AccountController.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207
  1. <?php
  2. namespace application\controllers;
  3. class AccountController {
  4. public static function create($data): void {
  5. $username = $data['username'];
  6. $domain = $data['domain'];
  7. $adminName = $data['admin_name'] ?? '';
  8. $adminPassword = $data['admin_password'];
  9. if (empty($username) || empty($domain) || empty($adminName) || empty($adminPassword)) {
  10. error_log("deploy: ERROR: No username, domain, admin_name or admin_password provided");
  11. http_response_code(400);
  12. error_log("deploy: ERROR: UserName 1 " . $username);
  13. error_log("deploy: ERROR: Domain 1 " . $domain);
  14. error_log("deploy: ERROR: UserName 2 " . $data['username'] );
  15. error_log("deploy: ERROR: Domain 2 " . $data['domain'] );
  16. error_log("deploy: ERROR: AdminName " . $adminName);
  17. error_log("deploy: ERROR: AdminPasswd" . $adminPassword);
  18. error_log(print_r($data,true));
  19. echo json_encode(['error' => 'Missing required parameters']);
  20. return;
  21. }
  22. error_log(" Creating user " . $username . " DebugMode: " . $GLOBALS['debug']);
  23. $userExisted = false;
  24. if( strpos(file_get_contents("/etc/passwd"),$username) !== false) {
  25. $userExisted = true;
  26. }
  27. if ($userExisted != true) {
  28. // Create user without login access
  29. if ($GLOBALS['debug'] == true) {error_log("Adding User: " . $username); }
  30. exec("sudo /usr/sbin/useradd -m -k -M -s /usr/sbin/nologin $username 2>&1", $userOutput, $userReturnCode);
  31. if ($userReturnCode !== 0) {
  32. error_log("deploy: ERROR: Useradd for $username failed, details => " . implode("\n", $userOutput));
  33. http_response_code(500);
  34. echo json_encode(['error' => 'Failed to create user', 'details' => implode("\n", $userOutput)]);
  35. return;
  36. }
  37. }
  38. if ($GLOBALS['debug'] == true) { error_log("Creating Webdir ($webDir) for : " . $username); }
  39. exec("sudo /usr/bin/mkdir -p $webDir 2>&1", $mkdirOutput, $mkdirReturnCode);
  40. if ($mkdirReturnCode !== 0) {
  41. error_log("deploy: ERROR: Create Webdir for $username failed, details => ". implode("\n", $mkdirOutput));
  42. http_response_code(500);
  43. echo json_encode(['error' => 'Failed to create web dir', 'details' => implode("\n", $mkdirOutput)]);
  44. return;
  45. }
  46. if ($GLOBALS['debug'] == true) { error_log("Install Placeholder on : " . $webDir); }
  47. exec("sudo /usr/bin/cp -rf $placeholderdir/* $webdir/. 2>&1", $mkdirOutput, $cpReturnCode);
  48. if ($cpReturnCode !== 0) {
  49. error_log("deploy: ERROR: Copy placeholder for $username failed, details => ". implode("\n", $mkdirOutput));
  50. http_response_code(500);
  51. echo json_encode(['error' => 'Failed to copy placeholder', 'details' => implode("\n", $mkdirOutput)]);
  52. return;
  53. }
  54. if ($GLOBALS['debug'] == true) { error_log("Creating logdir for : " . $username); }
  55. if (is_dir("/home/$username/logs") != true) {
  56. exec("sudo /usr/bin/mkdir -p /home/$username/logs 2>&1", $mkdirOutput, $mkdirReturnCode);
  57. if ($mkdirReturnCode !== 0) {
  58. error_log("deploy: ERROR: Failed to create log directory for $username failed, details => " . implode("\n", $mkdirOutput));
  59. http_response_code(500);
  60. echo json_encode(['error' => 'Failed to create logs dir', 'details' => implode("\n", $mkdirOutput)]);
  61. return;
  62. }
  63. }
  64. if ($GLOBALS['debug'] == true) { error_log("Creating backup dir for : " . $username); }
  65. if (is_dir("/home/$username/backups") != true) {
