter_the_Tenant_Info_Here" value with the Tenant Id or Tenant name (for example, contoso.microsoft.com).
+ * - If your application supports Accounts in any organizational directory, replace "Enter_the_Tenant_Info_Here" value with organizations.
+ * - If your application supports Accounts in any organizational directory and personal Microsoft accounts, replace "Enter_the_Tenant_Info_Here" value with common.
+ * - To restrict support to Personal Microsoft accounts only, replace "Enter_the_Tenant_Info_Here" value with consumers.
+ *
+ * Azure B2C authorities are of the form https://\{instance\}/\{tenant\}/\{policy\}. Each policy is considered
+ * its own authority. You will have to set the all of the knownAuthorities at the time of the client application
+ * construction.
+ *
+ * ADFS authorities are of the form https://\{instance\}/adfs.
+ */
+ function PublicClientApplication(configuration) {
+ return _ClientApplication.call(this, configuration) || this;
+ }
+ /**
+ * Acquires a token from the authority using OAuth2.0 device code flow.
+ * This flow is designed for devices that do not have access to a browser or have input constraints.
+ * The authorization server issues a DeviceCode object with a verification code, an end-user code,
+ * and the end-user verification URI. The DeviceCode object is provided through a callback, and the end-user should be
+ * instructed to use another device to navigate to the verification URI to input credentials.
+ * Since the client cannot receive incoming requests, it polls the authorization server repeatedly
+ * until the end-user completes input of credentials.
+ */
+
+
+ var _proto = PublicClientApplication.prototype;
+
+ _proto.acquireTokenByDeviceCode =
+ /*#__PURE__*/
+ function () {
+ var _acquireTokenByDeviceCode = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee(request) {
+ var validRequest, serverTelemetryManager, deviceCodeConfig, deviceCodeClient;
+ return runtime_1.wrap(function _callee$(_context) {
+ while (1) {
+ switch (_context.prev = _context.next) {
+ case 0:
+ this.logger.info("acquireTokenByDeviceCode called");
+ validRequest = _extends({}, request, this.initializeBaseRequest(request));
+ serverTelemetryManager = this.initializeServerTelemetryManager(ApiId.acquireTokenByDeviceCode, validRequest.correlationId);
+ _context.prev = 3;
+ _context.next = 6;
+ return this.buildOauthClientConfiguration(validRequest.authority, serverTelemetryManager);
+
+ case 6:
+ deviceCodeConfig = _context.sent;
+ this.logger.verbose("Auth client config generated");
+ deviceCodeClient = new msalCommon.DeviceCodeClient(deviceCodeConfig);
+ return _context.abrupt("return", deviceCodeClient.acquireToken(validRequest));
+
+ case 12:
+ _context.prev = 12;
+ _context.t0 = _context["catch"](3);
+ serverTelemetryManager.cacheFailedRequest(_context.t0);
+ throw _context.t0;
+
+ case 16:
+ case "end":
+ return _context.stop();
+ }
+ }
+ }, _callee, this, [[3, 12]]);
+ }));
+
+ function acquireTokenByDeviceCode(_x) {
+ return _acquireTokenByDeviceCode.apply(this, arguments);
+ }
+
+ return acquireTokenByDeviceCode;
+ }()
+ /**
+ * Acquires tokens with password grant by exchanging client applications username and password for credentials
+ *
+ * The latest OAuth 2.0 Security Best Current Practice disallows the password grant entirely.
+ * More details on this recommendation at https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13#section-3.4
+ * Microsoft's documentation and recommendations are at:
+ * https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-authentication-flows#usernamepassword
+ *
+ * @param request - UsenamePasswordRequest
+ */
+ ;
+
+ _proto.acquireTokenByUsernamePassword =
+ /*#__PURE__*/
+ function () {
+ var _acquireTokenByUsernamePassword = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee2(request) {
+ var validRequest, serverTelemetryManager, usernamePasswordClientConfig, usernamePasswordClient;
+ return runtime_1.wrap(function _callee2$(_context2) {
+ while (1) {
+ switch (_context2.prev = _context2.next) {
+ case 0:
+ this.logger.info("acquireTokenByUsernamePassword called");
+ validRequest = _extends({}, request, this.initializeBaseRequest(request));
+ serverTelemetryManager = this.initializeServerTelemetryManager(ApiId.acquireTokenByUsernamePassword, validRequest.correlationId);
+ _context2.prev = 3;
+ _context2.next = 6;
+ return this.buildOauthClientConfiguration(validRequest.authority, serverTelemetryManager);
+
+ case 6:
+ usernamePasswordClientConfig = _context2.sent;
+ this.logger.verbose("Auth client config generated");
+ usernamePasswordClient = new msalCommon.UsernamePasswordClient(usernamePasswordClientConfig);
+ return _context2.abrupt("return", usernamePasswordClient.acquireToken(validRequest));
+
+ case 12:
+ _context2.prev = 12;
+ _context2.t0 = _context2["catch"](3);
+ serverTelemetryManager.cacheFailedRequest(_context2.t0);
+ throw _context2.t0;
+
+ case 16:
+ case "end":
+ return _context2.stop();
+ }
+ }
+ }, _callee2, this, [[3, 12]]);
+ }));
+
+ function acquireTokenByUsernamePassword(_x2) {
+ return _acquireTokenByUsernamePassword.apply(this, arguments);
+ }
+
+ return acquireTokenByUsernamePassword;
+ }();
+
+ return PublicClientApplication;
+}(ClientApplication);
+
+/*
+ * Copyright (c) Microsoft Corporation. All rights reserved.
+ * Licensed under the MIT License.
+ */
+/**
+ * Client assertion of type jwt-bearer used in confidential client flows
+ * @public
+ */
+
+var ClientAssertion = /*#__PURE__*/function () {
+ function ClientAssertion() {}
+
+ /**
+ * Initialize the ClientAssertion class from the clientAssertion passed by the user
+ * @param assertion - refer https://tools.ietf.org/html/rfc7521
+ */
+ ClientAssertion.fromAssertion = function fromAssertion(assertion) {
+ var clientAssertion = new ClientAssertion();
+ clientAssertion.jwt = assertion;
+ return clientAssertion;
+ }
+ /**
+ * Initialize the ClientAssertion class from the certificate passed by the user
+ * @param thumbprint - identifier of a certificate
+ * @param privateKey - secret key
+ * @param publicCertificate - electronic document provided to prove the ownership of the public key
+ */
+ ;
+
+ ClientAssertion.fromCertificate = function fromCertificate(thumbprint, privateKey, publicCertificate) {
+ var clientAssertion = new ClientAssertion();
+ clientAssertion.privateKey = privateKey;
+ clientAssertion.thumbprint = thumbprint;
+
+ if (publicCertificate) {
+ clientAssertion.publicCertificate = this.parseCertificate(publicCertificate);
+ }
+
+ return clientAssertion;
+ }
+ /**
+ * Update JWT for certificate based clientAssertion, if passed by the user, uses it as is
+ * @param cryptoProvider - library's crypto helper
+ * @param issuer - iss claim
+ * @param jwtAudience - aud claim
+ */
+ ;
+
+ var _proto = ClientAssertion.prototype;
+
+ _proto.getJwt = function getJwt(cryptoProvider, issuer, jwtAudience) {
+ // if assertion was created from certificate, check if jwt is expired and create new one.
+ if (this.privateKey && this.thumbprint) {
+ if (this.jwt && !this.isExpired() && issuer === this.issuer && jwtAudience === this.jwtAudience) {
+ return this.jwt;
+ }
+
+ return this.createJwt(cryptoProvider, issuer, jwtAudience);
+ }
+ /*
+ * if assertion was created by caller, then we just append it. It is up to the caller to
+ * ensure that it contains necessary claims and that it is not expired.
+ */
+
+
+ if (this.jwt) {
+ return this.jwt;
+ }
+
+ throw msalCommon.ClientAuthError.createInvalidAssertionError();
+ }
+ /**
+ * JWT format and required claims specified: https://tools.ietf.org/html/rfc7523#section-3
+ */
+ ;
+
+ _proto.createJwt = function createJwt(cryptoProvider, issuer, jwtAudience) {
+ var _header, _payload;
+
+ this.issuer = issuer;
+ this.jwtAudience = jwtAudience;
+ var issuedAt = msalCommon.TimeUtils.nowSeconds();
+ this.expirationTime = issuedAt + 600;
+ var header = (_header = {}, _header[JwtConstants.ALGORITHM] = JwtConstants.RSA_256, _header[JwtConstants.X5T] = EncodingUtils.base64EncodeUrl(this.thumbprint, "hex"), _header);
+
+ if (this.publicCertificate) {
+ var _Object$assign;
+
+ Object.assign(header, (_Object$assign = {}, _Object$assign[JwtConstants.X5C] = this.publicCertificate, _Object$assign));
+ }
+
+ var payload = (_payload = {}, _payload[JwtConstants.AUDIENCE] = this.jwtAudience, _payload[JwtConstants.EXPIRATION_TIME] = this.expirationTime, _payload[JwtConstants.ISSUER] = this.issuer, _payload[JwtConstants.SUBJECT] = this.issuer, _payload[JwtConstants.NOT_BEFORE] = issuedAt, _payload[JwtConstants.JWT_ID] = cryptoProvider.createNewGuid(), _payload);
+ this.jwt = jsonwebtoken.sign(payload, this.privateKey, {
+ header: header
+ });
+ return this.jwt;
+ }
+ /**
+ * Utility API to check expiration
+ */
+ ;
+
+ _proto.isExpired = function isExpired() {
+ return this.expirationTime < msalCommon.TimeUtils.nowSeconds();
+ }
+ /**
+ * Extracts the raw certs from a given certificate string and returns them in an array.
+ * @param publicCertificate - electronic document provided to prove the ownership of the public key
+ */
+ ;
+
+ ClientAssertion.parseCertificate = function parseCertificate(publicCertificate) {
+ /**
+ * This is regex to identify the certs in a given certificate string.
+ * We want to look for the contents between the BEGIN and END certificate strings, without the associated newlines.
+ * The information in parens "(.+?)" is the capture group to represent the cert we want isolated.
+ * "." means any string character, "+" means match 1 or more times, and "?" means the shortest match.
+ * The "g" at the end of the regex means search the string globally, and the "s" enables the "." to match newlines.
+ */
+ var regexToFindCerts = /\x2D\x2D\x2D\x2D\x2DBEGIN CERTIFICATE\x2D\x2D\x2D\x2D\x2D\n([\s\S]+?)\n\x2D\x2D\x2D\x2D\x2DEND CERTIFICATE\x2D\x2D\x2D\x2D\x2D/g;
+ var certs = [];
+ var matches;
+
+ while ((matches = regexToFindCerts.exec(publicCertificate)) !== null) {
+ // matches[1] represents the first parens capture group in the regex.
+ certs.push(matches[1].replace(/\n/, ""));
+ }
+
+ return certs;
+ };
+
+ return ClientAssertion;
+}();
+
+/**
+ * This class is to be used to acquire tokens for confidential client applications (webApp, webAPI). Confidential client applications
+ * will configure application secrets, client certificates/assertions as applicable
+ * @public
+ */
+
+var ConfidentialClientApplication = /*#__PURE__*/function (_ClientApplication) {
+ _inheritsLoose(ConfidentialClientApplication, _ClientApplication);
+
+ /**
+ * Constructor for the ConfidentialClientApplication
+ *
+ * Required attributes in the Configuration object are:
+ * - clientID: the application ID of your application. You can obtain one by registering your application with our application registration portal
+ * - authority: the authority URL for your application.
+ * - client credential: Must set either client secret, certificate, or assertion for confidential clients. You can obtain a client secret from the application registration portal.
+ *
+ * In Azure AD, authority is a URL indicating of the form https://login.microsoftonline.com/\{Enter_the_Tenant_Info_Here\}.
+ * If your application supports Accounts in one organizational directory, replace "Enter_the_Tenant_Info_Here" value with the Tenant Id or Tenant name (for example, contoso.microsoft.com).
+ * If your application supports Accounts in any organizational directory, replace "Enter_the_Tenant_Info_Here" value with organizations.
+ * If your application supports Accounts in any organizational directory and personal Microsoft accounts, replace "Enter_the_Tenant_Info_Here" value with common.
+ * To restrict support to Personal Microsoft accounts only, replace "Enter_the_Tenant_Info_Here" value with consumers.
+ *
+ * In Azure B2C, authority is of the form https://\{instance\}/tfp/\{tenant\}/\{policyName\}/
+ * Full B2C functionality will be available in this library in future versions.
+ *
+ * @param Configuration - configuration object for the MSAL ConfidentialClientApplication instance
+ */
+ function ConfidentialClientApplication(configuration) {
+ var _this;
+
+ _this = _ClientApplication.call(this, configuration) || this;
+
+ _this.setClientCredential(_this.config);
+
+ return _this;
+ }
+ /**
+ * Acquires tokens from the authority for the application (not for an end user).
+ */
+
+
+ var _proto = ConfidentialClientApplication.prototype;
+
+ _proto.acquireTokenByClientCredential =
+ /*#__PURE__*/
+ function () {
+ var _acquireTokenByClientCredential = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee(request) {
+ var validRequest, serverTelemetryManager, clientCredentialConfig, clientCredentialClient;
+ return runtime_1.wrap(function _callee$(_context) {
+ while (1) {
+ switch (_context.prev = _context.next) {
+ case 0:
+ this.logger.info("acquireTokenByClientCredential called");
+ validRequest = _extends({}, request, this.initializeBaseRequest(request));
+ serverTelemetryManager = this.initializeServerTelemetryManager(ApiId.acquireTokenByClientCredential, validRequest.correlationId, validRequest.skipCache);
+ _context.prev = 3;
+ _context.next = 6;
+ return this.buildOauthClientConfiguration(validRequest.authority, serverTelemetryManager);
+
+ case 6:
+ clientCredentialConfig = _context.sent;
+ this.logger.verbose("Auth client config generated");
+ clientCredentialClient = new msalCommon.ClientCredentialClient(clientCredentialConfig);
+ return _context.abrupt("return", clientCredentialClient.acquireToken(validRequest));
+
+ case 12:
+ _context.prev = 12;
+ _context.t0 = _context["catch"](3);
+ serverTelemetryManager.cacheFailedRequest(_context.t0);
+ throw _context.t0;
+
+ case 16:
+ case "end":
+ return _context.stop();
+ }
+ }
+ }, _callee, this, [[3, 12]]);
+ }));
+
+ function acquireTokenByClientCredential(_x) {
+ return _acquireTokenByClientCredential.apply(this, arguments);
+ }
+
+ return acquireTokenByClientCredential;
+ }()
+ /**
+ * Acquires tokens from the authority for the application.
+ *
+ * Used in scenarios where the current app is a middle-tier service which was called with a token
+ * representing an end user. The current app can use the token (oboAssertion) to request another
+ * token to access downstream web API, on behalf of that user.
+ *
+ * The current middle-tier app has no user interaction to obtain consent.
+ * See how to gain consent upfront for your middle-tier app from this article.
+ * https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-on-behalf-of-flow#gaining-consent-for-the-middle-tier-application
+ */
+ ;
+
+ _proto.acquireTokenOnBehalfOf =
+ /*#__PURE__*/
+ function () {
+ var _acquireTokenOnBehalfOf = /*#__PURE__*/_asyncToGenerator( /*#__PURE__*/runtime_1.mark(function _callee2(request) {
+ var validRequest, clientCredentialConfig, oboClient;
+ return runtime_1.wrap(function _callee2$(_context2) {
+ while (1) {
+ switch (_context2.prev = _context2.next) {
+ case 0:
+ this.logger.info("acquireTokenOnBehalfOf called");
+ validRequest = _extends({}, request, this.initializeBaseRequest(request));
+ _context2.next = 4;
+ return this.buildOauthClientConfiguration(validRequest.authority);
+
+ case 4:
+ clientCredentialConfig = _context2.sent;
+ this.logger.verbose("Auth client config generated");
+ oboClient = new msalCommon.OnBehalfOfClient(clientCredentialConfig);
+ return _context2.abrupt("return", oboClient.acquireToken(validRequest));
+
+ case 8:
+ case "end":
+ return _context2.stop();
+ }
+ }
+ }, _callee2, this);
+ }));
+
+ function acquireTokenOnBehalfOf(_x2) {
+ return _acquireTokenOnBehalfOf.apply(this, arguments);
+ }
+
+ return acquireTokenOnBehalfOf;
+ }();
+
+ _proto.setClientCredential = function setClientCredential(configuration) {
+ var clientSecretNotEmpty = !msalCommon.StringUtils.isEmpty(configuration.auth.clientSecret);
+ var clientAssertionNotEmpty = !msalCommon.StringUtils.isEmpty(configuration.auth.clientAssertion);
+ var certificate = configuration.auth.clientCertificate;
+ var certificateNotEmpty = !msalCommon.StringUtils.isEmpty(certificate.thumbprint) || !msalCommon.StringUtils.isEmpty(certificate.privateKey); // Check that at most one credential is set on the application
+
+ if (clientSecretNotEmpty && clientAssertionNotEmpty || clientAssertionNotEmpty && certificateNotEmpty || clientSecretNotEmpty && certificateNotEmpty) {
+ throw msalCommon.ClientAuthError.createInvalidCredentialError();
+ }
+
+ if (clientSecretNotEmpty) {
+ this.clientSecret = configuration.auth.clientSecret;
+ return;
+ }
+
+ if (clientAssertionNotEmpty) {
+ this.clientAssertion = ClientAssertion.fromAssertion(configuration.auth.clientAssertion);
+ return;
+ }
+
+ if (!certificateNotEmpty) {
+ throw msalCommon.ClientAuthError.createInvalidCredentialError();
+ } else {
+ var _configuration$auth$c;
+
+ this.clientAssertion = ClientAssertion.fromCertificate(certificate.thumbprint, certificate.privateKey, (_configuration$auth$c = configuration.auth.clientCertificate) == null ? void 0 : _configuration$auth$c.x5c);
+ }
+ };
+
+ return ConfidentialClientApplication;
+}(ClientApplication);
+
+Object.defineProperty(exports, 'AuthError', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.AuthError;
