/** * Recursive Provider credential redaction (DESIGN.md §16). * * This Module is the single source of truth for stripping Provider * credentials before any value leaves Scoutline's outward boundaries: * formatted errors, cached metadata, quota failures, diagnostics output, * and fatal shell errors. * * Redaction properties (Phase 4 P4-01): * - Case-insensitive for the canonical credential-shaped keys. * - Recursive through nested arrays and plain objects. * - Non-mutating — the original input is never modified. * - Secret-aware — every configured secret value is replaced inside * any string the value tree reaches, not just the configured key. * - Empty-safe — empty strings are never treated as a replacement token. * * The Module retains the legacy `redactSecrets(value, apiKey?)` and * `redactTool(tool)` exports so existing call sites keep compiling. * New code should pass an explicit array of secrets so every Provider's * credential is covered in one pass. */ import type { Tool } from "@utcp/sdk"; /** * Replace credential-shaped substrings inside a single string. Useful * for error messages and load-failure texts where the value is a flat * string rather than a structured object. * * Replaces: * - Authorization header values under common schemes: `Bearer`, * `Basic`, `Digest`, `Token`, and `ApiKey` (any case). * - `Credential=` parameter values, covering the AWS SigV4 header form * (`AWS4-HMAC-SHA256 Credential=AKIA…/scope`) that carries no scheme * keyword of its own (#180). The label is preserved; the value is not. * - x-api-key assignments (any case; `=`, `:`, or whitespace as the * key/value separator — covers both `x-api-key=value` and * `x-api-key value`). * - Z_AI_API_KEY, ZAI_API_KEY, MINIMAX_API_KEY, TAVILY_API_KEY, * EXA_API_KEY, BRAVE_SEARCH_API_KEY, FIRECRAWL_API_KEY, * YDC_API_KEY, YOU_API_KEY, LINKUP_API_KEY, SPIDER_API_KEY, * BOCHA_API_KEY, SEARCHAPI_API_KEY, SERPAPI_API_KEY, * KAGI_API_KEY, KAGI_TOKEN assignments. * - The literal credentials passed in `extraSecrets` (each value is * replaced wherever it appears; empty strings are skipped). * * @param input - The string from which credential-like values are redacted * @param extraSecrets - Optional secret(s) additionally replaced wherever * their values appear * @returns The input with every detected credential replaced by * `[REDACTED]` */ export declare function redactCredentialString(input: string, extraSecrets?: string | string[]): string; /** * Resolve the configured Provider credential values from the current * process environment. Returned values are deduplicated and empty * entries skipped, so callers can pass the result directly to * {@link redactSecrets}. */ export declare function configuredSecrets(env?: NodeJS.ProcessEnv): string[]; /** * Recursively redact credential values from an arbitrary tree. * * Accepts either a single string (back-compat overload) or an array of * secret values. Returns a NEW value tree; the input is never mutated. * * Key matching is case-insensitive over {@link CREDENTIAL_KEYS}. Plain * objects and arrays are descended into. Other object kinds (Date, * typed arrays, class instances) are returned as-is so their internal * state is not reflected. */ export declare function redactSecrets(value: unknown, secrets?: string | string[]): unknown; /** * Redact credential-shaped fields from a Tool's metadata tree. * * Back-compat: when called with a single argument the function reads * the configured Provider credentials from the current process * environment. When called with an explicit secrets argument, the * caller's value is used instead. */ export declare function redactTool(tool: Tool, secrets?: string | string[]): Tool; //# sourceMappingURL=redact.d.ts.map