forked from web-cyradm/web-cyradm
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathinit.php
More file actions
70 lines (61 loc) · 2.26 KB
/
Copy pathinit.php
File metadata and controls
70 lines (61 loc) · 2.26 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
<?php
if (!defined('WC_BASE')) define('WC_BASE', dirname(__FILE__));
$ref=WC_BASE."/index.php";
if ($ref!=$_SERVER['SCRIPT_FILENAME']){
header("Location: index.php");
exit();
}
# Connecting to database
$handle =DB::connect($DB['DSN'],true);
if (DB::isError($handle)) {
die (_("Database error (init 12)"));
}
#### Getting admin settings
$query = "SELECT * FROM settings WHERE username='".$_SESSION['user']."'";
$result = $handle->query($query);
if (DB::isError($result)) {
die (_("Database error (init 19)").": "._("Check scripts/upgrade-*.sql files."));
}
$row = $result->fetchRow(DB_FETCHMODE_ASSOC, 0);
$_SESSION['style'] = $row['style'];
$_SESSION['warnlevel'] = $row['warnlevel'];
$_SESSION['domain_row_pos'] = 0;
$_SESSION['maxdisplay'] = $row['maxdisplay'];
$_SESSION['domain_orderby'] = 'domain_name';
$_SESSION['domain_orderby_desc'] = 'asc';
$_SESSION['account_row_pos'] = 0;
$_SESSION['account_maxdisplay'] = $_SESSION['maxdisplay'];
##### Getting admin privilages
# Check if admin has any domain to administrate.
# Superuser has always 1 entry.
$query = "SELECT * FROM domainadmin WHERE adminuser='".$_SESSION['user']."'";
$result = $handle->query($query);
$cnt = $result->numRows();
if (!$cnt){
print _("Security violation detected, attempt logged");
logger(sprintf("SECURITY VIOLATION %s %s %s %s %s%s", $_SERVER['REMOTE_ADDR'], $_SESSION['user'], $_SERVER['HTTP_USER_AGENT'], $_SERVER['HTTP_REFERER'], $_SERVER['REQUEST_METHOD'], "\n"),"WARN");
include WC_BASE . "/logout.php";
die ();
}
# We check and remember admin type (superuser or domain admin).
$query2 = "SELECT * FROM adminuser WHERE username='".$_SESSION['user']."'";
$result2 = $handle->query($query2);
$row = $result2->fetchRow(DB_FETCHMODE_ASSOC, 0);
$_SESSION['admintype'] = $row['type'];
# We check and remember list of domains for domain admin
if ($_SESSION['admintype'] != 0){
$allowed_domains = array();
for ($i=0; $i < $cnt; $i++){
$row=$result->fetchRow(DB_FETCHMODE_ASSOC, $i);
$allowed_domains[] = $row['domain_name'];
}
$_SESSION['allowed_domains'] = $allowed_domains;
#Fix me: It's unnecessary (duplicated with "if (!$cnt)").
if (sizeof($allowed_domains)==0){
print _("Security violation detected, attempt logged");
include WC_BASE . "/logout.php";
die ();
}
}
unset($_SESSION['init']);
?>