-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclientdatabasesprocess.php
More file actions
114 lines (96 loc) · 3.61 KB
/
Copy pathclientdatabasesprocess.php
File metadata and controls
114 lines (96 loc) · 3.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
<?php
$return = true;
require __DIR__ . '/configuration.php';
require __DIR__ . '/include.php';
requireSameOrigin('index.php');
require __DIR__ . '/includes/dbctl.php';
$clientId = (int) ($_SESSION['clientid'] ?? 0);
if (!$clientId) {
header('Location: login.php');
exit;
}
$cfg = clientDbConfig();
if (!$cfg['enabled']) {
header('Location: index.php');
exit;
}
$task = sanitizeInput($_POST['task'] ?? ($_GET['task'] ?? ''));
$clientName = trim(($_SESSION['clientfirstname'] ?? '') . ' ' . ($_SESSION['clientlastname'] ?? ''));
$clientIp = $_SERVER['REMOTE_ADDR'] ?? '';
function cdb_flash(string $a, string $b): void
{
$_SESSION['msg1'] = $a;
$_SESSION['msg2'] = $b;
header('Location: clientdatabases.php');
exit;
}
function cdb_log(int $clientId, string $message, string $name, string $ip): void
{
dbExec(
"INSERT INTO `log` SET " .
"`clientid` = '" . $clientId . "', " .
"`message` = '" . dbEscape($message) . "', " .
"`name` = '" . dbEscape($name) . "', " .
"`ip` = '" . dbEscape($ip) . "'"
);
}
if ($task === 'create') {
$count = dbCount("SELECT `dbid` FROM `clientdatabase` WHERE `clientid` = '" . $clientId . "'");
if ($cfg['max'] > 0 && $count >= $cfg['max']) {
cdb_flash('Limit reached', 'Your account already has the maximum of ' . (int) $cfg['max'] . ' database(s).');
}
$name = clientDbSanitizeName($_POST['name'] ?? '');
if ($name === null) {
cdb_flash('Invalid name', 'Use 1-24 characters: lowercase letters, digits or underscore.');
}
$dbname = 'c' . $clientId . '_' . $name;
if (dbCount("SELECT `dbid` FROM `clientdatabase` WHERE `dbname` = '" . dbEscape($dbname) . "'") > 0) {
cdb_flash('Name in use', 'You already have a database with that name.');
}
try {
$created = clientDbCreate($clientId, $name, $cfg['host']);
} catch (Throwable $e) {
cdb_flash('Could not create database', $e->getMessage());
}
dbExec(
"INSERT INTO `clientdatabase` SET " .
"`clientid` = '" . $clientId . "', " .
"`dbname` = '" . dbEscape($created['dbname']) . "', " .
"`dbuser` = '" . dbEscape($created['dbuser']) . "', " .
"`dbpass` = '" . dbEscape(clientDbEncode($created['dbpass'])) . "', " .
"`dbhost` = '" . dbEscape($created['dbhost']) . "', " .
"`maxsize` = '" . (int) $cfg['maxsize'] . "', " .
"`disksize` = '0.00', " .
"`created` = NOW()"
);
cdb_log($clientId, 'Database created: <b>' . htmlspecialchars($created['dbname'], ENT_QUOTES, 'UTF-8') . '</b> (Client)', $clientName, $clientIp);
cdb_flash('Database created', 'Your database and login are ready.');
}
$dbid = (int) ($_POST['dbid'] ?? ($_GET['dbid'] ?? 0));
$row = dbRow(
"SELECT * FROM `clientdatabase` WHERE `dbid` = '" . $dbid . "' AND `clientid` = '" . $clientId . "' LIMIT 1",
true
);
if (!is_array($row) || !$row) {
cdb_flash('Not found', 'That database is not on your account.');
}
if ($task === 'resetpw') {
try {
$new = clientDbResetPassword($row);
} catch (Throwable $e) {
cdb_flash('Could not reset password', $e->getMessage());
}
dbExec("UPDATE `clientdatabase` SET `dbpass` = '" . dbEscape(clientDbEncode($new)) . "' WHERE `dbid` = '" . $dbid . "'");
cdb_flash('Password reset', 'The new password is shown on the database list.');
}
if ($task === 'delete') {
try {
clientDbDelete($row);
} catch (Throwable $e) {
// fall through — still drop the panel row so it can't get stuck
}
dbExec("DELETE FROM `clientdatabase` WHERE `dbid` = '" . $dbid . "'");
cdb_log($clientId, 'Database deleted: <b>' . htmlspecialchars($row['dbname'], ENT_QUOTES, 'UTF-8') . '</b> (Client)', $clientName, $clientIp);
cdb_flash('Database deleted', 'The database and its user have been removed.');
}
header('Location: clientdatabases.php');