Skip to content

Demo for how Angular automatically applies XSS defenses

Notifications You must be signed in to change notification settings

asaadsaad/angular-security-XSS

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

angular-security-XSS

Demo for how Angular automatically applies XSS defenses

import { Component } from '@angular/core';
import { DomSanitizer } from '@angular/platform-browser'

@Component({
  selector: 'app-root',
  template: `
    <h3>Angular automatically applies XSS defenses</h3>
    
    <input #i (input)="null"/>
    <br />
    {{i.value}}
    
    {{hack}}
        
    <div [innerHTML]="hack"></div>
    <a [href]="hackURL">untrusted URL</a>

    <!--div-- [innerHTML]="sanitizer.bypassSecurityTrustHtml(hack)"></!--div-->
  `,
})
export class AppComponent {
  hack = `<img src="a.png" onerror="alert(1)"/>`
  hackURL = `javascript:alert(1)`

  constructor(private sanitizer: DomSanitizer) { }
}

About

Demo for how Angular automatically applies XSS defenses

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published