HTTP-only Cookie AuthenticationMechanism and implementation of session-based authentication using HTTP-only Cookies