openclaw
Version:
Multi-channel AI gateway with extensible messaging integrations
85 lines • 4.02 kB
TypeScript
import { t as ChannelId } from "./channel-id.types-CjcGKHk0.js";
//#region src/security/dm-policy-shared.d.ts
/**
* Derive a stable main-DM owner from a single-entry allowlist.
* Wildcards, multi-owner lists, and non-main DM scopes stay unpinned so callers keep route-specific sessions.
*/
declare function resolvePinnedMainDmOwnerFromAllowlist(params: {
dmScope?: string | null;
allowFrom?: Array<string | number> | null;
normalizeEntry: (entry: string) => string | undefined;
}): string | null;
/** @deprecated Use `resolveChannelMessageIngress` from `openclaw/plugin-sdk/channel-ingress-runtime`. */
declare function resolveEffectiveAllowFromLists(params: {
allowFrom?: Array<string | number> | null;
groupAllowFrom?: Array<string | number> | null;
storeAllowFrom?: Array<string | number> | null;
dmPolicy?: string | null;
groupAllowFromFallbackToAllowFrom?: boolean | null;
}): {
effectiveAllowFrom: string[];
effectiveGroupAllowFrom: string[];
};
/** Admission decision returned by legacy DM/group access helpers. */
type DmGroupAccessDecision = "allow" | "block" | "pairing";
/** Stable reason codes used by channel plugins, command auth, and diagnostics. */
declare const DM_GROUP_ACCESS_REASON: {
readonly GROUP_POLICY_ALLOWED: "group_policy_allowed";
readonly GROUP_POLICY_DISABLED: "group_policy_disabled";
readonly GROUP_POLICY_EMPTY_ALLOWLIST: "group_policy_empty_allowlist";
readonly GROUP_POLICY_NOT_ALLOWLISTED: "group_policy_not_allowlisted";
readonly DM_POLICY_OPEN: "dm_policy_open";
readonly DM_POLICY_DISABLED: "dm_policy_disabled";
readonly DM_POLICY_ALLOWLISTED: "dm_policy_allowlisted";
readonly DM_POLICY_PAIRING_REQUIRED: "dm_policy_pairing_required";
readonly DM_POLICY_NOT_ALLOWLISTED: "dm_policy_not_allowlisted";
};
/** Machine-readable reason code for a DM/group access decision. */
type DmGroupAccessReasonCode = (typeof DM_GROUP_ACCESS_REASON)[keyof typeof DM_GROUP_ACCESS_REASON];
type DmGroupAccessResult = {
decision: DmGroupAccessDecision;
reasonCode: DmGroupAccessReasonCode;
reason: string;
};
/**
* Resolve sender access for `dmPolicy=open`, where `*` means fully open and a configured
* allowlist still restricts the accepted sender set.
*
* @deprecated Use `resolveChannelMessageIngress` from `openclaw/plugin-sdk/channel-ingress-runtime`.
*/
declare function resolveOpenDmAllowlistAccess(params: {
effectiveAllowFrom: Array<string | number>;
isSenderAllowed: (allowFrom: string[]) => boolean;
}): DmGroupAccessResult;
type DmGroupAccessInputParams = {
isGroup: boolean;
dmPolicy?: string | null;
groupPolicy?: string | null;
allowFrom?: Array<string | number> | null;
groupAllowFrom?: Array<string | number> | null;
storeAllowFrom?: Array<string | number> | null;
groupAllowFromFallbackToAllowFrom?: boolean | null;
isSenderAllowed: (allowFrom: string[]) => boolean;
};
/** @deprecated Use `resolveChannelMessageIngress` or `readChannelIngressStoreAllowFromForDmPolicy` from `openclaw/plugin-sdk/channel-ingress-runtime`. */
declare function readStoreAllowFromForDmPolicy(params: {
provider: ChannelId;
accountId: string;
dmPolicy?: string | null;
shouldRead?: boolean | null;
readStore?: (provider: ChannelId, accountId: string) => Promise<string[]>;
}): Promise<string[]>;
/**
* Resolve legacy DM/group sender admission and return the effective allowlists used.
*
* @deprecated Use `resolveChannelMessageIngress` from `openclaw/plugin-sdk/channel-ingress-runtime`.
*/
declare function resolveDmGroupAccessWithLists(params: DmGroupAccessInputParams): {
decision: DmGroupAccessDecision;
reasonCode: DmGroupAccessReasonCode;
reason: string;
effectiveAllowFrom: string[];
effectiveGroupAllowFrom: string[];
};
//#endregion
export { resolveEffectiveAllowFromLists as a, resolveDmGroupAccessWithLists as i, DmGroupAccessReasonCode as n, resolveOpenDmAllowlistAccess as o, readStoreAllowFromForDmPolicy as r, resolvePinnedMainDmOwnerFromAllowlist as s, DM_GROUP_ACCESS_REASON as t };