/** * This Source Code is subject to the terms of the Mozilla Public * License, v. 2.0. If a copy of the MPL was not distributed with this * file, You can obtain one at http://mozilla.org/MPL/2.0/. * * Copyright (c) Infonomic Company Limited */ import type { PasswordSignInLimiter } from '@byline/auth'; import type { RecurringTaskDefinition } from '@byline/core'; export interface SignInRateLimitStore { /** Atomically increment, saturating at limit + 1; true only for the first limit calls. */ consume(key: string, limit: number, expiresAt: Date): Promise; /** Remove at most 100 expired counters and return the number removed. */ purgeExpired(before: Date): Promise; } export interface SignInRateLimitPolicy { account: { limit: number; windowSeconds: number; }; ip: { limit: number; windowSeconds: number; }; } export interface SignInSecurityEvent { type: 'admitted' | 'denied' | 'capacity' | 'store-error' | 'cleanup-error' | 'success' | 'failure'; scope?: 'account' | 'ip'; /** Stable, pseudonymous digests for cross-network correlation. Never passwords or raw IPs. */ account?: string; network?: string; } export interface SignInLimiterOptions { onEvent?: (event: SignInSecurityEvent) => void; slots?: number; maxQueue?: number; queueTimeoutMs?: number; /** Also bounds counter creation when the provider or a denial completes very quickly. */ minimumSlotMs?: number; } /** * Instantiate once per process. Acquire before consume and release in finally after verification. * Network admission precedes account-plus-network admission. There is no account-wide lockout. */ export declare function createPasswordSignInLimiter(store: SignInRateLimitStore, secret: string | Uint8Array, policy?: SignInRateLimitPolicy, now?: () => number, options?: SignInLimiterOptions): PasswordSignInLimiter & { cleanupTask: RecurringTaskDefinition; dispose(): void; };