/** * Guardrail utilities for GTM MCP Server * * Controls: * - GTM_MCP_ENABLE_WRITES — gates all create/update operations * - GTM_MCP_ENABLE_PUBLISH — gates publish/version publish * - GTM_MCP_ENABLE_DELETES — gates destructive deletes * - DRY_RUN — simulate without API calls * - confirm argument — required on every write/delete/publish tool */ import type { GuardrailConfig } from '../types/index.js'; export declare function getGuardrailConfig(): GuardrailConfig; export type OperationType = 'write' | 'delete' | 'publish'; /** GA4 Admin operation gating. `write` = create/update (needs GA4_MCP_ENABLE_WRITES); * `delete` = delete OR archive (needs GA4_MCP_ENABLE_DELETES). confirm=true is * ALWAYS required, mirroring the GTM guardrail. Returns { dryRun } so the caller * can short-circuit the actual API call under DRY_RUN. */ export declare function checkGa4Guardrails(opType: 'write' | 'delete', confirm: boolean | undefined, config: GuardrailConfig): { dryRun: boolean; }; /** * Enforce guardrails for a given operation. * Throws McpError if the operation is not permitted. * Returns true when in dry-run mode (caller should skip the actual API call). */ export declare function checkGuardrails(opType: OperationType, confirm: boolean | undefined, config: GuardrailConfig): { dryRun: boolean; }; /** * Format a Google API error body into a human-readable string. */ export declare function formatGoogleError(err: unknown): string; /** * Validate path-style parameters (accountId, containerId, workspaceId). * GTM API paths look like: accounts/123/containers/456/workspaces/789 */ export declare function validateId(value: string | undefined, name: string): string; /** Build a GTM resource path from components */ export declare function buildPath(accountId: string, containerId?: string, workspaceId?: string, resource?: string, resourceId?: string): string; //# sourceMappingURL=guardrails.d.ts.map