#http-only #security "#cross-site scripting"