feat: harden external reading links with rel="noopener noreferrer"
CI / Run tests (pull_request) Has been cancelled

All reading list links point at external http(s) URLs, so each rendered
anchor now carries rel="noopener noreferrer" as a hardening best
practice. Renderer test updated for the new attribute and asserts every
rendered link carries it.
This commit is contained in:
2026-08-25 15:15:31 +00:00
parent 5bd86f3f9b
commit fb62194d40
2 changed files with 12 additions and 2 deletions
+9 -1
View File
@@ -18,7 +18,7 @@ const indexHtml = readFileSync(join(root, "index.html"), "utf8");
const contactHtml = readFileSync(join(root, "contact.html"), "utf8");
const rendererSource = readFileSync(join(root, "js/reading-list.js"), "utf8");
const ANCHOR_RE = /<a class="reading-link" href="([^"]*)">([^<]*)<\/a>/g;
const ANCHOR_RE = /<a class="reading-link" href="([^"]*)"[^>]*>([^<]*)<\/a>/g;
const ENTRY_LI_RE = /<li class="reading-entry">/g;
const SECTION_RE = /<section class="reading-category"/g;
@@ -152,6 +152,14 @@ test("each rendered link has a valid href and shows its title, with the note sho
);
}
// All reading links point at external sites, so each carries the
// rel="noopener noreferrer" hardening attribute.
assert.equal(
(html.match(/rel="noopener noreferrer"/g) || []).length,
anchors.length,
"every rendered link carries rel=\"noopener noreferrer\""
);
assert.ok(html.includes("One line of context."), "note is rendered when present");
assert.equal(
(html.match(/<p class="reading-note">/g) || []).length,