Page MenuHomePhabricator

Add "noreferrer" to the "rel" attribute for links leading to archive.today or one of its mirrors
Open, Needs TriagePublic

Description

Archive.today currently redirects to Tehran Times if accessed with a referrer containing "wikipedia" in it, see discussion here and video proof. This seems to affect every Wikipedia language, not only enwiki or other Wikipedias with consensus to remove these links.

Due to the scale of the problem (millions of links now inaccessible), I request noreferrer to be added to the rel attribute of links leading to any of the following URLs:

  • archive.today
  • archive.fo
  • archive.is
  • archive.li
  • archive.md
  • archive.ph
  • archive.vn
  • possibly archiveiya74codqgiixo33q62qlrqtkgmcitqx5u2oeqnmn5bpcbiyd.onion?

Event Timeline

To acknowledge receipt - we're working on this internally, and thank you for flagging it for us.

Change #1302149 had a related patch set uploaded (by Kosta Harlan; author: Kosta Harlan):

[mediawiki/extensions/WikimediaCustomizations@master] NoReferrerLinks: Add rel=noreferrer for configured external domains

https://gerrit.wikimedia.org/r/1302149

Change #1302149 merged by jenkins-bot:

[mediawiki/extensions/WikimediaCustomizations@master] NoReferrerLinks: Add rel=noreferrer noopener for configured domains

https://gerrit.wikimedia.org/r/1302149

Change #1302169 had a related patch set uploaded (by Kosta Harlan; author: Kosta Harlan):

[mediawiki/extensions/WikimediaCustomizations@wmf/1.47.0-wmf.6] NoReferrerLinks: Add rel=noreferrer noopener for configured domains

https://gerrit.wikimedia.org/r/1302169

This was done for T427561: Remove outdated rel=noreferrer from target=_blank links created by $wgExternalLinkTarget and WikimediaCustomizations would add rel=noreferrer back to legacy parses but not to Parsoid Read Views (almost all wikipedias). (EDIT: sorry, I forgot that the LinkerMakeExternalLinkWithContext hook /is/ actually Parsoid-compatible.)

Change #1302169 merged by jenkins-bot:

[mediawiki/extensions/WikimediaCustomizations@wmf/1.47.0-wmf.6] NoReferrerLinks: Add rel=noreferrer noopener for configured domains

https://gerrit.wikimedia.org/r/1302169

I can not reproduce it, but according to this edit summary btdig.com also redirected to Terran Times: https://en.wikipedia.org/w/index.php?title=BTDigg&oldid=1358639447

btdig.com is also owned by archive.today, see https://infosec.exchange/@iampytest1/116010542909144419 and https://en.wikipedia.org/wiki/Talk:BTDigg#btdig.com_is_not_the_same_as_btdigg.org

Moreover, archive.today seems to have reverted the change as they no longer redirect to Terran Times when accessed with a Wikipedia referer.

@Sapphaline: What makes you think so; Why would it matter; How would that be relevant to you?

The commit clearly states it was generated with Anthropic's Claude LLM: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikimediaCustomizations/+/1302169 (hit "Show All" to see it)
It matters because AI produces bad code and is bad for the environment, alongside other concerns including incompatibility with free software licenses. WMF's counterargument is they are competent and AI usage is common, but that doesn't address all the concerns, and moreover even competent engineers easily get complacent.

Thanks for explanation! If folks want to generally discuss AI use, then this specific ticket about "Adding noreferrer to the rel attribute" is the wrong venue, as comments here should be directly related to reporting, confirming, evaluating the severity, or fixing the bug. Please bring this up in a more suited venue. Thank you.

Change #1304876 had a related patch set uploaded (by SBassett; author: SBassett):

[operations/mediawiki-config@master] Lazily reject pre-fix parser-cache entries for noreferrer/noopener links

https://gerrit.wikimedia.org/r/1304876

Change #1304876 merged by jenkins-bot:

[operations/mediawiki-config@master] Lazily reject pre-fix parser-cache entries for noreferrer/noopener links

https://gerrit.wikimedia.org/r/1304876

Mentioned in SAL (#wikimedia-operations) [2026-06-23T20:08:07Z] <sbassett@deploy1003> Started scap sync-world: Backport for [[gerrit:1304876|Lazily reject pre-fix parser-cache entries for noreferrer/noopener links (T429090 T429244)]], [[gerrit:1305049|Enable MMV carousel on non-en wikipedias (T429509)]]

Mentioned in SAL (#wikimedia-operations) [2026-06-23T20:10:12Z] <sbassett@deploy1003> sbassett, mlitn: Backport for [[gerrit:1304876|Lazily reject pre-fix parser-cache entries for noreferrer/noopener links (T429090 T429244)]], [[gerrit:1305049|Enable MMV carousel on non-en wikipedias (T429509)]] synced to the testservers (see https://wikitech.wikimedia.org/wiki/Mwdebug). Changes can now be verified there.

Mentioned in SAL (#wikimedia-operations) [2026-06-23T20:18:23Z] <sbassett@deploy1003> Finished scap sync-world: Backport for [[gerrit:1304876|Lazily reject pre-fix parser-cache entries for noreferrer/noopener links (T429090 T429244)]], [[gerrit:1305049|Enable MMV carousel on non-en wikipedias (T429509)]] (duration: 10m 17s)