+ }
+});
+Object.defineProperty(exports, 'AuthErrorMessage', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.AuthErrorMessage;
+ }
+});
+Object.defineProperty(exports, 'ClientAuthError', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.ClientAuthError;
+ }
+});
+Object.defineProperty(exports, 'ClientAuthErrorMessage', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.ClientAuthErrorMessage;
+ }
+});
+Object.defineProperty(exports, 'ClientConfigurationError', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.ClientConfigurationError;
+ }
+});
+Object.defineProperty(exports, 'ClientConfigurationErrorMessage', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.ClientConfigurationErrorMessage;
+ }
+});
+Object.defineProperty(exports, 'InteractionRequiredAuthError', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.InteractionRequiredAuthError;
+ }
+});
+Object.defineProperty(exports, 'LogLevel', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.LogLevel;
+ }
+});
+Object.defineProperty(exports, 'Logger', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.Logger;
+ }
+});
+Object.defineProperty(exports, 'PromptValue', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.PromptValue;
+ }
+});
+Object.defineProperty(exports, 'ProtocolMode', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.ProtocolMode;
+ }
+});
+Object.defineProperty(exports, 'ResponseMode', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.ResponseMode;
+ }
+});
+Object.defineProperty(exports, 'ServerError', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.ServerError;
+ }
+});
+Object.defineProperty(exports, 'TokenCacheContext', {
+ enumerable: true,
+ get: function () {
+ return msalCommon.TokenCacheContext;
+ }
+});
+exports.ClientApplication = ClientApplication;
+exports.ClientAssertion = ClientAssertion;
+exports.ConfidentialClientApplication = ConfidentialClientApplication;
+exports.CryptoProvider = CryptoProvider;
+exports.NodeStorage = NodeStorage;
+exports.PublicClientApplication = PublicClientApplication;
+exports.TokenCache = TokenCache;
+exports.buildAppConfiguration = buildAppConfiguration;
+//# sourceMappingURL=msal-node.cjs.development.js.map
diff --git a/node_modules/@azure/msal-node/dist/msal-node.cjs.development.js.map b/node_modules/@azure/msal-node/dist/msal-node.cjs.development.js.map
new file mode 100644
index 0000000..afb1485
--- /dev/null
+++ b/node_modules/@azure/msal-node/dist/msal-node.cjs.development.js.map
@@ -0,0 +1 @@
+{"version":3,"file":"msal-node.cjs.development.js","sources":["../node_modules/regenerator-runtime/runtime.js","../src/utils/Constants.ts","../src/network/HttpClient.ts","../src/utils/NetworkUtils.ts","../src/config/Configuration.ts","../src/crypto/GuidGenerator.ts","../src/utils/EncodingUtils.ts","../src/crypto/PkceGenerator.ts","../src/crypto/CryptoProvider.ts","../src/cache/serializer/Deserializer.ts","../src/cache/serializer/Serializer.ts","../src/cache/NodeStorage.ts","../src/cache/TokenCache.ts","../src/packageMetadata.ts","../src/client/ClientApplication.ts","../src/client/PublicClientApplication.ts","../src/client/ClientAssertion.ts","../src/client/ConfidentialClientApplication.ts"],"sourcesContent":["/**\n * Copyright (c) 2014-present, Facebook, Inc.\n *\n * This source code is licensed under the MIT license found in the\n * LICENSE file in the root directory of this source tree.\n */\n\nvar runtime = (function (exports) {\n \"use strict\";\n\n var Op = Object.prototype;\n var hasOwn = Op.hasOwnProperty;\n var undefined; // More compressible than void 0.\n var $Symbol = typeof Symbol === \"function\" ? Symbol : {};\n var iteratorSymbol = $Symbol.iterator || \"@@iterator\";\n var asyncIteratorSymbol = $Symbol.asyncIterator || \"@@asyncIterator\";\n var toStringTagSymbol = $Symbol.toStringTag || \"@@toStringTag\";\n\n function define(obj, key, value) {\n Object.defineProperty(obj, key, {\n value: value,\n enumerable: true,\n configurable: true,\n writable: true\n });\n return obj[key];\n }\n try {\n // IE 8 has a broken Object.defineProperty that only works on DOM objects.\n define({}, \"\");\n } catch (err) {\n define = function(obj, key, value) {\n return obj[key] = value;\n };\n }\n\n function wrap(innerFn, outerFn, self, tryLocsList) {\n // If outerFn provided and outerFn.prototype is a Generator, then outerFn.prototype instanceof Generator.\n var protoGenerator = outerFn && outerFn.prototype instanceof Generator ? outerFn : Generator;\n var generator = Object.create(protoGenerator.prototype);\n var context = new Context(tryLocsList || []);\n\n // The ._invoke method unifies the implementations of the .next,\n // .throw, and .return methods.\n generator._invoke = makeInvokeMethod(innerFn, self, context);\n\n return generator;\n }\n exports.wrap = wrap;\n\n // Try/catch helper to minimize deoptimizations. Returns a completion\n // record like context.tryEntries[i].completion. This interface could\n // have been (and was previously) designed to take a closure to be\n // invoked without arguments, but in all the cases we care about we\n // already have an existing method we want to call, so there's no need\n // to create a new function object. We can even get away with assuming\n // the method takes exactly one argument, since that happens to be true\n // in every case, so we don't have to touch the arguments object. The\n // only additional allocation required is the completion record, which\n // has a stable shape and so hopefully should be cheap to allocate.\n function tryCatch(fn, obj, arg) {\n try {\n return { type: \"normal\", arg: fn.call(obj, arg) };\n } catch (err) {\n return { type: \"throw\", arg: err };\n }\n }\n\n var GenStateSuspendedStart = \"suspendedStart\";\n var GenStateSuspendedYield = \"suspendedYield\";\n var GenStateExecuting = \"executing\";\n var GenStateCompleted = \"completed\";\n\n // Returning this object from the innerFn has the same effect as\n // breaking out of the dispatch switch statement.\n var ContinueSentinel = {};\n\n // Dummy constructor functions that we use as the .constructor and\n // .constructor.prototype properties for functions that return Generator\n // objects. For full spec compliance, you may wish to configure your\n // minifier not to mangle the names of these two functions.\n function Generator() {}\n function GeneratorFunction() {}\n function GeneratorFunctionPrototype() {}\n\n // This is a polyfill for %IteratorPrototype% for environments that\n // don't natively support it.\n var IteratorPrototype = {};\n IteratorPrototype[iteratorSymbol] = function () {\n return this;\n };\n\n var getProto = Object.getPrototypeOf;\n var NativeIteratorPrototype = getProto && getProto(getProto(values([])));\n if (NativeIteratorPrototype &&\n NativeIteratorPrototype !== Op &&\n hasOwn.call(NativeIteratorPrototype, iteratorSymbol)) {\n // This environment has a native %IteratorPrototype%; use it instead\n // of the polyfill.\n IteratorPrototype = NativeIteratorPrototype;\n }\n\n var Gp = GeneratorFunctionPrototype.prototype =\n Generator.prototype = Object.create(IteratorPrototype);\n GeneratorFunction.prototype = Gp.constructor = GeneratorFunctionPrototype;\n GeneratorFunctionPrototype.constructor = GeneratorFunction;\n GeneratorFunction.displayName = define(\n GeneratorFunctionPrototype,\n toStringTagSymbol,\n \"GeneratorFunction\"\n );\n\n // Helper for defining the .next, .throw, and .return methods of the\n // Iterator interface in terms of a single ._invoke method.\n function defineIteratorMethods(prototype) {\n [\"next\", \"throw\", \"return\"].forEach(function(method) {\n define(prototype, method, function(arg) {\n return this._invoke(method, arg);\n });\n });\n }\n\n exports.isGeneratorFunction = function(genFun) {\n var ctor = typeof genFun === \"function\" && genFun.constructor;\n return ctor\n ? ctor === GeneratorFunction ||\n // For the native GeneratorFunction constructor, the best we can\n // do is to check its .name property.\n (ctor.displayName || ctor.name) === \"GeneratorFunction\"\n : false;\n };\n\n exports.mark = function(genFun) {\n if (Object.setPrototypeOf) {\n Object.setPrototypeOf(genFun, GeneratorFunctionPrototype);\n } else {\n genFun.__proto__ = GeneratorFunctionPrototype;\n define(genFun, toStringTagSymbol, \"GeneratorFunction\");\n }\n genFun.prototype = Object.create(Gp);\n return genFun;\n };\n\n // Within the body of any async function, `await x` is transformed to\n // `yield regeneratorRuntime.awrap(x)`, so that the runtime can test\n // `hasOwn.call(value, \"__await\")` to determine if the yielded value is\n // meant to be awaited.\n exports.awrap = function(arg) {\n return { __await: arg };\n };\n\n function AsyncIterator(generator, PromiseImpl) {\n function invoke(method, arg, resolve, reject) {\n var record = tryCatch(generator[method], generator, arg);\n if (record.type === \"throw\") {\n reject(record.arg);\n } else {\n var result = record.arg;\n var value = result.value;\n if (value &&\n typeof value === \"object\" &&\n hasOwn.call(value, \"__await\")) {\n return PromiseImpl.resolve(value.__await).then(function(value) {\n invoke(\"next\", value, resolve, reject);\n }, function(err) {\n invoke(\"throw\", err, resolve, reject);\n });\n }\n\n return PromiseImpl.resolve(value).then(function(unwrapped) {\n // When a yielded Promise is resolved, its final value becomes\n // the .value of the Promise<{value,done}> result for the\n // current iteration.\n result.value = unwrapped;\n resolve(result);\n }, function(error) {\n // If a rejected Promise was yielded, throw the rejection back\n // into the async generator function so it can be handled there.\n return invoke(\"throw\", error, resolve, reject);\n });\n }\n }\n\n var previousPromise;\n\n function enqueue(method, arg) {\n function callInvokeWithMethodAndArg() {\n return new PromiseImpl(function(resolve, reject) {\n invoke(method, arg, resolve, reject);\n });\n }\n\n return previousPromise =\n // If enqueue has been called before, then we want to wait until\n // all previous Promises have been resolved before calling invoke,\n // so that results are always delivered in the correct order. If\n // enqueue has not been called before, then it is important to\n // call invoke immediately, without waiting on a callback to fire,\n // so that the async generator function has the opportunity to do\n // any necessary setup in a predictable way. This predictability\n // is why the Promise constructor synchronously invokes its\n // executor callback, and why async functions synchronously\n // execute code before the first await. Since we implement simple\n // async functions in terms of async generators, it is especially\n // important to get this right, even though it requires care.\n previousPromise ? previousPromise.then(\n callInvokeWithMethodAndArg,\n // Avoid propagating failures to Promises returned by later\n // invocations of the iterator.\n callInvokeWithMethodAndArg\n ) : callInvokeWithMethodAndArg();\n }\n\n // Define the unified helper method that is used to implement .next,\n // .throw, and .return (see defineIteratorMethods).\n this._invoke = enqueue;\n }\n\n defineIteratorMethods(AsyncIterator.prototype);\n AsyncIterator.prototype[asyncIteratorSymbol] = function () {\n return this;\n };\n exports.AsyncIterator = AsyncIterator;\n\n // Note that simple async functions are implemented on top of\n // AsyncIterator objects; they just return a Promise for the value of\n // the final result produced by the iterator.\n exports.async = function(innerFn, outerFn, self, tryLocsList, PromiseImpl) {\n if (PromiseImpl === void 0) PromiseImpl = Promise;\n\n var iter = new AsyncIterator(\n wrap(innerFn, outerFn, self, tryLocsList),\n PromiseImpl\n );\n\n return exports.isGeneratorFunction(outerFn)\n ? iter // If outerFn is a generator, return the full iterator.\n : iter.next().then(function(result) {\n return result.done ? result.value : iter.next();\n });\n };\n\n function makeInvokeMethod(innerFn, self, context) {\n var state = GenStateSuspendedStart;\n\n return function invoke(method, arg) {\n if (state === GenStateExecuting) {\n throw new Error(\"Generator is already running\");\n }\n\n if (state === GenStateCompleted) {\n if (method === \"throw\") {\n throw arg;\n }\n\n // Be forgiving, per 25.3.3.3.3 of the spec:\n // https://people.mozilla.org/~jorendorff/es6-draft.html#sec-generatorresume\n return doneResult();\n }\n\n context.method = method;\n context.arg = arg;\n\n while (true) {\n var delegate = context.delegate;\n if (delegate) {\n var delegateResult = maybeInvokeDelegate(delegate, context);\n if (delegateResult) {\n if (delegateResult === ContinueSentinel) continue;\n return delegateResult;\n }\n }\n\n if (context.method === \"next\") {\n // Setting context._sent for legacy support of Babel's\n // function.sent implementation.\n context.sent = context._sent = context.arg;\n\n } else if (context.method === \"throw\") {\n if (state === GenStateSuspendedStart) {\n state = GenStateCompleted;\n throw context.arg;\n }\n\n context.dispatchException(context.arg);\n\n } else if (context.method === \"return\") {\n context.abrupt(\"return\", context.arg);\n }\n\n state = GenStateExecuting;\n\n var record = tryCatch(innerFn, self, context);\n if (record.type === \"normal\") {\n // If an exception is thrown from innerFn, we leave state ===\n // GenStateExecuting and loop back for another invocation.\n state = context.done\n ? GenStateCompleted\n : GenStateSuspendedYield;\n\n if (record.arg === ContinueSentinel) {\n continue;\n }\n\n return {\n value: record.arg,\n done: context.done\n };\n\n } else if (record.type === \"throw\") {\n state = GenStateCompleted;\n // Dispatch the exception by looping back around to the\n // context.dispatchException(context.arg) call above.\n context.method = \"throw\";\n context.arg = record.arg;\n }\n }\n };\n }\n\n // Call delegate.iterator[context.method](context.arg) and handle the\n // result, either by returning a { value, done } result from the\n // delegate iterator, or by modifying context.method and context.arg,\n // setting context.delegate to null, and returning the ContinueSentinel.\n function maybeInvokeDelegate(delegate, context) {\n var method = delegate.iterator[context.method];\n if (method === undefined) {\n // A .throw or .return when the delegate iterator has no .throw\n // method always terminates the yield* loop.\n context.delegate = null;\n\n if (context.method === \"throw\") {\n // Note: [\"return\"] must be used for ES3 parsing compatibility.\n if (delegate.iterator[\"return\"]) {\n // If the delegate iterator has a return method, give it a\n // chance to clean up.\n context.method = \"return\";\n context.arg = undefined;\n maybeInvokeDelegate(delegate, context);\n\n if (context.method === \"throw\") {\n // If maybeInvokeDelegate(context) changed context.method from\n // \"return\" to \"throw\", let that override the TypeError below.\n return ContinueSentinel;\n }\n }\n\n context.method = \"throw\";\n context.arg = new TypeError(\n \"The iterator does not provide a 'throw' method\");\n }\n\n return ContinueSentinel;\n }\n\n var record = tryCatch(method, delegate.iterator, context.arg);\n\n if (record.type === \"throw\") {\n context.method = \"throw\";\n context.arg = record.arg;\n context.delegate = null;\n return ContinueSentinel;\n }\n\n var info = record.arg;\n\n if (! info) {\n context.method = \"throw\";\n context.arg = new TypeError(\"iterator result is not an object\");\n context.delegate = null;\n return ContinueSentinel;\n }\n\n if (info.done) {\n // Assign the result of the finished delegate to the temporary\n // variable specified by delegate.resultName (see delegateYield).\n context[delegate.resultName] = info.value;\n\n // Resume execution at the desired location (see delegateYield).\n context.next = delegate.nextLoc;\n\n // If context.method was \"throw\" but the delegate handled the\n // exception, let the outer generator proceed normally. If\n // context.method was \"next\", forget context.arg since it has been\n // \"consumed\" by the delegate iterator. If context.method was\n // \"return\", allow the original .return call to continue in the\n // outer generator.\n if (context.method !== \"return\") {\n context.method = \"next\";\n context.arg = undefined;\n }\n\n } else {\n // Re-yield the result returned by the delegate method.\n return info;\n }\n\n // The delegate iterator is finished, so forget it and continue with\n // the outer generator.\n context.delegate = null;\n return ContinueSentinel;\n }\n\n // Define Generator.prototype.{next,throw,return} in terms of the\n // unified ._invoke helper method.\n defineIteratorMethods(Gp);\n\n define(Gp, toStringTagSymbol, \"Generator\");\n\n // A Generator should always return itself as the iterator object when the\n // @@iterator function is called on it. Some browsers' implementations of the\n // iterator prototype chain incorrectly implement this, causing the Generator\n // object to not be returned from this call. This ensures that doesn't happen.\n // See https://github.com/facebook/regenerator/issues/274 for more details.\n Gp[iteratorSymbol] = function() {\n return this;\n };\n\n Gp.toString = function() {\n return \"[object Generator]\";\n };\n\n function pushTryEntry(locs) {\n var entry = { tryLoc: locs[0] };\n\n if (1 in locs) {\n entry.catchLoc = locs[1];\n }\n\n if (2 in locs) {\n entry.finallyLoc = locs[2];\n entry.afterLoc = locs[3];\n }\n\n this.tryEntries.push(entry);\n }\n\n function resetTryEntry(entry) {\n var record = entry.completion || {};\n record.type = \"normal\";\n delete record.arg;\n entry.completion = record;\n }\n\n function Context(tryLocsList) {\n // The root entry object (effectively a try statement without a catch\n // or a finally block) gives us a place to store values thrown from\n // locations where there is no enclosing try statement.\n this.tryEntries = [{ tryLoc: \"root\" }];\n tryLocsList.forEach(pushTryEntry, this);\n this.reset(true);\n }\n\n exports.keys = function(object) {\n var keys = [];\n for (var key in object) {\n keys.push(key);\n }\n keys.reverse();\n\n // Rather than returning an object with a next method, we keep\n // things simple and return the next function itself.\n return function next() {\n while (keys.length) {\n var key = keys.pop();\n if (key in object) {\n next.value = key;\n next.done = false;\n return next;\n }\n }\n\n // To avoid creating an additional object, we just hang the .value\n // and .done properties off the next function object itself. This\n // also ensures that the minifier will not anonymize the function.\n next.done = true;\n return next;\n };\n };\n\n function values(iterable) {\n if (iterable) {\n var iteratorMethod = iterable[iteratorSymbol];\n if (iteratorMethod) {\n return iteratorMethod.call(iterable);\n }\n\n if (typeof iterable.next === \"function\") {\n return iterable;\n }\n\n if (!isNaN(iterable.length)) {\n var i = -1, next = function next() {\n while (++i < iterable.length) {\n if (hasOwn.call(iterable, i)) {\n next.value = iterable[i];\n next.done = false;\n return next;\n }\n }\n\n next.value = undefined;\n next.done = true;\n\n return next;\n };\n\n return next.next = next;\n }\n }\n\n // Return an iterator with no values.\n return { next: doneResult };\n }\n exports.values = values;\n\n function doneResult() {\n return { value: undefined, done: true };\n }\n\n Context.prototype = {\n constructor: Context,\n\n reset: function(skipTempReset) {\n this.prev = 0;\n this.next = 0;\n // Resetting context._sent for legacy support of Babel's\n // function.sent implementation.\n this.sent = this._sent = undefined;\n this.done = false;\n this.delegate = null;\n\n this.method = \"next\";\n this.arg = undefined;\n\n this.tryEntries.forEach(resetTryEntry);\n\n if (!skipTempReset) {\n for (var name in this) {\n // Not sure about the optimal order of these conditions:\n if (name.charAt(0) === \"t\" &&\n hasOwn.call(this, name) &&\n !isNaN(+name.slice(1))) {\n this[name] = undefined;\n }\n }\n }\n },\n\n stop: function() {\n this.done = true;\n\n var rootEntry = this.tryEntries[0];\n var rootRecord = rootEntry.completion;\n if (rootRecord.type === \"throw\") {\n throw rootRecord.arg;\n }\n\n return this.rval;\n },\n\n dispatchException: function(exception) {\n if (this.done) {\n throw exception;\n }\n\n var context = this;\n function handle(loc, caught) {\n record.type = \"throw\";\n record.arg = exception;\n context.next = loc;\n\n if (caught) {\n // If the dispatched exception was caught by a catch block,\n // then let that catch block handle the exception normally.\n context.method = \"next\";\n context.arg = undefined;\n }\n\n return !! caught;\n }\n\n for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n var entry = this.tryEntries[i];\n var record = entry.completion;\n\n if (entry.tryLoc === \"root\") {\n // Exception thrown outside of any try block that could handle\n // it, so set the completion value of the entire function to\n // throw the exception.\n return handle(\"end\");\n }\n\n if (entry.tryLoc <= this.prev) {\n var hasCatch = hasOwn.call(entry, \"catchLoc\");\n var hasFinally = hasOwn.call(entry, \"finallyLoc\");\n\n if (hasCatch && hasFinally) {\n if (this.prev < entry.catchLoc) {\n return handle(entry.catchLoc, true);\n } else if (this.prev < entry.finallyLoc) {\n return handle(entry.finallyLoc);\n }\n\n } else if (hasCatch) {\n if (this.prev < entry.catchLoc) {\n return handle(entry.catchLoc, true);\n }\n\n } else if (hasFinally) {\n if (this.prev < entry.finallyLoc) {\n return handle(entry.finallyLoc);\n }\n\n } else {\n throw new Error(\"try statement without catch or finally\");\n }\n }\n }\n },\n\n abrupt: function(type, arg) {\n for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n var entry = this.tryEntries[i];\n if (entry.tryLoc <= this.prev &&\n hasOwn.call(entry, \"finallyLoc\") &&\n this.prev < entry.finallyLoc) {\n var finallyEntry = entry;\n break;\n }\n }\n\n if (finallyEntry &&\n (type === \"break\" ||\n type === \"continue\") &&\n finallyEntry.tryLoc <= arg &&\n arg <= finallyEntry.finallyLoc) {\n // Ignore the finally entry if control is not jumping to a\n // location outside the try/catch block.\n finallyEntry = null;\n }\n\n var record = finallyEntry ? finallyEntry.completion : {};\n record.type = type;\n record.arg = arg;\n\n if (finallyEntry) {\n this.method = \"next\";\n this.next = finallyEntry.finallyLoc;\n return ContinueSentinel;\n }\n\n return this.complete(record);\n },\n\n complete: function(record, afterLoc) {\n if (record.type === \"throw\") {\n throw record.arg;\n }\n\n if (record.type === \"break\" ||\n record.type === \"continue\") {\n this.next = record.arg;\n } else if (record.type === \"return\") {\n this.rval = this.arg = record.arg;\n this.method = \"return\";\n this.next = \"end\";\n } else if (record.type === \"normal\" && afterLoc) {\n this.next = afterLoc;\n }\n\n return ContinueSentinel;\n },\n\n finish: function(finallyLoc) {\n for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n var entry = this.tryEntries[i];\n if (entry.finallyLoc === finallyLoc) {\n this.complete(entry.completion, entry.afterLoc);\n resetTryEntry(entry);\n return ContinueSentinel;\n }\n }\n },\n\n \"catch\": function(tryLoc) {\n for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n var entry = this.tryEntries[i];\n if (entry.tryLoc === tryLoc) {\n var record = entry.completion;\n if (record.type === \"throw\") {\n var thrown = record.arg;\n resetTryEntry(entry);\n }\n return thrown;\n }\n }\n\n // The context.catch method must only be called with a location\n // argument that corresponds to a known catch block.\n throw new Error(\"illegal catch attempt\");\n },\n\n delegateYield: function(iterable, resultName, nextLoc) {\n this.delegate = {\n iterator: values(iterable),\n resultName: resultName,\n nextLoc: nextLoc\n };\n\n if (this.method === \"next\") {\n // Deliberately forget the last sent value so that we don't\n // accidentally pass it on to the delegate.\n this.arg = undefined;\n }\n\n return ContinueSentinel;\n }\n };\n\n // Regardless of whether this script is executing as a CommonJS module\n // or not, return the runtime object so that we can declare the variable\n // regeneratorRuntime in the outer scope, which allows this module to be\n // injected easily by `bin/regenerator --include-runtime script.js`.\n return exports;\n\n}(\n // If this script is executing as a CommonJS module, use module.exports\n // as the regeneratorRuntime namespace. Otherwise create a new empty\n // object. Either way, the resulting object will be used to initialize\n // the regeneratorRuntime variable at the top of this file.\n typeof module === \"object\" ? module.exports : {}\n));\n\ntry {\n regeneratorRuntime = runtime;\n} catch (accidentalStrictMode) {\n // This module should not be running in strict mode, so the above\n // assignment should always work unless something is misconfigured. Just\n // in case runtime.js accidentally runs in strict mode, we can escape\n // strict mode using a global Function call. This could conceivably fail\n // if a Content Security Policy forbids using Function, but in that case\n // the proper solution is to fix the accidental strict mode problem. If\n // you've misconfigured your bundler to force strict mode and applied a\n // CSP to forbid Function, and you're not willing to fix either of those\n // problems, please detail your unique predicament in a GitHub issue.\n Function(\"r\", \"regeneratorRuntime = r\")(runtime);\n}\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\n/**\r\n * http methods\r\n */\r\nexport enum HttpMethod {\r\n GET = \"get\",\r\n POST = \"post\",\r\n}\r\n\r\n/**\r\n * Constant used for PKCE\r\n */\r\nexport const RANDOM_OCTET_SIZE = 32;\r\n\r\n/**\r\n * Constants used in PKCE\r\n */\r\nexport const Hash = {\r\n SHA256: \"sha256\",\r\n};\r\n\r\n/**\r\n * Constants for encoding schemes\r\n */\r\nexport const CharSet = {\r\n CV_CHARSET:\r\n \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-._~\",\r\n};\r\n\r\n/**\r\n * Cache Constants\r\n */\r\nexport const CACHE = {\r\n FILE_CACHE: \"fileCache\",\r\n EXTENSION_LIB: \"extenstion_library\",\r\n};\r\n\r\n/**\r\n * Constants\r\n */\r\nexport const Constants = {\r\n MSAL_SKU: \"msal.js.node\",\r\n JWT_BEARER_ASSERTION_TYPE: \"urn:ietf:params:oauth:client-assertion-type:jwt-bearer\"\r\n};\r\n\r\n/**\r\n * API Codes for Telemetry purposes.\r\n * Before adding a new code you must claim it in the MSAL Telemetry tracker as these number spaces are shared across all MSALs\r\n * 0-99 Silent Flow\r\n * 600-699 Device Code Flow\r\n * 800-899 Auth Code Flow\r\n */\r\nexport enum ApiId {\r\n acquireTokenSilent = 62,\r\n acquireTokenByUsernamePassword = 371,\r\n acquireTokenByDeviceCode = 671,\r\n acquireTokenByClientCredential = 771,\r\n acquireTokenByCode = 871,\r\n acquireTokenByRefreshToken = 872\r\n}\r\n\r\n/**\r\n * JWT constants\r\n */\r\nexport const JwtConstants = {\r\n ALGORITHM: \"alg\",\r\n RSA_256: \"RS256\",\r\n X5T: \"x5t\", \r\n X5C: \"x5c\",\r\n AUDIENCE: \"aud\",\r\n EXPIRATION_TIME: \"exp\",\r\n ISSUER: \"iss\",\r\n SUBJECT: \"sub\",\r\n NOT_BEFORE: \"nbf\",\r\n JWT_ID: \"jti\",\r\n};\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport {\r\n INetworkModule,\r\n NetworkRequestOptions,\r\n NetworkResponse,\r\n} from \"@azure/msal-common\";\r\nimport { HttpMethod } from \"../utils/Constants\";\r\nimport axios, { AxiosRequestConfig } from \"axios\";\r\n\r\n/**\r\n * This class implements the API for network requests.\r\n */\r\nexport class HttpClient implements INetworkModule {\r\n\r\n /**\r\n * Http Get request\r\n * @param url\r\n * @param options\r\n */\r\n async sendGetRequestAsync(\r\n url: string,\r\n options?: NetworkRequestOptions\r\n ): Promise> {\r\n const request: AxiosRequestConfig = {\r\n method: HttpMethod.GET,\r\n url: url,\r\n headers: options && options.headers,\r\n validateStatus: () => true\r\n };\r\n\r\n const response = await axios(request);\r\n return {\r\n headers: response.headers,\r\n body: response.data as T,\r\n status: response.status,\r\n };\r\n }\r\n\r\n /**\r\n * Http Post request\r\n * @param url\r\n * @param options\r\n */\r\n async sendPostRequestAsync(\r\n url: string,\r\n options?: NetworkRequestOptions\r\n ): Promise> {\r\n const request: AxiosRequestConfig = {\r\n method: HttpMethod.POST,\r\n url: url,\r\n data: (options && options.body) || \"\",\r\n headers: options && options.headers,\r\n validateStatus: () => true\r\n };\r\n\r\n const response = await axios(request);\r\n return {\r\n headers: response.headers,\r\n body: response.data as T,\r\n status: response.status,\r\n };\r\n }\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport { INetworkModule } from \"@azure/msal-common\";\r\nimport { HttpClient } from \"../network/HttpClient\";\r\n\r\nexport class NetworkUtils {\r\n /**\r\n * Returns best compatible network client object.\r\n */\r\n static getNetworkClient(): INetworkModule {\r\n return new HttpClient();\r\n }\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport {\r\n LoggerOptions,\r\n INetworkModule,\r\n LogLevel,\r\n ProtocolMode,\r\n ICachePlugin, Constants\r\n} from \"@azure/msal-common\";\r\nimport { NetworkUtils } from \"../utils/NetworkUtils\";\r\n\r\n/**\r\n * - clientId - Client id of the application.\r\n * - authority - Url of the authority. If no value is set, defaults to https://login.microsoftonline.com/common.\r\n * - knownAuthorities - Needed for Azure B2C and ADFS. All authorities that will be used in the client application. Only the host of the authority should be passed in.\r\n * - clientSecret - Secret string that the application uses when requesting a token. Only used in confidential client applications. Can be created in the Azure app registration portal.\r\n * - clientAssertion - Assertion string that the application uses when requesting a token. Only used in confidential client applications. Assertion should be of type urn:ietf:params:oauth:client-assertion-type:jwt-bearer.\r\n * - clientCertificate - Certificate that the application uses when requesting a token. Only used in confidential client applications. Requires hex encoded X.509 SHA-1 thumbprint of the certificiate, and the PEM encoded private key (string should contain -----BEGIN PRIVATE KEY----- ... -----END PRIVATE KEY----- )\r\n * - protocolMode - Enum that represents the protocol that msal follows. Used for configuring proper endpoints.\r\n * @public\r\n */\r\nexport type NodeAuthOptions = {\r\n clientId: string;\r\n authority?: string;\r\n clientSecret?: string;\r\n clientAssertion?:string;\r\n clientCertificate?: {\r\n thumbprint: string,\r\n privateKey: string,\r\n x5c?: string\r\n };\r\n knownAuthorities?: Array;\r\n cloudDiscoveryMetadata?: string;\r\n authorityMetadata?: string,\r\n clientCapabilities?: [];\r\n protocolMode?: ProtocolMode;\r\n};\r\n\r\n/**\r\n * Use this to configure the below cache configuration options:\r\n *\r\n * - cachePlugin - Plugin for reading and writing token cache to disk.\r\n * @public\r\n */\r\nexport type CacheOptions = {\r\n cachePlugin?: ICachePlugin;\r\n};\r\n\r\n/**\r\n * Type for configuring logger and http client options\r\n *\r\n * - logger - Used to initialize the Logger object; TODO: Expand on logger details or link to the documentation on logger\r\n * - networkClient - Http client used for all http get and post calls. Defaults to using MSAL's default http client.\r\n * @public\r\n */\r\nexport type NodeSystemOptions = {\r\n loggerOptions?: LoggerOptions;\r\n networkClient?: INetworkModule;\r\n};\r\n\r\n/**\r\n * Use the configuration object to configure MSAL and initialize the client application object\r\n *\r\n * - auth: this is where you configure auth elements like clientID, authority used for authenticating against the Microsoft Identity Platform\r\n * - cache: this is where you configure cache location\r\n * - system: this is where you can configure the network client, logger\r\n * @public\r\n */\r\nexport type Configuration = {\r\n auth: NodeAuthOptions;\r\n cache?: CacheOptions;\r\n system?: NodeSystemOptions;\r\n};\r\n\r\nconst DEFAULT_AUTH_OPTIONS: NodeAuthOptions = {\r\n clientId: \"\",\r\n authority: Constants.DEFAULT_AUTHORITY,\r\n clientSecret: \"\",\r\n clientAssertion: \"\",\r\n clientCertificate: {\r\n thumbprint: \"\",\r\n privateKey: \"\",\r\n x5c: \"\"\r\n },\r\n knownAuthorities: [],\r\n cloudDiscoveryMetadata: \"\",\r\n authorityMetadata: \"\",\r\n clientCapabilities: [],\r\n protocolMode: ProtocolMode.AAD\r\n};\r\n\r\nconst DEFAULT_CACHE_OPTIONS: CacheOptions = {};\r\n\r\nconst DEFAULT_LOGGER_OPTIONS: LoggerOptions = {\r\n loggerCallback: (): void => {\r\n // allow users to not set logger call back\r\n },\r\n piiLoggingEnabled: false,\r\n logLevel: LogLevel.Info,\r\n};\r\n\r\nconst DEFAULT_SYSTEM_OPTIONS: NodeSystemOptions = {\r\n loggerOptions: DEFAULT_LOGGER_OPTIONS,\r\n networkClient: NetworkUtils.getNetworkClient(),\r\n};\r\n\r\n/**\r\n * Sets the default options when not explicitly configured from app developer\r\n *\r\n * @param auth - Authentication options\r\n * @param cache - Cache options\r\n * @param system - System options\r\n *\r\n * @returns Configuration\r\n * @public\r\n */\r\nexport function buildAppConfiguration({\r\n auth,\r\n cache,\r\n system,\r\n}: Configuration): Configuration {\r\n return {\r\n auth: { ...DEFAULT_AUTH_OPTIONS, ...auth },\r\n cache: { ...DEFAULT_CACHE_OPTIONS, ...cache },\r\n system: { ...DEFAULT_SYSTEM_OPTIONS, ...system },\r\n };\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport { v4 as uuidv4 } from \"uuid\";\r\n\r\nexport class GuidGenerator {\r\n /**\r\n *\r\n * RFC4122: The version 4 UUID is meant for generating UUIDs from truly-random or pseudo-random numbers.\r\n * uuidv4 generates guids from cryprtographically-string random\r\n */\r\n static generateGuid(): string {\r\n return uuidv4();\r\n }\r\n\r\n /**\r\n * verifies if a string is GUID\r\n * @param guid\r\n */\r\n static isGuid(guid: string) {\r\n const regexGuid = /^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;\r\n return regexGuid.test(guid);\r\n }\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nexport class EncodingUtils {\r\n /**\r\n * 'utf8': Multibyte encoded Unicode characters. Many web pages and other document formats use UTF-8.\r\n * 'base64': Base64 encoding.\r\n *\r\n * @param str text\r\n */\r\n static base64Encode(str: string, encoding?: BufferEncoding): string {\r\n return Buffer.from(str, encoding).toString(\"base64\");\r\n }\r\n\r\n /**\r\n * encode a URL\r\n * @param str\r\n */\r\n static base64EncodeUrl(str: string, encoding?: BufferEncoding): string {\r\n return EncodingUtils.base64Encode(str, encoding)\r\n .replace(/=/g, \"\")\r\n .replace(/\\+/g, \"-\")\r\n .replace(/\\//g, \"_\");\r\n }\r\n\r\n /**\r\n * 'utf8': Multibyte encoded Unicode characters. Many web pages and other document formats use UTF-8.\r\n * 'base64': Base64 encoding.\r\n *\r\n * @param base64Str Base64 encoded text\r\n */\r\n static base64Decode(base64Str: string): string {\r\n return Buffer.from(base64Str, \"base64\").toString(\"utf8\");\r\n }\r\n\r\n /**\r\n * @param base64Str Base64 encoded Url\r\n */\r\n static base64DecodeUrl(base64Str: string): string {\r\n let str = base64Str.replace(/-/g, \"+\").replace(/_/g, \"/\");\r\n while (str.length % 4) {\r\n str += \"=\";\r\n }\r\n return EncodingUtils.base64Decode(str);\r\n }\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport { PkceCodes } from \"@azure/msal-common\";\r\nimport { CharSet, Hash, RANDOM_OCTET_SIZE } from \"../utils/Constants\";\r\nimport { EncodingUtils } from \"../utils/EncodingUtils\";\r\nimport crypto from \"crypto\";\r\n\r\n/**\r\n * https://tools.ietf.org/html/rfc7636#page-8\r\n */\r\nexport class PkceGenerator {\r\n /**\r\n * generates the codeVerfier and the challenge from the codeVerfier\r\n * reference: https://tools.ietf.org/html/rfc7636#section-4.1 and https://tools.ietf.org/html/rfc7636#section-4.2\r\n */\r\n async generatePkceCodes(): Promise {\r\n const verifier = this.generateCodeVerifier();\r\n const challenge = this.generateCodeChallengeFromVerifier(verifier);\r\n return { verifier, challenge };\r\n }\r\n\r\n /**\r\n * generates the codeVerfier; reference: https://tools.ietf.org/html/rfc7636#section-4.1\r\n */\r\n private generateCodeVerifier(): string {\r\n const buffer: Uint8Array = crypto.randomBytes(RANDOM_OCTET_SIZE);\r\n const verifier: string = this.bufferToCVString(buffer);\r\n return EncodingUtils.base64EncodeUrl(verifier);\r\n }\r\n\r\n /**\r\n * generate the challenge from the codeVerfier; reference: https://tools.ietf.org/html/rfc7636#section-4.2\r\n * @param codeVerifier\r\n */\r\n private generateCodeChallengeFromVerifier(codeVerifier: string): string {\r\n return EncodingUtils.base64EncodeUrl(\r\n this.sha256(codeVerifier).toString(\"base64\"), \r\n \"base64\"\r\n );\r\n }\r\n\r\n /**\r\n * generate 'SHA256' hash\r\n * @param buffer\r\n */\r\n private sha256(buffer: string): Buffer {\r\n return crypto\r\n .createHash(Hash.SHA256)\r\n .update(buffer)\r\n .digest();\r\n }\r\n\r\n /**\r\n * Accepted characters; reference: https://tools.ietf.org/html/rfc7636#section-4.1\r\n * @param buffer\r\n */\r\n private bufferToCVString(buffer: Uint8Array): string {\r\n const charArr = [];\r\n for (let i = 0; i < buffer.byteLength; i += 1) {\r\n const index = buffer[i] % CharSet.CV_CHARSET.length;\r\n charArr.push(CharSet.CV_CHARSET[index]);\r\n }\r\n return charArr.join(\"\");\r\n }\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport { ICrypto, PkceCodes } from \"@azure/msal-common\";\r\nimport { GuidGenerator } from \"./GuidGenerator\";\r\nimport { EncodingUtils } from \"../utils/EncodingUtils\";\r\nimport { PkceGenerator } from \"./PkceGenerator\";\r\n\r\n/**\r\n * This class implements MSAL node's crypto interface, which allows it to perform base64 encoding and decoding, generating cryptographically random GUIDs and\r\n * implementing Proof Key for Code Exchange specs for the OAuth Authorization Code Flow using PKCE (rfc here: https://tools.ietf.org/html/rfc7636).\r\n * @public\r\n */\r\nexport class CryptoProvider implements ICrypto {\r\n private pkceGenerator: PkceGenerator;\r\n\r\n constructor() {\r\n // Browser crypto needs to be validated first before any other classes can be set.\r\n this.pkceGenerator = new PkceGenerator();\r\n }\r\n\r\n /**\r\n * Creates a new random GUID - used to populate state and nonce.\r\n * @returns string (GUID)\r\n */\r\n createNewGuid(): string {\r\n return GuidGenerator.generateGuid();\r\n }\r\n\r\n /**\r\n * Encodes input string to base64.\r\n * @param input - string to be encoded\r\n */\r\n base64Encode(input: string): string {\r\n return EncodingUtils.base64Encode(input);\r\n }\r\n\r\n /**\r\n * Decodes input string from base64.\r\n * @param input - string to be decoded\r\n */\r\n base64Decode(input: string): string {\r\n return EncodingUtils.base64Decode(input);\r\n }\r\n\r\n /**\r\n * Generates PKCE codes used in Authorization Code Flow.\r\n */\r\n generatePkceCodes(): Promise {\r\n return this.pkceGenerator.generatePkceCodes();\r\n }\r\n\r\n /**\r\n * Generates a keypair, stores it and returns a thumbprint - not yet implemented for node\r\n */\r\n getPublicKeyThumbprint(): Promise {\r\n throw new Error(\"Method not implemented.\");\r\n }\r\n\r\n /**\r\n * Signs the given object as a jwt payload with private key retrieved by given kid - currently not implemented for node\r\n */\r\n signJwt(): Promise {\r\n throw new Error(\"Method not implemented.\");\r\n }\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport { StringUtils, AccountCache, IdTokenCache, AccessTokenCache, RefreshTokenCache, AppMetadataCache, AccountEntity, IdTokenEntity, AccessTokenEntity, RefreshTokenEntity, AppMetadataEntity, CacheManager } from \"@azure/msal-common\";\r\nimport { JsonCache, InMemoryCache, SerializedAccountEntity, SerializedIdTokenEntity, SerializedAccessTokenEntity, SerializedRefreshTokenEntity, SerializedAppMetadataEntity } from \"./SerializerTypes\";\r\n\r\n/**\r\n * This class deserializes cache entities read from the file into in memory object types defined internally\r\n */\r\nexport class Deserializer {\r\n /**\r\n * Parse the JSON blob in memory and deserialize the content\r\n * @param cachedJson\r\n */\r\n static deserializeJSONBlob(jsonFile: string): JsonCache {\r\n const deserializedCache = StringUtils.isEmpty(jsonFile)\r\n ? {}\r\n : JSON.parse(jsonFile);\r\n return deserializedCache;\r\n }\r\n\r\n /**\r\n * Deserializes accounts to AccountEntity objects\r\n * @param accounts\r\n */\r\n static deserializeAccounts(accounts: Record): AccountCache {\r\n const accountObjects: AccountCache = {};\r\n if (accounts) {\r\n Object.keys(accounts).map(function (key) {\r\n const serializedAcc = accounts[key];\r\n const mappedAcc = {\r\n homeAccountId: serializedAcc.home_account_id,\r\n environment: serializedAcc.environment,\r\n realm: serializedAcc.realm,\r\n