@@ -20,7 +20,6 @@ import {global} from '../global';
2020
2121import {
2222 TrustedHTML ,
23- TrustedScript ,
2423 TrustedScriptURL ,
2524 TrustedTypePolicy ,
2625 TrustedTypePolicyFactory ,
@@ -70,17 +69,6 @@ export function trustedHTMLFromString(html: string): TrustedHTML | string {
7069 return getPolicy ( ) ?. createHTML ( html ) || html ;
7170}
7271
73- /**
74- * Unsafely promote a string to a TrustedScript, falling back to strings when
75- * Trusted Types are not available.
76- * @security In particular, it must be assured that the provided string will
77- * never cause an XSS vulnerability if used in a context that will be
78- * interpreted and executed as a script by a browser, e.g. when calling eval.
79- */
80- export function trustedScriptFromString ( script : string ) : TrustedScript | string {
81- return getPolicy ( ) ?. createScript ( script ) || script ;
82- }
83-
8472/**
8573 * Unsafely promote a string to a TrustedScriptURL, falling back to strings
8674 * when Trusted Types are not available.
@@ -93,56 +81,3 @@ export function trustedScriptFromString(script: string): TrustedScript | string
9381export function trustedScriptURLFromString ( url : string ) : TrustedScriptURL | string {
9482 return getPolicy ( ) ?. createScriptURL ( url ) || url ;
9583}
96-
97- /**
98- * Unsafely call the Function constructor with the given string arguments. It
99- * is only available in development mode, and should be stripped out of
100- * production code.
101- * @security This is a security-sensitive function; any use of this function
102- * must go through security review. In particular, it must be assured that it
103- * is only called from development code, as use in production code can lead to
104- * XSS vulnerabilities.
105- */
106- export function newTrustedFunctionForDev ( ...args : string [ ] ) : Function {
107- if ( typeof ngDevMode === 'undefined' ) {
108- throw new Error ( 'newTrustedFunctionForDev should never be called in production' ) ;
109- }
110- if ( ! global . trustedTypes ) {
111- // In environments that don't support Trusted Types, fall back to the most
112- // straightforward implementation:
113- return new Function ( ...args ) ;
114- }
115-
116- // Chrome currently does not support passing TrustedScript to the Function
117- // constructor. The following implements the workaround proposed on the page
118- // below, where the Chromium bug is also referenced:
119- // https://github.com/w3c/webappsec-trusted-types/wiki/Trusted-Types-for-function-constructor
120- const fnArgs = args . slice ( 0 , - 1 ) . join ( ',' ) ;
121- const fnBody = args [ args . length - 1 ] ;
122- const body = `(function anonymous(${ fnArgs }
123- ) { ${ fnBody }
124- })` ;
125-
126- // Using eval directly confuses the compiler and prevents this module from
127- // being stripped out of JS binaries even if not used. The global['eval']
128- // indirection fixes that.
129- const fn = global [ 'eval' ] ( trustedScriptFromString ( body ) ) as Function ;
130- if ( fn . bind === undefined ) {
131- // Workaround for a browser bug that only exists in Chrome 83, where passing
132- // a TrustedScript to eval just returns the TrustedScript back without
133- // evaluating it. In that case, fall back to the most straightforward
134- // implementation:
135- return new Function ( ...args ) ;
136- }
137-
138- // To completely mimic the behavior of calling "new Function", two more
139- // things need to happen:
140- // 1. Stringifying the resulting function should return its source code
141- fn . toString = ( ) => body ;
142- // 2. When calling the resulting function, `this` should refer to `global`
143- return fn . bind ( global ) ;
144-
145- // When Trusted Types support in Function constructors is widely available,
146- // the implementation of this function can be simplified to:
147- // return new Function(...args.map(a => trustedScriptFromString(a)));
148- }
0 commit comments