/** * Cookie serialization helpers shared by the request context, session, and CSRF * middleware. * * @module bquery/server */ import type { ServerCookieOptions } from './types.cjs'; /** * Whether a cookie with these attributes may carry the `__Host-` prefix: * `Secure`, `Path=/` and no `Domain`. Browsers refuse such a cookie from a * sibling subdomain or over plain HTTP, so it cannot be planted. * @internal */ export declare const allowsHostPrefix: (options: ServerCookieOptions) => boolean; /** * The default cookie name for `base`: `__Host-` when the attributes * allow the prefix, `base` otherwise. * @internal */ export declare const defaultCookieName: (base: string, options: ServerCookieOptions) => string; /** * Throw when `name` carries a `__Host-` or `__Secure-` prefix that `options` * do not satisfy, or a mis-cased spelling of one. Browsers silently drop a * cookie that violates its prefix, which would otherwise surface only as every * request failing. Current browsers match the prefixes case-insensitively, but * older ones only enforce the exact spelling, so a name like `__host-sid` would * not stop a sibling subdomain from planting the cookie there. * @internal */ export declare const assertCookiePrefix: (owner: string, name: string, options: ServerCookieOptions) => void; /** * Serialize a `Set-Cookie` header value, validating the name and attribute * values so request-controlled data can never inject extra cookie attributes. */ export declare const serializeCookie: (name: string, value: string, options?: ServerCookieOptions) => string; /** * Append a `Set-Cookie` header to an existing response without collapsing it * into other cookies. * * Responses built by `createServer()` expose mutable headers, so the cookie is * appended in place. When the headers are immutable (e.g. a response produced by * `Response.redirect()`), the response is reconstructed around the same body so * the cookie is still emitted. */ export declare const appendSetCookie: (response: Response, cookie: string) => Response; //# sourceMappingURL=cookies.d.ts.map