37718 Commits

Author SHA1 Message Date
Alex Rickabaugh 2b3277f5b7 release: cut the v22.0.5 release v22.0.5 2026-07-01 13:47:47 -07:00
Bhuvansh855 0554bf5cf1 docs: improve introductory resource example
(cherry picked from commit c4cb66e602)
2026-06-30 18:00:07 -07:00
Shuaib Hasan Akib ca13b42e7c fix(router): fix malformed jsdoc comment for RouterLinkWithHref export
The export statement was incorrectly placed inside the JSDoc comment block,
and there was a stray text fragment "nstead." from the deprecation message.
This moves the export statement outside the comment and removes the stray text.

(cherry picked from commit a74801c59c)
2026-06-30 17:59:40 -07:00
Kam 8dfad89a3d docs(docs-infra): show the schema function in the validation example
The "schema function" example on the Validation guide page pointed its
visibleLines and highlight ranges at the wrong source lines. The
collapsed view showed the component's imports and model signal instead
of the schema function, and the highlight marked unrelated lines, so
readers had to expand the example to find the code the section is about.

The example file was edited at some point and these line numbers were
not updated to follow it. Point visibleLines at the form() schema call
(lines 29-34) and highlight the three validator calls (lines 30, 31, 33)
so the relevant code is visible by default.

Fixes #69547

(cherry picked from commit b9125db156)
2026-06-30 17:57:59 -07:00
Kam 23fe1a9116 fix(docs-infra): improve code selection contrast in dark mode
The ::selection background mixes only 10% of the accent color into
--octonary-contrast. In dark mode --octonary-contrast resolves to
gray-900 (#151417), which is the same color code blocks use as their
background, so selected code renders ~90% code-background and is almost
invisible.

Add a .docs-dark-mode ::selection override that raises the tint to 30%
so highlighted text stays legible over the near-black surface. Light
mode is unchanged, as its selection already contrasts the white page.

Fixes #69507

(cherry picked from commit a9e3336aae)
2026-06-30 17:56:39 -07:00
Eduard Fischer-Szava 17966c2ff5 docs: fix incorrect @defer trigger names and a duplicate word in guides
The @defer guide reused the viewport section's prose in the
interaction and hover sections without updating it:

- interaction: the template reference variable is passed on the
  interaction trigger, not the viewport trigger.
- hover: the element is hovered over and the variable is passed on the
  hover trigger, not "watched to enter the viewport" / viewport.

Also removes a duplicate "keep the" in the routing
customizing-route-behavior guide.

Documentation-only; no code changes.

(cherry picked from commit 19a912a6ef)
2026-06-30 17:52:19 -07:00
Hien Pham 39f112decd docs: clear mock after each test and refine expectation for tax calculator call
- We need to clear the mock between different assertions
- We have either toHaveBeenCalledOnce or toHaveBeenCalledExactlyOnceWith matcher

(cherry picked from commit d748e8160d)
2026-06-30 17:51:40 -07:00
SkyZeroZx 7979ece76b docs: remove ChangeDetectionStrategy.OnPush from Signal Forms tutorial
(cherry picked from commit b6dbdcfe34)
2026-06-30 17:49:35 -07:00
Michael Small 4dfb0c4425 docs: remove standalone: true and explicit OnPush from forms skill
docs: remove `standalone: true` from `signal-forms.md`

docs: remove explicit `OnPush` from signal forms skill

docs: remove import of CD strategy
(cherry picked from commit 42affba3b7)
2026-06-30 17:48:54 -07:00
arturovt eb8fb9fe58 fix(common): use Object.hasOwn in I18nSelectPipe to handle null-prototype and shadowed mappings
`I18nSelectPipe.transform()` called `mapping.hasOwnProperty()` directly,
which fails in two edge cases:

- Mappings created with `Object.create(null)` have no prototype and
  therefore no `hasOwnProperty` method, causing a TypeError at runtime.
- Mappings where a key literally named `hasOwnProperty` shadows the
  built-in method return incorrect results silently.

Replace both call sites with `Object.hasOwn(mapping, key)`, which
delegates through `Object` directly and is immune to both issues.

Add two regression tests that demonstrate the broken behaviour before
the fix and pass after it.

(cherry picked from commit 311aff05aa)
2026-06-30 17:46:41 -07:00
Alan Agius bd82899807 ci: setup Node.js in adev-preview-deploy workflow using .nvmrc
Ensures that the correct Node.js version is used.

(cherry picked from commit 785d254433)
2026-06-30 17:45:23 -07:00
Angular Robot 98ea50718a build: lock file maintenance
See associated pull request for more information.
2026-06-30 17:43:43 -07:00
Alan Agius 533e17f568 docs: remove fixed font-size from table headers in docs
Removes the fixed font size from table headers to ensure they scale properly and do not appear smaller than the table content.

(cherry picked from commit 7a7a612e48)
2026-06-30 17:41:31 -07:00
Alan Agius cfb5fbb933 docs: update service documentation to compare @Service and @Injectable decorators with a feature comparison table
Closes: #69563
(cherry picked from commit c92d38c097)
2026-06-30 17:40:55 -07:00
yamanerkam 9798af94e6 fix(docs-infra): don't auto-link code symbols used as link text
When an inline code symbol is used as the text of an explicit markdown
link (e.g. [`httpResource`](/guide/http/http-resource)), the codespan
renderer recognized it as an API symbol and wrapped it in a second
anchor pointing at the API reference. This produced nested <a> tags, so
the explicit link was effectively replaced by the API symbol link.

Disable auto-linking while rendering a link's inner tokens so the
explicit href is preserved, matching the pattern already used by the
heading and docs-card renderers.

Fixes #69549

(cherry picked from commit cbd97072f4)
2026-06-30 17:39:38 -07:00
SkyZeroZx ced0180b06 fix(core): reject dynamic script host elements
The previous fix for GHSA-692r-grfm-v8x7 was incomplete because it rejected script tags only when locating an explicit host element. Dynamic component instantiation can also infer the host element from the component selector.

Move the script-host rejection to the point where ComponentFactory has resolved the host element for either path, so createComponent rejects script hosts consistently.

(cherry picked from commit d7f70616a0)
2026-06-30 17:29:41 -07:00
Andrew Scott c3be83cfe1 refactor(core): allow AnimationClassBindingFn to return undefined or null
The AnimationClassBindingFn type was too restrictive, only allowing `string | string[]`. However, the runtime (`getClassListFromValue`) safely handles `undefined` and `null` values by treating them as no animation.

This change updates the type to allow `undefined` and `null`, which is consistent with other class/style bindings in Angular and avoids requiring workarounds (like empty strings) in host bindings.

Added a compliance test case to verify that `[animate.enter]` with a potentially `undefined` value compiles correctly.

(cherry picked from commit a7bde662c3)
2026-06-30 17:28:04 -07:00
marktechson 6c83124b46 docs: updated roadmap
(cherry picked from commit d791a7f496)
2026-06-30 17:24:08 -07:00
yamanerkam d34cd66e96 fix(docs-infra): align and highlight external-link icon in nav sidebar
The open_in_new icon on external navigation items stayed grey on hover
and sat inset from the chevron column, so it never matched the chevron
items visually.

- Add a hover rule so the icon brightens to --primary-contrast along
  with the label, matching the chevron/text behaviour.
- Override the 1rem max-width reserve inherited from
  .docs-faceted-list-item-text by chaining both classes the span carries
  (.docs-external-link.docs-faceted-list-item-text), so the icon lines up
  with the chevrons at the link's end-padding. Using :host was avoided
  because it breaks the nested `a:hover &` selector.

(cherry picked from commit 00226e7d80)
2026-06-30 17:23:30 -07:00
Shuaib Hasan Akib b235278699 fix(docs-infra): support header values containing apostrophes
Update the `headerRule` regex to capture the complete quoted header value. The previous pattern excluded quote characters from the content and failed to parse headers such as:

```angular-ts {avoid, header: "Can't inject interface"}
```

The new pattern matches everything between the opening and closing quote delimiters.

(cherry picked from commit 3f9d0ee985)
2026-06-30 17:22:40 -07:00
Alex Rickabaugh af7edd90ca Revert "fix(compiler-cli): include toSignal in debugName transform"
This reverts commit 165995285c. Reason: breaking
in g3 (ngDevMode not defined)

(cherry picked from commit a5f1b20373)
2026-06-30 13:24:21 -07:00
Matthieu Riegler b5ea3408ce refactor(compiler): remove visitAttributeComment
In #69463 we forgot to rename the visitor method after renaming the node class

(cherry picked from commit 74803c75cd)
2026-06-29 16:00:07 -07:00
aparziale ca76b2cca1 docs(forms): correct signal field access in form model example
The `myForm` field is a callable `FieldTree`, so its value must be read
via `this.myForm().value()`. Fixes two examples that incorrectly used
`this.myForm.value()`.

(cherry picked from commit e653a7bf30)
2026-06-29 14:49:42 -07:00
Paweł Maniecki baf09a9939 fix(compiler-cli): include toSignal in debugName transform
the toSignal function received a debugName option in 0812ac3bec,
but was not covered by the signalMetadataTransform which sets the debugName in dev mode
automatically.

(cherry picked from commit 165995285c)
2026-06-29 14:32:22 -07:00
cynavi 0c18ccb87c docs(docs-infra): fix typo and malformed markdown bullet in angular-developer skill
(cherry picked from commit 433993efa8)
2026-06-29 14:24:27 -07:00
Hien Pham 32c1f30a39 docs: update Vitest configuration option from configFile to runnerConfig
(cherry picked from commit d109cc5e9d)
2026-06-26 10:36:53 -07:00
Bhuvansh855 592e9d2e30 docs: reorder streaming resources description
(cherry picked from commit 9142712e06)
2026-06-26 10:35:33 -07:00
Bhuvansh855 dcb026bacb docs: document resource stream usage
(cherry picked from commit 9c9ead95d6)
2026-06-26 10:35:32 -07:00
Charles 60bb1a710f docs: streamline and update mcp server setup documentation
Update and streamline the Model Context Protocol (MCP) server setup guide. This includes revising tool descriptions, replacing multiple experimental tools with a single target runner option, updating configurations for supported IDEs, and removing obsolete setup sections.

(cherry picked from commit f7cb609770)
2026-06-26 10:34:41 -07:00
Karim Daher 9dff7f48c5 docs: disable overlay close-on-escape in Aria menubar examples
The Aria menubar examples render each menu in a `cdkConnectedOverlay`,
which detaches the top-most overlay on every Escape keypress
(`disableClose` defaults to `false`). The top-level menus are always
attached, so a detached overlay never reattaches and its `viewChild`
reference becomes `undefined`. Holding Escape detaches the overlays one by
one, permanently breaking menus such as "Insert" and "Format".

Set `cdkConnectedOverlayDisableClose` on the example overlays so the menu
pattern remains the single owner of open/close state, matching the
combobox and toolbar examples. Applied to the basic, disabled, and rtl
menubar examples (and their material/retro variants).

(cherry picked from commit db2101c994)
2026-06-26 10:33:26 -07:00
tmpln e598dc843f fix(core): improve input writes migration in best effort mode
Currently, signal migration schematics in best effort mode doesn't do a very good job migrating input writes when there is a nested property access in templates.

In event handlers, no attempt is made to migrate a nested access in the left-hand-side of assignments or anything in their right-hand-side. E.g., nothing will happen here:

`(ngModelChange)="inputD.prop = $event + inputF"`.

Additionally, when a migration attempt is made, parentheses are often incorrectly placed on the parent, both in event handlers and two-way bindings:

`(ngModelChange)="inputC = $event"` is migrated to `(ngModelChange)="inputC = $event()"`.

`[(ngModel)]="inputB.prop.prop"` is migrated to `[(ngModel)]="inputB.prop().prop"`.

(cherry picked from commit 74638cab84)
2026-06-26 10:31:01 -07:00
Alex Rickabaugh 0b1cbbd12f release: cut the v22.0.4 release v22.0.4 2026-06-26 10:04:16 -07:00
aparziale fd37f09f37 fix(migrations): resolve migration failure when tsconfig specifies rootDir
When `rootDir` was set in a project's tsconfig (e.g. `rootDir: "src"`),
tsurge-based migrations would fail because `projectRoot` was derived from
`rootDir`, causing `rootRelativePath` to be computed relative to `src/`
instead of the workspace root. This produced paths like `app/app.ts`
instead of `src/app/app.ts`, which the DevKit tree could not resolve.

