Skip to content
CAI
Software that uses CAICheck a score

travelping/eradius

36.3

Weak · 2 October 2026

4.7k

lines of production code

Erlang

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Erlang-based RADIUS server and client library that handles authentication, accounting, and authorization protocols. It supports modern RADIUS features including IPv6, Change of Authorization (CoA), and EAP, while providing helper modules for various password validation methods. The system exposes operational metrics via Prometheus and includes a sample server implementation for testing and reference.

Features

Introduce Prometheus metrics collector application

A new application, eradius\_prometheus\_collector, has been added to the system to handle metrics collection. This change introduces a dependency on the Prometheus Erlang client library (version 4.10.0), enabling the application to expose metrics in the Prometheus format. This replaces the previous exometer-based metrics implementation.

applications · high confidence

Introduction of a dedicated RADIUS client and authentication helper modules

This change introduces \eradius\_client\, a new supervised gen\_server that handles outgoing RADIUS requests with configurable retries, timeouts, and failover support across multiple upstream servers. It also adds \eradius\_auth\, a new module providing helper functions for validating user passwords via PAP, CHAP, MS-CHAP, and MS-CHAPv2 mechanisms, including support for salt encryption and NT-hash generation. Additionally, \eradius\_eap\_packet\ is added to handle encoding and decoding of EAP messages according to RFC-3748, supporting standard types like Identity, MD5-Challenge, and GTC, as well as vendor-specific expanded types.

src · high confidence

RADIUS protocol support expanded with CoA/Disconnect and internal record restructuring

The RADIUS library now supports Change of Authorization (CoA) and Disconnect protocol messages, adding new packet type definitions (RDisconnect\_Request/Ack/Nak and RCoa\_Request/Ack/Nak) and corresponding statistics counters for tracking these interactions. The internal data structures have been significantly reworked: the old dictionary definitions in dictionary.hrl and eradius.hrl have been removed, while eradius\_dict.hrl and eradius\_lib.hrl now use modern Erlang type specs and updated record definitions (such as client\_counter) to support these new features and improve type safety.

include · high confidence

Removals

Removal of Debian packaging infrastructure

The project has removed all Debian packaging files, including the build rules, control metadata, changelog, copyright, and maintainer scripts (postinst, postrm, prerm). This means the software will no longer be built or distributed as a native Debian/Ubuntu package.

debian · high confidence

Removal of legacy application resource file

The eradius.app file, which defined the application metadata including version 0.0.0, module list, and dependencies, has been removed from the ebin directory. This change eliminates the legacy application resource definition, likely as part of a broader cleanup or migration away from the previous packaging structure.

ebin · high confidence

Behavioural changes

Expanded RADIUS dictionary support and IPv6 type corrections

The RADIUS dictionary has been significantly expanded with new vendor definitions for 3GPP, Alcatel-Lucent Service Router, APC, Ituma, Ruckus, Starent, and ADSL Forum (RFC 4679), alongside updates to existing dictionaries for Travelping, WISPr, and Alcatel. The core dictionary now correctly interprets NAS-IPv6-Address, Framed-IPv6-Prefix, and Login-IPv6-Host as native IPv6 types rather than generic octets, and includes new Acct-Terminate-Cause values for Lost Power and Volume Exhausted. Additionally, compatibility attributes like Login-Host have been removed, and various typos and case inconsistencies in vendor attributes have been corrected.

priv/dictionaries · high confidence

Replace exometer with Prometheus for RADIUS metrics

The RADIUS metrics collector has switched from the exometer library to the prometheus library. This change introduces a new application module that implements the prometheus\_collector behavior, exposing a comprehensive set of counters and gauges for server and client activity (such as requests, replies, and accounting events). Additionally, histogram values are now returned as cumulative totals to align with Prometheus best practices, and accounting metrics are divided by type (start, stop, update) for more granular monitoring.

_applications/eradius\_prometheus\collector · high confidence

Reworked RADIUS sample server implementation

The sample application has been updated to use the modern eradius server behavior. The previous example file (eradius\_server\_example.erl), which implemented manual PAP/CHAP authentication logic, has been removed. It is replaced by a new sample module (eradius\_server\_sample.erl) that implements the eradius\_server behavior, providing a simplified request handler and a built-in performance test function. The project structure now includes a standard rebar.config dependency on eradius and an example configuration file for local testing.

sample · high confidence

Switch to Erlang OTP Logger and add development configuration

The application now uses the standard Erlang OTP logger instead of the external lager library, with a new dev.config file providing default logging settings (info level, queue lengths) and RADIUS server environment variables. The previous priv/Makefile for generating dictionary maps has been removed, indicating a shift in how build artifacts or configuration files are handled.

priv · medium confidence

Test coverage

Added comprehensive Common Test suites for authentication, client, configuration, library, metrics, and proxy components

This change introduces a new suite of Common Test (CT) test cases to verify core RADIUS functionality. The \eradius\_auth\_SUITE\ tests validate password hashing, Unicode handling, and MPPE key generation. The \eradius\_client\_SUITE\ and \eradius\_client\_socket\_test\ verify client socket management, request sending, and failover logic. Configuration validation is covered by \eradius\_config\_SUITE\, including socket options and NAS IP ranges. The \eradius\_lib\_SUITE\ tests cover RADIUS attribute encoding/decoding, IPv6 prefixes, and Ascend encryption. Metrics integration with Prometheus is tested in \eradius\_metrics\_SUITE\, and proxy routing logic is validated in \eradius\_proxy\_SUITE\. A new \eradius\_logtest\ module provides an end-to-end logging and proxy test harness.

test · high confidence

Dependencies

Migrate build system from rebar2 to rebar3

The project has replaced the legacy Makefile and rebar2 build setup with rebar3. This change introduces a new rebar.config that enforces a minimum Erlang/OTP version of 22, configures pre- and post-compile hooks to run the dictionary compiler (dicts\_compiler.erl), and moves the meck testing dependency to the test profile. Legacy build artifacts such as the Emakefile, Makefile, and master.mk have been removed, and the .gitignore has been updated to reflect the new build output directories and lockfiles.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 36 → 36 (+0.3)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 95 → 95 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 55 → 53 (-2.5)
  • Readiness 45 → 45 (+0.0)
  • Security 65 → 74 (+8.7)
  • Event-Driven 10 → 10 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (4)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1

New (6)

  • Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
  • No dependency lockfile committed (applications/eradius_prometheus_collector/rebar.config)
  • No dependency lockfile committed (sample/rebar.config)
  • Off-boarding risk: anonymized user #1
  • Orphaned knowledge (src/eradius_lib.erl)
  • Unbounded dependency requirement: eradius

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

travelping/eradius was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 343daab128a78e6e0ead979fa803cf8c496b1c45 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.