index.php 3.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115
  1. <?php
  2. error_reporting(NULL);
  3. $TAB = 'WEB';
  4. // Main include
  5. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  6. // Prepare values
  7. if (!empty($_GET['domain'])) {
  8. $v_domain = $_GET['domain'];
  9. } else {
  10. $v_domain = 'example.ltd';
  11. }
  12. $v_email = '';
  13. $v_country = 'US';
  14. $v_state = 'California';
  15. $v_locality = 'San Francisco';
  16. $v_org = 'MyCompany LLC';
  17. $v_org_unit = 'IT';
  18. // Back uri
  19. $_SESSION['back'] = '';
  20. // Check POST
  21. if (!isset($_POST['generate'])) {
  22. render_page($user, $TAB, 'generate_ssl');
  23. exit;
  24. }
  25. // Check token
  26. if ((!isset($_POST['token'])) || ($_SESSION['token'] != $_POST['token'])) {
  27. header('Location: /login/');
  28. exit();
  29. }
  30. // Check input
  31. if (empty($_POST['v_domain'])) $errors[] = _('Domain');
  32. if (empty($_POST['v_country'])) $errors[] = _('Country');
  33. if (empty($_POST['v_state'])) $errors[] = _('State');
  34. if (empty($_POST['v_locality'])) $errors[] = _('City');
  35. if (empty($_POST['v_org'])) $errors[] = _('Organization');
  36. $v_domain = $_POST['v_domain'];
  37. $v_aliases = $_POST['v_aliases'];
  38. $v_email = $_POST['v_email'];
  39. $v_country = $_POST['v_country'];
  40. $v_state = $_POST['v_state'];
  41. $v_locality = $_POST['v_locality'];
  42. $v_org = $_POST['v_org'];
  43. // Check for errors
  44. if (!empty($errors[0])) {
  45. foreach ($errors as $i => $error) {
  46. if ( $i == 0 ) {
  47. $error_msg = $error;
  48. } else {
  49. $error_msg = $error_msg.", ".$error;
  50. }
  51. }
  52. $_SESSION['error_msg'] = sprintf(_('Field "%s" can not be blank.'),$error_msg);
  53. render_page($user, $TAB, 'generate_ssl');
  54. unset($_SESSION['error_msg']);
  55. exit;
  56. }
  57. // Protect input
  58. $v_domain = escapeshellarg($_POST['v_domain']);
  59. $waliases = preg_replace("/\n/", " ", $_POST['v_aliases']);
  60. $waliases = preg_replace("/,/", " ", $waliases);
  61. $waliases = preg_replace('/\s+/', ' ',$waliases);
  62. $waliases = trim($waliases);
  63. $aliases = explode(" ", $waliases);
  64. $v_aliases = escapeshellarg(str_replace(' ', "\n", $waliases));
  65. $v_email = escapeshellarg($_POST['v_email']);
  66. $v_country = escapeshellarg($_POST['v_country']);
  67. $v_state = escapeshellarg($_POST['v_state']);
  68. $v_locality = escapeshellarg($_POST['v_locality']);
  69. $v_org = escapeshellarg($_POST['v_org']);
  70. exec (HESTIA_CMD."v-generate-ssl-cert ".$v_domain." ".$v_email." ".$v_country." ".$v_state." ".$v_locality." ".$v_org." IT '".$v_aliases."' json", $output, $return_var);
  71. // Revert to raw values
  72. $v_domain = $_POST['v_domain'];
  73. $v_email = $_POST['v_email'];
  74. $v_country = $_POST['v_country'];
  75. $v_state = $_POST['v_state'];
  76. $v_locality = $_POST['v_locality'];
  77. $v_org = $_POST['v_org'];
  78. // Check return code
  79. if ($return_var != 0) {
  80. $error = implode('<br>', $output);
  81. if (empty($error)) $error = sprintf(_('Error code:'),$return_var);
  82. $_SESSION['error_msg'] = $error;
  83. render_page($user, $TAB, 'generate_ssl');
  84. unset($_SESSION['error_msg']);
  85. exit;
  86. }
  87. // OK message
  88. $_SESSION['ok_msg'] = _('SSL_GENERATED_OK');
  89. // Parse output
  90. $data = json_decode(implode('', $output), true);
  91. unset($output);
  92. $v_crt = $data[$v_domain]['CRT'];
  93. $v_key = $data[$v_domain]['KEY'];
  94. $v_csr = $data[$v_domain]['CSR'];
  95. // Back uri
  96. $_SESSION['back'] = $_SERVER['REQUEST_URI'];
  97. // Render page
  98. render_page($user, $TAB, 'list_ssl');
  99. unset($_SESSION['ok_msg']);