import { FactoryStorageDomain } from '@mastra/core/storage'; import type { CollectionSchema } from '@mastra/core/storage'; /** * A reverse index from a platform sender identity to a Mastra tenant. * * Inbound channel events (a Slack DM, a Discord mention, ...) carry only the * platform-side sender ids — there is no Mastra `(orgId, userId)` on the event. * Model credentials, however, resolve **per-tenant**, so a channel run cannot * load the sender's stored model credentials until we know which tenant the * sender is. This domain holds that mapping: an authenticated web user links * their platform account, and the dispatch seam reads it back to stamp the * tenant onto the run's request context. * * One row per `(platform, external_team_id, external_user_id)` — the same * platform user in two workspaces (two team ids) is two independent links, so * multi-workspace falls out of the key. `platform` is generic (`'slack'` today, * reusable for Discord/Telegram later). The `external_` prefix disambiguates * the platform-side ids from the tenant ids (`org_id` / `user_id`) that cohabit * the row. */ export interface ChannelAccountLink { /** Undefined for personal accounts (no organization). */ orgId?: string; userId: string; /** * Which Factory project this sender's channel runs route to. Unset until * the user picks one (or the dispatch path auto-stamps their only factory). */ defaultFactoryProjectId?: string; linkedAt: Date; } /** The reverse-lookup key: a platform sender identity. */ export interface ChannelAccountLinkKey { platform: string; externalTeamId: string; externalUserId: string; } /** * Human-readable labels for a linked identity, captured at link time (e.g. * from Slack OIDC id_token claims). Display-only — never part of the key. */ export interface ChannelAccountLinkNames { externalTeamName?: string; externalUserName?: string; } export declare const CHANNEL_ACCOUNT_LINKS_SCHEMA: CollectionSchema; /** A link row with its platform sender key, as listed for a tenant user. */ export interface ChannelAccountLinkEntry extends ChannelAccountLink, ChannelAccountLinkKey, ChannelAccountLinkNames { } export declare class ChannelIdentityStorage extends FactoryStorageDomain { #private; constructor(); init(): Promise; dangerouslyClearAll(): Promise; /** * Bind a platform sender identity to a Mastra tenant. Last-write-wins: a * re-link (e.g. the same Slack user connecting a different tenant) replaces * the stored tenant and refreshes `linkedAt`. */ saveAccountLink({ platform, externalTeamId, externalUserId, orgId, userId, externalTeamName, externalUserName, }: ChannelAccountLinkKey & ChannelAccountLinkNames & { orgId?: string; userId: string; }): Promise; /** * Set (or clear, with `null`) which Factory project a link's channel runs * route to. The `userId` guard makes this self-service only — a caller can * never repoint another tenant's link. Returns whether a row was updated. * * Note: `saveAccountLink` deliberately omits this column from its upsert * row, so a re-link keeps the stored default. */ setDefaultFactory({ platform, externalTeamId, externalUserId, userId, factoryProjectId, }: ChannelAccountLinkKey & { userId: string; factoryProjectId: string | null; }): Promise; /** Resolve the tenant a platform sender is linked to, or `null` if unlinked. */ getAccountLink({ platform, externalTeamId, externalUserId, }: ChannelAccountLinkKey): Promise; /** Remove a platform sender's link. Returns whether a row was deleted. */ deleteAccountLink({ platform, externalTeamId, externalUserId }: ChannelAccountLinkKey): Promise; /** * All platform identities linked to a tenant user, for the "Connected * accounts" settings surface. Keyed by the tenant `userId` alone — a link * belongs to the person, and their personal/org context at link time does * not change who may see or sever it. */ listAccountLinksForUser(userId: string): Promise; /** All links bound to an organization, for the mention-roster fallback. */ listAccountLinksForOrg(orgId: string, { limit }?: { limit?: number; }): Promise; /** * Remove one of the tenant user's own links, addressed by its sender key. * The `userId` guard makes the delete self-service only: a caller can never * sever another tenant's link even with a known sender key. */ deleteAccountLinkForUser({ userId, platform, externalTeamId, externalUserId, }: ChannelAccountLinkKey & { userId: string; }): Promise; } //# sourceMappingURL=base.d.ts.map