Bug #89757

Fix noopener noreferrer issue

Added by Benni Mack about 2 months ago. Updated 27 days ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
Miscellaneous
Start date:
2019-11-23
Due date:
% Done:

100%

TYPO3 Version:
10
PHP Version:
Tags:
Complexity:
Is Regression:
Yes
Sprint Focus:

Description

Recent merges did not consider what the actual properties do, so only "noreferrer" is needed.

See
https://www.w3.org/TR/2011/WD-html5-20110113/links.html#link-type-noreferrer
https://web.dev/external-anchors-use-rel-noopener/


Related issues

Related to TYPO3 Core - Feature #78488: Add rel="noopener noreferrer" to links when target is set to _blank Closed 2016-10-28
Related to TYPO3 Core - Bug #89044: Links in the TYPO3 backend and install tool should have set rel="noopener noreferrer" for external links Closed 2019-08-29
Related to TYPO3 Core - Bug #89771: rel="noreferer" should be set for all new windows, not just _blank Resolved 2019-11-25

Associated revisions

Revision 4351529f (diff)
Added by Benni Mack about 2 months ago

[BUGFIX] Use "noreferrer" instead of "noopener noreferrer"

Various patches introduced a feature to not send the referer
nor the opener information to external links.

However, just because others CMS do it this way,
one should carefully consider WHAT THESE THINGS DO.

So, adding "noreferrer" implicitly includes "noopener".
What this means is that we can save a lot of bytes, save the
environment by producing less bytes and sending them over the wire.

References:
- https://www.w3.org/TR/2011/WD-html5-20110113/links.html#link-type-noreferrer
- https://web.dev/external-anchors-use-rel-noopener/
- https://html.spec.whatwg.org/multipage/links.html#link-type-noreferrer

Relates: #78488
Relates: #89044
Resolves: #89757
Releases: master
Change-Id: Ia366169cd30da23f988bae04175fdaa18be418b2
Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/62421
Tested-by: Daniel Goerz <>
Tested-by: TYPO3com <>
Tested-by: Susanne Moog <>
Reviewed-by: Daniel Goerz <>
Reviewed-by: Susanne Moog <>

History

#1 Updated by Gerrit Code Review about 2 months ago

  • Status changed from New to Under Review

Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/62421

#2 Updated by Gerrit Code Review about 2 months ago

Patch set 2 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/62421

#3 Updated by Daniel Goerz about 2 months ago

  • Related to Feature #78488: Add rel="noopener noreferrer" to links when target is set to _blank added

#4 Updated by Daniel Goerz about 2 months ago

  • Related to Bug #89044: Links in the TYPO3 backend and install tool should have set rel="noopener noreferrer" for external links added

#5 Updated by Gerrit Code Review about 2 months ago

Patch set 3 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/62421

#6 Updated by Benni Mack about 2 months ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100

#7 Updated by Jonas Eberle about 2 months ago

  • Related to Bug #89771: rel="noreferer" should be set for all new windows, not just _blank added

#8 Updated by Benni Mack 27 days ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF