https://medium.com/@roperluo.me/cross-site-scripting-xss-why-is-there-an-httponly-attribute-in-cookies-d1bcb51f355a