RSS DEV コミュニティ One missing flag on a cookie enables session hijacking, and I almost glossed over it dev.to