@afterpack/astro
v0.2.2
Published
Astro integration for AfterPack: obfuscate the client and server JavaScript of an Astro build
Maintainers
Readme
@afterpack/astro
An Astro integration (Astro 4, 5 and 6) that obfuscates your production JavaScript, using the AfterPack JavaScript obfuscator.
Install
npm install --save-dev @afterpack/astroUsage
// astro.config.mjs
import { defineConfig } from "astro/config";
import afterpack from "@afterpack/astro";
export default defineConfig({
integrations: [afterpack()],
});The default export and the named afterpackAstro export are the same function.
The integration adds AfterPack to Astro's Vite build. It obfuscates the JavaScript Astro ships to
the browser (islands and client scripts) and the server and prerender build of an output: "server"
or hybrid app. Every chunk is obfuscated before it is written, and a failed run fails the build.
Options
integrations: [afterpack({ preset: "medium", seed: "git" })],Options are the same as @afterpack/vite, except
leg and projectRoot, which Astro does not need.
The options you are most likely to set are preset, complexity,
seed, identifiers.reserved for names that must stay as they are,
paths.exclude for files to leave alone, and build.autorun to
turn AfterPack off. Every other option is in the configuration
reference. Options can also live in afterpack.json or in
AFTERPACK_* environment variables. The options object wins over the environment, which wins over
the file.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same
integration builds in AfterPack's cloud instead, which adds per-region
directives and two hardening transforms you can turn
on: self-integrity (anti-tamper) and comparison hardening. Keep the key out of astro.config.mjs.
See AfterPack Pro.
Links
- Astro setup guide
- Presets and protection levels
- How AfterPack compares to other obfuscators
- JavaScript obfuscation best practices
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
