autodiscover.php 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270
  1. <?php
  2. error_reporting(0);
  3. header("Content-Type: application/xml");
  4. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/lib/vendor/autoload.php';
  5. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/vars.inc.php';
  6. if(file_exists('inc/vars.local.inc.php')) {
  7. include_once 'inc/vars.local.inc.php';
  8. }
  9. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/functions.inc.php';
  10. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/sessions.inc.php';
  11. function error_xml($error_id, $error_code, $message) {
  12. list($usec, $sec) = explode(' ', microtime());
  13. $time_string = date('H:i:s', $sec) . substr($usec, 0, strlen($usec) - 2);
  14. return <<<EOD
  15. <?xml version="1.0" encoding="utf-8" ?>
  16. <Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006">
  17. <Response>
  18. <Error Time="$time_string" Id="$error_id">
  19. <ErrorCode>$error_code</ErrorCode>
  20. <Message>$message</Message>
  21. <DebugData />
  22. </Error>
  23. </Response>
  24. </Autodiscover>
  25. EOD;
  26. }
  27. function autodiscover_xml($type, $email, $displayname, $autodiscover_config) {
  28. $displayname = htmlspecialchars($displayname, ENT_XML1 | ENT_QUOTES, 'UTF-8');
  29. $caldav_port = $autodiscover_config['caldav']['port'] != 443 ? ':' . $autodiscover_config['caldav']['port'] : '';
  30. $carddav_port = $autodiscover_config['carddav']['port'] != 443 ? ':' . $autodiscover_config['carddav']['port'] : '';
  31. $xml = '';
  32. $calcardav_xml = '';
  33. if (getenv('SKIP_SOGO') != "y") {
  34. $calcardav_xml .= <<<EOD
  35. <Protocol>
  36. <Type>CalDAV</Type>
  37. <Server>https://{$autodiscover_config['caldav']['server']}{$caldav_port}/SOGo/dav/{$email}/</Server>
  38. <DomainRequired>off</DomainRequired>
  39. <LoginName>{$email}</LoginName>
  40. </Protocol>
  41. <Protocol>
  42. <Type>CardDAV</Type>
  43. <Server>https://{$autodiscover_config['carddav']['server']}{$carddav_port}/SOGo/dav/{$email}/</Server>
  44. <DomainRequired>off</DomainRequired>
  45. <LoginName>{$email}</LoginName>
  46. </Protocol>
  47. EOD;
  48. }
  49. if ($type == 'imap') {
  50. $xml .= <<<EOD
  51. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a">
  52. <User>
  53. <DisplayName>{$displayname}</DisplayName>
  54. </User>
  55. <Account>
  56. <AccountType>email</AccountType>
  57. <Action>settings</Action>
  58. <Protocol>
  59. <Type>IMAP</Type>
  60. <Server>{$autodiscover_config['imap']['server']}</Server>
  61. <Port>{$autodiscover_config['imap']['port']}</Port>
  62. <DomainRequired>off</DomainRequired>
  63. <LoginName>{$email}</LoginName>
  64. <SPA>off</SPA>
  65. <SSL>on</SSL>
  66. <AuthRequired>on</AuthRequired>
  67. </Protocol>
  68. <Protocol>
  69. <Type>SMTP</Type>
  70. <Server>{$autodiscover_config['smtp']['server']}</Server>
  71. <Port>{$autodiscover_config['smtp']['port']}</Port>
  72. <DomainRequired>off</DomainRequired>
  73. <LoginName>{$email}</LoginName>
  74. <SPA>off</SPA>
  75. <SSL>on</SSL>
  76. <AuthRequired>on</AuthRequired>
  77. <UsePOPAuth>on</UsePOPAuth>
  78. <SMTPLast>off</SMTPLast>
  79. </Protocol>
  80. {$calcardav_xml}
  81. </Account>
  82. </Response>
  83. EOD;
  84. }
  85. else if ($type == 'activesync') {
  86. $xml .= <<<EOD
  87. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/mobilesync/responseschema/2006">
  88. <Culture>en:en</Culture>
  89. <User>
  90. <DisplayName>{$displayname}</DisplayName>
  91. <EMailAddress>{$email}</EMailAddress>
  92. </User>
  93. <Action>
  94. <Settings>
  95. <Server>
  96. <Type>MobileSync</Type>
  97. <Url>{$autodiscover_config['activesync']['url']}</Url>
  98. <Name>{$autodiscover_config['activesync']['url']}</Name>
  99. </Server>
  100. </Settings>
  101. </Action>
  102. </Response>
  103. EOD;
  104. }
  105. return <<<EOD
  106. <?xml version="1.0" encoding="utf-8" ?>
  107. <Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006">
  108. $xml
  109. </Autodiscover>
  110. EOD;
  111. }
  112. $default_autodiscover_config = $autodiscover_config;
  113. $autodiscover_config = array_merge($default_autodiscover_config, $autodiscover_config);
  114. // SQL
  115. //$dsn = $database_type . ":host=" . $database_host . ";dbname=" . $database_name;
