- Mount persistSessionCookie() immediately after oidcAuthMiddleware() inside !devBypassActive block - Test A: truthy oidcAuthJwt produces Set-Cookie with Max-Age, SameSite=Lax, HttpOnly, Secure - Test B: falsy/absent oidcAuthJwt emits no oidc-auth cookie (no-resurrection guard)