Two more from the review. The section declared that no frontend change could
bring OAuth inside the criterion, which writes off the Storage Access API: an
embedded frame can ask the browser, on a user gesture, for access to its own
unpartitioned first-party cookies, and both Safari and Chrome implement it.
That would read the cookie the callback already set with no backend work, at
the cost of a revocable permission prompt. It belongs in the comparison, and it
is the only one of the three routes that is not a backend feature.
And the constraint bullet still offered CHIPS or a token not relying on ambient
cookies as alternatives, when the header path relies on one as soon as the page
reloads. Both routes rest on the same attribute; they differ over who writes the
cookie and what that costs.