"#cross-site scripting" #http-only #security