Learn more about Russian war crimes in Ukraine.

How does the Node.js REPL display previews?

When typing in the node repl, you get instant previews as you type, like this:

Clearly, the REPL is executing your code every time you hit a key. But how can this be safe?! Imagine the chaos if you typed rm -rf /foo/bar/baz and your shell tried to execute it at every keystroke!

The Node.js REPL implementation uses the inspector module, which is an interface to V8. Here’s a basic REPL for Node.js:

const readline = require('readline');
const inspector = require('inspector');
const session = new inspector.Session();
session.connect();
const rl = readline.createInterface({ input: process.stdin });
rl.on('line', function(line) {
  session.post(
    'Runtime.evaluate', 
    { expression: line }, 
    function cb(err, res) {
      console.log(res.result.value);
    }
  );
});

The key is that, for previews, the REPL passes throwOnSideEffect: true to V8. I’m not sure exactly what V8 considers a side-effect, but apparently it doesn’t consider Math.random() to have side-effects. I’m like 99% sure it would consider “deleting all my files” to be a side-effect, though.

What can computers do? What are the limits of mathematics? And just how busy can a busy beaver be? This year, I’m writing Busy Beavers, a unique interactive book on computability theory. You and I will take a practical and modern approach to answering these questions — or at least learning why some questions are unanswerable!

It’s only $19, and you can get 50% off if you find the discount code ... Not quite. Hackers use the console!

After months of secret toil, I and Andrew Carr released Everyday Data Science, a unique interactive online course! You’ll make the perfect glass of lemonade using Thompson sampling. You’ll lose weight with differential equations. And you might just qualify for the Olympics with a bit of statistics!

It’s $29, but you can get 50% off if you find the discount code ... Not quite. Hackers use the console!

More by Jim

Tagged #programming, #javascript. All content copyright James Fisher 2020. This post is not associated with my employer. Found an error? Edit this page.