I assume you want to make the reader think about preventing XSS but your solution doesn't really point the reader to that...