fix(sub): keep the spider settings in a reality spiderX seed's query (#6694)

* fix(sub): keep the spider settings in a reality spiderX seed's query

xray's REALITY client reads p, c, t, i and r from the spiderX query as
its spider's own settings (padding, concurrency, times, interval,
return). deriveSpiderX hashes the whole seed into a bare /path per
client, so any query set on the inbound was dropped from every share
link and JSON subscription, and the spider always ran with defaults.

Keep the seed's query after the derived path. The hash input is
unchanged, so every existing client's spx stays the same; only seeds
that carry a query gain it. The frontend mirror and the cross-language
vectors are updated together.

* docs(sub): keep the deriveSpiderX comments within two lines

Review feedback on #6694: the added lines pushed both doc blocks past the two-line cap.
This commit is contained in:
Farhan Zare
2026-10-02 18:31:52 -04:00
committed by GitHub
parent ed31ee432c
commit 93847dd106
4 changed files with 40 additions and 7 deletions
+6 -4
View File
@@ -1,10 +1,12 @@
import { sha256 } from '@noble/hashes/sha2.js';
import { bytesToHex, utf8ToBytes } from '@noble/hashes/utils.js';
// Mirrors deriveSpiderX in internal/sub/service.go byte-for-byte so panel
// links and subscription links agree; returns '' when there is no seed and
// no client key (the caller then omits spx, as the legacy builder did).
// Mirrors deriveSpiderX in internal/sub/service.go byte-for-byte, seed query included (#6693);
// '' with neither seed nor client key, so the caller omits spx as the legacy builder did.
export function deriveSpiderX(seed: string, clientKey: string): string {
if (!seed && !clientKey) return '';
return `/${bytesToHex(sha256(utf8ToBytes(`${seed}|${clientKey}`))).slice(0, 15)}`;
const path = `/${bytesToHex(sha256(utf8ToBytes(`${seed}|${clientKey}`))).slice(0, 15)}`;
const at = seed.indexOf('?');
const query = at === -1 ? '' : seed.slice(at + 1);
return query ? `${path}?${query}` : path;
}
+6
View File
@@ -9,6 +9,12 @@ describe('deriveSpiderX', () => {
it('matches the Go deriveSpiderX vectors', () => {
expect(deriveSpiderX('/seed', 'subAlice')).toBe('/c252fbc3ecd3e3c');
expect(deriveSpiderX('/', '')).toBe('/d08ed99bd9afc60');
expect(deriveSpiderX('/seed?p=40-400&r=500-2000', 'subAlice')).toBe(
'/09dd00b3f8c01f5?p=40-400&r=500-2000',
);
expect(deriveSpiderX('/?p=40-400&c=1-4&t=1-3&i=1500-6000&r=500-2000', '')).toBe(
'/ac2cb268d22908e?p=40-400&c=1-4&t=1-3&i=1500-6000&r=500-2000',
);
});
it('is stable per client, distinct across clients, and rotates with the seed', () => {