FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[Backport 21.2.X] fix(platform-server): reject protocol-relative paths in resolveUrl by alan-agius4 · Pull Request #71079 · angular/angular · GitHub

Repository navigation

[Backport 21.2.X] fix(platform-server): reject protocol-relative paths in resolveUrl - #71079

Merged
atscott merged 1 commit into
angular:21.2.xfrom
alan-agius4:backport-71077-to-21.2.x
Sep 30, 2026
Merged

atscott merged 1 commit into
angular:21.2.xfrom
alan-agius4:backport-71077-to-21.2.x

Conversation

Copy link
Copy Markdown
Contributor

Backport of #71077 to 21.2.x.

Previously, resolveUrl only checked whether the raw URL string started with '//' before WHATWG URL resolution. When given an input such as '/.//evil.test', WHATWG dot-segment normalization popped the leading '/.', leaving a pathname starting with '//'. This corrupted ServerPlatformLocation and led to protocol-relative open redirects in SSR.

Now, resolveUrl also verifies that the normalized URL pathname does not start with '//' when allowProtocolRelative is false.

Fixes angular#71076
pullapprove Bot requested a review from kirjs September 30, 2026 08:42
angular-robot Bot added the area: server Issues related to server-side rendering label Sep 30, 2026
ngbot Bot added this to the Backlog milestone Sep 30, 2026
JeanMeche removed the request for review from kirjs September 30, 2026 09:09
alan-agius4 added action: merge The PR is ready for merge by the caretaker target: lts This PR is targeting a version currently in long-term support labels Sep 30, 2026
atscott merged commit 450af9c into angular:21.2.x Sep 30, 2026
23 checks passed

atscott commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

This PR was merged into the repository. The changes were merged into the following branches:

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: server Issues related to server-side rendering target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL