When should I use rel=noreferrer?

前端 未结 4 505
长情又很酷
长情又很酷 2021-01-02 15:40

I have to link some other external sites.

I know when to use nofollow. But I am not clear when I should use rel=noreferrer.

4条回答
  •  我在风中等你
    2021-01-02 16:27

    noreferrer doesn't just block the HTTP referrer header, it also prevents a Javascript exploit involving window.opener

    Link
    Looks innocuous enough, but there's a hole because, by default, the page that's being opened is allowing the opened page to call back into it via window.opener. There are some restrictions, being cross-domain, but there's still some mischief that can be done
    window.opener.location = 'http://gotcha.badstuff';

    With noreferrer most browsers will disallow the window.opener exploit

提交回复
热议问题