"#cross-site scripting" #webdev #cookie #http-only