4 ms·
There are many ways to load and execute JavaScript, static/dynamic adding a script tag to the html, html imports, manual fetch + eval , concatenation of javascr
by GroSacASacs 10y ago
There are many ways to load and execute JavaScript, static/dynamic adding a script tag to the html, html imports, manual fetch + eval , concatenation of javascript files in 1 file, in the future maybe the import syntax ? and now <script module> ?
Do we really want to add more ways ? Complexity is an enemy of security, it will add more confusion. Maybe we should first disable/remove ways to load and execute JavaScript.
We should also think, if what really need is a client solution or a better tool/system to transform scripts, in a script server side.
Why, what should be clearly answered before thinking in terms of how.
Sometimes having the bigger picture in your head helps.
- esailija 10y agoYou basically cannot ever remove anything as it will break websites which will just make people switch to another browser where the websites work.
- GroSacASacs 10y agoBy remove, I meant "encourage to not do that". Like JSLint or "use strict"; didn't remove JavaScript possibilities, it encouraged us to not write insane JavaScript. They should consider making a document that lists all possibilities to organize code in modules and explain why some are betters than others, then in the same document explain the benefit for new syntax.