1190 Commits

Author SHA1 Message Date
Angular Robot 70fb3e114b build: lock file maintenance
See associated pull request for more information.
2026-07-21 11:02:05 +02:00
Angular Robot fb953b08ab build: update cross-repo angular dependencies
See associated pull request for more information.
2026-07-20 11:22:48 +02:00
Angular Robot 829d98e9ae build: update cross-repo angular dependencies to v22.0.7
See associated pull request for more information.
2026-07-15 14:49:17 -07:00
Angular Robot 86b10d7138 build: lock file maintenance
See associated pull request for more information.
2026-07-14 08:00:35 -07:00
Angular Robot ac5f4769dd build: update pnpm to v10.34.5
See associated pull request for more information.
2026-07-13 11:52:20 -07:00
Angular Robot ec9b4793e8 build: update cross-repo angular dependencies
See associated pull request for more information.

Closes #69411 as a pr takeover
2026-07-09 16:05:25 -07:00
Angular Robot f4d20693d5 build: lock file maintenance
See associated pull request for more information.
2026-07-07 13:48:52 -07:00
Angular Robot 98ea50718a build: lock file maintenance
See associated pull request for more information.
2026-06-30 17:43:43 -07:00
Angular Robot 6ff26e96e4 build: update babel monorepo to v7.29.7
See associated pull request for more information.
2026-06-24 10:35:42 -04:00
Angular Robot f2d3bb16c5 build: update pnpm to v10.34.4
See associated pull request for more information.
2026-06-24 10:35:18 -04:00
Angular Robot 7766dc0ef4 build: lock file maintenance
See associated pull request for more information.
2026-06-23 10:44:38 -04:00
Angular Robot 8dec7753a3 build: lock file maintenance
See associated pull request for more information.

Closes #69368 as a pr takeover
2026-06-17 09:59:32 -07:00
Angular Robot 0f1cfe3082 build: update cross-repo angular dependencies to v22.0.2
See associated pull request for more information.
2026-06-17 08:05:50 -07:00
Angular Robot 3856ef7b98 build: update pnpm to v10.34.3
See associated pull request for more information.
2026-06-15 08:54:56 -07:00
Angular Robot d45e318afd build: update pnpm to v10.34.2
See associated pull request for more information.
2026-06-12 08:26:26 -07:00
Angular Robot cbcf31bfa9 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-11 09:25:30 -07:00
Angular Robot 4d0091b40f build: update cross-repo angular dependencies to v22.0.1
See associated pull request for more information.
2026-06-10 15:45:37 -07:00
Angular Robot 4ab9c5bd55 build: lock file maintenance
See associated pull request for more information.
2026-06-10 15:43:37 -07:00
Angular Robot 8f06057abe build: lock file maintenance
See associated pull request for more information.
2026-06-04 14:44:49 -07:00
Angular Robot da07b3cbc7 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-03 18:22:53 +02:00
Angular Robot a301ba2878 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-02 12:27:30 +02:00
Angular Robot 6fee7aaf89 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-01 16:31:26 +02:00
Angular Robot 2652c256d1 build: update pnpm to v10.34.1
See associated pull request for more information.
2026-06-01 11:56:50 +02:00
Angular Robot d88b796518 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-05-27 16:41:13 -07:00
Angular Robot 7104453951 build: lock file maintenance
See associated pull request for more information.
2026-05-27 11:04:40 -07:00
Angular Robot 935a80a733 build: lock file maintenance
See associated pull request for more information.
2026-05-19 13:28:02 -07:00
Alan Agius 88d138ccc8 fix(core): support prefix-insensitive DOM schema lookups and compile-time i18n attribute validation
Updates `DomElementSchemaRegistry` to strip `:svg:` and `:math:` namespace prefixes
from tag names before querying `SECURITY_SCHEMA` at compile-time. This allows SVG
and MathML attributes to correctly match their security contexts during compilation.

(cherry picked from commit 61a97f22e8)
2026-05-19 13:00:36 -07:00
Angular Robot 35234a98c8 build: update cross-repo angular dependencies to v22.0.0-rc.0
See associated pull request for more information.
2026-05-15 10:41:15 -07:00
Angular Robot 7017557d4d build: update cross-repo angular dependencies
See associated pull request for more information.
2026-05-12 15:53:07 -07:00
Angular Robot 60eac0e55c build: lock file maintenance
See associated pull request for more information.
2026-05-12 11:43:17 -07:00
Angular Robot 1d621ead2f build: update pnpm to v10.33.4
See associated pull request for more information.
2026-05-08 10:05:58 -06:00
Alan Agius a451a1d66e fix(platform-server): add allowedHosts option to renderModule and renderApplication
In server-side rendering (SSR) setups, passing request URLs directly to the lower-level rendering APIs `renderModule` or `renderApplication` can expose applications to Server-Side Request Forgery (SSRF) or Host Header Injection attacks via absolute-form request URLs.
To mitigate these vulnerabilities at the framework layer, this commit introduces the `allowedHosts` option to `PlatformConfig` (supporting exact hostnames, wildcards like `*.example.com`, or `*` to allow all).

During platform initialization inside `createServerPlatform`, the hostname of the request `url` is validated against the `allowedHosts` list. If the hostname is not authorized, bootstrap immediately throws a host validation error, preventing unauthorized rendering and silent SSRF bypasses.

Closes #68436

(cherry picked from commit 60552a73e8)
2026-05-07 15:30:08 -07:00
Angular Robot fc526331e3 build: lock file maintenance
See associated pull request for more information.
2026-05-05 09:35:19 -07:00
Angular Robot 4f048e7de3 build: update dependency typescript to v6.0.3
See associated pull request for more information.
2026-05-04 13:05:58 -07:00
Angular Robot 9c7cbcd263 build: update all non-major dependencies
See associated pull request for more information.
2026-05-01 15:57:16 -07:00
SkyZeroZx 11721509b0 refactor(core): Makes @defer(hydrate ...) runtime tree-shakable
This commit updates `@defer` logic related to incremental hydration to be tree-shakable.

If hydrate triggers are used in a `@defer` block, the compiler emits a single top-level call to `ɵɵenableIncrementalHydrationRuntime`, placed once per create block before the first `ɵɵdefer` that requires it.

As a result, the incremental hydration runtime is only included in the bundle when hydrate is explicitly used.
2026-05-01 15:54:55 -07:00
Angular Robot 9dc4e44eea build: update cross-repo angular dependencies
See associated pull request for more information.
2026-04-30 15:52:21 -07:00
Angular Robot 37ba0a79a6 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-04-29 13:34:08 -07:00
Angular Robot 32d768f69c build: lock file maintenance
See associated pull request for more information.
2026-04-28 10:25:45 -07:00
Angular Robot f9c1f979d9 build: update pnpm to v10.33.2
See associated pull request for more information.
2026-04-24 10:10:56 -07:00
Angular Robot 65c205dc34 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-04-23 15:11:57 -07:00
Angular Robot 218e2d0240 build: update cross-repo angular dependencies to v22.0.0-next.6
See associated pull request for more information.
2026-04-23 14:13:04 -07:00
Angular Robot 09b9a62a25 build: lock file maintenance
See associated pull request for more information.
2026-04-21 11:52:07 -07:00
Matthieu Riegler 13be2961f6 ci: remove disabled side-effects integration tests
This test was disabled 5+ years ago, we probably don't need it anymore.
2026-04-20 13:13:22 -07:00
Angular Robot a0d45639a9 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-04-17 15:14:59 -07:00
Angular Robot 56ff89c92d build: update all non-major dependencies
See associated pull request for more information.
2026-04-17 14:26:35 -07:00
Angular Robot 8b4581d1bb build: lock file maintenance
See associated pull request for more information.
2026-04-15 10:49:13 -04:00
Doug Parker cf47eb41ff test: use strict mode for ng_elements integration test
Apparently the Rollup bundle for these tests defaults to `es` format, meaning it expects to be loaded at runtime as native ESM. This was not happening because it was loaded as a regular `<script src="...">` tag (note the lack of `type="module"`).

This is problematic because Rollup assumed it would be running in a scoped environment, meaning [this function](https://github.com/angular/angular/blob/adb8d1078d5f127085952ca81951c18e0178a038/packages/core/primitives/event-dispatch/src/event.ts#L45), which happens to be named `addEventListener` but does *not* implement the `EventTarget.prototype.addEventListener` contract, was being bundled as a simple:

```javascript
function addEventListener(element, ...) {
  // ...
}
```

Since this was loaded with no `type="module"` or `'use strict';`, the script executed in "sloppy mode", meaning all `var` statements and function definitions are implicitly global. Since `window` *is* the `globalThis` object, this random `addEventListener` function clobbers the actual `window.addEventListener` and breaks any calls to it because they're not implementing the same contract.

Fix is to just use `<script src="..." type="module">`. Alternatively we could bundle in an IIFE, which Rollup does support, but in theory we could depend on external ES modules which aren't bundled, so the `type="module"` seems a little safer and more future-proof.
2026-04-13 14:12:48 +03:00
Doug Parker cdda51a3b2 feat(core): support bootstrapping Angular applications underneath shadow roots
This is a minimal implmentation which just focuses on registering parent shadow roots in `SharedStylesHost` correctly.

We don't currently reference count usage of host values, meaning that as soon as we call `removeHost`, all styles are removed from it, even if other components relied on them. Therefore there is no good way to know whether styles are still needed or not, leaving us with the choice of either leaking them longer than necessary or destroying them while another component still needs them. The compromise I'm using here is to delete styles when destroying a component under a shadow root (based on the assumption that only one component will exist per shadow root) and to leave styles when destroying a component in the main document (based on the assumption that dialogs being destroyed should not impact the main application).

Neither assumption is totally safe to make, but we're hoping this is a viable balance for the moment. In the future we should look into lifting these restrictions to better support those use cases while properly reference counting usage of hosts in `SharedStylesHost`.

I also added some small tests to confirm that SSR styles are not duplicated, as an earlier implementation accidentally duplicated them. This should ensure we don't repeat that mistake.
2026-04-10 21:44:08 +03:00
Jessica Janiuk 68628dd45b feat(platform-browser): make incremental hydration default behavior
This commit updates provideClientHydration to automatically enable incremental hydration by default. It also introduces a new withNoIncrementalHydration feature for opting out, adds conflict safety checks, and includes a schematic migration.
2026-04-09 18:53:13 +03:00