/** * v1.25.0 — recall-side scope predicates, extracted from api.ts into a leaf * module so shared.ts (which api.ts imports) can apply the same default-deny * rule to searchBothHybrid's internal candidate loads without an import * cycle. Mirrors the v39 `project-identity.ts` precedent. api.ts imports * these for its own call sites AND re-exports them for back-compat * (`api.isPrivateScope`, test imports of `passesScopeFilterForRecall`). */ /** * v1.2.1: source-agnostic private-scope detector. A scope string is treated * as private when it has the shape `:private:`. * * Examples that match: * slack:private:Cabc, github:private:owner/repo, jira:private:PROJ-1 * Examples that DO NOT match: * slack:public:Cgeneral, acme:public:my-private-channel, null, '', * 'unknown:legacy', 'private' (alone), 'private:foo' (no source prefix). * * Used by api.recall, mcp/server.ts (hippo_recall + hippo_context), * cli.ts (cmdRecall + cmdExplain + continuity), shared.ts (searchBothHybrid * recall mode). Keep these in sync — the export is the single source of * truth so connector work cannot drift. */ export declare const PRIVATE_SCOPE_RE: RegExp; /** True when `scope` matches the `:private:*` shape. */ export declare function isPrivateScope(scope: string | null | undefined): boolean; /** * Recall-side scope filter — the canonical JS half of the recall default-deny * rule (the SQL half lives in `loadSearchRows` via `loadRecallSearchEntries`). * * - When `requested` is set and non-empty: exact match required. * - When `requested` is undefined/empty: default-deny on any * `:private:*` scope and on the `RECALL_DEFAULT_DENY_SCOPES` * quarantine buckets. `null` and public scopes pass. * * @internal v1.7.2 — exported for test parity with * `RECALL_DEFAULT_DENY_SCOPES` (single-source-of-truth verification). NOT part * of the public API surface; not re-exported from `src/index.ts`. Subject to * change without semver bump. */ export declare function passesScopeFilterForRecall(scope: string | null, requested: string | undefined): boolean; /** * v1.25.0 — the CLI `--scope` variant of the recall filter (JS half of the * SQL 'default-deny-or-exact' mode in loadSearchRows). * * The CLI flag predates the envelope column as a TAG-boost ranking hint * (`scope:` tags, HIPPO_SCOPE, detectScope()), so an explicit `--scope X` * UNLOCKS envelope scope X in addition to the default-admitted set — it does * NOT narrow the result to X (that would return zero rows for every * tag-scoped workflow, whose envelope scope is NULL). api.recall keeps the * narrowing 'exact' semantics via `passesScopeFilterForRecall`. * * Note the unlock applies to whatever scope was explicitly named — including * a private scope or a quarantine bucket (`--scope unknown:legacy`). That is * deliberate owner access, identical in reach to api.recall's exact-match * for the same input; only NON-requested private/quarantine scopes stay * denied. */ export declare function passesCliRecallScopeFilter(scope: string | null, requested: string | undefined): boolean; //# sourceMappingURL=recall-scope.d.ts.map