Session creation triggered by XSS/XSRF filter