Securing web applications by design