#Checks if $username begins by a letter and contains only letters, digits, -, _ or .
proctc2:username_isvalid{username}{
regexp{^[A-Za-z][A-Za-z0-9_\-\.]*$}$username
}
#Determines if $username exists on the system
#SECURITY: to avoid shell injection, call first tc2:username_isvalid $username
proctc2:username_exists{username}{
#TODO: Windows and other OSes (this line has been tested under FreeBSD)
if{[exec--logins-oxl$username]==""}{
return0
}{
return1
}
}
#Gets server hostname
proctc2:hostname{}{
exechostname-s
}
#Determines if $username is root
proctc2:isroot{username}{
#Validates input data
setusername[stringtolower$username]
if![tc2:username_isvalid$username]{
return0
}
#Check 1 - User has local accreditation
if![sql"SELECT count(*) FROM tc2_roots WHERE account_username = '$username' AND server_name = '[sqlescape [tc2:hostname]]'"]{
return0
}
#Check 2 - User is in the group wheel on the server
if{[lsearch[exec--id-Gn$username]wheel]=="-1"}{
return0
}{
return1
}
}
#Determines if $requester is *EXPLICITELY* allowed to allowed to manage the account $user
#When you invoke this proc, you should also check if the user is root.
# e.g. if {[tc2:isroot $requester] || [tc2:userallow $requester $user]} { ... }
proctc2:userallow{requesteruser}{
setsql"SELECT count(*) FROM tc2_users_permissions WHERE server_name = '[sqlescape [tc2:hostname]]' AND account_username = '[sqlescape $user]' AND user_id = [getuserid $user]"
putdebug$sql
sql$sql
}
#tc2:getpermissions on $username: Gets permissions on the $username account
#tc2:getpermissions from $username: Gets permissions $username have on server accounts
proctc2:getpermissions{keywordusername}{
switch$keyword{
"from"{
setsql"SELECT account_username FROM tc2_users_permissions WHERE server_name = '[sqlescape [tc2:hostname]]' AND user_id = '[getuserid $username]'"
}
"on"{
setsql"SELECT u.username FROM tc2_users_permissions p, users u WHERE p.server_name = '[sqlescape [tc2:hostname]]' AND p.account_username = '$username' AND u.user_id = p.user_id"
}
default{
error"from or on expected"
}
}
setaccounts""
foreachrow[sql$sql]{
lappendaccounts[lindex$row0]
}
}
#Creates an account $username from the $specified group
return"0 {$mandataire doesn't have a bot account, and so, no such permission.}"
}
#Checks if the permission exists
if![tc2:userallow$requester$mandataire]{
return"0 {$mandataire haven't had an access to $username account.}"
}
#Removess the permission
sql"DELETE FROM tc2_users_permissions WHERE server_name = '[sqlescape [tc2:hostname]]' AND account_username = '$username' AND user_id = '$mandataire_user_id'"
return"1 {$mandataire doesn't have access to $username account anymore.}"
}
"+root"{
#Checks right and need
if![tc2:isroot$requester]{
return"0 {you don't have root authority yourself.}"
}
if[tc2:isroot$username]{
return"0 {$username have already root authority.}"
setconfigblock[stringmap[list%REQUESTER%$requester%TIME%[unixtime]%COMMENT%"Autogenerated by $username"%FULLDOMAIN%$fulldomain%LOGDIR%$logdir%SSLDIR%$ssldir%SUBDOMAIN%$subdomain%WWWDIR%$wwwdir%PHPFPMPORT%$phpfpmport%CUSTOM-PREPHP%""%CUSTOM-PHP%""%CUSTOM%""%UPSTREAMKEYWORD%$upstream_keyword%UPSTREAMURL%$upstream_url%INDEX%$index%EXTRACONFIG%$xtra]$configblock]
#Opens or creates domain config file
if[fileexists$config]{
setfd[open$configa]
}{
#We use a also template for ou config file header
setfd[open$tpldir/vhost-header.tplr]
settemplate[read$fd]
close$fd
setfd[open$configw]
puts$fd[stringmap"%DOMAIN% $domain"$template]
flush$fd
}
#Writes new config block
puts$fd""
puts$fd$configblock
close$fd
return[list1"done, $fulldomain server block added to $config ; use .nginx reload to save"]
}
edit{
return[list1"not yet implemented, edit the file $config"]
}
}
}
return{0"usage: .nginx server add/edit domain \[options\]"}
}
""{
return{0"server add, server edit, status or reload expected"}