Page MenuHomePhabricator

Put rel="noreferrer" on all nonlocal links
ClosedPublic

Authored by epriestley on Apr 6 2014, 2:56 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Feb 9, 12:11 PM
Unknown Object (File)
Sun, Feb 9, 12:11 PM
Unknown Object (File)
Sun, Feb 9, 12:11 PM
Unknown Object (File)
Mon, Feb 3, 5:19 PM
Unknown Object (File)
Fri, Jan 31, 12:32 PM
Unknown Object (File)
Tue, Jan 28, 6:29 AM
Unknown Object (File)
Tue, Jan 28, 6:29 AM
Unknown Object (File)
Tue, Jan 28, 6:29 AM
Subscribers

Details

Summary

Ref T4342. By default, insert rel="noreferrer" for links. We do not insert this if:

  • The caller provided an explicit "rel" attribute.
  • We recognize the link as an anchor ("#comment-2"), or as local to the current domain ("/path/to/resource").

Otherwise, add it in all cases.

Test Plan

Added and executed unit tests. (The javascript stuff which was touched a little bit has a pile of tests already, too.)

Diff Detail

Repository
rPHU libphutil
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

epriestley retitled this revision from to Put rel="noreferrer" on all nonlocal links.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Apr 7 2014, 5:16 PM
epriestley updated this revision to Diff 20671.

Closed by commit rPHUfd6f1829e353 (authored by @epriestley).