Maybe I\'m just thinking about this too hard, but I\'m having a problem figuring out what escaping to use on a string in some JavaScript code inside a link\'s onClick handle
Use the Microsoft Anti-XSS library which includes a JavaScript encode.