Should we add any restrictions on message contents? We could e.g. strip html / js to avoid attacks if that data is presented in a browser, but is this really desired?