import { validateTenantId } from './validate.js'; import { enableTenantRls, tenantIsolationPolicy, verifyPrincipalContext } from './rls.js'; import { propagateTenantLocals } from './propagate.js'; import { extractTenant } from './extract.js'; import { isTenantScoped } from './scope.js'; /** Multi-tenant isolation namespace — RLS policies, tenant extraction, Postgres-side verification. */ export declare const tenant: { /** Validates a tenant ID format (non-empty string, safe characters). */ validate: typeof validateTenantId; /** Enables RLS on a table and creates the tenant isolation policy in Postgres. */ rls: typeof enableTenantRls; /** Returns the SQL string for a tenant isolation RLS policy — use in migrations. */ policy: typeof tenantIsolationPolicy; /** Cross-checks the ALS principal (tenant, user, asOf) against the Postgres session GUCs — defense-in-depth. */ verify: typeof verifyPrincipalContext; /** Sets pipework.tenant_id on the Postgres connection via set_config(). */ propagate: typeof propagateTenantLocals; /** Extracts tenant ID from auth context using the configured extraction strategy. */ extract: typeof extractTenant; /** Returns true if a table has been marked as tenant-scoped (via .tenant() field metadata). */ isTenantScoped: typeof isTenantScoped; }; //# sourceMappingURL=namespace.d.ts.map