main.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407
  1. <?php
  2. session_start();
  3. define('HESTIA_CMD', '/usr/bin/sudo /usr/local/hestia/bin/');
  4. define('JS_LATEST_UPDATE', '1491697868');
  5. define('DEFAULT_PHP_VERSION', "php-" . exec('php -r "echo (float)phpversion();"'));
  6. $i = 0;
  7. require_once(dirname(__FILE__).'/i18n.php');
  8. // Saving user IPs to the session for preventing session hijacking
  9. $user_combined_ip = $_SERVER['REMOTE_ADDR'];
  10. if(isset($_SERVER['HTTP_CLIENT_IP'])){
  11. $user_combined_ip .= '|'. $_SERVER['HTTP_CLIENT_IP'];
  12. }
  13. if(isset($_SERVER['HTTP_X_FORWARDED_FOR'])){
  14. $user_combined_ip .= '|'. $_SERVER['HTTP_X_FORWARDED_FOR'];
  15. }
  16. if(isset($_SERVER['HTTP_FORWARDED_FOR'])){
  17. $user_combined_ip .= '|'. $_SERVER['HTTP_FORWARDED_FOR'];
  18. }
  19. if(isset($_SERVER['HTTP_X_FORWARDED'])){
  20. $user_combined_ip .= '|'. $_SERVER['HTTP_X_FORWARDED'];
  21. }
  22. if(isset($_SERVER['HTTP_FORWARDED'])){
  23. $user_combined_ip .= '|'. $_SERVER['HTTP_FORWARDED'];
  24. }
  25. if(isset($_SERVER['HTTP_CF_CONNECTING_IP'])){
  26. if(!empty($_SERVER['HTTP_CF_CONNECTING_IP'])){
  27. $user_combined_ip = $_SERVER['HTTP_CF_CONNECTING_IP'];
  28. }
  29. }
  30. if(!isset($_SESSION['user_combined_ip'])){
  31. $_SESSION['user_combined_ip'] = $user_combined_ip;
  32. }
  33. // Checking user to use session from the same IP he has been logged in
  34. if($_SESSION['user_combined_ip'] != $user_combined_ip && $_SERVER['REMOTE_ADDR'] != '127.0.0.1'){
  35. session_destroy();
  36. session_start();
  37. $_SESSION['request_uri'] = $_SERVER['REQUEST_URI'];
  38. header("Location: /login/");
  39. exit;
  40. }
  41. // Check system settings
  42. if ((!isset($_SESSION['VERSION'])) && (!defined('NO_AUTH_REQUIRED'))) {
  43. session_destroy();
  44. session_start();
  45. $_SESSION['request_uri'] = $_SERVER['REQUEST_URI'];
  46. header("Location: /login/");
  47. exit;
  48. }
  49. // Check user session
  50. if ((!isset($_SESSION['user'])) && (!defined('NO_AUTH_REQUIRED'))) {
  51. $_SESSION['request_uri'] = $_SERVER['REQUEST_URI'];
  52. header("Location: /login/");
  53. exit;
  54. }
  55. // Generate CSRF Token
  56. if (isset($_SESSION['user'])) {
  57. if(!isset($_SESSION['token'])){
  58. $token = bin2hex(file_get_contents('/dev/urandom', false, null, 0, 16));
  59. $_SESSION['token'] = $token;
  60. }
  61. }
  62. if (isset($_SESSION['language'])) {
  63. switch ($_SESSION['language']) {
  64. case 'ro':
  65. setlocale(LC_ALL, 'ro_RO.utf8');
  66. break;
  67. case 'ru':
  68. setlocale(LC_ALL, 'ru_RU.utf8');
  69. break;
  70. case 'ua':
  71. setlocale(LC_ALL, 'uk_UA.utf8');
  72. break;
  73. case 'es':
  74. setlocale(LC_ALL, 'es_ES.utf8');
  75. break;
  76. case 'ja':
  77. setlocale(LC_ALL, 'ja_JP.utf8');
  78. break;
  79. default:
  80. setlocale(LC_ALL, 'en_US.utf8');
  81. }
  82. }
  83. if (isset($_SESSION['user'])) {
  84. $user = $_SESSION['user'];
  85. load_hestia_config();
  86. }
  87. if (isset($_SESSION['look']) && ( $_SESSION['look'] != 'admin' )) {
  88. $user = $_SESSION['look'];
  89. }
  90. function get_favourites(){
  91. exec (HESTIA_CMD."v-list-user-favourites ".$_SESSION['user']." json", $output, $return_var);
  92. // $data = json_decode(implode('', $output).'}', true);
  93. $data = json_decode(implode('', $output), true);
  94. $data = array_reverse($data,true);
  95. $favourites = array();
  96. foreach($data['Favourites'] as $key => $favourite){
  97. $favourites[$key] = array();
  98. $items = explode(',', $favourite);
  99. foreach($items as $item){
  100. if($item)
  101. $favourites[$key][trim($item)] = 1;
  102. }
  103. }
  104. $_SESSION['favourites'] = $favourites;
  105. }
  106. function check_error($return_var) {
  107. if ( $return_var > 0 ) {
  108. header("Location: /error/");
  109. exit;
  110. }
  111. }
  112. function check_return_code($return_var,$output) {
  113. if ($return_var != 0) {
  114. $error = implode('<br>', $output);
  115. if (empty($error)) $error = __('Error code:',$return_var);
  116. $_SESSION['error_msg'] = $error;
  117. }
  118. }
  119. function render_page($user, $TAB, $page) {
  120. $__template_dir = dirname(__DIR__) . '/templates/';
  121. $__pages_js_dir = dirname(__DIR__) . '/js/pages/';
  122. // Header
  123. include($__template_dir . 'header.html');
  124. // Panel
  125. top_panel(empty($_SESSION['look']) ? $_SESSION['user'] : $_SESSION['look'], $TAB);
  126. // Extarct global variables
  127. // I think those variables should be passed via arguments
  128. extract($GLOBALS, EXTR_SKIP);
  129. // Body
  130. if (($_SESSION['user'] !== 'admin') && (@include($__template_dir . "user/$page.html"))) {
  131. // User page loaded
  132. } else {
  133. // Not admin or user page doesn't exist
  134. // Load admin page
  135. @include($__template_dir . "admin/$page.html");
  136. }
  137. // Including common js files
  138. @include_once(dirname(__DIR__) . '/templates/scripts.html');
  139. // Including page specific js file
  140. if(file_exists($__pages_js_dir.$page.'.js'))
  141. echo '<script type="text/javascript" src="/js/pages/'.$page.'.js?'.JS_LATEST_UPDATE.'"></script>';
  142. // Footer
  143. include($__template_dir . 'footer.html');
  144. }
  145. function top_panel($user, $TAB) {
  146. global $panel;
  147. $command = HESTIA_CMD."v-list-user ".escapeshellarg($user)." 'json'";
  148. exec ($command, $output, $return_var);
  149. if ( $return_var > 0 ) {
  150. header("Location: /error/");
  151. exit;
  152. }
  153. $panel = json_decode(implode('', $output), true);
  154. unset($output);
  155. if ( $user == 'admin' ) {
  156. include(dirname(__FILE__).'/../templates/admin/panel.html');
  157. } else {
  158. include(dirname(__FILE__).'/../templates/user/panel.html');
  159. }
  160. }
  161. function translate_date($date){
  162. $date = strtotime($date);
  163. return strftime("%d &nbsp;", $date).__(strftime("%b", $date)).strftime(" &nbsp;%Y", $date);
  164. }
  165. function humanize_time($usage) {
  166. if ( $usage > 60 ) {
  167. $usage = $usage / 60;
  168. if ( $usage > 24 ) {
  169. $usage = $usage / 24;
  170. $usage = number_format($usage);
  171. if ( $usage == 1 ) {
  172. $usage = $usage." ".__('day');
  173. } else {
  174. $usage = $usage." ".__('days');
  175. }
  176. } else {
  177. $usage = number_format($usage);
  178. if ( $usage == 1 ) {
  179. $usage = $usage." ".__('hour');
  180. } else {
  181. $usage = $usage." ".__('hours');
  182. }
  183. }
  184. } else {
  185. if ( $usage == 1 ) {
  186. $usage = $usage." ".__('minute');
  187. } else {
  188. $usage = $usage." ".__('minutes');
  189. }
  190. }
  191. return $usage;
  192. }
  193. function humanize_usage_size($usage) {
  194. if ( $usage > 1024 ) {
  195. $usage = $usage / 1024;
  196. if ( $usage > 1024 ) {
  197. $usage = $usage / 1024 ;
  198. if ( $usage > 1024 ) {
  199. $usage = $usage / 1024 ;
  200. $usage = number_format($usage, 2);
  201. } else {
  202. $usage = number_format($usage, 2);
  203. }
  204. } else {
  205. $usage = number_format($usage, 2);
  206. }
  207. }
  208. return $usage;
  209. }
  210. function humanize_usage_measure($usage) {
  211. $measure = 'kb';
  212. if ( $usage > 1024 ) {
  213. $usage = $usage / 1024;
  214. if ( $usage > 1024 ) {
  215. $usage = $usage / 1024 ;
  216. if ( $usage > 1024 ) {
  217. $measure = 'pb';
  218. } else {
  219. $measure = 'tb';
  220. }
  221. } else {
  222. $measure = 'gb';
  223. }
  224. } else {
  225. $measure = 'mb';
  226. }
  227. return __($measure);
  228. }
  229. function get_percentage($used,$total) {
  230. if (!isset($total)) $total = 0;
  231. if (!isset($used)) $used = 0;
  232. if ( $total == 0 ) {
  233. $percent = 0;
  234. } else {
  235. $percent = $used / $total;
  236. $percent = $percent * 100;
  237. $percent = number_format($percent, 0, '', '');
  238. if ( $percent > 100 ) {
  239. $percent = 100;
  240. }
  241. if ( $percent < 0 ) {
  242. $percent = 0;
  243. }
  244. }
  245. return $percent;
  246. }
  247. function send_email($to,$subject,$mailtext,$from) {
  248. $charset = "utf-8";
  249. $to = '<'.$to.'>';
  250. $boundary = '--' . md5( uniqid("myboundary") );
  251. $priorities = array( '1 (Highest)', '2 (High)', '3 (Normal)', '4 (Low)', '5 (Lowest)' );
  252. $priority = $priorities[2];
  253. $ctencoding = "8bit";
  254. $sep = chr(13) . chr(10);
  255. $disposition = "inline";
  256. $subject = "=?$charset?B?".base64_encode($subject)."?=";
  257. $header = "From: $from \nX-Priority: $priority\nCC:\n";
  258. $header .= "Mime-Version: 1.0\nContent-Type: text/plain; charset=$charset \n";
  259. $header .= "Content-Transfer-Encoding: $ctencoding\nX-Mailer: Php/libMailv1.3\n";
  260. $message = $mailtext;
  261. mail($to, $subject, $message, $header);
  262. }
  263. function list_timezones() {
  264. $tz = new DateTimeZone('AKST');
  265. $timezone_offsets['AKST'] = $tz->getOffset(new DateTime);
  266. $tz = new DateTimeZone('AKDT');
  267. $timezone_offsets['AKDT'] = $tz->getOffset(new DateTime);
  268. $tz = new DateTimeZone('PST');
  269. $timezone_offsets['PST'] = $tz->getOffset(new DateTime);
  270. $tz = new DateTimeZone('PDT');
  271. $timezone_offsets['PDT'] = $tz->getOffset(new DateTime);
  272. $tz = new DateTimeZone('MST');
  273. $timezone_offsets['MST'] = $tz->getOffset(new DateTime);
  274. $tz = new DateTimeZone('MDT');
  275. $timezone_offsets['MDT'] = $tz->getOffset(new DateTime);
  276. $tz = new DateTimeZone('CST');
  277. $timezone_offsets['CST'] = $tz->getOffset(new DateTime);
  278. $tz = new DateTimeZone('CDT');
  279. $timezone_offsets['CDT'] = $tz->getOffset(new DateTime);
  280. $tz = new DateTimeZone('EST');
  281. $timezone_offsets['EST'] = $tz->getOffset(new DateTime);
  282. $tz = new DateTimeZone('EDT');
  283. $timezone_offsets['EDT'] = $tz->getOffset(new DateTime);
  284. $tz = new DateTimeZone('AST');
  285. $timezone_offsets['AST'] = $tz->getOffset(new DateTime);
  286. $tz = new DateTimeZone('ADT');
  287. $timezone_offsets['ADT'] = $tz->getOffset(new DateTime);
  288. foreach(DateTimeZone::listIdentifiers() as $timezone){
  289. $tz = new DateTimeZone($timezone);
  290. $timezone_offsets[$timezone] = $tz->getOffset(new DateTime);
  291. }
  292. foreach($timezone_offsets as $timezone => $offset){
  293. $offset_prefix = $offset < 0 ? '-' : '+';
  294. $offset_formatted = gmdate( 'H:i', abs($offset) );
  295. $pretty_offset = "UTC${offset_prefix}${offset_formatted}";
  296. $t = new DateTimeZone($timezone);
  297. $c = new DateTime(null, $t);
  298. $current_time = $c->format('H:i:s');
  299. $timezone_list[$timezone] = "$timezone [ $current_time ] ${pretty_offset}";
  300. }
  301. return $timezone_list;
  302. }
  303. /**
  304. * A function that tells is it MySQL installed on the system, or it is MariaDB.
  305. *
  306. * Explaination:
  307. * $_SESSION['DB_SYSTEM'] has 'mysql' value even if MariaDB is installed, so you can't figure out is it really MySQL or it's MariaDB.
  308. * So, this function will make it clear.
  309. *
  310. * If MySQL is installed, function will return 'mysql' as a string.
  311. * If MariaDB is installed, function will return 'mariadb' as a string.
  312. *
  313. * Hint: if you want to check if PostgreSQL is installed - check value of $_SESSION['DB_SYSTEM']
  314. *
  315. * @return string
  316. */
  317. function is_it_mysql_or_mariadb() {
  318. exec (HESTIA_CMD."v-list-sys-services json", $output, $return_var);
  319. $data = json_decode(implode('', $output), true);
  320. unset($output);
  321. $mysqltype='mysql';
  322. if (isset($data['mariadb'])) $mysqltype='mariadb';
  323. return $mysqltype;
  324. }
  325. function load_hestia_config() {
  326. // Check system configuration
  327. exec (HESTIA_CMD . "v-list-sys-config json", $output, $return_var);
  328. $data = json_decode(implode('', $output), true);
  329. $sys_arr = $data['config'];
  330. foreach ($sys_arr as $key => $value) {
  331. $_SESSION[$key] = $value;
  332. }
  333. }
  334. /**
  335. * Returns the list of all web domains from all users grouped by Backend Template used and owner
  336. *
  337. * @return array
  338. */
  339. function backendtpl_with_webdomains() {
  340. exec (HESTIA_CMD . "v-list-users json", $output, $return_var);
  341. $users = json_decode(implode('', $output), true);
  342. unset($output);
  343. $backend_list=[];
  344. foreach ($users as $user => $user_details) {
  345. exec (HESTIA_CMD . "v-list-web-domains ". escapeshellarg($user) . " json", $output, $return_var);
  346. $domains = json_decode(implode('', $output), true);
  347. unset($output);
  348. foreach ($domains as $domain => $domain_details) {
  349. if (!empty($domain_details['BACKEND'])) {
  350. $backend = $domain_details['BACKEND'];
  351. $backend_list[$backend][$user][] = $domain;
  352. }
  353. }
  354. }
  355. return $backend_list;
  356. }