38035 Commits

Author SHA1 Message Date
Alan Agius d366e4bd02 release: cut the v22.1.0 release v22.1.0 2026-07-29 22:39:16 +02:00
Kam 7825e607c8 docs: invoke signal inputs in adev examples and tutorials
Several adev example and tutorial files read a signal input as a bare
reference (this.foo) instead of invoking it (this.foo()). Because an
InputSignal is a function object, the bare reference is always truthy
and never yields the underlying value, so the surrounding guard or
binding silently did the wrong thing:

- animations open-close(.1/.3): the `!this.logging` guard in
  onAnimationEvent was always false, so the early return never fired.
- form-validation forbidden-name.directive: the `this.forbiddenName`
  ternary condition was always truthy, so validation ran even when no
  forbidden name was configured.
- first-app steps 12 and 14 housing-location: `housingLocation.photo`
  read `.photo` off the signal function (undefined), leaving the
  listing image src empty.

Invoke the signals so the examples reflect correct signal-input usage.

(cherry picked from commit 0d26130a4c)
2026-07-29 09:59:22 -07:00
SkyZeroZx c73dd603a4 refactor(forms): modernize signal forms tests to rely on whenStable
Rely on zoneless test scheduling instead of manually triggering change detection. Keep Signals Forms tests aligned with the async-first testing pattern.

(cherry picked from commit 59f6ef690b)
2026-07-29 09:57:42 -07:00
Shuaib Hasan Akib 098d28febf docs: fix self-referential link in defer block description
Replace broken  link with inline code
formatting. The link was pointing to the page itself, as no dedicated block concept page exists at that URL.
corrects 'everytime' to 'every time'.

Update tools/manual_api_docs/blocks/let.md

Co-authored-by: Matthieu Riegler <kyro38@gmail.com>
(cherry picked from commit 21eed5f8d4)
2026-07-29 09:45:17 -07:00
Kam fcaf15a0a4 fix(docs-infra): fix undefined CSS custom properties in shared-docs styles
Two custom properties in the shared-docs styles reference tokens that are
defined nowhere, so the declarations are invalid at computed-value time.

_kbd.scss sets the <kbd> text color with var(---tertiary-contrast); the extra
leading dash points at an undefined property with no fallback, so the color
resolves to the inherited value instead of the intended --tertiary-contrast.

_colors.scss builds --light-pink-to-light-purple-horizontal-gradient from
var(--light-purple), which is not defined anywhere (the sibling token is
--light-violet, defined in the same file), invalidating the gradient. The
gradient is not currently referenced, so this corrects a latent malformed
declaration rather than a visible bug.

Point both at the defined tokens: --tertiary-contrast and --light-violet.

(cherry picked from commit e70994bdc3)
2026-07-29 09:44:41 -07:00
Shuaib Hasan Akib 79a37f3d0b refactor(common): replaces the deprecated positional subscribe arguments with the
recommended observer object

(cherry picked from commit ec87f04200)
2026-07-29 09:43:57 -07:00
SkyZeroZx 2591fa6bd9 docs: clarify behavior of credentials option during SSR on Node.js
(cherry picked from commit 90ac011fa9)
2026-07-29 09:41:33 -07:00
Kam a7d67f9ccc fix(docs-infra): fix malformed --webgl-page-background declaration
In the light theme block of _colors.scss, --webgl-page-background and
--webgl-gray-unfilled were written on a single line without a separating
semicolon, and --webgl-page-background wrapped --page-background in an
invalid nested var(). As a result --webgl-page-background got a garbage
value and --webgl-gray-unfilled was never defined in the light theme.

Split them into two well-formed declarations and drop the nested var(),
matching the structure already used in the dark theme block.

(cherry picked from commit 91822538fe)
2026-07-29 09:04:14 -07:00
Kam 9658ad0ca8 fix(docs-infra): define missing win95 variables in aria autocomplete examples
The retro-themed aria autocomplete examples style the clear button with
var(--win95-gray), var(--win95-dark-gray), var(--win95-light), and
var(--win95-shadow), but none of the three example stylesheets defines
those custom properties. The variables resolve to nothing, so the button
falls back to inherited theme colors — color: var(--win95-shadow) becomes
the light-theme text color in dark mode, leaving the button unreadable.

Define the four variables in :host of each example, matching the values
already used by the sibling aria tree examples, so the clear button keeps
its Windows 95 look in both light and dark themes.

