target="_blank"站内链接是否需添加rel="noopener"属性?
Great question—it’s easy to assume internal links are "safe" and skip security attributes, but let’s break down why you still should add rel="noopener" here.
First, a quick recap: rel="noopener" cuts off the new window’s access to the original page’s window.opener object. Without it, any page opened via target="_blank" (even your own) can use window.opener to manipulate the original page—think redirecting it to a malicious site, modifying DOM content, or stealing sensitive data if your page has active user sessions.
You might be thinking, "But it’s my own website—all pages are trusted!" Even so, there are solid reasons to add it:
- XSS vulnerability risk: If any internal page ever gets hit with a cross-site scripting attack (accidentally or via a compromised plugin/script), that malicious code could leverage
window.openerto take over the original page the user came from. - Performance boost: Modern browsers use
noopenerto spin up the new window in a separate process, so any slowdown or crash in the new page won’t affect the original one.
To make it concrete, here’s how to update your example:
Original code:
<a href="internal/link/in/my/website" target="_blank">ClickMe</a>
Recommended safe version:
<a href="internal/link/in/my/website" target="_blank" rel="noopener">ClickMe</a>
If you also want to hide the referrer from the internal page (though not strictly necessary for security), you can use rel="noopener noreferrer" instead—but noopener is the key security-focused attribute here.
In short: Yes, you should add rel="noopener" to every target="_blank" link, regardless of whether it points to your own site or an external one. It’s a simple, low-effort way to lock down security and improve performance.
内容的提问来源于stack exchange,提问作者user10905710

