Ignore transformation of process.env.* (#1367)

This commit is contained in:
Timofey Kachalov
2026-01-06 23:37:42 +04:00
committed by GitHub
parent 90362a2555
commit c844f97cfc
16 changed files with 134 additions and 12 deletions
+1
View File
@@ -14,3 +14,4 @@ npm-debug.log
/test/benchmark/**/**
*dockerfile
/test*.js
/reproductions
+1
View File
@@ -12,3 +12,4 @@
/test*.js
index.ts
index.cli.ts
/reproductions
+4
View File
@@ -1,5 +1,9 @@
Change Log
v5.2.0
---
* Skip obfuscation of `process.env.*`
v5.1.0
---
* Add `version` parameter to the `apiConfig` to use different versions JavaScript Obfuscator Pro via API
+2 -2
View File
@@ -5,7 +5,7 @@
**JavaScript Obfuscator** is a powerful, enterprise-grade code obfuscation tool for JavaScript and Node.js applications. It transforms readable JavaScript code into a protected, difficult-to-understand format while maintaining full functionality. The project is widely used for protecting intellectual property and preventing reverse engineering.
- **Version**: 5.0.0
- **Author**: Timofey Kachalov (@sanex3339)
- **Author**: Timofei Kachalov (@sanex3339)
- **License**: BSD-2-Clause
- **Repository**: https://github.com/javascript-obfuscator/javascript-obfuscator
- **Homepage**: https://obfuscator.io/
@@ -1429,7 +1429,7 @@ Use [grunt-contrib-obfuscator](https://github.com/javascript-obfuscator/grunt-co
**BSD-2-Clause License**
Copyright (C) 2016-2024 Timofey Kachalov
Copyright (C) 2016-2026 Timofei Kachalov
See `LICENSE.BSD` for full license text.
+1 -1
View File
@@ -34,7 +34,7 @@ This Code of Conduct applies both within project spaces and in public spaces whe
## Enforcement
Instances of abusive, harassing, or otherwise unacceptable behavior may be reported by contacting the project team at sanex3339@yandex.ru. The project team will review and investigate all complaints, and will respond in a way that it deems appropriate to the circumstances. The project team is obligated to maintain confidentiality with regard to the reporter of an incident. Further details of specific enforcement policies may be posted separately.
Instances of abusive, harassing, or otherwise unacceptable behavior may be reported by contacting the project team at support@obfuscator.io. The project team will review and investigate all complaints, and will respond in a way that it deems appropriate to the circumstances. The project team is obligated to maintain confidentiality with regard to the reporter of an incident. Further details of specific enforcement policies may be posted separately.
Project maintainers who do not follow or enforce the Code of Conduct in good faith may face temporary or permanent repercussions as determined by other members of the project's leadership.
+2 -2
View File
@@ -1,7 +1,7 @@
<!--
Title: JavaScript Obfuscator
Description: A powerful obfuscator for JavaScript and Node.js.
Author: Timofey Kachalov
Author: Timofei Kachalov
-->
#### You can support this project by donating:
@@ -2101,7 +2101,7 @@ Become a sponsor and get your logo on our README on Github with a link to your s
## License
[![FOSSA Status](https://app.fossa.io/api/projects/git%2Bgithub.com%2Fjavascript-obfuscator%2Fjavascript-obfuscator.svg?type=large)](https://app.fossa.io/projects/git%2Bgithub.com%2Fjavascript-obfuscator%2Fjavascript-obfuscator?ref=badge_large)
Copyright (C) 2016-2024 [Timofey Kachalov](http://github.com/sanex3339).
Copyright (C) 2016-2026 [Timofei Kachalov](http://github.com/sanex3339).
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met:
+3 -6
View File
@@ -1,6 +1,6 @@
{
"name": "javascript-obfuscator",
"version": "5.1.0",
"version": "5.2.0",
"description": "JavaScript obfuscator",
"keywords": [
"obfuscator",
@@ -129,12 +129,9 @@
"prepare": "husky install"
},
"author": {
"name": "Timofey Kachalov"
"name": "Timofei Kachalov"
},
"contributors": [
"Timofey Kachalov (https://github.com/sanex3339)",
"Dmitry Zamotkin (https://github.com/zamotkin)"
],
"contributors": ["Timofei Kachalov (https://github.com/sanex3339)", "Dmitry Zamotkin (https://github.com/zamotkin)"],
"license": "BSD-2-Clause",
"packageManager": "yarn@1.22.21+sha512.ca75da26c00327d26267ce33536e5790f18ebd53266796fbb664d2a4a5116308042dd8ee7003b276a20eace7d3c5561c3577bdd71bcb67071187af124779620a"
}
@@ -15,6 +15,7 @@ import { EvalCallExpressionTransformer } from '../../../node-transformers/prepar
import { ForceTransformStringObfuscatingGuard } from '../../../node-transformers/preparing-transformers/obfuscating-guards/ForceTransformStringObfuscatingGuard';
import { IgnoredImportObfuscatingGuard } from '../../../node-transformers/preparing-transformers/obfuscating-guards/IgnoredImportObfuscatingGuard';
import { ImportMetaObfuscationGuard } from '../../../node-transformers/preparing-transformers/obfuscating-guards/ImportMetaObfuscationGuard';
import { ProcessEnvObfuscationGuard } from '../../../node-transformers/preparing-transformers/obfuscating-guards/ProcessEnvObfuscationGuard';
import { MetadataTransformer } from '../../../node-transformers/preparing-transformers/MetadataTransformer';
import { ObfuscatingGuardsTransformer } from '../../../node-transformers/preparing-transformers/ObfuscatingGuardsTransformer';
import { ParentificationTransformer } from '../../../node-transformers/preparing-transformers/ParentificationTransformer';
@@ -73,6 +74,11 @@ export const preparingTransformersModule: interfaces.ContainerModule = new Conta
.inSingletonScope()
.whenTargetNamed(ObfuscatingGuard.ImportMetaObfuscationGuard);
bind<IObfuscatingGuard>(ServiceIdentifiers.INodeGuard)
.to(ProcessEnvObfuscationGuard)
.inSingletonScope()
.whenTargetNamed(ObfuscatingGuard.ProcessEnvObfuscationGuard);
bind<IObfuscatingGuard>(ServiceIdentifiers.INodeGuard)
.to(ReservedStringObfuscatingGuard)
.inSingletonScope()
@@ -4,5 +4,6 @@ export enum ObfuscatingGuard {
ForceTransformStringObfuscatingGuard = 'ForceTransformStringObfuscatingGuard',
IgnoredImportObfuscatingGuard = 'IgnoredImportObfuscatingGuard',
ImportMetaObfuscationGuard = 'ImportMetaObfuscationGuard',
ProcessEnvObfuscationGuard = 'ProcessEnvObfuscationGuard',
ReservedStringObfuscatingGuard = 'ReservedStringObfuscatingGuard'
}
@@ -33,6 +33,7 @@ export class ObfuscatingGuardsTransformer extends AbstractNodeTransformer {
ObfuscatingGuard.ForceTransformStringObfuscatingGuard,
ObfuscatingGuard.IgnoredImportObfuscatingGuard,
ObfuscatingGuard.ImportMetaObfuscationGuard,
ObfuscatingGuard.ProcessEnvObfuscationGuard,
ObfuscatingGuard.ReservedStringObfuscatingGuard
];
@@ -0,0 +1,66 @@
import { injectable } from 'inversify';
import * as ESTree from 'estree';
import { IObfuscatingGuard } from '../../../interfaces/node-transformers/preparing-transformers/obfuscating-guards/IObfuscatingGuard';
import { ObfuscatingGuardResult } from '../../../enums/node/ObfuscatingGuardResult';
import { NodeGuards } from '../../../node/NodeGuards';
@injectable()
export class ProcessEnvObfuscationGuard implements IObfuscatingGuard {
/**
* @param {Node} node
* @return {boolean}
* @private
*/
private static isProcessEnvMemberExpression(node: ESTree.Node): boolean {
if (!NodeGuards.isMemberExpressionNode(node)) {
return false;
}
return (
NodeGuards.isIdentifierNode(node.object) &&
node.object.name === 'process' &&
NodeGuards.isIdentifierNode(node.property) &&
node.property.name === 'env' &&
!node.computed
);
}
/**
* @param {Node} node
* @return {boolean}
* @private
*/
private static isPartOfProcessEnvChain(node: ESTree.Node): boolean {
if (ProcessEnvObfuscationGuard.isProcessEnvMemberExpression(node)) {
return true;
}
const parentNode = node.parentNode;
if (parentNode && NodeGuards.isMemberExpressionNode(parentNode)) {
if (ProcessEnvObfuscationGuard.isProcessEnvMemberExpression(parentNode.object)) {
return true;
}
if (ProcessEnvObfuscationGuard.isProcessEnvMemberExpression(parentNode)) {
return true;
}
}
return false;
}
/**
* @param {Node} node
* @returns {ObfuscatingGuardResult}
*/
public check(node: ESTree.Node): ObfuscatingGuardResult {
return ProcessEnvObfuscationGuard.isPartOfProcessEnvChain(node)
? ObfuscatingGuardResult.Ignore
: ObfuscatingGuardResult.Transform;
}
}
@@ -721,6 +721,24 @@ describe('JavaScriptObfuscator', () => {
});
});
describe('process.env.* support', () => {
const regExp: RegExp = /console\['log']\(process\.env\.FOO\);/;
let obfuscatedCode: string;
beforeEach(() => {
const code: string = readFileAsString(__dirname + '/fixtures/process-env.js');
obfuscatedCode = JavaScriptObfuscator.obfuscate(code, {
...NO_ADDITIONAL_NODES_PRESET
}).getObfuscatedCode();
});
it('should not obfuscate `process.env.*`', () => {
assert.match(obfuscatedCode, regExp);
});
});
/**
* https://github.com/javascript-obfuscator/javascript-obfuscator/issues/710
*/
@@ -0,0 +1 @@
console.log(process.env.FOO);
+1 -1
View File
@@ -1,6 +1,6 @@
const fs = require('fs');
const copyright = 'Copyright (C) 2016-2024 Timofey Kachalov <sanex3339@yandex.ru>';
const copyright = 'Copyright (C) 2016-2026 Timofei Kachalov <support@obfuscator.io>';
const sourceMapSupportRequire = 'require("source-map-support").install();';
class WebpackUtils {
+13
View File
@@ -1,6 +1,7 @@
'use strict';
const webpack = require('webpack');
const TerserPlugin = require('terser-webpack-plugin');
const packageJson = require('pjson');
const WebpackUtils = require('./utils/WebpackUtils').WebpackUtils;
@@ -41,6 +42,18 @@ module.exports = {
process: ['process']
})
],
optimization: {
minimizer: [
new TerserPlugin({
extractComments: false,
terserOptions: {
format: {
comments: /^!/ // Keep comments starting with !
}
}
})
]
},
output: {
libraryTarget: 'umd',
library: 'JavaScriptObfuscator',
+13
View File
@@ -4,6 +4,7 @@ const path = require('path');
const nodeExternals = require('webpack-node-externals');
const webpack = require('webpack');
const TerserPlugin = require('terser-webpack-plugin');
const ForkTsCheckerWebpackPlugin = require('fork-ts-checker-webpack-plugin');
const ForkTsCheckerNotifierWebpackPlugin = require('fork-ts-checker-notifier-webpack-plugin');
const ESLintPlugin = require('eslint-webpack-plugin');
@@ -70,6 +71,18 @@ module.exports = {
skipFirstNotification: true
})
],
optimization: {
minimizer: [
new TerserPlugin({
extractComments: false,
terserOptions: {
format: {
comments: /^!/ // Keep comments starting with !
}
}
})
]
},
output: {
libraryTarget: 'commonjs2'
},