Close a loophole in CookieSessionProvider