functions.inc.php 44 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365
  1. <?php
  2. function hash_password($password) {
  3. $salt_str = bin2hex(openssl_random_pseudo_bytes(8));
  4. return "{SSHA256}".base64_encode(hash('sha256', $password . $salt_str, true) . $salt_str);
  5. }
  6. function hasDomainAccess($username, $role, $domain) {
  7. global $pdo;
  8. if (!filter_var($username, FILTER_VALIDATE_EMAIL) && !ctype_alnum(str_replace(array('_', '.', '-'), '', $username))) {
  9. return false;
  10. }
  11. if (empty($domain) || !is_valid_domain_name($domain)) {
  12. return false;
  13. }
  14. if ($role != 'admin' && $role != 'domainadmin' && $role != 'user') {
  15. return false;
  16. }
  17. try {
  18. $stmt = $pdo->prepare("SELECT `domain` FROM `domain_admins`
  19. WHERE (
  20. `active`='1'
  21. AND `username` = :username
  22. AND (`domain` = :domain1 OR `domain` = (SELECT `target_domain` FROM `alias_domain` WHERE `alias_domain` = :domain2))
  23. )
  24. OR 'admin' = :role");
  25. $stmt->execute(array(':username' => $username, ':domain1' => $domain, ':domain2' => $domain, ':role' => $role));
  26. $num_results = count($stmt->fetchAll(PDO::FETCH_ASSOC));
  27. }
  28. catch(PDOException $e) {
  29. $_SESSION['return'] = array(
  30. 'type' => 'danger',
  31. 'msg' => 'MySQL: '.$e
  32. );
  33. return false;
  34. }
  35. if (!empty($num_results)) {
  36. return true;
  37. }
  38. return false;
  39. }
  40. function hasMailboxObjectAccess($username, $role, $object) {
  41. global $pdo;
  42. if (!filter_var($username, FILTER_VALIDATE_EMAIL) && !ctype_alnum(str_replace(array('_', '.', '-'), '', $username))) {
  43. return false;
  44. }
  45. if ($role != 'admin' && $role != 'domainadmin' && $role != 'user') {
  46. return false;
  47. }
  48. if ($username == $object) {
  49. return true;
  50. }
  51. try {
  52. $stmt = $pdo->prepare("SELECT `domain` FROM `mailbox` WHERE `username` = :object");
  53. $stmt->execute(array(':object' => $object));
  54. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  55. if (isset($row['domain']) && hasDomainAccess($username, $role, $row['domain'])) {
  56. return true;
  57. }
  58. }
  59. catch(PDOException $e) {
  60. error_log($e);
  61. return false;
  62. }
  63. return false;
  64. }
  65. function verify_ssha256($hash, $password) {
  66. // Remove tag if any
  67. $hash = ltrim($hash, '{SSHA256}');
  68. // Decode hash
  69. $dhash = base64_decode($hash);
  70. // Get first 32 bytes of binary which equals a SHA256 hash
  71. $ohash = substr($dhash, 0, 32);
  72. // Remove SHA256 hash from decoded hash to get original salt string
  73. $osalt = str_replace($ohash, '', $dhash);
  74. // Check single salted SHA256 hash against extracted hash
  75. if (hash('sha256', $password . $osalt, true) == $ohash) {
  76. return true;
  77. }
  78. else {
  79. return false;
  80. }
  81. }
  82. function doveadm_authenticate($hash, $algorithm, $password) {
  83. $descr = array(0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w'));
  84. $pipes = array();
  85. $process = proc_open("/usr/bin/doveadm pw -s ".$algorithm." -t '".$hash."'", $descr, $pipes);
  86. if (is_resource($process)) {
  87. fputs($pipes[0], $password);
  88. fclose($pipes[0]);
  89. while ($f = fgets($pipes[1])) {
  90. if (preg_match('/(verified)/', $f)) {
  91. proc_close($process);
  92. return true;
  93. }
  94. return false;
  95. }
  96. fclose($pipes[1]);
  97. while ($f = fgets($pipes[2])) {
  98. proc_close($process);
  99. return false;
  100. }
  101. fclose($pipes[2]);
  102. proc_close($process);
  103. }
  104. return false;
  105. }
  106. function check_login($user, $pass) {
  107. global $pdo;
  108. if (!filter_var($user, FILTER_VALIDATE_EMAIL) && !ctype_alnum(str_replace(array('_', '.', '-'), '', $user))) {
  109. return false;
  110. }
  111. $user = strtolower(trim($user));
  112. $stmt = $pdo->prepare("SELECT `password` FROM `admin`
  113. WHERE `superadmin` = '1'
  114. AND `username` = :user");
  115. $stmt->execute(array(':user' => $user));
  116. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  117. foreach ($rows as $row) {
  118. if (verify_ssha256($row['password'], $pass)) {
  119. if (get_tfa($user)['name'] != "none") {
  120. $_SESSION['pending_mailcow_cc_username'] = $user;
  121. $_SESSION['pending_mailcow_cc_role'] = "admin";
  122. $_SESSION['pending_tfa_method'] = get_tfa($user)['name'];
  123. unset($_SESSION['ldelay']);
  124. return "pending";
  125. }
  126. else {
  127. unset($_SESSION['ldelay']);
  128. return "admin";
  129. }
  130. }
  131. }
  132. $stmt = $pdo->prepare("SELECT `password` FROM `admin`
  133. WHERE `superadmin` = '0'
  134. AND `active`='1'
  135. AND `username` = :user");
  136. $stmt->execute(array(':user' => $user));
  137. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  138. foreach ($rows as $row) {
  139. if (verify_ssha256($row['password'], $pass) !== false) {
  140. if (get_tfa($user)['name'] != "none") {
  141. $_SESSION['pending_mailcow_cc_username'] = $user;
  142. $_SESSION['pending_mailcow_cc_role'] = "domainadmin";
  143. $_SESSION['pending_tfa_method'] = get_tfa($user)['name'];
  144. unset($_SESSION['ldelay']);
  145. return "pending";
  146. }
  147. else {
  148. unset($_SESSION['ldelay']);
  149. $stmt = $pdo->prepare("UPDATE `tfa` SET `active`='1' WHERE `username` = :user");
  150. $stmt->execute(array(':user' => $user));
  151. return "domainadmin";
  152. }
  153. }
  154. }
  155. $stmt = $pdo->prepare("SELECT `password` FROM `mailbox`
  156. WHERE `kind` NOT REGEXP 'location|thing|group'
  157. AND `active`='1'
  158. AND `username` = :user");
  159. $stmt->execute(array(':user' => $user));
  160. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  161. foreach ($rows as $row) {
  162. if (verify_ssha256($row['password'], $pass) !== false) {
  163. unset($_SESSION['ldelay']);
  164. return "user";
  165. }
  166. }
  167. if (!isset($_SESSION['ldelay'])) {
  168. $_SESSION['ldelay'] = "0";
  169. }
  170. elseif (!isset($_SESSION['mailcow_cc_username'])) {
  171. $_SESSION['ldelay'] = $_SESSION['ldelay']+0.5;
  172. }
  173. sleep($_SESSION['ldelay']);
  174. }
  175. function formatBytes($size, $precision = 2) {
  176. if(!is_numeric($size)) {
  177. return "0";
  178. }
  179. $base = log($size, 1024);
  180. $suffixes = array(' Byte', ' KiB', ' MiB', ' GiB', ' TiB');
  181. if ($size == "0") {
  182. return "0";
  183. }
  184. return round(pow(1024, $base - floor($base)), $precision) . $suffixes[floor($base)];
  185. }
  186. function edit_admin_account($postarray) {
  187. global $lang;
  188. global $pdo;
  189. if ($_SESSION['mailcow_cc_role'] != "admin") {
  190. $_SESSION['return'] = array(
  191. 'type' => 'danger',
  192. 'msg' => sprintf($lang['danger']['access_denied'])
  193. );
  194. return false;
  195. }
  196. $username_now = $_SESSION['mailcow_cc_username'];
  197. $username = $postarray['admin_user'];
  198. $password = $postarray['admin_pass'];
  199. $password2 = $postarray['admin_pass2'];
  200. if (!ctype_alnum(str_replace(array('_', '.', '-'), '', $username)) || empty ($username)) {
  201. $_SESSION['return'] = array(
  202. 'type' => 'danger',
  203. 'msg' => sprintf($lang['danger']['username_invalid'])
  204. );
  205. return false;
  206. }
  207. if (!empty($password) && !empty($password2)) {
  208. if (!preg_match('/' . $GLOBALS['PASSWD_REGEP'] . '/', $password)) {
  209. $_SESSION['return'] = array(
  210. 'type' => 'danger',
  211. 'msg' => sprintf($lang['danger']['password_complexity'])
  212. );
  213. return false;
  214. }
  215. if ($password != $password2) {
  216. $_SESSION['return'] = array(
  217. 'type' => 'danger',
  218. 'msg' => sprintf($lang['danger']['password_mismatch'])
  219. );
  220. return false;
  221. }
  222. $password_hashed = hash_password($password);
  223. try {
  224. $stmt = $pdo->prepare("UPDATE `admin` SET
  225. `password` = :password_hashed,
  226. `username` = :username1
  227. WHERE `username` = :username2");
  228. $stmt->execute(array(
  229. ':password_hashed' => $password_hashed,
  230. ':username1' => $username,
  231. ':username2' => $username_now
  232. ));
  233. }
  234. catch (PDOException $e) {
  235. $_SESSION['return'] = array(
  236. 'type' => 'danger',
  237. 'msg' => 'MySQL: '.$e
  238. );
  239. return false;
  240. }
  241. }
  242. else {
  243. try {
  244. $stmt = $pdo->prepare("UPDATE `admin` SET
  245. `username` = :username1
  246. WHERE `username` = :username2");
  247. $stmt->execute(array(
  248. ':username1' => $username,
  249. ':username2' => $username_now
  250. ));
  251. }
  252. catch (PDOException $e) {
  253. $_SESSION['return'] = array(
  254. 'type' => 'danger',
  255. 'msg' => 'MySQL: '.$e
  256. );
  257. return false;
  258. }
  259. }
  260. try {
  261. $stmt = $pdo->prepare("UPDATE `domain_admins` SET `domain` = 'ALL', `username` = :username1 WHERE `username` = :username2");
  262. $stmt->execute(array(':username1' => $username, ':username2' => $username_now));
  263. $stmt = $pdo->prepare("UPDATE `tfa` SET `username` = :username1 WHERE `username` = :username2");
  264. $stmt->execute(array(':username1' => $username, ':username2' => $username_now));
  265. }
  266. catch (PDOException $e) {
  267. $_SESSION['return'] = array(
  268. 'type' => 'danger',
  269. 'msg' => 'MySQL: '.$e
  270. );
  271. return false;
  272. }
  273. $_SESSION['mailcow_cc_username'] = $username;
  274. $_SESSION['return'] = array(
  275. 'type' => 'success',
  276. 'msg' => sprintf($lang['success']['admin_modified'])
  277. );
  278. }
  279. function edit_user_account($postarray) {
  280. global $lang;
  281. global $pdo;
  282. if (isset($postarray['username']) && filter_var($postarray['username'], FILTER_VALIDATE_EMAIL)) {
  283. if (!hasMailboxObjectAccess($_SESSION['mailcow_cc_username'], $_SESSION['mailcow_cc_role'], $postarray['username'])) {
  284. $_SESSION['return'] = array(
  285. 'type' => 'danger',
  286. 'msg' => sprintf($lang['danger']['access_denied'])
  287. );
  288. return false;
  289. }
  290. else {
  291. $username = $postarray['username'];
  292. }
  293. }
  294. else {
  295. $username = $_SESSION['mailcow_cc_username'];
  296. }
  297. $password_old = $postarray['user_old_pass'];
  298. if (isset($postarray['user_new_pass']) && isset($postarray['user_new_pass2'])) {
  299. $password_new = $postarray['user_new_pass'];
  300. $password_new2 = $postarray['user_new_pass2'];
  301. }
  302. $stmt = $pdo->prepare("SELECT `password` FROM `mailbox`
  303. WHERE `kind` NOT REGEXP 'location|thing|group'
  304. AND `username` = :user");
  305. $stmt->execute(array(':user' => $username));
  306. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  307. if (!verify_ssha256($row['password'], $password_old)) {
  308. $_SESSION['return'] = array(
  309. 'type' => 'danger',
  310. 'msg' => sprintf($lang['danger']['access_denied'])
  311. );
  312. return false;
  313. }
  314. if (isset($password_new) && isset($password_new2)) {
  315. if (!empty($password_new2) && !empty($password_new)) {
  316. if ($password_new2 != $password_new) {
  317. $_SESSION['return'] = array(
  318. 'type' => 'danger',
  319. 'msg' => sprintf($lang['danger']['password_mismatch'])
  320. );
  321. return false;
  322. }
  323. if (!preg_match('/' . $GLOBALS['PASSWD_REGEP'] . '/', $password_new)) {
  324. $_SESSION['return'] = array(
  325. 'type' => 'danger',
  326. 'msg' => sprintf($lang['danger']['password_complexity'])
  327. );
  328. return false;
  329. }
  330. $password_hashed = hash_password($password_new);
  331. try {
  332. $stmt = $pdo->prepare("UPDATE `mailbox` SET `password` = :password_hashed WHERE `username` = :username");
  333. $stmt->execute(array(
  334. ':password_hashed' => $password_hashed,
  335. ':username' => $username
  336. ));
  337. }
  338. catch (PDOException $e) {
  339. $_SESSION['return'] = array(
