Angular SSR route-policy confusion can expose client-only data under public cache headers
- Ngôn ngữ chính
- TypeScript
- Star
- 27k
- Fork
- 11.8k
- Merge trung bình
- 14 giờ 23 phút
- Pull request đã merge (30 ngày)
- 162
Mô tả
### Description
Angular SSR can select server-route metadata from one route while Angular Router renders a different route when the request URL contains certain ambiguous path forms.
Example:
```text
/profile;
/profile//public
```
In both cases, a route configured as `RenderMode.Client` can be unexpectedly rendered on the server while inheriting public cache headers from another `ServerRoute`.
### Minimal Reproduction
### Minimal configuration
```ts
import { RenderMode, ServerRoute } from '@angular/ssr';
export const serverRoutes: ServerRoute[] = [
{
path: 'profile',
renderMode: RenderMode.Client,
headers: {
'Cache-Control': 'private, no-store',
},
},
{
path: 'profile/public',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
{
path: '**',
renderMode: RenderMode.Server,
headers: {
'Cache-Control': 'public, max-age=300',
},
},
];
```
The `/profile` component reads a benign request-derived marker through the SSR `REQUEST` token.
### Steps to reproduce
Request the normal client-only route:
```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile
```
The initial HTML does not contain the request-derived value.
Request either crafted path:
```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
'http://localhost:4000/profile;'
```
```bash
curl -i \
-H 'Cookie: session=PRIVATE_VALUE' \
http://localhost:4000/profile//public
```
### Actual behavior
The crafted requests can:
- render the `/profile` component on the server;
- expose request-derived data in the initial HTML;
- apply `Cache-Control: public` metadata belonging to another server route.
### Expected behavior
The route used to select `renderMode`, status, and response headers must always correspond to the route whose body is rendered.
A route configured as `RenderMode.Client` should not be server-rendered through an alternative URL representation.
### Your Environment
```text
Angular 22.X
```
### Anything else relevant?
This was previously reported at https://issuetracker.google.com/u/1/issues/518988455
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu bằng cách tái hiện sự không khớp với hai yêu cầu curl và cấu hình ServerRoute tối thiểu. Theo dõi cách Angular SSR chọn renderMode và response headers cho /profile; và cách Angular Router render /profile; và /profile//public. Được xem là hoàn tất khi body được render, renderMode và các cache headers luôn tương ứng với cùng một route, không để lộ giá trị nào bắt nguồn từ request cho client-only route.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- angular, typescript
- Lĩnh vực
- backend, security
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 48/100