/** * HTTP helpers for capability checks. */ import { type CapabilityId, type UserDto } from 'ysk-server-shared'; import type { AppContext } from '../app-context.js'; import type { IncomingMessage } from 'node:http'; /** Resolve store fields + require capability (throws YskError 403). */ export declare function requireCap(ctx: AppContext, user: UserDto, cap: CapabilityId): void; /** GET surfaces that any of several read/write caps may open. */ export declare function requireAnyCap(ctx: AppContext, user: UserDto, caps: readonly CapabilityId[]): void; export declare function effectiveCaps(ctx: AppContext, user: UserDto): string[]; /** * Host-browse iframe content / form POST is authenticated by contentToken * in the query string (browser cannot attach Authorization). Bearer GET * inventory must not 401 these — that response is X-Frame-Options: DENY * and the panel shows “refused to connect” after a successful navigate. */ export declare function isHostBrowseTokenPath(pathname: string): boolean; /** * Central gate for mutating /api/v1 routes listed in MUTATING_ROUTE_CAP_RULES. * Call early in the HTTP pipeline; throws YskError on deny. * No-op when method is not mutating or path has no rule. */ export declare function enforceMutatingRouteCaps(ctx: AppContext, req: IncomingMessage, method: string, pathname: string): void; /** * Central GET inventory gate (any-of caps). No-op when no rule or skipped. */ export declare function enforceGetRouteCaps(ctx: AppContext, req: IncomingMessage, method: string, pathname: string): void; //# sourceMappingURL=rbac-guard.d.ts.map