Localization cookie missing Secure and SameSite attributes on HTTPS stores

Yeah this one has to be fixed in Shopify’s Set-Cookie headers. You can’t safely patch Secure or SameSite from theme JS without risking a duplicte localization cookie and weird Markets switches, same as lumine said.

Best move for an audit is to screenshot the Network Set-Cookie line on first page load and file it with Shopify Support (Partner support if you have it) as a platform request. In teh report, mark localization as Shopify-owned so it doesn’t get treated like theme debt.