index.php 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431
  1. <?php
  2. error_reporting(NULL);
  3. $TAB = 'SERVER';
  4. // Main include
  5. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  6. // Check user
  7. if ($_SESSION['user'] != 'admin') {
  8. header("Location: /list/user");
  9. exit;
  10. }
  11. // Get server hostname
  12. $v_hostname = exec('hostname');
  13. // List available timezones and get current one
  14. $v_timezones = list_timezones();
  15. exec (HESTIA_CMD."v-get-sys-timezone", $output, $return_var);
  16. $v_timezone = $output[0];
  17. unset($output);
  18. if ($v_timezone == 'Etc/UTC' ) $v_timezone = 'UTC';
  19. if ($v_timezone == 'Pacific/Honolulu' ) $v_timezone = 'HAST';
  20. if ($v_timezone == 'US/Aleutian' ) $v_timezone = 'HADT';
  21. if ($v_timezone == 'Etc/GMT+9' ) $v_timezone = 'AKST';
  22. if ($v_timezone == 'America/Anchorage' ) $v_timezone = 'AKDT';
  23. if ($v_timezone == 'America/Dawson_Creek' ) $v_timezone = 'PST';
  24. if ($v_timezone == 'PST8PDT' ) $v_timezone = 'PDT';
  25. if ($v_timezone == 'MST7MDT' ) $v_timezone = 'MDT';
  26. if ($v_timezone == 'Canada/Saskatchewan' ) $v_timezone = 'CST';
  27. if ($v_timezone == 'CST6CDT' ) $v_timezone = 'CDT';
  28. if ($v_timezone == 'EST5EDT' ) $v_timezone = 'EDT';
  29. if ($v_timezone == 'America/Puerto_Rico' ) $v_timezone = 'AST';
  30. if ($v_timezone == 'America/Halifax' ) $v_timezone = 'ADT';
  31. // List supported languages
  32. exec (HESTIA_CMD."v-list-sys-languages json", $output, $return_var);
  33. $languages = json_decode(implode('', $output), true);
  34. unset($output);
  35. // List dns cluster hosts
  36. exec (HESTIA_CMD."v-list-remote-dns-hosts json", $output, $return_var);
  37. $dns_cluster = json_decode(implode('', $output), true);
  38. unset($output);
  39. foreach ($dns_cluster as $key => $value) {
  40. $v_dns_cluster = 'yes';
  41. }
  42. // List Database hosts
  43. exec (HESTIA_CMD."v-list-database-hosts json", $output, $return_var);
  44. $db_hosts = json_decode(implode('', $output), true);
  45. unset($output);
  46. $v_mysql_hosts = array_values(array_filter($db_hosts, function($host){return $host['TYPE'] === 'mysql';}));
  47. $v_mysql = count($v_mysql_hosts) ? 'yes' : 'no';
  48. $v_pgsql_hosts = array_values(array_filter($db_hosts, function($host){return $host['TYPE'] === 'pgsql';}));
  49. $v_pgsql = count($v_pgsql_hosts) ? 'yes' : 'no';
  50. unset($db_hosts);
  51. // List backup settings
  52. $v_backup_dir = "/backup";
  53. if (!empty($_SESSION['BACKUP'])) $v_backup_dir = $_SESSION['BACKUP'];
  54. $v_backup_gzip = '5';
  55. if (!empty($_SESSION['BACKUP_GZIP'])) $v_backup_gzip = $_SESSION['BACKUP_GZIP'];
  56. $backup_types = explode(",",$_SESSION['BACKUP_SYSTEM']);
  57. foreach ($backup_types as $backup_type) {
  58. if ($backup_type == 'local') {
  59. $v_backup = 'yes';
  60. } else {
  61. exec (HESTIA_CMD."v-list-backup-host ".escapeshellarg($backup_type)." json", $output, $return_var);
  62. $v_remote_backup = json_decode(implode('', $output), true);
  63. unset($output);
  64. $v_backup_host = $v_remote_backup[$backup_type]['HOST'];
