index.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422
  1. <?php
  2. use function Hestiacp\quoteshellarg\quoteshellarg;
  3. ob_start();
  4. $TAB = 'USER';
  5. // Main include
  6. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  7. // Check user argument
  8. if (empty($_GET['user'])) {
  9. header("Location: /list/user/");
  10. exit;
  11. }
  12. // Edit as someone else?
  13. if (($_SESSION['userContext'] === 'admin') && (!empty($_GET['user']))) {
  14. $user=$_GET['user'];
  15. $v_username=$_GET['user'];
  16. } else {
  17. $user=$_SESSION['user'];
  18. $v_username=$_SESSION['user'];
  19. }
  20. // Prevent other users with admin privileges from editing properties of default 'admin' user
  21. if (($_SESSION['userContext'] === 'admin') && (isset($_SESSION['look'])) && ($user == 'admin') || ($_SESSION['userContext'] === 'admin') && (!isset($_SESSION['look'])) && ($user == 'admin') && ($_SESSION['user'] != 'admin')) {
  22. header("Location: /list/user/");
  23. exit;
  24. }
  25. // Check token
  26. verify_csrf($_GET);
  27. // List user
  28. exec(HESTIA_CMD."v-list-user ".quoteshellarg($v_username)." json", $output, $return_var);
  29. check_return_code_redirect($return_var, $output, '/list/user/');
  30. $data = json_decode(implode('', $output), true);
  31. unset($output);
  32. // Parse user
  33. $v_password = "";
  34. $v_email = $data[$v_username]['CONTACT'];
  35. $v_package = $data[$v_username]['PACKAGE'];
  36. $v_language = $data[$v_username]['LANGUAGE'];
  37. $v_user_theme = $data[$v_username]['THEME'];
  38. $v_sort_order = $data[$v_username]['PREF_UI_SORT'];
  39. $v_name = $data[$v_username]['NAME'];
  40. $v_shell = $data[$v_username]['SHELL'];
  41. $v_twofa = $data[$v_username]['TWOFA'];
  42. $v_qrcode = $data[$v_username]['QRCODE'];
  43. $v_phpcli = $data[$v_username]['PHPCLI'];
  44. $v_role = $data[$v_username]['ROLE'];
  45. $v_login_disabled = $data[$v_username]['LOGIN_DISABLED'];
  46. $v_login_use_iplist = $data[$v_username]['LOGIN_USE_IPLIST'];
  47. $v_login_allowed_ips = $data[$v_username]['LOGIN_ALLOW_IPS'];
  48. $v_ns = $data[$v_username]['NS'];
  49. $nameservers = explode(",", $v_ns);
  50. if (empty($nameservers[0])) {
  51. $v_ns1 = '';
  52. } else {
  53. $v_ns1 = $nameservers[0];
  54. }
  55. if (empty($nameservers[1])) {
  56. $v_ns2 = '';
  57. } else {
  58. $v_ns2 = $nameservers[1];
  59. }
  60. if (empty($nameservers[2])) {
  61. $v_ns3 = '';
  62. } else {
  63. $v_ns3 = $nameservers[2];
  64. }
  65. if (empty($nameservers[3])) {
  66. $v_ns4 = '';
  67. } else {
  68. $v_ns4 = $nameservers[3];
  69. }
  70. if (empty($nameservers[4])) {
  71. $v_ns5 = '';
  72. } else {
  73. $v_ns5 = $nameservers[4];
  74. }
  75. if (empty($nameservers[5])) {
  76. $v_ns6 = '';
  77. } else {
  78. $v_ns6 = $nameservers[5];
  79. }
  80. if (empty($nameservers[6])) {
  81. $v_ns7 = '';
  82. } else {
  83. $v_ns7 = $nameservers[6];
  84. }
  85. if (empty($nameservers[7])) {
  86. $v_ns8 = '';
  87. } else {
  88. $v_ns8 = $nameservers[7];
  89. }
  90. $v_suspended = $data[$v_username]['SUSPENDED'];
  91. if ($v_suspended == 'yes') {
  92. $v_status = 'suspended';
  93. } else {
  94. $v_status = 'active';
  95. }
  96. $v_time = $data[$v_username]['TIME'];
  97. $v_date = $data[$v_username]['DATE'];
  98. if (empty($v_phpcli)) {
  99. $v_phpcli = substr(DEFAULT_PHP_VERSION, 4);
  100. }
  101. // List packages
  102. exec(HESTIA_CMD."v-list-user-packages json", $output, $return_var);
  103. $packages = json_decode(implode('', $output), true);
  104. unset($output);
  105. // List languages
  106. exec(HESTIA_CMD."v-list-sys-languages json", $output, $return_var);
  107. $language = json_decode(implode('', $output), true);
  108. foreach ($language as $lang) {
  109. $languages[$lang] = translate_json($lang);
  110. }
  111. asort($languages);
  112. unset($output);
  113. // List themes
  114. exec(HESTIA_CMD."v-list-sys-themes json", $output, $return_var);
  115. $themes = json_decode(implode('', $output), true);
  116. unset($output);
  117. // List shells
  118. exec(HESTIA_CMD."v-list-sys-shells json", $output, $return_var);
  119. $shells = json_decode(implode('', $output), true);
  120. unset($output);
  121. //List PHP Versions
  122. // List supported php versions
  123. exec(HESTIA_CMD."v-list-sys-php json", $output, $return_var);
  124. $php_versions = json_decode(implode('', $output), true);
  125. unset($output);
  126. // Check POST request
  127. if (!empty($_POST['save'])) {
  128. // Check token
  129. verify_csrf($_POST);
  130. // Change password
  131. if ((!empty($_POST['v_password'])) && (empty($_SESSION['error_msg']))) {
  132. // Check password length
  133. $pw_len = strlen($_POST['v_password']);
  134. if (!validate_password($_POST['v_password'])) {
  135. $_SESSION['error_msg'] = _('Password does not match the minimum requirements');
  136. }
  137. if (empty($_SESSION['error_msg'])) {
  138. $v_password = tempnam("/tmp", "vst");
  139. $fp = fopen($v_password, "w");
  140. fwrite($fp, $_POST['v_password']."\n");
  141. fclose($fp);
  142. exec(HESTIA_CMD."v-change-user-password ".quoteshellarg($v_username)." ".$v_password, $output, $return_var);
  143. check_return_code($return_var, $output);
  144. unset($output);
  145. unlink($v_password);
  146. $v_password = quoteshellarg($_POST['v_password']);
  147. }
  148. }
  149. // Enable twofa
  150. if ((!empty($_POST['v_twofa'])) && (empty($v_twofa)) && (empty($_SESSION['error_msg']))) {
  151. exec(HESTIA_CMD."v-add-user-2fa ".quoteshellarg($v_username), $output, $return_var);
  152. check_return_code($return_var, $output);
  153. unset($output);
  154. // List user
  155. exec(HESTIA_CMD."v-list-user ".quoteshellarg($v_username)." json", $output, $return_var);
  156. check_return_code($return_var, $output);
  157. $data = json_decode(implode('', $output), true);
  158. unset($output);
  159. // Parse user twofa
  160. $v_twofa = $data[$v_username]['TWOFA'];
  161. $v_qrcode = $data[$v_username]['QRCODE'];
  162. }
  163. // Disable twofa
  164. if ((empty($_POST['v_twofa'])) && (!empty($v_twofa)) && (empty($_SESSION['error_msg']))) {
  165. exec(HESTIA_CMD."v-delete-user-2fa ".quoteshellarg($v_username), $output, $return_var);
  166. check_return_code($return_var, $output);
  167. unset($output);
  168. $v_twofa = '';
  169. $v_qrcode = '';
  170. }
  171. // Change default sort order
  172. if (($v_sort_order != $_POST['v_sort_order']) && (empty($_SESSION['error_msg']))) {
  173. $v_sort_order = quoteshellarg($_POST['v_sort_order']);
  174. exec(HESTIA_CMD."v-change-user-sort-order ".quoteshellarg($v_username)." ".$v_sort_order, $output, $return_var);
  175. check_return_code($return_var, $output);
  176. unset($_SESSION['userSortOrder']);
  177. $_SESSION['userSortOrder'] = $v_sort_order;
  178. unset($output);
  179. }
  180. // Update Control Panel login disabled status (admin only)
  181. if (empty($_SESSION['error_msg'])) {
  182. if (empty($_POST['v_login_disabled'])) {
  183. $_POST['v_login_disabled'] = '';
  184. }
  185. if ($_POST['v_login_disabled'] != $v_login_disabled) {
  186. if ($_POST['v_login_disabled'] == 'on') {
  187. $_POST['v_login_disabled'] = 'yes';
  188. } else {
  189. $_POST['v_login_disabled'] = 'no';
  190. }
  191. exec(HESTIA_CMD."v-change-user-config-value ".quoteshellarg($v_username)." LOGIN_DISABLED ".quoteshellarg($_POST['v_login_disabled']), $output, $return_var);
  192. check_return_code($return_var, $output);
  193. $data[$user]['LOGIN_DISABLED'] = $_POST['v_login_disabled'];
  194. unset($output);
  195. }
  196. }
  197. // Update IP whitelist option
  198. if (empty($_SESSION['error_msg'])) {
  199. if (empty($_POST['v_login_use_iplist'])) {
  200. $_POST['v_login_use_iplist'] = '';
  201. }
  202. if ($_POST['v_login_use_iplist'] != $v_login_use_iplist) {
  203. if ($_POST['v_login_use_iplist'] == 'on') {
  204. $_POST['v_login_use_iplist'] = 'yes';
  205. } else {
  206. $_POST['v_login_use_iplist'] = 'no';
  207. }
  208. exec(HESTIA_CMD."v-change-user-config-value ".quoteshellarg($v_username)." LOGIN_USE_IPLIST ".quoteshellarg($_POST['v_login_use_iplist']), $output, $return_var);
  209. if ($_POST['v_login_use_iplist'] === 'no') {
  210. exec(HESTIA_CMD."v-change-user-config-value ".quoteshellarg($v_username)." LOGIN_ALLOW_IPS ''", $output, $return_var);
  211. $v_login_allowed_ips = '';
  212. } else {
  213. exec(HESTIA_CMD."v-change-user-config-value ".quoteshellarg($v_username)." LOGIN_ALLOW_IPS ".quoteshellarg($_POST['v_login_allowed_ips']), $output, $return_var);
  214. unset($v_login_allowed_ips);
  215. $v_login_allowed_ips = $_POST['v_login_allowed_ips'];
  216. }
  217. check_return_code($return_var, $output);
  218. $data[$user]['LOGIN_USE_IPLIST'] = $_POST['v_login_use_iplist'];
  219. unset($output);
  220. }
  221. }
  222. if ($_SESSION['userContext'] === 'admin') {
  223. // Change package (admin only)
  224. if (($v_package != $_POST['v_package']) && ($_SESSION['userContext'] === 'admin') && (empty($_SESSION['error_msg']))) {
  225. $v_package = quoteshellarg($_POST['v_package']);
  226. exec(HESTIA_CMD."v-change-user-package ".quoteshellarg($v_username)." ".$v_package, $output, $return_var);
  227. check_return_code($return_var, $output);
  228. unset($output);
  229. }
  230. // Change phpcli (admin only)
  231. if (($v_phpcli != $_POST['v_phpcli']) && ($_SESSION['userContext'] === 'admin') && (empty($_SESSION['error_msg']))) {
  232. $v_phpcli = quoteshellarg($_POST['v_phpcli']);
  233. exec(HESTIA_CMD."v-change-user-php-cli ".quoteshellarg($v_username)." ".$v_phpcli, $output, $return_var);
  234. check_return_code($return_var, $output);
  235. unset($output);
  236. }
  237. if (($v_role != $_POST['v_role']) && ($_SESSION['userContext'] === 'admin') && $v_username != "admin" && (empty($_SESSION['error_msg']))) {
  238. if (!empty($_POST['v_role'])) {
  239. $v_role = quoteshellarg($_POST['v_role']);
  240. exec(HESTIA_CMD."v-change-user-role ".quoteshellarg($v_username)." ".$v_role, $output, $return_var);
  241. check_return_code($return_var, $output);
  242. unset($output);
  243. $v_role = $_POST['v_role'];
  244. }
  245. }
  246. // Change shell (admin only)
  247. if (($v_shell != $_POST['v_shell']) && ($_SESSION['userContext'] === 'admin') && (empty($_SESSION['error_msg']))) {
  248. $v_shell = quoteshellarg($_POST['v_shell']);
  249. exec(HESTIA_CMD."v-change-user-shell ".quoteshellarg($v_username)." ".$v_shell, $output, $return_var);
  250. check_return_code($return_var, $output);
  251. unset($output);
  252. }
  253. }
  254. // Change language
  255. if (($v_language != $_POST['v_language']) && (empty($_SESSION['error_msg']))) {
  256. $v_language = quoteshellarg($_POST['v_language']);
  257. exec(HESTIA_CMD."v-change-user-language ".quoteshellarg($v_username)." ".$v_language, $output, $return_var);
  258. check_return_code($return_var, $output);
  259. if (empty($_SESSION['error_msg'])) {
  260. if (($_GET['user'] == $_SESSION['user'])) {
  261. unset($_SESSION['language']);
  262. $_SESSION['language'] = $_POST['v_language'];
  263. $refresh = $_SERVER['REQUEST_URI'];
  264. header("Location: $refresh");
  265. }
  266. }
  267. unset($output);
  268. }
  269. // Change contact email
  270. if (($v_email != $_POST['v_email']) && (empty($_SESSION['error_msg']))) {
  271. if (!filter_var($_POST['v_email'], FILTER_VALIDATE_EMAIL)) {
  272. $_SESSION['error_msg'] = _('Please enter valid email address.');
  273. } else {
  274. $v_email = quoteshellarg($_POST['v_email']);
  275. exec(HESTIA_CMD."v-change-user-contact ".quoteshellarg($v_username)." ".$v_email, $output, $return_var);
  276. check_return_code($return_var, $output);
  277. unset($output);
  278. }
  279. }
  280. // Change full name
  281. if ($v_name != $_POST['v_name']) {
  282. if (empty($_POST['v_name'])) {
  283. $_SESSION['error_msg'] = _('Please enter a valid name');
  284. } else {
  285. $v_name = quoteshellarg($_POST['v_name']);
  286. exec(HESTIA_CMD."v-change-user-name ".quoteshellarg($v_username). " ".$v_name, $output, $return_var);
  287. check_return_code($return_var, $output);
  288. unset($output);
  289. $v_name = $_POST['v_name'];
  290. }
  291. }
  292. // Update theme
  293. if (empty($_SESSION['error_msg'])) {
  294. if ($_POST['v_user_theme'] != $_SESSION['userTheme']) {
