mailcowauth.php 2.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374
  1. <?php
  2. ini_set('error_reporting', 0);
  3. header('Content-Type: application/json');
  4. $post = trim(file_get_contents('php://input'));
  5. if ($post) {
  6. $post = json_decode($post, true);
  7. }
  8. $return = array("success" => false);
  9. if(!isset($post['username']) || !isset($post['password']) || !isset($post['real_rip'])){
  10. error_log("MAILCOWAUTH: Bad Request");
  11. http_response_code(400); // Bad Request
  12. echo json_encode($return);
  13. exit();
  14. }
  15. require_once('../../../web/inc/vars.inc.php');
  16. if (file_exists('../../../web/inc/vars.local.inc.php')) {
  17. include_once('../../../web/inc/vars.local.inc.php');
  18. }
  19. require_once '../../../web/inc/lib/vendor/autoload.php';
  20. // Init database
  21. $dsn = $database_type . ":unix_socket=" . $database_sock . ";dbname=" . $database_name;
  22. $opt = [
  23. PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
  24. PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
  25. PDO::ATTR_EMULATE_PREPARES => false,
  26. ];
  27. try {
  28. $pdo = new PDO($dsn, $database_user, $database_pass, $opt);
  29. }
  30. catch (PDOException $e) {
  31. error_log("MAILCOWAUTH: " . $e . PHP_EOL);
  32. http_response_code(500); // Internal Server Error
  33. echo json_encode($return);
  34. exit;
  35. }
  36. // Load core functions first
  37. require_once 'functions.inc.php';
  38. require_once 'functions.auth.inc.php';
  39. require_once 'sessions.inc.php';
  40. // Init provider
  41. $iam_provider = identity_provider('init');
  42. $protocol = $post['protocol'];
  43. if ($post['real_rip'] == getenv('IPV4_NETWORK') . '.248') {
  44. $protocol = null;
  45. }
  46. $result = user_login($post['username'], $post['password'], $protocol, array('is_internal' => true));
  47. if ($result === false){
  48. $result = apppass_login($post['username'], $post['password'], $protocol, array(
  49. 'is_internal' => true,
  50. 'remote_addr' => $post['real_rip']
  51. ));
  52. }
  53. if ($result) {
  54. http_response_code(200); // OK
  55. $return['success'] = true;
  56. } else {
  57. error_log("MAILCOWAUTH: Login failed for user " . $post['username']);
  58. http_response_code(401); // Unauthorized
  59. }
  60. echo json_encode($return);
  61. session_destroy();
  62. exit;