838 lines
29 KiB
Bash
838 lines
29 KiB
Bash
siteLabel="[Site]"
|
|
siteWordpressLabel="[Wordpress]"
|
|
|
|
# Creates a new site: validates domain/source/DB, creates OLS vhost, copies files,
|
|
# sets up MariaDB/Redis/Postfix, rolls back via cmdSiteRemove on failure.
|
|
# $1 (domain): site domain name.
|
|
# $2 (sourceFiles): source directory or archive with site files.
|
|
# [$3] (sourceDatabase): optional SQL dump or archive with SQL dump.
|
|
function cmdSiteAdd() {
|
|
local domain sourceFiles
|
|
domain=$(domainPrepare "$1")
|
|
shift || true
|
|
|
|
sourceFiles="${1:-$appAssetsPath/vhost/default}"
|
|
shift || true
|
|
|
|
printSection "Add site"
|
|
printDotText "domain" "$domain"
|
|
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
elif ! run output error siteAdd "$domain" "$sourceFiles" "$@"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "status" "$labelDone"
|
|
|
|
cmdOpenlitespeedRestart
|
|
|
|
fi
|
|
}
|
|
|
|
# Removes a site and all associated MariaDB/Redis/Postfix/OLS/host resources.
|
|
# $1 (domain): site domain name.
|
|
function cmdSiteRemove() {
|
|
local domain mode
|
|
domain=$(domainPrepare "$1")
|
|
shift || true
|
|
|
|
mode="$1"
|
|
shift || true
|
|
|
|
if [[ ! "$mode" == "-f" && ! "$mode" == "--force" ]]; then
|
|
if ! cmdRouterConfirm "Are you sure you want to$fontRed DELETE$fontReset the site $fontBlue$domain$fontReset?"; then
|
|
printRow
|
|
return 0
|
|
fi
|
|
fi
|
|
|
|
printSection "Remove site"
|
|
printDotText "domain" "$domain"
|
|
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
elif ! run output error siteRemove "$domain"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "status" "$labelDone"
|
|
|
|
cmdOpenlitespeedRestart
|
|
fi
|
|
}
|
|
|
|
# Copies a site: exports source DB, creates target site, rebuilds WP config.
|
|
# $1 (domain): source site domain name.
|
|
# $2 (domainNew): target site domain name.
|
|
function cmdSiteCopy() {
|
|
local domain domainNew
|
|
domain=$(domainPrepare "$1")
|
|
domainNew=$(domainPrepare "$2")
|
|
|
|
printSection "Copy site"
|
|
printDotText "source" "$domain"
|
|
printDotText "target" "$domainNew"
|
|
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
elif ! runError error domainCheck "$domainNew"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
elif ! run output error siteCopy "$domain" "$domainNew"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "status" "$labelDone"
|
|
|
|
cmdOpenlitespeedRestart
|
|
|
|
if ! runError error wordpressDomainUpdate "$domainNew"; then
|
|
printDotText "update" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "update" "$labelDone"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# Renames a site by copying it to the new domain and removing the old one.
|
|
# $1 (domain): current site domain name.
|
|
# $2 (domainNew): new site domain name.
|
|
function cmdSiteRename() {
|
|
local domain domainNew
|
|
domain=$(domainPrepare "$1")
|
|
domainNew=$(domainPrepare "$2")
|
|
|
|
printSection "Rename site"
|
|
printDotText "source" "$domain"
|
|
printDotText "target" "$domainNew"
|
|
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
elif ! runError error domainCheck "$domainNew"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
elif ! run output error siteRename "$domain" "$domainNew"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "status" "$labelDone"
|
|
|
|
cmdOpenlitespeedRestart
|
|
|
|
if ! runError error wordpressDomainUpdate "$domainNew"; then
|
|
printDotText "update" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "update" "$labelDone"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# Creates a WordPress site from the bundled template, then rebuilds WP config.
|
|
# $1 (domain): site domain name.
|
|
# [$2] (sourceFiles): optional source directory or archive.
|
|
# [$@] (...): optional remaining arguments passed to cmdSiteAdd (e.g. database dump).
|
|
function cmdSiteAddWordpress() {
|
|
local domain sourceFiles
|
|
domain=$(domainPrepare "$1")
|
|
shift || true
|
|
|
|
sourceFiles="${1:-$appAssetsPath/vhost/wordpress}"
|
|
if [[ ! -e "$sourceFiles" ]]; then
|
|
sourceFiles="$appAssetsPath/vhost/wordpress.tar.gz"
|
|
fi
|
|
shift || true
|
|
|
|
printSection "Add site (Wordpress)"
|
|
printDotText "domain" "$domain"
|
|
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
elif ! run output error siteAdd "$domain" "$sourceFiles" "$@"; then
|
|
printDotText "status" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "status" "$labelDone"
|
|
|
|
cmdOpenlitespeedRestart
|
|
|
|
if ! run output error wordpressConfigRebuild "$domain"; then
|
|
printDanger "$error"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# Rebuilds OLS vhost/config, MariaDB, Redis, Postfix, and WordPress salt for a site.
|
|
# $1 (domain): site domain name.
|
|
function cmdSiteConfigRebuild() {
|
|
local domain
|
|
domain=$(domainPrepare "$1")
|
|
domainCheck "$domain" || return 1
|
|
|
|
printRow
|
|
|
|
if ! runError error openlitespeedVhostRebuild "$domain"; then
|
|
printDotText "OLS vhost" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "OLS vhost" "$labelDone"
|
|
fi
|
|
|
|
if ! runError error openlitespeedConfigVhostSet "$domain"; then
|
|
printDotText "OLS config" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "OLS config" "$labelDone"
|
|
fi
|
|
|
|
if ! runError error mariadbConfigRebuild "$domain"; then
|
|
printDotText "MariaDB" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "MariaDB" "$labelDone"
|
|
fi
|
|
|
|
if ! runError error redisConfigRebuild "$domain"; then
|
|
printDotText "Redis" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "Redis" "$labelDone"
|
|
fi
|
|
|
|
if ! runError error postfixConfigRebuild "$domain"; then
|
|
printDotText "Postfix" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "Postfix" "$labelDone"
|
|
fi
|
|
|
|
if ! runError error wordpressExec "$domain" config shuffle-salts; then
|
|
printDotText "Wordpress salt" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "Wordpress salt" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# Rebuilds the WordPress wp-config.php for a site.
|
|
# $1 (domain): site domain name.
|
|
function cmdSiteWordpressRebuild() {
|
|
local error
|
|
|
|
printRow
|
|
|
|
if ! runError error wordpressConfigRebuild "$@"; then
|
|
printDotText "Wordpress config rebuild" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "Wordpress config rebuild" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# Resets databasePass/redisPass/postfixPass and rebuilds configs for one site or all sites.
|
|
# Skips sites without wp-config.php in "all" mode.
|
|
# $1 (target): site domain name or "all".
|
|
function cmdSitePasswordReset() {
|
|
local target="$1"
|
|
local vhostList error
|
|
|
|
printRow
|
|
|
|
if [[ -z "$target" ]]; then
|
|
printDanger "Target not specified";
|
|
elif ! run vhostList error openlitespeedConfigVhostList; then
|
|
printDanger "Cannot get vhost list: $error";
|
|
elif [[ "$target" == "all" ]]; then
|
|
local domain
|
|
for domain in $vhostList; do
|
|
if ! runError error sitePasswordReset "$domain"; then
|
|
printDotText "$domain" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "$domain" "$labelDone"
|
|
fi
|
|
done
|
|
elif ! listContains "$target" "$vhostList"; then
|
|
printDanger "Unknown domain: $target";
|
|
elif ! runError error sitePasswordReset "$target"; then
|
|
printDotText "$target" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "$target" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# Resets all service credentials (passwords + usernames) and rebuilds configs for one site or all sites.
|
|
# Skips sites without wp-config.php in "all" mode.
|
|
# $1 (target): site domain name or "all".
|
|
function cmdSiteAuthReset() {
|
|
local target="$1"
|
|
local vhostList error
|
|
|
|
printRow
|
|
|
|
if [[ -z "$target" ]]; then
|
|
printDanger "Target not specified";
|
|
elif ! run vhostList error openlitespeedConfigVhostList; then
|
|
printDanger "Cannot get vhost list: $error";
|
|
elif [[ "$target" == "all" ]]; then
|
|
local domain
|
|
for domain in $vhostList; do
|
|
if ! runError error siteAuthReset "$domain"; then
|
|
printDotText "$domain" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "$domain" "$labelDone"
|
|
fi
|
|
done
|
|
elif ! listContains "$target" "$vhostList"; then
|
|
printDanger "Unknown domain: $target";
|
|
elif ! runError error siteAuthReset "$target"; then
|
|
printDotText "$target" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "$target" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# Exports a site's database to a file.
