Skip to content

fix(platform-server): reject protocol-relative paths in resolveUrl - #71077

Merged
atscott merged 1 commit into
angular:mainfrom
alan-agius4:fix-platform-server-protocol-relative
Sep 30, 2026
Merged

atscott merged 1 commit into
angular:mainfrom
alan-agius4:fix-platform-server-protocol-relative

Conversation

@alan-agius4

Copy link
Copy Markdown
Contributor

Previously, resolveUrl only checked whether the raw URL string started with // before WHATWG URL resolution. When given an input such as /.//evil.test (or serialized from route shapes like /.;/(//evil.test)), WHATWG dot-segment normalization popped the leading /., leaving a pathname starting with //. This corrupted ServerPlatformLocation and led to protocol-relative open redirects in SSR.

Now, resolveUrl also verifies that the normalized URL pathname does not start with // when allowProtocolRelative is false.

Fixes #71076

Previously, resolveUrl only checked whether the raw URL string started with '//' before WHATWG URL resolution. When given an input such as '/.//evil.test', WHATWG dot-segment normalization popped the leading '/.', leaving a pathname starting with '//'. This corrupted ServerPlatformLocation and led to protocol-relative open redirects in SSR.

Now, resolveUrl also verifies that the normalized URL pathname does not start with '//' when allowProtocolRelative is false.

Fixes angular#71076
@alan-agius4 alan-agius4 added action: merge The PR is ready for merge by the caretaker target: lts This PR is targeting a version currently in long-term support target: patch This PR is targeted for the next patch release and removed target: lts This PR is targeting a version currently in long-term support labels Sep 30, 2026
@atscott
atscott merged commit d7d81e1 into angular:main Sep 30, 2026
30 checks passed
@atscott

atscott commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

This PR was merged into the repository. The changes were merged into the following branches:

@alan-agius4
alan-agius4 deleted the fix-platform-server-protocol-relative branch September 30, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: server Issues related to server-side rendering target: patch This PR is targeted for the next patch release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Angular SSR pathname normalization can turn a same-origin navigation into an open redirect

3 participants