import { OAuthClientMetadata } from "@atproto/oauth-client"; import { AstroIntegration } from "astro"; //#region src/types/oauth-scope.d.ts type Nsid = `${string}.${string}`; type RepoAction = "create" | "update" | "delete"; type RepoActionSequence = Choice extends Available ? Choice | ([Exclude] extends [never] ? never : `${Choice}&action=${RepoActionSequence>}`) : never; type AccountAttribute = "email" | "repo"; type AccountAction = "read" | "manage"; type MimeType = `${string}/${string}`; type DidService = `did:${string}%23${string}`; type RepoScope = `repo:${Nsid | "*"}` | `repo:${Nsid | "*"}?action=${RepoActionSequence}`; type RpcScope = `rpc:${Nsid | "*"}?aud=${DidService | "*"}` | `rpc?lxm=${Nsid | "*"}&aud=${DidService | "*"}`; type BlobScope = `blob:${MimeType}`; type AccountScope = `account:${AccountAttribute}` | `account:${AccountAttribute}?action=${AccountAction}`; type IdentityScope = `identity:${"handle" | "*"}`; type IncludeScope = `include:${Nsid}` | `include:${Nsid}?aud=${DidService}`; /** An AT Protocol OAuth scope from the current permissions specification. */ type AtprotoOAuthScope = "atproto" | RepoScope | RpcScope | BlobScope | AccountScope | IdentityScope | IncludeScope; //#endregion //#region src/integration.d.ts type AtAstroConfig = { clientMetadata: OAuthClientMetadata; didSessionKey: string; oauthStatePrefix: string; oauthSessionPrefix: string; handleResolver: string; publicEndpoint: string; patchRedirects?: boolean; redirectAfterSignIn: string; redirectAfterSignOut: string; }; type AtAstroOptions = { /** The name of the OAuth client; defaults to the session prefix if not otherwise specified */ name?: string; /** The URL of the production version of the site. This (or the root Astro config's `site`) is required. */ site?: string; /** ATProto scopes, excluding the required "atproto" scope */ scopes?: AtprotoOAuthScope[]; /** The prefix to use for session storage keys; defaults to the site's hostname with dots replaced by dashes */ sessionPrefix?: string; /** * Base URL of an XRPC service that implements `com.atproto.identity.resolveHandle`. Most PDSs implement this. * * @default "https://bsky.social" */ handleResolver?: string; /** * Base URL of the public service endpoint to use for unauthenticated clients. * * @default "https://public.api.bsky.app" */ publicEndpoint?: string; /** Force-enable or disable the OAuth redirect compatibility patch; defaults to runtime detection. */ patchRedirects?: boolean; /** The path to redirect to after the user successfully signs in (defaults to the site's root) */ redirectAfterSignIn?: `/${string}`; /** The path to redirect to after the user successfully signs out (defaults to the site's root) */ redirectAfterSignOut?: `/${string}`; }; declare function createPlugin(options?: AtAstroOptions): AstroIntegration; //#endregion export { type AtAstroConfig, type AtAstroOptions, type AtprotoOAuthScope, createPlugin as default };