response.setHeader("Set-Cookie", "HttpOnly;Secure;SameSite=Strict");

You’ve been Roger Wilco’ed.