Skip to content

Conversation

@auralon
Copy link

@auralon auralon commented Mar 12, 2018

rel="noopener noreferrer" should be added to links containing target="_blank" as a precaution against reverse tabnabbing. For more information, please refer to the following article:
https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/

rel="noopener noreferrer" should be added to links containing target="_blank" as a precaution against reverse tabnabbing. For more information, please refer to the following article:
https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/
@terryupton
Copy link

+1 for this.

@terryupton
Copy link

terryupton commented Sep 3, 2018

@auralon I think this might be as simple as adding this in to the attributes like so;
{% set attributes = { rel: "noopener noreferrer" } %}

{{ block.linkTo.htmlLink(attributes) }}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants