@afterpack/electron
v0.2.2
Published
Electron integration for AfterPack: obfuscate the main, preload and renderer bundles of an app with one seed
Maintainers
Readme
@afterpack/electron
Electron app source protection for electron-vite and Electron Forge. @afterpack/electron
obfuscates the main, preload and renderer bundles of one app with one shared seed, using the
AfterPack JavaScript obfuscator.
Install
npm install --save-dev @afterpack/electronelectron-vite
Wrap your config once:
// electron.vite.config.ts
import { withAfterpack } from "@afterpack/electron";
import { defineConfig, externalizeDepsPlugin } from "electron-vite";
export default withAfterpack(
defineConfig({
main: { plugins: [externalizeDepsPlugin()] },
preload: { plugins: [externalizeDepsPlugin()] },
renderer: {},
}),
);withAfterpack adds AfterPack to each of main, preload and renderer that your config has, and
prints which ones it wired. Each bundle is obfuscated before Vite writes it. If obfuscation fails,
the build fails.
Electron Forge with Vite
Forge loads each Vite config separately, so add the plugin to each one and name the part it builds:
// vite.main.config.ts (and the same in vite.preload and vite.renderer, with their leg)
import { afterpackElectron } from "@afterpack/electron";
export default { plugins: [afterpackElectron({ leg: "main" })] };leg is required and is one of "main", "preload" or "renderer".
One seed for the whole app
Every part of one build shares one seed, so main, preload and renderer are obfuscated as one program. A new seed is drawn for each build. When your build script runs each part as a separate command, there is no shared process, so pin the seed in the environment:
AFTERPACK_SEED=git npm run buildOther toolchains
| Toolchain | Setup |
| --- | --- |
| electron-vite | withAfterpack(defineConfig({ ... })) |
| Electron Forge + Vite | afterpackElectron({ leg }) in each config |
| Electron Forge + webpack | @afterpack/webpack in each config |
| vite-plugin-electron | afterpackElectron({ leg: "renderer" }), placed last |
| electron-builder | packages, does not bundle; set up the bundler it packages |
| separate build commands | one plugin per part, with AFTERPACK_SEED set |
Keep local files out of app.asar
AfterPack writes its Protection Map to .afterpack/. It contains your original source, so exclude
it from the packaged app. The plugin prints this reminder when it finds a packager config:
// electron-builder
"files": ["**/*", "!.afterpack/**", "!**/*.backup.*", "!**/*.map"]
// Electron Forge
packagerConfig: { ignore: [/^\/\.afterpack/, /\.backup\./, /\.map$/] }Options
withAfterpack(config, { preset: "hard", seed: "git" });| Option | What it does | Default |
| --- | --- | --- |
| preset | "minify", "light", "medium", "hard" or "extreme" | "light" |
| seed | a number or string; "git" uses the current commit | a new random seed per build, shared by every part |
| identifiers.reserved | names never to rename | none |
| protectionMap.enabled | write the Protection Map, one per part in .afterpack/<leg>/ | on when Vite emits source maps |
| build.autorun | false turns AfterPack off | true |
| leg | plugin option: "main", "preload" or "renderer"; required for afterpackElectron | set by withAfterpack |
| projectRoot | plugin option: the app root that ties the parts into one build | process.cwd() |
Every other @afterpack/vite option works too, and
every other option is in the configuration reference.
Options can also live in afterpack.json or in AFTERPACK_* environment variables.
What the plugin refuses
- electron-vite's
bytecodePluginon the same part, or.jscfiles in the output: the build fails. Bytecode replaces the bundle AfterPack would protect, so the two cannot be combined. build.backupset totrue: the build fails, because the backup would hold your original source insideapp.asar.- Source maps turned on: a warning, since a map inside
app.asargives your source away.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same plugin
builds in AfterPack's cloud instead, which adds per-region
directives and two hardening transforms you can turn
on: self-integrity (anti-tamper) and comparison hardening. Keep the key out of your Vite config. See
AfterPack Pro.
Links
- Electron setup guide
- Protect an Electron app's license check
- Presets and protection levels
- How AfterPack compares to other obfuscators
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
