export declare const TOKEN_TTL_MS = 120000; export declare function requiresConfirmation(toolName: string, args?: Record): boolean; export declare function createPendingToken(toolName: string, args: Record): string; /** * Consume a pending confirmation token. * * SECURITY NOTE: 校验 token 值但不验证 caller 身份。单客户端 MCP 下 caller/session 绑定 * 不堵 AI 自确认(AI 同 session 产生+消费 token,caller 校验必过)。AI 自确认改由 * ToolDispatcher.confirm_and_execute 的 out-of-band elicitation gate 堵(2026-07-13): * consumeToken 成功后 elicitInput 经 server→client→user UI 问用户,AI 经 tools/call * 通道无法伪造 elicitation 响应。未来若加多客户端,此处仍需 clientId 防跨连接重放(与 elicitation 正交)。 */ export declare function consumeToken(token: string): { toolName: string; args: Record; wasTruncated?: boolean; } | null; /** * Peek a pending confirmation token without consuming it. * * P0-2 MRTR: confirm_and_execute 第一轮 peek(验证有效但不消费),返回 InputRequiredResult; * 第二轮收到 inputResponses 后才 consumeToken。两步分离避免第一轮误消费致第二轮 requestState 校验失败。 */ export declare function peekToken(token: string): { toolName: string; args: Record; wasTruncated?: boolean; } | null; export declare function pendingCount(): number; /** * Reset all mutable state: clear pending tokens and stop the cleanup interval. * Useful for test teardown or hot-reload scenarios. * The cleanup interval will be recreated on the next `createPendingToken()` call. */ export declare function resetState(): void; /** * Graceful shutdown: stop the cleanup interval and clear all pending tokens. * After calling this, the module is still usable — the interval restarts on * the next `createPendingToken()` call. */ export declare function cleanup(): void; /** @internal Exposed for testing — check whether the cleanup timer is active. */ export declare function isCleanupTimerRunning(): boolean; /** Whether a tool has ANY guarded action (任意 action 的 risk 非 read). Used by capability matrix. */ export declare function isGuardedTool(toolName: string): boolean;