  65. $v_backup_type = $v_remote_backup[$backup_type]['TYPE'];
  66. $v_backup_username = $v_remote_backup[$backup_type]['USERNAME'];
  67. $v_backup_password = "";
  68. $v_backup_port = $v_remote_backup[$backup_type]['PORT'];
  69. $v_backup_bpath = $v_remote_backup[$backup_type]['BPATH'];
  70. }
  71. }
  72. // List ssl certificate info
  73. exec (HESTIA_CMD."v-list-sys-hestia-ssl json", $output, $return_var);
  74. $ssl_str = json_decode(implode('', $output), true);
  75. unset($output);
  76. $v_ssl_crt = $ssl_str['HESTIA']['CRT'];
  77. $v_ssl_key = $ssl_str['HESTIA']['KEY'];
  78. $v_ssl_ca = $ssl_str['HESTIA']['CA'];
  79. $v_ssl_subject = $ssl_str['HESTIA']['SUBJECT'];
  80. $v_ssl_aliases = $ssl_str['HESTIA']['ALIASES'];
  81. $v_ssl_not_before = $ssl_str['HESTIA']['NOT_BEFORE'];
  82. $v_ssl_not_after = $ssl_str['HESTIA']['NOT_AFTER'];
  83. $v_ssl_signature = $ssl_str['HESTIA']['SIGNATURE'];
  84. $v_ssl_pub_key = $ssl_str['HESTIA']['PUB_KEY'];
  85. $v_ssl_issuer = $ssl_str['HESTIA']['ISSUER'];
  86. // Check POST request
  87. if (!empty($_POST['save'])) {
  88. // Check token
  89. if ((!isset($_POST['token'])) || ($_SESSION['token'] != $_POST['token'])) {
  90. header('location: /login/');
  91. exit();
  92. }
  93. // Change hostname
  94. if ((!empty($_POST['v_hostname'])) && ($v_hostname != $_POST['v_hostname'])) {
  95. exec (HESTIA_CMD."v-change-sys-hostname ".escapeshellarg($_POST['v_hostname']), $output, $return_var);
  96. check_return_code($return_var,$output);
  97. unset($output);
  98. $v_hostname = $_POST['v_hostname'];
  99. }
  100. // Change timezone
  101. if (empty($_SESSION['error_msg'])) {
  102. if (!empty($_POST['v_timezone'])) {
  103. $v_tz = $_POST['v_timezone'];
  104. if ($v_tz == 'UTC' ) $v_tz = 'Etc/UTC';
  105. if ($v_tz == 'HAST' ) $v_tz = 'Pacific/Honolulu';
  106. if ($v_tz == 'HADT' ) $v_tz = 'US/Aleutian';
  107. if ($v_tz == 'AKST' ) $v_tz = 'Etc/GMT+9';
  108. if ($v_tz == 'AKDT' ) $v_tz = 'America/Anchorage';
  109. if ($v_tz == 'PST' ) $v_tz = 'America/Dawson_Creek';
  110. if ($v_tz == 'PDT' ) $v_tz = 'PST8PDT';
  111. if ($v_tz == 'MDT' ) $v_tz = 'MST7MDT';
  112. if ($v_tz == 'CST' ) $v_tz = 'Canada/Saskatchewan';
  113. if ($v_tz == 'CDT' ) $v_tz = 'CST6CDT';
  114. if ($v_tz == 'EDT' ) $v_tz = 'EST5EDT';
  115. if ($v_tz == 'AST' ) $v_tz = 'America/Puerto_Rico';
  116. if ($v_tz == 'ADT' ) $v_tz = 'America/Halifax';
  117. if ($v_timezone != $v_tz) {
  118. exec (HESTIA_CMD."v-change-sys-timezone ".escapeshellarg($v_tz), $output, $return_var);
  119. check_return_code($return_var,$output);
  120. $v_timezone = $v_tz;
  121. unset($output);
  122. }
  123. }
  124. }
  125. // Change default language
  126. if (empty($_SESSION['error_msg'])) {
  127. if ((!empty($_POST['v_language'])) && ($_SESSION['LANGUAGE'] != $_POST['v_language'])) {
  128. exec (HESTIA_CMD."v-change-sys-language ".escapeshellarg($_POST['v_language']), $output, $return_var);
  129. check_return_code($return_var,$output);
  130. unset($output);
  131. if (empty($_SESSION['error_msg'])) $_SESSION['LANGUAGE'] = $_POST['v_language'];
  132. }
  133. }
  134. // Set disk_quota support
  135. if (empty($_SESSION['error_msg'])) {
  136. if ((!empty($_POST['v_quota'])) && ($_SESSION['DISK_QUOTA'] != $_POST['v_quota'])) {
  137. if($_POST['v_quota'] == 'yes') {
  138. exec (HESTIA_CMD."v-add-sys-quota", $output, $return_var);
  139. check_return_code($return_var,$output);
  140. unset($output);
  141. if (empty($_SESSION['error_msg'])) $_SESSION['DISK_QUOTA'] = 'yes';
  142. } else {
  143. exec (HESTIA_CMD."v-delete-sys-quota", $output, $return_var);
  144. check_return_code($return_var,$output);
  145. unset($output);
  146. if (empty($_SESSION['error_msg'])) $_SESSION['DISK_QUOTA'] = 'no';
  147. }
  148. }
  149. }
  150. // Set firewall support
  151. if (empty($_SESSION['error_msg'])) {
  152. if ($_SESSION['FIREWALL_SYSTEM'] == 'iptables') $v_firewall = 'yes';
  153. if ($_SESSION['FIREWALL_SYSTEM'] != 'iptables') $v_firewall = 'no';
  154. if ((!empty($_POST['v_firewall'])) && ($v_firewall != $_POST['v_firewall'])) {
  155. if($_POST['v_firewall'] == 'yes') {
  156. exec (HESTIA_CMD."v-add-sys-firewall", $output, $return_var);
  157. check_return_code($return_var,$output);
  158. unset($output);
  159. if (empty($_SESSION['error_msg'])) $_SESSION['FIREWALL_SYSTEM'] = 'iptables';
  160. } else {
  161. exec (HESTIA_CMD."v-delete-sys-firewall", $output, $return_var);
  162. check_return_code($return_var,$output);
  163. unset($output);
  164. if (empty($_SESSION['error_msg'])) $_SESSION['FIREWALL_SYSTEM'] = '';
  165. }
  166. }
  167. }
  168. // Update mysql pasword
  169. if (empty($_SESSION['error_msg'])) {
  170. if (!empty($_POST['v_mysql_password'])) {
  171. exec (HESTIA_CMD."v-change-database-host-password mysql localhost root ".escapeshellarg($_POST['v_mysql_password']), $output, $return_var);
  172. check_return_code($return_var,$output);
  173. unset($output);
  174. $v_db_adv = 'yes';
  175. }
  176. }
  177. // Update webmail url
  178. if (empty($_SESSION['error_msg'])) {
  179. if ($_POST['v_webmail_alias'] != $_SESSION['WEBMAIL_ALIAS']) {
  180. exec (HESTIA_CMD."v-change-sys-webmail ".escapeshellarg($_POST['v_webmail_alias']), $output, $return_var);
  181. check_return_code($return_var,$output);
  182. unset($output);
  183. $v_mail_adv = 'yes';
  184. }
  185. }
  186. // Update phpMyAdmin url
  187. if (empty($_SESSION['error_msg'])) {
  188. if ($_POST['v_mysql_url'] != $_SESSION['DB_PMA_URL']) {
  189. exec (HESTIA_CMD."v-change-sys-config-value DB_PMA_URL ".escapeshellarg($_POST['v_mysql_url']), $output, $return_var);
  190. check_return_code($return_var,$output);
  191. unset($output);
  192. $v_db_adv = 'yes';
  193. }
  194. }
  195. // Update phpPgAdmin url
  196. if (empty($_SESSION['error_msg'])) {
  197. if ($_POST['v_pgsql_url'] != $_SESSION['DB_PGA_URL']) {
  198. exec (HESTIA_CMD."v-change-sys-config-value DB_PGA_URL ".escapeshellarg($_POST['v_pgsql_url']), $output, $return_var);
  199. check_return_code($return_var,$output);
  200. unset($output);
  201. $v_db_adv = 'yes';
  202. }
  203. }
  204. // Update release branch
  205. if (empty($_SESSION['error_msg'])) {
