bootstrap-sogo.sh 8.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186
  1. #!/bin/bash
  2. # Wait for MySQL to warm-up
  3. while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  4. echo "Waiting for database to come up..."
  5. sleep 2
  6. done
  7. # Wait until port becomes free and send sig
  8. until ! nc -z sogo-mailcow 20000;
  9. do
  10. killall -TERM sogod
  11. sleep 3
  12. done
  13. # Wait for updated schema
  14. DBV_NOW=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions;" -BN)
  15. DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
  16. while [[ ${DBV_NOW} != ${DBV_NEW} ]]; do
  17. echo "Waiting for schema update..."
  18. DBV_NOW=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions;" -BN)
  19. DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
  20. sleep 5
  21. done
  22. echo "DB schema is ${DBV_NOW}"
  23. # Recreate view
  24. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "DROP VIEW IF EXISTS sogo_view"
  25. while [[ ${VIEW_OK} != 'OK' ]]; do
  26. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
  27. CREATE VIEW sogo_view (c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, kind, multiple_bookings) AS
  28. SELECT mailbox.username, mailbox.domain, mailbox.username, if(json_extract(attributes, '$.force_pw_update') LIKE '%0%', if(json_extract(attributes, '$.sogo_access') LIKE '%1%', password, 'invalid'), 'invalid'), mailbox.name, mailbox.username, IFNULL(GROUP_CONCAT(ga.aliases SEPARATOR ' '), ''), IFNULL(gda.ad_alias, ''), mailbox.kind, mailbox.multiple_bookings FROM mailbox
  29. LEFT OUTER JOIN grouped_mail_aliases ga ON ga.username REGEXP CONCAT('(^|,)', mailbox.username, '($|,)')
  30. LEFT OUTER JOIN grouped_domain_alias_address gda ON gda.username = mailbox.username
  31. WHERE mailbox.active = '1'
  32. GROUP BY mailbox.username;
  33. EOF
  34. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = 'sogo_view'") ]]; then
  35. VIEW_OK=OK
  36. else
  37. echo "Will retry to setup SOGo view in 3s"
  38. sleep 3
  39. fi
  40. done
  41. # Wait for static view table if missing after update and update content
  42. while [[ ${STATIC_VIEW_OK} != 'OK' ]]; do
  43. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = '_sogo_static_view'") ]]; then
  44. STATIC_VIEW_OK=OK
  45. echo "Updating _sogo_static_view content..."
  46. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "REPLACE INTO _sogo_static_view (c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, kind, multiple_bookings) SELECT c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, kind, multiple_bookings from sogo_view;"
  47. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "DELETE FROM _sogo_static_view WHERE c_uid NOT IN (SELECT username FROM mailbox WHERE active = '1')"
  48. else
  49. echo "Waiting for database initialization..."
  50. sleep 3
  51. fi
  52. done
  53. # Recreate password update trigger
  54. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "DROP TRIGGER IF EXISTS sogo_update_password"
  55. while [[ ${TRIGGER_OK} != 'OK' ]]; do
  56. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
  57. DELIMITER -
  58. CREATE TRIGGER sogo_update_password AFTER UPDATE ON _sogo_static_view
  59. FOR EACH ROW
  60. BEGIN
  61. UPDATE mailbox SET password = NEW.c_password WHERE NEW.c_uid = username;
  62. END;
  63. -
  64. DELIMITER ;
  65. EOF
  66. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TRIGGERS WHERE TRIGGER_NAME = 'sogo_update_password'") ]]; then
  67. TRIGGER_OK=OK
  68. else
  69. echo "Will retry to setup SOGo password update trigger in 3s"
  70. sleep 3
  71. fi
  72. done
  73. mkdir -p /var/lib/sogo/GNUstep/Defaults/
  74. # Generate plist header with timezone data
  75. cat <<EOF > /var/lib/sogo/GNUstep/Defaults/sogod.plist
  76. <?xml version="1.0" encoding="UTF-8"?>
  77. <!DOCTYPE plist PUBLIC "-//GNUstep//DTD plist 0.9//EN" "http://www.gnustep.org/plist-0_9.xml">
  78. <plist version="0.9">
  79. <dict>
  80. <key>OCSAclURL</key>
  81. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_acl</string>
  82. <key>OCSCacheFolderURL</key>
  83. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_cache_folder</string>
  84. <key>OCSEMailAlarmsFolderURL</key>
  85. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_alarms_folder</string>
  86. <key>OCSFolderInfoURL</key>
  87. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_folder_info</string>
  88. <key>OCSSessionsFolderURL</key>
  89. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_sessions_folder</string>
  90. <key>OCSStoreURL</key>
  91. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_store</string>
  92. <key>SOGoProfileURL</key>
  93. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_user_profile</string>
  94. <key>SOGoTimeZone</key>
  95. <string>${TZ}</string>
  96. <key>domains</key>
  97. <dict>
  98. EOF
  99. # Generate multi-domain setup
  100. while read line
  101. do
  102. echo " <key>${line}</key>
  103. <dict>
  104. <key>SOGoMailDomain</key>
  105. <string>${line}</string>
  106. <key>SOGoUserSources</key>
  107. <array>
  108. <dict>
  109. <key>MailFieldNames</key>
  110. <array>
  111. <string>aliases</string>
  112. <string>ad_aliases</string>
  113. </array>
  114. <key>KindFieldName</key>
  115. <string>kind</string>
  116. <key>DomainFieldName</key>
  117. <string>domain</string>
  118. <key>MultipleBookingsFieldName</key>
  119. <string>multiple_bookings</string>
  120. <key>listRequiresDot</key>
  121. <string>NO</string>
  122. <key>canAuthenticate</key>
  123. <string>YES</string>
  124. <key>displayName</key>
  125. <string>GAL</string>
  126. <key>id</key>
  127. <string>${line}</string>
  128. <key>isAddressBook</key>
  129. <string>YES</string>
  130. <key>type</key>
  131. <string>sql</string>
  132. <key>userPasswordAlgorithm</key>
  133. <string>ssha256</string>
  134. <key>prependPasswordScheme</key>
  135. <string>YES</string>
  136. <key>viewURL</key>
  137. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/_sogo_static_view</string>
  138. </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  139. # Generate alternative LDAP authentication dict, when SQL authentication fails
  140. # This will nevertheless read attributes from LDAP
  141. line=${line} envsubst < /etc/sogo/plist_ldap >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  142. echo " </array>
  143. </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  144. done < <(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT domain FROM domain;" -B -N)
  145. # Generate footer
  146. echo ' </dict>
  147. </dict>
  148. </plist>' >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  149. # Fix permissions
  150. chown sogo:sogo -R /var/lib/sogo/
  151. chmod 600 /var/lib/sogo/GNUstep/Defaults/sogod.plist
  152. # Patch ACLs
  153. if [[ ${ACL_ANYONE} == 'allow' ]]; then
  154. #enable any or authenticated targets for ACL
  155. if patch -R -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
  156. patch -R /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
  157. fi
  158. else
  159. #disable any or authenticated targets for ACL
  160. if patch -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
  161. patch /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
  162. fi
  163. fi
  164. # Copy logo, if any
  165. [[ -f /etc/sogo/sogo-full.svg ]] && cp /etc/sogo/sogo-full.svg /usr/lib/GNUstep/SOGo/WebServerResources/img/sogo-full.svg
  166. exec gosu sogo /usr/sbin/sogod