"#cross-site scripting" #cookie #r-shiny #httpOnly