import type { ColumnInfo } from "../types.js"; import { type CheckHints } from "./values.js"; /** * The most private value a visibility column can hold. * * Third structural invariant: a row we plant is seeded to its most private * state, so that a cross-user read of it can never be explained away as "that * row was published on purpose". Shared by both ways of planting a row — * synthesis, which builds one from nothing, and cloning, which copies one that * already exists — because the invariant belongs to the row, not to how it was * made. * * Returns `undefined` when the column enumerates states none of which is * recognisably private (`active`/`archived`). The callers differ in what they * then do, and deliberately: synthesis picks an ordinary value, while cloning * refuses a template whose value looks *published*, since copying a published * row would relax the invariant rather than merely fail to strengthen it. */ export declare function mostPrivateValue(col: ColumnInfo, hints: CheckHints | undefined): unknown | undefined; /** * Does this value put the row in a state the application calls public? * * Asked only of visibility columns whose private value we could not determine, * and only when cloning. A copy of a row flagged `is_public = true` would be * reachable across users by design, so a "leak" of it would prove nothing — * exactly the false positive the private-by-default invariant exists to * prevent. */ export declare function looksPublic(col: ColumnInfo, value: unknown): boolean; /** * The same question asked of a field of a JSON response rather than of a * column. * * The application plane has no catalog to read, so it has a name and a value * and nothing else — which is all this ever used. Kept as one implementation * because it is the third structural invariant, and an invariant with two * definitions is an invariant with one of them out of date. */ export declare function valueLooksPublic(column: string, value: unknown): boolean; /** * The most private value a *field of a JSON resource* can hold, inferred from * the name and the value the application itself put there. * * The third structural invariant, on the plane that had lost it. Where there is * a schema, the invariant is kept by writing the most private value into the * visibility column before the row is planted, so that a cross-user read can * never be explained away as "that row was published on purpose". Through an * endpoint there is no column to write — but there is a field the application * showed us in its own reply, and asking it to create the same resource with * that field set the other way costs one request and recovers the invariant. * * Deliberately narrow. It answers only for the shapes whose private state is * unambiguous — a boolean flag, and an empty list of audiences — plus the one * string every application spells the same way. `undefined` means "no value * here is recognisably private", and the caller's answer to that is to plant * nothing and claim nothing, which is what it did before this existed. */ export declare function privateValueFor(column: string, value: unknown): unknown | undefined;