/** * Shared machinery for the declarative login engines: resolving KDL values * (env overrides, obfuscation, hooks), `{placeholder}` templating, token * endpoint requests and token-response → `OAuthCredentials` projection. */ import type { CompiledAuthValue, CompiledCredentialMap, CompiledOAuthRequest, CompiledUserinfo } from "@oh-my-pi/pi-catalog/compat/types"; import type { FetchImpl } from "../../types.js"; import type { AfterExchangeHook, ExchangeContext, HeadersHook, LoginHook, RefreshHook } from "../hooks/types.js"; import type { OAuthCredentials } from "../oauth/types.js"; /** Far-future epoch ms: credentials that never expire (durable minted keys, session JWTs). */ export declare const NEVER_EXPIRES = 8640000000000000; /** Substitution values available to `{placeholder}` templates in KDL params/URLs. */ export type TemplateVars = Record; export declare function loadLoginHook(name: string): Promise; export declare function loadRefreshHook(name: string): Promise; export declare function loadAfterExchangeHook(name: string): Promise; export declare function loadHeadersHook(name: string): Promise; /** Resolves a KDL value node: env overrides first, then the (possibly encoded) literal or hook. */ export declare function resolveValue(value: CompiledAuthValue, signal?: AbortSignal): Promise; /** Replaces `{name}` placeholders; unknown or undefined placeholders resolve to the empty string. */ export declare function template(text: string, vars: TemplateVars): string; /** Reads a dot path (`data.user.email`) from a parsed JSON body. */ export declare function jsonPath(body: unknown, path: string): unknown; /** Decodes a JWT payload without verification; `null` for malformed tokens. */ export declare function decodeJwtPayload(token: string): Record | null; /** Epoch ms of a JWT `exp` claim minus `skewMs`, or undefined when absent. */ export declare function jwtExpiryMs(token: string, skewMs: number): number | undefined; /** * Projects a token response onto `OAuthCredentials` per the rule's * `credential` map. A missing refresh token keeps `previous.refresh` (refresh * grants that do not rotate) or falls back to the empty string. */ export declare function mapCredentials(map: CompiledCredentialMap, body: unknown, provider: string, previous?: OAuthCredentials): OAuthCredentials; export interface RequestContext { provider: string; fetch: FetchImpl; signal?: AbortSignal; /** Extra headers merged under the rule's declared headers. */ headers?: Record; } /** * Performs one declared token-style POST. `standardParams` are the grant's * baseline (included when the rule keeps `standard=#true`), `params` the * rule's declared extras; both are templated with `vars`. */ export declare function postTokenRequest(request: CompiledOAuthRequest, standardParams: Record, vars: TemplateVars, context: RequestContext, errorKind: "token-exchange" | "token-refresh" | "device-auth"): Promise<{ body: unknown; response: Response; }>; /** Bearer GET declared by `userinfo`; failures leave identity fields unset. */ export declare function applyUserinfo(userinfo: CompiledUserinfo | undefined, credentials: OAuthCredentials, context: RequestContext, vars?: TemplateVars): Promise; /** Runs the rule's after-exchange / after-refresh hook, if declared. */ export declare function applyAfterExchange(hook: string | undefined, credentials: OAuthCredentials, context: ExchangeContext): Promise; export declare function describeError(error: unknown): string; export declare function throwIfCancelled(signal: AbortSignal | undefined): void;