/** * @fileoverview URL sanitization for error messages. Strips operator-injected query params * (the `api_key` account credential and the `mailto` polite-pool identifier, plus any future * internal additions) so they never reach MCP clients via thrown error text. `api_key` is a * real secret under OpenAlex usage-based pricing — the allowlist below is what keeps it out * of surfaced errors. * @module services/openalex/url-redaction */ /** Drop every query param except the caller-controlled allowlist. */ export declare function redactUrl(url: string): string; /** * Scan a string for embedded URLs and redact each one. Used at the error-formatting site * because the framework's fetch helper formats messages as `Fetch failed for . Status: …` * — the URL chunk has to be sanitized in place. */ export declare function redactUrlsInMessage(message: string): string; //# sourceMappingURL=url-redaction.d.ts.map