index.php 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218
  1. <?php
  2. error_reporting(NULL);
  3. ob_start();
  4. $TAB = 'USER';
  5. header('Content-Type: application/json');
  6. // Main include
  7. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  8. // Check user argument
  9. if (empty($_GET['user'])) {
  10. exit;
  11. }
  12. // Edit as someone else?
  13. if (($_SESSION['user'] == 'admin') && (!empty($_GET['user']))) {
  14. $user=$_GET['user'];
  15. $v_username=$_GET['user'];
  16. } else {
  17. $user=$_SESSION['user'];
  18. $v_username=$_SESSION['user'];
  19. }
  20. // List user
  21. exec (VESTA_CMD."v-list-user ".escapeshellarg($v_username)." json", $output, $return_var);
  22. check_return_code($return_var,$output);
  23. $data = json_decode(implode('', $output), true);
  24. unset($output);
  25. // Parse user
  26. $v_password = "";
  27. $v_email = $data[$v_username]['CONTACT'];
  28. $v_package = $data[$v_username]['PACKAGE'];
  29. $v_language = $data[$v_username]['LANGUAGE'];
  30. $v_fname = $data[$v_username]['FNAME'];
  31. $v_lname = $data[$v_username]['LNAME'];
  32. $v_shell = $data[$v_username]['SHELL'];
  33. $v_ns = $data[$v_username]['NS'];
  34. $nameservers = explode(",", $v_ns);
  35. $v_ns1 = $nameservers[0];
  36. $v_ns2 = $nameservers[1];
  37. $v_ns3 = $nameservers[2];
  38. $v_ns4 = $nameservers[3];
  39. $v_ns5 = $nameservers[4];
  40. $v_ns6 = $nameservers[5];
  41. $v_ns7 = $nameservers[6];
  42. $v_ns8 = $nameservers[7];
  43. $v_suspended = $data[$v_username]['SUSPENDED'];
  44. if ( $v_suspended == 'yes' ) {
  45. $v_status = 'suspended';
  46. } else {
  47. $v_status = 'active';
  48. }
  49. $v_time = $data[$v_username]['TIME'];
  50. $v_date = $data[$v_username]['DATE'];
  51. // List packages
  52. exec (VESTA_CMD."v-list-user-packages json", $output, $return_var);
  53. $packages = json_decode(implode('', $output), true);
  54. unset($output);
  55. // List languages
  56. exec (VESTA_CMD."v-list-sys-languages json", $output, $return_var);
  57. $languages = json_decode(implode('', $output), true);
  58. unset($output);
  59. // List shells
  60. exec (VESTA_CMD."v-list-sys-shells json", $output, $return_var);
  61. $shells = json_decode(implode('', $output), true);
  62. unset($output);
  63. // Are you admin?
  64. // Check POST request
  65. if (!empty($_POST['save'])) {
  66. // Check token
  67. if ((!isset($_POST['token'])) || ($_SESSION['token'] != $_POST['token'])) {
  68. exit();
  69. }
  70. // Change password
  71. if ((!empty($_POST['v_password'])) && (empty($_SESSION['error_msg']))) {
  72. $v_password = tempnam("/tmp","vst");
  73. $fp = fopen($v_password, "w");
  74. fwrite($fp, $_POST['v_password']."\n");
  75. fclose($fp);
  76. exec (VESTA_CMD."v-change-user-password ".escapeshellarg($v_username)." ".$v_password, $output, $return_var);
  77. check_return_code($return_var,$output);
  78. unset($output);
  79. unlink($v_password);
  80. $v_password = escapeshellarg($_POST['v_password']);
  81. }
  82. // Change package (admin only)
  83. if (($v_package != $_POST['v_package']) && ($_SESSION['user'] == 'admin') && (empty($_SESSION['error_msg']))) {
  84. $v_package = escapeshellarg($_POST['v_package']);
  85. exec (VESTA_CMD."v-change-user-package ".escapeshellarg($v_username)." ".$v_package, $output, $return_var);
  86. check_return_code($return_var,$output);
  87. unset($output);
  88. }
  89. // Change language
  90. if (($v_language != $_POST['v_language']) && (empty($_SESSION['error_msg']))) {
  91. $v_language = escapeshellarg($_POST['v_language']);
  92. exec (VESTA_CMD."v-change-user-language ".escapeshellarg($v_username)." ".$v_language, $output, $return_var);
  93. check_return_code($return_var,$output);
  94. if (empty($_SESSION['error_msg'])) {
  95. if ((empty($_GET['user'])) || ($_GET['user'] == $_SESSION['user'])) $_SESSION['language'] = $_POST['v_language'];
  96. }
  97. unset($output);
  98. }
  99. // Change shell (admin only)
  100. if (($v_shell != $_POST['v_shell']) && ($_SESSION['user'] == 'admin') && (empty($_SESSION['error_msg']))) {
  101. $v_shell = escapeshellarg($_POST['v_shell']);
  102. exec (VESTA_CMD."v-change-user-shell ".escapeshellarg($v_username)." ".$v_shell, $output, $return_var);
  103. check_return_code($return_var,$output);
  104. unset($output);
  105. }
  106. // Change contact email
  107. if (($v_email != $_POST['v_email']) && (empty($_SESSION['error_msg']))) {
  108. if (!filter_var($_POST['v_email'], FILTER_VALIDATE_EMAIL)) {
  109. $_SESSION['error_msg'] = __('Please enter valid email address.');
  110. } else {
  111. $v_email = escapeshellarg($_POST['v_email']);
  112. exec (VESTA_CMD."v-change-user-contact ".escapeshellarg($v_username)." ".$v_email, $output, $return_var);
  113. check_return_code($return_var,$output);
  114. unset($output);
  115. }
  116. }
  117. // Change full name
  118. if (($v_fname != $_POST['v_fname']) || ($v_lname != $_POST['v_lname']) && (empty($_SESSION['error_msg']))) {
  119. $v_fname = escapeshellarg($_POST['v_fname']);
  120. $v_lname = escapeshellarg($_POST['v_lname']);
  121. exec (VESTA_CMD."v-change-user-name ".escapeshellarg($v_username)." ".$v_fname." ".$v_lname, $output, $return_var);
  122. check_return_code($return_var,$output);
  123. unset($output);
  124. $v_fname = $_POST['v_fname'];
  125. $v_lname = $_POST['v_lname'];
  126. }
  127. // Change NameServers
  128. if (($v_ns1 != $_POST['v_ns1']) || ($v_ns2 != $_POST['v_ns2']) || ($v_ns3 != $_POST['v_ns3']) || ($v_ns4 != $_POST['v_ns4']) || ($v_ns5 != $_POST['v_ns5'])
  129. || ($v_ns6 != $_POST['v_ns6']) || ($v_ns7 != $_POST['v_ns7']) || ($v_ns8 != $_POST['v_ns8']) && (empty($_SESSION['error_msg']))) {
  130. $v_ns1 = escapeshellarg($_POST['v_ns1']);
  131. $v_ns2 = escapeshellarg($_POST['v_ns2']);
  132. $v_ns3 = escapeshellarg($_POST['v_ns3']);
  133. $v_ns4 = escapeshellarg($_POST['v_ns4']);
  134. $v_ns5 = escapeshellarg($_POST['v_ns5']);
  135. $v_ns6 = escapeshellarg($_POST['v_ns6']);
  136. $v_ns7 = escapeshellarg($_POST['v_ns7']);
  137. $v_ns8 = escapeshellarg($_POST['v_ns8']);
  138. $ns_cmd = VESTA_CMD."v-change-user-ns ".escapeshellarg($v_username)." ".$v_ns1." ".$v_ns2;
  139. if (!empty($_POST['v_ns3'])) $ns_cmd = $ns_cmd." ".$v_ns3;
  140. if (!empty($_POST['v_ns4'])) $ns_cmd = $ns_cmd." ".$v_ns4;
  141. if (!empty($_POST['v_ns5'])) $ns_cmd = $ns_cmd." ".$v_ns5;
  142. if (!empty($_POST['v_ns6'])) $ns_cmd = $ns_cmd." ".$v_ns6;
  143. if (!empty($_POST['v_ns7'])) $ns_cmd = $ns_cmd." ".$v_ns7;
  144. if (!empty($_POST['v_ns8'])) $ns_cmd = $ns_cmd." ".$v_ns8;
  145. exec ($ns_cmd, $output, $return_var);
  146. check_return_code($return_var,$output);
  147. unset($output);
  148. $v_ns1 = str_replace("'","", $v_ns1);
  149. $v_ns2 = str_replace("'","", $v_ns2);
  150. $v_ns3 = str_replace("'","", $v_ns3);
  151. $v_ns4 = str_replace("'","", $v_ns4);
  152. $v_ns5 = str_replace("'","", $v_ns5);
  153. $v_ns6 = str_replace("'","", $v_ns6);
  154. $v_ns7 = str_replace("'","", $v_ns7);
  155. $v_ns8 = str_replace("'","", $v_ns8);
  156. }
  157. // Set success message
  158. if (empty($_SESSION['error_msg'])) {
  159. $_SESSION['ok_msg'] = __('Changes has been saved.');
  160. }
  161. }
  162. $result = array(
  163. 'password' => '',
  164. 'email' => $data[$v_username]['CONTACT'],
  165. 'package' => $data[$v_username]['PACKAGE'],
  166. 'language' => $data[$v_username]['LANGUAGE'],
  167. 'fname' => $data[$v_username]['FNAME'],
  168. 'lname' => $data[$v_username]['LNAME'],
  169. 'shell' => $data[$v_username]['SHELL'],
  170. 'nameservers' => $nameservers,
  171. 'ns1' => $nameservers[0],
  172. 'ns2' => $nameservers[1],
  173. 'ns3' => $nameservers[2],
  174. 'ns4' => $nameservers[3],
  175. 'ns5' => $nameservers[4],
  176. 'ns6' => $nameservers[5],
  177. 'ns7' => $nameservers[6],
  178. 'ns8' => $nameservers[7],
  179. 'suspended' => $data[$v_username]['SUSPENDED'],
  180. 'status' => $v_status,
  181. 'time' => $data[$v_username]['TIME'],
  182. 'date' => $data[$v_username]['DATE'],
  183. 'error_msg' => $_SESSION['error_msg'],
  184. 'ok_msg' => $_SESSION['ok_msg'],
  185. 'packages' => $packages,
  186. 'languages' => $languages,
  187. 'shells' => $shells
  188. );
  189. echo json_encode($result);
  190. // Flush session messages
  191. unset($_SESSION['error_msg']);
  192. unset($_SESSION['ok_msg']);