/** * Capability → entitlement-block grant requirements (commercial RBAC ceiling map). * * Authoring tokens use PIPE / SLASH / GLOB / LITERAL per expandAuthoringTokens. * Runtime CAPABILITY_ENTITLEMENT_REQUIREMENTS stores expanded literals only. * * NEVER import admin-app or up-backend into this module. */ import type { EntitlementBlockKey } from './types.js'; /** Copied PAYMENTS_HUB_NAV_ENTITLEMENT_ALL_OF literals (do not import admin-app). */ export declare const PAYMENTS_HUB_NAV_ENTITLEMENT_ALL_OF: readonly ["payments_hub_ui", "bank_inbox_claims_api"]; /** Advanced explore tab — Analytika entitlement only; PII is RBAC capability-gated. */ export declare const EXPLORE_ENTITLEMENT_ALL_OF: readonly ["analytics_explore"]; /** * Catalog CORE_IMMUTABLE keys — CI fails if any grant row lists these as requiredBlockKeys. * Do NOT list CONDITIONAL blocks here (they must remain requirable for fail-closed * grant ceilings when a pack is off). Commercial admin:outbox:* / tenant.outbox.* are * entitlementExempt — Události visibility is route-gated via incident_centre_ui only; * outbox_runtime stays CORE_IMMUTABLE ALWAYS_ON (workers), never a grant requirement. */ export declare const NEVER_REQUIRED_BLOCK_KEYS: readonly ["platform_core", "dev_entitlement_policy_editor", "audit_event_collection", "gdpr_consent_admin_ui", "payment_processing_runtime", "outbox_runtime"]; export type CapabilityEntitlementMatch = 'ALL' | 'ANY'; export type CapabilityEntitlementRequirement = { readonly capabilityKeys: readonly string[]; readonly entitlementExempt?: true; readonly requiredBlockKeys?: readonly EntitlementBlockKey[]; readonly match: CapabilityEntitlementMatch; }; export type CapabilityEntitlementLookup = { readonly kind: 'exempt'; } | { readonly kind: 'blocks'; readonly blockKeys: readonly EntitlementBlockKey[]; readonly match: CapabilityEntitlementMatch; } | { readonly kind: 'unmapped'; }; export type EvaluateCapabilityEntitlementResult = { readonly allowed: boolean; readonly missingBlockKeys: readonly EntitlementBlockKey[]; }; /** * Expand authoring tokens to sorted unique capability literals. * Algorithm: PIPE → SLASH → GLOB (one-level) → LITERAL. Pure; CI passes real LIVE_IDS. */ export declare function expandAuthoringTokens(tokens: readonly string[], liveIds: readonly string[]): readonly string[]; /** * LIVE_IDS snapshot for in-module authoring expansion only. * CI gate-capability-entitlement-requirements must assert equality with * getAllCanonicalRecords ∪ getAllCapabilityNames. */ export declare const CAPABILITY_ENTITLEMENT_LIVE_IDS_SNAPSHOT: readonly string[]; export declare const CAPABILITY_ENTITLEMENT_REQUIREMENTS: readonly CapabilityEntitlementRequirement[]; export declare function requiredBlocksForCapability(capabilityKey: string): CapabilityEntitlementLookup; export declare function capabilitiesRequiringBlock(blockKey: EntitlementBlockKey): readonly string[]; /** * Evaluate whether a capability is entitled given a write-ALLOW predicate on block keys. * ALL: every required block must be write-allowed. * ANY: at least one required block must be write-allowed (reserved; CapMap is ALL-only — * commercial outbox grants are entitlementExempt, not ANY(SIC|notifications)). */ export declare function evaluateCapabilityEntitlement(capabilityKey: string, options: { readonly isWriteAllowed: (blockKey: EntitlementBlockKey) => boolean; }): EvaluateCapabilityEntitlementResult; //# sourceMappingURL=capabilityEntitlementRequirements.d.ts.map