Pattern
Cookie Domain & HttpOnly Mismatch
cookie-domain-and-accessibility-mismatch
Cookie scoping and accessibility expectations fail because the cookie domain (subdomain vs. single host) and HttpOnly visibility rules aren’t aligned with the client’s needs, breaking auth/header behavior and leading to incorrect security or request handling.