"#cross-site scripting" #webdev #security #http-only