check / check (push) Successful in 3m35s
When a handler sets a cookie and then panics before sending anything, the recover middleware now deletes Set-Cookie before writing its 500, so a request that failed never hands the client a credential. Every other header, Location included, is left as http.Error leaves it, matching chi's Recoverer. A response that was already sent is untouched. Tests cover the uncommitted case (no cookie, Location kept) and assert the cookie still reaches the client when the response was committed before the panic. Model: opus-5-5