a8cb5c5933
SameSite=None requires Secure=true or modern browsers silently reject the Set-Cookie header. Since the site is served over HTTPS via Caddy, this was causing login to succeed (200) but the session cookie to be dropped, making the subsequent /auth/me call fail with 401. SameSite=Lax is the correct setting for same-origin session cookies.