Skip to content

Discovery: Limit HTML rel=hub links to <link> elements in <head> only. #67

@cweiske

Description

@cweiske

if <a rel="hub"> is allowed, then people could hijack the page's hub URL via the HTML comments box. " together with fat pings this would mean that I could inject fake news into people's readers when they susbcribe to someone's blog, just by posting a comment with a rel=hub link"

Please also note in the security considerations why implementations MUST NOT support <a rel="hub">

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions