People say that but it's not really true. If they just have 1P cookies for basic functionality (login), then I believe there can be a discreet notice at the bottom informing the user of that fact. Groups like IEEE should be the ones pioneering those patterns.
AFAIK, only 3rd party cookies require this consent. I am pretty sure you require consent for 2nd party as well. Your own site's cookies? Do what you want.
GDPR, however, also covers other things like your storing user's data, but that is separate from cookies. Cookies are stored on user's device.
Not even sure you need any discreet notice about anything for strictly necessary first party cookies. That's my understanding of GDPR, at any rate.
Cookies for auth do not need such thing