diff --git a/examples/sep10-auth/.gitignore b/examples/sep10-auth/.gitignore new file mode 100644 index 0000000..c2658d7 --- /dev/null +++ b/examples/sep10-auth/.gitignore @@ -0,0 +1 @@ +node_modules/ diff --git a/examples/sep10-auth/README.md b/examples/sep10-auth/README.md new file mode 100644 index 0000000..d213297 --- /dev/null +++ b/examples/sep10-auth/README.md @@ -0,0 +1,146 @@ +# SEP-10 Authentication for SwapTrade (Reference Implementation) + +Issue #260 — SEP-10 / Soroban-compatible authentication patterns and +examples for secure user onboarding into swaps and approvals. + +This package is a dependency-light, fully offline reference implementation of +the [SEP-10](https://github.com/stellar/stellar-protocol/blob/master/ecosystem/sep-0010.md) +challenge/response flow, plus two integration patterns showing how an +authenticated identity gates **Soroban contract invocations**. It is written +in TypeScript with no runtime dependencies other than `tweetnacl` (ed25519), +so it runs anywhere the SwapTrade backend runs. + +``` +src/sep10.ts challenge creation + verification, strkey codec, + session tokens (JWT analogue), replay guard +src/gating.ts Sep10Gate: session-gated contract intents and a + fee-sponsored relayer flow with signed intents +__tests__/ 14 tests: accepted flows, rejected flows, replay protection +``` + +## Quick start + +```bash +cd examples/sep10-auth +npm install # --ignore-scripts is fine; tweetnacl has none anyway +npm test # 14 passing tests +npx tsc --noEmit # strict typecheck +``` + +## The flow, step by step + +### 1. Server issues a challenge + +```ts +import { createChallenge } from "./src/sep10.js"; + +const serverSeedHex = "...64 hex chars..."; // server signing key seed +const { challenge, signedPayload } = createChallenge( + serverSeedHex, + clientAccountIdGStrKey, + Math.floor(Date.now() / 1000), + "dapp.example.com", // optional client_domain +); +// `signedPayload` is the canonical byte string both parties sign. +// Sign it with the SERVER key and return { challenge, serverSignature } +// to the client. +``` + +In full SEP-10 this payload is carried inside a Stellar transaction with +`manage_data` operations (`swaptrade auth` -> nonce, +`swaptrade client_domain` -> domain). The signing and verification rules are +identical; swap this layer for `@stellar/stellar-sdk`'s transaction builder +when wiring against a real anchor/domain server. + +### 2. Client countersigns + +```ts +import { signBytes } from "./src/sep10.js"; +const clientSignature = signBytes(signedPayload, clientSeedHex); +``` + +The client signs with the ed25519 key matching its `G...` account — exactly +what Stellar wallets (Freighter, etc.) do during SEP-10 web auth. + +### 3. Server verifies and mints a session token + +```ts +import nacl from "tweetnacl"; +import { Sep10Gate } from "./src/gating.js"; + +const gate = new Sep10Gate(serverPublicKeyRaw, serverSeedHex); + +const result = gate.completeChallenge(challenge, serverSig, clientSig); +if (!result.allowed) throw new Error(result.reason); +const sessionToken = result.token!; // HMAC-signed, expiring JWT analogue +``` + +Verification enforces all SEP-10 core rules: + +| Rule | Where | +| --- | --- | +| Both signatures present and valid | `verifyChallenge` | +| Server signature binds the advertised server account | step 1 of `verifyChallenge` | +| Client signature matches `challenge.clientAccount` | step 2 of `verifyChallenge` | +| Challenge used within its validity window | time check in `verifyChallenge` | +| Challenge nonce single-use (replay protection) | `ReplayGuard` in `Sep10Gate.completeChallenge` | + +### 4a. Gate contract-invoking operations on the session + +```ts +const intent = { + contractId: "CAS3J7GYLGXMF6TDJBBYYE3JNNFRVLDDTT6E8B2LNL4N25Q6YVGB72PI", + functionName: "execute_swap", + args: [{ amount: "100000000" }], + nonce: nextNonce(), +}; + +const verdict = gate.authorizeWithToken(sessionToken, intent); +if (!verdict.allowed) return res.status(401).json({ error: verdict.reason }); + +// Safe to relay: build & submit the Soroban invocation here, using +// verdict.account as the authorization entry signer / source account. +await sorobanServer.submitTransaction(buildInvocation(verdict.account!, intent)); +``` + +On-chain authorization stays anchored to the authenticated identity because +the relayer uses the verified account in the Soroban auth entry rather than +trusting a client-supplied address. + +### 4b. Fee-sponsored relayer with signed intents + +For flows where the backend pays fees, clients sign the *intent* itself: + +```ts +import { intentPayload } from "./src/gating.js"; +const signature = signBytes(intentPayload(intent), clientSeedHex); + +const verdict = gate.authorizeSignedIntent(clientAccountId, intent, signature); +``` + +The relayer validates the ed25519 signature against the claimed account and +enforces per-account single-use `(contract, function, args, nonce)` tuples, +preventing both forgery and replay. + +## Adopting SEP-10 in your DApp (GrantFox / Stellar support eligibility) + +Stellar and GrantFox look for standards-compliant authentication when +evaluating DApps. To adopt: + +1. Run an auth endpoint implementing steps 1–3 above (or use a hosted + anchor's `/auth`). +2. Treat the resulting token as your session credential; never accept raw + account ids from request bodies for privileged operations. +3. Gate every contract-invoking route through pattern 4a or 4b. +4. Keep nonces single-use and challenges short-lived (15 min default) — + both are enforced by this module. + +## Test coverage + +`npm test` exercises: + +- accepted end-to-end challenge -> token -> gated invocation +- rejected flows: wrong client key, tampered payloads, expired/out-of-window + challenges, forged/expired session tokens, malformed accounts +- replay protections: reused challenge nonce, repeated intent under a fresh + token, repeated signed intent at the relayer diff --git a/examples/sep10-auth/__tests__/sep10.test.ts b/examples/sep10-auth/__tests__/sep10.test.ts new file mode 100644 index 0000000..44e331c --- /dev/null +++ b/examples/sep10-auth/__tests__/sep10.test.ts @@ -0,0 +1,257 @@ +/** + * Tests for the SEP-10 example (issue #260): accepted flows, rejected + * flows and replay protections. + * + * Run with: npm test + */ +import { describe, expect, it } from "vitest"; +import nacl from "tweetnacl"; +import { + Challenge, + ReplayGuard, + canonicalPayload, + createChallenge, + decodeStrKey, + encodeStrKey, + issueSessionToken, + signBytes, + verifyChallenge, + verifySessionToken, +} from "../src/sep10.js"; +import { ContractIntent, Sep10Gate, intentPayload } from "../src/gating.js"; + +const T0 = 1_700_000_000; + +function serverKeyPair() { + const seed = Buffer.alloc(32, 7); // deterministic test seed + return nacl.sign.keyPair.fromSeed(seed); +} + +function makeClient() { + const pair = nacl.sign.keyPair(); + return { accountId: encodeStrKey(pair.publicKey), secret: pair.secretKey }; +} + +function clientSign(secret: Uint8Array, payload: string): string { + return Buffer.from(nacl.sign.detached(Buffer.from(payload, "utf8"), secret)).toString("base64"); +} + +describe("strkey codec", () => { + it("round-trips ed25519 keys as G... addresses", () => { + const raw = serverKeyPair().publicKey; + const str = encodeStrKey(raw); + expect(str[0]).toBe("G"); + expect(str.length).toBe(56); + expect(Buffer.from(decodeStrKey(str)).equals(Buffer.from(raw))).toBe(true); + }); + + it("rejects corrupted checksums", () => { + const str = encodeStrKey(serverKeyPair().publicKey); + const flipped = (str[10] === "A" ? "B" : "A") + str.slice(11); + expect(() => decodeStrKey(flipped)).toThrow(/checksum/); + }); +}); + +describe("challenge verification", () => { + it("accepts a correctly signed challenge", () => { + const server = serverKeyPair(); + const client = makeClient(); + const { challenge } = createChallenge( + Buffer.from(server.secretKey.slice(0, 32)).toString("hex"), + client.accountId, + T0, + ); + const payload = canonicalPayload(challenge); + const serverSig = clientSign(server.secretKey, payload); + const clientSig = clientSign(client.secret, payload); + expect(verifyChallenge(challenge, serverSig, clientSig, server.publicKey, T0 + 1)).toBe(true); + }); + + it("rejects a client signature from a different key", () => { + const server = serverKeyPair(); + const client = makeClient(); + const impostor = makeClient(); + const { challenge } = createChallenge( + Buffer.from(server.secretKey.slice(0, 32)).toString("hex"), + client.accountId, + T0, + ); + const payload = canonicalPayload(challenge); + const serverSig = clientSign(server.secretKey, payload); + const badClientSig = clientSign(impostor.secret, payload); + expect(verifyChallenge(challenge, serverSig, badClientSig, server.publicKey, T0 + 1)).toBe(false); + }); + + it("rejects tampered challenge payloads", () => { + const server = serverKeyPair(); + const client = makeClient(); + const { challenge } = createChallenge( + Buffer.from(server.secretKey.slice(0, 32)).toString("hex"), + client.accountId, + T0, + ); + const serverSig = clientSign(server.secretKey, canonicalPayload(challenge)); + const tampered: Challenge = { ...challenge, nonceB64: Buffer.alloc(64, 9).toString("base64") }; + const clientSig = clientSign(client.secret, canonicalPayload(tampered)); + // Client signed the *tampered* copy but the server signature is over the + // original bytes -> verification must fail. + expect( + verifyChallenge(tampered, serverSig, clientSig, server.publicKey, T0 + 1), + ).toBe(false); + }); + + it("rejects challenges outside the validity window", () => { + const server = serverKeyPair(); + const client = makeClient(); + const { challenge } = createChallenge( + Buffer.from(server.secretKey.slice(0, 32)).toString("hex"), + client.accountId, + T0, + ); + const payload = canonicalPayload(challenge); + const serverSig = clientSign(server.secretKey, payload); + const clientSig = clientSign(client.secret, payload); + + expect(verifyChallenge(challenge, serverSig, clientSig, server.publicKey, T0 - 1)).toBe(false); + expect( + verifyChallenge(challenge, serverSig, clientSig, server.publicKey, challenge.expiresAt), + ).toBe(false); + expect( + verifyChallenge(challenge, serverSig, clientSig, server.publicKey, challenge.expiresAt - 1), + ).toBe(true); + }); +}); + +describe("session tokens", () => { + it("verifies genuine tokens and rejects forgeries/expiry", () => { + const secret = "ab".repeat(32); + const token = issueSessionToken("GAAA", secret, 60, T0); + expect(verifySessionToken(token, secret, T0 + 30)).toBe(true); + expect(verifySessionToken(token, secret, T0 + 60)).toBe(false); // expired + const forged = { ...token, sig: Buffer.alloc(32).toString("base64") }; + expect(verifySessionToken(forged, secret, T0 + 1)).toBe(false); + expect(verifySessionToken(token, "cd".repeat(32), T0 + 1)).toBe(false); + }); +}); + +describe("replay guard", () => { + it("consumes each key exactly once", () => { + const guard = new ReplayGuard(); + expect(guard.consume("n1")).toBe(true); + expect(guard.consume("n1")).toBe(false); + expect(guard.consume("n2")).toBe(true); + expect(guard.size).toBe(2); + }); +}); + +describe("SEP-10 gated contract invocations", () => { + function setupGate() { + const server = serverKeyPair(); + const gate = new Sep10Gate( + server.publicKey, + Buffer.from(server.secretKey.slice(0, 32)).toString("hex"), + () => T0, + ); + return { gate, server }; + } + + function completeFlow(gate: Sep10Gate, server: nacl.SignKeyPair, client: ReturnType) { + const { challenge } = createChallenge( + Buffer.from(server.secretKey.slice(0, 32)).toString("hex"), + client.accountId, + T0, + ); + const payload = canonicalPayload(challenge); + return gate.completeChallenge( + challenge, + clientSign(server.secretKey, payload), + clientSign(client.secret, payload), + ); + } + + const intent: ContractIntent = { + contractId: "CAS3J7GYLGXMF6TDJBBYYE3JNNFRVLDDTT6E8B2LNL4N25Q6YVGB72PI", + functionName: "execute_swap", + args: [{ amount: "100000000" }], + nonce: 1, + }; + + it("mints a session token after a valid challenge and gates calls", () => { + const { gate, server } = setupGate(); + const result = completeFlow(gate, server, makeClient()); + + expect(result.allowed).toBe(true); + expect(result.token).toBeDefined(); + + const authorized = gate.authorizeWithToken(result.token!, intent); + expect(authorized.allowed).toBe(true); + expect(authorized.account).toBeDefined(); + }); + + it("rejects replayed challenges (same nonce reused)", () => { + const { gate, server } = setupGate(); + const client = makeClient(); + const { challenge } = createChallenge( + Buffer.from(server.secretKey.slice(0, 32)).toString("hex"), + client.accountId, + T0, + ); + const payload = canonicalPayload(challenge); + const serverSig = clientSign(server.secretKey, payload); + const clientSig = clientSign(client.secret, payload); + + const first = gate.completeChallenge(challenge, serverSig, clientSig); + expect(first.allowed).toBe(true); + + // The exact same challenge presented again -> replay. + const second = gate.completeChallenge(challenge, serverSig, clientSig); + expect(second.allowed).toBe(false); + expect(second.reason).toMatch(/replay/i); + }); + + it("rejects the same intent twice even under a fresh token", () => { + const { gate, server } = setupGate(); + const client = makeClient(); + const token1 = completeFlow(gate, server, client).token!; + const token2 = completeFlow(gate, server, client).token!; + + expect(gate.authorizeWithToken(token1, intent).allowed).toBe(true); + const again = gate.authorizeWithToken(token2, intent); + expect(again.allowed).toBe(false); + expect(again.reason).toMatch(/replay/i); + }); + + it("rejects expired or forged session tokens", () => { + const { gate, server } = setupGate(); + const token = completeFlow(gate, server, makeClient()).token!; + const expired = { ...token, expiresAt: T0 - 1 }; + expect(gate.authorizeWithToken(expired, intent).reason).toMatch(/invalid or expired/i); + + const forged = { ...token, account: encodeStrKey(nacl.sign.keyPair().publicKey) }; + const res = gate.authorizeWithToken(forged, intent); + expect(res.allowed).toBe(false); + expect(res.reason).toMatch(/invalid or expired/i); + }); + + it("relayer flow verifies signed intents and enforces nonces", () => { + const { gate } = setupGate(); + const client = makeClient(); + const payload = intentPayload(intent); + const sig = clientSign(client.secret, payload); + + expect(gate.authorizeSignedIntent(client.accountId, intent, sig).allowed).toBe(true); + const replayed = gate.authorizeSignedIntent(client.accountId, intent, sig); + expect(replayed.allowed).toBe(false); + expect(replayed.reason).toMatch(/replay/i); + }); + + it("relayer rejects intents signed by another key", () => { + const { gate } = setupGate(); + const attacker = makeClient(); + const sig = clientSign(attacker.secret, intentPayload(intent)); + const victim = makeClient(); + const res = gate.authorizeSignedIntent(victim.accountId, intent, sig); + expect(res.allowed).toBe(false); + expect(res.reason).toMatch(/signature invalid/i); + }); +}); diff --git a/examples/sep10-auth/package-lock.json b/examples/sep10-auth/package-lock.json new file mode 100644 index 0000000..f2ab197 --- /dev/null +++ b/examples/sep10-auth/package-lock.json @@ -0,0 +1,1482 @@ +{ + "name": "@swaptrade/sep10-auth-example", + "version": "1.0.0", + "lockfileVersion": 