Host-bound session and CSRF cookies in Waaseyaa

How Waaseyaa’s SessionCookiePolicy enforces the __Host- cookie prefix’s four constraints for both the session cookie and the CSRF double-submit cookie, and rejects misconfiguration at boot instead of failing silently in the browser.

September 19, 2026 · 6 min · Russell