# PHP customer portal using API

**URL:** <https://forum.genieacs.com/t/php-customer-portal-using-api/842>\
**Category:** Uncategorized\
**Created:** [June 17, 2020, 5:13pm UTC](https://forum.genieacs.com/t/php-customer-portal-using-api/842 "2020-06-17T17:13:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![terraping](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@terraping](https://forum.genieacs.com/u/terraping)\
**Post date:** [June 17, 2020, 5:13pm UTC](https://forum.genieacs.com/t/php-customer-portal-using-api/842/1 "2020-06-17T17:13:01Z")

</div>

Hello, I am new here and I am just wondering if anyone has an open source (or proprietary if you’re willing to share) PHP customer portal framework already written that allows customers to change their wifi name/password via the API? I was planning on writing my own but I don’t know where to start. I am running GenieACS drumsergio docker image on Ubuntu. Thanks!

---

<div class="post-metadata">

**Author:** ![akcoder](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/akcoder/32/11_2.png) [@akcoder](https://forum.genieacs.com/u/akcoder)\
**Post date:** [June 18, 2020, 8:03pm UTC](https://forum.genieacs.com/t/php-customer-portal-using-api/842/2 "2020-06-18T20:03:18Z")

</div>

I’ve written this, but because its owned by my employer I’m unable to share. I’m happy to answer any questions you might have though.

One of the biggest pieces of advice I can give you is don’t use the TR069 data model as your canonical data model. For example, I store customer wifi settings (with the password encrypted at rest of course) in json format in a table that looks similar to this: subscriber id, area (varchar), key (varchar), value (json). The advantage of this setup is I was able to easily add support for 5.8ghz wifi.

So a sample data structure looks like this:

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/genieacs/original/1X/40ec4182c7ff0dc4c3fdb0b19149136f49c39102.png)

When I send the data from our SMS to the ACS is when I map it to the TR069 data model. To do that, I built a mapping file for each CPE model. The mapping looks like this:  
Zyxel CPE:

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/genieacs/original/1X/1fc17dfd1f7cbeb384c18f96898d0161e206aa36.png)

Base config:  
 ![image](https://canada1.discourse-cdn.com/flex035/uploads/genieacs/original/1X/66de05b427a6747ce4503b2e74bf03d2f16b1bd9.png)

A particular CPE is composed of 1 to many mapping files, all layered on top of each other. So the base\_config.json file has general things that every CPE we support has. Then for specific models, I can override the key map. A good example of this is older generation SmartRG CPEs supported AutoChannelEnable for wifi, but used the X\_SMARTRG\_COM\_AutoChannelEnable naming, where as the Zyxel models used AutoChannelEnable. So the map layer for some of our CPEs looks like this:

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/genieacs/original/1X/e98705183c07a199617df41210debed5ef6fa8f0.png)

While this might sound complicated on the surface (and even under the covers), going with this approach has allowed me to support multiple different CPE models with different layers of screwed up data models without having to write custom code. It takes me about an hour to add support for a new CPE.

I used the Symfony framework. Our architecture is Customer Portal \<----\> Subscriber Management System \<----\> ACS this way our customer portal never talks directly to the ACS.

---

<div class="post-metadata">

**Author:** ![terraping](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@terraping](https://forum.genieacs.com/u/terraping)\
**Post date:** [June 26, 2020, 4:43pm UTC](https://forum.genieacs.com/t/php-customer-portal-using-api/842/3 "2020-06-26T16:43:37Z")

</div>

Thanks for the reply, very cool setup, and it does indeed look very complicated. I thought GenieACS would be more of a turnkey product, I will have to delve into this later when I have more time! Is there a particular reason you don’t want the portal communicating directly with the ACS API?

---

<div class="post-metadata">

**Author:** ![akcoder](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/akcoder/32/11_2.png) [@akcoder](https://forum.genieacs.com/u/akcoder)\
**Post date:** [June 26, 2020, 9:24pm UTC](https://forum.genieacs.com/t/php-customer-portal-using-api/842/4 "2020-06-26T21:24:01Z")

</div>

> [@terraping](#):
>
> I thought GenieACS would be more of a turnkey product…

GenieACS is not a turnkey product. If you want that, you need to look at Affinegy, Calix Cloud, Adtran’s Clear Access, etc.

> [@terraping](#):
>
> Is there a particular reason you don’t want the portal communicating directly with the ACS API?

The first rule of the internet is never trust the user 😃. So I have some validation in the customer portal, and a shit ton in our subscriber management system (as that code is also used by our internal users).

This design also means that our ACS is never ever exposed to our customers. Our subscriber management system acts as the DMZ. We put our customer facing portal on a much less trusted host.

---

<div class="post-metadata">

**Author:** ![terraping](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@terraping](https://forum.genieacs.com/u/terraping)\
**Post date:** [June 26, 2020, 9:53pm UTC](https://forum.genieacs.com/t/php-customer-portal-using-api/842/5 "2020-06-26T21:53:08Z")

</div>

I guess turnkey isn’t the word, just more like an appliance, rather than a framework, if you get my meaning.

That makes a lot of sense! Thanks for giving me a lot to think about, I appreciate it.
