#r-development #xss #http-only "#cross-site scripting"