angular / angular/angular-cli

Angular SSR route-policy confusion can expose client-only data under public cache headers

Offen
#33,555 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area: @angular/ssr gemini-triaged
Vorherrschende Sprache
TypeScript
Sterne
27k
Forks
11.8k
Ø Merge
14 Std. 23 Min.
Gemergte PRs (30 T.)
162

Beschreibung

### Description

Angular SSR can select server-route metadata from one route while Angular Router renders a different route when the request URL contains certain ambiguous path forms.

Example:

```text
/profile;
/profile//public
```

In both cases, a route configured as `RenderMode.Client` can be unexpectedly rendered on the server while inheriting public cache headers from another `ServerRoute`.

### Minimal Reproduction

### Minimal configuration

```ts
import { RenderMode, ServerRoute } from '@angular/ssr';

export const serverRoutes: ServerRoute[] = [
{
path: 'profile',
renderMode: RenderMode.Client,
headers: {
'Cache-Control': 'private, no-store',
},
},
{
path: 'profile/public',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
{
path: '**',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
];
```

The `/profile` component reads a benign request-derived marker through the SSR `REQUEST` token.

### Steps to reproduce

Request the normal client-only route:

```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile
```

The initial HTML does not contain the request-derived value.

Request either crafted path:

```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
'http://localhost:4000/profile;'
```

```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile//public
```

### Actual behavior

The crafted requests can:

- render the `/profile` component on the server;
- expose request-derived data in the initial HTML;
- apply `Cache-Control: public` metadata belonging to another server route.

### Expected behavior

The route used to select `renderMode`, status, and response headers must always correspond to the route whose body is rendered.

A route configured as `RenderMode.Client` should not be server-rendered through an alternative URL representation.

### Your Environment

```text
Angular 22.X
```

### Anything else relevant?

This was previously reported at https://issuetracker.google.com/u/1/issues/518988455

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne damit, die Abweichung mit den beiden curl-Anfragen und der minimalen ServerRoute-Konfiguration zu reproduzieren. Verfolge, wie Angular SSR renderMode und response headers für /profile auswählt; und wie Angular Router /profile; und /profile//public rendert. Als erledigt gilt die Aufgabe, wenn der gerenderte Body, renderMode und die Cache-Header immer derselben Route entsprechen und für die client-only route kein aus der Anfrage abgeleiteter Wert offengelegt wird.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
angular, typescript
Bereich
backend, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
48/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.