"#cross-site scripting" #http-only #webdev #security