type Environment = "sandbox" | "live"; interface ActiveCredentials { environment: Environment; client_id: string; client_secret: string; } export interface AccessTokenResult { accessToken: string; base: string; } export interface ResolvedSettings { additionalSettings: Record; advancedCardSettings: Record; apiDetails: Record; } /** * Self-contained credential and token management for PayPal payment providers. * * Payment providers in Medusa v2 run inside the payment module's scoped * container, which is isolated from the application container where the * PayPal module service lives. This resolver bypasses the container boundary * entirely by reading credentials directly from the database via pgConnection * (knex), which Medusa injects into every module container. * * Same source of truth (paypal_connection / paypal_settings tables), zero * cross-container dependencies. */ export declare class PayPalCredentialResolver { private db; private tokenRefreshPromise; constructor(pgConnection: any); private getConnectionRow; /** * Resolve the amount an admin actually requested for a capture. * * Medusa does NOT pass the requested capture amount to the provider — only * `context.idempotency_key`, which is the Medusa `capture` row id. Without * this lookup the provider can only capture the full session amount, which * over-charges the buyer on partial captures. Returns null when the id * doesn't resolve (caller falls back to the session amount). */ getRequestedCaptureAmount(captureRowId: string): Promise; /** * Sum of the capture amounts Medusa has already booked on the same payment * as `captureRowId`, EXCLUDING that row (which Medusa creates before calling * the provider). Lets `capturePayment` reconcile against Medusa's own ledger: * whatever PayPal holds beyond this figure is a capture Medusa lost track of * (its write failed and the admin is retrying with a fresh row) and must not * be taken from the buyer a second time. Returns null when the row can't be * resolved, in which case the caller falls back to PayPal's remaining amount. */ getBookedCaptureTotal(captureRowId: string): Promise; private getEnvCreds; getActiveCredentials(): Promise; getAccessToken(): Promise; private refreshAccessToken; getSettings(): Promise; recordAuditEvent(eventType: string, metadata?: Record): Promise; recordMetric(name: string, metadata?: Record): Promise; } export {}; //# sourceMappingURL=credential-resolver.d.ts.map