import type { AuthContext } from '../../auth/AuthContext'; export interface InternalPodAccessTokenProvider { getTrustedFetch(owner: string, auth?: InternalPodAccessAuthContext, context?: InternalPodAccessRequestContext): Promise; } export type InternalPodAccessAuthContext = AuthContext | undefined; export interface InternalPodAccessRequestContext { /** Opaque label recorded for internal Pod access; no longer grants implicit authorization. */ reason?: string; /** Physical Pod root when the identity WebID is hosted by a separate IdP. */ podBaseUrl?: string; } export interface HostedPodDataAccessOptions { cssBaseUrl: string; gatewayAdminProxyAuthSecret?: string; fetch?: typeof fetch; now?: () => number; nonce?: () => string; } export declare const HOSTED_POD_RAW_BODY_MAX_BYTES: number; export declare class HostedPodDataAccess implements InternalPodAccessTokenProvider { private readonly cssBaseUrl; private readonly gatewayAdminProxyAuthSecret?; private readonly fetch; private readonly now; private readonly nonce; constructor(options: HostedPodDataAccessOptions); getTrustedFetch(owner: string, auth?: InternalPodAccessAuthContext, context?: InternalPodAccessRequestContext): Promise; private authorize; private assertHostedAllowedResource; private headersForLoopback; }