angular / angular/angular-cli

Angular SSR route-policy confusion can expose client-only data under public cache headers

Abierto
#33,555 0 comentarios 0 reacciones 0 asignados Ver en GitHub
area: @angular/ssr gemini-triaged
Lenguaje dominante
TypeScript
Estrellas
27k
Forks
11.8k
Merge medio
14 h 23 min
PR fusionados (30 d)
162

Descripción

### Description

Angular SSR can select server-route metadata from one route while Angular Router renders a different route when the request URL contains certain ambiguous path forms.

Example:

```text
/profile;
/profile//public
```

In both cases, a route configured as `RenderMode.Client` can be unexpectedly rendered on the server while inheriting public cache headers from another `ServerRoute`.

### Minimal Reproduction

### Minimal configuration

```ts
import { RenderMode, ServerRoute } from '@angular/ssr';

export const serverRoutes: ServerRoute[] = [
{
path: 'profile',
renderMode: RenderMode.Client,
headers: {
'Cache-Control': 'private, no-store',
},
},
{
path: 'profile/public',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
{
path: '**',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
];
```

The `/profile` component reads a benign request-derived marker through the SSR `REQUEST` token.

### Steps to reproduce

Request the normal client-only route:

```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile
```

The initial HTML does not contain the request-derived value.

Request either crafted path:

```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
'http://localhost:4000/profile;'
```

```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile//public
```

### Actual behavior

The crafted requests can:

- render the `/profile` component on the server;
- expose request-derived data in the initial HTML;
- apply `Cache-Control: public` metadata belonging to another server route.

### Expected behavior

The route used to select `renderMode`, status, and response headers must always correspond to the route whose body is rendered.

A route configured as `RenderMode.Client` should not be server-rendered through an alternative URL representation.

### Your Environment

```text
Angular 22.X
```

### Anything else relevant?

This was previously reported at https://issuetracker.google.com/u/1/issues/518988455

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Empieza reproduciendo la discrepancia con las dos solicitudes curl y la configuración mínima de ServerRoute. Rastrea cómo Angular SSR selecciona renderMode y response headers para /profile; y cómo Angular Router renderiza /profile; y /profile//public. Se considera terminado cuando el body renderizado, renderMode y los encabezados de caché siempre correspondan a la misma ruta, sin que se exponga ningún valor derivado de la solicitud para la client-only route.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
angular, typescript
Área
backend, security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
48/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.