fix(@angular/ssr): preserve internal URL trust - #34158
Closed
BlueIridium wants to merge 1 commit into
Closed
BlueIridium wants to merge 1 commit into
BlueIridium wants to merge 1 commit into
Conversation
Mark both internal server platforms as trusted after their owning request, build, or development-server policy has accepted the URL.
There was a problem hiding this comment.
Code Review
This pull request updates the Angular SSR configuration to include 'allowedHosts: ['*']' within the 'INITIAL_CONFIG' for both route extraction and rendering. This change ensures that internal platform URLs are correctly identified as validated. Corresponding test cases and build dependencies have been updated to support and verify this configuration. I have no feedback to provide.
Collaborator
|
Kindly see angular/angular#70907 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hello Angular CLI team — we’re BlueIridium, an independent security research organization. This is our first contribution to Angular CLI.
PR Checklist
PR Type
What is the current behavior?
The companion
@angular/platform-serverchange validates authority-bearingINITIAL_CONFIG.urlvalues when the server platform adopts them. Angular CLI creates two internal server platforms for rendering and route extraction after the owning app-engine, build, or development-server flow has already accepted or constructed the URL, but those handoffs do not currently preserve that trust decision.Without an explicit policy at these internal handoffs, the companion platform-server change would reject their absolute URLs with
NG05706.Issue Number: N/A
What is the new behavior?
The rendering and route-extraction handoffs now set
allowedHosts: ['*']inINITIAL_CONFIGafter their owning policy has accepted the URL. This preserves the existing internal flows while keeping the shared platform check default-deny for public low-level callers.Tests verify that both internal platforms receive the explicit trust policy.
Does this PR introduce a breaking change?
Other information
This change is intended to land in coordination with angular/angular#70907. Both pull requests are being opened as drafts for coordinated review.