index.php 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188
  1. <?php
  2. // Init
  3. error_reporting(NULL);
  4. ob_start();
  5. session_start();
  6. $TAB = 'USER';
  7. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  8. // Check user argument
  9. if (empty($_GET['user'])) {
  10. header("Location: /list/user/");
  11. exit;
  12. }
  13. // Edit as someone else?
  14. if (($_SESSION['user'] == 'admin') && (!empty($_GET['user']))) {
  15. $user=$_GET['user'];
  16. $v_username=$_GET['user'];
  17. } else {
  18. $user=$_SESSION['user'];
  19. $v_username=$_SESSION['user'];
  20. }
  21. // List user
  22. exec (VESTA_CMD."v-list-user ".$v_username." json", $output, $return_var);
  23. check_return_code($return_var,$output);
  24. $data = json_decode(implode('', $output), true);
  25. unset($output);
  26. // Parse user
  27. $v_password = "";
  28. $v_email = $data[$v_username]['CONTACT'];
  29. $v_package = $data[$v_username]['PACKAGE'];
  30. $v_language = $data[$v_username]['LANGUAGE'];
  31. $v_fname = $data[$v_username]['FNAME'];
  32. $v_lname = $data[$v_username]['LNAME'];
  33. $v_shell = $data[$v_username]['SHELL'];
  34. $v_ns = $data[$v_username]['NS'];
  35. $nameservers = explode(", ", $v_ns);
  36. $v_ns1 = $nameservers[0];
  37. $v_ns2 = $nameservers[1];
  38. $v_ns3 = $nameservers[2];
  39. $v_ns4 = $nameservers[3];
  40. $v_suspended = $data[$v_username]['SUSPENDED'];
  41. if ( $v_suspended == 'yes' ) {
  42. $v_status = 'suspended';
  43. } else {
  44. $v_status = 'active';
  45. }
  46. $v_time = $data[$v_username]['TIME'];
  47. $v_date = $data[$v_username]['DATE'];
  48. // List packages
  49. exec (VESTA_CMD."v-list-user-packages json", $output, $return_var);
  50. $packages = json_decode(implode('', $output), true);
  51. unset($output);
  52. // List lanugages
  53. exec (VESTA_CMD."v-list-sys-languages json", $output, $return_var);
  54. $languages = json_decode(implode('', $output), true);
  55. unset($output);
  56. // List shells
  57. exec (VESTA_CMD."v-list-sys-shells json", $output, $return_var);
  58. $shells = json_decode(implode('', $output), true);
  59. unset($output);
  60. // Are you admin?
  61. // Check POST request
  62. if (!empty($_POST['save'])) {
  63. // Check token
  64. if ((!isset($_POST['token'])) || ($_SESSION['token'] != $_POST['token'])) {
  65. header('location: /login/');
  66. exit();
  67. }
  68. // Change password
  69. if ((!empty($_POST['v_password'])) && (empty($_SESSION['error_msg']))) {
  70. $v_password = tempnam("/tmp","vst");
  71. $fp = fopen($v_password, "w");
  72. fwrite($fp, $_POST['v_password']."\n");
  73. fclose($fp);
  74. exec (VESTA_CMD."v-change-user-password ".$v_username." ".$v_password, $output, $return_var);
  75. check_return_code($return_var,$output);
  76. unset($output);
  77. unlink($v_password);
  78. $v_password = escapeshellarg($_POST['v_password']);
  79. }
  80. // Change package (admin only)
  81. if (($v_package != $_POST['v_package']) && ($_SESSION['user'] == 'admin') && (empty($_SESSION['error_msg']))) {
  82. $v_package = escapeshellarg($_POST['v_package']);
  83. exec (VESTA_CMD."v-change-user-package ".$v_username." ".$v_package, $output, $return_var);
  84. check_return_code($return_var,$output);
  85. unset($output);
  86. }
  87. // Change language
  88. if (($v_language != $_POST['v_language']) && (empty($_SESSION['error_msg']))) {
  89. $v_language = escapeshellarg($_POST['v_language']);
  90. exec (VESTA_CMD."v-change-user-language ".$v_username." ".$v_language, $output, $return_var);
  91. check_return_code($return_var,$output);
  92. if (empty($_SESSION['error_msg'])) {
  93. if ((empty($_GET['user'])) || ($_GET['user'] == $_SESSION['user'])) $_SESSION['language'] = $_POST['v_language'];
  94. }
  95. unset($output);
  96. }
  97. // Change shell (admin only)
  98. if (($v_shell != $_POST['v_shell']) && ($_SESSION['user'] == 'admin') && (empty($_SESSION['error_msg']))) {
  99. $v_shell = escapeshellarg($_POST['v_shell']);
  100. exec (VESTA_CMD."v-change-user-shell ".$v_username." ".$v_shell, $output, $return_var);
  101. check_return_code($return_var,$output);
  102. unset($output);
  103. }
  104. // Change contact email
  105. if (($v_email != $_POST['v_email']) && (empty($_SESSION['error_msg']))) {
  106. if (!filter_var($_POST['v_email'], FILTER_VALIDATE_EMAIL)) {
  107. $_SESSION['error_msg'] = __('Please enter valid email address.');
  108. } else {
  109. $v_email = escapeshellarg($_POST['v_email']);
  110. exec (VESTA_CMD."v-change-user-contact ".$v_username." ".$v_email, $output, $return_var);
  111. check_return_code($return_var,$output);
  112. unset($output);
  113. }
  114. }
  115. // Change full name
  116. if (($v_fname != $_POST['v_fname']) || ($v_lname != $_POST['v_lname']) && (empty($_SESSION['error_msg']))) {
  117. $v_fname = escapeshellarg($_POST['v_fname']);
  118. $v_lname = escapeshellarg($_POST['v_lname']);
  119. exec (VESTA_CMD."v-change-user-name ".$v_username." ".$v_fname." ".$v_lname, $output, $return_var);
  120. check_return_code($return_var,$output);
  121. unset($output);
  122. $v_fname = $_POST['v_fname'];
  123. $v_lname = $_POST['v_lname'];
  124. }
  125. // Change NameServers
  126. if (($v_ns1 != $_POST['v_ns1']) || ($v_ns2 != $_POST['v_ns2']) || ($v_ns3 != $_POST['v_ns3']) || ($v_ns4 != $_POST['v_ns4']) && (empty($_SESSION['error_msg']))) {
  127. $v_ns1 = escapeshellarg($_POST['v_ns1']);
  128. $v_ns2 = escapeshellarg($_POST['v_ns2']);
  129. $v_ns3 = escapeshellarg($_POST['v_ns3']);
  130. $v_ns4 = escapeshellarg($_POST['v_ns4']);
  131. $ns_cmd = VESTA_CMD."v-change-user-ns ".$v_username." ".$v_ns1." ".$v_ns2;
  132. if (!empty($_POST['v_ns3'])) $ns_cmd = $ns_cmd." ".$v_ns3;
  133. if (!empty($_POST['v_ns4'])) $ns_cmd = $ns_cmd." ".$v_ns4;
  134. exec ($ns_cmd, $output, $return_var);
  135. check_return_code($return_var,$output);
  136. unset($output);
  137. }
  138. // Set success message
  139. if (empty($_SESSION['error_msg'])) {
  140. $_SESSION['ok_msg'] = __('Changes has been saved.');
  141. }
  142. }
  143. // Header
  144. include($_SERVER['DOCUMENT_ROOT'].'/templates/header.html');
  145. // Panel
  146. if (!empty($_SESSION['look'])) {
  147. top_panel($user,$TAB);
  148. } else {
  149. top_panel($_SESSION['user'],$TAB);
  150. }
  151. // Display body
  152. if ($_SESSION['user'] == 'admin') {
  153. include($_SERVER['DOCUMENT_ROOT'].'/templates/admin/edit_user.html');
  154. } else {
  155. include($_SERVER['DOCUMENT_ROOT'].'/templates/user/edit_user.html');
  156. }
  157. // Flush session messages
  158. unset($_SESSION['error_msg']);
  159. unset($_SESSION['ok_msg']);
  160. // Footer
  161. include($_SERVER['DOCUMENT_ROOT'].'/templates/footer.html');