Protect external links

This commit is contained in:
Andrés Moya 2021-09-29 11:41:29 +02:00
parent 9e5166d991
commit fe4cab3a9e

View file

@ -399,7 +399,9 @@
([uri] ([uri]
(open-new-window uri "_blank")) (open-new-window uri "_blank"))
([uri name] ([uri name]
(js/window.open (str uri) name))) ;; Warning: need to protect against reverse tabnabbing attack
;; https://www.comparitech.com/blog/information-security/reverse-tabnabbing/
(.open js/window (str uri) name "noopener,noreferrer")))
(defn browser-back (defn browser-back
[] []