(cherry picked from commit 8cd4c89c29)
2026-07-29 09:02:58 -07:00
Kam f5a968b003 fix(docs-infra): replace undefined --gray-50 in retro aria examples
The retro variants of the toolbar, select, and multiselect aria examples
tint the pressed button background with
color-mix(in srgb, var(--retro-button-color) 60%, var(--gray-50)), but
--gray-50 is defined nowhere. Per the CSS spec, a var() with no fallback
pointing at an undefined property invalidates the whole color-mix(), so the
declaration is dropped and the pressed-state tint never applies.

Define a local --retro-pressed-tint token in each example's :host (#fbfbfb,
the value $gray-50 resolved to) with a :host-context(.docs-dark-mode) override
to #151417, and use it for the pressed-state mix. This keeps the example
self-contained rather than depending on adev's global token scope, while
staying theme-aware in both light and dark, following the same token-flipping
pattern used in code-editor.component.scss.

(cherry picked from commit 48c1e5bb0f)
2026-07-29 09:00:00 -07:00
Angular Robot b11cdbd758 build: update pnpm to v11.17.0
See associated pull request for more information.
2026-07-29 08:57:34 -07:00
Kristiyan Kostadinov bbbd357bd2 fix(forms): add utility to assert that value is a field tree
Adds the `isFieldTree` utility that allows users to assert whether a value is a field tree. This is something that has come up on Material recently and will be useful for users as well.

Fixes #69984.

(cherry picked from commit 2a141847a5)
2026-07-29 08:53:29 -07:00
Matthew Beck b569f6e82b test(compiler-cli): add compliance case for @HostListener on a property
`@HostListener` is not limited to methods — it is equally valid on a property
holding a function, which is the idiomatic way to keep `this` bound:

    @HostListener('window:beforeunload', ['$event'])
    private onUnload = (event: BeforeUnloadEvent) => {...};

Every existing host-listener compliance case declares the handler as a method,
so the property form was uncovered. This adds a case exercising both a public
and a private function-valued property, one of them with a global (`window:`)
event target, and locks in the emitted chained `ɵɵlistener` calls plus
`ɵɵresolveWindow`.

Verified against all four compliance modes (full, partial/linked,
declaration-only); GOLDEN_PARTIAL.js regenerated via the golden update rule.

(cherry picked from commit d44b3224d9)
2026-07-29 08:52:58 -07:00
Matthieu Riegler 6dcb534e12 refactor(common): remove duplicate helper function
We have `useAutoTick` in our private shared utils.

(cherry picked from commit 36474f7011)
2026-07-29 08:49:21 -07:00
Maikel van Dort a3fb4fe052 docs: remove semicolon text node
(cherry picked from commit 9373d22a48)
2026-07-29 08:48:39 -07:00
Angular Robot 77c5815faf build: lock file maintenance
See associated pull request for more information.
2026-07-29 08:47:16 -07:00
Matthieu Riegler ada038fca8 refactor(core): Migrate more tests off fakeAsync
This will prevent to polute the agent context with outdated/bad practices.

(cherry picked from commit c1025a0510)
2026-07-29 08:46:06 -07:00
Alan Agius f6fa9eca7d docs: update default value for strictTemplates
Updates the strictTemplates documentation in Angular compiler options to note that the default is true, replacing the reference to the obsolete ng new --strict flag.

(cherry picked from commit 2bcd12a6a5)
2026-07-29 08:42:16 -07:00
Jaime Burgos ec16a3d6c6 fix(http): enable xsrf for root-provided HttpClient
Include the XSRF interceptor in the root token factory so the automatically provided HttpClient retains the documented default protection without requiring provideHttpClient().

(cherry picked from commit de240a5d0e)
2026-07-29 08:40:14 -07:00
SkyZeroZx 39e362eea5 fix(http): match header values exactly when deleting
Normalize value-specific HttpHeaders deletions before filtering. The string overload previously used String#indexOf and removed shorter values contained within the requested deletion value, potentially widening outgoing request metadata.

Preserve delete-all behavior only when no value is supplied, and cover string, array, and empty-string deletion.

(cherry picked from commit f33ee95045)
2026-07-29 08:39:13 -07:00
SkyZeroZx be46ca8696 fix(http): preserve immutability of materialized clones
Prevent lazy HttpHeaders and HttpParams clones from reusing value arrays owned by a materialized source. Append and value-specific delete operations previously mutated those shared arrays, violating the immutable API contract and allowing request metadata to bleed into later requests.

Share value arrays until an update mutates a specific header or parameter, then copy only that array. Cover the affected append and delete paths with regression tests that materialize the source first.

(cherry picked from commit ff02a16749)
2026-07-29 08:39:12 -07:00
Jaime Burgos 5496765f97 docs: Adds HTTP communication guidance to Angular Skills
(cherry picked from commit 840f071566)
2026-07-29 08:37:19 -07:00
SkyZeroZx 091456a214 fix(core): account for namespaces in host binding sanitization (#69558)
Make runtime URL sanitizer selection namespace-aware so SVG and MathML host bindings match the security schema.

Cover SVG href/xlink:href and MathML href host binding cases, including dynamic hostElement resolution.

PR Close #69558
2026-07-29 08:36:34 -07:00
SkyZeroZx 23cf1a828b fix(core): sanitize host bindings on concrete hosts (#69558)
Host binding sanitization previously used the declaring directive or component selector to choose a compile-time security context. The same host binding can execute on a different concrete element through hostDirectives, inherited host bindings, dynamic directives, or createComponent hostElement usage.

Compute host binding security contexts against possible concrete hosts and defer URL versus ResourceURL selection to runtime when necessary. Resolve dynamic root host TNodes to their native tag before sanitizer and security-sensitive attribute checks.

Fixes angular#69550

PR Close #69558
2026-07-29 08:36:34 -07:00
Suraj Yadav 5d5b2ea72d fix(migrations): correctly detect then/else keywords in control flow migration
The control flow migration determines whether an `*ngIf` uses a `then`
and/or `else` clause by regex matching the raw microsyntax string for
the literal keywords `then`/`else`. The regexes only checked that the
keyword was preceded by a non-word character, but not that it was
followed by one.

As a result, a template reference name that merely starts with `then`
(e.g. `else thenBlock`) or `else` was misidentified as the `then`/`else`
keyword itself. This caused the migration to take the wrong code path
(e.g. then+else instead of else-only), which in turn made
`getTemplateName()` compute a `slice(start, end)` with `start > end`,
producing an empty template name. That empty placeholder was never
resolved and was silently emitted as an invalid
`<ng-template [ngTemplateOutlet]=""></ng-template>`, dropping the
original template content without any warning.

Add a negative lookahead `(?![\w\d])` to both regexes so `then`/`else`
are only matched as whole keywords, not as a prefix of a longer
template reference name.

Fixes #69914

(cherry picked from commit 5ad8231397)
2026-07-24 13:56:23 -07:00
Matthew Beck 1caafa6d8a test(compiler-cli): format compliance TEST_CASES.json with prettier
Reformats the TEST_CASES.json files touched by the following change so they
satisfy the repo's prettier check (short inputFiles/files arrays collapsed to a
single line). Pure formatting; the parsed JSON is unchanged. Split into its own
commit so the coverage change that follows is easy to review.

(cherry picked from commit 5245ca5ba7)
2026-07-24 13:55:37 -07:00
Kristiyan Kostadinov a99fb915c0 fix(language-service): account for strictTemplates being enabled by default
We were raising the suggestion about enabling `strictTemplates` when `strictTemplates` is ommitted, however the option is now enabled by default.

Fixes #69905.

(cherry picked from commit e606a020e9)
2026-07-24 13:45:29 -07:00
Angular Robot da08a8fa59 build: update all github actions
See associated pull request for more information.
2026-07-24 13:44:01 -07:00
Ben Hong b2978dbfe1 docs: modernize directives guides (#69822)
Co-authored-by: Matthieu Riegler <kyro38@gmail.com>

PR Close #69822
2026-07-24 10:36:59 -07:00
Ben Hong 522041cefe docs: smooth out directives guide narrative flow (#69822)
PR Close #69822
2026-07-24 10:36:59 -07:00
Kam 125a794891 docs: use https for external links in adev
Several guides, examples, and the update-guide recommendations linked to
external resources over insecure http. Switch them to https.

(cherry picked from commit 28d59e8d63)
2026-07-24 08:28:12 -07:00
mfstapert 50f990a67a docs: update attribute testing guide to include canonical example with local component
(cherry picked from commit 738b8fe9d2)
2026-07-24 08:27:20 -07:00
Jens Kuehlers 2562246429 docs: add v23 release and change to yearly release cycle
## Summary

This PR adds v22.x and v23 release dates. It also changes Angular's release cadence to a yearly cycle.

## Why we are making this change

The community has long requested less frequent major releases due to the impact of breaking changes and upgrades for their projects as well as for enterprise customers. Additionally, a longer release cycle provides increased API stability for developers using agentic workflows, while still delivering a reasonable cadence of API upgrades and migrations.

(cherry picked from commit 25dbe79507)
2026-07-24 08:26:37 -07:00
Kristiyan Kostadinov 350ea416b6 refactor(core): align navigation types with built in ones
Aligns our clone of the navigation API types with the built-in TypeScript types. This is related to an internal issue.

(cherry picked from commit d79b3b65e9)
2026-07-24 08:26:05 -07:00
Pawel Kozlowski 1b85b3cd86 release: cut the v22.1.0-rc.0 release v22.1.0-rc.0 2026-07-22 16:41:22 +02:00
Pawel Kozlowski 509cad6e15 docs: release notes for the v22.0.8 release 2026-07-22 16:35:02 +02:00
Pawel Kozlowski e428df2b89 build: update pnpm-lock.yaml
Update pnpm lock after it got desychronized in
791b0646c8 build: update all non-major dependencies
2026-07-22 16:18:13 +02:00
Kam ab52df470a fix(docs-infra): fail the guide build when a markdown file starts with a BOM
A leading UTF-8 byte order mark (U+FEFF) before the first `#` stops the
Markdown parser from recognizing the heading, so the guide renders its
title as a paragraph and drops the standard docs header. The character
is invisible, so it cannot be caught in review.

Add a check in the guides generation pipeline that throws when a source
file starts with a BOM, failing the build with the offending file name.
This sits alongside the existing unknown-anchor check and prevents the
regression fixed in #69889 from recurring.
2026-07-22 14:26:19 +02:00
Kam f12db89659 docs: fix first heading rendering as paragraph on two template guides
The ng-container and binding template guide files each began with a
UTF-8 BOM (EF BB BF) before the leading `#`. The docs markdown parser
only promotes `#` to an H1 when it is the first character on the line,
so the BOM demoted the title to paragraph text (`<p># ...</p>`) and the
standard docs header (breadcrumbs, page title, edit button) never
rendered.

Stripping the BOM restores `#` as the first character, so both pages
now generate the proper `<header class="docs-header">` block. Verified
by rebuilding //adev/src/content/guide/templates:templates and
inspecting the generated HTML.

Fixes #69889
2026-07-22 14:26:19 +02:00
Angular Robot 9a1e620603 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-07-22 13:25:54 +02:00
hawkgs e23541b263 fix(zone.js): vitest patching of describe/it curried calls
Separate direct from curried calls of `describe`/`it` modifiers
(direct: `skip`, `only`, etc.; curried: `runIf`, `each`, etc.)
and perform the required patching to them.

Fixes: #69748
2026-07-22 12:34:00 +02:00
Jaime Burgos d14696e430 fix(common): preserve crossorigin on image preloads
Propagate the crossorigin attribute from priority NgOptimizedImage hosts to SSR-generated preload links. Keep preload and image requests in the same credentials mode to avoid an anonymous image issuing an earlier credentialed request.
2026-07-22 12:31:52 +02:00
Kam 6557df5dbe docs: update stale Twitter reference to X in the URL matcher guide
Twitter is now X. In the custom-route-matcher guide, point the author-credit
link at x.com and refer to an "X (formerly Twitter) handle" (clarified once,
then "X handle"), matching the "X (formerly Twitter)" wording already used in
the footer, navigation, and update guide.
2026-07-22 12:01:16 +02:00
Nikita Barsukov cb1841d10b docs: outdated section in the Signal Forms | Custom controls page 2026-07-22 12:00:06 +02:00
SkyZeroZx d955d67b57 docs: clarify usage of 'same-origin' mode and add SSR considerations 2026-07-22 11:58:56 +02:00
SkyZeroZx 6371f0beb1 docs: add skills for Angular pipes 2026-07-22 11:52:33 +02:00
SkyZeroZx 6ac3e26fe0 docs: clarify pipe usage to avoid DI misuse 2026-07-22 11:50:12 +02:00
Suraj Yadav 49672c437b fix(migrations): correctly migrate ngClass with mixed space-separated keys
Preserve NgClass import on partial migration and increment
skippedNgClassCount when an unmigrable mixed binding is encountered.
2026-07-21 19:20:20 +02:00
splincode 8201cebc49 refactor(compiler): enforce exhaustive defer trigger handling
Store the trigger kind before each switch and assign the value to `never` in the fallback branch.

This removes the `any` casts and makes the switches exhaustive. Adding a new `DeferTriggerKind` without handling it in either phase now produces a TypeScript compilation error.

Runtime behavior and error messages remain unchanged.
2026-07-21 19:19:02 +02:00
Angular Robot 9bf8b8ca56 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-07-21 17:20:55 +02:00