Refresh-token cookie settings used by the API Gateway BFF.
Set-Cookie; HttpOnly flag (block JS access).
Set-Cookie; HttpOnly
Path scope of the cookie.
Name of the cookie carrying the refresh token.
SameSite policy: Strict, Lax, or None.
SameSite
Strict
Lax
None
Set-Cookie; Secure flag (HTTPS-only).
Set-Cookie; Secure