dom based cross site scripting prevention