how to sanitize input to prevent xss