[IMP] Prevent reverse tabnabbing in plaintext2html, linkify, _makeLink
These functions convert plain text links into clickable hyperlinks. These open in new tabs but did not have the "noreferrer noopener" rel attributes, which made them susceptible to reverse tabnabbing. A lot of attack vectors were available to unregistered, uninvited anonymous users and presented a significant phishing threat (such as posting links in the instant-chat, through a mail-alias, in a forum post or in a twitter post) and leading the operator to believe he had been disconnected from odoo in the original tab, prompting them to enter their credentials. while these three places will add the noreferrer and noopener attributes on the anchor tags generated by them, there are still many places that create hyperlinks without the use of these functions, although most of them are static links, they still represent a transitive security vulnerability to the linked sites. There are also a few modules and widgets that roll out their own links or open new tabs unsafely using window.open(), these will need to be patched separately. closes odoo/odoo#37591 Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
This commit is contained in:
@@ -33,6 +33,9 @@ function linkify(text, attrs) {
|
||||
if (attrs.target === undefined) {
|
||||
attrs.target = '_blank';
|
||||
}
|
||||
if (attrs.target === '_blank') {
|
||||
attrs.rel = 'noreferrer noopener';
|
||||
}
|
||||
attrs = _.map(attrs, function (value, key) {
|
||||
return key + '="' + _.escape(value) + '"';
|
||||
}).join(' ');
|
||||
|
||||
@@ -74,6 +74,7 @@ publicWidget.registry.twitter = publicWidget.Widget.extend({
|
||||
text: text,
|
||||
href: url,
|
||||
target: '_blank',
|
||||
rel: 'noreferrer noopener',
|
||||
});
|
||||
return c.prop('outerHTML');
|
||||
}
|
||||
|
||||
+1
-1
@@ -261,7 +261,7 @@ def html_keep_url(text):
|
||||
link_tags = re.compile(r"""(?<!["'])((ftp|http|https):\/\/(\w+:{0,1}\w*@)?([^\s<"']+)(:[0-9]+)?(\/|\/([^\s<"']))?)(?![^\s<"']*["']|[^\s<"']*</a>)""")
|
||||
for item in re.finditer(link_tags, text):
|
||||
final += text[idx:item.start()]
|
||||
final += '<a href="%s" target="_blank">%s</a>' % (item.group(0), item.group(0))
|
||||
final += '<a href="%s" target="_blank" rel="noreferrer noopener">%s</a>' % (item.group(0), item.group(0))
|
||||
idx = item.end()
|
||||
final += text[idx:]
|
||||
return final
|
||||
|
||||
Reference in New Issue
Block a user