import json import os import config_utils import settings PRO_LICENSE = settings.is_pro() RADIUS_LOG_MAX = 50 RADIUS_LOG_FILE = '/var/log/freeradius/radius.log' def radius_log_tail(cfg): try: log_max_kb = cfg.get('radius', {}).get('general', {}).get('log_max_kb', 1024) current = [] try: with open(RADIUS_LOG_FILE) as f: current = f.readlines() except FileNotFoundError: pass prev = [] if len(current) < RADIUS_LOG_MAX: try: with open(RADIUS_LOG_FILE + '.1') as f: prev = f.readlines() except FileNotFoundError: pass need = max(0, RADIUS_LOG_MAX - len(current)) lines = (prev[-need:] if need and prev else []) + current if not lines: return '(no log entries yet)', '' log_dir = os.path.dirname(RADIUS_LOG_FILE) try: size_kb = sum( os.path.getsize(os.path.join(log_dir, f)) for f in os.listdir(log_dir) if os.path.isfile(os.path.join(log_dir, f)) ) / 1024 except OSError: size_kb = 0.0 tail = lines[-RADIUS_LOG_MAX:] pct = min(100, round(size_kb / log_max_kb * 100)) if log_max_kb else 0 note = ' (includes rotated log)' if (prev and need) else '' left = f'Showing {len(tail)} lines{note}' right = f'Total log size: {size_kb:.1f} KB ({pct}% of max)' summary = ( '
' f'{left}{right}
' ) return ''.join(tail).strip(), summary except Exception: return '(error reading log)', '' def collect_tokens(cfg): tokens = config_utils.collect_layout_tokens(cfg) try: tokens['RADIUS_SECRET'] = open(f'{config_utils.CONFIGS_DIR}/.radius-secret').read().strip() except OSError: tokens['RADIUS_SECRET'] = '(Generation is pending - visit Actions to apply generation command)' fr = cfg.get('radius', {}) fr_opts = fr.get('options', {}) fr_gen = fr.get('general', {}) tokens['RADIUS_MAC_FORMAT'] = fr_opts.get('mac_format', 'aabbccddeeff') tokens['RADIUS_AUTH_MODE'] = fr_opts.get('auth_mode', 'mab') tokens['RADIUS_EAP_PROTOCOL'] = fr_opts.get('eap_protocol', 'eap_peap') tokens['RADIUS_EAP_PROTOCOL_OPTIONS'] = json.dumps([ {'value': 'eap_peap', 'label': 'EAP-PEAP'}, {'value': 'eap_ttls', 'label': 'EAP-TTLS'}, {'value': 'eap_md5', 'label': 'EAP-MD5'}, ]) _eap_proto = fr_opts.get('eap_protocol', 'eap_peap') _inner_opts_peap = [ {'value': 'mschapv2', 'label': 'MSCHAPv2 (Default)'}, {'value': 'md5', 'label': 'MD5'}, {'value': 'gtc', 'label': 'GTC'}, ] _inner_opts_ttls = [ {'value': 'md5', 'label': 'MD5 (Default)'}, {'value': 'mschapv2', 'label': 'MSCHAPv2'}, {'value': 'gtc', 'label': 'GTC'}, ] tokens['RADIUS_INNER_PROTOCOL'] = fr_opts.get('inner_protocol', '') tokens['RADIUS_INNER_PROTOCOL_OPTIONS'] = json.dumps( _inner_opts_ttls if _eap_proto == 'eap_ttls' else _inner_opts_peap ) tokens['RADIUS_PRO_NOTE'] = '' if PRO_LICENSE else '

802.1X authentication modes require a Routlin Pro license.


' pro_suffix = '' if PRO_LICENSE else ' (PRO REQUIRED)' pro_disabled = not PRO_LICENSE tokens['RADIUS_AUTH_MODE_OPTIONS'] = json.dumps([ {'value': 'mab', 'label': 'MAC Authentication Bypass (MAB)'}, {'value': 'eap_password', 'label': f'802.1X - Client Username/Password{pro_suffix}', 'disabled': pro_disabled}, {'value': 'eap_certificate', 'label': f'802.1X - Client Certificate{pro_suffix}', 'disabled': pro_disabled}, ]) tokens['RADIUS_APPLY_TO'] = fr_opts.get('apply_to', 'all') tokens['RADIUS_AP_IPS'] = json.dumps(fr_opts.get('ap_ips', [])) all_radius_clients = [r for r in cfg.get('dhcp_reservations', []) if r.get('radius_client') is True] n = len(all_radius_clients) if n > 0: variant = 'success' text = f"There are currently {n} RADIUS Client{'s' if n != 1 else ''}. RADIUS is enabled." else: variant = 'warning' text = "There are currently 0 RADIUS Clients. RADIUS is disabled." tokens['RADIUS_STATUS_BAR'] = f'
{text}
' radius_client_reservations = [ r for r in all_radius_clients if r.get('ip') and r.get('ip') not in ('', 'dynamic') ] tokens['RADIUS_AP_IPS_OPTIONS'] = json.dumps([ {'value': r['ip'], 'label': f"{r.get('description', r['ip'])} ({r['ip']})"} for r in radius_client_reservations ]) tokens['RADIUS_LOGGING'] = 'true' if fr_gen.get('logging', False) else '' tokens['RADIUS_LOGGING_HINT'] = 'Unchecking will clear logs.' if fr_gen.get('logging', False) else '' tokens['RADIUS_GEN_LOG_MAX_KB'] = str(fr_gen.get('log_max_kb', 1024)) tokens['RADIUS_TUNNELED_REPLY'] = 'true' if fr_opts.get('tunneled_reply', False) else '' tokens['RADIUS_INCLUDE_LENGTH'] = 'true' if fr_opts.get('include_length', False) else '' tokens['RADIUS_MAB_FIRST'] = 'true' if fr_opts.get('mab_first', True) else '' secs = fr_opts.get('default_session_seconds', 0) or 0 if secs >= 86400 and secs % 86400 == 0: tokens['RADIUS_DEFAULT_SESSION_VALUE'] = str(secs // 86400) tokens['RADIUS_DEFAULT_SESSION_UNIT'] = 'days' elif secs > 0: tokens['RADIUS_DEFAULT_SESSION_VALUE'] = str(max(1, round(secs / 3600))) tokens['RADIUS_DEFAULT_SESSION_UNIT'] = 'hours' else: tokens['RADIUS_DEFAULT_SESSION_VALUE'] = '0' tokens['RADIUS_DEFAULT_SESSION_UNIT'] = 'hours' exps = fr_opts.get('default_expiration_seconds', 0) or 0 if exps >= 86400 and exps % 86400 == 0: tokens['RADIUS_DEFAULT_EXPIRATION_VALUE'] = str(exps // 86400) tokens['RADIUS_DEFAULT_EXPIRATION_UNIT'] = 'days' elif exps > 0: tokens['RADIUS_DEFAULT_EXPIRATION_VALUE'] = str(max(1, round(exps / 3600))) tokens['RADIUS_DEFAULT_EXPIRATION_UNIT'] = 'hours' else: tokens['RADIUS_DEFAULT_EXPIRATION_VALUE'] = '0' tokens['RADIUS_DEFAULT_EXPIRATION_UNIT'] = 'hours' vlans = cfg.get('vlans', []) default_vlan = next((v['name'] for v in vlans if v.get('radius_default') is True), '') vlan_options = [{'value': '', 'label': 'None (reject unknown devices)'}] vlan_options += [ {'value': v['name'], 'label': f"{v['name']} (VLAN {v.get('vlan_id', '?')})"} for v in vlans ] tokens['RADIUS_DEFAULT_VLAN'] = default_vlan tokens['RADIUS_DEFAULT_VLAN_OPTIONS'] = json.dumps(vlan_options) tokens['RADIUS_LOG_TAIL'], tokens['RADIUS_LOG_SUMMARY'] = radius_log_tail(cfg) return tokens