diff --git a/.nojekyll b/.nojekyll new file mode 100644 index 00000000..e69de29b diff --git a/404.html b/404.html new file mode 100644 index 00000000..a0a83790 --- /dev/null +++ b/404.html @@ -0,0 +1,2196 @@ + + + + + + + + + + + + + + + + + + + + + + + docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ +

404 - Not found

+ +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/aufgaben/bind-letsencrypt/index.html b/acme/aufgaben/bind-letsencrypt/index.html new file mode 100644 index 00000000..41e3857a --- /dev/null +++ b/acme/aufgaben/bind-letsencrypt/index.html @@ -0,0 +1,2299 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Bind DNS für Letsencrypt - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Bind DNS für Letsencrypt aufsetzen

+

Anleitung von Olat

+

Ich werde hier noch meine Probleme und Anmerkungen bei diesem Prozess erläutern.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/aufgaben/certbot/index.html b/acme/aufgaben/certbot/index.html new file mode 100644 index 00000000..8037c1f5 --- /dev/null +++ b/acme/aufgaben/certbot/index.html @@ -0,0 +1,2297 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Certbot in Betrieb nehmen - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Certbot in Betrieb nehmen

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/aufgaben/index.html b/acme/aufgaben/index.html new file mode 100644 index 00000000..45148a42 --- /dev/null +++ b/acme/aufgaben/index.html @@ -0,0 +1,2296 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Aufgaben - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Aufgaben

+
    +
  • = fertig
  • +
  • = WIP
  • +
+

Checkliste der Aufgaben gemäss Olat:

+
    +
  • Bind DNS für Letsencrypt aufsetzen
  • +
  • Certbot in Betrieb nehmen
  • +
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/glossar/acme/index.html b/acme/glossar/acme/index.html new file mode 100644 index 00000000..5ef946ce --- /dev/null +++ b/acme/glossar/acme/index.html @@ -0,0 +1,2298 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Was-ist-ACME - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+ +
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/glossar/index.html b/acme/glossar/index.html new file mode 100644 index 00000000..ff5c4679 --- /dev/null +++ b/acme/glossar/index.html @@ -0,0 +1,2297 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Glossar - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Glossar

+
    +
  • = fertig
  • +
  • = WIP
  • +
+

Checkliste meiner selbst-definierten Themen:

+
    +
  • Was ist ACME?
  • +
  • Let's Encrypt Zertifikate
  • +
  • Wildcard Zertifikate
  • +
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/glossar/lets-encrypt/index.html b/acme/glossar/lets-encrypt/index.html new file mode 100644 index 00000000..7e3c320f --- /dev/null +++ b/acme/glossar/lets-encrypt/index.html @@ -0,0 +1,2297 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Let's-Encrypt-Zertifikate - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Let's Encrypt Zertifikate

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/glossar/wildcard/index.html b/acme/glossar/wildcard/index.html new file mode 100644 index 00000000..5347e568 --- /dev/null +++ b/acme/glossar/wildcard/index.html @@ -0,0 +1,2297 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Wildcard-Zertifikate - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Wildcard Zertifikate

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/acme/index.html b/acme/index.html new file mode 100644 index 00000000..72a25450 --- /dev/null +++ b/acme/index.html @@ -0,0 +1,2285 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + M300 Auftrag ACME - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + Skip to content + + +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

M300 Auftrag ACME

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/assets/images/favicon.png b/assets/images/favicon.png new file mode 100644 index 00000000..1cf13b9f Binary files /dev/null and b/assets/images/favicon.png differ diff --git a/assets/javascripts/bundle.ad660dcc.min.js b/assets/javascripts/bundle.ad660dcc.min.js new file mode 100644 index 00000000..0ffc0460 --- /dev/null +++ b/assets/javascripts/bundle.ad660dcc.min.js @@ -0,0 +1,29 @@ +"use strict";(()=>{var Fi=Object.create;var gr=Object.defineProperty;var ji=Object.getOwnPropertyDescriptor;var Wi=Object.getOwnPropertyNames,Dt=Object.getOwnPropertySymbols,Ui=Object.getPrototypeOf,xr=Object.prototype.hasOwnProperty,no=Object.prototype.propertyIsEnumerable;var oo=(e,t,r)=>t in e?gr(e,t,{enumerable:!0,configurable:!0,writable:!0,value:r}):e[t]=r,R=(e,t)=>{for(var r in t||(t={}))xr.call(t,r)&&oo(e,r,t[r]);if(Dt)for(var r of Dt(t))no.call(t,r)&&oo(e,r,t[r]);return e};var io=(e,t)=>{var r={};for(var o in e)xr.call(e,o)&&t.indexOf(o)<0&&(r[o]=e[o]);if(e!=null&&Dt)for(var o of Dt(e))t.indexOf(o)<0&&no.call(e,o)&&(r[o]=e[o]);return r};var yr=(e,t)=>()=>(t||e((t={exports:{}}).exports,t),t.exports);var Di=(e,t,r,o)=>{if(t&&typeof t=="object"||typeof t=="function")for(let n of Wi(t))!xr.call(e,n)&&n!==r&&gr(e,n,{get:()=>t[n],enumerable:!(o=ji(t,n))||o.enumerable});return e};var Vt=(e,t,r)=>(r=e!=null?Fi(Ui(e)):{},Di(t||!e||!e.__esModule?gr(r,"default",{value:e,enumerable:!0}):r,e));var ao=(e,t,r)=>new Promise((o,n)=>{var i=p=>{try{s(r.next(p))}catch(c){n(c)}},a=p=>{try{s(r.throw(p))}catch(c){n(c)}},s=p=>p.done?o(p.value):Promise.resolve(p.value).then(i,a);s((r=r.apply(e,t)).next())});var co=yr((Er,so)=>{(function(e,t){typeof Er=="object"&&typeof so!="undefined"?t():typeof define=="function"&&define.amd?define(t):t()})(Er,function(){"use strict";function e(r){var o=!0,n=!1,i=null,a={text:!0,search:!0,url:!0,tel:!0,email:!0,password:!0,number:!0,date:!0,month:!0,week:!0,time:!0,datetime:!0,"datetime-local":!0};function s(H){return!!(H&&H!==document&&H.nodeName!=="HTML"&&H.nodeName!=="BODY"&&"classList"in H&&"contains"in H.classList)}function p(H){var mt=H.type,ze=H.tagName;return!!(ze==="INPUT"&&a[mt]&&!H.readOnly||ze==="TEXTAREA"&&!H.readOnly||H.isContentEditable)}function c(H){H.classList.contains("focus-visible")||(H.classList.add("focus-visible"),H.setAttribute("data-focus-visible-added",""))}function l(H){H.hasAttribute("data-focus-visible-added")&&(H.classList.remove("focus-visible"),H.removeAttribute("data-focus-visible-added"))}function f(H){H.metaKey||H.altKey||H.ctrlKey||(s(r.activeElement)&&c(r.activeElement),o=!0)}function u(H){o=!1}function h(H){s(H.target)&&(o||p(H.target))&&c(H.target)}function w(H){s(H.target)&&(H.target.classList.contains("focus-visible")||H.target.hasAttribute("data-focus-visible-added"))&&(n=!0,window.clearTimeout(i),i=window.setTimeout(function(){n=!1},100),l(H.target))}function A(H){document.visibilityState==="hidden"&&(n&&(o=!0),te())}function te(){document.addEventListener("mousemove",J),document.addEventListener("mousedown",J),document.addEventListener("mouseup",J),document.addEventListener("pointermove",J),document.addEventListener("pointerdown",J),document.addEventListener("pointerup",J),document.addEventListener("touchmove",J),document.addEventListener("touchstart",J),document.addEventListener("touchend",J)}function ie(){document.removeEventListener("mousemove",J),document.removeEventListener("mousedown",J),document.removeEventListener("mouseup",J),document.removeEventListener("pointermove",J),document.removeEventListener("pointerdown",J),document.removeEventListener("pointerup",J),document.removeEventListener("touchmove",J),document.removeEventListener("touchstart",J),document.removeEventListener("touchend",J)}function J(H){H.target.nodeName&&H.target.nodeName.toLowerCase()==="html"||(o=!1,ie())}document.addEventListener("keydown",f,!0),document.addEventListener("mousedown",u,!0),document.addEventListener("pointerdown",u,!0),document.addEventListener("touchstart",u,!0),document.addEventListener("visibilitychange",A,!0),te(),r.addEventListener("focus",h,!0),r.addEventListener("blur",w,!0),r.nodeType===Node.DOCUMENT_FRAGMENT_NODE&&r.host?r.host.setAttribute("data-js-focus-visible",""):r.nodeType===Node.DOCUMENT_NODE&&(document.documentElement.classList.add("js-focus-visible"),document.documentElement.setAttribute("data-js-focus-visible",""))}if(typeof window!="undefined"&&typeof document!="undefined"){window.applyFocusVisiblePolyfill=e;var t;try{t=new CustomEvent("focus-visible-polyfill-ready")}catch(r){t=document.createEvent("CustomEvent"),t.initCustomEvent("focus-visible-polyfill-ready",!1,!1,{})}window.dispatchEvent(t)}typeof document!="undefined"&&e(document)})});var Yr=yr((Rt,Kr)=>{/*! + * clipboard.js v2.0.11 + * https://clipboardjs.com/ + * + * Licensed MIT © Zeno Rocha + */(function(t,r){typeof Rt=="object"&&typeof Kr=="object"?Kr.exports=r():typeof define=="function"&&define.amd?define([],r):typeof Rt=="object"?Rt.ClipboardJS=r():t.ClipboardJS=r()})(Rt,function(){return function(){var e={686:function(o,n,i){"use strict";i.d(n,{default:function(){return Ii}});var a=i(279),s=i.n(a),p=i(370),c=i.n(p),l=i(817),f=i.n(l);function u(V){try{return document.execCommand(V)}catch(_){return!1}}var h=function(_){var O=f()(_);return u("cut"),O},w=h;function A(V){var _=document.documentElement.getAttribute("dir")==="rtl",O=document.createElement("textarea");O.style.fontSize="12pt",O.style.border="0",O.style.padding="0",O.style.margin="0",O.style.position="absolute",O.style[_?"right":"left"]="-9999px";var j=window.pageYOffset||document.documentElement.scrollTop;return O.style.top="".concat(j,"px"),O.setAttribute("readonly",""),O.value=V,O}var te=function(_,O){var j=A(_);O.container.appendChild(j);var D=f()(j);return u("copy"),j.remove(),D},ie=function(_){var O=arguments.length>1&&arguments[1]!==void 0?arguments[1]:{container:document.body},j="";return typeof _=="string"?j=te(_,O):_ instanceof HTMLInputElement&&!["text","search","url","tel","password"].includes(_==null?void 0:_.type)?j=te(_.value,O):(j=f()(_),u("copy")),j},J=ie;function H(V){"@babel/helpers - typeof";return typeof Symbol=="function"&&typeof Symbol.iterator=="symbol"?H=function(O){return typeof O}:H=function(O){return O&&typeof Symbol=="function"&&O.constructor===Symbol&&O!==Symbol.prototype?"symbol":typeof O},H(V)}var mt=function(){var _=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{},O=_.action,j=O===void 0?"copy":O,D=_.container,Y=_.target,ke=_.text;if(j!=="copy"&&j!=="cut")throw new Error('Invalid "action" value, use either "copy" or "cut"');if(Y!==void 0)if(Y&&H(Y)==="object"&&Y.nodeType===1){if(j==="copy"&&Y.hasAttribute("disabled"))throw new Error('Invalid "target" attribute. Please use "readonly" instead of "disabled" attribute');if(j==="cut"&&(Y.hasAttribute("readonly")||Y.hasAttribute("disabled")))throw new Error(`Invalid "target" attribute. You can't cut text from elements with "readonly" or "disabled" attributes`)}else throw new Error('Invalid "target" value, use a valid Element');if(ke)return J(ke,{container:D});if(Y)return j==="cut"?w(Y):J(Y,{container:D})},ze=mt;function Ie(V){"@babel/helpers - typeof";return typeof Symbol=="function"&&typeof Symbol.iterator=="symbol"?Ie=function(O){return typeof O}:Ie=function(O){return O&&typeof Symbol=="function"&&O.constructor===Symbol&&O!==Symbol.prototype?"symbol":typeof O},Ie(V)}function _i(V,_){if(!(V instanceof _))throw new TypeError("Cannot call a class as a function")}function ro(V,_){for(var O=0;O<_.length;O++){var j=_[O];j.enumerable=j.enumerable||!1,j.configurable=!0,"value"in j&&(j.writable=!0),Object.defineProperty(V,j.key,j)}}function Ai(V,_,O){return _&&ro(V.prototype,_),O&&ro(V,O),V}function Ci(V,_){if(typeof _!="function"&&_!==null)throw new TypeError("Super expression must either be null or a function");V.prototype=Object.create(_&&_.prototype,{constructor:{value:V,writable:!0,configurable:!0}}),_&&br(V,_)}function br(V,_){return br=Object.setPrototypeOf||function(j,D){return j.__proto__=D,j},br(V,_)}function Hi(V){var _=Pi();return function(){var j=Wt(V),D;if(_){var Y=Wt(this).constructor;D=Reflect.construct(j,arguments,Y)}else D=j.apply(this,arguments);return ki(this,D)}}function ki(V,_){return _&&(Ie(_)==="object"||typeof _=="function")?_:$i(V)}function $i(V){if(V===void 0)throw new ReferenceError("this hasn't been initialised - super() hasn't been called");return V}function Pi(){if(typeof Reflect=="undefined"||!Reflect.construct||Reflect.construct.sham)return!1;if(typeof Proxy=="function")return!0;try{return Date.prototype.toString.call(Reflect.construct(Date,[],function(){})),!0}catch(V){return!1}}function Wt(V){return Wt=Object.setPrototypeOf?Object.getPrototypeOf:function(O){return O.__proto__||Object.getPrototypeOf(O)},Wt(V)}function vr(V,_){var O="data-clipboard-".concat(V);if(_.hasAttribute(O))return _.getAttribute(O)}var Ri=function(V){Ci(O,V);var _=Hi(O);function O(j,D){var Y;return _i(this,O),Y=_.call(this),Y.resolveOptions(D),Y.listenClick(j),Y}return Ai(O,[{key:"resolveOptions",value:function(){var D=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{};this.action=typeof D.action=="function"?D.action:this.defaultAction,this.target=typeof D.target=="function"?D.target:this.defaultTarget,this.text=typeof D.text=="function"?D.text:this.defaultText,this.container=Ie(D.container)==="object"?D.container:document.body}},{key:"listenClick",value:function(D){var Y=this;this.listener=c()(D,"click",function(ke){return Y.onClick(ke)})}},{key:"onClick",value:function(D){var Y=D.delegateTarget||D.currentTarget,ke=this.action(Y)||"copy",Ut=ze({action:ke,container:this.container,target:this.target(Y),text:this.text(Y)});this.emit(Ut?"success":"error",{action:ke,text:Ut,trigger:Y,clearSelection:function(){Y&&Y.focus(),window.getSelection().removeAllRanges()}})}},{key:"defaultAction",value:function(D){return vr("action",D)}},{key:"defaultTarget",value:function(D){var Y=vr("target",D);if(Y)return document.querySelector(Y)}},{key:"defaultText",value:function(D){return vr("text",D)}},{key:"destroy",value:function(){this.listener.destroy()}}],[{key:"copy",value:function(D){var Y=arguments.length>1&&arguments[1]!==void 0?arguments[1]:{container:document.body};return J(D,Y)}},{key:"cut",value:function(D){return w(D)}},{key:"isSupported",value:function(){var D=arguments.length>0&&arguments[0]!==void 0?arguments[0]:["copy","cut"],Y=typeof D=="string"?[D]:D,ke=!!document.queryCommandSupported;return Y.forEach(function(Ut){ke=ke&&!!document.queryCommandSupported(Ut)}),ke}}]),O}(s()),Ii=Ri},828:function(o){var n=9;if(typeof Element!="undefined"&&!Element.prototype.matches){var i=Element.prototype;i.matches=i.matchesSelector||i.mozMatchesSelector||i.msMatchesSelector||i.oMatchesSelector||i.webkitMatchesSelector}function a(s,p){for(;s&&s.nodeType!==n;){if(typeof s.matches=="function"&&s.matches(p))return s;s=s.parentNode}}o.exports=a},438:function(o,n,i){var a=i(828);function s(l,f,u,h,w){var A=c.apply(this,arguments);return l.addEventListener(u,A,w),{destroy:function(){l.removeEventListener(u,A,w)}}}function p(l,f,u,h,w){return typeof l.addEventListener=="function"?s.apply(null,arguments):typeof u=="function"?s.bind(null,document).apply(null,arguments):(typeof l=="string"&&(l=document.querySelectorAll(l)),Array.prototype.map.call(l,function(A){return s(A,f,u,h,w)}))}function c(l,f,u,h){return function(w){w.delegateTarget=a(w.target,f),w.delegateTarget&&h.call(l,w)}}o.exports=p},879:function(o,n){n.node=function(i){return i!==void 0&&i instanceof HTMLElement&&i.nodeType===1},n.nodeList=function(i){var a=Object.prototype.toString.call(i);return i!==void 0&&(a==="[object NodeList]"||a==="[object HTMLCollection]")&&"length"in i&&(i.length===0||n.node(i[0]))},n.string=function(i){return typeof i=="string"||i instanceof String},n.fn=function(i){var a=Object.prototype.toString.call(i);return a==="[object Function]"}},370:function(o,n,i){var a=i(879),s=i(438);function p(u,h,w){if(!u&&!h&&!w)throw new Error("Missing required arguments");if(!a.string(h))throw new TypeError("Second argument must be a String");if(!a.fn(w))throw new TypeError("Third argument must be a Function");if(a.node(u))return c(u,h,w);if(a.nodeList(u))return l(u,h,w);if(a.string(u))return f(u,h,w);throw new TypeError("First argument must be a String, HTMLElement, HTMLCollection, or NodeList")}function c(u,h,w){return u.addEventListener(h,w),{destroy:function(){u.removeEventListener(h,w)}}}function l(u,h,w){return Array.prototype.forEach.call(u,function(A){A.addEventListener(h,w)}),{destroy:function(){Array.prototype.forEach.call(u,function(A){A.removeEventListener(h,w)})}}}function f(u,h,w){return s(document.body,u,h,w)}o.exports=p},817:function(o){function n(i){var a;if(i.nodeName==="SELECT")i.focus(),a=i.value;else if(i.nodeName==="INPUT"||i.nodeName==="TEXTAREA"){var s=i.hasAttribute("readonly");s||i.setAttribute("readonly",""),i.select(),i.setSelectionRange(0,i.value.length),s||i.removeAttribute("readonly"),a=i.value}else{i.hasAttribute("contenteditable")&&i.focus();var p=window.getSelection(),c=document.createRange();c.selectNodeContents(i),p.removeAllRanges(),p.addRange(c),a=p.toString()}return a}o.exports=n},279:function(o){function n(){}n.prototype={on:function(i,a,s){var p=this.e||(this.e={});return(p[i]||(p[i]=[])).push({fn:a,ctx:s}),this},once:function(i,a,s){var p=this;function c(){p.off(i,c),a.apply(s,arguments)}return c._=a,this.on(i,c,s)},emit:function(i){var a=[].slice.call(arguments,1),s=((this.e||(this.e={}))[i]||[]).slice(),p=0,c=s.length;for(p;p{"use strict";/*! + * escape-html + * Copyright(c) 2012-2013 TJ Holowaychuk + * Copyright(c) 2015 Andreas Lubbe + * Copyright(c) 2015 Tiancheng "Timothy" Gu + * MIT Licensed + */var ts=/["'&<>]/;ei.exports=rs;function rs(e){var t=""+e,r=ts.exec(t);if(!r)return t;var o,n="",i=0,a=0;for(i=r.index;i0&&i[i.length-1])&&(c[0]===6||c[0]===2)){r=0;continue}if(c[0]===3&&(!i||c[1]>i[0]&&c[1]=e.length&&(e=void 0),{value:e&&e[o++],done:!e}}};throw new TypeError(t?"Object is not iterable.":"Symbol.iterator is not defined.")}function N(e,t){var r=typeof Symbol=="function"&&e[Symbol.iterator];if(!r)return e;var o=r.call(e),n,i=[],a;try{for(;(t===void 0||t-- >0)&&!(n=o.next()).done;)i.push(n.value)}catch(s){a={error:s}}finally{try{n&&!n.done&&(r=o.return)&&r.call(o)}finally{if(a)throw a.error}}return i}function q(e,t,r){if(r||arguments.length===2)for(var o=0,n=t.length,i;o1||s(u,h)})})}function s(u,h){try{p(o[u](h))}catch(w){f(i[0][3],w)}}function p(u){u.value instanceof nt?Promise.resolve(u.value.v).then(c,l):f(i[0][2],u)}function c(u){s("next",u)}function l(u){s("throw",u)}function f(u,h){u(h),i.shift(),i.length&&s(i[0][0],i[0][1])}}function mo(e){if(!Symbol.asyncIterator)throw new TypeError("Symbol.asyncIterator is not defined.");var t=e[Symbol.asyncIterator],r;return t?t.call(e):(e=typeof de=="function"?de(e):e[Symbol.iterator](),r={},o("next"),o("throw"),o("return"),r[Symbol.asyncIterator]=function(){return this},r);function o(i){r[i]=e[i]&&function(a){return new Promise(function(s,p){a=e[i](a),n(s,p,a.done,a.value)})}}function n(i,a,s,p){Promise.resolve(p).then(function(c){i({value:c,done:s})},a)}}function k(e){return typeof e=="function"}function ft(e){var t=function(o){Error.call(o),o.stack=new Error().stack},r=e(t);return r.prototype=Object.create(Error.prototype),r.prototype.constructor=r,r}var zt=ft(function(e){return function(r){e(this),this.message=r?r.length+` errors occurred during unsubscription: +`+r.map(function(o,n){return n+1+") "+o.toString()}).join(` + `):"",this.name="UnsubscriptionError",this.errors=r}});function qe(e,t){if(e){var r=e.indexOf(t);0<=r&&e.splice(r,1)}}var Fe=function(){function e(t){this.initialTeardown=t,this.closed=!1,this._parentage=null,this._finalizers=null}return e.prototype.unsubscribe=function(){var t,r,o,n,i;if(!this.closed){this.closed=!0;var a=this._parentage;if(a)if(this._parentage=null,Array.isArray(a))try{for(var s=de(a),p=s.next();!p.done;p=s.next()){var c=p.value;c.remove(this)}}catch(A){t={error:A}}finally{try{p&&!p.done&&(r=s.return)&&r.call(s)}finally{if(t)throw t.error}}else a.remove(this);var l=this.initialTeardown;if(k(l))try{l()}catch(A){i=A instanceof zt?A.errors:[A]}var f=this._finalizers;if(f){this._finalizers=null;try{for(var u=de(f),h=u.next();!h.done;h=u.next()){var w=h.value;try{fo(w)}catch(A){i=i!=null?i:[],A instanceof zt?i=q(q([],N(i)),N(A.errors)):i.push(A)}}}catch(A){o={error:A}}finally{try{h&&!h.done&&(n=u.return)&&n.call(u)}finally{if(o)throw o.error}}}if(i)throw new zt(i)}},e.prototype.add=function(t){var r;if(t&&t!==this)if(this.closed)fo(t);else{if(t instanceof e){if(t.closed||t._hasParent(this))return;t._addParent(this)}(this._finalizers=(r=this._finalizers)!==null&&r!==void 0?r:[]).push(t)}},e.prototype._hasParent=function(t){var r=this._parentage;return r===t||Array.isArray(r)&&r.includes(t)},e.prototype._addParent=function(t){var r=this._parentage;this._parentage=Array.isArray(r)?(r.push(t),r):r?[r,t]:t},e.prototype._removeParent=function(t){var r=this._parentage;r===t?this._parentage=null:Array.isArray(r)&&qe(r,t)},e.prototype.remove=function(t){var r=this._finalizers;r&&qe(r,t),t instanceof e&&t._removeParent(this)},e.EMPTY=function(){var t=new e;return t.closed=!0,t}(),e}();var Tr=Fe.EMPTY;function qt(e){return e instanceof Fe||e&&"closed"in e&&k(e.remove)&&k(e.add)&&k(e.unsubscribe)}function fo(e){k(e)?e():e.unsubscribe()}var $e={onUnhandledError:null,onStoppedNotification:null,Promise:void 0,useDeprecatedSynchronousErrorHandling:!1,useDeprecatedNextContext:!1};var ut={setTimeout:function(e,t){for(var r=[],o=2;o0},enumerable:!1,configurable:!0}),t.prototype._trySubscribe=function(r){return this._throwIfClosed(),e.prototype._trySubscribe.call(this,r)},t.prototype._subscribe=function(r){return this._throwIfClosed(),this._checkFinalizedStatuses(r),this._innerSubscribe(r)},t.prototype._innerSubscribe=function(r){var o=this,n=this,i=n.hasError,a=n.isStopped,s=n.observers;return i||a?Tr:(this.currentObservers=null,s.push(r),new Fe(function(){o.currentObservers=null,qe(s,r)}))},t.prototype._checkFinalizedStatuses=function(r){var o=this,n=o.hasError,i=o.thrownError,a=o.isStopped;n?r.error(i):a&&r.complete()},t.prototype.asObservable=function(){var r=new F;return r.source=this,r},t.create=function(r,o){return new Eo(r,o)},t}(F);var Eo=function(e){re(t,e);function t(r,o){var n=e.call(this)||this;return n.destination=r,n.source=o,n}return t.prototype.next=function(r){var o,n;(n=(o=this.destination)===null||o===void 0?void 0:o.next)===null||n===void 0||n.call(o,r)},t.prototype.error=function(r){var o,n;(n=(o=this.destination)===null||o===void 0?void 0:o.error)===null||n===void 0||n.call(o,r)},t.prototype.complete=function(){var r,o;(o=(r=this.destination)===null||r===void 0?void 0:r.complete)===null||o===void 0||o.call(r)},t.prototype._subscribe=function(r){var o,n;return(n=(o=this.source)===null||o===void 0?void 0:o.subscribe(r))!==null&&n!==void 0?n:Tr},t}(g);var _r=function(e){re(t,e);function t(r){var o=e.call(this)||this;return o._value=r,o}return Object.defineProperty(t.prototype,"value",{get:function(){return this.getValue()},enumerable:!1,configurable:!0}),t.prototype._subscribe=function(r){var o=e.prototype._subscribe.call(this,r);return!o.closed&&r.next(this._value),o},t.prototype.getValue=function(){var r=this,o=r.hasError,n=r.thrownError,i=r._value;if(o)throw n;return this._throwIfClosed(),i},t.prototype.next=function(r){e.prototype.next.call(this,this._value=r)},t}(g);var Lt={now:function(){return(Lt.delegate||Date).now()},delegate:void 0};var _t=function(e){re(t,e);function t(r,o,n){r===void 0&&(r=1/0),o===void 0&&(o=1/0),n===void 0&&(n=Lt);var i=e.call(this)||this;return i._bufferSize=r,i._windowTime=o,i._timestampProvider=n,i._buffer=[],i._infiniteTimeWindow=!0,i._infiniteTimeWindow=o===1/0,i._bufferSize=Math.max(1,r),i._windowTime=Math.max(1,o),i}return t.prototype.next=function(r){var o=this,n=o.isStopped,i=o._buffer,a=o._infiniteTimeWindow,s=o._timestampProvider,p=o._windowTime;n||(i.push(r),!a&&i.push(s.now()+p)),this._trimBuffer(),e.prototype.next.call(this,r)},t.prototype._subscribe=function(r){this._throwIfClosed(),this._trimBuffer();for(var o=this._innerSubscribe(r),n=this,i=n._infiniteTimeWindow,a=n._buffer,s=a.slice(),p=0;p0?e.prototype.schedule.call(this,r,o):(this.delay=o,this.state=r,this.scheduler.flush(this),this)},t.prototype.execute=function(r,o){return o>0||this.closed?e.prototype.execute.call(this,r,o):this._execute(r,o)},t.prototype.requestAsyncId=function(r,o,n){return n===void 0&&(n=0),n!=null&&n>0||n==null&&this.delay>0?e.prototype.requestAsyncId.call(this,r,o,n):(r.flush(this),0)},t}(vt);var So=function(e){re(t,e);function t(){return e!==null&&e.apply(this,arguments)||this}return t}(gt);var Hr=new So(To);var Oo=function(e){re(t,e);function t(r,o){var n=e.call(this,r,o)||this;return n.scheduler=r,n.work=o,n}return t.prototype.requestAsyncId=function(r,o,n){return n===void 0&&(n=0),n!==null&&n>0?e.prototype.requestAsyncId.call(this,r,o,n):(r.actions.push(this),r._scheduled||(r._scheduled=bt.requestAnimationFrame(function(){return r.flush(void 0)})))},t.prototype.recycleAsyncId=function(r,o,n){var i;if(n===void 0&&(n=0),n!=null?n>0:this.delay>0)return e.prototype.recycleAsyncId.call(this,r,o,n);var a=r.actions;o!=null&&((i=a[a.length-1])===null||i===void 0?void 0:i.id)!==o&&(bt.cancelAnimationFrame(o),r._scheduled=void 0)},t}(vt);var Mo=function(e){re(t,e);function t(){return e!==null&&e.apply(this,arguments)||this}return t.prototype.flush=function(r){this._active=!0;var o=this._scheduled;this._scheduled=void 0;var n=this.actions,i;r=r||n.shift();do if(i=r.execute(r.state,r.delay))break;while((r=n[0])&&r.id===o&&n.shift());if(this._active=!1,i){for(;(r=n[0])&&r.id===o&&n.shift();)r.unsubscribe();throw i}},t}(gt);var me=new Mo(Oo);var M=new F(function(e){return e.complete()});function Yt(e){return e&&k(e.schedule)}function kr(e){return e[e.length-1]}function Xe(e){return k(kr(e))?e.pop():void 0}function He(e){return Yt(kr(e))?e.pop():void 0}function Bt(e,t){return typeof kr(e)=="number"?e.pop():t}var xt=function(e){return e&&typeof e.length=="number"&&typeof e!="function"};function Gt(e){return k(e==null?void 0:e.then)}function Jt(e){return k(e[ht])}function Xt(e){return Symbol.asyncIterator&&k(e==null?void 0:e[Symbol.asyncIterator])}function Zt(e){return new TypeError("You provided "+(e!==null&&typeof e=="object"?"an invalid object":"'"+e+"'")+" where a stream was expected. You can provide an Observable, Promise, ReadableStream, Array, AsyncIterable, or Iterable.")}function Gi(){return typeof Symbol!="function"||!Symbol.iterator?"@@iterator":Symbol.iterator}var er=Gi();function tr(e){return k(e==null?void 0:e[er])}function rr(e){return lo(this,arguments,function(){var r,o,n,i;return Nt(this,function(a){switch(a.label){case 0:r=e.getReader(),a.label=1;case 1:a.trys.push([1,,9,10]),a.label=2;case 2:return[4,nt(r.read())];case 3:return o=a.sent(),n=o.value,i=o.done,i?[4,nt(void 0)]:[3,5];case 4:return[2,a.sent()];case 5:return[4,nt(n)];case 6:return[4,a.sent()];case 7:return a.sent(),[3,2];case 8:return[3,10];case 9:return r.releaseLock(),[7];case 10:return[2]}})})}function or(e){return k(e==null?void 0:e.getReader)}function W(e){if(e instanceof F)return e;if(e!=null){if(Jt(e))return Ji(e);if(xt(e))return Xi(e);if(Gt(e))return Zi(e);if(Xt(e))return Lo(e);if(tr(e))return ea(e);if(or(e))return ta(e)}throw Zt(e)}function Ji(e){return new F(function(t){var r=e[ht]();if(k(r.subscribe))return r.subscribe(t);throw new TypeError("Provided object does not correctly implement Symbol.observable")})}function Xi(e){return new F(function(t){for(var r=0;r=2;return function(o){return o.pipe(e?b(function(n,i){return e(n,i,o)}):le,Te(1),r?Be(t):zo(function(){return new ir}))}}function Fr(e){return e<=0?function(){return M}:y(function(t,r){var o=[];t.subscribe(T(r,function(n){o.push(n),e=2,!0))}function pe(e){e===void 0&&(e={});var t=e.connector,r=t===void 0?function(){return new g}:t,o=e.resetOnError,n=o===void 0?!0:o,i=e.resetOnComplete,a=i===void 0?!0:i,s=e.resetOnRefCountZero,p=s===void 0?!0:s;return function(c){var l,f,u,h=0,w=!1,A=!1,te=function(){f==null||f.unsubscribe(),f=void 0},ie=function(){te(),l=u=void 0,w=A=!1},J=function(){var H=l;ie(),H==null||H.unsubscribe()};return y(function(H,mt){h++,!A&&!w&&te();var ze=u=u!=null?u:r();mt.add(function(){h--,h===0&&!A&&!w&&(f=Wr(J,p))}),ze.subscribe(mt),!l&&h>0&&(l=new at({next:function(Ie){return ze.next(Ie)},error:function(Ie){A=!0,te(),f=Wr(ie,n,Ie),ze.error(Ie)},complete:function(){w=!0,te(),f=Wr(ie,a),ze.complete()}}),W(H).subscribe(l))})(c)}}function Wr(e,t){for(var r=[],o=2;oe.next(document)),e}function $(e,t=document){return Array.from(t.querySelectorAll(e))}function P(e,t=document){let r=fe(e,t);if(typeof r=="undefined")throw new ReferenceError(`Missing element: expected "${e}" to be present`);return r}function fe(e,t=document){return t.querySelector(e)||void 0}function Re(){var e,t,r,o;return(o=(r=(t=(e=document.activeElement)==null?void 0:e.shadowRoot)==null?void 0:t.activeElement)!=null?r:document.activeElement)!=null?o:void 0}var xa=S(d(document.body,"focusin"),d(document.body,"focusout")).pipe(_e(1),Q(void 0),m(()=>Re()||document.body),B(1));function et(e){return xa.pipe(m(t=>e.contains(t)),K())}function kt(e,t){return C(()=>S(d(e,"mouseenter").pipe(m(()=>!0)),d(e,"mouseleave").pipe(m(()=>!1))).pipe(t?Ht(r=>Me(+!r*t)):le,Q(e.matches(":hover"))))}function Bo(e,t){if(typeof t=="string"||typeof t=="number")e.innerHTML+=t.toString();else if(t instanceof Node)e.appendChild(t);else if(Array.isArray(t))for(let r of t)Bo(e,r)}function x(e,t,...r){let o=document.createElement(e);if(t)for(let n of Object.keys(t))typeof t[n]!="undefined"&&(typeof t[n]!="boolean"?o.setAttribute(n,t[n]):o.setAttribute(n,""));for(let n of r)Bo(o,n);return o}function sr(e){if(e>999){let t=+((e-950)%1e3>99);return`${((e+1e-6)/1e3).toFixed(t)}k`}else return e.toString()}function wt(e){let t=x("script",{src:e});return C(()=>(document.head.appendChild(t),S(d(t,"load"),d(t,"error").pipe(v(()=>$r(()=>new ReferenceError(`Invalid script: ${e}`))))).pipe(m(()=>{}),L(()=>document.head.removeChild(t)),Te(1))))}var Go=new g,ya=C(()=>typeof ResizeObserver=="undefined"?wt("https://unpkg.com/resize-observer-polyfill"):I(void 0)).pipe(m(()=>new ResizeObserver(e=>e.forEach(t=>Go.next(t)))),v(e=>S(Ke,I(e)).pipe(L(()=>e.disconnect()))),B(1));function ce(e){return{width:e.offsetWidth,height:e.offsetHeight}}function ge(e){let t=e;for(;t.clientWidth===0&&t.parentElement;)t=t.parentElement;return ya.pipe(E(r=>r.observe(t)),v(r=>Go.pipe(b(o=>o.target===t),L(()=>r.unobserve(t)))),m(()=>ce(e)),Q(ce(e)))}function Tt(e){return{width:e.scrollWidth,height:e.scrollHeight}}function cr(e){let t=e.parentElement;for(;t&&(e.scrollWidth<=t.scrollWidth&&e.scrollHeight<=t.scrollHeight);)t=(e=t).parentElement;return t?e:void 0}function Jo(e){let t=[],r=e.parentElement;for(;r;)(e.clientWidth>r.clientWidth||e.clientHeight>r.clientHeight)&&t.push(r),r=(e=r).parentElement;return t.length===0&&t.push(document.documentElement),t}function Ue(e){return{x:e.offsetLeft,y:e.offsetTop}}function Xo(e){let t=e.getBoundingClientRect();return{x:t.x+window.scrollX,y:t.y+window.scrollY}}function Zo(e){return S(d(window,"load"),d(window,"resize")).pipe(Le(0,me),m(()=>Ue(e)),Q(Ue(e)))}function pr(e){return{x:e.scrollLeft,y:e.scrollTop}}function De(e){return S(d(e,"scroll"),d(window,"scroll"),d(window,"resize")).pipe(Le(0,me),m(()=>pr(e)),Q(pr(e)))}var en=new g,Ea=C(()=>I(new IntersectionObserver(e=>{for(let t of e)en.next(t)},{threshold:0}))).pipe(v(e=>S(Ke,I(e)).pipe(L(()=>e.disconnect()))),B(1));function tt(e){return Ea.pipe(E(t=>t.observe(e)),v(t=>en.pipe(b(({target:r})=>r===e),L(()=>t.unobserve(e)),m(({isIntersecting:r})=>r))))}function tn(e,t=16){return De(e).pipe(m(({y:r})=>{let o=ce(e),n=Tt(e);return r>=n.height-o.height-t}),K())}var lr={drawer:P("[data-md-toggle=drawer]"),search:P("[data-md-toggle=search]")};function rn(e){return lr[e].checked}function Je(e,t){lr[e].checked!==t&&lr[e].click()}function Ve(e){let t=lr[e];return d(t,"change").pipe(m(()=>t.checked),Q(t.checked))}function wa(e,t){switch(e.constructor){case HTMLInputElement:return e.type==="radio"?/^Arrow/.test(t):!0;case HTMLSelectElement:case HTMLTextAreaElement:return!0;default:return e.isContentEditable}}function Ta(){return S(d(window,"compositionstart").pipe(m(()=>!0)),d(window,"compositionend").pipe(m(()=>!1))).pipe(Q(!1))}function on(){let e=d(window,"keydown").pipe(b(t=>!(t.metaKey||t.ctrlKey)),m(t=>({mode:rn("search")?"search":"global",type:t.key,claim(){t.preventDefault(),t.stopPropagation()}})),b(({mode:t,type:r})=>{if(t==="global"){let o=Re();if(typeof o!="undefined")return!wa(o,r)}return!0}),pe());return Ta().pipe(v(t=>t?M:e))}function xe(){return new URL(location.href)}function pt(e,t=!1){if(G("navigation.instant")&&!t){let r=x("a",{href:e.href});document.body.appendChild(r),r.click(),r.remove()}else location.href=e.href}function nn(){return new g}function an(){return location.hash.slice(1)}function sn(e){let t=x("a",{href:e});t.addEventListener("click",r=>r.stopPropagation()),t.click()}function Sa(e){return S(d(window,"hashchange"),e).pipe(m(an),Q(an()),b(t=>t.length>0),B(1))}function cn(e){return Sa(e).pipe(m(t=>fe(`[id="${t}"]`)),b(t=>typeof t!="undefined"))}function $t(e){let t=matchMedia(e);return ar(r=>t.addListener(()=>r(t.matches))).pipe(Q(t.matches))}function pn(){let e=matchMedia("print");return S(d(window,"beforeprint").pipe(m(()=>!0)),d(window,"afterprint").pipe(m(()=>!1))).pipe(Q(e.matches))}function Nr(e,t){return e.pipe(v(r=>r?t():M))}function zr(e,t){return new F(r=>{let o=new XMLHttpRequest;return o.open("GET",`${e}`),o.responseType="blob",o.addEventListener("load",()=>{o.status>=200&&o.status<300?(r.next(o.response),r.complete()):r.error(new Error(o.statusText))}),o.addEventListener("error",()=>{r.error(new Error("Network error"))}),o.addEventListener("abort",()=>{r.complete()}),typeof(t==null?void 0:t.progress$)!="undefined"&&(o.addEventListener("progress",n=>{var i;if(n.lengthComputable)t.progress$.next(n.loaded/n.total*100);else{let a=(i=o.getResponseHeader("Content-Length"))!=null?i:0;t.progress$.next(n.loaded/+a*100)}}),t.progress$.next(5)),o.send(),()=>o.abort()})}function Ne(e,t){return zr(e,t).pipe(v(r=>r.text()),m(r=>JSON.parse(r)),B(1))}function ln(e,t){let r=new DOMParser;return zr(e,t).pipe(v(o=>o.text()),m(o=>r.parseFromString(o,"text/html")),B(1))}function mn(e,t){let r=new DOMParser;return zr(e,t).pipe(v(o=>o.text()),m(o=>r.parseFromString(o,"text/xml")),B(1))}function fn(){return{x:Math.max(0,scrollX),y:Math.max(0,scrollY)}}function un(){return S(d(window,"scroll",{passive:!0}),d(window,"resize",{passive:!0})).pipe(m(fn),Q(fn()))}function dn(){return{width:innerWidth,height:innerHeight}}function hn(){return d(window,"resize",{passive:!0}).pipe(m(dn),Q(dn()))}function bn(){return z([un(),hn()]).pipe(m(([e,t])=>({offset:e,size:t})),B(1))}function mr(e,{viewport$:t,header$:r}){let o=t.pipe(Z("size")),n=z([o,r]).pipe(m(()=>Ue(e)));return z([r,t,n]).pipe(m(([{height:i},{offset:a,size:s},{x:p,y:c}])=>({offset:{x:a.x-p,y:a.y-c+i},size:s})))}function Oa(e){return d(e,"message",t=>t.data)}function Ma(e){let t=new g;return t.subscribe(r=>e.postMessage(r)),t}function vn(e,t=new Worker(e)){let r=Oa(t),o=Ma(t),n=new g;n.subscribe(o);let i=o.pipe(X(),ne(!0));return n.pipe(X(),Pe(r.pipe(U(i))),pe())}var La=P("#__config"),St=JSON.parse(La.textContent);St.base=`${new URL(St.base,xe())}`;function ye(){return St}function G(e){return St.features.includes(e)}function Ee(e,t){return typeof t!="undefined"?St.translations[e].replace("#",t.toString()):St.translations[e]}function Se(e,t=document){return P(`[data-md-component=${e}]`,t)}function ae(e,t=document){return $(`[data-md-component=${e}]`,t)}function _a(e){let t=P(".md-typeset > :first-child",e);return d(t,"click",{once:!0}).pipe(m(()=>P(".md-typeset",e)),m(r=>({hash:__md_hash(r.innerHTML)})))}function gn(e){if(!G("announce.dismiss")||!e.childElementCount)return M;if(!e.hidden){let t=P(".md-typeset",e);__md_hash(t.innerHTML)===__md_get("__announce")&&(e.hidden=!0)}return C(()=>{let t=new g;return t.subscribe(({hash:r})=>{e.hidden=!0,__md_set("__announce",r)}),_a(e).pipe(E(r=>t.next(r)),L(()=>t.complete()),m(r=>R({ref:e},r)))})}function Aa(e,{target$:t}){return t.pipe(m(r=>({hidden:r!==e})))}function xn(e,t){let r=new g;return r.subscribe(({hidden:o})=>{e.hidden=o}),Aa(e,t).pipe(E(o=>r.next(o)),L(()=>r.complete()),m(o=>R({ref:e},o)))}function Pt(e,t){return t==="inline"?x("div",{class:"md-tooltip md-tooltip--inline",id:e,role:"tooltip"},x("div",{class:"md-tooltip__inner md-typeset"})):x("div",{class:"md-tooltip",id:e,role:"tooltip"},x("div",{class:"md-tooltip__inner md-typeset"}))}function yn(...e){return x("div",{class:"md-tooltip2",role:"tooltip"},x("div",{class:"md-tooltip2__inner md-typeset"},e))}function En(e,t){if(t=t?`${t}_annotation_${e}`:void 0,t){let r=t?`#${t}`:void 0;return x("aside",{class:"md-annotation",tabIndex:0},Pt(t),x("a",{href:r,class:"md-annotation__index",tabIndex:-1},x("span",{"data-md-annotation-id":e})))}else return x("aside",{class:"md-annotation",tabIndex:0},Pt(t),x("span",{class:"md-annotation__index",tabIndex:-1},x("span",{"data-md-annotation-id":e})))}function wn(e){return x("button",{class:"md-clipboard md-icon",title:Ee("clipboard.copy"),"data-clipboard-target":`#${e} > code`})}function qr(e,t){let r=t&2,o=t&1,n=Object.keys(e.terms).filter(p=>!e.terms[p]).reduce((p,c)=>[...p,x("del",null,c)," "],[]).slice(0,-1),i=ye(),a=new URL(e.location,i.base);G("search.highlight")&&a.searchParams.set("h",Object.entries(e.terms).filter(([,p])=>p).reduce((p,[c])=>`${p} ${c}`.trim(),""));let{tags:s}=ye();return x("a",{href:`${a}`,class:"md-search-result__link",tabIndex:-1},x("article",{class:"md-search-result__article md-typeset","data-md-score":e.score.toFixed(2)},r>0&&x("div",{class:"md-search-result__icon md-icon"}),r>0&&x("h1",null,e.title),r<=0&&x("h2",null,e.title),o>0&&e.text.length>0&&e.text,e.tags&&e.tags.map(p=>{let c=s?p in s?`md-tag-icon md-tag--${s[p]}`:"md-tag-icon":"";return x("span",{class:`md-tag ${c}`},p)}),o>0&&n.length>0&&x("p",{class:"md-search-result__terms"},Ee("search.result.term.missing"),": ",...n)))}function Tn(e){let t=e[0].score,r=[...e],o=ye(),n=r.findIndex(l=>!`${new URL(l.location,o.base)}`.includes("#")),[i]=r.splice(n,1),a=r.findIndex(l=>l.scoreqr(l,1)),...p.length?[x("details",{class:"md-search-result__more"},x("summary",{tabIndex:-1},x("div",null,p.length>0&&p.length===1?Ee("search.result.more.one"):Ee("search.result.more.other",p.length))),...p.map(l=>qr(l,1)))]:[]];return x("li",{class:"md-search-result__item"},c)}function Sn(e){return x("ul",{class:"md-source__facts"},Object.entries(e).map(([t,r])=>x("li",{class:`md-source__fact md-source__fact--${t}`},typeof r=="number"?sr(r):r)))}function Qr(e){let t=`tabbed-control tabbed-control--${e}`;return x("div",{class:t,hidden:!0},x("button",{class:"tabbed-button",tabIndex:-1,"aria-hidden":"true"}))}function On(e){return x("div",{class:"md-typeset__scrollwrap"},x("div",{class:"md-typeset__table"},e))}function Ca(e){var o;let t=ye(),r=new URL(`../${e.version}/`,t.base);return x("li",{class:"md-version__item"},x("a",{href:`${r}`,class:"md-version__link"},e.title,((o=t.version)==null?void 0:o.alias)&&e.aliases.length>0&&x("span",{class:"md-version__alias"},e.aliases[0])))}function Mn(e,t){var o;let r=ye();return e=e.filter(n=>{var i;return!((i=n.properties)!=null&&i.hidden)}),x("div",{class:"md-version"},x("button",{class:"md-version__current","aria-label":Ee("select.version")},t.title,((o=r.version)==null?void 0:o.alias)&&t.aliases.length>0&&x("span",{class:"md-version__alias"},t.aliases[0])),x("ul",{class:"md-version__list"},e.map(Ca)))}var Ha=0;function ka(e){let t=z([et(e),kt(e)]).pipe(m(([o,n])=>o||n),K()),r=C(()=>Jo(e)).pipe(oe(De),ct(1),m(()=>Xo(e)));return t.pipe(Ae(o=>o),v(()=>z([t,r])),m(([o,n])=>({active:o,offset:n})),pe())}function $a(e,t){let{content$:r,viewport$:o}=t,n=`__tooltip2_${Ha++}`;return C(()=>{let i=new g,a=new _r(!1);i.pipe(X(),ne(!1)).subscribe(a);let s=a.pipe(Ht(c=>Me(+!c*250,Hr)),K(),v(c=>c?r:M),E(c=>c.id=n),pe());z([i.pipe(m(({active:c})=>c)),s.pipe(v(c=>kt(c,250)),Q(!1))]).pipe(m(c=>c.some(l=>l))).subscribe(a);let p=a.pipe(b(c=>c),ee(s,o),m(([c,l,{size:f}])=>{let u=e.getBoundingClientRect(),h=u.width/2;if(l.role==="tooltip")return{x:h,y:8+u.height};if(u.y>=f.height/2){let{height:w}=ce(l);return{x:h,y:-16-w}}else return{x:h,y:16+u.height}}));return z([s,i,p]).subscribe(([c,{offset:l},f])=>{c.style.setProperty("--md-tooltip-host-x",`${l.x}px`),c.style.setProperty("--md-tooltip-host-y",`${l.y}px`),c.style.setProperty("--md-tooltip-x",`${f.x}px`),c.style.setProperty("--md-tooltip-y",`${f.y}px`),c.classList.toggle("md-tooltip2--top",f.y<0),c.classList.toggle("md-tooltip2--bottom",f.y>=0)}),a.pipe(b(c=>c),ee(s,(c,l)=>l),b(c=>c.role==="tooltip")).subscribe(c=>{let l=ce(P(":scope > *",c));c.style.setProperty("--md-tooltip-width",`${l.width}px`),c.style.setProperty("--md-tooltip-tail","0px")}),a.pipe(K(),be(me),ee(s)).subscribe(([c,l])=>{l.classList.toggle("md-tooltip2--active",c)}),z([a.pipe(b(c=>c)),s]).subscribe(([c,l])=>{l.role==="dialog"?(e.setAttribute("aria-controls",n),e.setAttribute("aria-haspopup","dialog")):e.setAttribute("aria-describedby",n)}),a.pipe(b(c=>!c)).subscribe(()=>{e.removeAttribute("aria-controls"),e.removeAttribute("aria-describedby"),e.removeAttribute("aria-haspopup")}),ka(e).pipe(E(c=>i.next(c)),L(()=>i.complete()),m(c=>R({ref:e},c)))})}function lt(e,{viewport$:t},r=document.body){return $a(e,{content$:new F(o=>{let n=e.title,i=yn(n);return o.next(i),e.removeAttribute("title"),r.append(i),()=>{i.remove(),e.setAttribute("title",n)}}),viewport$:t})}function Pa(e,t){let r=C(()=>z([Zo(e),De(t)])).pipe(m(([{x:o,y:n},i])=>{let{width:a,height:s}=ce(e);return{x:o-i.x+a/2,y:n-i.y+s/2}}));return et(e).pipe(v(o=>r.pipe(m(n=>({active:o,offset:n})),Te(+!o||1/0))))}function Ln(e,t,{target$:r}){let[o,n]=Array.from(e.children);return C(()=>{let i=new g,a=i.pipe(X(),ne(!0));return i.subscribe({next({offset:s}){e.style.setProperty("--md-tooltip-x",`${s.x}px`),e.style.setProperty("--md-tooltip-y",`${s.y}px`)},complete(){e.style.removeProperty("--md-tooltip-x"),e.style.removeProperty("--md-tooltip-y")}}),tt(e).pipe(U(a)).subscribe(s=>{e.toggleAttribute("data-md-visible",s)}),S(i.pipe(b(({active:s})=>s)),i.pipe(_e(250),b(({active:s})=>!s))).subscribe({next({active:s}){s?e.prepend(o):o.remove()},complete(){e.prepend(o)}}),i.pipe(Le(16,me)).subscribe(({active:s})=>{o.classList.toggle("md-tooltip--active",s)}),i.pipe(ct(125,me),b(()=>!!e.offsetParent),m(()=>e.offsetParent.getBoundingClientRect()),m(({x:s})=>s)).subscribe({next(s){s?e.style.setProperty("--md-tooltip-0",`${-s}px`):e.style.removeProperty("--md-tooltip-0")},complete(){e.style.removeProperty("--md-tooltip-0")}}),d(n,"click").pipe(U(a),b(s=>!(s.metaKey||s.ctrlKey))).subscribe(s=>{s.stopPropagation(),s.preventDefault()}),d(n,"mousedown").pipe(U(a),ee(i)).subscribe(([s,{active:p}])=>{var c;if(s.button!==0||s.metaKey||s.ctrlKey)s.preventDefault();else if(p){s.preventDefault();let l=e.parentElement.closest(".md-annotation");l instanceof HTMLElement?l.focus():(c=Re())==null||c.blur()}}),r.pipe(U(a),b(s=>s===o),Ge(125)).subscribe(()=>e.focus()),Pa(e,t).pipe(E(s=>i.next(s)),L(()=>i.complete()),m(s=>R({ref:e},s)))})}function Ra(e){return e.tagName==="CODE"?$(".c, .c1, .cm",e):[e]}function Ia(e){let t=[];for(let r of Ra(e)){let o=[],n=document.createNodeIterator(r,NodeFilter.SHOW_TEXT);for(let i=n.nextNode();i;i=n.nextNode())o.push(i);for(let i of o){let a;for(;a=/(\(\d+\))(!)?/.exec(i.textContent);){let[,s,p]=a;if(typeof p=="undefined"){let c=i.splitText(a.index);i=c.splitText(s.length),t.push(c)}else{i.textContent=s,t.push(i);break}}}}return t}function _n(e,t){t.append(...Array.from(e.childNodes))}function fr(e,t,{target$:r,print$:o}){let n=t.closest("[id]"),i=n==null?void 0:n.id,a=new Map;for(let s of Ia(t)){let[,p]=s.textContent.match(/\((\d+)\)/);fe(`:scope > li:nth-child(${p})`,e)&&(a.set(p,En(p,i)),s.replaceWith(a.get(p)))}return a.size===0?M:C(()=>{let s=new g,p=s.pipe(X(),ne(!0)),c=[];for(let[l,f]of a)c.push([P(".md-typeset",f),P(`:scope > li:nth-child(${l})`,e)]);return o.pipe(U(p)).subscribe(l=>{e.hidden=!l,e.classList.toggle("md-annotation-list",l);for(let[f,u]of c)l?_n(f,u):_n(u,f)}),S(...[...a].map(([,l])=>Ln(l,t,{target$:r}))).pipe(L(()=>s.complete()),pe())})}function An(e){if(e.nextElementSibling){let t=e.nextElementSibling;if(t.tagName==="OL")return t;if(t.tagName==="P"&&!t.children.length)return An(t)}}function Cn(e,t){return C(()=>{let r=An(e);return typeof r!="undefined"?fr(r,e,t):M})}var Hn=Vt(Yr());var Fa=0;function kn(e){if(e.nextElementSibling){let t=e.nextElementSibling;if(t.tagName==="OL")return t;if(t.tagName==="P"&&!t.children.length)return kn(t)}}function ja(e){return ge(e).pipe(m(({width:t})=>({scrollable:Tt(e).width>t})),Z("scrollable"))}function $n(e,t){let{matches:r}=matchMedia("(hover)"),o=C(()=>{let n=new g,i=n.pipe(Fr(1));n.subscribe(({scrollable:c})=>{c&&r?e.setAttribute("tabindex","0"):e.removeAttribute("tabindex")});let a=[];if(Hn.default.isSupported()&&(e.closest(".copy")||G("content.code.copy")&&!e.closest(".no-copy"))){let c=e.closest("pre");c.id=`__code_${Fa++}`;let l=wn(c.id);c.insertBefore(l,e),G("content.tooltips")&&a.push(lt(l,{viewport$}))}let s=e.closest(".highlight");if(s instanceof HTMLElement){let c=kn(s);if(typeof c!="undefined"&&(s.classList.contains("annotate")||G("content.code.annotate"))){let l=fr(c,e,t);a.push(ge(s).pipe(U(i),m(({width:f,height:u})=>f&&u),K(),v(f=>f?l:M)))}}return $(":scope > span[id]",e).length&&e.classList.add("md-code__content"),ja(e).pipe(E(c=>n.next(c)),L(()=>n.complete()),m(c=>R({ref:e},c)),Pe(...a))});return G("content.lazy")?tt(e).pipe(b(n=>n),Te(1),v(()=>o)):o}function Wa(e,{target$:t,print$:r}){let o=!0;return S(t.pipe(m(n=>n.closest("details:not([open])")),b(n=>e===n),m(()=>({action:"open",reveal:!0}))),r.pipe(b(n=>n||!o),E(()=>o=e.open),m(n=>({action:n?"open":"close"}))))}function Pn(e,t){return C(()=>{let r=new g;return r.subscribe(({action:o,reveal:n})=>{e.toggleAttribute("open",o==="open"),n&&e.scrollIntoView()}),Wa(e,t).pipe(E(o=>r.next(o)),L(()=>r.complete()),m(o=>R({ref:e},o)))})}var Rn=".node circle,.node ellipse,.node path,.node polygon,.node rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}marker{fill:var(--md-mermaid-edge-color)!important}.edgeLabel .label rect{fill:#0000}.label{color:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.label foreignObject{line-height:normal;overflow:visible}.label div .edgeLabel{color:var(--md-mermaid-label-fg-color)}.edgeLabel,.edgeLabel rect,.label div .edgeLabel{background-color:var(--md-mermaid-label-bg-color)}.edgeLabel,.edgeLabel rect{fill:var(--md-mermaid-label-bg-color);color:var(--md-mermaid-edge-color)}.edgePath .path,.flowchart-link{stroke:var(--md-mermaid-edge-color);stroke-width:.05rem}.edgePath .arrowheadPath{fill:var(--md-mermaid-edge-color);stroke:none}.cluster rect{fill:var(--md-default-fg-color--lightest);stroke:var(--md-default-fg-color--lighter)}.cluster span{color:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}g #flowchart-circleEnd,g #flowchart-circleStart,g #flowchart-crossEnd,g #flowchart-crossStart,g #flowchart-pointEnd,g #flowchart-pointStart{stroke:none}g.classGroup line,g.classGroup rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}g.classGroup text{fill:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.classLabel .box{fill:var(--md-mermaid-label-bg-color);background-color:var(--md-mermaid-label-bg-color);opacity:1}.classLabel .label{fill:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.node .divider{stroke:var(--md-mermaid-node-fg-color)}.relation{stroke:var(--md-mermaid-edge-color)}.cardinality{fill:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.cardinality text{fill:inherit!important}defs #classDiagram-compositionEnd,defs #classDiagram-compositionStart,defs #classDiagram-dependencyEnd,defs #classDiagram-dependencyStart,defs #classDiagram-extensionEnd,defs #classDiagram-extensionStart{fill:var(--md-mermaid-edge-color)!important;stroke:var(--md-mermaid-edge-color)!important}defs #classDiagram-aggregationEnd,defs #classDiagram-aggregationStart{fill:var(--md-mermaid-label-bg-color)!important;stroke:var(--md-mermaid-edge-color)!important}g.stateGroup rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}g.stateGroup .state-title{fill:var(--md-mermaid-label-fg-color)!important;font-family:var(--md-mermaid-font-family)}g.stateGroup .composit{fill:var(--md-mermaid-label-bg-color)}.nodeLabel,.nodeLabel p{color:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}a .nodeLabel{text-decoration:underline}.node circle.state-end,.node circle.state-start,.start-state{fill:var(--md-mermaid-edge-color);stroke:none}.end-state-inner,.end-state-outer{fill:var(--md-mermaid-edge-color)}.end-state-inner,.node circle.state-end{stroke:var(--md-mermaid-label-bg-color)}.transition{stroke:var(--md-mermaid-edge-color)}[id^=state-fork] rect,[id^=state-join] rect{fill:var(--md-mermaid-edge-color)!important;stroke:none!important}.statediagram-cluster.statediagram-cluster .inner{fill:var(--md-default-bg-color)}.statediagram-cluster rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}.statediagram-state rect.divider{fill:var(--md-default-fg-color--lightest);stroke:var(--md-default-fg-color--lighter)}defs #statediagram-barbEnd{stroke:var(--md-mermaid-edge-color)}.attributeBoxEven,.attributeBoxOdd{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}.entityBox{fill:var(--md-mermaid-label-bg-color);stroke:var(--md-mermaid-node-fg-color)}.entityLabel{fill:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.relationshipLabelBox{fill:var(--md-mermaid-label-bg-color);fill-opacity:1;background-color:var(--md-mermaid-label-bg-color);opacity:1}.relationshipLabel{fill:var(--md-mermaid-label-fg-color)}.relationshipLine{stroke:var(--md-mermaid-edge-color)}defs #ONE_OR_MORE_END *,defs #ONE_OR_MORE_START *,defs #ONLY_ONE_END *,defs #ONLY_ONE_START *,defs #ZERO_OR_MORE_END *,defs #ZERO_OR_MORE_START *,defs #ZERO_OR_ONE_END *,defs #ZERO_OR_ONE_START *{stroke:var(--md-mermaid-edge-color)!important}defs #ZERO_OR_MORE_END circle,defs #ZERO_OR_MORE_START circle{fill:var(--md-mermaid-label-bg-color)}.actor{fill:var(--md-mermaid-sequence-actor-bg-color);stroke:var(--md-mermaid-sequence-actor-border-color)}text.actor>tspan{fill:var(--md-mermaid-sequence-actor-fg-color);font-family:var(--md-mermaid-font-family)}line{stroke:var(--md-mermaid-sequence-actor-line-color)}.actor-man circle,.actor-man line{fill:var(--md-mermaid-sequence-actorman-bg-color);stroke:var(--md-mermaid-sequence-actorman-line-color)}.messageLine0,.messageLine1{stroke:var(--md-mermaid-sequence-message-line-color)}.note{fill:var(--md-mermaid-sequence-note-bg-color);stroke:var(--md-mermaid-sequence-note-border-color)}.loopText,.loopText>tspan,.messageText,.noteText>tspan{stroke:none;font-family:var(--md-mermaid-font-family)!important}.messageText{fill:var(--md-mermaid-sequence-message-fg-color)}.loopText,.loopText>tspan{fill:var(--md-mermaid-sequence-loop-fg-color)}.noteText>tspan{fill:var(--md-mermaid-sequence-note-fg-color)}#arrowhead path{fill:var(--md-mermaid-sequence-message-line-color);stroke:none}.loopLine{fill:var(--md-mermaid-sequence-loop-bg-color);stroke:var(--md-mermaid-sequence-loop-border-color)}.labelBox{fill:var(--md-mermaid-sequence-label-bg-color);stroke:none}.labelText,.labelText>span{fill:var(--md-mermaid-sequence-label-fg-color);font-family:var(--md-mermaid-font-family)}.sequenceNumber{fill:var(--md-mermaid-sequence-number-fg-color)}rect.rect{fill:var(--md-mermaid-sequence-box-bg-color);stroke:none}rect.rect+text.text{fill:var(--md-mermaid-sequence-box-fg-color)}defs #sequencenumber{fill:var(--md-mermaid-sequence-number-bg-color)!important}";var Br,Da=0;function Va(){return typeof mermaid=="undefined"||mermaid instanceof Element?wt("https://unpkg.com/mermaid@10/dist/mermaid.min.js"):I(void 0)}function In(e){return e.classList.remove("mermaid"),Br||(Br=Va().pipe(E(()=>mermaid.initialize({startOnLoad:!1,themeCSS:Rn,sequence:{actorFontSize:"16px",messageFontSize:"16px",noteFontSize:"16px"}})),m(()=>{}),B(1))),Br.subscribe(()=>ao(this,null,function*(){e.classList.add("mermaid");let t=`__mermaid_${Da++}`,r=x("div",{class:"mermaid"}),o=e.textContent,{svg:n,fn:i}=yield mermaid.render(t,o),a=r.attachShadow({mode:"closed"});a.innerHTML=n,e.replaceWith(r),i==null||i(a)})),Br.pipe(m(()=>({ref:e})))}var Fn=x("table");function jn(e){return e.replaceWith(Fn),Fn.replaceWith(On(e)),I({ref:e})}function Na(e){let t=e.find(r=>r.checked)||e[0];return S(...e.map(r=>d(r,"change").pipe(m(()=>P(`label[for="${r.id}"]`))))).pipe(Q(P(`label[for="${t.id}"]`)),m(r=>({active:r})))}function Wn(e,{viewport$:t,target$:r}){let o=P(".tabbed-labels",e),n=$(":scope > input",e),i=Qr("prev");e.append(i);let a=Qr("next");return e.append(a),C(()=>{let s=new g,p=s.pipe(X(),ne(!0));z([s,ge(e),tt(e)]).pipe(U(p),Le(1,me)).subscribe({next([{active:c},l]){let f=Ue(c),{width:u}=ce(c);e.style.setProperty("--md-indicator-x",`${f.x}px`),e.style.setProperty("--md-indicator-width",`${u}px`);let h=pr(o);(f.xh.x+l.width)&&o.scrollTo({left:Math.max(0,f.x-16),behavior:"smooth"})},complete(){e.style.removeProperty("--md-indicator-x"),e.style.removeProperty("--md-indicator-width")}}),z([De(o),ge(o)]).pipe(U(p)).subscribe(([c,l])=>{let f=Tt(o);i.hidden=c.x<16,a.hidden=c.x>f.width-l.width-16}),S(d(i,"click").pipe(m(()=>-1)),d(a,"click").pipe(m(()=>1))).pipe(U(p)).subscribe(c=>{let{width:l}=ce(o);o.scrollBy({left:l*c,behavior:"smooth"})}),r.pipe(U(p),b(c=>n.includes(c))).subscribe(c=>c.click()),o.classList.add("tabbed-labels--linked");for(let c of n){let l=P(`label[for="${c.id}"]`);l.replaceChildren(x("a",{href:`#${l.htmlFor}`,tabIndex:-1},...Array.from(l.childNodes))),d(l.firstElementChild,"click").pipe(U(p),b(f=>!(f.metaKey||f.ctrlKey)),E(f=>{f.preventDefault(),f.stopPropagation()})).subscribe(()=>{history.replaceState({},"",`#${l.htmlFor}`),l.click()})}return G("content.tabs.link")&&s.pipe(Ce(1),ee(t)).subscribe(([{active:c},{offset:l}])=>{let f=c.innerText.trim();if(c.hasAttribute("data-md-switching"))c.removeAttribute("data-md-switching");else{let u=e.offsetTop-l.y;for(let w of $("[data-tabs]"))for(let A of $(":scope > input",w)){let te=P(`label[for="${A.id}"]`);if(te!==c&&te.innerText.trim()===f){te.setAttribute("data-md-switching",""),A.click();break}}window.scrollTo({top:e.offsetTop-u});let h=__md_get("__tabs")||[];__md_set("__tabs",[...new Set([f,...h])])}}),s.pipe(U(p)).subscribe(()=>{for(let c of $("audio, video",e))c.pause()}),Na(n).pipe(E(c=>s.next(c)),L(()=>s.complete()),m(c=>R({ref:e},c)))}).pipe(Qe(se))}function Un(e,{viewport$:t,target$:r,print$:o}){return S(...$(".annotate:not(.highlight)",e).map(n=>Cn(n,{target$:r,print$:o})),...$("pre:not(.mermaid) > code",e).map(n=>$n(n,{target$:r,print$:o})),...$("pre.mermaid",e).map(n=>In(n)),...$("table:not([class])",e).map(n=>jn(n)),...$("details",e).map(n=>Pn(n,{target$:r,print$:o})),...$("[data-tabs]",e).map(n=>Wn(n,{viewport$:t,target$:r})),...$("[title]",e).filter(()=>G("content.tooltips")).map(n=>lt(n,{viewport$:t})))}function za(e,{alert$:t}){return t.pipe(v(r=>S(I(!0),I(!1).pipe(Ge(2e3))).pipe(m(o=>({message:r,active:o})))))}function Dn(e,t){let r=P(".md-typeset",e);return C(()=>{let o=new g;return o.subscribe(({message:n,active:i})=>{e.classList.toggle("md-dialog--active",i),r.textContent=n}),za(e,t).pipe(E(n=>o.next(n)),L(()=>o.complete()),m(n=>R({ref:e},n)))})}var qa=0;function Qa(e,t){document.body.append(e);let{width:r}=ce(e);e.style.setProperty("--md-tooltip-width",`${r}px`),e.remove();let o=cr(t),n=typeof o!="undefined"?De(o):I({x:0,y:0}),i=S(et(t),kt(t)).pipe(K());return z([i,n]).pipe(m(([a,s])=>{let{x:p,y:c}=Ue(t),l=ce(t),f=t.closest("table");return f&&t.parentElement&&(p+=f.offsetLeft+t.parentElement.offsetLeft,c+=f.offsetTop+t.parentElement.offsetTop),{active:a,offset:{x:p-s.x+l.width/2-r/2,y:c-s.y+l.height+8}}}))}function Vn(e){let t=e.title;if(!t.length)return M;let r=`__tooltip_${qa++}`,o=Pt(r,"inline"),n=P(".md-typeset",o);return n.innerHTML=t,C(()=>{let i=new g;return i.subscribe({next({offset:a}){o.style.setProperty("--md-tooltip-x",`${a.x}px`),o.style.setProperty("--md-tooltip-y",`${a.y}px`)},complete(){o.style.removeProperty("--md-tooltip-x"),o.style.removeProperty("--md-tooltip-y")}}),S(i.pipe(b(({active:a})=>a)),i.pipe(_e(250),b(({active:a})=>!a))).subscribe({next({active:a}){a?(e.insertAdjacentElement("afterend",o),e.setAttribute("aria-describedby",r),e.removeAttribute("title")):(o.remove(),e.removeAttribute("aria-describedby"),e.setAttribute("title",t))},complete(){o.remove(),e.removeAttribute("aria-describedby"),e.setAttribute("title",t)}}),i.pipe(Le(16,me)).subscribe(({active:a})=>{o.classList.toggle("md-tooltip--active",a)}),i.pipe(ct(125,me),b(()=>!!e.offsetParent),m(()=>e.offsetParent.getBoundingClientRect()),m(({x:a})=>a)).subscribe({next(a){a?o.style.setProperty("--md-tooltip-0",`${-a}px`):o.style.removeProperty("--md-tooltip-0")},complete(){o.style.removeProperty("--md-tooltip-0")}}),Qa(o,e).pipe(E(a=>i.next(a)),L(()=>i.complete()),m(a=>R({ref:e},a)))}).pipe(Qe(se))}function Ka({viewport$:e}){if(!G("header.autohide"))return I(!1);let t=e.pipe(m(({offset:{y:n}})=>n),Ye(2,1),m(([n,i])=>[nMath.abs(i-n.y)>100),m(([,[n]])=>n),K()),o=Ve("search");return z([e,o]).pipe(m(([{offset:n},i])=>n.y>400&&!i),K(),v(n=>n?r:I(!1)),Q(!1))}function Nn(e,t){return C(()=>z([ge(e),Ka(t)])).pipe(m(([{height:r},o])=>({height:r,hidden:o})),K((r,o)=>r.height===o.height&&r.hidden===o.hidden),B(1))}function zn(e,{header$:t,main$:r}){return C(()=>{let o=new g,n=o.pipe(X(),ne(!0));o.pipe(Z("active"),We(t)).subscribe(([{active:a},{hidden:s}])=>{e.classList.toggle("md-header--shadow",a&&!s),e.hidden=s});let i=ue($("[title]",e)).pipe(b(()=>G("content.tooltips")),oe(a=>Vn(a)));return r.subscribe(o),t.pipe(U(n),m(a=>R({ref:e},a)),Pe(i.pipe(U(n))))})}function Ya(e,{viewport$:t,header$:r}){return mr(e,{viewport$:t,header$:r}).pipe(m(({offset:{y:o}})=>{let{height:n}=ce(e);return{active:o>=n}}),Z("active"))}function qn(e,t){return C(()=>{let r=new g;r.subscribe({next({active:n}){e.classList.toggle("md-header__title--active",n)},complete(){e.classList.remove("md-header__title--active")}});let o=fe(".md-content h1");return typeof o=="undefined"?M:Ya(o,t).pipe(E(n=>r.next(n)),L(()=>r.complete()),m(n=>R({ref:e},n)))})}function Qn(e,{viewport$:t,header$:r}){let o=r.pipe(m(({height:i})=>i),K()),n=o.pipe(v(()=>ge(e).pipe(m(({height:i})=>({top:e.offsetTop,bottom:e.offsetTop+i})),Z("bottom"))));return z([o,n,t]).pipe(m(([i,{top:a,bottom:s},{offset:{y:p},size:{height:c}}])=>(c=Math.max(0,c-Math.max(0,a-p,i)-Math.max(0,c+p-s)),{offset:a-i,height:c,active:a-i<=p})),K((i,a)=>i.offset===a.offset&&i.height===a.height&&i.active===a.active))}function Ba(e){let t=__md_get("__palette")||{index:e.findIndex(o=>matchMedia(o.getAttribute("data-md-color-media")).matches)},r=Math.max(0,Math.min(t.index,e.length-1));return I(...e).pipe(oe(o=>d(o,"change").pipe(m(()=>o))),Q(e[r]),m(o=>({index:e.indexOf(o),color:{media:o.getAttribute("data-md-color-media"),scheme:o.getAttribute("data-md-color-scheme"),primary:o.getAttribute("data-md-color-primary"),accent:o.getAttribute("data-md-color-accent")}})),B(1))}function Kn(e){let t=$("input",e),r=x("meta",{name:"theme-color"});document.head.appendChild(r);let o=x("meta",{name:"color-scheme"});document.head.appendChild(o);let n=$t("(prefers-color-scheme: light)");return C(()=>{let i=new g;return i.subscribe(a=>{if(document.body.setAttribute("data-md-color-switching",""),a.color.media==="(prefers-color-scheme)"){let s=matchMedia("(prefers-color-scheme: light)"),p=document.querySelector(s.matches?"[data-md-color-media='(prefers-color-scheme: light)']":"[data-md-color-media='(prefers-color-scheme: dark)']");a.color.scheme=p.getAttribute("data-md-color-scheme"),a.color.primary=p.getAttribute("data-md-color-primary"),a.color.accent=p.getAttribute("data-md-color-accent")}for(let[s,p]of Object.entries(a.color))document.body.setAttribute(`data-md-color-${s}`,p);for(let s=0;sa.key==="Enter"),ee(i,(a,s)=>s)).subscribe(({index:a})=>{a=(a+1)%t.length,t[a].click(),t[a].focus()}),i.pipe(m(()=>{let a=Se("header"),s=window.getComputedStyle(a);return o.content=s.colorScheme,s.backgroundColor.match(/\d+/g).map(p=>(+p).toString(16).padStart(2,"0")).join("")})).subscribe(a=>r.content=`#${a}`),i.pipe(be(se)).subscribe(()=>{document.body.removeAttribute("data-md-color-switching")}),Ba(t).pipe(U(n.pipe(Ce(1))),st(),E(a=>i.next(a)),L(()=>i.complete()),m(a=>R({ref:e},a)))})}function Yn(e,{progress$:t}){return C(()=>{let r=new g;return r.subscribe(({value:o})=>{e.style.setProperty("--md-progress-value",`${o}`)}),t.pipe(E(o=>r.next({value:o})),L(()=>r.complete()),m(o=>({ref:e,value:o})))})}var Gr=Vt(Yr());function Ga(e){e.setAttribute("data-md-copying","");let t=e.closest("[data-copy]"),r=t?t.getAttribute("data-copy"):e.innerText;return e.removeAttribute("data-md-copying"),r.trimEnd()}function Bn({alert$:e}){Gr.default.isSupported()&&new F(t=>{new Gr.default("[data-clipboard-target], [data-clipboard-text]",{text:r=>r.getAttribute("data-clipboard-text")||Ga(P(r.getAttribute("data-clipboard-target")))}).on("success",r=>t.next(r))}).pipe(E(t=>{t.trigger.focus()}),m(()=>Ee("clipboard.copied"))).subscribe(e)}function Gn(e,t){return e.protocol=t.protocol,e.hostname=t.hostname,e}function Ja(e,t){let r=new Map;for(let o of $("url",e)){let n=P("loc",o),i=[Gn(new URL(n.textContent),t)];r.set(`${i[0]}`,i);for(let a of $("[rel=alternate]",o)){let s=a.getAttribute("href");s!=null&&i.push(Gn(new URL(s),t))}}return r}function ur(e){return mn(new URL("sitemap.xml",e)).pipe(m(t=>Ja(t,new URL(e))),ve(()=>I(new Map)))}function Xa(e,t){if(!(e.target instanceof Element))return M;let r=e.target.closest("a");if(r===null)return M;if(r.target||e.metaKey||e.ctrlKey)return M;let o=new URL(r.href);return o.search=o.hash="",t.has(`${o}`)?(e.preventDefault(),I(new URL(r.href))):M}function Jn(e){let t=new Map;for(let r of $(":scope > *",e.head))t.set(r.outerHTML,r);return t}function Xn(e){for(let t of $("[href], [src]",e))for(let r of["href","src"]){let o=t.getAttribute(r);if(o&&!/^(?:[a-z]+:)?\/\//i.test(o)){t[r]=t[r];break}}return I(e)}function Za(e){for(let o of["[data-md-component=announce]","[data-md-component=container]","[data-md-component=header-topic]","[data-md-component=outdated]","[data-md-component=logo]","[data-md-component=skip]",...G("navigation.tabs.sticky")?["[data-md-component=tabs]"]:[]]){let n=fe(o),i=fe(o,e);typeof n!="undefined"&&typeof i!="undefined"&&n.replaceWith(i)}let t=Jn(document);for(let[o,n]of Jn(e))t.has(o)?t.delete(o):document.head.appendChild(n);for(let o of t.values()){let n=o.getAttribute("name");n!=="theme-color"&&n!=="color-scheme"&&o.remove()}let r=Se("container");return je($("script",r)).pipe(v(o=>{let n=e.createElement("script");if(o.src){for(let i of o.getAttributeNames())n.setAttribute(i,o.getAttribute(i));return o.replaceWith(n),new F(i=>{n.onload=()=>i.complete()})}else return n.textContent=o.textContent,o.replaceWith(n),M}),X(),ne(document))}function Zn({location$:e,viewport$:t,progress$:r}){let o=ye();if(location.protocol==="file:")return M;let n=ur(o.base);I(document).subscribe(Xn);let i=d(document.body,"click").pipe(We(n),v(([p,c])=>Xa(p,c)),pe()),a=d(window,"popstate").pipe(m(xe),pe());i.pipe(ee(t)).subscribe(([p,{offset:c}])=>{history.replaceState(c,""),history.pushState(null,"",p)}),S(i,a).subscribe(e);let s=e.pipe(Z("pathname"),v(p=>ln(p,{progress$:r}).pipe(ve(()=>(pt(p,!0),M)))),v(Xn),v(Za),pe());return S(s.pipe(ee(e,(p,c)=>c)),s.pipe(v(()=>e),Z("pathname"),v(()=>e),Z("hash")),e.pipe(K((p,c)=>p.pathname===c.pathname&&p.hash===c.hash),v(()=>i),E(()=>history.back()))).subscribe(p=>{var c,l;history.state!==null||!p.hash?window.scrollTo(0,(l=(c=history.state)==null?void 0:c.y)!=null?l:0):(history.scrollRestoration="auto",sn(p.hash),history.scrollRestoration="manual")}),e.subscribe(()=>{history.scrollRestoration="manual"}),d(window,"beforeunload").subscribe(()=>{history.scrollRestoration="auto"}),t.pipe(Z("offset"),_e(100)).subscribe(({offset:p})=>{history.replaceState(p,"")}),s}var ri=Vt(ti());function oi(e){let t=e.separator.split("|").map(n=>n.replace(/(\(\?[!=<][^)]+\))/g,"").length===0?"\uFFFD":n).join("|"),r=new RegExp(t,"img"),o=(n,i,a)=>`${i}${a}`;return n=>{n=n.replace(/[\s*+\-:~^]+/g," ").trim();let i=new RegExp(`(^|${e.separator}|)(${n.replace(/[|\\{}()[\]^$+*?.-]/g,"\\$&").replace(r,"|")})`,"img");return a=>(0,ri.default)(a).replace(i,o).replace(/<\/mark>(\s+)]*>/img,"$1")}}function It(e){return e.type===1}function dr(e){return e.type===3}function ni(e,t){let r=vn(e);return S(I(location.protocol!=="file:"),Ve("search")).pipe(Ae(o=>o),v(()=>t)).subscribe(({config:o,docs:n})=>r.next({type:0,data:{config:o,docs:n,options:{suggest:G("search.suggest")}}})),r}function ii({document$:e}){let t=ye(),r=Ne(new URL("../versions.json",t.base)).pipe(ve(()=>M)),o=r.pipe(m(n=>{let[,i]=t.base.match(/([^/]+)\/?$/);return n.find(({version:a,aliases:s})=>a===i||s.includes(i))||n[0]}));r.pipe(m(n=>new Map(n.map(i=>[`${new URL(`../${i.version}/`,t.base)}`,i]))),v(n=>d(document.body,"click").pipe(b(i=>!i.metaKey&&!i.ctrlKey),ee(o),v(([i,a])=>{if(i.target instanceof Element){let s=i.target.closest("a");if(s&&!s.target&&n.has(s.href)){let p=s.href;return!i.target.closest(".md-version")&&n.get(p)===a?M:(i.preventDefault(),I(p))}}return M}),v(i=>ur(new URL(i)).pipe(m(a=>{let p=xe().href.replace(t.base,i);return a.has(p.split("#")[0])?new URL(p):new URL(i)})))))).subscribe(n=>pt(n,!0)),z([r,o]).subscribe(([n,i])=>{P(".md-header__topic").appendChild(Mn(n,i))}),e.pipe(v(()=>o)).subscribe(n=>{var a;let i=__md_get("__outdated",sessionStorage);if(i===null){i=!0;let s=((a=t.version)==null?void 0:a.default)||"latest";Array.isArray(s)||(s=[s]);e:for(let p of s)for(let c of n.aliases.concat(n.version))if(new RegExp(p,"i").test(c)){i=!1;break e}__md_set("__outdated",i,sessionStorage)}if(i)for(let s of ae("outdated"))s.hidden=!1})}function ns(e,{worker$:t}){let{searchParams:r}=xe();r.has("q")&&(Je("search",!0),e.value=r.get("q"),e.focus(),Ve("search").pipe(Ae(i=>!i)).subscribe(()=>{let i=xe();i.searchParams.delete("q"),history.replaceState({},"",`${i}`)}));let o=et(e),n=S(t.pipe(Ae(It)),d(e,"keyup"),o).pipe(m(()=>e.value),K());return z([n,o]).pipe(m(([i,a])=>({value:i,focus:a})),B(1))}function ai(e,{worker$:t}){let r=new g,o=r.pipe(X(),ne(!0));z([t.pipe(Ae(It)),r],(i,a)=>a).pipe(Z("value")).subscribe(({value:i})=>t.next({type:2,data:i})),r.pipe(Z("focus")).subscribe(({focus:i})=>{i&&Je("search",i)}),d(e.form,"reset").pipe(U(o)).subscribe(()=>e.focus());let n=P("header [for=__search]");return d(n,"click").subscribe(()=>e.focus()),ns(e,{worker$:t}).pipe(E(i=>r.next(i)),L(()=>r.complete()),m(i=>R({ref:e},i)),B(1))}function si(e,{worker$:t,query$:r}){let o=new g,n=tn(e.parentElement).pipe(b(Boolean)),i=e.parentElement,a=P(":scope > :first-child",e),s=P(":scope > :last-child",e);Ve("search").subscribe(l=>s.setAttribute("role",l?"list":"presentation")),o.pipe(ee(r),Ur(t.pipe(Ae(It)))).subscribe(([{items:l},{value:f}])=>{switch(l.length){case 0:a.textContent=f.length?Ee("search.result.none"):Ee("search.result.placeholder");break;case 1:a.textContent=Ee("search.result.one");break;default:let u=sr(l.length);a.textContent=Ee("search.result.other",u)}});let p=o.pipe(E(()=>s.innerHTML=""),v(({items:l})=>S(I(...l.slice(0,10)),I(...l.slice(10)).pipe(Ye(4),Vr(n),v(([f])=>f)))),m(Tn),pe());return p.subscribe(l=>s.appendChild(l)),p.pipe(oe(l=>{let f=fe("details",l);return typeof f=="undefined"?M:d(f,"toggle").pipe(U(o),m(()=>f))})).subscribe(l=>{l.open===!1&&l.offsetTop<=i.scrollTop&&i.scrollTo({top:l.offsetTop})}),t.pipe(b(dr),m(({data:l})=>l)).pipe(E(l=>o.next(l)),L(()=>o.complete()),m(l=>R({ref:e},l)))}function is(e,{query$:t}){return t.pipe(m(({value:r})=>{let o=xe();return o.hash="",r=r.replace(/\s+/g,"+").replace(/&/g,"%26").replace(/=/g,"%3D"),o.search=`q=${r}`,{url:o}}))}function ci(e,t){let r=new g,o=r.pipe(X(),ne(!0));return r.subscribe(({url:n})=>{e.setAttribute("data-clipboard-text",e.href),e.href=`${n}`}),d(e,"click").pipe(U(o)).subscribe(n=>n.preventDefault()),is(e,t).pipe(E(n=>r.next(n)),L(()=>r.complete()),m(n=>R({ref:e},n)))}function pi(e,{worker$:t,keyboard$:r}){let o=new g,n=Se("search-query"),i=S(d(n,"keydown"),d(n,"focus")).pipe(be(se),m(()=>n.value),K());return o.pipe(We(i),m(([{suggest:s},p])=>{let c=p.split(/([\s-]+)/);if(s!=null&&s.length&&c[c.length-1]){let l=s[s.length-1];l.startsWith(c[c.length-1])&&(c[c.length-1]=l)}else c.length=0;return c})).subscribe(s=>e.innerHTML=s.join("").replace(/\s/g," ")),r.pipe(b(({mode:s})=>s==="search")).subscribe(s=>{switch(s.type){case"ArrowRight":e.innerText.length&&n.selectionStart===n.value.length&&(n.value=e.innerText);break}}),t.pipe(b(dr),m(({data:s})=>s)).pipe(E(s=>o.next(s)),L(()=>o.complete()),m(()=>({ref:e})))}function li(e,{index$:t,keyboard$:r}){let o=ye();try{let n=ni(o.search,t),i=Se("search-query",e),a=Se("search-result",e);d(e,"click").pipe(b(({target:p})=>p instanceof Element&&!!p.closest("a"))).subscribe(()=>Je("search",!1)),r.pipe(b(({mode:p})=>p==="search")).subscribe(p=>{let c=Re();switch(p.type){case"Enter":if(c===i){let l=new Map;for(let f of $(":first-child [href]",a)){let u=f.firstElementChild;l.set(f,parseFloat(u.getAttribute("data-md-score")))}if(l.size){let[[f]]=[...l].sort(([,u],[,h])=>h-u);f.click()}p.claim()}break;case"Escape":case"Tab":Je("search",!1),i.blur();break;case"ArrowUp":case"ArrowDown":if(typeof c=="undefined")i.focus();else{let l=[i,...$(":not(details) > [href], summary, details[open] [href]",a)],f=Math.max(0,(Math.max(0,l.indexOf(c))+l.length+(p.type==="ArrowUp"?-1:1))%l.length);l[f].focus()}p.claim();break;default:i!==Re()&&i.focus()}}),r.pipe(b(({mode:p})=>p==="global")).subscribe(p=>{switch(p.type){case"f":case"s":case"/":i.focus(),i.select(),p.claim();break}});let s=ai(i,{worker$:n});return S(s,si(a,{worker$:n,query$:s})).pipe(Pe(...ae("search-share",e).map(p=>ci(p,{query$:s})),...ae("search-suggest",e).map(p=>pi(p,{worker$:n,keyboard$:r}))))}catch(n){return e.hidden=!0,Ke}}function mi(e,{index$:t,location$:r}){return z([t,r.pipe(Q(xe()),b(o=>!!o.searchParams.get("h")))]).pipe(m(([o,n])=>oi(o.config)(n.searchParams.get("h"))),m(o=>{var a;let n=new Map,i=document.createNodeIterator(e,NodeFilter.SHOW_TEXT);for(let s=i.nextNode();s;s=i.nextNode())if((a=s.parentElement)!=null&&a.offsetHeight){let p=s.textContent,c=o(p);c.length>p.length&&n.set(s,c)}for(let[s,p]of n){let{childNodes:c}=x("span",null,p);s.replaceWith(...Array.from(c))}return{ref:e,nodes:n}}))}function as(e,{viewport$:t,main$:r}){let o=e.closest(".md-grid"),n=o.offsetTop-o.parentElement.offsetTop;return z([r,t]).pipe(m(([{offset:i,height:a},{offset:{y:s}}])=>(a=a+Math.min(n,Math.max(0,s-i))-n,{height:a,locked:s>=i+n})),K((i,a)=>i.height===a.height&&i.locked===a.locked))}function Jr(e,o){var n=o,{header$:t}=n,r=io(n,["header$"]);let i=P(".md-sidebar__scrollwrap",e),{y:a}=Ue(i);return C(()=>{let s=new g,p=s.pipe(X(),ne(!0)),c=s.pipe(Le(0,me));return c.pipe(ee(t)).subscribe({next([{height:l},{height:f}]){i.style.height=`${l-2*a}px`,e.style.top=`${f}px`},complete(){i.style.height="",e.style.top=""}}),c.pipe(Ae()).subscribe(()=>{for(let l of $(".md-nav__link--active[href]",e)){if(!l.clientHeight)continue;let f=l.closest(".md-sidebar__scrollwrap");if(typeof f!="undefined"){let u=l.offsetTop-f.offsetTop,{height:h}=ce(f);f.scrollTo({top:u-h/2})}}}),ue($("label[tabindex]",e)).pipe(oe(l=>d(l,"click").pipe(be(se),m(()=>l),U(p)))).subscribe(l=>{let f=P(`[id="${l.htmlFor}"]`);P(`[aria-labelledby="${l.id}"]`).setAttribute("aria-expanded",`${f.checked}`)}),as(e,r).pipe(E(l=>s.next(l)),L(()=>s.complete()),m(l=>R({ref:e},l)))})}function fi(e,t){if(typeof t!="undefined"){let r=`https://api.github.com/repos/${e}/${t}`;return Ct(Ne(`${r}/releases/latest`).pipe(ve(()=>M),m(o=>({version:o.tag_name})),Be({})),Ne(r).pipe(ve(()=>M),m(o=>({stars:o.stargazers_count,forks:o.forks_count})),Be({}))).pipe(m(([o,n])=>R(R({},o),n)))}else{let r=`https://api.github.com/users/${e}`;return Ne(r).pipe(m(o=>({repositories:o.public_repos})),Be({}))}}function ui(e,t){let r=`https://${e}/api/v4/projects/${encodeURIComponent(t)}`;return Ne(r).pipe(ve(()=>M),m(({star_count:o,forks_count:n})=>({stars:o,forks:n})),Be({}))}function di(e){let t=e.match(/^.+github\.com\/([^/]+)\/?([^/]+)?/i);if(t){let[,r,o]=t;return fi(r,o)}if(t=e.match(/^.+?([^/]*gitlab[^/]+)\/(.+?)\/?$/i),t){let[,r,o]=t;return ui(r,o)}return M}var ss;function cs(e){return ss||(ss=C(()=>{let t=__md_get("__source",sessionStorage);if(t)return I(t);if(ae("consent").length){let o=__md_get("__consent");if(!(o&&o.github))return M}return di(e.href).pipe(E(o=>__md_set("__source",o,sessionStorage)))}).pipe(ve(()=>M),b(t=>Object.keys(t).length>0),m(t=>({facts:t})),B(1)))}function hi(e){let t=P(":scope > :last-child",e);return C(()=>{let r=new g;return r.subscribe(({facts:o})=>{t.appendChild(Sn(o)),t.classList.add("md-source__repository--active")}),cs(e).pipe(E(o=>r.next(o)),L(()=>r.complete()),m(o=>R({ref:e},o)))})}function ps(e,{viewport$:t,header$:r}){return ge(document.body).pipe(v(()=>mr(e,{header$:r,viewport$:t})),m(({offset:{y:o}})=>({hidden:o>=10})),Z("hidden"))}function bi(e,t){return C(()=>{let r=new g;return r.subscribe({next({hidden:o}){e.hidden=o},complete(){e.hidden=!1}}),(G("navigation.tabs.sticky")?I({hidden:!1}):ps(e,t)).pipe(E(o=>r.next(o)),L(()=>r.complete()),m(o=>R({ref:e},o)))})}function ls(e,{viewport$:t,header$:r}){let o=new Map,n=$(".md-nav__link",e);for(let s of n){let p=decodeURIComponent(s.hash.substring(1)),c=fe(`[id="${p}"]`);typeof c!="undefined"&&o.set(s,c)}let i=r.pipe(Z("height"),m(({height:s})=>{let p=Se("main"),c=P(":scope > :first-child",p);return s+.8*(c.offsetTop-p.offsetTop)}),pe());return ge(document.body).pipe(Z("height"),v(s=>C(()=>{let p=[];return I([...o].reduce((c,[l,f])=>{for(;p.length&&o.get(p[p.length-1]).tagName>=f.tagName;)p.pop();let u=f.offsetTop;for(;!u&&f.parentElement;)f=f.parentElement,u=f.offsetTop;let h=f.offsetParent;for(;h;h=h.offsetParent)u+=h.offsetTop;return c.set([...p=[...p,l]].reverse(),u)},new Map))}).pipe(m(p=>new Map([...p].sort(([,c],[,l])=>c-l))),We(i),v(([p,c])=>t.pipe(jr(([l,f],{offset:{y:u},size:h})=>{let w=u+h.height>=Math.floor(s.height);for(;f.length;){let[,A]=f[0];if(A-c=u&&!w)f=[l.pop(),...f];else break}return[l,f]},[[],[...p]]),K((l,f)=>l[0]===f[0]&&l[1]===f[1])))))).pipe(m(([s,p])=>({prev:s.map(([c])=>c),next:p.map(([c])=>c)})),Q({prev:[],next:[]}),Ye(2,1),m(([s,p])=>s.prev.length{let i=new g,a=i.pipe(X(),ne(!0));if(i.subscribe(({prev:s,next:p})=>{for(let[c]of p)c.classList.remove("md-nav__link--passed"),c.classList.remove("md-nav__link--active");for(let[c,[l]]of s.entries())l.classList.add("md-nav__link--passed"),l.classList.toggle("md-nav__link--active",c===s.length-1)}),G("toc.follow")){let s=S(t.pipe(_e(1),m(()=>{})),t.pipe(_e(250),m(()=>"smooth")));i.pipe(b(({prev:p})=>p.length>0),We(o.pipe(be(se))),ee(s)).subscribe(([[{prev:p}],c])=>{let[l]=p[p.length-1];if(l.offsetHeight){let f=cr(l);if(typeof f!="undefined"){let u=l.offsetTop-f.offsetTop,{height:h}=ce(f);f.scrollTo({top:u-h/2,behavior:c})}}})}return G("navigation.tracking")&&t.pipe(U(a),Z("offset"),_e(250),Ce(1),U(n.pipe(Ce(1))),st({delay:250}),ee(i)).subscribe(([,{prev:s}])=>{let p=xe(),c=s[s.length-1];if(c&&c.length){let[l]=c,{hash:f}=new URL(l.href);p.hash!==f&&(p.hash=f,history.replaceState({},"",`${p}`))}else p.hash="",history.replaceState({},"",`${p}`)}),ls(e,{viewport$:t,header$:r}).pipe(E(s=>i.next(s)),L(()=>i.complete()),m(s=>R({ref:e},s)))})}function ms(e,{viewport$:t,main$:r,target$:o}){let n=t.pipe(m(({offset:{y:a}})=>a),Ye(2,1),m(([a,s])=>a>s&&s>0),K()),i=r.pipe(m(({active:a})=>a));return z([i,n]).pipe(m(([a,s])=>!(a&&s)),K(),U(o.pipe(Ce(1))),ne(!0),st({delay:250}),m(a=>({hidden:a})))}function gi(e,{viewport$:t,header$:r,main$:o,target$:n}){let i=new g,a=i.pipe(X(),ne(!0));return i.subscribe({next({hidden:s}){e.hidden=s,s?(e.setAttribute("tabindex","-1"),e.blur()):e.removeAttribute("tabindex")},complete(){e.style.top="",e.hidden=!0,e.removeAttribute("tabindex")}}),r.pipe(U(a),Z("height")).subscribe(({height:s})=>{e.style.top=`${s+16}px`}),d(e,"click").subscribe(s=>{s.preventDefault(),window.scrollTo({top:0})}),ms(e,{viewport$:t,main$:o,target$:n}).pipe(E(s=>i.next(s)),L(()=>i.complete()),m(s=>R({ref:e},s)))}function xi({document$:e,viewport$:t}){e.pipe(v(()=>$(".md-ellipsis")),oe(r=>tt(r).pipe(U(e.pipe(Ce(1))),b(o=>o),m(()=>r),Te(1))),b(r=>r.offsetWidth{let o=r.innerText,n=r.closest("a")||r;return n.title=o,lt(n,{viewport$:t}).pipe(U(e.pipe(Ce(1))),L(()=>n.removeAttribute("title")))})).subscribe(),e.pipe(v(()=>$(".md-status")),oe(r=>lt(r,{viewport$:t}))).subscribe()}function yi({document$:e,tablet$:t}){e.pipe(v(()=>$(".md-toggle--indeterminate")),E(r=>{r.indeterminate=!0,r.checked=!1}),oe(r=>d(r,"change").pipe(Dr(()=>r.classList.contains("md-toggle--indeterminate")),m(()=>r))),ee(t)).subscribe(([r,o])=>{r.classList.remove("md-toggle--indeterminate"),o&&(r.checked=!1)})}function fs(){return/(iPad|iPhone|iPod)/.test(navigator.userAgent)}function Ei({document$:e}){e.pipe(v(()=>$("[data-md-scrollfix]")),E(t=>t.removeAttribute("data-md-scrollfix")),b(fs),oe(t=>d(t,"touchstart").pipe(m(()=>t)))).subscribe(t=>{let r=t.scrollTop;r===0?t.scrollTop=1:r+t.offsetHeight===t.scrollHeight&&(t.scrollTop=r-1)})}function wi({viewport$:e,tablet$:t}){z([Ve("search"),t]).pipe(m(([r,o])=>r&&!o),v(r=>I(r).pipe(Ge(r?400:100))),ee(e)).subscribe(([r,{offset:{y:o}}])=>{if(r)document.body.setAttribute("data-md-scrolllock",""),document.body.style.top=`-${o}px`;else{let n=-1*parseInt(document.body.style.top,10);document.body.removeAttribute("data-md-scrolllock"),document.body.style.top="",n&&window.scrollTo(0,n)}})}Object.entries||(Object.entries=function(e){let t=[];for(let r of Object.keys(e))t.push([r,e[r]]);return t});Object.values||(Object.values=function(e){let t=[];for(let r of Object.keys(e))t.push(e[r]);return t});typeof Element!="undefined"&&(Element.prototype.scrollTo||(Element.prototype.scrollTo=function(e,t){typeof e=="object"?(this.scrollLeft=e.left,this.scrollTop=e.top):(this.scrollLeft=e,this.scrollTop=t)}),Element.prototype.replaceWith||(Element.prototype.replaceWith=function(...e){let t=this.parentNode;if(t){e.length===0&&t.removeChild(this);for(let r=e.length-1;r>=0;r--){let o=e[r];typeof o=="string"?o=document.createTextNode(o):o.parentNode&&o.parentNode.removeChild(o),r?t.insertBefore(this.previousSibling,o):t.replaceChild(o,this)}}}));function us(){return location.protocol==="file:"?wt(`${new URL("search/search_index.js",Xr.base)}`).pipe(m(()=>__index),B(1)):Ne(new URL("search/search_index.json",Xr.base))}document.documentElement.classList.remove("no-js");document.documentElement.classList.add("js");var ot=Yo(),jt=nn(),Ot=cn(jt),Zr=on(),Oe=bn(),hr=$t("(min-width: 960px)"),Si=$t("(min-width: 1220px)"),Oi=pn(),Xr=ye(),Mi=document.forms.namedItem("search")?us():Ke,eo=new g;Bn({alert$:eo});var to=new g;G("navigation.instant")&&Zn({location$:jt,viewport$:Oe,progress$:to}).subscribe(ot);var Ti;((Ti=Xr.version)==null?void 0:Ti.provider)==="mike"&&ii({document$:ot});S(jt,Ot).pipe(Ge(125)).subscribe(()=>{Je("drawer",!1),Je("search",!1)});Zr.pipe(b(({mode:e})=>e==="global")).subscribe(e=>{switch(e.type){case"p":case",":let t=fe("link[rel=prev]");typeof t!="undefined"&&pt(t);break;case"n":case".":let r=fe("link[rel=next]");typeof r!