Skip to content

Conversation

@JVickery-TBS
Copy link

As described in the VA scan, all _blank targets should have rel="noopener norefferer" even if they are https and/or on the same domain.

- Added `noopener noreferrer` to all anchors with `_blank` targets.
- Added change log file.
Copy link
Member

@wardi wardi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changes some translated strings, make sure to update the translations too or we might be missing some fr versions of the text on our site (do we override these in our theme?)

@JVickery-TBS
Copy link
Author

Ah good point, and no overriding of these things. Just putting into our plugin strings.py cuz I don't like dealing with changing the PO files in the CKAN fork.

@JVickery-TBS
Copy link
Author

I lied, it might be easier to just compile the catalog in here. hmmm and then merging stuff from upstream we can always just re-extract and re-compile. Should not be a big problem.

- Build and unfuzzy FR strings.
@JVickery-TBS JVickery-TBS merged commit 5eebc54 into canada-v2.10 Aug 19, 2025
1 check passed
@JVickery-TBS JVickery-TBS deleted the fix/unsafe-blank-targets branch August 19, 2025 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants