import type { Kysely } from 'kysely'; /** * Cross-origin preview. * * `?preview=1` worked only because the site and the CMS shared an origin, so the admin's session * cookie came along — the check was on the session, never on the parameter. Once the site is a * separate deployment that cookie is not sent, and there is nothing to check. * * A row rather than a signed token, following `login_challenges` for the same reasons: it has to be * revocable and short-lived, and a self-contained signed value stays valid however the account * changes underneath it. It also avoids inventing a signing secret, which would need a default to * keep `npm run dev` working and a default signing secret is not a secret. * * `id` is the SHA-256 of the token, as everywhere else, so the raw value exists only in the link. */ export declare function up(db: Kysely): Promise; export declare function down(db: Kysely): Promise;