14417 Commits

Author SHA1 Message Date
Alan Agius 78fd159b78 fix(compiler): prevent XSS via SVG animation attributeName and MathML/SVG URLs
This commit implements a security fix to prevent XSS vulnerabilities where SVG animation elements (`<animate>`, `<set>`, etc.) could be used to modify the `href` or `xlink:href` attributes of other elements to `javascript:` URLs.

(cherry picked from commit 1c6b0704fb)
2025-12-01 10:27:00 +01:00
Matthieu Riegler a4084154f2 refactor(migrations): don't migration the server bootstrapApplicaiton on zoneless apps.
With the change we specifically analyse `boostrapApplication` with a config that uses `mergeApplicationConfig`.

fixes #65408

(cherry picked from commit c1dfd9cde6)
2025-11-26 15:58:57 -05:00
Matthieu Riegler 151616dd7c refactor(core): show error message on signal error
When a signal throws an error on read. The formatter will show the error message.

(cherry picked from commit 5b720aa2eb)
2025-11-26 13:11:10 -05:00
Leon Senft 0ae14cb746 test(core): test bundling of dynamic component creation and bindings
Add test coverage for bundling dynamic component creation API like
`createComponent()` and `inputBinding()`. This will be used to test that
Signal Forms related features for #64632 can be tree-shaken when unused.

(cherry picked from commit add8c41e5b)
2025-11-26 11:57:18 -05:00
Alan Agius 3240d856d9 fix(http): prevent XSRF token leakage to protocol-relative URLs
The XSRF interceptor previously failed to detect protocol-relative URLs (starting with `//`) as absolute URLs. This allowed requests to such URLs to include the XSRF token, potentially leaking it to external domains.

This change updates the interceptor to correctly identify protocol-relative URLs as absolute and exclude them from receiving the XSRF token.

(cherry picked from commit 40790ef980)
2025-11-25 13:47:29 -05:00
Alan Agius 908b5a41a3 refactor: replace getDocument() with inject(DOCUMENT)
This replaces `getDocument()` with `inject(DOCUMENT)` across hydration and transfer state logic.

(cherry picked from commit 400fc82c43)
2025-11-25 13:05:01 -05:00
Kristiyan Kostadinov 6b20adff62 refactor: add mark for signal forms
Adds a mark for signal forms so we can track adoption. Also moves the call for `@let` into `declareLet` since we don't need it to fire as often as in `storeLet`.

(cherry picked from commit c994267f17)
2025-11-25 13:03:46 -05:00
Alan Agius 49ad7c6508 fix(core): use injected DOCUMENT for CSP_NONCE
This ensures that the right document is used and that `CSP_NONCE` can be used in `provideAppInitializer` and `provideEnvironmentInitializer`.

Closes #65624

(cherry picked from commit 3b1fa8235b)
2025-11-25 11:39:23 -05:00
AntonChesnokov 8d3a89a477 fix(compiler-cli): escape angular control flow in jsdoc
Escape @-prefixed template control flow constructs during doc extraction so JSDoc parsing keeps description text intact. Add regression coverage for @for snippets.

(cherry picked from commit 5bfa027d41)
2025-11-25 11:33:29 -05:00
kirjs e3f5f34732 refactor(forms): Make reset take value
Now you can do form.reset({name: 'cat', age: 4});

(cherry picked from commit dec222d4d7)
2025-11-25 10:51:38 -05:00
Miles Malerba 7d5c7cf99a feat(forms): add DI option for classes on Field directive
Adds a DI configuration option for signal forms that allows the
developer to specify CSS classes that should be automatically added
by the `Field` directive based on the field's status.

(cherry picked from commit c70e246c23)
2025-11-25 10:33:41 -05:00
SkyZeroZx 477df38d17 docs: improve core package API documentation with additional reference links
(cherry picked from commit 67d41e9bcc)
2025-11-25 10:19:39 -05:00
Leon Senft 8acf5d2756 fix(forms): allow dynamic type bindings on signal form controls
The type checker will no longer prohibit binding the Signal Forms `[field]`
directive to an input with a dynamic `[attr.type]` or `[type]` binding.

(cherry picked from commit 3a1eb07c46)
2025-11-25 09:16:01 -05:00
Andrew Scott 0e458c7e12 refactor(core): Remove toggles used for zoneless by default migration
this migration is complete both internally and externally

(cherry picked from commit 51ebe9a4fc)
2025-11-24 16:57:52 -05:00
Kristiyan Kostadinov 70507b8c1c fix(core): debug data causing memory leak for root effects
We track all effects that are created for debugging purposes in the `resolverToEffects` map. This ends up leaking memory for effects registered on long-living resolvers (e.g. on the root injector), because they stay in the array, even if the effect itself has been destroyed.

These changes add a callback to clean up the references.

Fixes #65265.

(cherry picked from commit ca6ab6c914)
2025-11-24 15:26:12 -05:00
Leon Senft 4845a33018 refactor(forms): support custom control directives
Support binding `[field]` to directives that implement
`FormValueControl` or `FormCheckboxControl`.

