Deliberately hosted on a registrable domain with no relationship
to Clerk, to the producer instance (clerk.massivenights.org), or to the
payload host (app.massivenights.org). That is what makes the
cross-site claim unimpeachable: nothing about these pages is same-site with
anything in the chain.
<img> to a signed img.clerk.com blob. No
clicks. Does the attacker's Set-Cookie land on
.clerk.com from a cross-site subresource?Both pages take the blob URL as input, so nothing is hardcoded and switching
the SAMESITE arm on the payload host needs no redeploy here.