@afterpack/angular
v0.2.2
Published
Angular 17+ integration for AfterPack: obfuscate the browser bundle after ng build
Maintainers
Readme
@afterpack/angular
Obfuscate an Angular 17+ build. @afterpack/angular runs the
AfterPack JavaScript obfuscator over the browser bundle that ng build
writes.
Angular's application builder has no plugin hook, so AfterPack runs as a step after ng build.
The simplest setup: the CLI
You do not need this package for the common case. Add the
afterpack CLI after ng build:
// package.json
{
"scripts": {
"build": "ng build && afterpack dist/my-app/browser --seed=git"
}
}Using this package
Use this package when you prefer a Node script. It finds dist/<app>/browser for you.
npm install --save-dev @afterpack/angular// scripts/obfuscate.mjs, run after ng build
import { afterpackAngular } from "@afterpack/angular";
await afterpackAngular({ seed: "git" });Each JavaScript file is obfuscated in place. If obfuscation fails, the promise rejects.
Options
| Option | What it does | Default |
| --- | --- | --- |
| preset | "minify", "light", "medium", "hard" or "extreme" | "light" |
| seed | a number or string; "git" uses the current commit | a new random seed per build |
| identifiers.reserved | names never to rename | none |
| paths.exclude | globs for files to leave untouched | none |
| cwd | option of this package: the project root | process.cwd() |
| distRoot | option of this package: the Angular output folder | "dist" |
| browserDir | option of this package: the browser bundle folder; set it when there are several apps | found under distRoot |
Dotted names are nested objects: paths.exclude is { paths: { exclude: ["…"] } }. Every other
option is in the configuration reference, except
directives.enabled: the build output is already minified, so
/* @afterpack */ comments are gone by the time AfterPack sees it. Setting it to true fails with
an explanation.
Options can also live in afterpack.json or in AFTERPACK_* environment variables. The options
object wins over the environment, which wins over the file. An unknown or misspelled key fails the
run and names the right spelling.
Limitations
Because AfterPack runs after ng build, the readable bundle sits in dist/ until the step
finishes, and stays there if it fails. Projects on the older webpack-based builder can use
@afterpack/webpack through a custom builder
instead.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same step
builds in AfterPack's cloud instead, which adds two hardening transforms you can turn on:
self-integrity (anti-tamper) and comparison hardening. See AfterPack
Pro.
Links
- Angular setup guide
- Presets and protection levels
- Obfuscate your build in CI
- How AfterPack compares to other obfuscators
- Protecting pricing logic
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
