Finally tighten up the server-side wildcard security hole, the