TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: If target=“_blank” without rel=“noopener” is unsafe

1 点作者 JakeWesorick大约 5 年前
Ask HN: If links with target="_blank" without rel="noopener" are unsafe, why is "noopener" not just the default?

1 comment

Colegno大约 5 年前
Here is a link fyi : <a href="https:&#x2F;&#x2F;developers.google.com&#x2F;web&#x2F;tools&#x2F;lighthouse&#x2F;audits&#x2F;noopener" rel="nofollow">https:&#x2F;&#x2F;developers.google.com&#x2F;web&#x2F;tools&#x2F;lighthouse&#x2F;audits&#x2F;no...</a><p>Here is the rel attribute desc : <a href="https:&#x2F;&#x2F;developer.mozilla.org&#x2F;en-US&#x2F;docs&#x2F;Web&#x2F;HTML&#x2F;Attributes&#x2F;rel" rel="nofollow">https:&#x2F;&#x2F;developer.mozilla.org&#x2F;en-US&#x2F;docs&#x2F;Web&#x2F;HTML&#x2F;Attributes...</a> where you will find an explanation :<p>&quot;The rel attribute has no default value. If the attribute is omitted or if none of the values in the attribute are supported, then the document has no particular relationship with the destination resource other than there being a hyperlink between the two. In this case, on &lt;link&gt; and &lt;form&gt;, if the rel attribute is absent, has no keywords, or if not one or more of the space-separated keywords above, then the element does not create any links. &lt;a&gt; and &lt;area&gt; will still created links, but without a defined relationship.&quot;