Rev 807 | Rev 837 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed
Rev | Author | Line No. | Line |
---|---|---|---|
635 | daniel-mar | 1 | <?php |
2 | |||
3 | /* |
||
4 | * OIDplus 2.0 |
||
807 | daniel-mar | 5 | * Copyright 2019 - 2022 Daniel Marschall, ViaThinkSoft |
635 | daniel-mar | 6 | * |
7 | * Licensed under the Apache License, Version 2.0 (the "License"); |
||
8 | * you may not use this file except in compliance with the License. |
||
9 | * You may obtain a copy of the License at |
||
10 | * |
||
11 | * http://www.apache.org/licenses/LICENSE-2.0 |
||
12 | * |
||
13 | * Unless required by applicable law or agreed to in writing, software |
||
14 | * distributed under the License is distributed on an "AS IS" BASIS, |
||
15 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||
16 | * See the License for the specific language governing permissions and |
||
17 | * limitations under the License. |
||
18 | */ |
||
19 | |||
20 | if (!defined('INSIDE_OIDPLUS')) die(); |
||
21 | |||
22 | class OIDplusPageAdminSoftwareUpdate extends OIDplusPagePluginAdmin { |
||
23 | |||
24 | public function init($html=true) { |
||
25 | } |
||
26 | |||
697 | daniel-mar | 27 | private function getGitCommand() { |
698 | daniel-mar | 28 | return 'git --git-dir='.escapeshellarg(OIDplus::findGitFolder().'/').' --work-tree='.escapeshellarg(OIDplus::localpath()).' -C "" pull origin master -s recursive -X theirs'; |
697 | daniel-mar | 29 | } |
30 | |||
31 | private function getSvnCommand() { |
||
32 | return 'svn update --accept theirs-full'; |
||
33 | } |
||
34 | |||
635 | daniel-mar | 35 | public function action($actionID, $params) { |
36 | if ($actionID == 'update_now') { |
||
647 | daniel-mar | 37 | @set_time_limit(0); |
635 | daniel-mar | 38 | |
39 | if (!OIDplus::authUtils()->isAdminLoggedIn()) { |
||
40 | throw new OIDplusException(_L('You need to <a %1>log in</a> as administrator.',OIDplus::gui()->link('oidplus:login$admin'))); |
||
41 | } |
||
42 | |||
662 | daniel-mar | 43 | if (OIDplus::getInstallType() === 'git-wc') { |
697 | daniel-mar | 44 | $cmd = $this->getGitCommand().' 2>&1'; |
662 | daniel-mar | 45 | |
46 | $ec = -1; |
||
47 | $out = array(); |
||
48 | exec($cmd, $out, $ec); |
||
49 | |||
50 | $res = _L('Execute command:').' '.$cmd."\n\n".trim(implode("\n",$out)); |
||
51 | if ($ec === 0) { |
||
52 | $rev = 'HEAD'; // do not translate |
||
53 | return array("status" => 0, "content" => $res, "rev" => $rev); |
||
54 | } else { |
||
55 | return array("status" => -1, "error" => $res, "content" => ""); |
||
56 | } |
||
653 | daniel-mar | 57 | } |
662 | daniel-mar | 58 | else if (OIDplus::getInstallType() === 'svn-wc') { |
697 | daniel-mar | 59 | $cmd = $this->getSvnCommand().' 2>&1'; |
653 | daniel-mar | 60 | |
662 | daniel-mar | 61 | $ec = -1; |
62 | $out = array(); |
||
63 | exec($cmd, $out, $ec); |
||
635 | daniel-mar | 64 | |
662 | daniel-mar | 65 | $res = _L('Execute command:').' '.$cmd."\n\n".trim(implode("\n",$out)); |
66 | if ($ec === 0) { |
||
67 | $rev = 'HEAD'; // do not translate |
||
68 | return array("status" => 0, "content" => $res, "rev" => $rev); |
||
69 | } else { |
||
70 | return array("status" => -1, "error" => $res, "content" => ""); |
||
71 | } |
||
650 | daniel-mar | 72 | } |
662 | daniel-mar | 73 | else if (OIDplus::getInstallType() === 'svn-snapshot') { |
635 | daniel-mar | 74 | |
662 | daniel-mar | 75 | $rev = $params['rev']; |
650 | daniel-mar | 76 | |
807 | daniel-mar | 77 | $update_version = isset($params['update_version']) ? $params['update_version'] : 1; |
78 | if (($update_version != 1) && ($update_version != 2)) { |
||
79 | throw new OIDplusException(_L('Unknown update version')); |
||
80 | } |
||
81 | |||
662 | daniel-mar | 82 | // Download and unzip |
651 | daniel-mar | 83 | |
716 | daniel-mar | 84 | $cont = false; |
85 | for ($retry=1; $retry<=3; $retry++) { |
||
86 | if (function_exists('gzdecode')) { |
||
87 | $url = sprintf(OIDplus::getEditionInfo()['update_package_gz'], $rev-1, $rev); |
||
88 | $cont = url_get_contents($url); |
||
89 | if ($cont !== false) $cont = @gzdecode($cont); |
||
90 | } else { |
||
91 | $url = sprintf(OIDplus::getEditionInfo()['update_package'], $rev-1, $rev); |
||
92 | $cont = url_get_contents($url); |
||
93 | } |
||
94 | if ($cont !== false) { |
||
95 | break; |
||
96 | } else { |
||
97 | sleep(1); |
||
98 | } |
||
651 | daniel-mar | 99 | } |
662 | daniel-mar | 100 | if ($cont === false) throw new OIDplusException(_L("Update %1 could not be downloaded from ViaThinkSoft server. Please try again later.",$rev)); |
651 | daniel-mar | 101 | |
662 | daniel-mar | 102 | // Check signature... |
103 | |||
104 | if (function_exists('openssl_verify')) { |
||
105 | |||
106 | $m = array(); |
||
107 | if (!preg_match('@<\?php /\* <ViaThinkSoftSignature>(.+)</ViaThinkSoftSignature> \*/ \?>\n@ismU', $cont, $m)) { |
||
108 | throw new OIDplusException(_L("Update package file of revision %1 not digitally signed",$rev)); |
||
109 | } |
||
110 | $signature = base64_decode($m[1]); |
||
111 | |||
112 | $naked = preg_replace('@<\?php /\* <ViaThinkSoftSignature>(.+)</ViaThinkSoftSignature> \*/ \?>\n@ismU', '', $cont); |
||
113 | $hash = hash("sha256", $naked."update_".($rev-1)."_to_".($rev).".txt"); |
||
114 | |||
115 | $public_key = file_get_contents(__DIR__.'/public.pem'); |
||
116 | if (!openssl_verify($hash, $signature, $public_key, OPENSSL_ALGO_SHA256)) { |
||
117 | throw new OIDplusException(_L("Update package file of revision %1: Signature invalid",$rev)); |
||
118 | } |
||
119 | |||
651 | daniel-mar | 120 | } |
121 | |||
662 | daniel-mar | 122 | // All OK! Now write file |
651 | daniel-mar | 123 | |
662 | daniel-mar | 124 | $tmp_filename = 'update_'.generateRandomString(10).'.tmp.php'; |
125 | $local_file = OIDplus::localpath().$tmp_filename; |
||
651 | daniel-mar | 126 | |
662 | daniel-mar | 127 | @file_put_contents($local_file, $cont); |
635 | daniel-mar | 128 | |
662 | daniel-mar | 129 | if (!file_exists($local_file) || (@file_get_contents($local_file) !== $cont)) { |
130 | throw new OIDplusException(_L('Update file could not written. Probably there are no write-permissions to the root folder.')); |
||
131 | } |
||
647 | daniel-mar | 132 | |
807 | daniel-mar | 133 | if ($update_version == 1) { |
134 | // Now call the written file |
||
135 | // Note: we may not use eval($cont) because the script uses die(), |
||
136 | // and things in the script might collide with currently (un)loaded source code files, shutdown procedues, etc. |
||
137 | $web_file = OIDplus::webpath(null,OIDplus::PATH_ABSOLUTE).$tmp_filename; // NOT canonical URL! This might fail with reverse proxies which can only be executed from outside |
||
138 | $res = url_get_contents($web_file); |
||
139 | if ($res === false) { |
||
140 | throw new OIDplusException(_L('Update-script %1 could not be executed',$web_file)); |
||
141 | } |
||
142 | return array("status" => 0, "content" => $res, "rev" => $rev); |
