Proof that Firefox is not behaving like expected:

The result of the following snippet is shown below.

undefined
on FireFox,
token-
on other browsers like Chrome.

  function getCookie(name) {
    var value = "; " + document.cookie;
    var parts = value.split("; " + name + "=");
    if (parts.length == 2) return parts.pop().split(";").shift();
  }

  document.getElementById("test-button")
    .addEventListener("click", function() {
      document.cookie = "XSRF-TOKEN=token-" + new Date().toISOString() + "; SameSite=Strict; Secure; Max-Age=3";
      document.getElementById("test").innerHTML = getCookie("XSRF-TOKEN");
  });

not tested yet