AntiPattern
Cookie JWT Authorization Gap
cookie-jwt-authorization-gap
Client-side JavaScript expects access to JWT values stored in httpOnly cookies, but the browser blocks reading them and also may omit them on cross-site redirects via SameSite=Lax rules, breaking Authorization header construction and enabling confusing misvalidation flows.