in src/main/java/org/apache/sling/auth/oauth_client/impl/SlingLoginCookieManager.java [167:183]
private static void setCookie(@NotNull final HttpServletRequest request, @NotNull final HttpServletResponse response,
@NotNull final String name, @NotNull final String value, final int maxAge) {
// set the cookie
final StringBuilder cookie = new StringBuilder(name);
cookie.append('=');
cookie.append(value);
cookie.append("; Path=/; HttpOnly");
if (maxAge >= 0) {
cookie.append("; Max-Age=");
cookie.append(maxAge);
}
cookie.append("; SameSite=Lax");
if (request.isSecure()) {
cookie.append("; Secure");
}
response.addHeader("Set-Cookie", cookie.toString());
}