diff --git a/infra/conf/vless.go b/infra/conf/vless.go index 1c8ababfdb43..1e435d90095d 100644 --- a/infra/conf/vless.go +++ b/infra/conf/vless.go @@ -312,6 +312,9 @@ func (c *VLessOutboundConfig) Build() (proto.Message, error) { if err := json.Unmarshal(rawUser, account); err != nil { return nil, errors.New(`VLESS users: invalid user`).Base(err) } + // validateOutboundTransportSecurity needs to see these + c.Encryption = account.Encryption + c.Address = rec.Address if account.Reverse != nil { // may not be reached: error json unmarshal return nil, errors.New(`VLESS users: please use simplified outbound's config style to use "reverse"`) } diff --git a/infra/conf/xray.go b/infra/conf/xray.go index 0643a54f002a..be37cffe755a 100644 --- a/infra/conf/xray.go +++ b/infra/conf/xray.go @@ -242,7 +242,7 @@ func validateOutboundTransportSecurity(rawConfig interface{}, senderSettings *pr if vlessCfg.Encryption != "" && vlessCfg.Encryption != "none" { return nil } - if requiresTransportSecurity(vlessCfg.Vnext[0].Address) { + if requiresTransportSecurity(vlessCfg.Address) { return errors.New("vless without TLS or other encryption is prohibited unless the server address is a private IP or domain") } }