2eb14fc0378432977d83366a3211c67f8913018d max Mon Sep 21 06:21:51 2026 -0700 hgc and hgTrackUi: open off-site links in a new tab, with rel="noopener noreferrer" offsiteLinksToNewTab() in utils.js runs over the rendered page alongside addHgsidToLinks() and gives every http(s) link whose host is not ours a target=_blank it does not already have, plus rel="noopener noreferrer". Without noopener the page that opens keeps a handle on the tab it came from and can navigate it; without noreferrer the Referer header carries our own URL, which has the session id in it. The href on a track description page is written by whoever wrote the track or the hub, so neither is theoretical. A mailto: or an ftp: link is left alone, and so is every link that stays on this server. jsAddHgsidToLinks() now emits both calls and is renamed jsFixUpPageLinks(). hgTracks.js runs the same pass over the track description popup: the replace it does before that already puts a target on every link in there, so what this adds is the rel on the ones that leave. refs #38380 diff --git src/hg/js/hgTracks.js src/hg/js/hgTracks.js index 6a99eec5e20..93dd575e16d 100644 --- src/hg/js/hgTracks.js +++ src/hg/js/hgTracks.js @@ -5755,32 +5755,35 @@ // make sure all links (e.g. help links) open up in a new window response = response.replace(/<a /ig, "<a target='_blank' "); var cleanHtml = response; cleanHtml = stripJsFiles(cleanHtml,false); // DEBUG msg with true cleanHtml = stripCssFiles(cleanHtml,false); // DEBUG msg with true //cleanHtml = stripJsEmbedded(cleanHtml,false);// DEBUG msg with true // OBSOLETE BY CSP2? var nonceJs = {}; cleanHtml = stripCSPAndNonceJs(cleanHtml, false, nonceJs); // DEBUG msg with true //alert(cleanHtml); // DEBUG REMOVE $('#hgTrackUiDialog').html("<div id='pop' style='font-size:.9em;'>"+ cleanHtml +"</div>"); // the description page inside carries no session id of its own, so add it to the - // links in it that stay on this server - addHgsidToLinks(document.getElementById('pop')); + // links in it that stay on this server, and put a rel on the ones that do not -- + // the replace above has already given every link in it a target + var popDiv = document.getElementById('pop'); + addHgsidToLinks(popDiv); + offsiteLinksToNewTab(popDiv); appendNonceJsToPage(nonceJs); // Strategy for popups with js: // - jsFiles and CSS should not be included in html. Here they are shluped out. // - The resulting files ought to be loadable dynamically (with getScript()), // but this was not working nicely with the modal dialog // Therefore include files must be included with hgTracks CGI ! // - embedded js should not be in the popup box. // - Somethings should be in a popup.ready() function, and this is emulated below, // as soon as the cleanHtml is added // Since there are many possible popup cfg dialogs, the ready should be all inclusive. if ( ! popUp.trackDescriptionOnly ) { // If subtrack then vis rules differ