3 ms·
I really dont see the importance of this security layer, unless you major mess up and start eval'ing user input. I first I thought this was like deno where you
by herohamp 7y ago
I really dont see the importance of this security layer, unless you major mess up and start eval'ing user input. I first I thought this was like deno where you provide permissions from the commandline, but providing permissions inside of the code itself really doesnt make much sense to me. Am I missing something/viewing it in the wrong mindset?
- deleted 7y ago[deleted]
- bengl 7y agoHi there! I'm one of Osgood's authors. To clarify a few things: 1. Any tool that reduces the privileges of your application code, such as Osgood or Deno, is doing so because application code cannot necessarily be trusted, since you're pulling in external dependencies that can have vulnerabilities or malicious code, and even one's own code may have unknown vulnerabilities that may cause unexpected IO behaviour to happen. 2. The policies you can set with Osgood are defined in a JavaScript file that is run separately from your application code (i.e. the worker files), and it only runs once to build up the policy data structures in native code. This V8 Isolate is then discarded. This means that application code cannot modify its own policies.
- sneak 7y agoMost javascript apps are indeed eval’ing user input: they just happen to be users of npm instead of users of the app being run. Same problem, though.