fix potential xss attack