#r-development #http-only #xss "#cross-site scripting"