sourcedump
v1.1.0
Published
Recover a website's original source files from its published JS/CSS sourcemaps, like the Sources panel in Chrome DevTools
Maintainers
Readme
sourcedump
Recover a site's original source files from its published sourcemaps. The same thing Chrome DevTools does in the Sources panel, but on disk.
Zero dependencies. Node ≥ 18.3.
Usage
npx sourcedump -u https://example.comsourcedump -u <url> [-o <dir>]
-u, --url <url> page to scan. A .js/.css/.map URL works too and skips the
page scan. https:// is assumed if no scheme is given.
-o, --out <dir> where to write the recovered files (default: ./output)
-c, --concat <file> write every source into this ONE file instead of a tree,
each preceded by a /* ==== asset :: path ==== */ banner.
Made for grepping the lot for secrets, TODOs, comments.
Overrides -o.
-H, --header <h> extra request header, "Name: value". Repeat for more. Use
it to reach assets behind a login (Cookie, Authorization)
or a header-based WAF. Overrides the default User-Agent if
you pass one. NOTE: headers go to every fetched URL, so a
map hosted on a third-party CDN gets them too.
-s, --silent print nothing on success. Fatal errors still go to stderr
and the exit code still tells you what happened.
-h, --help help textPull sources from a staging app that needs a session:
npx sourcedump -u app.example.com -H "Cookie: session=abc" -H "X-Env: staging"Grep an entire site's sources in one pass:
npx sourcedump -u example.com -c all-sources.js -s && grep -nE 'api[_-]?key|secret|TODO' all-sources.js$ npx sourcedump -u https://example.com -o ./dump
12 asset(s) found
ok https://example.com/assets/app.4f1a.js -> 214 files
ok https://example.com/assets/dev.bundle.js -> 631 files (598 maps)
ok https://example.com/assets/style.9c2d.css -> 8 files
- https://example.com/vendor.js (HTTP 404 https://example.com/vendor.js.map)
3/12 assets, 601 sourcemaps, 853 files -> /home/you/dumpFiles land under the output dir at their original paths, so webpack://app/./src/ui/Button.tsx becomes dump/app/src/ui/Button.tsx.
What it does
- Fetches the page and pulls
<script src>/<link href>for.js,.mjs,.css. - Reads every
//# sourceMappingURLin each asset - external file or inlinedata:URI (base64 and percent-encoded). Webpackeval/eval-source-mapdev bundles carry one inline map per module, hundreds in a single file; all of them are unpacked. - If the comment was stripped, tries
<asset>.mapanyway. Many builds ship the map without the comment. - Writes every
sourcesContententry to disk. HonorssourceRootand index maps (sections).
Source paths are sanitized: .., absolute paths, UNC paths, and Windows-illegal characters can't write outside the output dir.
API
const { findAssets, decodeDataUri, extractMapRefs, entries, outPath, parseHeaders } = require("sourcedump");Limits
Assets are found by scanning the HTML, so chunks loaded at runtime by the JS itself are missed. Fetches are sequential and not retried.
License
MIT
