Where: src/token.rs:22-40 (extract_cookie_value).
The loop uses part.split_once('=')? — if any semicolon-separated segment in the Cookie header lacks an = (e.g. a stray malformed pair, or a client sending a flag-only cookie), the ? immediately returns None from the whole function, even if the target cookie (e.g. the JWT) appears later in the same header and is well-formed. This can cause spurious 401s depending on cookie ordering / other cookies present.
Fix direction: continue past segments without = instead of early-returning with ?.
Where:
src/token.rs:22-40(extract_cookie_value).The loop uses
part.split_once('=')?— if any semicolon-separated segment in theCookieheader lacks an=(e.g. a stray malformed pair, or a client sending a flag-only cookie), the?immediately returnsNonefrom the whole function, even if the target cookie (e.g. the JWT) appears later in the same header and is well-formed. This can cause spurious 401s depending on cookie ordering / other cookies present.Fix direction:
continuepast segments without=instead of early-returning with?.