Skip to:
don't ascii encode
implement allowed referrer
don't redirect if querystring contains hash parameter
implement direct link filter
don't ascii encode