From b96f5f9ceb79a0218f75479f046a5bd36c6bff77 Mon Sep 17 00:00:00 2001 From: bjkim Date: Tue, 29 Jul 2025 17:36:02 +0900 Subject: [PATCH] first release --- .gitignore | 53 +++ .mvn/wrapper/maven-wrapper.jar | Bin 0 -> 58727 bytes .mvn/wrapper/maven-wrapper.properties | 2 + README.md | 202 +++++++++++ build.gradle.kts | 53 +++ gradle.properties | 5 + gradle/libs.versions.toml | 32 ++ gradle/wrapper/gradle-wrapper.jar | Bin 0 -> 43764 bytes gradle/wrapper/gradle-wrapper.properties | 7 + gradlew | 251 ++++++++++++++ gradlew.bat | 94 ++++++ mvnw | 316 ++++++++++++++++++ mvnw.cmd | 188 +++++++++++ pom.xml | 106 ++++++ settings.gradle.kts | 5 + spring-security-jwt-auth-spring-boot-flow.png | Bin 0 -> 39757 bytes ...ity-refresh-token-jwt-spring-boot-flow.png | Bin 0 -> 38031 bytes ...SpringSecurityRefreshTokenApplication.java | 13 + .../security/jwt/advice/ErrorMessage.java | 33 ++ .../jwt/advice/TokenControllerAdvice.java | 25 ++ .../jwt/controllers/AuthController.java | 190 +++++++++++ .../jwt/controllers/TestController.java | 37 ++ .../jwt/exception/TokenRefreshException.java | 17 + .../kr/re/etri/security/jwt/models/ERole.java | 7 + .../security/jwt/models/RefreshToken.java | 58 ++++ .../kr/re/etri/security/jwt/models/Role.java | 39 +++ .../kr/re/etri/security/jwt/models/User.java | 89 +++++ .../jwt/payload/request/LoginRequest.java | 27 ++ .../jwt/payload/request/SignupRequest.java | 31 ++ .../jwt/payload/response/MessageResponse.java | 17 + .../payload/response/UserInfoResponse.java | 45 +++ .../repository/RefreshTokenRepository.java | 17 + .../jwt/repository/RoleRepository.java | 14 + .../jwt/repository/UserRepository.java | 17 + .../jwt/security/WebSecurityConfig.java | 104 ++++++ .../jwt/security/jwt/AuthEntryPointJwt.java | 43 +++ .../jwt/security/jwt/AuthTokenFilter.java | 60 ++++ .../security/jwt/security/jwt/JwtUtils.java | 119 +++++++ .../services/RefreshTokenService.java | 56 ++++ .../security/services/UserDetailsImpl.java | 103 ++++++ .../services/UserDetailsServiceImpl.java | 26 ++ .../security/jwt/swagger/OpenAPIConfig.java | 29 ++ src/main/resources/application.properties | 17 + ...gSecurityRefreshTokenApplicationTests.java | 13 + 44 files changed, 2560 insertions(+) create mode 100644 .gitignore create mode 100644 .mvn/wrapper/maven-wrapper.jar create mode 100644 .mvn/wrapper/maven-wrapper.properties create mode 100644 README.md create mode 100644 build.gradle.kts create mode 100644 gradle.properties create mode 100644 gradle/libs.versions.toml create mode 100644 gradle/wrapper/gradle-wrapper.jar create mode 100644 gradle/wrapper/gradle-wrapper.properties create mode 100644 gradlew create mode 100644 gradlew.bat create mode 100644 mvnw create mode 100644 mvnw.cmd create mode 100644 pom.xml create mode 100644 settings.gradle.kts create mode 100644 spring-security-jwt-auth-spring-boot-flow.png create mode 100644 spring-security-refresh-token-jwt-spring-boot-flow.png create mode 100644 src/main/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplication.java create mode 100644 src/main/java/kr/re/etri/security/jwt/advice/ErrorMessage.java create mode 100644 src/main/java/kr/re/etri/security/jwt/advice/TokenControllerAdvice.java create mode 100644 src/main/java/kr/re/etri/security/jwt/controllers/AuthController.java create mode 100644 src/main/java/kr/re/etri/security/jwt/controllers/TestController.java create mode 100644 src/main/java/kr/re/etri/security/jwt/exception/TokenRefreshException.java create mode 100644 src/main/java/kr/re/etri/security/jwt/models/ERole.java create mode 100644 src/main/java/kr/re/etri/security/jwt/models/RefreshToken.java create mode 100644 src/main/java/kr/re/etri/security/jwt/models/Role.java create mode 100644 src/main/java/kr/re/etri/security/jwt/models/User.java create mode 100644 src/main/java/kr/re/etri/security/jwt/payload/request/LoginRequest.java create mode 100644 src/main/java/kr/re/etri/security/jwt/payload/request/SignupRequest.java create mode 100644 src/main/java/kr/re/etri/security/jwt/payload/response/MessageResponse.java create mode 100644 src/main/java/kr/re/etri/security/jwt/payload/response/UserInfoResponse.java create mode 100644 src/main/java/kr/re/etri/security/jwt/repository/RefreshTokenRepository.java create mode 100644 src/main/java/kr/re/etri/security/jwt/repository/RoleRepository.java create mode 100644 src/main/java/kr/re/etri/security/jwt/repository/UserRepository.java create mode 100644 src/main/java/kr/re/etri/security/jwt/security/WebSecurityConfig.java create mode 100644 src/main/java/kr/re/etri/security/jwt/security/jwt/AuthEntryPointJwt.java create mode 100644 src/main/java/kr/re/etri/security/jwt/security/jwt/AuthTokenFilter.java create mode 100644 src/main/java/kr/re/etri/security/jwt/security/jwt/JwtUtils.java create mode 100644 src/main/java/kr/re/etri/security/jwt/security/services/RefreshTokenService.java create mode 100644 src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsImpl.java create mode 100644 src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsServiceImpl.java create mode 100644 src/main/java/kr/re/etri/security/jwt/swagger/OpenAPIConfig.java create mode 100644 src/main/resources/application.properties create mode 100644 src/test/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplicationTests.java diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..708dafd --- /dev/null +++ b/.gitignore @@ -0,0 +1,53 @@ +HELP.md +target/ +!.mvn/wrapper/maven-wrapper.jar +!**/src/main/**/target/ +!**/src/test/**/target/ + +### STS ### +.apt_generated +.classpath +.factorypath +.project +.settings +.springBeans +.sts4-cache + +### IntelliJ IDEA ### +.idea +*.iws +*.iml +*.ipr + +### NetBeans ### +/nbproject/private/ +/nbbuild/ +/dist/ +/nbdist/ +/.nb-gradle/ +build/ +!**/src/main/**/build/ +!**/src/test/**/build/ + +### VS Code ### +.vscode/ +logs/ +/deploy/ + +### Gradle ### +.gradle +bin/ +**/build/ +!src/**/build/ + +# Ignore Gradle GUI config +gradle-app.setting + +# Avoid ignoring Gradle wrapper jar file (.jar files are usually ignored) +!gradle-wrapper.jar + +# Avoid ignore Gradle wrappper properties +!gradle-wrapper.properties + +# Cache of project +.gradletasknamecache diff --git a/.mvn/wrapper/maven-wrapper.jar b/.mvn/wrapper/maven-wrapper.jar new file mode 100644 index 0000000000000000000000000000000000000000..c1dd12f17644411d6e840bd5a10c6ecda0175f18 GIT binary patch literal 58727 zcmb5W18`>1vNjyPv28mO+cqb*Z6_1kwr$(?#I}=(ZGUs`Jr}3`|DLbDUA3!L?dtC8 zUiH*ktDo+@6r@4HP=SCTA%WmZqm^Ro`Ls)bfPkcdfq?#g1(Fq27W^S8Cq^$TC?_c< zs-#ROD;6C)1wFuk7<3)nGuR^#!H;n&3*IjzXg+s8Z_S!!E0jUq(`}Itt=YdYa5Z_s z&e>2={87knpF*PKNzU;lsbk#P(l^WBvb$yEz)z+nYH43pKodrDkMp@h?;n{;K}hl>Fb^ zqx}C0|D7kg|Cj~3f7hn_zkAE}|6t|cZT|S5Hvb#3nc~C14u5UI{6#F<|FkJ0svs&S zA}S{=DXLT*BM1$`2rK%`D@vEw9l9%*=92X_2g?Fwfi=6Zfpr7+<~sgP#Bav+Df2ts zwtu~70zhqV?mrzM)}r7mMS`Hk_)NrI5K%CTtQtDxqw5iv5F0!ksIon{qqpPVnU?ds zN$|Vm{MHKEReUy>1kVfT-$3))Js0p2W_LFy3cjjZ7za0R zPdBH>y&pb0vr1|ckDpt2p$IQhwnPs5G*^b-y}sg4W!ALn}a`pY0JIa$H0$eV2T8WjWD= zWaENacQhlTyK4O!+aOXBurVR2k$eb8HVTCxy-bcHlZ4Xr!`juLAL#?t6|Ba!g9G4I zSwIt2Lla>C?C4wAZ8cKsZl9-Yd3kqE`%!5HlGdJJaFw0mu#--&**L-i|BcIdc3B$;0FC;FbE-dunVZ; zdIQ=tPKH4iJQQ=$5BeEMLov_Hn>gXib|9nOr}>eZt@B4W^m~>Zp#xhn1dax+?hS!AchWJ4makWZs@dQUeXQ zsI2+425_{X@t2KN zIbqec#)Jg5==VY3^YBeJ2B+%~^Y8|;F!mE8d(`UgNl2B9o>Ir5)qbBr)a?f%nrP zQyW(>FYPZjCVKDOU;Bw#PqPF1CCvp)dGdA&57a5hD&*vIc)jA)Z-!y5pS{5W6%#prH16zgD8s zexvpF#a|=*acp>L^lZ(PT)GiA8BJL-9!r8S$ZvXRKMVtiGe`+!@O%j<1!@msc177U zTDy>WOZu)W5anPrweQyjIu3IJC|ngdjZofGbdW&oj^DJlC7$;|xafB45evT|WBgGf-b|9y0J`fe0W-vw6xh}` z=(Tnq(-K0O{;VUcKe2y63{HXc+`R_#HLwnZ0rzWO*b#VeSuC4NG!H_ApCypbt1qx( z6y7Q$5(JOpQ&pTkc^0f}A0Kq*?;g9lEfzeE?5e2MBNZB)^8W1)YgdjsVyN+I9EZlh z3l}*}*)cFl=dOq|DvF=!ui$V%XhGQ%bDn3PK9 zV%{Y|VkAdt^d9~y4laGDqSwLd@pOnS&^@sI7}YTIb@El1&^_sq+{yAGf0|rq5TMp# z6d~;uAZ(fY3(eH=+rcbItl2=u6mf|P{lD4kiRCv;>GtFaHR3gim?WU9RjHmFZLm+m z+j<}_exaOQ1a}=K#voc~En+Mk_<(L!?1e#Uay~|H5q)LjD*yE6xFYQ-Wx{^iH1@pP zC0De#D6I26&W{;J40sZB!=%{c?XdO?YQvnTMA3TwfhAm@bvkX*(x?JTs*dFDv^=2X z284}AK)1nRn+8(Q2P?f)e>0~;NUI9%p%fnv1wBVpoXL+9OE`Vv1Y7=+nub$o7AN>y zB?R(^G8PYcMk4bxe7XItq@48QqWKb8fa*i9-N)=wdU-Q^=}!nFgTr_uT=Z=9pq z`{7!$U|+fnXFcsJ4GNm3JQQCN+G85k$)ZLhF{NbIy{REj84}Zt;0fe#>MARW)AoSb zrBpwF37ZVBMd>wZn_hAadI*xu8)Y#`aMbwRIA2n^-OS~M58_@j?#P1|PXJ1XBC9{4 zT^8*|xu<@(JlSOT*ILrVGr+7$nZN`Z3GxJJO@nY&mHsv^^duAh*lCu5q+S6zWA+`- z%^*y#)O7ko_RwGJl;bcEpP03FOrhlLWs`V_OUCrR-g>NJz*pN|itmN6O@Hw05Zq;Xtif%+sp4Py0{<7<^c zeoHHhRq>2EtYy9~2dZywm&OSk`u2ECWh6dJY?;fT-3-$U`!c(o$&hhPC%$~fT&bw3 zyj+8aXD;G!p*>BC6rpvx#6!|Qaic;KEv5>`Y+R(6F^1eIeYG6d1q3D3OL{7%7iw3R zwO)W7gMh27ASSB>-=OfP(YrKqBTNFv4hL@Im~~ombbSu44p~VoH$H-6+L_JW>Amkl zhDU~|r77?raaxD!-c$Ta?WAAi{w3T}YV=+S?1HQGC0+{Bny_^b+4Jum}oW4c=$ z#?D<}Ds{#d5v`L`${Pee;W84X*osNQ96xsKp^EAzuUh9#&zDX=eqdAp$UY)EGrkU% z(6m35n=46B$TNnejNSlih_!<)Iu@K!PW5S@Ya^0OK+EMWM=1w=GUKW^(r59U%i?d zzbo?|V4tDWGHHsrAQ}}ma#<`9r=M8%XF#%a=@Hn(p3wFBlkZ2L@8=*@J-^zuyF0aN zzJ7f!Jf8I+^6Tt$e+IIh zb80@?7y#Iz3w-0VEjgbHurqI>$qj<@n916)&O340!_5W9DtwR)P5mk6v2ljyK*DG5 zYjzE~m`>tq8HYXl%1JJ%e-%BqV4kRdPUZB1Cm$BQZr(fzp_@rn_W+;GwI$?L2Y4;b z)}c5D$#LT}2W8Si<`EHKIa_X+>+2PF(C*u~F=8E!jL(=IdQxY40%|( zoNg2Z&Aob@LEui-lJ#@)Ts)tE0_!*3{Uk)r{;-IZpX`N4mZX`#E|A;viQWImB6flI z?M_|xHCXV$5LOY-!U1_O1k;OWa=EchwlDCK4xHwBW2jE-6&%}og+9NILu${v10Z^Z#* zap|)B9a-AMU~>$r)3&|dQuP#MA$jnw54w*Ax~*_$iikp+j^OR8I5Fo<_UR#B-c>$? zeg)=;w^sGeAMi<3RGDRj$jA30Qq$e|zf2z;JyQ}tkU)ZI_k6tY%(`#AvL)p)iYXUy z5W9Su3NJ8mVyy)WqzFSk&vZM!;kUh8dVeA-myqcV%;xUne`PbHCPpvH?br`U2Y&dM zV!nJ!^n%`!H&!QSlpzLWnZpgi;#P0OAleH+<CfLa?&o|kyw1}W%6Pij zp$Vv5=;Z0LFN|j9i&9>zqX>*VnV3h#>n!2L?5gO6HJS3~kpy5G zYAVPMaB-FJOk3@OrxL(*-O~OB9^d{!G0K>wlzXuBm*$&%p1O#6SQ*?Q0CETLQ->XpfkW7< zj&Nep(}eAH1u$wWFvLV*lA{JOltP_%xKXC*a8DB&;{fD&2bATy>rC^kFY+$hFS7us;Y) zy_H?cv9XTHYz<4C<0b`WKC#{nJ15{F=oaq3x5}sYApT?Po+(Cmmo#dHZFO^{M#d~d znRT=TFATGVO%z_FNG-@G;9az|udZ>t@5l+A-K)BUWFn_|T#K3=d3EXRNqHyi#>;hX z*JQ`pT3#&tH>25laFlL6Rllu(seA*OboEd%rxMtz3@5v-+{qDP9&BcoS$2fgjgvp$ zc8!3=p0p@Ee1$u{Gg}Kkxg@M*qgZfYLlnD88{uwG1T?zxCbBR+x(RK$JB(eWJH#~; zZoY6L+esVRV?-*QmRCG}h`rB*Lv=uE%URF@+#l-g!Artx>Y9D;&G=jY2n2`J z{6-J%WX~Glx*QBmOOJ(RDRIzhfk&ibsm1t&&7aU{1P3U0uM%F2zJb4~50uby_ng+# zN)O9lK=dkJpxsUo7u8|e`Y~mmbxOTDn0i!i;d;ml#orN(Lc=j+n422NoSnlH6?0<0?th-qB7u}`5My%#?ES}>@RldOQz}WILz<$+cN~&ET zwUI01HCB((TyU$Ej8bxsE8oLmT-c7gA1Js?Iq`QMzIHV|)v)n2 zT_L(9x5%8*wU(C`VapaHoicWcm|0X@9TiNtbc|<4N6_H1F6&qgEEj=vjegFt;hC7- zLG7_=vedRFZ6Chbw!{#EpAlM?-sc#pc<~j#537n)M%RT)|L}y(ggi_-SLpsE3qi3V z=EEASxc>a{Su)jXcRS41Z@Mxk&0B7B<(?Izt5wpyyIBO|-M}ex8BhbIgi*X4 zDZ+Yk1<6&=PoZ=U-!9`!?sBVpYF#Y!JK<`fx}bXN651o0VVaW;t6ASVF@gq-mIDV_)?F^>rq1XX0NYy~(G=I6x%Fi5C2rMtvs z%P`g2>0{xLUy~#ye)%QAz^NkD5GUyPYl}K#;e-~UQ96`I$U0D!sMdQ>;%+c0h>k*Y z)sD1mi_@|rZnQ+zbWq~QxFlBQXj8WEY7NKaOYjUxAkGB8S#;l@b^C?;twRKl=mt0< zazifrBs`(q7_r14u1ZS`66VmsLpV>b5U!ktX>g4Nq~VPq6`%`3iCdr(>nS~uxxylU z>h(2p$XPJVh9BDpRLLzTDlNdp+oq8sOUlJ#{6boG`k)bwnsw5iy@#d{f_De-I|}vx6evw;ch97=;kLvM)-DBGwl6%fA%JItoMeyqjCR*_5Q70yd!KN zh=>ek8>f#~^6CJR0DXp0;7ifZjjSGBn}Cl{HeX!$iXMbtAU$F+;`%A<3TqbN#PCM& z&ueq$cB%pu2oMm_-@*aYzgn9`OiT@2ter*d+-$Aw42(@2Ng4mKG%M-IqX?q%3R|_( zN|&n$e1L#Ev=YMX5F53!O%))qDG3D(0rsOHblk;9ghWyqEOpg)mC$OduqpHAuIxr_>*|zy+|=EmOFn zFM+Ni%@CymLS-3vRWn=rVk?oZEz0V#y356IE6HR5#>7EigxZ05=cA|4<_tC8jyBJ| zgg!^kNwP7S^ooIj6riI9x`jFeQfRr4JCPumr<82M zto$j^Qb~MPmJ-|*2u{o7?yI8BI``zDaOCg2tG_5X;w<|uj5%oDthnLx-l4l)fmUGx z6N^jR|DC);yLi4q-ztTkf>*U$@2^w5(lhxu=OC|=WuTTp^!?2Nn27R`2FY_ zLHY-zFS}r+4|XyZw9b0D3)DmS!Gr+-LSdI}m{@-gL%^8CFSIYL?UZaCVd)2VI3|ay zwue39zshVrB+s2lp*};!gm<79@0HkjhgF^>`UhoR9Mi`aI#V#fI@x&1K3f&^8kaq% zkHVg$CTBoaGqEjrL)k*Y!rtiD2iQLYZ%|B}oBl8GHvR%n>HiIQN*+$mCN>I=c7H2N z&K4$4e@E^ff-cVHCbrHNMh4Dy|2Q;M{{xu|DYjeaRh2FK5QK!bG_K`kbBk$l$S4UF zq?F-%7UrX_Q?9M)a#WvcZ^R-fzJB5IFP>3uEoeCAAhN5W-ELRB&zsCnWY6#E?!)E56Pe+bxHjGF6;R9Hps)+t092-bf4 z_Wieg+0u5JL++k)#i0r?l`9*k)3ZlHOeMJ1DTdx9E1J2@BtdD3qX;&S_wMExOGv$T zl^T%oxb+)vq6vJvR`8{+YOsc@8}wSXpoK%v0k@8X*04Se3<8f)rE|fRXAoT!$6MdrKSuzeK@L*yug?MQs8oTbofqW)Df# zC2J3irHAaX_e~SGlBoRhEW`W6Z}&YX|5IMfzskAt{B*m z*w=3i!;x5Gfgc~>y9fPXFAPMhO@Si}SQESjh`P|dlV5HPRo7j(hV=$o8UMIT7~7+k z*@Sd>f%#{ARweJYhQs~ECpHie!~YXL|FJA;KS4m|CKFnT{fN`Ws>N?CcV@(>7WMPYN} z1}Wg+XU2(Yjpq7PJ|aSn;THEZ{4s8*@N!dz&bjys_Zk7%HiD+56;cF26`-a zEIo!B(T|L*uMXUvqJs&54`^@sUMtH-i~rOM9%$xGXTpmow$DxI>E5!csP zAHe|);0w%`I<==_Zw9t$e}?R+lIu%|`coRum(1p~*+20mBc?Z=$+z<0n&qS0-}|L4 zrgq|(U*eB%l3nfC=U1Y?(Tf@0x8bhdtsU2w&Y-WvyzkiyJ>GZqUP6c+<_p0`ZOnIK z#a~ynuzRWxO6c;S@*}B1pTjLJQHi(+EuE2;gG*p^Fq%6UoE1x95(^BY$H$$soSf=vpJ)_3E zp&$l=SiNaeoNLAK8x%XaHp3-So@F7 z3NMRRa@%k+Z$a%yb25ud&>Cdcb<+}n>=jZ`91)a z{wcA(j$%z#RoyB|&Z+B4%7Pe*No`pAX0Y;Ju4$wvJE{VF*Qej8C}uVF=xFpG^rY6Y+9mcz$T9^x(VP3uY>G3Zt&eU{pF*Bu<4j9MPbi4NMC=Z$kS6DMW9yN#vhM&1gd1t}8m(*YY9 zh2@s)$1p4yYT`~lYmU>>wKu+DhlnI1#Xn4(Rnv_qidPQHW=w3ZU!w3(@jO*f;4;h? zMH0!08(4=lT}#QA=eR(ZtW1=~llQij7)L6n#?5iY_p>|_mLalXYRH!x#Y?KHyzPB^ z6P3YRD}{ou%9T%|nOpP_??P;Rmra7$Q*Jz-f?42PF_y>d)+0Q^)o5h8@7S=je}xG# z2_?AdFP^t{IZHWK)9+EE_aPtTBahhUcWIQ7Awz?NK)ck2n-a$gplnd4OKbJ;;tvIu zH4vAexlK2f22gTALq5PZ&vfFqqERVT{G_d`X)eGI%+?5k6lRiHoo*Vc?ie6dx75_t z6hmd#0?OB9*OKD7A~P$e-TTv3^aCdZys6@`vq%Vi_D8>=`t&q9`Jn1=M#ktSC>SO3 z1V?vuIlQs6+{aHDHL?BB&3baSv;y#07}(xll9vs9K_vs2f9gC9Biy+9DxS77=)c z6dMbuokO-L*Te5JUSO$MmhIuFJRGR&9cDf)@y5OQu&Q$h@SW-yU&XQd9;_x;l z<`{S&Hnl!5U@%I~5p)BZspK894y7kVQE7&?t7Z|OOlnrCkvEf7$J5dR?0;Jt6oANc zMnb_Xjky|2ID#fhIB2hs-48Er>*M?56YFnjC)ixiCes%fgT?C|1tQupZ0Jon>yr|j z6M66rC(=;vw^orAMk!I1z|k}1Ox9qOILGJFxU*ZrMSfCe?)wByP=U73z+@Pfbcndc=VzYvSUnUy z+-B+_n`=f>kS8QBPwk+aD()=#IqkdxHPQMJ93{JGhP=48oRkmJyQ@i$pk(L&(p6<0 zC9ZEdO*i+t`;%(Ctae(SjV<@i%r5aune9)T4{hdzv33Uo9*K=V18S$6VVm^wgEteF za0zCLO(9~!U9_z@Qrh&rS|L0xG}RWoE1jXiEsrTgIF4qf#{0rl zE}|NGrvYLMtoORV&FWaFadDNCjMt|U8ba8|z&3tvd)s7KQ!Od*Kqe(48&C7=V;?`SQV)Qc?6L^k_vNUPbJ>>!5J?sDYm5kR&h_RZk)MfZ1 znOpQ|T;Me(%mdBJR$sbEmp3!HKDDSmMDnVpeo{S13l#9e6OImR$UPzjd-eCwmMwyT zm5~g6DIbY<_!8;xEUHdT(r_OQ<6QCE9Jy|QLoS>d(B zW6GRzX)~&Mx}})ITysFzl5_6JM*~ciBfVP(WF_r zY>z4gw&AxB%UV3Y{Y6z*t*o!p@~#u3X_t{Q9Us8ar8_9?N% zN&M~6y%2R(mAZ~@Tg1Oapt?vDr&fHuJ=V$wXstq|)eIG_4lB#@eU>fniJh zwJY<8yH5(+SSQ=$Y=-$2f$@^Ak#~kaR^NYFsi{XGlFCvK(eu{S$J(owIv17|p-%0O zL-@NyUg!rx0$Uh~JIeMX6JJE>*t<7vS9ev#^{AGyc;uio_-Je1?u#mA8+JVczhA2( zhD!koe;9$`Qgaxlcly4rdQ1VlmEHUhHe9TwduB+hm3wH2o27edh?|vrY{=;1Doy4& zIhP)IDd91@{`QQqVya(ASth4}6OY z-9BQj2d-%+-N7jO8!$QPq%o$9Fy8ja{4WT$gRP+b=Q1I48g-g|iLNjbhYtoNiR*d- z{sB}~8j*6*C3eM8JQj5Jn?mD#Gd*CrVEIDicLJ-4gBqUwLA-bp58UXko;M|ql+i5` zym-&U5BIS9@iPg#fFbuXCHrprSQKRU0#@yd%qrX1hhs*85R}~hahfFDq=e@bX))mf zWH%mXxMx|h5YhrTy;P_Xi_IDH*m6TYv>|hPX*_-XTW0G9iu!PqonQneKKaCVvvF^% zgBMDpN7!N?|G5t`v{neLaCFB{OyIl>qJQ_^0MJXQ zY2%-si~ej?F^%ytIIHU(pqT+3d+|IQ{ss#!c91R{2l*00e3ry!ha|XIsR%!q=E^Fal`6Oxu`K0fmPM?P6ZgzH7|TVQhl;l2 z)2w0L9CsN-(adU5YsuUw19OY_X69-!=7MIJ^(rUNr@#9l6aB8isAL^M{n2oD0FAHk97;X* z-INjZ5li`a|NYNt9gL2WbKT!`?%?lB^)J)9|025nBcBtEmWBRXQwi21EGg8>!tU>6Wf}S3p!>7vHNFSQR zgC>pb^&OHhRQD~7Q|gh5lV)F6i++k4Hp_F2L2WrcxH&@wK}QgVDg+y~o0gZ=$j&^W zz1aP8*cvnEJ#ffCK!Kz{K>yYW`@fc8ByF9X4XmyIv+h!?4&$YKl*~`ToalM{=Z_#^ zUs<1Do+PA*XaH;&0GW^tDjrctWKPmCF-qo7jGL)MK=XP*vt@O4wN1Y!8o`{DN|Rh) znK?nvyU&`ATc@U*l}=@+D*@l^gYOj&6SE|$n{UvyPwaiRQ_ua2?{Vfa|E~uqV$BhH z^QNqA*9F@*1dA`FLbnq;=+9KC@9Mel*>6i_@oVab95LHpTE)*t@BS>}tZ#9A^X7nP z3mIo+6TpvS$peMe@&=g5EQF9Mi9*W@Q`sYs=% z`J{3llzn$q;2G1{N!-#oTfQDY`8>C|n=Fu=iTk443Ld>>^fIr4-!R3U5_^ftd>VU> zij_ix{`V$I#k6!Oy2-z#QFSZkEPrXWsYyFURAo`Kl$LkN>@A?_);LE0rZIkmjb6T$ zvhc#L-Cv^4Ex*AIo=KQn!)A4;7K`pu-E+atrm@Cpmpl3e>)t(yo4gGOX18pL#xceU zbVB`#5_@(k{4LAygT1m#@(7*7f5zqB)HWH#TCrVLd9}j6Q>?p7HX{avFSb?Msb>Jg z9Q9DChze~0Psl!h0E6mcWh?ky! z$p#@LxUe(TR5sW2tMb#pS1ng@>w3o|r~-o4m&00p$wiWQ5Sh-vx2cv5nemM~Fl1Pn z@3ALEM#_3h4-XQ&z$#6X&r~U-&ge+HK6$)-`hqPj0tb|+kaKy*LS5@a9aSk!=WAEB z7cI`gaUSauMkEbg?nl0$44TYIwTngwzvUu0v0_OhpV;%$5Qgg&)WZm^FN=PNstTzW z5<}$*L;zrw>a$bG5r`q?DRc%V$RwwnGIe?m&(9mClc}9i#aHUKPLdt96(pMxt5u`F zsVoku+IC|TC;_C5rEU!}Gu*`2zKnDQ`WtOc3i#v}_9p>fW{L4(`pY;?uq z$`&LvOMMbLsPDYP*x|AVrmCRaI$UB?QoO(7mlBcHC};gA=!meK)IsI~PL0y1&{Dfm6! zxIajDc1$a0s>QG%WID%>A#`iA+J8HaAGsH z+1JH=+eX5F(AjmZGk|`7}Gpl#jvD6_Z!&{*kn@WkECV-~Ja@tmSR|e_L@9?N9 z3hyyry*D0!XyQh_V=8-SnJco#P{XBd1+7<5S3FA)2dFlkJY!1OO&M7z9uO?$#hp8K z><}uQS-^-B;u7Z^QD!7#V;QFmx0m%{^xtl3ZvPyZdi;^O&c;sNC4CHxzvvOB8&uHl zBN;-lu+P=jNn`2k$=vE0JzL{v67psMe_cb$LsmVfxA?yG z^q7lR00E@Ud3)mBPnT0KM~pwzZiBREupva^PE3~e zBgQ9oh@kcTk2)px3Hv^VzTtMzCG?*X(TDZ1MJ6zx{v- z;$oo46L#QNjk*1przHSQn~Ba#>3BG8`L)xla=P{Ql8aZ!A^Z6rPv%&@SnTI7FhdzT z-x7FR0{9HZg8Bd(puRlmXB(tB?&pxM&<=cA-;RT5}8rI%~CSUsR^{Dr%I2WAQghoqE5 zeQ874(T`vBC+r2Mi(w`h|d zA4x%EfH35I?h933@ic#u`b+%b+T?h=<}m@x_~!>o35p|cvIkkw07W=Ny7YcgssA_^ z|KJQrnu||Nu9@b|xC#C5?8Pin=q|UB?`CTw&AW0b)lKxZVYrBw+whPwZJCl}G&w9r zr7qsqm>f2u_6F@FhZU0%1Ioc3X7bMP%by_Z?hds`Q+&3P9-_AX+3CZ=@n!y7udAV2 zp{GT6;VL4-#t0l_h~?J^;trk1kxNAn8jdoaqgM2+mL&?tVy{I)e`HT9#Tr}HKnAfO zAJZ82j0+49)E0+=x%#1_D;sKu#W>~5HZV6AnZfC`v#unnm=hLTtGWz+21|p)uV+0= zDOyrLYI2^g8m3wtm-=pf^6N4ebLJbV%x`J8yd1!3Avqgg6|ar z=EM0KdG6a2L4YK~_kgr6w5OA;dvw0WPFhMF7`I5vD}#giMbMzRotEs&-q z^ji&t1A?l%UJezWv?>ijh|$1^UCJYXJwLX#IH}_1K@sAR!*q@j(({4#DfT|nj}p7M zFBU=FwOSI=xng>2lYo5*J9K3yZPwv(=7kbl8Xv0biOba>vik>6!sfwnH(pglq1mD-GrQi8H*AmfY*J7&;hny2F zupR}4@kzq+K*BE%5$iX5nQzayWTCLJ^xTam-EEIH-L2;huPSy;32KLb>>4 z#l$W^Sx7Q5j+Sy*E;1eSQQuHHWOT;1#LjoYpL!-{7W3SP4*MXf z<~>V7^&sY|9XSw`B<^9fTGQLPEtj=;<#x^=;O9f2{oR+{Ef^oZ z@N>P$>mypv%_#=lBSIr_5sn zBF-F_WgYS81vyW6$M;D_PoE&%OkNV1&-q+qgg~`A7s}>S`}cn#E$2m z%aeUXwNA(^3tP=;y5%pk#5Yz&H#AD`Jph-xjvZm_3KZ|J>_NR@croB^RUT~K;Exu5%wC}1D4nov3+@b8 zKyU5jYuQ*ZpTK23xXzpN51kB+r*ktnQJ7kee-gP+Ij0J_#rFTS4Gux;pkVB;n(c=6 zMks#)ZuXUcnN>UKDJ-IP-u2de1-AKdHxRZDUGkp)0Q#U$EPKlSLQSlnq)OsCour)+ zIXh@3d!ImInH7VrmR>p8p4%n;Tf6l2jx1qjJu>e3kf5aTzU)&910nXa-g0xn$tFa& z2qZ7UAl*@5o=PAh`6L${6S-0?pe3thPB4pahffb$#nL8ncN(Nyos`}r{%{g64Ji^= zK8BIywT0-g4VrhTt}n~Y;3?FGL74h?EG*QfQy0A8u>BtXuI{C-BYu*$o^}U1)z;8d zVN(ssw?oCbebREPD~I$-t7}`_5{{<0d10So7Pc2%EREdpMWIJI&$|rq<0!LL+BQM4 zn7)cq=qy|8YzdO(?NOsVRk{rW)@e7g^S~r^SCawzq3kj#u(5@C!PKCK0cCy zT@Tey2IeDYafA2~1{gyvaIT^a-Yo9kx!W#P-k6DfasKEgFji`hkzrmJ#JU^Yb%Nc~ zc)+cIfTBA#N0moyxZ~K!`^<>*Nzv-cjOKR(kUa4AkAG#vtWpaD=!Ku&;(D#(>$&~B zI?V}e8@p%s(G|8L+B)&xE<({g^M`#TwqdB=+oP|5pF3Z8u>VA!=w6k)zc6w2=?Q2` zYCjX|)fRKI1gNj{-8ymwDOI5Mx8oNp2JJHG3dGJGg!vK>$ji?n>5qG)`6lEfc&0uV z)te%G&Q1rN;+7EPr-n8LpNz6C6N0*v{_iIbta7OTukSY zt5r@sO!)rjh0aAmShx zd3=DJ3c(pJXGXzIh?#RR_*krI1q)H$FJ#dwIvz);mn;w6Rlw+>LEq4CN6pP4AI;!Y zk-sQ?O=i1Mp5lZX3yka>p+XCraM+a!1)`F`h^cG>0)f0OApGe(^cz-WoOno-Y(EeB zVBy3=Yj}ak7OBj~V259{&B`~tbJCxeVy@OEE|ke4O2=TwIvf-=;Xt_l)y`wuQ-9#D z(xD-!k+2KQzr`l$7dLvWf*$c8=#(`40h6d$m6%!SB1JzK+tYQihGQEwR*-!cM>#LD>x_J*w(LZbcvHW@LTjM?RSN z0@Z*4$Bw~Ki3W|JRI-r3aMSepJNv;mo|5yDfqNLHQ55&A>H5>_V9<_R!Ip`7^ylX=D<5 zr40z>BKiC@4{wSUswebDlvprK4SK2!)w4KkfX~jY9!W|xUKGTVn}g@0fG94sSJGV- z9@a~d2gf5s>8XT@`If?Oway5SNZS!L5=jpB8mceuf2Nd%aK2Zt|2FVcg8~7O{VPgI z#?H*_Kl!9!B}MrK1=O!Aw&faUBluA0v#gWVlAmZt;QN7KC<$;;%p`lmn@d(yu9scs zVjomrund9+p!|LWCOoZ`ur5QXPFJtfr_b5%&Ajig2dI6}s&Fy~t^j}()~4WEpAPL= zTj^d;OoZTUf?weuf2m?|R-7 z*C4M6ZhWF(F@2}nsp85rOqt+!+uZz3$ReX#{MP5-r6b`ztXDWl$_mcjFn*{sEx7f*O(ck+ou8_?~a_2Ztsq6qB|SPw26k!tLk{Q~Rz z$(8F1B;zK-#>AmmDC7;;_!;g&CU7a?qiIT=6Ts0cbUNMT6yPRH9~g zS%x{(kxYd=D&GKCkx;N21sU;OI8@4vLg2}L>Lb{Qv`B*O0*j>yJd#`R5ypf^lp<7V zCc|+>fYgvG`ROo>HK+FAqlDm81MS>&?n2E-(;N7}oF>3T9}4^PhY=Gm`9i(DPpuS- zq)>2qz!TmZ6q8;&M?@B;p1uG6RM_Y8zyId{-~XQD_}bXL{Jp7w`)~IR{l5a2?7!Vg zp!OfP4E$Ty_-K3VY!wdGj%2RL%QPHTL)uKfO5Am5<$`5 zHCBtvI~7q-ochU`=NJF*pPx@^IhAk&ZEA>w$%oPGc-}6~ywV~3-0{>*sb=|ruD{y$ ze%@-m`u28vKDaf*_rmN`tzQT>&2ltg-lofR8~c;p;E@`zK!1lkgi?JR0 z+<61+rEupp7F=mB=Ch?HwEjuQm}1KOh=o@ zMbI}0J>5}!koi&v9?!B?4FJR88jvyXR_v{YDm}C)lp@2G2{a{~6V5CwSrp6vHQsfb-U<{SSrQ zhjRbS;qlDTA&TQ2#?M(4xsRXFZ^;3A+_yLw>o-9GJ5sgsauB`LnB-hGo9sJ~tJ`Q>=X7sVmg<=Fcv=JDe*DjP-SK-0mJ7)>I zaLDLOU*I}4@cro&?@C`hH3tiXmN`!(&>@S2bFyAvI&axlSgd=!4IOi#+W;sS>lQ28 zd}q&dew9=x;5l0kK@1y9JgKWMv9!I`*C;((P>8C@JJRGwP5EL;JAPHi5fI|4MqlLU z^4D!~w+OIklt7dx3^!m6Be{Lp55j{5gSGgJz=hlNd@tt_I>UG(GP5s^O{jFU;m~l0 zfd`QdE~0Ym=6+XN*P`i0ogbgAJVjD9#%eBYJGIbDZ4s(f-KRE_>8D1Dv*kgO1~NSn zigx8f+VcA_xS)V-O^qrs&N9(}L!_3HAcegFfzVAntKxmhgOtsb4k6qHOpGWq6Q0RS zZO=EomYL%;nKgmFqxD<68tSGFOEM^u0M(;;2m1#4GvSsz2$jawEJDNWrrCrbO<}g~ zkM6516erswSi_yWuyR}}+h!VY?-F!&Y5Z!Z`tkJz&`8AyQ=-mEXxkQ%abc`V1s>DE zLXd7!Q6C)`7#dmZ4Lm?>CTlyTOslb(wZbi|6|Pl5fFq3y^VIzE4DALm=q$pK>-WM> z@ETsJj5=7=*4 z#Q8(b#+V=~6Gxl?$xq|?@_yQJ2+hAYmuTj0F76c(B8K%;DPhGGWr)cY>SQS>s7%O- zr6Ml8h`}klA=1&wvbFMqk}6fml`4A%G=o@K@8LHifs$)}wD?ix~Id@9-`;?+I7 zOhQN(D)j=^%EHN16(Z3@mMRM5=V)_z(6y^1b?@Bn6m>LUW7}?nupv*6MUVPSjf!Ym zMPo5YoD~t(`-c9w)tV%RX*mYjAn;5MIsD?0L&NQ#IY`9k5}Fr#5{CeTr)O|C2fRhY z4zq(ltHY2X)P*f?yM#RY75m8c<%{Y?5feq6xvdMWrNuqnR%(o(uo8i|36NaN<#FnT ze-_O*q0DXqR>^*1sAnsz$Ueqe5*AD@Htx?pWR*RP=0#!NjnaE-Gq3oUM~Kc9MO+o6 z7qc6wsBxp7GXx+hwEunnebz!|CX&`z{>loyCFSF-zg za}zec;B1H7rhGMDfn+t9n*wt|C_0-MM~XO*wx7-`@9~-%t?IegrHM(6oVSG^u?q`T zO<+YuVbO2fonR-MCa6@aND4dBy^~awRZcp!&=v+#kH@4jYvxt=)zsHV0;47XjlvDC8M1hSV zm!GB(KGLwSd{F-?dmMAe%W0oxkgDv8ivbs__S{*1U}yQ=tsqHJYI9)jduSKr<63$> zp;a-B^6Hg3OLUPi1UwHnptVSH=_Km$SXrCM2w8P z%F#Boi&CcZ5vAGjR1axw&YNh~Q%)VDYUDZ6f^0;>W7_sZr&QvRWc2v~p^PqkA%m=S zCwFUg2bNM(DaY>=TLmOLaDW&uH;Za?8BAwQo4+Xy4KXX;Z}@D5+}m)U#o?3UF}+(@jr$M4ja*`Y9gy~Y`0 z6Aex1*3ng@2er)@{%E9a3A;cts9cAor=RWt7ege)z=$O3$d5CX&hORZ3htL>jj5qT zW#KGQ;AZ|YbS0fvG~Y)CvVwXnBLJkSps7d~v;cj$D3w=rB9Tx>a&4>(x00yz!o*SOd*M!yIwx;NgqW?(ysFv8XLxs6Lrh8-F`3FO$}V{Avztc4qmZ zoz&YQR`*wWy_^&k-ifJ&N8Qh=E-fH6e}-}0C{h~hYS6L^lP>=pLOmjN-z4eQL27!6 zIe2E}knE;dxIJ_!>Mt|vXj%uGY=I^8(q<4zJy~Q@_^p@JUNiGPr!oUHfL~dw9t7C4I9$7RnG5p9wBpdw^)PtGwLmaQM=KYe z;Dfw@%nquH^nOI6gjP+K@B~0g1+WROmv1sk1tV@SUr>YvK7mxV3$HR4WeQ2&Y-{q~ z4PAR&mPOEsTbo~mRwg&EJE2Dj?TOZPO_@Z|HZX9-6NA!%Pb3h;G3F5J+30BoT8-PU z_kbx`I>&nWEMtfv(-m>LzC}s6q%VdBUVI_GUv3@^6SMkEBeVjWplD5y58LyJhikp4VLHhyf?n%gk0PBr(PZ3 z+V`qF971_d@rCO8p#7*#L0^v$DH>-qB!gy@ut`3 zy3cQ8*t@@{V7F*ti(u{G4i55*xY9Erw3{JZ8T4QPjo5b{n=&z4P^}wxA;x85^fwmD z6mEq9o;kx<5VneT_c-VUqa|zLe+BFgskp_;A)b>&EDmmP7Gx#nU-T@;O+(&&n7ljK zqK7&yV!`FIJAI+SaA6y=-H=tT`zWvBlaed!3X^_Lucc%Q=kuiG%65@@6IeG}e@`ieesOL} zKHBJBso6u&7gzlrpB%_yy<>TFwDI>}Ec|Gieb4=0fGwY|3YGW2Dq46=a1 zVo`Vi%yz+L9)9hbb%FLTC@-G(lODgJ(f&WmSCK9zV3-IV7XI<{2j}ms_Vmb!os)06 zhVIZPZF)hW--kWTCyDVRd2T&t|P&aDrtO5kzXy<*A+5$k7$>4+y%;% znYN-t#1^#}Z6d+ahj*Gzor+@kBD7@f|IGNR$4U=Y0J2#D2)YSxUCtiC1weJg zLp0Q&JFrt|In8!~1?fY0?=fPyaqPy$iQXJDhHP>N%B42Yck`Qz-OM_~GMuWow)>=Q z0pCCC7d0Z^Ipx29`}P3;?b{dO?7z0e{L|O*Z}nxi>X|RL8XAw$1eOLKd5j@f{RQ~Y zG?7$`hy@s7IoRF2@KA%2ZM6{ru9T5Gj)iDCz};VvlG$WuT+>_wCTS~J6`I9D{nsrU z2;X#OyopBgo778Q>D%_E>rMN~Po~d5H<`8|Zcv}F`xL5~NCVLX4Wkg007HhMgj9Pa z94$km3A+F&LzOJlpeFR*j+Y%M!Qm42ziH~cKM&3b;15s)ycD@3_tL-dk{+xP@J7#o z-)bYa-gd2esfy<&-nrj>1{1^_L>j&(MA1#WNPg3UD?reL*}V{ag{b!uT755x>mfbZ z0PzwF+kx91`qqOn`1>xw@801XAJlH>{`~|pyi6J;3s=cTOfelA&K5HX#gBp6s<|r5 zjSSj+CU*-TulqlnlP`}?)JkJ_7fg){;bRlXf+&^e8CWwFqGY@SZ=%NmLCXpYb+}7* z$4k}%iFUi^kBdeJg^kHt)f~<;Ovlz!9frq20cIj>2eIcG(dh57ry;^E^2T)E_8#;_9iJT>4sdCB_db|zO?Z^*lBN zNCs~f+Jkx%EUgkN2-xFF?B%TMr4#)%wq?-~+Nh;g9=n3tM>i5ZcH&nkVcPXgYRjG@ zf(Y7WN@hGV7o0bjx_2@bthJ`hjXXpfaes_(lWIw!(QK_nkyqj?{j#uFKpNVpV@h?7_WC3~&%)xHR1kKo`Cypj15#%0m z-o0GXem63g^|IltM?eZV=b+Z2e8&Z1%{0;*zmFc62mNqLTy$Y_c|9HiH0l>K z+mAx7DVYoHhXfdCE8Bs@j=t0f*uM++Idd25BgIm`Ad;I_{$mO?W%=JF82blr8rl>yMk6?pM z^tMluJ-ckG_}OkxP91t2o>CQ_O8^VZn$s$M_APWIXBGBq0Lt^YrTD5(Vwe2ta4y#DEYa(W~=eLOy7rD^%Vd$kL27M)MSpwgoP3P{ z!yS$zc|uP{yzaIqCwE!AfYNS;KW|OdP1Q%!LZviA0e^WDsIS5#= z!B{TW)VB)VHg{LoS#W7i6W>*sFz!qr^YS0t2kh90y=Je5{p>8)~D@dLS@QM(F# zIp{6M*#(@?tsu1Rq-Mdq+eV}ibRSpv#976C_5xlI`$#1tN`sK1?)5M+sj=OXG6dNu zV1K{y>!i0&9w8O{a>`IA#mo(3a zf*+Q=&HW7&(nX8~C1tiHZj%>;asBEp$p_Q!@Y0T8R~OuPEy3Lq@^t$8=~(FhPVmJJ z#VF8`(fNzK-b%Iin7|cxWP0xr*M&zoz|fCx@=Y!-0j_~cuxsDHHpmSo)qOalZ$bRl z2F$j0k3llJ$>28HH3l_W(KjF^!@LwtLej_b9;i;{ku2x+&WA@jKTO0ad71@_Yta!{ z2oqhO4zaU433LK371>E{bZ?+3kLZ9WQ2+3PTZAP90%P13Yy3lr3mhmy|>eN6(SHs1C%Q39p)YsUr7(kuaoIJGJhXV-PyG zjnxhcAC;fqY@6;MWWBnRK6ocG`%T&0&*k95#yK7DFtZV?;cy;!RD_*YJjsb6Q`$;K zy)&X{P`*5xEgjTQ9r=oh0|>Z_yeFm?ev!p z7q;JA4mtu@qa39v%6i)Z4%qwdxcHuOMO;a1wFMP_290FqH1OsmCG{ zq^afYrz2BQyQ0*JGE}1h!W9fKgk$b!)|!%q(1x?5=}PpmZQ$e;2EB*k4%+&+u;(E* z2n@=9HsqMv;4>Nn^2v&@4T-YTkd`TdWU^U*;sA5|r7TjZGnLY*xC=_K-GmDfkWEGC z;oN&!c1xB-<4J7=9 zJ(BedZwZhG4|64<=wvCn4)}w%Zx_TEs6ehmjVG&p5pi46r zg=3-3Q~;v55KR&8CfG;`Lv6NsXB}RqPVyNeKAfj9=Ol>fQlEUl2cH7=mPV!68+;jgtKvo5F#8&9m? z``w+#S5UR=QHFGM~noocC zVFa#v2%oo{%;wi~_~R2ci}`=B|0@ zinDfNxV3%iHIS(7{h_WEXqu!v~`CMH+7^SkvLe_3i}=pyDRah zN#L)F-`JLj6BiG}sj*WBmrdZuVVEo86Z<6VB}s)T$ZcWvG?i0cqI}WhUq2Y#{f~x# zi1LjxSZCwiKX}*ETGVzZ157=jydo*xC^}mJ<+)!DDCd4sx?VM%Y;&CTpw5;M*ihZ| zJ!FBJj0&j&-oJs?9a_I$;jzd%7|pdsQ3m`bPBe$nLoV1!YV8?Pw~0D zmSD-5Ue60>L$Rw;yk{_2d~v@CnvZa%!7{{7lb$kxWx!pzyh;6G~RbN5+|mFTbxcxf!XyfbLI^zMQSb6P~xzESXmV{9 zCMp)baZSz%)j&JWkc|Gq;_*$K@zQ%tH^91X2|Byv>=SmWR$7-shf|_^>Ll;*9+c(e z{N%43;&e8}_QGW+zE0m0myb-@QU%=Qo>``5UzB(lH0sK=E``{ZBl2Ni^-QtDp0ME1 zK88E-db_XBZQaU}cuvkCgH7crju~9eE-Y`os~0P-J=s;aS#wil$HGdK;Ut?dSO71ssyrdm{QRpMAV2nXslvlIE#+Oh>l7y_~?;}F!;ENCR zO+IG#NWIRI`FLntsz^FldCkky2f!d-%Pij9iLKr>IfCK);=}}?(NL%#4PfE(4kPQN zSC%BpZJ*P+PO5mHw0Wd%!zJsn&4g<$n#_?(=)JnoR2DK(mCPHp6e6VdV>?E5KCUF@ zf7W9wm%G#Wfm*NxTWIcJX-qtR=~NFxz4PSmDVAU8(B2wIm#IdHae-F{3jKQFiX?8NlKEhXR2Z|JCUd@HMnNVwqF~V9YJtD+T zQlOroDX-mg2% zBKV^Q5m5ECK{nWjJ7FHOSUi*a-C_?S_yo~G5HuRZH6R``^dS3Bh6u!nD`kFbxYThD zw~2%zL4tHA26rcdln4^=A(C+f9hLlcuMCv{8`u;?uoEVbU=YVNkBP#s3KnM@Oi)fQ zt_F3VjY)zASub%Q{Y?XgzlD3M5#gUBUuhW;$>uBSJH9UBfBtug*S|-;h?|L#^Z&uE zB&)spqM89dWg9ZrXi#F{KtL@r9g^xeR8J+$EhL~2u@cf`dS{8GUC76JP0hHtCKRg0 zt*rVyl&jaJAez;!fb!yX^+So4-8XMNpP@d3H*eF%t_?I|zN^1Iu5aGBXSm+}eCqn3 z^+vzcM*J>wV-FJRrx@^5;l>h0{OYT)lg{dr8!{s7(i{5T|3bivDoTonV1yo1@nVPR zXxEgGg^x5KHgp?=$xBwm_cKHeDurCgO>$B$GSO`Cd<~J8@>ni>Z-Ef!3+ck(MHVy@ z@#<*kCOb5S$V+Fvc@{Qv$oLfnOAG&YO5z_E2j6E z7a+c(>-`H)>g+6DeY1Y*ag-B6>Cl@@VhkZY@Uihe!{LlRpuTsmIsN4;+UDsHd954n9WZV6qq*{qZ5j<W)`UorOmXtVnLo3T{t#h3q^fooqQ~A+EY<$TDG4RKP*cK0liX95STt= zToC<2M2*(H1tZ)0s|v~iSAa^F-9jMwCy4cK0HM*3$@1Q`Pz}FFYm`PGP0wuamWrt*ehz3(|Fn%;0;K4}!Q~cx{0U0L=cs6lcrY^Y%Vf_rXpQIw~DfxB-72tZU6gdK8C~ea6(2P@kGH}!2N?>r(Ca{ zsI!6B!alPl%j1CHq97PTVRng$!~?s2{+6ffC#;X2z(Xb#9GsSYYe@9zY~7Dc7Hfgh z5Tq!})o30pA3ywg<9W3NpvUs;E%Cehz=s?EfLzcV0H?b{=q?vJCih2y%dhls6w3j$ zk9LB0L&(15mtul3T^QSK7KIZVTod#Sc)?1gzY~M=?ay87V}6G?F>~AIv()-N zD3rHX`;r;L{9N|Z8REN}OZB&SZ|5a80B%dQd-CNESP7HnuNn43T~Agcl1YOF@#W03 z1b*t!>t5G@XwVygHYczDIC|RdMB+ z$s5_5_W-EXN-u_5Pb{((!+8xa+?@_#dwtYHeJ_49Dql%3Fv0yXeV?!cC&Iqx@s~P%$X6%1 zYzS9pqaUv&aBQqO zBQs7d63FZIL1B&<8^oni%CZOdf6&;^oNqQ-9j-NBuQ^|9baQuZ^Jtyt&?cHq$Q9JE z5D>QY1?MU7%VVbvjysl~-a&ImiE(uFwHo{!kp;Jd`OLE!^4k8ID{`e-&>2uB7XB~= z+nIQGZ8-Sbfa}OrVPL}!mdieCrs3Nq8Ic_lpTKMIJ{h>XS$C3`h~ z?p2AbK~%t$t(NcOq5ZB3V|`a0io8A))v_PMt)Hg3x+07RL>i zGUq@t&+VV`kj55_snp?)Y@0rKZr`riC`9Q(B1P^nxffV9AvBLPrE<8D>ZP{HCDY@JIvYcYNRz8 z0Rf+Q0riSU@KaVpK)0M{2}Wuh!o~t*6>)EZSCQD{=}N4Oxjo1KO-MNpPYuPABh}E|rM!=TSl^F%NV^dg+>WNGi@Q5C z%JGsP#em`4LxDdIzA@VF&`2bLDv%J)(7vedDiXDqx{y6$Y0o~j*nVY73pINPCY?9y z$Rd&^64MN)Pkxr-CuZ+WqAJx6vuIAwmjkN{aPkrJ0I4F5-Bl}$hRzhRhZ^xN&Oe5$ za4Wrh6PyFfDG+Nzd8NTp2})j>pGtyejb&;NkU3C5-_H;{?>xK1QQ9S`xaHoMgee=2 zEbEh+*I!ggW@{T{qENlruZT)ODp~ZXHBc_Ngqu{jyC#qjyYGAQsO8VT^lts$z0HP+ z2xs^QjUwWuiEh863(PqO4BAosmhaK`pEI{-geBD9UuIn8ugOt-|6S(xkBLeGhW~)< z8aWBs0)bzOnY4wC$yW{M@&(iTe{8zhDnKP<1yr9J8akUK)1svAuxC)}x-<>S!9(?F zcA?{_C?@ZV2Aei`n#l(9zu`WS-hJsAXWt(SGp4(xg7~3*c5@odW;kXXbGuLOFMj{d z{gx81mQREmRAUHhfp#zoWh>z}GuS|raw1R#en%9R3hSR`qGglQhaq>#K!M%tooG;? zzjo}>sL7a3M5jW*s8R;#Y8b(l;%*I$@YH9)YzWR!T6WLI{$8ScBvw+5&()>NhPzd! z{>P(yk8{(G&2ovV^|#1HbcVMvXU&;0pk&6CxBTvBAB>#tK~qALsH`Ad1P0tAKWHv+BR8Fv4!`+>Obu1UX^Ov zmOpuS@Ui|NK4k-)TbG?+9T$)rkvq+?=0RDa=xdmY#JHLastjqPXdDbShqW>7NrHZ7 z7(9(HjM1-Ef(^`%3TlhySDJ27vQ?H`xr9VOM%0ANsA|A3-jj|r`KAo%oTajX3>^E` zq{Nq+*dAH{EQyjZw_d4E!54gka%phEHEm}XI5o%$)&Z+*4qj<_EChj#X+kA1t|O3V@_RzoBA(&rgxwAF+zhjMY6+Xi>tw<6k+vgz=?DPJS^! zei4z1%+2HDqt}Ow+|2v^3IZQkTR<&IRxc0IZ_-Di>CErQ+oFQ~G{;lJSzvh9rKkAiSGHlAB$1}ZRdR^v zs2OS)Pca>Ap(RaSs7lM2GfJ#%F`}$!)K4#RaGJ_tY}6PMzY{5uHi}HjU>Qb~wlXQ) zdd(`#gdDgN_cat+Q#1q&iH{`26k}U3UR5(?FXM>Jm{W%IKpM4Jo{`3aEHN)XI&Bwx zs}a_P|M)fwG1Tybl)Rkw#D__n_uM+eDn*}}uN4z)3dq)U)n>pIk&pbWpPt@TXlB?b z8AAgq!2_g-!QL>xdU4~4f6CB06j6@M?60$f;#gpb)X1N0YO*%fw2W`m=M@%ZGWPx; z)r*>C$WLCDX)-_~S%jEx%dBpzU6HNHNQ%gLO~*egm7li)zfi|oMBt1pwzMA$x@ zu{Ht#H}ZBZwaf0Ylus3KCZ*qfyfbTUYGuOQI9>??gLrBPf-0XB84}sCqt5Q(O$M& zoJ+1hx4Wp#z?uex+Q1crm2ai?kci;AE!yriBr}c@tQdCnhs$P-CE8jdP&uriF`WFt>D9wO9fCS0WzaqUKjV_uRWg>^hIC!n-~q=1K87NAECZb^W?R zjbI&9pJ)4SSxiq06Zasv*@ATm7ghLgGw3coL-dn6@_D-UhvwPXC3tLC)q3xA2`^D{ z&=G&aeSCN)6{2W6l@cg&2`cCja~D2N{_>ZQ)(5oSf!ns1i9szOif~I8@;2b)f2yQ5 zCqr{lGy5(^+d!<0g??wFzH^wuv=~0)g55&^7m8Ptk3y$OU|eI7 zIovLvNCoY%N(aW#=_C%GDqEO|hH3O9&iCp+LU=&CJ(=JYDGI;&ag&NKq}d;B`TonC zK+-t8V5KjcmDyMR@jvDs|7lkga4>TQej$5B+>A`@{zE&?j-QbQWk4J*eP2@%RzQ{J z?h`1~zwArwi^D7k9~%xtyf(2&$=GsP*n-fTKneej-y6y(3nNfC7|0{drDx{zz~cSs z<_+d2#ZDst@+`w{mwzmn?dM2aB;E;bS-Opq$%w@WnDwa$hUGL90u9c=as)+_6aO10 zLR|CR8nr<2DQTvkaH0QDsyn@TYCs7Nk3lN}Ix$)JM0*zf=0Ad$w9j723W#%{r8V&`{wx-8kSv#)mZ{FU%UZDIi zvbgLHyJ>z0BZe`GNM$Q;D6D48#zc9s(4^SGr>u-arE}okN62N{zuwX)@FL5>$ib=b z5Wtm~!ojD3X|g59lw%^hE?dL;c^bgVtBOkJxQR{Eb*nR1wVM&fJQ{<))bn9e3bSlu z3E-qpLbAE(S^I4mVn`?lycoV!yO!Qj_4qYgsg7tXR)Gu2%1)5FZu&lY7x>bU`eE}x zSZ5c`z~^&$9V?eEH!^Rp-Fz3WiCvEgf`Tq}CnWRZY+@jZ{2NewmyGUM6|xa3Sh7)v zj6d&NWUVqu9f-&W)tQ>Y%Ea!e76@y!Vm*aQp|wU5u<%knNvHZ!U}`fp*_)mIWba=j z*w9~{f5pD;zCmEWePjM#ERNiNjv!SnM-&rGpB9Nmiv}J+hwB&0f_+x?%*lgJFRHsqfFDPwyvh8<*xLT0u_BeEHw{q+UGj=$4udEx)Vq#sV zKB3+_C!RUKy?ac3-`+}dL2!D_2(5=8&@hBf`-AbU`-<_3>Ilqkg6qSI>9G(@Kx?g<0h0K&31$AR>R%d}{%DyXPss$&c^ja7NR z$0AN7Fl$>VpGxqHW15CjxAa6DUVmCpQNbOwBv8D^Y{bXg28> zEQE9xl?CWh0gS6%Y=G4Cy($Vb>jBb2f_dm#0_B<_Ce`|~Obt_Xp^nkR zK%o_`{h1XkWn}i|5Dp#q8D(;k;2|+{DAG{2gJgPNQ=KZ=FKY@d>QEu6W;oLsE(1}< zpnwSEj(K{Bu^#CXdi7L_$!X`QOx^tA1c{&-XTHo3G?3(H*&VM~*Aud?8%FU=dE&kV zJ$SqZoj^g@(q9x;7B30J$(-qUml{?3e+I^Cf?X0PpLr}m zS}W9`QaCwINRU&D5>j9O*j6S}R1`7{5+{d-xUlI~)U!^4+*b5tkuon-Msz03Z{{Kp zH!GAXoyr#1K;t5o#h#a%Lzj3XQGqM0TRnfu$(fsQe^wb_?W!m!+7r55q>svWN`k~T zS(gk9bi|@+8wg;dR<&0f;MpwQbY27$N{{laPQk3@3uCz$w1&jq)`uW*yn!Pe-V^%Q zR9)cW;UB~ODlwolWFAX?ik#_|v)AtHNwoq72E9Jg#v2e5SErf+7nTleI8&}%tn6hf zuz#5YtRs94Ui&E_1PakHfo+^t-{#ewhO*j5ls-zhm^C{kCARNEB1aORsxE!1SXBRz z6Oc-^#|0W6=7AJ;I|}pH#qby@i^C+Vsu9?zdtkE{0`oO_Hw|N=Lz9Is8j}R zI+8thGK?(KSZ5ZW4nQG1`v(=0Jd*0gIlavVihzo#fPaa=}(Rqdxl3^6O8K+{MqU`;1iTJ$<^k)Nms(A$j?A-wHJKvh9 zUHW3}JkE;x?FETPV8DFTxFLY8eSAd%C8vp?P_EuaMakmyFN_e?Hf|LBctnncUb}zF zIGP4WqtKCydoov~Bi<_I%y%$l+})!;SQVcP?>)9wM3q-GE6t9*LfoePBlo{gx~~e{g_XM5PQ8Y5dsuG%3Xq}I&qcY6 zTCo?<6E%)O$A2torq3-g8j3?GGd){+VHg@gM6Kw|E($M9}3HVIyL1D9321C zu#6~~h<<*=V7*ria%j^d5A;S^E;n!mOnFppfi+4)!BQ@#O2<|WH$RS~)&2Qol|@ff zFR#zmU(|jaqCXPA@q?UhrgbMO7zNXQYA@8$E+;4Bz7g=&zV-)=&08J_noLAz#ngz$ zA)8L8MrbXIDZuFsR_M(DsdX)s$}yH!*bLr{s$YWl5J?alLci=I#p`&MbL4`5bC}=2 z^8-(u4v2hs9*us}hjB!uiiY6vvv&QWJcVLTJ=SFG=lpR+S4Cd91l}oZ+B-*ehY2Ic_85)SRSa% zMEL~a3xrvH8ZnMIC!{9@pfOT7lrhxMf^8N20{CJXg}M35=`50S;6g-JYwjwj!K{^) z5Bohf6_G6z=+0V8&>F8xLbJ4mkCVu^g66#h&?tL z9odv&iW21IAh~y9D-DupKP-NcernF2(*RsFkAsM<$<>@-Cl1?&XAi4+Mh2Zm@2x#u zWH&J^1=8G|`|H2%94bnjUZyI>QACu9FS}^$lbtzzCz4AMspqGYEwFFM<%G!Oc$+;7 z3r_L!H~PR}5n8+3-&4v*fFr$uK{y_VamM0*TKn^))nQsn5U?7Iv?`4|Oy&m6himAG z%=a;2ji3f_RtDPqkwR>ISxhnS0f)E`ITo}TR!zIxPwECZy#jzo%q{BNYtd!<IP_S+=*yDOk1GgwLqe!d9esV@3$iVAm1!8RoE| zqnTz;5a)B(~~KcP)c>?+ysFAlAGF4EBor6)K{K*Kn>B(&QtMAkR^ynG%k%UbJpKM zI$}qQXXP3PISHe_vTFssbcL`irhG2zN7J((3ZFmh*bnPuiK~=#YG=820hXqOON#HI<0bvIT{z&SaqRvqaMG-d5<06zdP?-kIH{%UMR$Xn@S}Hx3 zFjg}6no}vN_512D+RIn-mo9^_Li-)WI5%VigYt{Jd!RyI%d|-LqJU$y3aJ*a$y6$1 zjyTuIF2&t>1rPlw&k5OVLhrYBvk5Vl8T(*Gd?Alqi}> z<@-`X_o@9EOB8Ik&?|;lvKHFU@#O+?T!kEf&oJUaLzN;>!}!!e1WIs(T}V#Irf$AK z42`x`z-9ogxd@%CS;D5S z2M^b;Pu)q)c&_KBO!va-4xnI57L7V@*_I_r4vU)z>xk5z6PDVqg92R7_iZH|VlO_B z#8R`5HZVn?ou>czd>gZ~s;w4ZkzVXJNP8FiezlB5JXe6Z-OLsDw%N7!(135!Vl2Lb zLYI79?U{h#W-_#W6hf`<$BQHJCu5ehv?IF+-uxUqt~j!ZW1cxfiEJal^q7~RMWQ0a z2CEaPa1_p|P6qRmmeKgas*N}@(2tH%U37-<5i(DSnVOFFxg-Sv%7&{hPeRh{U`&ufGz=V|JdYQ2sG5 zk%3JimSwQFP=Yr?u_beSG^B$nnh$4hrxb4lpTTiUFRQEZ3ulr+L3m;>;Io?D;jG6Wjj!b)nsZds<6 zX@cD%+aVr!ra~F7HYr`TB!|y-t)HSb^FQt zbo+_XP44IWJGGxg73JyhBjKMSv`77ngDOw}6Eve6ZIol$Q5s65d(1-sP{BU{1_y)7 zF8sh5A~jxRHk=wq3c5i3*e&otCd9>cstT?IQ&D4slC-&^q!ut1;WAQ}fE}Y+jU}r{ zmpSI%sW?})RAm8}$WUU+V$PmQOF5gSKOGQ2;LF-E(gd<67rYu2K| zom8mOppa%XJ6C(@I7-*opqLn73e9BMFStaBER?suJ{jte1$vA%z?$_`Em=a=(?T-q z*A=VZOQ`P{co!*UUKyV@Rd-c#*wmb7v<%rN=TGFmWmqhbj#&+?X|3bZYAjbNGTv~O zs7SIYi3VgW6@?=PGnbNNZIWaY^*+ChW&a)A$uqH8xxehwx2`<1w6mag?zuHbsVJiO$a)tQ zuBBoR>rLfhpA@)Qf`8BwRMx886%9HP5rOR%YCy9pQ|^Xw!=Mcnwx8j=(ZE)P-tJ&s zON&Nsr%14jS@K+IvrJj720NkCR*C(j&aI$EFCV)w$9M<#LdihyRKdzTjJPI|t9_S} z--#oF#;F?Y1KN%_yE);Bxv}9PWZphz_g5mReOKR`y%9UZ=n}GXWw?E$T1%NAfK1Ad z|0$Lp^;sntA>}=ybW)mkxNv1?hkZ`<8hCemcT5 zYl6$I^bhXDzPlz<>6zOy3Fu*3?>#q$;1fJ>nuxyx#&<&x6Y}j zCU&VmtCJ`;aYN+qP}nwr%s2ZQC|Z**axS^?iGu+x^{{>FIv!k0#HaXtEG=*C7kPe!mMnknbn}TKpp6Xv9 zVvq&%A3nmY^N*XTg&+=wO>(|{uTwm;ZP9@+M)6%T zwXPh-&{+aAfv^ZCzOEb;yj>A=f5Pbu)7T{9PT3u>#w*%?K8jqEF%I>A?q;E%CXn)f z|0ohNa5DMv@HVk^vT(L=HBtH*Vzo81L?)M=g7)>@j*vUx?S zxqZo23n3vn@K-Q@bx3lLT+5=fB_oz8+p?P;@*UU<-u)jb5WFEXzoc+8*EC5P6(HWr zY$mfFr=L&G>(jvl8US2fLQqTzHtAGizfR*;W4-kN2^I>L3KkXgx=e*}+i*N($}{?c zi=Q67G)oEMW{|Gdsm{)|V)5Evo}KLj%}gIe>98FFoNTLrJX z-ACRdewnT1w#Egct%wpGg~q%?!$}>$_UJPC4SP0^)G_$d4jN0jBEx}+rcd*^aDtnx zewG{`m!oSbQ?A~FZ6L{&V0hUE+b$DxjO_;oskFha>@gzy(jDnzGO>z3Tzz|i&Dakg zFid5$;SFxINis^4JzK5XIVabKoP`=ZWp|p|t{hTi8n|#XE=-rINwJ*blo?=%Se(qw zkW7x5Qs(LV5RVGxu2e&4);c73lY#0(iZo1x=MY;7mW`uUQIY+$_PqH`4a`6O#urwU zE6(FrvyExmB{c5z*YAj_P&t??F1t6TN2N!$N#~02u(t(PDVyD)$mL3hqKQ4E91N#GOIngPr&pUb-f_Z4*XV8`p1pq+mzrUlUY=4~i|3RDo;Lo36U}uwm zaOah}mO8c@%J*~~{Up7_7->8|3x<}WemgaMA}h>xD17Fey@V9;LgjQFSBS(A<+2kCP9( zlkD%;oXzWtZ_hgu0IxeTjH`6=vi|t_04Btl32=g8swD1oZguWr4|lx0RuXoDHbh27 z+ks?gkVWYnr~_{h+PzQjQ(#8kaJai4We{F!JuqCzU0t*+H{n6i3;K<>_6XUn1n)}) zJ?}JCUPYhT9S1Hi-M+$(Z**%fz7Z%IiMN6%kD>wh%r4#C?Ge4{>w9o??Vbehy9!3@ zffZs8?LGxyWQr@yB(|%~Aa>fVj3$O=i{K*f;?h-a@-ce{(cY8qByOCA1r0;NC}}gr zcC^fCa$Ot`42n>`ehclOAqBo7L&D6Mi=;M5!pd@jj$H z?U7LQWX_u7bHpBzF7L-s4*`C)`dUrbEIgKy5=QHsi7%#&WYozvQOXrNcG{~HIIM%x zV^eEHrB=(%$-FXVCvH@A@|nvmh`|agsu9s1UhmdPdKflZa7m&1G`3*tdUI5$9Z>*F zYy|l8`o!QqR9?pP4D7|Lqz&~*Rl-kIL8%z?mi`BQh9Pk9a$Z}_#nRe4NIwqEYR(W0 z1lAKVtT#ZTXK2pwfcCP%Apfo#EVU|strP=o4bbt3j zP?k0Bn$A&Xv$GTun3!izxU#IXsK1GQt;F0k`Tglr{z>v2>gCINX!vfs`aqag!S*AG5Z`y-# zUv_u&J4r;|EA`r!-gsoYGn<^nSZLH-nj1SRGc0MRG%LWVL)PckFn9z!ebIJ}eg+ix zIJo7GN;j1s$D6!({bYW)auypcB~eAWN;vhF%(l=|RR})$TOn;ldq^@8ZPi<%Xz~{Z zQQ|KAJ@JHaX!Ka2nhP%Cb^I}V6_C|e1SjOQpcPMMwfNz#U@Az|+rmH*Zn=cYJu-KR z{>f++Z~P=jm)4-7^yc#52U4qeNcBRYb!hhT3Q7Ngu5t@CvY*ygxu^Eh?2l6= zhdqN{QEaP(!p>1p1*toD!TllHH6EH~S%l9`mG62dyAd+?}1(vf@N*x^6vhEFU<-RqS7#12*q-xtU z5d|F^n%WSAQHnm-vL)4L-VvoUVvO0kvhpIg57Wf@9p;lYS5YfrG9jtrr?E<_JL{q% z7uPQ52{)aP{7<_v^&=J)?_|}Ep*`{dH-=cDt*65^%LodzPSH@+Z~;7sAL}ZECxQv+;z*f;(?k)>-Lp@jBh9%J`XotGJO(HcJc!21iZ98g zS-O!L9vpE(xMx1mf9DIcy8J5)hGpT!o|C8H4)o-_$BR!bDb^zNiWIT6UA{5}dYySM zHQT8>e*04zk1)?F99$dp5F^2Htt*jJ=( zH(#XwfEZ`EErdI~k(THhgbwNK9a(()+Ha1EBDWVRLSB?0Q;=5Y(M0?PRJ>2M#uzuD zmf5hDxfxr%P1;dy0k|ogO(?oahcJqGgVJmb=m16RKxNU3!xpt19>sEsWYvwP{J!u& zhdu+RFZ4v8PVYnwc{fM7MuBs+CsdV}`PdHl)2nn0;J!OA&)^P23|uK)87pmdZ@8~F$W)lLA}u#meb zcl7EI?ng$CAA;AN+8y~9?aon#I*BgYxWleUO+W3YsQxAUF@2;Lu-m#U?F(tFRNIYA zvXuKXpMuxLjHEn&4;#P|=^k+?^~TbcB2pzqPMEz1N%;UDcf{z2lSiwvJs(KhoK+3^2 zfrmK%Z-ShDHo^OUl@cfy#(cE=fZvfHxbQ!Chs#(vIsL%hf55_zyx>0|h2JT=|7JWo z+Uth3y@G;48O|plybV_jER4KV{y{$yL5wc#-5H&w(6~)&1NfQe9WP99*Kc+Z^!6u7 zj`vK@fV-8(sZW=(Si)_WUKp0uKT$p8mKTgi$@k}(Ng z#xPo-5i8eZl6VB8Bk%2=&`o=v+G7g|dW47~gh}b3hDtjW%w)47v#X!VYM}Z7hG1GI zj16;ufr@1^yZ*w3R&6pB8PMbuz%kQ%r=|F4+a!Gw2RBX6RD5c!3fU@+QCq#X7W@Q5 zuVQ}Uu0dzN+2mSX5)KV%CsU;2FL%B6YT`10$8JR^#;jOO1x?t()Q_gI zxpQr2HI0_^@ge0hNt&MQAI`yJ1Zhd-fpR{rdNmRkEEDu7SpB)QOP4ajV;UBZZZK<6 zWds;!f+|}iP-kqWAH#1@QisJpjcg`+s80!LhAG@(eMad|zcln~oE8}9l5!K{^zf~( zd=HArZ5+Mryc$uNa`@|GSdOX=y}8GZc-%p8W@OM)uk2DfmhQXCU1E#y3XJ>|+XdW2 z)FQLeK38}u_D(5E{GV|YT^rI4qds2{-r<@@@@SG@u&4LbC z5o|KKqVM{?wk$5>2?t*I?IHdh~gljn_2m2zqZNJEEz4Mb$o&I3_UAg#$B{0u$uF4-q}{ zzs5+k@qOe08!CGLGmy3eRrcuqsgB*B>i8c3>3=T^Hv>nL{{u)jtNc6tLbL7KxfUr; z=Pp14Nz+ggjuwd~*oRJ)xWwGwdge+~b!E%c3Gzw6`vT>CCxE0t6v5Z`tw1oKCcm68A~Dbc zgbhP6bkWwSQ=#5EsX*O9Sm^}EwmQQzt2V2phrqqe2y)w8;|&t6W?lUSOTjeU%PKXC z3Kw$|>1YrfgUf6^)h(|d9SRFO_0&Cvpk<+i83DLS_}jgt~^YFwg0XWQSKW?cnBUVU}$R9F3Uo;N#%+js-gOY@`B4+9DH zYuN|s&@2{9&>eH?p1WVQcdDx&V(%-kz&oSSnvqzcXC3VsggWet1#~bRj5lBJDo#zF zSz))FHQd8>3iSw{63m`Pgy_jkkj9LTmJ&!J(V0E~&}HJ4@nXp<(miz$sb;(I<8s!7 zZyezu!-+X81r03486gAlx@n#aKx_93DREBtNcYln*8oliQ zbh0~SkAgHXX%C6}HwN(TRwaK2k_$Y}PxKId;jYt=S1Bf<8s@(IL?k3u1(f^V%TYO1 zA_jPf*V)SLEZFWS#y>M&p$LoSk+%ubs`)H%WEZf=F)RKh&x;i)uLIGJ94~A4m$(;S z;1rQC{m>--`WHFcaFA&5#7~vz|5S;{fB(7pPnG;@$D~C0pZYNEG?B8X*GB2e4{Qk; za1oop8OvHqs1Lk6B`AuYOv4`y`IgM315iTr{VUVc9WeOG;xE z%eDQgE4rb_B%vuT>N?^K zRvPnQwG%7RjO26+DY!OXWjgBu4^!)W-+ob_G&nX++))pD->QdRCo0spZN?Y*J#@-q z)fk-fJvZYz8)GSxYc^oXYIM;Pw}ftHW+a3dis#dXx^OS^m-~FlwcVr6MXv78fNI!i z51K-2t&!&IZ4(GF=mT@;qIp!&R(I@UiWPPz)%Us&(FdAAGxZ-+6^UZ7em`J-F#_3r zLkHym@VAnZFM$J~?0b@&O`l4YXyvOQ+OqalbZ0{g{qD{neY_xno1ZpXlSJWM=Mv(~ zvK{?O>AcXpbd}+hn{~*>weZwDTURX*M^9RkOO#DUfRW1;comKg1bn+mlsrNY8XDyW zgWg9~AWb_1^D8zsD4bL(1J4oinVy0Fimrh&AC}Itl;IH*p4eU_I;SWkOI!9tAbi3B zO@0=q#LHAc>z?ve8Q&hsF(sR9lgf_99_5Kvuug<^&0}Y&m)YjI?bITGIuh}AJO|>z zc*`Mly$>TA={AIT#d%JuMpXHDt($qkc*3UTf-wS$8^awqDD^|EAeA{FoeyJfWM@QX zk>vJ4L|8DU7jg_fB^3Qvz*V$QmDl*AXdw6@KSckh#qxjLCM8Nba!dTkJgr(S@~Z0a zt8%|W!a~3zG4Y&X6xbLtt^JK5;JT($B`_9bv(BjRTfG_Y`tg3k-}%sQoY@F|=}}${ zwmW%Ub6jPd)$;NA0=b7w!^2dE-qvI4)AVr`yvkabJcGwvuQ2rAoRlTjvCC^-$2BG} ziy0<6nt8;J67rymwm&wVZ8E7Krouv2Ir@-GQ%ui6PR42KHKms3MK&Z$zp{_XAVvrd znK4cbg)Ggh5k(4SlFOM9yyRUlVH1oo%|6Lu9%ZxZW28!c9Z%H5#E?B?7H7ulcUtirB<{s@jnS(-R@we z^R#{Mn$#JXd~5sw9rU&~e3fYTx!T&hY{S<~7hviG-T$<4OPcG6eA0KOHJbTz^(`i~ z_WON4ILDLdi}Ra@cWXKLqyd0nPi06vnrU-)-{)Xp&|2gV>E{Uc>Td`@f@=WYJYZ^- zw&+fjnmyeRoK-unBVvX>g>wO3!ey<+X#z@8GNc9MD}khMO>TV{4`z zx4%!9|H6k|Ue;`M{G6d!p#LL+_@6WMpWgF7jk*%$D_JB3c%D`~YmHRJD1UNDLh;Tf zYbbKcv9R(81c4yK+g+1Ril{5w#?E}+NVz>d@n48C-T-(L?9a9W`JV*{dan-sH*P3_Hnt~iRv)}ye;7$b}^4l%ixphDK`G#b!4R4qoouT@*A zZ)kQa)e94??k7N>tqoRl>h(9DFq&92=z|F!LJrh-97EoFL|Wt2v}>(zG1*#aiYA_^ zM_&%_G^g*O8x650e>m!#MDmwRub!irY>^^|L=!4^%lBr;?}mvgP3y~^mSdKSm^R~WAt7T0_ck0mA`GS)J^SYTo6^vQ|vuM7!92&@$BhtcQ^Z4h2)aN zh~EQthyjn1(eI~$FtuHH!|x(iHU{9k40k5nPBwB)X@8Lo$P6u81EeoNOGRct%a-LM_4y3Ts z7ki0PWAO^Es6c%M*SSRn)2|NAoUsKyL%))uVx7?5lkrk`njxs4q@M~x+8%jr7xV;- z|KC=g3aTZO|y|g~oHXB6b42(|J_&fP2Y`*;L07H2d>{~JP zFNGl$MYUG(Qy3dR?9Bfdg8#peGRiVP8VYn@)6T1bj*v)s6q*7<6P(ZVm4ZnTA;rOHSd>P`_5uT0+azWdV`gIvLaJ1o*DB}&W6LCgX|BycgF5qd z!)}dT#A~4*6{1=Bd5VV(Qa2h4x9m#2X711z(ZN>i&cn`BopG*5P`CD*HfYiQmXNGk zhgqcHPBrJP$Z@PLZ4}d-8^}%X^LtUDHq&;~3}lUyrxxl@|IS={GP&6-qq&Iy5gKW- zC@$}`EEZd}DOSeSD+v_x5r_tpBWfN0gDa21p(@TAIrgWQFo7NO@slI6XOAML_lN;3 zEv~}LlMbGWKu}0s$tO-vR)wD!=olGcA?}vU;lRu4+Zf z?nCD7hBmA5`U9P#W8-*0V1=OT-NI0k&_`UZ87DbpYq_=DBdyNDchZ<|V1f%dbaa7i zf~R+6Xt%G)VXlM@8REfP3u#7UPadWYOBMsQ56fHRv!0p9R6q>Rbx!n|IY0goLb%{+ zzy|5WXk+(d@ChzOWatIV1lc1F!(uEOfEmMd;v`|$Kt3X2Uws;%@OV!E86PN?CeHV& z=4#TX{J8RWaH`)!J<8AUs#Ar{6Am^8M{S( zc%K7y2YbcLUz+*eDTXdthNE)Lm^P&*e^eV zilOS9)TVKgr9_^_M!TJ^44v<YF2NO=h(oOr5jYxVTxWk0XJ8n0{F_SOH%49WMk*Sg7`g6B(=^< z*rLAW;8I5;1?;Fh{N=f;kxjLpj}u^mD|k8lih|G4#}wEG1j`HIG( z8y;BMR3cE01e?(+k8NLR|Z+)#>qR^iMZc=BkcixWSKYmkaHpIFN?s%*74kc&wxwB zrtbYBGz9%pvV6E(uli6j)5ir%#lQkjb3dvlX*rw5tLv#Z>OZm@`Bf2t{r>u^&lRCg z11*w4A;Lyb@q~I(UQMdvrmi=)$OCVYnk+t;^r>c#G8`h!o`YcqH8gU}9po>S=du9c*l_g~>doGE0IcWrED`rvE=z~Ywv@;O-##+DMmBR>lb!~_7 zR`BUxf?+5fruGkiwwu|HbWP^Jzui=9t^Pmg#NmGvp(?!d)5EY<%rIhD=9w5u)G z%IE9*4yz9o$1)VZJQuppnkY)lK!TBiW`sGyfH16#{EV>_Im$y783ui)a;-}3CPRt- zmxO@Yt$vIOrD}k_^|B2lDb2%nl2OWg6Y)59a?)gy#YtpS+gXx?_I|RZ&XPO`M!yl7 z;2IS@aT4!^l`Tped5UGWStOw5PrH#`=se%(ox%gmJUBk18PsN$*-J8S%r51Y$i!4N zQ!rW%cgj44jA~_x%%smSTU2WG_W0c&PB$A5*kl8{$|865+lSIX~uyDT`uI7qnS!BPAg1Wwrc0e)8Usf zv9^E38H&hWSp5!@K8Qinl|)9 zEB?NMaxZK^GB!PUf1TBw+`H&jFSNI=Q@v5$Ryf-y^#IuXO#vsM5R+9@qz#z0fD0GP z9|Hj#E>?<=HTcsF$`xn`je~D&3kF1Qi%dfH{sKh!~(IpgjkDGQn zQx2F9rv{*x2$(@P9v?|JZY)^b9cd+SO6_1#63n-HAY3fE&s(G031g2@Q^a@63@o?I zE_^r%aUvMhsOi=tkW;}Shom;+Nc%cdktxtkh|>BIneNRGIK{m_1`lDB*U=m|M^HGl zWF#z8NRBduQcF-G43k2-5YrD}6~rn2DKdpV0gD%Kl{02J{G3<4zSJ1GFFSXFehumq zyPvyjMp2SLpdE5dG#@%A>+R3%AhLAwyqxjvGd{I7J`Iw{?=KKPRzyrdFeU}Qj{rm{351DoP_;vx zMo*s+!Gwgn;${(LXXO(xyI@$ULPZI|uzYR%`>MmW6Hcr1y2aM5b$grFwW_(9Fzz$Q z$&8dKNdWvBkK=iYWA|0}s1B7>8J$g*Ij_+S9vC1#jy~uA8nr)yY)a+ zoJ=e>Lp`7v3^tQN<&6UpDi{c1b}F~fJ$9r=p=@U^J_7bOck$5}ncVjYB0yEjbWrhe@E`j64yN3X?=k_F3BalH$aN zV=94?wDNv=BKLB<1*xU|65Zl!%51r5sHQ?qCggCw;$2QfCZ$lN40WPL=n^{Prf^QS zjbZ&1MRGgiZ2T)}DpiluFr#q*!AZJ$1v#d10YQ{>wQ5px!y28-1hCZ7lwvQnQYN*U zOg9BpvB0A$WUzFs+KWk1qLiGTrDT-0>DUpFl??l(FqWVz_3_Xzqg9vTpagp- zZcJ!5W?|0G%W|AJVVHJ7`u6@<4yyqMGHj@kpv`P+LV<)%PM__Rz&oq~t-*vV12@NR zoEVPz<2D>O==MlNI`;l8Gmv49&|1`FR!}2`NLRCqA{@`imLz6zrjS4ui0)O;!Pu&?KPAcX)?tDPS26uKvR(ry(p{6kiXPoZbnQ!vx6dLu zZCaj~Ocr$h##KqsD;9;ZiUwhmUd%5lrwczWr1Yn6V>+IK=>51;N7JDkrm1NY-ZBes z;FxeOTb^HAyA+~P2}WvSSu_fzt_K=(m4wUp%c*^hF zEJ+1dP0{0B8bryXR+qApLz43iu?ga<5QQxTa$1gMCBq0W=4|DTv4nY4T*-^Im%>U~ z)98;hc(d7vk0zAML$WnPWsqK>=O-FZSLI3_WQKr*PCK=(i6LelZ$$}XXrD5cb~VXz zT%egX>8e;KZs@jcD>cL9VP(Q}b0r~ST$Mc%mr1cC8mqRUQc|N^9@Weu$Z|KeczK7HhSFeFV0i)MQmwrn7CBL=p`_9n?nh320m}6-MSv3L7I*<*56GR zZ`zI^1zyC7F#*zVL@M)F2+oqxydaiQz?|ODmqs|Ub8%&KXk9P3P7<4tM?X{~!;Ygw zt=h7)AYGDO9F&wV=BhCyD9exr#YM_-<;Fo~iE>IBEXK$%;JCUAEr;lR&3S_DUy_E) z#!oCYdENVE9OaaeaIrPk-odMtvdFG;ocA#`L6AifMu0og^?Oy9F|Et9q6 z8;3_|9+Io@hqYoN;58x1K&OP!9Vd#dzhTRjB2kI?%31ceHb#Q~WqJV5lw;@b>4@Rd z={z1S`d05YdWC*RLc7sR0bVGSytn-a3`JZL3|d8KC?vj_70Vi4ohP9QbU&Q4?Zjd0 zSZA?KbqLBsJg(qj>fycto3`zN-)lDe4{Ij-QfoBn@rT_tTszA+CnM~xWmE(4zfpCQ z;zPJfl3=ctrggYM!KQg;V{J;utMMF9&BfOe!<{wU0ph?-VQ%cv3B%fFiW?6xBPdf0 zD-HhEU?0C`G@7e+b-=8fj=TP3mdz&SIQ}Nd`*G#DTz9Y@b zaoDF}Gx7ZhPzpDhi^fA7WZ)EAEFv;N2*bKp0T za0t<^1|Zc#`A+?s$!$8eO4CK~PUFECC3BwNR4f)!V&-Y>$xg(%T{MtrH|CPcO(Lf> zE_meE1?6S-qlV^p2fh! zT11Ub)hHw!_mpFDMIAFB`%Yal+`1IXV>b?%!q^Ps%8nh8wtjVGlF-!5x*D29WJ4=M zZ7X(QvKe$YZNgM(HibD7+VO5Q29?@HzS?k$c|3B@JI6dlLgu5S&LbU4=4p-Yn||z@ z4p05vq*k*pbOV9QjVTMp8`c$?t@~!$8&5AP_sz@tk%a$nWHMh-Gm{WS5+q)5W6pU# za@YZXJCLTpZ}zb=$HCYbIm->?Hu6XIBz_d7)n1+3eSLzGVoNQCTHcu9qS2@({0sxc zu<-mhx@Xz_*(S1DEL|d0`YV7uNevL*Y6|DAQmvSp{4DzPL@>hqJ?`FjvIU;<&}YEKDmFUGSBYjRmK{Km-1m%-t=fFfI9kV|POH|SxvO=P+><+1JK_lt5F6fTPf8PXU+lYEJz__** z&>`4F2F8EWE+k7ZsZx9%!?A56{lsk1juYw5zN)V+g$d^Q^Gm}fnHKA6L^36=`e;p% zp{;JD$X3%}O7qINR*2<>a422}_hmc=)-A7B-1#2v85jN5K31t0DtmqON-Dim`XIR; zOo`KRv)gtn?stp*`^f>}UDnGYGnJAbl(4srd>(5fo2#oqi>#bus86EHfeItFIu$+% z;lE|3gjQA`BXHEE5JdcjCoethN`@NEc~zm6CYf@LJ|hT^1>l}gRl7oDHMnw!*5*IC z@@Mi=gO=lZSnWln`dX^4Bd{9zYG{HNIX-87A#5OM%xu*%V?7K3j3CHcN*t!zNK4N4 z!U2?a>0`8m8}UQshILC0g6-k>8~;SRIJ?vQKDj z@U{DrstWIT7ufyRYox^&*IyHYb$3wtB}V^0sS|1OyK#sDc%sh+(gy&NT9j4Aa7J0C zPe$02TylMjad&|{_oe3`zx)Cqns?6qThYue6U=~j5+l0Po4`bX*&9V@a<-O;;vCzm z(af&;e<^}?5$7&MRW$eb*P< zX|33QmDvFSDFK-qMz|RF|Eedum@~W zt~8C1@i8@LammTr)rAgKm8X_SczCg@+@LeWpcmx;VL;iLQJ;t%Z*|XbNWUnHX|o=Q z%bsXc%bw=pk~8%3aV-w(7E$co9_cHQ$!}Ep6YcoCb7~GQBWl#4D!T8A5!P*tSl4FK zK2CX0mjmosg6TSK@-E-He{dm0?9h{&v~}OX15xgF<1-w4DCypYo22%@;uRq`ZFld- z{Uqof@a@P5dW@kfF-`1B1(!R>(DHb&$UXY%Gd+6r?w8klhP&ldzG*6#l#VuM&`)ki z)f$+Rp?YYog9u==<#MC%1daG#%3EOX9A{7$`_(s#_4mV`xZaB+6YlX`H4{}vq;)TF zo~fR@do6EZIR?413A$V6o^fq&QV7P(bB(9m1969szOosyhZRYciAWXe4@u-}s(LeJpuIkSx)XvjXmvVEseG zJvWN4s|$6r;s(3F+cgeh4DMEq??h!$eb^5h#`whT5d03qfYpol8dCim)A^NG1-H}} z!b)V8DTL2Q8@R2p`y4@CeSVj9;8B5#O?jfl-j<$Quv?Ztwp*)GvQ~|W8i6?-ZV@Lf z8$04U_1m{2|AIu+rd8KW`Qk|P1w(}d%}cjG6cxsTJ3Y&*J^_@bQgXwILWY7w zx+z)v81rZv-|mi>y#p$4S7AA760X?)P&0e{iKcWq4xvv@KA@EWjPGdt8CKvh4}p}~ zdUVzuzkBlU2Z+*hTK214><61~h~9zQ3k+-{Pv~w`#4|YdjTFKc{===9Ml7EMFmE!f zH}U3O{Z`DuJrBZbz~OjSVlD6uZSEeNK8epja_LanEh8v;_$Eg9?g*9ihMoat$#qd^ z?;x?a*y3-pW#6|kF^<$w;2^~s!fc;3D~#&#WYZfK@3;bO{MvmN?>qy%_%v`BVCgfC zdwL~(H14Gr6w(1CX|R;zhZh%?*Q{hxJH`MV2)@Jg$pbqjZeL+LO7^vwgi!@3yn@NT zU91-{;BWIi8bV-j-YR|A9Qs?M?e7Ru&Onl1(Sz(kxAw?LEbd+Le%Z43rZgb2h2m|e z^rblc;4r+}?@tC(YIBB_qpQL?_kg{;zO#6JD9{;HSUgf@zIZ)}Bh4wFZIs>meSd}f z4iF~nD$KAV6CVEw+{YOPrW~~y~Y=?snG4dE3edN$~SXh`!c_F zUsQ1M;ARz&v0mIbfP}aLWZ&cBPU+DU{l+0}_>9DZGL{@}lF6QCtgAg;EWUu`D$Evm znblG}kC!}Mw)bR~U;+S}T9TVc6lXWR!LNMm)nmxr*ORkv#&UO$_WQpt0WdX{A=bjC zV^lB~(r;y!C4$Rk0fWUR|09O?KBos@aFQjUx{ODABcj}h5~ObwM_cS>5;iI^I- zPVEP9qrox2CFbG`T5r_GwQQpoI0>mVc_|$o>zdY5vbE~B%oK26jZ)m=1nu_uLEvZ< z8QI_G?ejz`;^ap+REYQzBo}7CnlSHE_DI5qrR!yVx3J1Jl;`UaLnKp2G$R__fAe;R(9%n zC)#)tvvo-9WUBL~r_=XlhpWhM=WS6B0DItw{1160xd;M(JxX_-a&i%PXO@}rnu73_ zObHBZrH%R!#~pjEp~P?qIj4MdAx@sv;E96Doi$eO-~)oUz%Z0Tr4K`-jl06Il!9{s zdjF*1r{XU?)C(%XKPm;UnpnDGD%QL3pgo0ust~+sB0pa|v37>E1dp*Odn)n=DY;5j zDzSAkU9B6F$;|##_mrDe#%hd7pC1u`{9ZKeDdtkyl&4>H=e)Fq@}$UffPt1#cjYZg zd%O%xpg4~brEr>AnKT)kF@`cdX4tMlZ#Vk!l1Xz!G970p`Gkv^lk-|>jmt0W5Wu6woGf?hNA zXO2?BG)<{`NsYAY#3|L^x*=rS7uWU~s<*UhTC8AYc#lGP-=Aw1I)@y(<` znQb^nL~$rlDbsdAc4nc#{+$_;Z4iY;Pi0i9Q;>ZB3+IjWLg_r40-Fso^xF<*_s7Tj zujFrMH{vW3PmCndjQIscnQE%`Qj|E2kidi#c&PcWIMyH+e#7!l`<$_)*pDP$!49pY6w!bN)j8~A1wV%gIakf+vA04 zV)_Q=QMPSj6$M2Ar#KhhxsbZUOq3nZHh8m0?Fr}I6N(Fk zkhXM(f57yOa8vn^97J+g9ISPa=-**6^8ZX&g=z+m&6~x<1>)MyM&tpbWhSf8#+Pcd4rVK#)NSw>1eLKHTO z44A@sc_}Ypi#ggFRbDRFV(IhOnRU&XPrQYh9`mVMo-^U$&AwsXooSRUFqJ7)XUXCK zFpt;gJ}9QTN9xy9$=3OnRkjgUuQZ`X)!}LBm~WUIEKuK-Z%}f?2?+MKucWU<3)>9G zxsz~2pHut1AmH<@66;LdCB9+dSpojE4ggrYS?%icv*Rpi?G0Q($^`(g<1&Z){O_5B$@f#;I2-+Qa1P$a@=u-vOY5vqo z|6G67X;*A|V86ZET9OpFB&02twZtc2K}~ASoQpM_p{vJ{-XvA8UmQa4Ed%fS{D@g( zr_aY0gKw*=2SIGznXXKFo$r0x3)@bq8@4od^U(L0-jvTsK@qYOWX?2G_>N+?;r{TU2{M>V0zid zB_Zu?WSnRl@k?oE*gsgv;jH@+ z-}BDGyR-ls7$dz{e( ztv7lI2|OxNkLD4zc3xGA`!d7LiSdOys4H!8aA(_c0Nm*uLjS4TW%Z3v>am1nwQ_lI zIs85Uufd;cv-(4wi(Js;QsL#|qdv)n;r_?puaK*1>zTC@d=#sK+q1YF_Q(5B%%3TtI8&bNs_e8vIb;oc|Rk`F~u?|A?jj{c={?{Env{mW#q@8 z)#WEgt4B6b&X2?o3=b`ilz;)-h$t4;hsxPDo-%5C(7m#c9tZF-U`vcx0HnVtf_X(}4Tg}4wx(=y!@T7{)4;I_p95mBhikg-|U9z35q`|!1+Zz@97 z(PFE5jCv|=t;^=(CLqYp)k90rV4ZSiFDAhD8YOCzv{}1WDuB?epORibW36);q(Aig ze27@D?lN-ZyjuB4GsebA$;+(KGiOtCe6Bfd%GKRty>dBS1GUe}MXgnu61UdgO=m1& zE(eECPF_%J-lU{;R)eQJot;;}Wch$-8Z|lxN*AAdc;bkpbD`W}F=Z}^Cy(SKyfF#+ zQSalA%JDDAu|77$M3E|kv==3vx~pFPw_<+9xgcE#oigh*>#QsA2}sTYO7uY(h@dhR zHJBi^bb-`1?<1cGFZJa8Akzs{H^$N<)5@hlXeKwt9hD5^5K&`pdHOI92p<7XhS?>| z(5h9KYctN|H+W~Xh2N4W+yjMyBm(AdewjX?PBuRU$^J zS#+U($K6rhFFzf z0q*kJ>B6xI1qAti?H@X@dxtB7_vT+Nj@PNxr?CSK#xqE6jh5S{`nH#zzvjOId=i1X zK(Yjl!7KF(73GXYLVkQA5irn|v-ArCqwi)CM8X&m!#@NQ3bqmQlfurU4qT`zl_m^C zhpk?mfVvy9L|)*+bW8&NY4lG$@0_PKfO9+~(zrbn?wECGi7472W{H&dRPZum^Qf z73C-TR6$#q>XJgYnUgV!WkbmRas;`TY#7CxPXIEGwT6VPBDKbyr#|C2M%q|7l#Ql< zuM}j=2{D+?SxT8?ZJn&Z%cRN8Gu@y(`zV(lfj1T%g44(d#-g&@O0FL5;I9=?bW>!M z%c3J&e}GThdean-<||jUh zlLP`UeKBhhrQ?HHjM3}kfO7Z=EKB%+rs*t+nuBoeuD2yk%n32SA?-s)4+DsTV7U&K zyKQO2b2*tQT}#((=#fkb%hkRkt^%tY&VK$hcs91+hld zJ%lgC!ooILC&|(Z9$zzk=Q0*%&l7wwyf%nv=`C=OcPjb|Q%@9*XkPGFrn+bxp?t^D z!_qO=e-;bnT)^0d|Ex9X&svN9S8M&R>5l*5Df2H@r2l)VfBO@LqeVw`Fz6TSwAt^I z5Wu6A>LNnF7hq4Ow=7D7LEDv3A))d5!M=lT3ConlFN`5eTQMexVVs* zH0tx-*R+-B@&Lp`0V4j6Uy=LJmLQRY_6tH4vnV{_am%kkv|{CYkF}4Wn6U+|9Xre$ zJkO;_=dtw`@aEs|^GlO-zvpp-73H;PYk}V5RrH83G4SVkRJ0YSluQa8pKejcqB4u~ z^9^lDR|?7vEo|jITtaIFI6}1;vTI6n(d0kDGQUJuk>>sqdd7#VBF;?_dM5i<+VMEq zc>habJK}_0eEsOkdwv48d43jKMnqYFMnYDU&c?vi#Fp+S)sxo1-oVJ*g!X^^K! z>z!G8?KfU{qOnLHhaEF4QRHgOpfvoo7@=FG(2ZefYJk- zZuA9ubiTTP9jw9Uzpx8FfJBFt+NNE9dTlM!$g$|lTD za4LMNxWhw8!AV(x;U`IV-(bK@iQ%#QSmq8D$YqLgt?V#|~% z;{ST}6aQbOoewMKYzZT@8|Qq z@9SNBu1UErolMjrhJW-Id&7y<0I<+Z-lr`IHMh1;M)n@g|hx_T-maO`s{Tuhax}EjC zS;1kdL*A3BW5YZXgD|0zm)g3_3vMs>5xgHUhQDl19lfQWMcfLTsw$)amgDs>bW*Oe+$UK^`ioL%F0Ua5vb%II+EGS>*I zw)AmqcWBZpWH&Aswk_FJT=J|^Gn=MfnDTIzMdnoRUB91MeW?e>+C)g3_FDN8rN$(? zL+kH!*L}rq`MK`KDt^v4nUJg3Ce-`IW0Ph0?|}Puq5WIS_a7iEO;~mGQqqo=Ey;ND zhBXA^$ZrCc#&0}dMA&@)&TCq5PMzgJPafZCg-6$R zRqJ2+_t+dGUAY@~xPzU3`od7-(8nnuMfM-4#u`Q~`l-CUGC7u*^5VwH`ot;Ck#R1% zRr%?;!NrB$w^}NW=GGR}m!3a9bh#wXrq?fF7j-IS?E_!GaD3KYzcXhCUHhjEl-6b# zCmIF#4y@HN=^#uIz zRFl8D)Ri1<(Kr~Hoi_MtXWP8^AyTKxi1)ew88bV{*Ok8w8YLXBFW0sRJ<(vU{$ym| zz)feLQbz3k;_}2_{-bW`h~t&2$ObtlbS?k2k|5Kbu?FZLDMTVW_Z6p#A)c)`3DD?a*hxHS2Zj zcIiebfsINfWvwY7Z{YOlIQ61b`j=%6{>MPs+`()Q{wq0z0?|jwRN(1IrMQsj40BHx zvBC_Xfcr;55&}MeoP_@#nz$avCh%FJfE5NNAE~fW@L7~f8Y=?Wno31128EYOK8+O! zc4Vaj-DCsB6CPH$?pQQVbb_(tg^x{$STYM_WKLtrh-_-Hq-M%Ubpt6$mCHY!B{ISD zz}grIo^bNVDw4={SA2*nDNq5`e@ZO5r4TbQpHM)~qfD9!s0h(Jf>vYd;I~j<2fD4)_>ctbwNX6S*8>i^*4 zYKI5<4}d;hM!!N|A$@eg09J|HV;!UUVIau_I~dxZp#?a3u0G)pts6GKdCNk>FKxdh_`Xu!>zO3Kv?u+W6cYJPy!@=PuY868>3|Zg} z$7galV~M`d!q(`I{;CJsq6G9>W0}H6gVY`q7S@9s8ak1r{>}*Q0JyH&f!f8(NZxhC zkn|KS64r^A1fniFel2KkxYByk%erCx9UgFLI)`yuA)X z8SU?6kj!numPNCAj}>1ipax(t{%rxU;6`(Nqt$~Z4~76TQ$9d8l`yJ}rniII%HbH= zlS_7o!qB{55at^>N!Voer%)`KMh9Yd@Z?~nc19*hs)NGN954`O9zA&&vJHbm&|D@E za(&z6A=3NfC;>I)hlI@ulP8E@W-ziGe{iCf_mHvWGldxw8{ng-hI({EtOdALnD9zG ze)fU?I(DNt)Bzdd9Cs^>!|+2!xv1SK=I zJ+y_;=Sq-zqD~GKy@{5(my&aPgFfGY&_mayR_)?dF_^Fwc-n!UAG+fQQGfjWE-1MF YM{}PByk10KD_nuQ4E7Du?}+~TKh4V)`~Uy| literal 0 HcmV?d00001 diff --git a/.mvn/wrapper/maven-wrapper.properties b/.mvn/wrapper/maven-wrapper.properties new file mode 100644 index 0000000..b74bf7f --- /dev/null +++ b/.mvn/wrapper/maven-wrapper.properties @@ -0,0 +1,2 @@ +distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.8.6/apache-maven-3.8.6-bin.zip +wrapperUrl=https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar diff --git a/README.md b/README.md new file mode 100644 index 0000000..b6aa2e2 --- /dev/null +++ b/README.md @@ -0,0 +1,202 @@ +# Spring Security Refresh Token with JWT in Spring Boot example + +Build JWT Refresh Token with Spring Security in the Spring Boot Application. You can know how to expire the JWT Token, then renew the Access Token with Refresh Token in HttpOnly Cookie. + +The instruction can be found at: +[Spring Security Refresh Token with JWT](https://www.bezkoder.com/spring-security-refresh-token/) + +## User Registration, User Login and Authorization process. +The diagram shows flow of how we implement User Registration, User Login and Authorization process. + +![spring-security-jwt-auth-spring-boot-flow](spring-security-jwt-auth-spring-boot-flow.png) + +And this is for Refresh Token: + +![spring-security-refresh-token-jwt-spring-boot-flow](spring-security-refresh-token-jwt-spring-boot-flow.png) + +## Configure Spring Datasource, JPA, App properties +Open `src/main/resources/application.properties` + +```properties +spring.datasource.url= jdbc:mysql://localhost:3306/testdb?useSSL=false +spring.datasource.username= root +spring.datasource.password= 123456 + +spring.jpa.properties.hibernate.dialect= org.hibernate.dialect.MySQLDialect +spring.jpa.hibernate.ddl-auto= update + +# App Properties +bezkoder.app.jwtSecret= bezKoderSecretKey +bezkoder.app.jwtExpirationMs= 3600000 +bezkoder.app.jwtRefreshExpirationMs= 86400000 +``` + +## Run Spring Boot application +``` +mvn spring-boot:run +``` + +## Run following SQL insert statements +``` +INSERT INTO roles(name) VALUES('ROLE_USER'); +INSERT INTO roles(name) VALUES('ROLE_MODERATOR'); +INSERT INTO roles(name) VALUES('ROLE_ADMIN'); +``` + +Related Posts: +> [Spring Boot, Spring Security: JWT Authentication & Authorization example](https://www.bezkoder.com/spring-boot-security-login-jwt/) + +> [For MySQL/PostgreSQL](https://www.bezkoder.com/spring-boot-login-example-mysql/) + +> [For MongoDB](https://www.bezkoder.com/spring-boot-mongodb-login-example/) + +## More Practice: +> [Spring Boot File upload example with Multipart File](https://bezkoder.com/spring-boot-file-upload/) + +> [Exception handling: @RestControllerAdvice example in Spring Boot](https://bezkoder.com/spring-boot-restcontrolleradvice/) + +> [Spring Boot Repository Unit Test with @DataJpaTest](https://bezkoder.com/spring-boot-unit-test-jpa-repo-datajpatest/) + +> [Spring Boot Rest Controller Unit Test with @WebMvcTest](https://www.bezkoder.com/spring-boot-webmvctest/) + +> [Spring Boot Pagination & Sorting example](https://www.bezkoder.com/spring-boot-pagination-sorting-example/) + +> Validation: [Spring Boot Validate Request Body](https://www.bezkoder.com/spring-boot-validate-request-body/) + +> Documentation: [Spring Boot and Swagger 3 example](https://www.bezkoder.com/spring-boot-swagger-3/) + +> Caching: [Spring Boot Redis Cache example](https://www.bezkoder.com/spring-boot-redis-cache-example/) + +Associations: +> [Spring Boot One To Many example with Spring JPA, Hibernate](https://www.bezkoder.com/jpa-one-to-many/) + +> [Spring Boot Many To Many example with Spring JPA, Hibernate](https://www.bezkoder.com/jpa-many-to-many/) + +> [JPA One To One example with Spring Boot](https://www.bezkoder.com/jpa-one-to-one/) + +Deployment: +> [Deploy Spring Boot App on AWS – Elastic Beanstalk](https://www.bezkoder.com/deploy-spring-boot-aws-eb/) + +> [Docker Compose Spring Boot and MySQL example](https://www.bezkoder.com/docker-compose-spring-boot-mysql/) + +## Fullstack Authentication + +> [Spring Boot + Vue.js JWT Authentication](https://bezkoder.com/spring-boot-vue-js-authentication-jwt-spring-security/) + +> [Spring Boot + Angular 8 JWT Authentication](https://bezkoder.com/angular-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 10 JWT Authentication](https://bezkoder.com/angular-10-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 11 JWT Authentication](https://bezkoder.com/angular-11-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 12 JWT Authentication](https://www.bezkoder.com/angular-12-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 13 JWT Authentication](https://www.bezkoder.com/angular-13-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 14 JWT Authentication](https://www.bezkoder.com/angular-14-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 15 JWT Authentication](https://www.bezkoder.com/angular-15-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 16 JWT Authentication](https://www.bezkoder.com/angular-16-spring-boot-jwt-auth/) + +> [Spring Boot + Angular 17 JWT Authentication](https://www.bezkoder.com/angular-17-spring-boot-jwt-auth/) + +> [Spring Boot + React JWT Authentication](https://bezkoder.com/spring-boot-react-jwt-auth/) + +## Fullstack CRUD App + +> [Vue.js + Spring Boot + H2 Embedded database example](https://www.bezkoder.com/spring-boot-vue-js-crud-example/) + +> [Vue.js + Spring Boot + MySQL example](https://www.bezkoder.com/spring-boot-vue-js-mysql/) + +> [Vue.js + Spring Boot + PostgreSQL example](https://www.bezkoder.com/spring-boot-vue-js-postgresql/) + +> [Angular 8 + Spring Boot + Embedded database example](https://www.bezkoder.com/angular-spring-boot-crud/) + +> [Angular 8 + Spring Boot + MySQL example](https://bezkoder.com/angular-spring-boot-crud/) + +> [Angular 8 + Spring Boot + PostgreSQL example](https://bezkoder.com/angular-spring-boot-postgresql/) + +> [Angular 10 + Spring Boot + MySQL example](https://bezkoder.com/angular-10-spring-boot-crud/) + +> [Angular 10 + Spring Boot + PostgreSQL example](https://bezkoder.com/angular-10-spring-boot-postgresql/) + +> [Angular 11 + Spring Boot + MySQL example](https://bezkoder.com/angular-11-spring-boot-crud/) + +> [Angular 11 + Spring Boot + PostgreSQL example](https://bezkoder.com/angular-11-spring-boot-postgresql/) + +> [Angular 12 + Spring Boot + Embedded database example](https://www.bezkoder.com/angular-12-spring-boot-crud/) + +> [Angular 12 + Spring Boot + MySQL example](https://www.bezkoder.com/angular-12-spring-boot-mysql/) + +> [Angular 12 + Spring Boot + PostgreSQL example](https://www.bezkoder.com/angular-12-spring-boot-postgresql/) + +> [Angular 13 + Spring Boot + H2 Embedded Database example](https://www.bezkoder.com/spring-boot-angular-13-crud/) + +> [Angular 13 + Spring Boot + MySQL example](https://www.bezkoder.com/spring-boot-angular-13-mysql/) + +> [Angular 13 + Spring Boot + PostgreSQL example](https://www.bezkoder.com/spring-boot-angular-13-postgresql/) + +> [Angular 14 + Spring Boot + H2 Embedded Database example](https://www.bezkoder.com/spring-boot-angular-14-crud/) + +> [Angular 14 + Spring Boot + MySQL example](https://www.bezkoder.com/spring-boot-angular-14-mysql/) + +> [Angular 14 + Spring Boot + PostgreSQL example](https://www.bezkoder.com/spring-boot-angular-14-postgresql/) + +> [Angular 15 + Spring Boot + H2 Embedded Database example](https://www.bezkoder.com/spring-boot-angular-15-crud/) + +> [Angular 15 + Spring Boot + MySQL example](https://www.bezkoder.com/spring-boot-angular-15-mysql/) + +> [Angular 15 + Spring Boot + PostgreSQL example](https://www.bezkoder.com/spring-boot-angular-15-postgresql/) + +> [Angular 15 + Spring Boot + MongoDB example](https://www.bezkoder.com/spring-boot-angular-15-mongodb/) + +> [Angular 16 + Spring Boot + H2 Embedded Database example](https://www.bezkoder.com/spring-boot-angular-16-crud/) + +> [Angular 16 + Spring Boot + MySQL example](https://www.bezkoder.com/spring-boot-angular-16-mysql/) + +> [Angular 16 + Spring Boot + PostgreSQL example](https://www.bezkoder.com/spring-boot-angular-16-postgresql/) + +> [Angular 16 + Spring Boot + MongoDB example](https://www.bezkoder.com/spring-boot-angular-16-mongodb/) + +> [Angular 17 + Spring Boot + H2 Embedded Database example](https://www.bezkoder.com/spring-boot-angular-17-crud/) + +> [Angular 17 + Spring Boot + MySQL example](https://www.bezkoder.com/spring-boot-angular-17-mysql/) + +> [Angular 17 + Spring Boot + PostgreSQL example](https://www.bezkoder.com/spring-boot-angular-17-postgresql/) + +> [Angular 17 + Spring Boot + MongoDB example](https://www.bezkoder.com/spring-boot-angular-17-mongodb/) + +> [React + Spring Boot + MySQL example](https://bezkoder.com/react-spring-boot-crud/) + +> [React + Spring Boot + PostgreSQL example](https://bezkoder.com/spring-boot-react-postgresql/) + +> [React + Spring Boot + MongoDB example](https://bezkoder.com/react-spring-boot-mongodb/) + +Run both Back-end & Front-end in one place: +> [Integrate Angular with Spring Boot Rest API](https://bezkoder.com/integrate-angular-spring-boot/) + +> [Integrate React.js with Spring Boot Rest API](https://bezkoder.com/integrate-reactjs-spring-boot/) + +> [Integrate Vue.js with Spring Boot Rest API](https://bezkoder.com/integrate-vue-spring-boot/) + +## More Practice: +> [Spring Boot File upload example with Multipart File](https://bezkoder.com/spring-boot-file-upload/) + +> [Exception handling: @RestControllerAdvice example in Spring Boot](https://bezkoder.com/spring-boot-restcontrolleradvice/) + +> [Spring Boot Repository Unit Test with @DataJpaTest](https://bezkoder.com/spring-boot-unit-test-jpa-repo-datajpatest/) + +> [Spring Boot Pagination & Sorting example](https://www.bezkoder.com/spring-boot-pagination-sorting-example/) + +Associations: +> [JPA/Hibernate One To Many example](https://www.bezkoder.com/jpa-one-to-many/) + +> [JPA/Hibernate Many To Many example](https://www.bezkoder.com/jpa-many-to-many/) + +> [JPA/Hibernate One To One example](https://www.bezkoder.com/jpa-one-to-one/) + +Deployment: +> [Deploy Spring Boot App on AWS – Elastic Beanstalk](https://www.bezkoder.com/deploy-spring-boot-aws-eb/) + +> [Docker Compose Spring Boot and MySQL example](https://www.bezkoder.com/docker-compose-spring-boot-mysql/) diff --git a/build.gradle.kts b/build.gradle.kts new file mode 100644 index 0000000..76a0a9e --- /dev/null +++ b/build.gradle.kts @@ -0,0 +1,53 @@ +/* + * This file was generated by the Gradle 'init' task. + */ + +plugins { + `java-library` + `maven-publish` +} + +repositories { + mavenLocal() + maven { + url = uri("https://repo.maven.apache.org/maven2/") + } +} + +dependencies { + api(libs.org.springframework.boot.spring.boot.starter.data.jpa) + api(libs.org.springframework.boot.spring.boot.starter.security) + api(libs.org.springframework.boot.spring.boot.starter.web) + api(libs.org.springframework.boot.spring.boot.starter.validation) + api(libs.io.jsonwebtoken.jjwt.api) + api(libs.org.springdoc.springdoc.openapi.starter.webmvc.ui) + runtimeOnly(libs.io.jsonwebtoken.jjwt.impl) + runtimeOnly(libs.io.jsonwebtoken.jjwt.jackson) + runtimeOnly(libs.org.mariadb.jdbc.mariadb.java.client) + testImplementation(libs.org.springframework.boot.spring.boot.starter.test) + testImplementation(libs.org.springframework.security.spring.security.test) + + + compileOnly("org.projectlombok:lombok:1.18.38") + annotationProcessor("org.projectlombok:lombok:1.18.38") + testCompileOnly("org.projectlombok:lombok:1.18.38") + testAnnotationProcessor("org.projectlombok:lombok:1.18.38") +} +group = "kr.re.etri" +version = "0.0.1-SNAPSHOT" +description = "spring-security-refresh-token" +java.sourceCompatibility = JavaVersion.VERSION_21 + +publishing { + publications.create("maven") { + from(components["java"]) + } +} + +tasks.withType() { + options.encoding = "UTF-8" +} + +tasks.withType() { + options.encoding = "UTF-8" +} diff --git a/gradle.properties b/gradle.properties new file mode 100644 index 0000000..377538c --- /dev/null +++ b/gradle.properties @@ -0,0 +1,5 @@ +# This file was generated by the Gradle 'init' task. +# https://docs.gradle.org/current/userguide/build_environment.html#sec:gradle_configuration_properties + +org.gradle.configuration-cache=true + diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml new file mode 100644 index 0000000..5bded6e --- /dev/null +++ b/gradle/libs.versions.toml @@ -0,0 +1,32 @@ +# This file was generated by the Gradle 'init' task. +# https://docs.gradle.org/current/userguide/platforms.html#sub::toml-dependencies-format + +[versions] +com-mysql-mysql-connector-j = "8.0.33" +io-jsonwebtoken-jjwt-api = "0.11.5" +io-jsonwebtoken-jjwt-impl = "0.11.5" +io-jsonwebtoken-jjwt-jackson = "0.11.5" +org-mariadb-jdbc-mariadb-java-client = "3.1.4" +org-projectlombok-lombok = "1.18.26" +org-springdoc-springdoc-openapi-starter-webmvc-ui = "2.1.0" +org-springframework-boot-spring-boot-starter-data-jpa = "3.1.0" +org-springframework-boot-spring-boot-starter-security = "3.1.0" +org-springframework-boot-spring-boot-starter-test = "3.1.0" +org-springframework-boot-spring-boot-starter-validation = "3.1.0" +org-springframework-boot-spring-boot-starter-web = "3.1.0" +org-springframework-security-spring-security-test = "6.1.0" + +[libraries] +com-mysql-mysql-connector-j = { module = "com.mysql:mysql-connector-j", version.ref = "com-mysql-mysql-connector-j" } +io-jsonwebtoken-jjwt-api = { module = "io.jsonwebtoken:jjwt-api", version.ref = "io-jsonwebtoken-jjwt-api" } +io-jsonwebtoken-jjwt-impl = { module = "io.jsonwebtoken:jjwt-impl", version.ref = "io-jsonwebtoken-jjwt-impl" } +io-jsonwebtoken-jjwt-jackson = { module = "io.jsonwebtoken:jjwt-jackson", version.ref = "io-jsonwebtoken-jjwt-jackson" } +org-mariadb-jdbc-mariadb-java-client = { module = "org.mariadb.jdbc:mariadb-java-client", version.ref = "org-mariadb-jdbc-mariadb-java-client" } +org-projectlombok-lombok = { module = "org.projectlombok:lombok", version.ref = "org-projectlombok-lombok" } +org-springdoc-springdoc-openapi-starter-webmvc-ui = { module = "org.springdoc:springdoc-openapi-starter-webmvc-ui", version.ref = "org-springdoc-springdoc-openapi-starter-webmvc-ui" } +org-springframework-boot-spring-boot-starter-data-jpa = { module = "org.springframework.boot:spring-boot-starter-data-jpa", version.ref = "org-springframework-boot-spring-boot-starter-data-jpa" } +org-springframework-boot-spring-boot-starter-security = { module = "org.springframework.boot:spring-boot-starter-security", version.ref = "org-springframework-boot-spring-boot-starter-security" } +org-springframework-boot-spring-boot-starter-test = { module = "org.springframework.boot:spring-boot-starter-test", version.ref = "org-springframework-boot-spring-boot-starter-test" } +org-springframework-boot-spring-boot-starter-validation = { module = "org.springframework.boot:spring-boot-starter-validation", version.ref = "org-springframework-boot-spring-boot-starter-validation" } +org-springframework-boot-spring-boot-starter-web = { module = "org.springframework.boot:spring-boot-starter-web", version.ref = "org-springframework-boot-spring-boot-starter-web" } +org-springframework-security-spring-security-test = { module = "org.springframework.security:spring-security-test", version.ref = "org-springframework-security-spring-security-test" } diff --git a/gradle/wrapper/gradle-wrapper.jar b/gradle/wrapper/gradle-wrapper.jar new file mode 100644 index 0000000000000000000000000000000000000000..1b33c55baabb587c669f562ae36f953de2481846 GIT binary patch literal 43764 zcma&OWmKeVvL#I6?i3D%6z=Zs?ofE*?rw#G$eqJB ziT4y8-Y@s9rkH0Tz>ll(^xkcTl)CY?rS&9VNd66Yc)g^6)JcWaY(5$5gt z8gr3SBXUTN;~cBgz&})qX%#!Fxom2Yau_`&8)+6aSN7YY+pS410rRUU*>J}qL0TnJ zRxt*7QeUqTh8j)Q&iavh<}L+$Jqz))<`IfKussVk%%Ah-Ti?Eo0hQH!rK%K=#EAw0 zwq@@~XNUXRnv8$;zv<6rCRJ6fPD^hfrh;0K?n z=p!u^3xOgWZ%f3+?+>H)9+w^$Tn1e;?UpVMJb!!;f)`6f&4|8mr+g)^@x>_rvnL0< zvD0Hu_N>$(Li7|Jgu0mRh&MV+<}`~Wi*+avM01E)Jtg=)-vViQKax!GeDc!xv$^mL z{#OVBA$U{(Zr8~Xm|cP@odkHC*1R8z6hcLY#N@3E-A8XEvpt066+3t9L_6Zg6j@9Q zj$$%~yO-OS6PUVrM2s)(T4#6=JpI_@Uz+!6=GdyVU?`!F=d;8#ZB@(5g7$A0(`eqY z8_i@3w$0*es5mrSjhW*qzrl!_LQWs4?VfLmo1Sd@Ztt53+etwzAT^8ow_*7Jp`Y|l z*UgSEwvxq+FYO!O*aLf-PinZYne7Ib6ny3u>MjQz=((r3NTEeU4=-i0LBq3H-VJH< z^>1RE3_JwrclUn9vb7HcGUaFRA0QHcnE;6)hnkp%lY1UII#WPAv?-;c?YH}LWB8Nl z{sx-@Z;QxWh9fX8SxLZk8;kMFlGD3Jc^QZVL4nO)1I$zQwvwM&_!kW+LMf&lApv#< zur|EyC|U@5OQuph$TC_ZU`{!vJp`13e9alaR0Dbn5ikLFH7>eIz4QbV|C=%7)F=qo z_>M&5N)d)7G(A%c>}UCrW!Ql_6_A{?R7&CL`;!KOb3 z8Z=$YkV-IF;c7zs{3-WDEFJzuakFbd*4LWd<_kBE8~BFcv}js_2OowRNzWCtCQ6&k z{&~Me92$m*@e0ANcWKuz)?YjB*VoSTx??-3Cc0l2U!X^;Bv@m87eKHukAljrD54R+ zE;@_w4NPe1>3`i5Qy*3^E9x#VB6?}v=~qIprrrd5|DFkg;v5ixo0IsBmik8=Y;zv2 z%Bcf%NE$a44bk^`i4VwDLTbX=q@j9;JWT9JncQ!+Y%2&HHk@1~*L8-{ZpY?(-a9J-1~<1ltr9i~D9`P{XTIFWA6IG8c4;6bFw*lzU-{+?b&%OcIoCiw00n>A1ra zFPE$y@>ebbZlf(sN_iWBzQKDV zmmaLX#zK!@ZdvCANfwV}9@2O&w)!5gSgQzHdk2Q`jG6KD7S+1R5&F)j6QTD^=hq&7 zHUW+r^da^%V(h(wonR(j?BOiC!;y=%nJvz?*aW&5E87qq;2z`EI(f zBJNNSMFF9U{sR-af5{IY&AtoGcoG)Iq-S^v{7+t0>7N(KRoPj;+2N5;9o_nxIGjJ@ z7bYQK)bX)vEhy~VL%N6g^NE@D5VtV+Q8U2%{ji_=6+i^G%xeskEhH>Sqr194PJ$fB zu1y^){?9Vkg(FY2h)3ZHrw0Z<@;(gd_dtF#6y_;Iwi{yX$?asr?0N0_B*CifEi7<6 zq`?OdQjCYbhVcg+7MSgIM|pJRu~`g?g3x?Tl+V}#$It`iD1j+!x+!;wS0+2e>#g?Z z*EA^k7W{jO1r^K~cD#5pamp+o@8&yw6;%b|uiT?{Wa=4+9<}aXWUuL#ZwN1a;lQod zW{pxWCYGXdEq9qAmvAB904}?97=re$>!I%wxPV#|f#@A*Y=qa%zHlDv^yWbR03%V0 zprLP+b(#fBqxI%FiF*-n8HtH6$8f(P6!H3V^ysgd8de-N(@|K!A< z^qP}jp(RaM9kQ(^K(U8O84?D)aU(g?1S8iWwe)gqpHCaFlJxb*ilr{KTnu4_@5{K- z)n=CCeCrPHO0WHz)dDtkbZfUfVBd?53}K>C5*-wC4hpDN8cGk3lu-ypq+EYpb_2H; z%vP4@&+c2p;thaTs$dc^1CDGlPG@A;yGR5@$UEqk6p58qpw#7lc<+W(WR;(vr(D>W z#(K$vE#uBkT=*q&uaZwzz=P5mjiee6>!lV?c}QIX%ZdkO1dHg>Fa#xcGT6~}1*2m9 zkc7l3ItD6Ie~o_aFjI$Ri=C!8uF4!Ky7iG9QTrxVbsQroi|r)SAon#*B*{}TB-?=@ z8~jJs;_R2iDd!$+n$%X6FO&PYS{YhDAS+U2o4su9x~1+U3z7YN5o0qUK&|g^klZ6X zj_vrM5SUTnz5`*}Hyts9ADwLu#x_L=nv$Z0`HqN`Zo=V>OQI)fh01n~*a%01%cx%0 z4LTFVjmW+ipVQv5rYcn3;d2o4qunWUY!p+?s~X~(ost@WR@r@EuDOSs8*MT4fiP>! zkfo^!PWJJ1MHgKS2D_hc?Bs?isSDO61>ebl$U*9*QY(b=i&rp3@3GV@z>KzcZOxip z^dzA~44;R~cnhWz7s$$v?_8y-k!DZys}Q?4IkSyR!)C0j$(Gm|t#e3|QAOFaV2}36 z?dPNY;@I=FaCwylc_;~kXlZsk$_eLkNb~TIl8QQ`mmH&$*zwwR8zHU*sId)rxHu*K z;yZWa8UmCwju%aSNLwD5fBl^b0Ux1%q8YR*uG`53Mi<`5uA^Dc6Ync)J3N7;zQ*75)hf%a@{$H+%S?SGT)ks60)?6j$ zspl|4Ad6@%-r1t*$tT(en!gIXTUDcsj?28ZEzz)dH)SV3bZ+pjMaW0oc~rOPZP@g! zb9E+ndeVO_Ib9c_>{)`01^`ZS198 z)(t=+{Azi11$eu%aU7jbwuQrO`vLOixuh~%4z@mKr_Oc;F%Uq01fA)^W&y+g16e?rkLhTxV!EqC%2}sx_1u7IBq|}Be&7WI z4I<;1-9tJsI&pQIhj>FPkQV9{(m!wYYV@i5h?A0#BN2wqlEwNDIq06|^2oYVa7<~h zI_OLan0Do*4R5P=a3H9`s5*>xU}_PSztg`+2mv)|3nIy=5#Z$%+@tZnr> zLcTI!Mxa`PY7%{;KW~!=;*t)R_sl<^b>eNO@w#fEt(tPMg_jpJpW$q_DoUlkY|uo> z0-1{ouA#;t%spf*7VjkK&$QrvwUERKt^Sdo)5@?qAP)>}Y!h4(JQ!7{wIdkA+|)bv z&8hBwoX4v|+fie}iTslaBX^i*TjwO}f{V)8*!dMmRPi%XAWc8<_IqK1jUsApk)+~R zNFTCD-h>M5Y{qTQ&0#j@I@tmXGj%rzhTW5%Bkh&sSc=$Fv;M@1y!zvYG5P2(2|(&W zlcbR1{--rJ&s!rB{G-sX5^PaM@3EqWVz_y9cwLR9xMig&9gq(voeI)W&{d6j1jh&< zARXi&APWE1FQWh7eoZjuP z;vdgX>zep^{{2%hem;e*gDJhK1Hj12nBLIJoL<=0+8SVEBx7!4Ea+hBY;A1gBwvY<)tj~T=H`^?3>zeWWm|LAwo*S4Z%bDVUe z6r)CH1H!(>OH#MXFJ2V(U(qxD{4Px2`8qfFLG+=a;B^~Te_Z!r3RO%Oc#ZAHKQxV5 zRYXxZ9T2A%NVJIu5Pu7!Mj>t%YDO$T@M=RR(~mi%sv(YXVl`yMLD;+WZ{vG9(@P#e zMo}ZiK^7^h6TV%cG+;jhJ0s>h&VERs=tuZz^Tlu~%d{ZHtq6hX$V9h)Bw|jVCMudd zwZ5l7In8NT)qEPGF$VSKg&fb0%R2RnUnqa){)V(X(s0U zkCdVZe6wy{+_WhZh3qLp245Y2RR$@g-!9PjJ&4~0cFSHMUn=>dapv)hy}|y91ZWTV zCh=z*!S3_?`$&-eZ6xIXUq8RGl9oK0BJw*TdU6A`LJqX9eS3X@F)g$jLkBWFscPhR zpCv8#KeAc^y>>Y$k^=r|K(DTC}T$0#jQBOwB#@`P6~*IuW_8JxCG}J4va{ zsZzt}tt+cv7=l&CEuVtjD6G2~_Meh%p4RGuY?hSt?(sreO_F}8r7Kp$qQdvCdZnDQ zxzc*qchE*E2=WK)^oRNa>Ttj`fpvF-JZ5tu5>X1xw)J@1!IqWjq)ESBG?J|ez`-Tc zi5a}GZx|w-h%5lNDE_3ho0hEXMoaofo#Z;$8|2;EDF&*L+e$u}K=u?pb;dv$SXeQM zD-~7P0i_`Wk$#YP$=hw3UVU+=^@Kuy$>6?~gIXx636jh{PHly_a2xNYe1l60`|y!7 z(u%;ILuW0DDJ)2%y`Zc~hOALnj1~txJtcdD#o4BCT68+8gZe`=^te6H_egxY#nZH&P*)hgYaoJ^qtmpeea`35Fw)cy!w@c#v6E29co8&D9CTCl%^GV|X;SpneSXzV~LXyRn-@K0Df z{tK-nDWA!q38M1~`xUIt_(MO^R(yNY#9@es9RQbY@Ia*xHhD&=k^T+ zJi@j2I|WcgW=PuAc>hs`(&CvgjL2a9Rx zCbZyUpi8NWUOi@S%t+Su4|r&UoU|ze9SVe7p@f1GBkrjkkq)T}X%Qo1g!SQ{O{P?m z-OfGyyWta+UCXH+-+(D^%kw#A1-U;?9129at7MeCCzC{DNgO zeSqsV>W^NIfTO~4({c}KUiuoH8A*J!Cb0*sp*w-Bg@YfBIPZFH!M}C=S=S7PLLcIG zs7K77g~W)~^|+mx9onzMm0qh(f~OsDTzVmRtz=aZTllgR zGUn~_5hw_k&rll<4G=G+`^Xlnw;jNYDJz@bE?|r866F2hA9v0-8=JO3g}IHB#b`hy zA42a0>{0L7CcabSD+F7?pGbS1KMvT{@1_@k!_+Ki|5~EMGt7T%u=79F)8xEiL5!EJ zzuxQ`NBliCoJMJdwu|);zRCD<5Sf?Y>U$trQ-;xj6!s5&w=9E7)%pZ+1Nh&8nCCwM zv5>Ket%I?cxr3vVva`YeR?dGxbG@pi{H#8@kFEf0Jq6~K4>kt26*bxv=P&jyE#e$| zDJB_~imk^-z|o!2njF2hL*|7sHCnzluhJjwLQGDmC)Y9 zr9ZN`s)uCd^XDvn)VirMgW~qfn1~SaN^7vcX#K1G`==UGaDVVx$0BQnubhX|{e z^i0}>k-;BP#Szk{cFjO{2x~LjK{^Upqd&<+03_iMLp0$!6_$@TbX>8U-f*-w-ew1?`CtD_0y_Lo|PfKi52p?`5$Jzx0E8`M0 zNIb?#!K$mM4X%`Ry_yhG5k@*+n4||2!~*+&pYLh~{`~o(W|o64^NrjP?-1Lgu?iK^ zTX6u3?#$?R?N!{599vg>G8RGHw)Hx&=|g4599y}mXNpM{EPKKXB&+m?==R3GsIq?G zL5fH={=zawB(sMlDBJ+{dgb)Vx3pu>L=mDV0{r1Qs{0Pn%TpopH{m(By4;{FBvi{I z$}x!Iw~MJOL~&)p93SDIfP3x%ROjg}X{Sme#hiJ&Yk&a;iR}V|n%PriZBY8SX2*;6 z4hdb^&h;Xz%)BDACY5AUsV!($lib4>11UmcgXKWpzRL8r2Srl*9Y(1uBQsY&hO&uv znDNff0tpHlLISam?o(lOp#CmFdH<6HmA0{UwfU#Y{8M+7od8b8|B|7ZYR9f<#+V|ZSaCQvI$~es~g(Pv{2&m_rKSB2QQ zMvT}$?Ll>V+!9Xh5^iy3?UG;dF-zh~RL#++roOCsW^cZ&({6q|?Jt6`?S8=16Y{oH zp50I7r1AC1(#{b`Aq5cw>ypNggHKM9vBx!W$eYIzD!4KbLsZGr2o8>g<@inmS3*>J zx8oG((8f!ei|M@JZB`p7+n<Q}?>h249<`7xJ?u}_n;Gq(&km#1ULN87CeTO~FY zS_Ty}0TgQhV zOh3T7{{x&LSYGQfKR1PDIkP!WnfC1$l+fs@Di+d4O=eVKeF~2fq#1<8hEvpwuqcaH z4A8u~r^gnY3u6}zj*RHjk{AHhrrDqaj?|6GaVJbV%o-nATw}ASFr!f`Oz|u_QPkR# z0mDudY1dZRlk@TyQ?%Eti=$_WNFtLpSx9=S^be{wXINp%MU?a`F66LNU<c;0&ngifmP9i;bj6&hdGMW^Kf8e6ZDXbQD&$QAAMo;OQ)G zW(qlHh;}!ZP)JKEjm$VZjTs@hk&4{?@+NADuYrr!R^cJzU{kGc1yB?;7mIyAWwhbeA_l_lw-iDVi7wcFurf5 z#Uw)A@a9fOf{D}AWE%<`s1L_AwpZ?F!Vac$LYkp<#A!!`XKaDC{A%)~K#5z6>Hv@V zBEqF(D5?@6r3Pwj$^krpPDCjB+UOszqUS;b2n>&iAFcw<*im2(b3|5u6SK!n9Sg4I z0KLcwA6{Mq?p%t>aW0W!PQ>iUeYvNjdKYqII!CE7SsS&Rj)eIw-K4jtI?II+0IdGq z2WT|L3RL?;GtGgt1LWfI4Ka`9dbZXc$TMJ~8#Juv@K^1RJN@yzdLS8$AJ(>g!U9`# zx}qr7JWlU+&m)VG*Se;rGisutS%!6yybi%B`bv|9rjS(xOUIvbNz5qtvC$_JYY+c& za*3*2$RUH8p%pSq>48xR)4qsp!Q7BEiJ*`^>^6INRbC@>+2q9?x(h0bpc>GaNFi$K zPH$6!#(~{8@0QZk=)QnM#I=bDx5vTvjm$f4K}%*s+((H2>tUTf==$wqyoI`oxI7>C z&>5fe)Yg)SmT)eA(|j@JYR1M%KixxC-Eceknf-;N=jJTwKvk#@|J^&5H0c+%KxHUI z6dQbwwVx3p?X<_VRVb2fStH?HH zFR@Mp=qX%#L3XL)+$PXKV|o|#DpHAoqvj6uQKe@M-mnhCSou7Dj4YuO6^*V`m)1lf z;)@e%1!Qg$10w8uEmz{ENb$^%u}B;J7sDd zump}onoD#!l=agcBR)iG!3AF0-63%@`K9G(CzKrm$VJ{v7^O9Ps7Zej|3m= zVXlR&yW6=Y%mD30G@|tf=yC7-#L!16Q=dq&@beWgaIL40k0n% z)QHrp2Jck#evLMM1RGt3WvQ936ZC9vEje0nFMfvmOHVI+&okB_K|l-;|4vW;qk>n~ z+|kk8#`K?x`q>`(f6A${wfw9Cx(^)~tX7<#TpxR#zYG2P+FY~mG{tnEkv~d6oUQA+ z&hNTL=~Y@rF`v-RZlts$nb$3(OL1&@Y11hhL9+zUb6)SP!;CD)^GUtUpCHBE`j1te zAGud@miCVFLk$fjsrcpjsadP__yj9iEZUW{Ll7PPi<$R;m1o!&Xdl~R_v0;oDX2z^!&8}zNGA}iYG|k zmehMd1%?R)u6R#<)B)1oe9TgYH5-CqUT8N7K-A-dm3hbm_W21p%8)H{O)xUlBVb+iUR}-v5dFaCyfSd zC6Bd7=N4A@+Bna=!-l|*_(nWGDpoyU>nH=}IOrLfS+-d40&(Wo*dDB9nQiA2Tse$R z;uq{`X7LLzP)%Y9aHa4YQ%H?htkWd3Owv&UYbr5NUDAH^<l@Z0Cx%`N+B*i!!1u>D8%;Qt1$ zE5O0{-`9gdDxZ!`0m}ywH!;c{oBfL-(BH<&SQ~smbcobU!j49O^f4&IIYh~f+hK*M zZwTp%{ZSAhMFj1qFaOA+3)p^gnXH^=)`NTYgTu!CLpEV2NF=~-`(}7p^Eof=@VUbd z_9U|8qF7Rueg&$qpSSkN%%%DpbV?8E8ivu@ensI0toJ7Eas^jyFReQ1JeY9plb^{m z&eQO)qPLZQ6O;FTr*aJq=$cMN)QlQO@G&%z?BKUs1&I^`lq>=QLODwa`(mFGC`0H< zOlc*|N?B5&!U6BuJvkL?s1&nsi$*5cCv7^j_*l&$-sBmRS85UIrE--7eD8Gr3^+o? zqG-Yl4S&E;>H>k^a0GdUI(|n1`ws@)1%sq2XBdK`mqrNq_b4N{#VpouCXLzNvjoFv zo9wMQ6l0+FT+?%N(ka*;%m~(?338bu32v26!{r)|w8J`EL|t$}TA4q_FJRX5 zCPa{hc_I(7TGE#@rO-(!$1H3N-C0{R$J=yPCXCtGk{4>=*B56JdXU9cQVwB`6~cQZ zf^qK21x_d>X%dT!!)CJQ3mlHA@ z{Prkgfs6=Tz%63$6Zr8CO0Ak3A)Cv#@BVKr&aiKG7RYxY$Yx>Bj#3gJk*~Ps-jc1l z;4nltQwwT4@Z)}Pb!3xM?+EW0qEKA)sqzw~!C6wd^{03-9aGf3Jmt=}w-*!yXupLf z;)>-7uvWN4Unn8b4kfIza-X=x*e4n5pU`HtgpFFd))s$C@#d>aUl3helLom+RYb&g zI7A9GXLRZPl}iQS*d$Azxg-VgcUr*lpLnbPKUV{QI|bsG{8bLG<%CF( zMoS4pRDtLVYOWG^@ox^h8xL~afW_9DcE#^1eEC1SVSb1BfDi^@g?#f6e%v~Aw>@w- zIY0k+2lGWNV|aA*e#`U3=+oBDmGeInfcL)>*!w|*;mWiKNG6wP6AW4-4imN!W)!hE zA02~S1*@Q`fD*+qX@f3!2yJX&6FsEfPditB%TWo3=HA;T3o2IrjS@9SSxv%{{7&4_ zdS#r4OU41~GYMiib#z#O;zohNbhJknrPPZS6sN$%HB=jUnlCO_w5Gw5EeE@KV>soy z2EZ?Y|4RQDDjt5y!WBlZ(8M)|HP<0YyG|D%RqD+K#e7-##o3IZxS^wQ5{Kbzb6h(i z#(wZ|^ei>8`%ta*!2tJzwMv+IFHLF`zTU8E^Mu!R*45_=ccqI};Zbyxw@U%a#2}%f zF>q?SrUa_a4H9l+uW8JHh2Oob>NyUwG=QH~-^ZebU*R@67DcXdz2{HVB4#@edz?B< z5!rQH3O0>A&ylROO%G^fimV*LX7>!%re{_Sm6N>S{+GW1LCnGImHRoF@csnFzn@P0 zM=jld0z%oz;j=>c7mMwzq$B^2mae7NiG}%>(wtmsDXkWk{?BeMpTrIt3Mizq?vRsf zi_WjNp+61uV(%gEU-Vf0;>~vcDhe(dzWdaf#4mH3o^v{0EWhj?E?$5v02sV@xL0l4 zX0_IMFtQ44PfWBbPYN#}qxa%=J%dlR{O!KyZvk^g5s?sTNycWYPJ^FK(nl3k?z-5t z39#hKrdO7V(@!TU)LAPY&ngnZ1MzLEeEiZznn7e-jLCy8LO zu^7_#z*%I-BjS#Pg-;zKWWqX-+Ly$T!4`vTe5ZOV0j?TJVA*2?*=82^GVlZIuH%9s zXiV&(T(QGHHah=s&7e|6y?g+XxZGmK55`wGV>@1U)Th&=JTgJq>4mI&Av2C z)w+kRoj_dA!;SfTfkgMPO>7Dw6&1*Hi1q?54Yng`JO&q->^CX21^PrU^JU#CJ_qhV zSG>afB%>2fx<~g8p=P8Yzxqc}s@>>{g7}F!;lCXvF#RV)^fyYb_)iKVCz1xEq=fJ| z0a7DMCK*FuP=NM*5h;*D`R4y$6cpW-E&-i{v`x=Jbk_xSn@2T3q!3HoAOB`@5Vg6) z{PW|@9o!e;v1jZ2{=Uw6S6o{g82x6g=k!)cFSC*oemHaVjg?VpEmtUuD2_J^A~$4* z3O7HsbA6wxw{TP5Kk)(Vm?gKo+_}11vbo{Tp_5x79P~#F)ahQXT)tSH5;;14?s)On zel1J>1x>+7;g1Iz2FRpnYz;sD0wG9Q!vuzE9yKi3@4a9Nh1!GGN?hA)!mZEnnHh&i zf?#ZEN2sFbf~kV;>K3UNj1&vFhc^sxgj8FCL4v>EOYL?2uuT`0eDH}R zmtUJMxVrV5H{L53hu3#qaWLUa#5zY?f5ozIn|PkMWNP%n zWB5!B0LZB0kLw$k39=!akkE9Q>F4j+q434jB4VmslQ;$ zKiO#FZ`p|dKS716jpcvR{QJkSNfDVhr2%~eHrW;fU45>>snr*S8Vik-5eN5k*c2Mp zyxvX&_cFbB6lODXznHHT|rsURe2!swomtrqc~w5 zymTM8!w`1{04CBprR!_F{5LB+2_SOuZN{b*!J~1ZiPpP-M;);!ce!rOPDLtgR@Ie1 zPreuqm4!H)hYePcW1WZ0Fyaqe%l}F~Orr)~+;mkS&pOhP5Ebb`cnUt!X_QhP4_4p( z8YKQCDKGIy>?WIFm3-}Br2-N`T&FOi?t)$hjphB9wOhBXU#Hb+zm&We_-O)s(wc`2 z8?VsvU;J>Ju7n}uUb3s1yPx_F*|FlAi=Ge=-kN?1;`~6szP%$3B0|8Sqp%ebM)F8v zADFrbeT0cgE>M0DMV@_Ze*GHM>q}wWMzt|GYC%}r{OXRG3Ij&<+nx9;4jE${Fj_r* z`{z1AW_6Myd)i6e0E-h&m{{CvzH=Xg!&(bLYgRMO_YVd8JU7W+7MuGWNE=4@OvP9+ zxi^vqS@5%+#gf*Z@RVyU9N1sO-(rY$24LGsg1>w>s6ST^@)|D9>cT50maXLUD{Fzf zt~tp{OSTEKg3ZSQyQQ5r51){%=?xlZ54*t1;Ow)zLe3i?8tD8YyY^k%M)e`V*r+vL zPqUf&m)U+zxps+NprxMHF{QSxv}>lE{JZETNk1&F+R~bp{_T$dbXL2UGnB|hgh*p4h$clt#6;NO~>zuyY@C-MD@)JCc5XrYOt`wW7! z_ti2hhZBMJNbn0O-uTxl_b6Hm313^fG@e;RrhIUK9@# z+DHGv_Ow$%S8D%RB}`doJjJy*aOa5mGHVHz0e0>>O_%+^56?IkA5eN+L1BVCp4~m=1eeL zb;#G!#^5G%6Mw}r1KnaKsLvJB%HZL)!3OxT{k$Yo-XrJ?|7{s4!H+S2o?N|^Z z)+?IE9H7h~Vxn5hTis^3wHYuOU84+bWd)cUKuHapq=&}WV#OxHpLab`NpwHm8LmOo zjri+!k;7j_?FP##CpM+pOVx*0wExEex z@`#)K<-ZrGyArK;a%Km`^+We|eT+#MygHOT6lXBmz`8|lyZOwL1+b+?Z$0OhMEp3R z&J=iRERpv~TC=p2-BYLC*?4 zxvPs9V@g=JT0>zky5Poj=fW_M!c)Xxz1<=&_ZcL=LMZJqlnO1P^xwGGW*Z+yTBvbV z-IFe6;(k1@$1;tS>{%pXZ_7w+i?N4A2=TXnGf=YhePg8bH8M|Lk-->+w8Y+FjZ;L=wSGwxfA`gqSn)f(XNuSm>6Y z@|#e-)I(PQ^G@N`%|_DZSb4_pkaEF0!-nqY+t#pyA>{9^*I-zw4SYA1_z2Bs$XGUZbGA;VeMo%CezHK0lO={L%G)dI-+8w?r9iexdoB{?l zbJ}C?huIhWXBVs7oo{!$lOTlvCLZ_KN1N+XJGuG$rh<^eUQIqcI7^pmqhBSaOKNRq zrx~w^?9C?*&rNwP_SPYmo;J-#!G|{`$JZK7DxsM3N^8iR4vvn>E4MU&Oe1DKJvLc~ zCT>KLZ1;t@My zRj_2hI^61T&LIz)S!+AQIV23n1>ng+LUvzv;xu!4;wpqb#EZz;F)BLUzT;8UA1x*6vJ zicB!3Mj03s*kGV{g`fpC?V^s(=JG-k1EMHbkdP4P*1^8p_TqO|;!Zr%GuP$8KLxuf z=pv*H;kzd;P|2`JmBt~h6|GxdU~@weK5O=X&5~w$HpfO}@l-T7@vTCxVOwCkoPQv8 z@aV_)I5HQtfs7^X=C03zYmH4m0S!V@JINm6#(JmZRHBD?T!m^DdiZJrhKpBcur2u1 zf9e4%k$$vcFopK5!CC`;ww(CKL~}mlxK_Pv!cOsFgVkNIghA2Au@)t6;Y3*2gK=5d z?|@1a)-(sQ%uFOmJ7v2iG&l&m^u&^6DJM#XzCrF%r>{2XKyxLD2rgWBD;i(!e4InDQBDg==^z;AzT2z~OmV0!?Z z0S9pX$+E;w3WN;v&NYT=+G8hf=6w0E1$0AOr61}eOvE8W1jX%>&Mjo7&!ulawgzLH zbcb+IF(s^3aj12WSi#pzIpijJJzkP?JzRawnxmNDSUR#7!29vHULCE<3Aa#be}ie~d|!V+ z%l~s9Odo$G&fH!t!+`rUT0T9DulF!Yq&BfQWFZV1L9D($r4H(}Gnf6k3^wa7g5|Ws zj7%d`!3(0bb55yhC6@Q{?H|2os{_F%o=;-h{@Yyyn*V7?{s%Grvpe!H^kl6tF4Zf5 z{Jv1~yZ*iIWL_9C*8pBMQArfJJ0d9Df6Kl#wa}7Xa#Ef_5B7=X}DzbQXVPfCwTO@9+@;A^Ti6il_C>g?A-GFwA0#U;t4;wOm-4oS})h z5&on>NAu67O?YCQr%7XIzY%LS4bha9*e*4bU4{lGCUmO2UQ2U)QOqClLo61Kx~3dI zmV3*(P6F_Tr-oP%x!0kTnnT?Ep5j;_IQ^pTRp=e8dmJtI4YgWd0}+b2=ATkOhgpXe z;jmw+FBLE}UIs4!&HflFr4)vMFOJ19W4f2^W(=2)F%TAL)+=F>IE$=e=@j-*bFLSg z)wf|uFQu+!=N-UzSef62u0-C8Zc7 zo6@F)c+nZA{H|+~7i$DCU0pL{0Ye|fKLuV^w!0Y^tT$isu%i1Iw&N|tX3kwFKJN(M zXS`k9js66o$r)x?TWL}Kxl`wUDUpwFx(w4Yk%49;$sgVvT~n8AgfG~HUcDt1TRo^s zdla@6heJB@JV z!vK;BUMznhzGK6PVtj0)GB=zTv6)Q9Yt@l#fv7>wKovLobMV-+(8)NJmyF8R zcB|_K7=FJGGn^X@JdFaat0uhKjp3>k#^&xE_}6NYNG?kgTp>2Iu?ElUjt4~E-?`Du z?mDCS9wbuS%fU?5BU@Ijx>1HG*N?gIP+<~xE4u=>H`8o((cS5M6@_OK%jSjFHirQK zN9@~NXFx*jS{<|bgSpC|SAnA@I)+GB=2W|JJChLI_mx+-J(mSJ!b)uUom6nH0#2^(L@JBlV#t zLl?j54s`Y3vE^c_3^Hl0TGu*tw_n?@HyO@ZrENxA+^!)OvUX28gDSF*xFtQzM$A+O zCG=n#6~r|3zt=8%GuG} z<#VCZ%2?3Q(Ad#Y7GMJ~{U3>E{5e@z6+rgZLX{Cxk^p-7dip^d29;2N1_mm4QkASo z-L`GWWPCq$uCo;X_BmGIpJFBlhl<8~EG{vOD1o|X$aB9KPhWO_cKiU*$HWEgtf=fn zsO%9bp~D2c@?*K9jVN@_vhR03>M_8h!_~%aN!Cnr?s-!;U3SVfmhRwk11A^8Ns`@KeE}+ zN$H}a1U6E;*j5&~Og!xHdfK5M<~xka)x-0N)K_&e7AjMz`toDzasH+^1bZlC!n()crk9kg@$(Y{wdKvbuUd04N^8}t1iOgsKF zGa%%XWx@WoVaNC1!|&{5ZbkopFre-Lu(LCE5HWZBoE#W@er9W<>R=^oYxBvypN#x3 zq#LC8&q)GFP=5^-bpHj?LW=)-g+3_)Ylps!3^YQ{9~O9&K)xgy zMkCWaApU-MI~e^cV{Je75Qr7eF%&_H)BvfyKL=gIA>;OSq(y z052BFz3E(Prg~09>|_Z@!qj}@;8yxnw+#Ej0?Rk<y}4ghbD569B{9hSFr*^ygZ zr6j7P#gtZh6tMk6?4V$*Jgz+#&ug;yOr>=qdI#9U&^am2qoh4Jy}H2%a|#Fs{E(5r z%!ijh;VuGA6)W)cJZx+;9Bp1LMUzN~x_8lQ#D3+sL{be-Jyeo@@dv7XguJ&S5vrH` z>QxOMWn7N-T!D@1(@4>ZlL^y5>m#0!HKovs12GRav4z!>p(1~xok8+_{| z#Ae4{9#NLh#Vj2&JuIn5$d6t@__`o}umFo(n0QxUtd2GKCyE+erwXY?`cm*h&^9*8 zJ+8x6fRZI-e$CRygofIQN^dWysCxgkyr{(_oBwwSRxZora1(%(aC!5BTtj^+YuevI zx?)H#(xlALUp6QJ!=l9N__$cxBZ5p&7;qD3PsXRFVd<({Kh+mShFWJNpy`N@ab7?9 zv5=klvCJ4bx|-pvOO2-+G)6O?$&)ncA#Urze2rlBfp#htudhx-NeRnJ@u%^_bfw4o z4|{b8SkPV3b>Wera1W(+N@p9H>dc6{cnkh-sgr?e%(YkWvK+0YXVwk0=d`)}*47*B z5JGkEdVix!w7-<%r0JF~`ZMMPe;f0EQHuYHxya`puazyph*ZSb1mJAt^k4549BfS; zK7~T&lRb=W{s&t`DJ$B}s-eH1&&-wEOH1KWsKn0a(ZI+G!v&W4A*cl>qAvUv6pbUR z#(f#EKV8~hk&8oayBz4vaswc(?qw1vn`yC zZQDl2PCB-&Uu@g9ZQHhO+v(W0bNig{-k0;;`+wM@#@J)8r?qOYs#&vUna8ILxN7S{ zp1s41KnR8miQJtJtOr|+qk}wrLt+N*z#5o`TmD1)E&QD(Vh&pjZJ_J*0!8dy_ z>^=@v=J)C`x&gjqAYu`}t^S=DFCtc0MkBU2zf|69?xW`Ck~(6zLD)gSE{7n~6w8j_ zoH&~$ED2k5-yRa0!r8fMRy z;QjBYUaUnpd}mf%iVFPR%Dg9!d>g`01m~>2s))`W|5!kc+_&Y>wD@@C9%>-lE`WB0 zOIf%FVD^cj#2hCkFgi-fgzIfOi+ya)MZK@IZhHT5FVEaSbv-oDDs0W)pA0&^nM0TW zmgJmd7b1R7b0a`UwWJYZXp4AJPteYLH>@M|xZFKwm!t3D3&q~av?i)WvAKHE{RqpD{{%OhYkK?47}+}` zrR2(Iv9bhVa;cDzJ%6ntcSbx7v7J@Y4x&+eWSKZ*eR7_=CVIUSB$^lfYe@g+p|LD{ zPSpQmxx@b$%d!05|H}WzBT4_cq?@~dvy<7s&QWtieJ9)hd4)$SZz}#H2UTi$CkFWW|I)v_-NjuH!VypONC=1`A=rm_jfzQ8Fu~1r8i{q-+S_j$ z#u^t&Xnfi5tZtl@^!fUJhx@~Cg0*vXMK}D{>|$#T*+mj(J_@c{jXBF|rm4-8%Z2o! z2z0o(4%8KljCm^>6HDK!{jI7p+RAPcty_~GZ~R_+=+UzZ0qzOwD=;YeZt*?3%UGdr z`c|BPE;yUbnyARUl&XWSNJ<+uRt%!xPF&K;(l$^JcA_CMH6)FZt{>6ah$|(9$2fc~ z=CD00uHM{qv;{Zk9FR0~u|3|Eiqv9?z2#^GqylT5>6JNZwKqKBzzQpKU2_pmtD;CT zi%Ktau!Y2Tldfu&b0UgmF(SSBID)15*r08eoUe#bT_K-G4VecJL2Pa=6D1K6({zj6 za(2Z{r!FY5W^y{qZ}08+h9f>EKd&PN90f}Sc0ejf%kB4+f#T8Q1=Pj=~#pi$U zp#5rMR%W25>k?<$;$x72pkLibu1N|jX4cWjD3q^Pk3js!uK6h7!dlvw24crL|MZs_ zb%Y%?Fyp0bY0HkG^XyS76Ts*|Giw{31LR~+WU5NejqfPr73Rp!xQ1mLgq@mdWncLy z%8}|nzS4P&`^;zAR-&nm5f;D-%yNQPwq4N7&yULM8bkttkD)hVU>h>t47`{8?n2&4 zjEfL}UEagLUYwdx0sB2QXGeRmL?sZ%J!XM`$@ODc2!y|2#7hys=b$LrGbvvjx`Iqi z&RDDm3YBrlKhl`O@%%&rhLWZ*ABFz2nHu7k~3@e4)kO3%$=?GEFUcCF=6-1n!x^vmu+Ai*amgXH+Rknl6U>#9w;A} zn2xanZSDu`4%%x}+~FG{Wbi1jo@wqBc5(5Xl~d0KW(^Iu(U3>WB@-(&vn_PJt9{1`e9Iic@+{VPc`vP776L*viP{wYB2Iff8hB%E3|o zGMOu)tJX!`qJ}ZPzq7>=`*9TmETN7xwU;^AmFZ-ckZjV5B2T09pYliaqGFY|X#E-8 z20b>y?(r-Fn5*WZ-GsK}4WM>@TTqsxvSYWL6>18q8Q`~JO1{vLND2wg@58OaU!EvT z1|o+f1mVXz2EKAbL!Q=QWQKDZpV|jznuJ}@-)1&cdo z^&~b4Mx{*1gurlH;Vhk5g_cM&6LOHS2 zRkLfO#HabR1JD4Vc2t828dCUG#DL}f5QDSBg?o)IYYi@_xVwR2w_ntlpAW0NWk$F1 z$If?*lP&Ka1oWfl!)1c3fl`g*lMW3JOn#)R1+tfwrs`aiFUgz3;XIJ>{QFxLCkK30 zNS-)#DON3yb!7LBHQJ$)4y%TN82DC2-9tOIqzhZ27@WY^<6}vXCWcR5iN{LN8{0u9 zNXayqD=G|e?O^*ms*4P?G%o@J1tN9_76e}E#66mr89%W_&w4n66~R;X_vWD(oArwj z4CpY`)_mH2FvDuxgT+akffhX0b_slJJ*?Jn3O3~moqu2Fs1oL*>7m=oVek2bnprnW zixkaIFU%+3XhNA@@9hyhFwqsH2bM|`P?G>i<-gy>NflhrN{$9?LZ1ynSE_Mj0rADF zhOz4FnK}wpLmQuV zgO4_Oz9GBu_NN>cPLA=`SP^$gxAnj;WjJnBi%Q1zg`*^cG;Q)#3Gv@c^j6L{arv>- zAW%8WrSAVY1sj$=umcAf#ZgC8UGZGoamK}hR7j6}i8#np8ruUlvgQ$j+AQglFsQQq zOjyHf22pxh9+h#n$21&$h?2uq0>C9P?P=Juw0|;oE~c$H{#RGfa>| zj)Iv&uOnaf@foiBJ}_;zyPHcZt1U~nOcNB{)og8Btv+;f@PIT*xz$x!G?u0Di$lo7 zOugtQ$Wx|C($fyJTZE1JvR~i7LP{ zbdIwqYghQAJi9p}V&$=*2Azev$6K@pyblphgpv8^9bN!?V}{BkC!o#bl&AP!3DAjM zmWFsvn2fKWCfjcAQmE+=c3Y7j@#7|{;;0f~PIodmq*;W9Fiak|gil6$w3%b_Pr6K_ zJEG@&!J%DgBZJDCMn^7mk`JV0&l07Bt`1ymM|;a)MOWz*bh2#d{i?SDe9IcHs7 zjCrnyQ*Y5GzIt}>`bD91o#~5H?4_nckAgotN{2%!?wsSl|LVmJht$uhGa+HiH>;av z8c?mcMYM7;mvWr6noUR{)gE!=i7cZUY7e;HXa221KkRoc2UB>s$Y(k%NzTSEr>W(u z<(4mcc)4rB_&bPzX*1?*ra%VF}P1nwiP5cykJ&W{!OTlz&Td0pOkVp+wc z@k=-Hg=()hNg=Q!Ub%`BONH{ z_=ZFgetj@)NvppAK2>8r!KAgi>#%*7;O-o9MOOfQjV-n@BX6;Xw;I`%HBkk20v`qoVd0)}L6_49y1IhR z_OS}+eto}OPVRn*?UHC{eGyFU7JkPz!+gX4P>?h3QOwGS63fv4D1*no^6PveUeE5% zlehjv_3_^j^C({a2&RSoVlOn71D8WwMu9@Nb@=E_>1R*ve3`#TF(NA0?d9IR_tm=P zOP-x;gS*vtyE1Cm zG0L?2nRUFj#aLr-R1fX*$sXhad)~xdA*=hF3zPZhha<2O$Ps+F07w*3#MTe?)T8|A!P!v+a|ot{|^$q(TX`35O{WI0RbU zCj?hgOv=Z)xV?F`@HKI11IKtT^ocP78cqHU!YS@cHI@{fPD?YXL)?sD~9thOAv4JM|K8OlQhPXgnevF=F7GKD2#sZW*d za}ma31wLm81IZxX(W#A9mBvLZr|PoLnP>S4BhpK8{YV_}C|p<)4#yO{#ISbco92^3 zv&kCE(q9Wi;9%7>>PQ!zSkM%qqqLZW7O`VXvcj;WcJ`2~v?ZTYB@$Q&^CTfvy?1r^ z;Cdi+PTtmQwHX_7Kz?r#1>D zS5lWU(Mw_$B&`ZPmqxpIvK<~fbXq?x20k1~9az-Q!uR78mCgRj*eQ>zh3c$W}>^+w^dIr-u{@s30J=)1zF8?Wn|H`GS<=>Om|DjzC{}Jt?{!fSJe*@$H zg>wFnlT)k#T?LslW zu$^7Uy~$SQ21cE?3Ijl+bLfuH^U5P^$@~*UY#|_`uvAIe(+wD2eF}z_y!pvomuVO; zS^9fbdv)pcm-B@CW|Upm<7s|0+$@@<&*>$a{aW+oJ%f+VMO<#wa)7n|JL5egEgoBv zl$BY(NQjE0#*nv=!kMnp&{2Le#30b)Ql2e!VkPLK*+{jv77H7)xG7&=aPHL7LK9ER z5lfHxBI5O{-3S?GU4X6$yVk>lFn;ApnwZybdC-GAvaznGW-lScIls-P?Km2mF>%B2 zkcrXTk+__hj-3f48U%|jX9*|Ps41U_cd>2QW81Lz9}%`mTDIhE)jYI$q$ma7Y-`>% z8=u+Oftgcj%~TU}3nP8&h7k+}$D-CCgS~wtWvM|UU77r^pUw3YCV80Ou*+bH0!mf0 zxzUq4ed6y>oYFz7+l18PGGzhB^pqSt)si=9M>~0(Bx9*5r~W7sa#w+_1TSj3Jn9mW zMuG9BxN=}4645Cpa#SVKjFst;9UUY@O<|wpnZk$kE+to^4!?0@?Cwr3(>!NjYbu?x z1!U-?0_O?k!NdM^-rIQ8p)%?M+2xkhltt*|l=%z2WFJhme7*2xD~@zk#`dQR$6Lmd zb3LOD4fdt$Cq>?1<%&Y^wTWX=eHQ49Xl_lFUA(YQYHGHhd}@!VpYHHm=(1-O=yfK#kKe|2Xc*9}?BDFN zD7FJM-AjVi)T~OG)hpSWqH>vlb41V#^G2B_EvYlWhDB{Z;Q9-0)ja(O+By`31=biA zG&Fs#5!%_mHi|E4Nm$;vVQ!*>=_F;ZC=1DTPB#CICS5fL2T3XmzyHu?bI;m7D4@#; ztr~;dGYwb?m^VebuULtS4lkC_7>KCS)F@)0OdxZIFZp@FM_pHnJes8YOvwB|++#G( z&dm*OP^cz95Wi15vh`Q+yB>R{8zqEhz5of>Po$9LNE{xS<)lg2*roP*sQ}3r3t<}; zPbDl{lk{pox~2(XY5=qg0z!W-x^PJ`VVtz$git7?)!h>`91&&hESZy1KCJ2nS^yMH z!=Q$eTyRi68rKxdDsdt+%J_&lapa{ds^HV9Ngp^YDvtq&-Xp}60B_w@Ma>_1TTC;^ zpbe!#gH}#fFLkNo#|`jcn?5LeUYto%==XBk6Ik0kc4$6Z+L3x^4=M6OI1=z5u#M%0 z0E`kevJEpJjvvN>+g`?gtnbo$@p4VumliZV3Z%CfXXB&wPS^5C+7of2tyVkMwNWBiTE2 z8CdPu3i{*vR-I(NY5syRR}I1TJOV@DJy-Xmvxn^IInF>Tx2e)eE9jVSz69$6T`M9-&om!T+I znia!ZWJRB28o_srWlAxtz4VVft8)cYloIoVF=pL zugnk@vFLXQ_^7;%hn9x;Vq?lzg7%CQR^c#S)Oc-8d=q_!2ZVH764V z!wDKSgP}BrVV6SfCLZnYe-7f;igDs9t+K*rbMAKsp9L$Kh<6Z;e7;xxced zn=FGY<}CUz31a2G}$Q(`_r~75PzM4l_({Hg&b@d8&jC}B?2<+ed`f#qMEWi z`gm!STV9E4sLaQX+sp5Nu9*;9g12naf5?=P9p@H@f}dxYprH+3ju)uDFt^V{G0APn zS;16Dk{*fm6&BCg#2vo?7cbkkI4R`S9SSEJ=#KBk3rl69SxnCnS#{*$!^T9UUmO#&XXKjHKBqLdt^3yVvu8yn|{ zZ#%1CP)8t-PAz(+_g?xyq;C2<9<5Yy<~C74Iw(y>uUL$+$mp(DRcCWbCKiGCZw@?_ zdomfp+C5xt;j5L@VfhF*xvZdXwA5pcdsG>G<8II-|1dhAgzS&KArcb0BD4ZZ#WfiEY{hkCq5%z9@f|!EwTm;UEjKJsUo696V>h zy##eXYX}GUu%t{Gql8vVZKkNhQeQ4C%n|RmxL4ee5$cgwlU+?V7a?(jI#&3wid+Kz5+x^G!bb#$q>QpR#BZ}Xo5UW^ zD&I`;?(a}Oys7-`I^|AkN?{XLZNa{@27Dv^s4pGowuyhHuXc zuctKG2x0{WCvg_sGN^n9myJ}&FXyGmUQnW7fR$=bj$AHR88-q$D!*8MNB{YvTTEyS zn22f@WMdvg5~o_2wkjItJN@?mDZ9UUlat2zCh(zVE=dGi$rjXF7&}*sxac^%HFD`Y zTM5D3u5x**{bW!68DL1A!s&$2XG@ytB~dX-?BF9U@XZABO`a|LM1X3HWCllgl0+uL z04S*PX$%|^WAq%jkzp~%9HyYIF{Ym?k)j3nMwPZ=hlCg9!G+t>tf0o|J2%t1 ztC+`((dUplgm3`+0JN~}&FRRJ3?l*>Y&TfjS>!ShS`*MwO{WIbAZR#<%M|4c4^dY8 z{Rh;-!qhY=dz5JthbWoovLY~jNaw>%tS4gHVlt5epV8ekXm#==Po$)}mh^u*cE>q7*kvX&gq)(AHoItMYH6^s6f(deNw%}1=7O~bTHSj1rm2|Cq+3M z93djjdomWCTCYu!3Slx2bZVy#CWDozNedIHbqa|otsUl+ut?>a;}OqPfQA05Yim_2 zs@^BjPoFHOYNc6VbNaR5QZfSMh2S*`BGwcHMM(1@w{-4jVqE8Eu0Bi%d!E*^Rj?cR z7qgxkINXZR)K^=fh{pc0DCKtrydVbVILI>@Y0!Jm>x-xM!gu%dehm?cC6ok_msDVA*J#{75%4IZt}X|tIVPReZS#aCvuHkZxc zHVMtUhT(wp09+w9j9eRqz~LtuSNi2rQx_QgQ(}jBt7NqyT&ma61ldD(s9x%@q~PQl zp6N*?=N$BtvjQ_xIT{+vhb1>{pM0Arde0!X-y))A4znDrVx8yrP3B1(7bKPE5jR@5 zwpzwT4cu~_qUG#zYMZ_!2Tkl9zP>M%cy>9Y(@&VoB84#%>amTAH{(hL4cDYt!^{8L z645F>BWO6QaFJ-{C-i|-d%j7#&7)$X7pv#%9J6da#9FB5KyDhkA+~)G0^87!^}AP>XaCSScr;kL;Z%RSPD2CgoJ;gpYT5&6NUK$86$T?jRH=w8nI9Z534O?5fk{kd z`(-t$8W|#$3>xoMfXvV^-A(Q~$8SKDE^!T;J+rQXP71XZ(kCCbP%bAQ1|%$%Ov9_a zyC`QP3uPvFoBqr_+$HenHklqyIr>PU_Fk5$2C+0eYy^~7U&(!B&&P2%7#mBUhM!z> z_B$Ko?{Pf6?)gpYs~N*y%-3!1>o-4;@1Zz9VQHh)j5U1aL-Hyu@1d?X;jtDBNk*vMXPn@ z+u@wxHN*{uHR!*g*4Xo&w;5A+=Pf9w#PeZ^x@UD?iQ&${K2c}UQgLRik-rKM#Y5rdDphdcNTF~cCX&9ViRP}`>L)QA4zNXeG)KXFzSDa6 zd^St;inY6J_i=5mcGTx4_^Ys`M3l%Q==f>{8S1LEHn{y(kbxn5g1ezt4CELqy)~TV6{;VW>O9?5^ ztcoxHRa0jQY7>wwHWcxA-BCwzsP>63Kt&3fy*n#Cha687CQurXaRQnf5wc9o8v7Rw zNwGr2fac;Wr-Ldehn7tF^(-gPJwPt@VR1f;AmKgxN&YPL;j=0^xKM{!wuU|^mh3NE zy35quf}MeL!PU;|{OW_x$TBothLylT-J>_x6p}B_jW1L>k)ps6n%7Rh z96mPkJIM0QFNYUM2H}YF5bs%@Chs6#pEnloQhEl?J-)es!(SoJpEPoMTdgA14-#mC zghayD-DJWtUu`TD8?4mR)w5E`^EHbsz2EjH5aQLYRcF{l7_Q5?CEEvzDo(zjh|BKg z3aJl_n#j&eFHsUw4~lxqnr!6NL*se)6H=A+T1e3xUJGQrd}oSPwSy5+$tt{2t5J5@(lFxl43amsARG74iyNC}uuS zd2$=(r6RdamdGx^eatX@F2D8?U23tDpR+Os?0Gq2&^dF+$9wiWf?=mDWfjo4LfRwL zI#SRV9iSz>XCSgEj!cW&9H-njJopYiYuq|2w<5R2!nZ27DyvU4UDrHpoNQZiGPkp@ z1$h4H46Zn~eqdj$pWrv;*t!rTYTfZ1_bdkZmVVIRC21YeU$iS-*XMNK`#p8Z_DJx| zk3Jssf^XP7v0X?MWFO{rACltn$^~q(M9rMYoVxG$15N;nP)A98k^m3CJx8>6}NrUd@wp-E#$Q0uUDQT5GoiK_R{ z<{`g;8s>UFLpbga#DAf%qbfi`WN1J@6IA~R!YBT}qp%V-j!ybkR{uY0X|x)gmzE0J z&)=eHPjBxJvrZSOmt|)hC+kIMI;qgOnuL3mbNR0g^<%|>9x7>{}>a2qYSZAGPt4it?8 zNcLc!Gy0>$jaU?}ZWxK78hbhzE+etM`67*-*x4DN>1_&{@5t7_c*n(qz>&K{Y?10s zXsw2&nQev#SUSd|D8w7ZD2>E<%g^; zV{yE_O}gq?Q|zL|jdqB^zcx7vo(^})QW?QKacx$yR zhG|XH|8$vDZNIfuxr-sYFR{^csEI*IM#_gd;9*C+SysUFejP0{{z7@P?1+&_o6=7V|EJLQun^XEMS)w(=@eMi5&bbH*a0f;iC~2J74V2DZIlLUHD&>mlug5+v z6xBN~8-ovZylyH&gG#ptYsNlT?-tzOh%V#Y33zlsJ{AIju`CjIgf$@gr8}JugRq^c zAVQ3;&uGaVlVw}SUSWnTkH_6DISN&k2QLMBe9YU=sA+WiX@z)FoSYX`^k@B!j;ZeC zf&**P?HQG6Rk98hZ*ozn6iS-dG}V>jQhb3?4NJB*2F?6N7Nd;EOOo;xR7acylLaLy z9)^lykX39d@8@I~iEVar4jmjjLWhR0d=EB@%I;FZM$rykBNN~jf>#WbH4U{MqhhF6 zU??@fSO~4EbU4MaeQ_UXQcFyO*Rae|VAPLYMJEU`Q_Q_%s2*>$#S^)&7er+&`9L=1 z4q4ao07Z2Vsa%(nP!kJ590YmvrWg+YrgXYs_lv&B5EcoD`%uL79WyYA$0>>qi6ov7 z%`ia~J^_l{p39EY zv>>b}Qs8vxsu&WcXEt8B#FD%L%ZpcVtY!rqVTHe;$p9rbb5O{^rFMB>auLn-^;s+-&P1#h~mf~YLg$8M9 zZ4#87;e-Y6x6QO<{McUzhy(%*6| z)`D~A(TJ$>+0H+mct(jfgL4x%^oC^T#u(bL)`E2tBI#V1kSikAWmOOYrO~#-cc_8! zCe|@1&mN2{*ceeiBldHCdrURk4>V}79_*TVP3aCyV*5n@jiNbOm+~EQ_}1#->_tI@ zqXv+jj2#8xJtW508rzFrYcJxoek@iW6SR@1%a%Bux&;>25%`j3UI`0DaUr7l79`B1 zqqUARhW1^h6=)6?;@v>xrZNM;t}{yY3P@|L}ey@gG( z9r{}WoYN(9TW&dE2dEJIXkyHA4&pU6ki=rx&l2{DLGbVmg4%3Dlfvn!GB>EVaY_%3+Df{fBiqJV>~Xf8A0aqUjgpa} zoF8YXO&^_x*Ej}nw-$-F@(ddB>%RWoPUj?p8U{t0=n>gAI83y<9Ce@Q#3&(soJ{64 z37@Vij1}5fmzAuIUnXX`EYe;!H-yTVTmhAy;y8VZeB#vD{vw9~P#DiFiKQ|kWwGFZ z=jK;JX*A;Jr{#x?n8XUOLS;C%f|zj-7vXtlf_DtP7bpurBeX%Hjwr z4lI-2TdFpzkjgiv!8Vfv`=SP+s=^i3+N~1ELNWUbH|ytVu>EyPN_3(4TM^QE1swRo zoV7Y_g)a>28+hZG0e7g%@2^s>pzR4^fzR-El}ARTmtu!zjZLuX%>#OoU3}|rFjJg} zQ2TmaygxJ#sbHVyiA5KE+yH0LREWr%^C*yR|@gM$nK2P zo}M}PV0v))uJh&33N>#aU376@ZH79u(Yw`EQ2hM3SJs9f99+cO6_pNW$j$L-CtAfe zYfM)ccwD!P%LiBk!eCD?fHCGvgMQ%Q2oT_gmf?OY=A>&PaZQOq4eT=lwbaf}33LCH zFD|)lu{K7$8n9gX#w4~URjZxWm@wlH%oL#G|I~Fb-v^0L0TWu+`B+ZG!yII)w05DU z>GO?n(TN+B=>HdxVDSlIH76pta$_LhbBg;eZ`M7OGcqt||qi zogS72W1IN%=)5JCyOHWoFP7pOFK0L*OAh=i%&VW&4^LF@R;+K)t^S!96?}^+5QBIs zjJNTCh)?)4k^H^g1&jc>gysM`y^8Rm3qsvkr$9AeWwYpa$b22=yAd1t<*{ zaowSEFP+{y?Ob}8&cwfqoy4Pb9IA~VnM3u!trIK$&&0Op#Ql4j>(EW?UNUv#*iH1$ z^j>+W{afcd`{e&`-A{g}{JnIzYib)!T56IT@YEs{4|`sMpW3c8@UCoIJv`XsAw!XC z34|Il$LpW}CIHFC5e*)}00I5{%OL*WZRGzC0?_}-9{#ue?-ug^ zLE|uv-~6xnSs_2_&CN9{9vyc!Xgtn36_g^wI0C4s0s^;8+p?|mm;Odt3`2ZjwtK;l zfd6j)*Fr#53>C6Y8(N5?$H0ma;BCF3HCjUs7rpb2Kf*x3Xcj#O8mvs#&33i+McX zQpBxD8!O{5Y8D&0*QjD=Yhl9%M0)&_vk}bmN_Ud^BPN;H=U^bn&(csl-pkA+GyY0Z zKV7sU_4n;}uR78ouo8O%g*V;79KY?3d>k6%gpcmQsKk&@Vkw9yna_3asGt`0Hmj59 z%0yiF*`jXhByBI9QsD=+>big5{)BGe&+U2gAARGe3ID)xrid~QN_{I>k}@tzL!Md_ z&=7>TWciblF@EMC3t4-WX{?!m!G6$M$1S?NzF*2KHMP3Go4=#ZHkeIv{eEd;s-yD# z_jU^Ba06TZqvV|Yd;Z_sN%$X=!T+&?#p+OQIHS%!LO`Hx0q_Y0MyGYFNoM{W;&@0@ zLM^!X4KhdtsET5G<0+|q0oqVXMW~-7LW9Bg}=E$YtNh1#1D^6Mz(V9?2g~I1( zoz9Cz=8Hw98zVLwC2AQvp@pBeKyidn6Xu0-1SY1((^Hu*-!HxFUPs)yJ+i`^BC>PC zjwd0mygOVK#d2pRC9LxqGc6;Ui>f{YW9Bvb>33bp^NcnZoH~w9(lM5@JiIlfa-6|k ziy31UoMN%fvQfhi8^T+=yrP{QEyb-jK~>$A4SZT-N56NYEbpvO&yUme&pWKs3^94D zH{oXnUTb3T@H+RgzML*lejx`WAyw*?K7B-I(VJx($2!NXYm%3`=F~TbLv3H<{>D?A zJo-FDYdSA-(Y%;4KUP2SpHKAIcv9-ld(UEJE7=TKp|Gryn;72?0LHqAN^fk6%8PCW z{g_-t)G5uCIf0I`*F0ZNl)Z>))MaLMpXgqWgj-y;R+@A+AzDjsTqw2Mo9ULKA3c70 z!7SOkMtZb+MStH>9MnvNV0G;pwSW9HgP+`tg}e{ij0H6Zt5zJ7iw`hEnvye!XbA@!~#%vIkzowCOvq5I5@$3wtc*w2R$7!$*?}vg4;eDyJ_1=ixJuEp3pUS27W?qq(P^8$_lU!mRChT}ctvZz4p!X^ zOSp|JOAi~f?UkwH#9k{0smZ7-#=lK6X3OFEMl7%)WIcHb=#ZN$L=aD`#DZKOG4p4r zwlQ~XDZ`R-RbF&hZZhu3(67kggsM-F4Y_tI^PH8PMJRcs7NS9ogF+?bZB*fcpJ z=LTM4W=N9yepVvTj&Hu~0?*vR1HgtEvf8w%Q;U0^`2@e8{SwgX5d(cQ|1(!|i$km! zvY03MK}j`sff;*-%mN~ST>xU$6Bu?*Hm%l@0dk;j@%>}jsgDcQ)Hn*UfuThz9(ww_ zasV`rSrp_^bp-0sx>i35FzJwA!d6cZ5#5#nr@GcPEjNnFHIrtUYm1^Z$;{d&{hQV9 z6EfFHaIS}46p^5I-D_EcwwzUUuO}mqRh&T7r9sfw`)G^Q%oHxEs~+XoM?8e*{-&!7 z7$m$lg9t9KP9282eke608^Q2E%H-xm|oJ8=*SyEo} z@&;TQ3K)jgspgKHyGiKVMCz>xmC=H5Fy3!=TP)-R3|&1S-B)!6q50wfLHKM@7Bq6E z44CY%G;GY>tC`~yh!qv~YdXw! zSkquvYNs6k1r7>Eza?Vkkxo6XRS$W7EzL&A`o>=$HXgBp{L(i^$}t`NcnAxzbH8Ht z2!;`bhKIh`f1hIFcI5bHI=ueKdzmB9)!z$s-BT4ItyY|NaA_+o=jO%MU5as9 zc2)aLP>N%u>wlaXTK!p)r?+~)L+0eCGb5{8WIk7K52$nufnQ+m8YF+GQc&{^(zh-$ z#wyWV*Zh@d!b(WwXqvfhQX)^aoHTBkc;4ossV3&Ut*k>AI|m+{#kh4B!`3*<)EJVj zwrxK>99v^k4&Y&`Awm>|exo}NvewV%E+@vOc>5>%H#BK9uaE2$vje zWYM5fKuOTtn96B_2~~!xJPIcXF>E_;yO8AwpJ4)V`Hht#wbO3Ung~@c%%=FX4)q+9 z99#>VC2!4l`~0WHs9FI$Nz+abUq# zz`Of97})Su=^rGp2S$)7N3rQCj#0%2YO<R&p>$<#lgXcUj=4H_{oAYiT3 z44*xDn-$wEzRw7#@6aD)EGO$0{!C5Z^7#yl1o;k0PhN=aVUQu~eTQ^Xy{z8Ow6tk83 z4{5xe%(hx)%nD&|e*6sTWH`4W&U!Jae#U4TnICheJmsw{l|CH?UA{a6?2GNgpZLyzU2UlFu1ZVwlALmh_DOs03J^Cjh1im`E3?9&zvNmg(MuMw&0^Lu$(#CJ*q6DjlKsY-RMJ^8yIY|{SQZ*9~CH|u9L z`R78^r=EbbR*_>5?-)I+$6i}G)%mN(`!X72KaV(MNUP7Nv3MS9S|Pe!%N2AeOt5zG zVJ;jI4HZ$W->Ai_4X+`9c(~m=@ek*m`ZQbv3ryI-AD#AH=`x$~WeW~M{Js57(K7(v ze5`};LG|%C_tmd>bkufMWmAo&B+DT9ZV~h(4jg0>^aeAqL`PEUzJJtI8W1M!bQWpv zvN(d}E1@nlYa!L!!A*RN!(Q3F%J?5PvQ0udu?q-T)j3JKV~NL>KRb~w-lWc685uS6 z=S#aR&B8Sc8>cGJ!!--?kwsJTUUm`Jk?7`H z7PrO~xgBrSW2_tTlCq1LH8*!o?pj?qxy8}(=r_;G18POrFh#;buWR0qU24+XUaVZ0 z?(sXcr@-YqvkCmHr{U2oPogHL{r#3r49TeR<{SJX1pcUqyWPrkYz^X8#QW~?F)R5i z>p^!i<;qM8Nf{-fd6!_&V*e_9qP6q(s<--&1Ttj01j0w>bXY7y1W*%Auu&p|XSOH=)V7Bd4fUKh&T1)@cvqhuD-d=?w}O zjI%i(f|thk0Go*!d7D%0^ztBfE*V=(ZIN84f5HU}T9?ulmEYzT5usi=DeuI*d|;M~ zp_=Cx^!4k#=m_qSPBr5EK~E?3J{dWWPH&oCcNepYVqL?nh4D5ynfWip$m*YlZ8r^Z zuFEUL-nW!3qjRCLIWPT0x)FDL7>Yt7@8dA?R2kF@WE>ysMY+)lTsgNM#3VbXVGL}F z1O(>q>2a+_`6r5Xv$NZAnp=Kgnr3)cL(^=8ypEeOf3q8(HGe@7Tt59;yFl||w|mnO zHDxg2G3z8=(6wjj9kbcEY@Z0iOd7Gq5GiPS5% z*sF1J<#daxDV2Z8H>wxOF<;yKzMeTaSOp_|XkS9Sfn6Mpe9UBi1cSTieGG5$O;ZLIIJ60Y>SN4vC?=yE_CWlo(EEE$e4j?z&^FM%kNmRtlbEL^dPPgvs9sbK5fGw*r@ z+!EU@u$T8!nZh?Fdf_qk$VuHk^yVw`h`_#KoS*N%epIIOfQUy_&V}VWDGp3tplMbf z5Se1sJUC$7N0F1-9jdV2mmGK{-}fu|Nv;12jDy0<-kf^AmkDnu6j~TPWOgy1MT68|D z=4=50jVbUKdKaQgD`eWGr3I&^<6uhkjz$YwItY8%Yp9{z4-{6g{73<_b*@XJ4Nm3-3z z?BW3{aY_ccRjb@W1)i5nLg|7BnWS!B`_Uo9CWaE`Ij327QH?i)9A}4Ug4wmxVVa^b z-4+m%-wwOl7cKH7+=x&nrCrbEC)Q$fpg&V83#uEH;C=GNMz`ps@^RxK%T*8%OPnC` z{WO~J%nxYJ`x|N%?&i7?;{_8t^jM&=50HlaOQj8fS}_`moH$c;vI<|cruPFnpT8yU zS%rPOCUSd5Zdb(zwk`hqwTQn)*&n)uYsP*F_(~xEWq}C= zv30kFmZFwJZ@ELVX3?$dXQh|icO7UrL*_5G=I^xXjImz`ZPp>?g#tf(ej~KaIU0algsG!IS09;>?MvqGg#c{i+}qY|{P8W~O%#>|gFd z<1dr$-oxyRGN17yZo1OwLnzwYs0|;IS_nymNB0IlSzPQ%-r`?T=;_XQ^~&#}b|AB} zkNbN5uB?-sUB-T5QLlg%Uk3)uHB;>VIzGe9_J9 zaeISkQm!v(9d(0ML^b9fR^sfHFlH?7Mvddt37OuR{|O0{uv)(&-6<87W4 zyO>s!=cPgP3O&7xxU5DlIPw_o3O>6o6Qb?JWs3qw#p3sBc3g$?Dx zi(6D+DYgV;GrUis-CL%Qe{nvZnwaVXmbhH(|GFh|Q)k=1uvA$I@1DXI7bKlQ@8D6P zS?(*?><>)G49q0wr;NajpxP4W2G)kHl6^=Z>hrNEI4Mwd_$O6$1dXF;Q#hE(-eeW6 zz03GJF%Wl?HO=_ztv5*zRlcU~{+{k%#N59mgm~eK>P!QZ6E?#Cu^2)+K8m@ySvZ*5 z|HDT}BkF@3!l(0%75G=1u2hETXEj!^1Z$!)!lyGXlWD!_vqGE$Z)#cUVBqlORW>0^ zDjyVTxwKHKG|0}j-`;!R-p>}qQfBl(?($7pP<+Y8QE#M8SCDq~k<+>Q^Zf@cT_WdX3~BSe z+|KK|7OL5Hm5(NFP~j>Ct3*$wi0n0!xl=(C61`q&cec@mFlH(sy%+RH<=s)8aAPN`SfJdkAQjdv82G5iRdv8 zh{9wHUZaniSEpslXl^_ODh}mypC?b*9FzLjb~H@3DFSe;D(A-K3t3eOTB(m~I6C;(-lKAvit(70k`%@+O*Ztdz;}|_TS~B?Tpmi=QKC^m_ z2YpEaT3iiz*;T~ap1yiA)a`dKMwu`^UhIUeltNQ1Yjo=q@bI@&3zH?rVUg=IxLy-ni zyxDu%-Fr{H6owTjZU2O5>nDb=q&Jz_TjeSq%!2m40x&U6w~GQ({quPL73IsJS;f`$ zsuhioqCBj(gJ>2hoo)Gou7(WP*pX)f=Y=!=k!&1K?EYY%jJ~X&DnK{^saPQK<1BJ z_A`_{%ZozcB(3w$z^To^6d|XuT@=X~wtW!+{4ID@N{AB~J6AL5vuY>JwvWCNFKsKh zd}@>q@_WV#QZ&UJ0#?X(pXR!oyXOEG3rqzHbCzGLONDb042i$})fM@XF)uSP(DHUc z^&{|$*xe{cs?Gp8=B%RY3L7#$ve$?TWh>MZdxF1zH1v}1z+$Ov#G7?%D)bBCyDe*% zSeKSpETC2V1){II>@UwJi>4uBN+iAx+82E~gb|Cr&8E^i&)A!uv-g?jzH99wU}8+# z$nh>yvb;TwZmS@7LrvuCu_d0-WxFNI&C7%sWuTL%YU!l|I1{|->=dlOeHOCtUO#zkS3ESO8LHV4hTdQL5EdV zuWD33fFPH}HPrW^s$Qn1Xgp&AT6<-He{{4%eIu3rN=iK|9mURdKXfB&Q?qGok%!cs ze53UP{Z!TO-Y@q2;;k2avA3`lm4OoN4@S*k=UA)7H;qZ`d8`XaYFCv?Ba+uGW@r5v z&&{nf(24WSBOhc7!qF^@0cz;XcUynNaj6w2349;s!K{KVqs5yS{ z7VubS`2OzT^5#1~6Tt^RTvt9-J|D2F>y~>2;jeF>g`hx5l%B3H=aLExQihuYngzlnBTYOTHJQMzl>kwqN5JYs)Ej zblA@ntkUS~xi+}y6|(81helS}Q~&VB37qyV|S3Y=><^1wh%msQM?fz z<58MX(=|PSUKCF#)dbhR%D&xgCD?$aR0qen+wpp6 zst}vX18!Be96TD??j1HsHTUx(a&@F?=gT`Q$oJFFyrh^;zgz!(NlAHGn0cJy@us=w zNhC#l5G;H}+>49Nsh12=ZPO2r*2OBQe5kpb&1?*PIBFitK8}FUfb~S-#hKfF0o#&d z#3aPkB$9scYku&kA6{0xHnBV#&Wei5J>5T-XX-gUXEPo+9b7WL=*XESc(3BshL`aj zXp}QIp*40}oWJt*l043e8_5;H5PI5c)U&IEw5dF(4zjX0y_lk9 zAp@!mK>WUqHo)-jop=DoK>&no>kAD=^qIE7qis&_*4~ z6q^EF$D@R~3_xseCG>Ikb6Gfofb$g|75PPyyZN&tiRxqovo_k zO|HA|sgy#B<32gyU9x^&)H$1jvw@qp+1b(eGAb)O%O!&pyX@^nQd^9BQ4{(F8<}|A zhF&)xusQhtoXOOhic=8#Xtt5&slLia3c*a?dIeczyTbC#>FTfiLST57nc3@Y#v_Eg#VUv zT8cKH#f3=1PNj!Oroz_MAR*pow%Y0*6YCYmUy^7`^r|j23Q~^*TW#cU7CHf0eAD_0 zEWEVddxFgQ7=!nEBQ|ibaScslvhuUk^*%b#QUNrEB{3PG@uTxNwW}Bs4$nS9wc(~O zG7Iq>aMsYkcr!9#A;HNsJrwTDYkK8ikdj{M;N$sN6BqJ<8~z>T20{J8Z2rRUuH7~3 z=tgS`AgxbBOMg87UT4Lwge`*Y=01Dvk>)^{Iu+n6fuVX4%}>?3czOGR$0 zpp*wp>bsFFSV`V;r_m+TZns$ZprIi`OUMhe^cLE$2O+pP3nP!YB$ry}2THx2QJs3< za1;>d-AggCarrQ>&Z!d@;mW+!q6eXhb&`GbzUDSxpl8AJ#Cm#tuc)_xh(2NV=5XMs zrf_ozRYO$NkC=pKFX5OH8v1>0i9Z$ec`~Mf+_jQ68spn(CJwclDhEEkH2Qw;${J$clv__nUjn5jA0wCLEnu1j;v!0vB>Ri6m9`;R{JMS%^)4FC zU0Z44+u$I$w=Bj|iu4DT5h~sS`C*zbmX?@-crY}E+hy>}2~C0Nn(EKk@5^qO4@l@! z6O0lr%tzGC`D^)8xU3FnMZVm0kX1sBWhaQyzVoXFWwr%Ny?=2M{5s#5i7fTu3gEkG zc{(Pr$v=;`Y#&`y*J}#M9ux>0?xu!`$9cUKm#Bdd_&S#LPTS?ZPV6zN6>W6JTS~-LfjL{mB=b(KMk3 z2HjBSlJeyUVqDd=Mt!=hpYsvby2GL&3~zm;0{^nZJq+4vb?5HH4wufvr}IX42sHeK zm@x?HN$8TsTavXs)tLDFJtY9b)y~Tl@7z4^I8oUQq4JckH@~CVQ;FoK(+e0XAM>1O z(ei}h?)JQp>)d=6ng-BZF1Z5hsAKW@mXq+hU?r8I(*%`tnIIOXw7V6ZK(T9RFJJe@ zZS!aC+p)Gf2Ujc=a6hx4!A1Th%YH!Lb^xpI!Eu` zmJO{9rw){B1Ql18d%F%da+Tbu1()?o(zT7StYqK6_w`e+fjXq5L^y(0 z09QA6H4oFj59c2wR~{~>jUoDzDdKz}5#onYPJRwa`SUO)Pd4)?(ENBaFVLJr6Kvz= zhTtXqbx09C1z~~iZt;g^9_2nCZ{};-b4dQJbv8HsWHXPVg^@(*!@xycp#R?a|L!+` zY5w))JWV`Gls(=}shH0#r*;~>_+-P5Qc978+QUd>J%`fyn{*TsiG-dWMiJXNgwBaT zJ=wgYFt+1ACW)XwtNx)Q9tA2LPoB&DkL16P)ERWQlY4%Y`-5aM9mZ{eKPUgI!~J3Z zkMd5A_p&v?V-o-6TUa8BndiX?ooviev(DKw=*bBVOW|=zps9=Yl|-R5@yJe*BPzN}a0mUsLn{4LfjB_oxpv(mwq# zSY*%E{iB)sNvWfzg-B!R!|+x(Q|b@>{-~cFvdDHA{F2sFGA5QGiIWy#3?P2JIpPKg6ncI^)dvqe`_|N=8 '} + case $link in #( + /*) app_path=$link ;; #( + *) app_path=$APP_HOME$link ;; + esac +done + +# This is normally unused +# shellcheck disable=SC2034 +APP_BASE_NAME=${0##*/} +# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036) +APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s\n' "$PWD" ) || exit + +# Use the maximum available, or set MAX_FD != -1 to use that value. +MAX_FD=maximum + +warn () { + echo "$*" +} >&2 + +die () { + echo + echo "$*" + echo + exit 1 +} >&2 + +# OS specific support (must be 'true' or 'false'). +cygwin=false +msys=false +darwin=false +nonstop=false +case "$( uname )" in #( + CYGWIN* ) cygwin=true ;; #( + Darwin* ) darwin=true ;; #( + MSYS* | MINGW* ) msys=true ;; #( + NONSTOP* ) nonstop=true ;; +esac + +CLASSPATH="\\\"\\\"" + + +# Determine the Java command to use to start the JVM. +if [ -n "$JAVA_HOME" ] ; then + if [ -x "$JAVA_HOME/jre/sh/java" ] ; then + # IBM's JDK on AIX uses strange locations for the executables + JAVACMD=$JAVA_HOME/jre/sh/java + else + JAVACMD=$JAVA_HOME/bin/java + fi + if [ ! -x "$JAVACMD" ] ; then + die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME + +Please set the JAVA_HOME variable in your environment to match the +location of your Java installation." + fi +else + JAVACMD=java + if ! command -v java >/dev/null 2>&1 + then + die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. + +Please set the JAVA_HOME variable in your environment to match the +location of your Java installation." + fi +fi + +# Increase the maximum file descriptors if we can. +if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then + case $MAX_FD in #( + max*) + # In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked. + # shellcheck disable=SC2039,SC3045 + MAX_FD=$( ulimit -H -n ) || + warn "Could not query maximum file descriptor limit" + esac + case $MAX_FD in #( + '' | soft) :;; #( + *) + # In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked. + # shellcheck disable=SC2039,SC3045 + ulimit -n "$MAX_FD" || + warn "Could not set maximum file descriptor limit to $MAX_FD" + esac +fi + +# Collect all arguments for the java command, stacking in reverse order: +# * args from the command line +# * the main class name +# * -classpath +# * -D...appname settings +# * --module-path (only if needed) +# * DEFAULT_JVM_OPTS, JAVA_OPTS, and GRADLE_OPTS environment variables. + +# For Cygwin or MSYS, switch paths to Windows format before running java +if "$cygwin" || "$msys" ; then + APP_HOME=$( cygpath --path --mixed "$APP_HOME" ) + CLASSPATH=$( cygpath --path --mixed "$CLASSPATH" ) + + JAVACMD=$( cygpath --unix "$JAVACMD" ) + + # Now convert the arguments - kludge to limit ourselves to /bin/sh + for arg do + if + case $arg in #( + -*) false ;; # don't mess with options #( + /?*) t=${arg#/} t=/${t%%/*} # looks like a POSIX filepath + [ -e "$t" ] ;; #( + *) false ;; + esac + then + arg=$( cygpath --path --ignore --mixed "$arg" ) + fi + # Roll the args list around exactly as many times as the number of + # args, so each arg winds up back in the position where it started, but + # possibly modified. + # + # NB: a `for` loop captures its iteration list before it begins, so + # changing the positional parameters here affects neither the number of + # iterations, nor the values presented in `arg`. + shift # remove old arg + set -- "$@" "$arg" # push replacement arg + done +fi + + +# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"' + +# Collect all arguments for the java command: +# * DEFAULT_JVM_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments, +# and any embedded shellness will be escaped. +# * For example: A user cannot expect ${Hostname} to be expanded, as it is an environment variable and will be +# treated as '${Hostname}' itself on the command line. + +set -- \ + "-Dorg.gradle.appname=$APP_BASE_NAME" \ + -classpath "$CLASSPATH" \ + -jar "$APP_HOME/gradle/wrapper/gradle-wrapper.jar" \ + "$@" + +# Stop when "xargs" is not available. +if ! command -v xargs >/dev/null 2>&1 +then + die "xargs is not available" +fi + +# Use "xargs" to parse quoted args. +# +# With -n1 it outputs one arg per line, with the quotes and backslashes removed. +# +# In Bash we could simply go: +# +# readarray ARGS < <( xargs -n1 <<<"$var" ) && +# set -- "${ARGS[@]}" "$@" +# +# but POSIX shell has neither arrays nor command substitution, so instead we +# post-process each arg (as a line of input to sed) to backslash-escape any +# character that might be a shell metacharacter, then use eval to reverse +# that process (while maintaining the separation between arguments), and wrap +# the whole thing up as a single "set" statement. +# +# This will of course break if any of these variables contains a newline or +# an unmatched quote. +# + +eval "set -- $( + printf '%s\n' "$DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS" | + xargs -n1 | + sed ' s~[^-[:alnum:]+,./:=@_]~\\&~g; ' | + tr '\n' ' ' + )" '"$@"' + +exec "$JAVACMD" "$@" diff --git a/gradlew.bat b/gradlew.bat new file mode 100644 index 0000000..db3a6ac --- /dev/null +++ b/gradlew.bat @@ -0,0 +1,94 @@ +@rem +@rem Copyright 2015 the original author or authors. +@rem +@rem Licensed under the Apache License, Version 2.0 (the "License"); +@rem you may not use this file except in compliance with the License. +@rem You may obtain a copy of the License at +@rem +@rem https://www.apache.org/licenses/LICENSE-2.0 +@rem +@rem Unless required by applicable law or agreed to in writing, software +@rem distributed under the License is distributed on an "AS IS" BASIS, +@rem WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +@rem See the License for the specific language governing permissions and +@rem limitations under the License. +@rem +@rem SPDX-License-Identifier: Apache-2.0 +@rem + +@if "%DEBUG%"=="" @echo off +@rem ########################################################################## +@rem +@rem Gradle startup script for Windows +@rem +@rem ########################################################################## + +@rem Set local scope for the variables with windows NT shell +if "%OS%"=="Windows_NT" setlocal + +set DIRNAME=%~dp0 +if "%DIRNAME%"=="" set DIRNAME=. +@rem This is normally unused +set APP_BASE_NAME=%~n0 +set APP_HOME=%DIRNAME% + +@rem Resolve any "." and ".." in APP_HOME to make it shorter. +for %%i in ("%APP_HOME%") do set APP_HOME=%%~fi + +@rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +set DEFAULT_JVM_OPTS="-Xmx64m" "-Xms64m" + +@rem Find java.exe +if defined JAVA_HOME goto findJavaFromJavaHome + +set JAVA_EXE=java.exe +%JAVA_EXE% -version >NUL 2>&1 +if %ERRORLEVEL% equ 0 goto execute + +echo. 1>&2 +echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 + +goto fail + +:findJavaFromJavaHome +set JAVA_HOME=%JAVA_HOME:"=% +set JAVA_EXE=%JAVA_HOME%/bin/java.exe + +if exist "%JAVA_EXE%" goto execute + +echo. 1>&2 +echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 + +goto fail + +:execute +@rem Setup the command line + +set CLASSPATH= + + +@rem Execute Gradle +"%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -classpath "%CLASSPATH%" -jar "%APP_HOME%\gradle\wrapper\gradle-wrapper.jar" %* + +:end +@rem End local scope for the variables with windows NT shell +if %ERRORLEVEL% equ 0 goto mainEnd + +:fail +rem Set variable GRADLE_EXIT_CONSOLE if you need the _script_ return code instead of +rem the _cmd.exe /c_ return code! +set EXIT_CODE=%ERRORLEVEL% +if %EXIT_CODE% equ 0 set EXIT_CODE=1 +if not ""=="%GRADLE_EXIT_CONSOLE%" exit %EXIT_CODE% +exit /b %EXIT_CODE% + +:mainEnd +if "%OS%"=="Windows_NT" endlocal + +:omega diff --git a/mvnw b/mvnw new file mode 100644 index 0000000..8a8fb22 --- /dev/null +++ b/mvnw @@ -0,0 +1,316 @@ +#!/bin/sh +# ---------------------------------------------------------------------------- +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +# ---------------------------------------------------------------------------- + +# ---------------------------------------------------------------------------- +# Maven Start Up Batch script +# +# Required ENV vars: +# ------------------ +# JAVA_HOME - location of a JDK home dir +# +# Optional ENV vars +# ----------------- +# M2_HOME - location of maven2's installed home dir +# MAVEN_OPTS - parameters passed to the Java VM when running Maven +# e.g. to debug Maven itself, use +# set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 +# MAVEN_SKIP_RC - flag to disable loading of mavenrc files +# ---------------------------------------------------------------------------- + +if [ -z "$MAVEN_SKIP_RC" ] ; then + + if [ -f /usr/local/etc/mavenrc ] ; then + . /usr/local/etc/mavenrc + fi + + if [ -f /etc/mavenrc ] ; then + . /etc/mavenrc + fi + + if [ -f "$HOME/.mavenrc" ] ; then + . "$HOME/.mavenrc" + fi + +fi + +# OS specific support. $var _must_ be set to either true or false. +cygwin=false; +darwin=false; +mingw=false +case "`uname`" in + CYGWIN*) cygwin=true ;; + MINGW*) mingw=true;; + Darwin*) darwin=true + # Use /usr/libexec/java_home if available, otherwise fall back to /Library/Java/Home + # See https://developer.apple.com/library/mac/qa/qa1170/_index.html + if [ -z "$JAVA_HOME" ]; then + if [ -x "/usr/libexec/java_home" ]; then + export JAVA_HOME="`/usr/libexec/java_home`" + else + export JAVA_HOME="/Library/Java/Home" + fi + fi + ;; +esac + +if [ -z "$JAVA_HOME" ] ; then + if [ -r /etc/gentoo-release ] ; then + JAVA_HOME=`java-config --jre-home` + fi +fi + +if [ -z "$M2_HOME" ] ; then + ## resolve links - $0 may be a link to maven's home + PRG="$0" + + # need this for relative symlinks + while [ -h "$PRG" ] ; do + ls=`ls -ld "$PRG"` + link=`expr "$ls" : '.*-> \(.*\)$'` + if expr "$link" : '/.*' > /dev/null; then + PRG="$link" + else + PRG="`dirname "$PRG"`/$link" + fi + done + + saveddir=`pwd` + + M2_HOME=`dirname "$PRG"`/.. + + # make it fully qualified + M2_HOME=`cd "$M2_HOME" && pwd` + + cd "$saveddir" + # echo Using m2 at $M2_HOME +fi + +# For Cygwin, ensure paths are in UNIX format before anything is touched +if $cygwin ; then + [ -n "$M2_HOME" ] && + M2_HOME=`cygpath --unix "$M2_HOME"` + [ -n "$JAVA_HOME" ] && + JAVA_HOME=`cygpath --unix "$JAVA_HOME"` + [ -n "$CLASSPATH" ] && + CLASSPATH=`cygpath --path --unix "$CLASSPATH"` +fi + +# For Mingw, ensure paths are in UNIX format before anything is touched +if $mingw ; then + [ -n "$M2_HOME" ] && + M2_HOME="`(cd "$M2_HOME"; pwd)`" + [ -n "$JAVA_HOME" ] && + JAVA_HOME="`(cd "$JAVA_HOME"; pwd)`" +fi + +if [ -z "$JAVA_HOME" ]; then + javaExecutable="`which javac`" + if [ -n "$javaExecutable" ] && ! [ "`expr \"$javaExecutable\" : '\([^ ]*\)'`" = "no" ]; then + # readlink(1) is not available as standard on Solaris 10. + readLink=`which readlink` + if [ ! `expr "$readLink" : '\([^ ]*\)'` = "no" ]; then + if $darwin ; then + javaHome="`dirname \"$javaExecutable\"`" + javaExecutable="`cd \"$javaHome\" && pwd -P`/javac" + else + javaExecutable="`readlink -f \"$javaExecutable\"`" + fi + javaHome="`dirname \"$javaExecutable\"`" + javaHome=`expr "$javaHome" : '\(.*\)/bin'` + JAVA_HOME="$javaHome" + export JAVA_HOME + fi + fi +fi + +if [ -z "$JAVACMD" ] ; then + if [ -n "$JAVA_HOME" ] ; then + if [ -x "$JAVA_HOME/jre/sh/java" ] ; then + # IBM's JDK on AIX uses strange locations for the executables + JAVACMD="$JAVA_HOME/jre/sh/java" + else + JAVACMD="$JAVA_HOME/bin/java" + fi + else + JAVACMD="`\\unset -f command; \\command -v java`" + fi +fi + +if [ ! -x "$JAVACMD" ] ; then + echo "Error: JAVA_HOME is not defined correctly." >&2 + echo " We cannot execute $JAVACMD" >&2 + exit 1 +fi + +if [ -z "$JAVA_HOME" ] ; then + echo "Warning: JAVA_HOME environment variable is not set." +fi + +CLASSWORLDS_LAUNCHER=org.codehaus.plexus.classworlds.launcher.Launcher + +# traverses directory structure from process work directory to filesystem root +# first directory with .mvn subdirectory is considered project base directory +find_maven_basedir() { + + if [ -z "$1" ] + then + echo "Path not specified to find_maven_basedir" + return 1 + fi + + basedir="$1" + wdir="$1" + while [ "$wdir" != '/' ] ; do + if [ -d "$wdir"/.mvn ] ; then + basedir=$wdir + break + fi + # workaround for JBEAP-8937 (on Solaris 10/Sparc) + if [ -d "${wdir}" ]; then + wdir=`cd "$wdir/.."; pwd` + fi + # end of workaround + done + echo "${basedir}" +} + +# concatenates all lines of a file +concat_lines() { + if [ -f "$1" ]; then + echo "$(tr -s '\n' ' ' < "$1")" + fi +} + +BASE_DIR=`find_maven_basedir "$(pwd)"` +if [ -z "$BASE_DIR" ]; then + exit 1; +fi + +########################################################################################## +# Extension to allow automatically downloading the maven-wrapper.jar from Maven-central +# This allows using the maven wrapper in projects that prohibit checking in binary data. +########################################################################################## +if [ -r "$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" ]; then + if [ "$MVNW_VERBOSE" = true ]; then + echo "Found .mvn/wrapper/maven-wrapper.jar" + fi +else + if [ "$MVNW_VERBOSE" = true ]; then + echo "Couldn't find .mvn/wrapper/maven-wrapper.jar, downloading it ..." + fi + if [ -n "$MVNW_REPOURL" ]; then + jarUrl="$MVNW_REPOURL/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" + else + jarUrl="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" + fi + while IFS="=" read key value; do + case "$key" in (wrapperUrl) jarUrl="$value"; break ;; + esac + done < "$BASE_DIR/.mvn/wrapper/maven-wrapper.properties" + if [ "$MVNW_VERBOSE" = true ]; then + echo "Downloading from: $jarUrl" + fi + wrapperJarPath="$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" + if $cygwin; then + wrapperJarPath=`cygpath --path --windows "$wrapperJarPath"` + fi + + if command -v wget > /dev/null; then + if [ "$MVNW_VERBOSE" = true ]; then + echo "Found wget ... using wget" + fi + if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then + wget "$jarUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath" + else + wget --http-user=$MVNW_USERNAME --http-password=$MVNW_PASSWORD "$jarUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath" + fi + elif command -v curl > /dev/null; then + if [ "$MVNW_VERBOSE" = true ]; then + echo "Found curl ... using curl" + fi + if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then + curl -o "$wrapperJarPath" "$jarUrl" -f + else + curl --user $MVNW_USERNAME:$MVNW_PASSWORD -o "$wrapperJarPath" "$jarUrl" -f + fi + + else + if [ "$MVNW_VERBOSE" = true ]; then + echo "Falling back to using Java to download" + fi + javaClass="$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.java" + # For Cygwin, switch paths to Windows format before running javac + if $cygwin; then + javaClass=`cygpath --path --windows "$javaClass"` + fi + if [ -e "$javaClass" ]; then + if [ ! -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then + if [ "$MVNW_VERBOSE" = true ]; then + echo " - Compiling MavenWrapperDownloader.java ..." + fi + # Compiling the Java class + ("$JAVA_HOME/bin/javac" "$javaClass") + fi + if [ -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then + # Running the downloader + if [ "$MVNW_VERBOSE" = true ]; then + echo " - Running MavenWrapperDownloader.java ..." + fi + ("$JAVA_HOME/bin/java" -cp .mvn/wrapper MavenWrapperDownloader "$MAVEN_PROJECTBASEDIR") + fi + fi + fi +fi +########################################################################################## +# End of extension +########################################################################################## + +export MAVEN_PROJECTBASEDIR=${MAVEN_BASEDIR:-"$BASE_DIR"} +if [ "$MVNW_VERBOSE" = true ]; then + echo $MAVEN_PROJECTBASEDIR +fi +MAVEN_OPTS="$(concat_lines "$MAVEN_PROJECTBASEDIR/.mvn/jvm.config") $MAVEN_OPTS" + +# For Cygwin, switch paths to Windows format before running java +if $cygwin; then + [ -n "$M2_HOME" ] && + M2_HOME=`cygpath --path --windows "$M2_HOME"` + [ -n "$JAVA_HOME" ] && + JAVA_HOME=`cygpath --path --windows "$JAVA_HOME"` + [ -n "$CLASSPATH" ] && + CLASSPATH=`cygpath --path --windows "$CLASSPATH"` + [ -n "$MAVEN_PROJECTBASEDIR" ] && + MAVEN_PROJECTBASEDIR=`cygpath --path --windows "$MAVEN_PROJECTBASEDIR"` +fi + +# Provide a "standardized" way to retrieve the CLI args that will +# work with both Windows and non-Windows executions. +MAVEN_CMD_LINE_ARGS="$MAVEN_CONFIG $@" +export MAVEN_CMD_LINE_ARGS + +WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain + +exec "$JAVACMD" \ + $MAVEN_OPTS \ + $MAVEN_DEBUG_OPTS \ + -classpath "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" \ + "-Dmaven.home=${M2_HOME}" \ + "-Dmaven.multiModuleProjectDirectory=${MAVEN_PROJECTBASEDIR}" \ + ${WRAPPER_LAUNCHER} $MAVEN_CONFIG "$@" diff --git a/mvnw.cmd b/mvnw.cmd new file mode 100644 index 0000000..1d8ab01 --- /dev/null +++ b/mvnw.cmd @@ -0,0 +1,188 @@ +@REM ---------------------------------------------------------------------------- +@REM Licensed to the Apache Software Foundation (ASF) under one +@REM or more contributor license agreements. See the NOTICE file +@REM distributed with this work for additional information +@REM regarding copyright ownership. The ASF licenses this file +@REM to you under the Apache License, Version 2.0 (the +@REM "License"); you may not use this file except in compliance +@REM with the License. You may obtain a copy of the License at +@REM +@REM https://www.apache.org/licenses/LICENSE-2.0 +@REM +@REM Unless required by applicable law or agreed to in writing, +@REM software distributed under the License is distributed on an +@REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +@REM KIND, either express or implied. See the License for the +@REM specific language governing permissions and limitations +@REM under the License. +@REM ---------------------------------------------------------------------------- + +@REM ---------------------------------------------------------------------------- +@REM Maven Start Up Batch script +@REM +@REM Required ENV vars: +@REM JAVA_HOME - location of a JDK home dir +@REM +@REM Optional ENV vars +@REM M2_HOME - location of maven2's installed home dir +@REM MAVEN_BATCH_ECHO - set to 'on' to enable the echoing of the batch commands +@REM MAVEN_BATCH_PAUSE - set to 'on' to wait for a keystroke before ending +@REM MAVEN_OPTS - parameters passed to the Java VM when running Maven +@REM e.g. to debug Maven itself, use +@REM set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 +@REM MAVEN_SKIP_RC - flag to disable loading of mavenrc files +@REM ---------------------------------------------------------------------------- + +@REM Begin all REM lines with '@' in case MAVEN_BATCH_ECHO is 'on' +@echo off +@REM set title of command window +title %0 +@REM enable echoing by setting MAVEN_BATCH_ECHO to 'on' +@if "%MAVEN_BATCH_ECHO%" == "on" echo %MAVEN_BATCH_ECHO% + +@REM set %HOME% to equivalent of $HOME +if "%HOME%" == "" (set "HOME=%HOMEDRIVE%%HOMEPATH%") + +@REM Execute a user defined script before this one +if not "%MAVEN_SKIP_RC%" == "" goto skipRcPre +@REM check for pre script, once with legacy .bat ending and once with .cmd ending +if exist "%USERPROFILE%\mavenrc_pre.bat" call "%USERPROFILE%\mavenrc_pre.bat" %* +if exist "%USERPROFILE%\mavenrc_pre.cmd" call "%USERPROFILE%\mavenrc_pre.cmd" %* +:skipRcPre + +@setlocal + +set ERROR_CODE=0 + +@REM To isolate internal variables from possible post scripts, we use another setlocal +@setlocal + +@REM ==== START VALIDATION ==== +if not "%JAVA_HOME%" == "" goto OkJHome + +echo. +echo Error: JAVA_HOME not found in your environment. >&2 +echo Please set the JAVA_HOME variable in your environment to match the >&2 +echo location of your Java installation. >&2 +echo. +goto error + +:OkJHome +if exist "%JAVA_HOME%\bin\java.exe" goto init + +echo. +echo Error: JAVA_HOME is set to an invalid directory. >&2 +echo JAVA_HOME = "%JAVA_HOME%" >&2 +echo Please set the JAVA_HOME variable in your environment to match the >&2 +echo location of your Java installation. >&2 +echo. +goto error + +@REM ==== END VALIDATION ==== + +:init + +@REM Find the project base dir, i.e. the directory that contains the folder ".mvn". +@REM Fallback to current working directory if not found. + +set MAVEN_PROJECTBASEDIR=%MAVEN_BASEDIR% +IF NOT "%MAVEN_PROJECTBASEDIR%"=="" goto endDetectBaseDir + +set EXEC_DIR=%CD% +set WDIR=%EXEC_DIR% +:findBaseDir +IF EXIST "%WDIR%"\.mvn goto baseDirFound +cd .. +IF "%WDIR%"=="%CD%" goto baseDirNotFound +set WDIR=%CD% +goto findBaseDir + +:baseDirFound +set MAVEN_PROJECTBASEDIR=%WDIR% +cd "%EXEC_DIR%" +goto endDetectBaseDir + +:baseDirNotFound +set MAVEN_PROJECTBASEDIR=%EXEC_DIR% +cd "%EXEC_DIR%" + +:endDetectBaseDir + +IF NOT EXIST "%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config" goto endReadAdditionalConfig + +@setlocal EnableExtensions EnableDelayedExpansion +for /F "usebackq delims=" %%a in ("%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config") do set JVM_CONFIG_MAVEN_PROPS=!JVM_CONFIG_MAVEN_PROPS! %%a +@endlocal & set JVM_CONFIG_MAVEN_PROPS=%JVM_CONFIG_MAVEN_PROPS% + +:endReadAdditionalConfig + +SET MAVEN_JAVA_EXE="%JAVA_HOME%\bin\java.exe" +set WRAPPER_JAR="%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.jar" +set WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain + +set DOWNLOAD_URL="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" + +FOR /F "usebackq tokens=1,2 delims==" %%A IN ("%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.properties") DO ( + IF "%%A"=="wrapperUrl" SET DOWNLOAD_URL=%%B +) + +@REM Extension to allow automatically downloading the maven-wrapper.jar from Maven-central +@REM This allows using the maven wrapper in projects that prohibit checking in binary data. +if exist %WRAPPER_JAR% ( + if "%MVNW_VERBOSE%" == "true" ( + echo Found %WRAPPER_JAR% + ) +) else ( + if not "%MVNW_REPOURL%" == "" ( + SET DOWNLOAD_URL="%MVNW_REPOURL%/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" + ) + if "%MVNW_VERBOSE%" == "true" ( + echo Couldn't find %WRAPPER_JAR%, downloading it ... + echo Downloading from: %DOWNLOAD_URL% + ) + + powershell -Command "&{"^ + "$webclient = new-object System.Net.WebClient;"^ + "if (-not ([string]::IsNullOrEmpty('%MVNW_USERNAME%') -and [string]::IsNullOrEmpty('%MVNW_PASSWORD%'))) {"^ + "$webclient.Credentials = new-object System.Net.NetworkCredential('%MVNW_USERNAME%', '%MVNW_PASSWORD%');"^ + "}"^ + "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $webclient.DownloadFile('%DOWNLOAD_URL%', '%WRAPPER_JAR%')"^ + "}" + if "%MVNW_VERBOSE%" == "true" ( + echo Finished downloading %WRAPPER_JAR% + ) +) +@REM End of extension + +@REM Provide a "standardized" way to retrieve the CLI args that will +@REM work with both Windows and non-Windows executions. +set MAVEN_CMD_LINE_ARGS=%* + +%MAVEN_JAVA_EXE% ^ + %JVM_CONFIG_MAVEN_PROPS% ^ + %MAVEN_OPTS% ^ + %MAVEN_DEBUG_OPTS% ^ + -classpath %WRAPPER_JAR% ^ + "-Dmaven.multiModuleProjectDirectory=%MAVEN_PROJECTBASEDIR%" ^ + %WRAPPER_LAUNCHER% %MAVEN_CONFIG% %* +if ERRORLEVEL 1 goto error +goto end + +:error +set ERROR_CODE=1 + +:end +@endlocal & set ERROR_CODE=%ERROR_CODE% + +if not "%MAVEN_SKIP_RC%"=="" goto skipRcPost +@REM check for post script, once with legacy .bat ending and once with .cmd ending +if exist "%USERPROFILE%\mavenrc_post.bat" call "%USERPROFILE%\mavenrc_post.bat" +if exist "%USERPROFILE%\mavenrc_post.cmd" call "%USERPROFILE%\mavenrc_post.cmd" +:skipRcPost + +@REM pause the script if MAVEN_BATCH_PAUSE is set to 'on' +if "%MAVEN_BATCH_PAUSE%"=="on" pause + +if "%MAVEN_TERMINATE_CMD%"=="on" exit %ERROR_CODE% + +cmd /C exit /B %ERROR_CODE% diff --git a/pom.xml b/pom.xml new file mode 100644 index 0000000..e7c4fb3 --- /dev/null +++ b/pom.xml @@ -0,0 +1,106 @@ + + + 4.0.0 + + org.springframework.boot + spring-boot-starter-parent + 3.1.0 + + + com.bezkoder + autoflow + 0.0.1-SNAPSHOT + spring-security-refresh-token + Spring Security Refresh Token with JWT example in Spring Boot + + 17 + + + + org.springframework.boot + spring-boot-starter-data-jpa + + + + org.springframework.boot + spring-boot-starter-security + + + + org.springframework.boot + spring-boot-starter-web + + + + org.springframework.boot + spring-boot-starter-validation + + + + io.jsonwebtoken + jjwt-api + 0.11.5 + + + + io.jsonwebtoken + jjwt-impl + 0.11.5 + runtime + + + + io.jsonwebtoken + jjwt-jackson + 0.11.5 + runtime + + + + com.mysql + mysql-connector-j + runtime + + + + org.springframework.boot + spring-boot-starter-test + test + + + + org.springframework.security + spring-security-test + test + + + org.mariadb.jdbc + mariadb-java-client + runtime + + + + org.springdoc + springdoc-openapi-starter-webmvc-ui + 2.1.0 + + + + org.projectlombok + lombok + true + + + + + + + org.springframework.boot + spring-boot-maven-plugin + + + + + diff --git a/settings.gradle.kts b/settings.gradle.kts new file mode 100644 index 0000000..d2cb500 --- /dev/null +++ b/settings.gradle.kts @@ -0,0 +1,5 @@ +/* + * This file was generated by the Gradle 'init' task. + */ + +rootProject.name = "autoflow" diff --git a/spring-security-jwt-auth-spring-boot-flow.png b/spring-security-jwt-auth-spring-boot-flow.png new file mode 100644 index 0000000000000000000000000000000000000000..1349767775d78ee80f0676b45f930f9e11b6016e GIT binary patch literal 39757 zcmd3OWmHvN+b-SRDO~~r8w5nUQ&K^YW+Nyi-Q6j$X{00-Bn6QU=@djlQo6h2%Dl7y91Y9LWSuF$vq+ReQf`J5% zoQ>$`gMWxlS_;w#pN42Qzz39|V zu$2KbG?+jdW3)@L4}2uZi;0K9zmTP7;$Q+_gbT`R$-}>}jn0n-=P^uEC{cos(lvYu zkUu|Q{_j6P#p`%^e6`o)w(-3nPW+NR)v|M{`sMs%m(8VbQFOlNro3v2t4tUSB5`Rd zX-DR|t~-w%hZ9?_yLQyCi|*FMVR!Q>DYv_Hch!A3%6i%i`f+g*x98)%i9ta@==k>< zJx^X$3}LM2n%lSBWXxY%+SqWV7AhSP>W5Ja`e_yvA4=F=Ow*lSr`$Dqt;{#yHtn9B z2D6YQnX+o3VOef44d3wiu`X)qVRCZHZXsSEag5zfzgCE)sdwGcuXsYIoEH!fplj@N z0$ST9LYp2pq9xm_SI~Mm@8Yw<*;4P-f92JoANAy=r9&5JMKpTWgVHnicY7Fa5Iq;!qhrD%(#6_HL9iBc7&nnI?r;iRGBk(_da*?x(B_r175? z_kD{ZAB=?v3Z9NC(8Xkm@5Fcyt!__M7q`^-T#by3TpX=Uxh%G$21f>FQqz7ur&+<4 z{o%FOgsz$Nb>pM%ryOwzMEdu};^OiG}C?UU70~$v)d+#nBPUe@$P&}cKcF{(3~Uz!sB%DTl>q)ij4s9k#_-<1-6@etxj}r^Y>ip(xG>W#3y;D|_o!?{>;gno^g{IAmR_pMvSZb;6)$k~~Pk(^j@LFYW~w*Ag8X*D;Wa?}QY zCd>P_@SB5uSoCNB{_K3t43}>sWN$O(qbE9L{rv7?X&=vdti2;+a@^1A4kM(|x`lyedh))FLL} zyx)rGo>j&XH?C%$Q7qG`x*qK|M@dV2;szc1F~>FY*$F8+5P21WyB&9mW}lo)u^5~D zK~7-c?A?!YUzg<`!p+pREHAu|d;$W&Kiszlh4Al*p0}aX1=}unRh9Prf=Rd^?44#l zCVFPEBQlehU?PV31ayEoY#LmA;3UbjB#Hax<=Ngm z{-cmtI%;Z}#E$`=I6wPz!dh{%W+RBo`e;asDQ7b_6sZ&`o6GYdGb~(n1l(xZ7qg#V z|IC#M>+0?{UA$6L+}X<#MjYKA*H&-ZZ^!0oIwq>R;w*1OLPUIskmRpPfIEV&c%8yy zyh_~A)YNqDwYA3XHEr-q1)ALEDaDWlQ=Yz#Cx^~T z^NYpNJw83`=P~}`fSBE zN$knsjE0WR(T}m(iu(rdS2r>`9=-S;j?|b5ajI<%mCb4MVc*7B(WphuwJgUo=ul)9 z(yr*Ha+=$m#8u1nl$MX4wVkq_GlM=3R=7-1P|w5&RHgl`ek&s!SxMZ zaYu}kq|f^LD2O$^%Os~uo<}!l9xB$(&Lo2yL@T;U^<0<1u3?(Geb*^ocPz?v_p5c= z^RP#idCT`etcknKqjz$1aoL$`x&mYT7Ta4k1y$?!$xq`o5VS4dWPuV5Wv zcvAC{DEmyBT-|fN)Q&H~f_6Z*408=YdE~x;07V&BbsW>+RRQeR|0n`?SGlzFiZmhAaLkW3h! z?MyAMJbSdRkq30iT;ctDkTu^TN!(owThG@!u`MGx<7?e!P5Y4aAfb4Gh`i_l;+5OH z54nr5eL3Pv@HxoP3@8K^ofBmSqo^k%^Yd}m`@I?CY8`kbyxBDX83Mb91y3@FaQ zeC)}f4MtsitrgRRs}`zO8hX+mTZo$W;6eQdm`3wqMneZD!*sSY$5G4Ok978*9|m55 z@eMA<(X@P;_8Xq>SsID*Zj|C7-fkt|`bXUqPMbYMA+`3HDm;Imb#>S{XTC|Im9P5I z2kk1vm==ToYMD5ZhZTBzY%m{mQ@Q5)eXcOXi!HbqPg8%;_||+cfdJ{wBg=<#(^hX+ zVmc%MgJ|ld23q$MM=JWwS5b#`S_bY6vLWH$U)=^)N<2Q{oM2$RHJ$I6NGc*>f#&4Ni+^bqF&mQ9Niw=U+D-bL zB3&cKp=CLm5XN@6iy&a=aqgNlHy`l7*F%H z>9F78Yli7}BphQR68F+_b-l?~ZQP*liJ_^;F*@8RWRo`ry8c~S%BcYac@SCahkk8( zJ>fm>ccY);@gMBRVpl$}4?~ld3UPz_x^C)XgtTm*nBL6jF@KFmrcD&6GKr!wtFyH_ z9&0rgC`%cu5Sf)+Ztd|k;a~Clb@OL8^&gM*!X3#BB;Xoi~LuVdUD z3M+g4jZc5KyF~*X!B0E*ep?O3eO9K_+a38Q%usKdaW!=llC5z8!C&O^Xz`;+d1l&? zg^LYeFrQ$`S8F#^;4yhe67ikxK!~f!chnV>D1|$oFlE5FTy;ZT@0yeTjLHlBcS;9t z!ll+tM&+sOO0FJd{z&zbq)VSsvAiJyD58kykS{JP*=Q>&HHLzV5nl((CIip&kgcpa z_-BPuO%@+elxTJJlY?SemP7WDizO;%79)KE#E5t~1u}xgO1>a-A?>#r;Td9}p!$qa zt7wtC_}o@bu`fKdrUvGbd&;F^VbSZP+Z73K&5v-$%>k?`uMe;TPiU7`SI$rmJ6U2< zaS96ubfk0nhCtSY=BSd9g9!reALMx2&f@h674a0 zlr>*rQUR|p`BknWMM)+(pc?FIIGb5G96@FWDkK7#{segZgSiw+r=(ij@e(&UPbn>#-E<>_Ac>)`L@n9uN7pc`gqFqNdb3J5Ni$jA zY&^_5f+*PtLz6NubJ~LAx+}tu8e6uBR=a&SLQp}gkVRR~lR*|5?)X8OgQbxoZ}8tQ z_@JeX$rEbj#0=HX3oam+)(K@V`T)~vk7Agn`S%;&FM#cvh5vu_bD1Q6;2Fl~gZ~+~ z6{@=K{hFE?;};jdH!U6B=ip#sas|pd^-K&~hECOZ7)RoopuO*D+Dic8is`Q|uijkJ z-J`+z`%7Xlckf4m=_kj)q0I`=o(>r}5-F`!s0u%y3mhQ{$yZGS4bXfJj<91Xr9q~q zXK^0_=qQW&NSN23v$ZlecZ5uOfaL!K8vjC_9Ek^1xeUR@M8ao0F)LHlOX#QX z=ewEgovRrM_Y=;eeR3B)69xPItrwSg*#SMR^CMY=xIw>KR?3FCz4!!zQ&ImJ-n3*` zz4LYJ0`k1SYwv^ofR_~fv}8O+-a$-yuSGAG6WjFP*VPF*tL}(sF$okBH5Lued$;f; zkPuM%c@D>pq~e7KRhA0DAd_}Y)Dn}I1FZDH3V#n%;Ypc+pa6PIcTdm7JYVM!7VyKkeUg9${UHl+4Tk+EjrTcA_8kb})L6803AucX z27QvTlAJk{J288rpZDyW=fk8MW(lRf%_HTaV8%?-QeD2+@DQ!O`r_8A7YY#~i8iC5 z-W5VLIU~Ew;U!t?eV|wRlSZSm$5kc5K)}O7%4)5qsb$^$pP{p6hvvwg&Q;NWXTQMi zTGiz*(PDiXf1bft%uFj83X{T8D11rVo8j^bNf~j~McffPN|&@56a6C->()s=j^bQW z<)R?&l0w=l??Ah)<~x({`ZlXb6w=VXWXRn7Quq+yN&ZZ?L@=YKT3R6$mntMIj|*SH zLcd+3Kbxg6d)Tg$7V=QT?yHyyqe#=dymozr`6K7hIfeO`~x0f z?ohp+DCH|Nm#upR$;Z+9+>4z^74NV3+2E3Gy{gn+h`$)e3WW@P83vgfL`EO#%;bRT z*{~uE=ED$645BUb8X(dbe1;(4!bGzh#OqyZTM=1n@bU2Vrj`M=gtl8~G zzQsWheMcf(-f}~WNmIY6RpmTsXqh2YLQKSHb;~uwYF%0=|AxL_>B&sb=pt<%Y&(=` zYRb|+Jf=>>zl`#QG`Bp5dtG!3pAqoO+AC2hr%j;T@9e{|>qSsX`&ZCZ665HYk5Ijl3oHgT zN;qX6HiJIGKM{XZi83;d7F8)NV&3}0Q)y=gS#0{hgRRo3VVdZCbjn?&@oW-dUcuYH zBeKP7H=%LWrkBv|wQ_#tZc$Dq*&o9HnH18V1!tSwf7VxX&Xx)%8`BuTqYBopP}xJt^D2r7rro(#OV@6W@e%(O?c{w^%&8xcDY;;CYw_9E{8%uIo zbHDg9vK?M+IY@;Q98Z>AOBg0UBfA`(N`_^4jCh-pYxCg*!`F^8JVI@9HzxwO(oVe9 zK7_1Ac>j1vX`#1w#&OCQF{3sGa&ZkSu{A?`NkR1#b?vsGveHu*fkD<6Orm(l%2yUuDimmGn2Z#UK;(>c_}57N@Y?!fN+Zuqa7By9EPL7v~Nw6U&u$j^{!rS0@3@+3A?WV zr#eYnpt(V9|LARd8&S0>a+6cdmC|)*UKzqxS)HA)dqU`tZ&b1SOV^9p{18&vE?>U% zvQV{z$q8GiV#jmJ(^t>nRluLx1kFTC1W*TIT=v@NAY!n-kdy2z-DejX$NHM?OyFnq?u3$N0{t zAYyOKXf2PR_&F;!Rk`ziBWkGZ1y`RdMf_r6B^+m<_$@_O3HBUY&)q@bV@cjUJ zDtp8-Kz(SKlSOK?s;2t|s)?+lS-WL2V=`Wv53al)6t~l2n+t&}~&f z58a`9=du@pif^PQgiZLzLMH+G=w$!EtE*kMVTRVuV7JgwLG<^7gZ_NV%aiM}UrOST zhizJfhZojX@zwS90%ncWT7@THSgHGjqN(k&RxH{eMd1v@E(!+cDA7G|tU*FBzuDFO z*Nnr%!`a^0>gRy=oL`LXo!NLh?dV>$+&sVCWWLSA!`}92M&}6{FCCMom%1c*oZ@b( zBYbiirNt^RjYVUb00H&7fBGXa(I&Tm5CSD;Xs63LkMH4xbVJ2t6E&oJ-~(1^ow4nG zsJl$Dnp`SD9xA*fHng6HCt6MT{DR9oe^i=0_tTRzI%+B`T!u~?c-8vl`-T~ttit!1 zv7>GNVVn8dvbjgTp6=)S3k&t5qa&Z*fYtTDxY>L5tBbn$#WEm9Tb$O009WXJJgSgu zfDs=G>VMTOP~e6O25N<}JRQmRrJ&Yg?d?nA%=X%?H}8%`Wn<{n`MW-U@=b*@S#iWd zF^!b-8CQ9w%~aKlT|`y=zc457#=Maaxg&xWQCFAeV*1JlGM>AXL$~&G%5O1c!Z>?q5a9c017bu!7TUh z|KJinyTBW-$;WwKYePAE&vQLjt9eF0{2BZ%%upSj56>JXWSXPn;@13vI3ilas{QV6 zdG*3Sz{h7zUO^on|92i4$iq(LpFM9G$#9^T|il^CqSnN!r+`m921v~&zj5Ml3%Q^3(LC~^D1~~NlR$WwX zZ^_6?+5;=f_DxSfm36aH9R#X_2o6D>G8`1jdhr5@==x|_`!ko}*KrA%Al7Jg(F0ir zQuz1(lqivxEovB}^4nW`^Ubz1KolAo8eCXd@Hv}Rkos*uyw9-!7(Y}AhWkO_QBQ_d z%76z%d3t=Zc$__j-{%YF0Z=#M)1NncKT0PM=om{;kgj?74>+@y?|XZ5b*Au2-kv|= z6?{a&bks>+Ex>WVIr+)-uw!+u$tx&~fHcQ~quTvoiQ4Xq>0F~nu2}E&#gVCTjg_XA z8~dM2r1NpycRv4QH!il^CqD_J^A&c+)@@iAt|aNw8`GO@cMWK(i;-Ri zuR8+LcFmiE4qUj zv;%t)7u$`{iV%><)PO8X$ z&#NpfEKt<61%YlUH5PdE3^xYUEN%O?g<$F*EY52eJqf{M5J?ey3wg`YSlxaWry75J zb~eV1xr|3c@yl5q8)C#H5KQoN>HFlQjp(7@`UnF%MQeHgOp}+}IzgTj$MZgLli($$ z8n)bcEi}pW^Rram$gYtm2uaB3%9PmO1L2TXCmBg1TCHnt?runZ&)s|_+ve`_?rbIF z_6MimZMpGz|GeJ;-K`MCC~0PTDEZt-Dq+;?;7|fNjVjplYD+aWFO&nRSei%D@BKo_ z!7xq{Hy3BX7OB-igbOC%RteBr-OgGwzB_$seACw$jfDOs1hGC~bpc8S$GH_Xu`nru z>nLg}%#m-H$U~HVQzY*cdbPUdnDr}65P#q}<7^5XHZjxqy=4-`Qd=oCZn>v+rAjQO zATMuH7i0i5?a?X{MrhYCev8MMF-nu;SiXajj%(FLl7~arTi!2(U)(**{6#+1lrcf8 z4z%Q*MOjoRP4@WY_6?a^`MZ%(WpP-~;UXxygevuttgM6MR7S%FbN zN31@o3@>kRF}^dxr|jIt1=O^r)+nNeemwUG);0kT3A`IuKL<%xd?5&;eX$lqt*Q z-0KBH+P*3w>Np_QiQJlTg>}rsg5wFh<=;fHLL0UC7VO)akmc|ju4`?w=GdoEn@s+q zTfmC;_TG7QCvit8tJIOf*W1oO5lheTf{Im`ksT`i-t{P>3V}3{3qgE8Iunzr!%nLs zkqVu(kC0dZq$1540I@VXw?{**NOl52K%t?bXkAeSix$iAurtEv=B6m@NW6ZD(tCm0 z=-ogmy&^^m8mfYoFr$lEA2R8r7_oHW>7uqL6~=44wq?bbjt6)G@r!bpC+NJCFylVn z=H0%Uhn{U<@xJ@AKT*!82?=WV;>REjWGzk^jX!UiRiR8IlwVeTMP<$Ro6X)gzY7s3 zB!E?xQ4@*%xoWzqZePw5D?-~~Pzg!b5ToyX?Ttz(Mk%7weL@@S`94si?IEs(TlR@& z7*+T zGO^K1xy~IM7{%+=yB-YmmQm|TT%Ol0%xetN(=!zXmd4Sjv(p2l<&OoznGR+!V@Ezt z_&AYLS3paB+614bGL^SZuoW!R?C<0n00aZhj1DgzaWd=pXvakjx==X6?b*df zf;c8c96x7vlih-6Lcm<5Uk7qA$Y#LDxg#iO%xCj%Vb<>+{4z^*p->v1YlHY%aukc@ z`$zd#<3jsqF|r2q;7a~;-qZgmTc(;@ZjfI@{KHuhOVB>L#0 zAyU>aNjB`4vE&#)Y{TF+f=b^D5nuXYHr_?#VP3HKJ`AY#9p4PL#5}o(hGSz`4+SX- zPHqU?kJ8870(*3ME>v#p)9iiYRq1(WljqU&x~f$onnb#WnLiOSnwF*MuF{o-G{hdw zC3^)=EHibs9iO*!8+x+5zVCb z^~RKQgUX_h==I6cX(D5@wUm5Sl9!iX{n?yU{ML%!zePUn+AQeN`&?K6*_2m*;QIH( z7L(HPXo9ldQgKe1wVqV{1mY|q- zuU}N3UgcSpsMzcxP{9~g2Hjr1KpFcS^>QKYrly?KCs4^5VeBo$M%r)xSzn{aU~|VS zHz-il155Be@61>D-dqAQ@E75o%v2+1wMkpxNR|`58Q>q|;^M+ib+#{3H#RBAs0-FC zgRP_-mVRUL&f=R3T^prw7U6YpUm;I6uX{nYr0iZD?jYSYd7IUy)xr=@leMje#ecm> z6te%qbWS~8Hdyc*J&*GVzg)I8Q6B$7-OU8&^^-=?xJ&)s^IGF8??anL>^q=f+fQD9 z+oSnKGM(*xxRGKPuo7Qa7vkz9JMSrE2owgCwVx%ARVpVC_0Di;eE!HV8S&7OATk72JFiScV<`_yaN z@zCn{NU6yx1Nn4Rg;IiGkp1bKc_uoi>apCT&QM z1rD&Ou$zdW>rMZ_mZ9Z+zFBzB<5;< z_$?M;H(cToH%10Vh)7{KLwK(NkH0p=Pc@plp!9$bd+{bKW|Wley}<1_bSLU1L1J47 z!OoK``+gg}D*K5gNNVGkMJf!v?xbv&^U2RtWO$}jg@i8IJxZZ4507PBodpCY3oM^v z^H;IisSbSKf*7_T!gnL7jh@v*4^(i21)Pf_BD{_ za1#S)B6iayi7Hbbo1v3c(A!kuiFLA8U^?B#ODJ|_l6hTTdIFwp_@=4;^y8=;TZ4&W zC~VQsKD>89I{cZ5vELn>Ny8sr-XaojcKv*peb+OzYfXyhv6FF!C?);naz8S~GeQQh zRse^NDn4#h7FFh&lp3!wl8RCbEd+@LUe0lo2>F{c7;k^V*}2CG8&PaDB~inl+&-iG zACn+(yDCb#rV>bfGkTHsFtUuHs&_#C$q*^v{|!{seH`uMb+;#U(B1hW5AG? zH5>YJhx+L&UPOsJNN6Ch9D0{l2%MchWw zsXBv^C~_{(mtih@$vUK#l^s!P)Zb_;f1}At>1FpfKmdF0#|Ake$4m&3VKlFzXBCsv zJda|+voW%|UL1{GFsaopM6KLvxVw9Z)a2T3nVq33cpDiYVx&+=b6WLU&`PThp(noS z?wB%j_OauytN`Se9MfTLKVfcKWE-`LEO$&RS(XpxZG+$UC6zxAC{x}&BMiplA`lxj zq%_yp>QV_1hWYM|Q;4b~rH`KAcb2+wceF)Rh(<@DK86;l zevEf2U+mBp9fMD{CA8fsZ?crQH#Vsd@GpW$|gs=mMVYPC=nTGje!P00WEesw{Y zh=bbxPdt3C6x!^@adQlE;(ZbmF;YdctZ5t1%0Lm$W7Am)PICat*R9%WY{fInTnL|} z%5RfzdT(gf&358B((2WjGyMo7-oJhERp(`pQ?;^yl4e|~OpHlxWzLHi?I|?-A*#MT z7`!)Z+4*gpVY;I*+!*fwk75t@#|ZMMW6SZTL(T}^i;29#t*${OXk40aJqfo%wH@ET z$XwSOPzU^R=6rNFT}*>RF;A5-&qF1haYIV3_UJPqWTOQ4&r7tHfvk7BuOD&*$yLZi zxfs>EZ?u&J1SL0#e%enNl-{4YPu5~whNcS<*fjt6ZcXoGNR`)par;~QmN2!#V-DHA zx7A)*eodnd-yQr7DBdD}60DS42vA@pIeeVlK3dd&{J}T}-SW5vmvqY$?uI z3Sh1hb}sadwET80b(O%PBFu7$Ec^Q<3_)V_9S)J0aP(K&r}P`c{ms&vitux97k}fYW+}|qpE;@Q zf8u`N*f znNjZnMP<7~VGuX%*Dnk~Qd%934FccWf0CbXq~Uws$m7z{s6FvFY{frtsSE4OA>ah{Iir|1!V|ewGhG9zo-UJsNF8(PuO-uK;#?uelpt(B~~5>%(d@}s14s_@UG*zUDH zws{xi$Y8VNO7KS%YR^e_cl`A7>w$!nkGtQ{?w#Gfr-!%-4R6tXT zoMu7(@n#M6%LAHS6$#aF4o(PAd*z;RgH&e-tuw;i4-7nk8mn+{KnpKw#*&rt<7eDuWc7xavE%Qg-p|Msl@!pQjINFP>R~okYX>^_k?m(^ zG9T%=)1H2IR#w(@OsWB$-}S-c-7m;VO)vmRQjD1i>YS_5+etcT`gfh7EdhVIYsb+ zk7T*MYPm+=q+uGf>et-(P-CpU=oRHvIbtkky|K(ui%Bb7?T*0pr>$?7r&7G7v}F+O zNC@>Xp9wKzp)PETDQyZwFHbM^m`<`&oenLXs~LFP*Yqm1Q4^J!_B#TTYhTLMUJIQT zS`y%1cY^T6F=nNm1;!qK{Fcdg))Gy-!eDgF{hUf%30Z|7;dX+Q#XmivmlIknQM!?Y z-e4sJ4`9!89U{1V>Feasy|jCO*QF|VL{pRzW!6)jXV750H}*i5S4QawlcP~tE-{rl ze5z;{e$}oqNwYaBFSZ(i#pE~WBi8hZKC?S&^G#9P2`RZI+wN{wf*p_R6%rV z#R?abZiWTP7Fi`O{ivfLx@&~Pm7&LbziO<qjxdl>PR3jtk6_zr>Cwz zsftV8gw+~Wl`_+H2wjrL^`p>Bp(O0YKNzanUtz5^>$Rp=v{L_SdYCIliRJncnT~Si z^Q=@NAulIC(r%&O4+;i-MtoYE!Kjt*lX`~=DwbWtez#6mDS#!m{q^Ml*!tyY8_(vv zat*?ttX;ZD4Tu2&*cPq|eP?+Tb%9@cs};`j-Cwn`0W!i@@_~hPxrcpaIFq?Rn(`|Ai_kih@tNFXzLbZ(D<}15#20Q6G0#YEHs{S`AOk_>S>ltzL zjfGaI+iUlXB8FQ*$;5HHkQaVGnLIe<0Qw&CNPYVJ5jTgqaTRIX72kr_{M9{YoOw&6 zm%~}O_oQ`zpbP=BG(t@e(D>x2SO5ZddGD+$lP8qmxJg0OWH5?zJ4iB{kj7F`JN7-? z+l@oOGT>Uv(%akncNdID+x>E*C|4hFu3t?%(AFth+5GBkries?i_rk53`l+gFFQ-+ zi^G$7-Sl&Du`@A&N7-?N(l9w+j-&TJaAT<6KHr)s3wj0Tq~~>!&Su@{xPZ&` z3~=dz*#tk}JwH^Tbl5l#*jBfyZe<%@OA01fNzm?-d@q@k3cEP}9hdEQ>!H{B;ps<{ zqF9gf#V~6c8k+nff*(@g+CrB9Nyx!%L088ZWn7MjoR+z5{VZ?sJlPz2_js@A%t(K? zVNX1gV!xAEoy)kHrVH4VIigAaBI4Tu5MK;cNxV%vu(oB8z4{juwk1AN3pOo$AanR> z=%!if|Kp?XOop<_@2(i&zzDcekhs*O;E?_H7G`ZoZ{|=r(`-wHpNGXD64cfvg_Q#2 zmoQR?Zd$iV;^yTDwk-cDsh`OBq7J*i>i-fE#v&y<7yKSJ-vkqtN{7F4*c>kb?p<1> zl{v3HpXGRkWNrgADfrT(Ur$j|?G`;Ak@?P-*9UZTviNW~&-f}jCT7;}?uLNfZPtbS z7%LwqM5XhrVNq-18T_n$3;{lRN)csVgqm|_d;t-g* zj7$g&&`}{UkR3x{fB+1EiTU`1z-Ax22^s@rhs7bx6nP)y%?uup_+Kct^^y)(i8}2=@tw=GOSL-jyMs+ylfuVGBcY&Z5@BRDt-|4d-FoYkpD14zAKi^RI z!wPV`+NqN`=p>e^Rb4@sI7g&AMCEDRm!@Eq{R|v&#C<8Y2DRs}Gb1CFyU7*P#3Jy` z;Rf+N$}*!S5e}%J&7{NHJ2$P)UtmUs;nU%D1Q&~fsVU7-z4b$P2dOA8Pb(zhKD71m zUSl=bR1}^BJnDy!=DR`0$PK%pWn$%jFv`Tk|KRo_!xAeStK8WwNxYUB8hdoRrd~byxyKaB+zHr_00KdP5s)o2b9ElX#4LKU z!A}S{qS8gk{GDqU#-tDn7de2qWATT@1^Kz|@98_GPu#+LO%Nf3rINrwb6SDg9r# z88>z|JnW7vfk=11r}_4_Y<3o0C=mDG+w@-=>t9>x{@6!=z89flZhkpR#DE149AG+U z`K+e>8lcKHI9<9im;?HBFhLpcBUnk?-uUhKTAm$@ zq;gD2ji82&z+F zNDM?HMJZyLMv?Z2ih;7@bn8q(2^*2Go8D#lyXx$d6E3KRrE&0&?gIM($PNZWW5yWq z0iadOcf6+u*`>ZGh4ZmG*vj_p5KX&F+w-vadf>D#i42w}7AZ+!aiN!5tzC}U9ujeq zC_q>Vhx(M?_a?S`ra&;Ur9}C*k<+|G^T5!TWSjLx`13E^%IxPE)Ol?~A}rWj6*EuT z0u1u0sxhNBbMVcv|M+!5hNbabFE_7Dc#k7~{L|E1yb<=i(Vb5K>we>&^m`zO`SYi@ zVyED6{N@AkBiZv*F_wY^r5K0@8X*XigSfJW(KfBpKmIr(S)U`^H(DCGw?nd7`$&@( z%=JG8;a(=_oZdnAL+e8Wqrzn_3hKON|KVMPkPu^+pr=#u0xl&xE|2x~l(Hway; z@sRioM5dQ!Lomp*S4PC{)=O*luJ$N%#yaT#n3Jjs1{w_U<-b~3qP~&tRNYicTX)6Y z8`JoegFQ0zGGLI~pfB~AKN4?mpvcaxox%qa`etk?Rn^uW;c+3L+m#~LViJ@PYfImo z$$Zq&t{j|Ql$}4-MCk7KUnA7^dAoivL%U!gEQM$H_TzjA!BpB?)(h`(8qM($CrC_daTT&oX!Gp<>{oObJ>aiq=zIZufO*@uAMYrMEEJ?+=Z=nBXzoUjT!gEx+A+er zD!5f-ID(8CA|NXJu9{ZM2;ciYa?ZXWln&Pd#gLr*neCY)^K+o|cstlKLrdu`DMk{2 zzp4y#)yAH8BN=2A7!V&hA;%po@dOclK#bAQ>*avP-a06SKL9b)8Q4ppaFLwmD#eF^ zi19?(mm?^Z;VbagfUp%xL?s>03KDmsCtcT^Q$JF8+&iIf;D%tkLzmP5fg#2y(!V_4 ziRhwYkhqH3dTblso)KKqJv~s2RrwKIoXnu|TbhC37sA01{C-s2) zC`FCqQ|?2(El*lXJLi*_1^avxdVPm54S5gCIJ>02`Ho{6IwRkvWNmk6Xb3$vpJrW0 z5avv{*`<(Xz+gkRX+hW)m>xjn_BXu=CBT}zuBQ^Tog9sdq%(`R4i2KU<>RZUolAhc z!^qf`?TZ>!cTc7obTdBGno>&_|5mz?W8_nn(qP*}rQC_LG;XJ&R#?4BuJCxWfs|RuC|M zI0pqBTkE4tjjx#?F*!-x@1+^Aprd-2diA`{Vy{~Ke)4ovwJpZ^F@Cm1?3(NQ5=Uc- zV9&rd!bn1^nlb_jp`{;aU3n=TimU2ZA9U*-tAce%wYE~J<|j!5hOQw*&@ z)vAU%wLV{!4H&lmY)etPeLeM0+U>;px3oJJaE6wEm9rz+r=G;M!wKF0T2qceT=Gvu zfRw$S`VsGjXM297_n8^Xdx5emyrkyDkaE=YU#A4Uo(j`_fOjT-GT|fCayu{n^UUoI zZyME4GYsn9JqGF*>F|kv_9ze=_Ja*PA~%0+s;L(cboF$n@B`Ma(OclinEW|UM|DC; zM<*d9@?p$4d=*rl(&3B&Fb}X*NaGNLiUGbg2h>gRsj#$9IrV_Y1ly{cfy+%TL(s*| zt>tp_BQi2F*m#dUD;+NK*Qv6=9vGJs08>JGb5xyuv%Nn0zD)@u9)NN0Je4efwu+K% zq>vXKXKd@F8vLOTNAhzJ@qyv5pQq&-Y-C5VXXpet5*oOrZ?CTIT&b<8xv?!R1vkNg zElmJadOSpcad8$^nSH}5x8AK^%K~q5;FbK#On7dsN=llv2?M*G#D#fz#l?sG%z=a+ z)-OfNVGiK9H`rHvd@(ib>w2>JgID$6%!3@PX6~2jx_tx~R9|OZej3_09>@dC{Rb)f zC?pfSQ#h=gSL}S7rbJl*?(EgF@w4UDg@Q{q1db&^s20KJfojR&fMAUP!_w0?2ODms z+Et+d13K?+ZDIcoDZUSS1+V7Uq&N~8%oMfyL@(Fh1OCF`^DEMak%-Tc7eSvQbIe%d z(+LCNzCBRszt{uy&N?$5KAvS1Mc|mum+q-5?Zyflx#PpS=l@&X14x0UWTGS3;AdGJh zQ*^lBKD?!*`jFSdhLrqY8ic05#KO0`3Q@oHjRSq?`-~{o1$!)?qTdF6@5*3d@D*_69^)Sn;9x zndPK6u<`|l{YCMB5h~^yRG~z8h`fX3ZXYV~+5s>@zzO&PUID|`&2y}H$U<4&TweO( z%XD}1)z3eTz=YND2lhNb-WUTP8Q0P3ph2Vi0oathQ{3utdwp>XOo{PgMnPCyz<9U~ zj0G~-;vR793*}Jm^B40vm28&ml1$*M^UF5r6cg}|klY#g}NlDVEsbI3%PPoo+h zzW~K@I+-_U2Hg6`3UGeG+lZYi;U{k2v42mM zNRj3^9cD_v5WKE4M7KWMvW*RZl#zS@@~?IT29YR80Zz_z&N(mGx2Ec4^;6h!xd+UP zi*4+An?rk17I?667NzrZ-vL+&-*csKzJ2~(sbBrG(nrr1q8Uv0xq|$ZJ>nX77RIo> zpGm>wHV-=R4!)cTaaN_*LB_Z{oe2Me0ab4LvhxuS!>O4?Eh`wc4bwJ z7?0l;vv8?SklvX`{K!#=1}!j%_Yl(n13(}I+Lf=>$-f*PL`jcg6PzBzBUoJN&7bea zXk*)mm#_7#oYYOLeu?9u{RdtfBvNc!+gvoVo`e%~^?(4_Or3?xs(Q>(JA>+A2j+9* z#6*t!v^3Pe`USD|6kWGL7h?L}TEKjtyhyBYNbmxaE_+?!qA+f7(Fe`14ob+*b-zho z36a4Q$pr|^KM@s%c7b99T*3J3|tfZ%RPkwo~?Q75{3Dm7#C z%4^WPuMdd{;h!>75T9S^(MHc3bp^Dqh-dOJ1ROu$} zG#Tm0Rl6(~6d%L>Niol?#~zN~1Gl99qnW~;hu8x?PCXMmF8gGt5U0`)|1Cfp3AjPJ zWW(LD74E>NmR!Aly7AL*T?SNgl`_`ec*J}swaKAu-xPc6t{LkOkt5)a4CFITP=01T z(@%7olD$3j89C2sP(d{7vC|{LN!6$vxL6k)Fq_o)M@PhaU4*lc9MINU;1u6~(|<^rKM*IVj33l}bfy$CBd{ z#S%}9Qnx$|-lq=@9L>Ob$14ElZZKdid&AF~^t|h`h4%IdlTrq-xaNR3(#{xMrLb%V zm9?RA;`KoHtelDm@7VYZn9XB^>*vrmizfOmXp&hsLy2=cl1Y5=ah>z2H?|1OwVq@} zWj_cKO2ydi-bj@F7^0Zxc^qwp+w_Lx-Z4GR-8x})e#TO+iOa#exM}1;zCp0v7EaaO zy&y9j14k;ovb#uw!8CfJFJIfWO#gL2DWF(Bi79=v7!XMsB>*pJd;cIJZ?=$;6a{0a zi1h)B`Dhs_x}WhI5^Lxi#~%-6}cNSBYWrt5~0T;~6*&1rIT>U zMV)pc=cLriOkExkV`ciGA8h|j#%HyWk&t>p%Mm|FvS5Qge%G3yabik88p$i;O|fOJ zhAq2I-}VeiC$U+viHsZAT#m-eUGtra8;D?abP#{|h)0Xm<0K1w4F3snM9#E@Ac$QRPku@Gz|a!BZc(eT>aW^;gOqG36oHcsz{ia z5X+?E{0S~urr9IpNUH}&ec!i2O%8BTvVMOInTjpw(j!N6$0(@|Z0V0ZO`-(YkxtC_ zDCA*2;pxkQtLdItkx-5;`k3#!sv(93J=|NIHk;;rv?^6@?gWjJR2hXDmw&8|8-312 zsyfNqT%(s)`Zbkb-AyB>+!koLeUEW6$2Y3Rta(o*h9j7cXGDt7k*Oq^y({NSL*Kd6 zS{0(wnx8($#MsjE8Vtg(MXy{4l+!C{{|WGc>TXl|wn|jTND~$QIhX)7ybd_(&+syPONI&H>pf)>tUmH{=?>!C_&Yjb64o*Qt+bamXr zWw2uk5Hb%9O?=04Y3a#P)ZbTtEO zevgG%BL6tyI>dmjH816{M}{1>VK=g8$5SjxjBr)1;ccepWDF+fr##>YA1VCVo^N|E z8vAnDi<^YTW=O;)ke^cMAtfJyQ0x5bp4chjXDsaDp&pB{bXK^_egKR46SQ=B?s3`~ zq)*!7QxveAVeH1CQS#oXqt9C?d}svIEHpMbg6ZVus(q{|nN`ENyvLVI42xg;&oaEA z!bjVHOGFVa7xePkmwEQwYcwLfxmex_Qy?a1!M;1Ah}}?a_UE+~&k-(SQ=o-eAf)Nu zQ}C#II{eL_B~EE$l8-Z=lmjl|nLe?*Ie3V}CL&r(@mOr0WEJ7pD3Y5FWpgx(kT<78 z9c=aCPNrY!oc}sS-rFY?Lr#_LtSrd0q13wWk23f(mT8(|-Y}~61K#uN-B9`1BG$2| zJ+ig1W9dPzEIn`+g^*C?1qU)!7UEr>4^h1u?t3NJ9#DQhlIAa6gOPK{&I19s04*xvCmjddapR}Rnrks);nD`&* zMr9MGPy7yLAsS_8?+SJiyu*8u!C>}_Ml07U`Q?jr8dt@Z?+Gwx6UNI7_S(p5 zbf8-R9m0LFap4}+E?-ZVCf)58S1vw15foGD4C>F$HvJqoUAo*8XU-hfXV8U2nMg%C zRX!$4MSi<|4>ZIh1}7+fPH|lFqqX10Jte!1?@}Hu%onjuk+J0jmuNkFRw#o!4}FON zqMT+*g14Z`qHo41WCeP6oaUh4Rh**pWRgdXb}5|40ng z>Kr<7E_x|=40iUQd(l>xh^ggSXn!`6dw%hN>!}uYA*-&%FB?PQo%3`lKCY!9?s!@T z^6^T&JqSzsLwl`O3{^RQI`e8SIDyeg^wLJlj@(K=<1B=1%D$4(AI0DKh&}MlH@?Dp zISV>JPI(>)qe9jra(tTd5u#oZUxu~@k3Bq@3i%MHkF&u2V9)ZaWWNHZIOm6MfhkW~ zkf#k;a*|ALDO5qdt2f}Qxgr&a8V9@F7BQ<#gMK3k#{sSRc_lloV7kVzo%Z686Z9v( z7UP`X^w3hy)8V+9eO3 zd25d=_@oy77aTw*F0+xj$th6eBmese@#pNFr!pSL{Te6%CBuc zm#DVMTf_v~!yjS|Qui2j`MEBe1jLCyD9-d2N7F_%)XN_q;9R6@qhhs96dqtM^n2Fb zTiL7>yMHv+M6;?Zd1wvsm`l^v^H|8u$3_e%F1WAv4_3sw1>h~IG^`<(Ft5@1nXLpf4L}BrM z*!=19HBU+B@@_`8JU*U<(G;_xaIhTOk$FZ-y9zC})5(?0mH%KcPVDX{HtOVb!I|aE z!#ul3a1z&QWnYp>3SJ|k$vbzHbsBbMR#~{L+R@UU&RIjUv3p?esm>Qj0%kh-y&Duz z{;U#Ctp(XLsfb~2UskNrW<7%M5)~5k{K;7`U#v{;vTmbole*50E1T_*YR^@2y;DUS z<+HwA2VHob1o{9}q;XpDQ|s)O=KQ>K#GKa$cD&X3vn;N6?aaT0nAyWAmoIs0Gue@TGbcbZ-c0 zLi&&I6+u&<)(!_l81uL`M*cm)*XDVCMwG;%N1W8tj;#s6Fs7_v&pJvqD3LOpG}WI! zt1v&)#XP$uiPZf@78A4|Zc%yKoU#*th*$MGZ}*a%HmxYceikyR+_m}B2AN-6+NH)H zzl+lkw$_um-QgVe;ugHmfMe$EOeD2$hUx>R1r$bC%RTc1(NL8m&-0hXi2i6k)$?|^ z;}vVOERr0USLPuk&ijDcvXVjNAt)j63RpQEBNNHl#$OXYh>XtqqHAhpea#iiR)~$T?2~?D#s$9K zpp!S-Qsk@^YA!uZn?(Cg3?4&mpaC&NpM5EScQ#5WcXs&KqJB6>PCz|3mPY`8eE%kH zR>sV-O}X;rglvnBpUhfIxzQ(<=OPq*rN$(Y=2m@i?CdAJYcgtnmg~>5T(S)AE50;qD(s81(51MGY)upS8FOgvm^D~iK zD1qdAeZ=gKh(gH-*@z91+?~5W);bdli=&D8(g3(1rMBJi~a<*E9#KM}X5$I&Ux_CDf;woHaPR@1#5il_KQV zwQq1R&xtbM6mbMbI7>WKs&#NBy)#`%obl#*AGy|qOJTStkV1{6KPaj0zD;0C=z!!0 zaWYsMhED$gQAKBre2hta_YOhBK}D_EX>Gsb6)fQ9J?!+R?sDbk{G-d|RM5j43IwY= zgw}4oMU)n}qP}06)2aYbm6m(az=+k3f>D`>6~RBF@XGe%Gtyde(B@f3o->}N%UToZ zeR)5{Zx7P^IFNm-aYuO5Bf+P3j#wctqEC#RX8&TNd7l<7Ic*MY*BQf(KqA6CBh;kP zh2Y5C-H>pq*gLn+aHxacK3ei5|EpJb)7?rPvx7Srok>+DK+#fgF)knI1HvKEUeO?Nqs{1xDAPNQ^`6kTAkzvJgaLT@rqFjr@jZ0d>Cj_agIRCp0O%Na*k|dVmu;2#S9>Q z99ON^h>2YHl8HLz*z6s;#v78h{8NPzGpYxyVmPX&LmhvF85E)=y~ghn@fppmp*o^F ziX*50R7##yqC)WgQ)1b5isl&br zw(wwd@ab-;%5o)Mk$HDE)q*8SXxa+TKH@uoVzweI!xEiLbn5{s#Om2^7*F%l=bvQP zwbEaO%y7R_5J>%+Mwb+2Z!SDIInp9M3_-?v&uyasoy=ozYD%=)qi}x~H~cM`W7#${ z(p>tvTR8Cmr3o9dI4L#3Hk~-Kpbo~u_PC$!2~P;lv?GMlSvnF&_HlJbE)h)}hy|2eT=5cg)34~IYXlM$EO{%?&AiruT7fEz#ts{R2&WP;a9 zucWqEZKUGyz{z$?7~{{x_P;}Y{YXKs@8l(%FzS`^aLc8lz1BMGeQd>GcM_3v$x|n9=})BEnJR9Af}=WZZB475 z6X8S1r+S^Hs6%=2oS`Uy1z_<1;eX}RkpwPjXF#A}h9?xJzz~4r;bM%_sXHN z41+{uQ>&kk&4!nNd+?E;mVAVdhrzhkw!dsq3scTQ0k!t8X~&_{=TqPH{4FiT{-YWV zAJUP>-ztAL@)@9=Y9J6mT921KHUg+T%BucIP2JQ{_86N8Kd{}1p}Y+J9HyJ?wQ&0& zrqU1h9@FQAu!?-y$<1&#KzeZJ7x#Lh*IQ2u>*EY3E(m^n>Nv5evEq;(~{AUKQgwbG4;(a9K>7E_u73XVrzJdd}m}k|>%6Y#VEJs>V9pWW~KC zZG|nAWbKLk5Vqk|t3ZN|l0uR0KG2rA`dwR1dy_gFT^FASL&(oh9uxM>-Wdy5i3M4P ziprco^gQ-l*T2_^-G3-1yj7)S&fZC-5tEd!=}Soi&H@TR6H6V23V>gk!W}DhfKTNP zfFaxwG|W4xPBXBrB(6XOnItJbw09Go!U-W}S9apQ>>%;lg=6Me(Fa_<5S#PA*qUd$ z{Y}*Wl53jwP*-rzdj1A2X1@yhqS( z2uB_bb=QG3?>}__5+2Ta>~58xYt;)3s&6K&kMr^7NO156qy7qX&v_i_X|aJd-rjy# z;>98wuP$Hpj0X)McnM_>iTHNv$4(7P!d3-eedA4xA++N7DYbw95b~o4U2Yf83gA}v zG6}7e0m19Vb+8yM(1h}+_~}^(OT2FTZxTiD8<%+V-@#nLTNs zP{q-cMf5j6>6)jGh&BO9x>PhCm)q&C#oxScscmoS(Z(3&m2fAW=QO-HkwYi^HnvMa z@E)9&17Rdu0D8>Lgn9#u_*wWMfZ-Xuf4>9fhZ&&kkUxbJ27A4j21;_*<~cy9isO;z zCLjP#{Vp%!W)i7TqKvzrp+Ei3gaf?iYv-=`Tkaj2ChP%&aPi{`4Cj++H^O`!5MMq- z$RPo{_~Y$f^SB0avyu*zN<`7188E`$vRw1F@_DcA?Ew7)>PdysW=iD*3lr%w!#e-a~9E}(J# z;$#Q5RW+5Z_o&1)11d}?e<>(mgr@7g6w4(a%&yXkI4qEWIBspn6~6$lLT9GG(?u)q zpU&{u_~%Qutb?ls!hq8OWx@%LGWc?DT8U{rH3k;bGjIyx(PH1+8@cxxioDXFwPJVz z5c5~f;rQ_~`&eW>;PV<88gc_L%{)h_Dk`2fDninoW61p-vOozsQU^TYdyE8CucI$Kt5lNh|)kz|Nk+{Aw`&~ zgc#sV+%JGk@W>E1lxPU(1ho)&1GnZi2yGDm$$v9w{_lwAZK(PWi3eW%->Oa&V$?fs zK3)>QSNMJb(5emB{;%nu{6!Z0pNbL(98mYpj*4F0a*68{|pFZ zLlCOa|AYPW|MJ-XA|j0Bo0tI=8%0Qmh_40#=Izw>KU4@IhA?45P(eobKs+^od4d|i zr1-#{NC_Mk1N;+zKb?R-2rxjh5(urq#(RPODapq>R~1pqN5!2eH-h>AsadrLPQ(nL zCPV$=90R?Vi4aHvd=Y`}(!BwRH6XP%0ZHn;sAA6%cG>yM>LGo2(^$XRg(ORIiApO%ZyJcjj zKbwFZ9#|-_aE0W$^h5sb0{jh>hCsZ-@v-MZmWG8X!MHeGDyE4>L~jhLf3Zl_V!hjE z4j?zqc#bT;mmuHHVWKW`U1$P%e`wq0(A1P~GyXTvqn36-8x28UAz$4Hs^VBlsom{4ZQk^zCX?jRNxnpLzx*g05B2`N<%Fne zeKM;-KhkmfNp+N@HfugMX68FkgGFZ!pS!Jd%^RRj^$IM{#}tLP4bw7gHC47y1yg#n zi+rO%7s1XsK-U4JzhF?l9@gOKD%APzIgoml+|};}Kp~^0u7e*!xR?kRX=IxfZK)Kt zDLZu-Ms@4XoaLQC0!_^daoN`yA!*|_31QmmvZCTh?>vK44HE2lAAoTse;av?vSSewMXJGF`oEp!kQ znX;*+zYh0uk+E*iW`7k#NCxK*wuc+HJJ({H|EAw#%OiHhiu6ze zwkdFnFq1M!uWM4(vW5K8?b5ou|KMBGJk@-#^BJnUE!`+zL<*rBS*(_OkLq_?igFZ4 z%miP1vJTWR(uujL08ZM9h2>0~3!=)6Gs;pU>tU*isc(xXSdEeF;w_IKCoO!$+o?sA z25nbfrP3a(MLkE)IY?)V57jhW(FY8Ezx{nWbOGTz);p)Ww>3fNp7l@{M zKPpcGA2u&$CxJw5QHC1gstn9MvlAY~9~9RooWut!wHtevtsu6tKh=~Xs}Q|Jw^apC zoAuWsvml4sEwf#!6~3bZJt&T`SQ{`qhpXUx{(~K`X2)-lAQI8BZDky%h~_3(_esx% znjROo4!Y;XfSMT-{>CXXvE;~X?lDY_F_mn+GsTw+6;!JZaTuU`V1Kfx`-gH>34rYY zq*6ta{dDq8ma=Z zj5xxWPpN5!O31PFu*UkWg-(E4KrHKhSr#k~hc?^xt0YZ-*ZjK6PqZZeaoHYy*HY_c z$fXKNT520;Va`B#&D(JIz#Y|DZs_zIBeoDq4sl;kD(gslRkvK zObto(38%Sprh1ny+;3%`-N;__MF?!LqP{dcw9UW~Q|KW~Z7?p;-qK&a5?61iL`1>0 z4Ziz3bMnz8C(P2{`BfadPOc;+8jdf0$cKpqa| zwmF4=GyqQ$TFHxq1Blj-h9?;gMW&`@b?AOI``)cnuXkCo&@o3J$mThiL#E#_bo_3q z=}$fKlbPle4+@&bol=~-J=^ciAkDMtZ&FXYPu_Dn+baspVDSPViEIjPAAcD~GuU$Z z7M$mTZz5$9<8P`_VZ#2<>WiN_O}3<%u2}3;lZmeC_CJb7E2f+mOPs_fo`60SCDOYo zcIBWF(R9)^9Pp?uDc#d%->)R5pFv&l1HHK&%0VOiB|Z19MNRN08!Q#UTEgU(6*3h~ z=eV_459eSmBKI^5UJwsU1^UR*j|<5Xz^!%LiTY?yxh#HsONhs-OM^#v7a3!ryJ8Ub7?Gv=~zzOE@6H|-O zvE2DI-GcnmrUs?MXu=~ae78 zuCScR@S4rsO~Dv;>#UH8hXBkfJz zZ1nNxXt{Y!F3>!qPc&v-|K0={iTXYcB7Fbsq_)#OS@kesL>0}iQBnc%C8hqeAX+jn z6N)Su5Q5DX4^7#cGv8mk_lm?6N=ks(^0>VI=j#e^`ddfcfRx@6We>x$S<88B{oRu9Gz z9YI=}0FY`^Px{RZTtDZUOdk+^DpBA$C%Uu}aWY%ph}QM0dp6)wlsVK0u_ogH#PhmB zG#=>W%+~{I?1$p_+7XKYpsSul{qH@FZo7VnE~r5q#KIJa89~>aqHqkVZdd6rL{x*z z?Qd@+2wmi__YmEbXEU{)FaV0?=wRtFfCVueefw~?)IaoYBtbKfLgr_K#dBN0tvgco zWV+(@#j%K89~uXf3W`R`K4`<@`aFLl^ZwEXkdF8I_CZF&eWsaj_0<~oM`f$LuC1K9 z@-2W*@$vA`44FcK+R-mJIs-tZc1b?L;R!Z>41l8%S=$Z3rDZ1*c3Jf=|J(!3cZFax zC^u+xAK{tQbkXTwTY%1~oePE0dWg8X~SeXT_3WMIhUqv4?Bbf}i z73+pA05tl__xfz5S&)evTmUHm%WC?#75n7;IdY zK*#^{^_19GC;M7E8-z6ys!8qPyWGi21YMlG0GC7upJ`Ak(AguqG@LDik6d}n(nV|!GMOgk z1k4Wxcz})!wdW{)`g4D?qTlC^6=Cn;(Gie|e*R0&#_*)t`J*3DJWgqWH+m6>?QU%06M) zP_-xdr|AiBL5>jQ(~$E&rPKoVwQUR7baHI>O#AQ*gRbb{a<26g_80FnST+$ve3~8%Pi;1CUSvF?CRnTIJj-Uj4^y_0~mffTi z^VGVM2M>fHdGn|&sv~v9OCNhEJowZy5Q{paXK^`Wp+I7+F++Dh@PW-tc6jr&;6rsO zYRLc;OzNKkRg9qXz%;ydk0zMdLXtKbTeIFBa+dOdtC_+VRD=N)t84@A?VP;Nf0-bu z{3xa0e=#hX1&Fk+AhCr_|NNywta;=-=2jNiU@$}xeUSSpohtf*#;2J*CkHUSo3?r`0~8b!R-S0`7#6Fb)5>@W z9`-_wnF&(HA#9GU?zTP#TIEQ#8yzWv!ke_oEt*t;Qb#zVIRB9hB6|dcX_pAdMixNqJIKI+~ z*VK2mdykrdkyIv88HoT(+Lf3bUa{qdXdiw5QGp9}(}{gHdE&Gc-?H25{}@oOSJG}i$y8V7QkFnAsB0?pG{m@Ql>$1I?7@6! zQR|QU^)|#*;8+&+;LVfPy#PcV2Yz3_&6D@Dx6g17sQ}8@)sbM4o&G35C+Z(#| zUP?5D!0bszz~#c+&8L-yJy^qT66|JQ`{vnLFRTKfs|Rge^4=?-JY(wXp|M>guNdax;=?ZO#3nYqiOyxiWjK{`(>(3&zGiZ%H@1y{AZV>4#-rX^Buu`3 z%^yFkFB{twZ#@NRV0S+CPki^%7+m#kmCvZkn=5hCJRVWXP+#t;If1{RC7U zIhbq%9=?D%N_!`4rChRe^{IcDwc91dsK{`>H183d2oH}*C00G_E{Sp#X2v{bJ0O{S!B>lv{9w957%Je0g7G!W?~(0b?%mZ^&dC=&dePaqeSR?% zaElduS;wSIO8x%00?=Q8&R|wMdD9<&ruS>tR;%0= zf#bqMSNq(TVRmtu=C0T~o+ei~p46gnnEVV*)ImInybc7cq*|xA@3rwmVIC_5x9>L? z*X4?vgiVCAPCP`HsgP)^hgOz{MgOn56c(awMvn@#V&sOly^`=6(>8^QJ|N;oBg@S| zl+IpLK8frSt{}8Bqmx9&ED5I&_8 zDR;q#Xtez6Ya2jBSDM%H>d~j5Mja9ulm6zl75ajj+Qtj(b@7vaIr1C{rgbR|fqn85}qLw@82IFfMUGC=xo1(OauwUWJ z3*P&^yFwIbtrhTq#(=QJ86{_IQ%+dCOUjbDghhNP*2=;fBDmouoS)gENRdt@!!q>5 zb%^bqYL2dYG2Tomws9Tp9)zG^($DdPPma41NmZfsQP1MI+$5N*nWGm{yY}gxCQzyZ zE&7`bdip*$KIvNtsSl8l^2quAR|%=aUVm&{9B^=Y$g%HqiC%vU2Gy8;rgyU30NG@u z80|g`Oc`I-@_lD5#4OE>YLGnWz^e7}&^p7ThxJbRiK5nUO1F@BbWF__mYt;rwOqOe z8tpuWk~DrO`q!yvD!!pU>s^9!5vL~MZ0?h;g0)V#jqr6O=gygSf~H8m$xKV=h*NlA zqIIZ!(>JjA{37zV^K|4d=c&ULS}{@XQK$bSc5XF>8}jgUggNka(aBf5@(dk+bw@O9 zTQd)2&6=ZqGwbS(p4Hj8nn>W3wWIN8_vfwdsL>YqjEYtbb#Z+(ZPSNOF3%n1B!y#t z5dVmAO%>VVx{**Zi~yNX6GG)HKly+T^s8VhToGu2 zirUl>WWx;y6fy-BI0S6=-`$)6Y0l=Y%Ke-cH1Fy^oG1&c(tkt8lBDzy!)KrLaTqB; z^D~0o&C1aeXPA$mDLw5hT~wnQKz3z()#zwpEg+Z!P&ip}hPSR*-038{wGeO=OmSy4 zuEk;Ljm+Z($Vy?`8h*Rv;4b(G6tHZj&ZirfXaBB)%1_MkK*$=}p?sihQ-UW8~U~WsyBKb7A(6d-$j@hcr#lcBuI7`|8C&si>%;{P&1)L%(Y_Tr$fa z`}MqX$BT~re&q~0z@QVRMZvC?-kYmP0H;~+G zEF!CE{J+j+OwyZ~X}E<9E@l&0^$L0Ab~B&W?Gx zGTm7Mxfp&oaYvr3t??Z@b1G5|+2m)sai=jG7Dl5SFORINY#%Kf;Z^qF`&HeG?JNs_ z%qy|y>^~Igpz1i5kC$4RXR6bM;Ja2@$tA-B@cFb ztttLdl1ea5rcd~UMEyb@Pjh0Y!?Q4Z`qj7sphYR=xmvSfMBjCTVZ=PmXXrKK*WpKZhQVV=4TD zD3|Pi$~)ypeyn_uhsF`pwejAg>LP6t_es!oOJ)wDxr38Kl+(hbD{`1G3fl4g(9%B7 z5oydOFinp-x_Y_pf`|)@t%5;P&ZE&d?T%kH+ui)?S3BNB_)u-}2pj?o`Z2C6@VQsXM{-?dQH^D2X?swcCE0zn^CVOw53L4DnI7E|nb1U-Vpg&y;3FR)^ zuvnBQZj09>Pt(GmQ&QjkXE*s+mvGbpA@{WMve#mWxf?p*T3G~L$g>4j(3IWua!DYc zcN|K`-eA1>sv>50B6H)j{Ou_zf;R&hVKNyPY9Z6Iwtop;+V!@20+8i^vDdZorL1bb zo5eAAg0$~=gISf4p9lB}XWti{^nzA_>y$aLo@mrJ>>Xy+1B5gvQz167j4Taqu8DUT zynSglhLrT%8XdwYqN$m=<`PNyZDc_8pjG(z_*y*c#}S3u&56L}pBaMP#l);I5jT zhCG9G^w#e|)U%M!!TKR6Vfq+sZ(g2%&gR=%m#y z*(otJ+6QWndJ~(|870Lxc1+`3N@`F#t*OX@8Vx{nxFeHmcN%B{62&v^FiZ&=aPSwN zQ&4MbQq?U=R!`x%RlL94eOfy7iRsLYEV)A$){3imQ`J|w7a)@|`sqU=N>NsQ+P+7E*f7`b;AV<9vhZc(0(k(!N%0zUx| zCW@>t)CaWj^arT-27)P)3kYTA+4v4n0@{3#(P!^J=~6Mw^@;HRZR^p+I*%x8oa*2OsIbBPcO**nnb1AoP?N|w)xen*|C}-D zi}%P?)c97a8@AC5=qf}3i$qc)j6UB80NhC#&Hjn*XIZqi>XPG&>s;q2)$B685!u*A z?d0DGzVb|RPD_YOxmsqlg8^RbS!c1U+uPy6KM(q(K`*t30cd?Dl}betz%hMVN9%2h zPS2DxSP3m+A2P0VsF!kGcDU=BaDGrpC5WjdEqZV9+=62{6WB-kuB+yLPigp}jYp?h zBg*uH?;{;Lo0a8X9()SzFPSCCg?I+&1tJPnhiT` zjD~V>`?K4ljQ(W&in_6=Dx02WHg5k|DsWjoX3HCNSu>e6*0^u%o`CxUi>^1wkenx; zVi;D?(7DuQ>Vs<1)3ux53JbPH^Js8=BFfAd(VQ8BS00aVw7H9MU5R7GzH>S8XxwIM zzxm2hu~HJxj!h&ER?cP#|CZ$zPTGhSc}Bh7~}sg?YGY>5Pc;IGhRe@o+YCD#Ya_J zm&4A)SHz(g2SoFY+OosU;N%M*}t5u`#nJmN{HgIJk;xT;}fIbuyqVB zwFc0>T17v?93^uS4fb89$PwXu)a5u?iH&0m$ReP86yTnjft)y}h4RG1Jci#zDLd`6 zi7^bbh~Jd&H)hjWZH?q-H0OojG<%m)QL5vLcd?A>G%6ScG-mfX471Dq5#4*DNJ|rj zQ=_{lBA$oY+`DSnXlsAEAja0F6OJzTl4NQxz2tr+`)(PPCC_MBEXt@wb%&ra=X`ZA zzkL62X`zUt=u|GJTyBR>IMf07?hQm(FM`aV>9Cj#nT~3t=q!S-6YIj&7X9uGO?$olgN6@?mJhyZB$;QfZOOK z0<)BV8<)j*Gf=U0olZGOzW~fn-?sr(cp7o%r)8Gt>&gzWYI&30^U3JoqZJDzc7pGn zN#hI=G9>nx{t|-X241Da(Rg;!y9%P|a4M$tHy9{rhnO)=C_`}stPEW`cplq%o`qW{ z&_=t^J>87gZh{H3rEQokmR%pvY_7tgF!6t9cxDjiz0UUG>MaoiM(}F*57@ z-DRnP9EIYNugSik5U^-mRnlkG3YN?4Ve0idHg*&=VF&|DZX*8fsmSJ!ma^!A3`)me z$N}E$r&e?-90~GWvIb1N!&HIgA+42~V7Q$4d!kr!v3eopE1D~1o}+!L zln!vIYzhyUv*0iMaU=8S5FEZbF}9>uwF=OfTZFthdiOLp8Fikh0mttfw%MI2x-`~H zVhGv&C}l@a$C4nY)SOGL)y5hpsG?DP4OU5vKg3^6DkL|*2dE$Mw@?t{v36eX_!dqB zj4-D}(v@|5Fmep4MzC>Aa*)0FrJ3TLN8^&D=raNF__EcJP(m~3FK_K7s+{W!86(>X z(UPlr$yKDAm>kc)HFi*;R2;l580?4d4#hn(w-ibIr2HxrHG1b0H8O)&fs~50jU1#z zd-4m!iE|{Dj5^Axb%%YoIgejuUf7a%oxUYv=0nr+oXi7uzU5>`E>w(1Gn8uy>4<5n z0bI8k`1GL-ExU9GCv#iqIQ zP0J6P^-dfl-lU`L)x(^c8ZW8f5&IAkX^f`(`r>bNU2SEJkx_7i^F5GXofQ>;A#}kI z)#&-(LMg+B9Fs(T3C@pl=!}ed;GhJ(pqGTN!CxCuJ6}D52OunfF@RaOv%cLZ5Y8b! z-8+HI81g zf|x|qcLpjQAZR%{^@f-43kp&n09S!-Yb!e6;bQ#|f>oJ3HUu(e}&Ayr56L><2lj zaXOu}N9ZIggWoRPDqa?2q5S2aE;WYNq*CEo@P?g+i{J>(NX{@8WHo9Kg95Ir84N%v zm(S@%$x6>M1fZ1MlPX8=wU0?kd2OAE9DuMSF0tA@0U=U|4YaPLwJM z{s$HIpL6|y4wkRr5f7U6lI+p)+e8bJ)b18~^I;jSyt=pgvhNPyC2 z0dGlh?RK!jf`CaP0wo1EKX|C(aog?>jb*DDV(U497X%M>-Ii<$HZZA`4%GJD!1oov z#wk${UgqCvYT)I-*~SdEH7sZ{)U=<~<0 z)+2+4?#K+|V8iSt)$$KGSBqn9j)0R#C|%=ug1|Ye-|yl9!wZF?Kmp8kzXiMDMKMsp zzANY0@?;>Sld1%EmO^s>6ajfS+Gw%K#rhY3ruy6gbyL~|VLlaEMMzB;5t+G{S2BaH zG4K{=?OyH02hg71;-!_ef3c+_=6-(Z44v%f%ajN%(?PE;8=IX;<-He3p#l8afe=oD z6ncGY4YbhRS5SlivXcPiwuVz4fcg>$nLt{Pn02cq?EganYj9$>>iPbZKMMi93@6BB zZ%JH)$_8w{8;c%%Qqulwz~e2}35?00O%TEABK`#;b>;+T^_E3N`~<;Wc7kE=K(X`z z{9W+j@u5O5_(cRY33AcD2T=aM+eja<1A#YUtU8Fx*HX;>lBM1vsNH}WTsj<+7r8|& z{*w0m19AKpzVv@TsM|#PpHc9L+1y}aOdLLbSQSyOFk<=`ObBsK{;!m-e~}kp1Fsa> z1?mw*Y+#6`>>mug%_Kt6*Q6xIks=(=srxxPci=Fl5PDO4I>k3q!tR znAQ#mea8ix1S@X2$;#8d2N%p5$nW-k+6aWVy+Ta1XEa7k5a0dkxrBL~qHSKYTJ@Gl z>35DOmsM2aS-;T_SEj8TzGa*`W+T5ZQ<@5c4gwGr>{Qp%8utm;#$qa-WV~$FI_A!P zFoDxrMRjNT*7gg?XJTXlo4|U}gO&c1Y73-Rd~R0-w*SdM!4ECAo7n3C{I$xP55_L0(w!%zB|{x*#p9r4(iQ1sFg!1g2Qq zXFf_2W?^9ggCO7GSl>Yu%#vKzig;wJ#>HDQ0rtvy1GB}J6?D%r*F|^o0BwC5QMx}wz!r}GGd`8`a&-B@O zA8FtDrOpN6N-#)iTCmkR5_+5e4)!?tCrhX0WYbjMSHeP(uZ;;gpr-*39W&Av#gPZ^ zdEYd7h&c~AT$3moqneYq-BxS7oj4-`L5vNq>xUn)X@1C#tBW+fM|F=@G=+CBsVPjy z-Dnp;5{lEqnuQ;S$~|plsy<_+7P!moRvJQ{$JwrTvHW>bRn9cfTYL5pNUg#7iw zm;MNf{2#(p1EyPHDz@dpi3pl0+z9;?`$8i3;Fj4kHt8zGPC?mPl&{LDV^by~uP2|L zefdm#QmM;TNE^B<7ptMFAf1ISR_(}TWsLlIniY4wQl$5RT`~~(K07hN3TFD++#vzV zpLlimkZ%2{5c2=W6Y%_%oVMa8Z^u>HMM2Xa5uHwW~^N4 zO)d4ZQqxg$VO*w~=6;y2x#rXRetP-BHy$2tp8NdIeSYWs^~PBH@qAq;{o2UawKYw^ z_%eMOw`XLPs`q(eZq6ZwPVd;cQj@mlc9;+8BRF2^uL1UwR-iMFU1Pfyu_dHM_N6J! zMP0rW6(90xdTXTGWfujV2hEL7QLE2%0GjUX5nNrj&ehZLy+j(-B#Q`F@q7YcjI2xf zoYPeEkQR7K@d*$CJmd@v6O68af5OO~W&xdH$s}MXKCA-2c|l)NQ3!!n%KloRYPWZb5=1Ezc*49c`W*FPe4T@jT@k zv6qm2=(=S(Hfac&O$Y^{87UlVRm0#!Kc*D5!aK55uJ6}d2|NUeQ=TUx%CuF_a3CDn zWYANc-B$zY3j$!;YC={C^M4QGwkD4f90C0uKD25)@ zz$mALwGUL*hE{dTs4{s%9WMI?T)II8reAPD0j5;XV%zJ_srpL9ixF^b_S#Krz71?& zrbiKnPkS^{spoDCn2_(jEk#Xu6`$l&KnA^W8+BCSSF<4ea{DcwVGJWhzDnel_-I_O zwee-%zNm*8AMD<-WCEN)IL^mxH{JUdniT z^O`F}I1irfCLp+t8nq^ob-2xZ^#Km*;EuK`9^L$0yQpE<mQI=T=h3VN!^Xji^72?ZP|&Cn zt0FTG(tcqW_3%osJU&>6@W{;(+zkM1@e~qx-;rNh+R(aQfmJhz+9h?#$6FZhgMJ-h z1xIp)BqA!}RbS?6_pvZiGtWUWi{&vbtsi)lR@2*A%QR!*usMYc~=tAZw@tBLb< z{B(<}<54d#H^%WwTTXgq;JEz{eYrZnk@LN>pLQpB%**azROd#U2-ES?p6D7L2Rs9<4MAifg{~=W{bbfi#%EvlDQe5FsNx$gz}n zem?nx$mv(yM&spJ>JaR88?(r!R_LhAYT=(sVKUvbft>_Fadwwb*Tm2c<2b4|liS)E{eNg$*di|fC zsm$mSR4j#72J`GtSEhIdn8h9mwGA`oSSC~3LSrG85z15nSH6#y8o%XCYUHy02zNiI zE>D^`wT*)UooK-n$$=-}h;d(2RpXxKngk_}`zt$eawNechr>?-0}AqdCh5xYwQ!E%*AkDVZtHMA1HxZtpsT^=eN?Mq zm)6DyHsM4b$1BO z^M%^uq|p2m$dSR9p)){#M~jmH86N~#BCMB(Z{6X7H_rNJdV3BFLSl3DCLQOzu<>J9<~s2YJh zWbx0+$`O)i665p#;y4ktcn6qc7t4a2>OF8q+31s)B3IWmX@1KxBzJBN8UvwUESwFN u3f#=7I)uso9V!1;mi2%7fE!2bHor>y@@6d#)eZ__;6-+Jb9(6Df9Wq<%6%CC literal 0 HcmV?d00001 diff --git a/spring-security-refresh-token-jwt-spring-boot-flow.png b/spring-security-refresh-token-jwt-spring-boot-flow.png new file mode 100644 index 0000000000000000000000000000000000000000..aee0b9dc9cfb7fab6f158c0c71623356ed61a0e2 GIT binary patch literal 38031 zcmce;XH-*N*Djm{0!Zj3bVDx^n$kN+Q>n_WL|Q-)kd9O-38D9TOP8jCjS_kfMd?jZ zKzbFW_YP-sKhN`?@4REY;~VGC`9U%uBYUqs*IIMVt1O}n^|dL2L+Orm`HDZ6dx1d`|@q*ezqrG%56d3*0C z`{#81_;}~x{GIt$e4z84hifzfFGE%FZoIEZSjFiKg4O1SRbfx=tbieVkW6hJ3raGY zezq##N>+Ofp8RUQDNN4gMnb=G(fbee9}GqpE=~Qv|2&(IJ9{z|cnx*afdj8JZCohMP~guI|92l6i3FT&cXDuWFo{{5eJ>4K(uLxJ znd3RhmUNG|hqVz^H8qya0d+&c>XE5JZ;`T>7h;wwz8BhJ*Xx4js|^yIj#R=+T9&7) zZUnje-;HdZO=~$@>h_r)ukqRR-)#D&8-|SyTJFnekD$tt_j=E16&$=-UCFNEy|yx3 zn8+~j*u|{k?86PYo>HaDsu{oE@vD|Cn+Km%&i!`39AftKC)^7r1>=!p;{n?x^+YWf zL*bXZttXtc?~gvOi*cRc4refzBi$)k(k_i|bGTcKZ4ro|v9p5-|HBO>{{tsA*Ap)7 zX$P0-8rPYI&1Tc)M=%_+IQh-lpySKSevHX>9H!z7GhM%(r1xvuqro7RTIp}-ubE3e z;#SPjFo`)^S5a*fzlNpT#-v;qZq&k`()DmKSB2UgjUb(!Qpps@9UL4aD4%rIR901~ z-6v3?$^uWl$A(X*{Ws0)J+Hl*o&OxOXTt>HM&fR@W!$n8cYE}NXa2}rQUrn{GC|^k zE&4PuK@{M!>yi!{IbW!ik3hl_cEqHfx7|A2X&W?=m+w5yFV0~^mm6`JHKNiDIf6aG z*Sm3})UPh%tk^Ddh}EV)uge0F_~A37^kT8=;{240%5du-=g~e`1j#1tr25oZ?)ev_ zHWeah^;3;F`@RSzC5s*2;!Os7n>Q+~2< zQC-GCjY0Mp-WG-=^F14r=z}b@hL9$;O-1wQp|{I@KeBLx9Hw#EvOxiz@f_mTT9Sur z(|QU8&XcuCUJOpDh-xEa z8h>W{C3jb|T${&7Mmj1VTUrh>#Kbmut^V+t_9K1AiehK9hc*ssRfkVhJ5N038H(ZR z>L_-aY3BHSw)gv+Zhd5by3QBoNcn(i--S4O0ew{jnv4OoPMVeJz5eq%MZrBX6GDa# z4s9`Z_5o^g>wEVPndv;tw_u_~jxyCr0(RW0L-ivuAs*`bv-0=R_Cj%?YKQ7c-q+ga z0#EJ6HfZnp-hifB`d>Iok>7Dn^rFqv*eMH^3|M1BZ zp6R??C4YFg$3i%zK;d4U$5IcEc06ZQVZ6+w&Uc+|U;nt}4f6)H)_X0gFK)cPi%-d5 zd)!p)c>+UWHTz6Ie=^f22-47RHlMmID|fCmDNL{A$_27Mw%Y&m9SF0+@qofsD_h{7 zWMEUN37a(sjEl(3hfpi4GQB36e*!kV0qo@tYZ_-@Cf&lJc+QIV^a6sM7J>VJbuqb^ z-@Z+hUB_th+D2{W<>h)^%ilKzVf8#P3l(3B(QEaOCa*Jad-=w3xXvU=CG8wX5mrlE z^igPNCc#5|W_)wJg7jMYA=}P8_^ZhD%xzNfF2~ZQaHlw-qoBauw|Y9qI+t!CE(DY2 z{LY4e%LS6u90eb4s;|=QiKlhqB`<5&n*DAq5Rr$;%mk$Ph;hsE2G1L{3_Yi$xUgN@X z)8%Q`y9dn4QGS0$q82)7=~2g1E18&ufgBpjM3~NmZ(+jg__|uU=B$~oLxjryI>SyN zN=Ri%uoQ7YJ`7GAO!PGL^{f|EBRq$$)pGHzURIt_t#G||;+%2)ql@*OmhT*qeEO~U zSs-cEca}|jUf1BdAF;XS;{+u130EFxQ)#8=Cz4+kU8(YrM@wRuZrIM54fr>^U%kj( zg3dI1uPMyW4}CkZ2|<4?>;7!jsD%RD++20M(cyuqDVq(Lx9ebiLP$*zmVPSYy!-x3 zmj6Ls+IGGsGa{2njT1&=b9r%IRG7f)i{M_{S`>hu)!J-MH>GoU_1TUp{xi~P<9hRp zjX2gC1I;`4(~+_-4u}E+hEnDa3TfVj=wALXb>;HGZ$XstH}5yI7#(a*M1=NJU!dYS zlzxtkgwAE$J8$sj^5a3Y$IF~EuVO^Y_Tyyo7>}y2M`dW~hA!&aJ%b5%O-6 zONH39=ITzd@YY#~eEZQLRzBjQ6t|3sb;9yT_TpZpB9x!gxbwn7Y0T;FIhix5AP%jz z(^?y+o!=QrqPEr^m154D?OURgf#7WYUV#KXvmI5)K#0!-tf`~5=U&Y3tK`(D6cQ$W ziSevvQG2NHettuJ>+p6fDR)RFA#ZkNeV(6QJ(bPMy0=iWDmRuo+uH`ZBUwsJv#LI| z)-@SKJ`=D3g83Vj8#RK^WBb>Hn~?-n$xks4XlCMZZ&z2&Cb`m!Bhn;-96#5Xa~fF# zA-aFT$iwTQEB|c2oDko(-?7>VYsHdb4aE_;KR*@m0nc(wZ&RfR>pWpei<(K6x$)zk z-MyM%q-xGM2YiH9U`x$4@h9qxm|B)5>`BIs(b?a5);%Gxw`>tZ)9qJ@Nu+|+=ml^i z9L4Aa)b&up;Q|kORjjJJRjpwmJxfZH6!W3QW0w8T*{mvpn~ZCRx9iz4(^GfC>j9)= zQ;>!BXAke8Fy3`b64jqiB^5K3Ob4Xx7(~PMDE3O_$2?ofjgacJwqSDgD7x34w%}4Y zXAG$~14ij#=S1L-zyOpg#*+N1`P<>uaR`II{)^;Vvgod7J|5(??4ZILu(sZ88GyoC z=Of8rk8pQrZ$&Rc^=ZJAA!)&{iXgTeLYD^pw9Zl7 zslBfi1?LVGRKcY_v@bv7=z^#m7JgMiq0>VwJ-Q(L{_reO6RzkIxH01!VOV0(u^i5T z3I)PU8?DeEXGckLZ5nZXMb9LX;D4B`Sh#pR81klq8N#tGB}R< zoCb}2TH(f*9%kNpS65;vu6HYKWEW>xKr93d6Q|p9JQg;oVz)R-DmvykqrvHp=z-Lh zcbifYD);*<_nys}{j+@>jv08L$c%jh_u&JGn?3WUGLO3;se*lseVycQ-2!PZ7@~wV z@?VGtaDZxR%l*ULHQpJ0#pmt(d*kXjOo=iO2bWKL9wl`;$%Uo*&c!pn3Aa&u|9Sl` zmqs1!>q?ij`5xSl6#<&Fx21G<8{Imi@88CAexLV#LsKwGcK>nBJ$G9*x2l#{QO3Ml z%^14>?}wRp2V*8G3OW*zI#spiLZN~(xYV~_cjpg23QF+8?u)oQBIoLf<9zdOud!B1 z_%1~^&N${@8AZq8hLV`eVD$fs%L%H&BVTQ~+=E3sl5zDUo>Vz1$ltu2&{5LBU|8cHk^!n5+tHj0cs80#VsdZKWoz#cfsNKzWa?x^+tE^qGo+$bK zx};
flb9piFqG~Fmq;7d@uDz^5OMrRlY$u!>lu&ZsEzmXDHB*vA`t2cy_~j&?
zGd&WmlYfKwf_aHm-FM~XZ6it@`0I{~CVwL{9uZDh`hL=K(&%=iJpMFKEu9OJ0{s(Y^NQ5;_fnZ~8K%Gr+u`dw$0#{owmbEy6Y~2|cFuuqn+K~@8<#=Es$uJ@WGdwdQcAPb_
z$Q38WXdRg_#rbx~JCwh(TKtPt*QV*jR~^(1`DdUSYWUg7_`gW)F43ofxf5qo2CipX
zDvBG-0Yu0$g@m)RSSl%?Ug?}&{0%~@2S1`(`68Mu2n$G*%Fs?S6rxSfa?s#gUzlF
zEYmW(dg=6BX2#FCouj2;`@k}SzxYzCC9dZ1HuTNhhRWnl(_psQtxi85=uP=sN~$Lj
zd=W@a22$pgpX0XR`~1m#F}A3OW4(K80>(4oCTT?sil9gt;BTm{8WZw6ee=A7I^qat
zW%D_I?Xrmc+bmCix?x9065((`TNaNw+YltzFe(~khqT_
zPIxSeB`W0_v)7_N>#$_u8&l6?*ZFhFK1E7W75)b|!_yhCe4;QKa$5U6tNS$;mRig~
z_`}iLg#fHBAWuTB_-{2MUIdwac%IfV(>Q~|uOlk{b#qNeTh3pISr
zPV2kdTXOhW?ck}Nx2~5(XPc^P&K@@QmpMMP+ogy_64-7jeC1OMjXEzkDv{3l*I;37
zIH{!Cd?#rlWPqm#Nf;BEIgQ<=SKs4rU}N*@&Hra_Km<~6>*uK8M7p!{Z^liMVF;Oy9C`k}@v&DJx7#1GIH~0Zc
z>0{pe-#$(petv1Dri|y@UF{lfB8%EfaHBM$__Mm|x*NpKIx;dsta8A4gYG};qCrGt
z+m+jC<4;liZvA67{~sTq5!8s6{DSiCC{P~7S`Clp8(iVo_t0W9Af(Cbhk>Gf+mF&3
zZCYhcxTuIoc=^SLZ(sF1jIlOqmR~1kG<0;)=ck7?y;H@zoe6Vaa+RuQ2rL;_!;0xYcdUdzJ@7-{7iobzXZ=^O*Vce;)N^~!=nwDi76_EqB
zawn3XX|nAyIqcMCW;*)=83a;NhV<}>jG=<
z%KBWYB<-ZjbVCP8oY_i|?y`Tpb!9BP%K*;1JPPXQkT)-U07rwX9WI{H((9RK%`94r
zN4J*)*Lc;7(sYX$G{F5fUoTr{-msq`d6TkYJ=
ztc=yc83y%)ax_Ig`OVTUr^!!kmj-2@7vrR@cb8YZ&y5DhQpEJ%JG&DsRd)^K6{}AC
z1N;Z;#r&H(#+m2KPoz<-Tj@_^0q(!jav~Iwt=xD#;0QYx1YekLoCL;t86}f>$XSIG
z>G%hv_4VCNf1MF^?VB4-k3mLRVVV|IaG2azgO|%Bv+dC;QuMddIxTRY(Ui>kHR!OF
zd2$I_5zcAetwkieizCrW!7UDKOB|t^N(=KS@oG&O%O^t%Sb+{CiX9KCTt~&QBX}<+
zZFh5860S03x}kZYZlu5zevG^u2W;nm??_WPsBv=!$k0uX!6FFtJI0
zMR97X;Z?8Rsk$M+tGevf&g2%G$KY;gEO7yuZKB5IyI2vq(aEgr)YRAt>!XSnOFj42
z*Gsm$1==I1OW(cAkam9T?7aS=w7LFCCsm+q;+1ij7kE^;qRR7TdyL)Ex4QilKr)Hn^{jR|PPXjhY#Ihi$7tNjM!ifu3J?tlsOx
zE`7mAAi~$WaN%)m=ilO@qwm%+M2Cpl27}$jz1PP4c9*NFtL0s}dWgGmsfkEKBcauu
z`JE-PrX%ZDcx)`I)U%FAT1rYv7c9-vRquDdrTu$k5-DUpg
zD{bA&%c4*7r@sbrD(nWYs{|>&
z#?nJ+?bT&u1-S0g0naLV?*)dA=OGtCIuJ
zmk8y6F{!)BnVFf6C3PeX167(5SFIz?JUWM>(9ulqP8aUW7cC@ht+z%&dBE@>%Qd47
zh8r-#y9Y%8(R|BgQnmd$2$$3ECwr&G84ClfCN`FCaer
zobK>hwZI$RWKm12Ryz8)r5K>bFX_wJfZu)ikR@(~`vy(AY0?tZw7M!9DQ7>#na$Op
zyL*AEG{NT??x>`sUF^qtXyEf0fC(s={9TO%87S?i3K0dR4oy!Ph6=n849U!7eLSS0
zUnT!QcCY}eC%bh+30oE!P@3%o78zl83lEbBL};ikSJ%z1$rsEq2oo2g-QxzN&>tNI
z99TmsW7DZ5K2aH#?~mPdvUvW*Q*u5@fp{o_>Y|6`<%Dg%(>vxaE&|R?hkL7hw)(op
zTj&su%;{@qxSPCjtuVT#zt0IHS=!=T@4jvJs^yo%>(8X-CEilqKT^vD#;SNA3(<_i
zBoxfpr!7I}wGYVtOpca48Qdw-ItF(Tf{BKEMdc5<0F5D40SFzahoG#-tn^~<&-V}J
z+H>OO`MBNJe6e{0BaoFlvjhs8fj&N?Uw<3v%IQj%<^4W{u-OVng&0LSmes3N(I$j{
ztF?VN0=^L$yFWzMM>X3AZSRDG>@=2XWYceze?o^fxm9qP6vf%P(R^&}%>9XDt_JBp
zL&K2-sm3}(HA(M$oIT-7TZEVBG*GDWZ(Vng!TpZiy0$`JYd`ywwmHdkHKc?3w9KmA
ztbtyK6!S4DYODyr#zq?>rREd#DA4jij>5AM!5)aByyM)gXM%BSy)9Dl@k`AqgL@xA
zD)d7GudT%)v2et5ly`YL8Qmf8#c%oM@JWGRd3Vm@sy@%s4otdXqYBVeCj@({i}`b@
zC&H8I_Rl6nXB+Zy{5P6a@+9I_q`r74xp}uYG8SC-v&9Nz9uT+YI)35#1M(83Zf6N5
zL>gVp2P1kc6R1h+wFIsWs-2+gGR{5sVQn(_cuIR`=g-mp0M^S$+7Na=I(q|#NiF&A-!vZA)GtL%)e~KI)5xUX|
zHxm&lzf6q-3?K^hCiARkn*8&nFVP1_)@1YF5RCeNhbDe3lt;s$xn1J1(3|N}j_~RXEtNx3f{Qu3
za45~2b|Bp!8?}vHu~-mZ)Q|^iU``q#ECo<
z@^P0U_HAzP(4q72%7rSl}
zAo|5S%!-I8`P1)jrIsp4cLEkX8RP`=X_^uicbiqkj2@jzHdmFE^;U(^6iCX}Jo*0W
zolnb7j*8jgrwRoTgAm(U?zNFS+mWxu3Lk
zMvPJ;``Jbwj_sGM&z;(-r;$WtX1?&PNTw-pbr`FBC*VUS)gtTMdwA;Fy!$g;A;@Q8
zy@g88@DjLz>t+P`-S#O=?UH}4T;0?7-I9mtup|C5Bmo!f=z0GH4^m)>@r?T*l;2Tj
z{h9pU?)l07LSWe1GiPTGNqd@7LDjVJ=OBeY7knH+OteJfuT6!p^gZ2erEqetyAduJ
zwe9~AP=@K`(A~}cJMNz(erTgM@v16ov(bB(qlGOJ0G{*cUZ2v>f-)A7o=HH728vow
zj!PG$aZ@{y;|g8C;X
zhV|h73xW-{IGr3|zH&rz2Lk;8#4g1p;0D0*2$7%gLjatm6mC~j>UljkV5c|6F2q7O
zBa5Q>kmZ-ai;VX28HV?dulksRqwI@wmmK9~?7Gr!gW%&}Sd9U+p
zt~l9hS(eJ=R-^^?og7Wx9TXZIGPSxXEUVxsP*V6j6_G&&YIT@%GnQo=!_7a1G-IV-@sj|DgRl{?xdZV207)6w_c|3vH5eag0D^Xvc0b{
z&BY$%C!fCd&zx7D)LZJ63x=1#fkjnUTB*VPy4u9!D0V<@5}_P1}D6CbNDii2X28Qg-(Q;J!32W;Bjg
z+NmGcD2__*o=$9@I}r^ahpBU&5sILfKSTx#M~@kaE|ht)GxVUQQT%8`(zWuam9W85EkEHhnQ)IG
zs&jUgQtZj-0rH?t>+`;5`jl#X5faUD{7MFHl5&Ej;><##pYAUdx@fz2x|zwz&vr+*
zcuAg|f?v+MsWP$Cz|&c0kdx~F%V^EQ|Gzlzl65@26a;U^MGm_f8{pMnK{?}LQYg!-G^NH<@4}Oj!D+B(i=4bW+JnW3KwgqV%Hi&
zx4v5E92IVP%nSEmj`Qg-8ONNRS;$!>Vx8m4vMBB6AUS0XP&(`C9JfT(ryoDG0ASbR
z^;9FQ
z`xALyCyQrj>Zh*;Uz<--_L##PebBu>Fc+>_n`cd1jWohpE$0)am@Uh>O|7S-rJDXi
z6G@;o=r1;-D20V#3=YYeAi)}Uw92fFqpT^UQkJH@vllEOn+SU0&=K76WH7hQ5)^B~
zd&3j0M9SQ&S53Z3u~M2*YDyw$Cp$(J%;zrbv<>Oi~E*whE_ngU(#`sSo*gEn0PGMxW
z_sFr-FY0og-w_YXPHu(d38zyXo$}fy%ZPE5t(H5UH9crud?Zeva1K>$;cZPqTxY;^;na!UUvD
zj+vR+nX=U=r&b!$koCRc4?4?<=zRaEwg0+qu)Xh|HrUjz^1&2C5V2^;P$UGvpD>W(xD`)-OoN4RrmtmC9GWT8i{GvMq~A#J~XV!NeyE6sK7y~?r+
zhAk_mfHf1CJ||%rmrzGL;qbKcu07ZcPiBT|5Zc2JYPyrq2KBMr%G5YYkj*gBDd9Gbtuz^j#z;87dPuxViikvQf
zU^+~g_^vhTuJeVZnV*%l4iG=Ac~k}j?hHHj;UhEib=}q{-G46TI(SGEe0y;16a<%;
z?Q$sk`H|VFmMN(ItWdsLylu(-qq9)9bBc3b%XO97@erZf?-zpT)yg_7qBU08>@^~S
z_*OK7pbi|UjnBUMC^NEGAXoYWv-1D$_p!)Y_ko3Cx@JwbsQrfN?;61=*ra29;k)(Yis|`}cC-?#5;8D^nGrb^)S}Xpe{HF}GjTZDD57os9Bt)C
zhEDiQ&Bp9pGh2(_i=FzsK$-B7MujuLL;_+5kx>>(@0zFIl|k_66o-p|CaiDwMRL6q
z65;>$USuM|{38z;Q;7D4;K9v2%vUv&4-@i6<)13Ze%y1)aTE8q4h3Pf+6$sau>686
zry8cshZ#qFs+R&(aUBX2;?;8-1`5=)A=<_H?fE9D*~l`xOnH#&cE*L@myT{)uU8v#
z>`fU~MyzF`_4})%33^(QxhD65d0^Ma_Ht&f>5~fjT`2xp-aH#W)4
zRb4Y4s*=@Z3W9$C9%J&K$B6m7m|_nQkIH|C8azleq%;Lh);^tyDN)|-foAGXqI^@@8aE_6i7PU;!^MLdhS*Q7#;d-e^fYlif(B6TD1dxA`
zZjtT(Ovf#9S0COH*Br+3x#h9A)0lX@rs&36RE6{(@0WJO#l+J0BI2uWWi_9hw$_0@
zU-}s{_%7Ek9(|h8U?*8K#UV{_oPX~y-UsWzQ=tI&&2YWU?_XS;`fHtxZV2ynV>k5<
zp0A3M!BY}6b&JVRZ2#A}J>lJ*<3C^wsfhUF@xApKt*dJt@sD}?zY7lgd+jGVGy((=
z#BBj?CtJ%3r6MaX)-OeT&XvE^3j&wz?uML7gv{O!1ryzD%fNANFSpto{_eqbDE#f6
zaI~3aT@>Q`TOA%yh?p18qbWF)9se|Q!+D|tE~kvK1r7H5TqtYRZL7b&cc%-27|R$T
zItn3HV=~4q1wFp|5DwtZQ72XuHgb20(RP<3w?~BPCT=#~V4Yb}b@ZAB;%i#QS5XS)v!j-(Dn^zZCK3Vw%rn-&
zYmz4;nlfRZTk@E@aLr9MoJMe<19c_+1r;_X;;rFV9Y0&2@h(x1v?!dwV*vuS2mYyw@R7y^v6K)fSs?l*!P~Z;-ZX
zSo3>=w#h0QN3EFs3jb;ko7RNc?ETDEnN#QUqRX}`9iUJUkNs%T^x{h_i-F>HN2SA5
zog&uE6Cut%pSLvlOr;U8%_NqGrvlVC
zfeMgbPA5j%Ak*J$NXGaf;^yM6<(YNW+C<~R`$94mLfMWYj!j+0HzC&6zs0A)o
zQ^d>_3kH~~Spa{54fqd8J1#eUcvYKIcg{^5@pHV=a2th|K=k3rGgsmaddL%ap20BS
zwnXI0y_+g_dzXBdY>-U>ah$~!#B#MgmE%$I*>N>+_=U(d`Ls*hzZgjnJcRBaiCH+OjvRFx;V
z_Or@yXR&*T_&GowDhJkAz}2Zx=s~jT)cL3_mW~Y%=RxaJdd5+vxfT+TMN=OhdpsuQ
zYbC(%bdtpei-$h7XSjEHA)KxJ@!Pk|*uI5G^Ou{b`s~#Fv+vP>o~OLLg(JmDS{jZ6
z$yzS;yffi^GD>^IK|2iUb&^ii#SdFUd^Oa)?S_nQD*A;K1kl2~LY|3k#ZUw*^s`5R
z;!=BxvS94ODcai=b%q;D{mI+@#4#`!^)v
zY(e35WVVvO_u0`lz$1qteb>r6rJcrR<;h!TQk2K!o-W>Mli$|1dIG+&Rj$-0khw4G
zD+k46#njskDm}MuNm{)8csiyQT#sQmx(E^_y%<@;eGb@4XAV8e=Y@H2qJ}zcE^hp8
z$fZgSym&KL;`sdRujE{X3{(=o$aaN;H&wZXG-arD7**ejcLrDw4%2K1!;22UU{;b;
z5)jnvpnb12;yt-2wbwweh3s==9J?bM9U;`Y=-P;Ty&4og;)jC`2zf*1-$i>d`(;*;
zh5kZ*kwM_zhCy196zT~5#azEzM2*;DLgcsH9EsnmZqs(}3F8PB+!sziqJtB0)1x~K
z#CN*tXQ>VNxgJww^;%miv6Erm22^0t&dl>4h#{m|WKU4qVZ$J;@`3%+i^@C*CWZn-
zcrlzI<@jSEL4`^WNFq2|9xb!R^!?d>%7>2r*BatuI-mZ$h0_x!omb)6T9iKVpO|rQ
z-}1mSeY)(CJk#i95=dYrgv5A3WM0g_8DLVeoCB!W+n}R5_71!9M+yOG?J!u3!Jmko
zg-GmHE#vQ$<0nh57f%y6cZJL^%JI3DA`c2Ub4=-*4j!_JC$w$+yk2IimRwC%a{32G
zhs{5;{t5b0VTYVUuR5x=2
zOG_p~yef&{aa(wgi<|c}Q>h27S8J9LKj-_J;>xXfdA9rDt!_Slx{T|zLC{W0Z<<(x
zGS}T}fCQs+hASBKC#`OjSh<|e?xbdK{S}8f8~n$PVdKJY#PIe{-kthXsP0#G9QkuO
zt=2ZtW%IXo&&APpxFYseLDN`UpL@qn9(Oz!7=ZLWW;BPBVEQx68POuQx40wzs7(B+
z*=VH4jotDDzMrb_ju|$t=igF#uzC;C6gTU0d)35Ye2_qKcDN`~S!nAvik+ytGy+c;
z>?t<=q3vNC1bs^)F1}S$R%Z(qfQWy!CfEyi;=$P>teI|G!k`N?Hbqoxp);*WGlr^O
z1ol$YT>i+MKxP6{*&aW=(85e=
zAj7NB70`tX%Cw2su(E!dS;@b>TbvMQYr^j^qa(w=TuTH)>i+scT&*wr%~~i|PgRQ0
z*40ccu=FsUjU3_u2C88+0zr(&3XPM;6$4%&!W^>l0V#2RfK9MU)sok4K5O2?$g8~<
zLH_`x6WtfnJgl0wwme$`LV)m2=|@
zg`*#sn$Uwm-cD7n+i9$8G==w2ZYx87-Jk>x81w^X>XW_S48-UkA5p-mgW^?q!QPdm
z+i0WKp^XR{s$V)Lda(J^dl2DTxB9pktXRvDl21`I-=+YZbyCvyli~Y`=|B=
zzs{DHhg;u3hHpm;10EUIar45|E_VjYM&GNmA{@#AvROK3KrILaD#5FOojXNj-2A%f
zW$p`FCuByMSG-mGTfHm#R0=SfR0OhE4P?s!N+Yv`bq8Q)wi|q<<+;Q}nVE
zYj{<=g0^EUYr*QNipfxi1sDXd7jg9@0jEe}ITXAv&W`mV9kWv;t3N(H2QEnptTOA<
zAD;lXK140Apy0mNQkY$C6~L6@{Yn;tFCJan{r=&RLAtmVAUT(aXpCPm+v7pfjPro_ABjf;
z&n9;;P4MQZR}DfHvbQJkTIOdbJhMv>8Kz^VeMZ$Tekn1<9zzC^yfYKG`5sfRve!T=C2fRz!(7di2hG|!2Nlf=M^8WarLAC
zZiGKytc{AwI&1PwcFhR%vgyVl4
zOvk||Q^36}=$LoyCqUs+a@}CKqVxali1=?K*-=+f;(iYXlD|ol#~T+phJug7GPM5+
z_zAAyf5(&?gL11rov
ztyc76t~dG(H;oRq9M&IaXqVnxgjH2he+tQB;|$fgk_fJhni^?%bmx1X!$9wgAvVX&
zdI)KNYtw*YS;Zb@iU}$T;A{q38Q&ehS{9<
zF?|fILUK)f-e#-m<(X74qhJWf2hVBOf8!g88DFAkHI2z-o`CpQj9dN
zymCJye#`}85;s3p)|iJ6jx<=1uRRpcb_XIB`RXczWIH#@?!DEFI%F;>o!HFA_d+Px
zJ)V4Ot`Y=<8I!9gm`4bgTH-gsK}_3!ARO3fB}W58_Ql%A;)~&7WOPu#IwvX{{U7Jt
zJYXa->wnV2Asix!NEHPf+&J+}nu15eObnX;Ec7V+?3`(u#c_YZ>#tSFT9=E27UNEP
zTQ$8<$Jbp_qbqM-<<}gx&$UOK9&T>3G6F~Xib*_6bfYv-ZkU5CO4LpraN{qJwP07i
zh(sbCbMw1j!Ss}@l3h~CT_UhD<43Ea={Yd6od+9T0HpBf-zlBn-pILSl79}!Mq1A|
z%G1WrM&2t}werLUwF=6EOjTXV3b%;sv?@)VQd^9f8v-_F6aC_O>UF!f+^e$DN)%+-
zLMrq4yyoWSAx=KPC{avuW6@0{5I~jUg|oVGyEm^pZ2om(24|j1fv!HD+56U*yB{J-
zPWFHz>^>5us)sfZJ$o)35^zw4Aikq?NY6@>2K^h@)BkK|ZX>wj&e9vTca4
zIlH59)Q|Ki#K->S{i0g|sI9at?ZS9+Iu$_K`=q{;1Wix%XS+p`MX*3jxE5DHYI9NA
zCadbI1CSV{{ElV39laQ6f-!d16jya@PV%-a>c~TV3S;j6+%TAyBU1ufiHwjMFFmGdK8nrRa`3f?wyTKm@$b_&J
z*9OP{Wx0I;pv!Wq9?MMxxOXwpUEHLVC;0iUq5Qesde5J0y}a(G{!1>WXsvjcd}Swv
zQpu?NwXGJ6nNTL3$cVt?Ez#LPS+|qR>YV%na?0Ydt&Q1G_w?)`4dRhu#<0PT8Yd0p
zW3)gsvdo{%-YO-Hd`0!H27Js#Qk;DvlDys|U!vGe3zHN&_?D74nC-B-PdV_~m$8RBl`%bR;&e)`?E^a-|}W#|hH
z-o5E9b=@ezj#kp|2TAeP+NPcDt&?9TprZ=m?U7At4U=WMP+M+ox0bY3jkHhXU(o%1
zlI&0e4RJeSy8sudIKm(H-g>Jv;<3t2R#p0rtk;ih!9Eb|FiC;6X>fVvsTQaq?DNyd
z?7Q2CM1S0tD`po|c-(HM48)RPNXp5}9?=GvvLTKUV3
z{uLHIG*b~fwB)lwJeH2rAKqZ^&mlr8w57n;*z3I#5lxpK8S@OU87RrN5f-ut0UM25bWTvk01tY~01KHhm@06$V_
zJrIAXhmZ~_mxRC|Wf?C+h8c}PxTA))h=%wf>p`ZnvWt<*qXs5M*(110WXp)h+*NsB
zGBj3vG(ana-HZJOR#BLR64^LF(bP#K2
z0&dmdH4`u1&K5pf;oB{S6I*L)Oa(ee8M>*gI^_hZXz;7md6JL5)vi-7&Q^>@X$sWu
z`~}|%RP>^6Ms96oOndOrnR_Bssopx|#iGU~-OxiMktipPz?3I_BR!wUX=(zg|>G{%fZv6X=CMgR)*
z*0<0O6=NGUCSvepHBxNH3&N$5cGa+ODxnCgVE3cCCxf=Zai2AoRr|rV;*LL%rva@l
z8agRJ(UbLgA2>ZU8Zkyne&BP>$hM0THVlnmKLo6t|FVR?7J%VQNdpr1{XPT-Mq;&t
z1PT6RM_dq9sCgqV8o_;phHK@K2P>lmEs#qDZi}e?+yEQ!)m}bN4oqpjXlt(#4Wm*$
z-cI{-)ve7YlhW8WBfa2?0_O5$LYyBB$
z@);J1chaC6BkV!MR}B~O>q9QwRquJ1{l7Y}`|5{4gDnd5d8xjHwlVLEM#q4iZs3fI
zl42kDuJ)>fz|dNv^D{__`l^jMAv5O3OaZHLv~%kPoWt#4{RL
z?~BJ_(!8yN5!nvd02wtM{eIz+aI&KnG6A3o|ypk=J;z)2mIz
z;i2uNj{<$sK$?`z0xqb3+fZ3`;KjwMUI3*Iikf+cMPB(-*T%|=^m9C(gbMoc!oGs=
zpiF`k;GNQ|_J>V7JJgK?Eg|ka1@N3z8*yaF_Cn|A$cQSK_kAevD1dRaMC#z)x_T-<
z(BhK0Gp0fTmp<LqxJQjl=%}-4;pZg{b~}EAveM^py0$RI(-PX
zm%4EERNC>N8cxK)#*_l)B0!L6Rzr8*)emJ@G{vP*rla_cbjpe>aIEK!^%5qr#U
z!(XHp`&1Dq@OVmojOHoz9!0~|S5
zIorBDDx&c_>C1PBjpxBliBmw(r0{MiRz1omO0IPDFB3Lo!|L@w9?%iT1Zx26ch>J{
z%PRU>uEl-8K&@^Jno5Mu0*L(ycQFOw)}Z3TNvNRG3r+YD=l;%=$~Q$`$c{v&?)plV
zQGjUz1J&PHaz!hRoJVAdQ^Ul}uM&`|Hj)zXqkM7ppAd6HUhx7d9xVxFTkYX1dn;t+
z6%wQ!&(0#}@%qxCO<}X~>gp0N%;DnWM7^uvuAT#z>C4wx_|q5Ga60sxTCiBKBSL^9xXck?PuLF$So
z3az*N*n+N%nl^xhiapZ8c
zA)-bQGA&Az2)KG~x6;>!N2uH-(nvTiEtLGceRh!vNBtfH;IShzunN;voz`x=|6363L-KIt1x5
z@Q6rBN(>=gf|MYGba&Ug2G4ooeV$+Z$46mi@3r?{d#&sKUe{fk8`U5ak#}~#k@4b*
z$R2QhQNIlU8*s(xo2orNAGg229ZvVpK6$RsHt$UoLi{=SC{GsRLQd_}PVOG1KSvVX
ztWX)~OdNOSJsqn7wD(1q77zDQ{g#xfpH_WN_>H~(k2GQ2b{}bk}};z<(1Lo)rP2yv(o|kPfu`YJ$j2a@s5N|d=;|G`@
z*`&YO^>M;99O^8*IF37ilCcm?od{$UF1cr}iV==RU%HIX*e))<#=
zv1rvr0*w0XiWlM54L1F2`j9)Or-O*G!fpq@z6LU(zxI3W_lxTb$Z#96C%5y%yIOAq
zSSo~Z>&N`Z!wtq_i~w%PTk&_q(a-4#`KkNf_fTs64Ofp7*FMD=AnRLS`d+K&I!dCV
z*|37HapHJM3JVvmQ?>cisGiUCfq4+JSMaYb!g#045izRMjhM?x+O(LMhYnIK)$f(C
z_c;!3Yku$B74_rgprD7)J0?gi%feOPJ37+7QE>we
zGL4$0%kHyUL;>hJ;hqUmut~ocio!+HFG`XHQC(IXUnf_H(nPhm*_>KJ4><}AK6u-*
z5|G7G%y1(1CvJhAK}mEq%s%{t61=>(IW5i(lR2=wiGo(x)}M*jvZxlc5{v6omf>Jl
z4UOZ-q}v1C>Uoc`mmsnN?q2%w08<=o;$qYdMwBjzO5*G?_%
zs

kM-F*6nS7RX#LSeFoM{x_bb~i>H2V$ki`15TO~ti>TQ>=0iFUI9TCmXDQj95Y zF3>CTzw?XBRI+Q+-r$XwF&jjfYp=w<{+2$Tr>JIScr`dU$fq$8KgU2PRQ_D{hEK-{ z0a9+;hV(iAxNl5Ygs!>pqPZ)dnz6EtfCyZ#39D zVAjw2p~pQ|M=qF}Tf3(-e)7oPzdwDO1r_RLg#$VRU!XM6~FbkLcbSAs=AIrplaiF_i@7Vr$-C@Eya-a^b_DQ z*dNWg$S7GM3g9pHDZFn}=&yrC4CPsSG0rf?1}lHzxnCevjYc-wC(S)R z=8QH(rR@3zpKV@JN#wpwnQjO+VPt>aeAr%ogXYLA=j=PrR4@?z#_ z=8C_99Nfahz;T8>n54(9zB|#27>;Vhwz_oO&8gwGks-|6>I~zw4ir7{?tMZLn2i~^ zgEW=mmpXZv?kKo_G(;rA9d8NE#WwUyJs{C4!Wdri)Gu!x#dRN-V(?@`T$^RF{6@W%0W;+V|d3kbTjh#$a-bemOYqDx|QDw+9o{gEZmdSQpZl z5j-0{G@YbI&1RSea!7@H8Jj2b!a&^$e4Vwib+EXpj(#V@sR z?dO3Cri3g0GA7pb-fN0SW^zi+ae1+7*%=_Hff^N%LxEV-$dM&2u{UFaMvFP2ZcsyA zX_U+SBEA_PHiq!NATqNQ%y1iAU}2vL5jUM2$WJAhgCof~U;(C3;hgZ@c3gYMM@pq*`^J19t8G?A8A?x{Kr5V!TW%T)e_ zHs$oMa8wMXnF8;v8;)B!p606dtFSXLPec?6w*T0-QM|-^Np!GlmHAn)WfY;XNHXW- zMkgo&K^K?FFn!CNDQ+pvdT!aU>xH5cqIr}NK74xf8kzBJBjhDWX$(|3@1 zmdsBaKUUV%r=1iAGTRzZOYJL2A&&KnZWuBp1fudD&Y}wirC2W|0&^c+!BC1*dEr^s zC5pX~Hw?SkU8$8Hm$8ptF#MxXo&RrI>TW{Jx@fiE*mGs2vQ zh_PAl9;o)s8Rn}R>#i&HvD15uJ|>L>^)Ahx2R#A^f6V-s2>Wgyy$15>26-Hg7%UHO z%;V8YIcT*XUbh|U@}0hVo9WYNecuxM_k)sZv$pl?1^SiyAqD9& z&MH78Jo4!g-?VOgc@f1NT_B)CtolsBH{TBD?b|hhPU`U{T0dwrLC3GiK+P1*Su5KY z3rl`8$Cjg#Cu54zh;vyL)>Us@E6+w$1SefgR!DwjHaXz_#yLhyjqbw}{d%wHB1aWC zQf2DvEI_aK-MATV&h2wmY8x_=urLO?D&stW(k}T3>>j=(nYfWhvyaCC6H>TuwbSZ^ ziud~Lw6A3kxp9B9_Z87c*<$R!6cMR>J}_gMlQq*T>h_J=i|pScmKiKfhMtSxjD-(( zdd;f82`$F>x}SZx|Ga9KHxmzlN1oQ!;mek#*lP-~P6CEu!(b zsWkA|Qu>GHL!TV0(K60J>1cbO2828x?qYgayq?%M)u3z1aZK@96yfac5w*>hxn!y~Xj#Th!9 zEH6_D&9Vpuuf+*{Wae5ZYW#?n+%~G2~&> z7tc&Pu(5+gYY~*<3xB0qis5|78wv2~E?0*k@(JN>%}f?ArCEz0aKDQ!`W~Bu{r*&) zCdVz=8{x*FTtx0d~myz*Tu z=g>2iK#uE*#2kHG4xA<;Rw8Q;(_b}>5glK?CYKnH|)4;L)6mi;9ESy~3rKxY*I; zl0GlXGn!euQ8R4r2k6D*os~tHeE(UK-xc;=+G|WPN}WtPn8%nJpFs7udc~%|kcB6m zB%Y3L&UB=!g~s6}fZ{g)o9F_{ey@8`EA}HLyMf|Ae+o8^q$sEz^T2f8eKb0G!D!0g zrHXt_Ej@e*<}ukQQ)Fpf*}o|m;bTtV)4r{sS6X8>ah8WDv!hd@9=OI9~wG}+$kpc%cZB&$8C6-zPE z0{z^+qW6!A>woo@=n1{N>~tvHLMu~f84sVWZ&=_@&1v-qWpKIOVT;>|DD3S+;34hi zS8f9ZL?RGl7$zw!S?gps&wzwK%4mL}JiYJsJKA19Zoe9StDwNmm0$cN2=a>5A1OLj zlRYf1-*hpzC(sj~6Bq9Vq@+>j1ePm|{bh%>2TxdW{q#*kvi%*FVh)md{IQ|fxxa{3 z8z3dCGuOzs8(ON|lc8`|#%pBscbW4`FOT@l2%l}%-wCJjo#{=2-^xrhAvYm=O(0V6)!z)bgg zJT#ijEq%uNYk51y(7 z+6WlWWEod}-w~rwo!m}KZ0t8tjgW$If?vyD)z?P7n{G$1dEvr=5x)wxH=z|iDcJjC zzZk;tp;7U*cdXWka{3h{$K`;WR@kg45(NF|*C_|Ev>uib@ti8_L*|2b>OnaHa*qI| zQC~~hFTsE6uid*nUfc$|+B&j5`R$?q`%xUqJtElp6&!NsYH2@l&?}JEv9_$g2lN)n zLq0k}>&ZFTx@CMOg)kl2xNso!lb+>7s}>h=wcAQVcv)E)ve-GFzQoyD+}>V-ADl_>x659@$}=b?@W0|j_0Zi;Hk@XRe|Hd~&2$8RknH>6Q z6KsyWpd+4gC)G=LzW2lnmEG=gd3y^qo^KKg}!XZF344VvD4gyA+a&AuP7;yoYFd)D^%J z2{1ZY2#n#DgGo8R0|>`)ao~#X(lm%@1Wx)C;ItIS9v^I}MqZ?UPMhPxhf^Y)efUO$ z=aHrDKr(BzScU?_xNT8G+Dp{|CQde{Z$&2F62dw zn2yHwDE1Yk7Aa<6fxRMc3Le8-_GQ%|m&3V_0wL*C^Yv3*Gi994+Q{Qfo!HW&*ka z=lJ(1jj4 zefkt=h5+lCkJpr2pu@&p2HNjyblp;a5S90B$u$Af-J1%vmfzr|rW~p7*t9eg;IXAFTZ2owH7h@UL~onI%dfRGI1c^9gx~G(~+bJIH}#` z5x|X9Xc^O@f<-$AEx=_iMk+^BU(|U?@wXMRq zX5L0?Sn_LsZn(bb^V^O}PAHyK)cO?f_rAW^sXIW$L1AiDpOHuF8o#h=Pq+dopqszh zue&V+SQsg2I6o~{H@HXe5IEaWC)R2#k>w!Q6f|)md&|Zj>^ImF73+g za>8Iag$vQ-B#D78QP#&wgkmRFj&w;W7T3lT;bB@=>1Hx@1F5{5K@=#@Uuh()5Pirq zTp)&699!#s1TM9DDr{8%fY$PgRs}%;2l<~nzW&yyBr8T$Id#Co7n15n$ZkjrQ_z03 zvhRobOr8Xsiey0;k*CtgyP#C9unrO#dISyLeFP|q(49MXfMUJtz(E3x!ii#jd_u+T z{!O1D@}LAG!?s|(HmfbkK5NaW{hnD!SUCHkr5p7n>%h&eYjr{p4ips`QdZGdSgQKB zX#yH)TH!tIM`lGvl4$l^Q66b&5K%`TSY!0dz;xdqgBLeNX23)Ph_-`~9-rAu^*>M# zOXrJ1r&^+`0hL6cZ>1n<8im^a~Qm&o+&flo~-%VXiZIs#LxS(CoY#uZ3L~ z2g-kaUyFHJ{N{BrMtA%&;y0MD{At?(%Y#Fmmk=(;z#)~sVCFg&{5@9bto`}Zr!X7L5$$LE}b`6ICXgZ-SVc>gAM`2qQf z9`lD%_>SkI$Z-38xxfznheY|maHIcD0dbH6IAasS!veK zbAChsz`+9$e?I!3(3SJ54%{*CgWA~(9)1w@D+UOe9N0gY45-DBXakqbA7%)T|A=$G zY;BX~zbUAAPZEqqg6R9X4|J6z+T-}&>`v2vqchE=>^`4Hww>{&YCth^-{0js-Qa<#Ua35iyeLI_Zvrv+!qf&csg}vRi8!Cf90oG^Fi+XJpIih*7Y89ewS%E0hp@7 zr>*wN^L(%Aj@xT>MaUTdJLQmaSEb$61=M9r3D4at*;*K8o$Fb#_VuV+Jqp%4R?sS3 zy$ruZlY>alWGqspk=s)s;h-OSXUnV}Q-LC}CJZ(0>$J5;B8?<;4a0l;tL%D&MQ{Z~ z65(|c=>AmREcmq%WxcbJqA#vp&8(Fj#j!%lq&xQ|wD&q_&o)sJOu&fV(}i7RSxVwg zUFr*0=fSGVJ+aPLq>Y}XWOw7Nm{3md*H5~ywV9kiar#()aW<0KWpC)1OucK~Q%g@M zA3RWj$x7QqNuxin0|=7)`rKb%&iBCYZc_eYF+$Z8Y;_LnGi?Tq0@@7QMczsppPXsh zYuW5XPfO3H9m0E;l}*4PcW9FxX!HKU`VB2(R3R!KA?~Bi<4KDqGh9SOxo zd|u{R#ifAw25e90sow2+xzOOEf@fc%FYBTRFDw6 zrt*4GJ<^o4@ZJ%VQ~{zbr@Cf80`JaBh~P>OxOnYec6B?+9wqyqFOTLbA0d{$$dHAU z^x7wC7}u5hc6I7%wdA_8K5`GRxPG_xNsc3jx(d7DO2DhEhSwWvApA09|D)B1)U$qt zGskKZg%3=kgh4wE>gQAQ`T4{cAaS33PgCm260lMC^*=Llkm@hqlmNmSf5s1#t{KT) zk+iN*PGrdbLKoMOQUuU`zS*_)4BpK{tutVXFe;drPb=1}_n&N8&`g-edLQFv?Ns&+ z+C%zy$Z++hxtqUFc>aAoWYs&z%p;{Ov6Xj0s-A>1l%w_VfbK%)vrK3)wbO+{tcAT*kO}so^_-NGFZ)})xgW6~d%lYr2aLAIr{KXN1 z$^$i^Uwgy{zwjlbd5N8ZB!5BVh4%q`@R&X$0dYC0zjdbL{-uo-z>P1JT@lt<*RBdK> z6>00gYOS-tloY%_G~6AY39<&1=_ga!<6mjb^&7)J->AZho68ov?4fVO?hxmCz567C5qEK5@|9b> zZ|DDHnj9IdW|TXByy>;-RPl&6?ydOJP%T}XzXtx$;P^xH;EIEH3m7vJ+uP;%^F+)7 z2a|gl4PjBxj6T5IU7_Pb|FP%*D@@V4Iv$O!qVF?5{J|d0uMc)Su~L*t1UseN+;_8i z>GQVbY?9TyuI(;WYwfMM0_|IyJgx6$GYya&W=FI$5QWX{h1|9%m0x?w+P7RX%v_*-N!GrxNvC97Up<-DaD6_$L%iC^^%4m3_K#c1w|qc`jY~O`Ky;3I8#8^l zJi_UHq&eFcTfV%z$gKTb5+Wy*H)Gn?sIo@q;G0p?W)FdiI-iGm*1gIM0xS)asI)%+ ztT@uiHke)~BkDqyJyzPt`1tP|&lTJvHglc~e)eR#62HUeT-OOs@j$!VO)i$Mb>Jz$ z_GkNBzbDWB+^{u5_VdpN@$$bOdS{_9&G*8jDC<#&5>_4%a{R(7G?VRroBD|kEz@>> zzuERz6j&GLm;>8Q0H}H&?X9{-e*C};;%-1qJzH|HoB6N`LDwh(&Um)deP5WycirNM zht7QlW53J=G)3ZtE*&0cftvwVRu3?j9oR2q_wnb8>i>?t2DL8oTDVS-+PnvC#XgW^ z_f>O@(j=4W%}gJb$YF53c;c7$lZwzRokBs^%dCu1D%E2?CHhy75e55L`1>CzJ4?n3 z6KBzS(IR_S!K0urJkNgS=gKHr%<=b6$L$n?+bVo0{d&O%ww4+n9aWl&UVN%IC(wtL zr)*eg(M0AsR@Au`){hL1b;YIIp>_H3hK=5q_0MtsUYVMB8o%<4pOlG}SJi);5)?Y+ z`9N9qOGyXJQtHh$q_q@!oa^JYyN4=uQO3*}b*MtiPip8hy|t8RxmNs%gv<@#Pb5;u?w!w1-CDzPOU|Xd ztTq`hk?i7-@9)pl*F+`p$uyx(;xD?(o(x^qoz_i* zSbGCy#MN07$3Ii8Cs?_}O-;lVzsferd+NTMg@{#_&CO*xqvE6@gSb#C-8lWGDeyD ziQl|}ov<9lpY!Mh=izl#y{16FZuJXanDwIT?Z$G)o~Vg$QF}wNa}M!LSRiEBd#=FX|JISVC#pXkJ@gw-kBz_+s)d>JC_3 zQsg)KJ%&X4Xvq9juGc&$bQUzt#;g%&Nq#WfPyWdsjzNk-6c~A*p;SgtK2)i!NYv|} z&68n>63jYQIsbWA3+qjx9nhO+rR+1|w~U0U%i%AX3!nelOMWOkdCPq)#@WIeI`7Yc z`I$IVSwI_OH*_ZIkR?;}5w`B~?yqe5Vz|OD#fwS`!CO|)$afG_^uuoMS+I(l^M=9}!ul0ttek_L|< zuj7uKq{E#jxhS^LYNK@@)^-lzMEmpWeJcP&7q>*u9hE_jvxS^VJz0=W110hq;hZtvbXJVb!E6`c%Z zrp4s%R6uv=&aJfV8a3&FHO2hfX`|ulMfI7f=zA{>i@_!v@3ax?{hSqQJZ169JSqRb z?3F)LzY%+t@n8Q5@HqI5GoVdO0VzG?Zc=&`1c(8H)b84N`1aaGUFYITed6Lg_d`A8 zy1{1HzDYcyLg4VERwNFdm8&!ng3P&KJ6yT|{3gbp2QzlR>luLsuUir5hI+t~2fXcj zYnrFGT{znjcsv#4enM~CKZEEC16>ghV!o_rdIUJSs}J&}JS7gUN-HM7-)?gHF9fhW zuIE$Lcl=OuGM<=dp9JQ)n?h0(^yMs%AM<;RfE-V1AgX-JNm?-|N0xI4(3gX>3xjQc zFa5D%5V`t05jgGE+^*@z7_i7AkEb8=QLjt+o*si9Lvy^!`r1{+0Cjim%~AkS%J03w znGeo%fJo18J|~CSVPq-7P9zba1J$-!VAZ@PRI7zs*_-FVLk?c}+(ml&S0emWN?29D zXa5(6Zc8_7o5n334Ba3 zpOB!5Pu>U86bP{h|7u?M6-52(P#{McRybnGsd8BOwDs#V=T+NnXb)1?Hj_{9Ahl$A zNy0EPB*F4(dXC0up!3T2(A9sioI2b&6(3f-?WkYD*Iegllt5!>B&5E9hRwg2B&KZ^ zIBns(d1d#CW|8{3-#u-0u(E6x0K3R=gP7)OVv6z#4xC?v4e@8^LFk%*BR>ZMR2nV< z-4uBI#uz!(GiYAHZyn@upOi4{Bims|g_uk_y+C}Tg`O_m6#{Nx9q9Pt$&>~RuZBt_ z+70s8THsL9bJY!~dXQ(rKF989Sy>R8`wc+yYl&oT=}(|~tI5>iZ`K&B&6EYR0O`lo zt~X;vgkk1YZbEpWs1nn}&Omr620jhkh%&%$2*5>?7c=x}IzYvz8zR;s0`ao4zNcTA zxs^%p<`hHLrnIAdL*?P7YU3)O^on3|`Ocxym6dLbKu9b!0*94xsoft_i3YtHGy)49DBJ#nu}k%V%RVDvf+qT(}9G=Np_iCUmjq% z5+M7Ml$J+IySMGG=8YK;#(Q7=CUW>G=C}ZgfiZ&gz-B0$_In-(Hky6wo6gW1k^PzhWk`?-vW>pu zK9~O7Fq7&s=pJ!#o!9_>Q8K#Cj#E!9=im z#-qrEFG_&qTuW#Z^ispoTHTsVARq8Z{?P}sLW&_k5w-;a?>!>W*vs+3xvBe)JUCy8 zhlE%`e6JN2Fu*`?1v$ldx*L2n09z&PMyD^1TY);{)VIh0k-QHdK&){n08~W)CVsAR z%J*1dJwL5E7`oxI&rYXtsTmb}&ReTT$NrP$g6U2z>WqCeX@T>1L7d9^^C$%)qjXVM zhSOC}UxI6JAVd0=zikEp_>7vWs%m+ij!R|D)WU|rDtqC2Hrl{xZD%XM>5Lpf?CXPd zjxPuD2vtt>EfBT0M#T&UI^wKSo8=Z%GK=xdis~#0p!M^YDa5{R;kv>@#`HYbb`UTH z+$#-+^TJXe!<%#l0e0eH6Hd#3vjB|hz)BBw6+ZTni}fGA?CV3QrNEvMn!TIxHxVLM z#+wI`--cFN+=R(LJKNF%*D)5Rda>ui>9Rk7*%;oOrCG5xVf(&`3I;$=dJQpr` zUUD6pC(NZ#t#IRwL6k*cGJIuYL-96MI364^_VBX#O&)xZ0FXlOgRpTyt)j_=g1J3= zX2Y%GqEw^n4rR6Od7cCWRM2NsU0-fe&Wq~ffauBL0>Y+?N!i6>vk&Al91a7*$?Ui` z8kq>7pNV^+cZ~nSN1xg#^D$D#>r&e>edT~6Qq!vD&jn_>ONc+LmY{X*cE@4WNq25M zo*`sUB({GT!O{JJHtpTu`x<8w7`g_L#S`sJhzz2 ze)mTo2gu$x-6-;-5*hT{A}u7qKHt`}3GGqpg>pn#<1}V6_j*y=chJE{)WuMJOoI$k z^dMEJm~AfX$T%S23EeF@T?8Y#d>H`1T;2zqFfk!o3F8qTT?p-qECPR?P%ouVPtT zYKuAH_>Z*{N{zY8v?LWYs@942{oe2qW{u_BpQ2Mm$fwU4Vv!H_%UTWEr$suQvib)!GkE!R?BZ@(_5_hEgZfW|OtGS#_-pFfgnEgmD zlr8;umcac2ne0M5g`u8Sq3n>i_(BIPW7#lQ9v}lfEaT;r`%$?~^xJLar0#B93frPbQ`8@H#mQ8?UgkvL+U~Mvq2%GY?m1IeBo{l=m>-G7 z$UVKB_$m2;zGU^8y7jjmddQN-&%%9bOdD*VE5wLsDs?=QBAYSN;)S8`!?KaCP`_35&Bb(LZUJM&%$;i$gZ6Aj1qv-j9TvC?9(US7&+Wm|Jw=onv@+nZg% z*c$lC(21f%*~lyVX+ZNYuCz#3G-3Af8h}2;1WbYxIpWd2ob0PYD%O(6?8)A z|2y-&w@t1335>e_LS#cy=Gkn<>BjSQY{w7Hxx_VreAc^RB}dsFPLKx@k2+x0l|5f> zWMc{j2OoSjKB&#yUOM(RuMX;U7!6Ow?K~}~rux=Ygk2Ni5D95YQqb?cy@#Z00>aW# z(lUNMsapGW`;_^KHd~aBIID__^m|#H=ZvrSa)`UK!sylt>eghTp3ua6f2$??*YdJ4 zHO>7j`@4mt>?XwEzPiwCUh+B?+3nvj15HI-F6?ay&U!6orZ*UNFg)5BQXGshO%LkB z1^a8)UZc>|IhAhhelMH5vE0@m%ALLuYJ3*)t>luo9#sqlGSKEeO`4LQFaP^yFGk{M z;cvV_%$nF*?P=28Vej-KQG;X;-C3)|J4_d%*qFMA=QL*B-}z$hvUi*2GlOnR6w3Ac zjz0 zdFq%l6qPivi`Cfg2WLwPc&yLfbYC&9gpK?+IlUjF;yY1b55|628n9P!edX7Zz4cqMAAlL8EI~dOONeP`ODn{u+Vk9$(6q24|j&6IB zZGA8LQ%Lxm)D<<~+uqBUntA?`myMnDBD}6?aH=2HBh>Ri7Idhz<~0nLcW<}w+TuJ7 zqa-X5ChSCiWD~&IC=`h)3Fqz5l#>h@wH*uSP zoaz6J0^so~SdLdh?pG%EhRWJJ%7`wgrbS;7`J5VI8uTH7g78}MbMIrT{jia}2qAGt zVW}^!&uF#mPEL!RJ75Kw1XDj@$6Ab`JWJ5iM|4?HThvRzz7PBfG%Ya}C-EGU2T^7( zYNyns*D1TR^L`F27n8Bm22i0By0f#m8^o*3`=XbM_Nq{xgBcj-vg=e+6UuxtF(kDf zRQP2UsKT?MJqEfuYvZ$;#}dQ6anC0PvgTM7*Pg_r)~*Qe5&UqfCvQEYfN{>yDd86re)c_f|7K3;t3 zv>JYME(K+BN^>7yQlH-U|NS4@ycGBJU18xCZvZwzmmYALBt1x;KCV*WewoP=%V1{q z5bjdQ<40Ly2idy%a;+Z2*LkAR$ydh69Mllj*$~tm0y(Tunady@>kOf0Oj8dE^88L2 z^utNYA@yx6VKHQ1lVt^bFxc6TejxC-mMexha=g4_BX^HrfNVqUG6DvC1ust9IaB-s zUV+sG-PtQ8P7h|VFb1)skJ%rF?44j2FhRNuky%ObMx*li>+aXfpM;v@``Ul!Kr~+(I!=hqUMn{NZuA`5vu1DCV~@yg``1mIr64MjC)IBo-FXe z{3r2svyXS)B@vHx0)>?g_ni8(;K3QiD3A)cNODOzJzgmSJL~8$&54JCLMBajBh>{L z&cIs?;1KaWEq)7x++EdUy3TFcUNkNMzL4;n-5&IX5WjSF)g!tl+3PEnG~ipZ>?l&^cjKi9G*@8M%85(JZeUe91V`-baLLSFL9 zas-R+HLwW(pv^ovOGMJAipLLuD7${&T1ts!A9)o|3?TjssMN}k`E|{CYwcwDE4%N) z2YeN`#!aXyEuPBzCFp^)*_xC@B%J}8%2t#^y4#9zcqu<+edyy`&GnA_8tCs9-vy&k zxj7s*0A&9AY_{=k%xfqnT)=Y=c^?)mzn>L#AD^ZOcd6pbBYXr;HXR0w$Bl&-mV|^K zrpfx&<@=tU)-tO!`(9^7Rup9r?3+rpoo5jW8czCpvL?Y#>pDoZ`J`T!<4rd={&%3& zkspw&4S&>fW261}JhvBFGy8Cp%lk8@%*a|9p@TZ_t@nDx5Q@Zw$!IC*1bj;=68|^d zK{H_m$k5;4BZc_BjZ`|%Sw!C`vuvYbF;tCmImxt9d;@ZJ{=L5r6gN$H4(no4Rytl9 zou*N5if!>tT(zTMu??udaOe|*C+F?V;h(#LqUP8|j!5ISvC2#{!@*((Uc zPtH=Z0!K6^NWG+HvE0gLZZHo@{XD#elpBc%4R$@erfnm?pW6}I!=;?Y*6wdq?KXMS z*uVgxFKjC)`CtNSin?2T1#*$8 zUsA-s?iP%A>l%(l7ZRot(TvjjJLoN(zWY`#)r(Eg(J;yiAR!>DGV-GMVi<1*hUc}M z_aQJi8-<+j)74#ErVn4mi90`6V46PLYj-r3b`D`qW4)aSfV0F`W*cuIi=C^Cwr--Z zQKqun`Vho}P^-d6jyeX+$AG&gZ{kzwux>(KXb{K=qL0}?=Im7hmp8~~0uE^MJB8rq zB8wIYUT<-=P#t;vYyI>)wNFZnJ24lcih~4KX7z$$i1Zev6_l3WRLDQ8+pb-G;Kk*q z1P?>I05XeHE+yuW%7r@D`#;*a>p2E8a3E}Edjj>x3WZ96d|bc~o-Xn9q9s%eDnvgp zxX9b8yuhWerI>d8hn&OwlF~8({HQuGPXt8O%=;^?9+7^Bei-=iGSI0c50V8j{1o5+ zUK7tLgG{jj!mYU;b`Svu#3#dYs<)sGSlhEdp+G#|CqZDgB4fpDP6_?EQ)w~tacg&a zU(mdrP8T`g;`2&7baMtYp(a^n90p+C>uVPKBhZ5dP2Vc}aT&a@0t#?MU`_uNIGFH4 zK^th!CVi@R@c%(SqPLW06%&Bo`6%Wnl?3$qgcN51hHa=K<^K=N*sN2D<5iaUS3v{&pMbstMT@Nc9v*QV| z{uuyr;eTX|8N*X>I@L!%VnD7L$IQ=YI=K8*5KgvRIhT=JLS==2HbEHLEh^yF_av25 zu(h?tckBU^M;bEpHJCyINon8xm3|0XJ4>TE+d-qRZK;6)x-_eM_wKdlHLXc1ud)Lq zwk}-i`KsXni2mO3OwY*&&el|Umib@6=$V4QQ^GJP5NlQjw4*X`d{}T9v1q;&DLkZR zSTXP`W1rwsl8}jUp(*t2s6IK6&j5^mmRbM1c(t=!vS;|ng36ecxd;-psv|jPI}-n% z=K%p)R?7DJ5DAB0%a4IT2gVcsi*SHooTG1lytV%;l?O@5S~-4kPSXMWUyBG(WI^Yx zs1!*+ZW2D5fd#zd{xE`X{7#lY5R(_yFF!R>BRgdfma&V~E`N7C+(koKRH znuj2T8 zKtBef^LQ%`at;LOOoxw#_!FP?KOw~bMhb#~IzM($2v7rrqSKs?=Me}9`}1M{8=*K) zpx;~Pd-jA2^i51x!zZR)mLDyK=s^6lOzM2xS)?4ZN*>67!sgTd&n#rxvp7Ec;nFto zz&x$*iSPg-a(@mW96gwI!io=-mX%dSy;L#LqRW8+!|6?Nu$9BP!t(rp=RXVPjgyf( zAXEt@k{NUR`7|;zvh*{sxOUI~{ozA4bq&z{0;#hY$coR&1XIhsbh5HMzsdIhjX3V)BrV==zk6~Vs`?_B5$uRupwBE&y)&Fm< zm$9Jf9k?NYrhgfs+#H{Q3iV}?UzcO6xse2yK++}?h!ZDZ!Slbo1+S*&6vtnGFzS5w zzsJL|p9thy55NAXms76iM$>`T5XV%&K_mDl#XuOrtraBCE=-618&@w^xuk{vGjE+Z zI5wRy*mp_Zk%4pKWQ*UQ^1G}fIVF$h(0rf>zG*=S0)O+7;4@InF-CKeuXi{}wD#%@ zLSK$ElCb|xEIZ2VeaX|A=XJw#6^*~iF=XN)>L)JE|BFab z>v|tFJfgI&MS;z#U}+;!ji$S-?ZWS8jOuuqR}tAcKI$`Ajo zo`Fcxt2V3dxbQxDf7$jMLp=c=dZN#hm{EbZKtH_mkU0f=eN6f3!4ue3Eu!lW7E=7E z7C>LW^Ctt}zTkgk!*PlK`!uhWm0BLXYCI2#tIJ$||7$01sX7I0>i6wYjH^{(9jdkANwJKN838b6Yqsc_~lI&NUl7k`- z^)WSbkFV(H>PiCbc!;Vww>+~8V6=PDr|vb%U}mrNcq`Z)M)n>7ayEE69v@|9o1!rZ zRtg;(2)x7wC;}_L6RXS527eLrZs0UU2%Jzvo?qsKgq!B91kewGDH;SD6zHGcm;F`a zOmwx>cXbDA+kIoUc5)XOCL8=!8BhGRT_AdHa#vf34$qW=$;-7*DME@m>L`PhX6b4B ztki>}Kh6*?naSfc4uCU7_L31d*hMLe$9Q2}lPNZ=JwP7S_Qu&t?{Ws0!P*V3vNh?9l__iP z{#2&zgUp7@4O2-q`paC+=f1eKO}M<1`AlrGt?G^{PUHHXXk;lw=E#%z)JL?{vP>fQ zEw!8%vSO6uqG#n-)2EQNp);o~+gUq0o5IM4+X^x^4C>Rb)OP31(?L20t369p z!kTJs^a2TWd zXloh;;Z^8*(NHvYE=pLg@V_VR{ZhgAC2b3d_x;M`HZ3Z-Wfyd>>-jJD+#YQyTeGG< z#C0b$rR(&)?S@R%FE<;RniQcK&)pvuiPy(N1GH?-$z1vbLLC@rLL+ao8uf)cP*5&ZW+=JjYN6G2oH7=10b5%Jt-7&@?x~ z$qwe}y&R^JPLD&IkUTNky@h}`_#`KV0zi+T{DABd-Yj`Cp9p=z&8-@lHyt6N-;)FA#lk_Auz4M3Tf#m|MC zLDO{_vSrn93hCOU(736&2zQ>#iJV%1`W@AtBxNvNs+b&R&M%}OMsxTDy>~#9_l}5j zQMK#}V9-~+BuKgI&95UXYKK!T5UoF)LJx*v$F`vk*RkdCP35O~`^^yp#B}7hjy2}` zdar^x%#}ic>WL0lFZ-X7@i>`+)yzh)wgNAG1_~WY9^$;djqTJ3Cq(P7-^Q|PX?Ma=RAnx($vNjS$>9E=5O-Wf6mv2#2 z!`yFiA8{@Grg}?V$>es=-#Jl#J+vyF;#km^{1O}4YXit~cP?#hNr>0vn|lPqV!=C_ zxtPYOCnQLg=X?oOlg$2>nZ8UO7At^0sg~Dm+`6)q=jdD*S>{Agn&+keMc?IsMQ^yAVeRX-(KD~0md&jmuY?~{Wfa$7V z!Vf;edW8kAPg*DQ+o-y*w-&|~d7A`~KdARFrA&#i$cesvX$9-Ye}5RW%z+yCLWk} zI=)Zy9I@o~pqUMKhkZax7x((U@DrP1;vd>vQt^g}*J#sN+8>_CJ6j8gqt< z;jolzwbm8T0;-I>pAERqABTOtPh5wkdv7JcZ=L1!+X_!?$w0}74@c5_yPRabdX@cn zLM7Ecx5HMcAi3nqK|S!o_dg|J!vgs$dZuy@CYQ*&H*DDBA5v9htJ$aopab;qeTd#P zhR{dAYMUv!z!qBfFDQ6ER`}pjg?-bLUCyeI;9)+35J?(-bmg93P>U!_T3bL#(-0Nq zP0a!UjFOk|*pBO|M)vr}(86tKsj1t*i^XfElZI~gkwV4H_z1xL@;6@Xy+Q*LvYx#` zq1ac|Dy7%{rA*3SoHQ&+~(@sbEyiHW7$tlvWml$|6C zIF0lx6Yp?uVNc?I#lyY6jXd$BzaAoIM`ZDc5J@;31)nG5=h#T*nt%D*Dy!L;roQ3u zZoj`^co-RrS2%l<$=_5tyoUd0maA$j8fABED|dQWTWO*2){KeC`jZ}?Us|5rVVQ2_ zn{O&y?)tGX?3@{EQC<)?Z^@%<27^yb%nq&H2lve2HonC7$K-wTa&^8fy`Ro&#_$C5 zH8gB^y71)9+{+S*w@ci%?e{micIGZ?>V*IIwGUSUhxzjgJ{~Z;)z*EAZGB?3q&TaL z%TeBlrUwpwd&(m^yp$q=19G5MMMt9fYPan#X_>F~AzhrupLXlBH{pWi2HNfKD#4!0UP#vcW621MRe#{r0kyWz;SUktZ@lk zAPZWtifgTx=O4XAz@-JS)*`UIspygkI#m(0(hH@-m~(#@=t`WT<&cpB^qy$ULg2Qq zzaJY{q=62Me#8Y_fb{Rprc~e=SY9$6ua-!JdgiBuUN^>vWW*o=4i*waThAlV2%86>$Lv+ zyPJ=nGX?GrObzjoc>!97{bHZa4B(A3Gs{0N+q3m^dfANq7mucG)F_W^2tEm1$Mpbm zKp^Oj8Q@R@(4$8$2S*xwTYdh~MLmfxlXMJxkYb6XDC1F=7Q=_uLwetG}y0 z`{=^t!koEpoMg@&QjD<)Z^|f0)0f-%Os*-ovu?XX$0mj2dx57e0bRUO$KjG|lq+ke zm|MJLi5DgfdRnXH=FhE)fjtj?k-pUwAZ4vA=WP; z{M~FZ=12!u;1KW`*(LR>gRL%f9KFDoZelp08?wGRfw7whw_vg-ipEN$8yT zxSJI?-teLnc>4Afr4vk7X0HAC;xv;LOY8g7zJ?3>=I|;To6id2^m$mw6nQ{1Aw~Fy zSe4Q1V$TCb^#Q;Q)|>UJnA{fE2m(85TJs*AVA`E$*hVMZNX%PclA7$pAAKU>)<|8t(a63d0+oG-3y zERmNh<(1^;2KP9K1^67W{~^%G1-ymcl4})fo<>@KQp~}&-P=IJA{|G=IK{HS91do%vv?yS9H;xgMoj533fNAukt;$@x*-Ky20td&;^S3B;N#$IKW2k zu#R}3WIph+6FVdQ I&MBb@0H(3k2LJ#7 literal 0 HcmV?d00001 diff --git a/src/main/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplication.java b/src/main/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplication.java new file mode 100644 index 0000000..f913a40 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplication.java @@ -0,0 +1,13 @@ +package kr.re.etri.security.jwt; + +import org.springframework.boot.SpringApplication; +import org.springframework.boot.autoconfigure.SpringBootApplication; + +@SpringBootApplication +public class SpringSecurityRefreshTokenApplication { + + public static void main(String[] args) { + SpringApplication.run(SpringSecurityRefreshTokenApplication.class, args); + } + +} diff --git a/src/main/java/kr/re/etri/security/jwt/advice/ErrorMessage.java b/src/main/java/kr/re/etri/security/jwt/advice/ErrorMessage.java new file mode 100644 index 0000000..2f16242 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/advice/ErrorMessage.java @@ -0,0 +1,33 @@ +package kr.re.etri.security.jwt.advice; + +import java.util.Date; + +public class ErrorMessage { + private int statusCode; + private Date timestamp; + private String message; + private String description; + + public ErrorMessage(int statusCode, Date timestamp, String message, String description) { + this.statusCode = statusCode; + this.timestamp = timestamp; + this.message = message; + this.description = description; + } + + public int getStatusCode() { + return statusCode; + } + + public Date getTimestamp() { + return timestamp; + } + + public String getMessage() { + return message; + } + + public String getDescription() { + return description; + } +} \ No newline at end of file diff --git a/src/main/java/kr/re/etri/security/jwt/advice/TokenControllerAdvice.java b/src/main/java/kr/re/etri/security/jwt/advice/TokenControllerAdvice.java new file mode 100644 index 0000000..954fd8b --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/advice/TokenControllerAdvice.java @@ -0,0 +1,25 @@ +package kr.re.etri.security.jwt.advice; + +import java.util.Date; + +import org.springframework.http.HttpStatus; +import org.springframework.web.bind.annotation.ExceptionHandler; +import org.springframework.web.bind.annotation.ResponseStatus; +import org.springframework.web.bind.annotation.RestControllerAdvice; +import org.springframework.web.context.request.WebRequest; + +import kr.re.etri.security.jwt.exception.TokenRefreshException; + +@RestControllerAdvice +public class TokenControllerAdvice { + + @ExceptionHandler(value = TokenRefreshException.class) + @ResponseStatus(HttpStatus.FORBIDDEN) + public ErrorMessage handleTokenRefreshException(TokenRefreshException ex, WebRequest request) { + return new ErrorMessage( + HttpStatus.FORBIDDEN.value(), + new Date(), + ex.getMessage(), + request.getDescription(false)); + } +} \ No newline at end of file diff --git a/src/main/java/kr/re/etri/security/jwt/controllers/AuthController.java b/src/main/java/kr/re/etri/security/jwt/controllers/AuthController.java new file mode 100644 index 0000000..a549d58 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/controllers/AuthController.java @@ -0,0 +1,190 @@ +package kr.re.etri.security.jwt.controllers; + +import java.util.HashSet; +import java.util.List; +import java.util.Set; +import java.util.stream.Collectors; + +import jakarta.servlet.http.HttpServletRequest; +import jakarta.validation.Valid; + +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.http.HttpHeaders; +import org.springframework.http.ResponseCookie; +import org.springframework.http.ResponseEntity; +import org.springframework.security.authentication.AuthenticationManager; +import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; +import org.springframework.security.core.Authentication; +import org.springframework.security.core.context.SecurityContextHolder; +import org.springframework.security.crypto.password.PasswordEncoder; +import org.springframework.web.bind.annotation.*; + +import kr.re.etri.security.jwt.exception.TokenRefreshException; +import kr.re.etri.security.jwt.models.ERole; +import kr.re.etri.security.jwt.models.RefreshToken; +import kr.re.etri.security.jwt.models.Role; +import kr.re.etri.security.jwt.models.User; +import kr.re.etri.security.jwt.payload.request.LoginRequest; +import kr.re.etri.security.jwt.payload.request.SignupRequest; +import kr.re.etri.security.jwt.payload.response.UserInfoResponse; +import kr.re.etri.security.jwt.payload.response.MessageResponse; +import kr.re.etri.security.jwt.repository.RoleRepository; +import kr.re.etri.security.jwt.repository.UserRepository; +import kr.re.etri.security.jwt.security.jwt.JwtUtils; +import kr.re.etri.security.jwt.security.services.RefreshTokenService; +import kr.re.etri.security.jwt.security.services.UserDetailsImpl; + +import io.swagger.v3.oas.annotations.Operation; +import io.swagger.v3.oas.annotations.tags.Tag; +import io.swagger.v3.oas.annotations.responses.ApiResponse; +import io.swagger.v3.oas.annotations.responses.ApiResponses; + +@Tag(name = "Authentication", description = "User Authentication APIs") +@CrossOrigin(origins = "*", maxAge = 3600) +@RestController +@RequestMapping("/api/auth") +public class AuthController { + + @Autowired + AuthenticationManager authenticationManager; + + @Autowired + UserRepository userRepository; + + @Autowired + RoleRepository roleRepository; + + @Autowired + PasswordEncoder encoder; + + @Autowired + JwtUtils jwtUtils; + + @Autowired + RefreshTokenService refreshTokenService; + + @Operation(summary = "User login", description = "Authenticate user and return JWT and refresh token cookies.") + @ApiResponses({ + @ApiResponse(responseCode = "200", description = "Login successful"), + @ApiResponse(responseCode = "401", description = "Invalid credentials") + }) + + @PostMapping("/signin") + public ResponseEntity authenticateUser(@Valid @RequestBody LoginRequest loginRequest) { + Authentication authentication = authenticationManager.authenticate( + new UsernamePasswordAuthenticationToken(loginRequest.getUsername(), loginRequest.getPassword()) + ); + + SecurityContextHolder.getContext().setAuthentication(authentication); + UserDetailsImpl userDetails = (UserDetailsImpl) authentication.getPrincipal(); + + // 기존 refresh token 제거 + refreshTokenService.deleteByUserId(userDetails.getId()); + + // 새 JWT 및 RefreshToken 생성 + ResponseCookie jwtCookie = jwtUtils.generateJwtCookie(userDetails); + RefreshToken refreshToken = refreshTokenService.createRefreshToken(userDetails.getId()); + ResponseCookie jwtRefreshCookie = jwtUtils.generateRefreshJwtCookie(refreshToken.getToken()); + + List roles = userDetails.getAuthorities().stream() + .map(item -> item.getAuthority()) + .collect(Collectors.toList()); + + return ResponseEntity.ok() + .header(HttpHeaders.SET_COOKIE, jwtCookie.toString()) + .header(HttpHeaders.SET_COOKIE, jwtRefreshCookie.toString()) + .body(new UserInfoResponse( + userDetails.getId(), + userDetails.getUsername(), + userDetails.getEmail(), + roles + )); + } + + @PostMapping("/signup") + public ResponseEntity registerUser(@Valid @RequestBody SignupRequest signUpRequest) { + if (userRepository.existsByUsername(signUpRequest.getUsername())) { + return ResponseEntity.badRequest().body(new MessageResponse("Error: Username is already taken!")); + } + if (userRepository.existsByEmail(signUpRequest.getEmail())) { + return ResponseEntity.badRequest().body(new MessageResponse("Error: Email is already in use!")); + } + + User user = new User(signUpRequest.getUsername(), signUpRequest.getEmail(), + encoder.encode(signUpRequest.getPassword())); + + Set strRoles = signUpRequest.getRole(); + Set roles = new HashSet<>(); + + if (strRoles == null) { + Role userRole = roleRepository.findByName(ERole.ROLE_USER) + .orElseThrow(() -> new RuntimeException("Error: Role is not found.")); + roles.add(userRole); + } else { + strRoles.forEach(role -> { + switch (role) { + case "admin": + roles.add(roleRepository.findByName(ERole.ROLE_ADMIN) + .orElseThrow(() -> new RuntimeException("Error: Role is not found."))); + break; + case "mod": + roles.add(roleRepository.findByName(ERole.ROLE_MODERATOR) + .orElseThrow(() -> new RuntimeException("Error: Role is not found."))); + break; + default: + roles.add(roleRepository.findByName(ERole.ROLE_USER) + .orElseThrow(() -> new RuntimeException("Error: Role is not found."))); + } + }); + } + + user.setRoles(roles); + userRepository.save(user); + + return ResponseEntity.ok(new MessageResponse("User registered successfully!")); + } + + @Operation(summary = "Logout", description = "Logout current user by deleting cookies and refresh token.") + @ApiResponse(responseCode = "200", description = "Logged out successfully") + @PostMapping("/signout") + public ResponseEntity logoutUser() { + Object principle = SecurityContextHolder.getContext().getAuthentication().getPrincipal(); + if (!"anonymousUser".equals(principle.toString())) { + Long userId = ((UserDetailsImpl) principle).getId(); + refreshTokenService.deleteByUserId(userId); + } + + ResponseCookie jwtCookie = jwtUtils.getCleanJwtCookie(); + ResponseCookie jwtRefreshCookie = jwtUtils.getCleanJwtRefreshCookie(); + + return ResponseEntity.ok() + .header(HttpHeaders.SET_COOKIE, jwtCookie.toString()) + .header(HttpHeaders.SET_COOKIE, jwtRefreshCookie.toString()) + .body(new MessageResponse("You've been signed out!")); + } + + @Operation(summary = "Refresh token", description = "Get a new access token using the refresh token from cookie.") + @ApiResponses({ + @ApiResponse(responseCode = "200", description = "Token refreshed successfully"), + @ApiResponse(responseCode = "400", description = "Refresh token is missing or invalid") + }) + @PostMapping("/refreshtoken") + public ResponseEntity refreshtoken(HttpServletRequest request) { + String refreshToken = jwtUtils.getJwtRefreshFromCookies(request); + + if (refreshToken != null && !refreshToken.isEmpty()) { + return refreshTokenService.findByToken(refreshToken) + .map(refreshTokenService::verifyExpiration) + .map(RefreshToken::getUser) + .map(user -> { + ResponseCookie jwtCookie = jwtUtils.generateJwtCookie(user); + return ResponseEntity.ok() + .header(HttpHeaders.SET_COOKIE, jwtCookie.toString()) + .body(new MessageResponse("Token is refreshed successfully!")); + }) + .orElseThrow(() -> new TokenRefreshException(refreshToken, "Refresh token is not in database!")); + } + + return ResponseEntity.badRequest().body(new MessageResponse("Refresh Token is empty!")); + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/controllers/TestController.java b/src/main/java/kr/re/etri/security/jwt/controllers/TestController.java new file mode 100644 index 0000000..d903a77 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/controllers/TestController.java @@ -0,0 +1,37 @@ +package kr.re.etri.security.jwt.controllers; + +import org.springframework.security.access.prepost.PreAuthorize; +import org.springframework.web.bind.annotation.CrossOrigin; +import org.springframework.web.bind.annotation.GetMapping; +import org.springframework.web.bind.annotation.RequestMapping; +import org.springframework.web.bind.annotation.RestController; + +//for Angular Client (withCredentials) +//@CrossOrigin(origins = "http://localhost:8081", maxAge = 3600, allowCredentials="true") +@CrossOrigin(origins = "*", maxAge = 3600) +@RestController +@RequestMapping("/api/test") +public class TestController { + @GetMapping("/all") + public String allAccess() { + return "Public Content."; + } + + @GetMapping("/user") + @PreAuthorize("hasRole('USER') or hasRole('MODERATOR') or hasRole('ADMIN')") + public String userAccess() { + return "User Content."; + } + + @GetMapping("/mod") + @PreAuthorize("hasRole('MODERATOR')") + public String moderatorAccess() { + return "Moderator Board."; + } + + @GetMapping("/admin") + @PreAuthorize("hasRole('ADMIN')") + public String adminAccess() { + return "Admin Board."; + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/exception/TokenRefreshException.java b/src/main/java/kr/re/etri/security/jwt/exception/TokenRefreshException.java new file mode 100644 index 0000000..e15fc5e --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/exception/TokenRefreshException.java @@ -0,0 +1,17 @@ +package kr.re.etri.security.jwt.exception; + +import org.springframework.http.HttpStatus; +import org.springframework.web.bind.annotation.ResponseStatus; + +import java.io.Serial; + +@ResponseStatus(HttpStatus.FORBIDDEN) +public class TokenRefreshException extends RuntimeException { + + @Serial + private static final long serialVersionUID = 1L; + + public TokenRefreshException(String token, String message) { + super(String.format("Failed for [%s]: %s", token, message)); + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/models/ERole.java b/src/main/java/kr/re/etri/security/jwt/models/ERole.java new file mode 100644 index 0000000..53ee098 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/models/ERole.java @@ -0,0 +1,7 @@ +package kr.re.etri.security.jwt.models; + +public enum ERole { + ROLE_USER, + ROLE_MODERATOR, + ROLE_ADMIN +} diff --git a/src/main/java/kr/re/etri/security/jwt/models/RefreshToken.java b/src/main/java/kr/re/etri/security/jwt/models/RefreshToken.java new file mode 100644 index 0000000..7b274df --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/models/RefreshToken.java @@ -0,0 +1,58 @@ +package kr.re.etri.security.jwt.models; + +import java.time.Instant; + +import jakarta.persistence.