import { z } from 'zod'; /** * Acting as a principal with the REAL actor preserved (K-42, #868). * * Supporting a customer's live vertical means seeing what a named person sees. * Every platform grows that surface eventually, and the version that grows by * itself is a session swap: the staff member becomes the user, and the trail * says the user did it. That is the version an audit fails. * * So an impersonated operation carries **two** actors. The permission model * answers as the impersonated principal — that is the whole point, and an * intersection with the staff actor's own authority would be empty, because a * platform actor is not a principal in any tenant and holds no scope permissions * at all (`PlatformActorId` is branded apart from `PrincipalId` for exactly that * reason). What bounds the session instead is its MODE, its clock and its * reason: `read-only` unless someone wrote down why not, expiring on its own, * and admin-logged before it can be used. * * Every record the scope writes about who did what keeps both: the outbox * envelope, the denial log, the platform-intent journal. Stamped kernel-side on * K-34's pattern — `impersonation` is absent from `DomainEventInput`, so module * code can neither claim a session it is not in nor drop the one it is. */ /** * The hard ceiling on a session's life, in minutes. * * A support session is bounded because the alternative is a credential: a * session with no end is a second way to be that person, held by whoever last * opened one. K-33's rewind is time-boxed and audited on the same argument, and * the number is deliberately short enough that renewing is the normal case — * each renewal being a fresh admin-log row is the feature, not the friction. */ export declare const IMPERSONATION_MAX_MINUTES = 60; /** What a caller gets by not saying — a quarter hour, well inside the ceiling. */ export declare const IMPERSONATION_DEFAULT_MINUTES = 15; /** * The floor on a reason, in characters. * * Not a validation nicety: the reason is the only field of this record a human * writes, and 'x' passing means the field is decoration. Short enough that a * ticket reference ('#4182 — invoice missing') clears it. */ export declare const IMPERSONATION_MIN_REASON = 8; /** ULID, minted platform-side. Brands apart from every other id in the tree. */ export declare const impersonationSessionId: z.core.$ZodBranded; export type ImpersonationSessionId = z.infer; /** * What the session may do, and the answer to #868's last open question. * * `read-only` is most of the debugging value at a fraction of the argument, so * it is the default and it is MECHANICAL: a read-only invocation's transaction * is rolled back rather than committed, and the effecting verbs (`emit`, * `requestPlatform`, `grant`, `revoke`, `link`) refuse outright, so a support * engineer cannot approve an invoice by accident and a vertical cannot arrange * for them to. `write` exists because "reproduce the failing save" is a real * support task — it just has to be asked for, in a session that says so. */ export declare const impersonationMode: z.ZodEnum<{ "read-only": "read-only"; write: "write"; }>; export type ImpersonationMode = z.infer; /** * What staff supply to open a session. The acting actor is NOT here: it is the * `PlatformActorId` every `HostAdmin` verb already takes, so it can no more be * chosen by the caller than the actor on an admin-log row can. */ export declare const beginImpersonationInput: z.ZodObject<{ tenantId: z.core.$ZodBranded; scopeId: z.core.$ZodBranded; principal: z.core.$ZodBranded; reason: z.ZodString; minutes: z.ZodOptional; mode: z.ZodOptional>; }, z.core.$strip>; export type BeginImpersonationInput = z.infer; /** * A session as the directory holds it, and as `listImpersonations` reads it back. * * `endedAt` is the explicit close. It is distinct from expiry: a session that * ran out is over because time passed, one that was ended is over because * somebody stopped it, and an incident review wants to be able to tell those * apart. Neither is a delete — this record is evidence (K-21's tombstone rule). */ export declare const impersonationSession: z.ZodObject<{ id: z.core.$ZodBranded; actor: z.core.$ZodBranded; principal: z.core.$ZodBranded; tenantId: z.core.$ZodBranded; scopeId: z.core.$ZodBranded; reason: z.ZodString; mode: z.ZodEnum<{ "read-only": "read-only"; write: "write"; }>; startedAt: z.core.$ZodBranded; expiresAt: z.core.$ZodBranded; endedAt: z.ZodNullable>; }, z.core.$strip>; export type ImpersonationSession = z.infer; /** * The two actors a record keeps — the stamp the kernel puts on an event * envelope, a denial row and a platform intent raised under a session. * * `by` rather than `actor`, because the envelope's `actor` field is already * taken and already correct: the impersonated principal is who the permission * model answered about and who the domain fact is about. This says who was * holding the keyboard, which is a different question with a different answer. */ export declare const impersonationStamp: z.ZodObject<{ session: z.core.$ZodBranded; by: z.core.$ZodBranded; }, z.core.$strip>; export type ImpersonationStamp = z.infer; /** * How a caller narrows a read of the session log. `active` is evaluated against * the reader's clock — a session neither ended nor expired — because "who is in * a customer's data right now" is the question an incident opens with. */ export declare const impersonationFilter: z.ZodObject<{ tenantId: z.ZodOptional; scopeId: z.ZodOptional; actor: z.ZodOptional; principal: z.ZodOptional; active: z.ZodOptional; limit: z.ZodOptional; }, z.core.$strip>; export type ImpersonationFilter = z.infer; /** How many sessions an unbounded read returns — a screenful, newest first. */ export declare const DEFAULT_IMPERSONATION_LIMIT = 50; //# sourceMappingURL=impersonation.d.ts.map