Page MenuHomePhabricator

Put rel="noreferrer" on all nonlocal links
ClosedPublic

Authored by epriestley on Apr 6 2014, 2:56 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Apr 12, 1:12 PM
Unknown Object (File)
Tue, Apr 9, 11:24 AM
Unknown Object (File)
Sun, Apr 7, 3:46 PM
Unknown Object (File)
Sat, Apr 6, 5:42 PM
Unknown Object (File)
Fri, Mar 22, 11:53 PM
Unknown Object (File)
Fri, Mar 22, 11:52 PM
Unknown Object (File)
Fri, Mar 22, 11:08 PM
Unknown Object (File)
Fri, Mar 22, 10:45 PM
Subscribers

Details

Summary

Ref T4342. By default, insert rel="noreferrer" for links. We do not insert this if:

  • The caller provided an explicit "rel" attribute.
  • We recognize the link as an anchor ("#comment-2"), or as local to the current domain ("/path/to/resource").

Otherwise, add it in all cases.

Test Plan

Added and executed unit tests. (The javascript stuff which was touched a little bit has a pile of tests already, too.)

Diff Detail

Repository
rPHU libphutil
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

epriestley retitled this revision from to Put rel="noreferrer" on all nonlocal links.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Apr 7 2014, 5:16 PM
epriestley updated this revision to Diff 20671.

Closed by commit rPHUfd6f1829e353 (authored by @epriestley).