autodiscover.php 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226
  1. <?php
  2. require_once 'inc/vars.inc.php';
  3. require_once 'inc/functions.inc.php';
  4. $default_autodiscover_config = $autodiscover_config;
  5. if(file_exists('inc/vars.local.inc.php')) {
  6. include_once 'inc/vars.local.inc.php';
  7. }
  8. $autodiscover_config = array_merge($default_autodiscover_config, $autodiscover_config);
  9. // Redis
  10. $redis = new Redis();
  11. $redis->connect('redis-mailcow', 6379);
  12. error_reporting(0);
  13. $data = trim(file_get_contents("php://input"));
  14. file_put_contents('/tmp/dsa', json_encode($_SERVER), FILE_APPEND);
  15. if ($autodiscover_config['autodiscoverType'] == 'activesync') {
  16. if (preg_match("/(Outlook|Office)/i", $_SERVER['HTTP_USER_AGENT'])) {
  17. if ($autodiscover_config['useEASforOutlook'] == 'yes') {
  18. preg_match("/^((?!.*Mac).)*(Outlook|Office).+1[5-9].*/i", $_SERVER['HTTP_USER_AGENT'], $supported_outlook);
  19. if (empty($supported_outlook)) {
  20. $autodiscover_config['autodiscoverType'] = 'imap';
  21. }
  22. }
  23. else {
  24. $autodiscover_config['autodiscoverType'] = 'imap';
  25. }
  26. }
  27. if (preg_match("/eM Client/i", $_SERVER['HTTP_USER_AGENT']) || !isset($_SERVER['HTTP_USER_AGENT'])) {
  28. $autodiscover_config['autodiscoverType'] = 'imap';
  29. }
  30. }
  31. $dsn = $database_type . ":host=" . $database_host . ";dbname=" . $database_name;
  32. $opt = [
  33. PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
  34. PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
  35. PDO::ATTR_EMULATE_PREPARES => false,
  36. ];
  37. $pdo = new PDO($dsn, $database_user, $database_pass, $opt);
  38. $login_user = strtolower(trim($_SERVER['PHP_AUTH_USER']));
  39. $login_role = check_login($login_user, $_SERVER['PHP_AUTH_PW']);
  40. if (!isset($_SERVER['PHP_AUTH_USER']) OR $login_role !== "user") {
  41. try {
  42. $json = json_encode(
  43. array(
  44. "time" => time(),
  45. "ua" => $_SERVER['HTTP_USER_AGENT'],
  46. "user" => "none",
  47. "service" => "Error: must be authenticated"
  48. )
  49. );
  50. $redis->lPush('AUTODISCOVER_LOG', $json);
  51. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  52. }
  53. catch (RedisException $e) {
  54. $_SESSION['return'] = array(
  55. 'type' => 'danger',
  56. 'msg' => 'Redis: '.$e
  57. );
  58. return false;
  59. }
  60. header('WWW-Authenticate: Basic realm="' . $_SERVER['HTTP_HOST'] . '"');
  61. header('HTTP/1.0 401 Unauthorized');
  62. exit(0);
  63. }
  64. else {
  65. if (isset($_SERVER['PHP_AUTH_USER']) && isset($_SERVER['PHP_AUTH_PW'])) {
  66. if ($login_role === "user") {
  67. header("Content-Type: application/xml");
  68. echo '<?xml version="1.0" encoding="utf-8" ?>' . PHP_EOL;
  69. ?>
  70. <Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006">
  71. <?php
  72. if(!$data) {
  73. try {
  74. $json = json_encode(
  75. array(
  76. "time" => time(),
  77. "ua" => $_SERVER['HTTP_USER_AGENT'],
  78. "user" => $_SERVER['PHP_AUTH_USER'],
  79. "service" => "Error: invalid or missing request data"
  80. )
  81. );
  82. $redis->lPush('AUTODISCOVER_LOG', $json);
  83. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  84. }
  85. catch (RedisException $e) {
  86. $_SESSION['return'] = array(
  87. 'type' => 'danger',
  88. 'msg' => 'Redis: '.$e
  89. );
  90. return false;
  91. }
  92. list($usec, $sec) = explode(' ', microtime());
  93. ?>
  94. <Response>
  95. <Error Time="<?=date('H:i:s', $sec) . substr($usec, 0, strlen($usec) - 2);?>" Id="2477272013">
  96. <ErrorCode>600</ErrorCode>
  97. <Message>Invalid Request</Message>
  98. <DebugData />
  99. </Error>
  100. </Response>
  101. </Autodiscover>
  102. <?php
  103. exit(0);
  104. }
  105. try {
  106. $discover = new SimpleXMLElement($data);
  107. $email = $discover->Request->EMailAddress;
  108. } catch (Exception $e) {
  109. $email = $_SERVER['PHP_AUTH_USER'];
  110. }
  111. $username = trim($email);
  112. try {
  113. $stmt = $pdo->prepare("SELECT `name` FROM `mailbox` WHERE `username`= :username");
  114. $stmt->execute(array(':username' => $username));
  115. $MailboxData = $stmt->fetch(PDO::FETCH_ASSOC);
  116. }
  117. catch(PDOException $e) {
  118. die("Failed to determine name from SQL");
  119. }
  120. if (!empty($MailboxData['name'])) {
  121. $displayname = $MailboxData['name'];
  122. }
  123. else {
  124. $displayname = $email;
  125. }
  126. try {
  127. $json = json_encode(
  128. array(
  129. "time" => time(),
  130. "ua" => $_SERVER['HTTP_USER_AGENT'],
  131. "user" => $_SERVER['PHP_AUTH_USER'],
  132. "service" => $autodiscover_config['autodiscoverType']
  133. )
  134. );
  135. $redis->lPush('AUTODISCOVER_LOG', $json);
  136. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  137. }
  138. catch (RedisException $e) {
  139. $_SESSION['return'] = array(
  140. 'type' => 'danger',
  141. 'msg' => 'Redis: '.$e
  142. );
  143. return false;
  144. }
  145. if ($autodiscover_config['autodiscoverType'] == 'imap') {
  146. ?>
  147. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a">
  148. <User>
  149. <DisplayName><?=$displayname;?></DisplayName>
  150. </User>
  151. <Account>
  152. <AccountType>email</AccountType>
  153. <Action>settings</Action>
  154. <Protocol>
  155. <Type>IMAP</Type>
  156. <Server><?=$autodiscover_config['imap']['server'];?></Server>
  157. <Port><?=$autodiscover_config['imap']['port'];?></Port>
  158. <DomainRequired>off</DomainRequired>
  159. <LoginName><?=$email;?></LoginName>
  160. <SPA>off</SPA>
  161. <SSL>on</SSL>
  162. <AuthRequired>on</AuthRequired>
  163. </Protocol>
  164. <Protocol>
  165. <Type>SMTP</Type>
  166. <Server><?=$autodiscover_config['smtp']['server'];?></Server>
  167. <Port><?=$autodiscover_config['smtp']['port'];?></Port>
  168. <DomainRequired>off</DomainRequired>
  169. <LoginName><?=$email;?></LoginName>
  170. <SPA>off</SPA>
  171. <SSL>on</SSL>
  172. <AuthRequired>on</AuthRequired>
  173. <UsePOPAuth>on</UsePOPAuth>
  174. <SMTPLast>off</SMTPLast>
  175. </Protocol>
  176. <Protocol>
  177. <Type>CalDAV</Type>
  178. <Server>https://<?=$autodiscover_config['caldav']['server'];?><?php if ($autodiscover_config['caldav']['port'] != 443) echo ':'.$autodiscover_config['caldav']['port']; ?>/SOGo/dav/<?=$email;?>/</Server>
  179. <DomainRequired>off</DomainRequired>
  180. <LoginName><?=$email;?></LoginName>
  181. </Protocol>
  182. <Protocol>
  183. <Type>CardDAV</Type>
  184. <Server>https://<?=$autodiscover_config['carddav']['server'];?><?php if ($autodiscover_config['caldav']['port'] != 443) echo ':'.$autodiscover_config['carddav']['port']; ?>/SOGo/dav/<?=$email;?>/</Server>
  185. <DomainRequired>off</DomainRequired>
  186. <LoginName><?=$email;?></LoginName>
  187. </Protocol>
  188. </Account>
  189. </Response>
  190. <?php
  191. }
  192. else if ($autodiscover_config['autodiscoverType'] == 'activesync') {
  193. ?>
  194. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/mobilesync/responseschema/2006">
  195. <Culture>en:en</Culture>
  196. <User>
  197. <DisplayName><?=$displayname;?></DisplayName>
  198. <EMailAddress><?=$email;?></EMailAddress>
  199. </User>
  200. <Action>
  201. <Settings>
  202. <Server>
  203. <Type>MobileSync</Type>
  204. <Url><?=$autodiscover_config['activesync']['url'];?></Url>
  205. <Name><?=$autodiscover_config['activesync']['url'];?></Name>
  206. </Server>
  207. </Settings>
  208. </Action>
  209. </Response>
  210. <?php
  211. }
  212. ?>
  213. </Autodiscover>
  214. <?php
  215. }
  216. }
  217. }
  218. ?>