{"version":3,"file":"irs-B3kbyWmK-ZaM_ZVaW.d.mts","names":["o","EvmCompatibleNetworkConfig","n","CapabilityExecutor","t","SignAndBroadcast","Abi","Chain","TransactionReceipt","ClaimPayload","DeployOnchainIdConfirmedResult","DeployOnchainIdOutcome","DeployOnchainIdSubmittedResult","ExecutionConfig","IRSCapability","IdentityRegistration","NetworkConfig","OnboardingClaim","OnchainIdLookup","OperationResult","TransactionStatusUpdate","TxStatus","BuildClaimPayloadInput","buildClaimPayload","IdentityKeyPurposeLookup","Error","getOnchainId","Promise","isVerified","getJurisdiction","isTrustedIssuer","FactoryIdentityLookup","DeployReceiptWaitOptions","EvmIRSAddresses","EvmIRSExecutor","EvmIRSServiceOptions","EvmIRSService","createEvmIRSService","CreateIRSOptions","EvmIRSCapability","createIRS","_","a","c","d","f","g","h","i","l","m","p","r","s","u"],"sources":["../../adapter-evm-core/dist/irs-B3kbyWmK.d.mts"],"sourcesContent":["import { o as EvmCompatibleNetworkConfig } from \"./index-CmTidOM3.mjs\";\nimport { n as CapabilityExecutor, t as SignAndBroadcast } from \"./helpers-ZShvV2Sa.mjs\";\nimport { Abi, Chain, TransactionReceipt } from \"viem\";\nimport { ClaimPayload, DeployOnchainIdConfirmedResult, DeployOnchainIdOutcome, DeployOnchainIdSubmittedResult, ExecutionConfig, IRSCapability, IdentityRegistration, NetworkConfig, OnboardingClaim, OnchainIdLookup, OperationResult, TransactionStatusUpdate, TxStatus } from \"@openzeppelin/ui-types\";\n\n//#region src/irs/claim-payload.d.ts\n\n/**\n * Parameters for {@link buildClaimPayload}.\n */\ninterface BuildClaimPayloadInput {\n  /** The holder's ONCHAINID contract address. */\n  onchainId: string;\n  /** Claim topic. For ERC-3643 this is a uint256 — provide its decimal string form. */\n  topic: string;\n  /** Signature scheme (e.g. 1 for ECDSA). */\n  scheme: number;\n  /** Hex-encoded claim data (`0x`-prefixed). */\n  data: string;\n}\n/**\n * Build the canonical, signable claim digest for an ONCHAINID claim.\n *\n * Pure and key-free: identical inputs always yield identical output, with no RPC\n * and no signing.\n *\n * @param input - The ONCHAINID address, topic, scheme, and hex-encoded data.\n * @returns The {@link ClaimPayload} with the digest to sign and the echoed fields.\n */\ndeclare function buildClaimPayload(input: BuildClaimPayloadInput): ClaimPayload;\n//#endregion\n//#region src/irs/identity-keys.d.ts\n/**\n * Result of probing `keyHasPurpose` on an ONCHAINID identity.\n *\n * `lacks` (on-chain false) is distinct from `read_failed` (RPC/transport failure).\n */\ntype IdentityKeyPurposeLookup = {\n  readonly status: 'has';\n} | {\n  readonly status: 'lacks';\n} | {\n  readonly status: 'read_failed';\n  readonly cause: Error;\n};\n//#endregion\n//#region src/irs/onchain-reader.d.ts\n/**\n * Look up the ONCHAINID registered for `holder` in the identity registry.\n *\n * @returns `{ found: true, onchainId }` when registered, `{ found: false }` otherwise.\n * @throws {IdentityOperationFailed} On RPC failure (not for the expected-negative case).\n */\ndeclare function getOnchainId(rpcUrl: string, registryAddress: string, holder: string, viemChain?: Chain): Promise<OnchainIdLookup>;\n/**\n * The IRS verification pre-check. Returns `false` (never throws) for an unregistered\n * or unverifiable holder.\n */\ndeclare function isVerified(rpcUrl: string, registryAddress: string, holder: string, viemChain?: Chain): Promise<boolean>;\n/**\n * Read the holder's jurisdiction (ISO-3166 numeric country code) as a string.\n * Returns `undefined` when unavailable (e.g. unregistered holder).\n */\ndeclare function getJurisdiction(rpcUrl: string, registryAddress: string, holder: string, viemChain?: Chain): Promise<string | undefined>;\n/**\n * Whether `issuer` is already registered in the Trusted Issuers Registry.\n * Returns `false` (never throws) when the read is unavailable, enabling idempotent writes.\n */\ndeclare function isTrustedIssuer(rpcUrl: string, trustedIssuersRegistry: string, issuer: string, viemChain?: Chain): Promise<boolean>;\n/**\n * Resolve the ONCHAINID deployed for a wallet via the identity factory.\n *\n * @returns Explicit lookup — `not_found` (zero address) is distinct from `read_failed`.\n */\ntype FactoryIdentityLookup = {\n  readonly status: 'found';\n  readonly onchainId: string;\n} | {\n  readonly status: 'not_found';\n} | {\n  readonly status: 'read_failed';\n  readonly cause: Error;\n};\n//#endregion\n//#region src/irs/receipt-identity.d.ts\n\n/** Tunables for the deploy confirmation wait. */\ninterface DeployReceiptWaitOptions {\n  /**\n   * Confirmations to require. Must be an integer >= 1. Defaults to\n   * {@link DEFAULT_DEPLOY_CONFIRMATIONS}.\n   */\n  confirmations?: number;\n  /**\n   * Milliseconds before giving up. Must be a finite integer > 0. Defaults to\n   * {@link DEFAULT_DEPLOY_RECEIPT_TIMEOUT_MS}.\n   */\n  timeoutMs?: number;\n}\n//#endregion\n//#region src/irs/types.d.ts\n/**\n * Deployment-specific IRS / ONCHAINID contract addresses the capability operates against.\n *\n * Supplied by the consuming plugin at `createIRS` time, since the capability's methods\n * take holder/claim arguments rather than per-call contract addresses.\n */\ninterface EvmIRSAddresses {\n  /** ERC-3643 Identity Registry. */\n  identityRegistry: string;\n  /** ONCHAINID identity factory (IdFactory). */\n  identityFactory: string;\n  /** ERC-3643 Trusted Issuers Registry. */\n  trustedIssuersRegistry: string;\n}\n/**\n * Transaction executor callback — decouples the IRS service from wallet/signing.\n * Same shape as {@link CapabilityExecutor} (returns {@link WriteExecutionResult}).\n */\ntype EvmIRSExecutor = CapabilityExecutor;\n/**\n * Construction options for {@link EvmIRSService}.\n */\ninterface EvmIRSServiceOptions {\n  /** Deployment-specific IRS / ONCHAINID contract addresses. */\n  addresses: EvmIRSAddresses;\n  /**\n   * Default trusted-issuer identity address, used when an attached claim omits `issuer`.\n   * The capability never holds the issuer signing key — only this address.\n   */\n  trustedIssuer?: string;\n  /**\n   * Address that receives MANAGEMENT on deploy and executes `attachClaim` in the onboarding saga.\n   *\n   * Must be explicit — never inferred from the transaction signer, because the IdFactory\n   * `onlyOwner` caller may be a relayer contract distinct from the operator EOA.\n   */\n  operatorManagementKey: string;\n  /**\n   * Bounds on the `deployOnchainId` confirmation wait (confirmations + timeout).\n   *\n   * The wait is always bounded; this only tunes it. Raise the timeout on slow chains, but never\n   * remove the bound: an unbounded wait inside a server-side route is an outage. On timeout the\n   * deploy is reported as INDETERMINATE rather than failed, because the transaction may still land.\n   */\n  deployReceiptWait?: DeployReceiptWaitOptions;\n}\n//#endregion\n//#region src/irs/service.d.ts\n/**\n * EVM implementation of the IRS capability surface (sans the `RuntimeCapability` mixin).