export interface NexqlMcpRunner { kind: "path" | "npx"; command: string[]; version?: string; installedBy: "found" | "npx-resolved"; } /** * Locates the nexql-mcp runner: a real `nexql-mcp` on PATH is preferred, * otherwise `npx -y nexql-mcp` is resolved from the npm registry cache. */ export declare function resolveNexqlMcpRunner(): Promise; /** * Preflight TCP reachability check against a host:port (e.g. a DB target or a * relay listen port). Resolves with latency or throws a * NEXQL_MCP_DB_UNREACHABLE error when the target does not accept connections * within timeoutMs. */ export declare function preflightTcpCheck(options: { host: string; port: number; timeoutMs?: number; }): Promise<{ host: string; port: number; latencyMs: number; }>; /** * Masks the password in both URL-style and libpq keyword connection strings. * * B7 fix: also masks `password=…` (and `PASSWORD=…`) libpq keyword form so * keyword-style connection strings don't leak passwords into pidfiles / logs. */ export declare function maskConnString(value: string): string; /** * Extracts the password from a libpq connection string (postgres://user:pass@host:port/db). * * B8 fix: uses URL() + decodeURIComponent so percent-encoded passwords * (e.g. `%40` for `@`, `%2F` for `/`) are decoded correctly before being * placed into PGPASSWORD. Falls back to regex for non-URL connection strings. */ export declare function passwordFromConnString(value: string): string | undefined; /** * Returns a copy of the connection string with the embedded password removed * (postgres://user@host:port/db), so the password never appears in argv or * process listings; it is supplied via the PGPASSWORD env var instead. */ export declare function connStringWithoutPassword(value: string): string; export interface NexqlMcpHttpRecord { pid: number; command: string; httpPort: number; startedAt: string; /** Process start time (ms since epoch) for PID-reuse detection (B12). */ startTimeMs: number; /** Per-spawn nonce; used to verify probe response identity (B2). */ spawnNonce: string; runnerVersion?: string; } export declare function readNexqlMcpHttpRecord(): NexqlMcpHttpRecord | undefined; export declare function startNexqlMcpHttp(options: { runner: NexqlMcpRunner; connectionString: string; httpPort: number; token: string; logPath: string; bind?: string; env?: NodeJS.ProcessEnv; readyTimeoutMs?: number; profiles?: string[]; workspaceRoot?: string; }): Promise<{ pid: number; command: string; version?: string; waitForExit: Promise; }>; export declare function stopNexqlMcpHttp(): Promise<{ stopped: boolean; pid?: number; message: string; }>; export declare function maskToken(value: string): string; /** * Register relay configs as nexql-mcp profiles so the MCP server knows about * all databases. Each relay becomes a named profile that agents can switch * to via the `switch_connection` tool. * * Writes directly to the global nexql-mcp config (~/.config/nexql-mcp/config.toml) * because --profile flag only reads from global config, not workspace config. * Passwords are stored as separate .pw files in the cache bin dir. */ export declare function registerRelayProfiles(options: { runner: NexqlMcpRunner; mappings: Array<{ listenPort: number; targetHost: string; targetPort: number; user?: string; password?: string; database?: string; name?: string; accessMode?: string; }>; defaultProfile?: string; }): Promise; /** * Cryptographically secure random token using rejection sampling. * * B14 fix: eliminates modulo bias from `b % chars.length` (256 % 62 = 8 * causes the first 8 characters to appear ~0.4% more often than the rest). * Rejection sampling discards any byte >= floor(256/62)*62 = 248, then maps * the accepted bytes uniformly across the alphabet. */ export declare function randomToken(length?: number): string; //# sourceMappingURL=nexql-mcp.d.ts.map