Angular SSR route-policy confusion can expose client-only data under public cache headers
- Lingua principale
- TypeScript
- Stelle
- 27k
- Fork
- 11.8k
- Merge medio
- 14h 23m
- PR unite (30g)
- 162
Descrizione
### Description
Angular SSR can select server-route metadata from one route while Angular Router renders a different route when the request URL contains certain ambiguous path forms.
Example:
```text
/profile;
/profile//public
```
In both cases, a route configured as `RenderMode.Client` can be unexpectedly rendered on the server while inheriting public cache headers from another `ServerRoute`.
### Minimal Reproduction
### Minimal configuration
```ts
import { RenderMode, ServerRoute } from '@angular/ssr';
export const serverRoutes: ServerRoute[] = [
{
path: 'profile',
renderMode: RenderMode.Client,
headers: {
'Cache-Control': 'private, no-store',
},
},
{
path: 'profile/public',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
{
path: '**',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
];
```
The `/profile` component reads a benign request-derived marker through the SSR `REQUEST` token.
### Steps to reproduce
Request the normal client-only route:
```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile
```
The initial HTML does not contain the request-derived value.
Request either crafted path:
```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
'http://localhost:4000/profile;'
```
```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile//public
```
### Actual behavior
The crafted requests can:
- render the `/profile` component on the server;
- expose request-derived data in the initial HTML;
- apply `Cache-Control: public` metadata belonging to another server route.
### Expected behavior
The route used to select `renderMode`, status, and response headers must always correspond to the route whose body is rendered.
A route configured as `RenderMode.Client` should not be server-rendered through an alternative URL representation.
### Your Environment
```text
Angular 22.X
```
### Anything else relevant?
This was previously reported at https://issuetracker.google.com/u/1/issues/518988455
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Inizia riproducendo la discrepanza con le due richieste curl e la configurazione minima di ServerRoute. Traccia come Angular SSR seleziona renderMode e response headers per /profile; e come Angular Router esegue il rendering di /profile; e /profile//public. Il lavoro è completato quando il body renderizzato, renderMode e gli header di cache corrispondono sempre alla stessa route, senza esporre alcun valore derivato dalla richiesta per la client-only route.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- angular, typescript
- Ambito
- backend, security
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Tranquilla
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 48/100