import * as plugins from '../../plugins.js';
import { TlsAlertLevel, TlsAlertDescription } from '../utils/tls-utils.js';
/**
 * TlsAlert class for creating and sending TLS alert messages
 */
export declare class TlsAlert {
    static readonly LEVEL_WARNING = TlsAlertLevel.WARNING;
    static readonly LEVEL_FATAL = TlsAlertLevel.FATAL;
    static readonly CLOSE_NOTIFY = TlsAlertDescription.CLOSE_NOTIFY;
    static readonly UNEXPECTED_MESSAGE = TlsAlertDescription.UNEXPECTED_MESSAGE;
    static readonly BAD_RECORD_MAC = TlsAlertDescription.BAD_RECORD_MAC;
    static readonly DECRYPTION_FAILED = TlsAlertDescription.DECRYPTION_FAILED;
    static readonly RECORD_OVERFLOW = TlsAlertDescription.RECORD_OVERFLOW;
    static readonly DECOMPRESSION_FAILURE = TlsAlertDescription.DECOMPRESSION_FAILURE;
    static readonly HANDSHAKE_FAILURE = TlsAlertDescription.HANDSHAKE_FAILURE;
    static readonly NO_CERTIFICATE = TlsAlertDescription.NO_CERTIFICATE;
    static readonly BAD_CERTIFICATE = TlsAlertDescription.BAD_CERTIFICATE;
    static readonly UNSUPPORTED_CERTIFICATE = TlsAlertDescription.UNSUPPORTED_CERTIFICATE;
    static readonly CERTIFICATE_REVOKED = TlsAlertDescription.CERTIFICATE_REVOKED;
    static readonly CERTIFICATE_EXPIRED = TlsAlertDescription.CERTIFICATE_EXPIRED;
    static readonly CERTIFICATE_UNKNOWN = TlsAlertDescription.CERTIFICATE_UNKNOWN;
    static readonly ILLEGAL_PARAMETER = TlsAlertDescription.ILLEGAL_PARAMETER;
    static readonly UNKNOWN_CA = TlsAlertDescription.UNKNOWN_CA;
    static readonly ACCESS_DENIED = TlsAlertDescription.ACCESS_DENIED;
    static readonly DECODE_ERROR = TlsAlertDescription.DECODE_ERROR;
    static readonly DECRYPT_ERROR = TlsAlertDescription.DECRYPT_ERROR;
    static readonly EXPORT_RESTRICTION = TlsAlertDescription.EXPORT_RESTRICTION;
    static readonly PROTOCOL_VERSION = TlsAlertDescription.PROTOCOL_VERSION;
    static readonly INSUFFICIENT_SECURITY = TlsAlertDescription.INSUFFICIENT_SECURITY;
    static readonly INTERNAL_ERROR = TlsAlertDescription.INTERNAL_ERROR;
    static readonly INAPPROPRIATE_FALLBACK = TlsAlertDescription.INAPPROPRIATE_FALLBACK;
    static readonly USER_CANCELED = TlsAlertDescription.USER_CANCELED;
    static readonly NO_RENEGOTIATION = TlsAlertDescription.NO_RENEGOTIATION;
    static readonly MISSING_EXTENSION = TlsAlertDescription.MISSING_EXTENSION;
    static readonly UNSUPPORTED_EXTENSION = TlsAlertDescription.UNSUPPORTED_EXTENSION;
    static readonly CERTIFICATE_REQUIRED = TlsAlertDescription.CERTIFICATE_REQUIRED;
    static readonly UNRECOGNIZED_NAME = TlsAlertDescription.UNRECOGNIZED_NAME;
    static readonly BAD_CERTIFICATE_STATUS_RESPONSE = TlsAlertDescription.BAD_CERTIFICATE_STATUS_RESPONSE;
    static readonly BAD_CERTIFICATE_HASH_VALUE = TlsAlertDescription.BAD_CERTIFICATE_HASH_VALUE;
    static readonly UNKNOWN_PSK_IDENTITY = TlsAlertDescription.UNKNOWN_PSK_IDENTITY;
    static readonly CERTIFICATE_REQUIRED_1_3 = TlsAlertDescription.CERTIFICATE_REQUIRED_1_3;
    static readonly NO_APPLICATION_PROTOCOL = TlsAlertDescription.NO_APPLICATION_PROTOCOL;
    /**
     * Create a TLS alert buffer with the specified level and description code
     *
     * @param level Alert level (warning or fatal)
     * @param description Alert description code
     * @param tlsVersion TLS version bytes (default is TLS 1.2: 0x0303)
     * @returns Buffer containing the TLS alert message
     */
    static create(level: number, description: number, tlsVersion?: [number, number]): Buffer;
    /**
     * Create a warning-level TLS alert
     *
     * @param description Alert description code
     * @returns Buffer containing the warning-level TLS alert message
     */
    static createWarning(description: number): Buffer;
    /**
     * Create a fatal-level TLS alert
     *
     * @param description Alert description code
     * @returns Buffer containing the fatal-level TLS alert message
     */
    static createFatal(description: number): Buffer;
    /**
     * Send a TLS alert to a socket and optionally close the connection
     *
     * @param socket The socket to send the alert to
     * @param level Alert level (warning or fatal)
     * @param description Alert description code
     * @param closeAfterSend Whether to close the connection after sending the alert
     * @param closeDelay Milliseconds to wait before closing the connection (default: 200ms)
     * @returns Promise that resolves when the alert has been sent
     */
    static send(socket: plugins.net.Socket, level: number, description: number, closeAfterSend?: boolean, closeDelay?: number): Promise<void>;
    /**
     * Pre-defined TLS alert messages
     */
    static readonly alerts: {
        closeNotify: Buffer<ArrayBufferLike>;
        unsupportedExtension: Buffer<ArrayBufferLike>;
        certificateRequired: Buffer<ArrayBufferLike>;
        unrecognizedName: Buffer<ArrayBufferLike>;
        noRenegotiation: Buffer<ArrayBufferLike>;
        userCanceled: Buffer<ArrayBufferLike>;
        certificateExpiredWarning: Buffer<ArrayBufferLike>;
        handshakeFailureWarning: Buffer<ArrayBufferLike>;
        insufficientSecurityWarning: Buffer<ArrayBufferLike>;
        unexpectedMessage: Buffer<ArrayBufferLike>;
        badRecordMac: Buffer<ArrayBufferLike>;
        recordOverflow: Buffer<ArrayBufferLike>;
        handshakeFailure: Buffer<ArrayBufferLike>;
        badCertificate: Buffer<ArrayBufferLike>;
        certificateExpired: Buffer<ArrayBufferLike>;
        certificateUnknown: Buffer<ArrayBufferLike>;
        illegalParameter: Buffer<ArrayBufferLike>;
        unknownCA: Buffer<ArrayBufferLike>;
        accessDenied: Buffer<ArrayBufferLike>;
        decodeError: Buffer<ArrayBufferLike>;
        decryptError: Buffer<ArrayBufferLike>;
        protocolVersion: Buffer<ArrayBufferLike>;
        insufficientSecurity: Buffer<ArrayBufferLike>;
        internalError: Buffer<ArrayBufferLike>;
        unrecognizedNameFatal: Buffer<ArrayBufferLike>;
    };
    /**
     * Utility method to send a warning-level unrecognized_name alert
     * Specifically designed for SNI issues to encourage the client to retry with SNI
     *
     * @param socket The socket to send the alert to
     * @returns Promise that resolves when the alert has been sent
     */
    static sendSniRequired(socket: plugins.net.Socket): Promise<void>;
    /**
     * Utility method to send a close_notify alert and close the connection
     *
     * @param socket The socket to send the alert to
     * @param closeDelay Milliseconds to wait before closing the connection (default: 200ms)
     * @returns Promise that resolves when the alert has been sent and the connection closed
     */
    static sendCloseNotify(socket: plugins.net.Socket, closeDelay?: number): Promise<void>;
    /**
     * Utility method to send a certificate_expired alert to force new TLS session
     *
     * @param socket The socket to send the alert to
     * @param fatal Whether to send as a fatal alert (default: false)
     * @param closeAfterSend Whether to close the connection after sending the alert (default: true)
     * @param closeDelay Milliseconds to wait before closing the connection (default: 200ms)
     * @returns Promise that resolves when the alert has been sent
     */
    static sendCertificateExpired(socket: plugins.net.Socket, fatal?: boolean, closeAfterSend?: boolean, closeDelay?: number): Promise<void>;
    /**
     * Send a sequence of alerts to force SNI from clients
     * This combines multiple alerts to ensure maximum browser compatibility
     *
     * @param socket The socket to send the alerts to
     * @returns Promise that resolves when all alerts have been sent
     */
    static sendForceSniSequence(socket: plugins.net.Socket): Promise<void>;
    /**
     * Send a fatal level alert that immediately terminates the connection
     *
     * @param socket The socket to send the alert to
     * @param description Alert description code
     * @param closeDelay Milliseconds to wait before closing the connection (default: 100ms)
     * @returns Promise that resolves when the alert has been sent and the connection closed
     */
    static sendFatalAndClose(socket: plugins.net.Socket, description: number, closeDelay?: number): Promise<void>;
}