The `[field]` binds to whichever directive (or component) matches first in the
event there are multiple implementations. We are considering whether to make
this an error state, which could be reported during type checking.

Closes #63910, Closes #64992

(cherry picked from commit f97a1d4856)
2025-11-24 13:48:20 -05:00
Matthieu Riegler 6cb191bade docs: add callout on zone base testing helpers
With zoneless being the default, we need to make these requirements more explicit.

fixes #65539

(cherry picked from commit b34e48bdff)
2025-11-24 13:27:49 -05:00
SkyZeroZx a62162d2ee docs: Update router docs to add references and components input fixed syntaxis
(cherry picked from commit 2ac826867b)
2025-11-24 13:18:31 -05:00
Alessio Pelliccione 9d6b86958a docs(docs-infra): fix missing syntax highlighting
closed angular#65565

(cherry picked from commit 7d20f2071c)
2025-11-24 13:13:25 -05:00
Kristiyan Kostadinov 39c577bc36 fix(compiler-cli): do not type check native controls with ControlValueAccessor
Currently when we detect a `field` binding on a native element, we treat it as a built-in native control. This might not be the case if it's a pre-existing `ControlValueAccessor` relying on the CVA interop.

These changes try to detect any CVA-like directive on the element and disable the additional type checking if there are any.

Fixes #65468.

(cherry picked from commit 6b8720de91)
2025-11-24 13:08:46 -05:00
Kristiyan Kostadinov f0b34854cc refactor(compiler-cli): track public methods during analysis
Updates the directive analysis to track the public methods of the class.

(cherry picked from commit 5cfdd7897b)
2025-11-24 13:08:46 -05:00
Tomer953 f394215b14 fix(migrations): detect structural ngTemplateOutlet and ngComponentOutlet
the common-to-standalone migration only matched [ngTemplateOutlet] and
[ngComponentOutlet] bindings and missed their structural forms
(*ngTemplateOutlet and *ngComponentOutlet). This caused missing imports
when removing CommonModule. This change adds structural directive
patterns so the migration correctly identifies needed imports.

(cherry picked from commit a4f50bdd54)
2025-11-24 12:41:01 -05:00
hawkgs 98520333bd refactor(compiler-cli): add a resource debugName transform (#64172)
Add a TS transform for `resource` (and `httpResource`) `debugName`. Test the transformations.

PR Close #64172
2025-11-24 11:30:13 -05:00
hawkgs 6de8926594 refactor(core): add debug name to resource (#64172)
Decorate `resource` (and `httpResource`) with `debugName`, along with all of its internal signals.

PR Close #64172
2025-11-24 11:30:13 -05:00
Kristiyan Kostadinov 290513f5b6 test: remove unnecessary test calls
Removes calls to `TestBed.configureTestingModule` since they aren't necessary.

(cherry picked from commit 26e2092dd1)
2025-11-24 10:18:21 -05:00
SkyZeroZx a70a191713 docs: Adds signal type checking documentation
(cherry picked from commit 38a354ffa2)
2025-11-21 16:31:16 -05:00
Matthieu Riegler 0ea1e07174 fix(core): apply bootstrap-options migration to platformBrowserDynamic
The migration wasn't applied to projects relying on `platformBrowserDynamic()` prior to this fix.

(cherry picked from commit b6fee3f107)
2025-11-21 16:28:23 -05:00
Syam Gadde bc34083d34 fix(compiler-cli): ignore non-existent files
Ignore files that fail fs.exists() rather than throw ENOENT.  Some applications deliberately create "broken" symbolic links that are not relevant to compilation (e.g. emacs lock files that link to owner "user@host").

(cherry picked from commit 1628125bcb)
2025-11-21 11:39:01 -05:00
Johannes Hoppe 65c39ea324 docs(core): remove outdated regex template restriction in best-practices.md
Regular expressions in templates are now supported as of Angular 21.

(cherry picked from commit 11da7a65c0)
2025-11-20 16:42:55 -05:00
JoostK d7484f0519 refactor(core): let the profiler handle asymmetric events leniently
Although the prior commit has made more profiler events guaranteed symmetric
through the use of finally-blocks, there continue to be some situations
that could potentially result in asymmetric events, e.g. application
bootstrap doesn't guarantee symmetric events. This commit makes the profiler
lenient to these situations by unrolling the stack past the asymmetric event
data, eventually reaching the expected start event.

(cherry picked from commit 913cde8ab4)
2025-11-20 12:30:02 -05:00
JoostK a55482fca3 fix(core): notify profiler events in case of errors
Profiler events are expected to be symmetric, yet in the case of errors this symmetry may break
if events aren't always kept in sync with their corresponding start event. This commit moves
various end events to be run from a finally-block, allowing them to notify the profiler even
when an error has occurred.

Fixes #62947

(cherry picked from commit 3760045e3e)
2025-11-20 12:30:02 -05:00
David Kingma 630a3b29d8 refactor(core): add debugName option to rxjs-interop toSignal
toSignal predates the debugName option for signals to name the signals in the Angular dev-tools This adds the debugName option to toSignal.

(cherry picked from commit 0812ac3bec)
2025-11-20 10:49:54 -05:00
tsc036 2bf0c52775 refactor(core): export profile event as enum and move profile_types.ts and framework to shared devtools folder
move framework enum and profile_types to a shared folder so it can be used by wiz

(cherry picked from commit 34e1fe235f)
2025-11-19 23:22:53 +00:00
Angular Robot e0026c870a build: update cross-repo angular dependencies
See associated pull request for more information.
2025-11-19 15:08:39 -08:00
SkyZeroZx cb15142190 docs: Adds documentation for generic type argument to SimpleChanges
(cherry picked from commit e9ba63a4c1)
2025-11-19 22:31:57 +00:00
Shuaib Hasan Akib 35dc3ecfda refactor(common): update examples to align with Angular best practices
Updated examples to use the standalone component approach and the latest

(cherry picked from commit c7affdfbc9)
2025-11-19 22:29:53 +00:00
Kristiyan Kostadinov cc1ec09931 perf(core): avoid repeat searches for field directive
The `getControlDirective` is called multiple times, both at init and during each update run. Under the hood it performs a linear search for the `Field` directive.

We can speed this up by finding its index once and reusing it since the array of directive matches is static.

(cherry picked from commit 5e6d8573f4)
2025-11-19 22:28:59 +00:00
Kristiyan Kostadinov 279824c953 refactor(compiler): remove interpolation-related symbols
We removed the ability to customize the interpolation some time ago. These changes remove the remaining code related to them.

(cherry picked from commit 81ce1ba1d9)
2025-11-19 22:28:23 +00:00
Kristiyan Kostadinov 00531864e0 refactor(compiler): remove container blocks config
Removes the ability to specify container blocks when creating an i18n parser. We were only passing in `switch` and it likely won't change.

(cherry picked from commit b6c141bf8b)
2025-11-19 22:28:23 +00:00
Miles Malerba de5fca94c5 fix(forms): run reset as untracked
Run the signal forms `reset()` as untracked so it does not trigger
`effect` to rerun when the model changes

Fixes https://github.com/angular/angular/issues/65322

(cherry picked from commit 7ddf4a6b07)
2025-11-19 22:27:55 +00:00
Jessica Janiuk 685477632f build: bump core zone.js version
this bumps the core dep on zone.js to 0.16.0.

(cherry picked from commit 11ea1a01ff)
2025-11-19 21:22:17 +00:00
Joey Perrott fe5c9a1e6a release: bump version of in memory web api
(cherry picked from commit 9a663a28f9)
2025-11-19 20:05:54 +00:00
Angular Robot 77fc03ffb6 build: update cross-repo angular dependencies
See associated pull request for more information.
2025-11-18 15:29:10 -08:00
Angular Robot 1b43bfbbab build: update cross-repo angular dependencies
See associated pull request for more information.
2025-11-17 16:35:53 -08:00
Jessica Janiuk 127cadd3fc Revert "refactor(core): let the profiler handle asymmetric events leniently"
This reverts commit da9911f2b4.

(cherry picked from commit 88dfd96ec9)
2025-11-17 18:10:41 +00:00
Jessica Janiuk e430d69603 Revert "fix(core): notify profiler events in case of errors"
This reverts commit af1ba52587.

(cherry picked from commit adc2a57be0)
2025-11-17 18:10:41 +00:00
Matthew Beck ecea909bcc fix(compiler): don't choke on unbalanced parens in declaration block
Following https://github.com/angular/angular/pull/64509 we started
choking on unbalanced closing parentheses in declaration blocks,
specifically in quoted background-image urls. This was reported in
https://github.com/angular/angular/issues/65137.

This occured because we previously (and now again) traverse the entire
declaration block when selecting for :host-context() selectors to shim.
This is an oddity of how we parse styles today, and is likely something
we'd want to remove if we parsed selectors properly.

This change adds a new flag to _splitOnTopLevelCommas which allows it to
continue past unbalanced closing parentheses in the declaration block,
returning _convertColonHostContext to its previous behavior while
keeping support for the extra nesting in :host-context().

(cherry picked from commit 9e7ddcaa10)
2025-11-17 17:46:04 +00:00
Matthieu Riegler 035e07e3be refactor(core): promote the custom track profiler to stable.
We didn't get much report on the feature itself so we feel confident about promoting it to stable. In parallel we'll also land #62959 but one is not blocking the other.

fixes #64996

(cherry picked from commit c15836c8c7)
2025-11-17 17:42:35 +00:00
Matthieu Riegler 91d8d55a80 fix(forms): Set error message of a schema error.
Use the error message of the issue as the error message of the error itself.

fixes #65247

(cherry picked from commit b41a94bc85)
2025-11-17 17:41:57 +00:00
Miles Malerba 6aa4b7ea63 refactor(forms): avoid console warnings when setting NaN
It can be useful for a developer to set `NaN` as the value for a number
input, as a way to say "clear the input". However, directly setting this
value to the `.valueAsNumber` causes a console warning. This PR fixes
the console warning by just doing `.value = ''` when we would otherwise
to `.valueAsNumber = NaN`

(cherry picked from commit f47637426f)
2025-11-17 17:41:32 +00:00