/** * Lemma API v2 — identity store (Lane D) * * Persistence behind TenantResolver. Keys are stored as SHA-256 hashes only: * `key_hash` is the sole column that ever touches key material, and every write * is a parameterized insert that receives the hash, never the plaintext value. * * `InMemoryIdentityStore` powers unit tests and local/dev defaults. * `PostgresIdentityStore` is the production implementation over `pg`. */ import type { Pool } from 'pg'; import type { KeyPrefix } from './ApiKey'; import type { PlanId } from './PlanPolicy'; export interface NewKeyInput { tenantId: string; name: string; plan: PlanId; /** The persisted key derivation — sha256 of the plaintext. NEVER the key itself. */ hash: string; prefix: KeyPrefix; } export interface KeyRecord { id: string; tenantId: string; name: string; plan: PlanId; prefix: KeyPrefix; active: boolean; createdAt: number; expiresAt: number | null; revokedAt: number | null; } export interface IdentityStore { /** Look up a key by its hash. The ONLY read path — plaintext never enters a query. */ findKeyByHash(hash: string): Promise; /** Persist a new key. Callers pass the hash; `key_hash` is the only secret column. */ createKey(input: NewKeyInput): Promise; /** Soft-revoke: the key dies on the NEXT lookup. No 24h cache can survive this. */ revokeKey(keyId: string): Promise; } /** In-memory store. Records carry the hash only — same invariant as Postgres. */ export declare class InMemoryIdentityStore implements IdentityStore { readonly records: Map; findKeyByHash(hash: string): Promise; createKey(input: NewKeyInput): Promise; revokeKey(keyId: string): Promise; } /** Production store. All queries parameterized; key material appears only as hashed params. */ export declare class PostgresIdentityStore implements IdentityStore { private readonly pool; constructor(pool: Pool); findKeyByHash(hash: string): Promise; createKey(input: NewKeyInput): Promise; revokeKey(keyId: string): Promise; } //# sourceMappingURL=identityStore.d.ts.map