"#cross-site scripting" #xss #http-only