#http-only #webdev #security "#cross-site scripting"