{
  "version": 3,
  "sources": ["../../../../node_modules/@sniptt/guards/lib/guards/primitives.ts", "../../../../node_modules/@sniptt/guards/lib/guards/structural.ts", "../../../../node_modules/@sniptt/guards/lib/guards/convenience.ts", "../../../../node_modules/@sniptt/guards/lib/index.ts", "../../../../src/logic-functions/score-person-updated.logic-function.ts", "twenty-sdk-define-stub:__twenty-sdk-define-stub__", "../../../../src/constants/logic-function-identifiers.ts", "../../../../src/calibration/seal.ts", "../../../../src/logic-functions/licence-cache-seal.ts", "../../../../node_modules/twenty-shared/dist/is-record-object-schema-CwzshFdt.mjs", "../../../../node_modules/twenty-shared/dist/logic-function.mjs", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/errors/app-connection-auth-failed.error.ts", "../../../../node_modules/twenty-shared/dist/FieldMetadataType-PppCGM82.mjs", "../../../../node_modules/twenty-shared/dist/get-system-view-universal-identifier.util-CJoglbKX.mjs", "../../../../node_modules/twenty-shared/dist/application.mjs", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/utils/post-graphql-request.util.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/get-connection.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/list-connections.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/connections/find-connection-for-request.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/agents/run-agent.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/jobs/enqueue-job.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/key-value/kv.ts", "../../../../node_modules/twenty-sdk/src/sdk/logic-function/response.ts", "../../../../src/constants/licence-identifiers.ts", "../../../../src/logic-functions/greenlight-api.ts", "../../../../src/logic-functions/licence-cache-store.ts", "../../../../src/licensing/cache.ts", "../../../../src/calibration/canonical.ts", "../../../../src/calibration/state.ts", "../../../../src/calibration/refresh.ts", "../../../../src/enrichment/field-specs.ts", "../../../../src/scoring/defaults.ts", "../../../../src/scoring/field-access.ts", "../../../../src/scoring/rules/company-identified.rule.ts", "../../../../src/scoring/rules/compliance-opt-out.rule.ts", "../../../../src/scoring/rules/helpers.ts", "../../../../src/scoring/rules/contact-decision-maker.rule.ts", "../../../../src/scoring/rules/contact-email-valid.rule.ts", "../../../../src/scoring/rules/contact-named-person.rule.ts", "../../../../src/scoring/rules/contact-phone-valid.rule.ts", "../../../../src/scoring/rules/contact-shared-inbox.rule.ts", "../../../../src/scoring/rules/data-freshness.rule.ts", "../../../../src/scoring/rules/icp-company-size.rule.ts", "../../../../src/scoring/rules/icp-industry.rule.ts", "../../../../src/scoring/rules/icp-region.rule.ts", "../../../../src/scoring/rules/index.ts", "../../../../src/scoring/types.ts", "../../../../src/scoring/config.ts", "../../../../src/calibration/apply.ts", "../../../../src/logic-functions/licence-run.ts", "../../../../src/logic-functions/release-marker-store.ts", "../../../../src/scoring/engine.ts", "../../../../src/gate/release-decision.ts", "../../../../src/gate/suppression-decision.ts", "../../../../src/logic-functions/greenlight-config-record.ts", "../../../../src/logic-functions/scoring-run.ts"],
  "sourcesContent": [null, null, null, null, "import { CoreApiClient } from 'twenty-client-sdk/core';\nimport { defineLogicFunction } from 'twenty-sdk/define';\n\nimport { SCORE_PERSON_UPDATED_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER } from 'src/constants/logic-function-identifiers';\nimport { createLicenceKeySeal } from 'src/logic-functions/licence-cache-seal';\nimport { kvCalibrationReader } from 'src/logic-functions/licence-cache-store';\nimport { readLicenceEnvironment } from 'src/logic-functions/licence-run';\nimport { kvReleaseMarkerStore } from 'src/logic-functions/release-marker-store';\nimport {\n  runPersonScoring,\n  SCORING_TRIGGER_PERSON_FIELDS,\n} from 'src/logic-functions/scoring-run';\n\n/**\n * Re-score a Person when something that can move the score changes.\n *\n * ## The retrigger guard\n *\n * This is the registration that could loop. Writing `greenlightScore` back emits\n * `person.updated`, which is this very trigger.\n *\n * `updatedFields` is the fix, and it is the platform that enforces it: per\n * https://docs.twenty.com/developers/extend/apps/logic/logic-functions.md,\n * \"when the event operation is `updated`, specific fields to listen to can be\n * specified in the `updatedFields` array. If left undefined or empty, any update\n * will trigger the function.\" The list below is an allow-list of *scoring\n * inputs*; `greenlightScore`, `greenlightDecision` and `greenlightTrace` are\n * absent from it, so an update that only touches those three is never dispatched\n * here. Leaving the array off \u2014 which is the tempting default \u2014 is precisely the\n * bug: it would make every write-back a new event.\n *\n * `runPersonScoring` carries two further guards behind this one (an\n * authored-write check on `event.properties.updatedFields`, and an\n * outcome-fingerprint comparison that makes a redundant run write nothing). See\n * the module comment in `scoring-run.ts` for why three layers rather than one.\n *\n * ## The override contract\n *\n * This is also the registration that can undo a human release: a rep releases a\n * gated lead, then edits `jobTitle`, and the re-score re-gates it. The marker\n * store below is how the run sees the release \u2014 see `pinReleasedDecision` in\n * `scoring-run.ts`.\n */\nconst handler = async (event: unknown) =>\n  runPersonScoring({\n    client: new CoreApiClient(),\n    event,\n    now: new Date(),\n    markers: kvReleaseMarkerStore,\n    calibration: kvCalibrationReader,\n    calibrationSeal: createLicenceKeySeal(readLicenceEnvironment().licenceKey),\n  });\n\nexport default defineLogicFunction({\n  universalIdentifier: SCORE_PERSON_UPDATED_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER,\n  name: 'greenlight-score-person-updated',\n  description:\n    'Re-scores a Person when a scoring input changes. Never fires on Greenlight\u2019s own write-back.',\n  // Same budget and same reasoning as the create registration.\n  timeoutSeconds: 10,\n  handler,\n  databaseEventTriggerSettings: {\n    eventName: 'person.updated',\n    updatedFields: [...SCORING_TRIGGER_PERSON_FIELDS],\n  },\n});\n", "\n// Auto-generated stub for twenty-sdk/define injected by the SDK CLI build.\n// Real implementations would pull in zod, twenty-shared and ~1MB of code; at\n// runtime only `default.config.handler` is consumed, so tiny no-ops suffice.\nconst __defineFactoryStub = (config) => ({\n  success: true,\n  config,\n  errors: [],\n});\n\nconst __anyHandler = {\n  get(_target, prop) {\n    if (prop === '__esModule') return true;\n    if (prop === Symbol.toPrimitive) return () => '';\n    if (typeof prop === 'symbol') return undefined;\n    return new Proxy(() => undefined, __anyHandler);\n  },\n  apply() {\n    return new Proxy(() => undefined, __anyHandler);\n  },\n};\nconst __anyStub = new Proxy(() => undefined, __anyHandler);\n\nexport const createValidationResult = __defineFactoryStub;\nexport const defineAgent = __defineFactoryStub;\nexport const defineApplication = __defineFactoryStub;\nexport const defineApplicationRole = __defineFactoryStub;\nexport const defineCommandMenuItem = __defineFactoryStub;\nexport const defineConnectionProvider = __defineFactoryStub;\nexport const defineField = __defineFactoryStub;\nexport const defineFrontComponent = __defineFactoryStub;\nexport const defineIndex = __defineFactoryStub;\nexport const defineLogicFunction = __defineFactoryStub;\nexport const defineNavigationMenuItem = __defineFactoryStub;\nexport const defineObject = __defineFactoryStub;\nexport const definePageLayout = __defineFactoryStub;\nexport const definePageLayoutTab = __defineFactoryStub;\nexport const definePermissionFlag = __defineFactoryStub;\nexport const definePostInstallLogicFunction = __defineFactoryStub;\nexport const definePreInstallLogicFunction = __defineFactoryStub;\nexport const defineRole = __defineFactoryStub;\nexport const defineSettingsFrontComponent = __defineFactoryStub;\nexport const defineSkill = __defineFactoryStub;\nexport const defineUninstallLogicFunction = __defineFactoryStub;\nexport const defineView = __defineFactoryStub;\nexport const defineViewField = __defineFactoryStub;\nexport const AggregateOperations = __anyStub;\nexport const DateDisplayFormat = __anyStub;\nexport const FieldMetadataSettingsOnClickAction = __anyStub;\nexport const FieldType = __anyStub;\nexport const HTTPMethod = __anyStub;\nexport const NavigationMenuItemType = __anyStub;\nexport const NumberDataType = __anyStub;\nexport const ObjectRecordGroupByDateGranularity = __anyStub;\nexport const OnDeleteAction = __anyStub;\nexport const PageLayoutTabLayoutMode = __anyStub;\nexport const PageLayoutType = __anyStub;\nexport const RelationType = __anyStub;\nexport const RowLevelPermissionPredicateGroupLogicalOperator = __anyStub;\nexport const RowLevelPermissionPredicateOperand = __anyStub;\nexport const STANDARD_OBJECT = __anyStub;\nexport const STANDARD_OBJECT_UNIVERSAL_IDENTIFIERS = __anyStub;\nexport const STANDARD_PAGE_LAYOUT = __anyStub;\nexport const STANDARD_PAGE_LAYOUT_UNIVERSAL_IDENTIFIERS = __anyStub;\nexport const SystemPermissionFlag = __anyStub;\nexport const ViewCalendarLayout = __anyStub;\nexport const ViewFilterGroupLogicalOperator = __anyStub;\nexport const ViewFilterOperand = __anyStub;\nexport const ViewKey = __anyStub;\nexport const ViewOpenRecordIn = __anyStub;\nexport const ViewSortDirection = __anyStub;\nexport const ViewType = __anyStub;\nexport const ViewVisibility = __anyStub;\nexport const canAccessFullAdminPanel = __anyStub;\nexport const canImpersonate = __anyStub;\nexport const every = __anyStub;\nexport const everyDefined = __anyStub;\nexport const everyEquals = __anyStub;\nexport const favoriteRecordIds = __anyStub;\nexport const featureFlags = __anyStub;\nexport const getFieldUniversalIdentifier = __anyStub;\nexport const getSystemRelationFieldUniversalIdentifier = __anyStub;\nexport const getSystemViewFieldUniversalIdentifier = __anyStub;\nexport const getSystemViewUniversalIdentifier = __anyStub;\nexport const hasAnySoftDeleteFilterOnView = __anyStub;\nexport const includes = __anyStub;\nexport const includesEvery = __anyStub;\nexport const isDashboardPageLayoutInEditMode = __anyStub;\nexport const isDefined = __anyStub;\nexport const isInSidePanel = __anyStub;\nexport const isLayoutCustomizationModeEnabled = __anyStub;\nexport const isNonEmptyString = __anyStub;\nexport const isSelectAll = __anyStub;\nexport const none = __anyStub;\nexport const noneDefined = __anyStub;\nexport const noneEquals = __anyStub;\nexport const numberOfSelectedRecords = __anyStub;\nexport const objectMetadataItem = __anyStub;\nexport const objectMetadataLabel = __anyStub;\nexport const objectPermissions = __anyStub;\nexport const pageType = __anyStub;\nexport const selectedRecords = __anyStub;\nexport const some = __anyStub;\nexport const someDefined = __anyStub;\nexport const someEquals = __anyStub;\nexport const someNonEmptyString = __anyStub;\nexport const targetObjectReadPermissions = __anyStub;\nexport const targetObjectWritePermissions = __anyStub;\nexport const validateFields = __anyStub;\n", "/**\n * Permanent identifiers for Greenlight's logic functions.\n *\n * Same permanence rule as `universal-identifiers.ts`: a logic function's\n * `universalIdentifier` is how Twenty recognises an existing registration across\n * upgrades. Change one and the workspace gets a *second* function registered\n * alongside the old one \u2014 for a database-event trigger that means every Person\n * event is handled twice, and every scored lead gets two audit rows. Never edit\n * a value in this file. Adding is fine.\n *\n * These live apart from `universal-identifiers.ts` purely so two workstreams can\n * add entities without fighting over the same file.\n */\n\nexport const POST_INSTALL_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'feb529fe-4048-49cd-a304-bef009952699';\n\nexport const UNINSTALL_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  '4219d61c-c663-44d3-9978-758f89862ece';\n\n/**\n * Scoring is registered twice because `databaseEventTriggerSettings.eventName`\n * is a single string, not a list \u2014 see `score-person-created.logic-function.ts`\n * for why two narrow registrations beat one `person.*` wildcard.\n */\nexport const SCORE_PERSON_CREATED_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  '03736f42-ea80-4de7-9ae1-1264cc1adad0';\n\nexport const SCORE_PERSON_UPDATED_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'f3d817a4-806b-488a-9707-1988c58acee7';\n", "/**\n * Binding a cached calibration to the licence key that fetched it.\n *\n * ===========================================================================\n * ## What this is for, stated without decoration\n *\n * The calibration payload spends most of its life at rest in the workspace's own\n * key-value storage. The Ed25519 signature in `verify.ts` proves who *authored*\n * it, and is checked once, when it arrives. This adds a second, different\n * property to the copy that is kept: the cache is sealed with a secret derived\n * from the licence key, and a cache whose seal does not verify under the\n * currently-configured key is refused.\n *\n * **It does buy:** a calibration cache lifted out of a licensed workspace and\n * dropped into an unlicensed one is rejected. The unlicensed install has no key,\n * so it cannot produce a matching tag, and it falls back to shipped defaults.\n * The same applies to a workspace whose licence key has been changed or removed.\n * It is also tamper-evidence: an edited cache entry no longer verifies.\n *\n * **It does not buy:** protection against someone who *holds* a valid licence\n * key. They have the secret; they can seal whatever they like. Nothing that runs\n * entirely inside the customer's own infrastructure can prevent that, and a\n * comment claiming otherwise would be a comfortable story rather than a\n * security property. The signature is the control that survives a hostile\n * licence holder \u2014 they can forge a cache, but they cannot forge a payload that\n * verifies against the embedded public key, so they cannot manufacture a\n * *newer* calibration than the one they were sold.\n *\n * **It is licence-binding and tamper-evidence. It is not authenticity of\n * origin.** Those are different properties and this file provides the first two.\n *\n * ## Why a port rather than the key\n *\n * `src/licensing/types.ts` records a structural guarantee: no type in the\n * licensing core has a `key` field, so there is no variable in the core that\n * *could* leak one. Calibration keeps that guarantee by never receiving key\n * material either. The seal arrives as two functions, implemented at the edge in\n * `src/logic-functions/licence-cache-seal.ts`, which is the only place besides\n * the HTTP adapter that touches the raw key.\n *\n * The consequence worth noting: a `null` implementation \u2014 no licence key\n * configured \u2014 cannot seal and cannot verify, so an unlicensed workspace can\n * never present an acceptable cache. That is the correct direction of failure,\n * and it falls out of the port's shape rather than out of a check somebody has\n * to remember to write.\n * ===========================================================================\n */\n\n/**\n * Seal and verification over the canonical form of a cache entry.\n *\n * `seal` returns `null` when it cannot produce a tag \u2014 no key, or a runtime with\n * no HMAC. The caller then declines to cache at all rather than storing an\n * unsealed entry, because an entry that can be read back without a tag check is\n * exactly the entry this whole file exists to refuse.\n */\nexport interface CalibrationSealPort {\n  seal(canonical: string): Promise<string | null>;\n  verify(canonical: string, tag: string): Promise<boolean>;\n}\n\n/**\n * The seal for a workspace with no licence key: seals nothing, accepts nothing.\n *\n * Used as the default so that a caller which forgets to wire a real seal gets\n * \"no calibration\" rather than \"calibration with no integrity check\". Failing\n * closed on the *cache* is safe precisely because failing closed there means\n * falling back to the shipped defaults, which is a fully working product.\n */\nexport const NO_SEAL: CalibrationSealPort = {\n  seal: async () => null,\n  verify: async () => false,\n};\n", "/**\n * The real calibration cache seal: HMAC-SHA256 under a secret derived from the\n * licence key.\n *\n * This is one of only two modules in Greenlight that touch the raw licence key \u2014\n * the other is the HTTP adapter, which puts it in a request body. Everything\n * else works with a mask or with the ports declared in `src/licensing/types.ts`.\n * That is a structural guarantee rather than a discipline, and this file is\n * written to keep it: the key enters through the factory argument, is\n * immediately turned into a derived secret, and is never stored, returned,\n * logged or included in any error.\n *\n * ---------------------------------------------------------------------------\n * ## Why the key is not used as the HMAC secret directly\n *\n * It would work, and it would be a needless second use of the same secret for a\n * second purpose. The derivation is one HMAC with a fixed, versioned label, so\n * the cache secret and the credential are cryptographically separated: an\n * adversary who somehow recovered the cache secret has not recovered the licence\n * key, and could not present it to the licensing service.\n *\n * The label carries a version. Changing it invalidates every existing seal at\n * once, which is the intended lever if the sealed form ever has to change: every\n * workspace falls back to shipped defaults for one night and re-fetches. That is\n * a safe migration precisely because falling back is not a failure.\n *\n * ## Why WebCrypto\n *\n * Same reason as `src/calibration/verify.ts`: `crypto.subtle` is a global, so\n * nothing here depends on how the logic-function bundler treats Node built-ins.\n * A bundler that stubbed `node:crypto` would have silently turned the seal into\n * a no-op; a missing global cannot, because the absence is checked and produces\n * \"no seal\", which refuses every cache.\n * ---------------------------------------------------------------------------\n */\n\nimport { type CalibrationSealPort, NO_SEAL } from 'src/calibration/seal';\n\n/**\n * Domain-separation label. Versioned so the sealed form can be changed by\n * changing this string, with a one-night fall-back to shipped defaults as the\n * entire migration cost.\n */\nconst SEAL_LABEL = 'greenlight.calibration.cache.v1';\n\nconst subtle = (): SubtleCrypto | null => {\n  const candidate = (globalThis as { crypto?: { subtle?: SubtleCrypto } }).crypto\n    ?.subtle;\n\n  return candidate === undefined ? null : candidate;\n};\n\nconst toBase64 = (bytes: Uint8Array): string => {\n  let binary = '';\n\n  for (const byte of bytes) {\n    binary += String.fromCharCode(byte);\n  }\n\n  return btoa(binary);\n};\n\n/**\n * Constant-time comparison of two base64 tags.\n *\n * The timing channel here is not a realistic attack \u2014 the attacker would need\n * to be inside the customer's own infrastructure, at which point they can read\n * the cache directly \u2014 but an early-exit string compare in code that checks a\n * MAC is the kind of thing that gets copied somewhere it does matter.\n */\nconst equalTags = (left: string, right: string): boolean => {\n  if (left.length !== right.length) {\n    return false;\n  }\n\n  let difference = 0;\n\n  for (let index = 0; index < left.length; index += 1) {\n    difference |= left.charCodeAt(index) ^ right.charCodeAt(index);\n  }\n\n  return difference === 0;\n};\n\n/**\n * Build a seal for a given licence key.\n *\n * A `null` or blank key yields `NO_SEAL`, which seals nothing and accepts\n * nothing \u2014 so an unlicensed workspace cannot present a cache, and cannot\n * accidentally be given one.\n */\nexport const createLicenceKeySeal = (\n  licenceKey: string | null,\n): CalibrationSealPort => {\n  if (typeof licenceKey !== 'string' || licenceKey.trim().length === 0) {\n    return NO_SEAL;\n  }\n\n  const key = licenceKey.trim();\n\n  // Derived once per seal, held in this closure and nowhere else. The raw key\n  // is not captured beyond this line.\n  let cachedSecret: CryptoKey | null = null;\n\n  const secret = async (crypto: SubtleCrypto): Promise<CryptoKey> => {\n    if (cachedSecret !== null) {\n      return cachedSecret;\n    }\n\n    const encoder = new TextEncoder();\n\n    const keyMaterial = await crypto.importKey(\n      'raw',\n      encoder.encode(key) as unknown as BufferSource,\n      { name: 'HMAC', hash: 'SHA-256' },\n      false,\n      ['sign'],\n    );\n\n    const derived = await crypto.sign(\n      'HMAC',\n      keyMaterial,\n      encoder.encode(SEAL_LABEL) as unknown as BufferSource,\n    );\n\n    cachedSecret = await crypto.importKey(\n      'raw',\n      derived,\n      { name: 'HMAC', hash: 'SHA-256' },\n      false,\n      ['sign'],\n    );\n\n    return cachedSecret;\n  };\n\n  const tag = async (canonical: string): Promise<string | null> => {\n    const crypto = subtle();\n\n    if (crypto === null) {\n      return null;\n    }\n\n    try {\n      const signature = await crypto.sign(\n        'HMAC',\n        await secret(crypto),\n        new TextEncoder().encode(canonical) as unknown as BufferSource,\n      );\n\n      return toBase64(new Uint8Array(signature));\n    } catch {\n      // Deliberately no detail. Anything derived from a failure while handling\n      // key material is a string this codebase has promised never to produce.\n      return null;\n    }\n  };\n\n  return {\n    seal: tag,\n    verify: async (canonical, expected) => {\n      const computed = await tag(canonical);\n\n      return computed !== null && equalTags(computed, expected);\n    },\n  };\n};\n", "import { isNonEmptyString as e } from \"@sniptt/guards\";\n//#region src/logic-function/is-record-object-schema.ts\nvar t = (t) => (t?.type === \"record\" || t?.type === \"object\") && e(t.objectUniversalIdentifier);\n//#endregion\nexport { t };\n", "import { t as e } from \"./isDefined-Dtu5EYqP.mjs\";\nimport { t } from \"./is-record-object-schema-CwzshFdt.mjs\";\nimport { isNonEmptyString as n, isObject as r } from \"@sniptt/guards\";\n//#region src/logic-function/build-tool-input-json-schema.ts\nvar i = (e, t) => {\n\tlet r = n(e) ? t?.(e) : void 0;\n\treturn `Id of the ${n(r) ? r : \"linked\"} record`;\n}, a = (n, o) => {\n\tif (t(n)) return {\n\t\ttype: \"string\",\n\t\tdescription: i(n.objectUniversalIdentifier, o)\n\t};\n\tif (n.type === \"records\") return {\n\t\ttype: \"array\",\n\t\titems: {\n\t\t\ttype: \"string\",\n\t\t\tdescription: i(n.objectUniversalIdentifier, o)\n\t\t}\n\t};\n\tlet { objectUniversalIdentifier: s, multiline: c, label: l, items: u, properties: d, additionalProperties: f, ...p } = n, m = { ...p };\n\treturn e(u) && (m.items = a(u, o)), e(d) && (m.properties = Object.fromEntries(Object.entries(d).map(([e, t]) => [e, a(t, o)]))), e(f) && (m.additionalProperties = r(f) ? a(f, o) : f), m;\n}, o = {\n\ttype: \"object\",\n\tproperties: {}\n}, s = (e) => {\n\tlet t = { type: \"unknown\" };\n\tswitch (e.type) {\n\t\tcase \"string\":\n\t\t\tt.type = \"string\";\n\t\t\tbreak;\n\t\tcase \"number\":\n\t\tcase \"integer\":\n\t\t\tt.type = \"number\";\n\t\t\tbreak;\n\t\tcase \"boolean\":\n\t\t\tt.type = \"boolean\";\n\t\t\tbreak;\n\t\tcase \"array\":\n\t\t\tt.type = \"array\", e.items && (t.items = s(e.items));\n\t\t\tbreak;\n\t\tcase \"object\":\n\t\t\tt.type = \"object\", e.properties && (t.properties = Object.fromEntries(Object.entries(e.properties).map(([e, t]) => [e, s(t)])));\n\t\t\tbreak;\n\t\tcase \"record\":\n\t\t\tt.type = \"record\";\n\t\t\tbreak;\n\t\tcase \"records\":\n\t\t\tt.type = \"records\";\n\t\t\tbreak;\n\t\tdefault: t.type = \"unknown\";\n\t}\n\treturn Array.isArray(e.enum) && (t.enum = e.enum.filter((e) => typeof e == \"string\")), e.multiline === !0 && (t.multiline = !0), n(e.label) && (t.label = e.label), n(e.objectUniversalIdentifier) && (t.objectUniversalIdentifier = e.objectUniversalIdentifier), t;\n}, c = (e) => [s(e)], l = { inputSchema: c({\n\ttype: \"object\",\n\tproperties: {\n\t\ta: { type: \"string\" },\n\t\tb: { type: \"number\" }\n\t}\n}) }, u = async (t) => {\n\tlet { getFunctionInputSchema: n } = await import(\"./get-function-input-schema-GNk3NRLJ.mjs\"), r = n(t)[0];\n\treturn r?.type === \"object\" && e(r.properties) ? {\n\t\ttype: \"object\",\n\t\tproperties: r.properties\n\t} : o;\n}, d = (t) => !e(t) || t === null ? \"unknown\" : typeof t == \"string\" ? \"string\" : typeof t == \"number\" ? \"number\" : typeof t == \"boolean\" ? \"boolean\" : Array.isArray(t) ? \"array\" : \"unknown\", f = (e) => e ? Object.entries(e).reduce((e, [t, n]) => (r(n) && !Array.isArray(n) ? e[t] = {\n\tisLeaf: !1,\n\ttype: \"object\",\n\tlabel: t,\n\tvalue: f(n)\n} : e[t] = {\n\tisLeaf: !0,\n\tvalue: n,\n\ttype: d(n),\n\tlabel: t\n}, e), {}) : {}, p = (e, t) => e ? `${e}.${t}` : t, m = (t, n, r = \"\") => {\n\tlet i = [];\n\tfor (let [a, o] of Object.entries(n)) {\n\t\tlet n = p(r, a), s = t[a];\n\t\tif (!e(s)) {\n\t\t\ti.push(`Missing key \"${n}\" in declared output schema.`);\n\t\t\tcontinue;\n\t\t}\n\t\tif (o.isLeaf !== s.isLeaf) {\n\t\t\ti.push(`Type mismatch at \"${n}\": expected ${o.isLeaf ? o.type : \"object\"} but declared ${s.isLeaf ? s.type : \"object\"}.`);\n\t\t\tcontinue;\n\t\t}\n\t\tif (!o.isLeaf && !s.isLeaf) {\n\t\t\ti.push(...m(s.value, o.value, n));\n\t\t\tcontinue;\n\t\t}\n\t\to.isLeaf && s.isLeaf && o.type !== \"unknown\" && s.type !== \"unknown\" && o.type !== s.type && i.push(`Type mismatch at \"${n}\": expected ${o.type} but declared ${s.type}.`);\n\t}\n\treturn i;\n}, h = [\n\t\"string\",\n\t\"number\",\n\t\"boolean\",\n\t\"array\",\n\t\"unknown\"\n], g = (e) => h.includes(e), _ = (e, t) => {\n\tlet n = t.label ?? e;\n\treturn t.type === \"record\" ? {\n\t\tisLeaf: !0,\n\t\ttype: \"string\",\n\t\tlabel: n,\n\t\tvalue: null\n\t} : t.type === \"records\" ? {\n\t\tisLeaf: !0,\n\t\ttype: \"array\",\n\t\tlabel: n,\n\t\tvalue: null\n\t} : t.type === \"object\" ? {\n\t\tisLeaf: !1,\n\t\ttype: \"object\",\n\t\tlabel: n,\n\t\tvalue: r(t.properties) ? v(t.properties) : {}\n\t} : {\n\t\tisLeaf: !0,\n\t\ttype: g(t.type) ? t.type : \"unknown\",\n\t\tlabel: n,\n\t\tvalue: null\n\t};\n}, v = (e) => Object.entries(e).reduce((e, [t, n]) => (e[t] = _(t, n), e), {}), y = (e) => {\n\tlet t = e[0];\n\treturn t?.type !== \"object\" || !r(t.properties) ? {} : v(t.properties);\n}, b = (e) => e?.type === \"records\" && n(e.objectUniversalIdentifier) || e?.type === \"array\" && t(e?.items);\n//#endregion\nexport { o as DEFAULT_TOOL_INPUT_SCHEMA, l as SEED_WORKFLOW_ACTION_TRIGGER_SETTINGS, a as buildToolInputJsonSchema, u as getInputSchemaFromSourceCode, f as getOutputSchemaFromValue, m as getOutputSchemaMismatchIssues, y as inputSchemaToOutputSchema, b as isRecordArraySchema, t as isRecordObjectSchema, c as jsonSchemaToInputSchema };\n", "// Thrown when the platform asks the SDK to operate on a connection whose\n// OAuth refresh failed permanently (`authFailedAt` is set). The end user\n// must reconnect from the app's settings tab — the app cannot recover on\n// its own.\n//\n// `listConnections` filters these out by default (the user can't act on\n// them anyway). `getConnection` throws this when the looked-up connection\n// is in this state, so a stored connection id can be safely retried until\n// it works again.\nexport class AppConnectionAuthFailedError extends Error {\n  readonly connectionId: string;\n\n  constructor(connectionId: string) {\n    super(\n      `App connection ${connectionId} requires the user to reconnect ` +\n        `(authFailedAt is set). Surface a \"Reconnect\" prompt in your UI.`,\n    );\n    this.name = 'AppConnectionAuthFailedError';\n    this.connectionId = connectionId;\n  }\n}\n", "//#region src/types/FieldMetadataType.ts\nvar e = /* @__PURE__ */ function(e) {\n\treturn e.ACTOR = \"ACTOR\", e.ADDRESS = \"ADDRESS\", e.ARRAY = \"ARRAY\", e.BOOLEAN = \"BOOLEAN\", e.CURRENCY = \"CURRENCY\", e.DATE = \"DATE\", e.DATE_TIME = \"DATE_TIME\", e.EMAILS = \"EMAILS\", e.FILES = \"FILES\", e.FULL_NAME = \"FULL_NAME\", e.LINKS = \"LINKS\", e.MORPH_RELATION = \"MORPH_RELATION\", e.MULTI_SELECT = \"MULTI_SELECT\", e.NUMBER = \"NUMBER\", e.NUMERIC = \"NUMERIC\", e.PHONES = \"PHONES\", e.POSITION = \"POSITION\", e.RATING = \"RATING\", e.RAW_JSON = \"RAW_JSON\", e.RELATION = \"RELATION\", e.RICH_TEXT = \"RICH_TEXT\", e.SELECT = \"SELECT\", e.TEXT = \"TEXT\", e.TS_VECTOR = \"TS_VECTOR\", e.UUID = \"UUID\", e;\n}({});\n//#endregion\nexport { e as t };\n", "import { v5 as e } from \"uuid\";\n//#region src/application/constants/TwentyStandardApplicationUniversalIdentifier.ts\nvar t = \"20202020-64aa-4b6f-b003-9c74b97cee20\", n = ({ entityNamespace: t, value: n, applicationUniversalIdentifier: r }) => e(`${t}:${n}`, r), r = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: t, name: r }) => n({\n\tentityNamespace: \"fieldMetadata\",\n\tvalue: `${t}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), i = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: t, relationTargetObjectUniversalIdentifier: r }) => n({\n\tentityNamespace: \"fieldMetadata\",\n\tvalue: `${t}:systemRelation:${r}`,\n\tapplicationUniversalIdentifier: e\n}), a = ({ fieldMetadataApplicationUniversalIdentifier: e, viewUniversalIdentifier: t, fieldMetadataUniversalIdentifier: r }) => n({\n\tentityNamespace: \"viewField\",\n\tvalue: `${t}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), o = ({ objectMetadataApplicationUniversalIdentifier: e, objectUniversalIdentifier: t, viewKey: r }) => n({\n\tentityNamespace: \"view\",\n\tvalue: `${t}:${r}`,\n\tapplicationUniversalIdentifier: e\n});\n//#endregion\nexport { n as a, r as i, a as n, t as o, i as r, o as t };\n", "import { t as e } from \"./FieldMetadataType-PppCGM82.mjs\";\nimport { a as t, i as n, n as r, o as i, r as a, t as o } from \"./get-system-view-universal-identifier.util-CJoglbKX.mjs\";\n//#region src/application/applicationCategoryType.ts\nvar s = [\n\t\"Communication\",\n\t\"Productivity\",\n\t\"Product management\",\n\t\"Sales\",\n\t\"Marketing\",\n\t\"Enrichment\",\n\t\"Data\",\n\t\"Search\",\n\t\"Other\"\n], c = (e) => s.includes(e), l = [\n\te.TEXT,\n\te.ARRAY,\n\te.BOOLEAN,\n\te.DATE,\n\te.DATE_TIME,\n\te.NUMBER,\n\te.NUMERIC,\n\te.RAW_JSON,\n\te.RICH_TEXT,\n\te.SELECT,\n\te.MULTI_SELECT\n], u = \"public\", d = \"TWENTY_API_KEY\", f = \"TWENTY_API_URL\", p = \"TWENTY_APP_ACCESS_TOKEN\", m = \"TWENTY_FUNCTIONS_URL\", h = \"generated\", g = { js: \"import { createRequire as __createRequire } from 'module';\\nconst require = __createRequire(import.meta.url);\" }, _ = \".twenty/output\", v = \"Standard\", y = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"agent\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), b = ({ applicationUniversalIdentifier: e, key: n }) => t({\n\tentityNamespace: \"applicationVariable\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), x = \"navigation\", S = ({ applicationUniversalIdentifier: e, engineComponentKey: n }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `GLOBAL:${n}`,\n\tapplicationUniversalIdentifier: e\n}), C = ({ applicationUniversalIdentifier: e, engineComponentKey: n }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `GLOBAL_OBJECT_CONTEXT:${n}`,\n\tapplicationUniversalIdentifier: e\n}), w = ({ applicationUniversalIdentifier: e, engineComponentKey: n, objectUniversalIdentifier: r }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `RECORD_SELECTION:${n}:${r ?? \"\"}`,\n\tapplicationUniversalIdentifier: e\n}), T = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n }) => t({\n\tentityNamespace: \"commandMenuItem\",\n\tvalue: `${n}:${x}`,\n\tapplicationUniversalIdentifier: e\n}), E = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"connectionProvider\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), D = ({ applicationUniversalIdentifier: e, roleUniversalIdentifier: n, fieldUniversalIdentifier: r }) => t({\n\tentityNamespace: \"fieldPermission\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), O = ({ applicationUniversalIdentifier: e, pageLayoutWidgetUniversalIdentifier: n }) => t({\n\tentityNamespace: \"view\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), k = ({ applicationUniversalIdentifier: e, componentName: n }) => t({\n\tentityNamespace: \"frontComponent\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), A = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"index\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), j = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"logicFunction\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), ee = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `FOLDER:${n}`,\n\tapplicationUniversalIdentifier: e\n}), M = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `OBJECT:${n}`,\n\tapplicationUniversalIdentifier: e\n}), N = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `VIEW:${n}`,\n\tapplicationUniversalIdentifier: e\n}), P = ({ applicationUniversalIdentifier: e, link: n }) => t({\n\tentityNamespace: \"navigationMenuItem\",\n\tvalue: `LINK:${n}`,\n\tapplicationUniversalIdentifier: e\n}), F = ({ applicationUniversalIdentifier: e, roleUniversalIdentifier: n, objectUniversalIdentifier: r }) => t({\n\tentityNamespace: \"objectPermission\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), I = ({ applicationUniversalIdentifier: e, nameSingular: n }) => t({\n\tentityNamespace: \"objectMetadata\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), L = ({ applicationUniversalIdentifier: e, pageLayoutUniversalIdentifier: n, title: r }) => t({\n\tentityNamespace: \"pageLayoutTab\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), R = \"RECORD_PAGE\", z = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"pageLayout\",\n\tvalue: n ? `${n}:${r}` : r,\n\tapplicationUniversalIdentifier: e\n}), B = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n }) => t({\n\tentityNamespace: \"pageLayout\",\n\tvalue: `${n}:${R}`,\n\tapplicationUniversalIdentifier: e\n}), V = ({ applicationUniversalIdentifier: e, pageLayoutTabUniversalIdentifier: n, title: r }) => t({\n\tentityNamespace: \"pageLayoutWidget\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), H = ({ applicationUniversalIdentifier: e, key: n }) => t({\n\tentityNamespace: \"permissionFlag\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), U = ({ applicationUniversalIdentifier: e, roleUniversalIdentifier: n, permissionFlagUniversalIdentifier: r }) => t({\n\tentityNamespace: \"rolePermissionFlag\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), W = ({ applicationUniversalIdentifier: e, agentUniversalIdentifier: n }) => t({\n\tentityNamespace: \"roleTarget\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), G = ({ applicationUniversalIdentifier: e, label: n }) => t({\n\tentityNamespace: \"role\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), K = ({ applicationUniversalIdentifier: e, fieldMetadataUniversalIdentifier: n }) => t({\n\tentityNamespace: \"searchFieldMetadata\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), q = ({ applicationUniversalIdentifier: e, fieldUniversalIdentifier: n, value: r }) => t({\n\tentityNamespace: \"selectOption\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), J = ({ applicationUniversalIdentifier: e, name: n }) => t({\n\tentityNamespace: \"skill\",\n\tvalue: n,\n\tapplicationUniversalIdentifier: e\n}), Y = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"viewFieldGroup\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), X = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldMetadataUniversalIdentifier: r }) => t({\n\tentityNamespace: \"viewField\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), Z = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldMetadataUniversalIdentifier: r, operand: i, subFieldName: a }) => t({\n\tentityNamespace: \"viewFilter\",\n\tvalue: `${n}:${r}:${i}:${a ?? \"\"}`,\n\tapplicationUniversalIdentifier: e\n}), Q = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldValue: r }) => t({\n\tentityNamespace: \"viewGroup\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), $ = ({ applicationUniversalIdentifier: e, viewUniversalIdentifier: n, fieldMetadataUniversalIdentifier: r }) => t({\n\tentityNamespace: \"viewSort\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), te = ({ applicationUniversalIdentifier: e, objectUniversalIdentifier: n, name: r }) => t({\n\tentityNamespace: \"view\",\n\tvalue: `${n}:${r}`,\n\tapplicationUniversalIdentifier: e\n}), ne = /* @__PURE__ */ function(e) {\n\treturn e.Object = \"object\", e.Field = \"field\", e.LogicFunction = \"logicFunction\", e.FrontComponent = \"frontComponent\", e.Role = \"role\", e.Skill = \"skill\", e.Agent = \"agent\", e.ConnectionProvider = \"connectionProvider\", e.View = \"view\", e.ViewField = \"viewField\", e.NavigationMenuItem = \"navigationMenuItem\", e.PageLayout = \"pageLayout\", e.PageLayoutTab = \"pageLayoutTab\", e.CommandMenuItem = \"commandMenuItem\", e;\n}({}), re = (t, n = e.TEXT) => {\n\tif (t == null) return \"\";\n\tswitch (n) {\n\t\tcase e.BOOLEAN: return String(t) === \"true\" ? \"true\" : \"false\";\n\t\tcase e.NUMBER:\n\t\tcase e.NUMERIC: return String(t);\n\t\tcase e.ARRAY:\n\t\tcase e.MULTI_SELECT:\n\t\t\tif (Array.isArray(t)) return JSON.stringify(t);\n\t\t\tif (typeof t == \"string\") {\n\t\t\t\ttry {\n\t\t\t\t\tlet e = JSON.parse(t);\n\t\t\t\t\tif (Array.isArray(e)) return t;\n\t\t\t\t} catch {}\n\t\t\t\treturn JSON.stringify([t]);\n\t\t\t}\n\t\t\treturn JSON.stringify(t);\n\t\tcase e.RAW_JSON:\n\t\tcase e.RICH_TEXT: return typeof t == \"string\" ? t : JSON.stringify(t);\n\t\tdefault: return typeof t == \"string\" ? t : String(t);\n\t}\n}, ie = (t, n = e.TEXT) => {\n\tif (t === \"\") return n === e.ARRAY || n === e.MULTI_SELECT ? [] : \"\";\n\tswitch (n) {\n\t\tcase e.BOOLEAN: return t === \"true\";\n\t\tcase e.NUMBER:\n\t\tcase e.NUMERIC: {\n\t\t\tlet e = Number(t);\n\t\t\treturn Number.isNaN(e) ? t : e;\n\t\t}\n\t\tcase e.ARRAY:\n\t\tcase e.MULTI_SELECT: try {\n\t\t\tlet e = JSON.parse(t);\n\t\t\treturn Array.isArray(e) ? e : [];\n\t\t} catch {\n\t\t\treturn [];\n\t\t}\n\t\tcase e.RAW_JSON:\n\t\tcase e.RICH_TEXT: try {\n\t\t\treturn JSON.parse(t);\n\t\t} catch {\n\t\t\treturn t;\n\t\t}\n\t\tdefault: return t;\n\t}\n};\n//#endregion\nexport { s as APPLICATION_CATEGORIES, l as APPLICATION_VARIABLE_FIELD_METADATA_TYPES, u as ASSETS_DIR, d as DEFAULT_API_KEY_NAME, f as DEFAULT_API_URL_NAME, p as DEFAULT_APP_ACCESS_TOKEN_NAME, m as DEFAULT_FUNCTIONS_URL_NAME, h as GENERATED_DIR, g as NODE_ESM_CJS_BANNER, _ as OUTPUT_DIR, ne as SyncableEntity, v as TWENTY_STANDARD_APPLICATION_NAME, i as TWENTY_STANDARD_APPLICATION_UNIVERSAL_IDENTIFIER, t as computeDeterministicUuid, ie as deserializeApplicationVariableValue, y as getAgentUniversalIdentifier, b as getApplicationVariableUniversalIdentifier, E as getConnectionProviderUniversalIdentifier, D as getFieldPermissionUniversalIdentifier, n as getFieldUniversalIdentifier, O as getFieldsWidgetViewUniversalIdentifier, ee as getFolderNavigationMenuItemUniversalIdentifier, k as getFrontComponentUniversalIdentifier, S as getGlobalCommandMenuItemUniversalIdentifier, C as getGlobalObjectContextCommandMenuItemUniversalIdentifier, A as getIndexUniversalIdentifier, P as getLinkNavigationMenuItemUniversalIdentifier, j as getLogicFunctionUniversalIdentifier, T as getNavigationCommandUniversalIdentifier, M as getObjectNavigationMenuItemUniversalIdentifier, F as getObjectPermissionUniversalIdentifier, I as getObjectUniversalIdentifier, L as getPageLayoutTabUniversalIdentifier, z as getPageLayoutUniversalIdentifier, V as getPageLayoutWidgetUniversalIdentifier, H as getPermissionFlagUniversalIdentifier, B as getRecordPageLayoutUniversalIdentifier, w as getRecordSelectionCommandMenuItemUniversalIdentifier, U as getRolePermissionFlagUniversalIdentifier, W as getRoleTargetUniversalIdentifier, G as getRoleUniversalIdentifier, K as getSearchFieldUniversalIdentifier, q as getSelectOptionUniversalIdentifier, J as getSkillUniversalIdentifier, a as getSystemRelationFieldUniversalIdentifier, r as getSystemViewFieldUniversalIdentifier, o as getSystemViewUniversalIdentifier, Y as getViewFieldGroupUniversalIdentifier, X as getViewFieldUniversalIdentifier, Z as getViewFilterUniversalIdentifier, Q as getViewGroupUniversalIdentifier, N as getViewNavigationMenuItemUniversalIdentifier, $ as getViewSortUniversalIdentifier, te as getViewUniversalIdentifier, c as isKnownApplicationCategory, re as serializeApplicationVariableValue };\n", "import {\n  DEFAULT_API_URL_NAME,\n  DEFAULT_APP_ACCESS_TOKEN_NAME,\n} from 'twenty-shared/application';\n\nexport const postGraphqlRequest = async <TVariables, TData>({\n  query,\n  variables,\n  caller,\n}: {\n  query: string;\n  variables: TVariables;\n  caller: string;\n}): Promise<TData> => {\n  const apiUrl = process.env[DEFAULT_API_URL_NAME];\n  const accessToken = process.env[DEFAULT_APP_ACCESS_TOKEN_NAME];\n\n  if (!apiUrl || !accessToken) {\n    throw new Error(\n      `${caller}() requires the app runtime env vars ` +\n        `${DEFAULT_API_URL_NAME} and ${DEFAULT_APP_ACCESS_TOKEN_NAME}.`,\n    );\n  }\n\n  const response = await fetch(`${apiUrl}/metadata`, {\n    method: 'POST',\n    headers: {\n      'Content-Type': 'application/json',\n      Authorization: `Bearer ${accessToken}`,\n    },\n    body: JSON.stringify({ query, variables }),\n  });\n\n  if (!response.ok) {\n    throw new Error(\n      `${caller}() failed: HTTP ${response.status} ${response.statusText}`,\n    );\n  }\n\n  const body = (await response.json()) as {\n    data?: TData;\n    errors?: { message: string }[];\n  };\n\n  if (body.errors && body.errors.length > 0) {\n    throw new Error(\n      `${caller}() failed: ${body.errors.map((error) => error.message).join(', ')}`,\n    );\n  }\n\n  if (!body.data) {\n    throw new Error(`${caller}() failed: response contained no data.`);\n  }\n\n  return body.data;\n};\n", "import { AppConnectionAuthFailedError } from '@/sdk/logic-function/connections/errors/app-connection-auth-failed.error';\nimport { type AppConnection } from '@/sdk/logic-function/connections/types/app-connection.type';\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst GET_APP_CONNECTION_QUERY = `\n  query GetAppConnection($id: ID!) {\n    appConnection(id: $id) {\n      id\n      providerName\n      name\n      handle\n      visibility\n      userWorkspaceId\n      accessToken\n      scopes\n      authFailedAt\n    }\n  }\n`;\n\nexport const getConnection = async (id: string): Promise<AppConnection> => {\n  const { appConnection } = await postGraphqlRequest<\n    { id: string },\n    { appConnection: AppConnection }\n  >({\n    query: GET_APP_CONNECTION_QUERY,\n    variables: { id },\n    caller: 'getConnection',\n  });\n\n  if (appConnection.authFailedAt !== null) {\n    throw new AppConnectionAuthFailedError(appConnection.id);\n  }\n\n  return appConnection;\n};\n", "import { type AppConnection } from '@/sdk/logic-function/connections/types/app-connection.type';\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst LIST_APP_CONNECTIONS_QUERY = `\n  query ListAppConnections($filter: ListAppConnectionsInput) {\n    appConnections(filter: $filter) {\n      id\n      providerName\n      name\n      handle\n      visibility\n      userWorkspaceId\n      accessToken\n      scopes\n      authFailedAt\n    }\n  }\n`;\n\nexport type ListConnectionsFilter = {\n  providerName?: string;\n  userWorkspaceId?: string;\n  visibility?: 'user' | 'workspace';\n};\n\nexport const listConnections = async (\n  filter: ListConnectionsFilter = {},\n): Promise<AppConnection[]> => {\n  const { appConnections } = await postGraphqlRequest<\n    { filter: ListConnectionsFilter },\n    { appConnections: AppConnection[] }\n  >({\n    query: LIST_APP_CONNECTIONS_QUERY,\n    variables: { filter },\n    caller: 'listConnections',\n  });\n\n  return appConnections;\n};\n", "import { type AppConnection } from '@/sdk/logic-function/connections/types/app-connection.type';\n\nexport const findConnectionForRequest = (\n  connections: AppConnection[],\n  event: { userWorkspaceId: string | null },\n): AppConnection | null => {\n  if (event.userWorkspaceId !== null) {\n    const personal = connections.find(\n      (connection) =>\n        connection.visibility === 'user' &&\n        connection.userWorkspaceId === event.userWorkspaceId,\n    );\n\n    if (personal) {\n      return personal;\n    }\n  }\n\n  const workspaceShared = connections.find(\n    (connection) => connection.visibility === 'workspace',\n  );\n\n  return workspaceShared ?? null;\n};\n", "import {\n  type RunAgentInput,\n  type RunAgentResult,\n} from 'twenty-shared/application';\n\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst RUN_AGENT_MUTATION = `\n  mutation RunAgent($input: RunAgentInput!) {\n    runAgent(input: $input) {\n      result\n      error\n      success\n    }\n  }\n`;\n\nexport const runAgent = async (\n  input: RunAgentInput,\n): Promise<RunAgentResult> => {\n  const { runAgent: result } = await postGraphqlRequest<\n    { input: RunAgentInput },\n    { runAgent: RunAgentResult }\n  >({\n    query: RUN_AGENT_MUTATION,\n    variables: { input },\n    caller: 'runAgent',\n  });\n\n  return result;\n};\n", "import { MetadataApiClient } from 'twenty-client-sdk/metadata';\nimport {\n  type EnqueueJobInput,\n  type EnqueueJobResult,\n} from 'twenty-shared/application';\n\nexport const enqueueJob = async (\n  input: EnqueueJobInput,\n): Promise<EnqueueJobResult> => {\n  const client = new MetadataApiClient();\n\n  const { enqueueJob: result } = await client.mutation({\n    enqueueJob: {\n      __args: { input },\n      enqueued: true,\n      logicFunctionUniversalIdentifier: true,\n    },\n  });\n\n  return result;\n};\n", "import {\n  type AppKeyValue,\n  type AppKeyValueScope,\n} from 'twenty-shared/application';\n\nimport { postGraphqlRequest } from '@/sdk/logic-function/utils/post-graphql-request.util';\n\nconst GET_APP_KEY_VALUE_QUERY = `\n  query GetAppKeyValue($key: String!, $scope: AppKeyValueScope) {\n    appKeyValue(key: $key, scope: $scope) {\n      key\n      value\n      scope\n    }\n  }\n`;\n\nconst SET_APP_KEY_VALUE_MUTATION = `\n  mutation SetAppKeyValue($input: SetAppKeyValueInput!) {\n    setAppKeyValue(input: $input) {\n      key\n      value\n      scope\n    }\n  }\n`;\n\nconst DELETE_APP_KEY_VALUE_MUTATION = `\n  mutation DeleteAppKeyValue($key: String!, $scope: AppKeyValueScope) {\n    deleteAppKeyValue(key: $key, scope: $scope)\n  }\n`;\n\nconst DEFAULT_APP_KEY_VALUE_SCOPE: AppKeyValueScope = 'WORKSPACE';\n\ntype KvOptions = {\n  scope?: AppKeyValueScope;\n};\n\nexport const kv = {\n  async get<TValue = unknown>(\n    key: string,\n    options?: KvOptions,\n  ): Promise<TValue | null> {\n    const { appKeyValue } = await postGraphqlRequest<\n      { key: string; scope: AppKeyValueScope },\n      { appKeyValue: AppKeyValue | null }\n    >({\n      query: GET_APP_KEY_VALUE_QUERY,\n      variables: { key, scope: options?.scope ?? DEFAULT_APP_KEY_VALUE_SCOPE },\n      caller: 'kv.get',\n    });\n\n    return (appKeyValue?.value ?? null) as TValue | null;\n  },\n\n  async set<TValue>(\n    key: string,\n    value: TValue,\n    options?: KvOptions,\n  ): Promise<void> {\n    await postGraphqlRequest<\n      {\n        input: { key: string; value: TValue; scope: AppKeyValueScope };\n      },\n      { setAppKeyValue: AppKeyValue }\n    >({\n      query: SET_APP_KEY_VALUE_MUTATION,\n      variables: {\n        input: {\n          key,\n          value,\n          scope: options?.scope ?? DEFAULT_APP_KEY_VALUE_SCOPE,\n        },\n      },\n      caller: 'kv.set',\n    });\n  },\n\n  async delete(key: string, options?: KvOptions): Promise<boolean> {\n    const { deleteAppKeyValue } = await postGraphqlRequest<\n      { key: string; scope: AppKeyValueScope },\n      { deleteAppKeyValue: boolean }\n    >({\n      query: DELETE_APP_KEY_VALUE_MUTATION,\n      variables: { key, scope: options?.scope ?? DEFAULT_APP_KEY_VALUE_SCOPE },\n      caller: 'kv.delete',\n    });\n\n    return deleteAppKeyValue;\n  },\n};\n", "import { type LogicFunctionHttpResponse } from 'twenty-shared/types';\n\nexport type ResponseInit = {\n  status?: number;\n  headers?: Record<string, string>;\n};\n\nexport class Response implements LogicFunctionHttpResponse {\n  readonly __twentyHttpResponse = true as const;\n  readonly body: unknown;\n  readonly status?: number;\n  readonly headers?: Record<string, string>;\n\n  constructor(body: unknown, init?: ResponseInit) {\n    this.body = body;\n    this.status = init?.status;\n    this.headers = init?.headers;\n  }\n}\n", "/**\n * Identifiers, endpoint shape and storage keys for the Numaya licensing client.\n *\n * Same permanence rule as `src/constants/universal-identifiers.ts`: every UUID\n * here is written into the customer's workspace at install time, so changing one\n * orphans the old entity rather than renaming it. Adding is safe.\n *\n * These live in their own file rather than in `universal-identifiers.ts` for the\n * same reason the gate-queue constants do \u2014 so the licensing surface can be\n * built without touching the data-model constants the scoring engine depends on.\n *\n * ---------------------------------------------------------------------------\n * ## What is verified here, and how\n *\n * Everything below is now confirmed against the **REST API of the running\n * service**, not inferred. The service publishes an OpenAPI document at\n * `https://licensing.rizvigoc.com/openapi.json` (title: *Numaya Licensing -\n * Customer API*), and each request shape below was additionally exercised over\n * real HTTP on 2026-08-04.\n *\n * The spec is authoritative over `LICENSING_INTEGRATION.md`, which was written\n * from the service's **MCP** interface and predates the published spec. Where\n * the two disagree, the spec \u2014 and the live response \u2014 wins.\n *\n * The base URL stays an **application variable** (`LICENCE_API_BASE_URL`) even\n * though it is now confirmed, because a customer running a private Numaya\n * deployment still needs to point it somewhere else, and because a wrong\n * default must remain a settings change rather than a release.\n *\n * Nothing here is load-bearing for safety: every request this client makes\n * either succeeds, or fails in a way that degrades to rules-only scoring. A\n * wrong base URL costs the customer enrichment, never a lead. See\n * `src/licensing/state.ts`.