The Road to JSON Import Support in Node.js

Rate this content
Bookmark

JSON modules have been an important feature of the JavaScript ecosystem for a long time, and it’s started to take a new shape with there new ESM import syntax. Let’s review the history of JSON support in Node.js, its relationship with web compatibility, and how we can make (finally) it happen.

This talk has been presented at Node Congress 2022, check out the latest edition of this JavaScript Conference.

FAQ

Anton Duhamel is a member of the NodeJS Technical Steering Committee since April 2021.

JSON modules in NodeJS are a handy way for a JavaScript author to interact with JSON files, which can be used for configurations or to consume APIs.

JSON module support in NodeJS started with CommonJS, which had early support for JSON. Later, the ECMAScript modules (ESM) specification added import and export keywords, allowing NodeJS and other environments like browsers and Deno to interact with JSON files securely.

Security concerns arose when browsers implemented JSON module support, as malicious servers could potentially return harmful JavaScript instead of JSON, leading to security risks. This led to the proposal of import assertions to ensure only JSON data is processed.

As of the talk, JSON modules and import assertions are available in NodeJS v17, TypeScript 4.5, Deno 1.17, and Chromium browsers. They are still pending implementation in Firefox and Safari.

Developers can use JSON modules by importing them with an assertion at the end to ensure security. They must use the default import syntax as JSON files can be diverse in their structure, not limited to objects.

Anton suggested the possibility of expanding NodeJS module support beyond JSON, including potential support for Tomo modules, TypeScript, and even CoffeeScript, depending on community interest and contributions.

The restriction is due to performance reasons, as dynamically verifying parts of JSON during import could be computationally expensive and inefficient, especially when modules are fetched over a network.

Antoine du Hamel
Antoine du Hamel
16 min
18 Feb, 2022

Comments

Sign in or register to post your comment.

Video Summary and Transcription

This Talk discusses the road to JSON import support in NodeJS, covering the history and implementation of JSON modules. It explores security concerns and the proposal for import assertions. The Talk also explains how to use JSON modules in NetJS and the availability of support in different browsers. It mentions working with dynamic imports and future plans for adding more modules in Node Core. Additionally, it addresses the syntax differences between ESM and CommonJS and the challenges of overcoming them.

1. Introduction to JSON Modules

Short description:

Hello, everyone. My name is Anton Duhamel or aduh95 on GitHub. I'm here to tell you about the road to JSON import support in NodeJS. I'm gonna talk a bit about me, so I'm NodeJS Technical Steering Committee member since April, 2021. And I'm also working at Translordit, so that's my day job. My talk is about JSON modules, so what are they? It's just a handy way for a JavaScript author to interact with JSON files. The history of JSON modules goes back to the beginning of NodeJS. First, when Node.js was introduced, there was no module system, no standard module system in the JavaScript ecosystem. Node.js came up with the CommonJS, which is also called CGS, and they had support for JSON quite early. The next step is the ESM specification or the ECMAScript modules. That was part of the ES6 or ES2015 spec. It allows JavaScript code to interact with other JavaScript files. Currently supported by Node.js, browsers, Deno, TypeScript, most of the ecosystem. On Node.js side, the first implementation landed in version 8.5.0. It was a very experimental stage at this point and mimicked most of the common JS mechanisms. One of its features was to be able to import JSON files as well. There has been discussion to add the JSON module support in browsers. That was merged in 2019.

Hello, everyone. My name is Anton Duhamel or aduh95 on GitHub. I'm here to tell you about the road to JSON import support in NodeJS.

So first, I'm gonna talk a bit about me, so I'm NodeJS Technical Steering Committee member since April, 2021. And I'm also working at Translordit, so that's my day job. And they also pay me to tell you that if you want your work on NodeJS, your contribution on NodeJS core to be sponsored by them, just send an email. It's a good time.

Anyway, so my talk is about JSON modules, so what are they? So it's just a handy way for a JavaScript author to interact with JSON files. So that could be for configuration or to consume an API. And I'm gonna go through the history of JSON modules in the JavaScript ecosystem, and then I will see how we can use them today and what's the next steps.

So the history of JSON modules goes back to the beginning of NodeJS. So first, when Node.js was introduced, there was no module system, no standard module system in the JavaScript ecosystem. Mostly you were using flow boards. And so something has to be made up for this. So Node.js came up with the CommonJS, which is also called CGS, and they had support for JSON quite early. So on this screenshot, we can see it was in 2011. So you can say it was forever ago in the JavaScript world. And the one obvious drawback of CommonJS or CGS, it's not supported in browsers. So the next step is the ESM specification or the ECMAScript modules. So that was part of the ES6 or ES2015 spec. So it was, the ES6 spec is a big spec jump where we went from all JavaScript and more modern JavaScript. And one of its addition was the import and export keywords and the module mechanism that would allow JavaScript code to interact with other JavaScript files. And that is currently supported by Node.js, browsers, Deno, TypeScript, most of the ecosystem. And one notable thing I should add on that, it's browsers in particular enforce that only JavaScript files can be loaded through to this mechanism. And that's gonna be important just later. So on Node.js side, the first implementation landed in version 8.5.0. It was a very experimental stage at this point and mimicked most of the common JS mechanisms. So one of its feature was to be able to import JSON files as well. So when that landed, there has been discussion to add the JSON module support in browsers. So, and that was actually merged in 2019.

2. Security Concerns and Import Assertions

Short description:

The idea of loading modules fetched through HTTP was reverted due to security concerns. A proposal was raised to add an assert with type JSON to the import syntax, ensuring that only JSON data is loaded. The JavaScript language is governed by the ECMAScript spec, written by the TC39 committee. The JSON modules and import assertions proposal is currently in stage three and ready to be implemented.

So the idea was if, so on a browser, it's modules fetched through HTTP. So if the HTTP response contains a MIME type for a JSON file, it's gonna be loaded as a, and parsed as a JSON file. If it's JavaScript, it's gonna be parsed and loaded as JavaScript. But that was actually reverted a few months later because of security concerns raised by some of the implementers. So maybe we can go through the security in the details of this revert.

So let's say you are consuming a weather API and you expect to get a JSON object with a different value inside. So you import it as a module because you can. And what if instead of returning a JSON file, the server, either because it's compromised or because it's malicious, returns a JavaScript file that does something nasty. So in this example, I'm adding a fetch call that would send all the local storage data to another server. But the thing is it could be anything, it's undefined behavior at this point. And browser vendors decided it was not acceptable.

So to work around this, a proposal was raised to instead change to JavaScript language to add another addition to the server to the import syntax, which could ensure that this doesn't happen. So you can see here at the end of this import statement, there's an assert with type JSON, so that would mean for the JavaScript engine that if the response is not JSON data, JSON data, the import statement fails and the code is not executed. So if you're not familiar with what's, how to change the JavaScript language, it would be interesting to talk a bit about that. So the JavaScript language is governed by the ECMAScript spec and that spec is written by the TC39 committee. So that's a lot of acronyms, but bear with me. So the TC39 has a list of proposals that is publicly available that you can see. And each proposal goes through four different stage and the JSON module line posts, you go out and screenshot of that. So as you can see, the JSON modules and import assertions proposal are up there in the stage three packet. So that means it's mostly done. It's ready to be implemented. And they are waiting for feedback before deciding if it will go in stage four, which is the proposal is integrated to the official spec. I wanted to also to give a shout out to the template proposal. If you're not familiar. I'm pretty pumped about this one. So as you can see here on this screenshot, it's an API to replace the data API to work with time and date in JavaScript, which is supposed to be better than the current data API. Anyway, just wanted to mention that. So back to just modules. So now that the ECMAScript spec has a mechanism to ensure that there won't be a security problems when loading JSON modules.

QnA

Check out more articles and videos

We constantly think of articles and videos that might spark Git people interest / skill us up or help building a stellar career

It's a Jungle Out There: What's Really Going on Inside Your Node_Modules Folder
Node Congress 2022Node Congress 2022
26 min
It's a Jungle Out There: What's Really Going on Inside Your Node_Modules Folder
Top Content
The talk discusses the importance of supply chain security in the open source ecosystem, highlighting the risks of relying on open source code without proper code review. It explores the trend of supply chain attacks and the need for a new approach to detect and block malicious dependencies. The talk also introduces Socket, a tool that assesses the security of packages and provides automation and analysis to protect against malware and supply chain attacks. It emphasizes the need to prioritize security in software development and offers insights into potential solutions such as realms and Deno's command line flags.
Towards a Standard Library for JavaScript Runtimes
Node Congress 2022Node Congress 2022
34 min
Towards a Standard Library for JavaScript Runtimes
Top Content
There is a need for a standard library of APIs for JavaScript runtimes, as there are currently multiple ways to perform fundamental tasks like base64 encoding. JavaScript runtimes have historically lacked a standard library, causing friction and difficulty for developers. The idea of a small core has both benefits and drawbacks, with some runtimes abusing it to limit innovation. There is a misalignment between Node and web browsers in terms of functionality and API standards. The proposal is to involve browser developers in conversations about API standardization and to create a common standard library for JavaScript runtimes.
ESM Loaders: Enhancing Module Loading in Node.js
JSNation 2023JSNation 2023
22 min
ESM Loaders: Enhancing Module Loading in Node.js
ESM Loaders enhance module loading in Node.js by resolving URLs and reading files from the disk. Module loaders can override modules and change how they are found. Enhancing the loading phase involves loading directly from HTTP and loading TypeScript code without building it. The loader in the module URL handles URL resolution and uses fetch to fetch the source code. Loaders can be chained together to load from different sources, transform source code, and resolve URLs differently. The future of module loading enhancements is promising and simple to use.
Out of the Box Node.js Diagnostics
Node Congress 2022Node Congress 2022
34 min
Out of the Box Node.js Diagnostics
This talk covers various techniques for getting diagnostics information out of Node.js, including debugging with environment variables, handling warnings and deprecations, tracing uncaught exceptions and process exit, using the v8 inspector and dev tools, and generating diagnostic reports. The speaker also mentions areas for improvement in Node.js diagnostics and provides resources for learning and contributing. Additionally, the responsibilities of the Technical Steering Committee in the TS community are discussed.
Node.js Compatibility in Deno
Node Congress 2022Node Congress 2022
34 min
Node.js Compatibility in Deno
Deno aims to provide Node.js compatibility to make migration smoother and easier. While Deno can run apps and libraries offered for Node.js, not all are supported yet. There are trade-offs to consider, such as incompatible APIs and a less ideal developer experience. Deno is working on improving compatibility and the transition process. Efforts include porting Node.js modules, exploring a superset approach, and transparent package installation from npm.
Multithreaded Logging with Pino
JSNation Live 2021JSNation Live 2021
19 min
Multithreaded Logging with Pino
Top Content
Today's Talk is about logging with Pino, one of the fastest loggers for Node.js. Pino's speed and performance are achieved by avoiding expensive logging and optimizing event loop processing. It offers advanced features like async mode and distributed logging. The use of Worker Threads and Threadstream allows for efficient data processing. Pino.Transport enables log processing in a worker thread with various options for log destinations. The Talk concludes with a demonstration of logging output and an invitation to reach out for job opportunities.

Workshops on related topic

Node.js Masterclass
Node Congress 2023Node Congress 2023
109 min
Node.js Masterclass
Top Content
Workshop
Matteo Collina
Matteo Collina
Have you ever struggled with designing and structuring your Node.js applications? Building applications that are well organised, testable and extendable is not always easy. It can often turn out to be a lot more complicated than you expect it to be. In this live event Matteo will show you how he builds Node.js applications from scratch. You’ll learn how he approaches application design, and the philosophies that he applies to create modular, maintainable and effective applications.

Level: intermediate
Build and Deploy a Backend With Fastify & Platformatic
JSNation 2023JSNation 2023
104 min
Build and Deploy a Backend With Fastify & Platformatic
WorkshopFree
Matteo Collina
Matteo Collina
Platformatic allows you to rapidly develop GraphQL and REST APIs with minimal effort. The best part is that it also allows you to unleash the full potential of Node.js and Fastify whenever you need to. You can fully customise a Platformatic application by writing your own additional features and plugins. In the workshop, we’ll cover both our Open Source modules and our Cloud offering:- Platformatic OSS (open-source software) — Tools and libraries for rapidly building robust applications with Node.js (https://oss.platformatic.dev/).- Platformatic Cloud (currently in beta) — Our hosting platform that includes features such as preview apps, built-in metrics and integration with your Git flow (https://platformatic.dev/). 
In this workshop you'll learn how to develop APIs with Fastify and deploy them to the Platformatic Cloud.
Building a Hyper Fast Web Server with Deno
JSNation Live 2021JSNation Live 2021
156 min
Building a Hyper Fast Web Server with Deno
WorkshopFree
Matt Landers
Will Johnston
2 authors
Deno 1.9 introduced a new web server API that takes advantage of Hyper, a fast and correct HTTP implementation for Rust. Using this API instead of the std/http implementation increases performance and provides support for HTTP2. In this workshop, learn how to create a web server utilizing Hyper under the hood and boost the performance for your web apps.
0 to Auth in an Hour Using NodeJS SDK
Node Congress 2023Node Congress 2023
63 min
0 to Auth in an Hour Using NodeJS SDK
WorkshopFree
Asaf Shen
Asaf Shen
Passwordless authentication may seem complex, but it is simple to add it to any app using the right tool.
We will enhance a full-stack JS application (Node.JS backend + React frontend) to authenticate users with OAuth (social login) and One Time Passwords (email), including:- User authentication - Managing user interactions, returning session / refresh JWTs- Session management and validation - Storing the session for subsequent client requests, validating / refreshing sessions
At the end of the workshop, we will also touch on another approach to code authentication using frontend Descope Flows (drag-and-drop workflows), while keeping only session validation in the backend. With this, we will also show how easy it is to enable biometrics and other passwordless authentication methods.
Table of contents- A quick intro to core authentication concepts- Coding- Why passwordless matters
Prerequisites- IDE for your choice- Node 18 or higher
GraphQL - From Zero to Hero in 3 hours
React Summit 2022React Summit 2022
164 min
GraphQL - From Zero to Hero in 3 hours
Workshop
Pawel Sawicki
Pawel Sawicki
How to build a fullstack GraphQL application (Postgres + NestJs + React) in the shortest time possible.
All beginnings are hard. Even harder than choosing the technology is often developing a suitable architecture. Especially when it comes to GraphQL.
In this workshop, you will get a variety of best practices that you would normally have to work through over a number of projects - all in just three hours.
If you've always wanted to participate in a hackathon to get something up and running in the shortest amount of time - then take an active part in this workshop, and participate in the thought processes of the trainer.
Mastering Node.js Test Runner
TestJS Summit 2023TestJS Summit 2023
78 min
Mastering Node.js Test Runner
Workshop
Marco Ippolito
Marco Ippolito
Node.js test runner is modern, fast, and doesn't require additional libraries, but understanding and using it well can be tricky. You will learn how to use Node.js test runner to its full potential. We'll show you how it compares to other tools, how to set it up, and how to run your tests effectively. During the workshop, we'll do exercises to help you get comfortable with filtering, using native assertions, running tests in parallel, using CLI, and more. We'll also talk about working with TypeScript, making custom reports, and code coverage.