Bugfix accept additional attributes to the delete cookie

Recent browser changes mean that cookies will not be set if they have
the wrong combination of attributes e.g. SameSite none and not
secure. This also affects deletion which itself is a set cookie

Only the SameSite and secure attributes are required, however it seems
more useful to accept all the possibilities for other edge cases.

