Oh
Okay, anything like mod_security or anything else? It's weird because when the browser sends the cookies with the request, there's nothing that says whether it was or wasn't set by javascript, yet it's only the javascript ones that don't work...
