Commit Graph

38029 Commits

Author SHA1 Message Date
Kristiyan Kostadinov 2a141847a5 fix(forms): add utility to assert that value is a field tree
Adds the `isFieldTree` utility that allows users to assert whether a value is a field tree. This is something that has come up on Material recently and will be useful for users as well.

Fixes #69984.
2026-07-29 08:53:24 -07:00
Matthew Beck d44b3224d9 test(compiler-cli): add compliance case for @HostListener on a property
`@HostListener` is not limited to methods — it is equally valid on a property
holding a function, which is the idiomatic way to keep `this` bound:

    @HostListener('window:beforeunload', ['$event'])
    private onUnload = (event: BeforeUnloadEvent) => {...};

Every existing host-listener compliance case declares the handler as a method,
so the property form was uncovered. This adds a case exercising both a public
and a private function-valued property, one of them with a global (`window:`)
event target, and locks in the emitted chained `ɵɵlistener` calls plus
`ɵɵresolveWindow`.

Verified against all four compliance modes (full, partial/linked,
declaration-only); GOLDEN_PARTIAL.js regenerated via the golden update rule.
2026-07-29 08:52:53 -07:00
Matthieu Riegler 36474f7011 refactor(common): remove duplicate helper function
We have `useAutoTick` in our private shared utils.
2026-07-29 08:49:15 -07:00
Maikel van Dort 9373d22a48 docs: remove semicolon text node 2026-07-29 08:48:34 -07:00
Angular Robot 4eb0ed077c build: lock file maintenance
See associated pull request for more information.
2026-07-29 08:46:37 -07:00
Matthieu Riegler c1025a0510 refactor(core): Migrate more tests off fakeAsync
This will prevent to polute the agent context with outdated/bad practices.
2026-07-29 08:46:01 -07:00
Alan Agius 2bcd12a6a5 docs: update default value for strictTemplates
Updates the strictTemplates documentation in Angular compiler options to note that the default is true, replacing the reference to the obsolete ng new --strict flag.
2026-07-29 08:42:11 -07:00
Edu 1b09130640 feat(devtools): rename DevTools tab to "Angular & Wiz" for Googlers
Conditionally update the browser DevTools tab name to "Angular & Wiz" if the user is identified as a Google employee via internal corp network detection.
2026-07-29 08:41:07 -07:00
Jaime Burgos de240a5d0e fix(http): enable xsrf for root-provided HttpClient
Include the XSRF interceptor in the root token factory so the automatically provided HttpClient retains the documented default protection without requiring provideHttpClient().
2026-07-29 08:40:09 -07:00
brysonbw d5e8b1ef7a feat(forms): allow permanent hidden fields in signal forms
Allow the hidden utility function to be called without a configuration object to make fields permanently hidden.
2026-07-29 08:39:39 -07:00
SkyZeroZx f33ee95045 fix(http): match header values exactly when deleting
Normalize value-specific HttpHeaders deletions before filtering. The string overload previously used String#indexOf and removed shorter values contained within the requested deletion value, potentially widening outgoing request metadata.

Preserve delete-all behavior only when no value is supplied, and cover string, array, and empty-string deletion.
2026-07-29 08:39:07 -07:00
SkyZeroZx ff02a16749 fix(http): preserve immutability of materialized clones
Prevent lazy HttpHeaders and HttpParams clones from reusing value arrays owned by a materialized source. Append and value-specific delete operations previously mutated those shared arrays, violating the immutable API contract and allowing request metadata to bleed into later requests.

Share value arrays until an update mutates a specific header or parameter, then copy only that array. Cover the affected append and delete paths with regression tests that materialize the source first.
2026-07-29 08:39:07 -07:00
Georgi Serev 184c4797b8 refactor(devtools): rename timing API to performance track
Rename Timing API to Performance Track to better reflect the purpose of the actual feature;
Migrate the settings data object to match the new name and drop some redundant keys.
2026-07-29 08:38:39 -07:00
Jaime Burgos 840f071566 docs: Adds HTTP communication guidance to Angular Skills 2026-07-29 08:37:14 -07:00
SkyZeroZx f57d5d5c8c fix(core): account for namespaces in host binding sanitization (#69558)
Make runtime URL sanitizer selection namespace-aware so SVG and MathML host bindings match the security schema.

Cover SVG href/xlink:href and MathML href host binding cases, including dynamic hostElement resolution.

PR Close #69558
2026-07-29 08:36:32 -07:00
SkyZeroZx d06e3748b7 fix(core): sanitize host bindings on concrete hosts (#69558)
Host binding sanitization previously used the declaring directive or component selector to choose a compile-time security context. The same host binding can execute on a different concrete element through hostDirectives, inherited host bindings, dynamic directives, or createComponent hostElement usage.

Compute host binding security contexts against possible concrete hosts and defer URL versus ResourceURL selection to runtime when necessary. Resolve dynamic root host TNodes to their native tag before sanitizer and security-sensitive attribute checks.

Fixes angular#69550

PR Close #69558
2026-07-29 08:36:32 -07:00
Suraj Yadav 5ad8231397 fix(migrations): correctly detect then/else keywords in control flow migration
The control flow migration determines whether an `*ngIf` uses a `then`
and/or `else` clause by regex matching the raw microsyntax string for
the literal keywords `then`/`else`. The regexes only checked that the
keyword was preceded by a non-word character, but not that it was
followed by one.

As a result, a template reference name that merely starts with `then`
(e.g. `else thenBlock`) or `else` was misidentified as the `then`/`else`
keyword itself. This caused the migration to take the wrong code path
(e.g. then+else instead of else-only), which in turn made
`getTemplateName()` compute a `slice(start, end)` with `start > end`,
producing an empty template name. That empty placeholder was never
resolved and was silently emitted as an invalid
`<ng-template [ngTemplateOutlet]=""></ng-template>`, dropping the
original template content without any warning.

Add a negative lookahead `(?![\w\d])` to both regexes so `then`/`else`
are only matched as whole keywords, not as a prefix of a longer
template reference name.

Fixes #69914
2026-07-24 13:56:17 -07:00
Matthew Beck 5245ca5ba7 test(compiler-cli): format compliance TEST_CASES.json with prettier
Reformats the TEST_CASES.json files touched by the following change so they
satisfy the repo's prettier check (short inputFiles/files arrays collapsed to a
single line). Pure formatting; the parsed JSON is unchanged. Split into its own
commit so the coverage change that follows is easy to review.
2026-07-24 13:55:33 -07:00
Kristiyan Kostadinov e606a020e9 fix(language-service): account for strictTemplates being enabled by default
We were raising the suggestion about enabling `strictTemplates` when `strictTemplates` is ommitted, however the option is now enabled by default.

Fixes #69905.
2026-07-24 13:45:24 -07:00
Angular Robot 7cbf5e3c2b build: update all github actions
See associated pull request for more information.
2026-07-24 13:43:29 -07:00
Ben Hong 17845308ea docs: modernize directives guides (#69822)
Co-authored-by: Matthieu Riegler <kyro38@gmail.com>

PR Close #69822
2026-07-24 10:36:58 -07:00
Ben Hong 4e7aaa48f5 docs: smooth out directives guide narrative flow (#69822)
PR Close #69822
2026-07-24 10:36:58 -07:00
Kam 28d59e8d63 docs: use https for external links in adev
Several guides, examples, and the update-guide recommendations linked to
external resources over insecure http. Switch them to https.
2026-07-24 08:28:08 -07:00
mfstapert 738b8fe9d2 docs: update attribute testing guide to include canonical example with local component 2026-07-24 08:27:15 -07:00
Jens Kuehlers 25dbe79507 docs: add v23 release and change to yearly release cycle
## Summary

This PR adds v22.x and v23 release dates. It also changes Angular's release cadence to a yearly cycle.

## Why we are making this change

The community has long requested less frequent major releases due to the impact of breaking changes and upgrades for their projects as well as for enterprise customers. Additionally, a longer release cycle provides increased API stability for developers using agentic workflows, while still delivering a reasonable cadence of API upgrades and migrations.
2026-07-24 08:26:32 -07:00
Kristiyan Kostadinov d79b3b65e9 refactor(core): align navigation types with built in ones
Aligns our clone of the navigation API types with the built-in TypeScript types. This is related to an internal issue.
2026-07-24 08:26:02 -07:00
Doug Parker e779309930 release: bump Angular DevTools version to 1.18.0 2026-07-23 12:02:11 -07:00
Pawel Kozlowski 3bf24306be docs: release notes for the v22.1.0-rc.0 release 2026-07-22 16:45:32 +02:00
Pawel Kozlowski c855a5689f release: bump the next branch to v22.2.0-next.0 2026-07-22 16:45:32 +02:00
Pawel Kozlowski 509cad6e15 docs: release notes for the v22.0.8 release 2026-07-22 16:35:02 +02:00
Pawel Kozlowski e428df2b89 build: update pnpm-lock.yaml
Update pnpm lock after it got desychronized in
791b0646c8 build: update all non-major dependencies
2026-07-22 16:18:13 +02:00
Kam ab52df470a fix(docs-infra): fail the guide build when a markdown file starts with a BOM
A leading UTF-8 byte order mark (U+FEFF) before the first `#` stops the
Markdown parser from recognizing the heading, so the guide renders its
title as a paragraph and drops the standard docs header. The character
is invisible, so it cannot be caught in review.

Add a check in the guides generation pipeline that throws when a source
file starts with a BOM, failing the build with the offending file name.
This sits alongside the existing unknown-anchor check and prevents the
regression fixed in #69889 from recurring.
2026-07-22 14:26:19 +02:00
Kam f12db89659 docs: fix first heading rendering as paragraph on two template guides
The ng-container and binding template guide files each began with a
UTF-8 BOM (EF BB BF) before the leading `#`. The docs markdown parser
only promotes `#` to an H1 when it is the first character on the line,
so the BOM demoted the title to paragraph text (`<p># ...</p>`) and the
standard docs header (breadcrumbs, page title, edit button) never
rendered.

Stripping the BOM restores `#` as the first character, so both pages
now generate the proper `<header class="docs-header">` block. Verified
by rebuilding //adev/src/content/guide/templates:templates and
inspecting the generated HTML.

Fixes #69889
2026-07-22 14:26:19 +02:00
Angular Robot 9a1e620603 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-07-22 13:25:54 +02:00
hawkgs e23541b263 fix(zone.js): vitest patching of describe/it curried calls
Separate direct from curried calls of `describe`/`it` modifiers
(direct: `skip`, `only`, etc.; curried: `runIf`, `each`, etc.)
and perform the required patching to them.

Fixes: #69748
2026-07-22 12:34:00 +02:00
Jaime Burgos d14696e430 fix(common): preserve crossorigin on image preloads
Propagate the crossorigin attribute from priority NgOptimizedImage hosts to SSR-generated preload links. Keep preload and image requests in the same credentials mode to avoid an anonymous image issuing an earlier credentialed request.
2026-07-22 12:31:52 +02:00
Kam 6557df5dbe docs: update stale Twitter reference to X in the URL matcher guide
Twitter is now X. In the custom-route-matcher guide, point the author-credit
link at x.com and refer to an "X (formerly Twitter) handle" (clarified once,
then "X handle"), matching the "X (formerly Twitter)" wording already used in
the footer, navigation, and update guide.
2026-07-22 12:01:16 +02:00
Nikita Barsukov cb1841d10b docs: outdated section in the Signal Forms | Custom controls page 2026-07-22 12:00:06 +02:00
SkyZeroZx d955d67b57 docs: clarify usage of 'same-origin' mode and add SSR considerations 2026-07-22 11:58:56 +02:00
SkyZeroZx 6371f0beb1 docs: add skills for Angular pipes 2026-07-22 11:52:33 +02:00
SkyZeroZx 6ac3e26fe0 docs: clarify pipe usage to avoid DI misuse 2026-07-22 11:50:12 +02:00
Suraj Yadav 49672c437b fix(migrations): correctly migrate ngClass with mixed space-separated keys
Preserve NgClass import on partial migration and increment
skippedNgClassCount when an unmigrable mixed binding is encountered.
2026-07-21 19:20:20 +02:00
splincode 8201cebc49 refactor(compiler): enforce exhaustive defer trigger handling
Store the trigger kind before each switch and assign the value to `never` in the fallback branch.

This removes the `any` casts and makes the switches exhaustive. Adding a new `DeferTriggerKind` without handling it in either phase now produces a TypeScript compilation error.

Runtime behavior and error messages remain unchanged.
2026-07-21 19:19:02 +02:00
Angular Robot 9bf8b8ca56 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-07-21 17:20:55 +02:00
Kam 8422da814d feat(docs-infra): react with Angie in the playground minigame
The angle-guessing minigame's result popup personifies your score with a
hand-drawn stick-figure that changes expression by accuracy. Now that Angie
appears across adev — the 404 page, docs search, the embedded editor, the
tutorial intros and completions — give the minigame the same treatment so
its result feels consistent with the rest of the docs.

Replace the result reactor's stick-figure illustration with an Angie pose
keyed to accuracy (seven tiers, superhero down to angry). She is revealed
once the accuracy counter finishes counting up, popping in beside a speech
bubble that carries the round's existing quote. The result popup is widened
so Angie and the bubble sit side by side, and the share link is moved from
twitter.com to x.com.

This removes the previous hand-drawn stick-figure result art. NG the Angle,
the interactive character in the play area, is unchanged.
2026-07-21 17:19:58 +02:00
Angular Robot 791b0646c8 build: update all non-major dependencies
See associated pull request for more information.
2026-07-21 17:17:43 +02:00
Matthieu Riegler 3497c9b943 fix(forms): ensure pending status propagates to the root form in signal forms
Previously, the `pending()` status on a field's `ValidationState` only checked if the field itself or its immediate children had a pending asynchronous validator by directly inspecting `asyncErrors()`. This meant that a pending asynchronous validator deep within a nested form (e.g. on a grand-child) would not correctly bubble the `pending` state up to the root form.

fixes #69840
2026-07-21 13:48:32 +02:00
Angular Robot 22aecf5ed9 build: update cross-repo angular dependencies
See associated pull request for more information.
2026-07-21 13:28:27 +02:00
Angular Robot 9ca95d8f0e build: update bazel dependencies
See associated pull request for more information.
2026-07-21 13:25:46 +02:00
Angular Robot 2bc2146e09 build: update pnpm to v11.15.1
See associated pull request for more information.
2026-07-21 12:08:13 +02:00