Pattern: Use of insecure target="_blank"
Issue: -
This rule disallows using target="_blank"
attribute without rel="noopener noreferrer"
to avoid a security vulnerability(see here for more details).
<template>
<!-- ✓ Good -->
<a href="http://example.com" target="_blank" rel="noopener noreferrer">link</a>
<!-- ✗ BAD -->
<a href="http://example.com" target="_blank" >link</a>
</temlate>
{
"vue/no-template-target-blank": ["error", {
"allowReferrer": true,
"enforceDynamicLinks": "always"
}]
}
allowReferrer
... Iftrue
, does not require noreferrer.defaultfalse
enforceDynamicLinks ("always" | "never")
... Ifalways
, enforces the rule if the href is a dynamic link. defaultalways
.
<template>
<!-- ✓ Good -->
<a href="http://example.com" target="_blank" rel="noopener noreferrer">link</a>
<!-- ✗ BAD -->
<a href="http://example.com" target="_blank" rel="noopener">link</a>
</temlate>
<template>
<!-- ✓ Good -->
<a href="http://example.com" target="_blank" rel="noopener">link</a>
<!-- ✗ BAD -->
<a href="http://example.com" target="_blank" >link</a>
</temlate>
<template>
<!-- ✓ Good -->
<a :href="link" target="_blank" rel="noopener noreferrer">link</a>
<!-- ✗ BAD -->
<a :href="link" target="_blank">link</a>
</temlate>
<template>
<!-- ✓ Good -->
<a :href="link" target="_blank">link</a>
<!-- ✗ BAD -->
<a href="http://example.com" target="_blank" >link</a>
</temlate>