fix: add rel='noopener noreferrer' to external links - #729
Pranav-IIITM wants to merge 2 commits into
Conversation
Adds rel='noopener noreferrer' to all target='_blank' links across the site's layout partials to improve security and performance. Signed-off-by: Pranav-IIITM <jogdandpranav2007@gmail.com>
|
@zyyw @OrlinVasilev @AllForNothing Please review the PR !! |
There was a problem hiding this comment.
Pull request overview
This PR hardens the site’s Hugo partial templates by adding rel="noopener noreferrer" to anchors that open in a new tab (target="_blank"), mitigating reverse-tabnapping risk and addressing the security intent in issue #726.
Changes:
- Added
rel="noopener noreferrer"to social button links that open in a new tab. - Added
rel="noopener noreferrer"to external navbar/footer/docs/blog links that open in a new tab. - Updated docs/CLI sidebar and blog post link partials to include the
relattribute alongsidetarget="_blank".
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| layouts/partials/social-buttons.html | Adds rel="noopener noreferrer" to social links opened in a new tab. |
| layouts/partials/navbar.html | Adds rel to external menu items that use target="_blank". |
| layouts/partials/home/project.html | Adds rel to the community button link opened in a new tab. |
| layouts/partials/home/hero.html | Adds rel to the GitHub releases download link. |
| layouts/partials/footer.html | Adds rel to multiple external footer links opened in a new tab. |
| layouts/partials/docs/sidebar.html | Adds rel to source/issues sidebar buttons opened in a new tab. |
| layouts/partials/cli-docs/sidebar.html | Adds rel to source/issues sidebar buttons opened in a new tab. |
| layouts/partials/blog/posts.html | Adds rel to external blog links opened in a new tab. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Signed-off-by: Pranav-IIITM <jogdandpranav2007@gmail.com>
Head branch was pushed to by a user without write access
|
Hey @zyyw @AllForNothing — this just needs one more approval to clear the 2-reviewer requirement, checks are all green. Would appreciate a look when you get a chance |
Vad1mo
left a comment
There was a problem hiding this comment.
The render hook change in layouts/_default/_markup/render-link.html is the one that matters, since it covers every external link in markdown content. Three things before this can land:
- It no longer merges.
layouts/partials/footer.htmlwas rewritten in #727, so the Linux Foundation and Trademark Usage anchors this patches are gone from main. Needs a rebase. layouts/partials/home/project.html:51links to/community, which is internal. Addingrel="noopener noreferrer"there is wrong; the actual bug on that line is thetarget="_blank"on a same-site link, which should be dropped instead.- Use
rel="noopener"rather thannoopener noreferrer.noreferrerstrips the Referer on links to our own GitHub, Slack and status page and costs us referral attribution, without adding anything to the stated goal.
Worth noting for the description: noopener has been implied for target="_blank" in all current browsers since 2021, so this is hygiene rather than a live vulnerability.
Vad1mo
left a comment
There was a problem hiding this comment.
The render hook change in layouts/_default/_markup/render-link.html is the one that matters, since it covers every external link in markdown content. Three things before this can land:
- It no longer merges.
layouts/partials/footer.htmlwas rewritten in #727, so the Linux Foundation and Trademark Usage anchors this patches are gone from main. Needs a rebase. layouts/partials/home/project.html:51links to/community, which is internal. Addingrel="noopener noreferrer"there is wrong; the actual bug on that line is thetarget="_blank"on a same-site link, which should be dropped instead.- Use
rel="noopener"rather thannoopener noreferrer.noreferrerstrips the Referer on links to our own GitHub, Slack and status page and costs us referral attribution, without adding anything to the stated goal.
Worth noting for the description: noopener has been implied for target="_blank" in all current browsers since 2021, so this is hygiene rather than a live vulnerability.
Summary
All external links using
target="_blank"across the site's partials, shortcodes, and render hooks were missing therel="noopener noreferrer"attribute, exposing the site to reverse tabnapping attacks and minor performance issues. This PR fixes all affected files.Closes #726
Changes Made
Added
rel="noopener noreferrer"to alltarget="_blank"links in the following files:layouts/partials/social-buttons.html— GitHub, Twitter, Slack linkslayouts/partials/navbar.html— External top menu linkslayouts/partials/home/hero.html— Download releases buttonlayouts/partials/home/project.html— Community linklayouts/partials/footer.html— GitHub, Status Page, Logos, Slack, Twitter, CC-BY-4.0 License, The Linux Foundation, Trademark Usage linkslayouts/partials/docs/sidebar.html— GitHub source & issues linkslayouts/partials/cli-docs/sidebar.html— GitHub source & issues linkslayouts/partials/blog/posts.html— External blog linkslayouts/_default/_markup/render-link.html— Markdown render hook external linkslayouts/404.html— External menu links on 404 pagelayouts/shortcodes/community-info.html— Meeting notes, mailing list, YouTube linkslayouts/shortcodes/social.html— Distribution list linksBefore & After
Before
After
Why It Matters
window.openerand redirect the original page to a malicious URLnoreferrerstops the browser from sending theRefererheader, preventing the origin URL from leaking to external sitesnoopenerensures the new tab runs in a separate process, improving performance in some browsersReferences
Checklist
target="_blank"links now includerel="noopener noreferrer"