security: missing security-context entries for SVG animation, iframe i18n, and namespaced SVG script elements
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- rust, typescript
Hướng nghiên cứu
So sánh trusted_types_sinks.ts, dom_security_schema.ts và template_preparser.ts từ upstream với các tệp schema Rust tương ứng và parser trong crates/oxc_angular_compiler/. Bắt đầu với kiểm tra thuộc tính i18n hiện có, bảng bảo mật DOM và việc phân loại phần tử. Hoàn thành khi iframe|src được loại khỏi việc dịch, bốn thuộc tính hoạt ảnh SVG sử dụng bảo mật URL và các phần tử script/style có namespace SVG nhận được phân loại bắt buộc.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
Three security-context tables in OXC are missing entries that landed in packages/compiler since v21.2.2. Each gap creates a small XSS or unsanitized-binding surface in templates compiled by OXC.
Sub-gaps
1. iframe|src missing from TRUSTED_TYPES_SINKS
Upstream: packages/compiler/src/schema/trusted_types_sinks.ts:28 (added in 78dea55351).
ngc registers iframe|src so the i18n translation pipeline cannot rewrite the src attribute on iframes — translated strings flowing into iframe sources is an XSS vector. OXC has no trusted_types_sinks.rs equivalent in crates/oxc_angular_compiler/src/schema/.
Required work: create crates/oxc_angular_compiler/src/schema/trusted_types_sinks.rs mirroring upstream's set, wire into the i18n extractor's isTranslatableAttribute check.
2. SVG animation attributes missing from URL security context
Upstream: packages/compiler/src/schema/dom_security_schema.ts:108-113 (added in 08d36599d7).
ngc registers animate|to, animate|from, animate|values, and set|to as SecurityContext.URL, ensuring [attr.to]="..." on an SVG <animate> element runs through URL sanitization. OXC at crates/oxc_angular_compiler/src/schema/dom_security_schema.rs:30-110 registers only animate|attributename (and similar non-value attrs), leaving the value attrs in the default no-binding context — they bypass sanitization.
Required work: add the four entries to the URL group in dom_security_schema.rs.
3. Namespaced SVG script elements not classified as script-like
Upstream: packages/compiler/src/template_parser/template_preparser.ts:17-18,41-43 (added in 90494cd909).
ngc's preparseElement treats both script and :svg:script as script elements (and :svg:style as a style element), stripping their content during template compilation. OXC has no template-preparser equivalent — <svg:script> survives template compilation as a normal element, executing at runtime.
Required work: introduce a template-preparser pass (or extend the existing element classification) under crates/oxc_angular_compiler/src/parser/ that recognizes the SVG-namespaced variants.
Why this matters
Each gap is small, but together they widen OXC's attack surface vs ngc:
- Sub-gap 1 lets an i18n translation team inject iframe content
- Sub-gap 2 lets SVG animation attributes accept unsanitized URLs (
javascript:etc.) - Sub-gap 3 lets SVG script elements execute
All three fixes are data-table or detection-logic additions, no architectural work.
Reference
- Trusted types:
packages/compiler/src/schema/trusted_types_sinks.ts - DOM security schema:
packages/compiler/src/schema/dom_security_schema.ts - Template preparser:
packages/compiler/src/template_parser/template_preparser.ts
- Ngôn ngữ chính
- Rust
- Star
- 228
- Fork
- 20
- Merge trung bình
- 1 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 36
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của voidzero-dev/oxc-angular-compiler
-
bug rust
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 56/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
voidzero-dev/oxc-angular-compiler#73 · 11 bình luận ·
-
voidzero-dev/oxc-angular-compiler#61 · 1 người được giao ·
-
voidzero-dev/oxc-angular-compiler#60 · 4 bình luận · 1 người được giao ·
Tất cả issue của voidzero-dev/oxc-angular-compiler
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
Axis areas are always keyboard-focusable (Sense::drag), even with allow_axis_zoom_drag(false) Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
-
bug team:backend track:services-maintenance
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
cowprotocol/services#4950 ·
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
gitbutlerapp/gitbutler#15998 · 1 bình luận ·