From 26a3823d86f4b6def846d316ec8fab2bd91754b3 Mon Sep 17 00:00:00 2001 From: Ben McCann <322311+benmccann@users.noreply.github.com> Date: Wed, 3 Jan 2024 14:14:27 -0800 Subject: [PATCH] docs: clarify docs for `svelte/no-target-blank` (#656) --- docs/rules/no-target-blank.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/rules/no-target-blank.md b/docs/rules/no-target-blank.md index 401124a2e..836a4381f 100644 --- a/docs/rules/no-target-blank.md +++ b/docs/rules/no-target-blank.md @@ -12,7 +12,7 @@ since: 'v0.0.4' ## :book: Rule Details -This rule disallows using `target="_blank"` attribute without `rel="noopener noreferrer"` to avoid a security vulnerability([see here for more details](https://mathiasbynens.github.io/rel-noopener/)). +This rule disallows using `target="_blank"` attribute without `rel="noopener noreferrer"` to avoid a security vulnerability in legacy browsers where a page can trigger a navigation in the opener regardless of origin ([see here for more details](https://mathiasbynens.github.io/rel-noopener/)). @@ -46,8 +46,8 @@ This rule disallows using `target="_blank"` attribute without `rel="noopener nor } ``` -- `allowReferrer` ... If `true`, does not require noreferrer.default `false` -- `enforceDynamicLinks ("always" | "never")` ... If `always`, enforces the rule if the href is a dynamic link. default `always`. +- `allowReferrer` ... If `true`, allows the `Referrer` header to be sent by not requiring `noreferrer` to be present. default `false` +- `enforceDynamicLinks ("always" | "never")` ... If `always`, enforces the rule if the href is a dynamic link. default `always` ### `{ allowReferrer: false }` (default)