1
0
mirror of https://github.com/MetaCubeX/mihomo.git synced 2026-10-10 04:03:11 +08:00

feat: add allow-insecure config to anytls/trojan/vless listeners for nginx/caddy front users

This commit is contained in:
wwqgtxx
2026-06-02 10:19:20 +08:00
parent fc8c5a24b1
commit 317bfc206a
10 changed files with 22 additions and 9 deletions
+6 -2
View File
@@ -1904,7 +1904,8 @@ listeners:
after-bytes: 0 # 传输指定字节后开始限速
bytes-per-sec: 0 # 基准速率(字节/秒)
burst-bytes-per-sec: 0 # 突发速率(字节/秒),大于 bytesPerSec 时生效
### 注意,对于vless listener, 至少需要填写 “certificate和private-key” 或 “reality-config” 或 “decryption” 的其中一项 ###
### 注意,对于vless listener, 如果 "allow-insecure" 不为 true, 至少需要填写 “certificate和private-key” 或 “reality-config” 或 “decryption” 的其中一项 ###
# allow-insecure: false # 是否允许不开启tls加密(注意:仅用于有 nginx, caddy 前置的情况)
- name: anytls-in-1
type: anytls
@@ -1926,6 +1927,8 @@ listeners:
# madSJjYQIf9o1N5GXjkW4DEEeb17qMxHdwMdNnwADAABAAEAAQACAAEAAwAIdGVz
# dC5jb20AAA==
# -----END ECH KEYS-----
### 注意,anytls listener, 如果 "allow-insecure" 不为 true, 必须填写 “certificate和private-key” ###
# allow-insecure: false # 是否允许不开启tls加密(注意:仅用于有 nginx, caddy 前置的情况)
# padding-scheme: "" # https://github.com/anytls/anytls-go/blob/main/docs/protocol.md#cmdupdatepaddingscheme
- name: mieru-in-1
@@ -2010,7 +2013,8 @@ listeners:
# enabled: false
# method: aes-128-gcm # aes-128-gcm/aes-256-gcm/chacha20-ietf-poly1305
# password: "example"
### 注意,对于trojan listener, 至少需要填写 “certificate和private-key” 或 “reality-config” 或 “ss-option” 的其中一项 ###
### 注意,对于trojan listener, 如果 "allow-insecure" 不为 true, 至少需要填写 “certificate和private-key” 或 “reality-config” 或 “ss-option” 的其中一项 ###
# allow-insecure: false # 是否允许不开启tls加密(注意:仅用于有 nginx, caddy 前置的情况)
- name: hysteria2-in-1
type: hysteria2
+2 -2
View File
@@ -112,8 +112,8 @@ func New(config LC.AnyTLSServer, tunnel C.Tunnel, additions ...inbound.Addition)
}
if tlsConfig.GetCertificate != nil {
l = tls.NewListener(l, tlsConfig)
} else {
return nil, errors.New("disallow using AnyTLS without certificates config")
} else if !config.AllowInsecure {
return nil, errors.New("disallow using AnyTLS without certificates/allow-insecure config")
}
sl.listeners = append(sl.listeners, l)
+2 -1
View File
@@ -12,7 +12,8 @@ type AnyTLSServer struct {
PrivateKey string `yaml:"private-key" json:"private-key"`
ClientAuthType string `yaml:"client-auth-type" json:"client-auth-type,omitempty"`
ClientAuthCert string `yaml:"client-auth-cert" json:"client-auth-cert,omitempty"`
EchKey string `yaml:"ech-key" json:"ech-key"`
EchKey string `yaml:"ech-key" json:"ech-key,omitempty"`
AllowInsecure bool `yaml:"allow-insecure" json:"allow-insecure,omitempty"`
PaddingScheme string `yaml:"padding-scheme" json:"padding-scheme,omitempty"`
}
+1
View File
@@ -23,6 +23,7 @@ type TrojanServer struct {
ClientAuthType string
ClientAuthCert string
EchKey string
AllowInsecure bool
RealityConfig reality.Config
MuxOption sing.MuxOption
TrojanSSOption TrojanSSOption
+1
View File
@@ -26,6 +26,7 @@ type VlessServer struct {
ClientAuthType string
ClientAuthCert string
EchKey string
AllowInsecure bool
RealityConfig reality.Config
MuxOption sing.MuxOption `yaml:"mux-option" json:"mux-option,omitempty"`
}
+2
View File
@@ -17,6 +17,7 @@ type AnyTLSOption struct {
ClientAuthType string `inbound:"client-auth-type,omitempty"`
ClientAuthCert string `inbound:"client-auth-cert,omitempty"`
EchKey string `inbound:"ech-key,omitempty"`
AllowInsecure bool `inbound:"allow-insecure,omitempty"`
PaddingScheme string `inbound:"padding-scheme,omitempty"`
}
@@ -48,6 +49,7 @@ func NewAnyTLS(options *AnyTLSOption) (*AnyTLS, error) {
ClientAuthType: options.ClientAuthType,
ClientAuthCert: options.ClientAuthCert,
EchKey: options.EchKey,
AllowInsecure: options.AllowInsecure,
PaddingScheme: options.PaddingScheme,
},
}, nil
+2
View File
@@ -19,6 +19,7 @@ type TrojanOption struct {
ClientAuthType string `inbound:"client-auth-type,omitempty"`
ClientAuthCert string `inbound:"client-auth-cert,omitempty"`
EchKey string `inbound:"ech-key,omitempty"`
AllowInsecure bool `inbound:"allow-insecure,omitempty"`
RealityConfig RealityConfig `inbound:"reality-config,omitempty"`
MuxOption MuxOption `inbound:"mux-option,omitempty"`
SSOption TrojanSSOption `inbound:"ss-option,omitempty"`
@@ -73,6 +74,7 @@ func NewTrojan(options *TrojanOption) (*Trojan, error) {
ClientAuthType: options.ClientAuthType,
ClientAuthCert: options.ClientAuthCert,
EchKey: options.EchKey,
AllowInsecure: options.AllowInsecure,
RealityConfig: options.RealityConfig.Build(),
MuxOption: options.MuxOption.Build(),
TrojanSSOption: LC.TrojanSSOption{
+2
View File
@@ -21,6 +21,7 @@ type VlessOption struct {
ClientAuthType string `inbound:"client-auth-type,omitempty"`
ClientAuthCert string `inbound:"client-auth-cert,omitempty"`
EchKey string `inbound:"ech-key,omitempty"`
AllowInsecure bool `inbound:"allow-insecure,omitempty"`
RealityConfig RealityConfig `inbound:"reality-config,omitempty"`
MuxOption MuxOption `inbound:"mux-option,omitempty"`
}
@@ -121,6 +122,7 @@ func NewVless(options *VlessOption) (*Vless, error) {
ClientAuthType: options.ClientAuthType,
ClientAuthCert: options.ClientAuthCert,
EchKey: options.EchKey,
AllowInsecure: options.AllowInsecure,
RealityConfig: options.RealityConfig.Build(),
MuxOption: options.MuxOption.Build(),
},
+2 -2
View File
@@ -229,8 +229,8 @@ func New(config LC.VlessServer, tunnel C.Tunnel, additions ...inbound.Addition)
l = realityBuilder.NewListener(l)
} else if tlsConfig.GetCertificate != nil {
l = tls.NewListener(l, tlsConfig)
} else if sl.decryption == nil {
return nil, errors.New("disallow using Vless without any certificates/reality/decryption config")
} else if sl.decryption == nil && !config.AllowInsecure {
return nil, errors.New("disallow using Vless without any certificates/reality/decryption/allow-insecure config")
}
sl.listeners = append(sl.listeners, l)
+2 -2
View File
@@ -168,8 +168,8 @@ func New(config LC.TrojanServer, tunnel C.Tunnel, additions ...inbound.Addition)
l = realityBuilder.NewListener(l)
} else if tlsConfig.GetCertificate != nil {
l = tls.NewListener(l, tlsConfig)
} else if !config.TrojanSSOption.Enabled {
return nil, errors.New("disallow using Trojan without both certificates/reality/ss config")
} else if !config.TrojanSSOption.Enabled && !config.AllowInsecure {
return nil, errors.New("disallow using Trojan without both certificates/reality/ss/allow-insecure config")
}
sl.listeners = append(sl.listeners, l)