From d758acbb73edda1a922e05992442bc9ba477e422 Mon Sep 17 00:00:00 2001 From: Claude Code Date: Mon, 13 Jul 2026 12:40:19 +0530 Subject: [PATCH 1/3] Add on-device Android port (lwc-core, lwc-android, Compose sample) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Kotlin port of the SDK that runs entirely on-device — no server, no API key. Users sign in with their own ChatGPT subscription via the device-code flow and stream Codex models billed to their plan. - lwc-core: pure Kotlin/JVM engine mirroring packages/core (device OAuth, token refresh, JWT parsing, SSE streaming to Flow); 14 JUnit tests ported from the TS test oracles. - lwc-android: Keystore-backed encrypted token store, Custom Tab launcher, LoginWithChatGPT facade. - sample: minimal Compose app (login -> device code -> streamed chat). Verified end-to-end against a real ChatGPT account: device login, model discovery, and a streamed gpt-5.5 completion (Stage-0 spike, `gradlew :lwc-core:run`). Wire-format requirements discovered live and encoded in the transport: /responses needs `stream: true`, and `input` must be a list of message items. --- android/.gitignore | 6 + android/README.md | 65 +++++ android/build.gradle.kts | 9 + android/gradle.properties | 4 + android/gradle/wrapper/gradle-wrapper.jar | Bin 0 -> 48462 bytes .../gradle/wrapper/gradle-wrapper.properties | 9 + android/gradlew | 248 ++++++++++++++++ android/gradlew.bat | 82 ++++++ android/lwc-android/build.gradle.kts | 31 ++ .../android/KeystoreTokenStore.kt | 54 ++++ .../android/LoginWithChatGPT.kt | 87 ++++++ .../android/VerificationLauncher.kt | 15 + android/lwc-core/README.md | 53 ++++ android/lwc-core/build.gradle.kts | 33 +++ .../loginwithchatgpt/CodexTransport.kt | 275 ++++++++++++++++++ .../opencoredev/loginwithchatgpt/Config.kt | 70 +++++ .../opencoredev/loginwithchatgpt/Constants.kt | 56 ++++ .../opencoredev/loginwithchatgpt/Device.kt | 146 ++++++++++ .../com/opencoredev/loginwithchatgpt/Http.kt | 38 +++ .../com/opencoredev/loginwithchatgpt/Jwt.kt | 61 ++++ .../opencoredev/loginwithchatgpt/Models.kt | 77 +++++ .../com/opencoredev/loginwithchatgpt/OAuth.kt | 121 ++++++++ .../com/opencoredev/loginwithchatgpt/Spike.kt | 68 +++++ .../loginwithchatgpt/TokenStore.kt | 21 ++ .../opencoredev/loginwithchatgpt/Tokens.kt | 43 +++ .../loginwithchatgpt/CodexTransportTest.kt | 135 +++++++++ .../opencoredev/loginwithchatgpt/JwtTest.kt | 82 ++++++ android/sample/build.gradle.kts | 50 ++++ android/sample/src/main/AndroidManifest.xml | 21 ++ .../loginwithchatgpt/sample/MainActivity.kt | 220 ++++++++++++++ android/sample/src/main/res/values/themes.xml | 5 + android/settings.gradle.kts | 21 ++ 32 files changed, 2206 insertions(+) create mode 100644 android/.gitignore create mode 100644 android/README.md create mode 100644 android/build.gradle.kts create mode 100644 android/gradle.properties create mode 100644 android/gradle/wrapper/gradle-wrapper.jar create mode 100644 android/gradle/wrapper/gradle-wrapper.properties create mode 100644 android/gradlew create mode 100644 android/gradlew.bat create mode 100644 android/lwc-android/build.gradle.kts create mode 100644 android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/KeystoreTokenStore.kt create mode 100644 android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/LoginWithChatGPT.kt create mode 100644 android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/VerificationLauncher.kt create mode 100644 android/lwc-core/README.md create mode 100644 android/lwc-core/build.gradle.kts create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/CodexTransport.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Config.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Constants.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Device.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Http.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Jwt.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Models.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/OAuth.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Spike.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/TokenStore.kt create mode 100644 android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Tokens.kt create mode 100644 android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/CodexTransportTest.kt create mode 100644 android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/JwtTest.kt create mode 100644 android/sample/build.gradle.kts create mode 100644 android/sample/src/main/AndroidManifest.xml create mode 100644 android/sample/src/main/kotlin/com/opencoredev/loginwithchatgpt/sample/MainActivity.kt create mode 100644 android/sample/src/main/res/values/themes.xml create mode 100644 android/settings.gradle.kts diff --git a/android/.gitignore b/android/.gitignore new file mode 100644 index 0000000..cf3c081 --- /dev/null +++ b/android/.gitignore @@ -0,0 +1,6 @@ +.gradle/ +build/ +*.tsbuildinfo +local.properties +*.log +.kotlin/ diff --git a/android/README.md b/android/README.md new file mode 100644 index 0000000..f2490e6 --- /dev/null +++ b/android/README.md @@ -0,0 +1,65 @@ +# Login with ChatGPT — Android + +On-device, serverless Android port of the [Login with ChatGPT](../README.md) SDK. +Users sign in with **their own** ChatGPT subscription via OpenAI's device-code +OAuth flow, and the app calls Codex models billed to that user — no OpenAI API key, +and no backend to host. Tokens live on the device in the Android Keystore. + +## Modules + +| Module | What it is | +| --- | --- | +| [`lwc-core`](./lwc-core) | Pure Kotlin/JVM engine — device flow, token refresh, JWT parsing, Codex streaming. No Android deps; unit-tested on the JVM. Port of the TS `-core` package. | +| `lwc-android` | Android library — `KeystoreTokenStore` (encrypted at rest), a Custom Tab launcher, and the `LoginWithChatGPT` facade. | +| `sample` | Minimal Compose app: sign-in screen → device code → streamed chat. | + +## Build & run + +Uses the Gradle wrapper (8.11.1) — the JDK 17 toolchain and Android SDK are picked +up from `JAVA_HOME` / `local.properties`. + +On a low-RAM machine (≤8 GB), add these to your user `~/.gradle/gradle.properties` +to keep the build inside one small JVM: + +```properties +org.gradle.jvmargs=-Xmx1024m -XX:MaxMetaspaceSize=512m +org.gradle.workers.max=1 +kotlin.compiler.execution.strategy=in-process +``` + +```bash +# Run the pure-JVM unit tests (body normalization + JWT parsing) +./gradlew :lwc-core:test + +# Stage-0 spike: full device login + streamed reply against a REAL ChatGPT account +./gradlew :lwc-core:run --args="Say hello in one short sentence." + +# Build the sample APK +./gradlew :sample:assembleDebug + +# Install + launch on a running emulator/device +./gradlew :sample:installDebug +adb shell am start -n com.opencoredev.loginwithchatgpt.sample/.MainActivity +``` + +## Using the library in your own app + +```kotlin +val lwc = LoginWithChatGPT(context) // Keystore-backed by default + +// Sign in +val device = lwc.startDeviceLogin() +lwc.openVerification(device) // Custom Tab; user enters device.userCode +while (lwc.poll(device) is DevicePollResult.Pending) delay(device.interval * 1000L) + +// Call a model — billed to the signed-in user's ChatGPT plan +lwc.chat(buildJsonObject { put("model", "gpt-5.5"); put("input", "Hi") }) + .collect { delta -> /* append streamed text */ } +``` + +## Security & status + +Tokens are encrypted at rest via Android-Keystore-backed `EncryptedSharedPreferences` +(see [`lwc-core/README`](./lwc-core/README.md) for the trust-boundary notes). This +rides OpenAI's unofficial Codex OAuth client, so it may break if OpenAI changes an +endpoint — every URL/id is overridable through `ChatGPTConfig`. diff --git a/android/build.gradle.kts b/android/build.gradle.kts new file mode 100644 index 0000000..d095d72 --- /dev/null +++ b/android/build.gradle.kts @@ -0,0 +1,9 @@ +// Root build: declare plugin versions once; modules apply them without versions. +plugins { + id("com.android.application") version "8.7.3" apply false + id("com.android.library") version "8.7.3" apply false + id("org.jetbrains.kotlin.android") version "2.0.21" apply false + id("org.jetbrains.kotlin.jvm") version "2.0.21" apply false + id("org.jetbrains.kotlin.plugin.compose") version "2.0.21" apply false + id("org.jetbrains.kotlin.plugin.serialization") version "2.0.21" apply false +} diff --git a/android/gradle.properties b/android/gradle.properties new file mode 100644 index 0000000..55b6c89 --- /dev/null +++ b/android/gradle.properties @@ -0,0 +1,4 @@ +org.gradle.jvmargs=-Xmx2048m -Dfile.encoding=UTF-8 +org.gradle.caching=true +kotlin.code.style=official +android.useAndroidX=true diff --git a/android/gradle/wrapper/gradle-wrapper.jar b/android/gradle/wrapper/gradle-wrapper.jar new file mode 100644 index 0000000000000000000000000000000000000000..b1b8ef56b44f16b14dc800fa8103a6d89abb526f GIT binary patch literal 48462 zcma&NV{|3jwk;gnwr$(CRk3Z`Sy9Ed?Nn^ruGlsztklcC=e7I2x9>aqJFB(1eyu-q z%|3b`eLzVT6buar3JMAc2#EOW{C^)LAZQ?YaW!FjX$1*JIcZUG1yyl%HEd!6f#E+}*Jo*NafvM<-FbE0;-_L#rp}qdn%JEoAVNlEB#J^Oq`mU_#*ev4HLmc> zjXz_hFft^><#omb;Zer-%wm4hxo!wjuX3hBldg(^-RiOleKin`>KHfL3P*{k?(rji(#j2Cc0K509#>qu=-T&B!-5EBi(+ zIuTD-qfcAYgS@`Fb2^-p)4#o6A3z0&fp?~cV=CRsAeCmO4ZQ5kKgC%0el=Q&Rhd#k zaGmAbUW8uKC}-C0s~2);d{;mpsNBx9rn__66W{AhaSvJEK+c0b6ARO+l(CI7E|S5x zhaYP--@F<|99X&)9`q^2(^-Zu^Tzfm)v|gkTJHQ!G*zIg5hzoygeXZoYUEJ;iFkE# zq^r$*c|>Hmn3GapzcDYnjgSFiO^NFyTR5AH#mh%zRToMpEi(r)1$5)h455DuV}0al z!*psWuL@Ke-2gvftfMEGf9YEi^<{B@qru zINgo+YsE&LN?)1qItJoNhISp-fZ86`XR#*6xcvM~_7=JHUX;K9*=Gu5X~ zix|O2d=&C#u_w{=B$eCpJ4L*6i7={j+{Og~`Emz@&98}6s<-p^)`0fXE4cJBP{>)Ltb>JwcqI>yz z0-r-SEhC@p)XOoh|1|XgjFaREHfsu4dAGVz*k#m+V<4 zHqvlud6=;#QWHUoTR_a8Y8+heN?M%n1@0YLiaN@GuOPNd26tik7eKulTx?mM-R!1H znB6+H{^krFXg_b{y=QeCT~qR3T4}l+b!Oz9;~|3*6F<3?#|DYYW&1RtFE)ILZ!`85 zVmvrZkLTzf31unH7Cc5E0iFShqlBE9hgEnRJH1juII*vyp&xd!g`q}X_6WT6E$hhQ`Vdp9k^<)VS?lj!cTh z7FQcQAVA@jL^cXod8cnhKG2TS9+;QU6Kq>}UOY3&TL9gXbl{Fv8@WsF=z7>X0To@$ zY@Oi1uc|MdJ$>Kn{@!g_e`-I&Tpwfg9cr>(iakDX1qciCG_1y!Di#4_)lE!bWJbrp z5aUonb6m-?tiQyR_`P#~SOu+tb_ev6JO>EbEhHK@KbeT0_FDo>dl9bMg)>xmCNB*g zG5NC8ABavuTEZVGW6jP*nAqRt3W?7Iigc-EE~zpNJXRAE z>`~RO9$892j&I1kV;9U)xT8^}IeV`n{}QDtj2o-RBt`DGZUOO;O*lFCb_vpyGh*;95PfeGu!dyrmZ9VJ3Z*upg z6R-3Lr%_55$Hw1^{+KWx0#z`T7O6sXo1h;m?B_ur`X2bFz-SzDrL zpk^@B<+I6imc@7vip za%1jMB7q@1j# zz{u?YojZMW{5j$@h=v4iu2mTu7IzI|)Sxn!74=*J>1a&?Xjt z2%JhSi#4huEcD9qdR9Lj4vwmfnL{%+vQ{f-KgYeqin(OPd8+(g*Uq#TLxQjD4 zLCL%ul(V&PAPlAx8D`@K8Rc`{GPecQ<)d=KWel0ejFeeXGQ6o7601B!!I@RY&eDriADD6wP6DcFKDLZ|lO#YwnrNCZ)zRJpdxX_nPZa4j#$j6v!h|6p!dH}MY6#B`@%6=) z-HigguDACKBULnon^FKzazF|Y1{t(U5rUGnEU|}djVsWT-F>@@mNx?_$kF51QF4C5 zStKR$^3(fw85(4HGs9{mUTtn1)3PwxTN?6}j;32&vJ^BiPHfndLkdU5sOemXKGyCZ z@<7j(k>DNeo~QXyJkFWk!7(y1SB%nA3{v~P2c8ooKa4auM!el!Q_=;lJ$c5ADqE+^ zX8*|A99v;jWPrm(8=h;2ZAj|(vVbx~wQ{N%v;eYLD_BB2LAEWCs@xauyBDl(_HIBvA(XJ7B1E;O zJYCJ8xFJh7f5sr;Y#Wp_`$4Z_H4e9bGiBp?Qu&2!@%Bl2dT5evfFO*^hLDiBu2%Jl z*WAlL5PaQ7skJa(qVysky}DQquZ8U?2@UyJ8zB#=U_E>MgE%XA$CtfL31m$rATJvC zs@!crc0=128PM=Zp zW_5Czv9))n_8Ru?{pxM2F8^r%*O41}RnONbSj*piG%`nyF>6ky=|;B&k8iot(J=kyoU3p<_zaAX(1ijzf*uXA zZ_5jeC{Lks+&QeFIlmzZi3+fsF4fNW^~kvC4Q*T-vrNP!x9xnen12lZQM=1_MdW76LKX(GuW`%T~dM^YX6+ras|Xy4Qhfcq=D+z-P-ea z`T;^gj3+grr3^hwqcNTJErl$z+k>{bYFm6QV%7Opth?9+>|Dn)O@`7F@=j-XSqGPW zjUAu%b3Er@;j1%RZxVDhI3sakg-gvTLOSV7;FV6ED=(5;UG??=WADZw^=$4AyFh#}VMe3afM^pF zFa}-nM8X=K?Jy02*o02@6k{ z%O!hBhjXlXKdhy3A{xGB<##e|j3^dFv~~%v2_H{t(mN7NVeS~51?D&Ozbxa`qwZ_4 z;C#Q#fL1sua%ggucgIEHZtcY=Ag&GgE|h7Q{77D!WUq`;SSGEE0pU;aoj<7-JCAvf zduN=(tx3Mb+EUXKoax|v;8b@#HJ&Q|!g4ryrl|R>WlAv?IH`bk)I24;eE4NIq@SLK31LD4+w~#3iN{=<`<1R!t^$@K5>U6%W=%8_ANuR5 zs(IDuI18ftirTDARnGmF%;iz+4{MlMihJw_l!0Y)NttXC_t+s)V<EY>=Xin*nGX79k6vQ?beRk zy_J>@YSC_gMIG$yjO-y&o>S6xtfT27aSs>e|`x(f2R1bM}*518~%x>1Yct=18b&Z>GiS*>VB$+i2876zL)1cT zN33g=g|>xWE2)dds5m2+8Vy)m-u@NHOlGYxxjam21r1;xWtT0TgqKZrl}*LSkqFt4 zNTI1=3o%C*!-i;iWnlca$stRdwITA1?#fD~5OIqIQAM18BwO_u>hqL&OAANiF|8rG z_IZ9mp?FA-{Gq9+Ky<#NgL1gWJixfO0ziP$4T4G>vsvqC-NQh+A64F4! z-(t<=AbPSG%`mTl6BJtH~3RmvPhQlE-EUkEoBIP(_WMN zK~Fe!siee{M*ns1hkp5(2}vX#%u+T!Abh=<_gEx_QW?h4V@B>uOCEetEe01tl)^`V z(=cOLmuOB;8&&m%_6pcyrt83UXkJ`f9I&0KxY09}RTTs!l^_7~8$tPA%Hm#&$k0;# zF;O0zCGo0IN)X~SyKDoY1DW{Ulce|V9w=ld;U`z$t$>8U!Gu8V?_LAJAudt3eI#*! z2i9~F=kP5m>!bmb%1e~b1!1gz01Py(Yw5gOsFN#o1a&d|=PpgN(#UVreY9^99I0iG zaYE@>(C^V7pnoB~#w$2C1_TIb1N5Je&iao?S2A*TF>@vpHg`31{uk<9{zf_}s&z%dL-Fo)C$yl$%pAdqU!HJgp zh_{m1imk{&{ScyeuziqZHu5cto0{S}^BlXu% z0~;>_yHGd#?Kt8ErxK)z6ojj5SacQobw)-8`c!$HOI*V6eyqou{1Upm%_p!BY^t(D zDtn(oQ!jff`ddGSD;P8Hes!v)OKW-*>mS&#i0ow87;h>(=Cu0>b4)|=EegbN5=Xkh z9Ge13=3z#sk+fT<)PuUUf_%Nx@l!P?t*mni^94p^Ax6b2SVL5U>9dHH!H4DL4}@?@ z?Gpq$C**OmWliYA{5s<|EZ@QI2{-K#brFxfA~AIqq&-WSALHWQ8}%mvaNFasrtnE{ zg=sB4-RF!?)nf{>Wo~kNFgYefoFHBcSr*;iF9B!R=5Np|jv>Uf+mcarG-XGy*kP{z zISVyoPcl_9cOg-@613Qx16OGF#sH&2NTHDa_}vyidmxS~pMfY#AeQvu?AXpWNzi7A z*6&7a7!C9HRU+N{>WYTh0GXoBnXw{lQby^XShgDOw@e8TP}9Y*oFV4MVF#@Ds2A+A zXBEt3a@-IIl)TOcXx;0P;|ihR%Tq@DXeG5p-O{!T7Sg$s1 z8OA4iOx-!>6eK^x{jU-0SvByimK|nZik5zKIvvWVGE)4=x^&5Nx%Qgje!k3VoizaB zip#?$u(R8u{wUFC>tVR8oA%7fs?xEu(gYn>y6BB%vwPR9&RoZE%%RK! zl#Qnkl^+Y*Y4L{Xk(YX&aGj|zSpqO_;C3CTepA!L#4EXO|(eA`Fi+2EQ3!C zo^SpVP?{chQ3uaxu7y>w213e22cdA#l-M2kStPE%sq6vE4M*?3At!S7tIp(tQg(Ml zECjeJw8)*#LYYk_+Txv3rxsH9jJZBRrHp29yJ(^;_PEdn%#U1q`r89}38;XeF{ee& zsZEsUbJ{LtwOjU{vjL(Wvs2!Bx;#^Mzld&TjS@oo3kk=0P36MC-Ie6eHNN&{8b^s z0@jcbdejrrj!>r#Wu=3H1dgjeOI}NkhmE}K+UK&M>%7b!n&{0Zixk%^)6#@=V~IZN zxG>9kl&STQth}qScidfg58d2dF|v_U<@+V^eE@$4x;7oS3)MvWusA?9+%rN>aY#eA_6 zic@S(@e9$9tQM-&-7>X8~#n{5G}nuOu=dSyN+b~jA;_SExZ1H9Q1A}}Rz;XtXUIOP0~ zZzS|~T+%de-nGI$s?wxaJoe+99vmo%xm8o8SNEsAqAE)4LNvHc-1AX24C4k4u3vZmov^_VcxgGxapV(8)_K(^8= z2d{xCrmk(x&514Ly?e{Mf6}h3=oeP7+ZE{%B^c-kK8g0W{tYw3q%zty_Rd@1nbnyHMwabNp-sSyzpV4v>QsnKcQjF67%g~n&3t^1MesVxCzfJ5b=SOI#YfPP^^JGQw=9L1RCMFbrU{8O0LWOUdBK#j&{`tzXX zpe2_{+-8$a+o#%8MUlL4$yK`*--z&3{@Y?jP!m{g5nM+Ht=bD3o}Ok~sBQ_!^!->! z?NDVtyLXzmGYCEmjSCDK*q?Aq1;8fz9l9|z@~l{)R6GfKELc^(nV+TjjI^n0M+S0i z@YOu*Tk>|M6a0_n$(E;#^1Zgif<-CpYiMvyT+Y*9Z?&~IKSwsLa5Q#p_?FqK3lKIw zlp6Hk%lio6)yq>m-`QT2Nj-q!aX7~Hlm^Xh6FNbw z$#ri(Kk*GUHXORu@`aYQU@ zB~S-oIO^~abRPocemkm!W73dbb!j^_xgo_@#W#6p12>w^{){VfeX?U71Xyn9&E zHa1#*!4c;?r}jv7dMN`g#&R_S215)dccDOJr=uz%LIz@zia+LIFjRakROr?P zQ|Xw0Pa8o7&W=fw17`+SqepsQ-Os5v3ncD5|N?N(AHH&`>hLY+CLOluJ z_ErpaT49zK(UcdNmQ%iA-`jS`A_1c|$W86{d_T_T2V-HH3xUqpX0QJSH%i>1i>#vK z&y{;5)^pMB=u;&_DEWakQU>j&+opIrBf~2GUh{`kG{|Z&2Z}5dwG}>Y{W_uQHaR$_ zYH%}$c`CGC-FGCetRdQ@RZ2-%ucC_|R?mHzYEnqC%u9zRBH8wx7po`=EVPMpq+hL2 zTdjVhQn$)++17^cn;<3=bxJy0Z$U;i3AqJMPJO&SuieU&0eVX?eLEEI7Av@#PV_ZQ zsa>I>B5HE996O$z6HyJfhEt^aC><@AnzeN`xs@lv>^pPFtcodrcGyqPSB?#C`Piu0 zh5=hAW|OtT9hs*G?7}@*mG_f7ae@-Nz4{qvne66kco^uD$(JbCo2ttqUm-SMy@kx% z!eDt?5>w5)M!E#C!b#Iu9GqyhUs|QoYWHtR{4espRS-LUt=viY2iygF=-j3kcU#uF z{ka2=zsOuLR}s;&PbbrB`zty&NfZpV*Y;~i*W$EH0JOGS&FMS%VK@)f*%OOrcU3P9 zq4zjhMpx}oc`PWtP!o5Bdlp=(A***TZwVwuZbuB1Pibv5uiHvW{PsE-k5IfCgUz~l z0nMeZU0R>(ajoQ0G%Il)z0BgRR*bsdz5NcqJ<)niF6|PUO0i}<4)q>6wx4K(5>Y_I z4$WMkbCOQFs(krBnl zx85i0*7%Zm(&nKNP?AQ}d~6@?D9dO%@}ouN2paSR;zyUqJuw)1SRy=g%o;g(BD|Bh ztnKV(4fcBgDJ~M@%}n-6ow3xOhnC>C^d?PbS(9=TnO)k5p+W;pu2F4eiG7ts zJVL4M(NiZPQDy*9`H>-P0GWY#=UTnh8feiNF}hCs`8^ZDKy;XIL^9K4Ps&y^#DQSE z-?J z@YOQ9NQi>ZP>^ix5K`R07kWj?`R(B?E*OyR1$Vd;8p%2Y2zEYt4CJM~gVX%MO(E1B zzXhsHn~R1ifq9~dtzuH!*3&W;r`D(Sjrc)m#EI%`Car;CMWcU0c+0r?O!)HpjEvyP zb^;pO-Bn6e-+>dS^o{q&8yEH9v}vuXX`W;NPRlwJdX|59`z?~z{pFE!^u{3k{KkJ55^ zD;F0ldy9W*`d5YP|0(E6|K%}9|D^SIq>wO)4^cJ+yCa&xl*3}hpvcQ1eP_k;@>tz= zOZnw)#fxHc81jPcTM#)jgy|0?n0(jd3IPu-lJ&Tm`#F1)o$GTwYp@dlqy-qiHFCHS zKgikMUx|%x=_%B)>n_y^+HvD2=nP`}-G_0A7)I$yc4`tXS-On8qOkNp>Q^$|Ew%Jm zYx34*(*Z3SF}xw$CA?nG9O3ZH7l)@Dp4EyH>8eXDb}AFz)k*T53iA~gRu&e15u@|% z9Rw?69nQOeJhv^^unjd-VGFwbDzf9K{i(U{xxHyM@-aI+0qP{TU0G~w+Fs>taL#Ik z4+92(Z7n%+okd478;__0GkE`&(C`k8h@?UNnM=F%A~2|TKo)q9F<5`s)KwxJRw~k; z4giS~|8AIVG;rde6I^W6m9fliR^7YT*>&x7wv^?xu(5p45n{|2F>x%?9Jq+~Tqo9# zChbeGm@9!(s;uIKae_4h@`~yIj`Tqct+-M>d>~2PCiQ?UmFUioyy&~h_DTBQ--W|q zqA^UaJMTz4tEggQ*_cQ_LA7j7bLyz8#cpGggy;YBVk!%oSdufoh5-FYAQ)v=d$Bi`G$^~ zm!O;En#M9uCykPzLZ5SHa%?hDHP5P;T4HN0L6J*r9DAvC1WWPOrd{*obfr3yJ?Kl3 z^_6dnXRoi4<$Tr!=4mhHg6ig~BatHR zv%ZMJr-`8w_JyFEzUSQdp0HT>|9QQG?IXj$7Rbx4E)%HauDyY!tedHP ztIbq;D)ckd-eirAHOG7icBH23*ApHA@nG*Jdh}~G?L5C^Xw^+nLWG+>hRi&(fnpY5 z?^hj4si6I{m1u^%i_yk$tco}28X8|}g5*tAEZYF37$f(+xT%XvO^`i^Ig}%cydrwF zlpL!xdO->&@q|8MiJrAxt;z2CP*a+EvV`_2& z<1=p{zjhmmYVkpx#RV=#zuy&7^2Trn=H$nT{OBVF*0z|QH!NxBF%gbqT!BEx zKB!SsSUwSo1Zr?kMM%N)@hG=&m`vRQ6QK6=oIvnUI+|C)dGKM@jNwqG2Xi8;YCUHYRh? zbl@DN-za)+0F9kw>Yv=ioL)01uFp7@AVEB0AH-nmB%j$RC_totFy4BKd;OPCMUMBb zu3oUUK`|{AvkM+@KPZD4Tn$(VlQi&aWV*Uf@DO|FQjLOoVw&C@z~Um*h%Ka-C=n4H z@(Lf&MDJXNS{3Hs@J)11(zo9tGp>wS^b9{Q1WN=Ktn>ZieRZS?k`gb7P4n?cl^7^* zG5-oARAG#i<*z`J0ski%;QCLD-T$AbOHq<{KxIb4=QJRn@MGj=ns0WhZX+uX z=oTjz`o-VviMt1mB0W1vA*7oq1ENz{<*-EU)U;r*ODfV!G-?hdnzhM@rRZ=|qaFTN zX*t~$gc-)M7GS{#34R-n`B)eAPfebN46~61R?j^(Pg3TXR1PyQrO7Mf@xf<3VL0`4 zh(i?-SktJu8Oj?KIy4p@%5ZH;P&p5LB8 z^}7P)9h}vUP+1Hd3nNzNcbR`%1>dSZbWhiXe-CcB+s9e)_w<{bypZ(@cQT`P@ch=d zSOPhExgI31MVFPsClEXe>$~qYQ+d}7(!BE*9y%AjQ47BMDt=#>`1ie)|ES{pFFdHa zI)CK`f3x>)DtZnm!f5=e@g;3iK^jf!RU6hpjYu^V#q0uWLuJ-6={Ua3gDi9#*P7;- z`rm*5)n{2QE{UZ01PVy@_9(amogzzOwYcVgp2>LsJ(}hKbX_!ayZ7=U{!p{BHussVj(W z2z3$zu7h$KK<%}P0YBJ+)0unV*xD&6GusXqs=M=Cl&fP@Ttzfq?>H9TW#qDId+C7? zhD;;HOxDJR4dc_xI7-b6N6nZ@bUWueDk<_9Rju2I*o(i)M0&~%C^ zc)a<25M<^NrsjAccydV2HJu_-1W>b;xrB~Mi@c7FrW-94$-GnKXvF7( zA68!d!gkIo8(URS{(u{zRtrF}B$9@*)KH9POqOW-B$za4Sg-A&PM*on$>$o#L7pH~ z&YW8oJX3T!!@2r4Rr6ac0ZDbtB1b5yc$5}7oZSDvGF0FWTpZ#r7@GfM^MmC-p{9Qj z_JmmlTxO(^(NHqBc$ECU$jQp^;)%xnyr$qvNTd`R@j$8JppDCGQAHQ7?fja9McCUZ^;``VW$1+G#=<;K{_OfH- z_$fp~S3K`;jPNNZnkB@=DFQy3{6+Bq9nOf3~dr4q8zD_t{P4-^%<4kj!U z0aj`=#@G*w?!4fpM? z8Pwb15(Ka*TtDN-2aWK>*hh{R_C}*e*vSTkHdM(ETM!JrJ=1h?(_WL}2p#QXjrKZ_ z0k_yu^;~)#*r>sQP7d_4VBRvWJCzw#TxA{*hktwQI3ST{8{>3$KHJIgMGK6I!d}Q zinmfq&RLRxX8P)_@@vVr0gPu7*)uU<%xS{|Eg;*w1}2=C&?7B zSX?OLt-gZO+<4@tLeF+K0~*|xwMD__KxWgGfsUpj)KyeCM3J-f*uxe|xk;Dlqq%1< zL(PaY@U(>Z#k!C!B45JlmE^~wHSH;r1c^kWTG9_VT~1LN6$a6Yg@kNF?&b0hs+5Dw=0j zR(wcEYmdfgojx+Hzu89*C}4$I7^?^vYKhF(`>=MC)VeeFR}}?j#XeLnp8OhW9%9ND zt6utD8DHnQj5@YJv+$USdN{8apQir2)Z{8_s!BABmG2O#pz5lSh|gf#CI8X4I|U4g zhQwk=VEV+j+-KNxuIk96Bi%^(Sf9}A7o$zHJ5mV~)qP))QQY&^>9}z9z9)PWpw>8T z7#NWNEtnUoUl{DP5(lmy<3;tpLJ3hG|;CGB`3**uH0tf9>;7w;Aq9SRVg1FDpI5y~rY#B|eCNpAXD z9692@_%$t2^nu&4lU~(~_iVf|Cs|mXs-xKlY$-~FZB$!oDK#)JgHZCG)ySDURM=@(i zCpd{Er89|l&)(&5>L6LuWY3yC6)`jPz(Po8pY=AYIBnx3y2Qx6*sT42mpR$zwx!!< zHHCc~tbF^-bje?bo#~Q59Dmw_-VcliCn^FfI*EV)U1NkNA`6Cm=^%j`%M?1Zxa=1U zn#DPNc32&XHHfUfmPx*J+3_GA&g-_pd#wO=Q^5bdhzmm)>s@yO0q|>ROV(hkhJWf@ zqWjI#+9Wx%C+!kp&kxX|XPS5m9CBC&3r>}SwdFd#YF_W78A*CN6mFC)qzOjM);Z&v z#MjdXXMw63v*tbvY+$tDmuHNFunOlRM#qe|eV&|$98!xy{n)-=N?lrkr0_}U^sz|x zs0y);(2Dooa;(9zHzRi=I{GSVcv!6jl%ck@)>JODfR? z%aI)0HvbhzY9K7eYsntq#JvWzj$WCuoyGoPY7;LSPfZlFiWU)X?(-p}s4FXQcpIp00;%Jv;k0t@2vBu4i;rh-?{z}cHTLL9Rz zT8r(1Ws*H~EyH+adP$cGv|7HkeS9p6eOEI*`idH3twkEJ*72|ey4JgISglGV0Vo@qe#)f-=|g%l$S&Onwl@mmdn|sjXXYaQ4MlfzjiK1* zY&hWQyc9?G2}2s1fYnQ}LXpq{!&Kr97d?=a?_xXAU0SXrZE?T+=9os2*v9%Csph*M zW{}m4+PIRmHEI;<=c5$PMrfg#MTs);4Tb_0**o}*cimSWRcxo(;G&&NV+-?W7v*%4ACG#t5J zQP=$g-(mN*;B6s)d9JNkF0#Zz_WA>J;{=2a!IJsiqCV!YLjJ(wUJ`3b$>qcZ!HjDT z2xm;fMSbtJ|3o~tc!jJ+U8a)vX@NcxU8y#u!Puq%R~{sps0msRFO2!GM4}786S7* zxgNmf{q@|Sdnf6_he>gEGX7Hn)uih5nL&&t4`O{?V;;bdl1U~9RAnjNmt~1UPC3mh zrR8ZtHzz1(yOYSK$OjKf;InJ+7mH$WfqI^OG3dhA+S!YmIgRv>2H78?<6A=~%E{ug^P+^b*+f=j32&Nv&Ypq?DcH&Busg^AUDE|p; z8(tQxZs1+0gUX<5~Ah zT0cGckI5%nM~d`uaMJ$o%2bt^##I0UdaQ2>-bpsP4P1Vk8r7EOSr+a!D*Z4shiKFL z35Lvs^i;#;G{%ksUUo8(Nj2DY?u5->J8kqS_#{B`HqS(UkzR|K5&6XI_#FH4?$ znMXeTb$nmr1`|{n*#5H1T%vtU4-H)vrtAchme!ZG#@c+Hrf4uxx$;VU(Dr~N-ich4 zMKpdwot^bPY#kBILFgi?i3W_kV%vn2J+%R5x}TL8I?B~o#VXlmr?i=y`yJi-><;X* zPCDrsU51x;mkr+t18lPs=6)r^gEh2$saaA!qv_< zKQP13J}ptHaUjT_(*x+P}wfV-}57aU3rp#3AB&~e3%y}0ju#22u5@mUIT!GA{* zd%-e2DTmr#$(P6^$&N0oCgR)F9IPR~!Q!x6YI*7dx6LR6n8tj(#1~!0rofeMtT#g* zW%-p@V09>&o>iz0j66K^soJWg(o9#T(8Xx-P3?;J|t~nIDSGPq(?-B zOoNnc5HZhsW(m6!J+yj~kjmjV6GKvhO>%^v5`O2I@4B$Z!~DgelYWdC4P>YfmI$TR zq`atDEhIt5ua)PS;Yz1`FX@3Na6j^uBx_rNKTmgboWGwE6O5;iQiN6Q8>ZX%ApVJS zTEf6oj=@?7klS(JaijG|(gO@dTgxB3#H)4&?+@VWkTc)dl;qK|uv;WRI*cG2`6PiF z4+svy+Bfn&Fs57Jz6i!C(w$w@VWPAbRGak~oN>3vUg|Mmk0NpfURt0*DSJ_e*Gi8I zqshW4F}L&aS8x~4*#{4vOc`gKW99cx*L^69fgPj#?++q9LidItd}<@&#E{ZGz7g|c zFX$uKJ;Qv^NpN*e&EL;l@1br8j8oxO3e`g<911L_jr~Xb0)t$x$A~dFay9(}gt4&L zyb=1<`|)_7(!^xJ14xLBGKXO3`R^_;F01 zG70TiF<5(=pRsJYj!^XjLl_vFJOQPhN#Pkr#G0-m#xG>q)GAHjE4WFhe7Zi83;gte zdDv6+)qrgh3F0}$gPmtb9-Ff1m|xDD$6jX)Dcd5Ms-(@nKM_3)2+hfh6@Cs@-=%Z_ zIinf|ck6rN{EOadGmJ-rzvxZnAL)(mf108HL2v&m)%=a*?3CnX2ZfOQY?ha_11m@UzRqlkhrVbQ@0M(tSSTerx}IH@Dn2={w$iGqU#`v}PuV7I&A9JYNP%sqMn z1bTq*Ok{V>SlVH8H*4X-lO?VzaDQzAaLvc1tTL+To)YOuj^V8mQ?)K-FT(s_!ds-O zeb$rKRR-~g^+_aiGtH6kbJ)!K^ie;ipJ8e;>iy2}73i(1RY-~!(tk2zPj;pwB4k1a zVa~7lF^EE`UH=#eb**88zBH%!WkO0S?_Zu0KpRtXN+XMsAwfT56IZI}&cs+R5N~p3 zlQH7o$(zsQQBPIRmD)i>TfdcgCSKbVVD;VCmO3l1VNbV&rWc9o>Pk>ex!)Nap%NtP z&kKIFMm@k9-HeXj2$((SmG+a-dXvl7q(7n=8)cELHf!@Le+X)=++(}pKC*dcns?>G zVa*fV{2FDIJNaK_jq)WE9MvxiTm6sI%YUn|S=oP0Z`vE#GMZa`4V5byxmv0@8@Zb~ zyBOJuTAG>Im^uIL@!ZrWJy6xL{%n;pEwY87Y^xYSfmmgRcgcEDfz4TJ#{;n|g>8(> zv$(RLnp4oD1Mj>H@ar|0RCy}E{GwvuKOf1FS}O&z-Q)MmCVEK{p~b2xFj@lTn}#s4xg7h+r;n$TZDlT2AXAv z7R^$J?R|*xL^>7HI}e>7{HszA#Y_e8=~8*3zy_J$ejuhByeI0I!w-&%MW7Q-FGMKU z8qPm&IdU3w#^#`d%Vcn&q^w;EEr|w2F@ax^`R;a@p>l`U-T%~f&^`#zG}qdSV)A<0 z^*U=#=#o&gd{o+*s#j$xf+2y^t1Wj9_h}(DNi^aK#jI}z)v1rk-H)gocbgc`wB*?$ zfg~22r!^VEN+n>U8|3{Ebe#!9k|dF8lV*9c&9H~&g|$Ymc-2O^j9w$Q^I)ldd}5zv zQkBFDS2TxDn`p}-{-`br?tUCgyfr0Wbf3QeATbp=9sN|e90U^eVOu0~VT$1A5))@C zPcwzUn7bP^Gd~hLA@8EwiklMmlc^(;uPE%tLecC-iZ$_~jNJnZYn1A%r}=VE(-LG; znh6Q+b;zKz_N7)0SH7t~u#)e>Pr194w7xp;V&CpmJw5j6zBO%yB zjVf*iveYaWlrE~+p8YYym=-QmTd_F!`)ATishn6(oD}hTE2AqnVPF_os`ca^ET@@Z zoo~4YJASOBn<;8#(#3G>n1E)&@JA^3LV7mK^kaJ$((~ASWup3G(%#8O%xFX8XSiN~ zUF0&gDyT`FzIjtA`<-+9RXEKbwu%RtcrG!#-aoN0aj)i z(G|=#b_!z{o1}cIyw#n=j~Ac|NnR@<-CW$c%JFBFTi5JW0BX#4k2o2w{L0EglSN7E zFUcmFVF&U6NBA7!t`Lut>faDk>pW>Lz9BSzsqWvnI<+L#wg=zw+aeL6=70S773#Rq zG@fVM9=1ZibB`>L>hKz>rHG}`pX;dZD>I!_x~u>jsx3;0d$`Q%t7d<8^lkl8w0WZ3 z(HGiok6h^#G2EzIH}G*;!U8FW>@|C+wE+z{@e{wwWEkzUEiT0aDJo2JwZR{zcX$Bz ze2pzE&vKCc6@vE*GIv1LZ=qSg~HR)Jf|ljt#^m2hZF4z|32*7{hd|u`C7{C zjG>}`{SC3Dnc~5%D4yBa!V@}xSBtQ$ZWY^qs3)9jTuIXYMgPF5E0*&A0B(=JEntcVgC%ZO4UKHyuzuSblKNHWJ}OzVpeS z?8|{P8FtkJ=~%YMf1h*@o-YsZkLVQU!43cY~nWEmBt#&Ar%7WClZK8 zSe-!M)B8((tj^wSIm3?e5oe&mQs6BAE#Y7K*^boU^Z#aITL%-H zul5Gx*FKM}n~RnE*Ko3}nXrk8nTw0Ok-d?{|KMda<$n9cFHzkfb4wa&Dp0x>XjayP zg-KZ^Ayey*gb`NecHls@$a-2|Z!Xe^@P`uYYo`Q*jKzDQGPFf^GDQ5rd(-X3n)&f|bD>?`-DktKL<0hWK!cPS>L^@|VH6## zG*0#NtGfzpZpt+e{yL@K$|Lg*JfO%I+hp&kR;NxOJ+y2H49xZA7=^RKObPZi6 zL&R70!l_{PTFcxI#h+WsO^Y<`hE*z1vg9n7nG-6n0xBU8F8yDd}=?${Kl$qim3(S98@^W*vvSs{l zU}!oUIXap-i#nT`er(?avm4Q4-snuM&-cwu#-M{K8n;l1gP$ z3sw?`ls1z%eb%&mNBvLuEci8}-Q`|kUw6;F0-pHb?+A)+BLSn7_@my}6u%J=Ub~(* zU1n~wcfO|73IBZF;|Bhy$0FeO^>lmmZz?ZuZC8$p6<>B{Lsp-*mS05IVU00ergKWv z(LIsLS=?(>QLLQQ?bdTpyO?iiEL`;>(XJw^lA*7FCd|$g@c3VRy#tUf-Lfs*_HNs@ zZQC|>+qT`k+qP}nwz1o`ZNC1_y*J{2=fCentcZ%LwW?M`<;L&dcdwa@4GT@LCkltq=Xfy+OasOLT!lXrqy` zEW9YuDcfQtJ$oJ|Ln|b|q*_a|YPgCbBBfQ|5;-1(P3R`sK~3T`TtVV6yrtDbioJKI zPDV1BAaj#O~V^ll>$# zNC?nv_r5RiH^A2t<)qzcvns9Qd$_UU$`jN;KUSNqMCQiCFCi3A$*D#(v=FXCqz$SB zyC8vjHyJhMy$5kCi}FBy0NdSCJa6{q(|*9I^zwX1NHX*dHOIDB8bsI3_{(*-kkQV@ng|lWd*nWx!(xQ1stGMcRDjH=YUQvY2^uCZuO%-0Jw5az*F1nW_|h zR~z5DT4j&Z7527|#z9b}pmRW}p^|OrU(TWox^&Kn>YUn%%JlZJ^16vzy|O|GnZsf3 zSXEMjOhuYZlh*ikE0&zHt5va@6&GI{1&D+NPop@Tss&f!V4;}nqX@iOvdonoDa}J_ zE-u%qrrUpYVYSGU5NeXJr?#B#3dkObD8uk*U|u*zS;T2YgAk;_kdF0s4A6A*YGO4)#dKwYLQi+*i=C3N85d93 zAe#Lng7EX?@}-FPvIdp0y!`J@^1tg|IHwZ=C-i6LW7u!d>#==7<(?=6?caFCo;)AM zwwV6XHIU7}%D3 z75#&7SiVq=f6k4N*gy{?o~K9`+fsId8Co*62ksPHLm=SB>G)@44I(Fbs1stfE==|e z5WM)k7Hs~OwT#*$%<~0|BEb_6HV0F0=kYy;P zdAZbN(@{*9FL}4bSi-&#J^2;N`G{J?KFD@i^8BEXQq3$Q#~shvw_cx5r%ZlgHz2&Y z*cU<9UD1(G6qg=Yx{LRix``xh^Yi7@j|r7hm00t{(0ei78ZQbt`JV={$XlXvX91YH zxbI<;-YQG@9xrY>Ar~yWklR>hQ-X6TUxD-S!;~b9lu;Tu@f59S=euifnkTO2C*G;S z@TJZ5{$VG<^ThBbq_74=9q9r7DxC6VBngr@olJ}~W87-NEagn(;M*)7Oj2!(TG+}U zsLu!TV4B7DH{}gtanAHawLkpH5_$jk$0~;0`rM1Hjkl;4D-KsjXTl<*z|E`_8Nlb6 zroi&vNu(socja8wZ}9J>;D}esqgs4BR?_u7ZyELz2k%GQjtG%Vx+yeS&QI*AK1Q~e z;1-8)WjT?WqB>et(n%42u5UPI+!F^B7Hx#oW{i;??}{9#vpvk}lwvHPB$=-+pnIAL zGBd3sTO%TRGFw?`Nh>DzU#VeO7C?`w!-QT4ZgBE!WsS1clJ&i=m$ zHn^;?BNx^_wESMCsSKfxi542WFvUJUh%GpT-JP-b+D|wh`H$h4?*AT6uKyK)=>%&^oOXr5Al10+ld z9x<66pEk?hlV|$s!otJ~_Kz3DcB~XFzWq<@HMwvNFc2}VQuS$6g{U$+nN4G0`E zua0)-H1D8k;mm6E{(!pNomCz*qxv$pI3NvG>(+Q4AcJvK#K8 zb9SOKS@GC!pN|JW#<}*37GFj>D1wi~_)k#-N5izNy0%(q7hMm?oL_Ju8jMFGA9bKb zv$!gbC9lC0>Unx?+*3GF(6ZZH<(4j|5-Om02Y2z2IG_&xn+2Z`6;N1An(~^lQwwUQ zOiKj)?fuj7EGlb8nv@wDs4us&o=Bt%l*TAhB{h=R+Pddpm83-ms{V0T&ofYt=D7dS=Kr=V{~wzR|1=j_+3Fh+3mcp0J6k#Z&$+yVt*OJ$s$BYK zRx!5u|IH#%N;9@dV#r@$o(;Dy3GBon{2-)SK+R!>`0yL(nq~lFeelQy_)_BZt2i}m z8rSXb0|MpaMQpG<_IaUCD@=+=`KtLmC}H1)-vV;8Y!fw&`K2B6oou$QOj%XL`Ye$dX*5~GV? zjoCc8{4m*B_lFn=K@#mp@(*Vga>;sjA3Ds|(a_aGGbuFi)9-z>)&hY^h=PM>jvvAt z$Q7Zfbr%lPeu2OFHW3uNyavs`ezAXnB`OuCGx+U1e%!gwF?S3T3XLaG+BzOfiLB-f zLsTI!R2nT{#3)Z+EHpqiKXE$CK-~2S!*Tvgi)l{*o7SZiuHQf&N=jK$gt6|+nF)`Gm z!Txq?dNfctW^}=z-436nDud8w974=Iuf~cqED93ykXqf1w8FZK9fiO>iyHhGH6`Xa zy99CYP)x3@)FSqPdVt-Br1$H%x6;EwpuBzZ?#_D^RUI0KPMzf^_Q2rPhK)0jFB8Xm zlV*;2seylEHqM|s4!E5>k-zx$17R0R2*LcwM(ea^%K>Rf92id$mc6SChy+Lhh?+zh zvO6({dx7GOFjsuW1#TIks9C3Y1NS^K;IL#Bmt5WRAnNcc>QhlO{Vj2vmon)s*asQd z33&IEDekAAXHibwHHW4Kjin6FB;UgbL))#+*%fRgjq!Uy)J$xt^A4P* z=wpGU$DPMXW)DL%DW!nu39E+G5tKB@YM$r#?rOf~PwEaIWOZ?-rZteokPGZsqWYS4;B z|0LjjIbp)2Q9#;HApIi0rAAv&MKYgXU3KhsoOYe|YT)zr{({<}EXL67@nFgE$g8n) zlwsHK7H3m?1l)9j7MVEeKIFU&$Urel=||l_I+%2%vpEWGJ4%Ae=4~9emV-GN((dey zu%{X&7)-JZ@$2L0Yqtni7;-H%fWs%8= z=kT2S6oOA<-_q!hTShh=6tYB`my{cf^+Lx>yzS~3hAy^=8Fn4^M9*a;F$7-pPb`5WTTi>BH<(hQt<2d>L}bEO@qeR~R5CV6M#}U~hOs$t?sI z7o&N-naKA!$TJ z>&^XTo(>zGjv|b*XTI$ut5?7&&KtRH*Xif1`>gBEp7*Joo(B{{&6%EYr?;2euFLC6 zyxINGDCvA&Z9Ke6+p?I9Q!BMcUI`b0h}(?yqWH@VsM zQOR!?^5j*fLK3_B=$34i3+r{u7IgD)M~W2q7y3L-307k;BupXtBuqlRxD3=-rhwa9 z?bS^@iS*Hnd^;p2cOp}nC~VDSN?;3$3z!yI^$)`1W?UAhtCjjqn>M&ph0;8EaiL{z zu|C4KQm1Ko&6~iXk*x&^ph_a+*qDsevtmcT;T0k>1Tvc@2_|YU#phijBjGm~(FAS> zlUlF>J!lV+cX^mbgNt|q+%c)}o#I2L8tL)BII4PpHABevx1oqq4Fk=enLf)lPJppehzt;iO9UQ2qK{ycJZ}25$Em8#QCj@IGeY)Ih;t1C_j5#Indn9> z?q%Mr*&t<`FGYDnXUw!Q9F(&(vc=j2NyA|}`{O%(aBk4&ic|F*CyG^zcJTh7Jbkku znj-MdZ0aPz3?=kXncCW=-<;dP;J9T1y-C;{aJj^)J(P2N6H-0wO?ZvS=U!GHKVCK< z=aWv?u%5>H&8MwXa49`eLmGW<%;nt}*#2=)K*`axE(dLvH|fGa6F34#8tRY?cr_y0 ze3Ys0rp;JgADiP65s|!r+v;Bhhv}`Vm{n>M24Hc%zOJ&UhG2A;(vSJbsM4>fU{u2_ z-6VIhEcV`qxROML_k8tmxBr)-{ z0Nki4Ka!>@`U^UZ)eJ*+dVEKh%hU52puWKbEG44AD>zWsBPQobQCa)OTlz41wS`U5 zA(_e!#MIkQ_D?<^L@2G~TpSiQGc{2i*D?M}9=ed6<%52)rPN_&_Zz}kJyQ*xrss+n z+*}R)Uzw_8MN}8>Nin$jkrHrz;R3n*HT*JD&M9fIRS?wRHq#A#i(f4q5+z;_5Ij)k z55fi>(u^$A=GCiS!o_k6hWVWf;@9>(C^LB-^lw%JYn+7v`}UC04jw=#dbI?>PxGb< z^hYM;a|^$Xv8HwRyEFBlC0EGDeVFD zsI=F15ChE=aHP6tL~Ao9#WHh`H@ZcicgWiJi5Wg12JkaFg6%fLuw^#2^+FGSBYJC) zcLQaBfXhJJeIf<*h>U>kVP9*cRCfKc<$@qO~wd*)<>-)SK6P zJ@I^4#us1Hf$yt#&=?VaIkhDY^^W;!&OFd#L5S3wEK(42b#OVRSI3Yn=DLC>djb3m zOx*FMX7ymI4;B56>=L7Cv?Opmx_j#kUAIX{b-S2c8Z$v=gOMvo?-ij^Qg7+-IsiMdRFM)v7G{O9O zb{zD!lmDA*H)}70ZFQ4xTkLM$F*jknM@CK!9fA;1rEyA1T;kT|rRhl7MQ@3Z8K3<$ zthbXo^c6w1sy3usEhrD|+wtJ{DqW>!SzzMAYG&n5P_48!FI7^!mt^UsJ=Ii%VFz|f zC`{_0n8zVxPB%8P&U9wpG3=awF3lq(pY)ZY+X0iPX>u?nXvOVKqHlZ!kPr!p?==9sB_~DS`Wz) z-C{l?ZU7>v`xhem*b=STWhZXwe7a@WUN>CeYu(sj2^yMe+X__p(O0XKfx z%AXEQxVFsfTzy)ozm#eCQhr*;4iF$jVCn@40VgXeH%1E z29UQ3y$aVZ3TOp-E~*g`Gz^slv`Lf|RO$MFBa@P)tKRuI=cc?XxIqzmXgmw~OWv_3 z79M~sk*g{jtNxD4ShkFGO@d3`N{)-(L`+B$P3o{T)|L%BE`c71nj=koezdtBY4~a%t^5r3-m!3Kj%V`9dB?v%w?BxOI$&~!jUNWa z@o8Q~I6n%f3*aDLLYK<|4FU2X@*``7jnlDRq5+VebLwb4vJVL_1XDYFTUc;$dW3relP0}p?81NZ&{!uRJU{&9)O%uEL4Mkts~ z&T=;)Kjl_c^Tc3YX*8y9Lb`*cpyU^wFHkn{Z--k1SA~|n0bO2_YwyEVv91paW(>>D z5A?fn$`0!!94mEWTUFmE5+yocu&wZDj;aE3+jOFJ95*T%`pKWaqKNiaixt!T^#`@p zHlA$6Fj^5&7!Hb19 zHyE9zQWe<12XmH)8IDIOtwPeM zHRd&LKn-qMRQRtyy5LYzR9#*8JDBD2K-E^^INa=#S{XA+rW5XKtg>7Nn^Of&Vhir! z+P>KycTUF|e~Hw_vAX%ap<+u9o9)jcAVaw~|4zkmS zZa8>nl~i|D8zjQ^%<{;ZR6cbVD>%?nlBzUD&(9h}VOpBkVW!AuVW!MGuz;OfTWE_| z{yi!0mE#74$DH%4$iv357s-5PS(g3aXJUS?=I-+Jz4Y{Czu2{VMepL1!wV0l8b0k) zSH~&|HJ~YYm{WKY&gKO*WNzB=l|JE3C?T`VIh$Fi$wHFx68QWYRy%ziF%z4Zc<{>B zjkGSyv*i{+F*O@tKQ!EDM%7xw!z{Yx)~Woo$kr{Z7+t7ve;X$MoE{R-LVe22TZY;% zOIFYRqSw}4;Mcno^z?O*G8Q`&wbgNV%>E*DX{fnqK*lP#K0dvcU3endLW%GugLOH< z>Y{oG#ECe$UPvO#$t@?@GA5JFE*6oY@?+$jRxnx(BiZ8q{AuRkwymR+;{*D6-bh*) z-5@PC8lo`?K**Ec9*n$U>OJRjK0H$J@vnMoQZa4ti zMegzJ2oft=1Y+aEG$4JE9{t_I{tH*SwKVixk$IyL|hvQq*qu&_4C6X zp>36)v+qAXl|OfXL8koN-RrhNjjA36)N;pjmTkOO>jg}c>35j<2gH)fb7QYv#8VV2-AXJ1-O{Vpi$uIz3lMp3dl`?Wwpp>|6_$}|ROmbQ- z+O3VID2pdMNR%dc(_#%+-P-%bNIb5Irk&d>rOY(_mq8%P;dkWuH0mR4vhl=r?rV5g z%=n2Yz2%@f5#I6!(KxF>D%1-3IyJU|VW-!(l$}cWBQtobb>#9D+>HlD>@kp+qgiCj zU_Y+2nP+9m^gw~vIRygs?R~aXBZ*Vk8cFZj_&b8(pTaY{Y}cTT z*fRuKeL3=89rk16#2TNQ%KL}Ryx)%5M0MHy=A(uL9M*f_;^wBL-FO~J+@|(7I)GQF zGxu8y$fzRDE)xoI0MCR3S^FKd3Mzir$&35HZu)9V$~5*Kk^r{%vt!7ISD#%fswRS1 z7x8ugQ&u(usOPXbN5Z5URhEFc|NLc;g}f4JzVjlUxu&$T#yH-Omy4s=$~b=B<)v}= z;R7RHY}oe#TExRVjM2_)jF*Q3%G{)3ZZqgSTa^}wnjk_InITrx)tW> zN_A5pLZ9CogVv`5^1_9Jm_n4I&Od-1kC6YSPp-Oxyt0!D zIplg&zC_?4NKvoQui_?BUY3EYOP5n0W0#hYf21a%4Fg1xeEs;w-CE2d_X6pd9A`2e zuiIRY)}Lqe0J(eXdpq{`UG}5w@h=I2qwDlnybY&n3-F)3(mWK*z~Y1=sqQ352UCF4 zQlI=T^y5Lp>gG~>1T94`()}Z4=w<|*zIWTL=+#(!PT$k6nPOoI-RVk#s?iWB=$tTc z;v`#9_oLoCy7W1j8Mn^hfr?}kDKcERb3jxH4>hafqve(?N%m6{o48;*Aj`VQb5)Ul zHK-31_Fm*+OH8EXSzh8{$7fljqN=ahTv<75(Rp-SR$Zz#EMGFOcXfT5%J^HHx8x@r zP2)nIWHes~>%OVy%4>O3(0{X?N*ukyQv5>kKb>M|32-D&p%1(V8j7s?3w|Lp63nOV z937ts^a~AioVI92W$?353}~XMK~{A}5JkKH5b=n9Ciq@IDBAB;Z!IUAV+ciiDvH*j zMD^3Dk+a${QM5$azio{#f^OHOx>LnJ+5kbRm4^N`5ii4(4>XD|b?3s1jrWv1Z}MFy zT9v+!?Ds9SiLUpcRnr?JG+C=^SKkC=BwXt~F8Tyir)=)czcAl$Z)2R5pR!H;e=OVl z8*}D=$~ONscK(|=^G~^sSitaqkw<2U?vov$hY7)fa=I8~62|7IuK10w(qZq9BnSjK zt$S9yI^QU{77(-&cteiu27n8-8*tNC&-dMPS#upD2hi$Q=J$O0#Os?xwTN{WtSzZC zp0+5nsTrDO-C3RykP7Y)6z8U{uiQ@973Pg|STBrbPO4R4VU>jA3ZJD%OK)mD`u%Bq zjUA|-$B9L(11X}nY*naJ%@8ESe`WsFWU8vR= z2;2}9@)$?_zbc_riw26%Kg!e8Kd<=z-OEDxpIr0*^LqcyFQ+uzy_6rD_)MF*+Au)L zK+sV!gc8RX!}1A93BeHY86igj>{s@tCS@2Inb@Wg|3Ir$G(TxPHZ`*>y-_zsskEEv zlcqu`YL%;Yn6XuOyEIg6vQ;HLymz>grb&Gw(*q#A5?6USh=@|D2=%(`I*cmsk7f^9^}}P? z?OW5EW$5ivagZURMyiQ!)dSTd0?Cq6Pu{r&OKRfiuu+&nj(M|bhppFk4ze_}sSz1;);PvKNiaE=q^G|5w^Vy2SN zBs0Xts91C^d0dq<=JmXesd8D;1K5UvF9?WTYl6d%lJqXxN`Pj}5LxPgSRE$%)Se9Nn;^;MLmXCiH$)23AiNRlj3 zB5S`@U11=y{xj(rqgS3zSUD^dhUILAwb|IZt>UN#gv=Rm63ig{MK*6HQPQQC{?1ODO*flB7}Q(AO3hFI}(g&O+0tS_v* zssss=fjAF6c7M%h{bJFcbm>-<=R>Xa4X{qGb3|a97zk+R8pO+p(k2^QM<;%(sz0y~ zRB?%#!Lct8vXEtAzqvF2#xo$NsieLB9TCSs^E_?X{@2BD7<@uv#vvJzQhJD^v3!dT zl|$vIA|g+p5nMz|Au5{UAyp|$2kfI)S~hhN0%yOnr(#(o-&bKg$Y+VeF{*sx3Du~N znZWwrE{QHx{GA?2J*uLTQ+AKA)Nbt+N2AXvftlF`pev3SOJ$4`MSDf=HiGkA5i0UO zd~$T7PLbVXMt2^U57wmD5}@X1U>&QO#B&jZ0J18_+exP+Z@5Me9xd0Jbq&L^e7(>X zNNZ(5fx4(0i?cEE=!j+2!b@EfJXIo&j};GwfS*019h#N=Yt|*|0J4`!D5 zN_q7;3^d-)FNmK&7&H^rwGK+yh}q{Hpt?|PFC?Fm#mlG5xknmlrQ>IgB05c3KF~=a zh6K*nAvP~CiOXlXY$wlxYQ8_)WN;>NeiQS5Mb-&Nuox?GER-8$-`li(QhmzUy}Keq zW@+_RPM`C|bx|r{2{VLpv4kQKehI>QOprT%3zknCxVb_F`5u!3W#trOn>06Z6D*XH z=M)M2!jWK4RGLfuttE%E2P@F6hVZljI&jmjn43^ zPJ~{D)br75_H1XB8(ej-Emk3-$#Qk8x9>hEB<9vjxJQ=EG&)&*v=3TD&pvVnxeR-) z?Lb+YlOky39f%jYERz8;%h7@zQH?O%8>!r^nUZ(>IPqq+lbCHA8Ax24#IZ@dwzGe_ zNr{+ocSoD-L2*Xdg%@t^OiJbgq#@1W&4(>T_SLJKpM5HrJSQaRRfbG&uyI9+T~>My zyWR{C12~~%bhg$$vJk%xRx<*^v~v)B^3%hV33i~-tUvA5Sfb|5i=rmc9n>)2!GqKa z^P&<_F>DtK$|77CJ5xuKX-Q%!OtxP3n%EsDQrn82M%6F*?l55XtzSVcMPQG0ZuQjl zmq*Ic&aackwk$S6PqbQ!TT;VJDSX~x&h0RoXfrD8&a{@qUZfVn6$ilU9V(GVzCpk^ zP$Zf;Ui%dnVGK2;ueF6kZ zFhW{mY7j^Tftei%owFtP`AO&4M?tOT( z;Htw$hS6rDA9#f<0l{2DA~U)NOfScqg!^m^q#5Caibizsnh)JfGIIAiSiC=S%J|_X-AWeS|ich7A5v3!>zaS0qG@+}6 zF+61ADkXR}zFbZ1mX?PdOp=@C9DI^|;2Tz^0qedK3>_4z?WYMY85qL(rt=Zq14q`G zmX)L~hGa0K_F1zeK5O`YjYkt&x-#C=rX%}-v%xC}Z95zssU#Mk{YR8Je z@U4Wha=tl!xo6aPg=VsfWT-Uw*s!bATd!Jrcam6JES#?b>09?3j3HtW9zjdZo{@vm z;Qsw!K~TU*LK!uvRJbS;OkNH2Wt%Y^x3I4&v!zodO!!r6#`%hm7yl~tBXG|sE%(t= zztYj^vC$ivB^+7S$l7s@do8-L_omu&g;hi4Q7^#p%DB);DAqKLC_yf{M--fbVCW4Q zpLSAJpyR=Jw|FpZ7!OY9&`o&H;FE5C-006%H7z?V^+c?EUl19l4m+%pxM%W-d$e~- zt(|&Ex@CFK^ihfbnmM|@OUuO+x=YOaa6Up`MZSv=z+ zj&v;Xfs>|(JoZyyf*n#2H&qEvkEBqz1th01TIY?cy1siJEZd%upf04|88q_e^UcqIJI$qO^tX{0Q=;ytn*d0;d>W zpbMg2hvsXQ_P18QOkwPq?4dM+V|(uRBPZ<<$bpw08v0vS$9$VUpbm=Fv(IMqMe~ij zM>0rOq>iZMoC}d%y?jB;97(AMLyv&6Zzi(5LIvB?<#Ywf0)mZ_~Rdangdl z&@8jcCHuwoEo63_;{rqY2HFx=n@YZylX9a} zl&P9Yv{)Lgc|b3Q1o2l|SANshLidoYfmF5?I`bsF`E$9kGP};}K?$qva#L^~CH` z!TFGfb4WF(Bq_ENC#V_OREgx>tR!Qa(Jg2?b%7g;M5AE-&>&(JHfZkcmN2s4eJeN!nCrcl9Way`gTk=o|nGo|BD1pGHLvB0ih$H-WM^@K##RBrgEQ`4$CSNzg z8QjInTy|bpvXE2PqeM9*$mGvZ!Ps7Fn?$@*V_0OIlsGq$7xq#m0A&oC)8WX5OB{I{& z&m4D92ULj=J&5P>4A>lRn(KPS@|aiq-&TfHnOC`uYpkgbZ!za!sgrKX&HmC&DR$Qw znLUwmqe#(ab!;OBsne)NG--Cm>qV#<+25uf(vCyt?AGIMoJse#4t}n3bFn42(girok)X zsLlF0m3f3uPV@^VjN3J zs7vW$dREOUH=t;vnxK-_6qp*ejG&zM*m*>v9wu&xniWe@+eJ-67VZtoVET-b0X5{6 zr(c*Y=7z@KB`=B#zMR8)M_(&sn@t?LtNkyD`lrk0nJapT+`Ued`PVEyOY{v7f2Alh zxP{mY>C3kmqt~@Sx9=weAH3PUD&9e;-4Z?DM%u2JrA~7?nOo3Fg!@?ilHRb~Q9Vh0 zS~k)vttP$Xy9A>{?$-j{oKIM^!~^qOk9nFfO9U;uX<{Z}MGPU&T0}pPw4d7EHF*^c z(1Qo888T#p5hW(|Q-(yg#r6vVzhg0gpd>56bb9oH0wu}%3M)p2fxFLEy>QG4R_-h8 zU+Al?!eBv?3%sHzLA?4>j0E@%7$S|RYf_S$ylY+ z4n%*ot_mG#p83HvVERPUjJRH!Ay-9T%yQe2biJr+b%|?XeE(`??bZyWEqp{h5`F<$ z|26&q>X&o$0crC>TI-zNN~}*w7-kFnefLs z2fQs{{%-wM-9ryBgJ*Iuv&{5yuKy+Eoc^si>??Jju|gyAn_Uf`ajXB1%g`EBtwiQ1 zx^awk%lc*V?-yf2mx&<2oHk?3d{TaxpMu&Sc>d+t2h>+*DNg;iw%P+Pbq56MHt1{8 zuC!j;1YlpBL2hXi-rks7|L=db0Mz7?nWiEF08stMZRP$Sn6!kAqm#as74d%`|J5u1 zZ`hY{-1iNNl z1=2bj@r1^~3~TeQTAAId%fY2ha|!FRU6VMpiAkkk@VViqVwhBxz8SBI0v70InyyD6 z3Bn|Jj3nVomoatTh{xa7jx;yvi_UnW_#l*M<|9E)rOc4j#iVycL>cKHTtp3#k-nKL z+7?|mS#aSINetxl?nE8)%Zyk>!C1k`<{`huyPwZD2`YbK4!99|Okznl56^r1}88nU&cpyn*~f zRP2FGaX0@#FpvKuii!WfqnQ6~#DBA2l_uoxjK6W&?wmdns)%IKg2?m;9KE4d3H+J4 z{P-@21_oU4WQ76zv4`7rf2c8VBqkLlTWX8sn;VP7*r9$|Zvr<123Vyh&st-dNnOt) zxtL4AjW-w3bde9fPrdt&)f0toUJ2&UdD?Duy5Ap7dEF=0V82i93p+Kxkri{*^!QAa z`)V#?MO?Egc}EaN?0rV`N9>*U}noU~6E-WouZiR;Mgh z;i}OVBurvrDpRj7!i%ICbMj)VT&(w5JB7dEWs8$MSfbZaa1D^jw$rlh41JSI!*+g5 zc`HjldKt~dEdKiq-t`OW#SHiFi#h4kU3|pR`S;CF5SvpIp|Cl8#>|qEO zL6o_yj`uN0$wSqXQfj)_qWIKrnS3$j-u8y`GrF8k5xy*m3E_xC>4xG+3@28lsi2dl zG->G?bNPxG)$u+RlKOK*4722EnDvKFTfCP}MVn#i1AP7T_HVVXeMTs4JO zpT_!OPG@)cEQ+es9a7Q~8ZJxuwg`RN6PqI_ZGrR{=g#vc28nWQy+I8dcb5dFR^-u; z&&P%sTVJJ;F`R;9s*$hDbF31St>mkHWdp=P*}5fF!x?lQhPw$TMi}e=#xDm^PWJok zBklIX+F!cN8)z!@No~Er@9ywmEwj?-&7I}xh?Aw0SPtK(3EQ+5LHqwwu+}k1p;#vH zrvh`dw3QgL-4@kIQ!Av--?{@#~s8|+dQ;(;Mo#ndpY6spn{3TJBv8{Ee0%vgX2)N zCCV1=Y(p9TH+hpYR^mG9QF6nF>tHb9wDPpXRlL7F+QvVV*IK(W=+D|wiR-*I;elS7 zY`O=x^{a5b-2CDtug6c%+y!Jb>;Y$1|5k+KbP-$ndnLz+PK~0IJ6_kenCmP!NG!nT z0oX@l4sD#DBU$@kjnc{sh4baeOf!mqY{x0?+@X-P%tFTkGt+fK8Xnl}SW!g#bX7&^ z+2;eo?q}&im*rirs}E*eubvzp8ZZ##(eDL0O^$sfaX!0;rmj^d#vG<0v5$vbadqkM z;c@S>jXq)Rz%lvuo_XtEk0U!0-X%0LG%_Oo&y;sC!y!Vzbv!1e%gjo7+E(!P5CXQg zglw~&%zv|GAITU4^EUXYL*ba5L|+fG{n2f#<$P`;XXQzw!rFG>1xIQtjYXPCx$0Tg z_y1H9*k8*NMu;cG(T9I5k|_z+!6-KvLctWLG?awCF`Wto6>5{_B*kX_J!#TlRfW|Q zTxT2;H#0}=YR;55U1N;$dTp5H%;k}GCmbbyfA00QK5!SnK;wWT_=y7G3YX(F_2ej zekKG-;-FFYlnsInfBS-ue-l(=JyzlnCV;dv+bFa!pd>$1xZyr37BgGGzr|0+^O~0j z15^}t&e-E6dU|#)QNVmuka5beLq1^$=n5hx6Mg@fLV!rjf(f07zjUyE!{MRr^$O81 z9c&-SdtEZ{pn(T}h6ZnUS7wPMBn?d!5HMe!BHRBbb05=@24O?2h_`+1 zSkky=Y6p<;hK&MFs_UV3Pi4-ZFlQ5qOdAaJ4>=1O04Q<~*!bCF?FPS~o{er4?b z@BAktYAQF=_~SF#TF%vAsN~HdgBetV+7Sn}tl<@KS7SOg0f&fC(;da%oL1YWSL+*m zGM#5P_te#*^#`lcd2E#Bzrd<*Ozyihcs6GM{UIN@;iOnS-MRs~qr?3IfIIow<-ibm z1axfeXk3WdOtrvL9~RrkL@RPE27Wm{vO5xg=Y{Si6xRMyB}nHWVL(7VUs(tiyCf+=eFX z^v*e{k1Tj6MkZdZ0LiaYY^zFpCUo+Dxx=bBlNeU*IS#VeeOAzI)Vt^$zh$j^EZMHM z**h+Kz~xZ6N@mz-#ETTbxO`K|Nr-N;@=2jQ#7ZgkFx(W;GWygjB|Jx@jU+qS`t!IrL_@Mh#X_TZx%@ z^4p_*L+-*ol_Bw(5gpCY^}j0qLkVl4eKqJivQEuSwK~_wQU=a?(Pr}B&EB% zySux)K|s1&x?55}O1is2>5>k~O$h(?yyyFj*W>Z~9|mI&_Fz2Mnsd!nbFSyU4NmP* zk_r34gxePNOJ$h6cykvyCw$qW0>}3|r&9U*AFcQWu@^Z90;YM#zVCO^+rx zNH@pXoqevqr|SqP@$wvXr8J@&d_JP>=uXmMSW8G@sN0shx}NXhJ^U;k3^P3*Y9*{X zT_){Q>`WUL%w79gi?=u4Dq=QB^rnC>Qexc!1mCKET58qi_4>ylhJterN@VVP&{9R} zf`VGjgzL=<92XlYXsi4V{!C1%tpasaKFas6LJV)K-=vfm;P_v(pq!FX4Y?&YsVKhO zR%%faHzRDbQ!M3E;64T2WnRzcuczPxKYjJ4E?oK+r6|}!&xa}zY4)CB2A?|sZ9Z0a z|7}5bo3I!eu5axh5J}j*49lzaa_Zc8rw3g>pdb(cSDK@($H8DyJ~4-_*`cwZ$s? ze5h6-?o%Yb`5-tXa|0?FF6Y2tk6?PhbB~VSfa6cTW01)6;9^4dE+jka44m<(+qOx| zS7+%A4{cV1vYAlL_6DE@7TAVxXLfPEJy)0APHnPc=nL6sYxCkc(#=FY#J=VU)@bgA z0_~_L;7&Dz1PtGWxfn&<4}Ma94p>_udw=f*7k4kv58VQ0lC!J^kehlmGtWV4Mi6UiYHz1L*lE`k@;g5_yK$-= zZtu<-NFGqxlm4JpB#T7g%Ex-iNmQO!&y7g$cHfwbO|=&7md}4l4Mn9|n24rEQ^>Ux zYO+gTedMAD(2~_1Q6k*FOpy38A*yn7gLcbXj?+s+U;2tl$BG4xn$@hHmfNzSfuA*V zDR8OI{FbT?yi6r34Q}@hSTAGKo2ggB19-#DmV2x|Zadz2|rHCQV8f=qYq3S-XQKr)V!L{fbjC(JB{i1oZ ziF#JsGKmxT>@0|5a3}*}b2#dWUIr!i`8n>4;r7E*)&qvB!SvEbZkC%_T$i>HF_iTK znSw(apn9nYdcK)KaXd!E__$?es}T}>(H*ztldjGo3~FxJOQHIwDEbA;V7L2u0y+iR zI z`Ta|+1SVzj1fro-ACvhOxw!`lkeVnt+5zUv+2Q>l6W3DEHS!?GkLeUc=jF=*DYi;4 zgAmXvqwtL98S&@oBP*(OL2;6Q!{jJ!x!SIzc(UKP=n25KVnzea3MJKb=3u8Cm>iLlc zo>?@$-95+WQf~)EAZt_5R=Kx&-+eesXf5(h%iWVsgV-k<5sR4Bt?SzA!_Si!Vs17{ z{6tvfF)5Sptk|88Zta~Yi^wNgFB3D>72<4rA$j}O^elvaJgTjo4ShF~YmiNpHeGbr zyKXGp)-!&Ibd!z^zbI+4QbF?)fGbwcwDyLFza9Z}=ghoEC1>_-5DRf*_-4`0`D_3% z-j$9^NUELnMfu|?&hgFGHu3n@;Oi!chfyGFC1tj zysM2L<;pVB&eZILeivP-DG6^E!_0P@Pv$*0)yMcNP8S ztipdgy#t~iDVyOeruzZb?;xzt0NZ53utk9^3ZvN}(iFQco`XI5+!2~Bt*g7s$UI9V zqTk}E=N|5KTZK~u!6+3ngR++0rc2UcL~b2^1ySOpH^5EkBa;19dk^IoLT_D(^eYV? zh)u!~KjQmm97L8GO!T6q$6zM-+4)P@I(QCal||#8B$YWzh+EnD6~{;lGD;KM(2Z~x zbfm^>#(c>3<`9QS(Mb$0_NoT37Om8`p*ft5u4+)-eY&scXqIdG8ph(=r%k3w~PVLOXd zvY%SJgzTUS)}20bSmIE#Ku2ArE#^+hFkz~5s)Jq}y~;DcyBxahE*PlD`+}A(u^rn<&8zczVDn%^A5dk-Vy_mr0qL*uM z+kH(G>dhnCDc>o`r?(AIs+^*rfe)ECTkV3CYD3Q#19fXQhe<>BD4P`WFJ{4fglrGp zMC#o(hLNzR_6BG%EOWFS0kBYlhLR^aX`ly0}L;y&ATq9Kgir+g(JSTR7eC^Kd70rtk@Qwh@u3M8?jc zvgkQ+ER2q@6iY?Es?2yUOPXy52HHmmw09OlCy8i1JSX$cFQ?Kz?WxLaD*;xXXdOZ= zBkjariS2=U=4{ztOD4WdLby%7@-N=%81G7r_onmAC}*~wh&dH`ElcXAaT1YCg!*3c zydPyIQxoLY1}B)t!AYV-sVm|=v@yqXQI~?W4Le?d1`+uZEGOQ|ee*VGf zrT|&74wW?}lFB{`V02N9RseY6=RHwR+vczuOFPU6KW$IutXl`cwNkIGa12qG zrJ%bP3TNk7J?}yS3x6XEWxoN1EKl;n-Jr)OR82@8A-lLcqJ0m!DhivFnJu)P!CIZozRj3Dupfu>UuxP6njtRWN0x(t)#GPjJ(W*QX;@KZebajIc;dm zCW~hL0jRsrD=aVq-P|3Oy{?-lW2lzd!ihrjVFr)oLbOS5oQOiE*S-!;?Lbx&bB@wB zIBCNkoH#5Y8I#5PlHx>EpLUEIfBnTV;pU3R%nfkZ z!YFhE-!>M@7lKEDX})s?nHWmd;*DDNM6GEm7PaY{ePtQ7vU*E6^Yo7t_xmKXg?pIw zLetbL($kGYR?TwDFJ{6?y@??DP->A;k*WI-u5h`r_Fj=a1?c8CaYv_fx+w3Y&sz)# z5l!Eerg8T>?FtY$ym)%@xf}a@V)bx@rCghzp-=;#(K|s@NOO*IZA)NzB23n8Oyp`N z6Y_)!pjq5GpOl;|9mspLVAjuk4Swf>dB>Z+oWGfksTiJHt6LL8{)`TN&}5mlo&S@f zn?k$j;4E88b8ms}U06xznINvR%znonws$*X0nXu~KR;D&0=; zq1MxLBj~1VFmZ3_rpJ&0B|edG0LL4z$TA%JtOE-~IHfCXompV+wy z8-&6rt-RaR;6BG2HZ5IoYkQ!W1K80!*5H1C5|T&@US7!VmLWU9nG%2IR0sf%g(q;p zir%R2#OCiM-FRbfu?u|_l)-Q7I{}F_K#B)nXF9wXSLm-9xO`&}clEL58GaMK6`1Uo zQKob~3zs=o{h-kD;27bhfCkdw{8=X?mD$rB(iIfJLV2z}Inma$btemM>{3VY_dH`c zRmH*W_;0{4Bi*0y!=kq3gCg}!KzsqQv(?<&2%Y|52_E_JZZE7axCF6;pWKz-h9;(1 zFEg|lBDp{TkLtU9pc8X{8!)$h;lT}wYiX`cFvH{sCC$IJ1nrkGsX1R-c54t zLc9jBHVaK(PZqQAK)*w|rQxaCi@4yDsR;BKp_0+QMY4^V@oQdty=y?g5jigp7$EqZ zjDUR~x@7qfAlguTFi<0JZx{E(?05$3ZrE!(`+7JwC(6-O)0zPfL-;9#k~GMZLtGy?nM#)>2+T`kNj ze-Cd%!Vd{3rx0cOIo+1L-plN7F!@)*0?vWum?{xsvwILKF<=UycOWzqNrt^1DAHo{ z&>l4+Ab^}}aY{#leq4;cq6#<-V$Ho7UKVZ81@Wh+CFOY)SxBEZUOMd5^n&4mJBI5y zhiL&%RP$EK=dU%dsx>v_%dKWSAnH{~OU>To6_twC8@+RTFwOV zjN#5sZh{G`WWFrn$+vV8xa_EdxGegTh$iG5fdf8|IkR2eF_u{^F!2%tv7EYty{ytY zfTzxF4)ngPoP_WTG|Fer08u&Q$%>o}_7yWw_VUke{^I-nDIPLL`#{~ep5)0hW*8ez z$=vvIc7ys0bTt^Z4cC$pSAr8jP+)*}S0n5;J4~41b{%cIM*fv_$1_a{7~CzEGF*%a zmo!~DyV(mH=a!>N6aTXY|l>8fd_G+w#(nF|q5jcLBA z13?#dl>PPCA}RNzqD6oVO(@OKym{I-Pa5JmLRwqW$FBiUBnL+P2)@~J(ec|s_sm!R2@$OKicGYN*2GqU(J&T z{Lqn)*=vxuAX1Gv0Dk!C`pCTtlDrGq_gKcHI?^jian>rS^UL?G0{-ilaNK#DTyw56 z{Mo5FbQ?Hew~5Kllovle5o!-n7?EA%~9 z%jQnBip8H@%a9KGo;gZW59-6s%P>_Y62@fk&z9tt_3vec<8wZNl}y-DPVJOG|Iin_ z626Fx(_8z21@R?Y6h3=m$wyZ(m0~u^gGm$C_>_E9bIWd}w}}Fi6`vO0&SEgSdVWB! z70oGSTwI5)%Dq)n3w0Upp_=|g;_;3OZw=}>WJUsdX*M=A4EsAwYD>0ZPrKc^Y`%(P zR4QJgyJNu4aNup&3279U6_ zdbsfLmw#jb+-(ai0SJf=$M4ESh--^XS307Zgwt`pJ8{}aNm%u@LRcdGx zw~H)F7#NIpX{7#kW5V(1H5 zz5AdL#5;!Xs~elu2h{fX{pR6_V=3+&^ruJ{iTx$`s^O_)RYD@?{ol+}(o43PDCFcy z>6@z&ig(9lnQ&Je#^YG*qG0nV5izc-nDi1Oya!vptC5L&xq!LbWas62!Jk9@Hgg$u zcf|NzytpAfC_?Eo)ZG&ywyD+)KyrtAk@F|5=o#Mda4t2W8yW1la)U@5zE9jn2t8L( zX81%5B2%>F4iIQQ*!=|^;t?PSN?@8gFwrSJ@S3$#y8xt&xUbuD-u=7}9#eLWR72-qTT@xu+BTcA6}iClYMq3D|3PS&w~_olnHK zbbUG}X3XIIUV2VpcbYSqR^lWK`E;G4pb|N_JYdhO-P9g;3Pq zx#XGZHE!5Xc?m~}&3$AbIXJZLI=xQV><&VT5CXbQ&*Kz10ue(bo$2A61QOcN*>`p;EOKRNXLPtn*{8w3F-Cleb(>;Dq;Q;C(4 zd?J7xq=(1C&}V+H(IjuWE!QWIPhSF^7YZk!fUfOIo+QzqwU^5k7P>3Y8U%-;?GA!O zHYcntF5ohIP^By2K2uO|W-gA~czK@O*61M(U{K*rXX`j+=FR!L5*bC z8%ZNoC}V;XL!Kpb>sP)JkSj_sf;rwMx2$<+g%bK77T7~8tSw-VD@GV=JA)2g5Hs@& zN(X^2sMAj;J;5fpbBvQ$s%Wr@mKo`t|+60qbQv%_fRc(1N8*2fDS zc~Y)?i3pyo`Y`?2GK=TmHMB1Sk?@)-KhzR}Oj=qWo(Ut-uUx}_lC%xNatZzBfmEBJ zSB2ILfPtS-VxP5RivoeD?|F1}MKFC}S2DXwe+>&i*)@^(pNc<0Ylm@t;ENoizkQkG z#jnpbKyf#qNVcsT*VPwT{GWW9AfDFmg(z^eN2;&JR3~wRYIg?8~`b z6w+Q}ETeZ#j>1Z?z5425VK$AnXI=J;)o?YW1AC@*n=7rc0xy8rmLo~Jcb!bgn3ceG zv1@S2g~rpP*}ia;hD~CRV%Kn2XA_Ux$o_4-22CZ*sM5r!eGy6Peeyw==5WHgAUBr! zfvRYibkq^Pj~pB0`BIi)Xx#xu3H)+%OM`sS+HY@3+2tFUh{#~*CgyA#2A6>lqfn z6S5O{6{Wk3D3`MS+HG^VfwulGBaN;h`#huNIg<4%zjQE;0edb^GBt_26eM9Eg~2<= z%x&8wNd;sz2J(b`T`Vn+b%GZu!pg_&@u44I_b|jc_M^Ast*GX% z~cER`C{E`DzN*%y4r>@ti4A$Le2~6EEK|BE&%nFopIQQ zN!-D9pX<=ija}?3M}Wur)SnR4!Q^=N{TZI>K-5OX+PuZ@ecEdP)O|3 z;Z49IgbEtgSJg(*(Aa^$Aoi=5ZV6^_E4HzP)mn?bbRzqSk-Q@}P! zU^@l7uS{R0FQ1#*uh%#!jP+VDBI7|deK+xz-o;cMwsFQa_N6oU`m|HL^uTLD=QXI? zqFiDND9*>fT!W9Zuh{5;R})jH-(6Au;dQ~kD`bIM)20??E{+DjC_(m7K9a=~L+3%m zmtNX7LSUw(wb78YdD4gQYKDwb0w6BK=Xyc%RRPAvWSvJs>w0h2R385!%w)PxhWr&M01bMie zx>a1ez2u_4;Q$qR#^a%(z`bD;W}PcbW;gZp$;XJ(jj16;20aY3xp5(V_)^EWM`}Gr zK#ADYB0DVWY&9JP_oH)FDL~K(Y0HNT%jo5+7MAC6`q*B*BqP)IfOA zSs1}p4ht#5?g87B?XYTl`HxLvWh($kg4e|Fz2Zvohr;hXR?n)(=s&V%ugp%$J_YTVFooJk<#&j9b704}aM+b!QM* zY2B{6NUDF@2GpzM?B-{6Ghg#rk|qw*Qr=FO%CA^HN`cxwni?*?^I8;o%^2I|#b!@H z!~kFZVrVLm*xR}zG$0!nJB)j{!+gufR3EieNl0$mvb9e%%PXc-huMH^XTw*p?1 zYyBDhW(uaF%N2hMyCTWakzvUi@hY_+R8p{u`b*vcrP^U z_*g|+yWK|d2olI`sQ^ThBwo*25*7;P@yH3tB(f9HU$-isz0RnuWHIEzUyNIb?n@Re zv$Du(b|ul3b3Fq0U>?6%DxBrqHZ@M!(Q9Sr<$XXSD&RZR=lmi8#WaVOpR03FJ!gJX7}xq)vi!L65L~h`COI7w7PQN!xMG^TmKZsOTAK%u z#7EYSymBa>Y&`4@Ffm&lxog|JGhG>BPx$u;Ig zhanra)@5TBV{@8(le)od=MZScTHK2=8cikHIuNW>^0PQLiQ-@U95r?P0sc?spnX8XB-Fwp8ZN9nk*gQNY==j2)0kCP> zDS3wH9LV%ani_3bU2|xy#zAU$rwL<`uAe~6y>{(&G8kQVUiZh>m`rur~bZ0XVL~QQ(q<_ClM)5o8+`+95hA?X0lOj&2f6?i%}xEm~y3R zZA1w3h^*;MJ*GFdRrP9o(a}EeSy$0MRB1H>ND#EI?o(ILX|D1yXsML7Jz;PiQelZ+ zp!i9t0BZQ}Y0c!zH|4A21GdDR7i)Cpg{XY}^=@lm1vWb9>y^p4F^Fj{5|XH~U(`1y zf0U&kUb4c0uQ(#`!MNRwE;%*DP}`saRhM}Q@8)WSInEKkDq_N)ih@A^4cDIuzpTR1 zg1^TRqQx;vVRq~}7XnA(a3&`_p-X}Rp+M!R82&a9yRuU2)qbcH!*(OuBG-ZxL$7^3 zk&b$I^~5I@OdQRRR`nvwa|Z8Ax*#R#RSH|9#$u7?>1oDhG*RHFDlwSr4bi&61QLwz zDLzl|vh{cbR+{+2Riced&uLkYy9`dK_ScE8u`N&ueqg2cUruA%=)P)#35CF58vwV> zIFPBlmMmvWShXzwjAC;X9Q9dnE`&F@@U8Utn=nx1ySEfLX(0((;LiiMhO*{o z332vyIVs;A+_1A?y(oW|?Fl2oUa(^_iON_+oYqiYgd}-iq2eyFl8e*2C7b|Q$7#)w zm1s2=sH^Fdv2u>d+BWU{?4KqFr-5CP>KbEH1xpYDVVij6M-c8AG=ym^@?d!I(P`9u z(W@77VDq{wy0<#R`)C@Tr;x*YPD61$^u=U&KnFrtLk+}c7XYQ}!}&%5t49-o8#I6j z8$BWc@|_PmISg)MZFq}`=(Tu&Y0*gn=!zUT%R6}HnzGC1I3zr#o#GHqMQG@>OzQj7okNAF z(psjhjkl6sE-6TI^GhnVg0K&Qnd~;28l$D{!$=pSZL9m)_hz5f__8{k;McQxsl7yL zoV4+ZL@DetHhsB+u&|Sr*#=j%+t!eitu!F$RMK>tLL_&GeKR_!oe^eQ=FnS3U9fs4 zI?FrCXlH>RT``+eW}G!(+Yec7JR&Y?WJi( zmoa%r*|6?kWI2MyMWFR&UR94W?=gsTJxJ}_*g_YkdUWL!owBrj-lX=Hx;)8+BIbFr zftcCqOWQ7{96mH7cGBrD==xgg7+$j^gyKT_a)O9QZ?{T>TX!jrkd>J#Cm|;2;tO2| z=43{SY5NJhTQKQ*&oeNy$u#WO!de&b$r+usOzH|f+vA&o_9PCcYXVad((7s>b=O!Z zxvTY)LL%1i&SDV@+C7(o`!I)3_ln}{m?q?=Y~@fKh>zj!lY5>N_O3$Ml2U5KPx+(7 zN0LYrf4JaN?NRvbXSVht{+PCc8`(XyfG??_f2D8e;jKH>`WI|T!;WbjqP9zrm*ZR7KW`bM%aMZ4>;lijsSslVlc+pT}&WfxFuQSMv0}uM1%mqJA$7GWa z6pIIode$f6LrBHlm1tMmunGE`=P4W`HIGYvT#t8kYINF0AA{{c=jGrCMA7YO`<&7m znPRW=3T+R(iyAEZD5LAgt+0a^)JQ95Y} zArV<65fxQBr;(Bl?f2HlYs0 ziGdJ%;O|#epl^W;RG_kRG@~>7OHhi=$l8MLJ1b@ZM>7{2pdviba?Qm47dPlXx4gn5 zAS((u#k2^#&-gl#^es}6f5-WyC+g41pS(8g(F7)M06uYiwe0*BfoQ)={+9!*<1+zM zpe4zFKtG#={Y zWh|VWfPQ@cp#n$BpCHi$Fq3A1NJ*f0`j5@bc=iX#zgcbujwXNJ%$8|Sv|Ql8_W^R* zf9Tq6-~sy2ga7Yw^MCDC&}KYbVj#*CIDmc}rk9j|j8g*IG1;2^%l?~tkPAUa! zoPSK-#rj{#|LUpVSk(V~Fn@15{M8crTjX;6d-DGbxPRIH@BK7?9A#=eKOijruWrUa zH|Ben#;-;|-(p?xH>CfwTj$T*@7>LQyk=br|G@pFquD<@LjKJ8-uCLNSK7B=k^Fbg zA3CS~4E^4B>8qpGw|FJ}1N48^U;fBn>u1XM)-XTrI(OM$QvTNt=KtpC^fUK+i;S=aQLge^)V~~G-zzMBoxuDS=O(|*`v;1gKX3c@GJ`*k za60qfF#ev4`Df+EpE=)Gb$=Bt{1(v`f5!Qj&icO6_{Yu)@%|;?4@$*8G>EADkeqE{m7WL`BO#91q`=2-V`_;N1uP(+}zs&l(<<*~)e?RN~b;0jj z5a;|l`5!F*{S5hjw(!SY+EDOI$ls&#chmVlGroU@`a19UEsRQj$M}a?NO>s;-~$;5 R2np~f1o-$>Q}y+){|A@R9n$~+ literal 0 HcmV?d00001 diff --git a/android/gradle/wrapper/gradle-wrapper.properties b/android/gradle/wrapper/gradle-wrapper.properties new file mode 100644 index 0000000..e3343bc --- /dev/null +++ b/android/gradle/wrapper/gradle-wrapper.properties @@ -0,0 +1,9 @@ +distributionBase=GRADLE_USER_HOME +distributionPath=wrapper/dists +distributionUrl=https\://services.gradle.org/distributions/gradle-8.11.1-bin.zip +networkTimeout=10000 +retries=0 +retryBackOffMs=500 +validateDistributionUrl=true +zipStoreBase=GRADLE_USER_HOME +zipStorePath=wrapper/dists diff --git a/android/gradlew b/android/gradlew new file mode 100644 index 0000000..b9bb139 --- /dev/null +++ b/android/gradlew @@ -0,0 +1,248 @@ +#!/bin/sh + +# +# Copyright © 2015 the original authors. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# SPDX-License-Identifier: Apache-2.0 +# + +############################################################################## +# +# Gradle start up script for POSIX generated by Gradle. +# +# Important for running: +# +# (1) You need a POSIX-compliant shell to run this script. If your /bin/sh is +# noncompliant, but you have some other compliant shell such as ksh or +# bash, then to run this script, type that shell name before the whole +# command line, like: +# +# ksh Gradle +# +# Busybox and similar reduced shells will NOT work, because this script +# requires all of these POSIX shell features: +# * functions; +# * expansions «$var», «${var}», «${var:-default}», «${var+SET}», +# «${var#prefix}», «${var%suffix}», and «$( cmd )»; +# * compound commands having a testable exit status, especially «case»; +# * various built-in commands including «command», «set», and «ulimit». +# +# Important for patching: +# +# (2) This script targets any POSIX shell, so it avoids extensions provided +# by Bash, Ksh, etc; in particular arrays are avoided. +# +# The "traditional" practice of packing multiple parameters into a +# space-separated string is a well documented source of bugs and security +# problems, so this is (mostly) avoided, by progressively accumulating +# options in "$@", and eventually passing that to Java. +# +# Where the inherited environment variables (DEFAULT_JVM_OPTS, JAVA_OPTS, +# and GRADLE_OPTS) rely on word-splitting, this is performed explicitly; +# see the in-line comments for details. +# +# There are tweaks for specific operating systems such as AIX, CygWin, +# Darwin, MinGW, and NonStop. +# +# (3) This script is generated from the Groovy template +# https://github.com/gradle/gradle/blob/3d91ce3b8caaf77ad09f381f43615b715b53f72c/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt +# within the Gradle project. +# +# You can find Gradle at https://github.com/gradle/gradle/. +# +############################################################################## + +# Attempt to set APP_HOME + +# Resolve links: $0 may be a link +app_path=$0 + +# Need this for daisy-chained symlinks. +while + APP_HOME=${app_path%"${app_path##*/}"} # leaves a trailing /; empty if no leading path + [ -h "$app_path" ] +do + ls=$( ls -ld "$app_path" ) + link=${ls#*' -> '} + case $link in #( + /*) app_path=$link ;; #( + *) app_path=$APP_HOME$link ;; + esac +done + +# This is normally unused +# shellcheck disable=SC2034 +APP_BASE_NAME=${0##*/} +# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036) +APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s\n' "$PWD" ) || exit + +# Use the maximum available, or set MAX_FD != -1 to use that value. +MAX_FD=maximum + +warn () { + echo "$*" +} >&2 + +die () { + echo + echo "$*" + echo + exit 1 +} >&2 + +# OS specific support (must be 'true' or 'false'). +cygwin=false +msys=false +darwin=false +nonstop=false +case "$( uname )" in #( + CYGWIN* ) cygwin=true ;; #( + Darwin* ) darwin=true ;; #( + MSYS* | MINGW* ) msys=true ;; #( + NONSTOP* ) nonstop=true ;; +esac + + + +# Determine the Java command to use to start the JVM. +if [ -n "$JAVA_HOME" ] ; then + if [ -x "$JAVA_HOME/jre/sh/java" ] ; then + # IBM's JDK on AIX uses strange locations for the executables + JAVACMD=$JAVA_HOME/jre/sh/java + else + JAVACMD=$JAVA_HOME/bin/java + fi + if [ ! -x "$JAVACMD" ] ; then + die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME + +Please set the JAVA_HOME variable in your environment to match the +location of your Java installation." + fi +else + JAVACMD=java + if ! command -v java >/dev/null 2>&1 + then + die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. + +Please set the JAVA_HOME variable in your environment to match the +location of your Java installation." + fi +fi + +# Increase the maximum file descriptors if we can. +if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then + case $MAX_FD in #( + max*) + # In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked. + # shellcheck disable=SC2039,SC3045 + MAX_FD=$( ulimit -H -n ) || + warn "Could not query maximum file descriptor limit" + esac + case $MAX_FD in #( + '' | soft) :;; #( + *) + # In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked. + # shellcheck disable=SC2039,SC3045 + ulimit -n "$MAX_FD" || + warn "Could not set maximum file descriptor limit to $MAX_FD" + esac +fi + +# Collect all arguments for the java command, stacking in reverse order: +# * args from the command line +# * the main class name +# * -classpath +# * -D...appname settings +# * --module-path (only if needed) +# * DEFAULT_JVM_OPTS, JAVA_OPTS, and GRADLE_OPTS environment variables. + +# For Cygwin or MSYS, switch paths to Windows format before running java +if "$cygwin" || "$msys" ; then + APP_HOME=$( cygpath --path --mixed "$APP_HOME" ) + + JAVACMD=$( cygpath --unix "$JAVACMD" ) + + # Now convert the arguments - kludge to limit ourselves to /bin/sh + for arg do + if + case $arg in #( + -*) false ;; # don't mess with options #( + /?*) t=${arg#/} t=/${t%%/*} # looks like a POSIX filepath + [ -e "$t" ] ;; #( + *) false ;; + esac + then + arg=$( cygpath --path --ignore --mixed "$arg" ) + fi + # Roll the args list around exactly as many times as the number of + # args, so each arg winds up back in the position where it started, but + # possibly modified. + # + # NB: a `for` loop captures its iteration list before it begins, so + # changing the positional parameters here affects neither the number of + # iterations, nor the values presented in `arg`. + shift # remove old arg + set -- "$@" "$arg" # push replacement arg + done +fi + + +# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"' + +# Collect all arguments for the java command: +# * DEFAULT_JVM_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments, +# and any embedded shellness will be escaped. +# * For example: A user cannot expect ${Hostname} to be expanded, as it is an environment variable and will be +# treated as '${Hostname}' itself on the command line. + +set -- \ + "-Dorg.gradle.appname=$APP_BASE_NAME" \ + -jar "$APP_HOME/gradle/wrapper/gradle-wrapper.jar" \ + "$@" + +# Stop when "xargs" is not available. +if ! command -v xargs >/dev/null 2>&1 +then + die "xargs is not available" +fi + +# Use "xargs" to parse quoted args. +# +# With -n1 it outputs one arg per line, with the quotes and backslashes removed. +# +# In Bash we could simply go: +# +# readarray ARGS < <( xargs -n1 <<<"$var" ) && +# set -- "${ARGS[@]}" "$@" +# +# but POSIX shell has neither arrays nor command substitution, so instead we +# post-process each arg (as a line of input to sed) to backslash-escape any +# character that might be a shell metacharacter, then use eval to reverse +# that process (while maintaining the separation between arguments), and wrap +# the whole thing up as a single "set" statement. +# +# This will of course break if any of these variables contains a newline or +# an unmatched quote. +# + +eval "set -- $( + printf '%s\n' "$DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS" | + xargs -n1 | + sed ' s~[^-[:alnum:]+,./:=@_]~\\&~g; ' | + tr '\n' ' ' + )" '"$@"' + +exec "$JAVACMD" "$@" diff --git a/android/gradlew.bat b/android/gradlew.bat new file mode 100644 index 0000000..24c62d5 --- /dev/null +++ b/android/gradlew.bat @@ -0,0 +1,82 @@ +@rem +@rem Copyright 2015 the original author or authors. +@rem +@rem Licensed under the Apache License, Version 2.0 (the "License"); +@rem you may not use this file except in compliance with the License. +@rem You may obtain a copy of the License at +@rem +@rem https://www.apache.org/licenses/LICENSE-2.0 +@rem +@rem Unless required by applicable law or agreed to in writing, software +@rem distributed under the License is distributed on an "AS IS" BASIS, +@rem WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +@rem See the License for the specific language governing permissions and +@rem limitations under the License. +@rem +@rem SPDX-License-Identifier: Apache-2.0 +@rem + +@if "%DEBUG%"=="" @echo off +@rem ########################################################################## +@rem +@rem Gradle startup script for Windows +@rem +@rem ########################################################################## + +@rem Set local scope for the variables, and ensure extensions are enabled +setlocal EnableExtensions + +set DIRNAME=%~dp0 +if "%DIRNAME%"=="" set DIRNAME=. +@rem This is normally unused +set APP_BASE_NAME=%~n0 +set APP_HOME=%DIRNAME% + +@rem Resolve any "." and ".." in APP_HOME to make it shorter. +for %%i in ("%APP_HOME%") do set APP_HOME=%%~fi + +@rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +set DEFAULT_JVM_OPTS="-Xmx64m" "-Xms64m" + +@rem Find java.exe +if defined JAVA_HOME goto findJavaFromJavaHome + +set JAVA_EXE=java.exe +%JAVA_EXE% -version >NUL 2>&1 +if %ERRORLEVEL% equ 0 goto execute + +echo. 1>&2 +echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 + +"%COMSPEC%" /c exit 1 + +:findJavaFromJavaHome +set JAVA_HOME=%JAVA_HOME:"=% +set JAVA_EXE=%JAVA_HOME%/bin/java.exe + +if exist "%JAVA_EXE%" goto execute + +echo. 1>&2 +echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 + +"%COMSPEC%" /c exit 1 + +:execute +@rem Setup the command line + + + +@rem Execute Gradle +@rem endlocal doesn't take effect until after the line is parsed and variables are expanded +@rem which allows us to clear the local environment before executing the java command +endlocal & "%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -jar "%APP_HOME%\gradle\wrapper\gradle-wrapper.jar" %* & call :exitWithErrorLevel + +:exitWithErrorLevel +@rem Use "%COMSPEC%" /c exit to allow operators to work properly in scripts +"%COMSPEC%" /c exit %ERRORLEVEL% diff --git a/android/lwc-android/build.gradle.kts b/android/lwc-android/build.gradle.kts new file mode 100644 index 0000000..62e6e54 --- /dev/null +++ b/android/lwc-android/build.gradle.kts @@ -0,0 +1,31 @@ +plugins { + id("com.android.library") + id("org.jetbrains.kotlin.android") +} + +android { + namespace = "com.opencoredev.loginwithchatgpt.android" + compileSdk = 36 + + defaultConfig { + minSdk = 24 + } + + compileOptions { + sourceCompatibility = JavaVersion.VERSION_17 + targetCompatibility = JavaVersion.VERSION_17 + } +} + +kotlin { + jvmToolchain(17) +} + +dependencies { + api(project(":lwc-core")) + implementation("org.jetbrains.kotlinx:kotlinx-coroutines-android:1.9.0") + implementation("org.jetbrains.kotlinx:kotlinx-serialization-json:1.7.3") + implementation("androidx.security:security-crypto:1.1.0-alpha06") + implementation("androidx.browser:browser:1.8.0") + implementation("androidx.core:core-ktx:1.13.1") +} diff --git a/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/KeystoreTokenStore.kt b/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/KeystoreTokenStore.kt new file mode 100644 index 0000000..e71e6b9 --- /dev/null +++ b/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/KeystoreTokenStore.kt @@ -0,0 +1,54 @@ +package com.opencoredev.loginwithchatgpt.android + +import android.content.Context +import androidx.security.crypto.EncryptedSharedPreferences +import androidx.security.crypto.MasterKey +import com.opencoredev.loginwithchatgpt.ChatGPTTokens +import com.opencoredev.loginwithchatgpt.TokenStore +import kotlinx.coroutines.Dispatchers +import kotlinx.coroutines.withContext +import kotlinx.serialization.decodeFromString +import kotlinx.serialization.encodeToString +import kotlinx.serialization.json.Json + +/** + * [TokenStore] backed by Android-Keystore-encrypted SharedPreferences. The user's + * ChatGPT access/refresh tokens are encrypted at rest; the master key lives in the + * hardware-backed Keystore and never leaves it. + */ +class KeystoreTokenStore( + context: Context, + private val fileName: String = "lwc_tokens", +) : TokenStore { + private val appContext = context.applicationContext + private val json = Json { ignoreUnknownKeys = true } + + private val prefs by lazy { + val masterKey = MasterKey.Builder(appContext) + .setKeyScheme(MasterKey.KeyScheme.AES256_GCM) + .build() + EncryptedSharedPreferences.create( + appContext, + fileName, + masterKey, + EncryptedSharedPreferences.PrefKeyEncryptionScheme.AES256_SIV, + EncryptedSharedPreferences.PrefValueEncryptionScheme.AES256_GCM, + ) + } + + override suspend fun load(): ChatGPTTokens? = withContext(Dispatchers.IO) { + prefs.getString(KEY, null)?.let { runCatching { json.decodeFromString(it) }.getOrNull() } + } + + override suspend fun save(tokens: ChatGPTTokens): Unit = withContext(Dispatchers.IO) { + prefs.edit().putString(KEY, json.encodeToString(tokens)).apply() + } + + override suspend fun clear(): Unit = withContext(Dispatchers.IO) { + prefs.edit().remove(KEY).apply() + } + + private companion object { + const val KEY = "tokens" + } +} diff --git a/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/LoginWithChatGPT.kt b/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/LoginWithChatGPT.kt new file mode 100644 index 0000000..fc56e64 --- /dev/null +++ b/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/LoginWithChatGPT.kt @@ -0,0 +1,87 @@ +package com.opencoredev.loginwithchatgpt.android + +import android.content.Context +import com.opencoredev.loginwithchatgpt.ChatGPTConfig +import com.opencoredev.loginwithchatgpt.ChatGPTUser +import com.opencoredev.loginwithchatgpt.CodexAuth +import com.opencoredev.loginwithchatgpt.CodexResponsesOptions +import com.opencoredev.loginwithchatgpt.DeviceCode +import com.opencoredev.loginwithchatgpt.DevicePollResult +import com.opencoredev.loginwithchatgpt.LoginStatus +import com.opencoredev.loginwithchatgpt.ResolvedConfig +import com.opencoredev.loginwithchatgpt.TokenStore +import com.opencoredev.loginwithchatgpt.codexResponses +import com.opencoredev.loginwithchatgpt.ensureFreshTokens +import com.opencoredev.loginwithchatgpt.exchangeDeviceAuthorization +import com.opencoredev.loginwithchatgpt.listCodexModels +import com.opencoredev.loginwithchatgpt.parseUser +import com.opencoredev.loginwithchatgpt.pollDeviceCode +import com.opencoredev.loginwithchatgpt.requestDeviceCode +import com.opencoredev.loginwithchatgpt.resolveConfig +import kotlinx.coroutines.flow.Flow +import kotlinx.serialization.json.JsonObject + +/** + * The on-device facade: wires the pure-Kotlin engine to a Keystore-backed token + * store and a Custom Tab launcher. One instance owns a signed-in ChatGPT session. + * + * Typical flow: + * ``` + * val lwc = LoginWithChatGPT(context) + * val device = lwc.startDeviceLogin() + * lwc.openVerification(device) // user enters device.userCode + * while (lwc.poll(device) is DevicePollResult.Pending) delay(device.interval * 1000L) + * lwc.chat(buildJsonObject { put("model", "gpt-5.5"); put("input", "Hi") }).collect { print(it) } + * ``` + */ +class LoginWithChatGPT( + context: Context, + config: ChatGPTConfig = ChatGPTConfig(), + private val store: TokenStore = KeystoreTokenStore(context), +) { + private val appContext = context.applicationContext + private val resolved: ResolvedConfig = resolveConfig(config) + + /** Coarse status derived from stored credentials. */ + suspend fun status(): LoginStatus { + val tokens = store.load() ?: return LoginStatus.UNAUTHENTICATED + return if (tokens.accessToken.isNotEmpty()) LoginStatus.AUTHENTICATED else LoginStatus.UNAUTHENTICATED + } + + /** The signed-in user's public profile, or null if signed out. */ + suspend fun currentUser(): ChatGPTUser? = store.load()?.let { parseUser(it.idToken) } + + /** Starts a device login; show [DeviceCode.userCode] and send the user to verify. */ + suspend fun startDeviceLogin(): DeviceCode = requestDeviceCode(resolved) + + /** Opens the verification page in a Custom Tab. */ + fun openVerification(device: DeviceCode) = VerificationLauncher.open(appContext, device.verificationUrl) + + /** Polls once. On authorization, exchanges + persists tokens and returns Authorized. */ + suspend fun poll(device: DeviceCode): DevicePollResult { + val result = pollDeviceCode(resolved, device) + if (result is DevicePollResult.Authorized) { + store.save(exchangeDeviceAuthorization(resolved, result)) + } + return result + } + + /** Clears stored credentials. */ + suspend fun logout() = store.clear() + + /** The account's currently available Codex model slugs. */ + suspend fun models(): List = listCodexModels(resolved, freshAuth()) + + /** Streams a Codex `/responses` completion as assistant-text deltas. */ + fun chat(body: JsonObject, options: CodexResponsesOptions = CodexResponsesOptions()): Flow = + codexResponses(resolved, getAuth = { freshAuth() }, body = body, options = options) + + /** Refreshes tokens if needed (persisting the result) and returns request auth. */ + private suspend fun freshAuth(): CodexAuth { + val tokens = ensureFreshTokens(resolved, store.load(), onRefresh = { store.save(it) }) + return CodexAuth( + accessToken = tokens.accessToken, + accountId = tokens.accountId ?: error("No ChatGPT account id available; sign in again."), + ) + } +} diff --git a/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/VerificationLauncher.kt b/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/VerificationLauncher.kt new file mode 100644 index 0000000..2030b5a --- /dev/null +++ b/android/lwc-android/src/main/kotlin/com/opencoredev/loginwithchatgpt/android/VerificationLauncher.kt @@ -0,0 +1,15 @@ +package com.opencoredev.loginwithchatgpt.android + +import android.content.Context +import android.net.Uri +import androidx.browser.customtabs.CustomTabsIntent + +/** Opens OpenAI's device-verification page in a Custom Tab (falls back to the browser). */ +object VerificationLauncher { + fun open(context: Context, url: String) { + CustomTabsIntent.Builder() + .setShowTitle(true) + .build() + .launchUrl(context, Uri.parse(url)) + } +} diff --git a/android/lwc-core/README.md b/android/lwc-core/README.md new file mode 100644 index 0000000..0409d4f --- /dev/null +++ b/android/lwc-core/README.md @@ -0,0 +1,53 @@ +# lwc-core + +Pure-Kotlin/JVM engine for **Login with ChatGPT** on Android — a port of the +TypeScript `@opencoredev/loginwithchatgpt-core` package. No Android dependencies, +so it runs on the JVM (and is unit-testable without a device). The `lwc-android` +module layers Keystore-backed token storage and a Custom Tab launcher on top. + +It lets an app sign a user in with **their own** ChatGPT subscription (Free/Plus/Pro) +via OpenAI's device-code OAuth flow, then call Codex models billed to that user — +the developer supplies no OpenAI API key. + +## What it does + +- **Device login** — `requestDeviceCode` → show the code → `pollDeviceCode` / + `waitForDeviceTokens` → tokens. No redirect URI or localhost listener needed, + which is what makes it work on mobile. +- **Token lifecycle** — `ensureFreshTokens` refreshes on expiry; `parseUser` + reads the public profile (email, name, plan) from the id token. +- **Model calls** — `codexResponses(...)