diff --git a/modules/ui/view_on_keepRight.js b/modules/ui/view_on_keepRight.js index 1a33b7d9a..d8595b853 100644 --- a/modules/ui/view_on_keepRight.js +++ b/modules/ui/view_on_keepRight.js @@ -24,7 +24,8 @@ export function uiViewOnKeepRight() { .append('a') .attr('class', 'view-on-keepRight') .attr('target', '_blank') - .attr('href', function(d) { return d; }) + .attr('rel', 'noopener') // security measure + .attr('href', d => d) .call(svgIcon('#iD-icon-out-link', 'inline')); linkEnter diff --git a/modules/ui/view_on_osmose.js b/modules/ui/view_on_osmose.js index 578d7d7a6..a487937f8 100644 --- a/modules/ui/view_on_osmose.js +++ b/modules/ui/view_on_osmose.js @@ -24,6 +24,7 @@ export function uiViewOnOsmose() { .append('a') .attr('class', 'view-on-osmose') .attr('target', '_blank') + .attr('rel', 'noopener') // security measure .attr('href', d => d) .call(svgIcon('#iD-icon-out-link', 'inline'));