mirror of
https://github.com/javascript-obfuscator/javascript-obfuscator
synced 2026-08-09 12:42:29 +00:00
fixed esprima crash when unicodeEscapeSequence is disabled
This commit is contained in:
Vendored
+8
-4
@@ -801,11 +801,17 @@ var Utils = function () {
|
||||
}, {
|
||||
key: "stringToUnicodeEscapeSequence",
|
||||
value: function stringToUnicodeEscapeSequence(string) {
|
||||
var nonLatinAndNonDigitsOnly = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : false;
|
||||
|
||||
var radix = 16;
|
||||
var regexp = new RegExp('[\x00-\x7F]');
|
||||
var escapeRegExp = new RegExp('[^a-zA-Z0-9]');
|
||||
var prefix = void 0,
|
||||
template = void 0;
|
||||
return "" + string.replace(/[\s\S]/g, function (escape) {
|
||||
if (nonLatinAndNonDigitsOnly && !escapeRegExp.test(escape)) {
|
||||
return escape;
|
||||
}
|
||||
if (regexp.test(escape)) {
|
||||
prefix = '\\x';
|
||||
template = '0'.repeat(2);
|
||||
@@ -5755,7 +5761,7 @@ var StringLiteralReplacer = StringLiteralReplacer_1 = function (_AbstractReplace
|
||||
if (this.options.stringArray && replaceWithStringArrayFlag) {
|
||||
return this.replaceStringLiteralWithStringArrayCall(nodeValue);
|
||||
}
|
||||
return "'" + Utils_1.Utils.stringToUnicodeEscapeSequence(nodeValue) + "'";
|
||||
return "'" + Utils_1.Utils.stringToUnicodeEscapeSequence(nodeValue, !this.options.unicodeEscapeSequence) + "'";
|
||||
}
|
||||
}, {
|
||||
key: "replaceStringLiteralWithStringArrayCall",
|
||||
@@ -5770,9 +5776,7 @@ var StringLiteralReplacer = StringLiteralReplacer_1 = function (_AbstractReplace
|
||||
value = CryptUtils_1.CryptUtils.btoa(value);
|
||||
break;
|
||||
}
|
||||
if (this.options.unicodeEscapeSequence) {
|
||||
value = Utils_1.Utils.stringToUnicodeEscapeSequence(value);
|
||||
}
|
||||
value = Utils_1.Utils.stringToUnicodeEscapeSequence(value, !this.options.unicodeEscapeSequence);
|
||||
var indexOfExistingValue = this.stringArrayStorage.getKeyOf(value);
|
||||
var indexOfValue = void 0;
|
||||
if (indexOfExistingValue >= 0) {
|
||||
|
||||
@@ -65,7 +65,7 @@ export class StringLiteralReplacer extends AbstractReplacer {
|
||||
return this.replaceStringLiteralWithStringArrayCall(nodeValue);
|
||||
}
|
||||
|
||||
return `'${Utils.stringToUnicodeEscapeSequence(nodeValue)}'`;
|
||||
return `'${Utils.stringToUnicodeEscapeSequence(nodeValue, !this.options.unicodeEscapeSequence)}'`;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -88,9 +88,7 @@ export class StringLiteralReplacer extends AbstractReplacer {
|
||||
break;
|
||||
}
|
||||
|
||||
if (this.options.unicodeEscapeSequence) {
|
||||
value = Utils.stringToUnicodeEscapeSequence(value);
|
||||
}
|
||||
value = Utils.stringToUnicodeEscapeSequence(value, !this.options.unicodeEscapeSequence);
|
||||
|
||||
const indexOfExistingValue: number = <number>this.stringArrayStorage.getKeyOf(value);
|
||||
|
||||
|
||||
+7
-1
@@ -124,16 +124,22 @@ export class Utils {
|
||||
|
||||
/**
|
||||
* @param string
|
||||
* @param nonLatinAndNonDigitsOnly
|
||||
* @returns {string}
|
||||
*/
|
||||
public static stringToUnicodeEscapeSequence (string: string): string {
|
||||
public static stringToUnicodeEscapeSequence (string: string, nonLatinAndNonDigitsOnly: boolean = false): string {
|
||||
const radix: number = 16;
|
||||
const regexp: RegExp = new RegExp('[\x00-\x7F]');
|
||||
const escapeRegExp: RegExp = new RegExp('[^a-zA-Z0-9]');
|
||||
|
||||
let prefix: string,
|
||||
template: string;
|
||||
|
||||
return `${string.replace(/[\s\S]/g, (escape: string): string => {
|
||||
if (nonLatinAndNonDigitsOnly && !escapeRegExp.test(escape)) {
|
||||
return escape;
|
||||
}
|
||||
|
||||
if (regexp.test(escape)) {
|
||||
prefix = '\\x';
|
||||
template = '0'.repeat(2);
|
||||
|
||||
+2
-1
@@ -84,7 +84,8 @@ if (!(<any>global)._babelPolyfill) {
|
||||
{
|
||||
compact: false,
|
||||
controlFlowFlattening: true,
|
||||
disableConsoleOutput: false
|
||||
disableConsoleOutput: false,
|
||||
unicodeEscapeSequence: false
|
||||
}
|
||||
).getObfuscatedCode();
|
||||
|
||||
|
||||
+1
@@ -0,0 +1 @@
|
||||
var test = '\nreturn \n//# sourceURL= there can only be \'^\' and \'!\' markers in a subscription marble diagram.';
|
||||
@@ -4,6 +4,8 @@ import { IObfuscationResult } from '../../../../src/interfaces/IObfuscationResul
|
||||
|
||||
import { NO_CUSTOM_NODES_PRESET } from '../../../../src/options/presets/NoCustomNodes';
|
||||
|
||||
import { readFileAsString } from '../../../helpers/readFileAsString';
|
||||
|
||||
import { JavaScriptObfuscator } from '../../../../src/JavaScriptObfuscator';
|
||||
|
||||
describe('LiteralObfuscator', () => {
|
||||
@@ -54,6 +56,33 @@ describe('LiteralObfuscator', () => {
|
||||
assert.match(obfuscationResult.getObfuscatedCode(), /var *test *= *_0x([a-z0-9]){4}\('0x0'\);/);
|
||||
});
|
||||
|
||||
it('should replace literal node value with raw value from unicode array if `unicodeEscapeSequence` and `stringArray` are disabled', () => {
|
||||
let obfuscationResult: IObfuscationResult = JavaScriptObfuscator.obfuscate(
|
||||
`var test = 'test';`,
|
||||
{
|
||||
...NO_CUSTOM_NODES_PRESET,
|
||||
unicodeEscapeSequence: false
|
||||
}
|
||||
);
|
||||
|
||||
assert.match(
|
||||
obfuscationResult.getObfuscatedCode(),
|
||||
/^var *test *= *'test';/
|
||||
);
|
||||
});
|
||||
|
||||
it('should\'t throw an error when string contains non-latin and non-digit characters and `unicodeEscapeSequence` is disabled', () => {
|
||||
assert.doesNotThrow(() => JavaScriptObfuscator.obfuscate(
|
||||
readFileAsString('./test/fixtures/node-transformers/node-obfuscators/literal-obfuscator/literal-obfuscator-unicode-sequence.js'),
|
||||
{
|
||||
...NO_CUSTOM_NODES_PRESET,
|
||||
stringArray: true,
|
||||
stringArrayThreshold: 1,
|
||||
unicodeEscapeSequence: false
|
||||
}
|
||||
));
|
||||
});
|
||||
|
||||
it('shouldn\'t replace short literal node value with unicode array value', () => {
|
||||
let obfuscationResult: IObfuscationResult = JavaScriptObfuscator.obfuscate(
|
||||
`var test = 'te';`,
|
||||
|
||||
@@ -111,11 +111,16 @@ describe('Utils', () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe('stringToUnicodeEscapeSequence (string: string): string', () => {
|
||||
let expected: string = '\\x73\\x74\\x72\\x69\\x6e\\x67';
|
||||
describe('stringToUnicodeEscapeSequence (string: string, nonLatinAndNonDigitsOnly: boolean = false): string', () => {
|
||||
const expected1: string = '\\x73\\x74\\x72\\x69\\x6e\\x67';
|
||||
const expected2: string = 'abc\\x21\\u0434\\u0435';
|
||||
|
||||
it('should return a unicode escape sequence based on a given string', () => {
|
||||
assert.equal(Utils.stringToUnicodeEscapeSequence('string'), expected);
|
||||
assert.equal(Utils.stringToUnicodeEscapeSequence('string'), expected1);
|
||||
});
|
||||
|
||||
it('should return a string where only non-digits and non-latin letters are escaped', () => {
|
||||
assert.equal(Utils.stringToUnicodeEscapeSequence('abc!де', true), expected2);
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user