#http-only #xss "#cross-site scripting"