The core issue with this bug is that we trample on any
pre-existing Set-Cookie headers by "willy-nilly" overwriting
our response header with that generated by the origin server.
Should we honor existing Set-Cookie headers, or is that
non-compliant?



Reply via email to