Corrects the iframe-login root cause on record: trust is per-origin including port, and a cert interstitial cannot be accepted inside an iframe, so the SameSite cookie was a downstream symptom rather than the cause. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>