index.php 2.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687
  1. <?php
  2. ob_start();
  3. $TAB = 'DB';
  4. // Main include
  5. include($_SERVER['DOCUMENT_ROOT'].'/inc/main.php');
  6. // Check database id
  7. if (empty($_GET['database'])) {
  8. header("Location: /list/db/");
  9. exit;
  10. }
  11. // Edit as someone else?
  12. if (($_SESSION['userContext'] === 'admin') && (!empty($_GET['user']))) {
  13. $user=escapeshellarg($_GET['user']);
  14. }
  15. // List datbase
  16. $v_database = $_GET['database'];
  17. exec(HESTIA_CMD."v-list-database ".$user." ".escapeshellarg($v_database)." 'json'", $output, $return_var);
  18. check_return_code_redirect($return_var, $output, '/list/db/');
  19. $data = json_decode(implode('', $output), true);
  20. unset($output);
  21. // Parse database
  22. $v_username = $user;
  23. $v_dbuser = preg_replace("/^".$user_plain."_/", "", $data[$v_database]['DBUSER']);
  24. $v_password = "";
  25. $v_host = $data[$v_database]['HOST'];
  26. $v_type = $data[$v_database]['TYPE'];
  27. $v_charset = $data[$v_database]['CHARSET'];
  28. $v_date = $data[$v_database]['DATE'];
  29. $v_time = $data[$v_database]['TIME'];
  30. $v_suspended = $data[$v_database]['SUSPENDED'];
  31. if ($v_suspended == 'yes') {
  32. $v_status = 'suspended';
  33. } else {
  34. $v_status = 'active';
  35. }
  36. // Check POST request
  37. if (!empty($_POST['save'])) {
  38. $v_username = $user;
  39. // Check token
  40. verify_csrf($_POST);
  41. // Change database user
  42. if (($v_dbuser != $_POST['v_dbuser']) && (empty($_SESSION['error_msg']))) {
  43. $v_dbuser = escapeshellarg($v_dbuser);
  44. exec(HESTIA_CMD."v-change-database-user ".$user." ".escapeshellarg($v_database)." ".$v_dbuser, $output, $return_var);
  45. check_return_code($return_var, $output);
  46. unset($output);
  47. $v_dbuser = $_POST['v_dbuser'];
  48. }
  49. // Change database password
  50. if ((!empty($_POST['v_password'])) && (empty($_SESSION['error_msg']))) {
  51. if (!validate_password($_POST['v_password'])) {
  52. $_SESSION['error_msg'] = _('Password does not match the minimum requirements');
  53. } else {
  54. $v_password = tempnam("/tmp", "vst");
  55. $fp = fopen($v_password, "w");
  56. fwrite($fp, $_POST['v_password']."\n");
  57. fclose($fp);
  58. exec(HESTIA_CMD."v-change-database-password ".$user." ".escapeshellarg($v_database)." ".$v_password, $output, $return_var);
  59. check_return_code($return_var, $output);
  60. unset($output);
  61. unlink($v_password);
  62. $v_password = escapeshellarg($_POST['v_password']);
  63. }
  64. }
  65. // Set success message
  66. if (empty($_SESSION['error_msg'])) {
  67. $_SESSION['ok_msg'] = _('Changes has been saved.');
  68. }
  69. }
  70. // Render page
  71. render_page($user, $TAB, 'edit_db');
  72. // Flush session messages
  73. unset($_SESSION['error_msg']);
  74. unset($_SESSION['ok_msg']);