localAccountId: serializedAcc.local_account_id,\r\n username: serializedAcc.username,\r\n authorityType: serializedAcc.authority_type,\r\n name: serializedAcc.name,\r\n clientInfo: serializedAcc.client_info,\r\n lastModificationTime: serializedAcc.last_modification_time,\r\n lastModificationApp: serializedAcc.last_modification_app,\r\n };\r\n const account: AccountEntity = new AccountEntity();\r\n CacheManager.toObject(account, mappedAcc);\r\n accountObjects[key] = account;\r\n });\r\n }\r\n\r\n return accountObjects;\r\n }\r\n\r\n /**\r\n * Deserializes id tokens to IdTokenEntity objects\r\n * @param idTokens\r\n */\r\n static deserializeIdTokens(idTokens: Record): IdTokenCache {\r\n const idObjects: IdTokenCache = {};\r\n if (idTokens) {\r\n Object.keys(idTokens).map(function (key) {\r\n const serializedIdT = idTokens[key];\r\n const mappedIdT = {\r\n homeAccountId: serializedIdT.home_account_id,\r\n environment: serializedIdT.environment,\r\n credentialType: serializedIdT.credential_type,\r\n clientId: serializedIdT.client_id,\r\n secret: serializedIdT.secret,\r\n realm: serializedIdT.realm,\r\n };\r\n const idToken: IdTokenEntity = new IdTokenEntity();\r\n CacheManager.toObject(idToken, mappedIdT);\r\n idObjects[key] = idToken;\r\n });\r\n }\r\n return idObjects;\r\n }\r\n\r\n /**\r\n * Deserializes access tokens to AccessTokenEntity objects\r\n * @param accessTokens\r\n */\r\n static deserializeAccessTokens(accessTokens: Record): AccessTokenCache {\r\n const atObjects: AccessTokenCache = {};\r\n if (accessTokens) {\r\n Object.keys(accessTokens).map(function (key) {\r\n const serializedAT = accessTokens[key];\r\n const mappedAT = {\r\n homeAccountId: serializedAT.home_account_id,\r\n environment: serializedAT.environment,\r\n credentialType: serializedAT.credential_type,\r\n clientId: serializedAT.client_id,\r\n secret: serializedAT.secret,\r\n realm: serializedAT.realm,\r\n target: serializedAT.target,\r\n cachedAt: serializedAT.cached_at,\r\n expiresOn: serializedAT.expires_on,\r\n extendedExpiresOn: serializedAT.extended_expires_on,\r\n refreshOn: serializedAT.refresh_on,\r\n keyId: serializedAT.key_id,\r\n tokenType: serializedAT.token_type,\r\n };\r\n const accessToken: AccessTokenEntity = new AccessTokenEntity();\r\n CacheManager.toObject(accessToken, mappedAT);\r\n atObjects[key] = accessToken;\r\n });\r\n }\r\n\r\n return atObjects;\r\n }\r\n\r\n /**\r\n * Deserializes refresh tokens to RefreshTokenEntity objects\r\n * @param refreshTokens\r\n */\r\n static deserializeRefreshTokens(refreshTokens: Record): RefreshTokenCache {\r\n const rtObjects: RefreshTokenCache = {};\r\n if (refreshTokens) {\r\n Object.keys(refreshTokens).map(function (key) {\r\n const serializedRT = refreshTokens[key];\r\n const mappedRT = {\r\n homeAccountId: serializedRT.home_account_id,\r\n environment: serializedRT.environment,\r\n credentialType: serializedRT.credential_type,\r\n clientId: serializedRT.client_id,\r\n secret: serializedRT.secret,\r\n familyId: serializedRT.family_id,\r\n target: serializedRT.target,\r\n realm: serializedRT.realm,\r\n };\r\n const refreshToken: RefreshTokenEntity = new RefreshTokenEntity();\r\n CacheManager.toObject(refreshToken, mappedRT);\r\n rtObjects[key] = refreshToken;\r\n });\r\n }\r\n\r\n return rtObjects;\r\n }\r\n\r\n /**\r\n * Deserializes appMetadata to AppMetaData objects\r\n * @param appMetadata\r\n */\r\n static deserializeAppMetadata(appMetadata: Record): AppMetadataCache {\r\n const appMetadataObjects: AppMetadataCache = {};\r\n if (appMetadata) {\r\n Object.keys(appMetadata).map(function (key) {\r\n const serializedAmdt = appMetadata[key];\r\n const mappedAmd = {\r\n clientId: serializedAmdt.client_id,\r\n environment: serializedAmdt.environment,\r\n familyId: serializedAmdt.family_id,\r\n };\r\n const amd: AppMetadataEntity = new AppMetadataEntity();\r\n CacheManager.toObject(amd, mappedAmd);\r\n appMetadataObjects[key] = amd;\r\n });\r\n }\r\n\r\n return appMetadataObjects;\r\n }\r\n\r\n /**\r\n * Deserialize an inMemory Cache\r\n * @param jsonCache\r\n */\r\n static deserializeAllCache(jsonCache: JsonCache): InMemoryCache {\r\n return {\r\n accounts: jsonCache.Account\r\n ? this.deserializeAccounts(jsonCache.Account)\r\n : {},\r\n idTokens: jsonCache.IdToken\r\n ? this.deserializeIdTokens(jsonCache.IdToken)\r\n : {},\r\n accessTokens: jsonCache.AccessToken\r\n ? this.deserializeAccessTokens(jsonCache.AccessToken)\r\n : {},\r\n refreshTokens: jsonCache.RefreshToken\r\n ? this.deserializeRefreshTokens(jsonCache.RefreshToken)\r\n : {},\r\n appMetadata: jsonCache.AppMetadata\r\n ? this.deserializeAppMetadata(jsonCache.AppMetadata)\r\n : {},\r\n };\r\n }\r\n}\r\n","/*\r\n * Copyright (c) Microsoft Corporation. All rights reserved.\r\n * Licensed under the MIT License.\r\n */\r\n\r\nimport { AccountCache, IdTokenCache, AccessTokenCache, RefreshTokenCache, AppMetadataCache } from \"@azure/msal-common\";\r\nimport { InMemoryCache, JsonCache, SerializedAccountEntity, SerializedIdTokenEntity, SerializedAccessTokenEntity, SerializedRefreshTokenEntity, SerializedAppMetadataEntity } from \"./SerializerTypes\";\r\n\r\nexport class Serializer {\r\n /**\r\n * serialize the JSON blob\r\n * @param data\r\n */\r\n static serializeJSONBlob(data: JsonCache): string {\r\n return JSON.stringify(data);\r\n }\r\n\r\n /**\r\n * Serialize Accounts\r\n * @param accCache\r\n */\r\n static serializeAccounts(accCache: AccountCache): Record {\r\n const accounts: Record = {};\r\n Object.keys(accCache).map(function (key) {\r\n const accountEntity = accCache[key];\r\n accounts[key] = {\r\n home_account_id: accountEntity.homeAccountId,\r\n environment: accountEntity.environment,\r\n realm: accountEntity.realm,\r\n local_account_id: accountEntity.localAccountId,\r\n username: accountEntity.username,\r\n authority_type: accountEntity.authorityType,\r\n name: accountEntity.name,\r\n client_info: accountEntity.clientInfo,\r\n last_modification_time: accountEntity.lastModificationTime,\r\n last_modification_app: accountEntity.lastModificationApp,\r\n };\r\n });\r\n\r\n return accounts;\r\n }\r\n\r\n /**\r\n * Serialize IdTokens\r\n * @param idTCache\r\n */\r\n static serializeIdTokens(idTCache: IdTokenCache): Record {\r\n const idTokens: Record = {};\r\n Object.keys(idTCache).map(function (key) {\r\n const idTEntity = idTCache[key];\r\n idTokens[key] = {\r\n home_account_id: idTEntity.homeAccountId,\r\n environment: idTEntity.environment,\r\n credential_type: idTEntity.credentialType,\r\n client_id: idTEntity.clientId,\r\n secret: idTEntity.secret,\r\n realm: idTEntity.realm,\r\n };\r\n });\r\n\r\n return idTokens;\r\n }\r\n\r\n /**\r\n * Serializes AccessTokens\r\n * @param atCache\r\n */\r\n static serializeAccessTokens(atCache: AccessTokenCache): Record {\r\n const accessTokens: Record = {};\r\n Object.keys(atCache).map(function (key) {\r\n const atEntity = atCache[key];\r\n accessTokens[key] = {\r\n home_account_id: atEntity.homeAccountId,\r\n environment: atEntity.environment,\r\n credential_type: atEntity.credentialType,\r\n client_id: atEntity.clientId,\r\n secret: atEntity.secret,\r\n realm: atEntity.realm,\r\n target: atEntity.target,\r\n cached_at: atEntity.cachedAt,\r\n expires_on: atEntity.expiresOn,\r\n extended_expires_on: atEntity.extendedExpiresOn,\r\n refresh_on: atEntity.refreshOn,\r\n key_id: atEntity.keyId,\r\n token_type: atEntity.tokenType,\r\n };\r\n });\r\n\r\n return accessTokens;\r\n }\r\n\r\n /**\r\n * Serialize refreshTokens\r\n * @param rtCache\r\n */\r\n static serializeRefreshTokens(rtCache: RefreshTokenCache): Record {\r\n const refreshTokens: Record = {};\r\n Object.keys(rtCache).map(function (key) {\r\n const rtEntity = rtCache[key];\r\n refreshTokens[key] = {\r\n home_account_id: rtEntity.homeAccountId,\r\n environment: rtEntity.environment,\r\n credential_type: rtEntity.credentialType,\r\n client_id: rtEntity.clientId,\r\n secret: rtEntity.secret,\r\n family_id: rtEntity.familyId,\r\n target: rtEntity.target,\r\n realm: rtEntity.realm\r\n };\r\n });\r\n\r\n return refreshTokens;\r\n }\r\n\r\n /**\r\n * Serialize amdtCache\r\n * @param amdtCache\r\n */\r\n static serializeAppMetadata(amdtCache: AppMetadataCache): Record