import { OnApplicationBootstrap } from "@nestjs/common"; import { Neo4jService } from "../../../core/neo4j/services/neo4j.service"; import { AppLoggingService } from "../../../core/logging/services/logging.service"; import type { RbacMatrix } from "../dsl/types"; /** * Applies the declared `RbacMatrix` to Neo4j at application bootstrap. * * Behaviour (per spec §6.3): * - Administrator role is never written as an HAS_PERMISSIONS edge — the * security layer short-circuits for it. * - Module defaults are stored on `Module.permissions`. * - Role-specific permissions are stored on `(Role)-[:HAS_PERMISSIONS]->(Module)`. * - Deletions are scoped to modules declared in the matrix: edges for * undeclared modules are left untouched. * - Preflight aborts with a clear error if any referenced role or module is * missing from the DB (seed migrations must run first). */ export declare class RbacReconcilerService implements OnApplicationBootstrap { private readonly neo4j; private readonly matrix; private readonly logger; constructor(neo4j: Neo4jService, matrix: RbacMatrix | null, logger: AppLoggingService); onApplicationBootstrap(): Promise; private preflight; private findMissing; private readActualState; private computeDiff; private apply; } //# sourceMappingURL=rbac-reconciler.service.d.ts.map