* Update exception handler * Explictly specify 'lax' same site config * Use the null secure option for session cookies