#httpOnly #dev "#cross-site scripting"