Web proxy softwares may convert the case of the cookie name.
Its behavior is permitted at least in the older RFCs.
Then many web libraries/frameworks handle cookie names as case-insensitive.
We should do the same, unless you expect all requests are encrypted and proxies can't modify it.