diff --git a/README.md b/README.md index ca62fa1..3e54c9b 100644 --- a/README.md +++ b/README.md @@ -5,8 +5,7 @@ * Status: Dev * Object : Massive LXC CT deploy system for proxmox hypervisor. - -## Quick start (testings) +## Quick start ### Requirement: * A proxmox server diff --git a/code/scripts/main/api/v1/__pycache__/api.cpython-35.pyc b/code/scripts/main/api/v1/__pycache__/api.cpython-35.pyc index 18113a7..2ae54dc 100644 Binary files a/code/scripts/main/api/v1/__pycache__/api.cpython-35.pyc and b/code/scripts/main/api/v1/__pycache__/api.cpython-35.pyc differ diff --git a/code/scripts/main/core/__pycache__/core.cpython-35.pyc b/code/scripts/main/core/__pycache__/core.cpython-35.pyc index d2b943c..adbbb06 100644 Binary files a/code/scripts/main/core/__pycache__/core.cpython-35.pyc and b/code/scripts/main/core/__pycache__/core.cpython-35.pyc differ diff --git a/code/scripts/main/core/libs/__pycache__/hcrypt.cpython-35.pyc b/code/scripts/main/core/libs/__pycache__/hcrypt.cpython-35.pyc index a2ad868..5579b14 100644 Binary files a/code/scripts/main/core/libs/__pycache__/hcrypt.cpython-35.pyc and b/code/scripts/main/core/libs/__pycache__/hcrypt.cpython-35.pyc differ diff --git a/code/scripts/main/core/modules/__pycache__/mod_access.cpython-35.pyc b/code/scripts/main/core/modules/__pycache__/mod_access.cpython-35.pyc index ab66529..82923a1 100644 Binary files a/code/scripts/main/core/modules/__pycache__/mod_access.cpython-35.pyc and b/code/scripts/main/core/modules/__pycache__/mod_access.cpython-35.pyc differ diff --git a/code/scripts/main/core/modules/__pycache__/mod_analyst.cpython-35.pyc b/code/scripts/main/core/modules/__pycache__/mod_analyst.cpython-35.pyc index be218d8..c15385f 100644 Binary files a/code/scripts/main/core/modules/__pycache__/mod_analyst.cpython-35.pyc and b/code/scripts/main/core/modules/__pycache__/mod_analyst.cpython-35.pyc differ diff --git a/code/scripts/main/core/modules/__pycache__/mod_database.cpython-35.pyc b/code/scripts/main/core/modules/__pycache__/mod_database.cpython-35.pyc index a7a3964..9117709 100644 Binary files a/code/scripts/main/core/modules/__pycache__/mod_database.cpython-35.pyc and b/code/scripts/main/core/modules/__pycache__/mod_database.cpython-35.pyc differ diff --git a/code/scripts/main/core/modules/__pycache__/mod_proxmox.cpython-35.pyc b/code/scripts/main/core/modules/__pycache__/mod_proxmox.cpython-35.pyc index 3b67846..5d0c521 100644 Binary files a/code/scripts/main/core/modules/__pycache__/mod_proxmox.cpython-35.pyc and b/code/scripts/main/core/modules/__pycache__/mod_proxmox.cpython-35.pyc differ diff --git a/code/scripts/main/core/modules/mod_access.py b/code/scripts/main/core/modules/mod_access.py index 5499a53..78c825a 100644 --- a/code/scripts/main/core/modules/mod_access.py +++ b/code/scripts/main/core/modules/mod_access.py @@ -8,7 +8,6 @@ Minimum version require: 3.4 import os from Crypto.PublicKey import RSA import hashlib -import codecs def encodepassphrase(passphrase): return hashlib.sha512(passphrase.encode("UTF-8")).hexdigest() @@ -97,7 +96,7 @@ class CryticalData: else: result_encrypt = { "result": "OK", - "data": codecs.encode(self.public_key.encrypt(mutable_bytes, 32)[0], 'base64') + "data": self.public_key.encrypt(data.encode("utf-8"), 64) } except BaseException as e: result_encrypt = { diff --git a/code/scripts/main/startup.py b/code/scripts/main/startup.py index 81f4257..6a6242c 100644 --- a/code/scripts/main/startup.py +++ b/code/scripts/main/startup.py @@ -62,12 +62,7 @@ if __name__ == "__main__": exit(1) key_pub = CritConf.read_public_key(localconf['system']['key_pub']) - """ - crypttest=CritConf.data_encryption("ploopp") - print(type(crypttest['data'])) - print(CritConf.data_decryption(crypttest['data'])) - exit(0) - """ + # URL MAPPING urls = \ ( @@ -81,7 +76,7 @@ if __name__ == "__main__": '/api/v1/instance/([0-9]+)/vhost(?:/([0-9]+))', 'vhost', '/api/v1/instance/([0-9]+)/database(?:/([0-9]+))', 'database', - #  MAPPIN NODES + #  MAPPING NODES '/api/v1/node(?:/([0-9]+))', 'node', # MAPPING SERVICES diff --git a/code/web/backend/.htaccess b/code/web/backend/.htaccess deleted file mode 100644 index 874120d..0000000 --- a/code/web/backend/.htaccess +++ /dev/null @@ -1,4 +0,0 @@ -# This file is - if you set up HUGE correctly - not needed. -# But, for fallback reasons (if you don't route your vhost to /public), it will stay here. -RewriteEngine on -RewriteRule ^(.*) public/$1 [L] diff --git a/code/web/backend/.scrutinizer.yml b/code/web/backend/.scrutinizer.yml deleted file mode 100644 index 2bbc927..0000000 --- a/code/web/backend/.scrutinizer.yml +++ /dev/null @@ -1,5 +0,0 @@ -# This file just tells the wonderful code quality analyzer Scrutinizer (https://scrutinizer-ci.com/g/panique/huge/) -# that we are using external services (Travis) to generate code coverage stats -# TODO is this correct ? -tools: - external_code_coverage: true \ No newline at end of file diff --git a/code/web/backend/.travis.yml b/code/web/backend/.travis.yml deleted file mode 100644 index 45ab715..0000000 --- a/code/web/backend/.travis.yml +++ /dev/null @@ -1,30 +0,0 @@ -language: php - -php: - - 5.5 - - 5.6 - - hhvm - -before_install: -- sudo apt-get update > /dev/null - -before_script: - - sudo apt-get install apache2 - - sudo a2enmod rewrite - # configure apache virtual hosts, create vhost via travis-ci-apache file template - - sudo cp -f travis-ci-apache /etc/apache2/sites-available/default - - sudo sed -e "s?%TRAVIS_BUILD_DIR%?$(pwd)?g" --in-place /etc/apache2/sites-available/default - - sudo service apache2 restart - # composer - - composer self-update - - composer install --prefer-source --no-interaction --dev - # go to tests folder - - cd tests - -# run unit tests, create result file -script: phpunit --configuration phpunit.xml --coverage-text --coverage-clover=coverage.clover - -# gets tools from Scrutinizer, uploads unit tests results to Scrutinizer (?) -after_script: - - wget https://scrutinizer-ci.com/ocular.phar - - php ocular.phar code-coverage:upload --format=php-clover coverage.clover \ No newline at end of file diff --git a/code/web/backend/CHANGELOG.md b/code/web/backend/CHANGELOG.md deleted file mode 100644 index 656016f..0000000 --- a/code/web/backend/CHANGELOG.md +++ /dev/null @@ -1,72 +0,0 @@ -# CHANGE LOG - -For the newest (und unstable) version always check the develop branch. - -## 3.1 - -Code Quality at Scrutinizer 9.7/10, at Code Climate 3.9/4 - -**February 2015** - -- [panique] several code quality improvements (and line reductions :) ) all over the project -- [PR](https://github.com/panique/huge/pull/620) [owenr88] view rending now possible with multiple view files -- [panique] lots of code refactorings and simplifications all over the project -- [PR](https://github.com/panique/huge/pull/615) [Dominic28] Avatar can now be deleted by the user -- [panique] First Unit tests :) -- [panique] several code quality improvements all over the project -- [panique] avatarModel code improvements -- [panique] renamed AccountType stuff to UserRole, minor changes - -## 3.0 - -Code Quality at Scrutinizer 9.3/10, at Code Climate 3.9/4 - -**February 2015** - -- [panique] removed duplicate code in AccountTypeModel -- [PR](https://github.com/panique/huge/pull/587) [upperwood] Facebook stuff completely removed from SQL -- [panique] tiny text changes - -**January 2015** - -- [panique] added static Text class (gets the messages etc) -- [panique] added static Environment class (get the environment) -- [panique] added static Config class (gets config easily and according to environment) -- [panique] new styling of the entire project: login/index has new look now -- [panique] massive refactoring of all model classes: lots of methods have been organized into other model classes -- [panique] massive refactoring of all model classes: all methods are static now -- [panique] EXPERIMENTAL: added static database call / DatabaseFactory, rebuild NoteModel with static methods -- [panique] massive refactoring of mail sending, (chose between PHPMailer, SwiftMailer, native / SMTP or no SMTP) - -**December 2014** - -- [panique] lots of refactorings -- [panique] refactored LoginModel'S login() method / LoginController's login() method -- [panique] removed COOKIE_DOMAIN (cookie is now valid on the domain/IP it has been created on) -- [panique] Abstracting super-globals like $_POST['x'] into Request::post('x') -- [panique] entirely removed all the Facebook stuff [will be replaced by new proper Oauth2 solution soon] -- [panique] lots of code refactorings and cleaning, deletions of duplicate code -- [panique] moving nearly all hardcoded values to config -- [panique] new View handling: you'll have to pass vars to the view renderer now -- [panique] completely removed Facebook login process from controller (incomplete) [will be replaced by new solution] -- [panique] less config, URL/IP is auto-detected now -- [panique] added loadConfig() to load a specific config according to environment setting (fallback: development) -- [panique] added getEnvironment() to fetch (potential) environment setting -- [panique] replaced native super-globals access by wrapper access (Session:get instead of $_SESSION) -- [panique] complete frontend rebuilding (incomplete yet) -- [panique] massive cleaning of all controllers -- [panique] added Session::add() to allow stacking of elements (useful for collecting feedback, errors etc) -- [panique] complete rebuild of model handling -- [panique] View can now render(), renderWithoutHeaderFooter() and renderJSON -- [panique] using Composer's PSR-4 autoloader (in a very basic way currently) -- [panique] DB construction needs now port by default -- [panique] removed (semi-optional) hashing cost factor (as it's redundant usually) -- [panique] email max limit increased to 254/255 (official number) -- [panique] simpler and improved core -- [panique] improved architecture, controllers are now named like "IndexController" -- [panique] moved index.php to /public folder, new .htaccess, new installation guideline -- [panique] MVC naming fixes -- [nerdalertdk] betters paths, automatic paths -- [panique] removed legacy PHP stuff: 5.5.x is now the minimum -- [PR](https://github.com/panique/php-login/pull/503) [Malkleth] allow users to request password reset by inputting email as well as user names -- [PR](https://github.com/panique/php-login/pull/516) [pein0119] cookie runtime calculation fix diff --git a/code/web/backend/README.md b/code/web/backend/README.md deleted file mode 100644 index bb50a7f..0000000 --- a/code/web/backend/README.md +++ /dev/null @@ -1,353 +0,0 @@ -[![HUGE, formerly "php-login" logo](_pictures/huge-logo.png)](http://www.php-login.net) - -# HUGE - -[![Scrutinizer Code Quality](https://scrutinizer-ci.com/g/panique/huge/badges/quality-score.png?b=master)](https://scrutinizer-ci.com/g/panique/huge/?branch=master) -[![Code Climate](https://codeclimate.com/github/panique/huge/badges/gpa.svg)](https://codeclimate.com/github/panique/huge) -[![Travis CI](https://travis-ci.org/panique/huge.svg?branch=master)](https://travis-ci.org/panique/huge) -[![Dependency Status](https://www.versioneye.com/user/projects/54ca11fbde7924f81a000010/badge.svg?style=flat)](https://www.versioneye.com/user/projects/54ca11fbde7924f81a000010) - -Just a simple user authentication solution inside a super-simple framework skeleton that works out-of-the-box -(and comes with an auto-installer), using the future-proof official bcrypt password hashing/salting implementation of -PHP 5.5+, plus some nice features that will speed up the time from idea to first usable prototype application -dramatically. Nothing more. This project has its focus on hardcore simplicity. Everything is as simple as possible, -made for smaller projects, typical agency work and quick pitch drafts. If you want to build massive corporate -applications with all the features modern frameworks have, then have a look at [Laravel](http://laravel.com), -[Symfony](http://symfony.com) or [Yii](http://www.yiiframework.com), but if you just want to quickly create something -that just works, then this script might be interesting for you. - -HUGE's simple-as-possible architecture was inspired by several conference talks, slides and articles about huge -applications that - surprisingly and intentionally - go back to the basics of programming, using procedural programming, -static classes, extremely simple constructs, not-totally-DRY code etc. while keeping the code extremely readable -([StackOverflow](http://www.dev-metal.com/architecture-stackoverflow/), Wikipedia, SoundCloud). - -Buzzwords: [KISS](http://en.wikipedia.org/wiki/KISS_principle), [YASNI](http://en.wikipedia.org/wiki/You_aren%27t_gonna_need_it). - -#### Quick-Index - -+ [Features](#features) -+ [Live-Demo](#live-demo) -+ [Support](#support) -+ [Follow the project](#follow) -+ [License](#license) -+ [Requirements](#requirements) -+ [Auto-Installation](#auto-installation) - - [Auto-Installation in Vagrant](#auto-installation-vagrant) - - [Auto-Installation in Ubuntu 14.04 LTS server](#auto-installation-ubuntu) -+ [Installation (Ubuntu 14.04 LTS)](#installation) - - [Quick Installation](#quick-installation) - - [Detailed Installation](#detailed-installation) -+ [Documentation](#documentation) -+ [Why is there no support forum anymore ?](#why-no-support-forum) -+ [Zero tolerance for idiots, trolls and vandals](#zero-tolerance) -+ [Contribute](#contribute) -+ [Report a bug](#bug-report) - -### The History of HUGE - -This script was formerly named "php-login" and by far the most popular version of the 4 simple PHP user auth -scripts of [The PHP Login Project](http://www.php-login.net) (a collection of simple login scripts, made to prevent -people from using totally outdated and insecure MD5 password hashing, which was still very popular in the PHP world -back in 2012). - -Why the name "HUGE" ? It's a nice combination to -[TINY](https://github.com/panique/tiny), -[MINI](https://github.com/panique/mini) and -[MINI2](https://github.com/panique/mini2), my other projects :) - -### Features -* built with the official PHP password hashing functions, fitting the most modern password hashing/salting web standards -* users can register, login, logout (with username, email, password) -* [planned: OAuth2 implementation for proper future-proof 3rd party auth] -* password-forget / reset -* remember-me (login via cookie) -* account verification via mail -* captcha -* failed-login-throttling -* user profiles -* account upgrade / downgrade -* supports local avatars and remote Gravatars -* supports native mail and SMTP sending (via PHPMailer and other tools) -* uses PDO for database access for sure, has nice DatabaseFactory (in case your project goes big) -* uses URL rewriting ("beautiful URLs") -* proper split of application and public files (requests only go into /public) -* uses Composer to load external dependencies (PHPMailer, Captcha-Generator, etc.) -* fits PSR-0/1/2/4 coding guidelines -* masses of comments -* is actively developed, maintained and bug-fixed - -### Live-Demo - -See a [live demo here](http://demo-huge.php-login.net) and [the server's phpinfo() here](http://demo-huge.php-login.net/info.php). - -### Support the project - -There a lot of work behind this project. I might save you hundreds, maybe thousands of hours of work (calculate that -in developer costs). So when you are earning money by using HUGE, be fair and give something back to open-source. -HUGE is totally free to private and commercial use. - -TODO new banners - -[![Donate with PayPal banner](_pictures/support-via-paypal.png)](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=P5YLUK4MW3LDG) -[![Donate by server affiliate sale](_pictures/support-via-a2hosting.png)](https://affiliates.a2hosting.com/idevaffiliate.php?id=4471&url=579) - -You can also rent your next $5 server at [Virpus](http://my.virpus.com/aff.php?aff=1836) or [DigitalOcean](https://www.digitalocean.com/?refcode=40d978532a20) -or donate via [PayPal](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=P5YLUK4MW3LDG). - -Also feel free to contribute to this project. - -### Follow the project - -Here on **[Twitter](https://twitter.com/simplephplogin)** or **[Facebook](https://www.facebook.com/pages/PHP-Login-Script/461306677235868)**. -I'm also blogging at **[Dev Metal](http://www.dev-metal.com)**. - -### License - -Licensed under [MIT](http://www.opensource.org/licenses/mit-license.php). -Totally free for private or commercial projects. - -### Requirements - -Make sure you know the basics of object-oriented programming and MVC, are able to use the command line and have -used Composer before. This script is not for beginners. - -* **PHP 5.5+** -* **MySQL 5** database (better use versions 5.5+ as very old versions have a [PDO injection bug](http://stackoverflow.com/q/134099/1114320) -* installed PHP extensions: pdo, gd, openssl (the install guideline shows how to do) -* installed tools on your server: git, curl, composer (the install guideline shows how to do) -* for professional mail sending: an SMTP account (I use [SMTP2GO](http://www.smtp2go.com/?s=devmetal)) -* activated mod_rewrite on your server (the install guideline shows how to do) - -### Auto-Installations - -Yo, fully automatic. Why ? Because I always hated it to spend days trying to find out how to install a thing. -This will save you masses of time and nerves. Donate a coffee if you like it. - -#### Auto-Installation (in Vagrant) - -If you are using Vagrant for your development, then simply - -1. Add the official Ubuntu 14.04 LTS box to your Vagrant: `vagrant box add ubuntu/trusty64` -2. Move *Vagrantfile* and *bootstrap.sh* (from *_one-click-installation* folder) to a folder where you want to initialize your project. -3. Do `vagrant up` in that folder. - -5 minutes later you'll have a fully installed HUGE inside Ubuntu 14.04 LTS. The full code will be auto-synced with -the current folder. MySQL root password and the PHPMyAdmin root password are set to *12345678*. By default -192.168.33.111 is the IP of your new box. - -#### Auto-Installation in a naked Ubuntu 14.04 LTS server - -Extremely simple installation in a fresh and naked typical Ubuntu 14.04 LTS server: - -Download the installer script -```bash -wget https://raw.githubusercontent.com/panique/huge/master/_one-click-installation/bootstrap.sh -``` - -Make it executable -```bash -chmod +x bootstrap.sh -``` - -Run it! Give it some minutes to perform all the tasks. And yes, you can thank me later :) -```bash -sudo ./bootstrap.sh -``` -### Installation - -This script is very fresh, so the install guidelines are not perfect yet. - -#### Quick guide: - -0. Make sure you have Apache, PHP, MySQL installed. [Tutorial](http://www.dev-metal.com/installsetup-basic-lamp-stack-linux-apache-mysql-php-ubuntu-14-04-lts/). -1. Clone the repo to a folder on your server -2. Activate mod_rewrite, route all traffic to application's /public folder. [Tutorial](http://www.dev-metal.com/enable-mod_rewrite-ubuntu-14-04-lts/). -3. Edit application/config: Set your database credentials -4. Execute SQL statements from application/_installation to setup database tables -5. [Install Composer](http://www.dev-metal.com/install-update-composer-windows-7-ubuntu-debian-centos/), - run `Composer install` on application's root folder to install dependencies -6. Make avatar folder (application/public/avatars) writable -7. For proper email usage: Set SMTP credentials in config file, set EMAIL_USE_SMTP to true - -"Email does not work" ? See the troubleshooting below. TODO - -#### Detailed guide (Ubuntu 14.04 LTS): - -This is just a quick guideline for easy setup of a development environment! - -Make sure you have Apache, PHP 5.5+ and MySQL installed. [Tutorial here](http://www.dev-metal.com/installsetup-basic-lamp-stack-linux-apache-mysql-php-ubuntu-14-04-lts/). -Nginx will work for sure too, but no install guidelines are available yet. - -Edit vhost to make clean URLs possible and route all traffic to /public folder of your project: -```bash -sudo nano /etc/apache2/sites-available/000-default.conf -``` - -and make the file look like -``` - - DocumentRoot "/var/www/html/public" - - AllowOverride All - Require all granted - - -``` - -Enable mod_rewrite and restart apache. -```bash -sudo a2enmod rewrite -service apache2 restart -``` - -Install curl (needed to use git), openssl (needed to clone from GitHub, as github is https only), -PHP GD, the graphic lib (we create captchas and avatars), and git. -```bash -sudo apt-get -y install curl -sudo apt-get -y install php5-curl -sudo apt-get -y install openssl -sudo apt-get -y install php5-gd -sudo apt-get -y install git -``` - -git clone HUGE -```bash -sudo git clone https://github.com/panique/huge "/var/www/html" -``` - -Install Composer -```bash -curl -s https://getcomposer.org/installer | php -mv composer.phar /usr/local/bin/composer -``` - -Go to project folder, load Composer packages (--dev is optional, you know the deal) -```bash -cd /var/www/html -composer install --dev -``` - -Execute the SQL statements. Via phpmyadmin or via the command line for example. 12345678 is the example password. -Note that this is written without a space. -```bash -sudo mysql -h "localhost" -u "root" "-p12345678" < "/var/www/html/application/_installation/01-create-database.sql" -sudo mysql -h "localhost" -u "root" "-p12345678" < "/var/www/html/application/_installation/02-create-table-users.sql" -sudo mysql -h "localhost" -u "root" "-p12345678" < "/var/www/html/application/_installation/03-create-table-notes.sql" -``` - -Make avatar folder writable -```bash -sudo chmod 0777 -R "/var/www/html/public/avatars" -``` - -Remove Apache's default demo file -```bash -sudo rm "/var/www/html/index.html" -``` - -Edit the application's config in application/config.development.php and put in your database credentials. - -Last part (not needed for a first test): Set your SMTP credentials in the same file and set EMAIL_USE_SMTP to true, so -you can send proper emails. It's highly recommended to use SMTP for mail sending! Native sending via PHP's mail() will -not work in nearly every case (spam blocking). I use [SMTP2GO](http://www.smtp2go.com/?s=devmetal). - -Then check your server's IP / domain. Everything should work fine. - -#### Testing with demo user - -By default HUGE has a demo-user: username is `demo`, password is `12345678`. The user is already activated. - -### What the hell are .travis.yml, .scrutinizer.yml etc. ? - -There are several files in the root folder of the project that might be irritating: - - - *.htaccess* (optionally) routes all traffic to /public/index.php! If you installed this project correctly, then this - file is not necessary, but as lots of people have problems setting up the vhost correctly, .htaccess it still there - to increase security, even on partly-broken-installations. - - *.scrutinizer.yml* (can be deleted): Configs for the external code quality analyzer Scrutinizer, just used here on - GitHub, you don't need this for your project. - - *.travis.yml* (can be deleted): Same like above. Travis is an external service that creates installations of this - repo after each code change to make sure everything runs fine. Also runs the unit tests. You don't need this inside - your project. - - *composer.json* (important): You should know what this does. ;) This file says what external dependencies are used. - - *travis-ci-apache* (can be deleted): Config file for Travis, see above, so Travis knows how to setup the Apache. - -*README* and *CHANGELOG* are self-explaining. - -#### Documentation - -A real documentation is in the making. Until then, please have a look at the code and use your IDE's code completion -features to get an idea how things work, it's quite obvious when you look at the controller files, the model files and -how data is shown in the view files. A big sorry that there's no documentation yet, but time is rare :) - - TODO: Full documentation - TODO: Basic examples on how to do things - -### Why is there no support forum (anymore) ? - -There were two (!) support forums for v1 and v2 of this project (HUGE is v3), and both were vandalized by people who -didn't even read the readme and / or the install guidelines. Most asked question was "script does not work plz help" -without giving any useful information (like code or server setup or even the version used). While I'm writing these -lines somebody just asked via Twitter "how to install without Composer". You know what I mean :) ... Beside, 140 -characters on Twitter are not a clever way to ask for / describe a complex development situation. 99% of the questions -were not necessary if the people would had read the guidelines, do a minimal research on their own or would stop making -things so unnecessarily complicated. And even when writing detailed answers most of them still messed it up, resulting -in rants and complaints (for free support for a free software!). It was just frustrating to deal with this every day, -especially when people take it for totally granted that *it's the duty* of open-source developers to give detailed, -free and personal support for every "plz help"-request. - -So I decided to completely stop any free support. For serious questions about real problems inside the script please -use the GitHub issues feature. - -### Zero tolerance for idiots, trolls and vandals! - -Harsh words, but as basically every public internet project gets harassed, vandalized and trolled these days by very -strange people it's necessary: Some simple rules. - -1. Respect that this is just a simple script written by unpaid volunteers in their free-time. - This is NOT business-software you've bought for $10.000. - There's no reason to complain (!) about free open-source software. The attitude against free software - is really frustrating these days, people take everything for granted without realizing the work behind it, and the - fact they they get serious software totally for free, saving thousands of dollars. If you don't like it, then don't - use it. If you want a feature, try to take part in the process, maybe even build it by yourself and add it to the - project! Be nice and respectful. Constructive criticism is for sure always welcome! - -2. Don't bash, don't hate, don't spam, don't vandalize. Don't ask for personal free support, don't ask if somebody - could do your work for you. Before you ask something, make sure you've read the README, followed every tutorial, - double-checked the code and tried to solve the problem by yourself. - -Trolls and very annoying people will get a permanent ban / block. GitHub has a very powerful anti-abuse team. - -### Contribute - -Please commit only in *develop* branch. The *master* branch will always contain the stable version. - -### Found a bug (Responsible Disclosure) ? - -Due to the possible consequences when publishing a bug on a public open-source project I'd kindly ask you to send really -big bugs to my email address, not posting this here. If the bug is not interesting for attackers: Feel free to create -an normal GitHub issue. - -### Current and further development - -See active issues and requested features here: -https://github.com/panique/huge/issues?state=open - -### Useful links - -- [How to use PDO](http://wiki.hashphp.org/PDO_Tutorial_for_MySQL_Developers) -- [A short guideline on how to use the PHP 5.5 password hashing functions and its PHP 5.3 & 5.4 implementations](http://www.dev-metal.com/use-php-5-5-password-hashing-functions/) -- [How to setup latest version of PHP 5.5 on Ubuntu 12.04 LTS](http://www.dev-metal.com/how-to-setup-latest-version-of-php-5-5-on-ubuntu-12-04-lts/) -- [How to setup latest version of PHP 5.5 on Debian Wheezy 7.0/7.1 (and how to fix the GPG key error)](http://www.dev-metal.com/setup-latest-version-php-5-5-debian-wheezy-7-07-1-fix-gpg-key-error/) -- [Notes on password & hashing salting in upcoming PHP versions (PHP 5.5.x & 5.6 etc.)](https://github.com/panique/huge/wiki/Notes-on-password-&-hashing-salting-in-upcoming-PHP-versions-%28PHP-5.5.x-&-5.6-etc.%29) -- [Some basic "benchmarks" of all PHP hash/salt algorithms](https://github.com/panique/huge/wiki/Which-hashing-&-salting-algorithm-should-be-used-%3F) -- [How to prevent PHP sessions being shared between different apache vhosts / different applications](http://www.dev-metal.com/prevent-php-sessions-shared-different-apache-vhosts-different-applications/) - -### Side-facts - -1. Weird! When I renamed php-login to HUGE (to get rid off the too generic project name and to make it fitting nicely - to MINI, TINY and MINI2, my other projects) I had a research if the word "huge" is already used in the php world for - sure. Nothing came up. Then, weeks later, I stumbled upon this: https://github.com/ffremont/HugeRest - I nice little framework in PHP, but it has only 1 star on Github, so it's obviously not so widely used. Looks very - professional, too. Hmm.... The guy behind published the entire readme etc. in pure french (!), so it's hard to use - for non-french-speaking people. However, I'm not related to him in any way, this is pure coincidence. diff --git a/code/web/backend/_one-click-installation/Vagrantfile b/code/web/backend/_one-click-installation/Vagrantfile deleted file mode 100644 index 0477872..0000000 --- a/code/web/backend/_one-click-installation/Vagrantfile +++ /dev/null @@ -1,22 +0,0 @@ -# -*- mode: ruby -*- -# vi: set ft=ruby : - -# Vagrantfile API/syntax version. Don't touch unless you know what you're doing! -VAGRANTFILE_API_VERSION = "2" - -Vagrant.configure(VAGRANTFILE_API_VERSION) do |config| - - # Every Vagrant virtual environment requires a box to build off of. - config.vm.box = "ubuntu/trusty64" - - # Create a private network, which allows host-only access to the machine using a specific IP. - config.vm.network "private_network", ip: "192.168.33.111" - - # Share an additional folder to the guest VM. The first argument is the path on the host to the actual folder. - # The second argument is the path on the guest to mount the folder. - config.vm.synced_folder "./", "/var/www/html" - - # Define the bootstrap file: A (shell) script that runs after first setup of your box (= provisioning) - config.vm.provision :shell, path: "bootstrap.sh" - -end diff --git a/code/web/backend/_one-click-installation/bootstrap.sh b/code/web/backend/_one-click-installation/bootstrap.sh deleted file mode 100644 index f9b7533..0000000 --- a/code/web/backend/_one-click-installation/bootstrap.sh +++ /dev/null @@ -1,83 +0,0 @@ -#!/usr/bin/env bash - -# Use single quotes instead of double quotes to make it work with special-character passwords -PASSWORD='12345678' -PROJECTFOLDER='myproject' - -# create project folder -sudo mkdir "/var/www/html/${PROJECTFOLDER}" - -sudo apt-get update -sudo apt-get -y upgrade - -sudo apt-get install -y apache2 -sudo apt-get install -y php5 - -sudo debconf-set-selections <<< "mysql-server mysql-server/root_password password $PASSWORD" -sudo debconf-set-selections <<< "mysql-server mysql-server/root_password_again password $PASSWORD" -sudo apt-get -y install mysql-server -sudo apt-get install php5-mysql - -sudo debconf-set-selections <<< "phpmyadmin phpmyadmin/dbconfig-install boolean true" -sudo debconf-set-selections <<< "phpmyadmin phpmyadmin/app-password-confirm password $PASSWORD" -sudo debconf-set-selections <<< "phpmyadmin phpmyadmin/mysql/admin-pass password $PASSWORD" -sudo debconf-set-selections <<< "phpmyadmin phpmyadmin/mysql/app-pass password $PASSWORD" -sudo debconf-set-selections <<< "phpmyadmin phpmyadmin/reconfigure-webserver multiselect apache2" -sudo apt-get -y install phpmyadmin - -# setup hosts file -VHOST=$(cat < - DocumentRoot "/var/www/html/${PROJECTFOLDER}/public" - - AllowOverride All - Require all granted - - -EOF -) -echo "${VHOST}" > /etc/apache2/sites-available/000-default.conf - -# enable mod_rewrite -sudo a2enmod rewrite - -# restart apache -service apache2 restart - -# install curl (needed to use git afaik) -sudo apt-get -y install curl -sudo apt-get -y install php5-curl - -# install openssl (needed to clone from GitHub, as github is https only) -sudo apt-get -y install openssl - -# install PHP GD, the graphic lib (we create captchas and avatars) -sudo apt-get -y install php5-gd - -# install git -sudo apt-get -y install git - -# git clone HUGE -sudo git clone https://github.com/panique/huge "/var/www/html/${PROJECTFOLDER}" - -# install Composer -curl -s https://getcomposer.org/installer | php -mv composer.phar /usr/local/bin/composer - -# go to project folder, load Composer packages -cd "/var/www/html/${PROJECTFOLDER}" -composer install --dev - -# run SQL statements from install folder -sudo mysql -h "localhost" -u "root" "-p${PASSWORD}" < "/var/www/html/${PROJECTFOLDER}/application/_installation/01-create-database.sql" -sudo mysql -h "localhost" -u "root" "-p${PASSWORD}" < "/var/www/html/${PROJECTFOLDER}/application/_installation/02-create-table-users.sql" -sudo mysql -h "localhost" -u "root" "-p${PASSWORD}" < "/var/www/html/${PROJECTFOLDER}/application/_installation/03-create-table-notes.sql" - -# writing rights to avatar folder -sudo chmod 0777 -R "/var/www/html/${PROJECTFOLDER}/public/avatars" - -# remove Apache's default demo file -sudo rm "/var/www/html/index.html" - -# final feedback -echo "Voila!" diff --git a/code/web/backend/_pictures/huge-logo.png b/code/web/backend/_pictures/huge-logo.png deleted file mode 100644 index 2cebaad..0000000 Binary files a/code/web/backend/_pictures/huge-logo.png and /dev/null differ diff --git a/code/web/backend/_pictures/support-via-a2hosting.png b/code/web/backend/_pictures/support-via-a2hosting.png deleted file mode 100644 index 33e70bd..0000000 Binary files a/code/web/backend/_pictures/support-via-a2hosting.png and /dev/null differ diff --git a/code/web/backend/_pictures/support-via-paypal.png b/code/web/backend/_pictures/support-via-paypal.png deleted file mode 100644 index c08885b..0000000 Binary files a/code/web/backend/_pictures/support-via-paypal.png and /dev/null differ diff --git a/code/web/backend/application/_installation/01-create-database.sql b/code/web/backend/application/_installation/01-create-database.sql deleted file mode 100644 index e0ffe92..0000000 --- a/code/web/backend/application/_installation/01-create-database.sql +++ /dev/null @@ -1 +0,0 @@ -CREATE DATABASE IF NOT EXISTS `huge`; diff --git a/code/web/backend/application/_installation/02-create-table-users.sql b/code/web/backend/application/_installation/02-create-table-users.sql deleted file mode 100644 index b39f832..0000000 --- a/code/web/backend/application/_installation/02-create-table-users.sql +++ /dev/null @@ -1,28 +0,0 @@ -CREATE TABLE IF NOT EXISTS `huge`.`users` ( - `user_id` int(11) NOT NULL AUTO_INCREMENT COMMENT 'auto incrementing user_id of each user, unique index', - `user_name` varchar(64) COLLATE utf8_unicode_ci NOT NULL COMMENT 'user''s name, unique', - `user_password_hash` varchar(255) COLLATE utf8_unicode_ci DEFAULT NULL COMMENT 'user''s password in salted and hashed format', - `user_email` varchar(64) COLLATE utf8_unicode_ci NOT NULL COMMENT 'user''s email, unique', - `user_active` tinyint(1) NOT NULL DEFAULT '0' COMMENT 'user''s activation status', - `user_account_type` tinyint(1) NOT NULL DEFAULT '1' COMMENT 'user''s account type (basic, premium, etc)', - `user_has_avatar` tinyint(1) NOT NULL DEFAULT '0' COMMENT '1 if user has a local avatar, 0 if not', - `user_remember_me_token` varchar(64) COLLATE utf8_unicode_ci DEFAULT NULL COMMENT 'user''s remember-me cookie token', - `user_creation_timestamp` bigint(20) DEFAULT NULL COMMENT 'timestamp of the creation of user''s account', - `user_last_login_timestamp` bigint(20) DEFAULT NULL COMMENT 'timestamp of user''s last login', - `user_failed_logins` tinyint(1) NOT NULL DEFAULT '0' COMMENT 'user''s failed login attempts', - `user_last_failed_login` int(10) DEFAULT NULL COMMENT 'unix timestamp of last failed login attempt', - `user_activation_hash` varchar(40) COLLATE utf8_unicode_ci DEFAULT NULL COMMENT 'user''s email verification hash string', - `user_password_reset_hash` char(40) COLLATE utf8_unicode_ci DEFAULT NULL COMMENT 'user''s password reset code', - `user_password_reset_timestamp` bigint(20) DEFAULT NULL COMMENT 'timestamp of the password reset request', - `user_provider_type` text COLLATE utf8_unicode_ci, - PRIMARY KEY (`user_id`), - UNIQUE KEY `user_name` (`user_name`), - UNIQUE KEY `user_email` (`user_email`) -) ENGINE=InnoDB AUTO_INCREMENT=2 DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci COMMENT='user data'; - -INSERT INTO `huge`.`users` (`user_id`, `user_name`, `user_password_hash`, `user_email`, `user_active`, `user_account_type`, -`user_has_avatar`, `user_remember_me_token`, `user_creation_timestamp`, `user_last_login_timestamp`, -`user_failed_logins`, `user_last_failed_login`, `user_activation_hash`, `user_password_reset_hash`, -`user_password_reset_timestamp`, `user_provider_type`) VALUES -(1, 'demo', '$2y$10$OvprunjvKOOhM1h9bzMPs.vuwGIsOqZbw88rzSyGCTJTcE61g5WXi', 'demo@demo.com', 1, 1, 0, NULL, 1422205178, -1422209189, 0, NULL, NULL, NULL, NULL, 'DEFAULT'); diff --git a/code/web/backend/application/_installation/03-create-table-notes.sql b/code/web/backend/application/_installation/03-create-table-notes.sql deleted file mode 100644 index 38d0368..0000000 --- a/code/web/backend/application/_installation/03-create-table-notes.sql +++ /dev/null @@ -1,6 +0,0 @@ -CREATE TABLE IF NOT EXISTS `huge`.`notes` ( - `note_id` int(11) unsigned NOT NULL AUTO_INCREMENT, - `note_text` text NOT NULL, - `user_id` int(11) unsigned NOT NULL, - PRIMARY KEY (`note_id`) -) ENGINE=InnoDB DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci COMMENT='user notes'; diff --git a/code/web/backend/application/config/config.development.php b/code/web/backend/application/config/config.development.php deleted file mode 100644 index 1ac7c5b..0000000 --- a/code/web/backend/application/config/config.development.php +++ /dev/null @@ -1,129 +0,0 @@ - 'http://' . $_SERVER['HTTP_HOST'] . str_replace('public', '', dirname($_SERVER['SCRIPT_NAME'])), - /** - * Configuration for: Folders - * Usually there's no reason to change this. - */ - 'PATH_CONTROLLER' => realpath(dirname(__FILE__).'/../../') . '/application/controller/', - 'PATH_VIEW' => realpath(dirname(__FILE__).'/../../') . '/application/view/', - /** - * Configuration for: Avatar paths - * Internal path to save avatars. Make sure this folder is writable. The slash at the end is VERY important! - */ - 'PATH_AVATARS' => realpath(dirname(__FILE__).'/../../') . '/public/avatars/', - 'PATH_AVATARS_PUBLIC' => 'avatars/', - /** - * Configuration for: Default controller and action - */ - 'DEFAULT_CONTROLLER' => 'index', - 'DEFAULT_ACTION' => 'index', - /** - * Configuration for: Database - * DB_TYPE The used database type. Note that other types than "mysql" might break the db construction currently. - * DB_HOST The mysql hostname, usually localhost or 127.0.0.1 - * DB_NAME The database name - * DB_USER The username - * DB_PASS The password - * DB_PORT The mysql port, 3306 by default (?), find out via phpinfo() and look for mysqli.default_port. - * DB_CHARSET The charset, necessary for security reasons. Check Database.php class for more info. - */ - 'DB_TYPE' => 'mysql', - 'DB_HOST' => '127.0.0.1', - 'DB_NAME' => 'huge', - 'DB_USER' => 'root', - 'DB_PASS' => '12345678', - 'DB_PORT' => '3306', - 'DB_CHARSET' => 'utf8', - /** - * Configuration for: Additional login providers: Facebook - * CURRENTLY REMOVED (as Facebook has removed support for the used API version). - * Another, better and up-to-date implementation might come soon. - */ - 'FACEBOOK_LOGIN' => false, - /** - * Configuration for: Captcha size - * The currently used Captcha generator (https://github.com/Gregwar/Captcha) also runs without giving a size, - * so feel free to use ->build(); inside CaptchaModel. - */ - 'CAPTCHA_WIDTH' => 359, - 'CAPTCHA_HEIGHT' => 100, - /** - * Configuration for: Cookies - * 1209600 seconds = 2 weeks - * COOKIE_PATH is the path the cookie is valid on, usually "/" to make it valid on the whole domain. - * @see http://stackoverflow.com/q/9618217/1114320 - * @see php.net/manual/en/function.setcookie.php - */ - 'COOKIE_RUNTIME' => 1209600, - 'COOKIE_PATH' => '/', - /** - * Configuration for: Avatars/Gravatar support - * Set to true if you want to use "Gravatar(s)", a service that automatically gets avatar pictures via using email - * addresses of users by requesting images from the gravatar.com API. Set to false to use own locally saved avatars. - * AVATAR_SIZE set the pixel size of avatars/gravatars (will be 44x44 by default). Avatars are always squares. - * AVATAR_DEFAULT_IMAGE is the default image in public/avatars/ - */ - 'USE_GRAVATAR' => false, - 'GRAVATAR_DEFAULT_IMAGESET' => 'mm', - 'GRAVATAR_RATING' => 'pg', - 'AVATAR_SIZE' => 44, - 'AVATAR_JPEG_QUALITY' => 85, - 'AVATAR_DEFAULT_IMAGE' => 'default.jpg', - /** - * Configuration for: Email server credentials - * - * Here you can define how you want to send emails. - * If you have successfully set up a mail server on your linux server and you know - * what you do, then you can skip this section. Otherwise please set EMAIL_USE_SMTP to true - * and fill in your SMTP provider account data. - * - * EMAIL_USED_MAILER: Check Mail class for alternatives - * EMAIL_USE_SMTP: Use SMTP or not - * EMAIL_SMTP_AUTH: leave this true unless your SMTP service does not need authentication - */ - 'EMAIL_USED_MAILER' => 'phpmailer', - 'EMAIL_USE_SMTP' => false, - 'EMAIL_SMTP_HOST' => 'yourhost', - 'EMAIL_SMTP_AUTH' => true, - 'EMAIL_SMTP_USERNAME' => 'yourusername', - 'EMAIL_SMTP_PASSWORD' => 'yourpassword', - 'EMAIL_SMTP_PORT' => 465, - 'EMAIL_SMTP_ENCRYPTION' => 'ssl', - /** - * Configuration for: Email content data - */ - 'EMAIL_PASSWORD_RESET_URL' => 'login/verifypasswordreset', - 'EMAIL_PASSWORD_RESET_FROM_EMAIL' => 'no-reply@example.com', - 'EMAIL_PASSWORD_RESET_FROM_NAME' => 'My Project', - 'EMAIL_PASSWORD_RESET_SUBJECT' => 'Password reset for PROJECT XY', - 'EMAIL_PASSWORD_RESET_CONTENT' => 'Please click on this link to reset your password: ', - 'EMAIL_VERIFICATION_URL' => 'login/verify', - 'EMAIL_VERIFICATION_FROM_EMAIL' => 'no-reply@example.com', - 'EMAIL_VERIFICATION_FROM_NAME' => 'My Project', - 'EMAIL_VERIFICATION_SUBJECT' => 'Account activation for PROJECT XY', - 'EMAIL_VERIFICATION_CONTENT' => 'Please click on this link to activate your account: ', -); diff --git a/code/web/backend/application/config/texts.php b/code/web/backend/application/config/texts.php deleted file mode 100644 index 6fd1c7c..0000000 --- a/code/web/backend/application/config/texts.php +++ /dev/null @@ -1,73 +0,0 @@ - "Unknown error occurred!", - "FEEDBACK_PASSWORD_WRONG_3_TIMES" => "You have typed in a wrong password 3 or more times already. Please wait 30 seconds to try again.", - "FEEDBACK_ACCOUNT_NOT_ACTIVATED_YET" => "Your account is not activated yet. Please click on the confirm link in the mail.", - "FEEDBACK_PASSWORD_WRONG" => "Password was wrong.", - "FEEDBACK_USER_DOES_NOT_EXIST" => "This user does not exist.", - "FEEDBACK_LOGIN_FAILED" => "Login failed.", - "FEEDBACK_USERNAME_FIELD_EMPTY" => "Username field was empty.", - "FEEDBACK_PASSWORD_FIELD_EMPTY" => "Password field was empty.", - "FEEDBACK_USERNAME_OR_PASSWORD_FIELD_EMPTY" => "Username or password field was empty.", - "FEEDBACK_USERNAME_EMAIL_FIELD_EMPTY" => "Username / email field was empty.", - "FEEDBACK_EMAIL_FIELD_EMPTY" => "Email field was empty.", - "FEEDBACK_EMAIL_AND_PASSWORD_FIELDS_EMPTY" => "Email and password fields were empty.", - "FEEDBACK_USERNAME_SAME_AS_OLD_ONE" => "Sorry, that username is the same as your current one. Please choose another one.", - "FEEDBACK_USERNAME_ALREADY_TAKEN" => "Sorry, that username is already taken. Please choose another one.", - "FEEDBACK_USER_EMAIL_ALREADY_TAKEN" => "Sorry, that email is already in use. Please choose another one.", - "FEEDBACK_USERNAME_CHANGE_SUCCESSFUL" => "Your username has been changed successfully.", - "FEEDBACK_USERNAME_AND_PASSWORD_FIELD_EMPTY" => "Username and password fields were empty.", - "FEEDBACK_USERNAME_DOES_NOT_FIT_PATTERN" => "Username does not fit the name pattern: only a-Z and numbers are allowed, 2 to 64 characters.", - "FEEDBACK_EMAIL_DOES_NOT_FIT_PATTERN" => "Sorry, your chosen email does not fit into the email naming pattern.", - "FEEDBACK_EMAIL_SAME_AS_OLD_ONE" => "Sorry, that email address is the same as your current one. Please choose another one.", - "FEEDBACK_EMAIL_CHANGE_SUCCESSFUL" => "Your email address has been changed successfully.", - "FEEDBACK_CAPTCHA_WRONG" => "The entered captcha security characters were wrong.", - "FEEDBACK_PASSWORD_REPEAT_WRONG" => "Password and password repeat are not the same.", - "FEEDBACK_PASSWORD_TOO_SHORT" => "Password has a minimum length of 6 characters.", - "FEEDBACK_USERNAME_TOO_SHORT_OR_TOO_LONG" => "Username cannot be shorter than 2 or longer than 64 characters.", - "FEEDBACK_ACCOUNT_SUCCESSFULLY_CREATED" => "Your account has been created successfully and we have sent you an email. Please click the VERIFICATION LINK within that mail.", - "FEEDBACK_VERIFICATION_MAIL_SENDING_FAILED" => "Sorry, we could not send you an verification mail. Your account has NOT been created.", - "FEEDBACK_ACCOUNT_CREATION_FAILED" => "Sorry, your registration failed. Please go back and try again.", - "FEEDBACK_VERIFICATION_MAIL_SENDING_ERROR" => "Verification mail could not be sent due to: ", - "FEEDBACK_VERIFICATION_MAIL_SENDING_SUCCESSFUL" => "A verification mail has been sent successfully.", - "FEEDBACK_ACCOUNT_ACTIVATION_SUCCESSFUL" => "Activation was successful! You can now log in.", - "FEEDBACK_ACCOUNT_ACTIVATION_FAILED" => "Sorry, no such id/verification code combination here...", - "FEEDBACK_AVATAR_UPLOAD_SUCCESSFUL" => "Avatar upload was successful.", - "FEEDBACK_AVATAR_UPLOAD_WRONG_TYPE" => "Only JPEG and PNG files are supported.", - "FEEDBACK_AVATAR_UPLOAD_TOO_SMALL" => "Avatar source file's width/height is too small. Needs to be 100x100 pixel minimum.", - "FEEDBACK_AVATAR_UPLOAD_TOO_BIG" => "Avatar source file is too big. 5 Megabyte is the maximum.", - "FEEDBACK_AVATAR_FOLDER_DOES_NOT_EXIST_OR_NOT_WRITABLE" => "Avatar folder does not exist or is not writable. Please change this via chmod 775 or 777.", - "FEEDBACK_AVATAR_IMAGE_UPLOAD_FAILED" => "Something went wrong with the image upload.", - "FEEDBACK_AVATAR_IMAGE_DELETE_SUCCESSFUL" => "You successfully deleted your avatar.", - "FEEDBACK_AVATAR_IMAGE_DELETE_NO_FILE" => "You don't have a custom avatar.", - "FEEDBACK_AVATAR_IMAGE_DELETE_FAILED" => "Something went wrong while deleting your avatar.", - "FEEDBACK_PASSWORD_RESET_TOKEN_FAIL" => "Could not write token to database.", - "FEEDBACK_PASSWORD_RESET_TOKEN_MISSING" => "No password reset token.", - "FEEDBACK_PASSWORD_RESET_MAIL_SENDING_ERROR" => "Password reset mail could not be sent due to: ", - "FEEDBACK_PASSWORD_RESET_MAIL_SENDING_SUCCESSFUL" => "A password reset mail has been sent successfully.", - "FEEDBACK_PASSWORD_RESET_LINK_EXPIRED" => "Your reset link has expired. Please use the reset link within one hour.", - "FEEDBACK_PASSWORD_RESET_COMBINATION_DOES_NOT_EXIST" => "Username/Verification code combination does not exist.", - "FEEDBACK_PASSWORD_RESET_LINK_VALID" => "Password reset validation link is valid. Please change the password now.", - "FEEDBACK_PASSWORD_CHANGE_SUCCESSFUL" => "Password successfully changed.", - "FEEDBACK_PASSWORD_CHANGE_FAILED" => "Sorry, your password changing failed.", - "FEEDBACK_ACCOUNT_TYPE_CHANGE_SUCCESSFUL" => "Account type change successful", - "FEEDBACK_ACCOUNT_TYPE_CHANGE_FAILED" => "Account type change failed", - "FEEDBACK_NOTE_CREATION_FAILED" => "Note creation failed.", - "FEEDBACK_NOTE_EDITING_FAILED" => "Note editing failed.", - "FEEDBACK_NOTE_DELETION_FAILED" => "Note deletion failed.", - "FEEDBACK_COOKIE_INVALID" => "Your remember-me-cookie is invalid.", - "FEEDBACK_COOKIE_LOGIN_SUCCESSFUL" => "You were successfully logged in via the remember-me-cookie.", - "FEEDBACK_FACEBOOK_LOGIN_NOT_REGISTERED" => "Sorry, you don't have an account here. Please register first.", - "FEEDBACK_FACEBOOK_EMAIL_NEEDED" => "Sorry, but you need to allow us to see your email address to register.", - "FEEDBACK_FACEBOOK_UID_ALREADY_EXISTS" => "Sorry, but you have already registered here (your Facebook ID exists in our database).", - "FEEDBACK_FACEBOOK_EMAIL_ALREADY_EXISTS" => "Sorry, but you have already registered here (your Facebook email exists in our database).", - "FEEDBACK_FACEBOOK_USERNAME_ALREADY_EXISTS" => "Sorry, but you have already registered here (your Facebook username exists in our database).", - "FEEDBACK_FACEBOOK_REGISTER_SUCCESSFUL" => "You have been successfully registered with Facebook.", - "FEEDBACK_FACEBOOK_OFFLINE" => "We could not reach the Facebook servers. Maybe Facebook is offline (that really happens sometimes).", -); \ No newline at end of file diff --git a/code/web/backend/application/controller/DashboardController.php b/code/web/backend/application/controller/DashboardController.php deleted file mode 100644 index ef82923..0000000 --- a/code/web/backend/application/controller/DashboardController.php +++ /dev/null @@ -1,26 +0,0 @@ -View->render('dashboard/index'); - } -} diff --git a/code/web/backend/application/controller/ErrorController.php b/code/web/backend/application/controller/ErrorController.php deleted file mode 100644 index 843a4b9..0000000 --- a/code/web/backend/application/controller/ErrorController.php +++ /dev/null @@ -1,25 +0,0 @@ -View->render('error/index'); - } -} diff --git a/code/web/backend/application/controller/IndexController.php b/code/web/backend/application/controller/IndexController.php deleted file mode 100644 index 8dff4eb..0000000 --- a/code/web/backend/application/controller/IndexController.php +++ /dev/null @@ -1,21 +0,0 @@ -View->render('index/index'); - } -} diff --git a/code/web/backend/application/controller/LoginController.php b/code/web/backend/application/controller/LoginController.php deleted file mode 100644 index 65aa7af..0000000 --- a/code/web/backend/application/controller/LoginController.php +++ /dev/null @@ -1,313 +0,0 @@ -View->render('login/index'); - } - } - - /** - * The login action, when you do login/login - */ - public function login() - { - // perform the login method, put result (true or false) into $login_successful - $login_successful = LoginModel::login( - Request::post('user_name'), Request::post('user_password'), Request::post('set_remember_me_cookie') - ); - - // check login status: if true, then redirect user login/showProfile, if false, then to login form again - if ($login_successful) { - Redirect::to('login/showProfile'); - } else { - Redirect::to('login/index'); - } - } - - /** - * The logout action - * Perform logout, redirect user to main-page - */ - public function logout() - { - LoginModel::logout(); - Redirect::home(); - } - - /** - * Login with cookie - */ - public function loginWithCookie() - { - // run the loginWithCookie() method in the login-model, put the result in $login_successful (true or false) - $login_successful = LoginModel::loginWithCookie(Request::cookie('remember_me')); - - // if login successful, redirect to dashboard/index ... - if ($login_successful) { - Redirect::to('dashboard/index'); - } else { - // if not, delete cookie (outdated? attack?) and route user to login form to prevent infinite login loops - LoginModel::deleteCookie(); - Redirect::to('login/index'); - } - } - - /** - * Show user's PRIVATE profile - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - */ - public function showProfile() - { - Auth::checkAuthentication(); - $this->View->render('login/showProfile', array( - 'user_name' => Session::get('user_name'), - 'user_email' => Session::get('user_email'), - 'user_gravatar_image_url' => Session::get('user_gravatar_image_url'), - 'user_avatar_file' => Session::get('user_avatar_file'), - 'user_account_type' => Session::get('user_account_type') - )); - } - - /** - * Show edit-my-username page - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - */ - public function editUsername() - { - Auth::checkAuthentication(); - $this->View->render('login/editUsername'); - } - - /** - * Edit user name (perform the real action after form has been submitted) - * Auth::checkAuthentication() makes sure that only logged in users can use this action - */ - public function editUsername_action() - { - Auth::checkAuthentication(); - UserModel::editUserName(Request::post('user_name')); - Redirect::to('login/index'); - } - - /** - * Show edit-my-user-email page - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - */ - public function editUserEmail() - { - Auth::checkAuthentication(); - $this->View->render('login/editUserEmail'); - } - - /** - * Edit user email (perform the real action after form has been submitted) - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - */ - // make this POST - public function editUserEmail_action() - { - Auth::checkAuthentication(); - UserModel::editUserEmail(Request::post('user_email')); - Redirect::to('login/editUserEmail'); - } - - /** - * Edit avatar - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - */ - public function editAvatar() - { - Auth::checkAuthentication(); - $this->View->render('login/editAvatar', array( - 'avatar_file_path' => AvatarModel::getPublicUserAvatarFilePathByUserId(Session::get('user_id')) - )); - } - - /** - * Perform the upload of the avatar - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - * POST-request - */ - public function uploadAvatar_action() - { - Auth::checkAuthentication(); - AvatarModel::createAvatar(); - Redirect::to('login/editAvatar'); - } - - /** - * Delete the current user's avatar - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - */ - public function deleteAvatar_action() - { - Auth::checkAuthentication(); - AvatarModel::deleteAvatar(Session::get("user_id")); - Redirect::to('login/editAvatar'); - } - - /** - * Show the change-account-type page - * Auth::checkAuthentication() makes sure that only logged in users can use this action and see this page - */ - public function changeUserRole() - { - Auth::checkAuthentication(); - $this->View->render('login/changeUserRole'); - } - - /** - * Perform the account-type changing - * Auth::checkAuthentication() makes sure that only logged in users can use this action - * POST-request - */ - public function changeUserRole_action() - { - Auth::checkAuthentication(); - - if (Request::post('user_account_upgrade')) { - // "2" is quick & dirty account type 2, something like "premium user" maybe. you got the idea :) - UserRoleModel::changeUserRole(2); - } - - if (Request::post('user_account_downgrade')) { - // "1" is quick & dirty account type 1, something like "basic user" maybe. - UserRoleModel::changeUserRole(1); - } - - Redirect::to('login/changeUserRole'); - } - - /** - * Register page - * Show the register form, but redirect to main-page if user is already logged-in - */ - public function register() - { - if (LoginModel::isUserLoggedIn()) { - Redirect::home(); - } else { - $this->View->render('login/register'); - } - } - - /** - * Register page action - * POST-request after form submit - */ - public function register_action() - { - $registration_successful = RegistrationModel::registerNewUser(); - - if ($registration_successful) { - Redirect::to('login/index'); - } else { - Redirect::to('login/register'); - } - } - - /** - * Verify user after activation mail link opened - * @param int $user_id user's id - * @param string $user_activation_verification_code user's verification token - */ - public function verify($user_id, $user_activation_verification_code) - { - if (isset($user_id) && isset($user_activation_verification_code)) { - RegistrationModel::verifyNewUser($user_id, $user_activation_verification_code); - $this->View->render('login/verify'); - } else { - Redirect::to('login/index'); - } - } - - /** - * Show the request-password-reset page - */ - public function requestPasswordReset() - { - $this->View->render('login/requestPasswordReset'); - } - - /** - * The request-password-reset action - * POST-request after form submit - */ - public function requestPasswordReset_action() - { - PasswordResetModel::requestPasswordReset(Request::post('user_name_or_email')); - Redirect::to('login/index'); - } - - /** - * Verify the verification token of that user (to show the user the password editing view or not) - * @param string $user_name username - * @param string $verification_code password reset verification token - */ - public function verifyPasswordReset($user_name, $verification_code) - { - // check if this the provided verification code fits the user's verification code - if (PasswordResetModel::verifyPasswordReset($user_name, $verification_code)) { - // pass URL-provided variable to view to display them - $this->View->render('login/changePassword', array( - 'user_name' => $user_name, - 'user_password_reset_hash' => $verification_code - )); - } else { - Redirect::to('login/index'); - } - } - - /** - * Set the new password - * Please note that this happens while the user is not logged in. The user identifies via the data provided by the - * password reset link from the email, automatically filled into the
fields. See verifyPasswordReset() - * for more. Then (regardless of result) route user to index page (user will get success/error via feedback message) - * POST request ! - * TODO this is an _action - */ - public function setNewPassword() - { - PasswordResetModel::setNewPassword( - Request::post('user_name'), Request::post('user_password_reset_hash'), - Request::post('user_password_new'), Request::post('user_password_repeat') - ); - Redirect::to('login/index'); - } - - /** - * Generate a captcha, write the characters into $_SESSION['captcha'] and returns a real image which will be used - * like this: - * IMPORTANT: As this action is called via AFTER the real application has finished executing (!), the - * SESSION["captcha"] has no content when the application is loaded. The SESSION["captcha"] gets filled at the - * moment the end-user requests the - * Maybe refactor this sometime. - */ - public function showCaptcha() - { - CaptchaModel::generateAndShowCaptcha(); - } -} diff --git a/code/web/backend/application/controller/NoteController.php b/code/web/backend/application/controller/NoteController.php deleted file mode 100644 index f44ee7e..0000000 --- a/code/web/backend/application/controller/NoteController.php +++ /dev/null @@ -1,77 +0,0 @@ -__construct - Auth::checkAuthentication(); - } - - /** - * This method controls what happens when you move to /note/index in your app. - * Gets all notes (of the user). - */ - public function index() - { - $this->View->render('note/index', array( - 'notes' => NoteModel::getAllNotes() - )); - } - - /** - * This method controls what happens when you move to /dashboard/create in your app. - * Creates a new note. This is usually the target of form submit actions. - * POST request. - */ - public function create() - { - NoteModel::createNote(Request::post('note_text')); - Redirect::to('note'); - } - - /** - * This method controls what happens when you move to /note/edit(/XX) in your app. - * Shows the current content of the note and an editing form. - * @param $note_id int id of the note - */ - public function edit($note_id) - { - $this->View->render('note/edit', array( - 'note' => NoteModel::getNote($note_id) - )); - } - - /** - * This method controls what happens when you move to /note/editSave in your app. - * Edits a note (performs the editing after form submit). - * POST request. - */ - public function editSave() - { - NoteModel::updateNote(Request::post('note_id'), Request::post('note_text')); - Redirect::to('note'); - } - - /** - * This method controls what happens when you move to /note/delete(/XX) in your app. - * Deletes a note. In a real application a deletion via GET/URL is not recommended, but for demo purposes it's - * totally okay. - * @param int $note_id id of the note - */ - public function delete($note_id) - { - NoteModel::deleteNote($note_id); - Redirect::to('note'); - } -} diff --git a/code/web/backend/application/controller/ProfileController.php b/code/web/backend/application/controller/ProfileController.php deleted file mode 100644 index 3cff93e..0000000 --- a/code/web/backend/application/controller/ProfileController.php +++ /dev/null @@ -1,39 +0,0 @@ -View->render('profile/index', array( - 'users' => UserModel::getPublicProfilesOfAllUsers()) - ); - } - - /** - * This method controls what happens when you move to /overview/showProfile in your app. - * Shows the (public) details of the selected user. - * @param $user_id int id the the user - */ - public function showProfile($user_id) - { - if (isset($user_id)) { - $this->View->render('profile/showProfile', array( - 'user' => UserModel::getPublicProfileOfUser($user_id)) - ); - } else { - Redirect::home(); - } - } -} diff --git a/code/web/backend/application/core/Application.php b/code/web/backend/application/core/Application.php deleted file mode 100644 index 7f87e15..0000000 --- a/code/web/backend/application/core/Application.php +++ /dev/null @@ -1,100 +0,0 @@ -splitUrl(); - - // creates controller and action names (from URL input) - $this->createControllerAndActionNames(); - - // does such a controller exist ? - if (file_exists(Config::get('PATH_CONTROLLER') . $this->controller_name . '.php')) { - - // load this file and create this controller - // example: if controller would be "car", then this line would translate into: $this->car = new car(); - require Config::get('PATH_CONTROLLER') . $this->controller_name . '.php'; - $this->controller = new $this->controller_name(); - - // check for method: does such a method exist in the controller ? - if (method_exists($this->controller, $this->action_name)) { - if (!empty($this->parameters)) { - // call the method and pass arguments to it - call_user_func_array(array($this->controller, $this->action_name), $this->parameters); - } else { - // if no parameters are given, just call the method without parameters, like $this->index->index(); - $this->controller->{$this->action_name}(); - } - } else { - header('location: ' . Config::get('URL') . 'error'); - } - } else { - header('location: ' . Config::get('URL') . 'error'); - } - } - - /** - * Get and split the URL - */ - private function splitUrl() - { - if (Request::get('url')) { - - // split URL - $url = trim(Request::get('url'), '/'); - $url = filter_var($url, FILTER_SANITIZE_URL); - $url = explode('/', $url); - - // put URL parts into according properties - $this->controller_name = isset($url[0]) ? $url[0] : null; - $this->action_name = isset($url[1]) ? $url[1] : null; - - // remove controller name and action name from the split URL - unset($url[0], $url[1]); - - // rebase array keys and store the URL parameters - $this->parameters = array_values($url); - } - } - - /** - * Checks if controller and action names are given. If not, default values are put into the properties. - * Also renames controller to usable name. - */ - private function createControllerAndActionNames() - { - // check for controller: no controller given ? then make controller = default controller (from config) - if (!$this->controller_name) { - $this->controller_name = Config::get('DEFAULT_CONTROLLER'); - } - - // check for action: no action given ? then make action = default action (from config) - if (!$this->action_name OR (strlen($this->action_name) == 0)) { - $this->action_name = Config::get('DEFAULT_ACTION'); - } - - // rename controller name to real controller class/file name ("index" to "IndexController") - $this->controller_name = ucwords($this->controller_name) . 'Controller'; - } -} diff --git a/code/web/backend/application/core/Auth.php b/code/web/backend/application/core/Auth.php deleted file mode 100644 index e193379..0000000 --- a/code/web/backend/application/core/Auth.php +++ /dev/null @@ -1,28 +0,0 @@ -View->render(); - $this->View = new View(); - } -} diff --git a/code/web/backend/application/core/DatabaseFactory.php b/code/web/backend/application/core/DatabaseFactory.php deleted file mode 100644 index e868d24..0000000 --- a/code/web/backend/application/core/DatabaseFactory.php +++ /dev/null @@ -1,46 +0,0 @@ -getConnection(); - * - * That's my personal favourite when creating a database connection. - * It's a slightly modified version of Jon Raphaelson's excellent answer on StackOverflow: - * http://stackoverflow.com/questions/130878/global-or-singleton-for-database-connection - * - * Full quote from the answer: - * - * "Then, in 6 months when your app is super famous and getting dugg and slashdotted and you decide you need more than - * a single connection, all you have to do is implement some pooling in the getConnection() method. Or if you decide - * that you want a wrapper that implements SQL logging, you can pass a PDO subclass. Or if you decide you want a new - * connection on every invocation, you can do do that. It's flexible, instead of rigid." - * - * Thanks! Big up, mate! - */ -class DatabaseFactory -{ - private static $factory; - private $database; - - public static function getFactory() - { - if (!self::$factory) { - self::$factory = new DatabaseFactory(); - } - return self::$factory; - } - - public function getConnection() { - if (!$this->database) { - $options = array(PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_OBJ, PDO::ATTR_ERRMODE => PDO::ERRMODE_WARNING); - $this->database = new PDO( - Config::get('DB_TYPE') . ':host=' . Config::get('DB_HOST') . ';dbname=' . - Config::get('DB_NAME') . ';port=' . Config::get('DB_PORT') . ';charset=' . Config::get('DB_CHARSET'), - Config::get('DB_USER'), Config::get('DB_PASS'), $options - ); - } - return $this->database; - } -} \ No newline at end of file diff --git a/code/web/backend/application/core/Environment.php b/code/web/backend/application/core/Environment.php deleted file mode 100644 index 49da44a..0000000 --- a/code/web/backend/application/core/Environment.php +++ /dev/null @@ -1,18 +0,0 @@ -IsSMTP(); - // 0 = off, 1 = commands, 2 = commands and data, perfect to see SMTP errors - $mail->SMTPDebug = 0; - // enable SMTP authentication - $mail->SMTPAuth = Config::get('EMAIL_SMTP_AUTH'); - // encryption - if (Config::get('EMAIL_SMTP_ENCRYPTION')) { - $mail->SMTPSecure = Config::get('EMAIL_SMTP_ENCRYPTION'); - } - // set SMTP provider's credentials - $mail->Host = Config::get('EMAIL_SMTP_HOST'); - $mail->Username = Config::get('EMAIL_SMTP_USERNAME'); - $mail->Password = Config::get('EMAIL_SMTP_PASSWORD'); - $mail->Port = Config::get('EMAIL_SMTP_PORT'); - } else { - $mail->IsMail(); - } - - // fill mail with data - $mail->From = $from_email; - $mail->FromName = $from_name; - $mail->AddAddress($user_email); - $mail->Subject = $subject; - $mail->Body = $body; - - // try to send mail - $mail->Send(); - - if ($mail) { - return true; - } else { - // if not successful, copy errors into Mail's error property - $this->error = $mail->ErrorInfo; - return false; - } - } - - public function sendMail($user_email, $from_email, $from_name, $subject, $body) - { - if (Config::get('EMAIL_USED_MAILER') == "phpmailer") { - // returns true if successful, false if not - return $this->sendMailWithPHPMailer( - $user_email, $from_email, $from_name, $subject, $body - ); - } - - if (Config::get('EMAIL_USED_MAILER') == "swiftmailer") { - return $this->sendMailWithSwiftMailer(); - } - - if (Config::get('EMAIL_USED_MAILER') == "native") { - return $this->sendMailWithNativeMailFunction(); - } - } - - public function getError() - { - return $this->error; - } -} diff --git a/code/web/backend/application/core/Redirect.php b/code/web/backend/application/core/Redirect.php deleted file mode 100644 index 3375638..0000000 --- a/code/web/backend/application/core/Redirect.php +++ /dev/null @@ -1,27 +0,0 @@ -view->render('help/index'); to show (in this example) the view index.php in the folder help. - * Usually the Class and the method are the same like the view, but sometimes you need to show different views. - * @param string $filename Path of the to-be-rendered view, usually folder/file(.php) - * @param array $data Data to be used in the view - */ - public function render($filename, $data = null) - { - if ($data) { - foreach ($data as $key => $value) { - $this->{$key} = $value; - } - } - - require Config::get('PATH_VIEW') . '_templates/header.php'; - require Config::get('PATH_VIEW') . $filename . '.php'; - require Config::get('PATH_VIEW') . '_templates/footer.php'; - } - - /** - * Similar to render, but accepts an array of separate views to render between the header and footer. Use like - * the following: $this->view->renderMulti(array('help/index', 'help/banner')); - * @param array $filenames Array of the paths of the to-be-rendered view, usually folder/file(.php) for each - * @param array $data Data to be used in the view - * @return bool - */ - public function renderMulti($filenames, $data = null) - { - if (!is_array($filenames)) { - self::render($filenames, $data); - return false; - } - - if ($data) { - foreach ($data as $key => $value) { - $this->{$key} = $value; - } - } - - require Config::get('PATH_VIEW') . '_templates/header.php'; - - foreach($filenames as $filename) { - require Config::get('PATH_VIEW') . $filename . '.php'; - } - - require Config::get('PATH_VIEW') . '_templates/footer.php'; - } - - /** - * Same like render(), but does not include header and footer - * @param string $filename Path of the to-be-rendered view, usually folder/file(.php) - * @param mixed $data Data to be used in the view - */ - public function renderWithoutHeaderAndFooter($filename, $data = null) - { - if ($data) { - foreach ($data as $key => $value) { - $this->{$key} = $value; - } - } - - require Config::get('PATH_VIEW') . $filename . '.php'; - } - - /** - * Renders pure JSON to the browser, useful for API construction - * @param $data - */ - public function renderJSON($data) - { - echo json_encode($data); - } - - /** - * renders the feedback messages into the view - */ - public function renderFeedbackMessages() - { - // echo out the feedback messages (errors and success messages etc.), - // they are in $_SESSION["feedback_positive"] and $_SESSION["feedback_negative"] - require Config::get('PATH_VIEW') . '_templates/feedback.php'; - - // delete these messages (as they are not needed anymore and we want to avoid to show them twice - Session::set('feedback_positive', null); - Session::set('feedback_negative', null); - } - - /** - * Checks if the passed string is the currently active controller. - * Useful for handling the navigation's active/non-active link. - * - * @param string $filename - * @param string $navigation_controller - * - * @return bool Shows if the controller is used or not - */ - public static function checkForActiveController($filename, $navigation_controller) - { - $split_filename = explode("/", $filename); - $active_controller = $split_filename[0]; - - if ($active_controller == $navigation_controller) { - return true; - } - - return false; - } - - /** - * Checks if the passed string is the currently active controller-action (=method). - * Useful for handling the navigation's active/non-active link. - * - * @param string $filename - * @param string $navigation_action - * - * @return bool Shows if the action/method is used or not - */ - public static function checkForActiveAction($filename, $navigation_action) - { - $split_filename = explode("/", $filename); - $active_action = $split_filename[1]; - - if ($active_action == $navigation_action) { - return true; - } - - return false; - } - - /** - * Checks if the passed string is the currently active controller and controller-action. - * Useful for handling the navigation's active/non-active link. - * - * @param string $filename - * @param string $navigation_controller_and_action - * - * @return bool - */ - public static function checkForActiveControllerAndAction($filename, $navigation_controller_and_action) - { - $split_filename = explode("/", $filename); - $active_controller = $split_filename[0]; - $active_action = $split_filename[1]; - - $split_filename = explode("/", $navigation_controller_and_action); - $navigation_controller = $split_filename[0]; - $navigation_action = $split_filename[1]; - - if ($active_controller == $navigation_controller AND $active_action == $navigation_action) { - return true; - } - - return false; - } -} diff --git a/code/web/backend/application/model/AvatarModel.php b/code/web/backend/application/model/AvatarModel.php deleted file mode 100644 index 0041d2c..0000000 --- a/code/web/backend/application/model/AvatarModel.php +++ /dev/null @@ -1,254 +0,0 @@ -getConnection(); - - $query = $database->prepare("SELECT user_has_avatar FROM users WHERE user_id = :user_id LIMIT 1"); - $query->execute(array(':user_id' => $user_id)); - - if ($query->fetch()->user_has_avatar) { - return Config::get('URL') . Config::get('PATH_AVATARS_PUBLIC') . $user_id . '.jpg'; - } - - return Config::get('URL') . Config::get('PATH_AVATARS_PUBLIC') . Config::get('AVATAR_DEFAULT_IMAGE'); - } - - /** - * Create an avatar picture (and checks all necessary things too) - * TODO decouple - * TODO total rebuild - */ - public static function createAvatar() - { - // check avatar folder writing rights, check if upload fits all rules - if (AvatarModel::isAvatarFolderWritable() AND AvatarModel::validateImageFile()) { - - // create a jpg file in the avatar folder, write marker to database - $target_file_path = Config::get('PATH_AVATARS') . Session::get('user_id'); - AvatarModel::resizeAvatarImage($_FILES['avatar_file']['tmp_name'], $target_file_path, Config::get('AVATAR_SIZE'), Config::get('AVATAR_SIZE'), Config::get('AVATAR_JPEG_QUALITY')); - AvatarModel::writeAvatarToDatabase(Session::get('user_id')); - Session::set('user_avatar_file', AvatarModel::getPublicUserAvatarFilePathByUserId(Session::get('user_id'))); - Session::add('feedback_positive', Text::get('FEEDBACK_AVATAR_UPLOAD_SUCCESSFUL')); - } - } - - /** - * Checks if the avatar folder exists and is writable - * - * @return bool success status - */ - public static function isAvatarFolderWritable() - { - if (is_dir(Config::get('PATH_AVATARS')) AND is_writable(Config::get('PATH_AVATARS'))) { - return true; - } - - Session::add('feedback_negative', Text::get('FEEDBACK_AVATAR_FOLDER_DOES_NOT_EXIST_OR_NOT_WRITABLE')); - return false; - } - - /** - * Validates the image - * TODO totally decouple - * - * @return bool - */ - public static function validateImageFile() - { - if (!isset($_FILES['avatar_file'])) { - Session::add('feedback_negative', Text::get('FEEDBACK_AVATAR_IMAGE_UPLOAD_FAILED')); - return false; - } - - if ($_FILES['avatar_file']['size'] > 5000000) { - // if input file too big (>5MB) - Session::add('feedback_negative', Text::get('FEEDBACK_AVATAR_UPLOAD_TOO_BIG')); - return false; - } - - // get the image width, height and mime type - $image_proportions = getimagesize($_FILES['avatar_file']['tmp_name']); - - // if input file too small - if ($image_proportions[0] < Config::get('AVATAR_SIZE') OR $image_proportions[1] < Config::get('AVATAR_SIZE')) { - Session::add('feedback_negative', Text::get('FEEDBACK_AVATAR_UPLOAD_TOO_SMALL')); - return false; - } - - if (!($image_proportions['mime'] == 'image/jpeg')) { - Session::add('feedback_negative', Text::get('FEEDBACK_AVATAR_UPLOAD_WRONG_TYPE')); - return false; - } - - return true; - } - - /** - * Writes marker to database, saying user has an avatar now - * - * @param $user_id - */ - public static function writeAvatarToDatabase($user_id) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $query = $database->prepare("UPDATE users SET user_has_avatar = TRUE WHERE user_id = :user_id LIMIT 1"); - $query->execute(array(':user_id' => $user_id)); - } - - /** - * Resize avatar image (while keeping aspect ratio and cropping it off sexy) - * - * TROUBLESHOOTING: You don't see the new image ? Press F5 or CTRL-F5 to refresh browser cache. - * - * @param string $source_image The location to the original raw image. - * @param string $destination The location to save the new image. - * @param int $final_width The desired width of the new image - * @param int $final_height The desired height of the new image. - * @param int $quality The quality of the JPG to produce 1 - 100 - * - * TODO currently we just allow .jpg - * - * @return bool success state - */ - public static function resizeAvatarImage($source_image, $destination, $final_width = 44, $final_height = 44, $quality = 85) - { - list($width, $height) = getimagesize($source_image); - - if (!$width || !$height) { - return false; - } - - //saving the image into memory (for manipulation with GD Library) - $myImage = imagecreatefromjpeg($source_image); - - // calculating the part of the image to use for thumbnail - if ($width > $height) { - $y = 0; - $x = ($width - $height) / 2; - $smallestSide = $height; - } else { - $x = 0; - $y = ($height - $width) / 2; - $smallestSide = $width; - } - - // copying the part into thumbnail, maybe edit this for square avatars - $thumb = imagecreatetruecolor($final_width, $final_height); - imagecopyresampled($thumb, $myImage, 0, 0, $x, $y, $final_width, $final_height, $smallestSide, $smallestSide); - - // add '.jpg' to file path, save it as a .jpg file with our $destination_filename parameter - $destination .= '.jpg'; - imagejpeg($thumb, $destination, $quality); - - // delete "working copy" - imagedestroy($thumb); - - if (file_exists($destination)) { - return true; - } - // default return - return false; - } - - /** - * Delete a user's avatar - * - * @param int $userId - * @return bool success - */ - public static function deleteAvatar($userId) - { - if (!ctype_digit($userId)) { - Session::add("feedback_negative", Text::get("FEEDBACK_AVATAR_IMAGE_DELETE_FAILED")); - return false; - } - - // try to delete image, but still go on regardless of file deletion result - self::deleteAvatarImageFile($userId); - - $database = DatabaseFactory::getFactory()->getConnection(); - - $sth = $database->prepare("UPDATE users SET user_has_avatar = 0 WHERE user_id = :user_id LIMIT 1"); - $sth->bindValue(":user_id", (int)$userId, PDO::PARAM_INT); - $sth->execute(); - - if ($sth->rowCount() == 1) { - Session::set('user_avatar_file', self::getPublicUserAvatarFilePathByUserId($userId)); - Session::add("feedback_positive", Text::get("FEEDBACK_AVATAR_IMAGE_DELETE_SUCCESSFUL")); - return true; - } else { - Session::add("feedback_negative", Text::get("FEEDBACK_AVATAR_IMAGE_DELETE_FAILED")); - return false; - } - } - - /** - * Removes the avatar image file from the filesystem - * - * @param $userId - * @return bool - */ - public static function deleteAvatarImageFile($userId) - { - // Check if file exists - if (!file_exists(Config::get('PATH_AVATARS') . $userId . ".jpg")) { - Session::add("feedback_negative", Text::get("FEEDBACK_AVATAR_IMAGE_DELETE_NO_FILE")); - return false; - } - - // Delete avatar file - if (!unlink(Config::get('PATH_AVATARS') . $userId . ".jpg")) { - Session::add("feedback_negative", Text::get("FEEDBACK_AVATAR_IMAGE_DELETE_FAILED")); - return false; - } - - return true; - } -} diff --git a/code/web/backend/application/model/CaptchaModel.php b/code/web/backend/application/model/CaptchaModel.php deleted file mode 100644 index 34047f5..0000000 --- a/code/web/backend/application/model/CaptchaModel.php +++ /dev/null @@ -1,46 +0,0 @@ -build( - Config::get('CAPTCHA_WIDTH'), - Config::get('CAPTCHA_HEIGHT') - ); - - // write the captcha character into session - Session::set('captcha', $captcha->getPhrase()); - - // render an image showing the characters (=the captcha) - header('Content-type: image/jpeg'); - $captcha->output(); - } - - /** - * Checks if the entered captcha is the same like the one from the rendered image which has been saved in session - * @param $captcha string The captcha characters - * @return bool success of captcha check - */ - public static function checkCaptcha($captcha) - { - if ($captcha == Session::get('captcha')) { - return true; - } - - return false; - } -} diff --git a/code/web/backend/application/model/LoginModel.php b/code/web/backend/application/model/LoginModel.php deleted file mode 100644 index 814a362..0000000 --- a/code/web/backend/application/model/LoginModel.php +++ /dev/null @@ -1,270 +0,0 @@ -user_last_failed_login > 0) { - self::resetFailedLoginCounterOfUser($result->user_name); - } - - // save timestamp of this login in the database line of that user - self::saveTimestampOfLoginOfUser($result->user_name); - - // if user has checked the "remember me" checkbox, then write token into database and into cookie - if ($set_remember_me_cookie) { - self::setRememberMeInDatabaseAndCookie($result->user_id); - } - - // successfully logged in, so we write all necessary data into the session and set "user_logged_in" to true - self::setSuccessfulLoginIntoSession( - $result->user_id, $result->user_name, $result->user_email, $result->user_account_type - ); - - // return true to make clear the login was successful - // maybe do this in dependence of setSuccessfulLoginIntoSession ? - return true; - } - - /** - * Validates the inputs of the users, checks if password is correct etc. - * If successful, user is returned - * - * @param $user_name - * @param $user_password - * - * @return bool|mixed - */ - private static function validateAndGetUser($user_name, $user_password) - { - // get all data of that user (to later check if password and password_hash fit) - $result = UserModel::getUserDataByUsername($user_name); - - // Check if that user exists. We don't give back a cause in the feedback to avoid giving an attacker details. - if (!$result) { - Session::add('feedback_negative', Text::get('FEEDBACK_LOGIN_FAILED')); - return false; - } - - // block login attempt if somebody has already failed 3 times and the last login attempt is less than 30sec ago - if (($result->user_failed_logins >= 3) AND ($result->user_last_failed_login > (time() - 30))) { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_WRONG_3_TIMES')); - return false; - } - - // if hash of provided password does NOT match the hash in the database: +1 failed-login counter - if (!password_verify($user_password, $result->user_password_hash)) { - self::incrementFailedLoginCounterOfUser($result->user_name); - // we say "password wrong" here, but less details like "login failed" would be better (= less information) - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_WRONG')); - return false; - } - - // if user is not active (= has not verified account by verification mail) - if ($result->user_active != 1) { - Session::add('feedback_negative', Text::get('FEEDBACK_ACCOUNT_NOT_ACTIVATED_YET')); - return false; - } - - return $result; - } - - /** - * performs the login via cookie (for DEFAULT user account, FACEBOOK-accounts are handled differently) - * TODO add throttling here ? - * - * @param $cookie string The cookie "remember_me" - * - * @return bool success state - */ - public static function loginWithCookie($cookie) - { - if (!$cookie) { - Session::add('feedback_negative', Text::get('FEEDBACK_COOKIE_INVALID')); - return false; - } - - // check cookie's contents, check if cookie contents belong together or token is empty - list ($user_id, $token, $hash) = explode(':', $cookie); - if ($hash !== hash('sha256', $user_id . ':' . $token) OR empty($token)) { - Session::add('feedback_negative', Text::get('FEEDBACK_COOKIE_INVALID')); - return false; - } - - // get data of user that has this id and this token - $result = UserModel::getUserDataByUserIdAndToken($user_id, $token); - if ($result) { - // successfully logged in, so we write all necessary data into the session and set "user_logged_in" to true - self::setSuccessfulLoginIntoSession($result->user_id, $result->user_name, $result->user_email, $result->user_account_type); - // save timestamp of this login in the database line of that user - self::saveTimestampOfLoginOfUser($result->user_name); - - Session::add('feedback_positive', Text::get('FEEDBACK_COOKIE_LOGIN_SUCCESSFUL')); - return true; - } else { - Session::add('feedback_negative', Text::get('FEEDBACK_COOKIE_INVALID')); - return false; - } - } - - /** - * Log out process: delete cookie, delete session - */ - public static function logout() - { - self::deleteCookie(); - Session::destroy(); - } - - /** - * The real login process: The user's data is written into the session. - * Cheesy name, maybe rename. Also maybe refactoring this, using an array. - * - * @param $user_id - * @param $user_name - * @param $user_email - * @param $user_account_type - */ - public static function setSuccessfulLoginIntoSession($user_id, $user_name, $user_email, $user_account_type) - { - Session::init(); - Session::set('user_id', $user_id); - Session::set('user_name', $user_name); - Session::set('user_email', $user_email); - Session::set('user_account_type', $user_account_type); - Session::set('user_provider_type', 'DEFAULT'); - - // get and set avatars - Session::set('user_avatar_file', AvatarModel::getPublicUserAvatarFilePathByUserId($user_id)); - Session::set('user_gravatar_image_url', AvatarModel::getGravatarLinkByEmail($user_email)); - - // finally, set user as logged-in - Session::set('user_logged_in', true); - } - - /** - * Increments the failed-login counter of a user - * - * @param $user_name - */ - public static function incrementFailedLoginCounterOfUser($user_name) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "UPDATE users - SET user_failed_logins = user_failed_logins+1, user_last_failed_login = :user_last_failed_login - WHERE user_name = :user_name OR user_email = :user_name - LIMIT 1"; - $sth = $database->prepare($sql); - $sth->execute(array(':user_name' => $user_name, ':user_last_failed_login' => time() )); - } - - /** - * Resets the failed-login counter of a user back to 0 - * - * @param $user_name - */ - public static function resetFailedLoginCounterOfUser($user_name) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "UPDATE users - SET user_failed_logins = 0, user_last_failed_login = NULL - WHERE user_name = :user_name AND user_failed_logins != 0 - LIMIT 1"; - $sth = $database->prepare($sql); - $sth->execute(array(':user_name' => $user_name)); - } - - /** - * Write timestamp of this login into database (we only write a "real" login via login form into the database, - * not the session-login on every page request - * - * @param $user_name - */ - public static function saveTimestampOfLoginOfUser($user_name) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "UPDATE users SET user_last_login_timestamp = :user_last_login_timestamp - WHERE user_name = :user_name LIMIT 1"; - $sth = $database->prepare($sql); - $sth->execute(array(':user_name' => $user_name, ':user_last_login_timestamp' => time())); - } - - /** - * Write remember-me token into database and into cookie - * Maybe splitting this into database and cookie part ? - * - * @param $user_id - */ - public static function setRememberMeInDatabaseAndCookie($user_id) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - // generate 64 char random string - $random_token_string = hash('sha256', mt_rand()); - - // write that token into database - $sql = "UPDATE users SET user_remember_me_token = :user_remember_me_token WHERE user_id = :user_id LIMIT 1"; - $sth = $database->prepare($sql); - $sth->execute(array(':user_remember_me_token' => $random_token_string, ':user_id' => $user_id)); - - // generate cookie string that consists of user id, random string and combined hash of both - $cookie_string_first_part = $user_id . ':' . $random_token_string; - $cookie_string_hash = hash('sha256', $cookie_string_first_part); - $cookie_string = $cookie_string_first_part . ':' . $cookie_string_hash; - - // set cookie - setcookie('remember_me', $cookie_string, time() + Config::get('COOKIE_RUNTIME'), Config::get('COOKIE_PATH')); - } - - /** - * Deletes the cookie - * It's necessary to split deleteCookie() and logout() as cookies are deleted without logging out too! - * Sets the remember-me-cookie to ten years ago (3600sec * 24 hours * 365 days * 10). - * that's obviously the best practice to kill a cookie @see http://stackoverflow.com/a/686166/1114320 - */ - public static function deleteCookie() - { - setcookie('remember_me', false, time() - (3600 * 24 * 3650), Config::get('COOKIE_PATH')); - } - - /** - * Returns the current state of the user's login - * - * @return bool user's login status - */ - public static function isUserLoggedIn() - { - return Session::userIsLoggedIn(); - } -} diff --git a/code/web/backend/application/model/NoteModel.php b/code/web/backend/application/model/NoteModel.php deleted file mode 100644 index 468694d..0000000 --- a/code/web/backend/application/model/NoteModel.php +++ /dev/null @@ -1,120 +0,0 @@ -getConnection(); - - $sql = "SELECT user_id, note_id, note_text FROM notes WHERE user_id = :user_id"; - $query = $database->prepare($sql); - $query->execute(array(':user_id' => Session::get('user_id'))); - - // fetchAll() is the PDO method that gets all result rows - return $query->fetchAll(); - } - - /** - * Get a single note - * @param int $note_id id of the specific note - * @return object a single object (the result) - */ - public static function getNote($note_id) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "SELECT user_id, note_id, note_text FROM notes WHERE user_id = :user_id AND note_id = :note_id LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array(':user_id' => Session::get('user_id'), ':note_id' => $note_id)); - - // fetch() is the PDO method that gets a single result - return $query->fetch(); - } - - /** - * Set a note (create a new one) - * @param string $note_text note text that will be created - * @return bool feedback (was the note created properly ?) - */ - public static function createNote($note_text) - { - if (!