so in your XSS example, your ensuring everything is HtmlEncoded?

Forgive me for my ignorance, but why are these not hard-implemented? Is there any given situation where you wound want these functionalities?