/**
 * Admin-issued MCP access — the token analogue of impersonation.
 *
 * POST /companies/{id}/mcp-token and POST /users/{id}/mcp-token issue a client
 * durable MCP service credentials (client_id + client_secret) plus a ready-to-use
 * short-lived Bearer token, so they connect an MCP client without the
 * email/password OAuth flow.
 */

/** Optional tuning for the issued MCP token. Everything defaults server-side. */
export interface GenerateMcpTokenPayload {
  /** Credential label (defaults to "Admin-issued (#<adminId>)"). */
  name?: string;
  /** Durable credential (client_id/secret) expiry, in days. Omit = never expires. */
  expires_in_days?: number;
  /** Ready-to-use Bearer token TTL, in minutes (5–1440, default 60). */
  ttl_minutes?: number;
}

/** Result of an admin-issued MCP token. `client_secret` is shown ONCE. */
export interface McpTokenResult {
  /** Ready to paste as `Authorization: Bearer <access_token>` now (short-lived). */
  access_token: string;
  token_type: string;
  /** Access-token lifetime, in seconds. */
  expires_in: number;
  /** Durable, revocable credential id. */
  client_id: string;
  /** Durable secret — returned ONCE, never stored in clear. */
  client_secret: string;
  /** ISO date the durable credential expires, or null = never. */
  credential_expires_at: string | null;
  /** Where the client points its MCP client. */
  mcp_url: string;
  /** Where the client re-mints tokens (client_credentials grant). */
  token_endpoint: string;
  user: {
    id: number;
    email: string;
    name: string | null;
  };
}

/** One durable MCP credential as listed on the admin side (never the secret). */
export interface McpCredential {
  id: number;
  client_id: string;
  name: string;
  /** active = usable · expired = past expires_at · revoked = revoked_at set. */
  status: "active" | "expired" | "revoked";
  usable: boolean;
  last_used_at: string | null;
  expires_at: string | null;
  revoked_at: string | null;
  created_at: string;
}
