UNPKG

552 kBJavaScriptView Raw
1(function (global, factory) {
2 typeof exports === 'object' && typeof module !== 'undefined' ? factory(exports, require('@polkadot/util')) :
3 typeof define === 'function' && define.amd ? define(['exports', '@polkadot/util'], factory) :
4 (global = typeof globalThis !== 'undefined' ? globalThis : global || self, factory(global.polkadotUtilCrypto = {}, global.polkadotUtil));
5})(this, (function (exports, util) { 'use strict';
6
7 const global = typeof globalThis !== "undefined" ? globalThis : typeof self !== "undefined" ? self : window;
8
9 const packageInfo$2 = { name: '@polkadot/x-global', path: (({ url: (typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href)) }) && (typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href))) ? new URL((typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href))).pathname.substring(0, new URL((typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href))).pathname.lastIndexOf('/') + 1) : 'auto', type: 'esm', version: '12.2.2' };
10
11 function evaluateThis(fn) {
12 return fn('return this');
13 }
14 const xglobal = (typeof globalThis !== 'undefined'
15 ? globalThis
16 : typeof global !== 'undefined'
17 ? global
18 : typeof self !== 'undefined'
19 ? self
20 : typeof window !== 'undefined'
21 ? window
22 : evaluateThis(Function));
23 function extractGlobal(name, fallback) {
24 return typeof xglobal[name] === 'undefined'
25 ? fallback
26 : xglobal[name];
27 }
28 function exposeGlobal(name, fallback) {
29 if (typeof xglobal[name] === 'undefined') {
30 xglobal[name] = fallback;
31 }
32 }
33
34 const build = /*#__PURE__*/Object.freeze({
35 __proto__: null,
36 exposeGlobal: exposeGlobal,
37 extractGlobal: extractGlobal,
38 packageInfo: packageInfo$2,
39 xglobal: xglobal
40 });
41
42 function invalidFallback() {
43 return Number.NaN;
44 }
45 const BigInt$1 = extractGlobal('BigInt', invalidFallback);
46
47 exposeGlobal('BigInt', BigInt$1);
48
49 function getDefaultExportFromCjs (x) {
50 return x && x.__esModule && Object.prototype.hasOwnProperty.call(x, 'default') ? x['default'] : x;
51 }
52
53 function getAugmentedNamespace(n) {
54 if (n.__esModule) return n;
55 var f = n.default;
56 if (typeof f == "function") {
57 var a = function a () {
58 if (this instanceof a) {
59 var args = [null];
60 args.push.apply(args, arguments);
61 var Ctor = Function.bind.apply(f, args);
62 return new Ctor();
63 }
64 return f.apply(this, arguments);
65 };
66 a.prototype = f.prototype;
67 } else a = {};
68 Object.defineProperty(a, '__esModule', {value: true});
69 Object.keys(n).forEach(function (k) {
70 var d = Object.getOwnPropertyDescriptor(n, k);
71 Object.defineProperty(a, k, d.get ? d : {
72 enumerable: true,
73 get: function () {
74 return n[k];
75 }
76 });
77 });
78 return a;
79 }
80
81 var browser = {};
82
83 const require$$0 = /*@__PURE__*/getAugmentedNamespace(build);
84
85 var packageInfo$1 = {};
86
87 Object.defineProperty(packageInfo$1, "__esModule", { value: true });
88 packageInfo$1.packageInfo = void 0;
89 packageInfo$1.packageInfo = { name: '@polkadot/x-randomvalues', path: typeof __dirname === 'string' ? __dirname : 'auto', type: 'cjs', version: '12.2.2' };
90
91 (function (exports) {
92 Object.defineProperty(exports, "__esModule", { value: true });
93 exports.getRandomValues = exports.crypto = exports.packageInfo = void 0;
94 const x_global_1 = require$$0;
95 var packageInfo_js_1 = packageInfo$1;
96 Object.defineProperty(exports, "packageInfo", { enumerable: true, get: function () { return packageInfo_js_1.packageInfo; } });
97 exports.crypto = x_global_1.xglobal.crypto;
98 function getRandomValues(arr) {
99 return exports.crypto.getRandomValues(arr);
100 }
101 exports.getRandomValues = getRandomValues;
102 } (browser));
103 getDefaultExportFromCjs(browser);
104
105 const DEFAULT_CRYPTO = { getRandomValues: browser.getRandomValues };
106 const DEFAULT_SELF = { crypto: DEFAULT_CRYPTO };
107 class Wbg {
108 constructor(bridge) {
109 this.abort = () => {
110 throw new Error('abort');
111 };
112 this.__wbindgen_is_undefined = (idx) => {
113 return this.__internal__bridge.getObject(idx) === undefined;
114 };
115 this.__wbindgen_throw = (ptr, len) => {
116 throw new Error(this.__internal__bridge.getString(ptr, len));
117 };
118 this.__wbg_self_1b7a39e3a92c949c = () => {
119 return this.__internal__bridge.addObject(DEFAULT_SELF);
120 };
121 this.__wbg_require_604837428532a733 = (ptr, len) => {
122 throw new Error(`Unable to require ${this.__internal__bridge.getString(ptr, len)}`);
123 };
124 this.__wbg_crypto_968f1772287e2df0 = (_idx) => {
125 return this.__internal__bridge.addObject(DEFAULT_CRYPTO);
126 };
127 this.__wbg_getRandomValues_a3d34b4fee3c2869 = (_idx) => {
128 return this.__internal__bridge.addObject(DEFAULT_CRYPTO.getRandomValues);
129 };
130 this.__wbg_getRandomValues_f5e14ab7ac8e995d = (_arg0, ptr, len) => {
131 DEFAULT_CRYPTO.getRandomValues(this.__internal__bridge.getU8a(ptr, len));
132 };
133 this.__wbg_randomFillSync_d5bd2d655fdf256a = (_idx, _ptr, _len) => {
134 throw new Error('randomFillsync is not available');
135 };
136 this.__wbindgen_object_drop_ref = (idx) => {
137 this.__internal__bridge.takeObject(idx);
138 };
139 this.__internal__bridge = bridge;
140 }
141 }
142
143 class Bridge {
144 constructor(createWasm) {
145 this.__internal__createWasm = createWasm;
146 this.__internal__cachegetInt32 = null;
147 this.__internal__cachegetUint8 = null;
148 this.__internal__heap = new Array(32)
149 .fill(undefined)
150 .concat(undefined, null, true, false);
151 this.__internal__heapNext = this.__internal__heap.length;
152 this.__internal__type = 'none';
153 this.__internal__wasm = null;
154 this.__internal__wasmError = null;
155 this.__internal__wasmPromise = null;
156 this.__internal__wbg = { ...new Wbg(this) };
157 }
158 get error() {
159 return this.__internal__wasmError;
160 }
161 get type() {
162 return this.__internal__type;
163 }
164 get wasm() {
165 return this.__internal__wasm;
166 }
167 async init(createWasm) {
168 if (!this.__internal__wasmPromise || createWasm) {
169 this.__internal__wasmPromise = (createWasm || this.__internal__createWasm)(this.__internal__wbg);
170 }
171 const { error, type, wasm } = await this.__internal__wasmPromise;
172 this.__internal__type = type;
173 this.__internal__wasm = wasm;
174 this.__internal__wasmError = error;
175 return this.__internal__wasm;
176 }
177 getObject(idx) {
178 return this.__internal__heap[idx];
179 }
180 dropObject(idx) {
181 if (idx < 36) {
182 return;
183 }
184 this.__internal__heap[idx] = this.__internal__heapNext;
185 this.__internal__heapNext = idx;
186 }
187 takeObject(idx) {
188 const ret = this.getObject(idx);
189 this.dropObject(idx);
190 return ret;
191 }
192 addObject(obj) {
193 if (this.__internal__heapNext === this.__internal__heap.length) {
194 this.__internal__heap.push(this.__internal__heap.length + 1);
195 }
196 const idx = this.__internal__heapNext;
197 this.__internal__heapNext = this.__internal__heap[idx];
198 this.__internal__heap[idx] = obj;
199 return idx;
200 }
201 getInt32() {
202 if (this.__internal__cachegetInt32 === null || this.__internal__cachegetInt32.buffer !== this.__internal__wasm.memory.buffer) {
203 this.__internal__cachegetInt32 = new Int32Array(this.__internal__wasm.memory.buffer);
204 }
205 return this.__internal__cachegetInt32;
206 }
207 getUint8() {
208 if (this.__internal__cachegetUint8 === null || this.__internal__cachegetUint8.buffer !== this.__internal__wasm.memory.buffer) {
209 this.__internal__cachegetUint8 = new Uint8Array(this.__internal__wasm.memory.buffer);
210 }
211 return this.__internal__cachegetUint8;
212 }
213 getU8a(ptr, len) {
214 return this.getUint8().subarray(ptr / 1, ptr / 1 + len);
215 }
216 getString(ptr, len) {
217 return util.u8aToString(this.getU8a(ptr, len));
218 }
219 allocU8a(arg) {
220 const ptr = this.__internal__wasm.__wbindgen_malloc(arg.length * 1);
221 this.getUint8().set(arg, ptr / 1);
222 return [ptr, arg.length];
223 }
224 allocString(arg) {
225 return this.allocU8a(util.stringToU8a(arg));
226 }
227 resultU8a() {
228 const r0 = this.getInt32()[8 / 4 + 0];
229 const r1 = this.getInt32()[8 / 4 + 1];
230 const ret = this.getU8a(r0, r1).slice();
231 this.__internal__wasm.__wbindgen_free(r0, r1 * 1);
232 return ret;
233 }
234 resultString() {
235 return util.u8aToString(this.resultU8a());
236 }
237 }
238
239 function createWasmFn(root, wasmBytes, asmFn) {
240 return async (wbg) => {
241 const result = {
242 error: null,
243 type: 'none',
244 wasm: null
245 };
246 try {
247 if (!wasmBytes || !wasmBytes.length) {
248 throw new Error('No WebAssembly provided for initialization');
249 }
250 else if (typeof WebAssembly !== 'object' || typeof WebAssembly.instantiate !== 'function') {
251 throw new Error('WebAssembly is not available in your environment');
252 }
253 const source = await WebAssembly.instantiate(wasmBytes, { wbg });
254 result.wasm = source.instance.exports;
255 result.type = 'wasm';
256 }
257 catch (error) {
258 if (typeof asmFn === 'function') {
259 result.wasm = asmFn(wbg);
260 result.type = 'asm';
261 }
262 else {
263 result.error = `FATAL: Unable to initialize @polkadot/wasm-${root}:: ${error.message}`;
264 console.error(result.error);
265 }
266 }
267 return result;
268 };
269 }
270
271 const chr = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';
272 const map = new Array(256);
273 for (let i = 0, count = chr.length; i < count; i++) {
274 map[chr.charCodeAt(i)] = i;
275 }
276 function base64Decode$1(data, out) {
277 let byte = 0;
278 let bits = 0;
279 let pos = -1;
280 for (let i = 0, count = out.length; pos < count; i++) {
281 byte = (byte << 6) | map[data.charCodeAt(i)];
282 if ((bits += 6) >= 8) {
283 out[++pos] = (byte >>> (bits -= 8)) & 0xff;
284 }
285 }
286 return out;
287 }
288
289 const u8 = Uint8Array, u16 = Uint16Array, u32$1 = Uint32Array;
290 const clim = new u8([16, 17, 18, 0, 8, 7, 9, 6, 10, 5, 11, 4, 12, 3, 13, 2, 14, 1, 15]);
291 const fleb = new u8([0, 0, 0, 0, 0, 0, 0, 0, 1, 1, 1, 1, 2, 2, 2, 2, 3, 3, 3, 3, 4, 4, 4, 4, 5, 5, 5, 5, 0, 0, 0, 0]);
292 const fdeb = new u8([0, 0, 0, 0, 1, 1, 2, 2, 3, 3, 4, 4, 5, 5, 6, 6, 7, 7, 8, 8, 9, 9, 10, 10, 11, 11, 12, 12, 13, 13, 0, 0]);
293 const freb = (eb, start) => {
294 const b = new u16(31);
295 for (let i = 0; i < 31; ++i) {
296 b[i] = start += 1 << eb[i - 1];
297 }
298 const r = new u32$1(b[30]);
299 for (let i = 1; i < 30; ++i) {
300 for (let j = b[i]; j < b[i + 1]; ++j) {
301 r[j] = ((j - b[i]) << 5) | i;
302 }
303 }
304 return [b, r];
305 };
306 const [fl, revfl] = freb(fleb, 2);
307 fl[28] = 258, revfl[258] = 28;
308 const [fd] = freb(fdeb, 0);
309 const rev = new u16(32768);
310 for (let i = 0; i < 32768; ++i) {
311 let x = ((i & 0xAAAA) >>> 1) | ((i & 0x5555) << 1);
312 x = ((x & 0xCCCC) >>> 2) | ((x & 0x3333) << 2);
313 x = ((x & 0xF0F0) >>> 4) | ((x & 0x0F0F) << 4);
314 rev[i] = (((x & 0xFF00) >>> 8) | ((x & 0x00FF) << 8)) >>> 1;
315 }
316 const hMap = ((cd, mb, r) => {
317 const s = cd.length;
318 let i = 0;
319 const l = new u16(mb);
320 for (; i < s; ++i)
321 ++l[cd[i] - 1];
322 const le = new u16(mb);
323 for (i = 0; i < mb; ++i) {
324 le[i] = (le[i - 1] + l[i - 1]) << 1;
325 }
326 let co;
327 if (r) {
328 co = new u16(1 << mb);
329 const rvb = 15 - mb;
330 for (i = 0; i < s; ++i) {
331 if (cd[i]) {
332 const sv = (i << 4) | cd[i];
333 const r = mb - cd[i];
334 let v = le[cd[i] - 1]++ << r;
335 for (const m = v | ((1 << r) - 1); v <= m; ++v) {
336 co[rev[v] >>> rvb] = sv;
337 }
338 }
339 }
340 }
341 else {
342 co = new u16(s);
343 for (i = 0; i < s; ++i)
344 co[i] = rev[le[cd[i] - 1]++] >>> (15 - cd[i]);
345 }
346 return co;
347 });
348 const flt = new u8(288);
349 for (let i = 0; i < 144; ++i)
350 flt[i] = 8;
351 for (let i = 144; i < 256; ++i)
352 flt[i] = 9;
353 for (let i = 256; i < 280; ++i)
354 flt[i] = 7;
355 for (let i = 280; i < 288; ++i)
356 flt[i] = 8;
357 const fdt = new u8(32);
358 for (let i = 0; i < 32; ++i)
359 fdt[i] = 5;
360 const flrm = hMap(flt, 9, 1);
361 const fdrm = hMap(fdt, 5, 1);
362 const bits = (d, p, m) => {
363 const o = p >>> 3;
364 return ((d[o] | (d[o + 1] << 8)) >>> (p & 7)) & m;
365 };
366 const bits16 = (d, p) => {
367 const o = p >>> 3;
368 return ((d[o] | (d[o + 1] << 8) | (d[o + 2] << 16)) >>> (p & 7));
369 };
370 const shft = (p) => (p >>> 3) + (p & 7 && 1);
371 const slc = (v, s, e) => {
372 if (s == null || s < 0)
373 s = 0;
374 if (e == null || e > v.length)
375 e = v.length;
376 const n = new (v instanceof u16 ? u16 : v instanceof u32$1 ? u32$1 : u8)(e - s);
377 n.set(v.subarray(s, e));
378 return n;
379 };
380 const max = (a) => {
381 let m = a[0];
382 for (let i = 1, count = a.length; i < count; ++i) {
383 if (a[i] > m)
384 m = a[i];
385 }
386 return m;
387 };
388 const inflt = (dat, buf, st) => {
389 const noSt = !st || st.i;
390 if (!st)
391 st = {};
392 const sl = dat.length;
393 const noBuf = !buf || !noSt;
394 if (!buf)
395 buf = new u8(sl * 3);
396 const cbuf = (l) => {
397 let bl = buf.length;
398 if (l > bl) {
399 const nbuf = new u8(Math.max(bl << 1, l));
400 nbuf.set(buf);
401 buf = nbuf;
402 }
403 };
404 let final = st.f || 0, pos = st.p || 0, bt = st.b || 0, lm = st.l, dm = st.d, lbt = st.m, dbt = st.n;
405 if (final && !lm)
406 return buf;
407 const tbts = sl << 3;
408 do {
409 if (!lm) {
410 st.f = final = bits(dat, pos, 1);
411 const type = bits(dat, pos + 1, 3);
412 pos += 3;
413 if (!type) {
414 const s = shft(pos) + 4, l = dat[s - 4] | (dat[s - 3] << 8), t = s + l;
415 if (t > sl) {
416 if (noSt)
417 throw 'unexpected EOF';
418 break;
419 }
420 if (noBuf)
421 cbuf(bt + l);
422 buf.set(dat.subarray(s, t), bt);
423 st.b = bt += l, st.p = pos = t << 3;
424 continue;
425 }
426 else if (type == 1)
427 lm = flrm, dm = fdrm, lbt = 9, dbt = 5;
428 else if (type == 2) {
429 const hLit = bits(dat, pos, 31) + 257, hcLen = bits(dat, pos + 10, 15) + 4;
430 const tl = hLit + bits(dat, pos + 5, 31) + 1;
431 pos += 14;
432 const ldt = new u8(tl);
433 const clt = new u8(19);
434 for (let i = 0; i < hcLen; ++i) {
435 clt[clim[i]] = bits(dat, pos + i * 3, 7);
436 }
437 pos += hcLen * 3;
438 const clb = max(clt), clbmsk = (1 << clb) - 1;
439 if (!noSt && pos + tl * (clb + 7) > tbts)
440 break;
441 const clm = hMap(clt, clb, 1);
442 for (let i = 0; i < tl;) {
443 const r = clm[bits(dat, pos, clbmsk)];
444 pos += r & 15;
445 const s = r >>> 4;
446 if (s < 16) {
447 ldt[i++] = s;
448 }
449 else {
450 let c = 0, n = 0;
451 if (s == 16)
452 n = 3 + bits(dat, pos, 3), pos += 2, c = ldt[i - 1];
453 else if (s == 17)
454 n = 3 + bits(dat, pos, 7), pos += 3;
455 else if (s == 18)
456 n = 11 + bits(dat, pos, 127), pos += 7;
457 while (n--)
458 ldt[i++] = c;
459 }
460 }
461 const lt = ldt.subarray(0, hLit), dt = ldt.subarray(hLit);
462 lbt = max(lt);
463 dbt = max(dt);
464 lm = hMap(lt, lbt, 1);
465 dm = hMap(dt, dbt, 1);
466 }
467 else
468 throw 'invalid block type';
469 if (pos > tbts)
470 throw 'unexpected EOF';
471 }
472 if (noBuf)
473 cbuf(bt + 131072);
474 const lms = (1 << lbt) - 1, dms = (1 << dbt) - 1;
475 const mxa = lbt + dbt + 18;
476 while (noSt || pos + mxa < tbts) {
477 const c = lm[bits16(dat, pos) & lms], sym = c >>> 4;
478 pos += c & 15;
479 if (pos > tbts)
480 throw 'unexpected EOF';
481 if (!c)
482 throw 'invalid length/literal';
483 if (sym < 256)
484 buf[bt++] = sym;
485 else if (sym == 256) {
486 lm = undefined;
487 break;
488 }
489 else {
490 let add = sym - 254;
491 if (sym > 264) {
492 const i = sym - 257, b = fleb[i];
493 add = bits(dat, pos, (1 << b) - 1) + fl[i];
494 pos += b;
495 }
496 const d = dm[bits16(dat, pos) & dms], dsym = d >>> 4;
497 if (!d)
498 throw 'invalid distance';
499 pos += d & 15;
500 let dt = fd[dsym];
501 if (dsym > 3) {
502 const b = fdeb[dsym];
503 dt += bits16(dat, pos) & ((1 << b) - 1), pos += b;
504 }
505 if (pos > tbts)
506 throw 'unexpected EOF';
507 if (noBuf)
508 cbuf(bt + 131072);
509 const end = bt + add;
510 for (; bt < end; bt += 4) {
511 buf[bt] = buf[bt - dt];
512 buf[bt + 1] = buf[bt + 1 - dt];
513 buf[bt + 2] = buf[bt + 2 - dt];
514 buf[bt + 3] = buf[bt + 3 - dt];
515 }
516 bt = end;
517 }
518 }
519 st.l = lm, st.p = pos, st.b = bt;
520 if (lm)
521 final = 1, st.m = lbt, st.d = dm, st.n = dbt;
522 } while (!final);
523 return bt == buf.length ? buf : slc(buf, 0, bt);
524 };
525 const zlv = (d) => {
526 if ((d[0] & 15) != 8 || (d[0] >>> 4) > 7 || ((d[0] << 8 | d[1]) % 31))
527 throw 'invalid zlib data';
528 if (d[1] & 32)
529 throw 'invalid zlib data: preset dictionaries not supported';
530 };
531 function unzlibSync(data, out) {
532 return inflt((zlv(data), data.subarray(2, -4)), out);
533 }
534
535 var lenIn = 171005;
536 var lenOut = 339466;
537 var bytes_1 = '';
538
539 const wasmBytes = unzlibSync(base64Decode$1(bytes_1, new Uint8Array(lenIn)), new Uint8Array(lenOut));
540
541 const createWasm = createWasmFn('crypto', wasmBytes, null);
542
543 const bridge = new Bridge(createWasm);
544 async function initBridge(createWasm) {
545 return bridge.init(createWasm);
546 }
547
548 function withWasm(fn) {
549 return (...params) => {
550 if (!bridge.wasm) {
551 throw new Error('The WASM interface has not been initialized. Ensure that you wait for the initialization Promise with waitReady() from @polkadot/wasm-crypto (or cryptoWaitReady() from @polkadot/util-crypto) before attempting to use WASM-only interfaces.');
552 }
553 return fn(bridge.wasm, ...params);
554 };
555 }
556 const bip39Generate = withWasm((wasm, words) => {
557 wasm.ext_bip39_generate(8, words);
558 return bridge.resultString();
559 });
560 const bip39ToEntropy = withWasm((wasm, phrase) => {
561 wasm.ext_bip39_to_entropy(8, ...bridge.allocString(phrase));
562 return bridge.resultU8a();
563 });
564 const bip39ToMiniSecret = withWasm((wasm, phrase, password) => {
565 wasm.ext_bip39_to_mini_secret(8, ...bridge.allocString(phrase), ...bridge.allocString(password));
566 return bridge.resultU8a();
567 });
568 const bip39ToSeed = withWasm((wasm, phrase, password) => {
569 wasm.ext_bip39_to_seed(8, ...bridge.allocString(phrase), ...bridge.allocString(password));
570 return bridge.resultU8a();
571 });
572 const bip39Validate = withWasm((wasm, phrase) => {
573 const ret = wasm.ext_bip39_validate(...bridge.allocString(phrase));
574 return ret !== 0;
575 });
576 const ed25519KeypairFromSeed = withWasm((wasm, seed) => {
577 wasm.ext_ed_from_seed(8, ...bridge.allocU8a(seed));
578 return bridge.resultU8a();
579 });
580 const ed25519Sign$1 = withWasm((wasm, pubkey, seckey, message) => {
581 wasm.ext_ed_sign(8, ...bridge.allocU8a(pubkey), ...bridge.allocU8a(seckey), ...bridge.allocU8a(message));
582 return bridge.resultU8a();
583 });
584 const ed25519Verify$1 = withWasm((wasm, signature, message, pubkey) => {
585 const ret = wasm.ext_ed_verify(...bridge.allocU8a(signature), ...bridge.allocU8a(message), ...bridge.allocU8a(pubkey));
586 return ret !== 0;
587 });
588 const secp256k1FromSeed = withWasm((wasm, seckey) => {
589 wasm.ext_secp_from_seed(8, ...bridge.allocU8a(seckey));
590 return bridge.resultU8a();
591 });
592 const secp256k1Compress$1 = withWasm((wasm, pubkey) => {
593 wasm.ext_secp_pub_compress(8, ...bridge.allocU8a(pubkey));
594 return bridge.resultU8a();
595 });
596 const secp256k1Expand$1 = withWasm((wasm, pubkey) => {
597 wasm.ext_secp_pub_expand(8, ...bridge.allocU8a(pubkey));
598 return bridge.resultU8a();
599 });
600 const secp256k1Recover$1 = withWasm((wasm, msgHash, sig, recovery) => {
601 wasm.ext_secp_recover(8, ...bridge.allocU8a(msgHash), ...bridge.allocU8a(sig), recovery);
602 return bridge.resultU8a();
603 });
604 const secp256k1Sign$1 = withWasm((wasm, msgHash, seckey) => {
605 wasm.ext_secp_sign(8, ...bridge.allocU8a(msgHash), ...bridge.allocU8a(seckey));
606 return bridge.resultU8a();
607 });
608 const sr25519DeriveKeypairHard = withWasm((wasm, pair, cc) => {
609 wasm.ext_sr_derive_keypair_hard(8, ...bridge.allocU8a(pair), ...bridge.allocU8a(cc));
610 return bridge.resultU8a();
611 });
612 const sr25519DeriveKeypairSoft = withWasm((wasm, pair, cc) => {
613 wasm.ext_sr_derive_keypair_soft(8, ...bridge.allocU8a(pair), ...bridge.allocU8a(cc));
614 return bridge.resultU8a();
615 });
616 const sr25519DerivePublicSoft = withWasm((wasm, pubkey, cc) => {
617 wasm.ext_sr_derive_public_soft(8, ...bridge.allocU8a(pubkey), ...bridge.allocU8a(cc));
618 return bridge.resultU8a();
619 });
620 const sr25519KeypairFromSeed = withWasm((wasm, seed) => {
621 wasm.ext_sr_from_seed(8, ...bridge.allocU8a(seed));
622 return bridge.resultU8a();
623 });
624 const sr25519Sign$1 = withWasm((wasm, pubkey, secret, message) => {
625 wasm.ext_sr_sign(8, ...bridge.allocU8a(pubkey), ...bridge.allocU8a(secret), ...bridge.allocU8a(message));
626 return bridge.resultU8a();
627 });
628 const sr25519Verify$1 = withWasm((wasm, signature, message, pubkey) => {
629 const ret = wasm.ext_sr_verify(...bridge.allocU8a(signature), ...bridge.allocU8a(message), ...bridge.allocU8a(pubkey));
630 return ret !== 0;
631 });
632 const sr25519Agree = withWasm((wasm, pubkey, secret) => {
633 wasm.ext_sr_agree(8, ...bridge.allocU8a(pubkey), ...bridge.allocU8a(secret));
634 return bridge.resultU8a();
635 });
636 const vrfSign = withWasm((wasm, secret, context, message, extra) => {
637 wasm.ext_vrf_sign(8, ...bridge.allocU8a(secret), ...bridge.allocU8a(context), ...bridge.allocU8a(message), ...bridge.allocU8a(extra));
638 return bridge.resultU8a();
639 });
640 const vrfVerify = withWasm((wasm, pubkey, context, message, extra, outAndProof) => {
641 const ret = wasm.ext_vrf_verify(...bridge.allocU8a(pubkey), ...bridge.allocU8a(context), ...bridge.allocU8a(message), ...bridge.allocU8a(extra), ...bridge.allocU8a(outAndProof));
642 return ret !== 0;
643 });
644 const blake2b$1 = withWasm((wasm, data, key, size) => {
645 wasm.ext_blake2b(8, ...bridge.allocU8a(data), ...bridge.allocU8a(key), size);
646 return bridge.resultU8a();
647 });
648 const hmacSha256 = withWasm((wasm, key, data) => {
649 wasm.ext_hmac_sha256(8, ...bridge.allocU8a(key), ...bridge.allocU8a(data));
650 return bridge.resultU8a();
651 });
652 const hmacSha512 = withWasm((wasm, key, data) => {
653 wasm.ext_hmac_sha512(8, ...bridge.allocU8a(key), ...bridge.allocU8a(data));
654 return bridge.resultU8a();
655 });
656 const keccak256 = withWasm((wasm, data) => {
657 wasm.ext_keccak256(8, ...bridge.allocU8a(data));
658 return bridge.resultU8a();
659 });
660 const keccak512 = withWasm((wasm, data) => {
661 wasm.ext_keccak512(8, ...bridge.allocU8a(data));
662 return bridge.resultU8a();
663 });
664 const pbkdf2$1 = withWasm((wasm, data, salt, rounds) => {
665 wasm.ext_pbkdf2(8, ...bridge.allocU8a(data), ...bridge.allocU8a(salt), rounds);
666 return bridge.resultU8a();
667 });
668 const scrypt$1 = withWasm((wasm, password, salt, log2n, r, p) => {
669 wasm.ext_scrypt(8, ...bridge.allocU8a(password), ...bridge.allocU8a(salt), log2n, r, p);
670 return bridge.resultU8a();
671 });
672 const sha256$1 = withWasm((wasm, data) => {
673 wasm.ext_sha256(8, ...bridge.allocU8a(data));
674 return bridge.resultU8a();
675 });
676 const sha512$1 = withWasm((wasm, data) => {
677 wasm.ext_sha512(8, ...bridge.allocU8a(data));
678 return bridge.resultU8a();
679 });
680 const twox = withWasm((wasm, data, rounds) => {
681 wasm.ext_twox(8, ...bridge.allocU8a(data), rounds);
682 return bridge.resultU8a();
683 });
684 function isReady() {
685 return !!bridge.wasm;
686 }
687 async function waitReady() {
688 try {
689 const wasm = await initBridge();
690 return !!wasm;
691 }
692 catch {
693 return false;
694 }
695 }
696
697 const cryptoIsReady = isReady;
698 function cryptoWaitReady() {
699 return waitReady()
700 .then(() => {
701 if (!isReady()) {
702 throw new Error('Unable to initialize @polkadot/util-crypto');
703 }
704 return true;
705 })
706 .catch(() => false);
707 }
708
709 cryptoWaitReady().catch(() => {
710 });
711
712 const packageInfo = { name: '@polkadot/util-crypto', path: (({ url: (typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href)) }) && (typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href))) ? new URL((typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href))).pathname.substring(0, new URL((typeof document === 'undefined' && typeof location === 'undefined' ? require('u' + 'rl').pathToFileURL(__filename).href : typeof document === 'undefined' ? location.href : (document.currentScript && document.currentScript.src || new URL('bundle-polkadot-util-crypto.js', document.baseURI).href))).pathname.lastIndexOf('/') + 1) : 'auto', type: 'esm', version: '12.2.2' };
713
714 /*! scure-base - MIT License (c) 2022 Paul Miller (paulmillr.com) */
715 function assertNumber(n) {
716 if (!Number.isSafeInteger(n))
717 throw new Error(`Wrong integer: ${n}`);
718 }
719 function chain(...args) {
720 const wrap = (a, b) => (c) => a(b(c));
721 const encode = Array.from(args)
722 .reverse()
723 .reduce((acc, i) => (acc ? wrap(acc, i.encode) : i.encode), undefined);
724 const decode = args.reduce((acc, i) => (acc ? wrap(acc, i.decode) : i.decode), undefined);
725 return { encode, decode };
726 }
727 function alphabet(alphabet) {
728 return {
729 encode: (digits) => {
730 if (!Array.isArray(digits) || (digits.length && typeof digits[0] !== 'number'))
731 throw new Error('alphabet.encode input should be an array of numbers');
732 return digits.map((i) => {
733 assertNumber(i);
734 if (i < 0 || i >= alphabet.length)
735 throw new Error(`Digit index outside alphabet: ${i} (alphabet: ${alphabet.length})`);
736 return alphabet[i];
737 });
738 },
739 decode: (input) => {
740 if (!Array.isArray(input) || (input.length && typeof input[0] !== 'string'))
741 throw new Error('alphabet.decode input should be array of strings');
742 return input.map((letter) => {
743 if (typeof letter !== 'string')
744 throw new Error(`alphabet.decode: not string element=${letter}`);
745 const index = alphabet.indexOf(letter);
746 if (index === -1)
747 throw new Error(`Unknown letter: "${letter}". Allowed: ${alphabet}`);
748 return index;
749 });
750 },
751 };
752 }
753 function join(separator = '') {
754 if (typeof separator !== 'string')
755 throw new Error('join separator should be string');
756 return {
757 encode: (from) => {
758 if (!Array.isArray(from) || (from.length && typeof from[0] !== 'string'))
759 throw new Error('join.encode input should be array of strings');
760 for (let i of from)
761 if (typeof i !== 'string')
762 throw new Error(`join.encode: non-string input=${i}`);
763 return from.join(separator);
764 },
765 decode: (to) => {
766 if (typeof to !== 'string')
767 throw new Error('join.decode input should be string');
768 return to.split(separator);
769 },
770 };
771 }
772 function padding(bits, chr = '=') {
773 assertNumber(bits);
774 if (typeof chr !== 'string')
775 throw new Error('padding chr should be string');
776 return {
777 encode(data) {
778 if (!Array.isArray(data) || (data.length && typeof data[0] !== 'string'))
779 throw new Error('padding.encode input should be array of strings');
780 for (let i of data)
781 if (typeof i !== 'string')
782 throw new Error(`padding.encode: non-string input=${i}`);
783 while ((data.length * bits) % 8)
784 data.push(chr);
785 return data;
786 },
787 decode(input) {
788 if (!Array.isArray(input) || (input.length && typeof input[0] !== 'string'))
789 throw new Error('padding.encode input should be array of strings');
790 for (let i of input)
791 if (typeof i !== 'string')
792 throw new Error(`padding.decode: non-string input=${i}`);
793 let end = input.length;
794 if ((end * bits) % 8)
795 throw new Error('Invalid padding: string should have whole number of bytes');
796 for (; end > 0 && input[end - 1] === chr; end--) {
797 if (!(((end - 1) * bits) % 8))
798 throw new Error('Invalid padding: string has too much padding');
799 }
800 return input.slice(0, end);
801 },
802 };
803 }
804 function normalize$1(fn) {
805 if (typeof fn !== 'function')
806 throw new Error('normalize fn should be function');
807 return { encode: (from) => from, decode: (to) => fn(to) };
808 }
809 function convertRadix(data, from, to) {
810 if (from < 2)
811 throw new Error(`convertRadix: wrong from=${from}, base cannot be less than 2`);
812 if (to < 2)
813 throw new Error(`convertRadix: wrong to=${to}, base cannot be less than 2`);
814 if (!Array.isArray(data))
815 throw new Error('convertRadix: data should be array');
816 if (!data.length)
817 return [];
818 let pos = 0;
819 const res = [];
820 const digits = Array.from(data);
821 digits.forEach((d) => {
822 assertNumber(d);
823 if (d < 0 || d >= from)
824 throw new Error(`Wrong integer: ${d}`);
825 });
826 while (true) {
827 let carry = 0;
828 let done = true;
829 for (let i = pos; i < digits.length; i++) {
830 const digit = digits[i];
831 const digitBase = from * carry + digit;
832 if (!Number.isSafeInteger(digitBase) ||
833 (from * carry) / from !== carry ||
834 digitBase - digit !== from * carry) {
835 throw new Error('convertRadix: carry overflow');
836 }
837 carry = digitBase % to;
838 digits[i] = Math.floor(digitBase / to);
839 if (!Number.isSafeInteger(digits[i]) || digits[i] * to + carry !== digitBase)
840 throw new Error('convertRadix: carry overflow');
841 if (!done)
842 continue;
843 else if (!digits[i])
844 pos = i;
845 else
846 done = false;
847 }
848 res.push(carry);
849 if (done)
850 break;
851 }
852 for (let i = 0; i < data.length - 1 && data[i] === 0; i++)
853 res.push(0);
854 return res.reverse();
855 }
856 const gcd = (a, b) => (!b ? a : gcd(b, a % b));
857 const radix2carry = (from, to) => from + (to - gcd(from, to));
858 function convertRadix2(data, from, to, padding) {
859 if (!Array.isArray(data))
860 throw new Error('convertRadix2: data should be array');
861 if (from <= 0 || from > 32)
862 throw new Error(`convertRadix2: wrong from=${from}`);
863 if (to <= 0 || to > 32)
864 throw new Error(`convertRadix2: wrong to=${to}`);
865 if (radix2carry(from, to) > 32) {
866 throw new Error(`convertRadix2: carry overflow from=${from} to=${to} carryBits=${radix2carry(from, to)}`);
867 }
868 let carry = 0;
869 let pos = 0;
870 const mask = 2 ** to - 1;
871 const res = [];
872 for (const n of data) {
873 assertNumber(n);
874 if (n >= 2 ** from)
875 throw new Error(`convertRadix2: invalid data word=${n} from=${from}`);
876 carry = (carry << from) | n;
877 if (pos + from > 32)
878 throw new Error(`convertRadix2: carry overflow pos=${pos} from=${from}`);
879 pos += from;
880 for (; pos >= to; pos -= to)
881 res.push(((carry >> (pos - to)) & mask) >>> 0);
882 carry &= 2 ** pos - 1;
883 }
884 carry = (carry << (to - pos)) & mask;
885 if (!padding && pos >= from)
886 throw new Error('Excess padding');
887 if (!padding && carry)
888 throw new Error(`Non-zero padding: ${carry}`);
889 if (padding && pos > 0)
890 res.push(carry >>> 0);
891 return res;
892 }
893 function radix(num) {
894 assertNumber(num);
895 return {
896 encode: (bytes) => {
897 if (!(bytes instanceof Uint8Array))
898 throw new Error('radix.encode input should be Uint8Array');
899 return convertRadix(Array.from(bytes), 2 ** 8, num);
900 },
901 decode: (digits) => {
902 if (!Array.isArray(digits) || (digits.length && typeof digits[0] !== 'number'))
903 throw new Error('radix.decode input should be array of strings');
904 return Uint8Array.from(convertRadix(digits, num, 2 ** 8));
905 },
906 };
907 }
908 function radix2(bits, revPadding = false) {
909 assertNumber(bits);
910 if (bits <= 0 || bits > 32)
911 throw new Error('radix2: bits should be in (0..32]');
912 if (radix2carry(8, bits) > 32 || radix2carry(bits, 8) > 32)
913 throw new Error('radix2: carry overflow');
914 return {
915 encode: (bytes) => {
916 if (!(bytes instanceof Uint8Array))
917 throw new Error('radix2.encode input should be Uint8Array');
918 return convertRadix2(Array.from(bytes), 8, bits, !revPadding);
919 },
920 decode: (digits) => {
921 if (!Array.isArray(digits) || (digits.length && typeof digits[0] !== 'number'))
922 throw new Error('radix2.decode input should be array of strings');
923 return Uint8Array.from(convertRadix2(digits, bits, 8, revPadding));
924 },
925 };
926 }
927 function unsafeWrapper(fn) {
928 if (typeof fn !== 'function')
929 throw new Error('unsafeWrapper fn should be function');
930 return function (...args) {
931 try {
932 return fn.apply(null, args);
933 }
934 catch (e) { }
935 };
936 }
937 function checksum(len, fn) {
938 assertNumber(len);
939 if (typeof fn !== 'function')
940 throw new Error('checksum fn should be function');
941 return {
942 encode(data) {
943 if (!(data instanceof Uint8Array))
944 throw new Error('checksum.encode: input should be Uint8Array');
945 const checksum = fn(data).slice(0, len);
946 const res = new Uint8Array(data.length + len);
947 res.set(data);
948 res.set(checksum, data.length);
949 return res;
950 },
951 decode(data) {
952 if (!(data instanceof Uint8Array))
953 throw new Error('checksum.decode: input should be Uint8Array');
954 const payload = data.slice(0, -len);
955 const newChecksum = fn(payload).slice(0, len);
956 const oldChecksum = data.slice(-len);
957 for (let i = 0; i < len; i++)
958 if (newChecksum[i] !== oldChecksum[i])
959 throw new Error('Invalid checksum');
960 return payload;
961 },
962 };
963 }
964 const utils = { alphabet, chain, checksum, radix, radix2, join, padding };
965 const base16 = chain(radix2(4), alphabet('0123456789ABCDEF'), join(''));
966 const base32 = chain(radix2(5), alphabet('ABCDEFGHIJKLMNOPQRSTUVWXYZ234567'), padding(5), join(''));
967 chain(radix2(5), alphabet('0123456789ABCDEFGHIJKLMNOPQRSTUV'), padding(5), join(''));
968 chain(radix2(5), alphabet('0123456789ABCDEFGHJKMNPQRSTVWXYZ'), join(''), normalize$1((s) => s.toUpperCase().replace(/O/g, '0').replace(/[IL]/g, '1')));
969 const base64 = chain(radix2(6), alphabet('ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'), padding(6), join(''));
970 const base64url = chain(radix2(6), alphabet('ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_'), padding(6), join(''));
971 const genBase58 = (abc) => chain(radix(58), alphabet(abc), join(''));
972 const base58 = genBase58('123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz');
973 genBase58('123456789abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ');
974 genBase58('rpshnaf39wBUDNEGHJKLM4PQRST7VWXYZ2bcdeCg65jkm8oFqi1tuvAxyz');
975 const XMR_BLOCK_LEN = [0, 2, 3, 5, 6, 7, 9, 10, 11];
976 const base58xmr = {
977 encode(data) {
978 let res = '';
979 for (let i = 0; i < data.length; i += 8) {
980 const block = data.subarray(i, i + 8);
981 res += base58.encode(block).padStart(XMR_BLOCK_LEN[block.length], '1');
982 }
983 return res;
984 },
985 decode(str) {
986 let res = [];
987 for (let i = 0; i < str.length; i += 11) {
988 const slice = str.slice(i, i + 11);
989 const blockLen = XMR_BLOCK_LEN.indexOf(slice.length);
990 const block = base58.decode(slice);
991 for (let j = 0; j < block.length - blockLen; j++) {
992 if (block[j] !== 0)
993 throw new Error('base58xmr: wrong padding');
994 }
995 res = res.concat(Array.from(block.slice(block.length - blockLen)));
996 }
997 return Uint8Array.from(res);
998 },
999 };
1000 const BECH_ALPHABET = chain(alphabet('qpzry9x8gf2tvdw0s3jn54khce6mua7l'), join(''));
1001 const POLYMOD_GENERATORS = [0x3b6a57b2, 0x26508e6d, 0x1ea119fa, 0x3d4233dd, 0x2a1462b3];
1002 function bech32Polymod(pre) {
1003 const b = pre >> 25;
1004 let chk = (pre & 0x1ffffff) << 5;
1005 for (let i = 0; i < POLYMOD_GENERATORS.length; i++) {
1006 if (((b >> i) & 1) === 1)
1007 chk ^= POLYMOD_GENERATORS[i];
1008 }
1009 return chk;
1010 }
1011 function bechChecksum(prefix, words, encodingConst = 1) {
1012 const len = prefix.length;
1013 let chk = 1;
1014 for (let i = 0; i < len; i++) {
1015 const c = prefix.charCodeAt(i);
1016 if (c < 33 || c > 126)
1017 throw new Error(`Invalid prefix (${prefix})`);
1018 chk = bech32Polymod(chk) ^ (c >> 5);
1019 }
1020 chk = bech32Polymod(chk);
1021 for (let i = 0; i < len; i++)
1022 chk = bech32Polymod(chk) ^ (prefix.charCodeAt(i) & 0x1f);
1023 for (let v of words)
1024 chk = bech32Polymod(chk) ^ v;
1025 for (let i = 0; i < 6; i++)
1026 chk = bech32Polymod(chk);
1027 chk ^= encodingConst;
1028 return BECH_ALPHABET.encode(convertRadix2([chk % 2 ** 30], 30, 5, false));
1029 }
1030 function genBech32(encoding) {
1031 const ENCODING_CONST = encoding === 'bech32' ? 1 : 0x2bc830a3;
1032 const _words = radix2(5);
1033 const fromWords = _words.decode;
1034 const toWords = _words.encode;
1035 const fromWordsUnsafe = unsafeWrapper(fromWords);
1036 function encode(prefix, words, limit = 90) {
1037 if (typeof prefix !== 'string')
1038 throw new Error(`bech32.encode prefix should be string, not ${typeof prefix}`);
1039 if (!Array.isArray(words) || (words.length && typeof words[0] !== 'number'))
1040 throw new Error(`bech32.encode words should be array of numbers, not ${typeof words}`);
1041 const actualLength = prefix.length + 7 + words.length;
1042 if (limit !== false && actualLength > limit)
1043 throw new TypeError(`Length ${actualLength} exceeds limit ${limit}`);
1044 prefix = prefix.toLowerCase();
1045 return `${prefix}1${BECH_ALPHABET.encode(words)}${bechChecksum(prefix, words, ENCODING_CONST)}`;
1046 }
1047 function decode(str, limit = 90) {
1048 if (typeof str !== 'string')
1049 throw new Error(`bech32.decode input should be string, not ${typeof str}`);
1050 if (str.length < 8 || (limit !== false && str.length > limit))
1051 throw new TypeError(`Wrong string length: ${str.length} (${str}). Expected (8..${limit})`);
1052 const lowered = str.toLowerCase();
1053 if (str !== lowered && str !== str.toUpperCase())
1054 throw new Error(`String must be lowercase or uppercase`);
1055 str = lowered;
1056 const sepIndex = str.lastIndexOf('1');
1057 if (sepIndex === 0 || sepIndex === -1)
1058 throw new Error(`Letter "1" must be present between prefix and data only`);
1059 const prefix = str.slice(0, sepIndex);
1060 const _words = str.slice(sepIndex + 1);
1061 if (_words.length < 6)
1062 throw new Error('Data must be at least 6 characters long');
1063 const words = BECH_ALPHABET.decode(_words).slice(0, -6);
1064 const sum = bechChecksum(prefix, words, ENCODING_CONST);
1065 if (!_words.endsWith(sum))
1066 throw new Error(`Invalid checksum in ${str}: expected "${sum}"`);
1067 return { prefix, words };
1068 }
1069 const decodeUnsafe = unsafeWrapper(decode);
1070 function decodeToBytes(str) {
1071 const { prefix, words } = decode(str, false);
1072 return { prefix, words, bytes: fromWords(words) };
1073 }
1074 return { encode, decode, decodeToBytes, decodeUnsafe, fromWords, fromWordsUnsafe, toWords };
1075 }
1076 genBech32('bech32');
1077 genBech32('bech32m');
1078 const utf8 = {
1079 encode: (data) => new TextDecoder().decode(data),
1080 decode: (str) => new TextEncoder().encode(str),
1081 };
1082 const hex = chain(radix2(4), alphabet('0123456789abcdef'), join(''), normalize$1((s) => {
1083 if (typeof s !== 'string' || s.length % 2)
1084 throw new TypeError(`hex.decode: expected string, got ${typeof s} with length ${s.length}`);
1085 return s.toLowerCase();
1086 }));
1087 const CODERS = {
1088 utf8, hex, base16, base32, base64, base64url, base58, base58xmr
1089 };
1090`Invalid encoding type. Available types: ${Object.keys(CODERS).join(', ')}`;
1091
1092 function createDecode({ coder, ipfs }, validate) {
1093 return (value, ipfsCompat) => {
1094 validate(value, ipfsCompat);
1095 return coder.decode(ipfs && ipfsCompat
1096 ? value.substring(1)
1097 : value);
1098 };
1099 }
1100 function createEncode({ coder, ipfs }) {
1101 return (value, ipfsCompat) => {
1102 const out = coder.encode(util.u8aToU8a(value));
1103 return ipfs && ipfsCompat
1104 ? `${ipfs}${out}`
1105 : out;
1106 };
1107 }
1108 function createIs(validate) {
1109 return (value, ipfsCompat) => {
1110 try {
1111 return validate(value, ipfsCompat);
1112 }
1113 catch {
1114 return false;
1115 }
1116 };
1117 }
1118 function createValidate({ chars, ipfs, type }) {
1119 return (value, ipfsCompat) => {
1120 if (typeof value !== 'string') {
1121 throw new Error(`Expected ${type} string input`);
1122 }
1123 else if (ipfs && ipfsCompat && value[0] !== ipfs) {
1124 throw new Error(`Expected ipfs-compatible ${type} to start with '${ipfs}'`);
1125 }
1126 for (let i = (ipfsCompat ? 1 : 0), count = value.length; i < count; i++) {
1127 if (!(chars.includes(value[i]) || (value[i] === '=' && ((i === value.length - 1) ||
1128 !chars.includes(value[i + 1]))))) {
1129 throw new Error(`Invalid ${type} character "${value[i]}" (0x${value.charCodeAt(i).toString(16)}) at index ${i}`);
1130 }
1131 }
1132 return true;
1133 };
1134 }
1135
1136 const config$2 = {
1137 chars: '123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz',
1138 coder: base58,
1139 ipfs: 'z',
1140 type: 'base58'
1141 };
1142 const base58Validate = createValidate(config$2);
1143 const base58Decode = createDecode(config$2, base58Validate);
1144 const base58Encode = createEncode(config$2);
1145 const isBase58 = createIs(base58Validate);
1146
1147 function number(n) {
1148 if (!Number.isSafeInteger(n) || n < 0)
1149 throw new Error(`Wrong positive integer: ${n}`);
1150 }
1151 function bool(b) {
1152 if (typeof b !== 'boolean')
1153 throw new Error(`Expected boolean, not ${b}`);
1154 }
1155 function bytes(b, ...lengths) {
1156 if (!(b instanceof Uint8Array))
1157 throw new Error('Expected Uint8Array');
1158 if (lengths.length > 0 && !lengths.includes(b.length))
1159 throw new Error(`Expected Uint8Array of length ${lengths}, not of length=${b.length}`);
1160 }
1161 function hash(hash) {
1162 if (typeof hash !== 'function' || typeof hash.create !== 'function')
1163 throw new Error('Hash should be wrapped by utils.wrapConstructor');
1164 number(hash.outputLen);
1165 number(hash.blockLen);
1166 }
1167 function exists(instance, checkFinished = true) {
1168 if (instance.destroyed)
1169 throw new Error('Hash instance has been destroyed');
1170 if (checkFinished && instance.finished)
1171 throw new Error('Hash#digest() has already been called');
1172 }
1173 function output(out, instance) {
1174 bytes(out);
1175 const min = instance.outputLen;
1176 if (out.length < min) {
1177 throw new Error(`digestInto() expects output buffer of length at least ${min}`);
1178 }
1179 }
1180 const assert = {
1181 number,
1182 bool,
1183 bytes,
1184 hash,
1185 exists,
1186 output,
1187 };
1188
1189 const crypto = typeof globalThis === 'object' && 'crypto' in globalThis ? globalThis.crypto : undefined;
1190
1191 /*! noble-hashes - MIT License (c) 2022 Paul Miller (paulmillr.com) */
1192 const u8a$1 = (a) => a instanceof Uint8Array;
1193 const u32 = (arr) => new Uint32Array(arr.buffer, arr.byteOffset, Math.floor(arr.byteLength / 4));
1194 const createView = (arr) => new DataView(arr.buffer, arr.byteOffset, arr.byteLength);
1195 const rotr = (word, shift) => (word << (32 - shift)) | (word >>> shift);
1196 const isLE = new Uint8Array(new Uint32Array([0x11223344]).buffer)[0] === 0x44;
1197 if (!isLE)
1198 throw new Error('Non little-endian hardware is not supported');
1199 Array.from({ length: 256 }, (v, i) => i.toString(16).padStart(2, '0'));
1200 function utf8ToBytes$1(str) {
1201 if (typeof str !== 'string')
1202 throw new Error(`utf8ToBytes expected string, got ${typeof str}`);
1203 return new Uint8Array(new TextEncoder().encode(str));
1204 }
1205 function toBytes(data) {
1206 if (typeof data === 'string')
1207 data = utf8ToBytes$1(data);
1208 if (!u8a$1(data))
1209 throw new Error(`expected Uint8Array, got ${typeof data}`);
1210 return data;
1211 }
1212 function concatBytes$1(...arrays) {
1213 const r = new Uint8Array(arrays.reduce((sum, a) => sum + a.length, 0));
1214 let pad = 0;
1215 arrays.forEach((a) => {
1216 if (!u8a$1(a))
1217 throw new Error('Uint8Array expected');
1218 r.set(a, pad);
1219 pad += a.length;
1220 });
1221 return r;
1222 }
1223 class Hash {
1224 clone() {
1225 return this._cloneInto();
1226 }
1227 }
1228 const isPlainObject = (obj) => Object.prototype.toString.call(obj) === '[object Object]' && obj.constructor === Object;
1229 function checkOpts(defaults, opts) {
1230 if (opts !== undefined && (typeof opts !== 'object' || !isPlainObject(opts)))
1231 throw new Error('Options should be object or undefined');
1232 const merged = Object.assign(defaults, opts);
1233 return merged;
1234 }
1235 function wrapConstructor(hashCons) {
1236 const hashC = (msg) => hashCons().update(toBytes(msg)).digest();
1237 const tmp = hashCons();
1238 hashC.outputLen = tmp.outputLen;
1239 hashC.blockLen = tmp.blockLen;
1240 hashC.create = () => hashCons();
1241 return hashC;
1242 }
1243 function wrapConstructorWithOpts(hashCons) {
1244 const hashC = (msg, opts) => hashCons(opts).update(toBytes(msg)).digest();
1245 const tmp = hashCons({});
1246 hashC.outputLen = tmp.outputLen;
1247 hashC.blockLen = tmp.blockLen;
1248 hashC.create = (opts) => hashCons(opts);
1249 return hashC;
1250 }
1251 function wrapXOFConstructorWithOpts(hashCons) {
1252 const hashC = (msg, opts) => hashCons(opts).update(toBytes(msg)).digest();
1253 const tmp = hashCons({});
1254 hashC.outputLen = tmp.outputLen;
1255 hashC.blockLen = tmp.blockLen;
1256 hashC.create = (opts) => hashCons(opts);
1257 return hashC;
1258 }
1259 function randomBytes(bytesLength = 32) {
1260 if (crypto && typeof crypto.getRandomValues === 'function') {
1261 return crypto.getRandomValues(new Uint8Array(bytesLength));
1262 }
1263 throw new Error('crypto.getRandomValues must be defined');
1264 }
1265
1266 const SIGMA = new Uint8Array([
1267 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15,
1268 14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3,
1269 11, 8, 12, 0, 5, 2, 15, 13, 10, 14, 3, 6, 7, 1, 9, 4,
1270 7, 9, 3, 1, 13, 12, 11, 14, 2, 6, 5, 10, 4, 0, 15, 8,
1271 9, 0, 5, 7, 2, 4, 10, 15, 14, 1, 11, 12, 6, 8, 3, 13,
1272 2, 12, 6, 10, 0, 11, 8, 3, 4, 13, 7, 5, 15, 14, 1, 9,
1273 12, 5, 1, 15, 14, 13, 4, 10, 0, 7, 6, 3, 9, 2, 8, 11,
1274 13, 11, 7, 14, 12, 1, 3, 9, 5, 0, 15, 4, 8, 6, 2, 10,
1275 6, 15, 14, 9, 11, 3, 0, 8, 12, 2, 13, 7, 1, 4, 10, 5,
1276 10, 2, 8, 4, 7, 6, 1, 5, 15, 11, 9, 14, 3, 12, 13, 0,
1277 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15,
1278 14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3,
1279 ]);
1280 class BLAKE2 extends Hash {
1281 constructor(blockLen, outputLen, opts = {}, keyLen, saltLen, persLen) {
1282 super();
1283 this.blockLen = blockLen;
1284 this.outputLen = outputLen;
1285 this.length = 0;
1286 this.pos = 0;
1287 this.finished = false;
1288 this.destroyed = false;
1289 assert.number(blockLen);
1290 assert.number(outputLen);
1291 assert.number(keyLen);
1292 if (outputLen < 0 || outputLen > keyLen)
1293 throw new Error('outputLen bigger than keyLen');
1294 if (opts.key !== undefined && (opts.key.length < 1 || opts.key.length > keyLen))
1295 throw new Error(`key must be up 1..${keyLen} byte long or undefined`);
1296 if (opts.salt !== undefined && opts.salt.length !== saltLen)
1297 throw new Error(`salt must be ${saltLen} byte long or undefined`);
1298 if (opts.personalization !== undefined && opts.personalization.length !== persLen)
1299 throw new Error(`personalization must be ${persLen} byte long or undefined`);
1300 this.buffer32 = u32((this.buffer = new Uint8Array(blockLen)));
1301 }
1302 update(data) {
1303 assert.exists(this);
1304 const { blockLen, buffer, buffer32 } = this;
1305 data = toBytes(data);
1306 const len = data.length;
1307 const offset = data.byteOffset;
1308 const buf = data.buffer;
1309 for (let pos = 0; pos < len;) {
1310 if (this.pos === blockLen) {
1311 this.compress(buffer32, 0, false);
1312 this.pos = 0;
1313 }
1314 const take = Math.min(blockLen - this.pos, len - pos);
1315 const dataOffset = offset + pos;
1316 if (take === blockLen && !(dataOffset % 4) && pos + take < len) {
1317 const data32 = new Uint32Array(buf, dataOffset, Math.floor((len - pos) / 4));
1318 for (let pos32 = 0; pos + blockLen < len; pos32 += buffer32.length, pos += blockLen) {
1319 this.length += blockLen;
1320 this.compress(data32, pos32, false);
1321 }
1322 continue;
1323 }
1324 buffer.set(data.subarray(pos, pos + take), this.pos);
1325 this.pos += take;
1326 this.length += take;
1327 pos += take;
1328 }
1329 return this;
1330 }
1331 digestInto(out) {
1332 assert.exists(this);
1333 assert.output(out, this);
1334 const { pos, buffer32 } = this;
1335 this.finished = true;
1336 this.buffer.subarray(pos).fill(0);
1337 this.compress(buffer32, 0, true);
1338 const out32 = u32(out);
1339 this.get().forEach((v, i) => (out32[i] = v));
1340 }
1341 digest() {
1342 const { buffer, outputLen } = this;
1343 this.digestInto(buffer);
1344 const res = buffer.slice(0, outputLen);
1345 this.destroy();
1346 return res;
1347 }
1348 _cloneInto(to) {
1349 const { buffer, length, finished, destroyed, outputLen, pos } = this;
1350 to || (to = new this.constructor({ dkLen: outputLen }));
1351 to.set(...this.get());
1352 to.length = length;
1353 to.finished = finished;
1354 to.destroyed = destroyed;
1355 to.outputLen = outputLen;
1356 to.buffer.set(buffer);
1357 to.pos = pos;
1358 return to;
1359 }
1360 }
1361
1362 const U32_MASK64 = BigInt(2 ** 32 - 1);
1363 const _32n$1 = BigInt(32);
1364 function fromBig(n, le = false) {
1365 if (le)
1366 return { h: Number(n & U32_MASK64), l: Number((n >> _32n$1) & U32_MASK64) };
1367 return { h: Number((n >> _32n$1) & U32_MASK64) | 0, l: Number(n & U32_MASK64) | 0 };
1368 }
1369 function split(lst, le = false) {
1370 let Ah = new Uint32Array(lst.length);
1371 let Al = new Uint32Array(lst.length);
1372 for (let i = 0; i < lst.length; i++) {
1373 const { h, l } = fromBig(lst[i], le);
1374 [Ah[i], Al[i]] = [h, l];
1375 }
1376 return [Ah, Al];
1377 }
1378 const toBig = (h, l) => (BigInt(h >>> 0) << _32n$1) | BigInt(l >>> 0);
1379 const shrSH = (h, l, s) => h >>> s;
1380 const shrSL = (h, l, s) => (h << (32 - s)) | (l >>> s);
1381 const rotrSH = (h, l, s) => (h >>> s) | (l << (32 - s));
1382 const rotrSL = (h, l, s) => (h << (32 - s)) | (l >>> s);
1383 const rotrBH = (h, l, s) => (h << (64 - s)) | (l >>> (s - 32));
1384 const rotrBL = (h, l, s) => (h >>> (s - 32)) | (l << (64 - s));
1385 const rotr32H = (h, l) => l;
1386 const rotr32L = (h, l) => h;
1387 const rotlSH = (h, l, s) => (h << s) | (l >>> (32 - s));
1388 const rotlSL = (h, l, s) => (l << s) | (h >>> (32 - s));
1389 const rotlBH = (h, l, s) => (l << (s - 32)) | (h >>> (64 - s));
1390 const rotlBL = (h, l, s) => (h << (s - 32)) | (l >>> (64 - s));
1391 function add(Ah, Al, Bh, Bl) {
1392 const l = (Al >>> 0) + (Bl >>> 0);
1393 return { h: (Ah + Bh + ((l / 2 ** 32) | 0)) | 0, l: l | 0 };
1394 }
1395 const add3L = (Al, Bl, Cl) => (Al >>> 0) + (Bl >>> 0) + (Cl >>> 0);
1396 const add3H = (low, Ah, Bh, Ch) => (Ah + Bh + Ch + ((low / 2 ** 32) | 0)) | 0;
1397 const add4L = (Al, Bl, Cl, Dl) => (Al >>> 0) + (Bl >>> 0) + (Cl >>> 0) + (Dl >>> 0);
1398 const add4H = (low, Ah, Bh, Ch, Dh) => (Ah + Bh + Ch + Dh + ((low / 2 ** 32) | 0)) | 0;
1399 const add5L = (Al, Bl, Cl, Dl, El) => (Al >>> 0) + (Bl >>> 0) + (Cl >>> 0) + (Dl >>> 0) + (El >>> 0);
1400 const add5H = (low, Ah, Bh, Ch, Dh, Eh) => (Ah + Bh + Ch + Dh + Eh + ((low / 2 ** 32) | 0)) | 0;
1401 const u64 = {
1402 fromBig, split, toBig,
1403 shrSH, shrSL,
1404 rotrSH, rotrSL, rotrBH, rotrBL,
1405 rotr32H, rotr32L,
1406 rotlSH, rotlSL, rotlBH, rotlBL,
1407 add, add3L, add3H, add4L, add4H, add5H, add5L,
1408 };
1409
1410 const IV$1 = new Uint32Array([
1411 0xf3bcc908, 0x6a09e667, 0x84caa73b, 0xbb67ae85, 0xfe94f82b, 0x3c6ef372, 0x5f1d36f1, 0xa54ff53a,
1412 0xade682d1, 0x510e527f, 0x2b3e6c1f, 0x9b05688c, 0xfb41bd6b, 0x1f83d9ab, 0x137e2179, 0x5be0cd19
1413 ]);
1414 const BUF = new Uint32Array(32);
1415 function G1(a, b, c, d, msg, x) {
1416 const Xl = msg[x], Xh = msg[x + 1];
1417 let Al = BUF[2 * a], Ah = BUF[2 * a + 1];
1418 let Bl = BUF[2 * b], Bh = BUF[2 * b + 1];
1419 let Cl = BUF[2 * c], Ch = BUF[2 * c + 1];
1420 let Dl = BUF[2 * d], Dh = BUF[2 * d + 1];
1421 let ll = u64.add3L(Al, Bl, Xl);
1422 Ah = u64.add3H(ll, Ah, Bh, Xh);
1423 Al = ll | 0;
1424 ({ Dh, Dl } = { Dh: Dh ^ Ah, Dl: Dl ^ Al });
1425 ({ Dh, Dl } = { Dh: u64.rotr32H(Dh, Dl), Dl: u64.rotr32L(Dh, Dl) });
1426 ({ h: Ch, l: Cl } = u64.add(Ch, Cl, Dh, Dl));
1427 ({ Bh, Bl } = { Bh: Bh ^ Ch, Bl: Bl ^ Cl });
1428 ({ Bh, Bl } = { Bh: u64.rotrSH(Bh, Bl, 24), Bl: u64.rotrSL(Bh, Bl, 24) });
1429 (BUF[2 * a] = Al), (BUF[2 * a + 1] = Ah);
1430 (BUF[2 * b] = Bl), (BUF[2 * b + 1] = Bh);
1431 (BUF[2 * c] = Cl), (BUF[2 * c + 1] = Ch);
1432 (BUF[2 * d] = Dl), (BUF[2 * d + 1] = Dh);
1433 }
1434 function G2(a, b, c, d, msg, x) {
1435 const Xl = msg[x], Xh = msg[x + 1];
1436 let Al = BUF[2 * a], Ah = BUF[2 * a + 1];
1437 let Bl = BUF[2 * b], Bh = BUF[2 * b + 1];
1438 let Cl = BUF[2 * c], Ch = BUF[2 * c + 1];
1439 let Dl = BUF[2 * d], Dh = BUF[2 * d + 1];
1440 let ll = u64.add3L(Al, Bl, Xl);
1441 Ah = u64.add3H(ll, Ah, Bh, Xh);
1442 Al = ll | 0;
1443 ({ Dh, Dl } = { Dh: Dh ^ Ah, Dl: Dl ^ Al });
1444 ({ Dh, Dl } = { Dh: u64.rotrSH(Dh, Dl, 16), Dl: u64.rotrSL(Dh, Dl, 16) });
1445 ({ h: Ch, l: Cl } = u64.add(Ch, Cl, Dh, Dl));
1446 ({ Bh, Bl } = { Bh: Bh ^ Ch, Bl: Bl ^ Cl });
1447 ({ Bh, Bl } = { Bh: u64.rotrBH(Bh, Bl, 63), Bl: u64.rotrBL(Bh, Bl, 63) });
1448 (BUF[2 * a] = Al), (BUF[2 * a + 1] = Ah);
1449 (BUF[2 * b] = Bl), (BUF[2 * b + 1] = Bh);
1450 (BUF[2 * c] = Cl), (BUF[2 * c + 1] = Ch);
1451 (BUF[2 * d] = Dl), (BUF[2 * d + 1] = Dh);
1452 }
1453 class BLAKE2b extends BLAKE2 {
1454 constructor(opts = {}) {
1455 super(128, opts.dkLen === undefined ? 64 : opts.dkLen, opts, 64, 16, 16);
1456 this.v0l = IV$1[0] | 0;
1457 this.v0h = IV$1[1] | 0;
1458 this.v1l = IV$1[2] | 0;
1459 this.v1h = IV$1[3] | 0;
1460 this.v2l = IV$1[4] | 0;
1461 this.v2h = IV$1[5] | 0;
1462 this.v3l = IV$1[6] | 0;
1463 this.v3h = IV$1[7] | 0;
1464 this.v4l = IV$1[8] | 0;
1465 this.v4h = IV$1[9] | 0;
1466 this.v5l = IV$1[10] | 0;
1467 this.v5h = IV$1[11] | 0;
1468 this.v6l = IV$1[12] | 0;
1469 this.v6h = IV$1[13] | 0;
1470 this.v7l = IV$1[14] | 0;
1471 this.v7h = IV$1[15] | 0;
1472 const keyLength = opts.key ? opts.key.length : 0;
1473 this.v0l ^= this.outputLen | (keyLength << 8) | (0x01 << 16) | (0x01 << 24);
1474 if (opts.salt) {
1475 const salt = u32(toBytes(opts.salt));
1476 this.v4l ^= salt[0];
1477 this.v4h ^= salt[1];
1478 this.v5l ^= salt[2];
1479 this.v5h ^= salt[3];
1480 }
1481 if (opts.personalization) {
1482 const pers = u32(toBytes(opts.personalization));
1483 this.v6l ^= pers[0];
1484 this.v6h ^= pers[1];
1485 this.v7l ^= pers[2];
1486 this.v7h ^= pers[3];
1487 }
1488 if (opts.key) {
1489 const tmp = new Uint8Array(this.blockLen);
1490 tmp.set(toBytes(opts.key));
1491 this.update(tmp);
1492 }
1493 }
1494 get() {
1495 let { v0l, v0h, v1l, v1h, v2l, v2h, v3l, v3h, v4l, v4h, v5l, v5h, v6l, v6h, v7l, v7h } = this;
1496 return [v0l, v0h, v1l, v1h, v2l, v2h, v3l, v3h, v4l, v4h, v5l, v5h, v6l, v6h, v7l, v7h];
1497 }
1498 set(v0l, v0h, v1l, v1h, v2l, v2h, v3l, v3h, v4l, v4h, v5l, v5h, v6l, v6h, v7l, v7h) {
1499 this.v0l = v0l | 0;
1500 this.v0h = v0h | 0;
1501 this.v1l = v1l | 0;
1502 this.v1h = v1h | 0;
1503 this.v2l = v2l | 0;
1504 this.v2h = v2h | 0;
1505 this.v3l = v3l | 0;
1506 this.v3h = v3h | 0;
1507 this.v4l = v4l | 0;
1508 this.v4h = v4h | 0;
1509 this.v5l = v5l | 0;
1510 this.v5h = v5h | 0;
1511 this.v6l = v6l | 0;
1512 this.v6h = v6h | 0;
1513 this.v7l = v7l | 0;
1514 this.v7h = v7h | 0;
1515 }
1516 compress(msg, offset, isLast) {
1517 this.get().forEach((v, i) => (BUF[i] = v));
1518 BUF.set(IV$1, 16);
1519 let { h, l } = u64.fromBig(BigInt(this.length));
1520 BUF[24] = IV$1[8] ^ l;
1521 BUF[25] = IV$1[9] ^ h;
1522 if (isLast) {
1523 BUF[28] = ~BUF[28];
1524 BUF[29] = ~BUF[29];
1525 }
1526 let j = 0;
1527 const s = SIGMA;
1528 for (let i = 0; i < 12; i++) {
1529 G1(0, 4, 8, 12, msg, offset + 2 * s[j++]);
1530 G2(0, 4, 8, 12, msg, offset + 2 * s[j++]);
1531 G1(1, 5, 9, 13, msg, offset + 2 * s[j++]);
1532 G2(1, 5, 9, 13, msg, offset + 2 * s[j++]);
1533 G1(2, 6, 10, 14, msg, offset + 2 * s[j++]);
1534 G2(2, 6, 10, 14, msg, offset + 2 * s[j++]);
1535 G1(3, 7, 11, 15, msg, offset + 2 * s[j++]);
1536 G2(3, 7, 11, 15, msg, offset + 2 * s[j++]);
1537 G1(0, 5, 10, 15, msg, offset + 2 * s[j++]);
1538 G2(0, 5, 10, 15, msg, offset + 2 * s[j++]);
1539 G1(1, 6, 11, 12, msg, offset + 2 * s[j++]);
1540 G2(1, 6, 11, 12, msg, offset + 2 * s[j++]);
1541 G1(2, 7, 8, 13, msg, offset + 2 * s[j++]);
1542 G2(2, 7, 8, 13, msg, offset + 2 * s[j++]);
1543 G1(3, 4, 9, 14, msg, offset + 2 * s[j++]);
1544 G2(3, 4, 9, 14, msg, offset + 2 * s[j++]);
1545 }
1546 this.v0l ^= BUF[0] ^ BUF[16];
1547 this.v0h ^= BUF[1] ^ BUF[17];
1548 this.v1l ^= BUF[2] ^ BUF[18];
1549 this.v1h ^= BUF[3] ^ BUF[19];
1550 this.v2l ^= BUF[4] ^ BUF[20];
1551 this.v2h ^= BUF[5] ^ BUF[21];
1552 this.v3l ^= BUF[6] ^ BUF[22];
1553 this.v3h ^= BUF[7] ^ BUF[23];
1554 this.v4l ^= BUF[8] ^ BUF[24];
1555 this.v4h ^= BUF[9] ^ BUF[25];
1556 this.v5l ^= BUF[10] ^ BUF[26];
1557 this.v5h ^= BUF[11] ^ BUF[27];
1558 this.v6l ^= BUF[12] ^ BUF[28];
1559 this.v6h ^= BUF[13] ^ BUF[29];
1560 this.v7l ^= BUF[14] ^ BUF[30];
1561 this.v7h ^= BUF[15] ^ BUF[31];
1562 BUF.fill(0);
1563 }
1564 destroy() {
1565 this.destroyed = true;
1566 this.buffer32.fill(0);
1567 this.set(0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0);
1568 }
1569 }
1570 const blake2b = wrapConstructorWithOpts((opts) => new BLAKE2b(opts));
1571
1572 function createAsHex(fn) {
1573 return (...args) => util.u8aToHex(fn(...args));
1574 }
1575 function createBitHasher(bitLength, fn) {
1576 return (data, onlyJs) => fn(data, bitLength, onlyJs);
1577 }
1578 function createDualHasher(wa, js) {
1579 return (value, bitLength = 256, onlyJs) => {
1580 const u8a = util.u8aToU8a(value);
1581 return !util.hasBigInt || (!onlyJs && isReady())
1582 ? wa[bitLength](u8a)
1583 : js[bitLength](u8a);
1584 };
1585 }
1586
1587 function blake2AsU8a(data, bitLength = 256, key, onlyJs) {
1588 const byteLength = Math.ceil(bitLength / 8);
1589 const u8a = util.u8aToU8a(data);
1590 return !util.hasBigInt || (!onlyJs && isReady())
1591 ? blake2b$1(u8a, util.u8aToU8a(key), byteLength)
1592 : key
1593 ? blake2b(u8a, { dkLen: byteLength, key })
1594 : blake2b(u8a, { dkLen: byteLength });
1595 }
1596 const blake2AsHex = createAsHex(blake2AsU8a);
1597
1598 const SS58_PREFIX = util.stringToU8a('SS58PRE');
1599 function sshash(key) {
1600 return blake2AsU8a(util.u8aConcat(SS58_PREFIX, key), 512);
1601 }
1602
1603 function checkAddressChecksum(decoded) {
1604 const ss58Length = (decoded[0] & 64) ? 2 : 1;
1605 const ss58Decoded = ss58Length === 1
1606 ? decoded[0]
1607 : ((decoded[0] & 63) << 2) | (decoded[1] >> 6) | ((decoded[1] & 63) << 8);
1608 const isPublicKey = [34 + ss58Length, 35 + ss58Length].includes(decoded.length);
1609 const length = decoded.length - (isPublicKey ? 2 : 1);
1610 const hash = sshash(decoded.subarray(0, length));
1611 const isValid = (decoded[0] & 128) === 0 && ![46, 47].includes(decoded[0]) && (isPublicKey
1612 ? decoded[decoded.length - 2] === hash[0] && decoded[decoded.length - 1] === hash[1]
1613 : decoded[decoded.length - 1] === hash[0]);
1614 return [isValid, length, ss58Length, ss58Decoded];
1615 }
1616
1617 const knownSubstrate = [
1618 {
1619 "prefix": 0,
1620 "network": "polkadot",
1621 "displayName": "Polkadot Relay Chain",
1622 "symbols": [
1623 "DOT"
1624 ],
1625 "decimals": [
1626 10
1627 ],
1628 "standardAccount": "*25519",
1629 "website": "https://polkadot.network"
1630 },
1631 {
1632 "prefix": 1,
1633 "network": "BareSr25519",
1634 "displayName": "Bare 32-bit Schnorr/Ristretto (S/R 25519) public key.",
1635 "symbols": [],
1636 "decimals": [],
1637 "standardAccount": "Sr25519",
1638 "website": null
1639 },
1640 {
1641 "prefix": 2,
1642 "network": "kusama",
1643 "displayName": "Kusama Relay Chain",
1644 "symbols": [
1645 "KSM"
1646 ],
1647 "decimals": [
1648 12
1649 ],
1650 "standardAccount": "*25519",
1651 "website": "https://kusama.network"
1652 },
1653 {
1654 "prefix": 3,
1655 "network": "BareEd25519",
1656 "displayName": "Bare 32-bit Ed25519 public key.",
1657 "symbols": [],
1658 "decimals": [],
1659 "standardAccount": "Ed25519",
1660 "website": null
1661 },
1662 {
1663 "prefix": 4,
1664 "network": "katalchain",
1665 "displayName": "Katal Chain",
1666 "symbols": [],
1667 "decimals": [],
1668 "standardAccount": "*25519",
1669 "website": null
1670 },
1671 {
1672 "prefix": 5,
1673 "network": "astar",
1674 "displayName": "Astar Network",
1675 "symbols": [
1676 "ASTR"
1677 ],
1678 "decimals": [
1679 18
1680 ],
1681 "standardAccount": "*25519",
1682 "website": "https://astar.network"
1683 },
1684 {
1685 "prefix": 6,
1686 "network": "bifrost",
1687 "displayName": "Bifrost",
1688 "symbols": [
1689 "BNC"
1690 ],
1691 "decimals": [
1692 12
1693 ],
1694 "standardAccount": "*25519",
1695 "website": "https://bifrost.finance/"
1696 },
1697 {
1698 "prefix": 7,
1699 "network": "edgeware",
1700 "displayName": "Edgeware",
1701 "symbols": [
1702 "EDG"
1703 ],
1704 "decimals": [
1705 18
1706 ],
1707 "standardAccount": "*25519",
1708 "website": "https://edgewa.re"
1709 },
1710 {
1711 "prefix": 8,
1712 "network": "karura",
1713 "displayName": "Karura",
1714 "symbols": [
1715 "KAR"
1716 ],
1717 "decimals": [
1718 12
1719 ],
1720 "standardAccount": "*25519",
1721 "website": "https://karura.network/"
1722 },
1723 {
1724 "prefix": 9,
1725 "network": "reynolds",
1726 "displayName": "Laminar Reynolds Canary",
1727 "symbols": [
1728 "REY"
1729 ],
1730 "decimals": [
1731 18
1732 ],
1733 "standardAccount": "*25519",
1734 "website": "http://laminar.network/"
1735 },
1736 {
1737 "prefix": 10,
1738 "network": "acala",
1739 "displayName": "Acala",
1740 "symbols": [
1741 "ACA"
1742 ],
1743 "decimals": [
1744 12
1745 ],
1746 "standardAccount": "*25519",
1747 "website": "https://acala.network/"
1748 },
1749 {
1750 "prefix": 11,
1751 "network": "laminar",
1752 "displayName": "Laminar",
1753 "symbols": [
1754 "LAMI"
1755 ],
1756 "decimals": [
1757 18
1758 ],
1759 "standardAccount": "*25519",
1760 "website": "http://laminar.network/"
1761 },
1762 {
1763 "prefix": 12,
1764 "network": "polymesh",
1765 "displayName": "Polymesh",
1766 "symbols": [
1767 "POLYX"
1768 ],
1769 "decimals": [
1770 6
1771 ],
1772 "standardAccount": "*25519",
1773 "website": "https://polymath.network/"
1774 },
1775 {
1776 "prefix": 13,
1777 "network": "integritee",
1778 "displayName": "Integritee",
1779 "symbols": [
1780 "TEER"
1781 ],
1782 "decimals": [
1783 12
1784 ],
1785 "standardAccount": "*25519",
1786 "website": "https://integritee.network"
1787 },
1788 {
1789 "prefix": 14,
1790 "network": "totem",
1791 "displayName": "Totem",
1792 "symbols": [
1793 "TOTEM"
1794 ],
1795 "decimals": [
1796 0
1797 ],
1798 "standardAccount": "*25519",
1799 "website": "https://totemaccounting.com"
1800 },
1801 {
1802 "prefix": 15,
1803 "network": "synesthesia",
1804 "displayName": "Synesthesia",
1805 "symbols": [
1806 "SYN"
1807 ],
1808 "decimals": [
1809 12
1810 ],
1811 "standardAccount": "*25519",
1812 "website": "https://synesthesia.network/"
1813 },
1814 {
1815 "prefix": 16,
1816 "network": "kulupu",
1817 "displayName": "Kulupu",
1818 "symbols": [
1819 "KLP"
1820 ],
1821 "decimals": [
1822 12
1823 ],
1824 "standardAccount": "*25519",
1825 "website": "https://kulupu.network/"
1826 },
1827 {
1828 "prefix": 17,
1829 "network": "dark",
1830 "displayName": "Dark Mainnet",
1831 "symbols": [],
1832 "decimals": [],
1833 "standardAccount": "*25519",
1834 "website": null
1835 },
1836 {
1837 "prefix": 18,
1838 "network": "darwinia",
1839 "displayName": "Darwinia Network",
1840 "symbols": [
1841 "RING",
1842 "KTON"
1843 ],
1844 "decimals": [
1845 9,
1846 9
1847 ],
1848 "standardAccount": "*25519",
1849 "website": "https://darwinia.network/"
1850 },
1851 {
1852 "prefix": 19,
1853 "network": "watr",
1854 "displayName": "Watr Protocol",
1855 "symbols": [
1856 "WATR"
1857 ],
1858 "decimals": [
1859 18
1860 ],
1861 "standardAccount": "*25519",
1862 "website": "https://www.watr.org"
1863 },
1864 {
1865 "prefix": 20,
1866 "network": "stafi",
1867 "displayName": "Stafi",
1868 "symbols": [
1869 "FIS"
1870 ],
1871 "decimals": [
1872 12
1873 ],
1874 "standardAccount": "*25519",
1875 "website": "https://stafi.io"
1876 },
1877 {
1878 "prefix": 22,
1879 "network": "dock-pos-mainnet",
1880 "displayName": "Dock Mainnet",
1881 "symbols": [
1882 "DCK"
1883 ],
1884 "decimals": [
1885 6
1886 ],
1887 "standardAccount": "*25519",
1888 "website": "https://dock.io"
1889 },
1890 {
1891 "prefix": 23,
1892 "network": "shift",
1893 "displayName": "ShiftNrg",
1894 "symbols": [],
1895 "decimals": [],
1896 "standardAccount": "*25519",
1897 "website": null
1898 },
1899 {
1900 "prefix": 24,
1901 "network": "zero",
1902 "displayName": "ZERO",
1903 "symbols": [
1904 "ZERO"
1905 ],
1906 "decimals": [
1907 18
1908 ],
1909 "standardAccount": "*25519",
1910 "website": "https://zero.io"
1911 },
1912 {
1913 "prefix": 25,
1914 "network": "zero-alphaville",
1915 "displayName": "ZERO Alphaville",
1916 "symbols": [
1917 "ZERO"
1918 ],
1919 "decimals": [
1920 18
1921 ],
1922 "standardAccount": "*25519",
1923 "website": "https://zero.io"
1924 },
1925 {
1926 "prefix": 26,
1927 "network": "jupiter",
1928 "displayName": "Jupiter",
1929 "symbols": [
1930 "jDOT"
1931 ],
1932 "decimals": [
1933 10
1934 ],
1935 "standardAccount": "*25519",
1936 "website": "https://jupiter.patract.io"
1937 },
1938 {
1939 "prefix": 27,
1940 "network": "kabocha",
1941 "displayName": "Kabocha",
1942 "symbols": [
1943 "KAB"
1944 ],
1945 "decimals": [
1946 12
1947 ],
1948 "standardAccount": "*25519",
1949 "website": "https://kabocha.network"
1950 },
1951 {
1952 "prefix": 28,
1953 "network": "subsocial",
1954 "displayName": "Subsocial",
1955 "symbols": [],
1956 "decimals": [],
1957 "standardAccount": "*25519",
1958 "website": null
1959 },
1960 {
1961 "prefix": 29,
1962 "network": "cord",
1963 "displayName": "CORD Network",
1964 "symbols": [
1965 "DHI",
1966 "WAY"
1967 ],
1968 "decimals": [
1969 12,
1970 12
1971 ],
1972 "standardAccount": "*25519",
1973 "website": "https://cord.network/"
1974 },
1975 {
1976 "prefix": 30,
1977 "network": "phala",
1978 "displayName": "Phala Network",
1979 "symbols": [
1980 "PHA"
1981 ],
1982 "decimals": [
1983 12
1984 ],
1985 "standardAccount": "*25519",
1986 "website": "https://phala.network"
1987 },
1988 {
1989 "prefix": 31,
1990 "network": "litentry",
1991 "displayName": "Litentry Network",
1992 "symbols": [
1993 "LIT"
1994 ],
1995 "decimals": [
1996 12
1997 ],
1998 "standardAccount": "*25519",
1999 "website": "https://litentry.com/"
2000 },
2001 {
2002 "prefix": 32,
2003 "network": "robonomics",
2004 "displayName": "Robonomics",
2005 "symbols": [
2006 "XRT"
2007 ],
2008 "decimals": [
2009 9
2010 ],
2011 "standardAccount": "*25519",
2012 "website": "https://robonomics.network"
2013 },
2014 {
2015 "prefix": 33,
2016 "network": "datahighway",
2017 "displayName": "DataHighway",
2018 "symbols": [],
2019 "decimals": [],
2020 "standardAccount": "*25519",
2021 "website": null
2022 },
2023 {
2024 "prefix": 34,
2025 "network": "ares",
2026 "displayName": "Ares Protocol",
2027 "symbols": [
2028 "ARES"
2029 ],
2030 "decimals": [
2031 12
2032 ],
2033 "standardAccount": "*25519",
2034 "website": "https://www.aresprotocol.com/"
2035 },
2036 {
2037 "prefix": 35,
2038 "network": "vln",
2039 "displayName": "Valiu Liquidity Network",
2040 "symbols": [
2041 "USDv"
2042 ],
2043 "decimals": [
2044 15
2045 ],
2046 "standardAccount": "*25519",
2047 "website": "https://valiu.com/"
2048 },
2049 {
2050 "prefix": 36,
2051 "network": "centrifuge",
2052 "displayName": "Centrifuge Chain",
2053 "symbols": [
2054 "CFG"
2055 ],
2056 "decimals": [
2057 18
2058 ],
2059 "standardAccount": "*25519",
2060 "website": "https://centrifuge.io/"
2061 },
2062 {
2063 "prefix": 37,
2064 "network": "nodle",
2065 "displayName": "Nodle Chain",
2066 "symbols": [
2067 "NODL"
2068 ],
2069 "decimals": [
2070 11
2071 ],
2072 "standardAccount": "*25519",
2073 "website": "https://nodle.io/"
2074 },
2075 {
2076 "prefix": 38,
2077 "network": "kilt",
2078 "displayName": "KILT Spiritnet",
2079 "symbols": [
2080 "KILT"
2081 ],
2082 "decimals": [
2083 15
2084 ],
2085 "standardAccount": "*25519",
2086 "website": "https://kilt.io/"
2087 },
2088 {
2089 "prefix": 39,
2090 "network": "mathchain",
2091 "displayName": "MathChain mainnet",
2092 "symbols": [
2093 "MATH"
2094 ],
2095 "decimals": [
2096 18
2097 ],
2098 "standardAccount": "*25519",
2099 "website": "https://mathwallet.org"
2100 },
2101 {
2102 "prefix": 40,
2103 "network": "mathchain-testnet",
2104 "displayName": "MathChain testnet",
2105 "symbols": [
2106 "MATH"
2107 ],
2108 "decimals": [
2109 18
2110 ],
2111 "standardAccount": "*25519",
2112 "website": "https://mathwallet.org"
2113 },
2114 {
2115 "prefix": 41,
2116 "network": "poli",
2117 "displayName": "Polimec Chain",
2118 "symbols": [],
2119 "decimals": [],
2120 "standardAccount": "*25519",
2121 "website": "https://polimec.io/"
2122 },
2123 {
2124 "prefix": 42,
2125 "network": "substrate",
2126 "displayName": "Substrate",
2127 "symbols": [],
2128 "decimals": [],
2129 "standardAccount": "*25519",
2130 "website": "https://substrate.io/"
2131 },
2132 {
2133 "prefix": 43,
2134 "network": "BareSecp256k1",
2135 "displayName": "Bare 32-bit ECDSA SECP-256k1 public key.",
2136 "symbols": [],
2137 "decimals": [],
2138 "standardAccount": "secp256k1",
2139 "website": null
2140 },
2141 {
2142 "prefix": 44,
2143 "network": "chainx",
2144 "displayName": "ChainX",
2145 "symbols": [
2146 "PCX"
2147 ],
2148 "decimals": [
2149 8
2150 ],
2151 "standardAccount": "*25519",
2152 "website": "https://chainx.org/"
2153 },
2154 {
2155 "prefix": 45,
2156 "network": "uniarts",
2157 "displayName": "UniArts Network",
2158 "symbols": [
2159 "UART",
2160 "UINK"
2161 ],
2162 "decimals": [
2163 12,
2164 12
2165 ],
2166 "standardAccount": "*25519",
2167 "website": "https://uniarts.me"
2168 },
2169 {
2170 "prefix": 46,
2171 "network": "reserved46",
2172 "displayName": "This prefix is reserved.",
2173 "symbols": [],
2174 "decimals": [],
2175 "standardAccount": null,
2176 "website": null
2177 },
2178 {
2179 "prefix": 47,
2180 "network": "reserved47",
2181 "displayName": "This prefix is reserved.",
2182 "symbols": [],
2183 "decimals": [],
2184 "standardAccount": null,
2185 "website": null
2186 },
2187 {
2188 "prefix": 48,
2189 "network": "neatcoin",
2190 "displayName": "Neatcoin Mainnet",
2191 "symbols": [
2192 "NEAT"
2193 ],
2194 "decimals": [
2195 12
2196 ],
2197 "standardAccount": "*25519",
2198 "website": "https://neatcoin.org"
2199 },
2200 {
2201 "prefix": 49,
2202 "network": "picasso",
2203 "displayName": "Picasso",
2204 "symbols": [
2205 "PICA"
2206 ],
2207 "decimals": [
2208 12
2209 ],
2210 "standardAccount": "*25519",
2211 "website": "https://picasso.composable.finance"
2212 },
2213 {
2214 "prefix": 50,
2215 "network": "composable",
2216 "displayName": "Composable Finance",
2217 "symbols": [
2218 "LAYR"
2219 ],
2220 "decimals": [
2221 12
2222 ],
2223 "standardAccount": "*25519",
2224 "website": "https://composable.finance"
2225 },
2226 {
2227 "prefix": 51,
2228 "network": "oak",
2229 "displayName": "OAK Network",
2230 "symbols": [
2231 "OAK",
2232 "TUR"
2233 ],
2234 "decimals": [
2235 10,
2236 10
2237 ],
2238 "standardAccount": "*25519",
2239 "website": "https://oak.tech"
2240 },
2241 {
2242 "prefix": 52,
2243 "network": "KICO",
2244 "displayName": "KICO",
2245 "symbols": [
2246 "KICO"
2247 ],
2248 "decimals": [
2249 14
2250 ],
2251 "standardAccount": "*25519",
2252 "website": "https://dico.io"
2253 },
2254 {
2255 "prefix": 53,
2256 "network": "DICO",
2257 "displayName": "DICO",
2258 "symbols": [
2259 "DICO"
2260 ],
2261 "decimals": [
2262 14
2263 ],
2264 "standardAccount": "*25519",
2265 "website": "https://dico.io"
2266 },
2267 {
2268 "prefix": 54,
2269 "network": "cere",
2270 "displayName": "Cere Network",
2271 "symbols": [
2272 "CERE"
2273 ],
2274 "decimals": [
2275 10
2276 ],
2277 "standardAccount": "*25519",
2278 "website": "https://cere.network"
2279 },
2280 {
2281 "prefix": 55,
2282 "network": "xxnetwork",
2283 "displayName": "xx network",
2284 "symbols": [
2285 "XX"
2286 ],
2287 "decimals": [
2288 9
2289 ],
2290 "standardAccount": "*25519",
2291 "website": "https://xx.network"
2292 },
2293 {
2294 "prefix": 56,
2295 "network": "pendulum",
2296 "displayName": "Pendulum chain",
2297 "symbols": [
2298 "PEN"
2299 ],
2300 "decimals": [
2301 12
2302 ],
2303 "standardAccount": "*25519",
2304 "website": "https://pendulumchain.org/"
2305 },
2306 {
2307 "prefix": 57,
2308 "network": "amplitude",
2309 "displayName": "Amplitude chain",
2310 "symbols": [
2311 "AMPE"
2312 ],
2313 "decimals": [
2314 12
2315 ],
2316 "standardAccount": "*25519",
2317 "website": "https://pendulumchain.org/"
2318 },
2319 {
2320 "prefix": 63,
2321 "network": "hydradx",
2322 "displayName": "HydraDX",
2323 "symbols": [
2324 "HDX"
2325 ],
2326 "decimals": [
2327 12
2328 ],
2329 "standardAccount": "*25519",
2330 "website": "https://hydradx.io"
2331 },
2332 {
2333 "prefix": 65,
2334 "network": "aventus",
2335 "displayName": "Aventus Mainnet",
2336 "symbols": [
2337 "AVT"
2338 ],
2339 "decimals": [
2340 18
2341 ],
2342 "standardAccount": "*25519",
2343 "website": "https://aventus.io"
2344 },
2345 {
2346 "prefix": 66,
2347 "network": "crust",
2348 "displayName": "Crust Network",
2349 "symbols": [
2350 "CRU"
2351 ],
2352 "decimals": [
2353 12
2354 ],
2355 "standardAccount": "*25519",
2356 "website": "https://crust.network"
2357 },
2358 {
2359 "prefix": 67,
2360 "network": "genshiro",
2361 "displayName": "Genshiro Network",
2362 "symbols": [
2363 "GENS",
2364 "EQD",
2365 "LPT0"
2366 ],
2367 "decimals": [
2368 9,
2369 9,
2370 9
2371 ],
2372 "standardAccount": "*25519",
2373 "website": "https://genshiro.equilibrium.io"
2374 },
2375 {
2376 "prefix": 68,
2377 "network": "equilibrium",
2378 "displayName": "Equilibrium Network",
2379 "symbols": [
2380 "EQ"
2381 ],
2382 "decimals": [
2383 9
2384 ],
2385 "standardAccount": "*25519",
2386 "website": "https://equilibrium.io"
2387 },
2388 {
2389 "prefix": 69,
2390 "network": "sora",
2391 "displayName": "SORA Network",
2392 "symbols": [
2393 "XOR"
2394 ],
2395 "decimals": [
2396 18
2397 ],
2398 "standardAccount": "*25519",
2399 "website": "https://sora.org"
2400 },
2401 {
2402 "prefix": 71,
2403 "network": "p3d",
2404 "displayName": "3DP network",
2405 "symbols": [
2406 "P3D"
2407 ],
2408 "decimals": [
2409 12
2410 ],
2411 "standardAccount": "*25519",
2412 "website": "https://3dpass.org"
2413 },
2414 {
2415 "prefix": 72,
2416 "network": "p3dt",
2417 "displayName": "3DP test network",
2418 "symbols": [
2419 "P3Dt"
2420 ],
2421 "decimals": [
2422 12
2423 ],
2424 "standardAccount": "*25519",
2425 "website": "https://3dpass.org"
2426 },
2427 {
2428 "prefix": 73,
2429 "network": "zeitgeist",
2430 "displayName": "Zeitgeist",
2431 "symbols": [
2432 "ZTG"
2433 ],
2434 "decimals": [
2435 10
2436 ],
2437 "standardAccount": "*25519",
2438 "website": "https://zeitgeist.pm"
2439 },
2440 {
2441 "prefix": 77,
2442 "network": "manta",
2443 "displayName": "Manta network",
2444 "symbols": [
2445 "MANTA"
2446 ],
2447 "decimals": [
2448 18
2449 ],
2450 "standardAccount": "*25519",
2451 "website": "https://manta.network"
2452 },
2453 {
2454 "prefix": 78,
2455 "network": "calamari",
2456 "displayName": "Calamari: Manta Canary Network",
2457 "symbols": [
2458 "KMA"
2459 ],
2460 "decimals": [
2461 12
2462 ],
2463 "standardAccount": "*25519",
2464 "website": "https://manta.network"
2465 },
2466 {
2467 "prefix": 81,
2468 "network": "sora_dot_para",
2469 "displayName": "SORA Polkadot Parachain",
2470 "symbols": [
2471 "XOR"
2472 ],
2473 "decimals": [
2474 18
2475 ],
2476 "standardAccount": "*25519",
2477 "website": "https://sora.org"
2478 },
2479 {
2480 "prefix": 88,
2481 "network": "polkadex",
2482 "displayName": "Polkadex Mainnet",
2483 "symbols": [
2484 "PDEX"
2485 ],
2486 "decimals": [
2487 12
2488 ],
2489 "standardAccount": "*25519",
2490 "website": "https://polkadex.trade"
2491 },
2492 {
2493 "prefix": 89,
2494 "network": "polkadexparachain",
2495 "displayName": "Polkadex Parachain",
2496 "symbols": [
2497 "PDEX"
2498 ],
2499 "decimals": [
2500 12
2501 ],
2502 "standardAccount": "*25519",
2503 "website": "https://polkadex.trade"
2504 },
2505 {
2506 "prefix": 90,
2507 "network": "frequency",
2508 "displayName": "Frequency",
2509 "symbols": [
2510 "FRQCY"
2511 ],
2512 "decimals": [
2513 8
2514 ],
2515 "standardAccount": "*25519",
2516 "website": "https://www.frequency.xyz"
2517 },
2518 {
2519 "prefix": 92,
2520 "network": "anmol",
2521 "displayName": "Anmol Network",
2522 "symbols": [
2523 "ANML"
2524 ],
2525 "decimals": [
2526 18
2527 ],
2528 "standardAccount": "*25519",
2529 "website": "https://anmol.network/"
2530 },
2531 {
2532 "prefix": 93,
2533 "network": "fragnova",
2534 "displayName": "Fragnova Network",
2535 "symbols": [
2536 "NOVA"
2537 ],
2538 "decimals": [
2539 12
2540 ],
2541 "standardAccount": "*25519",
2542 "website": "https://fragnova.com"
2543 },
2544 {
2545 "prefix": 98,
2546 "network": "polkasmith",
2547 "displayName": "PolkaSmith Canary Network",
2548 "symbols": [
2549 "PKS"
2550 ],
2551 "decimals": [
2552 18
2553 ],
2554 "standardAccount": "*25519",
2555 "website": "https://polkafoundry.com"
2556 },
2557 {
2558 "prefix": 99,
2559 "network": "polkafoundry",
2560 "displayName": "PolkaFoundry Network",
2561 "symbols": [
2562 "PKF"
2563 ],
2564 "decimals": [
2565 18
2566 ],
2567 "standardAccount": "*25519",
2568 "website": "https://polkafoundry.com"
2569 },
2570 {
2571 "prefix": 100,
2572 "network": "ibtida",
2573 "displayName": "Anmol Network Ibtida Canary network",
2574 "symbols": [
2575 "IANML"
2576 ],
2577 "decimals": [
2578 18
2579 ],
2580 "standardAccount": "*25519",
2581 "website": "https://anmol.network/"
2582 },
2583 {
2584 "prefix": 101,
2585 "network": "origintrail-parachain",
2586 "displayName": "OriginTrail Parachain",
2587 "symbols": [
2588 "OTP"
2589 ],
2590 "decimals": [
2591 12
2592 ],
2593 "standardAccount": "*25519",
2594 "website": "https://parachain.origintrail.io/"
2595 },
2596 {
2597 "prefix": 105,
2598 "network": "pontem-network",
2599 "displayName": "Pontem Network",
2600 "symbols": [
2601 "PONT"
2602 ],
2603 "decimals": [
2604 10
2605 ],
2606 "standardAccount": "*25519",
2607 "website": "https://pontem.network"
2608 },
2609 {
2610 "prefix": 110,
2611 "network": "heiko",
2612 "displayName": "Heiko",
2613 "symbols": [
2614 "HKO"
2615 ],
2616 "decimals": [
2617 12
2618 ],
2619 "standardAccount": "*25519",
2620 "website": "https://parallel.fi/"
2621 },
2622 {
2623 "prefix": 113,
2624 "network": "integritee-incognito",
2625 "displayName": "Integritee Incognito",
2626 "symbols": [],
2627 "decimals": [],
2628 "standardAccount": "*25519",
2629 "website": "https://integritee.network"
2630 },
2631 {
2632 "prefix": 117,
2633 "network": "tinker",
2634 "displayName": "Tinker",
2635 "symbols": [
2636 "TNKR"
2637 ],
2638 "decimals": [
2639 12
2640 ],
2641 "standardAccount": "*25519",
2642 "website": "https://invarch.network"
2643 },
2644 {
2645 "prefix": 126,
2646 "network": "joystream",
2647 "displayName": "Joystream",
2648 "symbols": [
2649 "JOY"
2650 ],
2651 "decimals": [
2652 10
2653 ],
2654 "standardAccount": "*25519",
2655 "website": "https://www.joystream.org"
2656 },
2657 {
2658 "prefix": 128,
2659 "network": "clover",
2660 "displayName": "Clover Finance",
2661 "symbols": [
2662 "CLV"
2663 ],
2664 "decimals": [
2665 18
2666 ],
2667 "standardAccount": "*25519",
2668 "website": "https://clover.finance"
2669 },
2670 {
2671 "prefix": 129,
2672 "network": "dorafactory-polkadot",
2673 "displayName": "Dorafactory Polkadot Network",
2674 "symbols": [
2675 "DORA"
2676 ],
2677 "decimals": [
2678 12
2679 ],
2680 "standardAccount": "*25519",
2681 "website": "https://dorafactory.org"
2682 },
2683 {
2684 "prefix": 131,
2685 "network": "litmus",
2686 "displayName": "Litmus Network",
2687 "symbols": [
2688 "LIT"
2689 ],
2690 "decimals": [
2691 12
2692 ],
2693 "standardAccount": "*25519",
2694 "website": "https://litentry.com/"
2695 },
2696 {
2697 "prefix": 136,
2698 "network": "altair",
2699 "displayName": "Altair",
2700 "symbols": [
2701 "AIR"
2702 ],
2703 "decimals": [
2704 18
2705 ],
2706 "standardAccount": "*25519",
2707 "website": "https://centrifuge.io/"
2708 },
2709 {
2710 "prefix": 137,
2711 "network": "vara",
2712 "displayName": "Vara Network",
2713 "symbols": [
2714 "VARA"
2715 ],
2716 "decimals": [
2717 12
2718 ],
2719 "standardAccount": "*25519",
2720 "website": "https://vara-network.io/"
2721 },
2722 {
2723 "prefix": 172,
2724 "network": "parallel",
2725 "displayName": "Parallel",
2726 "symbols": [
2727 "PARA"
2728 ],
2729 "decimals": [
2730 12
2731 ],
2732 "standardAccount": "*25519",
2733 "website": "https://parallel.fi/"
2734 },
2735 {
2736 "prefix": 252,
2737 "network": "social-network",
2738 "displayName": "Social Network",
2739 "symbols": [
2740 "NET"
2741 ],
2742 "decimals": [
2743 18
2744 ],
2745 "standardAccount": "*25519",
2746 "website": "https://social.network"
2747 },
2748 {
2749 "prefix": 255,
2750 "network": "quartz_mainnet",
2751 "displayName": "QUARTZ by UNIQUE",
2752 "symbols": [
2753 "QTZ"
2754 ],
2755 "decimals": [
2756 18
2757 ],
2758 "standardAccount": "*25519",
2759 "website": "https://unique.network"
2760 },
2761 {
2762 "prefix": 268,
2763 "network": "pioneer_network",
2764 "displayName": "Pioneer Network by Bit.Country",
2765 "symbols": [
2766 "NEER"
2767 ],
2768 "decimals": [
2769 18
2770 ],
2771 "standardAccount": "*25519",
2772 "website": "https://bit.country"
2773 },
2774 {
2775 "prefix": 420,
2776 "network": "sora_kusama_para",
2777 "displayName": "SORA Kusama Parachain",
2778 "symbols": [
2779 "XOR"
2780 ],
2781 "decimals": [
2782 18
2783 ],
2784 "standardAccount": "*25519",
2785 "website": "https://sora.org"
2786 },
2787 {
2788 "prefix": 789,
2789 "network": "geek",
2790 "displayName": "GEEK Network",
2791 "symbols": [
2792 "GEEK"
2793 ],
2794 "decimals": [
2795 18
2796 ],
2797 "standardAccount": "*25519",
2798 "website": "https://geek.gl"
2799 },
2800 {
2801 "prefix": 995,
2802 "network": "ternoa",
2803 "displayName": "Ternoa",
2804 "symbols": [
2805 "CAPS"
2806 ],
2807 "decimals": [
2808 18
2809 ],
2810 "standardAccount": "*25519",
2811 "website": "https://www.ternoa.network"
2812 },
2813 {
2814 "prefix": 1110,
2815 "network": "efinity",
2816 "displayName": "Efinity",
2817 "symbols": [
2818 "EFI"
2819 ],
2820 "decimals": [
2821 18
2822 ],
2823 "standardAccount": "*25519",
2824 "website": "https://efinity.io/"
2825 },
2826 {
2827 "prefix": 1221,
2828 "network": "peaq",
2829 "displayName": "Peaq Network",
2830 "symbols": [
2831 "PEAQ"
2832 ],
2833 "decimals": [
2834 18
2835 ],
2836 "standardAccount": "Sr25519",
2837 "website": "https://www.peaq.network/"
2838 },
2839 {
2840 "prefix": 1222,
2841 "network": "krest",
2842 "displayName": "Krest Network",
2843 "symbols": [
2844 "KREST"
2845 ],
2846 "decimals": [
2847 18
2848 ],
2849 "standardAccount": "Sr25519",
2850 "website": "https://www.peaq.network/"
2851 },
2852 {
2853 "prefix": 1284,
2854 "network": "moonbeam",
2855 "displayName": "Moonbeam",
2856 "symbols": [
2857 "GLMR"
2858 ],
2859 "decimals": [
2860 18
2861 ],
2862 "standardAccount": "secp256k1",
2863 "website": "https://moonbeam.network"
2864 },
2865 {
2866 "prefix": 1285,
2867 "network": "moonriver",
2868 "displayName": "Moonriver",
2869 "symbols": [
2870 "MOVR"
2871 ],
2872 "decimals": [
2873 18
2874 ],
2875 "standardAccount": "secp256k1",
2876 "website": "https://moonbeam.network"
2877 },
2878 {
2879 "prefix": 1328,
2880 "network": "ajuna",
2881 "displayName": "Ajuna Network",
2882 "symbols": [
2883 "AJUN"
2884 ],
2885 "decimals": [
2886 12
2887 ],
2888 "standardAccount": "*25519",
2889 "website": "https://ajuna.io"
2890 },
2891 {
2892 "prefix": 1337,
2893 "network": "bajun",
2894 "displayName": "Bajun Network",
2895 "symbols": [
2896 "BAJU"
2897 ],
2898 "decimals": [
2899 12
2900 ],
2901 "standardAccount": "*25519",
2902 "website": "https://ajuna.io"
2903 },
2904 {
2905 "prefix": 1516,
2906 "network": "societal",
2907 "displayName": "Societal",
2908 "symbols": [
2909 "SCTL"
2910 ],
2911 "decimals": [
2912 12
2913 ],
2914 "standardAccount": "*25519",
2915 "website": "https://www.sctl.xyz"
2916 },
2917 {
2918 "prefix": 1985,
2919 "network": "seals",
2920 "displayName": "Seals Network",
2921 "symbols": [
2922 "SEAL"
2923 ],
2924 "decimals": [
2925 9
2926 ],
2927 "standardAccount": "*25519",
2928 "website": "https://seals.app"
2929 },
2930 {
2931 "prefix": 2007,
2932 "network": "kapex",
2933 "displayName": "Kapex",
2934 "symbols": [
2935 "KAPEX"
2936 ],
2937 "decimals": [
2938 12
2939 ],
2940 "standardAccount": "*25519",
2941 "website": "https://totemaccounting.com"
2942 },
2943 {
2944 "prefix": 2009,
2945 "network": "cloudwalk_mainnet",
2946 "displayName": "CloudWalk Network Mainnet",
2947 "symbols": [
2948 "CWN"
2949 ],
2950 "decimals": [
2951 18
2952 ],
2953 "standardAccount": "*25519",
2954 "website": "https://explorer.mainnet.cloudwalk.io"
2955 },
2956 {
2957 "prefix": 2021,
2958 "network": "logion",
2959 "displayName": "logion network",
2960 "symbols": [
2961 "LGNT"
2962 ],
2963 "decimals": [
2964 18
2965 ],
2966 "standardAccount": "*25519",
2967 "website": "https://logion.network"
2968 },
2969 {
2970 "prefix": 2032,
2971 "network": "interlay",
2972 "displayName": "Interlay",
2973 "symbols": [
2974 "INTR"
2975 ],
2976 "decimals": [
2977 10
2978 ],
2979 "standardAccount": "*25519",
2980 "website": "https://interlay.io/"
2981 },
2982 {
2983 "prefix": 2092,
2984 "network": "kintsugi",
2985 "displayName": "Kintsugi",
2986 "symbols": [
2987 "KINT"
2988 ],
2989 "decimals": [
2990 12
2991 ],
2992 "standardAccount": "*25519",
2993 "website": "https://interlay.io/"
2994 },
2995 {
2996 "prefix": 2106,
2997 "network": "bitgreen",
2998 "displayName": "Bitgreen",
2999 "symbols": [
3000 "BBB"
3001 ],
3002 "decimals": [
3003 18
3004 ],
3005 "standardAccount": "*25519",
3006 "website": "https://bitgreen.org/"
3007 },
3008 {
3009 "prefix": 2112,
3010 "network": "chainflip",
3011 "displayName": "Chainflip",
3012 "symbols": [
3013 "FLIP"
3014 ],
3015 "decimals": [
3016 18
3017 ],
3018 "standardAccount": "*25519",
3019 "website": "https://chainflip.io/"
3020 },
3021 {
3022 "prefix": 2206,
3023 "network": "ICE",
3024 "displayName": "ICE Network",
3025 "symbols": [
3026 "ICY"
3027 ],
3028 "decimals": [
3029 18
3030 ],
3031 "standardAccount": "*25519",
3032 "website": "https://icenetwork.io"
3033 },
3034 {
3035 "prefix": 2207,
3036 "network": "SNOW",
3037 "displayName": "SNOW: ICE Canary Network",
3038 "symbols": [
3039 "ICZ"
3040 ],
3041 "decimals": [
3042 18
3043 ],
3044 "standardAccount": "*25519",
3045 "website": "https://icenetwork.io"
3046 },
3047 {
3048 "prefix": 2254,
3049 "network": "subspace_testnet",
3050 "displayName": "Subspace testnet",
3051 "symbols": [
3052 "tSSC"
3053 ],
3054 "decimals": [
3055 18
3056 ],
3057 "standardAccount": "*25519",
3058 "website": "https://subspace.network"
3059 },
3060 {
3061 "prefix": 4006,
3062 "network": "tangle",
3063 "displayName": "Tangle Network",
3064 "symbols": [
3065 "TNT"
3066 ],
3067 "decimals": [
3068 18
3069 ],
3070 "standardAccount": "*25519",
3071 "website": "https://www.webb.tools/"
3072 },
3073 {
3074 "prefix": 4450,
3075 "network": "g1",
3076 "displayName": "Ğ1",
3077 "symbols": [
3078 "G1"
3079 ],
3080 "decimals": [
3081 2
3082 ],
3083 "standardAccount": "*25519",
3084 "website": "https://duniter.org"
3085 },
3086 {
3087 "prefix": 5234,
3088 "network": "humanode",
3089 "displayName": "Humanode Network",
3090 "symbols": [
3091 "HMND"
3092 ],
3093 "decimals": [
3094 18
3095 ],
3096 "standardAccount": "*25519",
3097 "website": "https://humanode.io"
3098 },
3099 {
3100 "prefix": 6094,
3101 "network": "subspace",
3102 "displayName": "Subspace",
3103 "symbols": [
3104 "SSC"
3105 ],
3106 "decimals": [
3107 18
3108 ],
3109 "standardAccount": "*25519",
3110 "website": "https://subspace.network"
3111 },
3112 {
3113 "prefix": 7007,
3114 "network": "tidefi",
3115 "displayName": "Tidefi",
3116 "symbols": [
3117 "TDFY"
3118 ],
3119 "decimals": [
3120 12
3121 ],
3122 "standardAccount": "*25519",
3123 "website": "https://tidefi.com"
3124 },
3125 {
3126 "prefix": 7013,
3127 "network": "gm",
3128 "displayName": "GM",
3129 "symbols": [
3130 "FREN",
3131 "GM",
3132 "GN"
3133 ],
3134 "decimals": [
3135 12,
3136 0,
3137 0
3138 ],
3139 "standardAccount": "*25519",
3140 "website": "https://gmordie.com"
3141 },
3142 {
3143 "prefix": 7391,
3144 "network": "unique_mainnet",
3145 "displayName": "Unique Network",
3146 "symbols": [
3147 "UNQ"
3148 ],
3149 "decimals": [
3150 18
3151 ],
3152 "standardAccount": "*25519",
3153 "website": "https://unique.network"
3154 },
3155 {
3156 "prefix": 8883,
3157 "network": "sapphire_mainnet",
3158 "displayName": "Sapphire by Unique",
3159 "symbols": [
3160 "QTZ"
3161 ],
3162 "decimals": [
3163 18
3164 ],
3165 "standardAccount": "*25519",
3166 "website": "https://unique.network"
3167 },
3168 {
3169 "prefix": 9072,
3170 "network": "hashed",
3171 "displayName": "Hashed Network",
3172 "symbols": [
3173 "HASH"
3174 ],
3175 "decimals": [
3176 18
3177 ],
3178 "standardAccount": "*25519",
3179 "website": "https://hashed.network"
3180 },
3181 {
3182 "prefix": 9807,
3183 "network": "dentnet",
3184 "displayName": "DENTNet",
3185 "symbols": [
3186 "DENTX"
3187 ],
3188 "decimals": [
3189 18
3190 ],
3191 "standardAccount": "*25519",
3192 "website": "https://www.dentnet.io"
3193 },
3194 {
3195 "prefix": 9935,
3196 "network": "t3rn",
3197 "displayName": "t3rn",
3198 "symbols": [
3199 "TRN"
3200 ],
3201 "decimals": [
3202 12
3203 ],
3204 "standardAccount": "*25519",
3205 "website": "https://t3rn.io/"
3206 },
3207 {
3208 "prefix": 10041,
3209 "network": "basilisk",
3210 "displayName": "Basilisk",
3211 "symbols": [
3212 "BSX"
3213 ],
3214 "decimals": [
3215 12
3216 ],
3217 "standardAccount": "*25519",
3218 "website": "https://bsx.fi"
3219 },
3220 {
3221 "prefix": 11330,
3222 "network": "cess-testnet",
3223 "displayName": "CESS Testnet",
3224 "symbols": [
3225 "TCESS"
3226 ],
3227 "decimals": [
3228 12
3229 ],
3230 "standardAccount": "*25519",
3231 "website": "https://cess.cloud"
3232 },
3233 {
3234 "prefix": 11331,
3235 "network": "cess",
3236 "displayName": "CESS",
3237 "symbols": [
3238 "CESS"
3239 ],
3240 "decimals": [
3241 12
3242 ],
3243 "standardAccount": "*25519",
3244 "website": "https://cess.cloud"
3245 },
3246 {
3247 "prefix": 11486,
3248 "network": "luhn",
3249 "displayName": "Luhn Network",
3250 "symbols": [
3251 "LUHN"
3252 ],
3253 "decimals": [
3254 18
3255 ],
3256 "standardAccount": "*25519",
3257 "website": "https://luhn.network"
3258 },
3259 {
3260 "prefix": 11820,
3261 "network": "contextfree",
3262 "displayName": "Automata ContextFree",
3263 "symbols": [
3264 "CTX"
3265 ],
3266 "decimals": [
3267 18
3268 ],
3269 "standardAccount": "*25519",
3270 "website": "https://ata.network"
3271 },
3272 {
3273 "prefix": 12155,
3274 "network": "impact",
3275 "displayName": "Impact Protocol Network",
3276 "symbols": [
3277 "BSTY"
3278 ],
3279 "decimals": [
3280 18
3281 ],
3282 "standardAccount": "*25519",
3283 "website": "https://impactprotocol.network/"
3284 },
3285 {
3286 "prefix": 12191,
3287 "network": "nftmart",
3288 "displayName": "NFTMart",
3289 "symbols": [
3290 "NMT"
3291 ],
3292 "decimals": [
3293 12
3294 ],
3295 "standardAccount": "*25519",
3296 "website": "https://nftmart.io"
3297 },
3298 {
3299 "prefix": 13116,
3300 "network": "bittensor",
3301 "displayName": "Bittensor",
3302 "symbols": [
3303 "TAO"
3304 ],
3305 "decimals": [
3306 9
3307 ],
3308 "standardAccount": "*25519",
3309 "website": "https://bittensor.com"
3310 }
3311 ];
3312
3313 const knownGenesis = {
3314 acala: [
3315 '0xfc41b9bd8ef8fe53d58c7ea67c794c7ec9a73daf05e6d54b14ff6342c99ba64c'
3316 ],
3317 ajuna: [
3318 '0xe358eb1d11b31255a286c12e44fe6780b7edb171d657905a97e39f71d9c6c3ee'
3319 ],
3320 'aleph-node': [
3321 '0x70255b4d28de0fc4e1a193d7e175ad1ccef431598211c55538f1018651a0344e'
3322 ],
3323 astar: [
3324 '0x9eb76c5184c4ab8679d2d5d819fdf90b9c001403e9e17da2e14b6d8aec4029c6'
3325 ],
3326 basilisk: [
3327 '0xa85cfb9b9fd4d622a5b28289a02347af987d8f73fa3108450e2b4a11c1ce5755'
3328 ],
3329 bifrost: [
3330 '0x262e1b2ad728475fd6fe88e62d34c200abe6fd693931ddad144059b1eb884e5b'
3331 ],
3332 'bifrost-kusama': [
3333 '0x9f28c6a68e0fc9646eff64935684f6eeeece527e37bbe1f213d22caa1d9d6bed'
3334 ],
3335 bittensor: [
3336 '0x2f0555cc76fc2840a25a6ea3b9637146806f1f44b090c175ffde2a7e5ab36c03'
3337 ],
3338 centrifuge: [
3339 '0xb3db41421702df9a7fcac62b53ffeac85f7853cc4e689e0b93aeb3db18c09d82',
3340 '0x67dddf2673b69e5f875f6f25277495834398eafd67f492e09f3f3345e003d1b5'
3341 ],
3342 cere: [
3343 '0x81443836a9a24caaa23f1241897d1235717535711d1d3fe24eae4fdc942c092c'
3344 ],
3345 composable: [
3346 '0xdaab8df776eb52ec604a5df5d388bb62a050a0aaec4556a64265b9d42755552d'
3347 ],
3348 darwinia: [
3349 '0xe71578b37a7c799b0ab4ee87ffa6f059a6b98f71f06fb8c84a8d88013a548ad6'
3350 ],
3351 'dock-mainnet': [
3352 '0x6bfe24dca2a3be10f22212678ac13a6446ec764103c0f3471c71609eac384aae',
3353 '0xf73467c6544aa68df2ee546b135f955c46b90fa627e9b5d7935f41061bb8a5a9'
3354 ],
3355 edgeware: [
3356 '0x742a2ca70c2fda6cee4f8df98d64c4c670a052d9568058982dad9d5a7a135c5b'
3357 ],
3358 equilibrium: [
3359 '0x6f1a800de3daff7f5e037ddf66ab22ce03ab91874debeddb1086f5f7dbd48925'
3360 ],
3361 genshiro: [
3362 '0x9b8cefc0eb5c568b527998bdd76c184e2b76ae561be76e4667072230217ea243'
3363 ],
3364 hydradx: [
3365 '0xafdc188f45c71dacbaa0b62e16a91f726c7b8699a9748cdf715459de6b7f366d',
3366 '0xd2a620c27ec5cbc5621ff9a522689895074f7cca0d08e7134a7804e1a3ba86fc',
3367 '0x10af6e84234477d84dc572bac0789813b254aa490767ed06fb9591191d1073f9',
3368 '0x3d75507dd46301767e601265791da1d9cb47b6ebc94e87347b635e5bf58bd047',
3369 '0x0ed32bfcab4a83517fac88f2aa7cbc2f88d3ab93be9a12b6188a036bf8a943c2'
3370 ],
3371 'interlay-parachain': [
3372 '0xbf88efe70e9e0e916416e8bed61f2b45717f517d7f3523e33c7b001e5ffcbc72'
3373 ],
3374 karura: [
3375 '0xbaf5aabe40646d11f0ee8abbdc64f4a4b7674925cba08e4a05ff9ebed6e2126b'
3376 ],
3377 khala: [
3378 '0xd43540ba6d3eb4897c28a77d48cb5b729fea37603cbbfc7a86a73b72adb3be8d'
3379 ],
3380 kulupu: [
3381 '0xf7a99d3cb92853d00d5275c971c132c074636256583fee53b3bbe60d7b8769ba'
3382 ],
3383 kusama: [
3384 '0xb0a8d493285c2df73290dfb7e61f870f17b41801197a149ca93654499ea3dafe',
3385 '0xe3777fa922cafbff200cadeaea1a76bd7898ad5b89f7848999058b50e715f636',
3386 '0x3fd7b9eb6a00376e5be61f01abb429ffb0b104be05eaff4d458da48fcd425baf'
3387 ],
3388 nodle: [
3389 '0x97da7ede98d7bad4e36b4d734b6055425a3be036da2a332ea5a7037656427a21'
3390 ],
3391 origintrail: [
3392 '0xe7e0962324a3b86c83404dbea483f25fb5dab4c224791c81b756cfc948006174'
3393 ],
3394 p3d: [
3395 '0x6c5894837ad89b6d92b114a2fb3eafa8fe3d26a54848e3447015442cd6ef4e66'
3396 ],
3397 parallel: [
3398 '0xe61a41c53f5dcd0beb09df93b34402aada44cb05117b71059cce40a2723a4e97'
3399 ],
3400 pendulum: [
3401 '0x5d3c298622d5634ed019bf61ea4b71655030015bde9beb0d6a24743714462c86'
3402 ],
3403 phala: [
3404 '0x1bb969d85965e4bb5a651abbedf21a54b6b31a21f66b5401cc3f1e286268d736'
3405 ],
3406 picasso: [
3407 '0x6811a339673c9daa897944dcdac99c6e2939cc88245ed21951a0a3c9a2be75bc',
3408 '0xe8e7f0f4c4f5a00720b4821dbfddefea7490bcf0b19009961cc46957984e2c1c'
3409 ],
3410 polkadex: [
3411 '0x3920bcb4960a1eef5580cd5367ff3f430eef052774f78468852f7b9cb39f8a3c'
3412 ],
3413 polkadot: [
3414 '0x91b171bb158e2d3848fa23a9f1c25182fb8e20313b2c1eb49219da7a70ce90c3'
3415 ],
3416 polymesh: [
3417 '0x6fbd74e5e1d0a61d52ccfe9d4adaed16dd3a7caa37c6bc4d0c2fa12e8b2f4063'
3418 ],
3419 rococo: [
3420 '0x6408de7737c59c238890533af25896a2c20608d8b380bb01029acb392781063e',
3421 '0xaaf2cd1b74b5f726895921259421b534124726263982522174147046b8827897',
3422 '0x037f5f3c8e67b314062025fc886fcd6238ea25a4a9b45dce8d246815c9ebe770',
3423 '0xc196f81260cf1686172b47a79cf002120735d7cb0eb1474e8adce56618456fff',
3424 '0xf6e9983c37baf68846fedafe21e56718790e39fb1c582abc408b81bc7b208f9a',
3425 '0x5fce687da39305dfe682b117f0820b319348e8bb37eb16cf34acbf6a202de9d9',
3426 '0xe7c3d5edde7db964317cd9b51a3a059d7cd99f81bdbce14990047354334c9779',
3427 '0x1611e1dbf0405379b861e2e27daa90f480b2e6d3682414a80835a52e8cb8a215',
3428 '0x343442f12fa715489a8714e79a7b264ea88c0d5b8c66b684a7788a516032f6b9',
3429 '0x78bcd530c6b3a068bc17473cf5d2aff9c287102bed9af3ae3c41c33b9d6c6147',
3430 '0x47381ee0697153d64404fc578392c8fd5cba9073391908f46c888498415647bd',
3431 '0x19c0e4fa8ab75f5ac7865e0b8f74ff91eb9a100d336f423cd013a8befba40299'
3432 ],
3433 sora: [
3434 '0x7e4e32d0feafd4f9c9414b0be86373f9a1efa904809b683453a9af6856d38ad5'
3435 ],
3436 stafi: [
3437 '0x290a4149f09ea0e402c74c1c7e96ae4239588577fe78932f94f5404c68243d80'
3438 ],
3439 statemine: [
3440 '0x48239ef607d7928874027a43a67689209727dfb3d3dc5e5b03a39bdc2eda771a'
3441 ],
3442 statemint: [
3443 '0x68d56f15f85d3136970ec16946040bc1752654e906147f7e43e9d539d7c3de2f'
3444 ],
3445 subsocial: [
3446 '0x0bd72c1c305172e1275278aaeb3f161e02eccb7a819e63f62d47bd53a28189f8'
3447 ],
3448 ternoa: [
3449 '0x6859c81ca95ef624c9dfe4dc6e3381c33e5d6509e35e147092bfbc780f777c4e'
3450 ],
3451 unique: [
3452 '0x84322d9cddbf35088f1e54e9a85c967a41a56a4f43445768125e61af166c7d31'
3453 ],
3454 vtb: [
3455 '0x286bc8414c7000ce1d6ee6a834e29a54c1784814b76243eb77ed0b2c5573c60f',
3456 '0x7483b89572fb2bd687c7b9a93b242d0b237f9aba463aba07ec24503931038aaa'
3457 ],
3458 westend: [
3459 '0xe143f23803ac50e8f6f8e62695d1ce9e4e1d68aa36c1cd2cfd15340213f3423e'
3460 ],
3461 xxnetwork: [
3462 '0x50dd5d206917bf10502c68fb4d18a59fc8aa31586f4e8856b493e43544aa82aa'
3463 ]
3464 };
3465
3466 const knownIcon = {
3467 centrifuge: 'polkadot',
3468 kusama: 'polkadot',
3469 polkadot: 'polkadot',
3470 sora: 'polkadot',
3471 statemine: 'polkadot',
3472 statemint: 'polkadot',
3473 westmint: 'polkadot'
3474 };
3475
3476 const knownLedger = {
3477 acala: 0x00000313,
3478 ajuna: 0x00000162,
3479 'aleph-node': 0x00000283,
3480 astar: 0x0000032a,
3481 bifrost: 0x00000314,
3482 'bifrost-kusama': 0x00000314,
3483 centrifuge: 0x000002eb,
3484 composable: 0x00000162,
3485 darwinia: 0x00000162,
3486 'dock-mainnet': 0x00000252,
3487 edgeware: 0x0000020b,
3488 equilibrium: 0x05f5e0fd,
3489 genshiro: 0x05f5e0fc,
3490 hydradx: 0x00000162,
3491 'interlay-parachain': 0x00000162,
3492 karura: 0x000002ae,
3493 khala: 0x000001b2,
3494 kusama: 0x000001b2,
3495 nodle: 0x000003eb,
3496 origintrail: 0x00000162,
3497 parallel: 0x00000162,
3498 pendulum: 0x00000162,
3499 phala: 0x00000162,
3500 picasso: 0x000001b2,
3501 polkadex: 0x0000031f,
3502 polkadot: 0x00000162,
3503 polymesh: 0x00000253,
3504 sora: 0x00000269,
3505 stafi: 0x0000038b,
3506 statemine: 0x000001b2,
3507 statemint: 0x00000162,
3508 ternoa: 0x00003e3,
3509 unique: 0x00000162,
3510 vtb: 0x000002b6,
3511 xxnetwork: 0x000007a3
3512 };
3513
3514 const knownTestnet = {
3515 '': true,
3516 'cess-testnet': true,
3517 'dock-testnet': true,
3518 jupiter: true,
3519 'mathchain-testnet': true,
3520 p3dt: true,
3521 subspace_testnet: true,
3522 'zero-alphaville': true
3523 };
3524
3525 const UNSORTED = [0, 2, 42];
3526 const TESTNETS = ['testnet'];
3527 function toExpanded(o) {
3528 const network = o.network || '';
3529 const nameParts = network.replace(/_/g, '-').split('-');
3530 const n = o;
3531 n.slip44 = knownLedger[network];
3532 n.hasLedgerSupport = !!n.slip44;
3533 n.genesisHash = knownGenesis[network] || [];
3534 n.icon = knownIcon[network] || 'substrate';
3535 n.isTestnet = !!knownTestnet[network] || TESTNETS.includes(nameParts[nameParts.length - 1]);
3536 n.isIgnored = n.isTestnet || (!(o.standardAccount &&
3537 o.decimals && o.decimals.length &&
3538 o.symbols && o.symbols.length) &&
3539 o.prefix !== 42);
3540 return n;
3541 }
3542 function filterSelectable({ genesisHash, prefix }) {
3543 return !!genesisHash.length || prefix === 42;
3544 }
3545 function filterAvailable(n) {
3546 return !n.isIgnored && !!n.network;
3547 }
3548 function sortNetworks(a, b) {
3549 const isUnSortedA = UNSORTED.includes(a.prefix);
3550 const isUnSortedB = UNSORTED.includes(b.prefix);
3551 return isUnSortedA === isUnSortedB
3552 ? isUnSortedA
3553 ? 0
3554 : a.displayName.localeCompare(b.displayName)
3555 : isUnSortedA
3556 ? -1
3557 : 1;
3558 }
3559 const allNetworks = knownSubstrate.map(toExpanded);
3560 const availableNetworks = allNetworks.filter(filterAvailable).sort(sortNetworks);
3561 const selectableNetworks = availableNetworks.filter(filterSelectable);
3562
3563 const defaults = {
3564 allowedDecodedLengths: [1, 2, 4, 8, 32, 33],
3565 allowedEncodedLengths: [3, 4, 6, 10, 35, 36, 37, 38],
3566 allowedPrefix: availableNetworks.map(({ prefix }) => prefix),
3567 prefix: 42
3568 };
3569
3570 function decodeAddress(encoded, ignoreChecksum, ss58Format = -1) {
3571 if (!encoded) {
3572 throw new Error('Invalid empty address passed');
3573 }
3574 if (util.isU8a(encoded) || util.isHex(encoded)) {
3575 return util.u8aToU8a(encoded);
3576 }
3577 try {
3578 const decoded = base58Decode(encoded);
3579 if (!defaults.allowedEncodedLengths.includes(decoded.length)) {
3580 throw new Error('Invalid decoded address length');
3581 }
3582 const [isValid, endPos, ss58Length, ss58Decoded] = checkAddressChecksum(decoded);
3583 if (!isValid && !ignoreChecksum) {
3584 throw new Error('Invalid decoded address checksum');
3585 }
3586 else if (ss58Format !== -1 && ss58Format !== ss58Decoded) {
3587 throw new Error(`Expected ss58Format ${ss58Format}, received ${ss58Decoded}`);
3588 }
3589 return decoded.slice(ss58Length, endPos);
3590 }
3591 catch (error) {
3592 throw new Error(`Decoding ${encoded}: ${error.message}`);
3593 }
3594 }
3595
3596 function addressToEvm(address, ignoreChecksum) {
3597 return decodeAddress(address, ignoreChecksum).subarray(0, 20);
3598 }
3599
3600 function checkAddress(address, prefix) {
3601 let decoded;
3602 try {
3603 decoded = base58Decode(address);
3604 }
3605 catch (error) {
3606 return [false, error.message];
3607 }
3608 const [isValid, , , ss58Decoded] = checkAddressChecksum(decoded);
3609 if (ss58Decoded !== prefix) {
3610 return [false, `Prefix mismatch, expected ${prefix}, found ${ss58Decoded}`];
3611 }
3612 else if (!defaults.allowedEncodedLengths.includes(decoded.length)) {
3613 return [false, 'Invalid decoded address length'];
3614 }
3615 return [isValid, isValid ? null : 'Invalid decoded address checksum'];
3616 }
3617
3618 const BN_BE_OPTS = { isLe: false };
3619 const BN_LE_OPTS = { isLe: true };
3620 const BN_LE_16_OPTS = { bitLength: 16, isLe: true };
3621 const BN_BE_32_OPTS = { bitLength: 32, isLe: false };
3622 const BN_LE_32_OPTS = { bitLength: 32, isLe: true };
3623 const BN_BE_256_OPTS = { bitLength: 256, isLe: false };
3624 const BN_LE_256_OPTS = { bitLength: 256, isLe: true };
3625 const BN_LE_512_OPTS = { bitLength: 512, isLe: true };
3626
3627 const RE_NUMBER = /^\d+$/;
3628 const JUNCTION_ID_LEN = 32;
3629 class DeriveJunction {
3630 constructor() {
3631 this.__internal__chainCode = new Uint8Array(32);
3632 this.__internal__isHard = false;
3633 }
3634 static from(value) {
3635 const result = new DeriveJunction();
3636 const [code, isHard] = value.startsWith('/')
3637 ? [value.substring(1), true]
3638 : [value, false];
3639 result.soft(RE_NUMBER.test(code)
3640 ? new util.BN(code, 10)
3641 : code);
3642 return isHard
3643 ? result.harden()
3644 : result;
3645 }
3646 get chainCode() {
3647 return this.__internal__chainCode;
3648 }
3649 get isHard() {
3650 return this.__internal__isHard;
3651 }
3652 get isSoft() {
3653 return !this.__internal__isHard;
3654 }
3655 hard(value) {
3656 return this.soft(value).harden();
3657 }
3658 harden() {
3659 this.__internal__isHard = true;
3660 return this;
3661 }
3662 soft(value) {
3663 if (util.isNumber(value) || util.isBn(value) || util.isBigInt(value)) {
3664 return this.soft(util.bnToU8a(value, BN_LE_256_OPTS));
3665 }
3666 else if (util.isHex(value)) {
3667 return this.soft(util.hexToU8a(value));
3668 }
3669 else if (util.isString(value)) {
3670 return this.soft(util.compactAddLength(util.stringToU8a(value)));
3671 }
3672 else if (value.length > JUNCTION_ID_LEN) {
3673 return this.soft(blake2AsU8a(value));
3674 }
3675 this.__internal__chainCode.fill(0);
3676 this.__internal__chainCode.set(value, 0);
3677 return this;
3678 }
3679 soften() {
3680 this.__internal__isHard = false;
3681 return this;
3682 }
3683 }
3684
3685 const RE_JUNCTION = /\/(\/?)([^/]+)/g;
3686 function keyExtractPath(derivePath) {
3687 const parts = derivePath.match(RE_JUNCTION);
3688 const path = [];
3689 let constructed = '';
3690 if (parts) {
3691 constructed = parts.join('');
3692 for (const p of parts) {
3693 path.push(DeriveJunction.from(p.substring(1)));
3694 }
3695 }
3696 if (constructed !== derivePath) {
3697 throw new Error(`Re-constructed path "${constructed}" does not match input`);
3698 }
3699 return {
3700 parts,
3701 path
3702 };
3703 }
3704
3705 const RE_CAPTURE = /^(\w+( \w+)*)((\/\/?[^/]+)*)(\/\/\/(.*))?$/;
3706 function keyExtractSuri(suri) {
3707 const matches = suri.match(RE_CAPTURE);
3708 if (matches === null) {
3709 throw new Error('Unable to match provided value to a secret URI');
3710 }
3711 const [, phrase, , derivePath, , , password] = matches;
3712 const { path } = keyExtractPath(derivePath);
3713 return {
3714 derivePath,
3715 password,
3716 path,
3717 phrase
3718 };
3719 }
3720
3721 const HDKD$1 = util.compactAddLength(util.stringToU8a('Secp256k1HDKD'));
3722 function secp256k1DeriveHard(seed, chainCode) {
3723 if (!util.isU8a(chainCode) || chainCode.length !== 32) {
3724 throw new Error('Invalid chainCode passed to derive');
3725 }
3726 return blake2AsU8a(util.u8aConcat(HDKD$1, seed, chainCode), 256);
3727 }
3728
3729 function setBigUint64(view, byteOffset, value, isLE) {
3730 if (typeof view.setBigUint64 === 'function')
3731 return view.setBigUint64(byteOffset, value, isLE);
3732 const _32n = BigInt(32);
3733 const _u32_max = BigInt(0xffffffff);
3734 const wh = Number((value >> _32n) & _u32_max);
3735 const wl = Number(value & _u32_max);
3736 const h = isLE ? 4 : 0;
3737 const l = isLE ? 0 : 4;
3738 view.setUint32(byteOffset + h, wh, isLE);
3739 view.setUint32(byteOffset + l, wl, isLE);
3740 }
3741 class SHA2 extends Hash {
3742 constructor(blockLen, outputLen, padOffset, isLE) {
3743 super();
3744 this.blockLen = blockLen;
3745 this.outputLen = outputLen;
3746 this.padOffset = padOffset;
3747 this.isLE = isLE;
3748 this.finished = false;
3749 this.length = 0;
3750 this.pos = 0;
3751 this.destroyed = false;
3752 this.buffer = new Uint8Array(blockLen);
3753 this.view = createView(this.buffer);
3754 }
3755 update(data) {
3756 assert.exists(this);
3757 const { view, buffer, blockLen } = this;
3758 data = toBytes(data);
3759 const len = data.length;
3760 for (let pos = 0; pos < len;) {
3761 const take = Math.min(blockLen - this.pos, len - pos);
3762 if (take === blockLen) {
3763 const dataView = createView(data);
3764 for (; blockLen <= len - pos; pos += blockLen)
3765 this.process(dataView, pos);
3766 continue;
3767 }
3768 buffer.set(data.subarray(pos, pos + take), this.pos);
3769 this.pos += take;
3770 pos += take;
3771 if (this.pos === blockLen) {
3772 this.process(view, 0);
3773 this.pos = 0;
3774 }
3775 }
3776 this.length += data.length;
3777 this.roundClean();
3778 return this;
3779 }
3780 digestInto(out) {
3781 assert.exists(this);
3782 assert.output(out, this);
3783 this.finished = true;
3784 const { buffer, view, blockLen, isLE } = this;
3785 let { pos } = this;
3786 buffer[pos++] = 0b10000000;
3787 this.buffer.subarray(pos).fill(0);
3788 if (this.padOffset > blockLen - pos) {
3789 this.process(view, 0);
3790 pos = 0;
3791 }
3792 for (let i = pos; i < blockLen; i++)
3793 buffer[i] = 0;
3794 setBigUint64(view, blockLen - 8, BigInt(this.length * 8), isLE);
3795 this.process(view, 0);
3796 const oview = createView(out);
3797 const len = this.outputLen;
3798 if (len % 4)
3799 throw new Error('_sha2: outputLen should be aligned to 32bit');
3800 const outLen = len / 4;
3801 const state = this.get();
3802 if (outLen > state.length)
3803 throw new Error('_sha2: outputLen bigger than state');
3804 for (let i = 0; i < outLen; i++)
3805 oview.setUint32(4 * i, state[i], isLE);
3806 }
3807 digest() {
3808 const { buffer, outputLen } = this;
3809 this.digestInto(buffer);
3810 const res = buffer.slice(0, outputLen);
3811 this.destroy();
3812 return res;
3813 }
3814 _cloneInto(to) {
3815 to || (to = new this.constructor());
3816 to.set(...this.get());
3817 const { blockLen, buffer, length, finished, destroyed, pos } = this;
3818 to.length = length;
3819 to.pos = pos;
3820 to.finished = finished;
3821 to.destroyed = destroyed;
3822 if (length % blockLen)
3823 to.buffer.set(buffer);
3824 return to;
3825 }
3826 }
3827
3828 const Chi = (a, b, c) => (a & b) ^ (~a & c);
3829 const Maj = (a, b, c) => (a & b) ^ (a & c) ^ (b & c);
3830 const SHA256_K = new Uint32Array([
3831 0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5,
3832 0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174,
3833 0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da,
3834 0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967,
3835 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,
3836 0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070,
3837 0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3,
3838 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2
3839 ]);
3840 const IV = new Uint32Array([
3841 0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a, 0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19
3842 ]);
3843 const SHA256_W = new Uint32Array(64);
3844 class SHA256 extends SHA2 {
3845 constructor() {
3846 super(64, 32, 8, false);
3847 this.A = IV[0] | 0;
3848 this.B = IV[1] | 0;
3849 this.C = IV[2] | 0;
3850 this.D = IV[3] | 0;
3851 this.E = IV[4] | 0;
3852 this.F = IV[5] | 0;
3853 this.G = IV[6] | 0;
3854 this.H = IV[7] | 0;
3855 }
3856 get() {
3857 const { A, B, C, D, E, F, G, H } = this;
3858 return [A, B, C, D, E, F, G, H];
3859 }
3860 set(A, B, C, D, E, F, G, H) {
3861 this.A = A | 0;
3862 this.B = B | 0;
3863 this.C = C | 0;
3864 this.D = D | 0;
3865 this.E = E | 0;
3866 this.F = F | 0;
3867 this.G = G | 0;
3868 this.H = H | 0;
3869 }
3870 process(view, offset) {
3871 for (let i = 0; i < 16; i++, offset += 4)
3872 SHA256_W[i] = view.getUint32(offset, false);
3873 for (let i = 16; i < 64; i++) {
3874 const W15 = SHA256_W[i - 15];
3875 const W2 = SHA256_W[i - 2];
3876 const s0 = rotr(W15, 7) ^ rotr(W15, 18) ^ (W15 >>> 3);
3877 const s1 = rotr(W2, 17) ^ rotr(W2, 19) ^ (W2 >>> 10);
3878 SHA256_W[i] = (s1 + SHA256_W[i - 7] + s0 + SHA256_W[i - 16]) | 0;
3879 }
3880 let { A, B, C, D, E, F, G, H } = this;
3881 for (let i = 0; i < 64; i++) {
3882 const sigma1 = rotr(E, 6) ^ rotr(E, 11) ^ rotr(E, 25);
3883 const T1 = (H + sigma1 + Chi(E, F, G) + SHA256_K[i] + SHA256_W[i]) | 0;
3884 const sigma0 = rotr(A, 2) ^ rotr(A, 13) ^ rotr(A, 22);
3885 const T2 = (sigma0 + Maj(A, B, C)) | 0;
3886 H = G;
3887 G = F;
3888 F = E;
3889 E = (D + T1) | 0;
3890 D = C;
3891 C = B;
3892 B = A;
3893 A = (T1 + T2) | 0;
3894 }
3895 A = (A + this.A) | 0;
3896 B = (B + this.B) | 0;
3897 C = (C + this.C) | 0;
3898 D = (D + this.D) | 0;
3899 E = (E + this.E) | 0;
3900 F = (F + this.F) | 0;
3901 G = (G + this.G) | 0;
3902 H = (H + this.H) | 0;
3903 this.set(A, B, C, D, E, F, G, H);
3904 }
3905 roundClean() {
3906 SHA256_W.fill(0);
3907 }
3908 destroy() {
3909 this.set(0, 0, 0, 0, 0, 0, 0, 0);
3910 this.buffer.fill(0);
3911 }
3912 }
3913 class SHA224 extends SHA256 {
3914 constructor() {
3915 super();
3916 this.A = 0xc1059ed8 | 0;
3917 this.B = 0x367cd507 | 0;
3918 this.C = 0x3070dd17 | 0;
3919 this.D = 0xf70e5939 | 0;
3920 this.E = 0xffc00b31 | 0;
3921 this.F = 0x68581511 | 0;
3922 this.G = 0x64f98fa7 | 0;
3923 this.H = 0xbefa4fa4 | 0;
3924 this.outputLen = 28;
3925 }
3926 }
3927 const sha256 = wrapConstructor(() => new SHA256());
3928 wrapConstructor(() => new SHA224());
3929
3930 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
3931 const _0n$8 = BigInt(0);
3932 const _1n$8 = BigInt(1);
3933 const _2n$6 = BigInt(2);
3934 const u8a = (a) => a instanceof Uint8Array;
3935 const hexes = Array.from({ length: 256 }, (v, i) => i.toString(16).padStart(2, '0'));
3936 function bytesToHex(bytes) {
3937 if (!u8a(bytes))
3938 throw new Error('Uint8Array expected');
3939 let hex = '';
3940 for (let i = 0; i < bytes.length; i++) {
3941 hex += hexes[bytes[i]];
3942 }
3943 return hex;
3944 }
3945 function numberToHexUnpadded(num) {
3946 const hex = num.toString(16);
3947 return hex.length & 1 ? `0${hex}` : hex;
3948 }
3949 function hexToNumber(hex) {
3950 if (typeof hex !== 'string')
3951 throw new Error('hex string expected, got ' + typeof hex);
3952 return BigInt(hex === '' ? '0' : `0x${hex}`);
3953 }
3954 function hexToBytes(hex) {
3955 if (typeof hex !== 'string')
3956 throw new Error('hex string expected, got ' + typeof hex);
3957 const len = hex.length;
3958 if (len % 2)
3959 throw new Error('padded hex string expected, got unpadded hex of length ' + len);
3960 const array = new Uint8Array(len / 2);
3961 for (let i = 0; i < array.length; i++) {
3962 const j = i * 2;
3963 const hexByte = hex.slice(j, j + 2);
3964 const byte = Number.parseInt(hexByte, 16);
3965 if (Number.isNaN(byte) || byte < 0)
3966 throw new Error('Invalid byte sequence');
3967 array[i] = byte;
3968 }
3969 return array;
3970 }
3971 function bytesToNumberBE(bytes) {
3972 return hexToNumber(bytesToHex(bytes));
3973 }
3974 function bytesToNumberLE(bytes) {
3975 if (!u8a(bytes))
3976 throw new Error('Uint8Array expected');
3977 return hexToNumber(bytesToHex(Uint8Array.from(bytes).reverse()));
3978 }
3979 function numberToBytesBE(n, len) {
3980 return hexToBytes(n.toString(16).padStart(len * 2, '0'));
3981 }
3982 function numberToBytesLE(n, len) {
3983 return numberToBytesBE(n, len).reverse();
3984 }
3985 function numberToVarBytesBE(n) {
3986 return hexToBytes(numberToHexUnpadded(n));
3987 }
3988 function ensureBytes(title, hex, expectedLength) {
3989 let res;
3990 if (typeof hex === 'string') {
3991 try {
3992 res = hexToBytes(hex);
3993 }
3994 catch (e) {
3995 throw new Error(`${title} must be valid hex string, got "${hex}". Cause: ${e}`);
3996 }
3997 }
3998 else if (u8a(hex)) {
3999 res = Uint8Array.from(hex);
4000 }
4001 else {
4002 throw new Error(`${title} must be hex string or Uint8Array`);
4003 }
4004 const len = res.length;
4005 if (typeof expectedLength === 'number' && len !== expectedLength)
4006 throw new Error(`${title} expected ${expectedLength} bytes, got ${len}`);
4007 return res;
4008 }
4009 function concatBytes(...arrays) {
4010 const r = new Uint8Array(arrays.reduce((sum, a) => sum + a.length, 0));
4011 let pad = 0;
4012 arrays.forEach((a) => {
4013 if (!u8a(a))
4014 throw new Error('Uint8Array expected');
4015 r.set(a, pad);
4016 pad += a.length;
4017 });
4018 return r;
4019 }
4020 function equalBytes(b1, b2) {
4021 if (b1.length !== b2.length)
4022 return false;
4023 for (let i = 0; i < b1.length; i++)
4024 if (b1[i] !== b2[i])
4025 return false;
4026 return true;
4027 }
4028 function utf8ToBytes(str) {
4029 if (typeof str !== 'string')
4030 throw new Error(`utf8ToBytes expected string, got ${typeof str}`);
4031 return new Uint8Array(new TextEncoder().encode(str));
4032 }
4033 function bitLen(n) {
4034 let len;
4035 for (len = 0; n > _0n$8; n >>= _1n$8, len += 1)
4036 ;
4037 return len;
4038 }
4039 function bitGet(n, pos) {
4040 return (n >> BigInt(pos)) & _1n$8;
4041 }
4042 const bitSet = (n, pos, value) => {
4043 return n | ((value ? _1n$8 : _0n$8) << BigInt(pos));
4044 };
4045 const bitMask = (n) => (_2n$6 << BigInt(n - 1)) - _1n$8;
4046 const u8n = (data) => new Uint8Array(data);
4047 const u8fr = (arr) => Uint8Array.from(arr);
4048 function createHmacDrbg(hashLen, qByteLen, hmacFn) {
4049 if (typeof hashLen !== 'number' || hashLen < 2)
4050 throw new Error('hashLen must be a number');
4051 if (typeof qByteLen !== 'number' || qByteLen < 2)
4052 throw new Error('qByteLen must be a number');
4053 if (typeof hmacFn !== 'function')
4054 throw new Error('hmacFn must be a function');
4055 let v = u8n(hashLen);
4056 let k = u8n(hashLen);
4057 let i = 0;
4058 const reset = () => {
4059 v.fill(1);
4060 k.fill(0);
4061 i = 0;
4062 };
4063 const h = (...b) => hmacFn(k, v, ...b);
4064 const reseed = (seed = u8n()) => {
4065 k = h(u8fr([0x00]), seed);
4066 v = h();
4067 if (seed.length === 0)
4068 return;
4069 k = h(u8fr([0x01]), seed);
4070 v = h();
4071 };
4072 const gen = () => {
4073 if (i++ >= 1000)
4074 throw new Error('drbg: tried 1000 values');
4075 let len = 0;
4076 const out = [];
4077 while (len < qByteLen) {
4078 v = h();
4079 const sl = v.slice();
4080 out.push(sl);
4081 len += v.length;
4082 }
4083 return concatBytes(...out);
4084 };
4085 const genUntil = (seed, pred) => {
4086 reset();
4087 reseed(seed);
4088 let res = undefined;
4089 while (!(res = pred(gen())))
4090 reseed();
4091 reset();
4092 return res;
4093 };
4094 return genUntil;
4095 }
4096 const validatorFns = {
4097 bigint: (val) => typeof val === 'bigint',
4098 function: (val) => typeof val === 'function',
4099 boolean: (val) => typeof val === 'boolean',
4100 string: (val) => typeof val === 'string',
4101 isSafeInteger: (val) => Number.isSafeInteger(val),
4102 array: (val) => Array.isArray(val),
4103 field: (val, object) => object.Fp.isValid(val),
4104 hash: (val) => typeof val === 'function' && Number.isSafeInteger(val.outputLen),
4105 };
4106 function validateObject(object, validators, optValidators = {}) {
4107 const checkField = (fieldName, type, isOptional) => {
4108 const checkVal = validatorFns[type];
4109 if (typeof checkVal !== 'function')
4110 throw new Error(`Invalid validator "${type}", expected function`);
4111 const val = object[fieldName];
4112 if (isOptional && val === undefined)
4113 return;
4114 if (!checkVal(val, object)) {
4115 throw new Error(`Invalid param ${String(fieldName)}=${val} (${typeof val}), expected ${type}`);
4116 }
4117 };
4118 for (const [fieldName, type] of Object.entries(validators))
4119 checkField(fieldName, type, false);
4120 for (const [fieldName, type] of Object.entries(optValidators))
4121 checkField(fieldName, type, true);
4122 return object;
4123 }
4124
4125 const ut = /*#__PURE__*/Object.freeze({
4126 __proto__: null,
4127 bitGet: bitGet,
4128 bitLen: bitLen,
4129 bitMask: bitMask,
4130 bitSet: bitSet,
4131 bytesToHex: bytesToHex,
4132 bytesToNumberBE: bytesToNumberBE,
4133 bytesToNumberLE: bytesToNumberLE,
4134 concatBytes: concatBytes,
4135 createHmacDrbg: createHmacDrbg,
4136 ensureBytes: ensureBytes,
4137 equalBytes: equalBytes,
4138 hexToBytes: hexToBytes,
4139 hexToNumber: hexToNumber,
4140 numberToBytesBE: numberToBytesBE,
4141 numberToBytesLE: numberToBytesLE,
4142 numberToHexUnpadded: numberToHexUnpadded,
4143 numberToVarBytesBE: numberToVarBytesBE,
4144 utf8ToBytes: utf8ToBytes,
4145 validateObject: validateObject
4146 });
4147
4148 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
4149 const _0n$7 = BigInt(0), _1n$7 = BigInt(1), _2n$5 = BigInt(2), _3n$1 = BigInt(3);
4150 const _4n$1 = BigInt(4), _5n$1 = BigInt(5), _8n$1 = BigInt(8);
4151 BigInt(9); BigInt(16);
4152 function mod(a, b) {
4153 const result = a % b;
4154 return result >= _0n$7 ? result : b + result;
4155 }
4156 function pow(num, power, modulo) {
4157 if (modulo <= _0n$7 || power < _0n$7)
4158 throw new Error('Expected power/modulo > 0');
4159 if (modulo === _1n$7)
4160 return _0n$7;
4161 let res = _1n$7;
4162 while (power > _0n$7) {
4163 if (power & _1n$7)
4164 res = (res * num) % modulo;
4165 num = (num * num) % modulo;
4166 power >>= _1n$7;
4167 }
4168 return res;
4169 }
4170 function pow2(x, power, modulo) {
4171 let res = x;
4172 while (power-- > _0n$7) {
4173 res *= res;
4174 res %= modulo;
4175 }
4176 return res;
4177 }
4178 function invert(number, modulo) {
4179 if (number === _0n$7 || modulo <= _0n$7) {
4180 throw new Error(`invert: expected positive integers, got n=${number} mod=${modulo}`);
4181 }
4182 let a = mod(number, modulo);
4183 let b = modulo;
4184 let x = _0n$7, u = _1n$7;
4185 while (a !== _0n$7) {
4186 const q = b / a;
4187 const r = b % a;
4188 const m = x - u * q;
4189 b = a, a = r, x = u, u = m;
4190 }
4191 const gcd = b;
4192 if (gcd !== _1n$7)
4193 throw new Error('invert: does not exist');
4194 return mod(x, modulo);
4195 }
4196 function tonelliShanks(P) {
4197 const legendreC = (P - _1n$7) / _2n$5;
4198 let Q, S, Z;
4199 for (Q = P - _1n$7, S = 0; Q % _2n$5 === _0n$7; Q /= _2n$5, S++)
4200 ;
4201 for (Z = _2n$5; Z < P && pow(Z, legendreC, P) !== P - _1n$7; Z++)
4202 ;
4203 if (S === 1) {
4204 const p1div4 = (P + _1n$7) / _4n$1;
4205 return function tonelliFast(Fp, n) {
4206 const root = Fp.pow(n, p1div4);
4207 if (!Fp.eql(Fp.sqr(root), n))
4208 throw new Error('Cannot find square root');
4209 return root;
4210 };
4211 }
4212 const Q1div2 = (Q + _1n$7) / _2n$5;
4213 return function tonelliSlow(Fp, n) {
4214 if (Fp.pow(n, legendreC) === Fp.neg(Fp.ONE))
4215 throw new Error('Cannot find square root');
4216 let r = S;
4217 let g = Fp.pow(Fp.mul(Fp.ONE, Z), Q);
4218 let x = Fp.pow(n, Q1div2);
4219 let b = Fp.pow(n, Q);
4220 while (!Fp.eql(b, Fp.ONE)) {
4221 if (Fp.eql(b, Fp.ZERO))
4222 return Fp.ZERO;
4223 let m = 1;
4224 for (let t2 = Fp.sqr(b); m < r; m++) {
4225 if (Fp.eql(t2, Fp.ONE))
4226 break;
4227 t2 = Fp.sqr(t2);
4228 }
4229 const ge = Fp.pow(g, _1n$7 << BigInt(r - m - 1));
4230 g = Fp.sqr(ge);
4231 x = Fp.mul(x, ge);
4232 b = Fp.mul(b, g);
4233 r = m;
4234 }
4235 return x;
4236 };
4237 }
4238 function FpSqrt(P) {
4239 if (P % _4n$1 === _3n$1) {
4240 const p1div4 = (P + _1n$7) / _4n$1;
4241 return function sqrt3mod4(Fp, n) {
4242 const root = Fp.pow(n, p1div4);
4243 if (!Fp.eql(Fp.sqr(root), n))
4244 throw new Error('Cannot find square root');
4245 return root;
4246 };
4247 }
4248 if (P % _8n$1 === _5n$1) {
4249 const c1 = (P - _5n$1) / _8n$1;
4250 return function sqrt5mod8(Fp, n) {
4251 const n2 = Fp.mul(n, _2n$5);
4252 const v = Fp.pow(n2, c1);
4253 const nv = Fp.mul(n, v);
4254 const i = Fp.mul(Fp.mul(nv, _2n$5), v);
4255 const root = Fp.mul(nv, Fp.sub(i, Fp.ONE));
4256 if (!Fp.eql(Fp.sqr(root), n))
4257 throw new Error('Cannot find square root');
4258 return root;
4259 };
4260 }
4261 return tonelliShanks(P);
4262 }
4263 const isNegativeLE = (num, modulo) => (mod(num, modulo) & _1n$7) === _1n$7;
4264 const FIELD_FIELDS = [
4265 'create', 'isValid', 'is0', 'neg', 'inv', 'sqrt', 'sqr',
4266 'eql', 'add', 'sub', 'mul', 'pow', 'div',
4267 'addN', 'subN', 'mulN', 'sqrN'
4268 ];
4269 function validateField(field) {
4270 const initial = {
4271 ORDER: 'bigint',
4272 MASK: 'bigint',
4273 BYTES: 'isSafeInteger',
4274 BITS: 'isSafeInteger',
4275 };
4276 const opts = FIELD_FIELDS.reduce((map, val) => {
4277 map[val] = 'function';
4278 return map;
4279 }, initial);
4280 return validateObject(field, opts);
4281 }
4282 function FpPow(f, num, power) {
4283 if (power < _0n$7)
4284 throw new Error('Expected power > 0');
4285 if (power === _0n$7)
4286 return f.ONE;
4287 if (power === _1n$7)
4288 return num;
4289 let p = f.ONE;
4290 let d = num;
4291 while (power > _0n$7) {
4292 if (power & _1n$7)
4293 p = f.mul(p, d);
4294 d = f.sqr(d);
4295 power >>= _1n$7;
4296 }
4297 return p;
4298 }
4299 function FpInvertBatch(f, nums) {
4300 const tmp = new Array(nums.length);
4301 const lastMultiplied = nums.reduce((acc, num, i) => {
4302 if (f.is0(num))
4303 return acc;
4304 tmp[i] = acc;
4305 return f.mul(acc, num);
4306 }, f.ONE);
4307 const inverted = f.inv(lastMultiplied);
4308 nums.reduceRight((acc, num, i) => {
4309 if (f.is0(num))
4310 return acc;
4311 tmp[i] = f.mul(acc, tmp[i]);
4312 return f.mul(acc, num);
4313 }, inverted);
4314 return tmp;
4315 }
4316 function nLength(n, nBitLength) {
4317 const _nBitLength = nBitLength !== undefined ? nBitLength : n.toString(2).length;
4318 const nByteLength = Math.ceil(_nBitLength / 8);
4319 return { nBitLength: _nBitLength, nByteLength };
4320 }
4321 function Field(ORDER, bitLen, isLE = false, redef = {}) {
4322 if (ORDER <= _0n$7)
4323 throw new Error(`Expected Fp ORDER > 0, got ${ORDER}`);
4324 const { nBitLength: BITS, nByteLength: BYTES } = nLength(ORDER, bitLen);
4325 if (BYTES > 2048)
4326 throw new Error('Field lengths over 2048 bytes are not supported');
4327 const sqrtP = FpSqrt(ORDER);
4328 const f = Object.freeze({
4329 ORDER,
4330 BITS,
4331 BYTES,
4332 MASK: bitMask(BITS),
4333 ZERO: _0n$7,
4334 ONE: _1n$7,
4335 create: (num) => mod(num, ORDER),
4336 isValid: (num) => {
4337 if (typeof num !== 'bigint')
4338 throw new Error(`Invalid field element: expected bigint, got ${typeof num}`);
4339 return _0n$7 <= num && num < ORDER;
4340 },
4341 is0: (num) => num === _0n$7,
4342 isOdd: (num) => (num & _1n$7) === _1n$7,
4343 neg: (num) => mod(-num, ORDER),
4344 eql: (lhs, rhs) => lhs === rhs,
4345 sqr: (num) => mod(num * num, ORDER),
4346 add: (lhs, rhs) => mod(lhs + rhs, ORDER),
4347 sub: (lhs, rhs) => mod(lhs - rhs, ORDER),
4348 mul: (lhs, rhs) => mod(lhs * rhs, ORDER),
4349 pow: (num, power) => FpPow(f, num, power),
4350 div: (lhs, rhs) => mod(lhs * invert(rhs, ORDER), ORDER),
4351 sqrN: (num) => num * num,
4352 addN: (lhs, rhs) => lhs + rhs,
4353 subN: (lhs, rhs) => lhs - rhs,
4354 mulN: (lhs, rhs) => lhs * rhs,
4355 inv: (num) => invert(num, ORDER),
4356 sqrt: redef.sqrt || ((n) => sqrtP(f, n)),
4357 invertBatch: (lst) => FpInvertBatch(f, lst),
4358 cmov: (a, b, c) => (c ? b : a),
4359 toBytes: (num) => (isLE ? numberToBytesLE(num, BYTES) : numberToBytesBE(num, BYTES)),
4360 fromBytes: (bytes) => {
4361 if (bytes.length !== BYTES)
4362 throw new Error(`Fp.fromBytes: expected ${BYTES}, got ${bytes.length}`);
4363 return isLE ? bytesToNumberLE(bytes) : bytesToNumberBE(bytes);
4364 },
4365 });
4366 return Object.freeze(f);
4367 }
4368 function FpSqrtEven(Fp, elm) {
4369 if (!Fp.isOdd)
4370 throw new Error(`Field doesn't have isOdd`);
4371 const root = Fp.sqrt(elm);
4372 return Fp.isOdd(root) ? Fp.neg(root) : root;
4373 }
4374 function hashToPrivateScalar(hash, groupOrder, isLE = false) {
4375 hash = ensureBytes('privateHash', hash);
4376 const hashLen = hash.length;
4377 const minLen = nLength(groupOrder).nByteLength + 8;
4378 if (minLen < 24 || hashLen < minLen || hashLen > 1024)
4379 throw new Error(`hashToPrivateScalar: expected ${minLen}-1024 bytes of input, got ${hashLen}`);
4380 const num = isLE ? bytesToNumberLE(hash) : bytesToNumberBE(hash);
4381 return mod(num, groupOrder - _1n$7) + _1n$7;
4382 }
4383
4384 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
4385 const _0n$6 = BigInt(0);
4386 const _1n$6 = BigInt(1);
4387 function wNAF(c, bits) {
4388 const constTimeNegate = (condition, item) => {
4389 const neg = item.negate();
4390 return condition ? neg : item;
4391 };
4392 const opts = (W) => {
4393 const windows = Math.ceil(bits / W) + 1;
4394 const windowSize = 2 ** (W - 1);
4395 return { windows, windowSize };
4396 };
4397 return {
4398 constTimeNegate,
4399 unsafeLadder(elm, n) {
4400 let p = c.ZERO;
4401 let d = elm;
4402 while (n > _0n$6) {
4403 if (n & _1n$6)
4404 p = p.add(d);
4405 d = d.double();
4406 n >>= _1n$6;
4407 }
4408 return p;
4409 },
4410 precomputeWindow(elm, W) {
4411 const { windows, windowSize } = opts(W);
4412 const points = [];
4413 let p = elm;
4414 let base = p;
4415 for (let window = 0; window < windows; window++) {
4416 base = p;
4417 points.push(base);
4418 for (let i = 1; i < windowSize; i++) {
4419 base = base.add(p);
4420 points.push(base);
4421 }
4422 p = base.double();
4423 }
4424 return points;
4425 },
4426 wNAF(W, precomputes, n) {
4427 const { windows, windowSize } = opts(W);
4428 let p = c.ZERO;
4429 let f = c.BASE;
4430 const mask = BigInt(2 ** W - 1);
4431 const maxNumber = 2 ** W;
4432 const shiftBy = BigInt(W);
4433 for (let window = 0; window < windows; window++) {
4434 const offset = window * windowSize;
4435 let wbits = Number(n & mask);
4436 n >>= shiftBy;
4437 if (wbits > windowSize) {
4438 wbits -= maxNumber;
4439 n += _1n$6;
4440 }
4441 const offset1 = offset;
4442 const offset2 = offset + Math.abs(wbits) - 1;
4443 const cond1 = window % 2 !== 0;
4444 const cond2 = wbits < 0;
4445 if (wbits === 0) {
4446 f = f.add(constTimeNegate(cond1, precomputes[offset1]));
4447 }
4448 else {
4449 p = p.add(constTimeNegate(cond2, precomputes[offset2]));
4450 }
4451 }
4452 return { p, f };
4453 },
4454 wNAFCached(P, precomputesMap, n, transform) {
4455 const W = P._WINDOW_SIZE || 1;
4456 let comp = precomputesMap.get(P);
4457 if (!comp) {
4458 comp = this.precomputeWindow(P, W);
4459 if (W !== 1) {
4460 precomputesMap.set(P, transform(comp));
4461 }
4462 }
4463 return this.wNAF(W, comp, n);
4464 },
4465 };
4466 }
4467 function validateBasic(curve) {
4468 validateField(curve.Fp);
4469 validateObject(curve, {
4470 n: 'bigint',
4471 h: 'bigint',
4472 Gx: 'field',
4473 Gy: 'field',
4474 }, {
4475 nBitLength: 'isSafeInteger',
4476 nByteLength: 'isSafeInteger',
4477 });
4478 return Object.freeze({
4479 ...nLength(curve.n, curve.nBitLength),
4480 ...curve,
4481 ...{ p: curve.Fp.ORDER },
4482 });
4483 }
4484
4485 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
4486 function validatePointOpts(curve) {
4487 const opts = validateBasic(curve);
4488 validateObject(opts, {
4489 a: 'field',
4490 b: 'field',
4491 }, {
4492 allowedPrivateKeyLengths: 'array',
4493 wrapPrivateKey: 'boolean',
4494 isTorsionFree: 'function',
4495 clearCofactor: 'function',
4496 allowInfinityPoint: 'boolean',
4497 fromBytes: 'function',
4498 toBytes: 'function',
4499 });
4500 const { endo, Fp, a } = opts;
4501 if (endo) {
4502 if (!Fp.eql(a, Fp.ZERO)) {
4503 throw new Error('Endomorphism can only be defined for Koblitz curves that have a=0');
4504 }
4505 if (typeof endo !== 'object' ||
4506 typeof endo.beta !== 'bigint' ||
4507 typeof endo.splitScalar !== 'function') {
4508 throw new Error('Expected endomorphism with beta: bigint and splitScalar: function');
4509 }
4510 }
4511 return Object.freeze({ ...opts });
4512 }
4513 const { bytesToNumberBE: b2n, hexToBytes: h2b } = ut;
4514 const DER = {
4515 Err: class DERErr extends Error {
4516 constructor(m = '') {
4517 super(m);
4518 }
4519 },
4520 _parseInt(data) {
4521 const { Err: E } = DER;
4522 if (data.length < 2 || data[0] !== 0x02)
4523 throw new E('Invalid signature integer tag');
4524 const len = data[1];
4525 const res = data.subarray(2, len + 2);
4526 if (!len || res.length !== len)
4527 throw new E('Invalid signature integer: wrong length');
4528 if (res[0] & 0b10000000)
4529 throw new E('Invalid signature integer: negative');
4530 if (res[0] === 0x00 && !(res[1] & 0b10000000))
4531 throw new E('Invalid signature integer: unnecessary leading zero');
4532 return { d: b2n(res), l: data.subarray(len + 2) };
4533 },
4534 toSig(hex) {
4535 const { Err: E } = DER;
4536 const data = typeof hex === 'string' ? h2b(hex) : hex;
4537 if (!(data instanceof Uint8Array))
4538 throw new Error('ui8a expected');
4539 let l = data.length;
4540 if (l < 2 || data[0] != 0x30)
4541 throw new E('Invalid signature tag');
4542 if (data[1] !== l - 2)
4543 throw new E('Invalid signature: incorrect length');
4544 const { d: r, l: sBytes } = DER._parseInt(data.subarray(2));
4545 const { d: s, l: rBytesLeft } = DER._parseInt(sBytes);
4546 if (rBytesLeft.length)
4547 throw new E('Invalid signature: left bytes after parsing');
4548 return { r, s };
4549 },
4550 hexFromSig(sig) {
4551 const slice = (s) => (Number.parseInt(s[0], 16) & 0b1000 ? '00' + s : s);
4552 const h = (num) => {
4553 const hex = num.toString(16);
4554 return hex.length & 1 ? `0${hex}` : hex;
4555 };
4556 const s = slice(h(sig.s));
4557 const r = slice(h(sig.r));
4558 const shl = s.length / 2;
4559 const rhl = r.length / 2;
4560 const sl = h(shl);
4561 const rl = h(rhl);
4562 return `30${h(rhl + shl + 4)}02${rl}${r}02${sl}${s}`;
4563 },
4564 };
4565 const _0n$5 = BigInt(0), _1n$5 = BigInt(1), _2n$4 = BigInt(2), _3n = BigInt(3), _4n = BigInt(4);
4566 function weierstrassPoints(opts) {
4567 const CURVE = validatePointOpts(opts);
4568 const { Fp } = CURVE;
4569 const toBytes = CURVE.toBytes ||
4570 ((c, point, isCompressed) => {
4571 const a = point.toAffine();
4572 return concatBytes(Uint8Array.from([0x04]), Fp.toBytes(a.x), Fp.toBytes(a.y));
4573 });
4574 const fromBytes = CURVE.fromBytes ||
4575 ((bytes) => {
4576 const tail = bytes.subarray(1);
4577 const x = Fp.fromBytes(tail.subarray(0, Fp.BYTES));
4578 const y = Fp.fromBytes(tail.subarray(Fp.BYTES, 2 * Fp.BYTES));
4579 return { x, y };
4580 });
4581 function weierstrassEquation(x) {
4582 const { a, b } = CURVE;
4583 const x2 = Fp.sqr(x);
4584 const x3 = Fp.mul(x2, x);
4585 return Fp.add(Fp.add(x3, Fp.mul(x, a)), b);
4586 }
4587 if (!Fp.eql(Fp.sqr(CURVE.Gy), weierstrassEquation(CURVE.Gx)))
4588 throw new Error('bad generator point: equation left != right');
4589 function isWithinCurveOrder(num) {
4590 return typeof num === 'bigint' && _0n$5 < num && num < CURVE.n;
4591 }
4592 function assertGE(num) {
4593 if (!isWithinCurveOrder(num))
4594 throw new Error('Expected valid bigint: 0 < bigint < curve.n');
4595 }
4596 function normPrivateKeyToScalar(key) {
4597 const { allowedPrivateKeyLengths: lengths, nByteLength, wrapPrivateKey, n } = CURVE;
4598 if (lengths && typeof key !== 'bigint') {
4599 if (key instanceof Uint8Array)
4600 key = bytesToHex(key);
4601 if (typeof key !== 'string' || !lengths.includes(key.length))
4602 throw new Error('Invalid key');
4603 key = key.padStart(nByteLength * 2, '0');
4604 }
4605 let num;
4606 try {
4607 num =
4608 typeof key === 'bigint'
4609 ? key
4610 : bytesToNumberBE(ensureBytes('private key', key, nByteLength));
4611 }
4612 catch (error) {
4613 throw new Error(`private key must be ${nByteLength} bytes, hex or bigint, not ${typeof key}`);
4614 }
4615 if (wrapPrivateKey)
4616 num = mod(num, n);
4617 assertGE(num);
4618 return num;
4619 }
4620 const pointPrecomputes = new Map();
4621 function assertPrjPoint(other) {
4622 if (!(other instanceof Point))
4623 throw new Error('ProjectivePoint expected');
4624 }
4625 class Point {
4626 constructor(px, py, pz) {
4627 this.px = px;
4628 this.py = py;
4629 this.pz = pz;
4630 if (px == null || !Fp.isValid(px))
4631 throw new Error('x required');
4632 if (py == null || !Fp.isValid(py))
4633 throw new Error('y required');
4634 if (pz == null || !Fp.isValid(pz))
4635 throw new Error('z required');
4636 }
4637 static fromAffine(p) {
4638 const { x, y } = p || {};
4639 if (!p || !Fp.isValid(x) || !Fp.isValid(y))
4640 throw new Error('invalid affine point');
4641 if (p instanceof Point)
4642 throw new Error('projective point not allowed');
4643 const is0 = (i) => Fp.eql(i, Fp.ZERO);
4644 if (is0(x) && is0(y))
4645 return Point.ZERO;
4646 return new Point(x, y, Fp.ONE);
4647 }
4648 get x() {
4649 return this.toAffine().x;
4650 }
4651 get y() {
4652 return this.toAffine().y;
4653 }
4654 static normalizeZ(points) {
4655 const toInv = Fp.invertBatch(points.map((p) => p.pz));
4656 return points.map((p, i) => p.toAffine(toInv[i])).map(Point.fromAffine);
4657 }
4658 static fromHex(hex) {
4659 const P = Point.fromAffine(fromBytes(ensureBytes('pointHex', hex)));
4660 P.assertValidity();
4661 return P;
4662 }
4663 static fromPrivateKey(privateKey) {
4664 return Point.BASE.multiply(normPrivateKeyToScalar(privateKey));
4665 }
4666 _setWindowSize(windowSize) {
4667 this._WINDOW_SIZE = windowSize;
4668 pointPrecomputes.delete(this);
4669 }
4670 assertValidity() {
4671 if (this.is0()) {
4672 if (CURVE.allowInfinityPoint)
4673 return;
4674 throw new Error('bad point: ZERO');
4675 }
4676 const { x, y } = this.toAffine();
4677 if (!Fp.isValid(x) || !Fp.isValid(y))
4678 throw new Error('bad point: x or y not FE');
4679 const left = Fp.sqr(y);
4680 const right = weierstrassEquation(x);
4681 if (!Fp.eql(left, right))
4682 throw new Error('bad point: equation left != right');
4683 if (!this.isTorsionFree())
4684 throw new Error('bad point: not in prime-order subgroup');
4685 }
4686 hasEvenY() {
4687 const { y } = this.toAffine();
4688 if (Fp.isOdd)
4689 return !Fp.isOdd(y);
4690 throw new Error("Field doesn't support isOdd");
4691 }
4692 equals(other) {
4693 assertPrjPoint(other);
4694 const { px: X1, py: Y1, pz: Z1 } = this;
4695 const { px: X2, py: Y2, pz: Z2 } = other;
4696 const U1 = Fp.eql(Fp.mul(X1, Z2), Fp.mul(X2, Z1));
4697 const U2 = Fp.eql(Fp.mul(Y1, Z2), Fp.mul(Y2, Z1));
4698 return U1 && U2;
4699 }
4700 negate() {
4701 return new Point(this.px, Fp.neg(this.py), this.pz);
4702 }
4703 double() {
4704 const { a, b } = CURVE;
4705 const b3 = Fp.mul(b, _3n);
4706 const { px: X1, py: Y1, pz: Z1 } = this;
4707 let X3 = Fp.ZERO, Y3 = Fp.ZERO, Z3 = Fp.ZERO;
4708 let t0 = Fp.mul(X1, X1);
4709 let t1 = Fp.mul(Y1, Y1);
4710 let t2 = Fp.mul(Z1, Z1);
4711 let t3 = Fp.mul(X1, Y1);
4712 t3 = Fp.add(t3, t3);
4713 Z3 = Fp.mul(X1, Z1);
4714 Z3 = Fp.add(Z3, Z3);
4715 X3 = Fp.mul(a, Z3);
4716 Y3 = Fp.mul(b3, t2);
4717 Y3 = Fp.add(X3, Y3);
4718 X3 = Fp.sub(t1, Y3);
4719 Y3 = Fp.add(t1, Y3);
4720 Y3 = Fp.mul(X3, Y3);
4721 X3 = Fp.mul(t3, X3);
4722 Z3 = Fp.mul(b3, Z3);
4723 t2 = Fp.mul(a, t2);
4724 t3 = Fp.sub(t0, t2);
4725 t3 = Fp.mul(a, t3);
4726 t3 = Fp.add(t3, Z3);
4727 Z3 = Fp.add(t0, t0);
4728 t0 = Fp.add(Z3, t0);
4729 t0 = Fp.add(t0, t2);
4730 t0 = Fp.mul(t0, t3);
4731 Y3 = Fp.add(Y3, t0);
4732 t2 = Fp.mul(Y1, Z1);
4733 t2 = Fp.add(t2, t2);
4734 t0 = Fp.mul(t2, t3);
4735 X3 = Fp.sub(X3, t0);
4736 Z3 = Fp.mul(t2, t1);
4737 Z3 = Fp.add(Z3, Z3);
4738 Z3 = Fp.add(Z3, Z3);
4739 return new Point(X3, Y3, Z3);
4740 }
4741 add(other) {
4742 assertPrjPoint(other);
4743 const { px: X1, py: Y1, pz: Z1 } = this;
4744 const { px: X2, py: Y2, pz: Z2 } = other;
4745 let X3 = Fp.ZERO, Y3 = Fp.ZERO, Z3 = Fp.ZERO;
4746 const a = CURVE.a;
4747 const b3 = Fp.mul(CURVE.b, _3n);
4748 let t0 = Fp.mul(X1, X2);
4749 let t1 = Fp.mul(Y1, Y2);
4750 let t2 = Fp.mul(Z1, Z2);
4751 let t3 = Fp.add(X1, Y1);
4752 let t4 = Fp.add(X2, Y2);
4753 t3 = Fp.mul(t3, t4);
4754 t4 = Fp.add(t0, t1);
4755 t3 = Fp.sub(t3, t4);
4756 t4 = Fp.add(X1, Z1);
4757 let t5 = Fp.add(X2, Z2);
4758 t4 = Fp.mul(t4, t5);
4759 t5 = Fp.add(t0, t2);
4760 t4 = Fp.sub(t4, t5);
4761 t5 = Fp.add(Y1, Z1);
4762 X3 = Fp.add(Y2, Z2);
4763 t5 = Fp.mul(t5, X3);
4764 X3 = Fp.add(t1, t2);
4765 t5 = Fp.sub(t5, X3);
4766 Z3 = Fp.mul(a, t4);
4767 X3 = Fp.mul(b3, t2);
4768 Z3 = Fp.add(X3, Z3);
4769 X3 = Fp.sub(t1, Z3);
4770 Z3 = Fp.add(t1, Z3);
4771 Y3 = Fp.mul(X3, Z3);
4772 t1 = Fp.add(t0, t0);
4773 t1 = Fp.add(t1, t0);
4774 t2 = Fp.mul(a, t2);
4775 t4 = Fp.mul(b3, t4);
4776 t1 = Fp.add(t1, t2);
4777 t2 = Fp.sub(t0, t2);
4778 t2 = Fp.mul(a, t2);
4779 t4 = Fp.add(t4, t2);
4780 t0 = Fp.mul(t1, t4);
4781 Y3 = Fp.add(Y3, t0);
4782 t0 = Fp.mul(t5, t4);
4783 X3 = Fp.mul(t3, X3);
4784 X3 = Fp.sub(X3, t0);
4785 t0 = Fp.mul(t3, t1);
4786 Z3 = Fp.mul(t5, Z3);
4787 Z3 = Fp.add(Z3, t0);
4788 return new Point(X3, Y3, Z3);
4789 }
4790 subtract(other) {
4791 return this.add(other.negate());
4792 }
4793 is0() {
4794 return this.equals(Point.ZERO);
4795 }
4796 wNAF(n) {
4797 return wnaf.wNAFCached(this, pointPrecomputes, n, (comp) => {
4798 const toInv = Fp.invertBatch(comp.map((p) => p.pz));
4799 return comp.map((p, i) => p.toAffine(toInv[i])).map(Point.fromAffine);
4800 });
4801 }
4802 multiplyUnsafe(n) {
4803 const I = Point.ZERO;
4804 if (n === _0n$5)
4805 return I;
4806 assertGE(n);
4807 if (n === _1n$5)
4808 return this;
4809 const { endo } = CURVE;
4810 if (!endo)
4811 return wnaf.unsafeLadder(this, n);
4812 let { k1neg, k1, k2neg, k2 } = endo.splitScalar(n);
4813 let k1p = I;
4814 let k2p = I;
4815 let d = this;
4816 while (k1 > _0n$5 || k2 > _0n$5) {
4817 if (k1 & _1n$5)
4818 k1p = k1p.add(d);
4819 if (k2 & _1n$5)
4820 k2p = k2p.add(d);
4821 d = d.double();
4822 k1 >>= _1n$5;
4823 k2 >>= _1n$5;
4824 }
4825 if (k1neg)
4826 k1p = k1p.negate();
4827 if (k2neg)
4828 k2p = k2p.negate();
4829 k2p = new Point(Fp.mul(k2p.px, endo.beta), k2p.py, k2p.pz);
4830 return k1p.add(k2p);
4831 }
4832 multiply(scalar) {
4833 assertGE(scalar);
4834 let n = scalar;
4835 let point, fake;
4836 const { endo } = CURVE;
4837 if (endo) {
4838 const { k1neg, k1, k2neg, k2 } = endo.splitScalar(n);
4839 let { p: k1p, f: f1p } = this.wNAF(k1);
4840 let { p: k2p, f: f2p } = this.wNAF(k2);
4841 k1p = wnaf.constTimeNegate(k1neg, k1p);
4842 k2p = wnaf.constTimeNegate(k2neg, k2p);
4843 k2p = new Point(Fp.mul(k2p.px, endo.beta), k2p.py, k2p.pz);
4844 point = k1p.add(k2p);
4845 fake = f1p.add(f2p);
4846 }
4847 else {
4848 const { p, f } = this.wNAF(n);
4849 point = p;
4850 fake = f;
4851 }
4852 return Point.normalizeZ([point, fake])[0];
4853 }
4854 multiplyAndAddUnsafe(Q, a, b) {
4855 const G = Point.BASE;
4856 const mul = (P, a
4857 ) => (a === _0n$5 || a === _1n$5 || !P.equals(G) ? P.multiplyUnsafe(a) : P.multiply(a));
4858 const sum = mul(this, a).add(mul(Q, b));
4859 return sum.is0() ? undefined : sum;
4860 }
4861 toAffine(iz) {
4862 const { px: x, py: y, pz: z } = this;
4863 const is0 = this.is0();
4864 if (iz == null)
4865 iz = is0 ? Fp.ONE : Fp.inv(z);
4866 const ax = Fp.mul(x, iz);
4867 const ay = Fp.mul(y, iz);
4868 const zz = Fp.mul(z, iz);
4869 if (is0)
4870 return { x: Fp.ZERO, y: Fp.ZERO };
4871 if (!Fp.eql(zz, Fp.ONE))
4872 throw new Error('invZ was invalid');
4873 return { x: ax, y: ay };
4874 }
4875 isTorsionFree() {
4876 const { h: cofactor, isTorsionFree } = CURVE;
4877 if (cofactor === _1n$5)
4878 return true;
4879 if (isTorsionFree)
4880 return isTorsionFree(Point, this);
4881 throw new Error('isTorsionFree() has not been declared for the elliptic curve');
4882 }
4883 clearCofactor() {
4884 const { h: cofactor, clearCofactor } = CURVE;
4885 if (cofactor === _1n$5)
4886 return this;
4887 if (clearCofactor)
4888 return clearCofactor(Point, this);
4889 return this.multiplyUnsafe(CURVE.h);
4890 }
4891 toRawBytes(isCompressed = true) {
4892 this.assertValidity();
4893 return toBytes(Point, this, isCompressed);
4894 }
4895 toHex(isCompressed = true) {
4896 return bytesToHex(this.toRawBytes(isCompressed));
4897 }
4898 }
4899 Point.BASE = new Point(CURVE.Gx, CURVE.Gy, Fp.ONE);
4900 Point.ZERO = new Point(Fp.ZERO, Fp.ONE, Fp.ZERO);
4901 const _bits = CURVE.nBitLength;
4902 const wnaf = wNAF(Point, CURVE.endo ? Math.ceil(_bits / 2) : _bits);
4903 return {
4904 CURVE,
4905 ProjectivePoint: Point,
4906 normPrivateKeyToScalar,
4907 weierstrassEquation,
4908 isWithinCurveOrder,
4909 };
4910 }
4911 function validateOpts$2(curve) {
4912 const opts = validateBasic(curve);
4913 validateObject(opts, {
4914 hash: 'hash',
4915 hmac: 'function',
4916 randomBytes: 'function',
4917 }, {
4918 bits2int: 'function',
4919 bits2int_modN: 'function',
4920 lowS: 'boolean',
4921 });
4922 return Object.freeze({ lowS: true, ...opts });
4923 }
4924 function weierstrass(curveDef) {
4925 const CURVE = validateOpts$2(curveDef);
4926 const { Fp, n: CURVE_ORDER } = CURVE;
4927 const compressedLen = Fp.BYTES + 1;
4928 const uncompressedLen = 2 * Fp.BYTES + 1;
4929 function isValidFieldElement(num) {
4930 return _0n$5 < num && num < Fp.ORDER;
4931 }
4932 function modN(a) {
4933 return mod(a, CURVE_ORDER);
4934 }
4935 function invN(a) {
4936 return invert(a, CURVE_ORDER);
4937 }
4938 const { ProjectivePoint: Point, normPrivateKeyToScalar, weierstrassEquation, isWithinCurveOrder, } = weierstrassPoints({
4939 ...CURVE,
4940 toBytes(c, point, isCompressed) {
4941 const a = point.toAffine();
4942 const x = Fp.toBytes(a.x);
4943 const cat = concatBytes;
4944 if (isCompressed) {
4945 return cat(Uint8Array.from([point.hasEvenY() ? 0x02 : 0x03]), x);
4946 }
4947 else {
4948 return cat(Uint8Array.from([0x04]), x, Fp.toBytes(a.y));
4949 }
4950 },
4951 fromBytes(bytes) {
4952 const len = bytes.length;
4953 const head = bytes[0];
4954 const tail = bytes.subarray(1);
4955 if (len === compressedLen && (head === 0x02 || head === 0x03)) {
4956 const x = bytesToNumberBE(tail);
4957 if (!isValidFieldElement(x))
4958 throw new Error('Point is not on curve');
4959 const y2 = weierstrassEquation(x);
4960 let y = Fp.sqrt(y2);
4961 const isYOdd = (y & _1n$5) === _1n$5;
4962 const isHeadOdd = (head & 1) === 1;
4963 if (isHeadOdd !== isYOdd)
4964 y = Fp.neg(y);
4965 return { x, y };
4966 }
4967 else if (len === uncompressedLen && head === 0x04) {
4968 const x = Fp.fromBytes(tail.subarray(0, Fp.BYTES));
4969 const y = Fp.fromBytes(tail.subarray(Fp.BYTES, 2 * Fp.BYTES));
4970 return { x, y };
4971 }
4972 else {
4973 throw new Error(`Point of length ${len} was invalid. Expected ${compressedLen} compressed bytes or ${uncompressedLen} uncompressed bytes`);
4974 }
4975 },
4976 });
4977 const numToNByteStr = (num) => bytesToHex(numberToBytesBE(num, CURVE.nByteLength));
4978 function isBiggerThanHalfOrder(number) {
4979 const HALF = CURVE_ORDER >> _1n$5;
4980 return number > HALF;
4981 }
4982 function normalizeS(s) {
4983 return isBiggerThanHalfOrder(s) ? modN(-s) : s;
4984 }
4985 const slcNum = (b, from, to) => bytesToNumberBE(b.slice(from, to));
4986 class Signature {
4987 constructor(r, s, recovery) {
4988 this.r = r;
4989 this.s = s;
4990 this.recovery = recovery;
4991 this.assertValidity();
4992 }
4993 static fromCompact(hex) {
4994 const l = CURVE.nByteLength;
4995 hex = ensureBytes('compactSignature', hex, l * 2);
4996 return new Signature(slcNum(hex, 0, l), slcNum(hex, l, 2 * l));
4997 }
4998 static fromDER(hex) {
4999 const { r, s } = DER.toSig(ensureBytes('DER', hex));
5000 return new Signature(r, s);
5001 }
5002 assertValidity() {
5003 if (!isWithinCurveOrder(this.r))
5004 throw new Error('r must be 0 < r < CURVE.n');
5005 if (!isWithinCurveOrder(this.s))
5006 throw new Error('s must be 0 < s < CURVE.n');
5007 }
5008 addRecoveryBit(recovery) {
5009 return new Signature(this.r, this.s, recovery);
5010 }
5011 recoverPublicKey(msgHash) {
5012 const { r, s, recovery: rec } = this;
5013 const h = bits2int_modN(ensureBytes('msgHash', msgHash));
5014 if (rec == null || ![0, 1, 2, 3].includes(rec))
5015 throw new Error('recovery id invalid');
5016 const radj = rec === 2 || rec === 3 ? r + CURVE.n : r;
5017 if (radj >= Fp.ORDER)
5018 throw new Error('recovery id 2 or 3 invalid');
5019 const prefix = (rec & 1) === 0 ? '02' : '03';
5020 const R = Point.fromHex(prefix + numToNByteStr(radj));
5021 const ir = invN(radj);
5022 const u1 = modN(-h * ir);
5023 const u2 = modN(s * ir);
5024 const Q = Point.BASE.multiplyAndAddUnsafe(R, u1, u2);
5025 if (!Q)
5026 throw new Error('point at infinify');
5027 Q.assertValidity();
5028 return Q;
5029 }
5030 hasHighS() {
5031 return isBiggerThanHalfOrder(this.s);
5032 }
5033 normalizeS() {
5034 return this.hasHighS() ? new Signature(this.r, modN(-this.s), this.recovery) : this;
5035 }
5036 toDERRawBytes() {
5037 return hexToBytes(this.toDERHex());
5038 }
5039 toDERHex() {
5040 return DER.hexFromSig({ r: this.r, s: this.s });
5041 }
5042 toCompactRawBytes() {
5043 return hexToBytes(this.toCompactHex());
5044 }
5045 toCompactHex() {
5046 return numToNByteStr(this.r) + numToNByteStr(this.s);
5047 }
5048 }
5049 const utils = {
5050 isValidPrivateKey(privateKey) {
5051 try {
5052 normPrivateKeyToScalar(privateKey);
5053 return true;
5054 }
5055 catch (error) {
5056 return false;
5057 }
5058 },
5059 normPrivateKeyToScalar: normPrivateKeyToScalar,
5060 randomPrivateKey: () => {
5061 const rand = CURVE.randomBytes(Fp.BYTES + 8);
5062 const num = hashToPrivateScalar(rand, CURVE_ORDER);
5063 return numberToBytesBE(num, CURVE.nByteLength);
5064 },
5065 precompute(windowSize = 8, point = Point.BASE) {
5066 point._setWindowSize(windowSize);
5067 point.multiply(BigInt(3));
5068 return point;
5069 },
5070 };
5071 function getPublicKey(privateKey, isCompressed = true) {
5072 return Point.fromPrivateKey(privateKey).toRawBytes(isCompressed);
5073 }
5074 function isProbPub(item) {
5075 const arr = item instanceof Uint8Array;
5076 const str = typeof item === 'string';
5077 const len = (arr || str) && item.length;
5078 if (arr)
5079 return len === compressedLen || len === uncompressedLen;
5080 if (str)
5081 return len === 2 * compressedLen || len === 2 * uncompressedLen;
5082 if (item instanceof Point)
5083 return true;
5084 return false;
5085 }
5086 function getSharedSecret(privateA, publicB, isCompressed = true) {
5087 if (isProbPub(privateA))
5088 throw new Error('first arg must be private key');
5089 if (!isProbPub(publicB))
5090 throw new Error('second arg must be public key');
5091 const b = Point.fromHex(publicB);
5092 return b.multiply(normPrivateKeyToScalar(privateA)).toRawBytes(isCompressed);
5093 }
5094 const bits2int = CURVE.bits2int ||
5095 function (bytes) {
5096 const num = bytesToNumberBE(bytes);
5097 const delta = bytes.length * 8 - CURVE.nBitLength;
5098 return delta > 0 ? num >> BigInt(delta) : num;
5099 };
5100 const bits2int_modN = CURVE.bits2int_modN ||
5101 function (bytes) {
5102 return modN(bits2int(bytes));
5103 };
5104 const ORDER_MASK = bitMask(CURVE.nBitLength);
5105 function int2octets(num) {
5106 if (typeof num !== 'bigint')
5107 throw new Error('bigint expected');
5108 if (!(_0n$5 <= num && num < ORDER_MASK))
5109 throw new Error(`bigint expected < 2^${CURVE.nBitLength}`);
5110 return numberToBytesBE(num, CURVE.nByteLength);
5111 }
5112 function prepSig(msgHash, privateKey, opts = defaultSigOpts) {
5113 if (['recovered', 'canonical'].some((k) => k in opts))
5114 throw new Error('sign() legacy options not supported');
5115 const { hash, randomBytes } = CURVE;
5116 let { lowS, prehash, extraEntropy: ent } = opts;
5117 if (lowS == null)
5118 lowS = true;
5119 msgHash = ensureBytes('msgHash', msgHash);
5120 if (prehash)
5121 msgHash = ensureBytes('prehashed msgHash', hash(msgHash));
5122 const h1int = bits2int_modN(msgHash);
5123 const d = normPrivateKeyToScalar(privateKey);
5124 const seedArgs = [int2octets(d), int2octets(h1int)];
5125 if (ent != null) {
5126 const e = ent === true ? randomBytes(Fp.BYTES) : ent;
5127 seedArgs.push(ensureBytes('extraEntropy', e, Fp.BYTES));
5128 }
5129 const seed = concatBytes(...seedArgs);
5130 const m = h1int;
5131 function k2sig(kBytes) {
5132 const k = bits2int(kBytes);
5133 if (!isWithinCurveOrder(k))
5134 return;
5135 const ik = invN(k);
5136 const q = Point.BASE.multiply(k).toAffine();
5137 const r = modN(q.x);
5138 if (r === _0n$5)
5139 return;
5140 const s = modN(ik * modN(m + r * d));
5141 if (s === _0n$5)
5142 return;
5143 let recovery = (q.x === r ? 0 : 2) | Number(q.y & _1n$5);
5144 let normS = s;
5145 if (lowS && isBiggerThanHalfOrder(s)) {
5146 normS = normalizeS(s);
5147 recovery ^= 1;
5148 }
5149 return new Signature(r, normS, recovery);
5150 }
5151 return { seed, k2sig };
5152 }
5153 const defaultSigOpts = { lowS: CURVE.lowS, prehash: false };
5154 const defaultVerOpts = { lowS: CURVE.lowS, prehash: false };
5155 function sign(msgHash, privKey, opts = defaultSigOpts) {
5156 const { seed, k2sig } = prepSig(msgHash, privKey, opts);
5157 const C = CURVE;
5158 const drbg = createHmacDrbg(C.hash.outputLen, C.nByteLength, C.hmac);
5159 return drbg(seed, k2sig);
5160 }
5161 Point.BASE._setWindowSize(8);
5162 function verify(signature, msgHash, publicKey, opts = defaultVerOpts) {
5163 const sg = signature;
5164 msgHash = ensureBytes('msgHash', msgHash);
5165 publicKey = ensureBytes('publicKey', publicKey);
5166 if ('strict' in opts)
5167 throw new Error('options.strict was renamed to lowS');
5168 const { lowS, prehash } = opts;
5169 let _sig = undefined;
5170 let P;
5171 try {
5172 if (typeof sg === 'string' || sg instanceof Uint8Array) {
5173 try {
5174 _sig = Signature.fromDER(sg);
5175 }
5176 catch (derError) {
5177 if (!(derError instanceof DER.Err))
5178 throw derError;
5179 _sig = Signature.fromCompact(sg);
5180 }
5181 }
5182 else if (typeof sg === 'object' && typeof sg.r === 'bigint' && typeof sg.s === 'bigint') {
5183 const { r, s } = sg;
5184 _sig = new Signature(r, s);
5185 }
5186 else {
5187 throw new Error('PARSE');
5188 }
5189 P = Point.fromHex(publicKey);
5190 }
5191 catch (error) {
5192 if (error.message === 'PARSE')
5193 throw new Error(`signature must be Signature instance, Uint8Array or hex string`);
5194 return false;
5195 }
5196 if (lowS && _sig.hasHighS())
5197 return false;
5198 if (prehash)
5199 msgHash = CURVE.hash(msgHash);
5200 const { r, s } = _sig;
5201 const h = bits2int_modN(msgHash);
5202 const is = invN(s);
5203 const u1 = modN(h * is);
5204 const u2 = modN(r * is);
5205 const R = Point.BASE.multiplyAndAddUnsafe(P, u1, u2)?.toAffine();
5206 if (!R)
5207 return false;
5208 const v = modN(R.x);
5209 return v === r;
5210 }
5211 return {
5212 CURVE,
5213 getPublicKey,
5214 getSharedSecret,
5215 sign,
5216 verify,
5217 ProjectivePoint: Point,
5218 Signature,
5219 utils,
5220 };
5221 }
5222 function SWUFpSqrtRatio(Fp, Z) {
5223 const q = Fp.ORDER;
5224 let l = _0n$5;
5225 for (let o = q - _1n$5; o % _2n$4 === _0n$5; o /= _2n$4)
5226 l += _1n$5;
5227 const c1 = l;
5228 const _2n_pow_c1_1 = _2n$4 << (c1 - _1n$5 - _1n$5);
5229 const _2n_pow_c1 = _2n_pow_c1_1 * _2n$4;
5230 const c2 = (q - _1n$5) / _2n_pow_c1;
5231 const c3 = (c2 - _1n$5) / _2n$4;
5232 const c4 = _2n_pow_c1 - _1n$5;
5233 const c5 = _2n_pow_c1_1;
5234 const c6 = Fp.pow(Z, c2);
5235 const c7 = Fp.pow(Z, (c2 + _1n$5) / _2n$4);
5236 let sqrtRatio = (u, v) => {
5237 let tv1 = c6;
5238 let tv2 = Fp.pow(v, c4);
5239 let tv3 = Fp.sqr(tv2);
5240 tv3 = Fp.mul(tv3, v);
5241 let tv5 = Fp.mul(u, tv3);
5242 tv5 = Fp.pow(tv5, c3);
5243 tv5 = Fp.mul(tv5, tv2);
5244 tv2 = Fp.mul(tv5, v);
5245 tv3 = Fp.mul(tv5, u);
5246 let tv4 = Fp.mul(tv3, tv2);
5247 tv5 = Fp.pow(tv4, c5);
5248 let isQR = Fp.eql(tv5, Fp.ONE);
5249 tv2 = Fp.mul(tv3, c7);
5250 tv5 = Fp.mul(tv4, tv1);
5251 tv3 = Fp.cmov(tv2, tv3, isQR);
5252 tv4 = Fp.cmov(tv5, tv4, isQR);
5253 for (let i = c1; i > _1n$5; i--) {
5254 let tv5 = i - _2n$4;
5255 tv5 = _2n$4 << (tv5 - _1n$5);
5256 let tvv5 = Fp.pow(tv4, tv5);
5257 const e1 = Fp.eql(tvv5, Fp.ONE);
5258 tv2 = Fp.mul(tv3, tv1);
5259 tv1 = Fp.mul(tv1, tv1);
5260 tvv5 = Fp.mul(tv4, tv1);
5261 tv3 = Fp.cmov(tv2, tv3, e1);
5262 tv4 = Fp.cmov(tvv5, tv4, e1);
5263 }
5264 return { isValid: isQR, value: tv3 };
5265 };
5266 if (Fp.ORDER % _4n === _3n) {
5267 const c1 = (Fp.ORDER - _3n) / _4n;
5268 const c2 = Fp.sqrt(Fp.neg(Z));
5269 sqrtRatio = (u, v) => {
5270 let tv1 = Fp.sqr(v);
5271 const tv2 = Fp.mul(u, v);
5272 tv1 = Fp.mul(tv1, tv2);
5273 let y1 = Fp.pow(tv1, c1);
5274 y1 = Fp.mul(y1, tv2);
5275 const y2 = Fp.mul(y1, c2);
5276 const tv3 = Fp.mul(Fp.sqr(y1), v);
5277 const isQR = Fp.eql(tv3, u);
5278 let y = Fp.cmov(y2, y1, isQR);
5279 return { isValid: isQR, value: y };
5280 };
5281 }
5282 return sqrtRatio;
5283 }
5284 function mapToCurveSimpleSWU(Fp, opts) {
5285 validateField(Fp);
5286 if (!Fp.isValid(opts.A) || !Fp.isValid(opts.B) || !Fp.isValid(opts.Z))
5287 throw new Error('mapToCurveSimpleSWU: invalid opts');
5288 const sqrtRatio = SWUFpSqrtRatio(Fp, opts.Z);
5289 if (!Fp.isOdd)
5290 throw new Error('Fp.isOdd is not implemented!');
5291 return (u) => {
5292 let tv1, tv2, tv3, tv4, tv5, tv6, x, y;
5293 tv1 = Fp.sqr(u);
5294 tv1 = Fp.mul(tv1, opts.Z);
5295 tv2 = Fp.sqr(tv1);
5296 tv2 = Fp.add(tv2, tv1);
5297 tv3 = Fp.add(tv2, Fp.ONE);
5298 tv3 = Fp.mul(tv3, opts.B);
5299 tv4 = Fp.cmov(opts.Z, Fp.neg(tv2), !Fp.eql(tv2, Fp.ZERO));
5300 tv4 = Fp.mul(tv4, opts.A);
5301 tv2 = Fp.sqr(tv3);
5302 tv6 = Fp.sqr(tv4);
5303 tv5 = Fp.mul(tv6, opts.A);
5304 tv2 = Fp.add(tv2, tv5);
5305 tv2 = Fp.mul(tv2, tv3);
5306 tv6 = Fp.mul(tv6, tv4);
5307 tv5 = Fp.mul(tv6, opts.B);
5308 tv2 = Fp.add(tv2, tv5);
5309 x = Fp.mul(tv1, tv3);
5310 const { isValid, value } = sqrtRatio(tv2, tv6);
5311 y = Fp.mul(tv1, u);
5312 y = Fp.mul(y, value);
5313 x = Fp.cmov(x, tv3, isValid);
5314 y = Fp.cmov(y, value, isValid);
5315 const e1 = Fp.isOdd(u) === Fp.isOdd(y);
5316 y = Fp.cmov(Fp.neg(y), y, e1);
5317 x = Fp.div(x, tv4);
5318 return { x, y };
5319 };
5320 }
5321
5322 function validateDST(dst) {
5323 if (dst instanceof Uint8Array)
5324 return dst;
5325 if (typeof dst === 'string')
5326 return utf8ToBytes(dst);
5327 throw new Error('DST must be Uint8Array or string');
5328 }
5329 const os2ip = bytesToNumberBE;
5330 function i2osp(value, length) {
5331 if (value < 0 || value >= 1 << (8 * length)) {
5332 throw new Error(`bad I2OSP call: value=${value} length=${length}`);
5333 }
5334 const res = Array.from({ length }).fill(0);
5335 for (let i = length - 1; i >= 0; i--) {
5336 res[i] = value & 0xff;
5337 value >>>= 8;
5338 }
5339 return new Uint8Array(res);
5340 }
5341 function strxor(a, b) {
5342 const arr = new Uint8Array(a.length);
5343 for (let i = 0; i < a.length; i++) {
5344 arr[i] = a[i] ^ b[i];
5345 }
5346 return arr;
5347 }
5348 function isBytes(item) {
5349 if (!(item instanceof Uint8Array))
5350 throw new Error('Uint8Array expected');
5351 }
5352 function isNum(item) {
5353 if (!Number.isSafeInteger(item))
5354 throw new Error('number expected');
5355 }
5356 function expand_message_xmd(msg, DST, lenInBytes, H) {
5357 isBytes(msg);
5358 isBytes(DST);
5359 isNum(lenInBytes);
5360 if (DST.length > 255)
5361 DST = H(concatBytes(utf8ToBytes('H2C-OVERSIZE-DST-'), DST));
5362 const { outputLen: b_in_bytes, blockLen: r_in_bytes } = H;
5363 const ell = Math.ceil(lenInBytes / b_in_bytes);
5364 if (ell > 255)
5365 throw new Error('Invalid xmd length');
5366 const DST_prime = concatBytes(DST, i2osp(DST.length, 1));
5367 const Z_pad = i2osp(0, r_in_bytes);
5368 const l_i_b_str = i2osp(lenInBytes, 2);
5369 const b = new Array(ell);
5370 const b_0 = H(concatBytes(Z_pad, msg, l_i_b_str, i2osp(0, 1), DST_prime));
5371 b[0] = H(concatBytes(b_0, i2osp(1, 1), DST_prime));
5372 for (let i = 1; i <= ell; i++) {
5373 const args = [strxor(b_0, b[i - 1]), i2osp(i + 1, 1), DST_prime];
5374 b[i] = H(concatBytes(...args));
5375 }
5376 const pseudo_random_bytes = concatBytes(...b);
5377 return pseudo_random_bytes.slice(0, lenInBytes);
5378 }
5379 function expand_message_xof(msg, DST, lenInBytes, k, H) {
5380 isBytes(msg);
5381 isBytes(DST);
5382 isNum(lenInBytes);
5383 if (DST.length > 255) {
5384 const dkLen = Math.ceil((2 * k) / 8);
5385 DST = H.create({ dkLen }).update(utf8ToBytes('H2C-OVERSIZE-DST-')).update(DST).digest();
5386 }
5387 if (lenInBytes > 65535 || DST.length > 255)
5388 throw new Error('expand_message_xof: invalid lenInBytes');
5389 return (H.create({ dkLen: lenInBytes })
5390 .update(msg)
5391 .update(i2osp(lenInBytes, 2))
5392 .update(DST)
5393 .update(i2osp(DST.length, 1))
5394 .digest());
5395 }
5396 function hash_to_field(msg, count, options) {
5397 validateObject(options, {
5398 DST: 'string',
5399 p: 'bigint',
5400 m: 'isSafeInteger',
5401 k: 'isSafeInteger',
5402 hash: 'hash',
5403 });
5404 const { p, k, m, hash, expand, DST: _DST } = options;
5405 isBytes(msg);
5406 isNum(count);
5407 const DST = validateDST(_DST);
5408 const log2p = p.toString(2).length;
5409 const L = Math.ceil((log2p + k) / 8);
5410 const len_in_bytes = count * m * L;
5411 let prb;
5412 if (expand === 'xmd') {
5413 prb = expand_message_xmd(msg, DST, len_in_bytes, hash);
5414 }
5415 else if (expand === 'xof') {
5416 prb = expand_message_xof(msg, DST, len_in_bytes, k, hash);
5417 }
5418 else if (expand === '_internal_pass') {
5419 prb = msg;
5420 }
5421 else {
5422 throw new Error('expand must be "xmd" or "xof"');
5423 }
5424 const u = new Array(count);
5425 for (let i = 0; i < count; i++) {
5426 const e = new Array(m);
5427 for (let j = 0; j < m; j++) {
5428 const elm_offset = L * (j + i * m);
5429 const tv = prb.subarray(elm_offset, elm_offset + L);
5430 e[j] = mod(os2ip(tv), p);
5431 }
5432 u[i] = e;
5433 }
5434 return u;
5435 }
5436 function isogenyMap(field, map) {
5437 const COEFF = map.map((i) => Array.from(i).reverse());
5438 return (x, y) => {
5439 const [xNum, xDen, yNum, yDen] = COEFF.map((val) => val.reduce((acc, i) => field.add(field.mul(acc, x), i)));
5440 x = field.div(xNum, xDen);
5441 y = field.mul(y, field.div(yNum, yDen));
5442 return { x, y };
5443 };
5444 }
5445 function createHasher(Point, mapToCurve, def) {
5446 if (typeof mapToCurve !== 'function')
5447 throw new Error('mapToCurve() must be defined');
5448 return {
5449 hashToCurve(msg, options) {
5450 const u = hash_to_field(msg, 2, { ...def, DST: def.DST, ...options });
5451 const u0 = Point.fromAffine(mapToCurve(u[0]));
5452 const u1 = Point.fromAffine(mapToCurve(u[1]));
5453 const P = u0.add(u1).clearCofactor();
5454 P.assertValidity();
5455 return P;
5456 },
5457 encodeToCurve(msg, options) {
5458 const u = hash_to_field(msg, 1, { ...def, DST: def.encodeDST, ...options });
5459 const P = Point.fromAffine(mapToCurve(u[0])).clearCofactor();
5460 P.assertValidity();
5461 return P;
5462 },
5463 };
5464 }
5465
5466 class HMAC extends Hash {
5467 constructor(hash, _key) {
5468 super();
5469 this.finished = false;
5470 this.destroyed = false;
5471 assert.hash(hash);
5472 const key = toBytes(_key);
5473 this.iHash = hash.create();
5474 if (typeof this.iHash.update !== 'function')
5475 throw new Error('Expected instance of class which extends utils.Hash');
5476 this.blockLen = this.iHash.blockLen;
5477 this.outputLen = this.iHash.outputLen;
5478 const blockLen = this.blockLen;
5479 const pad = new Uint8Array(blockLen);
5480 pad.set(key.length > blockLen ? hash.create().update(key).digest() : key);
5481 for (let i = 0; i < pad.length; i++)
5482 pad[i] ^= 0x36;
5483 this.iHash.update(pad);
5484 this.oHash = hash.create();
5485 for (let i = 0; i < pad.length; i++)
5486 pad[i] ^= 0x36 ^ 0x5c;
5487 this.oHash.update(pad);
5488 pad.fill(0);
5489 }
5490 update(buf) {
5491 assert.exists(this);
5492 this.iHash.update(buf);
5493 return this;
5494 }
5495 digestInto(out) {
5496 assert.exists(this);
5497 assert.bytes(out, this.outputLen);
5498 this.finished = true;
5499 this.iHash.digestInto(out);
5500 this.oHash.update(out);
5501 this.oHash.digestInto(out);
5502 this.destroy();
5503 }
5504 digest() {
5505 const out = new Uint8Array(this.oHash.outputLen);
5506 this.digestInto(out);
5507 return out;
5508 }
5509 _cloneInto(to) {
5510 to || (to = Object.create(Object.getPrototypeOf(this), {}));
5511 const { oHash, iHash, finished, destroyed, blockLen, outputLen } = this;
5512 to = to;
5513 to.finished = finished;
5514 to.destroyed = destroyed;
5515 to.blockLen = blockLen;
5516 to.outputLen = outputLen;
5517 to.oHash = oHash._cloneInto(to.oHash);
5518 to.iHash = iHash._cloneInto(to.iHash);
5519 return to;
5520 }
5521 destroy() {
5522 this.destroyed = true;
5523 this.oHash.destroy();
5524 this.iHash.destroy();
5525 }
5526 }
5527 const hmac = (hash, key, message) => new HMAC(hash, key).update(message).digest();
5528 hmac.create = (hash, key) => new HMAC(hash, key);
5529
5530 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
5531 function getHash(hash) {
5532 return {
5533 hash,
5534 hmac: (key, ...msgs) => hmac(hash, key, concatBytes$1(...msgs)),
5535 randomBytes,
5536 };
5537 }
5538 function createCurve(curveDef, defHash) {
5539 const create = (hash) => weierstrass({ ...curveDef, ...getHash(hash) });
5540 return Object.freeze({ ...create(defHash), create });
5541 }
5542
5543 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
5544 const secp256k1P = BigInt('0xfffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc2f');
5545 const secp256k1N = BigInt('0xfffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141');
5546 const _1n$4 = BigInt(1);
5547 const _2n$3 = BigInt(2);
5548 const divNearest = (a, b) => (a + b / _2n$3) / b;
5549 function sqrtMod(y) {
5550 const P = secp256k1P;
5551 const _3n = BigInt(3), _6n = BigInt(6), _11n = BigInt(11), _22n = BigInt(22);
5552 const _23n = BigInt(23), _44n = BigInt(44), _88n = BigInt(88);
5553 const b2 = (y * y * y) % P;
5554 const b3 = (b2 * b2 * y) % P;
5555 const b6 = (pow2(b3, _3n, P) * b3) % P;
5556 const b9 = (pow2(b6, _3n, P) * b3) % P;
5557 const b11 = (pow2(b9, _2n$3, P) * b2) % P;
5558 const b22 = (pow2(b11, _11n, P) * b11) % P;
5559 const b44 = (pow2(b22, _22n, P) * b22) % P;
5560 const b88 = (pow2(b44, _44n, P) * b44) % P;
5561 const b176 = (pow2(b88, _88n, P) * b88) % P;
5562 const b220 = (pow2(b176, _44n, P) * b44) % P;
5563 const b223 = (pow2(b220, _3n, P) * b3) % P;
5564 const t1 = (pow2(b223, _23n, P) * b22) % P;
5565 const t2 = (pow2(t1, _6n, P) * b2) % P;
5566 const root = pow2(t2, _2n$3, P);
5567 if (!Fp$1.eql(Fp$1.sqr(root), y))
5568 throw new Error('Cannot find square root');
5569 return root;
5570 }
5571 const Fp$1 = Field(secp256k1P, undefined, undefined, { sqrt: sqrtMod });
5572 const secp256k1 = createCurve({
5573 a: BigInt(0),
5574 b: BigInt(7),
5575 Fp: Fp$1,
5576 n: secp256k1N,
5577 Gx: BigInt('55066263022277343669578718895168534326250603453777594175500187360389116729240'),
5578 Gy: BigInt('32670510020758816978083085130507043184471273380659243275938904335757337482424'),
5579 h: BigInt(1),
5580 lowS: true,
5581 endo: {
5582 beta: BigInt('0x7ae96a2b657c07106e64479eac3434e99cf0497512f58995c1396c28719501ee'),
5583 splitScalar: (k) => {
5584 const n = secp256k1N;
5585 const a1 = BigInt('0x3086d221a7d46bcde86c90e49284eb15');
5586 const b1 = -_1n$4 * BigInt('0xe4437ed6010e88286f547fa90abfe4c3');
5587 const a2 = BigInt('0x114ca50f7a8e2f3f657c1108d9d44cfd8');
5588 const b2 = a1;
5589 const POW_2_128 = BigInt('0x100000000000000000000000000000000');
5590 const c1 = divNearest(b2 * k, n);
5591 const c2 = divNearest(-b1 * k, n);
5592 let k1 = mod(k - c1 * a1 - c2 * a2, n);
5593 let k2 = mod(-c1 * b1 - c2 * b2, n);
5594 const k1neg = k1 > POW_2_128;
5595 const k2neg = k2 > POW_2_128;
5596 if (k1neg)
5597 k1 = n - k1;
5598 if (k2neg)
5599 k2 = n - k2;
5600 if (k1 > POW_2_128 || k2 > POW_2_128) {
5601 throw new Error('splitScalar: Endomorphism failed, k=' + k);
5602 }
5603 return { k1neg, k1, k2neg, k2 };
5604 },
5605 },
5606 }, sha256);
5607 const _0n$4 = BigInt(0);
5608 const fe = (x) => typeof x === 'bigint' && _0n$4 < x && x < secp256k1P;
5609 const ge = (x) => typeof x === 'bigint' && _0n$4 < x && x < secp256k1N;
5610 const TAGGED_HASH_PREFIXES = {};
5611 function taggedHash(tag, ...messages) {
5612 let tagP = TAGGED_HASH_PREFIXES[tag];
5613 if (tagP === undefined) {
5614 const tagH = sha256(Uint8Array.from(tag, (c) => c.charCodeAt(0)));
5615 tagP = concatBytes(tagH, tagH);
5616 TAGGED_HASH_PREFIXES[tag] = tagP;
5617 }
5618 return sha256(concatBytes(tagP, ...messages));
5619 }
5620 const pointToBytes = (point) => point.toRawBytes(true).slice(1);
5621 const numTo32b = (n) => numberToBytesBE(n, 32);
5622 const modP = (x) => mod(x, secp256k1P);
5623 const modN = (x) => mod(x, secp256k1N);
5624 const Point = secp256k1.ProjectivePoint;
5625 const GmulAdd = (Q, a, b) => Point.BASE.multiplyAndAddUnsafe(Q, a, b);
5626 function schnorrGetExtPubKey(priv) {
5627 let d_ = secp256k1.utils.normPrivateKeyToScalar(priv);
5628 let p = Point.fromPrivateKey(d_);
5629 const scalar = p.hasEvenY() ? d_ : modN(-d_);
5630 return { scalar: scalar, bytes: pointToBytes(p) };
5631 }
5632 function lift_x(x) {
5633 if (!fe(x))
5634 throw new Error('bad x: need 0 < x < p');
5635 const xx = modP(x * x);
5636 const c = modP(xx * x + BigInt(7));
5637 let y = sqrtMod(c);
5638 if (y % _2n$3 !== _0n$4)
5639 y = modP(-y);
5640 const p = new Point(x, y, _1n$4);
5641 p.assertValidity();
5642 return p;
5643 }
5644 function challenge(...args) {
5645 return modN(bytesToNumberBE(taggedHash('BIP0340/challenge', ...args)));
5646 }
5647 function schnorrGetPublicKey(privateKey) {
5648 return schnorrGetExtPubKey(privateKey).bytes;
5649 }
5650 function schnorrSign(message, privateKey, auxRand = randomBytes(32)) {
5651 const m = ensureBytes('message', message);
5652 const { bytes: px, scalar: d } = schnorrGetExtPubKey(privateKey);
5653 const a = ensureBytes('auxRand', auxRand, 32);
5654 const t = numTo32b(d ^ bytesToNumberBE(taggedHash('BIP0340/aux', a)));
5655 const rand = taggedHash('BIP0340/nonce', t, px, m);
5656 const k_ = modN(bytesToNumberBE(rand));
5657 if (k_ === _0n$4)
5658 throw new Error('sign failed: k is zero');
5659 const { bytes: rx, scalar: k } = schnorrGetExtPubKey(k_);
5660 const e = challenge(rx, px, m);
5661 const sig = new Uint8Array(64);
5662 sig.set(rx, 0);
5663 sig.set(numTo32b(modN(k + e * d)), 32);
5664 if (!schnorrVerify(sig, m, px))
5665 throw new Error('sign: Invalid signature produced');
5666 return sig;
5667 }
5668 function schnorrVerify(signature, message, publicKey) {
5669 const sig = ensureBytes('signature', signature, 64);
5670 const m = ensureBytes('message', message);
5671 const pub = ensureBytes('publicKey', publicKey, 32);
5672 try {
5673 const P = lift_x(bytesToNumberBE(pub));
5674 const r = bytesToNumberBE(sig.subarray(0, 32));
5675 if (!fe(r))
5676 return false;
5677 const s = bytesToNumberBE(sig.subarray(32, 64));
5678 if (!ge(s))
5679 return false;
5680 const e = challenge(numTo32b(r), pointToBytes(P), m);
5681 const R = GmulAdd(P, s, modN(-e));
5682 if (!R || !R.hasEvenY() || R.toAffine().x !== r)
5683 return false;
5684 return true;
5685 }
5686 catch (error) {
5687 return false;
5688 }
5689 }
5690 (() => ({
5691 getPublicKey: schnorrGetPublicKey,
5692 sign: schnorrSign,
5693 verify: schnorrVerify,
5694 utils: {
5695 randomPrivateKey: secp256k1.utils.randomPrivateKey,
5696 lift_x,
5697 pointToBytes,
5698 numberToBytesBE,
5699 bytesToNumberBE,
5700 taggedHash,
5701 mod,
5702 },
5703 }))();
5704 const isoMap = (() => isogenyMap(Fp$1, [
5705 [
5706 '0x8e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38daaaaa8c7',
5707 '0x7d3d4c80bc321d5b9f315cea7fd44c5d595d2fc0bf63b92dfff1044f17c6581',
5708 '0x534c328d23f234e6e2a413deca25caece4506144037c40314ecbd0b53d9dd262',
5709 '0x8e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38daaaaa88c',
5710 ],
5711 [
5712 '0xd35771193d94918a9ca34ccbb7b640dd86cd409542f8487d9fe6b745781eb49b',
5713 '0xedadc6f64383dc1df7c4b2d51b54225406d36b641f5e41bbc52a56612a8c6d14',
5714 '0x0000000000000000000000000000000000000000000000000000000000000001',
5715 ],
5716 [
5717 '0x4bda12f684bda12f684bda12f684bda12f684bda12f684bda12f684b8e38e23c',
5718 '0xc75e0c32d5cb7c0fa9d0a54b12a0a6d5647ab046d686da6fdffc90fc201d71a3',
5719 '0x29a6194691f91a73715209ef6512e576722830a201be2018a765e85a9ecee931',
5720 '0x2f684bda12f684bda12f684bda12f684bda12f684bda12f684bda12f38e38d84',
5721 ],
5722 [
5723 '0xfffffffffffffffffffffffffffffffffffffffffffffffffffffffefffff93b',
5724 '0x7a06534bb8bdb49fd5e9e6632722c2989467c1bfc8e8d978dfb425d2685c2573',
5725 '0x6484aa716545ca2cf3a70c3fa8fe337e0a3d21162f0d6299a7bf8192bfd2a76f',
5726 '0x0000000000000000000000000000000000000000000000000000000000000001',
5727 ],
5728 ].map((i) => i.map((j) => BigInt(j)))))();
5729 const mapSWU = (() => mapToCurveSimpleSWU(Fp$1, {
5730 A: BigInt('0x3f8731abdd661adca08a5558f0f5d272e953d363cb6f0e5d405447c01a444533'),
5731 B: BigInt('1771'),
5732 Z: Fp$1.create(BigInt('-11')),
5733 }))();
5734 (() => createHasher(secp256k1.ProjectivePoint, (scalars) => {
5735 const { x, y } = mapSWU(Fp$1.create(scalars[0]));
5736 return isoMap(x, y);
5737 }, {
5738 DST: 'secp256k1_XMD:SHA-256_SSWU_RO_',
5739 encodeDST: 'secp256k1_XMD:SHA-256_SSWU_NU_',
5740 p: Fp$1.ORDER,
5741 m: 1,
5742 k: 128,
5743 expand: 'xmd',
5744 hash: sha256,
5745 }))();
5746
5747 function secp256k1PairFromSeed(seed, onlyJs) {
5748 if (seed.length !== 32) {
5749 throw new Error('Expected valid 32-byte private key as a seed');
5750 }
5751 if (!util.hasBigInt || (!onlyJs && isReady())) {
5752 const full = secp256k1FromSeed(seed);
5753 const publicKey = full.slice(32);
5754 if (util.u8aEmpty(publicKey)) {
5755 throw new Error('Invalid publicKey generated from WASM interface');
5756 }
5757 return {
5758 publicKey,
5759 secretKey: full.slice(0, 32)
5760 };
5761 }
5762 return {
5763 publicKey: secp256k1.getPublicKey(seed, true),
5764 secretKey: seed
5765 };
5766 }
5767
5768 function createSeedDeriveFn(fromSeed, derive) {
5769 return (keypair, { chainCode, isHard }) => {
5770 if (!isHard) {
5771 throw new Error('A soft key was found in the path and is not supported');
5772 }
5773 return fromSeed(derive(keypair.secretKey.subarray(0, 32), chainCode));
5774 };
5775 }
5776
5777 const keyHdkdEcdsa = createSeedDeriveFn(secp256k1PairFromSeed, secp256k1DeriveHard);
5778
5779 const HDKD = util.compactAddLength(util.stringToU8a('Ed25519HDKD'));
5780 function ed25519DeriveHard(seed, chainCode) {
5781 if (!util.isU8a(chainCode) || chainCode.length !== 32) {
5782 throw new Error('Invalid chainCode passed to derive');
5783 }
5784 return blake2AsU8a(util.u8aConcat(HDKD, seed, chainCode));
5785 }
5786
5787 function randomAsU8a(length = 32) {
5788 return browser.getRandomValues(new Uint8Array(length));
5789 }
5790 const randomAsHex = createAsHex(randomAsU8a);
5791
5792 const BN_53 = new util.BN(0b11111111111111111111111111111111111111111111111111111);
5793 function randomAsNumber() {
5794 return util.hexToBn(randomAsHex(8)).and(BN_53).toNumber();
5795 }
5796
5797 const [SHA512_Kh, SHA512_Kl] = u64.split([
5798 '0x428a2f98d728ae22', '0x7137449123ef65cd', '0xb5c0fbcfec4d3b2f', '0xe9b5dba58189dbbc',
5799 '0x3956c25bf348b538', '0x59f111f1b605d019', '0x923f82a4af194f9b', '0xab1c5ed5da6d8118',
5800 '0xd807aa98a3030242', '0x12835b0145706fbe', '0x243185be4ee4b28c', '0x550c7dc3d5ffb4e2',
5801 '0x72be5d74f27b896f', '0x80deb1fe3b1696b1', '0x9bdc06a725c71235', '0xc19bf174cf692694',
5802 '0xe49b69c19ef14ad2', '0xefbe4786384f25e3', '0x0fc19dc68b8cd5b5', '0x240ca1cc77ac9c65',
5803 '0x2de92c6f592b0275', '0x4a7484aa6ea6e483', '0x5cb0a9dcbd41fbd4', '0x76f988da831153b5',
5804 '0x983e5152ee66dfab', '0xa831c66d2db43210', '0xb00327c898fb213f', '0xbf597fc7beef0ee4',
5805 '0xc6e00bf33da88fc2', '0xd5a79147930aa725', '0x06ca6351e003826f', '0x142929670a0e6e70',
5806 '0x27b70a8546d22ffc', '0x2e1b21385c26c926', '0x4d2c6dfc5ac42aed', '0x53380d139d95b3df',
5807 '0x650a73548baf63de', '0x766a0abb3c77b2a8', '0x81c2c92e47edaee6', '0x92722c851482353b',
5808 '0xa2bfe8a14cf10364', '0xa81a664bbc423001', '0xc24b8b70d0f89791', '0xc76c51a30654be30',
5809 '0xd192e819d6ef5218', '0xd69906245565a910', '0xf40e35855771202a', '0x106aa07032bbd1b8',
5810 '0x19a4c116b8d2d0c8', '0x1e376c085141ab53', '0x2748774cdf8eeb99', '0x34b0bcb5e19b48a8',
5811 '0x391c0cb3c5c95a63', '0x4ed8aa4ae3418acb', '0x5b9cca4f7763e373', '0x682e6ff3d6b2b8a3',
5812 '0x748f82ee5defb2fc', '0x78a5636f43172f60', '0x84c87814a1f0ab72', '0x8cc702081a6439ec',
5813 '0x90befffa23631e28', '0xa4506cebde82bde9', '0xbef9a3f7b2c67915', '0xc67178f2e372532b',
5814 '0xca273eceea26619c', '0xd186b8c721c0c207', '0xeada7dd6cde0eb1e', '0xf57d4f7fee6ed178',
5815 '0x06f067aa72176fba', '0x0a637dc5a2c898a6', '0x113f9804bef90dae', '0x1b710b35131c471b',
5816 '0x28db77f523047d84', '0x32caab7b40c72493', '0x3c9ebe0a15c9bebc', '0x431d67c49c100d4c',
5817 '0x4cc5d4becb3e42b6', '0x597f299cfc657e2a', '0x5fcb6fab3ad6faec', '0x6c44198c4a475817'
5818 ].map(n => BigInt(n)));
5819 const SHA512_W_H = new Uint32Array(80);
5820 const SHA512_W_L = new Uint32Array(80);
5821 class SHA512 extends SHA2 {
5822 constructor() {
5823 super(128, 64, 16, false);
5824 this.Ah = 0x6a09e667 | 0;
5825 this.Al = 0xf3bcc908 | 0;
5826 this.Bh = 0xbb67ae85 | 0;
5827 this.Bl = 0x84caa73b | 0;
5828 this.Ch = 0x3c6ef372 | 0;
5829 this.Cl = 0xfe94f82b | 0;
5830 this.Dh = 0xa54ff53a | 0;
5831 this.Dl = 0x5f1d36f1 | 0;
5832 this.Eh = 0x510e527f | 0;
5833 this.El = 0xade682d1 | 0;
5834 this.Fh = 0x9b05688c | 0;
5835 this.Fl = 0x2b3e6c1f | 0;
5836 this.Gh = 0x1f83d9ab | 0;
5837 this.Gl = 0xfb41bd6b | 0;
5838 this.Hh = 0x5be0cd19 | 0;
5839 this.Hl = 0x137e2179 | 0;
5840 }
5841 get() {
5842 const { Ah, Al, Bh, Bl, Ch, Cl, Dh, Dl, Eh, El, Fh, Fl, Gh, Gl, Hh, Hl } = this;
5843 return [Ah, Al, Bh, Bl, Ch, Cl, Dh, Dl, Eh, El, Fh, Fl, Gh, Gl, Hh, Hl];
5844 }
5845 set(Ah, Al, Bh, Bl, Ch, Cl, Dh, Dl, Eh, El, Fh, Fl, Gh, Gl, Hh, Hl) {
5846 this.Ah = Ah | 0;
5847 this.Al = Al | 0;
5848 this.Bh = Bh | 0;
5849 this.Bl = Bl | 0;
5850 this.Ch = Ch | 0;
5851 this.Cl = Cl | 0;
5852 this.Dh = Dh | 0;
5853 this.Dl = Dl | 0;
5854 this.Eh = Eh | 0;
5855 this.El = El | 0;
5856 this.Fh = Fh | 0;
5857 this.Fl = Fl | 0;
5858 this.Gh = Gh | 0;
5859 this.Gl = Gl | 0;
5860 this.Hh = Hh | 0;
5861 this.Hl = Hl | 0;
5862 }
5863 process(view, offset) {
5864 for (let i = 0; i < 16; i++, offset += 4) {
5865 SHA512_W_H[i] = view.getUint32(offset);
5866 SHA512_W_L[i] = view.getUint32((offset += 4));
5867 }
5868 for (let i = 16; i < 80; i++) {
5869 const W15h = SHA512_W_H[i - 15] | 0;
5870 const W15l = SHA512_W_L[i - 15] | 0;
5871 const s0h = u64.rotrSH(W15h, W15l, 1) ^ u64.rotrSH(W15h, W15l, 8) ^ u64.shrSH(W15h, W15l, 7);
5872 const s0l = u64.rotrSL(W15h, W15l, 1) ^ u64.rotrSL(W15h, W15l, 8) ^ u64.shrSL(W15h, W15l, 7);
5873 const W2h = SHA512_W_H[i - 2] | 0;
5874 const W2l = SHA512_W_L[i - 2] | 0;
5875 const s1h = u64.rotrSH(W2h, W2l, 19) ^ u64.rotrBH(W2h, W2l, 61) ^ u64.shrSH(W2h, W2l, 6);
5876 const s1l = u64.rotrSL(W2h, W2l, 19) ^ u64.rotrBL(W2h, W2l, 61) ^ u64.shrSL(W2h, W2l, 6);
5877 const SUMl = u64.add4L(s0l, s1l, SHA512_W_L[i - 7], SHA512_W_L[i - 16]);
5878 const SUMh = u64.add4H(SUMl, s0h, s1h, SHA512_W_H[i - 7], SHA512_W_H[i - 16]);
5879 SHA512_W_H[i] = SUMh | 0;
5880 SHA512_W_L[i] = SUMl | 0;
5881 }
5882 let { Ah, Al, Bh, Bl, Ch, Cl, Dh, Dl, Eh, El, Fh, Fl, Gh, Gl, Hh, Hl } = this;
5883 for (let i = 0; i < 80; i++) {
5884 const sigma1h = u64.rotrSH(Eh, El, 14) ^ u64.rotrSH(Eh, El, 18) ^ u64.rotrBH(Eh, El, 41);
5885 const sigma1l = u64.rotrSL(Eh, El, 14) ^ u64.rotrSL(Eh, El, 18) ^ u64.rotrBL(Eh, El, 41);
5886 const CHIh = (Eh & Fh) ^ (~Eh & Gh);
5887 const CHIl = (El & Fl) ^ (~El & Gl);
5888 const T1ll = u64.add5L(Hl, sigma1l, CHIl, SHA512_Kl[i], SHA512_W_L[i]);
5889 const T1h = u64.add5H(T1ll, Hh, sigma1h, CHIh, SHA512_Kh[i], SHA512_W_H[i]);
5890 const T1l = T1ll | 0;
5891 const sigma0h = u64.rotrSH(Ah, Al, 28) ^ u64.rotrBH(Ah, Al, 34) ^ u64.rotrBH(Ah, Al, 39);
5892 const sigma0l = u64.rotrSL(Ah, Al, 28) ^ u64.rotrBL(Ah, Al, 34) ^ u64.rotrBL(Ah, Al, 39);
5893 const MAJh = (Ah & Bh) ^ (Ah & Ch) ^ (Bh & Ch);
5894 const MAJl = (Al & Bl) ^ (Al & Cl) ^ (Bl & Cl);
5895 Hh = Gh | 0;
5896 Hl = Gl | 0;
5897 Gh = Fh | 0;
5898 Gl = Fl | 0;
5899 Fh = Eh | 0;
5900 Fl = El | 0;
5901 ({ h: Eh, l: El } = u64.add(Dh | 0, Dl | 0, T1h | 0, T1l | 0));
5902 Dh = Ch | 0;
5903 Dl = Cl | 0;
5904 Ch = Bh | 0;
5905 Cl = Bl | 0;
5906 Bh = Ah | 0;
5907 Bl = Al | 0;
5908 const All = u64.add3L(T1l, sigma0l, MAJl);
5909 Ah = u64.add3H(All, T1h, sigma0h, MAJh);
5910 Al = All | 0;
5911 }
5912 ({ h: Ah, l: Al } = u64.add(this.Ah | 0, this.Al | 0, Ah | 0, Al | 0));
5913 ({ h: Bh, l: Bl } = u64.add(this.Bh | 0, this.Bl | 0, Bh | 0, Bl | 0));
5914 ({ h: Ch, l: Cl } = u64.add(this.Ch | 0, this.Cl | 0, Ch | 0, Cl | 0));
5915 ({ h: Dh, l: Dl } = u64.add(this.Dh | 0, this.Dl | 0, Dh | 0, Dl | 0));
5916 ({ h: Eh, l: El } = u64.add(this.Eh | 0, this.El | 0, Eh | 0, El | 0));
5917 ({ h: Fh, l: Fl } = u64.add(this.Fh | 0, this.Fl | 0, Fh | 0, Fl | 0));
5918 ({ h: Gh, l: Gl } = u64.add(this.Gh | 0, this.Gl | 0, Gh | 0, Gl | 0));
5919 ({ h: Hh, l: Hl } = u64.add(this.Hh | 0, this.Hl | 0, Hh | 0, Hl | 0));
5920 this.set(Ah, Al, Bh, Bl, Ch, Cl, Dh, Dl, Eh, El, Fh, Fl, Gh, Gl, Hh, Hl);
5921 }
5922 roundClean() {
5923 SHA512_W_H.fill(0);
5924 SHA512_W_L.fill(0);
5925 }
5926 destroy() {
5927 this.buffer.fill(0);
5928 this.set(0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0);
5929 }
5930 }
5931 class SHA512_224 extends SHA512 {
5932 constructor() {
5933 super();
5934 this.Ah = 0x8c3d37c8 | 0;
5935 this.Al = 0x19544da2 | 0;
5936 this.Bh = 0x73e19966 | 0;
5937 this.Bl = 0x89dcd4d6 | 0;
5938 this.Ch = 0x1dfab7ae | 0;
5939 this.Cl = 0x32ff9c82 | 0;
5940 this.Dh = 0x679dd514 | 0;
5941 this.Dl = 0x582f9fcf | 0;
5942 this.Eh = 0x0f6d2b69 | 0;
5943 this.El = 0x7bd44da8 | 0;
5944 this.Fh = 0x77e36f73 | 0;
5945 this.Fl = 0x04c48942 | 0;
5946 this.Gh = 0x3f9d85a8 | 0;
5947 this.Gl = 0x6a1d36c8 | 0;
5948 this.Hh = 0x1112e6ad | 0;
5949 this.Hl = 0x91d692a1 | 0;
5950 this.outputLen = 28;
5951 }
5952 }
5953 class SHA512_256 extends SHA512 {
5954 constructor() {
5955 super();
5956 this.Ah = 0x22312194 | 0;
5957 this.Al = 0xfc2bf72c | 0;
5958 this.Bh = 0x9f555fa3 | 0;
5959 this.Bl = 0xc84c64c2 | 0;
5960 this.Ch = 0x2393b86b | 0;
5961 this.Cl = 0x6f53b151 | 0;
5962 this.Dh = 0x96387719 | 0;
5963 this.Dl = 0x5940eabd | 0;
5964 this.Eh = 0x96283ee2 | 0;
5965 this.El = 0xa88effe3 | 0;
5966 this.Fh = 0xbe5e1e25 | 0;
5967 this.Fl = 0x53863992 | 0;
5968 this.Gh = 0x2b0199fc | 0;
5969 this.Gl = 0x2c85b8aa | 0;
5970 this.Hh = 0x0eb72ddc | 0;
5971 this.Hl = 0x81c52ca2 | 0;
5972 this.outputLen = 32;
5973 }
5974 }
5975 class SHA384 extends SHA512 {
5976 constructor() {
5977 super();
5978 this.Ah = 0xcbbb9d5d | 0;
5979 this.Al = 0xc1059ed8 | 0;
5980 this.Bh = 0x629a292a | 0;
5981 this.Bl = 0x367cd507 | 0;
5982 this.Ch = 0x9159015a | 0;
5983 this.Cl = 0x3070dd17 | 0;
5984 this.Dh = 0x152fecd8 | 0;
5985 this.Dl = 0xf70e5939 | 0;
5986 this.Eh = 0x67332667 | 0;
5987 this.El = 0xffc00b31 | 0;
5988 this.Fh = 0x8eb44a87 | 0;
5989 this.Fl = 0x68581511 | 0;
5990 this.Gh = 0xdb0c2e0d | 0;
5991 this.Gl = 0x64f98fa7 | 0;
5992 this.Hh = 0x47b5481d | 0;
5993 this.Hl = 0xbefa4fa4 | 0;
5994 this.outputLen = 48;
5995 }
5996 }
5997 const sha512 = wrapConstructor(() => new SHA512());
5998 wrapConstructor(() => new SHA512_224());
5999 wrapConstructor(() => new SHA512_256());
6000 wrapConstructor(() => new SHA384());
6001
6002 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
6003 const _0n$3 = BigInt(0), _1n$3 = BigInt(1), _2n$2 = BigInt(2), _8n = BigInt(8);
6004 const VERIFY_DEFAULT = { zip215: true };
6005 function validateOpts$1(curve) {
6006 const opts = validateBasic(curve);
6007 validateObject(curve, {
6008 hash: 'function',
6009 a: 'bigint',
6010 d: 'bigint',
6011 randomBytes: 'function',
6012 }, {
6013 adjustScalarBytes: 'function',
6014 domain: 'function',
6015 uvRatio: 'function',
6016 mapToCurve: 'function',
6017 });
6018 return Object.freeze({ ...opts });
6019 }
6020 function twistedEdwards(curveDef) {
6021 const CURVE = validateOpts$1(curveDef);
6022 const { Fp, n: CURVE_ORDER, prehash: prehash, hash: cHash, randomBytes, nByteLength, h: cofactor, } = CURVE;
6023 const MASK = _2n$2 << (BigInt(nByteLength * 8) - _1n$3);
6024 const modP = Fp.create;
6025 const uvRatio = CURVE.uvRatio ||
6026 ((u, v) => {
6027 try {
6028 return { isValid: true, value: Fp.sqrt(u * Fp.inv(v)) };
6029 }
6030 catch (e) {
6031 return { isValid: false, value: _0n$3 };
6032 }
6033 });
6034 const adjustScalarBytes = CURVE.adjustScalarBytes || ((bytes) => bytes);
6035 const domain = CURVE.domain ||
6036 ((data, ctx, phflag) => {
6037 if (ctx.length || phflag)
6038 throw new Error('Contexts/pre-hash are not supported');
6039 return data;
6040 });
6041 const inBig = (n) => typeof n === 'bigint' && _0n$3 < n;
6042 const inRange = (n, max) => inBig(n) && inBig(max) && n < max;
6043 const in0MaskRange = (n) => n === _0n$3 || inRange(n, MASK);
6044 function assertInRange(n, max) {
6045 if (inRange(n, max))
6046 return n;
6047 throw new Error(`Expected valid scalar < ${max}, got ${typeof n} ${n}`);
6048 }
6049 function assertGE0(n) {
6050 return n === _0n$3 ? n : assertInRange(n, CURVE_ORDER);
6051 }
6052 const pointPrecomputes = new Map();
6053 function isPoint(other) {
6054 if (!(other instanceof Point))
6055 throw new Error('ExtendedPoint expected');
6056 }
6057 class Point {
6058 constructor(ex, ey, ez, et) {
6059 this.ex = ex;
6060 this.ey = ey;
6061 this.ez = ez;
6062 this.et = et;
6063 if (!in0MaskRange(ex))
6064 throw new Error('x required');
6065 if (!in0MaskRange(ey))
6066 throw new Error('y required');
6067 if (!in0MaskRange(ez))
6068 throw new Error('z required');
6069 if (!in0MaskRange(et))
6070 throw new Error('t required');
6071 }
6072 get x() {
6073 return this.toAffine().x;
6074 }
6075 get y() {
6076 return this.toAffine().y;
6077 }
6078 static fromAffine(p) {
6079 if (p instanceof Point)
6080 throw new Error('extended point not allowed');
6081 const { x, y } = p || {};
6082 if (!in0MaskRange(x) || !in0MaskRange(y))
6083 throw new Error('invalid affine point');
6084 return new Point(x, y, _1n$3, modP(x * y));
6085 }
6086 static normalizeZ(points) {
6087 const toInv = Fp.invertBatch(points.map((p) => p.ez));
6088 return points.map((p, i) => p.toAffine(toInv[i])).map(Point.fromAffine);
6089 }
6090 _setWindowSize(windowSize) {
6091 this._WINDOW_SIZE = windowSize;
6092 pointPrecomputes.delete(this);
6093 }
6094 assertValidity() {
6095 const { a, d } = CURVE;
6096 if (this.is0())
6097 throw new Error('bad point: ZERO');
6098 const { ex: X, ey: Y, ez: Z, et: T } = this;
6099 const X2 = modP(X * X);
6100 const Y2 = modP(Y * Y);
6101 const Z2 = modP(Z * Z);
6102 const Z4 = modP(Z2 * Z2);
6103 const aX2 = modP(X2 * a);
6104 const left = modP(Z2 * modP(aX2 + Y2));
6105 const right = modP(Z4 + modP(d * modP(X2 * Y2)));
6106 if (left !== right)
6107 throw new Error('bad point: equation left != right (1)');
6108 const XY = modP(X * Y);
6109 const ZT = modP(Z * T);
6110 if (XY !== ZT)
6111 throw new Error('bad point: equation left != right (2)');
6112 }
6113 equals(other) {
6114 isPoint(other);
6115 const { ex: X1, ey: Y1, ez: Z1 } = this;
6116 const { ex: X2, ey: Y2, ez: Z2 } = other;
6117 const X1Z2 = modP(X1 * Z2);
6118 const X2Z1 = modP(X2 * Z1);
6119 const Y1Z2 = modP(Y1 * Z2);
6120 const Y2Z1 = modP(Y2 * Z1);
6121 return X1Z2 === X2Z1 && Y1Z2 === Y2Z1;
6122 }
6123 is0() {
6124 return this.equals(Point.ZERO);
6125 }
6126 negate() {
6127 return new Point(modP(-this.ex), this.ey, this.ez, modP(-this.et));
6128 }
6129 double() {
6130 const { a } = CURVE;
6131 const { ex: X1, ey: Y1, ez: Z1 } = this;
6132 const A = modP(X1 * X1);
6133 const B = modP(Y1 * Y1);
6134 const C = modP(_2n$2 * modP(Z1 * Z1));
6135 const D = modP(a * A);
6136 const x1y1 = X1 + Y1;
6137 const E = modP(modP(x1y1 * x1y1) - A - B);
6138 const G = D + B;
6139 const F = G - C;
6140 const H = D - B;
6141 const X3 = modP(E * F);
6142 const Y3 = modP(G * H);
6143 const T3 = modP(E * H);
6144 const Z3 = modP(F * G);
6145 return new Point(X3, Y3, Z3, T3);
6146 }
6147 add(other) {
6148 isPoint(other);
6149 const { a, d } = CURVE;
6150 const { ex: X1, ey: Y1, ez: Z1, et: T1 } = this;
6151 const { ex: X2, ey: Y2, ez: Z2, et: T2 } = other;
6152 if (a === BigInt(-1)) {
6153 const A = modP((Y1 - X1) * (Y2 + X2));
6154 const B = modP((Y1 + X1) * (Y2 - X2));
6155 const F = modP(B - A);
6156 if (F === _0n$3)
6157 return this.double();
6158 const C = modP(Z1 * _2n$2 * T2);
6159 const D = modP(T1 * _2n$2 * Z2);
6160 const E = D + C;
6161 const G = B + A;
6162 const H = D - C;
6163 const X3 = modP(E * F);
6164 const Y3 = modP(G * H);
6165 const T3 = modP(E * H);
6166 const Z3 = modP(F * G);
6167 return new Point(X3, Y3, Z3, T3);
6168 }
6169 const A = modP(X1 * X2);
6170 const B = modP(Y1 * Y2);
6171 const C = modP(T1 * d * T2);
6172 const D = modP(Z1 * Z2);
6173 const E = modP((X1 + Y1) * (X2 + Y2) - A - B);
6174 const F = D - C;
6175 const G = D + C;
6176 const H = modP(B - a * A);
6177 const X3 = modP(E * F);
6178 const Y3 = modP(G * H);
6179 const T3 = modP(E * H);
6180 const Z3 = modP(F * G);
6181 return new Point(X3, Y3, Z3, T3);
6182 }
6183 subtract(other) {
6184 return this.add(other.negate());
6185 }
6186 wNAF(n) {
6187 return wnaf.wNAFCached(this, pointPrecomputes, n, Point.normalizeZ);
6188 }
6189 multiply(scalar) {
6190 const { p, f } = this.wNAF(assertInRange(scalar, CURVE_ORDER));
6191 return Point.normalizeZ([p, f])[0];
6192 }
6193 multiplyUnsafe(scalar) {
6194 let n = assertGE0(scalar);
6195 if (n === _0n$3)
6196 return I;
6197 if (this.equals(I) || n === _1n$3)
6198 return this;
6199 if (this.equals(G))
6200 return this.wNAF(n).p;
6201 return wnaf.unsafeLadder(this, n);
6202 }
6203 isSmallOrder() {
6204 return this.multiplyUnsafe(cofactor).is0();
6205 }
6206 isTorsionFree() {
6207 return wnaf.unsafeLadder(this, CURVE_ORDER).is0();
6208 }
6209 toAffine(iz) {
6210 const { ex: x, ey: y, ez: z } = this;
6211 const is0 = this.is0();
6212 if (iz == null)
6213 iz = is0 ? _8n : Fp.inv(z);
6214 const ax = modP(x * iz);
6215 const ay = modP(y * iz);
6216 const zz = modP(z * iz);
6217 if (is0)
6218 return { x: _0n$3, y: _1n$3 };
6219 if (zz !== _1n$3)
6220 throw new Error('invZ was invalid');
6221 return { x: ax, y: ay };
6222 }
6223 clearCofactor() {
6224 const { h: cofactor } = CURVE;
6225 if (cofactor === _1n$3)
6226 return this;
6227 return this.multiplyUnsafe(cofactor);
6228 }
6229 static fromHex(hex, zip215 = false) {
6230 const { d, a } = CURVE;
6231 const len = Fp.BYTES;
6232 hex = ensureBytes('pointHex', hex, len);
6233 const normed = hex.slice();
6234 const lastByte = hex[len - 1];
6235 normed[len - 1] = lastByte & ~0x80;
6236 const y = bytesToNumberLE(normed);
6237 if (y === _0n$3) ;
6238 else {
6239 if (zip215)
6240 assertInRange(y, MASK);
6241 else
6242 assertInRange(y, Fp.ORDER);
6243 }
6244 const y2 = modP(y * y);
6245 const u = modP(y2 - _1n$3);
6246 const v = modP(d * y2 - a);
6247 let { isValid, value: x } = uvRatio(u, v);
6248 if (!isValid)
6249 throw new Error('Point.fromHex: invalid y coordinate');
6250 const isXOdd = (x & _1n$3) === _1n$3;
6251 const isLastByteOdd = (lastByte & 0x80) !== 0;
6252 if (!zip215 && x === _0n$3 && isLastByteOdd)
6253 throw new Error('Point.fromHex: x=0 and x_0=1');
6254 if (isLastByteOdd !== isXOdd)
6255 x = modP(-x);
6256 return Point.fromAffine({ x, y });
6257 }
6258 static fromPrivateKey(privKey) {
6259 return getExtendedPublicKey(privKey).point;
6260 }
6261 toRawBytes() {
6262 const { x, y } = this.toAffine();
6263 const bytes = numberToBytesLE(y, Fp.BYTES);
6264 bytes[bytes.length - 1] |= x & _1n$3 ? 0x80 : 0;
6265 return bytes;
6266 }
6267 toHex() {
6268 return bytesToHex(this.toRawBytes());
6269 }
6270 }
6271 Point.BASE = new Point(CURVE.Gx, CURVE.Gy, _1n$3, modP(CURVE.Gx * CURVE.Gy));
6272 Point.ZERO = new Point(_0n$3, _1n$3, _1n$3, _0n$3);
6273 const { BASE: G, ZERO: I } = Point;
6274 const wnaf = wNAF(Point, nByteLength * 8);
6275 function modN(a) {
6276 return mod(a, CURVE_ORDER);
6277 }
6278 function modN_LE(hash) {
6279 return modN(bytesToNumberLE(hash));
6280 }
6281 function getExtendedPublicKey(key) {
6282 const len = nByteLength;
6283 key = ensureBytes('private key', key, len);
6284 const hashed = ensureBytes('hashed private key', cHash(key), 2 * len);
6285 const head = adjustScalarBytes(hashed.slice(0, len));
6286 const prefix = hashed.slice(len, 2 * len);
6287 const scalar = modN_LE(head);
6288 const point = G.multiply(scalar);
6289 const pointBytes = point.toRawBytes();
6290 return { head, prefix, scalar, point, pointBytes };
6291 }
6292 function getPublicKey(privKey) {
6293 return getExtendedPublicKey(privKey).pointBytes;
6294 }
6295 function hashDomainToScalar(context = new Uint8Array(), ...msgs) {
6296 const msg = concatBytes(...msgs);
6297 return modN_LE(cHash(domain(msg, ensureBytes('context', context), !!prehash)));
6298 }
6299 function sign(msg, privKey, options = {}) {
6300 msg = ensureBytes('message', msg);
6301 if (prehash)
6302 msg = prehash(msg);
6303 const { prefix, scalar, pointBytes } = getExtendedPublicKey(privKey);
6304 const r = hashDomainToScalar(options.context, prefix, msg);
6305 const R = G.multiply(r).toRawBytes();
6306 const k = hashDomainToScalar(options.context, R, pointBytes, msg);
6307 const s = modN(r + k * scalar);
6308 assertGE0(s);
6309 const res = concatBytes(R, numberToBytesLE(s, Fp.BYTES));
6310 return ensureBytes('result', res, nByteLength * 2);
6311 }
6312 const verifyOpts = VERIFY_DEFAULT;
6313 function verify(sig, msg, publicKey, options = verifyOpts) {
6314 const { context, zip215 } = options;
6315 const len = Fp.BYTES;
6316 sig = ensureBytes('signature', sig, 2 * len);
6317 msg = ensureBytes('message', msg);
6318 if (prehash)
6319 msg = prehash(msg);
6320 const s = bytesToNumberLE(sig.slice(len, 2 * len));
6321 let A, R, SB;
6322 try {
6323 A = Point.fromHex(publicKey, zip215);
6324 R = Point.fromHex(sig.slice(0, len), zip215);
6325 SB = G.multiplyUnsafe(s);
6326 }
6327 catch (error) {
6328 return false;
6329 }
6330 if (!zip215 && A.isSmallOrder())
6331 return false;
6332 const k = hashDomainToScalar(context, R.toRawBytes(), A.toRawBytes(), msg);
6333 const RkA = R.add(A.multiplyUnsafe(k));
6334 return RkA.subtract(SB).clearCofactor().equals(Point.ZERO);
6335 }
6336 G._setWindowSize(8);
6337 const utils = {
6338 getExtendedPublicKey,
6339 randomPrivateKey: () => randomBytes(Fp.BYTES),
6340 precompute(windowSize = 8, point = Point.BASE) {
6341 point._setWindowSize(windowSize);
6342 point.multiply(BigInt(3));
6343 return point;
6344 },
6345 };
6346 return {
6347 CURVE,
6348 getPublicKey,
6349 sign,
6350 verify,
6351 ExtendedPoint: Point,
6352 utils,
6353 };
6354 }
6355
6356 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
6357 const _0n$2 = BigInt(0);
6358 const _1n$2 = BigInt(1);
6359 function validateOpts(curve) {
6360 validateObject(curve, {
6361 a: 'bigint',
6362 }, {
6363 montgomeryBits: 'isSafeInteger',
6364 nByteLength: 'isSafeInteger',
6365 adjustScalarBytes: 'function',
6366 domain: 'function',
6367 powPminus2: 'function',
6368 Gu: 'bigint',
6369 });
6370 return Object.freeze({ ...curve });
6371 }
6372 function montgomery(curveDef) {
6373 const CURVE = validateOpts(curveDef);
6374 const { P } = CURVE;
6375 const modP = (n) => mod(n, P);
6376 const montgomeryBits = CURVE.montgomeryBits;
6377 const montgomeryBytes = Math.ceil(montgomeryBits / 8);
6378 const fieldLen = CURVE.nByteLength;
6379 const adjustScalarBytes = CURVE.adjustScalarBytes || ((bytes) => bytes);
6380 const powPminus2 = CURVE.powPminus2 || ((x) => pow(x, P - BigInt(2), P));
6381 function cswap(swap, x_2, x_3) {
6382 const dummy = modP(swap * (x_2 - x_3));
6383 x_2 = modP(x_2 - dummy);
6384 x_3 = modP(x_3 + dummy);
6385 return [x_2, x_3];
6386 }
6387 function assertFieldElement(n) {
6388 if (typeof n === 'bigint' && _0n$2 <= n && n < P)
6389 return n;
6390 throw new Error('Expected valid scalar 0 < scalar < CURVE.P');
6391 }
6392 const a24 = (CURVE.a - BigInt(2)) / BigInt(4);
6393 function montgomeryLadder(pointU, scalar) {
6394 const u = assertFieldElement(pointU);
6395 const k = assertFieldElement(scalar);
6396 const x_1 = u;
6397 let x_2 = _1n$2;
6398 let z_2 = _0n$2;
6399 let x_3 = u;
6400 let z_3 = _1n$2;
6401 let swap = _0n$2;
6402 let sw;
6403 for (let t = BigInt(montgomeryBits - 1); t >= _0n$2; t--) {
6404 const k_t = (k >> t) & _1n$2;
6405 swap ^= k_t;
6406 sw = cswap(swap, x_2, x_3);
6407 x_2 = sw[0];
6408 x_3 = sw[1];
6409 sw = cswap(swap, z_2, z_3);
6410 z_2 = sw[0];
6411 z_3 = sw[1];
6412 swap = k_t;
6413 const A = x_2 + z_2;
6414 const AA = modP(A * A);
6415 const B = x_2 - z_2;
6416 const BB = modP(B * B);
6417 const E = AA - BB;
6418 const C = x_3 + z_3;
6419 const D = x_3 - z_3;
6420 const DA = modP(D * A);
6421 const CB = modP(C * B);
6422 const dacb = DA + CB;
6423 const da_cb = DA - CB;
6424 x_3 = modP(dacb * dacb);
6425 z_3 = modP(x_1 * modP(da_cb * da_cb));
6426 x_2 = modP(AA * BB);
6427 z_2 = modP(E * (AA + modP(a24 * E)));
6428 }
6429 sw = cswap(swap, x_2, x_3);
6430 x_2 = sw[0];
6431 x_3 = sw[1];
6432 sw = cswap(swap, z_2, z_3);
6433 z_2 = sw[0];
6434 z_3 = sw[1];
6435 const z2 = powPminus2(z_2);
6436 return modP(x_2 * z2);
6437 }
6438 function encodeUCoordinate(u) {
6439 return numberToBytesLE(modP(u), montgomeryBytes);
6440 }
6441 function decodeUCoordinate(uEnc) {
6442 const u = ensureBytes('u coordinate', uEnc, montgomeryBytes);
6443 if (fieldLen === montgomeryBytes)
6444 u[fieldLen - 1] &= 127;
6445 return bytesToNumberLE(u);
6446 }
6447 function decodeScalar(n) {
6448 const bytes = ensureBytes('scalar', n);
6449 if (bytes.length !== montgomeryBytes && bytes.length !== fieldLen)
6450 throw new Error(`Expected ${montgomeryBytes} or ${fieldLen} bytes, got ${bytes.length}`);
6451 return bytesToNumberLE(adjustScalarBytes(bytes));
6452 }
6453 function scalarMult(scalar, u) {
6454 const pointU = decodeUCoordinate(u);
6455 const _scalar = decodeScalar(scalar);
6456 const pu = montgomeryLadder(pointU, _scalar);
6457 if (pu === _0n$2)
6458 throw new Error('Invalid private or public key received');
6459 return encodeUCoordinate(pu);
6460 }
6461 const GuBytes = encodeUCoordinate(CURVE.Gu);
6462 function scalarMultBase(scalar) {
6463 return scalarMult(scalar, GuBytes);
6464 }
6465 return {
6466 scalarMult,
6467 scalarMultBase,
6468 getSharedSecret: (privateKey, publicKey) => scalarMult(privateKey, publicKey),
6469 getPublicKey: (privateKey) => scalarMultBase(privateKey),
6470 utils: { randomPrivateKey: () => CURVE.randomBytes(CURVE.nByteLength) },
6471 GuBytes: GuBytes,
6472 };
6473 }
6474
6475 /*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
6476 const ED25519_P = BigInt('57896044618658097711785492504343953926634992332820282019728792003956564819949');
6477 const ED25519_SQRT_M1 = BigInt('19681161376707505956807079304988542015446066515923890162744021073123829784752');
6478 const _0n$1 = BigInt(0), _1n$1 = BigInt(1), _2n$1 = BigInt(2), _5n = BigInt(5);
6479 const _10n = BigInt(10), _20n = BigInt(20), _40n = BigInt(40), _80n = BigInt(80);
6480 function ed25519_pow_2_252_3(x) {
6481 const P = ED25519_P;
6482 const x2 = (x * x) % P;
6483 const b2 = (x2 * x) % P;
6484 const b4 = (pow2(b2, _2n$1, P) * b2) % P;
6485 const b5 = (pow2(b4, _1n$1, P) * x) % P;
6486 const b10 = (pow2(b5, _5n, P) * b5) % P;
6487 const b20 = (pow2(b10, _10n, P) * b10) % P;
6488 const b40 = (pow2(b20, _20n, P) * b20) % P;
6489 const b80 = (pow2(b40, _40n, P) * b40) % P;
6490 const b160 = (pow2(b80, _80n, P) * b80) % P;
6491 const b240 = (pow2(b160, _80n, P) * b80) % P;
6492 const b250 = (pow2(b240, _10n, P) * b10) % P;
6493 const pow_p_5_8 = (pow2(b250, _2n$1, P) * x) % P;
6494 return { pow_p_5_8, b2 };
6495 }
6496 function adjustScalarBytes(bytes) {
6497 bytes[0] &= 248;
6498 bytes[31] &= 127;
6499 bytes[31] |= 64;
6500 return bytes;
6501 }
6502 function uvRatio(u, v) {
6503 const P = ED25519_P;
6504 const v3 = mod(v * v * v, P);
6505 const v7 = mod(v3 * v3 * v, P);
6506 const pow = ed25519_pow_2_252_3(u * v7).pow_p_5_8;
6507 let x = mod(u * v3 * pow, P);
6508 const vx2 = mod(v * x * x, P);
6509 const root1 = x;
6510 const root2 = mod(x * ED25519_SQRT_M1, P);
6511 const useRoot1 = vx2 === u;
6512 const useRoot2 = vx2 === mod(-u, P);
6513 const noRoot = vx2 === mod(-u * ED25519_SQRT_M1, P);
6514 if (useRoot1)
6515 x = root1;
6516 if (useRoot2 || noRoot)
6517 x = root2;
6518 if (isNegativeLE(x, P))
6519 x = mod(-x, P);
6520 return { isValid: useRoot1 || useRoot2, value: x };
6521 }
6522 const Fp = Field(ED25519_P, undefined, true);
6523 const ed25519Defaults = {
6524 a: BigInt(-1),
6525 d: BigInt('37095705934669439343138083508754565189542113879843219016388785533085940283555'),
6526 Fp,
6527 n: BigInt('7237005577332262213973186563042994240857116359379907606001950938285454250989'),
6528 h: BigInt(8),
6529 Gx: BigInt('15112221349535400772501151409588531511454012693041857206046113283949847762202'),
6530 Gy: BigInt('46316835694926478169428394003475163141307993866256225615783033603165251855960'),
6531 hash: sha512,
6532 randomBytes,
6533 adjustScalarBytes,
6534 uvRatio,
6535 };
6536 const ed25519 = twistedEdwards(ed25519Defaults);
6537 function ed25519_domain(data, ctx, phflag) {
6538 if (ctx.length > 255)
6539 throw new Error('Context is too big');
6540 return concatBytes$1(utf8ToBytes$1('SigEd25519 no Ed25519 collisions'), new Uint8Array([phflag ? 1 : 0, ctx.length]), ctx, data);
6541 }
6542 twistedEdwards({ ...ed25519Defaults, domain: ed25519_domain });
6543 twistedEdwards({
6544 ...ed25519Defaults,
6545 domain: ed25519_domain,
6546 prehash: sha512,
6547 });
6548 (() => montgomery({
6549 P: ED25519_P,
6550 a: BigInt(486662),
6551 montgomeryBits: 255,
6552 nByteLength: 32,
6553 Gu: BigInt(9),
6554 powPminus2: (x) => {
6555 const P = ED25519_P;
6556 const { pow_p_5_8, b2 } = ed25519_pow_2_252_3(x);
6557 return mod(pow2(pow_p_5_8, BigInt(3), P) * b2, P);
6558 },
6559 adjustScalarBytes,
6560 randomBytes,
6561 }))();
6562 const ELL2_C1 = (Fp.ORDER + BigInt(3)) / BigInt(8);
6563 const ELL2_C2 = Fp.pow(_2n$1, ELL2_C1);
6564 const ELL2_C3 = Fp.sqrt(Fp.neg(Fp.ONE));
6565 const ELL2_C4 = (Fp.ORDER - BigInt(5)) / BigInt(8);
6566 const ELL2_J = BigInt(486662);
6567 function map_to_curve_elligator2_curve25519(u) {
6568 let tv1 = Fp.sqr(u);
6569 tv1 = Fp.mul(tv1, _2n$1);
6570 let xd = Fp.add(tv1, Fp.ONE);
6571 let x1n = Fp.neg(ELL2_J);
6572 let tv2 = Fp.sqr(xd);
6573 let gxd = Fp.mul(tv2, xd);
6574 let gx1 = Fp.mul(tv1, ELL2_J);
6575 gx1 = Fp.mul(gx1, x1n);
6576 gx1 = Fp.add(gx1, tv2);
6577 gx1 = Fp.mul(gx1, x1n);
6578 let tv3 = Fp.sqr(gxd);
6579 tv2 = Fp.sqr(tv3);
6580 tv3 = Fp.mul(tv3, gxd);
6581 tv3 = Fp.mul(tv3, gx1);
6582 tv2 = Fp.mul(tv2, tv3);
6583 let y11 = Fp.pow(tv2, ELL2_C4);
6584 y11 = Fp.mul(y11, tv3);
6585 let y12 = Fp.mul(y11, ELL2_C3);
6586 tv2 = Fp.sqr(y11);
6587 tv2 = Fp.mul(tv2, gxd);
6588 let e1 = Fp.eql(tv2, gx1);
6589 let y1 = Fp.cmov(y12, y11, e1);
6590 let x2n = Fp.mul(x1n, tv1);
6591 let y21 = Fp.mul(y11, u);
6592 y21 = Fp.mul(y21, ELL2_C2);
6593 let y22 = Fp.mul(y21, ELL2_C3);
6594 let gx2 = Fp.mul(gx1, tv1);
6595 tv2 = Fp.sqr(y21);
6596 tv2 = Fp.mul(tv2, gxd);
6597 let e2 = Fp.eql(tv2, gx2);
6598 let y2 = Fp.cmov(y22, y21, e2);
6599 tv2 = Fp.sqr(y1);
6600 tv2 = Fp.mul(tv2, gxd);
6601 let e3 = Fp.eql(tv2, gx1);
6602 let xn = Fp.cmov(x2n, x1n, e3);
6603 let y = Fp.cmov(y2, y1, e3);
6604 let e4 = Fp.isOdd(y);
6605 y = Fp.cmov(y, Fp.neg(y), e3 !== e4);
6606 return { xMn: xn, xMd: xd, yMn: y, yMd: _1n$1 };
6607 }
6608 const ELL2_C1_EDWARDS = FpSqrtEven(Fp, Fp.neg(BigInt(486664)));
6609 function map_to_curve_elligator2_edwards25519(u) {
6610 const { xMn, xMd, yMn, yMd } = map_to_curve_elligator2_curve25519(u);
6611 let xn = Fp.mul(xMn, yMd);
6612 xn = Fp.mul(xn, ELL2_C1_EDWARDS);
6613 let xd = Fp.mul(xMd, yMn);
6614 let yn = Fp.sub(xMn, xMd);
6615 let yd = Fp.add(xMn, xMd);
6616 let tv1 = Fp.mul(xd, yd);
6617 let e = Fp.eql(tv1, Fp.ZERO);
6618 xn = Fp.cmov(xn, Fp.ZERO, e);
6619 xd = Fp.cmov(xd, Fp.ONE, e);
6620 yn = Fp.cmov(yn, Fp.ONE, e);
6621 yd = Fp.cmov(yd, Fp.ONE, e);
6622 const inv = Fp.invertBatch([xd, yd]);
6623 return { x: Fp.mul(xn, inv[0]), y: Fp.mul(yn, inv[1]) };
6624 }
6625 (() => createHasher(ed25519.ExtendedPoint, (scalars) => map_to_curve_elligator2_edwards25519(scalars[0]), {
6626 DST: 'edwards25519_XMD:SHA-512_ELL2_RO_',
6627 encodeDST: 'edwards25519_XMD:SHA-512_ELL2_NU_',
6628 p: Fp.ORDER,
6629 m: 1,
6630 k: 128,
6631 expand: 'xmd',
6632 hash: sha512,
6633 }))();
6634 function assertRstPoint(other) {
6635 if (!(other instanceof RistPoint))
6636 throw new Error('RistrettoPoint expected');
6637 }
6638 const SQRT_M1 = ED25519_SQRT_M1;
6639 const SQRT_AD_MINUS_ONE = BigInt('25063068953384623474111414158702152701244531502492656460079210482610430750235');
6640 const INVSQRT_A_MINUS_D = BigInt('54469307008909316920995813868745141605393597292927456921205312896311721017578');
6641 const ONE_MINUS_D_SQ = BigInt('1159843021668779879193775521855586647937357759715417654439879720876111806838');
6642 const D_MINUS_ONE_SQ = BigInt('40440834346308536858101042469323190826248399146238708352240133220865137265952');
6643 const invertSqrt = (number) => uvRatio(_1n$1, number);
6644 const MAX_255B = BigInt('0x7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff');
6645 const bytes255ToNumberLE = (bytes) => ed25519.CURVE.Fp.create(bytesToNumberLE(bytes) & MAX_255B);
6646 function calcElligatorRistrettoMap(r0) {
6647 const { d } = ed25519.CURVE;
6648 const P = ed25519.CURVE.Fp.ORDER;
6649 const mod = ed25519.CURVE.Fp.create;
6650 const r = mod(SQRT_M1 * r0 * r0);
6651 const Ns = mod((r + _1n$1) * ONE_MINUS_D_SQ);
6652 let c = BigInt(-1);
6653 const D = mod((c - d * r) * mod(r + d));
6654 let { isValid: Ns_D_is_sq, value: s } = uvRatio(Ns, D);
6655 let s_ = mod(s * r0);
6656 if (!isNegativeLE(s_, P))
6657 s_ = mod(-s_);
6658 if (!Ns_D_is_sq)
6659 s = s_;
6660 if (!Ns_D_is_sq)
6661 c = r;
6662 const Nt = mod(c * (r - _1n$1) * D_MINUS_ONE_SQ - D);
6663 const s2 = s * s;
6664 const W0 = mod((s + s) * D);
6665 const W1 = mod(Nt * SQRT_AD_MINUS_ONE);
6666 const W2 = mod(_1n$1 - s2);
6667 const W3 = mod(_1n$1 + s2);
6668 return new ed25519.ExtendedPoint(mod(W0 * W3), mod(W2 * W1), mod(W1 * W3), mod(W0 * W2));
6669 }
6670 class RistPoint {
6671 constructor(ep) {
6672 this.ep = ep;
6673 }
6674 static fromAffine(ap) {
6675 return new RistPoint(ed25519.ExtendedPoint.fromAffine(ap));
6676 }
6677 static hashToCurve(hex) {
6678 hex = ensureBytes('ristrettoHash', hex, 64);
6679 const r1 = bytes255ToNumberLE(hex.slice(0, 32));
6680 const R1 = calcElligatorRistrettoMap(r1);
6681 const r2 = bytes255ToNumberLE(hex.slice(32, 64));
6682 const R2 = calcElligatorRistrettoMap(r2);
6683 return new RistPoint(R1.add(R2));
6684 }
6685 static fromHex(hex) {
6686 hex = ensureBytes('ristrettoHex', hex, 32);
6687 const { a, d } = ed25519.CURVE;
6688 const P = ed25519.CURVE.Fp.ORDER;
6689 const mod = ed25519.CURVE.Fp.create;
6690 const emsg = 'RistrettoPoint.fromHex: the hex is not valid encoding of RistrettoPoint';
6691 const s = bytes255ToNumberLE(hex);
6692 if (!equalBytes(numberToBytesLE(s, 32), hex) || isNegativeLE(s, P))
6693 throw new Error(emsg);
6694 const s2 = mod(s * s);
6695 const u1 = mod(_1n$1 + a * s2);
6696 const u2 = mod(_1n$1 - a * s2);
6697 const u1_2 = mod(u1 * u1);
6698 const u2_2 = mod(u2 * u2);
6699 const v = mod(a * d * u1_2 - u2_2);
6700 const { isValid, value: I } = invertSqrt(mod(v * u2_2));
6701 const Dx = mod(I * u2);
6702 const Dy = mod(I * Dx * v);
6703 let x = mod((s + s) * Dx);
6704 if (isNegativeLE(x, P))
6705 x = mod(-x);
6706 const y = mod(u1 * Dy);
6707 const t = mod(x * y);
6708 if (!isValid || isNegativeLE(t, P) || y === _0n$1)
6709 throw new Error(emsg);
6710 return new RistPoint(new ed25519.ExtendedPoint(x, y, _1n$1, t));
6711 }
6712 toRawBytes() {
6713 let { ex: x, ey: y, ez: z, et: t } = this.ep;
6714 const P = ed25519.CURVE.Fp.ORDER;
6715 const mod = ed25519.CURVE.Fp.create;
6716 const u1 = mod(mod(z + y) * mod(z - y));
6717 const u2 = mod(x * y);
6718 const u2sq = mod(u2 * u2);
6719 const { value: invsqrt } = invertSqrt(mod(u1 * u2sq));
6720 const D1 = mod(invsqrt * u1);
6721 const D2 = mod(invsqrt * u2);
6722 const zInv = mod(D1 * D2 * t);
6723 let D;
6724 if (isNegativeLE(t * zInv, P)) {
6725 let _x = mod(y * SQRT_M1);
6726 let _y = mod(x * SQRT_M1);
6727 x = _x;
6728 y = _y;
6729 D = mod(D1 * INVSQRT_A_MINUS_D);
6730 }
6731 else {
6732 D = D2;
6733 }
6734 if (isNegativeLE(x * zInv, P))
6735 y = mod(-y);
6736 let s = mod((z - y) * D);
6737 if (isNegativeLE(s, P))
6738 s = mod(-s);
6739 return numberToBytesLE(s, 32);
6740 }
6741 toHex() {
6742 return bytesToHex(this.toRawBytes());
6743 }
6744 toString() {
6745 return this.toHex();
6746 }
6747 equals(other) {
6748 assertRstPoint(other);
6749 const { ex: X1, ey: Y1 } = this.ep;
6750 const { ex: X2, ey: Y2 } = other.ep;
6751 const mod = ed25519.CURVE.Fp.create;
6752 const one = mod(X1 * Y2) === mod(Y1 * X2);
6753 const two = mod(Y1 * Y2) === mod(X1 * X2);
6754 return one || two;
6755 }
6756 add(other) {
6757 assertRstPoint(other);
6758 return new RistPoint(this.ep.add(other.ep));
6759 }
6760 subtract(other) {
6761 assertRstPoint(other);
6762 return new RistPoint(this.ep.subtract(other.ep));
6763 }
6764 multiply(scalar) {
6765 return new RistPoint(this.ep.multiply(scalar));
6766 }
6767 multiplyUnsafe(scalar) {
6768 return new RistPoint(this.ep.multiplyUnsafe(scalar));
6769 }
6770 }
6771 (() => {
6772 if (!RistPoint.BASE)
6773 RistPoint.BASE = new RistPoint(ed25519.ExtendedPoint.BASE);
6774 if (!RistPoint.ZERO)
6775 RistPoint.ZERO = new RistPoint(ed25519.ExtendedPoint.ZERO);
6776 return RistPoint;
6777 })();
6778
6779 function ed25519PairFromSeed(seed, onlyJs) {
6780 if (!util.hasBigInt || (!onlyJs && isReady())) {
6781 const full = ed25519KeypairFromSeed(seed);
6782 return {
6783 publicKey: full.slice(32),
6784 secretKey: full.slice(0, 64)
6785 };
6786 }
6787 const publicKey = ed25519.getPublicKey(seed);
6788 return {
6789 publicKey,
6790 secretKey: util.u8aConcatStrict([seed, publicKey])
6791 };
6792 }
6793
6794 function ed25519PairFromRandom() {
6795 return ed25519PairFromSeed(randomAsU8a());
6796 }
6797
6798 function ed25519PairFromSecret(secretKey) {
6799 if (secretKey.length !== 64) {
6800 throw new Error('Invalid secretKey provided');
6801 }
6802 return {
6803 publicKey: secretKey.slice(32),
6804 secretKey
6805 };
6806 }
6807
6808 function ed25519PairFromString(value) {
6809 return ed25519PairFromSeed(blake2AsU8a(util.stringToU8a(value)));
6810 }
6811
6812 function ed25519Sign(message, { publicKey, secretKey }, onlyJs) {
6813 if (!secretKey) {
6814 throw new Error('Expected a valid secretKey');
6815 }
6816 else if (!publicKey) {
6817 throw new Error('Expected a valid publicKey');
6818 }
6819 const messageU8a = util.u8aToU8a(message);
6820 const privateU8a = secretKey.subarray(0, 32);
6821 return !util.hasBigInt || (!onlyJs && isReady())
6822 ? ed25519Sign$1(publicKey, privateU8a, messageU8a)
6823 : ed25519.sign(messageU8a, privateU8a);
6824 }
6825
6826 function ed25519Verify(message, signature, publicKey, onlyJs) {
6827 const messageU8a = util.u8aToU8a(message);
6828 const publicKeyU8a = util.u8aToU8a(publicKey);
6829 const signatureU8a = util.u8aToU8a(signature);
6830 if (publicKeyU8a.length !== 32) {
6831 throw new Error(`Invalid publicKey, received ${publicKeyU8a.length}, expected 32`);
6832 }
6833 else if (signatureU8a.length !== 64) {
6834 throw new Error(`Invalid signature, received ${signatureU8a.length} bytes, expected 64`);
6835 }
6836 try {
6837 return !util.hasBigInt || (!onlyJs && isReady())
6838 ? ed25519Verify$1(signatureU8a, messageU8a, publicKeyU8a)
6839 : ed25519.verify(signatureU8a, messageU8a, publicKeyU8a);
6840 }
6841 catch {
6842 return false;
6843 }
6844 }
6845
6846 const keyHdkdEd25519 = createSeedDeriveFn(ed25519PairFromSeed, ed25519DeriveHard);
6847
6848 const SEC_LEN = 64;
6849 const PUB_LEN = 32;
6850 const TOT_LEN = SEC_LEN + PUB_LEN;
6851 function sr25519PairFromU8a(full) {
6852 const fullU8a = util.u8aToU8a(full);
6853 if (fullU8a.length !== TOT_LEN) {
6854 throw new Error(`Expected keypair with ${TOT_LEN} bytes, found ${fullU8a.length}`);
6855 }
6856 return {
6857 publicKey: fullU8a.slice(SEC_LEN, TOT_LEN),
6858 secretKey: fullU8a.slice(0, SEC_LEN)
6859 };
6860 }
6861
6862 function sr25519KeypairToU8a({ publicKey, secretKey }) {
6863 return util.u8aConcat(secretKey, publicKey).slice();
6864 }
6865
6866 function createDeriveFn(derive) {
6867 return (keypair, chainCode) => {
6868 if (!util.isU8a(chainCode) || chainCode.length !== 32) {
6869 throw new Error('Invalid chainCode passed to derive');
6870 }
6871 return sr25519PairFromU8a(derive(sr25519KeypairToU8a(keypair), chainCode));
6872 };
6873 }
6874
6875 const sr25519DeriveHard = createDeriveFn(sr25519DeriveKeypairHard);
6876
6877 const sr25519DeriveSoft = createDeriveFn(sr25519DeriveKeypairSoft);
6878
6879 function keyHdkdSr25519(keypair, { chainCode, isSoft }) {
6880 return isSoft
6881 ? sr25519DeriveSoft(keypair, chainCode)
6882 : sr25519DeriveHard(keypair, chainCode);
6883 }
6884
6885 const generators = {
6886 ecdsa: keyHdkdEcdsa,
6887 ed25519: keyHdkdEd25519,
6888 ethereum: keyHdkdEcdsa,
6889 sr25519: keyHdkdSr25519
6890 };
6891 function keyFromPath(pair, path, type) {
6892 const keyHdkd = generators[type];
6893 let result = pair;
6894 for (const junction of path) {
6895 result = keyHdkd(result, junction);
6896 }
6897 return result;
6898 }
6899
6900 function sr25519Agreement(secretKey, publicKey) {
6901 const secretKeyU8a = util.u8aToU8a(secretKey);
6902 const publicKeyU8a = util.u8aToU8a(publicKey);
6903 if (publicKeyU8a.length !== 32) {
6904 throw new Error(`Invalid publicKey, received ${publicKeyU8a.length} bytes, expected 32`);
6905 }
6906 else if (secretKeyU8a.length !== 64) {
6907 throw new Error(`Invalid secretKey, received ${secretKeyU8a.length} bytes, expected 64`);
6908 }
6909 return sr25519Agree(publicKeyU8a, secretKeyU8a);
6910 }
6911
6912 function sr25519DerivePublic(publicKey, chainCode) {
6913 const publicKeyU8a = util.u8aToU8a(publicKey);
6914 if (!util.isU8a(chainCode) || chainCode.length !== 32) {
6915 throw new Error('Invalid chainCode passed to derive');
6916 }
6917 else if (publicKeyU8a.length !== 32) {
6918 throw new Error(`Invalid publicKey, received ${publicKeyU8a.length} bytes, expected 32`);
6919 }
6920 return sr25519DerivePublicSoft(publicKeyU8a, chainCode);
6921 }
6922
6923 function sr25519PairFromSeed(seed) {
6924 const seedU8a = util.u8aToU8a(seed);
6925 if (seedU8a.length !== 32) {
6926 throw new Error(`Expected a seed matching 32 bytes, found ${seedU8a.length}`);
6927 }
6928 return sr25519PairFromU8a(sr25519KeypairFromSeed(seedU8a));
6929 }
6930
6931 function sr25519Sign(message, { publicKey, secretKey }) {
6932 if (publicKey?.length !== 32) {
6933 throw new Error('Expected a valid publicKey, 32-bytes');
6934 }
6935 else if (secretKey?.length !== 64) {
6936 throw new Error('Expected a valid secretKey, 64-bytes');
6937 }
6938 return sr25519Sign$1(publicKey, secretKey, util.u8aToU8a(message));
6939 }
6940
6941 function sr25519Verify(message, signature, publicKey) {
6942 const publicKeyU8a = util.u8aToU8a(publicKey);
6943 const signatureU8a = util.u8aToU8a(signature);
6944 if (publicKeyU8a.length !== 32) {
6945 throw new Error(`Invalid publicKey, received ${publicKeyU8a.length} bytes, expected 32`);
6946 }
6947 else if (signatureU8a.length !== 64) {
6948 throw new Error(`Invalid signature, received ${signatureU8a.length} bytes, expected 64`);
6949 }
6950 return sr25519Verify$1(signatureU8a, util.u8aToU8a(message), publicKeyU8a);
6951 }
6952
6953 const EMPTY_U8A$1 = new Uint8Array();
6954 function sr25519VrfSign(message, { secretKey }, context = EMPTY_U8A$1, extra = EMPTY_U8A$1) {
6955 if (secretKey?.length !== 64) {
6956 throw new Error('Invalid secretKey, expected 64-bytes');
6957 }
6958 return vrfSign(secretKey, util.u8aToU8a(context), util.u8aToU8a(message), util.u8aToU8a(extra));
6959 }
6960
6961 const EMPTY_U8A = new Uint8Array();
6962 function sr25519VrfVerify(message, signOutput, publicKey, context = EMPTY_U8A, extra = EMPTY_U8A) {
6963 const publicKeyU8a = util.u8aToU8a(publicKey);
6964 const proofU8a = util.u8aToU8a(signOutput);
6965 if (publicKeyU8a.length !== 32) {
6966 throw new Error('Invalid publicKey, expected 32-bytes');
6967 }
6968 else if (proofU8a.length !== 96) {
6969 throw new Error('Invalid vrfSign output, expected 96 bytes');
6970 }
6971 return vrfVerify(publicKeyU8a, util.u8aToU8a(context), util.u8aToU8a(message), util.u8aToU8a(extra), proofU8a);
6972 }
6973
6974 function encodeAddress(key, ss58Format = defaults.prefix) {
6975 const u8a = decodeAddress(key);
6976 if ((ss58Format < 0) || (ss58Format > 16383) || [46, 47].includes(ss58Format)) {
6977 throw new Error('Out of range ss58Format specified');
6978 }
6979 else if (!defaults.allowedDecodedLengths.includes(u8a.length)) {
6980 throw new Error(`Expected a valid key to convert, with length ${defaults.allowedDecodedLengths.join(', ')}`);
6981 }
6982 const input = util.u8aConcat(ss58Format < 64
6983 ? [ss58Format]
6984 : [
6985 ((ss58Format & 252) >> 2) | 64,
6986 (ss58Format >> 8) | ((ss58Format & 3) << 6)
6987 ], u8a);
6988 return base58Encode(util.u8aConcat(input, sshash(input).subarray(0, [32, 33].includes(u8a.length) ? 2 : 1)));
6989 }
6990
6991 function filterHard({ isHard }) {
6992 return isHard;
6993 }
6994 function deriveAddress(who, suri, ss58Format) {
6995 const { path } = keyExtractPath(suri);
6996 if (!path.length || path.every(filterHard)) {
6997 throw new Error('Expected suri to contain a combination of non-hard paths');
6998 }
6999 let publicKey = decodeAddress(who);
7000 for (const { chainCode } of path) {
7001 publicKey = sr25519DerivePublic(publicKey, chainCode);
7002 }
7003 return encodeAddress(publicKey, ss58Format);
7004 }
7005
7006 const PREFIX$1 = util.stringToU8a('modlpy/utilisuba');
7007 function createKeyDerived(who, index) {
7008 return blake2AsU8a(util.u8aConcat(PREFIX$1, decodeAddress(who), util.bnToU8a(index, BN_LE_16_OPTS)));
7009 }
7010
7011 function encodeDerivedAddress(who, index, ss58Format) {
7012 return encodeAddress(createKeyDerived(decodeAddress(who), index), ss58Format);
7013 }
7014
7015 function addressToU8a(who) {
7016 return decodeAddress(who);
7017 }
7018
7019 const PREFIX = util.stringToU8a('modlpy/utilisuba');
7020 function createKeyMulti(who, threshold) {
7021 return blake2AsU8a(util.u8aConcat(PREFIX, util.compactToU8a(who.length), ...util.u8aSorted(who.map(addressToU8a)), util.bnToU8a(threshold, BN_LE_16_OPTS)));
7022 }
7023
7024 function encodeMultiAddress(who, threshold, ss58Format) {
7025 return encodeAddress(createKeyMulti(who, threshold), ss58Format);
7026 }
7027
7028 function addressEq(a, b) {
7029 return util.u8aEq(decodeAddress(a), decodeAddress(b));
7030 }
7031
7032 const [SHA3_PI, SHA3_ROTL, _SHA3_IOTA] = [[], [], []];
7033 const _0n = BigInt(0);
7034 const _1n = BigInt(1);
7035 const _2n = BigInt(2);
7036 const _7n$1 = BigInt(7);
7037 const _256n$1 = BigInt(256);
7038 const _0x71n = BigInt(0x71);
7039 for (let round = 0, R = _1n, x = 1, y = 0; round < 24; round++) {
7040 [x, y] = [y, (2 * x + 3 * y) % 5];
7041 SHA3_PI.push(2 * (5 * y + x));
7042 SHA3_ROTL.push((((round + 1) * (round + 2)) / 2) % 64);
7043 let t = _0n;
7044 for (let j = 0; j < 7; j++) {
7045 R = ((R << _1n) ^ ((R >> _7n$1) * _0x71n)) % _256n$1;
7046 if (R & _2n)
7047 t ^= _1n << ((_1n << BigInt(j)) - _1n);
7048 }
7049 _SHA3_IOTA.push(t);
7050 }
7051 const [SHA3_IOTA_H, SHA3_IOTA_L] = u64.split(_SHA3_IOTA, true);
7052 const rotlH = (h, l, s) => s > 32 ? u64.rotlBH(h, l, s) : u64.rotlSH(h, l, s);
7053 const rotlL = (h, l, s) => s > 32 ? u64.rotlBL(h, l, s) : u64.rotlSL(h, l, s);
7054 function keccakP(s, rounds = 24) {
7055 const B = new Uint32Array(5 * 2);
7056 for (let round = 24 - rounds; round < 24; round++) {
7057 for (let x = 0; x < 10; x++)
7058 B[x] = s[x] ^ s[x + 10] ^ s[x + 20] ^ s[x + 30] ^ s[x + 40];
7059 for (let x = 0; x < 10; x += 2) {
7060 const idx1 = (x + 8) % 10;
7061 const idx0 = (x + 2) % 10;
7062 const B0 = B[idx0];
7063 const B1 = B[idx0 + 1];
7064 const Th = rotlH(B0, B1, 1) ^ B[idx1];
7065 const Tl = rotlL(B0, B1, 1) ^ B[idx1 + 1];
7066 for (let y = 0; y < 50; y += 10) {
7067 s[x + y] ^= Th;
7068 s[x + y + 1] ^= Tl;
7069 }
7070 }
7071 let curH = s[2];
7072 let curL = s[3];
7073 for (let t = 0; t < 24; t++) {
7074 const shift = SHA3_ROTL[t];
7075 const Th = rotlH(curH, curL, shift);
7076 const Tl = rotlL(curH, curL, shift);
7077 const PI = SHA3_PI[t];
7078 curH = s[PI];
7079 curL = s[PI + 1];
7080 s[PI] = Th;
7081 s[PI + 1] = Tl;
7082 }
7083 for (let y = 0; y < 50; y += 10) {
7084 for (let x = 0; x < 10; x++)
7085 B[x] = s[y + x];
7086 for (let x = 0; x < 10; x++)
7087 s[y + x] ^= ~B[(x + 2) % 10] & B[(x + 4) % 10];
7088 }
7089 s[0] ^= SHA3_IOTA_H[round];
7090 s[1] ^= SHA3_IOTA_L[round];
7091 }
7092 B.fill(0);
7093 }
7094 class Keccak extends Hash {
7095 constructor(blockLen, suffix, outputLen, enableXOF = false, rounds = 24) {
7096 super();
7097 this.blockLen = blockLen;
7098 this.suffix = suffix;
7099 this.outputLen = outputLen;
7100 this.enableXOF = enableXOF;
7101 this.rounds = rounds;
7102 this.pos = 0;
7103 this.posOut = 0;
7104 this.finished = false;
7105 this.destroyed = false;
7106 assert.number(outputLen);
7107 if (0 >= this.blockLen || this.blockLen >= 200)
7108 throw new Error('Sha3 supports only keccak-f1600 function');
7109 this.state = new Uint8Array(200);
7110 this.state32 = u32(this.state);
7111 }
7112 keccak() {
7113 keccakP(this.state32, this.rounds);
7114 this.posOut = 0;
7115 this.pos = 0;
7116 }
7117 update(data) {
7118 assert.exists(this);
7119 const { blockLen, state } = this;
7120 data = toBytes(data);
7121 const len = data.length;
7122 for (let pos = 0; pos < len;) {
7123 const take = Math.min(blockLen - this.pos, len - pos);
7124 for (let i = 0; i < take; i++)
7125 state[this.pos++] ^= data[pos++];
7126 if (this.pos === blockLen)
7127 this.keccak();
7128 }
7129 return this;
7130 }
7131 finish() {
7132 if (this.finished)
7133 return;
7134 this.finished = true;
7135 const { state, suffix, pos, blockLen } = this;
7136 state[pos] ^= suffix;
7137 if ((suffix & 0x80) !== 0 && pos === blockLen - 1)
7138 this.keccak();
7139 state[blockLen - 1] ^= 0x80;
7140 this.keccak();
7141 }
7142 writeInto(out) {
7143 assert.exists(this, false);
7144 assert.bytes(out);
7145 this.finish();
7146 const bufferOut = this.state;
7147 const { blockLen } = this;
7148 for (let pos = 0, len = out.length; pos < len;) {
7149 if (this.posOut >= blockLen)
7150 this.keccak();
7151 const take = Math.min(blockLen - this.posOut, len - pos);
7152 out.set(bufferOut.subarray(this.posOut, this.posOut + take), pos);
7153 this.posOut += take;
7154 pos += take;
7155 }
7156 return out;
7157 }
7158 xofInto(out) {
7159 if (!this.enableXOF)
7160 throw new Error('XOF is not possible for this instance');
7161 return this.writeInto(out);
7162 }
7163 xof(bytes) {
7164 assert.number(bytes);
7165 return this.xofInto(new Uint8Array(bytes));
7166 }
7167 digestInto(out) {
7168 assert.output(out, this);
7169 if (this.finished)
7170 throw new Error('digest() was already called');
7171 this.writeInto(out);
7172 this.destroy();
7173 return out;
7174 }
7175 digest() {
7176 return this.digestInto(new Uint8Array(this.outputLen));
7177 }
7178 destroy() {
7179 this.destroyed = true;
7180 this.state.fill(0);
7181 }
7182 _cloneInto(to) {
7183 const { blockLen, suffix, outputLen, rounds, enableXOF } = this;
7184 to || (to = new Keccak(blockLen, suffix, outputLen, enableXOF, rounds));
7185 to.state32.set(this.state32);
7186 to.pos = this.pos;
7187 to.posOut = this.posOut;
7188 to.finished = this.finished;
7189 to.rounds = rounds;
7190 to.suffix = suffix;
7191 to.outputLen = outputLen;
7192 to.enableXOF = enableXOF;
7193 to.destroyed = this.destroyed;
7194 return to;
7195 }
7196 }
7197 const gen = (suffix, blockLen, outputLen) => wrapConstructor(() => new Keccak(blockLen, suffix, outputLen));
7198 gen(0x06, 144, 224 / 8);
7199 gen(0x06, 136, 256 / 8);
7200 gen(0x06, 104, 384 / 8);
7201 gen(0x06, 72, 512 / 8);
7202 gen(0x01, 144, 224 / 8);
7203 const keccak_256 = gen(0x01, 136, 256 / 8);
7204 gen(0x01, 104, 384 / 8);
7205 const keccak_512 = gen(0x01, 72, 512 / 8);
7206 const genShake = (suffix, blockLen, outputLen) => wrapXOFConstructorWithOpts((opts = {}) => new Keccak(blockLen, suffix, opts.dkLen === undefined ? outputLen : opts.dkLen, true));
7207 genShake(0x1f, 168, 128 / 8);
7208 genShake(0x1f, 136, 256 / 8);
7209
7210 const keccakAsU8a = createDualHasher({ 256: keccak256, 512: keccak512 }, { 256: keccak_256, 512: keccak_512 });
7211 const keccak256AsU8a = createBitHasher(256, keccakAsU8a);
7212 const keccak512AsU8a = createBitHasher(512, keccakAsU8a);
7213 const keccakAsHex = createAsHex(keccakAsU8a);
7214
7215 function hasher(hashType, data, onlyJs) {
7216 return hashType === 'keccak'
7217 ? keccakAsU8a(data, undefined, onlyJs)
7218 : blake2AsU8a(data, undefined, undefined, onlyJs);
7219 }
7220
7221 function evmToAddress(evmAddress, ss58Format, hashType = 'blake2') {
7222 const message = util.u8aConcat('evm:', evmAddress);
7223 if (message.length !== 24) {
7224 throw new Error(`Converting ${evmAddress}: Invalid evm address length`);
7225 }
7226 return encodeAddress(hasher(hashType, message), ss58Format);
7227 }
7228
7229 function validateAddress(encoded, ignoreChecksum, ss58Format) {
7230 return !!decodeAddress(encoded, ignoreChecksum, ss58Format);
7231 }
7232
7233 function isAddress(address, ignoreChecksum, ss58Format) {
7234 try {
7235 return validateAddress(address, ignoreChecksum, ss58Format);
7236 }
7237 catch {
7238 return false;
7239 }
7240 }
7241
7242 function sortAddresses(addresses, ss58Format) {
7243 const u8aToAddress = (u8a) => encodeAddress(u8a, ss58Format);
7244 return util.u8aSorted(addresses.map(addressToU8a)).map(u8aToAddress);
7245 }
7246
7247 const l = util.logger('setSS58Format');
7248 function setSS58Format(prefix) {
7249 l.warn('Global setting of the ss58Format is deprecated and not recommended. Set format on the keyring (if used) or as part of the address encode function');
7250 defaults.prefix = prefix;
7251 }
7252
7253 const chars = 'abcdefghijklmnopqrstuvwxyz234567';
7254 const config$1 = {
7255 chars,
7256 coder: utils.chain(
7257 utils.radix2(5), utils.alphabet(chars), {
7258 decode: (input) => input.split(''),
7259 encode: (input) => input.join('')
7260 }),
7261 ipfs: 'b',
7262 type: 'base32'
7263 };
7264 const base32Validate = createValidate(config$1);
7265 const isBase32 = createIs(base32Validate);
7266 const base32Decode = createDecode(config$1, base32Validate);
7267 const base32Encode = createEncode(config$1);
7268
7269 const config = {
7270 chars: 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/',
7271 coder: base64,
7272 type: 'base64'
7273 };
7274 const base64Validate = createValidate(config);
7275 const isBase64 = createIs(base64Validate);
7276 const base64Decode = createDecode(config, base64Validate);
7277 const base64Encode = createEncode(config);
7278
7279 function base64Pad(value) {
7280 return value.padEnd(value.length + (value.length % 4), '=');
7281 }
7282
7283 function base64Trim(value) {
7284 while (value.length && value[value.length - 1] === '=') {
7285 value = value.slice(0, -1);
7286 }
7287 return value;
7288 }
7289
7290 function secp256k1Compress(publicKey, onlyJs) {
7291 if (![33, 65].includes(publicKey.length)) {
7292 throw new Error(`Invalid publicKey provided, received ${publicKey.length} bytes input`);
7293 }
7294 if (publicKey.length === 33) {
7295 return publicKey;
7296 }
7297 return !util.hasBigInt || (!onlyJs && isReady())
7298 ? secp256k1Compress$1(publicKey)
7299 : secp256k1.ProjectivePoint.fromHex(publicKey).toRawBytes(true);
7300 }
7301
7302 function secp256k1Expand(publicKey, onlyJs) {
7303 if (![33, 65].includes(publicKey.length)) {
7304 throw new Error(`Invalid publicKey provided, received ${publicKey.length} bytes input`);
7305 }
7306 if (publicKey.length === 65) {
7307 return publicKey.subarray(1);
7308 }
7309 if (!util.hasBigInt || (!onlyJs && isReady())) {
7310 return secp256k1Expand$1(publicKey).subarray(1);
7311 }
7312 const { px, py } = secp256k1.ProjectivePoint.fromHex(publicKey);
7313 return util.u8aConcat(util.bnToU8a(px, BN_BE_256_OPTS), util.bnToU8a(py, BN_BE_256_OPTS));
7314 }
7315
7316 function secp256k1Recover(msgHash, signature, recovery, hashType = 'blake2', onlyJs) {
7317 const sig = util.u8aToU8a(signature).subarray(0, 64);
7318 const msg = util.u8aToU8a(msgHash);
7319 const publicKey = !util.hasBigInt || (!onlyJs && isReady())
7320 ? secp256k1Recover$1(msg, sig, recovery)
7321 : secp256k1.Signature
7322 .fromCompact(sig)
7323 .addRecoveryBit(recovery)
7324 .recoverPublicKey(msg)
7325 .toRawBytes();
7326 if (!publicKey) {
7327 throw new Error('Unable to recover publicKey from signature');
7328 }
7329 return hashType === 'keccak'
7330 ? secp256k1Expand(publicKey, onlyJs)
7331 : secp256k1Compress(publicKey, onlyJs);
7332 }
7333
7334 function secp256k1Sign(message, { secretKey }, hashType = 'blake2', onlyJs) {
7335 if (secretKey?.length !== 32) {
7336 throw new Error('Expected valid secp256k1 secretKey, 32-bytes');
7337 }
7338 const data = hasher(hashType, message, onlyJs);
7339 if (!util.hasBigInt || (!onlyJs && isReady())) {
7340 return secp256k1Sign$1(data, secretKey);
7341 }
7342 const signature = secp256k1.sign(data, secretKey, { lowS: true });
7343 return util.u8aConcat(util.bnToU8a(signature.r, BN_BE_256_OPTS), util.bnToU8a(signature.s, BN_BE_256_OPTS), new Uint8Array([signature.recovery || 0]));
7344 }
7345
7346 const N = 'ffffffff ffffffff ffffffff fffffffe baaedce6 af48a03b bfd25e8c d0364141'.replace(/ /g, '');
7347 const N_BI = BigInt$1(`0x${N}`);
7348 const N_BN = new util.BN(N, 'hex');
7349 function addBi(seckey, tweak) {
7350 let res = util.u8aToBigInt(tweak, BN_BE_OPTS);
7351 if (res >= N_BI) {
7352 throw new Error('Tweak parameter is out of range');
7353 }
7354 res += util.u8aToBigInt(seckey, BN_BE_OPTS);
7355 if (res >= N_BI) {
7356 res -= N_BI;
7357 }
7358 if (res === util._0n) {
7359 throw new Error('Invalid resulting private key');
7360 }
7361 return util.nToU8a(res, BN_BE_256_OPTS);
7362 }
7363 function addBn(seckey, tweak) {
7364 const res = new util.BN(tweak);
7365 if (res.cmp(N_BN) >= 0) {
7366 throw new Error('Tweak parameter is out of range');
7367 }
7368 res.iadd(new util.BN(seckey));
7369 if (res.cmp(N_BN) >= 0) {
7370 res.isub(N_BN);
7371 }
7372 if (res.isZero()) {
7373 throw new Error('Invalid resulting private key');
7374 }
7375 return util.bnToU8a(res, BN_BE_256_OPTS);
7376 }
7377 function secp256k1PrivateKeyTweakAdd(seckey, tweak, onlyBn) {
7378 if (!util.isU8a(seckey) || seckey.length !== 32) {
7379 throw new Error('Expected seckey to be an Uint8Array with length 32');
7380 }
7381 else if (!util.isU8a(tweak) || tweak.length !== 32) {
7382 throw new Error('Expected tweak to be an Uint8Array with length 32');
7383 }
7384 return !util.hasBigInt || onlyBn
7385 ? addBn(seckey, tweak)
7386 : addBi(seckey, tweak);
7387 }
7388
7389 function secp256k1Verify(msgHash, signature, address, hashType = 'blake2', onlyJs) {
7390 const sig = util.u8aToU8a(signature);
7391 if (sig.length !== 65) {
7392 throw new Error(`Expected signature with 65 bytes, ${sig.length} found instead`);
7393 }
7394 const publicKey = secp256k1Recover(hasher(hashType, msgHash), sig, sig[64], hashType, onlyJs);
7395 const signerAddr = hasher(hashType, publicKey, onlyJs);
7396 const inputAddr = util.u8aToU8a(address);
7397 return util.u8aEq(publicKey, inputAddr) || (hashType === 'keccak'
7398 ? util.u8aEq(signerAddr.slice(-20), inputAddr.slice(-20))
7399 : util.u8aEq(signerAddr, inputAddr));
7400 }
7401
7402 function getH160(u8a) {
7403 if ([33, 65].includes(u8a.length)) {
7404 u8a = keccakAsU8a(secp256k1Expand(u8a));
7405 }
7406 return u8a.slice(-20);
7407 }
7408 function ethereumEncode(addressOrPublic) {
7409 if (!addressOrPublic) {
7410 return '0x';
7411 }
7412 const u8aAddress = util.u8aToU8a(addressOrPublic);
7413 if (![20, 32, 33, 65].includes(u8aAddress.length)) {
7414 throw new Error(`Invalid address or publicKey provided, received ${u8aAddress.length} bytes input`);
7415 }
7416 const address = util.u8aToHex(getH160(u8aAddress), -1, false);
7417 const hash = util.u8aToHex(keccakAsU8a(address), -1, false);
7418 let result = '';
7419 for (let i = 0; i < 40; i++) {
7420 result = `${result}${parseInt(hash[i], 16) > 7 ? address[i].toUpperCase() : address[i]}`;
7421 }
7422 return `0x${result}`;
7423 }
7424
7425 function isInvalidChar(char, byte) {
7426 return char !== (byte > 7
7427 ? char.toUpperCase()
7428 : char.toLowerCase());
7429 }
7430 function isEthereumChecksum(_address) {
7431 const address = _address.replace('0x', '');
7432 const hash = util.u8aToHex(keccakAsU8a(address.toLowerCase()), -1, false);
7433 for (let i = 0; i < 40; i++) {
7434 if (isInvalidChar(address[i], parseInt(hash[i], 16))) {
7435 return false;
7436 }
7437 }
7438 return true;
7439 }
7440
7441 function isEthereumAddress(address) {
7442 if (!address || address.length !== 42 || !util.isHex(address)) {
7443 return false;
7444 }
7445 else if (/^(0x)?[0-9a-f]{40}$/.test(address) || /^(0x)?[0-9A-F]{40}$/.test(address)) {
7446 return true;
7447 }
7448 return isEthereumChecksum(address);
7449 }
7450
7451 const JS_HASH = {
7452 256: sha256,
7453 512: sha512
7454 };
7455 const WA_MHAC = {
7456 256: hmacSha256,
7457 512: hmacSha512
7458 };
7459 function createSha(bitLength) {
7460 return (key, data, onlyJs) => hmacShaAsU8a(key, data, bitLength, onlyJs);
7461 }
7462 function hmacShaAsU8a(key, data, bitLength = 256, onlyJs) {
7463 const u8aKey = util.u8aToU8a(key);
7464 return !util.hasBigInt || (!onlyJs && isReady())
7465 ? WA_MHAC[bitLength](u8aKey, data)
7466 : hmac(JS_HASH[bitLength], u8aKey, data);
7467 }
7468 const hmacSha256AsU8a = createSha(256);
7469 const hmacSha512AsU8a = createSha(512);
7470
7471 const HARDENED = 0x80000000;
7472 function hdValidatePath(path) {
7473 if (!path.startsWith('m/')) {
7474 return false;
7475 }
7476 const parts = path.split('/').slice(1);
7477 for (const p of parts) {
7478 const n = /^\d+'?$/.test(p)
7479 ? parseInt(p.replace(/'$/, ''), 10)
7480 : Number.NaN;
7481 if (isNaN(n) || (n >= HARDENED) || (n < 0)) {
7482 return false;
7483 }
7484 }
7485 return true;
7486 }
7487
7488 const MASTER_SECRET = util.stringToU8a('Bitcoin seed');
7489 function createCoded(secretKey, chainCode) {
7490 return {
7491 chainCode,
7492 publicKey: secp256k1PairFromSeed(secretKey).publicKey,
7493 secretKey
7494 };
7495 }
7496 function deriveChild(hd, index) {
7497 const indexBuffer = util.bnToU8a(index, BN_BE_32_OPTS);
7498 const data = index >= HARDENED
7499 ? util.u8aConcat(new Uint8Array(1), hd.secretKey, indexBuffer)
7500 : util.u8aConcat(hd.publicKey, indexBuffer);
7501 try {
7502 const I = hmacShaAsU8a(hd.chainCode, data, 512);
7503 return createCoded(secp256k1PrivateKeyTweakAdd(hd.secretKey, I.slice(0, 32)), I.slice(32));
7504 }
7505 catch {
7506 return deriveChild(hd, index + 1);
7507 }
7508 }
7509 function hdEthereum(seed, path = '') {
7510 const I = hmacShaAsU8a(MASTER_SECRET, seed, 512);
7511 let hd = createCoded(I.slice(0, 32), I.slice(32));
7512 if (!path || path === 'm' || path === 'M' || path === "m'" || path === "M'") {
7513 return hd;
7514 }
7515 if (!hdValidatePath(path)) {
7516 throw new Error('Invalid derivation path');
7517 }
7518 const parts = path.split('/').slice(1);
7519 for (const p of parts) {
7520 hd = deriveChild(hd, parseInt(p, 10) + ((p.length > 1) && p.endsWith("'")
7521 ? HARDENED
7522 : 0));
7523 }
7524 return hd;
7525 }
7526
7527 function pbkdf2Init(hash, _password, _salt, _opts) {
7528 assert.hash(hash);
7529 const opts = checkOpts({ dkLen: 32, asyncTick: 10 }, _opts);
7530 const { c, dkLen, asyncTick } = opts;
7531 assert.number(c);
7532 assert.number(dkLen);
7533 assert.number(asyncTick);
7534 if (c < 1)
7535 throw new Error('PBKDF2: iterations (c) should be >= 1');
7536 const password = toBytes(_password);
7537 const salt = toBytes(_salt);
7538 const DK = new Uint8Array(dkLen);
7539 const PRF = hmac.create(hash, password);
7540 const PRFSalt = PRF._cloneInto().update(salt);
7541 return { c, dkLen, asyncTick, DK, PRF, PRFSalt };
7542 }
7543 function pbkdf2Output(PRF, PRFSalt, DK, prfW, u) {
7544 PRF.destroy();
7545 PRFSalt.destroy();
7546 if (prfW)
7547 prfW.destroy();
7548 u.fill(0);
7549 return DK;
7550 }
7551 function pbkdf2(hash, password, salt, opts) {
7552 const { c, dkLen, DK, PRF, PRFSalt } = pbkdf2Init(hash, password, salt, opts);
7553 let prfW;
7554 const arr = new Uint8Array(4);
7555 const view = createView(arr);
7556 const u = new Uint8Array(PRF.outputLen);
7557 for (let ti = 1, pos = 0; pos < dkLen; ti++, pos += PRF.outputLen) {
7558 const Ti = DK.subarray(pos, pos + PRF.outputLen);
7559 view.setInt32(0, ti, false);
7560 (prfW = PRFSalt._cloneInto(prfW)).update(arr).digestInto(u);
7561 Ti.set(u.subarray(0, Ti.length));
7562 for (let ui = 1; ui < c; ui++) {
7563 PRF._cloneInto(prfW).update(u).digestInto(u);
7564 for (let i = 0; i < Ti.length; i++)
7565 Ti[i] ^= u[i];
7566 }
7567 }
7568 return pbkdf2Output(PRF, PRFSalt, DK, prfW, u);
7569 }
7570
7571 function pbkdf2Encode(passphrase, salt = randomAsU8a(), rounds = 2048, onlyJs) {
7572 const u8aPass = util.u8aToU8a(passphrase);
7573 const u8aSalt = util.u8aToU8a(salt);
7574 return {
7575 password: !util.hasBigInt || (!onlyJs && isReady())
7576 ? pbkdf2$1(u8aPass, u8aSalt, rounds)
7577 : pbkdf2(sha512, u8aPass, u8aSalt, { c: rounds, dkLen: 64 }),
7578 rounds,
7579 salt
7580 };
7581 }
7582
7583 const shaAsU8a = createDualHasher({ 256: sha256$1, 512: sha512$1 }, { 256: sha256, 512: sha512 });
7584 const sha256AsU8a = createBitHasher(256, shaAsU8a);
7585 const sha512AsU8a = createBitHasher(512, shaAsU8a);
7586
7587 const DEFAULT_WORDLIST = 'abandon|ability|able|about|above|absent|absorb|abstract|absurd|abuse|access|accident|account|accuse|achieve|acid|acoustic|acquire|across|act|action|actor|actress|actual|adapt|add|addict|address|adjust|admit|adult|advance|advice|aerobic|affair|afford|afraid|again|age|agent|agree|ahead|aim|air|airport|aisle|alarm|album|alcohol|alert|alien|all|alley|allow|almost|alone|alpha|already|also|alter|always|amateur|amazing|among|amount|amused|analyst|anchor|ancient|anger|angle|angry|animal|ankle|announce|annual|another|answer|antenna|antique|anxiety|any|apart|apology|appear|apple|approve|april|arch|arctic|area|arena|argue|arm|armed|armor|army|around|arrange|arrest|arrive|arrow|art|artefact|artist|artwork|ask|aspect|assault|asset|assist|assume|asthma|athlete|atom|attack|attend|attitude|attract|auction|audit|august|aunt|author|auto|autumn|average|avocado|avoid|awake|aware|away|awesome|awful|awkward|axis|baby|bachelor|bacon|badge|bag|balance|balcony|ball|bamboo|banana|banner|bar|barely|bargain|barrel|base|basic|basket|battle|beach|bean|beauty|because|become|beef|before|begin|behave|behind|believe|below|belt|bench|benefit|best|betray|better|between|beyond|bicycle|bid|bike|bind|biology|bird|birth|bitter|black|blade|blame|blanket|blast|bleak|bless|blind|blood|blossom|blouse|blue|blur|blush|board|boat|body|boil|bomb|bone|bonus|book|boost|border|boring|borrow|boss|bottom|bounce|box|boy|bracket|brain|brand|brass|brave|bread|breeze|brick|bridge|brief|bright|bring|brisk|broccoli|broken|bronze|broom|brother|brown|brush|bubble|buddy|budget|buffalo|build|bulb|bulk|bullet|bundle|bunker|burden|burger|burst|bus|business|busy|butter|buyer|buzz|cabbage|cabin|cable|cactus|cage|cake|call|calm|camera|camp|can|canal|cancel|candy|cannon|canoe|canvas|canyon|capable|capital|captain|car|carbon|card|cargo|carpet|carry|cart|case|cash|casino|castle|casual|cat|catalog|catch|category|cattle|caught|cause|caution|cave|ceiling|celery|cement|census|century|cereal|certain|chair|chalk|champion|change|chaos|chapter|charge|chase|chat|cheap|check|cheese|chef|cherry|chest|chicken|chief|child|chimney|choice|choose|chronic|chuckle|chunk|churn|cigar|cinnamon|circle|citizen|city|civil|claim|clap|clarify|claw|clay|clean|clerk|clever|click|client|cliff|climb|clinic|clip|clock|clog|close|cloth|cloud|clown|club|clump|cluster|clutch|coach|coast|coconut|code|coffee|coil|coin|collect|color|column|combine|come|comfort|comic|common|company|concert|conduct|confirm|congress|connect|consider|control|convince|cook|cool|copper|copy|coral|core|corn|correct|cost|cotton|couch|country|couple|course|cousin|cover|coyote|crack|cradle|craft|cram|crane|crash|crater|crawl|crazy|cream|credit|creek|crew|cricket|crime|crisp|critic|crop|cross|crouch|crowd|crucial|cruel|cruise|crumble|crunch|crush|cry|crystal|cube|culture|cup|cupboard|curious|current|curtain|curve|cushion|custom|cute|cycle|dad|damage|damp|dance|danger|daring|dash|daughter|dawn|day|deal|debate|debris|decade|december|decide|decline|decorate|decrease|deer|defense|define|defy|degree|delay|deliver|demand|demise|denial|dentist|deny|depart|depend|deposit|depth|deputy|derive|describe|desert|design|desk|despair|destroy|detail|detect|develop|device|devote|diagram|dial|diamond|diary|dice|diesel|diet|differ|digital|dignity|dilemma|dinner|dinosaur|direct|dirt|disagree|discover|disease|dish|dismiss|disorder|display|distance|divert|divide|divorce|dizzy|doctor|document|dog|doll|dolphin|domain|donate|donkey|donor|door|dose|double|dove|draft|dragon|drama|drastic|draw|dream|dress|drift|drill|drink|drip|drive|drop|drum|dry|duck|dumb|dune|during|dust|dutch|duty|dwarf|dynamic|eager|eagle|early|earn|earth|easily|east|easy|echo|ecology|economy|edge|edit|educate|effort|egg|eight|either|elbow|elder|electric|elegant|element|elephant|elevator|elite|else|embark|embody|embrace|emerge|emotion|employ|empower|empty|enable|enact|end|endless|endorse|enemy|energy|enforce|engage|engine|enhance|enjoy|enlist|enough|enrich|enroll|ensure|enter|entire|entry|envelope|episode|equal|equip|era|erase|erode|erosion|error|erupt|escape|essay|essence|estate|eternal|ethics|evidence|evil|evoke|evolve|exact|example|excess|exchange|excite|exclude|excuse|execute|exercise|exhaust|exhibit|exile|exist|exit|exotic|expand|expect|expire|explain|expose|express|extend|extra|eye|eyebrow|fabric|face|faculty|fade|faint|faith|fall|false|fame|family|famous|fan|fancy|fantasy|farm|fashion|fat|fatal|father|fatigue|fault|favorite|feature|february|federal|fee|feed|feel|female|fence|festival|fetch|fever|few|fiber|fiction|field|figure|file|film|filter|final|find|fine|finger|finish|fire|firm|first|fiscal|fish|fit|fitness|fix|flag|flame|flash|flat|flavor|flee|flight|flip|float|flock|floor|flower|fluid|flush|fly|foam|focus|fog|foil|fold|follow|food|foot|force|forest|forget|fork|fortune|forum|forward|fossil|foster|found|fox|fragile|frame|frequent|fresh|friend|fringe|frog|front|frost|frown|frozen|fruit|fuel|fun|funny|furnace|fury|future|gadget|gain|galaxy|gallery|game|gap|garage|garbage|garden|garlic|garment|gas|gasp|gate|gather|gauge|gaze|general|genius|genre|gentle|genuine|gesture|ghost|giant|gift|giggle|ginger|giraffe|girl|give|glad|glance|glare|glass|glide|glimpse|globe|gloom|glory|glove|glow|glue|goat|goddess|gold|good|goose|gorilla|gospel|gossip|govern|gown|grab|grace|grain|grant|grape|grass|gravity|great|green|grid|grief|grit|grocery|group|grow|grunt|guard|guess|guide|guilt|guitar|gun|gym|habit|hair|half|hammer|hamster|hand|happy|harbor|hard|harsh|harvest|hat|have|hawk|hazard|head|health|heart|heavy|hedgehog|height|hello|helmet|help|hen|hero|hidden|high|hill|hint|hip|hire|history|hobby|hockey|hold|hole|holiday|hollow|home|honey|hood|hope|horn|horror|horse|hospital|host|hotel|hour|hover|hub|huge|human|humble|humor|hundred|hungry|hunt|hurdle|hurry|hurt|husband|hybrid|ice|icon|idea|identify|idle|ignore|ill|illegal|illness|image|imitate|immense|immune|impact|impose|improve|impulse|inch|include|income|increase|index|indicate|indoor|industry|infant|inflict|inform|inhale|inherit|initial|inject|injury|inmate|inner|innocent|input|inquiry|insane|insect|inside|inspire|install|intact|interest|into|invest|invite|involve|iron|island|isolate|issue|item|ivory|jacket|jaguar|jar|jazz|jealous|jeans|jelly|jewel|job|join|joke|journey|joy|judge|juice|jump|jungle|junior|junk|just|kangaroo|keen|keep|ketchup|key|kick|kid|kidney|kind|kingdom|kiss|kit|kitchen|kite|kitten|kiwi|knee|knife|knock|know|lab|label|labor|ladder|lady|lake|lamp|language|laptop|large|later|latin|laugh|laundry|lava|law|lawn|lawsuit|layer|lazy|leader|leaf|learn|leave|lecture|left|leg|legal|legend|leisure|lemon|lend|length|lens|leopard|lesson|letter|level|liar|liberty|library|license|life|lift|light|like|limb|limit|link|lion|liquid|list|little|live|lizard|load|loan|lobster|local|lock|logic|lonely|long|loop|lottery|loud|lounge|love|loyal|lucky|luggage|lumber|lunar|lunch|luxury|lyrics|machine|mad|magic|magnet|maid|mail|main|major|make|mammal|man|manage|mandate|mango|mansion|manual|maple|marble|march|margin|marine|market|marriage|mask|mass|master|match|material|math|matrix|matter|maximum|maze|meadow|mean|measure|meat|mechanic|medal|media|melody|melt|member|memory|mention|menu|mercy|merge|merit|merry|mesh|message|metal|method|middle|midnight|milk|million|mimic|mind|minimum|minor|minute|miracle|mirror|misery|miss|mistake|mix|mixed|mixture|mobile|model|modify|mom|moment|monitor|monkey|monster|month|moon|moral|more|morning|mosquito|mother|motion|motor|mountain|mouse|move|movie|much|muffin|mule|multiply|muscle|museum|mushroom|music|must|mutual|myself|mystery|myth|naive|name|napkin|narrow|nasty|nation|nature|near|neck|need|negative|neglect|neither|nephew|nerve|nest|net|network|neutral|never|news|next|nice|night|noble|noise|nominee|noodle|normal|north|nose|notable|note|nothing|notice|novel|now|nuclear|number|nurse|nut|oak|obey|object|oblige|obscure|observe|obtain|obvious|occur|ocean|october|odor|off|offer|office|often|oil|okay|old|olive|olympic|omit|once|one|onion|online|only|open|opera|opinion|oppose|option|orange|orbit|orchard|order|ordinary|organ|orient|original|orphan|ostrich|other|outdoor|outer|output|outside|oval|oven|over|own|owner|oxygen|oyster|ozone|pact|paddle|page|pair|palace|palm|panda|panel|panic|panther|paper|parade|parent|park|parrot|party|pass|patch|path|patient|patrol|pattern|pause|pave|payment|peace|peanut|pear|peasant|pelican|pen|penalty|pencil|people|pepper|perfect|permit|person|pet|phone|photo|phrase|physical|piano|picnic|picture|piece|pig|pigeon|pill|pilot|pink|pioneer|pipe|pistol|pitch|pizza|place|planet|plastic|plate|play|please|pledge|pluck|plug|plunge|poem|poet|point|polar|pole|police|pond|pony|pool|popular|portion|position|possible|post|potato|pottery|poverty|powder|power|practice|praise|predict|prefer|prepare|present|pretty|prevent|price|pride|primary|print|priority|prison|private|prize|problem|process|produce|profit|program|project|promote|proof|property|prosper|protect|proud|provide|public|pudding|pull|pulp|pulse|pumpkin|punch|pupil|puppy|purchase|purity|purpose|purse|push|put|puzzle|pyramid|quality|quantum|quarter|question|quick|quit|quiz|quote|rabbit|raccoon|race|rack|radar|radio|rail|rain|raise|rally|ramp|ranch|random|range|rapid|rare|rate|rather|raven|raw|razor|ready|real|reason|rebel|rebuild|recall|receive|recipe|record|recycle|reduce|reflect|reform|refuse|region|regret|regular|reject|relax|release|relief|rely|remain|remember|remind|remove|render|renew|rent|reopen|repair|repeat|replace|report|require|rescue|resemble|resist|resource|response|result|retire|retreat|return|reunion|reveal|review|reward|rhythm|rib|ribbon|rice|rich|ride|ridge|rifle|right|rigid|ring|riot|ripple|risk|ritual|rival|river|road|roast|robot|robust|rocket|romance|roof|rookie|room|rose|rotate|rough|round|route|royal|rubber|rude|rug|rule|run|runway|rural|sad|saddle|sadness|safe|sail|salad|salmon|salon|salt|salute|same|sample|sand|satisfy|satoshi|sauce|sausage|save|say|scale|scan|scare|scatter|scene|scheme|school|science|scissors|scorpion|scout|scrap|screen|script|scrub|sea|search|season|seat|second|secret|section|security|seed|seek|segment|select|sell|seminar|senior|sense|sentence|series|service|session|settle|setup|seven|shadow|shaft|shallow|share|shed|shell|sheriff|shield|shift|shine|ship|shiver|shock|shoe|shoot|shop|short|shoulder|shove|shrimp|shrug|shuffle|shy|sibling|sick|side|siege|sight|sign|silent|silk|silly|silver|similar|simple|since|sing|siren|sister|situate|six|size|skate|sketch|ski|skill|skin|skirt|skull|slab|slam|sleep|slender|slice|slide|slight|slim|slogan|slot|slow|slush|small|smart|smile|smoke|smooth|snack|snake|snap|sniff|snow|soap|soccer|social|sock|soda|soft|solar|soldier|solid|solution|solve|someone|song|soon|sorry|sort|soul|sound|soup|source|south|space|spare|spatial|spawn|speak|special|speed|spell|spend|sphere|spice|spider|spike|spin|spirit|split|spoil|sponsor|spoon|sport|spot|spray|spread|spring|spy|square|squeeze|squirrel|stable|stadium|staff|stage|stairs|stamp|stand|start|state|stay|steak|steel|stem|step|stereo|stick|still|sting|stock|stomach|stone|stool|story|stove|strategy|street|strike|strong|struggle|student|stuff|stumble|style|subject|submit|subway|success|such|sudden|suffer|sugar|suggest|suit|summer|sun|sunny|sunset|super|supply|supreme|sure|surface|surge|surprise|surround|survey|suspect|sustain|swallow|swamp|swap|swarm|swear|sweet|swift|swim|swing|switch|sword|symbol|symptom|syrup|system|table|tackle|tag|tail|talent|talk|tank|tape|target|task|taste|tattoo|taxi|teach|team|tell|ten|tenant|tennis|tent|term|test|text|thank|that|theme|then|theory|there|they|thing|this|thought|three|thrive|throw|thumb|thunder|ticket|tide|tiger|tilt|timber|time|tiny|tip|tired|tissue|title|toast|tobacco|today|toddler|toe|together|toilet|token|tomato|tomorrow|tone|tongue|tonight|tool|tooth|top|topic|topple|torch|tornado|tortoise|toss|total|tourist|toward|tower|town|toy|track|trade|traffic|tragic|train|transfer|trap|trash|travel|tray|treat|tree|trend|trial|tribe|trick|trigger|trim|trip|trophy|trouble|truck|true|truly|trumpet|trust|truth|try|tube|tuition|tumble|tuna|tunnel|turkey|turn|turtle|twelve|twenty|twice|twin|twist|two|type|typical|ugly|umbrella|unable|unaware|uncle|uncover|under|undo|unfair|unfold|unhappy|uniform|unique|unit|universe|unknown|unlock|until|unusual|unveil|update|upgrade|uphold|upon|upper|upset|urban|urge|usage|use|used|useful|useless|usual|utility|vacant|vacuum|vague|valid|valley|valve|van|vanish|vapor|various|vast|vault|vehicle|velvet|vendor|venture|venue|verb|verify|version|very|vessel|veteran|viable|vibrant|vicious|victory|video|view|village|vintage|violin|virtual|virus|visa|visit|visual|vital|vivid|vocal|voice|void|volcano|volume|vote|voyage|wage|wagon|wait|walk|wall|walnut|want|warfare|warm|warrior|wash|wasp|waste|water|wave|way|wealth|weapon|wear|weasel|weather|web|wedding|weekend|weird|welcome|west|wet|whale|what|wheat|wheel|when|where|whip|whisper|wide|width|wife|wild|will|win|window|wine|wing|wink|winner|winter|wire|wisdom|wise|wish|witness|wolf|woman|wonder|wood|wool|word|work|world|worry|worth|wrap|wreck|wrestle|wrist|write|wrong|yard|year|yellow|you|young|youth|zebra|zero|zone|zoo'.split('|');
