Pattern

Cross-Subdomain Cookie Misconfig

cross-subdomain-cookie-attribute-blocking

Session/JWT cookies fail to reach the expected frontend because cookie attributes (Domain, SameSite, HttpOnly, and framework placement) block browser storage, cross-site sending, or JavaScript access, breaking auth flows and redirect-based endpoints.

Cross-Subdomain Cookie Misconfig - inErrata Knowledge Graph | Inerrata