Sitelet https://github.com/angular/angular/pull/68468
Skip to content

Patch port 20 - #68468

Closed
alan-agius4 wants to merge 9 commits into
angular:20.3.xfrom
alan-agius4:patch-port-20
Closed

alan-agius4 wants to merge 9 commits into
angular:20.3.xfrom
alan-agius4:patch-port-20

Conversation

@alan-agius4

Copy link
Copy Markdown
Contributor

Backport several security fixes

Ensures that security-sensitive attributes (e.g., sandbox, allow) are correctly validated when applied through i18n-* dynamic attribute bindings, preventing potential policy bypasses.

Closes angular#68418
…tionally

Moves the event attribute validation check outside of `ngDevMode` in the `elementAttributeInternal` instruction to ensure that bindings to event attributes like `on*` are always blocked at runtime.

Previously, this check was only performed when `ngDevMode` was `true`, which could allow attacker-controlled CMS data to be bound to event attributes in production mode, causing browser-executed XSS.

Fixes angular#68419
… url

The origin did not have a trailing slash, which caused parsing issues for relative URLs.

Fixes angular#68322
@alan-agius4 alan-agius4 added action: review The PR is still awaiting reviews from at least one requested reviewer target: lts This PR is targeting a version currently in long-term support labels Apr 30, 2026
@angular-robot angular-robot Bot added area: core Issues related to the framework runtime area: server Issues related to server-side rendering labels Apr 30, 2026
@ngbot ngbot Bot added this to the Backlog milestone Apr 30, 2026
@alan-agius4
alan-agius4 requested review from AndrewKushnir and removed request for AndrewKushnir April 30, 2026 06:51
@alan-agius4 alan-agius4 removed the action: review The PR is still awaiting reviews from at least one requested reviewer label May 6, 2026
@alan-agius4
alan-agius4 removed the request for review from AndrewKushnir May 6, 2026 06:19
@alan-agius4 alan-agius4 added the action: merge The PR is ready for merge by the caretaker label May 6, 2026
@alxhub

alxhub commented May 6, 2026

Copy link
Copy Markdown
Member

This PR was merged into the repository. The changes were merged into the following branches:

alxhub pushed a commit that referenced this pull request May 6, 2026
…68468)

Ensures that security-sensitive attributes (e.g., sandbox, allow) are correctly validated when applied through i18n-* dynamic attribute bindings, preventing potential policy bypasses.

Closes #68418

PR Close #68468
alxhub pushed a commit that referenced this pull request May 6, 2026
…tionally (#68468)

Moves the event attribute validation check outside of `ngDevMode` in the `elementAttributeInternal` instruction to ensure that bindings to event attributes like `on*` are always blocked at runtime.

Previously, this check was only performed when `ngDevMode` was `true`, which could allow attacker-controlled CMS data to be bound to event attributes in production mode, causing browser-executed XSS.

Fixes #68419

PR Close #68468
alxhub pushed a commit that referenced this pull request May 6, 2026
… url (#68468)

The origin did not have a trailing slash, which caused parsing issues for relative URLs.

Fixes #68322

PR Close #68468
@alxhub alxhub closed this May 6, 2026
@angular-automatic-lock-bot

Copy link
Copy Markdown

This pull request has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot Bot locked and limited conversation to collaborators Jun 6, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

action: merge The PR is ready for merge by the caretaker area: core Issues related to the framework runtime area: server Issues related to server-side rendering PullApprove: disable target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants