/** Minimal config fields required by every package. */ export interface BaseConfig { /** Path to the OpenAPI 3.1 spec file (JSON or YAML) */ input_openapi: string; /** Directory to write generated files */ output: string; } /** * String-prefix blocklist for common system directories. * * Threat model: interactive CLI misconfiguration (e.g. a typo in the output path). * This is NOT an exhaustive security control. It does not cover symlinks that point * into allowed dirs, relative traversal through an allowed directory, or Windows * short (8.3) names. Do not rely on it as a sandbox boundary. */ export declare const FORBIDDEN_OUTPUT_PREFIXES: string[]; /** * Same constraint as FORBIDDEN_OUTPUT_PREFIXES, applied to the input spec path. * See that constant's JSDoc for threat-model limitations. */ export declare const FORBIDDEN_INPUT_PREFIXES: string[]; /** Returns true when the path ends in a JS/ESM config extension. */ export declare function isJsConfigPath(configPath: string): boolean; export declare function validateConfigPath(configPath: string): void; export declare function validateOutputPath(resolvedOutput: string): void; export declare function validateInputPath(resolvedInput: string): void; /** Options for loadConfigFile. */ export interface LoadConfigOptions { /** Working directory used to resolve relative paths. */ cwd: string; /** Explicit config file path (optional). If omitted, defaultFileName is used. */ configPath?: string; /** Default config file name, resolved against cwd when configPath is not provided. */ defaultFileName: string; /** * Package-specific parse function. Receives the raw config record, the validated * base fields, and cwd. Must return the final typed config object. */ parse: (raw: Record, base: BaseConfig, cwd: string) => T; } export declare function loadConfigFile(opts: LoadConfigOptions): Promise; /** * Load a config file that may contain either a single-spec config or a * "projects" array of configs. Returns a normalized array of parsed configs. * * When the config root contains a "projects" key, each entry is parsed * independently. Having both "projects" and top-level single-spec keys * (input_openapi, output) in the same config is a validation error. * * Single-spec configs (no "projects" key) are returned as a one-element array, * making call sites uniform. */ export declare function loadConfigsFile(opts: LoadConfigOptions): Promise; /** * Run a per-project generation function over an array of configs sequentially. * * Single config: calls generateOne without a label (backward-compatible logging). * Multiple configs: calls generateOne with a "[i/N]" progress label for each, * logging per-project progress and failing fast with a clear error on any failure. * * This is the shared iteration kernel used by all generator packages to avoid * duplicating the sequential-loop, logging, and fail-fast error-wrapping logic. */ export declare function runProjects(configs: T[], generateOne: (config: T, label?: string) => Promise): Promise; //# sourceMappingURL=config-core.d.ts.map