# How VLESS URLs Are Generated in CFnew: A Complete Technical Breakdown

> Learn how CFnew generates VLESS URLs by sanitizing IPs, using URLSearchParams, and appending optional ALPN/ECH for the vless:// scheme. Get a technical breakdown.

- Repository: [byJoey/cfnew](https://github.com/byJoey/cfnew)
- Tags: deep-dive
- Published: 2026-05-23

---

**CFnew dynamically constructs VLESS URLs by sanitizing IP addresses, assembling mandatory parameters via `URLSearchParams`, and appending optional ALPN and ECH configurations before formatting everything into the standard `vless://` scheme.**

The byJoey/cfnew repository generates proxy subscription links directly within its Cloudflare Worker script. Understanding how VLESS URLs are generated in CFnew requires examining the core logic inside `明文源吗`, specifically the `generateXhttpLinksFromSource` function, which transforms raw proxy entries into client-compatible configuration strings.

## Anatomy of a CFnew VLESS URL

CFnew follows the standard VLESS URI specification while adding Cloudflare-specific optimizations. Every generated link conforms to this structure:

```text
vless://<UUID>@<IP>:<PORT>?<QUERY_STRING>#<NODE_ALIAS>

```

The `<QUERY_STRING>` contains URL-encoded parameters including encryption settings, security protocols, and transport-specific paths. As implemented in `明文源吗` around line 7954, this construction ensures compatibility with clients like Loon, Stash, and Shadowrocket.

## Step-by-Step URL Construction Process

The generation logic processes each proxy entry through a sanitization pipeline before final string assembly.

### IP Address Sanitization

Before embedding any address into the URL, CFnew checks for IPv6 formatting. If an IP contains colons (indicating IPv6), the code wraps it in square brackets to ensure RFC-compliant URL formatting:

```javascript
const safeIP = item.ip.includes(':') ? `[${item.ip}]` : item.ip;

```

This sanitization prevents malformed URLs when using IPv6 proxy endpoints.

### Query Parameter Assembly

The core of the generation happens inside `generateXhttpLinksFromSource` where a `URLSearchParams` object is populated with mandatory VLESS parameters:

- **`encryption=none`** – VLESS always uses "none" as it lacks built-in encryption
- **`security=tls`** or **`none`** – determined by port and Cloudflare TLS policy
- **`sni=<workerDomain>`** – the Cloudflare Worker's domain for TLS verification
- **`fp=chrome`** – Client fingerprint set to emulate Chrome
- **`type=ws`** or **`xhttp`** – Transport protocol (WebSocket or HTTP-over-WebSocket)
- **`host=<workerDomain>`** – Host header matching SNI
- **`path` **` – Request path carrying the UUID prefix (e.g., `/${nodePath}` or `/?ed=2048`)
- **`mode=stream-one`** – Specific to XHTTP transport links

These parameters are added using `params.set()` and serialized with `params.toString()` before final insertion.

### Optional Security Enhancements

If the configuration enables Advanced Layer 3 features, CFnew appends additional query items via `applyALPNParam` and manual ECH construction:

**ALPN Configuration:**
When `customALPN` is enabled, the ALPN list is passed directly to `applyALPNParam(params)`.

**ECH (Encrypted Client Hello):**
If `enableECH` is true, the code constructs an ECH parameter combining `customECHDomain` and `customDNS`:

```javascript
if (enableECH) {
    const dnsServer = customDNS || 'https://223.5.5.5/dns-query';
    const echDomain = customECHDomain || 'cloudflare-ech.com';
    params.set('ech', `${echDomain}+${dnsServer}`);
}

```

### Node Naming and Fragment Encoding

Human-readable node names are generated via `createCompactNodeNamer` or a custom `aliasNamer` function passed as an argument. The resulting name is URL-encoded into the fragment (hash) portion of the link:

```javascript
const nodeName = makeNodeName(item);
const encodedName = encodeURIComponent(nodeName);

```

## Source Code Implementation in `明文源吗`

The production logic resides in the `generateXhttpLinksFromSource` function within the main worker script. This implementation handles both WebSocket and XHTTP transports while iterating through proxy lists:

```javascript
function generateXhttpLinksFromSource(list, user, workerDomain, echConfig = null, skipNumbering = false, aliasNamer = null) {
    const links = [];
    const nodePath = user.substring(0, 8);
    const makeNodeName = aliasNamer || createCompactNodeNamer(skipNumbering);
    
    for (const item of list) {
        const safeIP = item.ip.includes(':') ? `[${item.ip}]` : item.ip;
        const port = item.port || 443;
        const wsNodeName = makeNodeName(item);
        
        const params = new URLSearchParams({
            encryption: 'none',
            security: 'tls',
            sni: workerDomain,
            fp: 'chrome',
            type: 'xhttp',
            host: workerDomain,
            path: `/${nodePath}`,
            mode: 'stream-one'
        });
        
        applyALPNParam(params);
        
        if (enableECH) {
            const dnsServer = customDNS || 'https://223.5.5.5/dns-query';
            const echDomain = customECHDomain || 'cloudflare-ech.com';
            params.set('ech', `${echDomain}+${dnsServer}`);
        }
        
        links.push(`vless://${user}@${safeIP}:${port}?${params.toString()}#${encodeURIComponent(wsNodeName)}`);
    }
    
    return links;
}

```

Source: <https://github.com/byJoey/cfnew/blob/main/明文源吗#L7954-L7956>

After generation, the function returns an array of complete VLESS URLs that downstream subscription generators format for specific client applications.

## Summary

- **Primary Location:** VLESS URL generation logic lives in `明文源吗`, specifically within `generateXhttpLinksFromSource` around line 7954
- **IP Handling:** IPv6 addresses are automatically wrapped in square brackets to ensure valid URL formatting
- **Core Parameters:** Every link includes `encryption=none`, `fp=chrome`, `sni`, and transport-specific settings (`ws` or `xhttp`)
- **Optional Features:** ALPN and ECH parameters are conditionally appended when enabled in configuration
- **Output Format:** Standard `vless://UUID@IP:PORT?params#name` format compatible with mainstream proxy clients

## Frequently Asked Questions

### What is the exact file path for VLESS generation logic in CFnew?

The VLESS URL generation logic is contained in **`明文源吗`** (the main Cloudflare Worker script) at approximately line 7954, within the `generateXhttpLinksFromSource` function. This file handles both WebSocket and XHTTP-based VLESS link construction.

### How does CFnew handle IPv6 addresses when generating VLESS URLs?

CFnew detects IPv6 addresses by checking for colons in the IP string. When found, it wraps the address in square brackets (e.g., `[2001:db8::1]`) before inserting it into the URL template. This ensures the resulting VLESS link remains RFC-compliant and parseable by standard client libraries.

### What optional parameters can CFnew add to generated VLESS links?

Beyond the standard VLESS parameters, CFnew conditionally adds **ALPN** (Application-Layer Protocol Negotiation) values via `applyALPNParam` and **ECH** (Encrypted Client Hello) configurations. The ECH parameter combines a domain (defaulting to `cloudflare-ech.com`) with a DNS-over-HTTPS server (defaulting to Alibaba DNS at `223.5.5.5`).

### Why does CFnew use `encryption=none` in all VLESS URLs?

VLESS always uses `encryption=none` because the protocol itself does not implement encryption—security is handled entirely by the underlying transport (typically TLS). This is a specification requirement rather than a configuration choice, ensuring compatibility with the VLESS protocol standard as implemented in tools like Xray-core and V2Ray.