/** * Shared file-manager helpers (root resolve, rate-limit, project chown). * Extracted from files-controller (Wave E1). */ import type { IncomingMessage } from 'node:http'; import type { UserDto } from 'ysk-server-shared'; import type { AppContext } from '../app-context.js'; /** Public share + WebDAV auth: 10 fails / 15m → 15m lock */ export declare const PUBLIC_AUTH_RL: { maxFailures: number; windowMs: number; lockMs: number; }; /** * Client IP for rate limits. Only trust X-Forwarded-For when * YSK_TRUST_PROXY=1 (or true) — otherwise spoofable. */ export declare function clientIp(req: IncomingMessage): string; export declare function resolveRoot(ctx: AppContext, rootParam: string, opts?: { user?: UserDto; /** Public share download — token already authorized */ skipCap?: boolean; }): { root: string; rootKey: string; owner?: { linuxUser: string; linuxGroup: string; homeDir: string; }; }; export declare function chownProjectRels(ctx: AppContext, owner: { linuxUser: string; linuxGroup: string; homeDir: string; } | undefined, relPaths: string[]): Promise<{ chowned: boolean; notes: string[]; }>; //# sourceMappingURL=files-shared.d.ts.map