How VLESS URLs Are Generated in CFnew: A Complete Technical Breakdown
CFnew dynamically constructs VLESS URLs by sanitizing IP addresses, assembling mandatory parameters via URLSearchParams, and appending optional ALPN and ECH configurations before formatting everything into the standard vless:// scheme.
The byJoey/cfnew repository generates proxy subscription links directly within its Cloudflare Worker script. Understanding how VLESS URLs are generated in CFnew requires examining the core logic inside 明文源吗, specifically the generateXhttpLinksFromSource function, which transforms raw proxy entries into client-compatible configuration strings.
Anatomy of a CFnew VLESS URL
CFnew follows the standard VLESS URI specification while adding Cloudflare-specific optimizations. Every generated link conforms to this structure:
vless://<UUID>@<IP>:<PORT>?<QUERY_STRING>#<NODE_ALIAS>
The <QUERY_STRING> contains URL-encoded parameters including encryption settings, security protocols, and transport-specific paths. As implemented in 明文源吗 around line 7954, this construction ensures compatibility with clients like Loon, Stash, and Shadowrocket.
Step-by-Step URL Construction Process
The generation logic processes each proxy entry through a sanitization pipeline before final string assembly.
IP Address Sanitization
Before embedding any address into the URL, CFnew checks for IPv6 formatting. If an IP contains colons (indicating IPv6), the code wraps it in square brackets to ensure RFC-compliant URL formatting:
const safeIP = item.ip.includes(':') ? `[${item.ip}]` : item.ip;
This sanitization prevents malformed URLs when using IPv6 proxy endpoints.
Query Parameter Assembly
The core of the generation happens inside generateXhttpLinksFromSource where a URLSearchParams object is populated with mandatory VLESS parameters:
encryption=none– VLESS always uses "none" as it lacks built-in encryptionsecurity=tlsornone– determined by port and Cloudflare TLS policysni=<workerDomain>– the Cloudflare Worker's domain for TLS verificationfp=chrome– Client fingerprint set to emulate Chrometype=wsorxhttp– Transport protocol (WebSocket or HTTP-over-WebSocket)host=<workerDomain>– Host header matching SNI- **
path**– Request path carrying the UUID prefix (e.g.,/${nodePath}or/?ed=2048`) mode=stream-one– Specific to XHTTP transport links
These parameters are added using params.set() and serialized with params.toString() before final insertion.
Optional Security Enhancements
If the configuration enables Advanced Layer 3 features, CFnew appends additional query items via applyALPNParam and manual ECH construction:
ALPN Configuration:
When customALPN is enabled, the ALPN list is passed directly to applyALPNParam(params).
ECH (Encrypted Client Hello):
If enableECH is true, the code constructs an ECH parameter combining customECHDomain and customDNS:
if (enableECH) {
const dnsServer = customDNS || 'https://223.5.5.5/dns-query';
const echDomain = customECHDomain || 'cloudflare-ech.com';
params.set('ech', `${echDomain}+${dnsServer}`);
}
Node Naming and Fragment Encoding
Human-readable node names are generated via createCompactNodeNamer or a custom aliasNamer function passed as an argument. The resulting name is URL-encoded into the fragment (hash) portion of the link:
const nodeName = makeNodeName(item);
const encodedName = encodeURIComponent(nodeName);
Source Code Implementation in 明文源吗
The production logic resides in the generateXhttpLinksFromSource function within the main worker script. This implementation handles both WebSocket and XHTTP transports while iterating through proxy lists:
function generateXhttpLinksFromSource(list, user, workerDomain, echConfig = null, skipNumbering = false, aliasNamer = null) {
const links = [];
const nodePath = user.substring(0, 8);
const makeNodeName = aliasNamer || createCompactNodeNamer(skipNumbering);
for (const item of list) {
const safeIP = item.ip.includes(':') ? `[${item.ip}]` : item.ip;
const port = item.port || 443;
const wsNodeName = makeNodeName(item);
const params = new URLSearchParams({
encryption: 'none',
security: 'tls',
sni: workerDomain,
fp: 'chrome',
type: 'xhttp',
host: workerDomain,
path: `/${nodePath}`,
mode: 'stream-one'
});
applyALPNParam(params);
if (enableECH) {
const dnsServer = customDNS || 'https://223.5.5.5/dns-query';
const echDomain = customECHDomain || 'cloudflare-ech.com';
params.set('ech', `${echDomain}+${dnsServer}`);
}
links.push(`vless://${user}@${safeIP}:${port}?${params.toString()}#${encodeURIComponent(wsNodeName)}`);
}
return links;
}
Source: https://github.com/byJoey/cfnew/blob/main/明文源吗#L7954-L7956
After generation, the function returns an array of complete VLESS URLs that downstream subscription generators format for specific client applications.
Summary
- Primary Location: VLESS URL generation logic lives in
明文源吗, specifically withingenerateXhttpLinksFromSourcearound line 7954 - IP Handling: IPv6 addresses are automatically wrapped in square brackets to ensure valid URL formatting
- Core Parameters: Every link includes
encryption=none,fp=chrome,sni, and transport-specific settings (wsorxhttp) - Optional Features: ALPN and ECH parameters are conditionally appended when enabled in configuration
- Output Format: Standard
vless://UUID@IP:PORT?params#nameformat compatible with mainstream proxy clients
Frequently Asked Questions
What is the exact file path for VLESS generation logic in CFnew?
The VLESS URL generation logic is contained in 明文源吗 (the main Cloudflare Worker script) at approximately line 7954, within the generateXhttpLinksFromSource function. This file handles both WebSocket and XHTTP-based VLESS link construction.
How does CFnew handle IPv6 addresses when generating VLESS URLs?
CFnew detects IPv6 addresses by checking for colons in the IP string. When found, it wraps the address in square brackets (e.g., [2001:db8::1]) before inserting it into the URL template. This ensures the resulting VLESS link remains RFC-compliant and parseable by standard client libraries.
What optional parameters can CFnew add to generated VLESS links?
Beyond the standard VLESS parameters, CFnew conditionally adds ALPN (Application-Layer Protocol Negotiation) values via applyALPNParam and ECH (Encrypted Client Hello) configurations. The ECH parameter combines a domain (defaulting to cloudflare-ech.com) with a DNS-over-HTTPS server (defaulting to Alibaba DNS at 223.5.5.5).
Why does CFnew use encryption=none in all VLESS URLs?
VLESS always uses encryption=none because the protocol itself does not implement encryption—security is handled entirely by the underlying transport (typically TLS). This is a specification requirement rather than a configuration choice, ensuring compatibility with the VLESS protocol standard as implemented in tools like Xray-core and V2Ray.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →