index.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280
  1. <?php
  2. // Init
  3. error_reporting(NULL);
  4. ob_start();
  5. session_start();
  6. $TAB = 'WEB';
  7. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  8. // Header
  9. include($_SERVER['DOCUMENT_ROOT'].'/templates/header.html');
  10. // Panel
  11. top_panel($user,$TAB);
  12. $v_ftp_email = $panel[$user]['CONTACT'];
  13. if (!empty($_POST['ok'])) {
  14. // Check input
  15. if (empty($_POST['v_domain'])) $errors[] = __('domain');
  16. if (empty($_POST['v_ip'])) $errors[] = __('ip');
  17. if ((!empty($_POST['v_ssl'])) && (empty($_POST['v_ssl_crt']))) $errors[] = __('ssl certificate');
  18. if ((!empty($_POST['v_ssl'])) && (empty($_POST['v_ssl_key']))) $errors[] = __('ssl key');
  19. if ((!empty($_POST['v_aliases'])) && ($_POST['v_aliases'] != 'www.'.$_POST['v_domain'])) $v_adv = 'yes';
  20. if ((!empty($_POST['v_ssl'])) || (!empty($_POST['v_elog']))) $v_adv = 'yes';
  21. if ((!empty($_POST['v_ssl_crt'])) || (!empty($_POST['v_ssl_key']))) $v_adv = 'yes';
  22. if ((!empty($_POST['v_ssl_ca'])) || ($_POST['v_stats'] != 'none')) $v_adv = 'yes';
  23. if (empty($_POST['v_proxy'])) $v_adv = 'yes';
  24. if (!empty($_POST['v_ftp'])) $v_adv = 'yes';
  25. $v_proxy_ext = 'jpeg, jpg, png, gif, bmp, ico, svg, tif, tiff, css, js, htm, html, ttf,';
  26. $v_proxy_ext .= 'otf, webp, woff, txt, csv, rtf, doc, docx, xls, xlsx, ppt, pptx, odf, ';
  27. $v_proxy_ext .= 'odp, ods, odt, pdf, psd, ai, eot, eps, ps, zip, tar, tgz, gz, rar, ';
  28. $v_proxy_ext .= 'bz2, 7z, aac, m4a, mp3, mp4, ogg, wav, wma, 3gp, avi, flv, m4v, mkv, ';
  29. $v_proxy_ext .= 'mov, mp4, mpeg, mpg, wmv, exe, iso, dmg, swf';
  30. if ($_POST['v_proxy_ext'] != $v_proxy_ext) $v_adv = 'yes';
  31. // Protect input
  32. $v_domain = preg_replace("/^www\./i", "", $_POST['v_domain']);
  33. $v_domain = escapeshellarg($v_domain);
  34. $v_domain = strtolower($v_domain);
  35. $v_ip = escapeshellarg($_POST['v_ip']);
  36. if (empty($_POST['v_dns'])) $v_dns = 'off';
  37. if (empty($_POST['v_mail'])) $v_mail = 'off';
  38. if (empty($_POST['v_proxy'])) $v_proxy = 'off';
  39. $v_aliases = $_POST['v_aliases'];
  40. $v_elog = $_POST['v_elog'];
  41. $v_ssl = $_POST['v_ssl'];
  42. $v_ssl_crt = $_POST['v_ssl_crt'];
  43. $v_ssl_key = $_POST['v_ssl_key'];
  44. $v_ssl_ca = $_POST['v_ssl_ca'];
  45. $v_ssl_home = $data[$v_domain]['SSL_HOME'];
  46. $v_stats = escapeshellarg($_POST['v_stats']);
  47. $v_stats_user = $data[$v_domain]['STATS_USER'];
  48. $v_stats_password = $data[$v_domain]['STATS_PASSWORD'];
  49. $v_proxy_ext = preg_replace("/\n/", " ", $_POST['v_proxy_ext']);
  50. $v_proxy_ext = preg_replace("/,/", " ", $v_proxy_ext);
  51. $v_proxy_ext = preg_replace('/\s+/', ' ',$v_proxy_ext);
  52. $v_proxy_ext = trim($v_proxy_ext);
  53. $v_proxy_ext = str_replace(' ', ", ", $v_proxy_ext);
  54. $v_ftp = $_POST['v_ftp'];
  55. $v_ftp_user = $_POST['v_ftp_user'];
  56. $v_ftp_password = $_POST['v_ftp_password'];
  57. $v_ftp_email = $_POST['v_ftp_email'];
  58. // Validate email
  59. if ((!empty($_POST['v_ftp_email'])) && (!filter_var($_POST['v_ftp_email'], FILTER_VALIDATE_EMAIL))) {
  60. $_SESSION['error_msg'] = __('Please enter valid email address.');
  61. }
  62. // Check ftp password length
  63. if ((!empty($_POST['v_ftp'])) && (empty($_SESSION['error_msg']))) {
  64. if (!empty($_POST['v_ftp_user'])) {
  65. $pw_len = strlen($_POST['v_ftp_password']);
  66. if ($pw_len < 6 ) $_SESSION['error_msg'] = __('Password is too short.',$error_msg);
  67. }
  68. }
  69. // Check stats password length
  70. if ((!empty($v_stats)) && (empty($_SESSION['error_msg']))) {
  71. if (!empty($_POST['v_stats_user'])) {
  72. $pw_len = strlen($_POST['v_stats_password']);
  73. if ($pw_len < 6 ) $_SESSION['error_msg'] = __('Password is too short.',$error_msg);
  74. }
  75. }
  76. // Check for errors
  77. if (!empty($errors[0])) {
  78. foreach ($errors as $i => $error) {
  79. if ( $i == 0 ) {
  80. $error_msg = $error;
  81. } else {
  82. $error_msg = $error_msg.", ".$error;
  83. }
  84. }
  85. $_SESSION['error_msg'] = __('Field "%s" can not be blank.',$error_msg);
  86. }
  87. if (empty($_SESSION['error_msg'])) {
  88. // Add WEB
  89. exec (VESTA_CMD."v-add-web-domain ".$user." ".$v_domain." ".$v_ip." 'no'", $output, $return_var);
  90. check_return_code($return_var,$output);
  91. unset($output);
  92. // Add DNS
  93. if (($_POST['v_dns'] == 'on') && (empty($_SESSION['error_msg']))) {
  94. exec (VESTA_CMD."v-add-dns-domain ".$user." ".$v_domain." ".$v_ip, $output, $return_var);
  95. check_return_code($return_var,$output);
  96. unset($output);
  97. }
  98. // Add Mail
  99. if (($_POST['v_mail'] == 'on') && (empty($_SESSION['error_msg']))) {
  100. exec (VESTA_CMD."v-add-mail-domain ".$user." ".$v_domain, $output, $return_var);
  101. check_return_code($return_var,$output);
  102. unset($output);
  103. }
  104. // Add Aliases
  105. if ((!empty($_POST['v_aliases'])) && (empty($_SESSION['error_msg']))) {
  106. $valiases = preg_replace("/\n/", " ", $_POST['v_aliases']);
  107. $valiases = preg_replace("/,/", " ", $valiases);
  108. $valiases = preg_replace('/\s+/', ' ',$valiases);
  109. $valiases = trim($valiases);
  110. $aliases = explode(" ", $valiases);
  111. foreach ($aliases as $alias) {
  112. if ($alias == 'www.'.$_POST['v_domain']) {
  113. $www_alias = 'yes';
  114. } else {
  115. $alias = escapeshellarg($alias);
  116. if (empty($_SESSION['error_msg'])) {
  117. exec (VESTA_CMD."v-add-web-domain-alias ".$user." ".$v_domain." ".$alias." 'no'", $output, $return_var);
  118. check_return_code($return_var,$output);
  119. }
  120. unset($output);
  121. if (($_POST['v_dns'] == 'on') && (empty($_SESSION['error_msg']))) {
  122. exec (VESTA_CMD."v-add-dns-on-web-alias ".$user." ".$v_domain." ".$alias." 'no'", $output, $return_var);
  123. check_return_code($return_var,$output);
  124. unset($output);
  125. }
  126. }
  127. }
  128. }
  129. if ((empty($www_alias)) && (empty($_SESSION['error_msg']))) {
  130. $alias = preg_replace("/^www./i", "", $_POST['v_domain']);
  131. $alias = 'www.'.$alias;
  132. $alias = escapeshellarg($alias);
  133. exec (VESTA_CMD."v-delete-web-domain-alias ".$user." ".$v_domain." ".$alias." 'no'", $output, $return_var);
  134. check_return_code($return_var,$output);
  135. }
  136. // Add proxy
  137. if (($_POST['v_proxy'] == 'on') && (empty($_SESSION['error_msg']))) {
  138. $ext = str_replace(' ', '', $v_proxy_ext);
  139. $ext = escapeshellarg($ext);
  140. exec (VESTA_CMD."v-add-web-domain-proxy ".$user." ".$v_domain." '' ".$ext." 'no'", $output, $return_var);
  141. check_return_code($return_var,$output);
  142. unset($output);
  143. }
  144. // Add SSL
  145. if (!empty($_POST['v_ssl'])) {
  146. exec ('mktemp -d', $output, $return_var);
  147. $tmpdir = $output[0];
  148. // Certificate
  149. if (!empty($_POST['v_ssl_crt'])) {
  150. $fp = fopen($tmpdir."/".$_POST['v_domain'].".crt", 'w');
  151. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_crt']));
  152. fwrite($fp, "\n");
  153. fclose($fp);
  154. }
  155. // Key
  156. if (!empty($_POST['v_ssl_key'])) {
  157. $fp = fopen($tmpdir."/".$_POST['v_domain'].".key", 'w');
  158. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_key']));
  159. fwrite($fp, "\n");
  160. fclose($fp);
  161. }
  162. // CA
  163. if (!empty($_POST['v_ssl_ca'])) {
  164. $fp = fopen($tmpdir."/".$_POST['v_domain'].".ca", 'w');
  165. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_ca']));
  166. fwrite($fp, "\n");
  167. fclose($fp);
  168. }
  169. $v_ssl_home = escapeshellarg($_POST['v_ssl_home']);
  170. exec (VESTA_CMD."v-add-web-domain-ssl ".$user." ".$v_domain." ".$tmpdir." ".$v_ssl_home." 'no'", $output, $return_var);
  171. check_return_code($return_var,$output);
  172. unset($output);
  173. }
  174. // Add WebStats
  175. if ((!empty($_POST['v_stats'])) && ($_POST['v_stats'] != 'none' ) && (empty($_SESSION['error_msg']))) {
  176. $v_stats = escapeshellarg($_POST['v_stats']);
  177. exec (VESTA_CMD."v-add-web-domain-stats ".$user." ".$v_domain." ".$v_stats, $output, $return_var);
  178. check_return_code($return_var,$output);
  179. unset($output);
  180. if ((!empty($_POST['v_stats_user'])) && (empty($_SESSION['error_msg']))) {
  181. $v_stats_user = escapeshellarg($_POST['v_stats_user']);
  182. $v_stats_password = escapeshellarg($_POST['v_stats_password']);
  183. exec (VESTA_CMD."v-add-web-domain-stats-user ".$user." ".$v_domain." ".$v_stats_user." ".$v_stats_password, $output, $return_var);
  184. check_return_code($return_var,$output);
  185. unset($v_stats_user);
  186. unset($v_stats_password);
  187. unset($output);
  188. }
  189. }
  190. // Add FTP
  191. if ((!empty($_POST['v_ftp'])) && (empty($_SESSION['error_msg']))) {
  192. $v_ftp_user = escapeshellarg($_POST['v_ftp_user']);
  193. $v_ftp_password = escapeshellarg($_POST['v_ftp_password']);
  194. exec (VESTA_CMD."v-add-web-domain-ftp ".$user." ".$v_domain." ".$v_ftp_user." ".$v_ftp_password, $output, $return_var);
  195. check_return_code($return_var,$output);
  196. if (empty($_SESSION['error_msg'])) {
  197. if (!empty($v_ftp_email)) {
  198. $to = $_POST['v_ftp_email'];
  199. $subject = __("FTP login credentials");
  200. $hostname = exec('hostname');
  201. $from = __('MAIL_FROM',$hostname);
  202. $mailtext .= __('FTP_ACCOUNT_READY',$_POST['v_domain'],$user,$_POST['v_ftp_user'],$_POST['v_ftp_password']);
  203. send_email($to, $subject, $mailtext, $from);
  204. }
  205. }
  206. unset($v_ftp);
  207. unset($v_ftp_user);
  208. unset($v_ftp_password);
  209. unset($output);
  210. }
  211. if (($_POST['v_dns'] == 'on') && (empty($_SESSION['error_msg']))) {
  212. exec (VESTA_CMD."v-restart-dns", $output, $return_var);
  213. check_return_code($return_var,$output);
  214. unset($output);
  215. }
  216. if (empty($_SESSION['error_msg'])) {
  217. exec (VESTA_CMD."v-restart-web", $output, $return_var);
  218. check_return_code($return_var,$output);
  219. unset($output);
  220. }
  221. if (empty($_SESSION['error_msg'])) {
  222. exec (VESTA_CMD."v-restart-proxy", $output, $return_var);
  223. check_return_code($return_var,$output);
  224. unset($output);
  225. }
  226. if (empty($_SESSION['error_msg'])) {
  227. unset($output);
  228. $_SESSION['ok_msg'] = __('WEB_DOMAIN_CREATED_OK',$_POST[v_domain],$_POST[v_domain]);
  229. unset($v_domain);
  230. unset($v_aliases);
  231. unset($v_ssl);
  232. unset($v_ssl_crt);
  233. unset($v_ssl_key);
  234. unset($v_ssl_ca);
  235. }
  236. }
  237. }
  238. exec (VESTA_CMD."v-list-user-ips ".$user." json", $output, $return_var);
  239. $ips = json_decode(implode('', $output), true);
  240. unset($output);
  241. exec (VESTA_CMD."v-list-web-stats json", $output, $return_var);
  242. $stats = json_decode(implode('', $output), true);
  243. unset($output);
  244. include($_SERVER['DOCUMENT_ROOT'].'/templates/admin/add_web.html');
  245. unset($_SESSION['error_msg']);
  246. unset($_SESSION['ok_msg']);
  247. //}
  248. // Footer
  249. include($_SERVER['DOCUMENT_ROOT'].'/templates/footer.html');