OAuth CSRF fails in Claude embedded webview — cookie not stored on 302 redirect | workthin