  66. exec("sudo /usr/bin/mkdir -p /home/$username/backups 2>&1", $mkdirOutput, $mkdirReturnCode);
  67. if ($mkdirReturnCode !== 0) {
  68. error_log("deploy: ERROR: mkdir /home/$username/backups failed, details => " . implode("\n", $mkdirOutput));
  69. http_response_code(500);
  70. echo json_encode(['error' => 'Failed to create backups dir', 'details' => implode("\n", $mkdirOutput)]);
  71. return;
  72. }
  73. }
  74. if ($GLOBALS['debug'] == true) { error_log("Chown homedir: " . $username); }
  75. exec("sudo /usr/bin/chown $username:$username /home/$username -R 2>&1", $chownOutput, $chownReturnCode);
  76. if ($chownReturnCode !== 0) {
  77. error_log("deploy: ERROR: chown on /home/$username failed, details => " . implode("\n", $chownOutput));
  78. http_response_code(500);
  79. echo json_encode(['error' => 'Failed to chown backups dir', 'details' => implode("\n", $chownOutput)]);
  80. return;
  81. }
  82. if ($GLOBALS['debug'] == true) { error_log("Reading Apache Config Template /etc/apache2/site-config.in"); }
  83. $configContent = file_get_contents($configTemplate);
  84. if ($GLOBALS['debug'] == true) { error_log("Replace config settings in Apache Config Template"); }
  85. $configContent = str_replace(['DOCUMENTROOT', 'SERVERNAME','USERNAME', 'DOMAINNAME', 'SERVERALIAS'], [$webDir, $domain, $username, $domain, "" ], $configContent);
  86. if ($GLOBALS['debug'] == true) { error_log("Running Certbot for Domain " . $domain); }
  87. exec("sudo /usr/bin/certbot certonly --webroot -w /etc/apache2/letsencrypt -d $domain --non-interactive --agree-tos --email admin@$domain 2>&1", $output, $returnCode);
  88. if ($returnCode !== 0) {
  89. error_log("deploy: ERROR: certbot failed to create certificate on $domain, details => " . implode("\n", $output));
  90. http_response_code(500);
  91. echo json_encode(['error' => 'Certbot failed', 'details' => implode("\n", $output)]);
  92. return;
  93. }
  94. if ($GLOBALS['debug'] == true) { error_log("Replace sslsettings in in Apache Config Template"); }
  95. $configContent = str_replace('DOMAINNAME', $domain, $configContent);
  96. if ($GLOBALS['debug'] == true) { error_log("Writing apache config file to " . $configFile); }
  97. if (file_put_contents($configFile, $configContent) != true) {
  98. error_log("deploy: ERROR: while writing apache config");
  99. echo json_encode(['error' => 'Failed to write Apache config', 'details' => []]);
  100. }
  101. exec('sudo /usr/bin/systemctl reload apache2 2>&1', $apacheOutput, $apacheReturnCode);
  102. if ($GLOBALS['debug'] == true) { error_log("Restarting Apache"); }
  103. if ($apacheReturnCode !== 0) {
  104. error_log("deploy: ERROR: Apache Reload error, details => " . implode("\n", $apacheOutput));
  105. http_response_code(500);
  106. echo json_encode(['error' => 'Failed to reload Apache', 'details' => implode("\n", $apacheOutput)]);
  107. return;
  108. }
  109. // Create PHP-FPM User
  110. // /etc/php/8.2/fpm/user.in
  111. if ($userExisted != true) {
  112. if ($GLOBALS['debug'] == true) {error_log("Writing PHP-FPM Config for : " . $username); }
  113. $phpContent = file_get_contents("/etc/php/8.2/fpm/user.in");
  114. $phpContent = str_replace("USERNAME", $username, $phpContent);
  115. file_put_contents("/etc/php/8.2/fpm/pool.d/" . $username . ".conf", $phpContent);
  116. if ($GLOBALS['debug'] == true) {error_log("Restarting PHP-FPM : " . $username);}
  117. exec('sudo /usr/bin/systemctl reload php8.2-fpm', $phpOutput, $phpReturnCode);
  118. if ($phpReturnCode !== 0) {
  119. error_log("deploy: ERROR: PHP-FPM reload error, details => " . implode("\n", $phpOutput));
  120. http_response_code(500);
  121. echo json_encode(['error' => 'Failed to reload PHP-FPM', 'details' => implode("\n", $phpOutput)]);
  122. return;
  123. }
  124. }
  125. echo json_encode(['success' => 'User crreation successfully','details' => '']);
  126. }
  127. public static function terminate($data): void {
  128. $username = $data['username'] ?? '';
  129. $domain = $data['domain'] ?? '';
  130. if (empty($username)) {
  131. error_log("terminate: ERROR: No username provided");
  132. http_response_code(400);
  133. error_log(print_r($data,true));
  134. echo json_encode(['error' => 'Missing username']);
  135. return;
  136. }
  137. if( strpos(file_get_contents("/etc/passwd"),$username) == false) {
  138. error_log("terminate: ERROR: User $username does not exist");
  139. http_response_code(400);
  140. error_log(print_r($data,true));
  141. echo json_encode(['error' => 'Unknown user']);
  142. return;
  143. }
  144. // remove PHP-FPM User
  145. if ($GLOBALS['debug'] == true) {error_log("Removing PHP-FPM Config for : " . $username); }
  146. $configName = "/etc/php/8.2/fpm/pool.d/" . $username . ".conf";
  147. exec("sudo /usr/bin/rm -f $configName 2>&1", $userOutput, $userReturnCode);
  148. if ($GLOBALS['debug'] == true) {error_log("Restarting PHP-FPM : " . $username);}
  149. exec('sudo /usr/bin/systemctl reload php8.2-fpm', $phpOutput, $phpReturnCode);
  150. if ($phpReturnCode !== 0) {
  151. error_log("deploy: ERROR: PHP-FPM reload error, details => " . implode("\n", $phpOutput));
  152. http_response_code(500);
  153. echo json_encode(['error' => 'Failed to reload PHP-FPM', 'details' => implode("\n", $phpOutput)]);
  154. return;
  155. }
  156. if(!empty($domain)) {
  157. $configFile = "/etc/apache2/sites-enabled/$domain.conf";
  158. if ($GLOBALS['debug'] == true) { error_log("Remove config of user : " . $username); }
  159. exec("sudo /usr/bin/rm -f $configFile 2>&1", $userOutput, $userReturnCode);
  160. exec("sudo /usr/bin/certbot delete --cert-name $domain --non-interactive 2>&1", $output, $returnCode);
  161. if ($returnCode !== 0) {
  162. error_log("deploy: ERROR: certbot failed to delete certificate on $domain, details => " . implode("\n", $output));
  163. http_response_code(500);
  164. echo json_encode(['error' => 'Certbot failed', 'details' => implode("\n", $output)]);
  165. return;
  166. }
  167. exec('sudo /usr/bin/systemctl reload apache2 2>&1', $apacheOutput, $apacheReturnCode);
  168. if ($GLOBALS['debug'] == true) { error_log("Restarting Apache"); }
  169. if ($apacheReturnCode !== 0) {
  170. error_log("deploy: ERROR: Apache Reload error, details => " . implode("\n", $apacheOutput));
  171. http_response_code(500);
  172. echo json_encode(['error' => 'Failed to reload Apache', 'details' => implode("\n", $apacheOutput)]);
  173. return;
  174. }
  175. }
  176. // Remove user and files
  177. if ($GLOBALS['debug'] == true) {error_log("Remove User: " . $username); }
  178. exec("sudo /usr/sbin/userdel -r -f $username 2>&1", $userOutput, $userReturnCode);
  179. if ($userReturnCode !== 0) {
  180. error_log("deploy: ERROR: Userdel for $username failed, details => " . implode("\n", $userOutput));
  181. http_response_code(500);
  182. echo json_encode(['error' => 'Failed to remove user', 'details' => implode("\n", $userOutput)]);
  183. return;
  184. }
  185. echo json_encode(['success' => 'Removing user ' . $username . ' successfully']);
  186. }
  187. }