Skip to content

Commit e06c8de

Browse files
moamenmahmodcrisbeto
authored andcommitted
fix(material/icon): keep FuncIRI references on current origin (#33812)
Paths beginning with two slashes were interpreted as protocol-relative URLs when MatIcon rewrote same-document SVG references. Prefix those paths with a dot segment so they resolve on the current origin while retaining the current document path. (cherry picked from commit f7e3a01)
1 parent 488e8a3 commit e06c8de

2 files changed

Lines changed: 31 additions & 1 deletion

File tree

‎src/material/icon/icon.spec.ts‎

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1012,6 +1012,32 @@ describe('MatIcon', () => {
10121012
expect(circle.getAttribute('filter')).toMatch(/^url\(['"]?\/\$fake-path#blur['"]?\)$/);
10131013
});
10141014

1015+
it('should not create protocol-relative `url()` references', () => {
1016+
fakePath = '////$fake-host/path?x=1';
1017+
iconRegistry.addSvgIconLiteral(
1018+
'fido',
1019+
trustHtml(`
1020+
<svg>
1021+
<filter id="blur">
1022+
<feGaussianBlur in="SourceGraphic" stdDeviation="5" />
1023+
</filter>
1024+
1025+
<circle cx="170" cy="60" r="50" fill="green" filter="url('#blur')" />
1026+
</svg>
1027+
`),
1028+
);
1029+
1030+
const fixture = TestBed.createComponent(IconFromSvgName);
1031+
fixture.componentInstance.iconName = 'fido';
1032+
fixture.changeDetectorRef.markForCheck();
1033+
fixture.detectChanges();
1034+
const circle = fixture.nativeElement.querySelector('mat-icon svg circle');
1035+
1036+
expect(circle.getAttribute('filter')).toMatch(
1037+
/^url\(['"]?\/\.\/\/\/\/\$fake-host\/path\?x=1#blur['"]?\)$/,
1038+
);
1039+
});
1040+
10151041
it('should use latest path when prefixing the `url()` references', () => {
10161042
iconRegistry.addSvgIconLiteral(
10171043
'fido',

‎src/material/icon/icon.ts‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -404,11 +404,15 @@ export class MatIcon implements OnInit, AfterViewChecked, OnDestroy {
404404
*/
405405
private _prependPathToReferences(path: string) {
406406
const elements = this._elementsWithExternalReferences;
407+
// A path starting with `//` would otherwise be interpreted as a protocol-relative URL.
408+
// Prefix it with a dot segment so it stays on the current origin without changing the resolved
409+
// path.
410+
const normalizedPath = path.startsWith('//') ? `/.${path}` : path;
407411

408412
if (elements) {
409413
elements.forEach((attrs, element) => {
410414
attrs.forEach(attr => {
411-
element.setAttribute(attr.name, `url('${path}#${attr.value}')`);
415+
element.setAttribute(attr.name, `url('${normalizedPath}#${attr.value}')`);
412416
});
413417
});
414418
}

0 commit comments

Comments
 (0)