Skip to content

fix(@angular/ssr): preserve internal URL trust - #34158

Closed
BlueIridium wants to merge 1 commit into
angular:mainfrom
BlueIridium-Security:ssr-internal-authority-trust
Closed

BlueIridium wants to merge 1 commit into
angular:mainfrom
BlueIridium-Security:ssr-internal-authority-trust

Conversation

@BlueIridium

Copy link
Copy Markdown

Hello Angular CLI team — we’re BlueIridium, an independent security research organization. This is our first contribution to Angular CLI.

PR Checklist

PR Type

  • Bugfix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • CI related changes
  • Documentation content changes
  • Other... Please describe:

What is the current behavior?

The companion @angular/platform-server change validates authority-bearing INITIAL_CONFIG.url values when the server platform adopts them. Angular CLI creates two internal server platforms for rendering and route extraction after the owning app-engine, build, or development-server flow has already accepted or constructed the URL, but those handoffs do not currently preserve that trust decision.

Without an explicit policy at these internal handoffs, the companion platform-server change would reject their absolute URLs with NG05706.

Issue Number: N/A

What is the new behavior?

The rendering and route-extraction handoffs now set allowedHosts: ['*'] in INITIAL_CONFIG after their owning policy has accepted the URL. This preserves the existing internal flows while keeping the shared platform check default-deny for public low-level callers.

Tests verify that both internal platforms receive the explicit trust policy.

Does this PR introduce a breaking change?

  • Yes
  • No

Other information

This change is intended to land in coordination with angular/angular#70907. Both pull requests are being opened as drafts for coordinated review.

Mark both internal server platforms as trusted after their owning request, build, or development-server policy has accepted the URL.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Angular SSR configuration to include 'allowedHosts: ['*']' within the 'INITIAL_CONFIG' for both route extraction and rendering. This change ensures that internal platform URLs are correctly identified as validated. Corresponding test cases and build dependencies have been updated to support and verify this configuration. I have no feedback to provide.

@alan-agius4

Copy link
Copy Markdown
Collaborator

Kindly see angular/angular#70907

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants