import type { AuthCredential, OAuthCredential, SessionsApi } from "./types.js"; import type { AuthCredentialStore } from "./store.js"; import type { CredentialPool } from "./pool.js"; import type { KeyOverrides } from "./cascade.js"; /** Prefix for persisted session-to-credential affinity. */ export declare const SESSION_STICKY_CACHE_PREFIX = "session:sticky:"; /** A session's pinned credential (resolved index + durable row id). */ export type SessionCredential = { type: AuthCredential["type"]; index: number; credentialId?: number; lastUsedAtMs?: number; /** Set only by the public user-facing pin API; automatic warm affinity leaves it absent. */ explicit?: true; }; /** Session → credential affinity (pins), persisted in the store cache. */ export declare class SessionAffinity implements SessionsApi { #private; constructor(store: AuthCredentialStore, pool: CredentialPool, overrides: KeyOverrides); /** Drop every pin for a provider, both in memory and in the persisted cache. */ clearProvider(provider: string): void; /** Drop only this in-memory session pin after OAuth selection falls through. */ forget(provider: string, sessionId: string): void; /** * Records which credential was used for a session (for rate-limit switching). * `lastUsedAtMs` backdates the sticky (session-file pin restores on resume); * it defaults to now for live selections. Automatic re-recording of the same * durable row preserves an explicit user pin. * * The in-memory sticky is always exact. The persisted row is rewritten only * when the credential, its type, or explicitness changes, or when the stored * last-use drifts by {@link SESSION_STICKY_PERSIST_INTERVAL_MS} — per-request * rewrites were pure database churn. */ record(provider: string, sessionId: string | undefined, type: AuthCredential["type"], index: number, lastUsedAtMs?: number, explicit?: boolean): void; /** Retrieves the last credential used by a session. */ get(provider: string, sessionId: string | undefined): SessionCredential | undefined; /** Clears the last credential used by a session for a provider. */ clear(provider: string, sessionId: string | undefined): void; activeOAuth(provider: string, sessionId?: string): OAuthCredential | undefined; /** * Pin one stored OAuth account as this session's preferred credential. * * The durable credential id keeps the pin stable across credential refreshes, * storage reordering, and process restarts. By default this is an explicit * user pin: ranking and account reserve never evict it; hard unavailability * and auth retry may still route around it. * * `options.restoredAtMs` instead restores an automatic affinity recorded by a * persisted session, backdated to its last use, so it keeps the provider's * warm-window semantics: a resume inside the prompt-cache TTL reuses the * account, a stale resume re-ranks. */ pin(provider: string, sessionId: string, credentialId: number, options?: { restoredAtMs?: number; }): boolean; /** * Copy every stored credential affinity from one live session to another. * * The target receives its own sticky entries, so request resolution, usage * blocking, credential rotation, metadata, and persisted pins all continue * through the target session id without retaining a live dependency on the * source session. */ inherit(sourceSessionId: string, targetSessionId: string): number; /** * Release a session's sticky credential so its next `KeyCascade.get` call * re-runs native pool ranking. This never blocks or penalizes the released * account; usage-aware routing uses it when another sibling has more * headroom, before considering a model/provider fallback. */ release(provider: string, sessionId: string): boolean; }