|
|
# $1 (domain): site domain name.
|
|
# [$2] (file): target dump file (auto-generated if omitted).
|
|
function cmdSiteDatabaseDump() {
|
|
local domain error
|
|
domain=$(domainPrepare "$1")
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDanger "$siteLabel $error"
|
|
return 1
|
|
fi
|
|
|
|
local file="$2"
|
|
if [[ -z "$file" ]]; then
|
|
file="$appDataPath/mariadb/${appDate}_${appTime}_$domain.sql.tar.gz"
|
|
fi
|
|
|
|
local databaseName databaseUser databasePass
|
|
databaseName=$(siteConfigGet "$domain" "databaseName")
|
|
databaseUser=$(siteConfigGet "$domain" "databaseUser")
|
|
databasePass=$(siteConfigGet "$domain" "databasePass")
|
|
|
|
printRow
|
|
printDotText "file" "$file"
|
|
printDotText "base" "$databaseName"
|
|
printDotText "user" "$databaseUser"
|
|
|
|
if ! runError error mariadbMasterExport "$databaseUser" "$databasePass" "$databaseName" "$file"; then
|
|
printDotText "status" "$labelFailed"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "status" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# Prints system, config, and OLS details for a site.
|
|
# $1 (domain): site domain name.
|
|
function cmdSiteInfo() {
|
|
printRow
|
|
|
|
local domain error
|
|
domain=$(domainPrepare "$1")
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDanger "$error"
|
|
return 1
|
|
fi
|
|
|
|
printSection "System"
|
|
local ug userId groupId
|
|
ug=$(domainToUser "$domain")
|
|
printDotText "user" "$ug"
|
|
printDotText "group" "$ug"
|
|
if ! run userId error id -u "$ug"; then
|
|
printDotText "userID" "$labelUnknown"
|
|
else
|
|
printDotText "userID" "$fontGreen$userId$fontReset"
|
|
fi
|
|
if ! run groupId error id -g "$ug"; then
|
|
printDotText "groupID" "$labelUnknown"
|
|
else
|
|
printDotText "groupID" "$fontGreen$groupId$fontReset"
|
|
fi
|
|
|
|
local ip
|
|
ip=$(systemHostGet "$domain")
|
|
if [[ -z "$ip" ]]; then
|
|
printDotText "/etc/hosts" "${fontGray}null$fontReset"
|
|
elif [[ "$ip" == '127.0.0.1' ]]; then
|
|
printDotText "/etc/hosts" "$fontGreen$ip$fontReset"
|
|
else
|
|
printDotText "/etc/hosts" "$fontRed$ip$fontReset"
|
|
fi
|
|
|
|
local limits blockLimit inodeLimit
|
|
if ! run limits error openlitespeedVhostQuotaGet "$ug"; then
|
|
printDotText "quota block limit" "$labelUnknown"
|
|
printDotText "quota inode limit" "$labelUnknown"
|
|
else
|
|
read -r blockLimit inodeLimit <<< "$limits"
|
|
blockLimit=$(numFormat "$blockLimit"000)
|
|
inodeLimit=$(numFormat "$inodeLimit")
|
|
printDotText "quota block limit" "$blockLimit"
|
|
printDotText "quota inode limit" "$inodeLimit"
|
|
fi
|
|
|
|
if groups "$ug" | grep -qw "$sftpAccessGroup"; then
|
|
printDotText "SFTP access" "$labelOn"
|
|
else
|
|
printDotText "SFTP access" "$labelOff"
|
|
fi
|
|
|
|
printSection "Config"
|
|
# printDotText "file$fontReset" "$appDataPath/config/$domain.config"
|
|
if [[ ! -f "$appDataPath/config/$domain.config" ]]; then
|
|
printDotText "file" "$fontRed$appDataPath/config/$domain.config$fontReset"
|
|
printDotText "file" "${fontRed}not found$fontReset"
|
|
else
|
|
printDotText "file" "$fontGreen$appDataPath/config/$domain.config$fontReset"
|
|
|
|
local -a params
|
|
local param value
|
|
params=(alias databaseName databaseUser databasePass redisUser redisPass postfixUser postfixPass postfixForwardTo sftpPass quotaBlockLimit quotaInodeLimit)
|
|
for param in "${params[@]}"; do
|
|
