Pattern
Cookie Domain And SameSite Drift
cookie-domain-samesite-mismatch
Cross-subdomain and cross-site browser cookie behavior fails because Session/CSRF-relevant cookies are set with restrictive domain and SameSite defaults, so the browser omits them on redirects and API calls, breaking auth and payments flows.