Please point them out here.
* There's no "Session" attribute -- (when no expires is set, it's a session cookie)
* session cookies deletion is misstated
* JWTs are just a possible format for OAuth, not a requirement
* incorrectly states that jwts are signed but not encrypted
This is really good advice and has bitten me in the past, I think as someone who is new to this it is tempting to avoid the term "Lax" but you might end up with some surprising behavior if you go with "Strict" as your default.
I also attempted to make sense of it all and created https://samesite.diduthink.com