/** * Path security utilities — I-ARCH-03 (extracted from helpers.ts) * * Path traversal protection, symlink resolution, allowed roots validation. */ /** A-15: Iterative URL decode — defeats multi-layer encoding. */ export declare function iterativeDecode(raw: string, maxIterations?: number): string; /** Resolve a path to absolute. Does NOT validate security — use resolveWithinRoot for that. */ export declare function resolvePath(p: string): string; /** Validate and resolve a project root path. */ export declare const validatePath: typeof resolvePath; /** Validate that a path is a valid Godot project root (contains project.godot). */ export declare function validateProjectRoot(p: string): string; /** * Resolve project path with priority chain: * 1. explicitPath (tool call argument) → use directly, no validation * 2. GODOT_PROJECT_PATH env → validate project.godot exists * 3. cwd upward search → find project.godot (max 30 levels) * 4. None → return undefined (caller decides error handling) * * Results are cached for 30s (PROJECT_PATH_CACHE_TTL_MS). */ export declare function resolveProjectPath(explicitPath?: string): string | undefined; /** Reset cache state (test-only). */ export declare function _resetProjectPathCache(): void; /** Safely resolve real path — walks up to find existing ancestor for symlink resolution. */ export declare function safeRealPath(p: string, base?: string): string; /** * Resolve userPath within root, blocking traversal attacks. * * Security layers: UNC path reject → Windows device name reject → * iterative URL decode → `..` segment reject → realpath + relative check. * * NOTE: TOCTOU window exists between symlink check and actual use — * accepted risk for local-only scenarios. */ export declare function resolveWithinRoot(root: string, userPath: string): string; export declare function normalizeUserProjectPath(input: string): string; export declare function getAllowedProjectPaths(): string[]; /** * Check whether a requested path is within allowed project roots. * * Priority (highest wins): * 1. GODOT_MCP_UNRESTRICTED=true → allow everything (dev mode) * 2. ALLOWED_PROJECT_PATHS=/path1;/path2 → allow only listed roots + children * 3. No config → restrict to process.cwd() (deny-by-default) * * C-07: Changed from allow-by-default to deny-by-default. * Users must explicitly opt in via ALLOWED_PROJECT_PATHS or GODOT_MCP_UNRESTRICTED. */ export declare function isPathInAllowedRoots(requestedPath: string): boolean; /** 审查 I-E(2026-09-03): 错误消息里的「允许根列表」必须与 isPathInAllowedRoots 判定同源生成。 * 上轮 NIT-2 的复刻式对齐(调用方本地重写分支逻辑)仍有残余漂移:判定侧对每条 allowlist 条目做 * safeRealPath 归一化、realpath 失败的条目跳过不放行,复刻的提示侧无差别列出——用户按提示把 * 文件放进该条目仍被拒。本函数与判定走相同归一化链:realpath 失败条目同样不列;空 allowlist 时 * 列 cwd fallback(同样归一化)。全部条目 realpath 失败时回列原始配置(此时问题在配置本身)。 */ export declare function describeAllowedRoots(): string; /** Reset log state (test-only). */ export declare function _resetPathAllowWarned(): void;