/** * projectShares.ts * * CRUD for the `project_shares` Postgres table via Supabase PostgREST. * Backs the internal-only `share_project` MCP tool (BRA-368): lets an owner * account grant a named grantee account read+write access to one project * (folder prefix) of the owner's own wiki storage namespace. * * Table: scripts/project-shares.sql */ /** * Grant levels for project_shares.permissions (GH #798 / BRA-5160, successor * to #499/BRA-5128). 'read_write' is the historical default and the only * value that ever existed before this change. */ export declare const PROJECT_SHARE_PERMISSIONS: readonly ["read_write", "read_only"]; export type ProjectSharePermission = (typeof PROJECT_SHARE_PERMISSIONS)[number]; export declare function isProjectSharePermission(value: unknown): value is ProjectSharePermission; export interface ProjectShareGrant { owner_subject: string; project_path: string; /** Absent only for rows predating this column's enforcement — treat as 'read_write'. */ permissions?: ProjectSharePermission; } /** * Master toggle for cross-account project sharing (BRA-3611 / GH #685). * Default off. Table presence used to be the de facto flag — creating * project-shares.sql WAS the feature launch, which is why the migration had * to be held back in apply-migrations.mjs (GH #409). This is now the only * thing that decides whether sharing is reachable; table presence is a * separate, orthogonal fact reported by getSharingStatus() for health_check. */ export declare function isProjectSharingEnabled(): boolean; /** * Thrown by listActiveGrantsForGrantee() when the grant lookup itself failed * (non-2xx from PostgREST — e.g. 404 PGRST205 for a missing project_shares * table). Distinct from a genuine empty grant list, which resolves to [] * without throwing (GH #409). */ export declare class GrantLookupError extends Error { readonly status: number; constructor(message: string, status: number); } /** * Returns the cached sharing availability. null means no conclusive observation * yet (no calls made, or only transient errors seen). Exported for health_check. */ export declare function getSharingAvailability(): boolean | null; /** * Three (plus one) states health_check needs to distinguish (BRA-3611): * - "off": ENABLE_PROJECT_SHARING is not set — the state production is in. * Table presence is irrelevant and deliberately not probed. * - "unknown": toggle on, but no grant-related PostgREST call has happened * yet to observe whether the table exists. * - "healthy": toggle on, table confirmed present. * - "table_missing": toggle on, table confirmed absent — a real * misconfiguration, not an intended state. */ export type SharingStatus = "off" | "unknown" | "healthy" | "table_missing"; export declare function getSharingStatus(): SharingStatus; /** Reset the availability cache. Tests only — not for production use. */ export declare function resetSharingAvailabilityForTest(): void; /** * Normalizes a project identity into a folder-prefix path, e.g. 'projects/5280'. * Matches the segment rules storage/client.ts enforces for wiki paths. */ export declare function normalizeProjectPath(input: string): string; /** * Resolves a grantee identifier (email or existing subject/UUID) to a Supabase * user id. Per BRA-368 v0 decision: the grantee must already have a Brains * account — no pending/email-based invite support yet. Returns null if no * matching user exists. */ export declare function resolveGranteeSubject(input: string): Promise; export declare function upsertProjectShare(params: { owner_subject: string; project_path: string; grantee_subject: string; enabled: boolean; permissions?: ProjectSharePermission; }): Promise; /** Drop cached grants for one grantee, or all of them when called bare. */ export declare function invalidateGrantCache(granteeSubject?: string): void; export declare function listActiveGrantsForGrantee(granteeSubject: string): Promise; export interface ActiveGrantee { subject: string; permissions: ProjectSharePermission; } /** * Returns everyone who currently holds an active (non-revoked) grant on the * given owner+project_path, with their grant level. Used to re-render the * "Shared Workspace" note in project instructions whenever a grant is created * or revoked (BRA-388), so the note can name a grant read-only (GH #798 / * BRA-5160) rather than implying every collaborator has read+write. */ export declare function listActiveGranteesForProject(ownerSubject: string, projectPath: string): Promise; /** * Best-effort reverse lookup of a Supabase user's email from their subject/UUID. * Returns null if unavailable — callers should fall back to the raw subject. */ export declare function resolveSubjectEmail(subject: string): Promise; //# sourceMappingURL=projectShares.d.ts.map