Visitar URL original
fix(platform-browser): escape newlines in Meta selector values by rootvector2 路 Pull Request #71236 路 angular/angular 路 GitHub
Skip to content

fix(platform-browser): escape newlines in Meta selector values - #71236

Open
rootvector2 wants to merge 1 commit into
angular:mainfrom
rootvector2:meta-selector-newline-escape
Open

rootvector2 wants to merge 1 commit into
angular:mainfrom
rootvector2:meta-selector-newline-escape

Conversation

@rootvector2

Copy link
Copy Markdown
Contributor

PR Checklist

PR Type

  • Bugfix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • CI related changes
  • Documentation content changes
  • angular.dev application / infrastructure changes
  • Other... Please describe:

What is the current behavior?

Issue Number: N/A

escapeSelectorValue escapes backslashes and double quotes to keep a value confined inside the meta[name="..."] selector that parseSelector derives. a newline cannot be confined that way: it terminates the string token (CSS Syntax 3 4.3.5), and carriage return and form feed are preprocessed into one (3.3). so a name or property holding one of them produces a bad-string token, and the selector is invalid:

metaService.addTag({name: 'description\nevil', content: 'x'});
// DOMException: 'meta[name="description
// evil"]' is not a valid selector

the throw comes from querySelector inside getTags, so it escapes addTag, updateTag, getTag and removeTag. it is reachable wherever the tag name is taken from content rather than written literally, which is the normal shape for og/twitter tags driven by a cms or an api response.

found while auditing the css-escaping helpers in common and platform-browser against each other: escapeCssUrl in ng_optimized_image already handles these characters and cites the same rule, and viewport_scroller defers to CSS.escape. this was the one that did not.

What is the new behavior?

newline, carriage return and form feed are written as css character escapes (\a , \d , \c ), which represent the same code points inside the string, so the value round-trips and the tag is matched. values without those characters serialize byte for byte as before.

Does this PR introduce a breaking change?

  • Yes
  • No

Other information

regression test added in meta_spec.ts. it fails on main in both test_web_chromium and test_web_firefox with the is not a valid selector error above and passes with this change. note the :test target would not have caught it, since domino accepts the invalid selector where browsers reject it.

`escapeSelectorValue` escaped only backslashes and double quotes, so a `name` or `property` value holding a newline ended the CSS string token early (CSS Syntax 3 4.3.5) and the derived `meta[...]` selector was rejected by `querySelector`. Write newline, carriage return and form feed as character escapes so the value stays inside the string.
@pullapprove
pullapprove Bot requested a review from kirjs October 7, 2026 16:12
@angular-robot angular-robot Bot added the area: core Issues related to the framework runtime label Oct 7, 2026
@ngbot ngbot Bot added this to the Backlog milestone Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Issues related to the framework runtime

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant