* Only blacklist query string extensions which match /^[a-zA-Z0-9_-]+$/. This avoids...