import { type AppAccess } from "@vendoai/core"; import type { VendoStore } from "../store.js"; /** Build contract §9.3 — the SHAPES and the PURE rules (the principal grammar, * the level order, the path rules) live in core, so the apps runtime's test * stand-in resolves access through the very same functions; only the ROW * reading is here, because only the store can do it. */ export type { AccessLevel, AppAccess, AppGrantRecord, CanThing, GrantPrincipal } from "@vendoai/core"; export { appOfOrgPath, isGrantPrincipal, orgOfPath, parseGrantPrincipal } from "@vendoai/core"; /** * Build contract §9.3 — `can()`, one function, three doors (the workspace * façade, the wire, and the MCP door all reach it through the apps runtime). * * It is OSS and NEVER key-conditional: with no Cloud key no grant row can be * written, so it simply degenerates to "is it yours?" (§9.6). Memberships come * from the ctx ONLY — the host asserted them this request and `can()` never * queries an org chart, because Vendo does not have one (§9.1). * * Every row is read and written through the `engine` family, never raw SQL: * multi-party deployments are exactly the ones running on a hosted store, which * has no local db handle. `vendo_apps` and `vendo_app_grants` are Vendo's OWN * drawers, so they are named to the family that knows that (the allowlist gate * in front, the same routed doors behind) rather than to the generic * `records.*` door a host reaches its own rows through. * * The store's own `ops` when it carries one — the hosted store does, and its * client is one hop shorter than its `records` façade, which is built on these * very ops. Otherwise the family over the adapter's record doors * (`engineOverAdapter`), which is what a store this package minted and every * host's BYO adapter gets. No `ops` parameter: unlike guard or mcp, this helper * lives INSIDE @vendoai/store and takes the store itself, whose `ops` slot * (store.ts:17-22) already IS the surface a composition would have threaded. */ export declare function appAccess(store: VendoStore): AppAccess; //# sourceMappingURL=app-access.d.ts.map