7588
7589 const INVALID_MNEMONIC = 'Invalid mnemonic';
7590 const INVALID_ENTROPY = 'Invalid entropy';
7591 const INVALID_CHECKSUM = 'Invalid mnemonic checksum';
7592 function normalize(str) {
7593 return (str || '').normalize('NFKD');
7594 }
7595 function binaryToByte(bin) {
7596 return parseInt(bin, 2);
7597 }
7598 function bytesToBinary(bytes) {
7599 return bytes.map((x) => x.toString(2).padStart(8, '0')).join('');
7600 }
7601 function deriveChecksumBits(entropyBuffer) {
7602 return bytesToBinary(Array.from(sha256AsU8a(entropyBuffer))).slice(0, (entropyBuffer.length * 8) / 32);
7603 }
7604 function mnemonicToSeedSync(mnemonic, password) {
7605 return pbkdf2Encode(util.stringToU8a(normalize(mnemonic)), util.stringToU8a(`mnemonic${normalize(password)}`)).password;
7606 }
7607 function mnemonicToEntropy$1(mnemonic, wordlist = DEFAULT_WORDLIST) {
7608 const words = normalize(mnemonic).split(' ');
7609 if (words.length % 3 !== 0) {
7610 throw new Error(INVALID_MNEMONIC);
7611 }
7612 const bits = words
7613 .map((word) => {
7614 const index = wordlist.indexOf(word);
7615 if (index === -1) {
7616 throw new Error(INVALID_MNEMONIC);
7617 }
7618 return index.toString(2).padStart(11, '0');
7619 })
7620 .join('');
7621 const dividerIndex = Math.floor(bits.length / 33) * 32;
7622 const entropyBits = bits.slice(0, dividerIndex);
7623 const checksumBits = bits.slice(dividerIndex);
7624 const matched = entropyBits.match(/(.{1,8})/g);
7625 const entropyBytes = matched && matched.map(binaryToByte);
7626 if (!entropyBytes || (entropyBytes.length % 4 !== 0) || (entropyBytes.length < 16) || (entropyBytes.length > 32)) {
7627 throw new Error(INVALID_ENTROPY);
7628 }
7629 const entropy = util.u8aToU8a(entropyBytes);
7630 if (deriveChecksumBits(entropy) !== checksumBits) {
7631 throw new Error(INVALID_CHECKSUM);
7632 }
7633 return entropy;
7634 }
7635 function entropyToMnemonic(entropy, wordlist = DEFAULT_WORDLIST) {
7636 if ((entropy.length % 4 !== 0) || (entropy.length < 16) || (entropy.length > 32)) {
7637 throw new Error(INVALID_ENTROPY);
7638 }
7639 const matched = `${bytesToBinary(Array.from(entropy))}${deriveChecksumBits(entropy)}`.match(/(.{1,11})/g);
7640 const mapped = matched && matched.map((b) => wordlist[binaryToByte(b)]);
7641 if (!mapped || (mapped.length < 12)) {
7642 throw new Error('Unable to map entropy to mnemonic');
7643 }
7644 return mapped.join(' ');
7645 }
7646 function generateMnemonic(numWords, wordlist) {
7647 return entropyToMnemonic(randomAsU8a((numWords / 3) * 4), wordlist);
7648 }
7649 function validateMnemonic(mnemonic, wordlist) {
7650 try {
7651 mnemonicToEntropy$1(mnemonic, wordlist);
7652 }
7653 catch {
7654 return false;
7655 }
7656 return true;
7657 }
7658
7659 function mnemonicGenerate(numWords = 12, wordlist, onlyJs) {
7660 return !util.hasBigInt || (!wordlist && !onlyJs && isReady())
7661 ? bip39Generate(numWords)
7662 : generateMnemonic(numWords, wordlist);
7663 }
7664
7665 function mnemonicToEntropy(mnemonic, wordlist, onlyJs) {
7666 return !util.hasBigInt || (!wordlist && !onlyJs && isReady())
7667 ? bip39ToEntropy(mnemonic)
7668 : mnemonicToEntropy$1(mnemonic, wordlist);
7669 }
7670
7671 function mnemonicValidate(mnemonic, wordlist, onlyJs) {
7672 return !util.hasBigInt || (!wordlist && !onlyJs && isReady())
7673 ? bip39Validate(mnemonic)
7674 : validateMnemonic(mnemonic, wordlist);
7675 }
7676
7677 function mnemonicToLegacySeed(mnemonic, password = '', onlyJs, byteLength = 32) {
7678 if (!mnemonicValidate(mnemonic)) {
7679 throw new Error('Invalid bip39 mnemonic specified');
7680 }
7681 else if (![32, 64].includes(byteLength)) {
7682 throw new Error(`Invalid seed length ${byteLength}, expected 32 or 64`);
7683 }
7684 return byteLength === 32
7685 ? !util.hasBigInt || (!onlyJs && isReady())
7686 ? bip39ToSeed(mnemonic, password)
7687 : mnemonicToSeedSync(mnemonic, password).subarray(0, 32)
7688 : mnemonicToSeedSync(mnemonic, password);
7689 }
7690
7691 function mnemonicToMiniSecret(mnemonic, password = '', wordlist, onlyJs) {
7692 if (!mnemonicValidate(mnemonic, wordlist, onlyJs)) {
7693 throw new Error('Invalid bip39 mnemonic specified');
7694 }
7695 else if (!wordlist && !onlyJs && isReady()) {
7696 return bip39ToMiniSecret(mnemonic, password);
7697 }
7698 const entropy = mnemonicToEntropy(mnemonic, wordlist);
7699 const salt = util.stringToU8a(`mnemonic${password}`);
7700 return pbkdf2Encode(entropy, salt).password.slice(0, 32);
7701 }
7702
7703 function ledgerDerivePrivate(xprv, index) {
7704 const kl = xprv.subarray(0, 32);
7705 const kr = xprv.subarray(32, 64);
7706 const cc = xprv.subarray(64, 96);
7707 const data = util.u8aConcat([0], kl, kr, util.bnToU8a(index, BN_LE_32_OPTS));
7708 const z = hmacShaAsU8a(cc, data, 512);
7709 data[0] = 0x01;
7710 return util.u8aConcat(util.bnToU8a(util.u8aToBn(kl, BN_LE_OPTS).iadd(util.u8aToBn(z.subarray(0, 28), BN_LE_OPTS).imul(util.BN_EIGHT)), BN_LE_512_OPTS).subarray(0, 32), util.bnToU8a(util.u8aToBn(kr, BN_LE_OPTS).iadd(util.u8aToBn(z.subarray(32, 64), BN_LE_OPTS)), BN_LE_512_OPTS).subarray(0, 32), hmacShaAsU8a(cc, data, 512).subarray(32, 64));
7711 }
7712
7713 const ED25519_CRYPTO = 'ed25519 seed';
7714 function ledgerMaster(mnemonic, password) {
7715 const seed = mnemonicToSeedSync(mnemonic, password);
7716 const chainCode = hmacShaAsU8a(ED25519_CRYPTO, new Uint8Array([1, ...seed]), 256);
7717 let priv;
7718 while (!priv || (priv[31] & 32)) {
7719 priv = hmacShaAsU8a(ED25519_CRYPTO, priv || seed, 512);
7720 }
7721 priv[0] &= 248;
7722 priv[31] &= 127;
7723 priv[31] |= 64;
7724 return util.u8aConcat(priv, chainCode);
7725 }
7726
7727 function hdLedger(_mnemonic, path) {
7728 const words = _mnemonic
7729 .split(' ')
7730 .map((s) => s.trim())
7731 .filter((s) => s);
7732 if (![12, 24, 25].includes(words.length)) {
7733 throw new Error('Expected a mnemonic with 24 words (or 25 including a password)');
7734 }
7735 const [mnemonic, password] = words.length === 25
7736 ? [words.slice(0, 24).join(' '), words[24]]
7737 : [words.join(' '), ''];
7738 if (!mnemonicValidate(mnemonic)) {
7739 throw new Error('Invalid mnemonic passed to ledger derivation');
7740 }
7741 else if (!hdValidatePath(path)) {
7742 throw new Error('Invalid derivation path');
7743 }
7744 const parts = path.split('/').slice(1);
7745 let seed = ledgerMaster(mnemonic, password);
7746 for (const p of parts) {
7747 const n = parseInt(p.replace(/'$/, ''), 10);
7748 seed = ledgerDerivePrivate(seed, (n < HARDENED) ? (n + HARDENED) : n);
7749 }
7750 return ed25519PairFromSeed(seed.slice(0, 32));
7751 }
7752
7753 function L32(x, c) { return (x << c) | (x >>> (32 - c)); }
7754 function ld32(x, i) {
7755 let u = x[i + 3] & 0xff;
7756 u = (u << 8) | (x[i + 2] & 0xff);
7757 u = (u << 8) | (x[i + 1] & 0xff);
7758 return (u << 8) | (x[i + 0] & 0xff);
7759 }
7760 function st32(x, j, u) {
7761 for (let i = 0; i < 4; i++) {
7762 x[j + i] = u & 255;
7763 u >>>= 8;
7764 }
7765 }
7766 function vn(x, xi, y, yi, n) {
7767 let d = 0;
7768 for (let i = 0; i < n; i++)
7769 d |= x[xi + i] ^ y[yi + i];
7770 return (1 & ((d - 1) >>> 8)) - 1;
7771 }
7772 function core(out, inp, k, c, h) {
7773 const w = new Uint32Array(16), x = new Uint32Array(16), y = new Uint32Array(16), t = new Uint32Array(4);
7774 let i, j, m;
7775 for (i = 0; i < 4; i++) {
7776 x[5 * i] = ld32(c, 4 * i);
7777 x[1 + i] = ld32(k, 4 * i);
7778 x[6 + i] = ld32(inp, 4 * i);
7779 x[11 + i] = ld32(k, 16 + 4 * i);
7780 }
7781 for (i = 0; i < 16; i++)
7782 y[i] = x[i];
7783 for (i = 0; i < 20; i++) {
7784 for (j = 0; j < 4; j++) {
7785 for (m = 0; m < 4; m++)
7786 t[m] = x[(5 * j + 4 * m) % 16];
7787 t[1] ^= L32((t[0] + t[3]) | 0, 7);
7788 t[2] ^= L32((t[1] + t[0]) | 0, 9);
7789 t[3] ^= L32((t[2] + t[1]) | 0, 13);
7790 t[0] ^= L32((t[3] + t[2]) | 0, 18);
7791 for (m = 0; m < 4; m++)
7792 w[4 * j + (j + m) % 4] = t[m];
7793 }
7794 for (m = 0; m < 16; m++)
7795 x[m] = w[m];
7796 }
7797 if (h) {
7798 for (i = 0; i < 16; i++)
7799 x[i] = (x[i] + y[i]) | 0;
7800 for (i = 0; i < 4; i++) {
7801 x[5 * i] = (x[5 * i] - ld32(c, 4 * i)) | 0;
7802 x[6 + i] = (x[6 + i] - ld32(inp, 4 * i)) | 0;
7803 }
7804 for (i = 0; i < 4; i++) {
7805 st32(out, 4 * i, x[5 * i]);
7806 st32(out, 16 + 4 * i, x[6 + i]);
7807 }
7808 }
7809 else {
7810 for (i = 0; i < 16; i++)
7811 st32(out, 4 * i, (x[i] + y[i]) | 0);
7812 }
7813 }
7814 const sigma = new Uint8Array([101, 120, 112, 97, 110, 100, 32, 51, 50, 45, 98, 121, 116, 101, 32, 107]);
7815 function crypto_stream_salsa20_xor(c, cpos, m, mpos, b, n, k) {
7816 const z = new Uint8Array(16), x = new Uint8Array(64);
7817 let u, i;
7818 if (!b)
7819 return 0;
7820 for (i = 0; i < 16; i++)
7821 z[i] = 0;
7822 for (i = 0; i < 8; i++)
7823 z[i] = n[i];
7824 while (b >= 64) {
7825 core(x, z, k, sigma, false);
7826 for (i = 0; i < 64; i++)
7827 c[cpos + i] = (m ? m[mpos + i] : 0) ^ x[i];
7828 u = 1;
7829 for (i = 8; i < 16; i++) {
7830 u = u + (z[i] & 0xff) | 0;
7831 z[i] = u & 0xff;
7832 u >>>= 8;
7833 }
7834 b -= 64;
7835 cpos += 64;
7836 if (m)
7837 mpos += 64;
7838 }
7839 if (b > 0) {
7840 core(x, z, k, sigma, false);
7841 for (i = 0; i < b; i++)
7842 c[cpos + i] = (m ? m[mpos + i] : 0) ^ x[i];
7843 }
7844 return 0;
7845 }
7846 function crypto_stream_xor(c, cpos, m, mpos, d, n, k) {
7847 const s = new Uint8Array(32);
7848 core(s, n, k, sigma, true);
7849 return crypto_stream_salsa20_xor(c, cpos, m, mpos, d, n.subarray(16), s);
7850 }
7851 function add1305(h, c) {
7852 let u = 0;
7853 for (let j = 0; j < 17; j++) {
7854 u = (u + ((h[j] + c[j]) | 0)) | 0;
7855 h[j] = u & 255;
7856 u >>>= 8;
7857 }
7858 }
7859 const minusp = new Uint32Array([5, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 252]);
7860 function crypto_onetimeauth(out, outpos, m, mpos, n, k) {
7861 let i, j, u;
7862 const x = new Uint32Array(17), r = new Uint32Array(17), h = new Uint32Array(17), c = new Uint32Array(17), g = new Uint32Array(17);
7863 for (j = 0; j < 17; j++)
7864 r[j] = h[j] = 0;
7865 for (j = 0; j < 16; j++)
7866 r[j] = k[j];
7867 r[3] &= 15;
7868 r[4] &= 252;
7869 r[7] &= 15;
7870 r[8] &= 252;
7871 r[11] &= 15;
7872 r[12] &= 252;
7873 r[15] &= 15;
7874 while (n > 0) {
7875 for (j = 0; j < 17; j++)
7876 c[j] = 0;
7877 for (j = 0; (j < 16) && (j < n); ++j)
7878 c[j] = m[mpos + j];
7879 c[j] = 1;
7880 mpos += j;
7881 n -= j;
7882 add1305(h, c);
7883 for (i = 0; i < 17; i++) {
7884 x[i] = 0;
7885 for (j = 0; j < 17; j++)
7886 x[i] = (x[i] + (h[j] * ((j <= i) ? r[i - j] : ((320 * r[i + 17 - j]) | 0))) | 0) | 0;
7887 }
7888 for (i = 0; i < 17; i++)
7889 h[i] = x[i];
7890 u = 0;
7891 for (j = 0; j < 16; j++) {
7892 u = (u + h[j]) | 0;
7893 h[j] = u & 255;
7894 u >>>= 8;
7895 }
7896 u = (u + h[16]) | 0;
7897 h[16] = u & 3;
7898 u = (5 * (u >>> 2)) | 0;
7899 for (j = 0; j < 16; j++) {
7900 u = (u + h[j]) | 0;
7901 h[j] = u & 255;
7902 u >>>= 8;
7903 }
7904 u = (u + h[16]) | 0;
7905 h[16] = u;
7906 }
7907 for (j = 0; j < 17; j++)
7908 g[j] = h[j];
7909 add1305(h, minusp);
7910 const s = (-(h[16] >>> 7) | 0);
7911 for (j = 0; j < 17; j++)
7912 h[j] ^= s & (g[j] ^ h[j]);
7913 for (j = 0; j < 16; j++)
7914 c[j] = k[j + 16];
7915 c[16] = 0;
7916 add1305(h, c);
7917 for (j = 0; j < 16; j++)
7918 out[outpos + j] = h[j];
7919 return 0;
7920 }
7921 function crypto_onetimeauth_verify(h, hpos, m, mpos, n, k) {
7922 const x = new Uint8Array(16);
7923 crypto_onetimeauth(x, 0, m, mpos, n, k);
7924 return vn(h, hpos, x, 0, 16);
7925 }
7926 function crypto_secretbox(c, m, d, n, k) {
7927 if (d < 32)
7928 return -1;
7929 crypto_stream_xor(c, 0, m, 0, d, n, k);
7930 crypto_onetimeauth(c, 16, c, 32, d - 32, c);
7931 for (let i = 0; i < 16; i++)
7932 c[i] = 0;
7933 return 0;
7934 }
7935 function crypto_secretbox_open(m, c, d, n, k) {
7936 const x = new Uint8Array(32);
7937 if (d < 32)
7938 return -1;
7939 crypto_stream_xor(x, 0, null, 0, 32, n, k);
7940 if (crypto_onetimeauth_verify(c, 16, c, 32, d - 32, x) !== 0)
7941 return -1;
7942 crypto_stream_xor(m, 0, c, 0, d, n, k);
7943 for (let i = 0; i < 32; i++)
7944 m[i] = 0;
7945 return 0;
7946 }
7947 const crypto_secretbox_KEYBYTES = 32;
7948 const crypto_secretbox_NONCEBYTES = 24;
7949 const crypto_secretbox_ZEROBYTES = 32;
7950 const crypto_secretbox_BOXZEROBYTES = 16;
7951 function checkLengths(k, n) {
7952 if (k.length !== crypto_secretbox_KEYBYTES)
7953 throw new Error('bad key size');
7954 if (n.length !== crypto_secretbox_NONCEBYTES)
7955 throw new Error('bad nonce size');
7956 }
7957 function checkArrayTypes(...args) {
7958 for (let i = 0; i < args.length; i++) {
7959 if (!(args[i] instanceof Uint8Array))
7960 throw new TypeError('unexpected type, use Uint8Array');
7961 }
7962 }
7963 function naclSecretbox(msg, nonce, key) {
7964 checkArrayTypes(msg, nonce, key);
7965 checkLengths(key, nonce);
7966 const m = new Uint8Array(crypto_secretbox_ZEROBYTES + msg.length);
7967 const c = new Uint8Array(m.length);
7968 for (let i = 0; i < msg.length; i++)
7969 m[i + crypto_secretbox_ZEROBYTES] = msg[i];
7970 crypto_secretbox(c, m, m.length, nonce, key);
7971 return c.subarray(crypto_secretbox_BOXZEROBYTES);
7972 }
7973 function naclSecretboxOpen(box, nonce, key) {
7974 checkArrayTypes(box, nonce, key);
7975 checkLengths(key, nonce);
7976 const c = new Uint8Array(crypto_secretbox_BOXZEROBYTES + box.length);
7977 const m = new Uint8Array(c.length);
7978 for (let i = 0; i < box.length; i++)
7979 c[i + crypto_secretbox_BOXZEROBYTES] = box[i];
7980 if (c.length < 32)
7981 return null;
7982 if (crypto_secretbox_open(m, c, c.length, nonce, key) !== 0)
7983 return null;
7984 return m.subarray(crypto_secretbox_ZEROBYTES);
7985 }
7986
7987 function naclDecrypt(encrypted, nonce, secret) {
7988 return naclSecretboxOpen(encrypted, nonce, secret);
7989 }
7990
7991 function naclEncrypt(message, secret, nonce = randomAsU8a(24)) {
7992 return {
7993 encrypted: naclSecretbox(message, nonce, secret),
7994 nonce
7995 };
7996 }
7997
7998 const rotl$1 = (a, b) => (a << b) | (a >>> (32 - b));
7999 function XorAndSalsa(prev, pi, input, ii, out, oi) {
8000 let y00 = prev[pi++] ^ input[ii++], y01 = prev[pi++] ^ input[ii++];
8001 let y02 = prev[pi++] ^ input[ii++], y03 = prev[pi++] ^ input[ii++];
8002 let y04 = prev[pi++] ^ input[ii++], y05 = prev[pi++] ^ input[ii++];
8003 let y06 = prev[pi++] ^ input[ii++], y07 = prev[pi++] ^ input[ii++];
8004 let y08 = prev[pi++] ^ input[ii++], y09 = prev[pi++] ^ input[ii++];
8005 let y10 = prev[pi++] ^ input[ii++], y11 = prev[pi++] ^ input[ii++];
8006 let y12 = prev[pi++] ^ input[ii++], y13 = prev[pi++] ^ input[ii++];
8007 let y14 = prev[pi++] ^ input[ii++], y15 = prev[pi++] ^ input[ii++];
8008 let x00 = y00, x01 = y01, x02 = y02, x03 = y03, x04 = y04, x05 = y05, x06 = y06, x07 = y07, x08 = y08, x09 = y09, x10 = y10, x11 = y11, x12 = y12, x13 = y13, x14 = y14, x15 = y15;
8009 for (let i = 0; i < 8; i += 2) {
8010 x04 ^= rotl$1(x00 + x12 | 0, 7);
8011 x08 ^= rotl$1(x04 + x00 | 0, 9);
8012 x12 ^= rotl$1(x08 + x04 | 0, 13);
8013 x00 ^= rotl$1(x12 + x08 | 0, 18);
8014 x09 ^= rotl$1(x05 + x01 | 0, 7);
8015 x13 ^= rotl$1(x09 + x05 | 0, 9);
8016 x01 ^= rotl$1(x13 + x09 | 0, 13);
8017 x05 ^= rotl$1(x01 + x13 | 0, 18);
8018 x14 ^= rotl$1(x10 + x06 | 0, 7);
8019 x02 ^= rotl$1(x14 + x10 | 0, 9);
8020 x06 ^= rotl$1(x02 + x14 | 0, 13);
8021 x10 ^= rotl$1(x06 + x02 | 0, 18);
8022 x03 ^= rotl$1(x15 + x11 | 0, 7);
8023 x07 ^= rotl$1(x03 + x15 | 0, 9);
8024 x11 ^= rotl$1(x07 + x03 | 0, 13);
8025 x15 ^= rotl$1(x11 + x07 | 0, 18);
8026 x01 ^= rotl$1(x00 + x03 | 0, 7);
8027 x02 ^= rotl$1(x01 + x00 | 0, 9);
8028 x03 ^= rotl$1(x02 + x01 | 0, 13);
8029 x00 ^= rotl$1(x03 + x02 | 0, 18);
8030 x06 ^= rotl$1(x05 + x04 | 0, 7);
8031 x07 ^= rotl$1(x06 + x05 | 0, 9);
8032 x04 ^= rotl$1(x07 + x06 | 0, 13);
8033 x05 ^= rotl$1(x04 + x07 | 0, 18);
8034 x11 ^= rotl$1(x10 + x09 | 0, 7);
8035 x08 ^= rotl$1(x11 + x10 | 0, 9);
8036 x09 ^= rotl$1(x08 + x11 | 0, 13);
8037 x10 ^= rotl$1(x09 + x08 | 0, 18);
8038 x12 ^= rotl$1(x15 + x14 | 0, 7);
8039 x13 ^= rotl$1(x12 + x15 | 0, 9);
8040 x14 ^= rotl$1(x13 + x12 | 0, 13);
8041 x15 ^= rotl$1(x14 + x13 | 0, 18);
8042 }
8043 out[oi++] = (y00 + x00) | 0;
8044 out[oi++] = (y01 + x01) | 0;
8045 out[oi++] = (y02 + x02) | 0;
8046 out[oi++] = (y03 + x03) | 0;
8047 out[oi++] = (y04 + x04) | 0;
8048 out[oi++] = (y05 + x05) | 0;
8049 out[oi++] = (y06 + x06) | 0;
8050 out[oi++] = (y07 + x07) | 0;
8051 out[oi++] = (y08 + x08) | 0;
8052 out[oi++] = (y09 + x09) | 0;
8053 out[oi++] = (y10 + x10) | 0;
8054 out[oi++] = (y11 + x11) | 0;
8055 out[oi++] = (y12 + x12) | 0;
8056 out[oi++] = (y13 + x13) | 0;
8057 out[oi++] = (y14 + x14) | 0;
8058 out[oi++] = (y15 + x15) | 0;
8059 }
8060 function BlockMix(input, ii, out, oi, r) {
8061 let head = oi + 0;
8062 let tail = oi + 16 * r;
8063 for (let i = 0; i < 16; i++)
8064 out[tail + i] = input[ii + (2 * r - 1) * 16 + i];
8065 for (let i = 0; i < r; i++, head += 16, ii += 16) {
8066 XorAndSalsa(out, tail, input, ii, out, head);
8067 if (i > 0)
8068 tail += 16;
8069 XorAndSalsa(out, head, input, (ii += 16), out, tail);
8070 }
8071 }
8072 function scryptInit(password, salt, _opts) {
8073 const opts = checkOpts({
8074 dkLen: 32,
8075 asyncTick: 10,
8076 maxmem: 1024 ** 3 + 1024,
8077 }, _opts);
8078 const { N, r, p, dkLen, asyncTick, maxmem, onProgress } = opts;
8079 assert.number(N);
8080 assert.number(r);
8081 assert.number(p);
8082 assert.number(dkLen);
8083 assert.number(asyncTick);
8084 assert.number(maxmem);
8085 if (onProgress !== undefined && typeof onProgress !== 'function')
8086 throw new Error('progressCb should be function');
8087 const blockSize = 128 * r;
8088 const blockSize32 = blockSize / 4;
8089 if (N <= 1 || (N & (N - 1)) !== 0 || N >= 2 ** (blockSize / 8) || N > 2 ** 32) {
8090 throw new Error('Scrypt: N must be larger than 1, a power of 2, less than 2^(128 * r / 8) and less than 2^32');
8091 }
8092 if (p < 0 || p > ((2 ** 32 - 1) * 32) / blockSize) {
8093 throw new Error('Scrypt: p must be a positive integer less than or equal to ((2^32 - 1) * 32) / (128 * r)');
8094 }
8095 if (dkLen < 0 || dkLen > (2 ** 32 - 1) * 32) {
8096 throw new Error('Scrypt: dkLen should be positive integer less than or equal to (2^32 - 1) * 32');
8097 }
8098 const memUsed = blockSize * (N + p);
8099 if (memUsed > maxmem) {
8100 throw new Error(`Scrypt: parameters too large, ${memUsed} (128 * r * (N + p)) > ${maxmem} (maxmem)`);
8101 }
8102 const B = pbkdf2(sha256, password, salt, { c: 1, dkLen: blockSize * p });
8103 const B32 = u32(B);
8104 const V = u32(new Uint8Array(blockSize * N));
8105 const tmp = u32(new Uint8Array(blockSize));
8106 let blockMixCb = () => { };
8107 if (onProgress) {
8108 const totalBlockMix = 2 * N * p;
8109 const callbackPer = Math.max(Math.floor(totalBlockMix / 10000), 1);
8110 let blockMixCnt = 0;
8111 blockMixCb = () => {
8112 blockMixCnt++;
8113 if (onProgress && (!(blockMixCnt % callbackPer) || blockMixCnt === totalBlockMix))
8114 onProgress(blockMixCnt / totalBlockMix);
8115 };
8116 }
8117 return { N, r, p, dkLen, blockSize32, V, B32, B, tmp, blockMixCb, asyncTick };
8118 }
8119 function scryptOutput(password, dkLen, B, V, tmp) {
8120 const res = pbkdf2(sha256, password, B, { c: 1, dkLen });
8121 B.fill(0);
8122 V.fill(0);
8123 tmp.fill(0);
8124 return res;
8125 }
8126 function scrypt(password, salt, opts) {
8127 const { N, r, p, dkLen, blockSize32, V, B32, B, tmp, blockMixCb } = scryptInit(password, salt, opts);
8128 for (let pi = 0; pi < p; pi++) {
8129 const Pi = blockSize32 * pi;
8130 for (let i = 0; i < blockSize32; i++)
8131 V[i] = B32[Pi + i];
8132 for (let i = 0, pos = 0; i < N - 1; i++) {
8133 BlockMix(V, pos, V, (pos += blockSize32), r);
8134 blockMixCb();
8135 }
8136 BlockMix(V, (N - 1) * blockSize32, B32, Pi, r);
8137 blockMixCb();
8138 for (let i = 0; i < N; i++) {
8139 const j = B32[Pi + blockSize32 - 16] % N;
8140 for (let k = 0; k < blockSize32; k++)
8141 tmp[k] = B32[Pi + k] ^ V[j * blockSize32 + k];
8142 BlockMix(tmp, 0, B32, Pi, r);
8143 blockMixCb();
8144 }
8145 }
8146 return scryptOutput(password, dkLen, B, V, tmp);
8147 }
8148
8149 const DEFAULT_PARAMS = {
8150 N: 1 << 15,
8151 p: 1,
8152 r: 8
8153 };
8154
8155 function scryptEncode(passphrase, salt = randomAsU8a(), params = DEFAULT_PARAMS, onlyJs) {
8156 const u8a = util.u8aToU8a(passphrase);
8157 return {
8158 params,
8159 password: !util.hasBigInt || (!onlyJs && isReady())
8160 ? scrypt$1(u8a, salt, Math.log2(params.N), params.r, params.p)
8161 : scrypt(u8a, salt, util.objectSpread({ dkLen: 64 }, params)),
8162 salt
8163 };
8164 }
8165
8166 function scryptFromU8a(data) {
8167 const salt = data.subarray(0, 32);
8168 const N = util.u8aToBn(data.subarray(32 + 0, 32 + 4), BN_LE_OPTS).toNumber();
8169 const p = util.u8aToBn(data.subarray(32 + 4, 32 + 8), BN_LE_OPTS).toNumber();
8170 const r = util.u8aToBn(data.subarray(32 + 8, 32 + 12), BN_LE_OPTS).toNumber();
8171 if (N !== DEFAULT_PARAMS.N || p !== DEFAULT_PARAMS.p || r !== DEFAULT_PARAMS.r) {
8172 throw new Error('Invalid injected scrypt params found');
8173 }
8174 return { params: { N, p, r }, salt };
8175 }
8176
8177 function scryptToU8a(salt, { N, p, r }) {
8178 return util.u8aConcat(salt, util.bnToU8a(N, BN_LE_32_OPTS), util.bnToU8a(p, BN_LE_32_OPTS), util.bnToU8a(r, BN_LE_32_OPTS));
8179 }
8180
8181 const ENCODING = ['scrypt', 'xsalsa20-poly1305'];
8182 const ENCODING_NONE = ['none'];
8183 const ENCODING_VERSION = '3';
8184 const NONCE_LENGTH = 24;
8185 const SCRYPT_LENGTH = 32 + (3 * 4);
8186
8187 function jsonDecryptData(encrypted, passphrase, encType = ENCODING) {
8188 if (!encrypted) {
8189 throw new Error('No encrypted data available to decode');
8190 }
8191 else if (encType.includes('xsalsa20-poly1305') && !passphrase) {
8192 throw new Error('Password required to decode encrypted data');
8193 }
8194 let encoded = encrypted;
8195 if (passphrase) {
8196 let password;
8197 if (encType.includes('scrypt')) {
8198 const { params, salt } = scryptFromU8a(encrypted);
8199 password = scryptEncode(passphrase, salt, params).password;
8200 encrypted = encrypted.subarray(SCRYPT_LENGTH);
8201 }
8202 else {
8203 password = util.stringToU8a(passphrase);
8204 }
8205 encoded = naclDecrypt(encrypted.subarray(NONCE_LENGTH), encrypted.subarray(0, NONCE_LENGTH), util.u8aFixLength(password, 256, true));
8206 }
8207 if (!encoded) {
8208 throw new Error('Unable to decode using the supplied passphrase');
8209 }
8210 return encoded;
8211 }
8212
8213 function jsonDecrypt({ encoded, encoding }, passphrase) {
8214 if (!encoded) {
8215 throw new Error('No encrypted data available to decode');
8216 }
8217 return jsonDecryptData(util.isHex(encoded)
8218 ? util.hexToU8a(encoded)
8219 : base64Decode(encoded), passphrase, Array.isArray(encoding.type)
8220 ? encoding.type
8221 : [encoding.type]);
8222 }
8223
8224 function jsonEncryptFormat(encoded, contentType, isEncrypted) {
8225 return {
8226 encoded: base64Encode(encoded),
8227 encoding: {
8228 content: contentType,
8229 type: isEncrypted
8230 ? ENCODING
8231 : ENCODING_NONE,
8232 version: ENCODING_VERSION
8233 }
8234 };
8235 }
8236
8237 function jsonEncrypt(data, contentType, passphrase) {
8238 let isEncrypted = false;
8239 let encoded = data;
8240 if (passphrase) {
8241 const { params, password, salt } = scryptEncode(passphrase);
8242 const { encrypted, nonce } = naclEncrypt(encoded, password.subarray(0, 32));
8243 isEncrypted = true;
8244 encoded = util.u8aConcat(scryptToU8a(salt, params), nonce, encrypted);
8245 }
8246 return jsonEncryptFormat(encoded, contentType, isEncrypted);
8247 }
8248
8249 const secp256k1VerifyHasher = (hashType) => (message, signature, publicKey) => secp256k1Verify(message, signature, publicKey, hashType);
8250 const VERIFIERS_ECDSA = [
8251 ['ecdsa', secp256k1VerifyHasher('blake2')],
8252 ['ethereum', secp256k1VerifyHasher('keccak')]
8253 ];
8254 const VERIFIERS = [
8255 ['ed25519', ed25519Verify],
8256 ['sr25519', sr25519Verify],
8257 ...VERIFIERS_ECDSA
8258 ];
8259 const CRYPTO_TYPES = ['ed25519', 'sr25519', 'ecdsa'];
8260 function verifyDetect(result, { message, publicKey, signature }, verifiers = VERIFIERS) {
8261 result.isValid = verifiers.some(([crypto, verify]) => {
8262 try {
8263 if (verify(message, signature, publicKey)) {
8264 result.crypto = crypto;
8265 return true;
8266 }
8267 }
8268 catch {
8269 }
8270 return false;
8271 });
8272 return result;
8273 }
8274 function verifyMultisig(result, { message, publicKey, signature }) {
8275 if (![0, 1, 2].includes(signature[0])) {
8276 throw new Error(`Unknown crypto type, expected signature prefix [0..2], found ${signature[0]}`);
8277 }
8278 const type = CRYPTO_TYPES[signature[0]] || 'none';
8279 result.crypto = type;
8280 try {
8281 result.isValid = {
8282 ecdsa: () => verifyDetect(result, { message, publicKey, signature: signature.subarray(1) }, VERIFIERS_ECDSA).isValid,
8283 ed25519: () => ed25519Verify(message, signature.subarray(1), publicKey),
8284 none: () => {
8285 throw Error('no verify for `none` crypto type');
8286 },
8287 sr25519: () => sr25519Verify(message, signature.subarray(1), publicKey)
8288 }[type]();
8289 }
8290 catch {
8291 }
8292 return result;
8293 }
8294 function getVerifyFn(signature) {
8295 return [0, 1, 2].includes(signature[0]) && [65, 66].includes(signature.length)
8296 ? verifyMultisig
8297 : verifyDetect;
8298 }
8299 function signatureVerify(message, signature, addressOrPublicKey) {
8300 const signatureU8a = util.u8aToU8a(signature);
8301 if (![64, 65, 66].includes(signatureU8a.length)) {
8302 throw new Error(`Invalid signature length, expected [64..66] bytes, found ${signatureU8a.length}`);
8303 }
8304 const publicKey = decodeAddress(addressOrPublicKey);
8305 const input = { message: util.u8aToU8a(message), publicKey, signature: signatureU8a };
8306 const result = { crypto: 'none', isValid: false, isWrapped: util.u8aIsWrapped(input.message, true), publicKey };
8307 const isWrappedBytes = util.u8aIsWrapped(input.message, false);
8308 const verifyFn = getVerifyFn(signatureU8a);
8309 verifyFn(result, input);
8310 if (result.crypto !== 'none' || (result.isWrapped && !isWrappedBytes)) {
8311 return result;
8312 }
8313 input.message = isWrappedBytes
8314 ? util.u8aUnwrapBytes(input.message)
8315 : util.u8aWrapBytes(input.message);
8316 return verifyFn(result, input);
8317 }
8318
8319 const P64_1 = BigInt$1('11400714785074694791');
8320 const P64_2 = BigInt$1('14029467366897019727');
8321 const P64_3 = BigInt$1('1609587929392839161');
8322 const P64_4 = BigInt$1('9650029242287828579');
8323 const P64_5 = BigInt$1('2870177450012600261');
8324 const U64 = BigInt$1('0xffffffffffffffff');
8325 const _7n = BigInt$1(7);
8326 const _11n = BigInt$1(11);
8327 const _12n = BigInt$1(12);
8328 const _16n = BigInt$1(16);
8329 const _18n = BigInt$1(18);
8330 const _23n = BigInt$1(23);
8331 const _27n = BigInt$1(27);
8332 const _29n = BigInt$1(29);
8333 const _31n = BigInt$1(31);
8334 const _32n = BigInt$1(32);
8335 const _33n = BigInt$1(33);
8336 const _64n = BigInt$1(64);
8337 const _256n = BigInt$1(256);
8338 function rotl(a, b) {
8339 const c = a & U64;
8340 return ((c << b) | (c >> (_64n - b))) & U64;
8341 }
8342 function fromU8a(u8a, p, count) {
8343 const bigints = new Array(count);
8344 let offset = 0;
8345 for (let i = 0; i < count; i++, offset += 2) {
8346 bigints[i] = BigInt$1(u8a[p + offset] | (u8a[p + 1 + offset] << 8));
8347 }
8348 let result = util._0n;
8349 for (let i = count - 1; i >= 0; i--) {
8350 result = (result << _16n) + bigints[i];
8351 }
8352 return result;
8353 }
8354 function init(seed, input) {
8355 const state = {
8356 seed,
8357 u8a: new Uint8Array(32),
8358 u8asize: 0,
8359 v1: seed + P64_1 + P64_2,
8360 v2: seed + P64_2,
8361 v3: seed,
8362 v4: seed - P64_1
8363 };
8364 if (input.length < 32) {
8365 state.u8a.set(input);
8366 state.u8asize = input.length;
8367 return state;
8368 }
8369 const limit = input.length - 32;
8370 let p = 0;
8371 if (limit >= 0) {
8372 const adjustV = (v) => P64_1 * rotl(v + P64_2 * fromU8a(input, p, 4), _31n);
8373 do {
8374 state.v1 = adjustV(state.v1);
8375 p += 8;
8376 state.v2 = adjustV(state.v2);
8377 p += 8;
8378 state.v3 = adjustV(state.v3);
8379 p += 8;
8380 state.v4 = adjustV(state.v4);
8381 p += 8;
8382 } while (p <= limit);
8383 }
8384 if (p < input.length) {
8385 state.u8a.set(input.subarray(p, input.length));
8386 state.u8asize = input.length - p;
8387 }
8388 return state;
8389 }
8390 function xxhash64(input, initSeed) {
8391 const { seed, u8a, u8asize, v1, v2, v3, v4 } = init(BigInt$1(initSeed), input);
8392 let p = 0;
8393 let h64 = U64 & (BigInt$1(input.length) + (input.length >= 32
8394 ? (((((((((rotl(v1, util._1n) + rotl(v2, _7n) + rotl(v3, _12n) + rotl(v4, _18n)) ^ (P64_1 * rotl(v1 * P64_2, _31n))) * P64_1 + P64_4) ^ (P64_1 * rotl(v2 * P64_2, _31n))) * P64_1 + P64_4) ^ (P64_1 * rotl(v3 * P64_2, _31n))) * P64_1 + P64_4) ^ (P64_1 * rotl(v4 * P64_2, _31n))) * P64_1 + P64_4)
8395 : (seed + P64_5)));
8396 while (p <= (u8asize - 8)) {
8397 h64 = U64 & (P64_4 + P64_1 * rotl(h64 ^ (P64_1 * rotl(P64_2 * fromU8a(u8a, p, 4), _31n)), _27n));
8398 p += 8;
8399 }
8400 if ((p + 4) <= u8asize) {
8401 h64 = U64 & (P64_3 + P64_2 * rotl(h64 ^ (P64_1 * fromU8a(u8a, p, 2)), _23n));
8402 p += 4;
8403 }
8404 while (p < u8asize) {
8405 h64 = U64 & (P64_1 * rotl(h64 ^ (P64_5 * BigInt$1(u8a[p++])), _11n));
8406 }
8407 h64 = U64 & (P64_2 * (h64 ^ (h64 >> _33n)));
8408 h64 = U64 & (P64_3 * (h64 ^ (h64 >> _29n)));
8409 h64 = U64 & (h64 ^ (h64 >> _32n));
8410 const result = new Uint8Array(8);
8411 for (let i = 7; i >= 0; i--) {
8412 result[i] = Number(h64 % _256n);
8413 h64 = h64 / _256n;
8414 }
8415 return result;
8416 }
8417
8418 function xxhashAsU8a(data, bitLength = 64, onlyJs) {
8419 const rounds = Math.ceil(bitLength / 64);
8420 const u8a = util.u8aToU8a(data);
8421 if (!util.hasBigInt || (!onlyJs && isReady())) {
8422 return twox(u8a, rounds);
8423 }
8424 const result = new Uint8Array(rounds * 8);
8425 for (let seed = 0; seed < rounds; seed++) {
8426 result.set(xxhash64(u8a, seed).reverse(), seed * 8);
8427 }
8428 return result;
8429 }
8430 const xxhashAsHex = createAsHex(xxhashAsU8a);
8431
8432 exports.addressEq = addressEq;
8433 exports.addressToEvm = addressToEvm;
8434 exports.allNetworks = allNetworks;
8435 exports.availableNetworks = availableNetworks;
8436 exports.base32Decode = base32Decode;
8437 exports.base32Encode = base32Encode;
8438 exports.base32Validate = base32Validate;
8439 exports.base58Decode = base58Decode;
8440 exports.base58Encode = base58Encode;
8441 exports.base58Validate = base58Validate;
8442 exports.base64Decode = base64Decode;
8443 exports.base64Encode = base64Encode;
8444 exports.base64Pad = base64Pad;
8445 exports.base64Trim = base64Trim;
8446 exports.base64Validate = base64Validate;
8447 exports.blake2AsHex = blake2AsHex;
8448 exports.blake2AsU8a = blake2AsU8a;
8449 exports.checkAddress = checkAddress;
8450 exports.checkAddressChecksum = checkAddressChecksum;
8451 exports.createKeyDerived = createKeyDerived;
8452 exports.createKeyMulti = createKeyMulti;
8453 exports.cryptoIsReady = cryptoIsReady;
8454 exports.cryptoWaitReady = cryptoWaitReady;
8455 exports.decodeAddress = decodeAddress;
8456 exports.deriveAddress = deriveAddress;
8457 exports.ed25519DeriveHard = ed25519DeriveHard;
8458 exports.ed25519PairFromRandom = ed25519PairFromRandom;
8459 exports.ed25519PairFromSecret = ed25519PairFromSecret;
8460 exports.ed25519PairFromSeed = ed25519PairFromSeed;
8461 exports.ed25519PairFromString = ed25519PairFromString;
8462 exports.ed25519Sign = ed25519Sign;
8463 exports.ed25519Verify = ed25519Verify;
8464 exports.encodeAddress = encodeAddress;
8465 exports.encodeDerivedAddress = encodeDerivedAddress;
8466 exports.encodeMultiAddress = encodeMultiAddress;
8467 exports.ethereumEncode = ethereumEncode;
8468 exports.evmToAddress = evmToAddress;
8469 exports.hdEthereum = hdEthereum;
8470 exports.hdLedger = hdLedger;
8471 exports.hdValidatePath = hdValidatePath;
8472 exports.hmacSha256AsU8a = hmacSha256AsU8a;
8473 exports.hmacSha512AsU8a = hmacSha512AsU8a;
8474 exports.hmacShaAsU8a = hmacShaAsU8a;
8475 exports.isAddress = isAddress;
8476 exports.isBase32 = isBase32;
8477 exports.isBase58 = isBase58;
8478 exports.isBase64 = isBase64;
8479 exports.isEthereumAddress = isEthereumAddress;
8480 exports.isEthereumChecksum = isEthereumChecksum;
8481 exports.jsonDecrypt = jsonDecrypt;
8482 exports.jsonDecryptData = jsonDecryptData;
8483 exports.jsonEncrypt = jsonEncrypt;
8484 exports.jsonEncryptFormat = jsonEncryptFormat;
8485 exports.keccak256AsU8a = keccak256AsU8a;
8486 exports.keccak512AsU8a = keccak512AsU8a;
8487 exports.keccakAsHex = keccakAsHex;
8488 exports.keccakAsU8a = keccakAsU8a;
8489 exports.keyExtractPath = keyExtractPath;
8490 exports.keyExtractSuri = keyExtractSuri;
8491 exports.keyFromPath = keyFromPath;
8492 exports.keyHdkdEcdsa = keyHdkdEcdsa;
8493 exports.keyHdkdEd25519 = keyHdkdEd25519;
8494 exports.keyHdkdSr25519 = keyHdkdSr25519;
8495 exports.mnemonicGenerate = mnemonicGenerate;
8496 exports.mnemonicToEntropy = mnemonicToEntropy;
8497 exports.mnemonicToLegacySeed = mnemonicToLegacySeed;
8498 exports.mnemonicToMiniSecret = mnemonicToMiniSecret;
8499 exports.mnemonicValidate = mnemonicValidate;
8500 exports.naclDecrypt = naclDecrypt;
8501 exports.naclEncrypt = naclEncrypt;
8502 exports.packageInfo = packageInfo;
8503 exports.pbkdf2Encode = pbkdf2Encode;
8504 exports.randomAsHex = randomAsHex;
8505 exports.randomAsNumber = randomAsNumber;
8506 exports.randomAsU8a = randomAsU8a;
8507 exports.scryptEncode = scryptEncode;
8508 exports.scryptFromU8a = scryptFromU8a;
8509 exports.scryptToU8a = scryptToU8a;
8510 exports.secp256k1Compress = secp256k1Compress;
8511 exports.secp256k1Expand = secp256k1Expand;
8512 exports.secp256k1PairFromSeed = secp256k1PairFromSeed;
8513 exports.secp256k1PrivateKeyTweakAdd = secp256k1PrivateKeyTweakAdd;
8514 exports.secp256k1Recover = secp256k1Recover;
8515 exports.secp256k1Sign = secp256k1Sign;
8516 exports.secp256k1Verify = secp256k1Verify;
8517 exports.selectableNetworks = selectableNetworks;
8518 exports.setSS58Format = setSS58Format;
8519 exports.sha256AsU8a = sha256AsU8a;
8520 exports.sha512AsU8a = sha512AsU8a;
8521 exports.shaAsU8a = shaAsU8a;
8522 exports.signatureVerify = signatureVerify;
8523 exports.sortAddresses = sortAddresses;
8524 exports.sr25519Agreement = sr25519Agreement;
8525 exports.sr25519DeriveHard = sr25519DeriveHard;
8526 exports.sr25519DerivePublic = sr25519DerivePublic;
8527 exports.sr25519DeriveSoft = sr25519DeriveSoft;
8528 exports.sr25519PairFromSeed = sr25519PairFromSeed;
8529 exports.sr25519Sign = sr25519Sign;
8530 exports.sr25519Verify = sr25519Verify;
8531 exports.sr25519VrfSign = sr25519VrfSign;
8532 exports.sr25519VrfVerify = sr25519VrfVerify;
8533 exports.validateAddress = validateAddress;
8534 exports.xxhashAsHex = xxhashAsHex;
8535 exports.xxhashAsU8a = xxhashAsU8a;
8536
8537}));
8538
\No newline at end of file