code `return HttpResponse('Unsupported type: ' + type)`, this 'type' is from user input, which may contains html tags and js code