[RD] blocking cross site scripting ?