Khoros Atlas Logo

Highlighted
Honored Contributor
Honored Contributor

Removing noreferrer

Jump to solution

I've had a request from our web team SEO guy to have the noreferrer attribute removed from our community so he can get accurate referrer data in our corporate site Google Analytics account for links coming from our community.

I understand from reading (I'm far from an expert) that noreferrer is in place to prevent malicious links from taking the control over a newly opened tab.  Good thing.   

Because it's a security issue, I'm hesitant to have it removed from our community, but I undersand the benefit of seeing links from the community to our company web site.   What are your thoughts / suggestions / ideas on the issue? 

I *assume* I would have to open a support incident to have it removed as I can't find a setting for it in studio.  (??)

Thanks in advance for your input. 

--
Community manager in the Micro Focus Community. My computer always used to beat me at chess, but it is no match for me now I changed the competition to kick boxing.
Tags (1)
0 Kudos
4 Replies 4
Honored Contributor
Honored Contributor

Re: Removing noreferrer

Jump to solution

Nobody?   Here's what I see.

  • Adding an external URL and telling it to open in a new window:
    • target="_blank" rel="noopener nofollow noopener noreferrer" gets added to the link.  (why two noopner attributes?)
  • Adding an external URL and telling it to open in the same window:
    • target="_selfrel="nofollow noopener noreferrer" gets added to the URL
  • Adding an internal URL and telling it to open in a new window:
    • target="_blankrel="noopener" gets added to the link
  • Adding an internal URL and telling it to open in the same window:
    • target="_self" with no rel attributes gets added

I would really like to get rid of the noreferrer attribute for external links.  Anyone?

--
Community manager in the Micro Focus Community. My computer always used to beat me at chess, but it is no match for me now I changed the competition to kick boxing.
0 Kudos
Reply
Loading...
Khoros Staff RohitS
Khoros Staff

Re: Removing noreferrer

Jump to solution

The noreferer attribute was added to our community to fix the Tab Nabbing vulnerability as you mentioned it is a big security issue. 

Secondly, as far as I know, it can be removed for user-generated links and not for system generated links. Turning this off would be a major security concern. 

Please find the following link posted by one of our customers. 

https://community.khoros.com/t5/Li-Product-Ideas/Add-quot-noreferrer-nofollow-quot-to-the-quot-rel-q...

Reply
Loading...
Honored Contributor
Honored Contributor

Re: Removing noreferrer

Jump to solution

Hi Rohit,

FYI... I had some trouble with the link you provided, but when I removed some parameters from the end, it worked. Here's the link that works for me: https://community.khoros.com/t5/Li-Product-Ideas/Add-quot-noreferrer-nofollow-quot-to-the-quot-rel-q...

Cheers!

----
Caroline Sekar | Community Manager @ Cisco Meraki | @merakicaroline
Reply
Loading...
Khoros Staff RohitS
Khoros Staff

Re: Removing noreferrer

Jump to solution

Hi Caroline,


Thank you for bringing it to my notice. I've modified the link in my solution.

Rohit

Reply
Loading...