Filtering unsafe servers in public subscriptions
// readme
🛡️ VPN Config Security Filter
🚀 What’s new in v5.1
🛡️ Security improvements
- ✅ Thread safety —
threading.Lockon health-tracking, correct operation with 5 parallel workers - ✅ Port validation — ports 1–65535 are checked on all protocols
- ✅ Exact domain matching —
.cfno longer matchescfire.ru, only TLD*.cf - ✅ Fail-closed SSR — broken encoding = reject, not silent skip
- ✅ VMess format-2
alterId— replay-attack protection for new format - ✅
pbkvalidation — exactly 43 characters (X25519 public key) - ✅ SS 2022 fail-closed — invalid base64-key = reject
- ✅ Post-quantum cryptography — validation of ML-KEM-768 + X25519 hybrids
⚡ Performance and UX
- ✅ LRU-caching —
@lru_cachefor frequently used checks - ✅ Parallel loading —
ThreadPoolExecutorfor sources - ✅ URL Health tracking — auto-skip dead sources (3+ failures in a row)
- ✅ Base64 round-trip — decoding → filtering → encoding
- ✅ QR-codes with HTML-index — convenient on mobile
- ✅ Multi-protocol on endpoint —
host:port:prototriplet, doesn’t cut valid combinations - ✅ **
RAW_BASE…