export declare const PASSKEY_DISCOVERABILITY_UNKNOWN_DIAGNOSTIC = "registration: discoverability unknown \u2192 authentication: allowCredentials=[] \u2192 browser returned no assertion"; export type AthenaDevtoolsCeremonyStage = "idle" | "generate-register-options" | "credentials-create" | "verify-registration" | "generate-authenticate-options" | "credentials-get" | "verify-authentication"; export declare function createAthenaDevtoolsRequestId(): string; export declare function mergeAthenaDevtoolsFetchHeaders(input: RequestInfo | URL, init?: RequestInit): Headers; export declare function athenaDevtoolsRequestRowKey(entry: Pick): string; export interface AthenaDevtoolsSanitizedRequest { id: string; latencyMs: number; method: string; path: string; status: number | null; traceId: string | null; } export type AthenaDevtoolsFetchStatus = "idle" | "loading" | "ok" | "error"; export interface AthenaDevtoolsPasskeyConfig { authenticatorAttachment: string | null; configured: boolean; enabled: boolean; onboardingEnabled: boolean; origins: string[]; relatedOrigins: string[]; residentKey: string | null; rpId: string | null; rpName: string | null; timeoutMs: number; userVerification: string | null; } export interface AthenaDevtoolsStoredPasskey { backedUp: boolean | null; createdAt: string | null; deviceType: string | null; displayName: string | null; id: string | null; name: string | null; residentKey: boolean | null; transports: string[]; userId: string | null; } export interface AthenaDevtoolsPasskeyClient { generateAuthenticateOptions?: (input?: unknown) => Promise; generateRegisterOptions?: (input?: unknown) => Promise; getRelatedOrigins?: () => Promise; listUser?: (input?: unknown) => Promise; listUserPasskeys?: (input?: unknown) => Promise; } export interface AthenaDevtoolsProjectConfig { authWarnings: string[]; autoMigrate: boolean; databaseConfigured: boolean; generatorConfigFile: string | null; localMigrationFiles: number; migrationsDirectory: string; migrationsDirectoryFound: boolean; modelsAttached: boolean; } export interface AthenaDevtoolsRuntimeDiagnostics { auth: string; config?: AthenaDevtoolsProjectConfig; database: string; passkey?: AthenaDevtoolsPasskeyConfig; runtime: string; storage: string; } export type AthenaDevtoolsInspectorRedactedFact = { configured: boolean; kind: "secret"; } | { kind: "structural"; value: boolean | number | string | null; } | { kind: "unset"; }; export interface AthenaDevtoolsInspectorSettingStages { inference?: AthenaDevtoolsInspectorRedactedFact; normalization?: AthenaDevtoolsInspectorRedactedFact; runtime?: AthenaDevtoolsInspectorRedactedFact; source?: AthenaDevtoolsInspectorRedactedFact; } export interface AthenaDevtoolsInspectorSetting { configured?: string; effective?: string; inferred?: string; path: string; source?: string; stages?: AthenaDevtoolsInspectorSettingStages; } export interface AthenaDevtoolsInspectorMigrationRecord { filename?: string; generatedBy?: string; name?: string; version?: number; } export interface AthenaDevtoolsInspectorMigrationSubsystem { generatedBy?: string; status?: string; } export interface AthenaDevtoolsInspectorModelField { name?: string; type?: string; } export interface AthenaDevtoolsInspectorModelRelation { kind?: string; name?: string; targetModel?: string; } export interface AthenaDevtoolsInspectorModelTable { fields?: AthenaDevtoolsInspectorModelField[]; identity?: string; name?: string; primaryKey?: string[]; relations?: AthenaDevtoolsInspectorModelRelation[]; schema?: string; schemaTable?: string; table?: string; } export interface AthenaDevtoolsAuthorizationInspector { audit: { entries: Array<{ action: string; actorUserId: string | null; createdAt: string | null; organizationId: string | null; targetId: string | null; targetKind: string | null; }>; events: Array<{ event: string; occurredAt: string; organizationId: string | null; roleKey: string | null; userId: string | null; }>; }; capabilities: { canChangeMemberRole: boolean; canDeleteOrganization: boolean; canInviteMembers: boolean; canManageOrganizationRoles: boolean; canManagePlatformRoles: boolean; canRemoveMember: boolean; } | null; catalog: { fingerprint: string; modules: Array<{ domain: string; rightCount: number; }>; rights: Array<{ action: string; assignable: boolean; description: string; displayName: string; domain: string; isPattern: boolean; key: string; kind: string; resource: string; riskLevel: string; scopeKind: string; source: string; }>; }; decisions: Array<{ decisionId: string; domain: string; missing: string[]; operation: string; outcome: string; required: { allOf: string[]; }; }>; diagnostics: Array<{ code: string; detail: string; severity: string; }>; grants: Array<{ id: string; organizationId: string | null; rightKeys: string[]; roleKey: string | null; scopeKind: string; source: string; status: string; subject: { id: string; kind: string; userId: string | null; }; }>; rights: { direct: AthenaDevtoolsResolvedRightView[]; effective: AthenaDevtoolsResolvedRightView[]; inherited: AthenaDevtoolsResolvedRightView[]; patterns: AthenaDevtoolsResolvedRightView[]; }; roleResolution: { direct: Array<{ displayName: string; key: string; scopeKind: string; }>; effective: Array<{ displayName: string; key: string; scopeKind: string; }>; inherited: Array<{ displayName: string; key: string; scopeKind: string; }>; }; roles: Array<{ assignable: boolean; assignmentCount: number; displayName: string; id: string; key: string; organizationId: string | null; protected: boolean; rightCount: number; rights: string[]; scopeKind: string; systemKind: string | null; version: number; }>; revision: number | null; source: "memory" | "postgres" | "none" | "unknown"; status: "ready" | "degraded" | "unavailable" | "not-configured"; inventory: { catalog: AthenaDevtoolsAuthorizationInspector["catalog"]; grants: AthenaDevtoolsAuthorizationInspector["grants"]; roles: AthenaDevtoolsAuthorizationInspector["roles"]; }; subject: { capabilities: AthenaDevtoolsAuthorizationInspector["capabilities"]; kind: string; organizationId: string | null; rights: AthenaDevtoolsAuthorizationInspector["rights"]; roles: AthenaDevtoolsAuthorizationInspector["roleResolution"]; sessionId: string | null; userId: string | null; }; timings: { authorizeMs: number | null; grantResolveMs: number | null; principalResolveMs: number | null; rightsResolveMs: number | null; }; } export interface AthenaDevtoolsResolvedRightView { action: string; key: string; matchKind: string; resource: string; scopeKind: string; sources: Array<{ grantId: string | null; kind: string; organizationId: string | null; roleKey: string | null; scopeKind: string; }>; } export interface AthenaDevtoolsInspectorSnapshot { authorization: AthenaDevtoolsAuthorizationInspector; configuration: { settings: AthenaDevtoolsInspectorSetting[]; } | null; migrations: { applied?: AthenaDevtoolsInspectorMigrationRecord[]; files?: AthenaDevtoolsInspectorMigrationRecord[]; generatedBy?: string[]; latestApplied?: string | number | null; localFileCount?: number; pending?: AthenaDevtoolsInspectorMigrationRecord[]; schemaVersion?: number; subsystems?: { auth?: AthenaDevtoolsInspectorMigrationSubsystem; billing?: AthenaDevtoolsInspectorMigrationSubsystem; storage?: AthenaDevtoolsInspectorMigrationSubsystem; }; version?: number; } | null; models: { drift?: Array<{ kind?: string; object?: string; }>; liveCatalog?: string; tables?: AthenaDevtoolsInspectorModelTable[]; } | null; } export interface AthenaDevtoolsRuntimeSnapshot { authorization: AthenaDevtoolsAuthorizationInspector; authorizationApis?: unknown; configuration?: AthenaDevtoolsInspectorSnapshot["configuration"]; dataAdvertised: boolean | null; diagnostics: AthenaDevtoolsRuntimeDiagnostics | null; endpoints: { auth?: string | false | null; data?: string; } | null; error: string | null; migrations?: AthenaDevtoolsInspectorSnapshot["migrations"]; models?: AthenaDevtoolsInspectorSnapshot["models"]; ok: boolean | null; protocol: { major: number; minor: number; } | null; runtime: string | null; runtimeImplementation: string | null; status: AthenaDevtoolsFetchStatus; transport: string | null; } export interface AthenaDevtoolsPasskeyCeremony { allowCredentialsCount: number; /** Wire challenge was present. The secret itself is never retained. */ challengePresent: boolean; rpId: string | null; rpName: string | null; timeout: number | null; userVerification: string | null; } export interface AthenaDevtoolsRegistrationCeremony { attachment: string | null; attestation: string | null; challengePresent: boolean; credProps: boolean | null; excludeCredentialsCount: number; hints: string[]; pubKeyCredAlgs: number[]; requireResidentKey: boolean | null; residentKey: string | null; rpId: string | null; rpName: string | null; timeout: number | null; userDisplayName: string | null; userName: string | null; userVerification: string | null; } export declare function coerceAthenaDevtoolsAuthorizationInspector(value: unknown): AthenaDevtoolsAuthorizationInspector; export declare function parseAthenaDevtoolsRuntimeSnapshot(value: unknown): Omit; export declare function fetchAthenaDevtoolsRuntimeSnapshot(path?: string): Promise; export declare function parsePasskeyCeremony(value: unknown): AthenaDevtoolsPasskeyCeremony | null; export declare function parseRegistrationCeremony(value: unknown): AthenaDevtoolsRegistrationCeremony | null; export interface PasskeyRpAlignment { authenticateRpIdMismatch: boolean; configuredOriginMismatch: boolean; configuredRpIdMismatch: boolean; messages: string[]; registrationRpIdMismatch: boolean; } /** * DevTools warning when advertised or ceremony RP identity is not the * browser hostname / origin. WebAuthn `rpId` is compared to hostname, not * scheme+port, and may be a parent domain of the browser host. Related-origin * advertisements count as allowed origins. */ export declare function resolvePasskeyRpAlignment(input: { authenticateRpId?: string | null; browserHostname: string; browserOrigin: string; configuredOrigins: readonly string[]; configuredRelatedOrigins?: readonly string[]; configuredRpId?: string | null; registrationRpId?: string | null; }): PasskeyRpAlignment; export declare function formatPasskeyDiscoverabilityDiagnostic(input: { allowCredentialsCount: number; assertionPresent: boolean; residentKey: boolean | null | undefined; }): string | null; export declare function redactChallengeMarker(present: boolean): string | null; /** * Eligibility actually handed to `navigator.credentials.create()`. * Hints are a UI steer; `authenticatorAttachment` is a hard filter. * Empty attachment + empty hints means Athena did not constrain the picker. */ export declare function passkeyCreateEligibility(input: { attachment: string | null; hints: readonly string[]; }): "cross-platform" | "hinted" | "platform" | "unconstrained"; export declare function unwrapAuthResultData(value: unknown): unknown; export declare function resolveAthenaDevtoolsPasskeyClient(client: unknown): AthenaDevtoolsPasskeyClient | null; export declare function parseStoredPasskeys(value: unknown): AthenaDevtoolsStoredPasskey[];