"#cross-site scripting" #http-only #cookies #dev