Merge pull request #899 from erikdubbelboer/domain-dest

Add domainDest option
This commit is contained in:
Timofey Kachalov
2021-06-10 20:25:21 +03:00
committed by GitHub
12 changed files with 508 additions and 213 deletions
+9
View File
@@ -361,6 +361,7 @@ Following options are available for the JS Obfuscator:
debugProtectionInterval: false,
disableConsoleOutput: false,
domainLock: [],
domainDest: 'about:blank',
forceTransformStrings: [],
identifierNamesCache: null,
identifierNamesGenerator: 'hexadecimal',
@@ -421,6 +422,7 @@ Following options are available for the JS Obfuscator:
--debug-protection-interval <boolean>
--disable-console-output <boolean>
--domain-lock '<list>' (comma separated)
--domain-dest 'url' <string>
--exclude '<list>' (comma separated)
--force-transform-strings '<list>' (comma separated)
--identifier-names-cache-path <string>
@@ -691,6 +693,13 @@ Allows to run the obfuscated source code only on specific domains and/or sub-dom
##### Multiple domains and sub-domains
It's possible to lock your code to more than one domain or sub-domain. For instance, to lock it so the code only runs on **www.example.com** add `www.example.com`. To make it work on the root domain including any sub-domains (`example.com`, `sub.example.com`), use `.example.com`.
### `domainDest`
Type: `string` Default: `about:blank`
##### :warning: This option does not work with `target: 'node'`
Location to redirect the browser to when domainLock is triggered.
### `exclude`
Type: `string[]` Default: `[]`
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+4
View File
@@ -236,6 +236,10 @@ export class JavaScriptObfuscatorCLI implements IInitializable {
'Allows to run the obfuscated source code only on specific domains and/or sub-domains (comma separated)',
ArraySanitizer
)
.option(
'--domain-dest <string>',
'Allows the browser to be redirected to this domain if the source code isn\'t run on the domains specified by --domain-lock',
)
.option(
'--exclude <list> (comma separated, without whitespaces)',
'A filename or glob which indicates files to exclude from obfuscation',
@@ -89,10 +89,15 @@ export class DomainLockCodeHelper extends AbstractCustomCodeHelper {
*/
protected override getCodeHelperTemplate (): string {
const domainsString: string = this.options.domainLock.join(';');
const [hiddenDomainsString, diff]: string[] = this.cryptUtils.hideString(
const domainsDest: string = this.options.domainDest;
const [hiddenDomainsString, domainsStringDiff]: string[] = this.cryptUtils.hideString(
domainsString,
domainsString.length * 3
);
const [hiddenDomainDest, domainDestDiff]: string[] = this.cryptUtils.hideString(
domainsDest,
domainsDest.length * 3
);
const globalVariableTemplate: string = this.options.target !== ObfuscationTarget.BrowserNoEval
? this.getGlobalVariableTemplate()
: GlobalVariableNoEvalTemplate();
@@ -100,8 +105,10 @@ export class DomainLockCodeHelper extends AbstractCustomCodeHelper {
return this.customCodeHelperFormatter.formatTemplate(DomainLockTemplate(), {
callControllerFunctionName: this.callsControllerFunctionName,
domainLockFunctionName: this.domainLockFunctionName,
diff,
domainsStringDiff,
domains: hiddenDomainsString,
domainDestDiff,
domainDest: hiddenDomainDest,
globalVariableTemplate
});
}
@@ -7,34 +7,43 @@ export function DomainLockTemplate (): string {
{globalVariableTemplate}
const func = function () {
return {
key: 'item',
value: 'attribute',
getAttribute: function () {
for (let i = 0; i < 1000; i--) {
const isPositive = i > 0;
switch (isPositive) {
case true:
return this.item + '_' + this.value + '_' + i;
default:
this.item + '_' + this.value;
}
}
}()
};
};
const regExp = new RegExp("[{diff}]", "g");
const regExp = new RegExp("[{domainsStringDiff}]", "g");
const domains = "{domains}".replace(regExp, "").split(";");
let document;
let domain;
let location;
let hostname;
const isName = function(name, length, cs) {
if (name.length != length) {
return false;
}
for (let i = 0; i < length; i++) {
for (let j = 0; j < cs.length; j += 2) {
if (i == cs[j] && name.charCodeAt(i) != cs[j+1]) {
return false;
}
}
}
return true;
};
const isNameVariant1 = function(cs, name, length) {
return isName(name, length, cs);
};
const isNameVariant2 = function(name, cs, length) {
return isNameVariant1(cs, name, length);
};
const isNameVariant3 = function(length, name, cs) {
return isNameVariant2(name, cs, length);
};
for (let d in that) {
if (d.length == 8 && d.charCodeAt(7) == 116 && d.charCodeAt(5) == 101 && d.charCodeAt(3) == 117 && d.charCodeAt(0) == 100) {
if (isName(d, 8, [7, 116, 5, 101, 3, 117, 0, 100])) {
document = d;
break;
@@ -42,24 +51,24 @@ export function DomainLockTemplate (): string {
}
for (let d1 in that[document]) {
if (d1.length == 6 && d1.charCodeAt(5) == 110 && d1.charCodeAt(0) == 100) {
if (isNameVariant3(6, d1, [5, 110, 0, 100])) {
domain = d1;
break;
}
}
for (let d2 in that[document]) {
if (isNameVariant2(d2, [7, 110, 0, 108], 8)) {
location = d2;
break;
}
}
if (!("~" > domain)) {
for (let d2 in that[document]) {
if (d2.length == 8 && d2.charCodeAt(7) == 110 && d2.charCodeAt(0) == 108) {
location = d2;
break;
}
}
for (let d3 in that[document][location]) {
if (d3.length == 8 && d3.charCodeAt(7) == 101 && d3.charCodeAt(0) == 104) {
if (isNameVariant1([7, 101, 0, 104], d3, 8)) {
hostname = d3;
break;
@@ -96,14 +105,13 @@ export function DomainLockTemplate (): string {
}
}
}
if (!ok) {
data;
} else {
return;
const regExp2 = new RegExp("[{domainDestDiff}]", "g");
const domainDest = "{domainDest}".replace(regExp2, "");
that[document][location] = domainDest;
}
func();
});
{domainLockFunctionName}();
+1
View File
@@ -20,6 +20,7 @@ export interface IOptions {
readonly debugProtectionInterval: boolean;
readonly disableConsoleOutput: boolean;
readonly domainLock: string[];
readonly domainDest: string;
readonly forceTransformStrings: string[];
readonly identifierNamesCache: TIdentifierNamesCache;
readonly identifierNamesGenerator: TTypeFromEnum<typeof IdentifierNamesGenerator>;
+10
View File
@@ -134,6 +134,16 @@ export class Options implements IOptions {
])
public readonly domainLock!: string[];
/**
* @type {string}
*/
@IsString()
@IsAllowedForObfuscationTargets([
ObfuscationTarget.Browser,
ObfuscationTarget.BrowserNoEval,
])
public readonly domainDest!: string;
/**
* @type {string[]}
*/
+1
View File
@@ -20,6 +20,7 @@ export const DEFAULT_PRESET: TInputOptions = Object.freeze({
debugProtectionInterval: false,
disableConsoleOutput: false,
domainLock: [],
domainDest: 'about:blank',
exclude: [],
forceTransformStrings: [],
identifierNamesCache: null,
+1
View File
@@ -18,6 +18,7 @@ export const NO_ADDITIONAL_NODES_PRESET: TInputOptions = Object.freeze({
debugProtectionInterval: false,
disableConsoleOutput: false,
domainLock: [],
domainDest: 'about:blank',
exclude: [],
forceTransformStrings: [],
identifierNamesGenerator: IdentifierNamesGenerator.HexadecimalIdentifierNamesGenerator,