UNPKG

@varlock/astro-integration

Version:

Astro integration to use varlock for .env file loading - adds validation, type-safety, and extra security features

1,909 lines â€ĸ 68.3 kB
import fs from "node:fs";
import { fileURLToPath } from "node:url";
import { createDebug } from "varlock";
import { VarlockExecError, execSyncVarlock } from "varlock/exec-sync-varlock";
import { initVarlockEnv, scanForLeaks, varlockSettings } from "varlock/env";
import path from "node:path";
import { patchGlobalConsole } from "varlock/patch-console";
import { patchGlobalServerResponse } from "varlock/patch-server-response";
import { patchGlobalResponse } from "varlock/patch-response";
import { encryptEnvBlobSync, generateEncryptionKeyHex } from "varlock/encrypt-env";
//#region ../vite/dist/index.mjs
var __create = Object.create;
var __defProp = Object.defineProperty;
var __getOwnPropDesc = Object.getOwnPropertyDescriptor;
var __getOwnPropNames = Object.getOwnPropertyNames;
var __getProtoOf = Object.getPrototypeOf;
var __hasOwnProp = Object.prototype.hasOwnProperty;
var __commonJSMin = (cb, mod) => () => (mod || (cb((mod = { exports: {} }).exports, mod), cb = null), mod.exports);
var __copyProps = (to, from, except, desc) => {
	if (from && typeof from === "object" || typeof from === "function") for (var keys = __getOwnPropNames(from), i = 0, n = keys.length, key; i < n; i++) {
		key = keys[i];
		if (!__hasOwnProp.call(to, key) && key !== except) __defProp(to, key, {
			get: ((k) => from[k]).bind(null, key),
			enumerable: !(desc = __getOwnPropDesc(from, key)) || desc.enumerable
		});
	}
	return to;
};
var __toESM = (mod, isNodeMode, target) => (target = mod != null ? __create(__getProtoOf(mod)) : {}, __copyProps(isNodeMode || !mod || !mod.__esModule || !__hasOwnProp.call(mod, "default") ? __defProp(target, "default", {
	value: mod,
	enumerable: true
}) : target, mod));
var comma = ",".charCodeAt(0);
var semicolon = ";".charCodeAt(0);
var chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
var intToChar = /* @__PURE__ */ new Uint8Array(64);
var charToInt = /* @__PURE__ */ new Uint8Array(128);
for (let i = 0; i < chars.length; i++) {
	const c = chars.charCodeAt(i);
	intToChar[i] = c;
	charToInt[c] = i;
}
function encodeInteger(builder, num, relative) {
	let delta = num - relative;
	delta = delta < 0 ? -delta << 1 | 1 : delta << 1;
	do {
		let clamped = delta & 31;
		delta >>>= 5;
		if (delta > 0) clamped |= 32;
		builder.write(intToChar[clamped]);
	} while (delta > 0);
	return num;
}
var bufLength = 16384;
var td = typeof TextDecoder !== "undefined" ? /* @__PURE__ */ new TextDecoder() : typeof Buffer !== "undefined" ? { decode(buf) {
	return Buffer.from(buf.buffer, buf.byteOffset, buf.byteLength).toString();
} } : { decode(buf) {
	let out = "";
	for (let i = 0; i < buf.length; i++) out += String.fromCharCode(buf[i]);
	return out;
} };
var StringWriter = class {
	constructor() {
		this.pos = 0;
		this.out = "";
		this.buffer = new Uint8Array(bufLength);
	}
	write(v) {
		const { buffer } = this;
		buffer[this.pos++] = v;
		if (this.pos === bufLength) {
			this.out += td.decode(buffer);
			this.pos = 0;
		}
	}
	flush() {
		const { buffer, out, pos } = this;
		return pos > 0 ? out + td.decode(buffer.subarray(0, pos)) : out;
	}
};
function encode(decoded) {
	const writer = new StringWriter();
	let sourcesIndex = 0;
	let sourceLine = 0;
	let sourceColumn = 0;
	let namesIndex = 0;
	for (let i = 0; i < decoded.length; i++) {
		const line = decoded[i];
		if (i > 0) writer.write(semicolon);
		if (line.length === 0) continue;
		let genColumn = 0;
		for (let j = 0; j < line.length; j++) {
			const segment = line[j];
			if (j > 0) writer.write(comma);
			genColumn = encodeInteger(writer, segment[0], genColumn);
			if (segment.length === 1) continue;
			sourcesIndex = encodeInteger(writer, segment[1], sourcesIndex);
			sourceLine = encodeInteger(writer, segment[2], sourceLine);
			sourceColumn = encodeInteger(writer, segment[3], sourceColumn);
			if (segment.length === 4) continue;
			namesIndex = encodeInteger(writer, segment[4], namesIndex);
		}
	}
	return writer.flush();
}
var BitSet = class BitSet {
	constructor(arg) {
		this.bits = arg instanceof BitSet ? arg.bits.slice() : [];
	}
	add(n) {
		this.bits[n >> 5] |= 1 << (n & 31);
	}
	has(n) {
		return !!(this.bits[n >> 5] & 1 << (n & 31));
	}
};
var Chunk = class Chunk {
	constructor(start, end, content) {
		this.start = start;
		this.end = end;
		this.original = content;
		this.intro = "";
		this.outro = "";
		this.content = content;
		this.storeName = false;
		this.edited = false;
		this.previous = null;
		this.next = null;
	}
	appendLeft(content) {
		this.outro += content;
	}
	appendRight(content) {
		this.intro = this.intro + content;
	}
	clone() {
		const chunk = new Chunk(this.start, this.end, this.original);
		chunk.intro = this.intro;
		chunk.outro = this.outro;
		chunk.content = this.content;
		chunk.storeName = this.storeName;
		chunk.edited = this.edited;
		return chunk;
	}
	contains(index) {
		return this.start < index && index < this.end;
	}
	eachNext(fn) {
		let chunk = this;
		while (chunk) {
			fn(chunk);
			chunk = chunk.next;
		}
	}
	eachPrevious(fn) {
		let chunk = this;
		while (chunk) {
			fn(chunk);
			chunk = chunk.previous;
		}
	}
	edit(content, storeName, contentOnly) {
		this.content = content;
		if (!contentOnly) {
			this.intro = "";
			this.outro = "";
		}
		this.storeName = storeName;
		this.edited = true;
		return this;
	}
	prependLeft(content) {
		this.outro = content + this.outro;
	}
	prependRight(content) {
		this.intro = content + this.intro;
	}
	reset() {
		this.intro = "";
		this.outro = "";
		if (this.edited) {
			this.content = this.original;
			this.storeName = false;
			this.edited = false;
		}
	}
	split(index) {
		const sliceIndex = index - this.start;
		const originalBefore = this.original.slice(0, sliceIndex);
		const originalAfter = this.original.slice(sliceIndex);
		this.original = originalBefore;
		const newChunk = new Chunk(index, this.end, originalAfter);
		newChunk.outro = this.outro;
		this.outro = "";
		this.end = index;
		if (this.edited) {
			newChunk.edit("", false);
			this.content = "";
		} else this.content = originalBefore;
		newChunk.next = this.next;
		if (newChunk.next) newChunk.next.previous = newChunk;
		newChunk.previous = this;
		this.next = newChunk;
		return newChunk;
	}
	toString() {
		return this.intro + this.content + this.outro;
	}
	trimEnd(rx) {
		this.outro = this.outro.replace(rx, "");
		if (this.outro.length) return true;
		const trimmed = this.content.replace(rx, "");
		if (trimmed.length) {
			if (trimmed !== this.content) {
				this.split(this.start + trimmed.length).edit("", void 0, true);
				if (this.edited) this.edit(trimmed, this.storeName, true);
			}
			return true;
		} else {
			this.edit("", void 0, true);
			this.intro = this.intro.replace(rx, "");
			if (this.intro.length) return true;
		}
	}
	trimStart(rx) {
		this.intro = this.intro.replace(rx, "");
		if (this.intro.length) return true;
		const trimmed = this.content.replace(rx, "");
		if (trimmed.length) {
			if (trimmed !== this.content) {
				const newChunk = this.split(this.end - trimmed.length);
				if (this.edited) newChunk.edit(trimmed, this.storeName, true);
				this.edit("", void 0, true);
			}
			return true;
		} else {
			this.edit("", void 0, true);
			this.outro = this.outro.replace(rx, "");
			if (this.outro.length) return true;
		}
	}
};
function getBtoa() {
	if (typeof globalThis !== "undefined" && typeof globalThis.btoa === "function") return (str) => globalThis.btoa(unescape(encodeURIComponent(str)));
	else if (typeof Buffer === "function") return (str) => Buffer.from(str, "utf-8").toString("base64");
	else return () => {
		throw new Error("Unsupported environment: `window.btoa` or `Buffer` should be supported.");
	};
}
const btoa = /*#__PURE__*/ getBtoa();
var SourceMap = class {
	constructor(properties) {
		this.version = 3;
		this.file = properties.file;
		this.sources = properties.sources;
		this.sourcesContent = properties.sourcesContent;
		this.names = properties.names;
		this.mappings = encode(properties.mappings);
		if (typeof properties.x_google_ignoreList !== "undefined") this.x_google_ignoreList = properties.x_google_ignoreList;
		if (typeof properties.debugId !== "undefined") this.debugId = properties.debugId;
	}
	toString() {
		return JSON.stringify(this);
	}
	toUrl() {
		return "data:application/json;charset=utf-8;base64," + btoa(this.toString());
	}
};
function guessIndent(code) {
	const lines = code.split("\n");
	const tabbed = lines.filter((line) => /^\t+/.test(line));
	const spaced = lines.filter((line) => /^ {2,}/.test(line));
	if (tabbed.length === 0 && spaced.length === 0) return null;
	if (tabbed.length >= spaced.length) return "	";
	const min = spaced.reduce((previous, current) => {
		const numSpaces = /^ +/.exec(current)[0].length;
		return Math.min(numSpaces, previous);
	}, Infinity);
	return new Array(min + 1).join(" ");
}
function getRelativePath(from, to) {
	const fromParts = from.split(/[/\\]/);
	const toParts = to.split(/[/\\]/);
	fromParts.pop();
	while (fromParts[0] === toParts[0]) {
		fromParts.shift();
		toParts.shift();
	}
	if (fromParts.length) {
		let i = fromParts.length;
		while (i--) fromParts[i] = "..";
	}
	return fromParts.concat(toParts).join("/");
}
const toString = Object.prototype.toString;
function isObject(thing) {
	return toString.call(thing) === "[object Object]";
}
function getLocator(source) {
	const originalLines = source.split("\n");
	const lineOffsets = [];
	for (let i = 0, pos = 0; i < originalLines.length; i++) {
		lineOffsets.push(pos);
		pos += originalLines[i].length + 1;
	}
	return function locate(index) {
		let i = 0;
		let j = lineOffsets.length;
		while (i < j) {
			const m = i + j >> 1;
			if (index < lineOffsets[m]) j = m;
			else i = m + 1;
		}
		const line = i - 1;
		return {
			line,
			column: index - lineOffsets[line]
		};
	};
}
const wordRegex = /\w/;
var Mappings = class {
	constructor(hires) {
		this.hires = hires;
		this.generatedCodeLine = 0;
		this.generatedCodeColumn = 0;
		this.raw = [];
		this.rawSegments = this.raw[this.generatedCodeLine] = [];
		this.pending = null;
	}
	addEdit(sourceIndex, content, loc, nameIndex) {
		if (content.length) {
			const contentLengthMinusOne = content.length - 1;
			let contentLineEnd = content.indexOf("\n", 0);
			let previousContentLineEnd = -1;
			while (contentLineEnd >= 0 && contentLengthMinusOne > contentLineEnd) {
				const segment = [
					this.generatedCodeColumn,
					sourceIndex,
					loc.line,
					loc.column
				];
				if (nameIndex >= 0) segment.push(nameIndex);
				this.rawSegments.push(segment);
				this.generatedCodeLine += 1;
				this.raw[this.generatedCodeLine] = this.rawSegments = [];
				this.generatedCodeColumn = 0;
				previousContentLineEnd = contentLineEnd;
				contentLineEnd = content.indexOf("\n", contentLineEnd + 1);
			}
			const segment = [
				this.generatedCodeColumn,
				sourceIndex,
				loc.line,
				loc.column
			];
			if (nameIndex >= 0) segment.push(nameIndex);
			this.rawSegments.push(segment);
			this.advance(content.slice(previousContentLineEnd + 1));
		} else if (this.pending) {
			this.rawSegments.push(this.pending);
			this.advance(content);
		}
		this.pending = null;
	}
	addUneditedChunk(sourceIndex, chunk, original, loc, sourcemapLocations) {
		let originalCharIndex = chunk.start;
		let first = true;
		let charInHiresBoundary = false;
		while (originalCharIndex < chunk.end) {
			if (original[originalCharIndex] === "\n") {
				loc.line += 1;
				loc.column = 0;
				this.generatedCodeLine += 1;
				this.raw[this.generatedCodeLine] = this.rawSegments = [];
				this.generatedCodeColumn = 0;
				first = true;
				charInHiresBoundary = false;
			} else {
				if (this.hires || first || sourcemapLocations.has(originalCharIndex)) {
					const segment = [
						this.generatedCodeColumn,
						sourceIndex,
						loc.line,
						loc.column
					];
					if (this.hires === "boundary") {
						if (wordRegex.test(original[originalCharIndex])) {
							if (!charInHiresBoundary) {
								this.rawSegments.push(segment);
								charInHiresBoundary = true;
							}
						} else {
							this.rawSegments.push(segment);
							charInHiresBoundary = false;
						}
					} else this.rawSegments.push(segment);
				}
				loc.column += 1;
				this.generatedCodeColumn += 1;
				first = false;
			}
			originalCharIndex += 1;
		}
		this.pending = null;
	}
	advance(str) {
		if (!str) return;
		const lines = str.split("\n");
		if (lines.length > 1) {
			for (let i = 0; i < lines.length - 1; i++) {
				this.generatedCodeLine++;
				this.raw[this.generatedCodeLine] = this.rawSegments = [];
			}
			this.generatedCodeColumn = 0;
		}
		this.generatedCodeColumn += lines[lines.length - 1].length;
	}
};
const n = "\n";
const warned = {
	insertLeft: false,
	insertRight: false,
	storeName: false
};
var MagicString = class MagicString {
	constructor(string, options = {}) {
		const chunk = new Chunk(0, string.length, string);
		Object.defineProperties(this, {
			original: {
				writable: true,
				value: string
			},
			outro: {
				writable: true,
				value: ""
			},
			intro: {
				writable: true,
				value: ""
			},
			firstChunk: {
				writable: true,
				value: chunk
			},
			lastChunk: {
				writable: true,
				value: chunk
			},
			lastSearchedChunk: {
				writable: true,
				value: chunk
			},
			byStart: {
				writable: true,
				value: {}
			},
			byEnd: {
				writable: true,
				value: {}
			},
			filename: {
				writable: true,
				value: options.filename
			},
			indentExclusionRanges: {
				writable: true,
				value: options.indentExclusionRanges
			},
			sourcemapLocations: {
				writable: true,
				value: new BitSet()
			},
			storedNames: {
				writable: true,
				value: {}
			},
			indentStr: {
				writable: true,
				value: void 0
			},
			ignoreList: {
				writable: true,
				value: options.ignoreList
			},
			offset: {
				writable: true,
				value: options.offset || 0
			}
		});
		this.byStart[0] = chunk;
		this.byEnd[string.length] = chunk;
	}
	addSourcemapLocation(char) {
		this.sourcemapLocations.add(char);
	}
	append(content) {
		if (typeof content !== "string") throw new TypeError("outro content must be a string");
		this.outro += content;
		return this;
	}
	appendLeft(index, content) {
		index = index + this.offset;
		if (typeof content !== "string") throw new TypeError("inserted content must be a string");
		this._split(index);
		const chunk = this.byEnd[index];
		if (chunk) chunk.appendLeft(content);
		else this.intro += content;
		return this;
	}
	appendRight(index, content) {
		index = index + this.offset;
		if (typeof content !== "string") throw new TypeError("inserted content must be a string");
		this._split(index);
		const chunk = this.byStart[index];
		if (chunk) chunk.appendRight(content);
		else this.outro += content;
		return this;
	}
	clone() {
		const cloned = new MagicString(this.original, {
			filename: this.filename,
			offset: this.offset
		});
		let originalChunk = this.firstChunk;
		let clonedChunk = cloned.firstChunk = cloned.lastSearchedChunk = originalChunk.clone();
		while (originalChunk) {
			cloned.byStart[clonedChunk.start] = clonedChunk;
			cloned.byEnd[clonedChunk.end] = clonedChunk;
			const nextOriginalChunk = originalChunk.next;
			const nextClonedChunk = nextOriginalChunk && nextOriginalChunk.clone();
			if (nextClonedChunk) {
				clonedChunk.next = nextClonedChunk;
				nextClonedChunk.previous = clonedChunk;
				clonedChunk = nextClonedChunk;
			}
			originalChunk = nextOriginalChunk;
		}
		cloned.lastChunk = clonedChunk;
		if (this.indentExclusionRanges) cloned.indentExclusionRanges = this.indentExclusionRanges.slice();
		cloned.sourcemapLocations = new BitSet(this.sourcemapLocations);
		cloned.intro = this.intro;
		cloned.outro = this.outro;
		return cloned;
	}
	generateDecodedMap(options) {
		options = options || {};
		const sourceIndex = 0;
		const names = Object.keys(this.storedNames);
		const mappings = new Mappings(options.hires);
		const locate = getLocator(this.original);
		if (this.intro) mappings.advance(this.intro);
		this.firstChunk.eachNext((chunk) => {
			const loc = locate(chunk.start);
			if (chunk.intro.length) mappings.advance(chunk.intro);
			if (chunk.edited) mappings.addEdit(sourceIndex, chunk.content, loc, chunk.storeName ? names.indexOf(chunk.original) : -1);
			else mappings.addUneditedChunk(sourceIndex, chunk, this.original, loc, this.sourcemapLocations);
			if (chunk.outro.length) mappings.advance(chunk.outro);
		});
		if (this.outro) mappings.advance(this.outro);
		return {
			file: options.file ? options.file.split(/[/\\]/).pop() : void 0,
			sources: [options.source ? getRelativePath(options.file || "", options.source) : options.file || ""],
			sourcesContent: options.includeContent ? [this.original] : void 0,
			names,
			mappings: mappings.raw,
			x_google_ignoreList: this.ignoreList ? [sourceIndex] : void 0
		};
	}
	generateMap(options) {
		return new SourceMap(this.generateDecodedMap(options));
	}
	_ensureindentStr() {
		if (this.indentStr === void 0) this.indentStr = guessIndent(this.original);
	}
	_getRawIndentString() {
		this._ensureindentStr();
		return this.indentStr;
	}
	getIndentString() {
		this._ensureindentStr();
		return this.indentStr === null ? "	" : this.indentStr;
	}
	indent(indentStr, options) {
		const pattern = /^[^\r\n]/gm;
		if (isObject(indentStr)) {
			options = indentStr;
			indentStr = void 0;
		}
		if (indentStr === void 0) {
			this._ensureindentStr();
			indentStr = this.indentStr || "	";
		}
		if (indentStr === "") return this;
		options = options || {};
		const isExcluded = {};
		if (options.exclude) (typeof options.exclude[0] === "number" ? [options.exclude] : options.exclude).forEach((exclusion) => {
			for (let i = exclusion[0]; i < exclusion[1]; i += 1) isExcluded[i] = true;
		});
		let shouldIndentNextCharacter = options.indentStart !== false;
		const replacer = (match) => {
			if (shouldIndentNextCharacter) return `${indentStr}${match}`;
			shouldIndentNextCharacter = true;
			return match;
		};
		this.intro = this.intro.replace(pattern, replacer);
		let charIndex = 0;
		let chunk = this.firstChunk;
		while (chunk) {
			const end = chunk.end;
			if (chunk.edited) {
				if (!isExcluded[charIndex]) {
					chunk.content = chunk.content.replace(pattern, replacer);
					if (chunk.content.length) shouldIndentNextCharacter = chunk.content[chunk.content.length - 1] === "\n";
				}
			} else {
				charIndex = chunk.start;
				while (charIndex < end) {
					if (!isExcluded[charIndex]) {
						const char = this.original[charIndex];
						if (char === "\n") shouldIndentNextCharacter = true;
						else if (char !== "\r" && shouldIndentNextCharacter) {
							shouldIndentNextCharacter = false;
							if (charIndex === chunk.start) chunk.prependRight(indentStr);
							else {
								this._splitChunk(chunk, charIndex);
								chunk = chunk.next;
								chunk.prependRight(indentStr);
							}
						}
					}
					charIndex += 1;
				}
			}
			charIndex = chunk.end;
			chunk = chunk.next;
		}
		this.outro = this.outro.replace(pattern, replacer);
		return this;
	}
	insert() {
		throw new Error("magicString.insert(...) is deprecated. Use prependRight(...) or appendLeft(...)");
	}
	insertLeft(index, content) {
		if (!warned.insertLeft) {
			console.warn("magicString.insertLeft(...) is deprecated. Use magicString.appendLeft(...) instead");
			warned.insertLeft = true;
		}
		return this.appendLeft(index, content);
	}
	insertRight(index, content) {
		if (!warned.insertRight) {
			console.warn("magicString.insertRight(...) is deprecated. Use magicString.prependRight(...) instead");
			warned.insertRight = true;
		}
		return this.prependRight(index, content);
	}
	move(start, end, index) {
		start = start + this.offset;
		end = end + this.offset;
		index = index + this.offset;
		if (index >= start && index <= end) throw new Error("Cannot move a selection inside itself");
		this._split(start);
		this._split(end);
		this._split(index);
		const first = this.byStart[start];
		const last = this.byEnd[end];
		const oldLeft = first.previous;
		const oldRight = last.next;
		const newRight = this.byStart[index];
		if (!newRight && last === this.lastChunk) return this;
		const newLeft = newRight ? newRight.previous : this.lastChunk;
		if (oldLeft) oldLeft.next = oldRight;
		if (oldRight) oldRight.previous = oldLeft;
		if (newLeft) newLeft.next = first;
		if (newRight) newRight.previous = last;
		if (!first.previous) this.firstChunk = last.next;
		if (!last.next) {
			this.lastChunk = first.previous;
			this.lastChunk.next = null;
		}
		first.previous = newLeft;
		last.next = newRight || null;
		if (!newLeft) this.firstChunk = first;
		if (!newRight) this.lastChunk = last;
		return this;
	}
	overwrite(start, end, content, options) {
		options = options || {};
		return this.update(start, end, content, {
			...options,
			overwrite: !options.contentOnly
		});
	}
	update(start, end, content, options) {
		start = start + this.offset;
		end = end + this.offset;
		if (typeof content !== "string") throw new TypeError("replacement content must be a string");
		if (this.original.length !== 0) {
			while (start < 0) start += this.original.length;
			while (end < 0) end += this.original.length;
		}
		if (end > this.original.length) throw new Error("end is out of bounds");
		if (start === end) throw new Error("Cannot overwrite a zero-length range – use appendLeft or prependRight instead");
		this._split(start);
		this._split(end);
		if (options === true) {
			if (!warned.storeName) {
				console.warn("The final argument to magicString.overwrite(...) should be an options object. See https://github.com/rich-harris/magic-string");
				warned.storeName = true;
			}
			options = { storeName: true };
		}
		const storeName = options !== void 0 ? options.storeName : false;
		const overwrite = options !== void 0 ? options.overwrite : false;
		if (storeName) {
			const original = this.original.slice(start, end);
			Object.defineProperty(this.storedNames, original, {
				writable: true,
				value: true,
				enumerable: true
			});
		}
		const first = this.byStart[start];
		const last = this.byEnd[end];
		if (first) {
			let chunk = first;
			while (chunk !== last) {
				if (chunk.next !== this.byStart[chunk.end]) throw new Error("Cannot overwrite across a split point");
				chunk = chunk.next;
				chunk.edit("", false);
			}
			first.edit(content, storeName, !overwrite);
		} else {
			const newChunk = new Chunk(start, end, "").edit(content, storeName);
			last.next = newChunk;
			newChunk.previous = last;
		}
		return this;
	}
	prepend(content) {
		if (typeof content !== "string") throw new TypeError("outro content must be a string");
		this.intro = content + this.intro;
		return this;
	}
	prependLeft(index, content) {
		index = index + this.offset;
		if (typeof content !== "string") throw new TypeError("inserted content must be a string");
		this._split(index);
		const chunk = this.byEnd[index];
		if (chunk) chunk.prependLeft(content);
		else this.intro = content + this.intro;
		return this;
	}
	prependRight(index, content) {
		index = index + this.offset;
		if (typeof content !== "string") throw new TypeError("inserted content must be a string");
		this._split(index);
		const chunk = this.byStart[index];
		if (chunk) chunk.prependRight(content);
		else this.outro = content + this.outro;
		return this;
	}
	remove(start, end) {
		start = start + this.offset;
		end = end + this.offset;
		if (this.original.length !== 0) {
			while (start < 0) start += this.original.length;
			while (end < 0) end += this.original.length;
		}
		if (start === end) return this;
		if (start < 0 || end > this.original.length) throw new Error("Character is out of bounds");
		if (start > end) throw new Error("end must be greater than start");
		this._split(start);
		this._split(end);
		let chunk = this.byStart[start];
		while (chunk) {
			chunk.intro = "";
			chunk.outro = "";
			chunk.edit("");
			chunk = end > chunk.end ? this.byStart[chunk.end] : null;
		}
		return this;
	}
	reset(start, end) {
		start = start + this.offset;
		end = end + this.offset;
		if (this.original.length !== 0) {
			while (start < 0) start += this.original.length;
			while (end < 0) end += this.original.length;
		}
		if (start === end) return this;
		if (start < 0 || end > this.original.length) throw new Error("Character is out of bounds");
		if (start > end) throw new Error("end must be greater than start");
		this._split(start);
		this._split(end);
		let chunk = this.byStart[start];
		while (chunk) {
			chunk.reset();
			chunk = end > chunk.end ? this.byStart[chunk.end] : null;
		}
		return this;
	}
	lastChar() {
		if (this.outro.length) return this.outro[this.outro.length - 1];
		let chunk = this.lastChunk;
		do {
			if (chunk.outro.length) return chunk.outro[chunk.outro.length - 1];
			if (chunk.content.length) return chunk.content[chunk.content.length - 1];
			if (chunk.intro.length) return chunk.intro[chunk.intro.length - 1];
		} while (chunk = chunk.previous);
		if (this.intro.length) return this.intro[this.intro.length - 1];
		return "";
	}
	lastLine() {
		let lineIndex = this.outro.lastIndexOf(n);
		if (lineIndex !== -1) return this.outro.substr(lineIndex + 1);
		let lineStr = this.outro;
		let chunk = this.lastChunk;
		do {
			if (chunk.outro.length > 0) {
				lineIndex = chunk.outro.lastIndexOf(n);
				if (lineIndex !== -1) return chunk.outro.substr(lineIndex + 1) + lineStr;
				lineStr = chunk.outro + lineStr;
			}
			if (chunk.content.length > 0) {
				lineIndex = chunk.content.lastIndexOf(n);
				if (lineIndex !== -1) return chunk.content.substr(lineIndex + 1) + lineStr;
				lineStr = chunk.content + lineStr;
			}
			if (chunk.intro.length > 0) {
				lineIndex = chunk.intro.lastIndexOf(n);
				if (lineIndex !== -1) return chunk.intro.substr(lineIndex + 1) + lineStr;
				lineStr = chunk.intro + lineStr;
			}
		} while (chunk = chunk.previous);
		lineIndex = this.intro.lastIndexOf(n);
		if (lineIndex !== -1) return this.intro.substr(lineIndex + 1) + lineStr;
		return this.intro + lineStr;
	}
	slice(start = 0, end = this.original.length - this.offset) {
		start = start + this.offset;
		end = end + this.offset;
		if (this.original.length !== 0) {
			while (start < 0) start += this.original.length;
			while (end < 0) end += this.original.length;
		}
		let result = "";
		let chunk = this.firstChunk;
		while (chunk && (chunk.start > start || chunk.end <= start)) {
			if (chunk.start < end && chunk.end >= end) return result;
			chunk = chunk.next;
		}
		if (chunk && chunk.edited && chunk.start !== start) throw new Error(`Cannot use replaced character ${start} as slice start anchor.`);
		const startChunk = chunk;
		while (chunk) {
			if (chunk.intro && (startChunk !== chunk || chunk.start === start)) result += chunk.intro;
			const containsEnd = chunk.start < end && chunk.end >= end;
			if (containsEnd && chunk.edited && chunk.end !== end) throw new Error(`Cannot use replaced character ${end} as slice end anchor.`);
			const sliceStart = startChunk === chunk ? start - chunk.start : 0;
			const sliceEnd = containsEnd ? chunk.content.length + end - chunk.end : chunk.content.length;
			result += chunk.content.slice(sliceStart, sliceEnd);
			if (chunk.outro && (!containsEnd || chunk.end === end)) result += chunk.outro;
			if (containsEnd) break;
			chunk = chunk.next;
		}
		return result;
	}
	snip(start, end) {
		const clone = this.clone();
		clone.remove(0, start);
		clone.remove(end, clone.original.length);
		return clone;
	}
	_split(index) {
		if (this.byStart[index] || this.byEnd[index]) return;
		let chunk = this.lastSearchedChunk;
		let previousChunk = chunk;
		const searchForward = index > chunk.end;
		while (chunk) {
			if (chunk.contains(index)) return this._splitChunk(chunk, index);
			chunk = searchForward ? this.byStart[chunk.end] : this.byEnd[chunk.start];
			if (chunk === previousChunk) return;
			previousChunk = chunk;
		}
	}
	_splitChunk(chunk, index) {
		if (chunk.edited && chunk.content.length) {
			const loc = getLocator(this.original)(index);
			throw new Error(`Cannot split a chunk that has already been edited (${loc.line}:${loc.column} – "${chunk.original}")`);
		}
		const newChunk = chunk.split(index);
		this.byEnd[index] = chunk;
		this.byStart[index] = newChunk;
		this.byEnd[newChunk.end] = newChunk;
		if (chunk === this.lastChunk) this.lastChunk = newChunk;
		this.lastSearchedChunk = chunk;
		return true;
	}
	toString() {
		let str = this.intro;
		let chunk = this.firstChunk;
		while (chunk) {
			str += chunk.toString();
			chunk = chunk.next;
		}
		return str + this.outro;
	}
	isEmpty() {
		let chunk = this.firstChunk;
		do
			if (chunk.intro.length && chunk.intro.trim() || chunk.content.length && chunk.content.trim() || chunk.outro.length && chunk.outro.trim()) return false;
		while (chunk = chunk.next);
		return true;
	}
	length() {
		let chunk = this.firstChunk;
		let length = 0;
		do
			length += chunk.intro.length + chunk.content.length + chunk.outro.length;
		while (chunk = chunk.next);
		return length;
	}
	trimLines() {
		return this.trim("[\\r\\n]");
	}
	trim(charType) {
		return this.trimStart(charType).trimEnd(charType);
	}
	trimEndAborted(charType) {
		const rx = new RegExp((charType || "\\s") + "+$");
		this.outro = this.outro.replace(rx, "");
		if (this.outro.length) return true;
		let chunk = this.lastChunk;
		do {
			const end = chunk.end;
			const aborted = chunk.trimEnd(rx);
			if (chunk.end !== end) {
				if (this.lastChunk === chunk) this.lastChunk = chunk.next;
				this.byEnd[chunk.end] = chunk;
				this.byStart[chunk.next.start] = chunk.next;
				this.byEnd[chunk.next.end] = chunk.next;
			}
			if (aborted) return true;
			chunk = chunk.previous;
		} while (chunk);
		return false;
	}
	trimEnd(charType) {
		this.trimEndAborted(charType);
		return this;
	}
	trimStartAborted(charType) {
		const rx = new RegExp("^" + (charType || "\\s") + "+");
		this.intro = this.intro.replace(rx, "");
		if (this.intro.length) return true;
		let chunk = this.firstChunk;
		do {
			const end = chunk.end;
			const aborted = chunk.trimStart(rx);
			if (chunk.end !== end) {
				if (chunk === this.lastChunk) this.lastChunk = chunk.next;
				this.byEnd[chunk.end] = chunk;
				this.byStart[chunk.next.start] = chunk.next;
				this.byEnd[chunk.next.end] = chunk.next;
			}
			if (aborted) return true;
			chunk = chunk.next;
		} while (chunk);
		return false;
	}
	trimStart(charType) {
		this.trimStartAborted(charType);
		return this;
	}
	hasChanged() {
		return this.original !== this.toString();
	}
	_replaceRegexp(searchValue, replacement) {
		function getReplacement(match, str) {
			if (typeof replacement === "string") return replacement.replace(/\$(\$|&|\d+)/g, (_, i) => {
				if (i === "$") return "$";
				if (i === "&") return match[0];
				if (+i < match.length) return match[+i];
				return `$${i}`;
			});
			else return replacement(...match, match.index, str, match.groups);
		}
		function matchAll(re, str) {
			let match;
			const matches = [];
			while (match = re.exec(str)) matches.push(match);
			return matches;
		}
		if (searchValue.global) matchAll(searchValue, this.original).forEach((match) => {
			if (match.index != null) {
				const replacement = getReplacement(match, this.original);
				if (replacement !== match[0]) this.overwrite(match.index, match.index + match[0].length, replacement);
			}
		});
		else {
			const match = this.original.match(searchValue);
			if (match && match.index != null) {
				const replacement = getReplacement(match, this.original);
				if (replacement !== match[0]) this.overwrite(match.index, match.index + match[0].length, replacement);
			}
		}
		return this;
	}
	_replaceString(string, replacement) {
		const { original } = this;
		const index = original.indexOf(string);
		if (index !== -1) {
			if (typeof replacement === "function") replacement = replacement(string, index, original);
			if (string !== replacement) this.overwrite(index, index + string.length, replacement);
		}
		return this;
	}
	replace(searchValue, replacement) {
		if (typeof searchValue === "string") return this._replaceString(searchValue, replacement);
		return this._replaceRegexp(searchValue, replacement);
	}
	_replaceAllString(string, replacement) {
		const { original } = this;
		const stringLength = string.length;
		for (let index = original.indexOf(string); index !== -1; index = original.indexOf(string, index + stringLength)) {
			const previous = original.slice(index, index + stringLength);
			let _replacement = replacement;
			if (typeof replacement === "function") _replacement = replacement(previous, index, original);
			if (previous !== _replacement) this.overwrite(index, index + stringLength, _replacement);
		}
		return this;
	}
	replaceAll(searchValue, replacement) {
		if (typeof searchValue === "string") return this._replaceAllString(searchValue, replacement);
		if (!searchValue.global) throw new TypeError("MagicString.prototype.replaceAll called with a non-global RegExp argument");
		return this._replaceRegexp(searchValue, replacement);
	}
};
var import_ast_matcher = /* @__PURE__ */ __toESM((/* @__PURE__ */ __commonJSMin(((exports, module) => {
	const STOP = false;
	const SKIP_BRANCH = 1;
	const IGNORED_KEYS = [
		"start",
		"end",
		"loc",
		"location",
		"locations",
		"line",
		"column",
		"range",
		"ranges",
		"raw",
		"extra"
	];
	let _parser = function() {
		throw new Error("No parser set, you need to set parser before use astMatcher. For instance, astMatcher.setParser(esprima.parse)");
	};
	function setParser(p) {
		if (typeof p !== "function") throw new Error("Input parser must be a function that takes JavaScript contents as input, produce a estree compliant syntax tree object.");
		_parser = function(contents) {
			let node = p(contents);
			if (node.type === "File" && node.program) node = node.program;
			return node;
		};
	}
	function traverse(object, visitor) {
		let child;
		if (!object) return;
		let r = visitor.call(null, object);
		if (r === STOP) return STOP;
		if (r === SKIP_BRANCH) return;
		for (let i = 0, keys = Object.keys(object); i < keys.length; i++) {
			let key = keys[i];
			if (IGNORED_KEYS.indexOf(key) !== -1) continue;
			child = object[key];
			if (typeof child === "object" && child !== null) {
				if (traverse(child, visitor) === STOP) return STOP;
			}
		}
	}
	const ANY = 1;
	const ANL = 2;
	const STR = 3;
	const ARR = 4;
	function matchTerm(pattern) {
		let possible;
		if (pattern.type === "Identifier") possible = pattern.name.toString();
		else if (pattern.type === "ExpressionStatement" && pattern.expression.type === "Identifier") possible = pattern.expression.name.toString();
		else if ((pattern.type === "FieldDefinition" || pattern.type === "ClassProperty") && pattern.key.type === "Identifier") possible = pattern.key.name.toString();
		if (!possible || !possible.startsWith("__")) return;
		let type;
		if (possible === "__any" || possible.startsWith("__any_")) type = ANY;
		else if (possible === "__anl" || possible.startsWith("__anl_")) type = ANL;
		else if (possible === "__str" || possible.startsWith("__str_")) type = STR;
		else if (possible === "__arr" || possible.startsWith("__arr_")) type = ARR;
		if (type) return {
			type,
			name: possible.slice(6)
		};
	}
	/**
	* Extract info from a partial estree syntax tree, see astMatcher for pattern format
	* @param pattern The pattern used on matching
	* @param part The target partial syntax tree
	* @return Returns named matches, or false.
	*/
	function extract(pattern, part) {
		if (!pattern) throw new Error("missing pattern");
		if (!part) return STOP;
		let term = matchTerm(pattern);
		if (term) {
			if (term.type === ANY) {
				if (term.name) {
					let r = {};
					r[term.name] = part;
					return r;
				}
				return {};
			} else if (term.type === STR) {
				if (part.type === "Literal" || part.type === "StringLiteral") {
					if (term.name) {
						let r = {};
						r[term.name] = part.value;
						return r;
					}
					return {};
				}
				return STOP;
			}
		}
		if (Array.isArray(pattern)) {
			if (!Array.isArray(part)) return STOP;
			if (pattern.length === 1) {
				let arrTerm = matchTerm(pattern[0]);
				if (arrTerm) {
					if (arrTerm.type === ARR) {
						let arr = part.filter(function(it) {
							return it.type === "Literal" || it.type === "StringLiteral";
						}).map(function(it) {
							return it.value;
						});
						if (arr.length) {
							if (arrTerm.name) {
								let r = {};
								r[arrTerm.name] = arr;
								return r;
							}
							return {};
						}
						return STOP;
					} else if (arrTerm.type === ANL) {
						if (arrTerm.name) {
							let r = {};
							r[arrTerm.name] = part;
							return r;
						}
						return {};
					}
				}
			}
			if (pattern.length !== part.length) return STOP;
		}
		let allResult = {};
		for (let i = 0, keys = Object.keys(pattern); i < keys.length; i++) {
			let key = keys[i];
			if (IGNORED_KEYS.indexOf(key) !== -1) continue;
			let nextPattern = pattern[key];
			let nextPart = part[key];
			if (!nextPattern || typeof nextPattern !== "object") {
				if (nextPattern === nextPart) continue;
				return STOP;
			}
			const result = extract(nextPattern, nextPart);
			if (result === STOP) return STOP;
			if (result) Object.assign(allResult, result);
		}
		return allResult;
	}
	/**
	* Compile a pattern into estree syntax tree
	* @param pattern The pattern used on matching, can be a string or estree node
	* @return Returns an estree node to be used as pattern in extract(pattern, part)
	*/
	function compilePattern(pattern) {
		let exp = ensureParsed(pattern);
		if (exp.type !== "Program" || !exp.body) throw new Error(`Not a valid expression:  "${pattern}".`);
		if (exp.body.length === 0) throw new Error(`There is no statement in pattern "${pattern}".`);
		if (exp.body.length > 1) throw new Error(`Multiple statements is not supported "${pattern}".`);
		exp = exp.body[0];
		if (exp.type === "ExpressionStatement") exp = exp.expression;
		return exp;
	}
	function ensureParsed(codeOrNode) {
		if (codeOrNode && codeOrNode.type) {
			if (codeOrNode.type === "File" && codeOrNode.program) return codeOrNode.program;
			return codeOrNode;
		}
		return _parser(codeOrNode);
	}
	/**
	* Pattern matching using AST on JavaScript source code
	* @param pattern The pattern to be matched
	* @return Returns a function that takes source code string (or estree syntax tree) as input, produces matched result or undefined.
	*
	* __any       matches any single node, but no extract
	* __anl       matches array of nodes, but no extract
	* __str       matches string literal, but no extract
	* __arr       matches array of partial string literals, but no extract
	* __any_aName matches single node, return {aName: node}
	* __anl_aName matches array of nodes, return {aName: array_of_nodes}
	* __str_aName matches string literal, return {aName: value}
	* __arr_aName matches array, extract string literals, return {aName: [values]}
	*
	* note: __arr_aName can match partial array
	*       [foo, "foo", lorem, "bar", lorem] => ["foo", "bar"]
	*
	* note: __anl, and __arr_*
	*       use method(__anl) or method(__arr_a) to match method(a, "b");
	*       use method([__anl]) or method([__arr_a]) to match method([a, "b"]);
	*
	* Usage:
	*   let m = astMatcher('__any.method(__str_foo, [__arr_opts])');
	*   m('au.method("a", ["b", "c"]); jq.method("d", ["e"])');
	*
	*   => [
	*         {match: {foo: "a", opts: ["b", "c"]}, node: <CallExpression node> }
	*         {match: {foo: "d", opts: ["e"]}, node: <CallExpression node> }
	*      ]
	*/
	function astMatcher(pattern) {
		let pat = compilePattern(pattern);
		return function(jsStr) {
			let node = ensureParsed(jsStr);
			let matches = [];
			traverse(node, function(n) {
				let m = extract(pat, n);
				if (m) matches.push({
					match: m,
					node: n
				});
			});
			return matches.length ? matches : void 0;
		};
	}
	/**
	* Dependency analysis for dummies, this is a high level api to simplify the usage of astMatcher
	* @param arguments Multiple patterns to match, instead of using __str_/__arr_,
	*        use __dep and __deps to match string and partial string array.
	* @return Returns a function that takes source code string (or estree syntax tree) as input, produces an array of string matched, or empty array.
	*
	* Usage:
	*   let f = depFinder('a(__dep)', '__any.globalResources([__deps])');
	*   f('a("a"); a("b"); config.globalResources(["./c", "./d"])');
	*
	*   => ['a', 'b', './c', './d']
	*/
	function depFinder() {
		if (arguments.length === 0) throw new Error("No patterns provided.");
		let seed = 0;
		let patterns = Array.prototype.map.call(arguments, function(p) {
			return compilePattern(p.replace(/__dep(s?)/g, function(m, wantArr) {
				return (wantArr ? "__arr_" : "__str_") + ++seed;
			}));
		});
		let len = patterns.length;
		return function(jsStr) {
			let node = ensureParsed(jsStr);
			let deps = [];
			traverse(node, function(n) {
				for (let i = 0; i < len; i += 1) {
					let result = extract(patterns[i], n);
					if (result) {
						Object.keys(result).forEach(function(k) {
							let d = result[k];
							if (typeof d === "string") deps.push(d);
							else deps.push.apply(deps, d);
						});
						break;
					}
				}
			});
			return deps;
		};
	}
	module.exports = astMatcher;
	module.exports.setParser = setParser;
	module.exports.ensureParsed = ensureParsed;
	module.exports.extract = extract;
	module.exports.compilePattern = compilePattern;
	module.exports.depFinder = depFinder;
	module.exports.STOP = STOP;
	module.exports.SKIP_BRANCH = SKIP_BRANCH;
	module.exports.traverse = traverse;
})))(), 1);
function escapeStringRegexp(string) {
	if (typeof string !== "string") throw new TypeError("Expected a string");
	return string.replace(/[|\\{}()[\]^$+*?.]/g, "\\$&").replace(/-/g, "\\x2d");
}
function markEdited(node, edits) {
	for (const [start, end] of edits) if (start <= node.start && node.start < end || start < node.end && node.end <= end) return false;
	return edits.push([node.start, node.end]);
}
const SUPPORTED_FILES = [
	"js",
	"ts",
	"mjs",
	"mts",
	"cjs",
	"cts",
	"jsx",
	"tsx",
	"vue",
	"svelte"
];
function getVueUnrefPattern(key) {
	const dotIdx = key.indexOf(".");
	if (dotIdx === -1) return void 0;
	return `_unref(${key.slice(0, dotIdx)})${key.slice(dotIdx)}`;
}
function createReplacerTransformFn(opts) {
	const keys = Object.keys(opts.replacements);
	let matchers;
	const extraMatchersForFileType = {};
	const findAnyReplacementPatterns = keys.flatMap((key) => {
		const unrefPattern = getVueUnrefPattern(key);
		return unrefPattern ? [key, unrefPattern] : [key];
	});
	const findAnyReplacementRegex = new RegExp(`(?:${findAnyReplacementPatterns.map(escapeStringRegexp).join("|")})`, "g");
	return function transform(parserCtx, code, id) {
		if (keys.length === 0) return null;
		const fileExt = id.split("?")[0].split("#")[0].split(".").pop() || "";
		if (!SUPPORTED_FILES.includes(fileExt)) return null;
		if (code.search(findAnyReplacementRegex) === -1) return null;
		const parse = (codeToParse, source = code) => {
			try {
				return parserCtx.parse(codeToParse, void 0);
			} catch (error) {
				error.message += ` in ${source}`;
				throw error;
			}
		};
		const ast = parse(code, id);
		matchers ||= keys.map((key) => ({
			matcher: (0, import_ast_matcher.default)(parse(key)),
			replacement: opts.replacements[key]
		}));
		if (fileExt === "vue") extraMatchersForFileType.vue ||= keys.flatMap((key) => {
			const unrefPattern = getVueUnrefPattern(key);
			return [`$setup.${key}`, ...unrefPattern ? [unrefPattern] : []].map((pattern) => ({
				matcher: (0, import_ast_matcher.default)(parse(pattern)),
				replacement: opts.replacements[key]
			}));
		});
		const magicString = new MagicString(code);
		const edits = [];
		Object.values([...matchers, ...extraMatchersForFileType[fileExt] || []]).forEach(({ matcher, replacement }) => {
			for (const { node } of matcher(ast) || []) if (markEdited(node, edits)) magicString.overwrite(node.start, node.end, replacement);
		});
		if (edits.length === 0) return null;
		return magicString;
	};
}
const ANSI_COLORS = {
	30: "#45475a",
	31: "#f38ba8",
	32: "#a6e3a1",
	33: "#f9e2af",
	34: "#89b4fa",
	35: "#f5c2e7",
	36: "#94e2d5",
	37: "#cdd6f4",
	90: "#585b70",
	91: "#f38ba8",
	92: "#a6e3a1",
	93: "#f9e2af",
	94: "#89b4fa",
	95: "#f5c2e7",
	96: "#94e2d5",
	97: "#cdd6f4"
};
const ANSI_RE = new RegExp(`${String.fromCharCode(27)}\\[([0-9;]*)m`, "g");
/**
* Convert a string with ANSI escape codes to HTML with inline styles.