  206. if ($_POST['v_release_branch'] != $_SESSION['RELEASE_BRANCH']) {
  207. exec (HESTIA_CMD."v-change-sys-release ".escapeshellarg($_POST['v_release_branch']), $output, $return_var);
  208. check_return_code($return_var,$output);
  209. unset($output);
  210. $v_release_adv = 'yes';
  211. }
  212. }
  213. // Disable local backup
  214. if (empty($_SESSION['error_msg'])) {
  215. if (($_POST['v_backup'] == 'no') && ($v_backup == 'yes' )) {
  216. exec (HESTIA_CMD."v-delete-backup-host local", $output, $return_var);
  217. check_return_code($return_var,$output);
  218. unset($output);
  219. if (empty($_SESSION['error_msg'])) $v_backup = 'no';
  220. $v_backup_adv = 'yes';
  221. }
  222. }
  223. // Enable local backups
  224. if (empty($_SESSION['error_msg'])) {
  225. if (($_POST['v_backup'] == 'yes') && ($v_backup != 'yes' )) {
  226. exec (HESTIA_CMD."v-add-backup-host local", $output, $return_var);
  227. check_return_code($return_var,$output);
  228. unset($output);
  229. if (empty($_SESSION['error_msg'])) $v_backup = 'yes';
  230. $v_backup_adv = 'yes';
  231. }
  232. }
  233. // Change backup gzip level
  234. if (empty($_SESSION['error_msg'])) {
  235. if ($_POST['v_backup_gzip'] != $v_backup_gzip ) {
  236. exec (HESTIA_CMD."v-change-sys-config-value BACKUP_GZIP ".escapeshellarg($_POST['v_backup_gzip']), $output, $return_var);
  237. check_return_code($return_var,$output);
  238. unset($output);
  239. if (empty($_SESSION['error_msg'])) $v_backup_gzip = $_POST['v_backup_gzip'];
  240. $v_backup_adv = 'yes';
  241. }
  242. }
  243. // Change backup path
  244. if (empty($_SESSION['error_msg'])) {
  245. if ($_POST['v_backup_dir'] != $v_backup_dir ) {
  246. exec (HESTIA_CMD."v-change-sys-config-value BACKUP ".escapeshellarg($_POST['v_backup_dir']), $output, $return_var);
  247. check_return_code($return_var,$output);
  248. unset($output);
  249. if (empty($_SESSION['error_msg'])) $v_backup_dir = $_POST['v_backup_dir'];
  250. $v_backup_adv = 'yes';
  251. }
  252. }
  253. // Add remote backup host
  254. if (empty($_SESSION['error_msg'])) {
  255. if ((!empty($_POST['v_backup_host'])) && (empty($v_backup_host))) {
  256. $v_backup_host = escapeshellarg($_POST['v_backup_host']);
  257. $v_backup_type = escapeshellarg($_POST['v_backup_type']);
  258. $v_backup_username = escapeshellarg($_POST['v_backup_username']);
  259. $v_backup_password = escapeshellcmd($_POST['v_backup_password']);
  260. $v_backup_bpath = escapeshellarg($_POST['v_backup_bpath']);
  261. exec (HESTIA_CMD."v-add-backup-host ". $v_backup_type ." ". $v_backup_host ." ". $v_backup_username ." '". $v_backup_password ."' ". $v_backup_bpath, $output, $return_var);
  262. check_return_code($return_var,$output);
  263. unset($output);
  264. if (empty($_SESSION['error_msg'])) $v_backup_host = $_POST['v_backup_host'];
  265. if (empty($_SESSION['error_msg'])) $v_backup_type = $_POST['v_backup_type'];
  266. if (empty($_SESSION['error_msg'])) $v_backup_username = $_POST['v_backup_username'];
  267. if (empty($_SESSION['error_msg'])) $v_backup_password = $_POST['v_backup_password'];
  268. if (empty($_SESSION['error_msg'])) $v_backup_bpath = $_POST['v_backup_bpath'];
  269. $v_backup_new = 'yes';
  270. $v_backup_adv = 'yes';
  271. $v_backup_remote_adv = 'yes';
  272. }
  273. }
  274. // Change remote backup host type
  275. if (empty($_SESSION['error_msg'])) {
  276. if ((!empty($_POST['v_backup_host'])) && ($_POST['v_backup_type'] != $v_backup_type)) {
  277. exec (HESTIA_CMD."v-delete-backup-host '". $v_backup_type ."'", $output, $return_var);
  278. unset($output);
  279. $v_backup_host = escapeshellarg($_POST['v_backup_host']);
  280. $v_backup_type = escapeshellarg($_POST['v_backup_type']);
  281. $v_backup_username = escapeshellarg($_POST['v_backup_username']);
  282. $v_backup_password = escapeshellcmd($_POST['v_backup_password']);
  283. $v_backup_bpath = escapeshellarg($_POST['v_backup_bpath']);
  284. exec (HESTIA_CMD."v-add-backup-host ". $v_backup_type ." ". $v_backup_host ." ". $v_backup_username ." '". $v_backup_password ."' ". $v_backup_bpath, $output, $return_var);
  285. check_return_code($return_var,$output);
  286. unset($output);
  287. if (empty($_SESSION['error_msg'])) $v_backup_host = $_POST['v_backup_host'];
  288. if (empty($_SESSION['error_msg'])) $v_backup_type = $_POST['v_backup_type'];
  289. if (empty($_SESSION['error_msg'])) $v_backup_username = $_POST['v_backup_username'];
  290. if (empty($_SESSION['error_msg'])) $v_backup_password = $_POST['v_backup_password'];
  291. if (empty($_SESSION['error_msg'])) $v_backup_bpath = $_POST['v_backup_bpath'];
  292. $v_backup_adv = 'yes';
  293. $v_backup_remote_adv = 'yes';
  294. }
  295. }
  296. // Change remote backup host
  297. if (empty($_SESSION['error_msg'])) {
  298. if ((!empty($_POST['v_backup_host'])) && ($_POST['v_backup_type'] == $v_backup_type) && (!isset($v_backup_new))) {
  299. if (($_POST['v_backup_host'] != $v_backup_host) || ($_POST['v_backup_username'] != $v_backup_username) || ($_POST['v_backup_password'] != $v_backup_password) || ($_POST['v_backup_bpath'] != $v_backup_bpath)){
  300. $v_backup_host = escapeshellarg($_POST['v_backup_host']);
  301. $v_backup_type = escapeshellarg($_POST['v_backup_type']);
  302. $v_backup_username = escapeshellarg($_POST['v_backup_username']);
  303. $v_backup_password = escapeshellcmd($_POST['v_backup_password']);
  304. $v_backup_bpath = escapeshellarg($_POST['v_backup_bpath']);
  305. exec (HESTIA_CMD."v-add-backup-host ". $v_backup_type ." ". $v_backup_host ." ". $v_backup_username ." '". $v_backup_password ."' ". $v_backup_bpath, $output, $return_var);
  306. check_return_code($return_var,$output);
  307. unset($output);
  308. if (empty($_SESSION['error_msg'])) $v_backup_host = $_POST['v_backup_host'];
  309. if (empty($_SESSION['error_msg'])) $v_backup_type = $_POST['v_backup_type'];
  310. if (empty($_SESSION['error_msg'])) $v_backup_username = $_POST['v_backup_username'];
  311. if (empty($_SESSION['error_msg'])) $v_backup_password = $_POST['v_backup_password'];
  312. if (empty($_SESSION['error_msg'])) $v_backup_bpath = $_POST['v_backup_bpath'];
  313. $v_backup_adv = 'yes';
  314. $v_backup_remote_adv = 'yes';
