import { z } from 'zod'; import mongoose from 'mongoose'; import express from 'express'; interface BooleanObject { [key: string]: boolean; } interface AccessRouterPermissionMap { } type AccessRouterPermissionKey = Extract; type PermissionName = AccessRouterPermissionKey | (string & {}); declare class Permission { private readonly permissions; private readonly permissionKeys; constructor(permissions: BooleanObject); get keys(): readonly string[]; private normalizePermissionArgs; hasKey(permission: PermissionName): boolean; has(permission: PermissionName): boolean; hasAny(permissionOrPermissions: PermissionName | readonly PermissionName[], ...permissions: PermissionName[]): boolean; hasAll(permissionOrPermissions: PermissionName | readonly PermissionName[], ...permissions: PermissionName[]): boolean; } type Permissions = Permission; type AccessRouterPermissions = Permission; declare class Service extends Base { protected model: any; protected options: ModelRouterOptions; defaults: Defaults; protected baseFields: string[]; protected baseFieldsExt: string[]; findRawParentDoc(args: { filter: Filter; select: string; populate: unknown; lean: boolean; }): any; protected createModelAdapter(modelName: string): any; protected getModelRouterOptions(modelName: string): ModelRouterOptions; private asServiceHookContext; private beginOp; private completeOp; constructor(req: ModelRequest, modelName: string); findOne(filter: Filter, args?: FindOneArgs, options?: FindOneOptions): Promise | ErrorResult>; findById(id: string, args?: FindByIdArgs, options?: FindByIdOptions): Promise | ErrorResult>; find(filter: Filter, args?: FindArgs, options?: FindOptions, decorate?: (doc: unknown, context?: ModelHookContext) => unknown): Promise | ErrorResult>; create(data: Record | Record[], args?: CreateArgs, options?: CreateOptions, decorate?: (doc: unknown, context?: ModelHookContext) => unknown): Promise | ErrorResult>; private formatBulkValidationIssue; new(args?: { select?: string[]; }, options?: { skim?: boolean; includePermissions?: boolean; }): Promise>; updateOne(filter: Filter, data: Record, args?: UpdateOneArgs, options?: UpdateOneOptions, decorate?: (doc: unknown, context?: ModelHookContext) => unknown): Promise | ErrorResult>; updateById(id: string, data: Record, args?: UpdateByIdArgs, options?: UpdateByIdOptions, decorate?: (doc: unknown, context?: ModelHookContext) => unknown): Promise | ErrorResult>; upsert(filter: Filter, data: Record, args?: UpsertArgs, options?: UpsertOptions, decorate?: (doc: unknown, context?: ModelHookContext) => unknown): Promise>; delete(id: string): Promise | ErrorResult>; exists(filter: Filter, options: ExistsOptions & { includeId: true; }): Promise | ErrorResult>; exists(filter: Filter, options?: ExistsOptions): Promise | ErrorResult>; protected isValidDistinctFieldName(field: unknown): boolean; protected authorizeDistinctField(field: string): Promise; distinct(field: string, args?: DistinctArgs): Promise | ErrorResult>; count(filter: Filter, access?: BaseFilterAccess): Promise | ErrorResult>; /** * Trusted count for correlated includes (ACI-03): the caller already * resolved parent references, revalidated expanded operands, and applied * explicit `count` access via `genFilter`. This skips client-filter * validation and subquery parsing so substituted parent data stays inert. */ countTrusted(authorizedFilter: Filter): Promise | ErrorResult>; countByFieldValues(foreignField: string, values: unknown[], filter?: Filter, access?: BaseFilterAccess): Promise>> | ErrorResult>; getDocPermissions(doc: unknown): Record; private resolveFindOneArgs; private resolveFindOneOptions; private resolveFindByIdArgs; private resolveFindByIdOptions; private resolveFindArgs; private resolveFindOptions; private resolveCreateArgs; private resolveCreateOptions; private resolveUpdateOneArgs; private resolveUpdateOneOptions; private resolveUpdateByIdArgs; private resolveUpdateByIdOptions; private resolveUpsertArgs; private resolveUpsertOptions; private resolveExistsOptions; private getFieldPermissionAccess; private getAccessibleIdSet; listSub(id: SubdocumentId, sub: SubdocumentName, options?: SubdocumentListOptions): Promise; readSub(id: SubdocumentId, sub: SubdocumentName, subId: SubdocumentId, options?: SubdocumentReadOptions): Promise; updateSub(id: SubdocumentId, sub: SubdocumentName, subId: SubdocumentId, data: Record): Promise; bulkUpdateSub(id: SubdocumentId, sub: SubdocumentName, data: SubdocumentBulkUpdateInput | Record): Promise; createSub(id: SubdocumentId, sub: SubdocumentName, data: SubdocumentCreateInput, options?: SubdocumentCreateOptions): Promise; deleteSub(id: SubdocumentId, sub: SubdocumentName, subId: SubdocumentId): Promise; getParentDoc(id: SubdocumentId, sub: SubdocumentName, args?: SubdocumentParentArgs, options?: SubdocumentParentOptions): Promise; } declare class PublicService extends Service { _list(filter: Filter, args?: Omit & { select?: TSelect; populate?: TPopulate; }, options?: PublicListOptions): Promise> | ErrorResult>; _create(data: unknown, args?: Omit & { select?: TSelect; populate?: TPopulate; }, options?: PublicCreateOptions): Promise> | ErrorResult>; _new(args?: { select?: string[]; }, options?: { skim?: boolean; includePermissions?: boolean; }): Promise>>; _read(id: string, args?: Omit & { select?: TSelect; populate?: TPopulate; }, options?: PublicReadOptions): Promise> | ErrorResult>; _readFilter(filter: Filter, args?: Omit & { select?: TSelect; populate?: TPopulate; sort?: Sort; }, options?: PublicReadOptions): Promise> | ErrorResult>; _update(id: string, data: Record, args?: Omit & { select?: TSelect; populate?: TPopulate; }, options?: PublicUpdateOptions): Promise> | ErrorResult>; _upsert(data: Record, args?: Omit & { select?: TSelect; populate?: TPopulate; }, options?: PublicUpsertOptions): Promise> | ErrorResult>; _delete(id: string): Promise | ErrorResult>; _distinct(field: string, options?: DistinctArgs): Promise | ErrorResult>; _count(filter: Filter, access?: BaseFilterAccess): Promise | ErrorResult>; private resolvePublicListArgs; private resolvePublicListOptions; private resolvePublicCreateArgs; private resolvePublicCreateOptions; private resolvePublicReadArgs; private resolvePublicReadFilterArgs; private resolvePublicReadOptions; private resolvePublicUpdateArgs; private resolvePublicUpdateOptions; } type ValidationError = { detail: string; pointer?: string; parameter?: string; }; type RequestSchemaIssue = { message: string; path?: Array; }; type RequestSchemaSuccess = { success: true; data: T; }; type RequestSchemaFailure = { success: false; issues: RequestSchemaIssue[]; }; type RequestSchemaResult = RequestSchemaSuccess | RequestSchemaFailure; type RequestSchemaValidator = (value: unknown) => RequestSchemaResult | Promise>; type RequestSchemaAdapter = { validate: RequestSchemaValidator; openapi?: Record; }; type RequestSchemaOptions = { openapi?: Record; }; type StandardSchemaPathSegment = { key: PropertyKey; }; type StandardSchemaIssue = { message: string; path?: ReadonlyArray; }; type StandardSchemaSuccess = { value: T; issues?: undefined; }; type StandardSchemaFailure = { issues: ReadonlyArray; }; type StandardSchemaResult = StandardSchemaSuccess | StandardSchemaFailure; type StandardSchemaV1 = { readonly '~standard': { readonly version: 1; readonly vendor: string; readonly validate: (value: unknown, options?: { readonly libraryOptions?: Record | undefined; }) => StandardSchemaResult | Promise>; readonly types?: { readonly input: Input; readonly output: Output; }; }; }; type StandardSchemaInferOutput = NonNullable['output']; type RequestSchemaLike = RequestSchemaValidator | RequestSchemaAdapter | StandardSchemaV1; type YupValidationErrorLike = { name: 'ValidationError'; message: string; errors: ReadonlyArray; path?: string; inner?: ReadonlyArray; }; type YupSchemaLike = { validate: (value: unknown, options?: { abortEarly?: boolean; stripUnknown?: boolean; }) => Promise | T; }; type JoiValidationErrorDetailLike = { message: string; path?: ReadonlyArray; }; type JoiSchemaLike = { validate: (value: unknown, options?: { abortEarly?: boolean; stripUnknown?: boolean; }) => { value: T; error?: { details?: ReadonlyArray; }; } | Promise<{ value: T; error?: { details?: ReadonlyArray; }; }>; }; type AjvErrorObjectLike = { message?: string; instancePath?: string; schemaPath?: string; params?: { missingProperty?: string; }; }; type AjvValidationErrorLike = { errors?: ReadonlyArray | null; }; type AjvValidatorLike = { (value: unknown): boolean | Promise; errors?: ReadonlyArray | null; $async?: boolean; }; type ValibotPathItemLike = { key?: unknown; }; type ValibotIssueLike = { message: string; path?: ReadonlyArray; }; type ValibotSafeParseResult = { success: true; output: T; issues?: undefined; } | { success: false; output?: undefined; issues: ReadonlyArray; }; type ValibotSafeParseLike = (schema: TSchema, value: unknown, config?: { abortEarly?: boolean; }) => ValibotSafeParseResult | Promise>; type ArkTypeProblemLike = { path?: ReadonlyArray; message?: string; problem?: string; }; type ArkTypeErrorsLike = ReadonlyArray & { summary?: string; readonly arkKind?: string; readonly ' arkKind'?: string; }; type ArkTypeLike = { (value: unknown): T | ArkTypeErrorsLike | Promise; errors?: unknown; readonly '~standard'?: StandardSchemaV1['~standard']; }; type IoTsContextEntryLike = { key: string; }; type IoTsDecodeErrorLike = { message?: string; context: ReadonlyArray; }; type IoTsDecoderLike = { decode: (value: unknown) => { _tag: 'Left'; left: ReadonlyArray; } | { _tag: 'Right'; right: T; }; }; type SuperstructFailureLike = { message?: string; path?: ReadonlyArray; key?: string | number; branch?: ReadonlyArray; failures?: () => ReadonlyArray; }; type SuperstructValidateLike = (value: unknown, struct: TStruct) => readonly [failure: SuperstructFailureLike, value: undefined] | readonly [failure: undefined, value: TOutput] | Promise; type VineValidationMessageLike = { field: string; message: string; index?: number; }; type VineValidationErrorLike = { name?: string; code?: string; status?: number; messages: ReadonlyArray; }; type VineValidatorLike = { validate: (value: unknown) => Promise | T; }; type ListQueryInput = { skip?: string; limit?: string; page?: string; page_size?: string; skim?: 'true' | 'false'; include_permissions?: 'true' | 'false'; include_count?: 'true' | 'false'; include_extra_headers?: 'true' | 'false'; }; type CreateQueryInput = { include_permissions?: 'true' | 'false'; }; type ReadQueryInput = { include_permissions?: 'true' | 'false'; try_list?: 'true' | 'false'; }; type UpdateQueryInput = { returning_all?: 'true' | 'false'; }; type UpsertQueryInput = { returning_all?: 'true' | 'false'; include_permissions?: 'true' | 'false'; }; type AdvancedListBody = { filter?: Filter | unknown[]; select?: Projection; sort?: Sort; populate?: Populate[] | string; include?: Include | Include[]; tasks?: Task | Task[]; skip?: string | number; limit?: string | number; page?: string | number; pageSize?: string | number; options?: { skim?: boolean; includePermissions?: boolean; includeCount?: boolean; includeExtraHeaders?: boolean; populateAccess?: unknown; }; }; type CountBody = { filter?: Filter | unknown[]; }; type AdvancedReadFilterBody = { filter?: Filter | unknown[]; select?: Projection; sort?: Sort; populate?: Populate[] | string; include?: Include | Include[]; tasks?: Task | Task[]; options?: { skim?: boolean; includePermissions?: boolean; tryList?: boolean; populateAccess?: unknown; }; }; type AdvancedReadBody = { select?: Projection; populate?: Populate[] | string; include?: Include | Include[]; tasks?: Task | Task[]; options?: { skim?: boolean; includePermissions?: boolean; tryList?: boolean; populateAccess?: unknown; }; }; type AdvancedCreateBody = { data: unknown; select?: Projection; populate?: Populate[] | string; tasks?: Task | Task[]; options?: { includePermissions?: boolean; populateAccess?: unknown; }; }; type AdvancedUpdateBody = { data: unknown; select?: Projection; populate?: Populate[] | string; tasks?: Task | Task[]; options?: { returningAll?: boolean; includePermissions?: boolean; populateAccess?: unknown; }; }; type AdvancedUpsertBody = { data: Record; select?: Projection; populate?: Populate[] | string; tasks?: Task | Task[]; options?: { returningAll?: boolean; includePermissions?: boolean; populateAccess?: unknown; }; }; type DistinctBody = { filter?: Filter | unknown[]; }; type SubListBody = { filter?: Filter; select?: string[]; }; type SubReadBody = { select?: string[]; populate?: SubPopulate | SubPopulate[] | string | string[]; }; interface RequestComplexityOptions { maxDepth?: number; maxNodes?: number; maxLogicalClauses?: number; maxInValues?: number; maxBulkItems?: number; maxIncludeCount?: number; maxSubQueryCount?: number; maxBulkConcurrency?: number; maxHookConcurrency?: number; maxCorrelatedQueries?: number; maxCorrelatedDepth?: number; } declare class RequestConcurrencyScheduler { readonly limit: number; constructor(limit: number); map(items: TInput[], iteratee: (item: TInput, index: number, scheduled: true) => Promise): Promise; run(iteratee: (scheduled: true) => Promise): Promise; } type CrossResourceModelOperation = 'list' | 'read' | 'count'; interface CorrelatedExecState { totalQueries: number; scheduler: RequestConcurrencyScheduler; } declare class Base { protected req: ModelRequest; protected modelName: string; constructor(req: ModelRequest, modelName: string); decorate(doc: T, access: DecorateAccess, context: ModelHookContext): Promise; decorateAll(docs: T[], access: DecorateAllAccess, context: ModelHookContext): Promise; genAllowedFields(doc: unknown, access: SelectAccess, baseFields?: string[]): Promise; genDocPermissions(doc: unknown, access: DocPermissionsAccess, context: ModelHookContext): Promise>; genFilter(access?: BaseFilterAccess, filter?: Filter): Promise>; getIdentifier(): string | null; genIDFilter(id: string): Promise>; genPopulate(access?: SelectAccess, populate?: Populate | Populate[] | string | null, subPaths?: string[]): Promise; genSelect(access: SelectAccess, targetFields?: Projection, skipChecks?: boolean, subPaths?: string[]): Promise; genQuerySelect(access: SelectAccess, targetFields?: Projection, skipChecks?: boolean, subPaths?: string[]): Promise; addEmptyPermissions(doc: T): T; addDocPermissions(doc: T, access: DocPermissionsAccess, context: ModelHookContext): Promise; addFieldPermissions(doc: T, access: DocPermissionsAccess, context: ModelHookContext): Promise; pickAllowedFields(doc: T, access: SelectAccess, baseFields?: string[]): Promise; trimOutputFields(doc: T, access: SelectAccess, baseFields?: string[]): Promise; prepare(allowedData: T, access: PrepareAccess, context: ModelHookContext): Promise; runTasks(docObject: T, tasks: Task | Task[]): T; transform(doc: T, access: TransformAccess, context: ModelHookContext): Promise; afterPersist(doc: T, access: AfterPersistAccess, context: ModelHookContext): Promise; changes(doc: Record, context: ModelHookContext): Promise; beforeDelete(doc: T, context: ModelHookContext): Promise; afterDelete(doc: T, context: ModelHookContext): Promise; validate(allowedData: unknown, access: ValidateAccess, context: ModelHookContext): Promise; checkIfModelPermissionExists(accesses: DocPermissionsAccess[]): boolean; protected validateClientFilter(filter: Filter | null | undefined): string[]; getRequestComplexity(): Required; protected getClientRequestErrorResult(error: unknown): ErrorResult | null; protected throwClientRequestError(code: ErrorResult['code'], detail: string): never; protected getAuthorizedTargetService(modelName: string, op: CrossResourceModelOperation): Promise>; protected processInclude(include: Include | Include[]): { includes: LegacyInclude[]; correlatedIncludes: CorrelatedInclude[]; includeLocalFields: string[]; includePaths: string[]; correlatedReferenceFields: string[]; }; private getForeignKeyValues; private getForeignKey; private buildForeignKeyIndex; private getIndexedMatches; private getIndexedCount; private sanitizeIncludeArgs; private assertIncludeForeignField; protected includeDocs(docs: TDoc | TDoc[], include: Include | Include[]): Promise; private includeDocsRead; private includeDocsList; private includeDocsCount; protected getCorrelatedExecState(): CorrelatedExecState; protected claimCorrelatedQuerySlot(): void; private sanitizeCorrelatedArgs; protected includeCorrelatedDocs(docs: TDoc[], correlatedIncludes: CorrelatedInclude[], snapshots?: unknown[], depth?: number): Promise; private includeCorrelatedRead; private includeCorrelatedList; private includeCorrelatedCount; protected parseClientData(filter: TValue, scheduler?: RequestConcurrencyScheduler, scheduled?: boolean): Promise; private handleSubQuery; private handleDate; } declare class DataService { protected req: DataRequest; protected dataName: string; protected options: DataRouterOptions; protected data: T[]; constructor(req: DataRequest, dataName: string); findOne(filter: DataFilter, args?: DataFindOneArgs, options?: DataFindOneOptions): Promise> | ErrorResult>; findById(id: string, args?: DataFindOneArgs, options?: DataFindOneOptions): Promise> | ErrorResult>; find(filter: DataFilter, args?: DataFindArgs, options?: DataFindOptions): Promise> | ErrorResult>; decorate(doc: TDoc, access: DecorateAccess, context?: DataHookContext): Promise; decorateAll(docs: TDoc[], access: DecorateAllAccess, context?: DataHookContext): Promise; getRequestComplexity(): Required; genAllowedFields(doc: unknown, access: SelectAccess, baseFields?: string[]): Promise; genFilter(access?: BaseFilterAccess, filter?: DataFilter): Promise>; genIDFilter(id: string): Promise>; genSelect(access: SelectAccess, targetFields?: Projection, skipChecks?: boolean, subPaths?: string[]): Promise; genQuerySelect(access: SelectAccess, targetFields?: Projection, skipChecks?: boolean, subPaths?: string[]): Promise; pickAllowedFields(doc: TDoc, access: SelectAccess, baseFields?: string[]): Promise; trimOutputFields(doc: TDoc, access: SelectAccess, baseFields?: string[]): Promise; } type InternalModelHookContext = ModelHookContext & { fieldPermissionAccess?: { readIds?: Set; updateIds?: Set; }; }; declare class Core { private req; private caches; private cachedPermissions; constructor(req: AccessRouterBaseRequest); getIdentifier(modelName: string): string; genIDFilter(modelName: string, id: string): Promise>; genFilter(modelName: string, access?: BaseFilterAccess, _filter?: Filter): Promise>; private removePrefix; genAllowedFields(modelName: string, doc: unknown, access: SelectAccess, baseFields?: string[]): Promise; pickAllowedFields(modelName: string, doc: T, access: SelectAccess, baseFields?: string[]): Promise; genSelect(modelName: string, access: SelectAccess, targetFields?: Projection, skipChecks?: boolean, subPaths?: string[]): Promise; genPopulate(modelName: string, access?: SelectAccess | BaseFilterAccess, _populate?: Populate | Populate[] | string | null, subPaths?: string[]): Promise<(string | Populate)[]>; validate(modelName: string, allowedData: unknown, access: ValidateAccess, context: ModelHookContext): Promise; prepare(modelName: string, allowedData: T, access: PrepareAccess, context: ModelHookContext): Promise; transform(modelName: string, doc: T, access: TransformAccess, context: ModelHookContext): Promise; afterPersist(modelName: string, doc: T, access: AfterPersistAccess, context: ModelHookContext): Promise; changes(modelName: string, doc: Record, context: ModelHookContext): Promise; beforeDelete(modelName: string, doc: T, context: ModelHookContext): Promise; afterDelete(modelName: string, doc: T, context: ModelHookContext): Promise; genDocPermissions(modelName: string, doc: unknown, access: DocPermissionsAccess, context: ModelHookContext): Promise<{}>; addEmptyPermissions(modelName: string, doc: T): T; addDocPermissions(modelName: string, doc: T, access: DocPermissionsAccess, context: ModelHookContext): Promise; addFieldPermissions(modelName: string, doc: T, access: DocPermissionsAccess, context: InternalModelHookContext): Promise; decorate(modelName: string, doc: T, access: DecorateAccess, context: ModelHookContext): Promise; decorateAll(modelName: string, docs: T[], access: DecorateAllAccess, context: ModelHookContext): Promise; runTasks(modelName: string, docObject: T, task: Task | Task[]): T; getPermissions(): Permission; setPermissions(): Promise; canActivate(routeGuard: Validation): Promise; isAllowed(modelName: string, access: RouteGuardAccess | string): Promise; getService(modelName: string): Service; getPublicService(modelName: string): PublicService; service(modelName: string): PublicService; svc(modelName: string): PublicService; private getGlobalPermissions; } declare class DataCore { private req; private caches; private cachedPermissions; constructor(req: AccessRouterBaseRequest); genIDFilter(dataName: string, id: string): Promise>; genFilter(dataName: string, access?: BaseFilterAccess, _filter?: Filter): Promise>; genAllowedFields(dataName: string, _doc: unknown, access: SelectAccess, baseFields?: string[]): Promise; pickAllowedFields(dataName: string, doc: TDoc, access: SelectAccess, baseFields?: string[]): Promise; genSelect(dataName: string, access: SelectAccess, targetFields?: Projection, skipChecks?: boolean, subPaths?: string[]): Promise; decorate(dataName: string, doc: TDoc, access: DecorateAccess, context?: DataHookContext): Promise; decorateAll(dataName: string, docs: TDoc[], access: DecorateAllAccess, context?: DataHookContext): Promise; getPermissions(): Permission; setPermissions(): Promise; canActivate(routeGuard: Validation): Promise; isAllowed(dataName: string, access: RouteGuardAccess | string): Promise; getService(dataName: string): DataService; service(dataName: string): DataService; svc(dataName: string): DataService; private getGlobalPermissions; } declare enum StatusCodes { OK = 200, Created = 201, BadRequest = 400, Unauthorized = 401, Forbidden = 403, NotFound = 404, UnprocessableContent = 422 } declare enum Codes { Success = "success", Created = "created", BadRequest = "bad_request", Unauthorized = "unauthorized", Forbidden = "forbidden", NotFound = "not_found" } declare enum CustomHeaders { TotalCount = "wtt-total-count", ReturnedCount = "wtt-returned-count", Page = "wtt-page", PageSize = "wtt-page-size", TotalPages = "wtt-total-pages", HasNextPage = "wtt-has-next-page", HasPreviousPage = "wtt-has-previous-page" } declare enum FilterOperator { SubQuery = 0, Date = 1 } declare const MIDDLEWARE: unique symbol; declare const DATA_MIDDLEWARE: unique symbol; declare const PERMISSIONS: unique symbol; declare const PERMISSION_KEYS: unique symbol; interface AccessRouterRequestExtensions { macl?: Core; dacl?: DataCore; [PERMISSIONS]?: AccessRouterPermissions; [PERMISSION_KEYS]?: string[]; [MIDDLEWARE]?: unknown[] | unknown; [DATA_MIDDLEWARE]?: unknown[] | unknown; [key: string]: unknown; [key: symbol]: unknown; } type AccessRouterRequest = express.Request & AccessRouterRequestExtensions; interface PublicCreateArgs { select?: Projection; populate?: Populate[] | string; tasks?: Task | Task[]; } interface CreateArgs extends Omit { } interface PublicCreateOptions { skim?: boolean; includePermissions?: boolean; populateAccess?: PopulateAccess; } interface CreateOptions extends PublicCreateOptions { } interface PublicListArgs { select?: Projection; populate?: Populate[] | string; include?: Include | Include[]; sort?: Sort; skip?: string | number; limit?: string | number; page?: string | number; pageSize?: string | number; tasks?: Task | Task[]; } interface PublicListOptions { skim?: boolean; includePermissions?: boolean; includeCount?: boolean; populateAccess?: PopulateAccess; lean?: boolean; } interface PublicReadArgs { select?: Projection; populate?: Populate[] | string; include?: Include | Include[]; tasks?: Task | Task[]; } interface PublicReadOptions { skim?: boolean; populateAccess?: PopulateAccess; lean?: boolean; includePermissions?: boolean; tryList?: boolean; } interface