voidzero-dev / voidzero-dev/oxc-angular-compiler

security: missing security-context entries for SVG animation, iframe i18n, and namespaced SVG script elements

Đang mở
#315 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

bug rust
Ngôn ngữ chính
Rust
Star
228
Fork
20
Merge trung bình
1 ngày 15 giờ
Pull request đã merge (30 ngày)
36

Mô tả

Summary

Three security-context tables in OXC are missing entries that landed in packages/compiler since v21.2.2. Each gap creates a small XSS or unsanitized-binding surface in templates compiled by OXC.

Sub-gaps

1. iframe|src missing from TRUSTED_TYPES_SINKS

Upstream: packages/compiler/src/schema/trusted_types_sinks.ts:28 (added in 78dea55351).

ngc registers iframe|src so the i18n translation pipeline cannot rewrite the src attribute on iframes — translated strings flowing into iframe sources is an XSS vector. OXC has no trusted_types_sinks.rs equivalent in crates/oxc_angular_compiler/src/schema/.

Required work: create crates/oxc_angular_compiler/src/schema/trusted_types_sinks.rs mirroring upstream's set, wire into the i18n extractor's isTranslatableAttribute check.

2. SVG animation attributes missing from URL security context

Upstream: packages/compiler/src/schema/dom_security_schema.ts:108-113 (added in 08d36599d7).

ngc registers animate|to, animate|from, animate|values, and set|to as SecurityContext.URL, ensuring [attr.to]="..." on an SVG <animate> element runs through URL sanitization. OXC at crates/oxc_angular_compiler/src/schema/dom_security_schema.rs:30-110 registers only animate|attributename (and similar non-value attrs), leaving the value attrs in the default no-binding context — they bypass sanitization.

Required work: add the four entries to the URL group in dom_security_schema.rs.

3. Namespaced SVG script elements not classified as script-like

Upstream: packages/compiler/src/template_parser/template_preparser.ts:17-18,41-43 (added in 90494cd909).

ngc's preparseElement treats both script and :svg:script as script elements (and :svg:style as a style element), stripping their content during template compilation. OXC has no template-preparser equivalent — <svg:script> survives template compilation as a normal element, executing at runtime.

Required work: introduce a template-preparser pass (or extend the existing element classification) under crates/oxc_angular_compiler/src/parser/ that recognizes the SVG-namespaced variants.

Why this matters

Each gap is small, but together they widen OXC's attack surface vs ngc:

  • Sub-gap 1 lets an i18n translation team inject iframe content
  • Sub-gap 2 lets SVG animation attributes accept unsanitized URLs (javascript: etc.)
  • Sub-gap 3 lets SVG script elements execute

All three fixes are data-table or detection-logic additions, no architectural work.

Reference

  • Trusted types: packages/compiler/src/schema/trusted_types_sinks.ts
  • DOM security schema: packages/compiler/src/schema/dom_security_schema.ts
  • Template preparser: packages/compiler/src/template_parser/template_preparser.ts

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

So sánh trusted_types_sinks.ts, dom_security_schema.ts và template_preparser.ts từ upstream với các tệp schema Rust tương ứng và parser trong crates/oxc_angular_compiler/. Bắt đầu với kiểm tra thuộc tính i18n hiện có, bảng bảo mật DOM và việc phân loại phần tử. Hoàn thành khi iframe|src được loại khỏi việc dịch, bốn thuộc tính hoạt ảnh SVG sử dụng bảo mật URL và các phần tử script/style có namespace SVG nhận được phân loại bắt buộc.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
rust, typescript
Lĩnh vực
compilers, security
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
55/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.