Skip to content

Releases: Nexora-VPN/panel

v0.0.3

Choose a tag to compare

@alireza0 alireza0 released this 09 Oct 13:13

Nexora Panel v0.0.3

Before you update

Update the panel first, then your nodes. Nodes on v0.0.3 expect this panel release; this panel keeps working with older nodes, but live config changes and cleaner quota cut-offs need nodes on v0.0.3.

What's new

Changes reach your nodes without restarts

  • Editing a template, routing, DNS or rule sets is applied to a running node without restarting it. The node restarts only when it has to.
  • Rule sets are downloaded by the panel and sent to your nodes. Nodes no longer fetch them themselves, so one unreachable list can no longer stop a node from starting.
  • Items a node cannot run are listed as warnings on the node instead of failing the whole configuration. They stay listed until a sync applies them.
  • Accounts that lack the credential an inbound needs are left out of that inbound with a warning, and accounts created before credentials were generated are given them once.
  • A node you switch off stops serving. Deleting a node stops it too, and the panel warns you if it could not be reached.
  • Actions that need a switched-off node now answer "node is off" instead of a generic gateway error.
  • A quota run now syncs each node once, however many accounts lapse in the same minute.

Addons

  • Addons can be installed on the panel's own server, without SSH.
  • The panel can issue an addon's HTTPS certificate and the addon fetches it. The panel's own certificate never leaves its server.
  • Password fields in addon install forms are checked before the install starts (at least 10 characters).
  • The addon install wizard keeps its answers and checks your input before running anything.

Subscriptions

  • Subscription files now load and connect on current Xray and sing-box clients:
    • Xray: the removed HTTP/2 transport is left out, mKCP uses the legacy mask, and Hysteria2 and WireGuard are included.
    • sing-box: naive trusts the pinned certificate.
  • Options that only matter to client apps, and ECH options that sing-box removed, are no longer offered or saved.
  • VLESS Encryption can be used on outbounds.

Panel interface

  • A new dashboard card walks a fresh install through its first inbound, template, node and user. Empty pages point to the next step, and nodes without a template are flagged.
  • Server addresses and certificate names are blurred until you hover them.
  • The sidebar groups fold away when the sidebar stops peeking, and the licence and update banners are softer in the dark theme.
  • You are told when a node is behind the newest node release.

Under the hood

  • Built with Go 1.27.2, which includes the latest standard-library security fixes.
  • Addon contract: addon-kit v0.4.4.

@MHSanaei @alireza0

v0.0.2

Choose a tag to compare

@alireza0 alireza0 released this 05 Oct 09:43

Second release of Nexora Panel. Pairs with node v0.0.2.

Update your nodes to v0.0.2 as well. Rule sets now reach nodes only by push, so a node older than v0.0.2 runs without its rule sets, and the route test needs v0.0.2 too.

bash <(curl -fsSL https://raw.githubusercontent.com/nexora-vpn/panel/main/install.sh)

Upgrading from v0.0.1: use the update notice in the panel. It takes a backup, swaps the binary and rolls back on its own if the new build does not come up. Running the installer again also works.

Docs: English · فارسی · Русский · 中文

What's new

Services menu

  • Telegram: notices for admins in a private chat or a group. Every account can pair its own chat, and the read-only commands /status, /user and /node answer within that account's reach.
  • Email: notices over SMTP. Each address is confirmed by a code mailed to it.
  • Delivery log for every Telegram chat and email address, with send again.
  • Backup destinations: each backup is copied to S3-compatible storage, SFTP or a Telegram chat. Each destination can keep its own number of backups.
  • Single sign-on: Google, Microsoft, GitHub, GitLab, Keycloak, Authentik, Okta, Auth0, or any OpenID Connect or OAuth 2.0 provider. Each account links its own identity.
  • Webhooks now live under Services.

Addons

  • Addons are separate programs that the panel registers. It never runs them.
  • Browse the addon directory at addons.nexora-panel.org from inside the panel.
  • Install an addon with a ready-made command and a claim code, or let the panel install, update and remove it on a host over SSH. Every file it uploads is checked against the release's signed checksums.
  • Manage a registered addon: suspend or resume it, watch its health, and approve an update only when the newer version asks for more permissions.

Nodes and routing

  • Route test page: ask a node which rule and outbound a connection would take, check what a rule set matches, and optionally make one real connection through it.
  • Rule sets are pushed to nodes over the control link and kept there as local files. Nodes no longer download rule sets, so the download address and its setting are gone. This fixes relay nodes whose default route goes through a tunnel, and a wrong panel address can no longer take every node's rule sets down. Needs node v0.0.2.

Users and resellers

  • An account that an admin switches off stays off. The quota enforcer no longer turns it back on within a minute.
  • An expired reseller can no longer use the panel: login, existing sessions, API tokens and Telegram commands are all refused until it is renewed.
  • New API routes: read one user, change some of a user's fields with a version check (PATCH /api/users/{id}), and renew a user counted from now or from its expiry, whichever is later (POST /api/users/renew/{id}).
  • New public_address setting: the address used in links when no subscription domain is set.
  • Repeating a request with the same Idempotency-Key while the first one is still running now gets 409 instead of running twice.

