I'm having trouble understanding why cookies are saved in a scenario in my application but not in another.
I have multiple services, each with its own subdomain, making REST requests to each other. In one case, service.example.com makes a POST request to login.example.com. I'm using the fetch API with credentials: include. I've also tested with axios and withCredentials: true with the same results. A successful response has a Set-Cookie header with a JWT and domain example.com and in this scenario the browser saves the cookie as expected.
Now, there's a development environment setup that mirrors the production setup, only every URL is under dev.example.com. So in the dev environment service.dev.example.com makes the same POST request to login.dev.example.com. In this case, if the cookie domain is example.com, it continues to work as expected.
However, if I change the cookie domain in the dev environment to be dev.example.com, the browser (tested on the latest Chrome and Firefox) won't save the cookie anymore, even though every URL involved is still in a subdomain of the cookie domain.
I've read the Domain matching section on RFC6265 and every condition listed there seems to be satisfied by my setup.
Does anyone know why it wouldn't work in this scenario? Is there any way I can have a test setup that won't store cookies that will also be used on requests to the prod environment?
Thanks.