PyScript Python ↔ JavaScript bridge: default global reachability of imported modules
0 reputation · 28 Aug 2022, 00:35 UTC
0 reputation · 28 Aug 2022, 00:35 UTC
PyScript runs Python in the browser via Pyodide and provides a JavaScript entry point that allows page scripts to invoke the Python runtime. Modules declared for a element are imported into the Pyodide runtime and become reachable from JavaScript through the shared global object.
The documented interoperability includes bidirectional calling via pyscript.run / pyodide.runPython and the Python js module, but there is no documented allowlist or deny-list for which Python names are exposed to JavaScript. Attributes such as data-pyscript support package declaration and code placement, yet the documented behavior does not specify a mechanism to hide imported modules or user-defined functions from the global JavaScript namespace.
With an actively developed exposure model, the design intent for scoping remains unclear. Is there a documented configuration to prevent imported Python modules or user-defined functions from being reachable via pyodide.runPython from page JavaScript? Does PyScript provide a supported way to isolate code so internal names are not exposed to the global JavaScript namespace? What is the intended default visibility model for Python objects across the Python ↔ JavaScript boundary?
28775 reputation · 28 Aug 2022, 09:49 UTC
By default, Python modules imported within a PyScript environment are not automatically exposed to the JavaScript global window object. They remain scoped to the Pyodide runtime instance. While JavaScript can invoke the Python interpreter to execute code, it cannot directly reference a Python module as a native JavaScript object unless that module has been explicitly proxied or assigned to the global namespace.
The intended visibility model is one of isolation by default. PyScript acts as a wrapper around Pyodide, which maintains a distinct memory boundary between the WebAssembly-based Python environment and the browser's JavaScript engine. This ensures that internal Python names, imported libraries, and user-defined functions do not pollute the JavaScript global namespace.
Because isolation is the default state, you do not need a configuration to "hide" internal names. However, if you need to control exactly what is reachable, follow these patterns:
<py-script> or .py files. They will be accessible to other Python code in the same runtime but invisible to window.my_function().import js
def my_exposed_function():
return "Hello from Python!"
js.window.my_exposed_function = my_exposed_function
pyodide.globals.get("variable_name") from JavaScript to retrieve a specific object from the Python global scope without attaching it to window.To verify the current scoping behavior in your environment, you can run the following test:
import math) inside your PyScript tag.window.math. It should return undefined.pyodide.globals.get("math"). This should return the Python module proxy, confirming the module is present in the runtime but isolated from the JS global scope.Note: This behavior assumes a standard PyScript/Pyodide implementation. If you are using a custom Pyodide build or a specific legacy version of PyScript, please specify the version number, as proxying behavior has evolved.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.