index.php 45 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036
  1. <?php
  2. ob_start();
  3. unset($_SESSION['error_msg']);
  4. $TAB = 'WEB';
  5. // Main include
  6. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  7. // Check domain argument
  8. if (empty($_GET['domain'])) {
  9. header("Location: /list/web/");
  10. exit;
  11. }
  12. // Edit as someone else?
  13. if (($_SESSION['userContext'] === 'admin') && (!empty($_GET['user']))) {
  14. $user=escapeshellarg($_GET['user']);
  15. }
  16. // Get all user domains
  17. exec(HESTIA_CMD."v-list-web-domains ".escapeshellarg($user)." json", $output, $return_var);
  18. $user_domains = json_decode(implode('', $output), true);
  19. $user_domains = array_keys($user_domains);
  20. unset($output);
  21. // List domain
  22. $v_domain = $_GET['domain'];
  23. if ($_SESSION['userContext'] !== 'admin') {
  24. if (!in_array($v_domain, $user_domains)) {
  25. header("Location: /list/mail/");
  26. exit;
  27. }
  28. }
  29. exec(HESTIA_CMD."v-list-web-domain ".$user." ".escapeshellarg($v_domain)." json", $output, $return_var);
  30. $data = json_decode(implode('', $output), true);
  31. unset($output);
  32. // Parse domain
  33. $v_username = $user;
  34. $v_ip = $data[$v_domain]['IP'];
  35. $v_template = $data[$v_domain]['TPL'];
  36. $v_aliases = str_replace(',', "\n", $data[$v_domain]['ALIAS']);
  37. $valiases = explode(",", $data[$v_domain]['ALIAS']);
  38. $v_tpl = $data[$v_domain]['IP'];
  39. $v_cgi = $data[$v_domain]['CGI'];
  40. $v_elog = $data[$v_domain]['ELOG'];
  41. $v_ssl = $data[$v_domain]['SSL'];
  42. if (!empty($v_ssl)) {
  43. exec(HESTIA_CMD."v-list-web-domain-ssl ".$user." ".escapeshellarg($v_domain)." json", $output, $return_var);
  44. $ssl_str = json_decode(implode('', $output), true);
  45. unset($output);
  46. $v_ssl_crt = $ssl_str[$v_domain]['CRT'];
  47. $v_ssl_key = $ssl_str[$v_domain]['KEY'];
  48. $v_ssl_ca = $ssl_str[$v_domain]['CA'];
  49. $v_ssl_subject = $ssl_str[$v_domain]['SUBJECT'];
  50. $v_ssl_aliases = $ssl_str[$v_domain]['ALIASES'];
  51. $v_ssl_not_before = $ssl_str[$v_domain]['NOT_BEFORE'];
  52. $v_ssl_not_after = $ssl_str[$v_domain]['NOT_AFTER'];
  53. $v_ssl_signature = $ssl_str[$v_domain]['SIGNATURE'];
  54. $v_ssl_pub_key = $ssl_str[$v_domain]['PUB_KEY'];
  55. $v_ssl_issuer = $ssl_str[$v_domain]['ISSUER'];
  56. $v_ssl_forcessl = $data[$v_domain]['SSL_FORCE'];
  57. $v_ssl_hsts = $data[$v_domain]['SSL_HSTS'];
  58. }
  59. $v_letsencrypt = $data[$v_domain]['LETSENCRYPT'];
  60. if (empty($v_letsencrypt)) {
  61. $v_letsencrypt = 'no';
  62. }
  63. $v_ssl_home = $data[$v_domain]['SSL_HOME'];
  64. $v_backend_template = $data[$v_domain]['BACKEND'];
  65. $v_nginx_cache = $data[$v_domain]['FASTCGI_CACHE'];
  66. $v_nginx_cache_duration = $data[$v_domain]['FASTCGI_DURATION'];
  67. $v_nginx_cache_check = '';
  68. if (empty($v_nginx_cache_duration)) {
  69. $v_nginx_cache_duration = '2m';
  70. $v_nginx_cache_check = '';
  71. } else {
  72. $v_nginx_cache_check = 'on';
  73. }
  74. $v_proxy = $data[$v_domain]['PROXY'];
  75. $v_proxy_template = $data[$v_domain]['PROXY'];
  76. $v_proxy_ext = str_replace(',', ', ', $data[$v_domain]['PROXY_EXT']);
  77. $v_stats = $data[$v_domain]['STATS'];
  78. $v_stats_user = $data[$v_domain]['STATS_USER'];
  79. if (!empty($v_stats_user)) {
  80. $v_stats_password = "";
  81. }
  82. $v_custom_doc_root_prepath = '/home/'.$v_username.'/web/';
  83. if (!empty($data[$v_domain]['CUSTOM_DOCROOT'])) {
  84. $v_custom_doc_root = realpath($data[$v_domain]['CUSTOM_DOCROOT']) . DIRECTORY_SEPARATOR;
  85. }
  86. if (!empty($v_custom_doc_root) &&
  87. false !== preg_match('/\/home\/'.$v_username.'\/web\/([[:alnum:]].*?)\/public_html\/([[:alnum:]].*)?/', $v_custom_doc_root, $matches)) {
  88. // Regex for extracting target web domain and custom document root. Regex test: https://regex101.com/r/2CLvIF/1
  89. if (!empty($matches[1])) {
  90. $v_custom_doc_domain = $matches[1];
  91. }
  92. if (!empty($matches[2])) {
  93. $v_custom_doc_folder = rtrim($matches[2], '/');
  94. }
  95. if ($v_custom_doc_domain && !in_array($v_custom_doc_domain, $user_domains)) {
  96. $v_custom_doc_domain = '';
  97. $v_custom_doc_folder = '';
  98. }
  99. }
  100. $redirect_code_options = array(301,302);
  101. $v_redirect = $data[$v_domain]['REDIRECT'];
  102. $v_redirect_code = $data[$v_domain]['REDIRECT_CODE'];
  103. if (!in_array($v_redirect, array('www.'.$v_domain, $v_domain))) {
  104. $v_redirect_custom = $v_redirect;
  105. }
  106. $v_ftp_user = $data[$v_domain]['FTP_USER'];
  107. $v_ftp_path = $data[$v_domain]['FTP_PATH'];
  108. if (!empty($v_ftp_user)) {
  109. $v_ftp_password = "";
  110. }
  111. if ($v_custom_doc_domain != '') {
  112. $v_ftp_user_prepath = '/home/'.$v_username.'/web/'.$v_custom_doc_domain;
  113. } else {
  114. $v_ftp_user_prepath = '/home/'.$v_username.'/web/'.$v_domain;
  115. }
  116. $v_ftp_email = $panel[$user]['CONTACT'];
  117. $v_suspended = $data[$v_domain]['SUSPENDED'];
  118. if ($v_suspended == 'yes') {
  119. $v_status = 'suspended';
  120. } else {
  121. $v_status = 'active';
  122. }
  123. $v_time = $data[$v_domain]['TIME'];
  124. $v_date = $data[$v_domain]['DATE'];
  125. // List ip addresses
  126. exec(HESTIA_CMD."v-list-user-ips ".$user." json", $output, $return_var);
