voidzero-dev / voidzero-dev/oxc-angular-compiler

security: missing security-context entries for SVG animation, iframe i18n, and namespaced SVG script elements

Offen
#315 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

bug rust
Vorherrschende Sprache
Rust
Sterne
228
Forks
20
Ø Merge
1 T. 15 Std.
Gemergte PRs (30 T.)
36

Beschreibung

Summary

Three security-context tables in OXC are missing entries that landed in packages/compiler since v21.2.2. Each gap creates a small XSS or unsanitized-binding surface in templates compiled by OXC.

Sub-gaps

1. iframe|src missing from TRUSTED_TYPES_SINKS

Upstream: packages/compiler/src/schema/trusted_types_sinks.ts:28 (added in 78dea55351).

ngc registers iframe|src so the i18n translation pipeline cannot rewrite the src attribute on iframes — translated strings flowing into iframe sources is an XSS vector. OXC has no trusted_types_sinks.rs equivalent in crates/oxc_angular_compiler/src/schema/.

Required work: create crates/oxc_angular_compiler/src/schema/trusted_types_sinks.rs mirroring upstream's set, wire into the i18n extractor's isTranslatableAttribute check.

2. SVG animation attributes missing from URL security context

Upstream: packages/compiler/src/schema/dom_security_schema.ts:108-113 (added in 08d36599d7).

ngc registers animate|to, animate|from, animate|values, and set|to as SecurityContext.URL, ensuring [attr.to]="..." on an SVG <animate> element runs through URL sanitization. OXC at crates/oxc_angular_compiler/src/schema/dom_security_schema.rs:30-110 registers only animate|attributename (and similar non-value attrs), leaving the value attrs in the default no-binding context — they bypass sanitization.

Required work: add the four entries to the URL group in dom_security_schema.rs.

3. Namespaced SVG script elements not classified as script-like

Upstream: packages/compiler/src/template_parser/template_preparser.ts:17-18,41-43 (added in 90494cd909).

ngc's preparseElement treats both script and :svg:script as script elements (and :svg:style as a style element), stripping their content during template compilation. OXC has no template-preparser equivalent — <svg:script> survives template compilation as a normal element, executing at runtime.

Required work: introduce a template-preparser pass (or extend the existing element classification) under crates/oxc_angular_compiler/src/parser/ that recognizes the SVG-namespaced variants.

Why this matters

Each gap is small, but together they widen OXC's attack surface vs ngc:

  • Sub-gap 1 lets an i18n translation team inject iframe content
  • Sub-gap 2 lets SVG animation attributes accept unsanitized URLs (javascript: etc.)
  • Sub-gap 3 lets SVG script elements execute

All three fixes are data-table or detection-logic additions, no architectural work.

Reference

  • Trusted types: packages/compiler/src/schema/trusted_types_sinks.ts
  • DOM security schema: packages/compiler/src/schema/dom_security_schema.ts
  • Template preparser: packages/compiler/src/template_parser/template_preparser.ts

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Vergleiche die upstream trusted_types_sinks.ts, dom_security_schema.ts und template_preparser.ts mit den entsprechenden Rust-Schemadateien und dem Parser unter crates/oxc_angular_compiler/. Beginne mit der bestehenden i18n-Attributprüfung, der DOM-Sicherheitstabelle und der Elementklassifizierung. Als abgeschlossen gilt die Arbeit, wenn iframe|src von der Übersetzung ausgeschlossen ist, die vier SVG-Animationsattribute URL-Sicherheit verwenden und SVG-namespaced script/style-Elemente die erforderliche Klassifizierung erhalten.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust, typescript
Bereich
compilers, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.