angular-cn/packages/platform-browser/test/security
Peter Bacon Darwin a751649c8d fix(core): use appropriate inert document strategy for Firefox & Safari (#17019)
Both Firefox and Safari are vulnerable to XSS if we use an inert document
created via `document.implementation.createHTMLDocument()`.

Now we check for those vulnerabilities and then use a DOMParser or XHR
strategy if needed.

Further the platform-server has its own library for parsing HTML, so we
sniff for that (by checking whether DOMParser exists) and fall back to
the standard strategy.

Thanks to @cure53 for the heads up on this issue.

PR Close #17019
2018-02-08 08:55:15 -08:00
..
dom_sanitization_service_spec.ts build: remove `main()` from specs (#21053) 2017-12-22 13:10:51 -08:00
html_sanitizer_spec.ts fix(core): use appropriate inert document strategy for Firefox & Safari (#17019) 2018-02-08 08:55:15 -08:00
style_sanitizer_spec.ts build: remove `main()` from specs (#21053) 2017-12-22 13:10:51 -08:00
url_sanitizer_spec.ts build: remove `main()` from specs (#21053) 2017-12-22 13:10:51 -08:00