||
143 | } else if ($update_version == 2) { |
||
144 | // In this version, the client will call the web-update file. |
||
145 | // This has the advantage that it will also work if the system is htpasswd protected |
||
146 | return array("status" => 0, "update_file" => $tmp_filename, "rev" => $rev); |
||
662 | daniel-mar | 147 | } |
653 | daniel-mar | 148 | } |
662 | daniel-mar | 149 | else { |
716 | daniel-mar | 150 | throw new OIDplusException(_L('Multiple version files/directories (oidplus_version.txt, .version.php, .git, or .svn) are existing! Therefore, the version is ambiguous!')); |
662 | daniel-mar | 151 | } |
635 | daniel-mar | 152 | } |
153 | } |
||
154 | |||
155 | public function gui($id, &$out, &$handled) { |
||
156 | $parts = explode('.',$id,2); |
||
157 | if (!isset($parts[1])) $parts[1] = ''; |
||
158 | if ($parts[0] == 'oidplus:software_update') { |
||
159 | @set_time_limit(0); |
||
160 | |||
161 | $handled = true; |
||
162 | $out['title'] = _L('Software update'); |
||
801 | daniel-mar | 163 | $out['icon'] = OIDplus::webpath(__DIR__,OIDplus::PATH_RELATIVE).'img/main_icon.png'; |
635 | daniel-mar | 164 | |
165 | if (!OIDplus::authUtils()->isAdminLoggedIn()) { |
||
800 | daniel-mar | 166 | $out['icon'] = 'img/error.png'; |
635 | daniel-mar | 167 | $out['text'] = '<p>'._L('You need to <a %1>log in</a> as administrator.',OIDplus::gui()->link('oidplus:login$admin')).'</p>'; |
168 | return; |
||
169 | } |
||
170 | |||
665 | daniel-mar | 171 | $out['text'] .= '<div id="update_versioninfo">'; |
172 | |||
635 | daniel-mar | 173 | $out['text'] .= '<p><u>'._L('There are three possibilities how to keep OIDplus up-to-date').':</u></p>'; |
174 | |||
699 | daniel-mar | 175 | if (isset(OIDplus::getEditionInfo()['gitrepo']) && (OIDplus::getEditionInfo()['gitrepo'] != '')) { |
176 | $out['text'] .= '<p><b>'._L('Method A').'</b>: '._L('Install OIDplus using the subversion tool in your SSH/Linux shell using the command <code>svn co %1</code> and update it regularly with the command <code>svn update</code> . This will automatically download the latest version and check for conflicts. Highly recommended if you have a Shell/SSH access to your webspace!',htmlentities(OIDplus::getEditionInfo()['svnrepo'])).'</p>'; |
||
177 | } else { |
||
178 | $out['text'] .= '<p><b>'._L('Method A').'</b>: '._L('Distribution via %1 is not possible with this edition of OIDplus','GIT').'</p>'; |
||
179 | } |
||
635 | daniel-mar | 180 | |
699 | daniel-mar | 181 | if (isset(OIDplus::getEditionInfo()['svnrepo']) && (OIDplus::getEditionInfo()['svnrepo'] != '')) { |
182 | $out['text'] .= '<p><b>'._L('Method B').'</b>: '._L('Install OIDplus using the Git client in your SSH/Linux shell using the command <code>git clone %1</code> and update it regularly with the command <code>git pull</code> . This will automatically download the latest version and check for conflicts. Highly recommended if you have a Shell/SSH access to your webspace!',htmlentities(OIDplus::getEditionInfo()['gitrepo'].'.git')).'</p>'; |
||
183 | } else { |
||
184 | $out['text'] .= '<p><b>'._L('Method B').'</b>: '._L('Distribution via %1 is not possible with this edition of OIDplus','SVN').'</p>'; |
||
185 | } |
||
635 | daniel-mar | 186 | |
699 | daniel-mar | 187 | if (isset(OIDplus::getEditionInfo()['downloadpage']) && (OIDplus::getEditionInfo()['downloadpage'] != '')) { |
