MenuReference / Outside Access

Docs / Reference

Outside Access

Code that reaches your files, the network or other programs is not run as you type. JSpark waits for you to press Run.

On this page

JSpark reads each Snippet as you type. Code that reaches outside it runs only when you press Run.

What counts as Outside Access

JSpark looks for code that uses one of these, with or without the node: prefix:

  • Your files: fs, fs/promises, sqlite, and process.chdir.
  • The network: http, https, http2, net, dgram, dns, tls, and fetch, WebSocket and EventSource.
  • Other programs: child_process, cluster, worker_threads, repl, and process.kill, process.exit and the like.
  • This process: vm, v8, inspector, module, and process.env.
  • Anything at runtime: eval, Function, and an import or require whose name is built while the code runs.

In a Node Snippet, an npm package counts too, because JSpark can't tell what a package does. A short list of packages that only compute is the exception, such as lodash, date-fns, zod and uuid. In a Web Snippet, packages don't count: they run in the page.

It counts import, require() and import() alike. A name in a comment or a string doesn't count. In a Web Snippet, code in the HTML's attributes is read too, and in a Vue or Svelte component, the template.

What JSpark does then

The Snippet no longer runs as you type. In the rail, a warning shield takes the place of the bolt that turns Run as you type on and off, and the footer says Runs on demand. Hover the shield to see why, for example Uses your files, so auto-run is paused.

The shield says the Snippet uses your files; it runs once Run is pressed.

Press Run or ⌘↵ or Ctrl+Enter whenever you are ready. Nothing is forbidden, only not started for you. Remove the code that reaches outside, and the Snippet can run as you type again.

What it does not do

Outside Access keeps a Snippet out of Run as you type. It does not limit what a Run can do once you press Run.

  • A Node Run is real Node, with your own access to your files, the network and your programs.
  • A Web Run is a real web page, with a page's access.
  • JavaScript can reach outside in ways that reading the code can't show. A Snippet without the shield may still reach outside when it runs.

Run only code you would run with node on your own computer. Relative paths in a Node Run go to the The Working Folder, but a Snippet can still write anywhere you can.

The pictures show JSpark on a Mac. On Windows, the window looks a little different and uses Ctrl for ⌘, but everything works the same way.

Esc

Type to search every docs page.