2764 Commits

Author SHA1 Message Date
Angular Robot 8dec7753a3 build: lock file maintenance
See associated pull request for more information.

Closes #69368 as a pr takeover
2026-06-17 09:59:32 -07:00
Angular Robot 0f1cfe3082 build: update cross-repo angular dependencies to v22.0.2
See associated pull request for more information.
2026-06-17 08:05:50 -07:00
rudzikdawid 35219dcac3 fix(docs-infra): increase SSR fetch limit to prevent 404 on page reload
Navigating to specific ARIA guide pages directly or via hard refresh
causes a 404 error because the payload exceeds the default SSR fetch
limit. This commit increases the maxResponseBodySize to 2MB.

(cherry picked from commit 02d6b436f1)
2026-06-17 15:03:59 +00:00
SkyZeroZx b32ee7ceb3 fix(core): treat iframe credentialless as security-sensitive
Mark the iframe `credentialless` attribute as security-sensitive so dynamic
bindings are handled consistently with other iframe attributes that affect the
initial navigation, such as `sandbox`, `allow`, `referrerPolicy`, `csp`, and
`fetchPriority`.

Because `credentialless` must be present before the iframe starts loading to
affect the navigation’s credential mode, late dynamic updates can leave the final
DOM looking correct while the initial request was not loaded credentiallessly.

(cherry picked from commit 0152e3cbdf)
2026-06-16 16:05:57 +00:00
yamanerkam f2c5045e0a docs: use the @Service decorator in the learn-angular DI tutorial
The "Creating an injectable service" tutorial introduced services with
`@Injectable({providedIn: 'root'})`, even though the essentials guide and
the in-depth dependency injection guides have already moved to the newer
`@Service` decorator. This left the tutorial out of step with the rest of
the documentation.

Update steps 19 and 20 to use `@Service()`. Because `@Service()` is an
ergonomic shorthand for `@Injectable({providedIn: 'root'})`, the examples
behave identically while teaching the recommended modern API. The step 19
README is reworked to match: it drops the now-unnecessary `providedIn`
configuration step and adds a note linking to the in-depth services guide
for the `autoProvided: false` opt-out.

(cherry picked from commit cbccd368af)
2026-06-16 15:49:09 +00:00
Kam 929a1553f2 fix(docs-infra): align homepage banner and search field
The homepage hero lays out the announcement banner and the search field on
the same flex row. The `.search-field` wrapper was a plain block, so its
`docs-text-field` kept its intrinsic height instead of filling the row,
leaving the two pills at different heights and vertically misaligned.

Make `.search-field` a flex container so the search control stretches to the
row height and matches the banner.

(cherry picked from commit 4ba8ba4ef2)
2026-06-15 16:15:33 +00:00
Kam fe7f9ed505 fix(docs-infra): center social and theme menus under their triggers on tablet
On tablet the social and theme mini-menus didn't line up with the buttons that
open them.

All three mini-menus now share one tablet positioning rule on `.adev-mini-menu`
that centers each panel under its trigger, with `--social`/`--theme`/`--version`
modifiers selecting the anchor; the version picker's on-screen behavior is
unchanged. The social trigger also gains `aria-controls` + a matching menu `id`
for a11y parity with the theme trigger.

(cherry picked from commit 50e7f3a1cd)
2026-06-15 15:59:22 +00:00
Kam eafdbe008a fix(docs-infra): use a facade for docs-video to fix Firefox embeds
Follow-up to #69205. After switching adev's COEP to `credentialless`, the
cross-origin YouTube iframe in `<docs-video>` loads in Chromium and Safari but
not Firefox, whose `credentialless` policy does not extend to nested frames. The
result was a COEP error screen instead of the player.

Render `<docs-video>` as a lightweight thumbnail facade instead of embedding the
iframe directly. The thumbnail is a cross-origin subresource, so it loads under
`credentialless` in every browser. `DocViewer` then upgrades the facade to the
inline player on hydration in browsers that can load the embed (Chromium,
Safari), preserving the previous behavior there. On Firefox the facade stays a
plain link that opens the video on YouTube (with autoplay), which replaces the
error screen.

