import { z } from "zod"; import type { PlanContext } from "../internals/plan.js"; /** Fixed, regular-file-only external authority input. It is never generated from policy JSON. */ export declare const POLICY_AUTHORITY_RECEIPT_PATH = ".aih/policy-authority-receipt.json"; /** Strict external authority receipt contract; policy JSON cannot supply these facts. */ export declare const PolicyAuthorityReceiptSchema: z.ZodObject<{ format: z.ZodLiteral<"aih-policy-authority-receipt">; version: z.ZodLiteral<1>; issuerRepository: z.ZodString; issuedAt: z.ZodString; expiresAt: z.ZodString; trustedIssuers: z.ZodDefault>>; evidence: z.ZodDefault; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; sourceDigest: z.ZodString; evidenceDigest: z.ZodString; identityDigest: z.ZodString; state: z.ZodEnum<{ failed: "failed"; missing: "missing"; verified: "verified"; }>; waivable: z.ZodBoolean; detectors: z.ZodDefault; reportDigest: z.ZodOptional; }, z.core.$strict>>>; findings: z.ZodDefault>>; }, z.core.$strict>>>; approvals: z.ZodDefault; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; issuer: z.ZodString; sourceDigest: z.ZodString; evidenceDigest: z.ZodString; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; policyVersion: z.ZodString; reason: z.ZodString; clarification: z.ZodOptional; scope: z.ZodArray>; notBefore: z.ZodString; expiresAt: z.ZodString; github: z.ZodObject<{ repository: z.ZodString; attestationId: z.ZodString; subjectDigest: z.ZodString; }, z.core.$strict>; }, z.core.$strict>>>; revocations: z.ZodDefault>>; targets: z.ZodArray>; }, z.core.$strict>; export type PolicyAuthorityReceipt = z.infer; /** Every externally-authored receipt leaf must have an authority consumer too. */ export declare function policyAuthorityReceiptLeafPaths(): string[]; /** Exact map compared to `policyAuthorityReceiptLeafPaths()` by the consumer-contract test. */ export declare const POLICY_AUTHORITY_RECEIPT_FIELD_CONSUMERS: Readonly>; /** Opaque result: only `verifyPolicyAuthorityReceipt` can mint a usable authority object. */ export interface VerifiedPolicyAuthority { readonly receipt: PolicyAuthorityReceipt; readonly receiptDigest: string; readonly repository: string; } export declare function isVerifiedPolicyAuthority(value: unknown): value is VerifiedPolicyAuthority; export interface PolicyAuthorityVerification { authority?: VerifiedPolicyAuthority; /** Deliberately scrubbed: trust-verifier child output may contain credentials. */ problem?: string; } /** * Verify the fixed authority receipt against an organization-admin registry set * outside the target checkout (`AIH_POLICY_AUTHORITY_REPOSITORY`, optionally * `AIH_POLICY_AUTHORITY_WORKFLOW`). The governed repository's origin and its * policy JSON are never trust roots. The receipt remains untrusted data until * `gh attestation verify` succeeds against that exact external identity. */ export declare function verifyPolicyAuthorityReceipt(ctx: PlanContext): Promise;