@mrkt_frwd/remap
v0.1.0
Published
Reconstruct the original sources embedded in a source map. Refuses any entry that climbs out of the output directory rather than relocating it.
Downloads
84
Readme
@mrkt_frwd/remap
Reconstruct the original source tree embedded in a source map.
npx @mrkt_frwd/remap main.js.map --out ./srcWhat it is for
Production bundles ship with .map files more often than people intend. When one is
available — your own build, a bundle you are debugging, an app whose maps were left on
the server — it usually carries sourcesContent: the original, unminified files. This
turns that back into a directory tree you can read.
The part that matters
A source map is a file you got from somewhere else, and its sources array is used to
build filenames. That makes path traversal the entire security surface of a tool like
this, and it is not theoretical:
sources: ["../../../../.ssh/authorized_keys"]Verified before the guard existed — a Vite/Rollup-style map with plain relative sources
wrote a file to its grandparent directory. Webpack's webpack:/// prefix normalises
away, which is why casual testing missed it.
Every entry is now checked against the output root. Anything that climbs out is refused and reported, not relocated:
REMAP main.js.map
────────────────────────────────────
ok src/components/Header.jsx
ok src/utils/math.js
-- ../../PWNED.txt
refused — path escapes the output directory
2 file(s) written to ./src, 1 refusedStripping the .. and writing it somewhere inside the root would also be safe, and it
would be a guess about what the map meant. A map that climbs out of its own output
directory is malformed or hostile; saying which is the caller's business, not this
tool's.
Absolute paths and Windows drive letters are made relative to the root rather than honoured. A source the map references but does not embed is reported too, so a partial reconstruction never looks like a complete one.
Use it on things you have the right to read
Your own builds, your own bundles, and code you are permitted to inspect. A source map being reachable is not by itself permission to redistribute what is inside it.
API
const { unpackBundle } = require('@mrkt_frwd/remap');
const { written, skipped } = await unpackBundle('main.js.map', './src');Requirements
Node 18+. One dependency: source-map.
MIT © Joe Asare. Built at Joe Asare Studio.
