//#region src/utils/origin.d.ts /** * Origin and hostname predicates shared by the RPC transports (the WS upgrade, * SSE, and MCP origin gates) and the instance shell's authentication-link * origin validation. Kept dependency-free and runtime-agnostic so any consumer * can pull in a single check without dragging in a transport's `crossws` * import. */ /** * Whether `hostname` names a loopback host: `localhost` (or any `*.localhost` * subdomain), the IPv6 loopback `::1`, or an IPv4 literal inside the * `127.0.0.0/8` loopback block. * * The IPv4 case is matched **structurally**: the whole hostname must be a * canonical dotted-decimal IPv4 literal whose first octet is `127`. A bare * `startsWith('127.')` prefix check would also accept an attacker-controlled * DNS name that merely *begins* with `127.` (`127.attacker.example`, * `127.0.0.1.attacker.example`), letting a cross-origin browser page defeat * the loopback origin gate that guards the RPC/MCP surface (a DNS-rebinding / * cross-site WebSocket-hijacking bypass). Requiring a real IPv4 literal keeps * genuine loopback addresses (`127.0.0.1`, `127.5.5.5`) allowed while rejecting * those DNS names. */ declare function isLoopbackHostname(hostname: string): boolean; /** * Whether `address` is a loopback peer address as reported by a socket * (`net.Socket.remoteAddress`): the IPv6 loopback `::1`, an IPv4 literal in * `127.0.0.0/8`, or an IPv4-mapped IPv6 form of one (`::ffff:127.0.0.1`). * * Unlike {@link isLoopbackHostname} this takes a raw address, not a hostname: * it never accepts a `localhost`-style name (a socket peer is always a literal * address) and understands the IPv4-mapped IPv6 form the OS hands back on a * dual-stack listener. Used to prove a same-machine caller from the connected * peer, which a client cannot forge, rather than from the `Origin` header, * which it can. */ declare function isLoopbackAddress(address: string): boolean; /** * Default origin policy for a localhost dev tool: allow requests with no * `Origin` header (native, non-browser clients), allow any loopback origin * (so cross-port localhost dev setups keep working), and allow explicitly * configured origins. Everything else, such as a real remote page in the dev's * browser, is rejected. */ declare function isAllowedOrigin(origin: string | undefined, allowedOrigins: readonly string[]): boolean; /** * Decide whether a request-derived origin candidate may back a devframe's * advertised public origin, the destination of the OTP magic link. Stricter * than {@link isAllowedOrigin}: it rejects credentials, a path, a query, a * fragment, a malformed port, and non-HTTP(S) schemes, and adopts a candidate * only when its hostname is loopback or its canonical origin exactly matches * an `allowedOrigins` entry (a caller with no static list passes none, so only * loopback qualifies). Returns the canonical origin to adopt, or `undefined` * to reject. Forwarded headers are never consulted. */ declare function validateOriginCandidate(candidate: string, allowedOrigins?: readonly string[]): string | undefined; //#endregion export { validateOriginCandidate as i, isLoopbackAddress as n, isLoopbackHostname as r, isAllowedOrigin as t };