mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 10:58:17 -05:00
[PR #24204] fix(security): add rel=noopener noreferrer to all target=_blank links #50549
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/24204
Author: @akinshaywai
Created: 4/28/2026
Status: 🔄 Open
Base:
dev← Head:fix/a11y-external-links-rel📝 Commits (10+)
fe6783cMerge pull request #19030 from open-webui/devfc05e0aMerge pull request #19405 from open-webui/deve3faec6Merge pull request #19416 from open-webui/dev9899293Merge pull request #19448 from open-webui/dev140605eMerge pull request #19462 from open-webui/dev6f1486fMerge pull request #19466 from open-webui/devd95f533Merge pull request #19729 from open-webui/deva7271530.6.43 (#20093)6adde20Merge pull request #20394 from open-webui/devf9b0534Merge pull request #20522 from open-webui/dev📊 Changes
4 files changed (+16 additions, -11 deletions)
View changed files
📝
src/lib/components/chat/Settings/About.svelte(+9 -7)📝
src/lib/components/chat/Settings/Integrations.svelte(+4 -2)📝
src/lib/components/chat/ShareChatModal.svelte(+1 -1)📝
src/lib/components/chat/ToolServersModal.svelte(+2 -1)📄 Description
Summary
External links opened with
target="_blank"expose the current page to reverse tabnapping — the opened tab can accesswindow.openerand redirect the parent page.rel="noopener noreferrer"prevents this by nullifyingwindow.openerand stripping theRefererheader.Added
rel="noopener noreferrer"to all affectedtarget="_blank"links across four components:ShareChatModal.svelteToolServersModal.svelteSettings/About.svelteSettings/Integrations.svelteChanges
src/lib/components/chat/ShareChatModal.sveltesrc/lib/components/chat/ToolServersModal.sveltesrc/lib/components/chat/Settings/About.sveltesrc/lib/components/chat/Settings/Integrations.svelteTest plan
window.openeris null in the opened tab (DevTools console:window.opener)🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.