5e57bf19a2
The SameSite=None change left clear_pkce_cookie() deleting every name variant with `SameSite=None; Secure` unconditionally. Over loopback HTTP the setter emits a bare-name cookie with `SameSite=Lax` and no `Secure` — a Secure deletion on a plain-HTTP origin can be ignored by the browser, leaving a stale PKCE cookie behind after callback/logout. Thread use_https from the request into clear_pkce_cookie() and derive both the set and clear attribute shapes from one helper (_pkce_attrs) so they cannot drift apart again. The __Host-/__Secure- variants keep `Secure; SameSite=None` regardless of origin — those names require Secure to be valid at all and only ever exist on HTTPS origins. Adds contract tests pinning the full Set-Cookie shape on both origins for set and clear, and updates the dashboard cookie documentation (which still claimed all cookies are SameSite=Lax).