#http-only "#cross-site scripting" #webdev #security