Warn on insecure nodes without pinned cert

This commit is contained in:
2dust committed 2026-07-29 20:13:21 +08:00
1 parent 827682b768
commit 4295d5d6d1
5 files changed
+6 -6

No files matched your search

@@ -162,9 +162,9 @@ object CoreServiceManager {
// val result = V2rayConfigUtil.getV2rayConfig(context, guid)
// if (!result.status) error(result.errorMessage.ifBlank { "Failed to get V2Ray config" })
if (config.insecure == true) {
context.toastError(R.string.toast_allow_insecure_deprecated)
if (config.insecure == true && config.pinnedCA256.isNullOrEmpty()) {
context.toastError(R.string.toast_allow_insecure_deprecated)
Utils.setClipboard(context,context.getString(R.string.toast_allow_insecure_deprecated))
}
if (MmkvManager.decodeSettingsBool(AppConfig.PREF_PROXY_SHARING)) {
@@ -121,7 +121,7 @@
<string name="server_lab_pinned_ca256">Отпечаток сертификата (SHA-256)</string>
<string name="server_lab_browser_dialer">Использовать переадресацию браузера</string>
<string name="server_lab_browser_dialer_tip">Поддерживаются только исходящие соединения XHTTP (packet-up) и WS; настройки, связанные с TLS, могут быть проигнорированы или конфликтовать</string>
<string name="toast_allow_insecure_deprecated">ВНИМАНИЕ: пропуск проверки сертификата («Разрешать небезопасные соединения») будет отключён в августе 2026 года. Пожалуйста, используйте отпечатки сертификатов как можно скорее. Функция будет недоступна после истечения срока действия.</string>
<string name="toast_allow_insecure_deprecated">Этот узел использует незашифрованное соединение. Ваши данные могут быть перехвачены и просмотрены государственными структурами через промежуточное сетевое оборудование.\nВ целях безопасности такие узлы больше не поддерживаются в Xray core версии 26.2.6+.\nДля исправления: включите TLS (или другое шифрование) на своем сервере или используйте Certificate Pinning (pinnedCA256).\nЕсли вы используете платный сервис, обратитесь в поддержку для обновления. Если провайдер отказывается, рекомендуем сменить его на более безопасный.\nПодробнее: https://github.com/2dust/v2rayN/discussions/9460</string>
<string name="pinned_ca256_action_fetch">Получить и заполнить отпечаток сертификата</string>
<string name="toast_fetch_cert_sha256_success">Отпечаток сертификата успешно получен</string>
<string name="toast_fetch_cert_sha256_failed">Отпечаток сертификата не получен</string>
@@ -121,7 +121,7 @@
<string name="server_lab_pinned_ca256">证书指纹 (SHA-256)</string>
<string name="server_lab_browser_dialer">启用浏览器转发</string>
<string name="server_lab_browser_dialer_tip">仅支持 xhttp (packet-up) 和 ws。与优选域名冲突,utls, alpn, ech 等 TLS 设置将被忽略</string>
<string name="toast_allow_insecure_deprecated">警告:将在 2026.8.1 移除跳过证书验证 "allowInsecure" ,请尽快改用证书指纹或修改服务端。否则到期后会无法使用。 </string>
<string name="toast_allow_insecure_deprecated">当前节点使用未加密连接,您的通信可能会被威权政府掌控的网络中间设施直接查看\n为了安全,此类节点无法通过 26.2.6+ 版本的 Xray 核心连接\n如果是自建节点请启用 TLS 等安全加密,或固定证书 pinnedCA256\n如果机场节点请联系服务商完成技术升级,如服务商拒绝配合,建议更换更重视用户安全的服务商\n更多的信息,请访问 https://github.com/2dust/v2rayN/discussions/9460</string>
<string name="pinned_ca256_action_fetch">获取并填充指纹证书</string>
<string name="toast_fetch_cert_sha256_success">获取指纹证书完成</string>
<string name="toast_fetch_cert_sha256_failed">获取证书指纹失败</string>
@@ -119,7 +119,7 @@
<string name="server_lab_ech_config_list">EchConfigList</string>
<string name="server_lab_verify_peer_cert_by_name">Verify Peer Cert By Name</string>
<string name="server_lab_pinned_ca256">證書指紋 (SHA-256)</string>
<string name="toast_allow_insecure_deprecated">警告:將在 2026.8.1 停用跳過憑證驗證 "allowInsecure" ,請盡快改用憑證指紋。到期後無法使用。 </string>
<string name="toast_allow_insecure_deprecated">目前節點使用未加密連線,您的通訊可能會被威權政府掌控的網路中間設施直接查看\n為了安全,此類節點無法通過 26.2.6+ 版本的 Xray 核心連線\n如果是自建節點請啟用 TLS 等安全加密,或固定憑證 pinnedCA256\n如果機場節點請聯繫服務商完成技術升級,如服務商拒絕配合,建議更換更重視用戶安全的服務商\n更多的資訊,請訪問 https://github.com/2dust/v2rayN/discussions/9460</string>
<string name="pinned_ca256_action_fetch">獲取並填充指紋證書</string>
<string name="toast_fetch_cert_sha256_success">獲取指紋證書完成</string>
<string name="toast_fetch_cert_sha256_failed">獲取證書指紋失敗</string>
+1 -1
View File
@@ -122,7 +122,7 @@
<string name="server_lab_pinned_ca256">Certificate fingerprint (SHA-256)</string>
<string name="server_lab_browser_dialer">Enable Browser Dialer</string>
<string name="server_lab_browser_dialer_tip">Only supports xhttp (packet-up) and ws outbound; TLS-related settings may be ignored or conflict</string>
<string name="toast_allow_insecure_deprecated">WARNING: Skipping certificate verification "allowInsecure" will be disabled in August 2026. Please use certificate fingerprints as soon as possible. This feature will not be available after its expiration.</string>
<string name="toast_allow_insecure_deprecated">Current node uses an unencrypted connection. Your communication may be directly viewed by network intermediate facilities controlled by authoritarian governments.\nFor security reasons, such nodes cannot be connected via Xray core version 26.2.6+.\nIf it is a self-built node, please enable security encryption such as TLS, or pin the certificate pinnedCA256.\nIf it is a provider node, please contact the service provider to complete the technical upgrade. If the service provider refuses to cooperate, it is recommended to switch to a provider that pays more attention to user security.\nFor more information, please visit https://github.com/2dust/v2rayN/discussions/9460</string>
<string name="pinned_ca256_action_fetch">Fetch and fill certificate fingerprint</string>
<string name="toast_fetch_cert_sha256_success">Certificate fingerprint fetched successfully</string>
<string name="toast_fetch_cert_sha256_failed">Failed to fetch certificate fingerprint</string>