Repository navigation
fix(platform-browser): don't write styles to a clobbered style property - #71255
Closed
rootvector2 wants to merge 1 commit into
Closed
rootvector2 wants to merge 1 commit into
rootvector2 wants to merge 1 commit into
Conversation
`HTMLFormElement` is `[LegacyOverrideBuiltIns]`, so a form-associated control named `style` is exposed as an own property of the `<form>` and shadows the inherited `style` accessor. `setStyle()` and `removeStyle()` read `el.style` and write the style name onto it, so on such a form the write lands on the control instead of a `CSSStyleDeclaration`, which turns `innerHTML` and `outerHTML` into HTML sinks for style names that come from a bound value. Bail out when `el.style` is not a style declaration. The form was never styled on this path, so elements with a real declaration keep behaving the same. Fixes angular#70021
Contributor
|
This is a duplicate of #70022 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Checklist
Please check if your PR fulfills the following requirements:
PR Type
What kind of change does this PR introduce?
What is the current behavior?
Issue Number: #70021
HTMLFormElementis[LegacyOverrideBuiltIns], so a form-associated control namedstyleis exposed as an own property of the<form>and shadows the inheritedstyleaccessor.setStyle()andremoveStyle()readel.styleand then write the style name onto it, so on such a form the write lands on the control rather than on aCSSStyleDeclaration.All styling goes through those two methods, and with
[ngStyle],[style]or[style.<prop>]the style name comes from the bound value, which makesinnerHTMLandouterHTMLHTML sinks:In Chrome 154
form.styleis the<button>, the markup is written into it and the<img>is live in the document.removeStyle()follows the same path and clears the control'sinnerHTMLinstead.What is the new behavior?
Both methods return early when
el.styleis not a style declaration. The form was never styled on this path to begin with, so nothing that works today changes, and elements that do have a declaration are untouched.Does this PR introduce a breaking change?
Other information
The two tests fail on
mainintest_web_chromiumandtest_web_firefox(Expected '<img src="#">' to be ''andExpected '' to be 'Save') and pass with the change. The node target skips this suite, and domino does not implement the form named getter, so the clobbering is browser-only.