Commit Graph

37780 Commits

Author SHA1 Message Date
Alex Rickabaugh e9509a96aa release: cut the v22.1.0-next.3 release v22.1.0-next.3 2026-06-26 10:24:17 -07:00
Alex Rickabaugh 5a8bdd18f2 docs: release notes for the v22.0.4 release 2026-06-26 10:18:12 -07:00
aparziale 26b0c719ef fix(migrations): resolve migration failure when tsconfig specifies rootDir
When `rootDir` was set in a project's tsconfig (e.g. `rootDir: "src"`),
tsurge-based migrations would fail because `projectRoot` was derived from
`rootDir`, causing `rootRelativePath` to be computed relative to `src/`
instead of the workspace root. This produced paths like `app/app.ts`
instead of `src/app/app.ts`, which the DevKit tree could not resolve.

Fix by overriding `info.projectRoot` to `absoluteFrom(info.program.getCurrentDirectory())`
immediately after program creation, ensuring workspace-relative paths are
used for all tree updates.
2026-06-26 09:14:46 -07:00
kirjs 28a90e30bb release: cut the v22.1.0-next.2 release v22.1.0-next.2 2026-06-25 11:34:11 -04:00
Alan Agius 7f2d34a649 docs: release notes for the v22.0.3 release 2026-06-25 17:12:11 +02:00
JoostK ecd047578e fix(compiler): account for NgModule dependencies in JIT-compiled partial declarations
When partial declarations are not preprocessed to AOT by the linker, the `ngDeclareComponent`
call causes them to be compiled ad-hoc. In this mode, NgModule imports in standalone components
would be dropped, deviating from the linker. This commit changes the ad-hoc compilation of
component declarations to pass the NgModule imports along just like the linker does.

Fixes #69451
2026-06-24 14:46:43 -04:00
Matthieu Riegler f9c4b71488 refactor(compiler): desable the legacy template syntax
This disables the legacy `bind`, `bindon-`, `on-`, `let-` `ref-` syntax in g3 ONLY.
This is mostly to evaluate the blast radius
2026-06-24 14:35:13 -04:00
Matthieu Riegler 4744bab38e refactor(core): Tree shake the SimpleChanges & co.
Any application that doesn't use the `ngOnChanges` hook shouldn't pull its code.
2026-06-24 13:04:35 -04:00
Matthieu Riegler 63c7ac325d refactor(forms): widen AsyncValidatorOptions.factory
This is to accept `Resource` and not only `ResourceRef`.

fixes #69443
2026-06-24 13:03:36 -04:00
arturovt 2d33fd55ff fix(zone.js): harden zoneSymbolEventNames and patches against __proto__ key
Initialize `zoneSymbolEventNames` and `patches` with `Object.create(null)` instead of `{}`.

This is a hardening change rather than a fix for an exploitable vulnerability. Calling `addEventListener('__proto__', fn)` is not directly attacker-controlled; its presence already implies an application bug. However, if such a call does occur, the current implementation can behave unexpectedly depending on the environment.

For `zoneSymbolEventNames`, accessing `zoneSymbolEventNames['__proto__']` on a plain object invokes the inherited `__proto__` accessor and returns `Object.prototype`, which is truthy. This causes `prepareEventNames()` to be skipped, leaving `symbolEventName` undefined and eventually leading to a runtime error when `window['undefined'] = []` is executed.

In Node.js environments running with `--disable-proto=throw`, the assignment:

```ts id="z8n4qm"
zoneSymbolEventNames['__proto__'] = {};
```

throws immediately because it triggers the disabled `__proto__` setter.

The `patches` registry has a similar issue. A `__proto__` key passed to `__load_patch()` bypasses the duplicate-patch check and reaches:

```ts id="f3v7kx"
patches['__proto__'] = fn(...);
```

which invokes the `__proto__` setter and changes the prototype of the `patches` object.

Using `Object.create(null)` removes the inherited `__proto__` accessor entirely, causing these keys to behave like ordinary properties rather than interacting with JavaScript's prototype machinery.

As part of this change, `patches.hasOwnProperty(name)` is also updated to:

```ts id="n2c8wp"
Object.prototype.hasOwnProperty.call(patches, name)
```

since null-prototype objects do not inherit `hasOwnProperty`.
2026-06-24 12:19:30 -04:00
arturovt 8d31b82116 fix(upgrade): support model() signals in downgradeComponent
`model()` signals are special because they combine a signal input with a writable output through an internal `OutputEmitterRef`. During upgrade, `setupOutputs()` subscribes to that emitter to keep Angular → AngularJS two-way binding working.

The issue was that `updateInput()` could overwrite the signal property directly when `isSignal` was `false` (which happens in JIT mode and when `unsafelyOverwriteSignalInputs` is enabled). Once that happened, the original `OutputEmitterRef` was lost, so the two-way binding stopped working.

The fix detects `model()` signals at runtime by checking for both `[SIGNAL]` and a writable `.set()` method, which distinguishes them from read-only `input()` signals. When those traits are present, updates are always applied through `applyValueToInputSignal()` instead of replacing the property directly, regardless of the `unsafelyOverwriteSignalInputs` setting.

Fixes #60599
2026-06-24 12:17:35 -04:00
arturovt 97a3fd6a55 feat(router): handle null and undefined inputs in RouterLinkActive
Without this change, components that use RouterLinkActive in multiple
contexts (e.g. both a navigation menu and body content) are forced to
branch the template for every conditional input:

  @if (activeClass) {
    <a [routerLink]="href" [routerLinkActive]="activeClass"
       [routerLinkActiveOptions]="activeOptions"
       [ariaCurrentWhenActive]="ariaCurrent">
      <ng-content />
    </a>
  } @else {
    <a [routerLink]="href"><ng-content /></a>
  }

Every additional input multiplies the branching, and each @if/@else
injects unwanted comment nodes into the DOM. There is no way to
conditionally attach a directive in Angular templates, making imperative
TypeScript instantiation the only alternative.

Accepting null/undefined collapses this to a single template branch:

  <a [routerLink]="href"
     [routerLinkActive]="activeClass"
     [routerLinkActiveOptions]="activeOptions"
     [ariaCurrentWhenActive]="ariaCurrent">
    <ng-content />
  </a>

When activeClass is undefined (e.g. in content areas), the directive
stays mounted but applies no CSS classes. When it is a string (e.g. in
the navigation), normal active-class behavior applies — no branching, no
extra DOM nodes, no TypeScript workarounds.

- `routerLinkActive`: null/undefined now sets an empty class list.

- `routerLinkActiveOptions`: null and undefined are treated differently:
  - undefined → falls back to the default subset match ("not set")
  - null → explicit opt-out, link is never considered active

Closes #66233
2026-06-24 12:15:49 -04:00
SkyZeroZx 6f98f98f1f fix(service-worker): preserve referrer policy in asset requests
Preserve explicit referrer policy when the service worker reconstructs asset requests for cache-busted and redirected asset fetches.

For example, an application can load a script or image with referrerPolicy: 'same-origin' or 'origin' to limit referrer data. Dropping that policy can expose more of the current URL to that resource host.
2026-06-24 12:15:15 -04:00
SkyZeroZx 716f9eb032 fix(service-worker): preserve referrer in asset requests
Preserve referrer metadata when the service worker reconstructs asset requests for cache-busted and redirected asset fetches.

For example, an attacker with access to asset host logs could receive a reset token embedded in a page URL if the reconstructed request falls back to default referrer behavior instead of carrying referrer: ''.
2026-06-24 12:15:15 -04:00
aparziale 8b2785b597 fix(compiler-cli): report diagnostic instead of crashing on malformed host binding
`parseHostBindings` throws plain `Error`s for malformed host bindings
(e.g. a property binding with a non-static value, as can happen while
editing in the language service). These were uncaught during directive
analysis, crashing the compiler and the Angular Language Service.

Wrap the call and surface the error as a `FatalDiagnosticError` so it
becomes a diagnostic and analysis can complete normally.

Fixes #69106
2026-06-24 12:14:23 -04:00
Kam 12fcec8ce9 docs(forms): clarify debounce('blur') usage with custom FormValueControl
A custom FormValueControl only participates in debounce('blur') if it emits
the touch output on the native blur event. This was undocumented, and the
touch name reads like a focus event, so users wired it to (focus) and
blur-based debouncing silently did nothing.

Add a dedicated guide section with a working example, link the debounce API
reference to it, and clarify the touch JSDoc that it must fire on blur, not
focus.

Fixes #69370
2026-06-24 11:38:48 -04:00
Modeste ASSIONGBON edea40b5a0 docs: add doc to focusBoundControl feature 2026-06-24 11:26:26 -04:00
cexbrayat a3a9308894 docs: clarify signal forms limit metadata keys
Explain that MIN and MAX are selection keys which point to the type-specific limit metadata keys, such as MIN_NUMBER, MIN_DATE, MAX_NUMBER, and MAX_DATE.

Also list minDate() and maxDate() alongside min() and max() in the Signal Forms metadata docs, so the validator tables match the actual metadata model.
2026-06-24 11:25:56 -04:00
Shuaib Hasan Akib 64bb7adda0 docs: standardize padding and margin for insert-container 2026-06-24 11:25:23 -04:00
Saurabh Singh 7057b1257f docs(core): document resource chaining with chain() in params context
Adds a 'Chaining resources' section to the resource guide covering:
- Basic usage of chain() to depend one resource on another
- Status propagation for all ResourceStatus values (idle, loading,
  reloading, error, resolved, local)
- Chaining vs reading .value() directly, shown as an avoid example
- Guidance on passing the chained value directly as params

Also adds an @see link from ResourceParamsContext to the new section.

Closes #69329
2026-06-24 11:23:49 -04:00
arturovt ea177257e9 docs: add error guide for NG05102
Adds an error reference page for NG05102 (UNSUPPORTED_EVENT_TARGET) explaining
what triggers it and how to fix it. Also marks the error code as negative (-5102)
so that in dev mode the error message automatically links to the new guide page
on angular.dev/errors, consistent with other documented runtime errors.
2026-06-24 10:58:27 -04:00
SkyZeroZx f76e8a98c1 fix(http): prevent caching of responses with Set-Cookie headers
Skip HttpTransferCache serialization for HTTP responses that contain a
Set-Cookie header.

Cookie-setting responses commonly represent session-specific,
user-specific, or security-sensitive state. Serializing their bodies into
SSR TransferState can embed sensitive data into the generated HTML, where
it may be reused during hydration or replayed by a shared cache/CDN.
2026-06-24 10:57:45 -04:00
hawkgs ff115925e7 refactor(devtools): restructure profiler and directive forest code
- Rename `DirectiveForestHooks` to `DirectiveForestManager`
- Keep profiler reference standalone; move it out from `DirectiveForestHooks`/`DirectiveForestManager`
- Convert profiler-specific `IdentityTracker` behavior to a more generalized one
- Separate timing API functionality from the `DirectiveForestHooks`/`DirectiveForestManager` initialization fn
- Reorganize files; rename `/hooks` to `/profiling`
- Use concrete types for directive and component instances (incomplete coverage; based on `any` at the moment)
- Other more minor changes
2026-06-24 10:57:08 -04:00
Matthieu Riegler 826017dd31 refactor(compiler): Move the attribute comment to the HTML AST
This is to help the support for comment formating by third-party tools like prettier.
2026-06-24 10:56:34 -04:00
Angular Robot 295dad7389 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-24 10:48:36 -04:00
Angular Robot d7d6a08074 build: update dependency node to v22.23.1
See associated pull request for more information.
2026-06-24 10:36:02 -04:00
Alan Agius b8d40c835b build: disable pnpm dependency verification during automated PR merges
Trying to unblock caretaker.
2026-06-24 10:34:12 -04:00
Angular Robot 681148c674 build: lock file maintenance
See associated pull request for more information.
2026-06-23 15:00:31 -04:00
yamanerkam af14ce16cf fix(docs-infra): keep footer headings on a single line
The "Community translations" column heading wrapped to two lines while
the other footer headings stayed on one. Add a `white-space: nowrap`
rule on the footer headings, scoped to the wide (4-column) layout. The
breakpoint is driven by a shared `$columns-breakpoint` variable so the
nowrap rule and the grid's 2-column collapse stay in sync.
2026-06-23 14:59:36 -04:00
Alan Agius 06e9da4428 docs: document support for standard forwarded proxy header
Update the security guide to document that the Angular SSR request handling pipeline now supports and validates the standard RFC 7239 `Forwarded` header.