  340. 'type' => 'danger',
  341. 'msg' => 'MySQL: '.$e
  342. );
  343. return false;
  344. }
  345. }
  346. }
  347. $_SESSION['return'] = array(
  348. 'type' => 'success',
  349. 'msg' => sprintf($lang['success']['mailbox_modified'], htmlspecialchars($username))
  350. );
  351. }
  352. function user_get_alias_details($username) {
  353. global $lang;
  354. global $pdo;
  355. if ($_SESSION['mailcow_cc_role'] == "user") {
  356. $username = $_SESSION['mailcow_cc_username'];
  357. }
  358. if (!filter_var($username, FILTER_VALIDATE_EMAIL)) {
  359. return false;
  360. }
  361. try {
  362. $data['address'] = $username;
  363. $stmt = $pdo->prepare("SELECT IFNULL(GROUP_CONCAT(`address` SEPARATOR ', '), '&#10008;') AS `aliases` FROM `alias`
  364. WHERE `goto` REGEXP :username_goto
  365. AND `address` NOT LIKE '@%'
  366. AND `address` != :username_address");
  367. $stmt->execute(array(':username_goto' => '(^|,)'.$username.'($|,)', ':username_address' => $username));
  368. $run = $stmt->fetchAll(PDO::FETCH_ASSOC);
  369. while ($row = array_shift($run)) {
  370. $data['aliases'] = $row['aliases'];
  371. }
  372. $stmt = $pdo->prepare("SELECT IFNULL(GROUP_CONCAT(local_part, '@', alias_domain SEPARATOR ', '), '&#10008;') AS `ad_alias` FROM `mailbox`
  373. LEFT OUTER JOIN `alias_domain` on `target_domain` = `domain`
  374. WHERE `username` = :username ;");
  375. $stmt->execute(array(':username' => $username));
  376. $run = $stmt->fetchAll(PDO::FETCH_ASSOC);
  377. while ($row = array_shift($run)) {
  378. $data['ad_alias'] = $row['ad_alias'];
  379. }
  380. $stmt = $pdo->prepare("SELECT IFNULL(GROUP_CONCAT(`send_as` SEPARATOR ', '), '&#10008;') AS `send_as` FROM `sender_acl` WHERE `logged_in_as` = :username AND `send_as` NOT LIKE '@%';");
  381. $stmt->execute(array(':username' => $username));
  382. $run = $stmt->fetchAll(PDO::FETCH_ASSOC);
  383. while ($row = array_shift($run)) {
  384. $data['aliases_also_send_as'] = $row['send_as'];
  385. }
  386. $stmt = $pdo->prepare("SELECT IFNULL(GROUP_CONCAT(`send_as` SEPARATOR ', '), '&#10008;') AS `send_as` FROM `sender_acl` WHERE `logged_in_as` = :username AND `send_as` LIKE '@%';");
  387. $stmt->execute(array(':username' => $username));
  388. $run = $stmt->fetchAll(PDO::FETCH_ASSOC);
  389. while ($row = array_shift($run)) {
  390. $data['aliases_send_as_all'] = $row['send_as'];
  391. }
  392. $stmt = $pdo->prepare("SELECT IFNULL(GROUP_CONCAT(`address` SEPARATOR ', '), '&#10008;') as `address` FROM `alias` WHERE `goto` REGEXP :username AND `address` LIKE '@%';");
  393. $stmt->execute(array(':username' => '(^|,)'.$username.'($|,)'));
  394. $run = $stmt->fetchAll(PDO::FETCH_ASSOC);
  395. while ($row = array_shift($run)) {
  396. $data['is_catch_all'] = $row['address'];
  397. }
  398. return $data;
  399. }
  400. catch(PDOException $e) {
  401. $_SESSION['return'] = array(
  402. 'type' => 'danger',
  403. 'msg' => 'MySQL: '.$e
  404. );
  405. return false;
  406. }
  407. }
  408. function is_valid_domain_name($domain_name) {
  409. if (empty($domain_name)) {
  410. return false;
  411. }
  412. $domain_name = idn_to_ascii($domain_name);
  413. return (preg_match("/^([a-z\d](-*[a-z\d])*)(\.([a-z\d](-*[a-z\d])*))*$/i", $domain_name)
  414. && preg_match("/^.{1,253}$/", $domain_name)
  415. && preg_match("/^[^\.]{1,63}(\.[^\.]{1,63})*$/", $domain_name));
  416. }
  417. function add_domain_admin($postarray) {
  418. global $lang;
  419. global $pdo;
  420. $username = strtolower(trim($postarray['username']));
  421. $password = $postarray['password'];
  422. $password2 = $postarray['password2'];
  423. $domains = (array)$postarray['domains'];
  424. $active = intval($postarray['active']);
  425. if ($_SESSION['mailcow_cc_role'] != "admin") {
  426. $_SESSION['return'] = array(
  427. 'type' => 'danger',
  428. 'msg' => sprintf($lang['danger']['access_denied'])
  429. );
  430. return false;
  431. }
  432. if (empty($domains)) {
  433. $_SESSION['return'] = array(
  434. 'type' => 'danger',
  435. 'msg' => sprintf($lang['danger']['domain_invalid'])
  436. );
  437. return false;
  438. }
  439. if (!ctype_alnum(str_replace(array('_', '.', '-'), '', $username)) || empty ($username)) {
  440. $_SESSION['return'] = array(
  441. 'type' => 'danger',
  442. 'msg' => sprintf($lang['danger']['username_invalid'])
  443. );
  444. return false;
  445. }
  446. try {
  447. $stmt = $pdo->prepare("SELECT `username` FROM `mailbox`
  448. WHERE `username` = :username");
  449. $stmt->execute(array(':username' => $username));
  450. $num_results[] = count($stmt->fetchAll(PDO::FETCH_ASSOC));
  451. $stmt = $pdo->prepare("SELECT `username` FROM `admin`
  452. WHERE `username` = :username");
  453. $stmt->execute(array(':username' => $username));
  454. $num_results[] = count($stmt->fetchAll(PDO::FETCH_ASSOC));
  455. $stmt = $pdo->prepare("SELECT `username` FROM `domain_admins`
  456. WHERE `username` = :username");
  457. $stmt->execute(array(':username' => $username));
  458. $num_results[] = count($stmt->fetchAll(PDO::FETCH_ASSOC));
  459. }
  460. catch(PDOException $e) {
  461. $_SESSION['return'] = array(
  462. 'type' => 'danger',
  463. 'msg' => 'MySQL: '.$e
  464. );
  465. return false;
  466. }
  467. foreach ($num_results as $num_results_each) {
  468. if ($num_results_each != 0) {
  469. $_SESSION['return'] = array(
  470. 'type' => 'danger',
  471. 'msg' => sprintf($lang['danger']['object_exists'], htmlspecialchars($username))
  472. );
  473. return false;
  474. }
  475. }
  476. if (!empty($password) && !empty($password2)) {
  477. if (!preg_match('/' . $GLOBALS['PASSWD_REGEP'] . '/', $password)) {
  478. $_SESSION['return'] = array(
  479. 'type' => 'danger',
  480. 'msg' => sprintf($lang['danger']['password_complexity'])
  481. );
  482. return false;
  483. }
  484. if ($password != $password2) {
  485. $_SESSION['return'] = array(
  486. 'type' => 'danger',
  487. 'msg' => sprintf($lang['danger']['password_mismatch'])
  488. );
  489. return false;
  490. }
  491. $password_hashed = hash_password($password);
  492. foreach ($domains as $domain) {
  493. if (!is_valid_domain_name($domain)) {
  494. $_SESSION['return'] = array(
  495. 'type' => 'danger',
  496. 'msg' => sprintf($lang['danger']['domain_invalid'])
  497. );
  498. return false;
  499. }
  500. try {
  501. $stmt = $pdo->prepare("INSERT INTO `domain_admins` (`username`, `domain`, `created`, `active`)
  502. VALUES (:username, :domain, :created, :active)");
  503. $stmt->execute(array(
  504. ':username' => $username,
  505. ':domain' => $domain,
  506. ':created' => date('Y-m-d H:i:s'),
  507. ':active' => $active
  508. ));
  509. }
  510. catch (PDOException $e) {
  511. delete_domain_admin(array('username' => $username));
  512. $_SESSION['return'] = array(
  513. 'type' => 'danger',
  514. 'msg' => 'MySQL: '.$e
  515. );
  516. return false;
  517. }
  518. }
  519. try {
  520. $stmt = $pdo->prepare("INSERT INTO `admin` (`username`, `password`, `superadmin`, `active`)
  521. VALUES (:username, :password_hashed, '0', :active)");
  522. $stmt->execute(array(
  523. ':username' => $username,
  524. ':password_hashed' => $password_hashed,
  525. ':active' => $active
  526. ));
  527. }
  528. catch (PDOException $e) {
  529. $_SESSION['return'] = array(
  530. 'type' => 'danger',
  531. 'msg' => 'MySQL: '.$e
  532. );
  533. return false;
  534. }
  535. }
  536. else {
  537. $_SESSION['return'] = array(
  538. 'type' => 'danger',
  539. 'msg' => sprintf($lang['danger']['password_empty'])
  540. );
  541. return false;
  542. }
  543. $_SESSION['return'] = array(
  544. 'type' => 'success',
  545. 'msg' => sprintf($lang['success']['domain_admin_added'], htmlspecialchars($username))
  546. );
  547. }
  548. function delete_domain_admin($postarray) {
  549. global $pdo;
  550. global $lang;
  551. if ($_SESSION['mailcow_cc_role'] != "admin") {
  552. $_SESSION['return'] = array(
  553. 'type' => 'danger',
  554. 'msg' => sprintf($lang['danger']['access_denied'])
  555. );
  556. return false;
  557. }
  558. $usernames = (array)$postarray['username'];
  559. foreach ($usernames as $username) {
  560. if (!ctype_alnum(str_replace(array('_', '.', '-'), '', $username))) {
  561. $_SESSION['return'] = array(
  562. 'type' => 'danger',
  563. 'msg' => sprintf($lang['danger']['username_invalid'])
  564. );
  565. return false;
  566. }
  567. try {
  568. $stmt = $pdo->prepare("DELETE FROM `domain_admins` WHERE `username` = :username");
  569. $stmt->execute(array(
  570. ':username' => $username,
  571. ));
  572. $stmt = $pdo->prepare("DELETE FROM `admin` WHERE `username` = :username");
  573. $stmt->execute(array(
  574. ':username' => $username,
  575. ));
  576. }
  577. catch (PDOException $e) {
  578. $_SESSION['return'] = array(
  579. 'type' => 'danger',
  580. 'msg' => 'MySQL: '.$e
  581. );
  582. return false;
  583. }
  584. }
  585. $_SESSION['return'] = array(
  586. 'type' => 'success',
  587. 'msg' => sprintf($lang['success']['domain_admin_removed'], htmlspecialchars(implode(', ', $usernames)))
  588. );
  589. }
  590. function get_domain_admins() {
  591. global $pdo;
  592. global $lang;
  593. $domainadmins = array();
  594. if ($_SESSION['mailcow_cc_role'] != "admin") {
  595. $_SESSION['return'] = array(
  596. 'type' => 'danger',
  597. 'msg' => sprintf($lang['danger']['access_denied'])
  598. );
  599. return false;
  600. }
  601. try {
  602. $stmt = $pdo->query("SELECT DISTINCT
  603. `username`
  604. FROM `domain_admins`
  605. WHERE `username` IN (
  606. SELECT `username` FROM `admin`
  607. WHERE `superadmin`!='1'
  608. )");
  609. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  610. while ($row = array_shift($rows)) {
  611. $domainadmins[] = $row['username'];
  612. }
  613. }
  614. catch(PDOException $e) {
  615. $_SESSION['return'] = array(
  616. 'type' => 'danger',
  617. 'msg' => 'MySQL: '.$e
  618. );
  619. }
  620. return $domainadmins;
  621. }
  622. function get_domain_admin_details($domain_admin) {
  623. global $pdo;
  624. global $lang;
  625. $domainadmindata = array();
  626. if (isset($domain_admin) && $_SESSION['mailcow_cc_role'] != "admin") {
  627. return false;
  628. }
  629. if (!isset($domain_admin) && $_SESSION['mailcow_cc_role'] != "domainadmin") {
  630. return false;
  631. }
  632. (!isset($domain_admin)) ? $domain_admin = $_SESSION['mailcow_cc_username'] : null;
  633. if (!ctype_alnum(str_replace(array('_', '.', '-'), '', $domain_admin))) {
  634. return false;
  635. }
  636. try {
  637. $stmt = $pdo->prepare("SELECT
  638. `tfa`.`active` AS `tfa_active_int`,
  639. CASE `tfa`.`active` WHEN 1 THEN '".$lang['mailbox']['yes']."' ELSE '".$lang['mailbox']['no']."' END AS `tfa_active`,
  640. `domain_admins`.`username`,
  641. `domain_admins`.`created`,
  642. `domain_admins`.`active` AS `active_int`,
  643. CASE `domain_admins`.`active` WHEN 1 THEN '".$lang['mailbox']['yes']."' ELSE '".$lang['mailbox']['no']."' END AS `active`
  644. FROM `domain_admins`
  645. LEFT OUTER JOIN `tfa` ON `tfa`.`username`=`domain_admins`.`username`
  646. WHERE `domain_admins`.`username`= :domain_admin");
  647. $stmt->execute(array(
  648. ':domain_admin' => $domain_admin
  649. ));
  650. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  651. if (empty($row)) {
  652. return false;
  653. }
  654. $domainadmindata['username'] = $row['username'];
  655. $domainadmindata['tfa_active'] = $row['tfa_active'];
  656. $domainadmindata['active'] = $row['active'];
  657. $domainadmindata['tfa_active_int'] = $row['tfa_active_int'];
  658. $domainadmindata['active_int'] = $row['active_int'];
  659. $domainadmindata['modified'] = $row['created'];
  660. // GET SELECTED
  661. $stmt = $pdo->prepare("SELECT `domain` FROM `domain`
  662. WHERE `domain` IN (
  663. SELECT `domain` FROM `domain_admins`
  664. WHERE `username`= :domain_admin)");
  665. $stmt->execute(array(':domain_admin' => $domain_admin));
  666. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  667. while($row = array_shift($rows)) {
  668. $domainadmindata['selected_domains'][] = $row['domain'];
  669. }
  670. // GET UNSELECTED
  671. $stmt = $pdo->prepare("SELECT `domain` FROM `domain`
  672. WHERE `domain` NOT IN (
  673. SELECT `domain` FROM `domain_admins`
  674. WHERE `username`= :domain_admin)");
  675. $stmt->execute(array(':domain_admin' => $domain_admin));
  676. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  677. while($row = array_shift($rows)) {
  678. $domainadmindata['unselected_domains'][] = $row['domain'];
  679. }
  680. if (!isset($domainadmindata['unselected_domains'])) {
  681. $domainadmindata['unselected_domains'] = "";
  682. }
  683. }
  684. catch(PDOException $e) {
  685. $_SESSION['return'] = array(
  686. 'type' => 'danger',
  687. 'msg' => 'MySQL: '.$e
  688. );
  689. }
  690. return $domainadmindata;
  691. }
  692. function set_tfa($postarray) {
  693. global $lang;
  694. global $pdo;
  695. global $yubi;
  696. global $u2f;
  697. global $tfa;
  698. if ($_SESSION['mailcow_cc_role'] != "domainadmin" &&
  699. $_SESSION['mailcow_cc_role'] != "admin") {
  700. $_SESSION['return'] = array(
  701. 'type' => 'danger',
  702. 'msg' => sprintf($lang['danger']['access_denied'])
  703. );
  704. return false;
  705. }
  706. $username = $_SESSION['mailcow_cc_username'];
  707. $stmt = $pdo->prepare("SELECT `password` FROM `admin`
  708. WHERE `username` = :user");
  709. $stmt->execute(array(':user' => $username));
  710. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  711. if (!verify_ssha256($row['password'], $postarray["confirm_password"])) {
  712. $_SESSION['return'] = array(
  713. 'type' => 'danger',
  714. 'msg' => sprintf($lang['danger']['access_denied'])
  715. );
  716. return false;
  717. }
  718. switch ($postarray["tfa_method"]) {
  719. case "yubi_otp":
  720. $key_id = (!isset($postarray["key_id"])) ? 'unidentified' : $postarray["key_id"];
  721. $yubico_id = $postarray['yubico_id'];
  722. $yubico_key = $postarray['yubico_key'];
  723. $yubi = new Auth_Yubico($yubico_id, $yubico_key);
  724. if (!$yubi) {
  725. $_SESSION['return'] = array(
  726. 'type' => 'danger',
  727. 'msg' => sprintf($lang['danger']['access_denied'])
  728. );
  729. return false;
  730. }
  731. if (!ctype_alnum($postarray["otp_token"]) || strlen($postarray["otp_token"]) != 44) {
  732. $_SESSION['return'] = array(
  733. 'type' => 'danger',
  734. 'msg' => sprintf($lang['danger']['tfa_token_invalid'])
  735. );
  736. return false;
  737. }
  738. $yauth = $yubi->verify($postarray["otp_token"]);
  739. if (PEAR::isError($yauth)) {
  740. $_SESSION['return'] = array(
  741. 'type' => 'danger',
  742. 'msg' => 'Yubico API: ' . $yauth->getMessage()
  743. );
  744. return false;
  745. }
  746. try {
  747. // We could also do a modhex translation here
  748. $yubico_modhex_id = substr($postarray["otp_token"], 0, 12);
  749. $stmt = $pdo->prepare("DELETE FROM `tfa`
  750. WHERE `username` = :username
  751. AND (`authmech` != 'yubi_otp')
  752. OR (`authmech` = 'yubi_otp' AND `secret` LIKE :modhex)");
  753. $stmt->execute(array(':username' => $username, ':modhex' => '%' . $yubico_modhex_id));
  754. $stmt = $pdo->prepare("INSERT INTO `tfa` (`key_id`, `username`, `authmech`, `active`, `secret`) VALUES
  755. (:key_id, :username, 'yubi_otp', '1', :secret)");
  756. $stmt->execute(array(':key_id' => $key_id, ':username' => $username, ':secret' => $yubico_id . ':' . $yubico_key . ':' . $yubico_modhex_id));
  757. }
  758. catch (PDOException $e) {
  759. $_SESSION['return'] = array(
  760. 'type' => 'danger',
  761. 'msg' => 'MySQL: '.$e
  762. );
  763. return false;
  764. }
  765. $_SESSION['return'] = array(
  766. 'type' => 'success',
  767. 'msg' => sprintf($lang['success']['object_modified'], htmlspecialchars($username))
  768. );
  769. break;
  770. case "u2f":
  771. $key_id = (!isset($postarray["key_id"])) ? 'unidentified' : $postarray["key_id"];
  772. try {
  773. $reg = $u2f->doRegister(json_decode($_SESSION['regReq']), json_decode($postarray['token']));
  774. $stmt = $pdo->prepare("DELETE FROM `tfa` WHERE `username` = :username AND `authmech` != 'u2f'");
  775. $stmt->execute(array(':username' => $username));
  776. $stmt = $pdo->prepare("INSERT INTO `tfa` (`username`, `key_id`, `authmech`, `keyHandle`, `publicKey`, `certificate`, `counter`, `active`) VALUES (?, ?, 'u2f', ?, ?, ?, ?, '1')");
  777. $stmt->execute(array($username, $key_id, $reg->keyHandle, $reg->publicKey, $reg->certificate, $reg->counter));
  778. $_SESSION['return'] = array(
  779. 'type' => 'success',
  780. 'msg' => sprintf($lang['success']['object_modified'], $username)
  781. );
  782. $_SESSION['regReq'] = null;
  783. }
  784. catch (Exception $e) {
  785. $_SESSION['return'] = array(
  786. 'type' => 'danger',
  787. 'msg' => "U2F: " . $e->getMessage()
  788. );
  789. $_SESSION['regReq'] = null;
  790. return false;
  791. }
  792. break;
  793. case "totp":
  794. $key_id = (!isset($postarray["key_id"])) ? 'unidentified' : $postarray["key_id"];
  795. if ($tfa->verifyCode($_POST['totp_secret'], $_POST['totp_confirm_token']) === true) {
  796. try {
  797. $stmt = $pdo->prepare("DELETE FROM `tfa` WHERE `username` = :username");
  798. $stmt->execute(array(':username' => $username));
  799. $stmt = $pdo->prepare("INSERT INTO `tfa` (`username`, `key_id`, `authmech`, `secret`, `active`) VALUES (?, ?, 'totp', ?, '1')");
  800. $stmt->execute(array($username, $key_id, $_POST['totp_secret']));
  801. }
  802. catch (PDOException $e) {
  803. $_SESSION['return'] = array(
  804. 'type' => 'danger',
  805. 'msg' => 'MySQL: '.$e
  806. );
  807. return false;
  808. }
  809. $_SESSION['return'] = array(
  810. 'type' => 'success',
  811. 'msg' => sprintf($lang['success']['object_modified'], $username)
  812. );
  813. }
  814. else {
