if ($server._domain) $server.server = $server._domaincountryCode3. 使用内部方法时, 检测条件放宽,
aso 和 countryCode 存在其一即可4. 如果嫌中转的名称太长, 可以加一步正则命名:
🇨🇳.*➮(.*)$ => $1 中转- ❤️1
if ($server._domain) $server.server = $server._domaincountryCodeaso 和 countryCode 存在其一即可🇨🇳.*➮(.*)$ => $1 中转SUB_STORE_PRODUCE_CRON, 格式为 0 */2 * * *,sub,a;0 */3 * * *,col,btimeout: 脚本超时时长, 按需调整sub: 自定义需定时处理的单条订阅名, 多个用 , 连接col: 自定义需定时处理的组合订阅名, 多个用 , 连接名称 name 不是 显示名称 displayName 名encodeURIComponent 编码, 请编码后再用 , 连接Produce=type=cron,cronexp="50 */6 * * *",timeout=120,script-path=https://github.com/sub-store-org/Sub-Store/releases/latest/download/cron-sync-artifacts.min.js,argument="sub=sub1,sub2&col=col1,col2"cache, 值设为 true 即可)开启缓存, 可设置持久化缓存 sub-store-csr-expiration-time 的值来自定义默认缓存时长, 默认为 172800000 (48 * 3600 * 1000, 即 48 小时)async function operator() {
scriptResourceCache._cleanup(undefined, 1 * 3600 * 1000);
}use-local-host-item-for-proxy 仅对 IP 映射生效
[General]
use-local-host-item-for-proxy = true
[Host]
githubusercontent.com = server:https://9.9.9.11/dns-query
github.com = server:https://9.9.9.11/dns-query
google.com = server:https://9.9.9.11/dns-queryuse-local-host-item-for-proxy2.14.316User-Agentserver-cert-fingerprinthttps://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-Country.mmdb 至 /data/adb/GeoLite2-Country.mmdbhttps://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-ASN.mmdb 至 /data/adb/GeoLite2-ASN.mmdb/data/adb/sub_store/scripts/sub_store.configsub_store_mmdb_country_path="/data/adb/GeoLite2-Country.mmdb"
sub_store_mmdb_asn_path="/data/adb/GeoLite2-ASN.mmdb"
sni, 其次节点服务端certificate_public_key_sha256)Trojan-Go : verify_hostname 表示服务端是否校验客户端提供的SNI与服务端设置的一致性 文档Xray : rejectUnknownSni 服务端接收到的 SNI 与证书域名不匹配即拒绝 TLS 握手 文档sing-box: 问了下薄荷佬, 官版没有,server-cert-fingerprint TLS 握手时验证服务器证书 SHA256 指纹 文档server-cert-fingerprint-sha256 文档skip-cert-verify=true :Surge will not verify the server's certificate.
sni=off :turn off SNI completely
sni 为 IP 时, 也不发 sniverifyPeerCertByName, URI 上叫 vcn$server['name-cert-verify'] = 'b.com'bing.com 自签证书:openssl req -x509 -nodes -newkey ec:<(openssl ecparam -name prime256v1) -keyout private.key -out certificate.pem -subj "/CN=bing.com" -days 36500openssl x509 -noout -fingerprint -sha256 -inform pem -in certificate.pemopenssl s_client -connect foo.com:443 -servername foo.com </dev/null 2>/dev/null | openssl x509 -noout -fingerprint -sha256 | cut -d= -f2tls-fingerprint 可自动转其他客户端, 但是 sing-box 的不一样, 没法直接转, 所以开放了字段让你自己设{ "name": "节点名", "type": "anytls", "server": "服务器", "port": 443, "password": "xYbpwdF9vIELWoLmdC", "udp": true, "sni": "a.foo.com", "fingerprint": "SHA256 指纹", "_certificate_public_key_sha256": [ "SHA-256 哈希" ] } openssl x509 -in certificate.pem -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64echo | openssl s_client -servername foo.com -connect foo.com:443 2>/dev/null | openssl x509 -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64$server._certificate_public_key_sha256 = [ "428F7quaQJvBhEr5TclcjPpsl1ryyNQo7oLBGhhC3UU=" ]
,ssm add 1(为方便小白 从 1 开始, 与 subs 列表对应)HTTP-METAntp 用于检测的 NTP 服务器. 默认 time.apple.comhttps://raw.githubusercontent.com/xream/scripts/main/surge/modules/sub-store-scripts/check/http_meta_udp.js#concurrency=10&timeout=5000&retries=1
2.14.313 前端 2.14.234token, 实现上传至其他账号的 Gistname Gist 名称. 为防止意外修改你已有的 Gist, 此参数为必填file 文件名. 为防止意外修改你已有的 Gist 文件, 此参数为必填token GitHub Token. 默认为 Sub-Store 中已经配置的 Tokentarget 指定输出的目标. 默认为 ClashMetahttps://raw.githubusercontent.com/xream/scripts/main/surge/modules/sub-store-scripts/upload/gist.js#name=share&file=mihomo.yaml