Skip to content

Remove target="_blank" links or sanitise them #558

@danielcompton

Description

@danielcompton

There is a vulnerability with opening target="_blank" links without adding rel="noopener noreferrer". I'd argue we probably don't want them at all, but if we do then we should also add the rel stuff too.

https://medium.com/@jitbit/target-blank-the-most-underestimated-vulnerability-ever-96e328301f4c#.5dcfxcy6q
https://news.ycombinator.com/item?id=11631292

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions