Yep SameSite lax, and just make sure you never perform any actions using Get requests, which you shouldn’t anyway.
Unsubscribe often need to be GET, or at least start as GET
Unsubscribe often need to be GET, or at least start as GET