3, + "requires": true, + "packages": { + "": { + "name": "@swaptrade/sep10-auth-example", + "version": "1.0.0", + "dependencies": { + "tweetnacl": "^1.0.3" + }, + "devDependencies": { + "@types/node": "^20.14.0", + "typescript": "^5.5.4", + "vitest": "^2.1.9" + } + }, + "node_modules/@esbuild/aix-ppc64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/aix-ppc64/-/aix-ppc64-0.21.5.tgz", + "integrity": "sha512-1SDgH6ZSPTlggy1yI6+Dbkiz8xzpHJEVAlF/AM1tHPLsf5STom9rwtjE4hKAF20FfXXNTFqEYXyJNWh1GiZedQ==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "aix" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/android-arm": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/android-arm/-/android-arm-0.21.5.tgz", + "integrity": "sha512-vCPvzSjpPHEi1siZdlvAlsPxXl7WbOVUBBAowWug4rJHb68Ox8KualB+1ocNvT5fjv6wpkX6o/iEpbDrf68zcg==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/android-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/android-arm64/-/android-arm64-0.21.5.tgz", + "integrity": "sha512-c0uX9VAUBQ7dTDCjq+wdyGLowMdtR/GoC2U5IYk/7D1H1JYC0qseD7+11iMP2mRLN9RcCMRcjC4YMclCzGwS/A==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/android-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/android-x64/-/android-x64-0.21.5.tgz", + "integrity": "sha512-D7aPRUUNHRBwHxzxRvp856rjUHRFW1SdQATKXH2hqA0kAZb1hKmi02OpYRacl0TxIGz/ZmXWlbZgjwWYaCakTA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/darwin-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/darwin-arm64/-/darwin-arm64-0.21.5.tgz", + "integrity": "sha512-DwqXqZyuk5AiWWf3UfLiRDJ5EDd49zg6O9wclZ7kUMv2WRFr4HKjXp/5t8JZ11QbQfUS6/cRCKGwYhtNAY88kQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/darwin-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/darwin-x64/-/darwin-x64-0.21.5.tgz", + "integrity": "sha512-se/JjF8NlmKVG4kNIuyWMV/22ZaerB+qaSi5MdrXtd6R08kvs2qCN4C09miupktDitvh8jRFflwGFBQcxZRjbw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/freebsd-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/freebsd-arm64/-/freebsd-arm64-0.21.5.tgz", + "integrity": "sha512-5JcRxxRDUJLX8JXp/wcBCy3pENnCgBR9bN6JsY4OmhfUtIHe3ZW0mawA7+RDAcMLrMIZaf03NlQiX9DGyB8h4g==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/freebsd-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/freebsd-x64/-/freebsd-x64-0.21.5.tgz", + "integrity": "sha512-J95kNBj1zkbMXtHVH29bBriQygMXqoVQOQYA+ISs0/2l3T9/kj42ow2mpqerRBxDJnmkUDCaQT/dfNXWX/ZZCQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-arm": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-arm/-/linux-arm-0.21.5.tgz", + "integrity": "sha512-bPb5AHZtbeNGjCKVZ9UGqGwo8EUu4cLq68E95A53KlxAPRmUyYv2D6F0uUI65XisGOL1hBP5mTronbgo+0bFcA==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-arm64/-/linux-arm64-0.21.5.tgz", + "integrity": "sha512-ibKvmyYzKsBeX8d8I7MH/TMfWDXBF3db4qM6sy+7re0YXya+K1cem3on9XgdT2EQGMu4hQyZhan7TeQ8XkGp4Q==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-ia32": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-ia32/-/linux-ia32-0.21.5.tgz", + "integrity": "sha512-YvjXDqLRqPDl2dvRODYmmhz4rPeVKYvppfGYKSNGdyZkA01046pLWyRKKI3ax8fbJoK5QbxblURkwK/MWY18Tg==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-loong64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-loong64/-/linux-loong64-0.21.5.tgz", + "integrity": "sha512-uHf1BmMG8qEvzdrzAqg2SIG/02+4/DHB6a9Kbya0XDvwDEKCoC8ZRWI5JJvNdUjtciBGFQ5PuBlpEOXQj+JQSg==", + "cpu": [ + "loong64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-mips64el": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-mips64el/-/linux-mips64el-0.21.5.tgz", + "integrity": "sha512-IajOmO+KJK23bj52dFSNCMsz1QP1DqM6cwLUv3W1QwyxkyIWecfafnI555fvSGqEKwjMXVLokcV5ygHW5b3Jbg==", + "cpu": [ + "mips64el" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-ppc64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-ppc64/-/linux-ppc64-0.21.5.tgz", + "integrity": "sha512-1hHV/Z4OEfMwpLO8rp7CvlhBDnjsC3CttJXIhBi+5Aj5r+MBvy4egg7wCbe//hSsT+RvDAG7s81tAvpL2XAE4w==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-riscv64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-riscv64/-/linux-riscv64-0.21.5.tgz", + "integrity": "sha512-2HdXDMd9GMgTGrPWnJzP2ALSokE/0O5HhTUvWIbD3YdjME8JwvSCnNGBnTThKGEB91OZhzrJ4qIIxk/SBmyDDA==", + "cpu": [ + "riscv64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-s390x": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-s390x/-/linux-s390x-0.21.5.tgz", + "integrity": "sha512-zus5sxzqBJD3eXxwvjN1yQkRepANgxE9lgOW2qLnmr8ikMTphkjgXu1HR01K4FJg8h1kEEDAqDcZQtbrRnB41A==", + "cpu": [ + "s390x" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-x64/-/linux-x64-0.21.5.tgz", + "integrity": "sha512-1rYdTpyv03iycF1+BhzrzQJCdOuAOtaqHTWJZCWvijKD2N5Xu0TtVC8/+1faWqcP9iBCWOmjmhoH94dH82BxPQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/netbsd-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/netbsd-x64/-/netbsd-x64-0.21.5.tgz", + "integrity": "sha512-Woi2MXzXjMULccIwMnLciyZH4nCIMpWQAs049KEeMvOcNADVxo0UBIQPfSmxB3CWKedngg7sWZdLvLczpe0tLg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "netbsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/openbsd-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/openbsd-x64/-/openbsd-x64-0.21.5.tgz", + "integrity": "sha512-HLNNw99xsvx12lFBUwoT8EVCsSvRNDVxNpjZ7bPn947b8gJPzeHWyNVhFsaerc0n3TsbOINvRP2byTZ5LKezow==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openbsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/sunos-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/sunos-x64/-/sunos-x64-0.21.5.tgz", + "integrity": "sha512-6+gjmFpfy0BHU5Tpptkuh8+uw3mnrvgs+dSPQXQOv3ekbordwnzTVEb4qnIvQcYXq6gzkyTnoZ9dZG+D4garKg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "sunos" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/win32-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/win32-arm64/-/win32-arm64-0.21.5.tgz", + "integrity": "sha512-Z0gOTd75VvXqyq7nsl93zwahcTROgqvuAcYDUr+vOv8uHhNSKROyU961kgtCD1e95IqPKSQKH7tBTslnS3tA8A==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/win32-ia32": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/win32-ia32/-/win32-ia32-0.21.5.tgz", + "integrity": "sha512-SWXFF1CL2RVNMaVs+BBClwtfZSvDgtL//G/smwAc5oVK/UPu2Gu9tIaRgFmYFFKrmg3SyAjSrElf0TiJ1v8fYA==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/win32-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/win32-x64/-/win32-x64-0.21.5.tgz", + "integrity": "sha512-tQd/1efJuzPC6rCFwEvLtci/xNFcTZknmXs98FYDfGE4wP9ClFV98nyKrzJKVPMhdDnjzLhdUyMX4PsQAPjwIw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@jridgewell/sourcemap-codec": { + "version": "1.5.5", + "resolved": "https://registry.npmjs.org/@jridgewell/sourcemap-codec/-/sourcemap-codec-1.5.5.tgz", + "integrity": "sha512-cYQ9310grqxueWbl+WuIUIaiUaDcj7WOq5fVhEljNVgRfOUhY9fy2zTvfoqWsnebh8Sl70VScFbICvJnLKB0Og==", + "dev": true, + "license": "MIT" + }, + "node_modules/@napi-rs/lzma-linux-x64-gnu": { + "version": "1.5.1", + "resolved": "https://registry.npmjs.org/@napi-rs/lzma-linux-x64-gnu/-/lzma-linux-x64-gnu-1.5.1.tgz", + "integrity": "sha512-oTXEIha4SsuXdTA4Iyskj0kpdx2yVXdhd75c2v3xGrHFfVMsbhTPZU/nMPL4sWKo4pBHm3aucLaqGlF696dTyQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^22.20 || ^24.12 || >=25" + } + }, + "node_modules/@rollup/rollup-android-arm-eabi": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-android-arm-eabi/-/rollup-android-arm-eabi-4.62.5.tgz", + "integrity": "sha512-jfkGfTwhQpsiSckPF8r9bU3pn3vyd72NlWaO+TgEO6WPSDnUhXzrNYCHBMOYj0ACaUgjm6eERLF+XV9a6RstoA==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ] + }, + "node_modules/@rollup/rollup-android-arm64": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-android-arm64/-/rollup-android-arm64-4.62.5.tgz", + "integrity": "sha512-oGVqyQlxnrz9/ty89oHpU857VUHEl5/Xu4R2lS+aivCTrNnSsbiENzTnNaBsjxH0CNWGPhzHArOLFwo+oKXveA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ] + }, + "node_modules/@rollup/rollup-darwin-arm64": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-darwin-arm64/-/rollup-darwin-arm64-4.62.5.tgz", + "integrity": "sha512-bW7B8xMEq8n99Q3ieEcPRGuphurdZAaFzQc9Efyyw3FL6DZO6pMy9xhdN+kBoD7Sy05xNXSr4OyPPnpkYriS/A==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ] + }, + "node_modules/@rollup/rollup-darwin-x64": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-darwin-x64/-/rollup-darwin-x64-4.62.5.tgz", + "integrity": "sha512-YSwBS86QeHOGlrxJ1PSOIZSkzRL/JmKeunhc+lV6M1a6En8QuVCD/T/qIA0J4Gd2Y86RIOBYrLcOUtqGh9+/1w==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ] + }, + "node_modules/@rollup/rollup-freebsd-arm64": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-freebsd-arm64/-/rollup-freebsd-arm64-4.62.5.tgz", + "integrity": "sha512-2fST8lILgl7cKbme/1KDdPCmbXbG+gqoV3bHp19L0ypX/3akYMBVdOunPleRCwonoLnXOZ/0F+Mt/v8POFmfcQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ] + }, + "node_modules/@rollup/rollup-freebsd-x64": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-freebsd-x64/-/rollup-freebsd-x64-4.62.5.tgz", + "integrity": "sha512-cpIxQCP9J+EVad0a6LO1kY3ZGODlk80VlI+2I96B8xMcdHZ4pLVhfQ49JFpYqjPF91FFkQWftf57YlDcTiw9yQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ] + }, + "node_modules/@rollup/rollup-linux-arm-gnueabihf": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm-gnueabihf/-/rollup-linux-arm-gnueabihf-4.62.5.tgz", + "integrity": "sha512-r9fGh3eFs3e/udWh5ZjXQtxiYK/xoFxQaYR/cELxac/Udkl5Th+IsFm0CX3Kl9hmUH/we7EoMpjJgeQNnE0+IA==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-arm-musleabihf": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm-musleabihf/-/rollup-linux-arm-musleabihf-4.62.5.tgz", + "integrity": "sha512-xdvFdp7OM6KLJviJT2g/YuRSUjnZgGHk4RNgwIbN7X6cPugOucV60DdHXWzsBVCUdrGb6qSXnJQrrAKMmQuj3Q==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-arm64-gnu": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm64-gnu/-/rollup-linux-arm64-gnu-4.62.5.tgz", + "integrity": "sha512-rRqILAndyzHzP7T9NFQrq+4HFWNhqkqkKur7eiBpfLmz01PO0JKx5Vchu3YllE4YXI/Ftgq/szrDWg5GJ0mI8g==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-arm64-musl": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm64-musl/-/rollup-linux-arm64-musl-4.62.5.tgz", + "integrity": "sha512-Gf4X3qVMucayUvux6aXXPgXovocSFUC0rrffDuPI/S2nHhNMhjcZxsrAFYCOF350PRreW1XwzFj3CT/3bKsWCw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-loong64-gnu": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-loong64-gnu/-/rollup-linux-loong64-gnu-4.62.5.tgz", + "integrity": "sha512-+s5qA0TNM0qm8PK/a5gt/1Hpx+NV08uSuCncvhziIlQzT6AEV2fnUQo7eBtFTFO0nA9scauvoR2HusfXmQnO4w==", + "cpu": [ + "loong64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-loong64-musl": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-loong64-musl/-/rollup-linux-loong64-musl-4.62.5.tgz", + "integrity": "sha512-ybb6QvWwWJCbBWqERpc8K3pYVGIrXlG8MEQ8IIuJY6Y9KdHQxoFoNyfkAOtKn1VHu3KuLidXvwrvGR1mEjeWCw==", + "cpu": [ + "loong64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-ppc64-gnu": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-ppc64-gnu/-/rollup-linux-ppc64-gnu-4.62.5.tgz", + "integrity": "sha512-nZb1DtnOyhCmYvsC8A2CwOkopVg+IS1+fPUa7rMOAXtNw5+lLCLLPqd6XAiNrGtoQKsbvIBOwsHnBH/3wnb4HQ==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-ppc64-musl": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-ppc64-musl/-/rollup-linux-ppc64-musl-4.62.5.tgz", + "integrity": "sha512-yMbj63Sp89ryrXLWyz+sy+fYD2HpOnMCLGbe4Oa1smclFSUukdtD/BgdiHaAetJNb74URD8U4hM+qG5KVzMEkg==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-riscv64-gnu": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-riscv64-gnu/-/rollup-linux-riscv64-gnu-4.62.5.tgz", + "integrity": "sha512-mhoan3OJw2kYV/e1jtIdmvUZgyBFeA6zGWsOswmR0Tg19TQbowZuR+JMLID6spbbBN7Zee2ejrgmy3+FxGrIdA==", + "cpu": [ + "riscv64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-riscv64-musl": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-riscv64-musl/-/rollup-linux-riscv64-musl-4.62.5.tgz", + "integrity": "sha512-5ZTLmjWbb1VZdjuyhe83K/8QO0/h11midQCBP+X5OYn32ra7eOBoM0ZqtaY4nkgNsYgmdVhMYPoyVPTjUpHf3w==", + "cpu": [ + "riscv64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-s390x-gnu": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-s390x-gnu/-/rollup-linux-s390x-gnu-4.62.5.tgz", + "integrity": "sha512-m53kG+br6PGxOTmgBEM2DHSDs9RVjsyEbUwjJPJGTFm1grWOG8EKJggDCTb60unD4Tjby8fi7/m9XfkEWasVWg==", + "cpu": [ + "s390x" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-x64-gnu": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-x64-gnu/-/rollup-linux-x64-gnu-4.62.5.tgz", + "integrity": "sha512-6RHPJR1g/uvdYU8uXBnfq3nlqyZCP82Fr6NHgfGoaIeSh0YEqnX/x6uA9MmJJbnSH7swqX4F+CkGdUF+6doiQA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-x64-musl": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-x64-musl/-/rollup-linux-x64-musl-4.62.5.tgz", + "integrity": "sha512-xs+OXQtEXgpXT0DmA5+U3qnRZHdCST/5HRQxS8wSPZTUZN/EMWeHuSIod32LQklTBZBV9DyfncKBQ8n5V3eFdw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-openbsd-x64": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-openbsd-x64/-/rollup-openbsd-x64-4.62.5.tgz", + "integrity": "sha512-e7hD+sl3s+mcLQDZ8pbudBVsdG6r5yN4w3LqG2TJ8sQHDpblWj5lrJs/3m01Cvlxbt4x13zu5thLjgypgtkYzw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openbsd" + ] + }, + "node_modules/@rollup/rollup-openharmony-arm64": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-openharmony-arm64/-/rollup-openharmony-arm64-4.62.5.tgz", + "integrity": "sha512-GiyJaCf+WpMub/17aPcKk27QMl5W6f+KhdPTjlFOn5akH5Wa/DCM9Stdx5cDfmasyKB08MqpVQ1uJE2RkkpbXg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openharmony" + ] + }, + "node_modules/@rollup/rollup-win32-arm64-msvc": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-arm64-msvc/-/rollup-win32-arm64-msvc-4.62.5.tgz", + "integrity": "sha512-+OQ8U2DdoEfXl8T4Fb18AjmEwbXMerKDKCL8yCPAYhKCEEKoul7rkbeGCBFCbAlaGaa7pmtRTpkAJM2LE/i5FA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@rollup/rollup-win32-ia32-msvc": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-ia32-msvc/-/rollup-win32-ia32-msvc-4.62.5.tgz", + "integrity": "sha512-KanvAZrPKbDBFwrgiU9yEVpQoox9QPV1WZOXX7HudJQY+eSlu82CtWxDU8WtuRRvtN5EGkLczkd6Y6DTcvm9wA==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@rollup/rollup-win32-x64-gnu": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-x64-gnu/-/rollup-win32-x64-gnu-4.62.5.tgz", + "integrity": "sha512-1aC3UEWTtRl3RK3VpDJ/Tqk1XI4SLTmXIthAq6wRWo8XiSXJNd+VprJM4/1P4+i6HIaFEFlVi9sTTziniD2tOQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@rollup/rollup-win32-x64-msvc": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-x64-msvc/-/rollup-win32-x64-msvc-4.62.5.tgz", + "integrity": "sha512-/gDJaRs4gl0NPIwqCz+6PkpmhhjRAD2j6P4rSNHBzUkO3naEx2mIU0pRle1vUNRQ7mE/+8OOeXLTv/J56FKiQg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@types/estree": { + "version": "1.0.9", + "resolved": "https://registry.npmjs.org/@types/estree/-/estree-1.0.9.tgz", + "integrity": "sha512-GhdPgy1el4/ImP05X05Uw4cw2/M93BCUmnEvWZNStlCzEKME4Fkk+YpoA5OiHNQmoS7Cafb8Xa3Pya8m1Qrzeg==", + "dev": true, + "license": "MIT" + }, + "node_modules/@types/node": { + "version": "20.19.43", + "resolved": "https://registry.npmjs.org/@types/node/-/node-20.19.43.tgz", + "integrity": "sha512-6oYBAi5ikg4Pl+kGsoYtawUMBT2zZMCvPNF7pVLnHZfd1zf38DRiWn/gT01RYCdUqkv7Fhr+C9ot4/tb+2sVvA==", + "dev": true, + "license": "MIT", + "peer": true, + "dependencies": { + "undici-types": "~6.21.0" + } + }, + "node_modules/@vitest/expect": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/expect/-/expect-2.1.9.tgz", + "integrity": "sha512-UJCIkTBenHeKT1TTlKMJWy1laZewsRIzYighyYiJKZreqtdxSos/S1t+ktRMQWu2CKqaarrkeszJx1cgC5tGZw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/spy": "2.1.9", + "@vitest/utils": "2.1.9", + "chai": "^5.1.2", + "tinyrainbow": "^1.2.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/mocker": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-2.1.9.tgz", + "integrity": "sha512-tVL6uJgoUdi6icpxmdrn5YNo3g3Dxv+IHJBr0GXHaEdTcw3F+cPKnsXFhli6nO+f/6SDKPHEK1UN+k+TQv0Ehg==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/spy": "2.1.9", + "estree-walker": "^3.0.3", + "magic-string": "^0.30.12" + }, + "funding": { + "url": "https://opencollective.com/vitest" + }, + "peerDependencies": { + "msw": "^2.4.9", + "vite": "^5.0.0" + }, + "peerDependenciesMeta": { + "msw": { + "optional": true + }, + "vite": { + "optional": true + } + } + }, + "node_modules/@vitest/pretty-format": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/pretty-format/-/pretty-format-2.1.9.tgz", + "integrity": "sha512-KhRIdGV2U9HOUzxfiHmY8IFHTdqtOhIzCpd8WRdJiE7D/HUcZVD0EgQCVjm+Q9gkUXWgBvMmTtZgIG48wq7sOQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "tinyrainbow": "^1.2.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/runner": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/runner/-/runner-2.1.9.tgz", + "integrity": "sha512-ZXSSqTFIrzduD63btIfEyOmNcBmQvgOVsPNPe0jYtESiXkhd8u2erDLnMxmGrDCwHCCHE7hxwRDCT3pt0esT4g==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/utils": "2.1.9", + "pathe": "^1.1.2" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/snapshot": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/snapshot/-/snapshot-2.1.9.tgz", + "integrity": "sha512-oBO82rEjsxLNJincVhLhaxxZdEtV0EFHMK5Kmx5sJ6H9L183dHECjiefOAdnqpIgT5eZwT04PoggUnW88vOBNQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/pretty-format": "2.1.9", + "magic-string": "^0.30.12", + "pathe": "^1.1.2" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/spy": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-2.1.9.tgz", + "integrity": "sha512-E1B35FwzXXTs9FHNK6bDszs7mtydNi5MIfUWpceJ8Xbfb1gBMscAnwLbEu+B44ed6W3XjL9/ehLPHR1fkf1KLQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "tinyspy": "^3.0.2" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/utils": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/utils/-/utils-2.1.9.tgz", + "integrity": "sha512-v0psaMSkNJ3A2NMrUEHFRzJtDPFn+/VWZ5WxImB21T9fjucJRmS7xCS3ppEnARb9y11OAzaD+P2Ps+b+BGX5iQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/pretty-format": "2.1.9", + "loupe": "^3.1.2", + "tinyrainbow": "^1.2.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/assertion-error": { + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/assertion-error/-/assertion-error-2.0.1.tgz", + "integrity": "sha512-Izi8RQcffqCeNVgFigKli1ssklIbpHnCYc6AknXGYoB6grJqyeby7jv12JUQgmTAnIDnbck1uxksT4dzN3PWBA==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=12" + } + }, + "node_modules/cac": { + "version": "6.7.14", + "resolved": "https://registry.npmjs.org/cac/-/cac-6.7.14.tgz", + "integrity": "sha512-b6Ilus+c3RrdDk+JhLKUAQfzzgLEPy6wcXqS7f/xe1EETvsDP6GORG7SFuOs6cID5YkqchW/LXZbX5bc8j7ZcQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=8" + } + }, + "node_modules/chai": { + "version": "5.3.3", + "resolved": "https://registry.npmjs.org/chai/-/chai-5.3.3.tgz", + "integrity": "sha512-4zNhdJD/iOjSH0A05ea+Ke6MU5mmpQcbQsSOkgdaUMJ9zTlDTD/GYlwohmIE2u0gaxHYiVHEn1Fw9mZ/ktJWgw==", + "dev": true, + "license": "MIT", + "dependencies": { + "assertion-error": "^2.0.1", + "check-error": "^2.1.1", + "deep-eql": "^5.0.1", + "loupe": "^3.1.0", + "pathval": "^2.0.0" + }, + "engines": { + "node": ">=18" + } + }, + "node_modules/check-error": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/check-error/-/check-error-2.1.3.tgz", + "integrity": "sha512-PAJdDJusoxnwm1VwW07VWwUN1sl7smmC3OKggvndJFadxxDRyFJBX/ggnu/KE4kQAB7a3Dp8f/YXC1FlUprWmA==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">= 16" + } + }, + "node_modules/debug": { + "version": "4.4.3", + "resolved": "https://registry.npmjs.org/debug/-/debug-4.4.3.tgz", + "integrity": "sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==", + "dev": true, + "license": "MIT", + "dependencies": { + "ms": "^2.1.3" + }, + "engines": { + "node": ">=6.0" + }, + "peerDependenciesMeta": { + "supports-color": { + "optional": true + } + } + }, + "node_modules/deep-eql": { + "version": "5.0.2", + "resolved": "https://registry.npmjs.org/deep-eql/-/deep-eql-5.0.2.tgz", + "integrity": "sha512-h5k/5U50IJJFpzfL6nO9jaaumfjO/f2NjK/oYB2Djzm4p9L+3T9qWpZqZ2hAbLPuuYq9wrU08WQyBTL5GbPk5Q==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=6" + } + }, + "node_modules/es-module-lexer": { + "version": "1.7.0", + "resolved": "https://registry.npmjs.org/es-module-lexer/-/es-module-lexer-1.7.0.tgz", + "integrity": "sha512-jEQoCwk8hyb2AZziIOLhDqpm5+2ww5uIE6lkO/6jcOCusfk6LhMHpXXfBLXTZ7Ydyt0j4VoUQv6uGNYbdW+kBA==", + "dev": true, + "license": "MIT" + }, + "node_modules/esbuild": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.21.5.tgz", + "integrity": "sha512-mg3OPMV4hXywwpoDxu3Qda5xCKQi+vCTZq8S9J/EpkhB2HzKXq4SNFZE3+NK93JYxc8VMSep+lOUSC/RVKaBqw==", + "dev": true, + "hasInstallScript": true, + "license": "MIT", + "bin": { + "esbuild": "bin/esbuild" + }, + "engines": { + "node": ">=12" + }, + "optionalDependencies": { + "@esbuild/aix-ppc64": "0.21.5", + "@esbuild/android-arm": "0.21.5", + "@esbuild/android-arm64": "0.21.5", + "@esbuild/android-x64": "0.21.5", + "@esbuild/darwin-arm64": "0.21.5", + "@esbuild/darwin-x64": "0.21.5", + "@esbuild/freebsd-arm64": "0.21.5", + "@esbuild/freebsd-x64": "0.21.5", + "@esbuild/linux-arm": "0.21.5", + "@esbuild/linux-arm64": "0.21.5", + "@esbuild/linux-ia32": "0.21.5", + "@esbuild/linux-loong64": "0.21.5", + "@esbuild/linux-mips64el": "0.21.5", + "@esbuild/linux-ppc64": "0.21.5", + "@esbuild/linux-riscv64": "0.21.5", + "@esbuild/linux-s390x": "0.21.5", + "@esbuild/linux-x64": "0.21.5", + "@esbuild/netbsd-x64": "0.21.5", + "@esbuild/openbsd-x64": "0.21.5", + "@esbuild/sunos-x64": "0.21.5", + "@esbuild/win32-arm64": "0.21.5", + "@esbuild/win32-ia32": "0.21.5", + "@esbuild/win32-x64": "0.21.5" + } + }, + "node_modules/estree-walker": { + "version": "3.0.3", + "resolved": "https://registry.npmjs.org/estree-walker/-/estree-walker-3.0.3.tgz", + "integrity": "sha512-7RUKfXgSMMkzt6ZuXmqapOurLGPPfgj6l9uRZ7lRGolvk0y2yocc35LdcxKC5PQZdn2DMqioAQ2NoWcrTKmm6g==", + "dev": true, + "license": "MIT", + "dependencies": { + "@types/estree": "^1.0.0" + } + }, + "node_modules/expect-type": { + "version": "1.4.0", + "resolved": "https://registry.npmjs.org/expect-type/-/expect-type-1.4.0.tgz", + "integrity": "sha512-KfYbmpRm0VbLjEvVa9yGwCi9GI34xvi7A/HXYWQO65CSD2u3MczUJSuwXKFIxlGsgBQizV9q5J9NHj4VG0n+pA==", + "dev": true, + "license": "Apache-2.0", + "engines": { + "node": ">=12.0.0" + } + }, + "node_modules/fsevents": { + "version": "2.3.3", + "resolved": "https://registry.npmjs.org/fsevents/-/fsevents-2.3.3.tgz", + "integrity": "sha512-5xoDfX+fL7faATnagmWPpbFtwh/R77WmMMqqHGS65C3vvB0YHrgF+B1YmZ3441tMj5n63k0212XNoJwzlhffQw==", + "dev": true, + "hasInstallScript": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^8.16.0 || ^10.6.0 || >=11.0.0" + } + }, + "node_modules/loupe": { + "version": "3.2.1", + "resolved": "https://registry.npmjs.org/loupe/-/loupe-3.2.1.tgz", + "integrity": "sha512-CdzqowRJCeLU72bHvWqwRBBlLcMEtIvGrlvef74kMnV2AolS9Y8xUv1I0U/MNAWMhBlKIoyuEgoJ0t/bbwHbLQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/magic-string": { + "version": "0.30.21", + "resolved": "https://registry.npmjs.org/magic-string/-/magic-string-0.30.21.tgz", + "integrity": "sha512-vd2F4YUyEXKGcLHoq+TEyCjxueSeHnFxyyjNp80yg0XV4vUhnDer/lvvlqM/arB5bXQN5K2/3oinyCRyx8T2CQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@jridgewell/sourcemap-codec": "^1.5.5" + } + }, + "node_modules/ms": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz", + "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==", + "dev": true, + "license": "MIT" + }, + "node_modules/nanoid": { + "version": "3.3.18", + "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.18.tgz", + "integrity": "sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==", + "dev": true, + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/ai" + } + ], + "license": "MIT", + "bin": { + "nanoid": "bin/nanoid.cjs" + }, + "engines": { + "node": "^10 || ^12 || ^13.7 || ^14 || >=15.0.1" + } + }, + "node_modules/pathe": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/pathe/-/pathe-1.1.2.tgz", + "integrity": "sha512-whLdWMYL2TwI08hn8/ZqAbrVemu0LNaNNJZX73O6qaIdCTfXutsLhMkjdENX0qhsQ9uIimo4/aQOmXkoon2nDQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/pathval": { + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/pathval/-/pathval-2.0.1.tgz", + "integrity": "sha512-//nshmD55c46FuFw26xV/xFAaB5HF9Xdap7HJBBnrKdAd6/GxDBaNA1870O79+9ueg61cZLSVc+OaFlfmObYVQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">= 14.16" + } + }, + "node_modules/picocolors": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/picocolors/-/picocolors-1.1.1.tgz", + "integrity": "sha512-xceH2snhtb5M9liqDsmEw56le376mTZkEX/jEb/RxNFyegNul7eNslCXP9FDj/Lcu0X8KEyMceP2ntpaHrDEVA==", + "dev": true, + "license": "ISC" + }, + "node_modules/postcss": { + "version": "8.5.26", + "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.26.tgz", + "integrity": "sha512-u82N74LFzG8ca+dD8puPnplTXoGH4fTPpVGuIbt36G3qvNlkvfD0lEAZSxaly3KX8TS/L1A1gsCEmvKmBcVbkQ==", + "dev": true, + "funding": [ + { + "type": "opencollective", + "url": "https://opencollective.com/postcss/" + }, + { + "type": "tidelift", + "url": "https://tidelift.com/funding/github/npm/postcss" + }, + { + "type": "github", + "url": "https://github.com/sponsors/ai" + } + ], + "license": "MIT", + "dependencies": { + "nanoid": "^3.3.17", + "picocolors": "^1.1.1", + "source-map-js": "^1.2.1" + }, + "engines": { + "node": "^10 || ^12 || >=14" + } + }, + "node_modules/rollup": { + "version": "4.62.5", + "resolved": "https://registry.npmjs.org/rollup/-/rollup-4.62.5.tgz", + "integrity": "sha512-/tqMfgP7GPA3PHhCmuiS4vIjrSVhHLgY++i+dhbG462euyAj7FpM4D9uq1X3BgjlqRdpcOrYhcQtfiQLNc8tqw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@types/estree": "1.0.9" + }, + "bin": { + "rollup": "dist/bin/rollup" + }, + "engines": { + "node": ">=18.0.0", + "npm": ">=8.0.0" + }, + "optionalDependencies": { + "@napi-rs/lzma-linux-x64-gnu": "1.5.1", + "@rollup/rollup-android-arm-eabi": "4.62.5", + "@rollup/rollup-android-arm64": "4.62.5", + "@rollup/rollup-darwin-arm64": "4.62.5", + "@rollup/rollup-darwin-x64": "4.62.5", + "@rollup/rollup-freebsd-arm64": "4.62.5", + "@rollup/rollup-freebsd-x64": "4.62.5", + "@rollup/rollup-linux-arm-gnueabihf": "4.62.5", + "@rollup/rollup-linux-arm-musleabihf": "4.62.5", + "@rollup/rollup-linux-arm64-gnu": "4.62.5", + "@rollup/rollup-linux-arm64-musl": "4.62.5", + "@rollup/rollup-linux-loong64-gnu": "4.62.5", + "@rollup/rollup-linux-loong64-musl": "4.62.5", + "@rollup/rollup-linux-ppc64-gnu": "4.62.5", + "@rollup/rollup-linux-ppc64-musl": "4.62.5", + "@rollup/rollup-linux-riscv64-gnu": "4.62.5", + "@rollup/rollup-linux-riscv64-musl": "4.62.5", + "@rollup/rollup-linux-s390x-gnu": "4.62.5", + "@rollup/rollup-linux-x64-gnu": "4.62.5", + "@rollup/rollup-linux-x64-musl": "4.62.5", + "@rollup/rollup-openbsd-x64": "4.62.5", + "@rollup/rollup-openharmony-arm64": "4.62.5", + "@rollup/rollup-win32-arm64-msvc": "4.62.5", + "@rollup/rollup-win32-ia32-msvc": "4.62.5", + "@rollup/rollup-win32-x64-gnu": "4.62.5", + "@rollup/rollup-win32-x64-msvc": "4.62.5", + "fsevents": "~2.3.2" + } + }, + "node_modules/siginfo": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/siginfo/-/siginfo-2.0.0.tgz", + "integrity": "sha512-ybx0WO1/8bSBLEWXZvEd7gMW3Sn3JFlW3TvX1nREbDLRNQNaeNN8WK0meBwPdAaOI7TtRRRJn/Es1zhrrCHu7g==", + "dev": true, + "license": "ISC" + }, + "node_modules/source-map-js": { + "version": "1.2.1", + "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz", + "integrity": "sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==", + "dev": true, + "license": "BSD-3-Clause", + "engines": { + "node": ">=0.10.0" + } + }, + "node_modules/stackback": { + "version": "0.0.2", + "resolved": "https://registry.npmjs.org/stackback/-/stackback-0.0.2.tgz", + "integrity": "sha512-1XMJE5fQo1jGH6Y/7ebnwPOBEkIEnT4QF32d5R1+VXdXveM0IBMJt8zfaxX1P3QhVwrYe+576+jkANtSS2mBbw==", + "dev": true, + "license": "MIT" + }, + "node_modules/std-env": { + "version": "3.10.0", + "resolved": "https://registry.npmjs.org/std-env/-/std-env-3.10.0.tgz", + "integrity": "sha512-5GS12FdOZNliM5mAOxFRg7Ir0pWz8MdpYm6AY6VPkGpbA7ZzmbzNcBJQ0GPvvyWgcY7QAhCgf9Uy89I03faLkg==", + "dev": true, + "license": "MIT" + }, + "node_modules/tinybench": { + "version": "2.9.0", + "resolved": "https://registry.npmjs.org/tinybench/-/tinybench-2.9.0.tgz", + "integrity": "sha512-0+DUvqWMValLmha6lr4kD8iAMK1HzV0/aKnCtWb9v9641TnP/MFb7Pc2bxoxQjTXAErryXVgUOfv2YqNllqGeg==", + "dev": true, + "license": "MIT" + }, + "node_modules/tinyexec": { + "version": "0.3.2", + "resolved": "https://registry.npmjs.org/tinyexec/-/tinyexec-0.3.2.tgz", + "integrity": "sha512-KQQR9yN7R5+OSwaK0XQoj22pwHoTlgYqmUscPYoknOoWCWfj/5/ABTMRi69FrKU5ffPVh5QcFikpWJI/P1ocHA==", + "dev": true, + "license": "MIT" + }, + "node_modules/tinypool": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/tinypool/-/tinypool-1.1.1.tgz", + "integrity": "sha512-Zba82s87IFq9A9XmjiX5uZA/ARWDrB03OHlq+Vw1fSdt0I+4/Kutwy8BP4Y/y/aORMo61FQ0vIb5j44vSo5Pkg==", + "dev": true, + "license": "MIT", + "engines": { + "node": "^18.0.0 || >=20.0.0" + } + }, + "node_modules/tinyrainbow": { + "version": "1.2.0", + "resolved": "https://registry.npmjs.org/tinyrainbow/-/tinyrainbow-1.2.0.tgz", + "integrity": "sha512-weEDEq7Z5eTHPDh4xjX789+fHfF+P8boiFB+0vbWzpbnbsEr/GRaohi/uMKxg8RZMXnl1ItAi/IUHWMsjDV7kQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, + "node_modules/tinyspy": { + "version": "3.0.2", + "resolved": "https://registry.npmjs.org/tinyspy/-/tinyspy-3.0.2.tgz", + "integrity": "sha512-n1cw8k1k0x4pgA2+9XrOkFydTerNcJ1zWCO5Nn9scWHTD+5tp8dghT2x1uduQePZTZgd3Tupf+x9BxJjeJi77Q==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, + "node_modules/tweetnacl": { + "version": "1.0.3", + "resolved": "https://registry.npmjs.org/tweetnacl/-/tweetnacl-1.0.3.tgz", + "integrity": "sha512-6rt+RN7aOi1nGMyC4Xa5DdYiukl2UWCbcJft7YhxReBGQD7OAM8Pbxw6YMo4r2diNEA8FEmu32YOn9rhaiE5yw==", + "license": "Unlicense" + }, + "node_modules/typescript": { + "version": "5.9.3", + "resolved": "https://registry.npmjs.org/typescript/-/typescript-5.9.3.tgz", + "integrity": "sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==", + "dev": true, + "license": "Apache-2.0", + "bin": { + "tsc": "bin/tsc", + "tsserver": "bin/tsserver" + }, + "engines": { + "node": ">=14.17" + } + }, + "node_modules/undici-types": { + "version": "6.21.0", + "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-6.21.0.tgz", + "integrity": "sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/vite": { + "version": "5.4.21", + "resolved": "https://registry.npmjs.org/vite/-/vite-5.4.21.tgz", + "integrity": "sha512-o5a9xKjbtuhY6Bi5S3+HvbRERmouabWbyUcpXXUA1u+GNUKoROi9byOJ8M0nHbHYHkYICiMlqxkg1KkYmm25Sw==", + "dev": true, + "license": "MIT", + "dependencies": { + "esbuild": "^0.21.3", + "postcss": "^8.4.43", + "rollup": "^4.20.0" + }, + "bin": { + "vite": "bin/vite.js" + }, + "engines": { + "node": "^18.0.0 || >=20.0.0" + }, + "funding": { + "url": "https://github.com/vitejs/vite?sponsor=1" + }, + "optionalDependencies": { + "fsevents": "~2.3.3" + }, + "peerDependencies": { + "@types/node": "^18.0.0 || >=20.0.0", + "less": "*", + "lightningcss": "^1.21.0", + "sass": "*", + "sass-embedded": "*", + "stylus": "*", + "sugarss": "*", + "terser": "^5.4.0" + }, + "peerDependenciesMeta": { + "@types/node": { + "optional": true + }, + "less": { + "optional": true + }, + "lightningcss": { + "optional": true + }, + "sass": { + "optional": true + }, + "sass-embedded": { + "optional": true + }, + "stylus": { + "optional": true + }, + "sugarss": { + "optional": true + }, + "terser": { + "optional": true + } + } + }, + "node_modules/vite-node": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/vite-node/-/vite-node-2.1.9.tgz", + "integrity": "sha512-AM9aQ/IPrW/6ENLQg3AGY4K1N2TGZdR5e4gu/MmmR2xR3Ll1+dib+nook92g4TV3PXVyeyxdWwtaCAiUL0hMxA==", + "dev": true, + "license": "MIT", + "dependencies": { + "cac": "^6.7.14", + "debug": "^4.3.7", + "es-module-lexer": "^1.5.4", + "pathe": "^1.1.2", + "vite": "^5.0.0" + }, + "bin": { + "vite-node": "vite-node.mjs" + }, + "engines": { + "node": "^18.0.0 || >=20.0.