apps/session-shell/src/policy.ts's withFrameAncestors rebuilds every relay-made response with new Headers(response.headers), which comma-joins repeated headers. Since the session shell stamps that CSP on everything the relay produces, an app's multiple Set-Cookie headers are merged into one and stop working as separate cookies.
Pre-existing (the old worker did the same), but it now applies to every app response in a session, so the app's cookies are a concrete victim.
Fix: append the CSP without reconstructing the header list, or copy repeated headers with getSetCookie() / an explicit per-name append.
apps/session-shell/src/policy.ts'swithFrameAncestorsrebuilds every relay-made response withnew Headers(response.headers), which comma-joins repeated headers. Since the session shell stamps that CSP on everything the relay produces, an app's multipleSet-Cookieheaders are merged into one and stop working as separate cookies.Pre-existing (the old worker did the same), but it now applies to every app response in a session, so the app's cookies are a concrete victim.
Fix: append the CSP without reconstructing the header list, or copy repeated headers with
getSetCookie()/ an explicit per-name append.