/** * Refuse to ship a transcript over a connection anyone can read. * * ── The hole this closes ───────────────────────────────────────────────── * TLS to the hosted service was never in doubt — valid cert, HSTS for a year, * plain HTTP redirected. But NOTHING in the collector required it. A user who * typed `chat-recall login http://recall.mycompany.com` got exactly what they * asked for: every transcript on the machine, in cleartext, over the open * internet, with no warning at any point. `isLocalHost()` existed to relax * upload pacing for LAN targets, not to gate the scheme, so a public host over * plain HTTP passed every check. * * The payload makes this worse than a generic cleartext warning deserves. A sync * body carries whole transcripts: source code, file paths, and — despite * client-side redaction being good — whatever the detectors did not recognise as * a secret. This is the single highest-value thing the product ever puts on a * wire. * * ── Where the line is ──────────────────────────────────────────────────── * Plain HTTP is fine to a host only YOU can reach, and that is the whole * exception. Loopback, mDNS/`.lan` names, RFC1918, IPv6 loopback and ULA, and * the CGNAT range Tailscale hands out — a self-hoster on any of those has no * public path to intercept. Everything else needs TLS. * * `CHAT_RECALL_ALLOW_INSECURE_HTTP=1` overrides it, for the real case this * would otherwise break: a corporate host reached through a VPN whose name and * address both look public. That is a deliberate, per-machine decision, which is * exactly the bar an override like this should meet. */ /** Hosts only reachable from the user's own machine or network. */ export declare function isPrivateHost(serverUrl: string): boolean; /** Explicit, per-machine opt-out for a VPN-reached host that looks public. */ export declare function insecureHttpAllowed(env?: NodeJS.ProcessEnv): boolean; /** * Why this target must not be used, or null when it is safe. * * Pure, so both the login gate and the sync-time gate can share one rule and a * test can pin it without a network. */ export declare function transportRisk(serverUrl: string, env?: NodeJS.ProcessEnv): string | null; /** Throwing form, for the login path. */ export declare function assertTransportSafe(serverUrl: string, env?: NodeJS.ProcessEnv): void; //# sourceMappingURL=transport-safety.d.ts.map