Skip to content

Commit 9eabd14

Browse files
committed
refactor(core): remove unused utility functions
Remove `isIterable` from `util/iterable.ts` and `newTrustedFunctionForDev` from `util/security/trusted_types.ts` as they are no longer referenced anywhere in the codebase.
1 parent d109cc5 commit 9eabd14

2 files changed

Lines changed: 0 additions & 69 deletions

File tree

‎packages/core/src/util/iterable.ts‎

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,6 @@
66
* found in the LICENSE file at https://angular.dev/license
77
*/
88

9-
export function isIterable(obj: any): obj is Iterable<any> {
10-
return obj !== null && typeof obj === 'object' && obj[Symbol.iterator] !== undefined;
11-
}
12-
139
export function isListLikeIterable(obj: any): boolean {
1410
if (!isJsObject(obj)) return false;
1511
return (

‎packages/core/src/util/security/trusted_types.ts‎

Lines changed: 0 additions & 65 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,6 @@ import {global} from '../global';
2020

2121
import {
2222
TrustedHTML,
23-
TrustedScript,
2423
TrustedScriptURL,
2524
TrustedTypePolicy,
2625
TrustedTypePolicyFactory,
@@ -70,17 +69,6 @@ export function trustedHTMLFromString(html: string): TrustedHTML | string {
7069
return getPolicy()?.createHTML(html) || html;
7170
}
7271

73-
/**
74-
* Unsafely promote a string to a TrustedScript, falling back to strings when
75-
* Trusted Types are not available.
76-
* @security In particular, it must be assured that the provided string will
77-
* never cause an XSS vulnerability if used in a context that will be
78-
* interpreted and executed as a script by a browser, e.g. when calling eval.
79-
*/
80-
export function trustedScriptFromString(script: string): TrustedScript | string {
81-
return getPolicy()?.createScript(script) || script;
82-
}
83-
8472
/**
8573
* Unsafely promote a string to a TrustedScriptURL, falling back to strings
8674
* when Trusted Types are not available.
@@ -93,56 +81,3 @@ export function trustedScriptFromString(script: string): TrustedScript | string
9381
export function trustedScriptURLFromString(url: string): TrustedScriptURL | string {
9482
return getPolicy()?.createScriptURL(url) || url;
9583
}
96-
97-
/**
98-
* Unsafely call the Function constructor with the given string arguments. It
99-
* is only available in development mode, and should be stripped out of
100-
* production code.
101-
* @security This is a security-sensitive function; any use of this function
102-
* must go through security review. In particular, it must be assured that it
103-
* is only called from development code, as use in production code can lead to
104-
* XSS vulnerabilities.
105-
*/
106-
export function newTrustedFunctionForDev(...args: string[]): Function {
107-
if (typeof ngDevMode === 'undefined') {
108-
throw new Error('newTrustedFunctionForDev should never be called in production');
109-
}
110-
if (!global.trustedTypes) {
111-
// In environments that don't support Trusted Types, fall back to the most
112-
// straightforward implementation:
113-
return new Function(...args);
114-
}
115-
116-
// Chrome currently does not support passing TrustedScript to the Function
117-
// constructor. The following implements the workaround proposed on the page
118-
// below, where the Chromium bug is also referenced:
119-
// https://github.com/w3c/webappsec-trusted-types/wiki/Trusted-Types-for-function-constructor
120-
const fnArgs = args.slice(0, -1).join(',');
121-
const fnBody = args[args.length - 1];
122-
const body = `(function anonymous(${fnArgs}
123-
) { ${fnBody}
124-
})`;
125-
126-
// Using eval directly confuses the compiler and prevents this module from
127-
// being stripped out of JS binaries even if not used. The global['eval']
128-
// indirection fixes that.
129-
const fn = global['eval'](trustedScriptFromString(body)) as Function;
130-
if (fn.bind === undefined) {
131-
// Workaround for a browser bug that only exists in Chrome 83, where passing
132-
// a TrustedScript to eval just returns the TrustedScript back without
133-
// evaluating it. In that case, fall back to the most straightforward
134-
// implementation:
135-
return new Function(...args);
136-
}
137-
138-
// To completely mimic the behavior of calling "new Function", two more
139-
// things need to happen:
140-
// 1. Stringifying the resulting function should return its source code
141-
fn.toString = () => body;
142-
// 2. When calling the resulting function, `this` should refer to `global`
143-
return fn.bind(global);
144-
145-
// When Trusted Types support in Function constructors is widely available,
146-
// the implementation of this function can be simplified to:
147-
// return new Function(...args.map(a => trustedScriptFromString(a)));
148-
}

0 commit comments

Comments
 (0)