188 | $out['text'] .= '<p><b>'._L('Method C').'</b>: '._L('Install OIDplus by downloading a TAR.GZ file from %1, which contains an SVN snapshot, and extract it to your webspace. The TAR.GZ file contains a file named ".version.php" which contains the SVN revision of the snapshot. This update-tool will then try to update your files on-the-fly by downloading them from the ViaThinkSoft SVN repository directly into your webspace directory. A change conflict detection is NOT implemented. It is required that the files on your webspace have create/write/delete permissions. Only recommended if you have no access to the SSH/Linux shell.','<a href="'.OIDplus::getEditionInfo()['downloadpage'].'">'.parse_url(OIDplus::getEditionInfo()['downloadpage'])['host'].'</a>').'</p>'; |
||
189 | } else { |
||
190 | $out['text'] .= '<p><b>'._L('Method C').'</b>: '._L('Distribution via %1 is not possible with this edition of OIDplus','Snapshot').'</p>'; |
||
191 | } |
||
635 | daniel-mar | 192 | |
699 | daniel-mar | 193 | |
635 | daniel-mar | 194 | $out['text'] .= '<hr>'; |
195 | |||
196 | $installType = OIDplus::getInstallType(); |
||
197 | |||
198 | if ($installType === 'ambigous') { |
||
716 | daniel-mar | 199 | $out['text'] .= '<font color="red">'.strtoupper(_L('Error')).': '._L('Multiple version files/directories (oidplus_version.txt, .version.php, .git, or .svn) are existing! Therefore, the version is ambiguous!').'</font>'; |
665 | daniel-mar | 200 | $out['text'] .= '</div>'; |
635 | daniel-mar | 201 | } else if ($installType === 'unknown') { |
202 | $out['text'] .= '<font color="red">'.strtoupper(_L('Error')).': '._L('The version cannot be determined, and the update needs to be applied manually!').'</font>'; |
||
665 | daniel-mar | 203 | $out['text'] .= '</div>'; |
662 | daniel-mar | 204 | } else if (($installType === 'svn-wc') || ($installType === 'git-wc') || ($installType === 'svn-snapshot')) { |
635 | daniel-mar | 205 | if ($installType === 'svn-wc') { |
206 | $out['text'] .= '<p>'._L('You are using <b>method A</b> (SVN working copy).').'</p>'; |
||
662 | daniel-mar | 207 | $requireInfo = _L('shell access with svn/svnversion tool, or PDO/SQLite3 PHP extension'); |
697 | daniel-mar | 208 | $updateCommand = $this->getSvnCommand(); |
662 | daniel-mar | 209 | } else if ($installType === 'git-wc') { |
635 | daniel-mar | 210 | $out['text'] .= '<p>'._L('You are using <b>method B</b> (Git working copy).').'</p>'; |
662 | daniel-mar | 211 | $requireInfo = _L('shell access with Git client'); |
697 | daniel-mar | 212 | $updateCommand = $this->getGitCommand(); |
662 | daniel-mar | 213 | } else if ($installType === 'svn-snapshot') { |
214 | $out['text'] .= '<p>'._L('You are using <b>method C</b> (Snapshot TAR.GZ file with .version.php file).').'</p>'; |
||
215 | $requireInfo = ''; // unused |
||
216 | $updateCommand = ''; // unused |
||
635 | daniel-mar | 217 | } |
218 | |||
219 | $local_installation = OIDplus::getVersion(); |
||
648 | daniel-mar | 220 | $newest_version = $this->getLatestRevision(); |
635 | daniel-mar | 221 | |
222 | $out['text'] .= _L('Local installation: %1',($local_installation ? $local_installation : _L('unknown'))).'<br>'; |
||
662 | daniel-mar | 223 | $out['text'] .= _L('Latest published version: %1',($newest_version ? $newest_version : _L('unknown'))).'<br><br>'; |
635 | daniel-mar | 224 | |
225 | if (!$newest_version) { |
||
226 | $out['text'] .= '<p><font color="red">'._L('OIDplus could not determine the latest version. Probably the ViaThinkSoft server could not be reached.').'</font></p>'; |
