4 ms·
Note that by not setting rel="noopener noreferrer" on the links you let the linked sites control the opener window (and of course see a detailed referrer header
by daxterspeed 7y ago
Note that by not setting rel="noopener noreferrer" on the links you let the linked sites control the opener window (and of course see a detailed referrer header).
https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/ https://www.jitbit.com/alexblog/256-targetblank---the-most-u... (This applies to more than just target="_blank")
- yzmtf2008 7y agoIf the link is for users to click and like this page on Facebook, then Facebook will be able to know the source URL regardless, no?
- daxterspeed 7y agoWell if the referrer header matches the shared url it's just bloat in the request headers, and if it doesn't it's possibly leaking details it shouldn't, like perhaps a token in a query parameter. Twitter, Facebook, etc doesn't really need to know where a user initiated a share anyway. Either way making sure that window.opener isn't available to random sites is a critical security feature and in some browsers that require you to set noreferrer, so better safe than sorry.
- StavrosK 7y agoYou are correct, fixed, thank you. It's a shame this isn't the default on all links.
- _delirium 7y agoFor the case of opening in a new tab, consensus seems to be moving to making it default, though that's not true everywhere yet. It's currently default on Safari and Firefox. Closed (fixed) Firefox bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1503681 https://bugzilla.mozilla.org/show_bug.cgi?id=1503681 Open Chromium bug: https://bugs.chromium.org/p/chromium/issues/detail?id=898942 https://bugs.chromium.org/p/chromium/issues/detail?id=898942