The unauthenticated GET /diagnostic endpoint and tools/smart-sub/src/constants.ts publish the operational fronting strategy in the clear: the annotated host-priority list (with notes like which hosts are considered un-blockable), the per-ISP fragment profiles, and ISP DNS resolver IPs.
Much of the underlying protocol knowledge is already public in xray/sing-box docs, but the specific, annotated combination is a ready-made block list for this deployment.
Decide deliberately what the threat model permits shipping publicly:
The unauthenticated
GET /diagnosticendpoint andtools/smart-sub/src/constants.tspublish the operational fronting strategy in the clear: the annotated host-priority list (with notes like which hosts are considered un-blockable), the per-ISP fragment profiles, and ISP DNS resolver IPs.Much of the underlying protocol knowledge is already public in xray/sing-box docs, but the specific, annotated combination is a ready-made block list for this deployment.
Decide deliberately what the threat model permits shipping publicly:
GET /diagnosticbehind a credential, or stripping resolver/host specifics from its unauthenticated response