feat(freeradius): add NAS client and user CRUD driver methods
CI / test (3.10) (push) Failing after 7s
CI / test (3.11) (push) Failing after 7s
CI / test (3.12) (push) Failing after 8s
CI / test (3.9) (push) Failing after 7s

get/create/delete_radius_client and get/create/delete_radius_user, backed
by /api/freeradius/{client,user}/{search,add,del}_* and a reconfigure call
to apply changes. Endpoints and field names (client.ip, not ipaddr) verified
against a live OPNsense 24.7 instance via a real add -> search/get -> set ->
del round trip, cleaned up immediately after.
This commit is contained in:
Christian Manivong
2026-07-15 15:26:05 +02:00
parent c8caa14176
commit e51607a020
2 changed files with 250 additions and 0 deletions
+83
View File
@@ -1118,6 +1118,89 @@ class OPNsenseDriver(FirewallDriver):
"running": status.get("status") == "running",
}
def get_radius_clients(self) -> list[dict[str, Any]]:
"""Return configured FreeRADIUS NAS clients.
Calls ``GET /api/freeradius/client/search_client``.
"""
try:
data = self._get("/api/freeradius/client/search_client")
except Exception as exc:
logger.warning("get_radius_clients() failed: %s", exc)
return []
return [
{
"id": row.get("uuid", ""),
"name": row.get("name", ""),
"ip": row.get("ip", ""),
"enabled": row.get("enabled") == "1",
}
for row in data.get("rows", [])
]
def create_radius_client(self, name: str, ip: str, secret: str) -> dict[str, Any]:
"""Create a FreeRADIUS NAS client and apply the change.
Calls ``POST /api/freeradius/client/add_client``, then
``POST /api/freeradius/service/reconfigure`` to apply -- a saved
client has no effect on the running radiusd until reconfigured.
"""
payload = {"client": {"name": name, "ip": ip, "secret": secret}}
result = self._post("/api/freeradius/client/add_client", payload)
if result.get("result") != "saved":
return {"success": False, "validations": result.get("validations", {})}
self._post("/api/freeradius/service/reconfigure")
return {"success": True}
def delete_radius_client(self, client_id: str) -> dict[str, Any]:
"""Delete a FreeRADIUS NAS client by uuid and apply the change."""
result = self._post(f"/api/freeradius/client/del_client/{client_id}")
if result.get("result") != "deleted":
return {"success": False}
self._post("/api/freeradius/service/reconfigure")
return {"success": True}
def get_radius_users(self) -> list[dict[str, Any]]:
"""Return configured FreeRADIUS users.
Calls ``GET /api/freeradius/user/search_user``. Never includes the
password field.
"""
try:
data = self._get("/api/freeradius/user/search_user")
except Exception as exc:
logger.warning("get_radius_users() failed: %s", exc)
return []
return [
{
"id": row.get("uuid", ""),
"username": row.get("username", ""),
"enabled": row.get("enabled") == "1",
}
for row in data.get("rows", [])
]
def create_radius_user(self, username: str, password: str) -> dict[str, Any]:
"""Create a FreeRADIUS user and apply the change.
Calls ``POST /api/freeradius/user/add_user``, then
``POST /api/freeradius/service/reconfigure`` to apply.
"""
payload = {"user": {"username": username, "password": password}}
result = self._post("/api/freeradius/user/add_user", payload)
if result.get("result") != "saved":
return {"success": False, "validations": result.get("validations", {})}
self._post("/api/freeradius/service/reconfigure")
return {"success": True}
def delete_radius_user(self, user_id: str) -> dict[str, Any]:
"""Delete a FreeRADIUS user by uuid and apply the change."""
result = self._post(f"/api/freeradius/user/del_user/{user_id}")
if result.get("result") != "deleted":
return {"success": False}
self._post("/api/freeradius/service/reconfigure")
return {"success": True}
def get_dhcp_leases(self) -> list[dict[str, Any]]:
"""Return active DHCP leases from OPNsense.