mirror of
https://we.phorge.it/source/phorge.git
synced 2024-11-28 01:32:42 +01:00
05a4c55c52
Summary: See D19117. Instead of automatically figuring this out inside `phutil_tag()`, explicitly add rel="noreferrer" at the application level to all external links. Test Plan: - Grepped for `_blank`, `isValidRemoteURIForLink`, checked all callsites for user-controlled data. - Created a link menu item, verified noreferrer in markup. - Created a link custom field, verified no referrer in markup. - Verified noreferrer for `{nav href=...}`. Subscribers: PHID-OPKG-gm6ozazyms6q6i22gyam Differential Revision: https://secure.phabricator.com/D19118 |
||
---|---|---|
.. | ||
PhabricatorApplicationProfileMenuItem.php | ||
PhabricatorConpherenceProfileMenuItem.php | ||
PhabricatorDashboardProfileMenuItem.php | ||
PhabricatorDividerProfileMenuItem.php | ||
PhabricatorEditEngineProfileMenuItem.php | ||
PhabricatorLabelProfileMenuItem.php | ||
PhabricatorLinkProfileMenuItem.php | ||
PhabricatorManageProfileMenuItem.php | ||
PhabricatorMotivatorProfileMenuItem.php | ||
PhabricatorProfileMenuItem.php | ||
PhabricatorProfileMenuItemIconSet.php | ||
PhabricatorProjectProfileMenuItem.php |