@naugtur noted that removing individual global properties carries a similar maintenance burden to denying individual Node APIs. The suggested direction was to control the guest's global environment ahead of execution and expose selected capabilities explicitly.
Evaluate the feasibility of a controlled global environment or SES Compartment for the supported source and module modes. Consider the Scope Ceiling proposal as a design reference, not as an assumed available runtime feature. Document how global name resolution, globalThis, native module loading, and explicit host-function globals would behave, including limitations of merely replacing a globalThis reference.
Produce a design decision identifying which global capabilities are intentionally available and how additions would be reviewed. Coordinate this with the wider default-deny Node API evaluation, while keeping global name resolution as a distinct concern.
References:
Based on review feedback from @naugtur, shared in a discussion with the maintainer.
@naugtur noted that removing individual global properties carries a similar maintenance burden to denying individual Node APIs. The suggested direction was to control the guest's global environment ahead of execution and expose selected capabilities explicitly.
Evaluate the feasibility of a controlled global environment or SES Compartment for the supported source and module modes. Consider the Scope Ceiling proposal as a design reference, not as an assumed available runtime feature. Document how global name resolution,
globalThis, native module loading, and explicit host-function globals would behave, including limitations of merely replacing aglobalThisreference.Produce a design decision identifying which global capabilities are intentionally available and how additions would be reviewed. Coordinate this with the wider default-deny Node API evaluation, while keeping global name resolution as a distinct concern.
References:
Based on review feedback from @naugtur, shared in a discussion with the maintainer.