MCPcopy Create free account
hub / github.com/angular/angular / ɵɵsanitizeResourceUrl

Function ɵɵsanitizeResourceUrl

packages/core/src/sanitization/sanitization.ts:134–148  ·  view source on GitHub ↗
(unsafeResourceUrl: any)

Source from the content-addressed store, hash-verified

132 * @codeGenApi
133 */
134export function ɵɵsanitizeResourceUrl(unsafeResourceUrl: any): TrustedScriptURL | string {
135 const sanitizer = getSanitizer();
136 if (sanitizer) {
137 return trustedScriptURLFromStringBypass(
138 sanitizer.sanitize(SecurityContext.RESOURCE_URL, unsafeResourceUrl) || '',
139 );
140 }
141 if (allowSanitizationBypassAndThrow(unsafeResourceUrl, BypassType.ResourceUrl)) {
142 return trustedScriptURLFromStringBypass(unwrapSafeValue(unsafeResourceUrl));
143 }
144 throw new RuntimeError(
145 RuntimeErrorCode.UNSAFE_VALUE_IN_RESOURCE_URL,
146 ngDevMode && `unsafe value used in a resource URL context (see ${XSS_SECURITY_URL})`,
147 );
148}
149
150/**
151 * A `script` sanitizer which only lets trusted javascript through.

Callers 1

Calls 5

unwrapSafeValueFunction · 0.90
getSanitizerFunction · 0.85
sanitizeMethod · 0.45

Tested by

no test coverage detected