index.php 3.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116
  1. <?php
  2. error_reporting(NULL);
  3. $TAB = 'WEB';
  4. // Main include
  5. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  6. // Prepare values
  7. if (!empty($_GET['domain'])) {
  8. $v_domain = $_GET['domain'];
  9. } else {
  10. $v_domain = 'example.ltd';
  11. }
  12. $v_email = 'admin@' . $v_domain;
  13. $v_country = 'US';
  14. $v_state = 'California';
  15. $v_locality = 'San Francisco';
  16. $v_org = 'MyCompany LLC';
  17. $v_org_unit = 'IT';
  18. // Back uri
  19. $_SESSION['back'] = '';
  20. // Check POST
  21. if (!isset($_POST['generate'])) {
  22. render_page($user, $TAB, 'generate_ssl');
  23. exit;
  24. }
  25. // Check token
  26. if ((!isset($_POST['token'])) || ($_SESSION['token'] != $_POST['token'])) {
  27. header('Location: /login/');
  28. exit();
  29. }
  30. // Check input
  31. if (empty($_POST['v_domain'])) $errors[] = _('Domain');
  32. if (empty($_POST['v_country'])) $errors[] = _('Country');
  33. if (empty($_POST['v_state'])) $errors[] = _('State');
  34. if (empty($_POST['v_locality'])) $errors[] = _('City');
  35. if (empty($_POST['v_org'])) $errors[] = _('Organization');
  36. if (empty($_POST['v_email'])) $errors[] = _('Email');
  37. $v_domain = $_POST['v_domain'];
  38. $v_aliases = $_POST['v_aliases'];
  39. $v_email = $_POST['v_email'];
  40. $v_country = $_POST['v_country'];
  41. $v_state = $_POST['v_state'];
  42. $v_locality = $_POST['v_locality'];
  43. $v_org = $_POST['v_org'];
  44. // Check for errors
  45. if (!empty($errors[0])) {
  46. foreach ($errors as $i => $error) {
  47. if ( $i == 0 ) {
  48. $error_msg = $error;
  49. } else {
  50. $error_msg = $error_msg.", ".$error;
  51. }
  52. }
  53. $_SESSION['error_msg'] = sprintf(_('Field "%s" can not be blank.'),$error_msg);
  54. render_page($user, $TAB, 'generate_ssl');
  55. unset($_SESSION['error_msg']);
  56. exit;
  57. }
  58. // Protect input
  59. $v_domain = escapeshellarg($_POST['v_domain']);
  60. $waliases = preg_replace("/\n/", " ", $_POST['v_aliases']);
  61. $waliases = preg_replace("/,/", " ", $waliases);
  62. $waliases = preg_replace('/\s+/', ' ',$waliases);
  63. $waliases = trim($waliases);
  64. $aliases = explode(" ", $waliases);
  65. $v_aliases = escapeshellarg(str_replace(' ', "\n", $waliases));
  66. $v_email = escapeshellarg($_POST['v_email']);
  67. $v_country = escapeshellarg($_POST['v_country']);
  68. $v_state = escapeshellarg($_POST['v_state']);
  69. $v_locality = escapeshellarg($_POST['v_locality']);
  70. $v_org = escapeshellarg($_POST['v_org']);
  71. exec (HESTIA_CMD."v-generate-ssl-cert ".$v_domain." ".$v_email." ".$v_country." ".$v_state." ".$v_locality." ".$v_org." IT '".$v_aliases."' json", $output, $return_var);
  72. // Revert to raw values
  73. $v_domain = $_POST['v_domain'];
  74. $v_email = $_POST['v_email'];
  75. $v_country = $_POST['v_country'];
  76. $v_state = $_POST['v_state'];
  77. $v_locality = $_POST['v_locality'];
  78. $v_org = $_POST['v_org'];
  79. // Check return code
  80. if ($return_var != 0) {
  81. $error = implode('<br>', $output);
  82. if (empty($error)) $error = sprintf(_('Error code:'),$return_var);
  83. $_SESSION['error_msg'] = $error;
  84. render_page($user, $TAB, 'generate_ssl');
  85. unset($_SESSION['error_msg']);
  86. exit;
  87. }
  88. // OK message
  89. $_SESSION['ok_msg'] = _('SSL_GENERATED_OK');
  90. // Parse output
  91. $data = json_decode(implode('', $output), true);
  92. unset($output);
  93. $v_crt = $data[$v_domain]['CRT'];
  94. $v_key = $data[$v_domain]['KEY'];
  95. $v_csr = $data[$v_domain]['CSR'];
  96. // Back uri
  97. $_SESSION['back'] = $_SERVER['REQUEST_URI'];
  98. // Render page
  99. render_page($user, $TAB, 'list_ssl');
  100. unset($_SESSION['ok_msg']);