This repository was archived by the owner on Apr 12, 2024. It is now read-only.
Commit 6ccbfa6
feat($compile): lower the
Previously, `xlink:href` on SVG's `<a>` and `<image>` elements, was
`$sce.RESOURCE_URL`. While this makes sense for other `xlink:href` usecases, it
was an overkill for these elements.
This commit lowers the `xlink:href` security context for these specific
elements, treating it in the same way as `a[href]` or `img[src]` respectively.
The `xlink:href` security context for other elements is not affected.
BREAKING CHANGE:
In the unlikely case that an app relied on RESOURCE_URL whitelisting for the
purpose of binding to the `xlink:href` property of SVG's `<a>` or `<image>`
elements and if the values do not pass the regular URL sanitization, they will
break.
To fix this you need to ensure that the values used for binding to the affected
`xlink:href` contexts are considered safe URLs, e.g. by whitelisting them in
`$compileProvider`'s `aHrefSanitizationWhitelist` (for `<a>` elements) or
`imgSrcSanitizationWhitelist` (for `<image>` elements).
Closes #15736xlink:href security context for SVG's a and image elements1 parent cc793a1 commit 6ccbfa6
2 files changed
+46
-8
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1673 | 1673 | | |
1674 | 1674 | | |
1675 | 1675 | | |
1676 | | - | |
| 1676 | + | |
| 1677 | + | |
1677 | 1678 | | |
1678 | | - | |
| 1679 | + | |
1679 | 1680 | | |
1680 | 1681 | | |
1681 | 1682 | | |
| |||
3256 | 3257 | | |
3257 | 3258 | | |
3258 | 3259 | | |
3259 | | - | |
3260 | | - | |
| 3260 | + | |
| 3261 | + | |
| 3262 | + | |
| 3263 | + | |
3261 | 3264 | | |
3262 | 3265 | | |
3263 | 3266 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11122 | 11122 | | |
11123 | 11123 | | |
11124 | 11124 | | |
| 11125 | + | |
| 11126 | + | |
| 11127 | + | |
| 11128 | + | |
| 11129 | + | |
| 11130 | + | |
| 11131 | + | |
| 11132 | + | |
| 11133 | + | |
| 11134 | + | |
| 11135 | + | |
| 11136 | + | |
| 11137 | + | |
| 11138 | + | |
| 11139 | + | |
| 11140 | + | |
| 11141 | + | |
| 11142 | + | |
| 11143 | + | |
| 11144 | + | |
| 11145 | + | |
| 11146 | + | |
| 11147 | + | |
11125 | 11148 | | |
11126 | 11149 | | |
11127 | 11150 | | |
11128 | 11151 | | |
11129 | 11152 | | |
11130 | 11153 | | |
11131 | | - | |
| 11154 | + | |
| 11155 | + | |
| 11156 | + | |
11132 | 11157 | | |
11133 | | - | |
11134 | 11158 | | |
11135 | | - | |
| 11159 | + | |
11136 | 11160 | | |
11137 | 11161 | | |
11138 | 11162 | | |
11139 | 11163 | | |
11140 | 11164 | | |
11141 | | - | |
| 11165 | + | |
11142 | 11166 | | |
11143 | 11167 | | |
11144 | 11168 | | |
| |||
11153 | 11177 | | |
11154 | 11178 | | |
11155 | 11179 | | |
| 11180 | + | |
| 11181 | + | |
| 11182 | + | |
| 11183 | + | |
| 11184 | + | |
| 11185 | + | |
| 11186 | + | |
| 11187 | + | |
| 11188 | + | |
| 11189 | + | |
| 11190 | + | |
11156 | 11191 | | |
11157 | 11192 | | |
11158 | 11193 | | |
| |||
0 commit comments