3 ms·
Caja's spiritual successor is HardenedJS (https://hardenedjs.org/ https://hardenedjs.org/), authored by some of the same folks (Mark Miller + friends). As I und
by kumavis 1y ago
Caja's spiritual successor is HardenedJS (https://hardenedjs.org/ https://hardenedjs.org/), authored by some of the same folks (Mark Miller + friends). As I understand it, Caja attempted to secure not just javascript but the DOM as well, which ultimately proved to be a too large, interconnected, and rapidly changing surface to keep up with.
LavaMoat (https://lavamoat.github.io/ https://lavamoat.github.io/), while not quite object capabilities, builds on HardenedJS to provide runtime supplychain security protections to js apps (nodejs or browser) by eliminating ambient authority and only exposing global capabilities per npm package according user-specified policy. LavaMoat is used in production at MetaMask, protecting ~300M users.
OCapN (https://github.com/ocapn/ocapn/ https://github.com/ocapn/ocapn/) is a nascent effort to standardize a distributed object capability protocol (transferring capabilities across mutually distrusting peers).