voidzero-dev / voidzero-dev/oxc-angular-compiler

security: missing security-context entries for SVG animation, iframe i18n, and namespaced SVG script elements

Open
#315 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug rust
Dominant language
Rust
Stars
228
Forks
20
Avg merge
1d 15h
Merged PRs (30d)
36

Description

Summary

Three security-context tables in OXC are missing entries that landed in packages/compiler since v21.2.2. Each gap creates a small XSS or unsanitized-binding surface in templates compiled by OXC.

Sub-gaps

1. iframe|src missing from TRUSTED_TYPES_SINKS

Upstream: packages/compiler/src/schema/trusted_types_sinks.ts:28 (added in 78dea55351).

ngc registers iframe|src so the i18n translation pipeline cannot rewrite the src attribute on iframes — translated strings flowing into iframe sources is an XSS vector. OXC has no trusted_types_sinks.rs equivalent in crates/oxc_angular_compiler/src/schema/.

Required work: create crates/oxc_angular_compiler/src/schema/trusted_types_sinks.rs mirroring upstream's set, wire into the i18n extractor's isTranslatableAttribute check.

2. SVG animation attributes missing from URL security context

Upstream: packages/compiler/src/schema/dom_security_schema.ts:108-113 (added in 08d36599d7).

ngc registers animate|to, animate|from, animate|values, and set|to as SecurityContext.URL, ensuring [attr.to]="..." on an SVG <animate> element runs through URL sanitization. OXC at crates/oxc_angular_compiler/src/schema/dom_security_schema.rs:30-110 registers only animate|attributename (and similar non-value attrs), leaving the value attrs in the default no-binding context — they bypass sanitization.

Required work: add the four entries to the URL group in dom_security_schema.rs.

3. Namespaced SVG script elements not classified as script-like

Upstream: packages/compiler/src/template_parser/template_preparser.ts:17-18,41-43 (added in 90494cd909).

ngc's preparseElement treats both script and :svg:script as script elements (and :svg:style as a style element), stripping their content during template compilation. OXC has no template-preparser equivalent — <svg:script> survives template compilation as a normal element, executing at runtime.

Required work: introduce a template-preparser pass (or extend the existing element classification) under crates/oxc_angular_compiler/src/parser/ that recognizes the SVG-namespaced variants.

Why this matters

Each gap is small, but together they widen OXC's attack surface vs ngc:

  • Sub-gap 1 lets an i18n translation team inject iframe content
  • Sub-gap 2 lets SVG animation attributes accept unsanitized URLs (javascript: etc.)
  • Sub-gap 3 lets SVG script elements execute

All three fixes are data-table or detection-logic additions, no architectural work.

Reference

  • Trusted types: packages/compiler/src/schema/trusted_types_sinks.ts
  • DOM security schema: packages/compiler/src/schema/dom_security_schema.ts
  • Template preparser: packages/compiler/src/template_parser/template_preparser.ts

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Compare the upstream trusted_types_sinks.ts, dom_security_schema.ts, and template_preparser.ts with the corresponding Rust schema files and parser under crates/oxc_angular_compiler/. Start with the existing i18n attribute check, DOM security table, and element classification. Done means iframe|src is excluded from translation, the four SVG animation attributes use URL security, and SVG-namespaced script/style elements receive the required classification.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust, typescript
Domain
compilers, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.