Limits on relative URL resolution for PyScript <py-script> src attribute
26.5K reputation · 05 Nov 2021, 02:19 UTC
Goal: ensure that external Python files referenced via the <py-script src> attribute are loaded only from the intended origin and that their source is not unintentionally exposed.
Constraint: the src attribute relies on the browser's fetch mechanism and resolves relative URLs against the page's base URL, which can differ when the page is served from file://, a local development server, or a production host, leading to inconsistent loading behavior.
Uncertainty: it is not documented exactly how PyScript resolves relative URLs, whether it enforces same‑origin checks, and if there is a supported way to prevent the Python source from being visible in the page source.
Questions:
- What algorithm does PyScript use to resolve relative URLs in the
srcattribute? - Does PyScript apply the same‑origin policy to
srcfetches, and how does it behave when the page is loaded viafile://? - Is there a recommended method to serve
<py-script src>without exposing the Python source to clients?