Previously, only non-standard `X-Forwarded-*` headers were supported for resolving proxy-forwarded protocols, hosts, and ports. With this update:
- The standard `Forwarded` header parameters (such as `host` and `proto`) are validated and take precedence over corresponding `X-Forwarded-*` headers when trusted.
- The `trustProxyHeaders` option and `NG_TRUST_PROXY_HEADERS` environment variable can be configured to trust the `Forwarded` header.

For more details on the implementation, see the corresponding PR:
https://github.com/angular/angular-cli/pull/33406
2026-06-23 14:16:51 -04:00
Kristiyan Kostadinov 91d168e74b fix(core): avoid uncaught promise errors in injectAsync prefetching
Fixes a minor issue where the `preload` function in `injectAsync` might cause an uncaught promise error.

I also fixed that in `onIdle` we were passing the wrong function into `assertInInjectionContext`.
2026-06-23 12:57:26 -04:00
yamanerkam 7421124956 docs: remove space before question mark in landing page heading
The bottom CTA heading on the landing page read "Want to learn more about
Angular ?" with a space before the question mark, while the matching heading
higher up the page correctly had no space. Removed the space so both read
"Want to learn more about Angular?".
2026-06-23 12:56:01 -04:00
arturovt dead64fbdb docs: add error guide for NG05101
Adds a new error reference page for NG05101 (NO_PLUGIN_FOR_EVENT),
which is thrown when no registered EventManagerPlugin supports the
event name passed to addEventListener. The page covers the two common
causes: a typo in the event binding and a missing plugin provider.
2026-06-23 11:25:48 -04:00
SkyZeroZx 7fc46ed3a1 docs: Add docs for markAsTouched with skipDescendants 2026-06-23 11:22:05 -04:00
Angular Robot e5d7b3a47b build: update dependency node to v22.23.0
See associated pull request for more information.
2026-06-23 10:45:43 -04:00
yamanerkam a4e9ff1e0c docs: add missing space before decorator link in components guide
The `@Component` inline-code span was directly adjacent to the
`[decorator](...)` link, rendering as a mashed-together token in the
source. Added a space so it reads "A `@Component` [decorator] that..."
as intended.
2026-06-23 09:48:16 -04:00
aparziale 69ac1d5ee8 docs: show selected menu item visually in context menu example
Replace console.log with a lastAction signal and render the result in a styled <p> element with a fade-in animation.
2026-06-22 16:46:53 -04:00
Kristiyan Kostadinov 792edaba48 refactor(migrations): account for inheritance in service migration
Updates the `@Service` migration to account for inheritance when determining if a class can be migrated.
2026-06-22 16:34:50 -04:00
Kristiyan Kostadinov c75ff0255c feat(migrations): add migration from injectable to service
Sets up an automated migration to convert `@Injectable` usages to `@Service`.
2026-06-22 16:34:50 -04:00
Kam 8b1726a1cf docs(forms): update package docs for Signal Forms graduation
After #68581 graduated the Signal Forms APIs to public API and #68654 removed
the experimental warnings from the Signal Forms documentation in adev, the
package READMEs still framed the API as experimental.

Update `packages/forms/signals/PACKAGE.md`: drop the experimental title and
intro, remove the now-shipped entries from "Not yet supported" (interop with
reactive/template forms and strongly-typed binding to UI controls), and remove
the remaining experimental and exploratory wording from the FAQ.

