What are the risks associated with doing something like this? For instance, there may be some special characters that would pass the validations, allow the user to include u