Host-bound session and CSRF cookies in Waaseyaa
How Waaseyaa’s SessionCookiePolicy enforces the __Host- cookie prefix’s four constraints for both the session cookie and the CSRF double-submit cookie, and rejects misconfiguration at boot instead of failing silently in the browser.