Efficient Context-aware Output Escaping for JavaScript Template Engines on September 28, 2015 appsecusa 2015 auto escaping context parsing secure-handlebars xss +