import { CanActivate, ExecutionContext } from "@nestjs/common"; import { JwtService } from "@nestjs/jwt"; /** * Decoded pending JWT payload structure. * This token is issued after password validation but before 2FA verification. */ export interface PendingAuthPayload { userId: string; pendingId: string; type: "pending_2fa"; exp: number; } /** * Guard for two-factor verification endpoints. * * This guard validates pending 2FA tokens that are issued after password validation. * Pending tokens have limited scope and cannot access protected endpoints. * They are only valid for 2FA verification endpoints. * * The guard: * 1. Extracts the Bearer token from Authorization header * 2. Verifies the JWT signature * 3. Validates that the token type is "pending_2fa" * 4. Attaches the decoded payload to request.pendingAuth */ export declare class PendingAuthGuard implements CanActivate { private readonly jwtService; constructor(jwtService: JwtService); canActivate(context: ExecutionContext): Promise; /** * Check if the decoded token is a valid pending 2FA token. */ private isPendingToken; } //# sourceMappingURL=pending-auth.guard.d.ts.map