Pattern

Cross-Subdomain Cookie Reachability

cross-origin-cookie-access-mismatch

Cookies set for one host (e.g., api subdomain or specific JSESSIONID) fail to be sent or read on other origins because Domain, SameSite, and httpOnly constraints aren’t aligned, breaking auth and even websocket/proxy flows.