diff --git a/documentation/etc/pure-ftpd/db/mysql.conf b/documentation/etc/pure-ftpd/db/mysql.conf index d89a605..9498a08 100644 --- a/documentation/etc/pure-ftpd/db/mysql.conf +++ b/documentation/etc/pure-ftpd/db/mysql.conf @@ -1,44 +1,44 @@ ############################################################### # # # Pure-FTPd Mysql configuration file suitable # # for boz-libre-hosting-panel. # # # # https://github.com/valerio-bozzolan/boz-libre-hosting-panel # # See README.MySQL for generic explanations. # # # ############################################################### MYSQLSocket /var/run/mysqld/mysqld.sock # www-data 33 MYSQLDefaultUID 33 MYSQLDefaultGID 33 -MYSQLUser YOUR_MYSQL_USERNAME -MYSQLPassword YOUR_MYSQL_PASSWORD -MYSQLDatabase YOUR_MYSQL_DATABASE_NAME -MYSQLCrypt md5 +MYSQLUser {$YOUR_MYSQL_USERNAME} +MYSQLPassword {$YOUR_MYSQL_PASSWORD} +MYSQLDatabase {$YOUR_MYSQL_DATABASE_NAME} # Please do not fight about that above crypt algorithm. # If you can't keep your database safe and distant from lamers your are an idiot, # and a stronger encryption will not save you from being an idiot. # Oh, obviously this software is a Free as in freedom software, so you can just change # this before using in production. Actually it's not important what damn crypt algo you use. # -- Valerio Bozzolan, Thu Mar 7 16:33:47 CET 2019 +MYSQLCrypt md5 # The ftp_directory can be manipulated by the user and so is sanitized removing ".." just in case your DB is compromised # If the user does not fill it with a trailing slash, it will be "/home/www-data/vhosts/domain.com//" that it's OK by the filesystem # -- Valerio, 15 Dec 2018 -MYSQLGetPW SELECT ftp_password FROM aw34w3_ftp AS ftp, aw34w3_domain AS domain WHERE ftp.domain_ID = domain.domain_ID AND domain_active = 1 AND ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 -MYSQLGetDir SELECT CONCAT("/home/www-data/vhosts/", domain_name, "/", REPLACE( ftp_directory, "..", "" )) FROM aw34w3_ftp as ftp, aw34w3_domain as domain WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") AND ftp.domain_ID=domain.domain_ID AND domain_active=1 LIMIT 1 -MySQLGetBandwidthUL SELECT ftp_ulbandwidth FROM aw34w3_ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 -MySQLGetBandwidthDL SELECT ftp_dlbandwidth FROM aw34w3_ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 -MySQLGetQTASZ SELECT ftp_quotasize FROM aw34w3_ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 -MySQLGetQTAFS SELECT ftp_quotafiles FROM aw34w3_ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 +MYSQLGetPW SELECT ftp_password FROM {$YOUR_DATABASE_PREFIX}ftp AS ftp, {$YOUR_DATABASE_PREFIX}domain AS domain WHERE ftp.domain_ID = domain.domain_ID AND domain_active = 1 AND ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 +MYSQLGetDir SELECT CONCAT("{$YOUR_VIRTUALHOSTS_PATH}/", domain_name, "/", REPLACE( ftp_directory, "..", "" )) FROM {$YOUR_DATABASE_PREFIX}ftp as ftp, {$YOUR_DATABASE_PREFIX}domain as domain WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") AND ftp.domain_ID=domain.domain_ID AND domain_active=1 LIMIT 1 +MySQLGetBandwidthUL SELECT ftp_ulbandwidth FROM {$YOUR_DATABASE_PREFIX}ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 +MySQLGetBandwidthDL SELECT ftp_dlbandwidth FROM {$YOUR_DATABASE_PREFIX}ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 +MySQLGetQTASZ SELECT ftp_quotasize FROM {$YOUR_DATABASE_PREFIX}ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 +MySQLGetQTAFS SELECT ftp_quotafiles FROM {$YOUR_DATABASE_PREFIX}ftp WHERE ftp_login="\L" AND ftp_active=1 AND (ftp_ipaccess="*" OR ftp_ipaccess LIKE "\R") LIMIT 1 # TODO: # PureFTPd with MySQL is so stupid if it runs 6 queries to obtain 6 columns. Some day I will fork it. # -- Valerio Bozzolan, Thu Mar 7 16:33:47 CET 2019 # When you modify this file, run: # service pure-ftpd-mysql restart diff --git a/load-post.php b/load-post.php index e6283f8..125b8e7 100644 --- a/load-post.php +++ b/load-post.php @@ -1,129 +1,129 @@ . /** * This is your versioned configuration file * * It does not contains secrets. * * This file is required after loading your * unversioned configuration file: * * load.php */ // database version // // you can increase your database version if you added some patches in: // documentation/database/patches -define( 'DATABASE_VERSION', 2 ); +define( 'DATABASE_VERSION', 3 ); // include path define_default( 'INCLUDE_PATH', ABSPATH . __ . 'include' ); // template path define_default( 'TEMPLATE_PATH', ABSPATH . __ . 'template' ); // autoload classes from the /include directory spl_autoload_register( function( $name ) { // TODO: autoload classes and create DomainTrait and use in Mailbox $path = INCLUDE_PATH . __ . "class-$name.php"; if( is_file( $path ) ) { require $path; } } ); // override default user class define( 'SESSIONUSER_CLASS', 'User' ); // load common functions require INCLUDE_PATH . __ . 'functions.php'; // jquery URL // provided by the libjs-jquery package as default define_default( 'JQUERY_URL', '/javascript/jquery/jquery.min.js' ); // Bootstrap CSS/JavaScript files without trailing slash // provided by the libjs-bootstrap package as default define_default( 'BOOTSTRAP_DIR_URL', '/javascript/bootstrap' ); // path to the Net SMTP class // provided by the php-net-smtp package as default define_default( 'NET_SMTP', '/usr/share/php/Net/SMTP.php' ); // base directory for your virtualhosts // e.g. you may have /var/www/example.com/index.html // do NOT end with a slash // TODO: support multiple hosts define_default( 'VIRTUALHOSTS_DIR', '/var/www' ); // default currency simbol define_default( 'DEFAULT_CURRENCY_SYMBOL', '€' ); // register JavaScript/CSS files register_js( 'jquery', JQUERY_URL ); register_js( 'bootstrap', BOOTSTRAP_DIR_URL . '/js/bootstrap.min.js' ); register_css( 'bootstrap', BOOTSTRAP_DIR_URL . '/css/bootstrap.min.css' ); register_css( 'custom-css', ROOT . '/content/style.css' ); // GNU Gettext i18n define( 'GETTEXT_DOMAIN', 'reyboz-hosting-panel' ); define( 'GETTEXT_DIRECTORY', 'l10n' ); define( 'GETTEXT_DEFAULT_ENCODE', CHARSET ); // UTF-8 // common strings define_default( 'SITE_NAME', "KISS Libre Hosting Panel" ); define_default( 'CONTACT_EMAIL', 'support@' . DOMAIN ); define_default( 'REPO_URL', 'https://gitpull.it/project/profile/15/' ); // limit session duration to 5 minutes (60s * 100m) define_default( 'SESSION_DURATION', 6000 ); /** * Mailbox base path * * Used by CLI scripts to calculate the current quotas. * * The mailboxes should have paths like: * MAILBOX_BASE_PATH/domain_name/user_name/ */ define_default( 'MAILBOX_BASE_PATH', '/home/vmail' ); // register web pages add_menu_entries( [ new MenuEntry( 'index', '/', __( "Dashboard" ), null, 'backend' ), new MenuEntry( 'login', 'login.php', __( "Login" ) ), new MenuEntry( 'profile', 'profile.php', __( "Profile" ) ), new MenuEntry( 'logout', 'logout.php', __( "Logout" ), null, 'read' ), new MenuEntry( 'user-list', 'user-list.php', __( "Users" ), null, 'edit-user-all' ), new MenuEntry( 'password-reset', 'password-reset.php', __( "Password reset" ) ), ] ); // permissions of a normal user register_permissions( 'user', [ 'read', 'backend', ] ); // permissions of an admin inherit_permissions( 'admin', 'user', [ 'edit-user-all', 'edit-email-all', 'edit-domain-all', 'edit-plan-all', 'edit-ftp-all', ] );