import { z, type ZodObject, type ZodRawShape } from 'zod'; import { type FieldNormalizer } from '../utils/normalize.ts'; export { z }; export declare const REDACTED_SECRET: ""; export type ConfigOf = { [K in keyof z.infer]: Exclude[K], undefined>; }; export type RedactedConfig = Omit & { [P in keyof Pick]: null extends T[P] ? typeof REDACTED_SECRET | null : typeof REDACTED_SECRET; }; export declare function secretStr(): z.ZodString; export declare function secretSchema(schema: T): T; /** * The one door a mount config comes through: rename the python-side * spellings, then validate. * * Every `normalize*Config` is this call with its schema, so a config that * reaches a resource has been checked the way pydantic checks the python * twin on construction. It used to be `normalizeFields` alone in 56 of 60 * normalizers, which let `bucket: 123`, `timeout: "abc"` and a Google * config naming no credential at all reach their clients unrefused, and * left every requiredness rule in these schemas unreachable from the mount * path -- `GitHubConfigSchema` required `owner` and nothing ever asked it. * * Unknown keys are stripped, not refused, because pydantic's default * `extra="ignore"` does the same on the python side; the CLI registry adds * its own fail-loud check on top for both languages. A callable a config * carries (a token provider, a refresh hook) must be declared in the schema * through `secretSchema(z.custom(...))` or parse strips it -- that is also * what keeps it out of snapshot state. */ export declare function parseConfigWithSchema(schema: ZodObject, input: Record, normalizer?: FieldNormalizer): ConfigOf>; export declare function redactConfigWithSchema(schema: ZodObject, config: unknown): Record; export declare function hasRedactedSecret(value: unknown): boolean; /** * Whether restoring this mount needs a live resource handed in. * * A redaction marker says the saved config is missing a credential. The * explicit `needs_override` says the mount cannot be rebuilt from its * state at all — which in TypeScript is true of every config-backed * backend, because `buildMountArgs` substitutes a `RAMResource` for any * mount it was not given (`snapshot/state.ts`). Python instead * reconstructs the class from `resource_state["type"]` via its registry * (`_resource_class_for`), so the field is inert there and only four of * its resources bother to write it; TypeScript has to read it or a live * database mount comes back as an empty directory. * * The lasting fix is to give `buildMountArgs` a resource factory, which * core cannot import today (`buildResource` lives in node/browser). */ export declare function resourceStateRequiresOverride(state: unknown): boolean; //# sourceMappingURL=secrets.d.ts.map