The thumbnail uses `maxresdefault` and falls back to `hqdefault` when a video
has no max-resolution image.

(cherry picked from commit 43acead06d)
2026-06-15 15:58:04 +00:00
Matthieu Riegler bbd056919f docs: add item about the resource breaking change.
In #67382 we changed how values are resolved which ended up being a breaking change for some unit tests.

fixes #69360

(cherry picked from commit 3b8bb7219b)
2026-06-15 15:57:06 +00:00
kirjs 34f9539623 docs(forms): use touch.emit() in custom controls example
(cherry picked from commit c0e2364f12)
2026-06-15 15:56:17 +00:00
hawkgs 02c1652091 fix(docs-infra): stabilize html element scroll gutter
Stabilize `<html>` scroll gutter.

Fixes #69036

(cherry picked from commit db677a4349)
2026-06-12 16:19:36 +00:00
hawkgs b7aa8dca6b fix(docs-infra): add explicit font styles to docs-primary-btn
Add font family, size and weight to the `.docs-primary-btn`. This guarantees that applying the class to non-button elements, like anchors, will results in the same visual representation.

(cherry picked from commit 91ab7c6dea)
2026-06-12 16:08:06 +00:00
SkyZeroZx 6c1f3e9d49 fix(common): skip transfer cache for uncacheable HTTP traffic (#69316)
Do not store HTTP transfer cache entries when either the request or response
uses `Cache-Control: no-store`, `Cache-Control: private`, or
`Cache-Control: no-cache`.

Also skip transfer cache when requests use the Fetch API `cache` option with
`no-store` or `no-cache`.

Because transfer cache serializes SSR HTTP responses into the rendered HTML,
Angular now treats these directives conservatively to avoid exposing sensitive
or explicitly uncacheable data through `TransferState`.

PR Close #69316
2026-06-11 16:58:24 +00:00
SkyZeroZx 7ef1399068 fix(http): skip transfer cache for fetch credentialed requests (#69316)
Treat HttpClient requests using `credentials: 'include'` and `same-origin` as credentialed
when deciding whether a response can be stored in the HTTP transfer cache.

The transfer cache already skips requests with `withCredentials`, `Cookie`,
`Authorization`, or `Proxy-Authorization` because those responses may contain
user-specific data. Fetch-backed requests can express the same credentialed
behavior through the `credentials` option, so these responses must not be
serialized into the SSR HTML.

This keeps credentialed SSR responses out of TransferState and aligns the
cache eligibility check with the fetch request options supported by HttpClient.

PR Close #69316
2026-06-11 16:58:24 +00:00
Angular Robot cbcf31bfa9 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-11 09:25:30 -07:00
Matthieu Riegler 033aa9720d docs(docs-infra): Update navigation status
(cherry picked from commit 59e2041847)
2026-06-11 16:24:32 +00:00
Angular Robot 4d0091b40f build: update cross-repo angular dependencies to v22.0.1
See associated pull request for more information.
2026-06-10 15:45:37 -07:00
SkyZeroZx b416da67c1 docs: add caching guidance for resource data with SSR
(cherry picked from commit 274d1d2dcc)
2026-06-10 18:27:48 +00:00
aparziale 48996d3ab2 docs: update webpack-based system docs
Update webpack-based system docs

Fixes #69279

(cherry picked from commit 8854f2d476)
2026-06-10 17:54:46 +00:00
SkyZeroZx 1bd5a562f5 docs: deprecate XHR support for server-side rendering in HTTP docs and recommend Fetch
(cherry picked from commit 2066225244)
2026-06-10 17:20:43 +00:00
Jad Chahed a704b08379 docs: add Signal Forms and v22 guidance to AI best-practices and llms.txt
Update the AI codegen resources for Angular v22:
- best-practices.md: OnPush is the default in v22+ (don't set it explicitly),
  recommend Signal Forms, and recommend the @Service decorator.
- llms.txt: add a Signal Forms reference, the httpResource guide, and an
  Accessibility section linking the Angular Aria overview.

(cherry picked from commit 248e9c146d)
2026-06-09 21:00:00 +00:00
Kam 4d24f465e3 fix(docs-infra): load cross-origin video embeds under COEP credentialless
adev is cross-origin isolated (COOP same-origin + COEP require-corp) so the
embedded WebContainer editor can use SharedArrayBuffer. Under require-corp the
cross-origin YouTube iframe in `<docs-video>` only loaded in Chromium, leaving
the player blank in Safari.

Switch COEP from `require-corp` to `credentialless`. The page stays cross-origin
isolated, so the editor keeps working, but cross-origin frames are now allowed
to load, which restores the inline player in Safari as well.

(cherry picked from commit 86cd166141)
2026-06-09 20:26:24 +00:00
Kam 8ddda4d0aa fix(docs-infra): improve version picker dropdown positioning
Drops `position: absolute` from the version picker `<ul>` and tightens `max-height` to `70dvh` so the cdk-overlay-pane fits the viewport and the inner scroll reaches the last versions on mobile and desktop.

(cherry picked from commit 7d92cc8b46)
2026-06-09 16:58:26 +00:00
Kam 35a8c28656 docs: fix CurrencyPipe locale override example
The "Override current locale for CurrencyPipe" example used `{{ amount | currency: 'en-US' }}`, but the first `CurrencyPipe` argument is the currency code, not the locale, so `'en-US'` was treated as an invalid currency code (rendered literally as the symbol) and the locale was never overridden. Since `locale` is the fourth positional argument, the example now passes a valid currency code, display, and digits before it (`'USD' : 'symbol' : '1.2-2' : 'en-US'`), matching the parameter order shown on the CurrencyPipe API page.

(cherry picked from commit a82f822057)
2026-06-08 21:36:21 +00:00
KirtiRamchandani e7dae12c3d fix(docs-infra): avoid code copy button overlap
Reveal code copy controls on hover and focus so long code snippets stay readable while keyboard access and copy state feedback remain intact.

(cherry picked from commit b7cb5844cf)
2026-06-08 21:19:54 +00:00
Bhuvansh855 60d88b11bd docs: fix malformed prettier-ignore comment in whitespace guide
(cherry picked from commit 422e6893e4)
2026-06-08 19:59:29 +00:00
aparziale 54fa77adc1 docs: close menù with click outside container
close menù with click outside container

Fixes #69222

(cherry picked from commit dc8165e253)
2026-06-08 19:58:03 +00:00
Matthieu Riegler b310d718d9 docs: mention required behavior for booleans
fixes #68509

(cherry picked from commit 9cfd3f52e1)
2026-06-08 19:54:44 +00:00
Kam 70d038774c docs: trim transparent padding from v22 event hero image
The v22 event hero PNG shipped with a wide transparent margin baked into
its 960x540 canvas. Under the shared `img { width: 100% }` rule that empty
border stretched along with the artwork, leaving visible space around the
image. Trims the canvas to the artwork bounds (831x473) so it renders
flush; the retained pixels are unchanged and the file shrinks from about
795 KB to 568 KB.

(cherry picked from commit af7cb63151)
2026-06-05 17:56:32 +00:00
marktechson 879750a756 docs: update landing page with embed link and updated messaging
(cherry picked from commit 0197be381e)
2026-06-05 17:41:34 +00:00
Kam 652b76b57d docs: bump schematics-for-libraries example peer deps to v22
The my-lib schematics-for-libraries example still declared `^21.0.0`
peerDependencies, the only adev example left on the previous major. Bumps
`@angular/common`/`@angular/core` to `^22.0.0`, matching the current major
and this file's stable-`^N.0.0` bump pattern.

Also adds this example's package.json to .prettierignore: it contains
`// #docregion` markers consumed by the schematics-for-libraries guide, and
Prettier's json-stringify parser (used for any package.json) rejects those as
invalid JSON. Editing the file surfaced this pre-existing incompatibility in
the format check.

(cherry picked from commit 3960ad64e5)
2026-06-05 17:18:42 +00:00
Michael Small c00387b8d2 docs: mention parse of validateHttp
(cherry picked from commit e100c75e37)
2026-06-04 19:32:15 +00:00
Sreeved 93e5f95dd2 docs: fix typo in update card link description
(cherry picked from commit 82193a19ee)
2026-06-04 19:29:07 +00:00
KirtiRamchandani 1f0aeac008 fix(docs-infra): reserve scrollbar gutter for mobile nav
(cherry picked from commit bcb9f8da03)
2026-06-04 19:22:59 +00:00
Matthieu Riegler addedf3f95 docs: update support & release dates
(cherry picked from commit ebb76a4313)
2026-06-04 18:36:32 +00:00
Ben Hong 296f3481d5 docs: fix directives guide issues and inaccuracies
(cherry picked from commit c39b2a3b18)
2026-06-03 22:39:17 +00:00
Angular Robot da07b3cbc7 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-03 18:22:53 +02:00
Alan Agius 14fc4b1018 refactor(docs-infra): rename tutorial & example package.json.template to package.json
Rename the tutorial and example template packages' package.json.template files to package.json on disk.

To comply with ng_package limitations (which forbids floating package.json files in package output), we added a copy_file rule in the BUILD files to generate the .template files during build/packaging, and excluded the source package.json files from the filegroups. This keeps package.json as standard files in the source tree while preserving docs packaging and runtime logic.

(cherry picked from commit ba59de563f)
2026-06-03 18:19:27 +02:00
marktechson 4e4242035b docs: update landing page for v22
(cherry picked from commit 20524958b7)
2026-06-03 17:54:55 +02:00
Pawel Kozlowski 24416ce92f docs: update tutorials and playground to v22.0.0
(cherry picked from commit 595660d796)
2026-06-03 17:11:43 +02:00
Pawel Kozlowski 0a3d22a571 docs: update version picker list for v22 release
(cherry picked from commit 95ede172a6)
2026-06-03 17:11:43 +02:00
Cheng-Hsuan Tsai 3401189488 docs: add Signal Forms integration example to Angular Aria Autocomplete guide
(cherry picked from commit b84e5ef183)
2026-06-03 11:23:27 +02:00
Kam da5a9505ef docs: use Türkiye as the country name in aria autocomplete examples
The aria autocomplete examples list "Turkey" in their country data, but
the country's official name is "Türkiye". Update all nine app.ts variants
to use it.

While there, remove a junk "Imporant" entry from the highlight/retro
variant's list, which is not a country and was a misspelled stray paste.

(cherry picked from commit 192ac021e4)
2026-06-03 11:19:58 +02:00
cexbrayat 62e1d88252 docs: simplify testing setup examples
(cherry picked from commit 3bb602ffe6)
2026-06-03 11:17:48 +02:00
Cheng-Hsuan Tsai 0066a640a2 docs: update Aria Menu focus/hover style and add context menu example
(cherry picked from commit af62d88bbd)
2026-06-03 11:16:19 +02:00
Angular Robot a301ba2878 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-02 12:27:30 +02:00
Cheng-Hsuan Tsai 04028c75d7 docs: add testing guides to Angular Aria
(cherry picked from commit a76bc3c849)
2026-06-02 11:25:05 +02:00
Michael Small 36ff378564 docs: fix min/max form template examples
(cherry picked from commit 42391329c2)
2026-06-02 11:23:09 +02:00
Joey Perrott 689d41dd1f fix(docs-infra): secure update-assets script against RCE and SSRF
- Validate storedSha and storedBranch from _build-info.json.
- Validate latestSha returned from GitHub API.
- Validate branch in GithubClient.getShaForBranch and baseSha/headSha in GithubClient.getAffectedFiles.
- Use execFileSync instead of execSync to avoid shell execution.

TAG=agy
CONV=4e3e69ba-3f3d-416b-9ce4-9ef75486d2f3

(cherry picked from commit 3093edcad0)
2026-06-02 11:22:04 +02:00
Ben Hong 3b79a6921a docs: add conditional validation to signal forms validation guide
(cherry picked from commit c0eef66bbe)
2026-06-02 11:20:57 +02:00