fatedier/frp
58.2
Adequate · 24 September 2026
29.8k
lines of production code
Go
with TypeScript
5
measurements over time
What this system is
This system is a high-performance reverse proxy solution that establishes secure tunnels between clients and servers to expose local services to the internet. It supports a wide variety of proxy protocols, including TCP, UDP, HTTP, HTTPS, and specialized NAT traversal methods like XTCP and STCP. The architecture features a modernized v2 wire protocol with binary framing and AEAD encryption, alongside robust client and server management capabilities such as persistent configuration stores, web dashboards, and comprehensive monitoring metrics.
How it got here
2015–2020 — v1 schema and v2 wire protocol migration
46 changes.
This period focused on migrating the project to a structured v1 configuration schema and a new v2 wire protocol with binary framing, replacing legacy JSON and INI formats. It involved extensive refactoring of client and server architectures to support modular proxy management, persistent configuration stores, and improved NAT traversal, alongside comprehensive updates to web dashboards and end-to-end testing infrastructure.
2021–2023 — v1 configuration schema and SSH tunneling
22 changes.
This period focused on introducing the v1 configuration schema with strict validation, persistent proxy/visitor storage, and legacy INI support. It also implemented SSH tunneling capabilities and expanded the web dashboard with detailed client and proxy management features. Comprehensive end-to-end tests were added to cover the new configuration system, SSH tunnels, and core proxy functionalities.
2024–2026 — v2 protocol and dashboard overhaul
18 changes.
This period focused on implementing the v2 wire protocol with AEAD encryption and binary framing, alongside a new Virtual Network subsystem for TUN-based routing. The web dashboards for both client and server were significantly redesigned to support the v2 API, featuring persistent configuration management, dark mode, and detailed traffic tracking. These changes were supported by a new feature gate system, strict JSON utilities, and comprehensive end-to-end testing infrastructure.
Features
Add detailed proxy name label to proxy count metrics
The Prometheus metrics implementation now exposes a new \frp\_server\_proxy\_counts\_detailed\ gauge that tracks proxy counts grouped by both type and specific proxy name, in addition to the existing \frp\_server\_proxy\_counts\ gauge which only tracks by type. This allows users to monitor individual proxy activity and distinguish between proxies with the same type in their monitoring dashboards.
pkg/metrics/prometheus · high confidence
Add internal metric utility types and counters
The \pkg/util/metric\ package now includes internal implementations for tracking metrics, specifically a thread-safe \Counter\ using atomic operations and a \DateCounter\ that tracks counts over a configurable number of days with daily rotation. These utilities, along with standard metric interfaces (\GaugeMetric\, \CounterMetric\, \HistogramMetric\), provide the foundation for internal metric collection, supported by comprehensive unit tests covering concurrency and time-rotation logic.
pkg/util/metric · high confidence
Added legacy INI configuration support and conversion layer
The system now supports parsing legacy INI-style configuration files for both client and server components, including proxy and visitor definitions. This change introduces a new \pkg/config/legacy\ package that handles INI parsing via the \go-ini\ library, manages environment variable rendering in config files, and provides conversion functions to map legacy INI structures to the modern v1 configuration types. Users can continue to use the traditional INI format while the system internally translates it to the current configuration schema.
pkg/config/legacy · high confidence
Initial frpc client entry point
The frpc client binary now has a defined entry point in cmd/frpc/main.go that initializes system compatibility modes and delegates execution to the subcommand handler, establishing the foundation for the client's CLI interface.
cmd/frpc · high confidence
Introduce SSH tunnel gateway and server implementation
This change adds the core implementation for the SSH tunnel feature in the \pkg/ssh\ package. It introduces \gateway.go\ to handle the SSH listener, private key management, and authorized key authentication, and \server.go\ to manage the tunnel server lifecycle, including parsing client configurations from SSH exec payloads, establishing virtual client connections, and serializing channel writes to prevent concurrency panics. The \terminal.go\ file provides user-facing status information upon successful connection, while \server\_test.go\ adds unit tests for payload parsing and write serialization.
pkg/ssh · high confidence
Introduce TypeScript type definitions for the v2 dashboard API
The web frontend now includes explicit TypeScript interfaces for the v2 API responses, covering client information (including connection status and metadata), proxy details (supporting v2 specs for TCP, UDP, HTTP, HTTPS, and multiplexed protocols with traffic stats), and server status. These types enable the dashboard to display detailed client and proxy views, paginate lists, and show real-time traffic and connection metrics for the v2 protocol.
web/frps/src/types · high confidence
Introduce Virtual Network (vnet) with TUN-based routing
Added a new Virtual Network subsystem in \pkg/vnet\ that creates a TUN interface to route traffic between clients and servers. The implementation includes platform-specific setup for macOS (\tun\_darwin.go\) and Linux (\tun\_linux.go\) to configure network interfaces and routes, along with a controller (\controller.go\) that manages packet handling, client/server routing logic, and connection lifecycle. Message framing (\message.go\) and buffer pooling are used for efficient data transfer over the tunnel.
pkg/vnet · high confidence
Introduce VirtualNet visitor plugin with resilient reconnection
A new VirtualNet visitor plugin is available, allowing visitors to register specific client routes (e.g., a /32 host route) via a TUN device controller. The plugin manages the lifecycle of this virtual connection, including automatic reconnection with exponential backoff (starting at 60 seconds and capping at 5 minutes) to handle transient failures gracefully.
pkg/plugin/visitor · high confidence
Introduce dark mode support to the frpc web dashboard
The frpc web dashboard now supports a dark theme, allowing users to toggle between light and dark modes via a switch in the header. This change updates the application's styling and configuration to respect system preferences and user choices, improving visibility and comfort in low-light environments.
web/frpc/src · high confidence
Introduce in-memory metrics storage with offline proxy pruning
The system now supports an in-memory metrics backend (pkg/metrics/mem) that aggregates server and proxy statistics, including traffic, connections, and client counts. This implementation introduces automatic pruning of proxy statistics for proxies that have been offline for more than 7 days, ensuring the dashboard and metrics remain accurate and performant by removing stale data. An aggregate metrics layer (pkg/metrics/aggregate) is also added to allow enabling multiple metrics backends simultaneously.
pkg/metrics/mem · high confidence
Introduce persistent visitor management and STCP/SUDP visitor implementations
The client/visitor package now includes a VisitorManager that persists visitor configurations and automatically restarts them if they stop, replacing the previous ad-hoc handling. New STCP and SUDP visitor implementations are added to support TCP and UDP traffic forwarding respectively, alongside the existing XTCP visitor. This change provides a more robust and consistent way to manage visitor proxies, ensuring they remain active and are properly cleaned up.
client/visitor · high confidence
Introduce server port management with reserved port cleanup
Added a new port management system in the server that handles port acquisition, release, and reservation. The system now supports specifying allowed port ranges via configuration and automatically cleans up reserved ports that have not been used for 24 hours, improving resource management and preventing port exhaustion.
server/ports · high confidence
Introduce v2 wire protocol with AEAD encryption and binary framing
The wire protocol package now implements version 2, adding a new binary framing format and a capability negotiation handshake (ClientHello/ServerHello). This handshake allows clients and servers to negotiate AEAD encryption algorithms (AES-256-GCM and XChaCha20-Poly1305) and binary UDP packet codecs, replacing the previous implicit or older negotiation methods. The change includes new crypto context handling and transcript hashing to secure the connection setup.
pkg/proto/wire · high confidence
Introduces FastBackoffManager with fast-retry and jitter logic
A new backoff implementation (FastBackoffManager) is added to pkg/util/wait, supporting configurable fast-retry windows, exponential backoff with jitter, and clock injection for testability. This changes the retry behavior for callers using this manager, allowing faster retries within a defined window and more predictable timing via jitter, while the existing Until and BackoffUntil helpers remain available.
pkg/util/wait · high confidence
Introduces v2 wire protocol with binary UDP packet support
The message handling layer now supports a new v2 wire protocol that uses binary framing and capability negotiation, replacing the legacy v1 JSON-based framing. This change adds a binary codec for UDP packets to avoid redundant base64 encoding/decoding, significantly reducing payload size and improving performance for UDP traffic. The implementation includes new \ReadWriter\ interfaces and dispatcher logic to handle both v1 and v2 protocols, with v2 being the default when negotiated. Existing v1 behavior is preserved for backward compatibility when v2 is not explicitly selected.
pkg/msg · high confidence
Introduction of centralized logging utility package
A new \pkg/util/log\ package has been added to provide a unified logging interface for the application. It wraps the \golib\ logger to offer standardized log levels (Trace, Debug, Info, Warn, Error) and supports both console output with optional colorization and daily rotating file logs. The package exposes convenience functions like \Infof\ and \Errorf\ that accept variadic arguments using the \any\ type, simplifying log formatting for developers.
pkg/util/log · high confidence
Introduction of feature gate system and unsafe feature tracking
The policy package now includes a new feature gate system (pkg/policy/featuregate) that allows for the dynamic enabling and disabling of features, such as the experimental 'VirtualNet' feature which is currently disabled by default. Additionally, a new security module (pkg/policy/security) has been added to track and manage 'unsafe' client and server features, specifically identifying 'TokenSourceExec' as an unsafe capability that can be explicitly allowed or denied.
pkg/policy · high confidence
New API layer for persistent proxy/visitor store management
The frpc web dashboard now supports managing persistent proxy and visitor configurations through a new API layer. This change introduces a dedicated HTTP client and a set of API functions that enable creating, reading, updating, and deleting (CRUD) proxies and visitors via the \/api/store/proxies\ and \/api/store/visitors\ endpoints. Users can now persist their network configurations directly from the dashboard interface, rather than relying solely on static configuration files.
