Well, if you can force the whole site to use HTTPS, then that's better than securing just the cookies
.
But are you saying that even with HTTPS forced, you still can't force secure cookies without breaking it? That would be weird.

But are you saying that even with HTTPS forced, you still can't force secure cookies without breaking it? That would be weird.