\n * ---------------------------------------------------------------------------\n */\n\n/* -------------------------------------------------------------------------- */\n/* Universal identifiers                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport const LICENCE_API_BASE_URL_APP_VARIABLE_UNIVERSAL_IDENTIFIER =\n  '0dbad279-c07c-4ae0-91e5-68cb0e87c944';\n\n/**\n * `LICENCE_ENVIRONMENT`. See `LICENCE_ENVIRONMENTS` below for why an endpoint\n * that a customer will never change is still a Layer 1 variable.\n */\nexport const LICENCE_ENVIRONMENT_APP_VARIABLE_UNIVERSAL_IDENTIFIER =\n  'e39571dd-0053-4c17-a11f-c0988985d312';\n\nexport const LICENCE_REVALIDATE_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  'fc2534ad-a3a1-4b05-bdf0-f2e7a1cef729';\n\nexport const LICENCE_STATUS_LOGIC_FUNCTION_UNIVERSAL_IDENTIFIER =\n  '42eaa3bc-75b6-49be-863c-a3b3c539e3a2';\n\nexport const LICENCE_FRONT_COMPONENT_UNIVERSAL_IDENTIFIER =\n  '42089a05-139e-4061-aaaa-1d53e851ac90';\n\nexport const LICENCE_COMMAND_MENU_ITEM_UNIVERSAL_IDENTIFIER =\n  'b0316c8e-e4ad-492c-9197-f26c553c0151';\n\n/* -------------------------------------------------------------------------- */\n/* The licence panel                                                           */\n/* -------------------------------------------------------------------------- */\n\nexport const LICENCE_ROUTE_PATH = '/greenlight/licence';\n\nexport const LICENCE_CLIENT_PATH = `/s${LICENCE_ROUTE_PATH}`;\n\n/**\n * Where \"Get a licence\" sends an admin.\n *\n * A constant rather than a literal in the component because it is the one part\n * of this feature guaranteed to move: today numaya.ai has no Greenlight\n * checkout, so the honest destination is the contact route, which reaches a\n * human who can issue a key. When a real purchase page exists this is the only\n * line that changes.\n *\n * The `source` parameter is not decoration. Without it there is no way to tell\n * an enquiry that came from inside a customer's own CRM \u2014 someone who has\n * already installed the app and hit the rules-only ceiling \u2014 from a cold\n * website visitor, and those two deserve different replies.\n */\nexport const LICENCE_PURCHASE_URL =\n  'https://numaya.ai/contact?source=greenlight-app';\n\n/* -------------------------------------------------------------------------- */\n/* Endpoint shape \u2014 confirmed against the published spec and live HTTP         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Default value of the `LICENCE_API_BASE_URL` application variable.\n *\n * `https://licensing.rizvigoc.com` is the licensing service's real public\n * hostname, confirmed on 2026-08-04 by fetching its OpenAPI document and by\n * driving `validate` and `activate` against it over HTTPS.\n *\n * The earlier default, `license.numaya.ai`, never existed: it was a placeholder\n * that entered this project's own documentation and was then cited by it. It\n * did not resolve in public DNS, so every install shipped with it fell straight\n * through the cache \u2192 grace \u2192 rules-only ladder. That ladder worked, which is\n * precisely why the wrong hostname survived as long as it did.\n */\nexport const DEFAULT_LICENCE_API_BASE_URL = 'https://licensing.rizvigoc.com';\n\n/**\n * Confirmed. Both paths appear verbatim in the service's published OpenAPI\n * document and both were exercised live. The `/v1` prefix and the US spelling\n * `licenses` are the service's, not ours.\n */\nexport const LICENCE_VALIDATE_PATH = '/v1/licenses/validate';\nexport const LICENCE_ACTIVATE_PATH = '/v1/licenses/activate';\n\n/* -------------------------------------------------------------------------- */\n/* Environment routing                                                         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The header that selects which side of the licensing service answers.\n *\n * One host serves both environments. Sandbox licences are **only** visible to a\n * request carrying `X-Numaya-Environment: sandbox`; without it the same key\n * comes back `200 valid:false reason:\"license_not_found\"`. The service's own\n * spec says so in one sentence \u2014 \"Use `X-Numaya-Environment: sandbox` header or\n * `nml_test_` API keys to access the sandbox\" \u2014 and the live behaviour matches.\n *\n * The header value is matched case-insensitively by the service (`sandbox`,\n * `Sandbox` and `SANDBOX` all worked); we send the lower-case form.\n */\nexport const LICENCE_ENVIRONMENT_HEADER = 'X-Numaya-Environment';\n\n/**\n * The two environments, and why this is an application variable at all.\n *\n * It is **not** derivable from the base URL \u2014 the same host serves both \u2014 so it\n * cannot be folded into `LICENCE_API_BASE_URL`. It cannot be a code constant\n * either: our own CI workspace and every throwaway dev container is licensed\n * out of sandbox, and making that a constant would mean a code change and a\n * republish to test a licensing change. And it cannot live in Layer 2, the\n * CRM-editable `GreenlightConfig` record, because the post-install hook\n * validates the licence before any Layer 2 record is guaranteed to exist.\n *\n * That leaves Layer 1. A customer never touches it \u2014 the default is\n * `production` and the description says as much \u2014 but it has to be *settable*\n * without a rebuild, which is the identical argument that already put\n * `LICENCE_API_BASE_URL` in Layer 1.\n */\nexport const LICENCE_ENVIRONMENTS = ['production', 'sandbox'] as const;\n\nexport const DEFAULT_LICENCE_ENVIRONMENT = 'production';\n\n/**\n * The service's `reason` when a key authenticated but resolved to no licence in\n * the environment the request was routed to. US spelling, the service's own.\n *\n * This is the misrouted-environment signal. See `src/licensing/entitlement.ts`\n * for why it cannot mean \"the key has a typo\".\n */\nexport const LICENCE_NOT_FOUND_REASON = 'license_not_found';\n\n/**\n * Request body field names.\n *\n * These are *not* guesses: they are the parameter names the licensing service's\n * own MCP tool schema declares for `numaya_validate_license` and\n * `numaya_activate_license`, which are generated from the service's parameter\n * model. The REST layer using different names is possible but unlikely.\n */\nexport const LICENCE_REQUEST_FIELDS = {\n  key: 'key',\n  deviceFingerprint: 'deviceFingerprint',\n  feature: 'feature',\n  deviceName: 'deviceName',\n} as const;\n\n/**\n * The feature name the paid capability is licensed under. `rules` \u2014 the\n * deterministic gate \u2014 is on every policy and is never checked, because rules\n * scoring is the free floor and must run with no licence at all.\n */\nexport const ENRICHMENT_FEATURE_NAME = 'enrichment';\n\n/* -------------------------------------------------------------------------- */\n/* App key-value storage                                                       */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Where the cached entitlement and the published admin-facing state live.\n *\n * `scope: 'WORKSPACE'` throughout \u2014 the licence is per workspace, and the\n * activation slot is claimed with the workspace id as its fingerprint. A read\n * under a different scope silently finds nothing, which is the failure mode\n * `release-marker-store.ts` documents.\n */\nexport const LICENCE_CACHE_KV_KEY = 'greenlight.licence.cache';\n\n/**\n * Sticky record of what happened the last time we tried to claim an activation\n * slot. Separate from the validation cache on purpose: a `409` is durable\n * customer state (the licence is bound to a different workspace) and must\n * survive every nightly re-validation, whereas the validation cache is replaced\n * nightly. See `src/licensing/state.ts` for why this matters.\n */\nexport const LICENCE_ACTIVATION_KV_KEY = 'greenlight.licence.activation';\n\n/**\n * The resolved licence state, published for the admin UI to read. Written on\n * every validation; never contains the licence key.\n */\nexport const LICENCE_STATE_KV_KEY = 'greenlight.licence.state';\n\n/**\n * The verified calibration payload, cached beside the entitlement.\n *\n * Separate from `LICENCE_CACHE_KV_KEY` on purpose. The two are written by the\n * same nightly run but answer different questions and age on different clocks \u2014\n * the entitlement tightens at 24h because a stale one risks serving a paid\n * feature to a revoked licence, while calibration survives to 72h because it is\n * a word list and dropping it early would move a customer's scores for a reason\n * that has nothing to do with their data. See `src/calibration/state.ts`.\n *\n * It holds no key, no entitlement and nothing secret: the payload is the same\n * vocabulary every licensed workspace receives.\n */\nexport const CALIBRATION_CACHE_KV_KEY = 'greenlight.calibration.cache';\n\n/**\n * The resolved calibration state, published for the admin panel: shipped\n * defaults or calibration vNN, from where, and when it last refreshed.\n */\nexport const CALIBRATION_STATE_KV_KEY = 'greenlight.calibration.state';\n\n/* -------------------------------------------------------------------------- */\n/* Schedule                                                                    */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Nightly re-validation, 03:17 UTC.\n *\n * Standard five-field CRON. The odd minute is deliberate: every Greenlight\n * install would otherwise phone home on the same second, and the licensing\n * service is a single small container. Daily is the right frequency because the\n * cache TTL is 24h \u2014 validating more often buys nothing, validating less often\n * would let the cache go stale before the next run.\n */\nexport const LICENCE_REVALIDATE_CRON_PATTERN = '17 3 * * *';\n", "/**\n * The narrowest possible view of Twenty's Core API client.\n *\n * `CoreApiClient` from `twenty-client-sdk/core` is typed `any` until\n * `dev:generate-client` regenerates it against the installed workspace schema,\n * so depending on it directly buys no type safety and costs testability \u2014 the\n * class reads `API_URL` / `APP_ACCESS_TOKEN` from the process environment in its\n * constructor, which no unit test has.\n *\n * Everything in this folder therefore talks to `GreenlightApiClient`. The\n * `define*` files are the only place `new CoreApiClient()` appears, and they do\n * nothing but hand it to a handler that can be driven by a fake in tests.\n */\n\nexport interface GreenlightApiClient {\n  query(request: Record<string, unknown>): Promise<unknown>;\n  mutation(request: Record<string, unknown>): Promise<unknown>;\n}\n\nexport const isPlainRecord = (\n  value: unknown,\n): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\n/**\n * Twenty returns connections as `{ edges: [{ node }] }`. Pull the nodes out\n * without assuming the shape is correct \u2014 a schema drift should degrade to\n * \"no records found\", never throw.\n */\nexport const readConnectionNodes = (\n  payload: unknown,\n  connectionName: string,\n): Record<string, unknown>[] => {\n  if (!isPlainRecord(payload)) {\n    return [];\n  }\n\n  const connection = payload[connectionName];\n\n  if (!isPlainRecord(connection)) {\n    return [];\n  }\n\n  const edges = connection['edges'];\n\n  if (!Array.isArray(edges)) {\n    return [];\n  }\n\n  return edges.flatMap((edge): Record<string, unknown>[] => {\n    if (!isPlainRecord(edge)) {\n      return [];\n    }\n\n    const node = edge['node'];\n\n    return isPlainRecord(node) ? [node] : [];\n  });\n};\n\n/** ISO-8601 sorts lexicographically, so this needs no Date parsing. */\nexport const oldestByCreatedAt = (\n  records: readonly Record<string, unknown>[],\n): Record<string, unknown> | null => {\n  let oldest: Record<string, unknown> | null = null;\n  let oldestKey: string | null = null;\n\n  for (const record of records) {\n    const createdAt = record['createdAt'];\n    const key = typeof createdAt === 'string' ? createdAt : '';\n\n    if (oldest === null || oldestKey === null || key < oldestKey) {\n      oldest = record;\n      oldestKey = key;\n    }\n  }\n\n  return oldest;\n};\n\n/**\n * Structured log line. Logic functions have no logger injected \u2014 stdout is what\n * `yarn twenty dev:function:logs` shows \u2014 so everything Greenlight emits is a\n * single JSON object with a stable `event` key that support can grep for.\n */\nexport const logGreenlight = (\n  event: string,\n  detail: Record<string, unknown>,\n): void => {\n  // eslint-disable-next-line no-console\n  console.log(JSON.stringify({ app: 'numaya-greenlight', event, ...detail }));\n};\n\nexport const describeError = (error: unknown): string => {\n  if (error instanceof Error) {\n    return `${error.name}: ${error.message}`;\n  }\n\n  if (typeof error === 'string') {\n    return error;\n  }\n\n  try {\n    return JSON.stringify(error) ?? 'unknown error';\n  } catch {\n    return 'unknown error';\n  }\n};\n", "/**\n * The real licence store: Twenty's app key-value storage.\n *\n * Same shape and the same reasoning as `release-marker-store.ts` \u2014 this is the\n * only licensing module that imports the SDK, which is what lets `licence-run.ts`\n * and the whole of `src/licensing/` be driven by a fake in unit tests.\n *\n * `scope: 'WORKSPACE'` throughout, and it is not a detail. A licence belongs to\n * a workspace, its activation slot is claimed with the workspace id as the\n * fingerprint, and a read under a different scope silently finds nothing \u2014 which\n * would present as \"the cache never survives a restart\", i.e. as a permanent\n * grace-expired state that fails open forever and never says why.\n *\n * ## Reads are tolerant, writes are best-effort\n *\n * `kv.get` returns whatever was stored, which after an upgrade might be a shape\n * this version has never seen. Every read validates the couple of fields it\n * actually depends on and returns `null` / `unknown` otherwise, so a stale entry\n * degrades to \"no cache\" rather than to a `TypeError` inside a cron job.\n *\n * Writes swallow their errors for the same reason install-run's audit write\n * does: failing a licence check because the *cache* could not be written would\n * convert a storage blip into a lost validation, when the validation itself\n * already succeeded.\n */\n\nimport { kv } from 'twenty-sdk/logic-function';\n\nimport {\n  CALIBRATION_CACHE_KV_KEY,\n  CALIBRATION_STATE_KV_KEY,\n  LICENCE_ACTIVATION_KV_KEY,\n  LICENCE_CACHE_KV_KEY,\n  LICENCE_STATE_KV_KEY,\n} from 'src/constants/licence-identifiers';\nimport {\n  type CachedCalibration,\n  type CalibrationReaderPort,\n  type CalibrationStorePort,\n} from 'src/calibration/types';\nimport {\n  describeError,\n  logGreenlight,\n} from 'src/logic-functions/greenlight-api';\nimport {\n  type CachedLicenceValidation,\n  type LicenceActivationState,\n  type LicenceState,\n  type LicenceStorePort,\n} from 'src/licensing/types';\n\nconst SCOPE = { scope: 'WORKSPACE' } as const;\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\n/**\n * A cache entry is only usable if it carries the three things the offline path\n * reads: when it was taken, and the two gate booleans. Everything else is\n * cosmetic and is allowed to be missing.\n */\nconst readCacheEntry = (value: unknown): CachedLicenceValidation | null => {\n  if (!isRecord(value)) {\n    return null;\n  }\n\n  const { cachedAt, valid, hasFeature } = value;\n\n  if (\n    typeof cachedAt !== 'string' ||\n    typeof valid !== 'boolean' ||\n    typeof hasFeature !== 'boolean'\n  ) {\n    return null;\n  }\n\n  return {\n    cachedAt,\n    maskedKey: typeof value['maskedKey'] === 'string' ? value['maskedKey'] : '',\n    valid,\n    hasFeature,\n    reason: typeof value['reason'] === 'string' ? value['reason'] : null,\n    features: Array.isArray(value['features'])\n      ? value['features'].filter((entry): entry is string => typeof entry === 'string')\n      : [],\n    tier: typeof value['tier'] === 'string' ? value['tier'] : null,\n    daysRemaining:\n      typeof value['daysRemaining'] === 'number' ? value['daysRemaining'] : null,\n    expiryWarning: value['expiryWarning'] === true,\n    expiryAt: typeof value['expiryAt'] === 'string' ? value['expiryAt'] : null,\n  };\n};\n\nconst readActivationState = (value: unknown): LicenceActivationState => {\n  if (!isRecord(value)) {\n    return { status: 'unknown' };\n  }\n\n  const status = value['status'];\n  const at = typeof value['at'] === 'string' ? value['at'] : '';\n\n  if (status === 'claimed' || status === 'limit_reached') {\n    return { status, at };\n  }\n\n  return { status: 'unknown' };\n};\n\nexport const kvLicenceStore: LicenceStorePort = {\n  readCache: async () => {\n    try {\n      return readCacheEntry(await kv.get<unknown>(LICENCE_CACHE_KV_KEY, SCOPE));\n    } catch (error) {\n      logGreenlight('licence_cache_read_failed', { error: describeError(error) });\n\n      return null;\n    }\n  },\n\n  writeCache: async (entry) => {\n    try {\n      await kv.set(LICENCE_CACHE_KV_KEY, entry, SCOPE);\n    } catch (error) {\n      logGreenlight('licence_cache_write_failed', { error: describeError(error) });\n    }\n  },\n\n  readActivation: async () => {\n    try {\n      return readActivationState(\n        await kv.get<unknown>(LICENCE_ACTIVATION_KV_KEY, SCOPE),\n      );\n    } catch (error) {\n      logGreenlight('licence_activation_read_failed', {\n        error: describeError(error),\n      });\n\n      return { status: 'unknown' };\n    }\n  },\n\n  writeActivation: async (state) => {\n    try {\n      await kv.set(LICENCE_ACTIVATION_KV_KEY, state, SCOPE);\n    } catch (error) {\n      logGreenlight('licence_activation_write_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n\n  publishState: async (state) => {\n    try {\n      await kv.set(LICENCE_STATE_KV_KEY, state, SCOPE);\n    } catch (error) {\n      logGreenlight('licence_state_publish_failed', { error: describeError(error) });\n    }\n  },\n};\n\n/* -------------------------------------------------------------------------- */\n/* Calibration                                                                 */\n/* -------------------------------------------------------------------------- */\n\n/**\n * A cached calibration is only usable if it carries when it was taken and a\n * payload with a version. Everything else is allowed to be missing and is\n * defaulted, for the same reason the entitlement cache is read tolerantly: an\n * entry written by a previous release must degrade to \"no calibration\" \u2014 i.e.\n * to shipped defaults \u2014 rather than to a `TypeError` inside a cron job.\n *\n * The lists are *not* re-validated element by element here. They were validated\n * and normalised by `src/calibration/parse.ts` before the signature was checked,\n * and re-deriving that on every read would spend a scoring run's time to\n * re-establish a fact the write already established.\n */\nconst readCalibrationEntry = (value: unknown): CachedCalibration | null => {\n  if (!isRecord(value)) {\n    return null;\n  }\n\n  const { cachedAt, calibration, sealTag, verifiedAt, keyId } = value;\n\n  if (typeof cachedAt !== 'string' || !isRecord(calibration)) {\n    return null;\n  }\n\n  if (typeof calibration['calibrationVersion'] !== 'number') {\n    return null;\n  }\n\n  // Every field the seal covers is read strictly, with no defaulting. A\n  // defaulted value would change the canonical bytes the tag is checked against\n  // and turn a legitimate entry into a seal mismatch \u2014 the failure would look\n  // like tampering, which is the most misleading thing it could look like. An\n  // entry missing any of them is simply not a sealed entry.\n  if (\n    typeof sealTag !== 'string' ||\n    sealTag.length === 0 ||\n    typeof verifiedAt !== 'string' ||\n    typeof keyId !== 'string'\n  ) {\n    return null;\n  }\n\n  return {\n    cachedAt,\n    verifiedAt,\n    keyId,\n    sealTag,\n    calibration: calibration as unknown as CachedCalibration['calibration'],\n  };\n};\n\nexport const kvCalibrationStore: CalibrationStorePort = {\n  readCalibration: async () => {\n    try {\n      return readCalibrationEntry(\n        await kv.get<unknown>(CALIBRATION_CACHE_KV_KEY, SCOPE),\n      );\n    } catch (error) {\n      logGreenlight('calibration_cache_read_failed', {\n        error: describeError(error),\n      });\n\n      return null;\n    }\n  },\n\n  writeCalibration: async (entry) => {\n    try {\n      await kv.set(CALIBRATION_CACHE_KV_KEY, entry, SCOPE);\n    } catch (error) {\n      logGreenlight('calibration_cache_write_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n\n  clearCalibration: async () => {\n    try {\n      // `kv.set(key, null)` rather than a delete: the SDK's key-value surface\n      // has no delete, and a stored `null` fails `readCalibrationEntry`'s record\n      // check, which is exactly \"no calibration\". Writing an empty object would\n      // not \u2014 it would parse as a record and then fail on a missing field, which\n      // is the same outcome by a longer route and one more shape to reason about.\n      await kv.set(CALIBRATION_CACHE_KV_KEY, null, SCOPE);\n    } catch (error) {\n      logGreenlight('calibration_cache_clear_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n\n  publishCalibrationState: async (state) => {\n    try {\n      await kv.set(CALIBRATION_STATE_KV_KEY, state, SCOPE);\n    } catch (error) {\n      logGreenlight('calibration_state_publish_failed', {\n        error: describeError(error),\n      });\n    }\n  },\n};\n\n/**\n * The scoring path's view: read-only, and narrower than the store above.\n *\n * A scoring run must not be handed something it could write through \u2014 the same\n * argument that keeps `readPublishedLicenceState` off `LicenceStorePort`. A run\n * that could rewrite the calibration cache would be a run that could change what\n * every *subsequent* lead is scored against, from inside a per-lead code path.\n */\nexport const kvCalibrationReader: CalibrationReaderPort = {\n  read: () => kvCalibrationStore.readCalibration(),\n};\n\n/**\n * Read the published calibration state back, for the admin panel.\n *\n * Returns `null` rather than a synthetic \"shipped defaults\" state when nothing\n * has been published: \"this workspace has never run a licence check\" and \"this\n * workspace ran one and is on shipped defaults\" are different things to show a\n * human, and inventing the second would hide the first.\n */\nexport const readPublishedCalibrationState = async (): Promise<unknown> => {\n  try {\n    const value = await kv.get<unknown>(CALIBRATION_STATE_KV_KEY, SCOPE);\n\n    return isRecord(value) && typeof value['status'] === 'string' ? value : null;\n  } catch (error) {\n    logGreenlight('calibration_state_read_failed', {\n      error: describeError(error),\n    });\n\n    return null;\n  }\n};\n\n/**\n * Read the published state back \u2014 what a future enrichment path calls before\n * consulting `isEnrichmentEnabled`. Deliberately not on `LicenceStorePort`: the\n * port is the *writer's* interface, and enrichment has no business being handed\n * something it could write through.\n */\nexport const readPublishedLicenceState = async (): Promise<LicenceState | null> => {\n  try {\n    const value = await kv.get<unknown>(LICENCE_STATE_KV_KEY, SCOPE);\n\n    if (!isRecord(value) || typeof value['mode'] !== 'string') {\n      return null;\n    }\n\n    return value as unknown as LicenceState;\n  } catch (error) {\n    logGreenlight('licence_state_read_failed', { error: describeError(error) });\n\n    return null;\n  }\n};\n", "/**\n * Cache freshness and offline-grace arithmetic.\n *\n * Pure: `now` is passed in, never read. The scoring engine holds the same line\n * for the same reason \u2014 a clock read inside a decision function makes the\n * decision untestable at its boundaries, and every interesting case here *is* a\n * boundary.\n *\n * ---------------------------------------------------------------------------\n * ## The windows, and why they are these windows\n *\n * From the error-state table in `LICENSING_INTEGRATION.md`:\n *\n * | Cache age        | Behaviour                                     |\n * |------------------|-----------------------------------------------|\n * | `< 24h`          | Cached entitlement used as-is                 |\n * | `24h \u2013 72h`      | Rules-only, \"grace period\"                    |\n * | `> 72h`          | Rules-only + visible warning                  |\n *\n * Note that grace **ends at 72h from `cachedAt`**, not at 24h + 72h. The prose\n * elsewhere reads \"24h cache, then a 72h offline grace window\", which would put\n * the cliff at 96h; the table is the specific claim and the table is what is\n * implemented. The difference is 24 hours of degraded-but-warned operation and\n * it changes nothing about safety, because **nothing is ever blocked at any\n * point on this ladder** \u2014 past 72h the product is still scoring leads, it is\n * just scoring them without enrichment and saying so loudly.\n *\n * ## Why grace disables enrichment rather than extending it\n *\n * Because the two failure modes are not symmetric. Trusting a stale entitlement\n * for three days means potentially serving a paid feature to a revoked licence,\n * and revocation is the one lever that has to work. Turning enrichment off means\n * the customer loses an optional enhancement during a Numaya outage. The second\n * is recoverable in seconds when the service returns; the first is not\n * recoverable at all.\n *\n * The 24h band is the exception, and it is bounded precisely so that \"Numaya\n * restarted a container\" never costs a customer anything.\n * ---------------------------------------------------------------------------\n */\n\nconst HOUR_MS = 60 * 60 * 1000;\n\n/** Entitlements younger than this are used exactly as if they were live. */\nexport const LICENCE_CACHE_TTL_MS = 24 * HOUR_MS;\n\n/**\n * Age at which the offline grace window closes, measured from `cachedAt`.\n * Past this the product warns visibly \u2014 it does not stop.\n */\nexport const LICENCE_OFFLINE_GRACE_LIMIT_MS = 72 * HOUR_MS;\n\nexport type CacheFreshness = 'fresh' | 'grace' | 'expired';\n\n/**\n * Age of a cached entitlement in milliseconds, or `null` when `cachedAt` is\n * missing or unparseable.\n *\n * A negative age \u2014 a cache written by a machine whose clock is ahead \u2014 is\n * clamped to `0` rather than rejected. The alternative is that a small clock\n * skew on the licensing service makes a workspace look like it has never\n * validated, which is a worse outcome than briefly treating a slightly-future\n * entitlement as fresh.\n */\nexport const cacheAgeMs = (\n  cachedAt: string | null | undefined,\n  now: Date,\n): number | null => {\n  if (typeof cachedAt !== 'string' || cachedAt.length === 0) {\n    return null;\n  }\n\n  const cachedMs = Date.parse(cachedAt);\n\n  if (Number.isNaN(cachedMs)) {\n    return null;\n  }\n\n  return Math.max(0, now.getTime() - cachedMs);\n};\n\n/**\n * Boundaries are inclusive at the *lower* edge of the worse band: an entitlement\n * exactly 24h old is already in grace, and one exactly 72h old is already\n * expired. Erring towards the stricter band on the boundary keeps the rule\n * \"fresh means strictly under a day old\" true as stated.\n */\nexport const classifyCacheAge = (ageMs: number): CacheFreshness => {\n  if (ageMs < LICENCE_CACHE_TTL_MS) {\n    return 'fresh';\n  }\n\n  if (ageMs < LICENCE_OFFLINE_GRACE_LIMIT_MS) {\n    return 'grace';\n  }\n\n  return 'expired';\n};\n\n/**\n * `null` when there is no usable cache at all \u2014 which is not the same as an\n * expired one, and the admin notice says so differently.\n */\nexport const classifyCache = (\n  cachedAt: string | null | undefined,\n  now: Date,\n): { readonly freshness: CacheFreshness | null; readonly ageMs: number | null } => {\n  const ageMs = cacheAgeMs(cachedAt, now);\n\n  return {\n    freshness: ageMs === null ? null : classifyCacheAge(ageMs),\n    ageMs,\n  };\n};\n", "/**\n * Canonical serialisation \u2014 the exact bytes that get signed and verified.\n *\n * A detached signature is worthless unless the signer and the verifier agree,\n * byte for byte, on what \"the payload\" is. JSON does not give that for free:\n * key order, whitespace and the treatment of `undefined` are all free choices,\n * and the payload makes a round trip through the licensing service's own JSON\n * storage before we see it again \u2014 a round trip that is entitled to reorder\n * keys and reformat numbers without changing meaning.\n *\n * So this module defines the agreement, and both halves import *this file*\n * rather than reimplementing it. The signer is `ops/calibration/sign.mjs`; the\n * verifier is `verify.ts`. There is no third copy.\n *\n * ---------------------------------------------------------------------------\n * ## The rules\n *\n * 1. **Object keys are sorted** by code unit, recursively. This is the whole\n *    point: a service that re-serialises our JSON may emit keys in any order,\n *    and sorting makes that reordering invisible to the signature.\n * 2. **Arrays keep their order.** Order is meaning here \u2014 `decisionMakerTitles`\n *    is scanned in sequence and the first match wins, so a reordered list is a\n *    genuinely different payload and must break the signature.\n * 3. **No insignificant whitespace**, i.e. `JSON.stringify` with no spacer.\n * 4. **`undefined` and functions are dropped**, exactly as `JSON.stringify`\n *    already drops them, so a key that is absent and a key that is explicitly\n *    `undefined` canonicalise identically. They mean the same thing to every\n *    reader downstream, so they must sign the same.\n * 5. **`null` is preserved**, because `notes: null` and an absent `notes` are\n *    both legal and both mean \"no note\" \u2014 but `null` survives a JSON round trip\n *    and `undefined` does not, so keeping `null` is what makes the round trip\n *    lossless.\n *\n * ## Why not JCS (RFC 8785)\n *\n * JCS is the standards-track answer and would be the right call if the payload\n * were ever exchanged with a third party's implementation. It is not: both ends\n * are this repository. JCS's remaining substance over the four rules above is\n * number canonicalisation, and the payload contains exactly two numbers, both\n * small non-negative integers, for which every JSON encoder in existence agrees.\n * Pulling in a dependency \u2014 into a bundle that ships to customer\n * infrastructure \u2014 to canonicalise `1` was not a trade worth making.\n *\n * If the payload ever grows a float, revisit this. The comment is here so that\n * decision is a decision rather than an accident.\n * ---------------------------------------------------------------------------\n */\n\ntype Json = string | number | boolean | null | Json[] | { [key: string]: Json };\n\n/**\n * Recursively rebuild a value with object keys in sorted order.\n *\n * Note the array branch preserves order and the primitive branch is the\n * identity \u2014 the sort applies to objects and nothing else.\n */\nconst sortValue = (value: unknown, seen: WeakSet<object>): unknown => {\n  if (Array.isArray(value)) {\n    // The cycle guard is checked here as well as on objects, because an array\n    // that contains itself is just as recursive and just as fatal.\n    if (seen.has(value)) {\n      throw new TypeError('circular reference');\n    }\n\n    seen.add(value);\n    const mapped = value.map((entry) => sortValue(entry, seen));\n    seen.delete(value);\n\n    return mapped;\n  }\n\n  if (typeof value === 'object' && value !== null) {\n    // Without this, a cycle recurses until the stack is exhausted and the\n    // `RangeError` is what `canonicalise` ends up catching. That happens to\n    // produce the right answer \u2014 `null` \u2014 but by accident, at the cost of\n    // however deep the runtime's stack is, and it is not a behaviour worth\n    // relying on inside a nightly cron job. `delete` after the descent so a\n    // value legitimately appearing twice in a *tree* is not mistaken for a\n    // cycle.\n    if (seen.has(value)) {\n      throw new TypeError('circular reference');\n    }\n\n    seen.add(value);\n\n    const source = value as Record<string, unknown>;\n    const sorted: Record<string, unknown> = {};\n\n    for (const key of Object.keys(source).sort()) {\n      const entry = source[key];\n\n      // Dropped rather than emitted as `null`: `JSON.stringify` drops\n      // `undefined` properties too, and the two must agree or a payload that\n      // has been through one `JSON.parse` would canonicalise differently from\n      // the same payload in memory.\n      if (entry !== undefined) {\n        sorted[key] = sortValue(entry, seen);\n      }\n    }\n\n    seen.delete(value);\n\n    return sorted;\n  }\n\n  return value;\n};\n\n/**\n * The canonical UTF-8 string for a payload.\n *\n * Returns `null` rather than throwing when the value cannot be represented \u2014\n * a circular reference, or a `BigInt`. Neither can occur in a payload that\n * arrived as parsed JSON, but this function is also called by the signing\n * script on hand-authored input, and a thrown error inside the nightly\n * verification path would be a cron run that dies rather than falls back.\n */\nexport const canonicalise = (value: unknown): string | null => {\n  try {\n    const serialised = JSON.stringify(sortValue(value, new WeakSet()) as Json);\n\n    return typeof serialised === 'string' ? serialised : null;\n  } catch {\n    return null;\n  }\n};\n\n/**\n * The canonical bytes. Split from `canonicalise` only so the verifier can hash\n * without a second UTF-8 conversion, and so tests can assert on the string.\n */\nexport const canonicalBytes = (value: unknown): Uint8Array | null => {\n  const serialised = canonicalise(value);\n\n  return serialised === null ? null : new TextEncoder().encode(serialised);\n};\n", "/**\n * Resolving \"am I running shipped defaults or calibration vNN, and when did it\n * last refresh?\" \u2014 one pure function, `now` injected, no I/O.\n *\n * ===========================================================================\n * ## The same ladder as the entitlement, for the same reasons\n *\n * Calibration is cached beside the entitlement in workspace key-value storage\n * and walks the identical 24h / 72h freshness ladder from\n * `src/licensing/cache.ts`. Sharing the arithmetic is not laziness \u2014 the two\n * caches are refreshed by the *same nightly run*, so any second ladder would\n * differ from this one only by drifting out of step with it.\n *\n * Where the two differ is what the far end of the ladder means, and the\n * difference is the whole point:\n *\n *   | Age        | Entitlement                  | Calibration                 |\n *   |------------|------------------------------|-----------------------------|\n *   | `< 24h`    | used as-is                   | used as-is                  |\n *   | `24\u201372h`   | rules-only (\"grace\")         | **still used**              |\n *   | `> 72h`    | rules-only + loud warning    | shipped defaults            |\n *\n * The entitlement tightens at 24h because trusting a stale one risks serving a\n * paid feature to a revoked licence, and revocation has to work. Calibration\n * carries no such risk: it is a word list. Dropping it the moment Numaya has a\n * bad night would make a customer's scores move for a reason that has nothing to\n * do with their data, which is a worse outcome than a slightly old vocabulary.\n * So calibration survives the grace window and is only abandoned past 72h, at\n * which point \"we have not spoken to Numaya in three days\" is a real statement\n * about the install and the admin should be seeing shipped-default behaviour\n * they can reason about.\n *\n * Note the asymmetry is safe in both directions: past 72h calibration falls back\n * to the shipped defaults, which is a *working product*, not a degraded one.\n * There is no branch below that can stop a lead being scored.\n * ===========================================================================\n */\n\nimport { classifyCache } from 'src/licensing/cache';\nimport {\n  type CachedCalibration,\n  type Calibration,\n  type CalibrationCounts,\n  type CalibrationReason,\n  type CalibrationState,\n} from 'src/calibration/types';\n\nexport const countCalibration = (\n  calibration: Calibration,\n): CalibrationCounts => ({\n  decisionMakerTitles: calibration.decisionMakerTitles.length,\n  influencerTitles: calibration.influencerTitles.length,\n  roleInboxLocalParts: calibration.roleInboxLocalParts.length,\n  placeholderValues: calibration.placeholderValues.length,\n  industrySynonyms: Object.keys(calibration.industrySynonyms).length,\n});\n\n/**\n * The state to publish when no usable calibration exists.\n *\n * Every field that describes a payload is `null` rather than zero or empty\n * string: \"there is no calibration\" and \"there is a calibration with nothing in\n * it\" must not render the same in the admin panel, and a zero count is exactly\n * how the second one would look.\n */\nexport const shippedDefaultsState = (\n  reason: CalibrationReason,\n  now: Date,\n): CalibrationState => ({\n  status: 'shipped_defaults',\n  reason,\n  source: 'none',\n  calibrationVersion: null,\n  issuedAt: null,\n  refreshedAt: null,\n  checkedAt: now.toISOString(),\n  cacheAgeMs: null,\n  keyId: null,\n  counts: null,\n});\n\nexport const calibratedState = (\n  entry: CachedCalibration,\n  source: 'live' | 'cache',\n  cacheAgeMs: number | null,\n  now: Date,\n): CalibrationState => ({\n  status: 'calibrated',\n  reason: 'calibrated',\n  source,\n  calibrationVersion: entry.calibration.calibrationVersion,\n  issuedAt: entry.calibration.issuedAt.length > 0 ? entry.calibration.issuedAt : null,\n  refreshedAt: entry.verifiedAt,\n  checkedAt: now.toISOString(),\n  cacheAgeMs,\n  keyId: entry.keyId,\n  counts: countCalibration(entry.calibration),\n});\n\n/**\n * Age at which a cached calibration stops being used. Deliberately the\n * entitlement's *outer* limit, not its inner one \u2014 see the table above.\n */\nexport const CALIBRATION_MAX_AGE_MS = 72 * 60 * 60 * 1000;\n\nexport interface ResolveCalibrationInput {\n  /** The cached payload, or `null` when none has ever been stored. */\n  readonly cached: CachedCalibration | null;\n  readonly now: Date;\n}\n\nexport interface ResolvedCalibration {\n  readonly state: CalibrationState;\n  /** The payload the scoring path should use, or `null` for shipped defaults. */\n  readonly calibration: Calibration | null;\n}\n\n/**\n * What the scoring path should use right now, and what the admin should be told.\n *\n * ===========================================================================\n * ## Why there is no entitlement check here\n *\n * Because the *existence of the cache is* the entitlement check, and moving it\n * to the writer is what keeps a licence lookup out of the per-lead scoring path.\n *\n * `refreshCalibration` writes the cache only while the licence resolves to\n * `full`, and **deletes it** the moment a nightly run finds the entitlement\n * gone. So a present, fresh cache already means \"this workspace was entitled at\n * its last successful licence check\". Re-deriving that per lead would mean a\n * second key-value read on the hot path to re-establish a fact the nightly run\n * has already written down.\n *\n * The consequence is a revocation latency of at most 24 hours \u2014 one nightly\n * cycle \u2014 which is exactly the latency enrichment revocation already has and is\n * documented as having, for the same reason: the alternative is putting a\n * network call to Numaya in front of a customer's scoring path, which is the\n * coupling the fail-open rule exists to prevent.\n *\n * The reverse case costs the customer one night. A renewed licence re-fetches on\n * the next run, and until then the workspace scores on shipped defaults \u2014 the\n * full working product, exactly as an unlicensed install always has.\n * ===========================================================================\n */\nexport const resolveCalibration = (\n  input: ResolveCalibrationInput,\n): ResolvedCalibration => {\n  if (input.cached === null) {\n    return {\n      state: shippedDefaultsState('not_provisioned', input.now),\n      calibration: null,\n    };\n  }\n\n  const { ageMs } = classifyCache(input.cached.cachedAt, input.now);\n\n  // An unreadable `cachedAt` is treated as expired rather than as fresh. The\n  // opposite choice would make a corrupt timestamp mean \"trust this forever\",\n  // which is the one thing a freshness check must never be talked into.\n  if (ageMs === null || ageMs >= CALIBRATION_MAX_AGE_MS) {\n    return {\n      state: {\n        ...shippedDefaultsState('stale', input.now),\n        cacheAgeMs: ageMs,\n        calibrationVersion: input.cached.calibration.calibrationVersion,\n        keyId: input.cached.keyId,\n      },\n      calibration: null,\n    };\n  }\n\n  return {\n    state: calibratedState(\n      input.cached,\n      ageMs === 0 ? 'live' : 'cache',\n      ageMs,\n      input.now,\n    ),\n    calibration: input.cached.calibration,\n  };\n};\n", "/**\n * The calibration half of a licence run: read what the `validate` response\n * carried, verify it, cache it, publish what an admin should see.\n *\n * ===========================================================================\n * ## Why this rides on the existing nightly revalidation\n *\n * It costs nothing. `runLicenceRevalidation` already calls\n * `POST /v1/licenses/validate` once a night at 03:17 UTC, and the response\n * already carries `customerMetadata` \u2014 the calibration arrives in bytes we were\n * fetching anyway. There is no second endpoint, no second credential, no second\n * timeout to tune, and no new failure mode: a run that could not reach Numaya\n * could not have fetched calibration either, and both fall back together.\n *\n * That was not the original plan. The plan was `GET /v1/licenses/{id}/config`,\n * which is the endpoint built for exactly this and which Greenlight cannot call\n * \u2014 it refuses licence-key credentials by design. `src/calibration/types.ts`\n * has the measurements and the service's own documentation of that refusal.\n *\n * ## Ordering: entitlement first, always\n *\n * `refreshCalibration` runs *after* the licence state is resolved and published,\n * and takes the resolved entitlement as an input. Two reasons, and the second is\n * the load-bearing one:\n *\n *  1. An unentitled licence should not have its calibration refreshed, and\n *     asking the entitlement is how we know.\n *  2. **Nothing in this file may be able to delay or fail the entitlement.**\n *     Enrichment gating, the audit row and the admin notice all depend on the\n *     licence state being published; a signature verification that hung or threw\n *     ahead of it would turn a word list into a dependency of the paid feature.\n *     Running afterwards makes that structurally impossible rather than merely\n *     unlikely.\n *\n * ## Every path ends in a published state\n *\n * Including the paths that fail. An admin who cannot tell the difference between\n * \"calibration is off\" and \"calibration broke and nobody said\" has been given\n * nothing, so `not_provisioned`, `signature_invalid`, `unknown_key` and\n * `verifier_unavailable` are all published as distinct reasons \u2014 even though all\n * four behave identically, which is to say the product keeps working on shipped\n * defaults.\n * ===========================================================================\n */\n\nimport { canonicalise } from 'src/calibration/canonical';\nimport { readCalibrationEnvelope } from 'src/calibration/parse';\nimport { NO_SEAL, type CalibrationSealPort } from 'src/calibration/seal';\nimport {\n  calibratedState,\n  countCalibration,\n  resolveCalibration,\n  shippedDefaultsState,\n} from 'src/calibration/state';\nimport {\n  type CachedCalibration,\n  type CalibrationState,\n  type CalibrationStorePort,\n  type SealedCalibrationBody,\n} from 'src/calibration/types';\nimport { verifyCalibrationEnvelope } from 'src/calibration/verify';\n\n/**\n * The canonical bytes a cache entry's seal covers.\n *\n * Shared by the writer here and the reader in `scoring-run.ts` \u2014 one function,\n * so the two cannot disagree about what is inside the MAC. `canonicalise`\n * sorts keys recursively, which is what makes the tag survive the round trip\n * through the workspace's key-value store.\n */\nexport const sealedCalibrationBody = (\n  body: SealedCalibrationBody,\n): string | null =>\n  canonicalise({\n    cachedAt: body.cachedAt,\n    verifiedAt: body.verifiedAt,\n    keyId: body.keyId,\n    calibration: body.calibration,\n  });\n\nexport interface RefreshCalibrationInput {\n  readonly store: CalibrationStorePort;\n  /**\n   * Binds the cached copy to this workspace's licence key. Defaults to\n   * `NO_SEAL`, which cannot produce a tag \u2014 and an entry that cannot be sealed\n   * is not written at all, so the default is \"no cache\" rather than \"a cache\n   * nothing checks\".\n   */\n  readonly seal?: CalibrationSealPort;\n  /**\n   * `customerMetadata` from the live `validate` response, or `undefined` when\n   * the run had no live response at all \u2014 an outage, or no licence key.\n   */\n  readonly metadata: unknown;\n  /** Whether a live answer was received. `false` means \"do not touch the cache\". */\n  readonly live: boolean;\n  /** The resolved entitlement: `state.mode === 'full'`. */\n  readonly entitled: boolean;\n  readonly now: Date;\n}\n\nexport interface RefreshCalibrationOutcome {\n  readonly state: CalibrationState;\n  /** Non-null only when a fresh payload was verified and written this run. */\n  readonly written: CachedCalibration | null;\n  /** For the structured log line. Never contains payload content. */\n  readonly detail: string | null;\n}\n\n/**\n * Fetch-verify-cache, as one function with no exceptions and no clock read.\n *\n * ## Why an unentitled run clears the cache\n *\n * This is the one place the paid boundary is enforced, and it is enforced by\n * deletion rather than by a flag. The scoring path then needs no entitlement\n * check of its own: a cache that exists is a cache that was written while the\n * licence resolved to `full`. See `src/calibration/state.ts`, \"Why there is no\n * entitlement check here\", for why keeping a licence lookup out of the per-lead\n * path is worth a deletion.\n *\n * The cost is that a licence restored after a lapse waits one nightly cycle\n * before calibration returns. That is a day of shipped-default scoring \u2014 the\n * full working product \u2014 against the alternative of a workspace keeping a paid\n * vocabulary for three days after it stopped paying for it.\n *\n * ## Why a failed verification does *not* clear the cache\n *\n * A payload that arrives corrupted is evidence about *that response*, not about\n * the payload verified last night. Discarding a good cached calibration because\n * a proxy mangled one nightly response would let a single bad night undo a\n * working install. The bad payload is refused, the reason is published, and the\n * previously verified cache continues to age out on its own 72-hour clock \u2014 so\n * a genuinely revoked or permanently-broken calibration still expires, it just\n * does not vanish on the first hiccup.\n */\nexport const refreshCalibration = async (\n  input: RefreshCalibrationInput,\n): Promise<RefreshCalibrationOutcome> => {\n  if (!input.entitled) {\n    await clearQuietly(input.store);\n\n    const state = shippedDefaultsState('not_licensed', input.now);\n    await publish(input.store, state);\n\n    return { state, written: null, detail: null };\n  }\n\n  if (!input.live) {\n    // No live answer: nothing new to say about calibration, so republish what\n    // the cache currently amounts to. Publishing a *failure* here would report\n    // the outage twice \u2014 the licence state already says it \u2014 and would blank the\n    // version number the admin panel is showing.\n    //\n    // The state is derived through `resolveCalibration`, the same function the\n    // scoring path uses, rather than assembled here. That is the whole point:\n    // a cache past 72h is no longer applied to leads, and a panel that said\n    // \"calibration v1\" while the engine was quietly on shipped defaults would be\n    // worse than a panel that said nothing. One function, one answer.\n    const cached = await readQuietly(input.store);\n    const { state } = resolveCalibration({ cached, now: input.now });\n\n    await publish(input.store, state);\n\n    return { state, written: null, detail: null };\n  }\n\n  const read = readCalibrationEnvelope(input.metadata);\n\n  if (read.kind === 'rejected') {\n    const state = shippedDefaultsState(read.reason, input.now);\n    await publish(input.store, state);\n\n    return { state, written: null, detail: read.detail };\n  }\n\n  const verification = await verifyCalibrationEnvelope(read.envelope);\n\n  if (verification.kind === 'rejected') {\n    const state = shippedDefaultsState(verification.reason, input.now);\n    await publish(input.store, state);\n\n    return { state, written: null, detail: verification.detail };\n  }\n\n  const body: SealedCalibrationBody = {\n    cachedAt: input.now.toISOString(),\n    verifiedAt: input.now.toISOString(),\n    keyId: read.envelope.keyId,\n    calibration: verification.calibration,\n  };\n\n  const canonical = sealedCalibrationBody(body);\n  const sealTag =\n    canonical === null ? null : await (input.seal ?? NO_SEAL).seal(canonical);\n\n  // No tag, no cache. Writing an unsealed entry would mean a subsequent read\n  // either has to accept it \u2014 defeating the seal entirely \u2014 or reject it, which\n  // is what happens anyway. Not writing is the same outcome with one fewer\n  // shape in the store.\n  if (sealTag === null) {\n    const state = shippedDefaultsState('cache_unsealed', input.now);\n    await publish(input.store, state);\n\n    return {\n      state,\n      written: null,\n      detail: 'calibration verified but could not be sealed to this licence key',\n    };\n  }\n\n  const entry: CachedCalibration = { ...body, sealTag };\n\n  await writeQuietly(input.store, entry);\n\n  const state = calibratedState(entry, 'live', 0, input.now);\n  await publish(input.store, state);\n\n  return {\n    state,\n    written: entry,\n    detail: `calibration v${verification.calibration.calibrationVersion} verified against ${read.envelope.keyId}`,\n  };\n};\n\n/**\n * A count summary safe to put in a log line.\n *\n * The payload itself is never logged: it is a few hundred kilobytes of word\n * lists, and a nightly cron that dumps it into the platform's log stream would\n * be indistinguishable from a bug.\n */\nexport const describeCalibration = (\n  outcome: RefreshCalibrationOutcome,\n): Record<string, unknown> => ({\n  calibrationStatus: outcome.state.status,\n  calibrationReason: outcome.state.reason,\n  calibrationSource: outcome.state.source,\n  calibrationVersion: outcome.state.calibrationVersion,\n  calibrationKeyId: outcome.state.keyId,\n  calibrationRefreshedAt: outcome.state.refreshedAt,\n  ...(outcome.written === null\n    ? {}\n    : { calibrationCounts: countCalibration(outcome.written.calibration) }),\n  ...(outcome.detail === null ? {} : { calibrationDetail: outcome.detail }),\n});\n\n/* -------------------------------------------------------------------------- */\n/* Storage, swallowed                                                          */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Storage failures are absorbed here rather than at the adapter, so that a\n * *test double* that throws is handled identically to the real store, which\n * logs and returns. A calibration cache is a convenience; failing a licence run\n * over one would be trading the load-bearing thing for the optional one.\n */\nconst readQuietly = async (\n  store: CalibrationStorePort,\n): Promise<CachedCalibration | null> => {\n  try {\n    return await store.readCalibration();\n  } catch {\n    return null;\n  }\n};\n\nconst writeQuietly = async (\n  store: CalibrationStorePort,\n  entry: CachedCalibration,\n): Promise<void> => {\n  try {\n    await store.writeCalibration(entry);\n  } catch {\n    // Swallowed: the state published below still says what was verified, and\n    // the next run re-verifies from the same source.\n  }\n};\n\n/**\n * A clear that fails leaves a workspace calibrated for up to another 72 hours,\n * after which the age check in `resolveCalibration` retires it regardless. So\n * the failure is bounded by the freshness ladder rather than open-ended, and\n * failing the licence run over it would trade a bounded problem for an\n * unbounded one.\n */\nconst clearQuietly = async (store: CalibrationStorePort): Promise<void> => {\n  try {\n    await store.clearCalibration();\n  } catch {\n    // Swallowed. See above.\n  }\n};\n\nconst publish = async (\n  store: CalibrationStorePort,\n  state: CalibrationState,\n): Promise<void> => {\n  try {\n    await store.publishCalibrationState(state);\n  } catch {\n    // Swallowed for the same reason. The admin panel shows a stale state for a\n    // night; nothing about scoring changes.\n  }\n};\n", "/**\n * The enrichable field catalogue: what may be asked for, in what shape.\n *\n * One table, read by three consumers that must not disagree \u2014 the prompt (what\n * the model is asked), the extractor (what is accepted back) and the gap\n * analysis (what is worth asking about at all). Keeping them keyed off the same\n * array is what stops the classic drift where a field is prompted for and then\n * silently discarded, or accepted without ever being requested.\n *\n * Every entry answers a *firmographic* question. Nothing here is a contact\n * detail: see the note on `EnrichableFieldKey` for why that boundary is a hard\n * one rather than a starting point.\n */\n\nimport type {\n  EnrichableFieldKey,\n  EnrichableFieldSpec,\n} from 'src/enrichment/types';\n\nexport const ENRICHABLE_FIELD_SPECS: readonly EnrichableFieldSpec[] = [\n  {\n    key: 'industry',\n    label: 'Industry',\n    question: \"What industry does this person's employer operate in?\",\n    kind: 'text',\n    maxLength: 60,\n  },\n  {\n    key: 'region',\n    label: 'Region',\n    question: 'Which country or region is the employer headquartered in?',\n    kind: 'text',\n    maxLength: 60,\n  },\n  {\n    key: 'employeeCount',\n    label: 'Employee count',\n    question: 'Approximately how many people does the employer employ?',\n    kind: 'integer',\n    maxLength: 12,\n  },\n  {\n    key: 'jobTitle',\n    label: 'Job title',\n    question: 'What is this person\u2019s job title at that employer?',\n    kind: 'text',\n    maxLength: 120,\n  },\n  {\n    key: 'seniority',\n    label: 'Seniority',\n    question:\n      'What seniority level does that job title correspond to (for example: C-level, VP, Director, Manager, Individual contributor)?',\n    kind: 'text',\n    maxLength: 40,\n  },\n];\n\nconst SPEC_BY_KEY: ReadonlyMap<string, EnrichableFieldSpec> = new Map(\n  ENRICHABLE_FIELD_SPECS.map((spec) => [spec.key, spec]),\n);\n\nexport const findFieldSpec = (key: string): EnrichableFieldSpec | null =>\n  SPEC_BY_KEY.get(key) ?? null;\n\nexport const isEnrichableFieldKey = (key: unknown): key is EnrichableFieldKey =>\n  typeof key === 'string' && SPEC_BY_KEY.has(key);\n\n/**\n * The dotted paths a workspace adds to its Layer 3 field mapping to let the\n * deterministic scorer read enriched values.\n *\n * Published from here rather than hard-coded in the config seed because the\n * shape of the provenance blob is this module's business, and a path written out\n * by hand somewhere else is a path that goes stale the first time the blob's\n * version changes.\n *\n * The ordering is the important part: the enriched path goes **after** the\n * workspace's own candidates in every mapping, never before. `field-access.ts`\n * tries candidates in order and takes the first that yields a value, so a human\n * value always wins and enrichment only ever fills a hole. That is the same\n * promise the storage shape makes \u2014 enrichment never overwrites a person \u2014 held\n * at the read side as well as the write side.\n */\nexport const enrichedFieldMappingPath = (key: EnrichableFieldKey): string =>\n  `greenlightEnrichment.fields.${key}.parsedValue`;\n\nexport const ENRICHED_FIELD_MAPPING_PATHS: Readonly<\n  Record<EnrichableFieldKey, string>\n> = Object.freeze(\n  Object.fromEntries(\n    ENRICHABLE_FIELD_SPECS.map((spec) => [\n      spec.key,\n      enrichedFieldMappingPath(spec.key),\n    ]),\n  ) as Record<EnrichableFieldKey, string>,\n);\n", "/**\n * Seeded defaults.\n *\n * \"Defaults are the feature.\" A configurable product that ships empty is a\n * homework assignment \u2014 these values are what the post-install hook writes into\n * the config record, and they are also the fall-back the engine uses whenever\n * configuration is missing or unusable.\n *\n * The ICP lists start empty on purpose: an empty list means \"no opinion\", so a\n * fresh install is permissive and nothing is gated for being in the wrong\n * industry before an admin has said what the right industry is.\n */\n\nimport type {\n  FieldMapping,\n  IcpConfig,\n  ScoringBand,\n} from 'src/scoring/types';\n\n/**\n * Default paths into the lead record, tried in order. These are defaults only \u2014\n * rule logic never mentions a field name, it asks for a logical key and the\n * mapping decides where that comes from.\n */\nexport const DEFAULT_FIELD_MAPPING: FieldMapping = {\n  companyName: ['companyName', 'company.name', 'company', 'accountName'],\n  industry: ['industry', 'company.industry', 'sector'],\n  region: ['region', 'country', 'address.addressCountry', 'company.region'],\n  employeeCount: ['employees', 'employeeCount', 'company.employees', 'companySize'],\n  contactName: ['name', 'fullName', 'contactName', 'firstName'],\n  // `position` is deliberately NOT a candidate. On Twenty \u2014 the only platform\n  // this ships on \u2014 `position` is the row-ordering number, not a job title, so\n  // the fallback resolved a real value of `-5` and handed it to the\n  // decision-maker rule as somebody's role. It was visible in a demo recording\n  // before it was visible in a test.\n  //\n  // The subtler half: `src/enrichment/plan.ts` reads this same mapping to decide\n  // whether a human has already answered a field. A resolvable `position` meant\n  // every Twenty Person looked like it already had a job title, so job-title\n  // enrichment could never fire at all.\n  //\n  // A workspace that genuinely stores titles in a field called `position` can\n  // still say so through the Layer 3 mapping. Guessing it by default costs more\n  // than it ever paid.\n  jobTitle: ['jobTitle', 'title', 'role'],\n  seniority: ['seniority', 'seniorityLevel'],\n  email: ['emails', 'email', 'emails.primaryEmail', 'workEmail'],\n  phone: ['phones', 'phone', 'phones.primaryPhoneNumber', 'mobile'],\n  lastVerifiedAt: ['lastVerifiedAt', 'verifiedAt', 'updatedAt', 'createdAt'],\n\n  // Greenlight's own suppression columns. Single-candidate and not extended by\n  // the Layer 3 mapping, unlike every other key here: these are fields the app\n  // ships and owns, so \"where does this live\" has exactly one answer. A\n  // workspace's *own* opt-out columns are `optedOut` below, and the compliance\n  // rule takes the union of the two rather than letting either win.\n  suppressed: ['greenlightSuppressed'],\n  suppressionReason: ['greenlightSuppressionReason'],\n\n  optedOut: ['optedOut', 'doNotContact', 'emailOptOut', 'unsubscribed'],\n};\n\n/** Permissive by default: no industry/region/size opinion until an admin sets one. */\nexport const DEFAULT_ICP: IcpConfig = {\n  industries: [],\n  regions: [],\n  sizeBands: [],\n};\n\n/**\n * Evenly-spaced neutral bands. Published in full in the scoring-model explainer;\n * a scoring product that hides its model does not get trusted by the people\n * whose leads it rejects.\n */\nexport const DEFAULT_BANDS: readonly ScoringBand[] = [\n  { id: 'excellent', label: 'Excellent', minScore: 85 },\n  { id: 'good', label: 'Good', minScore: 70 },\n  { id: 'fair', label: 'Fair', minScore: 50 },\n  { id: 'poor', label: 'Poor', minScore: 0 },\n];\n\n/** The floor of the \"Fair\" band: fair and above is cleared to work. */\nexport const DEFAULT_GATE_THRESHOLD = 50;\n\nexport const DEFAULT_SHELF_LIFE_DAYS = 30;\n\nexport const DEFAULT_DECISION_MAKER_TITLES: readonly string[] = [\n  'ceo',\n  'cto',\n  'cfo',\n  'coo',\n  'cmo',\n  'ciso',\n  'cio',\n  'chief',\n  'founder',\n  'co-founder',\n  'cofounder',\n  'owner',\n  'proprietor',\n  'president',\n  'partner',\n  'principal',\n  'vp',\n  'vice president',\n  'svp',\n  'evp',\n  'head of',\n  'director',\n  'managing director',\n  'general manager',\n  'board member',\n];\n\nexport const DEFAULT_INFLUENCER_TITLES: readonly string[] = [\n  'manager',\n  'lead',\n  'team lead',\n  'supervisor',\n  'architect',\n  'consultant',\n  'coordinator',\n  'buyer',\n  'procurement',\n];\n\nexport const DEFAULT_ROLE_INBOX_LOCAL_PARTS: readonly string[] = [\n  'info',\n  'sales',\n  'support',\n  'admin',\n  'contact',\n  'hello',\n  'hi',\n  'office',\n  'enquiries',\n  'enquiry',\n  'inquiries',\n  'inquiry',\n  'marketing',\n  'help',\n  'billing',\n  'accounts',\n  'accounting',\n  'finance',\n  'careers',\n  'jobs',\n  'hr',\n  'team',\n  'mail',\n  'general',\n  'noreply',\n  'no-reply',\n  'donotreply',\n  'webmaster',\n  'postmaster',\n  'abuse',\n];\n\n/** Values that mean \"somebody typed something rather than nothing\". */\nexport const PLACEHOLDER_VALUES: readonly string[] = [\n  '-',\n  '--',\n  '.',\n  'n/a',\n  'na',\n  'n.a.',\n  'none',\n  'null',\n  'nil',\n  'unknown',\n  'tbd',\n  'tba',\n  'test',\n  'testing',\n  'asdf',\n  'xxx',\n  '???',\n  'no name',\n  'not provided',\n  'not set',\n];\n", "/**\n * Reading values out of a lead record.\n *\n * Two problems are solved here, both of them schema-flexibility problems:\n *\n * 1. Customers name fields differently, so every read goes through the\n *    configured mapping (a list of candidate dotted paths, tried in order).\n * 2. CRM fields are often composite objects (`{ primaryEmail, additionalEmails }`,\n *    `{ firstName, lastName }`). Values are flattened generically by walking\n *    string leaves in key order \u2014 no field name is hard-coded anywhere.\n */\n\nimport { PLACEHOLDER_VALUES } from 'src/scoring/defaults';\nimport type {\n  FieldMapping,\n  FieldObservation,\n  FieldReader,\n  LeadFieldKey,\n  LeadRecord,\n} from 'src/scoring/types';\n\nconst MAX_LEAF_DEPTH = 4;\n\n/** Fail-open coercion of anything the caller has into a `LeadRecord`. */\nexport const toLeadRecord = (record: unknown): LeadRecord => {\n  if (!isPlainObject(record)) {\n    return { id: null, fields: {} };\n  }\n\n  const id = typeof record['id'] === 'string' ? record['id'] : null;\n\n  return { id, fields: record };\n};\n\nexport const isPlainObject = (\n  value: unknown,\n): value is Record<string, unknown> =>\n  typeof value === 'object' &&\n  value !== null &&\n  !Array.isArray(value) &&\n  !(value instanceof Date);\n\n/**\n * Resolve a dotted path against an object. Exact key match first, then a\n * case-insensitive match, so `address.addresscountry` still finds\n * `address.addressCountry`.\n */\nexport const getByPath = (source: unknown, path: string): unknown => {\n  const segments = path.split('.').filter((segment) => segment.length > 0);\n\n  let cursor: unknown = source;\n\n  for (const segment of segments) {\n    if (cursor === null || cursor === undefined) {\n      return undefined;\n    }\n\n    if (Array.isArray(cursor)) {\n      const index = Number(segment);\n      cursor = Number.isInteger(index) ? cursor[index] : undefined;\n      continue;\n    }\n\n    if (!isPlainObject(cursor)) {\n      return undefined;\n    }\n\n    if (segment in cursor) {\n      cursor = cursor[segment];\n      continue;\n    }\n\n    const lowered = segment.toLowerCase();\n    const matchedKey = Object.keys(cursor).find(\n      (key) => key.toLowerCase() === lowered,\n    );\n\n    cursor = matchedKey === undefined ? undefined : cursor[matchedKey];\n  }\n\n  return cursor;\n};\n\n/** Every non-empty string leaf under a value, in key order. */\nexport const stringLeaves = (value: unknown, depth = 0): string[] => {\n  if (depth > MAX_LEAF_DEPTH) {\n    return [];\n  }\n\n  if (typeof value === 'string') {\n    const trimmed = value.trim();\n    return trimmed.length > 0 ? [trimmed] : [];\n  }\n\n  if (typeof value === 'number' && Number.isFinite(value)) {\n    return [String(value)];\n  }\n\n  if (Array.isArray(value)) {\n    return value.flatMap((entry) => stringLeaves(entry, depth + 1));\n  }\n\n  if (value instanceof Date) {\n    return Number.isNaN(value.getTime()) ? [] : [value.toISOString()];\n  }\n\n  if (isPlainObject(value)) {\n    return Object.keys(value).flatMap((key) =>\n      stringLeaves(value[key], depth + 1),\n    );\n  }\n\n  return [];\n};\n\nconst isEmptyValue = (value: unknown): boolean =>\n  value === null ||\n  value === undefined ||\n  (typeof value === 'string' && value.trim().length === 0) ||\n  (Array.isArray(value) && value.length === 0) ||\n  (typeof value === 'number' && Number.isNaN(value)) ||\n  (isPlainObject(value) && stringLeaves(value).length === 0);\n\n/**\n * Whether a value is one of the strings that mean \"somebody typed something\n * rather than nothing\" \u2014 `n/a`, `tbd`, `xxx`, `keine angabe`.\n *\n * `known` defaults to the shipped list so every existing caller keeps its exact\n * behaviour. A rule that has a resolved config passes `config.placeholderValues`\n * instead, which is how a licence-delivered lexicon reaches this check without\n * the rule learning anything about licensing: the list is data, resolved by\n * `resolveConfig`, exactly like `decisionMakerTitles` already was.\n */\nexport const isPlaceholder = (\n  value: string,\n  known: readonly string[] = PLACEHOLDER_VALUES,\n): boolean => known.includes(value.trim().toLowerCase());\n\nexport const toNumberValue = (value: unknown): number | null => {\n  if (typeof value === 'number') {\n    return Number.isFinite(value) ? value : null;\n  }\n\n  if (typeof value === 'boolean') {\n    return null;\n  }\n\n  const leaves = stringLeaves(value);\n\n  for (const leaf of leaves) {\n    // Tolerate \"1,200\", \"1 200\", \"250+\", \"50-200\" (takes the lower bound).\n    const cleaned = leaf.replace(/[,\\s]/g, '');\n    const match = /-?\\d+(\\.\\d+)?/.exec(cleaned);\n\n    if (match !== null) {\n      const parsed = Number(match[0]);\n\n      if (Number.isFinite(parsed)) {\n        return parsed;\n      }\n    }\n  }\n\n  return null;\n};\n\nexport const toDateValue = (value: unknown): Date | null => {\n  if (value instanceof Date) {\n    return Number.isNaN(value.getTime()) ? null : value;\n  }\n\n  if (typeof value === 'number' && Number.isFinite(value)) {\n    const fromEpoch = new Date(value);\n    return Number.isNaN(fromEpoch.getTime()) ? null : fromEpoch;\n  }\n\n  const leaves = stringLeaves(value);\n\n  for (const leaf of leaves) {\n    const parsed = new Date(leaf);\n\n    if (!Number.isNaN(parsed.getTime())) {\n      return parsed;\n    }\n  }\n\n  return null;\n};\n\nconst TRUTHY_TOKENS = new Set([\n  'true',\n  'yes',\n  'y',\n  '1',\n  'opted_out',\n  'opted-out',\n  'optedout',\n  'unsubscribed',\n  'do_not_contact',\n  'do-not-contact',\n  'donotcontact',\n  'dnc',\n  'blocked',\n]);\n\nconst FALSY_TOKENS = new Set([\n  'false',\n  'no',\n  'n',\n  '0',\n  'subscribed',\n  'opted_in',\n  'opted-in',\n  'optedin',\n]);\n\nexport const toBooleanValue = (value: unknown): boolean | null => {\n  if (typeof value === 'boolean') {\n    return value;\n  }\n\n  if (typeof value === 'number' && Number.isFinite(value)) {\n    return value !== 0;\n  }\n\n  const leaves = stringLeaves(value);\n\n  for (const leaf of leaves) {\n    const token = leaf.toLowerCase();\n\n    if (TRUTHY_TOKENS.has(token)) {\n      return true;\n    }\n\n    if (FALSY_TOKENS.has(token)) {\n      return false;\n    }\n  }\n\n  return null;\n};\n\nconst renderDisplay = (value: unknown): string => {\n  if (typeof value === 'boolean') {\n    return value ? 'true' : 'false';\n  }\n\n  const leaves = stringLeaves(value);\n\n  if (leaves.length === 0) {\n    return '(not set)';\n  }\n\n  return leaves.slice(0, 3).join(', ');\n};\n\ninterface Resolution {\n  readonly mappedTo: string | null;\n  readonly candidates: readonly string[];\n  readonly value: unknown;\n  readonly present: boolean;\n}\n\n/**\n * Builds the reader handed to rules. Every lookup is recorded, so a trace entry\n * can tell a salesperson exactly which field was consulted and what was in it.\n */\nexport const createFieldReader = (\n  lead: LeadRecord,\n  mapping: FieldMapping,\n): FieldReader => {\n  const seen = new Map<LeadFieldKey, FieldObservation>();\n\n  const candidatesFor = (key: LeadFieldKey): readonly string[] => {\n    const configured = mapping[key];\n    return Array.isArray(configured) ? configured : [];\n  };\n\n  const resolveAll = (key: LeadFieldKey): Resolution[] => {\n    const candidates = candidatesFor(key);\n\n    return candidates.map((path) => {\n      const value = getByPath(lead.fields, path);\n\n      return {\n        mappedTo: path,\n        candidates,\n        value,\n        present: !isEmptyValue(value),\n      };\n    });\n  };\n\n  const resolve = (key: LeadFieldKey): Resolution => {\n    const candidates = candidatesFor(key);\n    const found = resolveAll(key).find((entry) => entry.present);\n\n    if (found !== undefined) {\n      return found;\n    }\n\n    return { mappedTo: null, candidates, value: undefined, present: false };\n  };\n\n  const record = (key: LeadFieldKey, resolution: Resolution): void => {\n    seen.set(key, {\n      key,\n      mappedTo: resolution.mappedTo,\n      candidates: resolution.candidates,\n      present: resolution.present,\n      display: resolution.present ? renderDisplay(resolution.value) : '(not set)',\n    });\n  };\n\n  const readResolved = (key: LeadFieldKey): Resolution => {\n    const resolution = resolve(key);\n    record(key, resolution);\n    return resolution;\n  };\n\n  return {\n    text: (key) => {\n      const leaves = stringLeaves(readResolved(key).value);\n      return leaves.length > 0 ? leaves.join(' ') : null;\n    },\n    textList: (key) => stringLeaves(readResolved(key).value),\n    number: (key) => toNumberValue(readResolved(key).value),\n    date: (key) => toDateValue(readResolved(key).value),\n    booleanAny: (key) => {\n      const all = resolveAll(key);\n      const present = all.filter((entry) => entry.present);\n      const truthy = present.find((entry) => toBooleanValue(entry.value) === true);\n\n      if (truthy !== undefined) {\n        record(key, truthy);\n        return true;\n      }\n\n      const first = present[0];\n\n      if (first !== undefined) {\n        record(key, first);\n        return toBooleanValue(first.value) === true ? true : false;\n      }\n\n      record(key, {\n        mappedTo: null,\n        candidates: candidatesFor(key),\n        value: undefined,\n        present: false,\n      });\n\n      return null;\n    },\n    observations: () => Array.from(seen.values()),\n  };\n};\n", "import { isPlaceholder } from 'src/scoring/field-access';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const companyIdentifiedRule: ScoringRule = {\n  id: 'company.identified',\n  name: 'Company named',\n  category: 'contact',\n  question: 'Do we know which company this lead works for?',\n  why: 'Every other qualification question \u2014 industry, size, region, territory, existing customer \u2014 depends on knowing the company. A lead with no company is a name floating in space, and a rep has nothing to research before they call.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 10,\n  reads: ['companyName'],\n\n  evaluate: ({ config, read }) => {\n    const name = read.text('companyName');\n\n    if (name === null) {\n      return {\n        outcome: 'fail',\n        explanation: 'No company is recorded on this lead.',\n        remedy: 'Add the company name, or link the lead to a company record.',\n      };\n    }\n\n    if (isPlaceholder(name, config.placeholderValues) || name.trim().length < 2) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${name}\" is a placeholder rather than a real company name.`,\n        remedy: 'Replace it with the real company name.',\n        detail: { companyName: name },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `The lead is attributed to ${name}.`,\n      detail: { companyName: name },\n    };\n  },\n};\n", "import type { RuleVerdict, ScoringRule } from 'src/scoring/types';\n\n/**\n * The one check in the product that is not about lead quality.\n *\n * ## What changed, and why it had to\n *\n * This rule used to read a single logical key, `optedOut`, resolved purely\n * through the customer's Layer 3 field mapping. Twenty ships no email management\n * \u2014 no unsubscribe handling, no bounce tracking, no do-not-contact list \u2014 so on\n * a stock workspace that mapping resolves to nothing at all,\n * `read.booleanAny('optedOut')` returned `null`, and the rule returned `pass`\n * with full credit. The single compliance check in Greenlight could not fire on\n * a default install, and it inflated every score by 15 points while failing to.\n *\n * Greenlight now ships the register itself (`greenlightSuppressed` and friends on\n * Person), and this rule reads it. Two consequences, both deliberate:\n *\n * ## 1. Union, not override\n *\n * Greenlight's field is read *first*, the customer's mapping second, and **any**\n * source saying \"suppressed\" fails the rule. A workspace that already had an\n * opt-out column keeps it working exactly as before, and gains a second register\n * rather than having its own replaced. There is no precedence question, because\n * for a compliance stop there is no argument in which \"the other column says it\n * is fine\" is a reason to send the email.\n *\n * A recorded suppression *reason* counts as suppression on its own, even with\n * the boolean cleared. Untick-the-box-but-leave-`SPAM_COMPLAINT`-behind is the\n * realistic hand edit, and reading it as \"contactable\" would silently re-enable\n * outreach to somebody whose own record still states, in writing, why we\n * stopped. The remedy names both fields so the fix is obvious.\n *\n * ## 2. \"Nobody knows\" is no longer the same answer as \"confirmed clear\"\n *\n * The old rule collapsed two very different states onto `pass` with full marks:\n * *this person has not opted out*, and *nothing anywhere in this workspace\n * records whether they have*. The second is not evidence of compliance; it is\n * the absence of a compliance system, and paying 15 points for it is how a\n * decorative check comes to look like a working one.\n *\n * They are now distinguished:\n *\n *   - **Confirmed clear** \u2014 Greenlight's register says no entry, or the\n *     customer's own opt-out column says false. `pass`, full credit. `false` on\n *     a Greenlight-owned column is a real assertion about a real register, not\n *     an absence.\n *   - **Genuinely unknown** \u2014 neither register is present on the record at all.\n *     `not_applicable`: the engine excludes it from *both* sides of the score, so\n *     the lead is neither credited for evidence it does not have nor punished for\n *     a check nobody could run. The remaining rules are renormalised over the\n *     weight that could actually be evaluated, and the trace says why.\n *\n * `not_applicable` rather than `fail` matters: only a blocking `fail` produces\n * the `blocked` decision, so an unknown never holds a lead. ARCHITECTURE.md's\n * golden rule is that a lead is never lost, and \"we could not check\" is not a\n * reason to stop somebody working a lead \u2014 it is a reason to stop pretending we\n * checked.\n *\n * In practice the unknown branch is what a workspace sees before the suppression\n * fields have synced, or when the engine is driven as a library over a record\n * shape that has neither register. On a synced workspace the field is present on\n * every Person, which is precisely the point: the fix for \"this rule cannot fail\"\n * is shipping somewhere for the answer to live, not re-weighting the rule.\n */\n\n/** `HARD_BOUNCE` -> `hard bounce`, without importing the gate layer's vocabulary. */\nconst humaniseReason = (code: string): string =>\n  code.trim().toLowerCase().replace(/[_-]+/g, ' ');\n\nconst failVerdict = (\n  greenlightSays: boolean,\n  customerSays: boolean,\n  reason: string | null,\n): RuleVerdict => {\n  const because =\n    reason === null ? '' : ` The recorded reason is \"${humaniseReason(reason)}\".`;\n\n  const explanation = greenlightSays\n    ? customerSays\n      ? `This person is on Greenlight's do-not-contact list and is also flagged as opted out in your own CRM field.${because} Contacting them is a compliance breach.`\n      : `This person is on Greenlight's do-not-contact list.${because} Contacting them is a compliance breach.`\n    : 'Your own opt-out field says this person has opted out of contact. Reaching out anyway is a compliance breach.';\n\n  return {\n    outcome: 'fail',\n    explanation,\n    remedy: greenlightSays\n      ? 'Do not contact this lead. If the block was recorded in error, use \"Allow contact again (Greenlight)\" \u2014 it clears both the flag and the reason, records who lifted it and why, and re-scores the lead.'\n      : 'Do not contact this lead. If the opt-out was recorded in error, correct your own opt-out field on the record and say why; the lead re-scores and clears itself.',\n    detail: {\n      suppressed: true,\n      suppressedByGreenlight: greenlightSays,\n      suppressedByCustomerField: customerSays,\n      suppressionReason: reason,\n      // Kept under the original key so anything already reading the trace for\n      // this rule \u2014 dashboards, exports, the release path's fallback \u2014 is not\n      // broken by the new field set.\n      optOutRecorded: true,\n    },\n  };\n};\n\nexport const complianceOptOutRule: ScoringRule = {\n  id: 'compliance.opt-out',\n  name: 'Not opted out',\n  category: 'compliance',\n  question: 'Has this person asked not to be contacted?',\n  why: 'Contacting someone who has opted out is a compliance breach and the fastest way to lose a domain reputation. This is the one check that is not about lead quality at all \u2014 it is about not doing something you are not allowed to do. Greenlight keeps its own do-not-contact register because Twenty has none, and reads any opt-out field the workspace already had alongside it.',\n  defaultEnabled: true,\n  defaultSeverity: 'blocking',\n  defaultWeight: 15,\n  reads: ['suppressed', 'suppressionReason', 'optedOut'],\n\n  evaluate: ({ read }) => {\n    // Greenlight's own register first.\n    const suppressedFlag = read.booleanAny('suppressed');\n    const suppressionReason = read.text('suppressionReason');\n    // Then the customer's, wherever their mapping points.\n    const optedOut = read.booleanAny('optedOut');\n\n    const greenlightSays = suppressedFlag === true || suppressionReason !== null;\n    const customerSays = optedOut === true;\n\n    if (greenlightSays || customerSays) {\n      return failVerdict(greenlightSays, customerSays, suppressionReason);\n    }\n\n    // Neither register is present on this record. Not a pass \u2014 an unanswered\n    // question, excluded from the score rather than paid out at full marks.\n    if (suppressedFlag === null && optedOut === null) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'Nothing on this record says whether this person has asked not to be contacted, so the compliance check could not be answered and was left out of the score rather than passed by default.',\n        remedy:\n          'Greenlight ships a \"Do not contact\" field for exactly this. If it is missing here, the app\u2019s fields have not reached this record yet \u2014 or point Greenlight at your own opt-out column under Opt-out fields in Greenlight settings.',\n        detail: {\n          suppressed: false,\n          suppressedByGreenlight: false,\n          suppressedByCustomerField: false,\n          suppressionReason: null,\n          optOutRecorded: false,\n          suppressionDataAvailable: false,\n        },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation:\n        suppressedFlag === false\n          ? 'Greenlight\u2019s do-not-contact list has no entry for this person, so outreach is permitted.'\n          : 'Your opt-out field is clear on this person, so outreach is permitted.',\n      detail: {\n        suppressed: false,\n        suppressedByGreenlight: false,\n        suppressedByCustomerField: false,\n        suppressionReason: null,\n        optOutRecorded: false,\n        suppressionDataAvailable: true,\n      },\n    };\n  },\n};\n", "/** Small shared primitives for rules. Pure, no I/O, no clock. */\n\nexport const normalise = (value: string): string =>\n  value.trim().toLowerCase().replace(/\\s+/g, ' ');\n\nconst escapeForRegex = (value: string): string =>\n  value.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\$&');\n\n/**\n * Whole-token keyword match, so \"lead\" does not match \"leadership\" and\n * \"vp\" does not match \"vps\".\n *\n * ## The boundary is Unicode-aware, and it has to be\n *\n * The boundary class is `\\p{L}\\p{N}` \u2014 any letter or number in any script \u2014 not\n * `a-z0-9`. The ASCII form was wrong, and it was wrong in the direction that\n * costs a lead: an accented letter is not in `a-z0-9`, so it counted as a word\n * *separator*, and every accented word silently split into fragments that could\n * match a keyword on their own.\n *\n * Found live, not by reasoning: with the multilingual calibration pack loaded, a\n * lead titled \"S\u00F3cio Propriet\u00E1rio\" matched the keyword **`cio`** \u2014 because the\n * \"\u00F3\" before it read as a boundary. The verdict happened to be right for that\n * title, but the same flaw promotes \"Gerente de Neg\u00F3cio\" to C-level, because\n * \"neg\u00F3cio\" ends in \"cio\" preceded by an accent. A mid-level manager scored as a\n * decision-maker is exactly the twenty-point error this rule exists to avoid.\n *\n * For pure-ASCII input the two forms are identical, which is why every\n * pre-existing test passes unchanged. The difference only appears where the\n * shipped English vocabulary never reached.\n */\nexport const containsKeyword = (haystack: string, keyword: string): boolean => {\n  const needle = normalise(keyword);\n\n  if (needle.length === 0) {\n    return false;\n  }\n\n  const pattern = new RegExp(\n    `(^|[^\\\\p{L}\\\\p{N}])${escapeForRegex(needle)}([^\\\\p{L}\\\\p{N}]|$)`,\n    'iu',\n  );\n\n  return pattern.test(normalise(haystack));\n};\n\nexport const firstKeywordMatch = (\n  haystack: string,\n  keywords: readonly string[],\n): string | null => keywords.find((keyword) => containsKeyword(haystack, keyword)) ?? null;\n\n/** Case-insensitive membership against a configured list. */\nexport const matchesList = (\n  values: readonly string[],\n  allowed: readonly string[],\n): string | null => {\n  const allowedSet = new Set(allowed.map(normalise));\n\n  return values.find((value) => allowedSet.has(normalise(value))) ?? null;\n};\n\nconst EMAIL_PATTERN =\n  /^[A-Za-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\\.[A-Za-z0-9!#$%&'*+/=?^_`{|}~-]+)*@(?:[A-Za-z0-9](?:[A-Za-z0-9-]*[A-Za-z0-9])?\\.)+[A-Za-z]{2,}$/;\n\nexport interface ParsedEmail {\n  readonly address: string;\n  readonly localPart: string;\n  readonly domain: string;\n}\n\nexport const parseEmail = (raw: string): ParsedEmail | null => {\n  const address = raw.trim();\n\n  if (address.length === 0 || address.length > 254) {\n    return null;\n  }\n\n  if (!EMAIL_PATTERN.test(address)) {\n    return null;\n  }\n\n  const separator = address.lastIndexOf('@');\n  const localPart = address.slice(0, separator);\n  const domain = address.slice(separator + 1);\n\n  if (localPart.length > 64) {\n    return null;\n  }\n\n  return { address, localPart: localPart.toLowerCase(), domain: domain.toLowerCase() };\n};\n\n/** Strip the local part down to its base, so `sales+eu` is still `sales`. */\nexport const emailLocalRoot = (localPart: string): string => {\n  const withoutTag = localPart.split('+')[0] ?? localPart;\n  return withoutTag.replace(/[._-]+$/, '');\n};\n\nexport const MILLISECONDS_PER_DAY = 86_400_000;\n\nexport const daysBetween = (earlier: Date, later: Date): number =>\n  (later.getTime() - earlier.getTime()) / MILLISECONDS_PER_DAY;\n\nexport const roundTo = (value: number, decimals: number): number => {\n  const factor = 10 ** decimals;\n  return Math.round(value * factor) / factor;\n};\n\nexport const clamp01 = (value: number): number => {\n  if (!Number.isFinite(value)) {\n    return 0;\n  }\n\n  return Math.min(1, Math.max(0, value));\n};\n", "import { firstKeywordMatch } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactDecisionMakerRule: ScoringRule = {\n  id: 'contact.decision-maker',\n  name: 'Decision-maker',\n  category: 'contact',\n  question: 'Can this person say yes, or at least get you in front of the person who can?',\n  why: 'The single biggest predictor of a deal is talking to someone with budget authority. A perfect-fit company represented by someone with no say costs a rep the same hours as a real opportunity and closes none of them.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 20,\n  reads: ['seniority', 'jobTitle'],\n\n  evaluate: ({ config, read }) => {\n    const seniority = read.text('seniority');\n    const jobTitle = read.text('jobTitle');\n    const subject = seniority ?? jobTitle;\n\n    if (subject === null) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'No job title is recorded, so we cannot tell whether this person can authorise a purchase.',\n        remedy: \"Add the contact's job title.\",\n      };\n    }\n\n    const decisionMaker = firstKeywordMatch(subject, config.decisionMakerTitles);\n\n    if (decisionMaker !== null) {\n      return {\n        outcome: 'pass',\n        explanation: `\"${subject}\" indicates buying authority.`,\n        detail: { title: subject, matchedKeyword: decisionMaker },\n      };\n    }\n\n    const influencer = firstKeywordMatch(subject, config.influencerTitles);\n\n    if (influencer !== null) {\n      return {\n        outcome: 'partial',\n        credit: 0.5,\n        explanation: `\"${subject}\" is likely an influencer rather than the person who signs.`,\n        remedy:\n          'Work this contact as a route in, and find the budget holder above them before forecasting the deal.',\n        detail: { title: subject, matchedKeyword: influencer },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `\"${subject}\" does not look like someone who can authorise a purchase.`,\n      remedy:\n        'Find a contact with budget authority at this company, or add their title keyword to your decision-maker list if it belongs there.',\n      detail: { title: subject },\n    };\n  },\n};\n", "import { parseEmail } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactEmailValidRule: ScoringRule = {\n  id: 'contact.email-valid',\n  name: 'Usable email address',\n  category: 'contact',\n  question: 'Is there an email address that will actually deliver?',\n  why: 'Email is how most first contact happens. A missing or malformed address means the outreach silently fails and the rep never learns why \u2014 the lead just looks unresponsive.',\n  defaultEnabled: true,\n  defaultSeverity: 'critical',\n  defaultWeight: 15,\n  reads: ['email'],\n\n  evaluate: ({ read }) => {\n    const candidates = read.textList('email');\n\n    if (candidates.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation: 'No email address is recorded, so this lead cannot be emailed.',\n        remedy: \"Add the contact's email address.\",\n      };\n    }\n\n    const parsed = candidates\n      .map((candidate) => parseEmail(candidate))\n      .find((candidate) => candidate !== null);\n\n    if (parsed === undefined || parsed === null) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${candidates[0] ?? ''}\" is not a valid email address, so anything sent to it will bounce.`,\n        remedy: 'Correct the email address.',\n        detail: { email: candidates[0] ?? null },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${parsed.address} is a well-formed email address.`,\n      detail: { email: parsed.address, domain: parsed.domain },\n    };\n  },\n};\n", "import { isPlaceholder } from 'src/scoring/field-access';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactNamedPersonRule: ScoringRule = {\n  id: 'contact.named-person',\n  name: 'Named contact',\n  category: 'contact',\n  question: 'Is there a real human being to call?',\n  why: 'A rep cannot open a conversation with an organisation. Leads without a named person become \"whoever picks up\", which is the lowest-converting outreach there is.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 8,\n  reads: ['contactName'],\n\n  evaluate: ({ config, read }) => {\n    const name = read.text('contactName');\n\n    if (name === null) {\n      return {\n        outcome: 'fail',\n        explanation: 'No contact name is recorded, so there is no one to address.',\n        remedy: 'Add the first and last name of the person to contact.',\n      };\n    }\n\n    if (isPlaceholder(name, config.placeholderValues) || !/[a-z]/i.test(name)) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${name}\" is a placeholder rather than a person's name.`,\n        remedy: \"Replace it with the contact's real name.\",\n        detail: { contactName: name },\n      };\n    }\n\n    const parts = name\n      .trim()\n      .split(/\\s+/)\n      .filter((part) => /[a-z]/i.test(part));\n\n    if (parts.length < 2) {\n      return {\n        outcome: 'partial',\n        credit: 0.5,\n        explanation: `Only a first name (\"${name}\") is recorded \u2014 enough to greet someone, not enough to find them.`,\n        remedy: 'Add the surname so the rep can verify the person before reaching out.',\n        detail: { contactName: name },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${name} is a named contact.`,\n      detail: { contactName: name },\n    };\n  },\n};\n", "import type { ScoringRule } from 'src/scoring/types';\n\nconst MIN_DIGITS = 7;\nconst MAX_DIGITS = 15;\n\nexport const contactPhoneValidRule: ScoringRule = {\n  id: 'contact.phone-valid',\n  name: 'Dialable phone number',\n  category: 'contact',\n  question: 'Is there a phone number a rep could actually dial?',\n  why: 'Phone is the fastest path to a real conversation and the fallback when email goes unanswered. A number with too few digits or a note typed into the field looks like coverage and gives none.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 5,\n  reads: ['phone'],\n\n  evaluate: ({ read }) => {\n    const candidates = read.textList('phone');\n\n    if (candidates.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation: 'No phone number is recorded, so this lead can only be reached by email.',\n        remedy: \"Add the contact's phone number.\",\n      };\n    }\n\n    const usable = candidates.find((candidate) => {\n      const stripped = candidate.replace(/[\\s().\\-/]/g, '').replace(/^\\+/, '');\n\n      if (!/^\\d+$/.test(stripped)) {\n        return false;\n      }\n\n      return stripped.length >= MIN_DIGITS && stripped.length <= MAX_DIGITS;\n    });\n\n    if (usable === undefined) {\n      return {\n        outcome: 'fail',\n        explanation: `\"${candidates[0] ?? ''}\" is not a number a rep could dial.`,\n        remedy: `Correct the phone number \u2014 it needs between ${MIN_DIGITS} and ${MAX_DIGITS} digits, optionally with a country code.`,\n        detail: { phone: candidates[0] ?? null },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${usable} is a dialable phone number.`,\n      detail: { phone: usable },\n    };\n  },\n};\n", "import { emailLocalRoot, parseEmail } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const contactSharedInboxRule: ScoringRule = {\n  id: 'contact.shared-inbox',\n  name: 'Personal mailbox',\n  category: 'contact',\n  question: 'Does the email address belong to a person, or to a shared inbox?',\n  why: 'A shared inbox \u2014 info@, sales@, enquiries@ \u2014 has no owner and no accountability, so replies are nobody\\'s job. These addresses look like a contactable lead in a report and behave like a dead end in practice.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 7,\n  reads: ['email'],\n\n  evaluate: ({ config, read }) => {\n    const candidates = read.textList('email');\n    const parsed = candidates\n      .map((candidate) => parseEmail(candidate))\n      .find((candidate) => candidate !== null);\n\n    if (parsed === undefined || parsed === null) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'There is no usable email address to judge, so this check was skipped \u2014 the email rule already covers it.',\n      };\n    }\n\n    const root = emailLocalRoot(parsed.localPart);\n\n    if (config.roleInboxLocalParts.includes(root)) {\n      return {\n        outcome: 'fail',\n        explanation: `${parsed.address} is a shared \"${root}@\" inbox, so no particular person owns a reply.`,\n        remedy:\n          'Find a named person at this company and use their direct address. Keep the shared inbox as a fallback only.',\n        detail: { email: parsed.address, mailbox: root },\n      };\n    }\n\n    return {\n      outcome: 'pass',\n      explanation: `${parsed.address} looks like a personal mailbox, so a named person will see it.`,\n      detail: { email: parsed.address, mailbox: root },\n    };\n  },\n};\n", "import { clamp01, daysBetween, roundTo } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\n/** Tolerance for clock skew between systems, in days. */\nconst FUTURE_TOLERANCE_DAYS = 1;\n\nexport const dataFreshnessRule: ScoringRule = {\n  id: 'data.freshness',\n  name: 'Data still in date',\n  category: 'data-quality',\n  question: 'Was this lead verified recently enough to trust?',\n  why: 'People change jobs, companies move, numbers get reassigned. A contact captured two years ago is not a lead, it is a historical record \u2014 and a rep who works it wastes the call and looks unprepared.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 10,\n  reads: ['lastVerifiedAt'],\n\n  evaluate: ({ config, now, read }) => {\n    if (now === null) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'The current date was not available for this run, so the age of this lead could not be checked.',\n      };\n    }\n\n    const shelfLifeDays =\n      config.fieldShelfLifeDays.lastVerifiedAt ?? config.defaultShelfLifeDays;\n\n    const verifiedAt = read.date('lastVerifiedAt');\n\n    if (verifiedAt === null) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'Nothing on this lead records when its details were last checked, so we have to assume they are stale.',\n        remedy: `Set a last-verified date, or map Greenlight's \"last verified\" field to a date your workspace already maintains. Your shelf life is ${shelfLifeDays} days.`,\n        detail: { shelfLifeDays },\n      };\n    }\n\n    const ageDays = daysBetween(verifiedAt, now);\n\n    if (ageDays < -FUTURE_TOLERANCE_DAYS) {\n      return {\n        outcome: 'fail',\n        explanation: `This lead says it was verified on ${verifiedAt.toISOString().slice(0, 10)}, which is in the future \u2014 the date is wrong.`,\n        remedy: 'Correct the last-verified date.',\n        detail: { verifiedAt: verifiedAt.toISOString(), shelfLifeDays },\n      };\n    }\n\n    const age = Math.max(0, ageDays);\n\n    if (age <= shelfLifeDays) {\n      return {\n        outcome: 'pass',\n        explanation: `Last verified ${roundTo(age, 1)} days ago, inside your ${shelfLifeDays}-day shelf life.`,\n        detail: { ageDays: roundTo(age, 1), shelfLifeDays },\n      };\n    }\n\n    if (age < shelfLifeDays * 2) {\n      const credit = clamp01(1 - (age - shelfLifeDays) / shelfLifeDays);\n\n      return {\n        outcome: 'partial',\n        credit,\n        explanation: `Last verified ${roundTo(age, 1)} days ago, past your ${shelfLifeDays}-day shelf life but not yet twice over.`,\n        remedy: 'Re-check the contact details before a rep spends time on this lead.',\n        detail: { ageDays: roundTo(age, 1), shelfLifeDays },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `Last verified ${roundTo(age, 1)} days ago \u2014 more than twice your ${shelfLifeDays}-day shelf life.`,\n      remedy: 'Re-verify the contact and company details, or retire the lead.',\n      detail: { ageDays: roundTo(age, 1), shelfLifeDays },\n    };\n  },\n};\n", "import type { ScoringRule } from 'src/scoring/types';\n\nexport const icpCompanySizeRule: ScoringRule = {\n  id: 'icp.company-size',\n  name: 'Target company size',\n  category: 'icp',\n  question: 'Is this company the size you sell to?',\n  why: 'Company size decides whether your pricing, contract and onboarding fit at all. Too small and the deal will not clear your floor; too large and the sales motion is a different product.',\n  defaultEnabled: true,\n  defaultSeverity: 'minor',\n  defaultWeight: 10,\n  reads: ['employeeCount'],\n\n  evaluate: ({ config, read }) => {\n    const bands = config.icp.sizeBands;\n\n    if (bands.length === 0) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'You have not defined any target company-size bands, so every company size is accepted.',\n        remedy:\n          'Define your target size bands in the Greenlight ICP settings to start filtering on headcount.',\n      };\n    }\n\n    const employees = read.number('employeeCount');\n\n    if (employees === null) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'This lead has no company size recorded, so we cannot tell whether the company is the size you sell to.',\n        remedy: 'Set the employee count on the lead or its company record.',\n      };\n    }\n\n    const matched = bands.find(\n      (band) =>\n        employees >= band.minEmployees &&\n        (band.maxEmployees === null || employees <= band.maxEmployees),\n    );\n\n    if (matched !== undefined) {\n      return {\n        outcome: 'pass',\n        explanation: `${employees} employees puts this company in your \"${matched.label}\" target band.`,\n        detail: { employees, band: matched.label },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `${employees} employees falls outside every target size band you defined.`,\n      remedy: `Widen a size band if you do sell to companies this size. Your bands are: ${bands\n        .map((band) => band.label)\n        .join(', ')}.`,\n      detail: { employees },\n    };\n  },\n};\n", "import { matchesList } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const icpIndustryRule: ScoringRule = {\n  id: 'icp.industry',\n  name: 'Target industry',\n  category: 'icp',\n  question: 'Is this company in an industry you sell to?',\n  why: 'Reps burn the most time on companies that were never going to buy. Industry is the cheapest, most reliable filter you have, and it is the one your team argues about most.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 20,\n  reads: ['industry', 'companyName'],\n\n  evaluate: ({ config, read }) => {\n    const targets = config.icp.industries;\n\n    if (targets.length === 0) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'You have not listed any target industries, so every industry is accepted.',\n        remedy:\n          'Add your target industries to the Greenlight ICP settings to start filtering on industry.',\n      };\n    }\n\n    const values = read.textList('industry');\n\n    if (values.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'This lead has no industry recorded, so we cannot tell whether it is in a market you sell to.',\n        remedy: 'Set the industry on the lead or its company record.',\n        detail: { targetIndustries: targets.join(', ') },\n      };\n    }\n\n    const matched = matchesList(values, targets);\n\n    if (matched !== null) {\n      return {\n        outcome: 'pass',\n        explanation: `${matched} is one of your target industries.`,\n        detail: { industry: matched },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `${values.join(', ')} is not one of your target industries.`,\n      remedy: `Add it to your target industries if you do sell there. Your current list is: ${targets.join(', ')}.`,\n      detail: { industry: values.join(', '), targetIndustries: targets.join(', ') },\n    };\n  },\n};\n", "import { matchesList } from 'src/scoring/rules/helpers';\nimport type { ScoringRule } from 'src/scoring/types';\n\nexport const icpRegionRule: ScoringRule = {\n  id: 'icp.region',\n  name: 'Target region',\n  category: 'icp',\n  question: 'Is this company somewhere you can actually sell and deliver?',\n  why: 'A perfect-fit company in a territory you do not cover is a perfect-fit company for someone else. Region also drives who the lead should be routed to.',\n  defaultEnabled: true,\n  defaultSeverity: 'major',\n  defaultWeight: 10,\n  reads: ['region'],\n\n  evaluate: ({ config, read }) => {\n    const targets = config.icp.regions;\n\n    if (targets.length === 0) {\n      return {\n        outcome: 'not_applicable',\n        explanation:\n          'You have not listed any target regions, so every region is accepted.',\n        remedy:\n          'Add the regions you sell into to the Greenlight ICP settings to start filtering on region.',\n      };\n    }\n\n    const values = read.textList('region');\n\n    if (values.length === 0) {\n      return {\n        outcome: 'fail',\n        explanation:\n          'This lead has no country or region recorded, so we cannot tell whether you cover it.',\n        remedy: 'Set the country or region on the lead.',\n        detail: { targetRegions: targets.join(', ') },\n      };\n    }\n\n    const matched = matchesList(values, targets);\n\n    if (matched !== null) {\n      return {\n        outcome: 'pass',\n        explanation: `${matched} is a region you sell into.`,\n        detail: { region: matched },\n      };\n    }\n\n    return {\n      outcome: 'fail',\n      explanation: `${values.join(', ')} is outside the regions you sell into.`,\n      remedy: `Add it to your target regions if you do cover it. Your current list is: ${targets.join(', ')}.`,\n      detail: { region: values.join(', '), targetRegions: targets.join(', ') },\n    };\n  },\n};\n", "/**\n * The rule catalogue.\n *\n * Adding a rule is a local change: write a `ScoringRule` in its own file, add\n * it to `ALL_RULES`, and it inherits default settings, config plumbing,\n * weighting, tracing and fail-open error handling for free. Removing one is\n * equally local \u2014 a config record referencing a rule that no longer exists is\n * ignored rather than fatal.\n */\n\nimport { companyIdentifiedRule } from 'src/scoring/rules/company-identified.rule';\nimport { complianceOptOutRule } from 'src/scoring/rules/compliance-opt-out.rule';\nimport { contactDecisionMakerRule } from 'src/scoring/rules/contact-decision-maker.rule';\nimport { contactEmailValidRule } from 'src/scoring/rules/contact-email-valid.rule';\nimport { contactNamedPersonRule } from 'src/scoring/rules/contact-named-person.rule';\nimport { contactPhoneValidRule } from 'src/scoring/rules/contact-phone-valid.rule';\nimport { contactSharedInboxRule } from 'src/scoring/rules/contact-shared-inbox.rule';\nimport { dataFreshnessRule } from 'src/scoring/rules/data-freshness.rule';\nimport { icpCompanySizeRule } from 'src/scoring/rules/icp-company-size.rule';\nimport { icpIndustryRule } from 'src/scoring/rules/icp-industry.rule';\nimport { icpRegionRule } from 'src/scoring/rules/icp-region.rule';\nimport type { RuleCatalogueEntry, ScoringRule } from 'src/scoring/types';\n\nexport const ALL_RULES: readonly ScoringRule[] = [\n  complianceOptOutRule,\n  icpIndustryRule,\n  icpRegionRule,\n  icpCompanySizeRule,\n  companyIdentifiedRule,\n  contactNamedPersonRule,\n  contactDecisionMakerRule,\n  contactEmailValidRule,\n  contactSharedInboxRule,\n  contactPhoneValidRule,\n  dataFreshnessRule,\n];\n\nexport {\n  companyIdentifiedRule,\n  complianceOptOutRule,\n  contactDecisionMakerRule,\n  contactEmailValidRule,\n  contactNamedPersonRule,\n  contactPhoneValidRule,\n  contactSharedInboxRule,\n  dataFreshnessRule,\n  icpCompanySizeRule,\n  icpIndustryRule,\n  icpRegionRule,\n};\n\n/**\n * The published rule catalogue \u2014 \"each rule: what it checks, why, what fixes\n * it\". The same text belongs in the docs and in the in-app help.\n */\nexport const describeRuleCatalogue = (\n  rules: readonly ScoringRule[] = ALL_RULES,\n): readonly RuleCatalogueEntry[] =>\n  rules.map((rule) => ({\n    id: rule.id,\n    name: rule.name,\n    category: rule.category,\n    question: rule.question,\n    why: rule.why,\n    reads: rule.reads,\n    defaultEnabled: rule.defaultEnabled,\n    defaultSeverity: rule.defaultSeverity,\n    defaultWeight: rule.defaultWeight,\n  }));\n", "/**\n * Numaya Greenlight \u2014 deterministic scoring engine types.\n *\n * This module is intentionally free of any Twenty SDK import, any network call,\n * any filesystem access and any clock read. Everything the engine needs arrives\n * through `scoreLead()`'s input, including `now`. That is what makes the whole\n * scoring path unit-testable in complete isolation.\n */\n\n/** Bumped whenever a change alters the score a given lead would receive. */\nexport const SCORING_ENGINE_VERSION = '0.1.0';\n\n/* -------------------------------------------------------------------------- */\n/* Lead input                                                                  */\n/* -------------------------------------------------------------------------- */\n\n/**\n * A lead as the engine sees it: an opaque bag of field values plus an optional\n * record id used only for the trace. The engine never assumes a field name \u2014\n * every read goes through the configured {@link FieldMapping}.\n */\nexport interface LeadRecord {\n  readonly id?: string | null;\n  readonly fields: Readonly<Record<string, unknown>>;\n}\n\n/**\n * Logical field keys. Rules only ever speak in these; the customer's actual\n * column names live in the config's field mapping.\n */\nexport type LeadFieldKey =\n  | 'companyName'\n  | 'industry'\n  | 'region'\n  | 'employeeCount'\n  | 'contactName'\n  | 'jobTitle'\n  | 'seniority'\n  | 'email'\n  | 'phone'\n  | 'lastVerifiedAt'\n  /** Greenlight's own block-list flag. Its mapping is not customer-configurable. */\n  | 'suppressed'\n  /** Greenlight's own block-list reason code. Read for the explanation, not the verdict. */\n  | 'suppressionReason'\n  /** The *customer's* opt-out column(s), wherever the Layer 3 mapping points. */\n  | 'optedOut';\n\nexport const LEAD_FIELD_KEYS: readonly LeadFieldKey[] = [\n  'companyName',\n  'industry',\n  'region',\n  'employeeCount',\n  'contactName',\n  'jobTitle',\n  'seniority',\n  'email',\n  'phone',\n  'lastVerifiedAt',\n  'suppressed',\n  'suppressionReason',\n  'optedOut',\n];\n\n/**\n * One or more dotted paths into the lead record, tried in order. Multiple\n * candidates let a workspace keep a preferred field with sane fallbacks\n * (e.g. `lastVerifiedAt` \u2192 `updatedAt` \u2192 `createdAt`).\n */\nexport type FieldMapping = Readonly<\n  Record<LeadFieldKey, readonly string[]>\n>;\n\n/** What a rule actually looked at, so the trace can show its working. */\nexport interface FieldObservation {\n  readonly key: LeadFieldKey;\n  /** The candidate path that produced a value, or null when none did. */\n  readonly mappedTo: string | null;\n  readonly candidates: readonly string[];\n  readonly present: boolean;\n  /** Human-readable rendering of the value, e.g. `Manufacturing` / `(not set)`. */\n  readonly display: string;\n}\n\n/**\n * Field reader handed to every rule. All lookups are recorded so the trace\n * entry can name the exact fields consulted and the values seen.\n */\nexport interface FieldReader {\n  text(key: LeadFieldKey): string | null;\n  textList(key: LeadFieldKey): readonly string[];\n  number(key: LeadFieldKey): number | null;\n  date(key: LeadFieldKey): Date | null;\n  /** True when any mapped candidate resolves truthy; null when none are set. */\n  booleanAny(key: LeadFieldKey): boolean | null;\n  observations(): readonly FieldObservation[];\n}\n\n/* -------------------------------------------------------------------------- */\n/* Configuration                                                               */\n/* -------------------------------------------------------------------------- */\n\nexport type RuleSeverity =\n  /** A failure blocks the lead outright (compliance), whatever the score. */\n  | 'blocking'\n  /** A failure gates the lead even if the score clears the threshold. */\n  | 'critical'\n  | 'major'\n  | 'minor'\n  /** Reported in the trace but never contributes to the score. */\n  | 'advisory';\n\nexport const RULE_SEVERITIES: readonly RuleSeverity[] = [\n  'blocking',\n  'critical',\n  'major',\n  'minor',\n  'advisory',\n];\n\nexport type RuleCategory = 'icp' | 'contact' | 'data-quality' | 'compliance';\n\nexport interface IcpSizeBand {\n  readonly label: string;\n  readonly minEmployees: number;\n  /** `null` means unbounded. */\n  readonly maxEmployees: number | null;\n}\n\nexport interface IcpConfig {\n  /** Empty list means \"no opinion\" \u2014 the matching rule reports not-applicable. */\n  readonly industries: readonly string[];\n  readonly regions: readonly string[];\n  readonly sizeBands: readonly IcpSizeBand[];\n}\n\nexport interface ScoringBand {\n  readonly id: string;\n  readonly label: string;\n  /** Inclusive lower bound on the 0-100 score. */\n  readonly minScore: number;\n}\n\nexport interface RuleSetting {\n  readonly enabled: boolean;\n  readonly severity: RuleSeverity;\n  /** Relative weight. Only meaningful against the other enabled rules. */\n  readonly weight: number;\n}\n\nexport interface ResolvedScoringConfig {\n  readonly icp: IcpConfig;\n  readonly rules: Readonly<Record<string, RuleSetting>>;\n  /** Sorted high \u2192 low by `minScore`. */\n  readonly bands: readonly ScoringBand[];\n  /** Score at or above which a lead is approved. */\n  readonly gateThreshold: number;\n  readonly defaultShelfLifeDays: number;\n  readonly fieldShelfLifeDays: Readonly<Partial<Record<LeadFieldKey, number>>>;\n  /** Title keywords that indicate authority to buy. */\n  readonly decisionMakerTitles: readonly string[];\n  /** Title keywords that indicate influence but not authority (partial credit). */\n  readonly influencerTitles: readonly string[];\n  /** Mailbox local-parts that mean \"shared inbox, nobody owns replies\". */\n  readonly roleInboxLocalParts: readonly string[];\n  /** Values that mean \"somebody typed something rather than nothing\". */\n  readonly placeholderValues: readonly string[];\n  readonly fieldMapping: FieldMapping;\n}\n\n/** A deeply-optional config, i.e. whatever came out of the CRM config record. */\nexport type ScoringConfigInput = unknown;\n\n/**\n * Vocabulary that replaces the shipped defaults as the *fall-back* for a\n * workspace that has not expressed its own opinion.\n *\n * Structurally identical to the calibration baseline in `src/calibration/`, and\n * deliberately declared here rather than imported from there: the engine must\n * not be able to tell where a baseline came from, and a `src/scoring/` import of\n * `src/calibration/` would invert a dependency direction that is load-bearing\n * (see `src/calibration/index.ts`). Every field is optional \u2014 an absent one\n * leaves the corresponding shipped default exactly as it is.\n *\n * It carries no weights, no thresholds and no rule identifiers, and there is no\n * field here through which one could be smuggled. The worst a baseline can do is\n * change which strings a rule matches.\n */\nexport interface ScoringVocabularyBaseline {\n  readonly decisionMakerTitles?: readonly string[];\n  readonly influencerTitles?: readonly string[];\n  readonly roleInboxLocalParts?: readonly string[];\n  readonly placeholderValues?: readonly string[];\n  /** Canonical industry term \u2192 equivalent free-text variants. */\n  readonly industrySynonyms?: Readonly<Record<string, readonly string[]>>;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Fail-open reporting                                                         */\n/* -------------------------------------------------------------------------- */\n\nexport type DegradationCode =\n  | 'config_missing'\n  | 'config_malformed'\n  | 'icp_malformed'\n  | 'rules_malformed'\n  | 'rule_setting_malformed'\n  | 'weight_malformed'\n  | 'severity_malformed'\n  | 'bands_malformed'\n  | 'gate_threshold_malformed'\n  | 'shelf_life_malformed'\n  | 'field_mapping_malformed'\n  | 'title_list_malformed'\n  | 'lead_malformed'\n  | 'now_malformed'\n  | 'rule_errored'\n  | 'no_scorable_rules'\n  | 'engine_errored';\n\n/**\n * A recorded fall-back. Every degradation means the engine chose to keep going\n * with a safe default rather than fail \u2014 the product's core promise is that a\n * lead is never lost and never silently dropped.\n */\nexport interface Degradation {\n  readonly code: DegradationCode;\n  /** Written for a CRM admin, not a developer. */\n  readonly message: string;\n  readonly detail?: string;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Rules                                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport type RuleOutcome =\n  | 'pass'\n  | 'partial'\n  | 'fail'\n  /** The rule has nothing to judge (e.g. the ICP list is empty). Not scored. */\n  | 'not_applicable'\n  /** Turned off in configuration. Not scored. */\n  | 'skipped'\n  /** The rule threw. Not scored \u2014 a broken rule never drags a lead down. */\n  | 'errored';\n\nexport type RuleDetail = Readonly<\n  Record<string, string | number | boolean | null | undefined>\n>;\n\n/** What a rule returns. `credit` defaults to 1 for pass and 0 for fail. */\nexport interface RuleVerdict {\n  readonly outcome: 'pass' | 'partial' | 'fail' | 'not_applicable';\n  /** 0-1. Required for `partial`; ignored elsewhere unless supplied. */\n  readonly credit?: number;\n  /** One sentence a salesperson understands. */\n  readonly explanation: string;\n  /** What to do about it, when there is something to do. */\n  readonly remedy?: string;\n  readonly detail?: RuleDetail;\n}\n\nexport interface RuleContext {\n  readonly lead: LeadRecord;\n  readonly config: ResolvedScoringConfig;\n  /** Null when the caller supplied an unusable `now`; time-based rules opt out. */\n  readonly now: Date | null;\n  readonly read: FieldReader;\n}\n\n/**\n * A single deterministic check. Adding a rule is a local change: write one of\n * these, add it to the catalogue array, done \u2014 defaults, config plumbing,\n * weighting, tracing and fail-open handling are all inherited.\n */\nexport interface ScoringRule {\n  readonly id: string;\n  /** Short label shown in the CRM, e.g. \"Decision-maker\". */\n  readonly name: string;\n  readonly category: RuleCategory;\n  /** The question the rule answers, in the buyer's words. */\n  readonly question: string;\n  /** Why the rule exists. Published in the rule catalogue and shown in-app. */\n  readonly why: string;\n  readonly defaultEnabled: boolean;\n  readonly defaultSeverity: RuleSeverity;\n  readonly defaultWeight: number;\n  readonly reads: readonly LeadFieldKey[];\n  evaluate(context: RuleContext): RuleVerdict;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Result                                                                      */\n/* -------------------------------------------------------------------------- */\n\nexport type GateDecision =\n  /** Cleared to work. */\n  | 'approved'\n  /** Held in the greenlight queue: visible, explained, human-overridable. */\n  | 'gated'\n  /** Compliance stop (e.g. opted out). Still visible and overridable. */\n  | 'blocked'\n  /** Nothing could be scored. Fail-open: the lead passes through, flagged. */\n  | 'unscored';\n\nexport interface RuleTraceEntry {\n  readonly ruleId: string;\n  readonly ruleName: string;\n  readonly category: RuleCategory;\n  readonly question: string;\n  readonly outcome: RuleOutcome;\n  readonly severity: RuleSeverity;\n  /** 0-1 share of this rule's weight that the lead earned. */\n  readonly credit: number;\n  readonly weight: number;\n  readonly pointsEarned: number;\n  readonly pointsPossible: number;\n  /** False for skipped / not-applicable / errored / advisory rules. */\n  readonly contributed: boolean;\n  readonly explanation: string;\n  readonly remedy?: string;\n  readonly detail?: RuleDetail;\n  readonly observations: readonly FieldObservation[];\n  readonly error?: string;\n}\n\nexport interface ScoringResult {\n  /** 0-100, rounded to one decimal. Null only when nothing was scorable. */\n  readonly score: number | null;\n  readonly band: ScoringBand | null;\n  readonly decision: GateDecision;\n  readonly gateThreshold: number;\n  /** One sentence for the top of the lead record. */\n  readonly summary: string;\n  /** The headline reasons behind the decision, worst first. */\n  readonly reasons: readonly string[];\n  readonly trace: readonly RuleTraceEntry[];\n  readonly degradations: readonly Degradation[];\n  readonly configSource: ConfigSource;\n  /** ISO timestamp of the `now` that was passed in. */\n  readonly scoredAt: string | null;\n  readonly leadId: string | null;\n  readonly engineVersion: string;\n  readonly totalWeight: number;\n  readonly earnedWeight: number;\n}\n\nexport type ConfigSource = 'provided' | 'defaults' | 'repaired';\n\nexport interface ConfigResolution {\n  readonly config: ResolvedScoringConfig;\n  readonly source: ConfigSource;\n  readonly degradations: readonly Degradation[];\n}\n\nexport interface ScoreLeadInput {\n  readonly lead: LeadRecord;\n  /**\n   * The clock, passed in. The engine never reads the clock itself, so every\n   * run is reproducible from its inputs alone.\n   */\n  readonly now: Date;\n  /** Raw config record straight from the CRM. Anything unusable is repaired. */\n  readonly config?: ScoringConfigInput;\n  /** Override the rule catalogue (tests, future per-workspace rule packs). */\n  readonly rules?: readonly ScoringRule[];\n  /**\n   * Licence-delivered vocabulary, if any. Absent \u2014 which is the unlicensed,\n   * offline and signature-failing case \u2014 scores identically to a build that\n   * never had this parameter.\n   */\n  readonly baseline?: ScoringVocabularyBaseline | null;\n}\n\n/** Public documentation shape for the rule catalogue (docs + in-app help). */\nexport interface RuleCatalogueEntry {\n  readonly id: string;\n  readonly name: string;\n  readonly category: RuleCategory;\n  readonly question: string;\n  readonly why: string;\n  readonly reads: readonly LeadFieldKey[];\n  readonly defaultEnabled: boolean;\n  readonly defaultSeverity: RuleSeverity;\n  readonly defaultWeight: number;\n}\n", "/**\n * Configuration resolution.\n *\n * `resolveConfig` takes whatever came out of the CRM config record \u2014 including\n * `undefined`, `null`, a string, or an object with half its fields the wrong\n * type \u2014 and always returns a usable config plus a list of the fall-backs it\n * had to make. Nothing in here throws. Missing config falls back to seeded\n * defaults; malformed weights fall back to neutral weights.\n */\n\nimport { ENRICHED_FIELD_MAPPING_PATHS } from 'src/enrichment/field-specs';\nimport {\n  DEFAULT_BANDS,\n  DEFAULT_DECISION_MAKER_TITLES,\n  DEFAULT_FIELD_MAPPING,\n  DEFAULT_GATE_THRESHOLD,\n  DEFAULT_ICP,\n  DEFAULT_INFLUENCER_TITLES,\n  DEFAULT_ROLE_INBOX_LOCAL_PARTS,\n  DEFAULT_SHELF_LIFE_DAYS,\n  PLACEHOLDER_VALUES,\n} from 'src/scoring/defaults';\nimport { isPlainObject } from 'src/scoring/field-access';\nimport { ALL_RULES } from 'src/scoring/rules';\nimport {\n  LEAD_FIELD_KEYS,\n  RULE_SEVERITIES,\n  type ConfigResolution,\n  type Degradation,\n  type DegradationCode,\n  type FieldMapping,\n  type IcpConfig,\n  type IcpSizeBand,\n  type LeadFieldKey,\n  type ResolvedScoringConfig,\n  type RuleSetting,\n  type RuleSeverity,\n  type ScoringBand,\n  type ScoringConfigInput,\n  type ScoringRule,\n  type ScoringVocabularyBaseline,\n} from 'src/scoring/types';\n\n/**\n * Set equality over normalised strings.\n *\n * Exported because `src/calibration/apply.ts` needs exactly this comparison and\n * the dependency may only run in that direction \u2014 calibration imports scoring,\n * never the reverse. Duplicating ten lines across that boundary would be two\n * implementations of one rule, and the rule decides whether a workspace's\n * configuration is honoured.\n */\nexport const isSameStringSet = (\n  left: readonly string[],\n  right: readonly string[],\n): boolean => {\n  const leftSet = new Set(left.map((entry) => entry.trim().toLowerCase().replace(/\\s+/g, ' ')));\n  const rightSet = new Set(right.map((entry) => entry.trim().toLowerCase().replace(/\\s+/g, ' ')));\n\n  if (leftSet.size !== rightSet.size) {\n    return false;\n  }\n\n  for (const entry of rightSet) {\n    if (!leftSet.has(entry)) {\n      return false;\n    }\n  }\n\n  return true;\n};\n\n/**\n * Expand a workspace's ICP industries through a synonym taxonomy.\n *\n * Declared here rather than imported from `src/calibration/` for the dependency\n * reason above, and applied at resolution rather than inside\n * `icp-industry.rule.ts` so the rule stays a pure set-membership test. The rule\n * is untouched by this feature; it simply finds a longer list of acceptable\n * strings. See `src/calibration/apply.ts` for the full argument.\n */\nexport const expandIndustriesWithSynonyms = (\n  industries: readonly string[],\n  synonyms: Readonly<Record<string, readonly string[]>> | undefined,\n): readonly string[] => {\n  if (synonyms === undefined || industries.length === 0) {\n    return industries;\n  }\n\n  const clusters = Object.entries(synonyms);\n\n  if (clusters.length === 0) {\n    return industries;\n  }\n\n  const variantToCanonical = new Map<string, string>();\n\n  for (const [canonical, variants] of clusters) {\n    const canonicalKey = normaliseTerm(canonical);\n    variantToCanonical.set(canonicalKey, canonicalKey);\n\n    for (const variant of variants) {\n      const variantKey = normaliseTerm(variant);\n\n      // A variant listed under two canonicals is a defect in the pack, and the\n      // resolution has to be independent of object key order or the same pack\n      // would behave differently in two builds. Two rules, in this order:\n      // **a canonical always wins over a variant** (the unconditional `set`\n      // above), and among competing variants the **first cluster wins**. Both\n      // are order-independent given a fixed pack, which is the property that\n      // matters.\n      if (!variantToCanonical.has(variantKey)) {\n        variantToCanonical.set(variantKey, canonicalKey);\n      }\n    }\n  }\n\n  // The workspace's own terms first and unmodified \u2014 expansion only ever adds.\n  const expanded = new Set(industries.map(normaliseTerm));\n\n  for (const industry of industries) {\n    const canonical = variantToCanonical.get(normaliseTerm(industry));\n\n    if (canonical === undefined) {\n      continue;\n    }\n\n    expanded.add(canonical);\n\n    for (const variant of synonyms[canonical] ?? []) {\n      expanded.add(normaliseTerm(variant));\n    }\n  }\n\n  return [...expanded];\n};\n\nconst normaliseTerm = (value: string): string =>\n  value.trim().toLowerCase().replace(/\\s+/g, ' ');\n\n/**\n * Append Greenlight's own enriched-value paths to the end of every enrichable\n * key's candidate list.\n *\n * ## Why this lives here and not in the config record\n *\n * `greenlightEnrichment` is a column Greenlight ships, owns and writes, so\n * \"where does an enriched industry live\" has exactly one answer and it is not\n * the customer's to give. There is also nowhere in `GreenlightConfig` to say it:\n * the record exposes precisely two mapping settings (`decisionMakerFieldName`,\n * `optOutFieldNames`), so seeding these five paths would mean minting columns\n * for values no admin should ever edit \u2014 and a seeded value is a value that can\n * be cleared, which would put us straight back to enrichment writing data\n * nothing reads. Doing it here also covers the workspace with *no* config record\n * at all, where `resolveConfig` short-circuits to `buildDefaultConfig` and never\n * looks at a field mapping the record could have carried.\n *\n * ## Appended, not pinned\n *\n * `PINNED_FIELD_MAPPING_KEYS` below *rejects* a workspace's mapping outright.\n * That is right for `suppressed`, whose key names a Greenlight-only column, and\n * wrong here: `industry`, `region`, `employeeCount`, `jobTitle` and `seniority`\n * are genuine Layer 3 seams and a workspace must keep saying where its own\n * columns live. The treatment is therefore the weaker half of pinning \u2014 the\n * workspace owns the head of the list, Greenlight owns the tail:\n *\n *   - **Unconditional**, so a config typo cannot silently disconnect enrichment.\n *     That is the same safety property pinning buys, without the cost.\n *   - **Always last**, so `field-access.ts` \u2014 which takes the first candidate\n *     that yields a value \u2014 reaches it only when every human-held candidate is\n *     empty. Enrichment fills a hole; it never overwrites a person.\n *\n * `DEFAULT_FIELD_MAPPING` itself is deliberately left alone: `src/enrichment/\n * plan.ts` reads it to answer \"has a human already answered this field\", and an\n * enriched value visible there would read as human input and never refresh.\n */\nconst withEnrichedFallbacks = (mapping: FieldMapping): FieldMapping => {\n  const next: Record<LeadFieldKey, readonly string[]> = { ...mapping };\n\n  for (const [key, path] of Object.entries(ENRICHED_FIELD_MAPPING_PATHS)) {\n    const leadKey = key as LeadFieldKey;\n    const candidates = next[leadKey] ?? [];\n\n    next[leadKey] = candidates.includes(path)\n      ? candidates\n      : [...candidates, path];\n  }\n\n  return next;\n};\n\n/**\n * The complete seeded configuration. Also what the install hook should write.\n *\n * The optional `baseline` supplies licence-delivered vocabulary in place of the\n * shipped lists. It is *only* consulted for the four vocabulary lists \u2014 bands,\n * weights, thresholds, shelf lives, the ICP and the field mapping are read from\n * the shipped constants unconditionally, and there is no argument here through\n * which a baseline could reach them.\n */\nexport const buildDefaultConfig = (\n  rules: readonly ScoringRule[] = ALL_RULES,\n  baseline?: ScoringVocabularyBaseline | null,\n): ResolvedScoringConfig => ({\n  icp: DEFAULT_ICP,\n  rules: Object.fromEntries(\n    rules.map((rule) => [\n      rule.id,\n      {\n        enabled: rule.defaultEnabled,\n        severity: rule.defaultSeverity,\n        weight: rule.defaultWeight,\n      } satisfies RuleSetting,\n    ]),\n  ),\n  bands: DEFAULT_BANDS,\n  gateThreshold: DEFAULT_GATE_THRESHOLD,\n  defaultShelfLifeDays: DEFAULT_SHELF_LIFE_DAYS,\n  fieldShelfLifeDays: {},\n  decisionMakerTitles:\n    baseline?.decisionMakerTitles ?? DEFAULT_DECISION_MAKER_TITLES,\n  influencerTitles: baseline?.influencerTitles ?? DEFAULT_INFLUENCER_TITLES,\n  roleInboxLocalParts:\n    baseline?.roleInboxLocalParts ?? DEFAULT_ROLE_INBOX_LOCAL_PARTS,\n  placeholderValues: baseline?.placeholderValues ?? PLACEHOLDER_VALUES,\n  fieldMapping: withEnrichedFallbacks(DEFAULT_FIELD_MAPPING),\n});\n\nconst isFiniteNumber = (value: unknown): value is number =>\n  typeof value === 'number' && Number.isFinite(value);\n\nconst toStringList = (value: unknown): string[] | null => {\n  if (typeof value === 'string') {\n    const trimmed = value.trim();\n    return trimmed.length > 0 ? [trimmed] : [];\n  }\n\n  if (!Array.isArray(value)) {\n    return null;\n  }\n\n  return value\n    .filter((entry): entry is string => typeof entry === 'string')\n    .map((entry) => entry.trim())\n    .filter((entry) => entry.length > 0);\n};\n\nconst lowerAll = (values: readonly string[]): string[] =>\n  values.map((value) => value.toLowerCase());\n\nclass DegradationLog {\n  private readonly entries: Degradation[] = [];\n\n  add(code: DegradationCode, message: string, detail?: string): void {\n    this.entries.push(detail === undefined ? { code, message } : { code, message, detail });\n  }\n\n  get list(): readonly Degradation[] {\n    return this.entries;\n  }\n\n  get count(): number {\n    return this.entries.length;\n  }\n}\n\nconst resolveIcp = (raw: unknown, log: DegradationLog): IcpConfig => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_ICP;\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'icp_malformed',\n      'Your ideal-customer-profile settings could not be read, so no industry, region or size filtering was applied.',\n    );\n    return DEFAULT_ICP;\n  }\n\n  const industries = toStringList(raw['industries']);\n  const regions = toStringList(raw['regions']);\n\n  if (raw['industries'] !== undefined && industries === null) {\n    log.add(\n      'icp_malformed',\n      'Your ICP industry list could not be read, so every industry was accepted.',\n    );\n  }\n\n  if (raw['regions'] !== undefined && regions === null) {\n    log.add(\n      'icp_malformed',\n      'Your ICP region list could not be read, so every region was accepted.',\n    );\n  }\n\n  const rawBands = raw['sizeBands'];\n  let sizeBands: IcpSizeBand[] = [];\n\n  if (rawBands !== undefined && rawBands !== null) {\n    if (!Array.isArray(rawBands)) {\n      log.add(\n        'icp_malformed',\n        'Your ICP company-size bands could not be read, so every company size was accepted.',\n      );\n    } else {\n      sizeBands = rawBands.flatMap((entry): IcpSizeBand[] => {\n        if (!isPlainObject(entry)) {\n          return [];\n        }\n\n        const min = entry['minEmployees'];\n        const max = entry['maxEmployees'];\n\n        if (!isFiniteNumber(min) || min < 0) {\n          return [];\n        }\n\n        const resolvedMax = isFiniteNumber(max) ? max : null;\n\n        if (resolvedMax !== null && resolvedMax < min) {\n          return [];\n        }\n\n        const label =\n          typeof entry['label'] === 'string' && entry['label'].trim().length > 0\n            ? entry['label'].trim()\n            : `${min}-${resolvedMax ?? '\u221E'} employees`;\n\n        return [{ label, minEmployees: min, maxEmployees: resolvedMax }];\n      });\n\n      if (sizeBands.length !== rawBands.length) {\n        log.add(\n          'icp_malformed',\n          'Some ICP company-size bands were incomplete and were ignored.',\n          `${rawBands.length - sizeBands.length} of ${rawBands.length} size bands dropped`,\n        );\n      }\n    }\n  }\n\n  return {\n    industries: industries ?? [],\n    regions: regions ?? [],\n    sizeBands,\n  };\n};\n\nconst readRuleOverrides = (\n  raw: unknown,\n  log: DegradationLog,\n): Map<string, Record<string, unknown>> => {\n  const overrides = new Map<string, Record<string, unknown>>();\n\n  if (raw === undefined || raw === null) {\n    return overrides;\n  }\n\n  // Accept both a keyed object and an array of { id, ... } records, because a\n  // CRM config record can reasonably be modelled either way.\n  if (Array.isArray(raw)) {\n    for (const entry of raw) {\n      if (!isPlainObject(entry)) {\n        continue;\n      }\n\n      const id = entry['id'] ?? entry['ruleId'];\n\n      if (typeof id === 'string' && id.length > 0) {\n        overrides.set(id, entry);\n      }\n    }\n\n    return overrides;\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'rules_malformed',\n      'Your rule settings could not be read, so every rule ran at its default setting.',\n    );\n    return overrides;\n  }\n\n  for (const [id, entry] of Object.entries(raw)) {\n    if (isPlainObject(entry)) {\n      overrides.set(id, entry);\n      continue;\n    }\n\n    if (typeof entry === 'boolean') {\n      overrides.set(id, { enabled: entry });\n      continue;\n    }\n\n    log.add(\n      'rule_setting_malformed',\n      `The settings for rule \"${id}\" could not be read, so the rule ran at its default setting.`,\n    );\n  }\n\n  return overrides;\n};\n\nconst resolveRuleSettings = (\n  raw: unknown,\n  rules: readonly ScoringRule[],\n  log: DegradationLog,\n): Record<string, RuleSetting> => {\n  const overrides = readRuleOverrides(raw, log);\n  const settings: Record<string, RuleSetting> = {};\n\n  for (const rule of rules) {\n    const override = overrides.get(rule.id);\n\n    let enabled = rule.defaultEnabled;\n    let severity: RuleSeverity = rule.defaultSeverity;\n    let weight = rule.defaultWeight;\n\n    if (override !== undefined) {\n      const rawEnabled = override['enabled'];\n\n      if (typeof rawEnabled === 'boolean') {\n        enabled = rawEnabled;\n      } else if (rawEnabled !== undefined && rawEnabled !== null) {\n        log.add(\n          'rule_setting_malformed',\n          `\"${rule.name}\" had an unreadable on/off setting, so it stayed at its default.`,\n          `rule ${rule.id}`,\n        );\n      }\n\n      const rawSeverity = override['severity'];\n\n      if (\n        typeof rawSeverity === 'string' &&\n        (RULE_SEVERITIES as readonly string[]).includes(rawSeverity)\n      ) {\n        severity = rawSeverity as RuleSeverity;\n      } else if (rawSeverity !== undefined && rawSeverity !== null) {\n        log.add(\n          'severity_malformed',\n          `\"${rule.name}\" had an unrecognised severity, so its default severity was used.`,\n          `rule ${rule.id}`,\n        );\n      }\n\n      const rawWeight = override['weight'];\n\n      if (isFiniteNumber(rawWeight) && rawWeight >= 0) {\n        weight = rawWeight;\n      } else if (rawWeight !== undefined && rawWeight !== null) {\n        log.add(\n          'weight_malformed',\n          `\"${rule.name}\" had an unusable weight, so its default weight was used instead.`,\n          `rule ${rule.id}`,\n        );\n      }\n    }\n\n    settings[rule.id] = { enabled, severity, weight };\n  }\n\n  // Neutral-weight fall-back: if nothing that can score carries any weight, the\n  // score would be undefined. Give every rule the same voice instead.\n  const scorable = rules.filter((rule) => {\n    const setting = settings[rule.id];\n    return setting !== undefined && setting.enabled && setting.severity !== 'advisory';\n  });\n\n  const totalWeight = scorable.reduce(\n    (sum, rule) => sum + (settings[rule.id]?.weight ?? 0),\n    0,\n  );\n\n  if (scorable.length > 0 && totalWeight <= 0) {\n    log.add(\n      'weight_malformed',\n      'None of your enabled rules carried any weight, so every rule was given equal weight.',\n    );\n\n    for (const rule of scorable) {\n      const current = settings[rule.id];\n\n      if (current !== undefined) {\n        settings[rule.id] = { ...current, weight: 1 };\n      }\n    }\n  }\n\n  return settings;\n};\n\nconst resolveBands = (raw: unknown, log: DegradationLog): readonly ScoringBand[] => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_BANDS;\n  }\n\n  if (!Array.isArray(raw)) {\n    log.add(\n      'bands_malformed',\n      'Your score bands could not be read, so the standard Excellent/Good/Fair/Poor bands were used.',\n    );\n    return DEFAULT_BANDS;\n  }\n\n  const bands = raw.flatMap((entry): ScoringBand[] => {\n    if (!isPlainObject(entry)) {\n      return [];\n    }\n\n    const minScore = entry['minScore'];\n\n    if (!isFiniteNumber(minScore)) {\n      return [];\n    }\n\n    const id =\n      typeof entry['id'] === 'string' && entry['id'].trim().length > 0\n        ? entry['id'].trim()\n        : null;\n\n    if (id === null) {\n      return [];\n    }\n\n    const label =\n      typeof entry['label'] === 'string' && entry['label'].trim().length > 0\n        ? entry['label'].trim()\n        : id;\n\n    return [{ id, label, minScore: Math.min(100, Math.max(0, minScore)) }];\n  });\n\n  if (bands.length === 0) {\n    log.add(\n      'bands_malformed',\n      'No usable score bands were configured, so the standard Excellent/Good/Fair/Poor bands were used.',\n    );\n    return DEFAULT_BANDS;\n  }\n\n  if (bands.length !== raw.length) {\n    log.add(\n      'bands_malformed',\n      'Some score bands were incomplete and were ignored.',\n      `${raw.length - bands.length} of ${raw.length} bands dropped`,\n    );\n  }\n\n  return [...bands].sort((a, b) => b.minScore - a.minScore);\n};\n\nconst resolveGateThreshold = (raw: unknown, log: DegradationLog): number => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_GATE_THRESHOLD;\n  }\n\n  if (!isFiniteNumber(raw) || raw < 0 || raw > 100) {\n    log.add(\n      'gate_threshold_malformed',\n      `Your gate threshold was not a score between 0 and 100, so the default of ${DEFAULT_GATE_THRESHOLD} was used.`,\n    );\n    return DEFAULT_GATE_THRESHOLD;\n  }\n\n  return raw;\n};\n\nconst resolveShelfLife = (raw: unknown, log: DegradationLog): number => {\n  if (raw === undefined || raw === null) {\n    return DEFAULT_SHELF_LIFE_DAYS;\n  }\n\n  if (!isFiniteNumber(raw) || raw <= 0) {\n    log.add(\n      'shelf_life_malformed',\n      `Your data shelf life was not a positive number of days, so the default of ${DEFAULT_SHELF_LIFE_DAYS} days was used.`,\n    );\n    return DEFAULT_SHELF_LIFE_DAYS;\n  }\n\n  return raw;\n};\n\nconst resolveFieldShelfLives = (\n  raw: unknown,\n  log: DegradationLog,\n): Partial<Record<LeadFieldKey, number>> => {\n  if (raw === undefined || raw === null) {\n    return {};\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'shelf_life_malformed',\n      'Your per-field shelf lives could not be read, so the single default shelf life was used for every field.',\n    );\n    return {};\n  }\n\n  const resolved: Partial<Record<LeadFieldKey, number>> = {};\n\n  for (const key of LEAD_FIELD_KEYS) {\n    const value = raw[key];\n\n    if (value === undefined || value === null) {\n      continue;\n    }\n\n    if (isFiniteNumber(value) && value > 0) {\n      resolved[key] = value;\n    } else {\n      log.add(\n        'shelf_life_malformed',\n        `The shelf life for \"${key}\" was not a positive number of days, so the default shelf life was used.`,\n      );\n    }\n  }\n\n  return resolved;\n};\n\n/**\n * Resolve one vocabulary list against the three-layer precedence.\n *\n * `shipped` is the in-source constant and `baseline` is the licence-delivered\n * replacement for it, or `undefined` when there is none. The workspace's own\n * value still wins over both \u2014 with one carefully-bounded exception.\n *\n * ## The exception: an unedited seed is not a choice\n *\n * The post-install hook copies the shipped decision-maker list *into* the config\n * record so an admin can see and edit it. Every fresh install therefore holds an\n * \"explicit\" list that is really just the default, and treating it as a choice\n * would let it shadow calibration permanently \u2014 calibration would arrive, verify,\n * publish, and change nothing.\n *\n * So a stored list whose set of entries is exactly the shipped set is recognised\n * as an untouched seed and steps aside for the baseline. Adding or removing a\n * single entry makes it a genuine curation that nothing will override. The\n * comparison is exact set equality: no subset test, no size heuristic, nothing\n * that could mistake a real edit for a seed. And it only ever applies when a\n * baseline exists \u2014 with no calibration, the shipped list is what the seed\n * resolves to either way, so the branch is unreachable in an unlicensed install.\n */\nconst resolveTitleList = (\n  raw: unknown,\n  shipped: readonly string[],\n  baseline: readonly string[] | undefined,\n  label: string,\n  log: DegradationLog,\n): readonly string[] => {\n  const fallback = baseline ?? shipped;\n\n  if (raw === undefined || raw === null) {\n    return fallback;\n  }\n\n  const list = toStringList(raw);\n\n  if (list === null || list.length === 0) {\n    log.add(\n      'title_list_malformed',\n      `Your ${label} list could not be read, so the built-in list was used.`,\n    );\n    return fallback;\n  }\n\n  if (baseline !== undefined && isSameStringSet(list, shipped)) {\n    return baseline;\n  }\n\n  return lowerAll(list);\n};\n\n/**\n * Keys the customer's field mapping is not allowed to move.\n *\n * These are Greenlight's own suppression columns: the app ships them, owns them,\n * and knows exactly where they live. Every other key here is a genuine Layer 3\n * seam because the field belongs to the customer's schema \u2014 these two do not,\n * and a config blob able to point `suppressed` somewhere else is a config blob\n * able to switch the block list off by mistyping a column name. The workspace's\n * *own* opt-out columns remain fully mappable under `optedOut`, and the\n * compliance rule takes the union of the two.\n */\nconst PINNED_FIELD_MAPPING_KEYS: readonly LeadFieldKey[] = [\n  'suppressed',\n  'suppressionReason',\n];\n\n/**\n * The workspace's mapping, resolved and repaired \u2014 before the enriched tail is\n * appended. Split out so `withEnrichedFallbacks` runs on *every* return path,\n * including the two that bail out early on unreadable configuration.\n */\nconst readConfiguredFieldMapping = (\n  raw: unknown,\n  log: DegradationLog,\n): FieldMapping => {\n  const mapping: Record<LeadFieldKey, readonly string[]> = {\n    ...DEFAULT_FIELD_MAPPING,\n  };\n\n  if (raw === undefined || raw === null) {\n    return mapping;\n  }\n\n  if (!isPlainObject(raw)) {\n    log.add(\n      'field_mapping_malformed',\n      'Your field mapping could not be read, so the default field names were used.',\n    );\n    return mapping;\n  }\n\n  for (const key of LEAD_FIELD_KEYS) {\n    const value = raw[key];\n\n    if (value === undefined || value === null) {\n      continue;\n    }\n\n    if (PINNED_FIELD_MAPPING_KEYS.includes(key)) {\n      log.add(\n        'field_mapping_malformed',\n        `\"${key}\" is one of Greenlight's own do-not-contact fields and cannot be remapped, so the mapping you supplied for it was ignored. Use \"Opt-out fields\" to add your own opt-out columns alongside it.`,\n      );\n      continue;\n    }\n\n    const paths = toStringList(value);\n\n    if (paths === null || paths.length === 0) {\n      log.add(\n        'field_mapping_malformed',\n        `The field mapping for \"${key}\" was unusable, so the default field names were used.`,\n      );\n      continue;\n    }\n\n    mapping[key] = paths;\n  }\n\n  return mapping;\n};\n\nconst resolveFieldMapping = (raw: unknown, log: DegradationLog): FieldMapping =>\n  withEnrichedFallbacks(readConfiguredFieldMapping(raw, log));\n\n/**\n * Turn an untrusted config value into a usable configuration.\n *\n * Never throws. The returned `source` tells the caller whether the workspace's\n * own configuration was used as-is (`provided`), had to be patched\n * (`repaired`), or was absent entirely (`defaults`).\n *\n * ## The baseline argument\n *\n * `baseline` is licence-delivered vocabulary \u2014 see\n * `src/calibration/apply.ts`. It is a *fall-back* replacement, never an\n * override: it stands in for the shipped constants when the workspace has said\n * nothing, and it is invisible when the workspace has said something. Passing\n * `undefined` or `null` \u2014 the unlicensed, offline, stale and\n * signature-failing cases, which is to say every case where anything went wrong\n * \u2014 makes this function behave exactly as it did before the parameter existed.\n * `__tests__/config.test.ts` asserts that identity rather than asserting a\n * promise about it.\n *\n * The baseline never reaches `source`. A calibrated workspace with an otherwise\n * clean config record still reports `provided`, because calibration is not a\n * repair and an admin reading the trace should not see one.\n */\nexport const resolveConfig = (\n  raw: ScoringConfigInput,\n  rules: readonly ScoringRule[] = ALL_RULES,\n  baseline?: ScoringVocabularyBaseline | null,\n): ConfigResolution => {\n  const log = new DegradationLog();\n  const vocabulary = baseline ?? undefined;\n\n  if (raw === undefined || raw === null) {\n    return {\n      config: buildDefaultConfig(rules, vocabulary),\n      source: 'defaults',\n      degradations: [\n        {\n          code: 'config_missing',\n          message:\n            'No Greenlight configuration was found, so this lead was scored with the built-in defaults.',\n        },\n      ],\n    };\n  }\n\n  if (!isPlainObject(raw)) {\n    return {\n      config: buildDefaultConfig(rules, vocabulary),\n      source: 'defaults',\n      degradations: [\n        {\n          code: 'config_malformed',\n          message:\n            'The Greenlight configuration record could not be read, so this lead was scored with the built-in defaults.',\n          detail: `expected an object, received ${Array.isArray(raw) ? 'array' : typeof raw}`,\n        },\n      ],\n    };\n  }\n\n  const resolvedIcp = resolveIcp(raw['icp'], log);\n\n  const config: ResolvedScoringConfig = {\n    // Expansion is applied to the *resolved* ICP, so a workspace that listed\n    // \"SaaS\" keeps \"SaaS\" at the head of the list and gains its cluster behind\n    // it. An empty list is returned untouched \u2014 \"no opinion\" must not become\n    // \"an opinion about eighty industries\".\n    icp: {\n      ...resolvedIcp,\n      industries: expandIndustriesWithSynonyms(\n        resolvedIcp.industries,\n        vocabulary?.industrySynonyms,\n      ),\n    },\n    rules: resolveRuleSettings(raw['rules'], rules, log),\n    bands: resolveBands(raw['bands'], log),\n    gateThreshold: resolveGateThreshold(raw['gateThreshold'], log),\n    defaultShelfLifeDays: resolveShelfLife(raw['defaultShelfLifeDays'], log),\n    fieldShelfLifeDays: resolveFieldShelfLives(raw['fieldShelfLifeDays'], log),\n    decisionMakerTitles: lowerAll(\n      resolveTitleList(\n        raw['decisionMakerTitles'],\n        DEFAULT_DECISION_MAKER_TITLES,\n        vocabulary?.decisionMakerTitles,\n        'decision-maker title',\n        log,\n      ),\n    ),\n    influencerTitles: lowerAll(\n      resolveTitleList(\n        raw['influencerTitles'],\n        DEFAULT_INFLUENCER_TITLES,\n        vocabulary?.influencerTitles,\n        'influencer title',\n        log,\n      ),\n    ),\n    roleInboxLocalParts: lowerAll(\n      resolveTitleList(\n        raw['roleInboxLocalParts'],\n        DEFAULT_ROLE_INBOX_LOCAL_PARTS,\n        vocabulary?.roleInboxLocalParts,\n        'shared-inbox',\n        log,\n      ),\n    ),\n    placeholderValues: lowerAll(\n      resolveTitleList(\n        raw['placeholderValues'],\n        PLACEHOLDER_VALUES,\n        vocabulary?.placeholderValues,\n        'placeholder value',\n        log,\n      ),\n    ),\n    fieldMapping: resolveFieldMapping(raw['fieldMapping'], log),\n  };\n\n  return {\n    config,\n    source: log.count > 0 ? 'repaired' : 'provided',\n    degradations: log.list,\n  };\n};\n", "/**\n * Turning a verified calibration into the *baseline* the scoring engine\n * resolves configuration against.\n *\n * ===========================================================================\n * ## Calibration is a baseline, never an override\n *\n * The precedence is, top wins:\n *\n *   1. the workspace's own explicit configuration  (`GreenlightConfig` record)\n *   2. licence-delivered calibration               (this module)\n *   3. the in-source shipped defaults              (`src/scoring/defaults.ts`)\n *\n * Layer 1 is the customer's data and calibration must not touch it. Layer 3 is\n * what an unlicensed install uses and must keep using. Calibration slots between\n * them: it replaces the *fall-back*, so a workspace that never expressed an\n * opinion about decision-maker titles gets 180 of them instead of 25, and a\n * workspace that curated its own list keeps exactly the list it curated.\n *\n * This is why nothing here is called from a rule. Rules stay pure and stay\n * ignorant: they read `config.decisionMakerTitles` exactly as they did before\n * this feature existed, and calibration arrives as data through the one config\n * resolution path that already existed. `src/scoring/` gains no import from\n * `src/calibration/` \u2014 the dependency runs the other way.\n *\n * ## The seeded-defaults problem, and why it needed solving\n *\n * `buildGreenlightConfigSeed()` writes the shipped title list *into the config\n * record* at install, so that an admin can see and edit it. That is good product\n * design and it quietly breaks the precedence above: after a fresh install every\n * workspace has an \"explicit\" decision-maker list, which is really just a copy of\n * the shipped defaults, and layer 1 would therefore shadow calibration forever.\n * Calibration would arrive, verify, publish \u2014 and change nothing.\n *\n * `isUntouchedShippedList` closes that. A stored list whose *set* of entries is\n * exactly the shipped set is a seed nobody has edited, not a choice, and\n * calibration is allowed past it. Add one title, remove one title, and it becomes\n * a real curation that calibration will not touch. Set comparison rather than\n * sequence comparison because a workspace that reordered the seeded list without\n * changing its contents has still not expressed an opinion about *which* titles\n * count, and reordering is exactly what a JSON editor does for free.\n *\n * The check is deliberately conservative in the direction that matters: a false\n * \"untouched\" costs the admin a list they did not ask to be replaced, so the\n * comparison is exact set equality and nothing looser \u2014 no subset test, no\n * fuzzy match, no size heuristic.\n * ===========================================================================\n */\n\nimport {\n  expandIndustriesWithSynonyms,\n  isSameStringSet,\n} from 'src/scoring/config';\nimport { type Calibration } from 'src/calibration/types';\n\n/**\n * The slice of a calibration that the config resolver consumes.\n *\n * A separate, narrower type from `Calibration` so `src/scoring/config.ts` can\n * depend on the *shape* of a baseline without depending on the calibration\n * module, its envelope, its cache or its verification. The scoring engine\n * should not be able to tell where its baseline came from.\n */\nexport interface ScoringBaseline {\n  readonly decisionMakerTitles: readonly string[];\n  readonly influencerTitles: readonly string[];\n  readonly roleInboxLocalParts: readonly string[];\n  readonly placeholderValues: readonly string[];\n  /** Canonical industry term \u2192 equivalent free-text variants. */\n  readonly industrySynonyms: Readonly<Record<string, readonly string[]>>;\n}\n\n/**\n * Narrow a verified calibration to the baseline.\n *\n * Empty lists are dropped, not carried: an empty list in the payload means \"this\n * pack has no opinion here\", and letting it through as a baseline would replace\n * twenty-five shipped titles with none \u2014 i.e. would silently disable the\n * highest-weighted rule in the product. Absent and empty must both mean \"leave\n * the shipped default alone\", and this is the single place that is enforced.\n */\nexport const toScoringBaseline = (\n  calibration: Calibration,\n): Partial<ScoringBaseline> => {\n  const baseline: {\n    -readonly [K in keyof ScoringBaseline]?: ScoringBaseline[K];\n  } = {};\n\n  if (calibration.decisionMakerTitles.length > 0) {\n    baseline.decisionMakerTitles = calibration.decisionMakerTitles;\n  }\n\n  if (calibration.influencerTitles.length > 0) {\n    baseline.influencerTitles = calibration.influencerTitles;\n  }\n\n  if (calibration.roleInboxLocalParts.length > 0) {\n    baseline.roleInboxLocalParts = calibration.roleInboxLocalParts;\n  }\n\n  if (calibration.placeholderValues.length > 0) {\n    baseline.placeholderValues = calibration.placeholderValues;\n  }\n\n  if (Object.keys(calibration.industrySynonyms).length > 0) {\n    baseline.industrySynonyms = calibration.industrySynonyms;\n  }\n\n  return baseline;\n};\n\n/**\n * True when a stored list is an unedited copy of what the installer seeded.\n *\n * See \"The seeded-defaults problem\" above. The comparison itself lives in\n * `src/scoring/config.ts` because that is where the decision is *taken* \u2014 this\n * is the name the calibration side reads it under, so a reader here does not\n * have to guess which of two set comparisons governs their config.\n *\n * Both sides are normalised, because the seed round-trips through a `RAW_JSON`\n * column and the engine lower-cases every list it resolves; a case difference\n * across that boundary is storage noise, not an edit.\n */\nexport const isUntouchedShippedList = isSameStringSet;\n\n/* -------------------------------------------------------------------------- */\n/* Industry expansion                                                          */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Expanding a workspace's ICP industry list through the synonym taxonomy is\n * what turns the twenty-point industry rule from decorative into useful.\n *\n * `icp-industry.rule.ts` does exact normalised set membership against\n * `config.icp.industries` \u2014 correct, cheap, and completely defeated by real CRM\n * data, where one industry arrives as \"SaaS\", \"Software as a Service\", \"B2B\n * Software\", \"Logiciel\" and \"Cloud Software\" on five records imported from four\n * tools.\n *\n * Rather than teach the rule about synonyms \u2014 a logic change, and a taxonomy\n * lookup inside a pure comparison \u2014 the expansion happens once, at config\n * resolution, in `expandIndustriesWithSynonyms` in `src/scoring/config.ts`. The\n * rule is untouched and simply finds a longer list of acceptable strings. That\n * is the entire mechanism, and it is why this feature required no edit to any\n * rule.\n *\n * The properties that make it safe, asserted in `__tests__/apply.test.ts`:\n *\n * - It never expands an **empty** list. Empty means \"no opinion\" and the rule\n *   reports `not_applicable`; expanding nothing into everything would turn a\n *   permissive install into one that silently started filtering.\n * - It never **removes** a term. The workspace's own entries always survive, at\n *   the head of the list, whether or not the taxonomy recognises them.\n * - It matches **bidirectionally**: an admin may type the canonical term or any\n *   variant, because they have no way to know which the pack treats as\n *   canonical and should not have to.\n * - It is **not transitive**. A variant pulls in its canonical's cluster and\n *   stops; there is no closure step, so one bad cluster cannot leak across the\n *   taxonomy.\n */\nexport const expandIndustries = (\n  industries: readonly string[],\n  synonyms: Readonly<Record<string, readonly string[]>>,\n): readonly string[] => expandIndustriesWithSynonyms(industries, synonyms);\n", "/**\n * The licensing composition root: reads the environment, drives the ports, hands\n * everything to the pure core, writes the result back out.\n *\n * Kept out of the `define*` file for the same reason `scoring-run.ts` is \u2014 so\n * the whole run can be exercised against fakes, with an injected `now` and no\n * network. There is no `new Date()` and no `new CoreApiClient()` below.\n *\n * ===========================================================================\n * ## Two entry points\n *\n * `runLicenceInstall`  \u2014 called once from the post-install hook. Activates, then\n *                        validates.\n * `runLicenceRevalidation` \u2014 called nightly by the cron function. Validates only.\n *\n * `activate` is **not** called nightly. It is idempotent on the fingerprint and\n * would be harmless, but it is a slot-claim, not a health check, and calling it\n * every night would turn one write per install into one write per workspace per\n * day against a service that gains nothing from them.\n *\n * ## What is sent to Numaya, and what is not\n *\n * The licence key, the workspace id (as `deviceFingerprint`) and the workspace\n * display name (as `deviceName`). That is the entire payload, and the data-egress\n * table in `ARCHITECTURE.md` says so. No lead, contact, company or score data\n * leaves the workspace on this path \u2014 there is no field in the request body that\n * could carry any.\n *\n * ## Why an unresolvable workspace is not fatal\n *\n * `deviceFingerprint` is optional on `validate`. If the workspace identity\n * cannot be read \u2014 the metadata API is unavailable, or a future SDK moves\n * `currentWorkspace` \u2014 the run still validates, just without a fingerprint, and\n * skips activation because activation *requires* one. That is a strictly better\n * outcome than failing the check: the customer keeps their entitlement, and the\n * only thing lost is the readable device name in Numaya's admin view.\n * ===========================================================================\n */\n\nimport {\n  DEFAULT_LICENCE_API_BASE_URL,\n  DEFAULT_LICENCE_ENVIRONMENT,\n  ENRICHMENT_FEATURE_NAME,\n} from 'src/constants/licence-identifiers';\nimport {\n  buildLicenceAuditDetail,\n  buildLicenceAuditRow,\n  describeLicenceForAdmin,\n  maskLicenceKey,\n  redactLicenceKey,\n  resolveLicenceState,\n  type LicenceNotice,\n  type LicenceEnvironmentName,\n  type LicenceState,\n  type LicenceStorePort,\n  type LicensingPort,\n  type LicenceValidateOutcome,\n} from 'src/licensing';\nimport {\n  describeCalibration,\n  refreshCalibration,\n  type CalibrationStorePort,\n  type RefreshCalibrationOutcome,\n} from 'src/calibration';\nimport {\n  describeError,\n  logGreenlight,\n  type GreenlightApiClient,\n} from 'src/logic-functions/greenlight-api';\nimport { createLicenceKeySeal } from 'src/logic-functions/licence-cache-seal';\n\n/* -------------------------------------------------------------------------- */\n/* Ports                                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport interface WorkspaceIdentity {\n  readonly workspaceId: string;\n  readonly workspaceName: string | null;\n}\n\n/**\n * Resolving \"which workspace am I\" is I/O, so it is a port like everything else.\n * The real adapter is `licence-workspace-identity.ts`; `null` means \"could not\n * tell\", which every caller below treats as a degradation rather than a failure.\n */\nexport interface WorkspaceIdentityPort {\n  read(): Promise<WorkspaceIdentity | null>;\n}\n\n/* -------------------------------------------------------------------------- */\n/* Environment                                                                 */\n/* -------------------------------------------------------------------------- */\n\nexport interface LicenceEnvironment {\n  /** `null` when unset or blank \u2014 the supported, unlicensed configuration. */\n  readonly licenceKey: string | null;\n  readonly baseUrl: string;\n  readonly environment: LicenceEnvironmentName;\n}\n\n/**\n * Application variables reach a logic function as environment variables.\n *\n * The `?? DEFAULT_LICENCE_API_BASE_URL` is belt-and-braces: the variable ships\n * with that value declared in `application-config.ts`, so it should always be\n * present. It would be absent on a workspace that installed a build predating\n * the variable and has not re-synced, and defaulting beats an empty base URL\n * only in that the failure is then identical to a normal outage.\n *\n * `LICENCE_ENVIRONMENT` is read the strict way round: **only** the exact string\n * `sandbox` selects sandbox, and everything else \u2014 unset, blank, misspelled,\n * `SANDBOX_`, a value from a future release \u2014 is production. Defaulting an\n * unrecognised value to sandbox would let a typo route a paying customer at the\n * test estate, where their licence does not exist and where this whole exercise\n * started. Casing and surrounding whitespace are forgiven because they are\n * transcription noise, not intent.\n */\nexport const readLicenceEnvironment = (\n  env: Record<string, string | undefined> = process.env,\n): LicenceEnvironment => {\n  const rawKey = env['LICENCE_KEY'];\n  const trimmed = typeof rawKey === 'string' ? rawKey.trim() : '';\n  const rawBase = env['LICENCE_API_BASE_URL'];\n  const rawEnvironment = env['LICENCE_ENVIRONMENT'];\n\n  return {\n    licenceKey: trimmed.length === 0 ? null : trimmed,\n    baseUrl:\n      typeof rawBase === 'string' && rawBase.trim().length > 0\n        ? rawBase.trim()\n        : DEFAULT_LICENCE_API_BASE_URL,\n    environment:\n      typeof rawEnvironment === 'string' &&\n      rawEnvironment.trim().toLowerCase() === 'sandbox'\n        ? 'sandbox'\n        : DEFAULT_LICENCE_ENVIRONMENT,\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Runs                                                                        */\n/* -------------------------------------------------------------------------- */\n\nexport interface LicenceRunDeps {\n  readonly licensing: LicensingPort;\n  readonly store: LicenceStorePort;\n  /**\n   * Where the verified calibration payload is cached and its state published.\n   *\n   * Optional, and its absence is a supported configuration rather than a\n   * mistake: a run without it resolves the entitlement exactly as it always\n   * did and simply does no calibration work. That is what makes this an\n   * additive change to a path whose failure is silent and nightly.\n   */\n  readonly calibration?: CalibrationStorePort | null;\n  readonly identity: WorkspaceIdentityPort;\n  /** Optional: without it the run still resolves state, it just writes no row. */\n  readonly client?: GreenlightApiClient | null;\n  readonly licenceKey: string | null;\n  /**\n   * Which environment the `licensing` port was pointed at. Passed separately\n   * rather than read back off the port because the port is an interface with no\n   * way to ask, and because the resolved state has to record what we *asked\n   * for* even when the call never left the building.\n   */\n  readonly environment: LicenceEnvironmentName;\n  readonly now: Date;\n}\n\nexport interface LicenceRunOutcome {\n  readonly state: LicenceState;\n  readonly notice: LicenceNotice;\n  /** What the activation attempt did, for the install path's return value. */\n  readonly activation: 'claimed' | 'limit_reached' | 'skipped' | 'failed' | 'not_attempted';\n  /** Null when no calibration store was wired. */\n  readonly calibration: RefreshCalibrationOutcome | null;\n}\n\n/**\n * Best-effort provenance row. Never fails the run \u2014 a licence check that\n * succeeded but could not be written to the audit log is still a licence check\n * that succeeded, and the resolved state has already been published to key-value\n * storage where the UI reads it.\n */\nconst writeLicenceAuditRow = async (\n  client: GreenlightApiClient | null | undefined,\n  state: LicenceState,\n  calibration: RefreshCalibrationOutcome | null,\n): Promise<boolean> => {\n  if (client === null || client === undefined) {\n    return false;\n  }\n\n  try {\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: buildLicenceAuditRow(state, calibration?.state ?? null),\n        },\n        id: true,\n      },\n    });\n\n    return true;\n  } catch (error) {\n    logGreenlight('licence_audit_write_failed', { error: describeError(error) });\n\n    return false;\n  }\n};\n\n/**\n * Resolve, persist, publish, audit, log. Shared by both entry points so the\n * install path and the nightly path cannot drift.\n */\nconst finishRun = async (\n  deps: LicenceRunDeps,\n  outcome: LicenceValidateOutcome | null,\n  activation: LicenceRunOutcome['activation'],\n): Promise<LicenceRunOutcome> => {\n  const presence = {\n    hasKey: deps.licenceKey !== null,\n    maskedKey: maskLicenceKey(deps.licenceKey),\n  };\n\n  const [cached, activationState] = await Promise.all([\n    deps.store.readCache(),\n    deps.store.readActivation(),\n  ]);\n\n  const { state, cacheWrite } = resolveLicenceState({\n    presence,\n    outcome,\n    cached,\n    activation: activationState,\n    environment: deps.environment,\n    now: deps.now,\n  });\n\n  if (cacheWrite !== null) {\n    await deps.store.writeCache(cacheWrite);\n  }\n\n  await deps.store.publishState(state);\n\n  // Calibration runs strictly after the entitlement has been resolved and\n  // published, and never before. See `src/calibration/refresh.ts`, \"Ordering\":\n  // nothing about a word list may be able to delay, fail or precede the decision\n  // that gates the paid feature and writes the admin notice.\n  const calibration =\n    deps.calibration === null || deps.calibration === undefined\n      ? null\n      : await refreshCalibration({\n          store: deps.calibration,\n          // Built here because this is one of the two modules that legitimately\n          // holds the raw key. The seal itself never receives it \u2014 see\n          // `licence-cache-seal.ts`.\n          seal: createLicenceKeySeal(deps.licenceKey),\n          metadata:\n            outcome !== null && outcome.kind === 'validated'\n              ? outcome.response.customerMetadata\n              : undefined,\n          live: outcome !== null && outcome.kind === 'validated',\n          // The same entitlement that gates enrichment. Calibration is the other\n          // half of what a licence buys, so it is bought on the same terms.\n          entitled: state.mode === 'full',\n          now: deps.now,\n        });\n\n  // Contains the mask, never the key \u2014 `buildLicenceAuditDetail` reads only\n  // fields of `LicenceState`, and `LicenceState` has no field that could hold\n  // a key. `describeCalibration` reads only counts and version numbers, never\n  // payload content.\n  logGreenlight('licence_resolved', {\n    ...buildLicenceAuditDetail(state),\n    activationAttempt: activation,\n    ...(calibration === null ? {} : describeCalibration(calibration)),\n  });\n\n  await writeLicenceAuditRow(deps.client, state, calibration);\n\n  return {\n    state,\n    notice: describeLicenceForAdmin(state),\n    activation,\n    calibration,\n  };\n};\n\nconst validateOnce = async (\n  deps: LicenceRunDeps,\n  workspace: WorkspaceIdentity | null,\n): Promise<LicenceValidateOutcome | null> => {\n  if (deps.licenceKey === null) {\n    return null;\n  }\n\n  try {\n    return await deps.licensing.validate({\n      key: deps.licenceKey,\n      deviceFingerprint: workspace?.workspaceId ?? null,\n      feature: ENRICHMENT_FEATURE_NAME,\n    });\n  } catch (error) {\n    // `LicensingPort` is documented as never throwing and the shipped adapter\n    // honours it. This catch is here because \"documented\" is not \"enforced by\n    // the type system\": a future adapter, or a test double, can throw, and the\n    // consequence would be a cron run that dies before publishing state.\n    // Downgrading it to the outcome the ladder already handles costs three\n    // lines and removes the failure mode entirely.\n    return {\n      kind: 'transport_failure',\n      detail: redactLicenceKey(describeError(error), deps.licenceKey),\n    };\n  }\n};\n\nconst readWorkspace = async (\n  identity: WorkspaceIdentityPort,\n): Promise<WorkspaceIdentity | null> => {\n  try {\n    return await identity.read();\n  } catch (error) {\n    logGreenlight('licence_workspace_identity_failed', {\n      error: describeError(error),\n    });\n\n    return null;\n  }\n};\n\n/**\n * Install: claim the activation slot, then validate.\n *\n * ## Why it validates even after a `409`\n *\n * The integration note's sketch returns early on `409`. This does not, and the\n * difference matters: because `validate` does not consult activation slots for\n * `Trial` / `Subscription` licences (gotcha 2), a refused workspace still gets\n * `valid: true, hasFeature: true`. Returning early would hide that, and \u2014 worse\n * \u2014 the *nightly* run has no activation step at all, so it would quietly switch\n * enrichment on the following morning.\n *\n * Instead the `409` is persisted, and `resolveLicenceState` applies it as an\n * override on every subsequent resolution. Validating anyway is then free\n * information: the admin notice can say how many days are left on the licence\n * that another workspace is holding, which is exactly what they need to decide\n * whether to free a slot or buy a seat.\n *\n * ## Idempotency\n *\n * `activate` is idempotent on `deviceFingerprint` \u2014 a repeat call with the same\n * workspace id returns the existing activation and consumes no second slot.\n * Reinstalling is therefore safe, and a successful activate clears a previously\n * stored `limit_reached`, which is how an admin who freed a slot recovers.\n */\nexport const runLicenceInstall = async (\n  deps: LicenceRunDeps,\n): Promise<LicenceRunOutcome> => {\n  if (deps.licenceKey === null) {\n    logGreenlight('licence_install_skipped', { reason: 'no_licence_key' });\n\n    return finishRun(deps, null, 'not_attempted');\n  }\n\n  const workspace = await readWorkspace(deps.identity);\n  let activation: LicenceRunOutcome['activation'] = 'skipped';\n\n  if (workspace === null) {\n    logGreenlight('licence_activate_skipped', {\n      reason: 'workspace_identity_unavailable',\n    });\n  } else {\n    const result = await deps.licensing.activate({\n      key: deps.licenceKey,\n      deviceFingerprint: workspace.workspaceId,\n      deviceName: workspace.workspaceName,\n    });\n\n    if (result.kind === 'activated') {\n      activation = 'claimed';\n      await deps.store.writeActivation({\n        status: 'claimed',\n        at: deps.now.toISOString(),\n      });\n    } else if (result.kind === 'activation_limit_reached') {\n      activation = 'limit_reached';\n      await deps.store.writeActivation({\n        status: 'limit_reached',\n        at: deps.now.toISOString(),\n      });\n    } else {\n      // A transport failure tells us nothing about the slot, so the stored\n      // activation state is left exactly as it was. Overwriting a known\n      // `claimed` with `unknown` because the network blipped would be losing\n      // information, not recording it.\n      activation = 'failed';\n      logGreenlight('licence_activate_failed', { failureKind: result.kind });\n    }\n  }\n\n  const outcome = await validateOnce(deps, workspace);\n\n  return finishRun(deps, outcome, activation);\n};\n\n/**\n * Nightly: validate, refresh the cache, republish the state, write the row.\n *\n * Never throws. The cron handler has nowhere to report a thrown error to, and a\n * run that dies before `finishRun` is a run that leaves yesterday's state\n * published \u2014 which is fine for a night and wrong for a month.\n */\nexport const runLicenceRevalidation = async (\n  deps: LicenceRunDeps,\n): Promise<LicenceRunOutcome> => {\n  const workspace = deps.licenceKey === null ? null : await readWorkspace(deps.identity);\n  const outcome = await validateOnce(deps, workspace);\n\n  return finishRun(deps, outcome, 'not_attempted');\n};\n", "import { kv } from 'twenty-sdk/logic-function';\n\nimport {\n  type ReleaseMarker,\n} from 'src/gate/release-decision';\nimport { type ReleaseMarkerStore } from 'src/logic-functions/scoring-run';\n\n/**\n * The real release-marker store: Twenty's app key-value storage.\n *\n * This is the only place in the scoring path that imports the SDK, which is why\n * it is three lines in a file of its own rather than a helper inside\n * `scoring-run.ts` \u2014 that module stays SDK-free so the whole run can be driven\n * by a fake in unit tests.\n *\n * `scope: 'WORKSPACE'` is not a detail: `release-lead.logic-function.ts` writes\n * the marker under that scope, and a read under a different scope silently finds\n * nothing. The key itself comes from `releaseMarkerKey` in\n * `src/gate/release-decision.ts` so neither side re-derives the string.\n */\nexport const kvReleaseMarkerStore: ReleaseMarkerStore = {\n  get: (key) => kv.get<ReleaseMarker>(key, { scope: 'WORKSPACE' }),\n  delete: async (key) => {\n    await kv.delete(key, { scope: 'WORKSPACE' });\n  },\n};\n", "/**\n * The scoring engine.\n *\n * Pure: no SDK import, no network, no I/O, no clock read. `now` arrives as a\n * parameter so every run is reproducible from its inputs alone.\n *\n * Fail-open is a hard product rule, and it is implemented at four levels:\n *   1. missing or unusable config     \u2192 seeded defaults / neutral weights\n *   2. a rule that throws             \u2192 recorded as `errored`, excluded from\n *                                       the score, never fatal\n *   3. nothing scorable at all        \u2192 decision `unscored`, lead passes\n *                                       through flagged rather than lost\n *   4. anything else that throws      \u2192 caught at the boundary, same as (3)\n *\n * A lead is never lost and never silently dropped.\n */\n\nimport { createFieldReader, isPlainObject } from 'src/scoring/field-access';\nimport { resolveConfig } from 'src/scoring/config';\nimport { ALL_RULES } from 'src/scoring/rules';\nimport { clamp01, roundTo } from 'src/scoring/rules/helpers';\nimport {\n  SCORING_ENGINE_VERSION,\n  type Degradation,\n  type GateDecision,\n  type LeadRecord,\n  type ResolvedScoringConfig,\n  type RuleSetting,\n  type RuleTraceEntry,\n  type RuleVerdict,\n  type ScoreLeadInput,\n  type ScoringBand,\n  type ScoringResult,\n  type ScoringRule,\n} from 'src/scoring/types';\n\nconst MAX_REASONS = 5;\n\nconst isUsableDate = (value: unknown): value is Date =>\n  value instanceof Date && !Number.isNaN(value.getTime());\n\nconst errorMessage = (error: unknown): string => {\n  if (error instanceof Error) {\n    return error.message;\n  }\n\n  return typeof error === 'string' ? error : 'unknown error';\n};\n\nconst creditFor = (verdict: RuleVerdict): number => {\n  switch (verdict.outcome) {\n    case 'pass':\n      return verdict.credit === undefined ? 1 : clamp01(verdict.credit);\n    case 'partial':\n      return verdict.credit === undefined ? 0.5 : clamp01(verdict.credit);\n    case 'fail':\n      return verdict.credit === undefined ? 0 : clamp01(verdict.credit);\n    case 'not_applicable':\n    default:\n      return 0;\n  }\n};\n\nconst settingFor = (\n  config: ResolvedScoringConfig,\n  rule: ScoringRule,\n): RuleSetting =>\n  config.rules[rule.id] ?? {\n    enabled: rule.defaultEnabled,\n    severity: rule.defaultSeverity,\n    weight: rule.defaultWeight,\n  };\n\nconst bandFor = (\n  score: number | null,\n  bands: readonly ScoringBand[],\n): ScoringBand | null => {\n  if (score === null) {\n    return null;\n  }\n\n  return (\n    [...bands]\n      .sort((a, b) => b.minScore - a.minScore)\n      .find((band) => score >= band.minScore) ?? null\n  );\n};\n\nconst SEVERITY_RANK: Record<string, number> = {\n  blocking: 0,\n  critical: 1,\n  major: 2,\n  minor: 3,\n  advisory: 4,\n};\n\nconst collectReasons = (trace: readonly RuleTraceEntry[]): string[] =>\n  trace\n    .filter(\n      (entry) =>\n        entry.contributed &&\n        (entry.outcome === 'fail' || entry.outcome === 'partial'),\n    )\n    .sort((a, b) => {\n      const bySeverity =\n        (SEVERITY_RANK[a.severity] ?? 9) - (SEVERITY_RANK[b.severity] ?? 9);\n\n      if (bySeverity !== 0) {\n        return bySeverity;\n      }\n\n      return b.pointsPossible - b.pointsEarned - (a.pointsPossible - a.pointsEarned);\n    })\n    .slice(0, MAX_REASONS)\n    .map((entry) => entry.explanation);\n\nconst summarise = (\n  decision: GateDecision,\n  score: number | null,\n  band: ScoringBand | null,\n  gateThreshold: number,\n  blockingReason: string | null,\n): string => {\n  switch (decision) {\n    case 'blocked':\n      return blockingReason ?? 'This lead is blocked from outreach on compliance grounds.';\n    case 'unscored':\n      return 'Greenlight could not score this lead, so it has been let through and flagged for a human to look at.';\n    case 'approved':\n      return `Cleared to work \u2014 scored ${score ?? 0}/100${\n        band === null ? '' : ` (${band.label})`\n      }, at or above your ${gateThreshold} threshold.`;\n    case 'gated':\n    default:\n      return `Held for review \u2014 scored ${score ?? 0}/100${\n        band === null ? '' : ` (${band.label})`\n      }, below your ${gateThreshold} threshold. Anyone can release it.`;\n  }\n};\n\nconst normaliseLead = (\n  lead: unknown,\n  degradations: Degradation[],\n): LeadRecord => {\n  if (!isPlainObject(lead)) {\n    degradations.push({\n      code: 'lead_malformed',\n      message:\n        'The lead record could not be read, so it was scored as if every field were empty. It has been let through and flagged.',\n    });\n\n    return { id: null, fields: {} };\n  }\n\n  const id = typeof lead['id'] === 'string' ? lead['id'] : null;\n  const fields = lead['fields'];\n\n  if (!isPlainObject(fields)) {\n    degradations.push({\n      code: 'lead_malformed',\n      message:\n        'The lead record had no readable fields, so it was scored as if every field were empty. It has been let through and flagged.',\n    });\n\n    return { id, fields: {} };\n  }\n\n  return { id, fields };\n};\n\nconst evaluateRule = (\n  rule: ScoringRule,\n  config: ResolvedScoringConfig,\n  lead: LeadRecord,\n  now: Date | null,\n  degradations: Degradation[],\n): RuleTraceEntry => {\n  const setting = settingFor(config, rule);\n  const reader = createFieldReader(lead, config.fieldMapping);\n\n  const base = {\n    ruleId: rule.id,\n    ruleName: rule.name,\n    category: rule.category,\n    question: rule.question,\n    severity: setting.severity,\n    weight: setting.weight,\n  } as const;\n\n  if (!setting.enabled) {\n    return {\n      ...base,\n      outcome: 'skipped',\n      credit: 0,\n      pointsEarned: 0,\n      pointsPossible: 0,\n      contributed: false,\n      explanation: `\"${rule.name}\" is switched off in your Greenlight settings, so it did not affect this score.`,\n      observations: [],\n    };\n  }\n\n  let verdict: RuleVerdict;\n\n  try {\n    verdict = rule.evaluate({ lead, config, now, read: reader });\n  } catch (error) {\n    // Fail-open level 2: a broken rule is reported, never fatal, and never\n    // drags the lead's score down.\n    const message = errorMessage(error);\n\n    degradations.push({\n      code: 'rule_errored',\n      message: `The \"${rule.name}\" check could not run, so it was left out of this score.`,\n      detail: `${rule.id}: ${message}`,\n    });\n\n    return {\n      ...base,\n      outcome: 'errored',\n      credit: 0,\n      pointsEarned: 0,\n      pointsPossible: 0,\n      contributed: false,\n      explanation: `The \"${rule.name}\" check could not run and was left out of this score, so the lead was not penalised for it.`,\n      remedy: 'Report this to your Greenlight administrator \u2014 it is a fault in the app, not in the lead.',\n      observations: reader.observations(),\n      error: message,\n    };\n  }\n\n  const isScorable =\n    verdict.outcome === 'pass' ||\n    verdict.outcome === 'partial' ||\n    verdict.outcome === 'fail';\n\n  const contributed = isScorable && setting.severity !== 'advisory';\n  const credit = creditFor(verdict);\n  const pointsPossible = contributed ? setting.weight : 0;\n  const pointsEarned = contributed ? roundTo(setting.weight * credit, 4) : 0;\n\n  const entry: RuleTraceEntry = {\n    ...base,\n    outcome: verdict.outcome,\n    credit,\n    pointsEarned,\n    pointsPossible,\n    contributed,\n    explanation: verdict.explanation,\n    observations: reader.observations(),\n  };\n\n  return {\n    ...entry,\n    ...(verdict.remedy === undefined ? {} : { remedy: verdict.remedy }),\n    ...(verdict.detail === undefined ? {} : { detail: verdict.detail }),\n  };\n};\n\nconst runScoring = (input: ScoreLeadInput): ScoringResult => {\n  const degradations: Degradation[] = [];\n  const rules = input.rules ?? ALL_RULES;\n\n  const lead = normaliseLead(input.lead, degradations);\n\n  let now: Date | null = null;\n\n  if (isUsableDate(input.now)) {\n    now = input.now;\n  } else {\n    degradations.push({\n      code: 'now_malformed',\n      message:\n        'The run had no usable date, so any check that depends on how old the data is was skipped.',\n    });\n  }\n\n  // The baseline is licence-delivered vocabulary and is threaded straight\n  // through to config resolution \u2014 the engine never inspects it, and no rule\n  // ever sees it as anything but the ordinary resolved lists. An absent\n  // baseline resolves exactly as this call did before the parameter existed.\n  const resolution = resolveConfig(input.config, rules, input.baseline);\n  degradations.push(...resolution.degradations);\n\n  const { config } = resolution;\n\n  const trace = rules.map((rule) =>\n    evaluateRule(rule, config, lead, now, degradations),\n  );\n\n  const contributing = trace.filter((entry) => entry.contributed);\n  const totalWeight = roundTo(\n    contributing.reduce((sum, entry) => sum + entry.pointsPossible, 0),\n    4,\n  );\n  const earnedWeight = roundTo(\n    contributing.reduce((sum, entry) => sum + entry.pointsEarned, 0),\n    4,\n  );\n\n  let score: number | null = null;\n\n  if (totalWeight > 0) {\n    score = roundTo((earnedWeight / totalWeight) * 100, 1);\n  } else {\n    // Fail-open level 3: nothing could be scored. The lead is not held on a\n    // technicality \u2014 it goes through, flagged.\n    degradations.push({\n      code: 'no_scorable_rules',\n      message:\n        'No Greenlight check was able to score this lead, so it was let through unscored and flagged for review.',\n    });\n  }\n\n  const band = bandFor(score, config.bands);\n\n  const blockingFailure = trace.find(\n    (entry) => entry.severity === 'blocking' && entry.outcome === 'fail',\n  );\n  const criticalFailure = trace.find(\n    (entry) => entry.severity === 'critical' && entry.outcome === 'fail',\n  );\n\n  let decision: GateDecision;\n\n  if (blockingFailure !== undefined) {\n    decision = 'blocked';\n  } else if (score === null) {\n    decision = 'unscored';\n  } else if (criticalFailure !== undefined) {\n    decision = 'gated';\n  } else {\n    decision = score >= config.gateThreshold ? 'approved' : 'gated';\n  }\n\n  const reasons = collectReasons(trace);\n\n  return {\n    score,\n    band,\n    decision,\n    gateThreshold: config.gateThreshold,\n    summary: summarise(\n      decision,\n      score,\n      band,\n      config.gateThreshold,\n      blockingFailure?.explanation ?? null,\n    ),\n    reasons,\n    trace,\n    degradations,\n    configSource: resolution.source,\n    scoredAt: now === null ? null : now.toISOString(),\n    leadId: lead.id ?? null,\n    engineVersion: SCORING_ENGINE_VERSION,\n    totalWeight,\n    earnedWeight,\n  };\n};\n\n/**\n * Score a lead and decide whether it is cleared to work.\n *\n * This is the entire public entry point. It never throws and always returns a\n * result \u2014 that guarantee is the product, not an implementation detail.\n */\nexport const scoreLead = (input: ScoreLeadInput): ScoringResult => {\n  try {\n    return runScoring(input);\n  } catch (error) {\n    // Fail-open level 4: the engine itself broke. The lead still passes.\n    const leadId =\n      isPlainObject(input?.lead) && typeof input.lead['id'] === 'string'\n        ? input.lead['id']\n        : null;\n\n    return {\n      score: null,\n      band: null,\n      decision: 'unscored',\n      gateThreshold: 0,\n      summary:\n        'Greenlight hit an unexpected error and could not score this lead, so it has been let through and flagged for a human to look at.',\n      reasons: ['Greenlight could not complete a scoring run for this lead.'],\n      trace: [],\n      degradations: [\n        {\n          code: 'engine_errored',\n          message:\n            'Greenlight hit an unexpected error while scoring. The lead was let through rather than held.',\n          detail: errorMessage(error),\n        },\n      ],\n      configSource: 'defaults',\n      scoredAt: isUsableDate(input?.now) ? input.now.toISOString() : null,\n      leadId,\n      engineVersion: SCORING_ENGINE_VERSION,\n      totalWeight: 0,\n      earnedWeight: 0,\n    };\n  }\n};\n", "/**\n * Numaya Greenlight \u2014 the decision half of the human override.\n *\n * Everything in this file is pure: no SDK import, no network, no clock read.\n * The logic function is a thin shell that fetches state, calls `decideRelease`,\n * and executes whatever it is told. That split exists because the override is\n * the GDPR Art. 22 load-bearing part of the product \u2014 the rules about what may\n * and may not be released have to be exhaustively testable without a live\n * Twenty workspace.\n *\n * Naming note: the engine's four decision states (`approved` / `gated` /\n * `blocked` / `unscored`, see `src/scoring/types.ts`) now map one-to-one onto\n * the `greenlightDecision` SELECT field on Person, which ships four options\n * (`PASS` / `GATE` / `BLOCKED` / `UNSCORED`). A compliance stop is therefore\n * readable straight off the field. Records scored before the `BLOCKED` option\n * existed still read `GATE`, so `isComplianceBlocked` survives as a fallback \u2014\n * see the comment on `blockedFromLead` for exactly when each one answers.\n */\n\n/* -------------------------------------------------------------------------- */\n/* The compliance question                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Whether a lead that the engine marked `blocked` may be released by a human.\n *\n * **True \u2014 product decision, 2026-08-02.** The opt-out register is maintained by\n * the sales team inside Twenty, and the business trusts the person maintaining\n * it to also be the person who corrects it. An earlier iteration refused this\n * and required the contact to re-consent by email; that was withdrawn, because\n * Twenty sends no email and building an outbound provider to gate a correction\n * the sales team is trusted to make anyway is disproportionate.\n *\n * What this restores: the golden rule in `ARCHITECTURE.md` and the promise in\n * `PRODUCT_SPEC.md` that a human can always release a held lead, with no\n * exception carved out for compliance.\n *\n * What it costs, stated plainly rather than buried:\n *\n *   1. A released compliance block leaves the record in a **contradictory\n *      state** \u2014 `greenlightDecision` says the lead is cleared while the\n *      suppression fields still say do-not-contact. The audit row is the only\n *      thing that explains it. Prefer clearing the suppression itself (\"Allow\n *      contact again\") when the block was recorded in error: that re-scores the\n *      lead and clears the gate through the data, which reads far better in a\n *      DPA conversation than an override sitting on top of a live opt-out.\n *   2. Under GDPR Art. 21(3) an objection to direct marketing is absolute, and\n *      \"a salesperson approved it\" is not a lawful basis on its own. This\n *      setting assumes the release reflects a real-world correction \u2014 the\n *      contact never opted out, or asked to be added back \u2014 not a decision to\n *      market to someone who said stop. That assumption is the customer's to\n *      hold, and every release is audited with who, when and why so it can be\n *      evidenced.\n *\n * Setting this back to `false` re-refuses compliance releases; the refusal\n * branch and its tests are the only readers.\n */\nexport const ALLOW_COMPLIANCE_OVERRIDE = true;\n\n/* -------------------------------------------------------------------------- */\n/* Reasons                                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The override reason is a **mandatory choice from a closed list**, plus an\n * optional free-text note.\n *\n * `ARCHITECTURE.md` leaves this as \"reason/none\". Neither extreme works:\n *\n *   - Optional reason. The whole Art. 22 argument is that a human applied\n *     judgement. An override with no recorded reason is indistinguishable in\n *     the audit trail from an automated release, so it evidences nothing.\n *\n *   - Mandatory free text. A required text box gets \"ok\" typed into it, which\n *     is worse than nothing: it manufactures the appearance of a reasoned\n *     decision without the substance, and it is unanalysable in aggregate. It\n *     is also a data-protection liability in its own right \u2014 an uncontrolled\n *     free-text field on an append-only log that nobody ever deletes is exactly\n *     where a rep eventually types something that should never have been\n *     recorded about a person.\n *\n * A required pick from five categories is a real judgement, cheap to make,\n * impossible to fake into meaninglessness, and analysable: 200 releases tagged\n * `ICP_TOO_NARROW` are not 200 judgement calls, they are one misconfigured ICP,\n * and the queue can say so. The optional note carries the specifics when there\n * are any.\n */\nexport const RELEASE_REASONS = [\n  {\n    code: 'ICP_TOO_NARROW',\n    label: 'Scoring rules are too narrow for this lead',\n    hint: 'The lead is fine; the ICP or rule configuration is what is wrong.',\n  },\n  {\n    code: 'DATA_INCOMPLETE',\n    label: 'Lead data is incomplete but I know this is a good lead',\n    hint: 'Missing fields dragged the score down. You have the context the record does not.',\n  },\n  {\n    code: 'KNOWN_ACCOUNT',\n    label: 'Existing relationship or inbound request',\n    hint: 'They asked us to get in touch, or there is a live thread already.',\n  },\n  {\n    code: 'STRATEGIC_EXCEPTION',\n    label: 'Deliberate exception I am accounting for',\n    hint: 'The gate is right and you are overriding it anyway, on purpose.',\n  },\n  {\n    code: 'TESTING',\n    label: 'Testing Greenlight',\n    hint: 'Keeps test releases out of the real override statistics.',\n  },\n] as const;\n\nexport type ReleaseReasonCode = (typeof RELEASE_REASONS)[number]['code'];\n\nexport const RELEASE_REASON_CODES: readonly ReleaseReasonCode[] =\n  RELEASE_REASONS.map((reason) => reason.code);\n\n/** Free-text notes are capped: an audit field is not a place to write an essay. */\nexport const MAX_REASON_NOTE_LENGTH = 500;\n\nconst findReason = (code: string) =>\n  RELEASE_REASONS.find((reason) => reason.code === code) ?? null;\n\n/* -------------------------------------------------------------------------- */\n/* Requests                                                                    */\n/* -------------------------------------------------------------------------- */\n\nexport interface ReleaseRequest {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly reasonCode: ReleaseReasonCode;\n  /** Empty string when the reviewer did not add one. */\n  readonly reasonNote: string;\n}\n\nexport type ParseResult =\n  | { readonly ok: true; readonly request: ReleaseRequest }\n  | { readonly ok: false; readonly message: string };\n\nconst UUID = /^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;\n\n/**\n * v0.1 physically ships the score fields on Person only (`defineField` binds at\n * build time \u2014 see `greenlight-score.field.ts`). Accepting any other object name\n * would mean writing `greenlightDecision` to an object that does not have it.\n * The parameter exists so the Layer 3 seam is visible in the wire format, not\n * because it is configurable yet.\n */\nexport const SUPPORTED_LEAD_OBJECTS: readonly string[] = ['person'];\n\nconst asString = (value: unknown): string | null =>\n  typeof value === 'string' ? value : null;\n\nconst isRecord = (value: unknown): value is Record<string, unknown> =>\n  typeof value === 'object' && value !== null && !Array.isArray(value);\n\nexport const parseReleaseRequest = (body: unknown): ParseResult => {\n  if (typeof body !== 'object' || body === null || Array.isArray(body)) {\n    return { ok: false, message: 'Release request body must be an object.' };\n  }\n\n  const raw = body as Record<string, unknown>;\n\n  const recordId = asString(raw['recordId'])?.trim() ?? '';\n\n  if (!UUID.test(recordId)) {\n    return { ok: false, message: 'Release request needs a valid recordId.' };\n  }\n\n  const leadObjectNameSingular =\n    asString(raw['leadObjectNameSingular'])?.trim() || 'person';\n\n  if (!SUPPORTED_LEAD_OBJECTS.includes(leadObjectNameSingular)) {\n    return {\n      ok: false,\n      message: `Greenlight v0.1 can only release leads on ${SUPPORTED_LEAD_OBJECTS.join(', ')}, not ${leadObjectNameSingular}.`,\n    };\n  }\n\n  const reasonCode = asString(raw['reasonCode'])?.trim() ?? '';\n  const reason = findReason(reasonCode);\n\n  if (reason === null) {\n    return {\n      ok: false,\n      message:\n        'Choose why you are releasing this lead. A recorded reason is what makes the override a human decision rather than an automated one.',\n    };\n  }\n\n  const reasonNote = (asString(raw['reasonNote']) ?? '')\n    .trim()\n    .slice(0, MAX_REASON_NOTE_LENGTH);\n\n  return {\n    ok: true,\n    request: {\n      leadObjectNameSingular,\n      recordId,\n      reasonCode: reason.code,\n      reasonNote,\n    },\n  };\n};\n\n/** The audit-trail rendering of a reason: machine code first, prose after. */\nexport const formatOverrideReason = (\n  reasonCode: ReleaseReasonCode,\n  reasonNote: string,\n): string => {\n  const reason = findReason(reasonCode);\n  const label = reason === null ? reasonCode : `${reason.code} \u00B7 ${reason.label}`;\n\n  return reasonNote === '' ? label : `${label} \u2014 ${reasonNote}`;\n};\n\n/* -------------------------------------------------------------------------- */\n/* Current state of the lead                                                   */\n/* -------------------------------------------------------------------------- */\n\n/** Values of the `greenlightDecision` SELECT on Person. */\nexport const DECISION_PASS = 'PASS';\nexport const DECISION_GATE = 'GATE';\nexport const DECISION_BLOCKED = 'BLOCKED';\nexport const DECISION_UNSCORED = 'UNSCORED';\n\nconst KNOWN_DECISIONS: readonly string[] = [\n  DECISION_PASS,\n  DECISION_GATE,\n  DECISION_BLOCKED,\n  DECISION_UNSCORED,\n];\n\n/** `greenlightDecision` as stored, normalised. Null when it is not a value we ship. */\nexport const normaliseDecision = (raw: string | null): string | null => {\n  const value = raw?.trim().toUpperCase() ?? '';\n\n  return KNOWN_DECISIONS.includes(value) ? value : null;\n};\n\n/**\n * The decision an audit row should record as the state the lead was left in.\n *\n * A refused release leaves the lead exactly where it was, and \"where it was\"\n * is now a distinction worth keeping: a refusal against a `BLOCKED` record and\n * a refusal against a `GATE` record are different compliance stories. Anything\n * unrecognised degrades to `GATE` rather than being written through, because\n * this value goes into a SELECT that would reject an unknown option and lose\n * the row.\n */\nexport const auditDecisionValue = (\n  currentDecision: string | null,\n  shouldClearGate: boolean,\n): string =>\n  shouldClearGate\n    ? DECISION_PASS\n    : (normaliseDecision(currentDecision) ?? DECISION_GATE);\n\n/** Values of the `band` SELECT on GreenlightAuditLog. */\nexport const BAND_UNSCORED = 'UNSCORED';\n\nconst KNOWN_BANDS: readonly string[] = [\n  'EXCELLENT',\n  'GOOD',\n  'FAIR',\n  'POOR',\n  BAND_UNSCORED,\n];\n\n/**\n * The band an override's audit row should record.\n *\n * The release path used to write no band at all, so every `RELEASED` row took\n * the field's `UNSCORED` default while the `GATED` row for the same lead read\n * `POOR`. Two contradictory bands for one lead is not a compliance record, it is\n * a bug with a paper trail \u2014 a reviewer comparing the two rows cannot tell which\n * one is lying.\n *\n * The band is **read out of the trace the scoring run left on the record**, not\n * recomputed here. The engine's bands are configurable (`bandExcellentThreshold`\n * and friends on GreenlightConfig), so deriving a band from the score with the\n * shipped defaults would produce a *different* wrong answer in any workspace\n * that moved a threshold \u2014 and it would disagree with the `GATED` row all over\n * again. The trace carries the band that run actually chose, which is the only\n * value that can agree with the earlier row by construction.\n *\n * `UNSCORED` remains the answer when the trace is missing or unreadable, but it\n * now means what the option says: nothing here knows the band. That is the state\n * of a lead released before it was ever scored, which the queue does allow.\n */\nexport const auditBandValue = (trace: unknown): string => {\n  if (!isRecord(trace)) {\n    return BAND_UNSCORED;\n  }\n\n  const value = asString(trace['band'])?.trim().toUpperCase() ?? '';\n\n  return KNOWN_BANDS.includes(value) ? value : BAND_UNSCORED;\n};\n\nexport interface CurrentLeadState {\n  readonly recordId: string;\n  /** Denormalised into the audit row so the trail survives the record. */\n  readonly displayName: string;\n  /** Raw `greenlightDecision`. Null when the lead has never been scored. */\n  readonly decision: string | null;\n  readonly score: number | null;\n  /** Raw `greenlightTrace`, whatever shape the engine wrote. */\n  readonly trace: unknown;\n}\n\n/**\n * A human release, recorded outside the record so the scoring function can see\n * it. Written to app key-value storage by the override; see the contract note\n * on `RELEASE_MARKER_SCOPE` below.\n */\nexport interface ReleaseMarker {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  /** ISO 8601. */\n  readonly releasedAt: string;\n  readonly releasedBy: string;\n  readonly reasonCode: string;\n}\n\nexport const releaseMarkerKey = (\n  leadObjectNameSingular: string,\n  recordId: string,\n): string => `greenlight:release:${leadObjectNameSingular}:${recordId}`;\n\n/**\n * Two releases of the same lead inside this window are the same release \u2014 a\n * double-click, or Twenty re-delivering the request. Mirrors the 5s event\n * de-duplication window ARCHITECTURE.md \u00A7 \"Idempotency & Retry Safety\" already\n * assumes, with headroom for a slow round trip.\n *\n * This is a *narrow race* guard only. The authoritative double-release check is\n * the decision field itself: if the lead already reads PASS it is not held, so\n * there is nothing to release, whatever the marker says. The marker can be\n * stale \u2014 a lead released on Monday and legitimately re-gated on Tuesday after\n * its email was deleted must be releasable again on Tuesday.\n */\nexport const DUPLICATE_RELEASE_WINDOW_MS = 10_000;\n\n/* -------------------------------------------------------------------------- */\n/* Compliance block detection                                                  */\n/* -------------------------------------------------------------------------- */\n\nconst entryIsBlocking = (entry: unknown): boolean => {\n  if (!isRecord(entry)) {\n    return false;\n  }\n\n  const severity = asString(entry['severity'])?.toLowerCase() ?? '';\n  const outcome = asString(entry['outcome'])?.toLowerCase() ?? '';\n\n  return severity === 'blocking' && outcome === 'fail';\n};\n\nconst traceEntries = (trace: unknown): readonly unknown[] => {\n  if (Array.isArray(trace)) {\n    return trace;\n  }\n\n  if (!isRecord(trace)) {\n    return [];\n  }\n\n  for (const key of ['rules', 'trace', 'entries']) {\n    const candidate = trace[key];\n\n    if (Array.isArray(candidate)) {\n      return candidate;\n    }\n  }\n\n  return [];\n};\n\n/**\n * Recover the engine's `blocked` state from the trace.\n *\n * **This is the legacy path.** `greenlightDecision` now ships a `BLOCKED`\n * option, so a lead scored by any current build states its compliance stop on\n * the field itself and never reaches this function. It is kept because nothing\n * backfills a SELECT option: every lead scored before the option existed still\n * reads `GATE`, and reading the trace is the only way to tell those apart. See\n * `blockedFromLead`.\n *\n * **It is the one place the queue depends on a shape the scoring function\n * writes, and it is deliberately forgiving about that shape**, because the trace\n * field's exact envelope is not pinned down anywhere in the spec. Accepted, in\n * order:\n *\n *   - a top-level `decision` of `blocked` (any case) on the trace object;\n *   - an array of rule-trace entries, or `{ rules: [...] }` / `{ trace: [...] }`\n *     / `{ entries: [...] }`, containing an entry with\n *     `severity: 'blocking'` and `outcome: 'fail'` \u2014 the exact discriminator\n *     `src/scoring/engine.ts` itself uses to choose `blocked`.\n *\n * If the trace is missing or unreadable the answer is `false`: an unreadable\n * trace must not silently turn every held lead into an unreleasable one. That\n * is the fail-open direction for *this* check, and it is the right one \u2014 the\n * compliance rule that produced the block also wrote an audit row, and a lead\n * whose trace we cannot read is a lead we cannot claim anything about.\n */\nexport const isComplianceBlocked = (trace: unknown): boolean => {\n  if (isRecord(trace)) {\n    const declared = asString(trace['decision'])?.toLowerCase() ?? '';\n\n    if (declared === 'blocked') {\n      return true;\n    }\n  }\n\n  return traceEntries(trace).some(entryIsBlocking);\n};\n\n/**\n * Is this lead held on compliance grounds?\n *\n * Field first, trace second, and the order is the whole point:\n *\n *   - **The field** is the current, cheap, unambiguous answer for anything\n *     scored since `BLOCKED` shipped. One string comparison, no assumptions\n *     about a RAW_JSON envelope.\n *   - **The trace** answers for records scored before that, which still read\n *     `GATE` because adding a SELECT option does not rewrite existing rows.\n *     Dropping this fallback would quietly make every historic opt-out\n *     releasable by hand on the day the option was added \u2014 the exact failure the\n *     compliance refusal exists to prevent. It can go once a workspace has\n *     re-scored every lead, which is not something this code can know.\n */\nconst blockedFromLead = (lead: CurrentLeadState): boolean =>\n  normaliseDecision(lead.decision) === DECISION_BLOCKED ||\n  isComplianceBlocked(lead.trace);\n\n/* -------------------------------------------------------------------------- */\n/* The decision                                                                */\n/* -------------------------------------------------------------------------- */\n\nexport type ReleaseOutcome =\n  /** The gate was cleared and an audit row must be written. */\n  | 'released'\n  /** Already `PASS`. Not an error \u2014 the rep got what they wanted. */\n  | 'already_released'\n  /** `UNSCORED`: the engine failed open, the lead was never held. */\n  | 'not_held'\n  /** No decision at all: never scored, so never gated. */\n  | 'not_scored'\n  /** A second request inside the de-duplication window. */\n  | 'duplicate_request'\n  /** Compliance stop. See `ALLOW_COMPLIANCE_OVERRIDE`. */\n  | 'refused_compliance_block';\n\nexport interface ReleaseDecision {\n  readonly outcome: ReleaseOutcome;\n  /** Shown to the reviewer. Written for a salesperson, not a developer. */\n  readonly message: string;\n  /** Whether `greenlightDecision` must be written to `PASS`. */\n  readonly shouldClearGate: boolean;\n  /** Whether a `GreenlightAuditLog` row must be appended. */\n  readonly shouldWriteAuditRow: boolean;\n  /** `RELEASED` for a real release, `SKIPPED` for a recorded refusal. */\n  readonly auditEventType: 'RELEASED' | 'SKIPPED' | null;\n  /** Rendered reason for the audit row. Empty when no row is written. */\n  readonly overrideReason: string;\n  /** Whether the release marker must be written for the scoring function. */\n  readonly shouldWriteMarker: boolean;\n}\n\nexport interface DecideReleaseInput {\n  readonly request: ReleaseRequest;\n  readonly lead: CurrentLeadState;\n  /** Previous release of this lead, if app storage had one. */\n  readonly marker: ReleaseMarker | null;\n  /** The clock, passed in \u2014 this module never reads it. */\n  readonly now: Date;\n}\n\nconst noop = (\n  outcome: ReleaseOutcome,\n  message: string,\n): ReleaseDecision => ({\n  outcome,\n  message,\n  shouldClearGate: false,\n  shouldWriteAuditRow: false,\n  auditEventType: null,\n  overrideReason: '',\n  shouldWriteMarker: false,\n});\n\nconst isWithinDuplicateWindow = (\n  marker: ReleaseMarker | null,\n  now: Date,\n): boolean => {\n  if (marker === null) {\n    return false;\n  }\n\n  const releasedAt = Date.parse(marker.releasedAt);\n\n  if (Number.isNaN(releasedAt)) {\n    return false;\n  }\n\n  const elapsed = now.getTime() - releasedAt;\n\n  return elapsed >= 0 && elapsed < DUPLICATE_RELEASE_WINDOW_MS;\n};\n\n/**\n * Decide what the override should do. Never throws.\n *\n * Order matters and is not arbitrary:\n *\n *   1. **Not held** beats everything. If the gate is already open there is\n *      nothing to release, so we neither write the record nor append an audit\n *      row \u2014 a rep double-clicking must not manufacture history. This is the\n *      \"safe against releasing something already approved\" guarantee, and it is\n *      checked against the record's own field rather than against any cached\n *      marker, because the field is the only authoritative statement of whether\n *      the lead is held right now.\n *   2. **Compliance** beats the reviewer. Read from `greenlightDecision` when it\n *      says `BLOCKED`, and from the trace otherwise so pre-`BLOCKED` records\n *      still refuse (`blockedFromLead`). Checked before the duplicate window so\n *      that every attempt against a blocked lead is recorded, including repeat\n *      attempts \u2014 repeated attempts to release an opt-out are exactly the\n *      pattern a DPO would want to see.\n *   3. **Duplicate window** catches the narrow double-submit race that the\n *      field check cannot see, because both requests read `GATE` before either\n *      wrote `PASS`.\n */\nexport const decideRelease = (input: DecideReleaseInput): ReleaseDecision => {\n  const { request, lead, marker, now } = input;\n\n  const decision = lead.decision?.trim().toUpperCase() ?? null;\n\n  if (decision === null || decision === '') {\n    return noop(\n      'not_scored',\n      'This lead has no Greenlight decision yet, so it is not being held. Nothing to release.',\n    );\n  }\n\n  if (decision === DECISION_PASS) {\n    return noop(\n      'already_released',\n      'This lead has already cleared the gate. No change made, and no second audit entry written.',\n    );\n  }\n\n  if (decision === DECISION_UNSCORED) {\n    return noop(\n      'not_held',\n      'Greenlight could not score this lead, so it was let through unscored rather than held. There is no gate to clear.',\n    );\n  }\n\n  if (decision !== DECISION_GATE && decision !== DECISION_BLOCKED) {\n    return noop(\n      'not_held',\n      `This lead is in an unrecognised Greenlight state (${decision}), so the override left it alone.`,\n    );\n  }\n\n  const blocked = blockedFromLead(lead);\n\n  if (blocked && !ALLOW_COMPLIANCE_OVERRIDE) {\n    return {\n      outcome: 'refused_compliance_block',\n      message:\n        'This lead is held on compliance grounds \u2014 the record carries a recorded opt-out. That is the contact\\'s own instruction, not a scoring judgement, so it cannot be overridden here. Correct the opt-out data on the record if it is wrong; the lead will re-score and clear itself.',\n      shouldClearGate: false,\n      // The refusal *is* recorded. An attempt to release an opted-out contact\n      // is a compliance-relevant human action even though nothing changed.\n      shouldWriteAuditRow: true,\n      auditEventType: 'SKIPPED',\n      overrideReason: `REFUSED_COMPLIANCE_BLOCK \u2014 release attempted with reason ${formatOverrideReason(\n        request.reasonCode,\n        request.reasonNote,\n      )}`,\n      shouldWriteMarker: false,\n    };\n  }\n\n  if (isWithinDuplicateWindow(marker, now)) {\n    return noop(\n      'duplicate_request',\n      'This lead was released moments ago. Treating this as a duplicate submission and leaving the audit trail alone.',\n    );\n  }\n\n  return {\n    outcome: 'released',\n    message: 'Released. The lead is cleared to work and the override is on record.',\n    shouldClearGate: true,\n    shouldWriteAuditRow: true,\n    auditEventType: 'RELEASED',\n    overrideReason: formatOverrideReason(request.reasonCode, request.reasonNote),\n    shouldWriteMarker: true,\n  };\n};\n\n/** One-line summary used as the audit row's record label. */\nexport const buildAuditSummary = (\n  eventType: 'RELEASED' | 'SKIPPED',\n  lead: CurrentLeadState,\n): string => {\n  const name = lead.displayName.trim() === '' ? 'Unnamed lead' : lead.displayName;\n  const score = lead.score === null ? 'unscored' : String(lead.score);\n\n  return `${eventType} \u00B7 ${name} \u00B7 ${score}`;\n};\n", "/**\n * Numaya Greenlight \u2014 the decision half of the suppression / block list.\n *\n * Everything in this file is pure: no SDK import, no network, no clock read.\n * The two logic functions are thin shells that fetch state, call `decideSuppress`\n * or `decideUnsuppress`, and execute whatever they are told. Same split, and the\n * same reason, as `src/gate/release-decision.ts`: this is the part a regulator\n * would read, so it has to be exhaustively testable without a live workspace.\n *\n * ## Why Greenlight owns this data at all\n *\n * Twenty does no email management. There is no unsubscribe handling, no bounce\n * tracking and no do-not-contact list anywhere in the product. Greenlight's\n * compliance rule used to read an opt-out flag purely through the customer's\n * Layer 3 field mapping (`optOutFieldNames`), and on a stock workspace that\n * mapping resolves to nothing at all \u2014 so the rule returned `pass`, awarded its\n * full 15 points, and could never once fire. The one compliance check in the\n * product was decorative on a default install.\n *\n * The four `greenlightSuppress*` fields on Person are the fix. They are the\n * register Twenty does not have, they are Greenlight's own, and \u2014 unlike the\n * score fields \u2014 they are UI-editable, because they are human-maintained data\n * rather than engine output.\n *\n * ## Union, not override\n *\n * A customer who already has an opt-out column keeps it working. The compliance\n * rule reads Greenlight's field *and* the customer's mapping and any source\n * saying \"suppressed\" wins. Nothing in this file assumes Greenlight's field is\n * the only one; it is only the only one Greenlight can write.\n */\n\n/* -------------------------------------------------------------------------- */\n/* The Person fields this feature owns                                         */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The suppression columns on the lead-bearing object.\n *\n * Declared here rather than in `scoring-run.ts` because both the scoring side\n * (which must re-score when they change) and the two action logic functions\n * (which write them) need the same strings, and a drift between the two is an\n * infinite loop or a silently ignored block, neither of which shows up in a\n * type error.\n */\nexport const SUPPRESSION_FIELD_SUPPRESSED = 'greenlightSuppressed';\nexport const SUPPRESSION_FIELD_REASON = 'greenlightSuppressionReason';\nexport const SUPPRESSION_FIELD_SUPPRESSED_AT = 'greenlightSuppressedAt';\nexport const SUPPRESSION_FIELD_NOTE = 'greenlightSuppressionNote';\n\nexport const SUPPRESSION_PERSON_FIELDS: readonly string[] = [\n  SUPPRESSION_FIELD_SUPPRESSED,\n  SUPPRESSION_FIELD_REASON,\n  SUPPRESSION_FIELD_SUPPRESSED_AT,\n  SUPPRESSION_FIELD_NOTE,\n];\n\n/**\n * The subset whose change can move the score, i.e. the ones the re-score trigger\n * listens on.\n *\n * `greenlightSuppressedAt` and `greenlightSuppressionNote` are excluded: neither\n * is read by any rule, both are always written in the same mutation as the flag,\n * and every name on a trigger allow-list is another chance for a write loop.\n */\nexport const SUPPRESSION_SCORING_INPUT_FIELDS: readonly string[] = [\n  SUPPRESSION_FIELD_SUPPRESSED,\n  SUPPRESSION_FIELD_REASON,\n];\n\n/* -------------------------------------------------------------------------- */\n/* Why someone is suppressed                                                   */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The closed list of suppression reasons.\n *\n * Closed rather than free text for the same reason the release override's reason\n * list is closed (see `release-decision.ts`), plus one this list has and that one\n * does not: these categories carry different *legal* weight. \"Unsubscribed\" and\n * \"legal or erasure request\" are both do-not-contact, but only one of them\n * survives a change of marketing platform, and only one of them makes lifting the\n * suppression a decision somebody senior should be making. A free-text column\n * cannot be filtered, counted or escalated on.\n *\n * The list is deliberately the union of the three sources of suppression a\n * mailing operation actually has \u2014 the contact's own instruction (unsubscribed,\n * spam complaint, legal request), the mail system's verdict (hard bounce), and a\n * human's or an import's judgement (manual block, imported do-not-contact list).\n *\n * Appending to this list is safe: SELECT option identity derives from the option\n * `value`, not from `position`. Editing or removing a `code` is not.\n */\nexport const SUPPRESSION_REASONS = [\n  {\n    code: 'UNSUBSCRIBED',\n    label: 'Unsubscribed',\n    hint: 'They used an unsubscribe link, replied STOP, or asked a rep to stop emailing them.',\n  },\n  {\n    code: 'HARD_BOUNCE',\n    label: 'Hard bounce',\n    hint: 'The mailbox does not exist. Sending again damages the sending domain.',\n  },\n  {\n    code: 'SPAM_COMPLAINT',\n    label: 'Spam complaint',\n    hint: 'They reported a message as spam. The most expensive signal on this list.',\n  },\n  {\n    code: 'MANUAL_BLOCK',\n    label: 'Manual block',\n    hint: 'A person decided not to contact this record. Say why in the note.',\n  },\n  {\n    code: 'LEGAL_REQUEST',\n    label: 'Legal or erasure request',\n    hint: 'A GDPR erasure or objection request, or anything counsel has told us to honour.',\n  },\n  {\n    code: 'IMPORTED_DNC',\n    label: 'Imported do-not-contact list',\n    hint: 'Came in on a suppression file \u2014 a previous CRM, a partner list, a TPS-style register.',\n  },\n] as const;\n\nexport type SuppressionReasonCode = (typeof SUPPRESSION_REASONS)[number]['code'];\n\nexport const SUPPRESSION_REASON_CODES: readonly SuppressionReasonCode[] =\n  SUPPRESSION_REASONS.map((reason) => reason.code);\n\nconst findSuppressionReason = (code: string) =>\n  SUPPRESSION_REASONS.find((reason) => reason.code === code) ?? null;\n\nexport const suppressionReasonLabel = (code: string | null): string => {\n  if (code === null || code.trim() === '') {\n    return 'no reason recorded';\n  }\n\n  return findSuppressionReason(code.trim().toUpperCase())?.label ?? code.trim();\n};\n\n/* -------------------------------------------------------------------------- */\n/* Why a suppression is being lifted                                           */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The closed list of *removal* reasons \u2014 a separate vocabulary on purpose.\n *\n * Removing a suppression re-enables contact with somebody who is on record\n * asking not to be contacted. There is no reason on the list above that is also\n * a good reason to undo it, so sharing one list would let a rep lift a spam\n * complaint by picking \"spam complaint\", which reads in the audit trail as\n * nonsense a year later.\n *\n * Every entry here is a claim that the *suppression itself* was wrong or has\n * been superseded. That is the only honest ground for removal.\n */\nexport const UNSUPPRESSION_REASONS = [\n  {\n    code: 'RECORDED_IN_ERROR',\n    label: 'The suppression was recorded in error',\n    hint: 'Nobody asked us to stop; the flag was set by mistake or by a bad import.',\n  },\n  {\n    code: 'CONSENT_RENEWED',\n    label: 'They have opted back in',\n    hint: 'They asked to start hearing from us again. Say where that is evidenced.',\n  },\n  {\n    code: 'WRONG_PERSON',\n    label: 'It was applied to the wrong record',\n    hint: 'A duplicate or a namesake was suppressed instead of the person who asked.',\n  },\n  {\n    code: 'BOUNCE_RESOLVED',\n    label: 'The bounce was a mail-server fault and is fixed',\n    hint: 'Only for hard bounces. Never for an unsubscribe or a complaint.',\n  },\n  {\n    code: 'TESTING',\n    label: 'Testing Greenlight',\n    hint: 'Keeps test removals out of the real compliance statistics.',\n  },\n] as const;\n\nexport type UnsuppressionReasonCode =\n  (typeof UNSUPPRESSION_REASONS)[number]['code'];\n\nexport const UNSUPPRESSION_REASON_CODES: readonly UnsuppressionReasonCode[] =\n  UNSUPPRESSION_REASONS.map((reason) => reason.code);\n\nconst findUnsuppressionReason = (code: string) =>\n  UNSUPPRESSION_REASONS.find((reason) => reason.code === code) ?? null;\n\n/* -------------------------------------------------------------------------- */\n/* Notes                                                                       */\n/* -------------------------------------------------------------------------- */\n\nexport const MAX_SUPPRESSION_NOTE_LENGTH = 500;\n\n/**\n * A removal note is **mandatory**, and a suppression note is not.\n *\n * This is the opposite of the release override's policy, and deliberately so.\n * The argument against mandatory free text is that a high-frequency action\n * collects the word \"ok\"; releasing a gated lead is a daily action and the\n * closed reason list carries the meaning. Lifting a do-not-contact entry is\n * rare, individually consequential, and the one thing a DPO will ask to see the\n * working for. Friction is the point.\n */\nexport const MIN_UNSUPPRESSION_NOTE_LENGTH = 10;\n\n/* -------------------------------------------------------------------------- */\n/* Requests                                                                    */\n/* -------------------------------------------------------------------------- */\n\n/** Mirrors `SUPPORTED_LEAD_OBJECTS` in `release-decision.ts`, and for the same reason. */\nexport const SUPPRESSION_SUPPORTED_LEAD_OBJECTS: readonly string[] = ['person'];\n\nconst UUID =\n  /^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;\n\nconst asString = (value: unknown): string | null =>\n  typeof value === 'string' ? value : null;\n\nexport interface SuppressRequest {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly reasonCode: SuppressionReasonCode;\n  /** Empty string when nothing was added. */\n  readonly note: string;\n}\n\nexport interface UnsuppressRequest {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly reasonCode: UnsuppressionReasonCode;\n  /** Never empty \u2014 see `MIN_UNSUPPRESSION_NOTE_LENGTH`. */\n  readonly note: string;\n  /** The reviewer ticked \"I understand this re-enables contact\". */\n  readonly acknowledged: true;\n}\n\nexport type ParseResult<T> =\n  | { readonly ok: true; readonly request: T }\n  | { readonly ok: false; readonly message: string };\n\ninterface CommonFields {\n  readonly leadObjectNameSingular: string;\n  readonly recordId: string;\n  readonly note: string;\n}\n\nconst parseCommon = (body: unknown): ParseResult<CommonFields> => {\n  if (typeof body !== 'object' || body === null || Array.isArray(body)) {\n    return { ok: false, message: 'Request body must be an object.' };\n  }\n\n  const raw = body as Record<string, unknown>;\n  const recordId = asString(raw['recordId'])?.trim() ?? '';\n\n  if (!UUID.test(recordId)) {\n    return { ok: false, message: 'This request needs a valid recordId.' };\n  }\n\n  const leadObjectNameSingular =\n    asString(raw['leadObjectNameSingular'])?.trim() || 'person';\n\n  if (!SUPPRESSION_SUPPORTED_LEAD_OBJECTS.includes(leadObjectNameSingular)) {\n    return {\n      ok: false,\n      message: `Greenlight v0.1 keeps its block list on ${SUPPRESSION_SUPPORTED_LEAD_OBJECTS.join(\n        ', ',\n      )}, not ${leadObjectNameSingular}.`,\n    };\n  }\n\n  const note = (asString(raw['note']) ?? '')\n    .trim()\n    .slice(0, MAX_SUPPRESSION_NOTE_LENGTH);\n\n  return { ok: true, request: { leadObjectNameSingular, recordId, note } };\n};\n\nexport const parseSuppressRequest = (\n  body: unknown,\n): ParseResult<SuppressRequest> => {\n  const common = parseCommon(body);\n\n  if (!common.ok) {\n    return common;\n  }\n\n  const raw = body as Record<string, unknown>;\n  const reason = findSuppressionReason(\n    asString(raw['reasonCode'])?.trim().toUpperCase() ?? '',\n  );\n\n  if (reason === null) {\n    return {\n      ok: false,\n      message:\n        'Choose why this person must not be contacted. A block list with no recorded reasons cannot be audited, cleaned up, or defended.',\n    };\n  }\n\n  return {\n    ok: true,\n    request: { ...common.request, reasonCode: reason.code },\n  };\n};\n\nexport const parseUnsuppressRequest = (\n  body: unknown,\n): ParseResult<UnsuppressRequest> => {\n  const common = parseCommon(body);\n\n  if (!common.ok) {\n    return common;\n  }\n\n  const raw = body as Record<string, unknown>;\n  const reason = findUnsuppressionReason(\n    asString(raw['reasonCode'])?.trim().toUpperCase() ?? '',\n  );\n\n  if (reason === null) {\n    return {\n      ok: false,\n      message:\n        'Choose why this suppression should be lifted. Every reason on the list is a claim that the suppression itself was wrong or has been superseded \u2014 if none of them is true, do not lift it.',\n    };\n  }\n\n  if (common.request.note.length < MIN_UNSUPPRESSION_NOTE_LENGTH) {\n    return {\n      ok: false,\n      message: `Write down what happened, in at least ${MIN_UNSUPPRESSION_NOTE_LENGTH} characters. Removing someone from the block list re-enables contact with a person who asked us to stop, and the note is the only place the evidence for that lives.`,\n    };\n  }\n\n  if (raw['acknowledged'] !== true) {\n    return {\n      ok: false,\n      message:\n        'Confirm that you understand this re-enables contact with this person.',\n    };\n  }\n\n  return {\n    ok: true,\n    request: {\n      ...common.request,\n      reasonCode: reason.code,\n      acknowledged: true,\n    },\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Current state                                                               */\n/* -------------------------------------------------------------------------- */\n\nexport interface CurrentSuppressionState {\n  readonly recordId: string;\n  /** Denormalised into the audit row so the trail survives the record. */\n  readonly displayName: string;\n  readonly suppressed: boolean;\n  /** Raw `greenlightSuppressionReason`. Null when nothing is recorded. */\n  readonly reasonCode: string | null;\n  /** Raw `greenlightSuppressedAt` as stored. Null when nothing is recorded. */\n  readonly suppressedAt: string | null;\n  readonly note: string;\n  /** Raw `greenlightDecision`, for the audit row's decision column. */\n  readonly decision: string | null;\n  readonly score: number | null;\n  /**\n   * Raw `greenlightTrace`, read only for the audit row's band column \u2014 see\n   * `auditBandValue` in `release-decision.ts`. Optional because nothing in this\n   * module's decision logic reads it: a suppression is decided from the flag and\n   * the reason, never from a score, and a caller that cannot supply a trace must\n   * still be able to suppress somebody.\n   */\n  readonly trace?: unknown;\n}\n\n/**\n * Is this record on the block list *as far as Greenlight's own fields go*?\n *\n * A recorded reason with the flag cleared counts as suppressed, and that is not\n * a bug. Half-clearing \u2014 untick the box, leave `SPAM_COMPLAINT` sitting in the\n * reason column \u2014 is the realistic hand-edit, and reading it as \"not suppressed\"\n * would silently re-enable outreach to somebody whose record still states, in\n * writing, why we stopped. The compliance rule takes the same view; see\n * `src/scoring/rules/compliance-opt-out.rule.ts`.\n */\nexport const isSuppressedState = (state: {\n  readonly suppressed: boolean;\n  readonly reasonCode: string | null;\n}): boolean =>\n  state.suppressed || (state.reasonCode ?? '').trim().length > 0;\n\n/* -------------------------------------------------------------------------- */\n/* Audit vocabulary                                                            */\n/* -------------------------------------------------------------------------- */\n\n/** New `GreenlightAuditLog.eventType` options \u2014 see `src/objects/greenlight-audit-log.ts`. */\nexport const AUDIT_EVENT_SUPPRESSED = 'SUPPRESSED';\nexport const AUDIT_EVENT_UNSUPPRESSED = 'UNSUPPRESSED';\n\nexport type SuppressionAuditEventType =\n  | typeof AUDIT_EVENT_SUPPRESSED\n  | typeof AUDIT_EVENT_UNSUPPRESSED;\n\n/** The audit-trail rendering of a reason: machine code first, prose after. */\nexport const formatSuppressionReason = (\n  reasonCode: string,\n  note: string,\n): string => {\n  const label =\n    findSuppressionReason(reasonCode)?.label ??\n    findUnsuppressionReason(reasonCode)?.label ??\n    null;\n  const rendered = label === null ? reasonCode : `${reasonCode} \u00B7 ${label}`;\n\n  return note === '' ? rendered : `${rendered} \u2014 ${note}`;\n};\n\n/** One-line summary used as the audit row's record label. */\nexport const buildSuppressionAuditSummary = (\n  eventType: SuppressionAuditEventType,\n  displayName: string,\n  reasonCode: string,\n): string => {\n  const name = displayName.trim() === '' ? 'Unnamed lead' : displayName.trim();\n\n  return `${eventType} \u00B7 ${name} \u00B7 ${reasonCode}`;\n};\n\n/* -------------------------------------------------------------------------- */\n/* The decisions                                                               */\n/* -------------------------------------------------------------------------- */\n\nexport type SuppressOutcome =\n  /** Newly added to the block list. */\n  | 'suppressed'\n  /** Already on the list under the same reason. Nothing written, nothing logged. */\n  | 'already_suppressed'\n  /** Already on the list under a different reason; the reason was amended. */\n  | 'reason_amended';\n\nexport type UnsuppressOutcome =\n  /** Removed from the block list. */\n  | 'unsuppressed'\n  /** Was not on the list. Nothing written, nothing logged. */\n  | 'not_suppressed';\n\nexport interface SuppressionWrite {\n  readonly [field: string]: string | boolean | null;\n}\n\nexport interface SuppressionDecision<TOutcome extends string> {\n  readonly outcome: TOutcome;\n  /** Shown to the reviewer. Written for a salesperson, not a developer. */\n  readonly message: string;\n  /** The Person patch to apply, or null when nothing changes. */\n  readonly write: SuppressionWrite | null;\n  readonly shouldWriteAuditRow: boolean;\n  readonly auditEventType: SuppressionAuditEventType | null;\n  /** Rendered reason for the audit row. Empty when no row is written. */\n  readonly auditReason: string;\n}\n\nexport interface DecideSuppressInput {\n  readonly request: SuppressRequest;\n  readonly lead: CurrentSuppressionState;\n  /** The clock, passed in \u2014 this module never reads it. */\n  readonly now: Date;\n}\n\nexport interface DecideUnsuppressInput {\n  readonly request: UnsuppressRequest;\n  readonly lead: CurrentSuppressionState;\n  readonly now: Date;\n}\n\n/**\n * Decide what adding to the block list should do. Never throws.\n *\n * Three cases, and the amendment case is the interesting one. A record already\n * suppressed as `MANUAL_BLOCK` that turns out to be a `LEGAL_REQUEST` must be\n * correctable *without* passing through an unsuppressed state \u2014 a remove-then-add\n * would re-enable contact for as long as it took somebody to do the second half,\n * and would put a spurious `UNSUPPRESSED` row in the compliance trail.\n *\n * `greenlightSuppressedAt` is **not** rewritten on an amendment. That column\n * answers \"since when has this person been off-limits\", and the answer does not\n * change because we relabelled why.\n */\nexport const decideSuppress = (\n  input: DecideSuppressInput,\n): SuppressionDecision<SuppressOutcome> => {\n  const { request, lead, now } = input;\n  const currentReason = (lead.reasonCode ?? '').trim().toUpperCase();\n  const alreadyOnList = isSuppressedState(lead);\n\n  if (alreadyOnList && currentReason === request.reasonCode) {\n    return {\n      outcome: 'already_suppressed',\n      message: `${\n        lead.displayName.trim() === '' ? 'This lead' : lead.displayName.trim()\n      } is already on the Greenlight block list for the same reason. Nothing changed, and no second audit entry was written.`,\n      write: null,\n      shouldWriteAuditRow: false,\n      auditEventType: null,\n      auditReason: '',\n    };\n  }\n\n  if (alreadyOnList) {\n    return {\n      outcome: 'reason_amended',\n      message: `Already blocked \u2014 the recorded reason has been changed from ${suppressionReasonLabel(\n        currentReason === '' ? null : currentReason,\n      )} to ${suppressionReasonLabel(\n        request.reasonCode,\n      )}. The original block date is unchanged and the amendment is on record.`,\n      write: {\n        [SUPPRESSION_FIELD_SUPPRESSED]: true,\n        [SUPPRESSION_FIELD_REASON]: request.reasonCode,\n        [SUPPRESSION_FIELD_NOTE]: request.note,\n      },\n      shouldWriteAuditRow: true,\n      auditEventType: AUDIT_EVENT_SUPPRESSED,\n      auditReason: `AMENDED from ${\n        currentReason === '' ? 'no recorded reason' : currentReason\n      } \u2014 ${formatSuppressionReason(request.reasonCode, request.note)}`,\n    };\n  }\n\n  return {\n    outcome: 'suppressed',\n    message:\n      'Added to the Greenlight block list. This person will not be contacted, the lead has been re-scored, and the block is on record.',\n    write: {\n      [SUPPRESSION_FIELD_SUPPRESSED]: true,\n      [SUPPRESSION_FIELD_REASON]: request.reasonCode,\n      [SUPPRESSION_FIELD_SUPPRESSED_AT]: now.toISOString(),\n      [SUPPRESSION_FIELD_NOTE]: request.note,\n    },\n    shouldWriteAuditRow: true,\n    auditEventType: AUDIT_EVENT_SUPPRESSED,\n    auditReason: formatSuppressionReason(request.reasonCode, request.note),\n  };\n};\n\n/**\n * Decide what removing from the block list should do. Never throws.\n *\n * Every field is cleared, not just the flag. Leaving the reason behind would\n * leave the record asserting \"spam complaint\" while claiming to be contactable,\n * and the compliance rule (correctly) reads a lingering reason as still\n * suppressed \u2014 so a partial clear would look like it worked and quietly do\n * nothing.\n *\n * The audit row records the reason the person was suppressed *under*, not just\n * the reason given for lifting it. \"Which legal-request suppressions has this\n * workspace lifted, and who lifted them\" is the question this trail exists to\n * answer, and it is unanswerable from the removal reason alone.\n */\nexport const decideUnsuppress = (\n  input: DecideUnsuppressInput,\n): SuppressionDecision<UnsuppressOutcome> => {\n  const { request, lead } = input;\n\n  if (!isSuppressedState(lead)) {\n    return {\n      outcome: 'not_suppressed',\n      message:\n        'This person is not on the Greenlight block list, so there was nothing to remove. No change made, and no audit entry written.',\n      write: null,\n      shouldWriteAuditRow: false,\n      auditEventType: null,\n      auditReason: '',\n    };\n  }\n\n  const originalReason =\n    (lead.reasonCode ?? '').trim() === ''\n      ? 'no recorded reason'\n      : (lead.reasonCode ?? '').trim().toUpperCase();\n\n  return {\n    outcome: 'unsuppressed',\n    message:\n      'Removed from the Greenlight block list. Contact is re-enabled, the lead has been re-scored, and your reason is on record and cannot be edited afterwards.',\n    write: {\n      [SUPPRESSION_FIELD_SUPPRESSED]: false,\n      [SUPPRESSION_FIELD_REASON]: null,\n      [SUPPRESSION_FIELD_SUPPRESSED_AT]: null,\n      [SUPPRESSION_FIELD_NOTE]: '',\n    },\n    shouldWriteAuditRow: true,\n    auditEventType: AUDIT_EVENT_UNSUPPRESSED,\n    auditReason: `LIFTED a ${originalReason} suppression recorded ${\n      lead.suppressedAt ?? 'at an unrecorded time'\n    } \u2014 ${formatSuppressionReason(request.reasonCode, request.note)}`,\n  };\n};\n", "/**\n * The adapter between the `GreenlightConfig` CRM record and the scoring engine.\n *\n * These are two different shapes on purpose and the gap has to live somewhere:\n *\n *   GreenlightConfig  is designed for a human with a record page. Bands are three\n *                     separate NUMBER fields because a typo inside a JSON blob\n *                     would silently gate a whole workspace; enable/severity and\n *                     weight are separate RAW_JSON maps because they are two\n *                     different decisions an admin makes at different times.\n *\n *   ResolvedScoringConfig  is designed for the engine. Bands are one sorted\n *                     array; every rule carries enabled + severity + weight\n *                     together.\n *\n * This file is the only place that knows both. Everything here is a pure\n * function of its input \u2014 no API client, no clock \u2014 so the whole\n * seed / read / merge story is unit-testable without a Twenty instance.\n */\n\nimport { buildDefaultConfig, DEFAULT_FIELD_MAPPING } from 'src/scoring';\nimport type { ResolvedScoringConfig } from 'src/scoring';\n\nimport { isPlainRecord } from 'src/logic-functions/greenlight-api';\n\n/**\n * The `GreenlightConfig.leadObjectNameSingular` SELECT value for Person.\n *\n * Duplicated from `src/objects/greenlight-config.ts` rather than imported: that\n * module pulls in `twenty-sdk/define`, and a logic-function bundle has no\n * business carrying the whole manifest-authoring toolkit. The value is a SELECT\n * option and is as permanent as the field identifier itself.\n */\nexport const DEFAULT_LEAD_OBJECT_SELECT_VALUE = 'PERSON';\n\n/** Lowercase API name matching the SELECT value above, for the audit trail. */\nexport const LEAD_OBJECT_SELECT_TO_NAME_SINGULAR: Readonly<\n  Record<string, string>\n> = {\n  PERSON: 'person',\n  COMPANY: 'company',\n  OPPORTUNITY: 'opportunity',\n};\n\n/** Every field this app reads from or writes to the config record. */\nexport const GREENLIGHT_CONFIG_FIELD_NAMES = [\n  'id',\n  'createdAt',\n  'name',\n  'isGateEnabled',\n  'icpIndustries',\n  'icpRegions',\n  'icpSizeBands',\n  'ruleSettings',\n  'scoreWeights',\n  'bandExcellentThreshold',\n  'bandGoodThreshold',\n  'bandFairThreshold',\n  'gateThreshold',\n  'defaultShelfLifeDays',\n  'fieldShelfLives',\n  'leadObjectNameSingular',\n  'decisionMakerFieldName',\n  'decisionMakerMatchValues',\n  'readyForOutreachFieldName',\n  'readyForOutreachValue',\n  'optOutFieldNames',\n] as const;\n\n/** GraphQL selection set for the fields above. */\nexport const greenlightConfigSelection = (): Record<string, boolean> =>\n  Object.fromEntries(GREENLIGHT_CONFIG_FIELD_NAMES.map((name) => [name, true]));\n\nexport type GreenlightConfigSeed = Record<string, unknown>;\n\nconst bandMinScore = (\n  config: ResolvedScoringConfig,\n  bandId: string,\n): number | undefined =>\n  config.bands.find((band) => band.id === bandId)?.minScore;\n\n/**\n * The record the post-install hook writes on a fresh install.\n *\n * Every value is set **explicitly** rather than left to the field manifest's\n * `defaultValue`, for three reasons:\n *\n *  1. The manifest defaults and the engine defaults disagree. The field\n *     manifests carry bands 80/60/40 and gate 40; `buildDefaultConfig()` \u2014 the\n *     thing that actually scores leads \u2014 carries 85/70/50 and gate 50. Whichever\n *     is \"right\", they must not differ, and the engine is the one that decides\n *     outcomes, so the engine wins. Leaving the record blank would ship a\n *     workspace whose visible configuration lies about its own behaviour.\n *     `decisionMakerMatchValues` has the same problem: 12 titles in the manifest,\n *     25 in the engine.\n *  2. `ruleSettings` and `scoreWeights` cannot come from a manifest default at\n *     all \u2014 they are keyed by the rule catalogue, which the engine owns and which\n *     grows every release.\n *  3. A `defaultValue` only applies at column creation. It is not a value a\n *     later read can distinguish from \"the admin set it to that\", so relying on\n *     it would make the upgrade-merge below unable to tell missing from chosen.\n *\n * The rule of thumb: if the engine has an opinion, seed it explicitly; the field\n * manifest `defaultValue` is then only a safety net for records created by hand.\n */\nexport const buildGreenlightConfigSeed = (): GreenlightConfigSeed => {\n  const defaults = buildDefaultConfig();\n\n  const ruleSettings: Record<string, { enabled: boolean; severity: string }> =\n    {};\n  const scoreWeights: Record<string, number> = {};\n\n  for (const [ruleId, setting] of Object.entries(defaults.rules)) {\n    ruleSettings[ruleId] = {\n      enabled: setting.enabled,\n      severity: setting.severity,\n    };\n    scoreWeights[ruleId] = setting.weight;\n  }\n\n  return {\n    name: 'Default',\n    isGateEnabled: true,\n\n    icpIndustries: [...defaults.icp.industries],\n    icpRegions: [...defaults.icp.regions],\n    icpSizeBands: { bands: [...defaults.icp.sizeBands] },\n\n    ruleSettings,\n    scoreWeights,\n\n    bandExcellentThreshold: bandMinScore(defaults, 'excellent') ?? 85,\n    bandGoodThreshold: bandMinScore(defaults, 'good') ?? 70,\n    bandFairThreshold: bandMinScore(defaults, 'fair') ?? 50,\n    gateThreshold: defaults.gateThreshold,\n\n    defaultShelfLifeDays: defaults.defaultShelfLifeDays,\n    fieldShelfLives: { ...defaults.fieldShelfLifeDays },\n\n    leadObjectNameSingular: DEFAULT_LEAD_OBJECT_SELECT_VALUE,\n    decisionMakerFieldName: 'jobTitle',\n    decisionMakerMatchValues: [...defaults.decisionMakerTitles],\n\n    // Stock Twenty's Person has no stage field, so there is nothing honest to\n    // point these at. Blank means \"the release action only clears the gate\".\n    readyForOutreachFieldName: null,\n    readyForOutreachValue: null,\n\n    // Empty, not absent: the engine's default field mapping already probes\n    // `optedOut` / `doNotContact` / `emailOptOut` / `unsubscribed`. This list is\n    // for *extra* workspace-specific opt-out fields.\n    optOutFieldNames: [],\n  };\n};\n\n/* -------------------------------------------------------------------------- */\n/* Upgrade merge                                                               */\n/* -------------------------------------------------------------------------- */\n\nconst isMissing = (value: unknown): boolean =>\n  value === undefined || value === null;\n\n/**\n * Whether writing `seedValue` over a missing field would actually change\n * anything once Twenty has stored it.\n *\n * Found by running a real `app:install` upgrade rather than by a unit test, and\n * unit tests structurally cannot see it: **Twenty persists an empty `RAW_JSON`\n * as `null`.** So `fieldShelfLives`, seeded `{}`, reads back as `null`,\n * `isMissing` says missing, the patch writes `{}` again, and it reads back\n * `null` again \u2014 forever. Every single upgrade patched exactly one key and filed\n * an audit row claiming a merge that had not happened, which quietly makes the\n * upgrade trail untrustworthy for the merges that are real.\n *\n * A patch that cannot converge is not a merge, it is a loop with an audit trail.\n * An empty seed value written over a missing field is a no-op by definition, so\n * it is skipped and the key is left to the field manifest's own default.\n */\nconst isNoOpSeed = (value: unknown): boolean => {\n  if (Array.isArray(value)) {\n    return value.length === 0;\n  }\n\n  if (isPlainRecord(value)) {\n    return Object.keys(value).length === 0;\n  }\n\n  return false;\n};\n\n/**\n * The patch an upgrade should apply to an existing config record.\n *\n * \"Missing\" means `null` or `undefined` only. An empty array, an empty object\n * and a zero are all *choices* a workspace made \u2014 a permissive ICP is the whole\n * point of the shipped default \u2014 and resetting them to seed values would be the\n * exact behaviour ARCHITECTURE.md's upgrade section forbids (\"config merge, not\n * replace\").\n *\n * The interesting case is `ruleSettings` / `scoreWeights`: a release that adds a\n * rule must make that rule appear in the workspace's config at its shipped\n * default, without disturbing a single existing entry. Both maps are therefore\n * merged key-by-key rather than compared wholesale.\n *\n * Returns an empty object when there is nothing to do, so the caller can skip\n * the mutation entirely \u2014 which is what makes re-running the hook a no-op.\n */\nexport const buildConfigUpgradePatch = (\n  existing: unknown,\n  seed: GreenlightConfigSeed = buildGreenlightConfigSeed(),\n): Record<string, unknown> => {\n  const record = isPlainRecord(existing) ? existing : {};\n  const patch: Record<string, unknown> = {};\n\n  for (const [key, seedValue] of Object.entries(seed)) {\n    // `null` is the intended seeded value for these two, so a null on the\n    // record is indistinguishable from the seed and must never be \"repaired\".\n    if (seedValue === null) {\n      continue;\n    }\n\n    if (key === 'ruleSettings' || key === 'scoreWeights') {\n      continue;\n    }\n\n    if (isMissing(record[key]) && !isNoOpSeed(seedValue)) {\n      patch[key] = seedValue;\n    }\n  }\n\n  const ruleSettingsPatch = mergeKeyedMap(\n    record['ruleSettings'],\n    seed['ruleSettings'],\n  );\n\n  if (ruleSettingsPatch !== null) {\n    patch['ruleSettings'] = ruleSettingsPatch;\n  }\n\n  const scoreWeightsPatch = mergeKeyedMap(\n    record['scoreWeights'],\n    seed['scoreWeights'],\n  );\n\n  if (scoreWeightsPatch !== null) {\n    patch['scoreWeights'] = scoreWeightsPatch;\n  }\n\n  return patch;\n};\n\n/**\n * Merge shipped keys into a stored map without overwriting anything present.\n * Returns `null` when the stored map already covers every shipped key \u2014 the\n * signal that no write is needed.\n */\nconst mergeKeyedMap = (\n  stored: unknown,\n  shipped: unknown,\n): Record<string, unknown> | null => {\n  if (!isPlainRecord(shipped)) {\n    return null;\n  }\n\n  if (!isPlainRecord(stored)) {\n    // Absent or unreadable: replacing it with the shipped map loses nothing,\n    // because there was nothing legible there to lose.\n    return { ...shipped };\n  }\n\n  const merged: Record<string, unknown> = { ...stored };\n  let added = false;\n\n  for (const [key, value] of Object.entries(shipped)) {\n    if (isMissing(merged[key])) {\n      merged[key] = value;\n      added = true;\n    }\n  }\n\n  return added ? merged : null;\n};\n\n/* -------------------------------------------------------------------------- */\n/* Record -> engine config                                                     */\n/* -------------------------------------------------------------------------- */\n\nconst asFiniteNumber = (value: unknown): number | undefined =>\n  typeof value === 'number' && Number.isFinite(value) ? value : undefined;\n\nconst asStringList = (value: unknown): string[] | undefined => {\n  if (!Array.isArray(value)) {\n    return undefined;\n  }\n\n  const list = value\n    .filter((entry): entry is string => typeof entry === 'string')\n    .map((entry) => entry.trim())\n    .filter((entry) => entry.length > 0);\n\n  return list;\n};\n\n/** `icpSizeBands` ships as `{ bands: [...] }`; tolerate a bare array too. */\nconst readSizeBands = (value: unknown): unknown => {\n  if (Array.isArray(value)) {\n    return value;\n  }\n\n  if (isPlainRecord(value) && Array.isArray(value['bands'])) {\n    return value['bands'];\n  }\n\n  return undefined;\n};\n\n/**\n * Recombine `ruleSettings` (enable + severity) and `scoreWeights` (weight) into\n * the single per-rule shape the engine reads.\n *\n * `isEnabled` is accepted as an alias for `enabled` because the field's own\n * description in `src/objects/greenlight-config.ts` documents that spelling.\n * The engine reads `enabled`; rather than let a hand-edited record silently do\n * nothing, both are honoured here. (The field description is stale \u2014 see the\n * report accompanying this change.)\n */\nconst readRules = (\n  ruleSettings: unknown,\n  scoreWeights: unknown,\n): Record<string, unknown> | undefined => {\n  const settings = isPlainRecord(ruleSettings) ? ruleSettings : undefined;\n  const weights = isPlainRecord(scoreWeights) ? scoreWeights : undefined;\n\n  if (settings === undefined && weights === undefined) {\n    return undefined;\n  }\n\n  const ruleIds = new Set<string>([\n    ...Object.keys(settings ?? {}),\n    ...Object.keys(weights ?? {}),\n  ]);\n\n  const rules: Record<string, unknown> = {};\n\n  for (const ruleId of ruleIds) {\n    const setting = settings?.[ruleId];\n    const merged: Record<string, unknown> = isPlainRecord(setting)\n      ? { ...setting }\n      : {};\n\n    if (merged['enabled'] === undefined && merged['isEnabled'] !== undefined) {\n      merged['enabled'] = merged['isEnabled'];\n    }\n\n    const weight = asFiniteNumber(weights?.[ruleId]);\n\n    if (weight !== undefined) {\n      merged['weight'] = weight;\n    }\n\n    rules[ruleId] = merged;\n  }\n\n  return rules;\n};\n\n/**\n * Rebuild the engine's band array from the three threshold fields.\n *\n * Returns `undefined` when no threshold is usable, which makes `resolveConfig`\n * fall back to the shipped bands without logging a degradation \u2014 the right\n * outcome, because \"the admin never touched this\" is not a fault.\n */\nconst readBands = (record: Record<string, unknown>): unknown => {\n  const excellent = asFiniteNumber(record['bandExcellentThreshold']);\n  const good = asFiniteNumber(record['bandGoodThreshold']);\n  const fair = asFiniteNumber(record['bandFairThreshold']);\n\n  if (excellent === undefined && good === undefined && fair === undefined) {\n    return undefined;\n  }\n\n  const bands: { id: string; label: string; minScore: number }[] = [];\n\n  if (excellent !== undefined) {\n    bands.push({ id: 'excellent', label: 'Excellent', minScore: excellent });\n  }\n\n  if (good !== undefined) {\n    bands.push({ id: 'good', label: 'Good', minScore: good });\n  }\n\n  if (fair !== undefined) {\n    bands.push({ id: 'fair', label: 'Fair', minScore: fair });\n  }\n\n  // Poor is the floor and has no threshold field: it is whatever is left.\n  bands.push({ id: 'poor', label: 'Poor', minScore: 0 });\n\n  return bands;\n};\n\n/**\n * The Layer 3 field mapping, expressed as *additional* candidate paths in front\n * of the engine's defaults rather than as a replacement.\n *\n * Prepending matters: a workspace that points `decisionMakerFieldName` at a\n * custom field still wants `jobTitle` probed as a fallback for the Person\n * records where the custom field is blank. De-duplicated so that pointing the\n * setting at the default field name produces the default list unchanged rather\n * than a list that probes the same path twice.\n */\nconst prepend = (\n  extra: readonly string[],\n  defaults: readonly string[],\n): string[] => [...new Set([...extra, ...defaults])];\n\nconst readFieldMapping = (\n  record: Record<string, unknown>,\n): Record<string, string[]> | undefined => {\n  const mapping: Record<string, string[]> = {};\n\n  const decisionMakerField = record['decisionMakerFieldName'];\n\n  if (typeof decisionMakerField === 'string' && decisionMakerField.trim()) {\n    // Read the shipped candidates rather than repeating them. They were\n    // duplicated here, and the two copies drifted the moment `position` was\n    // removed from the engine's list for reading Twenty's row-ordering number\n    // as a job title \u2014 this copy would have quietly kept the bug alive for any\n    // workspace that had configured a decision-maker field.\n    mapping['jobTitle'] = prepend(\n      [decisionMakerField.trim()],\n      DEFAULT_FIELD_MAPPING.jobTitle,\n    );\n  }\n\n  const optOutFields = asStringList(record['optOutFieldNames']);\n\n  if (optOutFields !== undefined && optOutFields.length > 0) {\n    mapping['optedOut'] = prepend(optOutFields, [\n      'optedOut',\n      'doNotContact',\n      'emailOptOut',\n      'unsubscribed',\n    ]);\n  }\n\n  return Object.keys(mapping).length > 0 ? mapping : undefined;\n};\n\n/**\n * Turn a `GreenlightConfig` record into the raw config `scoreLead` accepts.\n *\n * Deliberately lenient: anything unreadable is left out of the returned object\n * so `resolveConfig` supplies its own default. This function never throws and\n * never validates \u2014 validation is the engine's job and it already reports what\n * it had to repair.\n */\nexport const toScoringConfigInput = (record: unknown): unknown => {\n  if (!isPlainRecord(record)) {\n    return undefined;\n  }\n\n  const industries = asStringList(record['icpIndustries']);\n  const regions = asStringList(record['icpRegions']);\n  const sizeBands = readSizeBands(record['icpSizeBands']);\n\n  const icp =\n    industries !== undefined || regions !== undefined || sizeBands !== undefined\n      ? {\n          industries: industries ?? [],\n          regions: regions ?? [],\n          sizeBands: sizeBands ?? [],\n        }\n      : undefined;\n\n  const decisionMakerTitles = asStringList(record['decisionMakerMatchValues']);\n\n  return {\n    icp,\n    rules: readRules(record['ruleSettings'], record['scoreWeights']),\n    bands: readBands(record),\n    gateThreshold: asFiniteNumber(record['gateThreshold']),\n    defaultShelfLifeDays: asFiniteNumber(record['defaultShelfLifeDays']),\n    fieldShelfLifeDays: isPlainRecord(record['fieldShelfLives'])\n      ? record['fieldShelfLives']\n      : undefined,\n    // Empty means \"the admin cleared the list\", which disables the\n    // decision-maker rule on purpose. Only an unreadable value falls back.\n    decisionMakerTitles,\n    fieldMapping: readFieldMapping(record),\n  };\n};\n\n/** Is the gate switched on? Absent or unreadable reads as on. */\nexport const isGateEnabled = (record: unknown): boolean =>\n  !(isPlainRecord(record) && record['isGateEnabled'] === false);\n\n/** Which object the workspace calls the lead, as a lowercase API name. */\nexport const readLeadObjectNameSingular = (record: unknown): string => {\n  const raw = isPlainRecord(record) ? record['leadObjectNameSingular'] : null;\n\n  if (typeof raw !== 'string' || raw.trim().length === 0) {\n    return LEAD_OBJECT_SELECT_TO_NAME_SINGULAR[\n      DEFAULT_LEAD_OBJECT_SELECT_VALUE\n    ] as string;\n  }\n\n  const normalised = raw.trim().toUpperCase();\n\n  return LEAD_OBJECT_SELECT_TO_NAME_SINGULAR[normalised] ?? raw.trim();\n};\n", "/**\n * The Person scoring run \u2014 everything the two database-event registrations share.\n *\n * Kept out of the `define*` files so it can be exercised against a fake API\n * client. The only impure things it touches are the client it is handed and the\n * `now` it is passed; there is no `new Date()` and no `new CoreApiClient()`\n * anywhere below.\n *\n * ## Not retriggering ourselves\n *\n * Writing `greenlightScore` back to a Person emits `person.updated`, which is\n * the event that made us score in the first place. Three independent guards stop\n * that becoming a loop, in order of how much they can be trusted:\n *\n *  1. **The trigger allow-list** (`SCORING_TRIGGER_PERSON_FIELDS`, declared in\n *     `score-person-updated.logic-function.ts`). Twenty only dispatches an update\n *     event to a function whose `databaseEventTriggerSettings.updatedFields`\n *     names a field that actually changed. None of Greenlight's three fields is\n *     on that list, so the platform never delivers our own write back to us.\n *     This guard runs outside our process and is the one doing the real work.\n *\n *  2. **The authored-write check** (`isGreenlightAuthoredWrite`). If an event\n *     arrives anyway \u2014 a bulk edit that touched a scoring field *and* a\n *     Greenlight field, a future SDK that treats `updatedFields` as advisory \u2014\n *     and every field it reports is one we own, the run exits before any read or\n *     write. Cheap, and it does not depend on the platform honouring anything.\n *\n *  3. **The outcome fingerprint** (`fingerprintOutcome`). Even if both guards\n *     above were bypassed, the second pass over an unchanged lead produces an\n *     identical fingerprint to the one already stored on the record, so nothing\n *     is written and the chain terminates after exactly one extra iteration.\n *     This is also what makes a retried event idempotent: no second audit row,\n *     no second write.\n *\n * The allow-list in guard 1 does carry three Greenlight-named fields \u2014\n * `greenlightSuppressed`, `greenlightSuppressionReason` and\n * `greenlightEnrichment`. All three are safe for the same structural reason:\n * this run never writes any of them, so its own write-back still wakes nothing.\n * Both exceptions, and the bounded enrichment cycle the third one does close,\n * are argued in full on `SCORING_TRIGGER_PERSON_FIELDS` below.\n *\n * Guard 3 fingerprints the *outcome*, not the inputs, on purpose. The engine's\n * default field mapping reads `lastVerifiedAt` from `updatedAt`, which changes\n * on every write \u2014 an input hash would therefore differ on every pass and could\n * never terminate. The outcome is stable by construction.\n *\n * ## Not undoing a human override\n *\n * The guards above stop *our own* write from re-scoring a lead. They do nothing\n * about the other half of the contract with `release-lead.logic-function.ts`: a\n * rep releases a gated lead, then edits `jobTitle` seconds later, which is a\n * legitimate re-score that would re-gate the lead the human just released.\n *\n * The release writes a marker to app key-value storage. This run reads it before\n * writing a holding decision and pins the decision to `PASS` when one is present\n * \u2014 the score and the whole trace still update, only the decision is pinned. See\n * `pinReleasedDecision` for the exceptions and the failure directions.\n */\n\nimport {\n  SCORING_ENGINE_VERSION,\n  scoreLead,\n  toLeadRecord,\n  type GateDecision,\n  type ScoringResult,\n} from 'src/scoring';\n\nimport {\n  NO_SEAL,\n  resolveCalibration,\n  sealedCalibrationBody,\n  toScoringBaseline,\n  type CalibrationReaderPort,\n  type CalibrationSealPort,\n} from 'src/calibration';\nimport {\n  releaseMarkerKey,\n  type ReleaseMarker,\n} from 'src/gate/release-decision';\nimport { SUPPRESSION_SCORING_INPUT_FIELDS } from 'src/gate/suppression-decision';\nimport {\n  describeError,\n  isPlainRecord,\n  logGreenlight,\n  oldestByCreatedAt,\n  readConnectionNodes,\n  type GreenlightApiClient,\n} from 'src/logic-functions/greenlight-api';\nimport {\n  greenlightConfigSelection,\n  isGateEnabled,\n  readLeadObjectNameSingular,\n  toScoringConfigInput,\n} from 'src/logic-functions/greenlight-config-record';\n\n/* -------------------------------------------------------------------------- */\n/* Field vocabulary                                                            */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The Person fields **this run writes**. Nothing here may ever appear in a\n * `databaseEventTriggerSettings.updatedFields` list \u2014 see guard 1 above.\n *\n * \"Managed\" means written by the scoring run, not merely shipped by Greenlight.\n * The distinction started mattering when the app grew fields it *owns* but never\n * writes: the four `greenlightSuppress*` columns are Greenlight's own schema and\n * are human-maintained input, so two of them are on the trigger list below and\n * none of them belongs here. Adding one of them to this list would make guard 2\n * swallow the very event the feature depends on.\n */\nexport const GREENLIGHT_MANAGED_PERSON_FIELDS: readonly string[] = [\n  'greenlightScore',\n  'greenlightDecision',\n  'greenlightTrace',\n];\n\n/**\n * Fields whose change can move the score, i.e. the ones worth re-scoring for.\n *\n * `updatedAt` is deliberately absent even though the freshness rule reads it:\n * it changes on *every* write, including ours, which would defeat guard 1\n * entirely. Freshness is re-evaluated whenever anything else changes, and a lead\n * that goes stale without being touched is a reporting problem, not an event.\n *\n * `company` and `companyId` are both listed because Twenty reports a relation\n * change under the foreign-key name in some versions and the relation name in\n * others; a name that never fires costs nothing.\n *\n * ## The suppression exception\n *\n * `SUPPRESSION_SCORING_INPUT_FIELDS` appends `greenlightSuppressed` and\n * `greenlightSuppressionReason`. These are the only Greenlight-named fields on\n * this list, and the exception is mandatory rather than convenient: suppression\n * is a *blocking* input to the compliance rule, so a change that does not\n * re-score leaves a person who has just asked us to stop sitting in the queue\n * still marked `PASS`. A block list nobody re-scores against is not a block list.\n *\n * The loop still terminates, and the argument is the same three guards, checked\n * against the new field:\n *\n *   1. **Guard 1 still holds because the two sets are disjoint.** The scoring run\n *      writes exactly `GREENLIGHT_MANAGED_PERSON_FIELDS`, and no name on that\n *      list is on this one. A suppression change wakes the scorer; the scorer's\n *      own write-back does not wake anything, because it touches none of these\n *      names. The cycle would only close if the run wrote a suppression field,\n *      which it never does \u2014 the two block-list actions are the only writers, and\n *      they are human-triggered. `scoring-run.test.ts` asserts both halves.\n *   2. **Guard 2 is unaffected.** `isGreenlightAuthoredWrite` tests membership of\n *      the managed list, not of this one, so an event carrying only suppression\n *      fields is correctly *not* treated as our own write and is scored.\n *   3. **Guard 3 is the backstop and gets stronger, not weaker.** Suppression\n *      moves the compliance rule's outcome, so the first run after a change has a\n *      genuinely different fingerprint and writes; any replay of that same event\n *      fingerprints identically and writes nothing.\n *\n * ## The enrichment exception\n *\n * `greenlightEnrichment` is on this list for the same kind of reason and it is\n * equally mandatory. `resolveFieldMapping` appends\n * `greenlightEnrichment.fields.<key>.parsedValue` to every enrichable key, so an\n * enriched value is a *scoring input*. Leaving it off meant enrichment could\n * only ever benefit a lead on its next unrelated edit \u2014 the enriched industry\n * sat on the record, read by nothing, until somebody happened to change a phone\n * number. That is enrichment being cosmetic, which is the bug this closes.\n *\n * The two sibling columns are deliberately **not** here. `greenlightEnrichedAt`\n * and `greenlightEnrichmentStatus` are written by the same mutation but no rule\n * reads either, so waking the scorer for them would buy a guaranteed-identical\n * fingerprint and nothing else.\n *\n * ### Why this terminates\n *\n * Unlike suppression, this one *does* close a cycle: enrichment's own trigger is\n * `greenlightDecision`, which is a field this run writes. The cycle is real,\n * bounded, and cannot reach a provider more than a fixed number of times.\n *\n *   1. **The common case never starts.** Guard 3 is checked before any write. If\n *      enrichment changed no value the mapping reads \u2014 it accepted nothing, or\n *      the field already had a human value ahead of the enriched path \u2014 the score,\n *      band, decision and every rule verdict are identical, the fingerprint\n *      matches the one stored on the record, and this run writes *nothing*.\n *      `greenlightDecision` never changes, so enrichment is never woken. The\n *      chain is one hop long.\n *   2. **When the score does move**, this run writes `greenlightDecision` and\n *      enrichment wakes. Its gap analysis then finds every enrichable field\n *      either freshly cached (the run that just fired filled it) or inside the\n *      unresolved back-off window (it asked and found nothing), requests nothing,\n *      and returns `no_gaps` **before any provider call and before any write**.\n *      No write means no `greenlightEnrichment` change, which means the scorer is\n *      not woken again. The chain is two hops long and costs one key-value read.\n *   3. **The pathological case still terminates.** Even if a later enrichment run\n *      did find a fresh gap, every hop strictly shrinks the set of unfilled\n *      enrichable fields \u2014 a field that is sourced becomes fresh, and a field that\n *      is not becomes unresolved \u2014 so the chain is bounded by the five entries in\n *      `ENRICHABLE_FIELD_SPECS`, and the monthly spend cap bounds it again from\n *      outside.\n *\n * Guard 2 stays correct throughout: `isGreenlightAuthoredWrite` tests membership\n * of `GREENLIGHT_MANAGED_PERSON_FIELDS`, which this run writes and enrichment\n * does not, so an enrichment write is correctly *not* mistaken for our own and\n * is scored. `__tests__/enrich-score-cycle.test.ts` drives the whole loop against\n * both runs and asserts it settles rather than trusting this comment.\n */\nexport const SCORING_TRIGGER_PERSON_FIELDS: readonly string[] = [\n  'name',\n  'emails',\n  'phones',\n  'jobTitle',\n  'linkedinLink',\n  'company',\n  'companyId',\n  // The enriched-value blob. See \"The enrichment exception\" above \u2014 this is a\n  // scoring input, and the cycle it closes is bounded and proved by test.\n  'greenlightEnrichment',\n  ...SUPPRESSION_SCORING_INPUT_FIELDS,\n];\n\n/** `Person.greenlightDecision` / `GreenlightAuditLog.decision` SELECT values. */\nexport type DecisionValue = 'PASS' | 'GATE' | 'BLOCKED' | 'UNSCORED';\n\n/** `GreenlightAuditLog.eventType` SELECT values used by the scoring path. */\ntype AuditEventType = 'SCORED' | 'GATED' | 'SKIPPED' | 'ERROR';\n\n/* -------------------------------------------------------------------------- */\n/* Guards                                                                      */\n/* -------------------------------------------------------------------------- */\n\n/**\n * True when an update event carries nothing but fields Greenlight itself wrote.\n *\n * An empty or absent `updatedFields` returns false: \"we do not know what\n * changed\" must mean \"score it\", because the alternative is silently skipping a\n * real edit. Over-scoring is harmless \u2014 guard 3 makes the redundant run a no-op.\n */\nexport const isGreenlightAuthoredWrite = (\n  updatedFields: unknown,\n): boolean => {\n  if (!Array.isArray(updatedFields) || updatedFields.length === 0) {\n    return false;\n  }\n\n  return updatedFields.every(\n    (field) =>\n      typeof field === 'string' &&\n      GREENLIGHT_MANAGED_PERSON_FIELDS.includes(field),\n  );\n};\n\n/* -------------------------------------------------------------------------- */\n/* Result -> CRM vocabulary                                                    */\n/* -------------------------------------------------------------------------- */\n\n/**\n * Map the engine's four-valued decision onto the SELECT the schema ships.\n *\n * The mapping is now one-to-one: `greenlightDecision` carries a `BLOCKED` option\n * of its own (see `src/fields/greenlight-decision.field.ts`), so a compliance\n * stop is no longer indistinguishable from a low score. Before that option\n * existed `blocked` collapsed onto `GATE` and every consumer had to\n * reverse-engineer the difference out of `greenlightTrace`.\n *\n * When the gate is switched off, `gated` is downgraded to `PASS` per the\n * `isGateEnabled` field's contract (\"nothing is held for review\"). `blocked` is\n * **not** downgraded: that state only arises from a compliance stop such as an\n * opt-out, and quietly marking an opted-out contact as ready to call is not a\n * behaviour any switch on a settings page should be able to buy.\n */\nexport const toDecisionValue = (\n  decision: GateDecision,\n  gateEnabled: boolean,\n): DecisionValue => {\n  switch (decision) {\n    case 'approved':\n      return 'PASS';\n    case 'gated':\n      return gateEnabled ? 'GATE' : 'PASS';\n    case 'blocked':\n      return 'BLOCKED';\n    default:\n      return 'UNSCORED';\n  }\n};\n\n/** The decision values that mean \"this lead is being held from a rep\". */\nconst HOLDING_DECISIONS: readonly DecisionValue[] = ['GATE', 'BLOCKED'];\n\nconst KNOWN_BAND_VALUES: readonly string[] = [\n  'EXCELLENT',\n  'GOOD',\n  'FAIR',\n  'POOR',\n];\n\n/**\n * Band ids are configurable, so an unrecognised one has to degrade rather than\n * be written into a SELECT that would reject it.\n */\nexport const toBandValue = (result: ScoringResult): string => {\n  const id = result.band?.id;\n\n  if (typeof id !== 'string') {\n    return 'UNSCORED';\n  }\n\n  const value = id.trim().toUpperCase();\n\n  return KNOWN_BAND_VALUES.includes(value) ? value : 'UNSCORED';\n};\n\nexport const toAuditEventType = (\n  decision: DecisionValue,\n  result: ScoringResult,\n): AuditEventType => {\n  if (result.decision === 'unscored') {\n    return 'SKIPPED';\n  }\n\n  // GATED covers both holding states. The audit log's `eventType` vocabulary is\n  // about what happened to the lead \u2014 it was held \u2014 and the row's `decision`\n  // column already says which of the two states it was held in.\n  return HOLDING_DECISIONS.includes(decision) ? 'GATED' : 'SCORED';\n};\n\n/* -------------------------------------------------------------------------- */\n/* Fingerprint + trace id                                                      */\n/* -------------------------------------------------------------------------- */\n\n/** FNV-1a, 32-bit. Short, dependency-free, and stable across Node versions. */\nconst hash32 = (input: string): string => {\n  let hash = 0x811c9dc5;\n\n  for (let index = 0; index < input.length; index += 1) {\n    hash ^= input.charCodeAt(index);\n    hash = Math.imul(hash, 0x01000193) >>> 0;\n  }\n\n  return hash.toString(16).padStart(8, '0');\n};\n\n/**\n * A stable digest of everything about a run that a human would call \"the\n * outcome\": the score, the decision, the band, and the verdict of every rule.\n *\n * Explicitly excludes `scoredAt`, the trace prose and the degradation list, so\n * re-scoring an untouched lead a day later produces the same fingerprint and\n * writes nothing.\n */\nexport const fingerprintOutcome = (\n  result: ScoringResult,\n  decisionValue: string,\n): string => {\n  const parts = [\n    result.engineVersion,\n    decisionValue,\n    result.score === null ? 'null' : result.score.toFixed(1),\n    result.band?.id ?? 'none',\n    result.gateThreshold.toString(),\n    ...result.trace.map(\n      (entry) => `${entry.ruleId}:${entry.outcome}:${entry.credit.toFixed(3)}`,\n    ),\n  ];\n\n  return hash32(parts.join('|'));\n};\n\n/**\n * Deterministic per (lead, outcome). A retry that re-writes the same decision\n * reuses the id, so duplicate audit rows are recognisable as one run rather than\n * looking like the gate flip-flopped.\n */\nexport const buildTraceId = (\n  leadRecordId: string,\n  fingerprint: string,\n): string => `gl-${hash32(leadRecordId)}-${fingerprint}`;\n\n/** The fingerprint already stored on the Person, if any. */\nexport const readStoredFingerprint = (trace: unknown): string | null => {\n  if (!isPlainRecord(trace)) {\n    return null;\n  }\n\n  const value = trace['fingerprint'];\n\n  return typeof value === 'string' && value.length > 0 ? value : null;\n};\n\n/* -------------------------------------------------------------------------- */\n/* Display helpers                                                             */\n/* -------------------------------------------------------------------------- */\n\n/** Person.name is a FULL_NAME composite. Fall back to email, then to the id. */\nexport const readLeadDisplayName = (person: unknown): string => {\n  if (!isPlainRecord(person)) {\n    return 'Unknown lead';\n  }\n\n  const name = person['name'];\n\n  if (isPlainRecord(name)) {\n    const parts = [name['firstName'], name['lastName']]\n      .filter((part): part is string => typeof part === 'string')\n      .map((part) => part.trim())\n      .filter((part) => part.length > 0);\n\n    if (parts.length > 0) {\n      return parts.join(' ');\n    }\n  }\n\n  if (typeof name === 'string' && name.trim().length > 0) {\n    return name.trim();\n  }\n\n  const emails = person['emails'];\n\n  if (isPlainRecord(emails)) {\n    const primary = emails['primaryEmail'];\n\n    if (typeof primary === 'string' && primary.trim().length > 0) {\n      return primary.trim();\n    }\n  }\n\n  const id = person['id'];\n\n  return typeof id === 'string' ? id : 'Unknown lead';\n};\n\n/* -------------------------------------------------------------------------- */\n/* The run                                                                     */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The slice of app key-value storage this run needs, as a port.\n *\n * `kv` is only importable from `twenty-sdk/logic-function`, and this module is\n * deliberately SDK-free so it can be driven by a fake in tests \u2014 the same reason\n * `GreenlightApiClient` exists. `src/logic-functions/release-marker-store.ts`\n * holds the one real implementation.\n *\n * It is a *required* input rather than an optional one on purpose. A run without\n * a store silently re-gates every released lead, which is exactly the bug this\n * port exists to close; making it required means the compiler, not a reviewer,\n * catches a registration that forgot to wire it.\n */\nexport interface ReleaseMarkerStore {\n  get(key: string): Promise<ReleaseMarker | null>;\n  delete(key: string): Promise<void>;\n}\n\n/**\n * A config record the caller has already read, so the run does not read it again.\n *\n * Wrapped in an object rather than passed as `Record | null` because `null` is a\n * *legitimate answer* here \u2014 it means \"this workspace has no config record, score\n * on the engine's defaults\" \u2014 and would otherwise be indistinguishable from \"the\n * caller did not supply one\". The wrapper makes absent and empty different types\n * instead of different values.\n *\n * It exists for the backfill (`src/logic-functions/backfill-run.ts`), which scores\n * thirty records per cron tick against one config that cannot change between\n * them. Reading it per record would treble the run's share of the rate limit \u2014\n * 30 requests a minute buying thirty identical answers \u2014 and would be the single\n * largest cost in a bulk pass.\n *\n * Optional on purpose: the two event registrations pass nothing and keep the\n * exact behaviour they had, which is what makes this an additive change rather\n * than a rewrite of the hot path.\n */\nexport interface PreloadedConfig {\n  readonly record: Record<string, unknown> | null;\n}\n\nexport interface ScoringRunInput {\n  readonly client: GreenlightApiClient;\n  /** The `DatabaseEventPayload` as delivered, untyped on purpose. */\n  readonly event: unknown;\n  readonly now: Date;\n  readonly markers: ReleaseMarkerStore;\n  /** Omitted by the event registrations; supplied by the bulk backfill. */\n  readonly config?: PreloadedConfig;\n  /**\n   * Read-only access to the licence-delivered calibration cache.\n   *\n   * Optional, and its absence means \"shipped defaults\" \u2014 the same outcome as an\n   * unlicensed workspace, an expired cache, or a payload whose signature did not\n   * verify. That is what makes this additive: every existing caller that does\n   * not pass it keeps its exact previous behaviour, and the compiler does not\n   * have to be trusted on the point because there is nothing to break.\n   */\n  readonly calibration?: CalibrationReaderPort | null;\n  /**\n   * Checks that the cached calibration belongs to this workspace's licence key.\n   *\n   * Defaults to `NO_SEAL`, which accepts nothing \u2014 so a caller that wires the\n   * reader but forgets the seal gets shipped defaults rather than an unchecked\n   * cache. See `src/calibration/seal.ts` for what the seal does and does not\n   * prove.\n   */\n  readonly calibrationSeal?: CalibrationSealPort;\n}\n\nexport type ScoringRunOutcome =\n  | { status: 'skipped'; reason: string }\n  | { status: 'unchanged'; leadRecordId: string; fingerprint: string }\n  | {\n      status: 'scored';\n      leadRecordId: string;\n      traceId: string;\n      decision: string;\n      score: number | null;\n    }\n  | { status: 'failed'; leadRecordId: string | null; error: string };\n\nconst readEventRecord = (event: unknown): Record<string, unknown> | null => {\n  if (!isPlainRecord(event)) {\n    return null;\n  }\n\n  const properties = event['properties'];\n\n  if (!isPlainRecord(properties)) {\n    return null;\n  }\n\n  const after = properties['after'];\n\n  return isPlainRecord(after) ? after : null;\n};\n\nconst readEventUpdatedFields = (event: unknown): unknown => {\n  if (!isPlainRecord(event)) {\n    return undefined;\n  }\n\n  const properties = event['properties'];\n\n  return isPlainRecord(properties) ? properties['updatedFields'] : undefined;\n};\n\nconst readRecordId = (\n  event: unknown,\n  record: Record<string, unknown> | null,\n): string | null => {\n  if (isPlainRecord(event) && typeof event['recordId'] === 'string') {\n    return event['recordId'];\n  }\n\n  if (record !== null && typeof record['id'] === 'string') {\n    return record['id'];\n  }\n\n  return null;\n};\n\n/** Load the single config record. Absent or unreadable yields `null`. */\nexport const loadConfigRecord = async (\n  client: GreenlightApiClient,\n): Promise<Record<string, unknown> | null> => {\n  const response = await client.query({\n    greenlightConfigs: { edges: { node: greenlightConfigSelection() } },\n  });\n\n  return oldestByCreatedAt(readConnectionNodes(response, 'greenlightConfigs'));\n};\n\n/**\n * Best-effort company hydration.\n *\n * `event.properties.after` carries the Person's own columns and the company\n * foreign key, but not the company's name \u2014 and \"which company does this lead\n * work for\" is a rule worth 10 points. One extra read buys it. If the read\n * fails for any reason the lead is scored without it, because a lead scored\n * slightly low is recoverable and a lead not scored at all is not.\n */\nconst hydrateCompany = async (\n  client: GreenlightApiClient,\n  person: Record<string, unknown>,\n): Promise<Record<string, unknown>> => {\n  const companyId = person['companyId'];\n\n  if (typeof companyId !== 'string' || companyId.length === 0) {\n    return person;\n  }\n\n  if (isPlainRecord(person['company'])) {\n    return person;\n  }\n\n  try {\n    const response = await client.query({\n      companies: {\n        __args: { filter: { id: { eq: companyId } } },\n        edges: { node: { id: true, name: true } },\n      },\n    });\n\n    const [company] = readConnectionNodes(response, 'companies');\n\n    return company === undefined ? person : { ...person, company };\n  } catch (error) {\n    logGreenlight('company_hydration_failed', {\n      companyId,\n      error: describeError(error),\n    });\n\n    return person;\n  }\n};\n\n/* -------------------------------------------------------------------------- */\n/* The human override                                                          */\n/* -------------------------------------------------------------------------- */\n\n/**\n * The object name the release marker is keyed on.\n *\n * Hard-coded rather than taken from the config's `leadObjectNameSingular`\n * because the override can only ever write a `person` key \u2014\n * `SUPPORTED_LEAD_OBJECTS` in `release-decision.ts` has one entry, and both\n * scoring registrations are bound to `person.*` events. Deriving the key from\n * configuration would mean a workspace that renamed its lead object silently\n * looked up a key the release side never writes, which is the same silent\n * self-undoing override this whole mechanism exists to prevent.\n */\nconst RELEASE_MARKER_OBJECT = 'person';\n\n/**\n * A compliance stop, using the exact discriminator `src/scoring/engine.ts` uses\n * to choose `blocked` \u2014 checked from the trace as well as the decision so a\n * blocking failure is still recognised if the engine ever reports the two\n * inconsistently.\n */\nconst hasBlockingFailure = (result: ScoringResult): boolean =>\n  result.decision === 'blocked' ||\n  result.trace.some(\n    (entry) => entry.severity === 'blocking' && entry.outcome === 'fail',\n  );\n\ninterface ReleasePin {\n  /** The decision to actually write. */\n  readonly decision: DecisionValue;\n  /** Non-null only when a marker was honoured and the decision was pinned. */\n  readonly honoured: ReleaseMarker | null;\n}\n\n/**\n * Honour a human release when re-scoring would otherwise hold the lead again.\n *\n * The contract with `release-lead.logic-function.ts`: if a release marker\n * exists, the score and the trace still update freely, but `greenlightDecision`\n * stays at `PASS`. Three things are worth being explicit about.\n *\n * **A newly blocking compliance failure outranks the release.** The marker is\n * deleted and the lead is re-held. \"Newly\" needs no timestamp comparison: the\n * override refuses to release a compliance-blocked lead at all\n * (`ALLOW_COMPLIANCE_OVERRIDE === false`) and writes no marker when it refuses,\n * so any marker that exists was written for a lead that was *not* blocked at\n * release time. A blocking failure seen now is therefore newer by construction.\n *\n * **A failed key-value read re-gates rather than releases.** Falling back to\n * \"no marker\" means a released lead can be wrongly held for a moment \u2014 an\n * annoyance a human fixes by releasing it again, with the whole trail recording\n * what happened. The opposite fallback, treating an unreadable store as \"a\n * marker probably exists\", would let a storage outage quietly release leads the\n * gate is holding, including leads held on compliance grounds. That is not\n * recoverable by a human, because nobody knows it happened. The failure is\n * logged rather than swallowed, under `release_marker_read_failed`.\n *\n * **A failed delete is self-correcting.** If the marker survives a re-gating\n * compliance failure, the *next* run re-evaluates the same blocking rule and\n * re-holds the lead again \u2014 a stale marker only ever wins once the compliance\n * failure has genuinely gone away, which is the state a release should win in.\n */\nconst pinReleasedDecision = async (\n  markers: ReleaseMarkerStore,\n  leadRecordId: string,\n  decisionValue: DecisionValue,\n  result: ScoringResult,\n): Promise<ReleasePin> => {\n  if (!HOLDING_DECISIONS.includes(decisionValue)) {\n    // Nothing is being held, so there is nothing to pin and no reason to spend\n    // a read. A marker left behind by an earlier release is harmless: it is only\n    // ever consulted on a run that would hold the lead.\n    return { decision: decisionValue, honoured: null };\n  }\n\n  const key = releaseMarkerKey(RELEASE_MARKER_OBJECT, leadRecordId);\n\n  let marker: ReleaseMarker | null = null;\n\n  try {\n    marker = await markers.get(key);\n  } catch (error) {\n    logGreenlight('release_marker_read_failed', {\n      leadRecordId,\n      decision: decisionValue,\n      error: describeError(error),\n    });\n\n    return { decision: decisionValue, honoured: null };\n  }\n\n  if (marker === null) {\n    return { decision: decisionValue, honoured: null };\n  }\n\n  if (hasBlockingFailure(result)) {\n    try {\n      await markers.delete(key);\n    } catch (error) {\n      logGreenlight('release_marker_delete_failed', {\n        leadRecordId,\n        error: describeError(error),\n      });\n    }\n\n    logGreenlight('release_marker_overruled', {\n      leadRecordId,\n      decision: decisionValue,\n      releasedAt: marker.releasedAt,\n    });\n\n    return { decision: decisionValue, honoured: null };\n  }\n\n  return { decision: 'PASS', honoured: marker };\n};\n\nconst buildTracePayload = (\n  result: ScoringResult,\n  traceId: string,\n  fingerprint: string,\n  decisionValue: string,\n  bandValue: string,\n  releaseOverride: Record<string, unknown> | null,\n  /**\n   * Which calibration produced this score, or `null` for shipped defaults.\n   *\n   * Recorded on the lead itself rather than only in the admin panel, because\n   * \"why did this lead score 68 last week and 82 today\" is a question asked\n   * about one record months later, and the panel only ever shows *now*. It is\n   * the version number and nothing else \u2014 the payload is a few hundred\n   * kilobytes of word lists and does not belong on every Person row.\n   */\n  calibrationVersion: number | null,\n): Record<string, unknown> => ({\n  calibration:\n    calibrationVersion === null\n      ? { source: 'shipped_defaults' }\n      : { source: 'licensed', version: calibrationVersion },\n  traceId,\n  fingerprint,\n  engineVersion: result.engineVersion,\n  scoredAt: result.scoredAt,\n  score: result.score,\n  band: bandValue,\n  decision: decisionValue,\n  gateThreshold: result.gateThreshold,\n  summary: result.summary,\n  reasons: [...result.reasons],\n  configSource: result.configSource,\n  degradations: result.degradations.map((entry) => ({ ...entry })),\n  rules: result.trace.map((entry) => ({ ...entry })),\n  // Present only on a pinned run. Without it the trace would show a lead\n  // scoring 12 against a threshold of 40 sitting at PASS with nothing on the\n  // record explaining why, which is the same silence the marker exists to fix.\n  ...(releaseOverride === null ? {} : { releaseOverride }),\n});\n\n/**\n * Score one Person event end to end.\n *\n * Never throws. Every failure path returns a `failed` outcome after making a\n * best-effort attempt to leave the lead flagged `UNSCORED` with an ERROR audit\n * row \u2014 ARCHITECTURE.md's golden rule is that a lead is never blocked from\n * reaching a rep, so a broken run must leave a visible, explained record rather\n * than a silent gap.\n */\n/**\n * Read the cached calibration and reduce it to the vocabulary baseline the\n * engine accepts.\n *\n * Never throws and never blocks: a store that errors, a cache that is absent\n * (which is also what a lapsed entitlement leaves behind \u2014 the nightly run\n * clears it), and a payload that has aged past 72 hours all return `null`,\n * which resolves to the in-source defaults. There is no branch here that can\n * stop a lead being scored, and there is deliberately no way to write one \u2014 the\n * port has no method but `read`.\n *\n * No licence state is consulted. That is not an omission: see\n * `src/calibration/state.ts`, \"Why there is no entitlement check here\".\n */\ninterface AppliedCalibration {\n  readonly baseline: ReturnType<typeof toScoringBaseline>;\n  readonly version: number;\n}\n\n/**\n * Return the entry only if its seal verifies under this workspace's licence key.\n *\n * A failure is logged once and reported as `null`, i.e. as \"no calibration\",\n * which is the shipped-defaults path. It is deliberately not an error: a cache\n * that fails its seal is most often a licence key that was changed, and a rep\n * scoring a lead is not the person to tell about it. The nightly run rewrites a\n * correctly-sealed entry and the condition clears itself.\n */\nconst verifySeal = async (\n  stored: Awaited<ReturnType<CalibrationReaderPort['read']>>,\n  seal: CalibrationSealPort,\n): Promise<typeof stored> => {\n  if (stored === null) {\n    return null;\n  }\n\n  const canonical = sealedCalibrationBody(stored);\n\n  if (canonical === null) {\n    return null;\n  }\n\n  const sealed = await seal.verify(canonical, stored.sealTag);\n\n  if (!sealed) {\n    logGreenlight('calibration_cache_seal_mismatch', {\n      calibrationVersion: stored.calibration.calibrationVersion,\n      keyId: stored.keyId,\n    });\n\n    return null;\n  }\n\n  return stored;\n};\n\nconst readCalibrationBaseline = async (\n  calibration: CalibrationReaderPort | null | undefined,\n  seal: CalibrationSealPort,\n  now: Date,\n): Promise<AppliedCalibration | null> => {\n  if (calibration === null || calibration === undefined) {\n    return null;\n  }\n\n  try {\n    const stored = await calibration.read();\n\n    // The seal is checked before the freshness ladder, not after. A cache\n    // lifted from another workspace should be refused on the grounds that it is\n    // not ours, whatever its age \u2014 and checking age first would mean a stolen\n    // cache and an expired one produce the same reason in the log, which is the\n    // one distinction worth keeping here.\n    const cached = await verifySeal(stored, seal);\n\n    const resolved = resolveCalibration({ cached, now });\n\n    return resolved.calibration === null\n      ? null\n      : {\n          baseline: toScoringBaseline(resolved.calibration),\n          version: resolved.calibration.calibrationVersion,\n        };\n  } catch (error) {\n    logGreenlight('calibration_read_failed', { error: describeError(error) });\n\n    return null;\n  }\n};\n\nexport const runPersonScoring = async ({\n  client,\n  event,\n  now,\n  markers,\n  config,\n  calibration,\n  calibrationSeal = NO_SEAL,\n}: ScoringRunInput): Promise<ScoringRunOutcome> => {\n  const person = readEventRecord(event);\n  const leadRecordId = readRecordId(event, person);\n\n  // Guard 2. Runs before anything else so a Greenlight-authored write costs one\n  // array scan, not two API round trips.\n  if (isGreenlightAuthoredWrite(readEventUpdatedFields(event))) {\n    return { status: 'skipped', reason: 'greenlight_authored_write' };\n  }\n\n  if (person === null || leadRecordId === null) {\n    logGreenlight('event_unreadable', { leadRecordId });\n\n    return { status: 'skipped', reason: 'event_unreadable' };\n  }\n\n  try {\n    // A supplied config is used as-is, including a supplied `null`. Only an\n    // absent wrapper triggers the read \u2014 see `PreloadedConfig`.\n    const configRecord =\n      config === undefined ? await loadConfigRecord(client) : config.record;\n    const gateEnabled = isGateEnabled(configRecord);\n    const leadObjectNameSingular = readLeadObjectNameSingular(configRecord);\n\n    const hydrated = await hydrateCompany(client, person);\n\n    const applied = await readCalibrationBaseline(\n      calibration,\n      calibrationSeal,\n      now,\n    );\n\n    // `scoreLead` never throws and repairs anything unusable in the config, so\n    // a missing record needs no special case here \u2014 it becomes `configSource:\n    // 'defaults'` and a degradation entry in the trace. A `null` baseline is\n    // likewise not a special case: it is what the parameter means when there is\n    // no calibration, and it scores identically to the build that predates it.\n    const result = scoreLead({\n      lead: toLeadRecord(hydrated),\n      now,\n      config: toScoringConfigInput(configRecord),\n      baseline: applied?.baseline ?? null,\n    });\n\n    const engineDecision = toDecisionValue(result.decision, gateEnabled);\n    const pin = await pinReleasedDecision(\n      markers,\n      leadRecordId,\n      engineDecision,\n      result,\n    );\n    const decisionValue = pin.decision;\n    const bandValue = toBandValue(result);\n\n    // The fingerprint is taken over the decision actually written, not the one\n    // the engine proposed. That keeps guard 3 honest in both directions: the\n    // first pinned run differs from the stored GATE fingerprint and writes, and\n    // every identical pinned run afterwards matches and writes nothing. A\n    // fingerprint over `engineDecision` would record a decision the record does\n    // not carry.\n    const fingerprint = fingerprintOutcome(result, decisionValue);\n\n    // Guard 3.\n    if (readStoredFingerprint(person['greenlightTrace']) === fingerprint) {\n      return { status: 'unchanged', leadRecordId, fingerprint };\n    }\n\n    const traceId = buildTraceId(leadRecordId, fingerprint);\n    const leadDisplayName = readLeadDisplayName(person);\n    const eventType = toAuditEventType(decisionValue, result);\n    const tracePayload = buildTracePayload(\n      result,\n      traceId,\n      fingerprint,\n      decisionValue,\n      bandValue,\n      pin.honoured === null\n        ? null\n        : {\n            engineDecision,\n            releasedAt: pin.honoured.releasedAt,\n            releasedBy: pin.honoured.releasedBy,\n            reasonCode: pin.honoured.reasonCode,\n          },\n      applied?.version ?? null,\n    );\n    // A pinned run is still a SYSTEM action \u2014 the system honouring a human\n    // decision taken earlier \u2014 so `actorType` stays SYSTEM and the human's\n    // fingerprints go in the reason, where the audit log already looks for them.\n    const overrideReason =\n      pin.honoured === null\n        ? ''\n        : `RELEASE_MARKER_HONOURED \u2014 engine decision ${engineDecision} held at PASS by the release recorded ${pin.honoured.releasedAt} (${pin.honoured.releasedBy}, ${pin.honoured.reasonCode})`;\n\n    // Audit row first, Person second \u2014 and the order is load-bearing.\n    //\n    // If the audit write succeeds and the Person write fails, the next event\n    // re-scores, finds the stored fingerprint still absent, and writes both\n    // again: the trail over-records. If the order were reversed, the Person\n    // would carry the new fingerprint, guard 3 would suppress every subsequent\n    // run, and the decision would never be recorded at all. An append-only\n    // trail is allowed to repeat itself; it is not allowed to lose an entry.\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: {\n            name: `${eventType} \u00B7 ${leadDisplayName} \u00B7 ${result.score ?? '\u2014'}`,\n            eventType,\n            occurredAt: now.toISOString(),\n            leadObjectNameSingular,\n            leadRecordId,\n            leadDisplayName,\n            actorType: 'SYSTEM',\n            actorDisplayName: `Greenlight engine ${SCORING_ENGINE_VERSION}`,\n            ruleTrace: tracePayload,\n            score: result.score,\n            band: bandValue,\n            decision: decisionValue,\n            overrideReason,\n            traceId,\n          },\n        },\n        id: true,\n      },\n    });\n\n    await client.mutation({\n      updatePerson: {\n        __args: {\n          id: leadRecordId,\n          data: {\n            greenlightScore: result.score,\n            greenlightDecision: decisionValue,\n            greenlightTrace: tracePayload,\n          },\n        },\n        id: true,\n      },\n    });\n\n    logGreenlight('lead_scored', {\n      leadRecordId,\n      traceId,\n      score: result.score,\n      band: bandValue,\n      decision: decisionValue,\n      engineDecision,\n      releasePinned: pin.honoured !== null,\n      configSource: result.configSource,\n      calibrationVersion: applied?.version ?? null,\n      degradations: result.degradations.length,\n    });\n\n    return {\n      status: 'scored',\n      leadRecordId,\n      traceId,\n      decision: decisionValue,\n      score: result.score,\n    };\n  } catch (error) {\n    const message = describeError(error);\n\n    logGreenlight('scoring_failed', { leadRecordId, error: message });\n\n    await flagUnscored(client, leadRecordId, person, now, message);\n\n    return { status: 'failed', leadRecordId, error: message };\n  }\n};\n\n/**\n * Last-ditch fail-open write. Each half is independently guarded: a lead left\n * with no flag is bad, a logic function that throws out to the platform because\n * its error handler also failed is worse.\n */\nconst flagUnscored = async (\n  client: GreenlightApiClient,\n  leadRecordId: string,\n  person: Record<string, unknown>,\n  now: Date,\n  error: string,\n): Promise<void> => {\n  const traceId = buildTraceId(leadRecordId, hash32(error));\n  const leadDisplayName = readLeadDisplayName(person);\n\n  const tracePayload = {\n    traceId,\n    // No fingerprint: an errored run must not suppress the next attempt.\n    engineVersion: SCORING_ENGINE_VERSION,\n    scoredAt: now.toISOString(),\n    score: null,\n    band: 'UNSCORED',\n    decision: 'UNSCORED',\n    summary:\n      'Greenlight could not score this lead. It has been passed through unscored and flagged for review.',\n    reasons: [error],\n    rules: [],\n  };\n\n  try {\n    await client.mutation({\n      createGreenlightAuditLog: {\n        __args: {\n          data: {\n            name: `ERROR \u00B7 ${leadDisplayName} \u00B7 \u2014`,\n            eventType: 'ERROR',\n            occurredAt: now.toISOString(),\n            leadObjectNameSingular: 'person',\n            leadRecordId,\n            leadDisplayName,\n            actorType: 'SYSTEM',\n            actorDisplayName: `Greenlight engine ${SCORING_ENGINE_VERSION}`,\n            ruleTrace: tracePayload,\n            score: null,\n            band: 'UNSCORED',\n            decision: 'UNSCORED',\n            overrideReason: '',\n            traceId,\n          },\n        },\n        id: true,\n      },\n    });\n  } catch (auditError) {\n    logGreenlight('fail_open_audit_write_failed', {\n      leadRecordId,\n      error: describeError(auditError),\n    });\n  }\n\n  try {\n    await client.mutation({\n      updatePerson: {\n        __args: {\n          id: leadRecordId,\n          data: {\n            greenlightDecision: 'UNSCORED',\n            greenlightTrace: tracePayload,\n          },\n        },\n        id: true,\n      },\n    });\n  } catch (updateError) {\n    logGreenlight('fail_open_person_write_failed', {\n      leadRecordId,\n      error: describeError(updateError),\n    });\n  }\n};\n"],
  "mappings": ";;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AAEO,QAAM,cAAc,CAAI,SAA0C;AACvE,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,cAAW;AAIjB,QAAM,YAAY,CAAI,SAAsC;AACjE,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,YAAS;AAIf,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS,YAAY,CAAC,OAAO,MAAM,IAAI;IACvD;AAFa,YAAA,WAAQ;AAId,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,WAAQ;AAId,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,WAAQ;AAId,QAAM,WAAW,CAAI,SAAoC;AAC9D,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,WAAQ;;;;;;;;;;ACpBd,QAAM,SAAS,CAAI,SAAgC;AACxD,aAAO,SAAS;IAClB;AAFa,YAAA,SAAM;AAIZ,QAAM,aAAa,CAAwB,SAA0B;AAC1E,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,aAAU;AAIhB,QAAM,WAAW,CACtB,SAC0B;AAC1B,aAAO,CAAC,QAAA,OAAO,IAAI,KAAK,OAAO,SAAS;IAC1C;AAJa,YAAA,WAAQ;AAMd,QAAM,UAAU,CAAO,SAAwC;AACpE,aAAO,MAAM,QAAQ,IAAI;IAC3B;AAFa,YAAA,UAAO;AAIb,QAAM,QAAQ,CAAU,SAA0C;AACvE,aAAO,gBAAgB;IACzB;AAFa,YAAA,QAAK;AAIX,QAAM,QAAQ,CAAO,SAAoC;AAC9D,aAAO,gBAAgB;IACzB;AAFa,YAAA,QAAK;AAIX,QAAM,YAAY,CACvB,SACyB;AACzB,aAAO,gBAAgB;IACzB;AAJa,YAAA,YAAS;AAMf,QAAM,YAAY,CACvB,SACsB;AACtB,aAAO,gBAAgB;IACzB;AAJa,YAAA,YAAS;AAMf,QAAM,SAAS,CAAI,SAAgC;AACxD,aAAO,gBAAgB;IACzB;AAFa,YAAA,SAAM;;;;;;;;;;ACxCnB,QAAA,eAAA;AACA,QAAA,eAAA;AAEO,QAAM,iBAAiB,CAAsB,SAA0B;AAC5E,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,iBAAc;AAIpB,QAAM,kBAAkB,CAAO,SAAwC;AAC5E,aAAO,aAAA,QAAQ,IAAI,KAAK,KAAK,SAAS;IACxC;AAFa,YAAA,kBAAe;AAIrB,QAAM,mBAAmB,CAAI,SAAoC;AACtE,aAAO,aAAA,SAAS,IAAI,KAAK,KAAK,SAAS;IACzC;AAFa,YAAA,mBAAgB;AAItB,QAAM,gBAAgB,CAAI,SAAoC;AACnE,aAAO,OAAO,SAAS;IACzB;AAFa,YAAA,gBAAa;AAInB,QAAM,YAAY,CAAI,SAAoC;AAC/D,aAAO,aAAA,SAAS,IAAI,KAAK,OAAO,UAAU,IAAI;IAChD;AAFa,YAAA,YAAS;AAIf,QAAM,oBAAoB,CAAI,SAAoC;AACvE,aAAO,QAAA,UAAU,IAAI,KAAK,OAAO;IACnC;AAFa,YAAA,oBAAiB;AAIvB,QAAM,uBAAuB,CAAI,SAAoC;AAC1E,aAAO,QAAA,UAAU,IAAI,KAAK,QAAQ;IACpC;AAFa,YAAA,uBAAoB;AAI1B,QAAM,oBAAoB,CAAI,SAAoC;AACvE,aAAO,QAAA,UAAU,IAAI,KAAK,OAAO;IACnC;AAFa,YAAA,oBAAiB;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AC/B9B,YAAA,cAAA,aAAA,qBAAA;AACA,iBAAA,uBAAA,OAAA;AACA,YAAA,aAAA,aAAA,oBAAA;AACA,iBAAA,sBAAA,OAAA;AACA,YAAA,aAAA,aAAA,oBAAA;AACA,iBAAA,sBAAA,OAAA;;;;;ACLA,SAAS,qBAAqB;;;ACI9B,IAAM,sBAAsB,CAAC,YAAY;AAAA,EACvC,SAAS;AAAA,EACT;AAAA,EACA,QAAQ,CAAC;AACX;AAEA,IAAM,eAAe;AAAA,EACnB,IAAI,SAAS,MAAM;AACjB,QAAI,SAAS,aAAc,QAAO;AAClC,QAAI,SAAS,OAAO,YAAa,QAAO,MAAM;AAC9C,QAAI,OAAO,SAAS,SAAU,QAAO;AACrC,WAAO,IAAI,MAAM,MAAM,QAAW,YAAY;AAAA,EAChD;AAAA,EACA,QAAQ;AACN,WAAO,IAAI,MAAM,MAAM,QAAW,YAAY;AAAA,EAChD;AACF;AACA,IAAM,YAAY,IAAI,MAAM,MAAM,QAAW,YAAY;AAWlD,IAAM,sBAAsB;;;ACJ5B,IAAM,2DACX;;;ACwCK,IAAM,UAA+B;AAAA,EAC1C,MAAM,YAAY;AAAA,EAClB,QAAQ,YAAY;AACtB;;;AC7BA,IAAM,aAAa;AAEnB,IAAM,SAAS,MAA2B;AACxC,QAAM,YAAa,WAAsD,QACrE;AAEJ,SAAO,cAAc,SAAY,OAAO;AAC1C;AAEA,IAAM,WAAW,CAAC,UAA8B;AAC9C,MAAI,SAAS;AAEb,aAAW,QAAQ,OAAO;AACxB,cAAU,OAAO,aAAa,IAAI;AAAA,EACpC;AAEA,SAAO,KAAK,MAAM;AACpB;AAUA,IAAM,YAAY,CAAC,MAAc,UAA2B;AAC1D,MAAI,KAAK,WAAW,MAAM,QAAQ;AAChC,WAAO;AAAA,EACT;AAEA,MAAI,aAAa;AAEjB,WAAS,QAAQ,GAAG,QAAQ,KAAK,QAAQ,SAAS,GAAG;AACnD,kBAAc,KAAK,WAAW,KAAK,IAAI,MAAM,WAAW,KAAK;AAAA,EAC/D;AAEA,SAAO,eAAe;AACxB;AASO,IAAM,uBAAuB,CAClC,eACwB;AACxB,MAAI,OAAO,eAAe,YAAY,WAAW,KAAK,EAAE,WAAW,GAAG;AACpE,WAAO;AAAA,EACT;AAEA,QAAM,MAAM,WAAW,KAAK;AAI5B,MAAI,eAAiC;AAErC,QAAM,SAAS,OAAO,WAA6C;AACjE,QAAI,iBAAiB,MAAM;AACzB,aAAO;AAAA,IACT;AAEA,UAAM,UAAU,IAAI,YAAY;AAEhC,UAAM,cAAc,MAAM,OAAO;AAAA,MAC/B;AAAA,MACA,QAAQ,OAAO,GAAG;AAAA,MAClB,EAAE,MAAM,QAAQ,MAAM,UAAU;AAAA,MAChC;AAAA,MACA,CAAC,MAAM;AAAA,IACT;AAEA,UAAM,UAAU,MAAM,OAAO;AAAA,MAC3B;AAAA,MACA;AAAA,MACA,QAAQ,OAAO,UAAU;AAAA,IAC3B;AAEA,mBAAe,MAAM,OAAO;AAAA,MAC1B;AAAA,MACA;AAAA,MACA,EAAE,MAAM,QAAQ,MAAM,UAAU;AAAA,MAChC;AAAA,MACA,CAAC,MAAM;AAAA,IACT;AAEA,WAAO;AAAA,EACT;AAEA,QAAM,MAAM,OAAO,cAA8C;AAC/D,UAAM,SAAS,OAAO;AAEtB,QAAI,WAAW,MAAM;AACnB,aAAO;AAAA,IACT;AAEA,QAAI;AACF,YAAM,YAAY,MAAM,OAAO;AAAA,QAC7B;AAAA,QACA,MAAM,OAAO,MAAM;AAAA,QACnB,IAAI,YAAY,EAAE,OAAO,SAAS;AAAA,MACpC;AAEA,aAAO,SAAS,IAAI,WAAW,SAAS,CAAC;AAAA,IAC3C,QAAQ;AAGN,aAAO;AAAA,IACT;AAAA,EACF;AAEA,SAAO;AAAA,IACL,MAAM;AAAA,IACN,QAAQ,OAAO,WAAW,aAAa;AACrC,YAAM,WAAW,MAAM,IAAI,SAAS;AAEpC,aAAO,aAAa,QAAQ,UAAU,UAAU,QAAQ;AAAA,IAC1D;AAAA,EACF;AACF;A;;;;ACpKA,ICsBGA,IAAAA,CAAK,MAAM;AACb,MAAIC,KAAI,EAAE,MAAM,UAAU;AAC1B,UAAQ,EAAE,MAAV;IACC,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD,KAAK;IACL,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD,KAAK;AACJ,MAAAA,GAAE,OAAO,SAAS,EAAE,UAAUA,GAAE,QAAQD,EAAE,EAAE,KAAK;AACjD;IACD,KAAK;AACJ,MAAAC,GAAE,OAAO,UAAU,EAAE,eAAeA,GAAE,aAAa,OAAO,YAAY,OAAO,QAAQ,EAAE,UAAU,EAAE,IAAA,CAAK,CAACC,IAAGC,EAAA,MAAO,CAACD,IAAGF,EAAEG,EAAC,CAAC,CAAC,CAAC;AAC7H;IACD,KAAK;AACJ,MAAAF,GAAE,OAAO;AACT;IACD,KAAK;AACJ,MAAAA,GAAE,OAAO;AACT;IACD;AAAS,MAAAA,GAAE,OAAO;EACnB;AACA,SAAO,MAAM,QAAQ,EAAE,IAAI,MAAMA,GAAE,OAAO,EAAE,KAAK,OAAA,CAAQC,OAAM,OAAOA,MAAK,QAAQ,IAAI,EAAE,cAAc,SAAOD,GAAE,YAAY,WAAKA,cAAAA,kBAAE,EAAE,KAAK,MAAMA,GAAE,QAAQ,EAAE,YAAQA,cAAAA,kBAAE,EAAE,yBAAyB,MAAMA,GAAE,4BAA4B,EAAE,4BAA4BA;AACpQ;ADlDA,ICkDG,IAAA,CAAK,MAAM,CAACD,EAAE,CAAC,CAAC;AAAsB,EAAE;EAC1C,MAAM;EACN,YAAY;IACX,GAAG,EAAE,MAAM,SAAS;IACpB,GAAG,EAAE,MAAM,SAAS;EACrB;AACD,CAAC;AAtDD,IEHI,IAAoB,0BAAS,GAAG;AACnC,SAAO,EAAE,QAAQ,SAAS,EAAE,UAAU,WAAW,EAAE,QAAQ,SAAS,EAAE,UAAU,WAAW,EAAE,WAAW,YAAY,EAAE,OAAO,QAAQ,EAAE,YAAY,aAAa,EAAE,SAAS,UAAU,EAAE,QAAQ,SAAS,EAAE,YAAY,aAAa,EAAE,QAAQ,SAAS,EAAE,iBAAiB,kBAAkB,EAAE,eAAe,gBAAgB,EAAE,SAAS,UAAU,EAAE,UAAU,WAAW,EAAE,SAAS,UAAU,EAAE,WAAW,YAAY,EAAE,SAAS,UAAU,EAAE,WAAW,YAAY,EAAE,WAAW,YAAY,EAAE,YAAY,aAAa,EAAE,SAAS,UAAU,EAAE,OAAO,QAAQ,EAAE,YAAY,aAAa,EAAE,OAAO,QAAQ;AAC3kB,GAAE,CAAC,CAAC;AEWH,EAAE,MACF,EAAE,OACF,EAAE,SACF,EAAE,MACF,EAAE,WACF,EAAE,QACF,EAAE,SACF,EAAE,UACF,EAAE,WACF,EAAE,QACF,EAAE;AArBH,IAsBuC,IAAI;AAtB3C,IAsB6D,IAAI;AAtBjE,ICEa,IAAqB,OAA0B,EAC1D,OAAA,GACA,WAAAI,IACA,QAAAC,GAAA,MAKoB;AACpB,MAAMC,KAAS,QAAQ,IAAI,CAAA,GACrB,IAAc,QAAQ,IAAI,CAAA;AAEhC,MAAI,CAACA,MAAU,CAAC,EACd,OAAU,MACR,GAAGD,EAAA,wCACE,CAAA,QAA4B,CAAA,GACnC;AAGF,MAAM,IAAW,MAAM,MAAM,GAAGC,EAAA,aAAmB;IACjD,QAAQ;IACR,SAAS;MACP,gBAAgB;MAChB,eAAe,UAAU,CAAA;IAC3B;IACA,MAAM,KAAK,UAAU;MAAE,OAAA;MAAO,WAAAF;IAAU,CAAC;EAC3C,CAAC;AAED,MAAI,CAAC,EAAS,GACZ,OAAU,MACR,GAAGC,EAAA,mBAAyB,EAAS,MAAA,IAAU,EAAS,UAAA,EAC1D;AAGF,MAAM,IAAQ,MAAM,EAAS,KAAK;AAKlC,MAAI,EAAK,UAAU,EAAK,OAAO,SAAS,EACtC,OAAU,MACR,GAAGA,EAAA,cAAoB,EAAK,OAAO,IAAA,CAAKE,OAAUA,GAAM,OAAO,EAAE,KAAK,IAAI,CAAA,EAC5E;AAGF,MAAI,CAAC,EAAK,KACR,OAAU,MAAM,GAAGF,EAAA,wCAA8C;AAGnE,SAAO,EAAK;AACd;ADpDA,IOIM,IAA0B;APJhC,IOcM,IAA6B;APdnC,IOwBM,IAAgC;APxBtC,IO8BM,IAAgD;AP9BtD,IOoCa,IAAK;EAChB,MAAM,IACJ,GACAG,IACwB;AACxB,QAAM,EAAE,aAAAC,GAAA,IAAgB,MAAM,EAG5B;MACA,OAAO;MACP,WAAW;QAAE,KAAA;QAAK,OAAOD,IAAS,SAAS;MAA4B;MACvE,QAAQ;IACV,CAAC;AAED,WAAQC,IAAa,SAAS;EAChC;EAEA,MAAM,IACJ,GACAD,IACAC,IACe;AACf,UAAM,EAKJ;MACA,OAAO;MACP,WAAW,EACT,OAAO;QACL,KAAA;QACA,OAAAD;QACA,OAAOC,IAAS,SAAS;MAC3B,EACF;MACA,QAAQ;IACV,CAAC;EACH;EAEA,MAAM,OAAO,GAAaD,IAAuC;AAC/D,QAAM,EAAE,mBAAAC,GAAA,IAAsB,MAAM,EAGlC;MACA,OAAO;MACP,WAAW;QAAE,KAAA;QAAK,OAAOD,IAAS,SAAS;MAA4B;MACvE,QAAQ;IACV,CAAC;AAED,WAAOC;EACT;AACF;;;AEzBO,IAAM,qBAAqB;AAE3B,IAAM,sBAAsB,KAAK,kBAAkB;AAoCnD,IAAM,+BAA+B;AA8CrC,IAAM,8BAA8B;AA2EpC,IAAM,2BAA2B;AAMjC,IAAM,2BAA2B;;;ACpNjC,IAAM,gBAAgB,CAC3B,UAEA,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AAO9D,IAAM,sBAAsB,CACjC,SACA,mBAC8B;AAC9B,MAAI,CAAC,cAAc,OAAO,GAAG;AAC3B,WAAO,CAAC;AAAA,EACV;AAEA,QAAM,aAAa,QAAQ,cAAc;AAEzC,MAAI,CAAC,cAAc,UAAU,GAAG;AAC9B,WAAO,CAAC;AAAA,EACV;AAEA,QAAM,QAAQ,WAAW,OAAO;AAEhC,MAAI,CAAC,MAAM,QAAQ,KAAK,GAAG;AACzB,WAAO,CAAC;AAAA,EACV;AAEA,SAAO,MAAM,QAAQ,CAAC,SAAoC;AACxD,QAAI,CAAC,cAAc,IAAI,GAAG;AACxB,aAAO,CAAC;AAAA,IACV;AAEA,UAAM,OAAO,KAAK,MAAM;AAExB,WAAO,cAAc,IAAI,IAAI,CAAC,IAAI,IAAI,CAAC;AAAA,EACzC,CAAC;AACH;AAGO,IAAM,oBAAoB,CAC/B,YACmC;AACnC,MAAI,SAAyC;AAC7C,MAAI,YAA2B;AAE/B,aAAW,UAAU,SAAS;AAC5B,UAAM,YAAY,OAAO,WAAW;AACpC,UAAM,MAAM,OAAO,cAAc,WAAW,YAAY;AAExD,QAAI,WAAW,QAAQ,cAAc,QAAQ,MAAM,WAAW;AAC5D,eAAS;AACT,kBAAY;AAAA,IACd;AAAA,EACF;AAEA,SAAO;AACT;AAOO,IAAM,gBAAgB,CAC3B,OACA,WACS;AAET,UAAQ,IAAI,KAAK,UAAU,EAAE,KAAK,qBAAqB,OAAO,GAAG,OAAO,CAAC,CAAC;AAC5E;AAEO,IAAM,gBAAgB,CAAC,UAA2B;AACvD,MAAI,iBAAiB,OAAO;AAC1B,WAAO,GAAG,MAAM,IAAI,KAAK,MAAM,OAAO;AAAA,EACxC;AAEA,MAAI,OAAO,UAAU,UAAU;AAC7B,WAAO;AAAA,EACT;AAEA,MAAI;AACF,WAAO,KAAK,UAAU,KAAK,KAAK;AAAA,EAClC,QAAQ;AACN,WAAO;AAAA,EACT;AACF;;;ACxDA,IAAM,QAAQ,EAAE,OAAO,YAAY;AAEnC,IAAM,WAAW,CAAC,UAChB,OAAO,UAAU,YAAY,UAAU,QAAQ,CAAC,MAAM,QAAQ,KAAK;AA0HrE,IAAM,uBAAuB,CAAC,UAA6C;AACzE,MAAI,CAAC,SAAS,KAAK,GAAG;AACpB,WAAO;AAAA,EACT;AAEA,QAAM,EAAE,UAAU,aAAa,SAAS,YAAY,MAAM,IAAI;AAE9D,MAAI,OAAO,aAAa,YAAY,CAAC,SAAS,WAAW,GAAG;AAC1D,WAAO;AAAA,EACT;AAEA,MAAI,OAAO,YAAY,oBAAoB,MAAM,UAAU;AACzD,WAAO;AAAA,EACT;AAOA,MACE,OAAO,YAAY,YACnB,QAAQ,WAAW,KACnB,OAAO,eAAe,YACtB,OAAO,UAAU,UACjB;AACA,WAAO;AAAA,EACT;AAEA,SAAO;AAAA,IACL;AAAA,IACA;AAAA,IACA;AAAA,IACA;AAAA,IACA;AAAA,EACF;AACF;AAEO,IAAM,qBAA2C;AAAA,EACtD,iBAAiB,YAAY;AAC3B,QAAI;AACF,aAAO;AAAA,QACL,MAAM,EAAG,IAAa,0BAA0B,KAAK;AAAA,MACvD;AAAA,IACF,SAAS,OAAO;AACd,oBAAc,iCAAiC;AAAA,QAC7C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAED,aAAO;AAAA,IACT;AAAA,EACF;AAAA,EAEA,kBAAkB,OAAO,UAAU;AACjC,QAAI;AACF,YAAM,EAAG,IAAI,0BAA0B,OAAO,KAAK;AAAA,IACrD,SAAS,OAAO;AACd,oBAAc,kCAAkC;AAAA,QAC9C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAAA,EACF;AAAA,EAEA,kBAAkB,YAAY;AAC5B,QAAI;AAMF,YAAM,EAAG,IAAI,0BAA0B,MAAM,KAAK;AAAA,IACpD,SAAS,OAAO;AACd,oBAAc,kCAAkC;AAAA,QAC9C,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAAA,EACF;AAAA,EAEA,yBAAyB,OAAO,UAAU;AACxC,QAAI;AACF,YAAM,EAAG,IAAI,0BAA0B,OAAO,KAAK;AAAA,IACrD,SAAS,OAAO;AACd,oBAAc,oCAAoC;AAAA,QAChD,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAAA,EACF;AACF;AAUO,IAAM,sBAA6C;AAAA,EACxD,MAAM,MAAM,mBAAmB,gBAAgB;AACjD;;;AC1OA,IAAM,UAAU,KAAK,KAAK;AAGnB,IAAM,uBAAuB,KAAK;AAMlC,IAAM,iCAAiC,KAAK;AAc5C,IAAM,aAAa,CACxB,UACA,QACkB;AAClB,MAAI,OAAO,aAAa,YAAY,SAAS,WAAW,GAAG;AACzD,WAAO;AAAA,EACT;AAEA,QAAM,WAAW,KAAK,MAAM,QAAQ;AAEpC,MAAI,OAAO,MAAM,QAAQ,GAAG;AAC1B,WAAO;AAAA,EACT;AAEA,SAAO,KAAK,IAAI,GAAG,IAAI,QAAQ,IAAI,QAAQ;AAC7C;AAQO,IAAM,mBAAmB,CAAC,UAAkC;AACjE,MAAI,QAAQ,sBAAsB;AAChC,WAAO;AAAA,EACT;AAEA,MAAI,QAAQ,gCAAgC;AAC1C,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAMO,IAAM,gBAAgB,CAC3B,UACA,QACiF;AACjF,QAAM,QAAQ,WAAW,UAAU,GAAG;AAEtC,SAAO;AAAA,IACL,WAAW,UAAU,OAAO,OAAO,iBAAiB,KAAK;AAAA,IACzD;AAAA,EACF;AACF;;;ACzDA,IAAM,YAAY,CAAC,OAAgB,SAAmC;AACpE,MAAI,MAAM,QAAQ,KAAK,GAAG;AAGxB,QAAI,KAAK,IAAI,KAAK,GAAG;AACnB,YAAM,IAAI,UAAU,oBAAoB;AAAA,IAC1C;AAEA,SAAK,IAAI,KAAK;AACd,UAAM,SAAS,MAAM,IAAI,CAAC,UAAU,UAAU,OAAO,IAAI,CAAC;AAC1D,SAAK,OAAO,KAAK;AAEjB,WAAO;AAAA,EACT;AAEA,MAAI,OAAO,UAAU,YAAY,UAAU,MAAM;AAQ/C,QAAI,KAAK,IAAI,KAAK,GAAG;AACnB,YAAM,IAAI,UAAU,oBAAoB;AAAA,IAC1C;AAEA,SAAK,IAAI,KAAK;AAEd,UAAM,SAAS;AACf,UAAM,SAAkC,CAAC;AAEzC,eAAW,OAAO,OAAO,KAAK,MAAM,EAAE,KAAK,GAAG;AAC5C,YAAM,QAAQ,OAAO,GAAG;AAMxB,UAAI,UAAU,QAAW;AACvB,eAAO,GAAG,IAAI,UAAU,OAAO,IAAI;AAAA,MACrC;AAAA,IACF;AAEA,SAAK,OAAO,KAAK;AAEjB,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAWO,IAAM,eAAe,CAAC,UAAkC;AAC7D,MAAI;AACF,UAAM,aAAa,KAAK,UAAU,UAAU,OAAO,oBAAI,QAAQ,CAAC,CAAS;AAEzE,WAAO,OAAO,eAAe,WAAW,aAAa;AAAA,EACvD,QAAQ;AACN,WAAO;AAAA,EACT;AACF;;;AC9EO,IAAM,mBAAmB,CAC9B,iBACuB;AAAA,EACvB,qBAAqB,YAAY,oBAAoB;AAAA,EACrD,kBAAkB,YAAY,iBAAiB;AAAA,EAC/C,qBAAqB,YAAY,oBAAoB;AAAA,EACrD,mBAAmB,YAAY,kBAAkB;AAAA,EACjD,kBAAkB,OAAO,KAAK,YAAY,gBAAgB,EAAE;AAC9D;AAUO,IAAM,uBAAuB,CAClC,QACA,SACsB;AAAA,EACtB,QAAQ;AAAA,EACR;AAAA,EACA,QAAQ;AAAA,EACR,oBAAoB;AAAA,EACpB,UAAU;AAAA,EACV,aAAa;AAAA,EACb,WAAW,IAAI,YAAY;AAAA,EAC3B,YAAY;AAAA,EACZ,OAAO;AAAA,EACP,QAAQ;AACV;AAEO,IAAM,kBAAkB,CAC7B,OACA,QACAC,aACA,SACsB;AAAA,EACtB,QAAQ;AAAA,EACR,QAAQ;AAAA,EACR;AAAA,EACA,oBAAoB,MAAM,YAAY;AAAA,EACtC,UAAU,MAAM,YAAY,SAAS,SAAS,IAAI,MAAM,YAAY,WAAW;AAAA,EAC/E,aAAa,MAAM;AAAA,EACnB,WAAW,IAAI,YAAY;AAAA,EAC3B,YAAAA;AAAA,EACA,OAAO,MAAM;AAAA,EACb,QAAQ,iBAAiB,MAAM,WAAW;AAC5C;AAMO,IAAM,yBAAyB,KAAK,KAAK,KAAK;AAyC9C,IAAM,qBAAqB,CAChC,UACwB;AACxB,MAAI,MAAM,WAAW,MAAM;AACzB,WAAO;AAAA,MACL,OAAO,qBAAqB,mBAAmB,MAAM,GAAG;AAAA,MACxD,aAAa;AAAA,IACf;AAAA,EACF;AAEA,QAAM,EAAE,MAAM,IAAI,cAAc,MAAM,OAAO,UAAU,MAAM,GAAG;AAKhE,MAAI,UAAU,QAAQ,SAAS,wBAAwB;AACrD,WAAO;AAAA,MACL,OAAO;AAAA,QACL,GAAG,qBAAqB,SAAS,MAAM,GAAG;AAAA,QAC1C,YAAY;AAAA,QACZ,oBAAoB,MAAM,OAAO,YAAY;AAAA,QAC7C,OAAO,MAAM,OAAO;AAAA,MACtB;AAAA,MACA,aAAa;AAAA,IACf;AAAA,EACF;AAEA,SAAO;AAAA,IACL,OAAO;AAAA,MACL,MAAM;AAAA,MACN,UAAU,IAAI,SAAS;AAAA,MACvB;AAAA,MACA,MAAM;AAAA,IACR;AAAA,IACA,aAAa,MAAM,OAAO;AAAA,EAC5B;AACF;;;AC9GO,IAAM,wBAAwB,CACnC,SAEA,aAAa;AAAA,EACX,UAAU,KAAK;AAAA,EACf,YAAY,KAAK;AAAA,EACjB,OAAO,KAAK;AAAA,EACZ,aAAa,KAAK;AACpB,CAAC;;;AC3DI,IAAM,yBAAyD;AAAA,EACpE;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UAAU;AAAA,IACV,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AAAA,EACA;AAAA,IACE,KAAK;AAAA,IACL,OAAO;AAAA,IACP,UACE;AAAA,IACF,MAAM;AAAA,IACN,WAAW;AAAA,EACb;AACF;AAEA,IAAM,cAAwD,IAAI;AAAA,EAChE,uBAAuB,IAAI,CAAC,SAAS,CAAC,KAAK,KAAK,IAAI,CAAC;AACvD;AAwBO,IAAM,2BAA2B,CAAC,QACvC,+BAA+B,GAAG;AAE7B,IAAM,+BAET,OAAO;AAAA,EACT,OAAO;AAAA,IACL,uBAAuB,IAAI,CAAC,SAAS;AAAA,MACnC,KAAK;AAAA,MACL,yBAAyB,KAAK,GAAG;AAAA,IACnC,CAAC;AAAA,EACH;AACF;;;ACxEO,IAAM,wBAAsC;AAAA,EACjD,aAAa,CAAC,eAAe,gBAAgB,WAAW,aAAa;AAAA,EACrE,UAAU,CAAC,YAAY,oBAAoB,QAAQ;AAAA,EACnD,QAAQ,CAAC,UAAU,WAAW,0BAA0B,gBAAgB;AAAA,EACxE,eAAe,CAAC,aAAa,iBAAiB,qBAAqB,aAAa;AAAA,EAChF,aAAa,CAAC,QAAQ,YAAY,eAAe,WAAW;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,EAe5D,UAAU,CAAC,YAAY,SAAS,MAAM;AAAA,EACtC,WAAW,CAAC,aAAa,gBAAgB;AAAA,EACzC,OAAO,CAAC,UAAU,SAAS,uBAAuB,WAAW;AAAA,EAC7D,OAAO,CAAC,UAAU,SAAS,6BAA6B,QAAQ;AAAA,EAChE,gBAAgB,CAAC,kBAAkB,cAAc,aAAa,WAAW;AAAA;AAAA;AAAA;AAAA;AAAA;AAAA,EAOzE,YAAY,CAAC,sBAAsB;AAAA,EACnC,mBAAmB,CAAC,6BAA6B;AAAA,EAEjD,UAAU,CAAC,YAAY,gBAAgB,eAAe,cAAc;AACtE;AAGO,IAAM,cAAyB;AAAA,EACpC,YAAY,CAAC;AAAA,EACb,SAAS,CAAC;AAAA,EACV,WAAW,CAAC;AACd;AAOO,IAAM,gBAAwC;AAAA,EACnD,EAAE,IAAI,aAAa,OAAO,aAAa,UAAU,GAAG;AAAA,EACpD,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,GAAG;AAAA,EAC1C,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,GAAG;AAAA,EAC1C,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,EAAE;AAC3C;AAGO,IAAM,yBAAyB;AAE/B,IAAM,0BAA0B;AAEhC,IAAM,gCAAmD;AAAA,EAC9D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAEO,IAAM,4BAA+C;AAAA,EAC1D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAEO,IAAM,iCAAoD;AAAA,EAC/D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAGO,IAAM,qBAAwC;AAAA,EACnD;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;;;AC/JA,IAAM,iBAAiB;AAGhB,IAAM,eAAe,CAAC,WAAgC;AAC3D,MAAI,CAAC,cAAc,MAAM,GAAG;AAC1B,WAAO,EAAE,IAAI,MAAM,QAAQ,CAAC,EAAE;AAAA,EAChC;AAEA,QAAM,KAAK,OAAO,OAAO,IAAI,MAAM,WAAW,OAAO,IAAI,IAAI;AAE7D,SAAO,EAAE,IAAI,QAAQ,OAAO;AAC9B;AAEO,IAAM,gBAAgB,CAC3B,UAEA,OAAO,UAAU,YACjB,UAAU,QACV,CAAC,MAAM,QAAQ,KAAK,KACpB,EAAE,iBAAiB;AAOd,IAAM,YAAY,CAAC,QAAiB,SAA0B;AACnE,QAAM,WAAW,KAAK,MAAM,GAAG,EAAE,OAAO,CAAC,YAAY,QAAQ,SAAS,CAAC;AAEvE,MAAI,SAAkB;AAEtB,aAAW,WAAW,UAAU;AAC9B,QAAI,WAAW,QAAQ,WAAW,QAAW;AAC3C,aAAO;AAAA,IACT;AAEA,QAAI,MAAM,QAAQ,MAAM,GAAG;AACzB,YAAM,QAAQ,OAAO,OAAO;AAC5B,eAAS,OAAO,UAAU,KAAK,IAAI,OAAO,KAAK,IAAI;AACnD;AAAA,IACF;AAEA,QAAI,CAAC,cAAc,MAAM,GAAG;AAC1B,aAAO;AAAA,IACT;AAEA,QAAI,WAAW,QAAQ;AACrB,eAAS,OAAO,OAAO;AACvB;AAAA,IACF;AAEA,UAAM,UAAU,QAAQ,YAAY;AACpC,UAAM,aAAa,OAAO,KAAK,MAAM,EAAE;AAAA,MACrC,CAAC,QAAQ,IAAI,YAAY,MAAM;AAAA,IACjC;AAEA,aAAS,eAAe,SAAY,SAAY,OAAO,UAAU;AAAA,EACnE;AAEA,SAAO;AACT;AAGO,IAAM,eAAe,CAAC,OAAgB,QAAQ,MAAgB;AACnE,MAAI,QAAQ,gBAAgB;AAC1B,WAAO,CAAC;AAAA,EACV;AAEA,MAAI,OAAO,UAAU,UAAU;AAC7B,UAAM,UAAU,MAAM,KAAK;AAC3B,WAAO,QAAQ,SAAS,IAAI,CAAC,OAAO,IAAI,CAAC;AAAA,EAC3C;AAEA,MAAI,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK,GAAG;AACvD,WAAO,CAAC,OAAO,KAAK,CAAC;AAAA,EACvB;AAEA,MAAI,MAAM,QAAQ,KAAK,GAAG;AACxB,WAAO,MAAM,QAAQ,CAAC,UAAU,aAAa,OAAO,QAAQ,CAAC,CAAC;AAAA,EAChE;AAEA,MAAI,iBAAiB,MAAM;AACzB,WAAO,OAAO,MAAM,MAAM,QAAQ,CAAC,IAAI,CAAC,IAAI,CAAC,MAAM,YAAY,CAAC;AAAA,EAClE;AAEA,MAAI,cAAc,KAAK,GAAG;AACxB,WAAO,OAAO,KAAK,KAAK,EAAE;AAAA,MAAQ,CAAC,QACjC,aAAa,MAAM,GAAG,GAAG,QAAQ,CAAC;AAAA,IACpC;AAAA,EACF;AAEA,SAAO,CAAC;AACV;AAEA,IAAM,eAAe,CAAC,UACpB,UAAU,QACV,UAAU,UACT,OAAO,UAAU,YAAY,MAAM,KAAK,EAAE,WAAW,KACrD,MAAM,QAAQ,KAAK,KAAK,MAAM,WAAW,KACzC,OAAO,UAAU,YAAY,OAAO,MAAM,KAAK,KAC/C,cAAc,KAAK,KAAK,aAAa,KAAK,EAAE,WAAW;AAYnD,IAAM,gBAAgB,CAC3B,OACA,QAA2B,uBACf,MAAM,SAAS,MAAM,KAAK,EAAE,YAAY,CAAC;AAEhD,IAAM,gBAAgB,CAAC,UAAkC;AAC9D,MAAI,OAAO,UAAU,UAAU;AAC7B,WAAO,OAAO,SAAS,KAAK,IAAI,QAAQ;AAAA,EAC1C;AAEA,MAAI,OAAO,UAAU,WAAW;AAC9B,WAAO;AAAA,EACT;AAEA,QAAM,SAAS,aAAa,KAAK;AAEjC,aAAW,QAAQ,QAAQ;AAEzB,UAAM,UAAU,KAAK,QAAQ,UAAU,EAAE;AACzC,UAAM,QAAQ,gBAAgB,KAAK,OAAO;AAE1C,QAAI,UAAU,MAAM;AAClB,YAAM,SAAS,OAAO,MAAM,CAAC,CAAC;AAE9B,UAAI,OAAO,SAAS,MAAM,GAAG;AAC3B,eAAO;AAAA,MACT;AAAA,IACF;AAAA,EACF;AAEA,SAAO;AACT;AAEO,IAAM,cAAc,CAAC,UAAgC;AAC1D,MAAI,iBAAiB,MAAM;AACzB,WAAO,OAAO,MAAM,MAAM,QAAQ,CAAC,IAAI,OAAO;AAAA,EAChD;AAEA,MAAI,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK,GAAG;AACvD,UAAM,YAAY,IAAI,KAAK,KAAK;AAChC,WAAO,OAAO,MAAM,UAAU,QAAQ,CAAC,IAAI,OAAO;AAAA,EACpD;AAEA,QAAM,SAAS,aAAa,KAAK;AAEjC,aAAW,QAAQ,QAAQ;AACzB,UAAM,SAAS,IAAI,KAAK,IAAI;AAE5B,QAAI,CAAC,OAAO,MAAM,OAAO,QAAQ,CAAC,GAAG;AACnC,aAAO;AAAA,IACT;AAAA,EACF;AAEA,SAAO;AACT;AAEA,IAAM,gBAAgB,oBAAI,IAAI;AAAA,EAC5B;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF,CAAC;AAED,IAAM,eAAe,oBAAI,IAAI;AAAA,EAC3B;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF,CAAC;AAEM,IAAM,iBAAiB,CAAC,UAAmC;AAChE,MAAI,OAAO,UAAU,WAAW;AAC9B,WAAO;AAAA,EACT;AAEA,MAAI,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK,GAAG;AACvD,WAAO,UAAU;AAAA,EACnB;AAEA,QAAM,SAAS,aAAa,KAAK;AAEjC,aAAW,QAAQ,QAAQ;AACzB,UAAM,QAAQ,KAAK,YAAY;AAE/B,QAAI,cAAc,IAAI,KAAK,GAAG;AAC5B,aAAO;AAAA,IACT;AAEA,QAAI,aAAa,IAAI,KAAK,GAAG;AAC3B,aAAO;AAAA,IACT;AAAA,EACF;AAEA,SAAO;AACT;AAEA,IAAM,gBAAgB,CAAC,UAA2B;AAChD,MAAI,OAAO,UAAU,WAAW;AAC9B,WAAO,QAAQ,SAAS;AAAA,EAC1B;AAEA,QAAM,SAAS,aAAa,KAAK;AAEjC,MAAI,OAAO,WAAW,GAAG;AACvB,WAAO;AAAA,EACT;AAEA,SAAO,OAAO,MAAM,GAAG,CAAC,EAAE,KAAK,IAAI;AACrC;AAaO,IAAM,oBAAoB,CAC/B,MACA,YACgB;AAChB,QAAM,OAAO,oBAAI,IAAoC;AAErD,QAAM,gBAAgB,CAAC,QAAyC;AAC9D,UAAM,aAAa,QAAQ,GAAG;AAC9B,WAAO,MAAM,QAAQ,UAAU,IAAI,aAAa,CAAC;AAAA,EACnD;AAEA,QAAM,aAAa,CAAC,QAAoC;AACtD,UAAM,aAAa,cAAc,GAAG;AAEpC,WAAO,WAAW,IAAI,CAAC,SAAS;AAC9B,YAAM,QAAQ,UAAU,KAAK,QAAQ,IAAI;AAEzC,aAAO;AAAA,QACL,UAAU;AAAA,QACV;AAAA,QACA;AAAA,QACA,SAAS,CAAC,aAAa,KAAK;AAAA,MAC9B;AAAA,IACF,CAAC;AAAA,EACH;AAEA,QAAM,UAAU,CAAC,QAAkC;AACjD,UAAM,aAAa,cAAc,GAAG;AACpC,UAAM,QAAQ,WAAW,GAAG,EAAE,KAAK,CAAC,UAAU,MAAM,OAAO;AAE3D,QAAI,UAAU,QAAW;AACvB,aAAO;AAAA,IACT;AAEA,WAAO,EAAE,UAAU,MAAM,YAAY,OAAO,QAAW,SAAS,MAAM;AAAA,EACxE;AAEA,QAAM,SAAS,CAAC,KAAmB,eAAiC;AAClE,SAAK,IAAI,KAAK;AAAA,MACZ;AAAA,MACA,UAAU,WAAW;AAAA,MACrB,YAAY,WAAW;AAAA,MACvB,SAAS,WAAW;AAAA,MACpB,SAAS,WAAW,UAAU,cAAc,WAAW,KAAK,IAAI;AAAA,IAClE,CAAC;AAAA,EACH;AAEA,QAAM,eAAe,CAAC,QAAkC;AACtD,UAAM,aAAa,QAAQ,GAAG;AAC9B,WAAO,KAAK,UAAU;AACtB,WAAO;AAAA,EACT;AAEA,SAAO;AAAA,IACL,MAAM,CAAC,QAAQ;AACb,YAAM,SAAS,aAAa,aAAa,GAAG,EAAE,KAAK;AACnD,aAAO,OAAO,SAAS,IAAI,OAAO,KAAK,GAAG,IAAI;AAAA,IAChD;AAAA,IACA,UAAU,CAAC,QAAQ,aAAa,aAAa,GAAG,EAAE,KAAK;AAAA,IACvD,QAAQ,CAAC,QAAQ,cAAc,aAAa,GAAG,EAAE,KAAK;AAAA,IACtD,MAAM,CAAC,QAAQ,YAAY,aAAa,GAAG,EAAE,KAAK;AAAA,IAClD,YAAY,CAAC,QAAQ;AACnB,YAAM,MAAM,WAAW,GAAG;AAC1B,YAAM,UAAU,IAAI,OAAO,CAAC,UAAU,MAAM,OAAO;AACnD,YAAM,SAAS,QAAQ,KAAK,CAAC,UAAU,eAAe,MAAM,KAAK,MAAM,IAAI;AAE3E,UAAI,WAAW,QAAW;AACxB,eAAO,KAAK,MAAM;AAClB,eAAO;AAAA,MACT;AAEA,YAAM,QAAQ,QAAQ,CAAC;AAEvB,UAAI,UAAU,QAAW;AACvB,eAAO,KAAK,KAAK;AACjB,eAAO,eAAe,MAAM,KAAK,MAAM,OAAO,OAAO;AAAA,MACvD;AAEA,aAAO,KAAK;AAAA,QACV,UAAU;AAAA,QACV,YAAY,cAAc,GAAG;AAAA,QAC7B,OAAO;AAAA,QACP,SAAS;AAAA,MACX,CAAC;AAED,aAAO;AAAA,IACT;AAAA,IACA,cAAc,MAAM,MAAM,KAAK,KAAK,OAAO,CAAC;AAAA,EAC9C;AACF;;;ACjWO,IAAM,wBAAqC;AAAA,EAChD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,aAAa;AAAA,EAErB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,OAAO,KAAK,KAAK,aAAa;AAEpC,QAAI,SAAS,MAAM;AACjB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,QAAI,cAAc,MAAM,OAAO,iBAAiB,KAAK,KAAK,KAAK,EAAE,SAAS,GAAG;AAC3E,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,IAAI;AAAA,QACrB,QAAQ;AAAA,QACR,QAAQ,EAAE,aAAa,KAAK;AAAA,MAC9B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,6BAA6B,IAAI;AAAA,MAC9C,QAAQ,EAAE,aAAa,KAAK;AAAA,IAC9B;AAAA,EACF;AACF;;;AC2BA,IAAM,iBAAiB,CAAC,SACtB,KAAK,KAAK,EAAE,YAAY,EAAE,QAAQ,UAAU,GAAG;AAEjD,IAAM,cAAc,CAClB,gBACA,cACA,WACgB;AAChB,QAAM,UACJ,WAAW,OAAO,KAAK,4BAA4B,eAAe,MAAM,CAAC;AAE3E,QAAM,cAAc,iBAChB,eACE,6GAA6G,OAAO,6CACpH,sDAAsD,OAAO,6CAC/D;AAEJ,SAAO;AAAA,IACL,SAAS;AAAA,IACT;AAAA,IACA,QAAQ,iBACJ,+MACA;AAAA,IACJ,QAAQ;AAAA,MACN,YAAY;AAAA,MACZ,wBAAwB;AAAA,MACxB,2BAA2B;AAAA,MAC3B,mBAAmB;AAAA;AAAA;AAAA;AAAA,MAInB,gBAAgB;AAAA,IAClB;AAAA,EACF;AACF;AAEO,IAAM,uBAAoC;AAAA,EAC/C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,cAAc,qBAAqB,UAAU;AAAA,EAErD,UAAU,CAAC,EAAE,KAAK,MAAM;AAEtB,UAAM,iBAAiB,KAAK,WAAW,YAAY;AACnD,UAAM,oBAAoB,KAAK,KAAK,mBAAmB;AAEvD,UAAM,WAAW,KAAK,WAAW,UAAU;AAE3C,UAAM,iBAAiB,mBAAmB,QAAQ,sBAAsB;AACxE,UAAM,eAAe,aAAa;AAElC,QAAI,kBAAkB,cAAc;AAClC,aAAO,YAAY,gBAAgB,cAAc,iBAAiB;AAAA,IACpE;AAIA,QAAI,mBAAmB,QAAQ,aAAa,MAAM;AAChD,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,QACF,QAAQ;AAAA,UACN,YAAY;AAAA,UACZ,wBAAwB;AAAA,UACxB,2BAA2B;AAAA,UAC3B,mBAAmB;AAAA,UACnB,gBAAgB;AAAA,UAChB,0BAA0B;AAAA,QAC5B;AAAA,MACF;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aACE,mBAAmB,QACf,kGACA;AAAA,MACN,QAAQ;AAAA,QACN,YAAY;AAAA,QACZ,wBAAwB;AAAA,QACxB,2BAA2B;AAAA,QAC3B,mBAAmB;AAAA,QACnB,gBAAgB;AAAA,QAChB,0BAA0B;AAAA,MAC5B;AAAA,IACF;AAAA,EACF;AACF;;;AClKO,IAAM,YAAY,CAAC,UACxB,MAAM,KAAK,EAAE,YAAY,EAAE,QAAQ,QAAQ,GAAG;AAEhD,IAAM,iBAAiB,CAAC,UACtB,MAAM,QAAQ,uBAAuB,MAAM;AAyBtC,IAAM,kBAAkB,CAAC,UAAkB,YAA6B;AAC7E,QAAM,SAAS,UAAU,OAAO;AAEhC,MAAI,OAAO,WAAW,GAAG;AACvB,WAAO;AAAA,EACT;AAEA,QAAM,UAAU,IAAI;AAAA,IAClB,sBAAsB,eAAe,MAAM,CAAC;AAAA,IAC5C;AAAA,EACF;AAEA,SAAO,QAAQ,KAAK,UAAU,QAAQ,CAAC;AACzC;AAEO,IAAM,oBAAoB,CAC/B,UACA,aACkB,SAAS,KAAK,CAAC,YAAY,gBAAgB,UAAU,OAAO,CAAC,KAAK;AAG/E,IAAM,cAAc,CACzB,QACA,YACkB;AAClB,QAAM,aAAa,IAAI,IAAI,QAAQ,IAAI,SAAS,CAAC;AAEjD,SAAO,OAAO,KAAK,CAAC,UAAU,WAAW,IAAI,UAAU,KAAK,CAAC,CAAC,KAAK;AACrE;AAEA,IAAM,gBACJ;AAQK,IAAM,aAAa,CAAC,QAAoC;AAC7D,QAAM,UAAU,IAAI,KAAK;AAEzB,MAAI,QAAQ,WAAW,KAAK,QAAQ,SAAS,KAAK;AAChD,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,cAAc,KAAK,OAAO,GAAG;AAChC,WAAO;AAAA,EACT;AAEA,QAAM,YAAY,QAAQ,YAAY,GAAG;AACzC,QAAM,YAAY,QAAQ,MAAM,GAAG,SAAS;AAC5C,QAAM,SAAS,QAAQ,MAAM,YAAY,CAAC;AAE1C,MAAI,UAAU,SAAS,IAAI;AACzB,WAAO;AAAA,EACT;AAEA,SAAO,EAAE,SAAS,WAAW,UAAU,YAAY,GAAG,QAAQ,OAAO,YAAY,EAAE;AACrF;AAGO,IAAM,iBAAiB,CAAC,cAA8B;AAC3D,QAAM,aAAa,UAAU,MAAM,GAAG,EAAE,CAAC,KAAK;AAC9C,SAAO,WAAW,QAAQ,WAAW,EAAE;AACzC;AAEO,IAAM,uBAAuB;AAE7B,IAAM,cAAc,CAAC,SAAe,WACxC,MAAM,QAAQ,IAAI,QAAQ,QAAQ,KAAK;AAEnC,IAAM,UAAU,CAAC,OAAe,aAA6B;AAClE,QAAM,SAAS,MAAM;AACrB,SAAO,KAAK,MAAM,QAAQ,MAAM,IAAI;AACtC;AAEO,IAAM,UAAU,CAAC,UAA0B;AAChD,MAAI,CAAC,OAAO,SAAS,KAAK,GAAG;AAC3B,WAAO;AAAA,EACT;AAEA,SAAO,KAAK,IAAI,GAAG,KAAK,IAAI,GAAG,KAAK,CAAC;AACvC;;;AC/GO,IAAM,2BAAwC;AAAA,EACnD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,aAAa,UAAU;AAAA,EAE/B,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,YAAY,KAAK,KAAK,WAAW;AACvC,UAAM,WAAW,KAAK,KAAK,UAAU;AACrC,UAAM,UAAU,aAAa;AAE7B,QAAI,YAAY,MAAM;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,gBAAgB,kBAAkB,SAAS,OAAO,mBAAmB;AAE3E,QAAI,kBAAkB,MAAM;AAC1B,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,OAAO;AAAA,QACxB,QAAQ,EAAE,OAAO,SAAS,gBAAgB,cAAc;AAAA,MAC1D;AAAA,IACF;AAEA,UAAM,aAAa,kBAAkB,SAAS,OAAO,gBAAgB;AAErE,QAAI,eAAe,MAAM;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,QAAQ;AAAA,QACR,aAAa,IAAI,OAAO;AAAA,QACxB,QACE;AAAA,QACF,QAAQ,EAAE,OAAO,SAAS,gBAAgB,WAAW;AAAA,MACvD;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,IAAI,OAAO;AAAA,MACxB,QACE;AAAA,MACF,QAAQ,EAAE,OAAO,QAAQ;AAAA,IAC3B;AAAA,EACF;AACF;;;ACxDO,IAAM,wBAAqC;AAAA,EAChD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,OAAO;AAAA,EAEf,UAAU,CAAC,EAAE,KAAK,MAAM;AACtB,UAAM,aAAa,KAAK,SAAS,OAAO;AAExC,QAAI,WAAW,WAAW,GAAG;AAC3B,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,SAAS,WACZ,IAAI,CAAC,cAAc,WAAW,SAAS,CAAC,EACxC,KAAK,CAAC,cAAc,cAAc,IAAI;AAEzC,QAAI,WAAW,UAAa,WAAW,MAAM;AAC3C,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,WAAW,CAAC,KAAK,EAAE;AAAA,QACpC,QAAQ;AAAA,QACR,QAAQ,EAAE,OAAO,WAAW,CAAC,KAAK,KAAK;AAAA,MACzC;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,OAAO;AAAA,MAC9B,QAAQ,EAAE,OAAO,OAAO,SAAS,QAAQ,OAAO,OAAO;AAAA,IACzD;AAAA,EACF;AACF;;;ACzCO,IAAM,yBAAsC;AAAA,EACjD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,aAAa;AAAA,EAErB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,OAAO,KAAK,KAAK,aAAa;AAEpC,QAAI,SAAS,MAAM;AACjB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,QAAI,cAAc,MAAM,OAAO,iBAAiB,KAAK,CAAC,SAAS,KAAK,IAAI,GAAG;AACzE,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,IAAI;AAAA,QACrB,QAAQ;AAAA,QACR,QAAQ,EAAE,aAAa,KAAK;AAAA,MAC9B;AAAA,IACF;AAEA,UAAM,QAAQ,KACX,KAAK,EACL,MAAM,KAAK,EACX,OAAO,CAAC,SAAS,SAAS,KAAK,IAAI,CAAC;AAEvC,QAAI,MAAM,SAAS,GAAG;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,QAAQ;AAAA,QACR,aAAa,uBAAuB,IAAI;AAAA,QACxC,QAAQ;AAAA,QACR,QAAQ,EAAE,aAAa,KAAK;AAAA,MAC9B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,IAAI;AAAA,MACpB,QAAQ,EAAE,aAAa,KAAK;AAAA,IAC9B;AAAA,EACF;AACF;;;ACrDA,IAAM,aAAa;AACnB,IAAM,aAAa;AAEZ,IAAM,wBAAqC;AAAA,EAChD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,OAAO;AAAA,EAEf,UAAU,CAAC,EAAE,KAAK,MAAM;AACtB,UAAM,aAAa,KAAK,SAAS,OAAO;AAExC,QAAI,WAAW,WAAW,GAAG;AAC3B,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa;AAAA,QACb,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,SAAS,WAAW,KAAK,CAAC,cAAc;AAC5C,YAAM,WAAW,UAAU,QAAQ,eAAe,EAAE,EAAE,QAAQ,OAAO,EAAE;AAEvE,UAAI,CAAC,QAAQ,KAAK,QAAQ,GAAG;AAC3B,eAAO;AAAA,MACT;AAEA,aAAO,SAAS,UAAU,cAAc,SAAS,UAAU;AAAA,IAC7D,CAAC;AAED,QAAI,WAAW,QAAW;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,IAAI,WAAW,CAAC,KAAK,EAAE;AAAA,QACpC,QAAQ,oDAA+C,UAAU,QAAQ,UAAU;AAAA,QACnF,QAAQ,EAAE,OAAO,WAAW,CAAC,KAAK,KAAK;AAAA,MACzC;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,MAAM;AAAA,MACtB,QAAQ,EAAE,OAAO,OAAO;AAAA,IAC1B;AAAA,EACF;AACF;;;ACjDO,IAAM,yBAAsC;AAAA,EACjD,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,OAAO;AAAA,EAEf,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,aAAa,KAAK,SAAS,OAAO;AACxC,UAAM,SAAS,WACZ,IAAI,CAAC,cAAc,WAAW,SAAS,CAAC,EACxC,KAAK,CAAC,cAAc,cAAc,IAAI;AAEzC,QAAI,WAAW,UAAa,WAAW,MAAM;AAC3C,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,OAAO,eAAe,OAAO,SAAS;AAE5C,QAAI,OAAO,oBAAoB,SAAS,IAAI,GAAG;AAC7C,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,OAAO,OAAO,iBAAiB,IAAI;AAAA,QACnD,QACE;AAAA,QACF,QAAQ,EAAE,OAAO,OAAO,SAAS,SAAS,KAAK;AAAA,MACjD;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,OAAO;AAAA,MAC9B,QAAQ,EAAE,OAAO,OAAO,SAAS,SAAS,KAAK;AAAA,IACjD;AAAA,EACF;AACF;;;AC1CA,IAAM,wBAAwB;AAEvB,IAAM,oBAAiC;AAAA,EAC5C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,gBAAgB;AAAA,EAExB,UAAU,CAAC,EAAE,QAAQ,KAAK,KAAK,MAAM;AACnC,QAAI,QAAQ,MAAM;AAChB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,gBACJ,OAAO,mBAAmB,kBAAkB,OAAO;AAErD,UAAM,aAAa,KAAK,KAAK,gBAAgB;AAE7C,QAAI,eAAe,MAAM;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ,sIAAsI,aAAa;AAAA,QAC3J,QAAQ,EAAE,cAAc;AAAA,MAC1B;AAAA,IACF;AAEA,UAAM,UAAU,YAAY,YAAY,GAAG;AAE3C,QAAI,UAAU,CAAC,uBAAuB;AACpC,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,qCAAqC,WAAW,YAAY,EAAE,MAAM,GAAG,EAAE,CAAC;AAAA,QACvF,QAAQ;AAAA,QACR,QAAQ,EAAE,YAAY,WAAW,YAAY,GAAG,cAAc;AAAA,MAChE;AAAA,IACF;AAEA,UAAM,MAAM,KAAK,IAAI,GAAG,OAAO;AAE/B,QAAI,OAAO,eAAe;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,iBAAiB,QAAQ,KAAK,CAAC,CAAC,0BAA0B,aAAa;AAAA,QACpF,QAAQ,EAAE,SAAS,QAAQ,KAAK,CAAC,GAAG,cAAc;AAAA,MACpD;AAAA,IACF;AAEA,QAAI,MAAM,gBAAgB,GAAG;AAC3B,YAAM,SAAS,QAAQ,KAAK,MAAM,iBAAiB,aAAa;AAEhE,aAAO;AAAA,QACL,SAAS;AAAA,QACT;AAAA,QACA,aAAa,iBAAiB,QAAQ,KAAK,CAAC,CAAC,wBAAwB,aAAa;AAAA,QAClF,QAAQ;AAAA,QACR,QAAQ,EAAE,SAAS,QAAQ,KAAK,CAAC,GAAG,cAAc;AAAA,MACpD;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,iBAAiB,QAAQ,KAAK,CAAC,CAAC,yCAAoC,aAAa;AAAA,MAC9F,QAAQ;AAAA,MACR,QAAQ,EAAE,SAAS,QAAQ,KAAK,CAAC,GAAG,cAAc;AAAA,IACpD;AAAA,EACF;AACF;;;AC/EO,IAAM,qBAAkC;AAAA,EAC7C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,eAAe;AAAA,EAEvB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,QAAQ,OAAO,IAAI;AAEzB,QAAI,MAAM,WAAW,GAAG;AACtB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,YAAY,KAAK,OAAO,eAAe;AAE7C,QAAI,cAAc,MAAM;AACtB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,MACV;AAAA,IACF;AAEA,UAAM,UAAU,MAAM;AAAA,MACpB,CAAC,SACC,aAAa,KAAK,iBACjB,KAAK,iBAAiB,QAAQ,aAAa,KAAK;AAAA,IACrD;AAEA,QAAI,YAAY,QAAW;AACzB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,SAAS,yCAAyC,QAAQ,KAAK;AAAA,QAC/E,QAAQ,EAAE,WAAW,MAAM,QAAQ,MAAM;AAAA,MAC3C;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,SAAS;AAAA,MACzB,QAAQ,4EAA4E,MACjF,IAAI,CAAC,SAAS,KAAK,KAAK,EACxB,KAAK,IAAI,CAAC;AAAA,MACb,QAAQ,EAAE,UAAU;AAAA,IACtB;AAAA,EACF;AACF;;;ACzDO,IAAM,kBAA+B;AAAA,EAC1C,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,YAAY,aAAa;AAAA,EAEjC,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,UAAU,OAAO,IAAI;AAE3B,QAAI,QAAQ,WAAW,GAAG;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,SAAS,KAAK,SAAS,UAAU;AAEvC,QAAI,OAAO,WAAW,GAAG;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,QACR,QAAQ,EAAE,kBAAkB,QAAQ,KAAK,IAAI,EAAE;AAAA,MACjD;AAAA,IACF;AAEA,UAAM,UAAU,YAAY,QAAQ,OAAO;AAE3C,QAAI,YAAY,MAAM;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,OAAO;AAAA,QACvB,QAAQ,EAAE,UAAU,QAAQ;AAAA,MAC9B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,KAAK,IAAI,CAAC;AAAA,MACjC,QAAQ,gFAAgF,QAAQ,KAAK,IAAI,CAAC;AAAA,MAC1G,QAAQ,EAAE,UAAU,OAAO,KAAK,IAAI,GAAG,kBAAkB,QAAQ,KAAK,IAAI,EAAE;AAAA,IAC9E;AAAA,EACF;AACF;;;ACrDO,IAAM,gBAA6B;AAAA,EACxC,IAAI;AAAA,EACJ,MAAM;AAAA,EACN,UAAU;AAAA,EACV,UAAU;AAAA,EACV,KAAK;AAAA,EACL,gBAAgB;AAAA,EAChB,iBAAiB;AAAA,EACjB,eAAe;AAAA,EACf,OAAO,CAAC,QAAQ;AAAA,EAEhB,UAAU,CAAC,EAAE,QAAQ,KAAK,MAAM;AAC9B,UAAM,UAAU,OAAO,IAAI;AAE3B,QAAI,QAAQ,WAAW,GAAG;AACxB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QACE;AAAA,MACJ;AAAA,IACF;AAEA,UAAM,SAAS,KAAK,SAAS,QAAQ;AAErC,QAAI,OAAO,WAAW,GAAG;AACvB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aACE;AAAA,QACF,QAAQ;AAAA,QACR,QAAQ,EAAE,eAAe,QAAQ,KAAK,IAAI,EAAE;AAAA,MAC9C;AAAA,IACF;AAEA,UAAM,UAAU,YAAY,QAAQ,OAAO;AAE3C,QAAI,YAAY,MAAM;AACpB,aAAO;AAAA,QACL,SAAS;AAAA,QACT,aAAa,GAAG,OAAO;AAAA,QACvB,QAAQ,EAAE,QAAQ,QAAQ;AAAA,MAC5B;AAAA,IACF;AAEA,WAAO;AAAA,MACL,SAAS;AAAA,MACT,aAAa,GAAG,OAAO,KAAK,IAAI,CAAC;AAAA,MACjC,QAAQ,2EAA2E,QAAQ,KAAK,IAAI,CAAC;AAAA,MACrG,QAAQ,EAAE,QAAQ,OAAO,KAAK,IAAI,GAAG,eAAe,QAAQ,KAAK,IAAI,EAAE;AAAA,IACzE;AAAA,EACF;AACF;;;ACjCO,IAAM,YAAoC;AAAA,EAC/C;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;;;ACzBO,IAAM,yBAAyB;AAsC/B,IAAM,kBAA2C;AAAA,EACtD;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAkDO,IAAM,kBAA2C;AAAA,EACtD;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;;;AClEO,IAAM,kBAAkB,CAC7B,MACA,UACY;AACZ,QAAM,UAAU,IAAI,IAAI,KAAK,IAAI,CAAC,UAAU,MAAM,KAAK,EAAE,YAAY,EAAE,QAAQ,QAAQ,GAAG,CAAC,CAAC;AAC5F,QAAM,WAAW,IAAI,IAAI,MAAM,IAAI,CAAC,UAAU,MAAM,KAAK,EAAE,YAAY,EAAE,QAAQ,QAAQ,GAAG,CAAC,CAAC;AAE9F,MAAI,QAAQ,SAAS,SAAS,MAAM;AAClC,WAAO;AAAA,EACT;AAEA,aAAW,SAAS,UAAU;AAC5B,QAAI,CAAC,QAAQ,IAAI,KAAK,GAAG;AACvB,aAAO;AAAA,IACT;AAAA,EACF;AAEA,SAAO;AACT;AAWO,IAAM,+BAA+B,CAC1C,YACA,aACsB;AACtB,MAAI,aAAa,UAAa,WAAW,WAAW,GAAG;AACrD,WAAO;AAAA,EACT;AAEA,QAAM,WAAW,OAAO,QAAQ,QAAQ;AAExC,MAAI,SAAS,WAAW,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,QAAM,qBAAqB,oBAAI,IAAoB;AAEnD,aAAW,CAAC,WAAW,QAAQ,KAAK,UAAU;AAC5C,UAAM,eAAe,cAAc,SAAS;AAC5C,uBAAmB,IAAI,cAAc,YAAY;AAEjD,eAAW,WAAW,UAAU;AAC9B,YAAM,aAAa,cAAc,OAAO;AASxC,UAAI,CAAC,mBAAmB,IAAI,UAAU,GAAG;AACvC,2BAAmB,IAAI,YAAY,YAAY;AAAA,MACjD;AAAA,IACF;AAAA,EACF;AAGA,QAAM,WAAW,IAAI,IAAI,WAAW,IAAI,aAAa,CAAC;AAEtD,aAAW,YAAY,YAAY;AACjC,UAAM,YAAY,mBAAmB,IAAI,cAAc,QAAQ,CAAC;AAEhE,QAAI,cAAc,QAAW;AAC3B;AAAA,IACF;AAEA,aAAS,IAAI,SAAS;AAEtB,eAAW,WAAW,SAAS,SAAS,KAAK,CAAC,GAAG;AAC/C,eAAS,IAAI,cAAc,OAAO,CAAC;AAAA,IACrC;AAAA,EACF;AAEA,SAAO,CAAC,GAAG,QAAQ;AACrB;AAEA,IAAM,gBAAgB,CAAC,UACrB,MAAM,KAAK,EAAE,YAAY,EAAE,QAAQ,QAAQ,GAAG;AAsChD,IAAM,wBAAwB,CAAC,YAAwC;AACrE,QAAM,OAAgD,EAAE,GAAG,QAAQ;AAEnE,aAAW,CAAC,KAAK,IAAI,KAAK,OAAO,QAAQ,4BAA4B,GAAG;AACtE,UAAM,UAAU;AAChB,UAAM,aAAa,KAAK,OAAO,KAAK,CAAC;AAErC,SAAK,OAAO,IAAI,WAAW,SAAS,IAAI,IACpC,aACA,CAAC,GAAG,YAAY,IAAI;AAAA,EAC1B;AAEA,SAAO;AACT;AAWO,IAAM,qBAAqB,CAChC,QAAgC,WAChC,cAC2B;AAAA,EAC3B,KAAK;AAAA,EACL,OAAO,OAAO;AAAA,IACZ,MAAM,IAAI,CAAC,SAAS;AAAA,MAClB,KAAK;AAAA,MACL;AAAA,QACE,SAAS,KAAK;AAAA,QACd,UAAU,KAAK;AAAA,QACf,QAAQ,KAAK;AAAA,MACf;AAAA,IACF,CAAC;AAAA,EACH;AAAA,EACA,OAAO;AAAA,EACP,eAAe;AAAA,EACf,sBAAsB;AAAA,EACtB,oBAAoB,CAAC;AAAA,EACrB,qBACE,UAAU,uBAAuB;AAAA,EACnC,kBAAkB,UAAU,oBAAoB;AAAA,EAChD,qBACE,UAAU,uBAAuB;AAAA,EACnC,mBAAmB,UAAU,qBAAqB;AAAA,EAClD,cAAc,sBAAsB,qBAAqB;AAC3D;AAEA,IAAM,iBAAiB,CAAC,UACtB,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK;AAEpD,IAAM,eAAe,CAAC,UAAoC;AACxD,MAAI,OAAO,UAAU,UAAU;AAC7B,UAAM,UAAU,MAAM,KAAK;AAC3B,WAAO,QAAQ,SAAS,IAAI,CAAC,OAAO,IAAI,CAAC;AAAA,EAC3C;AAEA,MAAI,CAAC,MAAM,QAAQ,KAAK,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,SAAO,MACJ,OAAO,CAAC,UAA2B,OAAO,UAAU,QAAQ,EAC5D,IAAI,CAAC,UAAU,MAAM,KAAK,CAAC,EAC3B,OAAO,CAAC,UAAU,MAAM,SAAS,CAAC;AACvC;AAEA,IAAM,WAAW,CAAC,WAChB,OAAO,IAAI,CAAC,UAAU,MAAM,YAAY,CAAC;AAE3C,IAAM,iBAAN,MAAqB;AAAA,EAArB;AACE,SAAiB,UAAyB,CAAC;AAAA;AAAA,EAE3C,IAAI,MAAuB,SAAiB,QAAuB;AACjE,SAAK,QAAQ,KAAK,WAAW,SAAY,EAAE,MAAM,QAAQ,IAAI,EAAE,MAAM,SAAS,OAAO,CAAC;AAAA,EACxF;AAAA,EAEA,IAAI,OAA+B;AACjC,WAAO,KAAK;AAAA,EACd;AAAA,EAEA,IAAI,QAAgB;AAClB,WAAO,KAAK,QAAQ;AAAA,EACtB;AACF;AAEA,IAAM,aAAa,CAAC,KAAc,QAAmC;AACnE,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,cAAc,GAAG,GAAG;AACvB,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AACA,WAAO;AAAA,EACT;AAEA,QAAM,aAAa,aAAa,IAAI,YAAY,CAAC;AACjD,QAAM,UAAU,aAAa,IAAI,SAAS,CAAC;AAE3C,MAAI,IAAI,YAAY,MAAM,UAAa,eAAe,MAAM;AAC1D,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AAAA,EACF;AAEA,MAAI,IAAI,SAAS,MAAM,UAAa,YAAY,MAAM;AACpD,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AAAA,EACF;AAEA,QAAM,WAAW,IAAI,WAAW;AAChC,MAAI,YAA2B,CAAC;AAEhC,MAAI,aAAa,UAAa,aAAa,MAAM;AAC/C,QAAI,CAAC,MAAM,QAAQ,QAAQ,GAAG;AAC5B,UAAI;AAAA,QACF;AAAA,QACA;AAAA,MACF;AAAA,IACF,OAAO;AACL,kBAAY,SAAS,QAAQ,CAAC,UAAyB;AACrD,YAAI,CAAC,cAAc,KAAK,GAAG;AACzB,iBAAO,CAAC;AAAA,QACV;AAEA,cAAM,MAAM,MAAM,cAAc;AAChC,cAAM,MAAM,MAAM,cAAc;AAEhC,YAAI,CAAC,eAAe,GAAG,KAAK,MAAM,GAAG;AACnC,iBAAO,CAAC;AAAA,QACV;AAEA,cAAM,cAAc,eAAe,GAAG,IAAI,MAAM;AAEhD,YAAI,gBAAgB,QAAQ,cAAc,KAAK;AAC7C,iBAAO,CAAC;AAAA,QACV;AAEA,cAAM,QACJ,OAAO,MAAM,OAAO,MAAM,YAAY,MAAM,OAAO,EAAE,KAAK,EAAE,SAAS,IACjE,MAAM,OAAO,EAAE,KAAK,IACpB,GAAG,GAAG,IAAI,eAAe,QAAG;AAElC,eAAO,CAAC,EAAE,OAAO,cAAc,KAAK,cAAc,YAAY,CAAC;AAAA,MACjE,CAAC;AAED,UAAI,UAAU,WAAW,SAAS,QAAQ;AACxC,YAAI;AAAA,UACF;AAAA,UACA;AAAA,UACA,GAAG,SAAS,SAAS,UAAU,MAAM,OAAO,SAAS,MAAM;AAAA,QAC7D;AAAA,MACF;AAAA,IACF;AAAA,EACF;AAEA,SAAO;AAAA,IACL,YAAY,cAAc,CAAC;AAAA,IAC3B,SAAS,WAAW,CAAC;AAAA,IACrB;AAAA,EACF;AACF;AAEA,IAAM,oBAAoB,CACxB,KACA,QACyC;AACzC,QAAM,YAAY,oBAAI,IAAqC;AAE3D,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,EACT;AAIA,MAAI,MAAM,QAAQ,GAAG,GAAG;AACtB,eAAW,SAAS,KAAK;AACvB,UAAI,CAAC,cAAc,KAAK,GAAG;AACzB;AAAA,MACF;AAEA,YAAM,KAAK,MAAM,IAAI,KAAK,MAAM,QAAQ;AAExC,UAAI,OAAO,OAAO,YAAY,GAAG,SAAS,GAAG;AAC3C,kBAAU,IAAI,IAAI,KAAK;AAAA,MACzB;AAAA,IACF;AAEA,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,cAAc,GAAG,GAAG;AACvB,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AACA,WAAO;AAAA,EACT;AAEA,aAAW,CAAC,IAAI,KAAK,KAAK,OAAO,QAAQ,GAAG,GAAG;AAC7C,QAAI,cAAc,KAAK,GAAG;AACxB,gBAAU,IAAI,IAAI,KAAK;AACvB;AAAA,IACF;AAEA,QAAI,OAAO,UAAU,WAAW;AAC9B,gBAAU,IAAI,IAAI,EAAE,SAAS,MAAM,CAAC;AACpC;AAAA,IACF;AAEA,QAAI;AAAA,MACF;AAAA,MACA,0BAA0B,EAAE;AAAA,IAC9B;AAAA,EACF;AAEA,SAAO;AACT;AAEA,IAAM,sBAAsB,CAC1B,KACA,OACA,QACgC;AAChC,QAAM,YAAY,kBAAkB,KAAK,GAAG;AAC5C,QAAM,WAAwC,CAAC;AAE/C,aAAW,QAAQ,OAAO;AACxB,UAAM,WAAW,UAAU,IAAI,KAAK,EAAE;AAEtC,QAAI,UAAU,KAAK;AACnB,QAAI,WAAyB,KAAK;AAClC,QAAI,SAAS,KAAK;AAElB,QAAI,aAAa,QAAW;AAC1B,YAAM,aAAa,SAAS,SAAS;AAErC,UAAI,OAAO,eAAe,WAAW;AACnC,kBAAU;AAAA,MACZ,WAAW,eAAe,UAAa,eAAe,MAAM;AAC1D,YAAI;AAAA,UACF;AAAA,UACA,IAAI,KAAK,IAAI;AAAA,UACb,QAAQ,KAAK,EAAE;AAAA,QACjB;AAAA,MACF;AAEA,YAAM,cAAc,SAAS,UAAU;AAEvC,UACE,OAAO,gBAAgB,YACtB,gBAAsC,SAAS,WAAW,GAC3D;AACA,mBAAW;AAAA,MACb,WAAW,gBAAgB,UAAa,gBAAgB,MAAM;AAC5D,YAAI;AAAA,UACF;AAAA,UACA,IAAI,KAAK,IAAI;AAAA,UACb,QAAQ,KAAK,EAAE;AAAA,QACjB;AAAA,MACF;AAEA,YAAM,YAAY,SAAS,QAAQ;AAEnC,UAAI,eAAe,SAAS,KAAK,aAAa,GAAG;AAC/C,iBAAS;AAAA,MACX,WAAW,cAAc,UAAa,cAAc,MAAM;AACxD,YAAI;AAAA,UACF;AAAA,UACA,IAAI,KAAK,IAAI;AAAA,UACb,QAAQ,KAAK,EAAE;AAAA,QACjB;AAAA,MACF;AAAA,IACF;AAEA,aAAS,KAAK,EAAE,IAAI,EAAE,SAAS,UAAU,OAAO;AAAA,EAClD;AAIA,QAAM,WAAW,MAAM,OAAO,CAAC,SAAS;AACtC,UAAM,UAAU,SAAS,KAAK,EAAE;AAChC,WAAO,YAAY,UAAa,QAAQ,WAAW,QAAQ,aAAa;AAAA,EAC1E,CAAC;AAED,QAAM,cAAc,SAAS;AAAA,IAC3B,CAAC,KAAK,SAAS,OAAO,SAAS,KAAK,EAAE,GAAG,UAAU;AAAA,IACnD;AAAA,EACF;AAEA,MAAI,SAAS,SAAS,KAAK,eAAe,GAAG;AAC3C,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AAEA,eAAW,QAAQ,UAAU;AAC3B,YAAM,UAAU,SAAS,KAAK,EAAE;AAEhC,UAAI,YAAY,QAAW;AACzB,iBAAS,KAAK,EAAE,IAAI,EAAE,GAAG,SAAS,QAAQ,EAAE;AAAA,MAC9C;AAAA,IACF;AAAA,EACF;AAEA,SAAO;AACT;AAEA,IAAM,eAAe,CAAC,KAAc,QAAgD;AAClF,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,MAAM,QAAQ,GAAG,GAAG;AACvB,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AACA,WAAO;AAAA,EACT;AAEA,QAAM,QAAQ,IAAI,QAAQ,CAAC,UAAyB;AAClD,QAAI,CAAC,cAAc,KAAK,GAAG;AACzB,aAAO,CAAC;AAAA,IACV;AAEA,UAAM,WAAW,MAAM,UAAU;AAEjC,QAAI,CAAC,eAAe,QAAQ,GAAG;AAC7B,aAAO,CAAC;AAAA,IACV;AAEA,UAAM,KACJ,OAAO,MAAM,IAAI,MAAM,YAAY,MAAM,IAAI,EAAE,KAAK,EAAE,SAAS,IAC3D,MAAM,IAAI,EAAE,KAAK,IACjB;AAEN,QAAI,OAAO,MAAM;AACf,aAAO,CAAC;AAAA,IACV;AAEA,UAAM,QACJ,OAAO,MAAM,OAAO,MAAM,YAAY,MAAM,OAAO,EAAE,KAAK,EAAE,SAAS,IACjE,MAAM,OAAO,EAAE,KAAK,IACpB;AAEN,WAAO,CAAC,EAAE,IAAI,OAAO,UAAU,KAAK,IAAI,KAAK,KAAK,IAAI,GAAG,QAAQ,CAAC,EAAE,CAAC;AAAA,EACvE,CAAC;AAED,MAAI,MAAM,WAAW,GAAG;AACtB,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AACA,WAAO;AAAA,EACT;AAEA,MAAI,MAAM,WAAW,IAAI,QAAQ;AAC/B,QAAI;AAAA,MACF;AAAA,MACA;AAAA,MACA,GAAG,IAAI,SAAS,MAAM,MAAM,OAAO,IAAI,MAAM;AAAA,IAC/C;AAAA,EACF;AAEA,SAAO,CAAC,GAAG,KAAK,EAAE,KAAK,CAAC,GAAGC,OAAMA,GAAE,WAAW,EAAE,QAAQ;AAC1D;AAEA,IAAM,uBAAuB,CAAC,KAAc,QAAgC;AAC1E,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,eAAe,GAAG,KAAK,MAAM,KAAK,MAAM,KAAK;AAChD,QAAI;AAAA,MACF;AAAA,MACA,4EAA4E,sBAAsB;AAAA,IACpG;AACA,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAEA,IAAM,mBAAmB,CAAC,KAAc,QAAgC;AACtE,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,eAAe,GAAG,KAAK,OAAO,GAAG;AACpC,QAAI;AAAA,MACF;AAAA,MACA,6EAA6E,uBAAuB;AAAA,IACtG;AACA,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAEA,IAAM,yBAAyB,CAC7B,KACA,QAC0C;AAC1C,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO,CAAC;AAAA,EACV;AAEA,MAAI,CAAC,cAAc,GAAG,GAAG;AACvB,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AACA,WAAO,CAAC;AAAA,EACV;AAEA,QAAM,WAAkD,CAAC;AAEzD,aAAW,OAAO,iBAAiB;AACjC,UAAM,QAAQ,IAAI,GAAG;AAErB,QAAI,UAAU,UAAa,UAAU,MAAM;AACzC;AAAA,IACF;AAEA,QAAI,eAAe,KAAK,KAAK,QAAQ,GAAG;AACtC,eAAS,GAAG,IAAI;AAAA,IAClB,OAAO;AACL,UAAI;AAAA,QACF;AAAA,QACA,uBAAuB,GAAG;AAAA,MAC5B;AAAA,IACF;AAAA,EACF;AAEA,SAAO;AACT;AAyBA,IAAM,mBAAmB,CACvB,KACA,SACA,UACA,OACA,QACsB;AACtB,QAAM,WAAW,YAAY;AAE7B,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,EACT;AAEA,QAAM,OAAO,aAAa,GAAG;AAE7B,MAAI,SAAS,QAAQ,KAAK,WAAW,GAAG;AACtC,QAAI;AAAA,MACF;AAAA,MACA,QAAQ,KAAK;AAAA,IACf;AACA,WAAO;AAAA,EACT;AAEA,MAAI,aAAa,UAAa,gBAAgB,MAAM,OAAO,GAAG;AAC5D,WAAO;AAAA,EACT;AAEA,SAAO,SAAS,IAAI;AACtB;AAaA,IAAM,4BAAqD;AAAA,EACzD;AAAA,EACA;AACF;AAOA,IAAM,6BAA6B,CACjC,KACA,QACiB;AACjB,QAAM,UAAmD;AAAA,IACvD,GAAG;AAAA,EACL;AAEA,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,EACT;AAEA,MAAI,CAAC,cAAc,GAAG,GAAG;AACvB,QAAI;AAAA,MACF;AAAA,MACA;AAAA,IACF;AACA,WAAO;AAAA,EACT;AAEA,aAAW,OAAO,iBAAiB;AACjC,UAAM,QAAQ,IAAI,GAAG;AAErB,QAAI,UAAU,UAAa,UAAU,MAAM;AACzC;AAAA,IACF;AAEA,QAAI,0BAA0B,SAAS,GAAG,GAAG;AAC3C,UAAI;AAAA,QACF;AAAA,QACA,IAAI,GAAG;AAAA,MACT;AACA;AAAA,IACF;AAEA,UAAM,QAAQ,aAAa,KAAK;AAEhC,QAAI,UAAU,QAAQ,MAAM,WAAW,GAAG;AACxC,UAAI;AAAA,QACF;AAAA,QACA,0BAA0B,GAAG;AAAA,MAC/B;AACA;AAAA,IACF;AAEA,YAAQ,GAAG,IAAI;AAAA,EACjB;AAEA,SAAO;AACT;AAEA,IAAM,sBAAsB,CAAC,KAAc,QACzC,sBAAsB,2BAA2B,KAAK,GAAG,CAAC;AAyBrD,IAAM,gBAAgB,CAC3B,KACA,QAAgC,WAChC,aACqB;AACrB,QAAM,MAAM,IAAI,eAAe;AAC/B,QAAM,aAAa,YAAY;AAE/B,MAAI,QAAQ,UAAa,QAAQ,MAAM;AACrC,WAAO;AAAA,MACL,QAAQ,mBAAmB,OAAO,UAAU;AAAA,MAC5C,QAAQ;AAAA,MACR,cAAc;AAAA,QACZ;AAAA,UACE,MAAM;AAAA,UACN,SACE;AAAA,QACJ;AAAA,MACF;AAAA,IACF;AAAA,EACF;AAEA,MAAI,CAAC,cAAc,GAAG,GAAG;AACvB,WAAO;AAAA,MACL,QAAQ,mBAAmB,OAAO,UAAU;AAAA,MAC5C,QAAQ;AAAA,MACR,cAAc;AAAA,QACZ;AAAA,UACE,MAAM;AAAA,UACN,SACE;AAAA,UACF,QAAQ,gCAAgC,MAAM,QAAQ,GAAG,IAAI,UAAU,OAAO,GAAG;AAAA,QACnF;AAAA,MACF;AAAA,IACF;AAAA,EACF;AAEA,QAAM,cAAc,WAAW,IAAI,KAAK,GAAG,GAAG;AAE9C,QAAM,SAAgC;AAAA;AAAA;AAAA;AAAA;AAAA,IAKpC,KAAK;AAAA,MACH,GAAG;AAAA,MACH,YAAY;AAAA,QACV,YAAY;AAAA,QACZ,YAAY;AAAA,MACd;AAAA,IACF;AAAA,IACA,OAAO,oBAAoB,IAAI,OAAO,GAAG,OAAO,GAAG;AAAA,IACnD,OAAO,aAAa,IAAI,OAAO,GAAG,GAAG;AAAA,IACrC,eAAe,qBAAqB,IAAI,eAAe,GAAG,GAAG;AAAA,IAC7D,sBAAsB,iBAAiB,IAAI,sBAAsB,GAAG,GAAG;AAAA,IACvE,oBAAoB,uBAAuB,IAAI,oBAAoB,GAAG,GAAG;AAAA,IACzE,qBAAqB;AAAA,MACnB;AAAA,QACE,IAAI,qBAAqB;AAAA,QACzB;AAAA,QACA,YAAY;AAAA,QACZ;AAAA,QACA;AAAA,MACF;AAAA,IACF;AAAA,IACA,kBAAkB;AAAA,MAChB;AAAA,QACE,IAAI,kBAAkB;AAAA,QACtB;AAAA,QACA,YAAY;AAAA,QACZ;AAAA,QACA;AAAA,MACF;AAAA,IACF;AAAA,IACA,qBAAqB;AAAA,MACnB;AAAA,QACE,IAAI,qBAAqB;AAAA,QACzB;AAAA,QACA,YAAY;AAAA,QACZ;AAAA,QACA;AAAA,MACF;AAAA,IACF;AAAA,IACA,mBAAmB;AAAA,MACjB;AAAA,QACE,IAAI,mBAAmB;AAAA,QACvB;AAAA,QACA,YAAY;AAAA,QACZ;AAAA,QACA;AAAA,MACF;AAAA,IACF;AAAA,IACA,cAAc,oBAAoB,IAAI,cAAc,GAAG,GAAG;AAAA,EAC5D;AAEA,SAAO;AAAA,IACL;AAAA,IACA,QAAQ,IAAI,QAAQ,IAAI,aAAa;AAAA,IACrC,cAAc,IAAI;AAAA,EACpB;AACF;;;AC1xBO,IAAM,oBAAoB,CAC/B,gBAC6B;AAC7B,QAAM,WAEF,CAAC;AAEL,MAAI,YAAY,oBAAoB,SAAS,GAAG;AAC9C,aAAS,sBAAsB,YAAY;AAAA,EAC7C;AAEA,MAAI,YAAY,iBAAiB,SAAS,GAAG;AAC3C,aAAS,mBAAmB,YAAY;AAAA,EAC1C;AAEA,MAAI,YAAY,oBAAoB,SAAS,GAAG;AAC9C,aAAS,sBAAsB,YAAY;AAAA,EAC7C;AAEA,MAAI,YAAY,kBAAkB,SAAS,GAAG;AAC5C,aAAS,oBAAoB,YAAY;AAAA,EAC3C;AAEA,MAAI,OAAO,KAAK,YAAY,gBAAgB,EAAE,SAAS,GAAG;AACxD,aAAS,mBAAmB,YAAY;AAAA,EAC1C;AAEA,SAAO;AACT;;;ACQO,IAAM,yBAAyB,CACpC,MAA0C,QAAQ,QAC3B;AACvB,QAAM,SAAS,IAAI,aAAa;AAChC,QAAM,UAAU,OAAO,WAAW,WAAW,OAAO,KAAK,IAAI;AAC7D,QAAM,UAAU,IAAI,sBAAsB;AAC1C,QAAM,iBAAiB,IAAI,qBAAqB;AAEhD,SAAO;AAAA,IACL,YAAY,QAAQ,WAAW,IAAI,OAAO;AAAA,IAC1C,SACE,OAAO,YAAY,YAAY,QAAQ,KAAK,EAAE,SAAS,IACnD,QAAQ,KAAK,IACb;AAAA,IACN,aACE,OAAO,mBAAmB,YAC1B,eAAe,KAAK,EAAE,YAAY,MAAM,YACpC,YACA;AAAA,EACR;AACF;;;ACrHO,IAAM,uBAA2C;AAAA,EACtD,KAAK,CAAC,QAAQ,EAAG,IAAmB,KAAK,EAAE,OAAO,YAAY,CAAC;AAAA,EAC/D,QAAQ,OAAO,QAAQ;AACrB,UAAM,EAAG,OAAO,KAAK,EAAE,OAAO,YAAY,CAAC;AAAA,EAC7C;AACF;;;ACWA,IAAM,cAAc;AAEpB,IAAM,eAAe,CAAC,UACpB,iBAAiB,QAAQ,CAAC,OAAO,MAAM,MAAM,QAAQ,CAAC;AAExD,IAAM,eAAe,CAAC,UAA2B;AAC/C,MAAI,iBAAiB,OAAO;AAC1B,WAAO,MAAM;AAAA,EACf;AAEA,SAAO,OAAO,UAAU,WAAW,QAAQ;AAC7C;AAEA,IAAM,YAAY,CAAC,YAAiC;AAClD,UAAQ,QAAQ,SAAS;AAAA,IACvB,KAAK;AACH,aAAO,QAAQ,WAAW,SAAY,IAAI,QAAQ,QAAQ,MAAM;AAAA,IAClE,KAAK;AACH,aAAO,QAAQ,WAAW,SAAY,MAAM,QAAQ,QAAQ,MAAM;AAAA,IACpE,KAAK;AACH,aAAO,QAAQ,WAAW,SAAY,IAAI,QAAQ,QAAQ,MAAM;AAAA,IAClE,KAAK;AAAA,IACL;AACE,aAAO;AAAA,EACX;AACF;AAEA,IAAM,aAAa,CACjB,QACA,SAEA,OAAO,MAAM,KAAK,EAAE,KAAK;AAAA,EACvB,SAAS,KAAK;AAAA,EACd,UAAU,KAAK;AAAA,EACf,QAAQ,KAAK;AACf;AAEF,IAAM,UAAU,CACd,OACA,UACuB;AACvB,MAAI,UAAU,MAAM;AAClB,WAAO;AAAA,EACT;AAEA,SACE,CAAC,GAAG,KAAK,EACN,KAAK,CAAC,GAAGC,OAAMA,GAAE,WAAW,EAAE,QAAQ,EACtC,KAAK,CAAC,SAAS,SAAS,KAAK,QAAQ,KAAK;AAEjD;AAEA,IAAM,gBAAwC;AAAA,EAC5C,UAAU;AAAA,EACV,UAAU;AAAA,EACV,OAAO;AAAA,EACP,OAAO;AAAA,EACP,UAAU;AACZ;AAEA,IAAM,iBAAiB,CAAC,UACtB,MACG;AAAA,EACC,CAAC,UACC,MAAM,gBACL,MAAM,YAAY,UAAU,MAAM,YAAY;AACnD,EACC,KAAK,CAAC,GAAGA,OAAM;AACd,QAAM,cACH,cAAc,EAAE,QAAQ,KAAK,MAAM,cAAcA,GAAE,QAAQ,KAAK;AAEnE,MAAI,eAAe,GAAG;AACpB,WAAO;AAAA,EACT;AAEA,SAAOA,GAAE,iBAAiBA,GAAE,gBAAgB,EAAE,iBAAiB,EAAE;AACnE,CAAC,EACA,MAAM,GAAG,WAAW,EACpB,IAAI,CAAC,UAAU,MAAM,WAAW;AAErC,IAAM,YAAY,CAChB,UACA,OACA,MACA,eACA,mBACW;AACX,UAAQ,UAAU;AAAA,IAChB,KAAK;AACH,aAAO,kBAAkB;AAAA,IAC3B,KAAK;AACH,aAAO;AAAA,IACT,KAAK;AACH,aAAO,iCAA4B,SAAS,CAAC,OAC3C,SAAS,OAAO,KAAK,KAAK,KAAK,KAAK,GACtC,sBAAsB,aAAa;AAAA,IACrC,KAAK;AAAA,IACL;AACE,aAAO,iCAA4B,SAAS,CAAC,OAC3C,SAAS,OAAO,KAAK,KAAK,KAAK,KAAK,GACtC,gBAAgB,aAAa;AAAA,EACjC;AACF;AAEA,IAAM,gBAAgB,CACpB,MACA,iBACe;AACf,MAAI,CAAC,cAAc,IAAI,GAAG;AACxB,iBAAa,KAAK;AAAA,MAChB,MAAM;AAAA,MACN,SACE;AAAA,IACJ,CAAC;AAED,WAAO,EAAE,IAAI,MAAM,QAAQ,CAAC,EAAE;AAAA,EAChC;AAEA,QAAM,KAAK,OAAO,KAAK,IAAI,MAAM,WAAW,KAAK,IAAI,IAAI;AACzD,QAAM,SAAS,KAAK,QAAQ;AAE5B,MAAI,CAAC,cAAc,MAAM,GAAG;AAC1B,iBAAa,KAAK;AAAA,MAChB,MAAM;AAAA,MACN,SACE;AAAA,IACJ,CAAC;AAED,WAAO,EAAE,IAAI,QAAQ,CAAC,EAAE;AAAA,EAC1B;AAEA,SAAO,EAAE,IAAI,OAAO;AACtB;AAEA,IAAM,eAAe,CACnB,MACA,QACA,MACA,KACA,iBACmB;AACnB,QAAM,UAAU,WAAW,QAAQ,IAAI;AACvC,QAAM,SAAS,kBAAkB,MAAM,OAAO,YAAY;AAE1D,QAAM,OAAO;AAAA,IACX,QAAQ,KAAK;AAAA,IACb,UAAU,KAAK;AAAA,IACf,UAAU,KAAK;AAAA,IACf,UAAU,KAAK;AAAA,IACf,UAAU,QAAQ;AAAA,IAClB,QAAQ,QAAQ;AAAA,EAClB;AAEA,MAAI,CAAC,QAAQ,SAAS;AACpB,WAAO;AAAA,MACL,GAAG;AAAA,MACH,SAAS;AAAA,MACT,QAAQ;AAAA,MACR,cAAc;AAAA,MACd,gBAAgB;AAAA,MAChB,aAAa;AAAA,MACb,aAAa,IAAI,KAAK,IAAI;AAAA,MAC1B,cAAc,CAAC;AAAA,IACjB;AAAA,EACF;AAEA,MAAI;AAEJ,MAAI;AACF,cAAU,KAAK,SAAS,EAAE,MAAM,QAAQ,KAAK,MAAM,OAAO,CAAC;AAAA,EAC7D,SAAS,OAAO;AAGd,UAAM,UAAU,aAAa,KAAK;AAElC,iBAAa,KAAK;AAAA,MAChB,MAAM;AAAA,MACN,SAAS,QAAQ,KAAK,IAAI;AAAA,MAC1B,QAAQ,GAAG,KAAK,EAAE,KAAK,OAAO;AAAA,IAChC,CAAC;AAED,WAAO;AAAA,MACL,GAAG;AAAA,MACH,SAAS;AAAA,MACT,QAAQ;AAAA,MACR,cAAc;AAAA,MACd,gBAAgB;AAAA,MAChB,aAAa;AAAA,MACb,aAAa,QAAQ,KAAK,IAAI;AAAA,MAC9B,QAAQ;AAAA,MACR,cAAc,OAAO,aAAa;AAAA,MAClC,OAAO;AAAA,IACT;AAAA,EACF;AAEA,QAAM,aACJ,QAAQ,YAAY,UACpB,QAAQ,YAAY,aACpB,QAAQ,YAAY;AAEtB,QAAM,cAAc,cAAc,QAAQ,aAAa;AACvD,QAAM,SAAS,UAAU,OAAO;AAChC,QAAM,iBAAiB,cAAc,QAAQ,SAAS;AACtD,QAAM,eAAe,cAAc,QAAQ,QAAQ,SAAS,QAAQ,CAAC,IAAI;AAEzE,QAAM,QAAwB;AAAA,IAC5B,GAAG;AAAA,IACH,SAAS,QAAQ;AAAA,IACjB;AAAA,IACA;AAAA,IACA;AAAA,IACA;AAAA,IACA,aAAa,QAAQ;AAAA,IACrB,cAAc,OAAO,aAAa;AAAA,EACpC;AAEA,SAAO;AAAA,IACL,GAAG;AAAA,IACH,GAAI,QAAQ,WAAW,SAAY,CAAC,IAAI,EAAE,QAAQ,QAAQ,OAAO;AAAA,IACjE,GAAI,QAAQ,WAAW,SAAY,CAAC,IAAI,EAAE,QAAQ,QAAQ,OAAO;AAAA,EACnE;AACF;AAEA,IAAM,aAAa,CAAC,UAAyC;AAC3D,QAAM,eAA8B,CAAC;AACrC,QAAM,QAAQ,MAAM,SAAS;AAE7B,QAAM,OAAO,cAAc,MAAM,MAAM,YAAY;AAEnD,MAAI,MAAmB;AAEvB,MAAI,aAAa,MAAM,GAAG,GAAG;AAC3B,UAAM,MAAM;AAAA,EACd,OAAO;AACL,iBAAa,KAAK;AAAA,MAChB,MAAM;AAAA,MACN,SACE;AAAA,IACJ,CAAC;AAAA,EACH;AAMA,QAAM,aAAa,cAAc,MAAM,QAAQ,OAAO,MAAM,QAAQ;AACpE,eAAa,KAAK,GAAG,WAAW,YAAY;AAE5C,QAAM,EAAE,OAAO,IAAI;AAEnB,QAAM,QAAQ,MAAM;AAAA,IAAI,CAAC,SACvB,aAAa,MAAM,QAAQ,MAAM,KAAK,YAAY;AAAA,EACpD;AAEA,QAAM,eAAe,MAAM,OAAO,CAAC,UAAU,MAAM,WAAW;AAC9D,QAAM,cAAc;AAAA,IAClB,aAAa,OAAO,CAAC,KAAK,UAAU,MAAM,MAAM,gBAAgB,CAAC;AAAA,IACjE;AAAA,EACF;AACA,QAAM,eAAe;AAAA,IACnB,aAAa,OAAO,CAAC,KAAK,UAAU,MAAM,MAAM,cAAc,CAAC;AAAA,IAC/D;AAAA,EACF;AAEA,MAAI,QAAuB;AAE3B,MAAI,cAAc,GAAG;AACnB,YAAQ,QAAS,eAAe,cAAe,KAAK,CAAC;AAAA,EACvD,OAAO;AAGL,iBAAa,KAAK;AAAA,MAChB,MAAM;AAAA,MACN,SACE;AAAA,IACJ,CAAC;AAAA,EACH;AAEA,QAAM,OAAO,QAAQ,OAAO,OAAO,KAAK;AAExC,QAAM,kBAAkB,MAAM;AAAA,IAC5B,CAAC,UAAU,MAAM,aAAa,cAAc,MAAM,YAAY;AAAA,EAChE;AACA,QAAM,kBAAkB,MAAM;AAAA,IAC5B,CAAC,UAAU,MAAM,aAAa,cAAc,MAAM,YAAY;AAAA,EAChE;AAEA,MAAI;AAEJ,MAAI,oBAAoB,QAAW;AACjC,eAAW;AAAA,EACb,WAAW,UAAU,MAAM;AACzB,eAAW;AAAA,EACb,WAAW,oBAAoB,QAAW;AACxC,eAAW;AAAA,EACb,OAAO;AACL,eAAW,SAAS,OAAO,gBAAgB,aAAa;AAAA,EAC1D;AAEA,QAAM,UAAU,eAAe,KAAK;AAEpC,SAAO;AAAA,IACL;AAAA,IACA;AAAA,IACA;AAAA,IACA,eAAe,OAAO;AAAA,IACtB,SAAS;AAAA,MACP;AAAA,MACA;AAAA,MACA;AAAA,MACA,OAAO;AAAA,MACP,iBAAiB,eAAe;AAAA,IAClC;AAAA,IACA;AAAA,IACA;AAAA,IACA;AAAA,IACA,cAAc,WAAW;AAAA,IACzB,UAAU,QAAQ,OAAO,OAAO,IAAI,YAAY;AAAA,IAChD,QAAQ,KAAK,MAAM;AAAA,IACnB,eAAe;AAAA,IACf;AAAA,IACA;AAAA,EACF;AACF;AAQO,IAAM,YAAY,CAAC,UAAyC;AACjE,MAAI;AACF,WAAO,WAAW,KAAK;AAAA,EACzB,SAAS,OAAO;AAEd,UAAM,SACJ,cAAc,OAAO,IAAI,KAAK,OAAO,MAAM,KAAK,IAAI,MAAM,WACtD,MAAM,KAAK,IAAI,IACf;AAEN,WAAO;AAAA,MACL,OAAO;AAAA,MACP,MAAM;AAAA,MACN,UAAU;AAAA,MACV,eAAe;AAAA,MACf,SACE;AAAA,MACF,SAAS,CAAC,4DAA4D;AAAA,MACtE,OAAO,CAAC;AAAA,MACR,cAAc;AAAA,QACZ;AAAA,UACE,MAAM;AAAA,UACN,SACE;AAAA,UACF,QAAQ,aAAa,KAAK;AAAA,QAC5B;AAAA,MACF;AAAA,MACA,cAAc;AAAA,MACd,UAAU,aAAa,OAAO,GAAG,IAAI,MAAM,IAAI,YAAY,IAAI;AAAA,MAC/D;AAAA,MACA,eAAe;AAAA,MACf,aAAa;AAAA,MACb,cAAc;AAAA,IAChB;AAAA,EACF;AACF;;;AC3TO,IAAM,kBAAkB;AAAA,EAC7B;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AACF;AAIO,IAAM,uBACX,gBAAgB,IAAI,CAAC,WAAW,OAAO,IAAI;AAkNtC,IAAM,mBAAmB,CAC9B,wBACA,aACW,sBAAsB,sBAAsB,IAAI,QAAQ;;;AC9R9D,IAAM,+BAA+B;AACrC,IAAM,2BAA2B;AAmBjC,IAAM,mCAAsD;AAAA,EACjE;AAAA,EACA;AACF;AAyBO,IAAM,sBAAsB;AAAA,EACjC;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AACF;AAIO,IAAM,2BACX,oBAAoB,IAAI,CAAC,WAAW,OAAO,IAAI;AA6B1C,IAAM,wBAAwB;AAAA,EACnC;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AAAA,EACA;AAAA,IACE,MAAM;AAAA,IACN,OAAO;AAAA,IACP,MAAM;AAAA,EACR;AACF;AAKO,IAAM,6BACX,sBAAsB,IAAI,CAAC,WAAW,OAAO,IAAI;;;AC7J5C,IAAM,mCAAmC;AAGzC,IAAM,sCAET;AAAA,EACF,QAAQ;AAAA,EACR,SAAS;AAAA,EACT,aAAa;AACf;AAGO,IAAM,gCAAgC;AAAA,EAC3C;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAGO,IAAM,4BAA4B,MACvC,OAAO,YAAY,8BAA8B,IAAI,CAAC,SAAS,CAAC,MAAM,IAAI,CAAC,CAAC;AAwN9E,IAAM,iBAAiB,CAAC,UACtB,OAAO,UAAU,YAAY,OAAO,SAAS,KAAK,IAAI,QAAQ;AAEhE,IAAM,eAAe,CAAC,UAAyC;AAC7D,MAAI,CAAC,MAAM,QAAQ,KAAK,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,QAAM,OAAO,MACV,OAAO,CAAC,UAA2B,OAAO,UAAU,QAAQ,EAC5D,IAAI,CAAC,UAAU,MAAM,KAAK,CAAC,EAC3B,OAAO,CAAC,UAAU,MAAM,SAAS,CAAC;AAErC,SAAO;AACT;AAGA,IAAM,gBAAgB,CAAC,UAA4B;AACjD,MAAI,MAAM,QAAQ,KAAK,GAAG;AACxB,WAAO;AAAA,EACT;AAEA,MAAI,cAAc,KAAK,KAAK,MAAM,QAAQ,MAAM,OAAO,CAAC,GAAG;AACzD,WAAO,MAAM,OAAO;AAAA,EACtB;AAEA,SAAO;AACT;AAYA,IAAM,YAAY,CAChB,cACA,iBACwC;AACxC,QAAM,WAAW,cAAc,YAAY,IAAI,eAAe;AAC9D,QAAM,UAAU,cAAc,YAAY,IAAI,eAAe;AAE7D,MAAI,aAAa,UAAa,YAAY,QAAW;AACnD,WAAO;AAAA,EACT;AAEA,QAAM,UAAU,oBAAI,IAAY;AAAA,IAC9B,GAAG,OAAO,KAAK,YAAY,CAAC,CAAC;AAAA,IAC7B,GAAG,OAAO,KAAK,WAAW,CAAC,CAAC;AAAA,EAC9B,CAAC;AAED,QAAM,QAAiC,CAAC;AAExC,aAAW,UAAU,SAAS;AAC5B,UAAM,UAAU,WAAW,MAAM;AACjC,UAAM,SAAkC,cAAc,OAAO,IACzD,EAAE,GAAG,QAAQ,IACb,CAAC;AAEL,QAAI,OAAO,SAAS,MAAM,UAAa,OAAO,WAAW,MAAM,QAAW;AACxE,aAAO,SAAS,IAAI,OAAO,WAAW;AAAA,IACxC;AAEA,UAAM,SAAS,eAAe,UAAU,MAAM,CAAC;AAE/C,QAAI,WAAW,QAAW;AACxB,aAAO,QAAQ,IAAI;AAAA,IACrB;AAEA,UAAM,MAAM,IAAI;AAAA,EAClB;AAEA,SAAO;AACT;AASA,IAAM,YAAY,CAAC,WAA6C;AAC9D,QAAM,YAAY,eAAe,OAAO,wBAAwB,CAAC;AACjE,QAAM,OAAO,eAAe,OAAO,mBAAmB,CAAC;AACvD,QAAM,OAAO,eAAe,OAAO,mBAAmB,CAAC;AAEvD,MAAI,cAAc,UAAa,SAAS,UAAa,SAAS,QAAW;AACvE,WAAO;AAAA,EACT;AAEA,QAAM,QAA2D,CAAC;AAElE,MAAI,cAAc,QAAW;AAC3B,UAAM,KAAK,EAAE,IAAI,aAAa,OAAO,aAAa,UAAU,UAAU,CAAC;AAAA,EACzE;AAEA,MAAI,SAAS,QAAW;AACtB,UAAM,KAAK,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,KAAK,CAAC;AAAA,EAC1D;AAEA,MAAI,SAAS,QAAW;AACtB,UAAM,KAAK,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,KAAK,CAAC;AAAA,EAC1D;AAGA,QAAM,KAAK,EAAE,IAAI,QAAQ,OAAO,QAAQ,UAAU,EAAE,CAAC;AAErD,SAAO;AACT;AAYA,IAAM,UAAU,CACd,OACA,aACa,CAAC,GAAG,oBAAI,IAAI,CAAC,GAAG,OAAO,GAAG,QAAQ,CAAC,CAAC;AAEnD,IAAM,mBAAmB,CACvB,WACyC;AACzC,QAAM,UAAoC,CAAC;AAE3C,QAAM,qBAAqB,OAAO,wBAAwB;AAE1D,MAAI,OAAO,uBAAuB,YAAY,mBAAmB,KAAK,GAAG;AAMvE,YAAQ,UAAU,IAAI;AAAA,MACpB,CAAC,mBAAmB,KAAK,CAAC;AAAA,MAC1B,sBAAsB;AAAA,IACxB;AAAA,EACF;AAEA,QAAM,eAAe,aAAa,OAAO,kBAAkB,CAAC;AAE5D,MAAI,iBAAiB,UAAa,aAAa,SAAS,GAAG;AACzD,YAAQ,UAAU,IAAI,QAAQ,cAAc;AAAA,MAC1C;AAAA,MACA;AAAA,MACA;AAAA,MACA;AAAA,IACF,CAAC;AAAA,EACH;AAEA,SAAO,OAAO,KAAK,OAAO,EAAE,SAAS,IAAI,UAAU;AACrD;AAUO,IAAM,uBAAuB,CAAC,WAA6B;AAChE,MAAI,CAAC,cAAc,MAAM,GAAG;AAC1B,WAAO;AAAA,EACT;AAEA,QAAM,aAAa,aAAa,OAAO,eAAe,CAAC;AACvD,QAAM,UAAU,aAAa,OAAO,YAAY,CAAC;AACjD,QAAM,YAAY,cAAc,OAAO,cAAc,CAAC;AAEtD,QAAM,MACJ,eAAe,UAAa,YAAY,UAAa,cAAc,SAC/D;AAAA,IACE,YAAY,cAAc,CAAC;AAAA,IAC3B,SAAS,WAAW,CAAC;AAAA,IACrB,WAAW,aAAa,CAAC;AAAA,EAC3B,IACA;AAEN,QAAM,sBAAsB,aAAa,OAAO,0BAA0B,CAAC;AAE3E,SAAO;AAAA,IACL;AAAA,IACA,OAAO,UAAU,OAAO,cAAc,GAAG,OAAO,cAAc,CAAC;AAAA,IAC/D,OAAO,UAAU,MAAM;AAAA,IACvB,eAAe,eAAe,OAAO,eAAe,CAAC;AAAA,IACrD,sBAAsB,eAAe,OAAO,sBAAsB,CAAC;AAAA,IACnE,oBAAoB,cAAc,OAAO,iBAAiB,CAAC,IACvD,OAAO,iBAAiB,IACxB;AAAA;AAAA;AAAA,IAGJ;AAAA,IACA,cAAc,iBAAiB,MAAM;AAAA,EACvC;AACF;AAGO,IAAM,gBAAgB,CAAC,WAC5B,EAAE,cAAc,MAAM,KAAK,OAAO,eAAe,MAAM;AAGlD,IAAM,6BAA6B,CAAC,WAA4B;AACrE,QAAM,MAAM,cAAc,MAAM,IAAI,OAAO,wBAAwB,IAAI;AAEvE,MAAI,OAAO,QAAQ,YAAY,IAAI,KAAK,EAAE,WAAW,GAAG;AACtD,WAAO,oCACL,gCACF;AAAA,EACF;AAEA,QAAM,aAAa,IAAI,KAAK,EAAE,YAAY;AAE1C,SAAO,oCAAoC,UAAU,KAAK,IAAI,KAAK;AACrE;;;ACjZO,IAAM,mCAAsD;AAAA,EACjE;AAAA,EACA;AAAA,EACA;AACF;AAyFO,IAAM,gCAAmD;AAAA,EAC9D;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA;AAAA;AAAA,EAGA;AAAA,EACA,GAAG;AACL;AAmBO,IAAM,4BAA4B,CACvC,kBACY;AACZ,MAAI,CAAC,MAAM,QAAQ,aAAa,KAAK,cAAc,WAAW,GAAG;AAC/D,WAAO;AAAA,EACT;AAEA,SAAO,cAAc;AAAA,IACnB,CAAC,UACC,OAAO,UAAU,YACjB,iCAAiC,SAAS,KAAK;AAAA,EACnD;AACF;AAqBO,IAAM,kBAAkB,CAC7B,UACA,gBACkB;AAClB,UAAQ,UAAU;AAAA,IAChB,KAAK;AACH,aAAO;AAAA,IACT,KAAK;AACH,aAAO,cAAc,SAAS;AAAA,IAChC,KAAK;AACH,aAAO;AAAA,IACT;AACE,aAAO;AAAA,EACX;AACF;AAGA,IAAM,oBAA8C,CAAC,QAAQ,SAAS;AAEtE,IAAM,oBAAuC;AAAA,EAC3C;AAAA,EACA;AAAA,EACA;AAAA,EACA;AACF;AAMO,IAAM,cAAc,CAAC,WAAkC;AAC5D,QAAM,KAAK,OAAO,MAAM;AAExB,MAAI,OAAO,OAAO,UAAU;AAC1B,WAAO;AAAA,EACT;AAEA,QAAM,QAAQ,GAAG,KAAK,EAAE,YAAY;AAEpC,SAAO,kBAAkB,SAAS,KAAK,IAAI,QAAQ;AACrD;AAEO,IAAM,mBAAmB,CAC9B,UACA,WACmB;AACnB,MAAI,OAAO,aAAa,YAAY;AAClC,WAAO;AAAA,EACT;AAKA,SAAO,kBAAkB,SAAS,QAAQ,IAAI,UAAU;AAC1D;AAOA,IAAM,SAAS,CAAC,UAA0B;AACxC,MAAI,OAAO;AAEX,WAAS,QAAQ,GAAG,QAAQ,MAAM,QAAQ,SAAS,GAAG;AACpD,YAAQ,MAAM,WAAW,KAAK;AAC9B,WAAO,KAAK,KAAK,MAAM,QAAU,MAAM;AAAA,EACzC;AAEA,SAAO,KAAK,SAAS,EAAE,EAAE,SAAS,GAAG,GAAG;AAC1C;AAUO,IAAM,qBAAqB,CAChC,QACA,kBACW;AACX,QAAM,QAAQ;AAAA,IACZ,OAAO;AAAA,IACP;AAAA,IACA,OAAO,UAAU,OAAO,SAAS,OAAO,MAAM,QAAQ,CAAC;AAAA,IACvD,OAAO,MAAM,MAAM;AAAA,IACnB,OAAO,cAAc,SAAS;AAAA,IAC9B,GAAG,OAAO,MAAM;AAAA,MACd,CAAC,UAAU,GAAG,MAAM,MAAM,IAAI,MAAM,OAAO,IAAI,MAAM,OAAO,QAAQ,CAAC,CAAC;AAAA,IACxE;AAAA,EACF;AAEA,SAAO,OAAO,MAAM,KAAK,GAAG,CAAC;AAC/B;AAOO,IAAM,eAAe,CAC1B,cACA,gBACW,MAAM,OAAO,YAAY,CAAC,IAAI,WAAW;AAG/C,IAAM,wBAAwB,CAAC,UAAkC;AACtE,MAAI,CAAC,cAAc,KAAK,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,QAAM,QAAQ,MAAM,aAAa;AAEjC,SAAO,OAAO,UAAU,YAAY,MAAM,SAAS,IAAI,QAAQ;AACjE;AAOO,IAAM,sBAAsB,CAAC,WAA4B;AAC9D,MAAI,CAAC,cAAc,MAAM,GAAG;AAC1B,WAAO;AAAA,EACT;AAEA,QAAM,OAAO,OAAO,MAAM;AAE1B,MAAI,cAAc,IAAI,GAAG;AACvB,UAAM,QAAQ,CAAC,KAAK,WAAW,GAAG,KAAK,UAAU,CAAC,EAC/C,OAAO,CAAC,SAAyB,OAAO,SAAS,QAAQ,EACzD,IAAI,CAAC,SAAS,KAAK,KAAK,CAAC,EACzB,OAAO,CAAC,SAAS,KAAK,SAAS,CAAC;AAEnC,QAAI,MAAM,SAAS,GAAG;AACpB,aAAO,MAAM,KAAK,GAAG;AAAA,IACvB;AAAA,EACF;AAEA,MAAI,OAAO,SAAS,YAAY,KAAK,KAAK,EAAE,SAAS,GAAG;AACtD,WAAO,KAAK,KAAK;AAAA,EACnB;AAEA,QAAM,SAAS,OAAO,QAAQ;AAE9B,MAAI,cAAc,MAAM,GAAG;AACzB,UAAM,UAAU,OAAO,cAAc;AAErC,QAAI,OAAO,YAAY,YAAY,QAAQ,KAAK,EAAE,SAAS,GAAG;AAC5D,aAAO,QAAQ,KAAK;AAAA,IACtB;AAAA,EACF;AAEA,QAAM,KAAK,OAAO,IAAI;AAEtB,SAAO,OAAO,OAAO,WAAW,KAAK;AACvC;AAwFA,IAAM,kBAAkB,CAAC,UAAmD;AAC1E,MAAI,CAAC,cAAc,KAAK,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,QAAM,aAAa,MAAM,YAAY;AAErC,MAAI,CAAC,cAAc,UAAU,GAAG;AAC9B,WAAO;AAAA,EACT;AAEA,QAAM,QAAQ,WAAW,OAAO;AAEhC,SAAO,cAAc,KAAK,IAAI,QAAQ;AACxC;AAEA,IAAM,yBAAyB,CAAC,UAA4B;AAC1D,MAAI,CAAC,cAAc,KAAK,GAAG;AACzB,WAAO;AAAA,EACT;AAEA,QAAM,aAAa,MAAM,YAAY;AAErC,SAAO,cAAc,UAAU,IAAI,WAAW,eAAe,IAAI;AACnE;AAEA,IAAM,eAAe,CACnB,OACA,WACkB;AAClB,MAAI,cAAc,KAAK,KAAK,OAAO,MAAM,UAAU,MAAM,UAAU;AACjE,WAAO,MAAM,UAAU;AAAA,EACzB;AAEA,MAAI,WAAW,QAAQ,OAAO,OAAO,IAAI,MAAM,UAAU;AACvD,WAAO,OAAO,IAAI;AAAA,EACpB;AAEA,SAAO;AACT;AAGO,IAAM,mBAAmB,OAC9B,WAC4C;AAC5C,QAAM,WAAW,MAAM,OAAO,MAAM;AAAA,IAClC,mBAAmB,EAAE,OAAO,EAAE,MAAM,0BAA0B,EAAE,EAAE;AAAA,EACpE,CAAC;AAED,SAAO,kBAAkB,oBAAoB,UAAU,mBAAmB,CAAC;AAC7E;AAWA,IAAM,iBAAiB,OACrB,QACA,WACqC;AACrC,QAAM,YAAY,OAAO,WAAW;AAEpC,MAAI,OAAO,cAAc,YAAY,UAAU,WAAW,GAAG;AAC3D,WAAO;AAAA,EACT;AAEA,MAAI,cAAc,OAAO,SAAS,CAAC,GAAG;AACpC,WAAO;AAAA,EACT;AAEA,MAAI;AACF,UAAM,WAAW,MAAM,OAAO,MAAM;AAAA,MAClC,WAAW;AAAA,QACT,QAAQ,EAAE,QAAQ,EAAE,IAAI,EAAE,IAAI,UAAU,EAAE,EAAE;AAAA,QAC5C,OAAO,EAAE,MAAM,EAAE,IAAI,MAAM,MAAM,KAAK,EAAE;AAAA,MAC1C;AAAA,IACF,CAAC;AAED,UAAM,CAAC,OAAO,IAAI,oBAAoB,UAAU,WAAW;AAE3D,WAAO,YAAY,SAAY,SAAS,EAAE,GAAG,QAAQ,QAAQ;AAAA,EAC/D,SAAS,OAAO;AACd,kBAAc,4BAA4B;AAAA,MACxC;AAAA,MACA,OAAO,cAAc,KAAK;AAAA,IAC5B,CAAC;AAED,WAAO;AAAA,EACT;AACF;AAiBA,IAAM,wBAAwB;AAQ9B,IAAM,qBAAqB,CAAC,WAC1B,OAAO,aAAa,aACpB,OAAO,MAAM;AAAA,EACX,CAAC,UAAU,MAAM,aAAa,cAAc,MAAM,YAAY;AAChE;AAqCF,IAAM,sBAAsB,OAC1B,SACA,cACA,eACA,WACwB;AACxB,MAAI,CAAC,kBAAkB,SAAS,aAAa,GAAG;AAI9C,WAAO,EAAE,UAAU,eAAe,UAAU,KAAK;AAAA,EACnD;AAEA,QAAM,MAAM,iBAAiB,uBAAuB,YAAY;AAEhE,MAAI,SAA+B;AAEnC,MAAI;AACF,aAAS,MAAM,QAAQ,IAAI,GAAG;AAAA,EAChC,SAAS,OAAO;AACd,kBAAc,8BAA8B;AAAA,MAC1C;AAAA,MACA,UAAU;AAAA,MACV,OAAO,cAAc,KAAK;AAAA,IAC5B,CAAC;AAED,WAAO,EAAE,UAAU,eAAe,UAAU,KAAK;AAAA,EACnD;AAEA,MAAI,WAAW,MAAM;AACnB,WAAO,EAAE,UAAU,eAAe,UAAU,KAAK;AAAA,EACnD;AAEA,MAAI,mBAAmB,MAAM,GAAG;AAC9B,QAAI;AACF,YAAM,QAAQ,OAAO,GAAG;AAAA,IAC1B,SAAS,OAAO;AACd,oBAAc,gCAAgC;AAAA,QAC5C;AAAA,QACA,OAAO,cAAc,KAAK;AAAA,MAC5B,CAAC;AAAA,IACH;AAEA,kBAAc,4BAA4B;AAAA,MACxC;AAAA,MACA,UAAU;AAAA,MACV,YAAY,OAAO;AAAA,IACrB,CAAC;AAED,WAAO,EAAE,UAAU,eAAe,UAAU,KAAK;AAAA,EACnD;AAEA,SAAO,EAAE,UAAU,QAAQ,UAAU,OAAO;AAC9C;AAEA,IAAM,oBAAoB,CACxB,QACA,SACA,aACA,eACA,WACA,iBAUA,wBAC6B;AAAA,EAC7B,aACE,uBAAuB,OACnB,EAAE,QAAQ,mBAAmB,IAC7B,EAAE,QAAQ,YAAY,SAAS,mBAAmB;AAAA,EACxD;AAAA,EACA;AAAA,EACA,eAAe,OAAO;AAAA,EACtB,UAAU,OAAO;AAAA,EACjB,OAAO,OAAO;AAAA,EACd,MAAM;AAAA,EACN,UAAU;AAAA,EACV,eAAe,OAAO;AAAA,EACtB,SAAS,OAAO;AAAA,EAChB,SAAS,CAAC,GAAG,OAAO,OAAO;AAAA,EAC3B,cAAc,OAAO;AAAA,EACrB,cAAc,OAAO,aAAa,IAAI,CAAC,WAAW,EAAE,GAAG,MAAM,EAAE;AAAA,EAC/D,OAAO,OAAO,MAAM,IAAI,CAAC,WAAW,EAAE,GAAG,MAAM,EAAE;AAAA;AAAA;AAAA;AAAA,EAIjD,GAAI,oBAAoB,OAAO,CAAC,IAAI,EAAE,gBAAgB;AACxD;AAuCA,IAAM,aAAa,OACjB,QACA,SAC2B;AAC3B,MAAI,WAAW,MAAM;AACnB,WAAO;AAAA,EACT;AAEA,QAAM,YAAY,sBAAsB,MAAM;AAE9C,MAAI,cAAc,MAAM;AACtB,WAAO;AAAA,EACT;AAEA,QAAM,SAAS,MAAM,KAAK,OAAO,WAAW,OAAO,OAAO;AAE1D,MAAI,CAAC,QAAQ;AACX,kBAAc,mCAAmC;AAAA,MAC/C,oBAAoB,OAAO,YAAY;AAAA,MACvC,OAAO,OAAO;AAAA,IAChB,CAAC;AAED,WAAO;AAAA,EACT;AAEA,SAAO;AACT;AAEA,IAAM,0BAA0B,OAC9B,aACA,MACA,QACuC;AACvC,MAAI,gBAAgB,QAAQ,gBAAgB,QAAW;AACrD,WAAO;AAAA,EACT;AAEA,MAAI;AACF,UAAM,SAAS,MAAM,YAAY,KAAK;AAOtC,UAAM,SAAS,MAAM,WAAW,QAAQ,IAAI;AAE5C,UAAM,WAAW,mBAAmB,EAAE,QAAQ,IAAI,CAAC;AAEnD,WAAO,SAAS,gBAAgB,OAC5B,OACA;AAAA,MACE,UAAU,kBAAkB,SAAS,WAAW;AAAA,MAChD,SAAS,SAAS,YAAY;AAAA,IAChC;AAAA,EACN,SAAS,OAAO;AACd,kBAAc,2BAA2B,EAAE,OAAO,cAAc,KAAK,EAAE,CAAC;AAExE,WAAO;AAAA,EACT;AACF;AAEO,IAAM,mBAAmB,OAAO;AAAA,EACrC;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA;AAAA,EACA,kBAAkB;AACpB,MAAmD;AACjD,QAAM,SAAS,gBAAgB,KAAK;AACpC,QAAM,eAAe,aAAa,OAAO,MAAM;AAI/C,MAAI,0BAA0B,uBAAuB,KAAK,CAAC,GAAG;AAC5D,WAAO,EAAE,QAAQ,WAAW,QAAQ,4BAA4B;AAAA,EAClE;AAEA,MAAI,WAAW,QAAQ,iBAAiB,MAAM;AAC5C,kBAAc,oBAAoB,EAAE,aAAa,CAAC;AAElD,WAAO,EAAE,QAAQ,WAAW,QAAQ,mBAAmB;AAAA,EACzD;AAEA,MAAI;AAGF,UAAM,eACJ,WAAW,SAAY,MAAM,iBAAiB,MAAM,IAAI,OAAO;AACjE,UAAM,cAAc,cAAc,YAAY;AAC9C,UAAM,yBAAyB,2BAA2B,YAAY;AAEtE,UAAM,WAAW,MAAM,eAAe,QAAQ,MAAM;AAEpD,UAAM,UAAU,MAAM;AAAA,MACpB;AAAA,MACA;AAAA,MACA;AAAA,IACF;AAOA,UAAM,SAAS,UAAU;AAAA,MACvB,MAAM,aAAa,QAAQ;AAAA,MAC3B;AAAA,MACA,QAAQ,qBAAqB,YAAY;AAAA,MACzC,UAAU,SAAS,YAAY;AAAA,IACjC,CAAC;AAED,UAAM,iBAAiB,gBAAgB,OAAO,UAAU,WAAW;AACnE,UAAM,MAAM,MAAM;AAAA,MAChB;AAAA,MACA;AAAA,MACA;AAAA,MACA;AAAA,IACF;AACA,UAAM,gBAAgB,IAAI;AAC1B,UAAM,YAAY,YAAY,MAAM;AAQpC,UAAM,cAAc,mBAAmB,QAAQ,aAAa;AAG5D,QAAI,sBAAsB,OAAO,iBAAiB,CAAC,MAAM,aAAa;AACpE,aAAO,EAAE,QAAQ,aAAa,cAAc,YAAY;AAAA,IAC1D;AAEA,UAAM,UAAU,aAAa,cAAc,WAAW;AACtD,UAAM,kBAAkB,oBAAoB,MAAM;AAClD,UAAM,YAAY,iBAAiB,eAAe,MAAM;AACxD,UAAM,eAAe;AAAA,MACnB;AAAA,MACA;AAAA,MACA;AAAA,MACA;AAAA,MACA;AAAA,MACA,IAAI,aAAa,OACb,OACA;AAAA,QACE;AAAA,QACA,YAAY,IAAI,SAAS;AAAA,QACzB,YAAY,IAAI,SAAS;AAAA,QACzB,YAAY,IAAI,SAAS;AAAA,MAC3B;AAAA,MACJ,SAAS,WAAW;AAAA,IACtB;AAIA,UAAM,iBACJ,IAAI,aAAa,OACb,KACA,kDAA6C,cAAc,yCAAyC,IAAI,SAAS,UAAU,KAAK,IAAI,SAAS,UAAU,KAAK,IAAI,SAAS,UAAU;AAUzL,UAAM,OAAO,SAAS;AAAA,MACpB,0BAA0B;AAAA,QACxB,QAAQ;AAAA,UACN,MAAM;AAAA,YACJ,MAAM,GAAG,SAAS,SAAM,eAAe,SAAM,OAAO,SAAS,QAAG;AAAA,YAChE;AAAA,YACA,YAAY,IAAI,YAAY;AAAA,YAC5B;AAAA,YACA;AAAA,YACA;AAAA,YACA,WAAW;AAAA,YACX,kBAAkB,qBAAqB,sBAAsB;AAAA,YAC7D,WAAW;AAAA,YACX,OAAO,OAAO;AAAA,YACd,MAAM;AAAA,YACN,UAAU;AAAA,YACV;AAAA,YACA;AAAA,UACF;AAAA,QACF;AAAA,QACA,IAAI;AAAA,MACN;AAAA,IACF,CAAC;AAED,UAAM,OAAO,SAAS;AAAA,MACpB,cAAc;AAAA,QACZ,QAAQ;AAAA,UACN,IAAI;AAAA,UACJ,MAAM;AAAA,YACJ,iBAAiB,OAAO;AAAA,YACxB,oBAAoB;AAAA,YACpB,iBAAiB;AAAA,UACnB;AAAA,QACF;AAAA,QACA,IAAI;AAAA,MACN;AAAA,IACF,CAAC;AAED,kBAAc,eAAe;AAAA,MAC3B;AAAA,MACA;AAAA,MACA,OAAO,OAAO;AAAA,MACd,MAAM;AAAA,MACN,UAAU;AAAA,MACV;AAAA,MACA,eAAe,IAAI,aAAa;AAAA,MAChC,cAAc,OAAO;AAAA,MACrB,oBAAoB,SAAS,WAAW;AAAA,MACxC,cAAc,OAAO,aAAa;AAAA,IACpC,CAAC;AAED,WAAO;AAAA,MACL,QAAQ;AAAA,MACR;AAAA,MACA;AAAA,MACA,UAAU;AAAA,MACV,OAAO,OAAO;AAAA,IAChB;AAAA,EACF,SAAS,OAAO;AACd,UAAM,UAAU,cAAc,KAAK;AAEnC,kBAAc,kBAAkB,EAAE,cAAc,OAAO,QAAQ,CAAC;AAEhE,UAAM,aAAa,QAAQ,cAAc,QAAQ,KAAK,OAAO;AAE7D,WAAO,EAAE,QAAQ,UAAU,cAAc,OAAO,QAAQ;AAAA,EAC1D;AACF;AAOA,IAAM,eAAe,OACnB,QACA,cACA,QACA,KACA,UACkB;AAClB,QAAM,UAAU,aAAa,cAAc,OAAO,KAAK,CAAC;AACxD,QAAM,kBAAkB,oBAAoB,MAAM;AAElD,QAAM,eAAe;AAAA,IACnB;AAAA;AAAA,IAEA,eAAe;AAAA,IACf,UAAU,IAAI,YAAY;AAAA,IAC1B,OAAO;AAAA,IACP,MAAM;AAAA,IACN,UAAU;AAAA,IACV,SACE;AAAA,IACF,SAAS,CAAC,KAAK;AAAA,IACf,OAAO,CAAC;AAAA,EACV;AAEA,MAAI;AACF,UAAM,OAAO,SAAS;AAAA,MACpB,0BAA0B;AAAA,QACxB,QAAQ;AAAA,UACN,MAAM;AAAA,YACJ,MAAM,cAAW,eAAe;AAAA,YAChC,WAAW;AAAA,YACX,YAAY,IAAI,YAAY;AAAA,YAC5B,wBAAwB;AAAA,YACxB;AAAA,YACA;AAAA,YACA,WAAW;AAAA,YACX,kBAAkB,qBAAqB,sBAAsB;AAAA,YAC7D,WAAW;AAAA,YACX,OAAO;AAAA,YACP,MAAM;AAAA,YACN,UAAU;AAAA,YACV,gBAAgB;AAAA,YAChB;AAAA,UACF;AAAA,QACF;AAAA,QACA,IAAI;AAAA,MACN;AAAA,IACF,CAAC;AAAA,EACH,SAAS,YAAY;AACnB,kBAAc,gCAAgC;AAAA,MAC5C;AAAA,MACA,OAAO,cAAc,UAAU;AAAA,IACjC,CAAC;AAAA,EACH;AAEA,MAAI;AACF,UAAM,OAAO,SAAS;AAAA,MACpB,cAAc;AAAA,QACZ,QAAQ;AAAA,UACN,IAAI;AAAA,UACJ,MAAM;AAAA,YACJ,oBAAoB;AAAA,YACpB,iBAAiB;AAAA,UACnB;AAAA,QACF;AAAA,QACA,IAAI;AAAA,MACN;AAAA,IACF,CAAC;AAAA,EACH,SAAS,aAAa;AACpB,kBAAc,iCAAiC;AAAA,MAC7C;AAAA,MACA,OAAO,cAAc,WAAW;AAAA,IAClC,CAAC;AAAA,EACH;AACF;;;AnD5jCA,IAAM,UAAU,OAAO,UACrB,iBAAiB;AAAA,EACf,QAAQ,IAAI,cAAc;AAAA,EAC1B;AAAA,EACA,KAAK,oBAAI,KAAK;AAAA,EACd,SAAS;AAAA,EACT,aAAa;AAAA,EACb,iBAAiB,qBAAqB,uBAAuB,EAAE,UAAU;AAC3E,CAAC;AAEH,IAAO,8CAAQ,oBAAoB;AAAA,EACjC,qBAAqB;AAAA,EACrB,MAAM;AAAA,EACN,aACE;AAAA;AAAA,EAEF,gBAAgB;AAAA,EAChB;AAAA,EACA,8BAA8B;AAAA,IAC5B,WAAW;AAAA,IACX,eAAe,CAAC,GAAG,6BAA6B;AAAA,EAClD;AACF,CAAC;",
  "names": ["s", "n", "e", "t", "t", "n", "r", "e", "t", "n", "cacheAgeMs", "b", "b"]
}
