How CFnew Proxies VLESS, Trojan, and xhttp Protocols: Cloudflare Workers Implementation
CFnew proxies VLESS over WebSocket, Trojan over TLS, and xhttp over HTTP POST disguised as gRPC, generating subscription-compatible nodes via query parameters like ev, et, and ex parsed from the 明文源吗 source file.
CFnew is an open-source Cloudflare Workers proxy that dynamically generates subscription configurations for multiple client formats. Hosted at byJoey/cfnew, the tool inspects incoming HTTP requests at the /{uuid} endpoint, upgrades connections based on protocol-specific transport mechanisms, and forwards traffic to target destinations while masking it as standard web traffic.
VLESS WebSocket Implementation
CFnew implements VLESS using the Cloudflare Workers WebSocket upgrade mechanism. When a client connects to the generated subscription endpoint, the worker receives an incoming HTTP request and upgrades it to a persistent WebSocket connection, forwarding traffic through Cloudflare’s edge network.
The implementation reuses the native fetch API with the webSocket option to establish the tunnel. In the source code located at 明文源吗 lines 1539-1542, CFnew parses the VLESS share link and constructs the node configuration by injecting protocol-specific fields including id, security, and type=ws.
Key configuration options for VLESS include:
ev=yes– Enables the VLESS protocol (defaults to enabled).p– Specifies a custom proxy IP address and port (e.g.,p=1.2.3.4:443).path– Allows per-node parameters embedded in the URL path.
Trojan TLS Proxy Configuration
CFnew treats Trojan as a TLS-only stream authenticated via SHA-224 password hashing. When the et=yes parameter is present, the worker initiates a TLS connection to the destination server and injects the authentication token—either the user-provided tp variable or the UUID by default.
The parsing logic for Trojan links resides alongside the VLESS handler in 明文源吗 around lines 1539-1542, marked by the comment “解析 Trojan 链接”. This block extracts the password and builds the Clash-compatible node entry with security=tls enforced.
Configuration flags for Trojan:
et=yes– Activates Trojan protocol support.tp– Defines a custom Trojan password; if omitted, CFnew uses the UUID as the fallback credential.
xhttp HTTP POST Disguise
The xhttp protocol in CFnew functions as a pseudo-protocol that camouflages proxy traffic as ordinary HTTP POST requests. Rather than using a standard WebSocket, CFnew creates a gRPC-based worker endpoint where the client transmits POST data to a custom domain, and the worker forwards the payload to the remote target.
According to the README documentation referenced at line 3771 of 明文源吗, xhttp requires a bound custom domain and explicit gRPC activation in the worker settings to function correctly. This transport method is particularly effective for evading deep packet inspection by mimicking standard HTTPS POST traffic patterns.
Required configuration:
ex=yes– Enables the xhttp protocol.- Custom domain – Must be bound to the Cloudflare Workers instance.
- gRPC switch – Must be activated in the worker deployment settings.
Protocol Configuration Syntax
CFnew reads protocol selection and customization variables from URL query parameters or KV storage. You can enable multiple protocols simultaneously, and the worker will generate separate node entries for each enabled protocol in the subscription output.
To activate all three protocols with custom parameters:
https://your-worker.workers.dev/<UUID>?ev=yes&et=yes&ex=yes&tp=mySecretPassword&p=1.2.3.4:443
For single-protocol deployments:
- VLESS only:
https://your-worker.workers.dev/<UUID>?ev=yes - Trojan only:
https://your-worker.workers.dev/<UUID>?et=yes(uses UUID as password) - xhttp only:
https://your-worker.workers.dev/<UUID>?ex=yes&domain=proxy.example.com
The resulting subscription outputs follow standard URI formats:
vless://<UUID>@<worker-host>/path?encryption=none&security=none&type=ws&host=example.com#Node-VLESS-WS
trojan://<password>@<worker-host>/path?security=tls#Node-Trojan-TLS
http://<worker-host>/xhttp?host=example.com#Node-xhttp-POST
Source Code Architecture
The proxy flow is implemented across several key files in the byJoey/cfnew repository:
明文源吗– Contains the obfuscated runtime logic at lines 1539-1542 for parsing VLESS and Trojan links, and lines 3769-3772 for theprotocolHintUI block that renders configuration toggles.wrangler.toml– Defines the Cloudflare Workers environment, binding the KV namespaceCand setting compatibility dates.README.md– Documents the requirement for custom domains when using xhttp (line 3771) and describes transport optimizations like GrainTCP-style packet aggregation (lines 41-42).
Summary
- VLESS is proxied via WebSocket upgrade using the Cloudflare
fetchAPI with WebSocket options, configurable via theevflag. - Trojan utilizes TLS-only streams with SHA-224 password authentication, controlled by the
etandtpparameters. - xhttp disguises traffic as HTTP POST requests over a gRPC-based endpoint, requiring
ex=yes, a custom domain, and gRPC activation. - All protocol parsers reside in
明文源吗(lines 1539-1542), generating subscription nodes for Clash, Surge, and Sing-Box clients.
Frequently Asked Questions
How does CFnew differ from traditional VLESS/Trojan servers?
CFnew operates serverlessly on Cloudflare Workers, eliminating the need for dedicated VPS infrastructure. Unlike traditional servers that run persistent Xray or V2Ray cores, CFnew parses share links and upgrades HTTP requests to WebSocket/TLS connections dynamically at the edge, as implemented in the 明文源吗 parsing block.
Why does xhttp require a custom domain while VLESS does not?
The xhttp protocol relies on gRPC-over-HTTP/2 trailers and specific host header validation that conflicts with Cloudflare’s default *.workers.dev certificate constraints. According to the source analysis at line 3771, binding a custom domain allows CFnew to properly terminate TLS and route the gRPC traffic required for the HTTP POST disguise mechanism.
Can I use multiple protocols simultaneously in one subscription?
Yes. CFnew supports concurrent protocol activation by including multiple enable flags in the URL query string (e.g., ?ev=yes&et=yes). The worker generates distinct node entries for each protocol within the same subscription file, allowing clients to switch between VLESS WebSocket and Trojan TLS transports without redeploying the worker.
Where is the subscription generation logic located in the source code?
The core parsing and node generation logic is located in 明文源吗 between lines 1539-1542, where comments indicate “解析 VLESS 链接并生成 Clash 节点配置” and “解析 Trojan 链接”. This section handles URI parsing, parameter injection, and format conversion for supported client applications.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →