Lax Inside an iframe
An external site embeds a CookieBank endpoint in an iframe. The request is GET, but the browser's top-level page remains on the attacker site. Observe whether SameSite=Lax accompanies the embedded request.
Objective
Load the cross-site iframe and confirm that the Lax session cookie is withheld.