`extractToken` only ever looked up `cookieValue(cookie, "session")`. After the
M-1 fix switched cookie parsing from substring to exact-name matching
(fafee12), a consumer that sets its session cookie under the hardened
`__Host-session` name (fewo-webapp, #535) stopped resolving — every browser
cookie request extracted an empty token and 401'd. The bare-`session`
substring used to incidentally match inside `__Host-session=`; exact matching
correctly no longer does.
Fix: add `sessionCookieToken(cookieHeader)` which tries the bare `session`
name and falls back to `__Host-session` (the `__Host-` prefix is strictly more
secure, so recognizing it is safe), and route `extractToken` through it. The
bare name is preferred when both are present. `cookieValue` keeps its exact
generic semantics unchanged. Backward-compatible: consumers using `session=`
are unaffected.
Tests: new `test_session_cookie_token` covering both names, precedence, and
substring traps. All 20 ctest targets pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>