/** * These helpers keep credential material and other sensitive files off other * users on a shared machine. On POSIX we set 0600 (files) / 0700 (dirs); on * Windows chmod is a no-op (the user profile ACL already restricts access), so * every call is best-effort and never throws on the chmod. * * Writes are ATOMIC (write a temp file in the same directory, then rename over * the target). A credential file half-written by a crash or a killed process is * a login destroyed, so partial writes must never be observable. */ /** chmod a path to owner-only, ignoring failure (Windows/unsupported FS). */ export declare function restrictPermissions(target: string, mode: number): void; /** Create a directory owner-only (0700). */ export declare function secureMkdir(dir: string): void; /** Write a file owner-only (0600), atomically. */ export declare function writeSecretFile(file: string, data: string): void; /** Copy a file owner-only (0600), atomically (never a half-copied credential). */ export declare function copySecretFile(src: string, dest: string): void; /** Replace credential-shaped tokens with a redaction marker before logging output. */ export declare function redactSecrets(text: string): string;