-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Disable node integration in worker #8822
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
cwangsmv
reviewed
Jul 7, 2025
|
28eeb45
to
49ad3cf
Compare
1c7d0c3
to
3eaa758
Compare
7140033
to
86ba77f
Compare
gatzjames
approved these changes
Jul 14, 2025
RoamingLost
pushed a commit
to RoamingLost/insomnia
that referenced
this pull request
Aug 6, 2025
* simplify out tough-cookie * remove fs from vite config * bridge fs os and decode * polyfill crypto and uuid * replace node:url * remove require interceptor * bridge jsonpath * disable node in worker * fix elevated extension * remove spectral optimzation * abstract and type db router * complete abstraction * add info about dev deps * revert encode url * fix and extend tests * use jsonpath-plus import esm * fix type check * hide the openapi spam * rename readFile * optimise import * fix md5 test * speed up grpc test * fix grpc test * use global timeout * fix lint * fix tests * fix types * complete os support * fix test * update nodeOS
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
motivation: turn web worker into a sandbox capable of limiting what can be done from a nunjucks crafted tag. eg {{ require('fs').rmdir('/Users') }}
approach: build fewest bridges as possible to limit exploitable surface, therefore maximise use of available browser apis.
consequences of this approach:
todo
For later
issues