  127. $ips = json_decode(implode('', $output), true);
  128. unset($output);
  129. $v_ip_public = empty($ips[$v_ip]['NAT']) ? $v_ip : $ips[$v_ip]['NAT'];
  130. // List web templates
  131. exec(HESTIA_CMD."v-list-web-templates json", $output, $return_var);
  132. $templates = json_decode(implode('', $output), true);
  133. unset($output);
  134. // List backend templates
  135. if (!empty($_SESSION['WEB_BACKEND'])) {
  136. exec(HESTIA_CMD."v-list-web-templates-backend json", $output, $return_var);
  137. $backend_templates = json_decode(implode('', $output), true);
  138. unset($output);
  139. }
  140. // List proxy templates
  141. if (!empty($_SESSION['PROXY_SYSTEM'])) {
  142. exec(HESTIA_CMD."v-list-web-templates-proxy json", $output, $return_var);
  143. $proxy_templates = json_decode(implode('', $output), true);
  144. unset($output);
  145. }
  146. // List web stat engines
  147. exec(HESTIA_CMD."v-list-web-stats json", $output, $return_var);
  148. $stats = json_decode(implode('', $output), true);
  149. unset($output);
  150. // Check POST request
  151. if (!empty($_POST['save'])) {
  152. $v_domain = $_POST['v_domain'];
  153. if (!in_array($v_domain, $user_domains)) {
  154. check_return_code(3, ["Unknown domain"]);
  155. }
  156. // Check token
  157. verify_csrf($_POST);
  158. // Change web domain IP
  159. $v_newip='';
  160. $v_newip_public='';
  161. if (!empty($_POST['v_ip'])) {
  162. $v_newip = $_POST['v_ip'];
  163. $v_newip_public = empty($ips[$v_newip]['NAT']) ? $v_newip : $ips[$v_newip]['NAT'];
  164. }
  165. if (($v_ip != $_POST['v_ip']) && (empty($_SESSION['error_msg']))) {
  166. exec(HESTIA_CMD."v-change-web-domain-ip ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($_POST['v_ip'])." 'no'", $output, $return_var);
  167. check_return_code($return_var, $output);
  168. $restart_web = 'yes';
  169. $restart_proxy = 'yes';
  170. unset($output);
  171. }
  172. // Change dns domain IP
  173. if (($v_ip != $_POST['v_ip']) && (empty($_SESSION['error_msg']))) {
  174. exec(HESTIA_CMD."v-list-dns-domain ".$v_username." ".escapeshellarg($v_domain)." json", $output, $return_var);
  175. unset($output);
  176. if ($return_var == 0) {
  177. exec(HESTIA_CMD."v-change-dns-domain-ip ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($v_newip_public)." 'no'", $output, $return_var);
  178. check_return_code($return_var, $output);
  179. unset($output);
  180. $restart_dns = 'yes';
  181. }
  182. }
  183. // Change dns ip for each alias
  184. if (($v_ip != $_POST['v_ip']) && (empty($_SESSION['error_msg']))) {
  185. foreach ($valiases as $v_alias) {
  186. exec(HESTIA_CMD."v-list-dns-domain ".$v_username." ".escapeshellarg($v_alias)." json", $output, $return_var);
  187. unset($output);
  188. if ($return_var == 0) {
  189. exec(HESTIA_CMD."v-change-dns-domain-ip ".$v_username." ".escapeshellarg($v_alias)." ".escapeshellarg($v_newip_public), $output, $return_var);
  190. check_return_code($return_var, $output);
  191. unset($output);
  192. $restart_dns = 'yes';
  193. }
  194. }
  195. }
  196. // Change mail domain IP
  197. if (($v_ip != $_POST['v_ip']) && (empty($_SESSION['error_msg']))) {
  198. exec(HESTIA_CMD."v-list-mail-domain ".$v_username." ".escapeshellarg($v_domain)." json", $output, $return_var);
  199. unset($output);
  200. if ($return_var == 0) {
  201. exec(HESTIA_CMD."v-rebuild-mail-domain ".$v_username." ".escapeshellarg($v_domain), $output, $return_var);
  202. check_return_code($return_var, $output);
  203. unset($output);
  204. $restart_email = 'yes';
  205. }
  206. }
  207. if (($_SESSION['POLICY_USER_EDIT_WEB_TEMPLATES'] == 'yes') || ($_SESSION['userContext'] === "admin")) {
  208. // Change template
  209. if (($v_template != $_POST['v_template']) && (empty($_SESSION['error_msg']))) {
  210. exec(HESTIA_CMD."v-change-web-domain-tpl ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($_POST['v_template'])." 'no'", $output, $return_var);
  211. check_return_code($return_var, $output);
  212. unset($output);
  213. $restart_web = 'yes';
  214. }
  215. // Change backend template
  216. if ((!empty($_SESSION['WEB_BACKEND'])) && ($v_backend_template != $_POST['v_backend_template']) && (empty($_SESSION['error_msg']))) {
  217. $v_backend_template = $_POST['v_backend_template'];
  218. exec(HESTIA_CMD."v-change-web-domain-backend-tpl ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($v_backend_template), $output, $return_var);
  219. check_return_code($return_var, $output);
  220. unset($output);
  221. }
  222. // Enable/Disable nginx cache
  223. if (($_SESSION['WEB_SYSTEM'] == 'nginx') && ($v_nginx_cache_check != $_POST['v_nginx_cache_check']) || ($v_nginx_cache_duration != $_POST['v_nginx_cache_duration'] && $_POST['v_nginx_cache'] = "yes") && (empty($_SESSION['error_msg']))) {
  224. if ($_POST['v_nginx_cache_check'] == 'on') {
  225. if (empty($_POST['v_nginx_cache_duration'])) {
  226. $_POST['v_nginx_cache_duration'] = "2m";
  227. }
  228. exec(HESTIA_CMD."v-add-fastcgi-cache ".$v_username." ".escapeshellarg($v_domain).' '. escapeshellarg($_POST['v_nginx_cache_duration']), $output, $return_var);
  229. check_return_code($return_var, $output);
  230. unset($output);
  231. } else {
  232. exec(HESTIA_CMD."v-delete-fastcgi-cache ".$v_username." ".escapeshellarg($v_domain), $output, $return_var);
  233. check_return_code($return_var, $output);
  234. unset($output);
  235. }
  236. $restart_web = 'yes';
  237. }
  238. // Delete proxy support
  239. if ((!empty($_SESSION['PROXY_SYSTEM'])) && (!empty($v_proxy)) && (empty($_POST['v_proxy'])) && (empty($_SESSION['error_msg']))) {
  240. exec(HESTIA_CMD."v-delete-web-domain-proxy ".$v_username." ".escapeshellarg($v_domain)." 'no'", $output, $return_var);
  241. check_return_code($return_var, $output);
  242. unset($output);
  243. unset($v_proxy);
  244. $restart_web = 'yes';
  245. }
  246. // Change proxy template / Update extension list
  247. if ((!empty($_SESSION['PROXY_SYSTEM'])) && (!empty($v_proxy)) && (!empty($_POST['v_proxy'])) && (empty($_SESSION['error_msg']))) {
  248. $ext = preg_replace("/\n/", " ", $_POST['v_proxy_ext']);
  249. $ext = preg_replace("/,/", " ", $ext);
  250. $ext = preg_replace('/\s+/', ' ', $ext);
  251. $ext = trim($ext);
  252. $ext = str_replace(' ', ", ", $ext);
  253. if (($v_proxy_template != $_POST['v_proxy_template']) || ($v_proxy_ext != $ext)) {
  254. $ext = str_replace(', ', ",", $ext);
  255. if (!empty($_POST['v_proxy_template'])) {
  256. $v_proxy_template = $_POST['v_proxy_template'];
  257. }
  258. exec(HESTIA_CMD."v-change-web-domain-proxy-tpl ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($v_proxy_template)." ".escapeshellarg($ext)." 'no'", $output, $return_var);
  259. check_return_code($return_var, $output);
  260. $v_proxy_ext = str_replace(',', ', ', $ext);
  261. unset($output);
  262. $restart_proxy = 'yes';
  263. }
  264. }
  265. // Add proxy support
  266. if ((!empty($_SESSION['PROXY_SYSTEM'])) && (empty($v_proxy)) && (!empty($_POST['v_proxy'])) && (empty($_SESSION['error_msg']))) {
  267. $v_proxy_template = $_POST['v_proxy_template'];
  268. if (!empty($_POST['v_proxy_ext'])) {
  269. $ext = preg_replace("/\n/", " ", $_POST['v_proxy_ext']);
  270. $ext = preg_replace("/,/", " ", $ext);
  271. $ext = preg_replace('/\s+/', ' ', $ext);
  272. $ext = trim($ext);
  273. $ext = str_replace(' ', ",", $ext);
  274. $v_proxy_ext = str_replace(',', ', ', $ext);
  275. }
  276. exec(HESTIA_CMD."v-add-web-domain-proxy ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($v_proxy_template)." ".escapeshellarg($ext)." 'no'", $output, $return_var);
  277. check_return_code($return_var, $output);
  278. unset($output);
  279. $restart_proxy = 'yes';
  280. }
  281. }
  282. // Change aliases
  283. if (empty($_SESSION['error_msg'])) {
  284. $waliases = preg_replace("/\n/", " ", $_POST['v_aliases']);
  285. $waliases = preg_replace("/,/", " ", $waliases);
  286. $waliases = preg_replace('/\s+/', ' ', $waliases);
  287. $waliases = trim($waliases);
  288. $aliases = explode(" ", $waliases);
  289. $v_aliases = str_replace(' ', "\n", $waliases);
  290. $result = array_diff($valiases, $aliases);
  291. foreach ($result as $alias) {
  292. if ((empty($_SESSION['error_msg'])) && (!empty($alias))) {
  293. $restart_web = 'yes';
  294. $restart_proxy = 'yes';
  295. exec(HESTIA_CMD."v-delete-web-domain-alias ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($alias)." 'no'", $output, $return_var);
  296. check_return_code($return_var, $output);
  297. unset($output);
  298. if (empty($_SESSION['error_msg'])) {
  299. exec(HESTIA_CMD."v-list-dns-domain ".$v_username." ".escapeshellarg($v_domain), $output, $return_var);
  300. unset($output);
  301. if ($return_var == 0) {
  302. exec(HESTIA_CMD."v-delete-dns-on-web-alias ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($alias)." 'no'", $output, $return_var);
  303. check_return_code($return_var, $output);
  304. unset($output);
  305. $restart_dns = 'yes';
  306. }
  307. }
  308. }
  309. }
  310. $result = array_diff($aliases, $valiases);
  311. foreach ($result as $alias) {
  312. if ((empty($_SESSION['error_msg'])) && (!empty($alias))) {
  313. $restart_web = 'yes';
  314. $restart_proxy = 'yes';
  315. exec(HESTIA_CMD."v-add-web-domain-alias ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($alias)." 'no'", $output, $return_var);
  316. check_return_code($return_var, $output);
  317. unset($output);
  318. if (empty($_SESSION['error_msg'])) {
  319. exec(HESTIA_CMD."v-list-dns-domain ".$v_username." ".escapeshellarg($v_domain), $output, $return_var);
  320. unset($output);
  321. if ($return_var == 0) {
  322. exec(HESTIA_CMD."v-add-dns-on-web-alias ".$v_username." ".escapeshellarg($alias)." ".escapeshellarg($v_newip_public ?: $v_ip_public)." no", $output, $return_var);
  323. check_return_code($return_var, $output);
  324. unset($output);
  325. $restart_dns = 'yes';
  326. }
  327. }
  328. }
  329. }
  330. // Regenerate LE if aliases are different
  331. if ((!empty($_POST['v_ssl'])) && ($v_letsencrypt == 'yes') && (!empty($_POST['v_letsencrypt'])) && empty($_SESSION['error_msg'])) {
  332. // If aliases are different from stored aliases
  333. if (array_diff($valiases, $aliases) || array_diff($aliases, $valiases)) {
  334. // Add certificate with new aliases
  335. $l_aliases = str_replace("\n", ',', $v_aliases);
  336. exec(HESTIA_CMD."v-add-letsencrypt-domain ".$user." ".escapeshellarg($v_domain)." ".escapeshellarg($l_aliases)." ''", $output, $return_var);
  337. check_return_code($return_var, $output);
  338. unset($output);
  339. $v_letsencrypt = 'yes';
  340. $v_ssl = 'yes';
  341. $restart_web = 'yes';
  342. $restart_proxy = 'yes';
  343. exec(HESTIA_CMD."v-list-web-domain-ssl ".$user." ".escapeshellarg($v_domain)." json", $output, $return_var);
  344. $ssl_str = json_decode(implode('', $output), true);
  345. unset($output);
  346. $v_ssl_crt = $ssl_str[$v_domain]['CRT'];
  347. $v_ssl_key = $ssl_str[$v_domain]['KEY'];
  348. $v_ssl_ca = $ssl_str[$v_domain]['CA'];
  349. $v_ssl_subject = $ssl_str[$v_domain]['SUBJECT'];
  350. $v_ssl_aliases = $ssl_str[$v_domain]['ALIASES'];
  351. $v_ssl_not_before = $ssl_str[$v_domain]['NOT_BEFORE'];
  352. $v_ssl_not_after = $ssl_str[$v_domain]['NOT_AFTER'];
  353. $v_ssl_signature = $ssl_str[$v_domain]['SIGNATURE'];
  354. $v_ssl_pub_key = $ssl_str[$v_domain]['PUB_KEY'];
  355. $v_ssl_issuer = $ssl_str[$v_domain]['ISSUER'];
  356. }
  357. }
  358. if ((!empty($v_stats)) && ($_POST['v_stats'] == $v_stats) && (empty($_SESSION['error_msg']))) {
  359. // Update statistics configuration when changing domain aliases
  360. $v_stats = escapeshellarg($_POST['v_stats']);
  361. exec(HESTIA_CMD."v-change-web-domain-stats ".$v_username." ".escapeshellarg($v_domain)." ".$v_stats, $output, $return_var);
  362. check_return_code($return_var, $output);
  363. unset($output);
  364. }
  365. }
  366. // Change document root for ssl domain
  367. if (($v_ssl == 'yes') && (!empty($_POST['v_ssl'])) && (empty($_SESSION['error_msg']))) {
  368. if ($v_ssl_home != $_POST['v_ssl_home']) {
  369. $v_ssl_home = escapeshellarg($_POST['v_ssl_home']);
  370. exec(HESTIA_CMD."v-change-web-domain-sslhome ".$user." ".escapeshellarg($v_domain)." ".$v_ssl_home." 'no'", $output, $return_var);
  371. check_return_code($return_var, $output);
  372. $v_ssl_home = $_POST['v_ssl_home'];
  373. $restart_web = 'yes';
  374. $restart_proxy = 'yes';
  375. unset($output);
  376. }
  377. }
  378. // Change SSL certificate
  379. if (($v_letsencrypt == 'no') && (empty($_POST['v_letsencrypt'])) && ($v_ssl == 'yes') && (!empty($_POST['v_ssl'])) && (empty($_SESSION['error_msg']))) {
  380. if (($v_ssl_crt != str_replace("\r\n", "\n", $_POST['v_ssl_crt'])) || ($v_ssl_key != str_replace("\r\n", "\n", $_POST['v_ssl_key'])) || ($v_ssl_ca != str_replace("\r\n", "\n", $_POST['v_ssl_ca']))) {
  381. exec('mktemp -d', $mktemp_output, $return_var);
  382. $tmpdir = $mktemp_output[0];
  383. // Certificate
  384. if (!empty($_POST['v_ssl_crt'])) {
  385. $fp = fopen($tmpdir."/".$v_domain.".crt", 'w');
  386. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_crt']));
  387. fwrite($fp, "\n");
  388. fclose($fp);
  389. }
  390. // Key
  391. if (!empty($_POST['v_ssl_key'])) {
  392. $fp = fopen($tmpdir."/".$v_domain.".key", 'w');
  393. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_key']));
  394. fwrite($fp, "\n");
  395. fclose($fp);
  396. }
  397. // CA
  398. if (!empty($_POST['v_ssl_ca'])) {
  399. $fp = fopen($tmpdir."/".$v_domain.".ca", 'w');
  400. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_ca']));
  401. fwrite($fp, "\n");
  402. fclose($fp);
  403. }
  404. exec(HESTIA_CMD."v-change-web-domain-sslcert ".$user." ".escapeshellarg($v_domain)." ".$tmpdir." 'no'", $output, $return_var);
  405. check_return_code($return_var, $output);
  406. unset($output);
  407. $restart_web = 'yes';
  408. $restart_proxy = 'yes';
  409. exec(HESTIA_CMD."v-list-web-domain-ssl ".$user." ".escapeshellarg($v_domain)." json", $output, $return_var);
  410. $ssl_str = json_decode(implode('', $output), true);
  411. unset($output);
  412. $v_ssl_crt = $ssl_str[$v_domain]['CRT'];
  413. $v_ssl_key = $ssl_str[$v_domain]['KEY'];
  414. $v_ssl_ca = $ssl_str[$v_domain]['CA'];
  415. $v_ssl_subject = $ssl_str[$v_domain]['SUBJECT'];
  416. $v_ssl_aliases = $ssl_str[$v_domain]['ALIASES'];
  417. $v_ssl_not_before = $ssl_str[$v_domain]['NOT_BEFORE'];
  418. $v_ssl_not_after = $ssl_str[$v_domain]['NOT_AFTER'];
  419. $v_ssl_signature = $ssl_str[$v_domain]['SIGNATURE'];
  420. $v_ssl_pub_key = $ssl_str[$v_domain]['PUB_KEY'];
  421. $v_ssl_issuer = $ssl_str[$v_domain]['ISSUER'];
  422. // Cleanup certificate tempfiles
  423. if (!empty($_POST['v_ssl_crt'])) {
  424. unlink($tmpdir."/".$v_domain.".crt");
  425. }
  426. if (!empty($_POST['v_ssl_key'])) {
  427. unlink($tmpdir."/".$v_domain.".key");
  428. }
  429. if (!empty($_POST['v_ssl_ca'])) {
  430. unlink($tmpdir."/".$v_domain.".ca");
  431. }
  432. rmdir($tmpdir);
  433. }
  434. }
  435. // Delete Lets Encrypt support
  436. if (($v_letsencrypt == 'yes') && (empty($_POST['v_letsencrypt']) || empty($_POST['v_ssl'])) && (empty($_SESSION['error_msg']))) {
  437. exec(HESTIA_CMD."v-delete-letsencrypt-domain ".$user." ".escapeshellarg($v_domain)." ''", $output, $return_var);
  438. check_return_code($return_var, $output);
  439. unset($output);
  440. $v_ssl_crt = '';
  441. $v_ssl_key = '';
  442. $v_ssl_ca = '';
  443. $v_letsencrypt = 'no';
  444. $v_letsencrypt_deleted = 'yes';
  445. $v_ssl = 'no';
  446. $restart_web = 'yes';
  447. $restart_proxy = 'yes';
  448. }
  449. // Delete SSL certificate
  450. if (($v_ssl == 'yes') && (empty($_POST['v_ssl'])) && (empty($_SESSION['error_msg']))) {
  451. exec(HESTIA_CMD."v-delete-web-domain-ssl ".$v_username." ".escapeshellarg($v_domain)." 'no'", $output, $return_var);
  452. check_return_code($return_var, $output);
  453. unset($output);
  454. $v_ssl_crt = '';
  455. $v_ssl_key = '';
  456. $v_ssl_ca = '';
  457. $v_ssl = 'no';
  458. $v_ssl_forcessl = 'no';
  459. $v_ssl_hsts = 'no';
  460. $restart_web = 'yes';
  461. $restart_proxy = 'yes';
  462. }
  463. // Add Lets Encrypt support
  464. if ((!empty($_POST['v_ssl'])) && ($v_letsencrypt == 'no') && (!empty($_POST['v_letsencrypt'])) && empty($_SESSION['error_msg'])) {
  465. $l_aliases = str_replace("\n", ',', $v_aliases);
  466. exec(HESTIA_CMD."v-add-letsencrypt-domain ".$user." ".escapeshellarg($v_domain)." ".escapeshellarg($l_aliases)." ''", $output, $return_var);
  467. check_return_code($return_var, $output);
  468. unset($output);
  469. if ($return_var != 0) {
  470. $v_letsencrypt = 'no';
  471. } else {
  472. $v_letsencrypt = 'yes';
  473. }
  474. $v_ssl = 'yes';
  475. if ($_POST['v_ssl_forcessl'] == 'on') {
  476. $v_ssl_forcessl = 'yes';
  477. } else {
  478. $v_ssl_forcessl = 'no';
  479. }
  480. $restart_web = 'yes';
  481. $restart_proxy = 'yes';
  482. }
  483. // Add SSL certificate
  484. if (($v_ssl == 'no') && (!empty($_POST['v_ssl'])) && (empty($v_letsencrypt_deleted)) && (empty($_SESSION['error_msg']))) {
  485. if (empty($_POST['v_ssl_crt'])) {
  486. $errors[] = 'ssl certificate';
  487. }
  488. if (empty($_POST['v_ssl_key'])) {
  489. $errors[] = 'ssl key';
  490. }
  491. if (empty($_POST['v_ssl_home'])) {
  492. $errors[] = 'ssl home';
  493. }
  494. $v_ssl_home = escapeshellarg($_POST['v_ssl_home']);
  495. if (!empty($errors[0])) {
  496. foreach ($errors as $i => $error) {
  497. if ($i == 0) {
  498. $error_msg = $error;
  499. } else {
  500. $error_msg = $error_msg.", ".$error;
  501. }
  502. }
  503. $_SESSION['error_msg'] = _('Field "%s" can not be blank.', $error_msg);
  504. } else {
  505. exec('mktemp -d', $mktemp_output, $return_var);
  506. $tmpdir = $mktemp_output[0];
  507. // Certificate
  508. if (!empty($_POST['v_ssl_crt'])) {
  509. $fp = fopen($tmpdir."/".$v_domain.".crt", 'w');
  510. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_crt']));
  511. fclose($fp);
  512. }
  513. // Key
  514. if (!empty($_POST['v_ssl_key'])) {
  515. $fp = fopen($tmpdir."/".$v_domain.".key", 'w');
  516. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_key']));
  517. fclose($fp);
  518. }
  519. // CA
  520. if (!empty($_POST['v_ssl_ca'])) {
  521. $fp = fopen($tmpdir."/".$v_domain.".ca", 'w');
  522. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_ca']));
  523. fclose($fp);
  524. }
  525. exec(HESTIA_CMD."v-add-web-domain-ssl ".$user." ".escapeshellarg($v_domain)." ".$tmpdir." ".$v_ssl_home." 'no'", $output, $return_var);
  526. check_return_code($return_var, $output);
  527. unset($output);
  528. $v_ssl = 'yes';
  529. $restart_web = 'yes';
  530. $restart_proxy = 'yes';
  531. exec(HESTIA_CMD."v-list-web-domain-ssl ".$user." ".escapeshellarg($v_domain)." json", $output, $return_var);
  532. $ssl_str = json_decode(implode('', $output), true);
  533. unset($output);
  534. $v_ssl_crt = $ssl_str[$v_domain]['CRT'];
  535. $v_ssl_key = $ssl_str[$v_domain]['KEY'];
  536. $v_ssl_ca = $ssl_str[$v_domain]['CA'];
  537. $v_ssl_subject = $ssl_str[$v_domain]['SUBJECT'];
  538. $v_ssl_aliases = $ssl_str[$v_domain]['ALIASES'];
  539. $v_ssl_not_before = $ssl_str[$v_domain]['NOT_BEFORE'];
  540. $v_ssl_not_after = $ssl_str[$v_domain]['NOT_AFTER'];
  541. $v_ssl_signature = $ssl_str[$v_domain]['SIGNATURE'];
  542. $v_ssl_pub_key = $ssl_str[$v_domain]['PUB_KEY'];
  543. $v_ssl_issuer = $ssl_str[$v_domain]['ISSUER'];
  544. // Cleanup certificate tempfiles
  545. if (!empty($_POST['v_ssl_crt'])) {
  546. unlink($tmpdir."/".$v_domain.".crt");
  547. }
  548. if (!empty($_POST['v_ssl_key'])) {
  549. unlink($tmpdir."/".$v_domain.".key");
  550. }
  551. if (!empty($_POST['v_ssl_ca'])) {
  552. unlink($tmpdir."/".$v_domain.".ca");
  553. }
  554. rmdir($tmpdir);
  555. }
  556. }
  557. // Add Force SSL
  558. if ((!empty($_POST['v_ssl_forcessl'])) && (!empty($_POST['v_ssl'])) && (empty($_SESSION['error_msg']))) {
  559. exec(HESTIA_CMD."v-add-web-domain-ssl-force ".$user." ".escapeshellarg($v_domain), $output, $return_var);
  560. check_return_code($return_var, $output);
  561. unset($output);
  562. $v_ssl_forcessl = 'yes';
  563. $restart_web = 'yes';
  564. $restart_proxy = 'yes';
  565. }
  566. // Add SSL HSTS
  567. if ((!empty($_POST['v_ssl_hsts'])) && (!empty($_POST['v_ssl'])) && (empty($_SESSION['error_msg']))) {
  568. exec(HESTIA_CMD."v-add-web-domain-ssl-hsts ".$user." ".escapeshellarg($v_domain), $output, $return_var);
  569. check_return_code($return_var, $output);
  570. unset($output);
  571. $v_ssl_hsts = 'yes';
  572. $restart_web = 'yes';
  573. $restart_proxy = 'yes';
  574. }
  575. // Delete Force SSL
  576. if (($v_ssl_forcessl == 'yes') && (empty($_POST['v_ssl_forcessl'])) && (empty($_SESSION['error_msg']))) {
  577. exec(HESTIA_CMD."v-delete-web-domain-ssl-force ".$user." ".escapeshellarg($v_domain), $output, $return_var);
  578. check_return_code($return_var, $output);
  579. unset($output);
  580. $v_ssl_forcessl = 'no';
  581. $restart_web = 'yes';
  582. $restart_proxy = 'yes';
  583. }
  584. // Delete SSL HSTS
  585. if (($v_ssl_hsts == 'yes') && (empty($_POST['v_ssl_hsts'])) && (empty($_SESSION['error_msg']))) {
