HttpOnly, SameSite and a CSRF token each stop a different thing. Set this
week's cookie + endpoint config and watch two attacks at once: a stored-XSS cookie theft and a
forged cross-site POST to /comments. The lab's own Task 4 vs Task 5 lives in the gap.
Nothing is sent anywhere.
<script> steals the cookie