Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Protect JavaScript source code with v8 snapshot · nwjs/nw.js Wiki · GitHub
Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Protect JavaScript source code with v8 snapshot · nwjs/nw.js Wiki · GitHub
Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Protect JavaScript source code with v8 snapshot · nwjs/nw.js Wiki · GitHub
Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Protect JavaScript source code with v8 snapshot · nwjs/nw.js Wiki · GitHub
Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Protect JavaScript source code with v8 snapshot · nwjs/nw.js Wiki · GitHub
Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Protect JavaScript source code with v8 snapshot · nwjs/nw.js Wiki · GitHub
Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Protect JavaScript source code with v8 snapshot · nwjs/nw.js Wiki · GitHub
Skip to content

Protect JavaScript source code with v8 snapshot

Roger Wang edited this page Mar 24, 2017 · 20 revisions

NOTE: some content in this wiki applies only to 0.12 and earlier versions. For official documentation on 0.13 and later, see http://docs.nwjs.io

Since v0.4.2

There is a bug in 0.8.x that would make source code exposed. Do not use this feature with 0.8.x. It is fixed in 0.9.x

The JavaScript source code of your application can be protected by compiling to native code. Only the native code is distributed with the application and is loaded by the application.

There are important limitations in the current implementation. Please see the 'Limitation' section.

This feature is the fix for issue 269

Compilation

JS source code is compiled to native code (aka. 'snapshot') with the tool nwjc (before 0.12.0-rc1 it's supported by nwsnapshot tool, refer to the section below), which is provided in the binary download. To use it:

nwjc source.js binary.bin

The *.bin file is needed to be distributed with your application. You can name it whatever you want.

Load the compiled JS in your app

require('nw.gui').Window.get().evalNWBin(null,'binary.bin');

The arguments of the evalNWBin() method are similar with the Window.eval() method, where the first parameter is the target iframe ('null' for main frame), and the 2nd parameter is the binary code file.

Sample for nwjc

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwjc mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>require('nw.gui').Window.get().evalNWBin(null,'mytest.bin');mytest(2);console.log(mytest);</script></body></html>

Limitation of nwjc

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwjc for each of the platforms when you package your application.

Usage of the deprecated nwsnapshot way

Compilation

nwsnapshot --extra_code source.js snapshot.bin

Package

Add the following field to package.json:

"snapshot" : "snapshot.bin"

Run

It's important to remember that the code being compiled is evaluated when you launch nwsnapshot. Then the JS heap state is saved to the binary file (e.g. snapshot.bin) and restored right before JS context creation (and before your application launches). So you may not want to run any code in the top level scope. So it's better to just define functions or variables there.

And the scripts runs/loads loads very early (you can assume it's earlier than context creation) so Node and DOM objects such as window is not defined. So you may want to defined functions and pass window as argument.

The snapshot is used by V8 as a kind of 'template' to create JS contexts. So the objects defined there will be in every JS contexts.

Limitation of nwsnapshot

The source code being compiled cannot be too big. nwsnapshot will report error when this happens.

Experiments show that 3 copies of the jquery library will exceed this limit. If you feel this is too small for your application, consider split your code into 2 parts: compiled and plain source. If you have a real need against this limit, please file an issue and we'll find time to fix it.

The compiled code runs slower than normal JS: 30% performance according to v8bench. Normal JS source code will not be affected. Again, if you have a real need against this limit, please file an issue and we'll find time to fix it. The performance issue is fixed in 0.22: https://nwjs.io/blog/js-src-protect-perf/

The compiled code is not cross-platform nor compatible between versions of node-webkit. So you'll need to run nwsnapshot for each of the platforms when you package your application.

You cannot create closure in your code like this:

varsampleFunction;(function(){varprivateVar='private';sampleFunction=function(){returnprivateVar+'67868';};})();

It should be written like below instead:

functionsampleFunction(){varprivateVar='private';returnprivateVar+'67868';}

If you have a large piece of code like this then you could wrap it inside a function and then compile it.

Sample for nwsnapshot

mytest.js: (this is the JS code to be protected)

functionmytest(a){document.write(a+42);}

Compile mytest.js to native code:

nwsnapshot --extra_code mytest.js mytest.bin

package.json:

{
"name": "nw-demo",
"main": "index.html",
"snapshot": "mytest.bin"
}

index.html: (note that we don't need to distribute 'mytest.js' with it)

<html><head><title>snapshot demo</title></head><body><script>mytest(2);</script></body></html>

Troubleshooting

For some unknown reason, nwsnapshot will sometimes silently fail and provide a bad snapshot see issue#1295. To make sure that you always have a valid snapshot, you can use node-nw-snapshot.

Clone this wiki locally