="undefined"&&pt(r);break;case"Enter":let o=Re();o instanceof HTMLLabelElement&&o.click()}});xi({viewport$:Oe,document$:ot});yi({document$:ot,tablet$:hr});Ei({document$:ot});wi({viewport$:Oe,tablet$:hr});var rt=Nn(Se("header"),{viewport$:Oe}),Ft=ot.pipe(m(()=>Se("main")),v(e=>Qn(e,{viewport$:Oe,header$:rt})),B(1)),ds=S(...ae("consent").map(e=>xn(e,{target$:Ot})),...ae("dialog").map(e=>Dn(e,{alert$:eo})),...ae("header").map(e=>zn(e,{viewport$:Oe,header$:rt,main$:Ft})),...ae("palette").map(e=>Kn(e)),...ae("progress").map(e=>Yn(e,{progress$:to})),...ae("search").map(e=>li(e,{index$:Mi,keyboard$:Zr})),...ae("source").map(e=>hi(e))),hs=C(()=>S(...ae("announce").map(e=>gn(e)),...ae("content").map(e=>Un(e,{viewport$:Oe,target$:Ot,print$:Oi})),...ae("content").map(e=>G("search.highlight")?mi(e,{index$:Mi,location$:jt}):M),...ae("header-title").map(e=>qn(e,{viewport$:Oe,header$:rt})),...ae("sidebar").map(e=>e.getAttribute("data-md-type")==="navigation"?Nr(Si,()=>Jr(e,{viewport$:Oe,header$:rt,main$:Ft})):Nr(hr,()=>Jr(e,{viewport$:Oe,header$:rt,main$:Ft}))),...ae("tabs").map(e=>bi(e,{viewport$:Oe,header$:rt})),...ae("toc").map(e=>vi(e,{viewport$:Oe,header$:rt,main$:Ft,target$:Ot})),...ae("top").map(e=>gi(e,{viewport$:Oe,header$:rt,main$:Ft,target$:Ot})))),Li=ot.pipe(v(()=>hs),Pe(ds),B(1));Li.subscribe();window.document$=ot;window.location$=jt;window.target$=Ot;window.keyboard$=Zr;window.viewport$=Oe;window.tablet$=hr;window.screen$=Si;window.print$=Oi;window.alert$=eo;window.progress$=to;window.component$=Li;})(); +//# sourceMappingURL=bundle.ad660dcc.min.js.map + diff --git a/assets/javascripts/bundle.ad660dcc.min.js.map b/assets/javascripts/bundle.ad660dcc.min.js.map new file mode 100644 index 00000000..6d61170f --- /dev/null +++ b/assets/javascripts/bundle.ad660dcc.min.js.map @@ -0,0 +1,7 @@ +{ + "version": 3, + "sources": ["node_modules/focus-visible/dist/focus-visible.js", "node_modules/clipboard/dist/clipboard.js", "node_modules/escape-html/index.js", "src/templates/assets/javascripts/bundle.ts", "node_modules/rxjs/node_modules/tslib/tslib.es6.js", "node_modules/rxjs/src/internal/util/isFunction.ts", "node_modules/rxjs/src/internal/util/createErrorClass.ts", "node_modules/rxjs/src/internal/util/UnsubscriptionError.ts", "node_modules/rxjs/src/internal/util/arrRemove.ts", "node_modules/rxjs/src/internal/Subscription.ts", "node_modules/rxjs/src/internal/config.ts", "node_modules/rxjs/src/internal/scheduler/timeoutProvider.ts", "node_modules/rxjs/src/internal/util/reportUnhandledError.ts", "node_modules/rxjs/src/internal/util/noop.ts", "node_modules/rxjs/src/internal/NotificationFactories.ts", "node_modules/rxjs/src/internal/util/errorContext.ts", "node_modules/rxjs/src/internal/Subscriber.ts", "node_modules/rxjs/src/internal/symbol/observable.ts", "node_modules/rxjs/src/internal/util/identity.ts", "node_modules/rxjs/src/internal/util/pipe.ts", "node_modules/rxjs/src/internal/Observable.ts", "node_modules/rxjs/src/internal/util/lift.ts", "node_modules/rxjs/src/internal/operators/OperatorSubscriber.ts", "node_modules/rxjs/src/internal/scheduler/animationFrameProvider.ts", "node_modules/rxjs/src/internal/util/ObjectUnsubscribedError.ts", "node_modules/rxjs/src/internal/Subject.ts", "node_modules/rxjs/src/internal/BehaviorSubject.ts", "node_modules/rxjs/src/internal/scheduler/dateTimestampProvider.ts", "node_modules/rxjs/src/internal/ReplaySubject.ts", "node_modules/rxjs/src/internal/scheduler/Action.ts", "node_modules/rxjs/src/internal/scheduler/intervalProvider.ts", "node_modules/rxjs/src/internal/scheduler/AsyncAction.ts", "node_modules/rxjs/src/internal/Scheduler.ts", "node_modules/rxjs/src/internal/scheduler/AsyncScheduler.ts", "node_modules/rxjs/src/internal/scheduler/async.ts", "node_modules/rxjs/src/internal/scheduler/QueueAction.ts", "node_modules/rxjs/src/internal/scheduler/QueueScheduler.ts", "node_modules/rxjs/src/internal/scheduler/queue.ts", "node_modules/rxjs/src/internal/scheduler/AnimationFrameAction.ts", "node_modules/rxjs/src/internal/scheduler/AnimationFrameScheduler.ts", "node_modules/rxjs/src/internal/scheduler/animationFrame.ts", "node_modules/rxjs/src/internal/observable/empty.ts", "node_modules/rxjs/src/internal/util/isScheduler.ts", "node_modules/rxjs/src/internal/util/args.ts", "node_modules/rxjs/src/internal/util/isArrayLike.ts", "node_modules/rxjs/src/internal/util/isPromise.ts", "node_modules/rxjs/src/internal/util/isInteropObservable.ts", "node_modules/rxjs/src/internal/util/isAsyncIterable.ts", "node_modules/rxjs/src/internal/util/throwUnobservableError.ts", "node_modules/rxjs/src/internal/symbol/iterator.ts", "node_modules/rxjs/src/internal/util/isIterable.ts", "node_modules/rxjs/src/internal/util/isReadableStreamLike.ts", "node_modules/rxjs/src/internal/observable/innerFrom.ts", "node_modules/rxjs/src/internal/util/executeSchedule.ts", "node_modules/rxjs/src/internal/operators/observeOn.ts", "node_modules/rxjs/src/internal/operators/subscribeOn.ts", "node_modules/rxjs/src/internal/scheduled/scheduleObservable.ts", "node_modules/rxjs/src/internal/scheduled/schedulePromise.ts", "node_modules/rxjs/src/internal/scheduled/scheduleArray.ts", "node_modules/rxjs/src/internal/scheduled/scheduleIterable.ts", "node_modules/rxjs/src/internal/scheduled/scheduleAsyncIterable.ts", "node_modules/rxjs/src/internal/scheduled/scheduleReadableStreamLike.ts", "node_modules/rxjs/src/internal/scheduled/scheduled.ts", "node_modules/rxjs/src/internal/observable/from.ts", "node_modules/rxjs/src/internal/observable/of.ts", "node_modules/rxjs/src/internal/observable/throwError.ts", "node_modules/rxjs/src/internal/util/EmptyError.ts", "node_modules/rxjs/src/internal/util/isDate.ts", "node_modules/rxjs/src/internal/operators/map.ts", "node_modules/rxjs/src/internal/util/mapOneOrManyArgs.ts", "node_modules/rxjs/src/internal/util/argsArgArrayOrObject.ts", "node_modules/rxjs/src/internal/util/createObject.ts", "node_modules/rxjs/src/internal/observable/combineLatest.ts", "node_modules/rxjs/src/internal/operators/mergeInternals.ts", "node_modules/rxjs/src/internal/operators/mergeMap.ts", "node_modules/rxjs/src/internal/operators/mergeAll.ts", "node_modules/rxjs/src/internal/operators/concatAll.ts", "node_modules/rxjs/src/internal/observable/concat.ts", "node_modules/rxjs/src/internal/observable/defer.ts", "node_modules/rxjs/src/internal/observable/fromEvent.ts", "node_modules/rxjs/src/internal/observable/fromEventPattern.ts", "node_modules/rxjs/src/internal/observable/timer.ts", "node_modules/rxjs/src/internal/observable/merge.ts", "node_modules/rxjs/src/internal/observable/never.ts", "node_modules/rxjs/src/internal/util/argsOrArgArray.ts", "node_modules/rxjs/src/internal/operators/filter.ts", "node_modules/rxjs/src/internal/observable/zip.ts", "node_modules/rxjs/src/internal/operators/audit.ts", "node_modules/rxjs/src/internal/operators/auditTime.ts", "node_modules/rxjs/src/internal/operators/bufferCount.ts", "node_modules/rxjs/src/internal/operators/catchError.ts", "node_modules/rxjs/src/internal/operators/scanInternals.ts", "node_modules/rxjs/src/internal/operators/combineLatest.ts", "node_modules/rxjs/src/internal/operators/combineLatestWith.ts", "node_modules/rxjs/src/internal/operators/debounce.ts", "node_modules/rxjs/src/internal/operators/debounceTime.ts", "node_modules/rxjs/src/internal/operators/defaultIfEmpty.ts", "node_modules/rxjs/src/internal/operators/take.ts", "node_modules/rxjs/src/internal/operators/ignoreElements.ts", "node_modules/rxjs/src/internal/operators/mapTo.ts", "node_modules/rxjs/src/internal/operators/delayWhen.ts", "node_modules/rxjs/src/internal/operators/delay.ts", "node_modules/rxjs/src/internal/operators/distinctUntilChanged.ts", "node_modules/rxjs/src/internal/operators/distinctUntilKeyChanged.ts", "node_modules/rxjs/src/internal/operators/throwIfEmpty.ts", "node_modules/rxjs/src/internal/operators/endWith.ts", "node_modules/rxjs/src/internal/operators/finalize.ts", "node_modules/rxjs/src/internal/operators/first.ts", "node_modules/rxjs/src/internal/operators/takeLast.ts", "node_modules/rxjs/src/internal/operators/merge.ts", "node_modules/rxjs/src/internal/operators/mergeWith.ts", "node_modules/rxjs/src/internal/operators/repeat.ts", "node_modules/rxjs/src/internal/operators/scan.ts", "node_modules/rxjs/src/internal/operators/share.ts", "node_modules/rxjs/src/internal/operators/shareReplay.ts", "node_modules/rxjs/src/internal/operators/skip.ts", "node_modules/rxjs/src/internal/operators/skipUntil.ts", "node_modules/rxjs/src/internal/operators/startWith.ts", "node_modules/rxjs/src/internal/operators/switchMap.ts", "node_modules/rxjs/src/internal/operators/takeUntil.ts", "node_modules/rxjs/src/internal/operators/takeWhile.ts", "node_modules/rxjs/src/internal/operators/tap.ts", "node_modules/rxjs/src/internal/operators/throttle.ts", "node_modules/rxjs/src/internal/operators/throttleTime.ts", "node_modules/rxjs/src/internal/operators/withLatestFrom.ts", "node_modules/rxjs/src/internal/operators/zip.ts", "node_modules/rxjs/src/internal/operators/zipWith.ts", "src/templates/assets/javascripts/browser/document/index.ts", "src/templates/assets/javascripts/browser/element/_/index.ts", "src/templates/assets/javascripts/browser/element/focus/index.ts", "src/templates/assets/javascripts/browser/element/hover/index.ts", "src/templates/assets/javascripts/utilities/h/index.ts", "src/templates/assets/javascripts/utilities/round/index.ts", "src/templates/assets/javascripts/browser/script/index.ts", "src/templates/assets/javascripts/browser/element/size/_/index.ts", "src/templates/assets/javascripts/browser/element/size/content/index.ts", "src/templates/assets/javascripts/browser/element/offset/_/index.ts", "src/templates/assets/javascripts/browser/element/offset/content/index.ts", "src/templates/assets/javascripts/browser/element/visibility/index.ts", "src/templates/assets/javascripts/browser/toggle/index.ts", "src/templates/assets/javascripts/browser/keyboard/index.ts", "src/templates/assets/javascripts/browser/location/_/index.ts", "src/templates/assets/javascripts/browser/location/hash/index.ts", "src/templates/assets/javascripts/browser/media/index.ts", "src/templates/assets/javascripts/browser/request/index.ts", "src/templates/assets/javascripts/browser/viewport/offset/index.ts", "src/templates/assets/javascripts/browser/viewport/size/index.ts", "src/templates/assets/javascripts/browser/viewport/_/index.ts", "src/templates/assets/javascripts/browser/viewport/at/index.ts", "src/templates/assets/javascripts/browser/worker/index.ts", "src/templates/assets/javascripts/_/index.ts", "src/templates/assets/javascripts/components/_/index.ts", "src/templates/assets/javascripts/components/announce/index.ts", "src/templates/assets/javascripts/components/consent/index.ts", "src/templates/assets/javascripts/templates/tooltip/index.tsx", "src/templates/assets/javascripts/templates/annotation/index.tsx", "src/templates/assets/javascripts/templates/clipboard/index.tsx", "src/templates/assets/javascripts/templates/search/index.tsx", "src/templates/assets/javascripts/templates/source/index.tsx", "src/templates/assets/javascripts/templates/tabbed/index.tsx", "src/templates/assets/javascripts/templates/table/index.tsx", "src/templates/assets/javascripts/templates/version/index.tsx", "src/templates/assets/javascripts/components/tooltip2/index.ts", "src/templates/assets/javascripts/components/content/annotation/_/index.ts", "src/templates/assets/javascripts/components/content/annotation/list/index.ts", "src/templates/assets/javascripts/components/content/annotation/block/index.ts", "src/templates/assets/javascripts/components/content/code/_/index.ts", "src/templates/assets/javascripts/components/content/details/index.ts", "src/templates/assets/javascripts/components/content/mermaid/index.css", "src/templates/assets/javascripts/components/content/mermaid/index.ts", "src/templates/assets/javascripts/components/content/table/index.ts", "src/templates/assets/javascripts/components/content/tabs/index.ts", "src/templates/assets/javascripts/components/content/_/index.ts", "src/templates/assets/javascripts/components/dialog/index.ts", "src/templates/assets/javascripts/components/tooltip/index.ts", "src/templates/assets/javascripts/components/header/_/index.ts", "src/templates/assets/javascripts/components/header/title/index.ts", "src/templates/assets/javascripts/components/main/index.ts", "src/templates/assets/javascripts/components/palette/index.ts", "src/templates/assets/javascripts/components/progress/index.ts", "src/templates/assets/javascripts/integrations/clipboard/index.ts", "src/templates/assets/javascripts/integrations/sitemap/index.ts", "src/templates/assets/javascripts/integrations/instant/index.ts", "src/templates/assets/javascripts/integrations/search/highlighter/index.ts", "src/templates/assets/javascripts/integrations/search/worker/message/index.ts", "src/templates/assets/javascripts/integrations/search/worker/_/index.ts", "src/templates/assets/javascripts/integrations/version/index.ts", "src/templates/assets/javascripts/components/search/query/index.ts", "src/templates/assets/javascripts/components/search/result/index.ts", "src/templates/assets/javascripts/components/search/share/index.ts", "src/templates/assets/javascripts/components/search/suggest/index.ts", "src/templates/assets/javascripts/components/search/_/index.ts", "src/templates/assets/javascripts/components/search/highlight/index.ts", "src/templates/assets/javascripts/components/sidebar/index.ts", "src/templates/assets/javascripts/components/source/facts/github/index.ts", "src/templates/assets/javascripts/components/source/facts/gitlab/index.ts", "src/templates/assets/javascripts/components/source/facts/_/index.ts", "src/templates/assets/javascripts/components/source/_/index.ts", "src/templates/assets/javascripts/components/tabs/index.ts", "src/templates/assets/javascripts/components/toc/index.ts", "src/templates/assets/javascripts/components/top/index.ts", "src/templates/assets/javascripts/patches/ellipsis/index.ts", "src/templates/assets/javascripts/patches/indeterminate/index.ts", "src/templates/assets/javascripts/patches/scrollfix/index.ts", "src/templates/assets/javascripts/patches/scrolllock/index.ts", "src/templates/assets/javascripts/polyfills/index.ts"], + "sourcesContent": ["(function (global, factory) {\n typeof exports === 'object' && typeof module !== 'undefined' ? factory() :\n typeof define === 'function' && define.amd ? define(factory) :\n (factory());\n}(this, (function () { 'use strict';\n\n /**\n * Applies the :focus-visible polyfill at the given scope.\n * A scope in this case is either the top-level Document or a Shadow Root.\n *\n * @param {(Document|ShadowRoot)} scope\n * @see https://github.com/WICG/focus-visible\n */\n function applyFocusVisiblePolyfill(scope) {\n var hadKeyboardEvent = true;\n var hadFocusVisibleRecently = false;\n var hadFocusVisibleRecentlyTimeout = null;\n\n var inputTypesAllowlist = {\n text: true,\n search: true,\n url: true,\n tel: true,\n email: true,\n password: true,\n number: true,\n date: true,\n month: true,\n week: true,\n time: true,\n datetime: true,\n 'datetime-local': true\n };\n\n /**\n * Helper function for legacy browsers and iframes which sometimes focus\n * elements like document, body, and non-interactive SVG.\n * @param {Element} el\n */\n function isValidFocusTarget(el) {\n if (\n el &&\n el !== document &&\n el.nodeName !== 'HTML' &&\n el.nodeName !== 'BODY' &&\n 'classList' in el &&\n 'contains' in el.classList\n ) {\n return true;\n }\n return false;\n }\n\n /**\n * Computes whether the given element should automatically trigger the\n * `focus-visible` class being added, i.e. whether it should always match\n * `:focus-visible` when focused.\n * @param {Element} el\n * @return {boolean}\n */\n function focusTriggersKeyboardModality(el) {\n var type = el.type;\n var tagName = el.tagName;\n\n if (tagName === 'INPUT' && inputTypesAllowlist[type] && !el.readOnly) {\n return true;\n }\n\n if (tagName === 'TEXTAREA' && !el.readOnly) {\n return true;\n }\n\n if (el.isContentEditable) {\n return true;\n }\n\n return false;\n }\n\n /**\n * Add the `focus-visible` class to the given element if it was not added by\n * the author.\n * @param {Element} el\n */\n function addFocusVisibleClass(el) {\n if (el.classList.contains('focus-visible')) {\n return;\n }\n el.classList.add('focus-visible');\n el.setAttribute('data-focus-visible-added', '');\n }\n\n /**\n * Remove the `focus-visible` class from the given element if it was not\n * originally added by the author.\n * @param {Element} el\n */\n function removeFocusVisibleClass(el) {\n if (!el.hasAttribute('data-focus-visible-added')) {\n return;\n }\n el.classList.remove('focus-visible');\n el.removeAttribute('data-focus-visible-added');\n }\n\n /**\n * If the most recent user interaction was via the keyboard;\n * and the key press did not include a meta, alt/option, or control key;\n * then the modality is keyboard. Otherwise, the modality is not keyboard.\n * Apply `focus-visible` to any current active element and keep track\n * of our keyboard modality state with `hadKeyboardEvent`.\n * @param {KeyboardEvent} e\n */\n function onKeyDown(e) {\n if (e.metaKey || e.altKey || e.ctrlKey) {\n return;\n }\n\n if (isValidFocusTarget(scope.activeElement)) {\n addFocusVisibleClass(scope.activeElement);\n }\n\n hadKeyboardEvent = true;\n }\n\n /**\n * If at any point a user clicks with a pointing device, ensure that we change\n * the modality away from keyboard.\n * This avoids the situation where a user presses a key on an already focused\n * element, and then clicks on a different element, focusing it with a\n * pointing device, while we still think we're in keyboard modality.\n * @param {Event} e\n */\n function onPointerDown(e) {\n hadKeyboardEvent = false;\n }\n\n /**\n * On `focus`, add the `focus-visible` class to the target if:\n * - the target received focus as a result of keyboard navigation, or\n * - the event target is an element that will likely require interaction\n * via the keyboard (e.g. a text box)\n * @param {Event} e\n */\n function onFocus(e) {\n // Prevent IE from focusing the document or HTML element.\n if (!isValidFocusTarget(e.target)) {\n return;\n }\n\n if (hadKeyboardEvent || focusTriggersKeyboardModality(e.target)) {\n addFocusVisibleClass(e.target);\n }\n }\n\n /**\n * On `blur`, remove the `focus-visible` class from the target.\n * @param {Event} e\n */\n function onBlur(e) {\n if (!isValidFocusTarget(e.target)) {\n return;\n }\n\n if (\n e.target.classList.contains('focus-visible') ||\n e.target.hasAttribute('data-focus-visible-added')\n ) {\n // To detect a tab/window switch, we look for a blur event followed\n // rapidly by a visibility change.\n // If we don't see a visibility change within 100ms, it's probably a\n // regular focus change.\n hadFocusVisibleRecently = true;\n window.clearTimeout(hadFocusVisibleRecentlyTimeout);\n hadFocusVisibleRecentlyTimeout = window.setTimeout(function() {\n hadFocusVisibleRecently = false;\n }, 100);\n removeFocusVisibleClass(e.target);\n }\n }\n\n /**\n * If the user changes tabs, keep track of whether or not the previously\n * focused element had .focus-visible.\n * @param {Event} e\n */\n function onVisibilityChange(e) {\n if (document.visibilityState === 'hidden') {\n // If the tab becomes active again, the browser will handle calling focus\n // on the element (Safari actually calls it twice).\n // If this tab change caused a blur on an element with focus-visible,\n // re-apply the class when the user switches back to the tab.\n if (hadFocusVisibleRecently) {\n hadKeyboardEvent = true;\n }\n addInitialPointerMoveListeners();\n }\n }\n\n /**\n * Add a group of listeners to detect usage of any pointing devices.\n * These listeners will be added when the polyfill first loads, and anytime\n * the window is blurred, so that they are active when the window regains\n * focus.\n */\n function addInitialPointerMoveListeners() {\n document.addEventListener('mousemove', onInitialPointerMove);\n document.addEventListener('mousedown', onInitialPointerMove);\n document.addEventListener('mouseup', onInitialPointerMove);\n document.addEventListener('pointermove', onInitialPointerMove);\n document.addEventListener('pointerdown', onInitialPointerMove);\n document.addEventListener('pointerup', onInitialPointerMove);\n document.addEventListener('touchmove', onInitialPointerMove);\n document.addEventListener('touchstart', onInitialPointerMove);\n document.addEventListener('touchend', onInitialPointerMove);\n }\n\n function removeInitialPointerMoveListeners() {\n document.removeEventListener('mousemove', onInitialPointerMove);\n document.removeEventListener('mousedown', onInitialPointerMove);\n document.removeEventListener('mouseup', onInitialPointerMove);\n document.removeEventListener('pointermove', onInitialPointerMove);\n document.removeEventListener('pointerdown', onInitialPointerMove);\n document.removeEventListener('pointerup', onInitialPointerMove);\n document.removeEventListener('touchmove', onInitialPointerMove);\n document.removeEventListener('touchstart', onInitialPointerMove);\n document.removeEventListener('touchend', onInitialPointerMove);\n }\n\n /**\n * When the polfyill first loads, assume the user is in keyboard modality.\n * If any event is received from a pointing device (e.g. mouse, pointer,\n * touch), turn off keyboard modality.\n * This accounts for situations where focus enters the page from the URL bar.\n * @param {Event} e\n */\n function onInitialPointerMove(e) {\n // Work around a Safari quirk that fires a mousemove on whenever the\n // window blurs, even if you're tabbing out of the page. \u00AF\\_(\u30C4)_/\u00AF\n if (e.target.nodeName && e.target.nodeName.toLowerCase() === 'html') {\n return;\n }\n\n hadKeyboardEvent = false;\n removeInitialPointerMoveListeners();\n }\n\n // For some kinds of state, we are interested in changes at the global scope\n // only. For example, global pointer input, global key presses and global\n // visibility change should affect the state at every scope:\n document.addEventListener('keydown', onKeyDown, true);\n document.addEventListener('mousedown', onPointerDown, true);\n document.addEventListener('pointerdown', onPointerDown, true);\n document.addEventListener('touchstart', onPointerDown, true);\n document.addEventListener('visibilitychange', onVisibilityChange, true);\n\n addInitialPointerMoveListeners();\n\n // For focus and blur, we specifically care about state changes in the local\n // scope. This is because focus / blur events that originate from within a\n // shadow root are not re-dispatched from the host element if it was already\n // the active element in its own scope:\n scope.addEventListener('focus', onFocus, true);\n scope.addEventListener('blur', onBlur, true);\n\n // We detect that a node is a ShadowRoot by ensuring that it is a\n // DocumentFragment and also has a host property. This check covers native\n // implementation and polyfill implementation transparently. If we only cared\n // about the native implementation, we could just check if the scope was\n // an instance of a ShadowRoot.\n if (scope.nodeType === Node.DOCUMENT_FRAGMENT_NODE && scope.host) {\n // Since a ShadowRoot is a special kind of DocumentFragment, it does not\n // have a root element to add a class to. So, we add this attribute to the\n // host element instead:\n scope.host.setAttribute('data-js-focus-visible', '');\n } else if (scope.nodeType === Node.DOCUMENT_NODE) {\n document.documentElement.classList.add('js-focus-visible');\n document.documentElement.setAttribute('data-js-focus-visible', '');\n }\n }\n\n // It is important to wrap all references to global window and document in\n // these checks to support server-side rendering use cases\n // @see https://github.com/WICG/focus-visible/issues/199\n if (typeof window !== 'undefined' && typeof document !== 'undefined') {\n // Make the polyfill helper globally available. This can be used as a signal\n // to interested libraries that wish to coordinate with the polyfill for e.g.,\n // applying the polyfill to a shadow root:\n window.applyFocusVisiblePolyfill = applyFocusVisiblePolyfill;\n\n // Notify interested libraries of the polyfill's presence, in case the\n // polyfill was loaded lazily:\n var event;\n\n try {\n event = new CustomEvent('focus-visible-polyfill-ready');\n } catch (error) {\n // IE11 does not support using CustomEvent as a constructor directly:\n event = document.createEvent('CustomEvent');\n event.initCustomEvent('focus-visible-polyfill-ready', false, false, {});\n }\n\n window.dispatchEvent(event);\n }\n\n if (typeof document !== 'undefined') {\n // Apply the polyfill to the global document, so that no JavaScript\n // coordination is required to use the polyfill in the top-level document:\n applyFocusVisiblePolyfill(document);\n }\n\n})));\n", "/*!\n * clipboard.js v2.0.11\n * https://clipboardjs.com/\n *\n * Licensed MIT \u00A9 Zeno Rocha\n */\n(function webpackUniversalModuleDefinition(root, factory) {\n\tif(typeof exports === 'object' && typeof module === 'object')\n\t\tmodule.exports = factory();\n\telse if(typeof define === 'function' && define.amd)\n\t\tdefine([], factory);\n\telse if(typeof exports === 'object')\n\t\texports[\"ClipboardJS\"] = factory();\n\telse\n\t\troot[\"ClipboardJS\"] = factory();\n})(this, function() {\nreturn /******/ (function() { // webpackBootstrap\n/******/ \tvar __webpack_modules__ = ({\n\n/***/ 686:\n/***/ (function(__unused_webpack_module, __webpack_exports__, __webpack_require__) {\n\n\"use strict\";\n\n// EXPORTS\n__webpack_require__.d(__webpack_exports__, {\n \"default\": function() { return /* binding */ clipboard; }\n});\n\n// EXTERNAL MODULE: ./node_modules/tiny-emitter/index.js\nvar tiny_emitter = __webpack_require__(279);\nvar tiny_emitter_default = /*#__PURE__*/__webpack_require__.n(tiny_emitter);\n// EXTERNAL MODULE: ./node_modules/good-listener/src/listen.js\nvar listen = __webpack_require__(370);\nvar listen_default = /*#__PURE__*/__webpack_require__.n(listen);\n// EXTERNAL MODULE: ./node_modules/select/src/select.js\nvar src_select = __webpack_require__(817);\nvar select_default = /*#__PURE__*/__webpack_require__.n(src_select);\n;// CONCATENATED MODULE: ./src/common/command.js\n/**\n * Executes a given operation type.\n * @param {String} type\n * @return {Boolean}\n */\nfunction command(type) {\n try {\n return document.execCommand(type);\n } catch (err) {\n return false;\n }\n}\n;// CONCATENATED MODULE: ./src/actions/cut.js\n\n\n/**\n * Cut action wrapper.\n * @param {String|HTMLElement} target\n * @return {String}\n */\n\nvar ClipboardActionCut = function ClipboardActionCut(target) {\n var selectedText = select_default()(target);\n command('cut');\n return selectedText;\n};\n\n/* harmony default export */ var actions_cut = (ClipboardActionCut);\n;// CONCATENATED MODULE: ./src/common/create-fake-element.js\n/**\n * Creates a fake textarea element with a value.\n * @param {String} value\n * @return {HTMLElement}\n */\nfunction createFakeElement(value) {\n var isRTL = document.documentElement.getAttribute('dir') === 'rtl';\n var fakeElement = document.createElement('textarea'); // Prevent zooming on iOS\n\n fakeElement.style.fontSize = '12pt'; // Reset box model\n\n fakeElement.style.border = '0';\n fakeElement.style.padding = '0';\n fakeElement.style.margin = '0'; // Move element out of screen horizontally\n\n fakeElement.style.position = 'absolute';\n fakeElement.style[isRTL ? 'right' : 'left'] = '-9999px'; // Move element to the same position vertically\n\n var yPosition = window.pageYOffset || document.documentElement.scrollTop;\n fakeElement.style.top = \"\".concat(yPosition, \"px\");\n fakeElement.setAttribute('readonly', '');\n fakeElement.value = value;\n return fakeElement;\n}\n;// CONCATENATED MODULE: ./src/actions/copy.js\n\n\n\n/**\n * Create fake copy action wrapper using a fake element.\n * @param {String} target\n * @param {Object} options\n * @return {String}\n */\n\nvar fakeCopyAction = function fakeCopyAction(value, options) {\n var fakeElement = createFakeElement(value);\n options.container.appendChild(fakeElement);\n var selectedText = select_default()(fakeElement);\n command('copy');\n fakeElement.remove();\n return selectedText;\n};\n/**\n * Copy action wrapper.\n * @param {String|HTMLElement} target\n * @param {Object} options\n * @return {String}\n */\n\n\nvar ClipboardActionCopy = function ClipboardActionCopy(target) {\n var options = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {\n container: document.body\n };\n var selectedText = '';\n\n if (typeof target === 'string') {\n selectedText = fakeCopyAction(target, options);\n } else if (target instanceof HTMLInputElement && !['text', 'search', 'url', 'tel', 'password'].includes(target === null || target === void 0 ? void 0 : target.type)) {\n // If input type doesn't support `setSelectionRange`. Simulate it. https://developer.mozilla.org/en-US/docs/Web/API/HTMLInputElement/setSelectionRange\n selectedText = fakeCopyAction(target.value, options);\n } else {\n selectedText = select_default()(target);\n command('copy');\n }\n\n return selectedText;\n};\n\n/* harmony default export */ var actions_copy = (ClipboardActionCopy);\n;// CONCATENATED MODULE: ./src/actions/default.js\nfunction _typeof(obj) { \"@babel/helpers - typeof\"; if (typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\") { _typeof = function _typeof(obj) { return typeof obj; }; } else { _typeof = function _typeof(obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; }; } return _typeof(obj); }\n\n\n\n/**\n * Inner function which performs selection from either `text` or `target`\n * properties and then executes copy or cut operations.\n * @param {Object} options\n */\n\nvar ClipboardActionDefault = function ClipboardActionDefault() {\n var options = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n // Defines base properties passed from constructor.\n var _options$action = options.action,\n action = _options$action === void 0 ? 'copy' : _options$action,\n container = options.container,\n target = options.target,\n text = options.text; // Sets the `action` to be performed which can be either 'copy' or 'cut'.\n\n if (action !== 'copy' && action !== 'cut') {\n throw new Error('Invalid \"action\" value, use either \"copy\" or \"cut\"');\n } // Sets the `target` property using an element that will be have its content copied.\n\n\n if (target !== undefined) {\n if (target && _typeof(target) === 'object' && target.nodeType === 1) {\n if (action === 'copy' && target.hasAttribute('disabled')) {\n throw new Error('Invalid \"target\" attribute. Please use \"readonly\" instead of \"disabled\" attribute');\n }\n\n if (action === 'cut' && (target.hasAttribute('readonly') || target.hasAttribute('disabled'))) {\n throw new Error('Invalid \"target\" attribute. You can\\'t cut text from elements with \"readonly\" or \"disabled\" attributes');\n }\n } else {\n throw new Error('Invalid \"target\" value, use a valid Element');\n }\n } // Define selection strategy based on `text` property.\n\n\n if (text) {\n return actions_copy(text, {\n container: container\n });\n } // Defines which selection strategy based on `target` property.\n\n\n if (target) {\n return action === 'cut' ? actions_cut(target) : actions_copy(target, {\n container: container\n });\n }\n};\n\n/* harmony default export */ var actions_default = (ClipboardActionDefault);\n;// CONCATENATED MODULE: ./src/clipboard.js\nfunction clipboard_typeof(obj) { \"@babel/helpers - typeof\"; if (typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\") { clipboard_typeof = function _typeof(obj) { return typeof obj; }; } else { clipboard_typeof = function _typeof(obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; }; } return clipboard_typeof(obj); }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } }\n\nfunction _createClass(Constructor, protoProps, staticProps) { if (protoProps) _defineProperties(Constructor.prototype, protoProps); if (staticProps) _defineProperties(Constructor, staticProps); return Constructor; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function\"); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, writable: true, configurable: true } }); if (superClass) _setPrototypeOf(subClass, superClass); }\n\nfunction _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf || function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }\n\nfunction _createSuper(Derived) { var hasNativeReflectConstruct = _isNativeReflectConstruct(); return function _createSuperInternal() { var Super = _getPrototypeOf(Derived), result; if (hasNativeReflectConstruct) { var NewTarget = _getPrototypeOf(this).constructor; result = Reflect.construct(Super, arguments, NewTarget); } else { result = Super.apply(this, arguments); } return _possibleConstructorReturn(this, result); }; }\n\nfunction _possibleConstructorReturn(self, call) { if (call && (clipboard_typeof(call) === \"object\" || typeof call === \"function\")) { return call; } return _assertThisInitialized(self); }\n\nfunction _assertThisInitialized(self) { if (self === void 0) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return self; }\n\nfunction _isNativeReflectConstruct() { if (typeof Reflect === \"undefined\" || !Reflect.construct) return false; if (Reflect.construct.sham) return false; if (typeof Proxy === \"function\") return true; try { Date.prototype.toString.call(Reflect.construct(Date, [], function () {})); return true; } catch (e) { return false; } }\n\nfunction _getPrototypeOf(o) { _getPrototypeOf = Object.setPrototypeOf ? Object.getPrototypeOf : function _getPrototypeOf(o) { return o.__proto__ || Object.getPrototypeOf(o); }; return _getPrototypeOf(o); }\n\n\n\n\n\n\n/**\n * Helper function to retrieve attribute value.\n * @param {String} suffix\n * @param {Element} element\n */\n\nfunction getAttributeValue(suffix, element) {\n var attribute = \"data-clipboard-\".concat(suffix);\n\n if (!element.hasAttribute(attribute)) {\n return;\n }\n\n return element.getAttribute(attribute);\n}\n/**\n * Base class which takes one or more elements, adds event listeners to them,\n * and instantiates a new `ClipboardAction` on each click.\n */\n\n\nvar Clipboard = /*#__PURE__*/function (_Emitter) {\n _inherits(Clipboard, _Emitter);\n\n var _super = _createSuper(Clipboard);\n\n /**\n * @param {String|HTMLElement|HTMLCollection|NodeList} trigger\n * @param {Object} options\n */\n function Clipboard(trigger, options) {\n var _this;\n\n _classCallCheck(this, Clipboard);\n\n _this = _super.call(this);\n\n _this.resolveOptions(options);\n\n _this.listenClick(trigger);\n\n return _this;\n }\n /**\n * Defines if attributes would be resolved using internal setter functions\n * or custom functions that were passed in the constructor.\n * @param {Object} options\n */\n\n\n _createClass(Clipboard, [{\n key: \"resolveOptions\",\n value: function resolveOptions() {\n var options = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n this.action = typeof options.action === 'function' ? options.action : this.defaultAction;\n this.target = typeof options.target === 'function' ? options.target : this.defaultTarget;\n this.text = typeof options.text === 'function' ? options.text : this.defaultText;\n this.container = clipboard_typeof(options.container) === 'object' ? options.container : document.body;\n }\n /**\n * Adds a click event listener to the passed trigger.\n * @param {String|HTMLElement|HTMLCollection|NodeList} trigger\n */\n\n }, {\n key: \"listenClick\",\n value: function listenClick(trigger) {\n var _this2 = this;\n\n this.listener = listen_default()(trigger, 'click', function (e) {\n return _this2.onClick(e);\n });\n }\n /**\n * Defines a new `ClipboardAction` on each click event.\n * @param {Event} e\n */\n\n }, {\n key: \"onClick\",\n value: function onClick(e) {\n var trigger = e.delegateTarget || e.currentTarget;\n var action = this.action(trigger) || 'copy';\n var text = actions_default({\n action: action,\n container: this.container,\n target: this.target(trigger),\n text: this.text(trigger)\n }); // Fires an event based on the copy operation result.\n\n this.emit(text ? 'success' : 'error', {\n action: action,\n text: text,\n trigger: trigger,\n clearSelection: function clearSelection() {\n if (trigger) {\n trigger.focus();\n }\n\n window.getSelection().removeAllRanges();\n }\n });\n }\n /**\n * Default `action` lookup function.\n * @param {Element} trigger\n */\n\n }, {\n key: \"defaultAction\",\n value: function defaultAction(trigger) {\n return getAttributeValue('action', trigger);\n }\n /**\n * Default `target` lookup function.\n * @param {Element} trigger\n */\n\n }, {\n key: \"defaultTarget\",\n value: function defaultTarget(trigger) {\n var selector = getAttributeValue('target', trigger);\n\n if (selector) {\n return document.querySelector(selector);\n }\n }\n /**\n * Allow fire programmatically a copy action\n * @param {String|HTMLElement} target\n * @param {Object} options\n * @returns Text copied.\n */\n\n }, {\n key: \"defaultText\",\n\n /**\n * Default `text` lookup function.\n * @param {Element} trigger\n */\n value: function defaultText(trigger) {\n return getAttributeValue('text', trigger);\n }\n /**\n * Destroy lifecycle.\n */\n\n }, {\n key: \"destroy\",\n value: function destroy() {\n this.listener.destroy();\n }\n }], [{\n key: \"copy\",\n value: function copy(target) {\n var options = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {\n container: document.body\n };\n return actions_copy(target, options);\n }\n /**\n * Allow fire programmatically a cut action\n * @param {String|HTMLElement} target\n * @returns Text cutted.\n */\n\n }, {\n key: \"cut\",\n value: function cut(target) {\n return actions_cut(target);\n }\n /**\n * Returns the support of the given action, or all actions if no action is\n * given.\n * @param {String} [action]\n */\n\n }, {\n key: \"isSupported\",\n value: function isSupported() {\n var action = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : ['copy', 'cut'];\n var actions = typeof action === 'string' ? [action] : action;\n var support = !!document.queryCommandSupported;\n actions.forEach(function (action) {\n support = support && !!document.queryCommandSupported(action);\n });\n return support;\n }\n }]);\n\n return Clipboard;\n}((tiny_emitter_default()));\n\n/* harmony default export */ var clipboard = (Clipboard);\n\n/***/ }),\n\n/***/ 828:\n/***/ (function(module) {\n\nvar DOCUMENT_NODE_TYPE = 9;\n\n/**\n * A polyfill for Element.matches()\n */\nif (typeof Element !== 'undefined' && !Element.prototype.matches) {\n var proto = Element.prototype;\n\n proto.matches = proto.matchesSelector ||\n proto.mozMatchesSelector ||\n proto.msMatchesSelector ||\n proto.oMatchesSelector ||\n proto.webkitMatchesSelector;\n}\n\n/**\n * Finds the closest parent that matches a selector.\n *\n * @param {Element} element\n * @param {String} selector\n * @return {Function}\n */\nfunction closest (element, selector) {\n while (element && element.nodeType !== DOCUMENT_NODE_TYPE) {\n if (typeof element.matches === 'function' &&\n element.matches(selector)) {\n return element;\n }\n element = element.parentNode;\n }\n}\n\nmodule.exports = closest;\n\n\n/***/ }),\n\n/***/ 438:\n/***/ (function(module, __unused_webpack_exports, __webpack_require__) {\n\nvar closest = __webpack_require__(828);\n\n/**\n * Delegates event to a selector.\n *\n * @param {Element} element\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @param {Boolean} useCapture\n * @return {Object}\n */\nfunction _delegate(element, selector, type, callback, useCapture) {\n var listenerFn = listener.apply(this, arguments);\n\n element.addEventListener(type, listenerFn, useCapture);\n\n return {\n destroy: function() {\n element.removeEventListener(type, listenerFn, useCapture);\n }\n }\n}\n\n/**\n * Delegates event to a selector.\n *\n * @param {Element|String|Array} [elements]\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @param {Boolean} useCapture\n * @return {Object}\n */\nfunction delegate(elements, selector, type, callback, useCapture) {\n // Handle the regular Element usage\n if (typeof elements.addEventListener === 'function') {\n return _delegate.apply(null, arguments);\n }\n\n // Handle Element-less usage, it defaults to global delegation\n if (typeof type === 'function') {\n // Use `document` as the first parameter, then apply arguments\n // This is a short way to .unshift `arguments` without running into deoptimizations\n return _delegate.bind(null, document).apply(null, arguments);\n }\n\n // Handle Selector-based usage\n if (typeof elements === 'string') {\n elements = document.querySelectorAll(elements);\n }\n\n // Handle Array-like based usage\n return Array.prototype.map.call(elements, function (element) {\n return _delegate(element, selector, type, callback, useCapture);\n });\n}\n\n/**\n * Finds closest match and invokes callback.\n *\n * @param {Element} element\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @return {Function}\n */\nfunction listener(element, selector, type, callback) {\n return function(e) {\n e.delegateTarget = closest(e.target, selector);\n\n if (e.delegateTarget) {\n callback.call(element, e);\n }\n }\n}\n\nmodule.exports = delegate;\n\n\n/***/ }),\n\n/***/ 879:\n/***/ (function(__unused_webpack_module, exports) {\n\n/**\n * Check if argument is a HTML element.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.node = function(value) {\n return value !== undefined\n && value instanceof HTMLElement\n && value.nodeType === 1;\n};\n\n/**\n * Check if argument is a list of HTML elements.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.nodeList = function(value) {\n var type = Object.prototype.toString.call(value);\n\n return value !== undefined\n && (type === '[object NodeList]' || type === '[object HTMLCollection]')\n && ('length' in value)\n && (value.length === 0 || exports.node(value[0]));\n};\n\n/**\n * Check if argument is a string.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.string = function(value) {\n return typeof value === 'string'\n || value instanceof String;\n};\n\n/**\n * Check if argument is a function.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.fn = function(value) {\n var type = Object.prototype.toString.call(value);\n\n return type === '[object Function]';\n};\n\n\n/***/ }),\n\n/***/ 370:\n/***/ (function(module, __unused_webpack_exports, __webpack_require__) {\n\nvar is = __webpack_require__(879);\nvar delegate = __webpack_require__(438);\n\n/**\n * Validates all params and calls the right\n * listener function based on its target type.\n *\n * @param {String|HTMLElement|HTMLCollection|NodeList} target\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listen(target, type, callback) {\n if (!target && !type && !callback) {\n throw new Error('Missing required arguments');\n }\n\n if (!is.string(type)) {\n throw new TypeError('Second argument must be a String');\n }\n\n if (!is.fn(callback)) {\n throw new TypeError('Third argument must be a Function');\n }\n\n if (is.node(target)) {\n return listenNode(target, type, callback);\n }\n else if (is.nodeList(target)) {\n return listenNodeList(target, type, callback);\n }\n else if (is.string(target)) {\n return listenSelector(target, type, callback);\n }\n else {\n throw new TypeError('First argument must be a String, HTMLElement, HTMLCollection, or NodeList');\n }\n}\n\n/**\n * Adds an event listener to a HTML element\n * and returns a remove listener function.\n *\n * @param {HTMLElement} node\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listenNode(node, type, callback) {\n node.addEventListener(type, callback);\n\n return {\n destroy: function() {\n node.removeEventListener(type, callback);\n }\n }\n}\n\n/**\n * Add an event listener to a list of HTML elements\n * and returns a remove listener function.\n *\n * @param {NodeList|HTMLCollection} nodeList\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listenNodeList(nodeList, type, callback) {\n Array.prototype.forEach.call(nodeList, function(node) {\n node.addEventListener(type, callback);\n });\n\n return {\n destroy: function() {\n Array.prototype.forEach.call(nodeList, function(node) {\n node.removeEventListener(type, callback);\n });\n }\n }\n}\n\n/**\n * Add an event listener to a selector\n * and returns a remove listener function.\n *\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listenSelector(selector, type, callback) {\n return delegate(document.body, selector, type, callback);\n}\n\nmodule.exports = listen;\n\n\n/***/ }),\n\n/***/ 817:\n/***/ (function(module) {\n\nfunction select(element) {\n var selectedText;\n\n if (element.nodeName === 'SELECT') {\n element.focus();\n\n selectedText = element.value;\n }\n else if (element.nodeName === 'INPUT' || element.nodeName === 'TEXTAREA') {\n var isReadOnly = element.hasAttribute('readonly');\n\n if (!isReadOnly) {\n element.setAttribute('readonly', '');\n }\n\n element.select();\n element.setSelectionRange(0, element.value.length);\n\n if (!isReadOnly) {\n element.removeAttribute('readonly');\n }\n\n selectedText = element.value;\n }\n else {\n if (element.hasAttribute('contenteditable')) {\n element.focus();\n }\n\n var selection = window.getSelection();\n var range = document.createRange();\n\n range.selectNodeContents(element);\n selection.removeAllRanges();\n selection.addRange(range);\n\n selectedText = selection.toString();\n }\n\n return selectedText;\n}\n\nmodule.exports = select;\n\n\n/***/ }),\n\n/***/ 279:\n/***/ (function(module) {\n\nfunction E () {\n // Keep this empty so it's easier to inherit from\n // (via https://github.com/lipsmack from https://github.com/scottcorgan/tiny-emitter/issues/3)\n}\n\nE.prototype = {\n on: function (name, callback, ctx) {\n var e = this.e || (this.e = {});\n\n (e[name] || (e[name] = [])).push({\n fn: callback,\n ctx: ctx\n });\n\n return this;\n },\n\n once: function (name, callback, ctx) {\n var self = this;\n function listener () {\n self.off(name, listener);\n callback.apply(ctx, arguments);\n };\n\n listener._ = callback\n return this.on(name, listener, ctx);\n },\n\n emit: function (name) {\n var data = [].slice.call(arguments, 1);\n var evtArr = ((this.e || (this.e = {}))[name] || []).slice();\n var i = 0;\n var len = evtArr.length;\n\n for (i; i < len; i++) {\n evtArr[i].fn.apply(evtArr[i].ctx, data);\n }\n\n return this;\n },\n\n off: function (name, callback) {\n var e = this.e || (this.e = {});\n var evts = e[name];\n var liveEvents = [];\n\n if (evts && callback) {\n for (var i = 0, len = evts.length; i < len; i++) {\n if (evts[i].fn !== callback && evts[i].fn._ !== callback)\n liveEvents.push(evts[i]);\n }\n }\n\n // Remove event from queue to prevent memory leak\n // Suggested by https://github.com/lazd\n // Ref: https://github.com/scottcorgan/tiny-emitter/commit/c6ebfaa9bc973b33d110a84a307742b7cf94c953#commitcomment-5024910\n\n (liveEvents.length)\n ? e[name] = liveEvents\n : delete e[name];\n\n return this;\n }\n};\n\nmodule.exports = E;\nmodule.exports.TinyEmitter = E;\n\n\n/***/ })\n\n/******/ \t});\n/************************************************************************/\n/******/ \t// The module cache\n/******/ \tvar __webpack_module_cache__ = {};\n/******/ \t\n/******/ \t// The require function\n/******/ \tfunction __webpack_require__(moduleId) {\n/******/ \t\t// Check if module is in cache\n/******/ \t\tif(__webpack_module_cache__[moduleId]) {\n/******/ \t\t\treturn __webpack_module_cache__[moduleId].exports;\n/******/ \t\t}\n/******/ \t\t// Create a new module (and put it into the cache)\n/******/ \t\tvar module = __webpack_module_cache__[moduleId] = {\n/******/ \t\t\t// no module.id needed\n/******/ \t\t\t// no module.loaded needed\n/******/ \t\t\texports: {}\n/******/ \t\t};\n/******/ \t\n/******/ \t\t// Execute the module function\n/******/ \t\t__webpack_modules__[moduleId](module, module.exports, __webpack_require__);\n/******/ \t\n/******/ \t\t// Return the exports of the module\n/******/ \t\treturn module.exports;\n/******/ \t}\n/******/ \t\n/************************************************************************/\n/******/ \t/* webpack/runtime/compat get default export */\n/******/ \t!function() {\n/******/ \t\t// getDefaultExport function for compatibility with non-harmony modules\n/******/ \t\t__webpack_require__.n = function(module) {\n/******/ \t\t\tvar getter = module && module.__esModule ?\n/******/ \t\t\t\tfunction() { return module['default']; } :\n/******/ \t\t\t\tfunction() { return module; };\n/******/ \t\t\t__webpack_require__.d(getter, { a: getter });\n/******/ \t\t\treturn getter;\n/******/ \t\t};\n/******/ \t}();\n/******/ \t\n/******/ \t/* webpack/runtime/define property getters */\n/******/ \t!function() {\n/******/ \t\t// define getter functions for harmony exports\n/******/ \t\t__webpack_require__.d = function(exports, definition) {\n/******/ \t\t\tfor(var key in definition) {\n/******/ \t\t\t\tif(__webpack_require__.o(definition, key) && !__webpack_require__.o(exports, key)) {\n/******/ \t\t\t\t\tObject.defineProperty(exports, key, { enumerable: true, get: definition[key] });\n/******/ \t\t\t\t}\n/******/ \t\t\t}\n/******/ \t\t};\n/******/ \t}();\n/******/ \t\n/******/ \t/* webpack/runtime/hasOwnProperty shorthand */\n/******/ \t!function() {\n/******/ \t\t__webpack_require__.o = function(obj, prop) { return Object.prototype.hasOwnProperty.call(obj, prop); }\n/******/ \t}();\n/******/ \t\n/************************************************************************/\n/******/ \t// module exports must be returned from runtime so entry inlining is disabled\n/******/ \t// startup\n/******/ \t// Load entry module and return exports\n/******/ \treturn __webpack_require__(686);\n/******/ })()\n.default;\n});", "/*!\n * escape-html\n * Copyright(c) 2012-2013 TJ Holowaychuk\n * Copyright(c) 2015 Andreas Lubbe\n * Copyright(c) 2015 Tiancheng \"Timothy\" Gu\n * MIT Licensed\n */\n\n'use strict';\n\n/**\n * Module variables.\n * @private\n */\n\nvar matchHtmlRegExp = /[\"'&<>]/;\n\n/**\n * Module exports.\n * @public\n */\n\nmodule.exports = escapeHtml;\n\n/**\n * Escape special characters in the given string of html.\n *\n * @param {string} string The string to escape for inserting into HTML\n * @return {string}\n * @public\n */\n\nfunction escapeHtml(string) {\n var str = '' + string;\n var match = matchHtmlRegExp.exec(str);\n\n if (!match) {\n return str;\n }\n\n var escape;\n var html = '';\n var index = 0;\n var lastIndex = 0;\n\n for (index = match.index; index < str.length; index++) {\n switch (str.charCodeAt(index)) {\n case 34: // \"\n escape = '"';\n break;\n case 38: // &\n escape = '&';\n break;\n case 39: // '\n escape = ''';\n break;\n case 60: // <\n escape = '<';\n break;\n case 62: // >\n escape = '>';\n break;\n default:\n continue;\n }\n\n if (lastIndex !== index) {\n html += str.substring(lastIndex, index);\n }\n\n lastIndex = index + 1;\n html += escape;\n }\n\n return lastIndex !== index\n ? html + str.substring(lastIndex, index)\n : html;\n}\n", "/*\n * Copyright (c) 2016-2024 Martin Donath \n *\n * Permission is hereby granted, free of charge, to any person obtaining a copy\n * of this software and associated documentation files (the \"Software\"), to\n * deal in the Software without restriction, including without limitation the\n * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or\n * sell copies of the Software, and to permit persons to whom the Software is\n * furnished to do so, subject to the following conditions:\n *\n * The above copyright notice and this permission notice shall be included in\n * all copies or substantial portions of the Software.\n *\n * THE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\n * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\n * FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT. IN NO EVENT SHALL THE\n * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\n * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING\n * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS\n * IN THE SOFTWARE.\n */\n\nimport \"focus-visible\"\n\nimport {\n EMPTY,\n NEVER,\n Observable,\n Subject,\n defer,\n delay,\n filter,\n map,\n merge,\n mergeWith,\n shareReplay,\n switchMap\n} from \"rxjs\"\n\nimport { configuration, feature } from \"./_\"\nimport {\n at,\n getActiveElement,\n getOptionalElement,\n requestJSON,\n setLocation,\n setToggle,\n watchDocument,\n watchKeyboard,\n watchLocation,\n watchLocationTarget,\n watchMedia,\n watchPrint,\n watchScript,\n watchViewport\n} from \"./browser\"\nimport {\n getComponentElement,\n getComponentElements,\n mountAnnounce,\n mountBackToTop,\n mountConsent,\n mountContent,\n mountDialog,\n mountHeader,\n mountHeaderTitle,\n mountPalette,\n mountProgress,\n mountSearch,\n mountSearchHiglight,\n mountSidebar,\n mountSource,\n mountTableOfContents,\n mountTabs,\n watchHeader,\n watchMain\n} from \"./components\"\nimport {\n SearchIndex,\n setupClipboardJS,\n setupInstantNavigation,\n setupVersionSelector\n} from \"./integrations\"\nimport {\n patchEllipsis,\n patchIndeterminate,\n patchScrollfix,\n patchScrolllock\n} from \"./patches\"\nimport \"./polyfills\"\n\n/* ----------------------------------------------------------------------------\n * Functions - @todo refactor\n * ------------------------------------------------------------------------- */\n\n/**\n * Fetch search index\n *\n * @returns Search index observable\n */\nfunction fetchSearchIndex(): Observable {\n if (location.protocol === \"file:\") {\n return watchScript(\n `${new URL(\"search/search_index.js\", config.base)}`\n )\n .pipe(\n // @ts-ignore - @todo fix typings\n map(() => __index),\n shareReplay(1)\n )\n } else {\n return requestJSON(\n new URL(\"search/search_index.json\", config.base)\n )\n }\n}\n\n/* ----------------------------------------------------------------------------\n * Application\n * ------------------------------------------------------------------------- */\n\n/* Yay, JavaScript is available */\ndocument.documentElement.classList.remove(\"no-js\")\ndocument.documentElement.classList.add(\"js\")\n\n/* Set up navigation observables and subjects */\nconst document$ = watchDocument()\nconst location$ = watchLocation()\nconst target$ = watchLocationTarget(location$)\nconst keyboard$ = watchKeyboard()\n\n/* Set up media observables */\nconst viewport$ = watchViewport()\nconst tablet$ = watchMedia(\"(min-width: 960px)\")\nconst screen$ = watchMedia(\"(min-width: 1220px)\")\nconst print$ = watchPrint()\n\n/* Retrieve search index, if search is enabled */\nconst config = configuration()\nconst index$ = document.forms.namedItem(\"search\")\n ? fetchSearchIndex()\n : NEVER\n\n/* Set up Clipboard.js integration */\nconst alert$ = new Subject()\nsetupClipboardJS({ alert$ })\n\n/* Set up progress indicator */\nconst progress$ = new Subject()\n\n/* Set up instant navigation, if enabled */\nif (feature(\"navigation.instant\"))\n setupInstantNavigation({ location$, viewport$, progress$ })\n .subscribe(document$)\n\n/* Set up version selector */\nif (config.version?.provider === \"mike\")\n setupVersionSelector({ document$ })\n\n/* Always close drawer and search on navigation */\nmerge(location$, target$)\n .pipe(\n delay(125)\n )\n .subscribe(() => {\n setToggle(\"drawer\", false)\n setToggle(\"search\", false)\n })\n\n/* Set up global keyboard handlers */\nkeyboard$\n .pipe(\n filter(({ mode }) => mode === \"global\")\n )\n .subscribe(key => {\n switch (key.type) {\n\n /* Go to previous page */\n case \"p\":\n case \",\":\n const prev = getOptionalElement(\"link[rel=prev]\")\n if (typeof prev !== \"undefined\")\n setLocation(prev)\n break\n\n /* Go to next page */\n case \"n\":\n case \".\":\n const next = getOptionalElement(\"link[rel=next]\")\n if (typeof next !== \"undefined\")\n setLocation(next)\n break\n\n /* Expand navigation, see https://bit.ly/3ZjG5io */\n case \"Enter\":\n const active = getActiveElement()\n if (active instanceof HTMLLabelElement)\n active.click()\n }\n })\n\n/* Set up patches */\npatchEllipsis({ viewport$, document$ })\npatchIndeterminate({ document$, tablet$ })\npatchScrollfix({ document$ })\npatchScrolllock({ viewport$, tablet$ })\n\n/* Set up header and main area observable */\nconst header$ = watchHeader(getComponentElement(\"header\"), { viewport$ })\nconst main$ = document$\n .pipe(\n map(() => getComponentElement(\"main\")),\n switchMap(el => watchMain(el, { viewport$, header$ })),\n shareReplay(1)\n )\n\n/* Set up control component observables */\nconst control$ = merge(\n\n /* Consent */\n ...getComponentElements(\"consent\")\n .map(el => mountConsent(el, { target$ })),\n\n /* Dialog */\n ...getComponentElements(\"dialog\")\n .map(el => mountDialog(el, { alert$ })),\n\n /* Header */\n ...getComponentElements(\"header\")\n .map(el => mountHeader(el, { viewport$, header$, main$ })),\n\n /* Color palette */\n ...getComponentElements(\"palette\")\n .map(el => mountPalette(el)),\n\n /* Progress bar */\n ...getComponentElements(\"progress\")\n .map(el => mountProgress(el, { progress$ })),\n\n /* Search */\n ...getComponentElements(\"search\")\n .map(el => mountSearch(el, { index$, keyboard$ })),\n\n /* Repository information */\n ...getComponentElements(\"source\")\n .map(el => mountSource(el))\n)\n\n/* Set up content component observables */\nconst content$ = defer(() => merge(\n\n /* Announcement bar */\n ...getComponentElements(\"announce\")\n .map(el => mountAnnounce(el)),\n\n /* Content */\n ...getComponentElements(\"content\")\n .map(el => mountContent(el, { viewport$, target$, print$ })),\n\n /* Search highlighting */\n ...getComponentElements(\"content\")\n .map(el => feature(\"search.highlight\")\n ? mountSearchHiglight(el, { index$, location$ })\n : EMPTY\n ),\n\n /* Header title */\n ...getComponentElements(\"header-title\")\n .map(el => mountHeaderTitle(el, { viewport$, header$ })),\n\n /* Sidebar */\n ...getComponentElements(\"sidebar\")\n .map(el => el.getAttribute(\"data-md-type\") === \"navigation\"\n ? at(screen$, () => mountSidebar(el, { viewport$, header$, main$ }))\n : at(tablet$, () => mountSidebar(el, { viewport$, header$, main$ }))\n ),\n\n /* Navigation tabs */\n ...getComponentElements(\"tabs\")\n .map(el => mountTabs(el, { viewport$, header$ })),\n\n /* Table of contents */\n ...getComponentElements(\"toc\")\n .map(el => mountTableOfContents(el, {\n viewport$, header$, main$, target$\n })),\n\n /* Back-to-top button */\n ...getComponentElements(\"top\")\n .map(el => mountBackToTop(el, { viewport$, header$, main$, target$ }))\n))\n\n/* Set up component observables */\nconst component$ = document$\n .pipe(\n switchMap(() => content$),\n mergeWith(control$),\n shareReplay(1)\n )\n\n/* Subscribe to all components */\ncomponent$.subscribe()\n\n/* ----------------------------------------------------------------------------\n * Exports\n * ------------------------------------------------------------------------- */\n\nwindow.document$ = document$ /* Document observable */\nwindow.location$ = location$ /* Location subject */\nwindow.target$ = target$ /* Location target observable */\nwindow.keyboard$ = keyboard$ /* Keyboard observable */\nwindow.viewport$ = viewport$ /* Viewport observable */\nwindow.tablet$ = tablet$ /* Media tablet observable */\nwindow.screen$ = screen$ /* Media screen observable */\nwindow.print$ = print$ /* Media print observable */\nwindow.alert$ = alert$ /* Alert subject */\nwindow.progress$ = progress$ /* Progress indicator subject */\nwindow.component$ = component$ /* Component observable */\n", "/*! *****************************************************************************\r\nCopyright (c) Microsoft Corporation.\r\n\r\nPermission to use, copy, modify, and/or distribute this software for any\r\npurpose with or without fee is hereby granted.\r\n\r\nTHE SOFTWARE IS PROVIDED \"AS IS\" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH\r\nREGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY\r\nAND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,\r\nINDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM\r\nLOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR\r\nOTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR\r\nPERFORMANCE OF THIS SOFTWARE.\r\n***************************************************************************** */\r\n/* global Reflect, Promise */\r\n\r\nvar extendStatics = function(d, b) {\r\n extendStatics = Object.setPrototypeOf ||\r\n ({ __proto__: [] } instanceof Array && function (d, b) { d.__proto__ = b; }) ||\r\n function (d, b) { for (var p in b) if (Object.prototype.hasOwnProperty.call(b, p)) d[p] = b[p]; };\r\n return extendStatics(d, b);\r\n};\r\n\r\nexport function __extends(d, b) {\r\n if (typeof b !== \"function\" && b !== null)\r\n throw new TypeError(\"Class extends value \" + String(b) + \" is not a constructor or null\");\r\n extendStatics(d, b);\r\n function __() { this.constructor = d; }\r\n d.prototype = b === null ? Object.create(b) : (__.prototype = b.prototype, new __());\r\n}\r\n\r\nexport var __assign = function() {\r\n __assign = Object.assign || function __assign(t) {\r\n for (var s, i = 1, n = arguments.length; i < n; i++) {\r\n s = arguments[i];\r\n for (var p in s) if (Object.prototype.hasOwnProperty.call(s, p)) t[p] = s[p];\r\n }\r\n return t;\r\n }\r\n return __assign.apply(this, arguments);\r\n}\r\n\r\nexport function __rest(s, e) {\r\n var t = {};\r\n for (var p in s) if (Object.prototype.hasOwnProperty.call(s, p) && e.indexOf(p) < 0)\r\n t[p] = s[p];\r\n if (s != null && typeof Object.getOwnPropertySymbols === \"function\")\r\n for (var i = 0, p = Object.getOwnPropertySymbols(s); i < p.length; i++) {\r\n if (e.indexOf(p[i]) < 0 && Object.prototype.propertyIsEnumerable.call(s, p[i]))\r\n t[p[i]] = s[p[i]];\r\n }\r\n return t;\r\n}\r\n\r\nexport function __decorate(decorators, target, key, desc) {\r\n var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d;\r\n if (typeof Reflect === \"object\" && typeof Reflect.decorate === \"function\") r = Reflect.decorate(decorators, target, key, desc);\r\n else for (var i = decorators.length - 1; i >= 0; i--) if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r;\r\n return c > 3 && r && Object.defineProperty(target, key, r), r;\r\n}\r\n\r\nexport function __param(paramIndex, decorator) {\r\n return function (target, key) { decorator(target, key, paramIndex); }\r\n}\r\n\r\nexport function __metadata(metadataKey, metadataValue) {\r\n if (typeof Reflect === \"object\" && typeof Reflect.metadata === \"function\") return Reflect.metadata(metadataKey, metadataValue);\r\n}\r\n\r\nexport function __awaiter(thisArg, _arguments, P, generator) {\r\n function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }\r\n return new (P || (P = Promise))(function (resolve, reject) {\r\n function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }\r\n function rejected(value) { try { step(generator[\"throw\"](value)); } catch (e) { reject(e); } }\r\n function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }\r\n step((generator = generator.apply(thisArg, _arguments || [])).next());\r\n });\r\n}\r\n\r\nexport function __generator(thisArg, body) {\r\n var _ = { label: 0, sent: function() { if (t[0] & 1) throw t[1]; return t[1]; }, trys: [], ops: [] }, f, y, t, g;\r\n return g = { next: verb(0), \"throw\": verb(1), \"return\": verb(2) }, typeof Symbol === \"function\" && (g[Symbol.iterator] = function() { return this; }), g;\r\n function verb(n) { return function (v) { return step([n, v]); }; }\r\n function step(op) {\r\n if (f) throw new TypeError(\"Generator is already executing.\");\r\n while (_) try {\r\n if (f = 1, y && (t = op[0] & 2 ? y[\"return\"] : op[0] ? y[\"throw\"] || ((t = y[\"return\"]) && t.call(y), 0) : y.next) && !(t = t.call(y, op[1])).done) return t;\r\n if (y = 0, t) op = [op[0] & 2, t.value];\r\n switch (op[0]) {\r\n case 0: case 1: t = op; break;\r\n case 4: _.label++; return { value: op[1], done: false };\r\n case 5: _.label++; y = op[1]; op = [0]; continue;\r\n case 7: op = _.ops.pop(); _.trys.pop(); continue;\r\n default:\r\n if (!(t = _.trys, t = t.length > 0 && t[t.length - 1]) && (op[0] === 6 || op[0] === 2)) { _ = 0; continue; }\r\n if (op[0] === 3 && (!t || (op[1] > t[0] && op[1] < t[3]))) { _.label = op[1]; break; }\r\n if (op[0] === 6 && _.label < t[1]) { _.label = t[1]; t = op; break; }\r\n if (t && _.label < t[2]) { _.label = t[2]; _.ops.push(op); break; }\r\n if (t[2]) _.ops.pop();\r\n _.trys.pop(); continue;\r\n }\r\n op = body.call(thisArg, _);\r\n } catch (e) { op = [6, e]; y = 0; } finally { f = t = 0; }\r\n if (op[0] & 5) throw op[1]; return { value: op[0] ? op[1] : void 0, done: true };\r\n }\r\n}\r\n\r\nexport var __createBinding = Object.create ? (function(o, m, k, k2) {\r\n if (k2 === undefined) k2 = k;\r\n Object.defineProperty(o, k2, { enumerable: true, get: function() { return m[k]; } });\r\n}) : (function(o, m, k, k2) {\r\n if (k2 === undefined) k2 = k;\r\n o[k2] = m[k];\r\n});\r\n\r\nexport function __exportStar(m, o) {\r\n for (var p in m) if (p !== \"default\" && !Object.prototype.hasOwnProperty.call(o, p)) __createBinding(o, m, p);\r\n}\r\n\r\nexport function __values(o) {\r\n var s = typeof Symbol === \"function\" && Symbol.iterator, m = s && o[s], i = 0;\r\n if (m) return m.call(o);\r\n if (o && typeof o.length === \"number\") return {\r\n next: function () {\r\n if (o && i >= o.length) o = void 0;\r\n return { value: o && o[i++], done: !o };\r\n }\r\n };\r\n throw new TypeError(s ? \"Object is not iterable.\" : \"Symbol.iterator is not defined.\");\r\n}\r\n\r\nexport function __read(o, n) {\r\n var m = typeof Symbol === \"function\" && o[Symbol.iterator];\r\n if (!m) return o;\r\n var i = m.call(o), r, ar = [], e;\r\n try {\r\n while ((n === void 0 || n-- > 0) && !(r = i.next()).done) ar.push(r.value);\r\n }\r\n catch (error) { e = { error: error }; }\r\n finally {\r\n try {\r\n if (r && !r.done && (m = i[\"return\"])) m.call(i);\r\n }\r\n finally { if (e) throw e.error; }\r\n }\r\n return ar;\r\n}\r\n\r\n/** @deprecated */\r\nexport function __spread() {\r\n for (var ar = [], i = 0; i < arguments.length; i++)\r\n ar = ar.concat(__read(arguments[i]));\r\n return ar;\r\n}\r\n\r\n/** @deprecated */\r\nexport function __spreadArrays() {\r\n for (var s = 0, i = 0, il = arguments.length; i < il; i++) s += arguments[i].length;\r\n for (var r = Array(s), k = 0, i = 0; i < il; i++)\r\n for (var a = arguments[i], j = 0, jl = a.length; j < jl; j++, k++)\r\n r[k] = a[j];\r\n return r;\r\n}\r\n\r\nexport function __spreadArray(to, from, pack) {\r\n if (pack || arguments.length === 2) for (var i = 0, l = from.length, ar; i < l; i++) {\r\n if (ar || !(i in from)) {\r\n if (!ar) ar = Array.prototype.slice.call(from, 0, i);\r\n ar[i] = from[i];\r\n }\r\n }\r\n return to.concat(ar || Array.prototype.slice.call(from));\r\n}\r\n\r\nexport function __await(v) {\r\n return this instanceof __await ? (this.v = v, this) : new __await(v);\r\n}\r\n\r\nexport function __asyncGenerator(thisArg, _arguments, generator) {\r\n if (!Symbol.asyncIterator) throw new TypeError(\"Symbol.asyncIterator is not defined.\");\r\n var g = generator.apply(thisArg, _arguments || []), i, q = [];\r\n return i = {}, verb(\"next\"), verb(\"throw\"), verb(\"return\"), i[Symbol.asyncIterator] = function () { return this; }, i;\r\n function verb(n) { if (g[n]) i[n] = function (v) { return new Promise(function (a, b) { q.push([n, v, a, b]) > 1 || resume(n, v); }); }; }\r\n function resume(n, v) { try { step(g[n](v)); } catch (e) { settle(q[0][3], e); } }\r\n function step(r) { r.value instanceof __await ? Promise.resolve(r.value.v).then(fulfill, reject) : settle(q[0][2], r); }\r\n function fulfill(value) { resume(\"next\", value); }\r\n function reject(value) { resume(\"throw\", value); }\r\n function settle(f, v) { if (f(v), q.shift(), q.length) resume(q[0][0], q[0][1]); }\r\n}\r\n\r\nexport function __asyncDelegator(o) {\r\n var i, p;\r\n return i = {}, verb(\"next\"), verb(\"throw\", function (e) { throw e; }), verb(\"return\"), i[Symbol.iterator] = function () { return this; }, i;\r\n function verb(n, f) { i[n] = o[n] ? function (v) { return (p = !p) ? { value: __await(o[n](v)), done: n === \"return\" } : f ? f(v) : v; } : f; }\r\n}\r\n\r\nexport function __asyncValues(o) {\r\n if (!Symbol.asyncIterator) throw new TypeError(\"Symbol.asyncIterator is not defined.\");\r\n var m = o[Symbol.asyncIterator], i;\r\n return m ? m.call(o) : (o = typeof __values === \"function\" ? __values(o) : o[Symbol.iterator](), i = {}, verb(\"next\"), verb(\"throw\"), verb(\"return\"), i[Symbol.asyncIterator] = function () { return this; }, i);\r\n function verb(n) { i[n] = o[n] && function (v) { return new Promise(function (resolve, reject) { v = o[n](v), settle(resolve, reject, v.done, v.value); }); }; }\r\n function settle(resolve, reject, d, v) { Promise.resolve(v).then(function(v) { resolve({ value: v, done: d }); }, reject); }\r\n}\r\n\r\nexport function __makeTemplateObject(cooked, raw) {\r\n if (Object.defineProperty) { Object.defineProperty(cooked, \"raw\", { value: raw }); } else { cooked.raw = raw; }\r\n return cooked;\r\n};\r\n\r\nvar __setModuleDefault = Object.create ? (function(o, v) {\r\n Object.defineProperty(o, \"default\", { enumerable: true, value: v });\r\n}) : function(o, v) {\r\n o[\"default\"] = v;\r\n};\r\n\r\nexport function __importStar(mod) {\r\n if (mod && mod.__esModule) return mod;\r\n var result = {};\r\n if (mod != null) for (var k in mod) if (k !== \"default\" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);\r\n __setModuleDefault(result, mod);\r\n return result;\r\n}\r\n\r\nexport function __importDefault(mod) {\r\n return (mod && mod.__esModule) ? mod : { default: mod };\r\n}\r\n\r\nexport function __classPrivateFieldGet(receiver, state, kind, f) {\r\n if (kind === \"a\" && !f) throw new TypeError(\"Private accessor was defined without a getter\");\r\n if (typeof state === \"function\" ? receiver !== state || !f : !state.has(receiver)) throw new TypeError(\"Cannot read private member from an object whose class did not declare it\");\r\n return kind === \"m\" ? f : kind === \"a\" ? f.call(receiver) : f ? f.value : state.get(receiver);\r\n}\r\n\r\nexport function __classPrivateFieldSet(receiver, state, value, kind, f) {\r\n if (kind === \"m\") throw new TypeError(\"Private method is not writable\");\r\n if (kind === \"a\" && !f) throw new TypeError(\"Private accessor was defined without a setter\");\r\n if (typeof state === \"function\" ? receiver !== state || !f : !state.has(receiver)) throw new TypeError(\"Cannot write private member to an object whose class did not declare it\");\r\n return (kind === \"a\" ? f.call(receiver, value) : f ? f.value = value : state.set(receiver, value)), value;\r\n}\r\n", "/**\n * Returns true if the object is a function.\n * @param value The value to check\n */\nexport function isFunction(value: any): value is (...args: any[]) => any {\n return typeof value === 'function';\n}\n", "/**\n * Used to create Error subclasses until the community moves away from ES5.\n *\n * This is because compiling from TypeScript down to ES5 has issues with subclassing Errors\n * as well as other built-in types: https://github.com/Microsoft/TypeScript/issues/12123\n *\n * @param createImpl A factory function to create the actual constructor implementation. The returned\n * function should be a named function that calls `_super` internally.\n */\nexport function createErrorClass(createImpl: (_super: any) => any): T {\n const _super = (instance: any) => {\n Error.call(instance);\n instance.stack = new Error().stack;\n };\n\n const ctorFunc = createImpl(_super);\n ctorFunc.prototype = Object.create(Error.prototype);\n ctorFunc.prototype.constructor = ctorFunc;\n return ctorFunc;\n}\n", "import { createErrorClass } from './createErrorClass';\n\nexport interface UnsubscriptionError extends Error {\n readonly errors: any[];\n}\n\nexport interface UnsubscriptionErrorCtor {\n /**\n * @deprecated Internal implementation detail. Do not construct error instances.\n * Cannot be tagged as internal: https://github.com/ReactiveX/rxjs/issues/6269\n */\n new (errors: any[]): UnsubscriptionError;\n}\n\n/**\n * An error thrown when one or more errors have occurred during the\n * `unsubscribe` of a {@link Subscription}.\n */\nexport const UnsubscriptionError: UnsubscriptionErrorCtor = createErrorClass(\n (_super) =>\n function UnsubscriptionErrorImpl(this: any, errors: (Error | string)[]) {\n _super(this);\n this.message = errors\n ? `${errors.length} errors occurred during unsubscription:\n${errors.map((err, i) => `${i + 1}) ${err.toString()}`).join('\\n ')}`\n : '';\n this.name = 'UnsubscriptionError';\n this.errors = errors;\n }\n);\n", "/**\n * Removes an item from an array, mutating it.\n * @param arr The array to remove the item from\n * @param item The item to remove\n */\nexport function arrRemove(arr: T[] | undefined | null, item: T) {\n if (arr) {\n const index = arr.indexOf(item);\n 0 <= index && arr.splice(index, 1);\n }\n}\n", "import { isFunction } from './util/isFunction';\nimport { UnsubscriptionError } from './util/UnsubscriptionError';\nimport { SubscriptionLike, TeardownLogic, Unsubscribable } from './types';\nimport { arrRemove } from './util/arrRemove';\n\n/**\n * Represents a disposable resource, such as the execution of an Observable. A\n * Subscription has one important method, `unsubscribe`, that takes no argument\n * and just disposes the resource held by the subscription.\n *\n * Additionally, subscriptions may be grouped together through the `add()`\n * method, which will attach a child Subscription to the current Subscription.\n * When a Subscription is unsubscribed, all its children (and its grandchildren)\n * will be unsubscribed as well.\n *\n * @class Subscription\n */\nexport class Subscription implements SubscriptionLike {\n /** @nocollapse */\n public static EMPTY = (() => {\n const empty = new Subscription();\n empty.closed = true;\n return empty;\n })();\n\n /**\n * A flag to indicate whether this Subscription has already been unsubscribed.\n */\n public closed = false;\n\n private _parentage: Subscription[] | Subscription | null = null;\n\n /**\n * The list of registered finalizers to execute upon unsubscription. Adding and removing from this\n * list occurs in the {@link #add} and {@link #remove} methods.\n */\n private _finalizers: Exclude[] | null = null;\n\n /**\n * @param initialTeardown A function executed first as part of the finalization\n * process that is kicked off when {@link #unsubscribe} is called.\n */\n constructor(private initialTeardown?: () => void) {}\n\n /**\n * Disposes the resources held by the subscription. May, for instance, cancel\n * an ongoing Observable execution or cancel any other type of work that\n * started when the Subscription was created.\n * @return {void}\n */\n unsubscribe(): void {\n let errors: any[] | undefined;\n\n if (!this.closed) {\n this.closed = true;\n\n // Remove this from it's parents.\n const { _parentage } = this;\n if (_parentage) {\n this._parentage = null;\n if (Array.isArray(_parentage)) {\n for (const parent of _parentage) {\n parent.remove(this);\n }\n } else {\n _parentage.remove(this);\n }\n }\n\n const { initialTeardown: initialFinalizer } = this;\n if (isFunction(initialFinalizer)) {\n try {\n initialFinalizer();\n } catch (e) {\n errors = e instanceof UnsubscriptionError ? e.errors : [e];\n }\n }\n\n const { _finalizers } = this;\n if (_finalizers) {\n this._finalizers = null;\n for (const finalizer of _finalizers) {\n try {\n execFinalizer(finalizer);\n } catch (err) {\n errors = errors ?? [];\n if (err instanceof UnsubscriptionError) {\n errors = [...errors, ...err.errors];\n } else {\n errors.push(err);\n }\n }\n }\n }\n\n if (errors) {\n throw new UnsubscriptionError(errors);\n }\n }\n }\n\n /**\n * Adds a finalizer to this subscription, so that finalization will be unsubscribed/called\n * when this subscription is unsubscribed. If this subscription is already {@link #closed},\n * because it has already been unsubscribed, then whatever finalizer is passed to it\n * will automatically be executed (unless the finalizer itself is also a closed subscription).\n *\n * Closed Subscriptions cannot be added as finalizers to any subscription. Adding a closed\n * subscription to a any subscription will result in no operation. (A noop).\n *\n * Adding a subscription to itself, or adding `null` or `undefined` will not perform any\n * operation at all. (A noop).\n *\n * `Subscription` instances that are added to this instance will automatically remove themselves\n * if they are unsubscribed. Functions and {@link Unsubscribable} objects that you wish to remove\n * will need to be removed manually with {@link #remove}\n *\n * @param teardown The finalization logic to add to this subscription.\n */\n add(teardown: TeardownLogic): void {\n // Only add the finalizer if it's not undefined\n // and don't add a subscription to itself.\n if (teardown && teardown !== this) {\n if (this.closed) {\n // If this subscription is already closed,\n // execute whatever finalizer is handed to it automatically.\n execFinalizer(teardown);\n } else {\n if (teardown instanceof Subscription) {\n // We don't add closed subscriptions, and we don't add the same subscription\n // twice. Subscription unsubscribe is idempotent.\n if (teardown.closed || teardown._hasParent(this)) {\n return;\n }\n teardown._addParent(this);\n }\n (this._finalizers = this._finalizers ?? []).push(teardown);\n }\n }\n }\n\n /**\n * Checks to see if a this subscription already has a particular parent.\n * This will signal that this subscription has already been added to the parent in question.\n * @param parent the parent to check for\n */\n private _hasParent(parent: Subscription) {\n const { _parentage } = this;\n return _parentage === parent || (Array.isArray(_parentage) && _parentage.includes(parent));\n }\n\n /**\n * Adds a parent to this subscription so it can be removed from the parent if it\n * unsubscribes on it's own.\n *\n * NOTE: THIS ASSUMES THAT {@link _hasParent} HAS ALREADY BEEN CHECKED.\n * @param parent The parent subscription to add\n */\n private _addParent(parent: Subscription) {\n const { _parentage } = this;\n this._parentage = Array.isArray(_parentage) ? (_parentage.push(parent), _parentage) : _parentage ? [_parentage, parent] : parent;\n }\n\n /**\n * Called on a child when it is removed via {@link #remove}.\n * @param parent The parent to remove\n */\n private _removeParent(parent: Subscription) {\n const { _parentage } = this;\n if (_parentage === parent) {\n this._parentage = null;\n } else if (Array.isArray(_parentage)) {\n arrRemove(_parentage, parent);\n }\n }\n\n /**\n * Removes a finalizer from this subscription that was previously added with the {@link #add} method.\n *\n * Note that `Subscription` instances, when unsubscribed, will automatically remove themselves\n * from every other `Subscription` they have been added to. This means that using the `remove` method\n * is not a common thing and should be used thoughtfully.\n *\n * If you add the same finalizer instance of a function or an unsubscribable object to a `Subscription` instance\n * more than once, you will need to call `remove` the same number of times to remove all instances.\n *\n * All finalizer instances are removed to free up memory upon unsubscription.\n *\n * @param teardown The finalizer to remove from this subscription\n */\n remove(teardown: Exclude): void {\n const { _finalizers } = this;\n _finalizers && arrRemove(_finalizers, teardown);\n\n if (teardown instanceof Subscription) {\n teardown._removeParent(this);\n }\n }\n}\n\nexport const EMPTY_SUBSCRIPTION = Subscription.EMPTY;\n\nexport function isSubscription(value: any): value is Subscription {\n return (\n value instanceof Subscription ||\n (value && 'closed' in value && isFunction(value.remove) && isFunction(value.add) && isFunction(value.unsubscribe))\n );\n}\n\nfunction execFinalizer(finalizer: Unsubscribable | (() => void)) {\n if (isFunction(finalizer)) {\n finalizer();\n } else {\n finalizer.unsubscribe();\n }\n}\n", "import { Subscriber } from './Subscriber';\nimport { ObservableNotification } from './types';\n\n/**\n * The {@link GlobalConfig} object for RxJS. It is used to configure things\n * like how to react on unhandled errors.\n */\nexport const config: GlobalConfig = {\n onUnhandledError: null,\n onStoppedNotification: null,\n Promise: undefined,\n useDeprecatedSynchronousErrorHandling: false,\n useDeprecatedNextContext: false,\n};\n\n/**\n * The global configuration object for RxJS, used to configure things\n * like how to react on unhandled errors. Accessible via {@link config}\n * object.\n */\nexport interface GlobalConfig {\n /**\n * A registration point for unhandled errors from RxJS. These are errors that\n * cannot were not handled by consuming code in the usual subscription path. For\n * example, if you have this configured, and you subscribe to an observable without\n * providing an error handler, errors from that subscription will end up here. This\n * will _always_ be called asynchronously on another job in the runtime. This is because\n * we do not want errors thrown in this user-configured handler to interfere with the\n * behavior of the library.\n */\n onUnhandledError: ((err: any) => void) | null;\n\n /**\n * A registration point for notifications that cannot be sent to subscribers because they\n * have completed, errored or have been explicitly unsubscribed. By default, next, complete\n * and error notifications sent to stopped subscribers are noops. However, sometimes callers\n * might want a different behavior. For example, with sources that attempt to report errors\n * to stopped subscribers, a caller can configure RxJS to throw an unhandled error instead.\n * This will _always_ be called asynchronously on another job in the runtime. This is because\n * we do not want errors thrown in this user-configured handler to interfere with the\n * behavior of the library.\n */\n onStoppedNotification: ((notification: ObservableNotification, subscriber: Subscriber) => void) | null;\n\n /**\n * The promise constructor used by default for {@link Observable#toPromise toPromise} and {@link Observable#forEach forEach}\n * methods.\n *\n * @deprecated As of version 8, RxJS will no longer support this sort of injection of a\n * Promise constructor. If you need a Promise implementation other than native promises,\n * please polyfill/patch Promise as you see appropriate. Will be removed in v8.\n */\n Promise?: PromiseConstructorLike;\n\n /**\n * If true, turns on synchronous error rethrowing, which is a deprecated behavior\n * in v6 and higher. This behavior enables bad patterns like wrapping a subscribe\n * call in a try/catch block. It also enables producer interference, a nasty bug\n * where a multicast can be broken for all observers by a downstream consumer with\n * an unhandled error. DO NOT USE THIS FLAG UNLESS IT'S NEEDED TO BUY TIME\n * FOR MIGRATION REASONS.\n *\n * @deprecated As of version 8, RxJS will no longer support synchronous throwing\n * of unhandled errors. All errors will be thrown on a separate call stack to prevent bad\n * behaviors described above. Will be removed in v8.\n */\n useDeprecatedSynchronousErrorHandling: boolean;\n\n /**\n * If true, enables an as-of-yet undocumented feature from v5: The ability to access\n * `unsubscribe()` via `this` context in `next` functions created in observers passed\n * to `subscribe`.\n *\n * This is being removed because the performance was severely problematic, and it could also cause\n * issues when types other than POJOs are passed to subscribe as subscribers, as they will likely have\n * their `this` context overwritten.\n *\n * @deprecated As of version 8, RxJS will no longer support altering the\n * context of next functions provided as part of an observer to Subscribe. Instead,\n * you will have access to a subscription or a signal or token that will allow you to do things like\n * unsubscribe and test closed status. Will be removed in v8.\n */\n useDeprecatedNextContext: boolean;\n}\n", "import type { TimerHandle } from './timerHandle';\ntype SetTimeoutFunction = (handler: () => void, timeout?: number, ...args: any[]) => TimerHandle;\ntype ClearTimeoutFunction = (handle: TimerHandle) => void;\n\ninterface TimeoutProvider {\n setTimeout: SetTimeoutFunction;\n clearTimeout: ClearTimeoutFunction;\n delegate:\n | {\n setTimeout: SetTimeoutFunction;\n clearTimeout: ClearTimeoutFunction;\n }\n | undefined;\n}\n\nexport const timeoutProvider: TimeoutProvider = {\n // When accessing the delegate, use the variable rather than `this` so that\n // the functions can be called without being bound to the provider.\n setTimeout(handler: () => void, timeout?: number, ...args) {\n const { delegate } = timeoutProvider;\n if (delegate?.setTimeout) {\n return delegate.setTimeout(handler, timeout, ...args);\n }\n return setTimeout(handler, timeout, ...args);\n },\n clearTimeout(handle) {\n const { delegate } = timeoutProvider;\n return (delegate?.clearTimeout || clearTimeout)(handle as any);\n },\n delegate: undefined,\n};\n", "import { config } from '../config';\nimport { timeoutProvider } from '../scheduler/timeoutProvider';\n\n/**\n * Handles an error on another job either with the user-configured {@link onUnhandledError},\n * or by throwing it on that new job so it can be picked up by `window.onerror`, `process.on('error')`, etc.\n *\n * This should be called whenever there is an error that is out-of-band with the subscription\n * or when an error hits a terminal boundary of the subscription and no error handler was provided.\n *\n * @param err the error to report\n */\nexport function reportUnhandledError(err: any) {\n timeoutProvider.setTimeout(() => {\n const { onUnhandledError } = config;\n if (onUnhandledError) {\n // Execute the user-configured error handler.\n onUnhandledError(err);\n } else {\n // Throw so it is picked up by the runtime's uncaught error mechanism.\n throw err;\n }\n });\n}\n", "/* tslint:disable:no-empty */\nexport function noop() { }\n", "import { CompleteNotification, NextNotification, ErrorNotification } from './types';\n\n/**\n * A completion object optimized for memory use and created to be the\n * same \"shape\" as other notifications in v8.\n * @internal\n */\nexport const COMPLETE_NOTIFICATION = (() => createNotification('C', undefined, undefined) as CompleteNotification)();\n\n/**\n * Internal use only. Creates an optimized error notification that is the same \"shape\"\n * as other notifications.\n * @internal\n */\nexport function errorNotification(error: any): ErrorNotification {\n return createNotification('E', undefined, error) as any;\n}\n\n/**\n * Internal use only. Creates an optimized next notification that is the same \"shape\"\n * as other notifications.\n * @internal\n */\nexport function nextNotification(value: T) {\n return createNotification('N', value, undefined) as NextNotification;\n}\n\n/**\n * Ensures that all notifications created internally have the same \"shape\" in v8.\n *\n * TODO: This is only exported to support a crazy legacy test in `groupBy`.\n * @internal\n */\nexport function createNotification(kind: 'N' | 'E' | 'C', value: any, error: any) {\n return {\n kind,\n value,\n error,\n };\n}\n", "import { config } from '../config';\n\nlet context: { errorThrown: boolean; error: any } | null = null;\n\n/**\n * Handles dealing with errors for super-gross mode. Creates a context, in which\n * any synchronously thrown errors will be passed to {@link captureError}. Which\n * will record the error such that it will be rethrown after the call back is complete.\n * TODO: Remove in v8\n * @param cb An immediately executed function.\n */\nexport function errorContext(cb: () => void) {\n if (config.useDeprecatedSynchronousErrorHandling) {\n const isRoot = !context;\n if (isRoot) {\n context = { errorThrown: false, error: null };\n }\n cb();\n if (isRoot) {\n const { errorThrown, error } = context!;\n context = null;\n if (errorThrown) {\n throw error;\n }\n }\n } else {\n // This is the general non-deprecated path for everyone that\n // isn't crazy enough to use super-gross mode (useDeprecatedSynchronousErrorHandling)\n cb();\n }\n}\n\n/**\n * Captures errors only in super-gross mode.\n * @param err the error to capture\n */\nexport function captureError(err: any) {\n if (config.useDeprecatedSynchronousErrorHandling && context) {\n context.errorThrown = true;\n context.error = err;\n }\n}\n", "import { isFunction } from './util/isFunction';\nimport { Observer, ObservableNotification } from './types';\nimport { isSubscription, Subscription } from './Subscription';\nimport { config } from './config';\nimport { reportUnhandledError } from './util/reportUnhandledError';\nimport { noop } from './util/noop';\nimport { nextNotification, errorNotification, COMPLETE_NOTIFICATION } from './NotificationFactories';\nimport { timeoutProvider } from './scheduler/timeoutProvider';\nimport { captureError } from './util/errorContext';\n\n/**\n * Implements the {@link Observer} interface and extends the\n * {@link Subscription} class. While the {@link Observer} is the public API for\n * consuming the values of an {@link Observable}, all Observers get converted to\n * a Subscriber, in order to provide Subscription-like capabilities such as\n * `unsubscribe`. Subscriber is a common type in RxJS, and crucial for\n * implementing operators, but it is rarely used as a public API.\n *\n * @class Subscriber\n */\nexport class Subscriber extends Subscription implements Observer {\n /**\n * A static factory for a Subscriber, given a (potentially partial) definition\n * of an Observer.\n * @param next The `next` callback of an Observer.\n * @param error The `error` callback of an\n * Observer.\n * @param complete The `complete` callback of an\n * Observer.\n * @return A Subscriber wrapping the (partially defined)\n * Observer represented by the given arguments.\n * @nocollapse\n * @deprecated Do not use. Will be removed in v8. There is no replacement for this\n * method, and there is no reason to be creating instances of `Subscriber` directly.\n * If you have a specific use case, please file an issue.\n */\n static create(next?: (x?: T) => void, error?: (e?: any) => void, complete?: () => void): Subscriber {\n return new SafeSubscriber(next, error, complete);\n }\n\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n protected isStopped: boolean = false;\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n protected destination: Subscriber | Observer; // this `any` is the escape hatch to erase extra type param (e.g. R)\n\n /**\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n * There is no reason to directly create an instance of Subscriber. This type is exported for typings reasons.\n */\n constructor(destination?: Subscriber | Observer) {\n super();\n if (destination) {\n this.destination = destination;\n // Automatically chain subscriptions together here.\n // if destination is a Subscription, then it is a Subscriber.\n if (isSubscription(destination)) {\n destination.add(this);\n }\n } else {\n this.destination = EMPTY_OBSERVER;\n }\n }\n\n /**\n * The {@link Observer} callback to receive notifications of type `next` from\n * the Observable, with a value. The Observable may call this method 0 or more\n * times.\n * @param {T} [value] The `next` value.\n * @return {void}\n */\n next(value?: T): void {\n if (this.isStopped) {\n handleStoppedNotification(nextNotification(value), this);\n } else {\n this._next(value!);\n }\n }\n\n /**\n * The {@link Observer} callback to receive notifications of type `error` from\n * the Observable, with an attached `Error`. Notifies the Observer that\n * the Observable has experienced an error condition.\n * @param {any} [err] The `error` exception.\n * @return {void}\n */\n error(err?: any): void {\n if (this.isStopped) {\n handleStoppedNotification(errorNotification(err), this);\n } else {\n this.isStopped = true;\n this._error(err);\n }\n }\n\n /**\n * The {@link Observer} callback to receive a valueless notification of type\n * `complete` from the Observable. Notifies the Observer that the Observable\n * has finished sending push-based notifications.\n * @return {void}\n */\n complete(): void {\n if (this.isStopped) {\n handleStoppedNotification(COMPLETE_NOTIFICATION, this);\n } else {\n this.isStopped = true;\n this._complete();\n }\n }\n\n unsubscribe(): void {\n if (!this.closed) {\n this.isStopped = true;\n super.unsubscribe();\n this.destination = null!;\n }\n }\n\n protected _next(value: T): void {\n this.destination.next(value);\n }\n\n protected _error(err: any): void {\n try {\n this.destination.error(err);\n } finally {\n this.unsubscribe();\n }\n }\n\n protected _complete(): void {\n try {\n this.destination.complete();\n } finally {\n this.unsubscribe();\n }\n }\n}\n\n/**\n * This bind is captured here because we want to be able to have\n * compatibility with monoid libraries that tend to use a method named\n * `bind`. In particular, a library called Monio requires this.\n */\nconst _bind = Function.prototype.bind;\n\nfunction bind any>(fn: Fn, thisArg: any): Fn {\n return _bind.call(fn, thisArg);\n}\n\n/**\n * Internal optimization only, DO NOT EXPOSE.\n * @internal\n */\nclass ConsumerObserver implements Observer {\n constructor(private partialObserver: Partial>) {}\n\n next(value: T): void {\n const { partialObserver } = this;\n if (partialObserver.next) {\n try {\n partialObserver.next(value);\n } catch (error) {\n handleUnhandledError(error);\n }\n }\n }\n\n error(err: any): void {\n const { partialObserver } = this;\n if (partialObserver.error) {\n try {\n partialObserver.error(err);\n } catch (error) {\n handleUnhandledError(error);\n }\n } else {\n handleUnhandledError(err);\n }\n }\n\n complete(): void {\n const { partialObserver } = this;\n if (partialObserver.complete) {\n try {\n partialObserver.complete();\n } catch (error) {\n handleUnhandledError(error);\n }\n }\n }\n}\n\nexport class SafeSubscriber extends Subscriber {\n constructor(\n observerOrNext?: Partial> | ((value: T) => void) | null,\n error?: ((e?: any) => void) | null,\n complete?: (() => void) | null\n ) {\n super();\n\n let partialObserver: Partial>;\n if (isFunction(observerOrNext) || !observerOrNext) {\n // The first argument is a function, not an observer. The next\n // two arguments *could* be observers, or they could be empty.\n partialObserver = {\n next: (observerOrNext ?? undefined) as (((value: T) => void) | undefined),\n error: error ?? undefined,\n complete: complete ?? undefined,\n };\n } else {\n // The first argument is a partial observer.\n let context: any;\n if (this && config.useDeprecatedNextContext) {\n // This is a deprecated path that made `this.unsubscribe()` available in\n // next handler functions passed to subscribe. This only exists behind a flag\n // now, as it is *very* slow.\n context = Object.create(observerOrNext);\n context.unsubscribe = () => this.unsubscribe();\n partialObserver = {\n next: observerOrNext.next && bind(observerOrNext.next, context),\n error: observerOrNext.error && bind(observerOrNext.error, context),\n complete: observerOrNext.complete && bind(observerOrNext.complete, context),\n };\n } else {\n // The \"normal\" path. Just use the partial observer directly.\n partialObserver = observerOrNext;\n }\n }\n\n // Wrap the partial observer to ensure it's a full observer, and\n // make sure proper error handling is accounted for.\n this.destination = new ConsumerObserver(partialObserver);\n }\n}\n\nfunction handleUnhandledError(error: any) {\n if (config.useDeprecatedSynchronousErrorHandling) {\n captureError(error);\n } else {\n // Ideal path, we report this as an unhandled error,\n // which is thrown on a new call stack.\n reportUnhandledError(error);\n }\n}\n\n/**\n * An error handler used when no error handler was supplied\n * to the SafeSubscriber -- meaning no error handler was supplied\n * do the `subscribe` call on our observable.\n * @param err The error to handle\n */\nfunction defaultErrorHandler(err: any) {\n throw err;\n}\n\n/**\n * A handler for notifications that cannot be sent to a stopped subscriber.\n * @param notification The notification being sent\n * @param subscriber The stopped subscriber\n */\nfunction handleStoppedNotification(notification: ObservableNotification, subscriber: Subscriber) {\n const { onStoppedNotification } = config;\n onStoppedNotification && timeoutProvider.setTimeout(() => onStoppedNotification(notification, subscriber));\n}\n\n/**\n * The observer used as a stub for subscriptions where the user did not\n * pass any arguments to `subscribe`. Comes with the default error handling\n * behavior.\n */\nexport const EMPTY_OBSERVER: Readonly> & { closed: true } = {\n closed: true,\n next: noop,\n error: defaultErrorHandler,\n complete: noop,\n};\n", "/**\n * Symbol.observable or a string \"@@observable\". Used for interop\n *\n * @deprecated We will no longer be exporting this symbol in upcoming versions of RxJS.\n * Instead polyfill and use Symbol.observable directly *or* use https://www.npmjs.com/package/symbol-observable\n */\nexport const observable: string | symbol = (() => (typeof Symbol === 'function' && Symbol.observable) || '@@observable')();\n", "/**\n * This function takes one parameter and just returns it. Simply put,\n * this is like `(x: T): T => x`.\n *\n * ## Examples\n *\n * This is useful in some cases when using things like `mergeMap`\n *\n * ```ts\n * import { interval, take, map, range, mergeMap, identity } from 'rxjs';\n *\n * const source$ = interval(1000).pipe(take(5));\n *\n * const result$ = source$.pipe(\n * map(i => range(i)),\n * mergeMap(identity) // same as mergeMap(x => x)\n * );\n *\n * result$.subscribe({\n * next: console.log\n * });\n * ```\n *\n * Or when you want to selectively apply an operator\n *\n * ```ts\n * import { interval, take, identity } from 'rxjs';\n *\n * const shouldLimit = () => Math.random() < 0.5;\n *\n * const source$ = interval(1000);\n *\n * const result$ = source$.pipe(shouldLimit() ? take(5) : identity);\n *\n * result$.subscribe({\n * next: console.log\n * });\n * ```\n *\n * @param x Any value that is returned by this function\n * @returns The value passed as the first parameter to this function\n */\nexport function identity(x: T): T {\n return x;\n}\n", "import { identity } from './identity';\nimport { UnaryFunction } from '../types';\n\nexport function pipe(): typeof identity;\nexport function pipe(fn1: UnaryFunction): UnaryFunction;\nexport function pipe(fn1: UnaryFunction, fn2: UnaryFunction): UnaryFunction;\nexport function pipe(fn1: UnaryFunction, fn2: UnaryFunction, fn3: UnaryFunction): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction,\n fn8: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction,\n fn8: UnaryFunction,\n fn9: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction,\n fn8: UnaryFunction,\n fn9: UnaryFunction,\n ...fns: UnaryFunction[]\n): UnaryFunction;\n\n/**\n * pipe() can be called on one or more functions, each of which can take one argument (\"UnaryFunction\")\n * and uses it to return a value.\n * It returns a function that takes one argument, passes it to the first UnaryFunction, and then\n * passes the result to the next one, passes that result to the next one, and so on. \n */\nexport function pipe(...fns: Array>): UnaryFunction {\n return pipeFromArray(fns);\n}\n\n/** @internal */\nexport function pipeFromArray(fns: Array>): UnaryFunction {\n if (fns.length === 0) {\n return identity as UnaryFunction;\n }\n\n if (fns.length === 1) {\n return fns[0];\n }\n\n return function piped(input: T): R {\n return fns.reduce((prev: any, fn: UnaryFunction) => fn(prev), input as any);\n };\n}\n", "import { Operator } from './Operator';\nimport { SafeSubscriber, Subscriber } from './Subscriber';\nimport { isSubscription, Subscription } from './Subscription';\nimport { TeardownLogic, OperatorFunction, Subscribable, Observer } from './types';\nimport { observable as Symbol_observable } from './symbol/observable';\nimport { pipeFromArray } from './util/pipe';\nimport { config } from './config';\nimport { isFunction } from './util/isFunction';\nimport { errorContext } from './util/errorContext';\n\n/**\n * A representation of any set of values over any amount of time. This is the most basic building block\n * of RxJS.\n *\n * @class Observable\n */\nexport class Observable implements Subscribable {\n /**\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n */\n source: Observable | undefined;\n\n /**\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n */\n operator: Operator | undefined;\n\n /**\n * @constructor\n * @param {Function} subscribe the function that is called when the Observable is\n * initially subscribed to. This function is given a Subscriber, to which new values\n * can be `next`ed, or an `error` method can be called to raise an error, or\n * `complete` can be called to notify of a successful completion.\n */\n constructor(subscribe?: (this: Observable, subscriber: Subscriber) => TeardownLogic) {\n if (subscribe) {\n this._subscribe = subscribe;\n }\n }\n\n // HACK: Since TypeScript inherits static properties too, we have to\n // fight against TypeScript here so Subject can have a different static create signature\n /**\n * Creates a new Observable by calling the Observable constructor\n * @owner Observable\n * @method create\n * @param {Function} subscribe? the subscriber function to be passed to the Observable constructor\n * @return {Observable} a new observable\n * @nocollapse\n * @deprecated Use `new Observable()` instead. Will be removed in v8.\n */\n static create: (...args: any[]) => any = (subscribe?: (subscriber: Subscriber) => TeardownLogic) => {\n return new Observable(subscribe);\n };\n\n /**\n * Creates a new Observable, with this Observable instance as the source, and the passed\n * operator defined as the new observable's operator.\n * @method lift\n * @param operator the operator defining the operation to take on the observable\n * @return a new observable with the Operator applied\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n * If you have implemented an operator using `lift`, it is recommended that you create an\n * operator by simply returning `new Observable()` directly. See \"Creating new operators from\n * scratch\" section here: https://rxjs.dev/guide/operators\n */\n lift(operator?: Operator): Observable {\n const observable = new Observable();\n observable.source = this;\n observable.operator = operator;\n return observable;\n }\n\n subscribe(observerOrNext?: Partial> | ((value: T) => void)): Subscription;\n /** @deprecated Instead of passing separate callback arguments, use an observer argument. Signatures taking separate callback arguments will be removed in v8. Details: https://rxjs.dev/deprecations/subscribe-arguments */\n subscribe(next?: ((value: T) => void) | null, error?: ((error: any) => void) | null, complete?: (() => void) | null): Subscription;\n /**\n * Invokes an execution of an Observable and registers Observer handlers for notifications it will emit.\n *\n * Use it when you have all these Observables, but still nothing is happening.\n *\n * `subscribe` is not a regular operator, but a method that calls Observable's internal `subscribe` function. It\n * might be for example a function that you passed to Observable's constructor, but most of the time it is\n * a library implementation, which defines what will be emitted by an Observable, and when it be will emitted. This means\n * that calling `subscribe` is actually the moment when Observable starts its work, not when it is created, as it is often\n * the thought.\n *\n * Apart from starting the execution of an Observable, this method allows you to listen for values\n * that an Observable emits, as well as for when it completes or errors. You can achieve this in two\n * of the following ways.\n *\n * The first way is creating an object that implements {@link Observer} interface. It should have methods\n * defined by that interface, but note that it should be just a regular JavaScript object, which you can create\n * yourself in any way you want (ES6 class, classic function constructor, object literal etc.). In particular, do\n * not attempt to use any RxJS implementation details to create Observers - you don't need them. Remember also\n * that your object does not have to implement all methods. If you find yourself creating a method that doesn't\n * do anything, you can simply omit it. Note however, if the `error` method is not provided and an error happens,\n * it will be thrown asynchronously. Errors thrown asynchronously cannot be caught using `try`/`catch`. Instead,\n * use the {@link onUnhandledError} configuration option or use a runtime handler (like `window.onerror` or\n * `process.on('error)`) to be notified of unhandled errors. Because of this, it's recommended that you provide\n * an `error` method to avoid missing thrown errors.\n *\n * The second way is to give up on Observer object altogether and simply provide callback functions in place of its methods.\n * This means you can provide three functions as arguments to `subscribe`, where the first function is equivalent\n * of a `next` method, the second of an `error` method and the third of a `complete` method. Just as in case of an Observer,\n * if you do not need to listen for something, you can omit a function by passing `undefined` or `null`,\n * since `subscribe` recognizes these functions by where they were placed in function call. When it comes\n * to the `error` function, as with an Observer, if not provided, errors emitted by an Observable will be thrown asynchronously.\n *\n * You can, however, subscribe with no parameters at all. This may be the case where you're not interested in terminal events\n * and you also handled emissions internally by using operators (e.g. using `tap`).\n *\n * Whichever style of calling `subscribe` you use, in both cases it returns a Subscription object.\n * This object allows you to call `unsubscribe` on it, which in turn will stop the work that an Observable does and will clean\n * up all resources that an Observable used. Note that cancelling a subscription will not call `complete` callback\n * provided to `subscribe` function, which is reserved for a regular completion signal that comes from an Observable.\n *\n * Remember that callbacks provided to `subscribe` are not guaranteed to be called asynchronously.\n * It is an Observable itself that decides when these functions will be called. For example {@link of}\n * by default emits all its values synchronously. Always check documentation for how given Observable\n * will behave when subscribed and if its default behavior can be modified with a `scheduler`.\n *\n * #### Examples\n *\n * Subscribe with an {@link guide/observer Observer}\n *\n * ```ts\n * import { of } from 'rxjs';\n *\n * const sumObserver = {\n * sum: 0,\n * next(value) {\n * console.log('Adding: ' + value);\n * this.sum = this.sum + value;\n * },\n * error() {\n * // We actually could just remove this method,\n * // since we do not really care about errors right now.\n * },\n * complete() {\n * console.log('Sum equals: ' + this.sum);\n * }\n * };\n *\n * of(1, 2, 3) // Synchronously emits 1, 2, 3 and then completes.\n * .subscribe(sumObserver);\n *\n * // Logs:\n * // 'Adding: 1'\n * // 'Adding: 2'\n * // 'Adding: 3'\n * // 'Sum equals: 6'\n * ```\n *\n * Subscribe with functions ({@link deprecations/subscribe-arguments deprecated})\n *\n * ```ts\n * import { of } from 'rxjs'\n *\n * let sum = 0;\n *\n * of(1, 2, 3).subscribe(\n * value => {\n * console.log('Adding: ' + value);\n * sum = sum + value;\n * },\n * undefined,\n * () => console.log('Sum equals: ' + sum)\n * );\n *\n * // Logs:\n * // 'Adding: 1'\n * // 'Adding: 2'\n * // 'Adding: 3'\n * // 'Sum equals: 6'\n * ```\n *\n * Cancel a subscription\n *\n * ```ts\n * import { interval } from 'rxjs';\n *\n * const subscription = interval(1000).subscribe({\n * next(num) {\n * console.log(num)\n * },\n * complete() {\n * // Will not be called, even when cancelling subscription.\n * console.log('completed!');\n * }\n * });\n *\n * setTimeout(() => {\n * subscription.unsubscribe();\n * console.log('unsubscribed!');\n * }, 2500);\n *\n * // Logs:\n * // 0 after 1s\n * // 1 after 2s\n * // 'unsubscribed!' after 2.5s\n * ```\n *\n * @param {Observer|Function} observerOrNext (optional) Either an observer with methods to be called,\n * or the first of three possible handlers, which is the handler for each value emitted from the subscribed\n * Observable.\n * @param {Function} error (optional) A handler for a terminal event resulting from an error. If no error handler is provided,\n * the error will be thrown asynchronously as unhandled.\n * @param {Function} complete (optional) A handler for a terminal event resulting from successful completion.\n * @return {Subscription} a subscription reference to the registered handlers\n * @method subscribe\n */\n subscribe(\n observerOrNext?: Partial> | ((value: T) => void) | null,\n error?: ((error: any) => void) | null,\n complete?: (() => void) | null\n ): Subscription {\n const subscriber = isSubscriber(observerOrNext) ? observerOrNext : new SafeSubscriber(observerOrNext, error, complete);\n\n errorContext(() => {\n const { operator, source } = this;\n subscriber.add(\n operator\n ? // We're dealing with a subscription in the\n // operator chain to one of our lifted operators.\n operator.call(subscriber, source)\n : source\n ? // If `source` has a value, but `operator` does not, something that\n // had intimate knowledge of our API, like our `Subject`, must have\n // set it. We're going to just call `_subscribe` directly.\n this._subscribe(subscriber)\n : // In all other cases, we're likely wrapping a user-provided initializer\n // function, so we need to catch errors and handle them appropriately.\n this._trySubscribe(subscriber)\n );\n });\n\n return subscriber;\n }\n\n /** @internal */\n protected _trySubscribe(sink: Subscriber): TeardownLogic {\n try {\n return this._subscribe(sink);\n } catch (err) {\n // We don't need to return anything in this case,\n // because it's just going to try to `add()` to a subscription\n // above.\n sink.error(err);\n }\n }\n\n /**\n * Used as a NON-CANCELLABLE means of subscribing to an observable, for use with\n * APIs that expect promises, like `async/await`. You cannot unsubscribe from this.\n *\n * **WARNING**: Only use this with observables you *know* will complete. If the source\n * observable does not complete, you will end up with a promise that is hung up, and\n * potentially all of the state of an async function hanging out in memory. To avoid\n * this situation, look into adding something like {@link timeout}, {@link take},\n * {@link takeWhile}, or {@link takeUntil} amongst others.\n *\n * #### Example\n *\n * ```ts\n * import { interval, take } from 'rxjs';\n *\n * const source$ = interval(1000).pipe(take(4));\n *\n * async function getTotal() {\n * let total = 0;\n *\n * await source$.forEach(value => {\n * total += value;\n * console.log('observable -> ' + value);\n * });\n *\n * return total;\n * }\n *\n * getTotal().then(\n * total => console.log('Total: ' + total)\n * );\n *\n * // Expected:\n * // 'observable -> 0'\n * // 'observable -> 1'\n * // 'observable -> 2'\n * // 'observable -> 3'\n * // 'Total: 6'\n * ```\n *\n * @param next a handler for each value emitted by the observable\n * @return a promise that either resolves on observable completion or\n * rejects with the handled error\n */\n forEach(next: (value: T) => void): Promise;\n\n /**\n * @param next a handler for each value emitted by the observable\n * @param promiseCtor a constructor function used to instantiate the Promise\n * @return a promise that either resolves on observable completion or\n * rejects with the handled error\n * @deprecated Passing a Promise constructor will no longer be available\n * in upcoming versions of RxJS. This is because it adds weight to the library, for very\n * little benefit. If you need this functionality, it is recommended that you either\n * polyfill Promise, or you create an adapter to convert the returned native promise\n * to whatever promise implementation you wanted. Will be removed in v8.\n */\n forEach(next: (value: T) => void, promiseCtor: PromiseConstructorLike): Promise;\n\n forEach(next: (value: T) => void, promiseCtor?: PromiseConstructorLike): Promise {\n promiseCtor = getPromiseCtor(promiseCtor);\n\n return new promiseCtor((resolve, reject) => {\n const subscriber = new SafeSubscriber({\n next: (value) => {\n try {\n next(value);\n } catch (err) {\n reject(err);\n subscriber.unsubscribe();\n }\n },\n error: reject,\n complete: resolve,\n });\n this.subscribe(subscriber);\n }) as Promise;\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): TeardownLogic {\n return this.source?.subscribe(subscriber);\n }\n\n /**\n * An interop point defined by the es7-observable spec https://github.com/zenparsing/es-observable\n * @method Symbol.observable\n * @return {Observable} this instance of the observable\n */\n [Symbol_observable]() {\n return this;\n }\n\n /* tslint:disable:max-line-length */\n pipe(): Observable;\n pipe(op1: OperatorFunction): Observable;\n pipe(op1: OperatorFunction, op2: OperatorFunction): Observable;\n pipe(op1: OperatorFunction, op2: OperatorFunction, op3: OperatorFunction): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction,\n op8: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction,\n op8: OperatorFunction,\n op9: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction,\n op8: OperatorFunction,\n op9: OperatorFunction,\n ...operations: OperatorFunction[]\n ): Observable;\n /* tslint:enable:max-line-length */\n\n /**\n * Used to stitch together functional operators into a chain.\n * @method pipe\n * @return {Observable} the Observable result of all of the operators having\n * been called in the order they were passed in.\n *\n * ## Example\n *\n * ```ts\n * import { interval, filter, map, scan } from 'rxjs';\n *\n * interval(1000)\n * .pipe(\n * filter(x => x % 2 === 0),\n * map(x => x + x),\n * scan((acc, x) => acc + x)\n * )\n * .subscribe(x => console.log(x));\n * ```\n */\n pipe(...operations: OperatorFunction[]): Observable {\n return pipeFromArray(operations)(this);\n }\n\n /* tslint:disable:max-line-length */\n /** @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise */\n toPromise(): Promise;\n /** @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise */\n toPromise(PromiseCtor: typeof Promise): Promise;\n /** @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise */\n toPromise(PromiseCtor: PromiseConstructorLike): Promise;\n /* tslint:enable:max-line-length */\n\n /**\n * Subscribe to this Observable and get a Promise resolving on\n * `complete` with the last emission (if any).\n *\n * **WARNING**: Only use this with observables you *know* will complete. If the source\n * observable does not complete, you will end up with a promise that is hung up, and\n * potentially all of the state of an async function hanging out in memory. To avoid\n * this situation, look into adding something like {@link timeout}, {@link take},\n * {@link takeWhile}, or {@link takeUntil} amongst others.\n *\n * @method toPromise\n * @param [promiseCtor] a constructor function used to instantiate\n * the Promise\n * @return A Promise that resolves with the last value emit, or\n * rejects on an error. If there were no emissions, Promise\n * resolves with undefined.\n * @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise\n */\n toPromise(promiseCtor?: PromiseConstructorLike): Promise {\n promiseCtor = getPromiseCtor(promiseCtor);\n\n return new promiseCtor((resolve, reject) => {\n let value: T | undefined;\n this.subscribe(\n (x: T) => (value = x),\n (err: any) => reject(err),\n () => resolve(value)\n );\n }) as Promise;\n }\n}\n\n/**\n * Decides between a passed promise constructor from consuming code,\n * A default configured promise constructor, and the native promise\n * constructor and returns it. If nothing can be found, it will throw\n * an error.\n * @param promiseCtor The optional promise constructor to passed by consuming code\n */\nfunction getPromiseCtor(promiseCtor: PromiseConstructorLike | undefined) {\n return promiseCtor ?? config.Promise ?? Promise;\n}\n\nfunction isObserver(value: any): value is Observer {\n return value && isFunction(value.next) && isFunction(value.error) && isFunction(value.complete);\n}\n\nfunction isSubscriber(value: any): value is Subscriber {\n return (value && value instanceof Subscriber) || (isObserver(value) && isSubscription(value));\n}\n", "import { Observable } from '../Observable';\nimport { Subscriber } from '../Subscriber';\nimport { OperatorFunction } from '../types';\nimport { isFunction } from './isFunction';\n\n/**\n * Used to determine if an object is an Observable with a lift function.\n */\nexport function hasLift(source: any): source is { lift: InstanceType['lift'] } {\n return isFunction(source?.lift);\n}\n\n/**\n * Creates an `OperatorFunction`. Used to define operators throughout the library in a concise way.\n * @param init The logic to connect the liftedSource to the subscriber at the moment of subscription.\n */\nexport function operate(\n init: (liftedSource: Observable, subscriber: Subscriber) => (() => void) | void\n): OperatorFunction {\n return (source: Observable) => {\n if (hasLift(source)) {\n return source.lift(function (this: Subscriber, liftedSource: Observable) {\n try {\n return init(liftedSource, this);\n } catch (err) {\n this.error(err);\n }\n });\n }\n throw new TypeError('Unable to lift unknown Observable type');\n };\n}\n", "import { Subscriber } from '../Subscriber';\n\n/**\n * Creates an instance of an `OperatorSubscriber`.\n * @param destination The downstream subscriber.\n * @param onNext Handles next values, only called if this subscriber is not stopped or closed. Any\n * error that occurs in this function is caught and sent to the `error` method of this subscriber.\n * @param onError Handles errors from the subscription, any errors that occur in this handler are caught\n * and send to the `destination` error handler.\n * @param onComplete Handles completion notification from the subscription. Any errors that occur in\n * this handler are sent to the `destination` error handler.\n * @param onFinalize Additional teardown logic here. This will only be called on teardown if the\n * subscriber itself is not already closed. This is called after all other teardown logic is executed.\n */\nexport function createOperatorSubscriber(\n destination: Subscriber,\n onNext?: (value: T) => void,\n onComplete?: () => void,\n onError?: (err: any) => void,\n onFinalize?: () => void\n): Subscriber {\n return new OperatorSubscriber(destination, onNext, onComplete, onError, onFinalize);\n}\n\n/**\n * A generic helper for allowing operators to be created with a Subscriber and\n * use closures to capture necessary state from the operator function itself.\n */\nexport class OperatorSubscriber extends Subscriber {\n /**\n * Creates an instance of an `OperatorSubscriber`.\n * @param destination The downstream subscriber.\n * @param onNext Handles next values, only called if this subscriber is not stopped or closed. Any\n * error that occurs in this function is caught and sent to the `error` method of this subscriber.\n * @param onError Handles errors from the subscription, any errors that occur in this handler are caught\n * and send to the `destination` error handler.\n * @param onComplete Handles completion notification from the subscription. Any errors that occur in\n * this handler are sent to the `destination` error handler.\n * @param onFinalize Additional finalization logic here. This will only be called on finalization if the\n * subscriber itself is not already closed. This is called after all other finalization logic is executed.\n * @param shouldUnsubscribe An optional check to see if an unsubscribe call should truly unsubscribe.\n * NOTE: This currently **ONLY** exists to support the strange behavior of {@link groupBy}, where unsubscription\n * to the resulting observable does not actually disconnect from the source if there are active subscriptions\n * to any grouped observable. (DO NOT EXPOSE OR USE EXTERNALLY!!!)\n */\n constructor(\n destination: Subscriber,\n onNext?: (value: T) => void,\n onComplete?: () => void,\n onError?: (err: any) => void,\n private onFinalize?: () => void,\n private shouldUnsubscribe?: () => boolean\n ) {\n // It's important - for performance reasons - that all of this class's\n // members are initialized and that they are always initialized in the same\n // order. This will ensure that all OperatorSubscriber instances have the\n // same hidden class in V8. This, in turn, will help keep the number of\n // hidden classes involved in property accesses within the base class as\n // low as possible. If the number of hidden classes involved exceeds four,\n // the property accesses will become megamorphic and performance penalties\n // will be incurred - i.e. inline caches won't be used.\n //\n // The reasons for ensuring all instances have the same hidden class are\n // further discussed in this blog post from Benedikt Meurer:\n // https://benediktmeurer.de/2018/03/23/impact-of-polymorphism-on-component-based-frameworks-like-react/\n super(destination);\n this._next = onNext\n ? function (this: OperatorSubscriber, value: T) {\n try {\n onNext(value);\n } catch (err) {\n destination.error(err);\n }\n }\n : super._next;\n this._error = onError\n ? function (this: OperatorSubscriber, err: any) {\n try {\n onError(err);\n } catch (err) {\n // Send any errors that occur down stream.\n destination.error(err);\n } finally {\n // Ensure finalization.\n this.unsubscribe();\n }\n }\n : super._error;\n this._complete = onComplete\n ? function (this: OperatorSubscriber) {\n try {\n onComplete();\n } catch (err) {\n // Send any errors that occur down stream.\n destination.error(err);\n } finally {\n // Ensure finalization.\n this.unsubscribe();\n }\n }\n : super._complete;\n }\n\n unsubscribe() {\n if (!this.shouldUnsubscribe || this.shouldUnsubscribe()) {\n const { closed } = this;\n super.unsubscribe();\n // Execute additional teardown if we have any and we didn't already do so.\n !closed && this.onFinalize?.();\n }\n }\n}\n", "import { Subscription } from '../Subscription';\n\ninterface AnimationFrameProvider {\n schedule(callback: FrameRequestCallback): Subscription;\n requestAnimationFrame: typeof requestAnimationFrame;\n cancelAnimationFrame: typeof cancelAnimationFrame;\n delegate:\n | {\n requestAnimationFrame: typeof requestAnimationFrame;\n cancelAnimationFrame: typeof cancelAnimationFrame;\n }\n | undefined;\n}\n\nexport const animationFrameProvider: AnimationFrameProvider = {\n // When accessing the delegate, use the variable rather than `this` so that\n // the functions can be called without being bound to the provider.\n schedule(callback) {\n let request = requestAnimationFrame;\n let cancel: typeof cancelAnimationFrame | undefined = cancelAnimationFrame;\n const { delegate } = animationFrameProvider;\n if (delegate) {\n request = delegate.requestAnimationFrame;\n cancel = delegate.cancelAnimationFrame;\n }\n const handle = request((timestamp) => {\n // Clear the cancel function. The request has been fulfilled, so\n // attempting to cancel the request upon unsubscription would be\n // pointless.\n cancel = undefined;\n callback(timestamp);\n });\n return new Subscription(() => cancel?.(handle));\n },\n requestAnimationFrame(...args) {\n const { delegate } = animationFrameProvider;\n return (delegate?.requestAnimationFrame || requestAnimationFrame)(...args);\n },\n cancelAnimationFrame(...args) {\n const { delegate } = animationFrameProvider;\n return (delegate?.cancelAnimationFrame || cancelAnimationFrame)(...args);\n },\n delegate: undefined,\n};\n", "import { createErrorClass } from './createErrorClass';\n\nexport interface ObjectUnsubscribedError extends Error {}\n\nexport interface ObjectUnsubscribedErrorCtor {\n /**\n * @deprecated Internal implementation detail. Do not construct error instances.\n * Cannot be tagged as internal: https://github.com/ReactiveX/rxjs/issues/6269\n */\n new (): ObjectUnsubscribedError;\n}\n\n/**\n * An error thrown when an action is invalid because the object has been\n * unsubscribed.\n *\n * @see {@link Subject}\n * @see {@link BehaviorSubject}\n *\n * @class ObjectUnsubscribedError\n */\nexport const ObjectUnsubscribedError: ObjectUnsubscribedErrorCtor = createErrorClass(\n (_super) =>\n function ObjectUnsubscribedErrorImpl(this: any) {\n _super(this);\n this.name = 'ObjectUnsubscribedError';\n this.message = 'object unsubscribed';\n }\n);\n", "import { Operator } from './Operator';\nimport { Observable } from './Observable';\nimport { Subscriber } from './Subscriber';\nimport { Subscription, EMPTY_SUBSCRIPTION } from './Subscription';\nimport { Observer, SubscriptionLike, TeardownLogic } from './types';\nimport { ObjectUnsubscribedError } from './util/ObjectUnsubscribedError';\nimport { arrRemove } from './util/arrRemove';\nimport { errorContext } from './util/errorContext';\n\n/**\n * A Subject is a special type of Observable that allows values to be\n * multicasted to many Observers. Subjects are like EventEmitters.\n *\n * Every Subject is an Observable and an Observer. You can subscribe to a\n * Subject, and you can call next to feed values as well as error and complete.\n */\nexport class Subject extends Observable implements SubscriptionLike {\n closed = false;\n\n private currentObservers: Observer[] | null = null;\n\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n observers: Observer[] = [];\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n isStopped = false;\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n hasError = false;\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n thrownError: any = null;\n\n /**\n * Creates a \"subject\" by basically gluing an observer to an observable.\n *\n * @nocollapse\n * @deprecated Recommended you do not use. Will be removed at some point in the future. Plans for replacement still under discussion.\n */\n static create: (...args: any[]) => any = (destination: Observer, source: Observable): AnonymousSubject => {\n return new AnonymousSubject(destination, source);\n };\n\n constructor() {\n // NOTE: This must be here to obscure Observable's constructor.\n super();\n }\n\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n lift(operator: Operator): Observable {\n const subject = new AnonymousSubject(this, this);\n subject.operator = operator as any;\n return subject as any;\n }\n\n /** @internal */\n protected _throwIfClosed() {\n if (this.closed) {\n throw new ObjectUnsubscribedError();\n }\n }\n\n next(value: T) {\n errorContext(() => {\n this._throwIfClosed();\n if (!this.isStopped) {\n if (!this.currentObservers) {\n this.currentObservers = Array.from(this.observers);\n }\n for (const observer of this.currentObservers) {\n observer.next(value);\n }\n }\n });\n }\n\n error(err: any) {\n errorContext(() => {\n this._throwIfClosed();\n if (!this.isStopped) {\n this.hasError = this.isStopped = true;\n this.thrownError = err;\n const { observers } = this;\n while (observers.length) {\n observers.shift()!.error(err);\n }\n }\n });\n }\n\n complete() {\n errorContext(() => {\n this._throwIfClosed();\n if (!this.isStopped) {\n this.isStopped = true;\n const { observers } = this;\n while (observers.length) {\n observers.shift()!.complete();\n }\n }\n });\n }\n\n unsubscribe() {\n this.isStopped = this.closed = true;\n this.observers = this.currentObservers = null!;\n }\n\n get observed() {\n return this.observers?.length > 0;\n }\n\n /** @internal */\n protected _trySubscribe(subscriber: Subscriber): TeardownLogic {\n this._throwIfClosed();\n return super._trySubscribe(subscriber);\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n this._throwIfClosed();\n this._checkFinalizedStatuses(subscriber);\n return this._innerSubscribe(subscriber);\n }\n\n /** @internal */\n protected _innerSubscribe(subscriber: Subscriber) {\n const { hasError, isStopped, observers } = this;\n if (hasError || isStopped) {\n return EMPTY_SUBSCRIPTION;\n }\n this.currentObservers = null;\n observers.push(subscriber);\n return new Subscription(() => {\n this.currentObservers = null;\n arrRemove(observers, subscriber);\n });\n }\n\n /** @internal */\n protected _checkFinalizedStatuses(subscriber: Subscriber) {\n const { hasError, thrownError, isStopped } = this;\n if (hasError) {\n subscriber.error(thrownError);\n } else if (isStopped) {\n subscriber.complete();\n }\n }\n\n /**\n * Creates a new Observable with this Subject as the source. You can do this\n * to create custom Observer-side logic of the Subject and conceal it from\n * code that uses the Observable.\n * @return {Observable} Observable that the Subject casts to\n */\n asObservable(): Observable {\n const observable: any = new Observable();\n observable.source = this;\n return observable;\n }\n}\n\n/**\n * @class AnonymousSubject\n */\nexport class AnonymousSubject extends Subject {\n constructor(\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n public destination?: Observer,\n source?: Observable\n ) {\n super();\n this.source = source;\n }\n\n next(value: T) {\n this.destination?.next?.(value);\n }\n\n error(err: any) {\n this.destination?.error?.(err);\n }\n\n complete() {\n this.destination?.complete?.();\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n return this.source?.subscribe(subscriber) ?? EMPTY_SUBSCRIPTION;\n }\n}\n", "import { Subject } from './Subject';\nimport { Subscriber } from './Subscriber';\nimport { Subscription } from './Subscription';\n\n/**\n * A variant of Subject that requires an initial value and emits its current\n * value whenever it is subscribed to.\n *\n * @class BehaviorSubject\n */\nexport class BehaviorSubject extends Subject {\n constructor(private _value: T) {\n super();\n }\n\n get value(): T {\n return this.getValue();\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n const subscription = super._subscribe(subscriber);\n !subscription.closed && subscriber.next(this._value);\n return subscription;\n }\n\n getValue(): T {\n const { hasError, thrownError, _value } = this;\n if (hasError) {\n throw thrownError;\n }\n this._throwIfClosed();\n return _value;\n }\n\n next(value: T): void {\n super.next((this._value = value));\n }\n}\n", "import { TimestampProvider } from '../types';\n\ninterface DateTimestampProvider extends TimestampProvider {\n delegate: TimestampProvider | undefined;\n}\n\nexport const dateTimestampProvider: DateTimestampProvider = {\n now() {\n // Use the variable rather than `this` so that the function can be called\n // without being bound to the provider.\n return (dateTimestampProvider.delegate || Date).now();\n },\n delegate: undefined,\n};\n", "import { Subject } from './Subject';\nimport { TimestampProvider } from './types';\nimport { Subscriber } from './Subscriber';\nimport { Subscription } from './Subscription';\nimport { dateTimestampProvider } from './scheduler/dateTimestampProvider';\n\n/**\n * A variant of {@link Subject} that \"replays\" old values to new subscribers by emitting them when they first subscribe.\n *\n * `ReplaySubject` has an internal buffer that will store a specified number of values that it has observed. Like `Subject`,\n * `ReplaySubject` \"observes\" values by having them passed to its `next` method. When it observes a value, it will store that\n * value for a time determined by the configuration of the `ReplaySubject`, as passed to its constructor.\n *\n * When a new subscriber subscribes to the `ReplaySubject` instance, it will synchronously emit all values in its buffer in\n * a First-In-First-Out (FIFO) manner. The `ReplaySubject` will also complete, if it has observed completion; and it will\n * error if it has observed an error.\n *\n * There are two main configuration items to be concerned with:\n *\n * 1. `bufferSize` - This will determine how many items are stored in the buffer, defaults to infinite.\n * 2. `windowTime` - The amount of time to hold a value in the buffer before removing it from the buffer.\n *\n * Both configurations may exist simultaneously. So if you would like to buffer a maximum of 3 values, as long as the values\n * are less than 2 seconds old, you could do so with a `new ReplaySubject(3, 2000)`.\n *\n * ### Differences with BehaviorSubject\n *\n * `BehaviorSubject` is similar to `new ReplaySubject(1)`, with a couple of exceptions:\n *\n * 1. `BehaviorSubject` comes \"primed\" with a single value upon construction.\n * 2. `ReplaySubject` will replay values, even after observing an error, where `BehaviorSubject` will not.\n *\n * @see {@link Subject}\n * @see {@link BehaviorSubject}\n * @see {@link shareReplay}\n */\nexport class ReplaySubject extends Subject {\n private _buffer: (T | number)[] = [];\n private _infiniteTimeWindow = true;\n\n /**\n * @param bufferSize The size of the buffer to replay on subscription\n * @param windowTime The amount of time the buffered items will stay buffered\n * @param timestampProvider An object with a `now()` method that provides the current timestamp. This is used to\n * calculate the amount of time something has been buffered.\n */\n constructor(\n private _bufferSize = Infinity,\n private _windowTime = Infinity,\n private _timestampProvider: TimestampProvider = dateTimestampProvider\n ) {\n super();\n this._infiniteTimeWindow = _windowTime === Infinity;\n this._bufferSize = Math.max(1, _bufferSize);\n this._windowTime = Math.max(1, _windowTime);\n }\n\n next(value: T): void {\n const { isStopped, _buffer, _infiniteTimeWindow, _timestampProvider, _windowTime } = this;\n if (!isStopped) {\n _buffer.push(value);\n !_infiniteTimeWindow && _buffer.push(_timestampProvider.now() + _windowTime);\n }\n this._trimBuffer();\n super.next(value);\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n this._throwIfClosed();\n this._trimBuffer();\n\n const subscription = this._innerSubscribe(subscriber);\n\n const { _infiniteTimeWindow, _buffer } = this;\n // We use a copy here, so reentrant code does not mutate our array while we're\n // emitting it to a new subscriber.\n const copy = _buffer.slice();\n for (let i = 0; i < copy.length && !subscriber.closed; i += _infiniteTimeWindow ? 1 : 2) {\n subscriber.next(copy[i] as T);\n }\n\n this._checkFinalizedStatuses(subscriber);\n\n return subscription;\n }\n\n private _trimBuffer() {\n const { _bufferSize, _timestampProvider, _buffer, _infiniteTimeWindow } = this;\n // If we don't have an infinite buffer size, and we're over the length,\n // use splice to truncate the old buffer values off. Note that we have to\n // double the size for instances where we're not using an infinite time window\n // because we're storing the values and the timestamps in the same array.\n const adjustedBufferSize = (_infiniteTimeWindow ? 1 : 2) * _bufferSize;\n _bufferSize < Infinity && adjustedBufferSize < _buffer.length && _buffer.splice(0, _buffer.length - adjustedBufferSize);\n\n // Now, if we're not in an infinite time window, remove all values where the time is\n // older than what is allowed.\n if (!_infiniteTimeWindow) {\n const now = _timestampProvider.now();\n let last = 0;\n // Search the array for the first timestamp that isn't expired and\n // truncate the buffer up to that point.\n for (let i = 1; i < _buffer.length && (_buffer[i] as number) <= now; i += 2) {\n last = i;\n }\n last && _buffer.splice(0, last + 1);\n }\n }\n}\n", "import { Scheduler } from '../Scheduler';\nimport { Subscription } from '../Subscription';\nimport { SchedulerAction } from '../types';\n\n/**\n * A unit of work to be executed in a `scheduler`. An action is typically\n * created from within a {@link SchedulerLike} and an RxJS user does not need to concern\n * themselves about creating and manipulating an Action.\n *\n * ```ts\n * class Action extends Subscription {\n * new (scheduler: Scheduler, work: (state?: T) => void);\n * schedule(state?: T, delay: number = 0): Subscription;\n * }\n * ```\n *\n * @class Action\n */\nexport class Action extends Subscription {\n constructor(scheduler: Scheduler, work: (this: SchedulerAction, state?: T) => void) {\n super();\n }\n /**\n * Schedules this action on its parent {@link SchedulerLike} for execution. May be passed\n * some context object, `state`. May happen at some point in the future,\n * according to the `delay` parameter, if specified.\n * @param {T} [state] Some contextual data that the `work` function uses when\n * called by the Scheduler.\n * @param {number} [delay] Time to wait before executing the work, where the\n * time unit is implicit and defined by the Scheduler.\n * @return {void}\n */\n public schedule(state?: T, delay: number = 0): Subscription {\n return this;\n }\n}\n", "import type { TimerHandle } from './timerHandle';\ntype SetIntervalFunction = (handler: () => void, timeout?: number, ...args: any[]) => TimerHandle;\ntype ClearIntervalFunction = (handle: TimerHandle) => void;\n\ninterface IntervalProvider {\n setInterval: SetIntervalFunction;\n clearInterval: ClearIntervalFunction;\n delegate:\n | {\n setInterval: SetIntervalFunction;\n clearInterval: ClearIntervalFunction;\n }\n | undefined;\n}\n\nexport const intervalProvider: IntervalProvider = {\n // When accessing the delegate, use the variable rather than `this` so that\n // the functions can be called without being bound to the provider.\n setInterval(handler: () => void, timeout?: number, ...args) {\n const { delegate } = intervalProvider;\n if (delegate?.setInterval) {\n return delegate.setInterval(handler, timeout, ...args);\n }\n return setInterval(handler, timeout, ...args);\n },\n clearInterval(handle) {\n const { delegate } = intervalProvider;\n return (delegate?.clearInterval || clearInterval)(handle as any);\n },\n delegate: undefined,\n};\n", "import { Action } from './Action';\nimport { SchedulerAction } from '../types';\nimport { Subscription } from '../Subscription';\nimport { AsyncScheduler } from './AsyncScheduler';\nimport { intervalProvider } from './intervalProvider';\nimport { arrRemove } from '../util/arrRemove';\nimport { TimerHandle } from './timerHandle';\n\nexport class AsyncAction extends Action {\n public id: TimerHandle | undefined;\n public state?: T;\n // @ts-ignore: Property has no initializer and is not definitely assigned\n public delay: number;\n protected pending: boolean = false;\n\n constructor(protected scheduler: AsyncScheduler, protected work: (this: SchedulerAction, state?: T) => void) {\n super(scheduler, work);\n }\n\n public schedule(state?: T, delay: number = 0): Subscription {\n if (this.closed) {\n return this;\n }\n\n // Always replace the current state with the new state.\n this.state = state;\n\n const id = this.id;\n const scheduler = this.scheduler;\n\n //\n // Important implementation note:\n //\n // Actions only execute once by default, unless rescheduled from within the\n // scheduled callback. This allows us to implement single and repeat\n // actions via the same code path, without adding API surface area, as well\n // as mimic traditional recursion but across asynchronous boundaries.\n //\n // However, JS runtimes and timers distinguish between intervals achieved by\n // serial `setTimeout` calls vs. a single `setInterval` call. An interval of\n // serial `setTimeout` calls can be individually delayed, which delays\n // scheduling the next `setTimeout`, and so on. `setInterval` attempts to\n // guarantee the interval callback will be invoked more precisely to the\n // interval period, regardless of load.\n //\n // Therefore, we use `setInterval` to schedule single and repeat actions.\n // If the action reschedules itself with the same delay, the interval is not\n // canceled. If the action doesn't reschedule, or reschedules with a\n // different delay, the interval will be canceled after scheduled callback\n // execution.\n //\n if (id != null) {\n this.id = this.recycleAsyncId(scheduler, id, delay);\n }\n\n // Set the pending flag indicating that this action has been scheduled, or\n // has recursively rescheduled itself.\n this.pending = true;\n\n this.delay = delay;\n // If this action has already an async Id, don't request a new one.\n this.id = this.id ?? this.requestAsyncId(scheduler, this.id, delay);\n\n return this;\n }\n\n protected requestAsyncId(scheduler: AsyncScheduler, _id?: TimerHandle, delay: number = 0): TimerHandle {\n return intervalProvider.setInterval(scheduler.flush.bind(scheduler, this), delay);\n }\n\n protected recycleAsyncId(_scheduler: AsyncScheduler, id?: TimerHandle, delay: number | null = 0): TimerHandle | undefined {\n // If this action is rescheduled with the same delay time, don't clear the interval id.\n if (delay != null && this.delay === delay && this.pending === false) {\n return id;\n }\n // Otherwise, if the action's delay time is different from the current delay,\n // or the action has been rescheduled before it's executed, clear the interval id\n if (id != null) {\n intervalProvider.clearInterval(id);\n }\n\n return undefined;\n }\n\n /**\n * Immediately executes this action and the `work` it contains.\n * @return {any}\n */\n public execute(state: T, delay: number): any {\n if (this.closed) {\n return new Error('executing a cancelled action');\n }\n\n this.pending = false;\n const error = this._execute(state, delay);\n if (error) {\n return error;\n } else if (this.pending === false && this.id != null) {\n // Dequeue if the action didn't reschedule itself. Don't call\n // unsubscribe(), because the action could reschedule later.\n // For example:\n // ```\n // scheduler.schedule(function doWork(counter) {\n // /* ... I'm a busy worker bee ... */\n // var originalAction = this;\n // /* wait 100ms before rescheduling the action */\n // setTimeout(function () {\n // originalAction.schedule(counter + 1);\n // }, 100);\n // }, 1000);\n // ```\n this.id = this.recycleAsyncId(this.scheduler, this.id, null);\n }\n }\n\n protected _execute(state: T, _delay: number): any {\n let errored: boolean = false;\n let errorValue: any;\n try {\n this.work(state);\n } catch (e) {\n errored = true;\n // HACK: Since code elsewhere is relying on the \"truthiness\" of the\n // return here, we can't have it return \"\" or 0 or false.\n // TODO: Clean this up when we refactor schedulers mid-version-8 or so.\n errorValue = e ? e : new Error('Scheduled action threw falsy error');\n }\n if (errored) {\n this.unsubscribe();\n return errorValue;\n }\n }\n\n unsubscribe() {\n if (!this.closed) {\n const { id, scheduler } = this;\n const { actions } = scheduler;\n\n this.work = this.state = this.scheduler = null!;\n this.pending = false;\n\n arrRemove(actions, this);\n if (id != null) {\n this.id = this.recycleAsyncId(scheduler, id, null);\n }\n\n this.delay = null!;\n super.unsubscribe();\n }\n }\n}\n", "import { Action } from './scheduler/Action';\nimport { Subscription } from './Subscription';\nimport { SchedulerLike, SchedulerAction } from './types';\nimport { dateTimestampProvider } from './scheduler/dateTimestampProvider';\n\n/**\n * An execution context and a data structure to order tasks and schedule their\n * execution. Provides a notion of (potentially virtual) time, through the\n * `now()` getter method.\n *\n * Each unit of work in a Scheduler is called an `Action`.\n *\n * ```ts\n * class Scheduler {\n * now(): number;\n * schedule(work, delay?, state?): Subscription;\n * }\n * ```\n *\n * @class Scheduler\n * @deprecated Scheduler is an internal implementation detail of RxJS, and\n * should not be used directly. Rather, create your own class and implement\n * {@link SchedulerLike}. Will be made internal in v8.\n */\nexport class Scheduler implements SchedulerLike {\n public static now: () => number = dateTimestampProvider.now;\n\n constructor(private schedulerActionCtor: typeof Action, now: () => number = Scheduler.now) {\n this.now = now;\n }\n\n /**\n * A getter method that returns a number representing the current time\n * (at the time this function was called) according to the scheduler's own\n * internal clock.\n * @return {number} A number that represents the current time. May or may not\n * have a relation to wall-clock time. May or may not refer to a time unit\n * (e.g. milliseconds).\n */\n public now: () => number;\n\n /**\n * Schedules a function, `work`, for execution. May happen at some point in\n * the future, according to the `delay` parameter, if specified. May be passed\n * some context object, `state`, which will be passed to the `work` function.\n *\n * The given arguments will be processed an stored as an Action object in a\n * queue of actions.\n *\n * @param {function(state: ?T): ?Subscription} work A function representing a\n * task, or some unit of work to be executed by the Scheduler.\n * @param {number} [delay] Time to wait before executing the work, where the\n * time unit is implicit and defined by the Scheduler itself.\n * @param {T} [state] Some contextual data that the `work` function uses when\n * called by the Scheduler.\n * @return {Subscription} A subscription in order to be able to unsubscribe\n * the scheduled work.\n */\n public schedule(work: (this: SchedulerAction, state?: T) => void, delay: number = 0, state?: T): Subscription {\n return new this.schedulerActionCtor(this, work).schedule(state, delay);\n }\n}\n", "import { Scheduler } from '../Scheduler';\nimport { Action } from './Action';\nimport { AsyncAction } from './AsyncAction';\nimport { TimerHandle } from './timerHandle';\n\nexport class AsyncScheduler extends Scheduler {\n public actions: Array> = [];\n /**\n * A flag to indicate whether the Scheduler is currently executing a batch of\n * queued actions.\n * @type {boolean}\n * @internal\n */\n public _active: boolean = false;\n /**\n * An internal ID used to track the latest asynchronous task such as those\n * coming from `setTimeout`, `setInterval`, `requestAnimationFrame`, and\n * others.\n * @type {any}\n * @internal\n */\n public _scheduled: TimerHandle | undefined;\n\n constructor(SchedulerAction: typeof Action, now: () => number = Scheduler.now) {\n super(SchedulerAction, now);\n }\n\n public flush(action: AsyncAction): void {\n const { actions } = this;\n\n if (this._active) {\n actions.push(action);\n return;\n }\n\n let error: any;\n this._active = true;\n\n do {\n if ((error = action.execute(action.state, action.delay))) {\n break;\n }\n } while ((action = actions.shift()!)); // exhaust the scheduler queue\n\n this._active = false;\n\n if (error) {\n while ((action = actions.shift()!)) {\n action.unsubscribe();\n }\n throw error;\n }\n }\n}\n", "import { AsyncAction } from './AsyncAction';\nimport { AsyncScheduler } from './AsyncScheduler';\n\n/**\n *\n * Async Scheduler\n *\n * Schedule task as if you used setTimeout(task, duration)\n *\n * `async` scheduler schedules tasks asynchronously, by putting them on the JavaScript\n * event loop queue. It is best used to delay tasks in time or to schedule tasks repeating\n * in intervals.\n *\n * If you just want to \"defer\" task, that is to perform it right after currently\n * executing synchronous code ends (commonly achieved by `setTimeout(deferredTask, 0)`),\n * better choice will be the {@link asapScheduler} scheduler.\n *\n * ## Examples\n * Use async scheduler to delay task\n * ```ts\n * import { asyncScheduler } from 'rxjs';\n *\n * const task = () => console.log('it works!');\n *\n * asyncScheduler.schedule(task, 2000);\n *\n * // After 2 seconds logs:\n * // \"it works!\"\n * ```\n *\n * Use async scheduler to repeat task in intervals\n * ```ts\n * import { asyncScheduler } from 'rxjs';\n *\n * function task(state) {\n * console.log(state);\n * this.schedule(state + 1, 1000); // `this` references currently executing Action,\n * // which we reschedule with new state and delay\n * }\n *\n * asyncScheduler.schedule(task, 3000, 0);\n *\n * // Logs:\n * // 0 after 3s\n * // 1 after 4s\n * // 2 after 5s\n * // 3 after 6s\n * ```\n */\n\nexport const asyncScheduler = new AsyncScheduler(AsyncAction);\n\n/**\n * @deprecated Renamed to {@link asyncScheduler}. Will be removed in v8.\n */\nexport const async = asyncScheduler;\n", "import { AsyncAction } from './AsyncAction';\nimport { Subscription } from '../Subscription';\nimport { QueueScheduler } from './QueueScheduler';\nimport { SchedulerAction } from '../types';\nimport { TimerHandle } from './timerHandle';\n\nexport class QueueAction extends AsyncAction {\n constructor(protected scheduler: QueueScheduler, protected work: (this: SchedulerAction, state?: T) => void) {\n super(scheduler, work);\n }\n\n public schedule(state?: T, delay: number = 0): Subscription {\n if (delay > 0) {\n return super.schedule(state, delay);\n }\n this.delay = delay;\n this.state = state;\n this.scheduler.flush(this);\n return this;\n }\n\n public execute(state: T, delay: number): any {\n return delay > 0 || this.closed ? super.execute(state, delay) : this._execute(state, delay);\n }\n\n protected requestAsyncId(scheduler: QueueScheduler, id?: TimerHandle, delay: number = 0): TimerHandle {\n // If delay exists and is greater than 0, or if the delay is null (the\n // action wasn't rescheduled) but was originally scheduled as an async\n // action, then recycle as an async action.\n\n if ((delay != null && delay > 0) || (delay == null && this.delay > 0)) {\n return super.requestAsyncId(scheduler, id, delay);\n }\n\n // Otherwise flush the scheduler starting with this action.\n scheduler.flush(this);\n\n // HACK: In the past, this was returning `void`. However, `void` isn't a valid\n // `TimerHandle`, and generally the return value here isn't really used. So the\n // compromise is to return `0` which is both \"falsy\" and a valid `TimerHandle`,\n // as opposed to refactoring every other instanceo of `requestAsyncId`.\n return 0;\n }\n}\n", "import { AsyncScheduler } from './AsyncScheduler';\n\nexport class QueueScheduler extends AsyncScheduler {\n}\n", "import { QueueAction } from './QueueAction';\nimport { QueueScheduler } from './QueueScheduler';\n\n/**\n *\n * Queue Scheduler\n *\n * Put every next task on a queue, instead of executing it immediately\n *\n * `queue` scheduler, when used with delay, behaves the same as {@link asyncScheduler} scheduler.\n *\n * When used without delay, it schedules given task synchronously - executes it right when\n * it is scheduled. However when called recursively, that is when inside the scheduled task,\n * another task is scheduled with queue scheduler, instead of executing immediately as well,\n * that task will be put on a queue and wait for current one to finish.\n *\n * This means that when you execute task with `queue` scheduler, you are sure it will end\n * before any other task scheduled with that scheduler will start.\n *\n * ## Examples\n * Schedule recursively first, then do something\n * ```ts\n * import { queueScheduler } from 'rxjs';\n *\n * queueScheduler.schedule(() => {\n * queueScheduler.schedule(() => console.log('second')); // will not happen now, but will be put on a queue\n *\n * console.log('first');\n * });\n *\n * // Logs:\n * // \"first\"\n * // \"second\"\n * ```\n *\n * Reschedule itself recursively\n * ```ts\n * import { queueScheduler } from 'rxjs';\n *\n * queueScheduler.schedule(function(state) {\n * if (state !== 0) {\n * console.log('before', state);\n * this.schedule(state - 1); // `this` references currently executing Action,\n * // which we reschedule with new state\n * console.log('after', state);\n * }\n * }, 0, 3);\n *\n * // In scheduler that runs recursively, you would expect:\n * // \"before\", 3\n * // \"before\", 2\n * // \"before\", 1\n * // \"after\", 1\n * // \"after\", 2\n * // \"after\", 3\n *\n * // But with queue it logs:\n * // \"before\", 3\n * // \"after\", 3\n * // \"before\", 2\n * // \"after\", 2\n * // \"before\", 1\n * // \"after\", 1\n * ```\n */\n\nexport const queueScheduler = new QueueScheduler(QueueAction);\n\n/**\n * @deprecated Renamed to {@link queueScheduler}. Will be removed in v8.\n */\nexport const queue = queueScheduler;\n", "import { AsyncAction } from './AsyncAction';\nimport { AnimationFrameScheduler } from './AnimationFrameScheduler';\nimport { SchedulerAction } from '../types';\nimport { animationFrameProvider } from './animationFrameProvider';\nimport { TimerHandle } from './timerHandle';\n\nexport class AnimationFrameAction extends AsyncAction {\n constructor(protected scheduler: AnimationFrameScheduler, protected work: (this: SchedulerAction, state?: T) => void) {\n super(scheduler, work);\n }\n\n protected requestAsyncId(scheduler: AnimationFrameScheduler, id?: TimerHandle, delay: number = 0): TimerHandle {\n // If delay is greater than 0, request as an async action.\n if (delay !== null && delay > 0) {\n return super.requestAsyncId(scheduler, id, delay);\n }\n // Push the action to the end of the scheduler queue.\n scheduler.actions.push(this);\n // If an animation frame has already been requested, don't request another\n // one. If an animation frame hasn't been requested yet, request one. Return\n // the current animation frame request id.\n return scheduler._scheduled || (scheduler._scheduled = animationFrameProvider.requestAnimationFrame(() => scheduler.flush(undefined)));\n }\n\n protected recycleAsyncId(scheduler: AnimationFrameScheduler, id?: TimerHandle, delay: number = 0): TimerHandle | undefined {\n // If delay exists and is greater than 0, or if the delay is null (the\n // action wasn't rescheduled) but was originally scheduled as an async\n // action, then recycle as an async action.\n if (delay != null ? delay > 0 : this.delay > 0) {\n return super.recycleAsyncId(scheduler, id, delay);\n }\n // If the scheduler queue has no remaining actions with the same async id,\n // cancel the requested animation frame and set the scheduled flag to\n // undefined so the next AnimationFrameAction will request its own.\n const { actions } = scheduler;\n if (id != null && actions[actions.length - 1]?.id !== id) {\n animationFrameProvider.cancelAnimationFrame(id as number);\n scheduler._scheduled = undefined;\n }\n // Return undefined so the action knows to request a new async id if it's rescheduled.\n return undefined;\n }\n}\n", "import { AsyncAction } from './AsyncAction';\nimport { AsyncScheduler } from './AsyncScheduler';\n\nexport class AnimationFrameScheduler extends AsyncScheduler {\n public flush(action?: AsyncAction): void {\n this._active = true;\n // The async id that effects a call to flush is stored in _scheduled.\n // Before executing an action, it's necessary to check the action's async\n // id to determine whether it's supposed to be executed in the current\n // flush.\n // Previous implementations of this method used a count to determine this,\n // but that was unsound, as actions that are unsubscribed - i.e. cancelled -\n // are removed from the actions array and that can shift actions that are\n // scheduled to be executed in a subsequent flush into positions at which\n // they are executed within the current flush.\n const flushId = this._scheduled;\n this._scheduled = undefined;\n\n const { actions } = this;\n let error: any;\n action = action || actions.shift()!;\n\n do {\n if ((error = action.execute(action.state, action.delay))) {\n break;\n }\n } while ((action = actions[0]) && action.id === flushId && actions.shift());\n\n this._active = false;\n\n if (error) {\n while ((action = actions[0]) && action.id === flushId && actions.shift()) {\n action.unsubscribe();\n }\n throw error;\n }\n }\n}\n", "import { AnimationFrameAction } from './AnimationFrameAction';\nimport { AnimationFrameScheduler } from './AnimationFrameScheduler';\n\n/**\n *\n * Animation Frame Scheduler\n *\n * Perform task when `window.requestAnimationFrame` would fire\n *\n * When `animationFrame` scheduler is used with delay, it will fall back to {@link asyncScheduler} scheduler\n * behaviour.\n *\n * Without delay, `animationFrame` scheduler can be used to create smooth browser animations.\n * It makes sure scheduled task will happen just before next browser content repaint,\n * thus performing animations as efficiently as possible.\n *\n * ## Example\n * Schedule div height animation\n * ```ts\n * // html:
\n * import { animationFrameScheduler } from 'rxjs';\n *\n * const div = document.querySelector('div');\n *\n * animationFrameScheduler.schedule(function(height) {\n * div.style.height = height + \"px\";\n *\n * this.schedule(height + 1); // `this` references currently executing Action,\n * // which we reschedule with new state\n * }, 0, 0);\n *\n * // You will see a div element growing in height\n * ```\n */\n\nexport const animationFrameScheduler = new AnimationFrameScheduler(AnimationFrameAction);\n\n/**\n * @deprecated Renamed to {@link animationFrameScheduler}. Will be removed in v8.\n */\nexport const animationFrame = animationFrameScheduler;\n", "import { Observable } from '../Observable';\nimport { SchedulerLike } from '../types';\n\n/**\n * A simple Observable that emits no items to the Observer and immediately\n * emits a complete notification.\n *\n * Just emits 'complete', and nothing else.\n *\n * ![](empty.png)\n *\n * A simple Observable that only emits the complete notification. It can be used\n * for composing with other Observables, such as in a {@link mergeMap}.\n *\n * ## Examples\n *\n * Log complete notification\n *\n * ```ts\n * import { EMPTY } from 'rxjs';\n *\n * EMPTY.subscribe({\n * next: () => console.log('Next'),\n * complete: () => console.log('Complete!')\n * });\n *\n * // Outputs\n * // Complete!\n * ```\n *\n * Emit the number 7, then complete\n *\n * ```ts\n * import { EMPTY, startWith } from 'rxjs';\n *\n * const result = EMPTY.pipe(startWith(7));\n * result.subscribe(x => console.log(x));\n *\n * // Outputs\n * // 7\n * ```\n *\n * Map and flatten only odd numbers to the sequence `'a'`, `'b'`, `'c'`\n *\n * ```ts\n * import { interval, mergeMap, of, EMPTY } from 'rxjs';\n *\n * const interval$ = interval(1000);\n * const result = interval$.pipe(\n * mergeMap(x => x % 2 === 1 ? of('a', 'b', 'c') : EMPTY),\n * );\n * result.subscribe(x => console.log(x));\n *\n * // Results in the following to the console:\n * // x is equal to the count on the interval, e.g. (0, 1, 2, 3, ...)\n * // x will occur every 1000ms\n * // if x % 2 is equal to 1, print a, b, c (each on its own)\n * // if x % 2 is not equal to 1, nothing will be output\n * ```\n *\n * @see {@link Observable}\n * @see {@link NEVER}\n * @see {@link of}\n * @see {@link throwError}\n */\nexport const EMPTY = new Observable((subscriber) => subscriber.complete());\n\n/**\n * @param scheduler A {@link SchedulerLike} to use for scheduling\n * the emission of the complete notification.\n * @deprecated Replaced with the {@link EMPTY} constant or {@link scheduled} (e.g. `scheduled([], scheduler)`). Will be removed in v8.\n */\nexport function empty(scheduler?: SchedulerLike) {\n return scheduler ? emptyScheduled(scheduler) : EMPTY;\n}\n\nfunction emptyScheduled(scheduler: SchedulerLike) {\n return new Observable((subscriber) => scheduler.schedule(() => subscriber.complete()));\n}\n", "import { SchedulerLike } from '../types';\nimport { isFunction } from './isFunction';\n\nexport function isScheduler(value: any): value is SchedulerLike {\n return value && isFunction(value.schedule);\n}\n", "import { SchedulerLike } from '../types';\nimport { isFunction } from './isFunction';\nimport { isScheduler } from './isScheduler';\n\nfunction last(arr: T[]): T | undefined {\n return arr[arr.length - 1];\n}\n\nexport function popResultSelector(args: any[]): ((...args: unknown[]) => unknown) | undefined {\n return isFunction(last(args)) ? args.pop() : undefined;\n}\n\nexport function popScheduler(args: any[]): SchedulerLike | undefined {\n return isScheduler(last(args)) ? args.pop() : undefined;\n}\n\nexport function popNumber(args: any[], defaultValue: number): number {\n return typeof last(args) === 'number' ? args.pop()! : defaultValue;\n}\n", "export const isArrayLike = ((x: any): x is ArrayLike => x && typeof x.length === 'number' && typeof x !== 'function');", "import { isFunction } from \"./isFunction\";\n\n/**\n * Tests to see if the object is \"thennable\".\n * @param value the object to test\n */\nexport function isPromise(value: any): value is PromiseLike {\n return isFunction(value?.then);\n}\n", "import { InteropObservable } from '../types';\nimport { observable as Symbol_observable } from '../symbol/observable';\nimport { isFunction } from './isFunction';\n\n/** Identifies an input as being Observable (but not necessary an Rx Observable) */\nexport function isInteropObservable(input: any): input is InteropObservable {\n return isFunction(input[Symbol_observable]);\n}\n", "import { isFunction } from './isFunction';\n\nexport function isAsyncIterable(obj: any): obj is AsyncIterable {\n return Symbol.asyncIterator && isFunction(obj?.[Symbol.asyncIterator]);\n}\n", "/**\n * Creates the TypeError to throw if an invalid object is passed to `from` or `scheduled`.\n * @param input The object that was passed.\n */\nexport function createInvalidObservableTypeError(input: any) {\n // TODO: We should create error codes that can be looked up, so this can be less verbose.\n return new TypeError(\n `You provided ${\n input !== null && typeof input === 'object' ? 'an invalid object' : `'${input}'`\n } where a stream was expected. You can provide an Observable, Promise, ReadableStream, Array, AsyncIterable, or Iterable.`\n );\n}\n", "export function getSymbolIterator(): symbol {\n if (typeof Symbol !== 'function' || !Symbol.iterator) {\n return '@@iterator' as any;\n }\n\n return Symbol.iterator;\n}\n\nexport const iterator = getSymbolIterator();\n", "import { iterator as Symbol_iterator } from '../symbol/iterator';\nimport { isFunction } from './isFunction';\n\n/** Identifies an input as being an Iterable */\nexport function isIterable(input: any): input is Iterable {\n return isFunction(input?.[Symbol_iterator]);\n}\n", "import { ReadableStreamLike } from '../types';\nimport { isFunction } from './isFunction';\n\nexport async function* readableStreamLikeToAsyncGenerator(readableStream: ReadableStreamLike): AsyncGenerator {\n const reader = readableStream.getReader();\n try {\n while (true) {\n const { value, done } = await reader.read();\n if (done) {\n return;\n }\n yield value!;\n }\n } finally {\n reader.releaseLock();\n }\n}\n\nexport function isReadableStreamLike(obj: any): obj is ReadableStreamLike {\n // We don't want to use instanceof checks because they would return\n // false for instances from another Realm, like an

