autodiscover.php 6.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213
  1. <?php
  2. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/prerequisites.inc.php';
  3. $autodiscover_config = array_merge($default_autodiscover_config, $autodiscover_config);
  4. error_reporting(0);
  5. $data = trim(file_get_contents("php://input"));
  6. if (strpos($data, 'autodiscover/outlook/responseschema') !== false) {
  7. $autodiscover_config['autodiscoverType'] = 'imap';
  8. if ($autodiscover_config['useEASforOutlook'] == 'yes' &&
  9. // Office for macOS does not support EAS
  10. strpos($_SERVER['HTTP_USER_AGENT'], 'Mac') === false &&
  11. // Outlook 2013 (version 15) or higher
  12. preg_match('/(Outlook|Office).+1[5-9]\./', $_SERVER['HTTP_USER_AGENT'])
  13. ) {
  14. $autodiscover_config['autodiscoverType'] = 'activesync';
  15. }
  16. }
  17. if (getenv('SKIP_SOGO') == "y") {
  18. $autodiscover_config['autodiscoverType'] = 'imap';
  19. }
  20. //$dsn = $database_type . ":host=" . $database_host . ";dbname=" . $database_name;
  21. $dsn = $database_type . ":unix_socket=" . $database_sock . ";dbname=" . $database_name;
  22. $opt = [
  23. PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
  24. PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
  25. PDO::ATTR_EMULATE_PREPARES => false,
  26. ];
  27. $pdo = new PDO($dsn, $database_user, $database_pass, $opt);
  28. $login_user = strtolower(trim($_SERVER['PHP_AUTH_USER']));
  29. $login_pass = trim(htmlspecialchars_decode($_SERVER['PHP_AUTH_PW']));
  30. if (empty($_SERVER['PHP_AUTH_USER']) || empty($_SERVER['PHP_AUTH_PW'])) {
  31. $json = json_encode(
  32. array(
  33. "time" => time(),
  34. "ua" => $_SERVER['HTTP_USER_AGENT'],
  35. "user" => "none",
  36. "ip" => $_SERVER['REMOTE_ADDR'],
  37. "service" => "Error: must be authenticated"
  38. )
  39. );
  40. $redis->lPush('AUTODISCOVER_LOG', $json);
  41. header('WWW-Authenticate: Basic realm="' . $_SERVER['HTTP_HOST'] . '"');
  42. header('HTTP/1.0 401 Unauthorized');
  43. exit(0);
  44. }
  45. $login_role = check_login($login_user, $login_pass, array('eas' => TRUE));
  46. if ($login_role === "user") {
  47. header("Content-Type: application/xml");
  48. echo '<?xml version="1.0" encoding="utf-8" ?>' . PHP_EOL;
  49. ?>
  50. <Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006">
  51. <?php
  52. if(!$data) {
  53. try {
  54. $json = json_encode(
  55. array(
  56. "time" => time(),
  57. "ua" => $_SERVER['HTTP_USER_AGENT'],
  58. "user" => $_SERVER['PHP_AUTH_USER'],
  59. "ip" => $_SERVER['REMOTE_ADDR'],
  60. "service" => "Error: invalid or missing request data"
  61. )
  62. );
  63. $redis->lPush('AUTODISCOVER_LOG', $json);
  64. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  65. }
  66. catch (RedisException $e) {
  67. $_SESSION['return'][] = array(
  68. 'type' => 'danger',
  69. 'msg' => 'Redis: '.$e
  70. );
  71. return false;
  72. }
  73. list($usec, $sec) = explode(' ', microtime());
  74. ?>
  75. <Response>
  76. <Error Time="<?=date('H:i:s', $sec) . substr($usec, 0, strlen($usec) - 2);?>" Id="2477272013">
  77. <ErrorCode>600</ErrorCode>
  78. <Message>Invalid Request</Message>
  79. <DebugData />
  80. </Error>
  81. </Response>
  82. </Autodiscover>
  83. <?php
  84. exit(0);
  85. }
  86. try {
  87. $discover = new SimpleXMLElement($data);
  88. $email = $discover->Request->EMailAddress;
  89. } catch (Exception $e) {
  90. $email = $_SERVER['PHP_AUTH_USER'];
  91. }
  92. $username = trim($email);
  93. try {
  94. $stmt = $pdo->prepare("SELECT `name` FROM `mailbox` WHERE `username`= :username");
  95. $stmt->execute(array(':username' => $username));
