No shared state between elements, but it’s an interesting idea.
Edit: It runs other languages as well, like Python, C, Ruby.
I've been looking for 'runnable C examples' on my blog.
Do you know if I can integrate this with Hugo easily?
If you’ve got a way to add node packages to your frontend then it is pretty straightforward. If not, using unpkg (https://unpkg.com/) in a script tag should work.
Happy to help you figure it out! Post in the discussion board on GitHub or email me (address on the website).
But maybe using an <iframe> would make it a little more secure...
Example: what approach are you using in your hypothetical to actually get the cell contents into the iframe?
Most of the evolution of web dev can be described as people pushing the boundaries of what browsers were meant to do until standards caught up. I think iframes for running untrusted content is very standard now (https://caniuse.com/iframe-sandbox) with a lot of well supported safe guards built-in like treating the iframe as its own origin.
Obviously defense-in-depth is a good idea and you should be careful when setting up iframes, but if there's a good chance `iframe sandbox` is going to break in later browser releases, there's a lot of stuff you couldn't do anymore. Even with CSP, it would only reduce but not eliminate what an attacker could do.
That's not what I said.
Can you answer the question?: What approach are you using in your hypothetical to actually get the cell contents into the iframe?