+

slitaz

+

Probleme

+

1. Netzwerkadapter

+

Ich wusste nicht, wie ich mit den virtuellen Netzwerkadaptern umgehen musste. Ich habe einen NAT-Adapter und ein custom Netzwerksegment erstellt, doch mit dieser Konfiguration hatte ich keine Internetverbindung und dies lag daran, dass ich aus Versehen die ganze Konfiguration auf dem NAT-Adapter gemacht habe.

+

adapter

+

Weil ich den Überblick verloren habe, habe ich eine neue VM erstellt und mit einem NAT-Adapter + einem Vnet Adapter hinzugefügt. Den NAT-Adapter habe ich nicht angefasst, der diente nur zur Internetverbindung. Die ganze Konfiguration wurde auf dem Vnet Adapter vorgenommen (Vnet 5 in meinem Fall).

+

2. Gateway

+

gateway +Ich habe eine Konfiguration im Internet gefunden, welche eine alte (depprecated) Konfiguration hatte. Man muss mittlerweile mittels routes den gateway setzen.

+

3. Internetzugang Client

+

Nun habe ich festgestellt, dass die routes Option ein Fehler war, weil er versucht hat, über sich selbst zu routen und irgendeine zusätzliche Default Route gesetzt hat, die reingefunkt hat. Anschliessend habe die routes Option entfernt.

+

4. Internetzugang Server

+

Obwohl ich einen NAT-Adapter habe, kann ich mit dem DHCP-Server nicht mehr auf das Internet zugreifen. Ich konnte bis jetzt nicht herausfinden warum. Wir tun jetzt einfach so, als wäre es ein Security Feauture.
+It's not a bug, it's a feature - a clever human being

+

5. Wireshark

+

Zu Beginn habe ich nur ipconfig renew ausgeführt ohne ipconfig release. Dies hat dazu geführt, dass ich nur den Acknowledge und den Request sehen konnte, weil der Client sich die restlichen Informationen bereits gemerkt hatte. So konnte ich keine vernünftige Analyse durchführen.

+

Reflexion

+

Obwohl ich diese Aufgabe im Experts-Kurs bereits schon hatte, konnte ich doch etwas von diesem Auftrag profitieren. Grund dafür sind die Zusatzaufträge und der erweiterte Zeitrahmen für die Aufgabe.
+Ich habe dazugelernt:
+- DHCP Relay in betrieb nehmen
+- udchpd aufsetzen
+- DHCP Traffic mit Wireshark analysieren
+- Allgemein besseres Verständnis zu PXE & DHCP

+

Quellen

+ + + + + + + + + +
+
+
+ + + + \ No newline at end of file diff --git a/dns/downloadable/sephley_lookup.pcapng b/dns/downloadable/sephley_lookup.pcapng new file mode 100644 index 00000000..cbddea94 Binary files /dev/null and b/dns/downloadable/sephley_lookup.pcapng differ diff --git a/dns/downloadable/windows_dns.pcapng b/dns/downloadable/windows_dns.pcapng new file mode 100644 index 00000000..8e644398 Binary files /dev/null and b/dns/downloadable/windows_dns.pcapng differ diff --git a/dns/glossar/beginning/index.html b/dns/glossar/beginning/index.html new file mode 100644 index 00000000..98ab9069 --- /dev/null +++ b/dns/glossar/beginning/index.html @@ -0,0 +1,2303 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Anfänge-des-Internets - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Anfänge des Internets

+
    +
  • Recherchieren Sie über die Anfänge des Internets und setzen Sie die Primary / Secondary DNS-Infrastruktur in den Zusammenhang des redundanten dezentralen Konzepts.
  • +
+

Der Ursprung des DNS liegt in den frühen Tagen des Internets, als es noch ARPANET hiess und nur wenige Forscher und Institutionen miteinander vernetzt waren. Zu dieser Zeit wurden Hostnamen und ihre zugehörigen IP-Adressen in einer einzigen Datei namens "HOSTS.TXT" verwaltet, die zentral gepflegt wurde.

+

In den 1980er Jahren wurde das DNS-Konzept entwickelt, um diese Probleme zu lösen.

+

Im praktischen Teil können Sie sehen wie ich das implementiert habe, wobei ich keine geographische Verteilung implementiert habe, wäre aber eigentlich Teil des redundanten dezentralen Konzepts.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/glossar/dnsipv6/index.html b/dns/glossar/dnsipv6/index.html new file mode 100644 index 00000000..ea03f86a --- /dev/null +++ b/dns/glossar/dnsipv6/index.html @@ -0,0 +1,2360 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + DNS-unter-IPv6 - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

DNS unter IPv6

+
    +
  • DNS unter IPv6 – was ändert sich?
  • +
+

Reverse DNS unter IPv6

+
    +
  • Reverse DNS unter IPv6: https://tech.rana.at/2017/12/08/
  • +
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/glossar/dyndns/index.html b/dns/glossar/dyndns/index.html new file mode 100644 index 00000000..99d911c6 --- /dev/null +++ b/dns/glossar/dyndns/index.html @@ -0,0 +1,2409 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + DynDNS - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

DynDNS

+
    +
  • DynDNS hat einige spannende Probleme zu entdecken: Wie ist das mit den Timeouts? Wie lösen die das mit den vielen Anfragen? Wie ist DynDNS eigentlich entstanden?
  • +
+

DynDNS (Dynamic Domain Name System) ist ein Dienst, der es ermöglicht, eine ständig wechselnde IP-Adresse, wie sie bei vielen Internet Service Providern (ISPs) für Privatkunden üblich ist, mit einem festen Domainnamen zu verknüpfen.

+

Handling von Timeouts

+
    +
  • Update-Intervalle: Die Client-Software sendet regelmässig Updates, um sicherzustellen, dass die DNS-Einträge aktuell sind. Dies kann in festgelegten Intervallen (z.B. alle 5 Minuten) oder bei Erkennung einer IP-Änderung geschehen.
  • +
  • TTL (Time To Live): DNS-Einträge haben eine TTL, die bestimmt, wie lange ein DNS-Eintrag gecached werden darf. DynDNS setzt oft eine relativ kurze TTL (z.B. 300 Sekunden), um sicherzustellen, dass Änderungen schnell wirksam werden.
  • +
+

Handling von Anfragen

+
    +
  • Lastverteilung (Load Balancing): DynDNS-Dienste nutzen Lastverteilung, um eingehende Anfragen auf mehrere Server zu verteilen, was die Last auf einzelne Server reduziert.
  • +
  • Caching: DNS-Server und ISPs cachen DNS-Einträge für die Dauer der TTL, was die Anzahl der Anfragen an den DynDNS-Dienst reduziert.
  • +
  • Rate Limiting: Einige Dienste implementieren Rate Limiting, um die Anzahl der Updates von einzelnen Clients zu begrenzen und Missbrauch zu verhindern.
  • +
+

Beispiel

+

DynDNS (DDNS) ist sehr nützlich, wenn man von seinem ISP keine Statische Public IP erhält, aber trotzdem Dienste in einem lokalen Netzwerk veröffentlichen möchte. +In unserer geteilten Umgebung (Wyler, Oberle, Chio, Hurley) verwenden wir den DynDNS von Swisscom.
+swiss_ddns

+

So können wir mittels Cloudflare Zero Trust unsere Dienste verwalten und wenn nötig veröffentlichen.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/glossar/images/swiss_ddns.png b/dns/glossar/images/swiss_ddns.png new file mode 100644 index 00000000..356300d4 Binary files /dev/null and b/dns/glossar/images/swiss_ddns.png differ diff --git a/dns/glossar/index.html b/dns/glossar/index.html new file mode 100644 index 00000000..4074d9b1 --- /dev/null +++ b/dns/glossar/index.html @@ -0,0 +1,2302 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Glossar - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Glossar

+

Ich werde diesen Abschnitt referenzieren, wenn ich bei dem praktischen Teil etwas begründen oder belegen möchte. Hier ist nicht nur Theorie, sondern auch Beispiele aus meinem Geschäft sowie aus der Freizeit / persönlichen Umgebung.

+
    +
  • = fertig
  • +
  • = WIP
  • +
+

Checkliste der Aufträge gemäss Olat:

+
    +
  • Erklären Sie die Zonendatei inkl. allen Parametern im SOA.
  • +
  • Recherchieren Sie über die Anfänge des Internets und setzen Sie die Primary / Secondary DNS-Infrastruktur in den Zusammenhang des redundanten dezentralen Konzepts.
  • +
  • Recherchieren Sie verschiedene Record-Typen und erklären Sie diese.
  • +
  • DynDNS hat einige spannende Probleme zu entdecken: Wie ist das mit den Timeouts? Wie lösen die das mit den vielen Anfragen? Wie ist DynDNS eigentlich entstanden?
  • +
  • DNS unter IPv6 – was ändert sich?
  • +
  • Reverse DNS unter IPv6: https://tech.rana.at/2017/12/08/
  • +
+

Damit es nochmals geschrieben steht, DNS steht bedeutet ausgeschrieben: "Domain Name System".

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/glossar/primsec/index.html b/dns/glossar/primsec/index.html new file mode 100644 index 00000000..692edd91 --- /dev/null +++ b/dns/glossar/primsec/index.html @@ -0,0 +1,2301 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Primary-Secondary-Konzept - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Primary / Secondary Konzept

+
    +
  • Recherchieren Sie über die Anfänge des Internets und setzen Sie die Primary / Secondary DNS-Infrastruktur in den Zusammenhang des redundanten dezentralen Konzepts.
  • +
+

Wie Mario und Luigi, hat man Primary (master) und Secondary (slave) DNS-Server. Die Hauptaufgabe des sekundären DNS ist die Redundanz, falls der primäre ausfällt. Somit vermeidet man einen Single point of failure und man kann den Load aufteilen. Für den slave werden read-only kopien der Zonendateien eingesetzt und alle information erhaltet er direkt von dem primären DNS-Server.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/glossar/rectypes/index.html b/dns/glossar/rectypes/index.html new file mode 100644 index 00000000..16fd6b0c --- /dev/null +++ b/dns/glossar/rectypes/index.html @@ -0,0 +1,2346 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Record-Typen - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Record-Typen

+
    +
  • Recherchieren Sie verschiedene Record-Typen und erklären Sie diese.
  • +
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
RecordBeschreibungBeispiel
ADas "A" steht für Adresse. Dies ist der fundamentalste Bestandteil des DNS, denn er verbindet Domainnamen mit IP-Adressen.www IN A 192.168.1.4
AAAAGleich wie A, aber mit IPv6.www IN AAAA 2607:f8b0:400a:800::200e
CNAMECanonical Name record. CNAME Records können einem Domänen-Namen einen weiteren Namen zuweisen. Er wird oft dafür verwendet, Subdomänen wie www oder mail, der Domäne, die den Inhalt hostet zuzuordnen.www.sephley.local CNAME www.sephley.com
AliasWie ein CNAME record, können Alias Records einem Domänen-Namen einen weiteren Namen zuweisen. Allerdings können Aliases bestehen, auch wenn bereits ein Record mit demselben Namen existiert.@ IN ALIAS sephley.local.
MXMail Exchange Record. Sie leiten Mails an die dazugehörigen Server weiter und werden auch zur Priorisierung verwendetsephley.local. IN MX 10 mail.sephley.local.
NSNS steht für «Name Server». Er entscheidet, welcher DNS-Server massgeblich ist.@ IN NS primary.sephley.local.
PTRPTR steht für «Pointer» und macht das Gegenteil des A Records. Er kann IP-Adressen in Domain Namen verwandeln, was bedeutet das er in der Reverse-Zone verwendet wird.2 IN PTR primary.sephley.local
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/glossar/zonefile/index.html b/dns/glossar/zonefile/index.html new file mode 100644 index 00000000..b2a1308c --- /dev/null +++ b/dns/glossar/zonefile/index.html @@ -0,0 +1,2480 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Zonendatei - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + + + + + +
+
+ + + + + + + +

Zonendatei

+
    +
  • Erklären Sie die Zonendatei inkl. allen Parametern im SOA.
  • +
+

Die Zonendatei enthält die gesamte Hierarchie der Zone inklusive allen Records. Eine Zonendatei startet immer mit einem SOA record, wo alle wichtigen Infos zur Zone stehen (z.B. Kontakt zum Zonenadmin).

+

Hier sind die Parameter eines SOA-Eintrags und deren Bedeutung:

+

Primary Name Server (MNAME)

+

Dies ist der vollqualifizierte Domainname (FQDN) des primären Nameservers für die Zone. Er ist der erste Server, der autoritative Antworten für die Zone liefert.

+

Responsible Person (RNAME)

+

Dies ist die E-Mail-Adresse der Person, die für die Verwaltung der Zone verantwortlich ist. Das "@"-Zeichen wird durch einen Punkt (".") ersetzt. Zum Beispiel, "admin.example.com" bedeutet "admin@example.com".

+

Serial Number

+

Eine fortlaufende Nummer, die bei jeder Änderung der Zonendatei erhöht wird. Dies hilft sekundären Nameservern zu erkennen, wann die Zonendatei aktualisiert wurde, sodass sie ihre Kopien entsprechend aktualisieren können.

+

Refresh Interval

+

Die Zeit in Sekunden, nach der sekundäre Nameserver überprüfen sollen, ob die Zonendatei auf dem primären Nameserver aktualisiert wurde. Typischerweise ein Wert zwischen 1 Stunde (3600 Sekunden) und 1 Tag (86400 Sekunden).

+

Retry Interval

+

Die Zeit in Sekunden, die sekundäre Nameserver warten sollen, bevor sie nach einem fehlgeschlagenen Update-Versuch erneut versuchen, die Zonendatei zu aktualisieren. Dieser Wert ist normalerweise kürzer als das Refresh-Intervall.

+

Expire Time

+

Die maximale Zeit in Sekunden, die ein sekundärer Nameserver die Zonendatei als gültig betrachten soll, wenn keine Aktualisierung vom primären Server erfolgt. Nach dieser Zeit wird die Zonendatei als ungültig betrachtet, und der Server stellt die Beantwortung von Anfragen für diese Zone ein. Typischerweise ein Wert von mehreren Wochen.

+

Minimum TTL (Time To Live)

+

Die Standardzeit in Sekunden, die DNS-Einträge aus dieser Zone im Cache eines Clients oder eines zwischengeschalteten Nameservers verbleiben sollen. Wenn kein spezifischer TTL-Wert für einen Eintrag festgelegt ist, wird dieser Wert verwendet.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/index.html b/dns/index.html new file mode 100644 index 00000000..b4bf2244 --- /dev/null +++ b/dns/index.html @@ -0,0 +1,2369 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + DNS Modul 300 - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

DNS Modul 300

+

Link zum Auftrag

+

Vorwissen

+

Ich habe bereits im Geschäft einen Bind9 DNS-Server aufgesetzt. Dies ist nun schon zwei Jahre her, von dem her bin ich also, doch froh kann ich dies erneut tun. Mit DynDNS habe ich auch schon in meiner privaten Infrastruktur Erfahrungen gemacht.

+

Aufbau

+

Die praktischen Aufgaben mit den persönlichen Erfahrungen finden Sie unter dem praktischen Block. +Das Glossar dient als Hilfsmittel, um den praktischen Teil zu verstehen.

+

Quellen

+

Glossar

+ +

Bind9

+
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/praktisch/bind9/index.html b/dns/praktisch/bind9/index.html new file mode 100644 index 00000000..fe9d19a4 --- /dev/null +++ b/dns/praktisch/bind9/index.html @@ -0,0 +1,2588 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Bind9 - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Bind9

+
    +
  • Als Pflichtprogramm wird die Inbetriebnahme eines DNS-Resolvers und Nameservers erwartet (bind unter Linux).
  • +
+

Bind9 ist eine Open-Source Implementation von DNS.

+

Setup

+

Wie folgt habe Bind9 installiert, konfiguriert und in meine Umgebung integriert.

+
    +
  • LAN: 192.168.1.0/26
  • +
  • DNS server: 192.168.1.7
  • +
  • Client: 192.168.1.4
  • +
  • Domain: sephley.local
  • +
+

1. APT Pakete installieren

+
sudo apt update
+sudo apt install bind9 bind9utils bind9-doc dnsutils
+
+

2. Konfiguration vornehmen

+

Die config-files für Bind9 befinden findet man unter /etc/bind.
+Zuerst bearbeiten wir die Datei named.conf.options.
+Vieles ist hier schon ausgefüllt, ich habe bloss den DNS zu dem von Cloudflare umkonfiguriert und das Netzwerk angepasst.

+
acl internal-network {
+192.168.1.0/26;
+};
+options {
+        directory "/var/cache/bind";
+        allow-query { localhost; internal-network; };
+        allow-transfer { localhost; };
+        forwarders { 1.1.1.1; };
+        recursion yes;
+        dnssec-validation auto;
+};
+
+

Als nächstes bearbeiten wir die Datei named.conf.local

+
zone "sephley.local" IN {
+        type master;
+        file "/etc/bind/forward.sephley.local";
+        allow-update { none; };
+};
+zone "1.168.192.in-addr.arpa" IN {
+        type master;
+        file "/etc/bind/reverse.sephley.local";
+        allow-update { none; };
+};
+
+

Nun schreiben wir endlich unser zone file. Dazugehörige Theorie: Zonendatei
+Um uns diese Arbeit zu erleichtern, kopieren wir den Inhalt von db.local in unsere neues zone file forward.sephley.local

+
cp db.local forward.sephley.local
+
+

Anschliessend fügen wir folgendes in forward.sephley.local ein:

+
$TTL    604800
+@       IN      SOA     primary.sephley.local. root.primary.sephley.local. (
+                              2         ; Serial
+                         604800         ; Refresh
+                          86400         ; Retry
+                        2419200         ; Expire
+                         604800 )       ; Negative Cache TTL
+;
+@       IN      NS      primary.sephley.local.
+primary IN      A       192.168.1.7
+www     IN      A       192.168.1.4
+
+

Dazugehörige Theorie: Record-Typen
+Nun konfigurieren wie die Reverse Zone. Wie vorhin kopieren wir eine bestehende Datei als Vorlage:

+
cp db.127 reverse.sephley.local
+
+

Anschliessend fügen wir folgendes in reverse.sephley.local ein:

+
$TTL    604800
+@       IN      SOA     sephley.local. root.sephley.local. (
+                              1         ; Serial
+                         604800         ; Refresh
+                          86400         ; Retry
+                        2419200         ; Expire
+                         604800 )       ; Negative Cache TTL
+;
+@       IN      NS      primary.sephley.local.
+primary IN      A       192.168.1.7
+
+7       IN      PTR     primary.sephley.local.
+4       IN      PTR     www.sephley.local.
+
+

Als nächstes fügen wir folgende Zeile in /etc/default/named ein, um beim Aufstarten von Bind9 IPv4 zu erzwingen.

+
OPTIONS="-u bind -4"
+
+

3. Systemd

+

Nun können wir den Dienst aktivieren und starten:

+
sudo systemctl start named
+sudo systemctl enable named
+
+

4. Funktionalität testen

+

Zuerst validieren wir den Syntax unser Konfig-Dateien:

+
sudo named-checkconf /etc/bind/named.conf.local
+
+

Wenn nichts ausgegeben wird, dann stimmt diese Konfig. +Als nächstes prüfen wir die Forward & Reverse Zone:

+
sudo named-checkzone sephley.local /etc/bind/forward.sephley.local
+sudo named-checkzone sephley.local /etc/bind/reverse.sephley.local
+
+

Wenn man hier ein OK erhaltet dann stimmen die Konfigs.
+Nun wechseln wir auf einen Client im selben Netzwerk und setzen den DNS zu 192.168.1.7:
+sudo vim /etc/netplan/00-installer-config.yaml bearbeiten:

+
network:
+  ethernets:
+    ens33:
+      dhcp4: true
+      nameservers:
+        addresses: [192.168.1.7]
+  version: 2
+
+

Nun führen wir auf einem Client im selben Netzwerk folgenden Befehl aus:

+
dig primary.sephley.local
+
+

dig syntax & usage

+

Output:
+Output

+

Probleme / Anmerkungen

+
    +
  • Zuerst wollte ich den Bind9 mit der Anleitung von Digitalocean aufsetzen, diese war jedoch overkill für meine Umgebung. Aber welche Anleitung sollte ich denn nehmen?
  • +
  • Meine lokale VMware Umgebung ist sehr langsam. Vielleicht sollte ich sie migrieren. Ich glaube ich verwende ab nun Terraform & Packer, um meine VMs zu erstellen.
  • +
  • network unreachable resolving './DNSKEY/IN': 2001:dc3::35#53
    +Viele solche Meldungen wurden mir bei systemctl status named angezeigt. Dies ist, weil ich noch IPv6 aktiviert hatte, was ich in meiner Konfig nicht mit-einbezogen habe.
  • +
  • Gemäss Anleitung von Linuxtechi wollte ich den DNS statisch konfigurieren, um die Funktionalität meines DNS zu testen. Da stand ich sollte /etc/resolv.conf bearbeiten, doch das Erste, was in dieser Datei stand, war:
  • +
+
# This is /run/systemd/resolve/stub-resolv.conf managed by man:systemd-resolved(8).
+# Do not edit.
+#
+# This file might be symlinked as /etc/resolv.conf. If you're looking at
+# /etc/resolv.conf and seeing this text, you have followed the symlink.
+#
+# This is a dynamic resolv.conf file for connecting local clients to the
+# internal DNS stub resolver of systemd-resolved. This file lists all
+# configured search domains.
+
+

Die Datei war also nur ein Symlink. Ich habe herausgefunden, dass man es theoretisch überschreiben kann mit einem statischen File, aber dass es nicht empfohlen wird. Ich habe dann im /etc/netplan/00-installer-config.yaml den Nameserver angegeben.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/praktisch/dnsaws/index.html b/dns/praktisch/dnsaws/index.html new file mode 100644 index 00000000..1816b18d --- /dev/null +++ b/dns/praktisch/dnsaws/index.html @@ -0,0 +1,2361 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + DNS-in-AWS - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

DNS in AWS

+
    +
  • Auch in der AWS oder Azure-Umgebung finden Sie DNS. Was lässt sich damit anstellen?
  • +
+

AWS garantiert eine 100% uptime, was für ein so kritischer Dienst wie der DNS sehr von Vorteil ist.
+Der DNS in AWS ist unter Route 53 zu finden.

+

Probleme / Anmerkungen

+

Um dies zu testen, wollte ich das Learnerlab verwenden, doch ich verfügte nicht über ausreichende Berechtigungen. +aws_1

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/praktisch/drawio/netzwerkschama_m300_dns.drawio b/dns/praktisch/drawio/netzwerkschama_m300_dns.drawio new file mode 100644 index 00000000..6b5c99b8 --- /dev/null +++ b/dns/praktisch/drawio/netzwerkschama_m300_dns.drawio @@ -0,0 +1,88 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/dns/praktisch/images/aws_1.png b/dns/praktisch/images/aws_1.png new file mode 100644 index 00000000..fedd68c1 Binary files /dev/null and b/dns/praktisch/images/aws_1.png differ diff --git a/dns/praktisch/images/dig.png b/dns/praktisch/images/dig.png new file mode 100644 index 00000000..2832b03d Binary files /dev/null and b/dns/praktisch/images/dig.png differ diff --git a/dns/praktisch/images/key_secret.png b/dns/praktisch/images/key_secret.png new file mode 100644 index 00000000..ddf40622 Binary files /dev/null and b/dns/praktisch/images/key_secret.png differ diff --git a/dns/praktisch/images/maas-1.png b/dns/praktisch/images/maas-1.png new file mode 100644 index 00000000..1bcd87b7 Binary files /dev/null and b/dns/praktisch/images/maas-1.png differ diff --git a/dns/praktisch/images/uebersteuern_1.png b/dns/praktisch/images/uebersteuern_1.png new file mode 100644 index 00000000..de085914 Binary files /dev/null and b/dns/praktisch/images/uebersteuern_1.png differ diff --git a/dns/praktisch/images/uebersteuern_2.png b/dns/praktisch/images/uebersteuern_2.png new file mode 100644 index 00000000..44de7c69 Binary files /dev/null and b/dns/praktisch/images/uebersteuern_2.png differ diff --git a/dns/praktisch/images/wireshark_1.png b/dns/praktisch/images/wireshark_1.png new file mode 100644 index 00000000..7925947e Binary files /dev/null and b/dns/praktisch/images/wireshark_1.png differ diff --git a/dns/praktisch/images/wireshark_2.png b/dns/praktisch/images/wireshark_2.png new file mode 100644 index 00000000..1f8fc3a0 Binary files /dev/null and b/dns/praktisch/images/wireshark_2.png differ diff --git a/dns/praktisch/images/wireshark_3.png b/dns/praktisch/images/wireshark_3.png new file mode 100644 index 00000000..1e278ae7 Binary files /dev/null and b/dns/praktisch/images/wireshark_3.png differ diff --git a/dns/praktisch/images/wireshark_4.png b/dns/praktisch/images/wireshark_4.png new file mode 100644 index 00000000..c8411325 Binary files /dev/null and b/dns/praktisch/images/wireshark_4.png differ diff --git a/dns/praktisch/index.html b/dns/praktisch/index.html new file mode 100644 index 00000000..d94c03bf --- /dev/null +++ b/dns/praktisch/index.html @@ -0,0 +1,882 @@ + + + + + + + + + + + + + + +Aufgaben - docs + + + + + + + + + + + + +
+
+
+ +
+
+ +
+
+
+
+
+ +
+
+
+
+
+
+ +
+
+
+
+
+

Aufgaben

+
    +
  • = fertig
  • +
  • = WIP
  • +
+

Checkliste der Aufträge gemäss Olat:

+
    +
  • Als Pflichtprogramm wird die Inbetriebnahme eines DNS-Resolvers und Nameservers erwartet (bind unter Linux).
      +
    • In Wireshark zeichnen Sie die rekursive Abfrage auf und erklären diese.
    • +
    • Erstellen Sie einen Secondary DNS und lassen Sie die Zonen automatisiert synchronisieren.
    • +
    • In einem früheren Auftrag haben Sie exotische Betriebssysteme ans Netzwerk angebunden. Binden Sie Ihren DNS-Resolver ein und zeigen Sie per Wireshark, ob diese Betriebssysteme die Abfragen korrekt durchführen.
    • +
    • Versuchen Sie dynamisch DNS-Einträge anpassen zu lassen. Spielen Sie Kapitel 3 von https://strugglers.net/~andy/blog/2018/03/19/ nach. Beachten Sie, dass sich die Welt ändert: Nutzen Sie tsig-keygen statt dnssec-keygen.
    • +
    • Unter maas.bbw-it.ch haben Sie Zugriff auf eine «persönliche» DNS-Subdomain. Nutzen Sie diese Möglichkeit und testen Sie, wie sie diese einsetzen können. Für Fortgeschrittene können Sie auch die dynamische Anpassung ausprobieren.
    • +
    • Übersteuern Sie den DNS mittels Hosts-File (auch unter Windows). Wie verhält sich der Resolver, wenn Sie ihm per Hosts-File andere Werte unterjubeln? Werden diese da berücksichtigt?
    • +
    +
  • +
+

Netzwerkschema

+

Ich übernehme das Netzwerk vom letzten Auftrag zu PXE und DHCP. Einerseits weil es praktisch ist, andererseits weil es eine gute Übung für mich ist. +

+
+
+ +
+ +
+ +
+
+
+
+ + + + \ No newline at end of file diff --git a/dns/praktisch/pers_subdomain/index.html b/dns/praktisch/pers_subdomain/index.html new file mode 100644 index 00000000..fd73c7be --- /dev/null +++ b/dns/praktisch/pers_subdomain/index.html @@ -0,0 +1,2380 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Persönliche-Subdomain - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Persönliche Subdomain

+
    +
  • Unter maas.bbw-it.ch haben Sie Zugriff auf eine «persönliche» DNS-Subdomain. Nutzen Sie diese Möglichkeit und testen Sie, wie sie diese einsetzen können. Für Fortgeschrittene können Sie auch die dynamische Anpassung ausprobieren.
  • +
+

Auf dem Maas der BBW hat man eine persönliche Subdomain mit der Möglichkeit, seine eigene Zone zu konfigurieren.
+maas-1

+

Somit können wir eine dynamische Anpassung einrichten. Zuerst kopieren wir unseren TSIG Schlüssel und fügen es in die Datei /secrets/maas ein.

+

Dann setzen wir die erforderlichen Berechtigungen:

+
sudo chown root:root /secrets/maas
+sudo chmod 600 /secrets/maas
+
+

Nun können wir unseren Key hinzufügen:

+
nsupdate -k /secrets/maas 
+>server ns.users.bbw-it.ch. 
+>update add xyz.joseph.hurley.users.bbw-it.ch. 300 IN A 1.2.3.4 
+>send
+>quit
+
+

Und zum Schluss noch die Änderungen überprüfen:

+
nslookup xyz.joseph.hurley.users.bbw-it.ch
+nslookup xyz.joseph.hurley.users.bbw-it.ch ns.users.bbw-it.ch
+
+

Probleme / Anmerkungen

+

Ich erhalte bei dem send Befehl folgende Fehlermeldung:
+"TSIG error with server: tsig indicates error update failed: NOTAUTH(BADKEY)".

