mirror of
https://github.com/javascript-obfuscator/javascript-obfuscator
synced 2026-08-09 12:42:29 +00:00
Merge pull request #899 from erikdubbelboer/domain-dest
Add domainDest option
This commit is contained in:
@@ -361,6 +361,7 @@ Following options are available for the JS Obfuscator:
|
||||
debugProtectionInterval: false,
|
||||
disableConsoleOutput: false,
|
||||
domainLock: [],
|
||||
domainDest: 'about:blank',
|
||||
forceTransformStrings: [],
|
||||
identifierNamesCache: null,
|
||||
identifierNamesGenerator: 'hexadecimal',
|
||||
@@ -421,6 +422,7 @@ Following options are available for the JS Obfuscator:
|
||||
--debug-protection-interval <boolean>
|
||||
--disable-console-output <boolean>
|
||||
--domain-lock '<list>' (comma separated)
|
||||
--domain-dest 'url' <string>
|
||||
--exclude '<list>' (comma separated)
|
||||
--force-transform-strings '<list>' (comma separated)
|
||||
--identifier-names-cache-path <string>
|
||||
@@ -691,6 +693,13 @@ Allows to run the obfuscated source code only on specific domains and/or sub-dom
|
||||
##### Multiple domains and sub-domains
|
||||
It's possible to lock your code to more than one domain or sub-domain. For instance, to lock it so the code only runs on **www.example.com** add `www.example.com`. To make it work on the root domain including any sub-domains (`example.com`, `sub.example.com`), use `.example.com`.
|
||||
|
||||
### `domainDest`
|
||||
Type: `string` Default: `about:blank`
|
||||
|
||||
##### :warning: This option does not work with `target: 'node'`
|
||||
|
||||
Location to redirect the browser to when domainLock is triggered.
|
||||
|
||||
### `exclude`
|
||||
Type: `string[]` Default: `[]`
|
||||
|
||||
|
||||
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
@@ -236,6 +236,10 @@ export class JavaScriptObfuscatorCLI implements IInitializable {
|
||||
'Allows to run the obfuscated source code only on specific domains and/or sub-domains (comma separated)',
|
||||
ArraySanitizer
|
||||
)
|
||||
.option(
|
||||
'--domain-dest <string>',
|
||||
'Allows the browser to be redirected to this domain if the source code isn\'t run on the domains specified by --domain-lock',
|
||||
)
|
||||
.option(
|
||||
'--exclude <list> (comma separated, without whitespaces)',
|
||||
'A filename or glob which indicates files to exclude from obfuscation',
|
||||
|
||||
@@ -89,10 +89,15 @@ export class DomainLockCodeHelper extends AbstractCustomCodeHelper {
|
||||
*/
|
||||
protected override getCodeHelperTemplate (): string {
|
||||
const domainsString: string = this.options.domainLock.join(';');
|
||||
const [hiddenDomainsString, diff]: string[] = this.cryptUtils.hideString(
|
||||
const domainsDest: string = this.options.domainDest;
|
||||
const [hiddenDomainsString, domainsStringDiff]: string[] = this.cryptUtils.hideString(
|
||||
domainsString,
|
||||
domainsString.length * 3
|
||||
);
|
||||
const [hiddenDomainDest, domainDestDiff]: string[] = this.cryptUtils.hideString(
|
||||
domainsDest,
|
||||
domainsDest.length * 3
|
||||
);
|
||||
const globalVariableTemplate: string = this.options.target !== ObfuscationTarget.BrowserNoEval
|
||||
? this.getGlobalVariableTemplate()
|
||||
: GlobalVariableNoEvalTemplate();
|
||||
@@ -100,8 +105,10 @@ export class DomainLockCodeHelper extends AbstractCustomCodeHelper {
|
||||
return this.customCodeHelperFormatter.formatTemplate(DomainLockTemplate(), {
|
||||
callControllerFunctionName: this.callsControllerFunctionName,
|
||||
domainLockFunctionName: this.domainLockFunctionName,
|
||||
diff,
|
||||
domainsStringDiff,
|
||||
domains: hiddenDomainsString,
|
||||
domainDestDiff,
|
||||
domainDest: hiddenDomainDest,
|
||||
globalVariableTemplate
|
||||
});
|
||||
}
|
||||
|
||||
@@ -7,34 +7,43 @@ export function DomainLockTemplate (): string {
|
||||
|
||||
{globalVariableTemplate}
|
||||
|
||||
const func = function () {
|
||||
return {
|
||||
key: 'item',
|
||||
value: 'attribute',
|
||||
getAttribute: function () {
|
||||
for (let i = 0; i < 1000; i--) {
|
||||
const isPositive = i > 0;
|
||||
|
||||
switch (isPositive) {
|
||||
case true:
|
||||
return this.item + '_' + this.value + '_' + i;
|
||||
default:
|
||||
this.item + '_' + this.value;
|
||||
}
|
||||
}
|
||||
}()
|
||||
};
|
||||
};
|
||||
|
||||
