Docs / Reference
Outside Access
Code that reaches your files, the network or other programs is not run as you type. JSpark waits for you to press Run.
JSpark reads each Snippet as you type. Code that reaches outside it runs only when you press Run.
What counts as Outside Access
JSpark looks for code that uses one of these, with or without the node: prefix:
- Your files:
fs,fs/promises,sqlite, andprocess.chdir. - The network:
http,https,http2,net,dgram,dns,tls, andfetch,WebSocketandEventSource. - Other programs:
child_process,cluster,worker_threads,repl, andprocess.kill,process.exitand the like. - This process:
vm,v8,inspector,module, andprocess.env. - Anything at runtime:
eval,Function, and animportorrequirewhose name is built while the code runs.
In a Node Snippet, an npm package counts too, because JSpark can't tell what a package does. A short list of packages that only compute is the exception, such as lodash, date-fns, zod and uuid. In a Web Snippet, packages don't count: they run in the page.
It counts import, require() and import() alike. A name in a comment or a string doesn't count. In a Web Snippet, code in the HTML's attributes is read too, and in a Vue or Svelte component, the template.
What JSpark does then
The Snippet no longer runs as you type. In the rail, a warning shield takes the place of the bolt that turns Run as you type on and off, and the footer says Runs on demand. Hover the shield to see why, for example Uses your files, so auto-run is paused.
Press Run or ⌘↵ or Ctrl+Enter whenever you are ready. Nothing is forbidden, only not started for you. Remove the code that reaches outside, and the Snippet can run as you type again.
What it does not do
Outside Access keeps a Snippet out of Run as you type. It does not limit what a Run can do once you press Run.
- A Node Run is real Node, with your own access to your files, the network and your programs.
- A Web Run is a real web page, with a page's access.
- JavaScript can reach outside in ways that reading the code can't show. A Snippet without the shield may still reach outside when it runs.
Run only code you would run with node on your own computer. Relative paths in a Node Run go to the The Working Folder, but a Snippet can still write anywhere you can.
The pictures show JSpark on a Mac. On Windows, the window looks a little different and uses Ctrl for ⌘, but everything works the same way.