{
  "version": 3,
  "sources": ["../../../../node_modules/@sniptt/guards/lib/guards/primitives.ts", "../../../../node_modules/@sniptt/guards/lib/guards/structural.ts", "../../../../node_modules/@sniptt/guards/lib/guards/convenience.ts", "../../../../node_modules/@sniptt/guards/lib/index.ts", "../../../../src/logic-functions/post-install.logic-function.ts", "twenty-sdk-define-stub:__twenty-sdk-define-stub__", "../../../../src/constants/logic-function-identifiers.ts", "../../../../src/enrichment/field-specs.ts", "../../../../src/scoring/defaults.ts", "../../../../src/scoring/field-access.ts", "../../../../src/scoring/rules/company-identified.rule.ts", "../../../../src/scoring/rules/compliance-opt-out.rule.ts", "../../../../src/scoring/rules/helpers.ts", "../../../../src/scoring/rules/contact-decision-maker.rule.ts", "../../../../src/scoring/rules/contact-email-valid.rule.ts", "../../../../src/scoring/rules/contact-named-person.rule.ts", "../../../../src/scoring/rules/contact-phone-valid.rule.ts", "../../../../src/scoring/rules/contact-shared-inbox.rule.ts", "../../../../src/scoring/rules/data-freshness.rule.ts", "../../../../src/scoring/rules/icp-company-size.rule.ts", "../../../../src/scoring/rules/icp-industry.rule.ts", "../../../../src/scoring/rules/icp-region.rule.ts", "../../../../src/scoring/rules/index.ts", "../../../../src/scoring/types.ts", "../../../../src/scoring/config.ts", "../../../../src/logic-functions/greenlight-api.ts", "../../../../src/backfill/field-mapping-check.ts", "../../../../src/backfill/backfill-plan.ts", "../../../../src/backfill/backfill-state.ts", "../../../../src/logic-functions/greenlight-config-record.ts", "../../../../src/calibration/canonical.ts", "../../../../src/calibration/keys.ts", "../../../../src/calibration/types.ts", "../../../../src/calibration/parse.ts", "../../../../src/calibration/verify.ts", "../../../../src/calibration/seal.ts", "../../../../src/licensing/cache.ts", "../../../../src/calibration/state.ts", "../../../../src/calibration/refresh.ts", "../../../../src/gate/release-decision.ts", "../../../../src/gate/suppression-decision.ts", "../../../../src/logic-functions/scoring-run.ts", "../../../../src/logic-functions/backfill-run.ts", "../../../../node_modules/twenty-shared/dist/is-record-object-schema-CwzshFdt.mjs", "../../../../node_modules/twenty-shared/dist/logic-function.mjs", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/errors/app-connection-auth-failed.error.ts", "../../../../node_modules/twenty-shared/dist/FieldMetadataType-PppCGM82.mjs", "../../../../node_modules/twenty-shared/dist/get-system-view-universal-identifier.util-CJoglbKX.mjs", "../../../../node_modules/twenty-shared/dist/application.mjs", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/utils/post-graphql-request.util.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/get-connection.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/list-connections.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/find-connection-for-request.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/agents/run-agent.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/jobs/enqueue-job.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/key-value/kv.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/response.ts", "../../../../src/constants/backfill-identifiers.ts", "../../../../src/logic-functions/backfill-state-store.ts", "../../../../src/logic-functions/install-run.ts", "../../../../src/constants/licence-identifiers.ts", "../../../../src/logic-functions/licence-cache-store.ts", "../../../../src/licensing/parse.ts", "../../../../src/licensing/mask.ts", "../../../../src/logic-functions/licence-http-client.ts", "../../../../src/licensing/audit.ts", "../../../../src/licensing/entitlement.ts", "../../../../src/licensing/state.ts", "../../../../src/logic-functions/licence-cache-seal.ts", "../../../../src/logic-functions/licence-run.ts", "../../../../src/logic-functions/licence-workspace-identity.ts"],
  "sourcesContent": [null, null, null, null, "import { CoreApiClient } from 'twenty-client-sdk/core';\nimport {\n  definePostInstallLogicFunction,\n  type InstallPayload,\n} from 'twenty-sdk/define';\n\nimport { POST_INSTALL_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER } from 'src/constants/logic-function-identifiers';\nimport { requestInstallBackfill } from 'src/logic-functions/backfill-run';\nimport { kvBackfillStateStore } from 'src/logic-functions/backfill-state-store';\nimport { runPostInstall } from 'src/logic-functions/install-run';\nimport {\n  kvCalibrationStore,\n  kvLicenceStore,\n} from 'src/logic-functions/licence-cache-store';\nimport { createHttpLicensingClient } from 'src/logic-functions/licence-http-client';\nimport {\n  readLicenceEnvironment,\n  runLicenceInstall,\n} from 'src/logic-functions/licence-run';\nimport { metadataWorkspaceIdentity } from 'src/logic-functions/licence-workspace-identity';\n\n/**\n * Seed (fresh install) or merge (upgrade) the workspace's `GreenlightConfig`.\n *\n * ## Where the values come from\n *\n * `buildDefaultConfig()` in the scoring engine, via\n * `buildGreenlightConfigSeed()`. Nothing here invents a threshold. The seed is\n * written **explicitly** rather than left to the field manifests'\n * `defaultValue`s: the manifests currently carry bands 80/60/40 with gate 40\n * while the engine scores against 85/70/50 with gate 50, and a config record\n * that disagrees with the code that reads it is worse than no record at all.\n * The manifest defaults remain a safety net for records created by hand; the\n * engine is the source of truth for records this app creates. Full reasoning in\n * `greenlight-config-record.ts`.\n *\n * ## Execution model\n *\n * `shouldRunSynchronously: false` (the default). Seeding is one query and one\n * mutation, so speed is not the argument \u2014 retries are. Async post-install is\n * enqueued with `retryLimit: 3`, and a transient API failure during install\n * should be retried rather than surfaced as `POST_INSTALL_ERROR` to whoever\n * clicked Install. The cost is that the install response returns before the\n * record exists; that costs nothing here, because `scoreLead` treats a missing\n * config as \"use the built-in defaults\" and reports it as a degradation, which\n * is the same configuration the seed would have written.\n *\n * `shouldRunOnVersionUpgrade: true` is what makes the `previousVersion` branch\n * reachable at all \u2014 without it the hook only ever runs on fresh installs and\n * the merge path is dead code.\n *\n * ## Idempotency\n *\n * Creation happens only when the workspace has zero config records; every other\n * path either patches missing keys or does nothing. Re-running creates nothing\n * new. See `runPostInstall` for the duplicate-tolerance argument.\n */\n/**\n * ## Ordering, and why nothing here is wrapped in a try\n *\n * Three steps, in this order, and the order is load-bearing:\n *\n *   1. `runPostInstall` seeds or merges the config record. Deliberately **not**\n *      caught: its thrown error is what buys the three platform retries. Wrap it\n *      and a transient API blip becomes a workspace permanently running on\n *      engine defaults.\n *   2. `requestInstallBackfill` must come *after* the seed, or the first cron\n *      tick scores a chunk against defaults instead of the customer's config.\n *   3. Licence validation runs last and is best-effort. Config seeding is the\n *      critical path and must not wait on a network call to Numaya.\n *\n * Steps 2 and 3 never throw \u2014 every failure they have degrades to something\n * visible (an unstarted backfill, rules-only scoring) rather than failing the\n * install. That is why they need no try/catch and must not be given one.\n */\nconst handler = async (payload: InstallPayload) => {\n  const client = new CoreApiClient();\n\n  const config = await runPostInstall({ client, payload });\n\n  const backfill = await requestInstallBackfill({\n    client,\n    store: kvBackfillStateStore,\n    now: new Date(),\n  });\n\n  const environment = readLicenceEnvironment();\n  const licence = await runLicenceInstall({\n    licensing: createHttpLicensingClient({\n      baseUrl: environment.baseUrl,\n      environment: environment.environment,\n    }),\n    store: kvLicenceStore,\n    // Fetched at install too, so a licensed workspace is calibrated from its\n    // very first scored lead rather than from the first night after install.\n    calibration: kvCalibrationStore,\n    identity: metadataWorkspaceIdentity,\n    client,\n    licenceKey: environment.licenceKey,\n    environment: environment.environment,\n    now: new Date(),\n  });\n\n  return {\n    ...config,\n    backfill,\n    licence: { mode: licence.state.mode, reason: licence.state.reason },\n  };\n};\n\nexport default definePostInstallLogicFunction({\n  universalIdentifier: POST_INSTALL_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER,\n  name: 'greenlight-post-install',\n  description:\n    'Seeds the Greenlight configuration record on install and merges newly-shipped configuration keys on upgrade.',\n  // The platform default is 300s, sized for bulk data seeding. This hook issues\n  // one query and at most two mutations against a single-row object, so 60s is\n  // already an order of magnitude of headroom. Failing fast matters more than\n  // hanging on: the run is retried three times, and every retry is cheap.\n  timeoutSeconds: 60,\n  shouldRunOnVersionUpgrade: true,\n  shouldRunSynchronously: false,\n  handler,\n});\n", "\n// Auto-generated stub for twenty-sdk/define injected by the SDK CLI build.\n// Real implementations would pull in zod, twenty-shared and ~1MB of code; at\n// runtime only `default.config.handler` is consumed, so tiny no-ops suffice.\nconst __defineFactoryStub = (config) => ({\n  success: true,\n  config,\n  errors: [],\n});\n\nconst __anyHandler = {\n  get(_target, prop) {\n    if (prop === '__esModule') return true;\n    if (prop === Symbol.toPrimitive) return () => '';\n    if (typeof prop === 'symbol') return undefined;\n    return new Proxy(() => undefined, __anyHandler);\n  },\n  apply() {\n    return new Proxy(() => undefined, __anyHandler);\n  },\n};\nconst __anyStub = new Proxy(() => undefined, __anyHandler);\n\nexport const createValidationResult = __defineFactoryStub;\nexport const defineAgent = __defineFactoryStub;\nexport const defineApplication = __defineFactoryStub;\nexport const defineApplicationRole = __defineFactoryStub;\nexport const defineCommandMenuItem = __defineFactoryStub;\nexport const defineConnectionProvider = __defineFactoryStub;\nexport const defineField = __defineFactoryStub;\nexport const defineFrontComponent = __defineFactoryStub;\nexport const defineIndex = __defineFactoryStub;\nexport const defineLogicFunction = __defineFactoryStub;\nexport const defineNavigationMenuItem = __defineFactoryStub;\nexport const defineObject = __defineFactoryStub;\nexport const definePageLayout = __defineFactoryStub;\nexport const definePageLayoutTab = __defineFactoryStub;\nexport const definePermissionFlag = __defineFactoryStub;\nexport const definePostInstallLogicFunction = __defineFactoryStub;\nexport const definePreInstallLogicFunction = __defineFactoryStub;\nexport const defineRole = __defineFactoryStub;\nexport const defineSettingsFrontComponent = __defineFactoryStub;\nexport const defineSkill = __defineFactoryStub;\nexport const defineUninstallLogicFunction = __defineFactoryStub;\nexport const defineView = __defineFactoryStub;\nexport const defineViewField = __defineFactoryStub;\nexport const AggregateOperations = __anyStub;\nexport const DateDisplayFormat = __anyStub;\nexport const FieldMetadataSettingsOnClickAction = __anyStub;\nexport const FieldType = __anyStub;\nexport const HTTPMethod = __anyStub;\nexport const NavigationMenuItemType = __anyStub;\nexport const NumberDataType = __anyStub;\nexport const ObjectRecordGroupByDateGranularity = __anyStub;\nexport const OnDeleteAction = __anyStub;\nexport const PageLayoutTabLayoutMode = __anyStub;\nexport const PageLayoutType = __anyStub;\nexport const RelationType = __anyStub;\nexport const RowLevelPermissionPredicateGroupLogicalOperator = __anyStub;\nexport const RowLevelPermissionPredicateOperand = __anyStub;\nexport const STANDARD_OBJECT = __anyStub;\nexport const STANDARD_OBJECT_UNIVERSAL_IDENTIFIERS = __anyStub;\nexport const STANDARD_PAGE_LAYOUT = __anyStub;\nexport const STANDARD_PAGE_LAYOUT_UNIVERSAL_IDENTIFIERS = __anyStub;\nexport const SystemPermissionFlag = __anyStub;\nexport const ViewCalendarLayout = __anyStub;\nexport const ViewFilterGroupLogicalOperator = __anyStub;\nexport const ViewFilterOperand = __anyStub;\nexport const ViewKey = __anyStub;\nexport const ViewOpenRecordIn = __anyStub;\nexport const ViewSortDirection = __anyStub;\nexport const ViewType = __anyStub;\nexport const ViewVisibility = __anyStub;\nexport const canAccessFullAdminPanel = __anyStub;\nexport const canImpersonate = __anyStub;\nexport const every = __anyStub;\nexport const everyDefined = __anyStub;\nexport const everyEquals = __anyStub;\nexport const favoriteRecordIds = __anyStub;\nexport const featureFlags = __anyStub;\nexport const getFieldUniversalIdentifier = __anyStub;\nexport const getSystemRelationFieldUniversalIdentifier = __anyStub;\nexport const getSystemViewFieldUniversalIdentifier = __anyStub;\nexport const getSystemViewUniversalIdentifier = __anyStub;\nexport const hasAnySoftDeleteFilterOnView = __anyStub;\nexport const includes = __anyStub;\nexport const includesEvery = __anyStub;\nexport const isDashboardPageLayoutInEditMode = __anyStub;\nexport const isDefined = __anyStub;\nexport const isInSidePanel = __anyStub;\nexport const isLayoutCustomizationModeEnabled = __anyStub;\nexport const isNonEmptyString = __anyStub;\nexport const isSelectAll = __anyStub;\nexport const none = __anyStub;\nexport const noneDefined = __anyStub;\nexport const noneEquals = __anyStub;\nexport const numberOfSelectedRecords = __anyStub;\nexport const objectMetadataItem = __anyStub;\nexport const objectMetadataLabel = __anyStub;\nexport const objectPermissions = __anyStub;\nexport const pageType = __anyStub;\nexport const selectedRecords = __anyStub;\nexport const some = __anyStub;\nexport const someDefined = __anyStub;\nexport const someEquals = __anyStub;\nexport const someNonEmptyString = __anyStub;\nexport const targetObjectReadPermissions = __anyStub;\nexport const targetObjectWritePermissions = __anyStub;\nexport const validateFields = __anyStub;\n", "/**\n * Permanent identifiers for Greenlight's logic functions.\n *\n * Same permanence rule as `universal-identifiers.ts`: a logic function's\n * `universalIdentifier` is how Twenty recognises an existing registration across\n * upgrades. Change one and the workspace gets a *second* function registered\n * alongside the old one \u2014 for a database-event trigger that means every Person\n * event is handled twice, and every scored lead gets two audit rows. Never edit\n * a value in this file. Adding is fine.\n *\n * These live apart from `universal-identifiers.ts` purely so two workstreams can\n * add entities without fighting over the same file.\n */\n\nexport const POST_INSTALL_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'feb529fe-4048-49cd-a304-bef009952699';\n\nexport const UNINSTALL_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  '4219d61c-c663-44d3-9978-758f89862ece';\n\n/**\n * Scoring is registered twice because `databaseEventTriggerSettings.eventName`\n * is a single string, not a list \u2014 see `score-person-created.logic-function.ts`\n * for why two narrow registrations beat one `person.*` wildcard.\n */\nexport const SCORE_PERSON_CREATED_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  '03736f42-ea80-4de7-9ae1-1264cc1adad0';\n\nexport const SCORE_PERSON_UPDATED_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'f3d817a4-806b-488a-9707-1988c58acee7';\n", "/**\n * The enrichable field catalogue: what may be asked for, in what shape.\n *\n * One table, read by three consumers that must not disagree \u2014 the prompt (what\n * the model is asked), the extractor (what is accepted back) and the gap\n * analysis (what is worth asking about at all). Keeping them keyed off the same\n * array is what stops the classic drift where a field is prompted for and then\n * silently discarded, or accepted without ever being requested.\n *\n * Every entry answers a *firmographic* question. Nothing here is a contact\n * detail: see the note on `EnrichableFieldKey` for why that boundary is a hard\n * one rather than a starting point.\n */\n\nimport type {\n  EnrichableFieldKey,\n  EnrichableFieldSpec,\n} from 'src/enrichment/types';\n\nexport const ENRICHABLE_FIELD_SPECS: readonly EnrichableFieldSpec[] = [\n  {\n    key: 'industry',\n    label: 'Industry',\n    question: \"What industry does this person's employer operate in?\",\n    kind: 'text',\n    maxLength: 60,\n  },\n  {\n    key: 'region',\n    label: 'Region',\n    question: 'Which country or region is the employer headquartered in?',\n    kind: 'text',\n    maxLength: 60,\n  },\n  {\n    key: 'employeeCount',\n    label: 'Employee count',\n    question: 'Approximately how many people does the employer employ?',\n    kind: 'integer',\n    maxLength: 12,\n  },\n  {\n    key: 'jobTitle',\n    label: 'Job title',\n    question: 'What is this person\u2019s job title at that employer?',\n    kind: 'text',\n    maxLength: 120,\n  },\n  {\n    key: 'seniority',\n    label: 'Seniority',\n    question:\n      'What seniority level does that job title correspond to (for example: C-level, VP, Director, Manager, Individual contributor)?',\n    kind: 'text',\n    maxLength: 40,\n  },\n];\n\nconst SPEC_BY_KEY: ReadonlyMap<string, EnrichableFieldSpec> = new Map(\n  ENRICHABLE_FIELD_SPECS.map((spec) => [spec.key, spec]),\n);\n\nexport const findFieldSpec = (key: string): EnrichableFieldSpec | null =>\n  SPEC_BY_KEY.get(key) ?? null;\n\nexport const isEnrichableFieldKey = (key: unknown): key is EnrichableFieldKey =>\n  typeof key === 'string' && SPEC_BY_KEY.has(key);\n\n/**\n * The dotted paths a workspace adds to its Layer 3 field mapping to let the\n * deterministic scorer read enriched values.\n *\n * Published from here rather than hard-coded in the config seed because the\n * shape of the provenance blob is this module's business, and a path written out\n * by hand somewhere else is a path that goes stale the first time the blob's\n * version changes.\n *\n * The ordering is the important part: the enriched path goes **after** the\n * workspace's own candidates in every mapping, never before. `field-access.ts`\n * tries candidates in order and takes the first that yields a value, so a human\n * value always wins and enrichment only ever fills a hole. That is the same\n * promise the storage shape makes \u2014 enrichment never overwrites a person \u2014 held\n * at the read side as well as the write side.\n */\nexport const enrichedFieldMappingPath = (key: EnrichableFieldKey): string =>\n  `greenlightEnrichment.fields.${key}.parsedValue`;\n\nexport const ENRICHED_FIELD_MAPPING_PATHS: Readonly<\n  Record<EnrichableFieldKey, string>\n> = Object.freeze(\n  Object.fromEntries(\n    ENRICHABLE_FIELD_SPECS.map((spec) => [\n      spec.key,\n      enrichedFieldMappingPath(spec.key),\n    ]),\n  ) as Record<EnrichableFieldKey, string>,\n);\n", "/**\n * Seeded defaults.\n *\n * \"Defaults are the feature.\" A configurable product that ships empty is a\n * homework assignment \u2014 these values are what the post-install hook writes into\n * the config record, and they are also the fall-back the engine uses whenever\n * configuration is missing or unusable.\n *\n * The ICP lists start empty on purpose: an empty list means \"no opinion\", so a\n * fresh install is permissive and nothing is gated for being in the wrong\n * industry before an admin has said what the right industry is.\n */\n\nimport type {\n  FieldMapping,\n  IcpConfig,\n  ScoringBand,\n} from 'src/scoring/types';\n\n/**\n * Default paths into the lead record, tried in order. These are defaults only \u2014\n * rule logic never mentions a field name, it asks for a logical key and the\n * mapping decides where that comes from.\n */\nexport const DEFAULT_FIELD_MAPPING: FieldMapping = {\n  companyName: ['companyName', 'company.name', 'company', 'accountName'],\n  industry: ['industry', 'company.industry', 'sector'],\n  region: ['region', 'country', 'address.addressCountry', 'company.region'],\n  employeeCount: ['employees', 'employeeCount', 'company.employees', 'companySize'],\n  contactName: ['name', 'fullName', 'contactName', 'firstName'],\n  // `position` is deliberately NOT a candidate. On Twenty \u2014 the only platform\n  // this ships on \u2014 `position` is the row-ordering number, not a job title, so\n  // the fallback resolved a real value of `-5` and handed it to the\n  // decision-maker rule as somebody's role. It was visible in a demo recording\n  // before it was visible in a test.\n  //\n  // The subtler half: `src/enrichment/plan.ts` reads this same mapping to decide\n  // whether a human has already answered a field. A resolvable `position` meant\n  // every Twenty Person looked like it already had a job title, so job-title\n  // enrichment could never fire at all.\n  //\n  // A workspace that genuinely stores titles in a field called `position` can\n  // still say so through the Layer 3 mapping. Guessing it by default costs more\n  // than it ever paid.\n  jobTitle: ['jobTitle', 'title', 'role'],\n  seniority: ['seniority', 'seniorityLevel'],\n  email: ['emails', 'email', 'emails.primaryEmail', 'workEmail'],\n  phone: ['phones', 'phone', 'phones.primaryPhoneNumber', 'mobile'],\n  lastVerifiedAt: ['lastVerifiedAt', 'verifiedAt', 'updatedAt', 'createdAt'],\n\n  // Greenlight's own suppression columns. Single-candidate and not extended by\n  // the Layer 3 mapping, unlike every other key here: these are fields the app\n  // ships and owns, so \"where does this live\" has exactly one answer. A\n  // workspace's *own* opt-out columns are `optedOut` below, and the compliance\n  // rule takes the union of the two rather than letting either win.\n  suppressed: ['greenlightSuppressed'],\n  suppressionReason: ['greenlightSuppressionReason'],\n\n  optedOut: ['optedOut', 'doNotContact', 'emailOptOut', 'unsubscribed'],\n};\n\n/** Permissive by default: no industry/region/size opinion until an admin sets one. */\nexport const DEFAULT_ICP: IcpConfig = {\n  industries: [],\n  regions: [],\n  sizeBands: [],\n};\n\n/**\n * Evenly-spaced neutral bands. Published in full in the scoring-model explainer;\n * a scoring product that hides its model does not get trusted by the people\n * whose leads it rejects.\n */\nexport const DEFAULT_BANDS: readonly ScoringBand[] = [\n  { id: 'excellent', label: 'Excellent', minScore: 85 },\n  { id: 'good', label: 'Good', minScore: 70 },\n  { id: 'fair', label: 'Fair', minScore: 50 },\n  { id: 'poor', label: 'Poor', minScore: 0 },\n];\n\n/** The floor of the \"Fair\" band: fair and above is cleared to work. */\nexport const DEFAULT_GATE_THRESHOLD = 50;\n\nexport const DEFAULT_SHELF_LIFE_DAYS = 30;\n\nexport const DEFAULT_DECISION_MAKER_TITLES: readonly string[] = [\n  'ceo',\n  'cto',\n  'cfo',\n  'coo',\n  'cmo',\n  'ciso',\n  'cio',\n  'chief',\n  'founder',\n  'co-founder',\n  'cofounder',\n  'owner',\n  'proprietor',\n  'president',\n  'partner',\n  'principal',\n  'vp',\n  'vice president',\n  'svp',\n  'evp',\n  'head of',\n  'director',\n  'managing director',\n  'general manager',\n  'board member',\n];\n\nexport const DEFAULT_INFLUENCER_TITLES: readonly string[] = [\n  'manager',\n  'lead',\n  'team lead',\n  'supervisor',\n  'architect',\n  'consultant',\n  'coordinator',\n  'buyer',\n  'procurement',\n];\n\nexport const DEFAULT_ROLE_INBOX_LOCAL_PARTS: readonly string[] = [\n  'info',\n  'sales',\n  'support',\n  'admin',\n  'contact',\n  'hello',\n  'hi',\n  'office',\n  'enquiries',\n  'enquiry',\n  'inquiries',\n  'inquiry',\n  'marketing',\n  'help',\n  'billing',\n  'accounts',\n  'accounting',\n  'finance',\n  'careers',\n  'jobs',\n  'hr',\n  'team',\n  'mail',\n  'general',\n  'noreply',\n  'no-reply',\n  'donotreply',\n  'webmaster',\n  'postmaster',\n  'abuse',\n];\n\n/** Values that mean \"somebody typed something rather than nothing\". */\nexport const PLACEHOLDER_VALUES: readonly string[] = [\n  '-',\n  '--',\n  '.',\n  'n/a',\n  'na',\n  'n.a.',\n  'none',\n  'null',\n  'nil',\n  'unknown',\n  'tbd',\n  'tba',\n  'test',\n  'testing',\n  'asdf',\n  'xxx',\n  '???',\n  'no name',\n  'not provided',\n  'not set',\n];\n", "/**\n * Reading values out of a lead record.\n *\n * Two problems are solved here, both of them schema-flexibility problems:\n *\n * 1. Customers name fields differently, so every read goes through the\n *    configured mapping (a list of candidate dotted paths, tried in order).\n * 2. CRM fields are often composite objects (`{ primaryEmail, additionalEmails }`,\n *    `{ firstName, lastName }`). Values are flattened generically by walking\n *    string leaves in key order \u2014 no field name is hard-coded anywhere.\n */\n\nimport { PLACEHOLDER_VALUES } from 'src/scoring/defaults';\nimport type {\n  FieldMapping,\n  FieldObservation,\n  FieldReader,\n  LeadFieldKey,\n  LeadRecord,\n} from 'src/scoring/types';\n\nconst MAX_LEAF_DEPTH = 4;\n\n/** Fail-open coercion of anything the caller has into a `LeadRecord`. */\nexport const toLeadRecord = (record: unknown): LeadRecord => {\n  if (!isPlainObject(record)) {\n    return { id: null, fields: {} };\n  }\n\n  const id = typeof record['id'] === 'string' ? record['id'] : null;\n\n  return { id, fields: record };\n};\n\nexport const isPlainObject = (\n  value: unknown,\n): value is Record<string, unknown> =>\n  typeof value === 'object' &&\n  value !== null &&\n  !Array.isArray(value) &&\n  !(value instanceof Date);\n\n/**\n * Resolve a dotted path against an object. Exact key match first, then a\n * case-insensitive match, so `address.addresscountry` still finds\n * `address.addressCountry`.\n */\nexport const getByPath = (source: unknown, path: string): unknown => {\n  const segments = path.split('.').filter((segment) => segment.length > 0);\n\n  let cursor: unknown = source;\n\n  for (const segment of segments) {\n    if (cursor === null || cursor === undefined) {\n      return undefined;\n    }\n\n    if (Array.isArray(cursor)) {\n      const index = Number(segment);\n      cursor = Number.isInteger(index) ? cursor[index] : undefined;\n      continue;\n    }\n\n    if (!isPlainObject(cursor)) {\n      return undefined;\n    }\n\n    if (segment in cursor) {\n      cursor = cursor[segment];\n      continue;\n    }\n\n    const lowered = segment.toLowerCase();\n    const matchedKey = Object.keys(cursor).find(\n      (key) => key.toLowerCase() === lowered,\n    );\n\n    cursor = matchedKey === undefined ? undefined : cursor[matchedKey];\n  }\n\n  return cursor;\n};\n\n/** Every non-empty string leaf under a value, in key order. */\nexport const stringLeaves = (value: unknown, depth = 0): string[] => {\n  if (depth > MAX_LEAF_DEPTH) {\n    return [];\n  }\n\n  if (typeof value === 'string') {\n    const trimmed = value.trim();\n    return trimmed.length > 0 ? [trimmed] : [];\n  }\n\n  if (typeof value === 'number' && Number.isFinite(value)) {\n    return [String(value)];\n  }\n\n  if (Array.isArray(value)) {\n    return value.flatMap((entry) => stringLeaves(entry, depth + 1));\n  }\n\n  if (value instanceof Date) {\n    return Number.isNaN(value.getTime()) ? [] : [value.toISOString()];\n  }\n\n  if (isPlainObject(value)) {\n    return Object.keys(value).flatMap((key) =>\n      stringLeaves(value[key], depth + 1),\n    );\n  }\n\n  return [];\n};\n\nconst isEmptyValue = (value: unknown): boolean =>\n  value === null ||\n  value === undefined ||\n  (typeof value === 'string' && value.trim().length === 0) ||\n  (Array.isArray(value) && value.length === 0) ||\n  (typeof value === 'number' && Number.isNaN(value)) ||\n  (isPlainObject(value) && stringLeaves(value).length === 0);\n\n/**\n * Whether a value is one of the strings that mean \"somebody typed something\n * rather than nothing\" \u2014 `n/a`, `tbd`, `xxx`, `keine angabe`.\n *\n * `known` defaults to the shipped list so every existing caller keeps its exact\n * behaviour. A rule that has a resolved config passes `config.placeholderValues`\n * instead, which is how a licence-delivered lexicon reaches this check without\n * the rule learning anything about licensing: the list is data, resolved by\n * `resolveConfig`, exactly like `decisionMakerTitles` already was.\n */\nexport const isPlaceholder = (\n  value: string,\n  known: readonly string[] = PLACEHOLDER_VALUES,\n): boolean => known.includes(value.trim().toLowerCase());\n\nexport const toNumberValue = (value: unknown): number | null => {\n  if (typeof value === 'number') {\n    return Number.isFinite(value) ? value : null;\n  }\n\n  if (typeof value === 'boolean') {\n    return null;\n  }\n\n  const leaves = stringLeaves(value);\n\n  for (const leaf of leaves) {\n    // Tolerate \"1,200\", \"1 200\", \"250+\", \"50-200\" (takes the lower bound).\n    const cleaned = leaf.replace(/[,\\s]/g, '');\n    const match = /-?\\d+(\\.\\d+)?/.exec(cleaned);\n\n    if (match !== null) {\n      const parsed = Number(match[0]);\n\n      if (Number.isFinite(parsed)) {\n        return parsed;\n      }\n    }\n  }\n\n  return null;\n};\n\nexport const toDateValue = (value: unknown): Date | null => {\n  if (value instanceof Date) {\n    return Number.isNaN(value.getTime()) ? null : value;\n  }\n\n  if (typeof value === 'number' && Number.isFinite(value)) {\n    const fromEpoch = new Date(value);\n    return Number.isNaN(fromEpoch.getTime()) ? null : fromEpoch;\n  }\n\n  const leaves = stringLeaves(value);\n\n  for (const leaf of leaves) {\n    const parsed = new Date(leaf);\n\n    if (!Number.isNaN(parsed.getTime())) {\n      return parsed;\n    }\n  }\n\n  return null;\n};\n\nconst TRUTHY_TOKENS = new Set([\n  'true',\n  'yes',\n  'y',\n  '1',\n  'opted_out',\n  'opted-out',\n  'optedout',\n  'unsubscribed',\n  'do_not_contact',\n  'do-not-contact',\n  'donotcontact',\n  'dnc',\n  'blocked',\n]);\n\nconst FALSY_TOKENS = new Set([\n  'false',\n  'no',\n  'n',\n  '0',\n  'subscribed',\n  'opted_in',\n  'opted-in',\n  'optedin',\n]);\n\nexport const toBooleanValue = (value: unknown): boolean | null => {\n  if (typeof value === 'boolean') {\n    return value;\n  }\n\n  if (typeof value === 'number' && Number.isFinite(value)) {\n    return value !== 0;\n  }\n\n  const leaves = stringLeaves(value);\n\n  for (const leaf of leaves) {\n    const token = leaf.toLowerCase();\n\n    if (TRUTHY_TOKENS.has(token)) {\n      return true;\n    }\n\n    if (FALSY_TOKENS.has(token)) {\n      return false;\n    }\n  }\n\n  return null;\n};\n\nconst renderDisplay = (value: unknown): string => {\n  if (typeof value === 'boolean') {\n    return value ? 'true' : 'false';\n  }\n\n  const leaves = stringLeaves(value);\n\n  if (leaves.length === 0) {\n    return '(not set)';\n  }\n\n  return leaves.slice(0, 3).join(', ');\n};\n\ninterface Resolution {\n  readonly mappedTo: string | null;\n  readonly candidates: readonly string[];\n  readonly value: unknown;\n  readonly present: boolean;\n}\n\n/**\n * Builds the reader handed to rules. Every lookup is recorded, so a trace entry\n * can tell a salesperson exactly which field was consulted and what was in it.\n */\nexport const createFieldReader = (\n  lead: LeadRecord,\n  mapping: FieldMapping,\n): FieldReader => {\n  const seen = new Map<LeadFieldKey, FieldObservation>();\n\n  const candidatesFor = (key: LeadFieldKey): readonly string[] => {\n    const configured = mapping[key];\n    return Array.isArray(configured) ? configured : [];\n  };\n\n  const resolveAll = (key: LeadFieldKey): Resolution[] => {\n    const candidates = candidatesFor(key);\n\n    return candidates.map((path) => {\n      const value = getByPath(lead.fields, path);\n\n      return {\n        mappedTo: path,\n        candidates,\n        value,\n        present: !isEmptyValue(value),\n      };\n    });\n  };\n\n  const resolve = (key: LeadFieldKey): Resolution => {\n    const candidates = candidatesFor(key);\n    const found = resolveAll(key).find((entry) => entry.present);\n\n    if (found !== undefined) {\n      return found;\n    }\n\n    return { mappedTo: null, candidates, value: undefined, present: false };\n  };\n\n  const record = (key: LeadFieldKey, resolution: Resolution): void => {\n    seen.set(key, {\n      key,\n      mappedTo: resolution.mappedTo,\n      candidates: resolution.candidates,\n      present: resolution.present,\n      display: resolution.present ? renderDisplay(resolution.value) : '(not set)',\n    });\n  };\n\n  const readResolved = (key: LeadFieldKey): Resolution => {\n    const resolution = resolve(key);\n    record(key, resolution);\n    return resolution;\n  };\n\n  return {\n    text: (key) => {\n      const leaves = stringLeaves(readResolved(key).value);\n      return leaves.length > 0 ? leaves.join(' ') : null;\n    },\n    textList: (key) => stringLeaves(readResolved(key).value),\n    number: (key) => toNumberValue(readResolved(key).value),\n    date: (key) => toDateValue(readResolved(key).value),\n    booleanAny: (key) => {\n      const all = resolveAll(key);\n      const present = all.filter((entry) => entry.present);\n      const truthy = present.find((entry) => toBooleanValue(entry.value) === true);\n\n      if (truthy !== undefined) {\n        record(key, truthy);\n        return true;\n      }\n\n      const first = present[0];\n\n      if (first !== undefined) {\n        record(key, first);\n        return toBooleanValue(first.value) === true ? true : false;\n      }\n\n      record(key, {\n        mappedTo: null,\n        candidates: candidatesFor(key),\n        value: undefined,\n        present: false,\n      });\n\n      return null;\n    },\n    observations: () => Array.from(seen.values()),\n  };\n};\n", "import { isPlaceholder } from 'src/scoring/field-access';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const companyIdentifiedRule: ScoringRule = {\n  id: 'company.identified',\n  name: 'Company named',\n  category: 'contact',\n  question: 'Do we know which company this lead works for?',\n  why: 'Every other qualification question \u2014 industry, size, region, territory, existing customer \u2014 depends on knowing the company. A lead with no company is a name floating in space, and a rep has nothing to research before they call.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 10,\n  reads: ['companyName'],\n\n  evaluate: ({ config, read }) => {\n    const name = read.text('companyName');\n\n    if (name === null) {\n      return {\n        outcome: 'fail',\n        explanation: 'No company is recorded on this lead.',\n        remedy: 'Add the company name, or link the lead to a company record.',\n      };\n    }\n\n    if (isPlaceholder(name, config.placeholderValues) || name.trim().length < 2) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${name}\" is a placeholder rather than a real company name.`,\n        remedy: 'Replace it with the real company name.',\n        detail: { companyName: name },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `The lead is attributed to ${name}.`,\n      detail: { companyName: name },\n    };\n  },\n};\n", "import type { RuleVerdict, ScoringRule } from 'src/scoring/types';\n\n/**\n * The one check in the product that is not about lead quality.\n *\n * ## What changed, and why it had to\n *\n * This rule used to read a single logical key, `optedOut`, resolved purely\n * through the customer's Layer 3 field mapping. Twenty ships no email management\n * \u2014 no unsubscribe handling, no bounce tracking, no do-not-contact list \u2014 so on\n * a stock workspace that mapping resolves to nothing at all,\n * `read.booleanAny('optedOut')` returned `null`, and the rule returned `pass`\n * with full credit. The single compliance check in Greenlight could not fire on\n * a default install, and it inflated every score by 15 points while failing to.\n *\n * Greenlight now ships the register itself (`greenlightSuppressed` and friends on\n * Person), and this rule reads it. Two consequences, both deliberate:\n *\n * ## 1. Union, not override\n *\n * Greenlight's field is read *first*, the customer's mapping second, and **any**\n * source saying \"suppressed\" fails the rule. A workspace that already had an\n * opt-out column keeps it working exactly as before, and gains a second register\n * rather than having its own replaced. There is no precedence question, because\n * for a compliance stop there is no argument in which \"the other column says it\n * is fine\" is a reason to send the email.\n *\n * A recorded suppression *reason* counts as suppression on its own, even with\n * the boolean cleared. Untick-the-box-but-leave-`SPAM_COMPLAINT`-behind is the\n * realistic hand edit, and reading it as \"contactable\" would silently re-enable\n * outreach to somebody whose own record still states, in writing, why we\n * stopped. The remedy names both fields so the fix is obvious.\n *\n * ## 2. \"Nobody knows\" is no longer the same answer as \"confirmed clear\"\n *\n * The old rule collapsed two very different states onto `pass` with full marks:\n * *this person has not opted out*, and *nothing anywhere in this workspace\n * records whether they have*. The second is not evidence of compliance; it is\n * the absence of a compliance system, and paying 15 points for it is how a\n * decorative check comes to look like a working one.\n *\n * They are now distinguished:\n *\n *   - **Confirmed clear** \u2014 Greenlight's register says no entry, or the\n *     customer's own opt-out column says false. `pass`, full credit. `false` on\n *     a Greenlight-owned column is a real assertion about a real register, not\n *     an absence.\n *   - **Genuinely unknown** \u2014 neither register is present on the record at all.\n *     `not_applicable`: the engine excludes it from *both* sides of the score, so\n *     the lead is neither credited for evidence it does not have nor punished for\n *     a check nobody could run. The remaining rules are renormalised over the\n *     weight that could actually be evaluated, and the trace says why.\n *\n * `not_applicable` rather than `fail` matters: only a blocking `fail` produces\n * the `blocked` decision, so an unknown never holds a lead. ARCHITECTURE.md's\n * golden rule is that a lead is never lost, and \"we could not check\" is not a\n * reason to stop somebody working a lead \u2014 it is a reason to stop pretending we\n * checked.\n *\n * In practice the unknown branch is what a workspace sees before the suppression\n * fields have synced, or when the engine is driven as a library over a record\n * shape that has neither register. On a synced workspace the field is present on\n * every Person, which is precisely the point: the fix for \"this rule cannot fail\"\n * is shipping somewhere for the answer to live, not re-weighting the rule.\n */\n\n/** `HARD_BOUNCE` -> `hard bounce`, without importing the gate layer's vocabulary. */\nconst humaniseReason = (code: string): string =>\n  code.trim().toLowerCase().replace(/[_-]+/g, ' ');\n\nconst failVerdict = (\n  greenlightSays: boolean,\n  customerSays: boolean,\n  reason: string | null,\n): RuleVerdict => {\n  const because =\n    reason === null ? '' : ` The recorded reason is \"${humaniseReason(reason)}\".`;\n\n  const explanation = greenlightSays\n    ? customerSays\n      ? `This person is on Greenlight's do-not-contact list and is also flagged as opted out in your own CRM field.${because} Contacting them is a compliance breach.`\n      : `This person is on Greenlight's do-not-contact list.${because} Contacting them is a compliance breach.`\n    : 'Your own opt-out field says this person has opted out of contact. Reaching out anyway is a compliance breach.';\n\n  return {\n    outcome: 'fail',\n    explanation,\n    remedy: greenlightSays\n      ? 'Do not contact this lead. If the block was recorded in error, use \"Allow contact again (Greenlight)\" \u2014 it clears both the flag and the reason, records who lifted it and why, and re-scores the lead.'\n      : 'Do not contact this lead. If the opt-out was recorded in error, correct your own opt-out field on the record and say why; the lead re-scores and clears itself.',\n    detail: {\n      suppressed: true,\n      suppressedByGreenlight: greenlightSays,\n      suppressedByCustomerField: customerSays,\n      suppressionReason: reason,\n      // Kept under the original key so anything already reading the trace for\n      // this rule \u2014 dashboards, exports, the release path's fallback \u2014 is not\n      // broken by the new field set.\n      optOutRecorded: true,\n    },\n  };\n};\n\nexport const complianceOptOutRule: ScoringRule = {\n  id: 'compliance.opt-out',\n  name: 'Not opted out',\n  category: 'compliance',\n  question: 'Has this person asked not to be contacted?',\n  why: 'Contacting someone who has opted out is a compliance breach and the fastest way to lose a domain reputation. This is the one check that is not about lead quality at all \u2014 it is about not doing something you are not allowed to do. Greenlight keeps its own do-not-contact register because Twenty has none, and reads any opt-out field the workspace already had alongside it.',\n  defaultEnabled: true,\n  defaultSeverity: 'blocking',\n  defaultWeight: 15,\n  reads: ['suppressed', 'suppressionReason', 'optedOut'],\n\n  evaluate: ({ read }) => {\n    // Greenlight's own register first.\n    const suppressedFlag = read.booleanAny('suppressed');\n    const suppressionReason = read.text('suppressionReason');\n    // Then the customer's, wherever their mapping points.\n    const optedOut = read.booleanAny('optedOut');\n\n    const greenlightSays = suppressedFlag === true || suppressionReason !== null;\n    const customerSays = optedOut === true;\n\n    if (greenlightSays || customerSays) {\n      return failVerdict(greenlightSays, customerSays, suppressionReason);\n    }\n\n    // Neither register is present on this record. Not a pass \u2014 an unanswered\n    // question, excluded from the score rather than paid out at full marks.\n    if (suppressedFlag === null && optedOut === null) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'Nothing on this record says whether this person has asked not to be contacted, so the compliance check could not be answered and was left out of the score rather than passed by default.',\n        remedy:\n          'Greenlight ships a \"Do not contact\" field for exactly this. If it is missing here, the app\u2019s fields have not reached this record yet \u2014 or point Greenlight at your own opt-out column under Opt-out fields in Greenlight settings.',\n        detail: {\n          suppressed: false,\n          suppressedByGreenlight: false,\n          suppressedByCustomerField: false,\n          suppressionReason: null,\n          optOutRecorded: false,\n          suppressionDataAvailable: false,\n        },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation:\n        suppressedFlag === false\n          ? 'Greenlight\u2019s do-not-contact list has no entry for this person, so outreach is permitted.'\n          : 'Your opt-out field is clear on this person, so outreach is permitted.',\n      detail: {\n        suppressed: false,\n        suppressedByGreenlight: false,\n        suppressedByCustomerField: false,\n        suppressionReason: null,\n        optOutRecorded: false,\n        suppressionDataAvailable: true,\n      },\n    };\n  },\n};\n", "/** Small shared primitives for rules. Pure, no I/O, no clock. */\n\nexport const normalise = (value: string): string =>\n  value.trim().toLowerCase().replace(/\\s+/g, ' ');\n\nconst escapeForRegex = (value: string): string =>\n  value.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\$&');\n\n/**\n * Whole-token keyword match, so \"lead\" does not match \"leadership\" and\n * \"vp\" does not match \"vps\".\n *\n * ## The boundary is Unicode-aware, and it has to be\n *\n * The boundary class is `\\p{L}\\p{N}` \u2014 any letter or number in any script \u2014 not\n * `a-z0-9`. The ASCII form was wrong, and it was wrong in the direction that\n * costs a lead: an accented letter is not in `a-z0-9`, so it counted as a word\n * *separator*, and every accented word silently split into fragments that could\n * match a keyword on their own.\n *\n * Found live, not by reasoning: with the multilingual calibration pack loaded, a\n * lead titled \"S\u00F3cio Propriet\u00E1rio\" matched the keyword **`cio`** \u2014 because the\n * \"\u00F3\" before it read as a boundary. The verdict happened to be right for that\n * title, but the same flaw promotes \"Gerente de Neg\u00F3cio\" to C-level, because\n * \"neg\u00F3cio\" ends in \"cio\" preceded by an accent. A mid-level manager scored as a\n * decision-maker is exactly the twenty-point error this rule exists to avoid.\n *\n * For pure-ASCII input the two forms are identical, which is why every\n * pre-existing test passes unchanged. The difference only appears where the\n * shipped English vocabulary never reached.\n */\nexport const containsKeyword = (haystack: string, keyword: string): boolean => {\n  const needle = normalise(keyword);\n\n  if (needle.length === 0) {\n    return false;\n  }\n\n  const pattern = new RegExp(\n    `(^|[^\\\\p{L}\\\\p{N}])${escapeForRegex(needle)}([^\\\\p{L}\\\\p{N}]|$)`,\n    'iu',\n  );\n\n  return pattern.test(normalise(haystack));\n};\n\nexport const firstKeywordMatch = (\n  haystack: string,\n  keywords: readonly string[],\n): string | null => keywords.find((keyword) => containsKeyword(haystack, keyword)) ?? null;\n\n/** Case-insensitive membership against a configured list. */\nexport const matchesList = (\n  values: readonly string[],\n  allowed: readonly string[],\n): string | null => {\n  const allowedSet = new Set(allowed.map(normalise));\n\n  return values.find((value) => allowedSet.has(normalise(value))) ?? null;\n};\n\nconst EMAIL_PATTERN =\n  /^[A-Za-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\\.[A-Za-z0-9!#$%&'*+/=?^_`{|}~-]+)*@(?:[A-Za-z0-9](?:[A-Za-z0-9-]*[A-Za-z0-9])?\\.)+[A-Za-z]{2,}$/;\n\nexport interface ParsedEmail {\n  readonly address: string;\n  readonly localPart: string;\n  readonly domain: string;\n}\n\nexport const parseEmail = (raw: string): ParsedEmail | null => {\n  const address = raw.trim();\n\n  if (address.length === 0 || address.length > 254) {\n    return null;\n  }\n\n  if (!EMAIL_PATTERN.test(address)) {\n    return null;\n  }\n\n  const separator = address.lastIndexOf('@');\n  const localPart = address.slice(0, separator);\n  const domain = address.slice(separator + 1);\n\n  if (localPart.length > 64) {\n    return null;\n  }\n\n  return { address, localPart: localPart.toLowerCase(), domain: domain.toLowerCase() };\n};\n\n/** Strip the local part down to its base, so `sales+eu` is still `sales`. */\nexport const emailLocalRoot = (localPart: string): string => {\n  const withoutTag = localPart.split('+')[0] ?? localPart;\n  return withoutTag.replace(/[._-]+$/, '');\n};\n\nexport const MILLISECONDS_PER_DAY = 86_400_000;\n\nexport const daysBetween = (earlier: Date, later: Date): number =>\n  (later.getTime() - earlier.getTime()) / MILLISECONDS_PER_DAY;\n\nexport const roundTo = (value: number, decimals: number): number => {\n  const factor = 10 ** decimals;\n  return Math.round(value * factor) / factor;\n};\n\nexport const clamp01 = (value: number): number => {\n  if (!Number.isFinite(value)) {\n    return 0;\n  }\n\n  return Math.min(1, Math.max(0, value));\n};\n", "import { firstKeywordMatch } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactDecisionMakerRule: ScoringRule = {\n  id: 'contact.decision-maker',\n  name: 'Decision-maker',\n  category: 'contact',\n  question: 'Can this person say yes, or at least get you in front of the person who can?',\n  why: 'The single biggest predictor of a deal is talking to someone with budget authority. A perfect-fit company represented by someone with no say costs a rep the same hours as a real opportunity and closes none of them.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 20,\n  reads: ['seniority', 'jobTitle'],\n\n  evaluate: ({ config, read }) => {\n    const seniority = read.text('seniority');\n    const jobTitle = read.text('jobTitle');\n    const subject = seniority ?? jobTitle;\n\n    if (subject === null) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'No job title is recorded, so we cannot tell whether this person can authorise a purchase.',\n        remedy: \"Add the contact's job title.\",\n      };\n    }\n\n    const decisionMaker = firstKeywordMatch(subject, config.decisionMakerTitles);\n\n    if (decisionMaker !== null) {\n      return {\n        outcome: 'pass',\n        explanation: `\"${subject}\" indicates buying authority.`,\n        detail: { title: subject, matchedKeyword: decisionMaker },\n      };\n    }\n\n    const influencer = firstKeywordMatch(subject, config.influencerTitles);\n\n    if (influencer !== null) {\n      return {\n        outcome: 'partial',\n        credit: 0.5,\n        explanation: `\"${subject}\" is likely an influencer rather than the person who signs.`,\n        remedy:\n          'Work this contact as a route in, and find the budget holder above them before forecasting the deal.',\n        detail: { title: subject, matchedKeyword: influencer },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `\"${subject}\" does not look like someone who can authorise a purchase.`,\n      remedy:\n        'Find a contact with budget authority at this company, or add their title keyword to your decision-maker list if it belongs there.',\n      detail: { title: subject },\n    };\n  },\n};\n", "import { parseEmail } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactEmailValidRule: ScoringRule = {\n  id: 'contact.email-valid',\n  name: 'Usable email address',\n  category: 'contact',\n  question: 'Is there an email address that will actually deliver?',\n  why: 'Email is how most first contact happens. A missing or malformed address means the outreach silently fails and the rep never learns why \u2014 the lead just looks unresponsive.',\n  defaultEnabled: true,\n  defaultSeverity: 'critical',\n  defaultWeight: 15,\n  reads: ['email'],\n\n  evaluate: ({ read }) => {\n    const candidates = read.textList('email');\n\n    if (candidates.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation: 'No email address is recorded, so this lead cannot be emailed.',\n        remedy: \"Add the contact's email address.\",\n      };\n    }\n\n    const parsed = candidates\n      .map((candidate) => parseEmail(candidate))\n      .find((candidate) => candidate !== null);\n\n    if (parsed === undefined || parsed === null) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${candidates[0] ?? ''}\" is not a valid email address, so anything sent to it will bounce.`,\n        remedy: 'Correct the email address.',\n        detail: { email: candidates[0] ?? null },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${parsed.address} is a well-formed email address.`,\n      detail: { email: parsed.address, domain: parsed.domain },\n    };\n  },\n};\n", "import { isPlaceholder } from 'src/scoring/field-access';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactNamedPersonRule: ScoringRule = {\n  id: 'contact.named-person',\n  name: 'Named contact',\n  category: 'contact',\n  question: 'Is there a real human being to call?',\n  why: 'A rep cannot open a conversation with an organisation. Leads without a named person become \"whoever picks up\", which is the lowest-converting outreach there is.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 8,\n  reads: ['contactName'],\n\n  evaluate: ({ config, read }) => {\n    const name = read.text('contactName');\n\n    if (name === null) {\n      return {\n        outcome: 'fail',\n        explanation: 'No contact name is recorded, so there is no one to address.',\n        remedy: 'Add the first and last name of the person to contact.',\n      };\n    }\n\n    if (isPlaceholder(name, config.placeholderValues) || !/[a-z]/i.test(name)) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${name}\" is a placeholder rather than a person's name.`,\n        remedy: \"Replace it with the contact's real name.\",\n        detail: { contactName: name },\n      };\n    }\n\n    const parts = name\n      .trim()\n      .split(/\\s+/)\n      .filter((part) => /[a-z]/i.test(part));\n\n    if (parts.length < 2) {\n      return {\n        outcome: 'partial',\n        credit: 0.5,\n        explanation: `Only a first name (\"${name}\") is recorded \u2014 enough to greet someone, not enough to find them.`,\n        remedy: 'Add the surname so the rep can verify the person before reaching out.',\n        detail: { contactName: name },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${name} is a named contact.`,\n      detail: { contactName: name },\n    };\n  },\n};\n", "import type { ScoringRule } from 'src/scoring/types';\n\nconst MIN_DIGITS = 7;\nconst MAX_DIGITS = 15;\n\nexport const contactPhoneValidRule: ScoringRule = {\n  id: 'contact.phone-valid',\n  name: 'Dialable phone number',\n  category: 'contact',\n  question: 'Is there a phone number a rep could actually dial?',\n  why: 'Phone is the fastest path to a real conversation and the fallback when email goes unanswered. A number with too few digits or a note typed into the field looks like coverage and gives none.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 5,\n  reads: ['phone'],\n\n  evaluate: ({ read }) => {\n    const candidates = read.textList('phone');\n\n    if (candidates.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation: 'No phone number is recorded, so this lead can only be reached by email.',\n        remedy: \"Add the contact's phone number.\",\n      };\n    }\n\n    const usable = candidates.find((candidate) => {\n      const stripped = candidate.replace(/[\\s().\\-/]/g, '').replace(/^\\+/, '');\n\n      if (!/^\\d+$/.test(stripped)) {\n        return false;\n      }\n\n      return stripped.length >= MIN_DIGITS && stripped.length <= MAX_DIGITS;\n    });\n\n    if (usable === undefined) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${candidates[0] ?? ''}\" is not a number a rep could dial.`,\n        remedy: `Correct the phone number \u2014 it needs between ${MIN_DIGITS} and ${MAX_DIGITS} digits, optionally with a country code.`,\n        detail: { phone: candidates[0] ?? null },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${usable} is a dialable phone number.`,\n      detail: { phone: usable },\n    };\n  },\n};\n", "import { emailLocalRoot, parseEmail } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactSharedInboxRule: ScoringRule = {\n  id: 'contact.shared-inbox',\n  name: 'Personal mailbox',\n  category: 'contact',\n  question: 'Does the email address belong to a person, or to a shared inbox?',\n  why: 'A shared inbox \u2014 info@, sales@, enquiries@ \u2014 has no owner and no accountability, so replies are nobody\\'s job. These addresses look like a contactable lead in a report and behave like a dead end in practice.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 7,\n  reads: ['email'],\n\n  evaluate: ({ config, read }) => {\n    const candidates = read.textList('email');\n    const parsed = candidates\n      .map((candidate) => parseEmail(candidate))\n      .find((candidate) => candidate !== null);\n\n    if (parsed === undefined || parsed === null) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'There is no usable email address to judge, so this check was skipped \u2014 the email rule already covers it.',\n      };\n    }\n\n    const root = emailLocalRoot(parsed.localPart);\n\n    if (config.roleInboxLocalParts.includes(root)) {\n      return {\n        outcome: 'fail',\n        explanation: `${parsed.address} is a shared \"${root}@\" inbox, so no particular person owns a reply.`,\n        remedy:\n          'Find a named person at this company and use their direct address. Keep the shared inbox as a fallback only.',\n        detail: { email: parsed.address, mailbox: root },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${parsed.address} looks like a personal mailbox, so a named person will see it.`,\n      detail: { email: parsed.address, mailbox: root },\n    };\n  },\n};\n", "import { clamp01, daysBetween, roundTo } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\n/** Tolerance for clock skew between systems, in days. */\nconst FUTURE_TOLERANCE_DAYS = 1;\n\nexport const dataFreshnessRule: ScoringRule = {\n  id: 'data.freshness',\n  name: 'Data still in date',\n  category: 'data-quality',\n  question: 'Was this lead verified recently enough to trust?',\n  why: 'People change jobs, companies move, numbers get reassigned. A contact captured two years ago is not a lead, it is a historical record \u2014 and a rep who works it wastes the call and looks unprepared.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 10,\n  reads: ['lastVerifiedAt'],\n\n  evaluate: ({ config, now, read }) => {\n    if (now === null) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'The current date was not available for this run, so the age of this lead could not be checked.',\n      };\n    }\n\n    const shelfLifeDays =\n      config.fieldShelfLifeDays.lastVerifiedAt ?? config.defaultShelfLifeDays;\n\n    const verifiedAt = read.date('lastVerifiedAt');\n\n    if (verifiedAt === null) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'Nothing on this lead records when its details were last checked, so we have to assume they are stale.',\n        remedy: `Set a last-verified date, or map Greenlight's \"last verified\" field to a date your workspace already maintains. Your shelf life is ${shelfLifeDays} days.`,\n        detail: { shelfLifeDays },\n      };\n    }\n\n    const ageDays = daysBetween(verifiedAt, now);\n\n    if (ageDays < -FUTURE_TOLERANCE_DAYS) {\n      return {\n        outcome: 'fail',\n        explanation: `This lead says it was verified on ${verifiedAt.toISOString().slice(0, 10)}, which is in the future \u2014 the date is wrong.`,\n        remedy: 'Correct the last-verified date.',\n        detail: { verifiedAt: verifiedAt.toISOString(), shelfLifeDays },\n      };\n    }\n\n    const age = Math.max(0, ageDays);\n\n    if (age <= shelfLifeDays) {\n      return {\n        outcome: 'pass',\n        explanation: `Last verified ${roundTo(age, 1)} days ago, inside your ${shelfLifeDays}-day shelf life.`,\n        detail: { ageDays: roundTo(age, 1), shelfLifeDays },\n      };\n    }\n\n    if (age < shelfLifeDays * 2) {\n      const credit = clamp01(1 - (age - shelfLifeDays) / shelfLifeDays);\n\n      return {\n        outcome: 'partial',\n        credit,\n        explanation: `Last verified ${roundTo(age, 1)} days ago, past your ${shelfLifeDays}-day shelf life but not yet twice over.`,\n        remedy: 'Re-check the contact details before a rep spends time on this lead.',\n        detail: { ageDays: roundTo(age, 1), shelfLifeDays },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `Last verified ${roundTo(age, 1)} days ago \u2014 more than twice your ${shelfLifeDays}-day shelf life.`,\n      remedy: 'Re-verify the contact and company details, or retire the lead.',\n      detail: { ageDays: roundTo(age, 1), shelfLifeDays },\n    };\n  },\n};\n", "import type { ScoringRule } from 'src/scoring/types';\n\nexport const icpCompanySizeRule: ScoringRule = {\n  id: 'icp.company-size',\n  name: 'Target company size',\n  category: 'icp',\n  question: 'Is this company the size you sell to?',\n  why: 'Company size decides whether your pricing, contract and onboarding fit at all. Too small and the deal will not clear your floor; too large and the sales motion is a different product.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 10,\n  reads: ['employeeCount'],\n\n  evaluate: ({ config, read }) => {\n    const bands = config.icp.sizeBands;\n\n    if (bands.length === 0) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'You have not defined any target company-size bands, so every company size is accepted.',\n        remedy:\n          'Define your target size bands in the Greenlight ICP settings to start filtering on headcount.',\n      };\n    }\n\n    const employees = read.number('employeeCount');\n\n    if (employees === null) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'This lead has no company size recorded, so we cannot tell whether the company is the size you sell to.',\n        remedy: 'Set the employee count on the lead or its company record.',\n      };\n    }\n\n    const matched = bands.find(\n      (band) =>\n        employees >= band.minEmployees &&\n        (band.maxEmployees === null || employees <= band.maxEmployees),\n    );\n\n    if (matched !== undefined) {\n      return {\n        outcome: 'pass',\n        explanation: `${employees} employees puts this company in your \"${matched.label}\" target band.`,\n        detail: { employees, band: matched.label },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `${employees} employees falls outside every target size band you defined.`,\n      remedy: `Widen a size band if you do sell to companies this size. Your bands are: ${bands\n        .map((band) => band.label)\n        .join(', ')}.`,\n      detail: { employees },\n    };\n  },\n};\n", "import { matchesList } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const icpIndustryRule: ScoringRule = {\n  id: 'icp.industry',\n  name: 'Target industry',\n  category: 'icp',\n  question: 'Is this company in an industry you sell to?',\n  why: 'Reps burn the most time on companies that were never going to buy. Industry is the cheapest, most reliable filter you have, and it is the one your team argues about most.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 20,\n  reads: ['industry', 'companyName'],\n\n  evaluate: ({ config, read }) => {\n    const targets = config.icp.industries;\n\n    if (targets.length === 0) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'You have not listed any target industries, so every industry is accepted.',\n        remedy:\n          'Add your target industries to the Greenlight ICP settings to start filtering on industry.',\n      };\n    }\n\n    const values = read.textList('industry');\n\n    if (values.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'This lead has no industry recorded, so we cannot tell whether it is in a market you sell to.',\n        remedy: 'Set the industry on the lead or its company record.',\n        detail: { targetIndustries: targets.join(', ') },\n      };\n    }\n\n    const matched = matchesList(values, targets);\n\n    if (matched !== null) {\n      return {\n        outcome: 'pass',\n        explanation: `${matched} is one of your target industries.`,\n        detail: { industry: matched },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `${values.join(', ')} is not one of your target industries.`,\n      remedy: `Add it to your target industries if you do sell there. Your current list is: ${targets.join(', ')}.`,\n      detail: { industry: values.join(', '), targetIndustries: targets.join(', ') },\n    };\n  },\n};\n", "import { matchesList } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const icpRegionRule: ScoringRule = {\n  id: 'icp.region',\n  name: 'Target region',\n  category: 'icp',\n  question: 'Is this company somewhere you can actually sell and deliver?',\n  why: 'A perfect-fit company in a territory you do not cover is a perfect-fit company for someone else. Region also drives who the lead should be routed to.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 10,\n  reads: ['region'],\n\n  evaluate: ({ config, read }) => {\n    const targets = config.icp.regions;\n\n    if (targets.length === 0) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'You have not listed any target regions, so every region is accepted.',\n        remedy:\n          'Add the regions you sell into to the Greenlight ICP settings to start filtering on region.',\n      };\n    }\n\n    const values = read.textList('region');\n\n    if (values.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'This lead has no country or region recorded, so we cannot tell whether you cover it.',\n        remedy: 'Set the country or region on the lead.',\n        detail: { targetRegions: targets.join(', ') },\n      };\n    }\n\n    const matched = matchesList(values, targets);\n\n    if (matched !== null) {\n      return {\n        outcome: 'pass',\n        explanation: `${matched} is a region you sell into.`,\n        detail: { region: matched },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `${values.join(', ')} is outside the regions you sell into.`,\n      remedy: `Add it to your target regions if you do cover it. Your current list is: ${targets.join(', ')}.`,\n      detail: { region: values.join(', '), targetRegions: targets.join(', ') },\n    };\n  },\n};\n", "/**\n * The rule catalogue.\n *\n * Adding a rule is a local change: write a `ScoringRule` in its own file, add\n * it to `ALL_RULES`, and it inherits default settings, config plumbing,\n * weighting, tracing and fail-open error handling for free. Removing one is\n * equally local \u2014 a config record referencing a rule that no longer exists is\n * ignored rather than fatal.\n */\n\nimport { companyIdentifiedRule } from 'src/scoring/rules/company-identified.rule';\nimport { complianceOptOutRule } from 'src/scoring/rules/compliance-opt-out.rule';\nimport { contactDecisionMakerRule } from 'src/scoring/rules/contact-decision-maker.rule';\nimport { contactEmailValidRule } from 'src/scoring/rules/contact-email-valid.rule';\nimport { contactNamedPersonRule } from 'src/scoring/rules/contact-named-person.rule';\nimport { contactPhoneValidRule } from 'src/scoring/rules/contact-phone-valid.rule';\nimport { contactSharedInboxRule } from 'src/scoring/rules/contact-shared-inbox.rule';\nimport { dataFreshnessRule } from 'src/scoring/rules/data-freshness.rule';\nimport { icpCompanySizeRule } from 'src/scoring/rules/icp-company-size.rule';\nimport { icpIndustryRule } from 'src/scoring/rules/icp-industry.rule';\nimport { icpRegionRule } from 'src/scoring/rules/icp-region.rule';\nimport type { RuleCatalogueEntry, ScoringRule } from 'src/scoring/types';\n\nexport const ALL_RULES: readonly ScoringRule[] = [\n  complianceOptOutRule,\n  icpIndustryRule,\n  icpRegionRule,\n  icpCompanySizeRule,\n  companyIdentifiedRule,\n  contactNamedPersonRule,\n  contactDecisionMakerRule,\n  contactEmailValidRule,\n  contactSharedInboxRule,\n  contactPhoneValidRule,\n  dataFreshnessRule,\n];\n\nexport {\n  companyIdentifiedRule,\n  complianceOptOutRule,\n  contactDecisionMakerRule,\n  contactEmailValidRule,\n  contactNamedPersonRule,\n  contactPhoneValidRule,\n  contactSharedInboxRule,\n  dataFreshnessRule,\n  icpCompanySizeRule,\n  icpIndustryRule,\n  icpRegionRule,\n};\n\n/**\n * The published rule catalogue \u2014 \"each rule: what it checks, why, what fixes\n * it\". The same text belongs in the docs and in the in-app help.\n */\nexport const describeRuleCatalogue = (\n  rules: readonly ScoringRule[] = ALL_RULES,\n): readonly RuleCatalogueEntry[] =>\n  rules.map((rule) => ({\n    id: rule.id,\n    name: rule.name,\n    category: rule.category,\n    question: rule.question,\n    why: rule.why,\n    reads: rule.reads,\n    defaultEnabled: rule.defaultEnabled,\n    defaultSeverity: rule.defaultSeverity,\n    defaultWeight: rule.defaultWeight,\n  }));\n", "/**\n * Numaya Greenlight \u2014 deterministic scoring engine types.\n *\n * This module is intentionally free of any Twenty SDK import, any network call,\n * any filesystem access and any clock read. Everything the engine needs arrives\n * through `scoreLead()`'s input, including `now`. That is what makes the whole\n * scoring path unit-testable in complete isolation.\n */\n\n/** Bumped whenever a change alters the score a given lead would receive. */\nexport const SCORING_ENGINE_VERSION = '0.1.0';\n\n/* -------------------------------------------------------------------------- */\n/* Lead input                                                                  */\n/* -------------------------------------------------------------------------- */\n\n/**\n * A lead as the engine sees it: an opaque bag of field values plus an optional\n * record id used only for the trace. The engine never assumes a field name \u2014\n * every read goes through the configured {@link FieldMapping}.\n */\nexport interface LeadRecord {\n  readonly id?: string | null;\n  readonly fields: Readonly<Record<string, unknown>>;\n}\n\n/**\n * Logical field keys. Rules only ever speak in these; the customer's actual\n * column names live in the config's field mapping.\n */\nexport type LeadFieldKey =\n  | 'companyName'\n  | 'industry'\n  | 'region'\n  | 'employeeCount'\n  | 'contactName'\n  | 'jobTitle'\n  | 'seniority'\n  | 'email'\n  | 'phone'\n  | 'lastVerifiedAt'\n  /** Greenlight's own block-list flag. Its mapping is not customer-configurable. */\n  | 'suppressed'\n  /** Greenlight's own block-list reason code. Read for the explanation, not the verdict. */\n  | 'suppressionReason'\n  /** The *customer's* opt-out column(s), wherever the Layer 3 mapping points. */\n  | 'optedOut';\n\nexport const LEAD_FIELD_KEYS: readonly LeadFieldKey[] = [\n  'companyName',\n  'industry',\n  'region',\n  'employeeCount',\n  'contactName',\n  'jobTitle',\n  'seniority',\n  'email',\n  'phone',\n  'lastVerifiedAt',\n  'suppressed',\n  'suppressionReason',\n  'optedOut',\n];\n\n/**\n * One or more dotted paths into the lead record, tried in order. Multiple\n * candidates let a workspace keep a preferred field with sane fallbacks\n * (e.g. `lastVerifiedAt` \u2192 `updatedAt` \u2192 `createdAt`).\n */\nexport type FieldMapping = Readonly<\n  Record<LeadFieldKey, readonly string[]>\n>;\n\n/** What a rule actually looked at, so the trace can show its working. */\nexport interface FieldObservation {\n  readonly key: LeadFieldKey;\n  /** The candidate path that produced a value, or null when none did. */\n  readonly mappedTo: string | null;\n  readonly candidates: readonly string[];\n  readonly present: boolean;\n  /** Human-readable rendering of the value, e.g. `Manufacturing` / `(not set)`. */\n  readonly display: string;\n}\n\n/**\n * Field reader handed to every rule. All lookups are recorded so the trace\n * entry can name the exact fields consulted and the values seen.\n */\nexport interface FieldReader {\n  text(key: LeadFieldKey): string | null;\n  textList(key: LeadFieldKey): readonly string[];\n  number(key: LeadFieldKey): number | null;\n  date(key: LeadFieldKey): Date | null;\n  /** True when any mapped candidate resolves truthy; null when none are set. */\n  booleanAny(key: LeadFieldKey): boolean | null;\n  observations(): readonly FieldObservation[];\n}\n\n/* -------------------------------------------------------------------------- */\n/* Configuration                                                               */\n/* -------------------------------------------------------------------------- */\n\nexport type RuleSeverity =\n  /** A failure blocks the lead outright (compliance), whatever the score. */\n  | 'blocking'\n  /** A failure gates the lead even if the score clears the threshold. */\n  | 'critical'\n  | 'major'\n  | 'minor'\n  /** Reported in the trace but never contributes to the score. */\n  | 'advisory';\n\nexport const RULE_SEVERITIES: readonly RuleSeverity[] = [\n  'blocking',\n  'critical',\n  'major',\n  'minor',\n  'advisory',\n];\n\nexport type RuleCategory = 'icp' | 'contact' | 'data-quality' | 'compliance';\n\nexport interface IcpSizeBand {\n  readonly label: string;\n  readonly minEmployees: number;\n  /** `null` means unbounded. */\n  readonly maxEmployees: number | null;\n}\n\nexport interface IcpConfig {\n  /** Empty list means \"no opinion\" \u2014 the matching rule reports not-applicable. */\n  readonly industries: readonly string[];\n  readonly regions: readonly string[];\n  readonly sizeBands: readonly IcpSizeBand[];\n}\n\nexport interface ScoringBand {\n  readonly id: string;\n  readonly label: string;\n  /** Inclusive lower bound on the 0-100 score. */\n  readonly minScore: number;\n}\n\nexport interface RuleSetting {\n  readonly enabled: boolean;\n  readonly severity: RuleSeverity;\n  /** Relative weight. Only meaningful against the other enabled rules. */\n  readonly weight: number;\n}\n\nexport interface ResolvedScoringConfig {\n  readonly icp: IcpConfig;\n  readonly rules: Readonly<Record<string, RuleSetting>>;\n  /** Sorted high \u2192 low by `minScore`. */\n  readonly bands: readonly ScoringBand[];\n  /** Score at or above which a lead is approved. */\n  readonly gateThreshold: number;\n  readonly defaultShelfLifeDays: number;\n  readonly fieldShelfLifeDays: Readonly<Partial<Record<LeadFieldKey, number>>>;\n  /** Title keywords that indicate authority to buy. */\n  readonly decisionMakerTitles: readonly string[];\n  /** Title keywords that indicate influence but not authority (partial credit). */\n  readonly influencerTitles: readonly string[];\n  /** Mailbox local-parts that mean \"shared inbox, nobody owns replies\". */\n  readonly roleInboxLocalParts: readonly string[];\n  /** Values that mean \"somebody typed something rather than nothing\". */\n  readonly placeholderValues: readonly string[];\n  readonly fieldMapping: FieldMapping;\n}\n\n/** A deeply-optional config, i.e. whatever came out of the CRM config record. */\nexport type ScoringConfigInput = unknown;\n\n/**\n * Vocabulary that replaces the shipped defaults as the *fall-back* for a\n * workspace that has not expressed its own opinion.\n *\n * Structurally identical to the calibration baseline in `src/calibration/`, and\n * deliberately declared here rather than imported from there: the engine must\n * not be able to tell where a baseline came from, and a `src/scoring/` import of\n * `src/calibration/` would invert a dependency direction that is load-bearing\n * (see `src/calibration/index.ts`). Every field is optional \u2014 an absent one\n * leaves the corresponding shipped default exactly as it is.\n *\n * It carries no weights, no thresholds and no rule identifiers, and there is no\n * field here through which one could be smuggled. The worst a baseline can do is\n * change which strings a rule matches.\n */\nexport interface ScoringVocabularyBaseline {\n  readonly decisionMakerTitles?: readonly string[];\n  readonly influencerTitles?: readonly string[];\n  readonly roleInboxLocalParts?: readonly string[];\n  readonly placeholderValues?: readonly string[];\n  /** Canonical industry term \u2192 equivalent free-text variants. */\n  readonly industrySynonyms?: Readonly<Record<string, readonly string[]>>;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Fail-open reporting                                                         */\n/* -------------------------------------------------------------------------- */\n\nexport type DegradationCode =\n  | 'config_missing'\n  | 'config_malformed'\n  | 'icp_malformed'\n  | 'rules_malformed'\n  | 'rule_setting_malformed'\n  | 'weight_malformed'\n  | 'severity_malformed'\n  | 'bands_malformed'\n  | 'gate_threshold_malformed'\n  | 'shelf_life_malformed'\n  | 'field_mapping_malformed'\n  | 'title_list_malformed'\n  | 'lead_malformed'\n  | 'now_malformed'\n  | 'rule_errored'\n  | 'no_scorable_rules'\n  | 'engine_errored';\n\n/**\n * A recorded fall-back. Every degradation means the engine chose to keep going\n * with a safe default rather than fail \u2014 the product's core promise is that a\n * lead is never lost and never silently dropped.\n */\nexport interface Degradation {\n  readonly code: DegradationCode;\n  /** Written for a CRM admin, not a developer. */\n  readonly message: string;\n  readonly detail?: string;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Rules                                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport type RuleOutcome =\n  | 'pass'\n  | 'partial'\n  | 'fail'\n  /** The rule has nothing to judge (e.g. the ICP list is empty). Not scored. */\n  | 'not_applicable'\n  /** Turned off in configuration. Not scored. */\n  | 'skipped'\n  /** The rule threw. Not scored \u2014 a broken rule never drags a lead down. */\n  | 'errored';\n\nexport type RuleDetail = Readonly<\n  Record<string, string | number | boolean | null | undefined>\n>;\n\n/** What a rule returns. `credit` defaults to 1 for pass and 0 for fail. */\nexport interface RuleVerdict {\n  readonly outcome: 'pass' | 'partial' | 'fail' | 'not_applicable';\n  /** 0-1. Required for `partial`; ignored elsewhere unless supplied. */\n  readonly credit?: number;\n  /** One sentence a salesperson understands. */\n  readonly explanation: string;\n  /** What to do about it, when there is something to do. */\n  readonly remedy?: string;\n  readonly detail?: RuleDetail;\n}\n\nexport interface RuleContext {\n  readonly lead: LeadRecord;\n  readonly config: ResolvedScoringConfig;\n  /** Null when the caller supplied an unusable `now`; time-based rules opt out. */\n  readonly now: Date | null;\n  readonly read: FieldReader;\n}\n\n/**\n * A single deterministic check. Adding a rule is a local change: write one of\n * these, add it to the catalogue array, done \u2014 defaults, config plumbing,\n * weighting, tracing and fail-open handling are all inherited.\n */\nexport interface ScoringRule {\n  readonly id: string;\n  /** Short label shown in the CRM, e.g. \"Decision-maker\". */\n  readonly name: string;\n  readonly category: RuleCategory;\n  /** The question the rule answers, in the buyer's words. */\n  readonly question: string;\n  /** Why the rule exists. Published in the rule catalogue and shown in-app. */\n  readonly why: string;\n  readonly defaultEnabled: boolean;\n  readonly defaultSeverity: RuleSeverity;\n  readonly defaultWeight: number;\n  readonly reads: readonly LeadFieldKey[];\n  evaluate(context: RuleContext): RuleVerdict;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Result                                                                      */\n/* -------------------------------------------------------------------------- */\n\nexport type GateDecision =\n  /** Cleared to work. */\n  | 'approved'\n  /** Held in the greenlight queue: visible, explained, human-overridable. */\n  | 'gated'\n  /** Compliance stop (e.g. opted out). Still visible and overridable. */\n  | 'blocked'\n  /** Nothing could be scored. Fail-open: the lead passes through, flagged. */\n  | 'unscored';\n\nexport interface RuleTraceEntry {\n  readonly ruleId: string;\n  readonly ruleName: string;\n  readonly category: RuleCategory;\n  readonly question: string;\n  readonly outcome: RuleOutcome;\n  readonly severity: RuleSeverity;\n  /** 0-1 share of this rule's weight that the lead earned. */\n  readonly credit: number;\n  readonly weight: number;\n  readonly pointsEarned: number;\n  readonly pointsPossible: number;\n  /** False for skipped / not-applicable / errored / advisory rules. */\n  readonly contributed: boolean;\n  readonly explanation: string;\n  readonly remedy?: string;\n  readonly detail?: RuleDetail;\n  readonly observations: readonly FieldObservation[];\n  readonly error?: string;\n}\n\nexport interface ScoringResult {\n  /** 0-100, rounded to one decimal. Null only when nothing was scorable. */\n  readonly score: number | null;\n  readonly band: ScoringBand | null;\n  readonly decision: GateDecision;\n  readonly gateThreshold: number;\n  /** One sentence for the top of the lead record. */\n  readonly summary: string;\n  /** The headline reasons behind the decision, worst first. */\n  readonly reasons: readonly string[];\n  readonly trace: readonly RuleTraceEntry[];\n  readonly degradations: readonly Degradation[];\n  readonly configSource: ConfigSource;\n  /** ISO timestamp of the `now` that was passed in. */\n  readonly scoredAt: string | null;\n  readonly leadId: string | null;\n  readonly engineVersion: string;\n  readonly totalWeight: number;\n  readonly earnedWeight: number;\n}\n\nexport type ConfigSource = 'provided' | 'defaults' | 'repaired';\n\nexport interface ConfigResolution {\n  readonly config: ResolvedScoringConfig;\n  readonly source: ConfigSource;\n  readonly degradations: readonly Degradation[];\n}\n\nexport interface ScoreLeadInput {\n  readonly lead: LeadRecord;\n  /**\n   * The clock, passed in. The engine never reads the clock itself, so every\n   * run is reproducible from its inputs alone.\n   */\n  readonly now: Date;\n  /** Raw config record straight from the CRM. Anything unusable is repaired. */\n  readonly config?: ScoringConfigInput;\n  /** Override the rule catalogue (tests, future per-workspace rule packs). */\n  readonly rules?: readonly ScoringRule[];\n  /**\n   * Licence-delivered vocabulary, if any. Absent \u2014 which is the unlicensed,\n   * offline and signature-failing case \u2014 scores identically to a build that\n   * never had this parameter.\n   */\n  readonly baseline?: ScoringVocabularyBaseline | null;\n}\n\n/** Public documentation shape for the rule catalogue (docs + in-app help). */\nexport interface RuleCatalogueEntry {\n  readonly id: string;\n  readonly name: string;\n  readonly category: RuleCategory;\n  readonly question: string;\n  readonly why: string;\n  readonly reads: readonly LeadFieldKey[];\n  readonly defaultEnabled: boolean;\n  readonly defaultSeverity: RuleSeverity;\n  readonly defaultWeight: number;\n}\n", "/**\n * Configuration resolution.\n *\n * `resolveConfig` takes whatever came out of the CRM config record \u2014 including\n * `undefined`, `null`, a string, or an object with half its fields the wrong\n * type \u2014 and always returns a usable config plus a list of the fall-backs it\n * had to make. Nothing in here throws. Missing config falls back to seeded\n * defaults; malformed weights fall back to neutral weights.\n */\n\nimport { ENRICHED_FIELD_MAPPING_PATHS } from 'src/enrichment/field-specs';\nimport {\n  DEFAULT_BANDS,\n  DEFAULT_DECISION_MAKER_TITLES,\n  DEFAULT_FIELD_MAPPING,\n  DEFAULT_GATE_THRESHOLD,\n  DEFAULT_ICP,\n  DEFAULT_INFLUENCER_TITLES,\n  DEFAULT_ROLE_INBOX_LOCAL_PARTS,\n  DEFAULT_SHELF_LIFE_DAYS,\n  PLACEHOLDER_VALUES,\n} from 'src/scoring/defaults';\nimport { isPlainObject } from 'src/scoring/field-access';\nimport { ALL_RULES } from 'src/scoring/rules';\nimport {\n  LEAD_FIELD_KEYS,\n  RULE_SEVERITIES,\n  type ConfigResolution,\n  type Degradation,\n  type DegradationCode,\n  type FieldMapping,\n  type IcpConfig,\n  type IcpSizeBand,\n  type LeadFieldKey,\n  type ResolvedScoringConfig,\n  type RuleSetting,\n  type RuleSeverity,\n  type ScoringBand,\n  type ScoringConfigInput,\n  type ScoringRule,\n  type ScoringVocabularyBaseline,\n} from 'src/scoring/types';\n\n/**\n * Set equality over normalised strings.\n *\n * Exported because `src/calibration/apply.ts` needs exactly this comparison and\n * the dependency may only run in that direction \u2014 calibration imports scoring,\n * never the reverse. Duplicating ten lines across that boundary would be two\n * implementations of one rule, and the rule decides whether a workspace's\n * configuration is honoured.\n */\nexport const isSameStringSet = (\n  left: readonly string[],\n  right: readonly string[],\n): boolean => {\n  const leftSet = new Set(left.map((entry) => entry.trim().toLowerCase().replace(/\\s+/g, ' ')));\n  const rightSet = new Set(right.map((entry) => entry.trim().toLowerCase().replace(/\\s+/g, ' ')));\n\n  if (leftSet.size !== rightSet.size) {\n    return false;\n  }\n\n  for (const entry of rightSet) {\n    if (!leftSet.has(entry)) {\n      return false;\n    }\n  }\n\n  return true;\n};\n\n/**\n * Expand a workspace's ICP industries through a synonym taxonomy.\n *\n * Declared here rather than imported from `src/calibration/` for the dependency\n * reason above, and applied at resolution rather than inside\n * `icp-industry.rule.ts` so the rule stays a pure set-membership test. The rule\n * is untouched by this feature; it simply finds a longer list of acceptable\n * strings. See `src/calibration/apply.ts` for the full argument.\n */\nexport const expandIndustriesWithSynonyms = (\n  industries: readonly string[],\n  synonyms: Readonly<Record<string, readonly string[]>> | undefined,\n): readonly string[] => {\n  if (synonyms === undefined || industries.length === 0) {\n    return industries;\n  }\n\n  const clusters = Object.entries(synonyms);\n\n  if (clusters.length === 0) {\n    return industries;\n  }\n\n  const variantToCanonical = new Map<string, string>();\n\n  for (const [canonical, variants] of clusters) {\n    const canonicalKey = normaliseTerm(canonical);\n    variantToCanonical.set(canonicalKey, canonicalKey);\n\n    for (const variant of variants) {\n      const variantKey = normaliseTerm(variant);\n\n      // A variant listed under two canonicals is a defect in the pack, and the\n      // resolution has to be independent of object key order or the same pack\n      // would behave differently in two builds. Two rules, in this order:\n      // **a canonical always wins over a variant** (the unconditional `set`\n      // above), and among competing variants the **first cluster wins**. Both\n      // are order-independent given a fixed pack, which is the property that\n      // matters.\n      if (!variantToCanonical.has(variantKey)) {\n        variantToCanonical.set(variantKey, canonicalKey);\n      }\n    }\n  }\n\n  // The workspace's own terms first and unmodified \u2014 expansion only ever adds.\n  const expanded = new Set(industries.map(normaliseTerm));\n\n  for (const industry of industries) {\n    const canonical = variantToCanonical.get(normaliseTerm(industry));\n\n    if (canonical === undefined) {\n      continue;\n    }\n\n    expanded.add(canonical);\n\n    for (const variant of synonyms[canonical] ?? []) {\n      expanded.add(normaliseTerm(variant));\n    }\n  }\n\n  return [...expanded];\n};\n\nconst normaliseTerm = (value: string): string =>\n  value.trim().toLowerCase().replace(/\\s+/g, ' ');\n\n/**\n * Append Greenlight's own enriched-value paths to the end of every enrichable\n * key's candidate list.\n *\n * ## Why this lives here and not in the config record\n *\n * `greenlightEnrichment` is a column Greenlight ships, owns and writes, so\n * \"where does an enriched industry live\" has exactly one answer and it is not\n * the customer's to give. There is also nowhere in `GreenlightConfig` to say it:\n * the record exposes precisely two mapping settings (`decisionMakerFieldName`,\n * `optOutFieldNames`), so seeding these five paths would mean minting columns\n * for values no admin should ever edit \u2014 and a seeded value is a value that can\n * be cleared, which would put us straight back to enrichment writing data\n * nothing reads. Doing it here also covers the workspace with *no* config record\n * at all, where `resolveConfig` short-circuits to `buildDefaultConfig` and never\n * looks at a field mapping the record could have carried.\n *\n * ## Appended, not pinned\n *\n * `PINNED_FIELD_MAPPING_KEYS` below *rejects* a workspace's mapping outright.\n * That is right for `suppressed`, whose key names a Greenlight-only column, and\n * wrong here: `industry`, `region`, `employeeCount`, `jobTitle` and `seniority`\n * are genuine Layer 3 seams and a workspace must keep saying where its own\n * columns live. The treatment is therefore the weaker half of pinning \u2014 the\n * workspace owns the head of the list, Greenlight owns the tail:\n *\n *   - **Unconditional**, so a config typo cannot silently disconnect enrichment.\n *     That is the same safety property pinning buys, without the cost.\n *   - **Always last**, so `field-access.ts` \u2014 which takes the first candidate\n *     that yields a value \u2014 reaches it only when every human-held candidate is\n *     empty. Enrichment fills a hole; it never overwrites a person.\n *\n * `DEFAULT_FIELD_MAPPING` itself is deliberately left alone: `src/enrichment/\n * plan.ts` reads it to answer \"has a human already answered this field\", and an\n * enriched value visible there would read as human input and never refresh.\n */\nconst withEnrichedFallbacks = (mapping: FieldMapping): FieldMapping => {\n  const next: Record<LeadFieldKey, readonly string[]> = { ...mapping };\n\n  for (const [key, path] of Object.entries(ENRICHED_FIELD_MAPPING_PATHS)) {\n    const leadKey = key as LeadFieldKey;\n    const candidates = next[leadKey] ?? [];\n\n    next[leadKey] = candidates.includes(path)\n      ? candidates\n      : [...candidates, path];\n  }\n\n  return next;\n};\n\n/**\n * The complete seeded configuration. Also what the install hook should write.\n *\n * The optional `baseline` supplies licence-delivered vocabulary in place of the\n * shipped lists. It is *only* consulted for the four vocabulary lists \u2014 bands,\n * weights, thresholds, shelf lives, the ICP and the field mapping are read from\n * the shipped constants unconditionally, and there is no argument here through\n * which a baseline could reach them.\n */\nexport const buildDefaultConfig = (\n  rules: readonly ScoringRule[] = ALL_RULES,\n  baseline?: ScoringVocabularyBaseline | null,\n): ResolvedScoringConfig => ({\n  icp: DEFAULT_ICP,\n  rules: Object.fromEntries(\n    rules.map((rule) => [\n      rule.id,\n      {\n        enabled: rule.defaultEnabled,\n        severity: rule.defaultSeverity,\n        weight: rule.defaultWeight,\n      } satisfies RuleSetting,\n    ]),\n  ),\n  bands: DEFAULT_BANDS,\n  gateThreshold: DEFAULT_GATE_THRESHOLD,\n  defaultShelfLifeDays: DEFAULT_SHELF_LIFE_DAYS,\n  fieldShelfLifeDays: {},\n  decisionMakerTitles:\n    baseline?.decisionMakerTitles ?? DEFAULT_DECISION_MAKER_TITLES,\n  influencerTitles: baseline?.influencerTitles ?? DEFAULT_INFLUENCER_TITLES,\n  roleInboxLocalParts:\n    baseline?.roleInboxLocalParts ?? DEFAULT_ROLE_INBOX_LOCAL_PARTS,\n  placeholderValues: baseline?.placeholderValues ?? PLACEHOLDER_VALUES,\n  fieldMapping: withEnrichedFallbacks(DEFAULT_FIELD_MAPPING),\n});\n\nconst isFiniteNumber = (value: unknown): value is number =>\n  typeof value === 'number' && Number.isFinite(value);\n\nconst toStringList = (value: unknown): string[] | null => {\n  if (typeof value === 'string') {\n    const trimmed = value.trim();\n    return trimmed.length > 0 ? [trimmed] : [];\n  }\n\n  if (!Array.isArray(value)) {\n    return null;\n  }\n\n  return value\n    .filter((entry): entry is string => typeof entry === 'string')\n    .map((entry) => entry.trim())\n    .filter((entry) => entry.length > 0);\n};\n\nconst lowerAll = (values: readonly string[]): string[] =>\n  values.map((value) => value.toLowerCase());\n\nclass DegradationLog {\n  private readonly entries: Degradation[] = [];\n\n  add(code: DegradationCode, message: string, detail?: string): void {\n    this.entries.push(detail === undefined ? { code, message } : { code, message, detail });\n  }\n\n  get list(): readonly Degradation[] {\n    return this.entries;\n  }\n\n  get count(): number {\n    return this.entries.length;\n  }\n}\n\nconst resolveIcp = (raw: unknown, log: DegradationLog): IcpConfig => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_ICP;\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'icp_malformed',\n      'Your ideal-customer-profile settings could not be read, so no industry, region or size filtering was applied.',\n    );\n    return DEFAULT_ICP;\n  }\n\n  const industries = toStringList(raw['industries']);\n  const regions = toStringList(raw['regions']);\n\n  if (raw['industries'] !== undefined && industries === null) {\n    log.add(\n      'icp_malformed',\n      'Your ICP industry list could not be read, so every industry was accepted.',\n    );\n  }\n\n  if (raw['regions'] !== undefined && regions === null) {\n    log.add(\n      'icp_malformed',\n      'Your ICP region list could not be read, so every region was accepted.',\n    );\n  }\n\n  const rawBands = raw['sizeBands'];\n  let sizeBands: IcpSizeBand[] = [];\n\n  if (rawBands !== undefined && rawBands !== null) {\n    if (!Array.isArray(rawBands)) {\n      log.add(\n        'icp_malformed',\n        'Your ICP company-size bands could not be read, so every company size was accepted.',\n      );\n    } else {\n      sizeBands = rawBands.flatMap((entry): IcpSizeBand[] => {\n        if (!isPlainObject(entry)) {\n          return [];\n        }\n\n        const min = entry['minEmployees'];\n        const max = entry['maxEmployees'];\n\n        if (!isFiniteNumber(min) || min < 0) {\n          return [];\n        }\n\n        const resolvedMax = isFiniteNumber(max) ? max : null;\n\n        if (resolvedMax !== null && resolvedMax < min) {\n          return [];\n        }\n\n        const label =\n          typeof entry['label'] === 'string' && entry['label'].trim().length > 0\n            ? entry['label'].trim()\n            : `${min}-${resolvedMax ?? '\u221E'} employees`;\n\n        return [{ label, minEmployees: min, maxEmployees: resolvedMax }];\n      });\n\n      if (sizeBands.length !== rawBands.length) {\n        log.add(\n          'icp_malformed',\n          'Some ICP company-size bands were incomplete and were ignored.',\n          `${rawBands.length - sizeBands.length} of ${rawBands.length} size bands dropped`,\n        );\n      }\n    }\n  }\n\n  return {\n    industries: industries ?? [],\n    regions: regions ?? [],\n    sizeBands,\n  };\n};\n\nconst readRuleOverrides = (\n  raw: unknown,\n  log: DegradationLog,\n): Map<string, Record<string, unknown>> => {\n  const overrides = new Map<string, Record<string, unknown>>();\n\n  if (raw === undefined || raw === null) {\n    return overrides;\n  }\n\n  // Accept both a keyed object and an array of { id, ... } records, because a\n  // CRM config record can reasonably be modelled either way.\n  if (Array.isArray(raw)) {\n    for (const entry of raw) {\n      if (!isPlainObject(entry)) {\n        continue;\n      }\n\n      const id = entry['id'] ?? entry['ruleId'];\n\n      if (typeof id === 'string' && id.length > 0) {\n        overrides.set(id, entry);\n      }\n    }\n\n    return overrides;\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'rules_malformed',\n      'Your rule settings could not be read, so every rule ran at its default setting.',\n    );\n    return overrides;\n  }\n\n  for (const [id, entry] of Object.entries(raw)) {\n    if (isPlainObject(entry)) {\n      overrides.set(id, entry);\n      continue;\n    }\n\n    if (typeof entry === 'boolean') {\n      overrides.set(id, { enabled: entry });\n      continue;\n    }\n\n    log.add(\n      'rule_setting_malformed',\n      `The settings for rule \"${id}\" could not be read, so the rule ran at its default setting.`,\n    );\n  }\n\n  return overrides;\n};\n\nconst resolveRuleSettings = (\n  raw: unknown,\n  rules: readonly ScoringRule[],\n  log: DegradationLog,\n): Record<string, RuleSetting> => {\n  const overrides = readRuleOverrides(raw, log);\n  const settings: Record<string, RuleSetting> = {};\n\n  for (const rule of rules) {\n    const override = overrides.get(rule.id);\n\n    let enabled = rule.defaultEnabled;\n    let severity: RuleSeverity = rule.defaultSeverity;\n    let weight = rule.defaultWeight;\n\n    if (override !== undefined) {\n      const rawEnabled = override['enabled'];\n\n      if (typeof rawEnabled === 'boolean') {\n        enabled = rawEnabled;\n      } else if (rawEnabled !== undefined && rawEnabled !== null) {\n        log.add(\n          'rule_setting_malformed',\n          `\"${rule.name}\" had an unreadable on/off setting, so it stayed at its default.`,\n          `rule ${rule.id}`,\n        );\n      }\n\n      const rawSeverity = override['severity'];\n\n      if (\n        typeof rawSeverity === 'string' &&\n        (RULE_SEVERITIES as readonly string[]).includes(rawSeverity)\n      ) {\n        severity = rawSeverity as RuleSeverity;\n      } else if (rawSeverity !== undefined && rawSeverity !== null) {\n        log.add(\n          'severity_malformed',\n          `\"${rule.name}\" had an unrecognised severity, so its default severity was used.`,\n          `rule ${rule.id}`,\n        );\n      }\n\n      const rawWeight = override['weight'];\n\n      if (isFiniteNumber(rawWeight) && rawWeight >= 0) {\n        weight = rawWeight;\n      } else if (rawWeight !== undefined && rawWeight !== null) {\n        log.add(\n          'weight_malformed',\n          `\"${rule.name}\" had an unusable weight, so its default weight was used instead.`,\n          `rule ${rule.id}`,\n        );\n      }\n    }\n\n    settings[rule.id] = { enabled, severity, weight };\n  }\n\n  // Neutral-weight fall-back: if nothing that can score carries any weight, the\n  // score would be undefined. Give every rule the same voice instead.\n  const scorable = rules.filter((rule) => {\n    const setting = settings[rule.id];\n    return setting !== undefined && setting.enabled && setting.severity !== 'advisory';\n  });\n\n  const totalWeight = scorable.reduce(\n    (sum, rule) => sum + (settings[rule.id]?.weight ?? 0),\n    0,\n  );\n\n  if (scorable.length > 0 && totalWeight <= 0) {\n    log.add(\n      'weight_malformed',\n      'None of your enabled rules carried any weight, so every rule was given equal weight.',\n    );\n\n    for (const rule of scorable) {\n      const current = settings[rule.id];\n\n      if (current !== undefined) {\n        settings[rule.id] = { ...current, weight: 1 };\n      }\n    }\n  }\n\n  return settings;\n};\n\nconst resolveBands = (raw: unknown, log: DegradationLog): readonly ScoringBand[] => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_BANDS;\n  }\n\n  if (!Array.isArray(raw)) {\n    log.add(\n      'bands_malformed',\n      'Your score bands could not be read, so the standard Excellent/Good/Fair/Poor bands were used.',\n    );\n    return DEFAULT_BANDS;\n  }\n\n  const bands = raw.flatMap((entry): ScoringBand[] => {\n    if (!isPlainObject(entry)) {\n      return [];\n    }\n\n    const minScore = entry['minScore'];\n\n    if (!isFiniteNumber(minScore)) {\n      return [];\n    }\n\n    const id =\n      typeof entry['id'] === 'string' && entry['id'].trim().length > 0\n        ? entry['id'].trim()\n        : null;\n\n    if (id === null) {\n      return [];\n    }\n\n    const label =\n      typeof entry['label'] === 'string' && entry['label'].trim().length > 0\n        ? entry['label'].trim()\n        : id;\n\n    return [{ id, label, minScore: Math.min(100, Math.max(0, minScore)) }];\n  });\n\n  if (bands.length === 0) {\n    log.add(\n      'bands_malformed',\n      'No usable score bands were configured, so the standard Excellent/Good/Fair/Poor bands were used.',\n    );\n    return DEFAULT_BANDS;\n  }\n\n  if (bands.length !== raw.length) {\n    log.add(\n      'bands_malformed',\n      'Some score bands were incomplete and were ignored.',\n      `${raw.length - bands.length} of ${raw.length} bands dropped`,\n    );\n  }\n\n  return [...bands].sort((a, b) => b.minScore - a.minScore);\n};\n\nconst resolveGateThreshold = (raw: unknown, log: DegradationLog): number => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_GATE_THRESHOLD;\n  }\n\n  if (!isFiniteNumber(raw) || raw < 0 || raw > 100) {\n    log.add(\n      'gate_threshold_malformed',\n      `Your gate threshold was not a score between 0 and 100, so the default of ${DEFAULT_GATE_THRESHOLD} was used.`,\n    );\n    return DEFAULT_GATE_THRESHOLD;\n  }\n\n  return raw;\n};\n\nconst resolveShelfLife = (raw: unknown, log: DegradationLog): number => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_SHELF_LIFE_DAYS;\n  }\n\n  if (!isFiniteNumber(raw) || raw <= 0) {\n    log.add(\n      'shelf_life_malformed',\n      `Your data shelf life was not a positive number of days, so the default of ${DEFAULT_SHELF_LIFE_DAYS} days was used.`,\n    );\n    return DEFAULT_SHELF_LIFE_DAYS;\n  }\n\n  return raw;\n};\n\nconst resolveFieldShelfLives = (\n  raw: unknown,\n  log: DegradationLog,\n): Partial<Record<LeadFieldKey, number>> => {\n  if (raw === undefined || raw === null) {\n    return {};\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'shelf_life_malformed',\n      'Your per-field shelf lives could not be read, so the single default shelf life was used for every field.',\n    );\n    return {};\n  }\n\n  const resolved: Partial<Record<LeadFieldKey, number>> = {};\n\n  for (const key of LEAD_FIELD_KEYS) {\n    const value = raw[key];\n\n    if (value === undefined || value === null) {\n      continue;\n    }\n\n    if (isFiniteNumber(value) && value > 0) {\n      resolved[key] = value;\n    } else {\n      log.add(\n        'shelf_life_malformed',\n        `The shelf life for \"${key}\" was not a positive number of days, so the default shelf life was used.`,\n      );\n    }\n  }\n\n  return resolved;\n};\n\n/**\n * Resolve one vocabulary list against the three-layer precedence.\n *\n * `shipped` is the in-source constant and `baseline` is the licence-delivered\n * replacement for it, or `undefined` when there is none. The workspace's own\n * value still wins over both \u2014 with one carefully-bounded exception.\n *\n * ## The exception: an unedited seed is not a choice\n *\n * The post-install hook copies the shipped decision-maker list *into* the config\n * record so an admin can see and edit it. Every fresh install therefore holds an\n * \"explicit\" list that is really just the default, and treating it as a choice\n * would let it shadow calibration permanently \u2014 calibration would arrive, verify,\n * publish, and change nothing.\n *\n * So a stored list whose set of entries is exactly the shipped set is recognised\n * as an untouched seed and steps aside for the baseline. Adding or removing a\n * single entry makes it a genuine curation that nothing will override. The\n * comparison is exact set equality: no subset test, no size heuristic, nothing\n * that could mistake a real edit for a seed. And it only ever applies when a\n * baseline exists \u2014 with no calibration, the shipped list is what the seed\n * resolves to either way, so the branch is unreachable in an unlicensed install.\n */\nconst resolveTitleList = (\n  raw: unknown,\n  shipped: readonly string[],\n  baseline: readonly string[] | undefined,\n  label: string,\n  log: DegradationLog,\n): readonly string[] => {\n  const fallback = baseline ?? shipped;\n\n  if (raw === undefined || raw === null) {\n    return fallback;\n  }\n\n  const list = toStringList(raw);\n\n  if (list === null || list.length === 0) {\n    log.add(\n      'title_list_malformed',\n      `Your ${label} list could not be read, so the built-in list was used.`,\n    );\n    return fallback;\n  }\n\n  if (baseline !== undefined && isSameStringSet(list, shipped)) {\n    return baseline;\n  }\n\n  return lowerAll(list);\n};\n\n/**\n * Keys the customer's field mapping is not allowed to move.\n *\n * These are Greenlight's own suppression columns: the app ships them, owns them,\n * and knows exactly where they live. Every other key here is a genuine Layer 3\n * seam because the field belongs to the customer's schema \u2014 these two do not,\n * and a config blob able to point `suppressed` somewhere else is a config blob\n * able to switch the block list off by mistyping a column name. The workspace's\n * *own* opt-out columns remain fully mappable under `optedOut`, and the\n * compliance rule takes the union of the two.\n */\nconst PINNED_FIELD_MAPPING_KEYS: readonly LeadFieldKey[] = [\n  'suppressed',\n  'suppressionReason',\n];\n\n/**\n * The workspace's mapping, resolved and repaired \u2014 before the enriched tail is\n * appended. Split out so `withEnrichedFallbacks` runs on *every* return path,\n * including the two that bail out early on unreadable configuration.\n */\nconst readConfiguredFieldMapping = (\n  raw: unknown,\n  log: DegradationLog,\n): FieldMapping => {\n  const mapping: Record<LeadFieldKey, readonly string[]> = {\n    ...DEFAULT_FIELD_MAPPING,\n  };\n\n  if (raw === undefined || raw === null) {\n    return mapping;\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'field_mapping_malformed',\n      'Your field mapping could not be read, so the default field names were used.',\n    );\n    return mapping;\n  }\n\n  for (const key of LEAD_FIELD_KEYS) {\n    const value = raw[key];\n\n    if (value === undefined || value === null) {\n      continue;\n    }\n\n    if (PINNED_FIELD_MAPPING_KEYS.includes(key)) {\n      log.add(\n        'field_mapping_malformed',\n        `\"${key}\" is one of Greenlight's own do-not-contact fields and cannot be remapped, so the mapping you supplied for it was ignored. Use \"Opt-out fields\" to add your own opt-out columns alongside it.`,\n      );\n      continue;\n    }\n\n    const paths = toStringList(value);\n\n    if (paths === null || paths.length === 0) {\n      log.add(\n        'field_mapping_malformed',\n        `The field mapping for \"${key}\" was unusable, so the default field names were used.`,\n      );\n      continue;\n    }\n\n    mapping[key] = paths;\n  }\n\n  return mapping;\n};\n\nconst resolveFieldMapping = (raw: unknown, log: DegradationLog): FieldMapping =>\n  withEnrichedFallbacks(readConfiguredFieldMapping(raw, log));\n\n/**\n * Turn an untrusted config value into a usable configuration.\n *\n * Never throws. The returned `source` tells the caller whether the workspace's\n * own configuration was used as-is (`provided`), had to be patched\n * (`repaired`), or was absent entirely (`defaults`).\n *\n * ## The baseline argument\n *\n * `baseline` is licence-delivered vocabulary \u2014 see\n * `src/calibration/apply.ts`. It is a *fall-back* replacement, never an\n * override: it stands in for the shipped constants when the workspace has said\n * nothing, and it is invisible when the workspace has said something. Passing\n * `undefined` or `null` \u2014 the unlicensed, offline, stale and\n * signature-failing cases, which is to say every case where anything went wrong\n * \u2014 makes this function behave exactly as it did before the parameter existed.\n * `__tests__/config.test.ts` asserts that identity rather than asserting a\n * promise about it.\n *\n * The baseline never reaches `source`. A calibrated workspace with an otherwise\n * clean config record still reports `provided`, because calibration is not a\n * repair and an admin reading the trace should not see one.\n */\nexport const resolveConfig = (\n  raw: ScoringConfigInput,\n  rules: readonly ScoringRule[] = ALL_RULES,\n  baseline?: ScoringVocabularyBaseline | null,\n): ConfigResolution => {\n  const log = new DegradationLog();\n  const vocabulary = baseline ?? undefined;\n\n  if (raw === undefined || raw === null) {\n    return {\n      config: buildDefaultConfig(rules, vocabulary),\n      source: 'defaults',\n      degradations: [\n        {\n          code: 'config_missing',\n          message:\n            'No Greenlight configuration was found, so this lead was scored with the built-in defaults.',\n        },\n      ],\n    };\n  }\n\n  if (!isPlainObject(raw)) {\n    return {\n      config: buildDefaultConfig(rules, vocabulary),\n      source: 'defaults',\n      degradations: [\n        {\n          code: 'config_malformed',\n          message:\n            'The Greenlight configuration record could not be read, so this lead was scored with the built-in defaults.',\n          detail: `expected an object, received ${Array.isArray(raw) ? 'array' : typeof raw}`,\n        },\n      ],\n    };\n  }\n\n  const resolvedIcp = resolveIcp(raw['icp'], log);\n\n  const config: ResolvedScoringConfig = {\n    // Expansion is applied to the *resolved* ICP, so a workspace that listed\n    // \"SaaS\" keeps \"SaaS\" at the head of the list and gains its cluster behind\n    // it. An empty list is returned untouched \u2014 \"no opinion\" must not become\n    // \"an opinion about eighty industries\".\n    icp: {\n      ...resolvedIcp,\n      industries: expandIndustriesWithSynonyms(\n        resolvedIcp.industries,\n        vocabulary?.industrySynonyms,\n      ),\n    },\n    rules: resolveRuleSettings(raw['rules'], rules, log),\n    bands: resolveBands(raw['bands'], log),\n    gateThreshold: resolveGateThreshold(raw['gateThreshold'], log),\n    defaultShelfLifeDays: resolveShelfLife(raw['defaultShelfLifeDays'], log),\n    fieldShelfLifeDays: resolveFieldShelfLives(raw['fieldShelfLifeDays'], log),\n    decisionMakerTitles: lowerAll(\n      resolveTitleList(\n        raw['decisionMakerTitles'],\n        DEFAULT_DECISION_MAKER_TITLES,\n        vocabulary?.decisionMakerTitles,\n        'decision-maker title',\n        log,\n      ),\n    ),\n    influencerTitles: lowerAll(\n      resolveTitleList(\n        raw['influencerTitles'],\n        DEFAULT_INFLUENCER_TITLES,\n        vocabulary?.influencerTitles,\n        'influencer title',\n        log,\n      ),\n    ),\n    roleInboxLocalParts: lowerAll(\n      resolveTitleList(\n        raw['roleInboxLocalParts'],\n        DEFAULT_ROLE_INBOX_LOCAL_PARTS,\n        vocabulary?.roleInboxLocalParts,\n        'shared-inbox',\n        log,\n      ),\n    ),\n    placeholderValues: lowerAll(\n      resolveTitleList(\n        raw['placeholderValues'],\n        PLACEHOLDER_VALUES,\n        vocabulary?.placeholderValues,\n        'placeholder value',\n        log,\n      ),\n    ),\n    fieldMapping: resolveFieldMapping(raw['fieldMapping'], log),\n  };\n\n  return {\n    config,\n    source: log.count > 0 ? 'repaired' : 'provided',\n    degradations: log.list,\n  };\n};\n", "/**\n * The narrowest possible view of Twenty's Core API client.\n *\n * `CoreApiClient` from `twenty-client-sdk/core` is typed `any` until\n * `dev:generate-client` regenerates it against the installed workspace schema,\n * so depending on it directly buys no type safety and costs testability \u2014 the\n * class reads `API_URL` / `APP_ACCESS_TOKEN` from the process environment in its\n * constructor, which no unit test has.\n *\n * Everything in this folder therefore talks to `GreenlightApiClient`. The\n * `define*` files are the only place `new CoreApiClient()` appears, and they do\n * nothing but hand it to a handler that can be driven by a fake in tests.\n */\n\nexport interface GreenlightApiClient {\n  query(request: Record<string, unknown>): Promise<unknown>;\n  mutation(request: Record<string, unknown>): Promise<unknown>;\n}\n\nexport const isPlainRecord = (\n  value: unknown,\n): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\n/**\n * Twenty returns connections as `{ edges: [{ node }] }`. Pull the nodes out\n * without assuming the shape is correct \u2014 a schema drift should degrade to\n * \"no records found\", never throw.\n */\nexport const readConnectionNodes = (\n  payload: unknown,\n  connectionName: string,\n): Record<string, unknown>[] => {\n  if (!isPlainRecord(payload)) {\n    return [];\n  }\n\n  const connection = payload[connectionName];\n\n  if (!isPlainRecord(connection)) {\n    return [];\n  }\n\n  const edges = connection['edges'];\n\n  if (!Array.isArray(edges)) {\n    return [];\n  }\n\n  return edges.flatMap((edge): Record<string, unknown>[] => {\n    if (!isPlainRecord(edge)) {\n      return [];\n    }\n\n    const node = edge['node'];\n\n    return isPlainRecord(node) ? [node] : [];\n  });\n};\n\n/** ISO-8601 sorts lexicographically, so this needs no Date parsing. */\nexport const oldestByCreatedAt = (\n  records: readonly Record<string, unknown>[],\n): Record<string, unknown> | null => {\n  let oldest: Record<string, unknown> | null = null;\n  let oldestKey: string | null = null;\n\n  for (const record of records) {\n    const createdAt = record['createdAt'];\n    const key = typeof createdAt === 'string' ? createdAt : '';\n\n    if (oldest === null || oldestKey === null || key < oldestKey) {\n      oldest = record;\n      oldestKey = key;\n    }\n  }\n\n  return oldest;\n};\n\n/**\n * Structured log line. Logic functions have no logger injected \u2014 stdout is what\n * `yarn twenty dev:function:logs` shows \u2014 so everything Greenlight emits is a\n * single JSON object with a stable `event` key that support can grep for.\n */\nexport const logGreenlight = (\n  event: string,\n  detail: Record<string, unknown>,\n): void => {\n  // eslint-disable-next-line no-console\n  console.log(JSON.stringify({ app: 'numaya-greenlight', event, ...detail }));\n};\n\nexport const describeError = (error: unknown): string => {\n  if (error instanceof Error) {\n    return `${error.name}: ${error.message}`;\n  }\n\n  if (typeof error === 'string') {\n    return error;\n  }\n\n  try {\n    return JSON.stringify(error) ?? 'unknown error';\n  } catch {\n    return 'unknown error';\n  }\n};\n", "/**\n * Numaya Greenlight \u2014 does the Layer 3 field mapping name fields that exist?\n *\n * Pure, like `backfill-plan.ts` and `backfill-state.ts` beside it, and for the\n * same reason: the request shape below and the reading of what came back are the\n * two things most likely to be wrong against a real schema, and a pure module is\n * the only place they can be asserted without a workspace. The one piece of I/O\n * the check needs \u2014 actually asking Twenty \u2014 is issued by `backfill-run.ts`.\n *\n * ============================================================================\n * ## The defect this exists to make visible\n *\n * An admin maps logical keys to their own field names on the `GreenlightConfig`\n * record: `decisionMakerFieldName`, `readyForOutreachFieldName`,\n * `optOutFieldNames`. Those names reach exactly one place in a request \u2014 the\n * **selection set** (`configuredSelectionFields` in `backfill-plan.ts`).\n *\n * It was believed, and written down in this repository, that a name which does\n * not exist would fail the query and trip the backfill's retry ladder. That was\n * wrong. Proved against a live instance in `src/__live__/api-contract.live-test.ts`:\n *\n *   - Twenty **validates arguments** \u2014 `filter`, `orderBy`, a mutation's `data`.\n *     A field the object does not have is rejected outright.\n *   - Twenty **does not validate selection sets**. A column the object does not\n *     have is selected without complaint and comes back `null`.\n *\n * So a single mistyped character in a settings field does not fail anything. The\n * page succeeds, the column arrives `null`, and the engine scores the record as\n * though a human had deliberately left that field blank. The backfill runs to\n * completion, reports success, and every score in the workspace is quietly worse\n * than it should be. No error, no notice, nothing for an admin to find.\n *\n * That is the worst class of defect this product can have, because it makes the\n * scores wrong while the product looks healthy, and the scores are what\n * customers buy.\n *\n * ============================================================================\n * ## Why the probe is a filter and never a selection\n *\n * Probing by selection is the bug itself: `{ people { edges { node { nonesuch } } } }`\n * answers happily on every workspace in existence, so a probe built that way\n * reports every name as present and is worse than no probe at all. Two field\n * probes in this repository were written that way and both answered `true`\n * everywhere \u2014 `probeOpportunityOwner` in `pipeline-store.ts` and `probeField` in\n * `icp-run.ts`, the latter reporting an ICP derived from industry columns that\n * mostly do not exist.\n *\n * The technique that works is the one `icp-run.ts` was corrected to use: put the\n * name in the half of the query Twenty *does* check.\n *\n *     people(first: 1, filter: { <name>: { is: \"NOT_NULL\" } }) { edges { node { id } } }\n *\n * `NOT_NULL` over `NULL` only because it reads as the question being asked: is\n * there such a thing. The rows are never looked at.\n *\n * ============================================================================\n * ## Silence is the safe answer, and this module is built to prefer it\n *\n * A validation that can break scoring is worse than the bug it was written to\n * catch, so nothing here is allowed to guess. A name is reported missing on one\n * condition only: Twenty rejected the probe with a message that names *that*\n * field as one the object does not have. Every other outcome \u2014 a composite type,\n * a transport failure, a permission error, an empty response, a message this\n * module does not recognise \u2014 resolves to `inconclusive`, which says nothing to\n * anybody and leaves scoring exactly as it is today.\n *\n * The composite case is worth stating on its own, because it is the one that\n * would produce a *false accusation* rather than a missed one. A configured name\n * pointing at a composite (`CURRENCY`, `ADDRESS`, `LINKS`, `emails`, `phones`)\n * is rejected with *\"Sub field 'is' not found for composite type: \u2026\"*. The field\n * plainly exists \u2014 the probe simply cannot ask about it this way \u2014 so that shape\n * is read as **present**. `icp-run.ts` makes the opposite trade for its own\n * candidates and is right to: it is choosing between candidate columns and\n * \"no industry field answered\" is a true thing to say about a currency-typed\n * industry. Here the output is a sentence telling an admin their configuration is\n * wrong, and telling them that about a field they can see on the record page is\n * the kind of mistake that gets a warning ignored forever afterwards.\n */\n\nimport { DEFAULT_FIELD_MAPPING } from 'src/scoring';\n\nimport { isPlainRecord } from 'src/logic-functions/greenlight-api';\n\n/* -------------------------------------------------------------------------- */\n/* Which settings carry a field name                                           */\n/* -------------------------------------------------------------------------- */\n\n/** The `GreenlightConfig` settings whose value is a field name on the lead. */\nexport type MappedFieldSource =\n  | 'decisionMakerFieldName'\n  | 'readyForOutreachFieldName'\n  | 'optOutFieldNames';\n\ninterface MappedFieldSourceDescriptor {\n  /** The setting's label on the record page, so the sentence is findable. */\n  readonly label: string;\n  /**\n   * The engine's logical key this setting feeds, or `null` for a setting that\n   * only widens the selection. Naming the key is half of what makes the notice\n   * actionable: \"this name is wrong\" is a fault report, \"this name is wrong *so\n   * the decision-maker signal is being read as empty*\" is a decision.\n   */\n  readonly logicalKey: keyof typeof DEFAULT_FIELD_MAPPING | null;\n}\n\nexport const MAPPED_FIELD_SOURCES: Readonly<\n  Record<MappedFieldSource, MappedFieldSourceDescriptor>\n> = {\n  decisionMakerFieldName: {\n    label: 'Decision-maker field',\n    logicalKey: 'jobTitle',\n  },\n  readyForOutreachFieldName: {\n    label: 'Ready-for-outreach field',\n    logicalKey: null,\n  },\n  optOutFieldNames: { label: 'Opt-out fields', logicalKey: 'optedOut' },\n};\n\nexport interface MappedFieldName {\n  readonly name: string;\n  readonly source: MappedFieldSource;\n}\n\n/**\n * A plain GraphQL identifier, and nothing else, ever.\n *\n * Config values are admin-supplied text one query away from the schema, so a\n * name that is not an identifier is dropped rather than interpolated. Dropping\n * is also why the check below can be honest about its own coverage: a name this\n * regex rejects never reaches a request, so it cannot be silently read as\n * `null`, and there is nothing to report about it.\n */\nconst FIELD_NAME = /^[A-Za-z_][A-Za-z0-9_]*$/;\n\nconst asFieldName = (value: unknown): string | null => {\n  if (typeof value !== 'string') {\n    return null;\n  }\n\n  const trimmed = value.trim();\n\n  return FIELD_NAME.test(trimmed) ? trimmed : null;\n};\n\n/**\n * Every field name the workspace has pointed Greenlight at, with the setting it\n * came from.\n *\n * The provenance is the point. `configuredSelectionFields` in `backfill-plan.ts`\n * needs only the strings and is derived from this, so the two can never disagree\n * about which names reach a request \u2014 but a notice that says *\"\u2018jobTitl\u2019 is not\n * a field\"* without saying which box it was typed into leaves an admin hunting\n * through a record page, and a notice nobody can act on is furniture.\n *\n * De-duplicated by name: the same string in two settings is one column to probe,\n * and it keeps the first setting that mentioned it because that is the reading\n * order of the record page.\n */\nexport const mappedFieldNames = (\n  configRecord: unknown,\n): MappedFieldName[] => {\n  if (!isPlainRecord(configRecord)) {\n    return [];\n  }\n\n  const found: MappedFieldName[] = [];\n  const seen = new Set<string>();\n\n  const add = (value: unknown, source: MappedFieldSource): void => {\n    const name = asFieldName(value);\n\n    if (name === null || seen.has(name)) {\n      return;\n    }\n\n    seen.add(name);\n    found.push({ name, source });\n  };\n\n  add(configRecord['decisionMakerFieldName'], 'decisionMakerFieldName');\n  add(configRecord['readyForOutreachFieldName'], 'readyForOutreachFieldName');\n\n  const optOutFields = configRecord['optOutFieldNames'];\n\n  if (Array.isArray(optOutFields)) {\n    for (const value of optOutFields) {\n      add(value, 'optOutFieldNames');\n    }\n  }\n\n  return found;\n};\n\n/* -------------------------------------------------------------------------- */\n/* The probe                                                                   */\n/* -------------------------------------------------------------------------- */\n\n/**\n * How many names one check is allowed to ask about.\n *\n * `optOutFieldNames` is a free-text array an admin can paste anything into, and a\n * check that scaled with it would let a fifty-entry list turn one click on Start\n * into fifty requests against a 100-a-minute ceiling the backfill's own chunk\n * arithmetic already spends 62 of. A workspace configuring more than eight\n * mapped columns is not the shape this product is sold in, and the names past\n * the limit are simply not asked about \u2014 they are reported as unchecked in the\n * log rather than quietly assumed correct.\n *\n * Eight is comfortably above the realistic ceiling: one decision-maker field,\n * one ready-for-outreach field and up to six workspace opt-out columns.\n */\nexport const FIELD_MAPPING_PROBE_LIMIT = 8;\n\n/**\n * The cheapest question that means \"does this column exist\", as a request.\n *\n * `first: 1` and a selection of nothing but `id`: the answer is carried entirely\n * by whether Twenty accepted the argument, so fetching a row is incidental and\n * fetching a wide one would be waste.\n */\nexport const buildFieldExistenceProbe = (\n  connection: string,\n  fieldName: string,\n): Record<string, unknown> => ({\n  [connection]: {\n    __args: { first: 1, filter: { [fieldName]: { is: 'NOT_NULL' } } },\n    edges: { node: { id: true } },\n  },\n});\n\n/**\n * `absent` is the only verdict that ever reaches an admin. The other two are\n * both silence, and are kept apart only so the log can say which kind it was.\n */\nexport type FieldProbeVerdict = 'present' | 'absent' | 'inconclusive';\n\n/**\n * Did the response actually answer, or did it merely come back?\n *\n * A rejected request normally throws out of the client, but a transport that\n * returns `{ errors, data: null }` without throwing would make every probe look\n * like a success. Requiring the connection to be present costs nothing and\n * closes that path \u2014 and because an unrecognised shape resolves to\n * `inconclusive` rather than `absent`, closing it errs towards saying nothing.\n */\nexport const probeAnswered = (\n  connection: string,\n  response: unknown,\n): boolean =>\n  isPlainRecord(response) && isPlainRecord(response[connection]);\n\n/**\n * Twenty's way of saying \"that object has no such field\", in the two spellings\n * this app has actually seen come back.\n *\n * The first is the one that cost this repository months of wrong pipeline\n * criteria: `Object taskTarget doesn't have any \"opportunityId\" field.` The\n * second is the standard GraphQL rejection for a filter input that has no such\n * member. Both are matched only in company with the field's own name, so a\n * message about some *other* field \u2014 a nested error, a batched response \u2014 can\n * never be read as a verdict on this one.\n */\nconst ABSENT_PHRASES: readonly RegExp[] = [\n  /does(?:n['\u2019]t| not) have any/i,\n  /is not defined by type/i,\n  /unknown field/i,\n];\n\n/**\n * The field exists; the probe simply may not ask about it this way. See the\n * header: reporting a visible column as missing is the failure mode that gets\n * every future notice ignored, so this shape is read as present.\n */\nconst COMPOSITE_PHRASE = /sub ?field .* (?:not found|is not defined)/i;\n\n/**\n * Read a rejection. Anything unrecognised is `inconclusive`, on purpose.\n *\n * This is where fail-open is actually implemented, so it is worth being blunt\n * about the trade: a Twenty release that reworded its errors turns this check\n * off \u2014 every probe becomes `inconclusive`, nothing is reported, and scoring\n * behaves precisely as it does today. It does not turn the check into a source\n * of false accusations, and it cannot stop a backfill. The live contract test is\n * what would notice the rewording; this function is what makes the rewording\n * survivable in the meantime.\n */\nexport const classifyProbeRejection = (\n  fieldName: string,\n  message: string,\n): FieldProbeVerdict => {\n  if (COMPOSITE_PHRASE.test(message)) {\n    return 'present';\n  }\n\n  if (!message.includes(fieldName)) {\n    return 'inconclusive';\n  }\n\n  return ABSENT_PHRASES.some((phrase) => phrase.test(message))\n    ? 'absent'\n    : 'inconclusive';\n};\n\n/* -------------------------------------------------------------------------- */\n/* What an admin is told                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport interface MappingFinding {\n  readonly name: string;\n  readonly source: MappedFieldSource;\n}\n\nexport interface FieldMappingCheckResult {\n  /** Names Twenty explicitly said the object does not have. */\n  readonly missing: readonly MappingFinding[];\n  /** How many names were asked about. */\n  readonly probed: number;\n  /** Asked, but the answer could not be trusted either way. */\n  readonly inconclusive: number;\n  /** Past `FIELD_MAPPING_PROBE_LIMIT`, or the check never ran. */\n  readonly unchecked: number;\n}\n\nexport const EMPTY_FIELD_MAPPING_CHECK: FieldMappingCheckResult = {\n  missing: [],\n  probed: 0,\n  inconclusive: 0,\n  unchecked: 0,\n};\n\n/** The candidates the engine still reads when a configured name is not there. */\nconst fallbacksFor = (finding: MappingFinding): readonly string[] => {\n  const key = MAPPED_FIELD_SOURCES[finding.source].logicalKey;\n\n  if (key === null) {\n    return [];\n  }\n\n  return DEFAULT_FIELD_MAPPING[key].filter((path) => path !== finding.name);\n};\n\n/** \"a, b and c\" \u2014 an English list, because this is a sentence a human reads. */\nconst asList = (values: readonly string[]): string => {\n  if (values.length <= 1) {\n    return values[0] ?? '';\n  }\n\n  return `${values.slice(0, -1).join(', ')} and ${values[values.length - 1]}`;\n};\n\n/**\n * What this particular name being absent actually costs.\n *\n * Precision here is the whole requirement. \"Invalid config\" is useless, and so\n * is overstating it: the Layer 3 mapping *prepends* a configured name to the\n * engine's shipped candidates rather than replacing them (see `readFieldMapping`\n * in `greenlight-config-record.ts`), so a mistyped decision-maker field does not\n * blank the signal for every lead \u2014 it blanks it for the leads whose seniority\n * lives only in the workspace's own column. Saying \"no lead has a job title\"\n * would be a bigger claim than the code makes, and an admin who checks one\n * record and finds it scored fine will stop believing the next notice too.\n */\nconst consequenceOf = (finding: MappingFinding): string => {\n  const fallbacks = fallbacksFor(finding);\n\n  switch (finding.source) {\n    case 'decisionMakerFieldName':\n      return fallbacks.length === 0\n        ? 'the decision-maker rule has nothing left to read, so seniority scores nothing on any lead'\n        : `Greenlight falls back to ${asList(fallbacks)}, so a lead whose seniority is recorded only in that column is scored as though it had no job title`;\n\n    case 'optOutFieldNames':\n      return fallbacks.length === 0\n        ? 'nothing is left for the compliance rule to read, so no lead can be recognised as opted out'\n        : `Greenlight falls back to ${asList(fallbacks)}, so a lead who has opted out only in that column is not recognised as opted out and can be released for outreach`;\n\n    case 'readyForOutreachFieldName':\n    default:\n      return 'no rule reads that setting in this release, so no score changes \u2014 but the setting is not pointing at anything, and it will matter as soon as one does';\n  }\n};\n\n/**\n * The paragraph the admin reads, or `null` when there is nothing to say.\n *\n * One paragraph rather than a list because the panel renders this string as\n * prose, and a bullet list that arrives as a run-on line is worse than a\n * sentence written to be one. It leads with the consequence, names each field\n * and the box it was typed into, and ends with the two things to do \u2014 because a\n * notice that stops at \"something is wrong\" makes the reader do the work of\n * working out whether it matters.\n *\n * It never suggests the admin made a mistake. A field can vanish from a\n * workspace long after somebody typed its name correctly, and the sentence is\n * true either way.\n */\nexport const describeFieldMappingFindings = (\n  missing: readonly MappingFinding[],\n  objectLabel: string,\n): string | null => {\n  if (missing.length === 0) {\n    return null;\n  }\n\n  const head =\n    missing.length === 1\n      ? `Greenlight\u2019s field mapping names a field ${objectLabel} does not have, so this backfill reads it as empty on every lead.`\n      : `Greenlight\u2019s field mapping names ${missing.length} fields ${objectLabel} does not have, so this backfill reads them as empty on every lead.`;\n\n  const lines = missing.map(\n    (finding) =>\n      `\u201C${finding.name}\u201D (${MAPPED_FIELD_SOURCES[finding.source].label}) is not a field on ${objectLabel} \u2014 ${consequenceOf(finding)}.`,\n  );\n\n  return [\n    head,\n    ...lines,\n    'Correct the name on the Greenlight Configuration record, then run a backfill over all records to re-score what this run has already done.',\n  ].join(' ');\n};\n\n/** The audit row's name \u2014 what the log shows before anybody opens the row. */\nexport const fieldMappingAuditName = (\n  missing: readonly MappingFinding[],\n  objectLabel: string,\n): string =>\n  missing.length === 1 && missing[0] !== undefined\n    ? `ERROR \u00B7 Greenlight field mapping \u00B7 \u201C${missing[0].name}\u201D is not a field on ${objectLabel}`\n    : `ERROR \u00B7 Greenlight field mapping \u00B7 ${missing.length} configured names are not fields on ${objectLabel}`;\n\n/**\n * The structured half of the audit row, so the trail carries the facts and not\n * only the sentence. Same split as everywhere else here: `name` is for reading,\n * `ruleTrace` is for answering questions later.\n */\nexport const fieldMappingAuditDetail = (\n  result: FieldMappingCheckResult,\n  objectNameSingular: string,\n): Record<string, unknown> => ({\n  action: 'field_mapping_check',\n  leadObjectNameSingular: objectNameSingular,\n  missing: result.missing.map((finding) => ({\n    name: finding.name,\n    setting: finding.source,\n    settingLabel: MAPPED_FIELD_SOURCES[finding.source].label,\n    logicalKey: MAPPED_FIELD_SOURCES[finding.source].logicalKey,\n    remainingCandidates: fallbacksFor(finding),\n  })),\n  probed: result.probed,\n  inconclusive: result.inconclusive,\n  unchecked: result.unchecked,\n});\n", "/**\n * Numaya Greenlight \u2014 how one backfill tick decides what to read.\n *\n * Pure, like `backfill-state.ts` and for the same reason: the request shapes\n * below are the part most likely to be wrong against a real schema, and a pure\n * module is the only place they can be asserted without a workspace.\n *\n * Three things live here \u2014 the size of a chunk and the arithmetic that fixes it,\n * the Person selection and why it is exactly that wide, and the keyset cursor.\n */\n\nimport { mappedFieldNames } from 'src/backfill/field-mapping-check';\nimport { isPlainRecord } from 'src/logic-functions/greenlight-api';\n\nimport type { BackfillCursor, BackfillMode } from 'src/backfill/backfill-state';\n\n/* -------------------------------------------------------------------------- */\n/* Chunk size \u2014 the rate-limit arithmetic                                      */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Twenty's documented ceiling. Stated here rather than left implicit because\n * every number below is derived from it and a future change to it must land in\n * one place.\n */\nexport const TWENTY_REQUESTS_PER_MINUTE = 100;\n\n/**\n * Records handled per cron tick, and the cron fires once a minute.\n *\n * ## The arithmetic\n *\n * Per tick, against the Core API:\n *\n *     1   page query      (this module's `buildPageRequest`)\n *     1   config query    (`loadConfigRecord`, hoisted out of the per-record path)\n *   2\u00D7N   record writes   (`createGreenlightAuditLog` + `updatePerson`)\n *     \u2500\u2500\u2500\u2500\u2500\n *     2 + 2N requests\n *\n * `2\u00D7N` is the worst case: it is what a record whose outcome actually *changed*\n * costs. A record guard 3 recognises as unchanged costs zero writes, so a re-run\n * over an already-scored workspace issues 2 requests a minute, not 62.\n *\n * At N = 30:  2 + 60 = **62 Core API requests per minute**, 62% of the ceiling.\n *\n * Against app key-value storage, per tick: 1 state read, 2 state writes (claim\n * the lease, commit the chunk), and up to N release-marker reads \u2014 but only for\n * records the engine wants to *hold*, since `pinReleasedDecision` does not spend\n * a read on a passing lead. Worst case 33 key-value operations. If Twenty ever\n * counts those against the same bucket the total is 95, still inside 100.\n *\n * ## Why not 49, which is what 100 requests would actually buy\n *\n * Because the backfill is not the only thing talking to the API. The create and\n * update scoring hooks keep firing while it runs, each costing up to 3 requests,\n * and a workspace importing leads during a backfill is not a hypothetical \u2014 it is\n * the most likely time for one. Roughly 38 requests a minute of headroom is\n * twelve concurrent live scoring events, which is a busy import.\n *\n * Spending the whole budget would make the backfill throttle the live gate. A\n * backfill that finishes an hour sooner by making new leads score late has\n * optimised the wrong thing: new leads are the ones a rep is about to call.\n *\n * ## What it costs in wall-clock\n *\n * 30/minute = 1,800/hour. The 1,205-person dev workspace: ~40 minutes. A\n * 10,000-contact workspace: ~5.6 hours. Both unattended, both resumable, and\n * both visible while they run \u2014 which is the requirement, rather than speed.\n */\nexport const BACKFILL_CHUNK_SIZE = 30;\n\n/**\n * Twenty's page ceiling \u2014 the documented batch size. A page may therefore be\n * twice a chunk, and the difference is spent on the cursor boundary rather than\n * on scoring: see `pageSizeFor`.\n */\nexport const BACKFILL_PAGE_SIZE = 60;\n\n/**\n * Stop starting new records after this much of the tick has gone.\n *\n * The cron function is registered with `timeoutSeconds: 55`. Being killed by the\n * platform is survivable \u2014 the cursor simply does not advance and the next tick\n * redoes the chunk \u2014 but it is wasteful, and it makes the panel's counters lag\n * reality by a whole lease. Stopping early and committing the prefix that was\n * actually finished is strictly better: the position is recorded, and the tail is\n * re-fetched rather than re-scored.\n */\nexport const BACKFILL_TICK_BUDGET_MS = 40_000;\n\n/* -------------------------------------------------------------------------- */\n/* What to read off a Person                                                   */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The Person columns a bulk score reads.\n *\n * ## The governing constraint is parity, not completeness\n *\n * The event path hands `scoring-run.ts` `event.properties.after` \u2014 every column\n * on the record \u2014 and then hydrates the company with exactly `{ id, name }` (see\n * `hydrateCompany`). A backfilled lead and a freshly-created lead must land on\n * the same score, or the gate queue becomes incoherent: the same person scores\n * one way if they were imported yesterday and another if they arrive tomorrow,\n * and nobody can explain the queue to the rep working it.\n *\n * So this selection deliberately does **not** pull richer company data than the\n * event path can see. `company.industry` and `company.employees` would raise ICP\n * scores \u2014 and would raise them only for backfilled records. Being consistently\n * conservative beats being inconsistently generous.\n *\n * ## The three that are not about scoring\n *\n *   - `greenlightTrace` carries the stored outcome fingerprint. Without it guard\n *     3 cannot fire, and every backfill pass would rewrite every record and\n *     append a duplicate audit row. This one field is what makes re-running the\n *     backfill idempotent.\n *   - `greenlightDecision` and `greenlightScore` are what the modes filter and\n *     sort on, and what the panel counts.\n *   - `createdAt` is the cursor. `updatedAt` is also the freshness rule's input.\n *\n * ## The suppression columns are not optional\n *\n * `greenlightSuppressed` / `greenlightSuppressionReason` are the compliance\n * rule's primary input (`DEFAULT_FIELD_MAPPING.suppressed`). Omitting them would\n * make every bulk-scored record answer the compliance question with \"nothing on\n * this record says\" \u2014 and a workspace's whole do-not-contact register would be\n * silently ignored for exactly the records nobody has checked yet. That is the\n * single worst thing this feature could do, so they are listed first among the\n * Greenlight fields and asserted in the tests.\n */\nexport const backfillPersonSelection = (\n  extraFieldNames: readonly string[] = [],\n): Record<string, unknown> => {\n  const selection: Record<string, unknown> = {\n    id: true,\n    createdAt: true,\n    updatedAt: true,\n    name: { firstName: true, lastName: true },\n    emails: { primaryEmail: true, additionalEmails: true },\n    phones: {\n      primaryPhoneNumber: true,\n      primaryPhoneCallingCode: true,\n      primaryPhoneCountryCode: true,\n      additionalPhones: true,\n    },\n    jobTitle: true,\n    city: true,\n    linkedinLink: { primaryLinkUrl: true, primaryLinkLabel: true },\n    // Both, for the same reason `SCORING_TRIGGER_PERSON_FIELDS` lists both: the\n    // relation and its foreign key are reported under different names across\n    // versions. Supplying `company` is also what stops `hydrateCompany` spending\n    // an extra query per record \u2014 the difference between 2 and 3 requests each.\n    companyId: true,\n    company: { id: true, name: true },\n    greenlightSuppressed: true,\n    greenlightSuppressionReason: true,\n    // A scoring *input*, not bookkeeping: the resolved field mapping appends\n    // `greenlightEnrichment.fields.<key>.parsedValue` to every enrichable key,\n    // so a page fetched without this column scores an enriched lead as though it\n    // had never been enriched \u2014 and a bulk pass would then disagree with the\n    // event path on the same record. The two sibling columns are deliberately\n    // absent; no rule reads a date or a status.\n    greenlightEnrichment: true,\n    greenlightScore: true,\n    greenlightDecision: true,\n    greenlightTrace: true,\n  };\n\n  for (const name of extraFieldNames) {\n    if (!(name in selection)) {\n      selection[name] = true;\n    }\n  }\n\n  return selection;\n};\n\n/**\n * The Layer 3 field names a workspace has pointed Greenlight at, so a customised\n * workspace scores the same in bulk as it does on an event.\n *\n * The event path gets every column for free; this one has to ask by name, and the\n * names it does not know are exactly the ones an admin configured. Anything that\n * is not a plain GraphQL identifier is dropped rather than interpolated \u2014 a\n * config field is admin-supplied text, and it is one query away from the schema.\n * That filtering, and the provenance of each name, now live in\n * `field-mapping-check.ts`, which needs to know not just *which* names reach a\n * request but *which setting* each one was typed into. One list, one owner: the\n * names this function puts in a selection are by construction the names that\n * module probes.\n *\n * ## What a typo in a configured name actually does\n *\n * This used to read: \"a name that passes the regex but does not exist still fails\n * the query, which is why `backfill-run.ts` retries the page without extras\n * before giving up.\" That is wrong, and it was wrong in the direction that hides\n * the problem.\n *\n * Proved against a live instance (`src/__live__/api-contract.live-test.ts`):\n * **Twenty validates arguments and does not validate selection sets.** A `filter`\n * or `orderBy` naming a column the object lacks is rejected outright; a\n * *selected* column the object lacks is accepted and comes back `null`.\n *\n * These names only ever reach the selection. So a typo in a settings field does\n * not fail the page and does not trip the retry ladder \u2014 the query succeeds, the\n * column arrives as `null`, and the engine scores the record as though the human\n * had left that field blank. The backfill runs to completion, reports success,\n * and produces quietly worse scores across the whole workspace.\n *\n * It is still not this function's job to fix that \u2014 a page builder that started\n * probing the schema would put a round trip on the path a tick takes every\n * minute. It is fixed one level up and once per run: `startBackfill` in\n * `backfill-run.ts` asks Twenty whether each of these names exists, using the\n * half of a query Twenty actually checks, and reports the ones that do not to the\n * panel and the audit log. See `field-mapping-check.ts` for why the probe is a\n * filter and never a selection.\n */\nexport const configuredSelectionFields = (configRecord: unknown): string[] =>\n  mappedFieldNames(configRecord).map((mapped) => mapped.name);\n\n/* -------------------------------------------------------------------------- */\n/* The page request                                                            */\n/* -------------------------------------------------------------------------- */\n\nexport interface PageRequestInput {\n  readonly mode: BackfillMode;\n  readonly cursor: BackfillCursor;\n  readonly chunkSize: number;\n  readonly selection: Record<string, unknown>;\n  /**\n   * False drops `orderBy` **and** the cursor together \u2014 they are one mechanism\n   * and a cursor without an order is a random walk. See `PAGE_ATTEMPTS`.\n   */\n  readonly ordered: boolean;\n}\n\n/**\n * `is: 'NULL'` rather than a comparison against a value: a Person that predates\n * the app has no `greenlightDecision` at all, which is a different state from the\n * `UNSCORED` value the fail-open path writes. See `BACKFILL_MODES`.\n */\nexport const buildModeFilter = (mode: BackfillMode): Record<string, unknown> =>\n  mode === 'unscored' ? { greenlightDecision: { is: 'NULL' } } : {};\n\n/**\n * `gte`, not `gt`, and the boundary ids in the cursor are what make that correct.\n *\n * `createdAt` is not unique \u2014 a CSV import stamps hundreds of records within the\n * same millisecond. `gt` would step straight over every record sharing the\n * boundary timestamp with the last one handled, silently leaving them unscored:\n * the exact class of bug this whole feature exists to fix, reintroduced inside\n * the fix. `gte` re-reads the boundary and `cursor.ids` removes the ones already\n * done.\n */\nexport const buildPageFilter = ({\n  mode,\n  cursor,\n  ordered,\n}: Pick<PageRequestInput, 'mode' | 'cursor' | 'ordered'>): Record<\n  string,\n  unknown\n> => {\n  const filter: Record<string, unknown> = { ...buildModeFilter(mode) };\n\n  if (ordered && cursor.createdAt !== null) {\n    filter['createdAt'] = { gte: cursor.createdAt };\n  }\n\n  return filter;\n};\n\n/**\n * How many rows to ask for, given how many the page will have to skip.\n *\n * A `gte` cursor re-reads every record sharing the boundary timestamp, and\n * `cursor.ids` is how those are recognised and skipped. If the page were sized to\n * the chunk, those skips would eat the chunk's budget \u2014 and in the worst case a\n * page could be *entirely* boundary records, examine nothing, advance nothing,\n * and repeat forever. That is head-of-line blocking, and it is not hypothetical:\n * Postgres `now()` is constant within a transaction, so an import writes rows\n * with identical `createdAt`.\n *\n * Over-fetching by exactly the boundary size means a page always contains a full\n * chunk of *new* records, right up to Twenty's page ceiling. It costs nothing \u2014\n * it is the same single request either way, which is why the rate arithmetic on\n * `BACKFILL_CHUNK_SIZE` is unaffected.\n *\n * `BACKFILL_MAX_CURSOR_IDS` is what stops the boundary set outgrowing the\n * headroom; past that the walk can only re-read records, never skip one, and\n * `BACKFILL_MAX_STALLS` turns a walk that has stopped advancing into a visible\n * failure rather than a silent spin.\n */\nexport const pageSizeFor = (\n  chunkSize: number,\n  cursor: BackfillCursor,\n): number => Math.min(BACKFILL_PAGE_SIZE, chunkSize + cursor.ids.length);\n\nexport const buildPageRequest = ({\n  mode,\n  cursor,\n  chunkSize,\n  selection,\n  ordered,\n}: PageRequestInput): Record<string, unknown> => {\n  const filter = buildPageFilter({ mode, cursor, ordered });\n\n  const args: Record<string, unknown> = {\n    first: ordered ? pageSizeFor(chunkSize, cursor) : chunkSize,\n  };\n\n  if (Object.keys(filter).length > 0) {\n    args['filter'] = filter;\n  }\n\n  if (ordered) {\n    args['orderBy'] = [{ createdAt: 'AscNullsFirst' }];\n  }\n\n  return { people: { __args: args, edges: { node: selection } } };\n};\n\n/**\n * The ladder `backfill-run.ts` walks when a page query is rejected, in order.\n *\n * Each rung drops the next-most-likely cause and keeps everything below it:\n *\n *   1. **Everything.** Ordered, cursored, with the workspace's configured field\n *      names in the selection.\n *   2. **Without the configured names.** This rung is, on Twenty 2.26,\n *      **unreachable**, and the comment that used to be here said the opposite \u2014\n *      \"by far the likeliest failure\". Configured names only ever enter the\n *      *selection*, and Twenty does not validate selection sets: an unknown\n *      column is accepted and returns `null`. So a mistyped mapping cannot reject\n *      a page, and this rung cannot be the thing that saves it. See\n *      `configuredSelectionFields` for what a typo does instead, which is worse\n *      than a failed page and much quieter.\n *\n *      It stays in the ladder for two reasons. It is free \u2014 a rung that never\n *      fires costs one unreached branch \u2014 and it is the correct response if a\n *      future Twenty starts validating selections, which is the stricter and more\n *      likely direction for that behaviour to move. The live contract test\n *      exercises every rung, so this note stops being true the moment it stops\n *      being true.\n *   3. **Unordered and uncursored.** Only reachable in `unscored` mode, and it\n *      works there because that mode's filter *is* the queue: a record the tick\n *      scores stops matching `greenlightDecision is NULL`, so repeatedly asking\n *      for \"the next 30 unscored\" drains the workspace with no ordering support\n *      whatsoever. In `all` mode there is no such self-consuming filter, so there\n *      is no honest fallback and the run records the error and stalls where an\n *      admin can see it \u2014 which is the correct outcome, not a worse one.\n *\n * The ladder exists because `orderBy` direction enums and cursor comparators are\n * the two things in this file that cannot be verified without a live schema, and\n * an app that stops scoring a whole workspace because of an enum spelling is a\n * bad trade against ~30 lines of degradation.\n */\nexport const PAGE_ATTEMPTS = [\n  { useExtraFields: true, ordered: true },\n  { useExtraFields: false, ordered: true },\n  { useExtraFields: false, ordered: false },\n] as const;\n\n/** Counting is a nicety: it drives the progress bar and nothing else. */\nexport const buildCountRequest = (\n  mode: BackfillMode,\n): Record<string, unknown> => {\n  const filter = buildModeFilter(mode);\n\n  return {\n    people: {\n      ...(Object.keys(filter).length > 0 ? { __args: { filter } } : {}),\n      totalCount: true,\n    },\n  };\n};\n\nexport const readTotalCount = (response: unknown): number | null => {\n  if (!isPlainRecord(response)) {\n    return null;\n  }\n\n  const connection = response['people'];\n\n  if (!isPlainRecord(connection)) {\n    return null;\n  }\n\n  const total = connection['totalCount'];\n\n  return typeof total === 'number' && Number.isFinite(total) && total >= 0\n    ? Math.floor(total)\n    : null;\n};\n\n/* -------------------------------------------------------------------------- */\n/* The cursor                                                                  */\n/* -------------------------------------------------------------------------- */\n\nexport const readNodeId = (node: unknown): string | null =>\n  isPlainRecord(node) && typeof node['id'] === 'string' && node['id'].length > 0\n    ? node['id']\n    : null;\n\nexport const readNodeCreatedAt = (node: unknown): string | null =>\n  isPlainRecord(node) &&\n  typeof node['createdAt'] === 'string' &&\n  node['createdAt'].length > 0\n    ? node['createdAt']\n    : null;\n\n/** Has this record already been handled at the current cursor boundary? */\nexport const isAlreadyHandled = (\n  cursor: BackfillCursor,\n  node: unknown,\n): boolean => {\n  const id = readNodeId(node);\n\n  return id !== null && cursor.ids.includes(id);\n};\n\n/**\n * Move the cursor over the records this tick actually reached.\n *\n * `handled` must be a **prefix** of the page in `createdAt` order \u2014 the records\n * the tick got through before its budget ran out, including any it skipped\n * because they were already at the boundary. Passing the whole page when only\n * part of it was processed is how a backfill silently skips records, so\n * `backfill-run.ts` builds the prefix as it goes rather than after the fact.\n *\n * The boundary id set carries forward only when the timestamp did not move; a\n * new timestamp starts a fresh, and usually tiny, set.\n */\nexport const advanceCursor = (\n  previous: BackfillCursor,\n  handled: readonly unknown[],\n): BackfillCursor => {\n  if (handled.length === 0) {\n    return previous;\n  }\n\n  const last = handled[handled.length - 1];\n  const createdAt = readNodeCreatedAt(last) ?? previous.createdAt;\n\n  const carried =\n    previous.createdAt === createdAt ? previous.ids : ([] as readonly string[]);\n\n  const atBoundary = handled\n    .filter((node) => (readNodeCreatedAt(node) ?? createdAt) === createdAt)\n    .map(readNodeId)\n    .filter((id): id is string => id !== null);\n\n  return {\n    createdAt,\n    ids: [...new Set([...carried, ...atBoundary])],\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Handing a record to the scoring run                                         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Dress a fetched Person as the database-event payload `runPersonScoring` reads.\n *\n * This is the whole of the \"reuse, do not duplicate\" story: the bulk path builds\n * the same envelope the platform would have delivered and calls the same\n * function, so every guard, the release-marker pin, the audit row, the fail-open\n * flag and the trace payload are the ones the live path uses \u2014 not a second\n * implementation that will drift.\n *\n * `updatedFields` is deliberately absent. `isGreenlightAuthoredWrite` reads an\n * absent list as \"we do not know what changed\", which means \"score it\" \u2014 exactly\n * right for a record nobody has ever scored. Supplying a synthetic list would be\n * inventing history, and supplying the Greenlight-owned names would make guard 2\n * swallow every single record in the backfill.\n */\nexport const toScoringEvent = (\n  node: Record<string, unknown>,\n): Record<string, unknown> => ({\n  recordId: readNodeId(node),\n  properties: { after: node },\n});\n", "/**\n * Numaya Greenlight \u2014 the durable state of a backfill run.\n *\n * Everything in this file is pure: no SDK import, no network, no clock read.\n * `src/logic-functions/backfill-run.ts` is the shell that reads this state out of\n * Twenty's app key-value storage, hands it to the functions below, and writes the\n * result back. That split exists for the same reason it exists in\n * `src/gate/release-decision.ts`: resumability is the property this feature lives\n * or dies by, and it has to be exhaustively testable without a live workspace and\n * without waiting a real minute between cron ticks.\n *\n * ## Why there is state at all\n *\n * The scoring trigger fires on Person create and update. Records that already\n * existed when Greenlight was installed emit neither, so they are never scored \u2014\n * measured on a dev workspace, 1200 of 1205 people, while the gate queue sat\n * empty. An empty queue reads as \"everything has been checked and is clean\". It\n * was not: nothing had been checked.\n *\n * Fixing that means walking every existing Person, and a workspace of ten\n * thousand cannot be walked inside one function invocation at 100 requests a\n * minute. The walk therefore spans many invocations, and anything that spans\n * invocations needs its progress somewhere a crash cannot take with it.\n *\n * ## What \"resumable\" means precisely here\n *\n * A crashed or timed-out tick loses **the chunk it was in the middle of**, not\n * the run. The cursor is only advanced over records the tick actually reached, so\n * the next tick re-fetches the tail it did not get to. Records it *did* reach are\n * re-fetched too when the crash landed mid-chunk \u2014 and re-scoring them costs\n * nothing, because `scoring-run.ts`'s outcome fingerprint (guard 3) recognises an\n * unchanged outcome and writes neither the record nor an audit row. Idempotency\n * is not something this module has to provide; it only has to avoid *losing*\n * position, and it is allowed to lose a little.\n *\n * ## The lease\n *\n * `kv` offers no compare-and-set, so two overlapping ticks could both read the\n * same cursor. `leaseUntil` narrows that window: a tick claims the lease before\n * it does any work and releases it when it commits. It is a courtesy, not a\n * mutex \u2014 the read-modify-write race is still theoretically open.\n *\n * That is acceptable because the lease is not what makes the run safe. Guard 3\n * is. Two ticks processing the same page produce one set of writes and one set of\n * audit rows; the second finds every fingerprint already stored and does nothing.\n * The lease exists to stop us *wasting* the rate-limit budget, not to stop us\n * corrupting anything.\n *\n * The lease also has to expire, and that is the whole point: a tick the platform\n * killed on timeout never releases it, so a permanent lease would deadlock the\n * run at the first timeout. `BACKFILL_LEASE_MS` is therefore the maximum a crash\n * can cost \u2014 see the constant.\n */\n\n/* -------------------------------------------------------------------------- */\n/* Vocabulary                                                                  */\n/* -------------------------------------------------------------------------- */\n\n/**\n * What a run is allowed to look at.\n *\n *   - `unscored` \u2014 Person records with **no** `greenlightDecision` at all. This\n *     is the defect: never seen by the engine. It is the default and it is the\n *     only mode that runs itself on install.\n *   - `all` \u2014 every Person, re-scored. Needed after a rule or weight change, and\n *     needed to move records scored before `BLOCKED` existed off their legacy\n *     `GATE` value. Never automatic: it rewrites decisions a workspace may have\n *     been working from, so a human asks for it explicitly.\n *\n * Note what is *not* here: a mode that re-scores `UNSCORED` records. Those are\n * fail-opens the engine already looked at and could not score, they already have\n * a view of their own, and a mode that retried them on a schedule would append an\n * ERROR audit row per record per pass forever. `all` covers them when a human\n * decides the underlying cause is fixed.\n */\nexport const BACKFILL_MODES = ['unscored', 'all'] as const;\n\nexport type BackfillMode = (typeof BACKFILL_MODES)[number];\n\nexport const isBackfillMode = (value: unknown): value is BackfillMode =>\n  typeof value === 'string' &&\n  (BACKFILL_MODES as readonly string[]).includes(value);\n\n/**\n * `running` is the only state the cron acts on. The other three are terminal and\n * exist so the panel can say which of them happened \u2014 \"finished\", \"you stopped\n * it\" and \"it broke\" are three different things an admin needs told apart, and\n * collapsing them into \"not running\" is the same species of silence this whole\n * feature exists to remove.\n */\nexport type BackfillStatus = 'running' | 'completed' | 'cancelled' | 'failed';\n\n/* -------------------------------------------------------------------------- */\n/* Timings                                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * How long a tick holds the lease.\n *\n * Sized at roughly twice the cron function's `timeoutSeconds` (55). Shorter than\n * the timeout and a slow-but-healthy tick would have its lease stolen by the next\n * one, which is the overlap the lease exists to prevent. Much longer and a tick\n * the platform killed would idle the run for no reason: this is the exact cost of\n * a crash, so it is deliberately the smallest value that is safely above one full\n * invocation.\n */\nexport const BACKFILL_LEASE_MS = 120_000;\n\n/**\n * Ceiling on how many boundary ids the cursor carries.\n *\n * `cursor.ids` holds the records already handled at the cursor's exact timestamp,\n * so the `gte` filter does not re-process them. It grows whenever more records\n * than one chunk share a single `createdAt` \u2014 which is not exotic: Postgres\n * `now()` is constant within a transaction, so a bulk import writes rows with\n * byte-identical timestamps.\n *\n * The value is not arbitrary. `backfill-plan.ts` over-fetches a page by exactly\n * this many rows so that skipping the boundary does not eat the chunk's budget,\n * and Twenty's page ceiling is 60, so this is `60 \u2212 BACKFILL_CHUNK_SIZE`. It is\n * declared here rather than imported from there only because `backfill-plan.ts`\n * imports *this* module; `backfill-plan.test.ts` asserts the two agree.\n *\n * Beyond the cap the walk still cannot skip a record \u2014 it can only re-read one,\n * which guard 3 makes free. What it can do is stop making progress, and\n * `BACKFILL_MAX_STALLS` is what turns that into something visible.\n */\nexport const BACKFILL_MAX_CURSOR_IDS = 30;\n\n/**\n * Consecutive ticks that fetched records but got through none of them before the\n * run is declared failed.\n *\n * The only way this happens is a `createdAt` boundary wider than a whole page:\n * more than sixty records sharing one timestamp, where the order among ties is\n * not stable enough for the boundary set to cover them. In `unscored` mode it\n * self-corrects, because a scored record leaves the filter. In `all` mode there\n * is no self-correction, and without this the run would spin against the rate\n * limit forever, reporting \"running\", making no progress, and looking exactly\n * like a healthy backfill on a large workspace.\n *\n * Three rather than one: tie ordering can legitimately shuffle between pages, so\n * a single unproductive tick is not evidence of anything. Three in a row is.\n */\nexport const BACKFILL_MAX_STALLS = 3;\n\n/* -------------------------------------------------------------------------- */\n/* The state                                                                   */\n/* -------------------------------------------------------------------------- */\n\n/** Where the walk has got to. Split out because it is advanced as a unit. */\nexport interface BackfillCursor {\n  /** ISO 8601 `createdAt` of the last record handled. Null before the first. */\n  readonly createdAt: string | null;\n  /** Ids already handled that share exactly `createdAt`. */\n  readonly ids: readonly string[];\n}\n\nexport interface BackfillTally {\n  /** Records fetched and looked at, including ones nothing was written for. */\n  readonly examined: number;\n  /** `scoring-run` wrote a record and an audit row. */\n  readonly scored: number;\n  /** Guard 3 recognised the outcome; nothing was written. */\n  readonly unchanged: number;\n  /** `scoring-run` declined to score (unreadable event, authored write). */\n  readonly skipped: number;\n  /** `scoring-run` failed open: flagged UNSCORED, ERROR row appended. */\n  readonly failed: number;\n}\n\nexport const EMPTY_TALLY: BackfillTally = {\n  examined: 0,\n  scored: 0,\n  unchanged: 0,\n  skipped: 0,\n  failed: 0,\n};\n\nexport interface BackfillState {\n  /** Bumped only for a shape change the reader below cannot absorb. */\n  readonly version: 1;\n  /** Derived from the start time, so it is unique without a random source. */\n  readonly runId: string;\n  readonly mode: BackfillMode;\n  readonly status: BackfillStatus;\n  readonly startedAt: string;\n  readonly updatedAt: string;\n  readonly finishedAt: string | null;\n  /** ISO 8601. Null when no tick holds the lease. */\n  readonly leaseUntil: string | null;\n  readonly cursor: BackfillCursor;\n  /**\n   * How many records matched the mode when the run started. Null when the count\n   * query failed \u2014 a count is a nicety and must never stop a run beginning.\n   */\n  readonly totalAtStart: number | null;\n  readonly tally: BackfillTally;\n  /** Ticks that committed work. Distinguishes \"slow\" from \"stuck\". */\n  readonly chunks: number;\n  /** Consecutive ticks that fetched records and got through none. */\n  readonly stalls: number;\n  /** The most recent tick-level failure, kept so the panel can show it. */\n  readonly lastError: string | null;\n  /** Server-derived, or `'install'` for the automatic run. */\n  readonly requestedBy: string;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Reading it back                                                             */\n/* -------------------------------------------------------------------------- */\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\nconst asString = (value: unknown, fallback: string): string =>\n  typeof value === 'string' && value.length > 0 ? value : fallback;\n\nconst asNullableString = (value: unknown): string | null =>\n  typeof value === 'string' && value.length > 0 ? value : null;\n\nconst asCount = (value: unknown): number =>\n  typeof value === 'number' && Number.isFinite(value) && value >= 0\n    ? Math.floor(value)\n    : 0;\n\nconst asIdList = (value: unknown): string[] =>\n  Array.isArray(value)\n    ? value.filter((entry): entry is string => typeof entry === 'string')\n    : [];\n\nconst STATUSES: readonly string[] = [\n  'running',\n  'completed',\n  'cancelled',\n  'failed',\n];\n\n/**\n * Coerce whatever came out of key-value storage into a state, or `null`.\n *\n * Deliberately lenient about every field except the two that decide behaviour \u2014\n * `status` and `mode`. An unreadable counter is cosmetic and defaults to zero; an\n * unreadable *status* would let a corrupt blob keep a cron loop alive against a\n * cursor nobody can interpret, so anything it does not recognise is refused\n * outright and the run reads as \"there is no backfill\", which is the state an\n * admin can act on.\n *\n * Refusing rather than repairing is the right direction here specifically because\n * the recovery is cheap and visible: the panel shows no run, and starting a fresh\n * one costs one click and re-walks records that are almost all already scored \u2014\n * which guard 3 makes nearly free.\n */\nexport const toBackfillState = (value: unknown): BackfillState | null => {\n  if (!isRecord(value)) {\n    return null;\n  }\n\n  const status = value['status'];\n  const mode = value['mode'];\n\n  if (typeof status !== 'string' || !STATUSES.includes(status)) {\n    return null;\n  }\n\n  if (!isBackfillMode(mode)) {\n    return null;\n  }\n\n  const startedAt = asString(value['startedAt'], '');\n\n  if (startedAt === '') {\n    return null;\n  }\n\n  const cursor = isRecord(value['cursor']) ? value['cursor'] : {};\n  const tally = isRecord(value['tally']) ? value['tally'] : {};\n\n  return {\n    version: 1,\n    runId: asString(value['runId'], startedAt),\n    mode,\n    status: status as BackfillStatus,\n    startedAt,\n    updatedAt: asString(value['updatedAt'], startedAt),\n    finishedAt: asNullableString(value['finishedAt']),\n    leaseUntil: asNullableString(value['leaseUntil']),\n    cursor: {\n      createdAt: asNullableString(cursor['createdAt']),\n      ids: asIdList(cursor['ids']),\n    },\n    totalAtStart:\n      typeof value['totalAtStart'] === 'number' &&\n      Number.isFinite(value['totalAtStart'])\n        ? Math.floor(value['totalAtStart'])\n        : null,\n    tally: {\n      examined: asCount(tally['examined']),\n      scored: asCount(tally['scored']),\n      unchanged: asCount(tally['unchanged']),\n      skipped: asCount(tally['skipped']),\n      failed: asCount(tally['failed']),\n    },\n    chunks: asCount(value['chunks']),\n    stalls: asCount(value['stalls']),\n    lastError: asNullableString(value['lastError']),\n    requestedBy: asString(value['requestedBy'], 'unknown'),\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Transitions                                                                 */\n/* -------------------------------------------------------------------------- */\n\nexport interface BeginBackfillInput {\n  readonly mode: BackfillMode;\n  readonly now: Date;\n  readonly requestedBy: string;\n  readonly totalAtStart: number | null;\n}\n\n/**\n * The run id is derived from the start instant rather than drawn from a random\n * source, so this module stays pure and a test can assert the exact id. Two runs\n * cannot start in the same millisecond \u2014 `beginBackfill` is only reachable from\n * the control route, which refuses while a run is `running`.\n */\nexport const beginBackfill = ({\n  mode,\n  now,\n  requestedBy,\n  totalAtStart,\n}: BeginBackfillInput): BackfillState => {\n  const startedAt = now.toISOString();\n\n  return {\n    version: 1,\n    runId: `backfill-${startedAt}`,\n    mode,\n    status: 'running',\n    startedAt,\n    updatedAt: startedAt,\n    finishedAt: null,\n    // Left unclaimed so the very next cron tick picks the run up rather than\n    // waiting out a lease nobody is holding.\n    leaseUntil: null,\n    cursor: { createdAt: null, ids: [] },\n    totalAtStart,\n    tally: EMPTY_TALLY,\n    chunks: 0,\n    stalls: 0,\n    lastError: null,\n    requestedBy,\n  };\n};\n\nexport const isLeaseHeld = (state: BackfillState, now: Date): boolean => {\n  if (state.leaseUntil === null) {\n    return false;\n  }\n\n  const until = Date.parse(state.leaseUntil);\n\n  // An unparseable lease is treated as expired. The alternative \u2014 treating it as\n  // held \u2014 would strand the run permanently on one bad write, and the cost of\n  // being wrong is one duplicated chunk that writes nothing.\n  return !Number.isNaN(until) && until > now.getTime();\n};\n\nexport const claimLease = (state: BackfillState, now: Date): BackfillState => ({\n  ...state,\n  updatedAt: now.toISOString(),\n  leaseUntil: new Date(now.getTime() + BACKFILL_LEASE_MS).toISOString(),\n});\n\n/** Give the lease back without changing anything else. Used on a failed tick. */\nexport const releaseLease = (\n  state: BackfillState,\n  now: Date,\n  lastError: string | null,\n): BackfillState => ({\n  ...state,\n  updatedAt: now.toISOString(),\n  leaseUntil: null,\n  lastError,\n});\n\nconst addTally = (left: BackfillTally, right: BackfillTally): BackfillTally => ({\n  examined: left.examined + right.examined,\n  scored: left.scored + right.scored,\n  unchanged: left.unchanged + right.unchanged,\n  skipped: left.skipped + right.skipped,\n  failed: left.failed + right.failed,\n});\n\nexport interface CommitChunkInput {\n  readonly now: Date;\n  readonly cursor: BackfillCursor;\n  readonly tally: BackfillTally;\n  readonly lastError: string | null;\n  /** True when the page proved there is nothing left to walk. */\n  readonly exhausted: boolean;\n  /** True when records came back and the tick got through none of them. */\n  readonly stalled: boolean;\n}\n\nconst STALL_MESSAGE =\n  'The backfill stopped making progress. More records share one creation timestamp than a single page can hold, so the walk cannot get past them. Run the backfill over unscored leads only \u2014 that mode drains regardless \u2014 or contact support.';\n\n/**\n * Fold one tick's work into the run and release the lease.\n *\n * The cursor is replaced wholesale rather than merged: the caller has already\n * worked out where the walk actually reached, and it is the only party that can \u2014\n * see `advanceCursor` in `backfill-plan.ts`.\n *\n * Three ways out of `running`, and it matters that they are distinguishable:\n * `exhausted` is the walk finishing, `stalled` past its limit is the walk being\n * unable to continue, and neither is a cancel. A run that quietly stayed\n * \"running\" while achieving nothing would be the same defect as an empty gate\n * queue over an unscored workspace \u2014 a surface that looks healthy and is not.\n */\nexport const commitChunk = (\n  state: BackfillState,\n  { now, cursor, tally, lastError, exhausted, stalled }: CommitChunkInput,\n): BackfillState => {\n  const at = now.toISOString();\n  const stalls = stalled ? state.stalls + 1 : 0;\n  const wedged = stalls >= BACKFILL_MAX_STALLS;\n\n  return {\n    ...state,\n    status: exhausted ? 'completed' : wedged ? 'failed' : state.status,\n    updatedAt: at,\n    finishedAt: exhausted || wedged ? at : state.finishedAt,\n    leaseUntil: null,\n    cursor: {\n      createdAt: cursor.createdAt,\n      ids: cursor.ids.slice(-BACKFILL_MAX_CURSOR_IDS),\n    },\n    tally: addTally(state.tally, tally),\n    chunks: state.chunks + 1,\n    stalls,\n    lastError: wedged ? STALL_MESSAGE : lastError,\n  };\n};\n\nexport const cancelBackfill = (\n  state: BackfillState,\n  now: Date,\n  requestedBy: string,\n): BackfillState => ({\n  ...state,\n  status: 'cancelled',\n  updatedAt: now.toISOString(),\n  finishedAt: now.toISOString(),\n  // Released so a cancel taken while a tick is mid-flight does not leave a lease\n  // behind on a run nobody will ever pick up again.\n  leaseUntil: null,\n  requestedBy,\n});\n\n/* -------------------------------------------------------------------------- */\n/* What the admin is shown                                                     */\n/* -------------------------------------------------------------------------- */\n\nexport interface BackfillProgress {\n  readonly runId: string;\n  readonly mode: BackfillMode;\n  readonly status: BackfillStatus;\n  readonly startedAt: string;\n  readonly updatedAt: string;\n  readonly finishedAt: string | null;\n  readonly totalAtStart: number | null;\n  readonly examined: number;\n  readonly scored: number;\n  readonly unchanged: number;\n  readonly skipped: number;\n  readonly failed: number;\n  readonly chunks: number;\n  readonly lastError: string | null;\n  readonly requestedBy: string;\n  /** 0-100, or null when the total was never known. */\n  readonly percent: number | null;\n  /** Whole minutes, or null when there is nothing to estimate from. */\n  readonly minutesRemaining: number | null;\n  /** True when a tick is currently holding the lease. */\n  readonly working: boolean;\n}\n\n/**\n * Render the state for a human.\n *\n * `percent` is capped at 100 and floored at 0 rather than reported raw. The total\n * is a snapshot taken when the run started, and records created *during* a run\n * are walked too, so the honest arithmetic can exceed the denominator. A progress\n * bar reading 114% is a bug report; the cap is not hiding anything the counters\n * beside it do not already state exactly.\n *\n * `minutesRemaining` is deliberately derived from the chunk *rate this run has\n * actually achieved* rather than from the nominal chunk size, so a workspace\n * whose ticks are being skipped is told the truth about how long it will take.\n */\nexport const describeBackfill = (\n  state: BackfillState,\n  now: Date,\n): BackfillProgress => {\n  const { tally, totalAtStart } = state;\n\n  const percent =\n    totalAtStart === null || totalAtStart <= 0\n      ? null\n      : Math.max(0, Math.min(100, Math.round((tally.examined / totalAtStart) * 100)));\n\n  const elapsedMs = Math.max(\n    0,\n    Date.parse(state.updatedAt) - Date.parse(state.startedAt),\n  );\n\n  const remaining =\n    totalAtStart === null ? null : Math.max(0, totalAtStart - tally.examined);\n\n  const minutesRemaining =\n    state.status !== 'running' ||\n    remaining === null ||\n    remaining === 0 ||\n    tally.examined === 0 ||\n    elapsedMs <= 0\n      ? null\n      : Math.ceil(remaining / (tally.examined / (elapsedMs / 60_000)));\n\n  return {\n    runId: state.runId,\n    mode: state.mode,\n    status: state.status,\n    startedAt: state.startedAt,\n    updatedAt: state.updatedAt,\n    finishedAt: state.finishedAt,\n    totalAtStart,\n    examined: tally.examined,\n    scored: tally.scored,\n    unchanged: tally.unchanged,\n    skipped: tally.skipped,\n    failed: tally.failed,\n    chunks: state.chunks,\n    lastError: state.lastError,\n    requestedBy: state.requestedBy,\n    percent,\n    minutesRemaining:\n      minutesRemaining === null || !Number.isFinite(minutesRemaining)\n        ? null\n        : minutesRemaining,\n    working: isLeaseHeld(state, now),\n  };\n};\n", "/**\n * The adapter between the `GreenlightConfig` CRM record and the scoring engine.\n *\n * These are two different shapes on purpose and the gap has to live somewhere:\n *\n *   GreenlightConfig  is designed for a human with a record page. Bands are three\n *                     separate NUMBER fields because a typo inside a JSON blob\n *                     would silently gate a whole workspace; enable/severity and\n *                     weight are separate RAW_JSON maps because they are two\n *                     different decisions an admin makes at different times.\n *\n *   ResolvedScoringConfig  is designed for the engine. Bands are one sorted\n *                     array; every rule carries enabled + severity + weight\n *                     together.\n *\n * This file is the only place that knows both. Everything here is a pure\n * function of its input \u2014 no API client, no clock \u2014 so the whole\n * seed / read / merge story is unit-testable without a Twenty instance.\n */\n\nimport { buildDefaultConfig, DEFAULT_FIELD_MAPPING } from 'src/scoring';\nimport type { ResolvedScoringConfig } from 'src/scoring';\n\nimport { isPlainRecord } from 'src/logic-functions/greenlight-api';\n\n/**\n * The `GreenlightConfig.leadObjectNameSingular` SELECT value for Person.\n *\n * Duplicated from `src/objects/greenlight-config.ts` rather than imported: that\n * module pulls in `twenty-sdk/define`, and a logic-function bundle has no\n * business carrying the whole manifest-authoring toolkit. The value is a SELECT\n * option and is as permanent as the field identifier itself.\n */\nexport const DEFAULT_LEAD_OBJECT_SELECT_VALUE = 'PERSON';\n\n/** Lowercase API name matching the SELECT value above, for the audit trail. */\nexport const LEAD_OBJECT_SELECT_TO_NAME_SINGULAR: Readonly<\n  Record<string, string>\n> = {\n  PERSON: 'person',\n  COMPANY: 'company',\n  OPPORTUNITY: 'opportunity',\n};\n\n/** Every field this app reads from or writes to the config record. */\nexport const GREENLIGHT_CONFIG_FIELD_NAMES = [\n  'id',\n  'createdAt',\n  'name',\n  'isGateEnabled',\n  'icpIndustries',\n  'icpRegions',\n  'icpSizeBands',\n  'ruleSettings',\n  'scoreWeights',\n  'bandExcellentThreshold',\n  'bandGoodThreshold',\n  'bandFairThreshold',\n  'gateThreshold',\n  'defaultShelfLifeDays',\n  'fieldShelfLives',\n  'leadObjectNameSingular',\n  'decisionMakerFieldName',\n  'decisionMakerMatchValues',\n  'readyForOutreachFieldName',\n  'readyForOutreachValue',\n  'optOutFieldNames',\n] as const;\n\n/** GraphQL selection set for the fields above. */\nexport const greenlightConfigSelection = (): Record<string, boolean> =>\n  Object.fromEntries(GREENLIGHT_CONFIG_FIELD_NAMES.map((name) => [name, true]));\n\nexport type GreenlightConfigSeed = Record<string, unknown>;\n\nconst bandMinScore = (\n  config: ResolvedScoringConfig,\n  bandId: string,\n): number | undefined =>\n  config.bands.find((band) => band.id === bandId)?.minScore;\n\n/**\n * The record the post-install hook writes on a fresh install.\n *\n * Every value is set **explicitly** rather than left to the field manifest's\n * `defaultValue`, for three reasons:\n *\n *  1. The manifest defaults and the engine defaults disagree. The field\n *     manifests carry bands 80/60/40 and gate 40; `buildDefaultConfig()` \u2014 the\n *     thing that actually scores leads \u2014 carries 85/70/50 and gate 50. Whichever\n *     is \"right\", they must not differ, and the engine is the one that decides\n *     outcomes, so the engine wins. Leaving the record blank would ship a\n *     workspace whose visible configuration lies about its own behaviour.\n *     `decisionMakerMatchValues` has the same problem: 12 titles in the manifest,\n *     25 in the engine.\n *  2. `ruleSettings` and `scoreWeights` cannot come from a manifest default at\n *     all \u2014 they are keyed by the rule catalogue, which the engine owns and which\n *     grows every release.\n *  3. A `defaultValue` only applies at column creation. It is not a value a\n *     later read can distinguish from \"the admin set it to that\", so relying on\n *     it would make the upgrade-merge below unable to tell missing from chosen.\n *\n * The rule of thumb: if the engine has an opinion, seed it explicitly; the field\n * manifest `defaultValue` is then only a safety net for records created by hand.\n */\nexport const buildGreenlightConfigSeed = (): GreenlightConfigSeed => {\n  const defaults = buildDefaultConfig();\n\n  const ruleSettings: Record<string, { enabled: boolean; severity: string }> =\n    {};\n  const scoreWeights: Record<string, number> = {};\n\n  for (const [ruleId, setting] of Object.entries(defaults.rules)) {\n    ruleSettings[ruleId] = {\n      enabled: setting.enabled,\n      severity: setting.severity,\n    };\n    scoreWeights[ruleId] = setting.weight;\n  }\n\n  return {\n    name: 'Default',\n    isGateEnabled: true,\n\n    icpIndustries: [...defaults.icp.industries],\n    icpRegions: [...defaults.icp.regions],\n    icpSizeBands: { bands: [...defaults.icp.sizeBands] },\n\n    ruleSettings,\n    scoreWeights,\n\n    bandExcellentThreshold: bandMinScore(defaults, 'excellent') ?? 85,\n    bandGoodThreshold: bandMinScore(defaults, 'good') ?? 70,\n    bandFairThreshold: bandMinScore(defaults, 'fair') ?? 50,\n    gateThreshold: defaults.gateThreshold,\n\n    defaultShelfLifeDays: defaults.defaultShelfLifeDays,\n    fieldShelfLives: { ...defaults.fieldShelfLifeDays },\n\n    leadObjectNameSingular: DEFAULT_LEAD_OBJECT_SELECT_VALUE,\n    decisionMakerFieldName: 'jobTitle',\n    decisionMakerMatchValues: [...defaults.decisionMakerTitles],\n\n    // Stock Twenty's Person has no stage field, so there is nothing honest to\n    // point these at. Blank means \"the release action only clears the gate\".\n    readyForOutreachFieldName: null,\n    readyForOutreachValue: null,\n\n    // Empty, not absent: the engine's default field mapping already probes\n    // `optedOut` / `doNotContact` / `emailOptOut` / `unsubscribed`. This list is\n    // for *extra* workspace-specific opt-out fields.\n    optOutFieldNames: [],\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Upgrade merge                                                               */\n/* -------------------------------------------------------------------------- */\n\nconst isMissing = (value: unknown): boolean =>\n  value === undefined || value === null;\n\n/**\n * Whether writing `seedValue` over a missing field would actually change\n * anything once Twenty has stored it.\n *\n * Found by running a real `app:install` upgrade rather than by a unit test, and\n * unit tests structurally cannot see it: **Twenty persists an empty `RAW_JSON`\n * as `null`.** So `fieldShelfLives`, seeded `{}`, reads back as `null`,\n * `isMissing` says missing, the patch writes `{}` again, and it reads back\n * `null` again \u2014 forever. Every single upgrade patched exactly one key and filed\n * an audit row claiming a merge that had not happened, which quietly makes the\n * upgrade trail untrustworthy for the merges that are real.\n *\n * A patch that cannot converge is not a merge, it is a loop with an audit trail.\n * An empty seed value written over a missing field is a no-op by definition, so\n * it is skipped and the key is left to the field manifest's own default.\n */\nconst isNoOpSeed = (value: unknown): boolean => {\n  if (Array.isArray(value)) {\n    return value.length === 0;\n  }\n\n  if (isPlainRecord(value)) {\n    return Object.keys(value).length === 0;\n  }\n\n  return false;\n};\n\n/**\n * The patch an upgrade should apply to an existing config record.\n *\n * \"Missing\" means `null` or `undefined` only. An empty array, an empty object\n * and a zero are all *choices* a workspace made \u2014 a permissive ICP is the whole\n * point of the shipped default \u2014 and resetting them to seed values would be the\n * exact behaviour ARCHITECTURE.md's upgrade section forbids (\"config merge, not\n * replace\").\n *\n * The interesting case is `ruleSettings` / `scoreWeights`: a release that adds a\n * rule must make that rule appear in the workspace's config at its shipped\n * default, without disturbing a single existing entry. Both maps are therefore\n * merged key-by-key rather than compared wholesale.\n *\n * Returns an empty object when there is nothing to do, so the caller can skip\n * the mutation entirely \u2014 which is what makes re-running the hook a no-op.\n */\nexport const buildConfigUpgradePatch = (\n  existing: unknown,\n  seed: GreenlightConfigSeed = buildGreenlightConfigSeed(),\n): Record<string, unknown> => {\n  const record = isPlainRecord(existing) ? existing : {};\n  const patch: Record<string, unknown> = {};\n\n  for (const [key, seedValue] of Object.entries(seed)) {\n    // `null` is the intended seeded value for these two, so a null on the\n    // record is indistinguishable from the seed and must never be \"repaired\".\n    if (seedValue === null) {\n      continue;\n    }\n\n    if (key === 'ruleSettings' || key === 'scoreWeights') {\n      continue;\n    }\n\n    if (isMissing(record[key]) && !isNoOpSeed(seedValue)) {\n      patch[key] = seedValue;\n    }\n  }\n\n  const ruleSettingsPatch = mergeKeyedMap(\n    record['ruleSettings'],\n    seed['ruleSettings'],\n  );\n\n  if (ruleSettingsPatch !== null) {\n    patch['ruleSettings'] = ruleSettingsPatch;\n  }\n\n  const scoreWeightsPatch = mergeKeyedMap(\n    record['scoreWeights'],\n    seed['scoreWeights'],\n  );\n\n  if (scoreWeightsPatch !== null) {\n    patch['scoreWeights'] = scoreWeightsPatch;\n  }\n\n  return patch;\n};\n\n/**\n * Merge shipped keys into a stored map without overwriting anything present.\n * Returns `null` when the stored map already covers every shipped key \u2014 the\n * signal that no write is needed.\n */\nconst mergeKeyedMap = (\n  stored: unknown,\n  shipped: unknown,\n): Record<string, unknown> | null => {\n  if (!isPlainRecord(shipped)) {\n    return null;\n  }\n\n  if (!isPlainRecord(stored)) {\n    // Absent or unreadable: replacing it with the shipped map loses nothing,\n    // because there was nothing legible there to lose.\n    return { ...shipped };\n  }\n\n  const merged: Record<string, unknown> = { ...stored };\n  let added = false;\n\n  for (const [key, value] of Object.entries(shipped)) {\n    if (isMissing(merged[key])) {\n      merged[key] = value;\n      added = true;\n    }\n  }\n\n  return added ? merged : null;\n};\n\n/* -------------------------------------------------------------------------- */\n/* Record -> engine config                                                     */\n/* -------------------------------------------------------------------------- */\n\nconst asFiniteNumber = (value: unknown): number | undefined =>\n  typeof value === 'number' && Number.isFinite(value) ? value : undefined;\n\nconst asStringList = (value: unknown): string[] | undefined => {\n  if (!Array.isArray(value)) {\n    return undefined;\n  }\n\n  const list = value\n    .filter((entry): entry is string => typeof entry === 'string')\n    .map((entry) => entry.trim())\n    .filter((entry) => entry.length > 0);\n\n  return list;\n};\n\n/** `icpSizeBands` ships as `{ bands: [...] }`; tolerate a bare array too. */\nconst readSizeBands = (value: unknown): unknown => {\n  if (Array.isArray(value)) {\n    return value;\n  }\n\n  if (isPlainRecord(value) && Array.isArray(value['bands'])) {\n    return value['bands'];\n  }\n\n  return undefined;\n};\n\n/**\n * Recombine `ruleSettings` (enable + severity) and `scoreWeights` (weight) into\n * the single per-rule shape the engine reads.\n *\n * `isEnabled` is accepted as an alias for `enabled` because the field's own\n * description in `src/objects/greenlight-config.ts` documents that spelling.\n * The engine reads `enabled`; rather than let a hand-edited record silently do\n * nothing, both are honoured here. (The field description is stale \u2014 see the\n * report accompanying this change.)\n */\nconst readRules = (\n  ruleSettings: unknown,\n  scoreWeights: unknown,\n): Record<string, unknown> | undefined => {\n  const settings = isPlainRecord(ruleSettings) ? ruleSettings : undefined;\n  const weights = isPlainRecord(scoreWeights) ? scoreWeights : undefined;\n\n  if (settings === undefined && weights === undefined) {\n    return undefined;\n  }\n\n  const ruleIds = new Set<string>([\n    ...Object.keys(settings ?? {}),\n    ...Object.keys(weights ?? {}),\n  ]);\n\n  const rules: Record<string, unknown> = {};\n\n  for (const ruleId of ruleIds) {\n    const setting = settings?.[ruleId];\n    const merged: Record<string, unknown> = isPlainRecord(setting)\n      ? { ...setting }\n      : {};\n\n    if (merged['enabled'] === undefined && merged['isEnabled'] !== undefined) {\n      merged['enabled'] = merged['isEnabled'];\n    }\n\n    const weight = asFiniteNumber(weights?.[ruleId]);\n\n    if (weight !== undefined) {\n      merged['weight'] = weight;\n    }\n\n    rules[ruleId] = merged;\n  }\n\n  return rules;\n};\n\n/**\n * Rebuild the engine's band array from the three threshold fields.\n *\n * Returns `undefined` when no threshold is usable, which makes `resolveConfig`\n * fall back to the shipped bands without logging a degradation \u2014 the right\n * outcome, because \"the admin never touched this\" is not a fault.\n */\nconst readBands = (record: Record<string, unknown>): unknown => {\n  const excellent = asFiniteNumber(record['bandExcellentThreshold']);\n  const good = asFiniteNumber(record['bandGoodThreshold']);\n  const fair = asFiniteNumber(record['bandFairThreshold']);\n\n  if (excellent === undefined && good === undefined && fair === undefined) {\n    return undefined;\n  }\n\n  const bands: { id: string; label: string; minScore: number }[] = [];\n\n  if (excellent !== undefined) {\n    bands.push({ id: 'excellent', label: 'Excellent', minScore: excellent });\n  }\n\n  if (good !== undefined) {\n    bands.push({ id: 'good', label: 'Good', minScore: good });\n  }\n\n  if (fair !== undefined) {\n    bands.push({ id: 'fair', label: 'Fair', minScore: fair });\n  }\n\n  // Poor is the floor and has no threshold field: it is whatever is left.\n  bands.push({ id: 'poor', label: 'Poor', minScore: 0 });\n\n  return bands;\n};\n\n/**\n * The Layer 3 field mapping, expressed as *additional* candidate paths in front\n * of the engine's defaults rather than as a replacement.\n *\n * Prepending matters: a workspace that points `decisionMakerFieldName` at a\n * custom field still wants `jobTitle` probed as a fallback for the Person\n * records where the custom field is blank. De-duplicated so that pointing the\n * setting at the default field name produces the default list unchanged rather\n * than a list that probes the same path twice.\n */\nconst prepend = (\n  extra: readonly string[],\n  defaults: readonly string[],\n): string[] => [...new Set([...extra, ...defaults])];\n\nconst readFieldMapping = (\n  record: Record<string, unknown>,\n): Record<string, string[]> | undefined => {\n  const mapping: Record<string, string[]> = {};\n\n  const decisionMakerField = record['decisionMakerFieldName'];\n\n  if (typeof decisionMakerField === 'string' && decisionMakerField.trim()) {\n    // Read the shipped candidates rather than repeating them. They were\n    // duplicated here, and the two copies drifted the moment `position` was\n    // removed from the engine's list for reading Twenty's row-ordering number\n    // as a job title \u2014 this copy would have quietly kept the bug alive for any\n    // workspace that had configured a decision-maker field.\n    mapping['jobTitle'] = prepend(\n      [decisionMakerField.trim()],\n      DEFAULT_FIELD_MAPPING.jobTitle,\n    );\n  }\n\n  const optOutFields = asStringList(record['optOutFieldNames']);\n\n  if (optOutFields !== undefined && optOutFields.length > 0) {\n    mapping['optedOut'] = prepend(optOutFields, [\n      'optedOut',\n      'doNotContact',\n      'emailOptOut',\n      'unsubscribed',\n    ]);\n  }\n\n  return Object.keys(mapping).length > 0 ? mapping : undefined;\n};\n\n/**\n * Turn a `GreenlightConfig` record into the raw config `scoreLead` accepts.\n *\n * Deliberately lenient: anything unreadable is left out of the returned object\n * so `resolveConfig` supplies its own default. This function never throws and\n * never validates \u2014 validation is the engine's job and it already reports what\n * it had to repair.\n */\nexport const toScoringConfigInput = (record: unknown): unknown => {\n  if (!isPlainRecord(record)) {\n    return undefined;\n  }\n\n  const industries = asStringList(record['icpIndustries']);\n  const regions = asStringList(record['icpRegions']);\n  const sizeBands = readSizeBands(record['icpSizeBands']);\n\n  const icp =\n    industries !== undefined || regions !== undefined || sizeBands !== undefined\n      ? {\n          industries: industries ?? [],\n          regions: regions ?? [],\n          sizeBands: sizeBands ?? [],\n        }\n      : undefined;\n\n  const decisionMakerTitles = asStringList(record['decisionMakerMatchValues']);\n\n  return {\n    icp,\n    rules: readRules(record['ruleSettings'], record['scoreWeights']),\n    bands: readBands(record),\n    gateThreshold: asFiniteNumber(record['gateThreshold']),\n    defaultShelfLifeDays: asFiniteNumber(record['defaultShelfLifeDays']),\n    fieldShelfLifeDays: isPlainRecord(record['fieldShelfLives'])\n      ? record['fieldShelfLives']\n      : undefined,\n    // Empty means \"the admin cleared the list\", which disables the\n    // decision-maker rule on purpose. Only an unreadable value falls back.\n    decisionMakerTitles,\n    fieldMapping: readFieldMapping(record),\n  };\n};\n\n/** Is the gate switched on? Absent or unreadable reads as on. */\nexport const isGateEnabled = (record: unknown): boolean =>\n  !(isPlainRecord(record) && record['isGateEnabled'] === false);\n\n/** Which object the workspace calls the lead, as a lowercase API name. */\nexport const readLeadObjectNameSingular = (record: unknown): string => {\n  const raw = isPlainRecord(record) ? record['leadObjectNameSingular'] : null;\n\n  if (typeof raw !== 'string' || raw.trim().length === 0) {\n    return LEAD_OBJECT_SELECT_TO_NAME_SINGULAR[\n      DEFAULT_LEAD_OBJECT_SELECT_VALUE\n    ] as string;\n  }\n\n  const normalised = raw.trim().toUpperCase();\n\n  return LEAD_OBJECT_SELECT_TO_NAME_SINGULAR[normalised] ?? raw.trim();\n};\n", "/**\n * Canonical serialisation \u2014 the exact bytes that get signed and verified.\n *\n * A detached signature is worthless unless the signer and the verifier agree,\n * byte for byte, on what \"the payload\" is. JSON does not give that for free:\n * key order, whitespace and the treatment of `undefined` are all free choices,\n * and the payload makes a round trip through the licensing service's own JSON\n * storage before we see it again \u2014 a round trip that is entitled to reorder\n * keys and reformat numbers without changing meaning.\n *\n * So this module defines the agreement, and both halves import *this file*\n * rather than reimplementing it. The signer is `ops/calibration/sign.mjs`; the\n * verifier is `verify.ts`. There is no third copy.\n *\n * ---------------------------------------------------------------------------\n * ## The rules\n *\n * 1. **Object keys are sorted** by code unit, recursively. This is the whole\n *    point: a service that re-serialises our JSON may emit keys in any order,\n *    and sorting makes that reordering invisible to the signature.\n * 2. **Arrays keep their order.** Order is meaning here \u2014 `decisionMakerTitles`\n *    is scanned in sequence and the first match wins, so a reordered list is a\n *    genuinely different payload and must break the signature.\n * 3. **No insignificant whitespace**, i.e. `JSON.stringify` with no spacer.\n * 4. **`undefined` and functions are dropped**, exactly as `JSON.stringify`\n *    already drops them, so a key that is absent and a key that is explicitly\n *    `undefined` canonicalise identically. They mean the same thing to every\n *    reader downstream, so they must sign the same.\n * 5. **`null` is preserved**, because `notes: null` and an absent `notes` are\n *    both legal and both mean \"no note\" \u2014 but `null` survives a JSON round trip\n *    and `undefined` does not, so keeping `null` is what makes the round trip\n *    lossless.\n *\n * ## Why not JCS (RFC 8785)\n *\n * JCS is the standards-track answer and would be the right call if the payload\n * were ever exchanged with a third party's implementation. It is not: both ends\n * are this repository. JCS's remaining substance over the four rules above is\n * number canonicalisation, and the payload contains exactly two numbers, both\n * small non-negative integers, for which every JSON encoder in existence agrees.\n * Pulling in a dependency \u2014 into a bundle that ships to customer\n * infrastructure \u2014 to canonicalise `1` was not a trade worth making.\n *\n * If the payload ever grows a float, revisit this. The comment is here so that\n * decision is a decision rather than an accident.\n * ---------------------------------------------------------------------------\n */\n\ntype Json = string | number | boolean | null | Json[] | { [key: string]: Json };\n\n/**\n * Recursively rebuild a value with object keys in sorted order.\n *\n * Note the array branch preserves order and the primitive branch is the\n * identity \u2014 the sort applies to objects and nothing else.\n */\nconst sortValue = (value: unknown, seen: WeakSet<object>): unknown => {\n  if (Array.isArray(value)) {\n    // The cycle guard is checked here as well as on objects, because an array\n    // that contains itself is just as recursive and just as fatal.\n    if (seen.has(value)) {\n      throw new TypeError('circular reference');\n    }\n\n    seen.add(value);\n    const mapped = value.map((entry) => sortValue(entry, seen));\n    seen.delete(value);\n\n    return mapped;\n  }\n\n  if (typeof value === 'object' && value !== null) {\n    // Without this, a cycle recurses until the stack is exhausted and the\n    // `RangeError` is what `canonicalise` ends up catching. That happens to\n    // produce the right answer \u2014 `null` \u2014 but by accident, at the cost of\n    // however deep the runtime's stack is, and it is not a behaviour worth\n    // relying on inside a nightly cron job. `delete` after the descent so a\n    // value legitimately appearing twice in a *tree* is not mistaken for a\n    // cycle.\n    if (seen.has(value)) {\n      throw new TypeError('circular reference');\n    }\n\n    seen.add(value);\n\n    const source = value as Record<string, unknown>;\n    const sorted: Record<string, unknown> = {};\n\n    for (const key of Object.keys(source).sort()) {\n      const entry = source[key];\n\n      // Dropped rather than emitted as `null`: `JSON.stringify` drops\n      // `undefined` properties too, and the two must agree or a payload that\n      // has been through one `JSON.parse` would canonicalise differently from\n      // the same payload in memory.\n      if (entry !== undefined) {\n        sorted[key] = sortValue(entry, seen);\n      }\n    }\n\n    seen.delete(value);\n\n    return sorted;\n  }\n\n  return value;\n};\n\n/**\n * The canonical UTF-8 string for a payload.\n *\n * Returns `null` rather than throwing when the value cannot be represented \u2014\n * a circular reference, or a `BigInt`. Neither can occur in a payload that\n * arrived as parsed JSON, but this function is also called by the signing\n * script on hand-authored input, and a thrown error inside the nightly\n * verification path would be a cron run that dies rather than falls back.\n */\nexport const canonicalise = (value: unknown): string | null => {\n  try {\n    const serialised = JSON.stringify(sortValue(value, new WeakSet()) as Json);\n\n    return typeof serialised === 'string' ? serialised : null;\n  } catch {\n    return null;\n  }\n};\n\n/**\n * The canonical bytes. Split from `canonicalise` only so the verifier can hash\n * without a second UTF-8 conversion, and so tests can assert on the string.\n */\nexport const canonicalBytes = (value: unknown): Uint8Array | null => {\n  const serialised = canonicalise(value);\n\n  return serialised === null ? null : new TextEncoder().encode(serialised);\n};\n", "/**\n * The public keys this build will accept a calibration signature from.\n *\n * ===========================================================================\n * ## These are public keys. Embedding them is correct.\n *\n * A verification key is meant to be published \u2014 it can check a signature and\n * cannot produce one. Shipping it inside a public repository leaks nothing, and\n * shipping it is the *only* way the guarantee works: a key fetched at runtime\n * could be swapped by whoever swapped the payload, which would make the whole\n * exercise a decoration. The trust anchor has to travel with the code that\n * relies on it, and the code is what the customer already chose to install.\n *\n * ## Why this is a Greenlight key and not the licensing service's org key\n *\n * The obvious anchor is the Numaya org's Ed25519 public key, published at\n * `GET /v1/orgs/current/public-key`\n * (`+VrgNZ38aH8OABL0Wt2fDlhHdc52Hy5H7ganNqf541I=`, `keyVersion: 1`). It is not\n * usable here, for two independent reasons, both measured on 2026-08-05:\n *\n *  1. **The service will not sign an arbitrary payload.** Its private half is\n *     internal and the only signing operation it exposes is the offline licence\n *     file (`GET /v1/licenses/{id}/file`), which signs licence fields \u2014\n *     `licenseId`, `status`, `features`, `expiry` \u2014 and nothing we author. There\n *     is no endpoint that takes bytes and returns a signature over them, so\n *     there is no way to obtain a calibration signature that verifies against\n *     that key. `ConfigDownloadResponse` has no `signature` field at all: the\n *     config surface is entirely unsigned.\n *  2. **Its signature is not independently verifiable anyway.** The licence\n *     file's signature was checked against that public key over roughly 150,000\n *     candidate canonicalisations \u2014 every plausible field order, delimiter,\n *     datetime precision and JSON shape \u2014 and none verified. The service does\n *     not publish the byte string it signs, so a third party cannot confirm the\n *     signature at all. A verifier that cannot verify is not an integrity\n *     control; claiming one would be worse than claiming none.\n *\n * So Greenlight signs its own calibration, with a key it holds, and anchors on\n * that. See `verify.ts` for exactly what that does and does not prove.\n *\n * ## Rotation\n *\n * Add the new key here, ship the release, *then* start signing with it. A build\n * that predates the rotation refuses the new payload (`unknown_key`) and falls\n * back to shipped defaults \u2014 degraded, never broken. Retiring a key is the\n * reverse: stop signing with it, wait out the deployed fleet, remove the entry.\n * Never remove and re-add the same `keyId` with different bytes; mint a new id.\n * ===========================================================================\n */\n\n/**\n * `keyId` \u2192 raw 32-byte Ed25519 public key, base64.\n *\n * Raw, not SPKI: `crypto.subtle.importKey('raw', \u2026)` takes the bare 32 bytes\n * for Ed25519, which keeps this table readable and removes a DER prefix that\n * would be one more thing to get wrong by hand.\n */\nexport const CALIBRATION_PUBLIC_KEYS: Readonly<Record<string, string>> = {\n  'greenlight-calibration-1': 'jPjyCrgLvAt3XsBQzUl5T7A/AszXPjL35WY93iPdDcI=',\n};\n\n/** The key new payloads are signed with. Read by the signing script only. */\nexport const CALIBRATION_SIGNING_KEY_ID = 'greenlight-calibration-1';\n\n/**\n * The one signature algorithm accepted.\n *\n * Compared case-sensitively against the envelope's `alg`, and there is no\n * \"choose the algorithm from the envelope\" branch anywhere \u2014 an attacker-chosen\n * algorithm field is the oldest hole in signed-token design and the cheapest\n * way to close it is to have exactly one accepted value.\n */\nexport const CALIBRATION_SIGNATURE_ALGORITHM = 'Ed25519';\n", "/**\n * The vocabulary of licence-delivered scoring calibration.\n *\n * ===========================================================================\n * ## What calibration is, and what it is emphatically not\n *\n * Greenlight ships as readable JavaScript, its `.ts` sources travel inside the\n * published tarball, and the repository is going public. A fork can therefore\n * delete the licence check in an afternoon. The answer to that is *not*\n * obfuscation \u2014 it is to make a licence deliver data that a fork cannot\n * reproduce, while the product keeps working perfectly without it.\n *\n * Calibration is that data: expanded decision-maker and influencer title\n * vocabularies, a shared-inbox and placeholder lexicon, and an industry synonym\n * taxonomy. All of it is accumulated grind, none of it is algorithm. A fork gets\n * the twenty-five English titles in `src/scoring/defaults.ts` and mis-scores\n * every German `Gesch\u00E4ftsf\u00FChrer` and every Brazilian `S\u00F3cio`.\n *\n * ## The rule this module must never break\n *\n * **Fail-open is the product's promise and calibration must not weaken it.**\n * Every type below is optional at the point of use, and every failure \u2014 absent,\n * stale, unlicensed, malformed, unsigned, wrongly signed \u2014 resolves to exactly\n * one behaviour: the in-source defaults, unchanged, with no error surfaced to\n * the lead. An unlicensed workspace scores a lead byte-for-byte identically to\n * how it scored that lead before this feature existed. `apply.ts` is the only\n * consumer and it is a pure function whose fall-back branch is the identity.\n *\n * Nothing server-side is load-bearing. If `licensing.rizvigoc.com` disappeared\n * permanently, Greenlight would keep scoring on shipped defaults forever.\n *\n * ## Where it arrives from \u2014 and why it is not the config endpoint\n *\n * The licensing service publishes `GET /v1/licenses/{id}/config`, and the\n * obvious design is to call it. It cannot be called. Both config endpoints\n * (`/v1/licenses/{id}/config` and `/v1/products/{id}/config`) **reject a licence\n * key as a credential** \u2014 measured on 2026-08-05 as a bare `401` for the licence\n * key in the `X-Numaya-License-Key` header, as an `Authorization: Bearer` value,\n * and as a `?key=` query parameter. The service's own Configurations guide says\n * so in as many words:\n *\n *   > Both config endpoints require an API key or JWT \u2014 the credential a\n *   > *license key* holder would present is turned away. [\u2026] if your product\n *   > ships to a customer's own infrastructure (not a SaaS you host yourself),\n *   > the product binary itself can never call these two endpoints directly.\n *\n * Greenlight runs inside the customer's Twenty instance and may never carry an\n * org-scoped management credential, so that door is shut. The guide's two\n * suggested workarounds are a self-hosted relay (forbidden: no Rizvi\n * infrastructure may be load-bearing) and baking the config into the release\n * (self-defeating: a public tarball hands the calibration to the fork).\n *\n * What *is* reachable with nothing but the customer's licence key is the\n * `validate` response, which Greenlight already calls nightly. It carries\n * `customerMetadata` \u2014 an org-authored JSON object, set when the licence is\n * issued \u2014 straight back to the key holder. That is the delivery channel, and it\n * costs no additional request. See `src/licensing/parse.ts`.\n *\n * ## What integrity can honestly be claimed\n *\n * See `verify.ts`. Short version: the envelope is signed by *us* with a key we\n * hold, not by the licensing service, because the service has no endpoint that\n * will sign an arbitrary payload. That is a real end-to-end authorship\n * guarantee and it is not the same guarantee as \"Numaya signed this\".\n * ===========================================================================\n */\n\n/* -------------------------------------------------------------------------- */\n/* The payload                                                                 */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The calibration pack itself \u2014 pure data, no behaviour, no thresholds.\n *\n * Note what is absent: weights, band thresholds, the gate threshold, and every\n * rule identifier. Those are either scoring logic or the workspace's own\n * configuration, and neither is ours to deliver. Calibration only ever supplies\n * *vocabulary* \u2014 the lists a rule matches against \u2014 so the worst a hostile or\n * corrupted payload could do is match more or fewer job titles. It cannot move a\n * threshold, disable a rule, or change what a score means.\n */\nexport interface Calibration {\n  /** Shape version. A payload from a future shape is refused, not guessed at. */\n  readonly schemaVersion: number;\n  /** Content version, shown to the admin as \"calibration v3\". Monotonic. */\n  readonly calibrationVersion: number;\n  readonly issuedAt: string;\n  readonly notes: string | null;\n  readonly decisionMakerTitles: readonly string[];\n  readonly influencerTitles: readonly string[];\n  readonly roleInboxLocalParts: readonly string[];\n  readonly placeholderValues: readonly string[];\n  /**\n   * Canonical industry term \u2192 the free-text variants that mean the same thing.\n   *\n   * Used to *expand* a workspace's own ICP target list, never to replace it: an\n   * admin who types \"Construction\" gets `bau`, `b\u00E2timent`, `edilizia` and\n   * `construcci\u00F3n` matched too. This is what turns the 40 idle ICP points into\n   * points that actually fire against real free-text industry columns.\n   */\n  readonly industrySynonyms: Readonly<Record<string, readonly string[]>>;\n}\n\n/** The only schema version this build understands. */\nexport const CALIBRATION_SCHEMA_VERSION = 1;\n\n/* -------------------------------------------------------------------------- */\n/* The signed envelope                                                         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * What actually travels: the payload plus a detached signature over its\n * canonical form.\n *\n * `keyId` rather than a bare key so rotation is a data change and not a release.\n * A payload naming a key this build does not carry is refused \u2014 see\n * `verify.ts`, \"Why an unknown key is refused rather than trusted\".\n */\nexport interface SignedCalibrationEnvelope {\n  readonly alg: string;\n  readonly keyId: string;\n  readonly signature: string;\n  readonly payload: Calibration;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Verification outcome                                                        */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Why calibration is or is not in use, as a closed vocabulary.\n *\n * Closed rather than free text because these values reach an admin-facing panel\n * and an audit row, and because every single one of them resolves to the same\n * *behaviour* \u2014 shipped defaults \u2014 so the only thing distinguishing them is how\n * clearly they explain themselves to the person reading.\n */\nexport type CalibrationReason =\n  /** Verified and in use. */\n  | 'calibrated'\n  /** No licence key configured, or the licence is not entitled. */\n  | 'not_licensed'\n  /** Licensed, but this licence carries no calibration. */\n  | 'not_provisioned'\n  /** Present but not a readable envelope. */\n  | 'malformed'\n  /** Present, readable, but carries no signature at all. */\n  | 'unsigned'\n  /** Signed with a key id this build does not know. */\n  | 'unknown_key'\n  /** Signature did not verify against the embedded public key. */\n  | 'signature_invalid'\n  /** A payload shape from a future release. */\n  | 'schema_unsupported'\n  /** Verification could not run \u2014 no crypto primitive in this runtime. */\n  | 'verifier_unavailable'\n  /** Cached calibration older than the offline grace window. */\n  | 'stale'\n  /**\n   * A cached payload whose seal does not verify under the configured licence\n   * key: moved between workspaces, edited in place, or left behind by a key\n   * that has since been changed or removed.\n   */\n  | 'cache_unsealed';\n\nexport type CalibrationVerification =\n  | { readonly kind: 'verified'; readonly calibration: Calibration }\n  | { readonly kind: 'rejected'; readonly reason: CalibrationReason; readonly detail: string };\n\n/* -------------------------------------------------------------------------- */\n/* Cache + published state                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * What survives between runs, beside the entitlement cache and on the same\n * ladder.\n *\n * The verified payload is stored, not the envelope: re-verifying on every lead\n * would spend an Ed25519 check per scoring run to re-derive a fact the nightly\n * run already established, and the signature has no value once the bytes are\n * inside the workspace's own key-value storage \u2014 anything able to tamper with\n * that store is already inside the trust boundary the signature protects.\n * `keyId` and `verifiedAt` are kept so the admin panel can say what was checked\n * and when.\n */\nexport interface CachedCalibration {\n  readonly cachedAt: string;\n  readonly verifiedAt: string;\n  readonly keyId: string;\n  /**\n   * HMAC over this entry's canonical form, under a secret derived from the\n   * licence key. See `seal.ts` for exactly what it does and does not prove \u2014\n   * it is licence-binding and tamper-evidence, not authenticity of origin.\n   *\n   * An entry with no tag is not accepted. There is no \"unsealed\" mode.\n   */\n  readonly sealTag: string;\n  readonly calibration: Calibration;\n}\n\n/**\n * The bytes the seal is computed over: everything in a cache entry except the\n * tag itself.\n *\n * Declared as its own type so the sealing side and the verifying side cannot\n * drift \u2014 a field added to `CachedCalibration` and not to this shape would be\n * a field outside the seal, which is the quiet way a MAC stops covering what\n * everyone assumes it covers.\n */\nexport type SealedCalibrationBody = Omit<CachedCalibration, 'sealTag'>;\n\nexport type CalibrationSource = 'live' | 'cache' | 'none';\n\n/**\n * The admin-facing answer to \"am I running shipped defaults or calibration\n * vNN, and when did it last refresh?\".\n *\n * Published to key-value storage on every nightly run and read by the licence\n * panel. Deliberately a separate record from `LicenceState`: a workspace can be\n * perfectly licensed and still be on shipped defaults (its licence predates\n * calibration provisioning), and collapsing the two would make that state\n * unreadable.\n */\nexport interface CalibrationState {\n  readonly status: 'calibrated' | 'shipped_defaults';\n  readonly reason: CalibrationReason;\n  readonly source: CalibrationSource;\n  readonly calibrationVersion: number | null;\n  readonly issuedAt: string | null;\n  /** When the payload was last fetched and verified. Null on shipped defaults. */\n  readonly refreshedAt: string | null;\n  readonly checkedAt: string;\n  readonly cacheAgeMs: number | null;\n  readonly keyId: string | null;\n  /** Sizes of each list, so the panel can show what arrived without dumping it. */\n  readonly counts: CalibrationCounts | null;\n}\n\nexport interface CalibrationCounts {\n  readonly decisionMakerTitles: number;\n  readonly influencerTitles: number;\n  readonly roleInboxLocalParts: number;\n  readonly placeholderValues: number;\n  readonly industrySynonyms: number;\n}\n\n/**\n * Read-only access to the cached payload, for the scoring path.\n *\n * A reader, never a writer: the scoring run must not be handed something it\n * could use to change what future runs score against, for the same reason\n * `readPublishedLicenceState` is not on `LicenceStorePort`.\n */\nexport interface CalibrationReaderPort {\n  read(): Promise<CachedCalibration | null>;\n}\n\n/**\n * The writer's side, used only by the nightly licence run.\n *\n * Separate from `LicenceStorePort` rather than bolted onto it, because the two\n * have different failure consequences and different lifetimes: a licence cache\n * that fails to write costs an entitlement re-check, whereas a calibration cache\n * that fails to write costs a vocabulary that the very next run replaces. Both\n * swallow their errors, and keeping them apart means neither can be made to fail\n * the other.\n */\nexport interface CalibrationStorePort {\n  readCalibration(): Promise<CachedCalibration | null>;\n  writeCalibration(entry: CachedCalibration): Promise<void>;\n  /**\n   * Drop the cached payload entirely.\n   *\n   * Called on exactly one transition \u2014 a nightly run finding the licence no\n   * longer entitled \u2014 and it is what lets the scoring path skip an entitlement\n   * check: the cache's *existence* carries that fact. See\n   * `src/calibration/state.ts`, \"Why there is no entitlement check here\".\n   */\n  clearCalibration(): Promise<void>;\n  publishCalibrationState(state: CalibrationState): Promise<void>;\n}\n", "/**\n * Reading a calibration envelope out of whatever the licensing service sent.\n *\n * The input is the `customerMetadata` object from a `validate` response \u2014 a\n * free-form JSON document, authored by us but stored, re-serialised and\n * returned by a service we do not deploy in lockstep with this app. It is\n * untrusted in the ordinary sense (it crossed a network) and unstable in the\n * boring sense (a future release may put other things beside ours in there).\n *\n * So parsing is **total**: it never throws, it never returns `undefined`, and\n * every malformed shape becomes a named rejection rather than a `TypeError`\n * inside a customer's nightly cron job.\n *\n * ## Why the envelope lives under one namespaced key\n *\n * `customerMetadata.greenlightCalibration`, not the root. The field is the\n * licence's general-purpose metadata bag and there is every chance it will one\n * day also carry a customer reference, a support tier, or a flag for some\n * feature that does not exist yet. Owning one key means none of that collides\n * with us and none of it changes the bytes we verify \u2014 the signature covers the\n * envelope, not its surroundings, so a sibling key appearing next to ours must\n * not invalidate a payload. Namespacing is what makes that true.\n *\n * ## Every list is normalised here, once\n *\n * Entries are lower-cased, trimmed and de-duplicated at the boundary rather\n * than at the point of use. `src/scoring/rules/helpers.ts` normalises again on\n * every comparison and would cope regardless \u2014 but doing it here means the\n * counts shown to an admin are the counts that actually take effect, and a\n * payload with `\"CEO\"` and `\"ceo\"` in it does not read as 200 titles when it\n * carries 199.\n */\n\nimport {\n  CALIBRATION_SCHEMA_VERSION,\n  type Calibration,\n  type CalibrationVerification,\n  type SignedCalibrationEnvelope,\n} from 'src/calibration/types';\n\n/** The key our envelope occupies inside the licence's metadata bag. */\nexport const CALIBRATION_METADATA_KEY = 'greenlightCalibration';\n\nexport type EnvelopeRead =\n  | { readonly kind: 'envelope'; readonly envelope: SignedCalibrationEnvelope }\n  | {\n      readonly kind: 'rejected';\n      readonly reason: Extract<\n        CalibrationVerification,\n        { kind: 'rejected' }\n      >['reason'];\n      readonly detail: string;\n    };\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\nconst reject = (\n  reason: Extract<CalibrationVerification, { kind: 'rejected' }>['reason'],\n  detail: string,\n): EnvelopeRead => ({ kind: 'rejected', reason, detail });\n\n/**\n * A list of lowercase, trimmed, de-duplicated non-empty strings.\n *\n * Non-strings are dropped rather than rejected: one bad entry in a list of two\n * hundred should cost that entry, not the whole calibration. A list that is not\n * an array at all is a different matter and is handled by the caller.\n */\nconst readStringList = (value: unknown): readonly string[] | null => {\n  if (!Array.isArray(value)) {\n    return null;\n  }\n\n  const seen = new Set<string>();\n\n  for (const entry of value) {\n    if (typeof entry !== 'string') {\n      continue;\n    }\n\n    const normalised = entry.trim().toLowerCase().replace(/\\s+/g, ' ');\n\n    if (normalised.length > 0) {\n      seen.add(normalised);\n    }\n  }\n\n  return [...seen];\n};\n\n/**\n * The synonym taxonomy: canonical term \u2192 variants.\n *\n * A canonical whose variant list is unusable is dropped whole rather than kept\n * empty, because an empty variant list would expand a workspace's ICP by\n * nothing while still appearing in the admin panel's count as if it had done\n * something.\n */\nconst readSynonyms = (\n  value: unknown,\n): Readonly<Record<string, readonly string[]>> | null => {\n  if (!isRecord(value)) {\n    return null;\n  }\n\n  const table: Record<string, readonly string[]> = {};\n\n  for (const [rawCanonical, rawVariants] of Object.entries(value)) {\n    const canonical = rawCanonical.trim().toLowerCase().replace(/\\s+/g, ' ');\n\n    if (canonical.length === 0) {\n      continue;\n    }\n\n    const variants = readStringList(rawVariants);\n\n    if (variants === null) {\n      continue;\n    }\n\n    // The canonical is never one of its own variants \u2014 it is already matched\n    // directly \u2014 and letting it in would double-count in the admin panel.\n    //\n    // The self-reference is stripped *before* the emptiness check, not after.\n    // Stripping afterwards left `{ construction: ['construction'] }` surviving\n    // as an empty cluster: harmless for scoring, but it inflated the synonym\n    // count the admin panel shows, which is the one thing this filter exists to\n    // stop.\n    const distinct = variants.filter((variant) => variant !== canonical);\n\n    if (distinct.length === 0) {\n      continue;\n    }\n\n    table[canonical] = distinct;\n  }\n\n  return table;\n};\n\nconst readInteger = (value: unknown): number | null =>\n  typeof value === 'number' && Number.isInteger(value) && value >= 0\n    ? value\n    : null;\n\nconst readPayload = (raw: unknown): Calibration | { readonly error: string } => {\n  if (!isRecord(raw)) {\n    return { error: 'payload is not a JSON object' };\n  }\n\n  const schemaVersion = readInteger(raw['schemaVersion']);\n\n  if (schemaVersion === null) {\n    return { error: 'payload has no non-negative integer schemaVersion' };\n  }\n\n  const calibrationVersion = readInteger(raw['calibrationVersion']);\n\n  if (calibrationVersion === null) {\n    return { error: 'payload has no non-negative integer calibrationVersion' };\n  }\n\n  const decisionMakerTitles = readStringList(raw['decisionMakerTitles']);\n  const influencerTitles = readStringList(raw['influencerTitles']);\n  const roleInboxLocalParts = readStringList(raw['roleInboxLocalParts']);\n  const placeholderValues = readStringList(raw['placeholderValues']);\n  const industrySynonyms = readSynonyms(raw['industrySynonyms']);\n\n  // Absent is fine and means \"this pack has no opinion about that list\" \u2014 the\n  // shipped default survives for it. Present-but-not-an-array is not fine: it\n  // means the payload is a shape we do not understand, and guessing would be\n  // how a calibration silently stops applying half of itself.\n  if (\n    (raw['decisionMakerTitles'] !== undefined && decisionMakerTitles === null) ||\n    (raw['influencerTitles'] !== undefined && influencerTitles === null) ||\n    (raw['roleInboxLocalParts'] !== undefined && roleInboxLocalParts === null) ||\n    (raw['placeholderValues'] !== undefined && placeholderValues === null) ||\n    (raw['industrySynonyms'] !== undefined && industrySynonyms === null)\n  ) {\n    return { error: 'one or more calibration lists were not of the expected type' };\n  }\n\n  return {\n    schemaVersion,\n    calibrationVersion,\n    issuedAt:\n      typeof raw['issuedAt'] === 'string' && raw['issuedAt'].length > 0\n        ? raw['issuedAt']\n        : '',\n    notes: typeof raw['notes'] === 'string' ? raw['notes'] : null,\n    decisionMakerTitles: decisionMakerTitles ?? [],\n    influencerTitles: influencerTitles ?? [],\n    roleInboxLocalParts: roleInboxLocalParts ?? [],\n    placeholderValues: placeholderValues ?? [],\n    industrySynonyms: industrySynonyms ?? {},\n  };\n};\n\n/**\n * Pull the envelope out of a licence's `customerMetadata`.\n *\n * Returns `not_provisioned` \u2014 not an error \u2014 when the key is simply absent.\n * That is the normal state of every licence issued before calibration existed,\n * and of every rules-only licence, and it must read as \"nothing to do here\"\n * rather than as a fault in the admin panel.\n */\nexport const readCalibrationEnvelope = (metadata: unknown): EnvelopeRead => {\n  if (!isRecord(metadata)) {\n    return reject('not_provisioned', 'licence carries no metadata');\n  }\n\n  const raw = metadata[CALIBRATION_METADATA_KEY];\n\n  if (raw === undefined || raw === null) {\n    return reject(\n      'not_provisioned',\n      `licence metadata has no \"${CALIBRATION_METADATA_KEY}\" entry`,\n    );\n  }\n\n  if (!isRecord(raw)) {\n    return reject(\n      'malformed',\n      `\"${CALIBRATION_METADATA_KEY}\" is not a JSON object`,\n    );\n  }\n\n  const signature = raw['signature'];\n  const keyId = raw['keyId'];\n  const alg = raw['alg'];\n\n  if (typeof signature !== 'string' || signature.length === 0) {\n    return reject('unsigned', 'envelope carries no signature');\n  }\n\n  if (typeof keyId !== 'string' || keyId.length === 0) {\n    return reject('unsigned', 'envelope names no signing key');\n  }\n\n  if (typeof alg !== 'string' || alg.length === 0) {\n    return reject('unsigned', 'envelope names no signature algorithm');\n  }\n\n  const payload = readPayload(raw['payload']);\n\n  if ('error' in payload) {\n    return reject('malformed', payload.error);\n  }\n\n  // Checked after parsing rather than before, so a future-shaped payload\n  // reports *why* it was refused \u2014 \"schema 2, this build understands 1\" \u2014 with\n  // the version it actually carried, rather than reporting the same generic\n  // \"malformed\" a truncated blob would.\n  if (payload.schemaVersion !== CALIBRATION_SCHEMA_VERSION) {\n    return reject(\n      'schema_unsupported',\n      `payload schemaVersion ${payload.schemaVersion}; this build understands ${CALIBRATION_SCHEMA_VERSION}`,\n    );\n  }\n\n  return { kind: 'envelope', envelope: { alg, keyId, signature, payload } };\n};\n", "/**\n * Signature verification for a calibration envelope.\n *\n * ===========================================================================\n * ## What this proves, and what it does not \u2014 read this before quoting it\n *\n * **It proves:** the payload now in memory is byte-identical, under the\n * canonicalisation in `canonical.ts`, to a payload signed by the holder of the\n * private half of an embedded key. Nobody between the signing step and this\n * function \u2014 the licensing service, its database, a compromised TLS path, a\n * proxy, a workspace administrator with API access \u2014 can substitute or edit the\n * calibration without the signature failing. That is a genuine end-to-end\n * authorship guarantee and it is the property worth having, because the payload\n * spends its life at rest inside a third-party service.\n *\n * **It does not prove that Numaya's licensing service signed anything.** It\n * cannot: the service has no endpoint that signs an arbitrary payload, and its\n * config download surface (`ConfigDownloadResponse`) carries no signature field\n * whatsoever. The transport integrity of the fetch is ordinary TLS to\n * `licensing.rizvigoc.com` plus licence-key authentication, and nothing more.\n * See `keys.ts` for the measurements behind that statement.\n *\n * **It does not prove freshness.** A signature is not a timestamp. Someone who\n * can control what the `validate` response returns could replay an *older*\n * genuinely-signed payload, and this function would accept it. Two things bound\n * that: `calibrationVersion` and `issuedAt` are inside the signed payload and\n * are published to the admin panel, so a rollback is visible rather than silent;\n * and the worst outcome of a successful replay is an older vocabulary, which is\n * strictly bounded by \"the shipped defaults\" in badness. There is no version\n * ratchet, deliberately \u2014 a ratchet would let one bad payload permanently wedge\n * a workspace, and permanently wedged is a worse failure than slightly stale.\n *\n * **It does not prove the payload is sensible.** Signing is authorship, not\n * review. `parse.ts` still validates the shape and `apply.ts` still refuses to\n * let calibration touch anything but vocabulary.\n *\n * ## Every failure lands in the same place\n *\n * Unknown key, wrong algorithm, bad base64, absent signature, no crypto in the\n * runtime, verification throwing \u2014 all of them return `rejected`, and every\n * caller of `rejected` uses the in-source defaults. There is no branch in this\n * file that can make scoring fail, and none that can make it throw.\n *\n * ## Why WebCrypto and not `node:crypto`\n *\n * `crypto.subtle` is a global. Reaching for it costs no import, so nothing here\n * depends on how the logic-function bundle treats Node built-ins \u2014 and a bundler\n * that decided to inline or stub `node:crypto` would have turned signature\n * verification into a silent no-op rather than a build error. A global that is\n * either present or absent fails loudly in the one direction that matters.\n * ===========================================================================\n */\n\nimport { canonicalBytes } from 'src/calibration/canonical';\nimport {\n  CALIBRATION_PUBLIC_KEYS,\n  CALIBRATION_SIGNATURE_ALGORITHM,\n} from 'src/calibration/keys';\nimport {\n  type CalibrationReason,\n  type CalibrationVerification,\n  type SignedCalibrationEnvelope,\n} from 'src/calibration/types';\n\nconst reject = (\n  reason: CalibrationReason,\n  detail: string,\n): CalibrationVerification => ({ kind: 'rejected', reason, detail });\n\n/**\n * Base64 \u2192 bytes without `Buffer`.\n *\n * `atob` is a global in every runtime this ships to and, unlike `Buffer`, needs\n * no Node shim in a browser-ish bundle. Returns `null` on anything unparseable\n * instead of throwing, because \"the signature field held garbage\" is an\n * expected input here, not an exceptional one.\n */\nconst decodeBase64 = (value: string): Uint8Array | null => {\n  try {\n    const binary = atob(value);\n    const bytes = new Uint8Array(binary.length);\n\n    for (let index = 0; index < binary.length; index += 1) {\n      bytes[index] = binary.charCodeAt(index);\n    }\n\n    return bytes;\n  } catch {\n    return null;\n  }\n};\n\n/** Ed25519 signatures are always exactly 64 bytes; keys always exactly 32. */\nconst ED25519_SIGNATURE_BYTES = 64;\nconst ED25519_PUBLIC_KEY_BYTES = 32;\n\nconst subtle = (): SubtleCrypto | null => {\n  const candidate = (globalThis as { crypto?: { subtle?: SubtleCrypto } }).crypto\n    ?.subtle;\n\n  return candidate === undefined ? null : candidate;\n};\n\n/**\n * Verify an envelope whose *shape* has already been checked by `parse.ts`.\n *\n * Split from parsing on purpose: parsing is synchronous and total, verification\n * is asynchronous and needs a runtime capability. Keeping them apart means the\n * shape tests do not need a crypto stub and the crypto tests do not need a\n * fixture with nineteen fields.\n */\nexport const verifyCalibrationEnvelope = async (\n  envelope: SignedCalibrationEnvelope,\n): Promise<CalibrationVerification> => {\n  if (envelope.alg !== CALIBRATION_SIGNATURE_ALGORITHM) {\n    return reject(\n      'unsigned',\n      `unsupported signature algorithm \"${envelope.alg}\"`,\n    );\n  }\n\n  const publicKeyBase64 = CALIBRATION_PUBLIC_KEYS[envelope.keyId];\n\n  // ## Why an unknown key is refused rather than trusted\n  //\n  // The alternative \u2014 accept any key id and verify against whatever the payload\n  // supplies \u2014 verifies that the payload signed itself, which is not a\n  // property. The key table is the trust anchor; a key outside it is a stranger.\n  // A workspace on an older build therefore refuses a payload signed with a\n  // newly rotated key and keeps shipped defaults, which is the correct\n  // degradation and is why `keys.ts` says to ship the key before signing with\n  // it.\n  if (publicKeyBase64 === undefined) {\n    return reject(\n      'unknown_key',\n      `no embedded public key for keyId \"${envelope.keyId}\"`,\n    );\n  }\n\n  const signature = decodeBase64(envelope.signature);\n\n  if (signature === null || signature.length !== ED25519_SIGNATURE_BYTES) {\n    return reject(\n      'signature_invalid',\n      `signature is not ${ED25519_SIGNATURE_BYTES} bytes of base64`,\n    );\n  }\n\n  const publicKey = decodeBase64(publicKeyBase64);\n\n  if (publicKey === null || publicKey.length !== ED25519_PUBLIC_KEY_BYTES) {\n    // An embedded key that does not decode is a build defect, not an input\n    // problem. It still degrades rather than throws \u2014 a customer's nightly cron\n    // is not the place to discover a typo in a constant, and the fall-back is\n    // the same shipped defaults either way.\n    return reject(\n      'verifier_unavailable',\n      `embedded public key \"${envelope.keyId}\" is not ${ED25519_PUBLIC_KEY_BYTES} raw bytes`,\n    );\n  }\n\n  const message = canonicalBytes(envelope.payload);\n\n  if (message === null) {\n    return reject('malformed', 'payload could not be canonicalised');\n  }\n\n  const crypto = subtle();\n\n  if (crypto === null) {\n    return reject(\n      'verifier_unavailable',\n      'this runtime exposes no crypto.subtle, so the signature could not be checked',\n    );\n  }\n\n  try {\n    const key = await crypto.importKey(\n      'raw',\n      publicKey as unknown as BufferSource,\n      { name: CALIBRATION_SIGNATURE_ALGORITHM },\n      false,\n      ['verify'],\n    );\n\n    const verified = await crypto.verify(\n      { name: CALIBRATION_SIGNATURE_ALGORITHM },\n      key,\n      signature as unknown as BufferSource,\n      message as unknown as BufferSource,\n    );\n\n    return verified\n      ? { kind: 'verified', calibration: envelope.payload }\n      : reject(\n          'signature_invalid',\n          'the signature does not match the payload under this build\u2019s canonicalisation',\n        );\n  } catch (error) {\n    // A runtime that has `crypto.subtle` but not Ed25519 throws here rather\n    // than returning false. Same landing place: shipped defaults, and a reason\n    // string an admin can act on.\n    return reject(\n      'verifier_unavailable',\n      `Ed25519 verification is unavailable in this runtime: ${\n        error instanceof Error ? error.name : 'unknown error'\n      }`,\n    );\n  }\n};\n", "/**\n * Binding a cached calibration to the licence key that fetched it.\n *\n * ===========================================================================\n * ## What this is for, stated without decoration\n *\n * The calibration payload spends most of its life at rest in the workspace's own\n * key-value storage. The Ed25519 signature in `verify.ts` proves who *authored*\n * it, and is checked once, when it arrives. This adds a second, different\n * property to the copy that is kept: the cache is sealed with a secret derived\n * from the licence key, and a cache whose seal does not verify under the\n * currently-configured key is refused.\n *\n * **It does buy:** a calibration cache lifted out of a licensed workspace and\n * dropped into an unlicensed one is rejected. The unlicensed install has no key,\n * so it cannot produce a matching tag, and it falls back to shipped defaults.\n * The same applies to a workspace whose licence key has been changed or removed.\n * It is also tamper-evidence: an edited cache entry no longer verifies.\n *\n * **It does not buy:** protection against someone who *holds* a valid licence\n * key. They have the secret; they can seal whatever they like. Nothing that runs\n * entirely inside the customer's own infrastructure can prevent that, and a\n * comment claiming otherwise would be a comfortable story rather than a\n * security property. The signature is the control that survives a hostile\n * licence holder \u2014 they can forge a cache, but they cannot forge a payload that\n * verifies against the embedded public key, so they cannot manufacture a\n * *newer* calibration than the one they were sold.\n *\n * **It is licence-binding and tamper-evidence. It is not authenticity of\n * origin.** Those are different properties and this file provides the first two.\n *\n * ## Why a port rather than the key\n *\n * `src/licensing/types.ts` records a structural guarantee: no type in the\n * licensing core has a `key` field, so there is no variable in the core that\n * *could* leak one. Calibration keeps that guarantee by never receiving key\n * material either. The seal arrives as two functions, implemented at the edge in\n * `src/logic-functions/licence-cache-seal.ts`, which is the only place besides\n * the HTTP adapter that touches the raw key.\n *\n * The consequence worth noting: a `null` implementation \u2014 no licence key\n * configured \u2014 cannot seal and cannot verify, so an unlicensed workspace can\n * never present an acceptable cache. That is the correct direction of failure,\n * and it falls out of the port's shape rather than out of a check somebody has\n * to remember to write.\n * ===========================================================================\n */\n\n/**\n * Seal and verification over the canonical form of a cache entry.\n *\n * `seal` returns `null` when it cannot produce a tag \u2014 no key, or a runtime with\n * no HMAC. The caller then declines to cache at all rather than storing an\n * unsealed entry, because an entry that can be read back without a tag check is\n * exactly the entry this whole file exists to refuse.\n */\nexport interface CalibrationSealPort {\n  seal(canonical: string): Promise<string | null>;\n  verify(canonical: string, tag: string): Promise<boolean>;\n}\n\n/**\n * The seal for a workspace with no licence key: seals nothing, accepts nothing.\n *\n * Used as the default so that a caller which forgets to wire a real seal gets\n * \"no calibration\" rather than \"calibration with no integrity check\". Failing\n * closed on the *cache* is safe precisely because failing closed there means\n * falling back to the shipped defaults, which is a fully working product.\n */\nexport const NO_SEAL: CalibrationSealPort = {\n  seal: async () => null,\n  verify: async () => false,\n};\n", "/**\n * Cache freshness and offline-grace arithmetic.\n *\n * Pure: `now` is passed in, never read. The scoring engine holds the same line\n * for the same reason \u2014 a clock read inside a decision function makes the\n * decision untestable at its boundaries, and every interesting case here *is* a\n * boundary.\n *\n * ---------------------------------------------------------------------------\n * ## The windows, and why they are these windows\n *\n * From the error-state table in `LICENSING_INTEGRATION.md`:\n *\n * | Cache age        | Behaviour                                     |\n * |------------------|-----------------------------------------------|\n * | `< 24h`          | Cached entitlement used as-is                 |\n * | `24h \u2013 72h`      | Rules-only, \"grace period\"                    |\n * | `> 72h`          | Rules-only + visible warning                  |\n *\n * Note that grace **ends at 72h from `cachedAt`**, not at 24h + 72h. The prose\n * elsewhere reads \"24h cache, then a 72h offline grace window\", which would put\n * the cliff at 96h; the table is the specific claim and the table is what is\n * implemented. The difference is 24 hours of degraded-but-warned operation and\n * it changes nothing about safety, because **nothing is ever blocked at any\n * point on this ladder** \u2014 past 72h the product is still scoring leads, it is\n * just scoring them without enrichment and saying so loudly.\n *\n * ## Why grace disables enrichment rather than extending it\n *\n * Because the two failure modes are not symmetric. Trusting a stale entitlement\n * for three days means potentially serving a paid feature to a revoked licence,\n * and revocation is the one lever that has to work. Turning enrichment off means\n * the customer loses an optional enhancement during a Numaya outage. The second\n * is recoverable in seconds when the service returns; the first is not\n * recoverable at all.\n *\n * The 24h band is the exception, and it is bounded precisely so that \"Numaya\n * restarted a container\" never costs a customer anything.\n * ---------------------------------------------------------------------------\n */\n\nconst HOUR_MS = 60 * 60 * 1000;\n\n/** Entitlements younger than this are used exactly as if they were live. */\nexport const LICENCE_CACHE_TTL_MS = 24 * HOUR_MS;\n\n/**\n * Age at which the offline grace window closes, measured from `cachedAt`.\n * Past this the product warns visibly \u2014 it does not stop.\n */\nexport const LICENCE_OFFLINE_GRACE_LIMIT_MS = 72 * HOUR_MS;\n\nexport type CacheFreshness = 'fresh' | 'grace' | 'expired';\n\n/**\n * Age of a cached entitlement in milliseconds, or `null` when `cachedAt` is\n * missing or unparseable.\n *\n * A negative age \u2014 a cache written by a machine whose clock is ahead \u2014 is\n * clamped to `0` rather than rejected. The alternative is that a small clock\n * skew on the licensing service makes a workspace look like it has never\n * validated, which is a worse outcome than briefly treating a slightly-future\n * entitlement as fresh.\n */\nexport const cacheAgeMs = (\n  cachedAt: string | null | undefined,\n  now: Date,\n): number | null => {\n  if (typeof cachedAt !== 'string' || cachedAt.length === 0) {\n    return null;\n  }\n\n  const cachedMs = Date.parse(cachedAt);\n\n  if (Number.isNaN(cachedMs)) {\n    return null;\n  }\n\n  return Math.max(0, now.getTime() - cachedMs);\n};\n\n/**\n * Boundaries are inclusive at the *lower* edge of the worse band: an entitlement\n * exactly 24h old is already in grace, and one exactly 72h old is already\n * expired. Erring towards the stricter band on the boundary keeps the rule\n * \"fresh means strictly under a day old\" true as stated.\n */\nexport const classifyCacheAge = (ageMs: number): CacheFreshness => {\n  if (ageMs < LICENCE_CACHE_TTL_MS) {\n    return 'fresh';\n  }\n\n  if (ageMs < LICENCE_OFFLINE_GRACE_LIMIT_MS) {\n    return 'grace';\n  }\n\n  return 'expired';\n};\n\n/**\n * `null` when there is no usable cache at all \u2014 which is not the same as an\n * expired one, and the admin notice says so differently.\n */\nexport const classifyCache = (\n  cachedAt: string | null | undefined,\n  now: Date,\n): { readonly freshness: CacheFreshness | null; readonly ageMs: number | null } => {\n  const ageMs = cacheAgeMs(cachedAt, now);\n\n  return {\n    freshness: ageMs === null ? null : classifyCacheAge(ageMs),\n    ageMs,\n  };\n};\n", "/**\n * Resolving \"am I running shipped defaults or calibration vNN, and when did it\n * last refresh?\" \u2014 one pure function, `now` injected, no I/O.\n *\n * ===========================================================================\n * ## The same ladder as the entitlement, for the same reasons\n *\n * Calibration is cached beside the entitlement in workspace key-value storage\n * and walks the identical 24h / 72h freshness ladder from\n * `src/licensing/cache.ts`. Sharing the arithmetic is not laziness \u2014 the two\n * caches are refreshed by the *same nightly run*, so any second ladder would\n * differ from this one only by drifting out of step with it.\n *\n * Where the two differ is what the far end of the ladder means, and the\n * difference is the whole point:\n *\n *   | Age        | Entitlement                  | Calibration                 |\n *   |------------|------------------------------|-----------------------------|\n *   | `< 24h`    | used as-is                   | used as-is                  |\n *   | `24\u201372h`   | rules-only (\"grace\")         | **still used**              |\n *   | `> 72h`    | rules-only + loud warning    | shipped defaults            |\n *\n * The entitlement tightens at 24h because trusting a stale one risks serving a\n * paid feature to a revoked licence, and revocation has to work. Calibration\n * carries no such risk: it is a word list. Dropping it the moment Numaya has a\n * bad night would make a customer's scores move for a reason that has nothing to\n * do with their data, which is a worse outcome than a slightly old vocabulary.\n * So calibration survives the grace window and is only abandoned past 72h, at\n * which point \"we have not spoken to Numaya in three days\" is a real statement\n * about the install and the admin should be seeing shipped-default behaviour\n * they can reason about.\n *\n * Note the asymmetry is safe in both directions: past 72h calibration falls back\n * to the shipped defaults, which is a *working product*, not a degraded one.\n * There is no branch below that can stop a lead being scored.\n * ===========================================================================\n */\n\nimport { classifyCache } from 'src/licensing/cache';\nimport {\n  type CachedCalibration,\n  type Calibration,\n  type CalibrationCounts,\n  type CalibrationReason,\n  type CalibrationState,\n} from 'src/calibration/types';\n\nexport const countCalibration = (\n  calibration: Calibration,\n): CalibrationCounts => ({\n  decisionMakerTitles: calibration.decisionMakerTitles.length,\n  influencerTitles: calibration.influencerTitles.length,\n  roleInboxLocalParts: calibration.roleInboxLocalParts.length,\n  placeholderValues: calibration.placeholderValues.length,\n  industrySynonyms: Object.keys(calibration.industrySynonyms).length,\n});\n\n/**\n * The state to publish when no usable calibration exists.\n *\n * Every field that describes a payload is `null` rather than zero or empty\n * string: \"there is no calibration\" and \"there is a calibration with nothing in\n * it\" must not render the same in the admin panel, and a zero count is exactly\n * how the second one would look.\n */\nexport const shippedDefaultsState = (\n  reason: CalibrationReason,\n  now: Date,\n): CalibrationState => ({\n  status: 'shipped_defaults',\n  reason,\n  source: 'none',\n  calibrationVersion: null,\n  issuedAt: null,\n  refreshedAt: null,\n  checkedAt: now.toISOString(),\n  cacheAgeMs: null,\n  keyId: null,\n  counts: null,\n});\n\nexport const calibratedState = (\n  entry: CachedCalibration,\n  source: 'live' | 'cache',\n  cacheAgeMs: number | null,\n  now: Date,\n): CalibrationState => ({\n  status: 'calibrated',\n  reason: 'calibrated',\n  source,\n  calibrationVersion: entry.calibration.calibrationVersion,\n  issuedAt: entry.calibration.issuedAt.length > 0 ? entry.calibration.issuedAt : null,\n  refreshedAt: entry.verifiedAt,\n  checkedAt: now.toISOString(),\n  cacheAgeMs,\n  keyId: entry.keyId,\n  counts: countCalibration(entry.calibration),\n});\n\n/**\n * Age at which a cached calibration stops being used. Deliberately the\n * entitlement's *outer* limit, not its inner one \u2014 see the table above.\n */\nexport const CALIBRATION_MAX_AGE_MS = 72 * 60 * 60 * 1000;\n\nexport interface ResolveCalibrationInput {\n  /** The cached payload, or `null` when none has ever been stored. */\n  readonly cached: CachedCalibration | null;\n  readonly now: Date;\n}\n\nexport interface ResolvedCalibration {\n  readonly state: CalibrationState;\n  /** The payload the scoring path should use, or `null` for shipped defaults. */\n  readonly calibration: Calibration | null;\n}\n\n/**\n * What the scoring path should use right now, and what the admin should be told.\n *\n * ===========================================================================\n * ## Why there is no entitlement check here\n *\n * Because the *existence of the cache is* the entitlement check, and moving it\n * to the writer is what keeps a licence lookup out of the per-lead scoring path.\n *\n * `refreshCalibration` writes the cache only while the licence resolves to\n * `full`, and **deletes it** the moment a nightly run finds the entitlement\n * gone. So a present, fresh cache already means \"this workspace was entitled at\n * its last successful licence check\". Re-deriving that per lead would mean a\n * second key-value read on the hot path to re-establish a fact the nightly run\n * has already written down.\n *\n * The consequence is a revocation latency of at most 24 hours \u2014 one nightly\n * cycle \u2014 which is exactly the latency enrichment revocation already has and is\n * documented as having, for the same reason: the alternative is putting a\n * network call to Numaya in front of a customer's scoring path, which is the\n * coupling the fail-open rule exists to prevent.\n *\n * The reverse case costs the customer one night. A renewed licence re-fetches on\n * the next run, and until then the workspace scores on shipped defaults \u2014 the\n * full working product, exactly as an unlicensed install always has.\n * ===========================================================================\n */\nexport const resolveCalibration = (\n  input: ResolveCalibrationInput,\n): ResolvedCalibration => {\n  if (input.cached === null) {\n    return {\n      state: shippedDefaultsState('not_provisioned', input.now),\n      calibration: null,\n    };\n  }\n\n  const { ageMs } = classifyCache(input.cached.cachedAt, input.now);\n\n  // An unreadable `cachedAt` is treated as expired rather than as fresh. The\n  // opposite choice would make a corrupt timestamp mean \"trust this forever\",\n  // which is the one thing a freshness check must never be talked into.\n  if (ageMs === null || ageMs >= CALIBRATION_MAX_AGE_MS) {\n    return {\n      state: {\n        ...shippedDefaultsState('stale', input.now),\n        cacheAgeMs: ageMs,\n        calibrationVersion: input.cached.calibration.calibrationVersion,\n        keyId: input.cached.keyId,\n      },\n      calibration: null,\n    };\n  }\n\n  return {\n    state: calibratedState(\n      input.cached,\n      ageMs === 0 ? 'live' : 'cache',\n      ageMs,\n      input.now,\n    ),\n    calibration: input.cached.calibration,\n  };\n};\n", "/**\n * The calibration half of a licence run: read what the `validate` response\n * carried, verify it, cache it, publish what an admin should see.\n *\n * ===========================================================================\n * ## Why this rides on the existing nightly revalidation\n *\n * It costs nothing. `runLicenceRevalidation` already calls\n * `POST /v1/licenses/validate` once a night at 03:17 UTC, and the response\n * already carries `customerMetadata` \u2014 the calibration arrives in bytes we were\n * fetching anyway. There is no second endpoint, no second credential, no second\n * timeout to tune, and no new failure mode: a run that could not reach Numaya\n * could not have fetched calibration either, and both fall back together.\n *\n * That was not the original plan. The plan was `GET /v1/licenses/{id}/config`,\n * which is the endpoint built for exactly this and which Greenlight cannot call\n * \u2014 it refuses licence-key credentials by design. `src/calibration/types.ts`\n * has the measurements and the service's own documentation of that refusal.\n *\n * ## Ordering: entitlement first, always\n *\n * `refreshCalibration` runs *after* the licence state is resolved and published,\n * and takes the resolved entitlement as an input. Two reasons, and the second is\n * the load-bearing one:\n *\n *  1. An unentitled licence should not have its calibration refreshed, and\n *     asking the entitlement is how we know.\n *  2. **Nothing in this file may be able to delay or fail the entitlement.**\n *     Enrichment gating, the audit row and the admin notice all depend on the\n *     licence state being published; a signature verification that hung or threw\n *     ahead of it would turn a word list into a dependency of the paid feature.\n *     Running afterwards makes that structurally impossible rather than merely\n *     unlikely.\n *\n * ## Every path ends in a published state\n *\n * Including the paths that fail. An admin who cannot tell the difference between\n * \"calibration is off\" and \"calibration broke and nobody said\" has been given\n * nothing, so `not_provisioned`, `signature_invalid`, `unknown_key` and\n * `verifier_unavailable` are all published as distinct reasons \u2014 even though all\n * four behave identically, which is to say the product keeps working on shipped\n * defaults.\n * ===========================================================================\n */\n\nimport { canonicalise } from 'src/calibration/canonical';\nimport { readCalibrationEnvelope } from 'src/calibration/parse';\nimport { NO_SEAL, type CalibrationSealPort } from 'src/calibration/seal';\nimport {\n  calibratedState,\n  countCalibration,\n  resolveCalibration,\n  shippedDefaultsState,\n} from 'src/calibration/state';\nimport {\n  type CachedCalibration,\n  type CalibrationState,\n  type CalibrationStorePort,\n  type SealedCalibrationBody,\n} from 'src/calibration/types';\nimport { verifyCalibrationEnvelope } from 'src/calibration/verify';\n\n/**\n * The canonical bytes a cache entry's seal covers.\n *\n * Shared by the writer here and the reader in `scoring-run.ts` \u2014 one function,\n * so the two cannot disagree about what is inside the MAC. `canonicalise`\n * sorts keys recursively, which is what makes the tag survive the round trip\n * through the workspace's key-value store.\n */\nexport const sealedCalibrationBody = (\n  body: SealedCalibrationBody,\n): string | null =>\n  canonicalise({\n    cachedAt: body.cachedAt,\n    verifiedAt: body.verifiedAt,\n    keyId: body.keyId,\n    calibration: body.calibration,\n  });\n\nexport interface RefreshCalibrationInput {\n  readonly store: CalibrationStorePort;\n  /**\n   * Binds the cached copy to this workspace's licence key. Defaults to\n   * `NO_SEAL`, which cannot produce a tag \u2014 and an entry that cannot be sealed\n   * is not written at all, so the default is \"no cache\" rather than \"a cache\n   * nothing checks\".\n   */\n  readonly seal?: CalibrationSealPort;\n  /**\n   * `customerMetadata` from the live `validate` response, or `undefined` when\n   * the run had no live response at all \u2014 an outage, or no licence key.\n   */\n  readonly metadata: unknown;\n  /** Whether a live answer was received. `false` means \"do not touch the cache\". */\n  readonly live: boolean;\n  /** The resolved entitlement: `state.mode === 'full'`. */\n  readonly entitled: boolean;\n  readonly now: Date;\n}\n\nexport interface RefreshCalibrationOutcome {\n  readonly state: CalibrationState;\n  /** Non-null only when a fresh payload was verified and written this run. */\n  readonly written: CachedCalibration | null;\n  /** For the structured log line. Never contains payload content. */\n  readonly detail: string | null;\n}\n\n/**\n * Fetch-verify-cache, as one function with no exceptions and no clock read.\n *\n * ## Why an unentitled run clears the cache\n *\n * This is the one place the paid boundary is enforced, and it is enforced by\n * deletion rather than by a flag. The scoring path then needs no entitlement\n * check of its own: a cache that exists is a cache that was written while the\n * licence resolved to `full`. See `src/calibration/state.ts`, \"Why there is no\n * entitlement check here\", for why keeping a licence lookup out of the per-lead\n * path is worth a deletion.\n *\n * The cost is that a licence restored after a lapse waits one nightly cycle\n * before calibration returns. That is a day of shipped-default scoring \u2014 the\n * full working product \u2014 against the alternative of a workspace keeping a paid\n * vocabulary for three days after it stopped paying for it.\n *\n * ## Why a failed verification does *not* clear the cache\n *\n * A payload that arrives corrupted is evidence about *that response*, not about\n * the payload verified last night. Discarding a good cached calibration because\n * a proxy mangled one nightly response would let a single bad night undo a\n * working install. The bad payload is refused, the reason is published, and the\n * previously verified cache continues to age out on its own 72-hour clock \u2014 so\n * a genuinely revoked or permanently-broken calibration still expires, it just\n * does not vanish on the first hiccup.\n */\nexport const refreshCalibration = async (\n  input: RefreshCalibrationInput,\n): Promise<RefreshCalibrationOutcome> => {\n  if (!input.entitled) {\n    await clearQuietly(input.store);\n\n    const state = shippedDefaultsState('not_licensed', input.now);\n    await publish(input.store, state);\n\n    return { state, written: null, detail: null };\n  }\n\n  if (!input.live) {\n    // No live answer: nothing new to say about calibration, so republish what\n    // the cache currently amounts to. Publishing a *failure* here would report\n    // the outage twice \u2014 the licence state already says it \u2014 and would blank the\n    // version number the admin panel is showing.\n    //\n    // The state is derived through `resolveCalibration`, the same function the\n    // scoring path uses, rather than assembled here. That is the whole point:\n    // a cache past 72h is no longer applied to leads, and a panel that said\n    // \"calibration v1\" while the engine was quietly on shipped defaults would be\n    // worse than a panel that said nothing. One function, one answer.\n    const cached = await readQuietly(input.store);\n    const { state } = resolveCalibration({ cached, now: input.now });\n\n    await publish(input.store, state);\n\n    return { state, written: null, detail: null };\n  }\n\n  const read = readCalibrationEnvelope(input.metadata);\n\n  if (read.kind === 'rejected') {\n    const state = shippedDefaultsState(read.reason, input.now);\n    await publish(input.store, state);\n\n    return { state, written: null, detail: read.detail };\n  }\n\n  const verification = await verifyCalibrationEnvelope(read.envelope);\n\n  if (verification.kind === 'rejected') {\n    const state = shippedDefaultsState(verification.reason, input.now);\n    await publish(input.store, state);\n\n    return { state, written: null, detail: verification.detail };\n  }\n\n  const body: SealedCalibrationBody = {\n    cachedAt: input.now.toISOString(),\n    verifiedAt: input.now.toISOString(),\n    keyId: read.envelope.keyId,\n    calibration: verification.calibration,\n  };\n\n  const canonical = sealedCalibrationBody(body);\n  const sealTag =\n    canonical === null ? null : await (input.seal ?? NO_SEAL).seal(canonical);\n\n  // No tag, no cache. Writing an unsealed entry would mean a subsequent read\n  // either has to accept it \u2014 defeating the seal entirely \u2014 or reject it, which\n  // is what happens anyway. Not writing is the same outcome with one fewer\n  // shape in the store.\n  if (sealTag === null) {\n    const state = shippedDefaultsState('cache_unsealed', input.now);\n    await publish(input.store, state);\n\n    return {\n      state,\n      written: null,\n      detail: 'calibration verified but could not be sealed to this licence key',\n    };\n  }\n\n  const entry: CachedCalibration = { ...body, sealTag };\n\n  await writeQuietly(input.store, entry);\n\n  const state = calibratedState(entry, 'live', 0, input.now);\n  await publish(input.store, state);\n\n  return {\n    state,\n    written: entry,\n    detail: `calibration v${verification.calibration.calibrationVersion} verified against ${read.envelope.keyId}`,\n  };\n};\n\n/**\n * A count summary safe to put in a log line.\n *\n * The payload itself is never logged: it is a few hundred kilobytes of word\n * lists, and a nightly cron that dumps it into the platform's log stream would\n * be indistinguishable from a bug.\n */\nexport const describeCalibration = (\n  outcome: RefreshCalibrationOutcome,\n): Record<string, unknown> => ({\n  calibrationStatus: outcome.state.status,\n  calibrationReason: outcome.state.reason,\n  calibrationSource: outcome.state.source,\n  calibrationVersion: outcome.state.calibrationVersion,\n  calibrationKeyId: outcome.state.keyId,\n  calibrationRefreshedAt: outcome.state.refreshedAt,\n  ...(outcome.written === null\n    ? {}\n    : { calibrationCounts: countCalibration(outcome.written.calibration) }),\n  ...(outcome.detail === null ? {} : { calibrationDetail: outcome.detail }),\n});\n\n/* -------------------------------------------------------------------------- */\n/* Storage, swallowed                                                          */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Storage failures are absorbed here rather than at the adapter, so that a\n * *test double* that throws is handled identically to the real store, which\n * logs and returns. A calibration cache is a convenience; failing a licence run\n * over one would be trading the load-bearing thing for the optional one.\n */\nconst readQuietly = async (\n  store: CalibrationStorePort,\n): Promise<CachedCalibration | null> => {\n  try {\n    return await store.readCalibration();\n  } catch {\n    return null;\n  }\n};\n\nconst writeQuietly = async (\n  store: CalibrationStorePort,\n  entry: CachedCalibration,\n): Promise<void> => {\n  try {\n    await store.writeCalibration(entry);\n  } catch {\n    // Swallowed: the state published below still says what was verified, and\n    // the next run re-verifies from the same source.\n  }\n};\n\n/**\n * A clear that fails leaves a workspace calibrated for up to another 72 hours,\n * after which the age check in `resolveCalibration` retires it regardless. So\n * the failure is bounded by the freshness ladder rather than open-ended, and\n * failing the licence run over it would trade a bounded problem for an\n * unbounded one.\n */\nconst clearQuietly = async (store: CalibrationStorePort): Promise<void> => {\n  try {\n    await store.clearCalibration();\n  } catch {\n    // Swallowed. See above.\n  }\n};\n\nconst publish = async (\n  store: CalibrationStorePort,\n  state: CalibrationState,\n): Promise<void> => {\n  try {\n    await store.publishCalibrationState(state);\n  } catch {\n    // Swallowed for the same reason. The admin panel shows a stale state for a\n    // night; nothing about scoring changes.\n  }\n};\n", "/**\n * Numaya Greenlight \u2014 the decision half of the human override.\n *\n * Everything in this file is pure: no SDK import, no network, no clock read.\n * The logic function is a thin shell that fetches state, calls `decideRelease`,\n * and executes whatever it is told. That split exists because the override is\n * the GDPR Art. 22 load-bearing part of the product \u2014 the rules about what may\n * and may not be released have to be exhaustively testable without a live\n * Twenty workspace.\n *\n * Naming note: the engine's four decision states (`approved` / `gated` /\n * `blocked` / `unscored`, see `src/scoring/types.ts`) now map one-to-one onto\n * the `greenlightDecision` SELECT field on Person, which ships four options\n * (`PASS` / `GATE` / `BLOCKED` / `UNSCORED`). A compliance stop is therefore\n * readable straight off the field. Records scored before the `BLOCKED` option\n * existed still read `GATE`, so `isComplianceBlocked` survives as a fallback \u2014\n * see the comment on `blockedFromLead` for exactly when each one answers.\n */\n\n/* -------------------------------------------------------------------------- */\n/* The compliance question                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Whether a lead that the engine marked `blocked` may be released by a human.\n *\n * **True \u2014 product decision, 2026-08-02.** The opt-out register is maintained by\n * the sales team inside Twenty, and the business trusts the person maintaining\n * it to also be the person who corrects it. An earlier iteration refused this\n * and required the contact to re-consent by email; that was withdrawn, because\n * Twenty sends no email and building an outbound provider to gate a correction\n * the sales team is trusted to make anyway is disproportionate.\n *\n * What this restores: the golden rule in `ARCHITECTURE.md` and the promise in\n * `PRODUCT_SPEC.md` that a human can always release a held lead, with no\n * exception carved out for compliance.\n *\n * What it costs, stated plainly rather than buried:\n *\n *   1. A released compliance block leaves the record in a **contradictory\n *      state** \u2014 `greenlightDecision` says the lead is cleared while the\n *      suppression fields still say do-not-contact. The audit row is the only\n *      thing that explains it. Prefer clearing the suppression itself (\"Allow\n *      contact again\") when the block was recorded in error: that re-scores the\n *      lead and clears the gate through the data, which reads far better in a\n *      DPA conversation than an override sitting on top of a live opt-out.\n *   2. Under GDPR Art. 21(3) an objection to direct marketing is absolute, and\n *      \"a salesperson approved it\" is not a lawful basis on its own. This\n *      setting assumes the release reflects a real-world correction \u2014 the\n *      contact never opted out, or asked to be added back \u2014 not a decision to\n *      market to someone who said stop. That assumption is the customer's to\n *      hold, and every release is audited with who, when and why so it can be\n *      evidenced.\n *\n * Setting this back to `false` re-refuses compliance releases; the refusal\n * branch and its tests are the only readers.\n */\nexport const ALLOW_COMPLIANCE_OVERRIDE = true;\n\n/* -------------------------------------------------------------------------- */\n/* Reasons                                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The override reason is a **mandatory choice from a closed list**, plus an\n * optional free-text note.\n *\n * `ARCHITECTURE.md` leaves this as \"reason/none\". Neither extreme works:\n *\n *   - Optional reason. The whole Art. 22 argument is that a human applied\n *     judgement. An override with no recorded reason is indistinguishable in\n *     the audit trail from an automated release, so it evidences nothing.\n *\n *   - Mandatory free text. A required text box gets \"ok\" typed into it, which\n *     is worse than nothing: it manufactures the appearance of a reasoned\n *     decision without the substance, and it is unanalysable in aggregate. It\n *     is also a data-protection liability in its own right \u2014 an uncontrolled\n *     free-text field on an append-only log that nobody ever deletes is exactly\n *     where a rep eventually types something that should never have been\n *     recorded about a person.\n *\n * A required pick from five categories is a real judgement, cheap to make,\n * impossible to fake into meaninglessness, and analysable: 200 releases tagged\n * `ICP_TOO_NARROW` are not 200 judgement calls, they are one misconfigured ICP,\n * and the queue can say so. The optional note carries the specifics when there\n * are any.\n */\nexport const RELEASE_REASONS = [\n  {\n    code: 'ICP_TOO_NARROW',\n    label: 'Scoring rules are too narrow for this lead',\n    hint: 'The lead is fine; the ICP or rule configuration is what is wrong.',\n  },\n  {\n    code: 'DATA_INCOMPLETE',\n    label: 'Lead data is incomplete but I know this is a good lead',\n    hint: 'Missing fields dragged the score down. You have the context the record does not.',\n  },\n  {\n    code: 'KNOWN_ACCOUNT',\n    label: 'Existing relationship or inbound request',\n    hint: 'They asked us to get in touch, or there is a live thread already.',\n  },\n  {\n    code: 'STRATEGIC_EXCEPTION',\n    label: 'Deliberate exception I am accounting for',\n    hint: 'The gate is right and you are overriding it anyway, on purpose.',\n  },\n  {\n    code: 'TESTING',\n    label: 'Testing Greenlight',\n    hint: 'Keeps test releases out of the real override statistics.',\n  },\n] as const;\n\nexport type ReleaseReasonCode = (typeof RELEASE_REASONS)[number]['code'];\n\nexport const RELEASE_REASON_CODES: readonly ReleaseReasonCode[] =\n  RELEASE_REASONS.map((reason) => reason.code);\n\n/** Free-text notes are capped: an audit field is not a place to write an essay. */\nexport const MAX_REASON_NOTE_LENGTH = 500;\n\nconst findReason = (code: string) =>\n  RELEASE_REASONS.find((reason) => reason.code === code) ?? null;\n\n/* -------------------------------------------------------------------------- */\n/* Requests                                                                    */\n/* -------------------------------------------------------------------------- */\n\nexport interface ReleaseRequest {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly reasonCode: ReleaseReasonCode;\n  /** Empty string when the reviewer did not add one. */\n  readonly reasonNote: string;\n}\n\nexport type ParseResult =\n  | { readonly ok: true; readonly request: ReleaseRequest }\n  | { readonly ok: false; readonly message: string };\n\nconst UUID = /^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;\n\n/**\n * v0.1 physically ships the score fields on Person only (`defineField` binds at\n * build time \u2014 see `greenlight-score.field.ts`). Accepting any other object name\n * would mean writing `greenlightDecision` to an object that does not have it.\n * The parameter exists so the Layer 3 seam is visible in the wire format, not\n * because it is configurable yet.\n */\nexport const SUPPORTED_LEAD_OBJECTS: readonly string[] = ['person'];\n\nconst asString = (value: unknown): string | null =>\n  typeof value === 'string' ? value : null;\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\nexport const parseReleaseRequest = (body: unknown): ParseResult => {\n  if (typeof body !== 'object' || body === null || Array.isArray(body)) {\n    return { ok: false, message: 'Release request body must be an object.' };\n  }\n\n  const raw = body as Record<string, unknown>;\n\n  const recordId = asString(raw['recordId'])?.trim() ?? '';\n\n  if (!UUID.test(recordId)) {\n    return { ok: false, message: 'Release request needs a valid recordId.' };\n  }\n\n  const leadObjectNameSingular =\n    asString(raw['leadObjectNameSingular'])?.trim() || 'person';\n\n  if (!SUPPORTED_LEAD_OBJECTS.includes(leadObjectNameSingular)) {\n    return {\n      ok: false,\n      message: `Greenlight v0.1 can only release leads on ${SUPPORTED_LEAD_OBJECTS.join(', ')}, not ${leadObjectNameSingular}.`,\n    };\n  }\n\n  const reasonCode = asString(raw['reasonCode'])?.trim() ?? '';\n  const reason = findReason(reasonCode);\n\n  if (reason === null) {\n    return {\n      ok: false,\n      message:\n        'Choose why you are releasing this lead. A recorded reason is what makes the override a human decision rather than an automated one.',\n    };\n  }\n\n  const reasonNote = (asString(raw['reasonNote']) ?? '')\n    .trim()\n    .slice(0, MAX_REASON_NOTE_LENGTH);\n\n  return {\n    ok: true,\n    request: {\n      leadObjectNameSingular,\n      recordId,\n      reasonCode: reason.code,\n      reasonNote,\n    },\n  };\n};\n\n/** The audit-trail rendering of a reason: machine code first, prose after. */\nexport const formatOverrideReason = (\n  reasonCode: ReleaseReasonCode,\n  reasonNote: string,\n): string => {\n  const reason = findReason(reasonCode);\n  const label = reason === null ? reasonCode : `${reason.code} \u00B7 ${reason.label}`;\n\n  return reasonNote === '' ? label : `${label} \u2014 ${reasonNote}`;\n};\n\n/* -------------------------------------------------------------------------- */\n/* Current state of the lead                                                   */\n/* -------------------------------------------------------------------------- */\n\n/** Values of the `greenlightDecision` SELECT on Person. */\nexport const DECISION_PASS = 'PASS';\nexport const DECISION_GATE = 'GATE';\nexport const DECISION_BLOCKED = 'BLOCKED';\nexport const DECISION_UNSCORED = 'UNSCORED';\n\nconst KNOWN_DECISIONS: readonly string[] = [\n  DECISION_PASS,\n  DECISION_GATE,\n  DECISION_BLOCKED,\n  DECISION_UNSCORED,\n];\n\n/** `greenlightDecision` as stored, normalised. Null when it is not a value we ship. */\nexport const normaliseDecision = (raw: string | null): string | null => {\n  const value = raw?.trim().toUpperCase() ?? '';\n\n  return KNOWN_DECISIONS.includes(value) ? value : null;\n};\n\n/**\n * The decision an audit row should record as the state the lead was left in.\n *\n * A refused release leaves the lead exactly where it was, and \"where it was\"\n * is now a distinction worth keeping: a refusal against a `BLOCKED` record and\n * a refusal against a `GATE` record are different compliance stories. Anything\n * unrecognised degrades to `GATE` rather than being written through, because\n * this value goes into a SELECT that would reject an unknown option and lose\n * the row.\n */\nexport const auditDecisionValue = (\n  currentDecision: string | null,\n  shouldClearGate: boolean,\n): string =>\n  shouldClearGate\n    ? DECISION_PASS\n    : (normaliseDecision(currentDecision) ?? DECISION_GATE);\n\n/** Values of the `band` SELECT on GreenlightAuditLog. */\nexport const BAND_UNSCORED = 'UNSCORED';\n\nconst KNOWN_BANDS: readonly string[] = [\n  'EXCELLENT',\n  'GOOD',\n  'FAIR',\n  'POOR',\n  BAND_UNSCORED,\n];\n\n/**\n * The band an override's audit row should record.\n *\n * The release path used to write no band at all, so every `RELEASED` row took\n * the field's `UNSCORED` default while the `GATED` row for the same lead read\n * `POOR`. Two contradictory bands for one lead is not a compliance record, it is\n * a bug with a paper trail \u2014 a reviewer comparing the two rows cannot tell which\n * one is lying.\n *\n * The band is **read out of the trace the scoring run left on the record**, not\n * recomputed here. The engine's bands are configurable (`bandExcellentThreshold`\n * and friends on GreenlightConfig), so deriving a band from the score with the\n * shipped defaults would produce a *different* wrong answer in any workspace\n * that moved a threshold \u2014 and it would disagree with the `GATED` row all over\n * again. The trace carries the band that run actually chose, which is the only\n * value that can agree with the earlier row by construction.\n *\n * `UNSCORED` remains the answer when the trace is missing or unreadable, but it\n * now means what the option says: nothing here knows the band. That is the state\n * of a lead released before it was ever scored, which the queue does allow.\n */\nexport const auditBandValue = (trace: unknown): string => {\n  if (!isRecord(trace)) {\n    return BAND_UNSCORED;\n  }\n\n  const value = asString(trace['band'])?.trim().toUpperCase() ?? '';\n\n  return KNOWN_BANDS.includes(value) ? value : BAND_UNSCORED;\n};\n\nexport interface CurrentLeadState {\n  readonly recordId: string;\n  /** Denormalised into the audit row so the trail survives the record. */\n  readonly displayName: string;\n  /** Raw `greenlightDecision`. Null when the lead has never been scored. */\n  readonly decision: string | null;\n  readonly score: number | null;\n  /** Raw `greenlightTrace`, whatever shape the engine wrote. */\n  readonly trace: unknown;\n}\n\n/**\n * A human release, recorded outside the record so the scoring function can see\n * it. Written to app key-value storage by the override; see the contract note\n * on `RELEASE_MARKER_SCOPE` below.\n */\nexport interface ReleaseMarker {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  /** ISO 8601. */\n  readonly releasedAt: string;\n  readonly releasedBy: string;\n  readonly reasonCode: string;\n}\n\nexport const releaseMarkerKey = (\n  leadObjectNameSingular: string,\n  recordId: string,\n): string => `greenlight:release:${leadObjectNameSingular}:${recordId}`;\n\n/**\n * Two releases of the same lead inside this window are the same release \u2014 a\n * double-click, or Twenty re-delivering the request. Mirrors the 5s event\n * de-duplication window ARCHITECTURE.md \u00A7 \"Idempotency & Retry Safety\" already\n * assumes, with headroom for a slow round trip.\n *\n * This is a *narrow race* guard only. The authoritative double-release check is\n * the decision field itself: if the lead already reads PASS it is not held, so\n * there is nothing to release, whatever the marker says. The marker can be\n * stale \u2014 a lead released on Monday and legitimately re-gated on Tuesday after\n * its email was deleted must be releasable again on Tuesday.\n */\nexport const DUPLICATE_RELEASE_WINDOW_MS = 10_000;\n\n/* -------------------------------------------------------------------------- */\n/* Compliance block detection                                                  */\n/* -------------------------------------------------------------------------- */\n\nconst entryIsBlocking = (entry: unknown): boolean => {\n  if (!isRecord(entry)) {\n    return false;\n  }\n\n  const severity = asString(entry['severity'])?.toLowerCase() ?? '';\n  const outcome = asString(entry['outcome'])?.toLowerCase() ?? '';\n\n  return severity === 'blocking' && outcome === 'fail';\n};\n\nconst traceEntries = (trace: unknown): readonly unknown[] => {\n  if (Array.isArray(trace)) {\n    return trace;\n  }\n\n  if (!isRecord(trace)) {\n    return [];\n  }\n\n  for (const key of ['rules', 'trace', 'entries']) {\n    const candidate = trace[key];\n\n    if (Array.isArray(candidate)) {\n      return candidate;\n    }\n  }\n\n  return [];\n};\n\n/**\n * Recover the engine's `blocked` state from the trace.\n *\n * **This is the legacy path.** `greenlightDecision` now ships a `BLOCKED`\n * option, so a lead scored by any current build states its compliance stop on\n * the field itself and never reaches this function. It is kept because nothing\n * backfills a SELECT option: every lead scored before the option existed still\n * reads `GATE`, and reading the trace is the only way to tell those apart. See\n * `blockedFromLead`.\n *\n * **It is the one place the queue depends on a shape the scoring function\n * writes, and it is deliberately forgiving about that shape**, because the trace\n * field's exact envelope is not pinned down anywhere in the spec. Accepted, in\n * order:\n *\n *   - a top-level `decision` of `blocked` (any case) on the trace object;\n *   - an array of rule-trace entries, or `{ rules: [...] }` / `{ trace: [...] }`\n *     / `{ entries: [...] }`, containing an entry with\n *     `severity: 'blocking'` and `outcome: 'fail'` \u2014 the exact discriminator\n *     `src/scoring/engine.ts` itself uses to choose `blocked`.\n *\n * If the trace is missing or unreadable the answer is `false`: an unreadable\n * trace must not silently turn every held lead into an unreleasable one. That\n * is the fail-open direction for *this* check, and it is the right one \u2014 the\n * compliance rule that produced the block also wrote an audit row, and a lead\n * whose trace we cannot read is a lead we cannot claim anything about.\n */\nexport const isComplianceBlocked = (trace: unknown): boolean => {\n  if (isRecord(trace)) {\n    const declared = asString(trace['decision'])?.toLowerCase() ?? '';\n\n    if (declared === 'blocked') {\n      return true;\n    }\n  }\n\n  return traceEntries(trace).some(entryIsBlocking);\n};\n\n/**\n * Is this lead held on compliance grounds?\n *\n * Field first, trace second, and the order is the whole point:\n *\n *   - **The field** is the current, cheap, unambiguous answer for anything\n *     scored since `BLOCKED` shipped. One string comparison, no assumptions\n *     about a RAW_JSON envelope.\n *   - **The trace** answers for records scored before that, which still read\n *     `GATE` because adding a SELECT option does not rewrite existing rows.\n *     Dropping this fallback would quietly make every historic opt-out\n *     releasable by hand on the day the option was added \u2014 the exact failure the\n *     compliance refusal exists to prevent. It can go once a workspace has\n *     re-scored every lead, which is not something this code can know.\n */\nconst blockedFromLead = (lead: CurrentLeadState): boolean =>\n  normaliseDecision(lead.decision) === DECISION_BLOCKED ||\n  isComplianceBlocked(lead.trace);\n\n/* -------------------------------------------------------------------------- */\n/* The decision                                                                */\n/* -------------------------------------------------------------------------- */\n\nexport type ReleaseOutcome =\n  /** The gate was cleared and an audit row must be written. */\n  | 'released'\n  /** Already `PASS`. Not an error \u2014 the rep got what they wanted. */\n  | 'already_released'\n  /** `UNSCORED`: the engine failed open, the lead was never held. */\n  | 'not_held'\n  /** No decision at all: never scored, so never gated. */\n  | 'not_scored'\n  /** A second request inside the de-duplication window. */\n  | 'duplicate_request'\n  /** Compliance stop. See `ALLOW_COMPLIANCE_OVERRIDE`. */\n  | 'refused_compliance_block';\n\nexport interface ReleaseDecision {\n  readonly outcome: ReleaseOutcome;\n  /** Shown to the reviewer. Written for a salesperson, not a developer. */\n  readonly message: string;\n  /** Whether `greenlightDecision` must be written to `PASS`. */\n  readonly shouldClearGate: boolean;\n  /** Whether a `GreenlightAuditLog` row must be appended. */\n  readonly shouldWriteAuditRow: boolean;\n  /** `RELEASED` for a real release, `SKIPPED` for a recorded refusal. */\n  readonly auditEventType: 'RELEASED' | 'SKIPPED' | null;\n  /** Rendered reason for the audit row. Empty when no row is written. */\n  readonly overrideReason: string;\n  /** Whether the release marker must be written for the scoring function. */\n  readonly shouldWriteMarker: boolean;\n}\n\nexport interface DecideReleaseInput {\n  readonly request: ReleaseRequest;\n  readonly lead: CurrentLeadState;\n  /** Previous release of this lead, if app storage had one. */\n  readonly marker: ReleaseMarker | null;\n  /** The clock, passed in \u2014 this module never reads it. */\n  readonly now: Date;\n}\n\nconst noop = (\n  outcome: ReleaseOutcome,\n  message: string,\n): ReleaseDecision => ({\n  outcome,\n  message,\n  shouldClearGate: false,\n  shouldWriteAuditRow: false,\n  auditEventType: null,\n  overrideReason: '',\n  shouldWriteMarker: false,\n});\n\nconst isWithinDuplicateWindow = (\n  marker: ReleaseMarker | null,\n  now: Date,\n): boolean => {\n  if (marker === null) {\n    return false;\n  }\n\n  const releasedAt = Date.parse(marker.releasedAt);\n\n  if (Number.isNaN(releasedAt)) {\n    return false;\n  }\n\n  const elapsed = now.getTime() - releasedAt;\n\n  return elapsed >= 0 && elapsed < DUPLICATE_RELEASE_WINDOW_MS;\n};\n\n/**\n * Decide what the override should do. Never throws.\n *\n * Order matters and is not arbitrary:\n *\n *   1. **Not held** beats everything. If the gate is already open there is\n *      nothing to release, so we neither write the record nor append an audit\n *      row \u2014 a rep double-clicking must not manufacture history. This is the\n *      \"safe against releasing something already approved\" guarantee, and it is\n *      checked against the record's own field rather than against any cached\n *      marker, because the field is the only authoritative statement of whether\n *      the lead is held right now.\n *   2. **Compliance** beats the reviewer. Read from `greenlightDecision` when it\n *      says `BLOCKED`, and from the trace otherwise so pre-`BLOCKED` records\n *      still refuse (`blockedFromLead`). Checked before the duplicate window so\n *      that every attempt against a blocked lead is recorded, including repeat\n *      attempts \u2014 repeated attempts to release an opt-out are exactly the\n *      pattern a DPO would want to see.\n *   3. **Duplicate window** catches the narrow double-submit race that the\n *      field check cannot see, because both requests read `GATE` before either\n *      wrote `PASS`.\n */\nexport const decideRelease = (input: DecideReleaseInput): ReleaseDecision => {\n  const { request, lead, marker, now } = input;\n\n  const decision = lead.decision?.trim().toUpperCase() ?? null;\n\n  if (decision === null || decision === '') {\n    return noop(\n      'not_scored',\n      'This lead has no Greenlight decision yet, so it is not being held. Nothing to release.',\n    );\n  }\n\n  if (decision === DECISION_PASS) {\n    return noop(\n      'already_released',\n      'This lead has already cleared the gate. No change made, and no second audit entry written.',\n    );\n  }\n\n  if (decision === DECISION_UNSCORED) {\n    return noop(\n      'not_held',\n      'Greenlight could not score this lead, so it was let through unscored rather than held. There is no gate to clear.',\n    );\n  }\n\n  if (decision !== DECISION_GATE && decision !== DECISION_BLOCKED) {\n    return noop(\n      'not_held',\n      `This lead is in an unrecognised Greenlight state (${decision}), so the override left it alone.`,\n    );\n  }\n\n  const blocked = blockedFromLead(lead);\n\n  if (blocked && !ALLOW_COMPLIANCE_OVERRIDE) {\n    return {\n      outcome: 'refused_compliance_block',\n      message:\n        'This lead is held on compliance grounds \u2014 the record carries a recorded opt-out. That is the contact\\'s own instruction, not a scoring judgement, so it cannot be overridden here. Correct the opt-out data on the record if it is wrong; the lead will re-score and clear itself.',\n      shouldClearGate: false,\n      // The refusal *is* recorded. An attempt to release an opted-out contact\n      // is a compliance-relevant human action even though nothing changed.\n      shouldWriteAuditRow: true,\n      auditEventType: 'SKIPPED',\n      overrideReason: `REFUSED_COMPLIANCE_BLOCK \u2014 release attempted with reason ${formatOverrideReason(\n        request.reasonCode,\n        request.reasonNote,\n      )}`,\n      shouldWriteMarker: false,\n    };\n  }\n\n  if (isWithinDuplicateWindow(marker, now)) {\n    return noop(\n      'duplicate_request',\n      'This lead was released moments ago. Treating this as a duplicate submission and leaving the audit trail alone.',\n    );\n  }\n\n  return {\n    outcome: 'released',\n    message: 'Released. The lead is cleared to work and the override is on record.',\n    shouldClearGate: true,\n    shouldWriteAuditRow: true,\n    auditEventType: 'RELEASED',\n    overrideReason: formatOverrideReason(request.reasonCode, request.reasonNote),\n    shouldWriteMarker: true,\n  };\n};\n\n/** One-line summary used as the audit row's record label. */\nexport const buildAuditSummary = (\n  eventType: 'RELEASED' | 'SKIPPED',\n  lead: CurrentLeadState,\n): string => {\n  const name = lead.displayName.trim() === '' ? 'Unnamed lead' : lead.displayName;\n  const score = lead.score === null ? 'unscored' : String(lead.score);\n\n  return `${eventType} \u00B7 ${name} \u00B7 ${score}`;\n};\n", "/**\n * Numaya Greenlight \u2014 the decision half of the suppression / block list.\n *\n * Everything in this file is pure: no SDK import, no network, no clock read.\n * The two logic functions are thin shells that fetch state, call `decideSuppress`\n * or `decideUnsuppress`, and execute whatever they are told. Same split, and the\n * same reason, as `src/gate/release-decision.ts`: this is the part a regulator\n * would read, so it has to be exhaustively testable without a live workspace.\n *\n * ## Why Greenlight owns this data at all\n *\n * Twenty does no email management. There is no unsubscribe handling, no bounce\n * tracking and no do-not-contact list anywhere in the product. Greenlight's\n * compliance rule used to read an opt-out flag purely through the customer's\n * Layer 3 field mapping (`optOutFieldNames`), and on a stock workspace that\n * mapping resolves to nothing at all \u2014 so the rule returned `pass`, awarded its\n * full 15 points, and could never once fire. The one compliance check in the\n * product was decorative on a default install.\n *\n * The four `greenlightSuppress*` fields on Person are the fix. They are the\n * register Twenty does not have, they are Greenlight's own, and \u2014 unlike the\n * score fields \u2014 they are UI-editable, because they are human-maintained data\n * rather than engine output.\n *\n * ## Union, not override\n *\n * A customer who already has an opt-out column keeps it working. The compliance\n * rule reads Greenlight's field *and* the customer's mapping and any source\n * saying \"suppressed\" wins. Nothing in this file assumes Greenlight's field is\n * the only one; it is only the only one Greenlight can write.\n */\n\n/* -------------------------------------------------------------------------- */\n/* The Person fields this feature owns                                         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The suppression columns on the lead-bearing object.\n *\n * Declared here rather than in `scoring-run.ts` because both the scoring side\n * (which must re-score when they change) and the two action logic functions\n * (which write them) need the same strings, and a drift between the two is an\n * infinite loop or a silently ignored block, neither of which shows up in a\n * type error.\n */\nexport const SUPPRESSION_FIELD_SUPPRESSED = 'greenlightSuppressed';\nexport const SUPPRESSION_FIELD_REASON = 'greenlightSuppressionReason';\nexport const SUPPRESSION_FIELD_SUPPRESSED_AT = 'greenlightSuppressedAt';\nexport const SUPPRESSION_FIELD_NOTE = 'greenlightSuppressionNote';\n\nexport const SUPPRESSION_PERSON_FIELDS: readonly string[] = [\n  SUPPRESSION_FIELD_SUPPRESSED,\n  SUPPRESSION_FIELD_REASON,\n  SUPPRESSION_FIELD_SUPPRESSED_AT,\n  SUPPRESSION_FIELD_NOTE,\n];\n\n/**\n * The subset whose change can move the score, i.e. the ones the re-score trigger\n * listens on.\n *\n * `greenlightSuppressedAt` and `greenlightSuppressionNote` are excluded: neither\n * is read by any rule, both are always written in the same mutation as the flag,\n * and every name on a trigger allow-list is another chance for a write loop.\n */\nexport const SUPPRESSION_SCORING_INPUT_FIELDS: readonly string[] = [\n  SUPPRESSION_FIELD_SUPPRESSED,\n  SUPPRESSION_FIELD_REASON,\n];\n\n/* -------------------------------------------------------------------------- */\n/* Why someone is suppressed                                                   */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The closed list of suppression reasons.\n *\n * Closed rather than free text for the same reason the release override's reason\n * list is closed (see `release-decision.ts`), plus one this list has and that one\n * does not: these categories carry different *legal* weight. \"Unsubscribed\" and\n * \"legal or erasure request\" are both do-not-contact, but only one of them\n * survives a change of marketing platform, and only one of them makes lifting the\n * suppression a decision somebody senior should be making. A free-text column\n * cannot be filtered, counted or escalated on.\n *\n * The list is deliberately the union of the three sources of suppression a\n * mailing operation actually has \u2014 the contact's own instruction (unsubscribed,\n * spam complaint, legal request), the mail system's verdict (hard bounce), and a\n * human's or an import's judgement (manual block, imported do-not-contact list).\n *\n * Appending to this list is safe: SELECT option identity derives from the option\n * `value`, not from `position`. Editing or removing a `code` is not.\n */\nexport const SUPPRESSION_REASONS = [\n  {\n    code: 'UNSUBSCRIBED',\n    label: 'Unsubscribed',\n    hint: 'They used an unsubscribe link, replied STOP, or asked a rep to stop emailing them.',\n  },\n  {\n    code: 'HARD_BOUNCE',\n    label: 'Hard bounce',\n    hint: 'The mailbox does not exist. Sending again damages the sending domain.',\n  },\n  {\n    code: 'SPAM_COMPLAINT',\n    label: 'Spam complaint',\n    hint: 'They reported a message as spam. The most expensive signal on this list.',\n  },\n  {\n    code: 'MANUAL_BLOCK',\n    label: 'Manual block',\n    hint: 'A person decided not to contact this record. Say why in the note.',\n  },\n  {\n    code: 'LEGAL_REQUEST',\n    label: 'Legal or erasure request',\n    hint: 'A GDPR erasure or objection request, or anything counsel has told us to honour.',\n  },\n  {\n    code: 'IMPORTED_DNC',\n    label: 'Imported do-not-contact list',\n    hint: 'Came in on a suppression file \u2014 a previous CRM, a partner list, a TPS-style register.',\n  },\n] as const;\n\nexport type SuppressionReasonCode = (typeof SUPPRESSION_REASONS)[number]['code'];\n\nexport const SUPPRESSION_REASON_CODES: readonly SuppressionReasonCode[] =\n  SUPPRESSION_REASONS.map((reason) => reason.code);\n\nconst findSuppressionReason = (code: string) =>\n  SUPPRESSION_REASONS.find((reason) => reason.code === code) ?? null;\n\nexport const suppressionReasonLabel = (code: string | null): string => {\n  if (code === null || code.trim() === '') {\n    return 'no reason recorded';\n  }\n\n  return findSuppressionReason(code.trim().toUpperCase())?.label ?? code.trim();\n};\n\n/* -------------------------------------------------------------------------- */\n/* Why a suppression is being lifted                                           */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The closed list of *removal* reasons \u2014 a separate vocabulary on purpose.\n *\n * Removing a suppression re-enables contact with somebody who is on record\n * asking not to be contacted. There is no reason on the list above that is also\n * a good reason to undo it, so sharing one list would let a rep lift a spam\n * complaint by picking \"spam complaint\", which reads in the audit trail as\n * nonsense a year later.\n *\n * Every entry here is a claim that the *suppression itself* was wrong or has\n * been superseded. That is the only honest ground for removal.\n */\nexport const UNSUPPRESSION_REASONS = [\n  {\n    code: 'RECORDED_IN_ERROR',\n    label: 'The suppression was recorded in error',\n    hint: 'Nobody asked us to stop; the flag was set by mistake or by a bad import.',\n  },\n  {\n    code: 'CONSENT_RENEWED',\n    label: 'They have opted back in',\n    hint: 'They asked to start hearing from us again. Say where that is evidenced.',\n  },\n  {\n    code: 'WRONG_PERSON',\n    label: 'It was applied to the wrong record',\n    hint: 'A duplicate or a namesake was suppressed instead of the person who asked.',\n  },\n  {\n    code: 'BOUNCE_RESOLVED',\n    label: 'The bounce was a mail-server fault and is fixed',\n    hint: 'Only for hard bounces. Never for an unsubscribe or a complaint.',\n  },\n  {\n    code: 'TESTING',\n    label: 'Testing Greenlight',\n    hint: 'Keeps test removals out of the real compliance statistics.',\n  },\n] as const;\n\nexport type UnsuppressionReasonCode =\n  (typeof UNSUPPRESSION_REASONS)[number]['code'];\n\nexport const UNSUPPRESSION_REASON_CODES: readonly UnsuppressionReasonCode[] =\n  UNSUPPRESSION_REASONS.map((reason) => reason.code);\n\nconst findUnsuppressionReason = (code: string) =>\n  UNSUPPRESSION_REASONS.find((reason) => reason.code === code) ?? null;\n\n/* -------------------------------------------------------------------------- */\n/* Notes                                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport const MAX_SUPPRESSION_NOTE_LENGTH = 500;\n\n/**\n * A removal note is **mandatory**, and a suppression note is not.\n *\n * This is the opposite of the release override's policy, and deliberately so.\n * The argument against mandatory free text is that a high-frequency action\n * collects the word \"ok\"; releasing a gated lead is a daily action and the\n * closed reason list carries the meaning. Lifting a do-not-contact entry is\n * rare, individually consequential, and the one thing a DPO will ask to see the\n * working for. Friction is the point.\n */\nexport const MIN_UNSUPPRESSION_NOTE_LENGTH = 10;\n\n/* -------------------------------------------------------------------------- */\n/* Requests                                                                    */\n/* -------------------------------------------------------------------------- */\n\n/** Mirrors `SUPPORTED_LEAD_OBJECTS` in `release-decision.ts`, and for the same reason. */\nexport const SUPPRESSION_SUPPORTED_LEAD_OBJECTS: readonly string[] = ['person'];\n\nconst UUID =\n  /^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;\n\nconst asString = (value: unknown): string | null =>\n  typeof value === 'string' ? value : null;\n\nexport interface SuppressRequest {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly reasonCode: SuppressionReasonCode;\n  /** Empty string when nothing was added. */\n  readonly note: string;\n}\n\nexport interface UnsuppressRequest {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly reasonCode: UnsuppressionReasonCode;\n  /** Never empty \u2014 see `MIN_UNSUPPRESSION_NOTE_LENGTH`. */\n  readonly note: string;\n  /** The reviewer ticked \"I understand this re-enables contact\". */\n  readonly acknowledged: true;\n}\n\nexport type ParseResult<T> =\n  | { readonly ok: true; readonly request: T }\n  | { readonly ok: false; readonly message: string };\n\ninterface CommonFields {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly note: string;\n}\n\nconst parseCommon = (body: unknown): ParseResult<CommonFields> => {\n  if (typeof body !== 'object' || body === null || Array.isArray(body)) {\n    return { ok: false, message: 'Request body must be an object.' };\n  }\n\n  const raw = body as Record<string, unknown>;\n  const recordId = asString(raw['recordId'])?.trim() ?? '';\n\n  if (!UUID.test(recordId)) {\n    return { ok: false, message: 'This request needs a valid recordId.' };\n  }\n\n  const leadObjectNameSingular =\n    asString(raw['leadObjectNameSingular'])?.trim() || 'person';\n\n  if (!SUPPRESSION_SUPPORTED_LEAD_OBJECTS.includes(leadObjectNameSingular)) {\n    return {\n      ok: false,\n      message: `Greenlight v0.1 keeps its block list on ${SUPPRESSION_SUPPORTED_LEAD_OBJECTS.join(\n        ', ',\n      )}, not ${leadObjectNameSingular}.`,\n    };\n  }\n\n  const note = (asString(raw['note']) ?? '')\n    .trim()\n    .slice(0, MAX_SUPPRESSION_NOTE_LENGTH);\n\n  return { ok: true, request: { leadObjectNameSingular, recordId, note } };\n};\n\nexport const parseSuppressRequest = (\n  body: unknown,\n): ParseResult<SuppressRequest> => {\n  const common = parseCommon(body);\n\n  if (!common.ok) {\n    return common;\n  }\n\n  const raw = body as Record<string, unknown>;\n  const reason = findSuppressionReason(\n    asString(raw['reasonCode'])?.trim().toUpperCase() ?? '',\n  );\n\n  if (reason === null) {\n    return {\n      ok: false,\n      message:\n        'Choose why this person must not be contacted. A block list with no recorded reasons cannot be audited, cleaned up, or defended.',\n    };\n  }\n\n  return {\n    ok: true,\n    request: { ...common.request, reasonCode: reason.code },\n  };\n};\n\nexport const parseUnsuppressRequest = (\n  body: unknown,\n): ParseResult<UnsuppressRequest> => {\n  const common = parseCommon(body);\n\n  if (!common.ok) {\n    return common;\n  }\n\n  const raw = body as Record<string, unknown>;\n  const reason = findUnsuppressionReason(\n    asString(raw['reasonCode'])?.trim().toUpperCase() ?? '',\n  );\n\n  if (reason === null) {\n    return {\n      ok: false,\n      message:\n        'Choose why this suppression should be lifted. Every reason on the list is a claim that the suppression itself was wrong or has been superseded \u2014 if none of them is true, do not lift it.',\n    };\n  }\n\n  if (common.request.note.length < MIN_UNSUPPRESSION_NOTE_LENGTH) {\n    return {\n      ok: false,\n      message: `Write down what happened, in at least ${MIN_UNSUPPRESSION_NOTE_LENGTH} characters. Removing someone from the block list re-enables contact with a person who asked us to stop, and the note is the only place the evidence for that lives.`,\n    };\n  }\n\n  if (raw['acknowledged'] !== true) {\n    return {\n      ok: false,\n      message:\n        'Confirm that you understand this re-enables contact with this person.',\n    };\n  }\n\n  return {\n    ok: true,\n    request: {\n      ...common.request,\n      reasonCode: reason.code,\n      acknowledged: true,\n    },\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Current state                                                               */\n/* -------------------------------------------------------------------------- */\n\nexport interface CurrentSuppressionState {\n  readonly recordId: string;\n  /** Denormalised into the audit row so the trail survives the record. */\n  readonly displayName: string;\n  readonly suppressed: boolean;\n  /** Raw `greenlightSuppressionReason`. Null when nothing is recorded. */\n  readonly reasonCode: string | null;\n  /** Raw `greenlightSuppressedAt` as stored. Null when nothing is recorded. */\n  readonly suppressedAt: string | null;\n  readonly note: string;\n  /** Raw `greenlightDecision`, for the audit row's decision column. */\n  readonly decision: string | null;\n  readonly score: number | null;\n  /**\n   * Raw `greenlightTrace`, read only for the audit row's band column \u2014 see\n   * `auditBandValue` in `release-decision.ts`. Optional because nothing in this\n   * module's decision logic reads it: a suppression is decided from the flag and\n   * the reason, never from a score, and a caller that cannot supply a trace must\n   * still be able to suppress somebody.\n   */\n  readonly trace?: unknown;\n}\n\n/**\n * Is this record on the block list *as far as Greenlight's own fields go*?\n *\n * A recorded reason with the flag cleared counts as suppressed, and that is not\n * a bug. Half-clearing \u2014 untick the box, leave `SPAM_COMPLAINT` sitting in the\n * reason column \u2014 is the realistic hand-edit, and reading it as \"not suppressed\"\n * would silently re-enable outreach to somebody whose record still states, in\n * writing, why we stopped. The compliance rule takes the same view; see\n * `src/scoring/rules/compliance-opt-out.rule.ts`.\n */\nexport const isSuppressedState = (state: {\n  readonly suppressed: boolean;\n  readonly reasonCode: string | null;\n}): boolean =>\n  state.suppressed || (state.reasonCode ?? '').trim().length > 0;\n\n/* -------------------------------------------------------------------------- */\n/* Audit vocabulary                                                            */\n/* -------------------------------------------------------------------------- */\n\n/** New `GreenlightAuditLog.eventType` options \u2014 see `src/objects/greenlight-audit-log.ts`. */\nexport const AUDIT_EVENT_SUPPRESSED = 'SUPPRESSED';\nexport const AUDIT_EVENT_UNSUPPRESSED = 'UNSUPPRESSED';\n\nexport type SuppressionAuditEventType =\n  | typeof AUDIT_EVENT_SUPPRESSED\n  | typeof AUDIT_EVENT_UNSUPPRESSED;\n\n/** The audit-trail rendering of a reason: machine code first, prose after. */\nexport const formatSuppressionReason = (\n  reasonCode: string,\n  note: string,\n): string => {\n  const label =\n    findSuppressionReason(reasonCode)?.label ??\n    findUnsuppressionReason(reasonCode)?.label ??\n    null;\n  const rendered = label === null ? reasonCode : `${reasonCode} \u00B7 ${label}`;\n\n  return note === '' ? rendered : `${rendered} \u2014 ${note}`;\n};\n\n/** One-line summary used as the audit row's record label. */\nexport const buildSuppressionAuditSummary = (\n  eventType: SuppressionAuditEventType,\n  displayName: string,\n  reasonCode: string,\n): string => {\n  const name = displayName.trim() === '' ? 'Unnamed lead' : displayName.trim();\n\n  return `${eventType} \u00B7 ${name} \u00B7 ${reasonCode}`;\n};\n\n/* -------------------------------------------------------------------------- */\n/* The decisions                                                               */\n/* -------------------------------------------------------------------------- */\n\nexport type SuppressOutcome =\n  /** Newly added to the block list. */\n  | 'suppressed'\n  /** Already on the list under the same reason. Nothing written, nothing logged. */\n  | 'already_suppressed'\n  /** Already on the list under a different reason; the reason was amended. */\n  | 'reason_amended';\n\nexport type UnsuppressOutcome =\n  /** Removed from the block list. */\n  | 'unsuppressed'\n  /** Was not on the list. Nothing written, nothing logged. */\n  | 'not_suppressed';\n\nexport interface SuppressionWrite {\n  readonly [field: string]: string | boolean | null;\n}\n\nexport interface SuppressionDecision<TOutcome extends string> {\n  readonly outcome: TOutcome;\n  /** Shown to the reviewer. Written for a salesperson, not a developer. */\n  readonly message: string;\n  /** The Person patch to apply, or null when nothing changes. */\n  readonly write: SuppressionWrite | null;\n  readonly shouldWriteAuditRow: boolean;\n  readonly auditEventType: SuppressionAuditEventType | null;\n  /** Rendered reason for the audit row. Empty when no row is written. */\n  readonly auditReason: string;\n}\n\nexport interface DecideSuppressInput {\n  readonly request: SuppressRequest;\n  readonly lead: CurrentSuppressionState;\n  /** The clock, passed in \u2014 this module never reads it. */\n  readonly now: Date;\n}\n\nexport interface DecideUnsuppressInput {\n  readonly request: UnsuppressRequest;\n  readonly lead: CurrentSuppressionState;\n  readonly now: Date;\n}\n\n/**\n * Decide what adding to the block list should do. Never throws.\n *\n * Three cases, and the amendment case is the interesting one. A record already\n * suppressed as `MANUAL_BLOCK` that turns out to be a `LEGAL_REQUEST` must be\n * correctable *without* passing through an unsuppressed state \u2014 a remove-then-add\n * would re-enable contact for as long as it took somebody to do the second half,\n * and would put a spurious `UNSUPPRESSED` row in the compliance trail.\n *\n * `greenlightSuppressedAt` is **not** rewritten on an amendment. That column\n * answers \"since when has this person been off-limits\", and the answer does not\n * change because we relabelled why.\n */\nexport const decideSuppress = (\n  input: DecideSuppressInput,\n): SuppressionDecision<SuppressOutcome> => {\n  const { request, lead, now } = input;\n  const currentReason = (lead.reasonCode ?? '').trim().toUpperCase();\n  const alreadyOnList = isSuppressedState(lead);\n\n  if (alreadyOnList && currentReason === request.reasonCode) {\n    return {\n      outcome: 'already_suppressed',\n      message: `${\n        lead.displayName.trim() === '' ? 'This lead' : lead.displayName.trim()\n      } is already on the Greenlight block list for the same reason. Nothing changed, and no second audit entry was written.`,\n      write: null,\n      shouldWriteAuditRow: false,\n      auditEventType: null,\n      auditReason: '',\n    };\n  }\n\n  if (alreadyOnList) {\n    return {\n      outcome: 'reason_amended',\n      message: `Already blocked \u2014 the recorded reason has been changed from ${suppressionReasonLabel(\n        currentReason === '' ? null : currentReason,\n      )} to ${suppressionReasonLabel(\n        request.reasonCode,\n      )}. The original block date is unchanged and the amendment is on record.`,\n      write: {\n        [SUPPRESSION_FIELD_SUPPRESSED]: true,\n        [SUPPRESSION_FIELD_REASON]: request.reasonCode,\n        [SUPPRESSION_FIELD_NOTE]: request.note,\n      },\n      shouldWriteAuditRow: true,\n      auditEventType: AUDIT_EVENT_SUPPRESSED,\n      auditReason: `AMENDED from ${\n        currentReason === '' ? 'no recorded reason' : currentReason\n      } \u2014 ${formatSuppressionReason(request.reasonCode, request.note)}`,\n    };\n  }\n\n  return {\n    outcome: 'suppressed',\n    message:\n      'Added to the Greenlight block list. This person will not be contacted, the lead has been re-scored, and the block is on record.',\n    write: {\n      [SUPPRESSION_FIELD_SUPPRESSED]: true,\n      [SUPPRESSION_FIELD_REASON]: request.reasonCode,\n      [SUPPRESSION_FIELD_SUPPRESSED_AT]: now.toISOString(),\n      [SUPPRESSION_FIELD_NOTE]: request.note,\n    },\n    shouldWriteAuditRow: true,\n    auditEventType: AUDIT_EVENT_SUPPRESSED,\n    auditReason: formatSuppressionReason(request.reasonCode, request.note),\n  };\n};\n\n/**\n * Decide what removing from the block list should do. Never throws.\n *\n * Every field is cleared, not just the flag. Leaving the reason behind would\n * leave the record asserting \"spam complaint\" while claiming to be contactable,\n * and the compliance rule (correctly) reads a lingering reason as still\n * suppressed \u2014 so a partial clear would look like it worked and quietly do\n * nothing.\n *\n * The audit row records the reason the person was suppressed *under*, not just\n * the reason given for lifting it. \"Which legal-request suppressions has this\n * workspace lifted, and who lifted them\" is the question this trail exists to\n * answer, and it is unanswerable from the removal reason alone.\n */\nexport const decideUnsuppress = (\n  input: DecideUnsuppressInput,\n): SuppressionDecision<UnsuppressOutcome> => {\n  const { request, lead } = input;\n\n  if (!isSuppressedState(lead)) {\n    return {\n      outcome: 'not_suppressed',\n      message:\n        'This person is not on the Greenlight block list, so there was nothing to remove. No change made, and no audit entry written.',\n      write: null,\n      shouldWriteAuditRow: false,\n      auditEventType: null,\n      auditReason: '',\n    };\n  }\n\n  const originalReason =\n    (lead.reasonCode ?? '').trim() === ''\n      ? 'no recorded reason'\n      : (lead.reasonCode ?? '').trim().toUpperCase();\n\n  return {\n    outcome: 'unsuppressed',\n    message:\n      'Removed from the Greenlight block list. Contact is re-enabled, the lead has been re-scored, and your reason is on record and cannot be edited afterwards.',\n    write: {\n      [SUPPRESSION_FIELD_SUPPRESSED]: false,\n      [SUPPRESSION_FIELD_REASON]: null,\n      [SUPPRESSION_FIELD_SUPPRESSED_AT]: null,\n      [SUPPRESSION_FIELD_NOTE]: '',\n    },\n    shouldWriteAuditRow: true,\n    auditEventType: AUDIT_EVENT_UNSUPPRESSED,\n    auditReason: `LIFTED a ${originalReason} suppression recorded ${\n      lead.suppressedAt ?? 'at an unrecorded time'\n    } \u2014 ${formatSuppressionReason(request.reasonCode, request.note)}`,\n  };\n};\n", "/**\n * The Person scoring run \u2014 everything the two database-event registrations share.\n *\n * Kept out of the `define*` files so it can be exercised against a fake API\n * client. The only impure things it touches are the client it is handed and the\n * `now` it is passed; there is no `new Date()` and no `new CoreApiClient()`\n * anywhere below.\n *\n * ## Not retriggering ourselves\n *\n * Writing `greenlightScore` back to a Person emits `person.updated`, which is\n * the event that made us score in the first place. Three independent guards stop\n * that becoming a loop, in order of how much they can be trusted:\n *\n *  1. **The trigger allow-list** (`SCORING_TRIGGER_PERSON_FIELDS`, declared in\n *     `score-person-updated.logic-function.ts`). Twenty only dispatches an update\n *     event to a function whose `databaseEventTriggerSettings.updatedFields`\n *     names a field that actually changed. None of Greenlight's three fields is\n *     on that list, so the platform never delivers our own write back to us.\n *     This guard runs outside our process and is the one doing the real work.\n *\n *  2. **The authored-write check** (`isGreenlightAuthoredWrite`). If an event\n *     arrives anyway \u2014 a bulk edit that touched a scoring field *and* a\n *     Greenlight field, a future SDK that treats `updatedFields` as advisory \u2014\n *     and every field it reports is one we own, the run exits before any read or\n *     write. Cheap, and it does not depend on the platform honouring anything.\n *\n *  3. **The outcome fingerprint** (`fingerprintOutcome`). Even if both guards\n *     above were bypassed, the second pass over an unchanged lead produces an\n *     identical fingerprint to the one already stored on the record, so nothing\n *     is written and the chain terminates after exactly one extra iteration.\n *     This is also what makes a retried event idempotent: no second audit row,\n *     no second write.\n *\n * The allow-list in guard 1 does carry three Greenlight-named fields \u2014\n * `greenlightSuppressed`, `greenlightSuppressionReason` and\n * `greenlightEnrichment`. All three are safe for the same structural reason:\n * this run never writes any of them, so its own write-back still wakes nothing.\n * Both exceptions, and the bounded enrichment cycle the third one does close,\n * are argued in full on `SCORING_TRIGGER_PERSON_FIELDS` below.\n *\n * Guard 3 fingerprints the *outcome*, not the inputs, on purpose. The engine's\n * default field mapping reads `lastVerifiedAt` from `updatedAt`, which changes\n * on every write \u2014 an input hash would therefore differ on every pass and could\n * never terminate. The outcome is stable by construction.\n *\n * ## Not undoing a human override\n *\n * The guards above stop *our own* write from re-scoring a lead. They do nothing\n * about the other half of the contract with `release-lead.logic-function.ts`: a\n * rep releases a gated lead, then edits `jobTitle` seconds later, which is a\n * legitimate re-score that would re-gate the lead the human just released.\n *\n * The release writes a marker to app key-value storage. This run reads it before\n * writing a holding decision and pins the decision to `PASS` when one is present\n * \u2014 the score and the whole trace still update, only the decision is pinned. See\n * `pinReleasedDecision` for the exceptions and the failure directions.\n */\n\nimport {\n  SCORING_ENGINE_VERSION,\n  scoreLead,\n  toLeadRecord,\n  type GateDecision,\n  type ScoringResult,\n} from 'src/scoring';\n\nimport {\n  NO_SEAL,\n  resolveCalibration,\n  sealedCalibrationBody,\n  toScoringBaseline,\n  type CalibrationReaderPort,\n  type CalibrationSealPort,\n} from 'src/calibration';\nimport {\n  releaseMarkerKey,\n  type ReleaseMarker,\n} from 'src/gate/release-decision';\nimport { SUPPRESSION_SCORING_INPUT_FIELDS } from 'src/gate/suppression-decision';\nimport {\n  describeError,\n  isPlainRecord,\n  logGreenlight,\n  oldestByCreatedAt,\n  readConnectionNodes,\n  type GreenlightApiClient,\n} from 'src/logic-functions/greenlight-api';\nimport {\n  greenlightConfigSelection,\n  isGateEnabled,\n  readLeadObjectNameSingular,\n  toScoringConfigInput,\n} from 'src/logic-functions/greenlight-config-record';\n\n/* -------------------------------------------------------------------------- */\n/* Field vocabulary                                                            */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The Person fields **this run writes**. Nothing here may ever appear in a\n * `databaseEventTriggerSettings.updatedFields` list \u2014 see guard 1 above.\n *\n * \"Managed\" means written by the scoring run, not merely shipped by Greenlight.\n * The distinction started mattering when the app grew fields it *owns* but never\n * writes: the four `greenlightSuppress*` columns are Greenlight's own schema and\n * are human-maintained input, so two of them are on the trigger list below and\n * none of them belongs here. Adding one of them to this list would make guard 2\n * swallow the very event the feature depends on.\n */\nexport const GREENLIGHT_MANAGED_PERSON_FIELDS: readonly string[] = [\n  'greenlightScore',\n  'greenlightDecision',\n  'greenlightTrace',\n];\n\n/**\n * Fields whose change can move the score, i.e. the ones worth re-scoring for.\n *\n * `updatedAt` is deliberately absent even though the freshness rule reads it:\n * it changes on *every* write, including ours, which would defeat guard 1\n * entirely. Freshness is re-evaluated whenever anything else changes, and a lead\n * that goes stale without being touched is a reporting problem, not an event.\n *\n * `company` and `companyId` are both listed because Twenty reports a relation\n * change under the foreign-key name in some versions and the relation name in\n * others; a name that never fires costs nothing.\n *\n * ## The suppression exception\n *\n * `SUPPRESSION_SCORING_INPUT_FIELDS` appends `greenlightSuppressed` and\n * `greenlightSuppressionReason`. These are the only Greenlight-named fields on\n * this list, and the exception is mandatory rather than convenient: suppression\n * is a *blocking* input to the compliance rule, so a change that does not\n * re-score leaves a person who has just asked us to stop sitting in the queue\n * still marked `PASS`. A block list nobody re-scores against is not a block list.\n *\n * The loop still terminates, and the argument is the same three guards, checked\n * against the new field:\n *\n *   1. **Guard 1 still holds because the two sets are disjoint.** The scoring run\n *      writes exactly `GREENLIGHT_MANAGED_PERSON_FIELDS`, and no name on that\n *      list is on this one. A suppression change wakes the scorer; the scorer's\n *      own write-back does not wake anything, because it touches none of these\n *      names. The cycle would only close if the run wrote a suppression field,\n *      which it never does \u2014 the two block-list actions are the only writers, and\n *      they are human-triggered. `scoring-run.test.ts` asserts both halves.\n *   2. **Guard 2 is unaffected.** `isGreenlightAuthoredWrite` tests membership of\n *      the managed list, not of this one, so an event carrying only suppression\n *      fields is correctly *not* treated as our own write and is scored.\n *   3. **Guard 3 is the backstop and gets stronger, not weaker.** Suppression\n *      moves the compliance rule's outcome, so the first run after a change has a\n *      genuinely different fingerprint and writes; any replay of that same event\n *      fingerprints identically and writes nothing.\n *\n * ## The enrichment exception\n *\n * `greenlightEnrichment` is on this list for the same kind of reason and it is\n * equally mandatory. `resolveFieldMapping` appends\n * `greenlightEnrichment.fields.<key>.parsedValue` to every enrichable key, so an\n * enriched value is a *scoring input*. Leaving it off meant enrichment could\n * only ever benefit a lead on its next unrelated edit \u2014 the enriched industry\n * sat on the record, read by nothing, until somebody happened to change a phone\n * number. That is enrichment being cosmetic, which is the bug this closes.\n *\n * The two sibling columns are deliberately **not** here. `greenlightEnrichedAt`\n * and `greenlightEnrichmentStatus` are written by the same mutation but no rule\n * reads either, so waking the scorer for them would buy a guaranteed-identical\n * fingerprint and nothing else.\n *\n * ### Why this terminates\n *\n * Unlike suppression, this one *does* close a cycle: enrichment's own trigger is\n * `greenlightDecision`, which is a field this run writes. The cycle is real,\n * bounded, and cannot reach a provider more than a fixed number of times.\n *\n *   1. **The common case never starts.** Guard 3 is checked before any write. If\n *      enrichment changed no value the mapping reads \u2014 it accepted nothing, or\n *      the field already had a human value ahead of the enriched path \u2014 the score,\n *      band, decision and every rule verdict are identical, the fingerprint\n *      matches the one stored on the record, and this run writes *nothing*.\n *      `greenlightDecision` never changes, so enrichment is never woken. The\n *      chain is one hop long.\n *   2. **When the score does move**, this run writes `greenlightDecision` and\n *      enrichment wakes. Its gap analysis then finds every enrichable field\n *      either freshly cached (the run that just fired filled it) or inside the\n *      unresolved back-off window (it asked and found nothing), requests nothing,\n *      and returns `no_gaps` **before any provider call and before any write**.\n *      No write means no `greenlightEnrichment` change, which means the scorer is\n *      not woken again. The chain is two hops long and costs one key-value read.\n *   3. **The pathological case still terminates.** Even if a later enrichment run\n *      did find a fresh gap, every hop strictly shrinks the set of unfilled\n *      enrichable fields \u2014 a field that is sourced becomes fresh, and a field that\n *      is not becomes unresolved \u2014 so the chain is bounded by the five entries in\n *      `ENRICHABLE_FIELD_SPECS`, and the monthly spend cap bounds it again from\n *      outside.\n *\n * Guard 2 stays correct throughout: `isGreenlightAuthoredWrite` tests membership\n * of `GREENLIGHT_MANAGED_PERSON_FIELDS`, which this run writes and enrichment\n * does not, so an enrichment write is correctly *not* mistaken for our own and\n * is scored. `__tests__/enrich-score-cycle.test.ts` drives the whole loop against\n * both runs and asserts it settles rather than trusting this comment.\n */\nexport const SCORING_TRIGGER_PERSON_FIELDS: readonly string[] = [\n  'name',\n  'emails',\n  'phones',\n  'jobTitle',\n  'linkedinLink',\n  'company',\n  'companyId',\n  // The enriched-value blob. See \"The enrichment exception\" above \u2014 this is a\n  // scoring input, and the cycle it closes is bounded and proved by test.\n  'greenlightEnrichment',\n  ...SUPPRESSION_SCORING_INPUT_FIELDS,\n];\n\n/** `Person.greenlightDecision` / `GreenlightAuditLog.decision` SELECT values. */\nexport type DecisionValue = 'PASS' | 'GATE' | 'BLOCKED' | 'UNSCORED';\n\n/** `GreenlightAuditLog.eventType` SELECT values used by the scoring path. */\ntype AuditEventType = 'SCORED' | 'GATED' | 'SKIPPED' | 'ERROR';\n\n/* -------------------------------------------------------------------------- */\n/* Guards                                                                      */\n/* -------------------------------------------------------------------------- */\n\n/**\n * True when an update event carries nothing but fields Greenlight itself wrote.\n *\n * An empty or absent `updatedFields` returns false: \"we do not know what\n * changed\" must mean \"score it\", because the alternative is silently skipping a\n * real edit. Over-scoring is harmless \u2014 guard 3 makes the redundant run a no-op.\n */\nexport const isGreenlightAuthoredWrite = (\n  updatedFields: unknown,\n): boolean => {\n  if (!Array.isArray(updatedFields) || updatedFields.length === 0) {\n    return false;\n  }\n\n  return updatedFields.every(\n    (field) =>\n      typeof field === 'string' &&\n      GREENLIGHT_MANAGED_PERSON_FIELDS.includes(field),\n  );\n};\n\n/* -------------------------------------------------------------------------- */\n/* Result -> CRM vocabulary                                                    */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Map the engine's four-valued decision onto the SELECT the schema ships.\n *\n * The mapping is now one-to-one: `greenlightDecision` carries a `BLOCKED` option\n * of its own (see `src/fields/greenlight-decision.field.ts`), so a compliance\n * stop is no longer indistinguishable from a low score. Before that option\n * existed `blocked` collapsed onto `GATE` and every consumer had to\n * reverse-engineer the difference out of `greenlightTrace`.\n *\n * When the gate is switched off, `gated` is downgraded to `PASS` per the\n * `isGateEnabled` field's contract (\"nothing is held for review\"). `blocked` is\n * **not** downgraded: that state only arises from a compliance stop such as an\n * opt-out, and quietly marking an opted-out contact as ready to call is not a\n * behaviour any switch on a settings page should be able to buy.\n */\nexport const toDecisionValue = (\n  decision: GateDecision,\n  gateEnabled: boolean,\n): DecisionValue => {\n  switch (decision) {\n    case 'approved':\n      return 'PASS';\n    case 'gated':\n      return gateEnabled ? 'GATE' : 'PASS';\n    case 'blocked':\n      return 'BLOCKED';\n    default:\n      return 'UNSCORED';\n  }\n};\n\n/** The decision values that mean \"this lead is being held from a rep\". */\nconst HOLDING_DECISIONS: readonly DecisionValue[] = ['GATE', 'BLOCKED'];\n\nconst KNOWN_BAND_VALUES: readonly string[] = [\n  'EXCELLENT',\n  'GOOD',\n  'FAIR',\n  'POOR',\n];\n\n/**\n * Band ids are configurable, so an unrecognised one has to degrade rather than\n * be written into a SELECT that would reject it.\n */\nexport const toBandValue = (result: ScoringResult): string => {\n  const id = result.band?.id;\n\n  if (typeof id !== 'string') {\n    return 'UNSCORED';\n  }\n\n  const value = id.trim().toUpperCase();\n\n  return KNOWN_BAND_VALUES.includes(value) ? value : 'UNSCORED';\n};\n\nexport const toAuditEventType = (\n  decision: DecisionValue,\n  result: ScoringResult,\n): AuditEventType => {\n  if (result.decision === 'unscored') {\n    return 'SKIPPED';\n  }\n\n  // GATED covers both holding states. The audit log's `eventType` vocabulary is\n  // about what happened to the lead \u2014 it was held \u2014 and the row's `decision`\n  // column already says which of the two states it was held in.\n  return HOLDING_DECISIONS.includes(decision) ? 'GATED' : 'SCORED';\n};\n\n/* -------------------------------------------------------------------------- */\n/* Fingerprint + trace id                                                      */\n/* -------------------------------------------------------------------------- */\n\n/** FNV-1a, 32-bit. Short, dependency-free, and stable across Node versions. */\nconst hash32 = (input: string): string => {\n  let hash = 0x811c9dc5;\n\n  for (let index = 0; index < input.length; index += 1) {\n    hash ^= input.charCodeAt(index);\n    hash = Math.imul(hash, 0x01000193) >>> 0;\n  }\n\n  return hash.toString(16).padStart(8, '0');\n};\n\n/**\n * A stable digest of everything about a run that a human would call \"the\n * outcome\": the score, the decision, the band, and the verdict of every rule.\n *\n * Explicitly excludes `scoredAt`, the trace prose and the degradation list, so\n * re-scoring an untouched lead a day later produces the same fingerprint and\n * writes nothing.\n */\nexport const fingerprintOutcome = (\n  result: ScoringResult,\n  decisionValue: string,\n): string => {\n  const parts = [\n    result.engineVersion,\n    decisionValue,\n    result.score === null ? 'null' : result.score.toFixed(1),\n    result.band?.id ?? 'none',\n    result.gateThreshold.toString(),\n    ...result.trace.map(\n      (entry) => `${entry.ruleId}:${entry.outcome}:${entry.credit.toFixed(3)}`,\n    ),\n  ];\n\n  return hash32(parts.join('|'));\n};\n\n/**\n * Deterministic per (lead, outcome). A retry that re-writes the same decision\n * reuses the id, so duplicate audit rows are recognisable as one run rather than\n * looking like the gate flip-flopped.\n */\nexport const buildTraceId = (\n  leadRecordId: string,\n  fingerprint: string,\n): string => `gl-${hash32(leadRecordId)}-${fingerprint}`;\n\n/** The fingerprint already stored on the Person, if any. */\nexport const readStoredFingerprint = (trace: unknown): string | null => {\n  if (!isPlainRecord(trace)) {\n    return null;\n  }\n\n  const value = trace['fingerprint'];\n\n  return typeof value === 'string' && value.length > 0 ? value : null;\n};\n\n/* -------------------------------------------------------------------------- */\n/* Display helpers                                                             */\n/* -------------------------------------------------------------------------- */\n\n/** Person.name is a FULL_NAME composite. Fall back to email, then to the id. */\nexport const readLeadDisplayName = (person: unknown): string => {\n  if (!isPlainRecord(person)) {\n    return 'Unknown lead';\n  }\n\n  const name = person['name'];\n\n  if (isPlainRecord(name)) {\n    const parts = [name['firstName'], name['lastName']]\n      .filter((part): part is string => typeof part === 'string')\n      .map((part) => part.trim())\n      .filter((part) => part.length > 0);\n\n    if (parts.length > 0) {\n      return parts.join(' ');\n    }\n  }\n\n  if (typeof name === 'string' && name.trim().length > 0) {\n    return name.trim();\n  }\n\n  const emails = person['emails'];\n\n  if (isPlainRecord(emails)) {\n    const primary = emails['primaryEmail'];\n\n    if (typeof primary === 'string' && primary.trim().length > 0) {\n      return primary.trim();\n    }\n  }\n\n  const id = person['id'];\n\n  return typeof id === 'string' ? id : 'Unknown lead';\n};\n\n/* -------------------------------------------------------------------------- */\n/* The run                                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The slice of app key-value storage this run needs, as a port.\n *\n * `kv` is only importable from `twenty-sdk/logic-function`, and this module is\n * deliberately SDK-free so it can be driven by a fake in tests \u2014 the same reason\n * `GreenlightApiClient` exists. `src/logic-functions/release-marker-store.ts`\n * holds the one real implementation.\n *\n * It is a *required* input rather than an optional one on purpose. A run without\n * a store silently re-gates every released lead, which is exactly the bug this\n * port exists to close; making it required means the compiler, not a reviewer,\n * catches a registration that forgot to wire it.\n */\nexport interface ReleaseMarkerStore {\n  get(key: string): Promise<ReleaseMarker | null>;\n  delete(key: string): Promise<void>;\n}\n\n/**\n * A config record the caller has already read, so the run does not read it again.\n *\n * Wrapped in an object rather than passed as `Record | null` because `null` is a\n * *legitimate answer* here \u2014 it means \"this workspace has no config record, score\n * on the engine's defaults\" \u2014 and would otherwise be indistinguishable from \"the\n * caller did not supply one\". The wrapper makes absent and empty different types\n * instead of different values.\n *\n * It exists for the backfill (`src/logic-functions/backfill-run.ts`), which scores\n * thirty records per cron tick against one config that cannot change between\n * them. Reading it per record would treble the run's share of the rate limit \u2014\n * 30 requests a minute buying thirty identical answers \u2014 and would be the single\n * largest cost in a bulk pass.\n *\n * Optional on purpose: the two event registrations pass nothing and keep the\n * exact behaviour they had, which is what makes this an additive change rather\n * than a rewrite of the hot path.\n */\nexport interface PreloadedConfig {\n  readonly record: Record<string, unknown> | null;\n}\n\nexport interface ScoringRunInput {\n  readonly client: GreenlightApiClient;\n  /** The `DatabaseEventPayload` as delivered, untyped on purpose. */\n  readonly event: unknown;\n  readonly now: Date;\n  readonly markers: ReleaseMarkerStore;\n  /** Omitted by the event registrations; supplied by the bulk backfill. */\n  readonly config?: PreloadedConfig;\n  /**\n   * Read-only access to the licence-delivered calibration cache.\n   *\n   * Optional, and its absence means \"shipped defaults\" \u2014 the same outcome as an\n   * unlicensed workspace, an expired cache, or a payload whose signature did not\n   * verify. That is what makes this additive: every existing caller that does\n   * not pass it keeps its exact previous behaviour, and the compiler does not\n   * have to be trusted on the point because there is nothing to break.\n   */\n  readonly calibration?: CalibrationReaderPort | null;\n  /**\n   * Checks that the cached calibration belongs to this workspace's licence key.\n   *\n   * Defaults to `NO_SEAL`, which accepts nothing \u2014 so a caller that wires the\n   * reader but forgets the seal gets shipped defaults rather than an unchecked\n   * cache. See `src/calibration/seal.ts` for what the seal does and does not\n   * prove.\n   */\n  readonly calibrationSeal?: CalibrationSealPort;\n}\n\nexport type ScoringRunOutcome =\n  | { status: 'skipped'; reason: string }\n  | { status: 'unchanged'; leadRecordId: string; fingerprint: string }\n  | {\n      status: 'scored';\n      leadRecordId: string;\n      traceId: string;\n      decision: string;\n      score: number | null;\n    }\n  | { status: 'failed'; leadRecordId: string | null; error: string };\n\nconst readEventRecord = (event: unknown): Record<string, unknown> | null => {\n  if (!isPlainRecord(event)) {\n    return null;\n  }\n\n  const properties = event['properties'];\n\n  if (!isPlainRecord(properties)) {\n    return null;\n  }\n\n  const after = properties['after'];\n\n  return isPlainRecord(after) ? after : null;\n};\n\nconst readEventUpdatedFields = (event: unknown): unknown => {\n  if (!isPlainRecord(event)) {\n    return undefined;\n  }\n\n  const properties = event['properties'];\n\n  return isPlainRecord(properties) ? properties['updatedFields'] : undefined;\n};\n\nconst readRecordId = (\n  event: unknown,\n  record: Record<string, unknown> | null,\n): string | null => {\n  if (isPlainRecord(event) && typeof event['recordId'] === 'string') {\n    return event['recordId'];\n  }\n\n  if (record !== null && typeof record['id'] === 'string') {\n    return record['id'];\n  }\n\n  return null;\n};\n\n/** Load the single config record. Absent or unreadable yields `null`. */\nexport const loadConfigRecord = async (\n  client: GreenlightApiClient,\n): Promise<Record<string, unknown> | null> => {\n  const response = await client.query({\n    greenlightConfigs: { edges: { node: greenlightConfigSelection() } },\n  });\n\n  return oldestByCreatedAt(readConnectionNodes(response, 'greenlightConfigs'));\n};\n\n/**\n * Best-effort company hydration.\n *\n * `event.properties.after` carries the Person's own columns and the company\n * foreign key, but not the company's name \u2014 and \"which company does this lead\n * work for\" is a rule worth 10 points. One extra read buys it. If the read\n * fails for any reason the lead is scored without it, because a lead scored\n * slightly low is recoverable and a lead not scored at all is not.\n */\nconst hydrateCompany = async (\n  client: GreenlightApiClient,\n  person: Record<string, unknown>,\n): Promise<Record<string, unknown>> => {\n  const companyId = person['companyId'];\n\n  if (typeof companyId !== 'string' || companyId.length === 0) {\n    return person;\n  }\n\n  if (isPlainRecord(person['company'])) {\n    return person;\n  }\n\n  try {\n    const response = await client.query({\n      companies: {\n        __args: { filter: { id: { eq: companyId } } },\n        edges: { node: { id: true, name: true } },\n      },\n    });\n\n    const [company] = readConnectionNodes(response, 'companies');\n\n    return company === undefined ? person : { ...person, company };\n  } catch (error) {\n    logGreenlight('company_hydration_failed', {\n      companyId,\n      error: describeError(error),\n    });\n\n    return person;\n  }\n};\n\n/* -------------------------------------------------------------------------- */\n/* The human override                                                          */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The object name the release marker is keyed on.\n *\n * Hard-coded rather than taken from the config's `leadObjectNameSingular`\n * because the override can only ever write a `person` key \u2014\n * `SUPPORTED_LEAD_OBJECTS` in `release-decision.ts` has one entry, and both\n * scoring registrations are bound to `person.*` events. Deriving the key from\n * configuration would mean a workspace that renamed its lead object silently\n * looked up a key the release side never writes, which is the same silent\n * self-undoing override this whole mechanism exists to prevent.\n */\nconst RELEASE_MARKER_OBJECT = 'person';\n\n/**\n * A compliance stop, using the exact discriminator `src/scoring/engine.ts` uses\n * to choose `blocked` \u2014 checked from the trace as well as the decision so a\n * blocking failure is still recognised if the engine ever reports the two\n * inconsistently.\n */\nconst hasBlockingFailure = (result: ScoringResult): boolean =>\n  result.decision === 'blocked' ||\n  result.trace.some(\n    (entry) => entry.severity === 'blocking' && entry.outcome === 'fail',\n  );\n\ninterface ReleasePin {\n  /** The decision to actually write. */\n  readonly decision: DecisionValue;\n  /** Non-null only when a marker was honoured and the decision was pinned. */\n  readonly honoured: ReleaseMarker | null;\n}\n\n/**\n * Honour a human release when re-scoring would otherwise hold the lead again.\n *\n * The contract with `release-lead.logic-function.ts`: if a release marker\n * exists, the score and the trace still update freely, but `greenlightDecision`\n * stays at `PASS`. Three things are worth being explicit about.\n *\n * **A newly blocking compliance failure outranks the release.** The marker is\n * deleted and the lead is re-held. \"Newly\" needs no timestamp comparison: the\n * override refuses to release a compliance-blocked lead at all\n * (`ALLOW_COMPLIANCE_OVERRIDE === false`) and writes no marker when it refuses,\n * so any marker that exists was written for a lead that was *not* blocked at\n * release time. A blocking failure seen now is therefore newer by construction.\n *\n * **A failed key-value read re-gates rather than releases.** Falling back to\n * \"no marker\" means a released lead can be wrongly held for a moment \u2014 an\n * annoyance a human fixes by releasing it again, with the whole trail recording\n * what happened. The opposite fallback, treating an unreadable store as \"a\n * marker probably exists\", would let a storage outage quietly release leads the\n * gate is holding, including leads held on compliance grounds. That is not\n * recoverable by a human, because nobody knows it happened. The failure is\n * logged rather than swallowed, under `release_marker_read_failed`.\n *\n * **A failed delete is self-correcting.** If the marker survives a re-gating\n * compliance failure, the *next* run re-evaluates the same blocking rule and\n * re-holds the lead again \u2014 a stale marker only ever wins once the compliance\n * failure has genuinely gone away, which is the state a release should win in.\n */\nconst pinReleasedDecision = async (\n  markers: ReleaseMarkerStore,\n  leadRecordId: string,\n  decisionValue: DecisionValue,\n  result: ScoringResult,\n): Promise<ReleasePin> => {\n  if (!HOLDING_DECISIONS.includes(decisionValue)) {\n    // Nothing is being held, so there is nothing to pin and no reason to spend\n    // a read. A marker left behind by an earlier release is harmless: it is only\n    // ever consulted on a run that would hold the lead.\n    return { decision: decisionValue, honoured: null };\n  }\n\n  const key = releaseMarkerKey(RELEASE_MARKER_OBJECT, leadRecordId);\n\n  let marker: ReleaseMarker | null = null;\n\n  try {\n    marker = await markers.get(key);\n  } catch (error) {\n    logGreenlight('release_marker_read_failed', {\n      leadRecordId,\n      decision: decisionValue,\n      error: describeError(error),\n    });\n\n    return { decision: decisionValue, honoured: null };\n  }\n\n  if (marker === null) {\n    return { decision: decisionValue, honoured: null };\n  }\n\n  if (hasBlockingFailure(result)) {\n    try {\n      await markers.delete(key);\n    } catch (error) {\n      logGreenlight('release_marker_delete_failed', {\n        leadRecordId,\n        error: describeError(error),\n      });\n    }\n\n    logGreenlight('release_marker_overruled', {\n      leadRecordId,\n      decision: decisionValue,\n      releasedAt: marker.releasedAt,\n    });\n\n    return { decision: decisionValue, honoured: null };\n  }\n\n  return { decision: 'PASS', honoured: marker };\n};\n\nconst buildTracePayload = (\n  result: ScoringResult,\n  traceId: string,\n  fingerprint: string,\n  decisionValue: string,\n  bandValue: string,\n  releaseOverride: Record<string, unknown> | null,\n  /**\n   * Which calibration produced this score, or `null` for shipped defaults.\n   *\n   * Recorded on the lead itself rather than only in the admin panel, because\n   * \"why did this lead score 68 last week and 82 today\" is a question asked\n   * about one record months later, and the panel only ever shows *now*. It is\n   * the version number and nothing else \u2014 the payload is a few hundred\n   * kilobytes of word lists and does not belong on every Person row.\n   */\n  calibrationVersion: number | null,\n): Record<string, unknown> => ({\n  calibration:\n    calibrationVersion === null\n      ? { source: 'shipped_defaults' }\n      : { source: 'licensed', version: calibrationVersion },\n  traceId,\n  fingerprint,\n  engineVersion: result.engineVersion,\n  scoredAt: result.scoredAt,\n  score: result.score,\n  band: bandValue,\n  decision: decisionValue,\n  gateThreshold: result.gateThreshold,\n  summary: result.summary,\n  reasons: [...result.reasons],\n  configSource: result.configSource,\n  degradations: result.degradations.map((entry) => ({ ...entry })),\n  rules: result.trace.map((entry) => ({ ...entry })),\n  // Present only on a pinned run. Without it the trace would show a lead\n  // scoring 12 against a threshold of 40 sitting at PASS with nothing on the\n  // record explaining why, which is the same silence the marker exists to fix.\n  ...(releaseOverride === null ? {} : { releaseOverride }),\n});\n\n/**\n * Score one Person event end to end.\n *\n * Never throws. Every failure path returns a `failed` outcome after making a\n * best-effort attempt to leave the lead flagged `UNSCORED` with an ERROR audit\n * row \u2014 ARCHITECTURE.md's golden rule is that a lead is never blocked from\n * reaching a rep, so a broken run must leave a visible, explained record rather\n * than a silent gap.\n */\n/**\n * Read the cached calibration and reduce it to the vocabulary baseline the\n * engine accepts.\n *\n * Never throws and never blocks: a store that errors, a cache that is absent\n * (which is also what a lapsed entitlement leaves behind \u2014 the nightly run\n * clears it), and a payload that has aged past 72 hours all return `null`,\n * which resolves to the in-source defaults. There is no branch here that can\n * stop a lead being scored, and there is deliberately no way to write one \u2014 the\n * port has no method but `read`.\n *\n * No licence state is consulted. That is not an omission: see\n * `src/calibration/state.ts`, \"Why there is no entitlement check here\".\n */\ninterface AppliedCalibration {\n  readonly baseline: ReturnType<typeof toScoringBaseline>;\n  readonly version: number;\n}\n\n/**\n * Return the entry only if its seal verifies under this workspace's licence key.\n *\n * A failure is logged once and reported as `null`, i.e. as \"no calibration\",\n * which is the shipped-defaults path. It is deliberately not an error: a cache\n * that fails its seal is most often a licence key that was changed, and a rep\n * scoring a lead is not the person to tell about it. The nightly run rewrites a\n * correctly-sealed entry and the condition clears itself.\n */\nconst verifySeal = async (\n  stored: Awaited<ReturnType<CalibrationReaderPort['read']>>,\n  seal: CalibrationSealPort,\n): Promise<typeof stored> => {\n  if (stored === null) {\n    return null;\n  }\n\n  const canonical = sealedCalibrationBody(stored);\n\n  if (canonical === null) {\n    return null;\n  }\n\n  const sealed = await seal.verify(canonical, stored.sealTag);\n\n  if (!sealed) {\n    logGreenlight('calibration_cache_seal_mismatch', {\n      calibrationVersion: stored.calibration.calibrationVersion,\n      keyId: stored.keyId,\n    });\n\n    return null;\n  }\n\n  return stored;\n};\n\nconst readCalibrationBaseline = async (\n  calibration: CalibrationReaderPort | null | undefined,\n  seal: CalibrationSealPort,\n  now: Date,\n): Promise<AppliedCalibration | null> => {\n  if (calibration === null || calibration === undefined) {\n    return null;\n  }\n\n  try {\n    const stored = await calibration.read();\n\n    // The seal is checked before the freshness ladder, not after. A cache\n    // lifted from another workspace should be refused on the grounds that it is\n    // not ours, whatever its age \u2014 and checking age first would mean a stolen\n    // cache and an expired one produce the same reason in the log, which is the\n    // one distinction worth keeping here.\n    const cached = await verifySeal(stored, seal);\n\n    const resolved = resolveCalibration({ cached, now });\n\n    return resolved.calibration === null\n      ? null\n      : {\n          baseline: toScoringBaseline(resolved.calibration),\n          version: resolved.calibration.calibrationVersion,\n        };\n  } catch (error) {\n    logGreenlight('calibration_read_failed', { error: describeError(error) });\n\n    return null;\n  }\n};\n\nexport const runPersonScoring = async ({\n  client,\n  event,\n  now,\n  markers,\n  config,\n  calibration,\n  calibrationSeal = NO_SEAL,\n}: ScoringRunInput): Promise<ScoringRunOutcome> => {\n  const person = readEventRecord(event);\n  const leadRecordId = readRecordId(event, person);\n\n  // Guard 2. Runs before anything else so a Greenlight-authored write costs one\n  // array scan, not two API round trips.\n  if (isGreenlightAuthoredWrite(readEventUpdatedFields(event))) {\n    return { status: 'skipped', reason: 'greenlight_authored_write' };\n  }\n\n  if (person === null || leadRecordId === null) {\n    logGreenlight('event_unreadable', { leadRecordId });\n\n    return { status: 'skipped', reason: 'event_unreadable' };\n  }\n\n  try {\n    // A supplied config is used as-is, including a supplied `null`. Only an\n    // absent wrapper triggers the read \u2014 see `PreloadedConfig`.\n    const configRecord =\n      config === undefined ? await loadConfigRecord(client) : config.record;\n    const gateEnabled = isGateEnabled(configRecord);\n    const leadObjectNameSingular = readLeadObjectNameSingular(configRecord);\n\n    const hydrated = await hydrateCompany(client, person);\n\n    const applied = await readCalibrationBaseline(\n      calibration,\n      calibrationSeal,\n      now,\n    );\n\n    // `scoreLead` never throws and repairs anything unusable in the config, so\n    // a missing record needs no special case here \u2014 it becomes `configSource:\n    // 'defaults'` and a degradation entry in the trace. A `null` baseline is\n    // likewise not a special case: it is what the parameter means when there is\n    // no calibration, and it scores identically to the build that predates it.\n    const result = scoreLead({\n      lead: toLeadRecord(hydrated),\n      now,\n      config: toScoringConfigInput(configRecord),\n      baseline: applied?.baseline ?? null,\n    });\n\n    const engineDecision = toDecisionValue(result.decision, gateEnabled);\n    const pin = await pinReleasedDecision(\n      markers,\n      leadRecordId,\n      engineDecision,\n      result,\n    );\n    const decisionValue = pin.decision;\n    const bandValue = toBandValue(result);\n\n    // The fingerprint is taken over the decision actually written, not the one\n    // the engine proposed. That keeps guard 3 honest in both directions: the\n    // first pinned run differs from the stored GATE fingerprint and writes, and\n    // every identical pinned run afterwards matches and writes nothing. A\n    // fingerprint over `engineDecision` would record a decision the record does\n    // not carry.\n    const fingerprint = fingerprintOutcome(result, decisionValue);\n\n    // Guard 3.\n    if (readStoredFingerprint(person['greenlightTrace']) === fingerprint) {\n      return { status: 'unchanged', leadRecordId, fingerprint };\n    }\n\n    const traceId = buildTraceId(leadRecordId, fingerprint);\n    const leadDisplayName = readLeadDisplayName(person);\n    const eventType = toAuditEventType(decisionValue, result);\n    const tracePayload = buildTracePayload(\n      result,\n      traceId,\n      fingerprint,\n      decisionValue,\n      bandValue,\n      pin.honoured === null\n        ? null\n        : {\n            engineDecision,\n            releasedAt: pin.honoured.releasedAt,\n            releasedBy: pin.honoured.releasedBy,\n            reasonCode: pin.honoured.reasonCode,\n          },\n      applied?.version ?? null,\n    );\n    // A pinned run is still a SYSTEM action \u2014 the system honouring a human\n    // decision taken earlier \u2014 so `actorType` stays SYSTEM and the human's\n    // fingerprints go in the reason, where the audit log already looks for them.\n    const overrideReason =\n      pin.honoured === null\n        ? ''\n        : `RELEASE_MARKER_HONOURED \u2014 engine decision ${engineDecision} held at PASS by the release recorded ${pin.honoured.releasedAt} (${pin.honoured.releasedBy}, ${pin.honoured.reasonCode})`;\n\n    // Audit row first, Person second \u2014 and the order is load-bearing.\n    //\n    // If the audit write succeeds and the Person write fails, the next event\n    // re-scores, finds the stored fingerprint still absent, and writes both\n    // again: the trail over-records. If the order were reversed, the Person\n    // would carry the new fingerprint, guard 3 would suppress every subsequent\n    // run, and the decision would never be recorded at all. An append-only\n    // trail is allowed to repeat itself; it is not allowed to lose an entry.\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: {\n            name: `${eventType} \u00B7 ${leadDisplayName} \u00B7 ${result.score ?? '\u2014'}`,\n            eventType,\n            occurredAt: now.toISOString(),\n            leadObjectNameSingular,\n            leadRecordId,\n            leadDisplayName,\n            actorType: 'SYSTEM',\n            actorDisplayName: `Greenlight engine ${SCORING_ENGINE_VERSION}`,\n            ruleTrace: tracePayload,\n            score: result.score,\n            band: bandValue,\n            decision: decisionValue,\n            overrideReason,\n            traceId,\n          },\n        },\n        id: true,\n      },\n    });\n\n    await client.mutation({\n      updatePerson: {\n        __args: {\n          id: leadRecordId,\n          data: {\n            greenlightScore: result.score,\n            greenlightDecision: decisionValue,\n            greenlightTrace: tracePayload,\n          },\n        },\n        id: true,\n      },\n    });\n\n    logGreenlight('lead_scored', {\n      leadRecordId,\n      traceId,\n      score: result.score,\n      band: bandValue,\n      decision: decisionValue,\n      engineDecision,\n      releasePinned: pin.honoured !== null,\n      configSource: result.configSource,\n      calibrationVersion: applied?.version ?? null,\n      degradations: result.degradations.length,\n    });\n\n    return {\n      status: 'scored',\n      leadRecordId,\n      traceId,\n      decision: decisionValue,\n      score: result.score,\n    };\n  } catch (error) {\n    const message = describeError(error);\n\n    logGreenlight('scoring_failed', { leadRecordId, error: message });\n\n    await flagUnscored(client, leadRecordId, person, now, message);\n\n    return { status: 'failed', leadRecordId, error: message };\n  }\n};\n\n/**\n * Last-ditch fail-open write. Each half is independently guarded: a lead left\n * with no flag is bad, a logic function that throws out to the platform because\n * its error handler also failed is worse.\n */\nconst flagUnscored = async (\n  client: GreenlightApiClient,\n  leadRecordId: string,\n  person: Record<string, unknown>,\n  now: Date,\n  error: string,\n): Promise<void> => {\n  const traceId = buildTraceId(leadRecordId, hash32(error));\n  const leadDisplayName = readLeadDisplayName(person);\n\n  const tracePayload = {\n    traceId,\n    // No fingerprint: an errored run must not suppress the next attempt.\n    engineVersion: SCORING_ENGINE_VERSION,\n    scoredAt: now.toISOString(),\n    score: null,\n    band: 'UNSCORED',\n    decision: 'UNSCORED',\n    summary:\n      'Greenlight could not score this lead. It has been passed through unscored and flagged for review.',\n    reasons: [error],\n    rules: [],\n  };\n\n  try {\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: {\n            name: `ERROR \u00B7 ${leadDisplayName} \u00B7 \u2014`,\n            eventType: 'ERROR',\n            occurredAt: now.toISOString(),\n            leadObjectNameSingular: 'person',\n            leadRecordId,\n            leadDisplayName,\n            actorType: 'SYSTEM',\n            actorDisplayName: `Greenlight engine ${SCORING_ENGINE_VERSION}`,\n            ruleTrace: tracePayload,\n            score: null,\n            band: 'UNSCORED',\n            decision: 'UNSCORED',\n            overrideReason: '',\n            traceId,\n          },\n        },\n        id: true,\n      },\n    });\n  } catch (auditError) {\n    logGreenlight('fail_open_audit_write_failed', {\n      leadRecordId,\n      error: describeError(auditError),\n    });\n  }\n\n  try {\n    await client.mutation({\n      updatePerson: {\n        __args: {\n          id: leadRecordId,\n          data: {\n            greenlightDecision: 'UNSCORED',\n            greenlightTrace: tracePayload,\n          },\n        },\n        id: true,\n      },\n    });\n  } catch (updateError) {\n    logGreenlight('fail_open_person_write_failed', {\n      leadRecordId,\n      error: describeError(updateError),\n    });\n  }\n};\n", "/**\n * The I/O half of the backfill, kept out of the `define*` files so the whole\n * resume-after-crash story can be exercised against a fake API client and a fake\n * key-value store.\n *\n * Everything about *what* to read is in `src/backfill/backfill-plan.ts` and\n * everything about *where the walk has got to* is in\n * `src/backfill/backfill-state.ts`, both pure. This module reads state, fetches a\n * page, calls the existing scoring run once per record, and writes the position\n * back. The only impure things it touches are the client, the store and the `now`\n * it is handed \u2014 plus one elapsed-time reading, injected, so a test can make the\n * tick run out of budget without waiting forty seconds.\n *\n * ## Why a cron rather than the alternatives\n *\n * **Not inline in the post-install hook.** A 10,000-contact workspace at 100\n * requests a minute needs hours. The hook would time out, and the platform would\n * retry it \u2014 from the beginning, three times, each attempt re-walking whatever\n * the last one managed. That is not a slow backfill, it is a backfill that can\n * never finish and that spends its whole life re-scoring the first few hundred\n * records.\n *\n * **Not a self-enqueueing chain** (`enqueueJob` with a delay, each chunk booking\n * the next). Tempting, and it would pace itself precisely. But the chain has\n * exactly one thread of liveness: if any single link fails to enqueue \u2014 a\n * transient error in the one call that is not retried, because it *is* the retry\n * \u2014 the run stops silently and forever, and nothing in the system is left to\n * notice. A backfill that can die quietly is the same class of defect as a\n * scoring trigger that never fires on existing records. Fixing invisibility with\n * something else invisible is not a fix.\n *\n * **A cron draining a durable cursor.** The schedule is owned by the platform,\n * not by the job, so liveness is supplied from outside: every minute, something\n * asks \"is there work?\" whatever happened last time. A crashed tick costs one\n * lease and nothing else. And because progress lives in storage rather than in an\n * in-flight process, \"is a backfill running and how far has it got\" is a question\n * that can be *answered* \u2014 by the cron, by the admin panel, and by the next tick\n * \u2014 instead of inferred from the absence of a log line.\n *\n * The cost is that the cron ticks forever on workspaces with no backfill running.\n * That tick is one key-value read which returns null. It is the cheapest possible\n * price for the property that matters.\n *\n * ## Never throwing\n *\n * No path here throws out to the platform. A tick that fails releases its lease,\n * records the reason where the panel can show it, and returns; the next tick\n * tries again. A *record* that fails is logged and skipped \u2014 `runPersonScoring`\n * has already flagged it `UNSCORED` with an ERROR audit row on the way out, which\n * is ARCHITECTURE.md's golden rule doing its job. One bad record must not stall\n * the queue, and in `unscored` mode it cannot even be retried into a loop: the\n * fail-open write moves it off `greenlightDecision is NULL`, so it leaves the\n * queue by being flagged rather than by being fixed.\n */\n\nimport {\n  advanceCursor,\n  BACKFILL_CHUNK_SIZE,\n  BACKFILL_TICK_BUDGET_MS,\n  buildCountRequest,\n  buildPageRequest,\n  backfillPersonSelection,\n  configuredSelectionFields,\n  isAlreadyHandled,\n  PAGE_ATTEMPTS,\n  pageSizeFor,\n  readTotalCount,\n  toScoringEvent,\n} from 'src/backfill/backfill-plan';\nimport {\n  buildFieldExistenceProbe,\n  classifyProbeRejection,\n  describeFieldMappingFindings,\n  EMPTY_FIELD_MAPPING_CHECK,\n  fieldMappingAuditDetail,\n  fieldMappingAuditName,\n  FIELD_MAPPING_PROBE_LIMIT,\n  mappedFieldNames,\n  probeAnswered,\n  type FieldMappingCheckResult,\n  type FieldProbeVerdict,\n  type MappingFinding,\n} from 'src/backfill/field-mapping-check';\nimport {\n  beginBackfill,\n  cancelBackfill as cancelBackfillState,\n  claimLease,\n  commitChunk,\n  describeBackfill,\n  EMPTY_TALLY,\n  isLeaseHeld,\n  releaseLease,\n  toBackfillState,\n  type BackfillCursor,\n  type BackfillMode,\n  type BackfillProgress,\n  type BackfillState,\n  type BackfillTally,\n} from 'src/backfill/backfill-state';\nimport {\n  describeError,\n  logGreenlight,\n  readConnectionNodes,\n  type GreenlightApiClient,\n} from 'src/logic-functions/greenlight-api';\nimport {\n  type CalibrationReaderPort,\n  type CalibrationSealPort,\n} from 'src/calibration';\nimport { readLeadObjectNameSingular } from 'src/logic-functions/greenlight-config-record';\nimport {\n  loadConfigRecord,\n  runPersonScoring,\n  type ReleaseMarkerStore,\n} from 'src/logic-functions/scoring-run';\nimport { SCORING_ENGINE_VERSION } from 'src/scoring';\n\n/* -------------------------------------------------------------------------- */\n/* Ports                                                                       */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The slice of app key-value storage the backfill needs, as a port \u2014 same shape\n * and same justification as `ReleaseMarkerStore` in `scoring-run.ts`.\n * `src/logic-functions/backfill-state-store.ts` holds the one real implementation.\n */\nexport interface BackfillStateStore {\n  read(): Promise<unknown>;\n  write(state: BackfillState): Promise<void>;\n}\n\nexport interface BackfillDeps {\n  readonly client: GreenlightApiClient;\n  readonly store: BackfillStateStore;\n  readonly now: Date;\n  /**\n   * Elapsed-time source for the tick budget, injected so a test can expire the\n   * budget instantly. `now` cannot serve: it is a fixed instant on purpose, and\n   * the whole point of the budget is that real time passes during a chunk.\n   */\n  readonly clock?: () => number;\n}\n\nexport interface BackfillChunkDeps extends BackfillDeps {\n  readonly markers: ReleaseMarkerStore;\n  /**\n   * Read-only calibration cache, passed straight through to each record's\n   * scoring run so a bulk pass calibrates identically to a live event. Omitted\n   * means shipped defaults, which is what an unlicensed backfill has always\n   * produced.\n   */\n  readonly calibration?: CalibrationReaderPort | null;\n  /** Checks the cached calibration belongs to this workspace's licence key. */\n  readonly calibrationSeal?: CalibrationSealPort;\n  /** Overridden only by tests; production uses the rate-limit-derived default. */\n  readonly chunkSize?: number;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Shared helpers                                                              */\n/* -------------------------------------------------------------------------- */\n\nconst readState = async (\n  store: BackfillStateStore,\n): Promise<{ ok: true; state: BackfillState | null } | { ok: false; error: string }> => {\n  try {\n    return { ok: true, state: toBackfillState(await store.read()) };\n  } catch (error) {\n    return { ok: false, error: describeError(error) };\n  }\n};\n\n/** Best effort. A count drives a progress bar; it must never stop a run. */\nconst countMatching = async (\n  client: GreenlightApiClient,\n  mode: BackfillMode,\n): Promise<number | null> => {\n  try {\n    return readTotalCount(await client.query(buildCountRequest(mode)));\n  } catch (error) {\n    logGreenlight('backfill_count_failed', { mode, error: describeError(error) });\n\n    return null;\n  }\n};\n\n/**\n * A run-level row in the audit log, so \"was this workspace ever backfilled, and\n * when\" survives the key-value blob and is answerable from inside the CRM.\n *\n * Filed under `BACKFILL`, which the object's `eventType` SELECT now carries. It\n * used to borrow `CONFIG_CHANGED` \u2014 the precedent `install-run.ts` set for a\n * lifecycle event that is not about one lead \u2014 because appending a SELECT option\n * belonged to another workstream. It does not any more: a backfill is not a\n * configuration change, and an admin filtering for \"what did this workspace do\n * in bulk\" should not have to read row names to find out.\n *\n * Existing `CONFIG_CHANGED` rows are left exactly as written. Option identity in\n * Twenty derives from the option `value`, so appending disturbed nothing, and a\n * row that recorded what it recorded at the time is not something to rewrite.\n *\n * Swallows every failure, like its counterpart in `install-run.ts`: a missing\n * provenance row is not worth failing a backfill over.\n *\n * `eventType` is a parameter with a default rather than a constant because this\n * module files rows of two kinds. A backfill starting, progressing and finishing\n * is `BACKFILL`. A configured field name that does not exist is not a backfill\n * event at all \u2014 it is a fault an admin has to act on, and an admin filtering the\n * audit log for faults filters for `ERROR`. Making it share `BACKFILL` would bury\n * the one row in this app that says \"your scores are wrong\" underneath the\n * routine ones that say \"bulk scoring happened\", which is the same argument the\n * object's own `eventType` comment makes about SUPPRESSED and UNSUPPRESSED.\n */\nconst writeBackfillAuditRow = async (\n  client: GreenlightApiClient,\n  now: Date,\n  summary: string,\n  detail: Record<string, unknown>,\n  eventType: 'BACKFILL' | 'ERROR' = 'BACKFILL',\n): Promise<void> => {\n  try {\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: {\n            name: summary,\n            eventType,\n            occurredAt: now.toISOString(),\n            leadObjectNameSingular: '',\n            leadRecordId: null,\n            leadDisplayName: '',\n            actorType: 'SYSTEM',\n            actorDisplayName: `Greenlight backfill ${SCORING_ENGINE_VERSION}`,\n            ruleTrace: detail,\n            score: null,\n            band: 'UNSCORED',\n            decision: 'UNSCORED',\n            overrideReason: '',\n            traceId: String(detail['runId'] ?? ''),\n          },\n        },\n        id: true,\n      },\n    });\n  } catch (error) {\n    logGreenlight('backfill_audit_write_failed', {\n      summary,\n      error: describeError(error),\n    });\n  }\n};\n\n/* -------------------------------------------------------------------------- */\n/* Does the configured field mapping name fields that exist?                   */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The connection the backfill actually walks, and what to call it on screen.\n *\n * Hard-coded rather than derived from `leadObjectNameSingular`, and deliberately:\n * `buildPageRequest` walks `people` and nothing else, and v0.1 writes score,\n * decision and trace fields to Person only. Probing whichever object the SELECT\n * happens to name would ask about a schema this run is not going to read, and\n * would tell an admin their mapping is fine for records that are not being\n * scored at all. The configured object name still reaches the audit row, where\n * \"which object did it mean\" is a question worth being able to answer.\n */\nconst LEAD_CONNECTION = 'people';\nconst LEAD_OBJECT_LABEL = 'Person';\n\n/**\n * One name, one question, in the half of a query Twenty validates.\n *\n * A response that came back but carries no connection is `inconclusive`, not\n * `absent`: see `probeAnswered`. Every rejection is handed to the pure\n * classifier, which is where the decision to stay quiet unless certain lives.\n */\nconst probeFieldExists = async (\n  client: GreenlightApiClient,\n  fieldName: string,\n): Promise<FieldProbeVerdict> => {\n  try {\n    const response = await client.query(\n      buildFieldExistenceProbe(LEAD_CONNECTION, fieldName),\n    );\n\n    return probeAnswered(LEAD_CONNECTION, response) ? 'present' : 'inconclusive';\n  } catch (error) {\n    return classifyProbeRejection(fieldName, describeError(error));\n  }\n};\n\n/**\n * Ask about every configured name, one at a time.\n *\n * Serial rather than `Promise.all`, for the same reason `icp-run.ts` probes\n * serially: eight simultaneous requests is a burst against a per-minute ceiling\n * the live scoring path is also drawing on, and there is nothing to hurry for \u2014\n * this runs once, on a click, before a job that will take hours.\n *\n * Exported so the check can be unit-tested against a fake client without going\n * through a whole run.\n */\nexport const checkFieldMapping = async (\n  client: GreenlightApiClient,\n  configRecord: unknown,\n): Promise<FieldMappingCheckResult> => {\n  const mapped = mappedFieldNames(configRecord);\n  const asked = mapped.slice(0, FIELD_MAPPING_PROBE_LIMIT);\n\n  const missing: MappingFinding[] = [];\n  let inconclusive = 0;\n\n  for (const candidate of asked) {\n    const verdict = await probeFieldExists(client, candidate.name);\n\n    if (verdict === 'absent') {\n      missing.push(candidate);\n    } else if (verdict === 'inconclusive') {\n      inconclusive += 1;\n    }\n  }\n\n  return {\n    missing,\n    probed: asked.length,\n    inconclusive,\n    unchecked: mapped.length - asked.length,\n  };\n};\n\n/**\n * The whole check, wrapped so that it cannot cost the caller anything.\n *\n * Reads the config record itself rather than taking one, because the only caller\n * is `startBackfill`, which has no reason to hold a config otherwise \u2014 and\n * because the read has to be inside the `try` that makes this fail-open. If\n * anything at all goes wrong, from the config read to the last probe, the result\n * is the empty one: no findings, no notice, no audit row, and a backfill that\n * behaves precisely as it did before this check existed.\n *\n * That is the ordering rule the whole feature is built on. A validation that can\n * break scoring is worse than the defect it was written to catch.\n */\nconst runFieldMappingCheck = async (\n  client: GreenlightApiClient,\n): Promise<{\n  readonly result: FieldMappingCheckResult;\n  readonly configRecord: Record<string, unknown> | null;\n}> => {\n  try {\n    const configRecord = await loadConfigRecord(client);\n\n    return {\n      result: await checkFieldMapping(client, configRecord),\n      configRecord,\n    };\n  } catch (error) {\n    logGreenlight('backfill_field_mapping_check_failed', {\n      error: describeError(error),\n    });\n\n    return { result: EMPTY_FIELD_MAPPING_CHECK, configRecord: null };\n  }\n};\n\n/* -------------------------------------------------------------------------- */\n/* One tick                                                                    */\n/* -------------------------------------------------------------------------- */\n\nexport type BackfillChunkOutcome =\n  /** No run has ever been requested on this workspace. */\n  | { status: 'no_run' }\n  /** A run exists but is finished, cancelled or failed. */\n  | { status: 'not_running'; runStatus: BackfillState['status'] }\n  /** Another tick is mid-chunk. */\n  | { status: 'locked'; leaseUntil: string | null }\n  | { status: 'state_unreadable'; error: string }\n  | { status: 'lease_not_taken'; error: string }\n  | { status: 'config_unavailable'; error: string }\n  | { status: 'page_failed'; error: string }\n  | {\n      status: 'progressed';\n      runId: string;\n      tally: BackfillTally;\n      exhausted: boolean;\n      degraded: boolean;\n    };\n\ninterface PageResult {\n  readonly nodes: Record<string, unknown>[];\n  /** False on the fallback rung that drops ordering and the cursor together. */\n  readonly ordered: boolean;\n  readonly degraded: boolean;\n}\n\n/**\n * Walk `PAGE_ATTEMPTS` until one rung answers. See that constant for why each\n * rung exists; the `all`-mode filter below is why the last one is skipped there.\n */\nconst fetchPage = async (\n  client: GreenlightApiClient,\n  state: BackfillState,\n  chunkSize: number,\n  extraFields: readonly string[],\n): Promise<{ ok: true; page: PageResult } | { ok: false; error: string }> => {\n  const attempts = PAGE_ATTEMPTS.filter(\n    (attempt) => attempt.ordered || state.mode === 'unscored',\n  );\n\n  let lastError = 'no page attempt was made';\n\n  for (const [index, attempt] of attempts.entries()) {\n    const selection = backfillPersonSelection(\n      attempt.useExtraFields ? extraFields : [],\n    );\n\n    try {\n      const response = await client.query(\n        buildPageRequest({\n          mode: state.mode,\n          cursor: state.cursor,\n          chunkSize,\n          selection,\n          ordered: attempt.ordered,\n        }),\n      );\n\n      return {\n        ok: true,\n        page: {\n          nodes: readConnectionNodes(response, 'people'),\n          ordered: attempt.ordered,\n          degraded: index > 0,\n        },\n      };\n    } catch (error) {\n      lastError = describeError(error);\n\n      logGreenlight('backfill_page_attempt_failed', {\n        runId: state.runId,\n        mode: state.mode,\n        attempt: index,\n        ordered: attempt.ordered,\n        useExtraFields: attempt.useExtraFields,\n        error: lastError,\n      });\n    }\n  }\n\n  return { ok: false, error: lastError };\n};\n\n/**\n * Score one bounded chunk and record where the walk reached. Never throws.\n *\n * The ordering of the steps is the resumability argument, so it is worth stating\n * flatly:\n *\n *   1. Read the state. No run, or not `running` \u2014 return.\n *   2. Refuse if another tick holds the lease.\n *   3. Take the lease **and write it** before touching a single record. A tick\n *      that cannot record that it started must not start.\n *   4. Read the config once for the whole chunk. A failure here **abandons the\n *      tick** rather than falling back to engine defaults: the event path treats\n *      an unreadable config as a per-lead fail-open, which is right for one lead,\n *      but scoring thirty leads against defaults a workspace has deliberately\n *      moved away from would bulk-gate or bulk-pass them on configuration nobody\n *      chose. A minute of delay costs nothing; thirty wrong decisions do.\n *   5. Fetch the page, degrading through `PAGE_ATTEMPTS`.\n *   6. Score records in order, stopping when the tick budget runs out, and build\n *      the *prefix actually reached* as we go.\n *   7. Commit: advance the cursor over that prefix only, fold in the tally,\n *      release the lease.\n *\n * A crash anywhere in 4-6 leaves the cursor exactly where step 3 found it, so the\n * next tick after the lease expires re-fetches the same page. Records the crashed\n * tick had already scored are re-scored \u2014 and write nothing, because guard 3\n * recognises the stored fingerprint. That is the whole of the crash story: at\n * most one chunk of duplicated *reads*, never a duplicated write, never a\n * duplicated audit row, and never a skipped record.\n */\nexport const runBackfillChunk = async ({\n  client,\n  store,\n  markers,\n  calibration,\n  calibrationSeal,\n  now,\n  clock = () => Date.now(),\n  chunkSize = BACKFILL_CHUNK_SIZE,\n}: BackfillChunkDeps): Promise<BackfillChunkOutcome> => {\n  const read = await readState(store);\n\n  if (!read.ok) {\n    logGreenlight('backfill_state_unreadable', { error: read.error });\n\n    return { status: 'state_unreadable', error: read.error };\n  }\n\n  const state = read.state;\n\n  if (state === null) {\n    return { status: 'no_run' };\n  }\n\n  if (state.status !== 'running') {\n    return { status: 'not_running', runStatus: state.status };\n  }\n\n  if (isLeaseHeld(state, now)) {\n    return { status: 'locked', leaseUntil: state.leaseUntil };\n  }\n\n  const claimed = claimLease(state, now);\n\n  try {\n    await store.write(claimed);\n  } catch (error) {\n    const message = describeError(error);\n\n    logGreenlight('backfill_lease_write_failed', {\n      runId: state.runId,\n      error: message,\n    });\n\n    return { status: 'lease_not_taken', error: message };\n  }\n\n  const commit = async (\n    cursor: BackfillCursor,\n    tally: BackfillTally,\n    lastError: string | null,\n    exhausted: boolean,\n    stalled: boolean,\n  ): Promise<void> => {\n    const next = commitChunk(claimed, {\n      now,\n      cursor,\n      tally,\n      lastError,\n      exhausted,\n      stalled,\n    });\n\n    try {\n      await store.write(next);\n    } catch (error) {\n      // Nothing to be done but say so. The lease expires on its own, and the\n      // chunk that was not recorded is simply redone \u2014 which writes nothing.\n      logGreenlight('backfill_commit_failed', {\n        runId: state.runId,\n        error: describeError(error),\n      });\n\n      return;\n    }\n\n    if (exhausted) {\n      logGreenlight('backfill_completed', {\n        runId: next.runId,\n        mode: next.mode,\n        ...next.tally,\n        chunks: next.chunks,\n      });\n\n      await writeBackfillAuditRow(\n        client,\n        now,\n        `BACKFILL \u00B7 Greenlight backfill finished \u00B7 ${next.tally.examined} records examined`,\n        {\n          action: 'backfill_completed',\n          runId: next.runId,\n          mode: next.mode,\n          startedAt: next.startedAt,\n          finishedAt: next.finishedAt,\n          chunks: next.chunks,\n          ...next.tally,\n          engineVersion: SCORING_ENGINE_VERSION,\n        },\n      );\n    }\n  };\n\n  const abandon = async (lastError: string): Promise<void> => {\n    try {\n      await store.write(releaseLease(claimed, now, lastError));\n    } catch (error) {\n      logGreenlight('backfill_release_failed', {\n        runId: state.runId,\n        error: describeError(error),\n      });\n    }\n  };\n\n  let configRecord: Record<string, unknown> | null;\n\n  try {\n    configRecord = await loadConfigRecord(client);\n  } catch (error) {\n    const message = describeError(error);\n\n    logGreenlight('backfill_config_unavailable', {\n      runId: state.runId,\n      error: message,\n    });\n\n    await abandon(message);\n\n    return { status: 'config_unavailable', error: message };\n  }\n\n  const page = await fetchPage(\n    client,\n    state,\n    chunkSize,\n    configuredSelectionFields(configRecord),\n  );\n\n  if (!page.ok) {\n    await abandon(page.error);\n\n    return { status: 'page_failed', error: page.error };\n  }\n\n  const { nodes, ordered, degraded } = page.page;\n\n  const tally = { ...EMPTY_TALLY };\n  const handled: Record<string, unknown>[] = [];\n  const deadline = clock() + BACKFILL_TICK_BUDGET_MS;\n\n  for (const node of nodes) {\n    // The page is deliberately larger than the chunk \u2014 the surplus pays for\n    // skipping the cursor boundary, not for extra scoring. The rate arithmetic\n    // is sized on the chunk, so the chunk is what bounds the writes.\n    if (tally.examined >= chunkSize) {\n      break;\n    }\n\n    // At least one record is always attempted, so a clock that is already past\n    // the budget cannot stall the run forever.\n    if (tally.examined > 0 && clock() > deadline) {\n      break;\n    }\n\n    // Only meaningful on an ordered page: the boundary ids exist to stop `gte`\n    // re-processing records at the cursor's exact timestamp. The unordered rung\n    // has no cursor, and its filter already excludes anything scored.\n    if (ordered && isAlreadyHandled(state.cursor, node)) {\n      handled.push(node);\n      continue;\n    }\n\n    tally.examined += 1;\n\n    try {\n      const outcome = await runPersonScoring({\n        client,\n        event: toScoringEvent(node),\n        now,\n        markers,\n        // Read once per chunk, not once per record. The single largest saving in\n        // the whole design \u2014 see `PreloadedConfig` in `scoring-run.ts`.\n        config: { record: configRecord },\n        calibration,\n        calibrationSeal,\n      });\n\n      switch (outcome.status) {\n        case 'scored':\n          tally.scored += 1;\n          break;\n        case 'unchanged':\n          tally.unchanged += 1;\n          break;\n        case 'skipped':\n          tally.skipped += 1;\n          break;\n        default:\n          tally.failed += 1;\n          logGreenlight('backfill_record_failed', {\n            runId: state.runId,\n            leadRecordId: outcome.leadRecordId,\n            error: outcome.error,\n          });\n          break;\n      }\n    } catch (error) {\n      // `runPersonScoring` is documented never to throw, and it does not. This\n      // exists so that if it ever starts to, one malformed record costs one\n      // record rather than the whole queue.\n      tally.failed += 1;\n\n      logGreenlight('backfill_record_threw', {\n        runId: state.runId,\n        error: describeError(error),\n      });\n    }\n\n    handled.push(node);\n  }\n\n  // Only a page that came back short of what was asked for *and* was fully\n  // worked through proves there is nothing left. A page cut off by the chunk\n  // budget or the tick budget proves nothing.\n  const requested = ordered ? pageSizeFor(chunkSize, state.cursor) : chunkSize;\n  const exhausted =\n    nodes.length < requested && handled.length === nodes.length;\n\n  // Records came back and the tick got through none of them. See\n  // `BACKFILL_MAX_STALLS`: repeated, this is a walk that cannot advance, and it\n  // has to become visible rather than spin.\n  const stalled = nodes.length > 0 && tally.examined === 0;\n\n  const cursor = ordered ? advanceCursor(state.cursor, handled) : state.cursor;\n\n  await commit(\n    cursor,\n    tally,\n    degraded ? 'Ran with a reduced query. See logs.' : null,\n    exhausted,\n    stalled,\n  );\n\n  logGreenlight('backfill_chunk', {\n    runId: state.runId,\n    mode: state.mode,\n    requested,\n    fetched: nodes.length,\n    handled: handled.length,\n    ...tally,\n    exhausted,\n    stalled,\n    degraded,\n  });\n\n  return {\n    status: 'progressed',\n    runId: state.runId,\n    tally,\n    exhausted,\n    degraded,\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Control surface                                                             */\n/* -------------------------------------------------------------------------- */\n\nexport interface BackfillControlResult {\n  readonly status: number;\n  readonly body: {\n    readonly outcome: string;\n    readonly message: string;\n    /** Null when no backfill has ever been requested on this workspace. */\n    readonly run: BackfillProgress | null;\n    /** Person records with no Greenlight decision at all. Null if uncountable. */\n    readonly neverScoredCount: number | null;\n    /** So the panel can state the cadence without hard-coding it twice. */\n    readonly chunkSize: number;\n  };\n}\n\nconst control = (\n  status: number,\n  outcome: string,\n  message: string,\n  run: BackfillProgress | null,\n  neverScoredCount: number | null,\n): BackfillControlResult => ({\n  status,\n  body: {\n    outcome,\n    message,\n    run,\n    neverScoredCount,\n    chunkSize: BACKFILL_CHUNK_SIZE,\n  },\n});\n\n/**\n * What the admin panel renders.\n *\n * Deliberately answers all four questions in one round trip \u2014 how many are\n * unscored, is something running, how far has it got, when did it last finish \u2014\n * because a surface that needs three calls to tell you whether the gate is\n * working is a surface people stop opening.\n */\nexport const readBackfillStatus = async ({\n  client,\n  store,\n  now,\n}: BackfillDeps): Promise<BackfillControlResult> => {\n  const read = await readState(store);\n  const neverScoredCount = await countMatching(client, 'unscored');\n\n  if (!read.ok) {\n    return control(\n      200,\n      'state_unreadable',\n      'Greenlight could not read the backfill\u2019s progress. Scoring of new leads is unaffected. Try again, and start a backfill if this persists.',\n      null,\n      neverScoredCount,\n    );\n  }\n\n  if (read.state === null) {\n    return control(\n      200,\n      'no_run',\n      neverScoredCount === null || neverScoredCount === 0\n        ? 'No backfill has run on this workspace.'\n        : `No backfill has run on this workspace. ${neverScoredCount} people have never been scored \u2014 until they are, an empty gate queue does not mean they are clean.`,\n      null,\n      neverScoredCount,\n    );\n  }\n\n  return control(\n    200,\n    read.state.status,\n    '',\n    describeBackfill(read.state, now),\n    neverScoredCount,\n  );\n};\n\nexport interface StartBackfillInput extends BackfillDeps {\n  readonly mode: BackfillMode;\n  /** Server-derived. Never taken from the request body. */\n  readonly requestedBy: string;\n}\n\n/**\n * Begin a run, or refuse because one is already going.\n *\n * The refusal is a `200` carrying the running run's progress rather than a `409`:\n * the caller asked for a backfill and there is a backfill, so the honest answer\n * is to show them the one that exists. Starting a second would double the request\n * rate against a limit the first is already sized against.\n *\n * ============================================================================\n * ## Why the field-mapping check happens here\n *\n * A configured field name that does not exist comes back `null` rather than\n * failing anything (`field-mapping-check.ts` has the whole story). Somewhere has\n * to notice. Four places could:\n *\n *   - **On the per-record scoring path.** Never. Scoring one lead must not gain a\n *     schema round trip to answer a question whose answer changes about once a\n *     year. The mapping changes rarely; that path runs constantly.\n *   - **On each backfill tick.** Same objection in slower motion. A run is\n *     thousands of ticks, the answer is identical on every one of them, and the\n *     probes would be spent against the same per-minute ceiling the chunk\n *     arithmetic already budgets 62 of.\n *   - **On the config record's write path.** There is no such path to hook. The\n *     record is edited by a human on Twenty's own record page and this app\n *     registers no database-event function against it; adding one would mean a\n *     schema probe on every field save, and it would still say nothing about the\n *     workspaces that were already mis-configured before this shipped.\n *   - **On the panel's status poll.** The panel polls `readBackfillStatus` while\n *     a run is going. A probe there is a schema query every few seconds, for a\n *     fact that has not moved.\n *\n * **Here**, once per run, is the moment the question is actually being asked:\n * this is where a whole workspace gets scored against this mapping in one go, so\n * it is where a wrong mapping does its damage all at once. It is also the moment\n * an admin is looking \u2014 they pressed Start and are reading the reply. And because\n * `requestInstallBackfill` routes through this function, install and upgrade are\n * covered by the same code without a second implementation, as is the re-score\n * `icp-run.ts` kicks off after a profile is applied.\n *\n * ## What it costs\n *\n * One config read plus one `first: 1` query per configured name, capped at\n * `FIELD_MAPPING_PROBE_LIMIT`, once, on a human's click. A stock workspace has a\n * single configured name (`decisionMakerFieldName`, seeded `jobTitle`), so the\n * usual bill is two requests before a job that will run for hours. Nothing here\n * is on a schedule and nothing here can fail the start.\n */\nexport const startBackfill = async ({\n  client,\n  store,\n  now,\n  mode,\n  requestedBy,\n}: StartBackfillInput): Promise<BackfillControlResult> => {\n  const read = await readState(store);\n\n  if (read.ok && read.state !== null && read.state.status === 'running') {\n    return control(\n      200,\n      'already_running',\n      'A backfill is already running. Watch its progress here, or stop it first if you need to change the mode.',\n      describeBackfill(read.state, now),\n      await countMatching(client, 'unscored'),\n    );\n  }\n\n  const totalAtStart = await countMatching(client, mode);\n  const state = beginBackfill({ mode, now, requestedBy, totalAtStart });\n\n  try {\n    await store.write(state);\n  } catch (error) {\n    const message = describeError(error);\n\n    logGreenlight('backfill_start_failed', { mode, error: message });\n\n    return control(\n      502,\n      'start_failed',\n      `Greenlight could not record the backfill, so it did not start one. Nothing has changed. (${message})`,\n      null,\n      totalAtStart,\n    );\n  }\n\n  logGreenlight('backfill_started', {\n    runId: state.runId,\n    mode,\n    requestedBy,\n    totalAtStart,\n  });\n\n  // After the run is recorded, never before. A configured name that does not\n  // exist is a reason to tell somebody, not a reason to refuse to start: the\n  // backfill still fills in blanks, still respects suppression, and still leaves\n  // the workspace better off than the unscored state it was in. Refusing would\n  // trade a quiet defect for a loud one.\n  const mapping = await runFieldMappingCheck(client);\n  const mappingNotice = describeFieldMappingFindings(\n    mapping.result.missing,\n    LEAD_OBJECT_LABEL,\n  );\n\n  if (mapping.result.missing.length > 0) {\n    const detail = {\n      ...fieldMappingAuditDetail(\n        mapping.result,\n        readLeadObjectNameSingular(mapping.configRecord),\n      ),\n      runId: state.runId,\n      mode,\n      requestedBy,\n      engineVersion: SCORING_ENGINE_VERSION,\n    };\n\n    logGreenlight('backfill_field_mapping_missing', detail);\n\n    await writeBackfillAuditRow(\n      client,\n      now,\n      fieldMappingAuditName(mapping.result.missing, LEAD_OBJECT_LABEL),\n      detail,\n      'ERROR',\n    );\n  } else if (mapping.result.inconclusive > 0 || mapping.result.unchecked > 0) {\n    // Nothing an admin can act on, so nothing an admin is shown. Logged because\n    // \"the check ran and could not answer\" and \"the check ran and found nothing\n    // wrong\" are different states, and support should not have to guess which\n    // one a quiet run was in.\n    logGreenlight('backfill_field_mapping_unverified', {\n      runId: state.runId,\n      probed: mapping.result.probed,\n      inconclusive: mapping.result.inconclusive,\n      unchecked: mapping.result.unchecked,\n    });\n  }\n\n  await writeBackfillAuditRow(\n    client,\n    now,\n    `BACKFILL \u00B7 Greenlight backfill started \u00B7 ${mode}`,\n    {\n      action: 'backfill_started',\n      runId: state.runId,\n      mode,\n      requestedBy,\n      totalAtStart,\n      chunkSize: BACKFILL_CHUNK_SIZE,\n      engineVersion: SCORING_ENGINE_VERSION,\n      fieldMappingChecked: mapping.result.probed,\n      fieldMappingMissing: mapping.result.missing.length,\n    },\n  );\n\n  const started =\n    totalAtStart === null\n      ? 'Backfill started. It runs about one batch a minute in the background; you can close this panel.'\n      : `Backfill started over ${totalAtStart} records. It runs ${BACKFILL_CHUNK_SIZE} a minute in the background; you can close this panel.`;\n\n  return control(\n    200,\n    'started',\n    // The notice leads. The confirmation ends with \"you can close this panel\",\n    // and a warning placed after that sentence is a warning nobody reads.\n    mappingNotice === null ? started : `${mappingNotice} ${started}`,\n    describeBackfill(state, now),\n    await countMatching(client, 'unscored'),\n  );\n};\n\nexport const stopBackfill = async ({\n  client,\n  store,\n  now,\n  requestedBy,\n}: BackfillDeps & { requestedBy: string }): Promise<BackfillControlResult> => {\n  const read = await readState(store);\n  const neverScoredCount = await countMatching(client, 'unscored');\n\n  if (!read.ok || read.state === null) {\n    return control(\n      200,\n      'no_run',\n      'There is no backfill to stop.',\n      null,\n      neverScoredCount,\n    );\n  }\n\n  if (read.state.status !== 'running') {\n    return control(\n      200,\n      'not_running',\n      'That backfill is not running any more.',\n      describeBackfill(read.state, now),\n      neverScoredCount,\n    );\n  }\n\n  const cancelled = cancelBackfillState(read.state, now, requestedBy);\n\n  try {\n    await store.write(cancelled);\n  } catch (error) {\n    return control(\n      502,\n      'stop_failed',\n      `Greenlight could not stop the backfill. (${describeError(error)})`,\n      describeBackfill(read.state, now),\n      neverScoredCount,\n    );\n  }\n\n  logGreenlight('backfill_cancelled', {\n    runId: cancelled.runId,\n    requestedBy,\n    ...cancelled.tally,\n  });\n\n  return control(\n    200,\n    'stopped',\n    'Backfill stopped. Records already scored keep their scores; the rest are untouched. Starting again begins from the beginning, which is cheap \u2014 records that are already scored are recognised and left alone.',\n    describeBackfill(cancelled, now),\n    neverScoredCount,\n  );\n};\n\n/* -------------------------------------------------------------------------- */\n/* The install entry point                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Request the automatic first backfill. **This is the only function the\n * post-install hook needs to call.**\n *\n * ## Idempotency across install *and* upgrade\n *\n * The post-install hook runs on a fresh install, on every version upgrade\n * (`shouldRunOnVersionUpgrade: true`), and up to three times on each of those\n * because the async queue retries. So the question is not \"has a backfill run\",\n * it is \"has one ever been *requested*\" \u2014 and the presence of any state at all,\n * in any status, is the durable answer. A completed run, a cancelled run and a\n * run still going all mean the same thing here: a human has been given the\n * surface, do not start another behind their back.\n *\n * That deliberately includes a run somebody cancelled. Re-starting a backfill an\n * admin stopped, on the next patch release, is the app overruling a decision it\n * was told about. If they want another they can start one; the panel is one\n * command away and says exactly how many records are still unscored.\n *\n * ## Why `unscored` and never `all`\n *\n * An install-triggered `all` would rewrite `greenlightDecision` on every record in\n * the workspace, including ones a rep has already worked from \u2014 on an upgrade,\n * without anyone asking. `unscored` only ever fills in a blank, and a blank is\n * unambiguously wrong: nothing has looked at that lead.\n *\n * ## Never throws\n *\n * The post-install hook deliberately does not catch, so that a transient failure\n * is retried by the platform. That is right for seeding the config, which is what\n * that hook is *for*. It is not right for this: a backfill that could not be\n * requested must not fail the install or burn the hook's three retries, because\n * the workspace is perfectly functional without it and the admin can start one by\n * hand. Every failure below is logged and swallowed.\n */\nexport const requestInstallBackfill = async ({\n  client,\n  store,\n  now,\n}: BackfillDeps): Promise<\n  | { status: 'requested'; runId: string; totalAtStart: number | null }\n  | { status: 'already_requested'; runStatus: BackfillState['status'] }\n  | { status: 'nothing_to_do' }\n  | { status: 'failed'; error: string }\n> => {\n  try {\n    const read = await readState(store);\n\n    if (!read.ok) {\n      logGreenlight('backfill_install_state_unreadable', { error: read.error });\n\n      return { status: 'failed', error: read.error };\n    }\n\n    if (read.state !== null) {\n      logGreenlight('backfill_install_skipped', {\n        reason: 'already_requested',\n        runId: read.state.runId,\n        runStatus: read.state.status,\n      });\n\n      return { status: 'already_requested', runStatus: read.state.status };\n    }\n\n    const totalAtStart = await countMatching(client, 'unscored');\n\n    // A fresh workspace with nothing to walk gets no run and no audit row. The\n    // cron would finish it on the first tick anyway; not starting is tidier and\n    // leaves the panel saying \"no backfill has run\", which is true and correct.\n    if (totalAtStart === 0) {\n      logGreenlight('backfill_install_skipped', {\n        reason: 'nothing_unscored',\n      });\n\n      return { status: 'nothing_to_do' };\n    }\n\n    const result = await startBackfill({\n      client,\n      store,\n      now,\n      mode: 'unscored',\n      requestedBy: 'install',\n    });\n\n    if (result.body.outcome !== 'started' || result.body.run === null) {\n      return { status: 'failed', error: result.body.outcome };\n    }\n\n    return {\n      status: 'requested',\n      runId: result.body.run.runId,\n      totalAtStart,\n    };\n  } catch (error) {\n    const message = describeError(error);\n\n    logGreenlight('backfill_install_request_failed', { error: message });\n\n    return { status: 'failed', error: message };\n  }\n};\n", "import { isNonEmptyString as e } from \"@sniptt/guards\";\n//#region src/logic-function/is-record-object-schema.ts\nvar t = (t) => (t?.type === \"record\" || t?.type === \"object\") && e(t.objectUniversalIdentifier);\n//#endregion\nexport { t };\n", "import { t as e } from \"./isDefined-Dtu5EYqP.mjs\";\nimport { t } from \"./is-record-object-schema-CwzshFdt.mjs\";\nimport { isNonEmptyString as n, isObject as r } from \"@sniptt/guards\";\n//#region src/logic-function/build-tool-input-json-schema.ts\nvar i = (e, t) => {\n\tlet r = n(e) ? t?.(e) : void 0;\n\treturn `Id of the ${n(r) ? r : \"linked\"} record`;\n}, a = (n, o) => {\n\tif (t(n)) return {\n\t\ttype: \"string\",\n\t\tdescription: i(n.objectUniversalIdentifier, o)\n\t};\n\tif (n.type === \"records\") return {\n\t\ttype: \"array\",\n\t\titems: {\n\t\t\ttype: \"string\",\n\t\t\tdescription: i(n.objectUniversalIdentifier, o)\n\t\t}\n\t};\n\tlet { objectUniversalIdentifier: s, multiline: c, label: l, items: u, properties: d, additionalProperties: f, ...p } = n, m = { ...p };\n\treturn e(u) && (m.items = a(u, o)), e(d) && (m.properties = Object.fromEntries(Object.entries(d).map(([e, t]) => [e, a(t, o)]))), e(f) && (m.additionalProperties = r(f) ? a(f, o) : f), m;\n}, o = {\n\ttype: \"object\",\n\tproperties: {}\n}, s = (e) => {\n\tlet t = { type: \"unknown\" };\n\tswitch (e.type) {\n\t\tcase \"string\":\n\t\t\tt.type = \"string\";\n\t\t\tbreak;\n\t\tcase \"number\":\n\t\tcase \"integer\":\n\t\t\tt.type = \"number\";\n\t\t\tbreak;\n\t\tcase \"boolean\":\n\t\t\tt.type = \"boolean\";\n\t\t\tbreak;\n\t\tcase \"array\":\n\t\t\tt.type = \"array\", e.items && (t.items = s(e.items));\n\t\t\tbreak;\n\t\tcase \"object\":\n\t\t\tt.type = \"object\", e.properties && (t.properties = Object.fromEntries(Object.entries(e.properties).map(([e, t]) => [e, s(t)])));\n\t\t\tbreak;\n\t\tcase \"record\":\n\t\t\tt.type = \"record\";\n\t\t\tbreak;\n\t\tcase \"records\":\n\t\t\tt.type = \"records\";\n\t\t\tbreak;\n\t\tdefault: t.type = \"unknown\";\n\t}\n\treturn Array.isArray(e.enum) && (t.enum = e.enum.filter((e) => typeof e == \"string\")), e.multiline === !0 && (t.multiline = !0), n(e.label) && (t.label = e.label), n(e.objectUniversalIdentifier) && (t.objectUniversalIdentifier = e.objectUniversalIdentifier), t;\n}, c = (e) => [s(e)], l = { inputSchema: c({\n\ttype: \"object\",\n\tproperties: {\n\t\ta: { type: \"string\" },\n\t\tb: { type: \"number\" }\n\t}\n}) }, u = async (t) => {\n\tlet { getFunctionInputSchema: n } = await import(\"./get-function-input-schema-GNk3NRLJ.mjs\"), r = n(t)[0];\n\treturn r?.type === \"object\" && e(r.properties) ? {\n\t\ttype: \"object\",\n\t\tproperties: r.properties\n\t} : o;\n}, d = (t) => !e(t) || t === null ? \"unknown\" : typeof t == \"string\" ? \"string\" : typeof t == \"number\" ? \"number\" : typeof t == \"boolean\" ? \"boolean\" : Array.isArray(t) ? \"array\" : \"unknown\", f = (e) => e ? Object.entries(e).reduce((e, [t, n]) => (r(n) && !Array.isArray(n) ? e[t] = {\n\tisLeaf: !1,\n\ttype: \"object\",\n\tlabel: t,\n\tvalue: f(n)\n} : e[t] = {\n\tisLeaf: !0,\n\tvalue: n,\n\ttype: d(n),\n\tlabel: t\n}, e), {}) : {}, p = (e, t) => e ? `${e}.${t}` : t, m = (t, n, r = \"\") => {\n\tlet i = [];\n\tfor (let [a, o] of Object.entries(n)) {\n\t\tlet n = p(r, a), s = t[a];\n\t\tif (!e(s)) {\n\t\t\ti.push(`Missing key \"${n}\" in declared output schema.`);\n\t\t\tcontinue;\n\t\t}\n\t\tif (o.isLeaf !== s.isLeaf) {\n\t\t\ti.push(`Type mismatch at \"${n}\": expected ${o.isLeaf ? o.type : \"object\"} but declared ${s.isLeaf ? s.type : \"object\"}.`);\n\t\t\tcontinue;\n\t\t}\n\t\tif (!o.isLeaf && !s.isLeaf) {\n\t\t\ti.push(...m(s.value, o.value, n));\n\t\t\tcontinue;\n\t\t}\n\t\to.isLeaf && s.isLeaf && o.type !== \"unknown\" && s.type !== \"unknown\" && o.type !== s.type && i.push(`Type mismatch at \"${n}\": expected ${o.type} but declared ${s.type}.`);\n\t}\n\treturn i;\n}, h = [\n\t\"string\",\n\t\"number\",\n\t\"boolean\",\n\t\"array\",\n\t\"unknown\"\n], g = (e) => h.includes(e), _ = (e, t) => {\n\tlet n = t.label ?? e;\n\treturn t.type === \"record\" ? {\n\t\tisLeaf: !0,\n\t\ttype: \"string\",\n\t\tlabel: n,\n\t\tvalue: null\n\t} : t.type === \"records\" ? {\n\t\tisLeaf: !0,\n\t\ttype: \"array\",\n\t\tlabel: n,\n\t\tvalue: null\n\t} : t.type === \"object\" ? {\n\t\tisLeaf: !1,\n\t\ttype: \"object\",\n\t\tlabel: n,\n\t\tvalue: r(t.properties) ? v(t.properties) : {}\n\t} : {\n\t\tisLeaf: !0,\n\t\ttype: g(t.type) ? t.type : \"unknown\",\n\t\tlabel: n,\n\t\tvalue: null\n\t};\n}, v = (e) => Object.entries(e).reduce((e, [t, n]) => (e[t] = _(t, n), e), {}), y = (e) => {\n\tlet t = e[0];\n\treturn t?.type !== \"object\" || !r(t.properties) ? {} : v(t.properties);\n}, b = (e) => e?.type === \"records\" && n(e.objectUniversalIdentifier) || e?.type === \"array\" && t(e?.items);\n//#endregion\nexport { o as DEFAULT_TOOL_INPUT_SCHEMA, l as SEED_WORKFLOW_ACTION_TRIGGER_SETTINGS, a as buildToolInputJsonSchema, u as getInputSchemaFromSourceCode, f as getOutputSchemaFromValue, m as getOutputSchemaMismatchIssues, y as inputSchemaToOutputSchema, b as isRecordArraySchema, t as isRecordObjectSchema, c as jsonSchemaToInputSchema };\n", "// Thrown when the platform asks the SDK to operate on a connection whose\n// OAuth refresh failed permanently (`authFailedAt` is set). The end user\n// must reconnect from the app's settings tab — the app cannot recover on\n// its own.\n//\n// `listConnections` filters these out by default (the user can't act on\n// them anyway). `getConnection` throws this when the looked-up connection\n// is in this state, so a stored connection id can be safely retried until\n// it works again.\nexport class AppConnectionAuthFailedError extends Error {\n  readonly connectionId: string;\n\n  constructor(connectionId: string) {\n    super(\n      `App connection ${connectionId} requires the user to reconnect ` +\n        `(authFailedAt is set). Surface a \"Reconnect\" prompt in your UI.`,\n    );\n    this.name = 'AppConnectionAuthFailedError';\n    this.connectionId = connectionId;\n  }\n}\n", "//#region src/types/FieldMetadataType.ts\nvar e = /* @__PURE__ */ function(e) {\n\treturn e.ACTOR = \"ACTOR\", e.ADDRESS = \"ADDRESS\", e.ARRAY = \"ARRAY\", e.BOOLEAN = \"BOOLEAN\", e.CURRENCY = \"CURRENCY\", e.DATE = \"DATE\", e.DATE_TIME = \"DATE_TIME\", e.EMAILS = \"EMAILS\", e.FILES = \"FILES\", e.FULL_NAME = \"FULL_NAME\", e.LINKS = \"LINKS\", e.MORPH_RELATION = \"MORPH_RELATION\", e.MULTI_SELECT = \"MULTI_SELECT\", e.NUMBER = \"NUMBER\", e.NUMERIC = \"NUMERIC\", e.PHONES = \"PHONES\", e.POSITION = \"POSITION\", e.RATING = \"RATING\", e.RAW_JSON = \"RAW_JSON\", e.RELATION = \"RELATION\", e.RICH_TEXT = \"RICH_TEXT\", e.SELECT = \"SELECT\", e.TEXT = \"TEXT\", e.TS_VECTOR = \"TS_VECTOR\", e.UUID = \"UUID\", e;\n}({});\n//#endregion\nexport { e as t };\n", "import { v5 as e } from \"uuid\";\n//#region src/application/constants/TwentyStandardApplicationUniversalIdentifier.ts\nvar t = \"20202020-64aa-4b6f-b003-9c74b97cee20\", n = ({ entityNamespace: t, value: n, applicationUniversalIdentifier: r }) => e(`${t}:${n}`, r), r = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: t, name: r }) => n({\n\tentityNamespace: \"fieldMetadata\",\n\tvalue: `${t}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), i = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: t, relationTargetObjectUniversalIdentifier: r }) => n({\n\tentityNamespace: \"fieldMetadata\",\n\tvalue: `${t}:systemRelation:${r}`,\n\tapplicationUniversalIdentifier: e\n}), a = ({ fieldMetadataApplicationUniversalIdentifier: e, viewUniversalIdentifier: t, fieldMetadataUniversalIdentifier: r }) => n({\n\tentityNamespace: \"viewField\",\n\tvalue: `${t}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), o = ({ objectMetadataApplicationUniversalIdentifier: e, objectUniversalIdentifier: t, viewKey: r }) => n({\n\tentityNamespace: \"view\",\n\tvalue: `${t}:${r}`,\n\tapplicationUniversalIdentifier: e\n});\n//#endregion\nexport { n as a, r as i, a as n, t as o, i as r, o as t };\n", "import { t as e } from \"./FieldMetadataType-PppCGM82.mjs\";\nimport { a as t, i as n, n as r, o as i, r as a, t as o } from \"./get-system-view-universal-identifier.util-CJoglbKX.mjs\";\n//#region src/application/applicationCategoryType.ts\nvar s = [\n\t\"Communication\",\n\t\"Productivity\",\n\t\"Product management\",\n\t\"Sales\",\n\t\"Marketing\",\n\t\"Enrichment\",\n\t\"Data\",\n\t\"Search\",\n\t\"Other\"\n], c = (e) => s.includes(e), l = [\n\te.TEXT,\n\te.ARRAY,\n\te.BOOLEAN,\n\te.DATE,\n\te.DATE_TIME,\n\te.NUMBER,\n\te.NUMERIC,\n\te.RAW_JSON,\n\te.RICH_TEXT,\n\te.SELECT,\n\te.MULTI_SELECT\n], u = \"public\", d = \"TWENTY_API_KEY\", f = \"TWENTY_API_URL\", p = \"TWENTY_APP_ACCESS_TOKEN\", m = \"TWENTY_FUNCTIONS_URL\", h = \"generated\", g = { js: \"import { createRequire as __createRequire } from 'module';\\nconst require = __createRequire(import.meta.url);\" }, _ = \".twenty/output\", v = \"Standard\", y = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"agent\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), b = ({ applicationUniversalIdentifier: e, key: n }) => t({\n\tentityNamespace: \"applicationVariable\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), x = \"navigation\", S = ({ applicationUniversalIdentifier: e, engineComponentKey: n }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `GLOBAL:${n}`,\n\tapplicationUniversalIdentifier: e\n}), C = ({ applicationUniversalIdentifier: e, engineComponentKey: n }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `GLOBAL_OBJECT_CONTEXT:${n}`,\n\tapplicationUniversalIdentifier: e\n}), w = ({ applicationUniversalIdentifier: e, engineComponentKey: n, objectUniversalIdentifier: r }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `RECORD_SELECTION:${n}:${r ?? \"\"}`,\n\tapplicationUniversalIdentifier: e\n}), T = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `${n}:${x}`,\n\tapplicationUniversalIdentifier: e\n}), E = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"connectionProvider\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), D = ({ applicationUniversalIdentifier: e, roleUniversalIdentifier: n, fieldUniversalIdentifier: r }) => t({\n\tentityNamespace: \"fieldPermission\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), O = ({ applicationUniversalIdentifier: e, pageLayoutWidgetUniversalIdentifier: n }) => t({\n\tentityNamespace: \"view\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), k = ({ applicationUniversalIdentifier: e, componentName: n }) => t({\n\tentityNamespace: \"frontComponent\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), A = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"index\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), j = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"logicFunction\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), ee = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `FOLDER:${n}`,\n\tapplicationUniversalIdentifier: e\n}), M = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `OBJECT:${n}`,\n\tapplicationUniversalIdentifier: e\n}), N = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `VIEW:${n}`,\n\tapplicationUniversalIdentifier: e\n}), P = ({ applicationUniversalIdentifier: e, link: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `LINK:${n}`,\n\tapplicationUniversalIdentifier: e\n}), F = ({ applicationUniversalIdentifier: e, roleUniversalIdentifier: n, objectUniversalIdentifier: r }) => t({\n\tentityNamespace: \"objectPermission\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), I = ({ applicationUniversalIdentifier: e, nameSingular: n }) => t({\n\tentityNamespace: \"objectMetadata\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), L = ({ applicationUniversalIdentifier: e, pageLayoutUniversalIdentifier: n, title: r }) => t({\n\tentityNamespace: \"pageLayoutTab\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), R = \"RECORD_PAGE\", z = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"pageLayout\",\n\tvalue: n ? `${n}:${r}` : r,\n\tapplicationUniversalIdentifier: e\n}), B = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n }) => t({\n\tentityNamespace: \"pageLayout\",\n\tvalue: `${n}:${R}`,\n\tapplicationUniversalIdentifier: e\n}), V = ({ applicationUniversalIdentifier: e, pageLayoutTabUniversalIdentifier: n, title: r }) => t({\n\tentityNamespace: \"pageLayoutWidget\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), H = ({ applicationUniversalIdentifier: e, key: n }) => t({\n\tentityNamespace: \"permissionFlag\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), U = ({ applicationUniversalIdentifier: e, roleUniversalIdentifier: n, permissionFlagUniversalIdentifier: r }) => t({\n\tentityNamespace: \"rolePermissionFlag\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), W = ({ applicationUniversalIdentifier: e, agentUniversalIdentifier: n }) => t({\n\tentityNamespace: \"roleTarget\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), G = ({ applicationUniversalIdentifier: e, label: n }) => t({\n\tentityNamespace: \"role\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), K = ({ applicationUniversalIdentifier: e, fieldMetadataUniversalIdentifier: n }) => t({\n\tentityNamespace: \"searchFieldMetadata\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), q = ({ applicationUniversalIdentifier: e, fieldUniversalIdentifier: n, value: r }) => t({\n\tentityNamespace: \"selectOption\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), J = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"skill\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), Y = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"viewFieldGroup\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), X = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldMetadataUniversalIdentifier: r }) => t({\n\tentityNamespace: \"viewField\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), Z = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldMetadataUniversalIdentifier: r, operand: i, subFieldName: a }) => t({\n\tentityNamespace: \"viewFilter\",\n\tvalue: `${n}:${r}:${i}:${a ?? \"\"}`,\n\tapplicationUniversalIdentifier: e\n}), Q = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldValue: r }) => t({\n\tentityNamespace: \"viewGroup\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), $ = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldMetadataUniversalIdentifier: r }) => t({\n\tentityNamespace: \"viewSort\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), te = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"view\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), ne = /* @__PURE__ */ function(e) {\n\treturn e.Object = \"object\", e.Field = \"field\", e.LogicFunction = \"logicFunction\", e.FrontComponent = \"frontComponent\", e.Role = \"role\", e.Skill = \"skill\", e.Agent = \"agent\", e.ConnectionProvider = \"connectionProvider\", e.View = \"view\", e.ViewField = \"viewField\", e.NavigationMenuItem = \"navigationMenuItem\", e.PageLayout = \"pageLayout\", e.PageLayoutTab = \"pageLayoutTab\", e.CommandMenuItem = \"commandMenuItem\", e;\n}({}), re = (t, n = e.TEXT) => {\n\tif (t == null) return \"\";\n\tswitch (n) {\n\t\tcase e.BOOLEAN: return String(t) === \"true\" ? \"true\" : \"false\";\n\t\tcase e.NUMBER:\n\t\tcase e.NUMERIC: return String(t);\n\t\tcase e.ARRAY:\n\t\tcase e.MULTI_SELECT:\n\t\t\tif (Array.isArray(t)) return JSON.stringify(t);\n\t\t\tif (typeof t == \"string\") {\n\t\t\t\ttry {\n\t\t\t\t\tlet e = JSON.parse(t);\n\t\t\t\t\tif (Array.isArray(e)) return t;\n\t\t\t\t} catch {}\n\t\t\t\treturn JSON.stringify([t]);\n\t\t\t}\n\t\t\treturn JSON.stringify(t);\n\t\tcase e.RAW_JSON:\n\t\tcase e.RICH_TEXT: return typeof t == \"string\" ? t : JSON.stringify(t);\n\t\tdefault: return typeof t == \"string\" ? t : String(t);\n\t}\n}, ie = (t, n = e.TEXT) => {\n\tif (t === \"\") return n === e.ARRAY || n === e.MULTI_SELECT ? [] : \"\";\n\tswitch (n) {\n\t\tcase e.BOOLEAN: return t === \"true\";\n\t\tcase e.NUMBER:\n\t\tcase e.NUMERIC: {\n\t\t\tlet e = Number(t);\n\t\t\treturn Number.isNaN(e) ? t : e;\n\t\t}\n\t\tcase e.ARRAY:\n\t\tcase e.MULTI_SELECT: try {\n\t\t\tlet e = JSON.parse(t);\n\t\t\treturn Array.isArray(e) ? e : [];\n\t\t} catch {\n\t\t\treturn [];\n\t\t}\n\t\tcase e.RAW_JSON:\n\t\tcase e.RICH_TEXT: try {\n\t\t\treturn JSON.parse(t);\n\t\t} catch {\n\t\t\treturn t;\n\t\t}\n\t\tdefault: return t;\n\t}\n};\n//#endregion\nexport { s as APPLICATION_CATEGORIES, l as APPLICATION_VARIABLE_FIELD_METADATA_TYPES, u as ASSETS_DIR, d as DEFAULT_API_KEY_NAME, f as DEFAULT_API_URL_NAME, p as DEFAULT_APP_ACCESS_TOKEN_NAME, m as DEFAULT_FUNCTIONS_URL_NAME, h as GENERATED_DIR, g as NODE_ESM_CJS_BANNER, _ as OUTPUT_DIR, ne as SyncableEntity, v as TWENTY_STANDARD_APPLICATION_NAME, i as TWENTY_STANDARD_APPLICATION_UNIVERSAL_IDENTIFIER, t as computeDeterministicUuid, ie as deserializeApplicationVariableValue, y as getAgentUniversalIdentifier, b as getApplicationVariableUniversalIdentifier, E as getConnectionProviderUniversalIdentifier, D as getFieldPermissionUniversalIdentifier, n as getFieldUniversalIdentifier, O as getFieldsWidgetViewUniversalIdentifier, ee as getFolderNavigationMenuItemUniversalIdentifier, k as getFrontComponentUniversalIdentifier, S as getGlobalCommandMenuItemUniversalIdentifier, C as getGlobalObjectContextCommandMenuItemUniversalIdentifier, A as getIndexUniversalIdentifier, P as getLinkNavigationMenuItemUniversalIdentifier, j as getLogicFunctionUniversalIdentifier, T as getNavigationCommandUniversalIdentifier, M as getObjectNavigationMenuItemUniversalIdentifier, F as getObjectPermissionUniversalIdentifier, I as getObjectUniversalIdentifier, L as getPageLayoutTabUniversalIdentifier, z as getPageLayoutUniversalIdentifier, V as getPageLayoutWidgetUniversalIdentifier, H as getPermissionFlagUniversalIdentifier, B as getRecordPageLayoutUniversalIdentifier, w as getRecordSelectionCommandMenuItemUniversalIdentifier, U as getRolePermissionFlagUniversalIdentifier, W as getRoleTargetUniversalIdentifier, G as getRoleUniversalIdentifier, K as getSearchFieldUniversalIdentifier, q as getSelectOptionUniversalIdentifier, J as getSkillUniversalIdentifier, a as getSystemRelationFieldUniversalIdentifier, r as getSystemViewFieldUniversalIdentifier, o as getSystemViewUniversalIdentifier, Y as getViewFieldGroupUniversalIdentifier, X as getViewFieldUniversalIdentifier, Z as getViewFilterUniversalIdentifier, Q as getViewGroupUniversalIdentifier, N as getViewNavigationMenuItemUniversalIdentifier, $ as getViewSortUniversalIdentifier, te as getViewUniversalIdentifier, c as isKnownApplicationCategory, re as serializeApplicationVariableValue };\n", "import {\n  DEFAULT_API_URL_NAME,\n  DEFAULT_APP_ACCESS_TOKEN_NAME,\n} from 'twenty-shared/application';\n\nexport const postGraphqlRequest = async <TVariables, TData>({\n  query,\n  variables,\n  caller,\n}: {\n  query: string;\n  variables: TVariables;\n  caller: string;\n}): Promise<TData> => {\n  const apiUrl = process.env[DEFAULT_API_URL_NAME];\n  const accessToken = process.env[DEFAULT_APP_ACCESS_TOKEN_NAME];\n\n  if (!apiUrl || !accessToken) {\n    throw new Error(\n      `${caller}() requires the app runtime env vars ` +\n        `${DEFAULT_API_URL_NAME} and ${DEFAULT_APP_ACCESS_TOKEN_NAME}.`,\n    );\n  }\n\n  const response = await fetch(`${apiUrl}/metadata`, {\n    method: 'POST',\n    headers: {\n      'Content-Type': 'application/json',\n      Authorization: `Bearer ${accessToken}`,\n    },\n    body: JSON.stringify({ query, variables }),\n  });\n\n  if (!response.ok) {\n    throw new Error(\n      `${caller}() failed: HTTP ${response.status} ${response.statusText}`,\n    );\n  }\n\n  const body = (await response.json()) as {\n    data?: TData;\n    errors?: { message: string }[];\n  };\n\n  if (body.errors && body.errors.length > 0) {\n    throw new Error(\n      `${caller}() failed: ${body.errors.map((error) => error.message).join(', ')}`,\n    );\n  }\n\n  if (!body.data) {\n    throw new Error(`${caller}() failed: response contained no data.`);\n  }\n\n  return body.data;\n};\n", "import { AppConnectionAuthFailedError } from '@/sdk/logic-function/connections/errors/app-connection-auth-failed.error';\nimport { type AppConnection } from '@/sdk/logic-function/connections/types/app-connection.type';\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst GET_APP_CONNECTION_QUERY = `\n  query GetAppConnection($id: ID!) {\n    appConnection(id: $id) {\n      id\n      providerName\n      name\n      handle\n      visibility\n      userWorkspaceId\n      accessToken\n      scopes\n      authFailedAt\n    }\n  }\n`;\n\nexport const getConnection = async (id: string): Promise<AppConnection> => {\n  const { appConnection } = await postGraphqlRequest<\n    { id: string },\n    { appConnection: AppConnection }\n  >({\n    query: GET_APP_CONNECTION_QUERY,\n    variables: { id },\n    caller: 'getConnection',\n  });\n\n  if (appConnection.authFailedAt !== null) {\n    throw new AppConnectionAuthFailedError(appConnection.id);\n  }\n\n  return appConnection;\n};\n", "import { type AppConnection } from '@/sdk/logic-function/connections/types/app-connection.type';\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst LIST_APP_CONNECTIONS_QUERY = `\n  query ListAppConnections($filter: ListAppConnectionsInput) {\n    appConnections(filter: $filter) {\n      id\n      providerName\n      name\n      handle\n      visibility\n      userWorkspaceId\n      accessToken\n      scopes\n      authFailedAt\n    }\n  }\n`;\n\nexport type ListConnectionsFilter = {\n  providerName?: string;\n  userWorkspaceId?: string;\n  visibility?: 'user' | 'workspace';\n};\n\nexport const listConnections = async (\n  filter: ListConnectionsFilter = {},\n): Promise<AppConnection[]> => {\n  const { appConnections } = await postGraphqlRequest<\n    { filter: ListConnectionsFilter },\n    { appConnections: AppConnection[] }\n  >({\n    query: LIST_APP_CONNECTIONS_QUERY,\n    variables: { filter },\n    caller: 'listConnections',\n  });\n\n  return appConnections;\n};\n", "import { type AppConnection } from '@/sdk/logic-function/connections/types/app-connection.type';\n\nexport const findConnectionForRequest = (\n  connections: AppConnection[],\n  event: { userWorkspaceId: string | null },\n): AppConnection | null => {\n  if (event.userWorkspaceId !== null) {\n    const personal = connections.find(\n      (connection) =>\n        connection.visibility === 'user' &&\n        connection.userWorkspaceId === event.userWorkspaceId,\n    );\n\n    if (personal) {\n      return personal;\n    }\n  }\n\n  const workspaceShared = connections.find(\n    (connection) => connection.visibility === 'workspace',\n  );\n\n  return workspaceShared ?? null;\n};\n", "import {\n  type RunAgentInput,\n  type RunAgentResult,\n} from 'twenty-shared/application';\n\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst RUN_AGENT_MUTATION = `\n  mutation RunAgent($input: RunAgentInput!) {\n    runAgent(input: $input) {\n      result\n      error\n      success\n    }\n  }\n`;\n\nexport const runAgent = async (\n  input: RunAgentInput,\n): Promise<RunAgentResult> => {\n  const { runAgent: result } = await postGraphqlRequest<\n    { input: RunAgentInput },\n    { runAgent: RunAgentResult }\n  >({\n    query: RUN_AGENT_MUTATION,\n    variables: { input },\n    caller: 'runAgent',\n  });\n\n  return result;\n};\n", "import { MetadataApiClient } from 'twenty-client-sdk/metadata';\nimport {\n  type EnqueueJobInput,\n  type EnqueueJobResult,\n} from 'twenty-shared/application';\n\nexport const enqueueJob = async (\n  input: EnqueueJobInput,\n): Promise<EnqueueJobResult> => {\n  const client = new MetadataApiClient();\n\n  const { enqueueJob: result } = await client.mutation({\n    enqueueJob: {\n      __args: { input },\n      enqueued: true,\n      logicFunctionUniversalIdentifier: true,\n    },\n  });\n\n  return result;\n};\n", "import {\n  type AppKeyValue,\n  type AppKeyValueScope,\n} from 'twenty-shared/application';\n\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst GET_APP_KEY_VALUE_QUERY = `\n  query GetAppKeyValue($key: String!, $scope: AppKeyValueScope) {\n    appKeyValue(key: $key, scope: $scope) {\n      key\n      value\n      scope\n    }\n  }\n`;\n\nconst SET_APP_KEY_VALUE_MUTATION = `\n  mutation SetAppKeyValue($input: SetAppKeyValueInput!) {\n    setAppKeyValue(input: $input) {\n      key\n      value\n      scope\n    }\n  }\n`;\n\nconst DELETE_APP_KEY_VALUE_MUTATION = `\n  mutation DeleteAppKeyValue($key: String!, $scope: AppKeyValueScope) {\n    deleteAppKeyValue(key: $key, scope: $scope)\n  }\n`;\n\nconst DEFAULT_APP_KEY_VALUE_SCOPE: AppKeyValueScope = 'WORKSPACE';\n\ntype KvOptions = {\n  scope?: AppKeyValueScope;\n};\n\nexport const kv = {\n  async get<TValue = unknown>(\n    key: string,\n    options?: KvOptions,\n  ): Promise<TValue | null> {\n    const { appKeyValue } = await postGraphqlRequest<\n      { key: string; scope: AppKeyValueScope },\n      { appKeyValue: AppKeyValue | null }\n    >({\n      query: GET_APP_KEY_VALUE_QUERY,\n      variables: { key, scope: options?.scope ?? DEFAULT_APP_KEY_VALUE_SCOPE },\n      caller: 'kv.get',\n    });\n\n    return (appKeyValue?.value ?? null) as TValue | null;\n  },\n\n  async set<TValue>(\n    key: string,\n    value: TValue,\n    options?: KvOptions,\n  ): Promise<void> {\n    await postGraphqlRequest<\n      {\n        input: { key: string; value: TValue; scope: AppKeyValueScope };\n      },\n      { setAppKeyValue: AppKeyValue }\n    >({\n      query: SET_APP_KEY_VALUE_MUTATION,\n      variables: {\n        input: {\n          key,\n          value,\n          scope: options?.scope ?? DEFAULT_APP_KEY_VALUE_SCOPE,\n        },\n      },\n      caller: 'kv.set',\n    });\n  },\n\n  async delete(key: string, options?: KvOptions): Promise<boolean> {\n    const { deleteAppKeyValue } = await postGraphqlRequest<\n      { key: string; scope: AppKeyValueScope },\n      { deleteAppKeyValue: boolean }\n    >({\n      query: DELETE_APP_KEY_VALUE_MUTATION,\n      variables: { key, scope: options?.scope ?? DEFAULT_APP_KEY_VALUE_SCOPE },\n      caller: 'kv.delete',\n    });\n\n    return deleteAppKeyValue;\n  },\n};\n", "import { type LogicFunctionHttpResponse } from 'twenty-shared/types';\n\nexport type ResponseInit = {\n  status?: number;\n  headers?: Record<string, string>;\n};\n\nexport class Response implements LogicFunctionHttpResponse {\n  readonly __twentyHttpResponse = true as const;\n  readonly body: unknown;\n  readonly status?: number;\n  readonly headers?: Record<string, string>;\n\n  constructor(body: unknown, init?: ResponseInit) {\n    this.body = body;\n    this.status = init?.status;\n    this.headers = init?.headers;\n  }\n}\n", "/**\n * Universal identifiers and durable keys for the backfill \u2014 the surface that\n * scores the leads which already existed when Greenlight was installed.\n *\n * Same permanence rule as `src/constants/universal-identifiers.ts` and\n * `src/constants/gate-queue-identifiers.ts`: every value here is written into\n * the customer's workspace at install time. Changing one does not rename an\n * entity, it orphans the old one and creates a second one alongside it \u2014 and for\n * a **cron** logic function that means two schedulers draining the same queue\n * against the same rate limit. Adding is safe; editing is a breaking change.\n *\n * A third constants file rather than a section in the second one, for the same\n * reason the second one exists: so the backfill can be developed without\n * touching a file the gate-queue and data-model workstreams are both editing.\n * `src/backfill/__tests__/backfill-identifiers.test.ts` runs the uniqueness\n * guard across all three files together, which is the failure mode splitting\n * them introduces.\n */\n\n/* -------------------------------------------------------------------------- */\n/* Logic functions                                                             */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The cron drain. One tick, one bounded chunk \u2014 see `BACKFILL_CHUNK_SIZE` in\n * `src/backfill/backfill-plan.ts` for the request arithmetic that sizes it.\n */\nexport const BACKFILL_CRON_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'cb419da0-360d-4539-90a7-18b9a95a87fc';\n\n/**\n * The admin control surface: start, cancel, and read progress. An HTTP route\n * rather than a second cron because these are things a human does at a moment of\n * their choosing, and because the panel needs a synchronous answer to render.\n */\nexport const BACKFILL_CONTROL_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'b4ed46c6-db60-4994-b499-2257c3a0615b';\n\n/* -------------------------------------------------------------------------- */\n/* Admin surface \u2014 command menu item -> front component -> logic function       */\n/* -------------------------------------------------------------------------- */\n\nexport const BACKFILL_FRONT_COMPONENT_UNIVERSAL_IDENTIFIER =\n  '31e867f6-c35f-415d-9bcd-014ba9e8b365';\n\nexport const BACKFILL_COMMAND_MENU_ITEM_UNIVERSAL_IDENTIFIER =\n  'bf258f37-9673-4a8d-870f-fecc4ab44d43';\n\n/**\n * HTTP route the control function listens on. Same two-constant shape as the\n * gate-queue actions: the front component posts to the `/s`-prefixed path, which\n * is how `RestApiClient` recognises an app route rather than a core REST call,\n * and declaring both here means a mismatch is a test failure rather than a 404\n * discovered in a live workspace.\n */\nexport const BACKFILL_ROUTE_PATH = '/greenlight/backfill';\nexport const BACKFILL_CLIENT_PATH = `/s${BACKFILL_ROUTE_PATH}`;\n\n/* -------------------------------------------------------------------------- */\n/* Never-scored view \u2014 the defect, made visible                                */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Distinct from the existing \"Greenlight Unscored (Failed Open)\" view, and the\n * distinction is the whole bug report.\n *\n *   - `greenlightDecision = UNSCORED` means *the engine looked and could not\n *     score it*. That view is an error backlog.\n *   - `greenlightDecision` **empty** means *nothing has ever looked at it*.\n *     Before this feature existed there was no such view, so 1200 of 1205 people\n *     on a dev workspace sat in a state with no name and no surface, while the\n *     gate queue read empty \u2014 which looks exactly like \"everything is clean\".\n *\n * Collapsing the two into one view would have hidden the second inside the\n * first's error semantics. They are different questions with different answers.\n */\nexport const NEVER_SCORED_VIEW_UNIVERSAL_IDENTIFIER =\n  'eff19c4d-408f-40f4-ab25-99b24658a191';\n\nexport const NEVER_SCORED_NAVIGATION_MENU_ITEM_UNIVERSAL_IDENTIFIER =\n  '0b08bfea-6fc5-4219-ac28-d55775d36be5';\n\nexport const NEVER_SCORED_VIEW_FILTER_UNIVERSAL_IDENTIFIER =\n  '4de7f659-091d-4fba-9488-4530b1a79ac0';\n\nexport const NEVER_SCORED_VIEW_SORT_UNIVERSAL_IDENTIFIER =\n  '58b70c61-855c-4d4a-b824-91eed23c37c9';\n\nexport const NEVER_SCORED_VIEW_FIELD_UNIVERSAL_IDENTIFIERS = {\n  name: '4b1f9d1c-3f13-4d36-913d-4a23b6a3895c',\n  greenlightDecision: '4a6f7fc7-6a99-48be-9d52-af900b1a1900',\n  emails: 'b7593fb9-d8fe-47b8-b0eb-6c84ef9c8d0a',\n  company: '65fd67f1-da62-4b76-b64b-36933e03d02c',\n  createdAt: '8d5e193c-dd82-46b6-b28b-9e1876a70f7f',\n} as const;\n\n/* -------------------------------------------------------------------------- */\n/* Durable state keys                                                          */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Where the backfill's progress lives, in Twenty's app key-value storage.\n *\n * `scope: 'WORKSPACE'` is load-bearing and matches `release-marker-store.ts`:\n * progress is per-workspace, and a read under a different scope silently finds\n * nothing \u2014 which would read as \"no backfill has ever run\" and restart one.\n *\n * The key is versioned (`:v1`) because the stored shape is a contract between\n * releases. A future release that changes the state shape incompatibly bumps the\n * suffix rather than trying to migrate a half-finished run in place; the old key\n * is then simply an orphan, and an orphan is a much better failure than a run\n * that resumes against a cursor it no longer understands.\n */\nexport const BACKFILL_STATE_KEY = 'greenlight:backfill:state:v1';\n", "import { kv } from 'twenty-sdk/logic-function';\n\nimport { BACKFILL_STATE_KEY } from 'src/constants/backfill-identifiers';\nimport type { BackfillStateStore } from 'src/logic-functions/backfill-run';\n\n/**\n * The real backfill state store: Twenty's app key-value storage.\n *\n * Four lines in a file of its own, exactly like `release-marker-store.ts` and for\n * exactly the same reason: `kv` is only importable from\n * `twenty-sdk/logic-function`, and `backfill-run.ts` stays SDK-free so the whole\n * resume-after-crash story can be driven by a fake in unit tests. A backfill's\n * correctness is entirely about what happens across process boundaries, and a\n * test that cannot simulate a process boundary cannot test it.\n *\n * `scope: 'WORKSPACE'` is not a detail. Progress is per-workspace, and a read\n * under a different scope silently returns `null` \u2014 which this code reads as \"no\n * backfill has ever run\" and would answer by starting another one, forever.\n *\n * Neither method catches. The caller decides what an unreadable or unwritable\n * store means, and it decides differently for the two: a failed read is \"there is\n * no run, do nothing this tick\", while a failed *write* must abandon the tick\n * before it does any scoring, because work whose position cannot be recorded is\n * work that will be done again on every tick from now on.\n */\nexport const kvBackfillStateStore: BackfillStateStore = {\n  read: () => kv.get<unknown>(BACKFILL_STATE_KEY, { scope: 'WORKSPACE' }),\n  write: async (state) => {\n    await kv.set(BACKFILL_STATE_KEY, state, { scope: 'WORKSPACE' });\n  },\n};\n", "/**\n * Install-lifecycle behaviour, separated from the `define*` wrappers so it can\n * be driven by a fake API client in unit tests.\n *\n * Twenty runs the post-install hook on a fresh install and \u2014 because this app\n * sets `shouldRunOnVersionUpgrade: true` \u2014 on every upgrade, asynchronously,\n * with up to three retries. Both facts make idempotency mandatory rather than\n * merely tidy: a retried run must create nothing new, and an upgrade must not\n * flatten a workspace's tuning back to shipped defaults.\n */\n\nimport {\n  describeError,\n  logGreenlight,\n  oldestByCreatedAt,\n  readConnectionNodes,\n  type GreenlightApiClient,\n} from 'src/logic-functions/greenlight-api';\nimport {\n  buildConfigUpgradePatch,\n  buildGreenlightConfigSeed,\n  greenlightConfigSelection,\n} from 'src/logic-functions/greenlight-config-record';\nimport { SCORING_ENGINE_VERSION } from 'src/scoring';\n\nexport interface InstallRunInput {\n  readonly client: GreenlightApiClient;\n  readonly payload: { previousVersion?: string; newVersion?: string };\n}\n\nexport type PostInstallOutcome =\n  | { status: 'seeded'; configId: string | null }\n  | { status: 'already_seeded'; configCount: number }\n  | { status: 'up_to_date'; configId: string | null }\n  | { status: 'merged'; configId: string | null; mergedKeys: string[] };\n\nconst loadConfigRecords = async (\n  client: GreenlightApiClient,\n): Promise<Record<string, unknown>[]> => {\n  const response = await client.query({\n    greenlightConfigs: { edges: { node: greenlightConfigSelection() } },\n  });\n\n  return readConnectionNodes(response, 'greenlightConfigs');\n};\n\nconst readCreatedId = (response: unknown, mutationName: string): string | null => {\n  if (typeof response !== 'object' || response === null) {\n    return null;\n  }\n\n  const created = (response as Record<string, unknown>)[mutationName];\n\n  if (typeof created !== 'object' || created === null) {\n    return null;\n  }\n\n  const id = (created as Record<string, unknown>)['id'];\n\n  return typeof id === 'string' ? id : null;\n};\n\n/**\n * Best-effort provenance row. Not worth failing an install over, so every\n * failure is swallowed after being logged \u2014 but genuinely worth having, because\n * \"when was this workspace seeded, and from which version\" is the first question\n * every support conversation about a mis-scored lead starts with.\n */\nconst writeConfigAuditRow = async (\n  client: GreenlightApiClient,\n  summary: string,\n  detail: Record<string, unknown>,\n): Promise<void> => {\n  try {\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: {\n            name: summary,\n            eventType: 'CONFIG_CHANGED',\n            occurredAt: new Date().toISOString(),\n            leadObjectNameSingular: '',\n            leadDisplayName: '',\n            actorType: 'SYSTEM',\n            actorDisplayName: `Greenlight engine ${SCORING_ENGINE_VERSION}`,\n            ruleTrace: detail,\n            score: null,\n            band: 'UNSCORED',\n            decision: 'UNSCORED',\n            overrideReason: '',\n            traceId: '',\n          },\n        },\n        id: true,\n      },\n    });\n  } catch (error) {\n    logGreenlight('install_audit_write_failed', { error: describeError(error) });\n  }\n};\n\n/**\n * Seed on a fresh install; merge newly-shipped keys on an upgrade.\n *\n * ## Idempotency\n *\n * The only creation happens when the workspace has **zero** config records. A\n * retry of a run whose create already succeeded sees one record and takes the\n * \"already seeded\" branch. There is no unique constraint available on a Twenty\n * object, so a create whose response was lost in flight could in principle\n * produce a second record on retry; that duplicate is inert, because every\n * reader in this app resolves the config by `oldestByCreatedAt`, and the\n * upgrade path patches that same oldest record. Duplicate-tolerant beats\n * duplicate-impossible when the platform offers no way to be the latter.\n *\n * ## Upgrade\n *\n * `previousVersion` is `undefined` on a fresh install and set on an upgrade \u2014\n * this is the branch the ARCHITECTURE doc asks for. On an upgrade the seed is\n * never written wholesale; `buildConfigUpgradePatch` returns only the keys the\n * record is genuinely missing plus any rules the new release added, so a\n * workspace's thresholds, ICP and per-rule severities survive untouched. An\n * upgrade that adds nothing produces no mutation at all.\n *\n * ## Errors\n *\n * Deliberately **not** caught. Post-install runs async with three retries, so a\n * transient API failure should propagate and be retried by the platform \u2014\n * swallowing it would turn a recoverable blip into a permanently unseeded\n * workspace. This is safe precisely because the run is idempotent. Nothing here\n * touches lead data, so a failed seed degrades to \"the engine scores with its\n * built-in defaults\", which is the documented fall-back anyway.\n */\nexport const runPostInstall = async ({\n  client,\n  payload,\n}: InstallRunInput): Promise<PostInstallOutcome> => {\n  const existing = await loadConfigRecords(client);\n\n  if (existing.length === 0) {\n    const seed = buildGreenlightConfigSeed();\n\n    const response = await client.mutation({\n      createGreenlightConfig: { __args: { data: seed }, id: true },\n    });\n\n    const configId = readCreatedId(response, 'createGreenlightConfig');\n\n    logGreenlight('config_seeded', {\n      configId,\n      newVersion: payload.newVersion ?? null,\n    });\n\n    await writeConfigAuditRow(\n      client,\n      `CONFIG_CHANGED \u00B7 Greenlight configuration seeded \u00B7 ${payload.newVersion ?? 'unknown version'}`,\n      {\n        action: 'seeded',\n        newVersion: payload.newVersion ?? null,\n        engineVersion: SCORING_ENGINE_VERSION,\n        ruleCount: Object.keys(\n          (seed['ruleSettings'] as Record<string, unknown>) ?? {},\n        ).length,\n      },\n    );\n\n    return { status: 'seeded', configId };\n  }\n\n  const target = oldestByCreatedAt(existing);\n  const configId =\n    target !== null && typeof target['id'] === 'string' ? target['id'] : null;\n\n  if (payload.previousVersion === undefined) {\n    // Fresh install, but a record already exists: this is a retry of a run whose\n    // create landed. Do nothing at all \u2014 in particular, do not \"top up\" missing\n    // keys, because on a fresh install there are none to top up and any\n    // difference is something the admin did in the window since.\n    logGreenlight('config_seed_skipped', {\n      configCount: existing.length,\n      reason: 'config_already_present',\n    });\n\n    return { status: 'already_seeded', configCount: existing.length };\n  }\n\n  const patch = buildConfigUpgradePatch(target);\n  const mergedKeys = Object.keys(patch);\n\n  if (mergedKeys.length === 0 || configId === null) {\n    logGreenlight('config_upgrade_noop', {\n      configId,\n      previousVersion: payload.previousVersion,\n      newVersion: payload.newVersion ?? null,\n    });\n\n    return { status: 'up_to_date', configId };\n  }\n\n  await client.mutation({\n    updateGreenlightConfig: { __args: { id: configId, data: patch }, id: true },\n  });\n\n  logGreenlight('config_upgraded', {\n    configId,\n    previousVersion: payload.previousVersion,\n    newVersion: payload.newVersion ?? null,\n    mergedKeys,\n  });\n\n  await writeConfigAuditRow(\n    client,\n    `CONFIG_CHANGED \u00B7 Greenlight configuration merged on upgrade \u00B7 ${payload.newVersion ?? 'unknown version'}`,\n    {\n      action: 'merged',\n      previousVersion: payload.previousVersion,\n      newVersion: payload.newVersion ?? null,\n      mergedKeys,\n    },\n  );\n\n  return { status: 'merged', configId, mergedKeys };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Uninstall                                                                   */\n/* -------------------------------------------------------------------------- */\n\nexport interface UninstallRunOutcome {\n  readonly version: string | null;\n  readonly configRecordsObserved: number;\n  readonly cleanupPerformed: 'none';\n}\n\n/**\n * Record what is about to disappear. That is genuinely all this hook can do \u2014\n * see `uninstall.logic-function.ts` for the full argument.\n *\n * Never throws: a cleanup hook that can fail an uninstall makes an app\n * impossible to remove, and the platform documents the hook as best-effort for\n * exactly that reason.\n */\nexport const runUninstall = async ({\n  client,\n  payload,\n}: {\n  client: GreenlightApiClient;\n  payload: { version?: string };\n}): Promise<UninstallRunOutcome> => {\n  let configRecordsObserved = 0;\n\n  try {\n    configRecordsObserved = (await loadConfigRecords(client)).length;\n  } catch (error) {\n    logGreenlight('uninstall_inventory_failed', {\n      error: describeError(error),\n    });\n  }\n\n  logGreenlight('uninstalled', {\n    version: payload.version ?? null,\n    engineVersion: SCORING_ENGINE_VERSION,\n    configRecordsObserved,\n    // Stated explicitly so the log is self-documenting a year from now.\n    note: 'Greenlight v0.1 provisions no external resources; the platform removes all app-owned metadata and records.',\n  });\n\n  return {\n    version: payload.version ?? null,\n    configRecordsObserved,\n    cleanupPerformed: 'none',\n  };\n};\n", "/**\n * Identifiers, endpoint shape and storage keys for the Numaya licensing client.\n *\n * Same permanence rule as `src/constants/universal-identifiers.ts`: every UUID\n * here is written into the customer's workspace at install time, so changing one\n * orphans the old entity rather than renaming it. Adding is safe.\n *\n * These live in their own file rather than in `universal-identifiers.ts` for the\n * same reason the gate-queue constants do \u2014 so the licensing surface can be\n * built without touching the data-model constants the scoring engine depends on.\n *\n * ---------------------------------------------------------------------------\n * ## What is verified here, and how\n *\n * Everything below is now confirmed against the **REST API of the running\n * service**, not inferred. The service publishes an OpenAPI document at\n * `https://licensing.rizvigoc.com/openapi.json` (title: *Numaya Licensing -\n * Customer API*), and each request shape below was additionally exercised over\n * real HTTP on 2026-08-04.\n *\n * The spec is authoritative over `LICENSING_INTEGRATION.md`, which was written\n * from the service's **MCP** interface and predates the published spec. Where\n * the two disagree, the spec \u2014 and the live response \u2014 wins.\n *\n * The base URL stays an **application variable** (`LICENCE_API_BASE_URL`) even\n * though it is now confirmed, because a customer running a private Numaya\n * deployment still needs to point it somewhere else, and because a wrong\n * default must remain a settings change rather than a release.\n *\n * Nothing here is load-bearing for safety: every request this client makes\n * either succeeds, or fails in a way that degrades to rules-only scoring. A\n * wrong base URL costs the customer enrichment, never a lead. See\n * `src/licensing/state.ts`.\n * ---------------------------------------------------------------------------\n */\n\n/* -------------------------------------------------------------------------- */\n/* Universal identifiers                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport const LICENCE_API_BASE_URL_APP_VARIABLE_UNIVERSAL_IDENTIFIER =\n  '0dbad279-c07c-4ae0-91e5-68cb0e87c944';\n\n/**\n * `LICENCE_ENVIRONMENT`. See `LICENCE_ENVIRONMENTS` below for why an endpoint\n * that a customer will never change is still a Layer 1 variable.\n */\nexport const LICENCE_ENVIRONMENT_APP_VARIABLE_UNIVERSAL_IDENTIFIER =\n  'e39571dd-0053-4c17-a11f-c0988985d312';\n\nexport const LICENCE_REVALIDATE_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'fc2534ad-a3a1-4b05-bdf0-f2e7a1cef729';\n\nexport const LICENCE_STATUS_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  '42eaa3bc-75b6-49be-863c-a3b3c539e3a2';\n\nexport const LICENCE_FRONT_COMPONENT_UNIVERSAL_IDENTIFIER =\n  '42089a05-139e-4061-aaaa-1d53e851ac90';\n\nexport const LICENCE_COMMAND_MENU_ITEM_UNIVERSAL_IDENTIFIER =\n  'b0316c8e-e4ad-492c-9197-f26c553c0151';\n\n/* -------------------------------------------------------------------------- */\n/* The licence panel                                                           */\n/* -------------------------------------------------------------------------- */\n\nexport const LICENCE_ROUTE_PATH = '/greenlight/licence';\n\nexport const LICENCE_CLIENT_PATH = `/s${LICENCE_ROUTE_PATH}`;\n\n/**\n * Where \"Get a licence\" sends an admin.\n *\n * A constant rather than a literal in the component because it is the one part\n * of this feature guaranteed to move: today numaya.ai has no Greenlight\n * checkout, so the honest destination is the contact route, which reaches a\n * human who can issue a key. When a real purchase page exists this is the only\n * line that changes.\n *\n * The `source` parameter is not decoration. Without it there is no way to tell\n * an enquiry that came from inside a customer's own CRM \u2014 someone who has\n * already installed the app and hit the rules-only ceiling \u2014 from a cold\n * website visitor, and those two deserve different replies.\n */\nexport const LICENCE_PURCHASE_URL =\n  'https://numaya.ai/contact?source=greenlight-app';\n\n/* -------------------------------------------------------------------------- */\n/* Endpoint shape \u2014 confirmed against the published spec and live HTTP         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Default value of the `LICENCE_API_BASE_URL` application variable.\n *\n * `https://licensing.rizvigoc.com` is the licensing service's real public\n * hostname, confirmed on 2026-08-04 by fetching its OpenAPI document and by\n * driving `validate` and `activate` against it over HTTPS.\n *\n * The earlier default, `license.numaya.ai`, never existed: it was a placeholder\n * that entered this project's own documentation and was then cited by it. It\n * did not resolve in public DNS, so every install shipped with it fell straight\n * through the cache \u2192 grace \u2192 rules-only ladder. That ladder worked, which is\n * precisely why the wrong hostname survived as long as it did.\n */\nexport const DEFAULT_LICENCE_API_BASE_URL = 'https://licensing.rizvigoc.com';\n\n/**\n * Confirmed. Both paths appear verbatim in the service's published OpenAPI\n * document and both were exercised live. The `/v1` prefix and the US spelling\n * `licenses` are the service's, not ours.\n */\nexport const LICENCE_VALIDATE_PATH = '/v1/licenses/validate';\nexport const LICENCE_ACTIVATE_PATH = '/v1/licenses/activate';\n\n/* -------------------------------------------------------------------------- */\n/* Environment routing                                                         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The header that selects which side of the licensing service answers.\n *\n * One host serves both environments. Sandbox licences are **only** visible to a\n * request carrying `X-Numaya-Environment: sandbox`; without it the same key\n * comes back `200 valid:false reason:\"license_not_found\"`. The service's own\n * spec says so in one sentence \u2014 \"Use `X-Numaya-Environment: sandbox` header or\n * `nml_test_` API keys to access the sandbox\" \u2014 and the live behaviour matches.\n *\n * The header value is matched case-insensitively by the service (`sandbox`,\n * `Sandbox` and `SANDBOX` all worked); we send the lower-case form.\n */\nexport const LICENCE_ENVIRONMENT_HEADER = 'X-Numaya-Environment';\n\n/**\n * The two environments, and why this is an application variable at all.\n *\n * It is **not** derivable from the base URL \u2014 the same host serves both \u2014 so it\n * cannot be folded into `LICENCE_API_BASE_URL`. It cannot be a code constant\n * either: our own CI workspace and every throwaway dev container is licensed\n * out of sandbox, and making that a constant would mean a code change and a\n * republish to test a licensing change. And it cannot live in Layer 2, the\n * CRM-editable `GreenlightConfig` record, because the post-install hook\n * validates the licence before any Layer 2 record is guaranteed to exist.\n *\n * That leaves Layer 1. A customer never touches it \u2014 the default is\n * `production` and the description says as much \u2014 but it has to be *settable*\n * without a rebuild, which is the identical argument that already put\n * `LICENCE_API_BASE_URL` in Layer 1.\n */\nexport const LICENCE_ENVIRONMENTS = ['production', 'sandbox'] as const;\n\nexport const DEFAULT_LICENCE_ENVIRONMENT = 'production';\n\n/**\n * The service's `reason` when a key authenticated but resolved to no licence in\n * the environment the request was routed to. US spelling, the service's own.\n *\n * This is the misrouted-environment signal. See `src/licensing/entitlement.ts`\n * for why it cannot mean \"the key has a typo\".\n */\nexport const LICENCE_NOT_FOUND_REASON = 'license_not_found';\n\n/**\n * Request body field names.\n *\n * These are *not* guesses: they are the parameter names the licensing service's\n * own MCP tool schema declares for `numaya_validate_license` and\n * `numaya_activate_license`, which are generated from the service's parameter\n * model. The REST layer using different names is possible but unlikely.\n */\nexport const LICENCE_REQUEST_FIELDS = {\n  key: 'key',\n  deviceFingerprint: 'deviceFingerprint',\n  feature: 'feature',\n  deviceName: 'deviceName',\n} as const;\n\n/**\n * The feature name the paid capability is licensed under. `rules` \u2014 the\n * deterministic gate \u2014 is on every policy and is never checked, because rules\n * scoring is the free floor and must run with no licence at all.\n */\nexport const ENRICHMENT_FEATURE_NAME = 'enrichment';\n\n/* -------------------------------------------------------------------------- */\n/* App key-value storage                                                       */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Where the cached entitlement and the published admin-facing state live.\n *\n * `scope: 'WORKSPACE'` throughout \u2014 the licence is per workspace, and the\n * activation slot is claimed with the workspace id as its fingerprint. A read\n * under a different scope silently finds nothing, which is the failure mode\n * `release-marker-store.ts` documents.\n */\nexport const LICENCE_CACHE_KV_KEY = 'greenlight.licence.cache';\n\n/**\n * Sticky record of what happened the last time we tried to claim an activation\n * slot. Separate from the validation cache on purpose: a `409` is durable\n * customer state (the licence is bound to a different workspace) and must\n * survive every nightly re-validation, whereas the validation cache is replaced\n * nightly. See `src/licensing/state.ts` for why this matters.\n */\nexport const LICENCE_ACTIVATION_KV_KEY = 'greenlight.licence.activation';\n\n/**\n * The resolved licence state, published for the admin UI to read. Written on\n * every validation; never contains the licence key.\n */\nexport const LICENCE_STATE_KV_KEY = 'greenlight.licence.state';\n\n/**\n * The verified calibration payload, cached beside the entitlement.\n *\n * Separate from `LICENCE_CACHE_KV_KEY` on purpose. The two are written by the\n * same nightly run but answer different questions and age on different clocks \u2014\n * the entitlement tightens at 24h because a stale one risks serving a paid\n * feature to a revoked licence, while calibration survives to 72h because it is\n * a word list and dropping it early would move a customer's scores for a reason\n * that has nothing to do with their data. See `src/calibration/state.ts`.\n *\n * It holds no key, no entitlement and nothing secret: the payload is the same\n * vocabulary every licensed workspace receives.\n */\nexport const CALIBRATION_CACHE_KV_KEY = 'greenlight.calibration.cache';\n\n/**\n * The resolved calibration state, published for the admin panel: shipped\n * defaults or calibration vNN, from where, and when it last refreshed.\n */\nexport const CALIBRATION_STATE_KV_KEY = 'greenlight.calibration.state';\n\n/* -------------------------------------------------------------------------- */\n/* Schedule                                                                    */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Nightly re-validation, 03:17 UTC.\n *\n * Standard five-field CRON. The odd minute is deliberate: every Greenlight\n * install would otherwise phone home on the same second, and the licensing\n * service is a single small container. Daily is the right frequency because the\n * cache TTL is 24h \u2014 validating more often buys nothing, validating less often\n * would let the cache go stale before the next run.\n */\nexport const LICENCE_REVALIDATE_CRON_PATTERN = '17 3 * * *';\n", "/**\n * The real licence store: Twenty's app key-value storage.\n *\n * Same shape and the same reasoning as `release-marker-store.ts` \u2014 this is the\n * only licensing module that imports the SDK, which is what lets `licence-run.ts`\n * and the whole of `src/licensing/` be driven by a fake in unit tests.\n *\n * `scope: 'WORKSPACE'` throughout, and it is not a detail. A licence belongs to\n * a workspace, its activation slot is claimed with the workspace id as the\n * fingerprint, and a read under a different scope silently finds nothing \u2014 which\n * would present as \"the cache never survives a restart\", i.e. as a permanent\n * grace-expired state that fails open forever and never says why.\n *\n * ## Reads are tolerant, writes are best-effort\n *\n * `kv.get` returns whatever was stored, which after an upgrade might be a shape\n * this version has never seen. Every read validates the couple of fields it\n * actually depends on and returns `null` / `unknown` otherwise, so a stale entry\n * degrades to \"no cache\" rather than to a `TypeError` inside a cron job.\n *\n * Writes swallow their errors for the same reason install-run's audit write\n * does: failing a licence check because the *cache* could not be written would\n * convert a storage blip into a lost validation, when the validation itself\n * already succeeded.\n */\n\nimport { kv } from 'twenty-sdk/logic-function';\n\nimport {\n  CALIBRATION_CACHE_KV_KEY,\n  CALIBRATION_STATE_KV_KEY,\n  LICENCE_ACTIVATION_KV_KEY,\n  LICENCE_CACHE_KV_KEY,\n  LICENCE_STATE_KV_KEY,\n} from 'src/constants/licence-identifiers';\nimport {\n  type CachedCalibration,\n  type CalibrationReaderPort,\n  type CalibrationStorePort,\n} from 'src/calibration/types';\nimport {\n  describeError,\n  logGreenlight,\n} from 'src/logic-functions/greenlight-api';\nimport {\n  type CachedLicenceValidation,\n  type LicenceActivationState,\n  type LicenceState,\n  type LicenceStorePort,\n} from 'src/licensing/types';\n\nconst SCOPE = { scope: 'WORKSPACE' } as const;\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\n/**\n * A cache entry is only usable if it carries the three things the offline path\n * reads: when it was taken, and the two gate booleans. Everything else is\n * cosmetic and is allowed to be missing.\n */\nconst readCacheEntry = (value: unknown): CachedLicenceValidation | null => {\n  if (!isRecord(value)) {\n    return null;\n  }\n\n  const { cachedAt, valid, hasFeature } = value;\n\n  if (\n    typeof cachedAt !== 'string' ||\n    typeof valid !== 'boolean' ||\n    typeof hasFeature !== 'boolean'\n  ) {\n    return null;\n  }\n\n  return {\n    cachedAt,\n    maskedKey: typeof value['maskedKey'] === 'string' ? value['maskedKey'] : '',\n    valid,\n    hasFeature,\n    reason: typeof value['reason'] === 'string' ? value['reason'] : null,\n    features: Array.isArray(value['features'])\n      ? value['features'].filter((entry): entry is string => typeof entry === 'string')\n      : [],\n    tier: typeof value['tier'] === 'string' ? value['tier'] : null,\n    daysRemaining:\n      typeof value['daysRemaining'] === 'number' ? value['daysRemaining'] : null,\n    expiryWarning: value['expiryWarning'] === true,\n    expiryAt: typeof value['expiryAt'] === 'string' ? value['expiryAt'] : null,\n  };\n};\n\nconst readActivationState = (value: unknown): LicenceActivationState => {\n  if (!isRecord(value)) {\n    return { status: 'unknown' };\n  }\n\n  const status = value['status'];\n  const at = typeof value['at'] === 'string' ? value['at'] : '';\n\n  if (status === 'claimed' || status === 'limit_reached') {\n    return { status, at };\n  }\n\n  return { status: 'unknown' };\n};\n\nexport const kvLicenceStore: LicenceStorePort = {\n  readCache: async () => {\n    try {\n      return readCacheEntry(await kv.get<unknown>(LICENCE_CACHE_KV_KEY, SCOPE));\n    } catch (error) {\n      logGreenlight('licence_cache_read_failed', { error: describeError(error) });\n\n      return null;\n    }\n  },\n\n  writeCache: async (entry) => {\n    try {\n      await kv.set(LICENCE_CACHE_KV_KEY, entry, SCOPE);\n    } catch (error) {\n      logGreenlight('licence_cache_write_failed', { error: describeError(error) });\n    }\n  },\n\n  readActivation: async () => {\n    try {\n      return readActivationState(\n        await kv.get<unknown>(LICENCE_ACTIVATION_KV_KEY, SCOPE),\n      );\n    } catch (error) {\n      logGreenlight('licence_activation_read_failed', {\n        error: describeError(error),\n      });\n\n      return { status: 'unknown' };\n    }\n  },\n\n  writeActivation: async (state) => {\n    try {\n      await kv.set(LICENCE_ACTIVATION_KV_KEY, state, SCOPE);\n    } catch (error) {\n      logGreenlight('licence_activation_write_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n\n  publishState: async (state) => {\n    try {\n      await kv.set(LICENCE_STATE_KV_KEY, state, SCOPE);\n    } catch (error) {\n      logGreenlight('licence_state_publish_failed', { error: describeError(error) });\n    }\n  },\n};\n\n/* -------------------------------------------------------------------------- */\n/* Calibration                                                                 */\n/* -------------------------------------------------------------------------- */\n\n/**\n * A cached calibration is only usable if it carries when it was taken and a\n * payload with a version. Everything else is allowed to be missing and is\n * defaulted, for the same reason the entitlement cache is read tolerantly: an\n * entry written by a previous release must degrade to \"no calibration\" \u2014 i.e.\n * to shipped defaults \u2014 rather than to a `TypeError` inside a cron job.\n *\n * The lists are *not* re-validated element by element here. They were validated\n * and normalised by `src/calibration/parse.ts` before the signature was checked,\n * and re-deriving that on every read would spend a scoring run's time to\n * re-establish a fact the write already established.\n */\nconst readCalibrationEntry = (value: unknown): CachedCalibration | null => {\n  if (!isRecord(value)) {\n    return null;\n  }\n\n  const { cachedAt, calibration, sealTag, verifiedAt, keyId } = value;\n\n  if (typeof cachedAt !== 'string' || !isRecord(calibration)) {\n    return null;\n  }\n\n  if (typeof calibration['calibrationVersion'] !== 'number') {\n    return null;\n  }\n\n  // Every field the seal covers is read strictly, with no defaulting. A\n  // defaulted value would change the canonical bytes the tag is checked against\n  // and turn a legitimate entry into a seal mismatch \u2014 the failure would look\n  // like tampering, which is the most misleading thing it could look like. An\n  // entry missing any of them is simply not a sealed entry.\n  if (\n    typeof sealTag !== 'string' ||\n    sealTag.length === 0 ||\n    typeof verifiedAt !== 'string' ||\n    typeof keyId !== 'string'\n  ) {\n    return null;\n  }\n\n  return {\n    cachedAt,\n    verifiedAt,\n    keyId,\n    sealTag,\n    calibration: calibration as unknown as CachedCalibration['calibration'],\n  };\n};\n\nexport const kvCalibrationStore: CalibrationStorePort = {\n  readCalibration: async () => {\n    try {\n      return readCalibrationEntry(\n        await kv.get<unknown>(CALIBRATION_CACHE_KV_KEY, SCOPE),\n      );\n    } catch (error) {\n      logGreenlight('calibration_cache_read_failed', {\n        error: describeError(error),\n      });\n\n      return null;\n    }\n  },\n\n  writeCalibration: async (entry) => {\n    try {\n      await kv.set(CALIBRATION_CACHE_KV_KEY, entry, SCOPE);\n    } catch (error) {\n      logGreenlight('calibration_cache_write_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n\n  clearCalibration: async () => {\n    try {\n      // `kv.set(key, null)` rather than a delete: the SDK's key-value surface\n      // has no delete, and a stored `null` fails `readCalibrationEntry`'s record\n      // check, which is exactly \"no calibration\". Writing an empty object would\n      // not \u2014 it would parse as a record and then fail on a missing field, which\n      // is the same outcome by a longer route and one more shape to reason about.\n      await kv.set(CALIBRATION_CACHE_KV_KEY, null, SCOPE);\n    } catch (error) {\n      logGreenlight('calibration_cache_clear_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n\n  publishCalibrationState: async (state) => {\n    try {\n      await kv.set(CALIBRATION_STATE_KV_KEY, state, SCOPE);\n    } catch (error) {\n      logGreenlight('calibration_state_publish_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n};\n\n/**\n * The scoring path's view: read-only, and narrower than the store above.\n *\n * A scoring run must not be handed something it could write through \u2014 the same\n * argument that keeps `readPublishedLicenceState` off `LicenceStorePort`. A run\n * that could rewrite the calibration cache would be a run that could change what\n * every *subsequent* lead is scored against, from inside a per-lead code path.\n */\nexport const kvCalibrationReader: CalibrationReaderPort = {\n  read: () => kvCalibrationStore.readCalibration(),\n};\n\n/**\n * Read the published calibration state back, for the admin panel.\n *\n * Returns `null` rather than a synthetic \"shipped defaults\" state when nothing\n * has been published: \"this workspace has never run a licence check\" and \"this\n * workspace ran one and is on shipped defaults\" are different things to show a\n * human, and inventing the second would hide the first.\n */\nexport const readPublishedCalibrationState = async (): Promise<unknown> => {\n  try {\n    const value = await kv.get<unknown>(CALIBRATION_STATE_KV_KEY, SCOPE);\n\n    return isRecord(value) && typeof value['status'] === 'string' ? value : null;\n  } catch (error) {\n    logGreenlight('calibration_state_read_failed', {\n      error: describeError(error),\n    });\n\n    return null;\n  }\n};\n\n/**\n * Read the published state back \u2014 what a future enrichment path calls before\n * consulting `isEnrichmentEnabled`. Deliberately not on `LicenceStorePort`: the\n * port is the *writer's* interface, and enrichment has no business being handed\n * something it could write through.\n */\nexport const readPublishedLicenceState = async (): Promise<LicenceState | null> => {\n  try {\n    const value = await kv.get<unknown>(LICENCE_STATE_KV_KEY, SCOPE);\n\n    if (!isRecord(value) || typeof value['mode'] !== 'string') {\n      return null;\n    }\n\n    return value as unknown as LicenceState;\n  } catch (error) {\n    logGreenlight('licence_state_read_failed', { error: describeError(error) });\n\n    return null;\n  }\n};\n", "/**\n * Tolerant parsing of the licensing service's `validate` response.\n *\n * The response is JSON from a service we do not deploy in lockstep with this\n * app. It will change shape at some point \u2014 a field renamed, a number arriving\n * as a string, a proxy returning an HTML error page with a `200`. None of those\n * may throw inside a customer's workspace, because the caller is a nightly cron\n * job whose failure is silent and whose consequence is a licence that stops\n * being re-checked.\n *\n * So parsing is total and returns a discriminated result: either a fully\n * populated response with every field defaulted, or `malformed`. There is no\n * middle state and no `undefined` anywhere downstream.\n *\n * ## What counts as malformed\n *\n * Only one thing: `valid` is not a boolean. That field is the entire contract \u2014\n * `LICENSING_INTEGRATION.md` is explicit that a failed validation is a normal\n * `200` and that the caller must branch on the boolean. A body without a usable\n * `valid` is not a licence answer, whatever else it contains.\n *\n * Everything else degrades. A missing `hasFeature` is `false` (fail closed on\n * the *paid feature*, which is the safe direction \u2014 the customer keeps rules\n * scoring either way). A missing `daysRemaining` is `null`, not `0`, because\n * `0` would read as \"expires today\" in the admin notice.\n *\n * ## The service's own spec over-promises, and this is why that costs nothing\n *\n * `ValidateLicenseResponse` in the published OpenAPI document marks nineteen\n * fields `required`, including `reason`, `gracePeriodDaysRemaining` and\n * `maintenanceExpiryAt`. A healthy live response on 2026-08-04 carried none of\n * those three: `reason` is simply absent when the licence is valid, and the two\n * grace/maintenance fields were absent from every response observed, valid and\n * invalid alike.\n *\n * A parser written to the spec \u2014 destructuring required fields, or validating\n * their presence \u2014 would therefore have rejected every real response the\n * service sends. Tolerant parsing was the right call for a reason better than\n * the one originally given: not \"the schema will drift one day\", but \"the\n * schema is already wrong today\".\n */\n\nimport { type LicenceValidationResponse } from 'src/licensing/types';\n\nexport type ParsedValidation =\n  | { readonly kind: 'parsed'; readonly response: LicenceValidationResponse }\n  | { readonly kind: 'malformed'; readonly detail: string };\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\nconst readBoolean = (value: unknown, fallback: boolean): boolean =>\n  typeof value === 'boolean' ? value : fallback;\n\nconst readString = (value: unknown): string | null =>\n  typeof value === 'string' && value.length > 0 ? value : null;\n\n/**\n * Accepts a numeric string too. Numbers crossing a JSON boundary from a .NET or\n * JVM service occasionally arrive quoted, and `daysRemaining: \"14\"` meaning\n * `null` would silently suppress every expiry warning.\n */\nconst readNumber = (value: unknown): number | null => {\n  if (typeof value === 'number' && Number.isFinite(value)) {\n    return value;\n  }\n\n  if (typeof value === 'string' && value.trim().length > 0) {\n    const parsed = Number(value);\n\n    return Number.isFinite(parsed) ? parsed : null;\n  }\n\n  return null;\n};\n\nconst readStringArray = (value: unknown): readonly string[] =>\n  Array.isArray(value)\n    ? value.filter((entry): entry is string => typeof entry === 'string')\n    : [];\n\nexport const parseValidationResponse = (payload: unknown): ParsedValidation => {\n  if (!isRecord(payload)) {\n    return {\n      kind: 'malformed',\n      detail: `expected a JSON object, received ${payload === null ? 'null' : typeof payload}`,\n    };\n  }\n\n  const valid = payload['valid'];\n\n  if (typeof valid !== 'boolean') {\n    return {\n      kind: 'malformed',\n      detail: `response has no boolean \"valid\" field (received ${typeof valid})`,\n    };\n  }\n\n  return {\n    kind: 'parsed',\n    response: {\n      valid,\n      reason: readString(payload['reason']),\n      // Fail closed on the paid capability, open on the product: absent\n      // hasFeature means \"no enrichment\", never \"enrichment\".\n      hasFeature: readBoolean(payload['hasFeature'], false),\n      features: readStringArray(payload['features']),\n      tier: readString(payload['tier']),\n      // The service calls this `type`; `type` is a reserved-ish name in this\n      // codebase's field vocabulary, so it is widened to `licenceType` here and\n      // nowhere else.\n      licenceType: readString(payload['type']),\n      status: readString(payload['status']),\n      daysRemaining: readNumber(payload['daysRemaining']),\n      expiryWarning: readBoolean(payload['expiryWarning'], false),\n      expiryAt: readString(payload['expiryAt']),\n      activatedCount: readNumber(payload['activatedCount']),\n      maxActivations: readNumber(payload['maxActivations']),\n      inGracePeriod: readBoolean(payload['inGracePeriod'], false),\n      // Declared required by the spec, absent from every live response so far.\n      // Read anyway: the day the service starts sending them, a maintenance\n      // window that has already lapsed is something an admin should be able to\n      // see in the audit row rather than something we silently dropped. Nothing\n      // branches on either \u2014 `isEnrichmentEntitled` is still `valid && hasFeature`\n      // and nothing else.\n      gracePeriodDaysRemaining: readNumber(payload['gracePeriodDaysRemaining']),\n      maintenanceExpired: readBoolean(payload['maintenanceExpired'], false),\n      maintenanceExpiryAt: readString(payload['maintenanceExpiryAt']),\n      // Undocumented and present on every live response \u2014 the mirror image of\n      // the three fields above, which are documented and present on none.\n      licenceId: readString(payload['licenseId']),\n      // Passed through untouched, including `undefined`. Validating it here\n      // would mean the licensing parser knowing what calibration is, and the\n      // whole point of `unknown` is that it does not.\n      customerMetadata: payload['customerMetadata'],\n    },\n  };\n};\n", "/**\n * Licence-key masking.\n *\n * `LICENCE_KEY` is a secret application variable. Twenty keeps it out of its own\n * UI and logs, but nothing stops *us* writing it into a structured log line, an\n * audit row's `ruleTrace`, or an error message \u2014 and an audit row is queryable\n * by every workspace admin and survives forever. So the key is masked exactly\n * once, at the edge of the run, and only the mask travels inwards.\n *\n * ## Why the mask keeps no key characters at all\n *\n * The obvious mask \u2014 \"first four, last four\" \u2014 is the wrong trade here. A key\n * is shaped `NUMAYA-XXXXX-XXXXX-XXXXX-X`: the last group is a single character and\n * the whole secret is about nineteen base-32 characters, so showing eight of\n * them is not a redaction, it is a discount. What support actually needs from a\n * mask is only ever *\"is this the same key as the one in that other log line\"*,\n * and a fingerprint answers that without revealing anything.\n *\n * So the mask is:\n *\n *   `NUMAYA-*****-*****-*****-* #6f1c2a9b`\n *\n * \u2014 group *structure* preserved (which makes a malformed key obvious at a\n * glance, e.g. someone pasting an invoice number), zero secret characters, and a\n * stable 32-bit fingerprint that distinguishes two keys from one another.\n *\n * ## Why FNV-1a and not a real hash\n *\n * This module is part of the pure core and may not import `node:crypto` \u2014 the\n * same rule that keeps `src/scoring/` runnable anywhere. FNV-1a is eleven lines\n * and deterministic. It is emphatically *not* a security primitive, and it does\n * not need to be: it never guards anything, it only labels. The key's entropy is\n * not protected by the hash being strong, it is protected by the hash being\n * lossy \u2014 32 bits out of ~95 bits of key means the fingerprint identifies a\n * gigantic equivalence class, not a key.\n */\n\nconst FNV_OFFSET_BASIS = 0x811c9dc5;\nconst FNV_PRIME = 0x01000193;\n\nconst fingerprint = (value: string): string => {\n  let hash = FNV_OFFSET_BASIS;\n\n  for (let index = 0; index < value.length; index += 1) {\n    hash ^= value.charCodeAt(index);\n    // Multiply in 32-bit space without overflowing into float precision.\n    hash = Math.imul(hash, FNV_PRIME) >>> 0;\n  }\n\n  return hash.toString(16).padStart(8, '0');\n};\n\n/**\n * The one product prefix that carries no information \u2014 every Greenlight key\n * starts with it, so echoing it back reveals nothing and makes the mask\n * readable. Any other leading group is masked like the rest.\n */\nconst NON_SECRET_PREFIX = 'NUMAYA';\n\nexport const MISSING_LICENCE_MASK = '(no licence key)';\n\n/**\n * Mask a licence key for logging, audit rows and error messages.\n *\n * Total: an empty, whitespace-only, `undefined` or non-string input returns\n * `MISSING_LICENCE_MASK` rather than throwing, because the commonest reason to\n * call this is precisely that the admin has not set the variable yet.\n */\nexport const maskLicenceKey = (key: string | null | undefined): string => {\n  if (typeof key !== 'string') {\n    return MISSING_LICENCE_MASK;\n  }\n\n  const trimmed = key.trim();\n\n  if (trimmed.length === 0) {\n    return MISSING_LICENCE_MASK;\n  }\n\n  const shape = trimmed\n    .split('-')\n    .map((group, index) =>\n      index === 0 && group.toUpperCase() === NON_SECRET_PREFIX\n        ? NON_SECRET_PREFIX\n        : '*'.repeat(group.length),\n    )\n    .join('-');\n\n  return `${shape} #${fingerprint(trimmed)}`;\n};\n\n/**\n * Last line of defence: strip any occurrence of the key from text that is about\n * to be logged or stored.\n *\n * `maskLicenceKey` is the primary mechanism and this is the belt to its braces \u2014\n * it exists because error messages are written by code we do not own. A `fetch`\n * rejection, a JSON parse error or a future SDK could all echo a request body,\n * and the URL-encoded form of a key is a plausible variant, so both are\n * replaced.\n *\n * Deliberately a no-op when there is no key: passing an empty string must not\n * turn every character of the message into a mask.\n */\nexport const redactLicenceKey = (\n  text: string,\n  key: string | null | undefined,\n): string => {\n  if (typeof key !== 'string') {\n    return text;\n  }\n\n  const trimmed = key.trim();\n\n  if (trimmed.length < 4) {\n    return text;\n  }\n\n  const mask = maskLicenceKey(trimmed);\n\n  return text\n    .split(trimmed)\n    .join(mask)\n    .split(encodeURIComponent(trimmed))\n    .join(mask);\n};\n", "/**\n * The HTTP adapter for the Numaya licensing service \u2014 the only module in\n * Greenlight that opens a socket to Numaya.\n *\n * It implements `LicensingPort`, which is what keeps `src/licensing/` testable\n * without a network: every test in this repo drives the core through a fake\n * port, and this file is exercised on its own against a fake `fetch`.\n *\n * ===========================================================================\n * ## It never throws\n *\n * Both methods return a discriminated outcome instead. A thrown error crossing\n * this boundary would have to be caught identically at every call site, and the\n * call sites are a cron handler and an install hook \u2014 places where one missing\n * `catch` is a workspace that silently stops re-validating and nobody notices\n * for a month. Making failure a return value makes the compiler enumerate it.\n *\n * ## What the status codes mean here\n *\n * | Wire                              | Outcome                      | Why |\n * |-----------------------------------|------------------------------|-----|\n * | `200` + `{ valid: false, \u2026 }`     | `validated`                  | **Not an error.** A failed validation is a normal 200; the caller branches on the boolean. |\n * | `200` + unparseable body          | `malformed_response`         | A proxy error page, or a schema change. |\n * | `401` / `403`                     | `key_rejected`               | The key **is** the credential here. Measured: an unknown or mistyped key gets a bare `401`. |\n * | `404`                             | `licence_not_found`          | On `activate`, this is the misrouted-environment failure. See below. |\n * | `409` on `activate`               | `activation_limit_reached`   | Matched on the **status code**, never on a title \u2014 see below. |\n * | `429`                             | `rate_limited`               | Honours `Retry-After` if present. |\n * | `500` / `502` / `503` / `504`     | `service_unavailable`        | Numaya-side, retriable on the next run. |\n * | anything else non-2xx             | `unexpected_status`          | Deliberately not silently retried. |\n * | thrown (DNS, TLS, timeout, abort) | `transport_failure`          | Includes a base URL that does not resolve. |\n *\n * ### Gotcha 3 \u2014 match the activation limit on the status code\n *\n * The REST layer answers a consumed licence with RFC 7807 problem details:\n *\n * ```json\n * { \"type\": \"https://httpstatuses.io/409\", \"title\": \"max_activations_reached\",\n *   \"status\": 409, \"detail\": \"Max activations reached for this license.\",\n *   \"instance\": \"/v1/licenses/activate\", \"retryable\": false }\n * ```\n *\n * The `title` is present over REST, and absent from the body previously observed\n * through the MCP layer \u2014 which is exactly why the match is\n * `response.status === 409` and only that. The status code is the half of the\n * contract both surfaces agree on. The body is never inspected.\n *\n * ### Gotcha 4 \u2014 `activate` reports a wrong environment as a `404`\n *\n * `validate` hides a misrouted environment inside a `200` (see\n * `src/licensing/entitlement.ts`). `activate` does not \u2014 it returns a bare\n * `404 license_not_found`. Classifying that as `unexpected_status` would bury\n * the clearest signal the service gives us, so it gets its own kind and lands on\n * the same admin notice as the `200` form.\n *\n * ## The licence key does not appear in anything this module returns\n *\n * Failure details are built from the error's name and message, then passed\n * through `redactLicenceKey`. That second step is belt-and-braces: the messages\n * come from `fetch`, from `JSON.parse` and from future runtimes, none of which\n * we control, and at least one plausible implementation echoes the request. Both\n * the raw and URL-encoded forms are replaced.\n * ===========================================================================\n */\n\nimport {\n  DEFAULT_LICENCE_ENVIRONMENT,\n  LICENCE_ACTIVATE_PATH,\n  LICENCE_ENVIRONMENT_HEADER,\n  LICENCE_REQUEST_FIELDS,\n  LICENCE_VALIDATE_PATH,\n} from 'src/constants/licence-identifiers';\nimport { parseValidationResponse } from 'src/licensing/parse';\nimport { redactLicenceKey } from 'src/licensing/mask';\nimport {\n  type LicenceActivateOutcome,\n  type LicenceCallFailure,\n  type LicenceEnvironmentName,\n  type LicensingPort,\n  type LicenceValidateOutcome,\n} from 'src/licensing/types';\n\n/** Injected so tests never touch the network and never need a timer. */\nexport type FetchLike = (\n  url: string,\n  init: {\n    method: string;\n    headers: Record<string, string>;\n    body: string;\n    signal?: AbortSignal;\n  },\n) => Promise<{\n  readonly ok: boolean;\n  readonly status: number;\n  readonly headers: { get(name: string): string | null };\n  text(): Promise<string>;\n}>;\n\nexport interface HttpLicensingClientOptions {\n  readonly baseUrl: string;\n  /**\n   * Which side of the service to ask. Optional, and `production` when omitted \u2014\n   * the same default the application variable ships with, so a caller that has\n   * not been updated behaves exactly as this client did before the header\n   * existed rather than silently switching a customer to sandbox.\n   */\n  readonly environment?: LicenceEnvironmentName;\n  readonly fetchImpl?: FetchLike | null;\n  /**\n   * 8 seconds. The nightly cron is given 30s and the install hook 60s, so this\n   * leaves room for the surrounding API writes. A licence check that takes\n   * longer than eight seconds is a service that is down, not a service that is\n   * slow, and the cache ladder is a better answer than waiting.\n   */\n  readonly timeoutMs?: number;\n}\n\nconst DEFAULT_TIMEOUT_MS = 8_000;\n\nconst describe = (error: unknown): string => {\n  if (error instanceof Error) {\n    return `${error.name}: ${error.message}`;\n  }\n\n  return typeof error === 'string' ? error : 'unknown transport error';\n};\n\n/**\n * `Retry-After` is defined as either seconds or an HTTP date. Only the numeric\n * form is read: the date form would need a clock, and this value is advisory \u2014\n * it is recorded for the audit row and never used to schedule anything, because\n * the next attempt is tomorrow's cron regardless.\n */\nconst readRetryAfter = (headers: { get(name: string): string | null }): number | null => {\n  const raw = headers.get('retry-after');\n\n  if (raw === null) {\n    return null;\n  }\n\n  const seconds = Number(raw.trim());\n\n  return Number.isFinite(seconds) && seconds >= 0 ? seconds : null;\n};\n\nconst classifyStatus = (\n  status: number,\n  headers: { get(name: string): string | null },\n): LicenceCallFailure => {\n  if (status === 429) {\n    return { kind: 'rate_limited', retryAfterSeconds: readRetryAfter(headers) };\n  }\n\n  if (status >= 500) {\n    return { kind: 'service_unavailable', statusCode: status };\n  }\n\n  // The licence key is the credential on these endpoints \u2014 it travels in the\n  // request body in place of an `Authorization` header \u2014 so a 401 means the\n  // service does not recognise the key at all, in any environment. Measured\n  // live: an unknown key, and a real key with one character changed, both\n  // return `401` with an empty body.\n  if (status === 401 || status === 403) {\n    return { kind: 'key_rejected', statusCode: status };\n  }\n\n  // Note what is *not* here: `404`. On `validate` a 404 means the path was\n  // wrong \u2014 a misconfigured base URL \u2014 not that the licence is missing, because\n  // `validate` reports a missing licence in-band with a `200`. Only `activate`\n  // uses 404 to mean \"no such licence\", and that is handled at its call site.\n  return { kind: 'unexpected_status', statusCode: status };\n};\n\nconst timeoutSignal = (timeoutMs: number): AbortSignal | undefined => {\n  // `AbortSignal.timeout` is available on Node 20+ and in the logic-function\n  // runtime; guarded anyway so a fake `fetch` in a stripped environment does not\n  // take the whole module down over a nicety.\n  if (typeof AbortSignal !== 'undefined' && typeof AbortSignal.timeout === 'function') {\n    return AbortSignal.timeout(timeoutMs);\n  }\n\n  return undefined;\n};\n\nconst normaliseBaseUrl = (baseUrl: string): string =>\n  baseUrl.trim().replace(/\\/+$/, '');\n\n/**\n * Build the licensing client.\n *\n * A blank base URL is not an error to throw \u2014 it is a configuration the admin\n * has not finished, and it produces a `transport_failure` so it walks the same\n * cache \u2192 grace \u2192 rules-only ladder as a real outage. One ladder, one set of\n * tests, no special case.\n */\nexport const createHttpLicensingClient = (\n  options: HttpLicensingClientOptions,\n): LicensingPort => {\n  const baseUrl = normaliseBaseUrl(options.baseUrl ?? '');\n  const environment = options.environment ?? DEFAULT_LICENCE_ENVIRONMENT;\n  const timeoutMs = options.timeoutMs ?? DEFAULT_TIMEOUT_MS;\n\n  /**\n   * The header is sent **only** for sandbox. Production is the service's own\n   * default, so sending `X-Numaya-Environment: production` would be a no-op that\n   * every request then carries \u2014 and a header we send unconditionally is one\n   * that has to be right unconditionally. Omitting it keeps the production path\n   * byte-for-byte what it was before this feature existed.\n   */\n  const environmentHeaders: Record<string, string> =\n    environment === 'sandbox' ? { [LICENCE_ENVIRONMENT_HEADER]: 'sandbox' } : {};\n  const doFetch =\n    options.fetchImpl ??\n    (typeof globalThis.fetch === 'function'\n      ? (globalThis.fetch as unknown as FetchLike)\n      : null);\n\n  const post = async (\n    path: string,\n    body: Record<string, unknown>,\n    key: string,\n  ): Promise<\n    | { kind: 'ok'; payload: unknown }\n    | { kind: 'status'; status: number; headers: { get(name: string): string | null } }\n    | LicenceCallFailure\n  > => {\n    if (baseUrl.length === 0) {\n      return {\n        kind: 'transport_failure',\n        detail: 'LICENCE_API_BASE_URL is not configured',\n      };\n    }\n\n    if (doFetch === null) {\n      return {\n        kind: 'transport_failure',\n        detail: 'no fetch implementation available in this runtime',\n      };\n    }\n\n    let response: Awaited<ReturnType<FetchLike>>;\n\n    try {\n      response = await doFetch(`${baseUrl}${path}`, {\n        method: 'POST',\n        headers: {\n          'content-type': 'application/json',\n          accept: 'application/json',\n          ...environmentHeaders,\n        },\n        body: JSON.stringify(body),\n        signal: timeoutSignal(timeoutMs),\n      });\n    } catch (error) {\n      return {\n        kind: 'transport_failure',\n        detail: redactLicenceKey(describe(error), key),\n      };\n    }\n\n    if (!response.ok) {\n      return { kind: 'status', status: response.status, headers: response.headers };\n    }\n\n    let raw: string;\n\n    try {\n      raw = await response.text();\n    } catch (error) {\n      return {\n        kind: 'malformed_response',\n        detail: redactLicenceKey(describe(error), key),\n      };\n    }\n\n    try {\n      return { kind: 'ok', payload: JSON.parse(raw) as unknown };\n    } catch (error) {\n      return {\n        kind: 'malformed_response',\n        detail: redactLicenceKey(describe(error), key),\n      };\n    }\n  };\n\n  return {\n    validate: async ({ key, deviceFingerprint, feature }): Promise<LicenceValidateOutcome> => {\n      const body: Record<string, unknown> = { [LICENCE_REQUEST_FIELDS.key]: key };\n\n      if (typeof deviceFingerprint === 'string' && deviceFingerprint.length > 0) {\n        body[LICENCE_REQUEST_FIELDS.deviceFingerprint] = deviceFingerprint;\n      }\n\n      if (typeof feature === 'string' && feature.length > 0) {\n        body[LICENCE_REQUEST_FIELDS.feature] = feature;\n      }\n\n      const result = await post(LICENCE_VALIDATE_PATH, body, key);\n\n      if (result.kind === 'status') {\n        // A 409 on `validate` is not the activation-limit error \u2014 that only\n        // arises from `activate`. Left as an unexpected status rather than\n        // pattern-matched into something more specific we have never observed.\n        return classifyStatus(result.status, result.headers);\n      }\n\n      if (result.kind !== 'ok') {\n        return result;\n      }\n\n      const parsed = parseValidationResponse(result.payload);\n\n      return parsed.kind === 'parsed'\n        ? { kind: 'validated', response: parsed.response }\n        : { kind: 'malformed_response', detail: parsed.detail };\n    },\n\n    activate: async ({\n      key,\n      deviceFingerprint,\n      deviceName,\n    }): Promise<LicenceActivateOutcome> => {\n      const body: Record<string, unknown> = {\n        [LICENCE_REQUEST_FIELDS.key]: key,\n        [LICENCE_REQUEST_FIELDS.deviceFingerprint]: deviceFingerprint,\n      };\n\n      if (typeof deviceName === 'string' && deviceName.length > 0) {\n        body[LICENCE_REQUEST_FIELDS.deviceName] = deviceName;\n      }\n\n      const result = await post(LICENCE_ACTIVATE_PATH, body, key);\n\n      if (result.kind === 'status') {\n        // Gotcha 3. Status code only \u2014 the two surfaces disagree about the body.\n        if (result.status === 409) {\n          return { kind: 'activation_limit_reached' };\n        }\n\n        // Gotcha 4. `activate` has no in-band way to say \"not found\", so it uses\n        // a 404 \u2014 measured live, that is exactly what a sandbox licence returns\n        // when the request is routed to production.\n        if (result.status === 404) {\n          return { kind: 'licence_not_found', statusCode: 404 };\n        }\n\n        return classifyStatus(result.status, result.headers);\n      }\n\n      if (result.kind !== 'ok') {\n        return result;\n      }\n\n      // Activation is idempotent on the fingerprint and returns the existing\n      // activation id on a repeat call, so the id is informational: nothing\n      // branches on it. A body we cannot read is therefore still a successful\n      // activation \u2014 refusing to record the claimed slot because the id was\n      // missing would be strictly worse.\n      const payload = result.payload;\n      const id =\n        typeof payload === 'object' && payload !== null\n          ? ((payload as Record<string, unknown>)['id'] ??\n            (payload as Record<string, unknown>)['activationId'])\n          : null;\n\n      return { kind: 'activated', activationId: typeof id === 'string' ? id : null };\n    },\n  };\n};\n", "/**\n * How licence state reaches a human \u2014 the audit row and the admin notice.\n *\n * ===========================================================================\n * ## Why this is a problem worth solving rather than a log line\n *\n * The whole point of failing open is that a licence problem is *quiet*: the\n * product keeps working, leads keep scoring, nobody's day breaks. That is\n * exactly what makes it dangerous. An expired licence that silently downgrades\n * the product produces a support ticket six weeks later reading \"enrichment\n * stopped working at some point, we don't know when\" \u2014 and by then the audit\n * trail is the only way to answer it.\n *\n * So every validation is recorded, including the boring ones. One row a night\n * is 365 rows a year against an object built for one row per scored lead; the\n * cost is nil and the alternative \u2014 only recording changes \u2014 means the row you\n * want is the one that was suppressed because \"nothing changed\".\n *\n * ## Where it surfaces\n *\n * Three places, in descending order of how likely an admin is to see them:\n *\n *  1. **`GreenlightAuditLog`** \u2014 the object already has a view and a sidebar\n *     item, is sorted newest-first, and is the place admins are already told to\n *     look when they ask \"why did this happen\". Licence rows land there next to\n *     scoring decisions, which is right: from the customer's point of view they\n *     are the same story.\n *  2. **App key-value storage** (`LICENCE_STATE_KV_KEY`) \u2014 the resolved state,\n *     republished on every run, for the Greenlight main page to render as a\n *     banner. Cheap to read, always current, no query.\n *  3. **Structured logs** \u2014 `logGreenlight('licence_resolved', \u2026)`, for support\n *     with server access.\n *\n * ## The event type is `LICENCE`, for every severity\n *\n * These rows used to file under `CONFIG_CHANGED` when healthy and `ERROR` when\n * not, because `GreenlightAuditLog.eventType` had no option of its own. It has\n * one now, and both halves of that compromise are gone rather than one:\n *\n *   - `CONFIG_CHANGED` was never true. Nobody changed any configuration; a\n *     scheduled check ran and reported what the licence server already thought.\n *   - `ERROR` is worse. `eventType` says *what happened*, and what happened is a\n *     licence check \u2014 in exactly the way `scoring-run.ts` files a held lead as\n *     `GATED` and leaves the `decision` column to say which kind of hold it was.\n *     Reserving `ERROR` for \"Greenlight itself failed\" is what keeps a red row\n *     meaning something: an expired licence is a customer's commercial state,\n *     not a fault in this app, and filing it as a fault is how an admin learns\n *     to ignore red.\n *\n * The severity survives the move and is not inferred from the event type: it is\n * carried explicitly in `ruleTrace.severity`, and the row's summary leads with\n * the admin-facing headline. `LICENCE` is yellow in the SELECT, which is the\n * colour for \"look at this\" without the claim that something broke.\n *\n * Every row's summary still starts with a `LICENCE` prefix, so the text search\n * that isolated these rows before the option existed keeps working.\n *\n * ## Nothing here may contain the licence key\n *\n * `LicenceState` has no field that could hold one \u2014 it carries `maskedKey`, and\n * `maskLicenceKey` emits no characters of the secret. This module never sees the\n * raw key, so there is no code path from the key to a row. That is asserted in\n * `__tests__/audit.test.ts` by scanning the serialised row for the sandbox keys.\n * ===========================================================================\n */\n\nimport {\n  type LicenceEnvironmentName,\n  type LicenceSeverity,\n  type LicenceState,\n} from 'src/licensing/types';\n\nexport const LICENSING_CLIENT_VERSION = '0.1.0';\n\n/** Prefix on every licence audit summary, so the rows are greppable today. */\nexport const LICENCE_AUDIT_PREFIX = 'LICENCE';\n\n/* -------------------------------------------------------------------------- */\n/* Admin-facing description                                                    */\n/* -------------------------------------------------------------------------- */\n\nexport interface LicenceNotice {\n  readonly severity: LicenceSeverity;\n  /** One line, suitable as a banner title or an audit row summary. */\n  readonly headline: string;\n  /** One or two sentences telling the admin what to actually do. */\n  readonly detail: string;\n}\n\nconst daysPhrase = (daysRemaining: number | null): string =>\n  daysRemaining === null\n    ? 'soon'\n    : daysRemaining <= 0\n      ? 'today'\n      : daysRemaining === 1\n        ? 'in 1 day'\n        : `in ${daysRemaining} days`;\n\nconst hoursSince = (cacheAgeMs: number | null): string =>\n  cacheAgeMs === null ? 'never' : `${Math.floor(cacheAgeMs / 3_600_000)}h ago`;\n\n/**\n * States published before `environment` existed read back as `undefined`. The\n * fallback keeps a stale row readable rather than rendering \"the undefined\n * environment\" at the admin; the next nightly run replaces it with the truth.\n */\nconst environmentLabel = (environment: LicenceEnvironmentName): string =>\n  environment === 'sandbox' ? 'sandbox' : 'production';\n\n/** The setting to try, named rather than implied. */\nconst otherEnvironmentLabel = (environment: LicenceEnvironmentName): string =>\n  environment === 'sandbox' ? 'production' : 'sandbox';\n\n/**\n * Turn a resolved state into something an admin can act on.\n *\n * Every `detail` names the next action. A notice that says \"your licence is\n * invalid\" and stops is a notice that generates a support ticket; one that says\n * which lever to pull does not.\n */\nexport const describeLicenceForAdmin = (state: LicenceState): LicenceNotice => {\n  const expiring =\n    state.expiryWarning ||\n    (state.daysRemaining !== null && state.daysRemaining <= 7);\n\n  switch (state.reason) {\n    case 'licensed':\n      return expiring\n        ? {\n            severity: state.severity,\n            headline: `Greenlight licence expires ${daysPhrase(state.daysRemaining)}`,\n            detail:\n              'Enrichment is running normally. Renew before the expiry date to avoid dropping to rules-only scoring. Deterministic scoring and the gate continue either way.',\n          }\n        : {\n            severity: state.severity,\n            headline: 'Greenlight licence active',\n            detail: `Enrichment is enabled${state.tier === null ? '' : ` on the ${state.tier} tier`}.`,\n          };\n\n    case 'no_licence_key':\n      return {\n        severity: state.severity,\n        headline: 'Greenlight is running in rules-only mode',\n        detail:\n          'No licence key is configured, so AI and search enrichment are off. Deterministic scoring, the gate and the queue all work without one. Add a key in the app settings to enable enrichment.',\n      };\n\n    case 'feature_not_licensed':\n      return {\n        severity: state.severity,\n        headline: 'Enrichment is not included in this licence',\n        detail:\n          'The licence is valid and in good standing, but does not include the enrichment capability. Rules-only scoring is unaffected. Upgrade the licence to turn enrichment on.',\n      };\n\n    // The one notice in this file that names a Greenlight setting as the likely\n    // culprit, because it is the one failure the service reports with a message\n    // that reads like a customer problem when it is almost always ours. It says\n    // which environment was asked, what to change, and \u2014 explicitly \u2014 that the\n    // key is not the thing to go and re-check. See gotcha 4 in `entitlement.ts`.\n    case 'licence_not_found_in_environment':\n      return {\n        severity: state.severity,\n        headline: `Licence key was accepted but no licence exists in the ${environmentLabel(state.environment)} environment`,\n        detail:\n          `This is almost certainly a misconfiguration, not a bad key: the licensing service accepted the key as valid credentials, then found no licence attached to it in the ${environmentLabel(state.environment)} environment. Set LICENCE_ENVIRONMENT to ${otherEnvironmentLabel(state.environment)} in the app settings if this workspace is licensed there, and re-run the licence check. Do not re-enter the key \u2014 a wrong or mistyped key is rejected outright and reports \"licence was rejected\" instead. If the environment is already correct, the licence has been deleted and Numaya AI support can restore it. Scoring, the gate and the queue are unaffected throughout.`,\n      };\n\n    case 'expired':\n      return {\n        severity: state.severity,\n        headline: 'Greenlight licence has expired',\n        detail:\n          'Enrichment is off. Scoring, the gate and the queue continue to work. Renew the licence to restore enrichment.',\n      };\n\n    case 'suspended':\n      return {\n        severity: state.severity,\n        headline: 'Greenlight licence is suspended',\n        detail:\n          'Enrichment is off. This is usually a billing issue and is reversible \u2014 contact Numaya AI support. Scoring is unaffected.',\n      };\n\n    case 'revoked':\n      return {\n        severity: state.severity,\n        headline: 'Greenlight licence has been revoked',\n        detail:\n          'Enrichment is off and this cannot be reversed on the existing key. Contact Numaya AI support for a replacement. Scoring is unaffected.',\n      };\n\n    case 'quota_exceeded':\n      return {\n        severity: state.severity,\n        headline: 'Greenlight enrichment quota reached',\n        detail:\n          'Enrichment is paused until the quota period resets. Scoring is unaffected.',\n      };\n\n    case 'device_not_activated':\n      return {\n        severity: state.severity,\n        headline: 'This workspace is not activated against the licence',\n        detail:\n          'Reinstall the app, or contact Numaya AI support, to claim an activation slot. Scoring is unaffected.',\n      };\n\n    case 'max_activations_reached':\n      return {\n        severity: state.severity,\n        headline: 'Licence is already in use by another workspace',\n        detail:\n          'Every activation slot on this licence is taken, so this workspace runs rules-only. Free a slot on the other workspace or add a seat, then reinstall Greenlight here.',\n      };\n\n    case 'invalid_licence':\n      return {\n        severity: state.severity,\n        headline: 'Greenlight licence was rejected',\n        detail:\n          'The licensing service refused this key outright \u2014 it does not recognise it in any environment. Check the key in the app settings for a typo or a truncated paste, then contact Numaya AI support. Scoring is unaffected.',\n      };\n\n    case 'licence_service_rate_limited':\n      return {\n        severity: state.severity,\n        headline: 'Licence check was rate-limited',\n        detail:\n          'Numaya returned HTTP 429, so this workspace could not re-check its licence. Enrichment is paused until the next nightly check succeeds; scoring, the gate and the queue are unaffected. Nothing needs doing unless this persists for several days.',\n      };\n\n    case 'licence_response_malformed':\n      return {\n        severity: state.severity,\n        headline: 'Licence service returned an unreadable response',\n        detail:\n          'The licensing service answered, but not in a shape this version understands \u2014 usually a proxy or an upgrade in progress. Enrichment is paused; scoring is unaffected. Report it to Numaya AI support if it persists.',\n      };\n\n    case 'licence_service_unreachable':\n      return {\n        severity: state.severity,\n        headline: 'Cannot reach the Numaya AI licensing service',\n        detail: `Enrichment is paused while the cached entitlement ages out (last successful check ${hoursSince(state.cacheAgeMs)}). Check outbound network access to the licensing service. Scoring is unaffected.`,\n      };\n\n    case 'licence_service_unreachable_grace_expired':\n      return {\n        severity: state.severity,\n        headline:\n          state.cacheAgeMs === null\n            ? 'Greenlight has never successfully checked its licence'\n            : 'Licence has not been verified for over 72 hours',\n        detail: `Enrichment is off until a licence check succeeds (last successful check ${hoursSince(state.cacheAgeMs)}). Confirm LICENCE_API_BASE_URL and outbound network access. Scoring, the gate and the queue are unaffected and will keep running indefinitely.`,\n      };\n  }\n};\n\n/* -------------------------------------------------------------------------- */\n/* Audit row                                                                   */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The structured payload written to `ruleTrace`. This is the row that answers\n * \"what did Numaya say, and what did we do about it, at 03:17 on the 14th\".\n *\n * Carries `valid` and `hasFeature` as separate fields on purpose \u2014 collapsing\n * them into the resulting mode would erase precisely the distinction that the\n * independence gotcha makes load-bearing.\n */\nexport interface LicenceAuditDetail {\n  readonly checkedAt: string;\n  readonly maskedKey: string;\n  /**\n   * Recorded on every row, healthy ones included. A row that says\n   * `reason: license_not_found` without saying which environment was asked is a\n   * support ticket; with it, it is a two-minute fix.\n   */\n  readonly environment: string;\n  readonly valid: boolean | null;\n  readonly hasFeature: boolean | null;\n  readonly reason: string;\n  readonly source: 'live' | 'cache' | 'grace' | 'none';\n  readonly cached: boolean;\n  readonly cacheAgeHours: number | null;\n  readonly mode: string;\n  readonly severity: LicenceSeverity;\n  readonly failureKind: string | null;\n  readonly tier: string | null;\n  readonly daysRemaining: number | null;\n  readonly expiryWarning: boolean;\n  readonly expiryAt: string | null;\n}\n\nexport const buildLicenceAuditDetail = (\n  state: LicenceState,\n): LicenceAuditDetail => ({\n  checkedAt: state.checkedAt,\n  maskedKey: state.maskedKey,\n  environment: environmentLabel(state.environment),\n  valid: state.observedValid,\n  hasFeature: state.observedHasFeature,\n  reason: state.reason,\n  source: state.source,\n  // Spelled out as a boolean as well as a source, because \"cached vs live\" is\n  // the question support asks and `source: 'grace'` does not obviously answer\n  // it.\n  cached: state.source !== 'live',\n  cacheAgeHours:\n    state.cacheAgeMs === null\n      ? null\n      : Math.round((state.cacheAgeMs / 3_600_000) * 10) / 10,\n  mode: state.mode,\n  severity: state.severity,\n  failureKind: state.failureKind,\n  tier: state.tier,\n  daysRemaining: state.daysRemaining,\n  expiryWarning: state.expiryWarning,\n  expiryAt: state.expiryAt,\n});\n\n/**\n * The `data` argument for `createGreenlightAuditLog`.\n *\n * Shaped to match the rows `install-run.ts` writes: the lead-pointer fields are\n * empty strings rather than omitted, because the object's `SELECT` fields have\n * literal defaults and a partially-populated row reads worse in the view than a\n * deliberately blank one. `band` and `decision` are `UNSCORED` for the same\n * reason \u2014 this row describes no lead, and `UNSCORED` is the vocabulary's word\n * for \"not applicable\".\n */\nexport const buildLicenceAuditRow = (\n  state: LicenceState,\n  /**\n   * The calibration outcome of the same run, if there was one.\n   *\n   * Passed in as a loose record rather than typed against\n   * `src/calibration/types.ts` for the same reason `LicenceValidationResponse`\n   * types `customerMetadata` as `unknown`: the licensing core must not acquire\n   * a dependency on what calibration is. It reads three fields for display and\n   * copies the rest verbatim into the trace.\n   *\n   * It is on the row rather than only in the panel because an audit row outlives\n   * the panel's \"now\". \"Which vocabulary was this workspace scoring on last\n   * March\" is a question asked months later, and the only place that can answer\n   * it is the append-only trail.\n   */\n  calibration?: {\n    readonly status?: unknown;\n    readonly reason?: unknown;\n    readonly calibrationVersion?: unknown;\n    readonly refreshedAt?: unknown;\n  } | null,\n): Record<string, unknown> => {\n  const notice = describeLicenceForAdmin(state);\n\n  // \"calibration v1\" or \"shipped defaults\" \u2014 the whole answer to \"am I running\n  // the calibrated lists?\", short enough to sit in a row name in a list view.\n  const calibrationLabel =\n    calibration === null || calibration === undefined\n      ? null\n      : calibration.status === 'calibrated' &&\n          typeof calibration.calibrationVersion === 'number'\n        ? `calibration v${calibration.calibrationVersion}`\n        : 'shipped defaults';\n\n  return {\n    name:\n      calibrationLabel === null\n        ? `${LICENCE_AUDIT_PREFIX} \u00B7 ${notice.headline} \u00B7 ${state.mode}`\n        : `${LICENCE_AUDIT_PREFIX} \u00B7 ${notice.headline} \u00B7 ${state.mode} \u00B7 ${calibrationLabel}`,\n    // One value for every severity. See the module comment: the severity lives\n    // in `ruleTrace.severity` and in the headline above, not in a borrowed\n    // event type.\n    eventType: 'LICENCE',\n    occurredAt: state.checkedAt,\n    leadObjectNameSingular: '',\n    leadDisplayName: '',\n    actorType: 'SYSTEM',\n    actorDisplayName: `Greenlight licensing ${LICENSING_CLIENT_VERSION}`,\n    ruleTrace: {\n      ...buildLicenceAuditDetail(state),\n      adminDetail: notice.detail,\n      ...(calibration === null || calibration === undefined\n        ? {}\n        : { calibration }),\n    },\n    score: null,\n    band: 'UNSCORED',\n    decision: 'UNSCORED',\n    overrideReason: '',\n    traceId: '',\n  };\n};\n", "/**\n * The entitlement gate: turning one `validate` response into \"may enrichment\n * run, and if not, why not\".\n *\n * This module exists because the obvious implementation is wrong in two\n * directions at once, and both were confirmed by live test rather than inferred\n * from the service's documented reason codes.\n *\n * ---------------------------------------------------------------------------\n * ## Gotcha 1 \u2014 `valid` and `hasFeature` are independent\n *\n * The service documents a reason code `feature_not_licensed`, which invites the\n * assumption that an unlicensed feature makes the whole validation fail. It does\n * not. Two observed responses:\n *\n * | Licence                       | `valid` | `reason`      | `hasFeature` |\n * |-------------------------------|---------|---------------|--------------|\n * | Rules-only, asked `enrichment` | `true`  | `null`        | **`false`**  |\n * | Suspended, asked `enrichment`  | `false` | `\"suspended\"` | **`true`**   |\n *\n * So each single-boolean check is wrong in a different and expensive way:\n *\n * - `if (response.valid)` \u2014 enables the **paid feature on a licence that does\n *   not include it**. Revenue leak, and it would never surface as a bug report\n *   because the customer is delighted.\n * - `if (response.hasFeature)` \u2014 keeps enrichment running on a **suspended**\n *   licence, because `hasFeature` still reports the policy's feature list.\n *   Suspension is the reversible lever Numaya pulls on non-payment; ignoring it\n *   makes the lever useless.\n *\n * The only correct gate is the conjunction, and it is written exactly once, in\n * `isEnrichmentEntitled` below. Nothing else in this codebase may read\n * `.hasFeature` on its own.\n *\n * ## The reason we have to invent\n *\n * When `valid: true, hasFeature: false`, the service sends `reason: null` \u2014\n * there is nothing wrong with the licence, it simply does not include the\n * feature. That is still the single most important thing to tell an admin who is\n * wondering why enrichment is off, so we *derive* `feature_not_licensed`\n * ourselves. It is in the `LicenceReason` union for that reason and no other:\n * it never arrives over the wire.\n *\n * ---------------------------------------------------------------------------\n * ## Gotcha 4 \u2014 `license_not_found` cannot mean \"the key has a typo\"\n *\n * This is the one that would have cost us a customer.\n *\n * A sandbox licence is invisible to a request that does not carry\n * `X-Numaya-Environment: sandbox`. What comes back is not an error:\n *\n * ```\n * POST /v1/licenses/validate  {key, feature}            \u2192 200 valid:false reason:license_not_found\n * POST /v1/licenses/validate  {key, feature} + sandbox  \u2192 200 valid:true  hasFeature:true\n * ```\n *\n * A plausible rejection with a plausible reason, on the happy status code. Read\n * naively it says \"bad key\", the admin retypes a key that was always correct,\n * and the workspace sits in rules-only forever while every layer of the\n * fail-open design politely hides it.\n *\n * ### Why treating it as an environment problem is honest\n *\n * Because the service itself separates the two causes, and we measured where it\n * draws the line (2026-08-04, live):\n *\n * | Key                                        | Response                            |\n * |--------------------------------------------|-------------------------------------|\n * | Not a key the service knows, any shape     | **`401`**, empty body               |\n * | One character altered in a real key        | **`401`**, empty body               |\n * | A real key, wrong environment              | `200 valid:false license_not_found` |\n * | A real key, right environment              | `200 valid:true`                    |\n *\n * The key **is** the credential on these endpoints \u2014 it is sent in the request\n * body in place of an `Authorization` header \u2014 so a key the service cannot\n * resolve at all fails authentication and never reaches the licence lookup.\n * `license_not_found` is therefore only reachable by a key that authenticated:\n * it exists, it is spelled correctly, and no licence matched it *in the\n * environment this request asked for*.\n *\n * That leaves exactly two causes, and the notice in `audit.ts` names both:\n * we asked the wrong environment, or the licence was deleted from the right\n * one. What it must never say is \"check the key for a typo\" \u2014 the 401 above is\n * what a typo actually looks like, and it maps to `invalid_licence`, which says\n * precisely that.\n *\n * No signal here is invented. We do not guess the environment from the shape of\n * the key: customer licence keys are `NUMAYA-XXXXX-XXXXX-XXXXX-X` in **both**\n * environments and carry no sandbox marker. (The `nml_live_` / `nml_test_`\n * prefixes in the spec belong to org API keys, which Greenlight never holds.)\n * The only thing we know is which environment *we* asked for, and that is a\n * local fact we can state without inference.\n * ---------------------------------------------------------------------------\n */\n\nimport { LICENCE_NOT_FOUND_REASON } from 'src/constants/licence-identifiers';\nimport {\n  type LicenceReason,\n  type LicenceValidationResponse,\n} from 'src/licensing/types';\n\n/**\n * The reason strings the service is documented to send when `valid: false`.\n * Anything outside this set is mapped to `invalid_licence` rather than passed\n * through, so a new reason code shipped by Numaya cannot inject an unknown\n * string into audit rows the admin filters on.\n *\n * `device_not_activated` is listed even though it was never observed for our\n * policy types \u2014 see gotcha 2 in `state.ts`. If a future `NodeLocked` policy\n * does produce it, it should read as itself, not as a generic failure.\n */\nconst KNOWN_INVALID_REASONS: ReadonlySet<string> = new Set<LicenceReason>([\n  'revoked',\n  'suspended',\n  'expired',\n  'device_not_activated',\n  'feature_not_licensed',\n  'quota_exceeded',\n]);\n\nexport const normaliseInvalidReason = (\n  reason: string | null,\n): LicenceReason => {\n  // Gotcha 4. Checked before the known-reason set because the service's spelling\n  // (`license_not_found`) is not a member of `LicenceReason` and would otherwise\n  // fall through to `invalid_licence` \u2014 whose admin notice tells the customer to\n  // check their key for a typo, which is the single most misleading thing we\n  // could say about a correctly-typed key pointed at the wrong environment.\n  if (reason !== null && reason.trim().toLowerCase() === LICENCE_NOT_FOUND_REASON) {\n    return 'licence_not_found_in_environment';\n  }\n\n  if (reason !== null && KNOWN_INVALID_REASONS.has(reason)) {\n    return reason as LicenceReason;\n  }\n\n  return 'invalid_licence';\n};\n\n/**\n * The gate. **Both** booleans, always.\n *\n * Takes a structural type rather than the full response so the cached\n * entitlement \u2014 which stores the same two booleans and nothing else about the\n * decision \u2014 goes through the identical predicate. One gate, two callers, no\n * chance of the cache path drifting from the live path.\n */\nexport const isEnrichmentEntitled = (entitlement: {\n  readonly valid: boolean;\n  readonly hasFeature: boolean;\n}): boolean => entitlement.valid === true && entitlement.hasFeature === true;\n\n/**\n * Why enrichment is on or off, for one entitlement.\n *\n * Order matters and is the whole point:\n *\n *  1. `!valid` wins outright \u2014 a suspended licence is suspended regardless of\n *     what its feature list still claims. Reporting `feature_not_licensed` for\n *     a suspended licence with the feature would send the admin to the wrong\n *     support page entirely.\n *  2. `valid && !hasFeature` is the derived `feature_not_licensed` \u2014 the\n *     licence is healthy, this capability simply is not part of it. This is the\n *     upgrade prompt, not an error.\n *  3. Otherwise: licensed.\n */\nexport const entitlementReason = (entitlement: {\n  readonly valid: boolean;\n  readonly hasFeature: boolean;\n  readonly reason: string | null;\n}): LicenceReason => {\n  if (!entitlement.valid) {\n    return normaliseInvalidReason(entitlement.reason);\n  }\n\n  if (!entitlement.hasFeature) {\n    return 'feature_not_licensed';\n  }\n\n  return 'licensed';\n};\n\n/**\n * Convenience for the live path: both answers from one response.\n */\nexport const resolveEntitlement = (\n  response: LicenceValidationResponse,\n): { readonly entitled: boolean; readonly reason: LicenceReason } => ({\n  entitled: isEnrichmentEntitled(response),\n  reason: entitlementReason(response),\n});\n", "/**\n * `resolveLicenceState` \u2014 the entire licensing decision, as one pure function.\n *\n * Everything impure happened before this call: the HTTP adapter turned the wire\n * into a `LicenceValidateOutcome`, the store read the cache, the run masked the\n * key and read the clock. What is left is arithmetic and a decision table, which\n * is why every interesting case in this module has a test rather than a comment\n * promising it works.\n *\n * ===========================================================================\n * ## The golden rule this module exists to protect\n *\n * *Greenlight never hard-blocks on a licence state.* Every branch below returns\n * either `full` or `rules-only`, and `rules-only` is a fully working product:\n * deterministic scoring, the gate, the queue, the audit trail. There is no\n * branch that stops scoring, and there is deliberately no way to express one \u2014\n * `LicenceMode` has two members and neither of them is \"off\".\n *\n * The earlier draft of the integration spec proposed a hard block once the\n * offline grace window expired. It is withdrawn: a Numaya-side outage lasting\n * three days would then start silently dropping a customer's leads on the floor,\n * which is a far worse outcome for them *and* for us than three days of\n * unlicensed enrichment would have been for us alone.\n *\n * ===========================================================================\n * ## Gotcha 2 \u2014 activation is not a precondition for validity\n *\n * The service documents a `device_not_activated` reason, which invites the\n * classic recovery loop: validate, see `device_not_activated`, call `activate`,\n * validate again. For our policies that loop is dead code. Validating a\n * brand-new Trial licence **before any activation at all** returned\n * `valid: true, activatedCount: 0`. Activation on `Trial` and `Subscription`\n * types is slot consumption, not a gate.\n *\n * So this module never treats a missing activation as invalidating, never\n * re-validates after activating, and `activate` is called exactly once, at\n * install, from `licence-run.ts`. `device_not_activated` remains in the reason\n * vocabulary only because a future `NodeLocked` policy might genuinely produce\n * it, and it should then read as itself.\n *\n * ## Why activation state is sticky, and why that is not a contradiction\n *\n * Gotcha 2 says validity does not depend on activation. Gotcha 3 says exceeding\n * the activation limit is a bare `409` on the `activate` call. Put together,\n * they have a consequence that neither states on its own:\n *\n *   A workspace whose activation was refused with `409` \u2014 because the licence\n *   is already bound to a different workspace \u2014 will still get\n *   `valid: true, hasFeature: true` from `validate`, because validation does not\n *   check slots for these licence types.\n *\n * If the `409` were only handled at install time, the very next nightly run\n * would see a healthy validation and quietly switch enrichment back on. The\n * activation limit would be unenforceable in practice. So the `409` is persisted\n * (`LicenceActivationState`) and re-applied on every resolution, *after* the\n * entitlement decision, as an override. It is cleared only by a subsequent\n * successful `activate` \u2014 i.e. by the admin actually freeing a slot or buying a\n * seat, and reinstalling.\n *\n * ===========================================================================\n * ## The decision table\n *\n * | Input                                     | Mode         | Reason                                      | Source  |\n * |-------------------------------------------|--------------|---------------------------------------------|---------|\n * | No `LICENCE_KEY`                          | `rules-only` | `no_licence_key`                            | `none`  |\n * | Live: `valid && hasFeature`               | `full`       | `licensed`                                  | `live`  |\n * | Live: `valid && !hasFeature`              | `rules-only` | `feature_not_licensed` *(derived)*          | `live`  |\n * | Live: `!valid`                            | `rules-only` | `suspended` / `expired` / `revoked` / \u2026     | `live`  |\n * | Live: `!valid`, `license_not_found`       | `rules-only` | `licence_not_found_in_environment`          | `live`  |\n * | `401` \u2014 key refused as a credential       | `rules-only` | `invalid_licence` *(no cache fallback)*     | `none`  |\n * | `404` on activate \u2014 wrong environment     | `rules-only` | `licence_not_found_in_environment`          | `none`  |\n * | Failure, cache `< 24h`                    | as cached    | as cached                                   | `cache` |\n * | Failure, cache `24\u201372h`                   | `rules-only` | `licence_service_unreachable` *(or 429/\u2026)*  | `grace` |\n * | Failure, cache `> 72h` or never validated | `rules-only` | `\u2026_grace_expired` *(or 429/\u2026)*              | `none`  |\n * | Any of the above + sticky `409`           | `rules-only` | `max_activations_reached`                   | *kept*  |\n * ===========================================================================\n */\n\nimport {\n  classifyCache,\n  type CacheFreshness,\n} from 'src/licensing/cache';\nimport {\n  entitlementReason,\n  isEnrichmentEntitled,\n} from 'src/licensing/entitlement';\nimport {\n  type CachedLicenceValidation,\n  type LicenceActivationState,\n  type LicenceCallFailure,\n  type LicenceEnvironmentName,\n  type LicenceKeyPresence,\n  type LicenceReason,\n  type LicenceSeverity,\n  type LicenceState,\n  type LicenceValidateOutcome,\n  type LicenceValidationResponse,\n} from 'src/licensing/types';\n\n/* -------------------------------------------------------------------------- */\n/* Severity                                                                    */\n/* -------------------------------------------------------------------------- */\n\n/**\n * How loudly the admin hears about a reason.\n *\n * `feature_not_licensed` is a **notice**, not a problem: the licence is healthy\n * and the customer simply has not bought enrichment. Rendering that in red next\n * to a genuine revocation would train admins to ignore the red.\n *\n * `no_licence_key` is likewise a notice. Running Greenlight unlicensed is a\n * supported configuration \u2014 it is the free floor, not a fault.\n */\nconst REASON_SEVERITY: Readonly<Record<LicenceReason, LicenceSeverity>> = {\n  licensed: 'ok',\n  no_licence_key: 'notice',\n  feature_not_licensed: 'notice',\n  // A `problem`, and deliberately the same rank as a revocation. The whole\n  // failure mode is that it looks survivable \u2014 a 200, a plausible reason, a\n  // product that keeps working \u2014 so the one place it is allowed to be loud is\n  // here. See gotcha 4 in `entitlement.ts`.\n  licence_not_found_in_environment: 'problem',\n  expired: 'problem',\n  revoked: 'problem',\n  suspended: 'problem',\n  quota_exceeded: 'warning',\n  device_not_activated: 'warning',\n  max_activations_reached: 'problem',\n  invalid_licence: 'problem',\n  licence_service_rate_limited: 'warning',\n  licence_response_malformed: 'warning',\n  licence_service_unreachable: 'warning',\n  licence_service_unreachable_grace_expired: 'problem',\n};\n\nconst SEVERITY_RANK: Readonly<Record<LicenceSeverity, number>> = {\n  ok: 0,\n  notice: 1,\n  warning: 2,\n  problem: 3,\n};\n\nconst worst = (a: LicenceSeverity, b: LicenceSeverity): LicenceSeverity =>\n  SEVERITY_RANK[a] >= SEVERITY_RANK[b] ? a : b;\n\n/**\n * Renewal is a deadline, so it escalates on its own clock rather than waiting\n * for the licence to actually break. `expiryWarning` is the service's own flag;\n * the seven-day floor is ours, because a Trial is fourteen days long and a\n * warning that only fires on the service's schedule may arrive too late for a\n * purchase order to clear.\n */\nexport const EXPIRY_WARNING_DAYS = 7;\n\nconst isExpiringSoon = (\n  daysRemaining: number | null,\n  expiryWarning: boolean,\n): boolean =>\n  expiryWarning || (daysRemaining !== null && daysRemaining <= EXPIRY_WARNING_DAYS);\n\n/* -------------------------------------------------------------------------- */\n/* Failure \u2192 reason                                                            */\n/* -------------------------------------------------------------------------- */\n\n/**\n * What to tell the admin when we could not get a fresh answer and the cache no\n * longer covers us.\n *\n * A `429` and a `503` are not the same event and must not read the same. \"The\n * licence service is unreachable\" sends someone to check DNS and firewalls; if\n * the truth is that we are being rate-limited, that is an hour of their day\n * spent on the wrong system. The mode is identical in every case \u2014 rules-only \u2014\n * so the only thing this choice affects is whether the message is useful.\n */\nconst failureReason = (\n  failure: LicenceCallFailure,\n  covered: boolean,\n): LicenceReason => {\n  switch (failure.kind) {\n    case 'rate_limited':\n      return 'licence_service_rate_limited';\n    case 'malformed_response':\n      return 'licence_response_malformed';\n    case 'key_rejected':\n      // A 401 is the service refusing the key as a credential \u2014 measured live\n      // as what a typo'd or unknown key actually produces. Reporting it as\n      // \"cannot reach the licensing service\" would send an admin to check DNS\n      // and firewalls over a mistyped key.\n      return 'invalid_licence';\n    case 'licence_not_found':\n      // `activate`'s out-of-band form of gotcha 4: a 404 rather than a 200 with\n      // a reason, but the same cause and the same fix.\n      return 'licence_not_found_in_environment';\n    default:\n      return covered\n        ? 'licence_service_unreachable'\n        : 'licence_service_unreachable_grace_expired';\n  }\n};\n\n/**\n * Whether a failure is the service *answering* rather than the service being\n * unavailable.\n *\n * Definitive failures skip the cache \u2192 grace ladder entirely. The ladder exists\n * to ride out an outage; there is no outage to ride out when the service has\n * told us the key is refused or the licence is not in this environment, and\n * serving `full` from a cache for another 24 hours would only delay the notice\n * that fixes it. This is the same treatment `valid: false` already gets.\n */\nconst isDefinitive = (failure: LicenceCallFailure): boolean =>\n  failure.kind === 'key_rejected' || failure.kind === 'licence_not_found';\n\n/* -------------------------------------------------------------------------- */\n/* Cache entry                                                                 */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The snapshot written after a successful live validation.\n *\n * Note what is stored: the two gate booleans, the reason, and the renewal\n * fields. Not the key, not the licence id, not the activation counts. The cache\n * is read by the offline path to answer one question \u2014 \"may enrichment run\" \u2014\n * and storing more than that only widens what a storage dump reveals.\n */\nexport const buildCacheEntry = (\n  response: LicenceValidationResponse,\n  maskedKey: string,\n  now: Date,\n): CachedLicenceValidation => ({\n  cachedAt: now.toISOString(),\n  maskedKey,\n  valid: response.valid,\n  hasFeature: response.hasFeature,\n  reason: response.reason,\n  features: response.features,\n  tier: response.tier,\n  daysRemaining: response.daysRemaining,\n  expiryWarning: response.expiryWarning,\n  expiryAt: response.expiryAt,\n});\n\n/* -------------------------------------------------------------------------- */\n/* Resolution                                                                  */\n/* -------------------------------------------------------------------------- */\n\nexport interface ResolveLicenceStateInput {\n  /** Whether a key is configured, and its mask. Never the key itself. */\n  readonly presence: LicenceKeyPresence;\n  /** `null` when no call was attempted \u2014 i.e. when there is no key. */\n  readonly outcome: LicenceValidateOutcome | null;\n  readonly cached: CachedLicenceValidation | null;\n  readonly activation: LicenceActivationState;\n  /**\n   * Which environment the call was routed to. Required rather than defaulted:\n   * a resolver that quietly assumes `production` is exactly the silent\n   * misrouting this whole module now exists to make visible.\n   */\n  readonly environment: LicenceEnvironmentName;\n  readonly now: Date;\n}\n\nexport interface ResolvedLicence {\n  readonly state: LicenceState;\n  /** Non-null only after a live validation. Nothing else may write the cache. */\n  readonly cacheWrite: CachedLicenceValidation | null;\n}\n\nconst emptyState = (\n  input: ResolveLicenceStateInput,\n  reason: LicenceReason,\n): LicenceState => ({\n  mode: 'rules-only',\n  reason,\n  source: 'none',\n  severity: REASON_SEVERITY[reason],\n  maskedKey: input.presence.maskedKey,\n  environment: input.environment,\n  checkedAt: input.now.toISOString(),\n  cacheAgeMs: null,\n  failureKind: null,\n  observedValid: null,\n  observedHasFeature: null,\n  tier: null,\n  daysRemaining: null,\n  expiryWarning: false,\n  expiryAt: null,\n  features: [],\n});\n\n/**\n * Applied last, over any entitlement decision. See \"Why activation state is\n * sticky\" above \u2014 without this, the `409` is unenforceable because `validate`\n * does not consult activation slots for our licence types.\n *\n * It cannot override `no_licence_key`: a workspace with no key has nothing to\n * say about activation, and reporting `max_activations_reached` there would be\n * nonsense left over from a previous key.\n */\nconst applyActivationOverride = (\n  state: LicenceState,\n  activation: LicenceActivationState,\n): LicenceState => {\n  if (activation.status !== 'limit_reached') {\n    return state;\n  }\n\n  if (state.reason === 'no_licence_key') {\n    return state;\n  }\n\n  return {\n    ...state,\n    mode: 'rules-only',\n    reason: 'max_activations_reached',\n    severity: worst(state.severity, REASON_SEVERITY['max_activations_reached']),\n  };\n};\n\nconst resolveFromLive = (\n  input: ResolveLicenceStateInput,\n  response: LicenceValidationResponse,\n): ResolvedLicence => {\n  const reason = entitlementReason(response);\n  const entitled = isEnrichmentEntitled(response);\n\n  const severity = isExpiringSoon(response.daysRemaining, response.expiryWarning)\n    ? worst(REASON_SEVERITY[reason], 'warning')\n    : REASON_SEVERITY[reason];\n\n  const state: LicenceState = {\n    mode: entitled ? 'full' : 'rules-only',\n    reason,\n    source: 'live',\n    severity,\n    maskedKey: input.presence.maskedKey,\n    environment: input.environment,\n    checkedAt: input.now.toISOString(),\n    cacheAgeMs: 0,\n    failureKind: null,\n    observedValid: response.valid,\n    observedHasFeature: response.hasFeature,\n    tier: response.tier,\n    daysRemaining: response.daysRemaining,\n    expiryWarning: response.expiryWarning,\n    expiryAt: response.expiryAt,\n    features: response.features,\n  };\n\n  return {\n    state: applyActivationOverride(state, input.activation),\n    // The cache records what the service said, not what we decided. A sticky\n    // 409 must not be baked into the entitlement snapshot, or clearing the 409\n    // would leave a poisoned cache behind for up to 24 hours.\n    cacheWrite: buildCacheEntry(response, input.presence.maskedKey, input.now),\n  };\n};\n\nconst resolveFromCache = (\n  input: ResolveLicenceStateInput,\n  failure: LicenceCallFailure,\n  cached: CachedLicenceValidation,\n  freshness: CacheFreshness,\n  ageMs: number,\n): ResolvedLicence => {\n  const covered = freshness === 'grace';\n\n  // `fresh` is the only branch that may still return `full`. Beyond 24h the\n  // entitlement is not trusted for the paid feature \u2014 see cache.ts for why the\n  // two failure directions are not symmetric.\n  const reason: LicenceReason =\n    freshness === 'fresh' ? entitlementReason(cached) : failureReason(failure, covered);\n\n  const mode = freshness === 'fresh' && isEnrichmentEntitled(cached) ? 'full' : 'rules-only';\n\n  const baseSeverity =\n    freshness === 'fresh'\n      ? // Serving from cache is itself worth a notice: the admin should be able\n        // to tell \"validated tonight\" from \"we have not reached Numaya since\n        // Tuesday\", even while nothing is degraded.\n        worst(REASON_SEVERITY[reason], 'notice')\n      : REASON_SEVERITY[reason];\n\n  const severity = isExpiringSoon(cached.daysRemaining, cached.expiryWarning)\n    ? worst(baseSeverity, 'warning')\n    : baseSeverity;\n\n  const state: LicenceState = {\n    mode,\n    reason,\n    source: freshness === 'fresh' ? 'cache' : freshness === 'grace' ? 'grace' : 'none',\n    severity,\n    maskedKey: input.presence.maskedKey,\n    environment: input.environment,\n    checkedAt: input.now.toISOString(),\n    cacheAgeMs: ageMs,\n    failureKind: failure.kind,\n    observedValid: cached.valid,\n    observedHasFeature: cached.hasFeature,\n    tier: cached.tier,\n    daysRemaining: cached.daysRemaining,\n    expiryWarning: cached.expiryWarning,\n    expiryAt: cached.expiryAt,\n    features: cached.features,\n  };\n\n  return {\n    state: applyActivationOverride(state, input.activation),\n    // A failed call never writes the cache. Refreshing `cachedAt` on a failure\n    // would make the 24h and 72h windows unreachable \u2014 the cache would look\n    // permanently fresh while never being re-validated, which is the exact\n    // opposite of what the window is for.\n    cacheWrite: null,\n  };\n};\n\nexport const resolveLicenceState = (\n  input: ResolveLicenceStateInput,\n): ResolvedLicence => {\n  if (!input.presence.hasKey) {\n    return {\n      state: applyActivationOverride(\n        emptyState(input, 'no_licence_key'),\n        input.activation,\n      ),\n      cacheWrite: null,\n    };\n  }\n\n  if (input.outcome !== null && input.outcome.kind === 'validated') {\n    return resolveFromLive(input, input.outcome.response);\n  }\n\n  // No outcome with a key present means the caller could not even attempt the\n  // call (no base URL configured, for instance). Treat it as a transport\n  // failure so it walks the identical cache ladder rather than inventing a\n  // fifteenth branch that would need its own tests.\n  const failure: LicenceCallFailure =\n    input.outcome === null\n      ? { kind: 'transport_failure', detail: 'validation not attempted' }\n      : input.outcome;\n\n  // The service answered. There is nothing to wait out, so no cache ladder.\n  if (isDefinitive(failure)) {\n    const reason = failureReason(failure, false);\n\n    return {\n      state: applyActivationOverride(\n        { ...emptyState(input, reason), failureKind: failure.kind },\n        input.activation,\n      ),\n      cacheWrite: null,\n    };\n  }\n\n  const { freshness, ageMs } = classifyCache(input.cached?.cachedAt, input.now);\n\n  if (input.cached === null || freshness === null || ageMs === null) {\n    const reason = failureReason(failure, false);\n\n    return {\n      state: applyActivationOverride(\n        { ...emptyState(input, reason), failureKind: failure.kind },\n        input.activation,\n      ),\n      cacheWrite: null,\n    };\n  }\n\n  return resolveFromCache(input, failure, input.cached, freshness, ageMs);\n};\n", "/**\n * The real calibration cache seal: HMAC-SHA256 under a secret derived from the\n * licence key.\n *\n * This is one of only two modules in Greenlight that touch the raw licence key \u2014\n * the other is the HTTP adapter, which puts it in a request body. Everything\n * else works with a mask or with the ports declared in `src/licensing/types.ts`.\n * That is a structural guarantee rather than a discipline, and this file is\n * written to keep it: the key enters through the factory argument, is\n * immediately turned into a derived secret, and is never stored, returned,\n * logged or included in any error.\n *\n * ---------------------------------------------------------------------------\n * ## Why the key is not used as the HMAC secret directly\n *\n * It would work, and it would be a needless second use of the same secret for a\n * second purpose. The derivation is one HMAC with a fixed, versioned label, so\n * the cache secret and the credential are cryptographically separated: an\n * adversary who somehow recovered the cache secret has not recovered the licence\n * key, and could not present it to the licensing service.\n *\n * The label carries a version. Changing it invalidates every existing seal at\n * once, which is the intended lever if the sealed form ever has to change: every\n * workspace falls back to shipped defaults for one night and re-fetches. That is\n * a safe migration precisely because falling back is not a failure.\n *\n * ## Why WebCrypto\n *\n * Same reason as `src/calibration/verify.ts`: `crypto.subtle` is a global, so\n * nothing here depends on how the logic-function bundler treats Node built-ins.\n * A bundler that stubbed `node:crypto` would have silently turned the seal into\n * a no-op; a missing global cannot, because the absence is checked and produces\n * \"no seal\", which refuses every cache.\n * ---------------------------------------------------------------------------\n */\n\nimport { type CalibrationSealPort, NO_SEAL } from 'src/calibration/seal';\n\n/**\n * Domain-separation label. Versioned so the sealed form can be changed by\n * changing this string, with a one-night fall-back to shipped defaults as the\n * entire migration cost.\n */\nconst SEAL_LABEL = 'greenlight.calibration.cache.v1';\n\nconst subtle = (): SubtleCrypto | null => {\n  const candidate = (globalThis as { crypto?: { subtle?: SubtleCrypto } }).crypto\n    ?.subtle;\n\n  return candidate === undefined ? null : candidate;\n};\n\nconst toBase64 = (bytes: Uint8Array): string => {\n  let binary = '';\n\n  for (const byte of bytes) {\n    binary += String.fromCharCode(byte);\n  }\n\n  return btoa(binary);\n};\n\n/**\n * Constant-time comparison of two base64 tags.\n *\n * The timing channel here is not a realistic attack \u2014 the attacker would need\n * to be inside the customer's own infrastructure, at which point they can read\n * the cache directly \u2014 but an early-exit string compare in code that checks a\n * MAC is the kind of thing that gets copied somewhere it does matter.\n */\nconst equalTags = (left: string, right: string): boolean => {\n  if (left.length !== right.length) {\n    return false;\n  }\n\n  let difference = 0;\n\n  for (let index = 0; index < left.length; index += 1) {\n    difference |= left.charCodeAt(index) ^ right.charCodeAt(index);\n  }\n\n  return difference === 0;\n};\n\n/**\n * Build a seal for a given licence key.\n *\n * A `null` or blank key yields `NO_SEAL`, which seals nothing and accepts\n * nothing \u2014 so an unlicensed workspace cannot present a cache, and cannot\n * accidentally be given one.\n */\nexport const createLicenceKeySeal = (\n  licenceKey: string | null,\n): CalibrationSealPort => {\n  if (typeof licenceKey !== 'string' || licenceKey.trim().length === 0) {\n    return NO_SEAL;\n  }\n\n  const key = licenceKey.trim();\n\n  // Derived once per seal, held in this closure and nowhere else. The raw key\n  // is not captured beyond this line.\n  let cachedSecret: CryptoKey | null = null;\n\n  const secret = async (crypto: SubtleCrypto): Promise<CryptoKey> => {\n    if (cachedSecret !== null) {\n      return cachedSecret;\n    }\n\n    const encoder = new TextEncoder();\n\n    const keyMaterial = await crypto.importKey(\n      'raw',\n      encoder.encode(key) as unknown as BufferSource,\n      { name: 'HMAC', hash: 'SHA-256' },\n      false,\n      ['sign'],\n    );\n\n    const derived = await crypto.sign(\n      'HMAC',\n      keyMaterial,\n      encoder.encode(SEAL_LABEL) as unknown as BufferSource,\n    );\n\n    cachedSecret = await crypto.importKey(\n      'raw',\n      derived,\n      { name: 'HMAC', hash: 'SHA-256' },\n      false,\n      ['sign'],\n    );\n\n    return cachedSecret;\n  };\n\n  const tag = async (canonical: string): Promise<string | null> => {\n    const crypto = subtle();\n\n    if (crypto === null) {\n      return null;\n    }\n\n    try {\n      const signature = await crypto.sign(\n        'HMAC',\n        await secret(crypto),\n        new TextEncoder().encode(canonical) as unknown as BufferSource,\n      );\n\n      return toBase64(new Uint8Array(signature));\n    } catch {\n      // Deliberately no detail. Anything derived from a failure while handling\n      // key material is a string this codebase has promised never to produce.\n      return null;\n    }\n  };\n\n  return {\n    seal: tag,\n    verify: async (canonical, expected) => {\n      const computed = await tag(canonical);\n\n      return computed !== null && equalTags(computed, expected);\n    },\n  };\n};\n", "/**\n * The licensing composition root: reads the environment, drives the ports, hands\n * everything to the pure core, writes the result back out.\n *\n * Kept out of the `define*` file for the same reason `scoring-run.ts` is \u2014 so\n * the whole run can be exercised against fakes, with an injected `now` and no\n * network. There is no `new Date()` and no `new CoreApiClient()` below.\n *\n * ===========================================================================\n * ## Two entry points\n *\n * `runLicenceInstall`  \u2014 called once from the post-install hook. Activates, then\n *                        validates.\n * `runLicenceRevalidation` \u2014 called nightly by the cron function. Validates only.\n *\n * `activate` is **not** called nightly. It is idempotent on the fingerprint and\n * would be harmless, but it is a slot-claim, not a health check, and calling it\n * every night would turn one write per install into one write per workspace per\n * day against a service that gains nothing from them.\n *\n * ## What is sent to Numaya, and what is not\n *\n * The licence key, the workspace id (as `deviceFingerprint`) and the workspace\n * display name (as `deviceName`). That is the entire payload, and the data-egress\n * table in `ARCHITECTURE.md` says so. No lead, contact, company or score data\n * leaves the workspace on this path \u2014 there is no field in the request body that\n * could carry any.\n *\n * ## Why an unresolvable workspace is not fatal\n *\n * `deviceFingerprint` is optional on `validate`. If the workspace identity\n * cannot be read \u2014 the metadata API is unavailable, or a future SDK moves\n * `currentWorkspace` \u2014 the run still validates, just without a fingerprint, and\n * skips activation because activation *requires* one. That is a strictly better\n * outcome than failing the check: the customer keeps their entitlement, and the\n * only thing lost is the readable device name in Numaya's admin view.\n * ===========================================================================\n */\n\nimport {\n  DEFAULT_LICENCE_API_BASE_URL,\n  DEFAULT_LICENCE_ENVIRONMENT,\n  ENRICHMENT_FEATURE_NAME,\n} from 'src/constants/licence-identifiers';\nimport {\n  buildLicenceAuditDetail,\n  buildLicenceAuditRow,\n  describeLicenceForAdmin,\n  maskLicenceKey,\n  redactLicenceKey,\n  resolveLicenceState,\n  type LicenceNotice,\n  type LicenceEnvironmentName,\n  type LicenceState,\n  type LicenceStorePort,\n  type LicensingPort,\n  type LicenceValidateOutcome,\n} from 'src/licensing';\nimport {\n  describeCalibration,\n  refreshCalibration,\n  type CalibrationStorePort,\n  type RefreshCalibrationOutcome,\n} from 'src/calibration';\nimport {\n  describeError,\n  logGreenlight,\n  type GreenlightApiClient,\n} from 'src/logic-functions/greenlight-api';\nimport { createLicenceKeySeal } from 'src/logic-functions/licence-cache-seal';\n\n/* -------------------------------------------------------------------------- */\n/* Ports                                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport interface WorkspaceIdentity {\n  readonly workspaceId: string;\n  readonly workspaceName: string | null;\n}\n\n/**\n * Resolving \"which workspace am I\" is I/O, so it is a port like everything else.\n * The real adapter is `licence-workspace-identity.ts`; `null` means \"could not\n * tell\", which every caller below treats as a degradation rather than a failure.\n */\nexport interface WorkspaceIdentityPort {\n  read(): Promise<WorkspaceIdentity | null>;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Environment                                                                 */\n/* -------------------------------------------------------------------------- */\n\nexport interface LicenceEnvironment {\n  /** `null` when unset or blank \u2014 the supported, unlicensed configuration. */\n  readonly licenceKey: string | null;\n  readonly baseUrl: string;\n  readonly environment: LicenceEnvironmentName;\n}\n\n/**\n * Application variables reach a logic function as environment variables.\n *\n * The `?? DEFAULT_LICENCE_API_BASE_URL` is belt-and-braces: the variable ships\n * with that value declared in `application-config.ts`, so it should always be\n * present. It would be absent on a workspace that installed a build predating\n * the variable and has not re-synced, and defaulting beats an empty base URL\n * only in that the failure is then identical to a normal outage.\n *\n * `LICENCE_ENVIRONMENT` is read the strict way round: **only** the exact string\n * `sandbox` selects sandbox, and everything else \u2014 unset, blank, misspelled,\n * `SANDBOX_`, a value from a future release \u2014 is production. Defaulting an\n * unrecognised value to sandbox would let a typo route a paying customer at the\n * test estate, where their licence does not exist and where this whole exercise\n * started. Casing and surrounding whitespace are forgiven because they are\n * transcription noise, not intent.\n */\nexport const readLicenceEnvironment = (\n  env: Record<string, string | undefined> = process.env,\n): LicenceEnvironment => {\n  const rawKey = env['LICENCE_KEY'];\n  const trimmed = typeof rawKey === 'string' ? rawKey.trim() : '';\n  const rawBase = env['LICENCE_API_BASE_URL'];\n  const rawEnvironment = env['LICENCE_ENVIRONMENT'];\n\n  return {\n    licenceKey: trimmed.length === 0 ? null : trimmed,\n    baseUrl:\n      typeof rawBase === 'string' && rawBase.trim().length > 0\n        ? rawBase.trim()\n        : DEFAULT_LICENCE_API_BASE_URL,\n    environment:\n      typeof rawEnvironment === 'string' &&\n      rawEnvironment.trim().toLowerCase() === 'sandbox'\n        ? 'sandbox'\n        : DEFAULT_LICENCE_ENVIRONMENT,\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Runs                                                                        */\n/* -------------------------------------------------------------------------- */\n\nexport interface LicenceRunDeps {\n  readonly licensing: LicensingPort;\n  readonly store: LicenceStorePort;\n  /**\n   * Where the verified calibration payload is cached and its state published.\n   *\n   * Optional, and its absence is a supported configuration rather than a\n   * mistake: a run without it resolves the entitlement exactly as it always\n   * did and simply does no calibration work. That is what makes this an\n   * additive change to a path whose failure is silent and nightly.\n   */\n  readonly calibration?: CalibrationStorePort | null;\n  readonly identity: WorkspaceIdentityPort;\n  /** Optional: without it the run still resolves state, it just writes no row. */\n  readonly client?: GreenlightApiClient | null;\n  readonly licenceKey: string | null;\n  /**\n   * Which environment the `licensing` port was pointed at. Passed separately\n   * rather than read back off the port because the port is an interface with no\n   * way to ask, and because the resolved state has to record what we *asked\n   * for* even when the call never left the building.\n   */\n  readonly environment: LicenceEnvironmentName;\n  readonly now: Date;\n}\n\nexport interface LicenceRunOutcome {\n  readonly state: LicenceState;\n  readonly notice: LicenceNotice;\n  /** What the activation attempt did, for the install path's return value. */\n  readonly activation: 'claimed' | 'limit_reached' | 'skipped' | 'failed' | 'not_attempted';\n  /** Null when no calibration store was wired. */\n  readonly calibration: RefreshCalibrationOutcome | null;\n}\n\n/**\n * Best-effort provenance row. Never fails the run \u2014 a licence check that\n * succeeded but could not be written to the audit log is still a licence check\n * that succeeded, and the resolved state has already been published to key-value\n * storage where the UI reads it.\n */\nconst writeLicenceAuditRow = async (\n  client: GreenlightApiClient | null | undefined,\n  state: LicenceState,\n  calibration: RefreshCalibrationOutcome | null,\n): Promise<boolean> => {\n  if (client === null || client === undefined) {\n    return false;\n  }\n\n  try {\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: buildLicenceAuditRow(state, calibration?.state ?? null),\n        },\n        id: true,\n      },\n    });\n\n    return true;\n  } catch (error) {\n    logGreenlight('licence_audit_write_failed', { error: describeError(error) });\n\n    return false;\n  }\n};\n\n/**\n * Resolve, persist, publish, audit, log. Shared by both entry points so the\n * install path and the nightly path cannot drift.\n */\nconst finishRun = async (\n  deps: LicenceRunDeps,\n  outcome: LicenceValidateOutcome | null,\n  activation: LicenceRunOutcome['activation'],\n): Promise<LicenceRunOutcome> => {\n  const presence = {\n    hasKey: deps.licenceKey !== null,\n    maskedKey: maskLicenceKey(deps.licenceKey),\n  };\n\n  const [cached, activationState] = await Promise.all([\n    deps.store.readCache(),\n    deps.store.readActivation(),\n  ]);\n\n  const { state, cacheWrite } = resolveLicenceState({\n    presence,\n    outcome,\n    cached,\n    activation: activationState,\n    environment: deps.environment,\n    now: deps.now,\n  });\n\n  if (cacheWrite !== null) {\n    await deps.store.writeCache(cacheWrite);\n  }\n\n  await deps.store.publishState(state);\n\n  // Calibration runs strictly after the entitlement has been resolved and\n  // published, and never before. See `src/calibration/refresh.ts`, \"Ordering\":\n  // nothing about a word list may be able to delay, fail or precede the decision\n  // that gates the paid feature and writes the admin notice.\n  const calibration =\n    deps.calibration === null || deps.calibration === undefined\n      ? null\n      : await refreshCalibration({\n          store: deps.calibration,\n          // Built here because this is one of the two modules that legitimately\n          // holds the raw key. The seal itself never receives it \u2014 see\n          // `licence-cache-seal.ts`.\n          seal: createLicenceKeySeal(deps.licenceKey),\n          metadata:\n            outcome !== null && outcome.kind === 'validated'\n              ? outcome.response.customerMetadata\n              : undefined,\n          live: outcome !== null && outcome.kind === 'validated',\n          // The same entitlement that gates enrichment. Calibration is the other\n          // half of what a licence buys, so it is bought on the same terms.\n          entitled: state.mode === 'full',\n          now: deps.now,\n        });\n\n  // Contains the mask, never the key \u2014 `buildLicenceAuditDetail` reads only\n  // fields of `LicenceState`, and `LicenceState` has no field that could hold\n  // a key. `describeCalibration` reads only counts and version numbers, never\n  // payload content.\n  logGreenlight('licence_resolved', {\n    ...buildLicenceAuditDetail(state),\n    activationAttempt: activation,\n    ...(calibration === null ? {} : describeCalibration(calibration)),\n  });\n\n  await writeLicenceAuditRow(deps.client, state, calibration);\n\n  return {\n    state,\n    notice: describeLicenceForAdmin(state),\n    activation,\n    calibration,\n  };\n};\n\nconst validateOnce = async (\n  deps: LicenceRunDeps,\n  workspace: WorkspaceIdentity | null,\n): Promise<LicenceValidateOutcome | null> => {\n  if (deps.licenceKey === null) {\n    return null;\n  }\n\n  try {\n    return await deps.licensing.validate({\n      key: deps.licenceKey,\n      deviceFingerprint: workspace?.workspaceId ?? null,\n      feature: ENRICHMENT_FEATURE_NAME,\n    });\n  } catch (error) {\n    // `LicensingPort` is documented as never throwing and the shipped adapter\n    // honours it. This catch is here because \"documented\" is not \"enforced by\n    // the type system\": a future adapter, or a test double, can throw, and the\n    // consequence would be a cron run that dies before publishing state.\n    // Downgrading it to the outcome the ladder already handles costs three\n    // lines and removes the failure mode entirely.\n    return {\n      kind: 'transport_failure',\n      detail: redactLicenceKey(describeError(error), deps.licenceKey),\n    };\n  }\n};\n\nconst readWorkspace = async (\n  identity: WorkspaceIdentityPort,\n): Promise<WorkspaceIdentity | null> => {\n  try {\n    return await identity.read();\n  } catch (error) {\n    logGreenlight('licence_workspace_identity_failed', {\n      error: describeError(error),\n    });\n\n    return null;\n  }\n};\n\n/**\n * Install: claim the activation slot, then validate.\n *\n * ## Why it validates even after a `409`\n *\n * The integration note's sketch returns early on `409`. This does not, and the\n * difference matters: because `validate` does not consult activation slots for\n * `Trial` / `Subscription` licences (gotcha 2), a refused workspace still gets\n * `valid: true, hasFeature: true`. Returning early would hide that, and \u2014 worse\n * \u2014 the *nightly* run has no activation step at all, so it would quietly switch\n * enrichment on the following morning.\n *\n * Instead the `409` is persisted, and `resolveLicenceState` applies it as an\n * override on every subsequent resolution. Validating anyway is then free\n * information: the admin notice can say how many days are left on the licence\n * that another workspace is holding, which is exactly what they need to decide\n * whether to free a slot or buy a seat.\n *\n * ## Idempotency\n *\n * `activate` is idempotent on `deviceFingerprint` \u2014 a repeat call with the same\n * workspace id returns the existing activation and consumes no second slot.\n * Reinstalling is therefore safe, and a successful activate clears a previously\n * stored `limit_reached`, which is how an admin who freed a slot recovers.\n */\nexport const runLicenceInstall = async (\n  deps: LicenceRunDeps,\n): Promise<LicenceRunOutcome> => {\n  if (deps.licenceKey === null) {\n    logGreenlight('licence_install_skipped', { reason: 'no_licence_key' });\n\n    return finishRun(deps, null, 'not_attempted');\n  }\n\n  const workspace = await readWorkspace(deps.identity);\n  let activation: LicenceRunOutcome['activation'] = 'skipped';\n\n  if (workspace === null) {\n    logGreenlight('licence_activate_skipped', {\n      reason: 'workspace_identity_unavailable',\n    });\n  } else {\n    const result = await deps.licensing.activate({\n      key: deps.licenceKey,\n      deviceFingerprint: workspace.workspaceId,\n      deviceName: workspace.workspaceName,\n    });\n\n    if (result.kind === 'activated') {\n      activation = 'claimed';\n      await deps.store.writeActivation({\n        status: 'claimed',\n        at: deps.now.toISOString(),\n      });\n    } else if (result.kind === 'activation_limit_reached') {\n      activation = 'limit_reached';\n      await deps.store.writeActivation({\n        status: 'limit_reached',\n        at: deps.now.toISOString(),\n      });\n    } else {\n      // A transport failure tells us nothing about the slot, so the stored\n      // activation state is left exactly as it was. Overwriting a known\n      // `claimed` with `unknown` because the network blipped would be losing\n      // information, not recording it.\n      activation = 'failed';\n      logGreenlight('licence_activate_failed', { failureKind: result.kind });\n    }\n  }\n\n  const outcome = await validateOnce(deps, workspace);\n\n  return finishRun(deps, outcome, activation);\n};\n\n/**\n * Nightly: validate, refresh the cache, republish the state, write the row.\n *\n * Never throws. The cron handler has nowhere to report a thrown error to, and a\n * run that dies before `finishRun` is a run that leaves yesterday's state\n * published \u2014 which is fine for a night and wrong for a month.\n */\nexport const runLicenceRevalidation = async (\n  deps: LicenceRunDeps,\n): Promise<LicenceRunOutcome> => {\n  const workspace = deps.licenceKey === null ? null : await readWorkspace(deps.identity);\n  const outcome = await validateOnce(deps, workspace);\n\n  return finishRun(deps, outcome, 'not_attempted');\n};\n", "/**\n * Resolving \"which Twenty workspace is this\" \u2014 the value Numaya stores as the\n * licence's `deviceFingerprint`.\n *\n * ## Why the workspace id is the fingerprint\n *\n * Greenlight's unit of installation is a workspace, not a machine: the app runs\n * inside the customer's Twenty instance, there is no hardware to fingerprint,\n * and a per-seat identifier would meter the wrong thing (the product plan sells\n * a per-workspace base fee, not seats). The workspace UUID is stable across\n * restarts, upgrades and reinstalls, which is exactly what makes `activate`\n * idempotent. `maxActivations: 1` then means \"one workspace per licence\".\n *\n * `deviceName` is the workspace display name \u2014 purely so Numaya's admin view\n * reads \"Acme Corp\" rather than a bare UUID when a customer calls about a slot.\n *\n * ## Why this lives on the metadata API\n *\n * `currentWorkspace` is a metadata-API query, not a core-API one, so this is the\n * only file in the app that instantiates `MetadataApiClient`. It is isolated\n * behind `WorkspaceIdentityPort` for the usual reason \u2014 the client reads its URL\n * and token from the process environment in its constructor, which no unit test\n * has \u2014 and for one more: this is the least-verified call in the licensing path,\n * and isolating it means a wrong guess costs a `null` rather than an exception.\n *\n * Returning `null` is a supported outcome throughout. `licence-run.ts` then\n * validates without a fingerprint and skips activation; the customer keeps their\n * entitlement and only the readable device name is lost.\n */\n\nimport { MetadataApiClient } from 'twenty-client-sdk/metadata';\n\nimport {\n  describeError,\n  logGreenlight,\n} from 'src/logic-functions/greenlight-api';\nimport {\n  type WorkspaceIdentity,\n  type WorkspaceIdentityPort,\n} from 'src/logic-functions/licence-run';\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\n/**\n * Tolerant to the point of paranoia, on purpose: the shape of this response is\n * the one thing in the licensing path that was never exercised against a live\n * instance, and the failure mode of getting it wrong must be \"no fingerprint\",\n * never \"install hook throws\".\n */\nexport const readWorkspaceIdentityFrom = (payload: unknown): WorkspaceIdentity | null => {\n  if (!isRecord(payload)) {\n    return null;\n  }\n\n  const workspace = payload['currentWorkspace'];\n\n  if (!isRecord(workspace)) {\n    return null;\n  }\n\n  const id = workspace['id'];\n\n  if (typeof id !== 'string' || id.length === 0) {\n    return null;\n  }\n\n  const displayName = workspace['displayName'];\n\n  return {\n    workspaceId: id,\n    workspaceName:\n      typeof displayName === 'string' && displayName.length > 0 ? displayName : null,\n  };\n};\n\nexport const metadataWorkspaceIdentity: WorkspaceIdentityPort = {\n  read: async () => {\n    try {\n      const client = new MetadataApiClient();\n      const response = (await client.query({\n        currentWorkspace: { id: true, displayName: true },\n      })) as unknown;\n\n      const identity = readWorkspaceIdentityFrom(response);\n\n      if (identity === null) {\n        logGreenlight('licence_workspace_identity_unreadable', {\n          note: 'currentWorkspace query returned an unexpected shape; validating without a device fingerprint',\n        });\n      }\n\n      return identity;\n    } catch (error) {\n      logGreenlight('licence_workspace_identity_failed', {\n        error: describeError(error),\n      });\n\n      return null;\n    }\n  },\n};\n"],
  "mappings": ";;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AAEO,QAAM,cAAc,CAAI,SAA0C;AACvE,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,cAAW;AAIjB,QAAM,YAAY,CAAI,SAAsC;AACjE,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,YAAS;AAIf,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS,YAAY,CAAC,OAAO,MAAM,IAAI;IACvD;AAFa,YAAA,WAAQ;AAId,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,WAAQ;AAId,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,WAAQ;AAId,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,WAAQ;;;;;;;;;;ACpBd,QAAM,SAAS,CAAI,SAAgC;AACxD,aAAO,SAAS;IAClB;AAFa,YAAA,SAAM;AAIZ,QAAM,aAAa,CAAwB,SAA0B;AAC1E,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,aAAU;AAIhB,QAAM,WAAW,CACtB,SAC0B;AAC1B,aAAO,CAAC,QAAA,OAAO,IAAI,KAAK,OAAO,SAAS;IAC1C;AAJa,YAAA,WAAQ;AAMd,QAAM,UAAU,CAAO,SAAwC;AACpE,aAAO,MAAM,QAAQ,IAAI;IAC3B;AAFa,YAAA,UAAO;AAIb,QAAM,QAAQ,CAAU,SAA0C;AACvE,aAAO,gBAAgB;IACzB;AAFa,YAAA,QAAK;AAIX,QAAM,QAAQ,CAAO,SAAoC;AAC9D,aAAO,gBAAgB;IACzB;AAFa,YAAA,QAAK;AAIX,QAAM,YAAY,CACvB,SACyB;AACzB,aAAO,gBAAgB;IACzB;AAJa,YAAA,YAAS;AAMf,QAAM,YAAY,CACvB,SACsB;AACtB,aAAO,gBAAgB;IACzB;AAJa,YAAA,YAAS;AAMf,QAAM,SAAS,CAAI,SAAgC;AACxD,aAAO,gBAAgB;IACzB;AAFa,YAAA,SAAM;;;;;;;;;;ACxCnB,QAAA,eAAA;AACA,QAAA,eAAA;AAEO,QAAM,iBAAiB,CAAsB,SAA0B;AAC5E,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,iBAAc;AAIpB,QAAM,kBAAkB,CAAO,SAAwC;AAC5E,aAAO,aAAA,QAAQ,IAAI,KAAK,KAAK,SAAS;IACxC;AAFa,YAAA,kBAAe;AAIrB,QAAM,mBAAmB,CAAI,SAAoC;AACtE,aAAO,aAAA,SAAS,IAAI,KAAK,KAAK,SAAS;IACzC;AAFa,YAAA,mBAAgB;AAItB,QAAM,gBAAgB,CAAI,SAAoC;AACnE,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,gBAAa;AAInB,QAAM,YAAY,CAAI,SAAoC;AAC/D,aAAO,aAAA,SAAS,IAAI,KAAK,OAAO,UAAU,IAAI;IAChD;AAFa,YAAA,YAAS;AAIf,QAAM,oBAAoB,CAAI,SAAoC;AACvE,aAAO,QAAA,UAAU,IAAI,KAAK,OAAO;IACnC;AAFa,YAAA,oBAAiB;AAIvB,QAAM,uBAAuB,CAAI,SAAoC;AAC1E,aAAO,QAAA,UAAU,IAAI,KAAK,QAAQ;IACpC;AAFa,YAAA,uBAAoB;AAI1B,QAAM,oBAAoB,CAAI,SAAoC;AACvE,aAAO,QAAA,UAAU,IAAI,KAAK,OAAO;IACnC;AAFa,YAAA,oBAAiB;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AC/B9B,YAAA,cAAA,aAAA,qBAAA;AACA,iBAAA,uBAAA,OAAA;AACA,YAAA,aAAA,aAAA,oBAAA;AACA,iBAAA,sBAAA,OAAA;AACA,YAAA,aAAA,aAAA,oBAAA;AACA,iBAAA,sBAAA,OAAA;;;;;ACLA,SAAS,qBAAqB;;;ACI9B,IAAM,sBAAsB,CAAC,YAAY;AAAA,EACvC,SAAS;AAAA,EACT;AAAA,EACA,QAAQ,CAAC;AACX;AAEA,IAAM,eAAe;AAAA,EACnB,IAAI,SAAS,MAAM;AACjB,QAAI,SAAS,aAAc,QAAO;AAClC,QAAI,SAAS,OAAO,YAAa,QAAO,MAAM;AAC9C,QAAI,OAAO,SAAS,SAAU,QAAO;AACrC,WAAO,IAAI,MAAM,MAAM,QAAW,YAAY;AAAA,EAChD;AAAA,EACA,QAAQ;AACN,WAAO,IAAI,MAAM,MAAM,QAAW,YAAY;AAAA,EAChD;AACF;AACA,IAAM,YAAY,IAAI,MAAM,MAAM,QAAW,YAAY;AAiBlD,IAAM,iCAAiC;;;ACxBvC,IAAM,mDACX;;;ACIK,IAAM,yBAAyD;AAAA,EACpE;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UACE;AAAA,IACF,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AACF;AAEA,IAAM,cAAwD,IAAI;AAAA,EAChE,uBAAuB,IAAI,CAAC,SAAS,CAAC,KAAK,KAAK,IAAI,CAAC;AACvD;AAwBO,IAAM,2BAA2B,CAAC,QACvC,+BAA+B,GAAG;AAE7B,IAAM,+BAET,OAAO;AAAA,EACT,OAAO;AAAA,IACL,uBAAuB,IAAI,CAAC,SAAS;AAAA,MACnC,KAAK;AAAA,MACL,yBAAyB,KAAK,GAAG;AAAA,IACnC,CAAC;AAAA,EACH;AACF;;;ACxEO,IAAM,wBAAsC;AAAA,EACjD,aAAa,CAAC,eAAe,gBAAgB,WAAW,aAAa;AAAA,EACrE,UAAU,CAAC,YAAY,oBAAoB,QAAQ;AAAA,EACnD,QAAQ,CAAC,UAAU,WAAW,0BAA0B,gBAAgB;AAAA,EACxE,eAAe,CAAC,aAAa,iBAAiB,qBAAqB,aAAa;AAAA,EAChF,aAAa,CAAC,QAAQ,YAAY,eAAe,WAAW;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,EAe5D,UAAU,CAAC,YAAY,SAAS,MAAM;AAAA,EACtC,WAAW,CAAC,aAAa,gBAAgB;AAAA,EACzC,OAAO,CAAC,UAAU,SAAS,uBAAuB,WAAW;AAAA,EAC7D,OAAO,CAAC,UAAU,SAAS,6BAA6B,QAAQ;AAAA,EAChE,gBAAgB,CAAC,kBAAkB,cAAc,aAAa,WAAW;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,EAOzE,YAAY,CAAC,sBAAsB;AAAA,EACnC,mBAAmB,CAAC,6BAA6B;AAAA,EAEjD,UAAU,CAAC,YAAY,gBAAgB,eAAe,cAAc;AACtE;AAGO,IAAM,cAAyB;AAAA,EACpC,YAAY,CAAC;AAAA,EACb,SAAS,CAAC;AAAA,EACV,WAAW,CAAC;AACd;AAOO,IAAM,gBAAwC;AAAA,EACnD,EAAE,IAAI,aAAa,OAAO,aAAa,UAAU,GAAG;AAAA,EACpD,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,GAAG;AAAA,EAC1C,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,GAAG;AAAA,EAC1C,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,EAAE;AAC3C;AAGO,IAAM,yBAAyB;AAE/B,IAAM,0BAA0B;AAEhC,IAAM,gCAAmD;AAAA,EAC9D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAEO,IAAM,4BAA+C;AAAA,EAC1D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAEO,IAAM,iCAAoD;AAAA,EAC/D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAGO,IAAM,qBAAwC;AAAA,EACnD;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;;;AC/CO,IAAM,gBAAgB,CAC3B,OACA,QAA2B,uBACf,MAAM,SAAS,MAAM,KAAK,EAAE,YAAY,CAAC;;;ACrIhD,IAAM,wBAAqC;AAAA,EAChD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,aAAa;AAAA,EAErB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,OAAO,KAAK,KAAK,aAAa;AAEpC,QAAI,SAAS,MAAM;AACjB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,QAAI,cAAc,MAAM,OAAO,iBAAiB,KAAK,KAAK,KAAK,EAAE,SAAS,GAAG;AAC3E,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,IAAI;AAAA,QACrB,QAAQ;AAAA,QACR,QAAQ,EAAE,aAAa,KAAK;AAAA,MAC9B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,6BAA6B,IAAI;AAAA,MAC9C,QAAQ,EAAE,aAAa,KAAK;AAAA,IAC9B;AAAA,EACF;AACF;;;AC2BA,IAAM,iBAAiB,CAAC,SACtB,KAAK,KAAK,EAAE,YAAY,EAAE,QAAQ,UAAU,GAAG;AAEjD,IAAM,cAAc,CAClB,gBACA,cACA,WACgB;AAChB,QAAM,UACJ,WAAW,OAAO,KAAK,4BAA4B,eAAe,MAAM,CAAC;AAE3E,QAAM,cAAc,iBAChB,eACE,6GAA6G,OAAO,6CACpH,sDAAsD,OAAO,6CAC/D;AAEJ,SAAO;AAAA,IACL,SAAS;AAAA,IACT;AAAA,IACA,QAAQ,iBACJ,+MACA;AAAA,IACJ,QAAQ;AAAA,MACN,YAAY;AAAA,MACZ,wBAAwB;AAAA,MACxB,2BAA2B;AAAA,MAC3B,mBAAmB;AAAA;AAAA;AAAA;AAAA,MAInB,gBAAgB;AAAA,IAClB;AAAA,EACF;AACF;AAEO,IAAM,uBAAoC;AAAA,EAC/C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,cAAc,qBAAqB,UAAU;AAAA,EAErD,UAAU,CAAC,EAAE,KAAK,MAAM;AAEtB,UAAM,iBAAiB,KAAK,WAAW,YAAY;AACnD,UAAM,oBAAoB,KAAK,KAAK,mBAAmB;AAEvD,UAAM,WAAW,KAAK,WAAW,UAAU;AAE3C,UAAM,iBAAiB,mBAAmB,QAAQ,sBAAsB;AACxE,UAAM,eAAe,aAAa;AAElC,QAAI,kBAAkB,cAAc;AAClC,aAAO,YAAY,gBAAgB,cAAc,iBAAiB;AAAA,IACpE;AAIA,QAAI,mBAAmB,QAAQ,aAAa,MAAM;AAChD,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,QACF,QAAQ;AAAA,UACN,YAAY;AAAA,UACZ,wBAAwB;AAAA,UACxB,2BAA2B;AAAA,UAC3B,mBAAmB;AAAA,UACnB,gBAAgB;AAAA,UAChB,0BAA0B;AAAA,QAC5B;AAAA,MACF;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aACE,mBAAmB,QACf,kGACA;AAAA,MACN,QAAQ;AAAA,QACN,YAAY;AAAA,QACZ,wBAAwB;AAAA,QACxB,2BAA2B;AAAA,QAC3B,mBAAmB;AAAA,QACnB,gBAAgB;AAAA,QAChB,0BAA0B;AAAA,MAC5B;AAAA,IACF;AAAA,EACF;AACF;;;AClKO,IAAM,YAAY,CAAC,UACxB,MAAM,KAAK,EAAE,YAAY,EAAE,QAAQ,QAAQ,GAAG;AAEhD,IAAM,iBAAiB,CAAC,UACtB,MAAM,QAAQ,uBAAuB,MAAM;AAyBtC,IAAM,kBAAkB,CAAC,UAAkB,YAA6B;AAC7E,QAAM,SAAS,UAAU,OAAO;AAEhC,MAAI,OAAO,WAAW,GAAG;AACvB,WAAO;AAAA,EACT;AAEA,QAAM,UAAU,IAAI;AAAA,IAClB,sBAAsB,eAAe,MAAM,CAAC;AAAA,IAC5C;AAAA,EACF;AAEA,SAAO,QAAQ,KAAK,UAAU,QAAQ,CAAC;AACzC;AAEO,IAAM,oBAAoB,CAC/B,UACA,aACkB,SAAS,KAAK,CAAC,YAAY,gBAAgB,UAAU,OAAO,CAAC,KAAK;AAG/E,IAAM,cAAc,CACzB,QACA,YACkB;AAClB,QAAM,aAAa,IAAI,IAAI,QAAQ,IAAI,SAAS,CAAC;AAEjD,SAAO,OAAO,KAAK,CAAC,UAAU,WAAW,IAAI,UAAU,KAAK,CAAC,CAAC,KAAK;AACrE;AAEA,IAAM,gBACJ;AAQK,IAAM,aAAa,CAAC,QAAoC;AAC7D,QAAM,UAAU,IAAI,KAAK;AAEzB,MAAI,QAAQ,WAAW,KAAK,QAAQ,SAAS,KAAK;AAChD,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,cAAc,KAAK,OAAO,GAAG;AAChC,WAAO;AAAA,EACT;AAEA,QAAM,YAAY,QAAQ,YAAY,GAAG;AACzC,QAAM,YAAY,QAAQ,MAAM,GAAG,SAAS;AAC5C,QAAM,SAAS,QAAQ,MAAM,YAAY,CAAC;AAE1C,MAAI,UAAU,SAAS,IAAI;AACzB,WAAO;AAAA,EACT;AAEA,SAAO,EAAE,SAAS,WAAW,UAAU,YAAY,GAAG,QAAQ,OAAO,YAAY,EAAE;AACrF;AAGO,IAAM,iBAAiB,CAAC,cAA8B;AAC3D,QAAM,aAAa,UAAU,MAAM,GAAG,EAAE,CAAC,KAAK;AAC9C,SAAO,WAAW,QAAQ,WAAW,EAAE;AACzC;AAEO,IAAM,uBAAuB;AAE7B,IAAM,cAAc,CAAC,SAAe,WACxC,MAAM,QAAQ,IAAI,QAAQ,QAAQ,KAAK;AAEnC,IAAM,UAAU,CAAC,OAAe,aAA6B;AAClE,QAAM,SAAS,MAAM;AACrB,SAAO,KAAK,MAAM,QAAQ,MAAM,IAAI;AACtC;AAEO,IAAM,UAAU,CAAC,UAA0B;AAChD,MAAI,CAAC,OAAO,SAAS,KAAK,GAAG;AAC3B,WAAO;AAAA,EACT;AAEA,SAAO,KAAK,IAAI,GAAG,KAAK,IAAI,GAAG,KAAK,CAAC;AACvC;;;AC/GO,IAAM,2BAAwC;AAAA,EACnD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,aAAa,UAAU;AAAA,EAE/B,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,YAAY,KAAK,KAAK,WAAW;AACvC,UAAM,WAAW,KAAK,KAAK,UAAU;AACrC,UAAM,UAAU,aAAa;AAE7B,QAAI,YAAY,MAAM;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,gBAAgB,kBAAkB,SAAS,OAAO,mBAAmB;AAE3E,QAAI,kBAAkB,MAAM;AAC1B,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,OAAO;AAAA,QACxB,QAAQ,EAAE,OAAO,SAAS,gBAAgB,cAAc;AAAA,MAC1D;AAAA,IACF;AAEA,UAAM,aAAa,kBAAkB,SAAS,OAAO,gBAAgB;AAErE,QAAI,eAAe,MAAM;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,QAAQ;AAAA,QACR,aAAa,IAAI,OAAO;AAAA,QACxB,QACE;AAAA,QACF,QAAQ,EAAE,OAAO,SAAS,gBAAgB,WAAW;AAAA,MACvD;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,IAAI,OAAO;AAAA,MACxB,QACE;AAAA,MACF,QAAQ,EAAE,OAAO,QAAQ;AAAA,IAC3B;AAAA,EACF;AACF;;;ACxDO,IAAM,wBAAqC;AAAA,EAChD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,OAAO;AAAA,EAEf,UAAU,CAAC,EAAE,KAAK,MAAM;AACtB,UAAM,aAAa,KAAK,SAAS,OAAO;AAExC,QAAI,WAAW,WAAW,GAAG;AAC3B,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,SAAS,WACZ,IAAI,CAAC,cAAc,WAAW,SAAS,CAAC,EACxC,KAAK,CAAC,cAAc,cAAc,IAAI;AAEzC,QAAI,WAAW,UAAa,WAAW,MAAM;AAC3C,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,WAAW,CAAC,KAAK,EAAE;AAAA,QACpC,QAAQ;AAAA,QACR,QAAQ,EAAE,OAAO,WAAW,CAAC,KAAK,KAAK;AAAA,MACzC;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,OAAO;AAAA,MAC9B,QAAQ,EAAE,OAAO,OAAO,SAAS,QAAQ,OAAO,OAAO;AAAA,IACzD;AAAA,EACF;AACF;;;ACzCO,IAAM,yBAAsC;AAAA,EACjD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,aAAa;AAAA,EAErB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,OAAO,KAAK,KAAK,aAAa;AAEpC,QAAI,SAAS,MAAM;AACjB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,QAAI,cAAc,MAAM,OAAO,iBAAiB,KAAK,CAAC,SAAS,KAAK,IAAI,GAAG;AACzE,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,IAAI;AAAA,QACrB,QAAQ;AAAA,QACR,QAAQ,EAAE,aAAa,KAAK;AAAA,MAC9B;AAAA,IACF;AAEA,UAAM,QAAQ,KACX,KAAK,EACL,MAAM,KAAK,EACX,OAAO,CAAC,SAAS,SAAS,KAAK,IAAI,CAAC;AAEvC,QAAI,MAAM,SAAS,GAAG;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,QAAQ;AAAA,QACR,aAAa,uBAAuB,IAAI;AAAA,QACxC,QAAQ;AAAA,QACR,QAAQ,EAAE,aAAa,KAAK;AAAA,MAC9B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,IAAI;AAAA,MACpB,QAAQ,EAAE,aAAa,KAAK;AAAA,IAC9B;AAAA,EACF;AACF;;;ACrDA,IAAM,aAAa;AACnB,IAAM,aAAa;AAEZ,IAAM,wBAAqC;AAAA,EAChD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,OAAO;AAAA,EAEf,UAAU,CAAC,EAAE,KAAK,MAAM;AACtB,UAAM,aAAa,KAAK,SAAS,OAAO;AAExC,QAAI,WAAW,WAAW,GAAG;AAC3B,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,SAAS,WAAW,KAAK,CAAC,cAAc;AAC5C,YAAM,WAAW,UAAU,QAAQ,eAAe,EAAE,EAAE,QAAQ,OAAO,EAAE;AAEvE,UAAI,CAAC,QAAQ,KAAK,QAAQ,GAAG;AAC3B,eAAO;AAAA,MACT;AAEA,aAAO,SAAS,UAAU,cAAc,SAAS,UAAU;AAAA,IAC7D,CAAC;AAED,QAAI,WAAW,QAAW;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,WAAW,CAAC,KAAK,EAAE;AAAA,QACpC,QAAQ,oDAA+C,UAAU,QAAQ,UAAU;AAAA,QACnF,QAAQ,EAAE,OAAO,WAAW,CAAC,KAAK,KAAK;AAAA,MACzC;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,MAAM;AAAA,MACtB,QAAQ,EAAE,OAAO,OAAO;AAAA,IAC1B;AAAA,EACF;AACF;;;ACjDO,IAAM,yBAAsC;AAAA,EACjD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,OAAO;AAAA,EAEf,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,aAAa,KAAK,SAAS,OAAO;AACxC,UAAM,SAAS,WACZ,IAAI,CAAC,cAAc,WAAW,SAAS,CAAC,EACxC,KAAK,CAAC,cAAc,cAAc,IAAI;AAEzC,QAAI,WAAW,UAAa,WAAW,MAAM;AAC3C,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,OAAO,eAAe,OAAO,SAAS;AAE5C,QAAI,OAAO,oBAAoB,SAAS,IAAI,GAAG;AAC7C,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,OAAO,OAAO,iBAAiB,IAAI;AAAA,QACnD,QACE;AAAA,QACF,QAAQ,EAAE,OAAO,OAAO,SAAS,SAAS,KAAK;AAAA,MACjD;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,OAAO;AAAA,MAC9B,QAAQ,EAAE,OAAO,OAAO,SAAS,SAAS,KAAK;AAAA,IACjD;AAAA,EACF;AACF;;;AC1CA,IAAM,wBAAwB;AAEvB,IAAM,oBAAiC;AAAA,EAC5C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,gBAAgB;AAAA,EAExB,UAAU,CAAC,EAAE,QAAQ,KAAK,KAAK,MAAM;AACnC,QAAI,QAAQ,MAAM;AAChB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,gBACJ,OAAO,mBAAmB,kBAAkB,OAAO;AAErD,UAAM,aAAa,KAAK,KAAK,gBAAgB;AAE7C,QAAI,eAAe,MAAM;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ,sIAAsI,aAAa;AAAA,QAC3J,QAAQ,EAAE,cAAc;AAAA,MAC1B;AAAA,IACF;AAEA,UAAM,UAAU,YAAY,YAAY,GAAG;AAE3C,QAAI,UAAU,CAAC,uBAAuB;AACpC,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,qCAAqC,WAAW,YAAY,EAAE,MAAM,GAAG,EAAE,CAAC;AAAA,QACvF,QAAQ;AAAA,QACR,QAAQ,EAAE,YAAY,WAAW,YAAY,GAAG,cAAc;AAAA,MAChE;AAAA,IACF;AAEA,UAAM,MAAM,KAAK,IAAI,GAAG,OAAO;AAE/B,QAAI,OAAO,eAAe;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,iBAAiB,QAAQ,KAAK,CAAC,CAAC,0BAA0B,aAAa;AAAA,QACpF,QAAQ,EAAE,SAAS,QAAQ,KAAK,CAAC,GAAG,cAAc;AAAA,MACpD;AAAA,IACF;AAEA,QAAI,MAAM,gBAAgB,GAAG;AAC3B,YAAM,SAAS,QAAQ,KAAK,MAAM,iBAAiB,aAAa;AAEhE,aAAO;AAAA,QACL,SAAS;AAAA,QACT;AAAA,QACA,aAAa,iBAAiB,QAAQ,KAAK,CAAC,CAAC,wBAAwB,aAAa;AAAA,QAClF,QAAQ;AAAA,QACR,QAAQ,EAAE,SAAS,QAAQ,KAAK,CAAC,GAAG,cAAc;AAAA,MACpD;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,iBAAiB,QAAQ,KAAK,CAAC,CAAC,yCAAoC,aAAa;AAAA,MAC9F,QAAQ;AAAA,MACR,QAAQ,EAAE,SAAS,QAAQ,KAAK,CAAC,GAAG,cAAc;AAAA,IACpD;AAAA,EACF;AACF;;;AC/EO,IAAM,qBAAkC;AAAA,EAC7C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,eAAe;AAAA,EAEvB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,QAAQ,OAAO,IAAI;AAEzB,QAAI,MAAM,WAAW,GAAG;AACtB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,YAAY,KAAK,OAAO,eAAe;AAE7C,QAAI,cAAc,MAAM;AACtB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,UAAU,MAAM;AAAA,MACpB,CAAC,SACC,aAAa,KAAK,iBACjB,KAAK,iBAAiB,QAAQ,aAAa,KAAK;AAAA,IACrD;AAEA,QAAI,YAAY,QAAW;AACzB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,SAAS,yCAAyC,QAAQ,KAAK;AAAA,QAC/E,QAAQ,EAAE,WAAW,MAAM,QAAQ,MAAM;AAAA,MAC3C;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,SAAS;AAAA,MACzB,QAAQ,4EAA4E,MACjF,IAAI,CAAC,SAAS,KAAK,KAAK,EACxB,KAAK,IAAI,CAAC;AAAA,MACb,QAAQ,EAAE,UAAU;AAAA,IACtB;AAAA,EACF;AACF;;;ACzDO,IAAM,kBAA+B;AAAA,EAC1C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,YAAY,aAAa;AAAA,EAEjC,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,UAAU,OAAO,IAAI;AAE3B,QAAI,QAAQ,WAAW,GAAG;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,SAAS,KAAK,SAAS,UAAU;AAEvC,QAAI,OAAO,WAAW,GAAG;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,QACR,QAAQ,EAAE,kBAAkB,QAAQ,KAAK,IAAI,EAAE;AAAA,MACjD;AAAA,IACF;AAEA,UAAM,UAAU,YAAY,QAAQ,OAAO;AAE3C,QAAI,YAAY,MAAM;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,OAAO;AAAA,QACvB,QAAQ,EAAE,UAAU,QAAQ;AAAA,MAC9B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,KAAK,IAAI,CAAC;AAAA,MACjC,QAAQ,gFAAgF,QAAQ,KAAK,IAAI,CAAC;AAAA,MAC1G,QAAQ,EAAE,UAAU,OAAO,KAAK,IAAI,GAAG,kBAAkB,QAAQ,KAAK,IAAI,EAAE;AAAA,IAC9E;AAAA,EACF;AACF;;;ACrDO,IAAM,gBAA6B;AAAA,EACxC,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,QAAQ;AAAA,EAEhB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,UAAU,OAAO,IAAI;AAE3B,QAAI,QAAQ,WAAW,GAAG;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,SAAS,KAAK,SAAS,QAAQ;AAErC,QAAI,OAAO,WAAW,GAAG;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,QACR,QAAQ,EAAE,eAAe,QAAQ,KAAK,IAAI,EAAE;AAAA,MAC9C;AAAA,IACF;AAEA,UAAM,UAAU,YAAY,QAAQ,OAAO;AAE3C,QAAI,YAAY,MAAM;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,OAAO;AAAA,QACvB,QAAQ,EAAE,QAAQ,QAAQ;AAAA,MAC5B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,KAAK,IAAI,CAAC;AAAA,MACjC,QAAQ,2EAA2E,QAAQ,KAAK,IAAI,CAAC;AAAA,MACrG,QAAQ,EAAE,QAAQ,OAAO,KAAK,IAAI,GAAG,eAAe,QAAQ,KAAK,IAAI,EAAE;AAAA,IACzE;AAAA,EACF;AACF;;;ACjCO,IAAM,YAAoC;AAAA,EAC/C;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;;;ACzBO,IAAM,yBAAyB;;;ACsKtC,IAAM,wBAAwB,CAAC,YAAwC;AACrE,QAAM,OAAgD,EAAE,GAAG,QAAQ;AAEnE,aAAW,CAAC,KAAK,IAAI,KAAK,OAAO,QAAQ,4BAA4B,GAAG;AACtE,UAAM,UAAU;AAChB,UAAM,aAAa,KAAK,OAAO,KAAK,CAAC;AAErC,SAAK,OAAO,IAAI,WAAW,SAAS,IAAI,IACpC,aACA,CAAC,GAAG,YAAY,IAAI;AAAA,EAC1B;AAEA,SAAO;AACT;AAWO,IAAM,qBAAqB,CAChC,QAAgC,WAChC,cAC2B;AAAA,EAC3B,KAAK;AAAA,EACL,OAAO,OAAO;AAAA,IACZ,MAAM,IAAI,CAAC,SAAS;AAAA,MAClB,KAAK;AAAA,MACL;AAAA,QACE,SAAS,KAAK;AAAA,QACd,UAAU,KAAK;AAAA,QACf,QAAQ,KAAK;AAAA,MACf;AAAA,IACF,CAAC;AAAA,EACH;AAAA,EACA,OAAO;AAAA,EACP,eAAe;AAAA,EACf,sBAAsB;AAAA,EACtB,oBAAoB,CAAC;AAAA,EACrB,qBACE,UAAU,uBAAuB;AAAA,EACnC,kBAAkB,UAAU,oBAAoB;AAAA,EAChD,qBACE,UAAU,uBAAuB;AAAA,EACnC,mBAAmB,UAAU,qBAAqB;AAAA,EAClD,cAAc,sBAAsB,qBAAqB;AAC3D;;;AC/MO,IAAM,gBAAgB,CAC3B,UAEA,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AAO9D,IAAM,sBAAsB,CACjC,SACA,mBAC8B;AAC9B,MAAI,CAAC,cAAc,OAAO,GAAG;AAC3B,WAAO,CAAC;AAAA,EACV;AAEA,QAAM,aAAa,QAAQ,cAAc;AAEzC,MAAI,CAAC,cAAc,UAAU,GAAG;AAC9B,WAAO,CAAC;AAAA,EACV;AAEA,QAAM,QAAQ,WAAW,OAAO;AAEhC,MAAI,CAAC,MAAM,QAAQ,KAAK,GAAG;AACzB,WAAO,CAAC;AAAA,EACV;AAEA,SAAO,MAAM,QAAQ,CAAC,SAAoC;AACxD,QAAI,CAAC,cAAc,IAAI,GAAG;AACxB,aAAO,CAAC;AAAA,IACV;AAEA,UAAM,OAAO,KAAK,MAAM;AAExB,WAAO,cAAc,IAAI,IAAI,CAAC,IAAI,IAAI,CAAC;AAAA,EACzC,CAAC;AACH;AAGO,IAAM,oBAAoB,CAC/B,YACmC;AACnC,MAAI,SAAyC;AAC7C,MAAI,YAA2B;AAE/B,aAAW,UAAU,SAAS;AAC5B,UAAM,YAAY,OAAO,WAAW;AACpC,UAAM,MAAM,OAAO,cAAc,WAAW,YAAY;AAExD,QAAI,WAAW,QAAQ,cAAc,QAAQ,MAAM,WAAW;AAC5D,eAAS;AACT,kBAAY;AAAA,IACd;AAAA,EACF;AAEA,SAAO;AACT;AAOO,IAAM,gBAAgB,CAC3B,OACA,WACS;AAET,UAAQ,IAAI,KAAK,UAAU,EAAE,KAAK,qBAAqB,OAAO,GAAG,OAAO,CAAC,CAAC;AAC5E;AAEO,IAAM,gBAAgB,CAAC,UAA2B;AACvD,MAAI,iBAAiB,OAAO;AAC1B,WAAO,GAAG,MAAM,IAAI,KAAK,MAAM,OAAO;AAAA,EACxC;AAEA,MAAI,OAAO,UAAU,UAAU;AAC7B,WAAO;AAAA,EACT;AAEA,MAAI;AACF,WAAO,KAAK,UAAU,KAAK,KAAK;AAAA,EAClC,QAAQ;AACN,WAAO;AAAA,EACT;AACF;;;ACFO,IAAM,uBAET;AAAA,EACF,wBAAwB;AAAA,IACtB,OAAO;AAAA,IACP,YAAY;AAAA,EACd;AAAA,EACA,2BAA2B;AAAA,IACzB,OAAO;AAAA,IACP,YAAY;AAAA,EACd;AAAA,EACA,kBAAkB,EAAE,OAAO,kBAAkB,YAAY,WAAW;AACtE;AAgBA,IAAM,aAAa;AAEnB,IAAM,cAAc,CAAC,UAAkC;AACrD,MAAI,OAAO,UAAU,UAAU;AAC7B,WAAO;AAAA,EACT;AAEA,QAAM,UAAU,MAAM,KAAK;AAE3B,SAAO,WAAW,KAAK,OAAO,IAAI,UAAU;AAC9C;AAgBO,IAAM,mBAAmB,CAC9B,iBACsB;AACtB,MAAI,CAAC,cAAc,YAAY,GAAG;AAChC,WAAO,CAAC;AAAA,EACV;AAEA,QAAM,QAA2B,CAAC;AAClC,QAAM,OAAO,oBAAI,IAAY;AAE7B,QAAM,MAAM,CAAC,OAAgB,WAAoC;AAC/D,UAAM,OAAO,YAAY,KAAK;AAE9B,QAAI,SAAS,QAAQ,KAAK,IAAI,IAAI,GAAG;AACnC;AAAA,IACF;AAEA,SAAK,IAAI,IAAI;AACb,UAAM,KAAK,EAAE,MAAM,OAAO,CAAC;AAAA,EAC7B;AAEA,MAAI,aAAa,wBAAwB,GAAG,wBAAwB;AACpE,MAAI,aAAa,2BAA2B,GAAG,2BAA2B;AAE1E,QAAM,eAAe,aAAa,kBAAkB;AAEpD,MAAI,MAAM,QAAQ,YAAY,GAAG;AAC/B,eAAW,SAAS,cAAc;AAChC,UAAI,OAAO,kBAAkB;AAAA,IAC/B;AAAA,EACF;AAEA,SAAO;AACT;AAoBO,IAAM,4BAA4B;AASlC,IAAM,2BAA2B,CACtC,YACA,eAC6B;AAAA,EAC7B,CAAC,UAAU,GAAG;AAAA,IACZ,QAAQ,EAAE,OAAO,GAAG,QAAQ,EAAE,CAAC,SAAS,GAAG,EAAE,IAAI,WAAW,EAAE,EAAE;AAAA,IAChE,OAAO,EAAE,MAAM,EAAE,IAAI,KAAK,EAAE;AAAA,EAC9B;AACF;AAiBO,IAAM,gBAAgB,CAC3B,YACA,aAEA,cAAc,QAAQ,KAAK,cAAc,SAAS,UAAU,CAAC;AAa/D,IAAM,iBAAoC;AAAA,EACxC;AAAA,EACA;AAAA,EACA;AACF;AAOA,IAAM,mBAAmB;AAalB,IAAM,yBAAyB,CACpC,WACA,YACsB;AACtB,MAAI,iBAAiB,KAAK,OAAO,GAAG;AAClC,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,QAAQ,SAAS,SAAS,GAAG;AAChC,WAAO;AAAA,EACT;AAEA,SAAO,eAAe,KAAK,CAAC,WAAW,OAAO,KAAK,OAAO,CAAC,IACvD,WACA;AACN;AAsBO,IAAM,4BAAqD;AAAA,EAChE,SAAS,CAAC;AAAA,EACV,QAAQ;AAAA,EACR,cAAc;AAAA,EACd,WAAW;AACb;AAGA,IAAM,eAAe,CAAC,YAA+C;AACnE,QAAM,MAAM,qBAAqB,QAAQ,MAAM,EAAE;AAEjD,MAAI,QAAQ,MAAM;AAChB,WAAO,CAAC;AAAA,EACV;AAEA,SAAO,sBAAsB,GAAG,EAAE,OAAO,CAAC,SAAS,SAAS,QAAQ,IAAI;AAC1E;AAGA,IAAM,SAAS,CAAC,WAAsC;AACpD,MAAI,OAAO,UAAU,GAAG;AACtB,WAAO,OAAO,CAAC,KAAK;AAAA,EACtB;AAEA,SAAO,GAAG,OAAO,MAAM,GAAG,EAAE,EAAE,KAAK,IAAI,CAAC,QAAQ,OAAO,OAAO,SAAS,CAAC,CAAC;AAC3E;AAcA,IAAM,gBAAgB,CAAC,YAAoC;AACzD,QAAM,YAAY,aAAa,OAAO;AAEtC,UAAQ,QAAQ,QAAQ;AAAA,IACtB,KAAK;AACH,aAAO,UAAU,WAAW,IACxB,8FACA,4BAA4B,OAAO,SAAS,CAAC;AAAA,IAEnD,KAAK;AACH,aAAO,UAAU,WAAW,IACxB,+FACA,4BAA4B,OAAO,SAAS,CAAC;AAAA,IAEnD,KAAK;AAAA,IACL;AACE,aAAO;AAAA,EACX;AACF;AAgBO,IAAM,+BAA+B,CAC1C,SACA,gBACkB;AAClB,MAAI,QAAQ,WAAW,GAAG;AACxB,WAAO;AAAA,EACT;AAEA,QAAM,OACJ,QAAQ,WAAW,IACf,iDAA4C,WAAW,sEACvD,yCAAoC,QAAQ,MAAM,WAAW,WAAW;AAE9E,QAAM,QAAQ,QAAQ;AAAA,IACpB,CAAC,YACC,SAAI,QAAQ,IAAI,WAAM,qBAAqB,QAAQ,MAAM,EAAE,KAAK,uBAAuB,WAAW,WAAM,cAAc,OAAO,CAAC;AAAA,EAClI;AAEA,SAAO;AAAA,IACL;AAAA,IACA,GAAG;AAAA,IACH;AAAA,EACF,EAAE,KAAK,GAAG;AACZ;AAGO,IAAM,wBAAwB,CACnC,SACA,gBAEA,QAAQ,WAAW,KAAK,QAAQ,CAAC,MAAM,SACnC,kDAAuC,QAAQ,CAAC,EAAE,IAAI,4BAAuB,WAAW,KACxF,4CAAsC,QAAQ,MAAM,uCAAuC,WAAW;AAOrG,IAAM,0BAA0B,CACrC,QACA,wBAC6B;AAAA,EAC7B,QAAQ;AAAA,EACR,wBAAwB;AAAA,EACxB,SAAS,OAAO,QAAQ,IAAI,CAAC,aAAa;AAAA,IACxC,MAAM,QAAQ;AAAA,IACd,SAAS,QAAQ;AAAA,IACjB,cAAc,qBAAqB,QAAQ,MAAM,EAAE;AAAA,IACnD,YAAY,qBAAqB,QAAQ,MAAM,EAAE;AAAA,IACjD,qBAAqB,aAAa,OAAO;AAAA,EAC3C,EAAE;AAAA,EACF,QAAQ,OAAO;AAAA,EACf,cAAc,OAAO;AAAA,EACrB,WAAW,OAAO;AACpB;;;AC9XO,IAAM,sBAAsB;AA6K5B,IAAM,kBAAkB,CAAC,SAC9B,SAAS,aAAa,EAAE,oBAAoB,EAAE,IAAI,OAAO,EAAE,IAAI,CAAC;AAyH3D,IAAM,oBAAoB,CAC/B,SAC4B;AAC5B,QAAM,SAAS,gBAAgB,IAAI;AAEnC,SAAO;AAAA,IACL,QAAQ;AAAA,MACN,GAAI,OAAO,KAAK,MAAM,EAAE,SAAS,IAAI,EAAE,QAAQ,EAAE,OAAO,EAAE,IAAI,CAAC;AAAA,MAC/D,YAAY;AAAA,IACd;AAAA,EACF;AACF;AAEO,IAAM,iBAAiB,CAAC,aAAqC;AAClE,MAAI,CAAC,cAAc,QAAQ,GAAG;AAC5B,WAAO;AAAA,EACT;AAEA,QAAM,aAAa,SAAS,QAAQ;AAEpC,MAAI,CAAC,cAAc,UAAU,GAAG;AAC9B,WAAO;AAAA,EACT;AAEA,QAAM,QAAQ,WAAW,YAAY;AAErC,SAAO,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK,KAAK,SAAS,IACnE,KAAK,MAAM,KAAK,IAChB;AACN;;;AC/TO,IAAM,iBAAiB,CAAC,YAAY,KAAK;AAIzC,IAAM,iBAAiB,CAAC,UAC7B,OAAO,UAAU,YAChB,eAAqC,SAAS,KAAK;AA0F/C,IAAM,cAA6B;AAAA,EACxC,UAAU;AAAA,EACV,QAAQ;AAAA,EACR,WAAW;AAAA,EACX,SAAS;AAAA,EACT,QAAQ;AACV;AAmCA,IAAM,WAAW,CAAC,UAChB,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AAErE,IAAM,WAAW,CAAC,OAAgB,aAChC,OAAO,UAAU,YAAY,MAAM,SAAS,IAAI,QAAQ;AAE1D,IAAM,mBAAmB,CAAC,UACxB,OAAO,UAAU,YAAY,MAAM,SAAS,IAAI,QAAQ;AAE1D,IAAM,UAAU,CAAC,UACf,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK,KAAK,SAAS,IAC5D,KAAK,MAAM,KAAK,IAChB;AAEN,IAAM,WAAW,CAAC,UAChB,MAAM,QAAQ,KAAK,IACf,MAAM,OAAO,CAAC,UAA2B,OAAO,UAAU,QAAQ,IAClE,CAAC;AAEP,IAAM,WAA8B;AAAA,EAClC;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAiBO,IAAM,kBAAkB,CAAC,UAAyC;AACvE,MAAI,CAAC,SAAS,KAAK,GAAG;AACpB,WAAO;AAAA,EACT;AAEA,QAAM,SAAS,MAAM,QAAQ;AAC7B,QAAM,OAAO,MAAM,MAAM;AAEzB,MAAI,OAAO,WAAW,YAAY,CAAC,SAAS,SAAS,MAAM,GAAG;AAC5D,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,eAAe,IAAI,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,QAAM,YAAY,SAAS,MAAM,WAAW,GAAG,EAAE;AAEjD,MAAI,cAAc,IAAI;AACpB,WAAO;AAAA,EACT;AAEA,QAAM,SAAS,SAAS,MAAM,QAAQ,CAAC,IAAI,MAAM,QAAQ,IAAI,CAAC;AAC9D,QAAM,QAAQ,SAAS,MAAM,OAAO,CAAC,IAAI,MAAM,OAAO,IAAI,CAAC;AAE3D,SAAO;AAAA,IACL,SAAS;AAAA,IACT,OAAO,SAAS,MAAM,OAAO,GAAG,SAAS;AAAA,IACzC;AAAA,IACA;AAAA,IACA;AAAA,IACA,WAAW,SAAS,MAAM,WAAW,GAAG,SAAS;AAAA,IACjD,YAAY,iBAAiB,MAAM,YAAY,CAAC;AAAA,IAChD,YAAY,iBAAiB,MAAM,YAAY,CAAC;AAAA,IAChD,QAAQ;AAAA,MACN,WAAW,iBAAiB,OAAO,WAAW,CAAC;AAAA,MAC/C,KAAK,SAAS,OAAO,KAAK,CAAC;AAAA,IAC7B;AAAA,IACA,cACE,OAAO,MAAM,cAAc,MAAM,YACjC,OAAO,SAAS,MAAM,cAAc,CAAC,IACjC,KAAK,MAAM,MAAM,cAAc,CAAC,IAChC;AAAA,IACN,OAAO;AAAA,MACL,UAAU,QAAQ,MAAM,UAAU,CAAC;AAAA,MACnC,QAAQ,QAAQ,MAAM,QAAQ,CAAC;AAAA,MAC/B,WAAW,QAAQ,MAAM,WAAW,CAAC;AAAA,MACrC,SAAS,QAAQ,MAAM,SAAS,CAAC;AAAA,MACjC,QAAQ,QAAQ,MAAM,QAAQ,CAAC;AAAA,IACjC;AAAA,IACA,QAAQ,QAAQ,MAAM,QAAQ,CAAC;AAAA,IAC/B,QAAQ,QAAQ,MAAM,QAAQ,CAAC;AAAA,IAC/B,WAAW,iBAAiB,MAAM,WAAW,CAAC;AAAA,IAC9C,aAAa,SAAS,MAAM,aAAa,GAAG,SAAS;AAAA,EACvD;AACF;AAmBO,IAAM,gBAAgB,CAAC;AAAA,EAC5B;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF,MAAyC;AACvC,QAAM,YAAY,IAAI,YAAY;AAElC,SAAO;AAAA,IACL,SAAS;AAAA,IACT,OAAO,YAAY,SAAS;AAAA,IAC5B;AAAA,IACA,QAAQ;AAAA,IACR;AAAA,IACA,WAAW;AAAA,IACX,YAAY;AAAA;AAAA;AAAA,IAGZ,YAAY;AAAA,IACZ,QAAQ,EAAE,WAAW,MAAM,KAAK,CAAC,EAAE;AAAA,IACnC;AAAA,IACA,OAAO;AAAA,IACP,QAAQ;AAAA,IACR,QAAQ;AAAA,IACR,WAAW;AAAA,IACX;AAAA,EACF;AACF;AAEO,IAAM,cAAc,CAAC,OAAsB,QAAuB;AACvE,MAAI,MAAM,eAAe,MAAM;AAC7B,WAAO;AAAA,EACT;AAEA,QAAM,QAAQ,KAAK,MAAM,MAAM,UAAU;AAKzC,SAAO,CAAC,OAAO,MAAM,KAAK,KAAK,QAAQ,IAAI,QAAQ;AACrD;AAwIO,IAAM,mBAAmB,CAC9B,OACA,QACqB;AACrB,QAAM,EAAE,OAAO,aAAa,IAAI;AAEhC,QAAM,UACJ,iBAAiB,QAAQ,gBAAgB,IACrC,OACA,KAAK,IAAI,GAAG,KAAK,IAAI,KAAK,KAAK,MAAO,MAAM,WAAW,eAAgB,GAAG,CAAC,CAAC;AAElF,QAAM,YAAY,KAAK;AAAA,IACrB;AAAA,IACA,KAAK,MAAM,MAAM,SAAS,IAAI,KAAK,MAAM,MAAM,SAAS;AAAA,EAC1D;AAEA,QAAM,YACJ,iBAAiB,OAAO,OAAO,KAAK,IAAI,GAAG,eAAe,MAAM,QAAQ;AAE1E,QAAM,mBACJ,MAAM,WAAW,aACjB,cAAc,QACd,cAAc,KACd,MAAM,aAAa,KACnB,aAAa,IACT,OACA,KAAK,KAAK,aAAa,MAAM,YAAY,YAAY,KAAQ;AAEnE,SAAO;AAAA,IACL,OAAO,MAAM;AAAA,IACb,MAAM,MAAM;AAAA,IACZ,QAAQ,MAAM;AAAA,IACd,WAAW,MAAM;AAAA,IACjB,WAAW,MAAM;AAAA,IACjB,YAAY,MAAM;AAAA,IAClB;AAAA,IACA,UAAU,MAAM;AAAA,IAChB,QAAQ,MAAM;AAAA,IACd,WAAW,MAAM;AAAA,IACjB,SAAS,MAAM;AAAA,IACf,QAAQ,MAAM;AAAA,IACd,QAAQ,MAAM;AAAA,IACd,WAAW,MAAM;AAAA,IACjB,aAAa,MAAM;AAAA,IACnB;AAAA,IACA,kBACE,qBAAqB,QAAQ,CAAC,OAAO,SAAS,gBAAgB,IAC1D,OACA;AAAA,IACN,SAAS,YAAY,OAAO,GAAG;AAAA,EACjC;AACF;;;ACzgBO,IAAM,mCAAmC;AAGzC,IAAM,sCAET;AAAA,EACF,QAAQ;AAAA,EACR,SAAS;AAAA,EACT,aAAa;AACf;AAGO,IAAM,gCAAgC;AAAA,EAC3C;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAGO,IAAM,4BAA4B,MACvC,OAAO,YAAY,8BAA8B,IAAI,CAAC,SAAS,CAAC,MAAM,IAAI,CAAC,CAAC;AAI9E,IAAM,eAAe,CACnB,QACA,WAEA,OAAO,MAAM,KAAK,CAAC,SAAS,KAAK,OAAO,MAAM,GAAG;AA0B5C,IAAM,4BAA4B,MAA4B;AACnE,QAAM,WAAW,mBAAmB;AAEpC,QAAM,eACJ,CAAC;AACH,QAAM,eAAuC,CAAC;AAE9C,aAAW,CAAC,QAAQ,OAAO,KAAK,OAAO,QAAQ,SAAS,KAAK,GAAG;AAC9D,iBAAa,MAAM,IAAI;AAAA,MACrB,SAAS,QAAQ;AAAA,MACjB,UAAU,QAAQ;AAAA,IACpB;AACA,iBAAa,MAAM,IAAI,QAAQ;AAAA,EACjC;AAEA,SAAO;AAAA,IACL,MAAM;AAAA,IACN,eAAe;AAAA,IAEf,eAAe,CAAC,GAAG,SAAS,IAAI,UAAU;AAAA,IAC1C,YAAY,CAAC,GAAG,SAAS,IAAI,OAAO;AAAA,IACpC,cAAc,EAAE,OAAO,CAAC,GAAG,SAAS,IAAI,SAAS,EAAE;AAAA,IAEnD;AAAA,IACA;AAAA,IAEA,wBAAwB,aAAa,UAAU,WAAW,KAAK;AAAA,IAC/D,mBAAmB,aAAa,UAAU,MAAM,KAAK;AAAA,IACrD,mBAAmB,aAAa,UAAU,MAAM,KAAK;AAAA,IACrD,eAAe,SAAS;AAAA,IAExB,sBAAsB,SAAS;AAAA,IAC/B,iBAAiB,EAAE,GAAG,SAAS,mBAAmB;AAAA,IAElD,wBAAwB;AAAA,IACxB,wBAAwB;AAAA,IACxB,0BAA0B,CAAC,GAAG,SAAS,mBAAmB;AAAA;AAAA;AAAA,IAI1D,2BAA2B;AAAA,IAC3B,uBAAuB;AAAA;AAAA;AAAA;AAAA,IAKvB,kBAAkB,CAAC;AAAA,EACrB;AACF;AAMA,IAAM,YAAY,CAAC,UACjB,UAAU,UAAa,UAAU;AAkBnC,IAAM,aAAa,CAAC,UAA4B;AAC9C,MAAI,MAAM,QAAQ,KAAK,GAAG;AACxB,WAAO,MAAM,WAAW;AAAA,EAC1B;AAEA,MAAI,cAAc,KAAK,GAAG;AACxB,WAAO,OAAO,KAAK,KAAK,EAAE,WAAW;AAAA,EACvC;AAEA,SAAO;AACT;AAmBO,IAAM,0BAA0B,CACrC,UACA,OAA6B,0BAA0B,MAC3B;AAC5B,QAAM,SAAS,cAAc,QAAQ,IAAI,WAAW,CAAC;AACrD,QAAM,QAAiC,CAAC;AAExC,aAAW,CAAC,KAAK,SAAS,KAAK,OAAO,QAAQ,IAAI,GAAG;AAGnD,QAAI,cAAc,MAAM;AACtB;AAAA,IACF;AAEA,QAAI,QAAQ,kBAAkB,QAAQ,gBAAgB;AACpD;AAAA,IACF;AAEA,QAAI,UAAU,OAAO,GAAG,CAAC,KAAK,CAAC,WAAW,SAAS,GAAG;AACpD,YAAM,GAAG,IAAI;AAAA,IACf;AAAA,EACF;AAEA,QAAM,oBAAoB;AAAA,IACxB,OAAO,cAAc;AAAA,IACrB,KAAK,cAAc;AAAA,EACrB;AAEA,MAAI,sBAAsB,MAAM;AAC9B,UAAM,cAAc,IAAI;AAAA,EAC1B;AAEA,QAAM,oBAAoB;AAAA,IACxB,OAAO,cAAc;AAAA,IACrB,KAAK,cAAc;AAAA,EACrB;AAEA,MAAI,sBAAsB,MAAM;AAC9B,UAAM,cAAc,IAAI;AAAA,EAC1B;AAEA,SAAO;AACT;AAOA,IAAM,gBAAgB,CACpB,QACA,YACmC;AACnC,MAAI,CAAC,cAAc,OAAO,GAAG;AAC3B,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,cAAc,MAAM,GAAG;AAG1B,WAAO,EAAE,GAAG,QAAQ;AAAA,EACtB;AAEA,QAAM,SAAkC,EAAE,GAAG,OAAO;AACpD,MAAI,QAAQ;AAEZ,aAAW,CAAC,KAAK,KAAK,KAAK,OAAO,QAAQ,OAAO,GAAG;AAClD,QAAI,UAAU,OAAO,GAAG,CAAC,GAAG;AAC1B,aAAO,GAAG,IAAI;AACd,cAAQ;AAAA,IACV;AAAA,EACF;AAEA,SAAO,QAAQ,SAAS;AAC1B;AA0NO,IAAM,6BAA6B,CAAC,WAA4B;AACrE,QAAM,MAAM,cAAc,MAAM,IAAI,OAAO,wBAAwB,IAAI;AAEvE,MAAI,OAAO,QAAQ,YAAY,IAAI,KAAK,EAAE,WAAW,GAAG;AACtD,WAAO,oCACL,gCACF;AAAA,EACF;AAEA,QAAM,aAAa,IAAI,KAAK,EAAE,YAAY;AAE1C,SAAO,oCAAoC,UAAU,KAAK,IAAI,KAAK;AACrE;;;ACvcA,IAAM,YAAY,CAAC,OAAgB,SAAmC;AACpE,MAAI,MAAM,QAAQ,KAAK,GAAG;AAGxB,QAAI,KAAK,IAAI,KAAK,GAAG;AACnB,YAAM,IAAI,UAAU,oBAAoB;AAAA,IAC1C;AAEA,SAAK,IAAI,KAAK;AACd,UAAM,SAAS,MAAM,IAAI,CAAC,UAAU,UAAU,OAAO,IAAI,CAAC;AAC1D,SAAK,OAAO,KAAK;AAEjB,WAAO;AAAA,EACT;AAEA,MAAI,OAAO,UAAU,YAAY,UAAU,MAAM;AAQ/C,QAAI,KAAK,IAAI,KAAK,GAAG;AACnB,YAAM,IAAI,UAAU,oBAAoB;AAAA,IAC1C;AAEA,SAAK,IAAI,KAAK;AAEd,UAAM,SAAS;AACf,UAAM,SAAkC,CAAC;AAEzC,eAAW,OAAO,OAAO,KAAK,MAAM,EAAE,KAAK,GAAG;AAC5C,YAAM,QAAQ,OAAO,GAAG;AAMxB,UAAI,UAAU,QAAW;AACvB,eAAO,GAAG,IAAI,UAAU,OAAO,IAAI;AAAA,MACrC;AAAA,IACF;AAEA,SAAK,OAAO,KAAK;AAEjB,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAWO,IAAM,eAAe,CAAC,UAAkC;AAC7D,MAAI;AACF,UAAM,aAAa,KAAK,UAAU,UAAU,OAAO,oBAAI,QAAQ,CAAC,CAAS;AAEzE,WAAO,OAAO,eAAe,WAAW,aAAa;AAAA,EACvD,QAAQ;AACN,WAAO;AAAA,EACT;AACF;AAMO,IAAM,iBAAiB,CAAC,UAAsC;AACnE,QAAM,aAAa,aAAa,KAAK;AAErC,SAAO,eAAe,OAAO,OAAO,IAAI,YAAY,EAAE,OAAO,UAAU;AACzE;;;AC/EO,IAAM,0BAA4D;AAAA,EACvE,4BAA4B;AAC9B;AAaO,IAAM,kCAAkC;;;ACiCxC,IAAM,6BAA6B;;;AC/DnC,IAAM,2BAA2B;AAaxC,IAAMA,YAAW,CAAC,UAChB,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AAErE,IAAM,SAAS,CACb,QACA,YACkB,EAAE,MAAM,YAAY,QAAQ,OAAO;AASvD,IAAM,iBAAiB,CAAC,UAA6C;AACnE,MAAI,CAAC,MAAM,QAAQ,KAAK,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,QAAM,OAAO,oBAAI,IAAY;AAE7B,aAAW,SAAS,OAAO;AACzB,QAAI,OAAO,UAAU,UAAU;AAC7B;AAAA,IACF;AAEA,UAAM,aAAa,MAAM,KAAK,EAAE,YAAY,EAAE,QAAQ,QAAQ,GAAG;AAEjE,QAAI,WAAW,SAAS,GAAG;AACzB,WAAK,IAAI,UAAU;AAAA,IACrB;AAAA,EACF;AAEA,SAAO,CAAC,GAAG,IAAI;AACjB;AAUA,IAAM,eAAe,CACnB,UACuD;AACvD,MAAI,CAACA,UAAS,KAAK,GAAG;AACpB,WAAO;AAAA,EACT;AAEA,QAAM,QAA2C,CAAC;AAElD,aAAW,CAAC,cAAc,WAAW,KAAK,OAAO,QAAQ,KAAK,GAAG;AAC/D,UAAM,YAAY,aAAa,KAAK,EAAE,YAAY,EAAE,QAAQ,QAAQ,GAAG;AAEvE,QAAI,UAAU,WAAW,GAAG;AAC1B;AAAA,IACF;AAEA,UAAM,WAAW,eAAe,WAAW;AAE3C,QAAI,aAAa,MAAM;AACrB;AAAA,IACF;AAUA,UAAM,WAAW,SAAS,OAAO,CAAC,YAAY,YAAY,SAAS;AAEnE,QAAI,SAAS,WAAW,GAAG;AACzB;AAAA,IACF;AAEA,UAAM,SAAS,IAAI;AAAA,EACrB;AAEA,SAAO;AACT;AAEA,IAAM,cAAc,CAAC,UACnB,OAAO,UAAU,YAAY,OAAO,UAAU,KAAK,KAAK,SAAS,IAC7D,QACA;AAEN,IAAM,cAAc,CAAC,QAA2D;AAC9E,MAAI,CAACA,UAAS,GAAG,GAAG;AAClB,WAAO,EAAE,OAAO,+BAA+B;AAAA,EACjD;AAEA,QAAM,gBAAgB,YAAY,IAAI,eAAe,CAAC;AAEtD,MAAI,kBAAkB,MAAM;AAC1B,WAAO,EAAE,OAAO,oDAAoD;AAAA,EACtE;AAEA,QAAM,qBAAqB,YAAY,IAAI,oBAAoB,CAAC;AAEhE,MAAI,uBAAuB,MAAM;AAC/B,WAAO,EAAE,OAAO,yDAAyD;AAAA,EAC3E;AAEA,QAAM,sBAAsB,eAAe,IAAI,qBAAqB,CAAC;AACrE,QAAM,mBAAmB,eAAe,IAAI,kBAAkB,CAAC;AAC/D,QAAM,sBAAsB,eAAe,IAAI,qBAAqB,CAAC;AACrE,QAAM,oBAAoB,eAAe,IAAI,mBAAmB,CAAC;AACjE,QAAM,mBAAmB,aAAa,IAAI,kBAAkB,CAAC;AAM7D,MACG,IAAI,qBAAqB,MAAM,UAAa,wBAAwB,QACpE,IAAI,kBAAkB,MAAM,UAAa,qBAAqB,QAC9D,IAAI,qBAAqB,MAAM,UAAa,wBAAwB,QACpE,IAAI,mBAAmB,MAAM,UAAa,sBAAsB,QAChE,IAAI,kBAAkB,MAAM,UAAa,qBAAqB,MAC/D;AACA,WAAO,EAAE,OAAO,8DAA8D;AAAA,EAChF;AAEA,SAAO;AAAA,IACL;AAAA,IACA;AAAA,IACA,UACE,OAAO,IAAI,UAAU,MAAM,YAAY,IAAI,UAAU,EAAE,SAAS,IAC5D,IAAI,UAAU,IACd;AAAA,IACN,OAAO,OAAO,IAAI,OAAO,MAAM,WAAW,IAAI,OAAO,IAAI;AAAA,IACzD,qBAAqB,uBAAuB,CAAC;AAAA,IAC7C,kBAAkB,oBAAoB,CAAC;AAAA,IACvC,qBAAqB,uBAAuB,CAAC;AAAA,IAC7C,mBAAmB,qBAAqB,CAAC;AAAA,IACzC,kBAAkB,oBAAoB,CAAC;AAAA,EACzC;AACF;AAUO,IAAM,0BAA0B,CAAC,aAAoC;AAC1E,MAAI,CAACA,UAAS,QAAQ,GAAG;AACvB,WAAO,OAAO,mBAAmB,6BAA6B;AAAA,EAChE;AAEA,QAAM,MAAM,SAAS,wBAAwB;AAE7C,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,MACL;AAAA,MACA,4BAA4B,wBAAwB;AAAA,IACtD;AAAA,EACF;AAEA,MAAI,CAACA,UAAS,GAAG,GAAG;AAClB,WAAO;AAAA,MACL;AAAA,MACA,IAAI,wBAAwB;AAAA,IAC9B;AAAA,EACF;AAEA,QAAM,YAAY,IAAI,WAAW;AACjC,QAAM,QAAQ,IAAI,OAAO;AACzB,QAAM,MAAM,IAAI,KAAK;AAErB,MAAI,OAAO,cAAc,YAAY,UAAU,WAAW,GAAG;AAC3D,WAAO,OAAO,YAAY,+BAA+B;AAAA,EAC3D;AAEA,MAAI,OAAO,UAAU,YAAY,MAAM,WAAW,GAAG;AACnD,WAAO,OAAO,YAAY,+BAA+B;AAAA,EAC3D;AAEA,MAAI,OAAO,QAAQ,YAAY,IAAI,WAAW,GAAG;AAC/C,WAAO,OAAO,YAAY,uCAAuC;AAAA,EACnE;AAEA,QAAM,UAAU,YAAY,IAAI,SAAS,CAAC;AAE1C,MAAI,WAAW,SAAS;AACtB,WAAO,OAAO,aAAa,QAAQ,KAAK;AAAA,EAC1C;AAMA,MAAI,QAAQ,kBAAkB,4BAA4B;AACxD,WAAO;AAAA,MACL;AAAA,MACA,yBAAyB,QAAQ,aAAa,4BAA4B,0BAA0B;AAAA,IACtG;AAAA,EACF;AAEA,SAAO,EAAE,MAAM,YAAY,UAAU,EAAE,KAAK,OAAO,WAAW,QAAQ,EAAE;AAC1E;;;ACtMA,IAAMC,UAAS,CACb,QACA,YAC6B,EAAE,MAAM,YAAY,QAAQ,OAAO;AAUlE,IAAM,eAAe,CAAC,UAAqC;AACzD,MAAI;AACF,UAAM,SAAS,KAAK,KAAK;AACzB,UAAM,QAAQ,IAAI,WAAW,OAAO,MAAM;AAE1C,aAAS,QAAQ,GAAG,QAAQ,OAAO,QAAQ,SAAS,GAAG;AACrD,YAAM,KAAK,IAAI,OAAO,WAAW,KAAK;AAAA,IACxC;AAEA,WAAO;AAAA,EACT,QAAQ;AACN,WAAO;AAAA,EACT;AACF;AAGA,IAAM,0BAA0B;AAChC,IAAM,2BAA2B;AAEjC,IAAM,SAAS,MAA2B;AACxC,QAAM,YAAa,WAAsD,QACrE;AAEJ,SAAO,cAAc,SAAY,OAAO;AAC1C;AAUO,IAAM,4BAA4B,OACvC,aACqC;AACrC,MAAI,SAAS,QAAQ,iCAAiC;AACpD,WAAOA;AAAA,MACL;AAAA,MACA,oCAAoC,SAAS,GAAG;AAAA,IAClD;AAAA,EACF;AAEA,QAAM,kBAAkB,wBAAwB,SAAS,KAAK;AAW9D,MAAI,oBAAoB,QAAW;AACjC,WAAOA;AAAA,MACL;AAAA,MACA,qCAAqC,SAAS,KAAK;AAAA,IACrD;AAAA,EACF;AAEA,QAAM,YAAY,aAAa,SAAS,SAAS;AAEjD,MAAI,cAAc,QAAQ,UAAU,WAAW,yBAAyB;AACtE,WAAOA;AAAA,MACL;AAAA,MACA,oBAAoB,uBAAuB;AAAA,IAC7C;AAAA,EACF;AAEA,QAAM,YAAY,aAAa,eAAe;AAE9C,MAAI,cAAc,QAAQ,UAAU,WAAW,0BAA0B;AAKvE,WAAOA;AAAA,MACL;AAAA,MACA,wBAAwB,SAAS,KAAK,YAAY,wBAAwB;AAAA,IAC5E;AAAA,EACF;AAEA,QAAM,UAAU,eAAe,SAAS,OAAO;AAE/C,MAAI,YAAY,MAAM;AACpB,WAAOA,QAAO,aAAa,oCAAoC;AAAA,EACjE;AAEA,QAAM,SAAS,OAAO;AAEtB,MAAI,WAAW,MAAM;AACnB,WAAOA;AAAA,MACL;AAAA,MACA;AAAA,IACF;AAAA,EACF;AAEA,MAAI;AACF,UAAM,MAAM,MAAM,OAAO;AAAA,MACvB;AAAA,MACA;AAAA,MACA,EAAE,MAAM,gCAAgC;AAAA,MACxC;AAAA,MACA,CAAC,QAAQ;AAAA,IACX;AAEA,UAAM,WAAW,MAAM,OAAO;AAAA,MAC5B,EAAE,MAAM,gCAAgC;AAAA,MACxC;AAAA,MACA;AAAA,MACA;AAAA,IACF;AAEA,WAAO,WACH,EAAE,MAAM,YAAY,aAAa,SAAS,QAAQ,IAClDA;AAAA,MACE;AAAA,MACA;AAAA,IACF;AAAA,EACN,SAAS,OAAO;AAId,WAAOA;AAAA,MACL;AAAA,MACA,wDACE,iBAAiB,QAAQ,MAAM,OAAO,eACxC;AAAA,IACF;AAAA,EACF;AACF;;;AC5IO,IAAM,UAA+B;AAAA,EAC1C,MAAM,YAAY;AAAA,EAClB,QAAQ,YAAY;AACtB;;;AC/BA,IAAM,UAAU,KAAK,KAAK;AAGnB,IAAM,uBAAuB,KAAK;AAMlC,IAAM,iCAAiC,KAAK;AAc5C,IAAM,aAAa,CACxB,UACA,QACkB;AAClB,MAAI,OAAO,aAAa,YAAY,SAAS,WAAW,GAAG;AACzD,WAAO;AAAA,EACT;AAEA,QAAM,WAAW,KAAK,MAAM,QAAQ;AAEpC,MAAI,OAAO,MAAM,QAAQ,GAAG;AAC1B,WAAO;AAAA,EACT;AAEA,SAAO,KAAK,IAAI,GAAG,IAAI,QAAQ,IAAI,QAAQ;AAC7C;AAQO,IAAM,mBAAmB,CAAC,UAAkC;AACjE,MAAI,QAAQ,sBAAsB;AAChC,WAAO;AAAA,EACT;AAEA,MAAI,QAAQ,gCAAgC;AAC1C,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAMO,IAAM,gBAAgB,CAC3B,UACA,QACiF;AACjF,QAAM,QAAQ,WAAW,UAAU,GAAG;AAEtC,SAAO;AAAA,IACL,WAAW,UAAU,OAAO,OAAO,iBAAiB,KAAK;AAAA,IACzD;AAAA,EACF;AACF;;;AClEO,IAAM,mBAAmB,CAC9B,iBACuB;AAAA,EACvB,qBAAqB,YAAY,oBAAoB;AAAA,EACrD,kBAAkB,YAAY,iBAAiB;AAAA,EAC/C,qBAAqB,YAAY,oBAAoB;AAAA,EACrD,mBAAmB,YAAY,kBAAkB;AAAA,EACjD,kBAAkB,OAAO,KAAK,YAAY,gBAAgB,EAAE;AAC9D;AAUO,IAAM,uBAAuB,CAClC,QACA,SACsB;AAAA,EACtB,QAAQ;AAAA,EACR;AAAA,EACA,QAAQ;AAAA,EACR,oBAAoB;AAAA,EACpB,UAAU;AAAA,EACV,aAAa;AAAA,EACb,WAAW,IAAI,YAAY;AAAA,EAC3B,YAAY;AAAA,EACZ,OAAO;AAAA,EACP,QAAQ;AACV;AAEO,IAAM,kBAAkB,CAC7B,OACA,QACAC,aACA,SACsB;AAAA,EACtB,QAAQ;AAAA,EACR,QAAQ;AAAA,EACR;AAAA,EACA,oBAAoB,MAAM,YAAY;AAAA,EACtC,UAAU,MAAM,YAAY,SAAS,SAAS,IAAI,MAAM,YAAY,WAAW;AAAA,EAC/E,aAAa,MAAM;AAAA,EACnB,WAAW,IAAI,YAAY;AAAA,EAC3B,YAAAA;AAAA,EACA,OAAO,MAAM;AAAA,EACb,QAAQ,iBAAiB,MAAM,WAAW;AAC5C;AAMO,IAAM,yBAAyB,KAAK,KAAK,KAAK;AAyC9C,IAAM,qBAAqB,CAChC,UACwB;AACxB,MAAI,MAAM,WAAW,MAAM;AACzB,WAAO;AAAA,MACL,OAAO,qBAAqB,mBAAmB,MAAM,GAAG;AAAA,MACxD,aAAa;AAAA,IACf;AAAA,EACF;AAEA,QAAM,EAAE,MAAM,IAAI,cAAc,MAAM,OAAO,UAAU,MAAM,GAAG;AAKhE,MAAI,UAAU,QAAQ,SAAS,wBAAwB;AACrD,WAAO;AAAA,MACL,OAAO;AAAA,QACL,GAAG,qBAAqB,SAAS,MAAM,GAAG;AAAA,QAC1C,YAAY;AAAA,QACZ,oBAAoB,MAAM,OAAO,YAAY;AAAA,QAC7C,OAAO,MAAM,OAAO;AAAA,MACtB;AAAA,MACA,aAAa;AAAA,IACf;AAAA,EACF;AAEA,SAAO;AAAA,IACL,OAAO;AAAA,MACL,MAAM;AAAA,MACN,UAAU,IAAI,SAAS;AAAA,MACvB;AAAA,MACA,MAAM;AAAA,IACR;AAAA,IACA,aAAa,MAAM,OAAO;AAAA,EAC5B;AACF;;;AC9GO,IAAM,wBAAwB,CACnC,SAEA,aAAa;AAAA,EACX,UAAU,KAAK;AAAA,EACf,YAAY,KAAK;AAAA,EACjB,OAAO,KAAK;AAAA,EACZ,aAAa,KAAK;AACpB,CAAC;AA0DI,IAAM,qBAAqB,OAChC,UACuC;AACvC,MAAI,CAAC,MAAM,UAAU;AACnB,UAAM,aAAa,MAAM,KAAK;AAE9B,UAAMC,SAAQ,qBAAqB,gBAAgB,MAAM,GAAG;AAC5D,UAAM,QAAQ,MAAM,OAAOA,MAAK;AAEhC,WAAO,EAAE,OAAAA,QAAO,SAAS,MAAM,QAAQ,KAAK;AAAA,EAC9C;AAEA,MAAI,CAAC,MAAM,MAAM;AAWf,UAAM,SAAS,MAAM,YAAY,MAAM,KAAK;AAC5C,UAAM,EAAE,OAAAA,OAAM,IAAI,mBAAmB,EAAE,QAAQ,KAAK,MAAM,IAAI,CAAC;AAE/D,UAAM,QAAQ,MAAM,OAAOA,MAAK;AAEhC,WAAO,EAAE,OAAAA,QAAO,SAAS,MAAM,QAAQ,KAAK;AAAA,EAC9C;AAEA,QAAM,OAAO,wBAAwB,MAAM,QAAQ;AAEnD,MAAI,KAAK,SAAS,YAAY;AAC5B,UAAMA,SAAQ,qBAAqB,KAAK,QAAQ,MAAM,GAAG;AACzD,UAAM,QAAQ,MAAM,OAAOA,MAAK;AAEhC,WAAO,EAAE,OAAAA,QAAO,SAAS,MAAM,QAAQ,KAAK,OAAO;AAAA,EACrD;AAEA,QAAM,eAAe,MAAM,0BAA0B,KAAK,QAAQ;AAElE,MAAI,aAAa,SAAS,YAAY;AACpC,UAAMA,SAAQ,qBAAqB,aAAa,QAAQ,MAAM,GAAG;AACjE,UAAM,QAAQ,MAAM,OAAOA,MAAK;AAEhC,WAAO,EAAE,OAAAA,QAAO,SAAS,MAAM,QAAQ,aAAa,OAAO;AAAA,EAC7D;AAEA,QAAM,OAA8B;AAAA,IAClC,UAAU,MAAM,IAAI,YAAY;AAAA,IAChC,YAAY,MAAM,IAAI,YAAY;AAAA,IAClC,OAAO,KAAK,SAAS;AAAA,IACrB,aAAa,aAAa;AAAA,EAC5B;AAEA,QAAM,YAAY,sBAAsB,IAAI;AAC5C,QAAM,UACJ,cAAc,OAAO,OAAO,OAAO,MAAM,QAAQ,SAAS,KAAK,SAAS;AAM1E,MAAI,YAAY,MAAM;AACpB,UAAMA,SAAQ,qBAAqB,kBAAkB,MAAM,GAAG;AAC9D,UAAM,QAAQ,MAAM,OAAOA,MAAK;AAEhC,WAAO;AAAA,MACL,OAAAA;AAAA,MACA,SAAS;AAAA,MACT,QAAQ;AAAA,IACV;AAAA,EACF;AAEA,QAAM,QAA2B,EAAE,GAAG,MAAM,QAAQ;AAEpD,QAAM,aAAa,MAAM,OAAO,KAAK;AAErC,QAAM,QAAQ,gBAAgB,OAAO,QAAQ,GAAG,MAAM,GAAG;AACzD,QAAM,QAAQ,MAAM,OAAO,KAAK;AAEhC,SAAO;AAAA,IACL;AAAA,IACA,SAAS;AAAA,IACT,QAAQ,gBAAgB,aAAa,YAAY,kBAAkB,qBAAqB,KAAK,SAAS,KAAK;AAAA,EAC7G;AACF;AASO,IAAM,sBAAsB,CACjC,aAC6B;AAAA,EAC7B,mBAAmB,QAAQ,MAAM;AAAA,EACjC,mBAAmB,QAAQ,MAAM;AAAA,EACjC,mBAAmB,QAAQ,MAAM;AAAA,EACjC,oBAAoB,QAAQ,MAAM;AAAA,EAClC,kBAAkB,QAAQ,MAAM;AAAA,EAChC,wBAAwB,QAAQ,MAAM;AAAA,EACtC,GAAI,QAAQ,YAAY,OACpB,CAAC,IACD,EAAE,mBAAmB,iBAAiB,QAAQ,QAAQ,WAAW,EAAE;AAAA,EACvE,GAAI,QAAQ,WAAW,OAAO,CAAC,IAAI,EAAE,mBAAmB,QAAQ,OAAO;AACzE;AAYA,IAAM,cAAc,OAClB,UACsC;AACtC,MAAI;AACF,WAAO,MAAM,MAAM,gBAAgB;AAAA,EACrC,QAAQ;AACN,WAAO;AAAA,EACT;AACF;AAEA,IAAM,eAAe,OACnB,OACA,UACkB;AAClB,MAAI;AACF,UAAM,MAAM,iBAAiB,KAAK;AAAA,EACpC,QAAQ;AAAA,EAGR;AACF;AASA,IAAM,eAAe,OAAO,UAA+C;AACzE,MAAI;AACF,UAAM,MAAM,iBAAiB;AAAA,EAC/B,QAAQ;AAAA,EAER;AACF;AAEA,IAAM,UAAU,OACd,OACA,UACkB;AAClB,MAAI;AACF,UAAM,MAAM,wBAAwB,KAAK;AAAA,EAC3C,QAAQ;AAAA,EAGR;AACF;;;ACzNO,IAAM,kBAAkB;AAAA,EAC7B;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AACF;AAIO,IAAM,uBACX,gBAAgB,IAAI,CAAC,WAAW,OAAO,IAAI;;;ACzEtC,IAAM,+BAA+B;AACrC,IAAM,2BAA2B;AAmBjC,IAAM,mCAAsD;AAAA,EACjE;AAAA,EACA;AACF;AAyBO,IAAM,sBAAsB;AAAA,EACjC;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AACF;AAIO,IAAM,2BACX,oBAAoB,IAAI,CAAC,WAAW,OAAO,IAAI;AA6B1C,IAAM,wBAAwB;AAAA,EACnC;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AACF;AAKO,IAAM,6BACX,sBAAsB,IAAI,CAAC,WAAW,OAAO,IAAI;;;ACa5C,IAAM,gCAAmD;AAAA,EAC9D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA;AAAA;AAAA,EAGA;AAAA,EACA,GAAG;AACL;AAqVO,IAAM,mBAAmB,OAC9B,WAC4C;AAC5C,QAAM,WAAW,MAAM,OAAO,MAAM;AAAA,IAClC,mBAAmB,EAAE,OAAO,EAAE,MAAM,0BAA0B,EAAE,EAAE;AAAA,EACpE,CAAC;AAED,SAAO,kBAAkB,oBAAoB,UAAU,mBAAmB,CAAC;AAC7E;;;AClZA,IAAM,YAAY,OAChB,UACsF;AACtF,MAAI;AACF,WAAO,EAAE,IAAI,MAAM,OAAO,gBAAgB,MAAM,MAAM,KAAK,CAAC,EAAE;AAAA,EAChE,SAAS,OAAO;AACd,WAAO,EAAE,IAAI,OAAO,OAAO,cAAc,KAAK,EAAE;AAAA,EAClD;AACF;AAGA,IAAM,gBAAgB,OACpB,QACA,SAC2B;AAC3B,MAAI;AACF,WAAO,eAAe,MAAM,OAAO,MAAM,kBAAkB,IAAI,CAAC,CAAC;AAAA,EACnE,SAAS,OAAO;AACd,kBAAc,yBAAyB,EAAE,MAAM,OAAO,cAAc,KAAK,EAAE,CAAC;AAE5E,WAAO;AAAA,EACT;AACF;AA6BA,IAAM,wBAAwB,OAC5B,QACA,KACA,SACA,QACA,YAAkC,eAChB;AAClB,MAAI;AACF,UAAM,OAAO,SAAS;AAAA,MACpB,0BAA0B;AAAA,QACxB,QAAQ;AAAA,UACN,MAAM;AAAA,YACJ,MAAM;AAAA,YACN;AAAA,YACA,YAAY,IAAI,YAAY;AAAA,YAC5B,wBAAwB;AAAA,YACxB,cAAc;AAAA,YACd,iBAAiB;AAAA,YACjB,WAAW;AAAA,YACX,kBAAkB,uBAAuB,sBAAsB;AAAA,YAC/D,WAAW;AAAA,YACX,OAAO;AAAA,YACP,MAAM;AAAA,YACN,UAAU;AAAA,YACV,gBAAgB;AAAA,YAChB,SAAS,OAAO,OAAO,OAAO,KAAK,EAAE;AAAA,UACvC;AAAA,QACF;AAAA,QACA,IAAI;AAAA,MACN;AAAA,IACF,CAAC;AAAA,EACH,SAAS,OAAO;AACd,kBAAc,+BAA+B;AAAA,MAC3C;AAAA,MACA,OAAO,cAAc,KAAK;AAAA,IAC5B,CAAC;AAAA,EACH;AACF;AAiBA,IAAM,kBAAkB;AACxB,IAAM,oBAAoB;AAS1B,IAAM,mBAAmB,OACvB,QACA,cAC+B;AAC/B,MAAI;AACF,UAAM,WAAW,MAAM,OAAO;AAAA,MAC5B,yBAAyB,iBAAiB,SAAS;AAAA,IACrD;AAEA,WAAO,cAAc,iBAAiB,QAAQ,IAAI,YAAY;AAAA,EAChE,SAAS,OAAO;AACd,WAAO,uBAAuB,WAAW,cAAc,KAAK,CAAC;AAAA,EAC/D;AACF;AAaO,IAAM,oBAAoB,OAC/B,QACA,iBACqC;AACrC,QAAM,SAAS,iBAAiB,YAAY;AAC5C,QAAM,QAAQ,OAAO,MAAM,GAAG,yBAAyB;AAEvD,QAAM,UAA4B,CAAC;AACnC,MAAI,eAAe;AAEnB,aAAW,aAAa,OAAO;AAC7B,UAAM,UAAU,MAAM,iBAAiB,QAAQ,UAAU,IAAI;AAE7D,QAAI,YAAY,UAAU;AACxB,cAAQ,KAAK,SAAS;AAAA,IACxB,WAAW,YAAY,gBAAgB;AACrC,sBAAgB;AAAA,IAClB;AAAA,EACF;AAEA,SAAO;AAAA,IACL;AAAA,IACA,QAAQ,MAAM;AAAA,IACd;AAAA,IACA,WAAW,OAAO,SAAS,MAAM;AAAA,EACnC;AACF;AAeA,IAAM,uBAAuB,OAC3B,WAII;AACJ,MAAI;AACF,UAAM,eAAe,MAAM,iBAAiB,MAAM;AAElD,WAAO;AAAA,MACL,QAAQ,MAAM,kBAAkB,QAAQ,YAAY;AAAA,MACpD;AAAA,IACF;AAAA,EACF,SAAS,OAAO;AACd,kBAAc,uCAAuC;AAAA,MACnD,OAAO,cAAc,KAAK;AAAA,IAC5B,CAAC;AAED,WAAO,EAAE,QAAQ,2BAA2B,cAAc,KAAK;AAAA,EACjE;AACF;AA+YA,IAAM,UAAU,CACd,QACA,SACA,SACA,KACA,sBAC2B;AAAA,EAC3B;AAAA,EACA,MAAM;AAAA,IACJ;AAAA,IACA;AAAA,IACA;AAAA,IACA;AAAA,IACA,WAAW;AAAA,EACb;AACF;AAsGO,IAAM,gBAAgB,OAAO;AAAA,EAClC;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF,MAA0D;AACxD,QAAM,OAAO,MAAM,UAAU,KAAK;AAElC,MAAI,KAAK,MAAM,KAAK,UAAU,QAAQ,KAAK,MAAM,WAAW,WAAW;AACrE,WAAO;AAAA,MACL;AAAA,MACA;AAAA,MACA;AAAA,MACA,iBAAiB,KAAK,OAAO,GAAG;AAAA,MAChC,MAAM,cAAc,QAAQ,UAAU;AAAA,IACxC;AAAA,EACF;AAEA,QAAM,eAAe,MAAM,cAAc,QAAQ,IAAI;AACrD,QAAM,QAAQ,cAAc,EAAE,MAAM,KAAK,aAAa,aAAa,CAAC;AAEpE,MAAI;AACF,UAAM,MAAM,MAAM,KAAK;AAAA,EACzB,SAAS,OAAO;AACd,UAAM,UAAU,cAAc,KAAK;AAEnC,kBAAc,yBAAyB,EAAE,MAAM,OAAO,QAAQ,CAAC;AAE/D,WAAO;AAAA,MACL;AAAA,MACA;AAAA,MACA,4FAA4F,OAAO;AAAA,MACnG;AAAA,MACA;AAAA,IACF;AAAA,EACF;AAEA,gBAAc,oBAAoB;AAAA,IAChC,OAAO,MAAM;AAAA,IACb;AAAA,IACA;AAAA,IACA;AAAA,EACF,CAAC;AAOD,QAAM,UAAU,MAAM,qBAAqB,MAAM;AACjD,QAAM,gBAAgB;AAAA,IACpB,QAAQ,OAAO;AAAA,IACf;AAAA,EACF;AAEA,MAAI,QAAQ,OAAO,QAAQ,SAAS,GAAG;AACrC,UAAM,SAAS;AAAA,MACb,GAAG;AAAA,QACD,QAAQ;AAAA,QACR,2BAA2B,QAAQ,YAAY;AAAA,MACjD;AAAA,MACA,OAAO,MAAM;AAAA,MACb;AAAA,MACA;AAAA,MACA,eAAe;AAAA,IACjB;AAEA,kBAAc,kCAAkC,MAAM;AAEtD,UAAM;AAAA,MACJ;AAAA,MACA;AAAA,MACA,sBAAsB,QAAQ,OAAO,SAAS,iBAAiB;AAAA,MAC/D;AAAA,MACA;AAAA,IACF;AAAA,EACF,WAAW,QAAQ,OAAO,eAAe,KAAK,QAAQ,OAAO,YAAY,GAAG;AAK1E,kBAAc,qCAAqC;AAAA,MACjD,OAAO,MAAM;AAAA,MACb,QAAQ,QAAQ,OAAO;AAAA,MACvB,cAAc,QAAQ,OAAO;AAAA,MAC7B,WAAW,QAAQ,OAAO;AAAA,IAC5B,CAAC;AAAA,EACH;AAEA,QAAM;AAAA,IACJ;AAAA,IACA;AAAA,IACA,kDAA4C,IAAI;AAAA,IAChD;AAAA,MACE,QAAQ;AAAA,MACR,OAAO,MAAM;AAAA,MACb;AAAA,MACA;AAAA,MACA;AAAA,MACA,WAAW;AAAA,MACX,eAAe;AAAA,MACf,qBAAqB,QAAQ,OAAO;AAAA,MACpC,qBAAqB,QAAQ,OAAO,QAAQ;AAAA,IAC9C;AAAA,EACF;AAEA,QAAM,UACJ,iBAAiB,OACb,oGACA,yBAAyB,YAAY,qBAAqB,mBAAmB;AAEnF,SAAO;AAAA,IACL;AAAA,IACA;AAAA;AAAA;AAAA,IAGA,kBAAkB,OAAO,UAAU,GAAG,aAAa,IAAI,OAAO;AAAA,IAC9D,iBAAiB,OAAO,GAAG;AAAA,IAC3B,MAAM,cAAc,QAAQ,UAAU;AAAA,EACxC;AACF;AAmGO,IAAM,yBAAyB,OAAO;AAAA,EAC3C;AAAA,EACA;AAAA,EACA;AACF,MAKK;AACH,MAAI;AACF,UAAM,OAAO,MAAM,UAAU,KAAK;AAElC,QAAI,CAAC,KAAK,IAAI;AACZ,oBAAc,qCAAqC,EAAE,OAAO,KAAK,MAAM,CAAC;AAExE,aAAO,EAAE,QAAQ,UAAU,OAAO,KAAK,MAAM;AAAA,IAC/C;AAEA,QAAI,KAAK,UAAU,MAAM;AACvB,oBAAc,4BAA4B;AAAA,QACxC,QAAQ;AAAA,QACR,OAAO,KAAK,MAAM;AAAA,QAClB,WAAW,KAAK,MAAM;AAAA,MACxB,CAAC;AAED,aAAO,EAAE,QAAQ,qBAAqB,WAAW,KAAK,MAAM,OAAO;AAAA,IACrE;AAEA,UAAM,eAAe,MAAM,cAAc,QAAQ,UAAU;AAK3D,QAAI,iBAAiB,GAAG;AACtB,oBAAc,4BAA4B;AAAA,QACxC,QAAQ;AAAA,MACV,CAAC;AAED,aAAO,EAAE,QAAQ,gBAAgB;AAAA,IACnC;AAEA,UAAM,SAAS,MAAM,cAAc;AAAA,MACjC;AAAA,MACA;AAAA,MACA;AAAA,MACA,MAAM;AAAA,MACN,aAAa;AAAA,IACf,CAAC;AAED,QAAI,OAAO,KAAK,YAAY,aAAa,OAAO,KAAK,QAAQ,MAAM;AACjE,aAAO,EAAE,QAAQ,UAAU,OAAO,OAAO,KAAK,QAAQ;AAAA,IACxD;AAEA,WAAO;AAAA,MACL,QAAQ;AAAA,MACR,OAAO,OAAO,KAAK,IAAI;AAAA,MACvB;AAAA,IACF;AAAA,EACF,SAAS,OAAO;AACd,UAAM,UAAU,cAAc,KAAK;AAEnC,kBAAc,mCAAmC,EAAE,OAAO,QAAQ,CAAC;AAEnE,WAAO,EAAE,QAAQ,UAAU,OAAO,QAAQ;AAAA,EAC5C;AACF;A;;;;AC5oCA,ICsBGC,IAAAA,CAAK,MAAM;AACb,MAAIC,KAAI,EAAE,MAAM,UAAU;AAC1B,UAAQ,EAAE,MAAV;IACC,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD,KAAK;IACL,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD,KAAK;AACJ,MAAAA,GAAE,OAAO,SAAS,EAAE,UAAUA,GAAE,QAAQD,EAAE,EAAE,KAAK;AACjD;IACD,KAAK;AACJ,MAAAC,GAAE,OAAO,UAAU,EAAE,eAAeA,GAAE,aAAa,OAAO,YAAY,OAAO,QAAQ,EAAE,UAAU,EAAE,IAAA,CAAK,CAACC,IAAGC,EAAA,MAAO,CAACD,IAAGF,EAAEG,EAAC,CAAC,CAAC,CAAC;AAC7H;IACD,KAAK;AACJ,MAAAF,GAAE,OAAO;AACT;IACD,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD;AAAS,MAAAA,GAAE,OAAO;EACnB;AACA,SAAO,MAAM,QAAQ,EAAE,IAAI,MAAMA,GAAE,OAAO,EAAE,KAAK,OAAA,CAAQC,OAAM,OAAOA,MAAK,QAAQ,IAAI,EAAE,cAAc,SAAOD,GAAE,YAAY,WAAKA,cAAAA,kBAAE,EAAE,KAAK,MAAMA,GAAE,QAAQ,EAAE,YAAQA,cAAAA,kBAAE,EAAE,yBAAyB,MAAMA,GAAE,4BAA4B,EAAE,4BAA4BA;AACpQ;ADlDA,ICkDG,IAAA,CAAK,MAAM,CAACD,EAAE,CAAC,CAAC;AAAsB,EAAE;EAC1C,MAAM;EACN,YAAY;IACX,GAAG,EAAE,MAAM,SAAS;IACpB,GAAG,EAAE,MAAM,SAAS;EACrB;AACD,CAAC;AAtDD,IEHI,IAAoB,0BAAS,GAAG;AACnC,SAAO,EAAE,QAAQ,SAAS,EAAE,UAAU,WAAW,EAAE,QAAQ,SAAS,EAAE,UAAU,WAAW,EAAE,WAAW,YAAY,EAAE,OAAO,QAAQ,EAAE,YAAY,aAAa,EAAE,SAAS,UAAU,EAAE,QAAQ,SAAS,EAAE,YAAY,aAAa,EAAE,QAAQ,SAAS,EAAE,iBAAiB,kBAAkB,EAAE,eAAe,gBAAgB,EAAE,SAAS,UAAU,EAAE,UAAU,WAAW,EAAE,SAAS,UAAU,EAAE,WAAW,YAAY,EAAE,SAAS,UAAU,EAAE,WAAW,YAAY,EAAE,WAAW,YAAY,EAAE,YAAY,aAAa,EAAE,SAAS,UAAU,EAAE,OAAO,QAAQ,EAAE,YAAY,aAAa,EAAE,OAAO,QAAQ;AAC3kB,GAAE,CAAC,CAAC;AEWH,EAAE,MACF,EAAE,OACF,EAAE,SACF,EAAE,MACF,EAAE,WACF,EAAE,QACF,EAAE,SACF,EAAE,UACF,EAAE,WACF,EAAE,QACF,EAAE;AArBH,IAsBuC,IAAI;AAtB3C,IAsB6D,IAAI;AAtBjE,ICEa,IAAqB,OAA0B,EAC1D,OAAA,GACA,WAAAI,IACA,QAAAC,GAAA,MAKoB;AACpB,MAAMC,KAAS,QAAQ,IAAI,CAAA,GACrB,IAAc,QAAQ,IAAI,CAAA;AAEhC,MAAI,CAACA,MAAU,CAAC,EACd,OAAU,MACR,GAAGD,EAAA,wCACE,CAAA,QAA4B,CAAA,GACnC;AAGF,MAAM,IAAW,MAAM,MAAM,GAAGC,EAAA,aAAmB;IACjD,QAAQ;IACR,SAAS;MACP,gBAAgB;MAChB,eAAe,UAAU,CAAA;IAC3B;IACA,MAAM,KAAK,UAAU;MAAE,OAAA;MAAO,WAAAF;IAAU,CAAC;EAC3C,CAAC;AAED,MAAI,CAAC,EAAS,GACZ,OAAU,MACR,GAAGC,EAAA,mBAAyB,EAAS,MAAA,IAAU,EAAS,UAAA,EAC1D;AAGF,MAAM,IAAQ,MAAM,EAAS,KAAK;AAKlC,MAAI,EAAK,UAAU,EAAK,OAAO,SAAS,EACtC,OAAU,MACR,GAAGA,EAAA,cAAoB,EAAK,OAAO,IAAA,CAAKE,OAAUA,GAAM,OAAO,EAAE,KAAK,IAAI,CAAA,EAC5E;AAGF,MAAI,CAAC,EAAK,KACR,OAAU,MAAM,GAAGF,EAAA,wCAA8C;AAGnE,SAAO,EAAK;AACd;ADpDA,IOIM,IAA0B;APJhC,IOcM,IAA6B;APdnC,IOwBM,IAAgC;APxBtC,IO8BM,IAAgD;AP9BtD,IOoCa,IAAK;EAChB,MAAM,IACJ,GACAG,IACwB;AACxB,QAAM,EAAE,aAAAC,GAAA,IAAgB,MAAM,EAG5B;MACA,OAAO;MACP,WAAW;QAAE,KAAA;QAAK,OAAOD,IAAS,SAAS;MAA4B;MACvE,QAAQ;IACV,CAAC;AAED,WAAQC,IAAa,SAAS;EAChC;EAEA,MAAM,IACJ,GACAD,IACAC,IACe;AACf,UAAM,EAKJ;MACA,OAAO;MACP,WAAW,EACT,OAAO;QACL,KAAA;QACA,OAAAD;QACA,OAAOC,IAAS,SAAS;MAC3B,EACF;MACA,QAAQ;IACV,CAAC;EACH;EAEA,MAAM,OAAO,GAAaD,IAAuC;AAC/D,QAAM,EAAE,mBAAAC,GAAA,IAAsB,MAAM,EAGlC;MACA,OAAO;MACP,WAAW;QAAE,KAAA;QAAK,OAAOD,IAAS,SAAS;MAA4B;MACvE,QAAQ;IACV,CAAC;AAED,WAAOC;EACT;AACF;;;AEpCO,IAAM,sBAAsB;AAC5B,IAAM,uBAAuB,KAAK,mBAAmB;AAyDrD,IAAM,qBAAqB;;;ACxF3B,IAAM,uBAA2C;AAAA,EACtD,MAAM,MAAM,EAAG,IAAa,oBAAoB,EAAE,OAAO,YAAY,CAAC;AAAA,EACtE,OAAO,OAAO,UAAU;AACtB,UAAM,EAAG,IAAI,oBAAoB,OAAO,EAAE,OAAO,YAAY,CAAC;AAAA,EAChE;AACF;;;ACMA,IAAM,oBAAoB,OACxB,WACuC;AACvC,QAAM,WAAW,MAAM,OAAO,MAAM;AAAA,IAClC,mBAAmB,EAAE,OAAO,EAAE,MAAM,0BAA0B,EAAE,EAAE;AAAA,EACpE,CAAC;AAED,SAAO,oBAAoB,UAAU,mBAAmB;AAC1D;AAEA,IAAM,gBAAgB,CAAC,UAAmB,iBAAwC;AAChF,MAAI,OAAO,aAAa,YAAY,aAAa,MAAM;AACrD,WAAO;AAAA,EACT;AAEA,QAAM,UAAW,SAAqC,YAAY;AAElE,MAAI,OAAO,YAAY,YAAY,YAAY,MAAM;AACnD,WAAO;AAAA,EACT;AAEA,QAAM,KAAM,QAAoC,IAAI;AAEpD,SAAO,OAAO,OAAO,WAAW,KAAK;AACvC;AAQA,IAAM,sBAAsB,OAC1B,QACA,SACA,WACkB;AAClB,MAAI;AACF,UAAM,OAAO,SAAS;AAAA,MACpB,0BAA0B;AAAA,QACxB,QAAQ;AAAA,UACN,MAAM;AAAA,YACJ,MAAM;AAAA,YACN,WAAW;AAAA,YACX,aAAY,oBAAI,KAAK,GAAE,YAAY;AAAA,YACnC,wBAAwB;AAAA,YACxB,iBAAiB;AAAA,YACjB,WAAW;AAAA,YACX,kBAAkB,qBAAqB,sBAAsB;AAAA,YAC7D,WAAW;AAAA,YACX,OAAO;AAAA,YACP,MAAM;AAAA,YACN,UAAU;AAAA,YACV,gBAAgB;AAAA,YAChB,SAAS;AAAA,UACX;AAAA,QACF;AAAA,QACA,IAAI;AAAA,MACN;AAAA,IACF,CAAC;AAAA,EACH,SAAS,OAAO;AACd,kBAAc,8BAA8B,EAAE,OAAO,cAAc,KAAK,EAAE,CAAC;AAAA,EAC7E;AACF;AAkCO,IAAM,iBAAiB,OAAO;AAAA,EACnC;AAAA,EACA;AACF,MAAoD;AAClD,QAAM,WAAW,MAAM,kBAAkB,MAAM;AAE/C,MAAI,SAAS,WAAW,GAAG;AACzB,UAAM,OAAO,0BAA0B;AAEvC,UAAM,WAAW,MAAM,OAAO,SAAS;AAAA,MACrC,wBAAwB,EAAE,QAAQ,EAAE,MAAM,KAAK,GAAG,IAAI,KAAK;AAAA,IAC7D,CAAC;AAED,UAAMC,YAAW,cAAc,UAAU,wBAAwB;AAEjE,kBAAc,iBAAiB;AAAA,MAC7B,UAAAA;AAAA,MACA,YAAY,QAAQ,cAAc;AAAA,IACpC,CAAC;AAED,UAAM;AAAA,MACJ;AAAA,MACA,4DAAsD,QAAQ,cAAc,iBAAiB;AAAA,MAC7F;AAAA,QACE,QAAQ;AAAA,QACR,YAAY,QAAQ,cAAc;AAAA,QAClC,eAAe;AAAA,QACf,WAAW,OAAO;AAAA,UACf,KAAK,cAAc,KAAiC,CAAC;AAAA,QACxD,EAAE;AAAA,MACJ;AAAA,IACF;AAEA,WAAO,EAAE,QAAQ,UAAU,UAAAA,UAAS;AAAA,EACtC;AAEA,QAAM,SAAS,kBAAkB,QAAQ;AACzC,QAAM,WACJ,WAAW,QAAQ,OAAO,OAAO,IAAI,MAAM,WAAW,OAAO,IAAI,IAAI;AAEvE,MAAI,QAAQ,oBAAoB,QAAW;AAKzC,kBAAc,uBAAuB;AAAA,MACnC,aAAa,SAAS;AAAA,MACtB,QAAQ;AAAA,IACV,CAAC;AAED,WAAO,EAAE,QAAQ,kBAAkB,aAAa,SAAS,OAAO;AAAA,EAClE;AAEA,QAAM,QAAQ,wBAAwB,MAAM;AAC5C,QAAM,aAAa,OAAO,KAAK,KAAK;AAEpC,MAAI,WAAW,WAAW,KAAK,aAAa,MAAM;AAChD,kBAAc,uBAAuB;AAAA,MACnC;AAAA,MACA,iBAAiB,QAAQ;AAAA,MACzB,YAAY,QAAQ,cAAc;AAAA,IACpC,CAAC;AAED,WAAO,EAAE,QAAQ,cAAc,SAAS;AAAA,EAC1C;AAEA,QAAM,OAAO,SAAS;AAAA,IACpB,wBAAwB,EAAE,QAAQ,EAAE,IAAI,UAAU,MAAM,MAAM,GAAG,IAAI,KAAK;AAAA,EAC5E,CAAC;AAED,gBAAc,mBAAmB;AAAA,IAC/B;AAAA,IACA,iBAAiB,QAAQ;AAAA,IACzB,YAAY,QAAQ,cAAc;AAAA,IAClC;AAAA,EACF,CAAC;AAED,QAAM;AAAA,IACJ;AAAA,IACA,uEAAiE,QAAQ,cAAc,iBAAiB;AAAA,IACxG;AAAA,MACE,QAAQ;AAAA,MACR,iBAAiB,QAAQ;AAAA,MACzB,YAAY,QAAQ,cAAc;AAAA,MAClC;AAAA,IACF;AAAA,EACF;AAEA,SAAO,EAAE,QAAQ,UAAU,UAAU,WAAW;AAClD;;;AC5JO,IAAM,qBAAqB;AAE3B,IAAM,sBAAsB,KAAK,kBAAkB;AAoCnD,IAAM,+BAA+B;AAOrC,IAAM,wBAAwB;AAC9B,IAAM,wBAAwB;AAkB9B,IAAM,6BAA6B;AAoBnC,IAAM,8BAA8B;AASpC,IAAM,2BAA2B;AAUjC,IAAM,yBAAyB;AAAA,EACpC,KAAK;AAAA,EACL,mBAAmB;AAAA,EACnB,SAAS;AAAA,EACT,YAAY;AACd;AAOO,IAAM,0BAA0B;AAchC,IAAM,uBAAuB;AAS7B,IAAM,4BAA4B;AAMlC,IAAM,uBAAuB;AAe7B,IAAM,2BAA2B;AAMjC,IAAM,2BAA2B;;;ACpLxC,IAAM,QAAQ,EAAE,OAAO,YAAY;AAEnC,IAAMC,YAAW,CAAC,UAChB,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AAOrE,IAAM,iBAAiB,CAAC,UAAmD;AACzE,MAAI,CAACA,UAAS,KAAK,GAAG;AACpB,WAAO;AAAA,EACT;AAEA,QAAM,EAAE,UAAU,OAAO,WAAW,IAAI;AAExC,MACE,OAAO,aAAa,YACpB,OAAO,UAAU,aACjB,OAAO,eAAe,WACtB;AACA,WAAO;AAAA,EACT;AAEA,SAAO;AAAA,IACL;AAAA,IACA,WAAW,OAAO,MAAM,WAAW,MAAM,WAAW,MAAM,WAAW,IAAI;AAAA,IACzE;AAAA,IACA;AAAA,IACA,QAAQ,OAAO,MAAM,QAAQ,MAAM,WAAW,MAAM,QAAQ,IAAI;AAAA,IAChE,UAAU,MAAM,QAAQ,MAAM,UAAU,CAAC,IACrC,MAAM,UAAU,EAAE,OAAO,CAAC,UAA2B,OAAO,UAAU,QAAQ,IAC9E,CAAC;AAAA,IACL,MAAM,OAAO,MAAM,MAAM,MAAM,WAAW,MAAM,MAAM,IAAI;AAAA,IAC1D,eACE,OAAO,MAAM,eAAe,MAAM,WAAW,MAAM,eAAe,IAAI;AAAA,IACxE,eAAe,MAAM,eAAe,MAAM;AAAA,IAC1C,UAAU,OAAO,MAAM,UAAU,MAAM,WAAW,MAAM,UAAU,IAAI;AAAA,EACxE;AACF;AAEA,IAAM,sBAAsB,CAAC,UAA2C;AACtE,MAAI,CAACA,UAAS,KAAK,GAAG;AACpB,WAAO,EAAE,QAAQ,UAAU;AAAA,EAC7B;AAEA,QAAM,SAAS,MAAM,QAAQ;AAC7B,QAAM,KAAK,OAAO,MAAM,IAAI,MAAM,WAAW,MAAM,IAAI,IAAI;AAE3D,MAAI,WAAW,aAAa,WAAW,iBAAiB;AACtD,WAAO,EAAE,QAAQ,GAAG;AAAA,EACtB;AAEA,SAAO,EAAE,QAAQ,UAAU;AAC7B;AAEO,IAAM,iBAAmC;AAAA,EAC9C,WAAW,YAAY;AACrB,QAAI;AACF,aAAO,eAAe,MAAM,EAAG,IAAa,sBAAsB,KAAK,CAAC;AAAA,IAC1E,SAAS,OAAO;AACd,oBAAc,6BAA6B,EAAE,OAAO,cAAc,KAAK,EAAE,CAAC;AAE1E,aAAO;AAAA,IACT;AAAA,EACF;AAAA,EAEA,YAAY,OAAO,UAAU;AAC3B,QAAI;AACF,YAAM,EAAG,IAAI,sBAAsB,OAAO,KAAK;AAAA,IACjD,SAAS,OAAO;AACd,oBAAc,8BAA8B,EAAE,OAAO,cAAc,KAAK,EAAE,CAAC;AAAA,IAC7E;AAAA,EACF;AAAA,EAEA,gBAAgB,YAAY;AAC1B,QAAI;AACF,aAAO;AAAA,QACL,MAAM,EAAG,IAAa,2BAA2B,KAAK;AAAA,MACxD;AAAA,IACF,SAAS,OAAO;AACd,oBAAc,kCAAkC;AAAA,QAC9C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAED,aAAO,EAAE,QAAQ,UAAU;AAAA,IAC7B;AAAA,EACF;AAAA,EAEA,iBAAiB,OAAO,UAAU;AAChC,QAAI;AACF,YAAM,EAAG,IAAI,2BAA2B,OAAO,KAAK;AAAA,IACtD,SAAS,OAAO;AACd,oBAAc,mCAAmC;AAAA,QAC/C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAAA,EACF;AAAA,EAEA,cAAc,OAAO,UAAU;AAC7B,QAAI;AACF,YAAM,EAAG,IAAI,sBAAsB,OAAO,KAAK;AAAA,IACjD,SAAS,OAAO;AACd,oBAAc,gCAAgC,EAAE,OAAO,cAAc,KAAK,EAAE,CAAC;AAAA,IAC/E;AAAA,EACF;AACF;AAkBA,IAAM,uBAAuB,CAAC,UAA6C;AACzE,MAAI,CAACA,UAAS,KAAK,GAAG;AACpB,WAAO;AAAA,EACT;AAEA,QAAM,EAAE,UAAU,aAAa,SAAS,YAAY,MAAM,IAAI;AAE9D,MAAI,OAAO,aAAa,YAAY,CAACA,UAAS,WAAW,GAAG;AAC1D,WAAO;AAAA,EACT;AAEA,MAAI,OAAO,YAAY,oBAAoB,MAAM,UAAU;AACzD,WAAO;AAAA,EACT;AAOA,MACE,OAAO,YAAY,YACnB,QAAQ,WAAW,KACnB,OAAO,eAAe,YACtB,OAAO,UAAU,UACjB;AACA,WAAO;AAAA,EACT;AAEA,SAAO;AAAA,IACL;AAAA,IACA;AAAA,IACA;AAAA,IACA;AAAA,IACA;AAAA,EACF;AACF;AAEO,IAAM,qBAA2C;AAAA,EACtD,iBAAiB,YAAY;AAC3B,QAAI;AACF,aAAO;AAAA,QACL,MAAM,EAAG,IAAa,0BAA0B,KAAK;AAAA,MACvD;AAAA,IACF,SAAS,OAAO;AACd,oBAAc,iCAAiC;AAAA,QAC7C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAED,aAAO;AAAA,IACT;AAAA,EACF;AAAA,EAEA,kBAAkB,OAAO,UAAU;AACjC,QAAI;AACF,YAAM,EAAG,IAAI,0BAA0B,OAAO,KAAK;AAAA,IACrD,SAAS,OAAO;AACd,oBAAc,kCAAkC;AAAA,QAC9C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAAA,EACF;AAAA,EAEA,kBAAkB,YAAY;AAC5B,QAAI;AAMF,YAAM,EAAG,IAAI,0BAA0B,MAAM,KAAK;AAAA,IACpD,SAAS,OAAO;AACd,oBAAc,kCAAkC;AAAA,QAC9C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAAA,EACF;AAAA,EAEA,yBAAyB,OAAO,UAAU;AACxC,QAAI;AACF,YAAM,EAAG,IAAI,0BAA0B,OAAO,KAAK;AAAA,IACrD,SAAS,OAAO;AACd,oBAAc,oCAAoC;AAAA,QAChD,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAAA,EACF;AACF;;;ACvNA,IAAMC,YAAW,CAAC,UAChB,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AAErE,IAAM,cAAc,CAAC,OAAgB,aACnC,OAAO,UAAU,YAAY,QAAQ;AAEvC,IAAM,aAAa,CAAC,UAClB,OAAO,UAAU,YAAY,MAAM,SAAS,IAAI,QAAQ;AAO1D,IAAM,aAAa,CAAC,UAAkC;AACpD,MAAI,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK,GAAG;AACvD,WAAO;AAAA,EACT;AAEA,MAAI,OAAO,UAAU,YAAY,MAAM,KAAK,EAAE,SAAS,GAAG;AACxD,UAAM,SAAS,OAAO,KAAK;AAE3B,WAAO,OAAO,SAAS,MAAM,IAAI,SAAS;AAAA,EAC5C;AAEA,SAAO;AACT;AAEA,IAAM,kBAAkB,CAAC,UACvB,MAAM,QAAQ,KAAK,IACf,MAAM,OAAO,CAAC,UAA2B,OAAO,UAAU,QAAQ,IAClE,CAAC;AAEA,IAAM,0BAA0B,CAAC,YAAuC;AAC7E,MAAI,CAACA,UAAS,OAAO,GAAG;AACtB,WAAO;AAAA,MACL,MAAM;AAAA,MACN,QAAQ,oCAAoC,YAAY,OAAO,SAAS,OAAO,OAAO;AAAA,IACxF;AAAA,EACF;AAEA,QAAM,QAAQ,QAAQ,OAAO;AAE7B,MAAI,OAAO,UAAU,WAAW;AAC9B,WAAO;AAAA,MACL,MAAM;AAAA,MACN,QAAQ,mDAAmD,OAAO,KAAK;AAAA,IACzE;AAAA,EACF;AAEA,SAAO;AAAA,IACL,MAAM;AAAA,IACN,UAAU;AAAA,MACR;AAAA,MACA,QAAQ,WAAW,QAAQ,QAAQ,CAAC;AAAA;AAAA;AAAA,MAGpC,YAAY,YAAY,QAAQ,YAAY,GAAG,KAAK;AAAA,MACpD,UAAU,gBAAgB,QAAQ,UAAU,CAAC;AAAA,MAC7C,MAAM,WAAW,QAAQ,MAAM,CAAC;AAAA;AAAA;AAAA;AAAA,MAIhC,aAAa,WAAW,QAAQ,MAAM,CAAC;AAAA,MACvC,QAAQ,WAAW,QAAQ,QAAQ,CAAC;AAAA,MACpC,eAAe,WAAW,QAAQ,eAAe,CAAC;AAAA,MAClD,eAAe,YAAY,QAAQ,eAAe,GAAG,KAAK;AAAA,MAC1D,UAAU,WAAW,QAAQ,UAAU,CAAC;AAAA,MACxC,gBAAgB,WAAW,QAAQ,gBAAgB,CAAC;AAAA,MACpD,gBAAgB,WAAW,QAAQ,gBAAgB,CAAC;AAAA,MACpD,eAAe,YAAY,QAAQ,eAAe,GAAG,KAAK;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,MAO1D,0BAA0B,WAAW,QAAQ,0BAA0B,CAAC;AAAA,MACxE,oBAAoB,YAAY,QAAQ,oBAAoB,GAAG,KAAK;AAAA,MACpE,qBAAqB,WAAW,QAAQ,qBAAqB,CAAC;AAAA;AAAA;AAAA,MAG9D,WAAW,WAAW,QAAQ,WAAW,CAAC;AAAA;AAAA;AAAA;AAAA,MAI1C,kBAAkB,QAAQ,kBAAkB;AAAA,IAC9C;AAAA,EACF;AACF;;;ACpGA,IAAM,mBAAmB;AACzB,IAAM,YAAY;AAElB,IAAM,cAAc,CAAC,UAA0B;AAC7C,MAAI,OAAO;AAEX,WAAS,QAAQ,GAAG,QAAQ,MAAM,QAAQ,SAAS,GAAG;AACpD,YAAQ,MAAM,WAAW,KAAK;AAE9B,WAAO,KAAK,KAAK,MAAM,SAAS,MAAM;AAAA,EACxC;AAEA,SAAO,KAAK,SAAS,EAAE,EAAE,SAAS,GAAG,GAAG;AAC1C;AAOA,IAAM,oBAAoB;AAEnB,IAAM,uBAAuB;AAS7B,IAAM,iBAAiB,CAAC,QAA2C;AACxE,MAAI,OAAO,QAAQ,UAAU;AAC3B,WAAO;AAAA,EACT;AAEA,QAAM,UAAU,IAAI,KAAK;AAEzB,MAAI,QAAQ,WAAW,GAAG;AACxB,WAAO;AAAA,EACT;AAEA,QAAM,QAAQ,QACX,MAAM,GAAG,EACT;AAAA,IAAI,CAAC,OAAO,UACX,UAAU,KAAK,MAAM,YAAY,MAAM,oBACnC,oBACA,IAAI,OAAO,MAAM,MAAM;AAAA,EAC7B,EACC,KAAK,GAAG;AAEX,SAAO,GAAG,KAAK,KAAK,YAAY,OAAO,CAAC;AAC1C;AAeO,IAAM,mBAAmB,CAC9B,MACA,QACW;AACX,MAAI,OAAO,QAAQ,UAAU;AAC3B,WAAO;AAAA,EACT;AAEA,QAAM,UAAU,IAAI,KAAK;AAEzB,MAAI,QAAQ,SAAS,GAAG;AACtB,WAAO;AAAA,EACT;AAEA,QAAM,OAAO,eAAe,OAAO;AAEnC,SAAO,KACJ,MAAM,OAAO,EACb,KAAK,IAAI,EACT,MAAM,mBAAmB,OAAO,CAAC,EACjC,KAAK,IAAI;AACd;;;ACTA,IAAM,qBAAqB;AAE3B,IAAM,WAAW,CAAC,UAA2B;AAC3C,MAAI,iBAAiB,OAAO;AAC1B,WAAO,GAAG,MAAM,IAAI,KAAK,MAAM,OAAO;AAAA,EACxC;AAEA,SAAO,OAAO,UAAU,WAAW,QAAQ;AAC7C;AAQA,IAAM,iBAAiB,CAAC,YAAiE;AACvF,QAAM,MAAM,QAAQ,IAAI,aAAa;AAErC,MAAI,QAAQ,MAAM;AAChB,WAAO;AAAA,EACT;AAEA,QAAM,UAAU,OAAO,IAAI,KAAK,CAAC;AAEjC,SAAO,OAAO,SAAS,OAAO,KAAK,WAAW,IAAI,UAAU;AAC9D;AAEA,IAAM,iBAAiB,CACrB,QACA,YACuB;AACvB,MAAI,WAAW,KAAK;AAClB,WAAO,EAAE,MAAM,gBAAgB,mBAAmB,eAAe,OAAO,EAAE;AAAA,EAC5E;AAEA,MAAI,UAAU,KAAK;AACjB,WAAO,EAAE,MAAM,uBAAuB,YAAY,OAAO;AAAA,EAC3D;AAOA,MAAI,WAAW,OAAO,WAAW,KAAK;AACpC,WAAO,EAAE,MAAM,gBAAgB,YAAY,OAAO;AAAA,EACpD;AAMA,SAAO,EAAE,MAAM,qBAAqB,YAAY,OAAO;AACzD;AAEA,IAAM,gBAAgB,CAAC,cAA+C;AAIpE,MAAI,OAAO,gBAAgB,eAAe,OAAO,YAAY,YAAY,YAAY;AACnF,WAAO,YAAY,QAAQ,SAAS;AAAA,EACtC;AAEA,SAAO;AACT;AAEA,IAAM,mBAAmB,CAAC,YACxB,QAAQ,KAAK,EAAE,QAAQ,QAAQ,EAAE;AAU5B,IAAM,4BAA4B,CACvC,YACkB;AAClB,QAAM,UAAU,iBAAiB,QAAQ,WAAW,EAAE;AACtD,QAAM,cAAc,QAAQ,eAAe;AAC3C,QAAM,YAAY,QAAQ,aAAa;AASvC,QAAM,qBACJ,gBAAgB,YAAY,EAAE,CAAC,0BAA0B,GAAG,UAAU,IAAI,CAAC;AAC7E,QAAM,UACJ,QAAQ,cACP,OAAO,WAAW,UAAU,aACxB,WAAW,QACZ;AAEN,QAAM,OAAO,OACX,MACA,MACA,QAKG;AACH,QAAI,QAAQ,WAAW,GAAG;AACxB,aAAO;AAAA,QACL,MAAM;AAAA,QACN,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,QAAI,YAAY,MAAM;AACpB,aAAO;AAAA,QACL,MAAM;AAAA,QACN,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,QAAI;AAEJ,QAAI;AACF,iBAAW,MAAM,QAAQ,GAAG,OAAO,GAAG,IAAI,IAAI;AAAA,QAC5C,QAAQ;AAAA,QACR,SAAS;AAAA,UACP,gBAAgB;AAAA,UAChB,QAAQ;AAAA,UACR,GAAG;AAAA,QACL;AAAA,QACA,MAAM,KAAK,UAAU,IAAI;AAAA,QACzB,QAAQ,cAAc,SAAS;AAAA,MACjC,CAAC;AAAA,IACH,SAAS,OAAO;AACd,aAAO;AAAA,QACL,MAAM;AAAA,QACN,QAAQ,iBAAiB,SAAS,KAAK,GAAG,GAAG;AAAA,MAC/C;AAAA,IACF;AAEA,QAAI,CAAC,SAAS,IAAI;AAChB,aAAO,EAAE,MAAM,UAAU,QAAQ,SAAS,QAAQ,SAAS,SAAS,QAAQ;AAAA,IAC9E;AAEA,QAAI;AAEJ,QAAI;AACF,YAAM,MAAM,SAAS,KAAK;AAAA,IAC5B,SAAS,OAAO;AACd,aAAO;AAAA,QACL,MAAM;AAAA,QACN,QAAQ,iBAAiB,SAAS,KAAK,GAAG,GAAG;AAAA,MAC/C;AAAA,IACF;AAEA,QAAI;AACF,aAAO,EAAE,MAAM,MAAM,SAAS,KAAK,MAAM,GAAG,EAAa;AAAA,IAC3D,SAAS,OAAO;AACd,aAAO;AAAA,QACL,MAAM;AAAA,QACN,QAAQ,iBAAiB,SAAS,KAAK,GAAG,GAAG;AAAA,MAC/C;AAAA,IACF;AAAA,EACF;AAEA,SAAO;AAAA,IACL,UAAU,OAAO,EAAE,KAAK,mBAAmB,QAAQ,MAAuC;AACxF,YAAM,OAAgC,EAAE,CAAC,uBAAuB,GAAG,GAAG,IAAI;AAE1E,UAAI,OAAO,sBAAsB,YAAY,kBAAkB,SAAS,GAAG;AACzE,aAAK,uBAAuB,iBAAiB,IAAI;AAAA,MACnD;AAEA,UAAI,OAAO,YAAY,YAAY,QAAQ,SAAS,GAAG;AACrD,aAAK,uBAAuB,OAAO,IAAI;AAAA,MACzC;AAEA,YAAM,SAAS,MAAM,KAAK,uBAAuB,MAAM,GAAG;AAE1D,UAAI,OAAO,SAAS,UAAU;AAI5B,eAAO,eAAe,OAAO,QAAQ,OAAO,OAAO;AAAA,MACrD;AAEA,UAAI,OAAO,SAAS,MAAM;AACxB,eAAO;AAAA,MACT;AAEA,YAAM,SAAS,wBAAwB,OAAO,OAAO;AAErD,aAAO,OAAO,SAAS,WACnB,EAAE,MAAM,aAAa,UAAU,OAAO,SAAS,IAC/C,EAAE,MAAM,sBAAsB,QAAQ,OAAO,OAAO;AAAA,IAC1D;AAAA,IAEA,UAAU,OAAO;AAAA,MACf;AAAA,MACA;AAAA,MACA;AAAA,IACF,MAAuC;AACrC,YAAM,OAAgC;AAAA,QACpC,CAAC,uBAAuB,GAAG,GAAG;AAAA,QAC9B,CAAC,uBAAuB,iBAAiB,GAAG;AAAA,MAC9C;AAEA,UAAI,OAAO,eAAe,YAAY,WAAW,SAAS,GAAG;AAC3D,aAAK,uBAAuB,UAAU,IAAI;AAAA,MAC5C;AAEA,YAAM,SAAS,MAAM,KAAK,uBAAuB,MAAM,GAAG;AAE1D,UAAI,OAAO,SAAS,UAAU;AAE5B,YAAI,OAAO,WAAW,KAAK;AACzB,iBAAO,EAAE,MAAM,2BAA2B;AAAA,QAC5C;AAKA,YAAI,OAAO,WAAW,KAAK;AACzB,iBAAO,EAAE,MAAM,qBAAqB,YAAY,IAAI;AAAA,QACtD;AAEA,eAAO,eAAe,OAAO,QAAQ,OAAO,OAAO;AAAA,MACrD;AAEA,UAAI,OAAO,SAAS,MAAM;AACxB,eAAO;AAAA,MACT;AAOA,YAAM,UAAU,OAAO;AACvB,YAAM,KACJ,OAAO,YAAY,YAAY,YAAY,OACrC,QAAoC,IAAI,KACzC,QAAoC,cAAc,IACnD;AAEN,aAAO,EAAE,MAAM,aAAa,cAAc,OAAO,OAAO,WAAW,KAAK,KAAK;AAAA,IAC/E;AAAA,EACF;AACF;;;ACvSO,IAAM,2BAA2B;AAGjC,IAAM,uBAAuB;AAcpC,IAAM,aAAa,CAAC,kBAClB,kBAAkB,OACd,SACA,iBAAiB,IACf,UACA,kBAAkB,IAChB,aACA,MAAM,aAAa;AAE7B,IAAM,aAAa,CAACC,gBAClBA,gBAAe,OAAO,UAAU,GAAG,KAAK,MAAMA,cAAa,IAAS,CAAC;AAOvE,IAAM,mBAAmB,CAAC,gBACxB,gBAAgB,YAAY,YAAY;AAG1C,IAAM,wBAAwB,CAAC,gBAC7B,gBAAgB,YAAY,eAAe;AAStC,IAAM,0BAA0B,CAAC,UAAuC;AAC7E,QAAM,WACJ,MAAM,iBACL,MAAM,kBAAkB,QAAQ,MAAM,iBAAiB;AAE1D,UAAQ,MAAM,QAAQ;AAAA,IACpB,KAAK;AACH,aAAO,WACH;AAAA,QACE,UAAU,MAAM;AAAA,QAChB,UAAU,8BAA8B,WAAW,MAAM,aAAa,CAAC;AAAA,QACvE,QACE;AAAA,MACJ,IACA;AAAA,QACE,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QAAQ,wBAAwB,MAAM,SAAS,OAAO,KAAK,WAAW,MAAM,IAAI,OAAO;AAAA,MACzF;AAAA,IAEN,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,IAOF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU,yDAAyD,iBAAiB,MAAM,WAAW,CAAC;AAAA,QACtG,QACE,wKAAwK,iBAAiB,MAAM,WAAW,CAAC,4CAA4C,sBAAsB,MAAM,WAAW,CAAC;AAAA,MACnS;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QACE;AAAA,MACJ;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UAAU;AAAA,QACV,QAAQ,qFAAqF,WAAW,MAAM,UAAU,CAAC;AAAA,MAC3H;AAAA,IAEF,KAAK;AACH,aAAO;AAAA,QACL,UAAU,MAAM;AAAA,QAChB,UACE,MAAM,eAAe,OACjB,0DACA;AAAA,QACN,QAAQ,2EAA2E,WAAW,MAAM,UAAU,CAAC;AAAA,MACjH;AAAA,EACJ;AACF;AAsCO,IAAM,0BAA0B,CACrC,WACwB;AAAA,EACxB,WAAW,MAAM;AAAA,EACjB,WAAW,MAAM;AAAA,EACjB,aAAa,iBAAiB,MAAM,WAAW;AAAA,EAC/C,OAAO,MAAM;AAAA,EACb,YAAY,MAAM;AAAA,EAClB,QAAQ,MAAM;AAAA,EACd,QAAQ,MAAM;AAAA;AAAA;AAAA;AAAA,EAId,QAAQ,MAAM,WAAW;AAAA,EACzB,eACE,MAAM,eAAe,OACjB,OACA,KAAK,MAAO,MAAM,aAAa,OAAa,EAAE,IAAI;AAAA,EACxD,MAAM,MAAM;AAAA,EACZ,UAAU,MAAM;AAAA,EAChB,aAAa,MAAM;AAAA,EACnB,MAAM,MAAM;AAAA,EACZ,eAAe,MAAM;AAAA,EACrB,eAAe,MAAM;AAAA,EACrB,UAAU,MAAM;AAClB;AAYO,IAAM,uBAAuB,CAClC,OAeA,gBAM4B;AAC5B,QAAM,SAAS,wBAAwB,KAAK;AAI5C,QAAM,mBACJ,gBAAgB,QAAQ,gBAAgB,SACpC,OACA,YAAY,WAAW,gBACrB,OAAO,YAAY,uBAAuB,WAC1C,gBAAgB,YAAY,kBAAkB,KAC9C;AAER,SAAO;AAAA,IACL,MACE,qBAAqB,OACjB,GAAG,oBAAoB,SAAM,OAAO,QAAQ,SAAM,MAAM,IAAI,KAC5D,GAAG,oBAAoB,SAAM,OAAO,QAAQ,SAAM,MAAM,IAAI,SAAM,gBAAgB;AAAA;AAAA;AAAA;AAAA,IAIxF,WAAW;AAAA,IACX,YAAY,MAAM;AAAA,IAClB,wBAAwB;AAAA,IACxB,iBAAiB;AAAA,IACjB,WAAW;AAAA,IACX,kBAAkB,wBAAwB,wBAAwB;AAAA,IAClE,WAAW;AAAA,MACT,GAAG,wBAAwB,KAAK;AAAA,MAChC,aAAa,OAAO;AAAA,MACpB,GAAI,gBAAgB,QAAQ,gBAAgB,SACxC,CAAC,IACD,EAAE,YAAY;AAAA,IACpB;AAAA,IACA,OAAO;AAAA,IACP,MAAM;AAAA,IACN,UAAU;AAAA,IACV,gBAAgB;AAAA,IAChB,SAAS;AAAA,EACX;AACF;;;AC5RA,IAAM,wBAA6C,oBAAI,IAAmB;AAAA,EACxE;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF,CAAC;AAEM,IAAM,yBAAyB,CACpC,WACkB;AAMlB,MAAI,WAAW,QAAQ,OAAO,KAAK,EAAE,YAAY,MAAM,0BAA0B;AAC/E,WAAO;AAAA,EACT;AAEA,MAAI,WAAW,QAAQ,sBAAsB,IAAI,MAAM,GAAG;AACxD,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAUO,IAAM,uBAAuB,CAAC,gBAGtB,YAAY,UAAU,QAAQ,YAAY,eAAe;AAgBjE,IAAM,oBAAoB,CAAC,gBAIb;AACnB,MAAI,CAAC,YAAY,OAAO;AACtB,WAAO,uBAAuB,YAAY,MAAM;AAAA,EAClD;AAEA,MAAI,CAAC,YAAY,YAAY;AAC3B,WAAO;AAAA,EACT;AAEA,SAAO;AACT;;;ACnEA,IAAM,kBAAoE;AAAA,EACxE,UAAU;AAAA,EACV,gBAAgB;AAAA,EAChB,sBAAsB;AAAA;AAAA;AAAA;AAAA;AAAA,EAKtB,kCAAkC;AAAA,EAClC,SAAS;AAAA,EACT,SAAS;AAAA,EACT,WAAW;AAAA,EACX,gBAAgB;AAAA,EAChB,sBAAsB;AAAA,EACtB,yBAAyB;AAAA,EACzB,iBAAiB;AAAA,EACjB,8BAA8B;AAAA,EAC9B,4BAA4B;AAAA,EAC5B,6BAA6B;AAAA,EAC7B,2CAA2C;AAC7C;AAEA,IAAM,gBAA2D;AAAA,EAC/D,IAAI;AAAA,EACJ,QAAQ;AAAA,EACR,SAAS;AAAA,EACT,SAAS;AACX;AAEA,IAAM,QAAQ,CAAC,GAAoBC,OACjC,cAAc,CAAC,KAAK,cAAcA,EAAC,IAAI,IAAIA;AAStC,IAAM,sBAAsB;AAEnC,IAAM,iBAAiB,CACrB,eACA,kBAEA,iBAAkB,kBAAkB,QAAQ,iBAAiB;AAgB/D,IAAM,gBAAgB,CACpB,SACA,YACkB;AAClB,UAAQ,QAAQ,MAAM;AAAA,IACpB,KAAK;AACH,aAAO;AAAA,IACT,KAAK;AACH,aAAO;AAAA,IACT,KAAK;AAKH,aAAO;AAAA,IACT,KAAK;AAGH,aAAO;AAAA,IACT;AACE,aAAO,UACH,gCACA;AAAA,EACR;AACF;AAYA,IAAM,eAAe,CAAC,YACpB,QAAQ,SAAS,kBAAkB,QAAQ,SAAS;AAc/C,IAAM,kBAAkB,CAC7B,UACA,WACA,SAC6B;AAAA,EAC7B,UAAU,IAAI,YAAY;AAAA,EAC1B;AAAA,EACA,OAAO,SAAS;AAAA,EAChB,YAAY,SAAS;AAAA,EACrB,QAAQ,SAAS;AAAA,EACjB,UAAU,SAAS;AAAA,EACnB,MAAM,SAAS;AAAA,EACf,eAAe,SAAS;AAAA,EACxB,eAAe,SAAS;AAAA,EACxB,UAAU,SAAS;AACrB;AA4BA,IAAM,aAAa,CACjB,OACA,YACkB;AAAA,EAClB,MAAM;AAAA,EACN;AAAA,EACA,QAAQ;AAAA,EACR,UAAU,gBAAgB,MAAM;AAAA,EAChC,WAAW,MAAM,SAAS;AAAA,EAC1B,aAAa,MAAM;AAAA,EACnB,WAAW,MAAM,IAAI,YAAY;AAAA,EACjC,YAAY;AAAA,EACZ,aAAa;AAAA,EACb,eAAe;AAAA,EACf,oBAAoB;AAAA,EACpB,MAAM;AAAA,EACN,eAAe;AAAA,EACf,eAAe;AAAA,EACf,UAAU;AAAA,EACV,UAAU,CAAC;AACb;AAWA,IAAM,0BAA0B,CAC9B,OACA,eACiB;AACjB,MAAI,WAAW,WAAW,iBAAiB;AACzC,WAAO;AAAA,EACT;AAEA,MAAI,MAAM,WAAW,kBAAkB;AACrC,WAAO;AAAA,EACT;AAEA,SAAO;AAAA,IACL,GAAG;AAAA,IACH,MAAM;AAAA,IACN,QAAQ;AAAA,IACR,UAAU,MAAM,MAAM,UAAU,gBAAgB,yBAAyB,CAAC;AAAA,EAC5E;AACF;AAEA,IAAM,kBAAkB,CACtB,OACA,aACoB;AACpB,QAAM,SAAS,kBAAkB,QAAQ;AACzC,QAAM,WAAW,qBAAqB,QAAQ;AAE9C,QAAM,WAAW,eAAe,SAAS,eAAe,SAAS,aAAa,IAC1E,MAAM,gBAAgB,MAAM,GAAG,SAAS,IACxC,gBAAgB,MAAM;AAE1B,QAAM,QAAsB;AAAA,IAC1B,MAAM,WAAW,SAAS;AAAA,IAC1B;AAAA,IACA,QAAQ;AAAA,IACR;AAAA,IACA,WAAW,MAAM,SAAS;AAAA,IAC1B,aAAa,MAAM;AAAA,IACnB,WAAW,MAAM,IAAI,YAAY;AAAA,IACjC,YAAY;AAAA,IACZ,aAAa;AAAA,IACb,eAAe,SAAS;AAAA,IACxB,oBAAoB,SAAS;AAAA,IAC7B,MAAM,SAAS;AAAA,IACf,eAAe,SAAS;AAAA,IACxB,eAAe,SAAS;AAAA,IACxB,UAAU,SAAS;AAAA,IACnB,UAAU,SAAS;AAAA,EACrB;AAEA,SAAO;AAAA,IACL,OAAO,wBAAwB,OAAO,MAAM,UAAU;AAAA;AAAA;AAAA;AAAA,IAItD,YAAY,gBAAgB,UAAU,MAAM,SAAS,WAAW,MAAM,GAAG;AAAA,EAC3E;AACF;AAEA,IAAM,mBAAmB,CACvB,OACA,SACA,QACA,WACA,UACoB;AACpB,QAAM,UAAU,cAAc;AAK9B,QAAM,SACJ,cAAc,UAAU,kBAAkB,MAAM,IAAI,cAAc,SAAS,OAAO;AAEpF,QAAM,OAAO,cAAc,WAAW,qBAAqB,MAAM,IAAI,SAAS;AAE9E,QAAM,eACJ,cAAc;AAAA;AAAA;AAAA;AAAA,IAIV,MAAM,gBAAgB,MAAM,GAAG,QAAQ;AAAA,MACvC,gBAAgB,MAAM;AAE5B,QAAM,WAAW,eAAe,OAAO,eAAe,OAAO,aAAa,IACtE,MAAM,cAAc,SAAS,IAC7B;AAEJ,QAAM,QAAsB;AAAA,IAC1B;AAAA,IACA;AAAA,IACA,QAAQ,cAAc,UAAU,UAAU,cAAc,UAAU,UAAU;AAAA,IAC5E;AAAA,IACA,WAAW,MAAM,SAAS;AAAA,IAC1B,aAAa,MAAM;AAAA,IACnB,WAAW,MAAM,IAAI,YAAY;AAAA,IACjC,YAAY;AAAA,IACZ,aAAa,QAAQ;AAAA,IACrB,eAAe,OAAO;AAAA,IACtB,oBAAoB,OAAO;AAAA,IAC3B,MAAM,OAAO;AAAA,IACb,eAAe,OAAO;AAAA,IACtB,eAAe,OAAO;AAAA,IACtB,UAAU,OAAO;AAAA,IACjB,UAAU,OAAO;AAAA,EACnB;AAEA,SAAO;AAAA,IACL,OAAO,wBAAwB,OAAO,MAAM,UAAU;AAAA;AAAA;AAAA;AAAA;AAAA,IAKtD,YAAY;AAAA,EACd;AACF;AAEO,IAAM,sBAAsB,CACjC,UACoB;AACpB,MAAI,CAAC,MAAM,SAAS,QAAQ;AAC1B,WAAO;AAAA,MACL,OAAO;AAAA,QACL,WAAW,OAAO,gBAAgB;AAAA,QAClC,MAAM;AAAA,MACR;AAAA,MACA,YAAY;AAAA,IACd;AAAA,EACF;AAEA,MAAI,MAAM,YAAY,QAAQ,MAAM,QAAQ,SAAS,aAAa;AAChE,WAAO,gBAAgB,OAAO,MAAM,QAAQ,QAAQ;AAAA,EACtD;AAMA,QAAM,UACJ,MAAM,YAAY,OACd,EAAE,MAAM,qBAAqB,QAAQ,2BAA2B,IAChE,MAAM;AAGZ,MAAI,aAAa,OAAO,GAAG;AACzB,UAAM,SAAS,cAAc,SAAS,KAAK;AAE3C,WAAO;AAAA,MACL,OAAO;AAAA,QACL,EAAE,GAAG,WAAW,OAAO,MAAM,GAAG,aAAa,QAAQ,KAAK;AAAA,QAC1D,MAAM;AAAA,MACR;AAAA,MACA,YAAY;AAAA,IACd;AAAA,EACF;AAEA,QAAM,EAAE,WAAW,MAAM,IAAI,cAAc,MAAM,QAAQ,UAAU,MAAM,GAAG;AAE5E,MAAI,MAAM,WAAW,QAAQ,cAAc,QAAQ,UAAU,MAAM;AACjE,UAAM,SAAS,cAAc,SAAS,KAAK;AAE3C,WAAO;AAAA,MACL,OAAO;AAAA,QACL,EAAE,GAAG,WAAW,OAAO,MAAM,GAAG,aAAa,QAAQ,KAAK;AAAA,QAC1D,MAAM;AAAA,MACR;AAAA,MACA,YAAY;AAAA,IACd;AAAA,EACF;AAEA,SAAO,iBAAiB,OAAO,SAAS,MAAM,QAAQ,WAAW,KAAK;AACxE;;;AC3aA,IAAM,aAAa;AAEnB,IAAMC,UAAS,MAA2B;AACxC,QAAM,YAAa,WAAsD,QACrE;AAEJ,SAAO,cAAc,SAAY,OAAO;AAC1C;AAEA,IAAM,WAAW,CAAC,UAA8B;AAC9C,MAAI,SAAS;AAEb,aAAW,QAAQ,OAAO;AACxB,cAAU,OAAO,aAAa,IAAI;AAAA,EACpC;AAEA,SAAO,KAAK,MAAM;AACpB;AAUA,IAAM,YAAY,CAAC,MAAc,UAA2B;AAC1D,MAAI,KAAK,WAAW,MAAM,QAAQ;AAChC,WAAO;AAAA,EACT;AAEA,MAAI,aAAa;AAEjB,WAAS,QAAQ,GAAG,QAAQ,KAAK,QAAQ,SAAS,GAAG;AACnD,kBAAc,KAAK,WAAW,KAAK,IAAI,MAAM,WAAW,KAAK;AAAA,EAC/D;AAEA,SAAO,eAAe;AACxB;AASO,IAAM,uBAAuB,CAClC,eACwB;AACxB,MAAI,OAAO,eAAe,YAAY,WAAW,KAAK,EAAE,WAAW,GAAG;AACpE,WAAO;AAAA,EACT;AAEA,QAAM,MAAM,WAAW,KAAK;AAI5B,MAAI,eAAiC;AAErC,QAAM,SAAS,OAAO,WAA6C;AACjE,QAAI,iBAAiB,MAAM;AACzB,aAAO;AAAA,IACT;AAEA,UAAM,UAAU,IAAI,YAAY;AAEhC,UAAM,cAAc,MAAM,OAAO;AAAA,MAC/B;AAAA,MACA,QAAQ,OAAO,GAAG;AAAA,MAClB,EAAE,MAAM,QAAQ,MAAM,UAAU;AAAA,MAChC;AAAA,MACA,CAAC,MAAM;AAAA,IACT;AAEA,UAAM,UAAU,MAAM,OAAO;AAAA,MAC3B;AAAA,MACA;AAAA,MACA,QAAQ,OAAO,UAAU;AAAA,IAC3B;AAEA,mBAAe,MAAM,OAAO;AAAA,MAC1B;AAAA,MACA;AAAA,MACA,EAAE,MAAM,QAAQ,MAAM,UAAU;AAAA,MAChC;AAAA,MACA,CAAC,MAAM;AAAA,IACT;AAEA,WAAO;AAAA,EACT;AAEA,QAAM,MAAM,OAAO,cAA8C;AAC/D,UAAM,SAASA,QAAO;AAEtB,QAAI,WAAW,MAAM;AACnB,aAAO;AAAA,IACT;AAEA,QAAI;AACF,YAAM,YAAY,MAAM,OAAO;AAAA,QAC7B;AAAA,QACA,MAAM,OAAO,MAAM;AAAA,QACnB,IAAI,YAAY,EAAE,OAAO,SAAS;AAAA,MACpC;AAEA,aAAO,SAAS,IAAI,WAAW,SAAS,CAAC;AAAA,IAC3C,QAAQ;AAGN,aAAO;AAAA,IACT;AAAA,EACF;AAEA,SAAO;AAAA,IACL,MAAM;AAAA,IACN,QAAQ,OAAO,WAAW,aAAa;AACrC,YAAM,WAAW,MAAM,IAAI,SAAS;AAEpC,aAAO,aAAa,QAAQ,UAAU,UAAU,QAAQ;AAAA,IAC1D;AAAA,EACF;AACF;;;ACjDO,IAAM,yBAAyB,CACpC,MAA0C,QAAQ,QAC3B;AACvB,QAAM,SAAS,IAAI,aAAa;AAChC,QAAM,UAAU,OAAO,WAAW,WAAW,OAAO,KAAK,IAAI;AAC7D,QAAM,UAAU,IAAI,sBAAsB;AAC1C,QAAM,iBAAiB,IAAI,qBAAqB;AAEhD,SAAO;AAAA,IACL,YAAY,QAAQ,WAAW,IAAI,OAAO;AAAA,IAC1C,SACE,OAAO,YAAY,YAAY,QAAQ,KAAK,EAAE,SAAS,IACnD,QAAQ,KAAK,IACb;AAAA,IACN,aACE,OAAO,mBAAmB,YAC1B,eAAe,KAAK,EAAE,YAAY,MAAM,YACpC,YACA;AAAA,EACR;AACF;AA+CA,IAAM,uBAAuB,OAC3B,QACA,OACA,gBACqB;AACrB,MAAI,WAAW,QAAQ,WAAW,QAAW;AAC3C,WAAO;AAAA,EACT;AAEA,MAAI;AACF,UAAM,OAAO,SAAS;AAAA,MACpB,0BAA0B;AAAA,QACxB,QAAQ;AAAA,UACN,MAAM,qBAAqB,OAAO,aAAa,SAAS,IAAI;AAAA,QAC9D;AAAA,QACA,IAAI;AAAA,MACN;AAAA,IACF,CAAC;AAED,WAAO;AAAA,EACT,SAAS,OAAO;AACd,kBAAc,8BAA8B,EAAE,OAAO,cAAc,KAAK,EAAE,CAAC;AAE3E,WAAO;AAAA,EACT;AACF;AAMA,IAAM,YAAY,OAChB,MACA,SACA,eAC+B;AAC/B,QAAM,WAAW;AAAA,IACf,QAAQ,KAAK,eAAe;AAAA,IAC5B,WAAW,eAAe,KAAK,UAAU;AAAA,EAC3C;AAEA,QAAM,CAAC,QAAQ,eAAe,IAAI,MAAM,QAAQ,IAAI;AAAA,IAClD,KAAK,MAAM,UAAU;AAAA,IACrB,KAAK,MAAM,eAAe;AAAA,EAC5B,CAAC;AAED,QAAM,EAAE,OAAO,WAAW,IAAI,oBAAoB;AAAA,IAChD;AAAA,IACA;AAAA,IACA;AAAA,IACA,YAAY;AAAA,IACZ,aAAa,KAAK;AAAA,IAClB,KAAK,KAAK;AAAA,EACZ,CAAC;AAED,MAAI,eAAe,MAAM;AACvB,UAAM,KAAK,MAAM,WAAW,UAAU;AAAA,EACxC;AAEA,QAAM,KAAK,MAAM,aAAa,KAAK;AAMnC,QAAM,cACJ,KAAK,gBAAgB,QAAQ,KAAK,gBAAgB,SAC9C,OACA,MAAM,mBAAmB;AAAA,IACvB,OAAO,KAAK;AAAA;AAAA;AAAA;AAAA,IAIZ,MAAM,qBAAqB,KAAK,UAAU;AAAA,IAC1C,UACE,YAAY,QAAQ,QAAQ,SAAS,cACjC,QAAQ,SAAS,mBACjB;AAAA,IACN,MAAM,YAAY,QAAQ,QAAQ,SAAS;AAAA;AAAA;AAAA,IAG3C,UAAU,MAAM,SAAS;AAAA,IACzB,KAAK,KAAK;AAAA,EACZ,CAAC;AAMP,gBAAc,oBAAoB;AAAA,IAChC,GAAG,wBAAwB,KAAK;AAAA,IAChC,mBAAmB;AAAA,IACnB,GAAI,gBAAgB,OAAO,CAAC,IAAI,oBAAoB,WAAW;AAAA,EACjE,CAAC;AAED,QAAM,qBAAqB,KAAK,QAAQ,OAAO,WAAW;AAE1D,SAAO;AAAA,IACL;AAAA,IACA,QAAQ,wBAAwB,KAAK;AAAA,IACrC;AAAA,IACA;AAAA,EACF;AACF;AAEA,IAAM,eAAe,OACnB,MACA,cAC2C;AAC3C,MAAI,KAAK,eAAe,MAAM;AAC5B,WAAO;AAAA,EACT;AAEA,MAAI;AACF,WAAO,MAAM,KAAK,UAAU,SAAS;AAAA,MACnC,KAAK,KAAK;AAAA,MACV,mBAAmB,WAAW,eAAe;AAAA,MAC7C,SAAS;AAAA,IACX,CAAC;AAAA,EACH,SAAS,OAAO;AAOd,WAAO;AAAA,MACL,MAAM;AAAA,MACN,QAAQ,iBAAiB,cAAc,KAAK,GAAG,KAAK,UAAU;AAAA,IAChE;AAAA,EACF;AACF;AAEA,IAAM,gBAAgB,OACpB,aACsC;AACtC,MAAI;AACF,WAAO,MAAM,SAAS,KAAK;AAAA,EAC7B,SAAS,OAAO;AACd,kBAAc,qCAAqC;AAAA,MACjD,OAAO,cAAc,KAAK;AAAA,IAC5B,CAAC;AAED,WAAO;AAAA,EACT;AACF;AA2BO,IAAM,oBAAoB,OAC/B,SAC+B;AAC/B,MAAI,KAAK,eAAe,MAAM;AAC5B,kBAAc,2BAA2B,EAAE,QAAQ,iBAAiB,CAAC;AAErE,WAAO,UAAU,MAAM,MAAM,eAAe;AAAA,EAC9C;AAEA,QAAM,YAAY,MAAM,cAAc,KAAK,QAAQ;AACnD,MAAI,aAA8C;AAElD,MAAI,cAAc,MAAM;AACtB,kBAAc,4BAA4B;AAAA,MACxC,QAAQ;AAAA,IACV,CAAC;AAAA,EACH,OAAO;AACL,UAAM,SAAS,MAAM,KAAK,UAAU,SAAS;AAAA,MAC3C,KAAK,KAAK;AAAA,MACV,mBAAmB,UAAU;AAAA,MAC7B,YAAY,UAAU;AAAA,IACxB,CAAC;AAED,QAAI,OAAO,SAAS,aAAa;AAC/B,mBAAa;AACb,YAAM,KAAK,MAAM,gBAAgB;AAAA,QAC/B,QAAQ;AAAA,QACR,IAAI,KAAK,IAAI,YAAY;AAAA,MAC3B,CAAC;AAAA,IACH,WAAW,OAAO,SAAS,4BAA4B;AACrD,mBAAa;AACb,YAAM,KAAK,MAAM,gBAAgB;AAAA,QAC/B,QAAQ;AAAA,QACR,IAAI,KAAK,IAAI,YAAY;AAAA,MAC3B,CAAC;AAAA,IACH,OAAO;AAKL,mBAAa;AACb,oBAAc,2BAA2B,EAAE,aAAa,OAAO,KAAK,CAAC;AAAA,IACvE;AAAA,EACF;AAEA,QAAM,UAAU,MAAM,aAAa,MAAM,SAAS;AAElD,SAAO,UAAU,MAAM,SAAS,UAAU;AAC5C;;;ACtXA,SAAS,yBAAyB;AAWlC,IAAMC,YAAW,CAAC,UAChB,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AAQ9D,IAAM,4BAA4B,CAAC,YAA+C;AACvF,MAAI,CAACA,UAAS,OAAO,GAAG;AACtB,WAAO;AAAA,EACT;AAEA,QAAM,YAAY,QAAQ,kBAAkB;AAE5C,MAAI,CAACA,UAAS,SAAS,GAAG;AACxB,WAAO;AAAA,EACT;AAEA,QAAM,KAAK,UAAU,IAAI;AAEzB,MAAI,OAAO,OAAO,YAAY,GAAG,WAAW,GAAG;AAC7C,WAAO;AAAA,EACT;AAEA,QAAM,cAAc,UAAU,aAAa;AAE3C,SAAO;AAAA,IACL,aAAa;AAAA,IACb,eACE,OAAO,gBAAgB,YAAY,YAAY,SAAS,IAAI,cAAc;AAAA,EAC9E;AACF;AAEO,IAAM,4BAAmD;AAAA,EAC9D,MAAM,YAAY;AAChB,QAAI;AACF,YAAM,SAAS,IAAI,kBAAkB;AACrC,YAAM,WAAY,MAAM,OAAO,MAAM;AAAA,QACnC,kBAAkB,EAAE,IAAI,MAAM,aAAa,KAAK;AAAA,MAClD,CAAC;AAED,YAAM,WAAW,0BAA0B,QAAQ;AAEnD,UAAI,aAAa,MAAM;AACrB,sBAAc,yCAAyC;AAAA,UACrD,MAAM;AAAA,QACR,CAAC;AAAA,MACH;AAEA,aAAO;AAAA,IACT,SAAS,OAAO;AACd,oBAAc,qCAAqC;AAAA,QACjD,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAED,aAAO;AAAA,IACT;AAAA,EACF;AACF;;;AlE1BA,IAAM,UAAU,OAAO,YAA4B;AACjD,QAAM,SAAS,IAAI,cAAc;AAEjC,QAAM,SAAS,MAAM,eAAe,EAAE,QAAQ,QAAQ,CAAC;AAEvD,QAAM,WAAW,MAAM,uBAAuB;AAAA,IAC5C;AAAA,IACA,OAAO;AAAA,IACP,KAAK,oBAAI,KAAK;AAAA,EAChB,CAAC;AAED,QAAM,cAAc,uBAAuB;AAC3C,QAAM,UAAU,MAAM,kBAAkB;AAAA,IACtC,WAAW,0BAA0B;AAAA,MACnC,SAAS,YAAY;AAAA,MACrB,aAAa,YAAY;AAAA,IAC3B,CAAC;AAAA,IACD,OAAO;AAAA;AAAA;AAAA,IAGP,aAAa;AAAA,IACb,UAAU;AAAA,IACV;AAAA,IACA,YAAY,YAAY;AAAA,IACxB,aAAa,YAAY;AAAA,IACzB,KAAK,oBAAI,KAAK;AAAA,EAChB,CAAC;AAED,SAAO;AAAA,IACL,GAAG;AAAA,IACH;AAAA,IACA,SAAS,EAAE,MAAM,QAAQ,MAAM,MAAM,QAAQ,QAAQ,MAAM,OAAO;AAAA,EACpE;AACF;AAEA,IAAO,sCAAQ,+BAA+B;AAAA,EAC5C,qBAAqB;AAAA,EACrB,MAAM;AAAA,EACN,aACE;AAAA;AAAA;AAAA;AAAA;AAAA,EAKF,gBAAgB;AAAA,EAChB,2BAA2B;AAAA,EAC3B,wBAAwB;AAAA,EACxB;AACF,CAAC;",
  "names": ["isRecord", "reject", "cacheAgeMs", "state", "s", "n", "e", "t", "t", "n", "r", "e", "t", "n", "configId", "isRecord", "isRecord", "cacheAgeMs", "b", "subtle", "isRecord"]
}
