The implementation captures intrinsics and repeatedly invokes methods through saved Reflect.apply references. @naugtur suggested using an uncurryThis helper to make this defensive code shorter and easier to review.
Review SES's approach to intrinsic capture and determine where receiver-first wrappers would simplify the existing code without changing its security assumptions. Capture any helper and method references before guest execution; document the exceptions where direct Reflect.apply remains appropriate. Validate that the refactor preserves behavior when guest-visible built-ins are modified.
This is a maintainability proposal, not a claim that the existing captured-Reflect.apply approach is incorrect.
Reference: SES intrinsic capture and uncurryThis.
Based on review feedback from @naugtur, shared in a discussion with the maintainer.
The implementation captures intrinsics and repeatedly invokes methods through saved
Reflect.applyreferences. @naugtur suggested using anuncurryThishelper to make this defensive code shorter and easier to review.Review SES's approach to intrinsic capture and determine where receiver-first wrappers would simplify the existing code without changing its security assumptions. Capture any helper and method references before guest execution; document the exceptions where direct
Reflect.applyremains appropriate. Validate that the refactor preserves behavior when guest-visible built-ins are modified.This is a maintainability proposal, not a claim that the existing captured-
Reflect.applyapproach is incorrect.Reference: SES intrinsic capture and uncurryThis.
Based on review feedback from @naugtur, shared in a discussion with the maintainer.