import { InteractionActor, type AccessGrant, type FileAsset } from "@opengeni/contracts"; import { type ApiRouteDeps, type ResolvedSessionAuthorization } from "@opengeni/core"; import type { Hono } from "hono"; export declare function registerBrowserSessionRoutes(app: Hono, deps: ApiRouteDeps): void; export declare function browserNeedsStandaloneDisplayStack(input: { headless: boolean; linkedComputer: boolean; nativeBrowserControl: boolean; }): boolean; export declare function interactionActorForGrant(grant: AccessGrant): ReturnType; /** Resolve Drive authority from the same immutable session authorization that * admitted the browser action. Agent-attempt subjects are technical worker * identities; their frozen initiating human is the only personal Drive * principal. Pure service attempts retain null and can read only ordinary * workspace files through the database predicate. */ export declare function browserFileAuthoritySubjectId(grant: AccessGrant, authorization: ResolvedSessionAuthorization | null): string | null; /** The batch authority query intentionally omits every unauthorized file. Any * omission therefore fails the whole upload before an object-storage URL is * minted, including mixed ordinary/Drive mappings and partially authorized * batches. */ export declare function requireAuthorizedBrowserUploadFiles(workspaceFileIds: readonly string[], authorizedFiles: readonly FileAsset[]): FileAsset[];