import { JwtService } from "@nestjs/jwt"; import { ClsService } from "nestjs-cls"; export declare const hashPassword: (password: string) => Promise; export declare const checkPassword: (password: string, hash: string) => Promise; export declare class SecurityService { protected readonly jwtService: JwtService; protected readonly clsService: ClsService; constructor(jwtService: JwtService, clsService: ClsService); get refreshTokenExpiration(): Date; get tokenExpiration(): Date; signJwt(params: { userId: string; roles: string[]; companyId: string; features: string[]; userName?: string; }): string; get invitationSelectionTokenExpiration(): Date; signInvitationSelectionJwt(params: { userId: string; }): string; get companySelectionTokenExpiration(): Date; signCompanySelectionJwt(params: { userId: string; }): string; decodeJwt(token: string): any; isCurrentUserCompanyAdmin(): boolean; validateAdmin(params: { user: any; }): void; isUserInRoles(params: { user: any; roles: string[]; }): boolean; userHasAccess(params: { validator: (params?: any) => string; }): string; /** * Generate a pending JWT for 2FA flows. * This token has limited access and a short TTL (5 minutes). * It includes the userId and indicates that 2FA verification is required. * * @param params - The parameters for the pending JWT * @param params.userId - The user's ID * @param params.pendingId - The pending 2FA session ID * @returns The signed pending JWT */ signPendingJwt(params: { userId: string; pendingId: string; }): string; /** * Check if a JWT payload is a pending 2FA token. * Pending tokens have limited access and require 2FA verification * before being exchanged for a full access token. * * @param payload - The decoded JWT payload * @returns true if this is a pending 2FA token */ isPendingToken(payload: any): boolean; /** * Get the expiration time for pending 2FA tokens (5 minutes). */ get pendingTokenExpiration(): Date; } //# sourceMappingURL=security.service.d.ts.map