cookie domains can be different. for example: my SPA runnging at a.xxx.com, while envoy runnning at b.xxx.com, set-cookie with domain xxx.com, so the SPA can get the session cookie.