{"slug": "iam-12-i-accidentally-built-a-secure-js-sandbox-while-patching-a-bug-here-is-how", "title": "Iam 12 .I Accidentally Built a Secure JS Sandbox While Patching a Bug. Here is How KODA Runs AI Code.", "summary": "A developer built a secure JavaScript execution sandbox for KODA, an AI coding assistant, by rendering AI-generated code into a hidden iframe with the sandbox=\"allow-scripts\" attribute and omitting allow-same-origin, trapping the code in an opaque origin that cannot access localStorage or the parent DOM. Console output is piped back to the UI via postMessage and execution is capped with a hard 3-second timeout to kill infinite loops without freezing the browser tab. The sandbox ships as a beta feature in KODA v29, which the developer says keeps the entire frontend at 92KB rather than adding Pyodide's 10MB+ WebAssembly Python runtime.", "body_md": "most ai wrappers just spit out a markdown block and say \"good luck.\"\n\nif the ai hallucinates and writes a malicious script or an infinite loop, your machine takes the hit.\n\nyesterday, i was patching a truncated script error in koda v29. the file just... ended mid-sentence. while rebuilding the event listeners, i realized something: i didn't just want koda to *write* code. i wanted it to *prove* the code works.\n\nso i accidentally built a local code execution sandbox. \n\nand it’s running entirely in a single 92kb html file. \n\nthe trick is the html `sandbox` attribute. \n\ni render the ai’s code into a hidden `<iframe sandbox=\"allow-scripts\">`. \n\nnotice what is missing? `allow-same-origin`. \n\nby omitting that, the browser assigns the iframe a completely unique, opaque origin. it is trapped in a ghost dimension. if the ai hallucinates and tries to read my supabase tokens from `localStorage`, or tries to manipulate the parent dom, the browser just blocks it. \n\nit can execute javascript, but it can't touch the real world.\n\nais love writing infinite loops. \n\n`while(true) { console.log(\"oops\") }`\n\nif i just let the iframe run, it would freeze the user's browser tab. \n\nso i overrode `console.log` to pipe the output back to the ui via `postMessage`, and wrapped the execution in a hard 3-second `setTimeout`. \n\nif the code doesn't finish in 3 seconds, the parent process kills the iframe. no frozen tabs. no crashed phones.\n\nright now, if you ask koda to run python or typescript, it just shows a \"coming soon\" toast.\n\npeople asked why i didn't just add python support immediately. \n\nthe answer is **pyodide**. \n\nrunning python in the browser requires webassembly. pyodide adds 10mb+ to your bundle. \n\nkoda’s entire frontend—chat, auth, streaming, ui, and now a code runner—is **92 kilobytes**. \n\nadding a 10mb python engine would destroy the core philosophy: an app that loads in under 1 second on a 3g mobile network. \n\nso for this test release, we are strict vanilla js. i'd rather have a blazing fast js sandbox than a bloated python one. \n\nkoda v29 is live with the sandbox as a beta feature. \n\ngo to koda-aicodementor.netlify.app. \n\nask it to write a javascript fibonacci sequence. click the \"Run\" button. watch it execute locally. \n\nthen, ask it to write an infinite loop. watch the 3-second bouncer kill it.\n\nif you find a way to break out of the ghost dimension, tell me. i'll patch it.", "url": "https://wpnews.pro/news/iam-12-i-accidentally-built-a-secure-js-sandbox-while-patching-a-bug-here-is-how", "canonical_source": "https://dev.to/koda2026/iam-12-i-accidentally-built-a-secure-js-sandbox-while-patching-a-bug-here-is-how-koda-runs-ai-45aj", "published_at": "2026-10-05 12:47:16+00:00", "updated_at": "2026-10-05 12:48:56.340786+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-products"], "entities": ["KODA", "Pyodide"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/iam-12-i-accidentally-built-a-secure-js-sandbox-while-patching-a-bug-here-is-how", "markdown": "https://wpnews.pro/news/iam-12-i-accidentally-built-a-secure-js-sandbox-while-patching-a-bug-here-is-how.md", "text": "https://wpnews.pro/news/iam-12-i-accidentally-built-a-secure-js-sandbox-while-patching-a-bug-here-is-how.txt", "jsonld": "https://wpnews.pro/news/iam-12-i-accidentally-built-a-secure-js-sandbox-while-patching-a-bug-here-is-how.jsonld"}}