\n */\ndeclare class EvmIRSService {\n  private readonly networkConfig;\n  private readonly executeTransaction;\n  private readonly addresses;\n  private readonly trustedIssuer?;\n  private readonly operatorManagementKey;\n  /**\n   * Wait bounds, resolved AND VALIDATED at construction so a misconfiguration fails at boot\n   * rather than at the first deploy — where the failure would land on a real holder.\n   */\n  private readonly deployReceiptWait;\n  constructor(networkConfig: EvmCompatibleNetworkConfig, executeTransaction: EvmIRSExecutor, options: EvmIRSServiceOptions);\n  getOnchainId(holder: string): Promise<OnchainIdLookup>;\n  /**\n   * Factory linkage probe — distinct from registry `getOnchainId`.\n   * Used by resume/idempotency paths that must detect deployed-but-unregistered holders.\n   */\n  getFactoryIdentity(holder: string): Promise<FactoryIdentityLookup>;\n  /**\n   * Probe whether `address` holds `purpose` on an ONCHAINID identity.\n   *\n   * Used by resume/idempotency paths that must detect whether `grantHolderManagementKey`\n   * already ran — `read_failed` must not be treated as `lacks`.\n   */\n  hasIdentityKeyPurpose(input: {\n    onchainId: string;\n    address: string;\n    purpose: number;\n  }): Promise<IdentityKeyPurposeLookup>;\n  isVerified(holder: string): Promise<boolean>;\n  getJurisdiction(holder: string): Promise<string | undefined>;\n  buildClaimPayload(input: {\n    onchainId: string;\n    topic: string;\n    scheme: number;\n    data: string;\n  }): ClaimPayload;\n  /**\n   * Deploy a fresh ONCHAINID for `holder`.\n   *\n   * Uses `createIdentityWithManagementKeys` so the configured {@link operatorManagementKey}\n   * receives MANAGEMENT and can execute the subsequent saga steps (`attachClaim`, etc.).\n   * The holder is wallet-linked but does **not** receive MANAGEMENT until\n   * {@link grantHolderManagementKey} runs — that ordering is deliberate (see that method).\n   *\n   * **Pre-submit fidelity (SF-5):** probes {@link getFactoryIdentity} **before** execute\n   * (both completion modes). `found` → {@link IdentityAlreadyRegistered} (no submit);\n   * `read_failed` → {@link IdentityOperationFailed} ambiguous (no submit; never already-onboarded);\n   * `not_found` → today's path below.\n   *\n   * **Completion (SF-2):** trusts SF-1 `WriteExecutionResult.completion` from {@link execute}.\n   * - `completion === 'submitted'`: return `{ id, completion: 'submitted' }` with **no**\n   *   `onchainId`. Skips receipt wait, log parse, and operator MANAGEMENT assert. Caller owns\n   *   Relayer poll + {@link getFactoryIdentity} resume — submit-only `{ id }` is not proof the\n   *   identity deployed.\n   * - absent / `'confirmed'`: wait → parse → assert (byte-identical). Identity resolution parses\n   *   `WalletLinked` (falling back to `Deployed`) out of the receipt obtained by **waiting** for\n   *   confirmation — `waitForTransactionReceipt`, bounded by `deployReceiptWait`. Returns\n   *   `{ id, onchainId, completion: 'confirmed' }` with required `onchainId`.\n   *\n   * Confirmed-path terminal outcomes (unchanged retry semantics):\n   *  - confirmed + identity parsed  -> success\n   *  - confirmed + reverted         -> nothing created, retry is SAFE\n   *  - wait timed out               -> INDETERMINATE, may still land, DO NOT retry blind\n   *    (never mapped to already-onboarded — typed indeterminate OUT of SF-5)\n   *\n   * On the confirmed arm this method makes no assumption about whether the injected executor\n   * awaits confirmation; it establishes confirmation itself.