Page MenuHomePhabricator

Put rel="noreferrer" on all nonlocal links
ClosedPublic

Authored by epriestley on Apr 6 2014, 2:56 PM.
Tags
None
Referenced Files
Unknown Object (File)
Jun 25 2025, 5:22 PM
Unknown Object (File)
Jun 21 2025, 1:12 PM
Unknown Object (File)
Jun 9 2025, 2:07 AM
Unknown Object (File)
May 10 2025, 7:14 PM
Unknown Object (File)
May 7 2025, 5:17 AM
Unknown Object (File)
Apr 18 2025, 5:43 PM
Unknown Object (File)
Apr 12 2025, 1:06 PM
Unknown Object (File)
Apr 12 2025, 1:22 AM
Subscribers

Details

Summary

Ref T4342. By default, insert rel="noreferrer" for links. We do not insert this if:

  • The caller provided an explicit "rel" attribute.
  • We recognize the link as an anchor ("#comment-2"), or as local to the current domain ("/path/to/resource").

Otherwise, add it in all cases.

Test Plan

Added and executed unit tests. (The javascript stuff which was touched a little bit has a pile of tests already, too.)

Diff Detail

Repository
rPHU libphutil
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

epriestley retitled this revision from to Put rel="noreferrer" on all nonlocal links.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Apr 7 2014, 5:16 PM
epriestley updated this revision to Diff 20671.

Closed by commit rPHUfd6f1829e353 (authored by @epriestley).