Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							5e12a95789 
							
						 
					 
					
						
						
							
							test(security): test case for quoted URL values.  
						
						... 
						
						
						
						Test case that fixes  #8701 . This is already supported with the latest sanitizer
changes, but it's good to have an explicit test case. 
						
						
					 
					
						2016-05-26 09:39:23 -07:00 
						 
				 
			
				
					
						
							
							
								Matias Niemelä 
							
						 
					 
					
						
						
						
						
							
						
						
							5e0f8cf3f0 
							
						 
					 
					
						
						
							
							feat(core): introduce support for animations  
						
						... 
						
						
						
						Closes  #8734  
					
						2016-05-25 13:56:50 -07:00 
						 
				 
			
				
					
						
							
							
								Alfonso Presa 
							
						 
					 
					
						
						
						
						
							
						
						
							5f3d02bc7c 
							
						 
					 
					
						
						
							
							fix(Animation): Problem decimals using commas as decimal separation  
						
						... 
						
						
						
						Tests where failing due to `.` character being used as decimal separator in some regional settings (like spanish for example)
Closes  #6335 
Closes  #6338  
						
						
					 
					
						2016-05-24 21:23:46 -07:00 
						 
				 
			
				
					
						
							
							
								Matias Niemelä 
							
						 
					 
					
						
						
						
						
							
						
						
							1ac38bd69a 
							
						 
					 
					
						
						
							
							feat(renderer): add a setElementStyles method  
						
						
						
						
					 
					
						2016-05-24 18:42:05 -07:00 
						 
				 
			
				
					
						
							
							
								Victor Berchet 
							
						 
					 
					
						
						
						
						
							
						
						
							75e6dfb9ab 
							
						 
					 
					
						
						
							
							fix(browser): platform code cleanup  
						
						
						
						
					 
					
						2016-05-23 17:57:28 -07:00 
						 
				 
			
				
					
						
							
							
								Victor Berchet 
							
						 
					 
					
						
						
						
						
							
						
						
							f95a604b59 
							
						 
					 
					
						
						
							
							fix(bootstrap): swap coreBootstrap() and coreLoadAndBootstrap() arguments  
						
						
						
						
					 
					
						2016-05-23 17:57:28 -07:00 
						 
				 
			
				
					
						
							
							
								Victor Berchet 
							
						 
					 
					
						
						
						
						
							
						
						
							e8e61de28d 
							
						 
					 
					
						
						
							
							refactor(WebWorker): move XHR worker side  
						
						
						
						
					 
					
						2016-05-20 10:48:55 -07:00 
						 
				 
			
				
					
						
							
							
								Victor Berchet 
							
						 
					 
					
						
						
						
						
							
						
						
							54f8308999 
							
						 
					 
					
						
						
							
							refactor(browser): merge static & dynamic platforms  
						
						
						
						
					 
					
						2016-05-20 10:48:55 -07:00 
						 
				 
			
				
					
						
							
							
								Victor Berchet 
							
						 
					 
					
						
						
						
						
							
						
						
							6e62217b78 
							
						 
					 
					
						
						
							
							fix(WebWorker): remove the platform-browser dependency on compiler  
						
						
						
						
					 
					
						2016-05-18 16:23:09 -07:00 
						 
				 
			
				
					
						
							
							
								Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							15ae710d22 
							
						 
					 
					
						
						
							
							feat(security): allow url(...) style values.  
						
						... 
						
						
						
						Allows sanitized URLs for CSS properties. These can be abused for information
leakage, but only if the CSS rules are already set up to allow for it. That is,
an attacker cannot cause information leakage without controlling the style rules
present, or a very particular setup.
Fixes  #8514 . 
						
						
					 
					
						2016-05-17 11:23:31 +02:00 
						 
				 
			
				
					
						
							
							
								Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							dd50124254 
							
						 
					 
					
						
						
							
							feat(security): allow data: URLs for images and videos.  
						
						... 
						
						
						
						Allows known-to-be-safe media types in data URIs.
Part of #8511 . 
						
						
					 
					
						2016-05-17 10:57:14 +02:00 
						 
				 
			
				
					
						
							
							
								Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							8b1b427195 
							
						 
					 
					
						
						
							
							feat(security): support transform CSS functions for sanitization.  
						
						... 
						
						
						
						Fixes part of #8514 . 
						
						
					 
					
						2016-05-14 13:25:45 +02:00 
						 
				 
			
				
					
						
							
							
								Marc Laval 
							
						 
					 
					
						
						
						
						
							
						
						
							61b339678d 
							
						 
					 
					
						
						
							
							test(compiler): test schema generation only in Chrome  
						
						... 
						
						
						
						Closes  #8581  
					
						2016-05-11 17:01:26 -07:00 
						 
				 
			
				
					
						
							
							
								Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							3e68b7eb1f 
							
						 
					 
					
						
						
							
							feat(security): warn users when sanitizing in dev mode.  
						
						... 
						
						
						
						This should help developers to figure out what's going on when the sanitizer
strips some input.
Fixes  #8522 . 
						
						
					 
					
						2016-05-09 16:46:31 +02:00 
						 
				 
			
				
					
						
							
							
								Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							7a524e3deb 
							
						 
					 
					
						
						
							
							feat(security): add tests for URL sanitization.  
						
						
						
						
					 
					
						2016-05-09 16:00:24 +02:00 
						 
				 
			
				
					
						
							
							
								Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							7b6c4d5acc 
							
						 
					 
					
						
						
							
							feat(security): add tests for style sanitisation.  
						
						
						
						
					 
					
						2016-05-09 16:00:24 +02:00 
						 
				 
			
				
					
						
							
							
								Martin Probst 
							
						 
					 
					
						
						
						
						
							
						
						
							f86edae9f3 
							
						 
					 
					
						
						
							
							feat(security): add an HTML sanitizer.  
						
						... 
						
						
						
						This is based on Angular 1's implementation, parsing an HTML document
into an inert DOM Document implementation, and then serializing only
specifically whitelisted elements.
It currently does not support SVG sanitization, all SVG elements are
rejected.
If available, the sanitizer uses the `<template>` HTML element as an
inert container.
Sanitization works client and server-side.
Reviewers: rjamet, tbosch , molnarg , koto
Differential Revision: https://reviews.angular.io/D108  
						
						
					 
					
						2016-05-09 16:00:24 +02:00 
						 
				 
			
				
					
						
							
							
								Misko Hevery 
							
						 
					 
					
						
						
						
						
							
						
						
							107016ec12 
							
						 
					 
					
						
						
							
							chore: router move import changes  
						
						
						
						
					 
					
						2016-05-02 13:27:03 -07:00 
						 
				 
			
				
					
						
							
							
								Misko Hevery 
							
						 
					 
					
						
						
						
						
							
						
						
							3e17c99f4e 
							
						 
					 
					
						
						
							
							chore: clang-reformat  
						
						
						
						
					 
					
						2016-05-01 22:59:41 -07:00 
						 
				 
			
				
					
						
							
							
								Igor Minar 
							
						 
					 
					
						
						
						
						
							
						
						
							a66cdb469f 
							
						 
					 
					
						
						
							
							repackaging: all the repackaging changes squashed  
						
						
						
						
					 
					
						2016-05-01 20:51:00 -07:00 
						 
				 
			
				
					
						
							
							
								Igor Minar 
							
						 
					 
					
						
						
						
						
							
						
						
							505da6c0a8 
							
						 
					 
					
						
						
							
							repackaging: all the file moves  
						
						
						
						
					 
					
						2016-05-01 20:51:00 -07:00