{"id":38498890,"url":"https://github.com/rdkcentral/webconfig","last_synced_at":"2026-01-17T05:57:36.544Z","repository":{"id":47464461,"uuid":"334979526","full_name":"rdkcentral/webconfig","owner":"rdkcentral","description":"Webconfig is a solution to pass configuration data from the server to networking devices. This makes the cloud based server the master for all device configurations.","archived":false,"fork":false,"pushed_at":"2025-12-17T00:28:23.000Z","size":1011,"stargazers_count":4,"open_issues_count":3,"forks_count":9,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-12-20T13:18:08.924Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rdkcentral.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"COPYING","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"security/aes_codec.go","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-02-01T14:40:45.000Z","updated_at":"2025-11-13T21:26:39.000Z","dependencies_parsed_at":"2023-10-12T06:00:55.609Z","dependency_job_id":"789ce10a-0030-43eb-9340-c5da2a017995","html_url":"https://github.com/rdkcentral/webconfig","commit_stats":{"total_commits":2,"total_committers":1,"mean_commits":2.0,"dds":0.0,"last_synced_commit":"b10d72fa3a61c26eb5618b5a0f0cc49955045179"},"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/rdkcentral/webconfig","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rdkcentral%2Fwebconfig","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rdkcentral%2Fwebconfig/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rdkcentral%2Fwebconfig/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rdkcentral%2Fwebconfig/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rdkcentral","download_url":"https://codeload.github.com/rdkcentral/webconfig/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rdkcentral%2Fwebconfig/sbom","scorecard":{"id":765055,"data":{"date":"2025-08-11","repo":{"name":"github.com/rdkcentral/webconfig","commit":"59d4ee756413a0634fd7f8a63cc7920f32116a1d"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":0,"reason":"Found 1/16 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":4,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'main'","Info: 'stale review dismissal' is required to merge on branch 'main'","Warn: branch 'main' does not require approvers","Warn: codeowners review is not required on branch 'main'","Warn: 'last push approval' is disabled on branch 'main'","Info: 'up-to-date branches' is required to merge on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":9,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/rdkcentral/.github/SECURITY.md:1","Info: Found linked content: github.com/rdkcentral/.github/SECURITY.md:1","Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy","Info: Found text in security policy: github.com/rdkcentral/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"13 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2025-3553 / GHSA-mh63-6h87-95cp","Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2023-1571 / GHSA-vvpx-j8f3-3w6h","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-23T00:32:46.913Z","repository_id":47464461,"created_at":"2025-08-23T00:32:46.913Z","updated_at":"2025-08-23T00:32:46.913Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28501351,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-17T04:31:57.058Z","status":"ssl_error","status_checked_at":"2026-01-17T04:31:45.816Z","response_time":85,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-01-17T05:57:36.464Z","updated_at":"2026-01-17T05:57:36.529Z","avatar_url":"https://github.com/rdkcentral.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# webconfig\n\nThis project is to implement a configuration management server. RDK devices download configurations from this server during bootup or notified when updates are available.\n\n## Transport route\nWebconfig supports 2 types of transport between cloud and devices\n1. http / webpa\n2. mqtt\n\n## Install go\nThis project is written and tested with Go **1.17**.\n\n## Build the binary\n```shell\ncd $HOME/go/src/github.com/rdkcentral/webconfig\nmake\n```\n**bin/webconfig-linux-amd64** will be created. \n\n## Configuration\nA sample configuration file can be found at config/sample_webconfig.conf\n\n### Setup an encryption key\nIf we want to encrypt the data in db for security, we can set a security key through an environment variable. A command like this generate a random key in base64\n```shell\n$ head -c 32 /dev/random | base64\nABCDEF...\n```\nSpecify the environ variable in the config\n```shell\nwebconfig {\n    security {\n        encryption_key_env_name = \"WEBCONFIG_KEY\"\n    }\n```\nThe subdocs that need encryption can be specified in the config\n```shell\n    encrypted_subdoc_ids = [ \"privatessid\", \"homessid\", \"telcovoip\", \"voiceservice\" ]\n```\n\n### Configurations for connecting to mqtt server\nWebconfig is designed to work with an \"http-collector\" service. It includes full MQTT broker capabilities and a REST api interface. The endpoint needs to be properly configure in the \"mqtt\" section of the config\n\n### Configurations for connecting to webpa server and JWT authentication\nWebconfig works with rdk devices through webpa. \"webpa\" and \"jwt\" sections need to be properly configured. If this route is not used, then the jwt should be disabled.\n\n### Configuration for kafka\nDevices use mqtt or webpa route send message to webconfig cloud. Webconfig supports 3 types of kafka message\n1. webpa state\n2. mqtt get\n3. mqtt state\nThe actual kafka topic names can be any. Below is just an example. \"topics\" should include all topics. \"ratelimit\" can be tuned to users env.\n```shell\n    kafka {\n        enabled = false\n        brokers = \"localhost:9092\"\n        topics = \"config-version-report\"\n        use_random_consumer_group = false\n        consumer_group = \"webconfig\"\n        assignor = \"roundrobin\"\n        oldest = false\n        ratelimit {\n            messages_per_second = 10\n        }\n        clusters {\n            mesh {\n                enabled = false\n                brokers = \"localhost:19092\"\n                topics = \"staging-chi-onewifi-from-device\"\n                use_random_consumer_group = false\n                consumer_group = \"webconfig\"\n                assignor = \"roundrobin\"\n                oldest = false\n                ratelimit {\n                    messages_per_second = 10\n                }\n            }\n        }\n```\n\n### Configuration for database\nThe main database operations are defined as an interface. Any driver that implements the interface should work. We has implemented using sqlite, cassandra and yugabytedb. After the db is properly configured, the dbinit.cql can be used to create the tables for cassandra.\n\n\n\n## Run the application\n```shell\n$ export WEBCONFIG_KEY='ABCDEF...'\n$ mkdir -p /app/logs/webconfig\n$ cd $HOME/go/src/github.com/rdkcentral/webconfig\n$ bin/webconfig-linux-amd64 -f config/sample_webconfig.conf\n```\n\n## APIs\n### Version API\nThis display the build date and code commit info\n```shell\ncurl http://localhost:9000/api/v1/version\n{\"status\":200,\"message\":\"OK\",\"data\":{\"code_git_commit\":\"2ac7ff4\",\"build_time\":\"Thu Feb 14 01:57:26 2019 UTC\",\"binary_version\":\"317f2d4\",\"binary_branch\":\"develop\",\"binary_build_time\":\"2021-02-10_18:26:49_UTC\"}}\n```\n\n### Write data into DB\nThe POST API is designed to accept binary input \"Content-type: application/msgpack\". A \"group_id\" is mandatory in the query parameter to specify the subdoc the input is meant for. Most programming languages supports HTTP would accept binary data as POST body. The example uses curl and reads the binary data from a file.\n```shell\ncurl -s -i \"http://localhost:9000/api/v1/device/010203040506/document/privatessid\" -H 'Content-type: application/msgpack' --data-binary @privatessid.bin -X POST\nHTTP/1.1 200 OK\nContent-Type: application/json\nDate: Wed, 14 Oct 2020 22:58:21 GMT\nContent-Length: 29\n\n{\"status\":200,\"message\":\"OK\"}\n```\n\n### Verify data in DB\nThe GET API read binary data in the response. The \"group_id\" is mandatory in the query parameter. For simplicity, the binary output is saved as a file. We can compare the 2 files to verify.\n```shell\ncurl -s -i \"http://localhost:9000/api/v1/device/010203040506/document/privatessid\" \u003e result.bin\n\ncmp privatessid.bin result.bin\n```\n\n### Poke RDK device to download the configuration\nWhen data are prepared in DB, users are expected to call this poke API. Webconfig uses the RDK webpa service to prompt the webconfig client on the devices to download the prepared configurations.\n```shell\ncurl -s \"http://localhost:9009/api/v1/device/010203040506/poke\" -X POST\n\n```\n\n### RDK devices downloads the configuration\nRDK devices use this API to fetch data. The response is in HTTP multipart. Each part maps to a subdoc, or a logical group of configurations encoded in msgpack.\n```shell\ncurl -s \"http://localhost:9000/api/v1/device/010203040506/config\"\nHTTP/1.1 200 OK\nContent-Type: multipart/mixed; boundary=2xKIxjfJuErFW+hmNCwEoMoY8I+ECM9efrV6EI4efSSW9QjI\nEtag: 2484248953\nDate: Sun, 18 Oct 2020 19:19:34 GMT\nContent-Length: 578\n\n--2xKIxjfJuErFW+hmNCwEoMoY8I+ECM9efrV6EI4efSSW9QjI\nContent-type: application/msgpack\nEtag: 1737259797\nNamespace: privatessid\n\n��parameters���name�Device.WiFi.Private�value�^AE��private_ssid_2g��SSID�garf_private_2g�EnableøSSIDAdvertisementEnabledïprivate_ssid_5g��SSID�garf_private_5g�EnableøSSIDAdvertisementEnabledóprivate_security_2g��Passphrase�garf_pw_2g�EncryptionMethod�AES�ModeEnabled�WPA2-Personal�private_security_5g��Passphrase�garf_pw_5g�EncryptionMethod�AES�ModeEnabled�WPA2-Personal�dataType�\n\n--2xKIxjfJuErFW+hmNCwEoMoY8I+ECM9efrV6EI4efSSW9QjI--\n```\n\n### Send new configurations to device through mqtt\nWhen data are prepared in DB, users are expected to call this poke API. Webconfig uses the RDK webpa service to prompt the webconfig client on the devices to download the prepared configurations.\n```shell\ncurl -s \"http://localhost:9009/api/v1/device/010203040506/poke?route=mqtt\" -X POST\n```\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frdkcentral%2Fwebconfig","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frdkcentral%2Fwebconfig","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frdkcentral%2Fwebconfig/lists"}