fix(material/icon): keep FuncIRI references on current origin - #33812
moamenmahmod wants to merge 1 commit into
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
Paths beginning with two slashes were interpreted as protocol-relative URLs when MatIcon rewrote same-document SVG references. Prefix those paths with a dot segment so they resolve on the current origin while retaining the current document path.
ed1f16c to
9860d5f
Compare
|
Friendly ping 🙂 This is a small (Low-severity) security-hardening fix for As a first-time contributor my CI is stuck on "5 workflows awaiting approval" — could a maintainer please Approve and run workflows and add the appropriate |
Summary
MatIconFuncIRI rewrites on the current origin when the page path starts with//dot segment
Background
MatIcon._prependPathToReferences()prepends the current pathname and search string to SVGsame-document references. A pathname beginning with
//is otherwise parsed as a protocol-relativeURL, which can turn
url(#id)into a cross-origin request.Google's OSS VRP referred this report to the Angular maintainers as issue
548479960.The local-only browser reproduction and evidence are available at
https://github.com/moamenmahmod/angular-material-funciri-poc.
Fixes #33811
Testing
pnpm test src/material/icon --no-watchpnpm lint