4 ms·
Except that with Deno, everything IO related is turned off by default and has to be granted access before it becomes a process. It's the first bullet point on t
by 0beah 6y ago
Except that with Deno, everything IO related is turned off by default and has to be granted access before it becomes a process. It's the first bullet point on the landing page.
Here is the page with more detail.
https://deno.land/manual/getting_started/permissions https://deno.land/manual/getting_started/permissions
It can even restrict access down to a specific directory or host. This is cool.
Whereas any NPM module can map your subnet, lift your .ssh directory, and yoink environment variables, wily-nily.
It's happened before.
- sterlind 6y agoThat still doesn't prevent imported modules from yoinking anything you did grant access to, though. For instance, if my service connects to a DB then `uuid` can slurp the contents. It'd be nice to have some capability model where modules can only access things through handles passed to them, but probably infeasible for a project like this.
- mrkurt 6y agoYou can actually run things as Workers in Deno and get some sandboxing abilities: https://github.com/denoland/deno/blob/master/docs/runtime/workers.md https://github.com/denoland/deno/blob/master/docs/runtime/wo...