import type { SecretSource } from "../actions/presets/index.js"; import { type ActAs, type Membership, type PermissionGrant, type Principal } from "../core/index.js"; import type { HostAuthPreset, HostAuthPresetUser, HostAuthPresetUserResolver } from "./shared.js"; /** Internal machinery shared by the named host-identity presets (09 §2.1). authJs (the template preset) predates this file and keeps its own copy of the same moves; the public surface stays the preset functions themselves. */ export type JwtClaims = Record; export declare function claimString(claims: JwtClaims, key: string): string | undefined; /** The presets' default claims→user mapping: display from the `name` claim, falling back to `email`; email from `email` (feeds actAs claims only). */ export declare function userFromNameEmailClaims(claims: JwtClaims): HostAuthPresetUser; /** One identity lookup for all three seams: the host's subject→user resolver when configured (null = subject unknown → decline), else the system's claims-derived defaults. `claims` is {} where no token exists (actAs minting, the door's subject lookup). */ export declare function makeUserResolver(user: HostAuthPresetUserResolver | undefined, defaults: (claims: JwtClaims) => HostAuthPresetUser): (subject: string, claims: JwtClaims) => Promise; /** Bridge the subject→user resolver into an actions-preset claims resolver: null still declines the mint; display/email become session claims. */ export declare function actAsClaimsFromUser(user: HostAuthPresetUserResolver, toClaims?: (resolved: HostAuthPresetUser) => JwtClaims): (principal: Principal, grant: PermissionGrant) => Promise; /** Per-call secret resolution (authJs's resolveAuthSecret pattern): default to the system's own env variable, resolved lazily so composition order never races env loading; absence fails loud with the fix in hand. */ export declare function resolvePresetSecret(source: SecretSource | undefined, environmentName: string | undefined, missingMessage: string): Promise; /** The operator-set FULL public URL (VENDO_BASE_URL — path prefix included) or, failing that, the request's own origin. Spec 2026-08-06 §B1: nothing strips the configured path, which is how the login redirect used to land on /login instead of /maple/login (#866). */ export declare function publicUrl(request: Request): URL; export declare function requestCookies(request: Request): [name: string, value: string][]; export declare function cookieValue(request: Request, name: string): string | undefined; export declare function bearerToken(request: Request): string | undefined; /** Optional-SDK loader mirroring authJs's loadGetToken: cached on success, reset on failure so a later call retries after an install, and an import failure surfaces the actionable install instruction, never a bare module-not-found. */ export declare function lazyModule(load: () => Promise, missingMessage: string): () => Promise; /** ActAs built lazily on FIRST MINT and cached (authJs's pattern, its TokenCache surviving across calls): env-dependent secrets and posture resolve at use time, never racing env loading at composition. */ export declare function lazyActAs(build: () => ActAs): ActAs; /** {login}?returnTo= on the deployment's public URL (authJs parity). The default target is `{public}/login`, overridable per deployment with VENDO_LOGIN_URL — which may be absolute, on another domain. Systems whose own convention demands it pass a different path (Clerk's /sign-in, Auth0's /auth/login) or extra params — never a new preset option. */ export declare function loginRedirect(request: Request, returnTo: string, path?: string, extraParams?: Record): Response; export interface ComposeHostAuthPresetOptions { /** See HostAuthPreset.name. REQUIRED here, optional there: a shipped preset may not forget to say which one it is, and a host-composed preset has nothing to say. */ name: string; /** Decode + verify the request's host session; null = no/invalid session. */ sessionClaims(request: Request): Promise; /** One identity lookup for all three seams ({} claims where none exist). */ resolveUser(subject: string, claims: JwtClaims): Promise; actAs: ActAs; /** The sessionless-door redirect (10-mcp §3). */ login(request: Request, returnTo: string): Response; /** Build contract §9.1 — forwarded verbatim; presets never interpret it. */ memberships?: (principal: Principal) => Promise; } /** The three-seam shape every named preset shares (authJs is the template): only session decoding, identity defaults, the mint, and the login target differ per system. The door's oauth half owns consent/CSRF/replay; this only supplies session lookup + subject resolution (10-mcp §3). */ export declare function composeHostAuthPreset(opts: ComposeHostAuthPresetOptions): HostAuthPreset;