  315. }
  316. }
  317. }
  318. // Delete remote backup host
  319. if (empty($_SESSION['error_msg'])) {
  320. if ((empty($_POST['v_backup_host'])) && (!empty($v_backup_host))) {
  321. exec (HESTIA_CMD."v-delete-backup-host ".escapeshellarg($v_backup_type), $output, $return_var);
  322. check_return_code($return_var,$output);
  323. unset($output);
  324. if (empty($_SESSION['error_msg'])) $v_backup_host = '';
  325. if (empty($_SESSION['error_msg'])) $v_backup_type = '';
  326. if (empty($_SESSION['error_msg'])) $v_backup_username = '';
  327. if (empty($_SESSION['error_msg'])) $v_backup_password = '';
  328. if (empty($_SESSION['error_msg'])) $v_backup_bpath = '';
  329. $v_backup_adv = '';
  330. $v_backup_remote_adv = '';
  331. }
  332. }
  333. // Update SSL certificate
  334. if ((!empty($_POST['v_ssl_crt'])) && (empty($_SESSION['error_msg']))) {
  335. if (($v_ssl_crt != str_replace("\r\n", "\n", $_POST['v_ssl_crt'])) || ($v_ssl_key != str_replace("\r\n", "\n", $_POST['v_ssl_key']))) {
  336. exec ('mktemp -d', $mktemp_output, $return_var);
  337. $tmpdir = $mktemp_output[0];
  338. // Certificate
  339. if (!empty($_POST['v_ssl_crt'])) {
  340. $fp = fopen($tmpdir."/certificate.crt", 'w');
  341. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_crt']));
  342. fwrite($fp, "\n");
  343. fclose($fp);
  344. }
  345. // Key
  346. if (!empty($_POST['v_ssl_key'])) {
  347. $fp = fopen($tmpdir."/certificate.key", 'w');
  348. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_key']));
  349. fwrite($fp, "\n");
  350. fclose($fp);
  351. }
  352. exec (HESTIA_CMD."v-change-sys-hestia-ssl ".$tmpdir, $output, $return_var);
  353. check_return_code($return_var,$output);
  354. unset($output);
  355. // List ssl certificate info
  356. exec (HESTIA_CMD."v-list-sys-hestia-ssl json", $output, $return_var);
  357. $ssl_str = json_decode(implode('', $output), true);
  358. unset($output);
  359. $v_ssl_crt = $ssl_str['HESTIA']['CRT'];
  360. $v_ssl_key = $ssl_str['HESTIA']['KEY'];
  361. $v_ssl_ca = $ssl_str['HESTIA']['CA'];
  362. $v_ssl_subject = $ssl_str['HESTIA']['SUBJECT'];
  363. $v_ssl_aliases = $ssl_str['HESTIA']['ALIASES'];
  364. $v_ssl_not_before = $ssl_str['HESTIA']['NOT_BEFORE'];
  365. $v_ssl_not_after = $ssl_str['HESTIA']['NOT_AFTER'];
  366. $v_ssl_signature = $ssl_str['HESTIA']['SIGNATURE'];
  367. $v_ssl_pub_key = $ssl_str['HESTIA']['PUB_KEY'];
  368. $v_ssl_issuer = $ssl_str['HESTIA']['ISSUER'];
  369. }
  370. }
  371. // Flush field values on success
  372. if (empty($_SESSION['error_msg'])) {
  373. $_SESSION['ok_msg'] = __('Changes has been saved.');
  374. }
  375. }
  376. // Check system configuration
  377. exec (HESTIA_CMD . "v-list-sys-config json", $output, $return_var);
  378. $data = json_decode(implode('', $output), true);
  379. unset($output);
  380. $sys_arr = $data['config'];
  381. foreach ($sys_arr as $key => $value) {
  382. $_SESSION[$key] = $value;
  383. }
  384. // Render page
  385. render_page($user, $TAB, 'edit_server');
  386. // Flush session messages
  387. unset($_SESSION['error_msg']);
  388. unset($_SESSION['ok_msg']);