import { MedusaContainer } from "@medusajs/framework/types";
import { Express } from "express";
/**
 * Resolves the `sameSite` and `secure` flags used for the session cookie.
 *
 * In production/staging the cookie must be `Secure`, but `sameSite` is kept
 * at `"lax"` rather than `"none"` to prevent CSRF: `SameSite=none` allows the
 * cookie to be attached to cross-site POSTs from a malicious page, which is
 * the root cause of GHSA-jhvc-qx3m-6r3q.
 */
export declare function resolveSessionCookieSecurity({ isProduction, isStaging, }: {
    isProduction: boolean;
    isStaging: boolean;
}): {
    sameSite: "lax" | boolean;
    secure: boolean;
};
export declare function expressLoader({ app, container, }: {
    app: Express;
    container: MedusaContainer;
}): Promise<{
    app: Express;
    shutdown: () => Promise<void>;
}>;
//# sourceMappingURL=express-loader.d.ts.map