• onlinepersona
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 day ago

    I’m not even sure whether there’s a defense against this when trying to limit the user to a subset of JavaScript. It feels like you need to write a compiler or interpreter that doesn’t know anything outside of that subset otherwise you can break out of the language sandbox.