AccountController.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208
  1. <?php
  2. namespace application\controllers;
  3. class AccountController {
  4. public static function create($data): void {
  5. $username = $data['username'];
  6. $domain = $data['domain'];
  7. $adminName = $data['admin_name'] ?? '';
  8. $adminPassword = $data['admin_password'];
  9. $webDir = "/home/$username/dev.$domain";
  10. if (empty($username) || empty($domain) || empty($adminName) || empty($adminPassword)) {
  11. error_log("deploy: ERROR: No username, domain, admin_name or admin_password provided");
  12. http_response_code(400);
  13. error_log("deploy: ERROR: UserName 1 " . $username);
  14. error_log("deploy: ERROR: Domain 1 " . $domain);
  15. error_log("deploy: ERROR: UserName 2 " . $data['username'] );
  16. error_log("deploy: ERROR: Domain 2 " . $data['domain'] );
  17. error_log("deploy: ERROR: AdminName " . $adminName);
  18. error_log("deploy: ERROR: AdminPasswd" . $adminPassword);
  19. error_log(print_r($data,true));
  20. echo json_encode(['error' => 'Missing required parameters']);
  21. return;
  22. }
  23. error_log(" Creating user " . $username . " DebugMode: " . $GLOBALS['debug']);
  24. $userExisted = false;
  25. if( strpos(file_get_contents("/etc/passwd"),$username) !== false) {
  26. $userExisted = true;
  27. }
  28. if ($userExisted != true) {
  29. // Create user without login access
  30. if ($GLOBALS['debug'] == true) {error_log("Adding User: " . $username); }
  31. exec("sudo /usr/sbin/useradd -m -k -M -s /usr/sbin/nologin $username 2>&1", $userOutput, $userReturnCode);
  32. if ($userReturnCode !== 0) {
  33. error_log("deploy: ERROR: Useradd for $username failed, details => " . implode("\n", $userOutput));
  34. http_response_code(500);
  35. echo json_encode(['error' => 'Failed to create user', 'details' => implode("\n", $userOutput)]);
  36. return;
  37. }
  38. }
  39. if ($GLOBALS['debug'] == true) { error_log("Creating Webdir ($webDir) for : " . $username); }
  40. exec("sudo /usr/bin/mkdir -p $webDir 2>&1", $mkdirOutput, $mkdirReturnCode);
  41. if ($mkdirReturnCode !== 0) {
  42. error_log("deploy: ERROR: Create Webdir for $username failed, details => ". implode("\n", $mkdirOutput));
  43. http_response_code(500);
  44. echo json_encode(['error' => 'Failed to create web dir', 'details' => implode("\n", $mkdirOutput)]);
  45. return;
  46. }
  47. if ($GLOBALS['debug'] == true) { error_log("Install Placeholder on : " . $webDir); }
  48. exec("sudo /usr/bin/cp -rf $placeholderdir/* $webdir/. 2>&1", $mkdirOutput, $cpReturnCode);
  49. if ($cpReturnCode !== 0) {
  50. error_log("deploy: ERROR: Copy placeholder for $username failed, details => ". implode("\n", $mkdirOutput));
  51. http_response_code(500);
  52. echo json_encode(['error' => 'Failed to copy placeholder', 'details' => implode("\n", $mkdirOutput)]);
  53. return;
  54. }
  55. if ($GLOBALS['debug'] == true) { error_log("Creating logdir for : " . $username); }
  56. if (is_dir("/home/$username/logs") != true) {
  57. exec("sudo /usr/bin/mkdir -p /home/$username/logs 2>&1", $mkdirOutput, $mkdirReturnCode);
  58. if ($mkdirReturnCode !== 0) {
  59. error_log("deploy: ERROR: Failed to create log directory for $username failed, details => " . implode("\n", $mkdirOutput));
  60. http_response_code(500);
  61. echo json_encode(['error' => 'Failed to create logs dir', 'details' => implode("\n", $mkdirOutput)]);
  62. return;
  63. }
  64. }
  65. if ($GLOBALS['debug'] == true) { error_log("Creating backup dir for : " . $username); }
