/** * Sanitize a report or page name for use as a file name. * Replaces characters that are problematic on Windows/Unix. */ export declare function sanitizeFileName(name: string): string; /** * Resolve an output path safely. * * - If `output` is provided, it's resolved relative to `cwd`. * - If `output` is absolute, it's checked to be within `cwd` or system temp. * - If `output` is not provided, a temp directory/file is used. * - Path traversal (`..`, NUL, etc.) is rejected. * * @returns The resolved absolute path. */ export declare function resolveOutputPath(output: string | undefined, cwd: string, isDirectory: boolean): string; /** * Resolve a path to its canonical form for security-aware path comparison. * * When a path (or an ancestor) exists on disk, `fs.realpathSync.native` is * used to resolve: * * - Symbolic links and reparse points (all platforms) * - 8.3 short names to long names (Windows) * - Case differences returned by the filesystem (Windows) * * For non-existing paths, the algorithm walks up the directory tree until it * finds an existing ancestor, resolves that, and appends the remainder. * If nothing exists on disk (e.g. a path on a non-existent drive or mount), * the normalised path is returned, lowercased on Windows for consistency. * * This is **not** a general-purpose canonicalisation utility. It deliberately * does *not* create files or directories; it only reads what is already on * disk. Callers must pass a path that has already passed basic safety checks * (NUL bytes, etc.). */ export declare function resolveCanonical(p: string): string; /** * Security-aware path containment check. * * Returns `true` if `child` is within `parent` or equal to it, after resolving * both to canonical forms via {@link resolveCanonical}. On Windows the * comparison is case-insensitive. * * @example * ```ts * isPathWithin('/home/user/project/out/file.png', '/home/user/project') // true * isPathWithin('/etc/passwd', '/home/user/project') // false * ``` */ export declare function isPathWithin(child: string, parent: string): boolean; /** * Ensure the parent directory of a file path exists, creating it if needed. */ export declare function ensureOutputDir(filePath: string): Promise; /** * Write a file atomically, with symlink/TOCTOU resistance. * * Algorithm: * 1. Resolve the target path and validate it is within a safe root. * 2. Create the parent directory if needed. * 3. Write to a temporary file in the same directory (same filesystem → atomic rename). * The temp file is created with `wx` flag (exclusive creation) to prevent symlink tricks. * 4. On Windows, if the target exists, we remove it first (renaming over an existing * file may fail with EEXIST on some Windows configurations; Node's rename defaults * to overwrite but we use unlink + rename for safety on all platforms). * 5. Rename the temp file to the target path. * 6. Revalidate the final path (TOCTOU check). * * Preserves native Windows overwrite behavior: existing file is replaced. * * @param filePath - The target output path. * @param data - The data to write. */ export declare function writeFileSafe(filePath: string, data: Buffer | string): Promise; //# sourceMappingURL=output-path.d.ts.map