#http-only #cookies "#cross-site scripting" #r-development