  66. if (is_dir("/home/$username/backups") != true) {
  67. exec("sudo /usr/bin/mkdir -p /home/$username/backups 2>&1", $mkdirOutput, $mkdirReturnCode);
  68. if ($mkdirReturnCode !== 0) {
  69. error_log("deploy: ERROR: mkdir /home/$username/backups failed, details => " . implode("\n", $mkdirOutput));
  70. http_response_code(500);
  71. echo json_encode(['error' => 'Failed to create backups dir', 'details' => implode("\n", $mkdirOutput)]);
  72. return;
  73. }
  74. }
  75. if ($GLOBALS['debug'] == true) { error_log("Chown homedir: " . $username); }
  76. exec("sudo /usr/bin/chown $username:$username /home/$username -R 2>&1", $chownOutput, $chownReturnCode);
  77. if ($chownReturnCode !== 0) {
  78. error_log("deploy: ERROR: chown on /home/$username failed, details => " . implode("\n", $chownOutput));
  79. http_response_code(500);
  80. echo json_encode(['error' => 'Failed to chown backups dir', 'details' => implode("\n", $chownOutput)]);
  81. return;
  82. }
  83. if ($GLOBALS['debug'] == true) { error_log("Reading Apache Config Template /etc/apache2/site-config.in"); }
  84. $configContent = file_get_contents($configTemplate);
  85. if ($GLOBALS['debug'] == true) { error_log("Replace config settings in Apache Config Template"); }
  86. $configContent = str_replace(['DOCUMENTROOT', 'SERVERNAME','USERNAME', 'DOMAINNAME', 'SERVERALIAS'], [$webDir, $domain, $username, $domain, "" ], $configContent);
  87. if ($GLOBALS['debug'] == true) { error_log("Running Certbot for Domain " . $domain); }
  88. exec("sudo /usr/bin/certbot certonly --webroot -w /etc/apache2/letsencrypt -d $domain --non-interactive --agree-tos --email admin@$domain 2>&1", $output, $returnCode);
  89. if ($returnCode !== 0) {
  90. error_log("deploy: ERROR: certbot failed to create certificate on $domain, details => " . implode("\n", $output));
  91. http_response_code(500);
  92. echo json_encode(['error' => 'Certbot failed', 'details' => implode("\n", $output)]);
  93. return;
  94. }
  95. if ($GLOBALS['debug'] == true) { error_log("Replace sslsettings in in Apache Config Template"); }
  96. $configContent = str_replace('DOMAINNAME', $domain, $configContent);
  97. if ($GLOBALS['debug'] == true) { error_log("Writing apache config file to " . $configFile); }
  98. if (file_put_contents($configFile, $configContent) != true) {
  99. error_log("deploy: ERROR: while writing apache config");
  100. echo json_encode(['error' => 'Failed to write Apache config', 'details' => []]);
  101. }
  102. exec('sudo /usr/bin/systemctl reload apache2 2>&1', $apacheOutput, $apacheReturnCode);
  103. if ($GLOBALS['debug'] == true) { error_log("Restarting Apache"); }
  104. if ($apacheReturnCode !== 0) {
  105. error_log("deploy: ERROR: Apache Reload error, details => " . implode("\n", $apacheOutput));
  106. http_response_code(500);
  107. echo json_encode(['error' => 'Failed to reload Apache', 'details' => implode("\n", $apacheOutput)]);
  108. return;
  109. }
  110. // Create PHP-FPM User
  111. // /etc/php/8.2/fpm/user.in
  112. if ($userExisted != true) {
  113. if ($GLOBALS['debug'] == true) {error_log("Writing PHP-FPM Config for : " . $username); }
  114. $phpContent = file_get_contents("/etc/php/8.2/fpm/user.in");
  115. $phpContent = str_replace("USERNAME", $username, $phpContent);
  116. file_put_contents("/etc/php/8.2/fpm/pool.d/" . $username . ".conf", $phpContent);
  117. if ($GLOBALS['debug'] == true) {error_log("Restarting PHP-FPM : " . $username);}
  118. exec('sudo /usr/bin/systemctl reload php8.2-fpm', $phpOutput, $phpReturnCode);
  119. if ($phpReturnCode !== 0) {
  120. error_log("deploy: ERROR: PHP-FPM reload error, details => " . implode("\n", $phpOutput));
  121. http_response_code(500);
  122. echo json_encode(['error' => 'Failed to reload PHP-FPM', 'details' => implode("\n", $phpOutput)]);
  123. return;
  124. }
  125. }
  126. echo json_encode(['success' => 'User crreation successfully','details' => '']);
  127. }
  128. public static function terminate($data): void {
  129. $username = $data['username'] ?? '';
  130. $domain = $data['domain'] ?? '';
  131. if (empty($username)) {
  132. error_log("terminate: ERROR: No username provided");
  133. http_response_code(400);
  134. error_log(print_r($data,true));
  135. echo json_encode(['error' => 'Missing username']);
  136. return;
  137. }
  138. if( strpos(file_get_contents("/etc/passwd"),$username) == false) {
  139. error_log("terminate: ERROR: User $username does not exist");
  140. http_response_code(400);
  141. error_log(print_r($data,true));
  142. echo json_encode(['error' => 'Unknown user']);
  143. return;
  144. }
  145. // remove PHP-FPM User
  146. if ($GLOBALS['debug'] == true) {error_log("Removing PHP-FPM Config for : " . $username); }
  147. $configName = "/etc/php/8.2/fpm/pool.d/" . $username . ".conf";
  148. exec("sudo /usr/bin/rm -f $configName 2>&1", $userOutput, $userReturnCode);
  149. if ($GLOBALS['debug'] == true) {error_log("Restarting PHP-FPM : " . $username);}
  150. exec('sudo /usr/bin/systemctl reload php8.2-fpm', $phpOutput, $phpReturnCode);
  151. if ($phpReturnCode !== 0) {
  152. error_log("deploy: ERROR: PHP-FPM reload error, details => " . implode("\n", $phpOutput));
  153. http_response_code(500);
  154. echo json_encode(['error' => 'Failed to reload PHP-FPM', 'details' => implode("\n", $phpOutput)]);
  155. return;
  156. }
  157. if(!empty($domain)) {
  158. $configFile = "/etc/apache2/sites-enabled/$domain.conf";
  159. if ($GLOBALS['debug'] == true) { error_log("Remove config of user : " . $username); }
  160. exec("sudo /usr/bin/rm -f $configFile 2>&1", $userOutput, $userReturnCode);
  161. exec("sudo /usr/bin/certbot delete --cert-name $domain --non-interactive 2>&1", $output, $returnCode);
  162. if ($returnCode !== 0) {
  163. error_log("deploy: ERROR: certbot failed to delete certificate on $domain, details => " . implode("\n", $output));
  164. http_response_code(500);
  165. echo json_encode(['error' => 'Certbot failed', 'details' => implode("\n", $output)]);
  166. return;
  167. }
  168. exec('sudo /usr/bin/systemctl reload apache2 2>&1', $apacheOutput, $apacheReturnCode);
  169. if ($GLOBALS['debug'] == true) { error_log("Restarting Apache"); }
  170. if ($apacheReturnCode !== 0) {
  171. error_log("deploy: ERROR: Apache Reload error, details => " . implode("\n", $apacheOutput));
  172. http_response_code(500);
  173. echo json_encode(['error' => 'Failed to reload Apache', 'details' => implode("\n", $apacheOutput)]);
  174. return;
  175. }
  176. }
  177. // Remove user and files
  178. if ($GLOBALS['debug'] == true) {error_log("Remove User: " . $username); }
  179. exec("sudo /usr/sbin/userdel -r -f $username 2>&1", $userOutput, $userReturnCode);
  180. if ($userReturnCode !== 0) {
  181. error_log("deploy: ERROR: Userdel for $username failed, details => " . implode("\n", $userOutput));
  182. http_response_code(500);
  183. echo json_encode(['error' => 'Failed to remove user', 'details' => implode("\n", $userOutput)]);
  184. return;
  185. }
  186. echo json_encode(['success' => 'Removing user ' . $username . ' successfully']);
  187. }
  188. }