#httpOnly #dev "#cross-site scripting" #xss