Skip to content

v0.0.2

Choose a tag to compare

@alireza0 alireza0 released this 05 Oct 09:43
· 5 commits to main since this release

Second release of Nexora Panel. Pairs with node v0.0.2.

Update your nodes to v0.0.2 as well. Rule sets now reach nodes only by push, so a node older than v0.0.2 runs without its rule sets, and the route test needs v0.0.2 too.

bash <(curl -fsSL https://raw.githubusercontent.com/nexora-vpn/panel/main/install.sh)

Upgrading from v0.0.1: use the update notice in the panel. It takes a backup, swaps the binary and rolls back on its own if the new build does not come up. Running the installer again also works.

Docs: English · فارسی · Русский · 中文

What's new

Services menu

  • Telegram: notices for admins in a private chat or a group. Every account can pair its own chat, and the read-only commands /status, /user and /node answer within that account's reach.
  • Email: notices over SMTP. Each address is confirmed by a code mailed to it.
  • Delivery log for every Telegram chat and email address, with send again.
  • Backup destinations: each backup is copied to S3-compatible storage, SFTP or a Telegram chat. Each destination can keep its own number of backups.
  • Single sign-on: Google, Microsoft, GitHub, GitLab, Keycloak, Authentik, Okta, Auth0, or any OpenID Connect or OAuth 2.0 provider. Each account links its own identity.
  • Webhooks now live under Services.

Addons

  • Addons are separate programs that the panel registers. It never runs them.
  • Browse the addon directory at addons.nexora-panel.org from inside the panel.
  • Install an addon with a ready-made command and a claim code, or let the panel install, update and remove it on a host over SSH. Every file it uploads is checked against the release's signed checksums.
  • Manage a registered addon: suspend or resume it, watch its health, and approve an update only when the newer version asks for more permissions.

Nodes and routing

  • Route test page: ask a node which rule and outbound a connection would take, check what a rule set matches, and optionally make one real connection through it.
  • Rule sets are pushed to nodes over the control link and kept there as local files. Nodes no longer download rule sets, so the download address and its setting are gone. This fixes relay nodes whose default route goes through a tunnel, and a wrong panel address can no longer take every node's rule sets down. Needs node v0.0.2.

Users and resellers

  • An account that an admin switches off stays off. The quota enforcer no longer turns it back on within a minute.
  • An expired reseller can no longer use the panel: login, existing sessions, API tokens and Telegram commands are all refused until it is renewed.
  • New API routes: read one user, change some of a user's fields with a version check (PATCH /api/users/{id}), and renew a user counted from now or from its expiry, whichever is later (POST /api/users/renew/{id}).
  • New public_address setting: the address used in links when no subscription domain is set.
  • Repeating a request with the same Idempotency-Key while the first one is still running now gets 409 instead of running twice.

Interface

  • A menu that can be pinned or set to hide itself.
  • A second built-in subscription page theme (amber).
  • Collapsible scope groups when editing roles, tokens and webhooks.

Security

  • The panel can no longer be embedded in a page on another site, which protects against clickjacking.

Fixes

  • PostgreSQL: JSON values containing quotes, newlines or backslashes are now stored correctly. Before, they were refused or corrupted, for example failed-backup notices and regular expressions in rules.
  • A restore never hands out an id that was already used (events, deliveries, accounts).
  • The node health bar and the folding of its history now show the right state.
  • Many smaller fixes from two full QA passes.

Breaking changes

  • The rule-set download mirror (/rulesets/{token}/{tag}) and the ruleset_base_url setting have been removed. Nodes get rule sets by push only, so a node before v0.0.2 runs without them, and every rule that names one is left out.
  • The old plaintext /module/* API has been removed, and its tokens are deleted on upgrade. Use API tokens (/api/v1).
  • The /api/users/{id}/ext/{addon} and /api/admins/{id}/ext/{addon} routes have been removed, and their tables are dropped on upgrade. Store contact details in the user's contact field.

Reports

Total
amd64
arm64
armv7
armv6
armv5
i386
s390x
riscv64