  116. $dsn = $database_type . ":unix_socket=" . $database_sock . ";dbname=" . $database_name;
  117. $opt = [
  118. PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
  119. PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
  120. PDO::ATTR_EMULATE_PREPARES => false,
  121. ];
  122. $pdo = new PDO($dsn, $database_user, $database_pass, $opt);
  123. // Redis
  124. $redis = new Redis();
  125. try {
  126. if (!empty(getenv('REDIS_SLAVEOF_IP'))) {
  127. $redis->connect(getenv('REDIS_SLAVEOF_IP'), getenv('REDIS_SLAVEOF_PORT'));
  128. }
  129. else {
  130. $redis->connect('redis-mailcow', 6379);
  131. }
  132. $redis->auth(getenv("REDISPASS"));
  133. }
  134. catch (Exception $e) {
  135. $_SESSION['return'][] = array(
  136. 'type' => 'danger',
  137. 'msg' => 'Redis: '.$e
  138. );
  139. echo error_xml("2477272013", "600", "Server Error");
  140. exit(0);
  141. }
  142. $data = trim(file_get_contents("php://input"));
  143. if (strpos($data, 'autodiscover/outlook/responseschema') !== false) {
  144. $autodiscover_config['autodiscoverType'] = 'imap';
  145. if ($autodiscover_config['useEASforOutlook'] == 'yes' &&
  146. // Office for macOS does not support EAS
  147. strpos($_SERVER['HTTP_USER_AGENT'], 'Mac') === false &&
  148. // Outlook 2013 (version 15) or higher
  149. preg_match('/(Outlook|Office).+1[5-9]\./', $_SERVER['HTTP_USER_AGENT'])
  150. ) {
  151. $autodiscover_config['autodiscoverType'] = 'activesync';
  152. }
  153. }
  154. if (getenv('SKIP_SOGO') == "y") {
  155. $autodiscover_config['autodiscoverType'] = 'imap';
  156. }
  157. if(!$data) {
  158. try {
  159. $json = json_encode(
  160. array(
  161. "time" => time(),
  162. "ua" => $_SERVER['HTTP_USER_AGENT'],
  163. "user" => $_SERVER['PHP_AUTH_USER'],
  164. "ip" => $_SERVER['REMOTE_ADDR'],
  165. "service" => "Error: invalid or missing request data"
  166. )
  167. );
  168. $redis->lPush('AUTODISCOVER_LOG', $json);
  169. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  170. }
  171. catch (RedisException $e) {
  172. $_SESSION['return'][] = array(
  173. 'type' => 'danger',
  174. 'msg' => 'Redis: '.$e
  175. );
  176. }
  177. echo error_xml("2477272013", "600", "Invalid Request");
  178. exit(0);
  179. }
  180. try {
  181. $discover = new SimpleXMLElement($data);
  182. $email = $discover->Request->EMailAddress;
  183. } catch (Exception $e) {
  184. // could not parse email address
  185. try {
  186. $json = json_encode(
  187. array(
  188. "time" => time(),
  189. "ua" => $_SERVER['HTTP_USER_AGENT'],
  190. "user" => $_SERVER['PHP_AUTH_USER'],
  191. "ip" => $_SERVER['REMOTE_ADDR'],
  192. "service" => "Error: missing email address in request data"
  193. )
  194. );
  195. $redis->lPush('AUTODISCOVER_LOG', $json);
  196. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  197. }
  198. catch (RedisException $e) {
  199. $_SESSION['return'][] = array(
  200. 'type' => 'danger',
  201. 'msg' => 'Redis: '.$e
  202. );
  203. }
  204. echo error_xml("2477272013", "600", "Invalid Request");
  205. exit(0);
  206. }
  207. $username = trim($email);
  208. $displayname = $username;
  209. try {
  210. $stmt = $pdo->prepare("SELECT `name` FROM `mailbox` WHERE `username`= :username");
  211. $stmt->execute(array(':username' => $username));
  212. $MailboxData = $stmt->fetch(PDO::FETCH_ASSOC);
  213. }
  214. catch(PDOException $e) {
  215. $MailboxData = array("name" => "");
  216. }
  217. if (!empty($MailboxData['name'])) {
  218. $displayname = $MailboxData['name'];
  219. }
  220. try {
  221. $json = json_encode(
  222. array(
  223. "time" => time(),
  224. "ua" => $_SERVER['HTTP_USER_AGENT'],
  225. "user" => $_SERVER['PHP_AUTH_USER'],
  226. "ip" => $_SERVER['REMOTE_ADDR'],
  227. "service" => $autodiscover_config['autodiscoverType']
  228. )
  229. );
  230. $redis->lPush('AUTODISCOVER_LOG', $json);
  231. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  232. }
  233. catch (RedisException $e) {
  234. $_SESSION['return'][] = array(
  235. 'type' => 'danger',
  236. 'msg' => 'Redis: '.$e
  237. );
  238. echo error_xml("2477272013", "600", "Server Error");
  239. exit(0);
  240. }
  241. echo autodiscover_xml($autodiscover_config['autodiscoverType'], $email, $displayname, $autodiscover_config);
  242. exit(0);