Thread:Project:Support desk/Using ampersands in a extension./reply (15)

The following code will do what you want:

You may see &amp;amp; in the page's source, but rest assured that the browser will decode them to &amp; before attempting to navigate to the URL. This method also protects you from XSS attacks, which your current code is vulnerable to.