index.php 3.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126
  1. <?php
  2. error_reporting(null);
  3. $TAB = 'WEB';
  4. // Main include
  5. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  6. // Prepare values
  7. if (!empty($_GET['domain'])) {
  8. $v_domain = $_GET['domain'];
  9. } else {
  10. $v_domain = 'example.ltd';
  11. }
  12. $v_email = '';
  13. $v_country = 'US';
  14. $v_state = 'California';
  15. $v_locality = 'San Francisco';
  16. $v_org = 'MyCompany LLC';
  17. $v_org_unit = 'IT';
  18. // Back uri
  19. $_SESSION['back'] = '';
  20. // Check POST
  21. if (!isset($_POST['generate'])) {
  22. render_page($user, $TAB, 'generate_ssl');
  23. exit;
  24. }
  25. // Check token
  26. verify_csrf($_POST);
  27. // Check input
  28. if (empty($_POST['v_domain'])) {
  29. $errors[] = _('Domain');
  30. }
  31. if (empty($_POST['v_country'])) {
  32. $errors[] = _('Country');
  33. }
  34. if (empty($_POST['v_state'])) {
  35. $errors[] = _('State');
  36. }
  37. if (empty($_POST['v_locality'])) {
  38. $errors[] = _('City');
  39. }
  40. if (empty($_POST['v_org'])) {
  41. $errors[] = _('Organization');
  42. }
  43. $v_domain = $_POST['v_domain'];
  44. $v_aliases = $_POST['v_aliases'];
  45. $v_email = $_POST['v_email'];
  46. $v_country = $_POST['v_country'];
  47. $v_state = $_POST['v_state'];
  48. $v_locality = $_POST['v_locality'];
  49. $v_org = $_POST['v_org'];
  50. // Check for errors
  51. if (!empty($errors[0])) {
  52. foreach ($errors as $i => $error) {
  53. if ($i == 0) {
  54. $error_msg = $error;
  55. } else {
  56. $error_msg = $error_msg.", ".$error;
  57. }
  58. }
  59. $_SESSION['error_msg'] = sprintf(_('Field "%s" can not be blank.'), $error_msg);
  60. render_page($user, $TAB, 'generate_ssl');
  61. unset($_SESSION['error_msg']);
  62. exit;
  63. }
  64. // Protect input
  65. $v_domain = escapeshellarg($_POST['v_domain']);
  66. $waliases = preg_replace("/\n/", " ", $_POST['v_aliases']);
  67. $waliases = preg_replace("/,/", " ", $waliases);
  68. $waliases = preg_replace('/\s+/', ' ', $waliases);
  69. $waliases = trim($waliases);
  70. $aliases = explode(" ", $waliases);
  71. $v_aliases = escapeshellarg(str_replace(' ', "\n", $waliases));
  72. $v_email = escapeshellarg($_POST['v_email']);
  73. $v_country = escapeshellarg($_POST['v_country']);
  74. $v_state = escapeshellarg($_POST['v_state']);
  75. $v_locality = escapeshellarg($_POST['v_locality']);
  76. $v_org = escapeshellarg($_POST['v_org']);
  77. exec(HESTIA_CMD."v-generate-ssl-cert ".$v_domain." ".$v_email." ".$v_country." ".$v_state." ".$v_locality." ".$v_org." IT ".$v_aliases." json", $output, $return_var);
  78. // Revert to raw values
  79. $v_domain = $_POST['v_domain'];
  80. $v_email = $_POST['v_email'];
  81. $v_country = $_POST['v_country'];
  82. $v_state = $_POST['v_state'];
  83. $v_locality = $_POST['v_locality'];
  84. $v_org = $_POST['v_org'];
  85. // Check return code
  86. if ($return_var != 0) {
  87. $error = implode('<br>', $output);
  88. if (empty($error)) {
  89. $error = sprintf(_('Error code:'), $return_var);
  90. }
  91. $_SESSION['error_msg'] = $error;
  92. render_page($user, $TAB, 'generate_ssl');
  93. unset($_SESSION['error_msg']);
  94. exit;
  95. }
  96. // OK message
  97. $_SESSION['ok_msg'] = _('SSL_GENERATED_OK');
  98. // Parse output
  99. $data = json_decode(implode('', $output), true);
  100. unset($output);
  101. $v_crt = $data[$v_domain]['CRT'];
  102. $v_key = $data[$v_domain]['KEY'];
  103. $v_csr = $data[$v_domain]['CSR'];
  104. // Back uri
  105. $_SESSION['back'] = $_SERVER['REQUEST_URI'];
  106. // Render page
  107. render_page($user, $TAB, 'list_ssl');
  108. unset($_SESSION['ok_msg']);