Skip to content

Use rel="noopener" instead of rel="noopener noreferrer" on outbound links - #116

Merged
TomPohys merged 1 commit into
openmaptiles:masterfrom
maptiler:fix/rel-noopener
Sep 18, 2026
Merged

TomPohys merged 1 commit into
openmaptiles:masterfrom
maptiler:fix/rel-noopener

Conversation

@martyan

@martyan martyan commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Drops noreferrer from outbound links, keeps noopener.

noreferrer strips the Referer header, so outbound clicks arrive as "direct" traffic and can't be attributed. noopener is the part that matters for security and stays.

`rel="noopener noreferrer"` strips the Referer header on every outbound
link, so traffic this site sends to MapTiler properties arrives as direct
and cannot be attributed in MapTiler's reports.

`noopener` alone is what the security concern actually needs: it severs
`window.opener` on target="_blank" links. `noreferrer` adds nothing there
and only suppresses the referrer.

Replaced across the 15 files that carried it, including the three literals
in _plugins/doclinks.rb — that plugin rewrites every external link in
/docs/ pages at build time, so leaving it would keep noreferrer on all 105
generated doclink anchors regardless of the template changes.

@TomPohys TomPohys left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@TomPohys
TomPohys merged commit 2a0d45b into openmaptiles:master Sep 18, 2026
1 check passed
@TomPohys
TomPohys deleted the fix/rel-noopener branch September 18, 2026 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants