I'm developing an application that contains some some qml files. I followed the qtquickcompiler guide to let the qt quick compiler do it's job in turning qml files into C++ code.
However, even when the qt quick compiler is run, the qml files are also 'baked' in the application executable as application resource. This makes the qml code readable using the strings command.
An example application:
QmlTest.pro:
QT += quick
CONFIG += c++11
CONFIG += qtquickcompiler
SOURCES += \
main.cpp
RESOURCES += qml.qrc
main.cpp:
#include <QGuiApplication>
#include <QQmlApplicationEngine>
int main(int argc, char *argv[])
{
QGuiApplication app(argc, argv);
QQmlApplicationEngine engine;
engine.load(QStringLiteral("qrc:/main.qml"));
return app.exec();
}
qml.qrc:
<RCC>
<qresource prefix="/">
<file>main.qml</file>
</qresource>
</RCC>
main.qml:
import QtQuick 2.15
import QtQuick.Window 2.15
Window {
width: 640
height: 480
visible: true
title: qsTr("Hello World!")
}
Running the command 'strings' on the executable (release mode), results in the following output:
qv4cdata)
5n4{wm
import QtQuick 2.15
import QtQuick.Window 2.15
Window {
width: 640
height: 480
visible: true
title: qsTr("Hello World!")
This makes clear that the QML code can easily be read from the application executable, which is undesirable. How can this be prevented, since the resource is not required at all since it's already compiled by the qt quick compiler.