Browse Source
While other targets could, potentially, represent legitimate issues for concern, opening a new window generally does not since that's typically a readily available option in the user agent anyway when choosing to follow any individual link. While using target="_blank" does not really represent any security issue, it may be an annoyance issue, but that's something for the author to address, not the sanitizer. Although rel="nofollow" is _not_ part of the HTML 4 standard, it may be very useful to avoid "endorsing" sites that are being linked to. Since it does not introduce any risk of scripting issues or other hidden issues, go ahead and allow it too. Signed-off-by: Kyle J. McKay <mackyle@gmail.com>master
Kyle J. McKay
4 years ago
1 changed files with 7 additions and 1 deletions
Loading…
Reference in new issue