web/frpc/src/api · high confidence
New Dockerfiles for frpc and frps clients
Added dedicated Dockerfiles for building the frpc and frps binaries. These images use Node.js 22 to build the embedded web UI assets and Go 1.25 to compile the final binaries, resulting in smaller Alpine-based production images that include timezone data.
dockerfiles · high confidence
New JSON utility package with strict decoding support
A new \pkg/util/jsonx\ package has been introduced, providing wrappers around the standard \encoding/json\ library. It includes a \DecodeOptions\ struct that allows users to enable \RejectUnknownMembers\, which causes unmarshaling to fail if the JSON contains fields not defined in the target struct. The package also exports a \RawMessage\ type that behaves like \encoding/json.RawMessage\ for storing raw JSON values.
pkg/util/jsonx · high confidence
New SDK client for FRP API interaction
The SDK now includes a new \client\ package that provides a Go client for interacting with the FRP server's HTTP API. This client exposes methods to retrieve proxy status (\GetProxyStatus\, \GetAllProxyStatus\), reload configuration with optional strict mode (\Reload\), stop the server (\Stop\), and get or update the configuration (\GetConfig\, \UpdateConfig\). It handles authentication via basic auth headers and manages HTTP requests to the standard API endpoints.
pkg/sdk · high confidence
New configuration types for bandwidth and port ranges
Added \BandwidthQuantity\ and \PortsRangeSlice\ types to the configuration package. \BandwidthQuantity\ allows users to specify bandwidth limits using human-readable strings (e.g., "1KB", "2MB") which are automatically parsed and serialized, while \PortsRangeSlice\ enables defining port configurations via ranges (e.g., "1000-2000,3000") in configuration files.
pkg/config/types · high confidence
New dashboard components for client, proxy, and traffic visualization
The frps dashboard now includes new UI components to display client status, proxy details, and traffic statistics. ClientCard shows online/offline status, IP, version, and wire protocol for each client. ProxyCard displays proxy name, type, port, connection count, client ID, and traffic in/out. StatCard provides summary statistics for clients, proxies, connections, and traffic. Traffic.vue renders a bar chart showing historical traffic data for a specific proxy.
web/frps/src/components · high confidence
New frpc CLI commands for configuration verification, NAT hole discovery, and client administration
The frpc client now includes several new subcommands to improve usability and operational control. You can verify configuration syntax before starting the client using the new \verify\ command. NAT hole discovery is now accessible via the \nathole discover\ command, which allows you to diagnose NAT types and behavior using a STUN server. Additionally, the client exposes administrative commands (\reload\, \status\, \stop\) that interact with the frpc web server to manage the running service without restarting it.
cmd/frpc/sub · high confidence
New frpc dashboard for managing client proxies and visitors
The frpc client now includes a web-based dashboard that allows users to view, create, edit, and delete proxy and visitor configurations directly from the browser. This new UI features a sidebar navigation, responsive layout, and detailed views for managing proxy types (TCP, UDP, HTTP, HTTPS, STCP, etc.) and visitor connections. It supports configuring authentication, backend modes (direct or plugin), health checks, load balancing, and transport settings like encryption and compression. The dashboard also displays proxy status (running, error, disabled) and allows enabling/disabling proxies on the fly.
web · high confidence
New network utility package with connection wrappers, dial hooks, and protocol support
The new \pkg/util/net\ package introduces a suite of network utilities for frp. It adds connection wrappers (\ContextConn\, \WrapReadWriteCloserConn\, \CloseNotifyConn\, \StatsConn\) to enhance connection handling with context propagation, logging, and statistics. Dial hooks are provided to support custom TLS head bytes and WebSocket upgrades, ensuring tunnel payloads are sent as binary frames to avoid issues with RFC 6455-compliant intermediaries. The package also includes implementations for KCP and UDP listeners, Proxy Protocol header building, HTTP authentication middleware, and TLS connection checking. Additionally, it provides DNS configuration utilities and AEAD crypto read/write wrappers for secure communication.
pkg/util/net · high confidence
New routing structure for proxy and visitor management
The frpc web dashboard now includes a dedicated router configuration that establishes navigation for proxy and visitor resources. Users can access lists, details, and creation/edit forms for both proxies and visitors via dedicated routes (e.g., /proxies, /visitors). The router also enforces a store-enabled check before allowing creation or editing actions, displaying a warning if the persistent store is not configured in frpc.
web/frpc/src/router · high confidence
New structured logging utility with context propagation and prefix management
The \pkg/util/xlog\ package introduces a new logging layer that supports structured log prefixes with configurable priorities, context-based logger propagation, and a \LogWriter\ adapter for standard \io.Writer\ compatibility. This change replaces previous logging implementations with a more robust system that ensures prefix strings are handled safely (preventing format string injection) and allows loggers to be spawned with inherited context.
pkg/util/xlog · high confidence
New utility classes for client and proxy data modeling in the dashboard
The dashboard now includes dedicated utility classes in \web/frps/src/utils\ to structure and display client and proxy information. The new \Client\ class maps raw client registry data (including connection timestamps, IP addresses, and protocol versions) into a user-friendly object with formatted relative time labels. Similarly, the \proxy.ts\ module introduces a hierarchy of proxy classes (TCP, UDP, HTTP, HTTPS, TCPMux, STCP, SUDP) that parse proxy statistics to expose details such as encryption/compression status, traffic volumes, and type-specific configuration (e.g., remote ports, custom domains, subdomains). Supporting format utilities handle distance-to-now calculations, Unix timestamp formatting, and file size display, enabling the UI to present detailed, real-time tracking for all connected clients and active proxies.
web/frps/src/utils · high confidence
New utility functions for generic cloning, safe string comparison, and random delays
The util package now includes several new helper functions: ClonePtr provides a generic way to deep-copy pointer values, ConstantTimeEqString performs timing-safe string comparisons for security, and RandomSleep introduces a randomized delay within a specified range to help mitigate timing-based attacks or reduce collision risks. Additionally, EmptyOr offers a generic fallback for zero values, and the package continues to support range number parsing and authentication key generation.
pkg/util/util · high confidence
Persistent client registry with generation-aware lifecycle management
The server now maintains a persistent in-memory registry of connected clients, tracking metadata such as user, hostname, version, and the negotiated wire protocol (v1 or v2). This registry prevents stale offline states by using generation-aware control IDs, ensuring that a disconnect from an older control connection does not incorrectly mark a newer, active connection as offline. It also handles client ID conflicts and run ID migrations, providing accurate online/offline status and connection history for monitoring and UI purposes.
server/registry · high confidence
Persistent proxy and visitor management via web UI store
The frpc dashboard now supports creating, editing, and deleting proxies and visitors directly from the web interface, with changes persisted to a local store (frpc\_store.json) rather than only the static configuration file. New views (ProxyList, ProxyDetail, ProxyEdit, VisitorList, VisitorDetail, VisitorEdit) provide a dedicated 'Store' tab for managing these persistent definitions, including validation rules for fields like bind ports and destination IPs, and confirmation dialogs for destructive actions. A new ClientConfigure view allows users to view and update the raw frpc configuration file content, with an 'Update & Reload' action that applies changes and restarts the client.
web/frpc/src/views · high confidence
Persistent proxy/visitor store with CRUD API
The frpc client now supports a persistent store for proxy and visitor configurations, allowing them to be managed via a CRUD API and a web UI. This change introduces a new \StoreSource\ in \pkg/config/source\ that persists proxy and visitor definitions to a JSON file, and an \Aggregator\ that merges these store entries with the static configuration source, giving the store higher priority. Users can now add, update, and remove proxies and visitors at runtime, with changes automatically persisted to disk.
pkg/config · high confidence
Persistent proxy/visitor store with CRUD API and web UI
The frpc client now supports a persistent store for proxy and visitor configurations, allowing them to be managed via a new REST API and a redesigned web dashboard. This change introduces a set of HTTP endpoints (under /api/store/proxies and /api/store/visitors) for creating, reading, updating, and deleting stored configurations, alongside a new web UI that provides sidebar navigation and detailed views for managing these assets.
client · high confidence
Server HTTP API v2 endpoints and typed proxy specs
The server/http package now exposes a new API v2 interface alongside the existing v1 endpoints. This includes paginated listing for clients and users, a system info endpoint, a system prune endpoint for offline proxies, and traffic statistics. The API v2 responses use typed proxy specifications that redact sensitive configuration fields (such as passwords and secret keys) while exposing structured proxy status and configuration details.
server/http · high confidence
Server metrics tracking interface introduced
The server now exposes a metrics interface to track client connections, proxy lifecycle events, and traffic volume. This change allows the system to integrate with external monitoring tools, such as Prometheus, by providing hooks for recording client and proxy creation/closure, connection open/close, and inbound/outbound traffic data.
server/metrics · high confidence
Visitor connection manager now supports wire protocol and UDP packet codec propagation
The server/visitor package introduces a new Manager that handles visitor listener lifecycle and connection acceptance. When a new visitor connection is established, the manager now propagates the specific wire protocol (e.g., ProtocolV2) and UDP packet codec (e.g., Binary) from the incoming connection to the accepted listener side. This allows downstream components to inspect and handle the connection based on its specific protocol and encoding requirements, enabling more flexible and efficient handling of mixed wire protocol SUDP payloads.
server/visitor · high confidence
Architecture
Centralized resource management for server controllers
The server controller now uses a unified ResourceController struct to manage all internal components, including visitor listeners, TCP/HTTP/HTTPS/TCP-Mux group controllers, port managers, reverse proxies, and plugin managers. This consolidation simplifies resource lifecycle management, ensuring that critical components like the HTTPS muxer and TCP-Mux HTTP CONNECT multiplexer are properly closed during server shutdown.
server/controller · high confidence
Client proxy logic refactored into a modular, factory-based architecture
The client proxy subsystem has been restructured from a monolithic implementation into a modular, factory-based architecture. A new \proxy\_manager.go\ now centrally manages proxy lifecycle, configuration updates, and status reporting, while individual proxy types (TCP, UDP, SUDP, XTCP) are implemented as distinct, pluggable modules registered via a factory registry in \general\_tcp.go\ and their respective files. This change introduces a \BaseProxy\ component that standardizes shared concerns such as bandwidth limiting, encryption, compression, and plugin handling across all proxy types, and adds a \Wrapper\ to manage proxy phases, health checks, and event dispatching. Additionally, the XTCP NAT traversal implementation now supports configurable assisted addresses and uses a selected wire protocol for reading NAT hole session IDs.
client/proxy · high confidence
Behavioural changes
Android compatibility mode for timezone and DNS resolution
On Android devices, the application now automatically activates a compatibility mode that corrects timezone settings by reading the system property and fixes DNS resolution issues by falling back to Google's public DNS (8.8.8.8) if the default resolver fails to resolve domains.
pkg/util/system · high confidence
Bandwidth limiter burst is clamped to prevent integer overflow
The bandwidth limiter in pkg/util/limit now clamps the burst size to the maximum representable integer value for the target platform. This change ensures that large byte limits do not cause integer overflow when creating the underlying rate limiter, preventing potential crashes or undefined behavior during high-throughput data transfers.
pkg/util/limit · high confidence
Client plugins refactored to use a shared HTTP bridge and reverse proxy
The client plugin implementations (http2http, http2https, https2http, https2https, and http\proxy) have been refactored to use a shared \httpBridgePlugin\ and \newHTTPBridgeReverseProxy\ helper. This change standardizes how these plugins handle incoming connections by routing them through a local HTTP server and a reverse proxy, allowing for consistent header rewriting (Host, X-Forwarded-\) and transport configuration. The \httpsserver\ package now includes a misdirected request check that returns 421 for SNI/host mismatches, and the \http\_proxy\ plugin now uses a read deadline to handle fragmented CONNECT method detection more robustly.
pkg/plugin/client · high confidence
Health check failure counting now resets on success
The health monitor in the client now resets the consecutive failure counter to zero whenever a health check succeeds. Previously, failed checks accumulated indefinitely, meaning a single successful check might not restore the service to a 'healthy' state if the total failure count had exceeded the threshold. This change ensures that transient failures do not permanently mark a service as failed as long as subsequent checks pass.
client/health · high confidence
Introduce API v2 client and proxy views with pagination and traffic tracking
The frps dashboard now uses the new API v2 endpoints to display client and proxy information, enabling paginated lists of clients and proxies with filtering options (status, search query, user, client ID, run ID, and proxy type). Proxy details now include enhanced tracking data such as today's traffic in/out, current connections, and last start/close times, while also exposing proxy traffic statistics via a dedicated API endpoint. The dashboard also supports pruning offline proxies through the system prune API and provides updated server info retrieval, all handled through a new HTTP client layer that supports v2 envelope responses.
web/frps/src/api · high confidence
Introduce dedicated HTTP utility package with API v2 handler support
The \pkg/util/http\ package now provides a centralized set of HTTP utilities, including a \Context\ wrapper for request handling, a structured error type, and a request logger middleware. It introduces \MakeHTTPHandlerFuncV2\, which wraps API handlers in a standardized v2 response envelope (code, message, data), enabling consistent API v2 responses across the application.
pkg/util/http · high confidence
Introduce golangci-lint v2 configuration and developer tooling documentation
The project now uses golangci-lint v2, replacing the previous configuration with a new \.golangci.yml\ that enables a comprehensive set of linters (including \gosec\, \modernize\, and \gocritic\) and formatters (\gofumpt\, \gci\). To support this, the \Makefile\ and \Makefile.cross-compiles\ have been updated to integrate these tools into the build and formatting workflows. Additionally, \AGENTS.md\ and \CLAUDE.md\ have been added to provide structured development commands and operational runbooks for developers and AI agents, while \.gitignore\ has been expanded to exclude new build artifacts and IDE/AI cache directories.
(repo-wide) · high confidence
Introduce v1 configuration schema and control lifecycle management
This change introduces the v1 configuration schema (pkg/config/v1), defining structured types for authentication (token/oidc), QUIC, web server, logging, and proxy settings, replacing the previous configuration model. Concurrently, the server's control manager (server/control.go) is refactored to manage client connections by run ID, implementing a replacement lifecycle that ensures safe handoffs and prevents control replacement lifecycle leaks when clients reconnect or update their configuration.
github.com/fatedier/frp · high confidence
Introduces Pinia stores for client, proxy, and visitor state management
The frpc dashboard now uses dedicated Pinia stores to manage application state. A new \useResponsive\ composable handles mobile breakpoint detection, while \useClientStore\ manages configuration fetching and reloading. \useProxyStore\ and \useVisitorStore\ provide centralized state for proxy and visitor definitions, including CRUD operations (create, update, delete, toggle) and status synchronization with the backend API.
web/frpc/src/composables, web/frpc/src/stores · high confidence
Introduces v1 configuration schema with strict validation and dynamic value sources
The \pkg/config/v1\ package now provides a new configuration schema for both client and server components, replacing the previous implicit structure with explicit Go types. This change introduces strict JSON decoding that rejects unknown fields when the \DisallowUnknownFields\ option is enabled, ensuring configuration errors are caught early. It also adds support for dynamic configuration values via \ValueSource\, allowing tokens and other secrets to be resolved from files or external commands at runtime. Additionally, the schema defines typed proxy and visitor configurations with deep-copy capabilities and enables granular control over individual proxies and visitors via an \enabled\ field.
pkg/config/v1 · high confidence
NAT traversal now supports user-scoped access control and configurable assisted addresses
The NAT hole discovery and traversal logic in \pkg/nathole\ now enforces per-proxy user restrictions: the controller validates that a visitor's user is explicitly listed in the proxy's \allowUsers\ configuration (or matches a wildcard) before establishing a session, and proxy names on the wire are prefixed with the user identifier to ensure cross-user isolation. Additionally, the \Prepare\ function now exposes a \DisableAssistedAddrs\ option, allowing users to opt out of using local network interface addresses for NAT hole punching when they are not desired.
pkg/nathole · high confidence
New client and proxy management views in the frps dashboard
The frps web dashboard now includes dedicated pages for managing clients and proxies. Users can view a paginated, searchable list of connected clients with online/offline status and drill down into a Client Detail page showing connection stats, protocol version, and associated proxies. A new Proxies page lists all proxies with type-based filtering (TCP, UDP, HTTP, HTTPS, TCPMUX, STCP, XTCP, SUDP), search, pagination, and a 'Clear Offline' action. Proxy Detail pages display configuration, traffic, and connection metrics. These views are powered by the new API v2 endpoints and replace the previous client/proxy listing behavior.
web/frps/src/views · high confidence
New dashboard assets and dark mode support
The frpc dashboard now includes dedicated CSS files for dark mode styling and design variables, along with SVG assets for the application logo and GitHub icon. These changes provide the visual foundation for the redesigned dashboard interface, ensuring consistent theming and layout for form elements across light and dark themes.
web/frpc/src/assets · high confidence
New v1 configuration validation layer with stricter security and feature-gate enforcement
The \pkg/config/v1/validation\ package introduces a comprehensive validation framework for the v1 configuration schema. It enforces mutual exclusivity between \auth.token\ and \auth.tokenSource\, and gates the \exec\ token source behind the \TokenSourceExec\ unsafe feature flag. OIDC configuration now strictly forbids mixing \tokenSource\ with other OIDC fields and validates client credentials. Domain validation rejects custom domains that conflict with the server's subdomain host, including case-insensitive matches. The server validator now rejects negative \transport.maxPoolCount\ values, and proxy/visitor configs enforce required fields and supported protocols.
pkg/config/v1/validation · high confidence
New vhost routing, HTTP/2 support, and TCP muxer implementation
The vhost package now includes a new HTTP reverse proxy that uses the Rewrite function for request modification and supports setting response headers, alongside a new HTTPConnectTCPMuxer that enables TCP multiplexing with optional passthrough mode. The HTTP server now supports unencrypted HTTP/2 (h2c) and the router has been rewritten to use the standard slices and cmp packages for case-insensitive domain matching and sorting. Additionally, the HTTPS muxer now returns an unrecognized\_name SSL alert for unregistered domains, and the HTTP reverse proxy returns a 504 Gateway Timeout instead of 404 for proxy request timeouts.
pkg/util/vhost · high confidence
Redesigned frps dashboard with dark mode and responsive layout
The frps web dashboard has been completely redesigned, introducing a sidebar navigation structure with dedicated sections for Overview, Clients, and Proxies. The interface now supports a dark mode toggle and features a responsive layout that adapts to mobile devices with a collapsible sidebar. This update replaces the previous dashboard implementation with a modern Vue-based architecture.
web/frps/src · high confidence
Refactored TLS configuration and introduced a message transport layer
The transport package now includes a new message transporter that manages request-response cycles using lane keys and message types, allowing for structured dispatching of messages. Additionally, TLS configuration logic has been refactored to support both custom and randomly generated certificates, with improved handling of CA certificates for client verification and server authentication.
pkg/transport · high confidence
Refactored authentication system with deferred OIDC token resolution and caching
The authentication logic in \pkg/auth\ has been restructured to support deferred token resolution and improved OIDC token management. For both client and server sides, authentication configuration is now resolved at runtime via \BuildClientAuth\ and \BuildServerAuth\, allowing dynamic token sources to be evaluated just before use. The OIDC implementation now defers the initial token fetch until the first login attempt, preventing startup failures when the identity provider is temporarily unavailable. Additionally, OIDC access tokens are cached and refreshed before expiry to reduce unnecessary network calls, with an adaptive fallback mechanism that switches to non-caching if the provider does not return an expiry time. The system also enforces OIDC subject consistency by verifying that the subject in ping messages matches the one established during login.
