diff --git a/demos/hooks-target-blank-demo.html b/demos/hooks-target-blank-demo.html index e565be61c..b87fd38a9 100644 --- a/demos/hooks-target-blank-demo.html +++ b/demos/hooks-target-blank-demo.html @@ -32,6 +32,8 @@ // set all elements owning target to target=_blank if ('target' in node) { node.setAttribute('target','_blank'); + // prevent https://www.owasp.org/index.php/Reverse_Tabnabbing + node.setAttribute('rel', 'noopener noreferrer'); } // set non-HTML/MathML links to xlink:show=new if (!node.hasAttribute('target')