import { type DetailV1, type FailureKind, type Outcome, type SnapshotV1, type WindowId } from "./dashboard-contract.js"; import { type DashboardBootstrap, type DashboardBootstrapResult, type DashboardLogoutResult, type DashboardSession, type DashboardSessionResult } from "./dashboard-auth.js"; export { DASHBOARD_MEDIA_TYPE } from "./dashboard-contract.js"; export declare const DASHBOARD_BOOTSTRAP_SCHEMA: "dashboard.bootstrap.v1"; export declare const DASHBOARD_SESSION_SCHEMA: "dashboard.session.v1"; export declare const DASHBOARD_BOOTSTRAP_REQUEST_SCHEMA: "dashboard.bootstrap.request.v1"; export declare const DASHBOARD_SESSION_REQUEST_SCHEMA: "dashboard.session.request.v1"; export declare const DASHBOARD_LOGOUT_REQUEST_SCHEMA: "dashboard.logout.request.v1"; /** A server-normalized, lowercased header map. Values stay multi-valued. */ export type DashboardHeaderMap = Readonly>; export interface DashboardAdmissionDenied { readonly hostAuthorized: false; } export interface DashboardAdmissionAllowed { readonly hostAuthorized: true; readonly expectedOrigin: string; readonly controlAuthorized: boolean; } export type DashboardAdmission = DashboardAdmissionDenied | DashboardAdmissionAllowed; export interface DashboardRouteRequest { readonly method: string; /** The raw request target, including its query string. */ readonly target: string; readonly headers: DashboardHeaderMap; /** Host/control admission is deliberately supplied by the server boundary. */ readonly admission: DashboardAdmission; /** Body buffering/streaming remains server-owned and is invoked at most once. */ readonly readBody: (maxBytes: number) => Promise; } export interface DashboardSnapshotQuery { readonly window: WindowId; readonly includeRepair: boolean; readonly attribution?: "relay-held" | "caller-operated" | "all"; readonly provider?: string; readonly model?: string; readonly client?: string; readonly credentialId?: string; readonly outcome?: Outcome; readonly failureKind?: FailureKind; } export interface DashboardDetailQuery { readonly requestId: string; readonly includeRepair: boolean; } export interface DashboardReadPort { readSnapshot(query: DashboardSnapshotQuery): Promise; readDetail(query: DashboardDetailQuery): Promise; } /** The auth port intentionally permits synchronous or asynchronous test seams. */ export interface DashboardAuthPort { createBootstrap(): DashboardBootstrap | Promise; exchangeBootstrap(candidate: string): DashboardBootstrapResult | Promise; createSession?(): DashboardSession | Promise; validateSession(candidate: string): DashboardSessionResult | Promise; logout(candidate: string): DashboardLogoutResult | Promise; } export interface DashboardRouteDependencies { readonly auth: DashboardAuthPort; readonly read: DashboardReadPort; } export interface DashboardRouteHandled { readonly handled: true; readonly status: number; readonly headers: Readonly>; /** Omitted for HEAD and for a 204 response. */ readonly body?: Uint8Array; } export interface DashboardRouteNotHandled { readonly handled: false; } export type DashboardRouteResponse = DashboardRouteHandled | DashboardRouteNotHandled; /** * The code a body reader sets when it refused a body for exceeding the cap. * * Exported so the PRODUCER and this consumer share one definition. Until 2026-08-25 the accepted * set was three codes that nothing in the repo ever set, so the only live classifier was a regex * over the error MESSAGE — the relay sniffing prose it had written itself, one line away from * deciding 413-vs-500. That is the inference this codebase refuses everywhere else * (`rate-limits.ts` needs an explicit axis and period; `refusal-interpretation.ts` is lookup, * never inference), and it was wrong in both directions: any unrelated rejection whose message * happened to contain "exceeded" — a timeout wrapper, a RangeError — was served as `oversized`, * and a future reader with different wording would silently become `internal`. */ export { BODY_TOO_LARGE_CODE } from "./stream-pipeline.js"; /** * Pure async dashboard API route handler. It returns `handled:false` for all * non-dashboard targets so the caller can continue routing existing endpoints. */ export declare function handleDashboardRoute(request: DashboardRouteRequest, dependencies: DashboardRouteDependencies): Promise; /** Small object wrapper useful to production mounts and unit tests. */ export declare class DashboardRouteHandler { #private; constructor(dependencies: DashboardRouteDependencies); handle(request: DashboardRouteRequest): Promise; } export declare function createDashboardRouteHandler(dependencies: DashboardRouteDependencies): DashboardRouteHandler;