That's a nasty query string you have there ![Very Happy :D]()
If you're confident that Google +1 is not actually vulnerable to an XSS attack, then you could try something like:
I'm not sure of the details of the XSS filter, but it's possible that Giorgio will find a way to improve it so that the exception is not needed.

If you're confident that Google +1 is not actually vulnerable to an XSS attack, then you could try something like:
- ^https://plusone\.google\.com/.*
I'm not sure of the details of the XSS filter, but it's possible that Giorgio will find a way to improve it so that the exception is not needed.