| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Previously, resolveUrl only checked whether the raw URL string started with '//' before WHATWG URL resolution. When given an input such as '/.//evil.test', WHATWG dot-segment normalization popped the leading '/.', leaving a pathname starting with '//'. This corrupted ServerPlatformLocation and led to protocol-relative open redirects in SSR. Now, resolveUrl also verifies that the normalized URL pathname does not start with '//' when allowProtocolRelative is false. Fixes angular#71076
|
This PR was merged into the repository. The changes were merged into the following branches:
|
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Backport of #71077 to 21.2.x.