close security holes in patron search autocompletion