` returns a `Flow` of streamed + assistant text; `listCodexModels(...)` returns the account's available models. + +## Quick start (JVM) + +```kotlin +val config = resolveConfig() // Codex defaults; every field overridable +val device = requestDeviceCode(config) +println("Open ${device.verificationUrl} and enter ${device.userCode}") +val tokens = waitForDeviceTokens(config, device) // blocks until authorized + +val auth = CodexAuth(tokens.accessToken, tokens.accountId!!) +codexResponses(config, getAuth = { auth }, body = buildJsonObject { + put("model", "gpt-5.5") + put("input", "Say hello.") +}).collect { print(it) } +``` + +Run the end-to-end spike against a real account: + +```bash +gradle :lwc-core:run --args="Say hello in one short sentence." +``` + +## Security / trust boundary + +Unlike the web SDK — where tokens stay on a server behind a proxy — this is an +**on-device** design. The user's `accessToken`/`refreshToken` live on their phone. +That is the same trust model as the Codex CLI and any "stay signed in" app: protect +them at rest. `lwc-android`'s `KeystoreTokenStore` does this with +Android-Keystore-backed `EncryptedSharedPreferences`. Never log tokens; only +`ChatGPTUser` (account id, email, name, plan) is safe to surface in the UI. + +This rides OpenAI's unofficial Codex OAuth client, so it could break if OpenAI +changes an endpoint — every URL/id is overridable via `ChatGPTConfig` to soften that. diff --git a/android/lwc-core/build.gradle.kts b/android/lwc-core/build.gradle.kts new file mode 100644 index 0000000..152ec80 --- /dev/null +++ b/android/lwc-core/build.gradle.kts @@ -0,0 +1,33 @@ +plugins { + // Versions are declared once in the root build (apply false). + kotlin("jvm") + kotlin("plugin.serialization") + application +} + +group = "com.opencoredev.loginwithchatgpt" +version = "0.1.0" + +dependencies { + // These types appear in the public API (OkHttpClient in config, Flow + // from codexResponses, JsonObject in params), so expose them transitively. + api("com.squareup.okhttp3:okhttp:4.12.0") + api("org.jetbrains.kotlinx:kotlinx-serialization-json:1.7.3") + api("org.jetbrains.kotlinx:kotlinx-coroutines-core:1.9.0") + + testImplementation(kotlin("test")) + testImplementation("org.jetbrains.kotlinx:kotlinx-coroutines-test:1.9.0") +} + +kotlin { + jvmToolchain(17) +} + +tasks.test { + useJUnitPlatform() +} + +application { + // Stage 0 spike entrypoint: `gradle :lwc-core:run` + mainClass.set("com.opencoredev.loginwithchatgpt.SpikeKt") +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/CodexTransport.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/CodexTransport.kt new file mode 100644 index 0000000..e84bc00 --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/CodexTransport.kt @@ -0,0 +1,275 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.coroutines.Dispatchers +import kotlinx.coroutines.flow.Flow +import kotlinx.coroutines.flow.flow +import kotlinx.coroutines.flow.flowOn +import kotlinx.serialization.json.Json +import kotlinx.serialization.json.JsonArray +import kotlinx.serialization.json.JsonElement +import kotlinx.serialization.json.JsonObject +import kotlinx.serialization.json.JsonPrimitive +import kotlinx.serialization.json.addJsonObject +import kotlinx.serialization.json.buildJsonObject +import kotlinx.serialization.json.contentOrNull +import kotlinx.serialization.json.jsonObject +import kotlinx.serialization.json.jsonPrimitive +import kotlinx.serialization.json.put +import kotlinx.serialization.json.putJsonArray +import okhttp3.HttpUrl.Companion.toHttpUrl +import okhttp3.MediaType.Companion.toMediaType +import okhttp3.Request +import okhttp3.RequestBody.Companion.toRequestBody + +/** Auth material required to call the Codex responses API. */ +data class CodexAuth(val accessToken: String, val accountId: String) + +/** Options controlling the shape of a `/responses` request. */ +data class CodexResponsesOptions( + val instructions: String? = null, + /** Reasoning effort. Defaults to `medium`. */ + val reasoningEffort: String? = null, + /** Reasoning summary mode. Defaults to `auto`. */ + val reasoningSummary: String? = null, + /** Text verbosity. Defaults to `medium`. */ + val textVerbosity: String? = null, + /** Default service tier, e.g. `fast` for eligible GPT-5.5/5.4 sessions. */ + val serviceTier: String? = null, +) + +private val json = Json { ignoreUnknownKeys = true } +private val jsonMedia = "application/json".toMediaType() + +/** + * Builds a `/responses` request body for a single user text prompt. The Codex + * backend requires `input` to be a **list** of message items (a bare string is + * rejected with `400 {"detail":"Input must be a list"}`), so wrap the text in the + * Responses-API `input_text` message shape. + */ +fun textPromptBody(model: String, prompt: String): JsonObject = buildJsonObject { + put("model", model) + putJsonArray("input") { + addJsonObject { + put("type", "message") + put("role", "user") + putJsonArray("content") { + addJsonObject { + put("type", "input_text") + put("text", prompt) + } + } + } + } +} + +/** + * Adapts a standard OpenAI responses payload for the ChatGPT-backed Codex + * endpoint, which runs **stateless** (`store: false`). Omitting any of these + * yields a stream with no assistant text: + * + * - `reasoning` must be configured (Codex models always reason). + * - `include` must request `reasoning.encrypted_content`. + * - input items must not carry server-side ids, and `item_reference` items are removed. + * - `max_output_tokens` / `max_completion_tokens` are rejected. + * + * Caller-provided values win over the defaults. Ported from `codex-transport.ts`. + */ +fun normalizeResponsesBody(body: JsonObject, options: CodexResponsesOptions = CodexResponsesOptions()): JsonObject { + val out = LinkedHashMap(body) + + if ((out["instructions"] as? JsonPrimitive)?.isString != true) { + out["instructions"] = JsonPrimitive(options.instructions ?: Constants.DEFAULT_CODEX_INSTRUCTIONS) + } + + // The ChatGPT backend requires stateless operation. + out["store"] = JsonPrimitive(false) + + // Reasoning is required; keep any caller-provided fields on top of the defaults. + val existingReasoning = out["reasoning"] as? JsonObject + out["reasoning"] = buildJsonObject { + put("effort", options.reasoningEffort ?: "medium") + put("summary", options.reasoningSummary ?: "auto") + existingReasoning?.forEach { (k, v) -> put(k, v) } + } + + val existingText = out["text"] as? JsonObject + out["text"] = buildJsonObject { + put("verbosity", options.textVerbosity ?: "medium") + existingText?.forEach { (k, v) -> put(k, v) } + } + + if ((out["service_tier"] as? JsonPrimitive)?.isString != true && options.serviceTier != null) { + out["service_tier"] = JsonPrimitive(options.serviceTier) + } + + // Ensure encrypted reasoning content is included. + val include = LinkedHashSet() + (out["include"] as? JsonArray)?.forEach { el -> + (el as? JsonPrimitive)?.takeIf { it.isString }?.let { include.add(it.content) } + } + include.add(Constants.REASONING_ENCRYPTED_CONTENT) + out["include"] = JsonArray(include.map { JsonPrimitive(it) }) + + (out["input"] as? JsonArray)?.let { out["input"] = filterCodexInput(it) } + + out.remove("max_output_tokens") + out.remove("max_completion_tokens") + return JsonObject(out) +} + +/** + * Strips server-side ids from input items and removes `item_reference` entries, + * which the stateless Codex API does not accept. + */ +fun filterCodexInput(input: JsonArray): JsonArray = + JsonArray( + input + .filter { !(it is JsonObject && (it["type"] as? JsonPrimitive)?.contentOrNull == "item_reference") } + .map { item -> + if (item is JsonObject && item.containsKey("id")) { + JsonObject(item.filterKeys { it != "id" }) + } else { + item + } + }, + ) + +/** + * Maps an incoming URL onto the Codex base URL, tolerating both absolute URLs and + * bare paths, and stripping a redundant `/v1` segment. + */ +fun resolveTargetUrl(input: String, codexBaseUrl: String): String { + val base = codexBaseUrl.toHttpUrl() + val basePath = base.encodedPath.trimEnd('/') + val parsed = if (Regex("^https?://").containsMatchIn(input)) { + input.toHttpUrl() + } else { + ("https://placeholder.invalid" + if (input.startsWith("/")) input else "/$input").toHttpUrl() + } + + var pathname = parsed.encodedPath + if (basePath.isNotEmpty() && pathname.startsWith("$basePath/")) pathname = pathname.substring(basePath.length) + if (pathname == "/v1") pathname = "/" else if (pathname.startsWith("/v1/")) pathname = pathname.substring(3) + if (!pathname.startsWith("/")) pathname = "/$pathname" + + val search = parsed.encodedQuery?.let { "?$it" } ?: "" + return "${base.scheme}://${base.host}$basePath$pathname$search" +} + +/** Ensures the `client_version` query param is present (the model gate depends on it). */ +fun withClientVersion(targetUrl: String, clientVersion: String): String { + if (clientVersion.isEmpty()) return targetUrl + val url = targetUrl.toHttpUrl() + if (url.queryParameter("client_version") != null) return targetUrl + return url.newBuilder().addQueryParameter("client_version", clientVersion).build().toString() +} + +/** + * Extracts model slugs from the shapes the ChatGPT backend has used for model + * lists. Unknown entries are ignored. Ported from `extractCodexModelSlugs`. + */ +fun extractCodexModelSlugs(value: JsonElement): List { + val seen = LinkedHashSet() + + fun visit(item: JsonElement) { + val candidate = when (item) { + is JsonPrimitive -> if (item.isString) item.content else null + is JsonObject -> listOf("slug", "id", "model", "name") + .firstNotNullOfOrNull { (item[it] as? JsonPrimitive)?.takeIf { p -> p.isString }?.content } + else -> null + } + val slug = candidate?.trim().orEmpty() + if (slug.isNotEmpty()) seen.add(slug) + } + + val candidateLists: List = when (value) { + is JsonArray -> listOf(value) + is JsonObject -> listOf("models", "data", "items", "available_models").mapNotNull { value[it] as? JsonArray } + else -> emptyList() + } + for (list in candidateLists) for (item in list) visit(item) + return seen.toList() +} + +private fun buildCodexRequest(config: ResolvedConfig, auth: CodexAuth, target: String): Request.Builder = + Request.Builder() + .url(target) + .header("Authorization", "Bearer ${auth.accessToken}") + .header("chatgpt-account-id", auth.accountId) + .header("OpenAI-Beta", "responses=experimental") + .header("originator", config.originator) + +/** + * Streams a Codex `/responses` completion, emitting assistant text deltas as they + * arrive. `getAuth` supplies fresh auth (wire it to a token store + [ensureFreshTokens]). + */ +fun codexResponses( + config: ResolvedConfig, + getAuth: suspend () -> CodexAuth, + body: JsonObject, + options: CodexResponsesOptions = CodexResponsesOptions(), +): Flow = flow { + val auth = getAuth() + // This helper streams, so the request must ask for SSE (`stream: true`); + // without it the Codex backend returns a single JSON body, not an event stream. + val normalized = JsonObject(normalizeResponsesBody(body, options) + ("stream" to JsonPrimitive(true))) + val target = withClientVersion( + resolveTargetUrl("${config.codexBaseUrl}/responses", config.codexBaseUrl), + config.clientVersion, + ) + val request = buildCodexRequest(config, auth, target) + .header("Accept", "text/event-stream") + .post(normalized.toString().toRequestBody(jsonMedia)) + .build() + + val debug = System.getenv("LWC_DEBUG") != null + + val response = config.httpClient.await(request) + if (debug) System.err.println("SSE| HTTP ${response.code} ${response.header("content-type")}") + if (!response.isSuccessful) { + val text = response.safeText() + response.close() + throw ChatGPTAuthError("responses_request_failed", "Codex /responses failed (${response.code}).", status = response.code, body = text) + } + + response.body?.source()?.use { source -> + while (!source.exhausted()) { + val line = source.readUtf8Line() ?: break + if (debug && line.isNotBlank()) System.err.println("SSE| ${line.take(400)}") + if (!line.startsWith("data:")) continue + val data = line.substring(5).trim() + if (data.isEmpty() || data == "[DONE]") continue + val event = try { + json.parseToJsonElement(data).jsonObject + } catch (_: Exception) { + continue + } + when (event["type"]?.jsonPrimitive?.contentOrNull) { + "response.output_text.delta" -> + event["delta"]?.jsonPrimitive?.contentOrNull?.let { emit(it) } + "response.failed", "error" -> + throw ChatGPTAuthError("responses_stream_error", "Codex stream reported: $data", body = data) + } + } + } +}.flowOn(Dispatchers.IO) + +/** Fetches the signed-in ChatGPT account's currently available Codex model slugs. */ +suspend fun listCodexModels(config: ResolvedConfig, auth: CodexAuth): List { + val target = withClientVersion( + resolveTargetUrl("${config.codexBaseUrl}/models", config.codexBaseUrl), + config.clientVersion, + ) + val request = buildCodexRequest(config, auth, target) + .header("Accept", "application/json") + .get() + .build() + + val response = config.httpClient.await(request) + response.use { + if (!it.isSuccessful) { + throw ChatGPTAuthError("models_request_failed", "Model list request failed (${it.code}).", status = it.code, body = it.safeText()) + } + return extractCodexModelSlugs(json.parseToJsonElement(it.safeText())) + } +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Config.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Config.kt new file mode 100644 index 0000000..752576b --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Config.kt @@ -0,0 +1,70 @@ +package com.opencoredev.loginwithchatgpt + +import okhttp3.OkHttpClient +import java.util.concurrent.TimeUnit + +/** + * Overridable configuration for every auth/transport call. All fields have + * sensible Codex defaults; override any of them so the SDK survives OpenAI + * moving an endpoint. Mirrors the TS `ChatGPTConfig`. + */ +data class ChatGPTConfig( + val clientId: String = Constants.DEFAULT_CLIENT_ID, + val issuer: String = Constants.DEFAULT_ISSUER, + val scope: String = Constants.DEFAULT_SCOPE, + val codexBaseUrl: String = Constants.DEFAULT_CODEX_BASE_URL, + val originator: String = Constants.DEFAULT_ORIGINATOR, + val clientVersion: String = Constants.DEFAULT_CLIENT_VERSION, + /** HTTP client. Override to inject interceptors, proxies, or test doubles. */ + val httpClient: OkHttpClient? = null, +) + +/** Fully-resolved configuration with all endpoint URLs derived from the issuer. */ +class ResolvedConfig internal constructor( + val clientId: String, + val issuer: String, + val scope: String, + val codexBaseUrl: String, + val originator: String, + val clientVersion: String, + val httpClient: OkHttpClient, +) { + /** OAuth token endpoint. */ + val tokenUrl: String = "$issuer/oauth/token" + + /** OAuth authorization endpoint. */ + val authorizeUrl: String = "$issuer/oauth/authorize" + + /** Device-auth API base. */ + val deviceApiBase: String = "$issuer/api/accounts" + + /** User-facing device verification page. */ + val deviceVerificationUrl: String = "$issuer/codex/device" + + /** Redirect URI used to exchange a device authorization code. */ + val deviceRedirectUri: String = "$issuer/deviceauth/callback" +} + +private fun stripTrailingSlash(value: String): String = value.trimEnd('/') + +/** Streaming-friendly default client: long read timeout for SSE, no call timeout. */ +private fun defaultHttpClient(): OkHttpClient = + OkHttpClient.Builder() + .connectTimeout(30, TimeUnit.SECONDS) + .readTimeout(0, TimeUnit.MILLISECONDS) + .callTimeout(0, TimeUnit.MILLISECONDS) + .build() + +/** Applies defaults and derives every endpoint URL from the issuer. */ +fun resolveConfig(config: ChatGPTConfig = ChatGPTConfig()): ResolvedConfig { + val issuer = stripTrailingSlash(config.issuer) + return ResolvedConfig( + clientId = config.clientId, + issuer = issuer, + scope = config.scope, + codexBaseUrl = stripTrailingSlash(config.codexBaseUrl), + originator = config.originator, + clientVersion = config.clientVersion, + httpClient = config.httpClient ?: defaultHttpClient(), + ) +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Constants.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Constants.kt new file mode 100644 index 0000000..f7d18a7 --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Constants.kt @@ -0,0 +1,56 @@ +package com.opencoredev.loginwithchatgpt + +/** + * Wire-protocol constants for the ChatGPT (Codex) OAuth flow. + * + * These mirror the public OpenAI Codex CLI client. Logging in with them grants + * access to the end user's own ChatGPT plan (Free/Plus/Pro) — usage is billed to + * that user, never to the app developer. Every value is overridable through + * [ChatGPTConfig] so the SDK keeps working if OpenAI moves an endpoint. + * + * Ported from `packages/core/src/constants.ts`. + */ +object Constants { + /** Public OAuth client id used by the Codex CLI. */ + const val DEFAULT_CLIENT_ID = "app_EMoamEEZ73f0CkXaXp7hrann" + + /** OAuth issuer / authorization server origin. */ + const val DEFAULT_ISSUER = "https://auth.openai.com" + + /** OAuth scopes required to obtain a refreshable ChatGPT session. */ + const val DEFAULT_SCOPE = "openid profile email offline_access" + + /** Base URL of the ChatGPT-backed Codex model API. */ + const val DEFAULT_CODEX_BASE_URL = "https://chatgpt.com/backend-api/codex" + + /** `originator` header/param value that identifies the client to OpenAI. */ + const val DEFAULT_ORIGINATOR = "codex_cli_rs" + + /** JWT claim namespace that carries ChatGPT account/plan metadata. */ + const val AUTH_CLAIM = "https://api.openai.com/auth" + + /** Device codes expire server-side ~15 minutes after issue. */ + const val DEVICE_CODE_TTL_MS = 15L * 60L * 1000L + + /** Default model used by the Codex responses API when the caller omits one. */ + const val DEFAULT_MODEL = "gpt-5.5" + + /** + * Codex client version sent as the `client_version` query parameter. The + * ChatGPT backend gates the available model set on this — omitting it (or + * sending a stale value) makes every model report as "not supported". Bump + * toward the current Codex CLI release if models disappear. + */ + const val DEFAULT_CLIENT_VERSION = "0.142.5" + + /** Default system instructions sent to the Codex responses API. */ + const val DEFAULT_CODEX_INSTRUCTIONS = + "You are a helpful assistant powered by the user's ChatGPT account. " + + "Answer the user's request directly and helpfully." + + /** + * The Codex backend runs stateless (`store: false`), so reasoning continuity + * is carried in encrypted reasoning content that must be explicitly requested. + */ + const val REASONING_ENCRYPTED_CONTENT = "reasoning.encrypted_content" +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Device.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Device.kt new file mode 100644 index 0000000..218e8fc --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Device.kt @@ -0,0 +1,146 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.coroutines.delay +import kotlinx.serialization.json.Json +import kotlinx.serialization.json.JsonObject +import kotlinx.serialization.json.buildJsonObject +import kotlinx.serialization.json.contentOrNull +import kotlinx.serialization.json.intOrNull +import kotlinx.serialization.json.jsonObject +import kotlinx.serialization.json.jsonPrimitive +import kotlinx.serialization.json.put +import okhttp3.MediaType.Companion.toMediaType +import okhttp3.Request +import okhttp3.RequestBody.Companion.toRequestBody + +/** + * The device-authorization flow — the mobile-friendly path. Unlike the loopback + * PKCE flow it needs no redirect listener, so it works on phones, servers, and + * CLIs. The PKCE pair is returned by OpenAI in the poll response, so the client + * never computes one. + * + * Ported from `packages/core/src/device.ts`. + */ + +private val json = Json { ignoreUnknownKeys = true } +private val jsonMedia = "application/json".toMediaType() + +/** Requests a fresh device code from OpenAI. */ +suspend fun requestDeviceCode(config: ResolvedConfig, now: () -> Long = System::currentTimeMillis): DeviceCode { + val url = "${config.deviceApiBase}/deviceauth/usercode" + val payload = buildJsonObject { put("client_id", config.clientId) } + val request = Request.Builder() + .url(url) + .header("Accept", "application/json") + .post(payload.toString().toRequestBody(jsonMedia)) + .build() + + val response = try { + config.httpClient.await(request) + } catch (cause: Exception) { + throw ChatGPTAuthError("network_error", "Failed to reach the device authorization endpoint.", cause = cause) + } + response.use { + if (it.code == 404) { + throw ChatGPTAuthError( + "device_code_disabled", + "Device-code login is not enabled for this server. Verify the issuer URL or use the redirect flow.", + status = 404, + ) + } + if (!it.isSuccessful) { + throw ChatGPTAuthError("device_code_request_failed", "Device code request failed (${it.code}).", status = it.code, body = it.safeText()) + } + val raw = json.parseToJsonElement(it.safeText()).jsonObject + val deviceAuthId = raw["device_auth_id"]?.jsonPrimitive?.contentOrNull + val userCode = raw["user_code"]?.jsonPrimitive?.contentOrNull + ?: raw["usercode"]?.jsonPrimitive?.contentOrNull + if (deviceAuthId == null || userCode == null) { + throw ChatGPTAuthError("device_code_request_failed", "Device code response was missing required fields.") + } + return DeviceCode( + deviceAuthId = deviceAuthId, + userCode = userCode, + verificationUrl = config.deviceVerificationUrl, + interval = normalizeInterval(raw["interval"]), + expiresAt = now() + Constants.DEVICE_CODE_TTL_MS, + ) + } +} + +/** + * Polls once for device-authorization completion. Returns [DevicePollResult.Pending] + * while the user has not finished, or [DevicePollResult.Authorized] with the code + * and server-generated PKCE pair to exchange for tokens. + */ +suspend fun pollDeviceCode(config: ResolvedConfig, device: DeviceCode): DevicePollResult { + val url = "${config.deviceApiBase}/deviceauth/token" + val payload = buildJsonObject { + put("device_auth_id", device.deviceAuthId) + put("user_code", device.userCode) + } + val request = Request.Builder() + .url(url) + .header("Accept", "application/json") + .post(payload.toString().toRequestBody(jsonMedia)) + .build() + + val response = try { + config.httpClient.await(request) + } catch (cause: Exception) { + throw ChatGPTAuthError("network_error", "Failed to reach the device token endpoint.", cause = cause) + } + response.use { + // 403/404 are the documented "keep waiting" responses; 429 is a transient + // Cloudflare rate-limit/challenge on the polling endpoint — also retryable. + if (it.code == 403 || it.code == 404 || it.code == 429) return DevicePollResult.Pending + if (!it.isSuccessful) { + throw ChatGPTAuthError("token_exchange_failed", "Device authorization failed (${it.code}).", status = it.code, body = it.safeText()) + } + val raw = json.parseToJsonElement(it.safeText()).jsonObject + val code = raw["authorization_code"]?.jsonPrimitive?.contentOrNull + val verifier = raw["code_verifier"]?.jsonPrimitive?.contentOrNull + val challenge = raw["code_challenge"]?.jsonPrimitive?.contentOrNull + // A 200 without a code means it is still binding — treat as pending. + if (code == null || verifier == null || challenge == null) return DevicePollResult.Pending + return DevicePollResult.Authorized(authorizationCode = code, codeChallenge = challenge, codeVerifier = verifier) + } +} + +/** Exchanges a successful device poll for tokens. */ +suspend fun exchangeDeviceAuthorization(config: ResolvedConfig, poll: DevicePollResult.Authorized): ChatGPTTokens = + exchangeAuthorizationCode( + config, + code = poll.authorizationCode, + codeVerifier = poll.codeVerifier, + redirectUri = config.deviceRedirectUri, + ) + +/** + * Blocks until the user authorizes the device or the code expires. Intended for + * CLIs/spikes; a UI should drive [pollDeviceCode] from its own polling loop. + */ +suspend fun waitForDeviceTokens( + config: ResolvedConfig, + device: DeviceCode, + intervalMs: Long = device.interval * 1000L, + now: () -> Long = System::currentTimeMillis, + onPoll: ((attempt: Int) -> Unit)? = null, +): ChatGPTTokens { + var attempt = 0 + while (now() < device.expiresAt) { + onPoll?.invoke(++attempt) + when (val result = pollDeviceCode(config, device)) { + is DevicePollResult.Authorized -> return exchangeDeviceAuthorization(config, result) + DevicePollResult.Pending -> delay(intervalMs) + } + } + throw ChatGPTAuthError("authorization_expired", "Device authorization expired before the user completed sign-in.") +} + +private fun normalizeInterval(value: kotlinx.serialization.json.JsonElement?): Int { + val prim = value?.jsonPrimitive ?: return 5 + prim.intOrNull?.let { if (it > 0) return it } + prim.contentOrNull?.trim()?.toIntOrNull()?.let { if (it > 0) return it } + return 5 +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Http.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Http.kt new file mode 100644 index 0000000..6b8d51d --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Http.kt @@ -0,0 +1,38 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.coroutines.suspendCancellableCoroutine +import okhttp3.Call +import okhttp3.Callback +import okhttp3.OkHttpClient +import okhttp3.Request +import okhttp3.Response +import java.io.IOException +import kotlin.coroutines.resumeWithException + +/** Suspending OkHttp call. Cancels the request when the coroutine is cancelled. */ +internal suspend fun OkHttpClient.await(request: Request): Response = + suspendCancellableCoroutine { cont -> + val call = newCall(request) + cont.invokeOnCancellation { runCatching { call.cancel() } } + call.enqueue( + object : Callback { + override fun onFailure(call: Call, e: IOException) { + if (cont.isCancelled) return + cont.resumeWithException(e) + } + + override fun onResponse(call: Call, response: Response) { + // Close the response if the coroutine was cancelled after + // delivery — otherwise the connection leaks. + cont.resume(response) { _ -> runCatching { response.close() } } + } + }, + ) + } + +/** Reads a response body as text, swallowing read errors. */ +internal fun Response.safeText(): String = try { + body?.string() ?: "" +} catch (_: Exception) { + "" +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Jwt.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Jwt.kt new file mode 100644 index 0000000..87cada9 --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Jwt.kt @@ -0,0 +1,61 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.serialization.json.Json +import kotlinx.serialization.json.JsonObject +import kotlinx.serialization.json.jsonObject +import kotlinx.serialization.json.jsonPrimitive +import kotlinx.serialization.json.contentOrNull +import kotlinx.serialization.json.longOrNull +import java.util.Base64 + +private val lenientJson = Json { ignoreUnknownKeys = true; isLenient = true } + +/** Decodes a base64url segment (no padding) to a UTF-8 string. */ +internal fun base64UrlDecodeToString(segment: String): String = + String(Base64.getUrlDecoder().decode(padBase64Url(segment))) + +private fun padBase64Url(value: String): String { + val remainder = value.length % 4 + return if (remainder == 0) value else value + "=".repeat(4 - remainder) +} + +/** + * Decodes a JWT payload **without verifying its signature**. These tokens come + * straight from OpenAI's token endpoint over TLS, so we only read claims we + * already trust. Never use this to validate a token from an untrusted source. + */ +fun decodeJwt(token: String?): JsonObject? { + if (token == null) return null + val parts = token.split(".") + if (parts.size != 3 || parts[1].isEmpty()) return null + return try { + lenientJson.parseToJsonElement(base64UrlDecodeToString(parts[1])).jsonObject + } catch (_: Exception) { + null + } +} + +/** Extracts the `exp` claim as epoch milliseconds, or `null`. */ +fun getTokenExpiry(token: String?): Long? { + val exp = decodeJwt(token)?.get("exp")?.jsonPrimitive?.longOrNull ?: return null + return exp * 1000 +} + +/** Reads the ChatGPT account id from an id (or access) token. */ +fun deriveAccountId(token: String?): String? { + val auth = decodeJwt(token)?.get(Constants.AUTH_CLAIM) as? JsonObject ?: return null + return auth["chatgpt_account_id"]?.jsonPrimitive?.contentOrNull +} + +/** Builds a public [ChatGPTUser] profile from an id token. */ +fun parseUser(idToken: String?): ChatGPTUser? { + val claims = decodeJwt(idToken) ?: return null + val accountId = deriveAccountId(idToken) ?: return null + val auth = claims[Constants.AUTH_CLAIM] as? JsonObject + return ChatGPTUser( + accountId = accountId, + email = claims["email"]?.jsonPrimitive?.contentOrNull?.ifEmpty { null }, + name = claims["name"]?.jsonPrimitive?.contentOrNull?.ifEmpty { null }, + plan = auth?.get("chatgpt_plan_type")?.jsonPrimitive?.contentOrNull?.ifEmpty { null }, + ) +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Models.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Models.kt new file mode 100644 index 0000000..03762e8 --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Models.kt @@ -0,0 +1,77 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.serialization.Serializable + +/** + * OAuth tokens for a signed-in ChatGPT user. + * + * [accessToken] is short-lived; [refreshToken] mints new access tokens. Both are + * secrets — on device they live in the Android Keystore-backed store. [accountId] + * is derived from the id token and is required on every model request. + */ +@Serializable +data class ChatGPTTokens( + val accessToken: String, + val refreshToken: String? = null, + val idToken: String? = null, + /** ChatGPT account id (`chatgpt_account_id` claim), sent as a request header. */ + val accountId: String? = null, + /** Epoch milliseconds at which [accessToken] expires, when known. */ + val expiresAt: Long? = null, +) + +/** Public profile derived from the id token — safe to show in the UI. */ +@Serializable +data class ChatGPTUser( + val accountId: String, + val email: String? = null, + val name: String? = null, + /** ChatGPT plan, e.g. `"free"`, `"plus"`, `"pro"`, when present in the token. */ + val plan: String? = null, +) + +/** + * A pending device-code login. Show [userCode] to the user and send them to + * [verificationUrl]; poll until they authorize. + */ +data class DeviceCode( + /** Opaque handle used when polling for completion. */ + val deviceAuthId: String, + /** Short human-enterable code (e.g. `7B0J-DPK78`). */ + val userCode: String, + /** URL the user opens to enter [userCode]. */ + val verificationUrl: String, + /** Minimum seconds to wait between polls. */ + val interval: Int, + /** Epoch milliseconds after which the code is no longer valid. */ + val expiresAt: Long, +) + +/** Result of a single device-token poll. */ +sealed interface DevicePollResult { + data object Pending : DevicePollResult + + data class Authorized( + val authorizationCode: String, + val codeChallenge: String, + val codeVerifier: String, + ) : DevicePollResult +} + +/** High-level status of a login session. */ +enum class LoginStatus { + UNAUTHENTICATED, + PENDING, + AUTHENTICATED, + EXPIRED, + ERROR, +} + +/** Structured auth/transport failure, mirroring the TS `ChatGPTAuthError`. */ +class ChatGPTAuthError( + val code: String, + message: String, + val status: Int? = null, + val body: String? = null, + cause: Throwable? = null, +) : Exception(message, cause) diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/OAuth.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/OAuth.kt new file mode 100644 index 0000000..40201b3 --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/OAuth.kt @@ -0,0 +1,121 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.serialization.json.Json +import kotlinx.serialization.json.JsonObject +import kotlinx.serialization.json.buildJsonObject +import kotlinx.serialization.json.contentOrNull +import kotlinx.serialization.json.intOrNull +import kotlinx.serialization.json.jsonObject +import kotlinx.serialization.json.jsonPrimitive +import kotlinx.serialization.json.put +import okhttp3.FormBody +import okhttp3.MediaType.Companion.toMediaType +import okhttp3.Request +import okhttp3.RequestBody.Companion.toRequestBody + +private val json = Json { ignoreUnknownKeys = true } +private val jsonMedia = "application/json".toMediaType() + +/** Normalizes OpenAI's token payload into [ChatGPTTokens]. */ +private fun toTokens(raw: JsonObject, previousRefreshToken: String? = null): ChatGPTTokens { + val accessToken = raw["access_token"]?.jsonPrimitive?.contentOrNull + ?: throw ChatGPTAuthError("token_exchange_failed", "Token response missing access_token.") + val idToken = raw["id_token"]?.jsonPrimitive?.contentOrNull + val expiresIn = raw["expires_in"]?.jsonPrimitive?.intOrNull + return ChatGPTTokens( + accessToken = accessToken, + refreshToken = raw["refresh_token"]?.jsonPrimitive?.contentOrNull ?: previousRefreshToken, + idToken = idToken, + accountId = deriveAccountId(idToken) ?: deriveAccountId(accessToken), + expiresAt = if (expiresIn != null) System.currentTimeMillis() + expiresIn * 1000L else getTokenExpiry(accessToken), + ) +} + +/** Exchanges an authorization code (+ PKCE verifier) for tokens. */ +suspend fun exchangeAuthorizationCode( + config: ResolvedConfig, + code: String, + codeVerifier: String, + redirectUri: String, +): ChatGPTTokens { + val form = FormBody.Builder() + .add("grant_type", "authorization_code") + .add("client_id", config.clientId) + .add("code", code) + .add("code_verifier", codeVerifier) + .add("redirect_uri", redirectUri) + .build() + val request = Request.Builder() + .url(config.tokenUrl) + .header("Accept", "application/json") + .post(form) + .build() + + val response = try { + config.httpClient.await(request) + } catch (cause: Exception) { + throw ChatGPTAuthError("network_error", "Failed to reach the token endpoint.", cause = cause) + } + response.use { + if (!it.isSuccessful) { + throw ChatGPTAuthError( + "token_exchange_failed", + "Authorization code exchange failed (${it.code}).", + status = it.code, + body = it.safeText(), + ) + } + return toTokens(json.parseToJsonElement(it.safeText()).jsonObject) + } +} + +/** Error codes OpenAI returns when a refresh token can no longer be used. */ +private val DEAD_REFRESH_ERRORS = setOf( + "refresh_token_expired", + "refresh_token_reused", + "refresh_token_invalidated", + "invalid_grant", +) + +/** Exchanges a refresh token for a fresh access token (and possibly a new refresh token). */ +suspend fun refreshTokens(config: ResolvedConfig, refreshToken: String): ChatGPTTokens { + val payload = buildJsonObject { + put("grant_type", "refresh_token") + put("refresh_token", refreshToken) + put("client_id", config.clientId) + put("scope", config.scope) + } + val request = Request.Builder() + .url(config.tokenUrl) + .header("Accept", "application/json") + .post(payload.toString().toRequestBody(jsonMedia)) + .build() + + val response = try { + config.httpClient.await(request) + } catch (cause: Exception) { + throw ChatGPTAuthError("network_error", "Failed to reach the token endpoint.", cause = cause) + } + response.use { + if (!it.isSuccessful) { + val text = it.safeText() + val errorCode = extractErrorCode(text) + if (errorCode != null && errorCode in DEAD_REFRESH_ERRORS) { + throw ChatGPTAuthError( + "refresh_token_invalid", + "Refresh token is no longer valid ($errorCode). The user must sign in again.", + status = it.code, + body = text, + ) + } + throw ChatGPTAuthError("token_refresh_failed", "Token refresh failed (${it.code}).", status = it.code, body = text) + } + return toTokens(json.parseToJsonElement(it.safeText()).jsonObject, refreshToken) + } +} + +private fun extractErrorCode(body: String): String? = try { + json.parseToJsonElement(body).jsonObject["error"]?.jsonPrimitive?.contentOrNull +} catch (_: Exception) { + null +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Spike.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Spike.kt new file mode 100644 index 0000000..4fbd3b0 --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Spike.kt @@ -0,0 +1,68 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.coroutines.runBlocking + +/** + * Stage 0 de-risk spike (no UI). Runs the full on-device flow against a real + * ChatGPT account and prints the result: + * + * gradle :lwc-core:run --args="Say hello in one short sentence." + * + * Go/no-go gate: proves device login + a streamed /responses completion works + * from a non-CLI native client, and that listCodexModels returns the account's + * models — before any Android/Compose work. + */ +fun main(args: Array) = runBlocking { + val prompt = args.joinToString(" ").ifBlank { "Say hello in exactly one short sentence." } + val config = resolveConfig() + + println("Requesting device code…") + val device = requestDeviceCode(config) + println() + println(" 1. Open: ${device.verificationUrl}") + println(" 2. Enter code: ${device.userCode}") + println() + println("Waiting for authorization (code expires in ~15 min)…") + + val tokens = waitForDeviceTokens(config, device) { attempt -> + if (attempt % 5 == 0) println(" …still waiting (poll #$attempt)") + } + + val user = parseUser(tokens.idToken) + println() + println("Signed in: ${user?.email ?: "(unknown email)"} plan=${user?.plan ?: "?"} account=${tokens.accountId}") + + val auth = CodexAuth(accessToken = tokens.accessToken, accountId = tokens.accountId ?: error("no account id")) + + println() + println("Available models:") + val models = listCodexModels(config, auth) + models.forEach { println(" - $it") } + check(models.isNotEmpty()) { "listCodexModels returned no models" } + + val model = if (models.contains(Constants.DEFAULT_MODEL)) Constants.DEFAULT_MODEL else models.first() + + println() + println("Streaming a completion from '$model':") + println("Prompt: $prompt") + print("Reply: ") + val body = textPromptBody(model, prompt) + val sb = StringBuilder() + try { + codexResponses(config, getAuth = { auth }, body = body).collect { delta -> + sb.append(delta) + print(delta) + System.out.flush() + } + } catch (e: ChatGPTAuthError) { + println() + System.err.println("‼ /responses failed: code=${e.code} httpStatus=${e.status}") + System.err.println("‼ response body: ${e.body}") + System.err.println("(Re-run with LWC_DEBUG=1 to dump the raw stream.)") + throw e + } + println() + check(sb.isNotBlank()) { "Stream produced no assistant text (AI_NoOutputGenerated) — check body normalization/headers." } + println() + println("✔ Stage 0 passed: login + models + streamed reply all worked.") +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/TokenStore.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/TokenStore.kt new file mode 100644 index 0000000..4f33398 --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/TokenStore.kt @@ -0,0 +1,21 @@ +package com.opencoredev.loginwithchatgpt + +import java.util.concurrent.atomic.AtomicReference + +/** + * Persists the signed-in user's tokens. The pure-Kotlin core ships an in-memory + * implementation; the `lwc-android` module provides a Keystore-backed one. + */ +interface TokenStore { + suspend fun load(): ChatGPTTokens? + suspend fun save(tokens: ChatGPTTokens) + suspend fun clear() +} + +/** Non-persistent store — process memory only. Useful for the spike and tests. */ +class InMemoryTokenStore(initial: ChatGPTTokens? = null) : TokenStore { + private val ref = AtomicReference(initial) + override suspend fun load(): ChatGPTTokens? = ref.get() + override suspend fun save(tokens: ChatGPTTokens) = ref.set(tokens) + override suspend fun clear() = ref.set(null) +} diff --git a/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Tokens.kt b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Tokens.kt new file mode 100644 index 0000000..3a0075b --- /dev/null +++ b/android/lwc-core/src/main/kotlin/com/opencoredev/loginwithchatgpt/Tokens.kt @@ -0,0 +1,43 @@ +package com.opencoredev.loginwithchatgpt + +/** Refresh when the access token is within this window of expiring. */ +private const val EXPIRY_MARGIN_MS = 60L * 1000L + +/** `true` when the access token is missing, expired, or about to expire. */ +fun isAccessTokenExpired(tokens: ChatGPTTokens, now: () -> Long = System::currentTimeMillis): Boolean { + if (tokens.accessToken.isEmpty()) return true + val expiresAt = tokens.expiresAt ?: getTokenExpiry(tokens.accessToken) ?: return false + return expiresAt <= now() + EXPIRY_MARGIN_MS +} + +/** Ensures `accountId` is populated by deriving it from the tokens when missing. */ +private fun withAccountId(tokens: ChatGPTTokens): ChatGPTTokens { + if (tokens.accountId != null) return tokens + val accountId = deriveAccountId(tokens.idToken) ?: deriveAccountId(tokens.accessToken) + return if (accountId != null) tokens.copy(accountId = accountId) else tokens +} + +/** + * Returns tokens guaranteed fresh enough to make an API call, refreshing via the + * refresh token when needed and reporting the new tokens through [onRefresh]. + * Throws [ChatGPTAuthError] `not_authenticated` when nothing usable is available. + */ +suspend fun ensureFreshTokens( + config: ResolvedConfig, + tokens: ChatGPTTokens?, + force: Boolean = false, + now: () -> Long = System::currentTimeMillis, + onRefresh: (suspend (ChatGPTTokens) -> Unit)? = null, +): ChatGPTTokens { + if (tokens != null && tokens.accessToken.isNotEmpty() && !force && !isAccessTokenExpired(tokens, now)) { + return withAccountId(tokens) + } + val refreshToken = tokens?.refreshToken + if (refreshToken == null) { + if (tokens != null && tokens.accessToken.isNotEmpty()) return withAccountId(tokens) + throw ChatGPTAuthError("not_authenticated", "No ChatGPT credentials available. The user must sign in.") + } + val refreshed = withAccountId(refreshTokens(config, refreshToken)) + onRefresh?.invoke(refreshed) + return refreshed +} diff --git a/android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/CodexTransportTest.kt b/android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/CodexTransportTest.kt new file mode 100644 index 0000000..54f5171 --- /dev/null +++ b/android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/CodexTransportTest.kt @@ -0,0 +1,135 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.serialization.json.JsonArray +import kotlinx.serialization.json.JsonObject +import kotlinx.serialization.json.JsonPrimitive +import kotlinx.serialization.json.booleanOrNull +import kotlinx.serialization.json.buildJsonArray +import kotlinx.serialization.json.buildJsonObject +import kotlinx.serialization.json.contentOrNull +import kotlinx.serialization.json.jsonObject +import kotlinx.serialization.json.jsonPrimitive +import kotlinx.serialization.json.put +import kotlin.test.Test +import kotlin.test.assertEquals +import kotlin.test.assertFalse +import kotlin.test.assertNull +import kotlin.test.assertTrue + +/** Ported from `packages/core/test/codex-transport.test.ts`. */ +class CodexTransportTest { + @Test + fun `normalizeResponsesBody adds all Codex stateless requirements`() { + val out = normalizeResponsesBody( + buildJsonObject { put("input", "hi"); put("max_output_tokens", 100) }, + CodexResponsesOptions(instructions = "sys"), + ) + assertEquals("sys", out["instructions"]?.jsonPrimitive?.contentOrNull) + assertEquals(false, out["store"]?.jsonPrimitive?.booleanOrNull) + val reasoning = out["reasoning"] as JsonObject + assertEquals("medium", reasoning["effort"]?.jsonPrimitive?.contentOrNull) + assertEquals("auto", reasoning["summary"]?.jsonPrimitive?.contentOrNull) + assertEquals("medium", (out["text"] as JsonObject)["verbosity"]?.jsonPrimitive?.contentOrNull) + val include = (out["include"] as JsonArray).map { it.jsonPrimitive.content } + assertTrue(include.contains("reasoning.encrypted_content")) + assertNull(out["max_output_tokens"]) + } + + @Test + fun `normalizeResponsesBody keeps caller instructions and merges reasoning overrides`() { + val out = normalizeResponsesBody( + buildJsonObject { + put("input", "hi") + put("instructions", "keep") + put("reasoning", buildJsonObject { put("effort", "high") }) + }, + CodexResponsesOptions(reasoningEffort = "low"), + ) + assertEquals("keep", out["instructions"]?.jsonPrimitive?.contentOrNull) + // caller-provided reasoning.effort wins over the option default + assertEquals("high", (out["reasoning"] as JsonObject)["effort"]?.jsonPrimitive?.contentOrNull) + assertEquals(false, out["store"]?.jsonPrimitive?.booleanOrNull) + } + + @Test + fun `normalizeResponsesBody accepts Codex service tier defaults`() { + val out = normalizeResponsesBody(buildJsonObject { put("input", "hi") }, CodexResponsesOptions(serviceTier = "fast")) + assertEquals("fast", out["service_tier"]?.jsonPrimitive?.contentOrNull) + + val callerTier = normalizeResponsesBody( + buildJsonObject { put("input", "hi"); put("service_tier", "flex") }, + CodexResponsesOptions(serviceTier = "fast"), + ) + assertEquals("flex", callerTier["service_tier"]?.jsonPrimitive?.contentOrNull) + } + + @Test + fun `normalizeResponsesBody strips input ids and drops item_reference`() { + val out = normalizeResponsesBody( + buildJsonObject { + put( + "input", + buildJsonArray { + add(buildJsonObject { put("id", "msg_1"); put("type", "message"); put("role", "user"); put("content", buildJsonArray {}) }) + add(buildJsonObject { put("type", "item_reference"); put("id", "ref_1") }) + }, + ) + }, + ) + val input = out["input"] as JsonArray + assertEquals(1, input.size) + val first = input[0] as JsonObject + assertFalse(first.containsKey("id")) + assertEquals("message", first["type"]?.jsonPrimitive?.contentOrNull) + } + + @Test + fun `resolveTargetUrl maps absolute and relative inputs onto the codex base`() { + val base = "https://chatgpt.com/backend-api/codex" + assertEquals("$base/responses", resolveTargetUrl("https://api.openai.com/v1/responses", base)) + assertEquals("$base/responses", resolveTargetUrl("/responses", base)) + assertEquals("$base/responses", resolveTargetUrl("$base/responses", base)) + } + + @Test + fun `withClientVersion adds param when absent and preserves an explicit one`() { + val base = "https://chatgpt.com/backend-api/codex/responses" + assertTrue(withClientVersion(base, "0.142.5").contains("client_version=0.142.5")) + assertTrue(withClientVersion("$base?client_version=9.9.9", "0.142.5").contains("client_version=9.9.9")) + } + + @Test + fun `extractCodexModelSlugs supports known model-list wrappers`() { + assertEquals( + listOf("gpt-a", "gpt-b", "gpt-c"), + extractCodexModelSlugs( + buildJsonObject { + put("models", buildJsonArray { + add(buildJsonObject { put("slug", "gpt-a") }) + add(buildJsonObject { put("id", "gpt-b") }) + add(buildJsonObject { put("slug", "gpt-a") }) + add(buildJsonObject { put("slug", "") }) + }) + put("data", buildJsonArray { add(buildJsonObject { put("model", "gpt-c") }) }) + }, + ), + ) + assertEquals( + listOf("gpt-c"), + extractCodexModelSlugs( + buildJsonObject { + put("models", buildJsonArray {}) + put("data", buildJsonArray { add(buildJsonObject { put("model", "gpt-c") }) }) + }, + ), + ) + assertEquals( + listOf("gpt-d"), + extractCodexModelSlugs(buildJsonArray { add(buildJsonObject { put("name", "gpt-d") }) }), + ) + assertEquals( + listOf("gpt-5.5", "gpt-5.4"), + extractCodexModelSlugs(buildJsonObject { put("models", buildJsonArray { add(JsonPrimitive("gpt-5.5")); add(JsonPrimitive("gpt-5.4")) }) }), + ) + } +} diff --git a/android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/JwtTest.kt b/android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/JwtTest.kt new file mode 100644 index 0000000..dc59e02 --- /dev/null +++ b/android/lwc-core/src/test/kotlin/com/opencoredev/loginwithchatgpt/JwtTest.kt @@ -0,0 +1,82 @@ +package com.opencoredev.loginwithchatgpt + +import kotlinx.serialization.json.JsonObject +import kotlinx.serialization.json.JsonObjectBuilder +import kotlinx.serialization.json.buildJsonObject +import kotlinx.serialization.json.contentOrNull +import kotlinx.serialization.json.intOrNull +import kotlinx.serialization.json.jsonPrimitive +import kotlinx.serialization.json.put +import java.util.Base64 +import kotlin.test.Test +import kotlin.test.assertEquals +import kotlin.test.assertNull + +/** Ported from `packages/core/test/jwt.test.ts` (and `helpers.ts`). */ +class JwtTest { + private fun b64Url(s: String): String = + Base64.getUrlEncoder().withoutPadding().encodeToString(s.toByteArray()) + + /** Builds an unsigned JWT (`alg: none`) with the given claims. */ + private fun makeJwt(build: JsonObjectBuilder.() -> Unit): String { + val header = b64Url("""{"alg":"none","typ":"JWT"}""") + val body = b64Url(buildJsonObject(build).toString()) + return "$header.$body.sig" + } + + private fun makeIdToken(accountId: String? = "acct_123", email: String? = null, name: String? = null, plan: String? = null): String = + makeJwt { + if (email != null) put("email", email) + if (name != null) put("name", name) + put("exp", (System.currentTimeMillis() / 1000) + 3600) + put( + Constants.AUTH_CLAIM, + buildJsonObject { + put("chatgpt_account_id", accountId) + if (plan != null) put("chatgpt_plan_type", plan) + }, + ) + } + + @Test + fun `decodes a payload`() { + val token = makeJwt { put("hello", "world"); put("n", 1) } + val decoded = decodeJwt(token) as JsonObject + assertEquals("world", decoded["hello"]?.jsonPrimitive?.contentOrNull) + assertEquals(1, decoded["n"]?.jsonPrimitive?.intOrNull) + } + + @Test + fun `returns null for malformed tokens`() { + assertNull(decodeJwt("not-a-jwt")) + assertNull(decodeJwt(null)) + assertNull(decodeJwt("a.b")) + } + + @Test + fun `derives the ChatGPT account id from the auth claim`() { + assertEquals("acct_xyz", deriveAccountId(makeIdToken(accountId = "acct_xyz"))) + } + + @Test + fun `returns null account id when the claim is absent`() { + assertNull(deriveAccountId(makeJwt { put("sub", "u") })) + } + + @Test + fun `reads token expiry in milliseconds`() { + val token = makeJwt { put("exp", 2_000_000_000L) } + assertEquals(2_000_000_000_000L, getTokenExpiry(token)) + } + + @Test + fun `parses a public user profile`() { + val token = makeIdToken(accountId = "acct_1", email = "a@b.dev", name = "Ada", plan = "pro") + assertEquals(ChatGPTUser(accountId = "acct_1", email = "a@b.dev", name = "Ada", plan = "pro"), parseUser(token)) + } + + @Test + fun `returns null user when account id is missing`() { + assertNull(parseUser(makeJwt { put("email", "x@y.dev") })) + } +} diff --git a/android/sample/build.gradle.kts b/android/sample/build.gradle.kts new file mode 100644 index 0000000..13db3ab --- /dev/null +++ b/android/sample/build.gradle.kts @@ -0,0 +1,50 @@ +plugins { + id("com.android.application") + id("org.jetbrains.kotlin.android") + id("org.jetbrains.kotlin.plugin.compose") +} + +android { + namespace = "com.opencoredev.loginwithchatgpt.sample" + compileSdk = 36 + + defaultConfig { + applicationId = "com.opencoredev.loginwithchatgpt.sample" + minSdk = 24 + targetSdk = 36 + versionCode = 1 + versionName = "0.1.0" + } + + buildFeatures { + compose = true + } + + compileOptions { + sourceCompatibility = JavaVersion.VERSION_17 + targetCompatibility = JavaVersion.VERSION_17 + } + + buildTypes { + getByName("release") { + isMinifyEnabled = false + } + } +} + +kotlin { + jvmToolchain(17) +} + +dependencies { + implementation(project(":lwc-android")) + + implementation(platform("androidx.compose:compose-bom:2024.10.01")) + implementation("androidx.compose.ui:ui") + implementation("androidx.compose.material3:material3") + implementation("androidx.compose.ui:ui-tooling-preview") + debugImplementation("androidx.compose.ui:ui-tooling") + implementation("androidx.activity:activity-compose:1.9.3") + implementation("androidx.lifecycle:lifecycle-runtime-ktx:2.8.7") + implementation("org.jetbrains.kotlinx:kotlinx-serialization-json:1.7.3") +} diff --git a/android/sample/src/main/AndroidManifest.xml b/android/sample/src/main/AndroidManifest.xml new file mode 100644 index 0000000..b587067 --- /dev/null +++ b/android/sample/src/main/AndroidManifest.xml @@ -0,0 +1,21 @@ + + + + + + + + + + + + + + + diff --git a/android/sample/src/main/kotlin/com/opencoredev/loginwithchatgpt/sample/MainActivity.kt b/android/sample/src/main/kotlin/com/opencoredev/loginwithchatgpt/sample/MainActivity.kt new file mode 100644 index 0000000..20b8ec4 --- /dev/null +++ b/android/sample/src/main/kotlin/com/opencoredev/loginwithchatgpt/sample/MainActivity.kt @@ -0,0 +1,220 @@ +package com.opencoredev.loginwithchatgpt.sample + +import android.os.Bundle +import androidx.activity.ComponentActivity +import androidx.activity.compose.setContent +import androidx.compose.foundation.layout.Arrangement +import androidx.compose.foundation.layout.Box +import androidx.compose.foundation.layout.Column +import androidx.compose.foundation.layout.Spacer +import androidx.compose.foundation.layout.fillMaxSize +import androidx.compose.foundation.layout.fillMaxWidth +import androidx.compose.foundation.layout.height +import androidx.compose.foundation.layout.padding +import androidx.compose.foundation.layout.Row +import androidx.compose.foundation.rememberScrollState +import androidx.compose.foundation.verticalScroll +import androidx.compose.material3.Button +import androidx.compose.material3.CircularProgressIndicator +import androidx.compose.material3.MaterialTheme +import androidx.compose.material3.OutlinedButton +import androidx.compose.material3.OutlinedTextField +import androidx.compose.material3.Surface +import androidx.compose.material3.Text +import androidx.compose.runtime.Composable +import androidx.compose.runtime.getValue +import androidx.compose.runtime.mutableStateOf +import androidx.compose.runtime.remember +import androidx.compose.runtime.rememberCoroutineScope +import androidx.compose.runtime.setValue +import androidx.compose.runtime.LaunchedEffect +import androidx.compose.ui.Alignment +import androidx.compose.ui.Modifier +import androidx.compose.ui.text.style.TextAlign +import androidx.compose.ui.unit.dp +import com.opencoredev.loginwithchatgpt.ChatGPTUser +import com.opencoredev.loginwithchatgpt.Constants +import com.opencoredev.loginwithchatgpt.DeviceCode +import com.opencoredev.loginwithchatgpt.DevicePollResult +import com.opencoredev.loginwithchatgpt.android.LoginWithChatGPT +import com.opencoredev.loginwithchatgpt.textPromptBody +import kotlinx.coroutines.delay +import kotlinx.coroutines.launch + +class MainActivity : ComponentActivity() { + override fun onCreate(savedInstanceState: Bundle?) { + super.onCreate(savedInstanceState) + val lwc = LoginWithChatGPT(applicationContext) + setContent { + MaterialTheme { + Surface(modifier = Modifier.fillMaxSize()) { + AppScreen(lwc) + } + } + } + } +} + +@Composable +private fun AppScreen(lwc: LoginWithChatGPT) { + val scope = rememberCoroutineScope() + var loading by remember { mutableStateOf(true) } + var user by remember { mutableStateOf(null) } + var device by remember { mutableStateOf(null) } + var error by remember { mutableStateOf(null) } + + LaunchedEffect(Unit) { + user = lwc.currentUser() + loading = false + } + + when { + loading -> Centered { CircularProgressIndicator() } + + user != null -> ChatScreen( + lwc = lwc, + user = user!!, + onLogout = { scope.launch { lwc.logout(); user = null } }, + ) + + device != null -> PendingScreen(device = device!!, error = error, onReopen = { lwc.openVerification(device!!) }) + + else -> LoginScreen(error = error, onLogin = { + error = null + scope.launch { + try { + val d = lwc.startDeviceLogin() + device = d + lwc.openVerification(d) + while (true) { + if (System.currentTimeMillis() > d.expiresAt) { + error = "Code expired — try again." + device = null + break + } + val result = lwc.poll(d) + if (result is DevicePollResult.Authorized) { + user = lwc.currentUser() + device = null + break + } + delay(d.interval * 1000L) + } + } catch (e: Exception) { + error = e.message ?: "Login failed." + device = null + } + } + }) + } +} + +@Composable +private fun LoginScreen(error: String?, onLogin: () -> Unit) { + Centered { + Column(horizontalAlignment = Alignment.CenterHorizontally) { + Text("Login with ChatGPT", style = MaterialTheme.typography.headlineSmall) + Spacer(Modifier.height(8.dp)) + Text( + "Sign in with your own ChatGPT account. Models run on your plan — " + + "no API key, and usage is billed to you.", + style = MaterialTheme.typography.bodyMedium, + textAlign = TextAlign.Center, + ) + Spacer(Modifier.height(24.dp)) + Button(onClick = onLogin) { Text("Sign in with ChatGPT") } + if (error != null) { + Spacer(Modifier.height(16.dp)) + Text(error, color = MaterialTheme.colorScheme.error, textAlign = TextAlign.Center) + } + } + } +} + +@Composable +private fun PendingScreen(device: DeviceCode, error: String?, onReopen: () -> Unit) { + Centered { + Column(horizontalAlignment = Alignment.CenterHorizontally) { + Text("Enter this code on OpenAI", style = MaterialTheme.typography.titleMedium) + Spacer(Modifier.height(12.dp)) + Text(device.userCode, style = MaterialTheme.typography.displaySmall) + Spacer(Modifier.height(24.dp)) + CircularProgressIndicator() + Spacer(Modifier.height(16.dp)) + Text("Waiting for authorization…", style = MaterialTheme.typography.bodyMedium) + Spacer(Modifier.height(16.dp)) + OutlinedButton(onClick = onReopen) { Text("Reopen verification page") } + if (error != null) { + Spacer(Modifier.height(16.dp)) + Text(error, color = MaterialTheme.colorScheme.error) + } + } + } +} + +@Composable +private fun ChatScreen(lwc: LoginWithChatGPT, user: ChatGPTUser, onLogout: () -> Unit) { + val scope = rememberCoroutineScope() + var prompt by remember { mutableStateOf("") } + var reply by remember { mutableStateOf("") } + var streaming by remember { mutableStateOf(false) } + var error by remember { mutableStateOf(null) } + + Column(modifier = Modifier.fillMaxSize().padding(16.dp)) { + Text("Signed in as ${user.email ?: user.accountId}", style = MaterialTheme.typography.titleMedium) + Text( + "Plan: ${user.plan ?: "unknown"} · billed to this ChatGPT account", + style = MaterialTheme.typography.bodySmall, + ) + Spacer(Modifier.height(16.dp)) + + OutlinedTextField( + value = prompt, + onValueChange = { prompt = it }, + label = { Text("Ask something") }, + modifier = Modifier.fillMaxWidth(), + ) + Spacer(Modifier.height(12.dp)) + Row(modifier = Modifier.fillMaxWidth(), horizontalArrangement = Arrangement.spacedBy(12.dp)) { + Button( + onClick = { + if (prompt.isBlank() || streaming) return@Button + error = null + reply = "" + streaming = true + val body = textPromptBody(Constants.DEFAULT_MODEL, prompt) + scope.launch { + try { + lwc.chat(body).collect { reply += it } + } catch (e: Exception) { + error = e.message ?: "Request failed." + } finally { + streaming = false + } + } + }, + enabled = !streaming, + ) { Text(if (streaming) "Streaming…" else "Send") } + + OutlinedButton(onClick = onLogout) { Text("Log out") } + } + + Spacer(Modifier.height(16.dp)) + if (error != null) { + Text(error!!, color = MaterialTheme.colorScheme.error) + Spacer(Modifier.height(8.dp)) + } + Text( + reply, + style = MaterialTheme.typography.bodyLarge, + modifier = Modifier.fillMaxWidth().verticalScroll(rememberScrollState()), + ) + } +} + +@Composable +private fun Centered(content: @Composable () -> Unit) { + Box(modifier = Modifier.fillMaxSize().padding(24.dp), contentAlignment = Alignment.Center) { + content() + } +} diff --git a/android/sample/src/main/res/values/themes.xml b/android/sample/src/main/res/values/themes.xml new file mode 100644 index 0000000..97c7d40 --- /dev/null +++ b/android/sample/src/main/res/values/themes.xml @@ -0,0 +1,5 @@ + + + +