Safari flat out doesn\'t let you set cookies in iframes of domains different than the parent domain, server-side CORS headers be damned.
To clarify: user
I think I might have found the solution: Apple's Storage Access API: https://webkit.org/blog/8124/introducing-storage-access-api/