Skip to content

Commit 56ac8ca

Browse files
committed
Security: Add attribute rel="noopener noreferrer" to links with target=_blank to reduce probability of tabnabbing - refs BT#21289
1 parent b3afaf6 commit 56ac8ca

7 files changed

+11
-11
lines changed

Diff for: documentation/changelog.html

+1-1
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,7 @@ <h1>Chamilo&nbsp;Changelog</h1>
9898
<p><i>Note: Some #wxyz references are issue numbers you can either find
9999
<a href="https://github.com/chamilo/chamilo-lms/issues">on Github</a> or (for very old ones) on
100100
<a href="https://support.chamilo.org/projects/chamilo-18/issues"
101-
target="_blank">our previous public bug tracking system (in which case
101+
target="_blank" rel="noopener noreferrer">our previous public bug tracking system (in which case
102102
they will be prefixed by the marker "CT")</a>.
103103
<br />
104104
Some references marked BT#xyz are developments made externally for BeezNest

Diff for: documentation/credits.html

+1-1
Original file line numberDiff line numberDiff line change
@@ -764,7 +764,7 @@ <h1>Deprecated developments</h1>
764764
<a id="association"></a>
765765
<h1>The Chamilo Association</h1>
766766
The Chamilo Association is very present inside the organizational structure of the Chamilo community, yet it tries to avoid interfering in the development of the software. It acts as a neutral organization supporting the development of the Chamilo software, and improving its popularity.
767-
To know more about the Chamilo Association and how to get involve, <a href="https://www.chamilo.org/en/association" target="_blank">&gt; start by reading its presentation &lt;</a>
767+
To know more about the Chamilo Association and how to get involve, <a href="https://www.chamilo.org/en/association" target="_blank" rel="noopener noreferrer">&gt; start by reading its presentation &lt;</a>
768768
</div>
769769

770770
<hr />

Diff for: documentation/installation_guide.html

+2-2
Original file line numberDiff line numberDiff line change
@@ -571,10 +571,10 @@ <h3>LDAP import into sessions</h3>
571571
<h2><a id="9._WIRIS_mathematical_formulas"></a>7. Mathematical formulas with WIRIS MathType</h2>
572572
<p>Installing this plugin you get WIRIS MathType. <br/>
573573
This activation will not be completed unless you have previously downloaded
574-
the <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank">PHP plugin for CKeditor WIRIS</a>
574+
the <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank" rel="noopener noreferrer">PHP plugin for CKeditor WIRIS</a>
575575
and unzipped its contents into the main/inc/lib/ckeditor/editor/plugins/ckeditor_wiris/ directory.<br/><br />
576576
This is necessary because Wiris is proprietary software and its services are
577-
<a href="https://www.wiris.com/store/who-pays" target="_blank">commercial</a>.
577+
<a href="https://www.wiris.com/store/who-pays" target="_blank" rel="noopener noreferrer">commercial</a>.
578578
To make adjustments to the plugin, edit configuration.ini file or replace his content by
579579
configuration.ini.default Chamilo file.</p>
580580

Diff for: documentation/installation_guide_es_ES.html

+2-2
Original file line numberDiff line numberDiff line change
@@ -674,8 +674,8 @@ <h3>Importar LDAP en sesiones</h3>
674674
<h2><a id="9._WIRIS_mathematical_formulas"></a>7. Fórmulas matemáticas con Wiris MathType</h2>
675675
<p>
676676
Instalando este plugin obtendrá Wiris MathType.<br />
677-
La activación no se realiza completamente si previamente no ha descargado el <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank">plugin PHP para CKeditor de WIRIS</a> y descomprimido su contenido en el directorio de Chamilo /main/inc/lib/javascript/ckeditor/plugins/ckeditor_wiris.<br /><br />
678-
Esto es necesario debido a que WIRIS es un software propietario y los servicios de WIRIS son <a href="https://www.wiris.com/store/who-pays" target="_blank">comerciales</a>. Para realizar ajustes en el plugin edite el archivo configuration.ini o sustituya su contenido por el de configuration.ini.default que acompaña a Chamilo.
677+
La activación no se realiza completamente si previamente no ha descargado el <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank" rel="noopener noreferrer">plugin PHP para CKeditor de WIRIS</a> y descomprimido su contenido en el directorio de Chamilo /main/inc/lib/javascript/ckeditor/plugins/ckeditor_wiris.<br /><br />
678+
Esto es necesario debido a que WIRIS es un software propietario y los servicios de WIRIS son <a href="https://www.wiris.com/store/who-pays" target="_blank" rel="noopener noreferrer">comerciales</a>. Para realizar ajustes en el plugin edite el archivo configuration.ini o sustituya su contenido por el de configuration.ini.default que acompaña a Chamilo.
679679
</p>
680680
<hr style="width: 100%; height: 2px;" />
681681

Diff for: documentation/installation_guide_fr_FR.html

+2-2
Original file line numberDiff line numberDiff line change
@@ -634,8 +634,8 @@ <h3>LDAP import into sessions</h3>
634634
<h2><a id="9._WIRIS_mathematical_formulas"></a>7. Formules mathématiques avec Wiris MathType</h2>
635635
<p>
636636
En installant ce plugin, vous intégrez Wiris MathType.<br />
637-
Cette activation ne sera pas complète à moins que vous n'ayez d'abord téléchargé le plugin <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank">PHP pour CKeditor WIRIS</a> et l'ayez décompressé dans main/inc/lib/javascript/ckeditor/plugins/ckeditor_wiris.<br /><br />
638-
Cette étape est nécessaire parce que WIRIS est un logiciel propriétaire et ses services sont de type <a href="https://www.wiris.com/store/who-pays" target="_blank">commerciaux</a>. Pour faire des modifications au plugin , éditez le fichier configuration.ini ou remplacez son contenu par le fichier configuration.ini.default de Chamilo.
637+
Cette activation ne sera pas complète à moins que vous n'ayez d'abord téléchargé le plugin <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank" rel="noopener noreferrer">PHP pour CKeditor WIRIS</a> et l'ayez décompressé dans main/inc/lib/javascript/ckeditor/plugins/ckeditor_wiris.<br /><br />
638+
Cette étape est nécessaire parce que WIRIS est un logiciel propriétaire et ses services sont de type <a href="https://www.wiris.com/store/who-pays" target="_blank" rel="noopener noreferrer">commerciaux</a>. Pour faire des modifications au plugin , éditez le fichier configuration.ini ou remplacez son contenu par le fichier configuration.ini.default de Chamilo.
639639

640640
</p>
641641
<hr style="width: 100%; height: 2px;" />

Diff for: documentation/installation_guide_it_IT.html

+2-2
Original file line numberDiff line numberDiff line change
@@ -495,10 +495,10 @@ <h1>Guida di installazione di Chamilo LMS 1.9</h1>
495495
<li class="li6"><span class="s1">9. Formule matematiche con Wiris MathType</span></li>
496496
</ol>
497497
<p>
498-
Installare il plugin <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank">PHP plugin for CKeditor WIRIS</a>, decompattarlo nella cartella /main/inc/lib/javascript/ckeditor/plugins/ckeditor_wiris.
498+
Installare il plugin <a href="https://www.wiris.com/plugins/ckeditor/download" target="_blank" rel="noopener noreferrer">PHP plugin for CKeditor WIRIS</a>, decompattarlo nella cartella /main/inc/lib/javascript/ckeditor/plugins/ckeditor_wiris.
499499
A seguito dell’installazione si ottiene un editor Wiris MathType.
500500
Si segnala che WIRIS è un software proprietario ed i suoi servizi sono servizi
501-
<a href="https://www.wiris.com/store/who-pays" target="_blank">commerciali</a>.
501+
<a href="https://www.wiris.com/store/who-pays" target="_blank" rel="noopener noreferrer">commerciali</a>.
502502
Per qualsiasi modifica o configurazione ulteriore del plugin modificare il file configuration.ini o sostituirlo con il file configuration.ini di default di Chamilo.
503503

504504
</p>

Diff for: documentation/security.html

+1-1
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ <h2><a id="3.Using-safe-browsers"></a>3. Using safe browsers</h2>
5656
security of your computer and the data it contains, but you can also put others in danger by letting crackers take
5757
control of it and attacking others.</p>
5858
<p>To avoid being a risk to yourself and others, you should download and install a recent browser. We recommend
59-
<a href="https://www.getfirefox.com" target="_blank">the latest stable version of Firefox</a>.</p>
59+
<a href="https://www.getfirefox.com" target="_blank" rel="noopener noreferrer">the latest stable version of Firefox</a>.</p>
6060

6161
<h2><a id="4.Moving-config-file"></a>4. Moving your configuration file out of the web directory</h2>
6262
<p>It is considered unsafe to leave the configuration file inside the app/config/ directory, as it will be directly

0 commit comments

Comments
 (0)