diff options
author | Lukas Reschke <lukas@statuscode.ch> | 2017-11-08 18:55:35 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2017-11-08 18:55:35 +0100 |
commit | 8c915baa3438c26454b7614ea03d4dadabcda5d5 (patch) | |
tree | 9b800f157cae8c4cd841fdf8e757c3779300224d /apps/user_ldap | |
parent | d948626736e65051dfe1affc562710bfedf2eb4a (diff) | |
parent | db34b59238846e5ec046a456b4f76649321571d1 (diff) | |
download | nextcloud-server-8c915baa3438c26454b7614ea03d4dadabcda5d5.tar.gz nextcloud-server-8c915baa3438c26454b7614ea03d4dadabcda5d5.zip |
Merge pull request #6788 from staabm/master
Prevent XSS in links which open a new browser window
Diffstat (limited to 'apps/user_ldap')
-rw-r--r-- | apps/user_ldap/templates/part.settingcontrols.php | 2 | ||||
-rw-r--r-- | apps/user_ldap/templates/part.wizardcontrols.php | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/apps/user_ldap/templates/part.settingcontrols.php b/apps/user_ldap/templates/part.settingcontrols.php index 3f7a53dd4dc..a418885f47e 100644 --- a/apps/user_ldap/templates/part.settingcontrols.php +++ b/apps/user_ldap/templates/part.settingcontrols.php @@ -3,7 +3,7 @@ <?php p($l->t('Test Configuration'));?> </button> <a href="<?php p(link_to_docs('admin-ldap')); ?>" - target="_blank" rel="noreferrer"> + target="_blank" rel="noreferrer noopener"> <img src="<?php print_unescaped(image_path('', 'actions/info.svg')); ?>" style="height:1.75ex" /> <?php p($l->t('Help'));?> diff --git a/apps/user_ldap/templates/part.wizardcontrols.php b/apps/user_ldap/templates/part.wizardcontrols.php index 2df1fd8d83f..89eb96827e6 100644 --- a/apps/user_ldap/templates/part.wizardcontrols.php +++ b/apps/user_ldap/templates/part.wizardcontrols.php @@ -9,7 +9,7 @@ <?php p($l->t('Continue'));?> </button> <a href="<?php p(link_to_docs('admin-ldap')); ?>" - target="_blank" rel="noreferrer"> + target="_blank" rel="noreferrer noopener"> <img src="<?php print_unescaped(image_path('', 'actions/info.svg')); ?>" style="height:1.75ex" /> <span class="ldap_grey"><?php p($l->t('Help'));?></span> |