const regExp = new RegExp("[{diff}]", "g");
|
||||
const regExp = new RegExp("[{domainsStringDiff}]", "g");
|
||||
const domains = "{domains}".replace(regExp, "").split(";");
|
||||
let document;
|
||||
let domain;
|
||||
let location;
|
||||
let hostname;
|
||||
|
||||
const isName = function(name, length, cs) {
|
||||
if (name.length != length) {
|
||||
return false;
|
||||
}
|
||||
|
||||
for (let i = 0; i < length; i++) {
|
||||
for (let j = 0; j < cs.length; j += 2) {
|
||||
if (i == cs[j] && name.charCodeAt(i) != cs[j+1]) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
};
|
||||
|
||||
const isNameVariant1 = function(cs, name, length) {
|
||||
return isName(name, length, cs);
|
||||
};
|
||||
|
||||
const isNameVariant2 = function(name, cs, length) {
|
||||
return isNameVariant1(cs, name, length);
|
||||
};
|
||||
|
||||
const isNameVariant3 = function(length, name, cs) {
|
||||
return isNameVariant2(name, cs, length);
|
||||
};
|
||||
|
||||
for (let d in that) {
|
||||
if (d.length == 8 && d.charCodeAt(7) == 116 && d.charCodeAt(5) == 101 && d.charCodeAt(3) == 117 && d.charCodeAt(0) == 100) {
|
||||
if (isName(d, 8, [7, 116, 5, 101, 3, 117, 0, 100])) {
|
||||
document = d;
|
||||
|
||||
break;
|
||||
@@ -42,24 +51,24 @@ export function DomainLockTemplate (): string {
|
||||
}
|
||||
|
||||
for (let d1 in that[document]) {
|
||||
if (d1.length == 6 && d1.charCodeAt(5) == 110 && d1.charCodeAt(0) == 100) {
|
||||
if (isNameVariant3(6, d1, [5, 110, 0, 100])) {
|
||||
domain = d1;
|
||||
|
||||
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
for (let d2 in that[document]) {
|
||||
if (isNameVariant2(d2, [7, 110, 0, 108], 8)) {
|
||||
location = d2;
|
||||
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
if (!("~" > domain)) {
|
||||
for (let d2 in that[document]) {
|
||||
if (d2.length == 8 && d2.charCodeAt(7) == 110 && d2.charCodeAt(0) == 108) {
|
||||
location = d2;
|
||||
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
for (let d3 in that[document][location]) {
|
||||
if (d3.length == 8 && d3.charCodeAt(7) == 101 && d3.charCodeAt(0) == 104) {
|
||||
if (isNameVariant1([7, 101, 0, 104], d3, 8)) {
|
||||
hostname = d3;
|
||||
|
||||
break;
|
||||
@@ -96,14 +105,13 @@ export function DomainLockTemplate (): string {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
if (!ok) {
|
||||
data;
|
||||
} else {
|
||||
return;
|
||||
const regExp2 = new RegExp("[{domainDestDiff}]", "g");
|
||||
const domainDest = "{domainDest}".replace(regExp2, "");
|
||||
|
||||
that[document][location] = domainDest;
|
||||
}
|
||||
|
||||
func();
|
||||
});
|
||||
|
||||
{domainLockFunctionName}();
|
||||
|
||||
@@ -20,6 +20,7 @@ export interface IOptions {
|
||||
readonly debugProtectionInterval: boolean;
|
||||
readonly disableConsoleOutput: boolean;
|
||||
readonly domainLock: string[];
|
||||
readonly domainDest: string;
|
||||
readonly forceTransformStrings: string[];
|
||||
readonly identifierNamesCache: TIdentifierNamesCache;
|
||||
readonly identifierNamesGenerator: TTypeFromEnum<typeof IdentifierNamesGenerator>;
|
||||
|
||||
@@ -134,6 +134,16 @@ export class Options implements IOptions {
|
||||
])
|
||||
public readonly domainLock!: string[];
|
||||
|
||||
/**
|
||||
* @type {string}
|
||||
*/
|
||||
@IsString()
|
||||
@IsAllowedForObfuscationTargets([
|
||||
ObfuscationTarget.Browser,
|
||||
ObfuscationTarget.BrowserNoEval,
|
||||
])
|
||||
public readonly domainDest!: string;
|
||||
|
||||
/**
|
||||
* @type {string[]}
|
||||
*/
|
||||
|
||||
@@ -20,6 +20,7 @@ export const DEFAULT_PRESET: TInputOptions = Object.freeze({
|
||||
debugProtectionInterval: false,
|
||||
disableConsoleOutput: false,
|
||||
domainLock: [],
|
||||
domainDest: 'about:blank',
|
||||
exclude: [],
|
||||
forceTransformStrings: [],
|
||||
identifierNamesCache: null,
|
||||
|
||||
@@ -18,6 +18,7 @@ export const NO_ADDITIONAL_NODES_PRESET: TInputOptions = Object.freeze({
|
||||
debugProtectionInterval: false,
|
||||
disableConsoleOutput: false,
|
||||
domainLock: [],
|
||||
domainDest: 'about:blank',
|
||||
exclude: [],
|
||||
forceTransformStrings: [],
|
||||
identifierNamesGenerator: IdentifierNamesGenerator.HexadecimalIdentifierNamesGenerator,
|
||||
|
||||
+424
-170
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user