Angular Munich – Telegram
Angular Munich
176 subscribers
543 photos
40 videos
9 files
700 links
Stay up to date with Angular Framework ;-)

Need more: https://linktr.ee/ngxsamurai
Download Telegram
👍21🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
Let start 🫶🤘
2👍1🔥1
‼️ WebStorm 2025.2.5 (252.28238.10 build) Release

```
[🐛][Built-in Formatter] - Formatter: Angular HTML template references produce line breaks

[🐛][Code vision, Inlay hints] - Angular: Misaligned inlay hints when using $any()

[Usability] - Add option to disable Angular navigation popup
```

Full Release Notes
Missed out on angular’s v21 Developer Event?

Here’s an infographic summary, c/o GoogleAI’s Nano Banana Pro.
🔥3👍1
🚨 XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client

‼️ Package » @angular/common
‼️ Severity » High (7.7/10)

The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain.

Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header.


Affected versions                  Patched versions
>=21.0.0-next.0 < 21.0.1 21.0.1
>=20.0.0-next.0 < 20.3.14 20.3.14
>=19.0.0-next.0 < 19.2.16 19.2.16
<= 18.2.14 none


Workarounds

Developers should avoid using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.


Link
ooooooo dependaaaabooooottttt.....

😂😂😂😂😂😂

but I don't have bugs in my ng app ))
😁1
I'm so happy!!!

Thank you @arctic_tempest!

#ai
😁64😇3
‼️ Angular - prevent XSS via SVG animation attributeName and MathML/SVG URLs

Fixed in:
> 21.0.2
> 20.3.15
> 19.2.17

#security #angular21 #angular20 #angular19
Ready??? 👆🏻👆🏻👆🏻👆🏻👆🏻
Go!!!
4👍3🔥1
Uff... what the evening... We are survived! 😂
1
Ok... I don't like React, but I can't stay away if there are security issues!

also...

Critical Security Vulnerability inReact Server Components

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of:

react-server-dom-webpack
react-server-dom-parcel
react-server-dom-turbopack


https://github.com/msanft/CVE-2025-55182

Big thx to @AD_POHEQUE to go with deep explanation too!

#secure
🎅🏻 HoHoHo! Here Comes the CSS Advent Calendar!☃️🎄🎁

https://css-advent-calendar.vercel.app/en/
R.I.P Cary-Hiroyuki Tagawa (75)

😭😭😭😭😭

#mortalkombat
😢7💔1