This is not perfect but at least we can be consistent about keeping URLs-that-lead-to-xss in the same query