4 ms·
Unfortunately no, because `import` is special syntax that just happens to look like a function call. It's not actually a function/object/etc. in the global scop
by exogen 8y ago
Unfortunately no, because `import` is special syntax that just happens to look like a function call. It's not actually a function/object/etc. in the global scope. Here's what Google's guide to `import` says about it:
> Note: Although import() looks like a function call, it is specified as syntax that just happens to use parentheses (similar to super()). That means that import doesn't inherit from Function.prototype so you cannot call or apply it, and things like const importAlias = import don't work — heck, import is not even an object! This doesn't really matter in practice, though.
Using eval (or the Function form of it in this case) doesn't seem like a huge issue here, because if you're accepting a user-supplied `src`, it doesn't have to contain any malicious syntax escapes in the `src` string itself to do whatever it wants...they could just supply a perfectly normal script URL of their choosing that will be executed anyway.