we should only send the Set-Cookie header to the browser on the first response after...