Which is the best configuration option to protect internal users from malicious, java code, without stripping java scripts?