  96. $MailboxData = $stmt->fetch(PDO::FETCH_ASSOC);
  97. }
  98. catch(PDOException $e) {
  99. die("Failed to determine name from SQL");
  100. }
  101. if (!empty($MailboxData['name'])) {
  102. $displayname = $MailboxData['name'];
  103. }
  104. else {
  105. $displayname = $email;
  106. }
  107. try {
  108. $json = json_encode(
  109. array(
  110. "time" => time(),
  111. "ua" => $_SERVER['HTTP_USER_AGENT'],
  112. "user" => $_SERVER['PHP_AUTH_USER'],
  113. "ip" => $_SERVER['REMOTE_ADDR'],
  114. "service" => $autodiscover_config['autodiscoverType']
  115. )
  116. );
  117. $redis->lPush('AUTODISCOVER_LOG', $json);
  118. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  119. }
  120. catch (RedisException $e) {
  121. $_SESSION['return'][] = array(
  122. 'type' => 'danger',
  123. 'msg' => 'Redis: '.$e
  124. );
  125. return false;
  126. }
  127. if ($autodiscover_config['autodiscoverType'] == 'imap') {
  128. ?>
  129. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a">
  130. <User>
  131. <DisplayName><?=htmlspecialchars($displayname, ENT_XML1 | ENT_QUOTES, 'UTF-8');?></DisplayName>
  132. </User>
  133. <Account>
  134. <AccountType>email</AccountType>
  135. <Action>settings</Action>
  136. <Protocol>
  137. <Type>IMAP</Type>
  138. <Server><?=$autodiscover_config['imap']['server'];?></Server>
  139. <Port><?=$autodiscover_config['imap']['port'];?></Port>
  140. <DomainRequired>off</DomainRequired>
  141. <LoginName><?=$email;?></LoginName>
  142. <SPA>off</SPA>
  143. <SSL>on</SSL>
  144. <AuthRequired>on</AuthRequired>
  145. </Protocol>
  146. <Protocol>
  147. <Type>SMTP</Type>
  148. <Server><?=$autodiscover_config['smtp']['server'];?></Server>
  149. <Port><?=$autodiscover_config['smtp']['port'];?></Port>
  150. <DomainRequired>off</DomainRequired>
  151. <LoginName><?=$email;?></LoginName>
  152. <SPA>off</SPA>
  153. <SSL>on</SSL>
  154. <AuthRequired>on</AuthRequired>
  155. <UsePOPAuth>on</UsePOPAuth>
  156. <SMTPLast>off</SMTPLast>
  157. </Protocol>
  158. <?php
  159. if (getenv('SKIP_SOGO') != "y") {
  160. ?>
  161. <Protocol>
  162. <Type>CalDAV</Type>
  163. <Server>https://<?=$autodiscover_config['caldav']['server'];?><?php if ($autodiscover_config['caldav']['port'] != 443) echo ':'.$autodiscover_config['caldav']['port']; ?>/SOGo/dav/<?=$email;?>/</Server>
  164. <DomainRequired>off</DomainRequired>
  165. <LoginName><?=$email;?></LoginName>
  166. </Protocol>
  167. <Protocol>
  168. <Type>CardDAV</Type>
  169. <Server>https://<?=$autodiscover_config['carddav']['server'];?><?php if ($autodiscover_config['caldav']['port'] != 443) echo ':'.$autodiscover_config['carddav']['port']; ?>/SOGo/dav/<?=$email;?>/</Server>
  170. <DomainRequired>off</DomainRequired>
  171. <LoginName><?=$email;?></LoginName>
  172. </Protocol>
  173. <?php
  174. }
  175. ?>
  176. </Account>
  177. </Response>
  178. <?php
  179. }
  180. else if ($autodiscover_config['autodiscoverType'] == 'activesync') {
  181. ?>
  182. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/mobilesync/responseschema/2006">
  183. <Culture>en:en</Culture>
  184. <User>
  185. <DisplayName><?=htmlspecialchars($displayname, ENT_XML1 | ENT_QUOTES, 'UTF-8');?></DisplayName>
  186. <EMailAddress><?=$email;?></EMailAddress>
  187. </User>
  188. <Action>
  189. <Settings>
  190. <Server>
  191. <Type>MobileSync</Type>
  192. <Url><?=$autodiscover_config['activesync']['url'];?></Url>
  193. <Name><?=$autodiscover_config['activesync']['url'];?></Name>
  194. </Server>
  195. </Settings>
  196. </Action>
  197. </Response>
  198. <?php
  199. }
  200. ?>
  201. </Autodiscover>
  202. <?php
  203. }
  204. ?>