Which flag stops which attack?

HttpOnly, SameSite and a CSRF token each stop a different thing. Set this week's cookie + endpoint config and watch two attacks at once: a stored-XSS cookie theft and a forged cross-site POST to /comments. The lab's own Task 4 vs Task 5 lives in the gap. Nothing is sent anywhere.

Server config

Attack 1 — stored <script> steals the cookie