  295. exec(HESTIA_CMD."v-change-user-theme ".quoteshellarg($v_username)." ".quoteshellarg($_POST['v_user_theme']), $output, $return_var);
  296. check_return_code($return_var, $output);
  297. unset($output);
  298. $v_user_theme = $_POST['v_user_theme'];
  299. if ($_SESSION['user'] === $v_username) {
  300. unset($_SESSION['userTheme']);
  301. $_SESSION['userTheme'] = $v_user_theme;
  302. }
  303. }
  304. }
  305. // Change NameServers
  306. if (empty($_POST['v_ns1'])) {
  307. $_POST['v_ns1'] = '';
  308. }
  309. if (empty($_POST['v_ns2'])) {
  310. $_POST['v_ns2'] = '';
  311. }
  312. if (empty($_POST['v_ns3'])) {
  313. $_POST['v_ns3'] = '';
  314. }
  315. if (empty($_POST['v_ns4'])) {
  316. $_POST['v_ns4'] = '';
  317. }
  318. if (empty($_POST['v_ns5'])) {
  319. $_POST['v_ns5'] = '';
  320. }
  321. if (empty($_POST['v_ns6'])) {
  322. $_POST['v_ns6'] = '';
  323. }
  324. if (empty($_POST['v_ns7'])) {
  325. $_POST['v_ns7'] = '';
  326. }
  327. if (empty($_POST['v_ns8'])) {
  328. $_POST['v_ns8'] = '';
  329. }
  330. if (($v_ns1 != $_POST['v_ns1']) || ($v_ns2 != $_POST['v_ns2']) || ($v_ns3 != $_POST['v_ns3']) || ($v_ns4 != $_POST['v_ns4']) || ($v_ns5 != $_POST['v_ns5'])
  331. || ($v_ns6 != $_POST['v_ns6']) || ($v_ns7 != $_POST['v_ns7']) || ($v_ns8 != $_POST['v_ns8']) && (empty($_SESSION['error_msg']))) {
  332. $v_ns1 = quoteshellarg($_POST['v_ns1']);
  333. $v_ns2 = quoteshellarg($_POST['v_ns2']);
  334. $v_ns3 = quoteshellarg($_POST['v_ns3']);
  335. $v_ns4 = quoteshellarg($_POST['v_ns4']);
  336. $v_ns5 = quoteshellarg($_POST['v_ns5']);
  337. $v_ns6 = quoteshellarg($_POST['v_ns6']);
  338. $v_ns7 = quoteshellarg($_POST['v_ns7']);
  339. $v_ns8 = quoteshellarg($_POST['v_ns8']);
  340. $ns_cmd = HESTIA_CMD."v-change-user-ns ".quoteshellarg($v_username)." ".$v_ns1." ".$v_ns2;
  341. if (!empty($_POST['v_ns3'])) {
  342. $ns_cmd = $ns_cmd." ".$v_ns3;
  343. }
  344. if (!empty($_POST['v_ns4'])) {
  345. $ns_cmd = $ns_cmd." ".$v_ns4;
  346. }
  347. if (!empty($_POST['v_ns5'])) {
  348. $ns_cmd = $ns_cmd." ".$v_ns5;
  349. }
  350. if (!empty($_POST['v_ns6'])) {
  351. $ns_cmd = $ns_cmd." ".$v_ns6;
  352. }
  353. if (!empty($_POST['v_ns7'])) {
  354. $ns_cmd = $ns_cmd." ".$v_ns7;
  355. }
  356. if (!empty($_POST['v_ns8'])) {
  357. $ns_cmd = $ns_cmd." ".$v_ns8;
  358. }
  359. exec($ns_cmd, $output, $return_var);
  360. check_return_code($return_var, $output);
  361. unset($output);
  362. $v_ns1 = str_replace("'", "", $v_ns1);
  363. $v_ns2 = str_replace("'", "", $v_ns2);
  364. $v_ns3 = str_replace("'", "", $v_ns3);
  365. $v_ns4 = str_replace("'", "", $v_ns4);
  366. $v_ns5 = str_replace("'", "", $v_ns5);
  367. $v_ns6 = str_replace("'", "", $v_ns6);
  368. $v_ns7 = str_replace("'", "", $v_ns7);
  369. $v_ns8 = str_replace("'", "", $v_ns8);
  370. }
  371. // Set success message
  372. if (empty($_SESSION['error_msg'])) {
  373. $_SESSION['ok_msg'] = _('Changes has been saved.');
  374. }
  375. }
  376. // Render page
  377. render_page($user, $TAB, 'edit_user');
  378. // Flush session messages
  379. unset($_SESSION['error_msg']);
  380. unset($_SESSION['ok_msg']);