FWIW, most of the untrusted code execution "platforms" these days use Docker with some hardening (dropped capabilities, syscall filtering, readonly fs etc).
Eg. Repl.it and Rust Playground.
I'm using Auth0 for the user login, and it relies on 3rd party cookies. Safari and Brave block these by default, if you enable them it should let you log in.
Thanks but Pop_OS also doesn't help here.
They did something different for the T490. My colleague has a T480 and that works fine. T490 also doesn't have a BIOS/UEFI option to disable the NVidia (again there's forum threads requesting that as well on the Lenovo forums).
The problem is that the NVidia card never enters its high power saving states even when it's disabled.