index.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353
  1. <?php
  2. // Init
  3. error_reporting(NULL);
  4. ob_start();
  5. session_start();
  6. $TAB = 'WEB';
  7. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  8. // Check POST request
  9. if (!empty($_POST['ok'])) {
  10. // Check for empty fields
  11. if (empty($_POST['v_domain'])) $errors[] = __('domain');
  12. if (empty($_POST['v_ip'])) $errors[] = __('ip');
  13. if ((!empty($_POST['v_ssl'])) && (empty($_POST['v_ssl_crt']))) $errors[] = __('ssl certificate');
  14. if ((!empty($_POST['v_ssl'])) && (empty($_POST['v_ssl_key']))) $errors[] = __('ssl key');
  15. if (!empty($errors[0])) {
  16. foreach ($errors as $i => $error) {
  17. if ( $i == 0 ) {
  18. $error_msg = $error;
  19. } else {
  20. $error_msg = $error_msg.", ".$error;
  21. }
  22. }
  23. $_SESSION['error_msg'] = __('Field "%s" can not be blank.',$error_msg);
  24. }
  25. // Check stats password length
  26. if ((!empty($v_stats)) && (empty($_SESSION['error_msg']))) {
  27. if (!empty($_POST['v_stats_user'])) {
  28. $pw_len = strlen($_POST['v_stats_password']);
  29. if ($pw_len < 6 ) $_SESSION['error_msg'] = __('Password is too short.',$error_msg);
  30. }
  31. }
  32. // Default proxy extention list
  33. $v_proxy_ext = 'jpeg, jpg, png, gif, bmp, ico, svg, tif, tiff, css, js, htm, html, ttf, ';
  34. $v_proxy_ext .= 'otf, webp, woff, txt, csv, rtf, doc, docx, xls, xlsx, ppt, pptx, odf, ';
  35. $v_proxy_ext .= 'odp, ods, odt, pdf, psd, ai, eot, eps, ps, zip, tar, tgz, gz, rar, ';
  36. $v_proxy_ext .= 'bz2, 7z, aac, m4a, mp3, mp4, ogg, wav, wma, 3gp, avi, flv, m4v, mkv, ';
  37. $v_proxy_ext .= 'mov, mp4, mpeg, mpg, wmv, exe, iso, dmg, swf';
  38. // Set advanced option checkmark
  39. if (empty($_POST['v_proxy'])) $v_adv = 'yes';
  40. if (!empty($_POST['v_ftp'])) $v_adv = 'yes';
  41. if ($_POST['v_proxy_ext'] != $v_proxy_ext) $v_adv = 'yes';
  42. // Set domain name to lowercase and remove www prefix
  43. $v_domain = preg_replace("/^www\./i", "", $_POST['v_domain']);
  44. $v_domain = escapeshellarg($v_domain);
  45. $v_domain = strtolower($v_domain);
  46. // Prepare domain values
  47. $v_ip = escapeshellarg($_POST['v_ip']);
  48. if ((!empty($_POST['v_aliases'])) && ($_POST['v_aliases'] != 'www.'.$_POST['v_domain'])) $v_adv = 'yes';
  49. if ((!empty($_POST['v_ssl'])) || (!empty($_POST['v_elog']))) $v_adv = 'yes';
  50. if ((!empty($_POST['v_ssl_crt'])) || (!empty($_POST['v_ssl_key']))) $v_adv = 'yes';
  51. if ((!empty($_POST['v_ssl_ca'])) || ($_POST['v_stats'] != 'none')) $v_adv = 'yes';
  52. if (!empty($v_domain)) $v_ftp_user_prepath .= $v_domain;
  53. if (empty($_POST['v_dns'])) $v_dns = 'off';
  54. if (empty($_POST['v_mail'])) $v_mail = 'off';
  55. if (empty($_POST['v_proxy'])) $v_proxy = 'off';
  56. $v_aliases = $_POST['v_aliases'];
  57. $v_elog = $_POST['v_elog'];
  58. $v_ssl = $_POST['v_ssl'];
  59. $v_ssl_crt = $_POST['v_ssl_crt'];
  60. $v_ssl_key = $_POST['v_ssl_key'];
  61. $v_ssl_ca = $_POST['v_ssl_ca'];
  62. $v_ssl_home = $data[$v_domain]['SSL_HOME'];
  63. $v_stats = escapeshellarg($_POST['v_stats']);
  64. $v_stats_user = $data[$v_domain]['STATS_USER'];
  65. $v_stats_password = $data[$v_domain]['STATS_PASSWORD'];
  66. $v_proxy_ext = preg_replace("/\n/", " ", $_POST['v_proxy_ext']);
  67. $v_proxy_ext = preg_replace("/,/", " ", $v_proxy_ext);
  68. $v_proxy_ext = preg_replace('/\s+/', ' ',$v_proxy_ext);
  69. $v_proxy_ext = trim($v_proxy_ext);
  70. $v_proxy_ext = str_replace(' ', ", ", $v_proxy_ext);
  71. $v_ftp = $_POST['v_ftp'];
  72. $v_ftp_user = $_POST['v_ftp_user'];
  73. $v_ftp_password = $_POST['v_ftp_password'];
  74. $v_ftp_email = $_POST['v_ftp_email'];
  75. // Add web domain
  76. if (empty($_SESSION['error_msg'])) {
  77. exec (VESTA_CMD."v-add-web-domain ".$user." ".$v_domain." ".$v_ip." 'no'", $output, $return_var);
  78. check_return_code($return_var,$output);
  79. unset($output);
  80. $domain_added = empty($_SESSION['error_msg']);
  81. }
  82. // Add DNS domain
  83. if (($_POST['v_dns'] == 'on') && (empty($_SESSION['error_msg']))) {
  84. exec (VESTA_CMD."v-add-dns-domain ".$user." ".$v_domain." ".$v_ip, $output, $return_var);
  85. check_return_code($return_var,$output);
  86. unset($output);
  87. }
  88. // Add mail domain
  89. if (($_POST['v_mail'] == 'on') && (empty($_SESSION['error_msg']))) {
  90. exec (VESTA_CMD."v-add-mail-domain ".$user." ".$v_domain, $output, $return_var);
  91. check_return_code($return_var,$output);
  92. unset($output);
  93. }
  94. // Add domain aliases
  95. if ((!empty($_POST['v_aliases'])) && (empty($_SESSION['error_msg']))) {
  96. $valiases = preg_replace("/\n/", " ", $_POST['v_aliases']);
  97. $valiases = preg_replace("/,/", " ", $valiases);
  98. $valiases = preg_replace('/\s+/', ' ',$valiases);
  99. $valiases = trim($valiases);
  100. $aliases = explode(" ", $valiases);
  101. foreach ($aliases as $alias) {
  102. if ($alias == 'www.'.$_POST['v_domain']) {
  103. $www_alias = 'yes';
  104. } else {
  105. $alias = escapeshellarg($alias);
  106. if (empty($_SESSION['error_msg'])) {
  107. exec (VESTA_CMD."v-add-web-domain-alias ".$user." ".$v_domain." ".$alias." 'no'", $output, $return_var);
  108. check_return_code($return_var,$output);
  109. unset($output);
  110. }
  111. if (($_POST['v_dns'] == 'on') && (empty($_SESSION['error_msg']))) {
  112. exec (VESTA_CMD."v-add-dns-on-web-alias ".$user." ".$v_domain." ".$alias." 'no'", $output, $return_var);
  113. check_return_code($return_var,$output);
  114. unset($output);
  115. }
  116. }
  117. }
  118. }
  119. // Delete www. alias if it wasn't found
  120. if ((empty($www_alias)) && (empty($_SESSION['error_msg']))) {
  121. $alias = preg_replace("/^www./i", "", $_POST['v_domain']);
  122. $alias = 'www.'.$alias;
  123. $alias = escapeshellarg($alias);
  124. exec (VESTA_CMD."v-delete-web-domain-alias ".$user." ".$v_domain." ".$alias." 'no'", $output, $return_var);
  125. check_return_code($return_var,$output);
  126. unset($output);
  127. }
  128. // Add proxy support
  129. if (($_POST['v_proxy'] == 'on') && (empty($_SESSION['error_msg']))) {
  130. $ext = str_replace(' ', '', $v_proxy_ext);
  131. $ext = escapeshellarg($ext);
  132. exec (VESTA_CMD."v-add-web-domain-proxy ".$user." ".$v_domain." '' ".$ext." 'no'", $output, $return_var);
  133. check_return_code($return_var,$output);
  134. unset($output);
  135. }
  136. // Add SSL certificates
  137. if ((!empty($_POST['v_ssl'])) && (empty($_SESSION['error_msg']))) {
  138. exec ('mktemp -d', $output, $return_var);
  139. $tmpdir = $output[0];
  140. unset($output);
  141. // Save certificate
  142. if (!empty($_POST['v_ssl_crt'])) {
  143. $fp = fopen($tmpdir."/".$_POST['v_domain'].".crt", 'w');
  144. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_crt']));
  145. fwrite($fp, "\n");
  146. fclose($fp);
  147. }
  148. // Save private key
  149. if (!empty($_POST['v_ssl_key'])) {
  150. $fp = fopen($tmpdir."/".$_POST['v_domain'].".key", 'w');
  151. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_key']));
  152. fwrite($fp, "\n");
  153. fclose($fp);
  154. }
  155. // Save CA bundle
  156. if (!empty($_POST['v_ssl_ca'])) {
  157. $fp = fopen($tmpdir."/".$_POST['v_domain'].".ca", 'w');
  158. fwrite($fp, str_replace("\r\n", "\n", $_POST['v_ssl_ca']));
  159. fwrite($fp, "\n");
  160. fclose($fp);
  161. }
  162. $v_ssl_home = escapeshellarg($_POST['v_ssl_home']);
  163. exec (VESTA_CMD."v-add-web-domain-ssl ".$user." ".$v_domain." ".$tmpdir." ".$v_ssl_home." 'no'", $output, $return_var);
  164. check_return_code($return_var,$output);
  165. unset($output);
  166. }
  167. // Add web stats
  168. if ((!empty($_POST['v_stats'])) && ($_POST['v_stats'] != 'none' ) && (empty($_SESSION['error_msg']))) {
  169. $v_stats = escapeshellarg($_POST['v_stats']);
  170. exec (VESTA_CMD."v-add-web-domain-stats ".$user." ".$v_domain." ".$v_stats, $output, $return_var);
  171. check_return_code($return_var,$output);
  172. unset($output);
  173. }
  174. // Add web stats password
  175. if ((!empty($_POST['v_stats_user'])) && (empty($_SESSION['error_msg']))) {
  176. $v_stats_user = escapeshellarg($_POST['v_stats_user']);
  177. $v_stats_password = escapeshellarg($_POST['v_stats_password']);
  178. exec (VESTA_CMD."v-add-web-domain-stats-user ".$user." ".$v_domain." ".$v_stats_user." ".$v_stats_password, $output, $return_var);
  179. check_return_code($return_var,$output);
  180. unset($output);
  181. }
  182. // Restart DNS server
  183. if (($_POST['v_dns'] == 'on') && (empty($_SESSION['error_msg']))) {
  184. exec (VESTA_CMD."v-restart-dns", $output, $return_var);
  185. check_return_code($return_var,$output);
  186. unset($output);
  187. }
  188. // Restart web server
  189. if (empty($_SESSION['error_msg'])) {
  190. exec (VESTA_CMD."v-restart-web", $output, $return_var);
  191. check_return_code($return_var,$output);
  192. unset($output);
  193. }
  194. // Restart proxy server
  195. if (($_POST['v_proxy'] == 'on') && (empty($_SESSION['error_msg']))) {
  196. exec (VESTA_CMD."v-restart-proxy", $output, $return_var);
  197. check_return_code($return_var,$output);
  198. unset($output);
  199. }
  200. // Add FTP
  201. if ((!empty($_POST['v_ftp'])) && (empty($_SESSION['error_msg']))) {
  202. $v_ftp_users_updated = array();
  203. foreach ($_POST['v_ftp_user'] as $i => $v_ftp_user_data) {
  204. if ($v_ftp_user_data['is_new'] == 1) {
  205. if ((!empty($v_ftp_user_data['v_ftp_email'])) && (!filter_var($v_ftp_user_data['v_ftp_email'], FILTER_VALIDATE_EMAIL))) $_SESSION['error_msg'] = __('Please enter valid email address.');
  206. if (empty($v_ftp_user_data['v_ftp_user'])) $errors[] = 'ftp user';
  207. if (empty($v_ftp_user_data['v_ftp_password'])) $errors[] = 'ftp user password';
  208. if (!empty($errors[0])) {
  209. foreach ($errors as $i => $error) {
  210. if ( $i == 0 ) {
  211. $error_msg = $error;
  212. } else {
  213. $error_msg = $error_msg.", ".$error;
  214. }
  215. }
  216. $_SESSION['error_msg'] = __('Field "%s" can not be blank.',$error_msg);
  217. }
  218. // Validate email
  219. if ((!empty($v_ftp_user_data['v_ftp_email'])) && (!filter_var($v_ftp_user_data['v_ftp_email'], FILTER_VALIDATE_EMAIL))) {
  220. $_SESSION['error_msg'] = __('Please enter valid email address.');
  221. }
  222. // Check ftp password length
  223. if ((!empty($v_ftp_user_data['v_ftp']))) {
  224. if (!empty($v_ftp_user_data['v_ftp_user'])) {
  225. $pw_len = strlen($v_ftp_user_data['v_ftp_password']);
  226. if ($pw_len < 6 ) $_SESSION['error_msg'] = __('Password is too short.',$error_msg);
  227. }
  228. }
  229. $v_ftp_user_data['v_ftp_user'] = preg_replace("/^".$user."_/i", "", $v_ftp_user_data['v_ftp_user']);
  230. $v_ftp_username = $v_ftp_user_data['v_ftp_user'];
  231. $v_ftp_username_full = $user . '_' . $v_ftp_user_data['v_ftp_user'];
  232. $v_ftp_user = escapeshellarg($v_ftp_user_data['v_ftp_user']);
  233. $v_ftp_password = escapeshellarg($v_ftp_user_data['v_ftp_password']);
  234. if ($domain_added) {
  235. exec (VESTA_CMD."v-add-web-domain-ftp ".$user." ".$v_domain." ".$v_ftp_username." ".$v_ftp_password . " " . $v_ftp_user_data['v_ftp_path'], $output, $return_var);
  236. check_return_code($return_var,$output);
  237. unset($output);
  238. if ((!empty($v_ftp_user_data['v_ftp_email'])) && (empty($_SESSION['error_msg']))) {
  239. $to = $v_ftp_user_data['v_ftp_email'];
  240. $subject = __("FTP login credentials");
  241. $from = __('MAIL_FROM',$_POST['v_domain']);
  242. $mailtext = __('FTP_ACCOUNT_READY',$_POST['v_domain'],$user,$v_ftp_user_data['v_ftp_user'],$v_ftp_user_data['v_ftp_password']);
  243. send_email($to, $subject, $mailtext, $from);
  244. unset($v_ftp_email);
  245. }
  246. } else {
  247. $return_var = -1;
  248. }
  249. if ($return_var == 0) {
  250. $v_ftp_password = "••••••••";
  251. $v_ftp_user_data['is_new'] = 0;
  252. } else {
  253. $v_ftp_user_data['is_new'] = 1;
  254. }
  255. $v_ftp_username = preg_replace("/^".$user."_/", "", $v_ftp_user_data['v_ftp_user']);
  256. $v_ftp_users_updated[] = array(
  257. 'is_new' => $v_ftp_user_data['is_new'],
  258. 'v_ftp_user' => $return_var == 0 ? $v_ftp_username_full : $v_ftp_username,
  259. 'v_ftp_password' => $v_ftp_password,
  260. 'v_ftp_path' => $v_ftp_user_data['v_ftp_path'],
  261. 'v_ftp_email' => $v_ftp_user_data['v_ftp_email'],
  262. 'v_ftp_pre_path' => $v_ftp_user_prepath
  263. );
  264. continue;
  265. }
  266. }
  267. if (!empty($_SESSION['error_msg']) && $domain_added) {
  268. $_SESSION['ok_msg'] = __('WEB_DOMAIN_CREATED_OK',$_POST[v_domain],$_POST[v_domain]);
  269. $_SESSION['flash_error_msg'] = $_SESSION['error_msg'];
  270. $url = '/edit/web/?domain='.strtolower(preg_replace("/^www\./i", "", $_POST['v_domain']));
  271. header('Location: ' . $url);
  272. exit;
  273. }
  274. }
  275. // Flush field values on success
  276. if (empty($_SESSION['error_msg'])) {
  277. $_SESSION['ok_msg'] = __('WEB_DOMAIN_CREATED_OK',$_POST[v_domain],$_POST[v_domain]);
  278. unset($v_domain);
  279. unset($v_aliases);
  280. unset($v_ssl);
  281. unset($v_ssl_crt);
  282. unset($v_ssl_key);
  283. unset($v_ssl_ca);
  284. unset($v_stats_user);
  285. unset($v_stats_password);
  286. unset($v_ftp);
  287. }
  288. }
  289. // Header
  290. include($_SERVER['DOCUMENT_ROOT'].'/templates/header.html');
  291. // Panel
  292. top_panel($user,$TAB);
  293. // Define user variables
  294. $v_ftp_user_prepath = $panel[$user]['HOME'] . "/web";
  295. $v_ftp_email = $panel[$user]['CONTACT'];
  296. // List IP addresses
  297. exec (VESTA_CMD."v-list-user-ips ".$user." json", $output, $return_var);
  298. $ips = json_decode(implode('', $output), true);
  299. unset($output);
  300. // List web stat engines
  301. exec (VESTA_CMD."v-list-web-stats json", $output, $return_var);
  302. $stats = json_decode(implode('', $output), true);
  303. unset($output);
  304. // Display body
  305. include($_SERVER['DOCUMENT_ROOT'].'/templates/admin/add_web.html');
  306. // Flush session messages
  307. unset($_SESSION['error_msg']);
  308. unset($_SESSION['ok_msg']);
  309. // Footer
  310. include($_SERVER['DOCUMENT_ROOT'].'/templates/footer.html');