Bug 3652: [SIGNED-OFF] XSS fixes - follow up