+

Wenn ich den key einlesen möchte, kann er nicht gelesen werden.

+

key_secret

+

Ich habe eine Stunde lang mit den Berechtigungen herumgespielt und diverse Forum posts durchgelesen, konnte aber keine Lösung finden.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/praktisch/secdns/index.html b/dns/praktisch/secdns/index.html new file mode 100644 index 00000000..e6a09e6a --- /dev/null +++ b/dns/praktisch/secdns/index.html @@ -0,0 +1,2415 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Secondary-DNS - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Secondary DNS

+
    +
  • Erstellen Sie einen Secondary DNS und lassen Sie die Zonen automatisiert synchronisieren.
  • +
+

Dazugehörige Theorie: Primary / Secondary Konzept
+Für den Secondary DNS erstellen wir nochmals eine Ubuntu-Server VM. Diesmal habe ich eine Ubuntu 24.04 (Noble Numbat) VM erstellt, denn so kann ich die neue Version testen sowie auch die Rückwärtskompatibilität prüfen.

+

1. APT Pakete installieren

+
sudo apt update
+sudo apt install bind9 bind9utils bind9-doc dnsutils
+
+

2. Konfiguration vornehmen

+

Zuerst müssen wir noch auf unserem primären DNS die folgenden parameter in /etc/bind/named.conf.local in beiden zone blocks einfügen:

+
allow-transfer { 192.168.1.9 };
+also-notify { 192.168.1.9 };
+
+

/etc/bind/named.conf.local wie folgt bearbeiten:

+
zone "sephley.local" {
+type slave;
+file "/etc/bind/forward.sephley.local";
+masters { 192.168.1.7; };
+};
+
+

Anschliessend laden wir den Dienst neu:

+
sudo systemctl reload named
+
+

Probleme / Anmerkungen

+

Keine. Die schnellen boot-Zeiten von Ubuntu-Noble gefallen mir sehr. Good job Canonical!

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/praktisch/uebersteuern/index.html b/dns/praktisch/uebersteuern/index.html new file mode 100644 index 00000000..11dd5765 --- /dev/null +++ b/dns/praktisch/uebersteuern/index.html @@ -0,0 +1,2405 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + DNS-übersteuern - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

DNS übersteuren

+
    +
  • Übersteuern Sie den DNS mittels Hosts-File (auch unter Windows). Wie verhält sich der Resolver, wenn Sie ihm per Hosts-File andere Werte unterjubeln? Werden diese da berücksichtigt?
  • +
+

Linux

+

Pfad: /etc/hosts

+

Ich habe die Zeile 0.0.0.0 www.facebook.com eingefügt, um Facebook zu blocken.
+uebersteuern_2

+

Windows

+

Pfad: C:\Windows\system32\drivers\etc\hosts

+

Wie vorhin, habe ich die Zeile 0.0.0.0 www.facebook.com eingefügt, um Facebook zu blocken. Anschliessend musste ich in Microsoft Edge folgende Einstellung ausschalten: +uebersteuern_1

+

Somit hört der Browser auf das lokale Hosts-File.

+

Probleme / Anmerkungen

+

Wir stellen also Fest, dass die Werte im Hosts file priorisiert werden.
+Als ich aber auf Windows im hosts file www.facebook.com geblockt habe und trotzdem mit dem Browser darauf zugreifen konnte war ich sehr verwirrt. Diese Quelle hat mich darauf aufmerksam gemacht, dass die meisten Browser eine Funktion namens "DNS over HTTPS" verwenden.
+"When DNS over HTTPS is enabled in a browser, the browser bypasses the normal DNS client in Windows 10 and 11."

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/dns/praktisch/wireshark/index.html b/dns/praktisch/wireshark/index.html new file mode 100644 index 00000000..498d5003 --- /dev/null +++ b/dns/praktisch/wireshark/index.html @@ -0,0 +1,2417 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Wireshark - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Wireshark

+
    +
  • In Wireshark zeichnen Sie die rekursive Abfrage auf und erklären diese.
  • +
  • In einem früheren Auftrag haben Sie exotische Betriebssysteme ans Netzwerk angebunden. Binden Sie Ihren DNS-Resolver ein und zeigen Sie per Wireshark, ob diese Betriebssysteme die Abfragen korrekt durchführen.
  • +
+

Ich habe meinen ehemaligen DHCP Client verwendet, wo Wireshark schon installiert war.

+

Windows

+

Ich habe einen Scan gestartet und nach dns gefiltert. Während dem Scan habe ich Microsoft Edge geöffnet und olat.bbw.ch aufgelöst.

+

wireshark_4 +Datei herunterladen

+
    +
  1. +

    Start bei dem Resolver:
    +Der Client sendet eine DNS-Abfrage an den DNS-Resolver.

    +
  2. +
  3. +

    DNS Server erhaltet die Anfrage:
    +Der Resolver fragt einen der Root-Nameserver an.

    +
  4. +
  5. +

    Weiterleitung an die TLD-Nameserver:
    +Der Root-Nameserver antwortet mit einem Verweis auf die TLD-Nameserver, die für die Domäne zuständig sind.

    +
  6. +
  7. +

    Anfrage an die autoritativen Nameserver: +Der TLD-Nameserver antwortet mit den autoritativen Nameservern für primary.sephley.local. Der Resolver schickt dann eine Anfrage an einen dieser autoritativen Nameserver.

    +
  8. +
  9. +

    Erhalt der endgültigen Antwort:
    +Der autoritative Nameserver (primary.sephley.local) antwortet mit der IP-Adresse der Domäne. Diese Antwort wird an den Resolver zurückgegeben.

    +
  10. +
  11. +

    Übermittlung an den Client:
    +Der Resolver sendet die erhaltene IP-Adresse an den ursprünglichen Client zurück, der die Anfrage gestellt hat.

    +
  12. +
  13. +

    Caching der Antwort:
    +Sowohl der Resolver als auch der Client speichern die Antwort im Cache, um bei zukünftigen Anfragen schneller antworten zu können.

    +
  14. +
+

Probleme / Anmerkungen

+

Ich habe irgendwie den Sinn der Aufgabe nicht begriffen und habe die rekursive Anfrage an olat.bbw.ch gemacht. Aber der Sinn und Zweck dieser Aufgabe ist ja, dass ich die Anfrage an meinen eigenen DNS mache...
+Dazu habe ich zuerst eine bereits gecachte Abfrage auf www.google.ch gemacht, was natürlich nichts nützt, wenn man den ganzen Prozess erklären möchte.

+

wireshark_1
+Datei herunterladen

+

Falls Sie sich fragen, was gstatic.com ist: Google lädt static content (Javascripts, Bilder, CSS) von einer anderen Domäne. Dies hilft bei der Ladezeit, da es die Bandbreite verringert.
+wireshark_2

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/drawio/plan.drawio b/drawio/plan.drawio new file mode 100644 index 00000000..648c6ff9 --- /dev/null +++ b/drawio/plan.drawio @@ -0,0 +1,56 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/experts/index.html b/experts/index.html new file mode 100644 index 00000000..1af68f0c --- /dev/null +++ b/experts/index.html @@ -0,0 +1,2544 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + My GitLab Setup - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + + + + + +
+
+ + + + + + + +

My GitLab Setup

+

The purpose of this assignment is to set up a GitLab Server as if it were for a large-scale company.

+

My GitLab Server was setup in a personal PVE (Proxmox Virtual Environment) as a VM using Docker-Compose.

+

Installation Procedure

+

Setup an Ubuntu Server and install Docker & Docker-Compose

+

Follow this guide (official Docker installation guide)

+

and this guide (official Docker-Compose installation guide)
+Note that after follwing the first guide Docker-Compose may already be installed.

+

Setup GitLab using Docker-Compose

+

Follow this guide

+

It is recommended to export the $GITLAB_HOME variable like this: export GITLAB_HOME=/srv/gitlab
+and then adding this to .bashrc so you don't have to do it every time.
+However, this didn't work for me, so I ended up hard-coding them in the docker-compose.yaml file.

+

I altered the docker-compose.yaml quite a lot from the one in the manual.
+I switched to the Commuity Edition of GitLab, altered the hostname to something I may use, hard-coded the $GITLAB_HOME variable (because it wasn't working) and added grafana & prometheus.
+My file:

+
version: '3.6'
+services:
+  web:
+    image: 'gitlab/gitlab-ce:latest'
+    restart: always
+    container_name: gitlab
+    hostname: 'localhost'
+    environment:
+      GITLAB_OMNIBUS_CONFIG: |
+        external_url 'http://localhost:8929'
+        prometheus_monitoring['enable'] = true
+        prometheus['listen_address'] = 'localhost:9090'
+        # Add any other gitlab.rb configuration here, each on its own line
+    ports:
+      - '8929:8929'
+      - '9090:9090'
+    volumes:
+      - '/srv/gitlab/config:/etc/gitlab'
+      - '/srv/gitlab/logs:/var/log/gitlab'
+      - '/srv/gitlab/data:/var/opt/gitlab'
+    shm_size: '1g'
+  grafana:
+    image: 'grafana/grafana'
+    container_name: grafana
+    restart: unless-stopped
+    ports:
+      - '3000:3000'
+    volumes:
+      - grafana-storage:/var/lib/grafana
+volumes:
+  grafana-storage: {}
+
+

Monitoring Solution

+

I used Prometheus (which comes preinstalled with GitLab) and Grafana as my monitoring solution.

+

For Grafana, follow this guide to set it up.
+It used to come shipped with GitLab just like Prometheus, but was deprecated in 16.0 and removed in 16.3.
+For this reason, I had to add it in as a separate container in the docker-compose.yml file.

+

Once I had my Grafana Container up and running, I imported the Prometheus Metrics by adding a connection to 192.168.1.212:9090 (My Prometheus).
+When it comes to actually adding graphs / dashboards, I found that there are many premade ones here: https://grafana.com/grafana/dashboards/
+Just download the JSON and import it into Grafana.

+

GitLab Runner Setup

+

For the GitLab Runner, I made a separate VM for resource management purposes.
+Since nothing else is running on this VM, there is no need to use Docker-Compose.

+

Just like before, I used this guide to install Docker.
+Then I proceeded to create a volume to store persistant data: docker volume create gitlab-runner-config

+

To run the GitLab Runner, use:

+
docker run -d --name gitlab-runner --restart always \
+    -v /var/run/docker.sock:/var/run/docker.sock \
+    -v gitlab-runner-config:/etc/gitlab-runner \
+    gitlab/gitlab-runner:alpine
+
+

Note that I am using the alpine image because it is more lightweight. The other option would be to use the latest tag which uses ubuntu.

+

Now we need to register this Runner.
+In your GitLab Settings you can add a runner, which will enable you to generate an authentication token.
+I ran this command on my Runner VM (setup in non-interactive mode):

+
docker run --rm -v /srv/gitlab-runner/config:/etc/gitlab-runner gitlab/gitlab-runner:alpine register \
+  --non-interactive \
+  --url "192.168.1.212" \
+  --token "$RUNNER_TOKEN" \
+  --executor "docker" \
+  --docker-image alpine:latest \
+  --description "docker-runner"
+
+

Then create a project with a CI-CD Pipeline and add the runner to the project.

+

Why only one Runner?

+

GitLab Conifguration

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/images/dhcp/dhcp1.png b/images/dhcp/dhcp1.png new file mode 100644 index 00000000..d26c1c2a Binary files /dev/null and b/images/dhcp/dhcp1.png differ diff --git a/images/dhcp/dhcp2.png b/images/dhcp/dhcp2.png new file mode 100644 index 00000000..005b4154 Binary files /dev/null and b/images/dhcp/dhcp2.png differ diff --git a/images/dhcp/dhcp3.png b/images/dhcp/dhcp3.png new file mode 100644 index 00000000..a6a80f88 Binary files /dev/null and b/images/dhcp/dhcp3.png differ diff --git a/images/dhcp/dhcp4.png b/images/dhcp/dhcp4.png new file mode 100644 index 00000000..05c3c71e Binary files /dev/null and b/images/dhcp/dhcp4.png differ diff --git a/images/dhcp/dhcp5.png b/images/dhcp/dhcp5.png new file mode 100644 index 00000000..dd574e66 Binary files /dev/null and b/images/dhcp/dhcp5.png differ diff --git a/images/dhcp/dhcpvogel.png b/images/dhcp/dhcpvogel.png new file mode 100644 index 00000000..9822c79e Binary files /dev/null and b/images/dhcp/dhcpvogel.png differ diff --git a/images/dhcp/dhcpwireshark.png b/images/dhcp/dhcpwireshark.png new file mode 100644 index 00000000..9b422845 Binary files /dev/null and b/images/dhcp/dhcpwireshark.png differ diff --git a/images/dhcp/plan.drawio.png b/images/dhcp/plan.drawio.png new file mode 100644 index 00000000..b7cac800 Binary files /dev/null and b/images/dhcp/plan.drawio.png differ diff --git a/images/dhcp/slitaz.png b/images/dhcp/slitaz.png new file mode 100644 index 00000000..e5f91694 Binary files /dev/null and b/images/dhcp/slitaz.png differ diff --git a/images/dhcp/udchp.png b/images/dhcp/udchp.png new file mode 100644 index 00000000..afaca22e Binary files /dev/null and b/images/dhcp/udchp.png differ diff --git a/images/nextcloud.png b/images/nextcloud.png new file mode 100644 index 00000000..391ec44e Binary files /dev/null and b/images/nextcloud.png differ diff --git a/images/nextcloud2.png b/images/nextcloud2.png new file mode 100644 index 00000000..fd161a0a Binary files /dev/null and b/images/nextcloud2.png differ diff --git a/images/nodeport.png b/images/nodeport.png new file mode 100644 index 00000000..279ed321 Binary files /dev/null and b/images/nodeport.png differ diff --git a/images/pod.png b/images/pod.png new file mode 100644 index 00000000..54668b85 Binary files /dev/null and b/images/pod.png differ diff --git a/images/quotes-app.png b/images/quotes-app.png new file mode 100644 index 00000000..f8219b48 Binary files /dev/null and b/images/quotes-app.png differ diff --git a/images/source_target_port_on_service.png b/images/source_target_port_on_service.png new file mode 100644 index 00000000..38fe844b Binary files /dev/null and b/images/source_target_port_on_service.png differ diff --git a/index.html b/index.html new file mode 100644 index 00000000..830a608b --- /dev/null +++ b/index.html @@ -0,0 +1,2440 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Home

+

This is where I will be documenting various modules related to school (for now).

+

Markdown Syntax

+

for the sake of having some form of a guide.

+

Italic

+

Use the stars, my friend

+

You can also change the strenth of the text, by adding more underscores

+

Bold

+

Use two stars, my friend

+

You can also change the strenth of the text, by adding more stars

+

Code

+
Here's a beautiful code block
+
+

Blockquotes

+
+

crocodile for the win

+
+

You can even add multiple paragraphs:

+
+

wow

+

how very interesting

+
+

Not only that, but you can also nest them:

+
+

WOW

+
+

SO DAMN INTERESTING

+
+
+

It's even possible to add some other elements, like bullet points.

+

source: https://www.markdownguide.org/basic-syntax

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/nextcloud-auftrag/index.html b/nextcloud-auftrag/index.html new file mode 100644 index 00000000..7f59c732 --- /dev/null +++ b/nextcloud-auftrag/index.html @@ -0,0 +1,2276 @@ + + + + + + + + + + + + + + + + + + + + + + + + + Nextcloud auftrag - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Nextcloud auftrag

+ +

Nextcloud installieren wir mittels snap. Man kann bereits bei der Installation einer Ubuntu Server vm spezifizeren, dass man Nextcloud installieren möchte.

+

Snap bietet zwar den Vorteil, dass man Pakete sehr leicht mit einem Klick installieren kann, wird jedoch trotzdem von vielen Ubuntu-usern verabscheut.

+

https://snapcraft.io/install/nextcloud/ubuntu

+

https://chat.openai.com/share/fc9fea12-cc87-497f-bd57-31a54410a7a4

+

https://chat.openai.com/share/f77371e3-b100-439f-8bc3-5f99b193a814

+

Installation von Nextcloud mittels snap

+
sudo snap install nextcloud  
+sudo nextcloud.manual-install
+
+

Man kann auch mittels snap verifizieren, ob der Server läuft oder nicht.

+
sudo snap services nextcloud
+
+
sudo vim /var/snap/nextcloud/current/nextcloud/config/config.php
+
+

In diesem File unter trusted domains, seine gewünschte Domäne hinzufügen.

+

Manual Install

+

nextcloud2

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/pruefung-security/index.html b/pruefung-security/index.html new file mode 100644 index 00000000..c60ea944 --- /dev/null +++ b/pruefung-security/index.html @@ -0,0 +1,2668 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Security - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Prüfung 19.06.2023

+

Ueb1

+

Linuxusererstellen.sh

+

Linux user add script for preparation.

+
cat  /etc/group
+
+# Erstellen der Gruppen
+groupadd dbusrgrp 
+groupadd dbadmgrp
+groupadd dbuser10
+groupadd dbuser11
+groupadd dbuser12
+
+
+# Anzeige welche User existieren:
+cat /etc/passwd
+
+# Erstellen der User (UserID und PW sind identisch)
+useradd -p $(openssl passwd -1 dbuser10) -g dbuser10  -G dbuser10           -s /bin/bash -c "Test user dbuser10"  -d /home/dbuser10   dbuser10
+useradd -p $(openssl passwd -1 dbuser11) -g dbuser11  -G dbuser11,dbusrgrp  -s /bin/bash -c "Test user dbuser11"  -d /home/dbuser11   dbuser11
+useradd -p $(openssl passwd -1 dbuser12) -g dbuser12  -G dbuser12,dbadmgrp  -s /bin/bash -c "Test user dbuser12"  -d /home/dbuser12   dbuser12
+
+

Ueb1_GRANT_User.sql

+
GRANT DATAACCESS ON DBBW001 TO GROUP dbusrgrp;
+GRANT DATAACCESS ON DBBW002 TO GROUP dbusrgrp;
+
+GRANT DBADM ON DATABASE DBBW001 TO GROUP dbadmgrp WITHOUT DATAACCESS;
+GRANT DBADM ON DATABASE DBBW002 TO GROUP dbadmgrp WITHOUT DATAACCESS;
+
+

Ueb2

+

The objective of this assignment was to make the pre-written scripts function.
+You may have to run db2 CONNECT TO <database-name> after you have run the pre-written scripts, as they have a connection reset command in them.

+

Ueb2_GRANT_User.sql

+
--
+-- Autorisierungen für User dbuser10
+--
+
+GRANT CONNECT ON DATABASE TO USER dbuser10;
+GRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER dbuser10;
+GRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER dbuser10;
+GRANT SELECT ON TABLE BIBLIO.TARTIKEL TO USER dbuser10;
+
+--
+-- Autorisierungen für User dbuser11
+--
+
+GRANT CONNECT ON DATABASE TO USER dbuser11;
+GRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER dbuser11;
+GRANT SELECT ON TABLE BIBLIO.TARTIKEL TO USER dbuser11;
+
+--
+-- Autorisierungen für User dbuser12
+--
+
+GRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER dbuser12;
+GRANT SELECT ON TABLE BIBLIO.TARTIKEL TO USER dbuser12;
+
+

Ueb3

+

The premise of this assignment is the same as Ueb2.
+To connect to a Database as a simple Database user, use this command:

+
db2 CONNECT TO DBBW002 USER dbuser10 USING dbuser10
+
+

Ueb3_GRANT_User.sql

+
--
+-- Speichern Sie in diesem SQL Script die notwendigen GRANT Statements
+--
+
+--
+-- Autorisierungen für User dbuser10
+--
+
+GRANT CREATETAB ON DATABASE TO USER dbuser10;
+GRANT IMPLICIT_SCHEMA ON DATABASE TO USER dbuser10;
+GRANT USE OF TABLESPACE USERSPACE1 TO USER dbuser10;
+
+--
+-- Autorisierungen für User dbuser11
+--
+
+GRANT CREATETAB ON DATABASE TO USER dbuser11;
+GRANT IMPLICIT_SCHEMA ON DATABASE TO USER dbuser11;
+GRANT USE OF TABLESPACE USERSPACE1 TO USER dbuser11;
+
+--
+-- Autorisierungen für User dbuser12
+--
+
+GRANT CREATETAB ON DATABASE TO USER dbuser12;
+
+

Ueb4

+

In this assignment, you must create a database role that has certain permissions on certain tables.
+After that, you must create two UNIX users that have the newly created role (in this case: TESTER)

+

Ueb4_GRANT_ROLE.sql

+
--
+-- Speichern Sie in diesem SQL Script die notwendigen GRANT Statements
+--
+
+CREATE ROLE TESTER;
+
+--
+-- Autorisierungen für User dbuser10
+--
+
+GRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER10.TDBS_PERSON TO TESTER;
+GRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER10.TDBS_ABTEILUNG TO TESTER;
+
+--
+-- Autorisierungen für User dbuser11
+--
+
+GRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER11.TDBS_PERSON TO TESTER;
+GRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER11.TDBS_ABTEILUNG TO TESTER;
+
+--
+-- Autorisierungen für User dbuser12
+--
+
+GRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER12.TDBS_PERSON TO TESTER;
+GRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER12.TDBS_ABTEILUNG TO TESTER;
+
+
+

Afterwards, you must assign this role to the users (in this case tester01 and tester02).

+
db2 GRANT TESTER TO USER tester01;
+db2 GRANT TESTER TO USER tester02;
+
+

Lastly, I had to enable the Workload for the users.

+
db2 GRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO ROLE TESTER;
+
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/pxe-mitschnitt/index.html b/pxe-mitschnitt/index.html new file mode 100644 index 00000000..4db53840 --- /dev/null +++ b/pxe-mitschnitt/index.html @@ -0,0 +1,2339 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Mitschnitt-DHCP-PXE-Debian - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Mitschnitt-DHCP-PXE-Debian

+ +
b## 2022-03-08, lp5jvogel
+## Slitaz per PXE / Debian 11
+## DHCP SERVER in Betrieb nehmen
+apt update
+apt install isc-dhcp-server
+vi /etc/dhcp/dhcpd.conf
+# ACHTUNG: Mac-Adresse anpassen!
+----8<-------8<----- /etc/dhcp/dhcpd.conf
+authoritative;
+subnet 192.168.0.0 netmask 255.255.255.0  {
+}
+
+host client {
+   fixed-address 192.168.0.10;
+   hardware ethernet 08:00:27:e8:30:46;
+   option routers 192.168.0.1;
+   option host-name "client";
+   next-server 192.168.0.1;
+   filename "gpxelinux.0";
+}
+---->8------->8----- /etc/dhcp/dhcpd.conf
+ip a add 192.168.0.10/24 up dev enp0s3
+service isc-dhcp-server restart
+
+
+## TFTP SERVER in Betrieb nehmen
+apt install tftpd
+mkdir /srv/tftp
+
+## PXELinux in Betrieb nehmen
+apt install pxelinux syslinux-common
+cp /usr/lib/PXELINUX/gpxelinux.0 /srv/tftp/.
+cp /usr/lib/syslinux/modules/bios/ldlinux.c32 /srv/tftp/.
+mkdir /srv/tftp/pxelinux.cfg
+vi /srv/tftp/pxelinux.cfg/default
+----8<----8<-- /srv/tftp/pxelinux.cfg/default
+default slitaz
+prompt 0
+label slitaz
+    menu label Slitaz
+    kernel slitaz/bzImage
+    append initrd=slitaz/rootfs4.gz,slitaz/rootfs3.gz,slitaz/rootfs2.gz,slitaz/rootfs1.gz rw root=/dev/null vga=normal autologin
+---->8---->8-- /srv/tftp/pxelinux.cfg/default
+
+## Slitaz an den richtigen Ort kopieren
+cd ~
+wget http://mirror.slitaz.org/iso/4.0/slitaz-4.0.iso
+mount -o loop slitaz-4.0.iso /mnt
+mkdir /srv/tftp/slitaz
+cp /mnt/boot/bzImage /mnt/boot/rootfs* /srv/tftp/slitaz/.
+umount /mnt
+
+## alles eingerichtet, jetzt Client booten
+
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/search/search_index.json b/search/search_index.json new file mode 100644 index 00000000..902214fa --- /dev/null +++ b/search/search_index.json @@ -0,0 +1 @@ +{"config":{"lang":["en"],"separator":"[\\s\\-]+","pipeline":["stopWordFilter"]},"docs":[{"location":"","title":"Home","text":""},{"location":"#home","title":"Home","text":"

This is where I will be documenting various modules related to school (for now).

"},{"location":"#markdown-syntax","title":"Markdown Syntax","text":"

for the sake of having some form of a guide.

"},{"location":"#italic","title":"Italic","text":"

Use the stars, my friend

You can also change the strenth of the text, by adding more underscores

"},{"location":"#bold","title":"Bold","text":"

Use two stars, my friend

You can also change the strenth of the text, by adding more stars

"},{"location":"#code","title":"Code","text":"
Here's a beautiful code block\n
"},{"location":"#blockquotes","title":"Blockquotes","text":"

crocodile for the win

You can even add multiple paragraphs:

wow

how very interesting

Not only that, but you can also nest them:

WOW

SO DAMN INTERESTING

It's even possible to add some other elements, like bullet points.

source: https://www.markdownguide.org/basic-syntax

"},{"location":"bbw-m141/","title":"M141 - Admin / Betrieb DBM","text":""},{"location":"bbw-m141/#m141-admin-betrieb-dbm","title":"M141 - Admin / Betrieb DBM","text":""},{"location":"bbw-m141/#start-stop-dbm","title":"Start / Stop DBM","text":"
db2 START DBM\n\ndb2 STOP DBM FORCE\n
"},{"location":"bbw-m141/#connect-to-database-disconnect-from-database","title":"Connect to database / Disconnect from database","text":"
db2 CONNECT TO DBBW001\n\ndb2 CONNECTION RESET\n
"},{"location":"bbw-m141/#run-sql-script-from-cli","title":"Run SQL script from CLI","text":"
db2 -tvsf script.sql\n
"},{"location":"bbw-m141/#grant-privileges-to-a-user-for-a-table","title":"Grant privileges to a user for a table","text":"
db2 \"GRANT SELECT, INSERT, UPDATE, DELETE ON BIBLIO.TARTIKEL TO USER bbwuser;\"\n

then proceed to check privileges: db2 SELECT * FROM SYSCAT.TABAUTH;

"},{"location":"bbw-m141/#backup-database","title":"Backup database","text":"

Offline

db2 backup database DBBW001 to /bbw/DBbackup\n

Online

db2 backup database DBBW001 online to /bbw/DBbackup\n
"},{"location":"bbw-m141/#restore-database","title":"Restore database","text":"

The location specified after 'FROM' must be a directory, not a file.

Make sure to select the timestamp that is equivalent to the one of your desired backup.

db2 \"RESTORE DB DBBW001 FROM /bbw/DBbackup/ TAKEN AT 20230417084512\"\n
"},{"location":"bbw-m141/#update-database-config","title":"Update database config","text":"

From first test:

db2 update db cfg for dbbw001 using LOGRETAIN RECOVERY\n\ndb2 update db cfg for dbbw001 using AUTO_MAINT OFF\n\ndb2 update db cfg for dbbw001 using AUTO_DEL_REC_OBJ ON\n\n

From Ueb4

db2 update db cfg for dbbw001 using NEWLOGPATH '/bbw/activelog1'\n\ndb2 update db cfg for dbbw001 using MIRRORLOGPATH '/bbw/activelog2'\n\ndb2 update db cfg for dbbw001 using LOGARCHMETH1 DISK:/bbw/archlog1\n\ndb2 update db cfg for dbbw001 using LOGARCHMETH2 DISK:/bbw/archlog2\n\ndb2 update db cfg for dbbw001 using LOG RETAIN RECOVERY\n\ndb2 update db cfg for dbbw001 using AUTO_DEL_REC_OBJ ON\n
"},{"location":"bbw-m141/#search-dbm-config","title":"Search DBM config","text":"

the parameter 'logprimary' is an example of a parameter to search for. make sure to specify the correct database after 'for'

db2 get db cfg for dbbw001 | grep -i logprimary\n
"},{"location":"bbw-m141/#rollforward-database-after-restore","title":"Rollforward database after restore","text":"

This is only necessary if the specified database is enabled for roll-forward recovery and it has been restored but not rolled forward. see https://www.ibm.com/docs/en/db2/10.5?topic=messages-sql1000-sql1249#sql1117n for more detail

db2 rollforward db DBBW001 to end of logs and stop\n
"},{"location":"bbw-m169/","title":"Infos for Capture-the-flag Test on 10.07.2023","text":""},{"location":"bbw-m169/#infos-for-capture-the-flag-test-on-10072023","title":"Infos for Capture-the-flag Test on 10.07.2023","text":"

see https://bbwin.gitlab.io/m169-aws-fargate/iac/ for the previous assignment regarding CI/CD.

"},{"location":"bbw-m169/#gitlab-ciyml","title":"gitlab-ci.yml","text":"
image: docker:23.0.4\n\nvariables:\n  DOCKER_HOST: tcp://docker:2375\n  DOCKER_TLS_CERTDIR: \"\"\n\nservices:\n  - docker:23.0.4-dind\n\npackage:\n  stage: build\n  before_script:\n    - apk add --no-cache py3-pip\n    - pip install awscli\n    - aws --version\n\n    - aws ecr get-login-password | docker login --username AWS --password-stdin $CI_AWS_ECR_REGISTRY\n\n  script:\n    - docker build --cache-from $CI_AWS_ECR_REGISTRY/$CI_AWS_ECR_REPOSITORY_NAME:latest -t $CI_AWS_ECR_REGISTRY/$CI_AWS_ECR_REPOSITORY_NAME:latest .\n    - docker push $CI_AWS_ECR_REGISTRY/$CI_AWS_ECR_REPOSITORY_NAME:latest\n
"},{"location":"bbw-m169/#dockerfile","title":"Dockerfile","text":"

This is an example Dockerfile from the refcard03 Assignment. Note that you may need to change some things depending on the application you receive for the test. For example the Java version may differ etc.

FROM maven:3-openjdk-11-slim\n\nCOPY src /src\nCOPY pom.xml /\nRUN mvn -f pom.xml clean package\n\nRUN mv /target/*.jar app.jar\nENTRYPOINT [\"java\",\"-jar\",\"/app.jar\"]\n

It would be better to use a multi-stage version, because time will be crucial during the test.

"},{"location":"bbw-m300/","title":"M300 Vogel","text":""},{"location":"dhcp/","title":"DHCP-PXE","text":""},{"location":"dhcp/#auftrag-dhcp-pxe-m300-vogel","title":"Auftrag DHCP & PXE M300 Vogel","text":"

Diese Dokumentation kombiniert beide Auftr\u00e4ge in einen grossen Auftrag. Ich habe diesen Auftrag auf meinem Client mit VMware Workstation Pro erledigt.

"},{"location":"dhcp/#netzwerkplan","title":"Netzwerkplan","text":""},{"location":"dhcp/#installation-dhcp","title":"Installation DHCP","text":"

DHCP Auftrag DHCP Pr\u00e4si Ich habe eine Ubuntu VM installiert und drei Netzwerkadapter erstellt: - NAT - Vnet5 - Vnet6

"},{"location":"dhcp/#1-apt-packet-installieren","title":"1. APT-Packet installieren","text":"
sudo apt update\nsudo apt install isc-dhcp-server\n
"},{"location":"dhcp/#2-konfiguration-dhcp","title":"2. Konfiguration DHCP","text":"

Um unseren frisch installierten DHCP server zu konfigurieren, m\u00fcssen wir das File /etc/dhcp/dhcpd.conf bearbeiten. Folgende Konfiguration habe ich verwendet (Die MAC-Adressen habe ich von VMware ausgelesen):

default-lease-time 600;\nmax-lease-time 7200;\n\n# LAN\nsubnet 192.168.1.0 netmask 255.255.255.192 {\n  range 192.168.1.5 192.168.1.60;\n  option routers 192.168.1.2;\n  option domain-name-servers 1.1.1.1, 9.9.9.9;\n  # PXE-Server config\n  next-server 192.168.1.3;\n  filename \"lpxelinux.0\";\n}\n\nhost windowsclient {\n  hardware ethernet 00:0C:29:15:BC:DB;\n  fixed-address 192.168.1.4;\n}\n\nhost pxeserver {\n  hardware ethernet 00:50:56:2B:35:1A;\n  fixed-address 192.168.1.3;\n}\n
"},{"location":"dhcp/#21-was-wurde-genau-konfiguriert","title":"2.1. Was wurde genau konfiguriert?","text":"
  • default-lease-time 600;: Legt die Standard-Leasedauer f\u00fcr IP-Adressen auf 600 Sekunden (10 Minuten) fest.
  • max-lease-time 7200;: Setzt die maximale Leasedauer f\u00fcr IP-Adressen auf 7200 Sekunden (2 Stunden).
  • subnet 192.168.1.0 netmask 255.255.255.192 { ... }: Definiert Subnetz, IP-Range Router, DNS-Server und PXE-Server.
  • host windowsclient { ... }: Definiert einen Host mit der MAC-Adresse 00:0C:29:15:BC:DB und der festen IP-Adresse 192.168.1.4.
  • host pxeserver { ... }: Definiert einen Host mit der MAC-Adresse 00:50:56:2B:35:1A und der festen IP-Adresse 192.168.1.3.

Anschliessend identifizieren wir unser Netzwerkinterface mittels ip a und tragen es bei /etc/default/isc-dhcp-server ein. Somit legen wir fest auf welchem Interface unser DHCP-server laufen sollte.

INTERFACESv4=\"ens33\"\n
"},{"location":"dhcp/#3-statische-ip-vergeben","title":"3. Statische IP vergeben","text":"

Nun k\u00f6nnen wir unseren DHCP server eine statische IP geben unter: /etc/netplan/00-installer-config.yaml Ich habe die bereits vorhandene Version wie folgt \u00fcberschrieben.

network:\n  version: 2\n  ethernets:\n    ens33:\n      dhcp4: no\n      addresses:\n        - 192.168.1.2/26\n      nameservers:\n        addresses: [1.1.1.1, 9.9.9.9]\n

Danach folgenden Befehl auf\u00fchren: sudo netplan apply

"},{"location":"dhcp/#4-dienst-neustarten-dhcp-testen","title":"4. Dienst neustarten & DHCP testen","text":"
sudo systemctl restart isc-dhcp-server.service\n

Nun sehen wir auf dem Windows Client die vergebene IP:

Allerdings hat der Client noch keinen Internetzugang.

"},{"location":"dhcp/#5-internetzugang-auf-dem-client-ermoglichen","title":"5. Internetzugang auf dem Client erm\u00f6glichen","text":"
echo 1 > /proc/sys/net/ipv4/ip_forward\niptables \u2013t nat \u2013A POSTROUTING \u2013o eth0 \u2013j MASQUERADE\n
"},{"location":"dhcp/#wireshark","title":"Wireshark","text":"

Durch den Installer kann man sich mit leichtigkeit durchklicken.

Um den DHCP Traffic zu analysieren habe ich auf dem Windows client ipconfig /renew & ipconfig /release ausgef\u00fchrt und dies mit Wireshark aufgenommen. Weil es etwas l\u00e4nger dauerte, gab es ein timeout. Deshalb sind im Bild 2-Mal Request & ACK.

"},{"location":"dhcp/#dhcp-relay","title":"DHCP Relay","text":"

Um diesen Dienst zu verwenden, ben\u00f6tigt man ein DHCP Relay Agent. Der Agent wird ben\u00f6tigt, um Clients von einem separaten Netzwerk mit unserem DHCP-Server zu verbinden.

"},{"location":"dhcp/#1-apt-packet-installieren_1","title":"1. APT-Packet installieren","text":"
sudo apt update\nsudo apt install isc-dhcp-relay\n
"},{"location":"dhcp/#2-konfiguration","title":"2. Konfiguration","text":"

Folgendes config file wie folgt bearbeiten /etc/default/isc-dhcp-relay:

SERVERS=\"192.168.1.2\"\nINTERFACES=\"ens33\"\n
"},{"location":"dhcp/#3-dienst-neustarten","title":"3. Dienst neustarten","text":"
sudo systemctl restart isc-dhcp-relay\n
"},{"location":"dhcp/#udhcpd","title":"udhcpd","text":"

Eine alternative zum isc-dhcp-server w\u00e4re udhcpd. Es wurde entwickelt, um eine ressourcenschonende Implementierung des DHCP-Protokolls bereitzustellen. Wie man sich also vorstellen kann, ist der Hauptvorteil von udhcpc der niedrige Ressourcenverbrauch im Vergleich zu isc-dhcp-relay, ist daf\u00fcr etwas limitierter was die Funktionalit\u00e4t angeht. Ich dachte zuerst, dass die neuste Version laut ihrer Webseite im Jahr 2002 ver\u00f6ffentlicht wurde. Das Debian Packet ist aber aktueller.

"},{"location":"dhcp/#1-apt-packet-installieren_2","title":"1. APT Packet installieren","text":"
sudo apt install udhcpd\n
"},{"location":"dhcp/#2-udhcpd-konfigurieren","title":"2. udhcpd konfigurieren","text":"

/etc/udhcpd.conf mit gew\u00fcnschtem Texteditor \u00f6ffnen und wie folgt bearbeiten:

start 192.168.1.5\nend 192.168.1.60\noption subnet 255.255.255.192\noption router 192.168.1.2\noption dns 1.1.1.1\noption lease 600\ninterface ens33\nlease_file /var/lib/misc/udhcpd.leases\nstatic_lease 00:0C:29:15:BC:DB 192.168.1.4\nstatic_lease 00:50:56:2B:35:1A 192.168.1.3\n
"},{"location":"dhcp/#3-aktivieren-und-dienst-starten","title":"3. Aktivieren und Dienst starten","text":"
sed -i '/DHCPD_ENABLED/ s/no/yes/' /etc/default/udhcpd\ntouch /var/lib/misc/udhcpd.leases\nupdate-rc.d udhcpd defaults\nsudo service udhcpd restart\n

Nun sehen wir auf dem Windows Client wieder die vergebene IP:

"},{"location":"dhcp/#pxe","title":"PXE","text":"

Slitaz Download PXE Auftrag

\"Beim Aufstarten des Clients soll dieser das Betriebssystem \u00fcber den PXE-Server beziehen und ordnungsgem\u00e4ss starten. Die Konfiguration und der Aufbau des Netzwerkes sollen ersichtlich sein.\"

Das setup des PXE-Servers wurde NICHT auf der gleichen VM wie der DHCP vorgenommen.

"},{"location":"dhcp/#1-tftp-server-installieren","title":"1. TFTP-server installieren","text":"

Ein TFTP-Server ist erforderlich, um die Boot-Dateien \u00fcber das Netzwerk bereitzustellen.

apt install tftpd-hpa\nmkdir /srv/tftp\n
"},{"location":"dhcp/#2-pxelinux-konfigurieren","title":"2. PXELinux konfigurieren","text":"
apt install pxelinux syslinux-common\ncp /usr/lib/PXELINUX/lpxelinux.0 /srv/tftp/.\ncp /usr/lib/syslinux/modules/bios/ldlinux.c32 /srv/tftp/.\nmkdir /srv/tftp/pxelinux.cfg\n

Erstelle und bearbeite anschliessend diese Datei /srv/tftp/pxelinux.cfg/default

default slitaz\nprompt 0\nlabel slitaz\n    menu label Slitaz\n    kernel slitaz/bzImage\n    append initrd=slitaz/rootfs4.gz,slitaz/rootfs3.gz,slitaz/rootfs2.gz,slitaz/rootfs1.gz rw root=/dev/null vga=normal autologin\n
"},{"location":"dhcp/#21-was-wurde-hier-konfiguriert","title":"2.1. Was wurde hier konfiguriert?","text":"

PXELinux ist ein Bootloader, der speziell f\u00fcr das Booten \u00fcber das Netzwerk entwickelt wurde und auf Syslinux basiert. Wir installieren es mittels APT. Das syslinux-common Packet enth\u00e4lt einige Abh\u00e4ngikeiten f\u00fcr PXELinux. Hierbei werden lpxelinux.0 und ldlinux.c32 in das TFTP-Verzeichnis kopiert, da sie f\u00fcr den Bootvorgang ben\u00f6tigt werden. Zudem erstellen wir das Verzeichnis /srv/tftp/pxelinux.cfg, wo wir das default config file f\u00fcr PXELinux erstellen.

"},{"location":"dhcp/#3-slitaz-an-den-richtigen-ort-kopieren","title":"3. Slitaz an den richtigen Ort kopieren","text":"
cd ~\nwget http://mirror.slitaz.org/iso/4.0/slitaz-4.0.iso\nmount -o loop slitaz-4.0.iso /mnt\nmkdir /srv/tftp/slitaz\ncp /mnt/boot/bzImage /mnt/boot/rootfs* /srv/tftp/slitaz/.\numount /mnt\n
"},{"location":"dhcp/#31-was-kopieren-wir-hier","title":"3.1. Was kopieren wir hier?","text":"

Hier werden die ben\u00f6tigten Dateien des Betriebssystems Slitaz heruntergeladen und gemountet. Anschliessend werden der Kernel (bzImage) und die initrd-Dateien (rootfs*) in das TFTP-Verzeichnis kopiert.

"},{"location":"dhcp/#4-setup-testen","title":"4. Setup Testen","text":""},{"location":"dhcp/#probleme","title":"Probleme","text":""},{"location":"dhcp/#1-netzwerkadapter","title":"1. Netzwerkadapter","text":"

Ich wusste nicht, wie ich mit den virtuellen Netzwerkadaptern umgehen musste. Ich habe einen NAT-Adapter und ein custom Netzwerksegment erstellt, doch mit dieser Konfiguration hatte ich keine Internetverbindung und dies lag daran, dass ich aus Versehen die ganze Konfiguration auf dem NAT-Adapter gemacht habe.

Weil ich den \u00dcberblick verloren habe, habe ich eine neue VM erstellt und mit einem NAT-Adapter + einem Vnet Adapter hinzugef\u00fcgt. Den NAT-Adapter habe ich nicht angefasst, der diente nur zur Internetverbindung. Die ganze Konfiguration wurde auf dem Vnet Adapter vorgenommen (Vnet 5 in meinem Fall).

"},{"location":"dhcp/#2-gateway","title":"2. Gateway","text":"

Ich habe eine Konfiguration im Internet gefunden, welche eine alte (depprecated) Konfiguration hatte. Man muss mittlerweile mittels routes den gateway setzen.

"},{"location":"dhcp/#3-internetzugang-client","title":"3. Internetzugang Client","text":"

Nun habe ich festgestellt, dass die routes Option ein Fehler war, weil er versucht hat, \u00fcber sich selbst zu routen und irgendeine zus\u00e4tzliche Default Route gesetzt hat, die reingefunkt hat. Anschliessend habe die routes Option entfernt.

"},{"location":"dhcp/#4-internetzugang-server","title":"4. Internetzugang Server","text":"

Obwohl ich einen NAT-Adapter habe, kann ich mit dem DHCP-Server nicht mehr auf das Internet zugreifen. Ich konnte bis jetzt nicht herausfinden warum. Wir tun jetzt einfach so, als w\u00e4re es ein Security Feauture. It's not a bug, it's a feature - a clever human being

"},{"location":"dhcp/#5-wireshark","title":"5. Wireshark","text":"

Zu Beginn habe ich nur ipconfig renew ausgef\u00fchrt ohne ipconfig release. Dies hat dazu gef\u00fchrt, dass ich nur den Acknowledge und den Request sehen konnte, weil der Client sich die restlichen Informationen bereits gemerkt hatte. So konnte ich keine vern\u00fcnftige Analyse durchf\u00fchren.

"},{"location":"dhcp/#reflexion","title":"Reflexion","text":"

Obwohl ich diese Aufgabe im Experts-Kurs bereits schon hatte, konnte ich doch etwas von diesem Auftrag profitieren. Grund daf\u00fcr sind die Zusatzauftr\u00e4ge und der erweiterte Zeitrahmen f\u00fcr die Aufgabe. Ich habe dazugelernt: - DHCP Relay in betrieb nehmen - udchpd aufsetzen - DHCP Traffic mit Wireshark analysieren - Allgemein besseres Verst\u00e4ndnis zu PXE & DHCP

"},{"location":"dhcp/#quellen","title":"Quellen","text":"
  • Offizielle Installation isc-dhcp-server von Canonical https://ubuntu.com/server/docs/how-to-install-and-configure-isc-dhcp-server
  • NAT Routing Ubuntu https://linuxhint.com/configure-nat-on-ubuntu/
  • Setup Blog isc-dhcp-relay von Reintech https://reintech.io/blog/configure-dhcp-relay-agent-ubuntu-2004
"},{"location":"experts/","title":"My GitLab Setup","text":""},{"location":"experts/#my-gitlab-setup","title":"My GitLab Setup","text":"

The purpose of this assignment is to set up a GitLab Server as if it were for a large-scale company.

My GitLab Server was setup in a personal PVE (Proxmox Virtual Environment) as a VM using Docker-Compose.

"},{"location":"experts/#installation-procedure","title":"Installation Procedure","text":""},{"location":"experts/#setup-an-ubuntu-server-and-install-docker-docker-compose","title":"Setup an Ubuntu Server and install Docker & Docker-Compose","text":"

Follow this guide (official Docker installation guide)

and this guide (official Docker-Compose installation guide) Note that after follwing the first guide Docker-Compose may already be installed.

"},{"location":"experts/#setup-gitlab-using-docker-compose","title":"Setup GitLab using Docker-Compose","text":"

Follow this guide

It is recommended to export the $GITLAB_HOME variable like this: export GITLAB_HOME=/srv/gitlab and then adding this to .bashrc so you don't have to do it every time. However, this didn't work for me, so I ended up hard-coding them in the docker-compose.yaml file.

I altered the docker-compose.yaml quite a lot from the one in the manual. I switched to the Commuity Edition of GitLab, altered the hostname to something I may use, hard-coded the $GITLAB_HOME variable (because it wasn't working) and added grafana & prometheus. My file:

version: '3.6'\nservices:\n  web:\n    image: 'gitlab/gitlab-ce:latest'\n    restart: always\n    container_name: gitlab\n    hostname: 'localhost'\n    environment:\n      GITLAB_OMNIBUS_CONFIG: |\n        external_url 'http://localhost:8929'\n        prometheus_monitoring['enable'] = true\n        prometheus['listen_address'] = 'localhost:9090'\n        # Add any other gitlab.rb configuration here, each on its own line\n    ports:\n      - '8929:8929'\n      - '9090:9090'\n    volumes:\n      - '/srv/gitlab/config:/etc/gitlab'\n      - '/srv/gitlab/logs:/var/log/gitlab'\n      - '/srv/gitlab/data:/var/opt/gitlab'\n    shm_size: '1g'\n  grafana:\n    image: 'grafana/grafana'\n    container_name: grafana\n    restart: unless-stopped\n    ports:\n      - '3000:3000'\n    volumes:\n      - grafana-storage:/var/lib/grafana\nvolumes:\n  grafana-storage: {}\n
"},{"location":"experts/#monitoring-solution","title":"Monitoring Solution","text":"

I used Prometheus (which comes preinstalled with GitLab) and Grafana as my monitoring solution.

For Grafana, follow this guide to set it up. It used to come shipped with GitLab just like Prometheus, but was deprecated in 16.0 and removed in 16.3. For this reason, I had to add it in as a separate container in the docker-compose.yml file.

Once I had my Grafana Container up and running, I imported the Prometheus Metrics by adding a connection to 192.168.1.212:9090 (My Prometheus). When it comes to actually adding graphs / dashboards, I found that there are many premade ones here: https://grafana.com/grafana/dashboards/ Just download the JSON and import it into Grafana.

"},{"location":"experts/#gitlab-runner-setup","title":"GitLab Runner Setup","text":"

For the GitLab Runner, I made a separate VM for resource management purposes. Since nothing else is running on this VM, there is no need to use Docker-Compose.

Just like before, I used this guide to install Docker. Then I proceeded to create a volume to store persistant data: docker volume create gitlab-runner-config

To run the GitLab Runner, use:

docker run -d --name gitlab-runner --restart always \\\n    -v /var/run/docker.sock:/var/run/docker.sock \\\n    -v gitlab-runner-config:/etc/gitlab-runner \\\n    gitlab/gitlab-runner:alpine\n

Note that I am using the alpine image because it is more lightweight. The other option would be to use the latest tag which uses ubuntu.

Now we need to register this Runner. In your GitLab Settings you can add a runner, which will enable you to generate an authentication token. I ran this command on my Runner VM (setup in non-interactive mode):

docker run --rm -v /srv/gitlab-runner/config:/etc/gitlab-runner gitlab/gitlab-runner:alpine register \\\n  --non-interactive \\\n  --url \"192.168.1.212\" \\\n  --token \"$RUNNER_TOKEN\" \\\n  --executor \"docker\" \\\n  --docker-image alpine:latest \\\n  --description \"docker-runner\"\n

Then create a project with a CI-CD Pipeline and add the runner to the project.

"},{"location":"experts/#why-only-one-runner","title":"Why only one Runner?","text":""},{"location":"experts/#gitlab-conifguration","title":"GitLab Conifguration","text":""},{"location":"nextcloud-auftrag/","title":"Nextcloud auftrag","text":"

Nextcloud installieren wir mittels snap. Man kann bereits bei der Installation einer Ubuntu Server vm spezifizeren, dass man Nextcloud installieren m\u00f6chte.

Snap bietet zwar den Vorteil, dass man Pakete sehr leicht mit einem Klick installieren kann, wird jedoch trotzdem von vielen Ubuntu-usern verabscheut.

https://snapcraft.io/install/nextcloud/ubuntu

https://chat.openai.com/share/fc9fea12-cc87-497f-bd57-31a54410a7a4

https://chat.openai.com/share/f77371e3-b100-439f-8bc3-5f99b193a814

"},{"location":"nextcloud-auftrag/#installation-von-nextcloud-mittels-snap","title":"Installation von Nextcloud mittels snap","text":"
sudo snap install nextcloud  \nsudo nextcloud.manual-install\n

Man kann auch mittels snap verifizieren, ob der Server l\u00e4uft oder nicht.

sudo snap services nextcloud\n
sudo vim /var/snap/nextcloud/current/nextcloud/config/config.php\n

In diesem File unter trusted domains, seine gew\u00fcnschte Dom\u00e4ne hinzuf\u00fcgen.

"},{"location":"nextcloud-auftrag/#manual-install","title":"Manual Install","text":""},{"location":"pruefung-security/","title":"Security","text":""},{"location":"pruefung-security/#prufung-19062023","title":"Pr\u00fcfung 19.06.2023","text":""},{"location":"pruefung-security/#ueb1","title":"Ueb1","text":""},{"location":"pruefung-security/#linuxusererstellensh","title":"Linuxusererstellen.sh","text":"

Linux user add script for preparation.

cat  /etc/group\n\n# Erstellen der Gruppen\ngroupadd dbusrgrp \ngroupadd dbadmgrp\ngroupadd dbuser10\ngroupadd dbuser11\ngroupadd dbuser12\n\n\n# Anzeige welche User existieren:\ncat /etc/passwd\n\n# Erstellen der User (UserID und PW sind identisch)\nuseradd -p $(openssl passwd -1 dbuser10) -g dbuser10  -G dbuser10           -s /bin/bash -c \"Test user dbuser10\"  -d /home/dbuser10   dbuser10\nuseradd -p $(openssl passwd -1 dbuser11) -g dbuser11  -G dbuser11,dbusrgrp  -s /bin/bash -c \"Test user dbuser11\"  -d /home/dbuser11   dbuser11\nuseradd -p $(openssl passwd -1 dbuser12) -g dbuser12  -G dbuser12,dbadmgrp  -s /bin/bash -c \"Test user dbuser12\"  -d /home/dbuser12   dbuser12\n
"},{"location":"pruefung-security/#ueb1_grant_usersql","title":"Ueb1_GRANT_User.sql","text":"
GRANT DATAACCESS ON DBBW001 TO GROUP dbusrgrp;\nGRANT DATAACCESS ON DBBW002 TO GROUP dbusrgrp;\n\nGRANT DBADM ON DATABASE DBBW001 TO GROUP dbadmgrp WITHOUT DATAACCESS;\nGRANT DBADM ON DATABASE DBBW002 TO GROUP dbadmgrp WITHOUT DATAACCESS;\n
"},{"location":"pruefung-security/#ueb2","title":"Ueb2","text":"

The objective of this assignment was to make the pre-written scripts function. You may have to run db2 CONNECT TO <database-name> after you have run the pre-written scripts, as they have a connection reset command in them.

"},{"location":"pruefung-security/#ueb2_grant_usersql","title":"Ueb2_GRANT_User.sql","text":"
--\n-- Autorisierungen f\u00fcr User dbuser10\n--\n\nGRANT CONNECT ON DATABASE TO USER dbuser10;\nGRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER dbuser10;\nGRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER dbuser10;\nGRANT SELECT ON TABLE BIBLIO.TARTIKEL TO USER dbuser10;\n\n--\n-- Autorisierungen f\u00fcr User dbuser11\n--\n\nGRANT CONNECT ON DATABASE TO USER dbuser11;\nGRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER dbuser11;\nGRANT SELECT ON TABLE BIBLIO.TARTIKEL TO USER dbuser11;\n\n--\n-- Autorisierungen f\u00fcr User dbuser12\n--\n\nGRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER dbuser12;\nGRANT SELECT ON TABLE BIBLIO.TARTIKEL TO USER dbuser12;\n
"},{"location":"pruefung-security/#ueb3","title":"Ueb3","text":"

The premise of this assignment is the same as Ueb2. To connect to a Database as a simple Database user, use this command:

db2 CONNECT TO DBBW002 USER dbuser10 USING dbuser10\n
"},{"location":"pruefung-security/#ueb3_grant_usersql","title":"Ueb3_GRANT_User.sql","text":"
--\n-- Speichern Sie in diesem SQL Script die notwendigen GRANT Statements\n--\n\n--\n-- Autorisierungen f\u00fcr User dbuser10\n--\n\nGRANT CREATETAB ON DATABASE TO USER dbuser10;\nGRANT IMPLICIT_SCHEMA ON DATABASE TO USER dbuser10;\nGRANT USE OF TABLESPACE USERSPACE1 TO USER dbuser10;\n\n--\n-- Autorisierungen f\u00fcr User dbuser11\n--\n\nGRANT CREATETAB ON DATABASE TO USER dbuser11;\nGRANT IMPLICIT_SCHEMA ON DATABASE TO USER dbuser11;\nGRANT USE OF TABLESPACE USERSPACE1 TO USER dbuser11;\n\n--\n-- Autorisierungen f\u00fcr User dbuser12\n--\n\nGRANT CREATETAB ON DATABASE TO USER dbuser12;\n
"},{"location":"pruefung-security/#ueb4","title":"Ueb4","text":"

In this assignment, you must create a database role that has certain permissions on certain tables. After that, you must create two UNIX users that have the newly created role (in this case: TESTER)

"},{"location":"pruefung-security/#ueb4_grant_rolesql","title":"Ueb4_GRANT_ROLE.sql","text":"
--\n-- Speichern Sie in diesem SQL Script die notwendigen GRANT Statements\n--\n\nCREATE ROLE TESTER;\n\n--\n-- Autorisierungen f\u00fcr User dbuser10\n--\n\nGRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER10.TDBS_PERSON TO TESTER;\nGRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER10.TDBS_ABTEILUNG TO TESTER;\n\n--\n-- Autorisierungen f\u00fcr User dbuser11\n--\n\nGRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER11.TDBS_PERSON TO TESTER;\nGRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER11.TDBS_ABTEILUNG TO TESTER;\n\n--\n-- Autorisierungen f\u00fcr User dbuser12\n--\n\nGRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER12.TDBS_PERSON TO TESTER;\nGRANT SELECT, INSERT, UPDATE, DELETE ON DBUSER12.TDBS_ABTEILUNG TO TESTER;\n\n

Afterwards, you must assign this role to the users (in this case tester01 and tester02).

db2 GRANT TESTER TO USER tester01;\ndb2 GRANT TESTER TO USER tester02;\n

Lastly, I had to enable the Workload for the users.

db2 GRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO ROLE TESTER;\n
"},{"location":"pxe-mitschnitt/","title":"Mitschnitt-DHCP-PXE-Debian","text":"
b## 2022-03-08, lp5jvogel\n## Slitaz per PXE / Debian 11\n## DHCP SERVER in Betrieb nehmen\napt update\napt install isc-dhcp-server\nvi /etc/dhcp/dhcpd.conf\n# ACHTUNG: Mac-Adresse anpassen!\n----8<-------8<----- /etc/dhcp/dhcpd.conf\nauthoritative;\nsubnet 192.168.0.0 netmask 255.255.255.0  {\n}\n\nhost client {\n   fixed-address 192.168.0.10;\n   hardware ethernet 08:00:27:e8:30:46;\n   option routers 192.168.0.1;\n   option host-name \"client\";\n   next-server 192.168.0.1;\n   filename \"gpxelinux.0\";\n}\n---->8------->8----- /etc/dhcp/dhcpd.conf\nip a add 192.168.0.10/24 up dev enp0s3\nservice isc-dhcp-server restart\n\n\n## TFTP SERVER in Betrieb nehmen\napt install tftpd\nmkdir /srv/tftp\n\n## PXELinux in Betrieb nehmen\napt install pxelinux syslinux-common\ncp /usr/lib/PXELINUX/gpxelinux.0 /srv/tftp/.\ncp /usr/lib/syslinux/modules/bios/ldlinux.c32 /srv/tftp/.\nmkdir /srv/tftp/pxelinux.cfg\nvi /srv/tftp/pxelinux.cfg/default\n----8<----8<-- /srv/tftp/pxelinux.cfg/default\ndefault slitaz\nprompt 0\nlabel slitaz\n    menu label Slitaz\n    kernel slitaz/bzImage\n    append initrd=slitaz/rootfs4.gz,slitaz/rootfs3.gz,slitaz/rootfs2.gz,slitaz/rootfs1.gz rw root=/dev/null vga=normal autologin\n---->8---->8-- /srv/tftp/pxelinux.cfg/default\n\n## Slitaz an den richtigen Ort kopieren\ncd ~\nwget http://mirror.slitaz.org/iso/4.0/slitaz-4.0.iso\nmount -o loop slitaz-4.0.iso /mnt\nmkdir /srv/tftp/slitaz\ncp /mnt/boot/bzImage /mnt/boot/rootfs* /srv/tftp/slitaz/.\numount /mnt\n\n## alles eingerichtet, jetzt Client booten\n
"},{"location":"zli-m109/","title":"ZLI Module 109","text":""},{"location":"zli-m109/#zli-module-109","title":"ZLI Module 109","text":"

\"Dienste in der Public Cloud betreiben und \u00fcberwachen\" Course: https://moodle.zli.ch/course/view.php?id=1610

"},{"location":"zli-m109/#auftrag-11-einfache-html-seite-erstellen-und-mit-ftp-deployen","title":"Auftrag 1.1: Einfache HTML Seite erstellen und mit FTP \u00abdeployen\u00bb","text":""},{"location":"zli-m109/#auftrag-22-git-zur-sourcecode-und-konfigurationsverwaltung","title":"Auftrag 2.2: Git zur Sourcecode- und Konfigurationsverwaltung","text":"

https://moodle.zli.ch/mod/h5pactivity/view.php?id=116428 https://github.com/Sephley/Zli-m109

Configure git username & email

git config --global user.name \"user\"\n\ngit config --global user.email \"mail@mail.com\"\n
"},{"location":"zli-m109/#auftrag-23-github-einfuhrung","title":"Auftrag 2.3: GitHub Einf\u00fchrung","text":"

https://github.com/Sephley/Zli-m109

"},{"location":"zli-m109/#auftrag-32","title":"Auftrag 3.2:","text":"
sudo apt install -y apt-transport-https ca-certificates curl gnupg-agent software-properties-common\n
"},{"location":"zli-m109/#intallation-minikube","title":"Intallation minikube","text":"

Minikube can create a cluster containing only one node.

sudo apt install curl wget apt-transport-https -y  \nwget https://storage.googleapis.com/minikube/releases/latest/minikube-linux-amd64  \nsudo cp minikube-linux-amd64 /usr/local/bin/minikube  \nsudo chmod +x /usr/local/bin/minikube  \ncurl -LO https://storage.googleapis.com/kubernetes-release/release/`curl -s https://storage.googleapis.com/kubernetes-release/release/stable.txt`/bin/linux/amd64/kubectl  \nsudo mv kubectl /usr/local/bin/  \nchmod +x kubectl  \nminikube start --driver=docker  \nminikube addons enable ingress  \nminikube addons enable dashboard  \nminikube addons enable metrics-server  \nsudo reboot  \n
"},{"location":"zli-m109/#auftrag-42-container-orchestration-mit-docker-compose","title":"Auftrag 4.2: Container Orchestration mit Docker Compose","text":"

see https://docs.docker.com/compose/gettingstarted/ for how to set up a generic docker-compose application

see https://github.com/Sephley/m109-site for all the files

Docker-compose requires a docker-compose.yml file that can set up multiple Containers. Using docker compose up you start the containers

"},{"location":"zli-m109/#kubernetes","title":"Kubernetes","text":""},{"location":"zli-m109/#pod","title":"Pod","text":"

The Pod is the smallest unit in Kubernetes, usually only runs 1 Application. Each Pod gets its own IP address, not the container. They are rather ephemeral, which means they are prone to crash.

"},{"location":"zli-m109/#service","title":"Service","text":"

is used to attach an IP address to a pod, so that if it dies, the new one just uses the service to retain the IP address. It is possible to specify, whether the service is internal or external.

"},{"location":"zli-m109/#ingress","title":"Ingress","text":"

Forwards IP-address of pod to domain name of application.

"},{"location":"zli-m109/#configmap","title":"ConfigMap","text":"

Is the external Configuration of your application. Is only for non-confidential data! Unless you use secret to encrypt it.

"},{"location":"zli-m109/#volumes-storage","title":"Volumes / Storage","text":"

Attaches a physical storage to a Pod, can be locally connected or also via Cloud. Think of it as an external drive plugged in to the kubernetes cluster.

"},{"location":"zli-m109/#deployment","title":"Deployment","text":"

A deployment is a template for creating pods.

"},{"location":"zli-m109/#kubernetes-configuration","title":"Kubernetes Configuration","text":"

deployments get sent to the API server. Each config file (written in yml) has 3 parts. The metadata, the specification and the third part defines the type of configuration (like service or deployment). Kubernetes always compares the desired state with the actual state and then does anything it can to reach the desired state if that is not the case.

"},{"location":"zli-m109/#minikube-kubernetes-ganz-einfach","title":"Minikube - Kubernetes ganz einfach","text":"

see https://github.com/sephley/dev_minikube also https://kubernetes.io/docs/home/

Note that the names 'mongo-config' or 'mongo-secret' do not need to be named this way. Kubernetes uses the 'name: ' key to differenciate between stuff.

"},{"location":"zli-m109/#mongo-configyml","title":"mongo-config.yml","text":"

mongo-config.yml is the ConfigMap Configuration File. You should only create this once as you will reference it a lot.

"},{"location":"zli-m109/#mongo-secretyml","title":"mongo-secret.yml","text":"

mongo-secret.yml add your encode secrets (username and password) into this file. to encode you can run: echo -n <word to encode> | base64 Once you have added these values they can be referenced by different deployments.

"},{"location":"zli-m109/#mongoyml","title":"mongo.yml","text":"

mongo.yml the spec section of the file specifys the deployment specific stuff like type of webserver. the template section is like a whole new deployment with its own spec section etc. It configures the Pod within the deployment. You also set your docker image here.

lables are key/value pairs. They are for identifiying the \"family\" of the pods, so that for example two pods with the same label would have similar application running on them. Lables are required of Pods and are good practice for anythin else. You can call the labes whatever you want, it just has to be in key/value format like: \"app: nginx\" or \"mykey: myvalue\". \"app:\" is the standard key.

selector defines that all the pods that have label x belong to deployment y.

replicas defines how many pods you want to create with the deployment.

"},{"location":"zli-m109/#webappyml","title":"webapp.yml","text":"

webapp.yml is very similar to te mongo.yml file, as it is what runs the webservice based on the mongodb. The deployment is exactly the same, except for labels and the extra envirionment variable.

You can reference things from other files using valueFrom. This applies to all files.

type: Nodeport The nodePort is used to make the service available externally. Must be between 30000-32767.

"},{"location":"zli-m109/#deployment_1","title":"Deployment","text":"
kubectl apply -f mongo-config.yaml  \nkubectl apply -f mongo-secret.yaml  \nkubectl apply -f mongo.yaml  \nkubectl apply -f webapp.yaml\n

kubectl get all outputs all the components created in the cluster, whicht includes deployments, pods and all the services.

kubectl get can be used for everything in the cluster, like secrets, configmap, pods etc. Example: kubectl get secret

kubectl --help for help lol. You can also use the --help parameter for kubectl get more specific help.

kubectl describe service webapp-service to get info on your webapp deployment. Outputs stuff like IP, name, port etc. also works for pods: kubectl describe pod mongo-deployment-564b4bdfdf-jx66n you can see name of pod from kubectl get output.

kubectl logs mongo-deployment-564b4bdfdf-jx66n to see logs.

minikube ip to get IP. Now your application is accessible in your webbrowser. Remember to specify the external port (nodePort).

"},{"location":"zli-m109/#auftrag-7-quotes-app","title":"Auftrag 7: Quotes App","text":"

Username: joshur (namespace = joshur-dev)

API token: sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y

Login command: oc login --token=sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y --server=https://api.sandbox-m3.1530.p1.openshiftapps.com:6443

"},{"location":"zli-m109/#variables","title":"Variables","text":"

Username (username): joshur Authorization token (token): sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y API server URL (api_server_url): https://api.sandbox-m3.1530.p1.openshiftapps.com:6443 Name of the cluster (cluster_name): api-sandbox-m3-1530-p1-openshiftapps-com:6443 Context assigned to us (context): joshur-dev/api-sandbox-m3-1530-p1-openshiftapps-com:6443/joshur

"},{"location":"zli-m109/#set-local-kubernetes-configuration","title":"Set Local Kubernetes configuration","text":"

Make sure to run the login command listed above before you proceed!

Set credentials: kubectl config set-credentials joshur/api-sandbox-m3-1530-p1-openshiftapps-com:6443 --token sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y Set cluster: kubectl config set-cluster api-sandbox-m3-1530-p1-openshiftapps-com:6443 --server=https://api.sandbox-m3.1530.p1.openshiftapps.com:6443 Set context: kubectl config set-context joshur-dev/api-sandbox-m3-1530-p1-openshiftapps-com:6443/joshur --user=joshur/https://api.sandbox-m3.1530.p1.openshiftapps.com:6443 --namespace=joshur-dev --cluster=api-sandbox-m3-1530-p1-openshiftapps-com:6443 Use context: kubectl config use-context joshur-dev/api-sandbox-m3-1530-p1-openshiftapps-com:6443/joshur

"},{"location":"zli-m109/#create-files","title":"Create files","text":"

First, clone the repositories that contain the yml files we need. git clone https://github.com/redhat-developer-demos/quotesweb.git git clone https://github.com/redhat-developer-demos/quotemysql.git git clone https://github.com/redhat-developer-demos/qotd-python.git

Create the following files in the qotd-python/k8s directory

kubectl create -f quotes-deployment.yaml  \nkubectl create -f service.yaml  \nkubectl create -f route.yaml\n

use kubectl get routes to view your new routes. run curl https://quotes-joshur-dev.apps.sandbox-m3.1530.p1.openshiftapps.com/quotes to see your file.

"},{"location":"zli-m109/#repo-links","title":"repo links","text":"

https://github.com/redhat-developer-demos/quotesweb/ https://github.com/redhat-developer-demos/qotd-python/ https://github.com/redhat-developer-demos/quotemysql/

"},{"location":"zusatz-pruefung/","title":"Zusatz-Security","text":""},{"location":"zusatz-pruefung/#federated-datasources","title":"Federated Datasources","text":"

Note that you will also need to hand in a documentation for this assignment. Assignment

"},{"location":"zusatz-pruefung/#part-1","title":"Part 1","text":"
  • connect to dbbw004 and run the scripts from Olat as user db2inst1
  • add this command to the CONFIG_DATABASE.sql file
update db cfg for dbbw004 using LOGSECOND 200;\n
  • run the script HRACCESS_Create.sql.
  • run the script HRACCESS_LOAD_DATA.sql. This will take a while.
  • run the script HRACCESS_COUNT_ROWS.sql This verifies if the Data was loaded.
  • create a linux user called m141fed. To do so, run the following command as root:
useradd -p $(openssl passwd -1 m141fed) -s /bin/bash m141fed -d /home/m141fed\n

Then proceed to grant all the priviliges the user needs and save them in the script HRACCESS_GRANT_m141fed.sql

"},{"location":"zusatz-pruefung/#hraccess_grant_m141fedsql","title":"HRACCESS_GRANT_m141fed.sql","text":"
GRANT CONNECT ON DATABASE TO USER m141fed;\nGRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER m141fed;\nGRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER m141fed;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPARTMENTS TO USER m141fed;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_EMP TO USER m141fed;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_MANAGER TO USER m141fed;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.EMPLOYEES TO USER m141fed;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.SALARIES TO USER m141fed;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.TITLES TO USER m141fed;\n
"},{"location":"zusatz-pruefung/#part-2","title":"Part 2","text":"
  • configure federated datasources as documented in the db2 Knowledge Center All the commands should be saved into the script HRREMOTE_Create.sql. You should also create a script HRREMOTE_Drop.sql where you remove all the data.

For this part you must be connected to DBBW003! First run this: UPDATE DBM CFG USING FEDERATED YES; and proceed to restart your DBM (it's probably easier to simply restart the VM)

"},{"location":"zusatz-pruefung/#hrremote_createsql","title":"HRREMOTE_Create.sql","text":"
CATALOG TCPIP NODE db2_node REMOTE system42 SERVER db2tcp42;\n\n-- Wrapper registrieren\nCREATE WRAPPER DRDA;\n\n-- Server Definitionen registrieren\nCREATE SERVER BBW TYPE DB2/LUW VERSION 11 WRAPPER DRDA AUTHORIZATION \"db2inst1\" PASSWORD \"db2inst1\" OPTIONS (DBNAME 'DBBW004') ;\n\n-- User Mapping erstellen, um dem Benutzer den Zugriff auf den remote server zu geben\nCREATE USER MAPPING FOR DB2INST1 SERVER BBW OPTIONS (REMOTE_AUTHID 'db2inst1', REMOTE_PASSWORD 'db2inst1');\n\n-- Nicknames aus DBBW004 hinzuf\u00fcgen\nCREATE NICKNAME HRREMOTE.DEPARTMENTS FOR BBW.HRACCESS.DEPARTMENTS;\nCREATE NICKNAME HRREMOTE.DEPT_MANAGER FOR BBW.HRACCESS.DEPT_MANAGER;\nCREATE NICKNAME HRREMOTE.EMPLOYEES FOR BBW.HRACCESS.EMPLOYEES;\nCREATE NICKNAME HRREMOTE.DEPT_EMP FOR BBW.HRACCESS.DEPT_EMP;\nCREATE NICKNAME HRREMOTE.TITLES FOR BBW.HRACCESS.TITLES;\nCREATE NICKNAME HRREMOTE.SALARIES FOR BBW.HRACCESS.SALARIES;\n
"},{"location":"zusatz-pruefung/#hrremote_dropsql","title":"HRREMOTE_Drop.sql","text":"
-- Nicknames l\u00f6schen\nDROP NICKNAME HRREMOTE.DEPARTMENTS;\nDROP NICKNAME HRREMOTE.DEPT_MANAGER;\nDROP NICKNAME HRREMOTE.EMPLOYEES;\nDROP NICKNAME HRREMOTE.DEPT_EMP;\nDROP NICKNAME HRREMOTE.TITLES;\nDROP NICKNAME HRREMOTE.SALARIES;\n\n-- User Mapping l\u00f6schen\nDROP USER MAPPING FOR DB2INST1 SERVER BBW;\n\n-- Server-Definition l\u00f6schen\nDROP SERVER BBW;\n\n-- Wrapper l\u00f6schen\nDROP WRAPPER DRDA;\n\n-- Node entfernen\nUNCATALOG NODE db2_node;\n

After running the script HRREMOTE_Create.sql, run HRREMOTE_CHECK_ACCESS.sql.

"},{"location":"zusatz-pruefung/#hraccess_grant_bbwusersql","title":"HRACCESS_GRANT_bbwuser.sql","text":"
  • Create a script named HRACCESS_GRANT_bbwuser.sql
  • Connect to dbbw004
  • Add the following content to the script and run the script.
GRANT CONNECT ON DATABASE TO USER bbwuser;\nGRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER bbwuser;\nGRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER bbwuser;\nGRANT EXECUTE ON PACKAGE NULLID.SYSSN200 TO USER bbwuser;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPARTMENTS TO USER bbwuser;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_EMP TO USER bbwuser;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_MANAGER TO USER bbwuser;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.EMPLOYEES TO USER bbwuser;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.SALARIES TO USER bbwuser;\nGRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.TITLES TO USER bbwuser;\n

If this was successful, you can connect to dbbw003 as bbwuser and run the script HRREMOTE_CHECK_ACCESS.sql .

If this was not successful, run the following command as db2inst1 in dbbw003.

CREATE USER MAPPING FOR BBWUSER SERVER BBW OPTIONS (REMOTE_AUTHID 'bbwuser', REMOTE_PASSWORD 'bbwuser');\n
"},{"location":"acme/","title":"M300 Auftrag ACME","text":""},{"location":"acme/aufgaben/","title":"Aufgaben","text":""},{"location":"acme/aufgaben/#aufgaben","title":"Aufgaben","text":"
  • = fertig
  • = WIP

Checkliste der Aufgaben gem\u00e4ss Olat:

  • Bind DNS f\u00fcr Letsencrypt aufsetzen
  • Certbot in Betrieb nehmen
"},{"location":"acme/aufgaben/bind-letsencrypt/","title":"Bind DNS f\u00fcr Letsencrypt","text":""},{"location":"acme/aufgaben/bind-letsencrypt/#bind-dns-fur-letsencrypt-aufsetzen","title":"Bind DNS f\u00fcr Letsencrypt aufsetzen","text":"

Anleitung von Olat

Ich werde hier noch meine Probleme und Anmerkungen bei diesem Prozess erl\u00e4utern.

"},{"location":"acme/aufgaben/certbot/","title":"Certbot in Betrieb nehmen","text":""},{"location":"acme/glossar/","title":"Glossar","text":""},{"location":"acme/glossar/#glossar","title":"Glossar","text":"
  • = fertig
  • = WIP

Checkliste meiner selbst-definierten Themen:

  • Was ist ACME?
  • Let's Encrypt Zertifikate
  • Wildcard Zertifikate
"},{"location":"acme/glossar/acme/","title":"Was-ist-ACME","text":""},{"location":"acme/glossar/acme/#was-ist-acme","title":"Was ist ACME?","text":"

https://letsencrypt.org/docs/client-options/

"},{"location":"acme/glossar/lets-encrypt/","title":"Let's Encrypt Zertifikate","text":""},{"location":"acme/glossar/wildcard/","title":"Wildcard Zertifikate","text":""},{"location":"dns/","title":"DNS Modul 300","text":""},{"location":"dns/#dns-modul-300","title":"DNS Modul 300","text":"

Link zum Auftrag

"},{"location":"dns/#vorwissen","title":"Vorwissen","text":"

Ich habe bereits im Gesch\u00e4ft einen Bind9 DNS-Server aufgesetzt. Dies ist nun schon zwei Jahre her, von dem her bin ich also, doch froh kann ich dies erneut tun. Mit DynDNS habe ich auch schon in meiner privaten Infrastruktur Erfahrungen gemacht.

"},{"location":"dns/#aufbau","title":"Aufbau","text":"

Die praktischen Aufgaben mit den pers\u00f6nlichen Erfahrungen finden Sie unter dem praktischen Block. Das Glossar dient als Hilfsmittel, um den praktischen Teil zu verstehen.

"},{"location":"dns/#quellen","title":"Quellen","text":""},{"location":"dns/#glossar","title":"Glossar","text":"
  • DNS Zone file Erkl\u00e4rung von Cloudflare https://www.cloudflare.com/learning/dns/glossary/dns-zone/
  • Primary / Secondary Konzept von Cloudflare https://www.cloudflare.com/learning/dns/glossary/primary-secondary-dns/
"},{"location":"dns/#bind9","title":"Bind9","text":"
  • Bind9 setup von Linuxtechi https://www.linuxtechi.com/install-configure-bind-9-dns-server-ubuntu-debian/
  • Bind9 setup von Cherryservers https://www.cherryservers.com/blog/how-to-install-and-configure-a-private-bind-dns-server-on-ubuntu-22-04
  • Bind9 offizielle Dokumentation https://bind9.readthedocs.io/en/latest/chapter3.html
  • Bind9 als Secondary DNS von Serverspace https://serverspace.io/support/help/bind9-as-a-secondary-dns-server-on-ubuntu/
"},{"location":"dns/glossar/","title":"Glossar","text":""},{"location":"dns/glossar/#glossar","title":"Glossar","text":"

Ich werde diesen Abschnitt referenzieren, wenn ich bei dem praktischen Teil etwas begr\u00fcnden oder belegen m\u00f6chte. Hier ist nicht nur Theorie, sondern auch Beispiele aus meinem Gesch\u00e4ft sowie aus der Freizeit / pers\u00f6nlichen Umgebung.

  • = fertig
  • = WIP

Checkliste der Auftr\u00e4ge gem\u00e4ss Olat:

  • Erkl\u00e4ren Sie die Zonendatei inkl. allen Parametern im SOA.
  • Recherchieren Sie \u00fcber die Anf\u00e4nge des Internets und setzen Sie die Primary / Secondary DNS-Infrastruktur in den Zusammenhang des redundanten dezentralen Konzepts.
  • Recherchieren Sie verschiedene Record-Typen und erkl\u00e4ren Sie diese.
  • DynDNS hat einige spannende Probleme zu entdecken: Wie ist das mit den Timeouts? Wie l\u00f6sen die das mit den vielen Anfragen? Wie ist DynDNS eigentlich entstanden?
  • DNS unter IPv6 \u2013 was \u00e4ndert sich?
  • Reverse DNS unter IPv6: https://tech.rana.at/2017/12/08/

Damit es nochmals geschrieben steht, DNS steht bedeutet ausgeschrieben: \"Domain Name System\".

"},{"location":"dns/glossar/beginning/","title":"Anf\u00e4nge-des-Internets","text":""},{"location":"dns/glossar/beginning/#anfange-des-internets","title":"Anf\u00e4nge des Internets","text":"
  • Recherchieren Sie \u00fcber die Anf\u00e4nge des Internets und setzen Sie die Primary / Secondary DNS-Infrastruktur in den Zusammenhang des redundanten dezentralen Konzepts.

Der Ursprung des DNS liegt in den fr\u00fchen Tagen des Internets, als es noch ARPANET hiess und nur wenige Forscher und Institutionen miteinander vernetzt waren. Zu dieser Zeit wurden Hostnamen und ihre zugeh\u00f6rigen IP-Adressen in einer einzigen Datei namens \"HOSTS.TXT\" verwaltet, die zentral gepflegt wurde.

In den 1980er Jahren wurde das DNS-Konzept entwickelt, um diese Probleme zu l\u00f6sen.

Im praktischen Teil k\u00f6nnen Sie sehen wie ich das implementiert habe, wobei ich keine geographische Verteilung implementiert habe, w\u00e4re aber eigentlich Teil des redundanten dezentralen Konzepts.

"},{"location":"dns/glossar/dnsipv6/","title":"DNS-unter-IPv6","text":""},{"location":"dns/glossar/dnsipv6/#dns-unter-ipv6","title":"DNS unter IPv6","text":"
  • DNS unter IPv6 \u2013 was \u00e4ndert sich?
"},{"location":"dns/glossar/dnsipv6/#reverse-dns-unter-ipv6","title":"Reverse DNS unter IPv6","text":"
  • Reverse DNS unter IPv6: https://tech.rana.at/2017/12/08/
"},{"location":"dns/glossar/dyndns/","title":"DynDNS","text":""},{"location":"dns/glossar/dyndns/#dyndns","title":"DynDNS","text":"
  • DynDNS hat einige spannende Probleme zu entdecken: Wie ist das mit den Timeouts? Wie l\u00f6sen die das mit den vielen Anfragen? Wie ist DynDNS eigentlich entstanden?

DynDNS (Dynamic Domain Name System) ist ein Dienst, der es erm\u00f6glicht, eine st\u00e4ndig wechselnde IP-Adresse, wie sie bei vielen Internet Service Providern (ISPs) f\u00fcr Privatkunden \u00fcblich ist, mit einem festen Domainnamen zu verkn\u00fcpfen.

"},{"location":"dns/glossar/dyndns/#handling-von-timeouts","title":"Handling von Timeouts","text":"
  • Update-Intervalle: Die Client-Software sendet regelm\u00e4ssig Updates, um sicherzustellen, dass die DNS-Eintr\u00e4ge aktuell sind. Dies kann in festgelegten Intervallen (z.B. alle 5 Minuten) oder bei Erkennung einer IP-\u00c4nderung geschehen.
  • TTL (Time To Live): DNS-Eintr\u00e4ge haben eine TTL, die bestimmt, wie lange ein DNS-Eintrag gecached werden darf. DynDNS setzt oft eine relativ kurze TTL (z.B. 300 Sekunden), um sicherzustellen, dass \u00c4nderungen schnell wirksam werden.
"},{"location":"dns/glossar/dyndns/#handling-von-anfragen","title":"Handling von Anfragen","text":"
  • Lastverteilung (Load Balancing): DynDNS-Dienste nutzen Lastverteilung, um eingehende Anfragen auf mehrere Server zu verteilen, was die Last auf einzelne Server reduziert.
  • Caching: DNS-Server und ISPs cachen DNS-Eintr\u00e4ge f\u00fcr die Dauer der TTL, was die Anzahl der Anfragen an den DynDNS-Dienst reduziert.
  • Rate Limiting: Einige Dienste implementieren Rate Limiting, um die Anzahl der Updates von einzelnen Clients zu begrenzen und Missbrauch zu verhindern.
"},{"location":"dns/glossar/dyndns/#beispiel","title":"Beispiel","text":"

DynDNS (DDNS) ist sehr n\u00fctzlich, wenn man von seinem ISP keine Statische Public IP erh\u00e4lt, aber trotzdem Dienste in einem lokalen Netzwerk ver\u00f6ffentlichen m\u00f6chte. In unserer geteilten Umgebung (Wyler, Oberle, Chio, Hurley) verwenden wir den DynDNS von Swisscom.

So k\u00f6nnen wir mittels Cloudflare Zero Trust unsere Dienste verwalten und wenn n\u00f6tig ver\u00f6ffentlichen.

"},{"location":"dns/glossar/primsec/","title":"Primary-Secondary-Konzept","text":""},{"location":"dns/glossar/primsec/#primary-secondary-konzept","title":"Primary / Secondary Konzept","text":"
  • Recherchieren Sie \u00fcber die Anf\u00e4nge des Internets und setzen Sie die Primary / Secondary DNS-Infrastruktur in den Zusammenhang des redundanten dezentralen Konzepts.

Wie Mario und Luigi, hat man Primary (master) und Secondary (slave) DNS-Server. Die Hauptaufgabe des sekund\u00e4ren DNS ist die Redundanz, falls der prim\u00e4re ausf\u00e4llt. Somit vermeidet man einen Single point of failure und man kann den Load aufteilen. F\u00fcr den slave werden read-only kopien der Zonendateien eingesetzt und alle information erhaltet er direkt von dem prim\u00e4ren DNS-Server.

"},{"location":"dns/glossar/rectypes/","title":"Record-Typen","text":""},{"location":"dns/glossar/rectypes/#record-typen","title":"Record-Typen","text":"
  • Recherchieren Sie verschiedene Record-Typen und erkl\u00e4ren Sie diese.
Record Beschreibung Beispiel A Das \"A\" steht f\u00fcr Adresse. Dies ist der fundamentalste Bestandteil des DNS, denn er verbindet Domainnamen mit IP-Adressen. www IN A 192.168.1.4 AAAA Gleich wie A, aber mit IPv6. www IN AAAA 2607:f8b0:400a:800::200e CNAME Canonical Name record. CNAME Records k\u00f6nnen einem Dom\u00e4nen-Namen einen weiteren Namen zuweisen. Er wird oft daf\u00fcr verwendet, Subdom\u00e4nen wie www oder mail, der Dom\u00e4ne, die den Inhalt hostet zuzuordnen. www.sephley.local CNAME www.sephley.com Alias Wie ein CNAME record, k\u00f6nnen Alias Records einem Dom\u00e4nen-Namen einen weiteren Namen zuweisen. Allerdings k\u00f6nnen Aliases bestehen, auch wenn bereits ein Record mit demselben Namen existiert. @ IN ALIAS sephley.local. MX Mail Exchange Record. Sie leiten Mails an die dazugeh\u00f6rigen Server weiter und werden auch zur Priorisierung verwendet sephley.local. IN MX 10 mail.sephley.local. NS NS steht f\u00fcr \u00abName Server\u00bb. Er entscheidet, welcher DNS-Server massgeblich ist. @ IN NS primary.sephley.local. PTR PTR steht f\u00fcr \u00abPointer\u00bb und macht das Gegenteil des A Records. Er kann IP-Adressen in Domain Namen verwandeln, was bedeutet das er in der Reverse-Zone verwendet wird. 2 IN PTR primary.sephley.local"},{"location":"dns/glossar/zonefile/","title":"Zonendatei","text":""},{"location":"dns/glossar/zonefile/#zonendatei","title":"Zonendatei","text":"
  • Erkl\u00e4ren Sie die Zonendatei inkl. allen Parametern im SOA.

Die Zonendatei enth\u00e4lt die gesamte Hierarchie der Zone inklusive allen Records. Eine Zonendatei startet immer mit einem SOA record, wo alle wichtigen Infos zur Zone stehen (z.B. Kontakt zum Zonenadmin).

Hier sind die Parameter eines SOA-Eintrags und deren Bedeutung:

"},{"location":"dns/glossar/zonefile/#primary-name-server-mname","title":"Primary Name Server (MNAME)","text":"

Dies ist der vollqualifizierte Domainname (FQDN) des prim\u00e4ren Nameservers f\u00fcr die Zone. Er ist der erste Server, der autoritative Antworten f\u00fcr die Zone liefert.

"},{"location":"dns/glossar/zonefile/#responsible-person-rname","title":"Responsible Person (RNAME)","text":"

Dies ist die E-Mail-Adresse der Person, die f\u00fcr die Verwaltung der Zone verantwortlich ist. Das \"@\"-Zeichen wird durch einen Punkt (\".\") ersetzt. Zum Beispiel, \"admin.example.com\" bedeutet \"admin@example.com\".

"},{"location":"dns/glossar/zonefile/#serial-number","title":"Serial Number","text":"

Eine fortlaufende Nummer, die bei jeder \u00c4nderung der Zonendatei erh\u00f6ht wird. Dies hilft sekund\u00e4ren Nameservern zu erkennen, wann die Zonendatei aktualisiert wurde, sodass sie ihre Kopien entsprechend aktualisieren k\u00f6nnen.

"},{"location":"dns/glossar/zonefile/#refresh-interval","title":"Refresh Interval","text":"

Die Zeit in Sekunden, nach der sekund\u00e4re Nameserver \u00fcberpr\u00fcfen sollen, ob die Zonendatei auf dem prim\u00e4ren Nameserver aktualisiert wurde. Typischerweise ein Wert zwischen 1 Stunde (3600 Sekunden) und 1 Tag (86400 Sekunden).

"},{"location":"dns/glossar/zonefile/#retry-interval","title":"Retry Interval","text":"

Die Zeit in Sekunden, die sekund\u00e4re Nameserver warten sollen, bevor sie nach einem fehlgeschlagenen Update-Versuch erneut versuchen, die Zonendatei zu aktualisieren. Dieser Wert ist normalerweise k\u00fcrzer als das Refresh-Intervall.

"},{"location":"dns/glossar/zonefile/#expire-time","title":"Expire Time","text":"

Die maximale Zeit in Sekunden, die ein sekund\u00e4rer Nameserver die Zonendatei als g\u00fcltig betrachten soll, wenn keine Aktualisierung vom prim\u00e4ren Server erfolgt. Nach dieser Zeit wird die Zonendatei als ung\u00fcltig betrachtet, und der Server stellt die Beantwortung von Anfragen f\u00fcr diese Zone ein. Typischerweise ein Wert von mehreren Wochen.

"},{"location":"dns/glossar/zonefile/#minimum-ttl-time-to-live","title":"Minimum TTL (Time To Live)","text":"

Die Standardzeit in Sekunden, die DNS-Eintr\u00e4ge aus dieser Zone im Cache eines Clients oder eines zwischengeschalteten Nameservers verbleiben sollen. Wenn kein spezifischer TTL-Wert f\u00fcr einen Eintrag festgelegt ist, wird dieser Wert verwendet.

"},{"location":"dns/praktisch/","title":"Aufgaben","text":""},{"location":"dns/praktisch/#aufgaben","title":"Aufgaben","text":"
  • = fertig
  • = WIP

Checkliste der Auftr\u00e4ge gem\u00e4ss Olat:

  • Als Pflichtprogramm wird die Inbetriebnahme eines DNS-Resolvers und Nameservers erwartet (bind unter Linux).
    • In Wireshark zeichnen Sie die rekursive Abfrage auf und erkl\u00e4ren diese.
    • Erstellen Sie einen Secondary DNS und lassen Sie die Zonen automatisiert synchronisieren.
    • In einem fr\u00fcheren Auftrag haben Sie exotische Betriebssysteme ans Netzwerk angebunden. Binden Sie Ihren DNS-Resolver ein und zeigen Sie per Wireshark, ob diese Betriebssysteme die Abfragen korrekt durchf\u00fchren.
    • Versuchen Sie dynamisch DNS-Eintr\u00e4ge anpassen zu lassen. Spielen Sie Kapitel 3 von https://strugglers.net/~andy/blog/2018/03/19/ nach. Beachten Sie, dass sich die Welt \u00e4ndert: Nutzen Sie tsig-keygen statt dnssec-keygen.
    • Unter maas.bbw-it.ch haben Sie Zugriff auf eine \u00abpers\u00f6nliche\u00bb DNS-Subdomain. Nutzen Sie diese M\u00f6glichkeit und testen Sie, wie sie diese einsetzen k\u00f6nnen. F\u00fcr Fortgeschrittene k\u00f6nnen Sie auch die dynamische Anpassung ausprobieren.
    • \u00dcbersteuern Sie den DNS mittels Hosts-File (auch unter Windows). Wie verh\u00e4lt sich der Resolver, wenn Sie ihm per Hosts-File andere Werte unterjubeln? Werden diese da ber\u00fccksichtigt?
"},{"location":"dns/praktisch/#netzwerkschema","title":"Netzwerkschema","text":"

Ich \u00fcbernehme das Netzwerk vom letzten Auftrag zu PXE und DHCP. Einerseits weil es praktisch ist, andererseits weil es eine gute \u00dcbung f\u00fcr mich ist.

"},{"location":"dns/praktisch/bind9/","title":"Bind9","text":""},{"location":"dns/praktisch/bind9/#bind9","title":"Bind9","text":"
  • Als Pflichtprogramm wird die Inbetriebnahme eines DNS-Resolvers und Nameservers erwartet (bind unter Linux).

Bind9 ist eine Open-Source Implementation von DNS.

"},{"location":"dns/praktisch/bind9/#setup","title":"Setup","text":"

Wie folgt habe Bind9 installiert, konfiguriert und in meine Umgebung integriert.

  • LAN: 192.168.1.0/26
  • DNS server: 192.168.1.7
  • Client: 192.168.1.4
  • Domain: sephley.local
"},{"location":"dns/praktisch/bind9/#1-apt-pakete-installieren","title":"1. APT Pakete installieren","text":"
sudo apt update\nsudo apt install bind9 bind9utils bind9-doc dnsutils\n
"},{"location":"dns/praktisch/bind9/#2-konfiguration-vornehmen","title":"2. Konfiguration vornehmen","text":"

Die config-files f\u00fcr Bind9 befinden findet man unter /etc/bind. Zuerst bearbeiten wir die Datei named.conf.options. Vieles ist hier schon ausgef\u00fcllt, ich habe bloss den DNS zu dem von Cloudflare umkonfiguriert und das Netzwerk angepasst.

acl internal-network {\n192.168.1.0/26;\n};\noptions {\n        directory \"/var/cache/bind\";\n        allow-query { localhost; internal-network; };\n        allow-transfer { localhost; };\n        forwarders { 1.1.1.1; };\n        recursion yes;\n        dnssec-validation auto;\n};\n

Als n\u00e4chstes bearbeiten wir die Datei named.conf.local

zone \"sephley.local\" IN {\n        type master;\n        file \"/etc/bind/forward.sephley.local\";\n        allow-update { none; };\n};\nzone \"1.168.192.in-addr.arpa\" IN {\n        type master;\n        file \"/etc/bind/reverse.sephley.local\";\n        allow-update { none; };\n};\n

Nun schreiben wir endlich unser zone file. Dazugeh\u00f6rige Theorie: Zonendatei Um uns diese Arbeit zu erleichtern, kopieren wir den Inhalt von db.local in unsere neues zone file forward.sephley.local

cp db.local forward.sephley.local\n

Anschliessend f\u00fcgen wir folgendes in forward.sephley.local ein:

$TTL    604800\n@       IN      SOA     primary.sephley.local. root.primary.sephley.local. (\n                              2         ; Serial\n                         604800         ; Refresh\n                          86400         ; Retry\n                        2419200         ; Expire\n                         604800 )       ; Negative Cache TTL\n;\n@       IN      NS      primary.sephley.local.\nprimary IN      A       192.168.1.7\nwww     IN      A       192.168.1.4\n

Dazugeh\u00f6rige Theorie: Record-Typen Nun konfigurieren wie die Reverse Zone. Wie vorhin kopieren wir eine bestehende Datei als Vorlage:

cp db.127 reverse.sephley.local\n

Anschliessend f\u00fcgen wir folgendes in reverse.sephley.local ein:

$TTL    604800\n@       IN      SOA     sephley.local. root.sephley.local. (\n                              1         ; Serial\n                         604800         ; Refresh\n                          86400         ; Retry\n                        2419200         ; Expire\n                         604800 )       ; Negative Cache TTL\n;\n@       IN      NS      primary.sephley.local.\nprimary IN      A       192.168.1.7\n\n7       IN      PTR     primary.sephley.local.\n4       IN      PTR     www.sephley.local.\n

Als n\u00e4chstes f\u00fcgen wir folgende Zeile in /etc/default/named ein, um beim Aufstarten von Bind9 IPv4 zu erzwingen.

OPTIONS=\"-u bind -4\"\n
"},{"location":"dns/praktisch/bind9/#3-systemd","title":"3. Systemd","text":"

Nun k\u00f6nnen wir den Dienst aktivieren und starten:

sudo systemctl start named\nsudo systemctl enable named\n
"},{"location":"dns/praktisch/bind9/#4-funktionalitat-testen","title":"4. Funktionalit\u00e4t testen","text":"

Zuerst validieren wir den Syntax unser Konfig-Dateien:

sudo named-checkconf /etc/bind/named.conf.local\n

Wenn nichts ausgegeben wird, dann stimmt diese Konfig. Als n\u00e4chstes pr\u00fcfen wir die Forward & Reverse Zone:

sudo named-checkzone sephley.local /etc/bind/forward.sephley.local\nsudo named-checkzone sephley.local /etc/bind/reverse.sephley.local\n

Wenn man hier ein OK erhaltet dann stimmen die Konfigs. Nun wechseln wir auf einen Client im selben Netzwerk und setzen den DNS zu 192.168.1.7: sudo vim /etc/netplan/00-installer-config.yaml bearbeiten:

network:\n  ethernets:\n    ens33:\n      dhcp4: true\n      nameservers:\n        addresses: [192.168.1.7]\n  version: 2\n

Nun f\u00fchren wir auf einem Client im selben Netzwerk folgenden Befehl aus:

dig primary.sephley.local\n

dig syntax & usage

Output:

"},{"location":"dns/praktisch/bind9/#probleme-anmerkungen","title":"Probleme / Anmerkungen","text":"
  • Zuerst wollte ich den Bind9 mit der Anleitung von Digitalocean aufsetzen, diese war jedoch overkill f\u00fcr meine Umgebung. Aber welche Anleitung sollte ich denn nehmen?
  • Meine lokale VMware Umgebung ist sehr langsam. Vielleicht sollte ich sie migrieren. Ich glaube ich verwende ab nun Terraform & Packer, um meine VMs zu erstellen.
  • network unreachable resolving './DNSKEY/IN': 2001:dc3::35#53 Viele solche Meldungen wurden mir bei systemctl status named angezeigt. Dies ist, weil ich noch IPv6 aktiviert hatte, was ich in meiner Konfig nicht mit-einbezogen habe.
  • Gem\u00e4ss Anleitung von Linuxtechi wollte ich den DNS statisch konfigurieren, um die Funktionalit\u00e4t meines DNS zu testen. Da stand ich sollte /etc/resolv.conf bearbeiten, doch das Erste, was in dieser Datei stand, war:
# This is /run/systemd/resolve/stub-resolv.conf managed by man:systemd-resolved(8).\n# Do not edit.\n#\n# This file might be symlinked as /etc/resolv.conf. If you're looking at\n# /etc/resolv.conf and seeing this text, you have followed the symlink.\n#\n# This is a dynamic resolv.conf file for connecting local clients to the\n# internal DNS stub resolver of systemd-resolved. This file lists all\n# configured search domains.\n

Die Datei war also nur ein Symlink. Ich habe herausgefunden, dass man es theoretisch \u00fcberschreiben kann mit einem statischen File, aber dass es nicht empfohlen wird. Ich habe dann im /etc/netplan/00-installer-config.yaml den Nameserver angegeben.

"},{"location":"dns/praktisch/dnsaws/","title":"DNS-in-AWS","text":""},{"location":"dns/praktisch/dnsaws/#dns-in-aws","title":"DNS in AWS","text":"
  • Auch in der AWS oder Azure-Umgebung finden Sie DNS. Was l\u00e4sst sich damit anstellen?

AWS garantiert eine 100% uptime, was f\u00fcr ein so kritischer Dienst wie der DNS sehr von Vorteil ist. Der DNS in AWS ist unter Route 53 zu finden.

"},{"location":"dns/praktisch/dnsaws/#probleme-anmerkungen","title":"Probleme / Anmerkungen","text":"

Um dies zu testen, wollte ich das Learnerlab verwenden, doch ich verf\u00fcgte nicht \u00fcber ausreichende Berechtigungen.

"},{"location":"dns/praktisch/pers_subdomain/","title":"Pers\u00f6nliche-Subdomain","text":""},{"location":"dns/praktisch/pers_subdomain/#personliche-subdomain","title":"Pers\u00f6nliche Subdomain","text":"
  • Unter maas.bbw-it.ch haben Sie Zugriff auf eine \u00abpers\u00f6nliche\u00bb DNS-Subdomain. Nutzen Sie diese M\u00f6glichkeit und testen Sie, wie sie diese einsetzen k\u00f6nnen. F\u00fcr Fortgeschrittene k\u00f6nnen Sie auch die dynamische Anpassung ausprobieren.

Auf dem Maas der BBW hat man eine pers\u00f6nliche Subdomain mit der M\u00f6glichkeit, seine eigene Zone zu konfigurieren.

Somit k\u00f6nnen wir eine dynamische Anpassung einrichten. Zuerst kopieren wir unseren TSIG Schl\u00fcssel und f\u00fcgen es in die Datei /secrets/maas ein.

Dann setzen wir die erforderlichen Berechtigungen:

sudo chown root:root /secrets/maas\nsudo chmod 600 /secrets/maas\n

Nun k\u00f6nnen wir unseren Key hinzuf\u00fcgen:

nsupdate -k /secrets/maas \n>server ns.users.bbw-it.ch. \n>update add xyz.joseph.hurley.users.bbw-it.ch. 300 IN A 1.2.3.4 \n>send\n>quit\n

Und zum Schluss noch die \u00c4nderungen \u00fcberpr\u00fcfen:

nslookup xyz.joseph.hurley.users.bbw-it.ch\nnslookup xyz.joseph.hurley.users.bbw-it.ch ns.users.bbw-it.ch\n
"},{"location":"dns/praktisch/pers_subdomain/#probleme-anmerkungen","title":"Probleme / Anmerkungen","text":"

Ich erhalte bei dem send Befehl folgende Fehlermeldung: \"TSIG error with server: tsig indicates error update failed: NOTAUTH(BADKEY)\".

Wenn ich den key einlesen m\u00f6chte, kann er nicht gelesen werden.

Ich habe eine Stunde lang mit den Berechtigungen herumgespielt und diverse Forum posts durchgelesen, konnte aber keine L\u00f6sung finden.

"},{"location":"dns/praktisch/secdns/","title":"Secondary-DNS","text":""},{"location":"dns/praktisch/secdns/#secondary-dns","title":"Secondary DNS","text":"
  • Erstellen Sie einen Secondary DNS und lassen Sie die Zonen automatisiert synchronisieren.

Dazugeh\u00f6rige Theorie: Primary / Secondary Konzept F\u00fcr den Secondary DNS erstellen wir nochmals eine Ubuntu-Server VM. Diesmal habe ich eine Ubuntu 24.04 (Noble Numbat) VM erstellt, denn so kann ich die neue Version testen sowie auch die R\u00fcckw\u00e4rtskompatibilit\u00e4t pr\u00fcfen.

"},{"location":"dns/praktisch/secdns/#1-apt-pakete-installieren","title":"1. APT Pakete installieren","text":"
sudo apt update\nsudo apt install bind9 bind9utils bind9-doc dnsutils\n
"},{"location":"dns/praktisch/secdns/#2-konfiguration-vornehmen","title":"2. Konfiguration vornehmen","text":"

Zuerst m\u00fcssen wir noch auf unserem prim\u00e4ren DNS die folgenden parameter in /etc/bind/named.conf.local in beiden zone blocks einf\u00fcgen:

allow-transfer { 192.168.1.9 };\nalso-notify { 192.168.1.9 };\n

/etc/bind/named.conf.local wie folgt bearbeiten:

zone \"sephley.local\" {\ntype slave;\nfile \"/etc/bind/forward.sephley.local\";\nmasters { 192.168.1.7; };\n};\n

Anschliessend laden wir den Dienst neu:

sudo systemctl reload named\n
"},{"location":"dns/praktisch/secdns/#probleme-anmerkungen","title":"Probleme / Anmerkungen","text":"

Keine. Die schnellen boot-Zeiten von Ubuntu-Noble gefallen mir sehr. Good job Canonical!

"},{"location":"dns/praktisch/uebersteuern/","title":"DNS-\u00fcbersteuern","text":""},{"location":"dns/praktisch/uebersteuern/#dns-ubersteuren","title":"DNS \u00fcbersteuren","text":"
  • \u00dcbersteuern Sie den DNS mittels Hosts-File (auch unter Windows). Wie verh\u00e4lt sich der Resolver, wenn Sie ihm per Hosts-File andere Werte unterjubeln? Werden diese da ber\u00fccksichtigt?
"},{"location":"dns/praktisch/uebersteuern/#linux","title":"Linux","text":"

Pfad: /etc/hosts

Ich habe die Zeile 0.0.0.0 www.facebook.com eingef\u00fcgt, um Facebook zu blocken.

"},{"location":"dns/praktisch/uebersteuern/#windows","title":"Windows","text":"

Pfad: C:\\Windows\\system32\\drivers\\etc\\hosts

Wie vorhin, habe ich die Zeile 0.0.0.0 www.facebook.com eingef\u00fcgt, um Facebook zu blocken. Anschliessend musste ich in Microsoft Edge folgende Einstellung ausschalten:

Somit h\u00f6rt der Browser auf das lokale Hosts-File.

"},{"location":"dns/praktisch/uebersteuern/#probleme-anmerkungen","title":"Probleme / Anmerkungen","text":"

Wir stellen also Fest, dass die Werte im Hosts file priorisiert werden. Als ich aber auf Windows im hosts file www.facebook.com geblockt habe und trotzdem mit dem Browser darauf zugreifen konnte war ich sehr verwirrt. Diese Quelle hat mich darauf aufmerksam gemacht, dass die meisten Browser eine Funktion namens \"DNS over HTTPS\" verwenden. \"When DNS over HTTPS is enabled in a browser, the browser bypasses the normal DNS client in Windows 10 and 11.\"

"},{"location":"dns/praktisch/wireshark/","title":"Wireshark","text":""},{"location":"dns/praktisch/wireshark/#wireshark","title":"Wireshark","text":"
  • In Wireshark zeichnen Sie die rekursive Abfrage auf und erkl\u00e4ren diese.
  • In einem fr\u00fcheren Auftrag haben Sie exotische Betriebssysteme ans Netzwerk angebunden. Binden Sie Ihren DNS-Resolver ein und zeigen Sie per Wireshark, ob diese Betriebssysteme die Abfragen korrekt durchf\u00fchren.

Ich habe meinen ehemaligen DHCP Client verwendet, wo Wireshark schon installiert war.

"},{"location":"dns/praktisch/wireshark/#windows","title":"Windows","text":"

Ich habe einen Scan gestartet und nach dns gefiltert. W\u00e4hrend dem Scan habe ich Microsoft Edge ge\u00f6ffnet und olat.bbw.ch aufgel\u00f6st.

Datei herunterladen

  1. Start bei dem Resolver: Der Client sendet eine DNS-Abfrage an den DNS-Resolver.

  2. DNS Server erhaltet die Anfrage: Der Resolver fragt einen der Root-Nameserver an.

  3. Weiterleitung an die TLD-Nameserver: Der Root-Nameserver antwortet mit einem Verweis auf die TLD-Nameserver, die f\u00fcr die Dom\u00e4ne zust\u00e4ndig sind.

  4. Anfrage an die autoritativen Nameserver: Der TLD-Nameserver antwortet mit den autoritativen Nameservern f\u00fcr primary.sephley.local. Der Resolver schickt dann eine Anfrage an einen dieser autoritativen Nameserver.

  5. Erhalt der endg\u00fcltigen Antwort: Der autoritative Nameserver (primary.sephley.local) antwortet mit der IP-Adresse der Dom\u00e4ne. Diese Antwort wird an den Resolver zur\u00fcckgegeben.

  6. \u00dcbermittlung an den Client: Der Resolver sendet die erhaltene IP-Adresse an den urspr\u00fcnglichen Client zur\u00fcck, der die Anfrage gestellt hat.

  7. Caching der Antwort: Sowohl der Resolver als auch der Client speichern die Antwort im Cache, um bei zuk\u00fcnftigen Anfragen schneller antworten zu k\u00f6nnen.

"},{"location":"dns/praktisch/wireshark/#probleme-anmerkungen","title":"Probleme / Anmerkungen","text":"

Ich habe irgendwie den Sinn der Aufgabe nicht begriffen und habe die rekursive Anfrage an olat.bbw.ch gemacht. Aber der Sinn und Zweck dieser Aufgabe ist ja, dass ich die Anfrage an meinen eigenen DNS mache... Dazu habe ich zuerst eine bereits gecachte Abfrage auf www.google.ch gemacht, was nat\u00fcrlich nichts n\u00fctzt, wenn man den ganzen Prozess erkl\u00e4ren m\u00f6chte.

Datei herunterladen

Falls Sie sich fragen, was gstatic.com ist: Google l\u00e4dt static content (Javascripts, Bilder, CSS) von einer anderen Dom\u00e4ne. Dies hilft bei der Ladezeit, da es die Bandbreite verringert.

"},{"location":"tls/","title":"Auftrag Transport Layer Security TLS M300","text":""},{"location":"tls/#auftrag-transport-layer-security-tls-m300","title":"Auftrag Transport Layer Security TLS M300","text":"

Link zum Auftrag

"},{"location":"tls/aufgaben/","title":"Aufgaben von Olat","text":""},{"location":"tls/aufgaben/#aufgaben-von-olat","title":"Aufgaben von Olat","text":"
  • = fertig
  • = WIP

Checkliste der Aufgaben gem\u00e4ss Olat:

  • TLS Wireshark Analyse
  • TLS im Web (HTTPS)
  • Vergleichen Sie verschiedene HTTPS-Seiten (digitec, olat, Schweizer Bank Ihrer Wahl, Nischenbank z. B. garantibank.nl) auf ihren Sicherheitslevel.
"},{"location":"tls/aufgaben/nginx/","title":"Nginx","text":""},{"location":"tls/aufgaben/nginx/#nginx-mit-tls","title":"Nginx mit TLS","text":"
  • TLS im Web (HTTPS)

Sie haben in der Vor\u00fcbung zwei zertifikatsbasierte Webzug\u00e4nge eingerichtet. Verwenden Sie diese f\u00fcr den Mitschnitt des HTTPS-Zugriffs. Finden Sie die Elemente der Theorie im Mitschnitt und ordnen Sie diese zu. Hier noch ein n\u00fctzlicher Link: https://www.sslshopper.com/article-most-common-openssl-commands.html Welche Verschl\u00fcsselung haben Sie verwendet? War Ihnen das bei der Erstellung bewusst? K\u00f6nnen Sie spezielle Protokollabl\u00e4ufe simulieren? Versuchen Sie einen Alert aufzuzeichnen.

In diesem Abschnitt installiere ich Nginx und konfiguriere ein selbstsigniertes Zertifikat.

"},{"location":"tls/aufgaben/nginx/#installation","title":"Installation","text":"

Ubuntu 24.04

sudo apt install nginx\n
"},{"location":"tls/aufgaben/nginx/#konfiguration","title":"Konfiguration","text":"

https://nginx.org/en/docs/http/configuring_https_servers.html

/etc/nginx/sites-available/vogel.conf

server {\n        listen 80 default_server;\n        listen [::]:80 default_server;\n\n        # SSL configuration\n        listen 443 ssl default_server;\n        listen [::]:443 ssl default_server;\n        server_name www.sephley.home;\n        ssl_certificate www.sephley.home.crt;\n        ssl_certificate_key www.sephley.home.key;\n        ssl_protocols TLSv1.2 TLSv1.3;\n        ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;\n\n        root /var/www/html;\n\n        # Add index.php to the list if you are using PHP\n        index index.html index.htm index.nginx-debian.html;\n\n\n        location / {\n                # First attempt to serve request as file, then\n                # as directory, then fall back to displaying a 404.\n                try_files $uri $uri/ =404;\n        }\n}\n
"},{"location":"tls/aufgaben/nginx/#self-signed-cert-generieren","title":"Self-signed cert generieren","text":"
openssl genrsa -out www.sephley.com.key 2048 # private key generieren\nopenssl req -new -key www.sephley.com.key -out csr.pem # CSR generieren\nopenssl req -x509 -key www.sephley.com.key -in csr.pem -out www.sephley.home.crt -days 365 # Zertifikat ausstellen\n

Um unserer CA mit Firefox zu vertrauen, m\u00fcssen wir es in den Zertifikats-Einstellungen importieren:

"},{"location":"tls/aufgaben/nginx/#reflexion","title":"Reflexion","text":"

Da ich dies schon mehrmals machen musste, war mir der Ablauf schon bekannt.

Als ich dies originell aufgesetzt habe, habe ich die Ciphers nicht beachtet. Ich habe jedoch bei dem Vergleich mit anderen Dom\u00e4nen gemerkt, dass dies sinnvoll w\u00e4re. Deshalb habe ich ssl_ciphers TLS_AES_256_GCM_SHA384; in der config spezifiziert.

ACHTUNG! Die Cipher TLS_AES_256_GCM_SHA384 hat nicht funktioniert, weil es von nginx nicht erkannt wird. Es ist aber eine valide Cipher, dies habe ich wie folgt gepr\u00fcft:

Mit dem Befehl oben pr\u00fcfe ich die SSL Konfigurations Datei um zu sehen, ob die Cipher unterst\u00fctzt wird.

Ich versuchte auch noch, TLS 1.3 zu erzwingen, dies hat aber nichts gen\u00fctzt.

Ich habe es schlussendlich gel\u00f6st, indem ich auf die empfohlenen Ciphers von Mozilla gewechselt habe:

ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;\n
"},{"location":"tls/aufgaben/vergleich/","title":"Vergleich-nach-Sicherheitslevel","text":""},{"location":"tls/aufgaben/vergleich/#vergleich-von-verschiedenen-https-seiten","title":"Vergleich von verschiedenen HTTPS-Seiten","text":"
  • Vergleichen Sie verschiedene HTTPS-Seiten (digitec, olat, Schweizer Bank Ihrer Wahl, Nischenbank z. B. garantibank.nl) auf ihren Sicherheitslevel.
"},{"location":"tls/aufgaben/vergleich/#vergleich","title":"Vergleich","text":"

F\u00fcr jeden der folgenden Dom\u00e4nen habe ich den \"SSL Server Test\" von SSL Labs ausgef\u00fchrt. Wie funktioniert die Auswertung?

URL Unterst\u00fctzte TLS Versionen SSL Labs Auswertung https://www.digitec.ch 1.2 - 1.3 A+ https://olat.bbw.ch 1.2 - 1.3 A+ https://garantibank.nl 1.2 - 1.3 A+ -- -- -- https://sephley.github.io/docs 1.2 - 1.3 A https://www.sephley.com(ohne spezifizierte Ciphers) 1.2 - 1.3 T (A wenn es trusted w\u00e4re) https://www.sephley.com(mit spezifizierten Ciphers) 1.2 - 1.3 T (A wenn es trusted w\u00e4re)"},{"location":"tls/aufgaben/vergleich/#reflexion","title":"Reflexion","text":"

Was bei meinen Webseiten zum A anstatt A+ gef\u00fchrt hat sind warscheinlich die Ciphers. Beispielsweise ist mir aufgefallen, das mein selbst-signiertes Zertifikat https://www.sephley.com schw\u00e4chere Ciphers unterst\u00fctzt als https://olat.bbw.ch.

https://olat.bbw.ch

https://www.sephley.com

Bei der Erstellung des private keys habe ich nicht darauf geachtet, welche Ciphers ich verwende. Falsch, das spezifiziert man nicht bei der Erstellung des private keys sondern bei dem Webserver. in meinem Fall musste ich also meine Nginx config anpassen:

ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;\n

Danach sah das Resultat besser aus:

https://www.sephley.com

Allerdings war der Score von SSL Labs immer noch bei A, also war es nicht die Schuld der Ciphers.

"},{"location":"tls/aufgaben/wireshark/","title":"Wireshark","text":""},{"location":"tls/aufgaben/wireshark/#wireshark-sniffing","title":"Wireshark Sniffing","text":"
  • TLS Wireshark Analyse

TLS ist auch dazu da, den Verkehr vor neugierigen Blicken zu verheimlichen. Doch zu Debugging-Zwecke w\u00e4re es oft hilfreich, den Traffic trotzdem mittels Wireshark mith\u00f6ren zu k\u00f6nnen. Und tats\u00e4chlich l\u00e4sst sich dies bewerkstelligen, wenn man Einfluss auf eine der Seiten hat. Nat\u00fcrlich wollen Sie das durchf\u00fchren und erforschen. Sie finden alles Wichtige dazu hier: https://wiki.wireshark.org/TLS Tipp: Sie m\u00fcssen dem TLS Stream folgen. Und da lohnt es sich oft, den Hex Dump anzuzeigen. Insbesondere bei der Nutzung bin\u00e4rer Daten. Auch ein Blick ins Hex Dump Feld und dessen Reiter ist lohnend!

tls capture download

Wenn wir in dieser Datei nach ssl filtern, wird der Handshake klar ersichtlich.