||
662 | daniel-mar | 227 | $out['text'] .= '</div>'; |
654 | daniel-mar | 228 | } else if (!$local_installation) { |
662 | daniel-mar | 229 | if ($installType === 'svn-snapshot') { |
230 | $out['text'] .= '<p><font color="red">'._L('OIDplus could not determine its version.').'</font></p>'; |
||
231 | } else { |
||
232 | $out['text'] .= '<p><font color="red">'._L('OIDplus could not determine its version. (Required: %1). Please update your system manually via the "%2" command regularly.',$requireInfo,$updateCommand).'</font></p>'; |
||
635 | daniel-mar | 233 | } |
647 | daniel-mar | 234 | $out['text'] .= '</div>'; |
654 | daniel-mar | 235 | } else if (substr($local_installation,4) >= substr($newest_version,4)) { |
635 | daniel-mar | 236 | $out['text'] .= '<p><font color="green">'._L('You are already using the latest version of OIDplus.').'</font></p>'; |
647 | daniel-mar | 237 | $out['text'] .= '</div>'; |
635 | daniel-mar | 238 | } else { |
662 | daniel-mar | 239 | if (($installType === 'svn-wc') || ($installType === 'git-wc')) { |
240 | $out['text'] .= '<p><font color="blue">'._L('Please enter %1 into the SSH shell to update OIDplus to the latest version.','<code>'.$updateCommand.'</code>').'</font></p>'; |
||
241 | $out['text'] .= '<p>'._L('Alternatively, click this button to execute the command through the web-interface (command execution and write permissions required).').'</p>'; |
||
242 | } |
||
635 | daniel-mar | 243 | |
648 | daniel-mar | 244 | $out['text'] .= '<p><input type="button" onclick="OIDplusPageAdminSoftwareUpdate.doUpdateOIDplus('.((int)substr($local_installation,4)+1).', '.substr($newest_version,4).')" value="'._L('Update NOW').'"></p>'; |
635 | daniel-mar | 245 | |
662 | daniel-mar | 246 | // TODO: Open "system_file_check" without page reload. |
247 | // TODO: Only show link if the plugin is installed |
||
700 | daniel-mar | 248 | $out['text'] .= '<p><font color="red">'.strtoupper(_L('Warning')).': '._L('Please make a backup of your files before updating. In case of an error, the OIDplus system (including this update-assistant) might become unavailable. Also, since the web-update does not contain collision-detection, changes you have applied (like adding, removing or modified files) might get reverted/lost! (<a href="%1">Click here to check which files have been modified</a>) In case the update fails, you can download and extract the complete <a href="%s">SVN-Snapshot TAR.GZ file</a> again. Since all your data should lay inside the folder "userdata" and "userdata_pub", this should be safe.','?goto='.urlencode('oidplus:system_file_check'),OIDplus::getEditionInfo()['downloadpage']).'</font></p>'; |
662 | daniel-mar | 249 | |
647 | daniel-mar | 250 | $out['text'] .= '</div>'; |
251 | |||
662 | daniel-mar | 252 | $out['text'] .= $this->showPreview($local_installation, $newest_version); |
635 | daniel-mar | 253 | } |
254 | } |
||
255 | } else { |
||
256 | $handled = false; |
||
257 | } |
||
258 | } |
||
259 | |||
260 | public function tree(&$json, $ra_email=null, $nonjs=false, $req_goto='') { |
||
261 | if (!OIDplus::authUtils()->isAdminLoggedIn()) return false; |
||
262 | |||
800 | daniel-mar | 263 | if (file_exists(__DIR__.'/img/main_icon16.png')) { |
801 | daniel-mar | 264 | $tree_icon = OIDplus::webpath(__DIR__,OIDplus::PATH_RELATIVE).'img/main_icon16.png'; |
635 | daniel-mar | 265 | } else { |
266 | $tree_icon = null; // default icon (folder) |
||
267 | } |
||
268 | |||
