Corpus, attribution, and sandbox runs
Course Lab is a browser-only JavaScript exercise desk. Instructors lock an allowed snippet corpus; students write connecting code, run it locally, and declare what they used. It is educational infrastructure — not an autograder, not a plagiarism judge, and not open-web Copilot.
Last updated 19 August 2026
1. In-bounds repositories
A course-aware coding workflow starts with a bounded source pool: starter repos, lecture examples, and explicitly permitted libraries. Everything outside that pool is out of bounds unless an instructor widens it.
The production spec ingests Git repositories, parses symbols with Tree-sitter, and retrieves only from that index. Course Lab is the public, zero-backend slice of that idea: the instructor pastes allowed JS snippets, sets each license, and locks the corpus. Students cannot pull from the open web inside this page — there is no retrieval API and no model.
What “in-bounds” means here
- Only snippets the instructor added and locked are insertable.
- Insert copies code with a
// from: Name (License)attribution comment. - Student-written glue code stays theirs; the lab does not auto-complete it.
2. Attribution vs ghostwriting
Academic integrity for code is not only “did it compile?” but where did it come from and what license applies. Ghostwriting is handing in work whose substantive blocks were produced without declared sources. Permitted reuse — with attribution — is different.
A full course-aware code assistant (2025-era design) generates functions and
classes grounded to in-bounds symbols, with inline citations and a project LICENSE file.
Course Lab deliberately does not generate code. It helps students:
- insert locked snippets with visible attribution comments;
- check an attribution map (which corpus items they used);
- get warned when editor text matches a snippet but the checkbox is unchecked;
- get warned when GPL-3.0 material is mixed into an MIT or Apache-2.0 project.
The export pack bundles LICENSE notes, ATTRIBUTION.md, and main.js
so submission hygiene is explicit. That is provenance hygiene, not a verdict on originality.
3. Sandbox run vs generate-only
The 2025 assistant spec emphasised grounded generation and export. Students on this
public tool originally needed help running code while staying inside the corpus —
seeing console.log output without shipping work to a server.
| Capability | Full course-aware assistant | Course Lab (public) |
|---|---|---|
| Corpus | Git ingest, AST symbols, vector search | Instructor-locked JS snippets in-browser |
| Code production | LLM generates attributed blocks | Student writes; optional snippet insert |
| Execution | Not in MVP spec (won’t-have: test grading) | Sandboxed iframe, 2s timeout, console.log via postMessage |
| Backend | API, Postgres, embeddings | None — localStorage opt-in only |
Runs use sandbox="allow-scripts" without allow-same-origin. Student code
never executes via eval in the parent page, and output is written with
textContent — not innerHTML — so console lines cannot inject markup
into the tool chrome.
// Parent captures logs from an isolated iframe bootstrap — not eval() on the host page.
parent.postMessage({ type: "cl-run", kind: "log", payload: ["clamped:", 10] }, "*");
4. Not test execution as grading
The spec’s won’t-have list includes automated grading, proctoring, and test execution as grading. Course Lab honours that boundary:
- no hidden instructor test suite;
- no pass/fail score or rank;
- no “correct answer” oracle beyond what the student’s own
console.logshows; - attribution warnings are compliance hints, not academic misconduct findings.
Instructors who need graded autograding should use their LMS or CI — not this page.
5. How to use
- Add snippets (name, license, JS body) and lock the corpus.
- Set the project license (MIT, Apache-2.0, or GPL-3.0).
- Write code; insert snippets where appropriate.
- Run (⌘/Ctrl+Enter) and read sandbox console output.
- Check every snippet you used in the attribution map; fix warnings.
- Export the pack for submission or portfolio.
6. What this tool will not do
- No LLM code generation or open-web Copilot behaviour.
- No automated grading, rubrics, or hidden tests.
- No server upload of source — optional save is localStorage on this device.
- No claim to detect plagiarism; only surface missing attribution declarations and license clashes.
7. Questions
Does Course Lab generate code for students?
No. Students write JavaScript. Instructors lock allowed snippets; students may insert them with attribution comments. There is no model and no web retrieval.
Is Course Lab an autograder?
No. It runs code in a local sandbox for learning and checks attribution declarations. It does not run instructor tests or assign scores.
How is this different from a course-aware code assistant?
A full assistant retrieves in-bounds symbols and generates attributed blocks server-side. Course Lab is the public browser lab: lock corpus, student writes, sandbox run, export attribution pack.
Does code leave the browser?
No. Optional save uses this device only. Runs stay inside a sandboxed iframe.
Why warn about GPL in an MIT project?
Copyleft licenses can require compatible licensing for derivative work. Mixing GPL-3.0 snippets into an MIT submission is a common mistake; the lab flags it early.
Open Course Lab
Lock snippets, write JS, run in the sandbox, and export attributions in Course Lab. Local, private, educational — not an autograder.