summaryrefslogtreecommitdiffstats
path: root/settings/templates/help.php
diff options
context:
space:
mode:
authorMarkus Staab <markus.staab@redaxo.de>2017-10-19 12:16:04 +0200
committerMarkus Staab <markus.staab@redaxo.de>2017-10-19 12:16:04 +0200
commitdb34b59238846e5ec046a456b4f76649321571d1 (patch)
tree3efe5a2c81888f6440c43ba6450998f6434ba7ea /settings/templates/help.php
parent8e25df9690a4d953721dcdc8e61038b332774a10 (diff)
downloadnextcloud-server-db34b59238846e5ec046a456b4f76649321571d1.tar.gz
nextcloud-server-db34b59238846e5ec046a456b4f76649321571d1.zip
Prevent XSS in links which open a new browser window
Diffstat (limited to 'settings/templates/help.php')
-rw-r--r--settings/templates/help.php8
1 files changed, 4 insertions, 4 deletions
diff --git a/settings/templates/help.php b/settings/templates/help.php
index f849ea0f427..3f042254f83 100644
--- a/settings/templates/help.php
+++ b/settings/templates/help.php
@@ -16,26 +16,26 @@
<?php } ?>
<li>
- <a href="https://docs.nextcloud.org" target="_blank" rel="noreferrer">
+ <a href="https://docs.nextcloud.org" target="_blank" rel="noreferrer noopener">
<?php p($l->t('Online documentation')); ?> ↗
</a>
</li>
<li>
- <a href="https://help.nextcloud.com" target="_blank" rel="noreferrer">
+ <a href="https://help.nextcloud.com" target="_blank" rel="noreferrer noopener">
<?php p($l->t('Forum')); ?> ↗
</a>
</li>
<?php if($_['admin']) { ?>
<li>
- <a href="https://nextcloud.com/support/" target="_blank" rel="noreferrer">
+ <a href="https://nextcloud.com/support/" target="_blank" rel="noreferrer noopener">
<?php p($l->t('Getting help')); ?> ↗
</a>
</li>
<?php } ?>
<li>
- <a href="https://nextcloud.com/enterprise/" target="_blank" rel="noreferrer">
+ <a href="https://nextcloud.com/enterprise/" target="_blank" rel="noreferrer noopener">
<?php p($l->t('Commercial support')); ?> ↗
</a>
</li>