3 ms·
> Just wish I can only give authorization to certain JS api. This is already implemented in any browser I know, but for some reason it is available only to som
by keinplan 5y ago
> Just wish I can only give authorization to certain JS api.
This is already implemented in any browser I know, but for some reason it is available only to some functionality (microphone, camera etc.) but not for eg. Ajax, Cross-Origin Things, Websockets, Canvas2D, WebGL etc.
Also before executing any Javascript browsers should ask if you want this website to execute (potentially malicious) code on your computer!
- noahtallen 5y agoJS is pretty well sandboxed — are there any examples of websites doing anything outside of their own JS context?
- keinplan 5y agoRemote-code-execution as a feature just isn't a good idea. Sandboxes can (and Murphy's Law says they will) be broken out of. There are many documented browser-exploits and basically all newer ones that are actually a danger to users involve Javascript. It's also not reasonable to assume that people only visit trusted sites.