/** * OAuth contract inputs shared by the real Worker and the OpenAI descriptor * freeze gate. Values in this module are public protocol metadata, not secrets. */ export declare const OPENAI_REVIEW_ORIGIN = "https://openai-mcp.frihet.io"; export declare const FULL_MCP_ORIGIN = "https://mcp.frihet.io"; export declare const FRIHET_CONNECTOR_SCOPE = "frihet:workspace.manage"; /** RFC 7636 S256 challenges are the 32-byte SHA-256 digest encoded as * unpadded base64url, which is always exactly 43 characters. */ export declare function isValidS256CodeChallenge(value: string): boolean; /** RFC 7636 code_verifier ABNF: 43–128 unreserved URI characters. */ export declare function isValidPKCECodeVerifier(value: string): boolean; export type FrihetAccessProfile = "openai" | "full"; /** Fail closed if a Worker deploy omits or mistypes its profile binding. */ export declare function resolveFrihetAccessProfile(value: string | undefined): FrihetAccessProfile; /** * Byte-compatible extraction of the options previously inlined in the Worker. * index.ts spreads this object into the real OAuthProvider constructor. */ export declare const OAUTH_PROVIDER_REVIEW_OPTIONS: { apiRoute: string; authorizeEndpoint: string; tokenEndpoint: string; clientRegistrationEndpoint: string; scopesSupported: string[]; accessTokenTTL: number; refreshTokenTTL: number; allowPlainPKCE: false; resourceMetadata: { resource: string; authorization_servers: string[]; scopes_supported: string[]; bearer_methods_supported: string[]; resource_name: string; }; }; export type OAuthBoundaryError = "invalid_target" | "invalid_scope"; export type OAuthBoundaryResult = { ok: true; } | { ok: false; error: OAuthBoundaryError; description: string; }; interface OAuthBoundaryParameters { resource?: string | string[]; scope?: string | string[]; /** The authorization request creates the grant and must carry the canonical * resource. Later token/refresh requests may omit it because the provider * inherits the already-validated value stored on that grant. */ requireResource: boolean; /** Authorization requests must include the advertised scope. Token refresh * requests may omit it because the provider reuses the validated grant. */ requireScope: boolean; } /** * Validate the two OAuth values that form the reviewed-host authorization * boundary. RFC 8707 resource comparison is exact by design: accepting an * arbitrary absolute URI would let a token minted by one Frihet Worker target * the other Worker. Unknown or empty scopes are rejected instead of silently * downscoping to an empty token. */ export declare function validateOAuthBoundary(parameters: OAuthBoundaryParameters, expectedResource: string): OAuthBoundaryResult; export declare function buildOpenAIUnauthorizedChallenge(origin?: string): string; /** * Materialize the public metadata generated by workers-oauth-provider 0.3.0 * from the same options used by the Worker. The dependency version is pinned * separately in the canonical descriptor snapshot. */ export declare function buildOpenAIReviewOAuthContract(origin?: string): { authorizationServer: { issuer: string; authorization_endpoint: string; token_endpoint: string; registration_endpoint: string; scopes_supported: string[]; response_types_supported: string[]; response_modes_supported: string[]; grant_types_supported: string[]; token_endpoint_auth_methods_supported: string[]; revocation_endpoint: string; code_challenge_methods_supported: string[]; client_id_metadata_document_supported: boolean; }; protectedResource: { resource: string; authorization_servers: string[]; scopes_supported: string[]; bearer_methods_supported: string[]; resource_name: string; }; wwwAuthenticate: { resourceMetadataUrl: string; missingTokenHeader: string; }; }; export {}; //# sourceMappingURL=openai-review-oauth.d.ts.map