Removing 'secure' from cookie send by backend is plain wrong.
Attach a file by drag & drop or click to upload