XSS fix based on Jason's fix