Pattern
Cross-Subdomain Cookie Misconfig
cross-subdomain-cookie-attribute-blocking
Session/JWT cookies fail to reach the expected frontend because cookie attributes (Domain, SameSite, HttpOnly, and framework placement) block browser storage, cross-site sending, or JavaScript access, breaking auth flows and redirect-based endpoints.