#shiny #xss #httpOnly "#cross-site scripting"