/** * Pure helpers for scoping the `auden mcp` server: resolving the `since` * window an agent asks for into an ISO timestamp the REST inbox endpoint * understands, and enforcing the local bundle allowlist. Kept free of I/O so * they unit-test directly. */ /** * Resolve a caller-supplied `since` value into an ISO-8601 timestamp for the * `GET /api/v1/context/inbox?since=` query. Accepts either an absolute ISO * timestamp (passed through, normalized) or a relative window like `"24h"` / * `"7d"` / `"30m"`, resolved against `now`. Returns `undefined` for an empty * value (meaning "no lower bound") and throws on anything unparseable so a * typo surfaces instead of silently widening the window. * * `now` is a parameter (not `new Date()`) so the resolution is deterministic * and testable. */ export declare function resolveSince(value: string, now: Date): string | undefined; /** * Parse a `--bundles a,b,c` flag into an allowlist of slugs. Returns `null` * (meaning "no restriction") when the flag is empty, so the caller can treat * "unset" and "empty" identically. */ export declare function parseBundleAllowlist(raw: string): string[] | null; /** * True when `slug` may be reached given `allowlist`. A `null` allowlist means * unrestricted; otherwise the slug must be listed explicitly. */ export declare function isBundleAllowed(slug: string, allowlist: string[] | null): boolean; /** * The capability token granting access to the user's personal inbox — * `list_inbox`, `pull_inbox`, `archive_inbox`. * * **Deliberately not a bundle slug, and structurally incapable of being one.** * `BundleSlugSchema` is lowercase alphanumerics and hyphens starting * alphanumeric (`packages/protocol/src/bundleSlug.ts`), so a leading `@` can * never name a bundle. That matters because the inbox gate used to be spelled * `isBundleAllowed('inbox', …)`: the string `inbox` was simultaneously a bundle * slug and the name of a capability over every note on the account. The reserved * slug used to keep those from colliding; `inbox-as-view` slice 4 removed the * reservation, so `inbox` is now an ordinary creatable slug. Without this token, * a user who names a project bundle `inbox` and allowlists it with * `--bundles inbox` would silently also grant read **and archive** over their * entire personal inbox. * * The token landed in slice 3a, one slice *before* the reservation was removed, * which is what closed that window; the reverse order would have opened a real * privilege leak (`inbox-as-view-plan.md` → Sequencing note). */ export declare const INBOX_SCOPE_TOKEN = "@inbox"; /** * True when the server may reach the caller's inbox. * * An unset allowlist stays unrestricted, exactly as before — the point is not to * revoke access from servers that never asked for a restriction, it is to stop * an *explicit* bundle allowlist from granting the inbox by accident. So a * restricted server must name `@inbox`; naming a bundle called `inbox` grants * that bundle and nothing more. */ export declare function isInboxAllowed(allowlist: string[] | null): boolean; //# sourceMappingURL=scope.d.ts.map