Page MenuHomePhabricator

Put rel="noreferrer" on all nonlocal links
ClosedPublic

Authored by epriestley on Apr 6 2014, 2:56 PM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, May 1, 12:20 AM
Unknown Object (File)
Sat, Apr 20, 6:44 PM
Unknown Object (File)
Fri, Apr 12, 1:12 PM
Unknown Object (File)
Tue, Apr 9, 11:24 AM
Unknown Object (File)
Sun, Apr 7, 3:46 PM
Unknown Object (File)
Sat, Apr 6, 5:42 PM
Unknown Object (File)
Mar 22 2024, 11:53 PM
Unknown Object (File)
Mar 22 2024, 11:52 PM
Subscribers

Details

Summary

Ref T4342. By default, insert rel="noreferrer" for links. We do not insert this if:

  • The caller provided an explicit "rel" attribute.
  • We recognize the link as an anchor ("#comment-2"), or as local to the current domain ("/path/to/resource").

Otherwise, add it in all cases.

Test Plan

Added and executed unit tests. (The javascript stuff which was touched a little bit has a pile of tests already, too.)

Diff Detail

Repository
rPHU libphutil
Branch
ref1
Lint
Lint Passed
Unit
Tests Passed

Event Timeline

epriestley retitled this revision from to Put rel="noreferrer" on all nonlocal links.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Apr 7 2014, 5:16 PM
epriestley updated this revision to Diff 20671.

Closed by commit rPHUfd6f1829e353 (authored by @epriestley).