Restore htmlspecialchars() on the editToken value before outputting to HTML.