travelping/eradius
36.3
Weak · 2 October 2026
4.7k
lines of production code
Erlang
primary language
2
measurements over time
What this system is
This system is an Erlang-based RADIUS server and client library that handles authentication, accounting, and authorization protocols. It supports modern RADIUS features including IPv6, Change of Authorization (CoA), and EAP, while providing helper modules for various password validation methods. The system exposes operational metrics via Prometheus and includes a sample server implementation for testing and reference.
Features
Introduce Prometheus metrics collector application
A new application, eradius\_prometheus\_collector, has been added to the system to handle metrics collection. This change introduces a dependency on the Prometheus Erlang client library (version 4.10.0), enabling the application to expose metrics in the Prometheus format. This replaces the previous exometer-based metrics implementation.
applications · high confidence
Introduction of a dedicated RADIUS client and authentication helper modules
This change introduces \eradius\_client\, a new supervised gen\_server that handles outgoing RADIUS requests with configurable retries, timeouts, and failover support across multiple upstream servers. It also adds \eradius\_auth\, a new module providing helper functions for validating user passwords via PAP, CHAP, MS-CHAP, and MS-CHAPv2 mechanisms, including support for salt encryption and NT-hash generation. Additionally, \eradius\_eap\_packet\ is added to handle encoding and decoding of EAP messages according to RFC-3748, supporting standard types like Identity, MD5-Challenge, and GTC, as well as vendor-specific expanded types.
src · high confidence
RADIUS protocol support expanded with CoA/Disconnect and internal record restructuring
The RADIUS library now supports Change of Authorization (CoA) and Disconnect protocol messages, adding new packet type definitions (RDisconnect\_Request/Ack/Nak and RCoa\_Request/Ack/Nak) and corresponding statistics counters for tracking these interactions. The internal data structures have been significantly reworked: the old dictionary definitions in dictionary.hrl and eradius.hrl have been removed, while eradius\_dict.hrl and eradius\_lib.hrl now use modern Erlang type specs and updated record definitions (such as client\_counter) to support these new features and improve type safety.
include · high confidence
Removals
Removal of Debian packaging infrastructure
The project has removed all Debian packaging files, including the build rules, control metadata, changelog, copyright, and maintainer scripts (postinst, postrm, prerm). This means the software will no longer be built or distributed as a native Debian/Ubuntu package.
debian · high confidence
Removal of legacy application resource file
The eradius.app file, which defined the application metadata including version 0.0.0, module list, and dependencies, has been removed from the ebin directory. This change eliminates the legacy application resource definition, likely as part of a broader cleanup or migration away from the previous packaging structure.
ebin · high confidence
Behavioural changes
Expanded RADIUS dictionary support and IPv6 type corrections
The RADIUS dictionary has been significantly expanded with new vendor definitions for 3GPP, Alcatel-Lucent Service Router, APC, Ituma, Ruckus, Starent, and ADSL Forum (RFC 4679), alongside updates to existing dictionaries for Travelping, WISPr, and Alcatel. The core dictionary now correctly interprets NAS-IPv6-Address, Framed-IPv6-Prefix, and Login-IPv6-Host as native IPv6 types rather than generic octets, and includes new Acct-Terminate-Cause values for Lost Power and Volume Exhausted. Additionally, compatibility attributes like Login-Host have been removed, and various typos and case inconsistencies in vendor attributes have been corrected.
priv/dictionaries · high confidence
Replace exometer with Prometheus for RADIUS metrics
The RADIUS metrics collector has switched from the exometer library to the prometheus library. This change introduces a new application module that implements the prometheus\_collector behavior, exposing a comprehensive set of counters and gauges for server and client activity (such as requests, replies, and accounting events). Additionally, histogram values are now returned as cumulative totals to align with Prometheus best practices, and accounting metrics are divided by type (start, stop, update) for more granular monitoring.
_applications/eradius\_prometheus\collector · high confidence
Reworked RADIUS sample server implementation
The sample application has been updated to use the modern eradius server behavior. The previous example file (eradius\_server\_example.erl), which implemented manual PAP/CHAP authentication logic, has been removed. It is replaced by a new sample module (eradius\_server\_sample.erl) that implements the eradius\_server behavior, providing a simplified request handler and a built-in performance test function. The project structure now includes a standard rebar.config dependency on eradius and an example configuration file for local testing.
sample · high confidence
Switch to Erlang OTP Logger and add development configuration
The application now uses the standard Erlang OTP logger instead of the external lager library, with a new dev.config file providing default logging settings (info level, queue lengths) and RADIUS server environment variables. The previous priv/Makefile for generating dictionary maps has been removed, indicating a shift in how build artifacts or configuration files are handled.
priv · medium confidence
Test coverage
Added comprehensive Common Test suites for authentication, client, configuration, library, metrics, and proxy components
This change introduces a new suite of Common Test (CT) test cases to verify core RADIUS functionality. The \eradius\_auth\_SUITE\ tests validate password hashing, Unicode handling, and MPPE key generation. The \eradius\_client\_SUITE\ and \eradius\_client\_socket\_test\ verify client socket management, request sending, and failover logic. Configuration validation is covered by \eradius\_config\_SUITE\, including socket options and NAS IP ranges. The \eradius\_lib\_SUITE\ tests cover RADIUS attribute encoding/decoding, IPv6 prefixes, and Ascend encryption. Metrics integration with Prometheus is tested in \eradius\_metrics\_SUITE\, and proxy routing logic is validated in \eradius\_proxy\_SUITE\. A new \eradius\_logtest\ module provides an end-to-end logging and proxy test harness.
test · high confidence
Dependencies
Migrate build system from rebar2 to rebar3
The project has replaced the legacy Makefile and rebar2 build setup with rebar3. This change introduces a new rebar.config that enforces a minimum Erlang/OTP version of 22, configures pre- and post-compile hooks to run the dictionary compiler (dicts\_compiler.erl), and moves the meck testing dependency to the test profile. Legacy build artifacts such as the Emakefile, Makefile, and master.mk have been removed, and the .gitignore has been updated to reflect the new build output directories and lockfiles.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 36 → 36 (+0.3)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 95 → 95 (+0.0)
- Architecture 100 → 100 (+0.0)
- Maturity 55 → 53 (-2.5)
- Readiness 45 → 45 (+0.0)
- Security 65 → 74 (+8.7)
- Event-Driven 10 → 10 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
Resolved (4)
- Coverage not measured — no coverage collector is wired up
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1
New (6)
- Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
- No dependency lockfile committed (applications/eradius_prometheus_collector/rebar.config)
- No dependency lockfile committed (sample/rebar.config)
- Off-boarding risk: anonymized user #1
- Orphaned knowledge (src/eradius_lib.erl)
- Unbounded dependency requirement: eradius
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
travelping/eradius was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 343daab128a78e6e0ead979fa803cf8c496b1c45 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.