#http-only #dev #cookies "#cross-site scripting"