But you can't apply any of that to one particular library that a program uses, while not restricting the rest of the program.
foo = require("excitingModule", {fs: true, net: true, os: true});
It wouldn't be that hard to implement either.And if you think creating an interpreter in the interpreter is the solution, I'm quite sure the thing will not be secure if it is a natural child of the JS ecosystem.
deno --allow-net https://deno.land/std/examples/echo_server.ts
This would be the same as running something with an unprivileged user: sudo -u otheruser node echo_server.js
Deno however takes it to a whole new level by running server code directly from the web =) deno --allow-net=0.0.0.0:8000 https://deno.land/std/examples/echo_server.ts
Or even provide a list of addresses: deno --allow-net=0.0.0.0:8000,localhost https://deno.land/std/examples/echo_server.ts ip netns exec networkname node script.js
Still only on the entire app though, the idea was how to restrict single modules and their dependencies, not your whole app! Something like: const foo = requires("bar", {fs: true, net: "0.0.0.0:8000", os: true});