AccountController.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. <?php
  2. namespace application\controllers;
  3. class AccountController {
  4. public static function create($data): void {
  5. $username = $data['username'];
  6. $domain = $data['domain'];
  7. $adminName = $data['admin_name'] ?? '';
  8. $adminPassword = $data['admin_password'];
  9. $webDir = "/home/$username/dev.$domain";
  10. $placeholderdir = "/var/www/catchall";
  11. $configTemplate = '/etc/apache2/site-config.in';
  12. $configFile = "/etc/apache2/sites-enabled/dev.$domain.conf";
  13. if (empty($username) || empty($domain) || empty($adminName) || empty($adminPassword)) {
  14. error_log("deploy: ERROR: No username, domain, admin_name or admin_password provided");
  15. http_response_code(400);
  16. error_log("deploy: ERROR: UserName 1 " . $username);
  17. error_log("deploy: ERROR: Domain 1 " . $domain);
  18. error_log("deploy: ERROR: UserName 2 " . $data['username'] );
  19. error_log("deploy: ERROR: Domain 2 " . $data['domain'] );
  20. error_log("deploy: ERROR: AdminName " . $adminName);
  21. error_log("deploy: ERROR: AdminPasswd" . $adminPassword);
  22. error_log(print_r($data,true));
  23. echo json_encode(['error' => 'Missing required parameters']);
  24. return;
  25. }
  26. error_log(" Creating user " . $username . " DebugMode: " . $GLOBALS['debug']);
  27. $userExisted = false;
  28. if( strpos(file_get_contents("/etc/passwd"),$username) !== false) {
  29. $userExisted = true;
  30. }
  31. if ($userExisted != true) {
  32. // Create user without login access
  33. if ($GLOBALS['debug'] == true) {error_log("Adding User: " . $username); }
  34. exec("sudo /usr/sbin/useradd -m -k -M -s /usr/sbin/nologin $username 2>&1", $userOutput, $userReturnCode);
  35. if ($userReturnCode !== 0) {
  36. error_log("deploy: ERROR: Useradd for $username failed, details => " . implode("\n", $userOutput));
  37. http_response_code(500);
  38. echo json_encode(['error' => 'Failed to create user', 'details' => implode("\n", $userOutput)]);
  39. return;
  40. }
  41. }
  42. if ($GLOBALS['debug'] == true) { error_log("Creating Webdir ($webDir) for : " . $username); }
  43. exec("sudo /usr/bin/mkdir -p $webDir 2>&1", $mkdirOutput, $mkdirReturnCode);
  44. if ($mkdirReturnCode !== 0) {
  45. error_log("deploy: ERROR: Create Webdir for $username failed, details => ". implode("\n", $mkdirOutput));
  46. http_response_code(500);
  47. echo json_encode(['error' => 'Failed to create web dir', 'details' => implode("\n", $mkdirOutput)]);
  48. return;
  49. }
  50. if ($GLOBALS['debug'] == true) { error_log("Install Placeholder on : " . $webDir); }
  51. exec("sudo /usr/bin/cp -rf $placeholderdir/* $webDir/. 2>&1", $mkdirOutput, $cpReturnCode);
  52. if ($cpReturnCode !== 0) {
  53. error_log("deploy: ERROR: Copy placeholder for $username failed, details => ". implode("\n", $mkdirOutput));
  54. http_response_code(500);
  55. echo json_encode(['error' => 'Failed to copy placeholder', 'details' => implode("\n", $mkdirOutput)]);
  56. return;
  57. }
  58. if ($GLOBALS['debug'] == true) { error_log("Creating logdir for : " . $username); }
  59. if (is_dir("/home/$username/logs") != true) {
  60. exec("sudo /usr/bin/mkdir -p /home/$username/logs 2>&1", $mkdirOutput, $mkdirReturnCode);
  61. if ($mkdirReturnCode !== 0) {
  62. error_log("deploy: ERROR: Failed to create log directory for $username failed, details => " . implode("\n", $mkdirOutput));
  63. http_response_code(500);
  64. echo json_encode(['error' => 'Failed to create logs dir', 'details' => implode("\n", $mkdirOutput)]);
  65. return;
  66. }
  67. }
  68. if ($GLOBALS['debug'] == true) { error_log("Creating backup dir for : " . $username); }
  69. if (is_dir("/home/$username/backups") != true) {
  70. exec("sudo /usr/bin/mkdir -p /home/$username/backups 2>&1", $mkdirOutput, $mkdirReturnCode);
  71. if ($mkdirReturnCode !== 0) {
  72. error_log("deploy: ERROR: mkdir /home/$username/backups failed, details => " . implode("\n", $mkdirOutput));
  73. http_response_code(500);
  74. echo json_encode(['error' => 'Failed to create backups dir', 'details' => implode("\n", $mkdirOutput)]);
  75. return;
  76. }
  77. }
  78. if ($GLOBALS['debug'] == true) { error_log("Chown homedir: " . $username); }
  79. exec("sudo /usr/bin/chown $username:$username /home/$username -R 2>&1", $chownOutput, $chownReturnCode);
  80. if ($chownReturnCode !== 0) {
  81. error_log("deploy: ERROR: chown on /home/$username failed, details => " . implode("\n", $chownOutput));
  82. http_response_code(500);
  83. echo json_encode(['error' => 'Failed to chown backups dir', 'details' => implode("\n", $chownOutput)]);
  84. return;
  85. }
  86. if ($GLOBALS['debug'] == true) { error_log("Reading Apache Config Template /etc/apache2/site-config.in"); }
  87. $configContent = file_get_contents($configTemplate);
  88. if ($GLOBALS['debug'] == true) { error_log("Replace config settings in Apache Config Template"); }
  89. $configContent = str_replace(['DOCUMENTROOT', 'SERVERNAME','USERNAME', 'DOMAINNAME', 'SERVERALIAS'], [$webDir, $domain, $username, $domain, "" ], $configContent);
  90. if ($GLOBALS['debug'] == true) { error_log("Running Certbot for Domain " . $domain); }
  91. exec("sudo /usr/bin/certbot certonly --webroot -w /etc/apache2/letsencrypt -d $domain --non-interactive --agree-tos --email admin@$domain 2>&1", $output, $returnCode);
  92. if ($returnCode !== 0) {
  93. error_log("deploy: ERROR: certbot failed to create certificate on $domain, details => " . implode("\n", $output));
  94. http_response_code(500);
  95. echo json_encode(['error' => 'Certbot failed', 'details' => implode("\n", $output)]);
  96. return;
  97. }
  98. if ($GLOBALS['debug'] == true) { error_log("Replace sslsettings in in Apache Config Template"); }
  99. $configContent = str_replace('DOMAINNAME', $domain, $configContent);
  100. if ($GLOBALS['debug'] == true) { error_log("Writing apache config file to " . $configFile); }
  101. if (file_put_contents($configFile, $configContent) != true) {
  102. error_log("deploy: ERROR: while writing apache config");
  103. echo json_encode(['error' => 'Failed to write Apache config', 'details' => []]);
  104. }
  105. exec('sudo /usr/bin/systemctl reload apache2 2>&1', $apacheOutput, $apacheReturnCode);
  106. if ($GLOBALS['debug'] == true) { error_log("Restarting Apache"); }
  107. if ($apacheReturnCode !== 0) {
  108. error_log("deploy: ERROR: Apache Reload error, details => " . implode("\n", $apacheOutput));
  109. http_response_code(500);
  110. echo json_encode(['error' => 'Failed to reload Apache', 'details' => implode("\n", $apacheOutput)]);
  111. return;
  112. }
  113. // Create PHP-FPM User
  114. // /etc/php/8.2/fpm/user.in
  115. if ($userExisted != true) {
  116. if ($GLOBALS['debug'] == true) {error_log("Writing PHP-FPM Config for : " . $username); }
  117. $phpContent = file_get_contents("/etc/php/8.2/fpm/user.in");
  118. $phpContent = str_replace("USERNAME", $username, $phpContent);
  119. file_put_contents("/etc/php/8.2/fpm/pool.d/" . $username . ".conf", $phpContent);
  120. if ($GLOBALS['debug'] == true) {error_log("Restarting PHP-FPM : " . $username);}
  121. exec('sudo /usr/bin/systemctl reload php8.2-fpm', $phpOutput, $phpReturnCode);
  122. if ($phpReturnCode !== 0) {
  123. error_log("deploy: ERROR: PHP-FPM reload error, details => " . implode("\n", $phpOutput));
  124. http_response_code(500);
  125. echo json_encode(['error' => 'Failed to reload PHP-FPM', 'details' => implode("\n", $phpOutput)]);
  126. return;
  127. }
  128. }
  129. echo json_encode(['success' => 'User crreation successfully','details' => '']);
  130. }
  131. public static function terminate($data): void {
  132. $username = $data['username'] ?? '';
  133. $domain = $data['domain'] ?? '';
  134. if (empty($username)) {
  135. error_log("terminate: ERROR: No username provided");
  136. http_response_code(400);
  137. error_log(print_r($data,true));
  138. echo json_encode(['error' => 'Missing username']);
  139. return;
  140. }
  141. if( strpos(file_get_contents("/etc/passwd"),$username) == false) {
  142. error_log("terminate: ERROR: User $username does not exist");
  143. http_response_code(400);
  144. error_log(print_r($data,true));
  145. echo json_encode(['error' => 'Unknown user']);
  146. return;
  147. }
  148. // remove PHP-FPM User
  149. if ($GLOBALS['debug'] == true) {error_log("Removing PHP-FPM Config for : " . $username); }
  150. $configName = "/etc/php/8.2/fpm/pool.d/" . $username . ".conf";
  151. exec("sudo /usr/bin/rm -f $configName 2>&1", $userOutput, $userReturnCode);
  152. if ($GLOBALS['debug'] == true) {error_log("Restarting PHP-FPM : " . $username);}
  153. exec('sudo /usr/bin/systemctl reload php8.2-fpm', $phpOutput, $phpReturnCode);
  154. if ($phpReturnCode !== 0) {
  155. error_log("deploy: ERROR: PHP-FPM reload error, details => " . implode("\n", $phpOutput));
  156. http_response_code(500);
  157. echo json_encode(['error' => 'Failed to reload PHP-FPM', 'details' => implode("\n", $phpOutput)]);
  158. return;
  159. }
  160. if(!empty($domain)) {
  161. $configFile = "/etc/apache2/sites-enabled/$domain.conf";
  162. if ($GLOBALS['debug'] == true) { error_log("Remove config of user : " . $username); }
  163. exec("sudo /usr/bin/rm -f $configFile 2>&1", $userOutput, $userReturnCode);
  164. exec("sudo /usr/bin/certbot delete --cert-name $domain --non-interactive 2>&1", $output, $returnCode);
  165. if ($returnCode !== 0) {
  166. error_log("deploy: ERROR: certbot failed to delete certificate on $domain, details => " . implode("\n", $output));
  167. http_response_code(500);
  168. echo json_encode(['error' => 'Certbot failed', 'details' => implode("\n", $output)]);
  169. return;
  170. }
  171. exec('sudo /usr/bin/systemctl reload apache2 2>&1', $apacheOutput, $apacheReturnCode);
  172. if ($GLOBALS['debug'] == true) { error_log("Restarting Apache"); }
  173. if ($apacheReturnCode !== 0) {
  174. error_log("deploy: ERROR: Apache Reload error, details => " . implode("\n", $apacheOutput));
  175. http_response_code(500);
  176. echo json_encode(['error' => 'Failed to reload Apache', 'details' => implode("\n", $apacheOutput)]);
  177. return;
  178. }
  179. }
  180. // Remove user and files
  181. if ($GLOBALS['debug'] == true) {error_log("Remove User: " . $username); }
  182. exec("sudo /usr/sbin/userdel -r -f $username 2>&1", $userOutput, $userReturnCode);
  183. if ($userReturnCode !== 0) {
  184. error_log("deploy: ERROR: Userdel for $username failed, details => " . implode("\n", $userOutput));
  185. http_response_code(500);
  186. echo json_encode(['error' => 'Failed to remove user', 'details' => implode("\n", $userOutput)]);
  187. return;
  188. }
  189. echo json_encode(['success' => 'Removing user ' . $username . ' successfully']);
  190. }
  191. }