Skip to content
Merged

v2.14.0 #5318

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
52 commits
Select commit Hold shift + click to select a range
187d21a
feat: add trust_forwarded_proto option for SSL redirect handling in r…
jerryzone Jan 31, 2026
2b6a617
fix: reformat migration scripts
jerryzone Jan 31, 2026
0547425
fix: Supplement Swagger documentation
jerryzone Jan 31, 2026
232b5b7
fix: make variable name meaningful
jerryzone Jan 31, 2026
21f63e3
fix: delete advanced options from redir_host/dead_host/streams
jerryzone Feb 1, 2026
b7402d4
Merge branch 'NginxProxyManager:develop' into develop
jerry-yuan Feb 3, 2026
7c67faf
Update Slovak translation
dodog Feb 6, 2026
b78ef9b
Add Czech translation and related locale files
MioOgbeni Feb 6, 2026
b552eb9
Add ArvanCloud DNS support
kiaxseventh Feb 9, 2026
304c51a
Bump cypress in /test in the prod-minor-updates group
dependabot[bot] Feb 9, 2026
c910cf9
Bump eslint from 9.39.2 to 10.0.0 in /test
dependabot[bot] Feb 9, 2026
09a3d65
Bump the dev-patch-updates group in /frontend with 2 updates
dependabot[bot] Feb 9, 2026
3f2aec7
Bump vite-tsconfig-paths in /frontend in the dev-minor-updates group
dependabot[bot] Feb 9, 2026
13fbc53
Fix bug when adding invalid custom certs
jc21 Feb 10, 2026
eeab425
fix: unknown "trust_forwarded_proto" variable error when run with alr…
jerryzone Feb 10, 2026
011191f
Merge pull request #5260 from jerry-yuan/develop
jc21 Feb 11, 2026
5fe12f6
Bump axios from 1.13.4 to 1.13.5 in /test
dependabot[bot] Feb 11, 2026
099243a
Bump jsonpath from 1.1.1 to 1.2.1 in /test
dependabot[bot] Feb 12, 2026
1d14f72
Add guardrail for disable 2fa
7heMech Feb 14, 2026
1b64126
Bump qs from 6.14.1 to 6.14.2 in /backend
dependabot[bot] Feb 14, 2026
d92cc95
Bump qs from 6.14.1 to 6.14.2 in /test
dependabot[bot] Feb 14, 2026
a62b6de
Update SQLite client configuration from sqlite3 to better-sqlite3
YTKme Feb 15, 2026
c59c237
Merge pull request #5306 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
fcca481
Merge pull request #5305 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
f3c4648
Merge pull request #5303 from 7heMech/fix-2fa-logout
jc21 Feb 16, 2026
1c189a1
Merge pull request #5300 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
7ff2fc1
Merge pull request #5299 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
010cb56
Merge pull request #5295 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
dbeab93
Merge pull request #5293 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
379099d
Merge pull request #5292 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
41a2a41
Bump @quobix/vacuum
dependabot[bot] Feb 16, 2026
5891c29
Bump eslint-plugin-cypress
dependabot[bot] Feb 16, 2026
7876160
Merge pull request #5289 from kiaxseventh/develop
jc21 Feb 16, 2026
6dcdefb
Merge pull request #5294 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
619a8e5
Merge pull request #5310 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
a90af83
Merge pull request #5309 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 16, 2026
3e5655c
Bump the dev-patch-updates group in /frontend with 3 updates
dependabot[bot] Feb 16, 2026
5601dd1
Bump the prod-minor-updates group in /backend with 3 updates
dependabot[bot] Feb 16, 2026
e5df45e
Merge pull request #5279 from dodog/develop
jc21 Feb 17, 2026
2695452
Merge pull request #5283 from broker-consulting/feat/add-czech-transl…
jc21 Feb 17, 2026
43bc2a7
Add note to docs about retiring armv7 after June 2026
jc21 Feb 17, 2026
a37d0b8
Merge pull request #5308 from YTKme/ytkme/fix-sqlite-internal-error
jc21 Feb 17, 2026
f105673
Merge pull request #5312 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 17, 2026
5916fd5
Merge pull request #5313 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 17, 2026
6c3cc83
Bump the prod-patch-updates group in /frontend with 2 updates
dependabot[bot] Feb 17, 2026
678fdd2
Bump the dev-minor-updates group in /frontend with 2 updates
dependabot[bot] Feb 17, 2026
40f363b
Fix uploading of custom certificates
Tech-no-1 Feb 17, 2026
5f5a387
Drop support for armv7 builds, bump version, update docs
jc21 Feb 17, 2026
aff390f
Merge pull request #5317 from Tech-no-1/fix-custom-certificates
jc21 Feb 17, 2026
fc4c5aa
Merge pull request #5315 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 17, 2026
627f43c
Merge pull request #5314 from NginxProxyManager/dependabot/npm_and_ya…
jc21 Feb 17, 2026
c7437dd
Merge branch 'master' into develop
jc21 Feb 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
2.13.7
2.14.0
17 changes: 10 additions & 7 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<p align="center">
<img src="https://nginxproxymanager.com/github.png">
<br><br>
<img src="https://img.shields.io/badge/version-2.13.7-green.svg?style=for-the-badge">
<img src="https://img.shields.io/badge/version-2.14.0-green.svg?style=for-the-badge">
<a href="https://hub.docker.com/repository/docker/jc21/nginx-proxy-manager">
<img src="https://img.shields.io/docker/stars/jc21/nginx-proxy-manager.svg?style=for-the-badge">
</a>
Expand Down Expand Up @@ -36,23 +36,26 @@ so that the barrier for entry here is low.
- Advanced Nginx configuration available for super users
- User management, permissions and audit log

::: warning
`armv7` is no longer supported in version 2.14+. This is due to Nodejs dropping support for armhf. Please
use the `2.13.7` image tag if this applies to you.
:::

## Hosting your home network

I won't go in to too much detail here but here are the basics for someone new to this self-hosted world.

1. Your home router will have a Port Forwarding section somewhere. Log in and find it
2. Add port forwarding for port 80 and 443 to the server hosting this project
3. Configure your domain name details to point to your home, either with a static ip or a service like DuckDNS or [Amazon Route53](https://github.com/jc21/route53-ddns)
3. Configure your domain name details to point to your home, either with a static ip or a service like
- DuckDNS
- [Amazon Route53](https://github.com/jc21/route53-ddns)
- [Cloudflare](https://github.com/jc21/cloudflare-ddns)
4. Use the Nginx Proxy Manager as your gateway to forward to your other web based services

## Quick Setup

1. Install Docker and Docker-Compose

- [Docker Install documentation](https://docs.docker.com/install/)
- [Docker-Compose Install documentation](https://docs.docker.com/compose/install/)

1. [Install Docker](https://docs.docker.com/install/)
2. Create a docker-compose.yml file similar to this:

```yml
Expand Down
8 changes: 8 additions & 0 deletions backend/certbot/dns-plugins.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,14 @@
"credentials": "dns_aliyun_access_key = 12345678\ndns_aliyun_access_key_secret = 1234567890abcdef1234567890abcdef",
"full_plugin_name": "dns-aliyun"
},
"arvan": {
"name": "ArvanCloud",
"package_name": "certbot-dns-arvan",
"version": ">=0.1.0",
"dependencies": "",
"credentials": "dns_arvan_key = Apikey xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"full_plugin_name": "dns-arvan"
},
"azure": {
"name": "Azure",
"package_name": "certbot-dns-azure",
Expand Down
2 changes: 1 addition & 1 deletion backend/config/sqlite-test-db.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"database": {
"engine": "knex-native",
"knex": {
"client": "sqlite3",
"client": "better-sqlite3",
"connection": {
"filename": "/app/config/mydb.sqlite"
},
Expand Down
9 changes: 6 additions & 3 deletions backend/internal/2fa.js
Original file line number Diff line number Diff line change
Expand Up @@ -161,9 +161,12 @@ const internal2fa = {
}

const result = await verify({
token: code,
secret: auth.meta.totp_secret,
});
token: code,
secret: auth.meta.totp_secret,
guardrails: createGuardrails({
MIN_SECRET_BYTES: 10,
}),
});

if (!result.valid) {
throw new errs.AuthError("Invalid verification code");
Expand Down
4 changes: 2 additions & 2 deletions backend/internal/certificate.js
Original file line number Diff line number Diff line change
Expand Up @@ -630,7 +630,7 @@ const internalCertificate = {
* @param {String} privateKey This is the entire key contents as a string
*/
checkPrivateKey: async (privateKey) => {
const filepath = await tempWrite(privateKey, "/tmp");
const filepath = await tempWrite(privateKey);
const failTimeout = setTimeout(() => {
throw new error.ValidationError(
"Result Validation Error: Validation timed out. This could be due to the key being passphrase-protected.",
Expand Down Expand Up @@ -660,8 +660,8 @@ const internalCertificate = {
* @param {Boolean} [throwExpired] Throw when the certificate is out of date
*/
getCertificateInfo: async (certificate, throwExpired) => {
const filepath = await tempWrite(certificate);
try {
const filepath = await tempWrite(certificate, "/tmp");
const certData = await internalCertificate.getCertificateInfoFromFile(filepath, throwExpired);
fs.unlinkSync(filepath);
return certData;
Expand Down
43 changes: 43 additions & 0 deletions backend/migrations/20260131163528_trust_forwarded_proto.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
import { migrate as logger } from "../logger.js";

const migrateName = "trust_forwarded_proto";

/**
* Migrate
*
* @see http://knexjs.org/#Schema
*
* @param {Object} knex
* @returns {Promise}
*/
const up = function (knex) {
logger.info(`[${migrateName}] Migrating Up...`);

return knex.schema
.alterTable('proxy_host', (table) => {
table.tinyint('trust_forwarded_proto').notNullable().defaultTo(0);
})
.then(() => {
logger.info(`[${migrateName}] proxy_host Table altered`);
});
};

/**
* Undo Migrate
*
* @param {Object} knex
* @returns {Promise}
*/
const down = function (knex) {
logger.info(`[${migrateName}] Migrating Down...`);

return knex.schema
.alterTable('proxy_host', (table) => {
table.dropColumn('trust_forwarded_proto');
})
.then(() => {
logger.info(`[${migrateName}] proxy_host Table altered`);
});
};

export { up, down };
1 change: 1 addition & 0 deletions backend/models/proxy_host.js
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ const boolFields = [
"enabled",
"hsts_enabled",
"hsts_subdomains",
"trust_forwarded_proto",
];

class ProxyHost extends Model {
Expand Down
6 changes: 3 additions & 3 deletions backend/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
},
"dependencies": {
"@apidevtools/json-schema-ref-parser": "^14.1.1",
"ajv": "^8.17.1",
"ajv": "^8.18.0",
"archiver": "^7.0.1",
"batchflow": "^0.4.0",
"bcrypt": "^6.0.0",
Expand All @@ -28,10 +28,10 @@
"liquidjs": "10.24.0",
"lodash": "^4.17.23",
"moment": "^2.30.1",
"mysql2": "^3.16.3",
"mysql2": "^3.17.1",
"node-rsa": "^1.1.1",
"objection": "3.1.5",
"otplib": "^13.2.1",
"otplib": "^13.3.0",
"path": "^0.12.7",
"pg": "^8.18.0",
"proxy-agent": "^6.5.0",
Expand Down
8 changes: 7 additions & 1 deletion backend/schema/components/proxy-host-object.json
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,8 @@
"enabled",
"locations",
"hsts_enabled",
"hsts_subdomains"
"hsts_subdomains",
"trust_forwarded_proto"
],
"properties": {
"id": {
Expand Down Expand Up @@ -141,6 +142,11 @@
"hsts_subdomains": {
"$ref": "../common.json#/properties/hsts_subdomains"
},
"trust_forwarded_proto":{
"type": "boolean",
"description": "Trust the forwarded headers",
"example": false
},
"certificate": {
"oneOf": [
{
Expand Down
3 changes: 2 additions & 1 deletion backend/schema/paths/nginx/proxy-hosts/get.json
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,8 @@
"enabled": true,
"locations": [],
"hsts_enabled": false,
"hsts_subdomains": false
"hsts_subdomains": false,
"trust_forwarded_proto": false
}
]
}
Expand Down
1 change: 1 addition & 0 deletions backend/schema/paths/nginx/proxy-hosts/hostID/get.json
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@
"locations": [],
"hsts_enabled": false,
"hsts_subdomains": false,
"trust_forwarded_proto": false,
"owner": {
"id": 1,
"created_on": "2025-10-28T00:50:24.000Z",
Expand Down
4 changes: 4 additions & 0 deletions backend/schema/paths/nginx/proxy-hosts/hostID/put.json
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,9 @@
"hsts_subdomains": {
"$ref": "../../../../components/proxy-host-object.json#/properties/hsts_subdomains"
},
"trust_forwarded_proto": {
"$ref": "../../../../components/proxy-host-object.json#/properties/trust_forwarded_proto"
},
"http2_support": {
"$ref": "../../../../components/proxy-host-object.json#/properties/http2_support"
},
Expand Down Expand Up @@ -122,6 +125,7 @@
"locations": [],
"hsts_enabled": false,
"hsts_subdomains": false,
"trust_forwarded_proto": false,
"owner": {
"id": 1,
"created_on": "2025-10-28T00:50:24.000Z",
Expand Down
4 changes: 4 additions & 0 deletions backend/schema/paths/nginx/proxy-hosts/post.json
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,9 @@
"hsts_subdomains": {
"$ref": "../../../components/proxy-host-object.json#/properties/hsts_subdomains"
},
"trust_forwarded_proto": {
"$ref": "../../../components/proxy-host-object.json#/properties/trust_forwarded_proto"
},
"http2_support": {
"$ref": "../../../components/proxy-host-object.json#/properties/http2_support"
},
Expand Down Expand Up @@ -119,6 +122,7 @@
"locations": [],
"hsts_enabled": false,
"hsts_subdomains": false,
"trust_forwarded_proto": false,
"certificate": null,
"owner": {
"id": 1,
Expand Down
5 changes: 5 additions & 0 deletions backend/templates/_forced_ssl.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,11 @@
{% if certificate and certificate_id > 0 -%}
{% if ssl_forced == 1 or ssl_forced == true %}
# Force SSL
{% if trust_forwarded_proto == true %}
set $trust_forwarded_proto "T";
{% else %}
set $trust_forwarded_proto "F";
{% endif %}
include conf.d/include/force-ssl.conf;
{% endif %}
{% endif %}
Loading
Loading