bootstrap-sogo.sh 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255
  1. #!/bin/bash
  2. # Wait for MySQL to warm-up
  3. while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  4. echo "Waiting for database to come up..."
  5. sleep 2
  6. done
  7. # Wait until port becomes free and send sig
  8. until ! nc -z sogo-mailcow 20000;
  9. do
  10. killall -TERM sogod
  11. sleep 3
  12. done
  13. # Wait for updated schema
  14. DBV_NOW=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions WHERE application = 'db_schema';" -BN)
  15. DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
  16. while [[ "${DBV_NOW}" != "${DBV_NEW}" ]]; do
  17. echo "Waiting for schema update..."
  18. DBV_NOW=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions WHERE application = 'db_schema';" -BN)
  19. DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
  20. sleep 5
  21. done
  22. echo "DB schema is ${DBV_NOW}"
  23. # Recreate view
  24. if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  25. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "DROP VIEW IF EXISTS sogo_view"
  26. while [[ ${VIEW_OK} != 'OK' ]]; do
  27. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
  28. CREATE VIEW sogo_view (c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, ext_acl, kind, multiple_bookings) AS
  29. SELECT
  30. mailbox.username,
  31. mailbox.domain,
  32. mailbox.username,
  33. if(json_extract(attributes, '$.force_pw_update') LIKE '%0%', if(json_extract(attributes, '$.sogo_access') LIKE '%1%', password, '{SSHA256}A123A123A321A321A321B321B321B123B123B321B432F123E321123123321321'), '{SSHA256}A123A123A321A321A321B321B321B123B123B321B432F123E321123123321321'),
  34. mailbox.name,
  35. mailbox.username,
  36. IFNULL(GROUP_CONCAT(ga.aliases ORDER BY ga.aliases SEPARATOR ' '), ''),
  37. IFNULL(gda.ad_alias, ''),
  38. IFNULL(external_acl.send_as_acl, ''),
  39. mailbox.kind,
  40. mailbox.multiple_bookings
  41. FROM
  42. mailbox
  43. LEFT OUTER JOIN
  44. grouped_mail_aliases ga
  45. ON ga.username REGEXP CONCAT('(^|,)', mailbox.username, '($|,)')
  46. LEFT OUTER JOIN
  47. grouped_domain_alias_address gda
  48. ON gda.username = mailbox.username
  49. LEFT OUTER JOIN
  50. grouped_sender_acl_external external_acl
  51. ON external_acl.username = mailbox.username
  52. WHERE
  53. mailbox.active = '1'
  54. GROUP BY
  55. mailbox.username;
  56. EOF
  57. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = 'sogo_view'") ]]; then
  58. VIEW_OK=OK
  59. else
  60. echo "Will retry to setup SOGo view in 3s..."
  61. sleep 3
  62. fi
  63. done
  64. else
  65. while [[ ${VIEW_OK} != 'OK' ]]; do
  66. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = 'sogo_view'") ]]; then
  67. VIEW_OK=OK
  68. else
  69. echo "Waiting for SOGo view to be created by master..."
  70. sleep 3
  71. fi
  72. done
  73. fi
  74. # Wait for static view table if missing after update and update content
  75. if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  76. while [[ ${STATIC_VIEW_OK} != 'OK' ]]; do
  77. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = '_sogo_static_view'") ]]; then
  78. STATIC_VIEW_OK=OK
  79. echo "Updating _sogo_static_view content..."
  80. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "REPLACE INTO _sogo_static_view (c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, ext_acl, kind, multiple_bookings) SELECT c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, ext_acl, kind, multiple_bookings from sogo_view;"
  81. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "DELETE FROM _sogo_static_view WHERE c_uid NOT IN (SELECT username FROM mailbox WHERE active = '1')"
  82. else
  83. echo "Waiting for database initialization by master..."
  84. sleep 3
  85. fi
  86. done
  87. else
  88. while [[ ${STATIC_VIEW_OK} != 'OK' ]]; do
  89. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = '_sogo_static_view'") ]]; then
  90. STATIC_VIEW_OK=OK
  91. else
  92. echo "Waiting for database initialization by master..."