* Uses a "close all, re-open with active styles" approach so that
* nested/overlapping ANSI sequences render correctly.
*/
function ansiToHtml(str) {
	let bold = false;
	let dim = false;
	let italic = false;
	let underline = false;
	let strikethrough = false;
	let color;
	let isOpen = false;
	function buildSpan() {
		const styles = [];
		if (bold) styles.push("font-weight:bold");
		if (dim) styles.push("opacity:0.6");
		if (italic) styles.push("font-style:italic");
		if (underline) styles.push("text-decoration:underline");
		if (strikethrough) styles.push("text-decoration:line-through");
		if (color) styles.push(`color:${color}`);
		if (!styles.length) return "";
		isOpen = true;
		return `<span style="${styles.join(";")}">`;
	}
	function closeIfOpen() {
		if (!isOpen) return "";
		isOpen = false;
		return "</span>";
	}
	let html = str.replace(/&/g, "&amp;").replace(/</g, "&lt;").replace(/>/g, "&gt;");
	html = html.replace(ANSI_RE, (_, codes) => {
		const parts = codes.split(";").filter(Boolean).map(Number);
		if (parts.length === 0 || parts.includes(0)) {
			bold = false;
			dim = false;
			italic = false;
			underline = false;
			strikethrough = false;
			color = void 0;
			return closeIfOpen();
		}
		const close = closeIfOpen();
		for (const code of parts) if (code === 1) bold = true;
		else if (code === 2) dim = true;
		else if (code === 3) italic = true;
		else if (code === 4) underline = true;
		else if (code === 9) strikethrough = true;
		else if (code === 22) {
			bold = false;
			dim = false;
		} else if (code === 23) italic = false;
		else if (code === 24) underline = false;
		else if (code === 29) strikethrough = false;
		else if (code === 39) color = void 0;
		else if (ANSI_COLORS[code]) color = ANSI_COLORS[code];
		return close + buildSpan();
	});
	html += closeIfOpen();
	return html;
}
function buildErrorPageHtml(ansiError) {
	return `<!DOCTYPE html>
<html><head><title>varlock - config error</title></head>
<body style="font-family: monospace; background: #1e1e2e; color: #cdd6f4; margin: 0; padding: 2rem;">
<div style="margin-bottom: 1.5rem;">
  <h2 style="color: #f38ba8; margin: 0 0 0.5rem 0;">🔒 Varlock — env config validation failed</h2>
  <p style="color: #6c7086; margin: 0;">Your environment variables are loaded and validated by <a href="https://varlock.dev" style="color: #89b4fa;">varlock</a>. Fix the error(s) below and save to reload.</p>
</div>
<pre style="white-space: pre-wrap; word-wrap: break-word; line-height: 1.5; background: #181825; padding: 1rem; border-radius: 8px;">${ansiError ? ansiToHtml(ansiError) : "Config is invalid — check your terminal for details."}</pre>
</body></html>`;
}
globalThis.__varlockThrowOnMissingKeys = true;
const originalProcessEnv = { ...process.env };
const debug$1 = createDebug("varlock:vite-integration");
debug$1("varlock vite plugin loaded");
let isDevCommand;
let configIsValid = true;
let varlockLoadedEnv;
/** Stderr output from the last failed varlock load (ANSI-colored) */
let varlockLastError;
let lastErrorAt = 0;
let configHookCalled = false;
let cfDetectNoticeLogged = false;
let vercelUnencryptedWarningLogged = false;
let staticReplacements = {};
let publicDynamicKeys = [];
let replacerFn;
function resetStaticReplacements() {
	staticReplacements = {};
	publicDynamicKeys = [];
	for (const itemKey in varlockLoadedEnv?.config) {
		const itemInfo = varlockLoadedEnv.config[itemKey];
		const isDynamic = itemInfo.isDynamic ?? itemInfo.isSensitive;
		if (isDynamic && !itemInfo.isSensitive) publicDynamicKeys.push(itemKey);
		if (!isDynamic) {
			const val = itemInfo.value === void 0 ? "undefined" : JSON.stringify(itemInfo.value);
			staticReplacements[`ENV.${itemKey}`] = val;
		}
	}
	globalThis.__varlockPublicDynamicKeys = publicDynamicKeys;
	debug$1("static replacements", staticReplacements);
	replacerFn = createReplacerTransformFn({ replacements: staticReplacements });
}
function isExistingNonRegularFile(filePath) {
	try {
		return !fs.statSync(filePath).isFile();
	} catch {
		return false;
	}
}
const warnedNonRegularSources = /* @__PURE__ */ new Set();
function warnNonRegularSourceOnce(absPath, basePath) {
	if (warnedNonRegularSources.has(absPath)) return;
	warnedNonRegularSources.add(absPath);
	const displayPath = basePath ? path.relative(basePath, absPath) || absPath : absPath;
	console.log(`â„šī¸ [varlock] ${displayPath} is not a regular file (FIFO/pipe), live reload is disabled for it`);
}
let loadCount = 0;
let activeIntegrationTelemetry = {
	name: "@varlock/vite-integration",
	version: "1.5.0"
};
/**
* Directory the current config was loaded from. Tracked so callers can ask for
* a specific root and only pay for a reload when it actually differs — the
* module-level load below uses `process.cwd()`, which is not the project root
* when a framework CLI is pointed elsewhere (e.g. `nuxt build --cwd ./app`).
*/
let loadedConfigDir;
function reloadConfig(cwd) {
	debug$1("loading config - count =", ++loadCount, cwd ? `(cwd: ${cwd})` : "");
	const prevItemCount = Object.keys(varlockLoadedEnv?.config || {}).length;
	loadedConfigDir = path.resolve(cwd ?? process.cwd());
	try {
		const { stdout } = execSyncVarlock("load --format json-full --compact", {
			fullResult: true,
			env: originalProcessEnv,
			integrationTelemetry: activeIntegrationTelemetry,
			...cwd && { cwd }
		});
		process.env.__VARLOCK_ENV = stdout;
		varlockLoadedEnv = JSON.parse(stdout);
		varlockLastError = void 0;
		lastErrorAt = 0;
		configIsValid = true;
	} catch (err) {
		if (err instanceof VarlockExecError) {
			if (err.stdout) try {
				varlockLoadedEnv = JSON.parse(err.stdout);
				process.env.__VARLOCK_ENV = err.stdout;
			} catch {}
			if (err.stderr) {
				const now = Date.now();
				const isDuplicate = err.stderr === varlockLastError && now - lastErrorAt < 5e3;
				varlockLastError = err.stderr;
				lastErrorAt = now;
				if (!isDuplicate) {
					console.error(err.stderr);
					console.error("\n[varlock] âš ī¸ config is invalid — fix the error(s) above to continue\n");
				}
			}
		}
		configIsValid = false;
		resetStaticReplacements();
		return;
	}
	if (cwd && prevItemCount > 0 && Object.keys(varlockLoadedEnv?.config || {}).length === 0) console.warn(`\x1b[33m[varlock] âš ī¸  no env items found when loading from ${cwd}\x1b[0m\nThis directory has no \`.env.schema\`, so \`ENV.*\` references will not be replaced at build time.
If your framework points vite's \`root\` at a source subdirectory, the integration should pass \`rootDir\` to \`varlockVitePlugin()\`.`);
	if (globalThis.__varlockLoadedEnv) globalThis.__varlockLoadedEnv = varlockLoadedEnv;
	initVarlockEnv();
	patchGlobalConsole();
	patchGlobalServerResponse();
	patchGlobalResponse();
	resetStaticReplacements();
}
reloadConfig();
/**
* Builds the varlock init module source — the code that initializes `ENV` and
* patches the global console/response objects before any user code runs.
*
* Exported so integrations can inject the same init sequence into build
* pipelines that vite does not own. `@varlock/nuxt-integration` uses it for the Nitro
* server bundle, which rollup builds separately from vite's SSR output.
*/
function buildVarlockSsrInitCode(opts = {}) {
	if (opts.rootDir && path.resolve(opts.rootDir) !== loadedConfigDir) reloadConfig(opts.rootDir);
	let ssrInjectMode = opts.ssrInjectMode ?? "init-only";
	const isCloudflareTarget = opts.isCloudflareTarget ?? false;
	const isDev = opts.isDev ?? isDevCommand;
	const isCfPrerenderEnv = isCloudflareTarget && opts.environmentName === "prerender" && !isDev;
	if (isCfPrerenderEnv) ssrInjectMode = "resolved-env";
	const isEdgeRuntime = opts.ssrEdgeRuntime ?? false;
	const lines = [
		"// Virtual module generated by @varlock/vite-integration",
		"// Runs before any user code to ensure ENV is available at module top-level",
		"globalThis.__varlockThrowOnMissingKeys = true;",
		`globalThis.__varlockPublicDynamicKeys = ${JSON.stringify(publicDynamicKeys)};`
	];
	const encryptionRequired = varlockLoadedEnv?.settings?.encryptInjectedEnv;
	let encryptionKey = isCfPrerenderEnv ? void 0 : process.env._VARLOCK_ENV_KEY;
	if (ssrInjectMode === "auto-load") {
		if (opts.preserveSideEffectImports) lines.push("import * as __varlockAutoLoad from 'varlock/auto-load';", "globalThis.__varlockAutoLoadModule = __varlockAutoLoad;");
		else lines.push("import 'varlock/auto-load';");
	} else {
		if (ssrInjectMode === "resolved-env") {
			if (isCloudflareTarget && !isDev && !isCfPrerenderEnv) throw new Error("[varlock] ssrInjectMode: 'resolved-env' is redundant on Cloudflare Workers and ships resolved (possibly sensitive) values into the worker bundle unnecessarily. Cloudflare deploys get their env injected at runtime from bindings via `varlock-wrangler` — remove the `ssrInjectMode` override (or set it to 'init-only') and let the Cloudflare integration handle it.\nSee https://varlock.dev/integrations/cloudflare/ for details.");
			if (process.env.VERCEL === "1" && !encryptionRequired && !isDev) {
				if (!vercelUnencryptedWarningLogged) {
					vercelUnencryptedWarningLogged = true;
					console.warn("\x1B[33m[varlock] âš ī¸ ssrInjectMode: 'resolved-env' on Vercel ships your resolved env as plaintext JSON in the build artifact. Consider enabling `@encryptInjectedEnv` — see https://varlock.dev/guides/encrypted-deployments/\x1B[0m");
				}
			}
			if (encryptionRequired && !encryptionKey && !isCfPrerenderEnv) {
				if (isDev) {
					encryptionKey = generateEncryptionKeyHex();
					process.env._VARLOCK_ENV_KEY = encryptionKey;
				} else throw new Error("[varlock] @encryptInjectedEnv is enabled but _VARLOCK_ENV_KEY is not set.\nGenerate a key with `varlock generate-key` and set it on your platform.\nSee https://varlock.dev/guides/encrypted-deployments/ for details.");
			}
			const serialized = JSON.stringify(varlockLoadedEnv);
			if (encryptionKey) {
				const encrypted = encryptEnvBlobSync(serialized, encryptionKey);
				lines.push(`globalThis.__varlockEncryptedEnv = ${JSON.stringify(encrypted)};`);
			} else lines.push(`globalThis.__varlockLoadedEnv = ${JSON.stringify(varlockLoadedEnv)};`);
		}
		if (opts.ssrEntryCode?.length && !isCfPrerenderEnv) lines.push(...opts.ssrEntryCode);
		lines.push("import { initVarlockEnv } from 'varlock/env';", "import { patchGlobalConsole } from 'varlock/patch-console';", "import { patchGlobalResponse } from 'varlock/patch-response';");
		lines.push("import { decryptEnvBlobSync } from 'varlock/encrypt-env';", "if (globalThis.__varlockEncryptedEnv) {", "  const __key = typeof process !== 'undefined' && process.env._VARLOCK_ENV_KEY;", "  if (!__key) throw new Error('[varlock] encrypted env blob present but _VARLOCK_ENV_KEY is not set');", "  globalThis.__varlockLoadedEnv = JSON.parse(decryptEnvBlobSync(globalThis.__varlockEncryptedEnv, __key));", "  delete globalThis.__varlockEncryptedEnv;", "}");
		if (!isEdgeRuntime) lines.push("import { patchGlobalServerResponse } from 'varlock/patch-server-response';");
		lines.push("initVarlockEnv();", "patchGlobalConsole();");
		if (!isEdgeRuntime) lines.push("patchGlobalServerResponse();");
		lines.push("patchGlobalResponse();");
	}
	return lines.join("\n");
}
const VARLOCK_INIT_MODULE_ID = "\0varlock-ssr-init";
function varlockVitePlugin(vitePluginOptions) {
	if (vitePluginOptions?.integrationTelemetry) {
		const prevName = activeIntegrationTelemetry.name;
		activeIntegrationTelemetry = vitePluginOptions.integrationTelemetry;
		if (prevName !== activeIntegrationTelemetry.name) reloadConfig(vitePluginOptions.rootDir ?? loadedConfigDir);
	}
	let resolvedSsrEdgeRuntime = vitePluginOptions?.ssrEdgeRuntime ?? false;
	let resolvedSsrEntryCode = vitePluginOptions?.ssrEntryCode;
	let resolvedIsCloudflareTarget = vitePluginOptions?.isCloudflareTarget ?? false;
	function buildInitModuleCode(environmentName) {
		return buildVarlockSsrInitCode({
			ssrInjectMode: vitePluginOptions?.ssrInjectMode,
			ssrEntryCode: resolvedSsrEntryCode,
			ssrEdgeRuntime: resolvedSsrEdgeRuntime,
			isCloudflareTarget: resolvedIsCloudflareTarget,
			environmentName
		});
	}
	async function detectSvelteKitCloudflareTarget(config) {
		if (resolvedSsrEntryCode) return;
		const sveltekitSetup = config.plugins?.find((p) => p?.api?.options?.kit?.adapter);
		if (!sveltekitSetup) return;
		const adapterName = sveltekitSetup.api.options.kit.adapter?.name;
		if (!(adapterName === "@sveltejs/adapter-cloudflare" || adapterName === "@sveltejs/adapter-auto" && !!(process.env.CF_PAGES || process.env.WORKERS_CI))) return;
		try {
			const { CLOUDFLARE_SSR_ENTRY_CODE } = await import("@varlock/cloudflare-integration/ssr-entry-code");
			resolvedSsrEntryCode = [CLOUDFLARE_SSR_ENTRY_CODE];
			resolvedSsrEdgeRuntime = true;
			resolvedIsCloudflareTarget = true;
			debug$1("detected SvelteKit + Cloudflare adapter — injecting edge env loader");
			if (!cfDetectNoticeLogged) {
				cfDetectNoticeLogged = true;
				console.log("\x1B[36m🔒 [varlock] detected @sveltejs/adapter-cloudflare — injecting the Cloudflare Workers env loader into the SSR entry\x1B[0m");
			}
		} catch {
			throw new Error("[varlock] SvelteKit deploying to Cloudflare requires @varlock/cloudflare-integration.\nInstall it alongside @varlock/vite-integration: npm install @varlock/cloudflare-integration");
		}
	}
	return {
		name: "inject-varlock-config",
		enforce: "post",
		resolveId(id) {
			if (id === VARLOCK_INIT_MODULE_ID) return id;
		},
		load(id) {
			if (id === VARLOCK_INIT_MODULE_ID) return buildInitModuleCode(this.environment?.name);
		},
		async config(config, env) {
			debug$1("vite plugin - config fn called, loadCount =", loadCount, "command =", env.command);
			if (config.envDir) console.warn(`
[varlock] âš ī¸  The \`envDir\` Vite option is not supported by varlock.
To load .env files from a custom directory, set \`varlock.loadPath\` in your \`package.json\`:

  {
    "varlock": {
      "loadPath": "./your-env-dir/"
    }
  }

See https://varlock.dev/integrations/vite/ for more details.
`);
			isDevCommand = env.command === "serve";
			if (env.command === "build") process.env.__VARLOCK_EXECUTION_PHASE = "build";
			else delete process.env.__VARLOCK_EXECUTION_PHASE;
			const rootDirSource = vitePluginOptions?.rootDir ?? config.root;
			const projectRoot = rootDirSource ? path.resolve(rootDirSource) : void 0;
			if (!!(projectRoot && projectRoot !== loadedConfigDir)) reloadConfig(projectRoot);
			else if (!configHookCalled) configHookCalled = true;
			else if (isDevCommand) reloadConfig(projectRoot ?? loadedConfigDir);
			const hasCfPlugin = config.plugins?.flat().some((p) => p?.name?.includes("cloudflare"));
			if (!configIsValid) {
				if (isDevCommand) config.clearScreen = false;
				else {
					console.error("\n[varlock] config is invalid — cannot proceed with build\n");
					process.exit(1);
				}
			}
			if (!hasCfPlugin) return { build: { rollupOptions: { external: ["cloudflare:workers"] } } };
		},
		async configResolved(config) {
			debug$1("vite plugin - configResolved fn called");
			await detectSvelteKitCloudflareTarget(config);
			if (!varlockLoadedEnv) return;
			for (const varlockSource of varlockLoadedEnv.sources) {
				if (!varlockSource.enabled) continue;
				if (varlockLoadedEnv.basePath && varlockSource.path) {
					const absPath = path.resolve(varlockLoadedEnv.basePath, varlockSource.path);
					if (isExistingNonRegularFile(absPath)) {
						warnNonRegularSourceOnce(absPath, varlockLoadedEnv.basePath);
						continue;
					}
					config.configFileDependencies.push(absPath);
				}
			}
		},
		async configureServer(server) {
			debug$1("vite plugin - configureServer fn called");
			server.middlewares.use((req, res, next) => {
				if (configIsValid) return next();
				if (req.url?.startsWith("/@")) return next();
				res.statusCode = 500;
				res.setHeader("Content-Type", "text/html; charset=utf-8");
				res.end(buildErrorPageHtml(varlockLastError));
			});
		},
		transform(code, id, options) {
			let magicString = replacerFn(this, code, id);
			const isDevEnv = this.environment ? this.environment.mode === "dev" : isDevCommand;
			const fileExt = id.split("?")[0].split("#")[0].split(".").pop() || "";
			let isEntry = false;
			if (SUPPORTED_FILES.includes(fileExt)) {
				try {
					if (this.getModuleInfo(id)?.isEntry) isEntry = true;
				} catch {}
				if (!isEntry && isDevEnv) {
					if (Array.from(this.getModuleIds())[0] === id) isEntry = true;
				}
			}
			if (vitePluginOptions?.ssrEntryModuleIds?.includes(id)) isEntry = true;
			if (isEntry) {
				debug$1(`detected entry: ${id}`);
				const injectCode = ["// INJECTED BY @varlock/vite-integration ----"];
				if (options?.ssr) injectCode.push(`import '${VARLOCK_INIT_MODULE_ID}';`);
				else {
					injectCode.push("globalThis.__varlockThrowOnMissingKeys = true;");
					if (isDevEnv) injectCode.push(`globalThis.__varlockValidKeys = ${JSON.stringify(Object.keys(varlockLoadedEnv?.config || {}))};`);
					injectCode.push(`globalThis.__varlockPublicDynamicKeys = ${JSON.stringify(publicDynamicKeys)};`);
				}
				injectCode.push("// -------- ");
				magicString ||= new MagicString(code);
				magicString.prepend(`${injectCode.join("\n")}\n`);
			}
			if (!magicString) return null;
			return {
				code: magicString.toString(),
				map: magicString.generateMap({
					source: code,
					includeContent: true,
					hires: true
				})
			};
		},
		renderChunk(code, chunk) {
			const magicString = replacerFn(this, code, chunk.fileName);
			if (!magicString) return null;
			return {
				code: magicString.toString(),
				map: magicString.generateMap({
					source: code,
					includeContent: true,
					hires: true
				})
			};
		},
		transformIndexHtml(html) {
			debug$1("transformIndexHtml called, configIsValid =", configIsValid);
			if (!configIsValid) return buildErrorPageHtml(varlockLastError);
			//! Note on vite's built-in html constant replacement
			return html.replace(/%ENV\.([a-zA-Z_][a-zA-Z0-9._]*)%/g, (_fullMatch, itemKey) => {
				if (!varlockLoadedEnv.config[itemKey]) throw new Error(`Config item \`${itemKey}\` does not exist`);
				else if (varlockLoadedEnv.config[itemKey].isSensitive) throw new Error(`Config item \`${itemKey}\` is sensitive and cannot be used in html replacements`);
				else if (varlockLoadedEnv.config[itemKey].isDynamic) throw new Error(`Config item \`${itemKey}\` is dynamic (runtime-resolved) and cannot be used in html replacements`);
				else return varlockLoadedEnv.config[itemKey].value ?? "";
			});
		}
	};
}
//#endregion
//#region src/index.ts
const debug = createDebug("varlock:astro-integration");
const DEFAULT_PUBLIC_DYNAMIC_ENDPOINT = "/__varlock/public-env";
const PUBLIC_DYNAMIC_ROUTE_ENTRYPOINT = fileURLToPath(new URL("./public-dynamic-env-route.mjs", import.meta.url));
debug("Loaded varlock astro integration file");
function hasPublicDynamicConfigInSchema(cwd) {
	try {
		const { stdout } = execSyncVarlock("load --format json-full --compact", {
			fullResult: true,
			...cwd && { cwd }
		});
		const loadedEnv = JSON.parse(stdout);
		return Object.values(loadedEnv.config || {}).some((itemInfo) => (itemInfo.isDynamic ?? itemInfo.isSensitive) && !itemInfo.isSensitive);
	} catch (err) {
		debug("Failed to auto-detect public+dynamic config, skipping endpoint injection", err);
		return false;
	}
}
function shouldInjectPublicDynamicEndpoint(option, cwd) {
	if (option === false) return false;
	if (option === true || typeof option === "object") return true;
	return hasPublicDynamicConfigInSchema(cwd);
}
function resolvePublicDynamicEndpointPath(option, cwd) {
	if (!shouldInjectPublicDynamicEndpoint(option, cwd)) return null;
	const configuredPath = typeof option === "object" && option.path || DEFAULT_PUBLIC_DYNAMIC_ENDPOINT;
	if (!configuredPath.startsWith("/")) throw new Error("[varlock] `publicDynamicEndpoint.path` must start with \"/\"");
	return configuredPath;
}
function varlockAstroIntegration(integrationOptions) {
	const { publicDynamicEndpoint } = integrationOptions ?? {};
	let command = "build";
	return {
		name: "varlock-astro-integration",
		hooks: {
			"astro:config:setup": (opts) => {
				command = opts.command;
				const routePath = resolvePublicDynamicEndpointPath(publicDynamicEndpoint, fileURLToPath(opts.config.root));
				if (!routePath) return;
				if (!(publicDynamicEndpoint === true || typeof publicDynamicEndpoint === "object") && opts.command === "build" && opts.config.output !== "server") {
					debug(`Skipping "${routePath}" injection for static build output. Set output="server" or pass publicDynamicEndpoint=true (requires an adapter) to enable the public dynamic env route.`);
					return;
				}
				opts.injectRoute({
					pattern: routePath,
					entrypoint: PUBLIC_DYNAMIC_ROUTE_ENTRYPOINT,
					prerender: false
				});
			},
			"astro:config:done": async (opts) => {
				const adapterName = opts.config.adapter?.name;
				let ssrInjectMode = integrationOptions?.ssrInjectMode;
				const { publicDynamicEndpoint: _publicDynamicEndpoint, ...vitePluginBaseOptions } = integrationOptions ?? {};
				let vitePluginOptions = { ...vitePluginBaseOptions };
				if (["@astrojs/netlify", "@astrojs/vercel"].includes(adapterName || "")) ssrInjectMode ??= "resolved-env";
				else if (adapterName === "@astrojs/node") ssrInjectMode ??= "auto-load";
				if (adapterName === "@astrojs/cloudflare") {
					if (command === "dev") ssrInjectMode ??= "resolved-env";
					let cloudflareSsrEntryCode;
					let logVarlockEnvInjectionNotice;
					try {
						const cfIntegration = await import("@varlock/cloudflare-integration/ssr-entry-code");
						({CLOUDFLARE_SSR_ENTRY_CODE: cloudflareSsrEntryCode, logVarlockEnvInjectionNotice} = cfIntegration);
						cfIntegration.disableWranglerDotEnvAutoload();
					} catch {
						throw new Error("[varlock] Using @astrojs/cloudflare requires @varlock/cloudflare-integration.\nInstall it alongside @varlock/astro-integration: npm install @varlock/cloudflare-integration");
					}
					vitePluginOptions = {
						...vitePluginOptions,
						ssrInjectMode,
						ssrEdgeRuntime: vitePluginOptions.ssrEdgeRuntime ?? true,
						ssrEntryModuleIds: [...vitePluginOptions.ssrEntryModuleIds ?? [], "\0virtual:cloudflare/worker-entry"],
						ssrEntryCode: vitePluginOptions.ssrEntryCode ?? [cloudflareSsrEntryCode],
						isCloudflareTarget: true
					};
					opts.config.vite.plugins ||= [];
					opts.config.vite.plugins.push({
						name: "varlock-cloudflare-env-notice",
						configureServer() {
							logVarlockEnvInjectionNotice();
						},
						configurePreviewServer() {
							logVarlockEnvInjectionNotice();
						}
					});
				} else vitePluginOptions = {
					...vitePluginOptions,
					ssrInjectMode
				};
				opts.config.vite.plugins ||= [];
				opts.config.vite?.plugins?.push(varlockVitePlugin({
					...vitePluginOptions,
					integrationTelemetry: integrationOptions?.integrationTelemetry ?? {
						name: "@varlock/astro-integration",
						version: "1.4.0"
					}
				}));
			},
			"astro:build:done": async ({ dir }) => {
				if (varlockSettings.preventLeaks === false) return;
				const outDir = fileURLToPath(dir);
				debug("scanning build output for leaks in", outDir);
				const leakedFiles = [];
				for await (const file of fs.promises.glob(`${outDir}/**/*.html`)) {
					const fileContents = await fs.promises.readFile(file, "utf8");
					try {
						scanForLeaks(fileContents, {
							method: "astro post-build scan",
							file
						});
					} catch (_err) {
						leakedFiles.push(file);
					}
				}
				if (leakedFiles.length > 0) throw new Error(`Build aborted: ${leakedFiles.length} file(s) contain leaked sensitive config`);
			}
		}
	};
}
//#endregion
export { varlockAstroIntegration as default };

//# sourceMappingURL=index.mjs.map