pkg/auth · high confidence
Refactored frontend asset loading to support embedded or disk-based sources
The application's asset management has been restructured to allow frontend files to be served either from embedded memory or from a specified disk directory. Users can now configure the system to load assets from a local path via the \Load\ function, falling back to embedded assets if no path is provided, or serving nothing if neither is available. This change replaces the previous static embedding mechanism with a more flexible approach that supports building without frontend assets via the \noweb\ tag.
assets · high confidence
Refactored server group logic with shared concurrency-safe abstractions
The server/group package has been rewritten to use shared base abstractions (baseGroup, Listener, groupRegistry) that consolidate connection fan-out, lifecycle management, and group registration. This change fixes concurrency issues and port leaks in TCP and HTTPS groups by ensuring a single real listener per group and proper cleanup when the last proxy unregisters, while also introducing an HTTPGroupController that uses round-robin callback routing instead of listener-based grouping.
server/group · high confidence
Server API and control lifecycle refactoring
The server's web interface and API endpoints have been restructured into a dedicated router file, introducing a comprehensive set of v2 API endpoints for system info, client details, proxy traffic, and pruning, alongside updated v1 endpoints for proxy and client management. Concurrently, the control connection handling has been overhauled to support a new wire protocol with binary framing and capability negotiation, including specific support for binary UDP packet codecs. The server also now enforces stricter validation on client pool counts and manages control replacement lifecycles more robustly to prevent resource leaks.
server · high confidence
Server plugin system refactored with HTTPS support and client address injection
The server plugin subsystem has been restructured to support HTTPS connections to external plugin services, including an option to skip TLS certificate verification. Additionally, the Login operation now passes the client's address to plugins, and the plugin manager has been updated to handle plugin errors with appropriate logging levels across different operations.
pkg/plugin/server · high confidence
Server proxy implementation refactored to wire protocol v2
The server proxy logic has been restructured to support the new wire protocol v2. This change introduces a factory-based registration system for proxy types (HTTP, HTTPS, TCP, UDP, STCP, SUDP, XTCP, TCPMux) and updates the connection handling to use v2 message framing. Specifically, the SUDP bridge now transcodes between protocol v1 and v2, and the XTCP NatHoleSid messages are sent using v2 frames, ensuring compatibility and performance improvements for mixed wire protocol environments.
server/proxy · high confidence
UDP proxy now supports Proxy Protocol and handles connection lifecycle correctly
UDP proxies can now prepend a Proxy Protocol header to the first packet of a new connection, allowing backend servers to see the original client IP. The implementation also fixes a bug where the Proxy Protocol header was incorrectly sent on every packet, and ensures that the forwarding goroutines properly terminate when the send channel is closed or errors occur, improving reliability and resource management.
pkg/proto/udp · high confidence
frps CLI restructured with strict config validation and verify command
The frps server command-line interface has been restructured to use the Cobra framework, introducing a new \verify\ subcommand that allows users to check configuration file syntax without starting the server. Configuration loading now defaults to strict parsing mode, where unknown fields cause errors, and the legacy INI format is deprecated in favor of YAML, JSON, or TOML. The CLI also supports an \--allow-unsafe\ flag to explicitly enable specific unsafe features and respects a \--strict\_config\ flag to control parsing strictness.
cmd/frps · high confidence
Test coverage
Added e2e compatibility test suite for wire protocol version negotiation; Added e2e mock stream server for testing; Added e2e port allocation utilities; Added e2e process management and log-waiting utilities; Added e2e test framework constants; Added e2e test helper for TCP half-open connection scenarios; Added e2e test helper for plugin HTTP server; Added e2e tests for SSH tunnel; Added e2e tests for bandwidth limiting, chaos recovery, control replacement, load balancing, heartbeats, monitoring, real IP, SSH tunnels, and store API; Added e2e tests for legacy basic proxy features; Added e2e tests for legacy client and server plugins; Added e2e tests for legacy frp features; Added e2e tests for v1 configuration and core proxy features; Added mock HTTP server for end-to-end testing; Added mock OIDC server for end-to-end testing; Added test utilities for generating and validating self-signed certificates; New E2E test framework using Ginkgo v2; New e2e test framework for FRP; New e2e test helper packages for request simulation and RPC communication; New e2e test infrastructure and compatibility testing scripts.
Dependencies
Upgrade Go dependencies and frontend tooling
The Go module (go.mod) has been updated to Go 1.25.0, upgrading key libraries including quic-go to v0.60.0, golib to v0.8.2, and go-oidc to v3.18.0, while reverting gorilla/websocket to v1.5.0. The frontend web workspace (web/) has been restructured into a monorepo with separate package.json files for frpc and frps dashboards, upgrading Vue to v3.5.40, Vite to v7.3.0, and ESLint to v10.8.0.
