export interface FileDownloadOptions { url: string; /** Path relative to rootDir; absolute or traversal paths are rejected. */ targetRel: string; rootDir: string; headers?: Record | undefined; overwrite?: boolean | undefined; /** Request timeout in milliseconds (defaults to 60s). */ timeoutMs?: number | undefined; /** Maximum response body size in bytes (defaults to 50 MiB). */ maxBytes?: number | undefined; /** * Whitelist of allowed origins (e.g., `["https://yt.example.com"]`). When * provided, the request is rejected unless `url`'s origin matches one of * the entries. Defends against SSRF when `url` originates from a * server-supplied response. */ allowedOrigins?: string[] | undefined; } /** * Downloads a file from the given URL into rootDir/targetRel. The path is * resolved through resolveOutputPath; absolute paths and `..` segments are * rejected. On error any partial file is removed. */ export declare function downloadFileFromUrl(options: FileDownloadOptions): Promise; /** * Extracts a filename from the URL or Content-Disposition header. The result is * a raw string and MUST be passed through sanitizeFilename before use as a path. */ export declare function extractFilenameFromUrlOrHeader(url: string, contentDisposition?: string): string; //# sourceMappingURL=file-download.d.ts.map