(unsafeResourceUrl: any)
| 132 | * @codeGenApi |
| 133 | */ |
| 134 | export function ɵɵsanitizeResourceUrl(unsafeResourceUrl: any): TrustedScriptURL | string { |
| 135 | const sanitizer = getSanitizer(); |
| 136 | if (sanitizer) { |
| 137 | return trustedScriptURLFromStringBypass( |
| 138 | sanitizer.sanitize(SecurityContext.RESOURCE_URL, unsafeResourceUrl) || '', |
| 139 | ); |
| 140 | } |
| 141 | if (allowSanitizationBypassAndThrow(unsafeResourceUrl, BypassType.ResourceUrl)) { |
| 142 | return trustedScriptURLFromStringBypass(unwrapSafeValue(unsafeResourceUrl)); |
| 143 | } |
| 144 | throw new RuntimeError( |
| 145 | RuntimeErrorCode.UNSAFE_VALUE_IN_RESOURCE_URL, |
| 146 | ngDevMode && `unsafe value used in a resource URL context (see ${XSS_SECURITY_URL})`, |
| 147 | ); |
| 148 | } |
| 149 | |
| 150 | /** |
| 151 | * A `script` sanitizer which only lets trusted javascript through. |
no test coverage detected