import type { IncomingMessage } from 'node:http'; /** * The first node-operator token in the set, i.e. one that no local agent owns. * Agent tokens share the set and can precede it once the token file is * reloaded, so the order of the set alone does not identify the operator. * Empty entries are skipped: a legacy agent recovered without a token adds one, * and no agent claims it. */ export declare function nodeOperatorToken(validTokens: Iterable, resolveAgentByToken: (token: string) => string | undefined): string | undefined; /** * The token to embed in the dashboard shell for this request, if any. The * shell itself is public so every caller can load it and authenticate, but the * node-operator token is injected only for a trusted local request: a loopback * client socket AND a `Host` that names the loopback interface AND no proxy * forwarding headers. A non-loopback client, a loopback client presenting any * other `Host`, or a request forwarded by a proxy is untrusted and is served * the same shell without a token. */ export declare function nodeUiTokenForRequest(req: Pick, opts: { authEnabled: boolean; validTokens: Iterable; resolveAgentByToken: (token: string) => string | undefined; }): string | undefined; //# sourceMappingURL=node-ui-access.d.ts.map