/** * Alibaba DashScope TTS provider (qwen-tts model). * * Implements the SpeechProviderPlugin contract directly because DashScope's * response shape (output.audio.url for the audio binary, no direct stream) * doesn't fit the OpenAI-compatible factory. * * Implementation notes (per docs/voice-rearchitecture.md ยง8.4.1): * - `maxTextLength = 512` (DashScope qwen-tts hard limit). Enforced upstream * via `truncateAtSentenceBoundary` before this provider sees the text. * - The audio URL returned by DashScope is hosted on Alibaba's CDN (variable * hostname). We do not SSRF-guard the audio fetch because: * (a) the URL is provided by the same provider we already trust for the * initial synthesis call, * (b) it's HTTPS-only and short-lived (~5 min TTL), * (c) maintaining a hostname allowlist breaks every time Alibaba rotates * CDN domains. * A dedicated `assertSafeUrl` for trusted-CDN responses can be added later * as a hardening pass. */ import type { SpeechProviderPlugin } from '../speech-provider-types.js'; export declare const ALIBABA_REALTIME_TTS_MODEL = "qwen3-tts-flash-realtime"; export declare const alibabaSpeechProvider: SpeechProviderPlugin;