angular/packages
Alan Agius 40790ef980 fix(http): prevent XSRF token leakage to protocol-relative URLs
The XSRF interceptor previously failed to detect protocol-relative URLs (starting with `//`) as absolute URLs. This allowed requests to such URLs to include the XSRF token, potentially leaking it to external domains.

This change updates the interceptor to correctly identify protocol-relative URLs as absolute and exclude them from receiving the XSRF token.
2025-11-25 13:47:26 -05:00
..
animations build: format md files 2025-11-06 10:03:05 -08:00
benchpress build: format md files 2025-11-06 10:03:05 -08:00
common fix(http): prevent XSRF token leakage to protocol-relative URLs 2025-11-25 13:47:26 -05:00
compiler refactor(compiler): remove interpolation-related symbols 2025-11-19 14:28:20 -08:00
compiler-cli fix(compiler-cli): escape angular control flow in jsdoc 2025-11-25 11:33:25 -05:00
core refactor: replace getDocument() with inject(DOCUMENT) 2025-11-25 13:04:58 -05:00
docs/di build: format md files 2025-11-06 10:03:05 -08:00
elements refactor(core): mark VERSION as @__PURE__ for better tree-shaking 2025-11-10 12:04:04 -08:00
examples refactor(common): update examples to align with Angular best practices 2025-11-19 14:29:49 -08:00
forms refactor(forms): Make reset take value 2025-11-25 10:51:35 -05:00
language-service fix(language-service): address potential memory leak during project creation 2025-11-07 11:57:22 -08:00
localize Revert "refactor(compiler-cli): remove deep imports from compiler-cli (#64732)" 2025-11-06 13:09:01 -08:00
misc/angular-in-memory-web-api release: bump version of in memory web api 2025-11-19 12:05:51 -08:00
platform-browser docs: ExperimentalIsolatedShadowDom mentions 2025-11-14 08:41:13 -08:00
platform-browser-dynamic refactor(core): mark VERSION as @__PURE__ for better tree-shaking 2025-11-10 12:04:04 -08:00
platform-server refactor: replace getDocument() with inject(DOCUMENT) 2025-11-25 13:04:58 -05:00
private/testing build: rename defaults2.bzl to defaults.bzl (#63383) 2025-08-25 15:45:01 -07:00
router docs: Update router docs to add references and components input fixed syntaxis 2025-11-24 13:18:28 -05:00
service-worker refactor(common): update examples to align with Angular best practices 2025-11-19 14:29:49 -08:00
ssr/docs build: rename defaults2.bzl to defaults.bzl (#63383) 2025-08-25 15:45:01 -07:00
upgrade refactor(core): mark VERSION as @__PURE__ for better tree-shaking 2025-11-10 12:04:04 -08:00
zone.js release: cut the zone.js-0.16.0 release 2025-11-19 12:38:52 -08:00
BUILD.bazel build(forms): expose signal forms compat package 2025-11-14 09:23:36 -08:00
circular-deps-test.conf.js docs(docs-infra): lift circular imports (#63186) 2025-08-19 07:58:45 +00:00
empty.ts refactor: update license text to point to angular.dev (#57901) 2024-09-24 15:33:00 +02:00
goog.d.ts refactor: update license text to point to angular.dev (#57901) 2024-09-24 15:33:00 +02:00
license-banner.txt docs: update website URL in license banners (#64183) 2025-10-02 07:56:58 -07:00
package.json build: prepare for compiler-cli to be using ts_project (#61181) 2025-05-09 15:59:46 +00:00
README.md build: format md files 2025-11-06 10:03:05 -08:00
system.d.ts refactor: update packages/core:{core,src} to ts_project (#61275) 2025-05-14 12:01:51 +00:00
tsconfig-build.json Revert "refactor(compiler-cli): remove deep imports from compiler-cli (#64732)" 2025-11-06 13:09:01 -08:00
tsconfig-legacy-saucelabs.json feat(core): support TypeScript 5.5 (#56096) 2024-05-29 15:33:33 +02:00
tsconfig-test.json
tsconfig.json feat(compiler-cli): enable type checking of host bindings by default (#63654) 2025-09-09 14:34:29 -07:00
tsec-exemption.json
types.d.ts build: move private testing helpers outside platform-browser/testing (#61472) 2025-05-20 10:00:43 +00:00

Angular

The sources for this package are in the main Angular repo. Please file issues and pull requests against that repo.

Usage information and reference details can be found in Angular documentation.

License: MIT