/** * SSRF guard — classifies an address (or hostname literal) as * private/loopback/link-local/cloud-metadata/CGNAT. Single source of truth * for address classification: `web.fetch` (classifier branch + per-hop * resolution check), `src/safety/classifier.ts`, and the legacy * `http.fetch` check (via {@link isBlockedAddress}) all delegate here. */ export type AddressClass = "loopback" | "rfc1918" | "ipv4-link-local" | "ipv6-link-local" | "cloud-metadata" | "cgnat"; export interface AddressClassification { class: AddressClass; } export declare function isAllowedScheme(url: string): boolean; export declare function classify(ip: string): AddressClassification | null; export declare function classifyHost(hostname: string): AddressClassification | null; /** * Legacy boolean shape preserved for the existing `http.fetch` SSRF check. * * Returns `true` whenever {@link classifyHost} would return a non-null * classification, plus a small additional set of historically-blocked * ranges (currently `0.0.0.0/8`, the "this network" range) that are kept * for backward compatibility with the previous `http.ts` implementation * but are not enumerated in the public {@link AddressClass} list. */ export declare function isBlockedAddress(host: string): boolean;