Files
forefront-wireless-portal/CHANGELOG.md
T

75 lines
4.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# CHANGELOG — Forefront Wireless Customer Portal
---
## 2026-07-25 (PM) — Multi-Source Architecture Scoped
**Scope expansion:** The portal at my.forefrontwireless.com will aggregate data from four sources, not just Splynx:
### Data Sources
| Source | Purpose | Auth | Location |
|--------|---------|------|----------|
| **Splynx v4.2** | Billing, CRM, customers, invoices, services | HMAC-SHA256 signature | Self-hosted at portal.forefrontwireless.com |
| **UISP (UNMS)** | Network management, tower/AP inventory, link quality | API token | app2 Docker (unms.forefrontwireless.com) |
| **MikroTik RouterOS** | Real-time bandwidth, DHCP leases, queue stats | REST API or SSH | 5 × CCR2004 routers on network |
| **Zabbix / SNMP** | Infrastructure monitoring, SNMP for non-UISP devices, historical graphs | Zabbix API | Currently on-prem; may move to cloud |
### Architecture Decision
The FastAPI backend is now an **aggregation layer** — read-only adapters for each source, normalizing data into a unified customer view. The backend never writes to Splynx/UISP/MikroTik/Zabbix directly; all mutations stay in the native tools.
### Build Phases
| Phase | Sources | V1? |
|:---:|---|---|
| 1 | Splynx (billing + CRM) | Yes — core self-service |
| 2 | MikroTik (router telemetry) | Yes — data usage, device lists |
| 3 | UISP (network management) | V2 — network status, outage awareness |
| 4 | Zabbix/SNMP (infra monitoring) | V2+ — SLA dashboards, historical graphs |
### Zabbix Migration Options
- **Recommended:** Cloud Zabbix + on-prem proxy — SNMP stays local, server moves to managed infra
- **Alternative:** Keep on-prem, API tunnel via Tailscale — zero cost, simple
- **For later:** Decision deferred until portal reaches Phase 4
### Page-to-Source Mapping
Every customer-facing feature mapped to its backend data provider — see README Data Aggregation Model section.
---
## 2026-07-25 (AM) — Splynx API Connection
**Context:** Germaine shared Splynx API credentials for Forefront Wireless, his WISP company. The self-hosted Splynx instance (v4.2) runs at `portal.forefrontwireless.com/admin/`. The goal is to build a branded customer portal at `my.forefrontwireless.com`.
### Completed
- **API connection established** — Splynx API v2.0 at `/api/2.0/` verified working
- **Authentication cracked** — Signature-based auth (HMAC-SHA256) with microtime nonce. Three methods tested:
- ✅ Signature: `Splynx-EA (key=K&nonce=N&signature=S)` — works
- ✅ Access Token: POST `/admin/auth/tokens` — generates token with 30-min expiry
- ⚠️ Basic Auth: returns 403 unless "Unsecure access" is enabled on the API key
- **API key configured** — Full permissions on all resources (customers, services, finance, networking, support, tariffs, scheduling, inventory)
- **Endpoint reconnaissance** — Verified working:
- `GET /admin/customers/customer` — 43 customers (33 active, 9 disabled)
- `GET /admin/customers/customer-internet-services/{id}` — per-customer services
- `GET /admin/networking/routers` — 5 MikroTik CCR2004 routers
- `GET /admin/tariffs/internet` — 9 plans ($59.95-$299.95/mo)
- `GET /admin/finance/invoices` — billing records
- **Splynx quirks documented** — 405 on query-param service endpoints, tariff name resolution, signature nonce format
### Decisions
- **Stack:** React SPA → FastAPI backend → Splynx API v2.0. Same pattern as IntelSight and VoIPSimplicity.
- **Hosting:** CloudPanel on app3 (152.53.241.111) — keeps customer portals together
- **Auth pattern:** Server-to-server signature auth (not per-user Access Tokens) — portal handles its own user auth, backend proxies to Splynx
- **Domain:** my.forefrontwireless.com (follows ITPP product convention: my.*.com)
- **Building after:** IntelSight + LaunchCheck (shared infrastructure, shared auth patterns, reusable Super Search engine)
### Reference: API Credentials
```
Key: 5a8dc490716424f435306f2c18b4fdcb
Secret: 5773f779e5ae5aac965845a66bd857a0
Base: https://portal.forefrontwireless.com/api/2.0/
```