"#cross-site scripting" #http-only #cookies #r-development