import type { DKGAgent } from '@origintrail-official/dkg-agent'; /** * The read-authority decision that admits a caller to a Context Graph's * subscription. It is the single admission boundary for subscribe, and for * every route that follows a name hash to the cleartext id it resolves to, * so those routes cannot drift apart. The caller is the request's agent, or * the node's default agent for a node-level token. The legacy subscription * fallback stays off: a subscription cannot be its own authorization proof. * Each route maps the decision itself; a throw is the route's to handle. */ export declare function readContextGraphSubscriptionAdmission(agent: DKGAgent, contextGraphId: string, requestAgentAddress: string | undefined): Promise<{ callerAgentAddress: string | undefined; authority: Awaited>; }>; /** The caller of a route that follows a public reference to a Context Graph row. */ export interface ContextGraphFollowCaller { /** The request carries node-operator authority. */ readonly isNodeAdmin: boolean; /** The request's agent, if any; the node's default agent stands in otherwise. */ readonly agentAddress: string | undefined; } /** * Whether `caller` may follow a public reference to `contextGraphId`, the * cleartext id this node resolved it to. The node operator can already list * every subscription, so it follows without a read. Any other caller follows * only when the subscribe route would admit it to that id. An admission read * that throws is `unavailable`; each route decides how it answers a refusal * and an outage. */ export declare function admitContextGraphFollow(agent: DKGAgent, contextGraphId: string, caller: ContextGraphFollowCaller): Promise<'allowed' | 'denied' | 'unavailable'>; //# sourceMappingURL=context-graph-subscription-admission.d.ts.map