value=$(siteConfigGet "$domain" "$param")
|
|
printDotText "$param" "${value:-$labelNull}"
|
|
done
|
|
fi
|
|
|
|
printSection "OpenLiteSpeed"
|
|
if [[ ! -f "$olsVhostsConfigPath/$domain.conf" ]]; then
|
|
printDotText "file$fontReset" "$fontRed$olsVhostsConfigPath/$domain.conf$fontReset"
|
|
printDotText "file$fontReset" "${fontRed}not found$fontReset"
|
|
else
|
|
printDotText "file$fontReset" "$fontGreen$olsVhostsConfigPath/$domain.conf$fontReset"
|
|
fi
|
|
|
|
if [[ ! -d "$olsVhostsPath/$domain" ]]; then
|
|
printDotText "path$fontReset" "$fontRed$olsVhostsPath/$domain$fontReset"
|
|
printDotText "path$fontReset" "${fontRed}not found$fontReset"
|
|
else
|
|
printDotText "path$fontReset" "$fontGreen$olsVhostsPath/$domain$fontReset"
|
|
fi
|
|
|
|
if [[ ! -d "$olsPrivatePath/$domain" ]]; then
|
|
printDotText "data$fontReset" "$fontRed$olsPrivatePath/$domain$fontReset"
|
|
printDotText "data$fontReset" "${fontRed}not found$fontReset"
|
|
else
|
|
printDotText "data$fontReset" "$fontGreen$olsPrivatePath/$domain$fontReset"
|
|
fi
|
|
}
|
|
|
|
# Checks site resources (config, system, dirs, OLS, MariaDB, Redis, Postfix, HTTP).
|
|
# $1 (domain): site domain name.
|
|
# [$@] (opts): full|short (mode).
|
|
function cmdSiteStatus() {
|
|
local domain opt error section label note
|
|
domain=$(domainPrepare "$1")
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDanger "$siteLabel $error"
|
|
return 1
|
|
fi
|
|
|
|
mode="${2:-full}"
|
|
|
|
printSection "Config"
|
|
if [[ -f "$appDataPath/config/$domain.config" ]]; then
|
|
printDotText "file" "$fontGreen$appDataPath/config/$domain.config$fontReset"
|
|
|
|
local -a params
|
|
local param value
|
|
params=(databaseName databaseUser databasePass redisUser redisPass postfixUser postfixPass quotaBlockLimit quotaInodeLimit)
|
|
for param in "${params[@]}"; do
|
|
value=$(siteConfigGet "$domain" "$param")
|
|
if [[ -n "$value" ]]; then
|
|
printDotText "$param" "$labelPass"
|
|
else
|
|
printDotText "$param" "$labelFail"
|
|
fi
|
|
done
|
|
else
|
|
printDotText "file" "$fontRed$appDataPath/config/$domain.config$fontReset"
|
|
fi
|
|
|
|
printSection "System"
|
|
local userId groupId ug
|
|
ug=$(domainToUser "$domain")
|
|
note="$fontGray$ug$fontReset"
|
|
if ! run userId error id -u "$ug"; then
|
|
printDotText "user" "$note $labelFail"
|
|
else
|
|
printDotText "user" "$note $labelPass"
|
|
fi
|
|
if ! run groupId error id -g "$ug"; then
|
|
printDotText "group" "$note $labelFail"
|
|
else
|
|
printDotText "group" "$note $labelPass"
|
|
fi
|
|
|
|
local ip
|
|
ip=$(systemHostGet "$domain")
|
|
note="$fontGray$ip$fontReset"
|
|
if [[ "$ip" != '127.0.0.1' ]]; then
|
|
printDotText "/etc/hosts" "$note $labelFail"
|
|
else
|
|
printDotText "/etc/hosts" "$note $labelPass"
|
|
fi
|
|
|
|
local limits blockLimit inodeLimit
|
|
if ! run limits error openlitespeedVhostQuotaGet "$ug"; then
|
|
printDotText "quota block limit" "$labelFail"
|
|
printDotText "quota inode limit" "$labelFail"
|
|
else
|
|
read -r blockLimit inodeLimit <<< "$limits"
|
|
blockLimit=$(numFormat "$blockLimit"000)
|
|
inodeLimit=$(numFormat "$inodeLimit")
|
|
printDotText "quota block limit" "$blockLimit $labelPass"
|
|
printDotText "quota inode limit" "$inodeLimit $labelPass"
|
|
fi
|
|
|
|
local sftpConfig
|
|
if ! sftpConfig=$(sshd -T -C user="$ug",host="$hostName",addr=127.0.0.1); then
|
|
