Skip to content

fix: add better security tags to links for opening in separate tabs#2989

Open
sammdec wants to merge 1 commit into
mainfrom
fix/aav-15-untrusted-ipfs-content-rendering-on-trusted-domain
Open

fix: add better security tags to links for opening in separate tabs#2989
sammdec wants to merge 1 commit into
mainfrom
fix/aav-15-untrusted-ipfs-content-rendering-on-trusted-domain

Conversation

@sammdec
Copy link
Copy Markdown
Contributor

@sammdec sammdec commented May 21, 2026

Summary

  • Add target="_blank" and rel="noopener noreferrer" to markdown-rendered <a> tags in ProposalOverview, so external links in proposal descriptions (including untrusted IPFS content rendered by /governance/ipfs-preview) open in a new tab and cannot access window.opener.

Linear: AAV-15

Test plan

  • Open a proposal on /governance/v3/proposal/... with markdown links in the description — links open in a new tab.
  • Inspect a rendered link's DOM and confirm target="_blank" and rel="noopener noreferrer".
  • Visit /governance/ipfs-preview?ipfsHash=<valid hash> and confirm description links also carry the safety attributes.

@odin-mjolnir
Copy link
Copy Markdown

odin-mjolnir Bot commented May 21, 2026

Linked Findings

AAV-15 Untrusted IPFS Content Rendering on Trusted Domain
Severity Medium
Status Mitigating
Discovered 15 May 2026

View in Odin

@sammdec sammdec requested a review from JoaquinBattilana May 21, 2026 12:36
@vercel
Copy link
Copy Markdown

vercel Bot commented May 21, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
interface Ready Ready Preview, Comment May 21, 2026 12:38pm

Request Review

@github-actions
Copy link
Copy Markdown

@github-actions
Copy link
Copy Markdown

📦 Next.js Bundle Analysis for aave-ui

This analysis was generated by the Next.js Bundle Analysis action. 🤖

⚠️ Global Bundle Size Increased

Page Size (compressed)
global 1.15 MB (🟡 +77 B)
Details

The global bundle is the javascript bundle that loads alongside every page. It is in its own category because its impact is much higher - an increase to its size means that every page on your website loads slower, and a decrease means every page loads faster.

Any third party scripts you have added directly to your app using the <script> tag are not accounted for in this analysis

If you want further insight into what is behind the changes, give @next/bundle-analyzer a try!

Two Pages Changed Size

The following pages changed size from the code in this PR compared to its base branch:

Page Size (compressed) First Load
/governance/ipfs-preview 102.05 KB (🟡 +9 B) 1.25 MB
/governance/v3/proposal 125.56 KB (🟡 +9 B) 1.27 MB
Details

Only the gzipped size is provided here based on an expert tip.

First Load is the size of the global bundle plus the bundle for the individual page. If a user were to show up to your website and land on a given page, the first load size represents the amount of javascript that user would need to download. If next/link is used, subsequent page loads would only need to download that page's bundle (the number in the "Size" column), since the global bundle has already been downloaded.

Any third party scripts you have added directly to your app using the <script> tag are not accounted for in this analysis

Next to the size is how much the size has increased or decreased compared with the base branch of this PR. If this percentage has increased by 20% or more, there will be a red status indicator applied, indicating that special attention should be given to this.

@sammdec sammdec requested a review from mgrabina May 22, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants