big update all menus
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
<?php
|
||||
namespace App\Services\Nas;
|
||||
use App\Models\CustomerNasAccount;
|
||||
use App\Models\NasPackageProfile;
|
||||
|
||||
class CustomerAccountReconciliationService
|
||||
{
|
||||
public function __construct(protected RouterOsApiService $routerOs) {}
|
||||
public function reconcile(CustomerNasAccount $account): void
|
||||
{
|
||||
$account->load(['mikrotik','packageProfile']);
|
||||
if ($account->mikrotik->connection_type !== 'api') return;
|
||||
$state = $this->routerOs->inspectAccount($account->mikrotik,$account->service_type,$account->username);
|
||||
$active = $state['active'];
|
||||
$uptime = max(
|
||||
$this->durationSeconds($active['uptime'] ?? ''),
|
||||
$this->durationSeconds($state['account']['uptime'] ?? '')
|
||||
);
|
||||
$bytes = max(
|
||||
(int) ($active['bytes-in'] ?? 0) + (int) ($active['bytes-out'] ?? 0),
|
||||
(int) ($state['account']['bytes-in'] ?? 0) + (int) ($state['account']['bytes-out'] ?? 0)
|
||||
);
|
||||
$updates=['remote_state'=>$state,'used_uptime_seconds'=>$uptime,'used_bytes'=>$bytes,'last_reconciled_at'=>now(),'last_sync_error'=>null];
|
||||
if ($active && ! $account->first_login_at) {
|
||||
$updates['first_login_at']=now();
|
||||
if ($account->packageProfile->validity_start === 'first_login') { $updates['validity_started_at']=now(); $updates['expires_at']=$this->expiry($account->packageProfile); }
|
||||
}
|
||||
$expires=$updates['expires_at'] ?? $account->expires_at;
|
||||
$expiresWithGrace = $expires?->copy()->addMinutes((int) $account->packageProfile->grace_period_minutes);
|
||||
$limitReached=($expiresWithGrace && now()->gte($expiresWithGrace)) || ($account->packageProfile->uptime_limit_seconds && $uptime >= $account->packageProfile->uptime_limit_seconds) || ($account->packageProfile->data_limit_bytes && $bytes >= $account->packageProfile->data_limit_bytes);
|
||||
if ($limitReached && $account->status === 'active') {
|
||||
$this->routerOs->setEnabled($account->mikrotik,$account->service_type,$account->username,false);
|
||||
$this->routerOs->disconnectAccount($account->mikrotik,$account->service_type,$account->username);
|
||||
$updates['status']='expired';
|
||||
}
|
||||
$account->update($updates);
|
||||
}
|
||||
private function durationSeconds(string $value): int { preg_match_all('/(\d+)(w|d|h|m|s)/',$value,$m,PREG_SET_ORDER); $map=['w'=>604800,'d'=>86400,'h'=>3600,'m'=>60,'s'=>1]; return array_sum(array_map(fn($x)=>(int)$x[1]*$map[$x[2]],$m)); }
|
||||
private function expiry(NasPackageProfile $p) { if(!$p->validity_value||!$p->validity_unit)return null; return match($p->validity_unit){'minutes'=>now()->addMinutes($p->validity_value),'hours'=>now()->addHours($p->validity_value),'days'=>now()->addDays($p->validity_value),'months'=>now()->addMonths($p->validity_value),default=>null}; }
|
||||
}
|
||||
@@ -0,0 +1,160 @@
|
||||
<?php
|
||||
|
||||
namespace App\Services\Nas;
|
||||
|
||||
use App\Models\Customer;
|
||||
use App\Models\CustomerNasAccount;
|
||||
use App\Models\NasMikrotik;
|
||||
use App\Models\NasPackageProfile;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
use Throwable;
|
||||
use Illuminate\Support\Carbon;
|
||||
|
||||
class CustomerRouterOsProvisioningService
|
||||
{
|
||||
public function __construct(
|
||||
protected RouterOsApiService $routerOs,
|
||||
protected PackageProfileDeploymentService $deployments,
|
||||
) {}
|
||||
|
||||
public function create(Customer $customer, array $data): CustomerNasAccount
|
||||
{
|
||||
[$mikrotik, $profile] = $this->resources($customer, $data);
|
||||
if ($mikrotik->connection_type !== 'api') {
|
||||
throw ValidationException::withMessages(['nas_mikrotik_id' => 'Tahap ini hanya mendukung Mikrotik dengan koneksi API.']);
|
||||
}
|
||||
$target = $this->deployments->assertSynced($profile, $mikrotik);
|
||||
|
||||
$username = trim((string) ($data['external_username'] ?? ''));
|
||||
$password = (string) ($data['external_password'] ?? '');
|
||||
if ($username === '' || $password === '') {
|
||||
throw ValidationException::withMessages(['external_username' => 'Username dan password RouterOS wajib diisi.']);
|
||||
}
|
||||
|
||||
$remote = $this->routerOs->createAccount($mikrotik, $profile->service_type, [
|
||||
'username' => $username,
|
||||
'password' => $password,
|
||||
'profile' => $target->external_profile_name,
|
||||
'comment' => $this->comment($customer),
|
||||
'disabled' => 'no',
|
||||
]);
|
||||
|
||||
try {
|
||||
return DB::transaction(fn () => CustomerNasAccount::create([
|
||||
'tenant_id' => $customer->tenant_id,
|
||||
'customer_id' => $customer->id,
|
||||
'nas_mikrotik_id' => $mikrotik->id,
|
||||
'nas_package_profile_id' => $profile->id,
|
||||
'nas_package_profile_target_id' => $target->id,
|
||||
'service_type' => $profile->service_type,
|
||||
'usage_mode' => $profile->usage_mode,
|
||||
'username' => $username,
|
||||
'password' => $password,
|
||||
'mac_address' => $data['mac_address'] ?? null,
|
||||
'serial_number' => $data['serial_number'] ?? null,
|
||||
'assigned_ip' => $data['assigned_ip'] ?? null,
|
||||
'remote_id' => $remote['.id'] ?? null,
|
||||
'remote_profile' => $target->external_profile_name,
|
||||
'status' => 'active',
|
||||
'validity_started_at' => $profile->validity_start === 'activation' ? now() : null,
|
||||
'expires_at' => $profile->validity_start === 'activation' ? $this->expiresAt($profile) : null,
|
||||
'last_synced_at' => now(),
|
||||
]));
|
||||
} catch (Throwable $exception) {
|
||||
try {
|
||||
$this->routerOs->deleteAccount($mikrotik, $profile->service_type, $username);
|
||||
} catch (Throwable) {
|
||||
// Compensating delete is best effort; original database error remains authoritative.
|
||||
}
|
||||
throw $exception;
|
||||
}
|
||||
}
|
||||
|
||||
public function setEnabled(Customer $customer, bool $enabled): CustomerNasAccount
|
||||
{
|
||||
$account = $this->account($customer);
|
||||
$remote = $this->routerOs->setEnabled(
|
||||
$account->mikrotik,
|
||||
$account->service_type,
|
||||
$account->username,
|
||||
$enabled,
|
||||
);
|
||||
$account->update([
|
||||
'remote_id' => $remote['.id'] ?? $account->remote_id,
|
||||
'status' => $enabled ? 'active' : 'disabled',
|
||||
'last_synced_at' => now(),
|
||||
'last_sync_error' => null,
|
||||
]);
|
||||
|
||||
return $account->fresh();
|
||||
}
|
||||
|
||||
public function update(Customer $customer, array $attributes): CustomerNasAccount
|
||||
{
|
||||
$account = $this->account($customer);
|
||||
$remote = $this->routerOs->updateAccount(
|
||||
$account->mikrotik,
|
||||
$account->service_type,
|
||||
$account->username,
|
||||
$attributes,
|
||||
);
|
||||
$account->update([
|
||||
'username' => $attributes['username'] ?? $account->username,
|
||||
'password' => $attributes['password'] ?? $account->password,
|
||||
'remote_profile' => $attributes['profile'] ?? $account->remote_profile,
|
||||
'remote_id' => $remote['.id'] ?? $account->remote_id,
|
||||
'last_synced_at' => now(),
|
||||
'last_sync_error' => null,
|
||||
]);
|
||||
|
||||
return $account->fresh();
|
||||
}
|
||||
|
||||
public function delete(Customer $customer): void
|
||||
{
|
||||
$account = $customer->nasAccount()->with('mikrotik')->first();
|
||||
if (! $account) {
|
||||
return;
|
||||
}
|
||||
$this->routerOs->deleteAccount($account->mikrotik, $account->service_type, $account->username);
|
||||
$account->delete();
|
||||
}
|
||||
|
||||
private function resources(Customer $customer, array $data): array
|
||||
{
|
||||
$mikrotik = NasMikrotik::whereKey($data['nas_mikrotik_id'])
|
||||
->where('tenant_id', $customer->tenant_id)->firstOrFail();
|
||||
$profile = NasPackageProfile::whereKey($data['package_profile_id'])
|
||||
->where('tenant_id', $customer->tenant_id)->firstOrFail();
|
||||
|
||||
return [$mikrotik, $profile];
|
||||
}
|
||||
|
||||
private function account(Customer $customer): CustomerNasAccount
|
||||
{
|
||||
$account = $customer->nasAccount()->with('mikrotik')->first();
|
||||
if (! $account) {
|
||||
throw ValidationException::withMessages(['nas_account' => 'Akun RouterOS customer belum tercatat.']);
|
||||
}
|
||||
|
||||
return $account;
|
||||
}
|
||||
|
||||
private function comment(Customer $customer): string
|
||||
{
|
||||
return "ManjaPro | {$customer->customer_code} | {$customer->name}";
|
||||
}
|
||||
|
||||
private function expiresAt(NasPackageProfile $profile): ?Carbon
|
||||
{
|
||||
if (! $profile->validity_value || ! $profile->validity_unit) return null;
|
||||
return match ($profile->validity_unit) {
|
||||
'minutes' => now()->addMinutes($profile->validity_value),
|
||||
'hours' => now()->addHours($profile->validity_value),
|
||||
'days' => now()->addDays($profile->validity_value),
|
||||
'months' => now()->addMonths($profile->validity_value),
|
||||
default => null,
|
||||
};
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,60 @@
|
||||
<?php
|
||||
|
||||
namespace App\Services\Nas;
|
||||
|
||||
use App\Models\NasMikrotik;
|
||||
use Throwable;
|
||||
|
||||
class MikrotikHealthService
|
||||
{
|
||||
public function __construct(
|
||||
protected RouterOsApiService $routerOs,
|
||||
protected RadiusHealthService $radius,
|
||||
) {}
|
||||
|
||||
public function check(NasMikrotik $mikrotik): array
|
||||
{
|
||||
try {
|
||||
$result = $mikrotik->connection_type === 'radius'
|
||||
? $this->radius->testConnection($mikrotik)
|
||||
: $this->routerOs->testConnection($mikrotik);
|
||||
$mikrotik->update([
|
||||
'connection_status' => 'online',
|
||||
'last_checked_at' => now(),
|
||||
'last_connected_at' => now(),
|
||||
'last_latency_ms' => $result['latency_ms'],
|
||||
'consecutive_failures' => 0,
|
||||
'router_identity' => $result['identity'] ?? null,
|
||||
'router_version' => $result['version'] ?? null,
|
||||
'health_details' => $result,
|
||||
'next_health_check_at' => now()->addMinutes(config('nas.health.online_interval_minutes', 5)),
|
||||
'last_connection_error' => null,
|
||||
]);
|
||||
|
||||
return $result;
|
||||
} catch (Throwable $exception) {
|
||||
$message = $exception instanceof \Illuminate\Validation\ValidationException
|
||||
? collect($exception->errors())->flatten()->first()
|
||||
: $exception->getMessage();
|
||||
$failures = $mikrotik->consecutive_failures + 1;
|
||||
$mikrotik->update([
|
||||
'connection_status' => 'offline',
|
||||
'last_checked_at' => now(),
|
||||
'consecutive_failures' => $failures,
|
||||
'next_health_check_at' => now()->addMinutes(min(
|
||||
config('nas.health.offline_max_interval_minutes', 30),
|
||||
2 ** min($failures, 5)
|
||||
)),
|
||||
'health_details' => [
|
||||
'connected' => false,
|
||||
'host' => $mikrotik->host,
|
||||
'api_port' => $mikrotik->connection_type === 'api' ? $mikrotik->api_port : null,
|
||||
'auth_port' => $mikrotik->connection_type === 'radius' ? $mikrotik->radius_auth_port : null,
|
||||
'accounting_port' => $mikrotik->connection_type === 'radius' ? $mikrotik->radius_accounting_port : null,
|
||||
],
|
||||
'last_connection_error' => $message,
|
||||
]);
|
||||
throw $exception;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -9,6 +9,7 @@ use App\Models\NasWebfigDevice;
|
||||
use App\Models\User;
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
use App\Models\NasScriptPolicy;
|
||||
|
||||
class NasResourceService
|
||||
{
|
||||
@@ -31,7 +32,7 @@ class NasResourceService
|
||||
$model = $this->model($resource);
|
||||
|
||||
return $model::query()
|
||||
->with('tenant:id,tenant_code,tenant_name')
|
||||
->with(['tenant:id,tenant_code,tenant_name', ...($resource === 'mikrotik' ? ['tenant.nasSetting'] : []), ...($resource === 'package-profile' ? ['scripts.latestVersion'] : [])])
|
||||
->when(! $actor->isMasterAdmin(), fn ($q) => $q->where('tenant_id', $tenantId))
|
||||
->when($actor->isMasterAdmin() && $tenantId, fn ($q) => $q->where('tenant_id', $tenantId))
|
||||
->when(! empty($filters['status']), fn ($q) => $q->where('status', $filters['status']))
|
||||
@@ -40,7 +41,7 @@ class NasResourceService
|
||||
->when(! empty($filters['search']), function ($q) use ($filters, $resource) {
|
||||
$columns = match ($resource) {
|
||||
'mikrotik' => ['name', 'host', 'api_username'],
|
||||
'package-profile' => ['name', 'external_profile_name'],
|
||||
'package-profile' => ['name', 'profile_code'],
|
||||
'olt' => ['name', 'host', 'vendor', 'model'],
|
||||
'webfig' => ['name', 'url', 'device_type'],
|
||||
};
|
||||
@@ -59,11 +60,15 @@ class NasResourceService
|
||||
{
|
||||
$model = $this->model($resource);
|
||||
|
||||
return $model::with('tenant:id,tenant_code,tenant_name')->findOrFail($id);
|
||||
return $model::with(['tenant:id,tenant_code,tenant_name', ...($resource === 'mikrotik' ? ['tenant.nasSetting'] : []), ...($resource === 'package-profile' ? ['scripts.latestVersion'] : [])])->findOrFail($id);
|
||||
}
|
||||
|
||||
public function create(string $resource, array $data, User $actor, ?int $tenantId): Model
|
||||
{
|
||||
if ($resource === 'mikrotik') $data['connection_type'] = 'api';
|
||||
if ($resource === 'package-profile') $data = $this->normalizePackageProfile($data);
|
||||
$scripts = $resource === 'package-profile' ? ($data['scripts'] ?? []) : [];
|
||||
unset($data['scripts']);
|
||||
$data['tenant_id'] = $actor->isMasterAdmin() ? ($data['tenant_id'] ?? $tenantId) : $tenantId;
|
||||
if (! $data['tenant_id']) {
|
||||
throw ValidationException::withMessages(['tenant_id' => 'Tenant wajib dipilih.']);
|
||||
@@ -71,11 +76,18 @@ class NasResourceService
|
||||
$data['status'] ??= 'active';
|
||||
$model = $this->model($resource);
|
||||
|
||||
return $model::create($data)->load('tenant:id,tenant_code,tenant_name');
|
||||
$created = $model::create($data);
|
||||
if ($resource === 'package-profile') $this->syncProfileScripts($created, $scripts);
|
||||
return $created->load('tenant:id,tenant_code,tenant_name');
|
||||
}
|
||||
|
||||
public function update(string $resource, Model $model, array $data, User $actor): Model
|
||||
{
|
||||
if ($resource === 'mikrotik') $data['connection_type'] = 'api';
|
||||
if ($resource === 'package-profile') $data = $this->normalizePackageProfile($data, $model);
|
||||
$hasScripts = $resource === 'package-profile' && array_key_exists('scripts', $data);
|
||||
$scripts = $data['scripts'] ?? [];
|
||||
unset($data['scripts']);
|
||||
if (! $actor->isMasterAdmin()) {
|
||||
unset($data['tenant_id']);
|
||||
}
|
||||
@@ -85,10 +97,45 @@ class NasResourceService
|
||||
}
|
||||
}
|
||||
$model->update($data);
|
||||
if ($hasScripts) $this->syncProfileScripts($model, $scripts);
|
||||
|
||||
return $model->fresh()->load('tenant:id,tenant_code,tenant_name');
|
||||
}
|
||||
|
||||
private function syncProfileScripts(Model $profile, array $scripts): void
|
||||
{
|
||||
$sync=[];
|
||||
foreach($scripts as $row) {
|
||||
$policy = NasScriptPolicy::with('versions:id,nas_script_policy_id')->findOrFail($row['policy_id']);
|
||||
if ($policy->service_type !== $profile->service_type || $policy->event !== $row['event']) {
|
||||
throw ValidationException::withMessages(['scripts' => "Script {$policy->name} tidak sesuai tipe layanan atau event profile."]);
|
||||
}
|
||||
if (($row['version_id'] ?? null) && ! $policy->versions->contains('id', $row['version_id'])) {
|
||||
throw ValidationException::withMessages(['scripts' => "Versi Script {$policy->name} tidak valid."]);
|
||||
}
|
||||
$sync[$row['policy_id']]=['event'=>$row['event'],'nas_script_policy_version_id'=>$row['version_id'] ?? null,'enabled'=>true];
|
||||
}
|
||||
$profile->scripts()->sync($sync);
|
||||
}
|
||||
|
||||
private function normalizePackageProfile(array $data, ?Model $profile = null): array
|
||||
{
|
||||
$type = $data['service_type'] ?? $profile?->service_type;
|
||||
if ($type !== 'hotspot') {
|
||||
foreach (['usage_mode','validity_start','validity_value','validity_unit','uptime_limit_seconds','data_limit_bytes','grace_period_minutes'] as $field) $data[$field] = null;
|
||||
}
|
||||
if ($type !== 'ppp') foreach (['local_address', 'remote_address_pool'] as $field) $data[$field] = null;
|
||||
if ($type !== 'hotspot') foreach (['session_timeout', 'idle_timeout', 'shared_users'] as $field) $data[$field] = null;
|
||||
if (! in_array($type, ['static_ip', 'dynamic_ip'], true)) {
|
||||
foreach (['ip_pool','subnet_cidr','gateway','dns_servers','vlan_id'] as $field) $data[$field] = null;
|
||||
$data['mac_lock_required'] = false;
|
||||
} else {
|
||||
$data['mac_lock_required'] = true;
|
||||
if ($type === 'static_ip') $data['ip_pool'] = null;
|
||||
}
|
||||
return $data;
|
||||
}
|
||||
|
||||
public function delete(Model $model): bool
|
||||
{
|
||||
return $model->delete();
|
||||
|
||||
@@ -0,0 +1,93 @@
|
||||
<?php
|
||||
namespace App\Services\Nas;
|
||||
|
||||
use App\Models\NasMikrotik;
|
||||
use App\Models\NasPackageProfile;
|
||||
use App\Models\NasPackageProfileTarget;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
use Throwable;
|
||||
|
||||
class PackageProfileDeploymentService
|
||||
{
|
||||
public function __construct(protected RouterOsApiService $routerOs) {}
|
||||
|
||||
public function targets(NasPackageProfile $profile)
|
||||
{
|
||||
return $profile->targets()->with('mikrotik:id,tenant_id,name,connection_type,host,connection_status')->orderBy('id')->get();
|
||||
}
|
||||
|
||||
public function saveTarget(NasPackageProfile $profile, array $data): NasPackageProfileTarget
|
||||
{
|
||||
$nas = NasMikrotik::with('tenant.nasSetting')->whereKey($data['nas_mikrotik_id'])->where('tenant_id', $profile->tenant_id)->firstOrFail();
|
||||
$backendMode = $nas->effectiveBackendMode();
|
||||
return NasPackageProfileTarget::updateOrCreate(
|
||||
['nas_package_profile_id' => $profile->id, 'nas_mikrotik_id' => $nas->id],
|
||||
['tenant_id' => $profile->tenant_id, 'backend_type' => in_array($backendMode, ['platform_radius','external_radius','hybrid'], true) ? 'radius' : 'routeros_api',
|
||||
'external_profile_name' => $data['external_profile_name'], 'sync_status' => 'not_deployed']
|
||||
);
|
||||
}
|
||||
|
||||
public function sync(NasPackageProfileTarget $target, string $mode): NasPackageProfileTarget
|
||||
{
|
||||
$target->load(['packageProfile.scripts.versions', 'mikrotik']);
|
||||
$desired = $this->desiredSnapshot($target->packageProfile);
|
||||
try {
|
||||
$remote = $target->backend_type === 'routeros_api'
|
||||
? (in_array($target->packageProfile->service_type, ['static_ip', 'dynamic_ip'], true)
|
||||
? ['managed_per_customer' => true, 'network' => $desired['network']]
|
||||
: $this->routerOs->syncProfile($target->mikrotik, $target->packageProfile->service_type, $target->external_profile_name, $desired['routeros'], $mode))
|
||||
: ['radius_attributes' => $desired['radius']];
|
||||
$checksum = hash('sha256', json_encode($desired));
|
||||
$target->update(['sync_status' => 'synced', 'desired_snapshot' => $desired, 'remote_snapshot' => $remote,
|
||||
'remote_id' => $remote['.id'] ?? null, 'deployed_checksum' => $checksum, 'last_checked_at' => now(), 'last_synced_at' => now(), 'last_error' => null]);
|
||||
} catch (Throwable $e) {
|
||||
$target->update(['sync_status' => 'error', 'desired_snapshot' => $desired, 'last_checked_at' => now(), 'last_error' => $e instanceof ValidationException ? collect($e->errors())->flatten()->first() : $e->getMessage()]);
|
||||
throw $e;
|
||||
}
|
||||
return $target->fresh('mikrotik');
|
||||
}
|
||||
|
||||
public function assertSynced(NasPackageProfile $profile, NasMikrotik $nas): NasPackageProfileTarget
|
||||
{
|
||||
$target = $profile->targets()->where('nas_mikrotik_id', $nas->id)->where('sync_status', 'synced')->first();
|
||||
if (! $target) throw ValidationException::withMessages(['package_profile_id' => 'Profile paket belum disinkronkan ke NAS yang dipilih.']);
|
||||
return $target;
|
||||
}
|
||||
|
||||
private function desiredSnapshot(NasPackageProfile $profile): array
|
||||
{
|
||||
$scripts = $profile->scripts->keyBy(fn ($policy) => $policy->pivot->event);
|
||||
$script = fn (string $event) => $this->scriptTemplate($scripts->get($event), $profile);
|
||||
$rate = ($profile->upload_kbps ? ($profile->upload_kbps.'k') : '0').'/'.($profile->download_kbps ? ($profile->download_kbps.'k') : '0');
|
||||
$common = ['rate-limit' => $rate, 'session-timeout' => $profile->session_timeout ? $profile->session_timeout.'s' : null,
|
||||
'idle-timeout' => $profile->idle_timeout ? $profile->idle_timeout.'s' : null];
|
||||
$router = $profile->service_type === 'hotspot'
|
||||
? [...$common, 'shared-users' => (string) $profile->shared_users, 'on-login' => $script('on_login'), 'on-logout' => $script('on_logout')]
|
||||
: ($profile->service_type === 'ppp'
|
||||
? [...$common, 'local-address' => $profile->local_address, 'remote-address' => $profile->remote_address_pool, 'on-up' => $script('on_up'), 'on-down' => $script('on_down')]
|
||||
: []);
|
||||
return ['routeros' => $router, 'radius' => ['Mikrotik-Rate-Limit' => $rate, 'Session-Timeout' => $profile->session_timeout, 'Idle-Timeout' => $profile->idle_timeout, 'Simultaneous-Use' => $profile->shared_users],
|
||||
'network' => $profile->only(['mac_lock_required','ip_pool','subnet_cidr','gateway','dns_servers','vlan_id']),
|
||||
'profile' => $profile->only(['profile_code','service_type','usage_mode','validity_start','validity_value','validity_unit','uptime_limit_seconds','data_limit_bytes'])];
|
||||
}
|
||||
|
||||
private function scriptTemplate($policy, NasPackageProfile $profile): ?string
|
||||
{
|
||||
if (! $policy || ! $policy->pivot->enabled) return null;
|
||||
|
||||
$versionId = $policy->pivot->nas_script_policy_version_id;
|
||||
$version = $versionId
|
||||
? $policy->versions->firstWhere('id', $versionId)
|
||||
: $policy->versions->sortByDesc('version')->first();
|
||||
if (! $version) return null;
|
||||
|
||||
return strtr($version->script_template, [
|
||||
'{{ username }}' => '$user',
|
||||
'{{username}}' => '$user',
|
||||
'{{ package_code }}' => (string) $profile->profile_code,
|
||||
'{{package_code}}' => (string) $profile->profile_code,
|
||||
'{{ tenant_code }}' => (string) optional($profile->tenant)->tenant_code,
|
||||
'{{tenant_code}}' => (string) optional($profile->tenant)->tenant_code,
|
||||
]);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,72 @@
|
||||
<?php
|
||||
|
||||
namespace App\Services\Nas;
|
||||
|
||||
use App\Models\NasMikrotik;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
|
||||
class RadiusHealthService
|
||||
{
|
||||
public function testConnection(NasMikrotik $radius): array
|
||||
{
|
||||
if (! $radius->host || ! $radius->radius_secret) {
|
||||
throw ValidationException::withMessages(['radius' => 'Host dan shared secret RADIUS wajib lengkap.']);
|
||||
}
|
||||
|
||||
$socket = socket_create(AF_INET, SOCK_DGRAM, SOL_UDP);
|
||||
if ($socket === false) {
|
||||
throw ValidationException::withMessages(['radius' => 'Socket UDP untuk RADIUS tidak dapat dibuat.']);
|
||||
}
|
||||
$timeout = max(1, min((int) ($radius->timeout ?: 5), 10));
|
||||
socket_set_option($socket, SOL_SOCKET, SO_RCVTIMEO, ['sec' => $timeout, 'usec' => 0]);
|
||||
$identifier = random_int(0, 255);
|
||||
$requestAuthenticator = random_bytes(16);
|
||||
$request = pack('CCn', 12, $identifier, 20).$requestAuthenticator;
|
||||
$startedAt = hrtime(true);
|
||||
|
||||
try {
|
||||
$sent = @socket_sendto(
|
||||
$socket,
|
||||
$request,
|
||||
strlen($request),
|
||||
0,
|
||||
$radius->host,
|
||||
(int) ($radius->radius_auth_port ?: 1812),
|
||||
);
|
||||
if ($sent === false) {
|
||||
throw ValidationException::withMessages(['radius' => 'Status-Server RADIUS gagal dikirim.']);
|
||||
}
|
||||
$response = '';
|
||||
$from = '';
|
||||
$port = 0;
|
||||
$received = @socket_recvfrom($socket, $response, 4096, 0, $from, $port);
|
||||
if ($received === false || $received < 20) {
|
||||
throw ValidationException::withMessages([
|
||||
'radius' => 'RADIUS tidak merespons Status-Server. Pastikan Status-Server diizinkan oleh server.',
|
||||
]);
|
||||
}
|
||||
|
||||
['code' => $code, 'identifier' => $responseIdentifier, 'length' => $length] = unpack('Ccode/Cidentifier/nlength', substr($response, 0, 4));
|
||||
if ($responseIdentifier !== $identifier || $length > strlen($response)) {
|
||||
throw ValidationException::withMessages(['radius' => 'Respons RADIUS tidak valid.']);
|
||||
}
|
||||
$attributes = substr($response, 20, $length - 20);
|
||||
$expected = md5(substr($response, 0, 4).$requestAuthenticator.$attributes.$radius->radius_secret, true);
|
||||
if (! hash_equals($expected, substr($response, 4, 16))) {
|
||||
throw ValidationException::withMessages(['radius' => 'Authenticator respons RADIUS tidak valid.']);
|
||||
}
|
||||
|
||||
return [
|
||||
'connected' => true,
|
||||
'latency_ms' => (int) round((hrtime(true) - $startedAt) / 1_000_000),
|
||||
'host' => $radius->host,
|
||||
'auth_port' => (int) ($radius->radius_auth_port ?: 1812),
|
||||
'accounting_port' => (int) ($radius->radius_accounting_port ?: 1813),
|
||||
'response_code' => $code,
|
||||
'probe' => 'radius_status_server',
|
||||
];
|
||||
} finally {
|
||||
socket_close($socket);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,185 @@
|
||||
<?php
|
||||
|
||||
namespace App\Services\Nas;
|
||||
|
||||
use App\Models\NasMikrotik;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
use RouterOS\Client;
|
||||
use RouterOS\Query;
|
||||
use Throwable;
|
||||
|
||||
class RouterOsApiService
|
||||
{
|
||||
public function testConnection(NasMikrotik $mikrotik): array
|
||||
{
|
||||
$startedAt = hrtime(true);
|
||||
$client = $this->connect($mikrotik);
|
||||
$identity = $client->query('/system/identity/print')->read()[0] ?? [];
|
||||
$resource = $client->query('/system/resource/print')->read()[0] ?? [];
|
||||
|
||||
return [
|
||||
'connected' => true,
|
||||
'latency_ms' => (int) round((hrtime(true) - $startedAt) / 1_000_000),
|
||||
'identity' => $identity['name'] ?? null,
|
||||
'version' => $resource['version'] ?? null,
|
||||
'uptime' => $resource['uptime'] ?? null,
|
||||
'platform' => $resource['platform'] ?? null,
|
||||
'board_name' => $resource['board-name'] ?? null,
|
||||
];
|
||||
}
|
||||
|
||||
public function createAccount(NasMikrotik $mikrotik, string $serviceType, array $attributes): array
|
||||
{
|
||||
$client = $this->connect($mikrotik);
|
||||
$this->assertUsernameAvailable($client, $serviceType, $attributes['username']);
|
||||
$query = new Query($this->path($serviceType, 'add'));
|
||||
foreach ($this->accountAttributes($attributes) as $key => $value) {
|
||||
$query->equal($key, $value);
|
||||
}
|
||||
$client->query($query)->read();
|
||||
|
||||
return $this->findAccount($client, $serviceType, $attributes['username']);
|
||||
}
|
||||
|
||||
public function updateAccount(NasMikrotik $mikrotik, string $serviceType, string $username, array $attributes): array
|
||||
{
|
||||
$client = $this->connect($mikrotik);
|
||||
$account = $this->findAccount($client, $serviceType, $username);
|
||||
$query = (new Query($this->path($serviceType, 'set')))->equal('.id', $account['.id']);
|
||||
foreach ($this->accountAttributes($attributes) as $key => $value) {
|
||||
$query->equal($key, $value);
|
||||
}
|
||||
$client->query($query)->read();
|
||||
|
||||
return $this->findAccount($client, $serviceType, $attributes['username'] ?? $username);
|
||||
}
|
||||
|
||||
public function setEnabled(NasMikrotik $mikrotik, string $serviceType, string $username, bool $enabled): array
|
||||
{
|
||||
return $this->updateAccount($mikrotik, $serviceType, $username, [
|
||||
'disabled' => $enabled ? 'no' : 'yes',
|
||||
]);
|
||||
}
|
||||
|
||||
public function deleteAccount(NasMikrotik $mikrotik, string $serviceType, string $username): void
|
||||
{
|
||||
$client = $this->connect($mikrotik);
|
||||
$account = $this->findAccount($client, $serviceType, $username);
|
||||
$client->query(
|
||||
(new Query($this->path($serviceType, 'remove')))->equal('.id', $account['.id'])
|
||||
)->read();
|
||||
}
|
||||
|
||||
public function syncProfile(NasMikrotik $mikrotik, string $serviceType, string $name, array $attributes, string $mode = 'update'): array
|
||||
{
|
||||
$client = $this->connect($mikrotik);
|
||||
$base = $serviceType === 'hotspot' ? '/ip/hotspot/user/profile' : '/ppp/profile';
|
||||
$rows = $client->query((new Query("{$base}/print"))->where('name', $name))->read();
|
||||
$existing = $rows[0] ?? null;
|
||||
if ($mode === 'adopt') {
|
||||
if (! $existing) throw ValidationException::withMessages(['profile' => "Profile {$name} tidak ditemukan untuk di-adopt."]);
|
||||
return $existing;
|
||||
}
|
||||
if (! $existing) {
|
||||
$query = (new Query("{$base}/add"))->equal('name', $name);
|
||||
} else {
|
||||
$query = (new Query("{$base}/set"))->equal('.id', $existing['.id']);
|
||||
}
|
||||
foreach (array_filter($attributes, fn ($value) => $value !== null) as $key => $value) $query->equal($key, $value);
|
||||
$client->query($query)->read();
|
||||
$rows = $client->query((new Query("{$base}/print"))->where('name', $name))->read();
|
||||
return $rows[0] ?? [];
|
||||
}
|
||||
|
||||
public function inspectAccount(NasMikrotik $mikrotik, string $serviceType, string $username): array
|
||||
{
|
||||
$client = $this->connect($mikrotik);
|
||||
$account = $this->findAccount($client, $serviceType, $username);
|
||||
$activeBase = in_array($serviceType, ['ppp','pppoe'], true) ? '/ppp/active' : '/ip/hotspot/active';
|
||||
$active = $client->query((new Query("{$activeBase}/print"))->where('name', $username))->read()[0] ?? null;
|
||||
return ['account' => $account, 'active' => $active];
|
||||
}
|
||||
|
||||
public function disconnectAccount(NasMikrotik $mikrotik, string $serviceType, string $username): void
|
||||
{
|
||||
$client = $this->connect($mikrotik);
|
||||
$activeBase = in_array($serviceType, ['ppp','pppoe'], true) ? '/ppp/active' : '/ip/hotspot/active';
|
||||
$rows = $client->query((new Query("{$activeBase}/print"))->where('name', $username))->read();
|
||||
foreach ($rows as $row) if (! empty($row['.id'])) $client->query((new Query("{$activeBase}/remove"))->equal('.id', $row['.id']))->read();
|
||||
}
|
||||
|
||||
private function connect(NasMikrotik $mikrotik): Client
|
||||
{
|
||||
if ($mikrotik->connection_type !== 'api') {
|
||||
throw ValidationException::withMessages(['mikrotik' => 'Perangkat tidak menggunakan koneksi RouterOS API.']);
|
||||
}
|
||||
if ($mikrotik->status !== 'active') {
|
||||
throw ValidationException::withMessages(['mikrotik' => 'Perangkat Mikrotik sedang nonaktif.']);
|
||||
}
|
||||
if (! $mikrotik->host || ! $mikrotik->api_username || ! $mikrotik->api_password) {
|
||||
throw ValidationException::withMessages(['mikrotik' => 'Host, username API, dan password API wajib lengkap.']);
|
||||
}
|
||||
|
||||
try {
|
||||
return new Client([
|
||||
'host' => $mikrotik->host,
|
||||
'user' => $mikrotik->api_username,
|
||||
'pass' => $mikrotik->api_password,
|
||||
'port' => (int) ($mikrotik->api_port ?: 8728),
|
||||
'timeout' => (int) ($mikrotik->timeout ?: 10),
|
||||
'socket_timeout' => (int) ($mikrotik->timeout ?: 10),
|
||||
'attempts' => 1,
|
||||
'delay' => 0,
|
||||
'ssl' => (int) ($mikrotik->api_port ?: 8728) === 8729,
|
||||
]);
|
||||
} catch (Throwable $exception) {
|
||||
throw ValidationException::withMessages([
|
||||
'mikrotik' => 'Koneksi RouterOS API gagal: '.$exception->getMessage(),
|
||||
]);
|
||||
}
|
||||
}
|
||||
|
||||
private function findAccount(Client $client, string $serviceType, string $username): array
|
||||
{
|
||||
$rows = $client->query(
|
||||
(new Query($this->path($serviceType, 'print')))->where('name', $username)
|
||||
)->read();
|
||||
if (empty($rows[0]['.id'])) {
|
||||
throw ValidationException::withMessages(['username' => "Akun {$username} tidak ditemukan di Mikrotik."]);
|
||||
}
|
||||
|
||||
return $rows[0];
|
||||
}
|
||||
|
||||
private function assertUsernameAvailable(Client $client, string $serviceType, string $username): void
|
||||
{
|
||||
$rows = $client->query(
|
||||
(new Query($this->path($serviceType, 'print')))->where('name', $username)
|
||||
)->read();
|
||||
if ($rows) {
|
||||
throw ValidationException::withMessages(['username' => "Username {$username} sudah ada di Mikrotik."]);
|
||||
}
|
||||
}
|
||||
|
||||
private function accountAttributes(array $attributes): array
|
||||
{
|
||||
return array_filter([
|
||||
'name' => $attributes['username'] ?? null,
|
||||
'password' => $attributes['password'] ?? null,
|
||||
'profile' => $attributes['profile'] ?? null,
|
||||
'comment' => $attributes['comment'] ?? null,
|
||||
'disabled' => $attributes['disabled'] ?? null,
|
||||
], fn ($value) => $value !== null);
|
||||
}
|
||||
|
||||
private function path(string $serviceType, string $action): string
|
||||
{
|
||||
$base = match ($serviceType) {
|
||||
'ppp', 'pppoe' => '/ppp/secret',
|
||||
'hotspot' => '/ip/hotspot/user',
|
||||
default => throw ValidationException::withMessages(['service_type' => 'Tipe layanan harus PPPoE atau Hotspot.']),
|
||||
};
|
||||
|
||||
return "{$base}/{$action}";
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
<?php
|
||||
namespace App\Services\Nas;
|
||||
use App\Models\NasScriptPolicy;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
|
||||
class ScriptPolicyService
|
||||
{
|
||||
private const VARIABLES = ['username','customer_code','customer_name','package_code','tenant_code','valid_until'];
|
||||
public function list(array $filters) { return NasScriptPolicy::with('latestVersion')->when($filters['search'] ?? null, fn($q,$s)=>$q->where('name','ILIKE',"%{$s}%")->orWhere('code','ILIKE',"%{$s}%"))->orderBy('service_type')->orderBy('event')->paginate($filters['per_page'] ?? 10); }
|
||||
public function save(array $data, int $userId, ?NasScriptPolicy $policy = null): NasScriptPolicy
|
||||
{
|
||||
$allowedEvents = $data['service_type'] === 'ppp' ? ['on_up', 'on_down'] : ['on_login', 'on_logout'];
|
||||
if (! in_array($data['event'], $allowedEvents, true)) {
|
||||
throw ValidationException::withMessages(['event' => 'Event tidak sesuai dengan tipe layanan Script Policy.']);
|
||||
}
|
||||
preg_match_all('/\{\{\s*([a-z_]+)\s*\}\}/', $data['script_template'], $matches);
|
||||
$invalid = array_diff(array_unique($matches[1]), self::VARIABLES);
|
||||
if ($invalid) throw ValidationException::withMessages(['script_template' => 'Variabel tidak diizinkan: '.implode(', ', $invalid)]);
|
||||
return DB::transaction(function () use ($data,$userId,$policy) {
|
||||
$version = $policy ? $policy->current_version + 1 : 1;
|
||||
$values = collect($data)->except(['script_template','change_notes'])->all();
|
||||
$values['allowed_variables'] = self::VARIABLES; $values['current_version'] = $version; $values['created_by'] ??= $userId;
|
||||
$policy ? $policy->update($values) : $policy = NasScriptPolicy::create($values);
|
||||
$policy->versions()->create(['version'=>$version,'script_template'=>$data['script_template'],'checksum'=>hash('sha256',$data['script_template']),'change_notes'=>$data['change_notes'] ?? null,'created_by'=>$userId]);
|
||||
return $policy->fresh(['latestVersion','versions']);
|
||||
});
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user