Repository navigation
Add way to stop the module resolution at a specific directory #43368
Description
Activity
- addedfeature requestIssues requesting new Node.js features.Issues requesting new Node.js features.
on Jun 10, 2022 Duplicate of #43192?
@nodejs/modules
Duplicate of #43192?
I've seen this issue before. I think it's related, but not exactly a duplicate. My intent is not related to security at all - only to improve the development process.
This is already possible via loaders: https://nodejs.org/api/esm.html#resolvespecifier-context-defaultresolve. I don’t think Node will likely support any other ways of customizing resolution, as there are too many potential preferences to consider. The
resolvehook allows you to write your own resolution algorithm if you’d prefer behavior different from Node’s default.@tmtron if an environment variable or command line argument meets your need, would a policy like the following do what you want, placed in the dist directory and loaded with
--experimental-policy? Alternatively placed somewhere else with the path adjusted accordingly.{ "scopes": { "./": { "integrity": true, "dependencies": true } } }NODE_OPTIONScan be set if an environment variable would be more convenient.@arhart Thanks, that seems to work.
- in my
distdirectory- I create the
policy.jsonfile:{ "scopes": { "./": { "integrity": true, "dependencies": true } } } - I also need a
package.jsonfile (can be empty) - then start the application with:
node --experimental-policy=policy.json main.js
- I create the
- in my
With policies now marked as deprecated, is there an alternative approach to achieving the above solution?
Reacted by ericchase, Matt Montag and JavierReacted by ericchaseReacted by ericchase
What is the problem this feature will solve?
Currently the node resolution will traverse all the way up to the root of the file-system.
It would be great to have a way to stop the resolution at a specific directory.
There are different use-cases that could benefit from this
package.jsonfiles at different levelspackage.jsonfile may wish to only use dependencies in this project to make sure, that no other dependencies are used by accidentdistdirectory which may include a separatenode_modulesfolder (with only the packages that are required for production).dist/node_modules, node might find it in./node_modulesWhat is the feature you are proposing to solve the problem?
Not sure what the best way is. Here are some thoughts:
package.json: e.g.resolutionRoot: trueThen nested packages could directly use this. And for the dist-use case, the build-process can create a
package.jsonfile in thedistdirectorypackage.jsonWhat alternatives have you considered?
Currently we copy the whole folder and subfolders to the root of the file-system and start the app from there: then the node-resolution will for sure not find additional
node_modulefolders.Cons: