1
0

index.php 2.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788
  1. <?php
  2. ob_start();
  3. $TAB = 'DB';
  4. // Main include
  5. include($_SERVER['DOCUMENT_ROOT'].'/inc/main.php');
  6. // Check database id
  7. if (empty($_GET['database'])) {
  8. header("Location: /list/db/");
  9. exit;
  10. }
  11. // Edit as someone else?
  12. if (($_SESSION['userContext'] === 'admin') && (!empty($_GET['user']))) {
  13. $user=escapeshellarg($_GET['user']);
  14. $user_plain=htmlentities($_GET['user']);
  15. }
  16. // List datbase
  17. $v_database = $_GET['database'];
  18. exec(HESTIA_CMD."v-list-database ".$user." ".escapeshellarg($v_database)." 'json'", $output, $return_var);
  19. check_return_code_redirect($return_var, $output, '/list/db/');
  20. $data = json_decode(implode('', $output), true);
  21. unset($output);
  22. // Parse database
  23. $v_username = $user;
  24. $v_dbuser = preg_replace("/^".$user_plain."_/", "", $data[$v_database]['DBUSER']);
  25. $v_password = "";
  26. $v_host = $data[$v_database]['HOST'];
  27. $v_type = $data[$v_database]['TYPE'];
  28. $v_charset = $data[$v_database]['CHARSET'];
  29. $v_date = $data[$v_database]['DATE'];
  30. $v_time = $data[$v_database]['TIME'];
  31. $v_suspended = $data[$v_database]['SUSPENDED'];
  32. if ($v_suspended == 'yes') {
  33. $v_status = 'suspended';
  34. } else {
  35. $v_status = 'active';
  36. }
  37. // Check POST request
  38. if (!empty($_POST['save'])) {
  39. $v_username = $user;
  40. // Check token
  41. verify_csrf($_POST);
  42. // Change database user
  43. if (($v_dbuser != $_POST['v_dbuser']) && (empty($_SESSION['error_msg']))) {
  44. $v_dbuser = escapeshellarg($v_dbuser);
  45. exec(HESTIA_CMD."v-change-database-user ".$user." ".escapeshellarg($v_database)." ".$v_dbuser, $output, $return_var);
  46. check_return_code($return_var, $output);
  47. unset($output);
  48. $v_dbuser = $_POST['v_dbuser'];
  49. }
  50. // Change database password
  51. if ((!empty($_POST['v_password'])) && (empty($_SESSION['error_msg']))) {
  52. if (!validate_password($_POST['v_password'])) {
  53. $_SESSION['error_msg'] = _('Password does not match the minimum requirements');
  54. } else {
  55. $v_password = tempnam("/tmp", "vst");
  56. $fp = fopen($v_password, "w");
  57. fwrite($fp, $_POST['v_password']."\n");
  58. fclose($fp);
  59. exec(HESTIA_CMD."v-change-database-password ".$user." ".escapeshellarg($v_database)." ".$v_password, $output, $return_var);
  60. check_return_code($return_var, $output);
  61. unset($output);
  62. unlink($v_password);
  63. $v_password = escapeshellarg($_POST['v_password']);
  64. }
  65. }
  66. // Set success message
  67. if (empty($_SESSION['error_msg'])) {
  68. $_SESSION['ok_msg'] = _('Changes has been saved.');
  69. }
  70. }
  71. // Render page
  72. render_page($user, $TAB, 'edit_db');
  73. // Flush session messages
  74. unset($_SESSION['error_msg']);
  75. unset($_SESSION['ok_msg']);