react-doctor/window-open-without-noopener
window.open without noopener
- Category: Security
- Severity: warn
- Source:
oxlint-plugin-react-doctor - Framework: global
- Enabled when: always
- Default: Enabled
Validate the diagnostic
Confirm the reported code matches this rule before you edit it.
Confirm the reported code matches react-doctor/window-open-without-noopener. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.
Compare the code
The corrected pattern shows a focused way to address the diagnostic.
Reported pattern
window.open(url, "_blank");Corrected pattern
window.open(url, "_blank", "noopener,noreferrer");How to fix
Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.
Copyable fix prompt
Copy this self-contained prompt into your coding agent after you confirm the diagnostic.
Fix every confirmed
Reference transformation:Before:react-doctor/window-open-without-noopener diagnostic in the current repository.
Required change:
- Pass 'noopener' in the third features argument of window.open so the opened page can't control your tab through window.opener. Add 'noreferrer' too when the destination must not receive the referrer.window.open(url, "_blank");window.open(url, "_blank", "noopener,noreferrer");Constraints:
- Confirm the reported code matches the Before pattern.
- Make the smallest change that fixes the root cause.
- Preserve behavior and interfaces unrelated to this diagnostic.
- Reuse existing project components, utilities, and conventions.
- Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations.
- Keep validation and authorization on trusted boundaries. Do not replace them with client-only checks.
- Adapt identifiers and framework details instead of copying blindly.
- Do not disable the rule or suppress matching code.
Verification:
- Run focused tests for the changed behavior.
- Run React Doctor and confirm this diagnostic no longer appears.
- Report the files changed and any checks you could not run.
Related rules
More Security rules from the rules reference:
socket/low-supply-chain-score: A direct dependency's worst Socket security axis (supply chain or vulnerability) scores below the configured minimum — bump it to a patched/healthier release, replace it, or vet it and raise `supplyChain.minScore`react-doctor/active-static-asset: A browser-reachable SVG that contains a `<script>` tag or `on*` event handler runs that code in your origin when someone opens it, which can lead to cross-site scripting.react-doctor/agent-tool-capability-risk: An AI agent tool that can reach shell, filesystem, or network primitives lets prompt-injected input trigger those actions, because the model treats tool arguments as trusted.react-doctor/artifact-baas-authority-surface: Shipping Firebase/Supabase client config with your collection and authorization-field names in a browser bundle hands attackers a map of your data model, which is dangerous when server-side rules do not enforce access.react-doctor/artifact-env-leak: A real secret shipped in a browser bundle under a public env prefix (`NEXT_PUBLIC_`, `VITE_`, `REACT_APP_`, `EXPO_PUBLIC_`) is world-readable and must be treated as compromised.