index.php 2.8 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192
  1. <?php
  2. // Init
  3. error_reporting(NULL);
  4. ob_start();
  5. $TAB = 'DB';
  6. // Main include
  7. include($_SERVER['DOCUMENT_ROOT'].'/inc/main.php');
  8. // Check database id
  9. if (empty($_GET['database'])) {
  10. header("Location: /list/db/");
  11. exit;
  12. }
  13. // Edit as someone else?
  14. if (($_SESSION['user'] == 'admin') && (!empty($_GET['user']))) {
  15. $user=escapeshellarg($_GET['user']);
  16. }
  17. // List datbase
  18. $v_database = $_GET['database'];
  19. exec (HESTIA_CMD."v-list-database ".$user." ".escapeshellarg($v_database)." 'json'", $output, $return_var);
  20. check_return_code($return_var,$output);
  21. $data = json_decode(implode('', $output), true);
  22. unset($output);
  23. // Parse database
  24. $v_username = $user;
  25. $v_dbuser = $data[$v_database]['DBUSER'];
  26. $v_password = "";
  27. $v_host = $data[$v_database]['HOST'];
  28. $v_type = $data[$v_database]['TYPE'];
  29. $v_charset = $data[$v_database]['CHARSET'];
  30. $v_date = $data[$v_database]['DATE'];
  31. $v_time = $data[$v_database]['TIME'];
  32. $v_suspended = $data[$v_database]['SUSPENDED'];
  33. if ( $v_suspended == 'yes' ) {
  34. $v_status = 'suspended';
  35. } else {
  36. $v_status = 'active';
  37. }
  38. // Check POST request
  39. if (!empty($_POST['save'])) {
  40. $v_username = $user;
  41. // Check token
  42. if ((!isset($_POST['token'])) || ($_SESSION['token'] != $_POST['token'])) {
  43. header('location: /login/');
  44. exit();
  45. }
  46. // Change database user
  47. if (($v_dbuser != $_POST['v_dbuser']) && (empty($_SESSION['error_msg']))) {
  48. $v_dbuser = preg_replace("/^".$user."_/", "", $_POST['v_dbuser']);
  49. $v_dbuser = escapeshellarg($v_dbuser);
  50. exec (HESTIA_CMD."v-change-database-user ".$v_username." ".escapeshellarg($v_database)." ".$v_dbuser, $output, $return_var);
  51. check_return_code($return_var,$output);
  52. unset($output);
  53. $v_dbuser = $user."_".preg_replace("/^".$user."_/", "", $_POST['v_dbuser']);
  54. }
  55. // Change database password
  56. if ((!empty($_POST['v_password'])) && (empty($_SESSION['error_msg']))) {
  57. if (!validate_password($_POST['v_password'])) {
  58. $_SESSION['error_msg'] = __('Password does not match the minimum requirements');
  59. }else{
  60. $v_password = tempnam("/tmp","vst");
  61. $fp = fopen($v_password, "w");
  62. fwrite($fp, $_POST['v_password']."\n");
  63. fclose($fp);
  64. exec (HESTIA_CMD."v-change-database-password ".$v_username." ".escapeshellarg($v_database)." ".$v_password, $output, $return_var);
  65. check_return_code($return_var,$output);
  66. unset($output);
  67. unlink($v_password);
  68. $v_password = escapeshellarg($_POST['v_password']);
  69. }
  70. }
  71. // Set success message
  72. if (empty($_SESSION['error_msg'])) {
  73. $_SESSION['ok_msg'] = _('Changes has been saved.');
  74. }
  75. }
  76. // Render page
  77. render_page($user, $TAB, 'edit_db');
  78. // Flush session messages
  79. unset($_SESSION['error_msg']);
  80. unset($_SESSION['ok_msg']);