Configuring per‑module network access in PyScript without production credentials
0 reputation · 15 May 2021, 15:05 UTC
0 reputation · 15 May 2021, 15:05 UTC
Goal: Verify whether a network (or proposed allow‑network) attribute on a <py-script> tag grants network access only to that specific script element or to all PyScript code on the page when testing third‑party API calls without production credentials.
Uncertainty: The current documentation does not state if the permission is scoped per‑module or applied globally, and the silent failure mode omits console warnings, making it difficult to observe the boundary.
Questions: Does adding the network attribute to one <py-script> element affect other <py-script> tags on the same page? Is the permission applied globally across the PyScript runtime or scoped to the element that declares it? If the permission is global, what mechanism can isolate network access for individual scripts during integration testing?
The network (or allow-network) attribute on a <py-script> tag is evaluated on a per‑element basis. Adding the attribute to one script element does not automatically enable network access for other <py-script> tags on the same page, unless a global configuration is in place.
<py-script network="true"> enables network requests only for the code inside that specific tag.<py-config network="true"> statement lifts the restriction for every script on the page. An individual <py-script> can still opt out by setting network="false".<py-script> tags:
<py-script network="true">
import js
await js.fetch('https://httpbin.org/get')
</py-script>
<py-script>
import js
await js.fetch('https://httpbin.org/get')
</py-script>
<py-config network="true"> and a second script set to network="false" to confirm that the override works.To test third‑party API calls without exposing production credentials, keep your test logic inside a dedicated <py-script network="true"> block and ensure all other scripts either omit the attribute or explicitly set network="false". Avoid using a global <py-config network="true"> unless you intend all scripts to have network access.
Does your page load any external PyScript plugins or perform dynamic imports that could create additional <py-script> elements at runtime? If so, those elements might inherit a global network setting and could unintentionally bypass the per‑element restriction.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.