Show HN: Sandbox.js - Run user code in a sandboxed environment
engineering.versal.com
engineering.versal.com
However, the problem with user-generated JavaScript is not security, it's termination. To my knowledge, there is no 100% safe way to prevent a user script from locking up the thread/tab/process without completely restructuring it. Looking at you, Google Caja. Iframe solutions will reduce the attack vectors to your page, but they will not keep it from locking up. So if you have user-generated content that is displayed on your main page/feed, make sure you don't allow JavaScript until there is a 99.5% sure way to determine script lockup pre-execution.
Calling this Sandbox.js is pretty irresponsible. The term is well defined and well understood. You can't just use the name because it sounds nice.