@afterpack/sveltekit
v0.2.2
Published
SvelteKit plugin for AfterPack: obfuscate a SvelteKit app's JavaScript during the Vite build
Maintainers
Readme
@afterpack/sveltekit
Obfuscate a SvelteKit build. @afterpack/sveltekit adds the
AfterPack JavaScript obfuscator to SvelteKit 1 and 2.
Install
npm install --save-dev @afterpack/sveltekitUsage
// vite.config.ts
import { sveltekit } from "@sveltejs/kit/vite";
import { afterpackSveltekit } from "@afterpack/sveltekit";
import { defineConfig } from "vite";
export default defineConfig({
plugins: [sveltekit(), afterpackSveltekit()],
});Put afterpackSveltekit() after sveltekit(). Every JavaScript chunk your adapter's build
produces is obfuscated before Vite writes it, on both the client and the server build. A failed run
fails the build.
afterpackSveltekit(options) takes the same options as
@afterpack/vite, for example
afterpackSveltekit({ preset: "hard", seed: "git" }).
The options you are most likely to set are preset, complexity,
seed, identifiers.reserved for names that must stay as they are,
paths.exclude for files to leave alone, and build.autorun to
turn AfterPack off. Every other option is in the configuration
reference. Options can also live in afterpack.json or in
AFTERPACK_* environment variables.
For a Svelte app without Kit, use
@afterpack/svelte.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same plugin
builds in AfterPack's cloud instead, which adds per-region
directives and two hardening transforms you can turn
on: self-integrity (anti-tamper) and comparison hardening. See AfterPack
Pro.
Links
- SvelteKit setup guide
- Presets and protection levels
- How AfterPack compares to other obfuscators
- Protecting paywall checks
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
