#http-only #dev #cookie "#cross-site scripting"