/** * accessControl.ts * * Runtime governance for Hive (team) brains. * * When BRAINS_HIVE_MODE=true, all read paths filter pages by: * 1. access_level — page must have access_level ≤ requesting user's level * 2. audience — when session_audience is set, page audience must match * * Solo (non-Hive) brains: isHiveModeEnabled() returns false, userLevel is * effectively 5 (owner), and no filtering occurs. * * Access level hierarchy: * 1 = contributor (default) * 2 = team * 3 = manager * 4 = exec * 5 = owner */ export declare const ACCESS_LEVEL_CONTRIBUTOR = 1; export declare const ACCESS_LEVEL_TEAM = 2; export declare const ACCESS_LEVEL_MANAGER = 3; export declare const ACCESS_LEVEL_EXEC = 4; export declare const ACCESS_LEVEL_OWNER = 5; /** Default access level assigned to pages with no explicit access_level field. */ export declare const DEFAULT_PAGE_ACCESS_LEVEL = 1; /** Default audience assigned to pages with no explicit audience field. */ export declare const DEFAULT_PAGE_AUDIENCE: "internal"; /** Access context passed through all read paths. */ export interface AccessContext { /** The requesting user's access level (1–5). 5 = full access (solo / owner). */ userAccessLevel: number; /** * Optional audience constraint declared by the caller for this session. * "client-safe" → only return pages with audience client-safe or public. * "public" → only return pages with audience public. * Omitted / undefined → no audience filter applied. */ sessionAudience?: string; } /** Default context used when governance is not applicable (solo brains). */ export declare const DEFAULT_ACCESS_CONTEXT: AccessContext; /** * Returns true only when BRAINS_HIVE_MODE=true is set. * Solo (non-Hive) brains are a no-op for access control. */ export declare function isHiveModeEnabled(): boolean; /** * Coerce an unknown frontmatter value to a valid access level integer (1–5). * Returns DEFAULT_PAGE_ACCESS_LEVEL when the value is absent or invalid. */ export declare function parseAccessLevel(raw: unknown): number; /** * Coerce an unknown frontmatter value to a valid audience string. * Returns DEFAULT_PAGE_AUDIENCE when the value is absent or invalid. */ export declare function parseAudience(raw: unknown): string; /** * Returns true when the page should be visible to the requesting user. * * Rules: * - page.access_level ≤ user.access_level (numeric gate) * - if sessionAudience = "public" → page.audience must be "public" * - if sessionAudience = "client-safe" → page.audience must be "client-safe" or "public" * - otherwise no audience gate applies */ export declare function pagePassesFilter(pageAccessLevel: number, pageAudience: string | undefined, userAccessLevel: number, sessionAudience?: string): boolean; /** * Retrieves the access level for a given user from the `user_access_levels` * Supabase table. * * - Returns ACCESS_LEVEL_OWNER (5) when Hive mode is disabled (solo brains). * - Returns DEFAULT_PAGE_ACCESS_LEVEL (1) when the user has no entry. * - Falls back to DEFAULT_PAGE_ACCESS_LEVEL on any network/parse error. */ export declare function getUserAccessLevel(userId: string): Promise; /** * Fire-and-forget: write a governance filter event to Supabase. * Never throws — failures are silently ignored. */ export declare function writeGovernanceAuditEntry(userId: string, pageName: string, pageAccessLevel: number, userAccessLevel: number, sessionAudience?: string, reason?: string): void; /** * Read governance audit log entries. * Only exec+ users (access_level ≥ 4) may call this. */ export declare function readGovernanceAuditLog(requestingUserId: string, limit?: number): Promise; //# sourceMappingURL=accessControl.d.ts.map