4 ms·
Yep: custom domain, iframe security policies. Communicate with the iframe via postMessage only, be strict about message origins, and have limited trust in those
by tmcw 6y ago
Yep: custom domain, iframe security policies. Communicate with the iframe via postMessage only, be strict about message origins, and have limited trust in those messages, too. Strict CSP policies and use the 'sandbox' iframe attribute.
iframes are cruddy, but they are designed for this - the long era of iframe-based embedded advertisements caused vendors to double-down on those security policies.
Observable doesn't use WebWorkers, duktape, or a custom JavaScript interpreter. If you had sandboxed JavaScript that didn't need access to the DOM, those might be options, but if you want people to write JavaScript like usually, they don't do any good.
- seanwilson 6y agoThis would cover protecting user code from the app code but what can you do to protect code from one user against code from another user? Custom domain for every user?
- tmcw 6y agoYes, use per-user domains to make sure that things like localStorage, which is domain-associated, is not leaked from one script to another.