$note_text || strlen($note_text) == 0) { - Session::add('feedback_negative', Text::get('FEEDBACK_NOTE_CREATION_FAILED')); - return false; - } - - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "INSERT INTO notes (note_text, user_id) VALUES (:note_text, :user_id)"; - $query = $database->prepare($sql); - $query->execute(array(':note_text' => $note_text, ':user_id' => Session::get('user_id'))); - - if ($query->rowCount() == 1) { - return true; - } - - // default return - Session::add('feedback_negative', Text::get('FEEDBACK_NOTE_CREATION_FAILED')); - return false; - } - - /** - * Update an existing note - * @param int $note_id id of the specific note - * @param string $note_text new text of the specific note - * @return bool feedback (was the update successful ?) - */ - public static function updateNote($note_id, $note_text) - { - if (!$note_id || !$note_text) { - return false; - } - - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "UPDATE notes SET note_text = :note_text WHERE note_id = :note_id AND user_id = :user_id LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array(':note_id' => $note_id, ':note_text' => $note_text, ':user_id' => Session::get('user_id'))); - - if ($query->rowCount() == 1) { - return true; - } - - Session::add('feedback_negative', Text::get('FEEDBACK_NOTE_EDITING_FAILED')); - return false; - } - - /** - * Delete a specific note - * @param int $note_id id of the note - * @return bool feedback (was the note deleted properly ?) - */ - public static function deleteNote($note_id) - { - if (!$note_id) { - return false; - } - - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "DELETE FROM notes WHERE note_id = :note_id AND user_id = :user_id LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array(':note_id' => $note_id, ':user_id' => Session::get('user_id'))); - - if ($query->rowCount() == 1) { - return true; - } - - // default return - Session::add('feedback_negative', Text::get('FEEDBACK_NOTE_DELETION_FAILED')); - return false; - } -} diff --git a/code/web/backend/application/model/PasswordResetModel.php b/code/web/backend/application/model/PasswordResetModel.php deleted file mode 100644 index 10e0648..0000000 --- a/code/web/backend/application/model/PasswordResetModel.php +++ /dev/null @@ -1,251 +0,0 @@ -user_name, $user_password_reset_hash, $temporary_timestamp); - if (!$token_set) { - return false; - } - - // ... and send a mail to the user, containing a link with username and token hash string - $mail_sent = PasswordResetModel::sendPasswordResetMail($result->user_name, $user_password_reset_hash, $result->user_email); - if ($mail_sent) { - return true; - } - - // default return - return false; - } - - /** - * Set password reset token in database (for DEFAULT user accounts) - * - * @param string $user_name username - * @param string $user_password_reset_hash password reset hash - * @param int $temporary_timestamp timestamp - * - * @return bool success status - */ - public static function setPasswordResetDatabaseToken($user_name, $user_password_reset_hash, $temporary_timestamp) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "UPDATE users - SET user_password_reset_hash = :user_password_reset_hash, user_password_reset_timestamp = :user_password_reset_timestamp - WHERE user_name = :user_name AND user_provider_type = :provider_type LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array( - ':user_password_reset_hash' => $user_password_reset_hash, ':user_name' => $user_name, - ':user_password_reset_timestamp' => $temporary_timestamp, ':provider_type' => 'DEFAULT' - )); - - // check if exactly one row was successfully changed - if ($query->rowCount() == 1) { - return true; - } - - // fallback - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_RESET_TOKEN_FAIL')); - return false; - } - - /** - * Send the password reset mail - * - * @param string $user_name username - * @param string $user_password_reset_hash password reset hash - * @param string $user_email user email - * - * @return bool success status - */ - public static function sendPasswordResetMail($user_name, $user_password_reset_hash, $user_email) - { - // create email body - $body = Config::get('EMAIL_PASSWORD_RESET_CONTENT') . ' ' . Config::get('URL') . - Config::get('EMAIL_PASSWORD_RESET_URL') . '/' . urlencode($user_name) . '/' . urlencode($user_password_reset_hash); - - // create instance of Mail class, try sending and check - $mail = new Mail; - $mail_sent = $mail->sendMail($user_email, Config::get('EMAIL_PASSWORD_RESET_FROM_EMAIL'), - Config::get('EMAIL_PASSWORD_RESET_FROM_NAME'), Config::get('EMAIL_PASSWORD_RESET_SUBJECT'), $body - ); - - if ($mail_sent) { - Session::add('feedback_positive', Text::get('FEEDBACK_PASSWORD_RESET_MAIL_SENDING_SUCCESSFUL')); - return true; - } - - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_RESET_MAIL_SENDING_ERROR') . $mail->getError() ); - return false; - } - - /** - * Verifies the password reset request via the verification hash token (that's only valid for one hour) - * @param string $user_name Username - * @param string $verification_code Hash token - * @return bool Success status - */ - public static function verifyPasswordReset($user_name, $verification_code) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - // check if user-provided username + verification code combination exists - $sql = "SELECT user_id, user_password_reset_timestamp - FROM users - WHERE user_name = :user_name - AND user_password_reset_hash = :user_password_reset_hash - AND user_provider_type = :user_provider_type - LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array( - ':user_password_reset_hash' => $verification_code, ':user_name' => $user_name, - ':user_provider_type' => 'DEFAULT' - )); - - // if this user with exactly this verification hash code does NOT exist - if ($query->rowCount() != 1) { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_RESET_COMBINATION_DOES_NOT_EXIST')); - return false; - } - - // get result row (as an object) - $result_user_row = $query->fetch(); - - // 3600 seconds are 1 hour - $timestamp_one_hour_ago = time() - 3600; - - // if password reset request was sent within the last hour (this timeout is for security reasons) - if ($result_user_row->user_password_reset_timestamp > $timestamp_one_hour_ago) { - // verification was successful - Session::add('feedback_positive', Text::get('FEEDBACK_PASSWORD_RESET_LINK_VALID')); - return true; - } else { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_RESET_LINK_EXPIRED')); - return false; - } - } - - /** - * Writes the new password to the database - * - * @param string $user_name username - * @param string $user_password_hash - * @param string $user_password_reset_hash - * - * @return bool - */ - public static function saveNewUserPassword($user_name, $user_password_hash, $user_password_reset_hash) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "UPDATE users SET user_password_hash = :user_password_hash, user_password_reset_hash = NULL, - user_password_reset_timestamp = NULL - WHERE user_name = :user_name AND user_password_reset_hash = :user_password_reset_hash - AND user_provider_type = :user_provider_type LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array( - ':user_password_hash' => $user_password_hash, ':user_name' => $user_name, - ':user_password_reset_hash' => $user_password_reset_hash, ':user_provider_type' => 'DEFAULT' - )); - - // if one result exists, return true, else false. Could be written even shorter btw. - return ($query->rowCount() == 1 ? true : false); - } - - /** - * Set the new password (for DEFAULT user, FACEBOOK-users don't have a password) - * Please note: At this point the user has already pre-verified via verifyPasswordReset() (within one hour), - * so we don't need to check again for the 60min-limit here. In this method we authenticate - * via username & password-reset-hash from (hidden) form fields. - * - * @param string $user_name - * @param string $user_password_reset_hash - * @param string $user_password_new - * @param string $user_password_repeat - * - * @return bool success state of the password reset - */ - public static function setNewPassword($user_name, $user_password_reset_hash, $user_password_new, $user_password_repeat) - { - // validate the password - if (!self::validateNewPassword($user_name, $user_password_reset_hash, $user_password_new, $user_password_repeat)) { - return false; - } - - // crypt the password (with the PHP 5.5+'s password_hash() function, result is a 60 character hash string) - $user_password_hash = password_hash($user_password_new, PASSWORD_DEFAULT); - - // write the password to database (as hashed and salted string), reset user_password_reset_hash - if (PasswordResetModel::saveNewUserPassword($user_name, $user_password_hash, $user_password_reset_hash)) { - Session::add('feedback_positive', Text::get('FEEDBACK_PASSWORD_CHANGE_SUCCESSFUL')); - return true; - } else { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_CHANGE_FAILED')); - return false; - } - } - - /** - * Validate the password submission - * - * @param $user_name - * @param $user_password_reset_hash - * @param $user_password_new - * @param $user_password_repeat - * - * @return bool - */ - public static function validateNewPassword($user_name, $user_password_reset_hash, $user_password_new, $user_password_repeat) - { - if (empty($user_name)) { - Session::add('feedback_negative', Text::get('FEEDBACK_USERNAME_FIELD_EMPTY')); - return false; - } else if (empty($user_password_reset_hash)) { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_RESET_TOKEN_MISSING')); - return false; - } else if (empty($user_password_new) || empty($user_password_repeat)) { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_FIELD_EMPTY')); - return false; - } else if ($user_password_new !== $user_password_repeat) { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_REPEAT_WRONG')); - return false; - } else if (strlen($user_password_new) < 6) { - Session::add('feedback_negative', Text::get('FEEDBACK_PASSWORD_TOO_SHORT')); - return false; - } - - return true; - } -} diff --git a/code/web/backend/application/model/RegistrationModel.php b/code/web/backend/application/model/RegistrationModel.php deleted file mode 100644 index b03a7ca..0000000 --- a/code/web/backend/application/model/RegistrationModel.php +++ /dev/null @@ -1,278 +0,0 @@ -getConnection(); - - // write new users data into database - $sql = "INSERT INTO users (user_name, user_password_hash, user_email, user_creation_timestamp, user_activation_hash, user_provider_type) - VALUES (:user_name, :user_password_hash, :user_email, :user_creation_timestamp, :user_activation_hash, :user_provider_type)"; - $query = $database->prepare($sql); - $query->execute(array(':user_name' => $user_name, - ':user_password_hash' => $user_password_hash, - ':user_email' => $user_email, - ':user_creation_timestamp' => $user_creation_timestamp, - ':user_activation_hash' => $user_activation_hash, - ':user_provider_type' => 'DEFAULT')); - $count = $query->rowCount(); - if ($count == 1) { - return true; - } - - return false; - } - - /** - * Deletes the user from users table. Currently used to rollback a registration when verification mail sending - * was not successful. - * - * @param $user_id - */ - public static function rollbackRegistrationByUserId($user_id) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $query = $database->prepare("DELETE FROM users WHERE user_id = :user_id"); - $query->execute(array(':user_id' => $user_id)); - } - - /** - * Sends the verification email (to confirm the account). - * The construction of the mail $body looks weird at first, but it's really just a simple string. - * - * @param int $user_id user's id - * @param string $user_email user's email - * @param string $user_activation_hash user's mail verification hash string - * - * @return boolean gives back true if mail has been sent, gives back false if no mail could been sent - */ - public static function sendVerificationEmail($user_id, $user_email, $user_activation_hash) - { - $body = Config::get('EMAIL_VERIFICATION_CONTENT') . Config::get('URL') . Config::get('EMAIL_VERIFICATION_URL') - . '/' . urlencode($user_id) . '/' . urlencode($user_activation_hash); - - $mail = new Mail; - $mail_sent = $mail->sendMail($user_email, Config::get('EMAIL_VERIFICATION_FROM_EMAIL'), - Config::get('EMAIL_VERIFICATION_FROM_NAME'), Config::get('EMAIL_VERIFICATION_SUBJECT'), $body - ); - - if ($mail_sent) { - Session::add('feedback_positive', Text::get('FEEDBACK_VERIFICATION_MAIL_SENDING_SUCCESSFUL')); - return true; - } else { - Session::add('feedback_negative', Text::get('FEEDBACK_VERIFICATION_MAIL_SENDING_ERROR') . $mail->getError() ); - return false; - } - } - - /** - * checks the email/verification code combination and set the user's activation status to true in the database - * - * @param int $user_id user id - * @param string $user_activation_verification_code verification token - * - * @return bool success status - */ - public static function verifyNewUser($user_id, $user_activation_verification_code) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "UPDATE users SET user_active = 1, user_activation_hash = NULL - WHERE user_id = :user_id AND user_activation_hash = :user_activation_hash LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array(':user_id' => $user_id, ':user_activation_hash' => $user_activation_verification_code)); - - if ($query->rowCount() == 1) { - Session::add('feedback_positive', Text::get('FEEDBACK_ACCOUNT_ACTIVATION_SUCCESSFUL')); - return true; - } - - Session::add('feedback_negative', Text::get('FEEDBACK_ACCOUNT_ACTIVATION_FAILED')); - return false; - } -} diff --git a/code/web/backend/application/model/UserModel.php b/code/web/backend/application/model/UserModel.php deleted file mode 100644 index 3261db8..0000000 --- a/code/web/backend/application/model/UserModel.php +++ /dev/null @@ -1,331 +0,0 @@ -getConnection(); - - $sql = "SELECT user_id, user_name, user_email, user_active, user_has_avatar FROM users"; - $query = $database->prepare($sql); - $query->execute(); - - $all_users_profiles = array(); - - foreach ($query->fetchAll() as $user) { - $all_users_profiles[$user->user_id] = new stdClass(); - $all_users_profiles[$user->user_id]->user_id = $user->user_id; - $all_users_profiles[$user->user_id]->user_name = $user->user_name; - $all_users_profiles[$user->user_id]->user_email = $user->user_email; - $all_users_profiles[$user->user_id]->user_active = $user->user_active; - $all_users_profiles[$user->user_id]->user_avatar_link = (Config::get('USE_GRAVATAR') ? AvatarModel::getGravatarLinkByEmail($user->user_email) : AvatarModel::getPublicAvatarFilePathOfUser($user->user_has_avatar, $user->user_id)); - } - - return $all_users_profiles; - } - - /** - * Gets a user's profile data, according to the given $user_id - * @param int $user_id The user's id - * @return mixed The selected user's profile - */ - public static function getPublicProfileOfUser($user_id) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "SELECT user_id, user_name, user_email, user_active, user_has_avatar - FROM users WHERE user_id = :user_id LIMIT 1"; - $query = $database->prepare($sql); - $query->execute(array(':user_id' => $user_id)); - - $user = $query->fetch(); - - if ($query->rowCount() == 1) { - if (Config::get('USE_GRAVATAR')) { - $user->user_avatar_link = AvatarModel::getGravatarLinkByEmail($user->user_email); - } else { - $user->user_avatar_link = AvatarModel::getPublicAvatarFilePathOfUser($user->user_has_avatar, $user->user_id); - } - } else { - Session::add('feedback_negative', Text::get('FEEDBACK_USER_DOES_NOT_EXIST')); - } - - return $user; - } - - /** - * @param $user_name_or_email - * - * @return mixed - */ - public static function getUserDataByUserNameOrEmail($user_name_or_email) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $query = $database->prepare("SELECT user_id, user_name, user_email FROM users - WHERE (user_name = :user_name_or_email OR user_email = :user_name_or_email) - AND user_provider_type = :provider_type LIMIT 1"); - $query->execute(array(':user_name_or_email' => $user_name_or_email, ':provider_type' => 'DEFAULT')); - - return $query->fetch(); - } - - /** - * Checks if a username is already taken - * - * @param $user_name string username - * - * @return bool - */ - public static function doesUsernameAlreadyExist($user_name) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $query = $database->prepare("SELECT user_id FROM users WHERE user_name = :user_name LIMIT 1"); - $query->execute(array(':user_name' => $user_name)); - if ($query->rowCount() == 0) { - return false; - } - return true; - } - - /** - * Checks if a email is already used - * - * @param $user_email string email - * - * @return bool - */ - public static function doesEmailAlreadyExist($user_email) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $query = $database->prepare("SELECT user_id FROM users WHERE user_email = :user_email LIMIT 1"); - $query->execute(array(':user_email' => $user_email)); - if ($query->rowCount() == 0) { - return false; - } - return true; - } - - /** - * Writes new username to database - * - * @param $user_id int user id - * @param $new_user_name string new username - * - * @return bool - */ - public static function saveNewUserName($user_id, $new_user_name) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $query = $database->prepare("UPDATE users SET user_name = :user_name WHERE user_id = :user_id LIMIT 1"); - $query->execute(array(':user_name' => $new_user_name, ':user_id' => $user_id)); - if ($query->rowCount() == 1) { - return true; - } - return false; - } - - /** - * Writes new email address to database - * - * @param $user_id int user id - * @param $new_user_email string new email address - * - * @return bool - */ - public static function saveNewEmailAddress($user_id, $new_user_email) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $query = $database->prepare("UPDATE users SET user_email = :user_email WHERE user_id = :user_id LIMIT 1"); - $query->execute(array(':user_email' => $new_user_email, ':user_id' => $user_id)); - $count = $query->rowCount(); - if ($count == 1) { - return true; - } - return false; - } - - /** - * Edit the user's name, provided in the editing form - * - * @param $new_user_name string The new username - * - * @return bool success status - */ - public static function editUserName($new_user_name) - { - // new username same as old one ? - if ($new_user_name == Session::get('user_name')) { - Session::add('feedback_negative', Text::get('FEEDBACK_USERNAME_SAME_AS_OLD_ONE')); - return false; - } - - // username cannot be empty and must be azAZ09 and 2-64 characters - if (!preg_match("/^[a-zA-Z0-9]{2,64}$/", $new_user_name)) { - Session::add('feedback_negative', Text::get('FEEDBACK_USERNAME_DOES_NOT_FIT_PATTERN')); - return false; - } - - // clean the input, strip usernames longer than 64 chars (maybe fix this ?) - $new_user_name = substr(strip_tags($new_user_name), 0, 64); - - // check if new username already exists - if (UserModel::doesUsernameAlreadyExist($new_user_name)) { - Session::add('feedback_negative', Text::get('FEEDBACK_USERNAME_ALREADY_TAKEN')); - return false; - } - - $status_of_action = UserModel::saveNewUserName(Session::get('user_id'), $new_user_name); - if ($status_of_action) { - Session::set('user_name', $new_user_name); - Session::add('feedback_positive', Text::get('FEEDBACK_USERNAME_CHANGE_SUCCESSFUL')); - return true; - } else { - Session::add('feedback_negative', Text::get('FEEDBACK_UNKNOWN_ERROR')); - return false; - } - } - - /** - * Edit the user's email - * - * @param $new_user_email - * - * @return bool success status - */ - public static function editUserEmail($new_user_email) - { - // email provided ? - if (empty($new_user_email)) { - Session::add('feedback_negative', Text::get('FEEDBACK_EMAIL_FIELD_EMPTY')); - return false; - } - - // check if new email is same like the old one - if ($new_user_email == Session::get('user_email')) { - Session::add('feedback_negative', Text::get('FEEDBACK_EMAIL_SAME_AS_OLD_ONE')); - return false; - } - - // user's email must be in valid email format, also checks the length - // @see http://stackoverflow.com/questions/21631366/php-filter-validate-email-max-length - // @see http://stackoverflow.com/questions/386294/what-is-the-maximum-length-of-a-valid-email-address - if (!filter_var($new_user_email, FILTER_VALIDATE_EMAIL)) { - Session::add('feedback_negative', Text::get('FEEDBACK_EMAIL_DOES_NOT_FIT_PATTERN')); - return false; - } - - // strip tags, just to be sure - $new_user_email = substr(strip_tags($new_user_email), 0, 254); - - // check if user's email already exists - if (UserModel::doesEmailAlreadyExist($new_user_email)) { - Session::add('feedback_negative', Text::get('FEEDBACK_USER_EMAIL_ALREADY_TAKEN')); - return false; - } - - // write to database, if successful ... - // ... then write new email to session, Gravatar too (as this relies to the user's email address) - if (UserModel::saveNewEmailAddress(Session::get('user_id'), $new_user_email)) { - Session::set('user_email', $new_user_email); - Session::set('user_gravatar_image_url', AvatarModel::getGravatarLinkByEmail($new_user_email)); - Session::add('feedback_positive', Text::get('FEEDBACK_EMAIL_CHANGE_SUCCESSFUL')); - return true; - } - - Session::add('feedback_negative', Text::get('FEEDBACK_UNKNOWN_ERROR')); - return false; - } - - /** - * Gets the user's id - * - * @param $user_name - * - * @return mixed - */ - public static function getUserIdByUsername($user_name) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "SELECT user_id FROM users WHERE user_name = :user_name AND user_provider_type = :provider_type LIMIT 1"; - $query = $database->prepare($sql); - - // DEFAULT is the marker for "normal" accounts (that have a password etc.) - // There are other types of accounts that don't have passwords etc. (FACEBOOK) - $query->execute(array(':user_name' => $user_name, ':provider_type' => 'DEFAULT')); - - // return one row (we only have one result or nothing) - return $query->fetch()->user_id; - } - - /** - * Gets the user's data - * - * @param $user_name string User's name - * - * @return mixed Returns false if user does not exist, returns object with user's data when user exists - */ - public static function getUserDataByUsername($user_name) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - $sql = "SELECT user_id, user_name, user_email, user_password_hash, user_active, user_account_type, - user_failed_logins, user_last_failed_login - FROM users - WHERE (user_name = :user_name OR user_email = :user_name) - AND user_provider_type = :provider_type - LIMIT 1"; - $query = $database->prepare($sql); - - // DEFAULT is the marker for "normal" accounts (that have a password etc.) - // There are other types of accounts that don't have passwords etc. (FACEBOOK) - $query->execute(array(':user_name' => $user_name, ':provider_type' => 'DEFAULT')); - - // return one row (we only have one result or nothing) - return $query->fetch(); - } - - /** - * Gets the user's data by user's id and a token (used by login-via-cookie process) - * - * @param $user_id - * @param $token - * - * @return mixed Returns false if user does not exist, returns object with user's data when user exists - */ - public static function getUserDataByUserIdAndToken($user_id, $token) - { - $database = DatabaseFactory::getFactory()->getConnection(); - - // get real token from database (and all other data) - $query = $database->prepare("SELECT user_id, user_name, user_email, user_password_hash, user_active, - user_account_type, user_has_avatar, user_failed_logins, user_last_failed_login - FROM users - WHERE user_id = :user_id - AND user_remember_me_token = :user_remember_me_token - AND user_remember_me_token IS NOT NULL - AND user_provider_type = :provider_type LIMIT 1"); - $query->execute(array(':user_id' => $user_id, ':user_remember_me_token' => $token, ':provider_type' => 'DEFAULT')); - - // return one row (we only have one result or nothing) - return $query->fetch(); - } -} diff --git a/code/web/backend/application/model/UserRoleModel.php b/code/web/backend/application/model/UserRoleModel.php deleted file mode 100644 index f45f088..0000000 --- a/code/web/backend/application/model/UserRoleModel.php +++ /dev/null @@ -1,65 +0,0 @@ -getConnection(); - - $query = $database->prepare("UPDATE users SET user_account_type = :new_type WHERE user_id = :user_id LIMIT 1"); - $query->execute(array( - ':new_type' => $type, - ':user_id' => Session::get('user_id') - )); - - if ($query->rowCount() == 1) { - // set account type in session - Session::set('user_account_type', $type); - return true; - } - - return false; - } -} \ No newline at end of file diff --git a/code/web/backend/application/view/_templates/feedback.php b/code/web/backend/application/view/_templates/feedback.php deleted file mode 100644 index 0ab3d62..0000000 --- a/code/web/backend/application/view/_templates/feedback.php +++ /dev/null @@ -1,19 +0,0 @@ -'.$feedback.''; - } -} - -// echo out negative messages -if (isset($feedback_negative)) { - foreach ($feedback_negative as $feedback) { - echo ''; - } -} diff --git a/code/web/backend/application/view/_templates/footer.php b/code/web/backend/application/view/_templates/footer.php deleted file mode 100644 index 6829782..0000000 --- a/code/web/backend/application/view/_templates/footer.php +++ /dev/null @@ -1,7 +0,0 @@ - - - - - - - \ No newline at end of file diff --git a/code/web/backend/application/view/_templates/header.php b/code/web/backend/application/view/_templates/header.php deleted file mode 100644 index 9859a71..0000000 --- a/code/web/backend/application/view/_templates/header.php +++ /dev/null @@ -1,66 +0,0 @@ - - - - - - - - - - -
- - - - - - - - - \ No newline at end of file diff --git a/code/web/backend/application/view/dashboard/index.php b/code/web/backend/application/view/dashboard/index.php deleted file mode 100644 index 7a74d9b..0000000 --- a/code/web/backend/application/view/dashboard/index.php +++ /dev/null @@ -1,15 +0,0 @@ -
-

DashboardController/index

-
- - - renderFeedbackMessages(); ?> - -

What happens here ?

-

- This is an area that's only visible for logged in users. Try to log out, an go to /dashboard/ again. You'll - be redirected to /index/ as you are not logged in. You can protect a whole section in your app within the - according controller by placing Auth::handleLogin(); into the constructor. -

-

-
diff --git a/code/web/backend/application/view/error/index.php b/code/web/backend/application/view/error/index.php deleted file mode 100644 index 4fea684..0000000 --- a/code/web/backend/application/view/error/index.php +++ /dev/null @@ -1,6 +0,0 @@ -
-

Page not found

-
-

This page does not exist.

-
-
diff --git a/code/web/backend/application/view/index/index.php b/code/web/backend/application/view/index/index.php deleted file mode 100644 index 3061171..0000000 --- a/code/web/backend/application/view/index/index.php +++ /dev/null @@ -1,18 +0,0 @@ -
-

IndexController/index

-
- - - renderFeedbackMessages(); ?> - -

What happens here ?

-

- This is the homepage. As no real URL-route (like /login/register) is provided, the app uses the default - controller and the default action, defined in application/config/config.php, by default it's - IndexController and index()-method. So, the app will load application/controller/IndexController.php and - run index() from that file. Easy. That index()-method (= the action) has just one line of code inside - ($this->view->render('index/index');) that loads application/view/index/index.php, which is basically - this text you are reading right now. -

-
-
diff --git a/code/web/backend/application/view/login/changePassword.php b/code/web/backend/application/view/login/changePassword.php deleted file mode 100644 index 12115c5..0000000 --- a/code/web/backend/application/view/login/changePassword.php +++ /dev/null @@ -1,27 +0,0 @@ -
-

LoginController/changePassword

- - - renderFeedbackMessages(); ?> - -
-

Set new password

- -

FYI: ... Idenfitication process works via password-reset-token (hidden input field)

- - - - - - - - - - - - - Back to Login Page -
-
diff --git a/code/web/backend/application/view/login/changeUserRole.php b/code/web/backend/application/view/login/changeUserRole.php deleted file mode 100644 index 2a0951c..0000000 --- a/code/web/backend/application/view/login/changeUserRole.php +++ /dev/null @@ -1,31 +0,0 @@ -
-

LoginController/changeUserRole

- - - renderFeedbackMessages(); ?> - -
-

Change account type

-

- This page is a basic implementation of the upgrade-process. - User can click on that button to upgrade their accounts from - "basic account" to "premium account". This script simple offers - a click-able button that will upgrade/downgrade the account instantly. - In a real world application you would implement something like a - pay-process. -

-

- Please note: This whole process has been renamed from AccountType (v3.0) to UserRole (v3.1). -

- -

Currently your account type is:

- -
- - - - - -
-
-
diff --git a/code/web/backend/application/view/login/editAvatar.php b/code/web/backend/application/view/login/editAvatar.php deleted file mode 100644 index f62f4e2..0000000 --- a/code/web/backend/application/view/login/editAvatar.php +++ /dev/null @@ -1,28 +0,0 @@ -
-

Edit your avatar

- - - renderFeedbackMessages(); ?> - -
-

Upload an Avatar

- - - -
- - - - - -
-
- -
-

Delete your avatar

-

Click this link to delete your (local) avatar: Delete your avatar -

-
diff --git a/code/web/backend/application/view/login/editUserEmail.php b/code/web/backend/application/view/login/editUserEmail.php deleted file mode 100644 index 7d1097f..0000000 --- a/code/web/backend/application/view/login/editUserEmail.php +++ /dev/null @@ -1,17 +0,0 @@ -
-

LoginController/editUserEmail

- - - renderFeedbackMessages(); ?> - -
-

Change your email address

- -
- - -
-
-
diff --git a/code/web/backend/application/view/login/editUsername.php b/code/web/backend/application/view/login/editUsername.php deleted file mode 100644 index fedd113..0000000 --- a/code/web/backend/application/view/login/editUsername.php +++ /dev/null @@ -1,18 +0,0 @@ -
-

LoginController/editUsername

- - - renderFeedbackMessages(); ?> - -
-

Change your username

- -
- - - -
-
-
diff --git a/code/web/backend/application/view/login/index.php b/code/web/backend/application/view/login/index.php deleted file mode 100644 index d430350..0000000 --- a/code/web/backend/application/view/login/index.php +++ /dev/null @@ -1,34 +0,0 @@ -
- - - renderFeedbackMessages(); ?> - - -
diff --git a/code/web/backend/application/view/login/register.php b/code/web/backend/application/view/login/register.php deleted file mode 100644 index a9169c1..0000000 --- a/code/web/backend/application/view/login/register.php +++ /dev/null @@ -1,37 +0,0 @@ -
- - - renderFeedbackMessages(); ?> - - - -
-
-

- Please note: This captcha will be generated when the img tag requests the captcha-generation - (= a real image) from YOURURL/login/showcaptcha. As this is a client-side triggered request, a - $_SESSION["captcha"] dump will not show the captcha characters. The captcha generation - happens AFTER the request that generates THIS page has been finished. -

-
diff --git a/code/web/backend/application/view/login/requestPasswordReset.php b/code/web/backend/application/view/login/requestPasswordReset.php deleted file mode 100644 index ce41a08..0000000 --- a/code/web/backend/application/view/login/requestPasswordReset.php +++ /dev/null @@ -1,18 +0,0 @@ -
-

Request a password reset

-
- - - renderFeedbackMessages(); ?> - - -
- - -
- -
-
diff --git a/code/web/backend/application/view/login/showProfile.php b/code/web/backend/application/view/login/showProfile.php deleted file mode 100644 index eeadc66..0000000 --- a/code/web/backend/application/view/login/showProfile.php +++ /dev/null @@ -1,21 +0,0 @@ -
-

LoginController/showProfile

- -
-

Your profile

- - - renderFeedbackMessages(); ?> - -
Your username: user_name; ?>
-
Your email: user_email; ?>
-
Your avatar image: - - Your gravatar pic (on gravatar.com): - - Your avatar pic (saved locally): - -
-
Your account type is: user_account_type; ?>
-
-
diff --git a/code/web/backend/application/view/login/verify.php b/code/web/backend/application/view/login/verify.php deleted file mode 100644 index 6a880c4..0000000 --- a/code/web/backend/application/view/login/verify.php +++ /dev/null @@ -1,12 +0,0 @@ -
- -

Verification

-
- - - renderFeedbackMessages(); ?> - - Go back to home page -
- -
diff --git a/code/web/backend/application/view/note/edit.php b/code/web/backend/application/view/note/edit.php deleted file mode 100644 index 6e29473..0000000 --- a/code/web/backend/application/view/note/edit.php +++ /dev/null @@ -1,22 +0,0 @@ -
-

NoteController/edit/:note_id

- -
-

Edit a note

- - - renderFeedbackMessages(); ?> - - note) { ?> -
- - - - - -
- -

This note does not exist.

- -
-
diff --git a/code/web/backend/application/view/note/index.php b/code/web/backend/application/view/note/index.php deleted file mode 100644 index 13379b6..0000000 --- a/code/web/backend/application/view/note/index.php +++ /dev/null @@ -1,43 +0,0 @@ -
-

NoteController/index

-
- - - renderFeedbackMessages(); ?> - -

What happens here ?

-

- This is just a simple CRUD implementation. Creating, reading, updating and deleting things. -

-

-

- - -
-

- - notes) { ?> - - - - - - - - - - - notes as $key => $value) { ?> - - - - - - - -
IdNoteEDITDELETE
note_text); ?>EditDelete
- -
No notes yet. Create some !
- -
-
diff --git a/code/web/backend/application/view/profile/index.php b/code/web/backend/application/view/profile/index.php deleted file mode 100644 index 14e1477..0000000 --- a/code/web/backend/application/view/profile/index.php +++ /dev/null @@ -1,44 +0,0 @@ -
-

ProfileController/index

-
- - - renderFeedbackMessages(); ?> - -

What happens here ?

-
- This controller/action/view shows a list of all users in the system. You could use the underlying code to - build things that use profile information of one or multiple/all users. -
-
- - - - - - - - - - - - users as $user) { ?> - - - - - - - - - -
IdAvatarUsernameUser's emailActivated ?Link to user's profile
user_id; ?> - user_avatar_link)) { ?> - - - user_name; ?>user_email; ?>user_active == 0 ? 'No' : 'Yes'); ?> - Profile -
-
-
-
diff --git a/code/web/backend/application/view/profile/showProfile.php b/code/web/backend/application/view/profile/showProfile.php deleted file mode 100644 index dc2bdba..0000000 --- a/code/web/backend/application/view/profile/showProfile.php +++ /dev/null @@ -1,41 +0,0 @@ -
-

ProfileController/showProfile/:id

-
- - - renderFeedbackMessages(); ?> - -

What happens here ?

-
This controller/action/view shows all public information about a certain user.
- - user) { ?> -
- - - - - - - - - - - - - - - - - - - -
IdAvatarUsernameUser's emailActivated ?
user->user_id; ?> - user->user_avatar_link)) { ?> - - - user->user_name; ?>user->user_email; ?>user->user_active == 0 ? 'No' : 'Yes'); ?>
-
- - -
-
diff --git a/code/web/backend/composer.json b/code/web/backend/composer.json deleted file mode 100644 index 6c8992b..0000000 --- a/code/web/backend/composer.json +++ /dev/null @@ -1,17 +0,0 @@ -{ - "name": "panique/huge", - "type": "project", - "description": "A full-feature user authentication / login system embedded into a simple but powerful MVC framework structure", - "keywords": ["login", "auth", "user", "authentication", "mvc", "membership"], - "homepage": "https://github.com/panique/huge", - "license": "MIT", - "require-dev": { - "php": ">=5.5.0", - "phpmailer/phpmailer": "~5.2", - "gregwar/captcha": "~1.0.12", - "phpunit/phpunit": "~4.5" - }, - "autoload": { - "psr-4": { "": ["application/core/", "application/model/"] } - } -} diff --git a/code/web/backend/public/.htaccess b/code/web/backend/public/.htaccess deleted file mode 100644 index fa61be3..0000000 --- a/code/web/backend/public/.htaccess +++ /dev/null @@ -1,23 +0,0 @@ -# Necessary to prevent problems when using a controller named "index" and having a root index.php -# more here: http://httpd.apache.org/docs/2.2/content-negotiation.html -Options -MultiViews - -# Activates URL rewriting (like myproject.com/controller/action/1/2/3) -RewriteEngine On - -# Prevent people from looking directly into folders -Options -Indexes - -# If the following conditions are true, then rewrite the URL: -# If the requested filename is not a directory, -RewriteCond %{REQUEST_FILENAME} !-d -# and if the requested filename is not a regular file that exists, -RewriteCond %{REQUEST_FILENAME} !-f -# and if the requested filename is not a symbolic link, -RewriteCond %{REQUEST_FILENAME} !-l -# then rewrite the URL in the following way: -# Take the whole request filename and provide it as the value of a -# "url" query parameter to index.php. Append any query string from -# the original URL as further query parameters (QSA), and stop -# processing this .htaccess file (L). -RewriteRule ^(.+)$ index.php?url=$1 [QSA,L] diff --git a/code/web/backend/public/avatars/.htaccess b/code/web/backend/public/avatars/.htaccess deleted file mode 100644 index daf4191..0000000 --- a/code/web/backend/public/avatars/.htaccess +++ /dev/null @@ -1,7 +0,0 @@ -# TODO is this really safe ? -# this disallows direct access to the folder listing -# and disallows access to any executables files (that users may upload) -# the script allows only .jpg/.png uploads, but we never know... -Options -Indexes -Options -ExecCGI -AddHandler cgi-script .php .php3 .php4 .phtml .pl .py .jsp .asp .htm .shtml .sh .cgi diff --git a/code/web/backend/public/avatars/default.jpg b/code/web/backend/public/avatars/default.jpg deleted file mode 100644 index 45f18c7..0000000 Binary files a/code/web/backend/public/avatars/default.jpg and /dev/null differ diff --git a/code/web/backend/public/css/style.css b/code/web/backend/public/css/style.css deleted file mode 100644 index d88c288..0000000 --- a/code/web/backend/public/css/style.css +++ /dev/null @@ -1,268 +0,0 @@ -body { - font-family: Arial, sans-serif; - font-weight: 400; - font-size: 14px; -} -.wrapper { - width: 960px; - margin: 0 auto; -} -.logo { - width: 722px; - height: 450px; - /* To keep this project compact, we show a base64-encoded image, not a real file. */ - /* Excellent base64-encoders and more information here: http://base64image.org and http://www.base64-image.de */ - background-image: url(''); - margin: auto; -} -.support-button { - position: absolute; - cursor: pointer; - top: 0; - right: 0; - width: 233px; - height: 233px; - background-image: url('data:image/png;base64, '); -} -.container { - max-width: 960px; - border: 1px solid #ccc; - padding: 20px; - margin: 30px 0 30px 0; -} -.container a { - color: #454545; -} -.container table { - font-size: 11px; - margin-top: 20px; -} -.container table thead td { - background-color: #f5f5f5; - padding: 4px 10px; -} -.container table tbody td { - padding: 4px 10px; -} -.container .box { - border-top: 1px solid #ddd; - padding-top: 10px; - margin-top: 30px; -} -.container input { - background-color: #f5f5f5; - border: 0; - padding: 5px 10px; -} -.container input[type="submit"] { - background-color: #ccc; - cursor: pointer; -} -.container input[type="submit"]:hover { - background-color: #222; - color: #fff; -} -.container button { - background-color: #ccc; - border: 0; - padding: 5px 10px; - cursor: pointer; -} -.container button:hover { - background-color: #222; - color: #fff; -} - - - -/* navigation dropdown menu */ -.navigation, .navigation-submenu { - display: inline-block; - list-style: none; - /* btw this is necessary to remove most browsers's "hidden" default
    intent */ - margin: 0; - padding: 0; -} -/* TODO */ -.navigation { -} -.navigation.right { - float: right; -} -.navigation li { - float: left; - margin-right: 5px; -} -.navigation .navigation-submenu { - display: none; -} -.navigation li a { - display: block; - text-decoration: none; - padding: 10px 15px; - border: 2px solid #454545; - background: #454545; - color: #fff; - float:none; - font-size: 10px; - text-transform: uppercase; - font-weight: bold; -} -.navigation li:hover .navigation-submenu { - display: block; - position: absolute; - float: left; -} -.navigation li:hover li, -.navigation li:hover a { - float: none; -} -.navigation li a:hover, -.navigation li:hover li a:hover { - background: #fff; - color: #454545; -} - -.navigation > li.active a { - background: #fff; - color: #454545; -} -.navigation > li.active li a { - background: #454545; - color: #fff; -} - -/* overview */ -.overview-table img { - width: 40px; - height: 40px; -} - -/* feedback boxes */ -.feedback { - padding: 30px; - margin-bottom: 10px; -} -.feedback.success { - color: #558f2d; - background-color: #ddf2c0; -} -.feedback.error { - color: #ff7272; - background-color: #ffe5e5; -} -.feedback.info { - color: #00529B; - background-color: #BDE5F8; -} - -.header_right_box { - float: right; -} - -/* login screen */ -.login-page-box { - display: table; - width: 100%; -} -.login-page-box .table-wrapper { - display: table-row; -} - -.login-box { - display: table-cell; - margin: 0; - color: #777; - background-color: #f4f3f1; - padding: 20px 50px 45px 50px; - width: 49%; - box-sizing: border-box; - font-weight: 400; - text-transform: uppercase; -} -.login-box h2 { - color: #252525; -} -.login-box input[type="text"], -.login-box input[type="password"] { - font-family: Arial, sans-serif; - color: #252525; - background-color: #ffffff; - padding: 15px 20px; - margin-bottom: 10px; - display: block; - width: 100%; - box-sizing: border-box; /* modern way to say width:100% without padding */ - /*text-transform: uppercase;*/ -} -.login-box input[type="submit"] { - color: #777; - background-color: transparent; - border: 2px solid #777; - padding: 15px 20px; - margin-bottom: 10px; - display: block; - width: 100%; - box-sizing: border-box; /* modern way to say width:100% without padding */ - text-transform: uppercase; -} -.login-box input[type="submit"]:hover { - color: #fff; - border-color: #252525; - background-color: #252525; -} -.login-box .remember-me-label { - display: block; - margin-bottom: 10px; -} -.login-box .link-forgot-my-password { - display: block; - text-align: right; -} -.login-box .link-forgot-my-password a { - color: #777; - text-decoration: none; -} -.login-box .link-forgot-my-password a:hover { - text-decoration: underline; -} -.login-box ::-webkit-input-placeholder { color: #777; opacity: 0.5; } -.login-box ::-moz-placeholder { color: #777; opacity: 0.5; } -.login-box :-ms-input-placeholder { color: #777; opacity: 0.5; } -.login-box input:-moz-placeholder { color: #777; opacity: 0.5; } - -.register-box { - display: table-cell; - color: #fff; - background-color: #252525; - padding: 20px 50px 45px 50px; - width: 49%; - box-sizing: border-box; - font-weight: 400; - margin: 0; - text-transform: uppercase; -} -.register-box h2 { - color: #fff; -} -.register-box a { - width: 100%; - display: block; - box-sizing: border-box; /* modern way to say width:100% without padding */ - background-color: transparent; - border: 2px solid #fff; - padding: 15px 20px; - margin-bottom: 10px; - text-decoration: none; - text-align: center; - color: #fff; -} -.register-box a:hover { - background-color: #ffffff; - color: #252525; -} - -/* error page */ -.red-text { - color: red; -} \ No newline at end of file diff --git a/code/web/backend/public/index.php b/code/web/backend/public/index.php deleted file mode 100644 index fc3bc9b..0000000 --- a/code/web/backend/public/index.php +++ /dev/null @@ -1,17 +0,0 @@ -assertEquals('index', Config::get('DEFAULT_ACTION')); - } - - public function testGetFailingEnvironment() - { - // fake application constants - putenv('APPLICATION_ENV=foobar'); - - // call for environment should return false because config.foobar.php does not exist - $this->assertEquals(false, Config::get('DEFAULT_ACTION')); - } -} diff --git a/code/web/backend/tests/core/EnvironmentTest.php b/code/web/backend/tests/core/EnvironmentTest.php deleted file mode 100644 index a6d32cf..0000000 --- a/code/web/backend/tests/core/EnvironmentTest.php +++ /dev/null @@ -1,23 +0,0 @@ -assertEquals('development', Environment::get()); - } - - public function testGetDevelopment() - { - putenv('APPLICATION_ENV=development'); - // call for environment should return "development" - $this->assertEquals('development', Environment::get()); - } - - public function testGetProduction() - { - putenv('APPLICATION_ENV=production'); - $this->assertEquals('production', Environment::get()); - } -} diff --git a/code/web/backend/tests/core/RequestTest.php b/code/web/backend/tests/core/RequestTest.php deleted file mode 100644 index e1382b3..0000000 --- a/code/web/backend/tests/core/RequestTest.php +++ /dev/null @@ -1,29 +0,0 @@ -assertEquals(22, Request::post('test')); - $this->assertEquals(null, Request::post('not_existing_key')); - - // test trim & strip_tags: Method is used with second argument "true", triggering a cleaning of the input - $_POST["attacker_string"] = ' '; - $this->assertEquals('alert("yo!");', Request::post('attacker_string', true)); - } - - public function testGet() - { - $_GET["test"] = 33; - $this->assertEquals(33, Request::get('test')); - $this->assertEquals(null, Request::get('not_existing_key')); - } - - public function testCookie() - { - $_COOKIE["test"] = 44; - $this->assertEquals(44, Request::cookie('test')); - $this->assertEquals(null, Request::cookie('not_existing_key')); - } -} diff --git a/code/web/backend/tests/core/TextTest.php b/code/web/backend/tests/core/TextTest.php deleted file mode 100644 index 1e12d70..0000000 --- a/code/web/backend/tests/core/TextTest.php +++ /dev/null @@ -1,28 +0,0 @@ -assertEquals('Password was wrong.', Text::get('FEEDBACK_PASSWORD_WRONG')); - } - - /** - * When argument is null, should return null - */ - public function testGetWithNullKey() - { - $this->assertEquals(null, Text::get(null)); - } - - /** - * When key does not exist in text data file, should return null - */ - public function testGetWithNonExistingKey() - { - $this->assertEquals(null, Text::get('XXX')); - } -} diff --git a/code/web/backend/tests/phpunit.xml b/code/web/backend/tests/phpunit.xml deleted file mode 100644 index a4f056a..0000000 --- a/code/web/backend/tests/phpunit.xml +++ /dev/null @@ -1,17 +0,0 @@ - - - - - ./core/ - - - \ No newline at end of file diff --git a/code/web/backend/travis-ci-apache b/code/web/backend/travis-ci-apache deleted file mode 100644 index 10050bf..0000000 --- a/code/web/backend/travis-ci-apache +++ /dev/null @@ -1,7 +0,0 @@ - - DocumentRoot "%TRAVIS_BUILD_DIR%/public" - - AllowOverride All - Require all granted - - diff --git a/code/web/frontend/README.md b/code/web/frontend/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/doc/Command Process.dia b/doc/Command Process.dia deleted file mode 100644 index 4c5170c..0000000 Binary files a/doc/Command Process.dia and /dev/null differ diff --git a/system/BASE_SOFT/APACHE/2.2/README.md b/system/BASE_SOFT/APACHE/2.2/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/APACHE/2.4/.htpasswd b/system/BASE_SOFT/APACHE/2.4/.htpasswd deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/APACHE/2.4/README.md b/system/BASE_SOFT/APACHE/2.4/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/APACHE/2.4/apache2.conf b/system/BASE_SOFT/APACHE/2.4/apache2.conf deleted file mode 100644 index 0573517..0000000 --- a/system/BASE_SOFT/APACHE/2.4/apache2.conf +++ /dev/null @@ -1,46 +0,0 @@ -ServerTokens Prod -ServerSignature Off - -TraceEnable Off - -ServerName sevppdlmp01.nexen.net -ServerRoot /etc/apache2 -PidFile ${APACHE_PID_FILE} -Timeout 300 -KeepAlive Off -MaxKeepAliveRequests 100 -KeepAliveTimeout 15 -LimitRequestFieldSize 8190 - -User www-data -Group www-data - -AccessFileName .htaccess - -Require all denied - - - - Options FollowSymLinks - AllowOverride None - - -HostnameLookups Off -LogLevel warn -EnableSendfile On -Include "/etc/apache2/mods-enabled/*.load" -Include "/etc/apache2/mods-enabled/*.conf" -Include "/etc/apache2/ports.conf" - -LogFormat "%{X-Forwarded-For}i %a %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\" %b %D %T %P %V:%p" syslog -CustomLog "|/bin/sh -c 'logger -p local7.info -t apache_access_log'" syslog -ErrorLog "|/bin/sh -c 'logger -p local7.err -t apache_error_log'" -IncludeOptional "/etc/apache2/conf.d/*.conf" -IncludeOptional "/etc/apache2/sites-enabled/*" - -## Settings debugging information in headers. -SetEnvIf Remote_Addr 127.0.0.1 DEBUG - - Header set X-Apache-Server-ID "sevppdlmp01" env=DEBUG - - diff --git a/system/BASE_SOFT/APACHE/2.4/conf-available/README.md b/system/BASE_SOFT/APACHE/2.4/conf-available/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/APACHE/2.4/conf-available/charset.conf b/system/BASE_SOFT/APACHE/2.4/conf-available/charset.conf deleted file mode 100644 index 8b0f415..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-available/charset.conf +++ /dev/null @@ -1,8 +0,0 @@ -# Read the documentation before enabling AddDefaultCharset. -# In general, it is only a good idea if you know that all your files -# have this encoding. It will override any encoding given in the files -# in meta http-equiv or xml encoding tags. - -#AddDefaultCharset UTF-8 - -# vim: syntax=apache ts=4 sw=4 sts=4 sr noet diff --git a/system/BASE_SOFT/APACHE/2.4/conf-available/javascript-common.conf b/system/BASE_SOFT/APACHE/2.4/conf-available/javascript-common.conf deleted file mode 100644 index 7e5dbd3..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-available/javascript-common.conf +++ /dev/null @@ -1,5 +0,0 @@ -Alias /javascript /usr/share/javascript/ - - - Options FollowSymLinks MultiViews - diff --git a/system/BASE_SOFT/APACHE/2.4/conf-available/localized-error-pages.conf b/system/BASE_SOFT/APACHE/2.4/conf-available/localized-error-pages.conf deleted file mode 100644 index f188d80..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-available/localized-error-pages.conf +++ /dev/null @@ -1,81 +0,0 @@ -# Customizable error responses come in three flavors: -# 1) plain text -# 2) local redirects -# 3) external redirects -# -# Some examples: -#ErrorDocument 500 "The server made a boo boo." -#ErrorDocument 404 /missing.html -#ErrorDocument 404 "/cgi-bin/missing_handler.pl" -#ErrorDocument 402 http://www.example.com/subscription_info.html -# - -# -# Putting this all together, we can internationalize error responses. -# -# We use Alias to redirect any /error/HTTP_.html.var response to -# our collection of by-error message multi-language collections. We use -# includes to substitute the appropriate text. -# -# You can modify the messages' appearance without changing any of the -# default HTTP_.html.var files by adding the line: -# -#Alias /error/include/ "/your/include/path/" -# -# which allows you to create your own set of files by starting with the -# /usr/share/apache2/error/include/ files and copying them to /your/include/path/, -# even on a per-VirtualHost basis. If you include the Alias in the global server -# context, is has to come _before_ the 'Alias /error/ ...' line. -# -# The default include files will display your Apache version number and your -# ServerAdmin email address regardless of the setting of ServerSignature. -# -# WARNING: The configuration below will NOT work out of the box if you have a -# SetHandler directive in a context somewhere. Adding -# the following three lines AFTER the context should -# make it work in most cases: -# -# SetHandler none -# -# -# The internationalized error documents require mod_alias, mod_include -# and mod_negotiation. To activate them, uncomment the following 37 lines. - -# -# -# -# -# Alias /error/ "/usr/share/apache2/error/" -# -# -# Options IncludesNoExec -# AddOutputFilter Includes html -# AddHandler type-map var -# Order allow,deny -# Allow from all -# LanguagePriority en cs de es fr it nl sv pt-br ro -# ForceLanguagePriority Prefer Fallback -# -# -# ErrorDocument 400 /error/HTTP_BAD_REQUEST.html.var -# ErrorDocument 401 /error/HTTP_UNAUTHORIZED.html.var -# ErrorDocument 403 /error/HTTP_FORBIDDEN.html.var -# ErrorDocument 404 /error/HTTP_NOT_FOUND.html.var -# ErrorDocument 405 /error/HTTP_METHOD_NOT_ALLOWED.html.var -# ErrorDocument 408 /error/HTTP_REQUEST_TIME_OUT.html.var -# ErrorDocument 410 /error/HTTP_GONE.html.var -# ErrorDocument 411 /error/HTTP_LENGTH_REQUIRED.html.var -# ErrorDocument 412 /error/HTTP_PRECONDITION_FAILED.html.var -# ErrorDocument 413 /error/HTTP_REQUEST_ENTITY_TOO_LARGE.html.var -# ErrorDocument 414 /error/HTTP_REQUEST_URI_TOO_LARGE.html.var -# ErrorDocument 415 /error/HTTP_UNSUPPORTED_MEDIA_TYPE.html.var -# ErrorDocument 500 /error/HTTP_INTERNAL_SERVER_ERROR.html.var -# ErrorDocument 501 /error/HTTP_NOT_IMPLEMENTED.html.var -# ErrorDocument 502 /error/HTTP_BAD_GATEWAY.html.var -# ErrorDocument 503 /error/HTTP_SERVICE_UNAVAILABLE.html.var -# ErrorDocument 506 /error/HTTP_VARIANT_ALSO_VARIES.html.var -# -# -# - -# vim: syntax=apache ts=4 sw=4 sts=4 sr noet diff --git a/system/BASE_SOFT/APACHE/2.4/conf-available/other-vhosts-access-log.conf b/system/BASE_SOFT/APACHE/2.4/conf-available/other-vhosts-access-log.conf deleted file mode 100644 index 5e9f5e9..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-available/other-vhosts-access-log.conf +++ /dev/null @@ -1,4 +0,0 @@ -# Define an access log for VirtualHosts that don't define their own logfile -CustomLog ${APACHE_LOG_DIR}/other_vhosts_access.log vhost_combined - -# vim: syntax=apache ts=4 sw=4 sts=4 sr noet diff --git a/system/BASE_SOFT/APACHE/2.4/conf-available/security.conf b/system/BASE_SOFT/APACHE/2.4/conf-available/security.conf deleted file mode 100644 index d008271..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-available/security.conf +++ /dev/null @@ -1,72 +0,0 @@ -# -# Disable access to the entire file system except for the directories that -# are explicitly allowed later. -# -# This currently breaks the configurations that come with some web application -# Debian packages. -# -# -# AllowOverride None -# Order Deny,Allow -# Deny from all -# - - -# Changing the following options will not really affect the security of the -# server, but might make attacks slightly more difficult in some cases. - -# -# ServerTokens -# This directive configures what you return as the Server HTTP response -# Header. The default is 'Full' which sends information about the OS-Type -# and compiled in modules. -# Set to one of: Full | OS | Minimal | Minor | Major | Prod -# where Full conveys the most information, and Prod the least. -ServerTokens Prod - -# -# Optionally add a line containing the server version and virtual host -# name to server-generated pages (internal error documents, FTP directory -# listings, mod_status and mod_info output etc., but not CGI generated -# documents or custom error documents). -# Set to "EMail" to also include a mailto: link to the ServerAdmin. -# Set to one of: On | Off | EMail -ServerSignature Off -#ServerSignature On - -# -# Allow TRACE method -# -# Set to "extended" to also reflect the request body (only for testing and -# diagnostic purposes). -# -# Set to one of: On | Off | extended -TraceEnable Off -#TraceEnable On - -# -# Forbid access to version control directories -# -# If you use version control systems in your document root, you should -# probably deny access to their directories. For example, for subversion: -# -# -# Require all denied -# - -# -# Setting this header will prevent MSIE from interpreting files as something -# else than declared by the content type in the HTTP headers. -# Requires mod_headers to be enabled. -# -#Header set X-Content-Type-Options: "nosniff" - -# -# Setting this header will prevent other sites from embedding pages from this -# site as frames. This defends against clickjacking attacks. -# Requires mod_headers to be enabled. -# -#Header set X-Frame-Options: "sameorigin" - - -# vim: syntax=apache ts=4 sw=4 sts=4 sr noet diff --git a/system/BASE_SOFT/APACHE/2.4/conf-available/serve-cgi-bin.conf b/system/BASE_SOFT/APACHE/2.4/conf-available/serve-cgi-bin.conf deleted file mode 100644 index b02782d..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-available/serve-cgi-bin.conf +++ /dev/null @@ -1,20 +0,0 @@ - - - Define ENABLE_USR_LIB_CGI_BIN - - - - Define ENABLE_USR_LIB_CGI_BIN - - - - ScriptAlias /cgi-bin/ /usr/lib/cgi-bin/ - - AllowOverride None - Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch - Require all granted - - - - -# vim: syntax=apache ts=4 sw=4 sts=4 sr noet diff --git a/system/BASE_SOFT/APACHE/2.4/conf-enabled/README.md b/system/BASE_SOFT/APACHE/2.4/conf-enabled/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/APACHE/2.4/conf-enabled/charset.conf b/system/BASE_SOFT/APACHE/2.4/conf-enabled/charset.conf deleted file mode 120000 index 4a6ca08..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-enabled/charset.conf +++ /dev/null @@ -1 +0,0 @@ -../conf-available/charset.conf \ No newline at end of file diff --git a/system/BASE_SOFT/APACHE/2.4/conf-enabled/localized-error-pages.conf b/system/BASE_SOFT/APACHE/2.4/conf-enabled/localized-error-pages.conf deleted file mode 120000 index 6e5ddaf..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-enabled/localized-error-pages.conf +++ /dev/null @@ -1 +0,0 @@ -../conf-available/localized-error-pages.conf \ No newline at end of file diff --git a/system/BASE_SOFT/APACHE/2.4/conf-enabled/other-vhosts-access-log.conf b/system/BASE_SOFT/APACHE/2.4/conf-enabled/other-vhosts-access-log.conf deleted file mode 120000 index 8af91e5..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-enabled/other-vhosts-access-log.conf +++ /dev/null @@ -1 +0,0 @@ -../conf-available/other-vhosts-access-log.conf \ No newline at end of file diff --git a/system/BASE_SOFT/APACHE/2.4/conf-enabled/security.conf b/system/BASE_SOFT/APACHE/2.4/conf-enabled/security.conf deleted file mode 120000 index 036c97f..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-enabled/security.conf +++ /dev/null @@ -1 +0,0 @@ -../conf-available/security.conf \ No newline at end of file diff --git a/system/BASE_SOFT/APACHE/2.4/conf-enabled/serve-cgi-bin.conf b/system/BASE_SOFT/APACHE/2.4/conf-enabled/serve-cgi-bin.conf deleted file mode 120000 index d917f68..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf-enabled/serve-cgi-bin.conf +++ /dev/null @@ -1 +0,0 @@ -../conf-available/serve-cgi-bin.conf \ No newline at end of file diff --git a/system/BASE_SOFT/APACHE/2.4/conf.d/README.md b/system/BASE_SOFT/APACHE/2.4/conf.d/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/APACHE/2.4/conf.d/awhsecure.conf b/system/BASE_SOFT/APACHE/2.4/conf.d/awhsecure.conf deleted file mode 100644 index 8afa809..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf.d/awhsecure.conf +++ /dev/null @@ -1,13 +0,0 @@ - - Order allow,deny - Deny from all - - - - Order allow,deny - Deny from all - - - - Options -Indexes - diff --git a/system/BASE_SOFT/APACHE/2.4/conf.d/badbot.conf b/system/BASE_SOFT/APACHE/2.4/conf.d/badbot.conf deleted file mode 100644 index 41f6d29..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf.d/badbot.conf +++ /dev/null @@ -1,222 +0,0 @@ -# Block Bad Bots & Scrapers -SetEnvIfNoCase User-Agent "Aboundex" bad_bot -SetEnvIfNoCase User-Agent "80legs" bad_bot -SetEnvIfNoCase User-Agent "360Spider" bad_bot -SetEnvIfNoCase User-Agent "^Java" bad_bot -SetEnvIfNoCase User-Agent "^Cogentbot" bad_bot -SetEnvIfNoCase User-Agent "^Alexibot" bad_bot -SetEnvIfNoCase User-Agent "^asterias" bad_bot -SetEnvIfNoCase User-Agent "^attach" bad_bot -SetEnvIfNoCase User-Agent "^BackDoorBot" bad_bot -SetEnvIfNoCase User-Agent "^BackWeb" bad_bot -SetEnvIfNoCase User-Agent "Bandit" bad_bot -SetEnvIfNoCase User-Agent "^BatchFTP" bad_bot -SetEnvIfNoCase User-Agent "^Bigfoot" bad_bot -SetEnvIfNoCase User-Agent "^Black.Hole" bad_bot -SetEnvIfNoCase User-Agent "^BlackWidow" bad_bot -SetEnvIfNoCase User-Agent "^BlowFish" bad_bot -SetEnvIfNoCase User-Agent "^BotALot" bad_bot -SetEnvIfNoCase User-Agent "Buddy" bad_bot -SetEnvIfNoCase User-Agent "^BuiltBotTough" bad_bot -SetEnvIfNoCase User-Agent "^Bullseye" bad_bot -SetEnvIfNoCase User-Agent "^BunnySlippers" bad_bot -SetEnvIfNoCase User-Agent "^Cegbfeieh" bad_bot -SetEnvIfNoCase User-Agent "^CheeseBot" bad_bot -SetEnvIfNoCase User-Agent "^CherryPicker" bad_bot -SetEnvIfNoCase User-Agent "^ChinaClaw" bad_bot -SetEnvIfNoCase User-Agent "Collector" bad_bot -SetEnvIfNoCase User-Agent "Copier" bad_bot -SetEnvIfNoCase User-Agent "^CopyRightCheck" bad_bot -SetEnvIfNoCase User-Agent "^cosmos" bad_bot -SetEnvIfNoCase User-Agent "^Crescent" bad_bot -SetEnvIfNoCase User-Agent "^Custo" bad_bot -SetEnvIfNoCase User-Agent "^AIBOT" bad_bot -SetEnvIfNoCase User-Agent "^DISCo" bad_bot -SetEnvIfNoCase User-Agent "^DIIbot" bad_bot -SetEnvIfNoCase User-Agent "^DittoSpyder" bad_bot -SetEnvIfNoCase User-Agent "^Download\ Demon" bad_bot -SetEnvIfNoCase User-Agent "^Download\ Devil" bad_bot -SetEnvIfNoCase User-Agent "^Download\ Wonder" bad_bot -SetEnvIfNoCase User-Agent "^dragonfly" bad_bot -SetEnvIfNoCase User-Agent "^Drip" bad_bot -SetEnvIfNoCase User-Agent "^eCatch" bad_bot -SetEnvIfNoCase User-Agent "^EasyDL" bad_bot -SetEnvIfNoCase User-Agent "^ebingbong" bad_bot -SetEnvIfNoCase User-Agent "^EirGrabber" bad_bot -SetEnvIfNoCase User-Agent "^EmailCollector" bad_bot -SetEnvIfNoCase User-Agent "^EmailSiphon" bad_bot -SetEnvIfNoCase User-Agent "^EmailWolf" bad_bot -SetEnvIfNoCase User-Agent "^EroCrawler" bad_bot -SetEnvIfNoCase User-Agent "^Exabot" bad_bot -SetEnvIfNoCase User-Agent "^Express\ WebPictures" bad_bot -SetEnvIfNoCase User-Agent "Extractor" bad_bot -SetEnvIfNoCase User-Agent "^EyeNetIE" bad_bot -SetEnvIfNoCase User-Agent "^Foobot" bad_bot -SetEnvIfNoCase User-Agent "^flunky" bad_bot -SetEnvIfNoCase User-Agent "^FrontPage" bad_bot -SetEnvIfNoCase User-Agent "^Go-Ahead-Got-It" bad_bot -SetEnvIfNoCase User-Agent "^gotit" bad_bot -SetEnvIfNoCase User-Agent "^GrabNet" bad_bot -SetEnvIfNoCase User-Agent "^Grafula" bad_bot -SetEnvIfNoCase User-Agent "^Harvest" bad_bot -SetEnvIfNoCase User-Agent "^hloader" bad_bot -SetEnvIfNoCase User-Agent "^HMView" bad_bot -SetEnvIfNoCase User-Agent "^HTTrack" bad_bot -SetEnvIfNoCase User-Agent "^humanlinks" bad_bot -SetEnvIfNoCase User-Agent "^IlseBot" bad_bot -SetEnvIfNoCase User-Agent "^Image\ Stripper" bad_bot -SetEnvIfNoCase User-Agent "^Image\ Sucker" bad_bot -SetEnvIfNoCase User-Agent "Indy\ Library" bad_bot -SetEnvIfNoCase User-Agent "^InfoNaviRobot" bad_bot -SetEnvIfNoCase User-Agent "^InfoTekies" bad_bot -SetEnvIfNoCase User-Agent "^Intelliseek" bad_bot -SetEnvIfNoCase User-Agent "^InterGET" bad_bot -SetEnvIfNoCase User-Agent "^Internet\ Ninja" bad_bot -SetEnvIfNoCase User-Agent "^Iria" bad_bot -SetEnvIfNoCase User-Agent "^Jakarta" bad_bot -SetEnvIfNoCase User-Agent "^JennyBot" bad_bot -SetEnvIfNoCase User-Agent "^JetCar" bad_bot -SetEnvIfNoCase User-Agent "^JOC" bad_bot -SetEnvIfNoCase User-Agent "^JustView" bad_bot -SetEnvIfNoCase User-Agent "^Jyxobot" bad_bot -SetEnvIfNoCase User-Agent "^Kenjin.Spider" bad_bot -SetEnvIfNoCase User-Agent "^Keyword.Density" bad_bot -SetEnvIfNoCase User-Agent "^larbin" bad_bot -SetEnvIfNoCase User-Agent "^LexiBot" bad_bot -SetEnvIfNoCase User-Agent "^lftp" bad_bot -SetEnvIfNoCase User-Agent "^libWeb/clsHTTP" bad_bot -SetEnvIfNoCase User-Agent "^likse" bad_bot -SetEnvIfNoCase User-Agent "^LinkextractorPro" bad_bot -SetEnvIfNoCase User-Agent "^LinkScan/8.1a.Unix" bad_bot -SetEnvIfNoCase User-Agent "^LNSpiderguy" bad_bot -SetEnvIfNoCase User-Agent "^LinkWalker" bad_bot -SetEnvIfNoCase User-Agent "^lwp-trivial" bad_bot -SetEnvIfNoCase User-Agent "^LWP::Simple" bad_bot -SetEnvIfNoCase User-Agent "^Magnet" bad_bot -SetEnvIfNoCase User-Agent "^Mag-Net" bad_bot -SetEnvIfNoCase User-Agent "^MarkWatch" bad_bot -SetEnvIfNoCase User-Agent "^Mass\ Downloader" bad_bot -SetEnvIfNoCase User-Agent "^Mata.Hari" bad_bot -SetEnvIfNoCase User-Agent "^Memo" bad_bot -SetEnvIfNoCase User-Agent "^Microsoft.URL" bad_bot -SetEnvIfNoCase User-Agent "^Microsoft\ URL\ Control" bad_bot -SetEnvIfNoCase User-Agent "^MIDown\ tool" bad_bot -SetEnvIfNoCase User-Agent "^MIIxpc" bad_bot -SetEnvIfNoCase User-Agent "^Mirror" bad_bot -SetEnvIfNoCase User-Agent "^Missigua\ Locator" bad_bot -SetEnvIfNoCase User-Agent "^Mister\ PiX" bad_bot -SetEnvIfNoCase User-Agent "^moget" bad_bot -SetEnvIfNoCase User-Agent "^Mozilla/3.Mozilla/2.01" bad_bot -SetEnvIfNoCase User-Agent "^Mozilla.*NEWT" bad_bot -SetEnvIfNoCase User-Agent "^NAMEPROTECT" bad_bot -SetEnvIfNoCase User-Agent "^Navroad" bad_bot -SetEnvIfNoCase User-Agent "^NearSite" bad_bot -SetEnvIfNoCase User-Agent "^NetAnts" bad_bot -SetEnvIfNoCase User-Agent "^Netcraft" bad_bot -SetEnvIfNoCase User-Agent "^NetMechanic" bad_bot -SetEnvIfNoCase User-Agent "^NetSpider" bad_bot -SetEnvIfNoCase User-Agent "^Net\ Vampire" bad_bot -SetEnvIfNoCase User-Agent "^NetZIP" bad_bot -SetEnvIfNoCase User-Agent "^NextGenSearchBot" bad_bot -SetEnvIfNoCase User-Agent "^NG" bad_bot -SetEnvIfNoCase User-Agent "^NICErsPRO" bad_bot -SetEnvIfNoCase User-Agent "^niki-bot" bad_bot -SetEnvIfNoCase User-Agent "^NimbleCrawler" bad_bot -SetEnvIfNoCase User-Agent "^Ninja" bad_bot -SetEnvIfNoCase User-Agent "^NPbot" bad_bot -SetEnvIfNoCase User-Agent "^Octopus" bad_bot -SetEnvIfNoCase User-Agent "^Offline\ Explorer" bad_bot -SetEnvIfNoCase User-Agent "^Offline\ Navigator" bad_bot -SetEnvIfNoCase User-Agent "^Openfind" bad_bot -SetEnvIfNoCase User-Agent "^OutfoxBot" bad_bot -SetEnvIfNoCase User-Agent "^PageGrabber" bad_bot -SetEnvIfNoCase User-Agent "^Papa\ Foto" bad_bot -SetEnvIfNoCase User-Agent "^pavuk" bad_bot -SetEnvIfNoCase User-Agent "^pcBrowser" bad_bot -SetEnvIfNoCase User-Agent "^PHP\ version\ tracker" bad_bot -SetEnvIfNoCase User-Agent "^Pockey" bad_bot -SetEnvIfNoCase User-Agent "^ProPowerBot/2.14" bad_bot -SetEnvIfNoCase User-Agent "^ProWebWalker" bad_bot -SetEnvIfNoCase User-Agent "^psbot" bad_bot -SetEnvIfNoCase User-Agent "^Pump" bad_bot -SetEnvIfNoCase User-Agent "^QueryN.Metasearch" bad_bot -SetEnvIfNoCase User-Agent "^RealDownload" bad_bot -SetEnvIfNoCase User-Agent "Reaper" bad_bot -SetEnvIfNoCase User-Agent "Recorder" bad_bot -SetEnvIfNoCase User-Agent "^ReGet" bad_bot -SetEnvIfNoCase User-Agent "^RepoMonkey" bad_bot -SetEnvIfNoCase User-Agent "^RMA" bad_bot -SetEnvIfNoCase User-Agent "Siphon" bad_bot -SetEnvIfNoCase User-Agent "^SiteSnagger" bad_bot -SetEnvIfNoCase User-Agent "^SlySearch" bad_bot -SetEnvIfNoCase User-Agent "^SmartDownload" bad_bot -SetEnvIfNoCase User-Agent "^Snake" bad_bot -SetEnvIfNoCase User-Agent "^Snapbot" bad_bot -SetEnvIfNoCase User-Agent "^Snoopy" bad_bot -SetEnvIfNoCase User-Agent "^sogou" bad_bot -SetEnvIfNoCase User-Agent "^SpaceBison" bad_bot -SetEnvIfNoCase User-Agent "^SpankBot" bad_bot -SetEnvIfNoCase User-Agent "^spanner" bad_bot -SetEnvIfNoCase User-Agent "^Sqworm" bad_bot -SetEnvIfNoCase User-Agent "Stripper" bad_bot -SetEnvIfNoCase User-Agent "Sucker" bad_bot -SetEnvIfNoCase User-Agent "^SuperBot" bad_bot -SetEnvIfNoCase User-Agent "^SuperHTTP" bad_bot -SetEnvIfNoCase User-Agent "^Surfbot" bad_bot -SetEnvIfNoCase User-Agent "^suzuran" bad_bot -SetEnvIfNoCase User-Agent "^Szukacz/1.4" bad_bot -SetEnvIfNoCase User-Agent "^tAkeOut" bad_bot -SetEnvIfNoCase User-Agent "^Teleport" bad_bot -SetEnvIfNoCase User-Agent "^Telesoft" bad_bot -SetEnvIfNoCase User-Agent "^TurnitinBot/1.5" bad_bot -SetEnvIfNoCase User-Agent "^The.Intraformant" bad_bot -SetEnvIfNoCase User-Agent "^TheNomad" bad_bot -SetEnvIfNoCase User-Agent "^TightTwatBot" bad_bot -SetEnvIfNoCase User-Agent "^Titan" bad_bot -SetEnvIfNoCase User-Agent "^True_Robot" bad_bot -SetEnvIfNoCase User-Agent "^turingos" bad_bot -SetEnvIfNoCase User-Agent "^TurnitinBot" bad_bot -SetEnvIfNoCase User-Agent "^URLy.Warning" bad_bot -SetEnvIfNoCase User-Agent "^Vacuum" bad_bot -SetEnvIfNoCase User-Agent "^VCI" bad_bot -SetEnvIfNoCase User-Agent "^VoidEYE" bad_bot -SetEnvIfNoCase User-Agent "^Web\ Image\ Collector" bad_bot -SetEnvIfNoCase User-Agent "^Web\ Sucker" bad_bot -SetEnvIfNoCase User-Agent "^WebAuto" bad_bot -SetEnvIfNoCase User-Agent "^WebBandit" bad_bot -SetEnvIfNoCase User-Agent "^Webclipping.com" bad_bot -SetEnvIfNoCase User-Agent "^WebCopier" bad_bot -SetEnvIfNoCase User-Agent "^WebEMailExtrac.*" bad_bot -SetEnvIfNoCase User-Agent "^WebEnhancer" bad_bot -SetEnvIfNoCase User-Agent "^WebFetch" bad_bot -SetEnvIfNoCase User-Agent "^WebGo\ IS" bad_bot -SetEnvIfNoCase User-Agent "^Web.Image.Collector" bad_bot -SetEnvIfNoCase User-Agent "^WebLeacher" bad_bot -SetEnvIfNoCase User-Agent "^WebmasterWorldForumBot" bad_bot -SetEnvIfNoCase User-Agent "^WebReaper" bad_bot -SetEnvIfNoCase User-Agent "^WebSauger" bad_bot -SetEnvIfNoCase User-Agent "^Website\ eXtractor" bad_bot -SetEnvIfNoCase User-Agent "^Website\ Quester" bad_bot -SetEnvIfNoCase User-Agent "^Webster" bad_bot -SetEnvIfNoCase User-Agent "^WebStripper" bad_bot -SetEnvIfNoCase User-Agent "^WebWhacker" bad_bot -SetEnvIfNoCase User-Agent "^WebZIP" bad_bot -SetEnvIfNoCase User-Agent "Whacker" bad_bot -SetEnvIfNoCase User-Agent "^Widow" bad_bot -SetEnvIfNoCase User-Agent "^WISENutbot" bad_bot -SetEnvIfNoCase User-Agent "^WWWOFFLE" bad_bot -SetEnvIfNoCase User-Agent "^WWW-Collector-E" bad_bot -SetEnvIfNoCase User-Agent "^Xaldon" bad_bot -SetEnvIfNoCase User-Agent "^Xenu" bad_bot -SetEnvIfNoCase User-Agent "^Zeus" bad_bot -SetEnvIfNoCase User-Agent "ZmEu" bad_bot -SetEnvIfNoCase User-Agent "^Zyborg" bad_bot - - - - Require all granted - - Require not env bad_bot - - - diff --git a/system/BASE_SOFT/APACHE/2.4/conf.d/security.conf b/system/BASE_SOFT/APACHE/2.4/conf.d/security.conf deleted file mode 100644 index 4bd808c..0000000 --- a/system/BASE_SOFT/APACHE/2.4/conf.d/security.conf +++ /dev/null @@ -1,15 +0,0 @@ -## Block access to SCM directories. - - Require all denied - # Don't add here, extensions like .sql .bak .ini .log ... Instead use apache_block['dot'] - - -## Block access to backup and source files - - Require all denied - # Don't add here, scm like .git .svn .bzr ... Instead use apache_block['scm'] - - - - RequestHeader unset Proxy - diff --git a/system/BASE_SOFT/APACHE/2.4/envvars b/system/BASE_SOFT/APACHE/2.4/envvars deleted file mode 100644 index 91328ac..0000000 --- a/system/BASE_SOFT/APACHE/2.4/envvars +++ /dev/null @@ -1,47 +0,0 @@ -# envvars - default environment variables for apache2ctl - -# this won't be correct after changing uid -unset HOME - -# for supporting multiple apache2 instances -if [ "${APACHE_CONFDIR##/etc/apache2-}" != "${APACHE_CONFDIR}" ] ; then - SUFFIX="-${APACHE_CONFDIR##/etc/apache2-}" -else - SUFFIX= -fi - -# Since there is no sane way to get the parsed apache2 config in scripts, some -# settings are defined via environment variables and then used in apache2ctl, -# /etc/init.d/apache2, /etc/logrotate.d/apache2, etc. -export APACHE_RUN_USER=www-data -export APACHE_RUN_GROUP=www-data -# temporary state file location. This might be changed to /run in Wheezy+1 -export APACHE_PID_FILE=/var/run/apache2/apache2$SUFFIX.pid -export APACHE_RUN_DIR=/var/run/apache2$SUFFIX -export APACHE_LOCK_DIR=/var/lock/apache2$SUFFIX -# Only /var/log/apache2 is handled by /etc/logrotate.d/apache2. -export APACHE_LOG_DIR=/var/log/apache2$SUFFIX - -## The locale used by some modules like mod_dav -export LANG=C -## Uncomment the following line to use the system default locale instead: -#. /etc/default/locale - -export LANG - -## The command to get the status for 'apache2ctl status'. -## Some packages providing 'www-browser' need '--dump' instead of '-dump'. -#export APACHE_LYNX='www-browser -dump' - -## If you need a higher file descriptor limit, uncomment and adjust the -## following line (default is 8192): -#APACHE_ULIMIT_MAX_FILES='ulimit -n 65536' - -## If you would like to pass arguments to the web server, add them below -## to the APACHE_ARGUMENTS environment. -#export APACHE_ARGUMENTS='' - -## Enable the debug mode for maintainer scripts. -## This will produce a verbose output on package installations of web server modules and web application -## installations which interact with Apache -#export APACHE2_MAINTSCRIPT_DEBUG=1 diff --git a/system/BASE_SOFT/APACHE/2.4/magic b/system/BASE_SOFT/APACHE/2.4/magic deleted file mode 100644 index cdf9ac5..0000000 --- a/system/BASE_SOFT/APACHE/2.4/magic +++ /dev/null @@ -1,935 +0,0 @@ -# Magic data for mod_mime_magic (originally for file(1) command) -# -# The format is 4-5 columns: -# Column #1: byte number to begin checking from, ">" indicates continuation -# Column #2: type of data to match -# Column #3: contents of data to match -# Column #4: MIME type of result -# Column #5: MIME encoding of result (optional) - -#------------------------------------------------------------------------------ -# Localstuff: file(1) magic for locally observed files -# Add any locally observed files here. - -# Real Audio (Magic .ra\0375) -0 belong 0x2e7261fd audio/x-pn-realaudio -0 string .RMF application/vnd.rn-realmedia - -#video/x-pn-realvideo -#video/vnd.rn-realvideo -#application/vnd.rn-realmedia -# sigh, there are many mimes for that but the above are the most common. - -# Taken from magic, converted to magic.mime -# mime types according to http://www.geocities.com/nevilo/mod.htm: -# audio/it .it -# audio/x-zipped-it .itz -# audio/xm fasttracker modules -# audio/x-s3m screamtracker modules -# audio/s3m screamtracker modules -# audio/x-zipped-mod mdz -# audio/mod mod -# audio/x-mod All modules (mod, s3m, 669, mtm, med, xm, it, mdz, stm, itz, xmz, s3z) - -# Taken from loader code from mikmod version 2.14 -# by Steve McIntyre (stevem@chiark.greenend.org.uk) -# added title printing on 2003-06-24 -0 string MAS_UTrack_V00 ->14 string >/0 audio/x-mod -#audio/x-tracker-module - -#0 string UN05 MikMod UNI format module sound data - -0 string Extended\ Module: audio/x-mod -#audio/x-tracker-module -##>17 string >\0 Title: "%s" - -21 string/c \!SCREAM! audio/x-mod -#audio/x-screamtracker-module -21 string BMOD2STM audio/x-mod -#audio/x-screamtracker-module -1080 string M.K. audio/x-mod -#audio/x-protracker-module -#>0 string >\0 Title: "%s" -1080 string M!K! audio/x-mod -#audio/x-protracker-module -#>0 string >\0 Title: "%s" -1080 string FLT4 audio/x-mod -#audio/x-startracker-module -#>0 string >\0 Title: "%s" -1080 string FLT8 audio/x-mod -#audio/x-startracker-module -#>0 string >\0 Title: "%s" -1080 string 4CHN audio/x-mod -#audio/x-fasttracker-module -#>0 string >\0 Title: "%s" -1080 string 6CHN audio/x-mod -#audio/x-fasttracker-module -#>0 string >\0 Title: "%s" -1080 string 8CHN audio/x-mod -#audio/x-fasttracker-module -#>0 string >\0 Title: "%s" -1080 string CD81 audio/x-mod -#audio/x-oktalyzer-tracker-module -#>0 string >\0 Title: "%s" -1080 string OKTA audio/x-mod -#audio/x-oktalyzer-tracker-module -#>0 string >\0 Title: "%s" -# Not good enough. -#1082 string CH -#>1080 string >/0 %.2s-channel Fasttracker "oktalyzer" module sound data -1080 string 16CN audio/x-mod -#audio/x-taketracker-module -#>0 string >\0 Title: "%s" -1080 string 32CN audio/x-mod -#audio/x-taketracker-module -#>0 string >\0 Title: "%s" - -# Impuse tracker module (it) -0 string IMPM audio/x-mod -#>4 string >\0 "%s" -#>40 leshort !0 compatible w/ITv%x -#>42 leshort !0 created w/ITv%x - -#------------------------------------------------------------------------------ -# end local stuff -#------------------------------------------------------------------------------ - -# xml based formats! - -# svg - -0 string \38 string \<\!DOCTYPE\040svg image/svg+xml - - -# xml -0 string \2 short 0xbabe application/java - -#------------------------------------------------------------------------------ -# audio: file(1) magic for sound formats -# -# from Jan Nicolai Langfeldt , -# - -# Sun/NeXT audio data -0 string .snd ->12 belong 1 audio/basic ->12 belong 2 audio/basic ->12 belong 3 audio/basic ->12 belong 4 audio/basic ->12 belong 5 audio/basic ->12 belong 6 audio/basic ->12 belong 7 audio/basic - ->12 belong 23 audio/x-adpcm - -# DEC systems (e.g. DECstation 5000) use a variant of the Sun/NeXT format -# that uses little-endian encoding and has a different magic number -# (0x0064732E in little-endian encoding). -0 lelong 0x0064732E ->12 lelong 1 audio/x-dec-basic ->12 lelong 2 audio/x-dec-basic ->12 lelong 3 audio/x-dec-basic ->12 lelong 4 audio/x-dec-basic ->12 lelong 5 audio/x-dec-basic ->12 lelong 6 audio/x-dec-basic ->12 lelong 7 audio/x-dec-basic -# compressed (G.721 ADPCM) ->12 lelong 23 audio/x-dec-adpcm - -# Bytes 0-3 of AIFF, AIFF-C, & 8SVX audio files are "FORM" -# AIFF audio data -8 string AIFF audio/x-aiff -# AIFF-C audio data -8 string AIFC audio/x-aiff -# IFF/8SVX audio data -8 string 8SVX audio/x-aiff - - - -# Creative Labs AUDIO stuff -# Standard MIDI data -0 string MThd audio/unknown -#>9 byte >0 (format %d) -#>11 byte >1 using %d channels -# Creative Music (CMF) data -0 string CTMF audio/unknown -# SoundBlaster instrument data -0 string SBI audio/unknown -# Creative Labs voice data -0 string Creative\ Voice\ File audio/unknown -## is this next line right? it came this way... -#>19 byte 0x1A -#>23 byte >0 - version %d -#>22 byte >0 \b.%d - -# [GRR 950115: is this also Creative Labs? Guessing that first line -# should be string instead of unknown-endian long...] -#0 long 0x4e54524b MultiTrack sound data -#0 string NTRK MultiTrack sound data -#>4 long x - version %ld - -# Microsoft WAVE format (*.wav) -# [GRR 950115: probably all of the shorts and longs should be leshort/lelong] -# Microsoft RIFF -0 string RIFF -# - WAVE format ->8 string WAVE audio/x-wav ->8 string/B AVI video/x-msvideo -# ->8 string CDRA image/x-coreldraw - -# AAC (aka MPEG-2 NBC) -0 beshort&0xfff6 0xfff0 audio/X-HX-AAC-ADTS -0 string ADIF audio/X-HX-AAC-ADIF -0 beshort&0xffe0 0x56e0 audio/MP4A-LATM -0 beshort 0x4De1 audio/MP4A-LATM - -# MPEG Layer 3 sound files -0 beshort&0xfffe =0xfffa audio/mpeg -#MP3 with ID3 tag -0 string ID3 audio/mpeg -# Ogg/Vorbis -0 string OggS application/ogg - -#------------------------------------------------------------------------------ -# c-lang: file(1) magic for C programs or various scripts -# - -# XPM icons (Greg Roelofs, newt@uchicago.edu) -# ideally should go into "images", but entries below would tag XPM as C source -0 string /*\ XPM image/x-xpmi 7bit - -# 3DS (3d Studio files) -#16 beshort 0x3d3d image/x-3ds - -# this first will upset you if you're a PL/1 shop... (are there any left?) -# in which case rm it; ascmagic will catch real C programs -# C or REXX program text -#0 string /* text/x-c -# C++ program text -#0 string // text/x-c++ - -#------------------------------------------------------------------------------ -# commands: file(1) magic for various shells and interpreters -# -#0 string :\ shell archive or commands for antique kernel text -0 string #!/bin/sh application/x-shellscript -0 string #!\ /bin/sh application/x-shellscript -0 string #!/bin/csh application/x-shellscript -0 string #!\ /bin/csh application/x-shellscript -# korn shell magic, sent by George Wu, gwu@clyde.att.com -0 string #!/bin/ksh application/x-shellscript -0 string #!\ /bin/ksh application/x-shellscript -0 string #!/bin/tcsh application/x-shellscript -0 string #!\ /bin/tcsh application/x-shellscript -0 string #!/usr/local/tcsh application/x-shellscript -0 string #!\ /usr/local/tcsh application/x-shellscript -0 string #!/usr/local/bin/tcsh application/x-shellscript -0 string #!\ /usr/local/bin/tcsh application/x-shellscript -# bash shell magic, from Peter Tobias (tobias@server.et-inf.fho-emden.de) -0 string #!/bin/bash application/x-shellscript -0 string #!\ /bin/bash application/x-shellscript -0 string #!/usr/local/bin/bash application/x-shellscript -0 string #!\ /usr/local/bin/bash application/x-shellscript - -# -# zsh/ash/ae/nawk/gawk magic from cameron@cs.unsw.oz.au (Cameron Simpson) -0 string #!/bin/zsh application/x-shellscript -0 string #!/usr/bin/zsh application/x-shellscript -0 string #!/usr/local/bin/zsh application/x-shellscript -0 string #!\ /usr/local/bin/zsh application/x-shellscript -0 string #!/usr/local/bin/ash application/x-shellscript -0 string #!\ /usr/local/bin/ash application/x-shellscript -#0 string #!/usr/local/bin/ae Neil Brown's ae -#0 string #!\ /usr/local/bin/ae Neil Brown's ae -0 string #!/bin/nawk application/x-nawk -0 string #!\ /bin/nawk application/x-nawk -0 string #!/usr/bin/nawk application/x-nawk -0 string #!\ /usr/bin/nawk application/x-nawk -0 string #!/usr/local/bin/nawk application/x-nawk -0 string #!\ /usr/local/bin/nawk application/x-nawk -0 string #!/bin/gawk application/x-gawk -0 string #!\ /bin/gawk application/x-gawk -0 string #!/usr/bin/gawk application/x-gawk -0 string #!\ /usr/bin/gawk application/x-gawk -0 string #!/usr/local/bin/gawk application/x-gawk -0 string #!\ /usr/local/bin/gawk application/x-gawk -# -0 string #!/bin/awk application/x-awk -0 string #!\ /bin/awk application/x-awk -0 string #!/usr/bin/awk application/x-awk -0 string #!\ /usr/bin/awk application/x-awk -# update to distinguish from *.vcf files by Joerg Jenderek: joerg dot jenderek at web dot de -#0 regex BEGIN[[:space:]]*[{] application/x-awk - -# For Larry Wall's perl language. The ``eval'' line recognizes an -# outrageously clever hack for USG systems. -# Keith Waclena -0 string #!/bin/perl application/x-perl -0 string #!\ /bin/perl application/x-perl -0 string eval\ "exec\ /bin/perl application/x-perl -0 string #!/usr/bin/perl application/x-perl -0 string #!\ /usr/bin/perl application/x-perl -0 string eval\ "exec\ /usr/bin/perl application/x-perl -0 string #!/usr/local/bin/perl application/x-perl -0 string #!\ /usr/local/bin/perl application/x-perl -0 string eval\ "exec\ /usr/local/bin/perl application/x-perl - -#------------------------------------------------------------------------------ -# compress: file(1) magic for pure-compression formats (no archives) -# -# compress, gzip, pack, compact, huf, squeeze, crunch, freeze, yabba, whap, etc. -# -# Formats for various forms of compressed data -# Formats for "compress" proper have been moved into "compress.c", -# because it tries to uncompress it to figure out what's inside. - -# standard unix compress -#0 string \037\235 application/x-compress - -# gzip (GNU zip, not to be confused with [Info-ZIP/PKWARE] zip archiver) -#0 string \037\213 application/x-gzip - -0 string PK\003\004 application/x-zip - -# RAR archiver (Greg Roelofs, newt@uchicago.edu) -0 string Rar! application/x-rar - -# According to gzip.h, this is the correct byte order for packed data. -0 string \037\036 application/octet-stream -# -# This magic number is byte-order-independent. -# -0 short 017437 application/octet-stream - -# XXX - why *two* entries for "compacted data", one of which is -# byte-order independent, and one of which is byte-order dependent? -# -# compacted data -0 short 0x1fff application/octet-stream -0 string \377\037 application/octet-stream -# huf output -0 short 0145405 application/octet-stream - -# Squeeze and Crunch... -# These numbers were gleaned from the Unix versions of the programs to -# handle these formats. Note that I can only uncrunch, not crunch, and -# I didn't have a crunched file handy, so the crunch number is untested. -# Keith Waclena -#0 leshort 0x76FF squeezed data (CP/M, DOS) -#0 leshort 0x76FE crunched data (CP/M, DOS) - -# Freeze -#0 string \037\237 Frozen file 2.1 -#0 string \037\236 Frozen file 1.0 (or gzip 0.5) - -# lzh? -#0 string \037\240 LZH compressed data - -257 string ustar\0 application/x-tar posix -257 string ustar\040\040\0 application/x-tar gnu - -0 short 070707 application/x-cpio -0 short 0143561 application/x-cpio swapped - -0 string = application/x-archive -0 string \! application/x-archive ->8 string debian application/x-debian-package - -#------------------------------------------------------------------------------ -# -# RPM: file(1) magic for Red Hat Packages Erik Troan (ewt@redhat.com) -# -0 beshort 0xedab ->2 beshort 0xeedb application/x-rpm - -0 lelong&0x8080ffff 0x0000081a application/x-arc lzw -0 lelong&0x8080ffff 0x0000091a application/x-arc squashed -0 lelong&0x8080ffff 0x0000021a application/x-arc uncompressed -0 lelong&0x8080ffff 0x0000031a application/x-arc packed -0 lelong&0x8080ffff 0x0000041a application/x-arc squeezed -0 lelong&0x8080ffff 0x0000061a application/x-arc crunched - -0 leshort 0xea60 application/x-arj - -# LHARC/LHA archiver (Greg Roelofs, newt@uchicago.edu) -2 string -lh0- application/x-lharc lh0 -2 string -lh1- application/x-lharc lh1 -2 string -lz4- application/x-lharc lz4 -2 string -lz5- application/x-lharc lz5 -# [never seen any but the last; -lh4- reported in comp.compression:] -2 string -lzs- application/x-lha lzs -2 string -lh\ - application/x-lha lh -2 string -lhd- application/x-lha lhd -2 string -lh2- application/x-lha lh2 -2 string -lh3- application/x-lha lh3 -2 string -lh4- application/x-lha lh4 -2 string -lh5- application/x-lha lh5 -2 string -lh6- application/x-lha lh6 -2 string -lh7- application/x-lha lh7 -# Shell archives -10 string #\ This\ is\ a\ shell\ archive application/octet-stream x-shell - -#------------------------------------------------------------------------------ -# frame: file(1) magic for FrameMaker files -# -# This stuff came on a FrameMaker demo tape, most of which is -# copyright, but this file is "published" as witness the following: -# -0 string \ -# -0 string/cB \14 byte 12 (OS/2 1.x format) -#>14 byte 64 (OS/2 2.x format) -#>14 byte 40 (Windows 3.x format) -#0 string IC icon -#0 string PI pointer -#0 string CI color icon -#0 string CP color pointer -#0 string BA bitmap array - -# CDROM Filesystems -32769 string CD001 application/x-iso9660 - -# Newer StuffIt archives (grant@netbsd.org) -0 string StuffIt application/x-stuffit -#>162 string >0 : %s - -# BinHex is the Macintosh ASCII-encoded file format (see also "apple") -# Daniel Quinlan, quinlan@yggdrasil.com -11 string must\ be\ converted\ with\ BinHex\ 4 application/mac-binhex40 -##>41 string x \b, version %.3s - - -#------------------------------------------------------------------------------ -# lisp: file(1) magic for lisp programs -# -# various lisp types, from Daniel Quinlan (quinlan@yggdrasil.com) -0 string ;; text/plain 8bit -# Emacs 18 - this is always correct, but not very magical. -0 string \012( application/x-elc -# Emacs 19 -0 string ;ELC\023\000\000\000 application/x-elc - -#------------------------------------------------------------------------------ -# mail.news: file(1) magic for mail and news -# -# There are tests to ascmagic.c to cope with mail and news. -0 string Relay-Version: message/rfc822 7bit -0 string #!\ rnews message/rfc822 7bit -0 string N#!\ rnews message/rfc822 7bit -0 string Forward\ to message/rfc822 7bit -0 string Pipe\ to message/rfc822 7bit -0 string Return-Path: message/rfc822 7bit -0 string Received: message/rfc822 -0 string Path: message/news 8bit -0 string Xref: message/news 8bit -0 string From: message/rfc822 7bit -0 string Article message/news 8bit -#------------------------------------------------------------------------------ -# msword: file(1) magic for MS Word files -# -# Contributor claims: -# Reversed-engineered MS Word magic numbers -# - -0 string \376\067\0\043 application/msword -0 string \320\317\021\340\241\261 application/msword -0 string \333\245-\0\0\0 application/msword - - - -#------------------------------------------------------------------------------ -# printer: file(1) magic for printer-formatted files -# - -# PostScript -0 string %! application/postscript -0 string \004%! application/postscript - -# Acrobat -# (due to clamen@cs.cmu.edu) -0 string %PDF- application/pdf - -#------------------------------------------------------------------------------ -# sc: file(1) magic for "sc" spreadsheet -# -38 string Spreadsheet application/x-sc - -#------------------------------------------------------------------------------ -# tex: file(1) magic for TeX files -# -# XXX - needs byte-endian stuff (big-endian and little-endian DVI?) -# -# From - -# Although we may know the offset of certain text fields in TeX DVI -# and font files, we can't use them reliably because they are not -# zero terminated. [but we do anyway, christos] -0 string \367\002 application/x-dvi -#0 string \367\203 TeX generic font data -#0 string \367\131 TeX packed font data -#0 string \367\312 TeX virtual font data -#0 string This\ is\ TeX, TeX transcript text -#0 string This\ is\ METAFONT, METAFONT transcript text - -# There is no way to detect TeX Font Metric (*.tfm) files without -# breaking them apart and reading the data. The following patterns -# match most *.tfm files generated by METAFONT or afm2tfm. -2 string \000\021 application/x-tex-tfm -2 string \000\022 application/x-tex-tfm -#>34 string >\0 (%s) - -# Texinfo and GNU Info, from Daniel Quinlan (quinlan@yggdrasil.com) -0 string \\input\ texinfo text/x-texinfo -0 string This\ is\ Info\ file text/x-info - -# correct TeX magic for Linux (and maybe more) -# from Peter Tobias (tobias@server.et-inf.fho-emden.de) -# -0 leshort 0x02f7 application/x-dvi - -# RTF - Rich Text Format -0 string {\\rtf text/rtf - -#------------------------------------------------------------------------------ -# animation: file(1) magic for animation/movie formats -# -# animation formats, originally from vax@ccwf.cc.utexas.edu (VaX#n8) -# MPEG file -# MPEG sequences -0 belong 0x000001BA ->4 byte &0x40 video/mp2p ->4 byte ^0x40 video/mpeg -0 belong 0x000001BB video/mpeg -0 belong 0x000001B0 video/mp4v-es -0 belong 0x000001B5 video/mp4v-es -0 belong 0x000001B3 video/mpv -0 belong&0xFF5FFF1F 0x47400010 video/mp2t -0 belong 0x00000001 ->4 byte&0x1F 0x07 video/h264 - -# FLI animation format -0 leshort 0xAF11 video/fli -# FLC animation format -0 leshort 0xAF12 video/flc -# -# SGI and Apple formats -# Added ISO mimes -0 string MOVI video/sgi -4 string moov video/quicktime -4 string mdat video/quicktime -4 string wide video/quicktime -4 string skip video/quicktime -4 string free video/quicktime -4 string idsc image/x-quicktime -4 string idat image/x-quicktime -4 string pckg application/x-quicktime -4 string/B jP image/jp2 -4 string ftyp ->8 string isom video/mp4 ->8 string mp41 video/mp4 ->8 string mp42 video/mp4 ->8 string/B jp2 image/jp2 ->8 string 3gp video/3gpp ->8 string avc1 video/3gpp ->8 string mmp4 video/mp4 ->8 string/B M4A audio/mp4 ->8 string/B qt video/quicktime -# The contributor claims: -# I couldn't find a real magic number for these, however, this -# -appears- to work. Note that it might catch other files, too, -# so BE CAREFUL! -# -# Note that title and author appear in the two 20-byte chunks -# at decimal offsets 2 and 22, respectively, but they are XOR'ed with -# 255 (hex FF)! DL format SUCKS BIG ROCKS. -# -# DL file version 1 , medium format (160x100, 4 images/screen) -0 byte 1 video/unknown -0 byte 2 video/unknown -# -# Databases -# -# GDBM magic numbers -# Will be maintained as part of the GDBM distribution in the future. -# -0 belong 0x13579ace application/x-gdbm -0 lelong 0x13579ace application/x-gdbm -0 string GDBM application/x-gdbm -# -0 belong 0x061561 application/x-dbm -# -# Executables -# -0 string \177ELF ->16 leshort 0 application/octet-stream ->16 leshort 1 application/x-object ->16 leshort 2 application/x-executable ->16 leshort 3 application/x-sharedlib ->16 leshort 4 application/x-coredump ->16 beshort 0 application/octet-stream ->16 beshort 1 application/x-object ->16 beshort 2 application/x-executable ->16 beshort 3 application/x-sharedlib ->16 beshort 4 application/x-coredump -# -# DOS -0 string MZ application/x-dosexec -# -# KDE -0 string [KDE\ Desktop\ Entry] application/x-kdelnk -0 string \#\ KDE\ Config\ File application/x-kdelnk -# xmcd database file for kscd -0 string \#\ xmcd text/xmcd - -#------------------------------------------------------------------------------ -# pkgadd: file(1) magic for SysV R4 PKG Datastreams -# -0 string #\ PaCkAgE\ DaTaStReAm application/x-svr4-package - -#PNG Image Format -0 string \x89PNG image/png - -# MNG Video Format, -0 string \x8aMNG video/x-mng -0 string \x8aJNG video/x-jng - -#------------------------------------------------------------------------------ -# Hierarchical Data Format, used to facilitate scientific data exchange -# specifications at http://hdf.ncsa.uiuc.edu/ -#Hierarchical Data Format (version 4) data -0 belong 0x0e031301 application/x-hdf -#Hierarchical Data Format (version 5) data -0 string \211HDF\r\n\032 application/x-hdf - -# Adobe Photoshop -0 string 8BPS image/x-photoshop - -# Felix von Leitner -0 string d8:announce application/x-bittorrent - - -# lotus 1-2-3 document -0 belong 0x00001a00 application/x-123 -0 belong 0x00000200 application/x-123 - -# MS Access database -4 string Standard\ Jet\ DB application/msaccess - -## magic for XBase files -#0 byte 0x02 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x03 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x04 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x05 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x30 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x43 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x7b -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x83 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x8b -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0x8e -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0xb3 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 byte 0xf5 -#>8 leshort >0 -#>>12 leshort 0 application/x-dbf -# -#0 leshort 0x0006 application/x-dbt - -# Debian has entries for the old PGP formats: -# pgp: file(1) magic for Pretty Good Privacy -# see http://lists.gnupg.org/pipermail/gnupg-devel/1999-September/016052.html -#text/PGP key public ring -0 beshort 0x9900 application/pgp -#text/PGP key security ring -0 beshort 0x9501 application/pgp -#text/PGP key security ring -0 beshort 0x9500 application/pgp -#text/PGP encrypted data -0 beshort 0xa600 application/pgp-encrypted -#text/PGP armored data -##public key block -2 string ---BEGIN\ PGP\ PUBLIC\ KEY\ BLOCK- application/pgp-keys -0 string -----BEGIN\040PGP\40MESSAGE- application/pgp -0 string -----BEGIN\040PGP\40SIGNATURE- application/pgp-signature -# -# GnuPG Magic: -# -# -#text/GnuPG key public ring -0 beshort 0x9901 application/pgp -#text/OpenPGP data -0 beshort 0x8501 application/pgp-encrypted - -# flash: file(1) magic for Macromedia Flash file format -# -# See -# -# http://www.macromedia.com/software/flash/open/ -# -0 string FWS ->3 byte x application/x-shockwave-flash - -# The following paramaters are created for Namazu. -# -# -# 1999/08/13 -#0 string \ - - - - - - -
    - -
    - - - -"}; diff --git a/system/BASE_SOFT/VARNISH/4.1/conf/includes/error.vcl b/system/BASE_SOFT/VARNISH/4.1/conf/includes/error.vcl deleted file mode 100644 index c0c2536..0000000 --- a/system/BASE_SOFT/VARNISH/4.1/conf/includes/error.vcl +++ /dev/null @@ -1,138 +0,0 @@ -# The vcl_error() procedure -set obj.http.Content-Type = "text/html; charset=utf-8"; -set obj.http.Retry-After = "5"; - -synthetic {" - - - - - "} + obj.status + " " + obj.response + {" - - - - - - - - - - - - -
    - -
    - - We're very sorry, but the page could not be loaded properly. - -
    - -
    This should be fixed very soon, and we apologize for any inconvenience.
    - -
    - -
    -
    -
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Debug Information

    VariableValue
    General
    XID"} + req.xid + {"
    Time"} + now + {"
    Request
    HTTP host"} + req.http.Host + {"
    Request type"} + req.request + {"
    HTTP Protocol version"} + req.proto + {"
    URL"} + req.url + {"
    Cookies"} + regsuball(req.http.cookie, "; ", "
    ") + {"
    Accept-Encoding"} + req.http.Accept-Encoding + {"
    Cache-Control"} + req.http.Cache-Control + {"
    HTTP header"} + req.http.header + {"
    GZIP supported"} + req.can_gzip + {"
    Backend"} + req.backend + {"
    Server
    Identity"} + server.identity + {"
    IP:port"} + server.ip + {":"} + server.port + {"
    Client
    IP"} + client.ip + {"
    -
    -
    -
    -
    -
    - - - - -"}; diff --git a/system/BASE_SOFT/VARNISH/4.1/conf/includes/probes.vcl b/system/BASE_SOFT/VARNISH/4.1/conf/includes/probes.vcl deleted file mode 100644 index d4cf27a..0000000 --- a/system/BASE_SOFT/VARNISH/4.1/conf/includes/probes.vcl +++ /dev/null @@ -1,8 +0,0 @@ -probe default_probe { - .url = "/"; - .expected_response = 200; - .timeout = 15s; - .interval = 15s; - .window = 5; - .threshold = 2; -} diff --git a/system/BASE_SOFT/VARNISH/4.1/conf/includes/wp-protection.vcl b/system/BASE_SOFT/VARNISH/4.1/conf/includes/wp-protection.vcl deleted file mode 100644 index ce03c91..0000000 --- a/system/BASE_SOFT/VARNISH/4.1/conf/includes/wp-protection.vcl +++ /dev/null @@ -1,16 +0,0 @@ - - set req.http.X-Actual-IP = regsub(req.http.X-Forwarded-For, "[, ].*$", ""); - - #Prevent hammering on wp-login page and users doing excessive searches (2 per second) - if(vsthrottle.is_denied(req.http.X-Actual-IP, 10, 20s) && (req.url ~ "xmlrpc|wp-login.php|\?s\=")) { - return (synth(429, "Too Many Request - Calm down")); - # Use shield vmod to reset connection - shield.conn_reset(); - } - - #Prevent users from making excessive POST requests that aren't for admin-ajax - if(vsthrottle.is_denied(req.http.X-Actual-IP, 15, 10s) && ((!req.url ~ "\/wp-admin\/|(xmlrpc|admin-ajax)\.php") && (req.method == "POST"))){ - return (synth(429, "Too Many Requests")); - # Use shield vmod to reset connection - shield.conn_reset(); - } diff --git a/system/BASE_SOFT/VARNISH/4.1/conf/production.vcl b/system/BASE_SOFT/VARNISH/4.1/conf/production.vcl deleted file mode 100644 index cd3f8de..0000000 --- a/system/BASE_SOFT/VARNISH/4.1/conf/production.vcl +++ /dev/null @@ -1,311 +0,0 @@ -vcl 4.0; -import vsthrottle; -import shield; -import std; -import directors; - -### {{{ PROBES, BACKENDS , ACLS , DIRECTORS -## Probes -include "includes/probes.vcl"; - -## Backends -include "includes/backends.vcl"; - -## ACLs -include "includes/acls.vcl"; - -## Directors -include "includes/directors.vcl"; - -### }}} PROBES, BACKENDS , ACLS , DIRECTORS - -### {{{ RECV -sub vcl_recv { - - include "includes/wp-protection.vcl"; - - if (req.restarts == 0) { - if (req.http.X-Forwarded-For) { - set req.http.X-Forwarded-For = req.http.X-Forwarded-For + ", " + client.ip; - } else { - set req.http.X-Forwarded-For = client.ip; - } - } - - # Normalisation des headers, suppression du port (si on utilise plusieurs ports TCP) - set req.http.Host = regsub(req.http.Host, ":[0-9]+", ""); - - # Normalisation des arguments - # Mis en commentaire : probleme sur les cms wp, drupal etc - # http://stackoverflow.com/questions/29929164/issue-with-wordpress-and-varnish-breaking-loadscript-php - # set req.url = std.querysort(req.url); - - - # Bye Bye w00tw00t - if (req.url ~ "^/w00tw00t") { - return (synth(404, "Not Found")); - } - - # Authorisation pour les purge - if (req.method == "PURGE") { - if (!client.ip ~ purge) { - # Non autorisé ! On lui fourni l'erreur 405 avec le message qui va bien, - return (synth(405, "This IP is not allowed to send PURGE requests.")); - } - # Autorisé on purge le cache demandé - return (purge); - } - - # Ne traiter que les type normaux, tout le reste est à passer directement aux backends - if (req.method != "GET" && - req.method != "HEAD" && - req.method != "PUT" && - req.method != "POST" && - req.method != "TRACE" && - req.method != "OPTIONS" && - req.method != "PATCH" && - req.method != "DELETE") { - return (pipe); - } - - # Ne mettre en cache que les requetes de type GET ou HEAD. Ceci permet de s'assurer que les requetes POST sont transmises directement aux backends - if (req.method != "GET" && req.method != "HEAD") { - return (pass); - } - - # Support de websocket , plus d'infos => https://www.varnish-cache.org/docs/4.0/users-guide/vcl-example-websockets.html - if (req.http.Upgrade ~ "(?i)websocket") { - return (pipe); - } - - # Suppression des parametres ajouté par Google Analytics, inutile pour les backends - if (req.url ~ "(\?|&)(utm_source|utm_medium|utm_campaign|gclid|cx|ie|cof|siteurl)=") { - set req.url = regsuball(req.url, "&(utm_source|utm_medium|utm_campaign|gclid|cx|ie|cof|siteurl)=([A-z0-9_\-\.%25]+)", ""); - set req.url = regsuball(req.url, "\?(utm_source|utm_medium|utm_campaign|gclid|cx|ie|cof|siteurl)=([A-z0-9_\-\.%25]+)", "?"); - set req.url = regsub(req.url, "\?&", "?"); - set req.url = regsub(req.url, "\?$", ""); - } - - # Suppression des # envoyés pour le backend. - if (req.url ~ "\#") { - set req.url = regsub(req.url, "\#.*$", ""); - } - - # Suppression des / à la fin des Urls pour eviter le duplicate content - if (req.url ~ "\?$") { - set req.url = regsub(req.url, "\?$", ""); - } - - # Suppression de "has_js" cookie si present - set req.http.Cookie = regsuball(req.http.Cookie, "has_js=[^;]+(; )?", ""); - - # Suppression de tous les cookies basés sur Google Analytics - set req.http.Cookie = regsuball(req.http.Cookie, "__utm.=[^;]+(; )?", ""); - set req.http.Cookie = regsuball(req.http.Cookie, "_ga=[^;]+(; )?", ""); - set req.http.Cookie = regsuball(req.http.Cookie, "utmctr=[^;]+(; )?", ""); - set req.http.Cookie = regsuball(req.http.Cookie, "utmcmd.=[^;]+(; )?", ""); - set req.http.Cookie = regsuball(req.http.Cookie, "utmccn.=[^;]+(; )?", ""); - - # Remove DoubleClick offensive cookies - set req.http.Cookie = regsuball(req.http.Cookie, "__gads=[^;]+(; )?", ""); - - # Suppression des cookies de Quant Capital (ajoutés par certains plugin, all __qca) - set req.http.Cookie = regsuball(req.http.Cookie, "__qc.=[^;]+(; )?", ""); - - # Suppression des cookies AddThis - set req.http.Cookie = regsuball(req.http.Cookie, "__atuvc=[^;]+(; )?", ""); - - # Suppression du prefix ";" du cookies si present - set req.http.Cookie = regsuball(req.http.Cookie, "^;\s*", ""); - - # Cookies vides ou seulement avec des espaces ? - if (req.http.cookie ~ "^\s*$") { - unset req.http.cookie; - } - - # Normalisation Accept-Encoding header - # Cf manuel => https://www.varnish-cache.org/docs/3.0/tutorial/vary.html - if (req.http.Accept-Encoding) { - if (req.url ~ "\.(jpg|png|gif|gz|tgz|bz2|tbz|mp3|ogg)$") { - unset req.http.Accept-Encoding; - } elsif (req.http.Accept-Encoding ~ "gzip") { - set req.http.Accept-Encoding = "gzip"; - } elsif (req.http.Accept-Encoding ~ "deflate") { - set req.http.Accept-Encoding = "deflate"; - } else { - # algorithm non connu - unset req.http.Accept-Encoding; - } - } - - # On passe les gros fichiers directements aux backends pour eviter les resets de connexions | CF vcl_backend_response - if (req.url ~ "^[^?]*\.(mp[34]|rar|tar|tgz|gz|wav|zip)(\?.*)?$") { - unset req.http.Cookie; - return (hash); - } - - # Suppression des cookies sur les fichiers static - if (req.url ~ "^[^?]*\.(bmp|bz2|css|doc|eot|flv|gif|gz|ico|jpeg|jpg|js|less|pdf|png|rtf|swf|txt|woff|xml)(\?.*)?$") { - unset req.http.Cookie; - return (hash); - } - - # Envoie de Surrogate-Capability headers pour le support des ESI au niveau des backend - set req.http.Surrogate-Capability = "key=ESI/1.0"; - - if (req.http.Authorization) { - # Ne pas mettre en cache par defaut - return (pass); - } - - return (hash); -} -### }}} RECV - - ### {{{ PIPE :: PASS -sub vcl_pipe { - # On renvoie toujours le X-Forwarded-For , pas uniquement sur la première requete envoyé aux backends - set bereq.http.Connection = "Close"; - - # Support de websocket , plus d'infos => https://www.varnish-cache.org/docs/4.0/users-guide/vcl-example-websockets.html - if (req.http.upgrade) { - set bereq.http.upgrade = req.http.upgrade; - } - return (pipe); -} - -sub vcl_pass { -# return (pass); -} - -### }}} PIPE :: PASS - -### {{{ HASH :: HIT :: MISS -sub vcl_hash { - hash_data(req.url); - - if (req.http.host) { - hash_data(req.http.host); - } else { - hash_data(server.ip); - } - - if (req.http.Cookie) { - hash_data(req.http.Cookie); - } -} - -sub vcl_hit { - if (obj.ttl >= 0s) { - return (deliver); - } - - if (std.healthy(req.backend_hint)) { - if (obj.ttl + 10s > 0s) { - return (deliver); - } else { - return(fetch); - } - } else { - if (obj.ttl + obj.grace > 0s) { - return (deliver); - } else { - return (fetch); - } - } - return (fetch); -} - -sub vcl_miss { - return (fetch); -} -### }}} HASH :: HIT :: MISS - -### {{{ BACKEND RESPONSE -sub vcl_backend_response { - # Parse des requetes ESI et suppression des headers Surrogate-Control - if (beresp.http.Surrogate-Control ~ "ESI/1.0") { - unset beresp.http.Surrogate-Control; - set beresp.do_esi = true; - } - - if (bereq.url ~ "^[^?]*\.(bmp|bz2|css|doc|eot|flv|gif|gz|ico|jpeg|jpg|js|less|mp[34]|pdf|png|rar|rtf|swf|tar|tgz|txt|wav|woff|xml|zip)(\?.*)?$") { - unset beresp.http.set-cookie; - } - - if (bereq.url ~ "^[^?]*\.(mp[34]|rar|tar|tgz|gz|wav|zip|bz2|xz|7z|avi|mov|ogm|mpe?g|mk[av])(\?.*)?$") { - unset beresp.http.set-cookie; - set beresp.do_stream = true; - set beresp.do_gzip = false; - } - - # On s'assure que s'il y a des 301 ou des 302 , les port TCP sont remis en place. - if (beresp.status == 301 || beresp.status == 302) { - set beresp.http.Location = regsub(beresp.http.Location, ":[0-9]+", ""); - } - - # On affiche le contenu en cache (Périmé) si les backends sont downs - set beresp.grace = 6h; - - return (deliver); -} - -### }}} BACKEND RESPONSE - -### {{{ DELIVER -sub vcl_deliver { - if (obj.hits > 0) { - set resp.http.X-Cache = "HIT"; - } else { - set resp.http.X-Cache = "MISS"; - } - - #if (resp.http.X-marker == "pass" ) { - # remove resp.http.X-marker; - # set resp.http.X-Varnish-Cache = "PASS"; - #} - set resp.http.X-Cache-Hits = obj.hits; - - if (client.ip ~ debug) { - set resp.http.X-Served-By = server.hostname; - set resp.http.X-Varnish-Ip = server.ip; - set resp.http.X-Varnish-Port = std.port(server.ip); - } else { - # Suppression des headers: PHP version, Apache , OS ... - unset resp.http.X-Powered-By; - unset resp.http.Server; - unset resp.http.X-Varnish; - unset resp.http.Via; - unset resp.http.Link; - } - - return (deliver); -} -### }}} DELIVER - -### {{{ SYNTH -sub vcl_synth { - if (resp.status == 720) { - set resp.http.Location = resp.reason; - set resp.status = 301; - set resp.reason = "Moved Permanently"; - } elseif (resp.status == 721) { - set resp.http.Location = resp.reason; - set resp.status = 302; - set resp.reason = "Moved Temporary"; - } - - return (deliver); -} -### }}} SYNTH - -### {{{ INIT -sub vcl_init { - return (ok); -} - -sub vcl_fini { - return (ok); -} - - ### }}} INIT :: FINI \ No newline at end of file diff --git a/system/BASE_SOFT/VARNISH/4.1/varnish b/system/BASE_SOFT/VARNISH/4.1/varnish deleted file mode 100644 index 88bd46b..0000000 --- a/system/BASE_SOFT/VARNISH/4.1/varnish +++ /dev/null @@ -1,15 +0,0 @@ -START=True -NFILES=131072 -MEMLOCK=82000 - -DAEMON_OPTS="-a 127.0.0.1:81 \ - -f /etc/varnish/production.vcl \ - -T 127.0.0.1:6082 \ - -S /etc/varnish/secret \ - -s default=malloc,1g \ - -p thread_pool_min=200 \ - -p thread_pool_max=4000 \ - -p thread_pool_timeout=300 \ - -p default_grace=300 \ - -p default_ttl=604800 \ - -p ban_lurker_sleep=1" diff --git a/system/BASE_SOFT/VARNISH/5.0/README.md b/system/BASE_SOFT/VARNISH/5.0/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/VARNISH/README.md b/system/BASE_SOFT/VARNISH/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/BASE_SOFT/changes.md b/system/BASE_SOFT/changes.md deleted file mode 100644 index ed8f79a..0000000 --- a/system/BASE_SOFT/changes.md +++ /dev/null @@ -1,15 +0,0 @@ - -# Apache 2.4 -apache2.conf --> ServerName -apache2.conf --> Header set X-Apache-Server-ID -sites-available --> 010-mywebsite.com.conf -010-mywebsite.com.conf --> ServerName -010-mywebsite.com.conf --> ServerAlias -010-mywebsite.com.conf --> DocumentRoot -010-mywebsite.com.conf --> mod_fastcgi -010-mywebsite.com.conf --> Directory -010-mywebsite.com.conf --> Header set X-Vhost-ID -.htpasswd --> ajout user random - -# HaProxy -userlist htaccess \ No newline at end of file diff --git a/system/README.md b/system/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/scripts/README.md b/system/scripts/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/scripts/install_packages.py b/system/scripts/install_packages.py deleted file mode 100755 index 811512d..0000000 --- a/system/scripts/install_packages.py +++ /dev/null @@ -1,69 +0,0 @@ -import ConfigParser -import os - -from fabric.contrib import files -from fabric.api import * -from fabric.utils import warn - -SERVER_ROLES = ['cache'] -env.user = 'root' -env.key_filename = '~/.ssh/id_rsa' - - -env.roledefs = dict.fromkeys(SERVER_ROLES, []) - -# Directory structure -PROJECT_ROOT = os.path.dirname(__file__) -CONF_ROOT = os.path.join(PROJECT_ROOT, 'lamp-debian9') - -def install_packages(*roles): - """ - Install packages for the given roles. - """ - roles = list(roles) - if roles == ['all', ]: - roles = SERVER_ROLES - if 'base' not in roles: - roles.insert(0, 'base') - config_file = os.path.join(CONF_ROOT, u'debian9.ini' % env) - print(config_file) - config = ConfigParser.SafeConfigParser() - config.read(config_file) - for role in roles: - if config.has_section(role): - # Get ppas - if config.has_option(role, 'ppas'): - for ppa in config.get(role, 'ppas').split(' '): - sudo(u'add-apt-repository %s' % ppa) - # Get sources - if config.has_option(role, 'sources'): - for section in config.get(role, 'sources').split(' '): - source = config.get(section, 'source') - key = config.get(section, 'key') - files.append(u'/etc/apt/sources.list', source, use_sudo=True) - sudo(u"wget -q %s -O - | sudo apt-key add -" % key) - sudo(u"apt-get update") - - for package in config.get(role, 'packages'): - if role == "database": - pass - sudo(u"apt-get install -y %s" % package) - - - - -def install_mysql(): - with settings(hide('warnings', 'stderr'), warn_only=True): - result = sudo('dpkg-query --show mysql-server') - if result.failed is False: - warn('MySQL is already installed') - return - mysql_password = prompt('Please enter MySQL root password:') - sudo('echo "mysql-server-5.0 mysql-server/root_password password ' \ - '%s" | debconf-set-selections' % mysql_password) - sudo('echo "mysql-server-5.0 mysql-server/root_password_again password ' \ - '%s" | debconf-set-selections' % mysql_password) - apt_get('mysql-server') - -def host_type(): - run('uname -s') \ No newline at end of file diff --git a/system/scripts/install_packages.pyc b/system/scripts/install_packages.pyc deleted file mode 100644 index d525408..0000000 Binary files a/system/scripts/install_packages.pyc and /dev/null differ diff --git a/system/scripts/lamp-debian9/README.md b/system/scripts/lamp-debian9/README.md deleted file mode 100644 index e69de29..0000000 diff --git a/system/scripts/lamp-debian9/debian9.ini b/system/scripts/lamp-debian9/debian9.ini deleted file mode 100644 index d2c3ebc..0000000 --- a/system/scripts/lamp-debian9/debian9.ini +++ /dev/null @@ -1,15 +0,0 @@ -[base] -packages = sudo inotify-tools vim net-tools htop locate screen curl unzip - -[web] -packages = memcached apache2 php-curl php7.0-curl php-gd php-fpm php-mysql - -[cache] -packages = varnish - -[database] -packages = mariadb-client mariadb-common mariadb-server - -#[rabbitmq-source] -#source = deb http://www.rabbitmq.com/debian/ testing main -#key = http://www.rabbitmq.com/rabbitmq-signing-key-public.asc \ No newline at end of file