feat: harden external reading links with rel="noopener noreferrer"
CI / Run tests (pull_request) Has been cancelled
CI / Run tests (pull_request) Has been cancelled
All reading list links point at external http(s) URLs, so each rendered anchor now carries rel="noopener noreferrer" as a hardening best practice. Renderer test updated for the new attribute and asserts every rendered link carries it.
This commit is contained in:
+3
-1
@@ -64,9 +64,11 @@ function renderEntry(entry) {
|
||||
const note = entry.note
|
||||
? `<p class="reading-note">${escapeHtml(entry.note)}</p>`
|
||||
: "";
|
||||
// Every reading link points at an external http(s) URL (isValidUrl), so it
|
||||
// carries rel="noopener noreferrer" as a hardening best practice.
|
||||
return (
|
||||
`<li class="reading-entry">` +
|
||||
`<a class="reading-link" href="${escapeHtml(entry.url)}">${escapeHtml(entry.title)}</a>` +
|
||||
`<a class="reading-link" href="${escapeHtml(entry.url)}" rel="noopener noreferrer">${escapeHtml(entry.title)}</a>` +
|
||||
note +
|
||||
`</li>`
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user