[development] AJAX security issue