diff options
author | Lukas Reschke <lukas@statuscode.ch> | 2017-11-08 18:55:35 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2017-11-08 18:55:35 +0100 |
commit | 8c915baa3438c26454b7614ea03d4dadabcda5d5 (patch) | |
tree | 9b800f157cae8c4cd841fdf8e757c3779300224d /apps/files/templates/appnavigation.php | |
parent | d948626736e65051dfe1affc562710bfedf2eb4a (diff) | |
parent | db34b59238846e5ec046a456b4f76649321571d1 (diff) | |
download | nextcloud-server-8c915baa3438c26454b7614ea03d4dadabcda5d5.tar.gz nextcloud-server-8c915baa3438c26454b7614ea03d4dadabcda5d5.zip |
Merge pull request #6788 from staabm/master
Prevent XSS in links which open a new browser window
Diffstat (limited to 'apps/files/templates/appnavigation.php')
-rw-r--r-- | apps/files/templates/appnavigation.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/apps/files/templates/appnavigation.php b/apps/files/templates/appnavigation.php index 8326fad73ea..955cd03a019 100644 --- a/apps/files/templates/appnavigation.php +++ b/apps/files/templates/appnavigation.php @@ -42,7 +42,7 @@ </div> <label for="webdavurl"><?php p($l->t('WebDAV'));?></label> <input id="webdavurl" type="text" readonly="readonly" value="<?php p(\OCP\Util::linkToRemote('webdav')); ?>" /> - <em><?php print_unescaped($l->t('Use this address to <a href="%s" target="_blank" rel="noreferrer">access your Files via WebDAV</a>', array(link_to_docs('user-webdav'))));?></em> + <em><?php print_unescaped($l->t('Use this address to <a href="%s" target="_blank" rel="noreferrer noopener">access your Files via WebDAV</a>', array(link_to_docs('user-webdav'))));?></em> </div> </div> </div> |