/** * Persistent record of a registered machine. * * Lives at `/machine.json` (mode 0600). Created the first time * `spectral serve` runs after login; reused across restarts so a single * developer machine appears as one logical agent in the backend's machine * list, regardless of how many times the CLI process restarts. * * Why a separate file from `config.json`? * - `config.json` carries the team API key (rotated on logout). The * machine identity outlives logout/login: if you `logout` then * `login` with the same team, your machine should keep its `machineId` * so the backend's audit log stays continuous. * - The machine JWT is short-lived (decoded `exp` checked by * `registration.ts`). Splitting it out keeps the auth file minimal and * avoids any risk of accidentally serializing the JWT into a * `spectral login` log line. * * Schema is intentionally minimal — Batch 3 will add capability flags; * unknown fields are preserved on round-trip via `extra` so older CLIs * don't strip data the backend later cares about. */ export interface MachineRecord { /** Stable machine id assigned by the backend on first register. */ machineId: string; /** Display name (defaults to hostname; user can override with --machine-name). */ machineName: string; /** Short-lived bearer JWT used for the WS Authorization header. */ machineJwt: string; /** Team id (optional — backend may or may not return one in this batch). */ teamId?: string; /** User who registered the machine via OAuth. Absent for team-API-key registrations. */ ownerId?: string; /** Machine visibility: "PRIVATE" or "SHARED". */ visibility?: string; /** Wall-clock ms when the JWT was issued (used for cheap freshness display). */ registeredAt: number; /** Hostname captured at registration time. Informational only. */ hostname: string; /** CLI version captured at registration time. Informational only. */ version: string; /** * Forward-compatibility bag: any unknown JSON keys read from disk are * preserved here and re-emitted on save so a newer backend that adds * fields doesn't get them stripped by an older CLI. */ extra?: Record; } export declare function getMachineFile(): string; /** * Read the persisted machine record. Returns `null` when the file is * missing or malformed — callers treat both as "needs registration". * * We intentionally do NOT throw on parse errors: a corrupted machine.json * should self-heal on the next `spectral serve` (re-register, overwrite), * not block startup forever. */ export declare function loadMachine(): Promise; /** * Write the machine record with restrictive permissions. Creates the * config directory if missing (matches `writeConfig` in `config.ts`). * * Atomicity: we do NOT write-then-rename. The record is small, the file * is single-writer (one `spectral serve` at a time per `$SPECTRAL_CONFIG_DIR`), * and a torn write self-heals via `loadMachine` returning null + re-register. */ export declare function saveMachine(rec: MachineRecord): Promise; //# sourceMappingURL=machine-store.d.ts.map