/** * Shared SIEM-vendor resolution. * * Every vendor-taking tool (poc_from_siem_submit, dependency_check, * pattern_mitigate, advise_*) otherwise rolls its own "is the user explicit * or should this sniff env vars?" logic. This module centralizes that, so * the same priority + ambiguity rules apply everywhere: * * 1. Explicit id wins, no probing. * 2. Otherwise discover all configured connectors in parallel. * 3. Single available → use it. * 4. Multiple → prefer the one whose creds came from explicit env * vars over ambient (AWS instance role / SSO chain). If a single * env-source winner exists → use it. Otherwise → ambiguous. * 5. None → caller decides whether to fall back to bash, error out, * or use a default. * * Tools that only support a subset of SIEMs (dep-check covers 4 of 8; * pattern_mitigate SIEM subset covers the same 4) pass `restrictTo` to * scope discovery. Both ambiguity and none-found resolve against the * narrower set. */ import { type CredentialSource } from './index.js'; import type { SiemId } from './pricing.js'; export type SelectionMethod = 'explicit' | 'sole' | 'preferred-explicit-env'; export interface AmbiguousCandidate { id: SiemId; displayName: string; source: CredentialSource; } export type ResolveResult = { kind: 'resolved'; id: SiemId; displayName: string; selectionMethod: SelectionMethod; /** Human note suitable for the report header; undefined when explicit. */ note?: string; } | { kind: 'ambiguous'; candidates: AmbiguousCandidate[]; } | { kind: 'none'; probedIds: SiemId[]; }; export interface ResolveOptions { /** When provided, bypass discovery and accept the user-supplied id verbatim. */ explicit?: string; /** * When provided, only consider these SIEMs during auto-detect. The * full registry is filtered to this set before discovery runs, so * ambiguity is computed on the narrower scope too. */ restrictTo?: SiemId[]; } export declare function resolveSiemSelection(opts: ResolveOptions): Promise; /** * Render an ambiguous-resolution result as the markdown error body the * MCP tool wrap fn surfaces back to the caller. Naming the arg is the * caller's job — `vendor` for dep-check / exclusion_filter, `siem` for * poc_from_siem, `destination` for advise_*. */ export declare function formatAmbiguousError(candidates: AmbiguousCandidate[], argName: string): string; /** * Render a no-creds result. Caller supplies a hint so the message can * point users at the right env-var docs (e.g., "see log10x_doctor for * per-SIEM discovery detail"). */ export declare function formatNoneError(probedIds: SiemId[], hint: string): string;