/** * Namespace-scoped, identity-verified shared state for multi-agent coordination. * * Every write is identity-verified (agent token), namespace-checked, * size-validated, input-sanitized, and atomically persisted through * the pluggable {@link BlackboardBackend}. * * @module SharedBlackboard */ import type { BlackboardBackend } from './blackboard-backend'; import type { BlackboardEntry } from './orchestrator-types'; /** * Namespace-scoped, identity-verified shared state for multi-agent coordination. * * Every write is identity-verified (agent token), namespace-checked, * size-validated, input-sanitized, and atomically persisted through * {@link LockedBlackboard}. * * @example * ```typescript * const bb = new SharedBlackboard('./workspace'); * bb.registerAgent('analyst', 'secret-token', ['task:', 'analytics:']); * bb.write('task:revenue', { q4: 42_000 }, 'analyst', 3600, 'secret-token'); * const entry = bb.read('task:revenue'); * ``` */ export declare class SharedBlackboard { private backend; private agentTokens; private agentNamespaces; private piiRedactor; constructor(backendOrPath: string | BlackboardBackend, options?: { enablePIIRedaction?: boolean; }); /** * Enable or disable PII redaction on writes. */ setPIIRedaction(enabled: boolean): void; /** * Register a verified agent identity. Only agents with registered tokens * can write to the blackboard. The orchestrator registers agents after * verifying their identity through the AuthGuardian. */ registerAgent(agentId: string, verificationToken: string, allowedNamespaces?: string[]): void; /** * Check if an agent is allowed to access a key based on namespace rules. */ private canAccessKey; /** * Verify that the calling agent is who they claim to be. */ private verifyAgent; /** * Validate value size and structure before writing. * Prevents DoS via oversized writes and circular data. */ private validateValue; /** * Sanitize a key to prevent markdown injection. */ private sanitizeKey; /** * Read an entry from the blackboard by key. * * @param key - The entry key to look up * @returns The entry, or `null` if not found or expired * @throws {@link ValidationError} if `key` is not a non-empty string */ read(key: string): BlackboardEntry | null; /** * Write to the blackboard with identity verification, namespace checks, * value validation, and input sanitization. Uses LockedBlackboard for * atomic file-system writes. * * @param key - The key to write * @param value - The value (will be sanitized and size-checked) * @param sourceAgent - Agent claiming to write (verified against registered token) * @param ttl - Optional TTL in seconds * @param agentToken - Optional verification token for identity check */ write(key: string, value: unknown, sourceAgent: string, ttl?: number, agentToken?: string): BlackboardEntry; /** * Check whether a key exists on the blackboard (not expired). * @param key - The entry key to check */ exists(key: string): boolean; /** * Get a full snapshot of all blackboard entries. */ getSnapshot(): Record; /** * Get a namespace-scoped snapshot -- only returns keys an agent is allowed to see. * Prevents data leakage between agents. */ getScopedSnapshot(agentId: string): Record; /** * Clear all entries (for testing). */ clear(): void; } //# sourceMappingURL=shared-blackboard.d.ts.map