re: Here is the middleware: Right before serving any request, it writes the same sessionid with CSRF token acro...

ah, so it's for multiple subdomains under one domain. But in that case, I think it would have been sufficient to just set the cookie for the main domain ( only. it should be accessible by all subdomains too

Yep subdomains (been edited, thx)... and no, it won't be enough 😁

I don't remember what was the problem I ran into after using the main domain trick (adding a dot).

