Skip to solution
hardFrontend

What are security vulnerabilities in Angular apps, and how does DomSanitizer prevent XSS?

1.2k views
01

Understand the problem

Explain Angular security model and context sanitization.

securityxss
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Nudge consolestandby

Stuck? Beam a request up — the console returns a conceptual nudge that guides your logic without spoiling the implementation.

03

Study the solution

Angular automatically escapes template bindings to prevent XSS. For dynamic content (e.g. iframe URLs, raw HTML, styles), inject DomSanitizer and call explicit trust methods (e.g., bypassSecurityTrustHtml()) only after manual sanitization.

Solution ready — 2 min read

Classified // press E to declassify

04

Read the code

Rendering dynamic video content in an iframe safely using DomSanitizer
import { Component, OnInit, inject } from '@angular/core';
import { DomSanitizer, SafeResourceUrl } from '@angular/platform-browser';

@Component({
  selector: 'app-safe-player',
  standalone: true,
  template: '<iframe [src]="safeUrl" width="560" height="315"></iframe>'
})
export class SafePlayerComponent implements OnInit {
  private sanitizer = inject(DomSanitizer);
  safeUrl!: SafeResourceUrl;

  ngOnInit() {
    const rawVideoId = 'dQw4w9WgXcQ';
    const rawUrl = 'https://www.youtube.com/embed/' + rawVideoId;
    this.safeUrl = this.sanitizer.bypassSecurityTrustResourceUrl(rawUrl);
  }
}
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.

Transmission complete // awaiting log

KEEP THE
STREAK ALIVE.

Dossier 80 of 121 decoded in the Angular track. One more won't hurt.

Back to track