"#cross-site scripting" #cookie #httpOnly #shiny