import { PermissionDefinition, PermissionResolver } from '@happyvertical/smrt-users'; /** The permission slug that authorises activating a persona directive. */ export declare const ACTIVATE_DIRECTIVE_PERMISSION = "personas.activate-directive"; /** Catalog definition contributed for {@link ACTIVATE_DIRECTIVE_PERMISSION}. */ export declare const DIRECTIVE_ACTIVATION_PERMISSION_DEF: PermissionDefinition; /** * An actor whose authority is expressed as a set of held permission slugs. * * Deliberately minimal so the gate depends only on the permission model, not on * any particular resolver or session machinery. */ export interface DirectivePrincipal { /** Optional stable id (recorded as the reviewer on approve/reject). */ readonly id?: string; /** * The tenant this principal's authority was resolved for. Permissions are * resolved per tenant (`PermissionResolver.resolvePermissions(userId, tenantId)`), * so a principal authorised in one tenant must not activate another tenant's * directive. When set, the approval service enforces * `principal.tenantId === proposal.tenantId`. `undefined` skips the check * (e.g. a system/global actor or a hand-built principal). */ readonly tenantId?: string; /** Whether this actor holds the given permission slug. */ can(slug: string): boolean; } /** * Build a {@link DirectivePrincipal} from an explicit set of granted slugs. */ export declare function principalFromPermissions(permissions: Iterable, options?: { id?: string; tenantId?: string; }): DirectivePrincipal; /** * Build a {@link DirectivePrincipal} for a user in a tenant by resolving their * effective permissions through the RBAC {@link PermissionResolver} — the * production wiring that makes the gate concretely the permission system. */ export declare function resolveDirectivePrincipal(options: { resolver: PermissionResolver; userId: string; tenantId: string; }): Promise; /** * Register the persona directive-activation permission into the runtime catalog. * * @returns An unregister function (primarily for tests). */ export declare function registerPersonaPermissions(): () => void; /** * Register the persona permissions once per process. Called as a side effect * from the package entry so the slug is present in the permission catalog for * any consumer that imports `@happyvertical/smrt-personas`. */ export declare function ensurePersonaPermissionsRegistered(): void; //# sourceMappingURL=directive-principal.d.ts.map