import { ClientState, CiphersuiteImpl, LeafNode } from 'ts-mls'; export { CiphersuiteImpl, ClientState, getCiphersuiteImpl, nobleCryptoProvider } from 'ts-mls'; import { P as PeerIndex, C as CipherSuite } from '../ratchet-crypto-Bu7ZATDd.js'; import { F as FrameCryptor } from '../frame-cryptor-aRTX0FM-.js'; /** Options for {@link createMlsRatchetProvider}. */ interface MlsRatchetProviderOptions { /** The FrameCryptor to deliver epoch material to (via setEpoch). */ frameCryptor: FrameCryptor; /** SFrame cipher suite — determines chainKeyBytes (32 or 64). */ suite: CipherSuite; /** MLS group ID — bound into the exporter context for key separation. */ groupId: Uint8Array; /** * Maximum SFrame epoch number (inclusive). Defaults to 0xFFFF (16-bit, * fixed KID format). For MLS KID format, set to `2^nEpochBits - 1`. * The provider throws RangeError if the MLS epoch exceeds this. * Defaults to 0xFFFF (16-bit, fixed KID format). When using MLS KID * format with nEpochBits > 16, set this to `2^nEpochBits - 1` or pass * `nEpochBits` to let the provider compute the default. */ maxEpoch?: number; /** * MLS KID format epoch bit width. When provided and `maxEpoch` is not * explicitly set, the provider defaults `maxEpoch` to `2^nEpochBits - 1` * (repo-review-council #34). */ nEpochBits?: number; /** * Maps an MLS LeafNode credential to a peerId string. The default uses * base64(credential.identity) for basic credentials, base64(signaturePublicKey) * for X509. Override for custom credential → peerId mapping. */ credentialToPeerId?: (leaf: LeafNode) => string; /** Called after each epoch is applied to FrameCryptor. */ onEpochApplied?: (epoch: number, peerIndexMap: Record) => void; /** Called with the MLS epoch authenticator (32 bytes) for out-of-band verification. */ onEpochAuthenticator?: (authenticator: Uint8Array) => void; } /** The MLS ratchet provider — bridges ts-mls ClientState → FrameCryptor.setEpoch. */ interface MlsRatchetProvider { /** * Extract epoch material from a ts-mls ClientState and deliver it to * FrameCryptor. Call this after createGroup, joinGroup, or processMessage * (on epoch advance). * * @param state The current ts-mls ClientState (after epoch advance). * @param cs The CiphersuiteImpl matching the MLS group's cipher suite. */ applyEpoch(state: ClientState, cs: CiphersuiteImpl): Promise; /** Get the current epoch authenticator (for out-of-band verification). */ getEpochAuthenticator(state: ClientState): Uint8Array; /** Mark the provider as disposed; subsequent applyEpoch calls throw. */ dispose(): void; } /** * Default credential → peerId mapping. * Basic credential → base64(identity). * X509 credential → base64(signaturePublicKey) (certificate subject is not used). */ declare function defaultCredentialToPeerId(leaf: LeafNode): string; /** * Epoch material extracted from a ts-mls ClientState — the common output * needed by both FrameCryptor.setEpoch (media path) and MlsChatProvider.setEpoch * (chat path). Extracted so the chat path does NOT need a mock FrameCryptor * to capture the ChainKey. */ interface MlsEpochMaterial { /** MLS epoch number. */ epoch: number; /** peerId → peerIndex map (lex-sorted, §7.8-valid). */ peerIndexMap: Record; /** MLS ChainKey (suite.chainKeyBytes long). CALLER must zeroize after use. */ chainKey: Uint8Array; /** 32-byte epoch authenticator for out-of-band verification. */ epochAuthenticator: Uint8Array; } /** * Derive epoch material (ChainKey + peerIndexMap + authenticator) from a * ts-mls ClientState. This is the shared core of `createMlsRatchetProvider.applyEpoch` * — extracted so the chat path (`createMlsChatProvider`) can consume it without * a FrameCryptor. * * The caller is responsible for zeroizing the ChainKey after delivering it to * the consumer (FrameCryptor.setEpoch or MlsChatProvider.setEpoch — both * zeroize internally, but defense-in-depth: the caller should too if it keeps * a reference). * * @param state ts-mls ClientState (after epoch advance). * @param cs CiphersuiteImpl matching the MLS group's cipher suite. * @param suite SFrame cipher suite — determines chainKeyBytes. * @param groupId MLS group ID — bound into the exporter context. * @param maxEpoch Maximum epoch (KID bit width guard). Default 0xFFFF. * @param credentialToPeerId Maps MLS LeafNode → peerId string. * @returns Epoch material (epoch, peerIndexMap, chainKey, epochAuthenticator). */ declare function deriveMlsEpochMaterial(state: ClientState, cs: CiphersuiteImpl, suite: CipherSuite, groupId: Uint8Array, maxEpoch?: number, credentialToPeerId?: (leaf: LeafNode) => string): Promise; /** * Create an MLS ratchet provider that bridges ts-mls group state → SFrame AEAD. * * The provider is stateless regarding MLS group state — the caller manages the * ts-mls group lifecycle (createGroup, joinGroup, processMessage) and calls * `applyEpoch` after each epoch advance. * * @example * ```ts * const cs = await getCiphersuiteImpl( * 'MLS_128_DHKEMX25519_AES128GCM_SHA256_Ed25519', * nobleCryptoProvider, * ); * const state = await createGroup(groupId, keyPackage, privateKeyPackage, [], cs); * const provider = createMlsRatchetProvider({ * frameCryptor, suite: 'AES_128_GCM_SHA256', groupId, * }); * await provider.applyEpoch(state, cs); * ``` */ declare function createMlsRatchetProvider(opts: MlsRatchetProviderOptions): MlsRatchetProvider; export { type MlsEpochMaterial, type MlsRatchetProvider, type MlsRatchetProviderOptions, createMlsRatchetProvider, defaultCredentialToPeerId, deriveMlsEpochMaterial };