Session cookies: HttpOnly, Secure, SameSite=Lax
Three attributes, each closing a class of attack. HttpOnly keeps scripts from reading it. Secure keeps it off plain HTTP. SameSite=Lax stops it being sent on cross-site POSTs, which is most CSRF.
Set-Cookie: session=...; HttpOnly; Secure; SameSite=Lax; Path=/; Max-Age=1209600Strict breaks arriving from an external link while logged in. Lax is the default worth keeping.
securityhttp