import type { PeerSecurityState as InternalPeerSecurityState, SecurityBackend, SecurityCancelPairingResult as InternalSecurityCancelPairingResult, SecurityUnpairResult as InternalSecurityUnpairResult } from '../backend-contract/security.js'; import type { FeatureId, Limitation } from '../backend-contract/capabilities.js'; import type { OperationOptions } from './operation-options.js'; import { type BlePeer } from './ble-manager.js'; import type { BlePeerDirectory } from './peer-directory.js'; import type { PeerReference } from './peer-reference.js'; export type SecurityBondState = InternalPeerSecurityState['bond']; export type SecurityEncryptionState = InternalPeerSecurityState['encryption']; export type SecurityAuthenticationState = InternalPeerSecurityState['authentication']; export type SecureConnectionsState = InternalPeerSecurityState['secureConnections']; export interface PeerSecurityState { readonly bond: SecurityBondState; readonly encryption: SecurityEncryptionState; readonly authentication: SecurityAuthenticationState; readonly secureConnections: SecureConnectionsState; readonly pairingPossible: boolean | null; readonly measuredAtMonotonicMs: number; readonly limitations: readonly Limitation[]; } export interface PeerSecurityEvent { readonly kind: 'state'; readonly peerId: string; readonly sequence: number; readonly state: PeerSecurityState; } export interface PairOptions extends OperationOptions { readonly transport?: 'le' | 'auto'; readonly protection?: 'system-default' | 'encrypted' | 'authenticated'; readonly ceremony?: 'system' | PairingAgent; /** * Preferred LE pairing generation. Defaults to 'prefer' (platform decides). * Use 'disallow' for peers that reject LE Secure Connections and require * legacy pairing. Backends that cannot honour it return an unsupported error. */ readonly secureConnections?: 'require' | 'prefer' | 'disallow'; } export type PairingChallenge = { readonly kind: 'confirm'; readonly peer: BlePeer; readonly challengeId: string; readonly deadlineMonotonicMs: number; } | { readonly kind: 'confirm-passkey'; readonly peer: BlePeer; readonly challengeId: string; readonly passkey: number; readonly deadlineMonotonicMs: number; } | { readonly kind: 'display-passkey'; readonly peer: BlePeer; readonly challengeId: string; readonly passkey: number; readonly deadlineMonotonicMs: number; } | { readonly kind: 'provide-pin'; readonly peer: BlePeer; readonly challengeId: string; readonly deadlineMonotonicMs: number; } | { readonly kind: 'provide-passkey'; readonly peer: BlePeer; readonly challengeId: string; readonly deadlineMonotonicMs: number; }; export type PairingResponse = { readonly kind: 'confirm'; readonly confirmed: boolean; } | { readonly kind: 'confirm-passkey'; readonly confirmed: boolean; } | { readonly kind: 'display-passkey'; readonly acknowledged: boolean; } | { readonly kind: 'provide-pin'; readonly pin: string; } | { readonly kind: 'provide-passkey'; readonly passkey: string; }; export interface PairingAgent { onChallenge(challenge: PairingChallenge): Promise; } export type PairResult = { readonly outcome: 'paired'; readonly state: PeerSecurityState; } | { readonly outcome: 'already-paired'; readonly state: PeerSecurityState; } | { readonly outcome: 'repaired'; readonly state: PeerSecurityState; } | { readonly outcome: 'rejected'; readonly reason: string | null; } | { readonly outcome: 'cancelled'; }; export type PairCancelResult = InternalSecurityCancelPairingResult; export type UnpairResult = InternalSecurityUnpairResult; export type SecurityPeer = BlePeer | PeerReference; export interface BleSecurity { state(peer: SecurityPeer, options?: OperationOptions): Promise; watch(peer: SecurityPeer): AsyncIterable; pair(peer: SecurityPeer, options?: PairOptions): Promise; cancelPairing(peer: SecurityPeer, options?: OperationOptions): Promise; unpair(peer: SecurityPeer, options?: OperationOptions): Promise; } export type SecurityRequirement = 'encrypted' | 'authenticated'; export interface RequiredSecurityOptions { readonly state?: OperationOptions; /** Pairing is never implicit; this option is the explicit opt-in. */ readonly pair?: PairOptions; } export declare function withRequiredSecurity(security: BleSecurity, peer: SecurityPeer, requirement: SecurityRequirement, action: () => Promise, options?: RequiredSecurityOptions): Promise; interface SecurityCapabilitySource { capability?: (id: FeatureId) => { readonly state: string; } | null; get?: (id: FeatureId) => { readonly state: string; } | undefined; } export declare function createPublicSecurity(backend: SecurityBackend | undefined, peers: BlePeerDirectory, capabilities: SecurityCapabilitySource, now: () => number): BleSecurity; export {}; //# sourceMappingURL=security.d.ts.map