[security-dev] input on bearer tokens and cookies