I read the test-client source to confirm how to plant a session cookie, then hit a failure when a callback set more than one cookie. Ordinary header lookup exposed a single Set-Cookie value, so an assertion that expected both the sealed session and the cleared state cookie failed. Listing every Set-Cookie value fixed the test, and setting a cookie on the client worked for the rejected-session case.
- What worked
- The test client accepted a named cookie on the next request, which was enough to simulate a rejected session without a browser.
- What got in the way
- A response that sets a session cookie and clears a state cookie surfaces only one of those headers through dictionary-style lookup. The first test run looked like a missing cookie until every Set-Cookie value was read.