🔒 Fix reverse tabnabbing vulnerability in social.html - #50
Conversation
- Appends `noopener noreferrer` to the `rel` attribute of anchor tags with `target="_blank"` in `_includes/social.html` - Preserves the existing `me` rel value for identity/SEO purposes - Mitigates the risk of the newly opened tab maliciously controlling the referring page's `window.opener` object Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
🎯 What: Fixed a reverse tabnabbing vulnerability in
_includes/social.htmlby appendingnoopener noreferrerto therelattribute of social media anchor links that usetarget="_blank".noopener noreferrer, when a user clicked a social media link and it opened in a new tab, the newly opened page would have access to thewindow.openerobject. This object could have been used by a malicious page (or an untrusted script on the target page) to maliciously redirect the user's original referring tab, which is a reverse tabnabbing risk.🛡️ Solution: Added
noopener noreferrerto therelattribute of the affected anchor tags, safely preserving the originalrel="me". I also scanned the repository usinggrepfor other occurrences oftarget="_blank"and found_includes/share.html, but it already correctly includedrel="noopener noreferrer". Tests and site builds were confirmed to pass locally.PR created automatically by Jules for task 18147369036786890761 started by @hodovani