printDotText "SFTP config" "$labelFail"
|
|
else
|
|
label="$fontBlue SFTP ForceCommand$fontReset"
|
|
if ! grep -Fxq "forcecommand internal-sftp -d /www -u 027" <<< "$sftpConfig"; then
|
|
printDotText "SFTP ForceCommand" "$labelFail"
|
|
else
|
|
printDotText "SFTP ForceCommand" "$labelPass"
|
|
fi
|
|
if ! grep -Fxq "chrootdirectory %h" <<< "$sftpConfig"; then
|
|
printDotText "SFTP ChrootDirectory" "$labelFail"
|
|
else
|
|
printDotText "SFTP ChrootDirectory" "$labelPass"
|
|
fi
|
|
fi
|
|
|
|
printSection "Path | existence, owner, permissions, ACL:nobody"
|
|
local path
|
|
path="$olsVhostsPath/$domain"
|
|
label="vhost $fontBlue/$fontReset"
|
|
note="${fontGray}755:root:root$fontReset"
|
|
if [[ ! -d "$path" ]]; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureCheck "$path" "755:root:root"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
else
|
|
printDotText "$label" "$note $labelPass"
|
|
fi
|
|
|
|
path="$olsVhostsPath/$domain/www"
|
|
label="vhost $fontBlue/www$fontReset"
|
|
note="${fontGray}2750:u:g acl:r-x$fontReset"
|
|
if [[ ! -d "$path" ]]; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureCheck "$path" "2750:$ug:$ug"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureAclCheck "$path" "user:nobody:r-x"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
else
|
|
printDotText "$label" "$note $labelPass"
|
|
fi
|
|
|
|
local -a dirs
|
|
local dir
|
|
dirs=(session tmp)
|
|
for dir in "${dirs[@]}"; do
|
|
path="$olsVhostsPath/$domain/$dir"
|
|
label="vhost $fontBlue/$dir$fontReset"
|
|
note="${fontGray}770:u:g acl:rwx$fontReset"
|
|
if [[ ! -d "$path" ]]; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureCheck "$path" "770:$ug:$ug"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureAclCheck "$path" "user:nobody:rwx"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
else
|
|
printDotText "$label" "$note $labelPass"
|
|
fi
|
|
done
|
|
|
|
path="$olsPrivatePath/$domain"
|
|
label="vhost-data $fontBlue/$fontReset"
|
|
note="${fontGray}750:u:g acl:r-x$fontReset"
|
|
if [[ ! -d "$path" ]]; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureCheck "$path" "750:$ug:$ug"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureAclCheck "$path" "user:nobody:r-x"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
else
|
|
printDotText "$label" "$note $labelPass"
|
|
fi
|
|
|
|
path="$olsPrivatePath/$domain/bootstrap.php"
|
|
label="vhost-data $fontBlue/bootstrap.php$fontReset"
|
|
note="${fontGray}600:u:g acl:r--$fontReset"
|
|
if [[ ! -f "$path" ]]; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureCheck "$path" "600:$ug:$ug"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
elif ! fileSignatureAclCheck "$path" "user:nobody:r--"; then
|
|
printDotText "$label" "$note $labelFail"
|
|
else
|
|
printDotText "$label" "$note $labelPass"
|
|
fi
|
|
# fileSignatureAclDiff "$path" "user:nobody:r--"
|
|
|
|
printSection "OpenLiteSpeed"
|
|
if ! run vhostList error openlitespeedConfigVhostList; then
|
|
printDotText "get vhost list" "$labelFail"
|
|
else
|
|
note="$fontGray$domain$fontReset"
|
|
if listContains "$domain" "$vhostList"; then
|
|
printDotText "vhost" "$note $labelPass"
|
|
else
|
|
printDotText "vhost" "$note $labelFail"
|
|
fi
|
|
fi
|
|
note="$fontGray$domain.conf$fontReset"
|
|
if [[ ! -f "$olsVhostsConfigPath/$domain.conf" ]]; then
|
|
printDotText "config" "$note $labelFail"
|
|
else
|
|
printDotText "config" "$note $labelPass"
|
|
fi
|
|
|
|
printSection "MariaDB"
|
|
local mariadbDatabaseList mariadbUserList
|
|
if ! run mariadbDatabaseList error mariadbDatabaseListGet; then
|
|
printDotText "get database list" "$labelFail"
|
|
elif ! run mariadbUserList error mariadbUserListGet; then
|
|
printDotText "get user list" "$labelFail"
|
|
else
|
|
mariadbDatabase=$(siteConfigGet "$domain" "databaseName")
|
|
note="$fontGray$mariadbDatabase$fontReset"
|
|
if ! listContains "$mariadbDatabase" "$mariadbDatabaseList"; then
|
|
printDotText "base" "$note $labelFail"
|
|
else
|
|
printDotText "base" "$note $labelPass"
|
|
fi
|
|
|
|
mariadbUser=$(siteConfigGet "$domain" "databaseUser")
|
|
note="$fontGray$mariadbUser$fontReset"
|
|
if ! listContains "$mariadbUser" "$mariadbUserList"; then
|
|
printDotText "user" "$note $labelFail"
|
|
else
|
|
printDotText "user" "$note $labelPass"
|
|
fi
|
|
|
|
if [[ "$mode" == "full" ]]; then
|
|
mariadbPass=$(siteConfigGet "$domain" "databasePass")
|
|
if ! run output error mariadbMasterExec mariadb -u"$mariadbUser" -p"$mariadbPass" -N -e "SELECT 1;"; then
|
|
printDotText "access" "$labelFail"
|
|
elif [[ "$output" != "1" ]]; then
|
|
printDotText "access" "$labelFail"
|
|
else
|
|
printDotText "access" "$labelPass"
|
|
fi
|
|
fi
|
|
fi
|
|
|
|
printSection "Redis"
|
|
local redisUserList
|
|
if ! run redisUserList error redisUserListGet; then
|
|
printDotText "$fontBlue get user list$fontReset" "$labelFail"
|
|
else
|
|
redisUser=$(siteConfigGet "$domain" "redisUser")
|
|
note="$fontGray$redisUser$fontReset"
|
|
if ! listContains "$redisUser" "$redisUserList"; then
|
|
printDotText "user" "$note $labelFail"
|
|
else
|
|
printDotText "user" "$note $labelPass"
|
|
fi
|
|
if [[ "$mode" == "full" ]]; then
|
|
redisPass=$(siteConfigGet "$domain" "redisPass")
|
|
if ! run output error redisExec redis-cli --no-auth-warning --user "$redisUser" --pass "$redisPass" PING; then
|
|
printDotText "access" "$labelFail"
|
|
elif [[ "$output" != "PONG" ]]; then
|
|
printDotText "access" "$labelFail"
|
|
else
|
|
printDotText "access" "$labelPass"
|
|
fi
|
|
fi
|
|
fi
|
|
|
|
printSection "Postfix"
|
|
local postfixSaslUserList
|
|
if ! run postfixSaslUserList error postfixSaslUserList; then
|
|
printDotText "get SASL list" "$labelFail"
|
|
else
|
|
postfixUser=$(siteConfigGet "$domain" "postfixUser")
|
|
note="$fontGray$postfixUser$fontReset"
|
|
if ! listContains "$postfixUser@$postfixDefaultRealm" "$postfixSaslUserList"; then
|
|
printDotText "SASL user" "$note $labelFail"
|
|
else
|
|
printDotText "SASL user" "$note $labelPass"
|
|
fi
|
|
postfixPass=$(siteConfigGet "$domain" "postfixPass")
|
|
printDotText "SASL access" "${fontGray}in progress$fontReset"
|
|
fi
|
|
|
|
if [[ "$mode" == "full" ]]; then
|
|
printSection "HTTP"
|
|
local httpCode urlEffective
|
|
if ! run httpCode error urlCode "http://$domain"; then
|
|
printDotText "HTTP code" "${fontGray}unknown$fontReset"
|
|
elif [[ "$httpCode" == 200 ]]; then
|
|
printDotText "HTTP code" "$fontGreen$httpCode$fontReset"
|
|
elif [[ "$httpCode" =~ ^[23][0-9]{2}$ ]]; then
|
|
printDotText "HTTP code" "$fontYellow$httpCode$fontReset"
|
|
else
|
|
printDotText "HTTP code" "$fontRed$httpCode$fontReset"
|
|
fi
|
|
if ! run urlEffective error urlAccessible "$domain"; then
|
|
printDotText "URL effective" "${fontGray}unknown$fontReset"
|
|
else
|
|
printDotText "URL effective" "$fontGreen$urlEffective$fontReset"
|
|
fi
|
|
|
|
printSection "Files"
|
|
siteFilesCheck "$domain"
|
|
fi
|
|
}
|
|
|
|
function siteFilesCheck() {
|
|
local domain error ug dots
|
|
domain=$(domainPrepare "$1")
|
|
if ! runError error domainCheck "$domain"; then
|
|
printDanger "$error"
|
|
return 1
|
|
fi
|
|
|
|
ug=$(domainToUser "$domain")
|
|
dots=30
|
|
|
|
# fileSignatureDiff "$olsVhostsPath/$domain" "755:root:root"
|
|
if ! run output error fileSignatureDiff "$olsVhostsPath/$domain" "755:root:root"; then
|
|
printDanger "${error:-$output}"
|
|
elif [[ -n "$output" ]]; then
|
|
local prefix=":$olsVhostsPath/$domain"
|
|
printDot "$dots" "${fontCyan}vhost d 755:root:root$fontReset" "" "${output/$prefix/ /}"
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsVhostsPath/$domain/www" "d" "2750|$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/www" "d" "2750|$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}www d 2750:u:g$fontReset"
|
|
local prefix=":$olsVhostsPath/$domain/www/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsVhostsPath/$domain/www" "f" "(600|640):$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/www" "f" "(600|640):$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}www f (600|640):u:g$fontReset"
|
|
local prefix=":$olsVhostsPath/$domain/www/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "d" "770:$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "d" "770:$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}tmp d 770:u:g$fontReset"
|
|
local prefix=":$olsVhostsPath/$domain/tmp/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "f" "660:$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "f" "660:$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}tmp f 660:u:g$fontReset"
|
|
local prefix=":$olsVhostsPath/$domain/tmp/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsVhostsPath/$domain/session" "d" "770:$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/session" "d" "770:$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}session d 770:u:g$fontReset"
|
|
local prefix=":$olsVhostsPath/$domain/session/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsVhostsPath/$domain/session" "f" "(660|600):$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/session" "f" "(660|600):$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}session f (660|600):u:g$fontReset"
|
|
local prefix=":$olsVhostsPath/$domain/session/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsPrivatePath/$domain" "d" "750:$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsPrivatePath/$domain" "d" "750:$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}data d 750:u:g$fontReset"
|
|
local prefix=":$olsPrivatePath/$domain/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
|
|
# fileSignatureDiffList "$olsPrivatePath/$domain" "f" "600:$ug:$ug"
|
|
if ! run output error fileSignatureDiffList "$olsPrivatePath/$domain" "f" "600:$ug:$ug"; then
|
|
printDanger "${error:-$output}"
|
|
else
|
|
lineCount=$(grep -c . <<< "$output" || true)
|
|
if [[ "$lineCount" -gt 0 ]]; then
|
|
local label="${fontCyan}data f 600:u:g$fontReset"
|
|
local prefix=":$olsPrivatePath/$domain/"
|
|
while read -r line; do
|
|
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
|
done < <(awk 'NF' <<< "$output")
|
|
fi
|
|
fi
|
|
}
|