/* esm.sh - @noble/curves@1.5.0/ed25519 */ function tn(t){return t instanceof Uint8Array||t!=null&&typeof t=="object"&&t.constructor.name==="Uint8Array"}function St(t,...e){if(!tn(t))throw new Error("Uint8Array expected");if(e.length>0&&!e.includes(t.length))throw new Error(`Uint8Array expected of length ${e}, not of length=${t.length}`)}function Mt(t,e=!0){if(t.destroyed)throw new Error("Hash instance has been destroyed");if(e&&t.finished)throw new Error("Hash#digest() has already been called")}function be(t,e){St(t);let n=e.outputLen;if(t.lengthnew DataView(t.buffer,t.byteOffset,t.byteLength);var po=new Uint8Array(new Uint32Array([287454020]).buffer)[0]===68;function vt(t){if(typeof t!="string")throw new Error(`utf8ToBytes expected string, got ${typeof t}`);return new Uint8Array(new TextEncoder().encode(t))}function $t(t){return typeof t=="string"&&(t=vt(t)),St(t),t}function ge(...t){let e=0;for(let o=0;ot().update($t(o)).digest(),n=t();return e.outputLen=n.outputLen,e.blockLen=n.blockLen,e.create=()=>t(),e}function Vt(t=32){if(At&&typeof At.getRandomValues=="function")return At.getRandomValues(new Uint8Array(t));throw new Error("crypto.getRandomValues must be defined")}function en(t,e,n,o){if(typeof t.setBigUint64=="function")return t.setBigUint64(e,n,o);let s=BigInt(32),r=BigInt(4294967295),i=Number(n>>s&r),f=Number(n&r),c=o?4:0,u=o?0:4;t.setUint32(e+c,i,o),t.setUint32(e+u,f,o)}var Tt=class extends It{constructor(e,n,o,s){super(),this.blockLen=e,this.outputLen=n,this.padOffset=o,this.isLE=s,this.finished=!1,this.length=0,this.pos=0,this.destroyed=!1,this.buffer=new Uint8Array(e),this.view=Lt(this.buffer)}update(e){Mt(this);let{view:n,buffer:o,blockLen:s}=this;e=$t(e);let r=e.length;for(let i=0;is-i&&(this.process(o,0),i=0);for(let d=i;da.length)throw new Error("_sha2: outputLen bigger than state");for(let d=0;d>Zt&Ct)}:{h:Number(t>>Zt&Ct)|0,l:Number(t&Ct)|0}}function nn(t,e=!1){let n=new Uint32Array(t.length),o=new Uint32Array(t.length);for(let s=0;sBigInt(t>>>0)<>>0),rn=(t,e,n)=>t>>>n,sn=(t,e,n)=>t<<32-n|e>>>n,cn=(t,e,n)=>t>>>n|e<<32-n,fn=(t,e,n)=>t<<32-n|e>>>n,an=(t,e,n)=>t<<64-n|e>>>n-32,un=(t,e,n)=>t>>>n-32|e<<64-n,ln=(t,e)=>e,dn=(t,e)=>t,hn=(t,e,n)=>t<>>32-n,pn=(t,e,n)=>e<>>32-n,xn=(t,e,n)=>e<>>64-n,bn=(t,e,n)=>t<>>64-n;function gn(t,e,n,o){let s=(e>>>0)+(o>>>0);return{h:t+n+(s/2**32|0)|0,l:s|0}}var wn=(t,e,n)=>(t>>>0)+(e>>>0)+(n>>>0),yn=(t,e,n,o)=>e+n+o+(t/2**32|0)|0,mn=(t,e,n,o)=>(t>>>0)+(e>>>0)+(n>>>0)+(o>>>0),Bn=(t,e,n,o,s)=>e+n+o+s+(t/2**32|0)|0,En=(t,e,n,o,s)=>(t>>>0)+(e>>>0)+(n>>>0)+(o>>>0)+(s>>>0),_n=(t,e,n,o,s,r)=>e+n+o+s+r+(t/2**32|0)|0;var Sn={fromBig:ye,split:nn,toBig:on,shrSH:rn,shrSL:sn,rotrSH:cn,rotrSL:fn,rotrBH:an,rotrBL:un,rotr32H:ln,rotr32L:dn,rotlSH:hn,rotlSL:pn,rotlBH:xn,rotlBL:bn,add:gn,add3L:wn,add3H:yn,add4L:mn,add4H:Bn,add5H:_n,add5L:En},_=Sn;var[An,In]=_.split(["0x428a2f98d728ae22","0x7137449123ef65cd","0xb5c0fbcfec4d3b2f","0xe9b5dba58189dbbc","0x3956c25bf348b538","0x59f111f1b605d019","0x923f82a4af194f9b","0xab1c5ed5da6d8118","0xd807aa98a3030242","0x12835b0145706fbe","0x243185be4ee4b28c","0x550c7dc3d5ffb4e2","0x72be5d74f27b896f","0x80deb1fe3b1696b1","0x9bdc06a725c71235","0xc19bf174cf692694","0xe49b69c19ef14ad2","0xefbe4786384f25e3","0x0fc19dc68b8cd5b5","0x240ca1cc77ac9c65","0x2de92c6f592b0275","0x4a7484aa6ea6e483","0x5cb0a9dcbd41fbd4","0x76f988da831153b5","0x983e5152ee66dfab","0xa831c66d2db43210","0xb00327c898fb213f","0xbf597fc7beef0ee4","0xc6e00bf33da88fc2","0xd5a79147930aa725","0x06ca6351e003826f","0x142929670a0e6e70","0x27b70a8546d22ffc","0x2e1b21385c26c926","0x4d2c6dfc5ac42aed","0x53380d139d95b3df","0x650a73548baf63de","0x766a0abb3c77b2a8","0x81c2c92e47edaee6","0x92722c851482353b","0xa2bfe8a14cf10364","0xa81a664bbc423001","0xc24b8b70d0f89791","0xc76c51a30654be30","0xd192e819d6ef5218","0xd69906245565a910","0xf40e35855771202a","0x106aa07032bbd1b8","0x19a4c116b8d2d0c8","0x1e376c085141ab53","0x2748774cdf8eeb99","0x34b0bcb5e19b48a8","0x391c0cb3c5c95a63","0x4ed8aa4ae3418acb","0x5b9cca4f7763e373","0x682e6ff3d6b2b8a3","0x748f82ee5defb2fc","0x78a5636f43172f60","0x84c87814a1f0ab72","0x8cc702081a6439ec","0x90befffa23631e28","0xa4506cebde82bde9","0xbef9a3f7b2c67915","0xc67178f2e372532b","0xca273eceea26619c","0xd186b8c721c0c207","0xeada7dd6cde0eb1e","0xf57d4f7fee6ed178","0x06f067aa72176fba","0x0a637dc5a2c898a6","0x113f9804bef90dae","0x1b710b35131c471b","0x28db77f523047d84","0x32caab7b40c72493","0x3c9ebe0a15c9bebc","0x431d67c49c100d4c","0x4cc5d4becb3e42b6","0x597f299cfc657e2a","0x5fcb6fab3ad6faec","0x6c44198c4a475817"].map(t=>BigInt(t))),dt=new Uint32Array(80),ht=new Uint32Array(80),zt=class extends Tt{constructor(){super(128,64,16,!1),this.Ah=1779033703,this.Al=-205731576,this.Bh=-1150833019,this.Bl=-2067093701,this.Ch=1013904242,this.Cl=-23791573,this.Dh=-1521486534,this.Dl=1595750129,this.Eh=1359893119,this.El=-1377402159,this.Fh=-1694144372,this.Fl=725511199,this.Gh=528734635,this.Gl=-79577749,this.Hh=1541459225,this.Hl=327033209}get(){let{Ah:e,Al:n,Bh:o,Bl:s,Ch:r,Cl:i,Dh:f,Dl:c,Eh:u,El:a,Fh:d,Fl:b,Gh:w,Gl:B,Hh:y,Hl:A}=this;return[e,n,o,s,r,i,f,c,u,a,d,b,w,B,y,A]}set(e,n,o,s,r,i,f,c,u,a,d,b,w,B,y,A){this.Ah=e|0,this.Al=n|0,this.Bh=o|0,this.Bl=s|0,this.Ch=r|0,this.Cl=i|0,this.Dh=f|0,this.Dl=c|0,this.Eh=u|0,this.El=a|0,this.Fh=d|0,this.Fl=b|0,this.Gh=w|0,this.Gl=B|0,this.Hh=y|0,this.Hl=A|0}process(e,n){for(let x=0;x<16;x++,n+=4)dt[x]=e.getUint32(n),ht[x]=e.getUint32(n+=4);for(let x=16;x<80;x++){let I=dt[x-15]|0,R=ht[x-15]|0,H=_.rotrSH(I,R,1)^_.rotrSH(I,R,8)^_.shrSH(I,R,7),z=_.rotrSL(I,R,1)^_.rotrSL(I,R,8)^_.shrSL(I,R,7),q=dt[x-2]|0,$=ht[x-2]|0,G=_.rotrSH(q,$,19)^_.rotrBH(q,$,61)^_.shrSH(q,$,6),Z=_.rotrSL(q,$,19)^_.rotrBL(q,$,61)^_.shrSL(q,$,6),ut=_.add4L(z,Z,ht[x-7],ht[x-16]),st=_.add4H(ut,H,G,dt[x-7],dt[x-16]);dt[x]=st|0,ht[x]=ut|0}let{Ah:o,Al:s,Bh:r,Bl:i,Ch:f,Cl:c,Dh:u,Dl:a,Eh:d,El:b,Fh:w,Fl:B,Gh:y,Gl:A,Hh:T,Hl:p}=this;for(let x=0;x<80;x++){let I=_.rotrSH(d,b,14)^_.rotrSH(d,b,18)^_.rotrBH(d,b,41),R=_.rotrSL(d,b,14)^_.rotrSL(d,b,18)^_.rotrBL(d,b,41),H=d&w^~d&y,z=b&B^~b&A,q=_.add5L(p,R,z,In[x],ht[x]),$=_.add5H(q,T,I,H,An[x],dt[x]),G=q|0,Z=_.rotrSH(o,s,28)^_.rotrBH(o,s,34)^_.rotrBH(o,s,39),ut=_.rotrSL(o,s,28)^_.rotrBL(o,s,34)^_.rotrBL(o,s,39),st=o&r^o&f^r&f,yt=s&i^s&c^i&c;T=y|0,p=A|0,y=w|0,A=B|0,w=d|0,B=b|0,{h:d,l:b}=_.add(u|0,a|0,$|0,G|0),u=f|0,a=c|0,f=r|0,c=i|0,r=o|0,i=s|0;let m=_.add3L(G,ut,yt);o=_.add3H(m,$,Z,st),s=m|0}({h:o,l:s}=_.add(this.Ah|0,this.Al|0,o|0,s|0)),{h:r,l:i}=_.add(this.Bh|0,this.Bl|0,r|0,i|0),{h:f,l:c}=_.add(this.Ch|0,this.Cl|0,f|0,c|0),{h:u,l:a}=_.add(this.Dh|0,this.Dl|0,u|0,a|0),{h:d,l:b}=_.add(this.Eh|0,this.El|0,d|0,b|0),{h:w,l:B}=_.add(this.Fh|0,this.Fl|0,w|0,B|0),{h:y,l:A}=_.add(this.Gh|0,this.Gl|0,y|0,A|0),{h:T,l:p}=_.add(this.Hh|0,this.Hl|0,T|0,p|0),this.set(o,s,r,i,f,c,u,a,d,b,w,B,y,A,T,p)}roundClean(){dt.fill(0),ht.fill(0)}destroy(){this.buffer.fill(0),this.set(0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0)}};var mt=we(()=>new zt);var Ln=BigInt(0),vn=BigInt(1),Tn=BigInt(2);function kt(t){return t instanceof Uint8Array||t!=null&&typeof t=="object"&&t.constructor.name==="Uint8Array"}function ct(t){if(!kt(t))throw new Error("Uint8Array expected")}function Ut(t,e){if(typeof e!="boolean")throw new Error(`${t} must be valid boolean, got "${e}".`)}var Cn=Array.from({length:256},(t,e)=>e.toString(16).padStart(2,"0"));function gt(t){ct(t);let e="";for(let n=0;n=it._0&&t<=it._9)return t-it._0;if(t>=it._A&&t<=it._F)return t-(it._A-10);if(t>=it._a&&t<=it._f)return t-(it._a-10)}function Ee(t){if(typeof t!="string")throw new Error("hex string expected, got "+typeof t);let e=t.length,n=e/2;if(e%2)throw new Error("padded hex string expected, got unpadded hex of length "+e);let o=new Uint8Array(n);for(let s=0,r=0;stypeof t=="bigint"&&Ln<=t;function Un(t,e,n){return Ft(t)&&Ft(e)&&Ft(n)&&e<=t&&t(Tn<typeof t=="bigint",function:t=>typeof t=="function",boolean:t=>typeof t=="boolean",string:t=>typeof t=="string",stringOrUint8Array:t=>typeof t=="string"||kt(t),isSafeInteger:t=>Number.isSafeInteger(t),array:t=>Array.isArray(t),field:(t,e)=>e.Fp.isValid(t),hash:t=>typeof t=="function"&&Number.isSafeInteger(t.outputLen)};function ot(t,e,n={}){let o=(s,r,i)=>{let f=On[r];if(typeof f!="function")throw new Error(`Invalid validator "${r}", expected function`);let c=t[s];if(!(i&&c===void 0)&&!f(c,t))throw new Error(`Invalid param ${String(s)}=${c} (${typeof c}), expected ${r}`)};for(let[s,r]of Object.entries(e))o(s,r,!1);for(let[s,r]of Object.entries(n))o(s,r,!0);return t}function jt(t){let e=new WeakMap;return(n,...o)=>{let s=e.get(n);if(s!==void 0)return s;let r=t(n,...o);return e.set(n,r),r}}var V=BigInt(0),D=BigInt(1),bt=BigInt(2),Rn=BigInt(3),Pt=BigInt(4),Ae=BigInt(5),Ie=BigInt(8),Hn=BigInt(9),qn=BigInt(16);function U(t,e){let n=t%e;return n>=V?n:e+n}function Yt(t,e,n){if(n<=V||e 0");if(n===D)return V;let o=D;for(;e>V;)e&D&&(o=o*t%n),t=t*t%n,e>>=D;return o}function X(t,e,n){let o=t;for(;e-- >V;)o*=o,o%=n;return o}function Le(t,e){if(t===V||e<=V)throw new Error(`invert: expected positive integers, got n=${t} mod=${e}`);let n=U(t,e),o=e,s=V,r=D,i=D,f=V;for(;n!==V;){let u=o/n,a=o%n,d=s-i*u,b=r-f*u;o=n,n=a,s=i,r=f,i=d,f=b}if(o!==D)throw new Error("invert: does not exist");return U(s,e)}function Dn(t){let e=(t-D)/bt,n,o,s;for(n=t-D,o=0;n%bt===V;n/=bt,o++);for(s=bt;s(U(t,e)&D)===D,$n=["create","isValid","is0","neg","inv","sqrt","sqr","eql","add","sub","mul","pow","div","addN","subN","mulN","sqrN"];function ve(t){let e={ORDER:"bigint",MASK:"bigint",BYTES:"isSafeInteger",BITS:"isSafeInteger"},n=$n.reduce((o,s)=>(o[s]="function",o),e);return ot(t,n)}function Vn(t,e,n){if(n 0");if(n===V)return t.ONE;if(n===D)return e;let o=t.ONE,s=e;for(;n>V;)n&D&&(o=t.mul(o,s)),s=t.sqr(s),n>>=D;return o}function Zn(t,e){let n=new Array(e.length),o=e.reduce((r,i,f)=>t.is0(i)?r:(n[f]=r,t.mul(r,i)),t.ONE),s=t.inv(o);return e.reduceRight((r,i,f)=>t.is0(i)?r:(n[f]=t.mul(r,n[f]),t.mul(r,i)),s),n}function Xt(t,e){let n=e!