/** * Persistent per-(source, target) masking salt. * * Lives beside the project id-map at `~/.sandbox-seed/id-maps/__.salt` * (chmod 600). Persisting it keeps masking deterministic across separate runs * against the same org pair — so re-seeds are idempotent and external-id UPSERT * keeps matching the rows a prior run masked. (masking-spec.md §4.5) * * The salt is a SECRET: it is never logged, and never returned in any tool * response. Only the masking engine (HMAC key) and session.json hold it. */ export type SaltOptions = { sourceAlias: string; targetAlias: string; /** Defaults to `~/.sandbox-seed`. Overridable for tests. */ rootDir?: string; }; export declare function saltPath(opts: SaltOptions): string; /** * Load the persistent salt for a (source, target) pair, creating it (CSPRNG) on * first use. Returns the 64-hex salt string. */ export declare function loadOrCreateSalt(opts: SaltOptions): Promise;