import { OauthRegisterDto } from '../dtos/oauth.register.dto'; import { AccessBusinessService } from './access.business.service'; export declare class OauthProtocolError extends Error { readonly error: string; readonly status: number; readonly redirect_to?: string; constructor(error: string, message?: string, status?: number, redirect_to?: string); } export declare class OauthAsService { private readonly accessBusinessService; constructor(accessBusinessService: AccessBusinessService); issuer(): string; scopesSupported(): string[]; authorizationServerMetadata(): { issuer: string; authorization_endpoint: string; token_endpoint: string; registration_endpoint: string; response_types_supported: string[]; grant_types_supported: string[]; code_challenge_methods_supported: string[]; token_endpoint_auth_methods_supported: string[]; scopes_supported: string[]; }; register(dto: OauthRegisterDto): Promise<{ client_id: string; client_name: string; redirect_uris: string[]; grant_types: string[]; response_types: string[]; token_endpoint_auth_method: string; client_id_issued_at: number; }>; beginAuthorize(query: Record): Promise<{ kind: 'error_page'; error: string; message: string; } | { kind: 'consent_redirect'; url: string; } | { kind: 'protocol_redirect'; url: string; }>; postAuthorize(body: Record): Promise<{ authorization_id: number; }>; getConsent(authorizationId: number): Promise<{ status: "not_found"; authorization_id?: undefined; client_name?: undefined; redirect_host?: undefined; scope?: undefined; expires_at?: undefined; businesses?: undefined; } | { status: "decided"; authorization_id: number; client_name?: undefined; redirect_host?: undefined; scope?: undefined; expires_at?: undefined; businesses?: undefined; } | { status: "expired"; authorization_id: number; client_name?: undefined; redirect_host?: undefined; scope?: undefined; expires_at?: undefined; businesses?: undefined; } | { status: "pending"; authorization_id: number; client_name: string; redirect_host: string; scope: string; expires_at: Date; businesses: { id: number; name: string; role: string; is_current: boolean; }[]; }>; decideConsent(authorizationId: number, action: 'approve' | 'deny', businessId?: number): Promise<{ status: "already_decided"; redirect_to: string; } | { status: "denied"; redirect_to: string; } | { status: "approved"; redirect_to: string; }>; exchangeToken(body: Record): Promise<{ resource?: string; access_token: string; token_type: string; scope: string; }>; private mintPersonalKey; private resolveBusiness; private validateAuthorizeParams; private createPendingAuthorization; private errorRedirect; private frontendBase; private buildConsentHandoffUrl; }