Use of SCE bypass¶
Scope and lifecycle¶
AngularJS 1.x Strict Contextual Escaping (SCE) distinguishes values that may enter sensitive contexts. $sce.trustAsHtml asserts trust; it does not sanitize input. Disabling SCE globally removes additional protections. Official AngularJS support ended in January 2022, so remediation should include a migration plan. See the AngularJS project status and $sce reference.
Legacy plain-text example¶
Assume userText is an untrusted string already in scope. The requirement is to display its text, with no user-authored formatting.
Unsafe AngularJS controller assignment and template:
$scope.displayValue = $sce.trustAsHtml(userText);
<p ng-bind-html="displayValue"></p>
Safer AngularJS controller assignment and template:
$scope.displayValue = userText;
<p ng-bind="displayValue"></p>
The text binding does not interpret the value as HTML. Leave SCE enabled, remove unnecessary trust wrappers and check filters/directives that may reintroduce them. A regex that removes selected words or tags is not an HTML sanitizer.
Modern Angular distinction¶
Modern Angular is a different framework with its own security model. Use ordinary text interpolation for this requirement. DomSanitizer.bypassSecurityTrustHtml is also a trust assertion, not a sanitizer. Review any intentional rich-HTML feature against the current Angular security guidance, including the binding context and source of the data.
Regression check¶
With an inert <em>sample</em> string, confirm the text binding displays the angle brackets and does not create an element. Check both initial rendering and updates in the actual AngularJS application. Test migration behavior separately in the target Angular version; changing a trust call does not address the legacy framework's support status. See HTML injection and autoescaping.