Cross-site scripting/Shield question