# 'use initial' directive, for globalThis mutation protection

**URL:** <https://es.discourse.group/t/use-initial-directive-for-globalthis-mutation-protection/1061>\
**Category:** 💡 Ideas\
**Created:** [October 29, 2021, 3:24pm UTC](https://es.discourse.group/t/use-initial-directive-for-globalthis-mutation-protection/1061 "2021-10-29T15:24:49Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![rdking](https://yyz2.discourse-cdn.com/free1/user_avatar/es.discourse.group/rdking/32/54_2.png) [@rdking](https://es.discourse.group/u/rdking)\
**Post date:** [November 1, 2021, 6:01pm UTC](https://es.discourse.group/t/use-initial-directive-for-globalthis-mutation-protection/1061/9 "2021-11-01T18:01:14Z")

</div>

Here's an even cleaner solution: provide an ES API function that allows a caller to disable other builtin API functions. By disable, I mean replace them with `undefined` or a function that throws.

```javascript
globalThis.disableAPI(owner, fnName) {
   let retval = owner.prototype[fnName];
   function disabledFn() {
      throw new ReferenceError(`This function ('${fnName}') has been disabled.`);
   }
   function isOriginal(fn) {
      return !fn.name.startsWith('bound ') && fn.toString().endsWith('{ [native code] }');
   }
   Object.defineProperty(disabledFn, Symbol.disabled, { value: true });
   if (isOriginal(owner) && isOriginal(retval)) {
      owner.prototype = disabledFn;
   }
   else {
      retval = undefined;
   }

   return retval;
}

```

Something like this implemented in engine would disable the call for all successive callers. The catch is that it would have to work in concert with something like `'use initial'` such that use initial would not be allowed to return the original of such disabled functions. It would do so by checking if `Symbol.disabled` has been set on the method. This not only gives the engine a simple, shim-able way of disabling methods, but also gives developers a way of doing the same for registered APIs under my alternative approach.

Regardless, the approach for denying access to ES API built-ins should be something generic. It should probably have a proposal all its own and be applicable regardless of any new feature added. BTW, I set it so the `disableAPI` function returns the original of the function that was disabled. This way the caller still has access to the function if desired.

---

_[View the full topic](https://es.discourse.group/t/use-initial-directive-for-globalthis-mutation-protection/1061)._
