#http-only #xss #webdev "#cross-site scripting"