  93. sleep 3
  94. fi
  95. done
  96. fi
  97. # Recreate password update trigger
  98. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "DROP TRIGGER IF EXISTS sogo_update_password"
  99. while [[ ${TRIGGER_OK} != 'OK' ]]; do
  100. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
  101. DELIMITER -
  102. CREATE TRIGGER sogo_update_password AFTER UPDATE ON _sogo_static_view
  103. FOR EACH ROW
  104. BEGIN
  105. UPDATE mailbox SET password = NEW.c_password WHERE NEW.c_uid = username;
  106. END;
  107. -
  108. DELIMITER ;
  109. EOF
  110. if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TRIGGERS WHERE TRIGGER_NAME = 'sogo_update_password'") ]]; then
  111. TRIGGER_OK=OK
  112. else
  113. echo "Will retry to setup SOGo password update trigger in 3s"
  114. sleep 3
  115. fi
  116. done
  117. if [[ "${ALLOW_ADMIN_EMAIL_LOGIN}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  118. TRUST_PROXY="YES"
  119. else
  120. TRUST_PROXY="NO"
  121. fi
  122. # cat /dev/urandom seems to hang here occasionally and is not recommended anyway, better use openssl
  123. RAND_PASS=$(openssl rand -base64 16 | tr -dc _A-Z-a-z-0-9)
  124. # Generate plist header with timezone data
  125. mkdir -p /var/lib/sogo/GNUstep/Defaults/
  126. cat <<EOF > /var/lib/sogo/GNUstep/Defaults/sogod.plist
  127. <?xml version="1.0" encoding="UTF-8"?>
  128. <!DOCTYPE plist PUBLIC "-//GNUstep//DTD plist 0.9//EN" "http://www.gnustep.org/plist-0_9.xml">
  129. <plist version="0.9">
  130. <dict>
  131. <key>OCSAclURL</key>
  132. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_acl</string>
  133. <key>SOGoIMAPServer</key>
  134. <string>imaps://${IPV4_NETWORK}.250:993</string>
  135. <key>SOGoTrustProxyAuthentication</key>
  136. <string>${TRUST_PROXY}</string>
  137. <key>SOGoEncryptionKey</key>
  138. <string>${RAND_PASS}</string>
  139. <key>OCSCacheFolderURL</key>
  140. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_cache_folder</string>
  141. <key>OCSEMailAlarmsFolderURL</key>
  142. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_alarms_folder</string>
  143. <key>OCSFolderInfoURL</key>
  144. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_folder_info</string>
  145. <key>OCSSessionsFolderURL</key>
  146. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_sessions_folder</string>
  147. <key>OCSStoreURL</key>
  148. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_store</string>
  149. <key>SOGoProfileURL</key>
  150. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_user_profile</string>
  151. <key>SOGoTimeZone</key>
  152. <string>${TZ}</string>
  153. <key>domains</key>
  154. <dict>
  155. EOF
  156. # Generate multi-domain setup
  157. while read -r line gal
  158. do
  159. echo " <key>${line}</key>
  160. <dict>
  161. <key>SOGoMailDomain</key>
  162. <string>${line}</string>
  163. <key>SOGoUserSources</key>
  164. <array>
  165. <dict>
  166. <key>MailFieldNames</key>
  167. <array>
  168. <string>aliases</string>
  169. <string>ad_aliases</string>
  170. <string>ext_acl</string>
  171. </array>
  172. <key>KindFieldName</key>
  173. <string>kind</string>
  174. <key>DomainFieldName</key>
  175. <string>domain</string>
  176. <key>MultipleBookingsFieldName</key>
  177. <string>multiple_bookings</string>
  178. <key>listRequiresDot</key>
  179. <string>NO</string>
  180. <key>canAuthenticate</key>
  181. <string>YES</string>
  182. <key>displayName</key>
  183. <string>GAL ${line}</string>
  184. <key>id</key>
  185. <string>${line}</string>
  186. <key>isAddressBook</key>
  187. <string>${gal}</string>
  188. <key>type</key>
  189. <string>sql</string>
  190. <key>userPasswordAlgorithm</key>
  191. <string>ssha256</string>
  192. <key>prependPasswordScheme</key>
  193. <string>YES</string>
  194. <key>viewURL</key>
  195. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/_sogo_static_view</string>
  196. </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  197. # Generate alternative LDAP authentication dict, when SQL authentication fails
  198. # This will nevertheless read attributes from LDAP
  199. line=${line} envsubst < /etc/sogo/plist_ldap >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  200. echo " </array>
  201. </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  202. done < <(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT domain, CASE gal WHEN '1' THEN 'YES' ELSE 'NO' END AS gal FROM domain;" -B -N)
  203. # Generate footer
  204. echo ' </dict>
  205. </dict>
  206. </plist>' >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  207. # Fix permissions
  208. chown sogo:sogo -R /var/lib/sogo/
  209. chmod 600 /var/lib/sogo/GNUstep/Defaults/sogod.plist
  210. # Patch ACLs
  211. #if [[ ${ACL_ANYONE} == 'allow' ]]; then
  212. # #enable any or authenticated targets for ACL
  213. # if patch -R -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
  214. # patch -R /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
  215. # fi
  216. #else
  217. # #disable any or authenticated targets for ACL
  218. # if patch -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
  219. # patch /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
  220. # fi
  221. #fi
  222. # Copy logo, if any
  223. [[ -f /etc/sogo/sogo-full.svg ]] && cp /etc/sogo/sogo-full.svg /usr/lib/GNUstep/SOGo/WebServerResources/img/sogo-full.svg
  224. # Rsync web content
  225. echo "Syncing web content with named volume"
  226. rsync -a /usr/lib/GNUstep/SOGo/. /sogo_web/
  227. # Creating cronjobs
  228. if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  229. echo "* * * * * sogo /usr/sbin/sogo-ealarms-notify -p /etc/sogo/sieve.creds 2>/dev/null" > /etc/cron.d/sogo
  230. echo "* * * * * sogo /usr/sbin/sogo-tool expire-sessions ${SOGO_EXPIRE_SESSION}" >> /etc/cron.d/sogo
  231. echo "0 0 * * * sogo /usr/sbin/sogo-tool update-autoreply -p /etc/sogo/sieve.creds" >> /etc/cron.d/sogo
  232. else
  233. rm /etc/cron.d/sogo
  234. fi
  235. exec gosu sogo /usr/sbin/sogod