Cookie missing SameSite
A non-session cookie does not set SameSite.
Why it matters
Browsers apply a default, but an explicit Lax or Strict makes the intent obvious.
What to do
Set SameSite=Lax unless the cookie is intentionally cross-site.
Reference
Cookie attributes such as Secure, HttpOnly, and SameSite protect session tokens in browsers.