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/vitest": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/vitest/-/vitest-2.1.9.tgz", + "integrity": "sha512-MSmPM9REYqDGBI8439mA4mWhV5sKmDlBKWIYbA3lRb2PTHACE0mgKwA8yQ2xq9vxDTuk4iPrECBAEW2aoFXY0Q==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/expect": "2.1.9", + "@vitest/mocker": "2.1.9", + "@vitest/pretty-format": "^2.1.9", + "@vitest/runner": "2.1.9", + "@vitest/snapshot": "2.1.9", + "@vitest/spy": "2.1.9", + "@vitest/utils": "2.1.9", + "chai": "^5.1.2", + "debug": "^4.3.7", + "expect-type": "^1.1.0", + "magic-string": "^0.30.12", + "pathe": "^1.1.2", + "std-env": "^3.8.0", + "tinybench": "^2.9.0", + "tinyexec": "^0.3.1", + "tinypool": "^1.0.1", + "tinyrainbow": "^1.2.0", + "vite": "^5.0.0", + "vite-node": "2.1.9", + "why-is-node-running": "^2.3.0" + }, + "bin": { + "vitest": "vitest.mjs" + }, + "engines": { + "node": "^18.0.0 || >=20.0.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + }, + "peerDependencies": { + "@edge-runtime/vm": "*", + "@types/node": "^18.0.0 || >=20.0.0", + "@vitest/browser": "2.1.9", + "@vitest/ui": "2.1.9", + "happy-dom": "*", + "jsdom": "*" + }, + "peerDependenciesMeta": { + "@edge-runtime/vm": { + "optional": true + }, + "@types/node": { + "optional": true + }, + "@vitest/browser": { + "optional": true + }, + "@vitest/ui": { + "optional": true + }, + "happy-dom": { + "optional": true + }, + "jsdom": { + "optional": true + } + } + }, + "node_modules/why-is-node-running": { + "version": "2.3.0", + "resolved": "https://registry.npmjs.org/why-is-node-running/-/why-is-node-running-2.3.0.tgz", + "integrity": "sha512-hUrmaWBdVDcxvYqnyh09zunKzROWjbZTiNy8dBEjkS7ehEDQibXJ7XvlmtbwuTclUiIyN+CyXQD4Vmko8fNm8w==", + "dev": true, + "license": "MIT", + "dependencies": { + "siginfo": "^2.0.0", + "stackback": "0.0.2" + }, + "bin": { + "why-is-node-running": "cli.js" + }, + "engines": { + "node": ">=8" + } + } + } +} diff --git a/examples/sep10-auth/package.json b/examples/sep10-auth/package.json new file mode 100644 index 0000000..1bde538 --- /dev/null +++ b/examples/sep10-auth/package.json @@ -0,0 +1,19 @@ +{ + "name": "@swaptrade/sep10-auth-example", + "version": "1.0.0", + "private": true, + "description": "SEP-10 challenge/response reference implementation for SwapTrade (issue #260)", + "type": "module", + "scripts": { + "test": "vitest run", + "typecheck": "tsc --noEmit" + }, + "dependencies": { + "tweetnacl": "^1.0.3" + }, + "devDependencies": { + "@types/node": "^20.14.0", + "typescript": "^5.5.4", + "vitest": "^2.1.9" + } +} diff --git a/examples/sep10-auth/src/gating.ts b/examples/sep10-auth/src/gating.ts new file mode 100644 index 0000000..fc09f3a --- /dev/null +++ b/examples/sep10-auth/src/gating.ts @@ -0,0 +1,131 @@ +/** + * Gating Soroban contract invocations behind SEP-10 authentication. + * + * Two patterns are demonstrated: + * + * 1. **Session gate** — the DApp backend only relays contract calls for + * requests carrying a valid SEP-10 session token. The user's Stellar + * account is passed through as the `source_account` / signer of the + * Soroban authorization entry, so on-chain authorization remains + * anchored to the authenticated identity. + * + * 2. **Relayer with signed intents** — for fee-sponsored flows the client + * signs an *intent* payload (contract id + function + args + nonce) + * with their Stellar ed25519 key. The relayer verifies the signature, + * enforces single-use nonces (replay protection) and submits the + * invocation on behalf of the user. + */ +import nacl from "tweetnacl"; +import { + ReplayGuard, + SessionToken, + Challenge, + decodeStrKey, + issueSessionToken, + verifyChallenge, + verifySessionToken, +} from "./sep10.js"; + +export interface ContractIntent { + contractId: string; + functionName: string; + args: unknown[]; + nonce: number; +} + +export interface GateResult { + allowed: boolean; + reason?: string; + account?: string; +} + +export class Sep10Gate { + private readonly nonces = new ReplayGuard(); + private readonly usedIntents = new ReplayGuard(); + + constructor( + private readonly serverPublicKeyRaw: Uint8Array, + private readonly serverSecretHex: string, + private readonly nowSeconds: () => number = () => Math.floor(Date.now() / 1000), + ) {} + + /** Step 1 of the flow: verify a completed challenge and mint a session token. */ + completeChallenge( + challenge: Challenge, + serverSignatureB64: string, + clientSignatureB64: string, + ttlSeconds = 3600, + ): GateResult & { token?: SessionToken } { + if ( + !verifyChallenge( + challenge, + serverSignatureB64, + clientSignatureB64, + this.serverPublicKeyRaw, + this.nowSeconds(), + ) + ) { + return { allowed: false, reason: "challenge verification failed" }; + } + const replayKey = `challenge:${challenge.nonceB64}`; + if (!this.nonces.consume(replayKey)) { + return { allowed: false, reason: "challenge replay detected" }; + } + const token = issueSessionToken(challenge.clientAccount, this.serverSecretHex, ttlSeconds, this.nowSeconds()); + return { allowed: true, account: challenge.clientAccount, token }; + } + + /** Step 2a: gate any contract-invoking operation on a session token. */ + authorizeWithToken(token: SessionToken, intent: ContractIntent): GateResult { + if (!verifySessionToken(token, this.serverSecretHex, this.nowSeconds())) { + return { allowed: false, reason: "invalid or expired session token" }; + } + return this.checkIntentReplay(token.account, intent); + } + + /** + * Step 2b: fee-sponsored flow — the client signs the canonical intent + * payload with their Stellar secret key; the relayer validates it against + * the claimed account before submitting. + */ + authorizeSignedIntent(accountId: string, intent: ContractIntent, signatureB64: string): GateResult { + let clientKey: Buffer; + try { + clientKey = decodeStrKey(accountId); + } catch { + return { allowed: false, reason: "malformed client account" }; + } + const message = Buffer.from(intentPayload(intent), "utf8"); + let ok = false; + try { + ok = nacl.sign.detached.verify(message, Buffer.from(signatureB64, "base64"), clientKey); + } catch { + ok = false; + } + if (!ok) { + return { allowed: false, reason: "intent signature invalid" }; + } + return this.checkIntentReplay(accountId, intent); + } + + private checkIntentReplay(account: string, intent: ContractIntent): GateResult { + const key = + `intent:${account}:${intent.contractId}:${intent.functionName}:` + + `${JSON.stringify(intent.args)}:${intent.nonce}`; + if (!this.usedIntents.consume(key)) { + return { allowed: false, reason: "intent replay detected" }; + } + return { allowed: true, account }; + } +} + +/** Canonical bytes a client signs for a fee-sponsored invocation. */ +export function intentPayload(intent: ContractIntent): string { + return [ + "swaptrade-intent-v1", + intent.contractId, + intent.functionName, + JSON.stringify(intent.args), + String(intent.nonce), + ].join("\n"); +} diff --git a/examples/sep10-auth/src/sep10.ts b/examples/sep10-auth/src/sep10.ts new file mode 100644 index 0000000..32d3b59 --- /dev/null +++ b/examples/sep10-auth/src/sep10.ts @@ -0,0 +1,231 @@ +/** + * SEP-10 challenge/response primitives for SwapTrade. + * + * Implements the core of SEP-10 (stellar-protocol/ecosystem/sep-0010.md) + * without requiring network access: + * - server builds a challenge containing a random 64-byte nonce in a + * `manage_data` style payload signed with the server key, + * - client countersigns the exact same payload, + * - verification checks both signatures, the time bounds and that the + * nonce has not been consumed (replay protection). + * + * Ed25519 is Stellar's signature scheme; tweetnacl provides it. + */ +import nacl from "tweetnacl"; +import { createHmac, randomBytes, timingSafeEqual } from "node:crypto"; + +export const CHALLENGE_TIMEOUT_SECONDS = 15 * 60; +export const SERVER_DATA_KEY = "swaptrade auth"; +export const CLIENT_DOMAIN_KEY = "swaptrade client_domain"; + +/** Stellar strkey: version byte (6<<3), then 32-byte key, CRC16-xmodem checksum. */ +const STRKEY_VERSION_ED25519 = (6 << 3) | 0; // 0x30 + +const BASE32_ALPHABET = "ABCDEFGHIJKLMNOPQRSTUVWXYZ234567"; + +function base32Encode(buf: Buffer): string { + let bits = 0; + let value = 0; + let out = ""; + for (const byte of buf) { + value = (value << 8) | byte; + bits += 8; + while (bits >= 5) { + out += BASE32_ALPHABET[(value >>> (bits - 5)) & 31]; + bits -= 5; + } + } + if (bits > 0) out += BASE32_ALPHABET[(value << (5 - bits)) & 31]; + return out; +} + +function base32Decode(s: string): Buffer { + let bits = 0; + let value = 0; + const bytes: number[] = []; + for (const c of s.toUpperCase()) { + const idx = BASE32_ALPHABET.indexOf(c); + if (idx === -1) throw new Error(`invalid base32 character ${c}`); + value = (value << 5) | idx; + bits += 5; + if (bits >= 8) { + bytes.push((value >>> (bits - 8)) & 0xff); + bits -= 8; + } + } + return Buffer.from(bytes); +} + +function crc16Xmodem(buf: Buffer): number { + let crc = 0; + for (const b of buf) { + crc ^= b << 8; + for (let i = 0; i < 8; i++) { + crc = crc & 0x8000 ? ((crc << 1) ^ 0x1021) & 0xffff : (crc << 1) & 0xffff; + } + } + return crc; +} + +/** Encode a raw 32-byte ed25519 public key as a Stellar `G...` strkey. */ +export function encodeStrKey(rawPublicKey: Uint8Array): string { + if (rawPublicKey.length !== 32) throw new Error("ed25519 public key must be 32 bytes"); + const payload = Buffer.concat([ + Buffer.from([STRKEY_VERSION_ED25519]), + Buffer.from(rawPublicKey), + ]); + const checksum = Buffer.alloc(2); + checksum.writeUInt16LE(crc16Xmodem(payload), 0); + return base32Encode(Buffer.concat([payload, checksum])); +} + +/** Decode a `G...` strkey back to the raw 32-byte key (checksum verified). */ +export function decodeStrKey(strKey: string): Buffer { + const decoded = base32Decode(strKey); + const payload = decoded.subarray(0, decoded.length - 2); + const checksum = decoded.readUInt16LE(decoded.length - 2); + if (crc16Xmodem(payload) !== checksum) throw new Error("invalid strkey checksum"); + if (payload[0] !== STRKEY_VERSION_ED25519) throw new Error("not an ed25519 strkey"); + return payload.subarray(1); +} + +export interface Challenge { + serverAccount: string; + clientAccount: string; + nonceB64: string; + issuedAt: number; // unix seconds + expiresAt: number; // unix seconds + clientDomain?: string; +} + +/** + * Server-side: build a SEP-10 challenge. In full SEP-10 this is encoded as + * a Stellar transaction with `manage_data` operations carrying + * `SERVER_DATA_KEY` -> nonce and `CLIENT_DOMAIN_KEY` -> client home domain. + * Here the equivalent canonical payload is produced so the same signing and + * verification rules apply. + */ +export function createChallenge( + serverSecretSeedHex: string, + clientAccount: string, + nowSeconds: number, + clientDomain?: string, +): { challenge: Challenge; signedPayload: string } { + decodeStrKey(clientAccount); // validates shape early + const nonceB64 = randomBytes(64).toString("base64"); + const expiresAt = nowSeconds + CHALLENGE_TIMEOUT_SECONDS; + const challenge: Challenge = { + serverAccount: encodeStrKey(nacl.sign.keyPair.fromSeed(Buffer.from(serverSecretSeedHex, "hex")).publicKey), + clientAccount, + nonceB64, + issuedAt: nowSeconds, + expiresAt, + clientDomain, + }; + return { challenge, signedPayload: canonicalPayload(challenge) }; +} + +/** Deterministic byte payload both parties sign (SEP-10 transaction hash analogue). */ +export function canonicalPayload(ch: Challenge): string { + return [ + SERVER_DATA_KEY, + ch.serverAccount, + ch.clientAccount, + ch.nonceB64, + String(ch.issuedAt), + String(ch.expiresAt), + ch.clientDomain ? `${CLIENT_DOMAIN_KEY}:${ch.clientDomain}` : "", + ].join("\n"); +} + +/** + * Verification rules (mirrors SEP-10 `verify_challenge_tx_hash`): + * 1. exactly two signatures expected: server then client + * 2. server signature must match the advertised server account + * 3. client signature must match `challenge.clientAccount` + * 4. challenge must still be within its validity window + */ +export function verifyChallenge( + challenge: Challenge, + serverSignatureB64: string, + clientSignatureB64: string, + serverPublicKeyRaw: Uint8Array, + nowSeconds: number, +): boolean { + if (nowSeconds < challenge.issuedAt || nowSeconds >= challenge.expiresAt) return false; + + const message = Buffer.from(canonicalPayload(challenge), "utf8"); + const serverSig = Buffer.from(serverSignatureB64, "base64"); + const clientSig = Buffer.from(clientSignatureB64, "base64"); + + const serverOk = nacl.sign.detached.verify(message, serverSig, serverPublicKeyRaw); + if (!serverOk) return false; + + let clientKey: Buffer; + try { + clientKey = decodeStrKey(challenge.clientAccount); + } catch { + return false; + } + return nacl.sign.detached.verify(message, clientSig, clientKey); +} + +export function signBytes(payload: string, secretSeedOrKeyHex: string): string { + const keyPair = + secretSeedOrKeyHex.length === 64 + ? nacl.sign.keyPair.fromSeed(Buffer.from(secretSeedOrKeyHex, "hex")) + : nacl.sign.keyPair.fromSecretKey(Buffer.from(secretSeedOrKeyHex, "hex")); + const sig = nacl.sign.detached(Buffer.from(payload, "utf8"), keyPair.secretKey); + return Buffer.from(sig).toString("base64"); +} + +// --------------------------------------------------------------------------- +// Session tokens (the JWT analogue SEP-10 servers hand out after a successful +// challenge). HMAC-SHA256 with explicit expiry keeps this dependency-free. +// --------------------------------------------------------------------------- + +export interface SessionToken { + account: string; + issuedAt: number; + expiresAt: number; + sig: string; +} + +export function issueSessionToken( + account: string, + serverSecretHex: string, + ttlSeconds: number, + nowSeconds: number, +): SessionToken { + const body = JSON.stringify({ account, issuedAt: nowSeconds, expiresAt: nowSeconds + ttlSeconds }); + const sig = createHmac("sha256", Buffer.from(serverSecretHex, "hex")).update(body).digest("base64"); + return { ...JSON.parse(body), sig }; +} + +export function verifySessionToken(token: SessionToken, serverSecretHex: string, nowSeconds: number): boolean { + const { account, issuedAt, expiresAt, sig } = token; + if (nowSeconds < issuedAt || nowSeconds >= expiresAt) return false; + const body = JSON.stringify({ account, issuedAt, expiresAt }); + const expected = createHmac("sha256", Buffer.from(serverSecretHex, "hex")).update(body).digest(); + const given = Buffer.from(sig, "base64"); + return expected.length === given.length && timingSafeEqual(expected, given); +} + +// --------------------------------------------------------------------------- +// Replay protection: consumed nonces and raw signed payloads. +// --------------------------------------------------------------------------- + +export class ReplayGuard { + private readonly seen = new Set(); + + /** Returns true on first sight of `key`, false afterwards. */ + consume(key: string): boolean { + if (this.seen.has(key)) return false; + this.seen.add(key); + return true; + } + + get size(): number { + return this.seen.size; + } +} diff --git a/examples/sep10-auth/tsconfig.json b/examples/sep10-auth/tsconfig.json new file mode 100644 index 0000000..92263fa --- /dev/null +++ b/examples/sep10-auth/tsconfig.json @@ -0,0 +1,14 @@ +{ + "compilerOptions": { + "target": "ES2022", + "module": "NodeNext", + "moduleResolution": "NodeNext", + "strict": true, + "noUncheckedIndexedAccess": false, + "esModuleInterop": true, + "skipLibCheck": true, + "types": ["node"], + "noEmit": true + }, + "include": ["src/**/*.ts", "__tests__/**/*.ts"] +}