*; + +@Entity(name = "refreshtoken") +public class RefreshToken { + @Id + @GeneratedValue(strategy = GenerationType.AUTO) + private long id; + + @OneToOne + @JoinColumn(name = "user_id", referencedColumnName = "id") + private User user; + + @Column(nullable = false, unique = true) + private String token; + + @Column(nullable = false) + private Instant expiryDate; + + public RefreshToken() { + } + + public long getId() { + return id; + } + + public void setId(long id) { + this.id = id; + } + + public User getUser() { + return user; + } + + public void setUser(User user) { + this.user = user; + } + + public String getToken() { + return token; + } + + public void setToken(String token) { + this.token = token; + } + + public Instant getExpiryDate() { + return expiryDate; + } + + public void setExpiryDate(Instant expiryDate) { + this.expiryDate = expiryDate; + } + +} diff --git a/src/main/java/kr/re/etri/security/jwt/models/Role.java b/src/main/java/kr/re/etri/security/jwt/models/Role.java new file mode 100644 index 0000000..8d23764 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/models/Role.java @@ -0,0 +1,39 @@ +package kr.re.etri.security.jwt.models; + +import jakarta.persistence.*; + +@Entity +@Table(name = "roles") +public class Role { + @Id + @GeneratedValue(strategy = GenerationType.IDENTITY) + private Integer id; + + @Enumerated(EnumType.STRING) + @Column(length = 20) + private ERole name; + + public Role() { + + } + + public Role(ERole name) { + this.name = name; + } + + public Integer getId() { + return id; + } + + public void setId(Integer id) { + this.id = id; + } + + public ERole getName() { + return name; + } + + public void setName(ERole name) { + this.name = name; + } +} \ No newline at end of file diff --git a/src/main/java/kr/re/etri/security/jwt/models/User.java b/src/main/java/kr/re/etri/security/jwt/models/User.java new file mode 100644 index 0000000..1c10ffb --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/models/User.java @@ -0,0 +1,89 @@ +package kr.re.etri.security.jwt.models; + +import java.util.HashSet; +import java.util.Set; + +import jakarta.persistence.*; +import jakarta.validation.constraints.Email; +import jakarta.validation.constraints.NotBlank; +import jakarta.validation.constraints.Size; + +@Entity +@Table(name = "users", + uniqueConstraints = { + @UniqueConstraint(columnNames = "username"), + @UniqueConstraint(columnNames = "email") + }) +public class User { + @Id + @GeneratedValue(strategy = GenerationType.IDENTITY) + private Long id; + + @NotBlank + @Size(max = 20) + private String username; + + @NotBlank + @Size(max = 50) + @Email + private String email; + + @NotBlank + @Size(max = 120) + private String password; + + @ManyToMany(fetch = FetchType.LAZY) + @JoinTable(name = "user_roles", + joinColumns = @JoinColumn(name = "user_id"), + inverseJoinColumns = @JoinColumn(name = "role_id")) + private Set roles = new HashSet<>(); + + public User() { + } + + public User(String username, String email, String password) { + this.username = username; + this.email = email; + this.password = password; + } + + public Long getId() { + return id; + } + + public void setId(Long id) { + this.id = id; + } + + public String getUsername() { + return username; + } + + public void setUsername(String username) { + this.username = username; + } + + public String getEmail() { + return email; + } + + public void setEmail(String email) { + this.email = email; + } + + public String getPassword() { + return password; + } + + public void setPassword(String password) { + this.password = password; + } + + public Set getRoles() { + return roles; + } + + public void setRoles(Set roles) { + this.roles = roles; + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/payload/request/LoginRequest.java b/src/main/java/kr/re/etri/security/jwt/payload/request/LoginRequest.java new file mode 100644 index 0000000..abb0452 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/payload/request/LoginRequest.java @@ -0,0 +1,27 @@ +package kr.re.etri.security.jwt.payload.request; + +import jakarta.validation.constraints.NotBlank; + +public class LoginRequest { + @NotBlank + private String username; + + @NotBlank + private String password; + + public String getUsername() { + return username; + } + + public void setUsername(String username) { + this.username = username; + } + + public String getPassword() { + return password; + } + + public void setPassword(String password) { + this.password = password; + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/payload/request/SignupRequest.java b/src/main/java/kr/re/etri/security/jwt/payload/request/SignupRequest.java new file mode 100644 index 0000000..8f2abba --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/payload/request/SignupRequest.java @@ -0,0 +1,31 @@ +package kr.re.etri.security.jwt.payload.request; + +import jakarta.validation.constraints.*; +import lombok.Getter; +import lombok.Setter; +import lombok.NoArgsConstructor; +import lombok.AllArgsConstructor; + +import java.util.Set; + +@Getter +@Setter +@NoArgsConstructor +@AllArgsConstructor +public class SignupRequest { + + @NotBlank + @Size(min = 3, max = 20) + private String username; + + @NotBlank + @Size(max = 50) + @Email + private String email; + + private Set role; + + @NotBlank + @Size(min = 6, max = 40) + private String password; +} diff --git a/src/main/java/kr/re/etri/security/jwt/payload/response/MessageResponse.java b/src/main/java/kr/re/etri/security/jwt/payload/response/MessageResponse.java new file mode 100644 index 0000000..f808880 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/payload/response/MessageResponse.java @@ -0,0 +1,17 @@ +package kr.re.etri.security.jwt.payload.response; + +public class MessageResponse { + private String message; + + public MessageResponse(String message) { + this.message = message; + } + + public String getMessage() { + return message; + } + + public void setMessage(String message) { + this.message = message; + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/payload/response/UserInfoResponse.java b/src/main/java/kr/re/etri/security/jwt/payload/response/UserInfoResponse.java new file mode 100644 index 0000000..523eecb --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/payload/response/UserInfoResponse.java @@ -0,0 +1,45 @@ +package kr.re.etri.security.jwt.payload.response; + +import java.util.List; + +public class UserInfoResponse { + private Long id; + private String username; + private String email; + private List roles; + + public UserInfoResponse(Long id, String username, String email, List roles) { + this.id = id; + this.username = username; + this.email = email; + this.roles = roles; + } + + public Long getId() { + return id; + } + + public void setId(Long id) { + this.id = id; + } + + public String getEmail() { + return email; + } + + public void setEmail(String email) { + this.email = email; + } + + public String getUsername() { + return username; + } + + public void setUsername(String username) { + this.username = username; + } + + public List getRoles() { + return roles; + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/repository/RefreshTokenRepository.java b/src/main/java/kr/re/etri/security/jwt/repository/RefreshTokenRepository.java new file mode 100644 index 0000000..ba3bd58 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/repository/RefreshTokenRepository.java @@ -0,0 +1,17 @@ +package kr.re.etri.security.jwt.repository; +import java.util.Optional; + +import org.springframework.data.jpa.repository.JpaRepository; +import org.springframework.data.jpa.repository.Modifying; +import org.springframework.stereotype.Repository; + +import kr.re.etri.security.jwt.models.RefreshToken; +import kr.re.etri.security.jwt.models.User; + +@Repository +public interface RefreshTokenRepository extends JpaRepository { + Optional findByToken(String token); + + @Modifying + int deleteByUser(User user); +} diff --git a/src/main/java/kr/re/etri/security/jwt/repository/RoleRepository.java b/src/main/java/kr/re/etri/security/jwt/repository/RoleRepository.java new file mode 100644 index 0000000..3352200 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/repository/RoleRepository.java @@ -0,0 +1,14 @@ +package kr.re.etri.security.jwt.repository; + +import java.util.Optional; + +import org.springframework.data.jpa.repository.JpaRepository; +import org.springframework.stereotype.Repository; + +import kr.re.etri.security.jwt.models.ERole; +import kr.re.etri.security.jwt.models.Role; + +@Repository +public interface RoleRepository extends JpaRepository { + Optional findByName(ERole name); +} diff --git a/src/main/java/kr/re/etri/security/jwt/repository/UserRepository.java b/src/main/java/kr/re/etri/security/jwt/repository/UserRepository.java new file mode 100644 index 0000000..2e4fd7d --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/repository/UserRepository.java @@ -0,0 +1,17 @@ +package kr.re.etri.security.jwt.repository; + +import java.util.Optional; + +import org.springframework.data.jpa.repository.JpaRepository; +import org.springframework.stereotype.Repository; + +import kr.re.etri.security.jwt.models.User; + +@Repository +public interface UserRepository extends JpaRepository { + Optional findByUsername(String username); + + Boolean existsByUsername(String username); + + Boolean existsByEmail(String email); +} diff --git a/src/main/java/kr/re/etri/security/jwt/security/WebSecurityConfig.java b/src/main/java/kr/re/etri/security/jwt/security/WebSecurityConfig.java new file mode 100644 index 0000000..5f41c99 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/security/WebSecurityConfig.java @@ -0,0 +1,104 @@ +package kr.re.etri.security.jwt.security; + +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.security.authentication.AuthenticationManager; +import org.springframework.security.authentication.dao.DaoAuthenticationProvider; +//import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; +import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration; +import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity; +import org.springframework.security.config.annotation.web.builders.HttpSecurity; +//import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; +//import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; +import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer; +import org.springframework.security.config.http.SessionCreationPolicy; +import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; +import org.springframework.security.crypto.password.PasswordEncoder; +import org.springframework.security.web.SecurityFilterChain; +import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; + +import kr.re.etri.security.jwt.security.jwt.AuthEntryPointJwt; +import kr.re.etri.security.jwt.security.jwt.AuthTokenFilter; +import kr.re.etri.security.jwt.security.services.UserDetailsServiceImpl; + +@Configuration +//@EnableWebSecurity +@EnableMethodSecurity +//(securedEnabled = true, +//jsr250Enabled = true, +//prePostEnabled = true) // by default +public class WebSecurityConfig { // extends WebSecurityConfigurerAdapter { + @Autowired + UserDetailsServiceImpl userDetailsService; + + @Autowired + private AuthEntryPointJwt unauthorizedHandler; + + @Bean + public AuthTokenFilter authenticationJwtTokenFilter() { + return new AuthTokenFilter(); + } + +// @Override +// public void configure(AuthenticationManagerBuilder authenticationManagerBuilder) throws Exception { +// authenticationManagerBuilder.userDetailsService(userDetailsService).passwordEncoder(passwordEncoder()); +// } + + @Bean + public DaoAuthenticationProvider authenticationProvider() { + DaoAuthenticationProvider authProvider = new DaoAuthenticationProvider(); + + authProvider.setUserDetailsService(userDetailsService); + authProvider.setPasswordEncoder(passwordEncoder()); + + return authProvider; + } + +// @Bean +// @Override +// public AuthenticationManager authenticationManagerBean() throws Exception { +// return super.authenticationManagerBean(); +// } + + @Bean + public AuthenticationManager authenticationManager(AuthenticationConfiguration authConfig) throws Exception { + return authConfig.getAuthenticationManager(); + } + + @Bean + public PasswordEncoder passwordEncoder() { + return new BCryptPasswordEncoder(); + } + +// @Override +// protected void configure(HttpSecurity http) throws Exception { +// http.cors().and().csrf().disable() +// .exceptionHandling().authenticationEntryPoint(unauthorizedHandler).and() +// .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and() +// .authorizeRequests().antMatchers("/api/auth/**").permitAll() +// .antMatchers("/api/test/**").permitAll() +// .anyRequest().authenticated(); +// +// http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class); +// } + + @Bean + public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { + http.csrf(AbstractHttpConfigurer::disable) + .exceptionHandling(exception -> exception.authenticationEntryPoint(unauthorizedHandler)) + .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) + .authorizeHttpRequests(auth -> + auth.requestMatchers("/api/auth/**").permitAll() + .requestMatchers("/v3/api-docs/**", "/swagger-ui/**", "/swagger-ui.html").permitAll() + .requestMatchers("/api/test/**").permitAll() + .anyRequest().authenticated() + ); + + http.authenticationProvider(authenticationProvider()); + + http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class); + + return http.build(); + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/security/jwt/AuthEntryPointJwt.java b/src/main/java/kr/re/etri/security/jwt/security/jwt/AuthEntryPointJwt.java new file mode 100644 index 0000000..19b1349 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/security/jwt/AuthEntryPointJwt.java @@ -0,0 +1,43 @@ +package kr.re.etri.security.jwt.security.jwt; + +import java.io.IOException; +import java.util.HashMap; +import java.util.Map; + +import jakarta.servlet.ServletException; +import jakarta.servlet.http.HttpServletRequest; +import jakarta.servlet.http.HttpServletResponse; + +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; +import org.springframework.http.MediaType; +import org.springframework.security.core.AuthenticationException; +import org.springframework.security.web.AuthenticationEntryPoint; +import org.springframework.stereotype.Component; + +import com.fasterxml.jackson.databind.ObjectMapper; + +@Component +public class AuthEntryPointJwt implements AuthenticationEntryPoint { + + private static final Logger logger = LoggerFactory.getLogger(AuthEntryPointJwt.class); + + @Override + public void commence(HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) + throws IOException, ServletException { + logger.error("Unauthorized error: {}", authException.getMessage()); + + response.setContentType(MediaType.APPLICATION_JSON_VALUE); + response.setStatus(HttpServletResponse.SC_UNAUTHORIZED); + + final Map body = new HashMap<>(); + body.put("status", HttpServletResponse.SC_UNAUTHORIZED); + body.put("error", "Unauthorized"); + body.put("message", authException.getMessage()); + body.put("path", request.getServletPath()); + + final ObjectMapper mapper = new ObjectMapper(); + mapper.writeValue(response.getOutputStream(), body); + } + +} diff --git a/src/main/java/kr/re/etri/security/jwt/security/jwt/AuthTokenFilter.java b/src/main/java/kr/re/etri/security/jwt/security/jwt/AuthTokenFilter.java new file mode 100644 index 0000000..8cbef7e --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/security/jwt/AuthTokenFilter.java @@ -0,0 +1,60 @@ +package kr.re.etri.security.jwt.security.jwt; + +import java.io.IOException; + +import jakarta.servlet.FilterChain; +import jakarta.servlet.ServletException; +import jakarta.servlet.http.HttpServletRequest; +import jakarta.servlet.http.HttpServletResponse; + +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; +import org.springframework.security.core.context.SecurityContextHolder; +import org.springframework.security.core.userdetails.UserDetails; +import org.springframework.security.web.authentication.WebAuthenticationDetailsSource; +import org.springframework.web.filter.OncePerRequestFilter; + +import kr.re.etri.security.jwt.security.services.UserDetailsServiceImpl; + +public class AuthTokenFilter extends OncePerRequestFilter { + @Autowired + private JwtUtils jwtUtils; + + @Autowired + private UserDetailsServiceImpl userDetailsService; + + private static final Logger logger = LoggerFactory.getLogger(AuthTokenFilter.class); + + @Override + protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) + throws ServletException, IOException { + try { + String jwt = parseJwt(request); + if (jwt != null && jwtUtils.validateJwtToken(jwt)) { + String username = jwtUtils.getUserNameFromJwtToken(jwt); + + UserDetails userDetails = userDetailsService.loadUserByUsername(username); + + UsernamePasswordAuthenticationToken authentication = + new UsernamePasswordAuthenticationToken(userDetails, + null, + userDetails.getAuthorities()); + + authentication.setDetails(new WebAuthenticationDetailsSource().buildDetails(request)); + + SecurityContextHolder.getContext().setAuthentication(authentication); + } + } catch (Exception e) { + logger.error("Cannot set user authentication: {}", e); + } + + filterChain.doFilter(request, response); + } + + private String parseJwt(HttpServletRequest request) { + String jwt = jwtUtils.getJwtFromCookies(request); + return jwt; + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/security/jwt/JwtUtils.java b/src/main/java/kr/re/etri/security/jwt/security/jwt/JwtUtils.java new file mode 100644 index 0000000..632d110 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/security/jwt/JwtUtils.java @@ -0,0 +1,119 @@ +package kr.re.etri.security.jwt.security.jwt; + +import java.security.Key; +import java.util.Date; + +import jakarta.servlet.http.Cookie; +import jakarta.servlet.http.HttpServletRequest; + +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; +import org.springframework.beans.factory.annotation.Value; +import org.springframework.http.ResponseCookie; +import org.springframework.stereotype.Component; +import org.springframework.web.util.WebUtils; + +import kr.re.etri.security.jwt.models.User; +import kr.re.etri.security.jwt.security.services.UserDetailsImpl; + +import io.jsonwebtoken.*; +import io.jsonwebtoken.io.Decoders; +import io.jsonwebtoken.security.Keys; + +@Component +public class JwtUtils { + private static final Logger logger = LoggerFactory.getLogger(JwtUtils.class); + + @Value("${bezkoder.app.jwtSecret}") + private String jwtSecret; + + @Value("${bezkoder.app.jwtExpirationMs}") + private int jwtExpirationMs; + + @Value("${bezkoder.app.jwtCookieName}") + private String jwtCookie; + + @Value("${bezkoder.app.jwtRefreshCookieName}") + private String jwtRefreshCookie; + + public ResponseCookie generateJwtCookie(UserDetailsImpl userPrincipal) { + String jwt = generateTokenFromUsername(userPrincipal.getUsername()); + return generateCookie(jwtCookie, jwt, "/api"); + } + + public ResponseCookie generateJwtCookie(User user) { + String jwt = generateTokenFromUsername(user.getUsername()); + return generateCookie(jwtCookie, jwt, "/api"); + } + + public ResponseCookie generateRefreshJwtCookie(String refreshToken) { + return generateCookie(jwtRefreshCookie, refreshToken, "/api/auth/refreshtoken"); + } + + public String getJwtFromCookies(HttpServletRequest request) { + return getCookieValueByName(request, jwtCookie); + } + + public String getJwtRefreshFromCookies(HttpServletRequest request) { + return getCookieValueByName(request, jwtRefreshCookie); + } + + public ResponseCookie getCleanJwtCookie() { + ResponseCookie cookie = ResponseCookie.from(jwtCookie, null).path("/api").build(); + return cookie; + } + + public ResponseCookie getCleanJwtRefreshCookie() { + ResponseCookie cookie = ResponseCookie.from(jwtRefreshCookie, null).path("/api/auth/refreshtoken").build(); + return cookie; + } + + public String getUserNameFromJwtToken(String token) { + return Jwts.parserBuilder().setSigningKey(key()).build() + .parseClaimsJws(token).getBody().getSubject(); + } + + private Key key() { + return Keys.hmacShaKeyFor(Decoders.BASE64.decode(jwtSecret)); + } + + public boolean validateJwtToken(String authToken) { + try { + Jwts.parserBuilder().setSigningKey(key()).build().parse(authToken); + return true; + } catch (MalformedJwtException e) { + logger.error("Invalid JWT token: {}", e.getMessage()); + } catch (ExpiredJwtException e) { + logger.error("JWT token is expired: {}", e.getMessage()); + } catch (UnsupportedJwtException e) { + logger.error("JWT token is unsupported: {}", e.getMessage()); + } catch (IllegalArgumentException e) { + logger.error("JWT claims string is empty: {}", e.getMessage()); + } + + return false; + } + + public String generateTokenFromUsername(String username) { + return Jwts.builder() + .setSubject(username) + .setIssuedAt(new Date()) + .setExpiration(new Date((new Date()).getTime() + jwtExpirationMs)) + .signWith(key(), SignatureAlgorithm.HS256) + .compact(); + } + + private ResponseCookie generateCookie(String name, String value, String path) { + ResponseCookie cookie = ResponseCookie.from(name, value).path(path).maxAge(24 * 60 * 60).httpOnly(true).build(); + return cookie; + } + + private String getCookieValueByName(HttpServletRequest request, String name) { + Cookie cookie = WebUtils.getCookie(request, name); + if (cookie != null) { + return cookie.getValue(); + } else { + return null; + } + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/security/services/RefreshTokenService.java b/src/main/java/kr/re/etri/security/jwt/security/services/RefreshTokenService.java new file mode 100644 index 0000000..f9b355a --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/security/services/RefreshTokenService.java @@ -0,0 +1,56 @@ +package kr.re.etri.security.jwt.security.services; + +import java.time.Instant; +import java.util.Optional; +import java.util.UUID; + +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.beans.factory.annotation.Value; +import org.springframework.stereotype.Service; +import org.springframework.transaction.annotation.Transactional; + +import kr.re.etri.security.jwt.exception.TokenRefreshException; +import kr.re.etri.security.jwt.models.RefreshToken; +import kr.re.etri.security.jwt.repository.RefreshTokenRepository; +import kr.re.etri.security.jwt.repository.UserRepository; + +@Service +public class RefreshTokenService { + @Value("${bezkoder.app.jwtRefreshExpirationMs}") + private Long refreshTokenDurationMs; + + @Autowired + private RefreshTokenRepository refreshTokenRepository; + + @Autowired + private UserRepository userRepository; + + public Optional findByToken(String token) { + return refreshTokenRepository.findByToken(token); + } + + public RefreshToken createRefreshToken(Long userId) { + RefreshToken refreshToken = new RefreshToken(); + + refreshToken.setUser(userRepository.findById(userId).get()); + refreshToken.setExpiryDate(Instant.now().plusMillis(refreshTokenDurationMs)); + refreshToken.setToken(UUID.randomUUID().toString()); + + refreshToken = refreshTokenRepository.save(refreshToken); + return refreshToken; + } + + public RefreshToken verifyExpiration(RefreshToken token) { + if (token.getExpiryDate().compareTo(Instant.now()) < 0) { + refreshTokenRepository.delete(token); + throw new TokenRefreshException(token.getToken(), "Refresh token was expired. Please make a new signin request"); + } + + return token; + } + + @Transactional + public int deleteByUserId(Long userId) { + return refreshTokenRepository.deleteByUser(userRepository.findById(userId).get()); + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsImpl.java b/src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsImpl.java new file mode 100644 index 0000000..cd10c11 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsImpl.java @@ -0,0 +1,103 @@ +package kr.re.etri.security.jwt.security.services; + +import java.util.Collection; +import java.util.List; +import java.util.Objects; +import java.util.stream.Collectors; + +import org.springframework.security.core.GrantedAuthority; +import org.springframework.security.core.authority.SimpleGrantedAuthority; +import org.springframework.security.core.userdetails.UserDetails; + +import kr.re.etri.security.jwt.models.User; +import com.fasterxml.jackson.annotation.JsonIgnore; + +public class UserDetailsImpl implements UserDetails { + private static final long serialVersionUID = 1L; + + private Long id; + + private String username; + + private String email; + + @JsonIgnore + private String password; + + private Collection authorities; + + public UserDetailsImpl(Long id, String username, String email, String password, + Collection authorities) { + this.id = id; + this.username = username; + this.email = email; + this.password = password; + this.authorities = authorities; + } + + public static UserDetailsImpl build(User user) { + List authorities = user.getRoles().stream() + .map(role -> new SimpleGrantedAuthority(role.getName().name())) + .collect(Collectors.toList()); + + return new UserDetailsImpl( + user.getId(), + user.getUsername(), + user.getEmail(), + user.getPassword(), + authorities); + } + + @Override + public Collection getAuthorities() { + return authorities; + } + + public Long getId() { + return id; + } + + public String getEmail() { + return email; + } + + @Override + public String getPassword() { + return password; + } + + @Override + public String getUsername() { + return username; + } + + @Override + public boolean isAccountNonExpired() { + return true; + } + + @Override + public boolean isAccountNonLocked() { + return true; + } + + @Override + public boolean isCredentialsNonExpired() { + return true; + } + + @Override + public boolean isEnabled() { + return true; + } + + @Override + public boolean equals(Object o) { + if (this == o) + return true; + if (o == null || getClass() != o.getClass()) + return false; + UserDetailsImpl user = (UserDetailsImpl) o; + return Objects.equals(id, user.id); + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsServiceImpl.java b/src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsServiceImpl.java new file mode 100644 index 0000000..d3c8c80 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/security/services/UserDetailsServiceImpl.java @@ -0,0 +1,26 @@ +package kr.re.etri.security.jwt.security.services; + +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.security.core.userdetails.UserDetails; +import org.springframework.security.core.userdetails.UserDetailsService; +import org.springframework.security.core.userdetails.UsernameNotFoundException; +import org.springframework.stereotype.Service; +import org.springframework.transaction.annotation.Transactional; + +import kr.re.etri.security.jwt.models.User; +import kr.re.etri.security.jwt.repository.UserRepository; + +@Service +public class UserDetailsServiceImpl implements UserDetailsService { + @Autowired + UserRepository userRepository; + + @Override + @Transactional + public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException { + User user = userRepository.findByUsername(username) + .orElseThrow(() -> new UsernameNotFoundException("User Not Found with username: " + username)); + + return UserDetailsImpl.build(user); + } +} diff --git a/src/main/java/kr/re/etri/security/jwt/swagger/OpenAPIConfig.java b/src/main/java/kr/re/etri/security/jwt/swagger/OpenAPIConfig.java new file mode 100644 index 0000000..f491254 --- /dev/null +++ b/src/main/java/kr/re/etri/security/jwt/swagger/OpenAPIConfig.java @@ -0,0 +1,29 @@ +package kr.re.etri.security.jwt.swagger; + +import io.swagger.v3.oas.models.OpenAPI; +import io.swagger.v3.oas.models.info.Info; +import io.swagger.v3.oas.models.security.SecurityRequirement; +import io.swagger.v3.oas.models.security.SecurityScheme; +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; + +@Configuration +public class OpenAPIConfig { + + private static final String SECURITY_SCHEME_NAME = "bezkoder-jwt-cookie"; + + @Bean + public OpenAPI customOpenAPI() { + return new OpenAPI() + .info(new Info() + .title("My API") + .version("v1")) + .addSecurityItem(new SecurityRequirement().addList(SECURITY_SCHEME_NAME)) + .components(new io.swagger.v3.oas.models.Components() + .addSecuritySchemes(SECURITY_SCHEME_NAME, + new SecurityScheme() + .name("bezkoder-jwt") + .type(SecurityScheme.Type.APIKEY) + .in(SecurityScheme.In.COOKIE))); + } +} diff --git a/src/main/resources/application.properties b/src/main/resources/application.properties new file mode 100644 index 0000000..a6a931e --- /dev/null +++ b/src/main/resources/application.properties @@ -0,0 +1,17 @@ +spring.datasource.url=jdbc:mariadb://192.168.10.143:3306/autoflow +spring.datasource.username=cuuva +spring.datasource.password=cuuva + +spring.jpa.database-platform=org.hibernate.dialect.MariaDBDialect +spring.jpa.hibernate.ddl-auto= create-drop + +# App Properties +bezkoder.app.jwtCookieName= bezkoder-jwt +bezkoder.app.jwtRefreshCookieName= bezkoder-jwt-refresh +bezkoder.app.jwtSecret= ======================BezKoder=Spring=========================== +#bezkoder.app.jwtExpirationMs= 86400000 +#bezkoder.app.jwtRefreshExpirationMs= 86400000 + +## For test +bezkoder.app.jwtExpirationMs= 60000 +bezkoder.app.jwtRefreshExpirationMs= 180000 \ No newline at end of file diff --git a/src/test/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplicationTests.java b/src/test/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplicationTests.java new file mode 100644 index 0000000..b41aea8 --- /dev/null +++ b/src/test/java/kr/re/etri/security/jwt/SpringSecurityRefreshTokenApplicationTests.java @@ -0,0 +1,13 @@ +package kr.re.etri.security.jwt; + +import org.junit.jupiter.api.Test; +import org.springframework.boot.test.context.SpringBootTest; + +@SpringBootTest +class SpringSecurityRefreshTokenApplicationTests { + + @Test + void contextLoads() { + } + +}