feat: harden external reading links with rel="noopener noreferrer"
CI / Run tests (pull_request) Has been cancelled

All reading list links point at external http(s) URLs, so each rendered
anchor now carries rel="noopener noreferrer" as a hardening best
practice. Renderer test updated for the new attribute and asserts every
rendered link carries it.
This commit is contained in:
2026-08-25 15:15:31 +00:00
parent 5bd86f3f9b
commit fb62194d40
2 changed files with 12 additions and 2 deletions
+3 -1
View File
@@ -64,9 +64,11 @@ function renderEntry(entry) {
const note = entry.note
? `<p class="reading-note">${escapeHtml(entry.note)}</p>`
: "";
// Every reading link points at an external http(s) URL (isValidUrl), so it
// carries rel="noopener noreferrer" as a hardening best practice.
return (
`<li class="reading-entry">` +
`<a class="reading-link" href="${escapeHtml(entry.url)}">${escapeHtml(entry.title)}</a>` +
`<a class="reading-link" href="${escapeHtml(entry.url)}" rel="noopener noreferrer">${escapeHtml(entry.title)}</a>` +
note +
`</li>`
);