Interface

  • A menu that can be pinned or set to hide itself.
  • A second built-in subscription page theme (amber).
  • Collapsible scope groups when editing roles, tokens and webhooks.

Security

  • The panel can no longer be embedded in a page on another site, which protects against clickjacking.

Fixes

  • PostgreSQL: JSON values containing quotes, newlines or backslashes are now stored correctly. Before, they were refused or corrupted, for example failed-backup notices and regular expressions in rules.
  • A restore never hands out an id that was already used (events, deliveries, accounts).
  • The node health bar and the folding of its history now show the right state.
  • Many smaller fixes from two full QA passes.

Breaking changes

  • The rule-set download mirror (/rulesets/{token}/{tag}) and the ruleset_base_url setting have been removed. Nodes get rule sets by push only, so a node before v0.0.2 runs without them, and every rule that names one is left out.
  • The old plaintext /module/* API has been removed, and its tokens are deleted on upgrade. Use API tokens (/api/v1).
  • The /api/users/{id}/ext/{addon} and /api/admins/{id}/ext/{addon} routes have been removed, and their tables are dropped on upgrade. Store contact details in the user's contact field.

Reports

Total
amd64
arm64
armv7
armv6
armv5
i386
s390x
riscv64

v0.0.1

Choose a tag to compare

@alireza0 alireza0 released this 27 Sep 12:03

First stable release of Nexora Panel. Pairs with node v0.0.1. @MHSanaei

bash <(curl -fsSL https://raw.githubusercontent.com/nexora-vpn/panel/main/install.sh)

Upgrading from a beta: run the installer again, after taking a backup. From this release on, the panel updates itself.

Docs: English · فارسی · Русский · 中文

Reports

Total
amd64
arm64
armv7
armv6
armv5
i386
s390x
riscv64

v0.0.0-beta.4

v0.0.0-beta.4 Pre-release
Pre-release

Choose a tag to compare

@alireza0 alireza0 released this 11 Sep 22:58

New features

  • Plans: a named bundle of the limits a new account starts with
  • Reseller restrictions: sell from allowed plans only, or create-only
  • On-hold users: the plan starts at the first connection
  • Rule sets: remote sing-box rule-sets mirrored by the panel, with presets
  • Bulk user operations: create in bulk, extend and gift, set limits, enable/disable, reset traffic, delete expired, export
  • Batch actions and duplicate action on the list pages
  • Renaming a tag rewrites every reference to it
  • Summary strip and inline filters on the tunnels page @MHSanaei
  • Database tuning and batched accounting writes

Bug fixes

  • Move configs to sing-box 1.14, migrating legacy DNS shapes on upgrade
  • Add Snell to the sing-box subscription
  • UI component, alignment and RTL locale fixes
  • Frontend build now requires Node.js 26

v0.0.0-beta.3

v0.0.0-beta.3 Pre-release
Pre-release

Choose a tag to compare

@alireza0 alireza0 released this 07 Sep 19:34

New features

  • Multi solution load balancing tunnel between nodes
  • Server-side user filters, sort and summary strips on every list page @MHSanaei
  • Move hint texts to hover infohint

v0.0.0-beta.2

v0.0.0-beta.2 Pre-release
Pre-release

Choose a tag to compare

@alireza0 alireza0 released this 04 Sep 11:43

New features

  • Backup & Restore
  • PortMux feature speedy and high throughput internal manager ( without any action on OS's iptables ) for:
    • Hysteris/Hysteris2 internal multiport
    • IP-Limit fully control internally (also sync between all the nodes)
    • Speedlimit for each user (per node)
  • Ingress inbound:
    • Multi-inbound proxy, with/without tls termination
    • Support all you need from HAproxy or nginx
    • Simulate xray's fallback
    • Active probing shields by reject/answer/proxy to another website
  • Support endpoints configs on clash/singbox sub and sub theme
  • UI performance: lazy load language packs

Bug fixes

  • fix ovpn mtls default option when it is not enabled
  • fix ipv6 listen view on front
  • fix go/crypto Vulnerabilities

v0.0.0-beta.1

v0.0.0-beta.1 Pre-release
Pre-release

Choose a tag to compare

@alireza0 alireza0 released this 31 Aug 22:38

New features

• Auto install node from panel using SSH
• Auto move node to another server
• IPv6 supprt (and also only IPv6 servers)
• Re-ordering dashboard tiles
• Loading for modals
• Quic + HTTP2 params for Hysteria and Quic

Bug fixes

• Fix UUID generation in HTTP only
• Fix OVPN ca error in client
• Fix client modal initiation

v0.0.0-beta.0

v0.0.0-beta.0 Pre-release
Pre-release

Choose a tag to compare

@alireza0 alireza0 released this 28 Aug 22:05
Publish the Nexora Panel install script, Docker stacks and documentation

This repository is the public face of the panel: releases, container images,
the installer and the docs. The source stays private.

The installer now draws from two repositories rather than one. Panel and node
are released independently, so each has its own "latest" — asset_url takes a
repository and a version, and --node-version pins the node binaries the panel
stages for node installers.