269 | $json[] = array( |
||
270 | 'id' => 'oidplus:software_update', |
||
271 | 'icon' => $tree_icon, |
||
272 | 'text' => _L('Software update') |
||
273 | ); |
||
274 | |||
275 | return true; |
||
276 | } |
||
277 | |||
278 | public function tree_search($request) { |
||
279 | return false; |
||
280 | } |
||
648 | daniel-mar | 281 | |
282 | private $releases_ser = null; |
||
283 | |||
284 | private function showChangelog($local_ver) { |
||
285 | |||
286 | try { |
||
287 | if (is_null($this->releases_ser)) { |
||
716 | daniel-mar | 288 | if (function_exists('gzdecode')) { |
289 | $url = OIDplus::getEditionInfo()['revisionlog_gz']; |
||
290 | $cont = url_get_contents($url); |
||
291 | if ($cont !== false) $cont = @gzdecode($cont); |
||
292 | } else { |
||
293 | $url = OIDplus::getEditionInfo()['revisionlog']; |
||
294 | $cont = url_get_contents($url); |
||
295 | } |
||
648 | daniel-mar | 296 | if ($cont === false) return false; |
297 | $this->releases_ser = $cont; |
||
298 | } else { |
||
299 | $cont = $this->releases_ser; |
||
300 | } |
||
301 | $content = ''; |
||
302 | $ary = @unserialize($cont); |
||
303 | if ($ary === false) return false; |
||
304 | krsort($ary); |
||
305 | foreach ($ary as $rev => $data) { |
||
306 | if ($rev <= substr($local_ver,4)) continue; |
||
307 | $comment = empty($data['msg']) ? _L('No comment') : $data['msg']; |
||
308 | $tex = _L("New revision %1 by %2",$rev,$data['author'])." (".$data['date'].") "; |
||
309 | $content .= trim($tex . str_replace("\n", "\n".str_repeat(' ', strlen($tex)), $comment)); |
||
310 | $content .= "\n"; |
||
311 | } |
||
312 | return $content; |
||
313 | } catch (Exception $e) { |
||
314 | return false; |
||
315 | } |
||
316 | |||
317 | } |
||
318 | |||
319 | private function getLatestRevision() { |
||
320 | try { |
||
321 | if (is_null($this->releases_ser)) { |
||
716 | daniel-mar | 322 | if (function_exists('gzdecode')) { |
323 | $url = OIDplus::getEditionInfo()['revisionlog_gz']; |
||
324 | $cont = url_get_contents($url); |
||
325 | if ($cont !== false) $cont = @gzdecode($cont); |
||
326 | } else { |
||
327 | $url = OIDplus::getEditionInfo()['revisionlog']; |
||
328 | $cont = url_get_contents($url); |
||
329 | } |
||
648 | daniel-mar | 330 | if ($cont === false) return false; |
331 | $this->releases_ser = $cont; |
||
332 | } else { |
||
333 | $cont = $this->releases_ser; |
||
334 | } |
||
335 | $ary = @unserialize($cont); |
||
336 | if ($ary === false) return false; |
||
337 | krsort($ary); |
||
338 | $max_rev = array_keys($ary)[0]; |
||
339 | $newest_version = 'svn-' . $max_rev; |
||
340 | return $newest_version; |
||
341 | } catch (Exception $e) { |
||
342 | return false; |
||
343 | } |
||
344 | } |
||
662 | daniel-mar | 345 | |
346 | private function showPreview($local_installation, $newest_version) { |
||
347 | $out = '<h2 id="update_header">'._L('Preview of update %1 → %2',$local_installation,$newest_version).'</h2>'; |
||
348 | |||
349 | ob_start(); |
||
350 | try { |
||
351 | $cont = $this->showChangelog($local_installation); |
||
352 | } catch (Exception $e) { |
||
353 | $cont = _L('Error: %1',$e->getMessage()); |
||
354 | } |
||
355 | ob_end_clean(); |
||
356 | |||
831 | daniel-mar | 357 | $cont = preg_replace('@!!!(.+)\\n@', '<font color="red">!!!\\1</font>'."\n", "$cont\n"); |
662 | daniel-mar | 358 | |
359 | $out .= '<pre id="update_infobox">'.$cont.'</pre>'; |
||
360 | |||
361 | return $out; |
||
362 | } |
||
661 | daniel-mar | 363 | } |