angular-cn/packages/zone.js
Martin Probst d498314850 fix(zone.js): a path traversal attack in test (#32392)
`simple-server.js` is vulnerable to a trivial path traversal attack, i.e. an
attacker can supply a path like `../../etc/passwd` to read arbitrary files on
the server. This change fixes the issue by properly resolving the path, and then
only serving files under the current directory (as intended).

This is not really a security issue, given the code is not part of Angular, but
rather just testing infrastructure for Angular itself, and the CI servers are
not expected to contain confidential information, but still worth fixing for
code hygiene.

PR Close #32392
2019-08-30 12:44:46 -07:00
..
dist test(zone.js): add test codes to ensure not include sourcemap (#31892) 2019-07-30 13:00:26 -07:00
doc
example
lib fix(zone.js): browser-legacy should not reference Zone (#32016) 2019-08-13 09:53:00 -07:00
scripts
test fix(zone.js): browser-legacy should not reference Zone (#32016) 2019-08-13 09:53:00 -07:00
BUILD.bazel
CHANGELOG.md release: cut the zone.js-0.10.2 release (#32128) 2019-08-13 16:55:04 -07:00
DEVELOPER.md docs(zone.js): update release docs instructions (#32128) 2019-08-13 16:55:03 -07:00
MODULE.md
NON-STANDARD-APIS.md
README.md fix(zone.js): update dart zone link (#31646) 2019-07-23 21:12:52 -07:00
SAMPLE.md
STANDARD-APIS.md
bundles.bzl
check-file-size.js
file-size-limit.json
karma-base.conf.js
karma-build-jasmine-phantomjs.conf.js
karma-build-jasmine.conf.js
karma-build-jasmine.es2015.conf.js
karma-build-mocha.conf.js
karma-build-sauce-mocha.conf.js
karma-build-sauce-selenium3-mocha.conf.js
karma-build.conf.js
karma-dist-jasmine.conf.js
karma-dist-mocha.conf.js
karma-dist-sauce-jasmine.conf.js
karma-dist-sauce-jasmine.es2015.conf.js
karma-dist-sauce-jasmine3.conf.js
karma-dist-sauce-selenium3-jasmine.conf.js
karma-dist.conf.js
karma-evergreen-dist-jasmine.conf.js
karma-evergreen-dist-sauce-jasmine.conf.js
karma-evergreen-dist.conf.js
package.json release: cut the zone.js-0.10.2 release (#32128) 2019-08-13 16:55:04 -07:00
presentation.png
promise-adapter.js
promise-test.js
promise.finally.spec.js
sauce-evergreen.conf.js
sauce-selenium3.conf.js
sauce.conf.js
sauce.es2015.conf.js
simple-server.js fix(zone.js): a path traversal attack in test (#32392) 2019-08-30 12:44:46 -07:00
tsconfig.json refactor: ensure zone.js can be built with typescript strict flag (#30993) 2019-07-18 14:21:26 -07:00

README.md

Zone.js

CDNJS

Implements Zones for JavaScript, inspired by Dart.

If you're using zone.js via unpkg (i.e. using https://unpkg.com/zone.js) and you're using any of the following libraries, make sure you import them first

  • 'newrelic' as it patches global.Promise before zone.js does
  • 'async-listener' as it patches global.setTimeout, global.setInterval before zone.js does
  • 'continuation-local-storage' as it uses async-listener

NEW Zone.js POST-v0.6.0

See the new API here.

Read up on Zone Primer.

What's a Zone?

A Zone is an execution context that persists across async tasks. You can think of it as thread-local storage for JavaScript VMs.

See this video from ng-conf 2014 for a detailed explanation:

screenshot of the zone.js presentation and ng-conf 2014

See also

Standard API support

zone.js patched most standard web APIs (such as DOM events, XMLHttpRequest, ...) and nodejs APIs (EventEmitter, fs, ...), for more details, please see STANDARD-APIS.md.

Nonstandard API support

We are adding support to some nonstandard APIs, such as MediaQuery and Notification. Please see NON-STANDARD-APIS.md for more details.

Examples

You can find some samples to describe how to use zone.js in SAMPLE.md.

Modules

zone.js patches the async APIs described above, but those patches will have some overhead. Starting from zone.js v0.8.9, you can choose which web API module you want to patch. For more details, please see MODULE.md.

Bundles

There are several bundles under dist folder.

Bundle Summary
zone.js the default bundle, contains the most used APIs such as setTimeout/Promise/EventTarget..., also this bundle supports all evergreen and legacy (IE/Legacy Firefox/Legacy Safari) Browsers
zone-evergreen.js the bundle for evergreen browsers, doesn't include the patch for legacy browsers such as IE or old versions of Firefox/Safari
zone-legacy.js the patch bundle for legacy browsers, only includes the patch for legacy browsers such as IE or old versions of Firefox/Safari. This bundle must be loaded after zone-evergreen.js, zone.js=zone-evergreen.js + zone-legacy.js
zone-testing.js the bundle for zone testing support, including jasmine/mocha support and async/fakeAsync/sync test utilities
zone-externs.js the API definitions for closure compiler

And here are the additional optional patches not included in the main zone.js bundles

Patch Summary
webapis-media-query.js patch for MediaQuery APIs
webapis-notification.js patch for Notification APIs
webapis-rtc-peer-connection.js patch for RTCPeerConnection APIs
webapis-shadydom.js patch for Shady DOM APIs
zone-bluebird.js patch for Bluebird APIs
zone-error.js patch for Error Global Object, supports remove Zone StackTrace
zone-patch-canvas.js patch for Canvas API
zone-patch-cordova.js patch for Cordova API
zone-patch-electron.js patch for Electron API
zone-patch-fetch.js patch for Fetch API
zone-patch-jsonp.js utility for jsonp API
zone-patch-resize-observer.js patch for ResizeObserver API
zone-patch-rxjs.js patch for rxjs API
zone-patch-rxjs-fake-async.js patch for rxjs fakeasync test
zone-patch-socket-io.js patch for socket-io
zone-patch-user-media.js patch for UserMedia API

Promise A+ test passed

Promises/A+ 1.1 compliant

License

MIT