  815. $_SESSION['return'] = array(
  816. 'type' => 'danger',
  817. 'msg' => 'TOTP verification failed'
  818. );
  819. }
  820. break;
  821. case "none":
  822. try {
  823. $stmt = $pdo->prepare("DELETE FROM `tfa` WHERE `username` = :username");
  824. $stmt->execute(array(':username' => $username));
  825. }
  826. catch (PDOException $e) {
  827. $_SESSION['return'] = array(
  828. 'type' => 'danger',
  829. 'msg' => 'MySQL: '.$e
  830. );
  831. return false;
  832. }
  833. $_SESSION['return'] = array(
  834. 'type' => 'success',
  835. 'msg' => sprintf($lang['success']['object_modified'], htmlspecialchars($username))
  836. );
  837. break;
  838. }
  839. }
  840. function unset_tfa_key($postarray) {
  841. // Can only unset own keys
  842. // Needs at least one key left
  843. global $pdo;
  844. global $lang;
  845. $id = intval($postarray['unset_tfa_key']);
  846. if ($_SESSION['mailcow_cc_role'] != "domainadmin" &&
  847. $_SESSION['mailcow_cc_role'] != "admin") {
  848. $_SESSION['return'] = array(
  849. 'type' => 'danger',
  850. 'msg' => sprintf($lang['danger']['access_denied'])
  851. );
  852. return false;
  853. }
  854. $username = $_SESSION['mailcow_cc_username'];
  855. try {
  856. if (!is_numeric($id)) {
  857. $_SESSION['return'] = array(
  858. 'type' => 'danger',
  859. 'msg' => sprintf($lang['danger']['access_denied'])
  860. );
  861. return false;
  862. }
  863. $stmt = $pdo->prepare("SELECT COUNT(*) AS `keys` FROM `tfa`
  864. WHERE `username` = :username AND `active` = '1'");
  865. $stmt->execute(array(':username' => $username));
  866. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  867. if ($row['keys'] == "1") {
  868. $_SESSION['return'] = array(
  869. 'type' => 'danger',
  870. 'msg' => sprintf($lang['danger']['last_key'])
  871. );
  872. return false;
  873. }
  874. $stmt = $pdo->prepare("DELETE FROM `tfa` WHERE `username` = :username AND `id` = :id");
  875. $stmt->execute(array(':username' => $username, ':id' => $id));
  876. $_SESSION['return'] = array(
  877. 'type' => 'success',
  878. 'msg' => sprintf($lang['success']['object_modified'], $username)
  879. );
  880. }
  881. catch (PDOException $e) {
  882. $_SESSION['return'] = array(
  883. 'type' => 'danger',
  884. 'msg' => 'MySQL: '.$e
  885. );
  886. return false;
  887. }
  888. }
  889. function get_tfa($username = null) {
  890. global $pdo;
  891. if (isset($_SESSION['mailcow_cc_username'])) {
  892. $username = $_SESSION['mailcow_cc_username'];
  893. }
  894. elseif (empty($username)) {
  895. return false;
  896. }
  897. $stmt = $pdo->prepare("SELECT * FROM `tfa`
  898. WHERE `username` = :username AND `active` = '1'");
  899. $stmt->execute(array(':username' => $username));
  900. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  901. switch ($row["authmech"]) {
  902. case "yubi_otp":
  903. $data['name'] = "yubi_otp";
  904. $data['pretty'] = "Yubico OTP";
  905. $stmt = $pdo->prepare("SELECT `id`, `key_id`, RIGHT(`secret`, 12) AS 'modhex' FROM `tfa` WHERE `authmech` = 'yubi_otp' AND `username` = :username");
  906. $stmt->execute(array(
  907. ':username' => $username,
  908. ));
  909. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  910. while($row = array_shift($rows)) {
  911. $data['additional'][] = $row;
  912. }
  913. return $data;
  914. break;
  915. case "u2f":
  916. $data['name'] = "u2f";
  917. $data['pretty'] = "Fido U2F";
  918. $stmt = $pdo->prepare("SELECT `id`, `key_id` FROM `tfa` WHERE `authmech` = 'u2f' AND `username` = :username");
  919. $stmt->execute(array(
  920. ':username' => $username,
  921. ));
  922. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  923. while($row = array_shift($rows)) {
  924. $data['additional'][] = $row;
  925. }
  926. return $data;
  927. break;
  928. case "hotp":
  929. $data['name'] = "hotp";
  930. $data['pretty'] = "HMAC-based OTP";
  931. return $data;
  932. break;
  933. case "totp":
  934. $data['name'] = "totp";
  935. $data['pretty'] = "Time-based OTP";
  936. $stmt = $pdo->prepare("SELECT `id`, `key_id`, `secret` FROM `tfa` WHERE `authmech` = 'totp' AND `username` = :username");
  937. $stmt->execute(array(
  938. ':username' => $username,
  939. ));
  940. $rows = $stmt->fetchAll(PDO::FETCH_ASSOC);
  941. while($row = array_shift($rows)) {
  942. $data['additional'][] = $row;
  943. }
  944. return $data;
  945. break;
  946. default:
  947. $data['name'] = 'none';
  948. $data['pretty'] = "-";
  949. return $data;
  950. break;
  951. }
  952. }
  953. function verify_tfa_login($username, $token) {
  954. global $pdo;
  955. global $lang;
  956. global $yubi;
  957. global $u2f;
  958. global $tfa;
  959. $stmt = $pdo->prepare("SELECT `authmech` FROM `tfa`
  960. WHERE `username` = :username AND `active` = '1'");
  961. $stmt->execute(array(':username' => $username));
  962. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  963. switch ($row["authmech"]) {
  964. case "yubi_otp":
  965. if (!ctype_alnum($token) || strlen($token) != 44) {
  966. return false;
  967. }
  968. $yubico_modhex_id = substr($token, 0, 12);
  969. $stmt = $pdo->prepare("SELECT `id`, `secret` FROM `tfa`
  970. WHERE `username` = :username
  971. AND `authmech` = 'yubi_otp'
  972. AND `active`='1'
  973. AND `secret` LIKE :modhex");
  974. $stmt->execute(array(':username' => $username, ':modhex' => '%' . $yubico_modhex_id));
  975. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  976. $yubico_auth = explode(':', $row['secret']);
  977. $yubi = new Auth_Yubico($yubico_auth[0], $yubico_auth[1]);
  978. $yauth = $yubi->verify($token);
  979. if (PEAR::isError($yauth)) {
  980. $_SESSION['return'] = array(
  981. 'type' => 'danger',
  982. 'msg' => 'Yubico Authentication error: ' . $yauth->getMessage()
  983. );
  984. return false;
  985. }
  986. else {
  987. $_SESSION['tfa_id'] = $row['id'];
  988. return true;
  989. }
  990. return false;
  991. break;
  992. case "u2f":
