/** * Register a secret keyed to the PRINCIPAL that owns it (an agent name). The * value becomes that principal's `current`; the prior current shifts into a * bounded previous-window so a rotation grace period stays covered. A live * principal's current value is never aged out by volume elsewhere. */ export declare function registerIdentitySecret(principal: string, value: unknown): void; /** * Register one or more secrets that have just been PERSISTED for a principal. * This is the sanctioned db.ts entry point and MUST be called only on a * mutation's SUCCESS path, AFTER the CAS/transaction commits — never before. * * WHY after-commit: registering before persistence lets a failed or retried * mutation plant a throwaway value as the principal's `current`; four such * failures for one name evict its live token from the window (the PR C v1 bug — * registering an unpersisted secret is wrong on its face, independent of whether * the eviction ever fires). Variadic because first-registration persists two * secrets at once (durable token + recovery handle); null/ineligible values are * skipped by registerIdentitySecret. * * ENFORCED, two independent paths (#61) — a db.ts function that mints a token * (generateToken) but never calls this reddens the build BEFORE merge, so a NEW * mutator cannot silently skip redaction: * 1. tests/v2-24-7-secret-register-guard.test.ts runs * scripts/secret-register-guard.mjs against the REAL src/db.ts on every PR in * the CI job "Test (Node 20/22)" (`npx vitest run`), and also proves the guard * FAILS on a synthetic unregistered minter (test the guard, not just the code). * 2. scripts/pre-publish-check.sh runs the same guard as a pre-publish step. * NOTE: `npm run build` does NOT run it — the enforcement is the test + the * pre-publish gate, not tsc. See that guard for its exact boundary. */ export declare function registerPersistedSecret(principal: string, ...values: unknown[]): void; /** Register an identity-less but FIXED secret (config http_secret / dashboard_secret). */ export declare function registerConfigSecret(value: unknown): void; /** * Register a genuinely identity-less value into the small orphan FIFO. Eviction * is LOGGED — coverage must not degrade silently. (Currently unused by the * codebase; every real secret has a principal or is a config secret. Kept as the * explicit home for any future identity-less case so it can't quietly reuse an * unbounded structure.) */ export declare function registerOrphanSecret(value: unknown): void; /** * Replace every registered secret VALUE in `line` with `***`, field- and * position-agnostic. Early-returns when nothing is registered (the common case * for stdio clients) so it costs nothing there. */ export declare function redactRegisteredValues(line: string): string; /** Test-only: clear all tiers between cases. */ export declare function _resetSecretRegistryForTests(): void; /** Test-only: number of distinct principals currently keyed. */ export declare function _identityCountForTests(): number; //# sourceMappingURL=secret-registry.d.ts.map