main.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415
  1. <?php
  2. use PHPMailer\PHPMailer\PHPMailer;
  3. use PHPMailer\PHPMailer\SMTP;
  4. use PHPMailer\PHPMailer\Exception;
  5. require 'vendor/autoload.php';
  6. session_start();
  7. define('HESTIA_CMD', '/usr/bin/sudo /usr/local/hestia/bin/');
  8. if ($_SESSION['RELEASE_BRANCH'] == 'release' && $_SESSION['DEBUG_MODE'] == 'false') {
  9. define('JS_LATEST_UPDATE','v=' . $_SESSION['VERSION']);
  10. }else{
  11. define('JS_LATEST_UPDATE','r=' . time());
  12. }
  13. define('DEFAULT_PHP_VERSION', 'php-' . exec('php -r "echo (float)phpversion();"'));
  14. function destroy_sessions(){
  15. unset($_SESSION);
  16. session_unset();
  17. session_destroy();
  18. }
  19. $i = 0;
  20. // Saving user IPs to the session for preventing session hijacking
  21. $user_combined_ip = $_SERVER['REMOTE_ADDR'];
  22. if (isset($_SERVER['HTTP_CLIENT_IP'])) {
  23. $user_combined_ip .= '|' . $_SERVER['HTTP_CLIENT_IP'];
  24. }
  25. if (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) {
  26. $user_combined_ip .= '|' . $_SERVER['HTTP_X_FORWARDED_FOR'];
  27. }
  28. if (isset($_SERVER['HTTP_FORWARDED_FOR'])) {
  29. $user_combined_ip .= '|' . $_SERVER['HTTP_FORWARDED_FOR'];
  30. }
  31. if (isset($_SERVER['HTTP_X_FORWARDED'])) {
  32. $user_combined_ip .= '|' . $_SERVER['HTTP_X_FORWARDED'];
  33. }
  34. if (isset($_SERVER['HTTP_FORWARDED'])) {
  35. $user_combined_ip .= '|' . $_SERVER['HTTP_FORWARDED'];
  36. }
  37. if (isset($_SERVER['HTTP_CF_CONNECTING_IP'])) {
  38. if (!empty($_SERVER['HTTP_CF_CONNECTING_IP'])) {
  39. $user_combined_ip = $_SERVER['HTTP_CF_CONNECTING_IP'];
  40. }
  41. }
  42. if (!isset($_SESSION['user_combined_ip'])) {
  43. $_SESSION['user_combined_ip'] = $user_combined_ip;
  44. }
  45. // Checking user to use session from the same IP he has been logged in
  46. if ($_SESSION['user_combined_ip'] != $user_combined_ip && $_SERVER['REMOTE_ADDR'] != '127.0.0.1'){
  47. $v_user = escapeshellarg($_SESSION['user']);
  48. $v_session_id = escapeshellarg($_SESSION['token']);
  49. exec(HESTIA_CMD . 'v-log-user-logout ' . $v_user . ' ' . $v_session_id, $output, $return_var);
  50. destroy_sessions();
  51. header('Location: /login/');
  52. exit;
  53. }
  54. // Load Hestia Config directly
  55. load_hestia_config();
  56. // Check system settings
  57. if ((!isset($_SESSION['VERSION'])) && (!defined('NO_AUTH_REQUIRED'))) {
  58. destroy_sessions();
  59. header('Location: /login/');
  60. exit;
  61. }
  62. // Check user session
  63. if ((!isset($_SESSION['user'])) && (!defined('NO_AUTH_REQUIRED'))) {
  64. destroy_sessions();
  65. header('Location: /login/');
  66. exit;
  67. }
  68. // Generate CSRF Token
  69. if (isset($_SESSION['user'])) {
  70. if (!isset($_SESSION['token'])){
  71. $token = bin2hex(file_get_contents('/dev/urandom', false, null, 0, 16));
  72. $_SESSION['token'] = $token;
  73. }
  74. }
  75. if (!defined('NO_AUTH_REQUIRED')){
  76. if (empty($_SESSION['LAST_ACTIVITY']) || empty($_SESSION['INACTIVE_SESSION_TIMEOUT'])){
  77. destroy_sessions();
  78. header('Location: /login/');
  79. } elseif ($_SESSION['INACTIVE_SESSION_TIMEOUT'] * 60 + $_SESSION['LAST_ACTIVITY'] < time()) {
  80. $v_user = escapeshellarg($_SESSION['user']);
  81. $v_session_id = escapeshellarg($_SESSION['token']);
  82. exec(HESTIA_CMD . 'v-log-user-logout ' . $v_user . ' ' . $v_session_id, $output, $return_var);
  83. destroy_sessions();
  84. header('Location: /login/');
  85. exit;
  86. } else {
  87. $_SESSION['LAST_ACTIVITY'] = time();
  88. }
  89. }
  90. if (isset($_SESSION['user'])) {
  91. $user = $_SESSION['user'];
  92. }
  93. if (isset($_SESSION['look']) && ($_SESSION['userContext'] === 'admin')) {
  94. $user = $_SESSION['look'];
  95. }
  96. require_once(dirname(__FILE__) . '/i18n.php');
  97. function check_error($return_var) {
  98. if ( $return_var > 0 ) {
  99. header('Location: /error/');
  100. exit;
  101. }
  102. }
  103. function check_return_code($return_var,$output) {
  104. if ($return_var != 0) {
  105. $error = implode('<br>', $output);
  106. if (empty($error)) $error = sprintf(_('Error code:'), $return_var);
  107. $_SESSION['error_msg'] = $error;
  108. }
  109. }
  110. function render_page($user, $TAB, $page) {
  111. $__template_dir = dirname(__DIR__) . '/templates/';
  112. $__pages_js_dir = dirname(__DIR__) . '/js/pages/';
  113. // Header
  114. include($__template_dir . 'header.html');
  115. // Panel
  116. top_panel(empty($_SESSION['look']) ? $_SESSION['user'] : $_SESSION['look'], $TAB);
  117. // Extract global variables
  118. // I think those variables should be passed via arguments
  119. extract($GLOBALS, EXTR_SKIP);
  120. // Policies controller
  121. @include_once(dirname(__DIR__) . '/inc/policies.php');
  122. // Body
  123. include($__template_dir . 'pages/' . $page . '.html');
  124. // Including common js files
  125. @include_once(dirname(__DIR__) . '/templates/includes/end_js.html');
  126. // Including page specific js file
  127. if(file_exists($__pages_js_dir . $page . '.js'))
  128. echo '<script src="/js/pages/' . $page . '.js?' . JS_LATEST_UPDATE . '"></script>';
  129. // Footer
  130. include($__template_dir . 'footer.html');
  131. }
  132. function top_panel($user, $TAB) {
  133. global $panel;
  134. $command = HESTIA_CMD . 'v-list-user ' . escapeshellarg($user) . " 'json'";
  135. exec ($command, $output, $return_var);
  136. if ( $return_var > 0 ) {
  137. echo '<span style="font-size: 18px;"><b>ERROR: Unable to retrieve account details.</b><br>Please <b><a href="/login/">log in</a></b> again.</span>';
  138. destroy_sessions();
  139. header('Location: /login/');
  140. exit;
  141. }
  142. $panel = json_decode(implode('', $output), true);
  143. unset($output);
  144. // Log out active sessions for suspended users
  145. if (($panel[$user]['SUSPENDED'] === 'yes') && ($_SESSION['POLICY_USER_VIEW_SUSPENDED'] !== 'yes')) {
  146. $_SESSION['error_msg'] = 'You have been logged out. Please log in again.';
  147. destroy_sessions();
  148. header('Location: /login/');
  149. }
  150. // Reset user permissions if changed while logged in
  151. if (($panel[$user]['ROLE']) !== ($_SESSION['userContext']) && (!isset($_SESSION['look']))) {
  152. unset($_SESSION['userContext']);
  153. $_SESSION['userContext'] = $panel[$user]['ROLE'];
  154. }
  155. // Load user's selected theme and do not change it when impersonting user
  156. if ( (isset($panel[$user]['THEME'])) && (!isset($_SESSION['look']) )) {
  157. $_SESSION['userTheme'] = $panel[$user]['THEME'];
  158. }
  159. // Unset userTheme override variable if POLICY_USER_CHANGE_THEME is set to no
  160. if ($_SESSION['POLICY_USER_CHANGE_THEME'] === 'no') {
  161. unset($_SESSION['userTheme']);
  162. }
  163. // Set preferred sort order
  164. if (!isset($_SESSION['look'])) {
  165. $_SESSION['userSortOrder'] = $panel[$user]['PREF_UI_SORT'];
  166. }
  167. // Set home location URLs
  168. if (($_SESSION['userContext'] === 'admin') && (!isset($_SESSION['look']))) {
  169. // Display users list for administrators unless they are impersonating a user account
  170. $home_url = '/list/user/';
  171. } else {
  172. // Set home location URL based on available package features from account
  173. if ($panel[$user]['WEB_DOMAINS'] != '0') {
  174. $home_url = '/list/web/';
  175. } elseif ($panel[$user]['DNS_DOMAINS'] != '0') {
  176. $home_url = '/list/dns/';
  177. } elseif ($panel[$user]['MAIL_DOMAINS'] != '0') {
  178. $home_url = '/list/mail/';
  179. } elseif ($panel[$user]['DATABASES'] != '0') {
  180. $home_url = '/list/db/';
  181. } elseif ($panel[$user]['CRON_JOBS'] != '0') {
  182. $home_url = '/list/cron/';
  183. } elseif ($panel[$user]['BACKUPS'] != '0') {
  184. $home_url = '/list/backups/';
  185. }
  186. }
  187. include(dirname(__FILE__) . '/../templates/includes/panel.html');
  188. }
  189. function translate_date($date){
  190. $date = strtotime($date);
  191. return strftime('%d &nbsp;', $date) . _(strftime('%b', $date)) . strftime(' &nbsp;%Y', $date);
  192. }
  193. function humanize_time($usage) {
  194. if ( $usage > 60 ) {
  195. $usage = $usage / 60;
  196. if ( $usage > 24 ) {
  197. $usage = $usage / 24;
  198. $usage = number_format($usage);
  199. return sprintf(ngettext('%d day', '%d days', $usage), $usage);
  200. } else {
  201. return sprintf(ngettext('%d hour', '%d hours', $usage), $usage);
  202. }
  203. } else {
  204. return sprintf(ngettext('%d minute', '%d minutes', $usage), $usage);
  205. }
  206. }
  207. function humanize_usage_size($usage) {
  208. if ( $usage > 1024 ) {
  209. $usage = $usage / 1024;
  210. if ( $usage > 1024 ) {
  211. $usage = $usage / 1024 ;
  212. if ( $usage > 1024 ) {
  213. $usage = $usage / 1024 ;
  214. $usage = number_format($usage, 2);
  215. } else {
  216. $usage = number_format($usage, 2);
  217. }
  218. } else {
  219. $usage = number_format($usage, 2);
  220. }
  221. }
  222. return $usage;
  223. }
  224. function humanize_usage_measure($usage) {
  225. $measure = 'kb';
  226. if ( $usage > 1024 ) {
  227. $usage = $usage / 1024;
  228. if ( $usage > 1024 ) {
  229. $usage = $usage / 1024 ;
  230. $measure = ( $usage > 1024 ) ? 'pb' : 'tb';
  231. } else {
  232. $measure = 'gb';
  233. }
  234. } else {
  235. $measure = 'mb';
  236. }
  237. return $measure;
  238. }
  239. function get_percentage($used,$total) {
  240. if (!isset($total)) $total = 0;
  241. if (!isset($used)) $used = 0;
  242. if ( $total == 0 ) {
  243. $percent = 0;
  244. } else {
  245. $percent = $used / $total;
  246. $percent = $percent * 100;
  247. $percent = number_format($percent, 0, '', '');
  248. if ( $percent < 0 ) {
  249. $percent = 0;
  250. } elseif ( $percent > 100 ) {
  251. $percent = 100;
  252. }
  253. }
  254. return $percent;
  255. }
  256. function send_email($to, $subject, $mailtext, $from, $from_name) {
  257. $mail = new PHPMailer();
  258. if (isset($_SESSION['USE_SERVER_SMTP']) && $_SESSION['USE_SERVER_SMTP'] == "true") {
  259. $from = $_SESSION['SERVER_SMTP_ADDR'];
  260. $mail->IsSMTP();
  261. $mail->Mailer = "smtp";
  262. $mail->SMTPDebug = 0;
  263. $mail->SMTPAuth = TRUE;
  264. $mail->SMTPSecure = $_SESSION['SERVER_SMTP_SECURITY'];
  265. $mail->Port = $_SESSION['SERVER_SMTP_PORT'];
  266. $mail->Host = $_SESSION['SERVER_SMTP_HOST'];
  267. $mail->Username = $_SESSION['SERVER_SMTP_USER'];
  268. $mail->Password = $_SESSION['SERVER_SMTP_PASSWD'];
  269. }
  270. $mail->IsHTML(true);
  271. $mail->ClearReplyTos();
  272. $mail->AddAddress($to, "Hestia Control Panel User");
  273. $mail->SetFrom($from, $from_name);
  274. $mail->Subject = $subject;
  275. $content = $mailtext;
  276. $content = nl2br($content);
  277. $mail->MsgHTML($content);
  278. $mail->Send();
  279. }
  280. function list_timezones() {
  281. foreach(['AKST', 'AKDT', 'PST', 'PDT', 'MST', 'MDT', 'CST', 'CDT', 'EST', 'EDT', 'AST', 'ADT'] as $timezone) {
  282. $tz = new DateTimeZone($timezone);
  283. $timezone_offsets[$timezone] = $tz->getOffset(new DateTime);
  284. }
  285. foreach(DateTimeZone::listIdentifiers() as $timezone) {
  286. $tz = new DateTimeZone($timezone);
  287. $timezone_offsets[$timezone] = $tz->getOffset(new DateTime);
  288. }
  289. foreach($timezone_offsets as $timezone => $offset) {
  290. $offset_prefix = $offset < 0 ? '-' : '+';
  291. $offset_formatted = gmdate( 'H:i', abs($offset) );
  292. $pretty_offset = "UTC${offset_prefix}${offset_formatted}";
  293. $t = new DateTimeZone($timezone);
  294. $c = new DateTime(null, $t);
  295. $current_time = $c->format('H:i:s');
  296. $timezone_list[$timezone] = "$timezone [ $current_time ] ${pretty_offset}";
  297. }
  298. return $timezone_list;
  299. }
  300. /**
  301. * A function that tells is it MySQL installed on the system, or it is MariaDB.
  302. *
  303. * Explaination:
  304. * $_SESSION['DB_SYSTEM'] has 'mysql' value even if MariaDB is installed, so you can't figure out is it really MySQL or it's MariaDB.
  305. * So, this function will make it clear.
  306. *
  307. * If MySQL is installed, function will return 'mysql' as a string.
  308. * If MariaDB is installed, function will return 'mariadb' as a string.
  309. *
  310. * Hint: if you want to check if PostgreSQL is installed - check value of $_SESSION['DB_SYSTEM']
  311. *
  312. * @return string
  313. */
  314. function is_it_mysql_or_mariadb() {
  315. exec (HESTIA_CMD . 'v-list-sys-services json', $output, $return_var);
  316. $data = json_decode(implode('', $output), true);
  317. unset($output);
  318. $mysqltype = 'mysql';
  319. if (isset($data['mariadb'])) $mysqltype = 'mariadb';
  320. return $mysqltype;
  321. }
  322. function load_hestia_config() {
  323. // Check system configuration
  324. exec (HESTIA_CMD . "v-list-sys-config json", $output, $return_var);
  325. $data = json_decode(implode('', $output), true);
  326. $sys_arr = $data['config'];
  327. foreach ($sys_arr as $key => $value) {
  328. $_SESSION[$key] = $value;
  329. }
  330. }
  331. /**
  332. * Returns the list of all web domains from all users grouped by Backend Template used and owner
  333. *
  334. * @return array
  335. */
  336. function backendtpl_with_webdomains() {
  337. exec (HESTIA_CMD . 'v-list-users json', $output, $return_var);
  338. $users = json_decode(implode('', $output), true);
  339. unset($output);
  340. $backend_list=[];
  341. foreach ($users as $user => $user_details) {
  342. exec (HESTIA_CMD . 'v-list-web-domains '. escapeshellarg($user) . ' json', $output, $return_var);
  343. $domains = json_decode(implode('', $output), true);
  344. unset($output);
  345. foreach ($domains as $domain => $domain_details) {
  346. if (!empty($domain_details['BACKEND'])) {
  347. $backend = $domain_details['BACKEND'];
  348. $backend_list[$backend][$user][] = $domain;
  349. }
  350. }
  351. }
  352. return $backend_list;
  353. }
  354. /**
  355. * Check if password is valid
  356. *
  357. * @return int; 1 / 0
  358. */
  359. function validate_password($password){
  360. return preg_match('/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(.){8,}$/', $password);
  361. }