import type { ValidationIssue } from './types.js'; import type { ResolvedDatabase } from '../config/load.js'; import type { IsolationStrategy } from '../config/schema.js'; export interface RlsRoleProbe { readonly role: string; readonly superuser: boolean; readonly bypassRls: boolean; } export declare function rlsRoleMessage(database: string, probe: RlsRoleProbe): string; /** The connection whose role actually executes queries under the harness: transaction isolation collapses every role onto the resolved `url` connection; database/container isolation resolves roles normally (`appUrl ?? url`). */ export declare function rlsProbeTarget(db: ResolvedDatabase, strategy: IsolationStrategy): string; /** Role flags for `current_user` at `url`. Short-lived probe connection, mirroring validateConnectivity. */ export declare function probeRlsRole(url: string, timeoutMs?: number): Promise; /** Startup-validation leg: for each database with `rls` configured, the runtime connection's role (`appUrl ?? url`) must not bypass RLS. */ export declare function validateRlsRoles(databases: ReadonlyMap, timeoutMs?: number): Promise; //# sourceMappingURL=rls-role.d.ts.map