import { a as ConfigStorage, A as AuthConfigStorage, U as UserAuthConfig, f as OAuthFlowContext, g as ProfileStore } from '../file-format-Bpmgm2Po.mjs'; import { C as CliDescriptor, A as AuthContext, a as CloudflareAuth, U as UserPreferences, K as KeyringPreferenceContext, S as SetKeyringPreferenceResult } from '../keyring-preference-CWjI7ct9.mjs'; export { b as CloudflareLoginProps } from '../keyring-preference-CWjI7ct9.mjs'; import '@cloudflare/workers-utils'; /** * A JSON-file-on-disk storage backend (cf's on-disk format), a thin * `JSON`-bound wrapper over the CLI-agnostic {@link createFileStorage}. */ declare function createJsonFileStorage(getPath: () => string): ConfigStorage; declare const getAuthConfigFilePath: (profile?: string) => string; declare const getEncryptedAuthConfigFilePath: (profile?: string) => string; declare const defaultAuthConfigStorage: (profile?: string) => AuthConfigStorage; declare const readAuthConfigFile: (profile?: string) => UserAuthConfig | undefined; declare const writeAuthConfigFile: (config: UserAuthConfig, profile?: string) => void; declare const CF_REGISTERED_SCOPES: readonly ["access:read", "access:write", "account:read", "agw:read", "agw:run", "agw:write", "ai:read", "ai:write", "ai-search:read", "ai-search:run", "ai-search:write", "aiaudit:read", "aiaudit:write", "aig:read", "aig:write", "auditlogs:read", "billing:read", "billing:write", "browser:read", "browser:write", "cfone:read", "cfone:write", "cloudchamber:write", "connectivity:admin", "connectivity:bind", "connectivity:read", "constellation:write", "containers:write", "d1:write", "dex:read", "dex:write", "dns_analytics:read", "dns_records:edit", "dns_records:read", "dns_settings:read", "email_routing:read", "email_routing:write", "email_sending:read", "email_sending:write", "firstpartytags:write", "images:read", "images:write", "lb:edit", "lb:read", "logpush:read", "logpush:write", "mcp_portals:read", "mcp_portals:write", "notebook-examples:read", "notebook-managed:read", "notification:read", "notification:write", "oauth_account_ssl_and_certificates_write", "offline", "openid", "pages:read", "pages:write", "pipelines:read", "pipelines:setup", "pipelines:write", "query_cache:write", "queues:write", "r2_catalog:write", "radar:read", "rag:read", "rag:write", "registrar:read", "registrar:write", "secrets_store:read", "secrets_store:write", "sso-connector:read", "sso-connector:write", "ssl_certs:write", "teams:pii", "teams:read", "teams:secure_location", "teams:write", "url_scanner:read", "url_scanner:write", "user:read", "vectorize:write", "workers:read", "workers:write", "workers_builds:read", "workers_builds:write", "workers_deployments:read", "workers_kv:write", "workers_observability:read", "workers_observability:write", "workers_observability_telemetry:write", "workers_routes:write", "workers_scripts:write", "workers_tail:read", "zone:read", "account-analytics.read", "account-ssl-and-certificates.write", "ssl-and-certificates.read", "ssl-and-certificates.write", "registrar-domains.read", "registrar-domains.admin", "logs.read", "logs.write", "websearch.run", "snippets.read", "snippets.write", "access-acct.read", "access-acct.revoke", "access-acct.write", "access-app.read", "access-app.revoke", "access-app.write", "access-audit-log.read", "access-certificate.read", "access-certificate.write", "access-custom-page.read", "access-custom-page.write", "access-device-posture.read", "access-device-posture.write", "access-group.read", "access-group.write", "access-idp.read", "access-idp.write", "access-key.read", "access-key.write", "access-org.read", "access-org.revoke", "access-org.write", "access-policy-test.read", "access-policy-test.write", "access-policy.read", "access-policy.write", "access-population.read", "access-population.write", "access-saml-certificate.read", "access-saml-certificate.write", "access-scim-log.read", "access-seats.write", "access-service-token.read", "access-service-token.write", "access-ssh-auditing.read", "access-ssh-auditing.write", "access-tag.read", "access-tag.write", "access-users.read", "access-users.write", "access.read", "access.revoke", "access.write", "account-api-gateway.read", "account-api-gateway.write", "account-custom-asset.read", "account-custom-asset.write", "account-custom-error-rules.read", "account-custom-error-rules.write", "account-custom-pages.read", "account-custom-pages.write", "account-disable-esc.read", "account-disable-esc.write", "account-dns-settings.read", "account-dns-settings.write", "account-firewall-access-rules.read", "account-firewall-access-rules.write", "account-logs.read", "account-logs.write", "account-rule-lists.read", "account-rule-lists.write", "account-rulesets.read", "account-rulesets.write", "account-security-center-insights.read", "account-security-center-insights.write", "account-settings.read", "account-settings.write", "account-ssl-and-certificates.read", "account-waf.read", "account-waf.write", "account-waiting-rooms.read", "address-maps.read", "address-maps.write", "agent-memory.write", "agw.read", "agw.run", "agw.write", "ai-search.index", "ai-search.metadata_read", "ai-search.read", "ai-search.run", "ai-search.write", "ai.read", "ai.write", "aiaudit.read", "aiaudit.write", "aig.metadata_read", "aig.read", "aig.run", "aig.write", "analytics.read", "api-gateway.read", "api-gateway.write", "apps.write", "argotunnel.read", "argotunnel.write", "artifacts.read", "artifacts.write", "bot-management-feedback.read", "bot-management-feedback.write", "bot-management.read", "bot-management.write", "browser-rendering.read", "browser-rendering.write", "cache-settings.read", "cache-settings.write", "cache.purge", "calls.read", "calls.write", "casb.read", "casb.write", "cf-agents.read", "cf-agents.write", "challenge-widgets.read", "challenge-widgets.write", "chinanetwork-steering.read", "chinanetwork-steering.write", "cloud-connector.read", "cloud-connector.write", "cloud-email-security.read", "cloud-email-security.write", "cloudchamber.read", "cloudchamber.write", "cloudforce-one.read", "cloudforce-one.write", "config-settings.read", "config-settings.write", "connectivity-directory.admin", "connectivity-directory.bind", "connectivity-directory.read", "constellation.read", "constellation.write", "containers.read", "containers.write", "custom-errors.read", "custom-errors.write", "custom-pages.read", "custom-pages.write", "d1.metadata_read", "d1.read", "d1.write", "ddos-botnet-feed.read", "ddos-botnet-feed.write", "ddos-protection.read", "ddos-protection.write", "dls.read", "dls.write", "dns-firewall.read", "dns-firewall.write", "dns-view.read", "dns-view.write", "dns.read", "dns.write", "domain-page-shield.read", "domain-page.shield", "dynamic-redirect.read", "dynamic-redirect.write", "email-routing-account-rule.read", "email-routing-address.read", "email-routing-address.write", "email-routing-rule.read", "email-routing-rule.write", "email-routing-suppression.read", "email-routing-suppression.write", "email-security-dmarcreports.read", "email-security-dmarcreports.write", "email-sending.read", "email-sending.write", "fbm.admin", "fbm.read", "fbm.write", "field-extractor.read", "field-extractor.write", "firewall-for-ai.read", "firewall-for-ai.write", "firewall-services.read", "firewall-services.write", "flagship.evaluate", "flagship.read", "flagship.write", "fraud-detection-pii.read", "fraud-detection.read", "fraud-detection.write", "fraud-events.write", "fraud-feedback.read", "fraud-feedback.write", "healthcheck.read", "healthcheck.write", "http-applications.read", "http-applications.write", "http-ddos-managed-ruleset.read", "http-ddos-managed-ruleset.write", "images.metadata_read", "images.read", "images.write", "integration.write", "intel.read", "intel.write", "iot.read", "iot.write", "ip-prefix-bgp-on-demand.read", "ip-prefix-bgp-on-demand.write", "ip-prefix.read", "ip-prefix.write", "l4-ddos-managed-ruleset.read", "l4-ddos-managed-ruleset.write", "load-balancers-account.read", "load-balancers-account.write", "load-balancers.read", "load-balancers.write", "load-balancing-monitors-and-pools.read", "load-balancing-monitors-and-pools.write", "magic-firewall.read", "magic-firewall.write", "magic-transit.read", "magic-transit.write", "magic-wan.read", "magic-wan.write", "managed-headers.read", "managed-headers.write", "mass-url-redirects.read", "mass-url-redirects.write", "mcp-portals.read", "mcp-portals.write", "memberships.read", "memberships.write", "messaging.edit", "messaging.metadata_read", "messaging.read", "moq.read", "moq.write", "notifications.read", "notifications.write", "origin.read", "origin.write", "page-rules.read", "page-rules.write", "page-shield.read", "page.read", "page.shield", "page.write", "pages.metadata_read", "payments-gateway.read", "payments-gateway.write", "pcaps-api.read", "pcaps-api.write", "pipelines.read", "pipelines.send", "pipelines.write", "precursor.read", "precursor.write", "pubsub.read", "pubsub.write", "query-cache.read", "query-cache.write", "queues.metadata_read", "queues.read", "queues.write", "r2-catalog-sql.read", "r2-catalog.read", "r2-catalog.write", "radar.read", "rag.read", "rag.run", "rag.write", "realtime.admin", "realtime.read", "realtime.write", "registrar-sandbox-domains.admin", "registrar-sandbox-domains.read", "reports-application-security-report.read", "request-tracer.read", "resource-library.read", "resource-library.write", "resource-sharing.read", "response-compression.read", "response-compression.write", "sanitize.read", "sanitize.write", "secrets-store.read", "secrets-store.write", "select-configuration.read", "select-configuration.write", "stream.metadata_read", "stream.read", "stream.write", "tag.read", "tag.write", "teams-cds-compute-account.read", "teams-cds-compute-account.write", "teams-connector-cloudflared.monitoring", "teams-connector-cloudflared.read", "teams-connector-cloudflared.write", "teams-connector-warp.read", "teams-connector-warp.write", "teams-connectors.read", "teams-connectors.write", "teams-dex.read", "teams-dex.write", "teams-networks.read", "teams-networks.write", "teams-pii.read", "teams-resilience.read", "teams-resilience.write", "teams-secure.location", "teams.read", "teams.report", "teams.write", "transform-rules.read", "transform-rules.write", "trust-and-safety.read", "trust-and-safety.write", "url-scanner.read", "url-scanner.write", "user-details.read", "user-details.write", "vectorize.read", "vectorize.write", "waiting-rooms.read", "waiting-rooms.write", "web3-hostnames.read", "web3-hostnames.write", "websearch.metadata_read", "websearch.read", "websearch.write", "workers-ci.read", "workers-ci.write", "workers-kv-storage.metadata_read", "workers-kv-storage.read", "workers-kv-storage.write", "workers-observability-telemetry.write", "workers-observability.read", "workers-observability.write", "workers-r2-bucket-item.read", "workers-r2-bucket-item.write", "workers-r2.metadata_read", "workers-r2.read", "workers-r2.write", "workers-routes.read", "workers-routes.write", "workers-scripts.bind", "workers-scripts.read", "workers-scripts.write", "workers-tail.read", "workers_ai.metadata_read", "zaraz.edit", "zaraz.read", "zaraz.write", "zone-access.read", "zone-access.revoke", "zone-access.write", "zone-custom-asset.read", "zone-custom-asset.write", "zone-disable-esc.read", "zone-disable-esc.write", "zone-dns-settings.read", "zone-dns-settings.write", "zone-security-center-insights.read", "zone-security-center-insights.write", "zone-settings.read", "zone-settings.write", "zone-transform-rules.read", "zone-transform-rules.write", "zone-versioning.read", "zone-versioning.write", "zone-waf.read", "zone-waf.write", "zone.read", "zone.write"]; /** * The possible explicitly requestable keys for a cf Scope. * * "offline_access" is automatically included. */ type Scope = (typeof CF_REGISTERED_SCOPES)[number]; declare let DefaultScopeKeys: Scope[]; declare function setLoginScopeKeys(scopes: Scope[]): void; declare function validateScopeKeys(scopes: string[]): scopes is Scope[]; /** * `CLOUDFLARE_CLIENT_ID` is the UUID of cf's registered OAuth app, used to * identify the `cf` CLI to the Cloudflare OAuth server. * * Normally you should not need to set this explicitly. cf has a single * registered OAuth app (there is no separate staging app), so the default is * the same regardless of `WRANGLER_API_ENVIRONMENT`; override via the env var * if a different app is ever needed. */ declare const getClientIdFromEnv: () => string; /** * OS-keyring service identifier for the `cf` CLI. Distinct from wrangler's so * the two CLIs' credentials never collide in the OS keychain. Becomes the `-s` * arg to macOS `security`, the `service` attribute for Linux `secret-tool`, and * the `service` arg to `@napi-rs/keyring` on Windows. */ declare const CF_KEYRING_SERVICE_NAME = "cloudflare"; /** * The `redirect_uri` registered on cf's OAuth app; also the local callback URL. * cf uses the fixed local callback port 8877 (from its historical 8877–8886 * range). */ declare const CF_OAUTH_CALLBACK_URL = "http://localhost:8877/oauth/callback"; /** * The `cf` CLI's global config directory: `~/.config/cloudflare` (XDG) — no * leading dot (unlike wrangler's `.wrangler`) and no legacy `~/.cloudflare` * fallback, since `cf` is new and has no historical home-dir layout to be * compatible with. Resolved lazily so `runInTempDir()` fixtures (which re-stub * `HOME` / `XDG_CONFIG_HOME`) are honoured per call. */ declare function getCfConfigPath(): string; /** * The cf {@link CliDescriptor}: JSON files under `~/.config/cloudflare`, cf's * OAuth app / consent pages, the `"cloudflare"` keyring service, and cf-worded * copy. */ declare const CF_CLI: CliDescriptor; declare const readUserPreferences: () => UserPreferences; declare const updateUserPreferences: (update: Partial) => void; /** * Build cf's auth layer, injecting the few consumer primitives that can't move * into the shared package (logger, interactive `prompt` / `select`, and the * User-Agent string). */ declare function createCfAuth(ctx: AuthContext): CloudflareAuth; /** Consumer primitives {@link createCfProfileStore} needs. */ interface CfProfileStoreContext { logger: OAuthFlowContext["logger"]; } /** Build cf's {@link ProfileStore} (JSON `.json` / `.enc` files under `~/.config/cloudflare`). */ declare function createCfProfileStore(ctx: CfProfileStoreContext): ProfileStore; /** Apply and persist cf's global keyring-storage preference. */ declare function setKeyringPreference(enabled: boolean, ctx: KeyringPreferenceContext): SetKeyringPreferenceResult; export { AuthContext, CF_CLI, CF_KEYRING_SERVICE_NAME, CF_OAUTH_CALLBACK_URL, type CfProfileStoreContext, CliDescriptor, CloudflareAuth, DefaultScopeKeys, KeyringPreferenceContext, type Scope, SetKeyringPreferenceResult, UserPreferences, createCfAuth, createCfProfileStore, createJsonFileStorage, defaultAuthConfigStorage, getAuthConfigFilePath, getCfConfigPath, getClientIdFromEnv, getEncryptedAuthConfigFilePath, readAuthConfigFile, readUserPreferences, setKeyringPreference, setLoginScopeKeys, updateUserPreferences, validateScopeKeys, writeAuthConfigFile };