/** * The company-slug safety rule, and nothing else. * * WHY THIS IS ITS OWN FILE * ------------------------ * Two callers need the identical rule: * * - `manifest-reconcile.ts`, which turns a slug into a manifest key and an * on-disk company directory; * - `manifest/build-manifest.ts`, which turns a scope slug into the walk * root (`companies/{slug}`). * * A second copy would be free to drift, and the failure mode of drift here is * a tenant boundary violation — a slug like `../personal` walking the wrong * tree and uploading it under someone else's `companyUid`. So there is one * definition. * * It lives in a LEAF module rather than in `manifest-reconcile.ts` because the * manifest builder is client hot-path code (and is imported by the CLI), while * `manifest-reconcile.ts` pulls in `vault-client` → `cognito-auth`, telemetry * and the AWS SDK. Importing the rule from there would drag that entire graph * into the builder for the sake of one pure path check. This file imports * `node:path` and nothing else; keep it that way. */ /** * Pure path check — a slug must name a direct child of `companies/` and nothing * else. This deliberately does NOT require the directory to exist; the on-disk * stat check is an eligibility concern and lives with each caller. */ export declare function isSafeCompanySlug(companiesDir: string, slug: string): boolean; //# sourceMappingURL=company-slug.d.ts.map