Verified Commit 1abf4357 authored by Jelle van der Waa's avatar Jelle van der Waa 🚧
Browse files

packages: remove onclick handler



The onclick handler is a CSP violator since no JavaScript is allowed to
be executed without a nounce. The inline script has been replaced with a
target="_blank".

Closes: #202
Signed-off-by: Jelle van der Waa's avatarJelle van der Waa <jelle@vdwaa.nl>
parent 6507d02c
...@@ -34,8 +34,8 @@ <h4>Package Actions</h4> ...@@ -34,8 +34,8 @@ <h4>Package Actions</h4>
<li><a href="flag/" title="Flag {{ pkg.pkgname }} as out-of-date">Flag Package Out-of-Date</a> <li><a href="flag/" title="Flag {{ pkg.pkgname }} as out-of-date">Flag Package Out-of-Date</a>
<a href="/packages/flaghelp/" <a href="/packages/flaghelp/"
title="Get help on package flagging" title="Get help on package flagging"
onclick="return !window.open('/packages/flaghelp/','FlagHelp', target="_blank"
'height=350,width=450,location=no,scrollbars=yes,menubars=no,toolbars=no,resizable=no');">(?)</a></li> >(?)</a></li>
{% endif %} {% endif %}
<li><a href="download/" rel="nofollow" title="Download {{ pkg.pkgname }} from mirror">Download From Mirror</a></li> <li><a href="download/" rel="nofollow" title="Download {{ pkg.pkgname }} from mirror">Download From Mirror</a></li>
</ul> </ul>
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment