#security #http-only #shiny-server "#cross-site scripting"