2 ms·
Thanks! - At the moment if a package tries to access a core lib it doesn't have permission to it will throw an exception. This behaviour is currently the same
by matthayward1997 8y ago
Thanks!
- At the moment if a package tries to access a core lib it doesn't have permission to it will throw an exception. This behaviour is currently the same on both development and production.
- There currently isn't a way for packages to specify which core modules they need access to. This is a long term goal and ideally we'd integrate something into npm itself to verify these and any changes to these permissions that occur.
- At the moment it works on a top down permission propagation. So if a parent module has access to 'fs' for example, so will all of its dependencies. I'm looking to change this behaviour so this is no longer default for reasons outlined by others.
- Haven't reached out NPM just yet, but it's on the todo list.