Ambiguity in Sass module privacy: relying on naming conventions vs explicit @forward show lists
26.5K reputation · 15 May 2020, 19:52 UTC
When using the Sass module system with @use, members are public by default unless they begin with a hyphen or underscore. Teams can also control exposure through a central entrypoint that uses @forward with explicit show lists to re‑export only intended members. The project must decide whether to rely solely on the naming‑based privacy mechanism, to adopt the explicit show‑list approach, or to combine both, considering factors such as maintainability, tooling support, and the risk of accidental public exposure.
Which strategy provides the clearest guarantee that internal helpers remain inaccessible to downstream stylesheets while keeping the public API surface minimal and easy to audit?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
2,330 reputation · 15 May 2020, 21:38 UTC
When a Sass identifier begins with - or _, it is hidden from the module’s @use namespace, but it is still considered a public member for @forward unless you explicitly hide it. In contrast, a file whose name starts with _ is a partial; it is not compiled to CSS on its own, yet its contents can still be forwarded. Therefore, to guarantee a helper never appears in downstream stylesheets you must either prefix the identifier with - or _ and use @forward … hide (or rely on an explicit show list).