Update `packages/forms/PACKAGE.md`: it listed only two ways to build forms
(reactive and template-driven). Add signal forms as the third.

Fixes #68724
2026-06-22 16:29:18 -04:00
Angular Robot 089b1d1b9f build: update bazel dependencies
See associated pull request for more information.
2026-06-22 16:28:43 -04:00
Kam 642165f6fc fix(docs-infra): remove white flash on example viewer tab labels
The code tabs rendered by the example viewer (e.g. the npm/pnpm/yarn/bun
install tabs) paint their active label as transparent text clipped to a
gradient. Material's MDC tab styles add `transition: color 0.15s linear`
to `.mdc-tab__text-label`, plus a 100ms delay on the active tab. Because
that transition animates `color` from the solid label color to
transparent, the solid color stays visible on top of the gradient for
~100ms when a tab is activated, which reads as a white flash.

Disable the transition on these labels so the color switches instantly,
and target `.mdc-tab__text-label` directly (instead of a generic `span`)
so `color: transparent` drives the gradient clip cleanly.
2026-06-22 16:27:57 -04:00
Angular Robot a286a328a4 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-06-22 16:11:26 -04:00
Angular Robot 738479f21c build: update pnpm to v11.8.0
See associated pull request for more information.
2026-06-22 16:08:41 -04:00
Kam 50bb0d6bfe fix(docs-infra): prevent inline code in table headers from wrapping mid-word
When a documentation table has a wide content column, the narrow header
columns get squeezed and inline-code header labels break mid-word at
their hyphens. On the MCP server tools page this rendered the `local-only`
and `read-only` column headers as `local-` / `only` and `read-` / `only`.

Apply `white-space: nowrap` to `code` inside `th` so header tokens stay on
a single line. The rule is scoped to headers, whose labels are always
short, so long code signatures in body cells continue to wrap and no
table gains a horizontal scrollbar.
2026-06-22 16:05:44 -04:00
Kam aa7d9fcc61 fix(devtools): restore build under stricter ts_project deps
The rules_angular bump in #69410 made ts_project require every `deps`
entry to provide the JsInfo provider. `esbuild_base` listed
`//packages:package_json` in its deps, but `esbuild-base.config.mts` never
imports or reads package.json, so the dependency is unnecessary and now
breaks analysis (`//packages:package_json` is a `copy_to_bin` target that
provides only DefaultInfo). Remove it.
2026-06-19 11:37:17 +02:00
Kam 350763d84a fix(docs-infra): restore adev build under stricter ts_project deps
The cross-repo dependency update in #69410 bumped rules_angular, whose
ts_project now requires every entry in `deps` to provide the JsInfo
provider. Two adev targets passed deps that don't, so `bazel build
//adev:build` fails analysis and the adev CI check has been red on main
since that PR.

Make generate_nav_items return JsInfo (with the generated routes.json as
its sources) so navigation-entries can keep importing routes.json through
its deps. Also drop the spurious deps entry on llms_lib: llms.mts reads
llms-list.md at runtime via readFile rather than importing it, and the
file is already provided to the binary via data.

Fixes #69429
2026-06-19 11:37:17 +02:00
Angular Robot 7e1fcd4ce6 build: update all github actions to v6.0.9
See associated pull request for more information.
2026-06-18 14:22:31 -04:00
rudzikdawid 69a00043a4 docs(docs-infra): add missing readonly property to combobox guide
PR angular/components#33364 restored the `readonly` property for the
combobox, but the documentation was not updated to reflect this change.
This commit adds the missing `readonly` input and its description to
the Inputs / Model table in the combobox guide.
2026-06-18 14:18:36 -04:00
yamanerkam e77a8a0c7a fix(docs-infra): align the page title with its edit action
The page title row (`.docs-page-title`) relied on the default flex
alignment, so the edit icon next to the title did not line up with the
title text. Add `align-items: baseline` so the icon sits on the title's
baseline.
2026-06-18 14:06:22 -04:00