# Disable the creation of dynamic function in current realm

**URL:** <https://es.discourse.group/t/disable-the-creation-of-dynamic-function-in-current-realm/145>\
**Category:** 💡 Ideas\
**Created:** [December 5, 2019, 6:47pm UTC](https://es.discourse.group/t/disable-the-creation-of-dynamic-function-in-current-realm/145 "2019-12-05T18:47:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![linzj](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@linzj](https://es.discourse.group/u/linzj)\
**Post date:** [December 5, 2019, 6:47pm UTC](https://es.discourse.group/t/disable-the-creation-of-dynamic-function-in-current-realm/145/1 "2019-12-05T18:47:13Z")

</div>

I am seeking of a mechanism that could make eval and new Function or new o.constructor.constructor disabled, and return undefined or throw an exception. Any exisiting proposal can make it happen?

---

<div class="post-metadata">

**Author:** ![ljharb](https://yyz2.discourse-cdn.com/free1/user_avatar/es.discourse.group/ljharb/32/8_2.png) [@ljharb](https://es.discourse.group/u/ljharb)\
**Post date:** [December 5, 2019, 7:27pm UTC](https://es.discourse.group/t/disable-the-creation-of-dynamic-function-in-current-realm/145/2 "2019-12-05T19:27:49Z")

</div>

If you're interested in doing this in first-party code, you can do this with eslint.

If in browsers, look into CSP ( [https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) ).

---

<div class="post-metadata">

**Author:** ![markm](https://yyz2.discourse-cdn.com/free1/user_avatar/es.discourse.group/markm/32/19_2.png) [@markm](https://es.discourse.group/u/markm)\
**Post date:** [December 6, 2019, 9:26pm UTC](https://es.discourse.group/t/disable-the-creation-of-dynamic-function-in-current-realm/145/3 "2019-12-06T21:26:10Z")

</div>

Realms [https://github.com/tc39/proposal-realms](https://github.com/tc39/proposal-realms)  
shim [https://github.com/Agoric/realms-shim](https://github.com/Agoric/realms-shim)

SES [https://github.com/tc39/proposal-ses](https://github.com/tc39/proposal-ses) but stale proposal text  
shim [https://github.com/Agoric/SES](https://github.com/Agoric/SES) dependent on realms-shim  
shim [https://github.com/Agoric/evaluator-shim](https://github.com/Agoric/evaluator-shim) redesign for single-realm, better security

Presentation to Node security:  
https://www.youtube.com/embed/9Snbss_tawI?feature=oembed&wmode=opaque&list=PLzDw4TTug5O0ywHrOz4VevVTYr6Kj_KtW

---

<div class="post-metadata">

**Author:** ![linzj](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@linzj](https://es.discourse.group/u/linzj)\
**Post date:** [December 6, 2019, 11:34pm UTC](https://es.discourse.group/t/disable-the-creation-of-dynamic-function-in-current-realm/145/4 "2019-12-06T23:34:23Z")

</div>

Thanks to all you folks. I will look into it.

But now we just disable them for good. eval is really evil. Our scenario just like node, not web. But we use some of the cross site security like web's frame.
