@afterpack/parcel-optimizer
v0.2.1
Published
Parcel 2 optimizer for AfterPack: obfuscate each JavaScript bundle in memory during parcel build
Maintainers
Readme
@afterpack/parcel-optimizer
A Parcel 2 optimizer (Parcel 2.9 and later) that obfuscates each JavaScript bundle in memory, using the AfterPack JavaScript obfuscator. Parcel writes only the obfuscated result.
Install
npm install --save-dev @afterpack/parcel-optimizerThe name is @afterpack/parcel-optimizer because Parcel requires optimizer packages to be named
that way.
Usage
// .parcelrc
{
"extends": "@parcel/config-default",
"optimizers": {
"*.{js,mjs,cjs}": ["...", "@afterpack/parcel-optimizer"]
}
}Keep the "...": it runs Parcel's own minifier first and AfterPack last. If obfuscation fails, the
build fails.
Check a deploy
Add the plugin's reporter to the build command, and each build writes .afterpack-protection.json
into the target's output directory, a receipt with a hash per obfuscated bundle:
parcel build index.html --reporter @afterpack/parcel-optimizer/reporter
npx afterpack verify dist # in the deploy step, before the uploadafterpack verify fails if a file changed after it was obfuscated, or if there is no receipt. The
reporter writes none when a bundle it shipped was not obfuscated in that build: the optimizer is
missing from .parcelrc, build.autorun is off, or Parcel reused the bundle from .parcel-cache.
Parcel's naming rule for plugins in .parcelrc leaves no place there for a reporter in this
package, so it goes on the command line. The optimizer leaves the reporter one small record per
bundle in .afterpack/parcel/. The reporter clears them as each build starts; without it they stay
there, ignored by git.
Configuration
.parcelrc cannot pass options, so put them in afterpack.json at your project root, or in
AFTERPACK_* environment variables, which win over the file:
{
"preset": "medium",
"seed": "git"
}| Key | What it does | Default |
| --- | --- | --- |
| preset | "minify", "light", "medium", "hard" or "extreme" | "light" |
| seed | a number or string; "git" uses the current commit | a new random seed per build |
| identifiers.reserved | names never to rename | none |
| paths.exclude | globs for files to leave untouched | none |
| sourceMap.enabled | write source maps for the obfuscated output | on in development when an input map exists, off in production |
| protectionMap.enabled | write the Protection Map | on when the bundle has a source map |
| build.autorun | false turns AfterPack off | true |
Every other option is in the configuration reference. An unknown or misspelled key fails the build and names the right spelling.
The plugin writes one Protection Map per bundle to
.afterpack/, which carries its own .gitignore and self-ignores. It contains your original
source, so never deploy or commit it.
Things to know
- Seeds. Parcel builds bundles in several worker processes. Set
seed(orAFTERPACK_SEED) to use one seed across the whole build. - Directives.
/* @afterpack */directives that raise protection for a region are a Pro feature. They are read back from the bundle's source map, so enable source maps on the target. Directives in your entry module usually cannot be recovered; move that code into an imported module. - Content hashes. When Parcel targets browsers without native ES modules, it can put
content-hash placeholders in string literals, and obfuscation would break the lazy-chunk URLs. The
plugin detects this and fails the build. Build with
parcel build --no-content-hash, or use"preset": "minify". Parcel's default ES module output is not affected. - Cache. Parcel caches optimizer output. Clear
.parcel-cachefor a fresh seed on an unchanged build. - Not available here:
build.backupandpaths.include. - Parcel may print that ES module dependencies are experimental and that the plugin has non-statically analyzable dependencies. Both are harmless.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same
optimizer builds in AfterPack's cloud instead, which adds per-region
directives and two hardening transforms you can turn
on: self-integrity (anti-tamper) and comparison hardening. See AfterPack
Pro.
Links
- Parcel setup guide
- Presets and protection levels
- How AfterPack compares to other obfuscators
- Protecting paywall checks
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
