Changelog
All notable changes to FRP Manager are recorded here.
The format follows Keep a Changelog and version numbers follow each other (0.0.50, 0.0.51…): every version first ships as a pre-release, then becomes the final release with the same number. Versions older than 0.0.51 are described in the GitHub release notes.
Unreleased
0.0.53 - 2026-09-28
Pre-release, then final release, on the same day.
frp is no longer updated automatically: you update it from the panel, when you decide.
Removed
- The frp auto-update is removed (
frp-autoupdate.py: daily cron job, check at every panel start, Discord notification). frp is only updated from the panel's Updates page.install.shinstalls frp withapp.py --install-frp(same verified download as the panel), and an existing install removes the cron job, the script and its line in the systemd service on its next start.
Fixed
- On the command line (
app.py --reset-password,--install-frp), messages are in French only if the system language is French, likeinstall.sh.
0.0.52 - 2026-09-28
Pre-release, then final release, on the same day.
The panel is now fully bilingual, and gets its own website.
Added
- Project website, frp-manager.gogow.fr: home page, documentation (generated from the repository's files) and live demo, in English and French (
website/). - English versions of SECURITY, CONTRIBUTING, CODE_OF_CONDUCT and this changelog (the French ones are now the
.fr.mdfiles). - Messages sent by the server (errors, confirmations, frp and panel install logs, live log notices, firewall port labels) follow the interface language, French or English.
install.shandfrp-autoupdate.pyspeak the system language (French ifLANGis French, English otherwise).
Changed
- English is now an official language: the panel follows the browser's language (English for any language other than French) and English is no longer marked as a preview in Settings.
- The demo is served under
/demo/of the website. Its panel now has a password, like every install since 0.0.51, and logging in brings you back to/demo/instead of/demo/index.html. - Website screenshots are taken from the demo, in English and French (
website/shots.py).
0.0.51 - 2026-09-28
Pre-release, then final release, on the same day.
A security-focused release. Updating from the panel or with install.sh is seamless: the existing password keeps working.
Security
- Password hashed with argon2id (argon2-cffi), with scrypt as a fallback if the module is missing. The old unsalted SHA-256 hash is still accepted and is rehashed automatically at the first successful login. Constant-time comparisons.
- Mandatory initial setup: without a password, the panel only shows the account creation page (12 characters minimum); no other page or API route answers.
- Login attempts limited per IP address: 5 attempts, then a 30 s lockout that doubles with each failure (1 h at most).
- CSRF token required on every request that changes something; WebSocket origin checked.
- HttpOnly and SameSite=Strict session cookies, Secure over HTTPS (
cookie_securebehind a TLS reverse proxy). Changing the password logs out the other sessions. - Content-Security-Policy (nonce-based scripts), X-Content-Type-Options, X-Frame-Options and Referrer-Policy headers; API responses never cached.
- systemd service and Docker container names checked against an allow-list; no more
sh -ccommand built from data. - TOML configurations checked (tomllib/tomli) before being written; writing confined to frp's configuration directories, symbolic links resolved.
- frp archives extracted without
extractall: absolute or..paths, links, non-ELF files and decompression bombs rejected; download and upload sizes capped. - frp archives checked against the SHA-256 published with each frp release; third-party mirrors (ghproxy, ghfast, gh-proxy) can be disabled (Settings or
FRP_MANAGER_NO_MIRRORS=1) and are never used without a checksum. - Panel update checked against the SHA-256 attached to the release (
frp-manager.zip.sha256, published from this version on) and archive inspected before extraction. - Panel configuration file written atomically, readable by root only; Discord webhook URL masked in the
frp-autoupdate.pylogs.
Changed
- A new install listens on
127.0.0.1instead of0.0.0.0. Existing installs keep their listening address.FRP_MANAGER_HOSTtakes precedence overbind_host, andFRP_MANAGER_PORTsets the port of a new install. - The panel now refuses to write an frp configuration outside
/etc/frp,/usr/local/etc/frp,/opt/frpand/root/frp, or an invalid TOML configuration (HTTP 400 with the error details). - 12 characters minimum for any new password (existing shorter passwords stay valid).
- README restructured (quick start, security, comparison); details moved to
docs/.
Added
python3 app.py --reset-passwordto reset the credentials from the console.- "Third-party download mirrors" setting (Settings → Network access).
- SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, issue and pull request templates.
- pytest tests (login, hash migration, TOML validation, service names, archives) and continuous integration: tests, ruff, pip-audit.