==void 0?e:t.toString(2).length,o=Math.ceil(n/8);return{nBitLength:n,nByteLength:o}}function Te(t,e,n=!1,o={}){if(t<=V)throw new Error(`Expected Field ORDER > 0, got ${t}`);let{nBitLength:s,nByteLength:r}=Xt(t,e);if(r>2048)throw new Error("Field lengths over 2048 bytes are not supported");let i=Mn(t),f=Object.freeze({ORDER:t,BITS:s,BYTES:r,MASK:Se(s),ZERO:V,ONE:D,create:c=>U(c,t),isValid:c=>{if(typeof c!="bigint")throw new Error(`Invalid field element: expected bigint, got ${typeof c}`);return V<=c&&cc===V,isOdd:c=>(c&D)===D,neg:c=>U(-c,t),eql:(c,u)=>c===u,sqr:c=>U(c*c,t),add:(c,u)=>U(c+u,t),sub:(c,u)=>U(c-u,t),mul:(c,u)=>U(c*u,t),pow:(c,u)=>Vn(f,c,u),div:(c,u)=>U(c*Le(u,t),t),sqrN:c=>c*c,addN:(c,u)=>c+u,subN:(c,u)=>c-u,mulN:(c,u)=>c*u,inv:c=>Le(c,t),sqrt:o.sqrt||(c=>i(f,c)),invertBatch:c=>Zn(f,c),cmov:(c,u,a)=>a?u:c,toBytes:c=>n?et(c,r):Gt(c,r),fromBytes:c=>{if(c.length!==r)throw new Error(`Fp.fromBytes: expected ${r}, got ${c.length}`);return n?W(c):Ot(c)}});return Object.freeze(f)}function Ce(t,e){if(!t.isOdd)throw new Error("Field doesn't have isOdd");let n=t.sqrt(e);return t.isOdd(n)?t.neg(n):n}var zn=BigInt(0),Wt=BigInt(1),Kt=new WeakMap,Ue=new WeakMap;function Oe(t,e){let n=(r,i)=>{let f=i.negate();return r?f:i},o=r=>{if(!Number.isSafeInteger(r)||r<=0||r>e)throw new Error(`Wrong window size=${r}, should be [1..${e}]`)},s=r=>{o(r);let i=Math.ceil(e/r)+1,f=2**(r-1);return{windows:i,windowSize:f}};return{constTimeNegate:n,unsafeLadder(r,i){let f=t.ZERO,c=r;for(;i>zn;)i&Wt&&(f=f.add(c)),c=c.double(),i>>=Wt;return f},precomputeWindow(r,i){let{windows:f,windowSize:c}=s(i),u=[],a=r,d=a;for(let b=0;b>=B,T>u&&(T-=w,f+=Wt);let p=A,x=A+Math.abs(T)-1,I=y%2!==0,R=T<0;T===0?d=d.add(n(I,i[p])):a=a.add(n(R,i[x]))}return{p:a,f:d}},wNAFCached(r,i,f){let c=Ue.get(r)||1,u=Kt.get(r);return u||(u=this.precomputeWindow(r,c),c!==1&&Kt.set(r,f(u))),this.wNAF(c,u,i)},setWindowSize(r,i){o(i),Ue.set(r,i),Kt.delete(r)}}}function Ne(t){return ve(t.Fp),ot(t,{n:"bigint",h:"bigint",Gx:"field",Gy:"field"},{nBitLength:"isSafeInteger",nByteLength:"isSafeInteger"}),Object.freeze({...Xt(t.n,t.nBitLength),...t,p:t.Fp.ORDER})}var K=BigInt(0),P=BigInt(1),Rt=BigInt(2),Fn=BigInt(8),kn={zip215:!0};function Gn(t){let e=Ne(t);return ot(t,{hash:"function",a:"bigint",d:"bigint",randomBytes:"function"},{adjustScalarBytes:"function",domain:"function",uvRatio:"function",mapToCurve:"function"}),Object.freeze({...e})}function Ht(t){let e=Gn(t),{Fp:n,n:o,prehash:s,hash:r,randomBytes:i,nByteLength:f,h:c}=e,u=Rt<{try{return{isValid:!0,value:n.sqrt(m*n.inv(l))}}catch{return{isValid:!1,value:K}}}),b=e.adjustScalarBytes||(m=>m),w=e.domain||((m,l,g)=>{if(Ut("phflag",g),l.length||g)throw new Error("Contexts/pre-hash are not supported");return m});function B(m,l){ft("coordinate "+m,l,K,u)}function y(m){if(!(m instanceof p))throw new Error("ExtendedPoint expected")}let A=jt((m,l)=>{let{ex:g,ey:E,ez:S}=m,L=m.is0();l==null&&(l=L?Fn:n.inv(S));let C=a(g*l),O=a(E*l),v=a(S*l);if(L)return{x:K,y:P};if(v!==P)throw new Error("invZ was invalid");return{x:C,y:O}}),T=jt(m=>{let{a:l,d:g}=e;if(m.is0())throw new Error("bad point: ZERO");let{ex:E,ey:S,ez:L,et:C}=m,O=a(E*E),v=a(S*S),N=a(L*L),M=a(N*N),j=a(O*l),J=a(N*a(j+v)),tt=a(M+a(g*a(O*v)));if(J!==tt)throw new Error("bad point: equation left != right (1)");let Y=a(E*S),lt=a(L*C);if(Y!==lt)throw new Error("bad point: equation left != right (2)");return!0});class p{constructor(l,g,E,S){this.ex=l,this.ey=g,this.ez=E,this.et=S,B("x",l),B("y",g),B("z",E),B("t",S),Object.freeze(this)}get x(){return this.toAffine().x}get y(){return this.toAffine().y}static fromAffine(l){if(l instanceof p)throw new Error("extended point not allowed");let{x:g,y:E}=l||{};return B("x",g),B("y",E),new p(g,E,P,a(g*E))}static normalizeZ(l){let g=n.invertBatch(l.map(E=>E.ez));return l.map((E,S)=>E.toAffine(g[S])).map(p.fromAffine)}_setWindowSize(l){R.setWindowSize(this,l)}assertValidity(){T(this)}equals(l){y(l);let{ex:g,ey:E,ez:S}=this,{ex:L,ey:C,ez:O}=l,v=a(g*O),N=a(L*S),M=a(E*O),j=a(C*S);return v===N&&M===j}is0(){return this.equals(p.ZERO)}negate(){return new p(a(-this.ex),this.ey,this.ez,a(-this.et))}double(){let{a:l}=e,{ex:g,ey:E,ez:S}=this,L=a(g*g),C=a(E*E),O=a(Rt*a(S*S)),v=a(l*L),N=g+E,M=a(a(N*N)-L-C),j=v+C,J=j-O,tt=v-C,Y=a(M*J),lt=a(j*tt),xt=a(M*tt),_t=a(J*j);return new p(Y,lt,_t,xt)}add(l){y(l);let{a:g,d:E}=e,{ex:S,ey:L,ez:C,et:O}=this,{ex:v,ey:N,ez:M,et:j}=l;if(g===BigInt(-1)){let ae=a((L-S)*(N+v)),ue=a((L+S)*(N-v)),Dt=a(ue-ae);if(Dt===K)return this.double();let le=a(C*Rt*j),de=a(O*Rt*M),he=de+le,pe=ue+ae,xe=de-le,We=a(he*Dt),Ke=a(pe*xe),Qe=a(he*xe),Je=a(Dt*pe);return new p(We,Ke,Je,Qe)}let J=a(S*v),tt=a(L*N),Y=a(O*E*j),lt=a(C*M),xt=a((S+L)*(v+N)-J-tt),_t=lt-Y,ce=lt+Y,fe=a(tt-g*J),je=a(xt*_t),Pe=a(ce*fe),Ye=a(xt*fe),Xe=a(_t*ce);return new p(je,Pe,Xe,Ye)}subtract(l){return this.add(l.negate())}wNAF(l){return R.wNAFCached(this,l,p.normalizeZ)}multiply(l){let g=l;ft("scalar",g,P,o);let{p:E,f:S}=this.wNAF(g);return p.normalizeZ([E,S])[0]}multiplyUnsafe(l){let g=l;return ft("scalar",g,K,o),g===K?I:this.equals(I)||g===P?this:this.equals(x)?this.wNAF(g).p:R.unsafeLadder(this,g)}isSmallOrder(){return this.multiplyUnsafe(c).is0()}isTorsionFree(){return R.unsafeLadder(this,o).is0()}toAffine(l){return A(this,l)}clearCofactor(){let{h:l}=e;return l===P?this:this.multiplyUnsafe(l)}static fromHex(l,g=!1){let{d:E,a:S}=e,L=n.BYTES;l=k("pointHex",l,L),Ut("zip215",g);let C=l.slice(),O=l[L-1];C[L-1]=O&-129;let v=W(C),N=g?u:n.ORDER;ft("pointHex.y",v,K,N);let M=a(v*v),j=a(M-P),J=a(E*M-S),{isValid:tt,value:Y}=d(j,J);if(!tt)throw new Error("Point.fromHex: invalid y coordinate");let lt=(Y&P)===P,xt=(O&128)!==0;if(!g&&Y===K&&xt)throw new Error("Point.fromHex: x=0 and x_0=1");return xt!==lt&&(Y=a(-Y)),p.fromAffine({x:Y,y:v})}static fromPrivateKey(l){return q(l).point}toRawBytes(){let{x:l,y:g}=this.toAffine(),E=et(g,n.BYTES);return E[E.length-1]|=l&P?128:0,E}toHex(){return gt(this.toRawBytes())}}p.BASE=new p(e.Gx,e.Gy,P,a(e.Gx*e.Gy)),p.ZERO=new p(K,P,P,K);let{BASE:x,ZERO:I}=p,R=Oe(p,f*8);function H(m){return U(m,o)}function z(m){return H(W(m))}function q(m){let l=f;m=k("private key",m,l);let g=k("hashed private key",r(m),2*l),E=b(g.slice(0,l)),S=g.slice(l,2*l),L=z(E),C=x.multiply(L),O=C.toRawBytes();return{head:E,prefix:S,scalar:L,point:C,pointBytes:O}}function $(m){return q(m).pointBytes}function G(m=new Uint8Array,...l){let g=nt(...l);return z(r(w(g,k("context",m),!!s)))}function Z(m,l,g={}){m=k("message",m),s&&(m=s(m));let{prefix:E,scalar:S,pointBytes:L}=q(l),C=G(g.context,E,m),O=x.multiply(C).toRawBytes(),v=G(g.context,O,L,m),N=H(C+v*S);ft("signature.s",N,K,o);let M=nt(O,et(N,n.BYTES));return k("result",M,f*2)}let ut=kn;function st(m,l,g,E=ut){let{context:S,zip215:L}=E,C=n.BYTES;m=k("signature",m,2*C),l=k("message",l),L!==void 0&&Ut("zip215",L),s&&(l=s(l));let O=W(m.slice(C,2*C)),v,N,M;try{v=p.fromHex(g,L),N=p.fromHex(m.slice(0,C),L),M=x.multiplyUnsafe(O)}catch{return!1}if(!L&&v.isSmallOrder())return!1;let j=G(S,N.toRawBytes(),v.toRawBytes(),l);return N.add(v.multiplyUnsafe(j)).subtract(M).clearCofactor().equals(p.ZERO)}return x._setWindowSize(8),{CURVE:e,getPublicKey:$,sign:Z,verify:st,ExtendedPoint:p,utils:{getExtendedPublicKey:q,randomPrivateKey:()=>i(n.BYTES),precompute(m=8,l=p.BASE){return l._setWindowSize(m),l.multiply(BigInt(3)),l}}}}var jn=Ot;function pt(t,e){if(t<0||t>=1<<8*e)throw new Error(`bad I2OSP call: value=${t} length=${e}`);let n=Array.from({length:e}).fill(0);for(let o=e-1;o>=0;o--)n[o]=t&255,t>>>=8;return new Uint8Array(n)}function Pn(t,e){let n=new Uint8Array(t.length);for(let o=0;o255&&(e=o(nt(Nt("H2C-OVERSIZE-DST-"),e)));let{outputLen:s,blockLen:r}=o,i=Math.ceil(n/s);if(i>255)throw new Error("Invalid xmd length");let f=nt(e,pt(e.length,1)),c=pt(0,r),u=pt(n,2),a=new Array(i),d=o(nt(c,t,u,pt(0,1),f));a[0]=o(nt(d,pt(1,1),f));for(let w=1;w<=i;w++){let B=[Pn(d,a[w-1]),pt(w+1,1),f];a[w]=o(nt(...B))}return nt(...a).slice(0,n)}function Yn(t,e,n,o,s){if(ct(t),ct(e),Qt(n),e.length>255){let r=Math.ceil(2*o/8);e=s.create({dkLen:r}).update(Nt("H2C-OVERSIZE-DST-")).update(e).digest()}if(n>65535||e.length>255)throw new Error("expand_message_xof: invalid lenInBytes");return s.create({dkLen:n}).update(t).update(pt(n,2)).update(e).update(pt(e.length,1)).digest()}function Re(t,e,n){ot(n,{DST:"stringOrUint8Array",p:"bigint",m:"isSafeInteger",k:"isSafeInteger",hash:"hash"});let{p:o,k:s,m:r,hash:i,expand:f,DST:c}=n;ct(t),Qt(e);let u=typeof c=="string"?Nt(c):c,a=o.toString(2).length,d=Math.ceil((a+s)/8),b=e*r*d,w;if(f==="xmd")w=Jt(t,u,b,i);else if(f==="xof")w=Yn(t,u,b,s,i);else if(f==="_internal_pass")w=t;else throw new Error('expand must be "xmd" or "xof"');let B=new Array(e);for(let y=0;yU(p,n),s=e.montgomeryBits,r=Math.ceil(s/8),i=e.nByteLength,f=e.adjustScalarBytes||(p=>p),c=e.powPminus2||(p=>Yt(p,n-BigInt(2),n));function u(p,x,I){let R=o(p*(x-I));return x=o(x-R),I=o(I+R),[x,I]}let a=(e.a-BigInt(2))/BigInt(4);function d(p,x){ft("u",p,wt,n),ft("scalar",x,wt,n);let I=x,R=p,H=te,z=wt,q=p,$=te,G=wt,Z;for(let st=BigInt(s-1);st>=wt;st--){let yt=I>>st&te;G^=yt,Z=u(G,H,q),H=Z[0],q=Z[1],Z=u(G,z,$),z=Z[0],$=Z[1],G=yt;let m=H+z,l=o(m*m),g=H-z,E=o(g*g),S=l-E,L=q+$,C=q-$,O=o(C*m),v=o(L*g),N=O+v,M=O-v;q=o(N*N),$=o(R*o(M*M)),H=o(l*E),z=o(S*(l+o(a*S)))}Z=u(G,H,q),H=Z[0],q=Z[1],Z=u(G,z,$),z=Z[0],$=Z[1];let ut=c(z);return o(H*ut)}function b(p){return et(o(p),r)}function w(p){let x=k("u coordinate",p,r);return i===32&&(x[31]&=127),W(x)}function B(p){let x=k("scalar",p),I=x.length;if(I!==r&&I!==i)throw new Error(`Expected ${r} or ${i} bytes, got ${I}`);return W(f(x))}function y(p,x){let I=w(x),R=B(p),H=d(I,R);if(H===wt)throw new Error("Invalid private or public key received");return b(H)}let A=b(e.Gu);function T(p){return y(p,A)}return{scalarMult:y,scalarMultBase:T,getSharedSecret:(p,x)=>y(p,x),getPublicKey:p=>T(p),utils:{randomPrivateKey:()=>e.randomBytes(e.nByteLength)},GuBytes:A}}var Bt=BigInt("57896044618658097711785492504343953926634992332820282019728792003956564819949"),oe=BigInt("19681161376707505956807079304988542015446066515923890162744021073123829784752"),Wn=BigInt(0),rt=BigInt(1),qt=BigInt(2),Ve=BigInt(3),Ze=BigInt(5),se=BigInt(8);function ze(t){let