Lax Still Travels on a Link
CookieBank uses SameSite=Lax and still exposes a legacy state-changing GET endpoint. Leave the bank for the external rewards site and follow its link back to CookieBank.
Objective
Confirm that a cross-site top-level GET can carry the Lax session and trigger the unsafe action.