Tomcat config disables 'HttpOnly' flag (XSS risk) | CodeQLRules.com