/** * Network-safe HTTP GET: SSRF protection, pinned DNS, redirect policy, and a byte ceiling. * * Extracted from the web connector when image inputs needed the same protection for binary * payloads. Security code that exists twice drifts, and the copy that drifts is the one nobody * audited; both callers now share this module, and the web connector keeps its exact behavior. */ /** * A URL refused by policy rather than by the network. * * Kept distinct so a caller can tell "that address is not allowed" from "that server is down" * without matching on message text. Extends `Error`, so existing handlers are unaffected. */ export declare class UrlPolicyError extends Error { constructor(message: string); } export type WebResolvedAddress = string | { address: string; family?: 4 | 6; }; export interface SafeFetchPolicy { allowedDomains?: string[]; /** Explicitly allow loopback/private targets, for example a trusted local development service. */ allowPrivateNetworks?: boolean; /** Cloud metadata endpoints remain denied unless this separate high-risk opt-in is enabled. */ allowCloudMetadata?: boolean; /** Optional resolver for split-horizon DNS or deterministic tests. Every returned address is validated. */ resolveHostname?: (hostname: string) => Promise; userAgent?: string; } export interface SafeFetchOptions extends SafeFetchPolicy { maxBytes: number; maxRedirects: number; signal: AbortSignal; accept?: string; } export interface SafeFetchResult { url: string; status: number; ok: boolean; bytes: Buffer; /** True when the body was cut at `maxBytes`. */ truncated: boolean; contentType?: string; } /** * Fetches a URL after validating every hop, following redirects up to the configured limit. * * Each redirect target is resolved and validated again, so a public URL cannot redirect into a * private address, and the socket is pinned to an address that passed validation so DNS cannot * be rebound between the check and the connect. */ export declare function safeFetch(initialUrl: URL, options: SafeFetchOptions): Promise; export declare function parseUrl(value: string, base?: URL): URL; export declare function positiveInteger(value: number | undefined, fallback: number, name: string): number; export declare function nonNegativeInteger(value: number | undefined, fallback: number, name: string): number;