This user was pointed out on talk-de. I thought it'd be a good idea to add rel="nofollow" to all links so I took the opportunity to change every occurrence of "auto_link" to "htmlize".

But I don't have a running Rails server or much experience with RoR so instead of committing it myself I attached the patch here for someone to at least give it a quick look.

comment:1 Changed 9 years ago by LarsF

The changes to list.html.erb are purely cosmetics and I've accidentally included them in this patch.

comment:2 Changed 9 years ago by Tom Hughes

Why do want to change all these auto_link calls to be htmlize calls? We've never claimed to allow html tags in comments so why should we start rendering them now?

comment:3 Changed 9 years ago by Tom Hughes

I meant "in tag values" not "in comments".

comment:4 Changed 9 years ago by LarsF

The links are rendered now (see the link in my initial post). I just changed the calls from auto_link to htmlize because that includes your recent changes to add rel="nofollow" to all links.

Another option would of course be to leave out auto_link all together and just use h on the comments or change auto_link to use rel="nofollow". In my opinion I think we should be consistent with user provided text ([18585]) so I chose this way as htmlize seems to be the safest option.

comment:5 Changed 9 years ago by Tom Hughes

There is another option of course (which was kind of my point) which is to add the rel=nofollow without also allowing arbitrary html in tags.

comment:6 Changed 9 years ago by tomhughes

(In [19089]) Add rel=nofollow to links in tags. Closes #2555.

