With 'Secure' set, it may default to 'None', which we don't need or want.
'Strict' is not suitable for session cookies - the user would see the login
screen when navigating from another site (e.g. hosting dashboard) and we
already have CSRF protection on forms.