make cookie http only, secure, etc. Everything that proceeds. Toggable via config so in development & tests can be disabled