Skip to content

refactor(compiler): remove img/video src attribute from the URL secur… - #71095

Open
JeanMeche wants to merge 1 commit into
angular:mainfrom
JeanMeche:img-src
Open

JeanMeche wants to merge 1 commit into
angular:mainfrom
JeanMeche:img-src

Conversation

@JeanMeche

@JeanMeche JeanMeche commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

…ity context.

Browsers are already blocking script execution on those attributes.

@angular-robot angular-robot Bot added the area: compiler Issues related to `ngc`, Angular's template compiler label Sep 30, 2026
@ngbot ngbot Bot added this to the Backlog milestone Sep 30, 2026
@JeanMeche
JeanMeche force-pushed the img-src branch 2 times, most recently from 28e2b7b to f631ab1 Compare October 1, 2026 14:42
@JeanMeche

JeanMeche commented Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

After some testing noticed this is a breaking change at least when the value is undefined.

Before: src remains unset
After: src is set to 'undefined'.

Other breaking change: any image passed to bypassSecurityTrustResourceUrl will be broken.

@JeanMeche JeanMeche modified the milestones: Backlog, v23 candidates Oct 1, 2026
@JeanMeche
JeanMeche marked this pull request as ready for review October 1, 2026 15:47

@alan-agius4 alan-agius4 left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

Note, this requires a TGP to ensure that G3 clean-up has been done.

NIT: commit message has some typos and it should probably mention that this is a breaking change.

@alan-agius4 alan-agius4 added the requires: TGP This PR requires a passing TGP before merging is allowed label Oct 1, 2026
@pullapprove
pullapprove Bot requested a review from alan-agius4 October 1, 2026 15:51
@alan-agius4 alan-agius4 added the action: cleanup The PR is in need of cleanup, either due to needing a rebase or in response to comments from reviews label Oct 1, 2026

@alan-agius4 alan-agius4 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed-for: fw-security

@JeanMeche

Copy link
Copy Markdown
Member Author

(currently looking if we can temporarily workaround this breaking change).

@JeanMeche
JeanMeche force-pushed the img-src branch 4 times, most recently from c827694 to bf205e7 Compare October 1, 2026 16:27
Comment thread packages/core/test/acceptance/property_binding_spec.ts
…ity context.

Browsers are already blocking script execution on those attributes.
@JeanMeche JeanMeche removed action: cleanup The PR is in need of cleanup, either due to needing a rebase or in response to comments from reviews breaking changes requires: TGP This PR requires a passing TGP before merging is allowed labels Oct 1, 2026
@JeanMeche

JeanMeche commented Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

Green TGP

I went with a workaround that will also allow me to cleanup g3 once this is merged, plan is to make the work around 3p only until we reach the breaking change window. Unit test will provide the necessary coverage in the mean time.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: compiler Issues related to `ngc`, Angular's template compiler

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants