/** * Small-object candidate and exact-version read transport for sync protocol v2. * * This module deliberately knows no bucket, object key, or S3 client. The * control-plane routes resolve those coordinates server-side and issue a * short-lived URL. A candidate PUT returns the immutable S3 VersionId from * S3's response; exact reads verify that same response header before exposing * an unbuffered body to the caller. Consequently this seam cannot fall back * to a latest-object read or materialize candidate bytes locally. */ import type { RealtimeLease } from "./lease-client.js"; import { type RealtimeCapabilityVector } from "./realtime-rollout.js"; export declare const MAX_SMALL_CANDIDATE_BYTES: number; export declare const MAX_SYNC_DESCRIPTOR_LIFETIME_MS = 60000; export interface CandidateFetchResponse { ok: boolean; status: number; headers: { get(name: string): string | null; }; /** Never consumed here: durable staging owns any byte materialization. */ body: AsyncIterable | null; text(): Promise; } export type CandidateFetch = (input: string, init?: { method?: string; headers?: Record; body?: string | Uint8Array; signal?: AbortSignal; }) => Promise; export interface CandidateTransportAuthorization { bearer: string; deviceId: string; capabilityVector: RealtimeCapabilityVector; lease: RealtimeLease; } export interface CandidateUploaderOptions { apiUrl: string; fetchImpl?: CandidateFetch; now?: () => number; authorizationTimeoutMs?: number; } export interface SmallCandidateUploadInput { authorization: CandidateTransportAuthorization; attemptId: string; bytes: Uint8Array; } export interface SmallCandidateUploadResult { candidateVersionId: string; sha256: `sha256:${string}`; size: number; } export interface ExactVersionDescriptor { url: string; expiresAt: string; versionId: string; sha256: `sha256:${string}`; size: number; } export interface ExactVersionRead extends ExactVersionDescriptor { /** The caller owns consumption, hashing, staging, and durable application. */ body: AsyncIterable | null; } /** * A bounded, fail-closed V2 transport. Its operations intentionally do not * retry a presigned byte request: retrying a possibly-completed PUT could * create a different S3 VersionId. Recovery is status-driven in later units. */ export declare class CandidateUploader { private readonly apiUrl; private readonly fetchImpl; private readonly now; private readonly authorizationTimeoutMs; constructor(options: CandidateUploaderOptions); /** Authorize a small candidate PUT and return S3's exact immutable VersionId. */ uploadSmall(input: SmallCandidateUploadInput): Promise; /** Open a server-resolved committed delta; never accepts S3 coordinates. */ openCommittedContent(authorization: CandidateTransportAuthorization, deltaId: string): Promise; /** Open a creator-authorized candidate recovery object at its exact VersionId. */ openCandidate(authorization: CandidateTransportAuthorization, attemptId: string): Promise; private openExactVersion; private controlJson; private controlHeaders; private assertAuthorization; private assertDescriptorLifetime; private requestPresigned; } //# sourceMappingURL=candidate-uploader.d.ts.map