Do not take this article for granted. There are so many incorrect explanations in it. This is a really bad writeup for a security blog. I really don't know where to start ...
* There's no "Session" attribute -- (when no expires is set, it's a session cookie)
* session cookies deletion is misstated
* JWTs are just a possible format for OAuth, not a requirement
* incorrectly states that jwts are signed but not encrypted
This is really good advice and has bitten me in the past, I think as someone who is new to this it is tempting to avoid the term "Lax" but you might end up with some surprising behavior if you go with "Strict" as your default.
I also attempted to make sense of it all and created https://samesite.diduthink.com