im struggling to figure out best practices for RCE (remote code execution) currently i containerize client provided code as string for a lambda functuon. how do ya'll do it?
OP's solution isn't remote code execution though. It's all in-browser, which is why it's pretty cool. Assuming you're only running code that the client themselves are providing, you're in pretty good shape from a security perspective.