fix(cdk/private): guard createPolicy against DOM clobbering#33410
Open
arturovt wants to merge 1 commit into
Open
fix(cdk/private): guard createPolicy against DOM clobbering#33410arturovt wants to merge 1 commit into
arturovt wants to merge 1 commit into
Conversation
crisbeto
reviewed
Jun 17, 2026
Wraps trustedTypes.createPolicy in a try/catch to handle two failure cases: the policy name already being registered (e.g. in a micro-frontend setup), and window.trustedTypes being DOM-clobbered by an HTML element before Angular bootstraps. In both cases the policy falls back to null, and trustedHTMLFromString continues to work via plain strings while sanitization in _setInnerHtml still runs.
39d7c2c to
383bb1a
Compare
crisbeto
reviewed
Jun 17, 2026
| policy = ttWindow.trustedTypes.createPolicy('angular#components', { | ||
| createHTML: (s: string) => s, | ||
| }); | ||
| } catch { |
Member
There was a problem hiding this comment.
Maybe we should console.error here so we know it's failing?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Wraps trustedTypes.createPolicy in a try/catch to handle two failure
cases: the policy name already being registered (e.g. in a micro-frontend
setup), and window.trustedTypes being DOM-clobbered by an HTML element
before Angular bootstraps. In both cases the policy falls back to null,
and trustedHTMLFromString continues to work via plain strings while
sanitization in _setInnerHtml still runs.