"#cross-site scripting" #security #httpOnly