1. Client Hello Mein Client initiiert den Verbindungsaufbau. Die Nachricht enth\u00e4lt Informationen wie die unterst\u00fctzten Cipher Suites und ein Secret, welcher im Schl\u00fcsselaustausch verwendet wird.

2. Server Hello Diese Nachricht enth\u00e4lt die vom Server gew\u00e4hlte Verschl\u00fcsselungsmethode und eine weiteres Secret.

3. Change Cipher Spec Der Server teilt dem Client mit, dass die zuk\u00fcnftigen Nachrichten mit den neu ausgehandelten Verschl\u00fcsselungseinstellungen verschl\u00fcsselt werden.

4. Application Data Daten werden verschl\u00fcsselt ausgetauscht.

Man sieht auch, dass die Daten verschl\u00fcsselt wurden.

https://wiki.wireshark.org/TLS

"},{"location":"tls/glossar/","title":"Glossar","text":""},{"location":"tls/glossar/#glossar","title":"Glossar","text":"
  • = fertig
  • = WIP

Checkliste der Recherche gem\u00e4ss Olat:

  • Verschaffen Sie sich einen \u00dcberblick \u00fcber die Architektur des Protokolls.
  • Wer setzt TLS ein? Sehen Sie noch speziellere Anwendungsf\u00e4lle insbesondere f\u00fcr 2-Way-Authentification.
  • W\u00e4hlen Sie eine der Angriffsm\u00f6glichkeiten aus und beschreiben Sie den Angriff und die Abwehrmechanismen von TLS detailliert.
  • Welche Verschl\u00fcsselungsverfahren k\u00f6nnen mit TLS eingesetzt werden?
  • Lange bestand das Problem, dass pro HTTPS-Subdomain eine eigene IP-Adresse n\u00f6tig war. Warum und wie l\u00f6ste man das? Wie funktioniert SNI?
  • Welche Nachteile erkennen Sie durch diese Erweiterung?
  • Der englischsprachige Wikipedia-Artikel ist noch einiges umfangreicher. Welche Informationen finden Sie da zus\u00e4tzlich?
"},{"location":"tls/glossar/angriff-abwehr/","title":"Angriff-Abwehrmechanismus","text":""},{"location":"tls/glossar/angriff-abwehr/#angriff-abwehrmoglichkeiten","title":"Angriff / Abwehrm\u00f6glichkeiten","text":"
  • W\u00e4hlen Sie eine der Angriffsm\u00f6glichkeiten aus und beschreiben Sie den Angriff und die Abwehrmechanismen von TLS detailliert.

Man-in-the-Middle ist eine bekannte Angriffsmethode, welche auf TLS betrifft.

Wenn ein Angreifer sich zwischen zwei kommunizierenden Parteien plaziert und den Datenverkehr liest oder manipuliert. Um dies zu verhindern, sollte man mit Zertifikaten arbeiten (2-way-authentification).

"},{"location":"tls/glossar/architektur/","title":"Architektur","text":""},{"location":"tls/glossar/architektur/#architektur-des-protokolls","title":"Architektur des Protokolls","text":"
  • Verschaffen Sie sich einen \u00dcberblick \u00fcber die Architektur des Protokolls.

https://www.cloudflare.com/learning/ssl/transport-layer-security-tls/

TLS (Transport Layer Security) besteht aus mehreren Schichten und Protokollen.

"},{"location":"tls/glossar/architektur/#record-protocol","title":"Record Protocol","text":"

Sorgt f\u00fcr die Vertraulichkeit und Integrit\u00e4t der \u00fcbertragenen Daten. Es zerteilt die Daten in Bl\u00f6cke, komprimiert sie optional, berechnet Authentifizierungscodes und verschl\u00fcsselt sie, bevor sie \u00fcber das Netzwerk gesendet werden.

"},{"location":"tls/glossar/architektur/#handshake-protocol-change-cipher-spec-protocol","title":"Handshake Protocol & Change Cipher Spec Protocol","text":"

Erm\u00f6glicht die Authentifizierung der Kommunikationspartner und die Aushandlung kryptographischer Parameter. Das Change Cipher Spec Protocol signalisiert den \u00dcbergang von unverschl\u00fcsselter zu verschl\u00fcsselter Kommunikation. https://www.cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake/

Bild von Cloudflare

"},{"location":"tls/glossar/architektur/#alert-protocol","title":"Alert Protocol","text":"

\u00dcbermittelt Fehlermeldungen und Warnungen. Mittels einem \"Close Notify\" Alert sieht man, dass eine Partei die Verbindung sauber schliessen m\u00f6chte.

"},{"location":"tls/glossar/nachteile/","title":"Nachteile","text":""},{"location":"tls/glossar/nachteile/#nachteile-von-tls","title":"Nachteile von TLS","text":"
  • Welche Nachteile erkennen Sie durch diese Erweiterung?

Meiner Meinung Nach ist es ein Nachteil, dass der Benutzer sich

TLS-Verschl\u00fcsselung kann die Leistung beeintr\u00e4chtigen, da die Verschl\u00fcsselung und Entschl\u00fcsselung der Daten zus\u00e4tzliche Rechenleistung erfordert.

"},{"location":"tls/glossar/sni/","title":"SNI","text":""},{"location":"tls/glossar/sni/#sni","title":"SNI","text":"
  • Lange bestand das Problem, dass pro HTTPS-Subdomain eine eigene IP-Adresse n\u00f6tig war. Warum und wie l\u00f6ste man das? Wie funktioniert SNI?
"},{"location":"tls/glossar/sni/#problem","title":"Problem","text":"

In den fr\u00fchen Versionen des SSL/TLS-Protokolls wird die Anfrage des Clients an den Server ohne Hostinformationen gesendet. Das bedeutet, dass der Server nicht weiss, f\u00fcr welche Subdomain oder welchen Hostname die Anfrage bestimmt ist, da die Hostinformationen erst in der HTTP-Anfrage enthalten sind, die nach dem SSL/TLS-Handshake kommt. Ohne diese Information konnte der Server nicht das richtige Zertifikat ausw\u00e4hlen, wenn mehrere Subdomains auf derselben IP-Adresse gehostet wurden.

"},{"location":"tls/glossar/sni/#losung","title":"L\u00f6sung","text":"

Um dieses Problem zu l\u00f6sen haben die Entwickler des \"EdelKey project\" SNI (Server Name Indication) als Erweiterung von TLS 2003 ins Leben gerufen. Ich finde die Erkl\u00e4rung von Cloudflare sehr verst\u00e4ndlich: SNI is somewhat like mailing a package to an apartment building instead of to a house. When mailing something to someone's house, the street address alone is enough to get the package to the right person. But when a package goes to an apartment building, it needs the apartment number in addition to the street address; otherwise, the package might not go to the right person or might not be delivered at all.

Technisch wird der Hostname in der ersten Nachricht des SSL/TLS-Handshakes gesendet. Dies erlabut es dem Server, das richtige Zertifikat f\u00fcr die angeforderte Subdomain auszuw\u00e4hlen.

"},{"location":"tls/glossar/use-cases/","title":"Anwendungsf\u00e4lle","text":""},{"location":"tls/glossar/use-cases/#spezielle-anwendungsfalle","title":"Spezielle Anwendungsf\u00e4lle","text":"
  • Wer setzt TLS ein? Sehen Sie noch speziellere Anwendungsf\u00e4lle insbesondere f\u00fcr 2-Way-Authentification.

TLS kann f\u00fcr sehr vieles noch eingesetzt werden, es ist schlussendlich eine Verschlusselungsm\u00f6glichkeit. Durch die Implementierung von 2-Way-Authentification mit Zertifikaten k\u00f6nnen sowohl Clients als auch Server in verschiedenen Szenarien authentifiziert werden, was die Sicherheit und Vertrauensw\u00fcrdigkeit der Kommunikation weiter erh\u00f6ht.

Unten ist noch eine Liste von anderen M\u00f6glichkeiten (von ChatGPT generiert).

  1. E-Mail-Sicherheit

    SMTP, IMAP und POP3: TLS wird verwendet, um E-Mails w\u00e4hrend des Transports zu sichern. Zwei-Wege-Authentifizierung kann durch die Verwendung von Client-Zertifikaten erreicht werden, um sowohl den E-Mail-Server als auch den E-Mail-Client zu authentifizieren.

  2. VPNs (Virtual Private Networks)

    SSL/TLS-VPNs: Viele VPN-L\u00f6sungen, wie OpenVPN, verwenden TLS, um eine sichere Verbindung zwischen dem Client und dem VPN-Server herzustellen. Zwei-Wege-Authentifizierung kann durch die Verwendung von Zertifikaten sowohl auf dem Client als auch auf dem Server implementiert werden.

  3. Datei\u00fcbertragungsprotokolle

    FTPS: File Transfer Protocol Secure verwendet TLS, um Datei\u00fcbertragungen zu sichern. Client- und Server-Zertifikate k\u00f6nnen verwendet werden, um beide Seiten zu authentifizieren. SFTP (SSH File Transfer Protocol): Obwohl SFTP oft \u00fcber SSH verwendet wird, kann es auch \u00fcber TLS implementiert werden.

  4. Datenbankverbindungen

    Datenbank-Verbindungen: TLS kann verwendet werden, um die Verbindung zwischen einem Client und einer Datenbank zu sichern. Datenbanken wie MySQL, PostgreSQL und SQL Server unterst\u00fctzen TLS-Verbindungen mit Zwei-Wege-Authentifizierung durch die Verwendung von Client- und Server-Zertifikaten.

  5. Messaging-Dienste

    XMPP (Extensible Messaging and Presence Protocol): TLS wird verwendet, um sichere Nachrichten\u00fcbermittlung in XMPP-basierten Diensten wie Jabber zu gew\u00e4hrleisten. Zwei-Wege-Authentifizierung kann durch die Verwendung von Zertifikaten implementiert werden. MQTT (Message Queuing Telemetry Transport): MQTT, ein Protokoll f\u00fcr das Internet der Dinge (IoT), kann TLS verwenden, um die Kommunikation zwischen Ger\u00e4ten zu sichern. Zwei-Wege-Authentifizierung wird durch die Verwendung von Zertifikaten erreicht.

  6. Cloud-Dienste und APIs

    RESTful APIs: TLS wird h\u00e4ufig verwendet, um die Kommunikation zwischen Clients und RESTful APIs zu sichern. Zwei-Wege-Authentifizierung kann durch die Verwendung von Client-Zertifikaten implementiert werden. Cloud-Speicherdienste: Dienste wie AWS, Google Cloud und Microsoft Azure verwenden TLS, um die Daten\u00fcbertragung zu sichern. Zwei-Wege-Authentifizierung wird oft durch die Verwendung von Zertifikaten und API-Schl\u00fcsseln erreicht.

  7. IoT (Internet of Things)

    Ger\u00e4tekommunikation: TLS wird verwendet, um die Kommunikation zwischen IoT-Ger\u00e4ten und zentralen Servern zu sichern. Zwei-Wege-Authentifizierung kann durch die Implementierung von Zertifikaten auf beiden Seiten erreicht werden.

"},{"location":"tls/glossar/verschluesslungsverfahren/","title":"Verschl\u00fcsslungsverfahren","text":""},{"location":"tls/glossar/verschluesslungsverfahren/#verschlusslungsverfahren","title":"Verschl\u00fcsslungsverfahren","text":"
  • Welche Verschl\u00fcsselungsverfahren k\u00f6nnen mit TLS eingesetzt werden?

Es gibt eine Menge Verschl\u00fcsselungsverfahren welche mit TLS eingesetzt werden k\u00f6nnen, da es viele Prozesse gibt. Dempentsprechend hat man viele M\u00f6glichkeiten. Wenn man diese sich f\u00fcr jeden Bereich ein Verschl\u00fcsslungsverfahren aussucht, hat man eine \"Cipher Suite\".

Bild von Microsoft

Hier sind einige Beispiele f\u00fcr TLS Cipher Suites, die diese Algorithmen kombinieren:

Cipher Suite Beschreibung TLS_AES_128_GCM_SHA256 Verwendet AES-128 im GCM-Modus f\u00fcr die Verschl\u00fcsselung und SHA-256 f\u00fcr die HMAC. TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 Verwendet ECDHE f\u00fcr den Schl\u00fcsselaustausch, RSA f\u00fcr die Authentifizierung, AES-128 im GCM-Modus f\u00fcr die Verschl\u00fcsselung und SHA-256 f\u00fcr die HMAC. TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 Verwendet ECDHE f\u00fcr den Schl\u00fcsselaustausch, ECDSA f\u00fcr die Authentifizierung, AES-256 im GCM-Modus f\u00fcr die Verschl\u00fcsselung und SHA-384 f\u00fcr die HMAC. TLS_CHACHA20_POLY1305_SHA256 Verwendet ChaCha20 f\u00fcr die Verschl\u00fcsselung und Poly1305 f\u00fcr die Authentifizierung, zusammen mit SHA-256.

Hier ist eine Liste von allen Cipher Suites, welche Mozilla Firefox unterst\u00fctzt: https://wiki.mozilla.org/Security/Cipher_Suites

"},{"location":"tls/glossar/wikipedia/","title":"Wikipedia-Artikel","text":""},{"location":"tls/glossar/wikipedia/#wikipedia-artikel","title":"Wikipedia-Artikel","text":"
  • Der englischsprachige Wikipedia-Artikel ist noch einiges umfangreicher. Welche Informationen finden Sie da zus\u00e4tzlich?

https://en.wikipedia.org/wiki/Transport_Layer_Security

"},{"location":"tls/homelab/","title":"Homelab","text":""},{"location":"tls/homelab/#homelab","title":"Homelab","text":"

Ich habe damit begonnen, Traefik privat einzusetzen und dachte es passt gleich zum Thema, vielleicht finden Sie es auch interessant.

"},{"location":"tls/homelab/traefik/","title":"Traefik","text":""},{"location":"tls/homelab/traefik/#traefik","title":"Traefik","text":"

How our Traefik Proxy is set up.

Like pretty much everything in ClusterStack at this point, Traefik runs in a Docker container. The Dashboard is only reachable from our internal network (so via VPN or GUI VM).

"},{"location":"tls/homelab/traefik/#dependencies","title":"Dependencies","text":"

APT-Packages required on the OS (Ubuntu 24.04) {.is-info}

Name Version docker-ce - docker-ce-cli - containerd.io - docker-buildx-plugin - docker-compose-plugin -

Follow the official installation guide of docker

I also recommend running docker in a rootless environment

"},{"location":"tls/homelab/traefik/#build","title":"Build","text":"

This is just a basic example! The active docker-compose.yml file can be found here! {.is-warning}

/home/stack/traefik/docker-compose.yml

version: '3'\n\nservices:\n  reverse-proxy:\n    # The official v3 Traefik docker image\n    image: traefik:v3.0\n    # Enables the web UI and tells Traefik to listen to docker\n    command: --api.insecure=true --providers.docker\n    ports:\n      # The HTTP port\n      - \"80:80\"\n      # The Web UI (enabled by --api.insecure=true)\n      - \"8080:8080\"\n    volumes:\n      # So that Traefik can listen to the Docker events\n      - /var/run/docker.sock:/var/run/docker.sock\n    whoami:\n    # A container that exposes an API to show its IP address\n    image: traefik/whoami\n    labels:\n      - \"traefik.http.routers.whoami.rule=Host(`whoami.docker.localhost`)\"\n
"},{"location":"tls/homelab/traefik/#config","title":"Config","text":"

/home/stack/traefik/traefik.yml

providers:\n  docker:\n    tls:\n      cert: ./certs/cert.pem\n      key: ./certs/key.pem\n

https://doc.traefik.io/traefik/routing/routers/#tls https://doc.traefik.io/traefik/providers/docker/#tls

"},{"location":"tls/homelab/traefik/#tls-in-traefik","title":"TLS in Traefik","text":"

https://doc.traefik.io/traefik/https/tls/

"}]} \ No newline at end of file diff --git a/sitemap.xml b/sitemap.xml new file mode 100644 index 00000000..96155c27 --- /dev/null +++ b/sitemap.xml @@ -0,0 +1,248 @@ + + + + https://docs.sephley.com/ + 2024-06-24 + daily + + + https://docs.sephley.com/bbw-m141/ + 2024-06-24 + daily + + + https://docs.sephley.com/bbw-m169/ + 2024-06-24 + daily + + + https://docs.sephley.com/bbw-m300/ + 2024-06-24 + daily + + + https://docs.sephley.com/dhcp/ + 2024-06-24 + daily + + + https://docs.sephley.com/experts/ + 2024-06-24 + daily + + + https://docs.sephley.com/nextcloud-auftrag/ + 2024-06-24 + daily + + + https://docs.sephley.com/pruefung-security/ + 2024-06-24 + daily + + + https://docs.sephley.com/pxe-mitschnitt/ + 2024-06-24 + daily + + + https://docs.sephley.com/zli-m109/ + 2024-06-24 + daily + + + https://docs.sephley.com/zusatz-pruefung/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/aufgaben/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/aufgaben/bind-letsencrypt/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/aufgaben/certbot/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/glossar/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/glossar/acme/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/glossar/lets-encrypt/ + 2024-06-24 + daily + + + https://docs.sephley.com/acme/glossar/wildcard/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/glossar/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/glossar/beginning/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/glossar/dnsipv6/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/glossar/dyndns/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/glossar/primsec/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/glossar/rectypes/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/glossar/zonefile/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/praktisch/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/praktisch/bind9/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/praktisch/dnsaws/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/praktisch/pers_subdomain/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/praktisch/secdns/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/praktisch/uebersteuern/ + 2024-06-24 + daily + + + https://docs.sephley.com/dns/praktisch/wireshark/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/aufgaben/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/aufgaben/nginx/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/aufgaben/vergleich/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/aufgaben/wireshark/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/angriff-abwehr/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/architektur/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/nachteile/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/sni/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/use-cases/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/verschluesslungsverfahren/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/glossar/wikipedia/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/homelab/ + 2024-06-24 + daily + + + https://docs.sephley.com/tls/homelab/traefik/ + 2024-06-24 + daily + + \ No newline at end of file diff --git a/sitemap.xml.gz b/sitemap.xml.gz new file mode 100644 index 00000000..bbc53891 Binary files /dev/null and b/sitemap.xml.gz differ diff --git a/tls/aufgaben/index.html b/tls/aufgaben/index.html new file mode 100644 index 00000000..417abcac --- /dev/null +++ b/tls/aufgaben/index.html @@ -0,0 +1,2297 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Aufgaben von Olat - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Aufgaben von Olat

+
    +
  • = fertig
  • +
  • = WIP
  • +
+

Checkliste der Aufgaben gemäss Olat:

+
    +
  • TLS Wireshark Analyse
  • +
  • TLS im Web (HTTPS)
  • +
  • Vergleichen Sie verschiedene HTTPS-Seiten (digitec, olat, Schweizer Bank Ihrer Wahl, Nischenbank z. B. garantibank.nl) auf ihren Sicherheitslevel.
  • +
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/aufgaben/nginx/index.html b/tls/aufgaben/nginx/index.html new file mode 100644 index 00000000..5d4c11c7 --- /dev/null +++ b/tls/aufgaben/nginx/index.html @@ -0,0 +1,2466 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Nginx - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Nginx mit TLS

+
    +
  • TLS im Web (HTTPS)
  • +
+

Sie haben in der Vorübung zwei zertifikatsbasierte Webzugänge eingerichtet. Verwenden Sie diese für den Mitschnitt des HTTPS-Zugriffs. Finden Sie die Elemente der Theorie im Mitschnitt und ordnen Sie diese zu. Hier noch ein nützlicher Link: https://www.sslshopper.com/article-most-common-openssl-commands.html Welche Verschlüsselung haben Sie verwendet? War Ihnen das bei der Erstellung bewusst? Können Sie spezielle Protokollabläufe simulieren? Versuchen Sie einen Alert aufzuzeichnen.

+

In diesem Abschnitt installiere ich Nginx und konfiguriere ein selbstsigniertes Zertifikat.

+

Installation

+
+

Ubuntu 24.04

+
+
sudo apt install nginx
+
+

Konfiguration

+

https://nginx.org/en/docs/http/configuring_https_servers.html

+

/etc/nginx/sites-available/vogel.conf

+
server {
+        listen 80 default_server;
+        listen [::]:80 default_server;
+
+        # SSL configuration
+        listen 443 ssl default_server;
+        listen [::]:443 ssl default_server;
+        server_name www.sephley.home;
+        ssl_certificate www.sephley.home.crt;
+        ssl_certificate_key www.sephley.home.key;
+        ssl_protocols TLSv1.2 TLSv1.3;
+        ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;
+
+        root /var/www/html;
+
+        # Add index.php to the list if you are using PHP
+        index index.html index.htm index.nginx-debian.html;
+
+
+        location / {
+                # First attempt to serve request as file, then
+                # as directory, then fall back to displaying a 404.
+                try_files $uri $uri/ =404;
+        }
+}
+
+

Self-signed cert generieren

+
openssl genrsa -out www.sephley.com.key 2048 # private key generieren
+openssl req -new -key www.sephley.com.key -out csr.pem # CSR generieren
+openssl req -x509 -key www.sephley.com.key -in csr.pem -out www.sephley.home.crt -days 365 # Zertifikat ausstellen
+
+

self-signed-cert

+

Um unserer CA mit Firefox zu vertrauen, müssen wir es in den Zertifikats-Einstellungen importieren:

+

firefox

+

Reflexion

+

Da ich dies schon mehrmals machen musste, war mir der Ablauf schon bekannt.

+

Als ich dies originell aufgesetzt habe, habe ich die Ciphers nicht beachtet. Ich habe jedoch bei dem Vergleich mit anderen Domänen gemerkt, dass dies sinnvoll wäre.
+Deshalb habe ich ssl_ciphers TLS_AES_256_GCM_SHA384; in der config spezifiziert.

+

ACHTUNG! Die Cipher TLS_AES_256_GCM_SHA384 hat nicht funktioniert, weil es von nginx nicht erkannt wird. Es ist aber eine valide Cipher, dies habe ich wie folgt geprüft:

+

suite

+

Mit dem Befehl oben prüfe ich die SSL Konfigurations Datei um zu sehen, ob die Cipher unterstützt wird.

+

Ich versuchte auch noch, TLS 1.3 zu erzwingen, dies hat aber nichts genützt.

+

Ich habe es schlussendlich gelöst, indem ich auf die empfohlenen Ciphers von Mozilla gewechselt habe:

+
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;
+
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/aufgaben/vergleich/index.html b/tls/aufgaben/vergleich/index.html new file mode 100644 index 00000000..29002d77 --- /dev/null +++ b/tls/aufgaben/vergleich/index.html @@ -0,0 +1,2444 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Vergleich-nach-Sicherheitslevel - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Vergleich von verschiedenen HTTPS-Seiten

+
    +
  • Vergleichen Sie verschiedene HTTPS-Seiten (digitec, olat, Schweizer Bank Ihrer Wahl, Nischenbank z. B. garantibank.nl) auf ihren Sicherheitslevel.
  • +
+

Vergleich

+

Für jeden der folgenden Domänen habe ich den "SSL Server Test" von SSL Labs ausgeführt.
+Wie funktioniert die Auswertung?

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
URLUnterstützte TLS VersionenSSL Labs Auswertung
https://www.digitec.ch1.2 - 1.3A+
https://olat.bbw.ch1.2 - 1.3A+
https://garantibank.nl1.2 - 1.3A+
------
https://sephley.github.io/docs1.2 - 1.3A
https://www.sephley.com(ohne spezifizierte Ciphers)1.2 - 1.3T (A wenn es trusted wäre)
https://www.sephley.com(mit spezifizierten Ciphers)1.2 - 1.3T (A wenn es trusted wäre)
+

Reflexion

+

Was bei meinen Webseiten zum A anstatt A+ geführt hat sind warscheinlich die Ciphers.
+Beispielsweise ist mir aufgefallen, das mein selbst-signiertes Zertifikat https://www.sephley.com schwächere Ciphers unterstützt als https://olat.bbw.ch.

+
+

https://olat.bbw.ch

+
+

olat-bbw-ciphers

+
+

https://www.sephley.com

+
+

www-sephley-ciphers

+

Bei der Erstellung des private keys habe ich nicht darauf geachtet, welche Ciphers ich verwende.
+Falsch, das spezifiziert man nicht bei der Erstellung des private keys sondern bei dem Webserver. in meinem Fall musste ich also meine Nginx config anpassen:

+
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;
+
+

Danach sah das Resultat besser aus:

+
+

https://www.sephley.com

+
+

www-sephley-ciphers-2

+

Allerdings war der Score von SSL Labs immer noch bei A, also war es nicht die Schuld der Ciphers.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/aufgaben/wireshark/index.html b/tls/aufgaben/wireshark/index.html new file mode 100644 index 00000000..79e54804 --- /dev/null +++ b/tls/aufgaben/wireshark/index.html @@ -0,0 +1,2315 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Wireshark - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Wireshark Sniffing

+
    +
  • TLS Wireshark Analyse
  • +
+

TLS ist auch dazu da, den Verkehr vor neugierigen Blicken zu verheimlichen. Doch zu Debugging-Zwecke wäre es oft hilfreich, den Traffic trotzdem mittels Wireshark mithören zu können. Und tatsächlich lässt sich dies bewerkstelligen, wenn man Einfluss auf eine der Seiten hat. Natürlich wollen Sie das durchführen und erforschen. Sie finden alles Wichtige dazu hier: https://wiki.wireshark.org/TLS Tipp: Sie müssen dem TLS Stream folgen. Und da lohnt es sich oft, den Hex Dump anzuzeigen. Insbesondere bei der Nutzung binärer Daten. Auch ein Blick ins Hex Dump Feld und dessen Reiter ist lohnend!

+

tls capture download

+

Wenn wir in dieser Datei nach ssl filtern, wird der Handshake klar ersichtlich.

+

wireshark-1

+

1. Client Hello
+Mein Client initiiert den Verbindungsaufbau. Die Nachricht enthält Informationen wie die unterstützten Cipher Suites und ein Secret, welcher im Schlüsselaustausch verwendet wird.

+

2. Server Hello
+Diese Nachricht enthält die vom Server gewählte Verschlüsselungsmethode und eine weiteres Secret.

+

3. Change Cipher Spec
+Der Server teilt dem Client mit, dass die zukünftigen Nachrichten mit den neu ausgehandelten Verschlüsselungseinstellungen verschlüsselt werden.

+

4. Application Data
+Daten werden verschlüsselt ausgetauscht.

+

Man sieht auch, dass die Daten verschlüsselt wurden.

+

encrypted_wireshark

+

https://wiki.wireshark.org/TLS

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/angriff-abwehr/index.html b/tls/glossar/angriff-abwehr/index.html new file mode 100644 index 00000000..8dda1710 --- /dev/null +++ b/tls/glossar/angriff-abwehr/index.html @@ -0,0 +1,2303 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Angriff-Abwehrmechanismus - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Angriff / Abwehrmöglichkeiten

+
    +
  • Wählen Sie eine der Angriffsmöglichkeiten aus und beschreiben Sie den Angriff und die Abwehrmechanismen von TLS detailliert.
  • +
+

Man-in-the-Middle ist eine bekannte Angriffsmethode, welche auf TLS betrifft.

+

Wenn ein Angreifer sich zwischen zwei kommunizierenden Parteien plaziert und den Datenverkehr liest oder manipuliert. +Um dies zu verhindern, sollte man mit Zertifikaten arbeiten (2-way-authentification).

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/architektur/index.html b/tls/glossar/architektur/index.html new file mode 100644 index 00000000..2353ad46 --- /dev/null +++ b/tls/glossar/architektur/index.html @@ -0,0 +1,2403 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Architektur - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Architektur des Protokolls

+
    +
  • Verschaffen Sie sich einen Überblick über die Architektur des Protokolls.
  • +
+

https://www.cloudflare.com/learning/ssl/transport-layer-security-tls/

+

TLS (Transport Layer Security) besteht aus mehreren Schichten und Protokollen.

+

Record Protocol

+

Sorgt für die Vertraulichkeit und Integrität der übertragenen Daten. Es zerteilt die Daten in Blöcke, komprimiert sie optional, berechnet Authentifizierungscodes und verschlüsselt sie, bevor sie über das Netzwerk gesendet werden.

+

Handshake Protocol & Change Cipher Spec Protocol

+

Ermöglicht die Authentifizierung der Kommunikationspartner und die Aushandlung kryptographischer Parameter. Das Change Cipher Spec Protocol signalisiert den Übergang von unverschlüsselter zu verschlüsselter Kommunikation.
+https://www.cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake/

+

handshake
+Bild von Cloudflare

+

Alert Protocol

+

Übermittelt Fehlermeldungen und Warnungen. Mittels einem "Close Notify" Alert sieht man, dass eine Partei die Verbindung sauber schliessen möchte.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/index.html b/tls/glossar/index.html new file mode 100644 index 00000000..2b032613 --- /dev/null +++ b/tls/glossar/index.html @@ -0,0 +1,2301 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Glossar - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Glossar

+
    +
  • = fertig
  • +
  • = WIP
  • +
+

Checkliste der Recherche gemäss Olat:

+
    +
  • Verschaffen Sie sich einen Überblick über die Architektur des Protokolls.
  • +
  • Wer setzt TLS ein? Sehen Sie noch speziellere Anwendungsfälle insbesondere für 2-Way-Authentification.
  • +
  • Wählen Sie eine der Angriffsmöglichkeiten aus und beschreiben Sie den Angriff und die Abwehrmechanismen von TLS detailliert.
  • +
  • Welche Verschlüsselungsverfahren können mit TLS eingesetzt werden?
  • +
  • Lange bestand das Problem, dass pro HTTPS-Subdomain eine eigene IP-Adresse nötig war. Warum und wie löste man das? Wie funktioniert SNI?
  • +
  • Welche Nachteile erkennen Sie durch diese Erweiterung?
  • +
  • Der englischsprachige Wikipedia-Artikel ist noch einiges umfangreicher. Welche Informationen finden Sie da zusätzlich?
  • +
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/nachteile/index.html b/tls/glossar/nachteile/index.html new file mode 100644 index 00000000..55c67262 --- /dev/null +++ b/tls/glossar/nachteile/index.html @@ -0,0 +1,2302 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Nachteile - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Nachteile von TLS

+
    +
  • Welche Nachteile erkennen Sie durch diese Erweiterung?
  • +
+

Meiner Meinung Nach ist es ein Nachteil, dass der Benutzer sich

+

TLS-Verschlüsselung kann die Leistung beeinträchtigen, da die Verschlüsselung und Entschlüsselung der Daten zusätzliche Rechenleistung erfordert.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/sni/index.html b/tls/glossar/sni/index.html new file mode 100644 index 00000000..b948765b --- /dev/null +++ b/tls/glossar/sni/index.html @@ -0,0 +1,2382 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + SNI - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

SNI

+
    +
  • Lange bestand das Problem, dass pro HTTPS-Subdomain eine eigene IP-Adresse nötig war. Warum und wie löste man das? Wie funktioniert SNI?
  • +
+

Problem

+

In den frühen Versionen des SSL/TLS-Protokolls wird die Anfrage des Clients an den Server ohne Hostinformationen gesendet. +Das bedeutet, dass der Server nicht weiss, für welche Subdomain oder welchen Hostname die Anfrage bestimmt ist, da die Hostinformationen erst in der HTTP-Anfrage enthalten sind, die nach dem SSL/TLS-Handshake kommt. +Ohne diese Information konnte der Server nicht das richtige Zertifikat auswählen, wenn mehrere Subdomains auf derselben IP-Adresse gehostet wurden.

+

Lösung

+

Um dieses Problem zu lösen haben die Entwickler des "EdelKey project" SNI (Server Name Indication) als Erweiterung von TLS 2003 ins Leben gerufen.
+Ich finde die Erklärung von Cloudflare sehr verständlich: SNI is somewhat like mailing a package to an apartment building instead of to a house. When mailing something to someone's house, the street address alone is enough to get the package to the right person. But when a package goes to an apartment building, it needs the apartment number in addition to the street address; otherwise, the package might not go to the right person or might not be delivered at all.

+

Technisch wird der Hostname in der ersten Nachricht des SSL/TLS-Handshakes gesendet. Dies erlabut es dem Server, das richtige Zertifikat für die angeforderte Subdomain auszuwählen.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/use-cases/index.html b/tls/glossar/use-cases/index.html new file mode 100644 index 00000000..9e699cc8 --- /dev/null +++ b/tls/glossar/use-cases/index.html @@ -0,0 +1,2335 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Anwendungsfälle - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Spezielle Anwendungsfälle

+
    +
  • Wer setzt TLS ein? Sehen Sie noch speziellere Anwendungsfälle insbesondere für 2-Way-Authentification.
  • +
+

TLS kann für sehr vieles noch eingesetzt werden, es ist schlussendlich eine Verschlusselungsmöglichkeit. Durch die Implementierung von 2-Way-Authentification mit Zertifikaten können sowohl Clients als auch Server in verschiedenen Szenarien authentifiziert werden, was die Sicherheit und Vertrauenswürdigkeit der Kommunikation weiter erhöht.

+

Unten ist noch eine Liste von anderen Möglichkeiten (von ChatGPT generiert).

+
    +
  1. +

    E-Mail-Sicherheit

    +

    SMTP, IMAP und POP3: TLS wird verwendet, um E-Mails während des Transports zu sichern. Zwei-Wege-Authentifizierung kann durch die Verwendung von Client-Zertifikaten erreicht werden, um sowohl den E-Mail-Server als auch den E-Mail-Client zu authentifizieren.

    +
  2. +
  3. +

    VPNs (Virtual Private Networks)

    +

    SSL/TLS-VPNs: Viele VPN-Lösungen, wie OpenVPN, verwenden TLS, um eine sichere Verbindung zwischen dem Client und dem VPN-Server herzustellen. Zwei-Wege-Authentifizierung kann durch die Verwendung von Zertifikaten sowohl auf dem Client als auch auf dem Server implementiert werden.

    +
  4. +
  5. +

    Dateiübertragungsprotokolle

    +

    FTPS: File Transfer Protocol Secure verwendet TLS, um Dateiübertragungen zu sichern. Client- und Server-Zertifikate können verwendet werden, um beide Seiten zu authentifizieren. +SFTP (SSH File Transfer Protocol): Obwohl SFTP oft über SSH verwendet wird, kann es auch über TLS implementiert werden.

    +
  6. +
  7. +

    Datenbankverbindungen

    +

    Datenbank-Verbindungen: TLS kann verwendet werden, um die Verbindung zwischen einem Client und einer Datenbank zu sichern. Datenbanken wie MySQL, PostgreSQL und SQL Server unterstützen TLS-Verbindungen mit Zwei-Wege-Authentifizierung durch die Verwendung von Client- und Server-Zertifikaten.

    +
  8. +
  9. +

    Messaging-Dienste

    +

    XMPP (Extensible Messaging and Presence Protocol): TLS wird verwendet, um sichere Nachrichtenübermittlung in XMPP-basierten Diensten wie Jabber zu gewährleisten. Zwei-Wege-Authentifizierung kann durch die Verwendung von Zertifikaten implementiert werden. +MQTT (Message Queuing Telemetry Transport): MQTT, ein Protokoll für das Internet der Dinge (IoT), kann TLS verwenden, um die Kommunikation zwischen Geräten zu sichern. Zwei-Wege-Authentifizierung wird durch die Verwendung von Zertifikaten erreicht.

    +
  10. +
  11. +

    Cloud-Dienste und APIs

    +

    RESTful APIs: TLS wird häufig verwendet, um die Kommunikation zwischen Clients und RESTful APIs zu sichern. Zwei-Wege-Authentifizierung kann durch die Verwendung von Client-Zertifikaten implementiert werden. +Cloud-Speicherdienste: Dienste wie AWS, Google Cloud und Microsoft Azure verwenden TLS, um die Datenübertragung zu sichern. Zwei-Wege-Authentifizierung wird oft durch die Verwendung von Zertifikaten und API-Schlüsseln erreicht.

    +
  12. +
  13. +

    IoT (Internet of Things)

    +

    Gerätekommunikation: TLS wird verwendet, um die Kommunikation zwischen IoT-Geräten und zentralen Servern zu sichern. Zwei-Wege-Authentifizierung kann durch die Implementierung von Zertifikaten auf beiden Seiten erreicht werden.

    +
  14. +
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/verschluesslungsverfahren/index.html b/tls/glossar/verschluesslungsverfahren/index.html new file mode 100644 index 00000000..afcf801a --- /dev/null +++ b/tls/glossar/verschluesslungsverfahren/index.html @@ -0,0 +1,2333 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Verschlüsslungsverfahren - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Verschlüsslungsverfahren

+
    +
  • Welche Verschlüsselungsverfahren können mit TLS eingesetzt werden?
  • +
+

Es gibt eine Menge Verschlüsselungsverfahren welche mit TLS eingesetzt werden können, da es viele Prozesse gibt. Dempentsprechend hat man viele Möglichkeiten.
+Wenn man diese sich für jeden Bereich ein Verschlüsslungsverfahren aussucht, hat man eine "Cipher Suite".

+

tls-cipher-microsoft
+Bild von Microsoft

+

Hier sind einige Beispiele für TLS Cipher Suites, die diese Algorithmen kombinieren:

+ + + + + + + + + + + + + + + + + + + + + + + + + +
Cipher SuiteBeschreibung
TLS_AES_128_GCM_SHA256Verwendet AES-128 im GCM-Modus für die Verschlüsselung und SHA-256 für die HMAC.
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256Verwendet ECDHE für den Schlüsselaustausch, RSA für die Authentifizierung, AES-128 im GCM-Modus für die Verschlüsselung und SHA-256 für die HMAC.
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384Verwendet ECDHE für den Schlüsselaustausch, ECDSA für die Authentifizierung, AES-256 im GCM-Modus für die Verschlüsselung und SHA-384 für die HMAC.
TLS_CHACHA20_POLY1305_SHA256Verwendet ChaCha20 für die Verschlüsselung und Poly1305 für die Authentifizierung, zusammen mit SHA-256.
+

Hier ist eine Liste von allen Cipher Suites, welche Mozilla Firefox unterstützt:
+https://wiki.mozilla.org/Security/Cipher_Suites

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/glossar/wikipedia/index.html b/tls/glossar/wikipedia/index.html new file mode 100644 index 00000000..b3d72384 --- /dev/null +++ b/tls/glossar/wikipedia/index.html @@ -0,0 +1,2301 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Wikipedia-Artikel - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+ +
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/homelab/index.html b/tls/homelab/index.html new file mode 100644 index 00000000..fbd6a63e --- /dev/null +++ b/tls/homelab/index.html @@ -0,0 +1,2288 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Homelab - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Homelab

+

Ich habe damit begonnen, Traefik privat einzusetzen und dachte es passt gleich zum Thema, vielleicht finden Sie es auch interessant.

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/homelab/traefik/index.html b/tls/homelab/traefik/index.html new file mode 100644 index 00000000..8f42ac9f --- /dev/null +++ b/tls/homelab/traefik/index.html @@ -0,0 +1,2487 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Traefik - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Traefik

+

How our Traefik Proxy is set up.

+

Like pretty much everything in ClusterStack at this point, Traefik runs in a Docker container. +The Dashboard is only reachable from our internal network (so via VPN or GUI VM).

+

Dependencies

+
+

APT-Packages required on the OS (Ubuntu 24.04) +{.is-info}

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameVersion
docker-ce-
docker-ce-cli-
containerd.io-
docker-buildx-plugin-
docker-compose-plugin-
+

Follow the official installation guide of docker

+

I also recommend running docker in a rootless environment

+

Build

+
+

This is just a basic example! The active docker-compose.yml file can be found here! +{.is-warning}

+
+

/home/stack/traefik/docker-compose.yml

+
version: '3'
+
+services:
+  reverse-proxy:
+    # The official v3 Traefik docker image
+    image: traefik:v3.0
+    # Enables the web UI and tells Traefik to listen to docker
+    command: --api.insecure=true --providers.docker
+    ports:
+      # The HTTP port
+      - "80:80"
+      # The Web UI (enabled by --api.insecure=true)
+      - "8080:8080"
+    volumes:
+      # So that Traefik can listen to the Docker events
+      - /var/run/docker.sock:/var/run/docker.sock
+    whoami:
+    # A container that exposes an API to show its IP address
+    image: traefik/whoami
+    labels:
+      - "traefik.http.routers.whoami.rule=Host(`whoami.docker.localhost`)"
+
+

Config

+

/home/stack/traefik/traefik.yml

+
providers:
+  docker:
+    tls:
+      cert: ./certs/cert.pem
+      key: ./certs/key.pem
+
+

https://doc.traefik.io/traefik/routing/routers/#tls
+https://doc.traefik.io/traefik/providers/docker/#tls

+

TLS in Traefik

+

https://doc.traefik.io/traefik/https/tls/

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/images/auftrag_tls.png b/tls/images/auftrag_tls.png new file mode 100644 index 00000000..14417c3c Binary files /dev/null and b/tls/images/auftrag_tls.png differ diff --git a/tls/images/auftrag_tls2.png b/tls/images/auftrag_tls2.png new file mode 100644 index 00000000..5f73a9de Binary files /dev/null and b/tls/images/auftrag_tls2.png differ diff --git a/tls/images/encrypted_wireshark.png b/tls/images/encrypted_wireshark.png new file mode 100644 index 00000000..c363c877 Binary files /dev/null and b/tls/images/encrypted_wireshark.png differ diff --git a/tls/images/firefox.png b/tls/images/firefox.png new file mode 100644 index 00000000..6ae4b837 Binary files /dev/null and b/tls/images/firefox.png differ diff --git a/tls/images/self-sigend-cert.png b/tls/images/self-sigend-cert.png new file mode 100644 index 00000000..fcf2336f Binary files /dev/null and b/tls/images/self-sigend-cert.png differ diff --git a/tls/images/ssllabs-olat-bbw.png b/tls/images/ssllabs-olat-bbw.png new file mode 100644 index 00000000..d73ee910 Binary files /dev/null and b/tls/images/ssllabs-olat-bbw.png differ diff --git a/tls/images/ssllabs-www-sephley-2.png b/tls/images/ssllabs-www-sephley-2.png new file mode 100644 index 00000000..515d6ab5 Binary files /dev/null and b/tls/images/ssllabs-www-sephley-2.png differ diff --git a/tls/images/ssllabs-www-sephley.png b/tls/images/ssllabs-www-sephley.png new file mode 100644 index 00000000..e323b2d1 Binary files /dev/null and b/tls/images/ssllabs-www-sephley.png differ diff --git a/tls/images/suite.png b/tls/images/suite.png new file mode 100644 index 00000000..5da56cb0 Binary files /dev/null and b/tls/images/suite.png differ diff --git a/tls/images/tls-ciphers-microsoft.png b/tls/images/tls-ciphers-microsoft.png new file mode 100644 index 00000000..7182b302 Binary files /dev/null and b/tls/images/tls-ciphers-microsoft.png differ diff --git a/tls/images/tls-ssl-handshake.png b/tls/images/tls-ssl-handshake.png new file mode 100644 index 00000000..42fc3017 Binary files /dev/null and b/tls/images/tls-ssl-handshake.png differ diff --git a/tls/images/wireshark-1.png b/tls/images/wireshark-1.png new file mode 100644 index 00000000..85abb74a Binary files /dev/null and b/tls/images/wireshark-1.png differ diff --git a/tls/index.html b/tls/index.html new file mode 100644 index 00000000..5be33f06 --- /dev/null +++ b/tls/index.html @@ -0,0 +1,2288 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Auftrag Transport Layer Security TLS M300 - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Auftrag Transport Layer Security TLS M300

+

Link zum Auftrag

+

auftrag-tls-1
+auftrag-tls-2

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/tls/tls.pcapng b/tls/tls.pcapng new file mode 100644 index 00000000..c90f4833 Binary files /dev/null and b/tls/tls.pcapng differ diff --git a/videos/vogel.mp4 b/videos/vogel.mp4 new file mode 100644 index 00000000..05522255 Binary files /dev/null and b/videos/vogel.mp4 differ diff --git a/zli-m109/index.html b/zli-m109/index.html new file mode 100644 index 00000000..2df4c9d1 --- /dev/null +++ b/zli-m109/index.html @@ -0,0 +1,2956 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + ZLI Module 109 - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + + + + + +
+
+ + + + + + + +

ZLI Module 109

+

"Dienste in der Public Cloud betreiben und überwachen" +Course: https://moodle.zli.ch/course/view.php?id=1610

+

Auftrag 1.1: Einfache HTML Seite erstellen und mit FTP «deployen»

+

Auftrag 2.2: Git zur Sourcecode- und Konfigurationsverwaltung

+

https://moodle.zli.ch/mod/h5pactivity/view.php?id=116428
+https://github.com/Sephley/Zli-m109

+

Configure git username & email

+
git config --global user.name "user"
+
+git config --global user.email "mail@mail.com"
+
+

Auftrag 2.3: GitHub Einführung

+

https://github.com/Sephley/Zli-m109

+

Auftrag 3.2:

+
sudo apt install -y apt-transport-https ca-certificates curl gnupg-agent software-properties-common
+
+

Intallation minikube

+

Minikube can create a cluster containing only one node.

+
sudo apt install curl wget apt-transport-https -y  
+wget https://storage.googleapis.com/minikube/releases/latest/minikube-linux-amd64  
+sudo cp minikube-linux-amd64 /usr/local/bin/minikube  
+sudo chmod +x /usr/local/bin/minikube  
+curl -LO https://storage.googleapis.com/kubernetes-release/release/`curl -s https://storage.googleapis.com/kubernetes-release/release/stable.txt`/bin/linux/amd64/kubectl  
+sudo mv kubectl /usr/local/bin/  
+chmod +x kubectl  
+minikube start --driver=docker  
+minikube addons enable ingress  
+minikube addons enable dashboard  
+minikube addons enable metrics-server  
+sudo reboot  
+
+

Auftrag 4.2: Container Orchestration mit Docker Compose

+

see https://docs.docker.com/compose/gettingstarted/ for how to set up a generic docker-compose application

+

see https://github.com/Sephley/m109-site for all the files

+

Docker-compose requires a docker-compose.yml file that can set up multiple Containers.
+Using docker compose up you start the containers

+

Kubernetes

+

Pod

+

The Pod is the smallest unit in Kubernetes, usually only runs 1 Application.
+Each Pod gets its own IP address, not the container. They are rather ephemeral, which means they are prone to crash. +pod +port

+

Service

+

is used to attach an IP address to a pod, so that if it dies, the new one just uses the service to retain the IP address.
+It is possible to specify, whether the service is internal or external.

+

Ingress

+

Forwards IP-address of pod to domain name of application.

+

ConfigMap

+

Is the external Configuration of your application. Is only for non-confidential data! Unless you use secret to encrypt it.

+

Volumes / Storage

+

Attaches a physical storage to a Pod, can be locally connected or also via Cloud.
+Think of it as an external drive plugged in to the kubernetes cluster.

+

Deployment

+

A deployment is a template for creating pods.

+

Kubernetes Configuration

+

deployments get sent to the API server.
+Each config file (written in yml) has 3 parts. The metadata, the specification and the third part defines the type of configuration (like service or deployment).
+Kubernetes always compares the desired state with the actual state and then does anything it can to reach the desired state if that is not the case.

+

Minikube - Kubernetes ganz einfach

+

see https://github.com/sephley/dev_minikube
+also https://kubernetes.io/docs/home/

+

Note that the names 'mongo-config' or 'mongo-secret' do not need to be named this way. Kubernetes uses the 'name: ' key to differenciate between stuff.

+

mongo-config.yml

+

mongo-config.yml is the ConfigMap Configuration File. You should only create this once as you will reference it a lot.

+

mongo-secret.yml

+

mongo-secret.yml add your encode secrets (username and password) into this file.
+to encode you can run: echo -n <word to encode> | base64
+Once you have added these values they can be referenced by different deployments.

+

mongo.yml

+

mongo.yml
+the spec section of the file specifys the deployment specific stuff like type of webserver.
+the template section is like a whole new deployment with its own spec section etc. It configures the Pod within the deployment. You also set your docker image here.

+

lables are key/value pairs. They are for identifiying the "family" of the pods, so that for example two pods with the same label would have similar application running on them. Lables are required of Pods and are good practice for anythin else.
+You can call the labes whatever you want, it just has to be in key/value format like: "app: nginx" or "mykey: myvalue". "app:" is the standard key.

+

selector defines that all the pods that have label x belong to deployment y.

+

replicas defines how many pods you want to create with the deployment.

+

webapp.yml

+

webapp.yml is very similar to te mongo.yml file, as it is what runs the webservice based on the mongodb. The deployment is exactly the same, except for labels and the extra envirionment variable.

+

You can reference things from other files using valueFrom. This applies to all files.

+

type: Nodeport The nodePort is used to make the service available externally. Must be between 30000-32767. +nodeport

+

Deployment

+
kubectl apply -f mongo-config.yaml  
+kubectl apply -f mongo-secret.yaml  
+kubectl apply -f mongo.yaml  
+kubectl apply -f webapp.yaml
+
+

kubectl get all outputs all the components created in the cluster, whicht includes deployments, pods and all the services.

+

kubectl get can be used for everything in the cluster, like secrets, configmap, pods etc. Example: kubectl get secret

+

kubectl --help for help lol. You can also use the --help parameter for kubectl get more specific help.

+

kubectl describe service webapp-service to get info on your webapp deployment. Outputs stuff like IP, name, port etc. also works for pods: kubectl describe pod mongo-deployment-564b4bdfdf-jx66n you can see name of pod from kubectl get output.

+

kubectl logs mongo-deployment-564b4bdfdf-jx66n to see logs.

+

minikube ip to get IP. Now your application is accessible in your webbrowser. Remember to specify the external port (nodePort).

+

Auftrag 7: Quotes App

+

Username:
+joshur (namespace = joshur-dev)

+

API token: sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y

+

Login command: +oc login --token=sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y --server=https://api.sandbox-m3.1530.p1.openshiftapps.com:6443

+

Variables

+

Username (username): joshur
+Authorization token (token): sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y
+API server URL (api_server_url): https://api.sandbox-m3.1530.p1.openshiftapps.com:6443
+Name of the cluster (cluster_name): api-sandbox-m3-1530-p1-openshiftapps-com:6443
+Context assigned to us (context): joshur-dev/api-sandbox-m3-1530-p1-openshiftapps-com:6443/joshur

+

Set Local Kubernetes configuration

+

Make sure to run the login command listed above before you proceed!

+

Set credentials: kubectl config set-credentials joshur/api-sandbox-m3-1530-p1-openshiftapps-com:6443 --token sha256~sIwXmH5DFLbWQHjn3RFzq2VvJGurkt2QN2xeFdV9h8Y
+Set cluster: kubectl config set-cluster api-sandbox-m3-1530-p1-openshiftapps-com:6443 --server=https://api.sandbox-m3.1530.p1.openshiftapps.com:6443
+Set context: kubectl config set-context joshur-dev/api-sandbox-m3-1530-p1-openshiftapps-com:6443/joshur --user=joshur/https://api.sandbox-m3.1530.p1.openshiftapps.com:6443 --namespace=joshur-dev --cluster=api-sandbox-m3-1530-p1-openshiftapps-com:6443
+Use context: kubectl config use-context joshur-dev/api-sandbox-m3-1530-p1-openshiftapps-com:6443/joshur

+

Create files

+

First, clone the repositories that contain the yml files we need.
+git clone https://github.com/redhat-developer-demos/quotesweb.git
+git clone https://github.com/redhat-developer-demos/quotemysql.git
+git clone https://github.com/redhat-developer-demos/qotd-python.git

+

Create the following files in the qotd-python/k8s directory

+
kubectl create -f quotes-deployment.yaml  
+kubectl create -f service.yaml  
+kubectl create -f route.yaml
+
+

use kubectl get routes to view your new routes.
+run curl https://quotes-joshur-dev.apps.sandbox-m3.1530.p1.openshiftapps.com/quotes to see your file.

+ +

https://github.com/redhat-developer-demos/quotesweb/
+https://github.com/redhat-developer-demos/qotd-python/
+https://github.com/redhat-developer-demos/quotemysql/

+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file diff --git a/zusatz-pruefung/index.html b/zusatz-pruefung/index.html new file mode 100644 index 00000000..7d45eacc --- /dev/null +++ b/zusatz-pruefung/index.html @@ -0,0 +1,2562 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Zusatz-Security - docs + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+ + +
+ +
+ + + + + + + + + +
+
+ + + +
+
+
+ + + + + + + +
+
+
+ + + +
+
+
+ + + +
+
+
+ + + +
+
+ + + + + + + +

Federated Datasources

+

Note that you will also need to hand in a documentation for this assignment.
+Assignment

+

Part 1

+
    +
  • connect to dbbw004 and run the scripts from Olat as user db2inst1
  • +
  • add this command to the CONFIG_DATABASE.sql file
  • +
+
update db cfg for dbbw004 using LOGSECOND 200;
+
+
    +
  • run the script HRACCESS_Create.sql.
  • +
  • run the script HRACCESS_LOAD_DATA.sql. This will take a while.
  • +
  • run the script HRACCESS_COUNT_ROWS.sql This verifies if the Data was loaded.
  • +
  • create a linux user called m141fed. To do so, run the following command as root:
  • +
+
useradd -p $(openssl passwd -1 m141fed) -s /bin/bash m141fed -d /home/m141fed
+
+

Then proceed to grant all the priviliges the user needs and save them in the script HRACCESS_GRANT_m141fed.sql

+

HRACCESS_GRANT_m141fed.sql

+
GRANT CONNECT ON DATABASE TO USER m141fed;
+GRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER m141fed;
+GRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER m141fed;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPARTMENTS TO USER m141fed;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_EMP TO USER m141fed;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_MANAGER TO USER m141fed;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.EMPLOYEES TO USER m141fed;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.SALARIES TO USER m141fed;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.TITLES TO USER m141fed;
+
+

Part 2

+
    +
  • configure federated datasources as documented in the db2 Knowledge Center
    +All the commands should be saved into the script HRREMOTE_Create.sql. You should also create a script HRREMOTE_Drop.sql where you remove all the data.
  • +
+

For this part you must be connected to DBBW003!
+First run this: UPDATE DBM CFG USING FEDERATED YES; and proceed to restart your DBM (it's probably easier to simply restart the VM)

+

HRREMOTE_Create.sql

+
CATALOG TCPIP NODE db2_node REMOTE system42 SERVER db2tcp42;
+
+-- Wrapper registrieren
+CREATE WRAPPER DRDA;
+
+-- Server Definitionen registrieren
+CREATE SERVER BBW TYPE DB2/LUW VERSION 11 WRAPPER DRDA AUTHORIZATION "db2inst1" PASSWORD "db2inst1" OPTIONS (DBNAME 'DBBW004') ;
+
+-- User Mapping erstellen, um dem Benutzer den Zugriff auf den remote server zu geben
+CREATE USER MAPPING FOR DB2INST1 SERVER BBW OPTIONS (REMOTE_AUTHID 'db2inst1', REMOTE_PASSWORD 'db2inst1');
+
+-- Nicknames aus DBBW004 hinzufügen
+CREATE NICKNAME HRREMOTE.DEPARTMENTS FOR BBW.HRACCESS.DEPARTMENTS;
+CREATE NICKNAME HRREMOTE.DEPT_MANAGER FOR BBW.HRACCESS.DEPT_MANAGER;
+CREATE NICKNAME HRREMOTE.EMPLOYEES FOR BBW.HRACCESS.EMPLOYEES;
+CREATE NICKNAME HRREMOTE.DEPT_EMP FOR BBW.HRACCESS.DEPT_EMP;
+CREATE NICKNAME HRREMOTE.TITLES FOR BBW.HRACCESS.TITLES;
+CREATE NICKNAME HRREMOTE.SALARIES FOR BBW.HRACCESS.SALARIES;
+
+

HRREMOTE_Drop.sql

+
-- Nicknames löschen
+DROP NICKNAME HRREMOTE.DEPARTMENTS;
+DROP NICKNAME HRREMOTE.DEPT_MANAGER;
+DROP NICKNAME HRREMOTE.EMPLOYEES;
+DROP NICKNAME HRREMOTE.DEPT_EMP;
+DROP NICKNAME HRREMOTE.TITLES;
+DROP NICKNAME HRREMOTE.SALARIES;
+
+-- User Mapping löschen
+DROP USER MAPPING FOR DB2INST1 SERVER BBW;
+
+-- Server-Definition löschen
+DROP SERVER BBW;
+
+-- Wrapper löschen
+DROP WRAPPER DRDA;
+
+-- Node entfernen
+UNCATALOG NODE db2_node;
+
+

After running the script HRREMOTE_Create.sql, run HRREMOTE_CHECK_ACCESS.sql.

+

HRACCESS_GRANT_bbwuser.sql

+
    +
  • Create a script named HRACCESS_GRANT_bbwuser.sql
  • +
  • Connect to dbbw004
  • +
  • Add the following content to the script and run the script.
  • +
+
GRANT CONNECT ON DATABASE TO USER bbwuser;
+GRANT USAGE ON WORKLOAD SYSDEFAULTUSERWORKLOAD TO USER bbwuser;
+GRANT EXECUTE ON PACKAGE NULLID.SQLC2P31 TO USER bbwuser;
+GRANT EXECUTE ON PACKAGE NULLID.SYSSN200 TO USER bbwuser;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPARTMENTS TO USER bbwuser;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_EMP TO USER bbwuser;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.DEPT_MANAGER TO USER bbwuser;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.EMPLOYEES TO USER bbwuser;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.SALARIES TO USER bbwuser;
+GRANT SELECT, INSERT, UPDATE, DELETE ON HRACCESS.TITLES TO USER bbwuser;
+
+

If this was successful, you can connect to dbbw003 as bbwuser and run the script HRREMOTE_CHECK_ACCESS.sql .

+

If this was not successful, run the following command as db2inst1 in dbbw003.

+
CREATE USER MAPPING FOR BBWUSER SERVER BBW OPTIONS (REMOTE_AUTHID 'bbwuser', REMOTE_PASSWORD 'bbwuser');
+
+ + + + + + + + + + + + + +
+
+ + + +
+ + + +
+ + + +
+
+
+
+ + + + + + + + + + \ No newline at end of file