Angular SSR route-policy confusion can expose client-only data under public cache headers

オープン
#33,555 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
48/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
angular, typescript
領域
backend, security

調査の方向性

まず、2つの curl リクエストと最小限の ServerRoute 設定で不一致を再現します。Angular SSR が /profile に対して renderMode と response headers をどのように選択するか、また Angular Router が /profile と /profile//public をどのようにレンダリングするかを追跡します。完了条件は、レンダリングされた body、renderMode、cache headers が常に同じ route に対応し、client-only route に対してリクエスト由来の値が公開されないことです。

索引モデルが issue の本文から書いたものです。

説明

area: @angular/ssr gemini-triaged
Description

Angular SSR can select server-route metadata from one route while Angular Router renders a different route when the request URL contains certain ambiguous path forms.

Example:

/profile;
/profile//public

In both cases, a route configured as RenderMode.Client can be unexpectedly rendered on the server while inheriting public cache headers from another ServerRoute.

Minimal Reproduction
Minimal configuration
import { RenderMode, ServerRoute } from '@angular/ssr';

export const serverRoutes: ServerRoute[] = [
  {
    path: 'profile',
    renderMode: RenderMode.Client,
    headers: {
      'Cache-Control': 'private, no-store',
    },
  },
  {
    path: 'profile/public',
    renderMode: RenderMode.Server,
    headers: {
      'Cache-Control': 'public, max-age=300',
    },
  },
  {
    path: '**',
    renderMode: RenderMode.Server,
    headers: {
      'Cache-Control': 'public, max-age=300',
    },
  },
];

The /profile component reads a benign request-derived marker through the SSR REQUEST token.

Steps to reproduce

Request the normal client-only route:

curl -i \
  -H 'Cookie: session=PRIVATE_VALUE' \
  http://localhost:4000/profile

The initial HTML does not contain the request-derived value.

Request either crafted path:

curl -i \
  -H 'Cookie: session=PRIVATE_VALUE' \
  'http://localhost:4000/profile;'
curl -i \
  -H 'Cookie: session=PRIVATE_VALUE' \
  http://localhost:4000/profile//public
Actual behavior

The crafted requests can:

  • render the /profile component on the server;
  • expose request-derived data in the initial HTML;
  • apply Cache-Control: public metadata belonging to another server route.
Expected behavior

The route used to select renderMode, status, and response headers must always correspond to the route whose body is rendered.

A route configured as RenderMode.Client should not be server-rendered through an alternative URL representation.

Your Environment
Angular 22.X
Anything else relevant?

This was previously reported at https://issuetracker.google.com/u/1/issues/518988455

主要言語
TypeScript
スター
27k
フォーク
11.8k
平均マージ
16時間 21分
マージ済み PR(30日)
170

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

angular/angular-cli のほかの issue

angular/angular-cli の issue をすべて見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。