Fix by overriding `info.projectRoot` to `absoluteFrom(info.program.getCurrentDirectory())`
immediately after program creation, ensuring workspace-relative paths are
used for all tree updates.

(cherry picked from commit 26b0c719ef)
2026-06-26 09:14:52 -07:00
Alan Agius 5ba6443e12 release: cut the v22.0.3 release v22.0.3 2026-06-25 17:10:29 +02:00
kirjs f4f7f3755c fix(compiler): remove unused import breaking CI in 22.0.x
The import of createContentBlock from ./r3_content_blocks was erroneously included in a cherry-pick but the file does not exist in this branch.
2026-06-25 06:59:05 -04:00
JoostK f90c20df40 fix(compiler): account for NgModule dependencies in JIT-compiled partial declarations
When partial declarations are not preprocessed to AOT by the linker, the `ngDeclareComponent`
call causes them to be compiled ad-hoc. In this mode, NgModule imports in standalone components
would be dropped, deviating from the linker. This commit changes the ad-hoc compilation of
component declarations to pass the NgModule imports along just like the linker does.

Fixes #69451

(cherry picked from commit ecd047578e)
2026-06-24 14:46:48 -04:00
Matthieu Riegler 489d1707d7 refactor(compiler): desable the legacy template syntax
This disables the legacy `bind`, `bindon-`, `on-`, `let-` `ref-` syntax in g3 ONLY.
This is mostly to evaluate the blast radius

(cherry picked from commit f9c4b71488)
2026-06-24 14:35:17 -04:00
Matthieu Riegler 01d58d7ad7 refactor(core): Tree shake the SimpleChanges & co.
Any application that doesn't use the `ngOnChanges` hook shouldn't pull its code.

(cherry picked from commit 4744bab38e)
2026-06-24 13:04:40 -04:00
Matthieu Riegler 2353bf22a5 refactor(forms): widen AsyncValidatorOptions.factory
This is to accept `Resource` and not only `ResourceRef`.

fixes #69443

(cherry picked from commit 63c7ac325d)
2026-06-24 13:03:41 -04:00
arturovt b0569fdb3f fix(zone.js): harden zoneSymbolEventNames and patches against __proto__ key
Initialize `zoneSymbolEventNames` and `patches` with `Object.create(null)` instead of `{}`.

This is a hardening change rather than a fix for an exploitable vulnerability. Calling `addEventListener('__proto__', fn)` is not directly attacker-controlled; its presence already implies an application bug. However, if such a call does occur, the current implementation can behave unexpectedly depending on the environment.

For `zoneSymbolEventNames`, accessing `zoneSymbolEventNames['__proto__']` on a plain object invokes the inherited `__proto__` accessor and returns `Object.prototype`, which is truthy. This causes `prepareEventNames()` to be skipped, leaving `symbolEventName` undefined and eventually leading to a runtime error when `window['undefined'] = []` is executed.

In Node.js environments running with `--disable-proto=throw`, the assignment:

```ts id="z8n4qm"
zoneSymbolEventNames['__proto__'] = {};
```

throws immediately because it triggers the disabled `__proto__` setter.

The `patches` registry has a similar issue. A `__proto__` key passed to `__load_patch()` bypasses the duplicate-patch check and reaches:

```ts id="f3v7kx"
patches['__proto__'] = fn(...);
```

which invokes the `__proto__` setter and changes the prototype of the `patches` object.

Using `Object.create(null)` removes the inherited `__proto__` accessor entirely, causing these keys to behave like ordinary properties rather than interacting with JavaScript's prototype machinery.

As part of this change, `patches.hasOwnProperty(name)` is also updated to:

```ts id="n2c8wp"
Object.prototype.hasOwnProperty.call(patches, name)
```

since null-prototype objects do not inherit `hasOwnProperty`.

(cherry picked from commit 2d33fd55ff)
2026-06-24 12:19:35 -04:00
arturovt bcc648f4b6 fix(upgrade): support model() signals in downgradeComponent
`model()` signals are special because they combine a signal input with a writable output through an internal `OutputEmitterRef`. During upgrade, `setupOutputs()` subscribes to that emitter to keep Angular → AngularJS two-way binding working.

The issue was that `updateInput()` could overwrite the signal property directly when `isSignal` was `false` (which happens in JIT mode and when `unsafelyOverwriteSignalInputs` is enabled). Once that happened, the original `OutputEmitterRef` was lost, so the two-way binding stopped working.

The fix detects `model()` signals at runtime by checking for both `[SIGNAL]` and a writable `.set()` method, which distinguishes them from read-only `input()` signals. When those traits are present, updates are always applied through `applyValueToInputSignal()` instead of replacing the property directly, regardless of the `unsafelyOverwriteSignalInputs` setting.

Fixes #60599

(cherry picked from commit 8d31b82116)
2026-06-24 12:17:38 -04:00
SkyZeroZx a16f9b2263 fix(service-worker): preserve referrer policy in asset requests
Preserve explicit referrer policy when the service worker reconstructs asset requests for cache-busted and redirected asset fetches.

For example, an application can load a script or image with referrerPolicy: 'same-origin' or 'origin' to limit referrer data. Dropping that policy can expose more of the current URL to that resource host.

(cherry picked from commit 6f98f98f1f)
2026-06-24 12:15:20 -04:00
SkyZeroZx b4a5a2fb4e fix(service-worker): preserve referrer in asset requests
Preserve referrer metadata when the service worker reconstructs asset requests for cache-busted and redirected asset fetches.

For example, an attacker with access to asset host logs could receive a reset token embedded in a page URL if the reconstructed request falls back to default referrer behavior instead of carrying referrer: ''.

(cherry picked from commit 716f9eb032)
2026-06-24 12:15:20 -04:00
aparziale 06d854929c fix(compiler-cli): report diagnostic instead of crashing on malformed host binding
`parseHostBindings` throws plain `Error`s for malformed host bindings
(e.g. a property binding with a non-static value, as can happen while
editing in the language service). These were uncaught during directive
analysis, crashing the compiler and the Angular Language Service.

Wrap the call and surface the error as a `FatalDiagnosticError` so it
becomes a diagnostic and analysis can complete normally.

Fixes #69106

(cherry picked from commit 8b2785b597)
2026-06-24 12:14:27 -04:00
Kam d2b613900c docs(forms): clarify debounce('blur') usage with custom FormValueControl
A custom FormValueControl only participates in debounce('blur') if it emits
the touch output on the native blur event. This was undocumented, and the
touch name reads like a focus event, so users wired it to (focus) and
blur-based debouncing silently did nothing.

Add a dedicated guide section with a working example, link the debounce API
reference to it, and clarify the touch JSDoc that it must fire on blur, not
focus.

Fixes #69370

(cherry picked from commit 12fcec8ce9)
2026-06-24 11:38:52 -04:00
SkyZeroZx cd8f472ab4 docs: add documentation for HttpClient response body size limit and related error NG02825
(cherry picked from commit e5098f00d5)
2026-06-24 11:29:25 -04:00
Modeste ASSIONGBON 9a81d30a58 docs: add doc to focusBoundControl feature
(cherry picked from commit edea40b5a0)
2026-06-24 11:26:32 -04:00
cexbrayat 2d4b57c906 docs: clarify signal forms limit metadata keys
Explain that MIN and MAX are selection keys which point to the type-specific limit metadata keys, such as MIN_NUMBER, MIN_DATE, MAX_NUMBER, and MAX_DATE.

Also list minDate() and maxDate() alongside min() and max() in the Signal Forms metadata docs, so the validator tables match the actual metadata model.

(cherry picked from commit a3a9308894)
2026-06-24 11:26:01 -04:00
Shuaib Hasan Akib 8da801f396 docs: standardize padding and margin for insert-container
(cherry picked from commit 64bb7adda0)
2026-06-24 11:25:27 -04:00
Saurabh Singh 03d1a6444a docs(core): document resource chaining with chain() in params context
Adds a 'Chaining resources' section to the resource guide covering:
- Basic usage of chain() to depend one resource on another
- Status propagation for all ResourceStatus values (idle, loading,
  reloading, error, resolved, local)
- Chaining vs reading .value() directly, shown as an avoid example
- Guidance on passing the chained value directly as params

Also adds an @see link from ResourceParamsContext to the new section.

Closes #69329

(cherry picked from commit 7057b1257f)
2026-06-24 11:23:53 -04:00