\n   */\n  deployOnchainId(input: {\n    holder: string;\n  }, executionConfig: ExecutionConfig, onStatusChange?: (status: TxStatus, details: TransactionStatusUpdate) => void, runtimeApiKey?: string): Promise<DeployOnchainIdOutcome>;\n  /**\n   * Grant the holder a MANAGEMENT key on their ONCHAINID.\n   *\n   * **Saga ordering is load-bearing:** consumers MUST call this after `deployOnchainId` and\n   * **before** `attachClaim`. If attach-claim or register fails partway through onboarding, the\n   * holder already holds MANAGEMENT and can rescue their own identity. Running this after\n   * attach-claim would leave a partial failure with an identity only the operator can touch —\n   * a fresh orphan trap. Do not reorder for convenience.\n   *\n   * **Pre-submit fidelity (SF-5):** probes {@link lookupIdentityKeyPurpose} for MANAGEMENT\n   * **before** execute (both completion modes). Mirrors {@link registerIdentity} pre-read→throw:\n   * - `has` → {@link IdentityAlreadyRegistered} (`ALREADY_ONBOARDED`); no submit\n   * - `read_failed` → {@link IdentityOperationFailed} ambiguous; no submit\n   *   (never invent already-onboarded or lacks)\n   * - `lacks` → today's path below\n   *\n   * **Completion (SF-3):** trusts SF-1 `WriteExecutionResult.completion` from {@link execute}.\n   * - `completion === 'submitted'`: return `{ id }` without post-submit key-purpose assert.\n   *   Submit-only `{ id }` is **not** proof that MANAGEMENT landed — confirm via\n   *   {@link hasIdentityKeyPurpose} (or Relayer/WAL).\n   * - absent / `'confirmed'`: assert holder MANAGEMENT via `keyHasPurpose`; throw\n   *   {@link IdentityOperationFailed} on lacks / RPC fail (unchanged).\n   */\n  grantHolderManagementKey(input: {\n    onchainId: string;\n    holder: string;\n  }, executionConfig: ExecutionConfig, onStatusChange?: (status: TxStatus, details: TransactionStatusUpdate) => void, runtimeApiKey?: string): Promise<OperationResult>;\n  registerTrustedIssuer(input: {\n    issuer: string;\n    topics: string[];\n  }, executionConfig: ExecutionConfig, onStatusChange?: (status: TxStatus, details: TransactionStatusUpdate) => void, runtimeApiKey?: string): Promise<OperationResult>;\n  attachClaim(input: {\n    onchainId: string;\n    claim: OnboardingClaim;\n  }, executionConfig: ExecutionConfig, onStatusChange?: (status: TxStatus, details: TransactionStatusUpdate) => void, runtimeApiKey?: string): Promise<OperationResult>;\n  registerIdentity(input: IdentityRegistration, executionConfig: ExecutionConfig, onStatusChange?: (status: TxStatus, details: TransactionStatusUpdate) => void, runtimeApiKey?: string): Promise<OperationResult>;\n  dispose(): void;\n  private rpcUrl;\n  private assertIdentityKeyHasPurpose;\n  /**\n   * Typing hygiene (INV-22): `runCapabilityWrite` already returns {@link WriteExecutionResult}.\n   * Widening the annotation lets grant (and future SF-2 deploy) read `.completion` without casts.\n   * Runtime passthrough — no wrapper that could strip `completion`.\n   */\n  private execute;\n}\n/**\n * Factory for {@link EvmIRSService}.\n */\ndeclare function createEvmIRSService(networkConfig: EvmCompatibleNetworkConfig, executeTransaction: EvmIRSExecutor, options: EvmIRSServiceOptions): EvmIRSService;\n//#endregion\n//#region src/capabilities/irs.d.ts\n/**\n * Options for {@link createIRS}.\n *\n * `addresses` carries the deployment-specific IRS / ONCHAINID contract addresses (the\n * capability methods take holder/claim arguments rather than per-call addresses). The\n * capability never holds the trusted-issuer signing key — only the optional `trustedIssuer`\n * identity address used as a fallback when an attached claim omits its issuer.\n */\ninterface CreateIRSOptions {\n  signAndBroadcast: SignAndBroadcast;\n  addresses: EvmIRSAddresses;\n  /**\n   * Address that receives MANAGEMENT on deploy and executes `attachClaim` in the onboarding saga.\n   *\n   * Must be the operator EOA — never inferred from the transaction signer, because the IdFactory\n   * `onlyOwner` caller may be a relayer contract.\n   */\n  operatorManagementKey: string;\n  trustedIssuer?: string;\n  /**\n   * Bounds on the `deployOnchainId` confirmation wait (confirmations + timeout).\n   *\n   * Validated eagerly here, so an out-of-range bound throws at capability construction rather than\n   * on a holder's first deploy. See `DeployReceiptWaitOptions`.\n   */\n  deployReceiptWait?: DeployReceiptWaitOptions;\n}\n/**\n * EVM IRS capability surface.\n *\n * A **plain extension** of the shared `IRSCapability`: as of `@openzeppelin/ui-types` 3.5.0\n * `IRSCapability.deployOnchainId` already returns the completion-keyed\n * {@link DeployOnchainIdOutcome}, so submit-only is honestly typed by the shared interface\n * itself (INV-4 / INV-6) and `onchainId` is still never optionalized.\n *\n * This restores two-way assignability with `IRSCapability`: the previous\n * `Omit<IRSCapability, 'deployOnchainId'>` + local override widened the return type in a way\n * the shared interface rejected, so an `EvmIRSCapability` could not be passed where an\n * `IRSCapability` was expected. Locked by the INV-4 type guards in\n * `irs.deploy-submit-only.test.ts`.\n */\ninterface EvmIRSCapability extends IRSCapability {\n  getFactoryIdentity(holder: string): Promise<FactoryIdentityLookup>;\n  hasIdentityKeyPurpose(input: {\n    onchainId: string;\n    address: string;\n    purpose: number;\n  }): Promise<IdentityKeyPurposeLookup>;\n  grantHolderManagementKey(input: {\n    onchainId: string;\n    holder: string;\n  }, executionConfig: ExecutionConfig, onStatusChange?: (status: TxStatus, details: TransactionStatusUpdate) => void, runtimeApiKey?: string): Promise<OperationResult>;\n}\n/**\n * Create the EVM IRS / ONCHAINID capability.\n *\n * Mirrors {@link createAccessControl}: assembles the service, adapts the injected\n * `signAndBroadcast` into the service's executor, and wraps the result with\n * `guardRuntimeCapability` for the `RuntimeCapability` surface and idempotent `dispose()`.\n */\ndeclare function createIRS(config: NetworkConfig, options: CreateIRSOptions): EvmIRSCapability;\n//#endregion\nexport { buildClaimPayload as _, createEvmIRSService as a, EvmIRSServiceOptions as c, isTrustedIssuer as d, isVerified as f, DeployOnchainIdSubmittedResult as g, DeployOnchainIdOutcome as h, EvmIRSService as i, getJurisdiction as l, DeployOnchainIdConfirmedResult as m, EvmIRSCapability as n, EvmIRSAddresses as o, IdentityKeyPurposeLookup as p, createIRS as r, EvmIRSExecutor as s, CreateIRSOptions as t, getOnchainId as u };\n//# sourceMappingURL=irs-B3kbyWmK.d.mts.map"],"mappings":";;;;;;;;;;;;;KAqCKwB,wBAAAA;;;;;;kBAMaC;;;;;;;;;;;;;;;;KA+BbM,qBAAAA;;;;;;;kBAOaN;;;;;;UAMRO,wBAAAA;;;;;;;;;;;;;;;;;;;;UAoBAC,eAAAA;;;;;;;;;;;;;;;;;;;;;;;UAiLAK,gBAAAA;oBACUjC;aACP4B;;;;;;;;;;;;;;;sBAeSD;;;;;;;;;;;;;;;;UAgBZO,gBAAAA,SAAyBzB;sCACGa,QAAQI;;;;;MAKxCJ,QAAQH;;;;sBAIQX,2CAA2CQ,mBAAmBD,2DAA2DO,QAAQR;;;;;;;;;iBAStIqB,SAAAA,SAAkBxB,wBAAwBsB,mBAAmBC"}