controller.php 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202
  1. <?php
  2. function moulinette_get($var) {
  3. return htmlspecialchars(exec('sudo yunohost app setting vpnclient '.escapeshellarg($var)));
  4. }
  5. function moulinette_set($var, $value) {
  6. return exec('sudo yunohost app setting vpnclient '.escapeshellarg($var).' -v '.escapeshellarg($value));
  7. }
  8. function stop_service() {
  9. exec('sudo service ynh-vpnclient stop');
  10. }
  11. function start_service() {
  12. exec('sudo service ynh-vpnclient start', $output, $retcode);
  13. return $retcode;
  14. }
  15. function service_status() {
  16. exec('sudo service ynh-vpnclient status', $output);
  17. return $output;
  18. }
  19. function service_faststatus() {
  20. exec('ip link show tun0', $output, $retcode);
  21. return $retcode;
  22. }
  23. function ipv6_expanded($ip) {
  24. exec('ipv6_expanded '.escapeshellarg($ip), $output);
  25. return $output[0];
  26. }
  27. function ipv6_compressed($ip) {
  28. exec('ipv6_compressed '.escapeshellarg($ip), $output);
  29. return $output[0];
  30. }
  31. dispatch('/', function() {
  32. $ip6_net = moulinette_get('ip6_net');
  33. $ip6_net = ($ip6_net == 'none') ? '' : $ip6_net;
  34. set('server_name', moulinette_get('server_name'));
  35. set('server_port', moulinette_get('server_port'));
  36. set('server_proto', moulinette_get('server_proto'));
  37. set('login_user', moulinette_get('login_user'));
  38. set('login_passphrase', moulinette_get('login_passphrase'));
  39. set('ip6_net', $ip6_net);
  40. set('crt_client_exists', file_exists('/etc/openvpn/keys/user.crt'));
  41. set('crt_client_key_exists', file_exists('/etc/openvpn/keys/user.key'));
  42. set('crt_server_ca_exists', file_exists('/etc/openvpn/keys/ca-server.crt'));
  43. set('faststatus', service_faststatus() == 0);
  44. return render('settings.html.php');
  45. });
  46. dispatch_put('/settings', function() {
  47. $crt_client_exists = file_exists('/etc/openvpn/keys/user.crt');
  48. $crt_client_key_exists = file_exists('/etc/openvpn/keys/user.key');
  49. $crt_server_ca_exists = file_exists('/etc/openvpn/keys/ca-server.crt');
  50. $ip6_net = empty($_POST['ip6_net']) ? 'none' : $_POST['ip6_net'];
  51. $ip6_addr = 'none';
  52. try {
  53. if(empty($_POST['server_name']) || empty($_POST['server_port']) || empty($_POST['server_proto'])) {
  54. throw new Exception(T_('The Server Address, the Server Port and the Protocol cannot be empty'));
  55. }
  56. if(!preg_match('/^\d+$/', $_POST['server_port'])) {
  57. throw new Exception(T_('The Server Port must be only composed of digits'));
  58. }
  59. if($_POST['server_proto'] != 'udp' && $_POST['server_proto'] != 'tcp') {
  60. throw new Exception(T_('The Protocol must be "udp" or "tcp"'));
  61. }
  62. if(($_FILES['crt_client']['error'] == UPLOAD_ERR_OK && $_FILES['crt_client_key']['error'] != UPLOAD_ERR_OK && (!$crt_client_key_exists || $_POST['crt_client_key_delete'] == 1))
  63. || ($_FILES['crt_client_key']['error'] == UPLOAD_ERR_OK && $_FILES['crt_client']['error'] != UPLOAD_ERR_OK && (!$crt_client_exists || $_POST['crt_client_delete'] == 1))) {
  64. throw new Exception(T_('A Client Certificate is needed when you suggest a Key, or vice versa'));
  65. }
  66. if(empty($_POST['login_user']) xor empty($_POST['login_passphrase'])) {
  67. throw new Exception(T_('A Password is needed when you suggest a Username, or vice versa'));
  68. }
  69. if($_FILES['crt_server_ca']['error'] != UPLOAD_ERR_OK && !$crt_server_ca_exists) {
  70. throw new Exception(T_('You need a Server CA.'));
  71. }
  72. if(($_FILES['crt_client_key']['error'] != UPLOAD_ERR_OK && (!$crt_client_key_exists || $_POST['crt_client_key_delete'] == 1)) && empty($_POST['login_user'])) {
  73. throw new Exception(T_('You need either a Client Certificate, either a Username, or both'));
  74. }
  75. if($ip6_net != 'none') {
  76. $ip6_net = ipv6_expanded($ip6_net);
  77. if(empty($ip6_net)) {
  78. throw new Exception(T_('The IPv6 Delegated Prefix format looks bad'));
  79. }
  80. $ip6_blocs = explode(':', $ip6_net);
  81. $ip6_addr = "${ip6_blocs[0]}:${ip6_blocs[1]}:${ip6_blocs[2]}:${ip6_blocs[3]}:${ip6_blocs[4]}:${ip6_blocs[5]}:${ip6_blocs[6]}:42";
  82. $ip6_net = ipv6_compressed($ip6_net);
  83. $ip6_addr = ipv6_compressed($ip6_addr);
  84. }
  85. } catch(Exception $e) {
  86. flash('error', $e->getMessage().T_(' (configuration not updated).'));
  87. goto redirect;
  88. }
  89. stop_service();
  90. moulinette_set('server_name', $_POST['server_name']);
  91. moulinette_set('server_port', $_POST['server_port']);
  92. moulinette_set('server_proto', $_POST['server_proto']);
  93. moulinette_set('login_user', $_POST['login_user']);
  94. moulinette_set('login_passphrase', $_POST['login_passphrase']);
  95. moulinette_set('ip6_net', $ip6_net);
  96. moulinette_set('ip6_addr', $ip6_addr);
  97. if($_FILES['crt_client']['error'] == UPLOAD_ERR_OK) {
  98. move_uploaded_file($_FILES['crt_client']['tmp_name'], '/etc/openvpn/keys/user.crt');
  99. } elseif($_POST['crt_client_delete'] == 1) {
  100. unlink('/etc/openvpn/keys/user.crt');
  101. }
  102. if($_FILES['crt_client_key']['error'] == UPLOAD_ERR_OK) {
  103. move_uploaded_file($_FILES['crt_client_key']['tmp_name'], '/etc/openvpn/keys/user.key');
  104. } elseif($_POST['crt_client_key_delete'] == 1) {
  105. unlink('/etc/openvpn/keys/user.key');
  106. }
  107. if($_FILES['crt_server_ca']['error'] == UPLOAD_ERR_OK) {
  108. move_uploaded_file($_FILES['crt_server_ca']['tmp_name'], '/etc/openvpn/keys/ca-server.crt');
  109. }
  110. if(!empty($_POST['login_user'])) {
  111. file_put_contents('/etc/openvpn/keys/credentials', "${_POST['login_user']}\n${_POST['login_passphrase']}");
  112. } else {
  113. file_put_contents('/etc/openvpn/keys/credentials', '');
  114. }
  115. $retcode = start_service();
  116. if($retcode == 0) {
  117. flash('success', T_('Configuration updated and service successfully reloaded'));
  118. } else {
  119. flash('error', T_('Configuration updated but service reload failed'));
  120. }
  121. redirect:
  122. redirect_to('/');
  123. });
  124. dispatch('/status', function() {
  125. $status_lines = service_status();
  126. $status_list = '';
  127. foreach($status_lines AS $status_line) {
  128. if(preg_match('/^\[INFO\]/', $status_line)) {
  129. $status_list .= "<li class='status-info'>${status_line}</li>";
  130. }
  131. elseif(preg_match('/^\[OK\]/', $status_line)) {
  132. $status_list .= "<li class='status-success'>${status_line}</li>";
  133. }
  134. elseif(preg_match('/^\[WARN\]/', $status_line)) {
  135. $status_list .= "<li class='status-warning'>${status_line}</li>";
  136. }
  137. elseif(preg_match('/^\[ERR\]/', $status_line)) {
  138. $status_list .= "<li class='status-danger'>${status_line}</li>";
  139. }
  140. }
  141. echo $status_list;
  142. });
  143. dispatch('/lang/:locale', function($locale = 'en') {
  144. switch ($locale) {
  145. case 'fr':
  146. $_SESSION['locale'] = 'fr';
  147. break;
  148. default:
  149. $_SESSION['locale'] = 'en';
  150. }
  151. if(!empty($_GET['redirect_to'])) {
  152. redirect_to($_GET['redirect_to']);
  153. } else {
  154. redirect_to('/');
  155. }
  156. });