  586. exec(HESTIA_CMD."v-delete-web-domain-ssl-hsts ".$user." ".escapeshellarg($v_domain), $output, $return_var);
  587. check_return_code($return_var, $output);
  588. unset($output);
  589. $v_ssl_hsts = 'no';
  590. $restart_web = 'yes';
  591. $restart_proxy = 'yes';
  592. }
  593. // Delete web stats
  594. if ((!empty($v_stats)) && ($_POST['v_stats'] == 'none') && (empty($_SESSION['error_msg']))) {
  595. exec(HESTIA_CMD."v-delete-web-domain-stats ".$v_username." ".escapeshellarg($v_domain), $output, $return_var);
  596. check_return_code($return_var, $output);
  597. unset($output);
  598. $v_stats = '';
  599. }
  600. // Change web stats engine
  601. if ((!empty($v_stats)) && ($_POST['v_stats'] != $v_stats) && (empty($_SESSION['error_msg']))) {
  602. $v_stats = escapeshellarg($_POST['v_stats']);
  603. exec(HESTIA_CMD."v-change-web-domain-stats ".$v_username." ".escapeshellarg($v_domain)." ".$v_stats, $output, $return_var);
  604. check_return_code($return_var, $output);
  605. unset($output);
  606. }
  607. // Add web stats
  608. if ((empty($v_stats)) && ($_POST['v_stats'] != 'none') && (empty($_SESSION['error_msg']))) {
  609. $v_stats = escapeshellarg($_POST['v_stats']);
  610. exec(HESTIA_CMD."v-add-web-domain-stats ".$v_username." ".escapeshellarg($v_domain)." ".$v_stats, $output, $return_var);
  611. check_return_code($return_var, $output);
  612. unset($output);
  613. }
  614. // Delete web stats authorization
  615. if ((!empty($v_stats_user)) && (empty($_POST['v_stats_auth'])) && (empty($_SESSION['error_msg']))) {
  616. exec(HESTIA_CMD."v-delete-web-domain-stats-user ".$v_username." ".escapeshellarg($v_domain), $output, $return_var);
  617. check_return_code($return_var, $output);
  618. unset($output);
  619. $v_stats_user = '';
  620. $v_stats_password = '';
  621. }
  622. // Change web stats user or password
  623. if ((empty($v_stats_user)) && (!empty($_POST['v_stats_auth'])) && (empty($_SESSION['error_msg']))) {
  624. if (empty($_POST['v_stats_user'])) {
  625. $errors[] = _('stats username');
  626. }
  627. if (!empty($errors[0])) {
  628. foreach ($errors as $i => $error) {
  629. if ($i == 0) {
  630. $error_msg = $error;
  631. } else {
  632. $error_msg = $error_msg.", ".$error;
  633. }
  634. }
  635. $_SESSION['error_msg'] = _('Field "%s" can not be blank.', $error_msg);
  636. } else {
  637. $v_stats_user = escapeshellarg($_POST['v_stats_user']);
  638. $v_stats_password = tempnam("/tmp", "vst");
  639. $fp = fopen($v_stats_password, "w");
  640. fwrite($fp, $_POST['v_stats_password']."\n");
  641. fclose($fp);
  642. exec(HESTIA_CMD."v-add-web-domain-stats-user ".$v_username." ".escapeshellarg($v_domain)." ".$v_stats_user." ".$v_stats_password, $output, $return_var);
  643. check_return_code($return_var, $output);
  644. unset($output);
  645. unlink($v_stats_password);
  646. $v_stats_password = escapeshellarg($_POST['v_stats_password']);
  647. }
  648. }
  649. // Add web stats authorization
  650. if ((!empty($v_stats_user)) && (!empty($_POST['v_stats_auth'])) && (empty($_SESSION['error_msg']))) {
  651. if (empty($_POST['v_stats_user'])) {
  652. $errors[] = _('stats user');
  653. }
  654. if (!empty($errors[0])) {
  655. foreach ($errors as $i => $error) {
  656. if ($i == 0) {
  657. $error_msg = $error;
  658. } else {
  659. $error_msg = $error_msg.", ".$error;
  660. }
  661. }
  662. $_SESSION['error_msg'] = _('Field "%s" can not be blank.', $error_msg);
  663. }
  664. if (($v_stats_user != $_POST['v_stats_user']) || (!empty($_POST['v_stats_password'])) && (empty($_SESSION['error_msg']))) {
  665. $v_stats_user = escapeshellarg($_POST['v_stats_user']);
  666. $v_stats_password = tempnam("/tmp", "vst");
  667. $fp = fopen($v_stats_password, "w");
  668. fwrite($fp, $_POST['v_stats_password']."\n");
  669. fclose($fp);
  670. exec(HESTIA_CMD."v-add-web-domain-stats-user ".$v_username." ".escapeshellarg($v_domain)." ".$v_stats_user." ".$v_stats_password, $output, $return_var);
  671. check_return_code($return_var, $output);
  672. unset($output);
  673. unlink($v_stats_password);
  674. $v_stats_password = escapeshellarg($_POST['v_stats_password']);
  675. }
  676. }
  677. // Update ftp account
  678. if (!empty($_POST['v_ftp_user'])) {
  679. $v_ftp_users_updated = array();
  680. foreach ($_POST['v_ftp_user'] as $i => $v_ftp_user_data) {
  681. if (empty($v_ftp_user_data['v_ftp_user'])) {
  682. continue;
  683. }
  684. $v_ftp_user_data['v_ftp_user'] = preg_replace("/^".$user."_/i", "", $v_ftp_user_data['v_ftp_user']);
  685. if ($v_ftp_user_data['is_new'] == 1 && !empty($_POST['v_ftp'])) {
  686. if ((!empty($v_ftp_user_data['v_ftp_email'])) && (!filter_var($v_ftp_user_data['v_ftp_email'], FILTER_VALIDATE_EMAIL))) {
  687. $_SESSION['error_msg'] = _('Please enter valid email address.');
  688. }
  689. if (empty($v_ftp_user_data['v_ftp_user'])) {
  690. $errors[] = 'ftp user';
  691. }
  692. if (!empty($errors[0])) {
  693. foreach ($errors as $i => $error) {
  694. if ($i == 0) {
  695. $error_msg = $error;
  696. } else {
  697. $error_msg = $error_msg.", ".$error;
  698. }
  699. }
  700. $_SESSION['error_msg'] = _('Field "%s" can not be blank.', $error_msg);
  701. }
  702. // Add ftp account
  703. $v_ftp_username = $v_ftp_user_data['v_ftp_user'];
  704. $v_ftp_username_full = $user . '_' . $v_ftp_user_data['v_ftp_user'];
  705. $v_ftp_user = escapeshellarg($v_ftp_username);
  706. $v_ftp_path = escapeshellarg(trim($v_ftp_user_data['v_ftp_path']));
  707. if (empty($_SESSION['error_msg'])) {
  708. $v_ftp_password = tempnam("/tmp", "vst");
  709. $fp = fopen($v_ftp_password, "w");
  710. fwrite($fp, $v_ftp_user_data['v_ftp_password']."\n");
  711. fclose($fp);
  712. exec(HESTIA_CMD."v-add-web-domain-ftp ".$v_username." ".escapeshellarg($v_domain)." ".$v_ftp_user." ".$v_ftp_password . " " . $v_ftp_path, $output, $return_var);
  713. check_return_code($return_var, $output);
  714. if ((!empty($v_ftp_user_data['v_ftp_email'])) && (empty($_SESSION['error_msg']))) {
  715. $to = $v_ftp_user_data['v_ftp_email'];
  716. $subject = _("FTP login credentials");
  717. $hostname = exec('hostname');
  718. $from = "noreply@".$hostname;
  719. $from_name = _('Hestia Control Panel');
  720. $mailtext = sprintf(_('FTP_ACCOUNT_READY'), escapeshellarg($_GET['domain']), $user, $v_ftp_username, $v_ftp_user_data['v_ftp_password']);
  721. send_email($to, $subject, $mailtext, $from, $from_name);
  722. unset($v_ftp_email);
  723. }
  724. unset($output);
  725. unlink($v_ftp_password);
  726. $v_ftp_password = escapeshellarg($v_ftp_user_data['v_ftp_password']);
  727. }
  728. if ($return_var == 0) {
  729. $v_ftp_password = "";
  730. $v_ftp_user_data['is_new'] = 0;
  731. } else {
  732. $v_ftp_user_data['is_new'] = 1;
  733. }
  734. $v_ftp_users_updated[] = array(
  735. 'is_new' => empty($_SESSION['error_msg']) ? 0 : 1,
  736. 'v_ftp_user' => $v_ftp_username_full,
  737. 'v_ftp_password' => $v_ftp_password,
  738. 'v_ftp_path' => $v_ftp_user_data['v_ftp_path'],
  739. 'v_ftp_email' => $v_ftp_user_data['v_ftp_email'],
  740. 'v_ftp_pre_path' => $v_ftp_user_prepath
  741. );
  742. continue;
  743. }
  744. // Delete FTP account
  745. if ($v_ftp_user_data['delete'] == 1) {
  746. $v_ftp_username = $user . '_' . $v_ftp_user_data['v_ftp_user'];
  747. exec(HESTIA_CMD."v-delete-web-domain-ftp ".$v_username." ".escapeshellarg($v_domain)." ".$v_ftp_username, $output, $return_var);
  748. check_return_code($return_var, $output);
  749. unset($output);
  750. continue;
  751. }
  752. if (!empty($_POST['v_ftp'])) {
  753. if (empty($v_ftp_user_data['v_ftp_user'])) {
  754. $errors[] = _('ftp user');
  755. }
  756. if (!empty($errors[0])) {
  757. foreach ($errors as $i => $error) {
  758. if ($i == 0) {
  759. $error_msg = $error;
  760. } else {
  761. $error_msg = $error_msg.", ".$error;
  762. }
  763. }
  764. $_SESSION['error_msg'] = _('Field "%s" can not be blank.', $error_msg);
  765. }
  766. // Change FTP account path
  767. $v_ftp_username_for_emailing = $v_ftp_user_data['v_ftp_user'];
  768. $v_ftp_username = $user . '_' . $v_ftp_user_data['v_ftp_user']; //preg_replace("/^".$user."_/", "", $v_ftp_user_data['v_ftp_user']);
  769. $v_ftp_username = escapeshellarg($v_ftp_username);
  770. $v_ftp_path = escapeshellarg(trim($v_ftp_user_data['v_ftp_path']));
  771. if (escapeshellarg(trim($v_ftp_user_data['v_ftp_path_prev'])) != $v_ftp_path) {
  772. exec(HESTIA_CMD."v-change-web-domain-ftp-path ".$v_username." ".escapeshellarg($v_domain)." ".$v_ftp_username." ".$v_ftp_path, $output, $return_var);
  773. }
  774. // Change FTP account password
  775. if (!empty($v_ftp_user_data['v_ftp_password'])) {
  776. $v_ftp_password = tempnam("/tmp", "vst");
  777. $fp = fopen($v_ftp_password, "w");
  778. fwrite($fp, $v_ftp_user_data['v_ftp_password']."\n");
  779. fclose($fp);
  780. exec(HESTIA_CMD."v-change-web-domain-ftp-password ".$v_username." ".escapeshellarg($v_domain)." ".$v_ftp_username." ".$v_ftp_password, $output, $return_var);
  781. unlink($v_ftp_password);
  782. $to = $v_ftp_user_data['v_ftp_email'];
  783. $subject = _("FTP login credentials");
  784. $hostname = exec('hostname');
  785. $from = "noreply@".$hostname;
  786. $from_name = _('Hestia Control Panel');
  787. $mailtext = _('FTP_ACCOUNT_READY', escapeshellarg($_GET['domain']), $user, $v_ftp_username_for_emailing, $v_ftp_user_data['v_ftp_password']);
  788. send_email($to, $subject, $mailtext, $from, $from_name);
  789. unset($v_ftp_email);
  790. }
  791. check_return_code($return_var, $output);
  792. unset($output);
  793. $v_ftp_users_updated[] = array(
  794. 'is_new' => 0,
  795. 'v_ftp_user' => $v_ftp_username,
  796. 'v_ftp_password' => $v_ftp_user_data['v_ftp_password'],
  797. 'v_ftp_path' => $v_ftp_user_data['v_ftp_path'],
  798. 'v_ftp_email' => $v_ftp_user_data['v_ftp_email'],
  799. 'v_ftp_pre_path' => $v_ftp_user_prepath
  800. );
  801. }
  802. }
  803. }
  804. //custom docoot with check box disabled
  805. if (!empty($v_custom_doc_root) && empty($_POST['v_custom_doc_root_check'])) {
  806. exec(HESTIA_CMD."v-change-web-domain-docroot ".$v_username." ".escapeshellarg($v_domain)." default", $output, $return_var);
  807. check_return_code($return_var, $output);
  808. unset($output);
  809. unset($_POST['v-custom-doc-domain'], $_POST['v-custom-doc-folder']);
  810. $restart_web = 'yes';
  811. $restart_proxy = 'yes';
  812. }
  813. if (!empty($_POST['v-custom-doc-domain']) && !empty($_POST['v_custom_doc_root_check']) && $v_custom_doc_root_prepath.$v_custom_doc_domain.'/public_html'.$v_custom_doc_folder != $v_custom_doc_root) {
  814. if ($_POST['v-custom-doc-domain'] == $v_domain && empty($_POST['v-custom-doc-folder'])) {
  815. exec(HESTIA_CMD."v-change-web-domain-docroot ".$v_username." ".escapeshellarg($v_domain)." default", $output, $return_var);
  816. check_return_code($return_var, $output);
  817. unset($output);
  818. } else {
  819. $v_custom_doc_folder = escapeshellarg(rtrim($_POST['v-custom-doc-folder'], '/'));
  820. $v_custom_doc_domain = escapeshellarg($_POST['v-custom-doc-domain']);
  821. exec(HESTIA_CMD."v-change-web-domain-docroot ".$v_username." ".escapeshellarg($v_domain)." ".$v_custom_doc_domain." ".$v_custom_doc_folder ." yes", $output, $return_var);
  822. check_return_code($return_var, $output);
  823. unset($output);
  824. $v_custom_doc_root = 1;
  825. }
  826. $restart_web = 'yes';
  827. $restart_proxy = 'yes';
  828. } else {
  829. unset($v_custom_doc_root);
  830. }
  831. if (!empty($v_redirect) && empty($_POST['v-redirect-checkbox'])) {
  832. exec(HESTIA_CMD."v-delete-web-domain-redirect ".$v_username." ".escapeshellarg($v_domain), $output, $return_var);
  833. check_return_code($return_var, $output);
  834. unset($output);
  835. unset($_POST['v-redirect']);
  836. $restart_web = 'yes';
  837. $restart_proxy = 'yes';
  838. }
  839. if (!empty($_POST['v-redirect']) && !empty($_POST['v-redirect-checkbox'])) {
  840. if (empty($v_redirect)) {
  841. if ($_POST['v-redirect'] == 'custom' && empty($_POST['v-redirect-custom'])) {
  842. } else {
  843. if ($_POST['v-redirect'] == 'custom') {
  844. $_POST['v-redirect'] = $_POST['v-redirect-custom'];
  845. }
  846. exec(HESTIA_CMD."v-add-web-domain-redirect ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($_POST['v-redirect'])." ".escapeshellarg($_POST['v-redirect-code']), $output, $return_var);
  847. check_return_code($return_var, $output);
  848. unset($output);
  849. $restart_web = 'yes';
  850. $restart_proxy = 'yes';
  851. }
  852. } else {
  853. if ($_POST['v-redirect'] == 'custom') {
  854. $_POST['v-redirect'] = $_POST['v-redirect-custom'];
  855. }
  856. if ($_POST['v-redirect'] != $v_redirect || $_POST['v-redirect-code'] != $v_redirect_code) {
  857. exec(HESTIA_CMD."v-add-web-domain-redirect ".$v_username." ".escapeshellarg($v_domain)." ".escapeshellarg($_POST['v-redirect'])." ".escapeshellarg($_POST['v-redirect-code']), $output, $return_var);
  858. check_return_code($return_var, $output);
  859. unset($output);
  860. $restart_web = 'yes';
  861. $restart_proxy = 'yes';
  862. }
  863. }
  864. }
  865. // Restart web server
  866. if (!empty($restart_web) && (empty($_SESSION['error_msg']))) {
  867. exec(HESTIA_CMD."v-restart-web", $output, $return_var);
  868. check_return_code($return_var, $output);
  869. unset($output);
  870. }
  871. // Restart proxy server
  872. if ((!empty($_SESSION['PROXY_SYSTEM'])) && !empty($restart_proxy) && (empty($_SESSION['error_msg']))) {
  873. exec(HESTIA_CMD."v-restart-proxy", $output, $return_var);
  874. check_return_code($return_var, $output);
  875. unset($output);
  876. }
  877. // Restart dns server
  878. if (!empty($restart_dns) && (empty($_SESSION['error_msg']))) {
  879. exec(HESTIA_CMD."v-restart-dns", $output, $return_var);
  880. check_return_code($return_var, $output);
  881. unset($output);
  882. }
  883. // Set success message
  884. if (empty($_SESSION['error_msg'])) {
  885. $_SESSION['ok_msg'] = _('Changes has been saved.');
  886. header("Location: /edit/web/?domain=" . $v_domain);
  887. exit();
  888. }
  889. }
  890. $v_ftp_users_raw = explode(':', $v_ftp_user);
  891. $v_ftp_users_paths_raw = explode(':', $data[$v_domain]['FTP_PATH']);
  892. $v_ftp_users = array();
  893. foreach ($v_ftp_users_raw as $v_ftp_user_index => $v_ftp_user_val) {
  894. if (empty($v_ftp_user_val)) {
  895. continue;
  896. }
  897. $v_ftp_users[] = array(
  898. 'is_new' => 0,
  899. 'v_ftp_user' => preg_replace("/^".$user."_/", "", $v_ftp_user_val),
  900. 'v_ftp_password' => $v_ftp_password,
  901. 'v_ftp_path' => (isset($v_ftp_users_paths_raw[$v_ftp_user_index]) ? $v_ftp_users_paths_raw[$v_ftp_user_index] : ''),
  902. 'v_ftp_email' => $v_ftp_email,
  903. 'v_ftp_pre_path' => $v_ftp_user_prepath
  904. );
  905. }
  906. if (empty($v_ftp_users)) {
  907. $v_ftp_user = null;
  908. $v_ftp_users[] = array(
  909. 'is_new' => 1,
  910. 'v_ftp_user' => '',
  911. 'v_ftp_password' => '',
  912. 'v_ftp_path' => (isset($v_ftp_users_paths_raw[$v_ftp_user_index]) ? $v_ftp_users_paths_raw[$v_ftp_user_index] : ''),
  913. 'v_ftp_email' => '',
  914. 'v_ftp_pre_path' => $v_ftp_user_prepath
  915. );
  916. }
  917. // set default pre path for newly created users
  918. $v_ftp_pre_path_new_user = $v_ftp_user_prepath;
  919. if (isset($v_ftp_users_updated)) {
  920. $v_ftp_users = $v_ftp_users_updated;
  921. if (empty($v_ftp_users_updated)) {
  922. $v_ftp_user = null;
  923. $v_ftp_users[] = array(
  924. 'is_new' => 1,
  925. 'v_ftp_user' => '',
  926. 'v_ftp_password' => '',
  927. 'v_ftp_path' => (isset($v_ftp_users_paths_raw[$v_ftp_user_index]) ? $v_ftp_users_paths_raw[$v_ftp_user_index] : ''),
  928. 'v_ftp_email' => '',
  929. 'v_ftp_pre_path' => $v_ftp_user_prepath
  930. );
  931. }
  932. }
  933. // Render page
  934. render_page($user, $TAB, 'edit_web');
  935. // Flush session messages
  936. unset($_SESSION['error_msg']);
  937. unset($_SESSION['ok_msg']);