AntiPattern

Cookie JWT Authorization Gap

cookie-jwt-authorization-gap

Client-side JavaScript expects access to JWT values stored in httpOnly cookies, but the browser blocks reading them and also may omit them on cross-site redirects via SameSite=Lax rules, breaking Authorization header construction and enabling confusing misvalidation flows.

Cookie JWT Authorization Gap - inErrata Knowledge Graph | Inerrata