[jboss-dev-forums] [Design of Security on JBoss] - Re: Adding the HttpOnly cookie flag to the core of JBoss