import type { InstanceScope } from "./instances.js"; /** * Claude Code permission rules that keep a human in front of destructive calls. * * This is the second half of the guard whose first half is * `anthropic/requiresUserInteraction` in the tool registry. That annotation * travels with the package and needs no configuration, but it is understood * only by Claude Code 2.1.199 and later; these rules cover the versions that * ignore it, and they make the guard visible in a file an operator can audit. * * Both survive `bypassPermissions`, and an `ask` rule beats a matching `allow` * rule -- rules are evaluated deny, then ask, then allow, first match wins -- * so answering "yes, don't ask again" cannot quietly retire one. */ export type SettingsDocument = Record; /** * The tools that may not run without a person answering for them. * * Derived from `confirmRequired` rather than from a list kept here, so the * rules cannot drift from the catalog as tools are added. Aliases are included * because each one is a separate tool name on the wire: a rule naming only * `pve_stop_qemu_vm` leaves `stopVM` wide open. * * `destructive` would be the wider net, but it also covers start and resume, * which change state without destroying anything. Prompting to power on a VM * is friction that buys nothing, and a guard people resent is a guard people * find ways around. */ export declare const humanGateToolNames: () => string[]; /** Rule strings for one configured instance, e.g. `mcp__lab-cluster__pve_qemu_delete`. */ export declare const humanGateRules: (serverKey: string) => string[]; /** * Where the rules go. * * Mirrors how instances already choose between the project and the home * directory, so a user-scope install -- reachable from every directory -- * carries its guard everywhere too, instead of being protected in the one * repository where setup happened to run. */ export declare const claudeSettingsPath: (scope: InstanceScope, cwd: string) => string; /** * Adds the rules to `permissions.ask`, leaving everything else untouched. * * `settings.json` routinely holds hooks, env vars and the operator's own * permission rules, so this merges instead of writing a fresh document, and * refuses outright when a value is not the shape it expects rather than * replacing something it does not understand. */ export declare const mergeAskRules: (doc: SettingsDocument | undefined, rules: string[]) => SettingsDocument; export type HumanGateWriteResult = { path: string; /** Rules that were not already there. Zero means the file was already covered. */ added: number; total: number; }; /** * Reads, merges and writes the settings file for one instance. * * Never clobbers a file it cannot parse: it almost certainly holds * configuration the operator wrote by hand, and losing that to a guard meant to * protect them would be its own kind of damage. */ export declare const writeHumanGateRules: (serverKey: string, scope: InstanceScope, cwd: string) => Promise; //# sourceMappingURL=permissions.d.ts.map