(dependencies) · high confidence
Housekeeping
Version bump to v0.71.0
The version string in the version package has been updated to 0.71.0, which will be reported by the Full() function.
pkg/util/version · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 54 → 58 (+4.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 79 → 80 (+1.5)
- Architecture 100 → 84 (-15.9)
- Maturity 70 → 72 (+2.0)
- Readiness 41 → 47 (+6.0)
- Security 56 → 62 (+6.6)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 67 → 67 (+0.0)
Resolved (53)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (pkg/config/types/types.go)
- Duplicated block (11 lines × 2) (client/config_manager.go)
- Duplicated block (11 lines × 2) (cmd/frpc/sub/proxy.go)
- Duplicated block (12 lines × 2) (server/proxy/proxy.go)
- Duplicated block (13 lines × 2) (client/proxy/xtcp.go)
- Duplicated block (16 lines × 2) (client/http/model/proxy_definition.go)
- Duplicated block (5 lines × 2) (client/api_router.go)
- Duplicated block (5 lines × 2) (cmd/frpc/sub/admin.go)
- Duplicated block (7 lines × 2) (client/http/controller.go)
- Duplicated block (7 lines × 2) (pkg/config/load.go)
- Duplicated block (7 lines × 2) (pkg/msg/udp_binary.go)
- Duplicated block (7 lines × 2) (server/proxy/http.go)
- Duplicated block (8 lines × 2) (client/http/controller.go)
- Duplicated block (8 lines × 2) (client/http/controller.go)
- Duplicated block (8 lines × 2) (pkg/auth/auth.go)
- Duplicated block (8 lines × 2) (pkg/config/legacy/conversion.go)
- Duplicated block (9 lines × 2) (client/proxy/sudp.go)
- Duplicated block (9 lines × 2) (pkg/config/legacy/value.go)
- …and 33 more
New (141)
- BaseProxy.HandleTCPWorkConnection (cognitive 20) (client/proxy/proxy.go)
- BaseProxy.HandleTCPWorkConnection (cyclomatic 18) (client/proxy/proxy.go)
- Coverage not measured — JavaScript/TypeScript suite
- Dependency pinned to a stale untagged commit: github.com/armon/go-socks5
- Dependency pinned to a stale untagged commit: github.com/songgao/water
- Dependency pinned to a stale untagged commit: k8s.io/utils
- Duplicated block (10 lines × 2) (client/proxy/udp.go)
- Duplicated block (10 lines × 2) (pkg/config/legacy/value.go)
- Duplicated block (10 lines × 2) (pkg/config/v1/proxy.go)
- Duplicated block (10 lines × 5) (server/proxy/http.go)
- Duplicated block (11 lines × 2) (client/http/controller.go)
- Duplicated block (11 lines × 2) (client/http/controller.go)
- Duplicated block (11 lines × 2) (pkg/auth/auth.go)
- Duplicated block (11 lines × 2) (pkg/config/types/types.go)
- Duplicated block (11 lines × 2) (server/proxy/tcp.go)
- Duplicated block (12 lines × 2) (pkg/sdk/client/client.go)
- Duplicated block (12 lines × 2) (pkg/util/http/handler.go)
- Duplicated block (13 lines × 2) (client/config_manager.go)
- Duplicated block (13 lines × 2) (client/config_manager.go)
- Duplicated block (13 lines × 2) (server/proxy/proxy.go)
- …and 121 more
Changes since last survey
- 17 commits — 15 feature/other, 2 fixes
By area
- (root) — 6 commits
- client/health — 2 commits
- pkg/plugin — 2 commits
- .circleci/config.yml — 1 commit
- .github/workflows — 1 commit
- pkg/config — 1 commit
- pkg/proto — 1 commit
- pkg/ssh — 1 commit
- pkg/util — 1 commit
- web/package-lock.json — 1 commit
Notable commits
- fix: fix(health): reset failed count after successful check (#5502)
- fix: vnet: fix route cleanup and reconnect backoff (#5492)
- change: ci: pin golangci-lint to v2.12.2 (#5496)
- change: ci: upgrade CircleCI config to 2.1 (#5530)
- change: client: reject invalid work connection addresses (#5472)
- change: config: reject case-insensitive subdomain domains (#5474)
- change: deps: migrate to fatedier/yamux v0.2.0 (#5498)
- change: docs: add rapidproxy as gold sponsor (#5529)
- change: docs: add release note for domain validation fix (#5475)
- change: docs: update release notes (#5521)
- change: limit: clamp bandwidth limiter burst (#5471)
- change: log: improve prefix handling (#5489)
- change: ssh: serialize tunnel channel writes (#5473)
- change: test: strengthen health check coverage (#5528)
- change: udp: handle closed forwarding channel (#5470)
- change: vnet: serialize VirtualNet route lifecycle (#5512)
- change: web: patch vulnerable transitive dependencies (#5490)
Architecture
- Unchanged — 0 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
fatedier/frp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d20a232996007dfe6ab425abc0a39a3ae9a0889b — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.