Skip to content
FrameworkJavaScript

Dev override seam: threat model and opt-out

A development seam every published entry ships with: how it works, why it's safe, and how to remove it from your bundle.

Last updated Aug 20, 2026Edit this page on GitHub

What it is

Every published entry of @bloklabs/core first consults globalThis.__BLOK_DEV_OVERRIDE__ and falls back to the bundled implementation. This is a development seam for Blok's own tooling: it lets a browser extension inject a local build into a running app.

Why it's safe

It is a passive, in-realm read. blok never fetches, evals, or resolves a URL. The seam never reads localStorage, meta tags, URL parameters, or DOM attributes.

So it grants nothing to an attacker who cannot already execute script in your origin. Payloads that are DOM nodes are rejected, which closes DOM clobbering.

Opt out

To remove the branch from your bundle entirely, alias each entry to its implementation module. Use an exact-match (regex) alias. A plain string key like '@bloklabs/core' also prefix-matches every subpath.

For Vite/Rollup: resolve: { alias: [{ find: /^@bloklabs\/core$/, replacement: '@bloklabs/core/dist/blok-impl.mjs' }] }. Each subpath entry (/tools, /full, …) gets its own pair pointing at its -impl module.