import type { RequestContext } from '@mastra/core/request-context'; import type { ApiRoute, IUserProvider } from '@mastra/core/server'; import type { Context } from 'hono'; import type { RouteAuth } from '../../../routes/route.js'; import type { FactoryProjectsStorage } from '../projects/base.js'; import type { AuditAction } from './actions.js'; import type { AuditActorProfileInput, AuditContext, AuditEventPage, AuditEventRow, AuditStorage, AuditTarget, ListAuditEventsInput, RecordAuditEventInput } from './base.js'; export interface EmitAuditInput { action: AuditAction; factoryProjectId?: string; projectRepositoryId?: string; targets: AuditTarget[]; metadata?: Record; } export interface EmitAgentAuditInput { action: AuditAction; targets: AuditTarget[]; metadata?: Record; } export interface AuditEmitter { emit(args: { context: Context; input: EmitAuditInput; }): Promise; } export interface AuditAgentEmitter { emitAgent(args: { requestContext: RequestContext; input: EmitAgentAuditInput; }): Promise; } /** Records with an explicit actor, for the paths that have no request: rule transitions, run starts, run ends, supervisor tools. */ export type AuditRecorder = Pick; /** Best-effort destination for locally persisted audit events (e.g. an integration's audit log). */ export interface AuditSink { id: string; audit?(args: { event: AuditEventRow; }): Promise; } export interface AuditDomainOptions { auth: RouteAuth; /** Audit storage domain handle. */ audit: AuditStorage; /** Projects domain handle, used to scope the audit trail route. */ projects: FactoryProjectsStorage; /** Resolve persisted human actor ids to display names and profile images. */ users?: Pick; /** Best-effort fan-out destinations notified after each recorded event. */ sinks?: AuditSink[]; /** Resolve the acting tenant for agent-emitted events from the request context. */ agentTenant?: (requestContext: RequestContext) => { orgId?: string; userId?: string; } | undefined; } export declare function auditRequestContext(c: Context): AuditContext; /** Who a browser request is and where it came from: the pair every funnel row carries. */ export declare function auditRequestOrigin(c: Context): { actorProfile: AuditActorProfileInput | undefined; context: AuditContext; }; /** Factory-owned audit behavior backed by the audit storage domain. */ export declare class AuditDomain implements AuditEmitter, AuditAgentEmitter { #private; constructor({ auth, audit, projects, users, sinks, agentTenant }: AuditDomainOptions); record(input: RecordAuditEventInput): Promise; list(input: ListAuditEventsInput): Promise; emit({ context, input }: { context: Context; input: EmitAuditInput; }): Promise; emitAgent({ requestContext, input, }: { requestContext: RequestContext; input: EmitAgentAuditInput; }): Promise; routes(): ApiRoute[]; } //# sourceMappingURL=domain.d.ts.map