diff --git a/internal/sub/json_service.go b/internal/sub/json_service.go index 043324434..7ce537a5f 100644 --- a/internal/sub/json_service.go +++ b/internal/sub/json_service.go @@ -639,6 +639,9 @@ func (s *SubJsonService) tlsData(tData map[string]any) map[string]any { if fingerprint, ok := tlsClientSettings["fingerprint"].(string); ok { tlsData["fingerprint"] = fingerprint } + if cs, ok := tData["cipherSuites"].(string); ok && cs != "" { + tlsData["cipherSuites"] = cs + } if ech, ok := tlsClientSettings["echConfigList"].(string); ok && ech != "" { tlsData["echConfigList"] = ech } diff --git a/internal/sub/json_service_test.go b/internal/sub/json_service_test.go index 392e30fc4..c7c6a4890 100644 --- a/internal/sub/json_service_test.go +++ b/internal/sub/json_service_test.go @@ -120,6 +120,22 @@ func TestSubJsonServicePinnedCertJoinedToString(t *testing.T) { } } +func TestSubJsonServiceTLSCipherSuitesForwarded(t *testing.T) { + svc := NewSubJsonService("", "", "", nil) + stream := svc.streamData(`{"network":"tcp","security":"tls","tlsSettings":{"serverName":"a.example.com","cipherSuites":"TLS_AES_256_GCM_SHA384","settings":{}}}`, "") + + tls, _ := stream["tlsSettings"].(map[string]any) + if got := tls["cipherSuites"]; got != "TLS_AES_256_GCM_SHA384" { + t.Fatalf("cipherSuites = %#v, want %q", got, "TLS_AES_256_GCM_SHA384") + } + + stream = svc.streamData(`{"network":"tcp","security":"tls","tlsSettings":{"serverName":"a.example.com","cipherSuites":"","settings":{}}}`, "") + tls, _ = stream["tlsSettings"].(map[string]any) + if _, present := tls["cipherSuites"]; present { + t.Fatalf("empty cipherSuites must be omitted, got %#v", tls["cipherSuites"]) + } +} + func TestSubJsonServiceVlessFlattened(t *testing.T) { inbound := &model.Inbound{Listen: "1.2.3.4", Port: 443, Protocol: model.VLESS, Settings: `{"encryption":"none"}`} client := model.Client{ID: "uuid-1", Flow: "xtls-rprx-vision"}