  993. try {
  994. $reg = $u2f->doAuthenticate(json_decode($_SESSION['authReq']), get_u2f_registrations($username), json_decode($token));
  995. $stmt = $pdo->prepare("UPDATE `tfa` SET `counter` = ? WHERE `id` = ?");
  996. $stmt->execute(array($reg->counter, $reg->id));
  997. $_SESSION['tfa_id'] = $reg->id;
  998. $_SESSION['authReq'] = null;
  999. return true;
  1000. }
  1001. catch (Exception $e) {
  1002. $_SESSION['return'] = array(
  1003. 'type' => 'danger',
  1004. 'msg' => "U2F: " . $e->getMessage()
  1005. );
  1006. $_SESSION['regReq'] = null;
  1007. return false;
  1008. }
  1009. return false;
  1010. break;
  1011. case "hotp":
  1012. return false;
  1013. break;
  1014. case "totp":
  1015. try {
  1016. $stmt = $pdo->prepare("SELECT `id`, `secret` FROM `tfa`
  1017. WHERE `username` = :username
  1018. AND `authmech` = 'totp'
  1019. AND `active`='1'");
  1020. $stmt->execute(array(':username' => $username));
  1021. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  1022. if ($tfa->verifyCode($row['secret'], $_POST['token']) === true) {
  1023. $_SESSION['tfa_id'] = $row['id'];
  1024. return true;
  1025. }
  1026. return false;
  1027. }
  1028. catch (PDOException $e) {
  1029. $_SESSION['return'] = array(
  1030. 'type' => 'danger',
  1031. 'msg' => 'MySQL: '.$e
  1032. );
  1033. return false;
  1034. }
  1035. break;
  1036. default:
  1037. return false;
  1038. break;
  1039. }
  1040. return false;
  1041. }
  1042. function edit_domain_admin($postarray) {
  1043. global $lang;
  1044. global $pdo;
  1045. if ($_SESSION['mailcow_cc_role'] != "admin" && $_SESSION['mailcow_cc_role'] != "domainadmin") {
  1046. $_SESSION['return'] = array(
  1047. 'type' => 'danger',
  1048. 'msg' => sprintf($lang['danger']['access_denied'])
  1049. );
  1050. return false;
  1051. }
  1052. // Administrator
  1053. if ($_SESSION['mailcow_cc_role'] == "admin") {
  1054. if (!is_array($postarray['username'])) {
  1055. $usernames = array();
  1056. $usernames[] = $postarray['username'];
  1057. }
  1058. else {
  1059. $usernames = $postarray['username'];
  1060. }
  1061. foreach ($usernames as $username) {
  1062. $is_now = get_domain_admin_details($username);
  1063. $domains = (isset($postarray['domains'])) ? (array)$postarray['domains'] : null;
  1064. if (!empty($is_now)) {
  1065. $active = (isset($postarray['active'])) ? $postarray['active'] : $is_now['active_int'];
  1066. $domains = (!empty($domains)) ? $domains : $is_now['selected_domains'];
  1067. $username_new = (!empty($postarray['username_new'])) ? $postarray['username_new'] : $is_now['username'];
  1068. }
  1069. else {
  1070. $_SESSION['return'] = array(
  1071. 'type' => 'danger',
  1072. 'msg' => sprintf($lang['danger']['access_denied'])
  1073. );
  1074. return false;
  1075. }
  1076. $password = $postarray['password'];
  1077. $password2 = $postarray['password2'];
  1078. if (!empty($domains)) {
  1079. foreach ($domains as $domain) {
  1080. if (!is_valid_domain_name($domain)) {
  1081. $_SESSION['return'] = array(
  1082. 'type' => 'danger',
  1083. 'msg' => sprintf($lang['danger']['domain_invalid'])
  1084. );
  1085. return false;
  1086. }
  1087. }
  1088. }
  1089. if (!ctype_alnum(str_replace(array('_', '.', '-'), '', $username_new))) {
  1090. $_SESSION['return'] = array(
  1091. 'type' => 'danger',
  1092. 'msg' => sprintf($lang['danger']['username_invalid'])
  1093. );
  1094. return false;
  1095. }
  1096. if ($username_new != $username) {
  1097. if (!empty(get_domain_admin_details($username_new)['username'])) {
  1098. $_SESSION['return'] = array(
  1099. 'type' => 'danger',
  1100. 'msg' => sprintf($lang['danger']['username_invalid'])
  1101. );
  1102. return false;
  1103. }
  1104. }
  1105. try {
  1106. $stmt = $pdo->prepare("DELETE FROM `domain_admins` WHERE `username` = :username");
  1107. $stmt->execute(array(
  1108. ':username' => $username,
  1109. ));
  1110. }
  1111. catch (PDOException $e) {
  1112. $_SESSION['return'] = array(
  1113. 'type' => 'danger',
  1114. 'msg' => 'MySQL: '.$e
  1115. );
  1116. return false;
  1117. }
  1118. if (!empty($domains)) {
  1119. foreach ($domains as $domain) {
  1120. try {
  1121. $stmt = $pdo->prepare("INSERT INTO `domain_admins` (`username`, `domain`, `created`, `active`)
  1122. VALUES (:username_new, :domain, :created, :active)");
  1123. $stmt->execute(array(
  1124. ':username_new' => $username_new,
  1125. ':domain' => $domain,
  1126. ':created' => date('Y-m-d H:i:s'),
  1127. ':active' => $active
  1128. ));
  1129. }
  1130. catch (PDOException $e) {
  1131. $_SESSION['return'] = array(
  1132. 'type' => 'danger',
  1133. 'msg' => 'MySQL: '.$e
  1134. );
  1135. return false;
  1136. }
  1137. }
  1138. }
  1139. if (!empty($password) && !empty($password2)) {
  1140. if (!preg_match('/' . $GLOBALS['PASSWD_REGEP'] . '/', $password)) {
  1141. $_SESSION['return'] = array(
  1142. 'type' => 'danger',
  1143. 'msg' => sprintf($lang['danger']['password_complexity'])
  1144. );
  1145. return false;
  1146. }
  1147. if ($password != $password2) {
  1148. $_SESSION['return'] = array(
  1149. 'type' => 'danger',
  1150. 'msg' => sprintf($lang['danger']['password_mismatch'])
  1151. );
  1152. return false;
  1153. }
  1154. $password_hashed = hash_password($password);
  1155. try {
  1156. $stmt = $pdo->prepare("UPDATE `admin` SET `username` = :username_new, `active` = :active, `password` = :password_hashed WHERE `username` = :username");
  1157. $stmt->execute(array(
  1158. ':password_hashed' => $password_hashed,
  1159. ':username_new' => $username_new,
  1160. ':username' => $username,
  1161. ':active' => $active
  1162. ));
  1163. if (isset($postarray['disable_tfa'])) {
  1164. $stmt = $pdo->prepare("UPDATE `tfa` SET `active` = '0' WHERE `username` = :username");
  1165. $stmt->execute(array(':username' => $username));
  1166. }
  1167. else {
  1168. $stmt = $pdo->prepare("UPDATE `tfa` SET `username` = :username_new WHERE `username` = :username");
  1169. $stmt->execute(array(':username_new' => $username_new, ':username' => $username));
  1170. }
  1171. }
  1172. catch (PDOException $e) {
  1173. $_SESSION['return'] = array(
  1174. 'type' => 'danger',
  1175. 'msg' => 'MySQL: '.$e
  1176. );
  1177. return false;
  1178. }
  1179. }
  1180. else {
  1181. try {
  1182. $stmt = $pdo->prepare("UPDATE `admin` SET `username` = :username_new, `active` = :active WHERE `username` = :username");
  1183. $stmt->execute(array(
  1184. ':username_new' => $username_new,
  1185. ':username' => $username,
  1186. ':active' => $active
  1187. ));
  1188. if (isset($postarray['disable_tfa'])) {
  1189. $stmt = $pdo->prepare("UPDATE `tfa` SET `active` = '0' WHERE `username` = :username");
  1190. $stmt->execute(array(':username' => $username));
  1191. }
  1192. else {
  1193. $stmt = $pdo->prepare("UPDATE `tfa` SET `username` = :username_new WHERE `username` = :username");
  1194. $stmt->execute(array(':username_new' => $username_new, ':username' => $username));
  1195. }
  1196. }
  1197. catch (PDOException $e) {
  1198. $_SESSION['return'] = array(
  1199. 'type' => 'danger',
  1200. 'msg' => 'MySQL: '.$e
  1201. );
  1202. return false;
  1203. }
  1204. }
  1205. }
  1206. $_SESSION['return'] = array(
  1207. 'type' => 'success',
  1208. 'msg' => sprintf($lang['success']['domain_admin_modified'], htmlspecialchars(implode(', ', $usernames)))
  1209. );
  1210. }
  1211. // Domain administrator
  1212. // Can only edit itself
  1213. elseif ($_SESSION['mailcow_cc_role'] == "domainadmin") {
  1214. $username = $_SESSION['mailcow_cc_username'];
  1215. $password_old = $postarray['user_old_pass'];
  1216. $password_new = $postarray['user_new_pass'];
  1217. $password_new2 = $postarray['user_new_pass2'];
  1218. $stmt = $pdo->prepare("SELECT `password` FROM `admin`
  1219. WHERE `username` = :user");
  1220. $stmt->execute(array(':user' => $username));
  1221. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  1222. if (!verify_ssha256($row['password'], $password_old)) {
  1223. $_SESSION['return'] = array(
  1224. 'type' => 'danger',
  1225. 'msg' => sprintf($lang['danger']['access_denied'])
  1226. );
  1227. return false;
  1228. }
  1229. if (!empty($password_new2) && !empty($password_new)) {
  1230. if ($password_new2 != $password_new) {
  1231. $_SESSION['return'] = array(
  1232. 'type' => 'danger',
  1233. 'msg' => sprintf($lang['danger']['password_mismatch'])
  1234. );
  1235. return false;
  1236. }
  1237. if (!preg_match('/' . $GLOBALS['PASSWD_REGEP'] . '/', $password_new)) {
  1238. $_SESSION['return'] = array(
  1239. 'type' => 'danger',
  1240. 'msg' => sprintf($lang['danger']['password_complexity'])
  1241. );
  1242. return false;
  1243. }
  1244. $password_hashed = hash_password($password_new);
  1245. try {
  1246. $stmt = $pdo->prepare("UPDATE `admin` SET `password` = :password_hashed WHERE `username` = :username");
  1247. $stmt->execute(array(
  1248. ':password_hashed' => $password_hashed,
  1249. ':username' => $username
  1250. ));
  1251. }
  1252. catch (PDOException $e) {
  1253. $_SESSION['return'] = array(
  1254. 'type' => 'danger',
  1255. 'msg' => 'MySQL: '.$e
  1256. );
  1257. return false;
  1258. }
  1259. }
  1260. $_SESSION['return'] = array(
  1261. 'type' => 'success',
  1262. 'msg' => sprintf($lang['success']['domain_admin_modified'], htmlspecialchars($username))
  1263. );
  1264. }
  1265. }
  1266. function get_admin_details() {
  1267. // No parameter to be given, only one admin should exist
  1268. global $pdo;
  1269. global $lang;
  1270. $data = array();
  1271. if ($_SESSION['mailcow_cc_role'] != 'admin') {
  1272. return false;
  1273. }
  1274. try {
  1275. $stmt = $pdo->prepare("SELECT `username`, `modified`, `created` FROM `admin` WHERE `superadmin`='1' AND active='1'");
  1276. $stmt->execute();
  1277. $data = $stmt->fetch(PDO::FETCH_ASSOC);
  1278. }
  1279. catch(PDOException $e) {
  1280. $_SESSION['return'] = array(
  1281. 'type' => 'danger',
  1282. 'msg' => 'MySQL: '.$e
  1283. );
  1284. }
  1285. return $data;
  1286. }
  1287. function get_u2f_registrations($username) {
  1288. global $pdo;
  1289. $sel = $pdo->prepare("SELECT * FROM `tfa` WHERE `authmech` = 'u2f' AND `username` = ? AND `active` = '1'");
  1290. $sel->execute(array($username));
  1291. return $sel->fetchAll(PDO::FETCH_OBJ);
  1292. }
  1293. function get_logs($container, $lines = 100) {
  1294. global $lang;
  1295. global $redis;
  1296. if ($_SESSION['mailcow_cc_role'] != "admin") {
  1297. return false;
  1298. }
  1299. $lines = intval($lines);
  1300. if ($container == "dovecot-mailcow") {
  1301. if ($data = $redis->lRange('DOVECOT_MAILLOG', 1, $lines)) {
  1302. foreach ($data as $json_line) {
  1303. $data_array[] = json_decode($json_line, true);
  1304. }
  1305. return $data_array;
  1306. }
  1307. }
  1308. if ($container == "postfix-mailcow") {
  1309. if ($data = $redis->lRange('POSTFIX_MAILLOG', 1, $lines)) {
  1310. foreach ($data as $json_line) {
  1311. $data_array[] = json_decode($json_line, true);
  1312. }
  1313. return $data_array;
  1314. }
  1315. }
  1316. if ($container == "sogo-mailcow") {
  1317. if ($data = $redis->lRange('SOGO_LOG', 1, $lines)) {
  1318. foreach ($data as $json_line) {
  1319. $data_array[] = json_decode($json_line, true);
  1320. }
  1321. return $data_array;
  1322. }
  1323. }
  1324. if ($container == "rspamd-history") {
  1325. $curl = curl_init();
  1326. curl_setopt($curl, CURLOPT_URL,"http://rspamd-mailcow:11334/history");
  1327. curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
  1328. $history = curl_exec($curl);
  1329. if (!curl_errno($ch)) {
  1330. $data_array = json_decode($history, true);
  1331. curl_close($curl);
  1332. return $data_array['rows'];
  1333. }
  1334. curl_close($curl);
  1335. return false;
  1336. }
  1337. return false;
  1338. }
  1339. ?>