PublicUpdateArgs { select?: Projection; populate?: Populate[] | string; tasks?: Task | Task[]; } interface PublicUpsertArgs extends PublicUpdateArgs { } interface UpdateOneArgs extends Omit { overrides?: { filter?: Filter; populate?: Populate[] | string; }; } interface UpdateByIdArgs extends Omit, 'overrides'> { overrides?: { populate?: Populate[] | string; idFilter?: Filter; }; } interface UpsertArgs extends UpdateOneArgs { } interface PublicUpdateOptions { skim?: boolean; returningAll?: boolean; includePermissions?: boolean; populateAccess?: PopulateAccess; } interface PublicUpsertOptions extends PublicUpdateOptions { } interface UpdateOneOptions extends Omit { } interface UpdateByIdOptions extends UpdateOneOptions { } interface UpsertOptions extends UpdateOneOptions { } type DataFilter = Filter; interface DataFindOneArgs { select?: TSelect; } interface DataFindOneOptions { access?: FindAccess; } interface DataFindArgs { select?: TSelect; sort?: Sort; skip?: string | number; limit?: string | number; page?: string | number; pageSize?: string | number; } interface DataFindOptions { } interface KeyValueProjection { [key: string]: 1 | -1; } type Projection = string[] | string | KeyValueProjection; type SortOrder = -1 | 1 | 'asc' | 'ascending' | 'desc' | 'descending'; type Sort = string | { [key: string]: SortOrder; } | [string, SortOrder][] | undefined | null; type Primitive = string | number | boolean | bigint | symbol | null | undefined; type NonTraversable = Primitive | Date | RegExp | Function; type PrevDepth = [never, 0, 1, 2, 3, 4, 5]; type IsUnknown = unknown extends T ? ([keyof T] extends [never] ? true : false) : false; type Descend = T extends readonly (infer U)[] ? U : T; type ArrayValue = T extends readonly (infer U)[] ? U : T; type ComparableValue = string | number | bigint | Date; type WithDefaultId = T extends object ? T & { _id?: unknown; } : { _id?: unknown; }; type PublicOutput = T extends object ? T & Record : Record; type ModelDocument = mongoose.Document & TModel; type TrimLeft = S extends ` ${infer Rest}` ? TrimLeft : S; type TrimRight = S extends `${infer Rest} ` ? TrimRight : S; type Trim = TrimLeft>; type SplitProjectionString = S extends `${infer Head} ${infer Tail}` ? SplitProjectionString | SplitProjectionString : Trim; type ProjectionTokens = TProjection extends readonly string[] ? TProjection[number] : TProjection extends string ? SplitProjectionString : TProjection extends KeyValueProjection ? { [K in Extract]: TProjection[K] extends 1 ? K : never; }[Extract] : never; type PositiveProjectionPaths = ProjectionTokens extends infer TToken ? TToken extends string ? TToken extends '' ? never : TToken extends `-${string}` ? never : TToken : never : never; type UnionToIntersection = (T extends unknown ? (value: T) => void : never) extends (value: infer I) => void ? I : never; type Simplify = { [K in keyof T]: T[K]; } & {}; type DeepPickSingle = TPath extends `${infer Head}.${infer Tail}` ? Head extends keyof WithDefaultId ? Head extends string ? { [K in Head]: WithDefaultId[K] extends readonly (infer U)[] ? Array>> : WithDefaultId[K] extends object ? Simplify[K], Tail>> : WithDefaultId[K]; } : {} : {} : TPath extends keyof WithDefaultId ? Pick, TPath> : {}; type DeepPick = Simplify>>; type SelectedPublicOutput = string extends PositiveProjectionPaths ? PublicOutput : [PositiveProjectionPaths] extends [never] ? PublicOutput : DeepPick, string>>; type PopulateInput = Populate | string; type PopulateInputs = TPopulate extends readonly (infer U)[] ? U : TPopulate; type PopulatePath = TPopulateEntry extends string ? TPopulateEntry : TPopulateEntry extends { path: infer TPath extends string; } ? TPath : never; type PopulateSelect = TPopulateEntry extends { select?: infer TSelect; } ? TSelect : undefined; type PopulateLeafValue = TValue extends readonly (infer U)[] ? Array>> : SelectedPublicOutput>; type PopulateEntryShape = TPath extends `${infer Head}.${infer Tail}` ? Head extends keyof WithDefaultId ? Head extends string ? { [K in Head]: WithDefaultId[K] extends readonly (infer U)[] ? Array>> : Simplify[K], Tail, TValue>>; } : {} : {} : TPath extends keyof WithDefaultId ? Pick<{ [K in TPath]: TValue; }, TPath> : {}; type PopulateOutputShape = PopulatePath extends infer TPath extends string ? PopulateEntryShape, TPath>, TPopulateEntry>> : {}; type PopulateOutput = string extends PopulatePath> ? {} : [PopulatePath>] extends [never] ? {} : Simplify, PopulateInput>>>>; type SelectedPopulatedPublicOutput = Simplify & PopulateOutput>; type Unwrap = NonNullable>; type DeepFieldPath = [Depth] extends [never] ? never : Unwrap extends NonTraversable ? never : { [K in Extract, string>]: K | (NonNullable[K]> extends NonTraversable ? never : NonNullable[K]> extends readonly (infer U)[] ? Unwrap extends NonTraversable ? never : `${K}.${DeepFieldPath}` : NonNullable[K]> extends object ? `${K}.${DeepFieldPath[K]>, PrevDepth[Depth]>}` : never); }[Extract, string>]; type PathValue = TPath extends `${infer Head}.${infer Tail}` ? Head extends Extract, string> ? PathValue[Head]>, Tail> : unknown : TPath extends Extract, string> ? Unwrap[TPath] : unknown; type FieldFilterOperators = { $eq?: T; $ne?: T; $in?: Array>; $nin?: Array>; $exists?: boolean; $gt?: ArrayValue extends ComparableValue ? ArrayValue : never; $gte?: ArrayValue extends ComparableValue ? ArrayValue : never; $lt?: ArrayValue extends ComparableValue ? ArrayValue : never; $lte?: ArrayValue extends ComparableValue ? ArrayValue : never; $regex?: ArrayValue extends string ? string | RegExp : never; $all?: T extends readonly unknown[] ? Array> : never; $size?: T extends readonly unknown[] ? number : never; $elemMatch?: ArrayValue extends object ? TypedFilter> : never; $$sq?: unknown; $$date?: unknown; [key: `$${string}`]: unknown; }; type FieldFilterValue = T | FieldFilterOperators>; type LooseFilter = false | Record; type TypedFilterObject = { [K in DeepFieldPath]?: FieldFilterValue>; } & { _id?: FieldFilterValue; $and?: TypedFilter[]; $or?: TypedFilter[]; $nor?: TypedFilter[]; [key: `$${string}`]: unknown; }; type TypedFilter = false | TypedFilterObject>; type Filter = IsUnknown extends true ? LooseFilter : TypedFilter; interface LegacyInclude { mode?: 'legacy'; model: string; op: 'list' | 'read' | 'count'; path: string; filter?: Filter; localField: string; foreignField: string; args?: unknown; options?: unknown; } /** * Explicit structural marker referencing a field of the immediate parent * document (ACI-01 D2.1). Recognized only in filter/id value positions of * correlated includes; magic `$field` strings are never markers. */ interface ParentRef { $parent: string; } /** Filter template for correlated includes; values may carry {@link ParentRef} markers. */ type CorrelatedFilter = Record; interface CorrelatedIncludeArgs { select?: Projection; sort?: Sort; skip?: number | string; limit?: number | string; page?: number | string; pageSize?: number | string; include?: Include | Include[]; } interface CorrelatedIncludeBase { mode: 'correlated'; model: string; op: 'list' | 'read' | 'count'; path: string; args?: CorrelatedIncludeArgs; options?: Record; } /** Identifier read: exactly one of `id` / `filter` must be present. */ interface CorrelatedReadByIdInclude extends CorrelatedIncludeBase { op: 'read'; id: string | ParentRef; filter?: never; } interface CorrelatedReadByFilterInclude extends CorrelatedIncludeBase { op: 'read'; filter: CorrelatedFilter; id?: never; } interface CorrelatedListInclude extends CorrelatedIncludeBase { op: 'list'; filter: CorrelatedFilter; id?: never; } interface CorrelatedCountInclude extends CorrelatedIncludeBase { op: 'count'; filter: CorrelatedFilter; id?: never; } type CorrelatedInclude = CorrelatedReadByIdInclude | CorrelatedReadByFilterInclude | CorrelatedListInclude | CorrelatedCountInclude; type Include = LegacyInclude | CorrelatedInclude; type FindAccess = 'list' | 'read'; type PopulateAccess = 'list' | 'read'; interface Populate { path: string; select?: Projection; match?: unknown; access?: PopulateAccess; } interface SubPopulate { path: string; select?: Projection; } type GuardHook = (this: TRequest, permissions: AccessRouterPermissions) => boolean | Promise; type Validation = boolean | string | string[] | GuardHook; type SelectAccess = 'list' | 'create' | 'read' | 'update' | string; type RouteGuardAccess = 'new' | 'list' | 'read' | 'update' | 'upsert' | 'delete' | 'create' | 'distinct' | 'count' | 'subs' | string; type DocPermissionsAccess = 'list' | 'create' | 'read' | 'update' | string; type BaseFilterAccess = 'list' | 'read' | 'update' | 'delete' | string; type DecorateAccess = 'list' | 'create' | 'read' | 'update' | string; type DecorateAllAccess = 'list' | string; type ValidateAccess = 'create' | 'update' | string; type PrepareAccess = 'create' | 'update' | string; type TransformAccess = 'update' | string; type AfterPersistAccess = 'create' | 'update' | string; interface KeyValue { [key: string]: unknown; } interface Change { op: 'add' | 'replace' | 'remove'; path: Array; value?: unknown; } interface ModelHookContext { modelName: string; mongooseModel: mongoose.Model; operation?: string; originalDocumentSnapshot?: Record; finalDocumentSnapshot?: Record; currentDocument?: ModelDocument; originalData?: Record; allowedData?: Record; preparedData?: Record; allowedFields?: string[]; modifiedPaths?: string[]; changes?: Change[]; docPermissions?: KeyValue; resolvedQuery?: { filter?: Filter; select?: string[]; populate?: Populate[] | string; sort?: Sort; skip?: number; limit?: number; }; } interface DataHookContext { dataName?: string; operation?: string; resolvedQuery?: { filter?: Filter; select?: string[]; sort?: Sort; skip?: number; limit?: number; }; } type RootTarget = 'model' | 'data'; type RootSubOperation = 'subList' | 'subRead' | 'subCreate' | 'subUpdate' | 'subBulkUpdate' | 'subDelete'; type RootModelOperation = 'new' | 'list' | 'read' | 'create' | 'update' | 'upsert' | 'delete' | 'distinct' | 'count' | RootSubOperation; type RootDataOperation = 'list' | 'read'; interface RootQueryEntryBase { target: TTarget; name: string; op: TOp; order?: number; } interface RootModelNewQueryEntry extends RootQueryEntryBase<'model', 'new'> { args?: { select?: string[]; }; options?: { skim?: boolean; includePermissions?: boolean; }; } interface RootModelListQueryEntry extends RootQueryEntryBase<'model', 'list'> { filter?: Filter; args?: PublicListArgs; options?: PublicListOptions; } interface RootModelReadByIdQueryEntry extends RootQueryEntryBase<'model', 'read'> { id: string; args?: PublicReadArgs; options?: PublicReadOptions; } interface RootModelReadByFilterQueryEntry extends RootQueryEntryBase<'model', 'read'> { filter: Filter; args?: PublicReadArgs & { sort?: Sort; }; options?: PublicReadOptions; } interface RootModelCreateQueryEntry extends RootQueryEntryBase<'model', 'create'> { data: unknown; args?: PublicCreateArgs; options?: PublicCreateOptions; } interface RootModelUpdateQueryEntry extends RootQueryEntryBase<'model', 'update'> { id: string; data: unknown; args?: PublicUpdateArgs; options?: PublicUpdateOptions; } interface RootModelUpsertQueryEntry extends RootQueryEntryBase<'model', 'upsert'> { data: Record; args?: PublicUpsertArgs; options?: PublicUpsertOptions; } interface RootModelDeleteQueryEntry extends RootQueryEntryBase<'model', 'delete'> { id: string; } interface RootModelSubListQueryEntry extends RootQueryEntryBase<'model', 'subList'> { id: string; sub: string; filter?: Filter; args?: { select?: string[]; }; } interface RootModelSubReadQueryEntry extends RootQueryEntryBase<'model', 'subRead'> { id: string; sub: string; subId: string; args?: { select?: string[]; populate?: SubPopulate | SubPopulate[] | string | string[]; }; } interface RootModelSubCreateQueryEntry extends RootQueryEntryBase<'model', 'subCreate'> { id: string; sub: string; data: unknown; } interface RootModelSubUpdateQueryEntry extends RootQueryEntryBase<'model', 'subUpdate'> { id: string; sub: string; subId: string; data: unknown; } interface RootModelSubBulkUpdateQueryEntry extends RootQueryEntryBase<'model', 'subBulkUpdate'> { id: string; sub: string; data: unknown; } interface RootModelSubDeleteQueryEntry extends RootQueryEntryBase<'model', 'subDelete'> { id: string; sub: string; subId: string; } interface RootModelDistinctQueryEntry extends RootQueryEntryBase<'model', 'distinct'> { field: string; filter?: Filter; } interface RootModelCountQueryEntry extends RootQueryEntryBase<'model', 'count'> { filter?: Filter; options?: Record; } interface RootDataListQueryEntry extends RootQueryEntryBase<'data', 'list'> { filter?: Filter; args?: DataFindArgs; options?: { includeCount?: boolean; [key: string]: unknown; }; } interface RootDataReadByIdQueryEntry extends RootQueryEntryBase<'data', 'read'> { id: string; args?: DataFindOneArgs; } interface RootDataReadByFilterQueryEntry extends RootQueryEntryBase<'data', 'read'> { filter: Filter; args?: DataFindOneArgs; } type RootQueryEntry = RootModelNewQueryEntry | RootModelListQueryEntry | RootModelReadByIdQueryEntry | RootModelReadByFilterQueryEntry | RootModelCreateQueryEntry | RootModelUpdateQueryEntry | RootModelUpsertQueryEntry | RootModelDeleteQueryEntry | RootModelSubListQueryEntry | RootModelSubReadQueryEntry | RootModelSubCreateQueryEntry | RootModelSubUpdateQueryEntry | RootModelSubBulkUpdateQueryEntry | RootModelSubDeleteQueryEntry | RootModelDistinctQueryEntry | RootModelCountQueryEntry | RootDataListQueryEntry | RootDataReadByIdQueryEntry | RootDataReadByFilterQueryEntry; interface RootOperationResult { index: number; target: RootTarget; name: string; op: RootModelOperation | RootDataOperation; result: PublicServiceResult; statusCode: number; message: string; } interface SubQueryEntry { model: string; op: 'list' | 'read' | string; id?: string; filter?: Filter; args?: Record; options?: Record; sqOptions?: { path?: string; compact?: boolean; }; } type TaskType = 'COPY_AND_DEPOPULATE' | 'COPY' | 'MOVE' | 'SLICE' | 'COUNT' | 'MASK' | string; interface Task { type: TaskType; args: unknown; options?: Record; } interface AccessRouterBaseRequest extends AccessRouterRequest { query: Record<'skip' | 'limit' | 'page' | 'page_size' | 'try_list' | 'skim' | 'include_permissions' | 'include_count' | 'include_extra_headers' | 'returning_all', string>; } interface ModelRequest extends AccessRouterBaseRequest { macl: Core; } interface DataRequest extends AccessRouterBaseRequest { dacl: DataCore; } type Request = AccessRouterBaseRequest; interface ErrorResult { success: false; kind: 'error'; code: Codes.BadRequest | Codes.Unauthorized | Codes.Forbidden | Codes.NotFound; errors?: TError[]; query?: TQuery; } interface SingleResult { success: true; kind: 'single'; code: Codes.Success | Codes.Created; data: T; input?: TInput; query?: TQuery; context?: ModelHookContext; } interface ListResult { success: true; kind: 'list'; code: Codes.Success | Codes.Created; data: T[]; count: number; totalCount?: number | null; input?: TInput; query?: TQuery; contexts?: ModelHookContext[]; } type ServiceResult = SingleResult | ListResult | ErrorResult; /** * Type-only nominal brand that marks an object as a fully-formed public DTO * produced by one of the `toPublic*` serializers. It has no runtime value, so * the serialized JSON shape is unchanged; its only purpose is to make the * internal {@link SingleResult}/{@link ListResult}/{@link ErrorResult} shapes * structurally incompatible with the public DTOs at the type level. Direct * assignment from an internal service result to a public DTO fails to compile * because the internal result does not carry this brand, and crossing the * boundary requires the explicit serializer (or an explicit cast). */ declare const publicResultBrand: unique symbol; interface PublicErrorResult { success: false; code: Codes.BadRequest | Codes.Unauthorized | Codes.Forbidden | Codes.NotFound; errors?: TError[]; [publicResultBrand]: 'public-error'; } interface PublicSingleResult { success: true; kind: 'single'; code: Codes.Success | Codes.Created; data: T; [publicResultBrand]: 'public-single'; } interface PublicListResult { success: true; kind: 'list'; code: Codes.Success | Codes.Created; data: T[]; count: number; totalCount?: number | null; [publicResultBrand]: 'public-list'; } type PublicServiceResult = PublicSingleResult | PublicListResult | PublicErrorResult; interface FindArgs { select?: Projection; populate?: Populate[] | string; include?: Include | Include[]; sort?: Sort; skip?: string | number; limit?: string | number; page?: string | number; pageSize?: string | number; overrides?: { filter?: Filter; select?: Projection; populate?: Populate[] | string; }; } interface FindOptions { skim?: boolean; includePermissions?: boolean; includeCount?: boolean; populateAccess?: PopulateAccess; lean?: boolean; } interface FindOneArgs { select?: Projection; sort?: Sort; populate?: Populate[] | string; include?: Include | Include[]; overrides?: { filter?: Filter; select?: Projection; populate?: Populate[] | string; }; } interface FindOneOptions { access?: FindAccess; populateAccess?: PopulateAccess; skim?: boolean; lean?: boolean; includePermissions?: boolean; } interface FindByIdArgs { select?: Projection; populate?: Populate[] | string; include?: Include | Include[]; overrides?: { select?: Projection; populate?: Populate[] | string; idFilter?: Filter; }; } interface FindByIdOptions extends FindOneOptions { } interface ExistsOptions { access?: BaseFilterAccess; includeId?: boolean; } type MaybePromise = T | Promise; type AccessRouterFieldKey = [Extract] extends [never] ? string : Extract; type IdentifierHook = (this: TRequest, id: string) => MaybePromise>; type GlobalPermissionValue = Record | string[] | string | null | undefined; type BaseFilterHook = (this: TRequest, permissions: AccessRouterPermissions) => MaybePromise; type OverrideFilterHook = (this: TRequest, filter: Filter, permissions: AccessRouterPermissions) => MaybePromise; type Hook = (this: TRequest, value: TValue, permissions: AccessRouterPermissions, context: TContext) => MaybePromise; type HookChain = Hook | Array>; type ValidateRule = boolean | unknown[]; type ValidateHook = (this: TRequest, allowedData: unknown, permissions: AccessRouterPermissions, context: ModelHookContext) => MaybePromise; type DocPermissionsHook = (this: TRequest, doc: unknown, permissions: AccessRouterPermissions, context: ModelHookContext) => MaybePromise>; type ChangeHook = (this: TRequest, previousValue: unknown, nextValue: unknown, changes: Change[], context: ModelHookContext) => MaybePromise; type DeleteHook = (this: TRequest, value: TValue, permissions: AccessRouterPermissions, context: ModelHookContext) => MaybePromise; type DocumentHook = (this: TRequest, value: ModelDocument, permissions: AccessRouterPermissions, context: ModelHookContext) => MaybePromise>; type DocumentHookChain = DocumentHook | Array>; type ModelBaseFilterHook = BaseFilterHook; type DataBaseFilterHook = BaseFilterHook; type ModelOverrideFilterHook = OverrideFilterHook; type DataOverrideFilterHook = OverrideFilterHook; type ModelIdentifierHook = IdentifierHook; type DataIdentifierHook = IdentifierHook; type ModelValidateHook = ValidateHook; type ModelDocPermissionsHook = DocPermissionsHook; type ModelChangeHook = ChangeHook; type ModelDocumentHook = DocumentHookChain; type ModelDeleteHook = DeleteHook, ModelRequest>; type ModelHook = HookChain; type ModelListHook = HookChain; type DataHook = HookChain; type DataListHook = HookChain; interface DefaultFindOneArgs extends Omit, 'overrides'> { } interface DefaultFindByIdArgs extends Omit, 'overrides'> { } interface DefaultFindArgs extends Omit, 'overrides'> { } type RequestSchema = RequestSchemaLike; type NestedRequestSchema = { default?: RequestSchema; data?: RequestSchema; }; type SubRouteGuardOptions = Record>; interface RequestSchemas { create?: RequestSchema; update?: RequestSchema; upsert?: RequestSchema; count?: RequestSchema; distinct?: RequestSchema; advancedList?: RequestSchema; advancedReadFilter?: RequestSchema; advancedRead?: RequestSchema; advancedCreate?: RequestSchema | NestedRequestSchema; advancedCreateData?: RequestSchema; advancedUpdate?: RequestSchema | NestedRequestSchema; advancedUpdateData?: RequestSchema; advancedUpsert?: RequestSchema | NestedRequestSchema; advancedUpsertData?: RequestSchema; subList?: RequestSchema; subRead?: RequestSchema; subCreate?: RequestSchema; subUpdate?: RequestSchema; subBulkUpdate?: RequestSchema; } interface DataRequestSchemas { advancedList?: RequestSchema; advancedReadFilter?: RequestSchema; advancedRead?: RequestSchema; } interface Defaults { findOneArgs?: DefaultFindOneArgs; findOneOptions?: FindOneOptions; findByIdArgs?: DefaultFindByIdArgs; findByIdOptions?: FindByIdOptions; findArgs?: DefaultFindArgs; findOptions?: FindOptions; createArgs?: CreateArgs; createOptions?: CreateOptions; updateOneArgs?: UpdateOneArgs; updateOneOptions?: UpdateOneOptions; upsertOptions?: UpsertOptions; updateByIdArgs?: UpdateByIdArgs; upsertArgs?: UpsertArgs; updateByIdOptions?: UpdateByIdOptions; existsOptions?: ExistsOptions; publicListArgs?: PublicListArgs; publicListOptions?: PublicListOptions; publicCreateArgs?: PublicCreateArgs; publicCreateOptions?: PublicCreateOptions; publicReadArgs?: PublicReadArgs; publicReadOptions?: PublicReadOptions; publicUpdateArgs?: PublicUpdateArgs; publicUpdateOptions?: PublicUpdateOptions; } interface AccessRouterLogger { debug?: (...args: unknown[]) => unknown; info?: (...args: unknown[]) => unknown; warn?: (...args: unknown[]) => unknown; error?: (...args: unknown[]) => unknown; isLevelEnabled?: (level: string) => boolean; } interface GlobalOptions { requestPermissionField?: string; globalPermissions?: (this: AccessRouterRequest, req: AccessRouterRequest) => MaybePromise; /** Require populate target models to be registered in the active runtime. Defaults to `true`. */ requireRegisteredPopulateModels?: boolean; logger?: AccessRouterLogger; requestComplexity?: RequestComplexityOptions; } interface RootRouterOptions { basePath: string; operationAccess?: Validation; maxBatchEntries?: number; maxOrderGroups?: number; maxConcurrentOperations?: number; } interface OperationAccess { new?: Validation; list?: Validation; create?: Validation; read?: Validation; update?: Validation; upsert?: Validation; delete?: Validation; distinct?: Validation; count?: Validation; subs?: Validation | SubRouteGuardOptions; } type PermissionRule = Validation | OperationAccess; type PermissionSchema = Partial>; interface DocPermissions { list?: ModelDocPermissionsHook; create?: ModelDocPermissionsHook; read?: ModelDocPermissionsHook; update?: ModelDocPermissionsHook; } interface DefaultModelRouterOptions { listHardLimit?: number; documentPermissionField?: string; idParam?: string; idField?: string; resolveIdFilter?: ModelIdentifierHook; parentPath?: string; queryRouteSegment?: string; mutationRouteSegment?: string; operationAccess?: Validation | OperationAccess; modelPermissionPrefix?: string; } interface ExtendedDefaultModelRouterOptions extends DefaultModelRouterOptions { 'operationAccess.default'?: Validation; 'operationAccess.new'?: Validation; 'operationAccess.list'?: Validation; 'operationAccess.read'?: Validation; 'operationAccess.update'?: Validation; 'operationAccess.upsert'?: Validation; 'operationAccess.delete'?: Validation; 'operationAccess.create'?: Validation; 'operationAccess.distinct'?: Validation; 'operationAccess.count'?: Validation; 'operationAccess.subs'?: SubRouteGuardOptions; } interface ModelRouterOptions extends DefaultModelRouterOptions { modelName?: string; basePath?: string; permissionSchema?: PermissionSchema>; alwaysSelectFields?: string[]; docPermissions?: DocPermissions | ModelDocPermissionsHook; baseFilter?: ModelBaseFilterHook | Record; overrideFilter?: ModelOverrideFilterHook | Record; decorate?: ModelHook | Record>; decorateAll?: ModelListHook | Record>; validate?: ValidateRule | ModelValidateHook | Record; prepare?: ModelHook | Record>; transform?: ModelDocumentHook | Record>; afterPersist?: ModelDocumentHook | Record>; onChange?: Record; beforeDelete?: ModelDeleteHook; afterDelete?: ModelDeleteHook; requestSchemas?: RequestSchemas; defaults?: Defaults; } interface DataRouterOptions { /** * In-memory records are owned by the router as an immutable configured snapshot. * Mutating this array or its records after configuration does not change served data; * use `setDataOption(name, 'data', nextRecords)` or `router.data(nextRecords)` to replace it. */ data?: TData[]; listHardLimit?: number; idParam?: string; idField?: string; resolveIdFilter?: DataIdentifierHook; parentPath?: string; queryRouteSegment?: string; operationAccess?: Validation | OperationAccess; dataName?: string; basePath?: string; permissionSchema?: PermissionSchema>; baseFilter?: DataBaseFilterHook | Record; overrideFilter?: DataOverrideFilterHook | Record; decorate?: DataHook | Record>; decorateAll?: DataListHook | Record>; requestSchemas?: DataRequestSchemas; } interface ExtendedModelRouterOptions extends ModelRouterOptions, ExtendedDefaultModelRouterOptions { 'alwaysSelectFields.default'?: string[]; 'alwaysSelectFields.list'?: string[]; 'alwaysSelectFields.create'?: string[]; 'alwaysSelectFields.read'?: string[]; 'alwaysSelectFields.update'?: string[]; 'docPermissions.default'?: ModelDocPermissionsHook; 'docPermissions.list'?: ModelDocPermissionsHook; 'docPermissions.create'?: ModelDocPermissionsHook; 'docPermissions.read'?: ModelDocPermissionsHook; 'docPermissions.update'?: ModelDocPermissionsHook; 'baseFilter.default'?: ModelBaseFilterHook; 'baseFilter.list'?: ModelBaseFilterHook; 'baseFilter.read'?: ModelBaseFilterHook; 'baseFilter.update'?: ModelBaseFilterHook; 'baseFilter.delete'?: ModelBaseFilterHook; 'overrideFilter.default'?: ModelOverrideFilterHook; 'overrideFilter.list'?: ModelOverrideFilterHook; 'overrideFilter.read'?: ModelOverrideFilterHook; 'overrideFilter.update'?: ModelOverrideFilterHook; 'overrideFilter.delete'?: ModelOverrideFilterHook; 'decorate.default'?: ModelHook; 'decorate.list'?: ModelHook; 'decorate.create'?: ModelHook; 'decorate.read'?: ModelHook; 'decorate.update'?: ModelHook; 'decorateAll.default'?: ModelListHook; 'decorateAll.list'?: ModelListHook; 'validate.default'?: ValidateRule | ModelValidateHook; 'validate.create'?: ValidateRule | ModelValidateHook; 'validate.update'?: ValidateRule | ModelValidateHook; 'prepare.default'?: ModelHook; 'prepare.create'?: ModelHook; 'prepare.update'?: ModelHook; 'transform.default'?: ModelDocumentHook; 'transform.update'?: ModelDocumentHook; 'afterPersist.default'?: ModelDocumentHook; 'afterPersist.create'?: ModelDocumentHook; 'afterPersist.update'?: ModelDocumentHook; onChange?: Record; 'requestSchemas.create'?: RequestSchema; 'requestSchemas.update'?: RequestSchema; 'requestSchemas.upsert'?: RequestSchema; 'requestSchemas.count'?: RequestSchema; 'requestSchemas.distinct'?: RequestSchema; 'requestSchemas.advancedList'?: RequestSchema; 'requestSchemas.advancedReadFilter'?: RequestSchema; 'requestSchemas.advancedRead'?: RequestSchema; 'requestSchemas.advancedCreate.default'?: RequestSchema; 'requestSchemas.advancedCreate.data'?: RequestSchema; 'requestSchemas.advancedUpdate'?: RequestSchema; 'requestSchemas.advancedUpdate.default'?: RequestSchema; 'requestSchemas.advancedUpdate.data'?: RequestSchema; 'requestSchemas.advancedUpsert.default'?: RequestSchema; 'requestSchemas.advancedUpsert.data'?: RequestSchema; 'requestSchemas.subList'?: RequestSchema; 'requestSchemas.subRead'?: RequestSchema; 'requestSchemas.subCreate'?: RequestSchema; 'requestSchemas.subUpdate'?: RequestSchema; 'requestSchemas.subBulkUpdate'?: RequestSchema; 'defaults.findOneArgs'?: DefaultFindOneArgs; 'defaults.findOneOptions'?: FindOneOptions; 'defaults.findByIdArgs'?: DefaultFindByIdArgs; 'defaults.findByIdOptions'?: FindByIdOptions; 'defaults.findArgs'?: DefaultFindArgs; 'defaults.findOptions'?: FindOptions; 'defaults.createArgs'?: CreateArgs; 'defaults.createOptions'?: CreateOptions; 'defaults.updateOneArgs'?: UpdateOneArgs; 'defaults.updateOneOptions'?: UpdateOneOptions; 'defaults.updateByIdArgs'?: UpdateByIdArgs; 'defaults.updateByIdOptions'?: UpdateByIdOptions; 'defaults.upsertArgs'?: UpsertArgs; 'defaults.existsOptions'?: ExistsOptions; 'defaults.publicListArgs'?: PublicListArgs; 'defaults.publicListOptions'?: PublicListOptions; 'defaults.publicCreateArgs'?: PublicCreateArgs; 'defaults.publicCreateOptions'?: PublicCreateOptions; 'defaults.publicReadArgs'?: PublicReadArgs; 'defaults.publicReadOptions'?: PublicReadOptions; 'defaults.publicUpdateArgs'?: PublicUpdateArgs; 'defaults.publicUpdateOptions'?: PublicUpdateOptions; } interface ExtendedDataRouterOptions extends DataRouterOptions { 'requestSchemas.advancedList'?: RequestSchema; 'requestSchemas.advancedReadFilter'?: RequestSchema; 'requestSchemas.advancedRead'?: RequestSchema; } interface DistinctArgs { filter?: Filter; } type SubdocumentId = string; type SubdocumentName = string; type SubdocumentRecord = Record; type SubdocumentBulkRecord = SubdocumentRecord & { _id?: unknown; }; type SubdocumentCreateInput = SubdocumentRecord | SubdocumentRecord[]; type SubdocumentBulkUpdateInput = SubdocumentBulkRecord[]; interface SubdocumentListOptions { filter?: Filter; select?: string[]; } interface SubdocumentReadOptions { select?: string[]; populate?: SubPopulate | SubPopulate[]; } interface SubdocumentCreateOptions { addFirst?: boolean; } interface SubdocumentParentArgs { populate?: SubPopulate | SubPopulate[]; } interface SubdocumentParentOptions { access?: BaseFilterAccess; lean?: boolean; } declare function parsePathParam(value: string | string[] | undefined, parameter: string): string; declare function parseQuery(schema: TSchema, value: unknown): z.output; declare function parseBody(schema: TSchema, value: unknown): z.output; declare function parseBodyWithSchema(schema: TSchema, value: unknown, userSchema?: RequestSchemaLike): Promise>; declare function parseNestedBodyWithSchema(schema: z.ZodTypeAny, value: unknown, nestedKey: string, userSchema?: RequestSchemaLike): Promise>; /** * Wraps a request validator into a request schema adapter used by `access-router`. * * @example * const schema = defineRequestSchema(fromZod(z.object({ name: z.string() }))); */ declare function defineRequestSchema(validator: RequestSchemaValidator, options?: RequestSchemaOptions): RequestSchemaAdapter; /** * Adapts a Zod schema into a `RequestSchemaValidator` for `access-router`. * * Supports both synchronous schemas and schemas with async refinements or * transforms via `safeParseAsync` when available. Synchronous schemas keep * their existing output values and issue paths. Operational exceptions thrown * by `safeParseAsync` itself propagate unchanged. * * @example * const validator = fromZod(z.object({ name: z.string() })); */ declare function fromZod(schema: TSchema): RequestSchemaValidator>; declare function fromStandardSchema(schema: TSchema): RequestSchemaValidator>; declare function fromYup(schema: TSchema): RequestSchemaValidator; declare function fromJoi(schema: TSchema): RequestSchemaValidator; /** * Adapts an AJV validator into a `RequestSchemaValidator`. * * Contract: synchronous validators return a boolean and expose input-local * diagnostics via mutable `validator.errors`; those errors are snapshotted * synchronously before any suspension so concurrent same-turn validations do * not observe another input's diagnostics. Asynchronous AJV schemas * (`$async: true`) return a promise that resolves with validated data on * success or rejects with a `ValidationError` carrying an `errors` array on * failure; rejection-carried errors are normalized, while any other rejection * propagates unchanged as an operational exception. */ declare function fromAjv(validator: AjvValidatorLike): RequestSchemaValidator; declare function fromValibot(schema: TSchema, safeParse: ValibotSafeParseLike): RequestSchemaValidator; /** * Adapts an ArkType type into a `RequestSchemaValidator`. * * Success/failure is discriminated via the supported ArkErrors brand key * (`hasArkKind(result, "errors")`, stored at runtime as `' arkKind'` with a * leading space; the unspaced `arkKind` alias is also accepted) or, when the * type exposes a Standard Schema `~standard.validate` contract, via that * contract. ArkType's Standard Schema `validate` returns `{ value }` on * success but returns raw `ArkErrors` on failure instead of `{ issues }`, so * both shapes are handled. Array shape and `message`/`path`-like record * fields are never used as discriminators, so valid empty/scalar/record/ * nullable arrays pass through unchanged. Unexpected exceptions thrown by the * type propagate unchanged. */ declare function fromArkType(type: ArkTypeLike): RequestSchemaValidator; declare function fromIoTs(decoder: IoTsDecoderLike): RequestSchemaValidator; declare function fromSuperstruct(struct: TStruct, validate: SuperstructValidateLike): RequestSchemaValidator; declare function fromVine(validator: VineValidatorLike): RequestSchemaValidator; export { type DistinctArgs as $, type AccessRouterBaseRequest as A, type BaseFilterAccess as B, type Change as C, type CreateArgs as D, type CreateOptions as E, type CreateQueryInput as F, CustomHeaders as G, DATA_MIDDLEWARE as H, type DataBaseFilterHook as I, type DataFilter as J, type DataFindArgs as K, type DataFindOneArgs as L, type DataFindOneOptions as M, type DataFindOptions as N, type DataHook as O, type DataHookContext as P, type DataIdentifierHook as Q, type DataListHook as R, type DataOverrideFilterHook as S, type DataRequest as T, type DataRequestSchemas as U, type DataRouterOptions as V, type DecorateAccess as W, type DecorateAllAccess as X, type DeepFieldPath as Y, type DefaultModelRouterOptions as Z, type Defaults as _, type AccessRouterFieldKey as a, type PublicReadOptions as a$, type DistinctBody as a0, type DocPermissionsAccess as a1, type ErrorResult as a2, type ExistsOptions as a3, type ExtendedDataRouterOptions as a4, type ExtendedDefaultModelRouterOptions as a5, type ExtendedModelRouterOptions as a6, type Filter as a7, FilterOperator as a8, type FindAccess as a9, type ModelDocument as aA, type ModelDocumentHook as aB, type ModelHook as aC, type ModelHookContext as aD, type ModelIdentifierHook as aE, type ModelListHook as aF, type ModelOverrideFilterHook as aG, type ModelRequest as aH, type ModelRouterOptions as aI, type ModelValidateHook as aJ, PERMISSIONS as aK, PERMISSION_KEYS as aL, type ParentRef as aM, type PathValue as aN, type PermissionSchema as aO, type Populate as aP, type PopulateAccess as aQ, type PrepareAccess as aR, type Projection as aS, type PublicCreateArgs as aT, type PublicCreateOptions as aU, type PublicErrorResult as aV, type PublicListArgs as aW, type PublicListOptions as aX, type PublicListResult as aY, type PublicOutput as aZ, type PublicReadArgs as a_, type FindArgs as aa, type FindByIdArgs as ab, type FindByIdOptions as ac, type FindOneArgs as ad, type FindOneOptions as ae, type FindOptions as af, type GlobalOptions as ag, type GlobalPermissionValue as ah, type GuardHook as ai, type IdentifierHook as aj, type Include as ak, type IoTsContextEntryLike as al, type IoTsDecodeErrorLike as am, type IoTsDecoderLike as an, type JoiSchemaLike as ao, type JoiValidationErrorDetailLike as ap, type KeyValueProjection as aq, type LegacyInclude as ar, type ListQueryInput as as, type ListResult as at, MIDDLEWARE as au, type MaybePromise as av, type ModelBaseFilterHook as aw, type ModelChangeHook as ax, type ModelDeleteHook as ay, type ModelDocPermissionsHook as az, type AccessRouterLogger as b, type SubdocumentBulkRecord as b$, type PublicServiceResult as b0, type PublicSingleResult as b1, type PublicUpdateArgs as b2, type PublicUpdateOptions as b3, type PublicUpsertArgs as b4, type PublicUpsertOptions as b5, type ReadQueryInput as b6, type Request as b7, type RequestSchemaAdapter as b8, type RequestSchemaFailure as b9, type RootModelUpdateQueryEntry as bA, type RootModelUpsertQueryEntry as bB, type RootOperationResult as bC, type RootQueryEntry as bD, type RootRouterOptions as bE, type RootSubOperation as bF, type RootTarget as bG, type RouteGuardAccess as bH, type SelectAccess as bI, type SelectedPopulatedPublicOutput as bJ, type SelectedPublicOutput as bK, type ServiceResult as bL, type SingleResult as bM, type Sort as bN, type SortOrder as bO, type StandardSchemaFailure as bP, type StandardSchemaInferOutput as bQ, type StandardSchemaIssue as bR, type StandardSchemaPathSegment as bS, type StandardSchemaResult as bT, type StandardSchemaSuccess as bU, type StandardSchemaV1 as bV, StatusCodes as bW, type SubListBody as bX, type SubPopulate as bY, type SubQueryEntry as bZ, type SubReadBody as b_, type RequestSchemaIssue as ba, type RequestSchemaLike as bb, type RequestSchemaOptions as bc, type RequestSchemaResult as bd, type RequestSchemaSuccess as be, type RequestSchemaValidator as bf, type RequestSchemas as bg, type RootDataListQueryEntry as bh, type RootDataOperation as bi, type RootDataReadByFilterQueryEntry as bj, type RootDataReadByIdQueryEntry as bk, type RootModelCountQueryEntry as bl, type RootModelCreateQueryEntry as bm, type RootModelDeleteQueryEntry as bn, type RootModelDistinctQueryEntry as bo, type RootModelListQueryEntry as bp, type RootModelNewQueryEntry as bq, type RootModelOperation as br, type RootModelReadByFilterQueryEntry as bs, type RootModelReadByIdQueryEntry as bt, type RootModelSubBulkUpdateQueryEntry as bu, type RootModelSubCreateQueryEntry as bv, type RootModelSubDeleteQueryEntry as bw, type RootModelSubListQueryEntry as bx, type RootModelSubReadQueryEntry as by, type RootModelSubUpdateQueryEntry as bz, type AccessRouterRequest as c, type SubdocumentBulkUpdateInput as c0, type SubdocumentCreateInput as c1, type SubdocumentCreateOptions as c2, type SubdocumentId as c3, type SubdocumentListOptions as c4, type SubdocumentName as c5, type SubdocumentParentArgs as c6, type SubdocumentParentOptions as c7, type SubdocumentReadOptions as c8, type SubdocumentRecord as c9, type YupValidationErrorLike as cA, defineRequestSchema as cB, fromAjv as cC, fromArkType as cD, fromIoTs as cE, fromJoi as cF, fromStandardSchema as cG, fromSuperstruct as cH, fromValibot as cI, fromVine as cJ, fromYup as cK, fromZod as cL, parseBody as cM, parseBodyWithSchema as cN, parseNestedBodyWithSchema as cO, parsePathParam as cP, parseQuery as cQ, DataService as cR, Service as cS, PublicService as cT, type AccessRouterPermissionMap as cU, type AccessRouterPermissions as cV, type Permissions as cW, type SuperstructFailureLike as ca, type SuperstructValidateLike as cb, type Task as cc, type TaskType as cd, type TransformAccess as ce, type TypedFilter as cf, type UpdateByIdArgs as cg, type UpdateByIdOptions as ch, type UpdateOneArgs as ci, type UpdateOneOptions as cj, type UpdateQueryInput as ck, type UpsertArgs as cl, type UpsertOptions as cm, type UpsertQueryInput as cn, type ValibotIssueLike as co, type ValibotPathItemLike as cp, type ValibotSafeParseLike as cq, type ValibotSafeParseResult as cr, type ValidateAccess as cs, type ValidateRule as ct, type Validation as cu, type ValidationError as cv, type VineValidationErrorLike as cw, type VineValidationMessageLike as cx, type VineValidatorLike as cy, type YupSchemaLike as cz, type AccessRouterRequestExtensions as d, type AdvancedCreateBody as e, type AdvancedListBody as f, type AdvancedReadBody as g, type AdvancedReadFilterBody as h, type AdvancedUpdateBody as i, type AdvancedUpsertBody as j, type AfterPersistAccess as k, type AjvErrorObjectLike as l, type AjvValidationErrorLike as m, type AjvValidatorLike as n, type ArkTypeErrorsLike as o, type ArkTypeLike as p, type ArkTypeProblemLike as q, Codes as r, type CorrelatedCountInclude as s, type CorrelatedFilter as t, type CorrelatedInclude as u, type CorrelatedIncludeArgs as v, type CorrelatedListInclude as w, type CorrelatedReadByFilterInclude as x, type CorrelatedReadByIdInclude as y, type CountBody as z };