Pattern
Cross-Subdomain Cookie Reachability
cross-origin-cookie-access-mismatch
Cookies set for one host (e.g., api subdomain or specific JSESSIONID) fail to be sent or read on other origins because Domain, SameSite, and httpOnly constraints aren’t aligned, breaking auth and even websocket/proxy flows.