e=BigInt(10),n=BigInt(20),o=BigInt(40),s=BigInt(80),r=Bt,f=t*t%r*t%r,c=X(f,qt,r)*f%r,u=X(c,rt,r)*t%r,a=X(u,Ze,r)*u%r,d=X(a,e,r)*a%r,b=X(d,n,r)*d%r,w=X(b,o,r)*b%r,B=X(w,s,r)*w%r,y=X(B,s,r)*w%r,A=X(y,e,r)*a%r;return{pow_p_5_8:X(A,qt,r)*t%r,b2:f}}function Fe(t){return t[0]&=248,t[31]&=127,t[31]|=64,t}function ie(t,e){let n=Bt,o=U(e*e*e,n),s=U(o*o*e,n),r=ze(t*s).pow_p_5_8,i=U(t*o*r,n),f=U(e*i*i,n),c=i,u=U(i*oe,n),a=f===t,d=f===U(-t,n),b=f===U(-t*oe,n);return a&&(i=c),(d||b)&&(i=u),at(i,n)&&(i=U(-i,n)),{isValid:a||d,value:i}}var Po=["0100000000000000000000000000000000000000000000000000000000000000","c7176a703d4dd84fba3c0b760d10670f2a2053fa2c39ccc64ec7fd7792ac037a","0000000000000000000000000000000000000000000000000000000000000080","26e8958fc2b227b045c3f489f2ef98f0d5dfac05d3c63339b13802886d53fc05","ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f","26e8958fc2b227b045c3f489f2ef98f0d5dfac05d3c63339b13802886d53fc85","0000000000000000000000000000000000000000000000000000000000000000","c7176a703d4dd84fba3c0b760d10670f2a2053fa2c39ccc64ec7fd7792ac03fa"],h=Te(Bt,void 0,!0),Et={a:BigInt(-1),d:BigInt("37095705934669439343138083508754565189542113879843219016388785533085940283555"),Fp:h,n:BigInt("7237005577332262213973186563042994240857116359379907606001950938285454250989"),h:se,Gx:BigInt("15112221349535400772501151409588531511454012693041857206046113283949847762202"),Gy:BigInt("46316835694926478169428394003475163141307993866256225615783033603165251855960"),hash:mt,randomBytes:Vt,adjustScalarBytes:Fe,uvRatio:ie},F=Ht(Et);function ke(t,e,n){if(e.length>255)throw new Error("Context is too big");return ge(vt("SigEd25519 no Ed25519 collisions"),new Uint8Array([n?1:0,e.length]),e,t)}var Yo=Ht({...Et,domain:ke}),Xo=Ht(Object.assign({},Et,{domain:ke,prehash:mt})),Wo=qe({P:Bt,a:BigInt(486662),montgomeryBits:255,nByteLength:32,Gu:BigInt(9),powPminus2:t=>{let e=Bt,{pow_p_5_8:n,b2:o}=ze(t);return U(X(n,Ve,e)*o,e)},adjustScalarBytes:Fe,randomBytes:Vt});function Kn(t){let{y:e}=F.ExtendedPoint.fromHex(t),n=BigInt(1);return h.toBytes(h.create((n+e)*h.inv(n-e)))}var Ko=Kn;function Qo(t){let e=Et.hash(t.subarray(0,32));return Et.adjustScalarBytes(e).subarray(0,32)}var Qn=(h.ORDER+Ve)/se,Jn=h.pow(qt,Qn),De=h.sqrt(h.neg(h.ONE));function to(t){let e=(h.ORDER-Ze)/se,n=BigInt(486662),o=h.sqr(t);o=h.mul(o,qt);let s=h.add(o,h.ONE),r=h.neg(n),i=h.sqr(s),f=h.mul(i,s),c=h.mul(o,n);c=h.mul(c,r),c=h.add(c,i),c=h.mul(c,r);let u=h.sqr(f);i=h.sqr(u),u=h.mul(u,f),u=h.mul(u,c),i=h.mul(i,u);let a=h.pow(i,e);a=h.mul(a,u);let d=h.mul(a,De);i=h.sqr(a),i=h.mul(i,f);let b=h.eql(i,c),w=h.cmov(d,a,b),B=h.mul(r,o),y=h.mul(a,t);y=h.mul(y,Jn);let A=h.mul(y,De),T=h.mul(c,o);i=h.sqr(y),i=h.mul(i,f);let p=h.eql(i,T),x=h.cmov(A,y,p);i=h.sqr(w),i=h.mul(i,f);let I=h.eql(i,c),R=h.cmov(B,r,I),H=h.cmov(x,w,I),z=h.isOdd(H);return H=h.cmov(H,h.neg(H),I!==z),{xMn:R,xMd:s,yMn:H,yMd:rt}}var eo=Ce(h,h.neg(BigInt(486664)));function no(t){let{xMn:e,xMd:n,yMn:o,yMd:s}=to(t),r=h.mul(e,s);r=h.mul(r,eo);let i=h.mul(n,o),f=h.sub(e,n),c=h.add(e,n),u=h.mul(i,c),a=h.eql(u,h.ZERO);r=h.cmov(r,h.ZERO,a),i=h.cmov(i,h.ONE,a),f=h.cmov(f,h.ONE,a),c=h.cmov(c,h.ONE,a);let d=h.invertBatch([i,c]);return{x:h.mul(r,d[0]),y:h.mul(f,d[1])}}var Ge=He(F.ExtendedPoint,t=>no(t[0]),{DST:"edwards25519_XMD:SHA-512_ELL2_RO_",encodeDST:"edwards25519_XMD:SHA-512_ELL2_NU_",p:h.ORDER,m:1,k:128,expand:"xmd",hash:mt}),Jo=Ge.hashToCurve,tr=Ge.encodeToCurve;function ee(t){if(!(t instanceof Q))throw new Error("RistrettoPoint expected")}var re=oe,oo=BigInt("25063068953384623474111414158702152701244531502492656460079210482610430750235"),ro=BigInt("54469307008909316920995813868745141605393597292927456921205312896311721017578"),so=BigInt("1159843021668779879193775521855586647937357759715417654439879720876111806838"),io=BigInt("40440834346308536858101042469323190826248399146238708352240133220865137265952"),Me=t=>ie(rt,t),co=BigInt("0x7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),ne=t=>F.CURVE.Fp.create(W(t)&co);function $e(t){let{d:e}=F.CURVE,n=F.CURVE.Fp.ORDER,o=F.CURVE.Fp.create,s=o(re*t*t),r=o((s+rt)*so),i=BigInt(-1),f=o((i-e*s)*o(s+e)),{isValid:c,value:u}=ie(r,f),a=o(u*t);at(a,n)||(a=o(-a)),c||(u=a),c||(i=s);let d=o(i*(s-rt)*io-f),b=u*u,w=o((u+u)*f),B=o(d*oo),y=o(rt-b),A=o(rt+b);return new F.ExtendedPoint(o(w*A),o(y*B),o(B*A),o(w*y))}var Q=class t{constructor(e){this.ep=e}static fromAffine(e){return new t(F.ExtendedPoint.fromAffine(e))}static hashToCurve(e){e=k("ristrettoHash",e,64);let n=ne(e.slice(0,32)),o=$e(n),s=ne(e.slice(32,64)),r=$e(s);return new t(o.add(r))}static fromHex(e){e=k("ristrettoHex",e,32);let{a:n,d:o}=F.CURVE,s=F.CURVE.Fp.ORDER,r=F.CURVE.Fp.create,i="RistrettoPoint.fromHex: the hex is not valid encoding of RistrettoPoint",f=ne(e);if(!_e(et(f,32),e)||at(f,s))throw new Error(i);let c=r(f*f),u=r(rt+n*c),a=r(rt-n*c),d=r(u*u),b=r(a*a),w=r(n*o*d-b),{isValid:B,value:y}=Me(r(w*b)),A=r(y*a),T=r(y*A*w),p=r((f+f)*A);at(p,s)&&(p=r(-p));let x=r(u*T),I=r(p*x);if(!B||at(I,s)||x===Wn)throw new Error(i);return new t(new F.ExtendedPoint(p,x,rt,I))}toRawBytes(){let{ex:e,ey:n,ez:o,et:s}=this.ep,r=F.CURVE.Fp.ORDER,i=F.CURVE.Fp.create,f=i(i(o+n)*i(o-n)),c=i(e*n),u=i(c*c),{value:a}=Me(i(f*u)),d=i(a*f),b=i(a*c),w=i(d*b*s),B;if(at(s*w,r)){let A=i(n*re),T=i(e*re);e=A,n=T,B=i(d*ro)}else B=b;at(e*w,r)&&(n=i(-n));let y=i((o-n)*B);return at(y,r)&&(y=i(-y)),et(y,32)}toHex(){return gt(this.toRawBytes())}toString(){return this.toHex()}equals(e){ee(e);let{ex:n,ey:o}=this.ep,{ex:s,ey:r}=e.ep,i=F.CURVE.Fp.create,f=i(n*r)===i(o*s),c=i(o*r)===i(n*s);return f||c}add(e){return ee(e),new t(this.ep.add(e.ep))}subtract(e){return ee(e),new t(this.ep.subtract(e.ep))}multiply(e){return new t(this.ep.multiply(e))}multiplyUnsafe(e){return new t(this.ep.multiplyUnsafe(e))}double(){return new t(this.ep.double())}negate(){return new t(this.ep.negate())}},er=(Q.BASE||(Q.BASE=new Q(F.ExtendedPoint.BASE)),Q.ZERO||(Q.ZERO=new Q(F.ExtendedPoint.ZERO)),Q),fo=(t,e)=>{let n=e.DST,o=typeof n=="string"?vt(n):n,s=Jt(t,o,64,mt);return Q.hashToCurve(s)},nr=fo;export{Po as ED25519_TORSION_SUBGROUP,er as RistrettoPoint,F as ed25519,Yo as ed25519ctx,Xo as ed25519ph,Ko as edwardsToMontgomery,Qo as edwardsToMontgomeryPriv,Kn as edwardsToMontgomeryPub,tr as encodeToCurve,Jo as hashToCurve,fo as hashToRistretto255,nr as hash_to_ristretto255,Wo as x25519}; /*! Bundled license information: @noble/hashes/esm/utils.js: (*! noble-hashes - MIT License (c) 2022 Paul Miller (paulmillr.com) *) @noble/curves/esm/abstract/utils.js: @noble/curves/esm/abstract/modular.js: @noble/curves/esm/abstract/curve.js: @noble/curves/esm/abstract/edwards.js: @noble/curves/esm/abstract/montgomery.js: @noble/curves/esm/ed25519.js: (*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) *) */