I currently have an angular interceptor that sets some headers. I am aware that on api calls the set-cookie header is created. On my set-cookie header I am missing a secure flag