Skip to content
This repository was archived by the owner on Apr 12, 2024. It is now read-only.
This repository was archived by the owner on Apr 12, 2024. It is now read-only.

docs(guide/security) add more info about template generation #15033

Closed
@petebacondarwin

Description

@petebacondarwin

We should enumerate the ways the Angular template can be generated.

Reflecting it from the server response is the most popular way, but there are XSS bugs using other compilation sinks in e.g. directives that are not obvious (e.g. $compile(userControlled) and $eval(userControlled).

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions