add.php 4.59 KB
Newer Older
1
<!-- /* Copyright (c) 2011, David Morley. This file is licensed under the Affero General Public License version 3 or later. See the COPYRIGHT file. */ -->
David Morley's avatar
David Morley committed
2
<?php
3
require_once __DIR__ . '/../logging.php';
dmorley's avatar
dmorley committed
4
require_once __DIR__ . '/../config.php';
dmorley's avatar
dmorley committed
5
$log = new Logging();
dmorley's avatar
dmorley committed
6
$log->lfile(__DIR__ . '/../' . $log_dir . '/add.log');
David Morley's avatar
David Morley committed
7
if (!($_domain = $_GET['domain'] ?? null)) {
8 9 10
  $log->lwrite('no domain given');
  die('no pod domain given');
}
David Morley's avatar
David Morley committed
11

David Morley's avatar
David Morley committed
12 13
$_email            = $_GET['email'] ?? '';
$_podmin_statement = $_GET['podmin_statement'] ?? '';
dmorley's avatar
dmorley committed
14
$_podmin_notify    = $_GET['podmin_notify'] ?? 0;
David Morley's avatar
David Morley committed
15

David Morley's avatar
David Morley committed
16 17 18
$_domain = strtolower($_domain);
if (!filter_var(gethostbyname($_domain), FILTER_VALIDATE_IP)) {
  die('Could not validate the domain name, be sure to enter it as "domain.com" (no caps, no slashes, no extras)');
19
}
20

dmorley's avatar
cleanup  
dmorley committed
21
$dbh = pg_connect("dbname=$pgdb user=$pguser password=$pgpass");
22 23
$dbh || die('Error in connection: ' . pg_last_error());

David Morley's avatar
David Morley committed
24
$sql    = 'SELECT domain, stats_apikey, publickey, email FROM pods';
dmorley's avatar
cleanup  
dmorley committed
25
$result = pg_query($dbh, $sql);
26 27
$result || die('Error in SQL query: ' . pg_last_error());

dmorley's avatar
cleanup  
dmorley committed
28
while ($row = pg_fetch_array($result)) {
David Morley's avatar
David Morley committed
29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48
  if ($row['domain'] === $_domain ) {
    if ($row['email']) {
      $log->lwrite('domain already exists and is registered to an owner' . $_domain);
      die('domain already exists and is registered to an owner, use the edit function to modify');
    }

    $digtxt = exec(escapeshellcmd('dig ' . $_domain . ' TXT +short'));
    if (strpos($digtxt, $row['publickey']) !== false) {
      echo 'domain validated, you can now add details '; 
      $uuid     = md5(uniqid($_domain, true));
      $expire   = time() + 2700;
      $sql      = 'UPDATE pods SET token = $1, tokenexpire = $2 WHERE domain = $3';
      $result   = pg_query_params($dbh, $sql, [$uuid, date('Y-m-d H:i:s', $expire), $_domain]);
      $result   || die('Error in SQL query: ' . pg_last_error());
      
      echo <<<EOF
      <form action="edit.php" method="get">
      <input type="hidden" name="domain" value="{$_domain}">
      <input type="hidden" name="token" value="{$uuid}">
      <label>Email <input type="text" size="20" name="email"></label><br>
David Morley's avatar
David Morley committed
49
      <label>Podmin Statement (You can include links to your terms and policies and information about your pod you wish to share with users.) <textarea cols="100" rows="7" name="podmin_statement"></textarea></label><br>
David Morley's avatar
David Morley committed
50 51 52 53 54 55 56 57 58 59
      <label>Weight <input type="text" size="2" name="weight"> This lets you weight your pod lower on the list if you have too much traffic coming in, 10 is the norm use lower to move down the list.</label><br>
      <input type="submit" name="action" value="save">
      </form>
EOF;
      
      die;
    } else {
      $log->lwrite('domain already exists and can be registered' . $_domain);
      die('domain already exists, you can claim the domain by adding a DNS TXT record that states<br><b> ' . $_domain . ' IN TXT "' . $row['publickey'] . '"</b>');
    }
dmorley's avatar
cleanup  
dmorley committed
60
  }
61 62
}

dmorley's avatar
cleanup  
dmorley committed
63
$chss = curl_init();
64
curl_setopt($chss, CURLOPT_URL, 'https://' . $_domain . '/nodeinfo/1.0');
dmorley's avatar
cleanup  
dmorley committed
65 66 67 68 69 70 71
curl_setopt($chss, CURLOPT_POST, 0);
curl_setopt($chss, CURLOPT_HEADER, 0);
curl_setopt($chss, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt($chss, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($chss, CURLOPT_NOBODY, 0);
$outputssl = curl_exec($chss);
curl_close($chss);
72

dmorley's avatar
dmorley committed
73
if (stristr($outputssl, 'openRegistrations')) {
74
  $log->lwrite('Your pod has ssl and is valid ' . $_domain);
75
  echo 'Your pod has ssl and is valid<br>';
dmorley's avatar
fixes  
dmorley committed
76

David Morley's avatar
David Morley committed
77
  $publickey = md5(uniqid($domain, true));
dmorley's avatar
dmorley committed
78
  $sql    = 'INSERT INTO pods (domain, email, podmin_statement, podmin_notify, publickey) VALUES ($1, $2, $3, $4, $5)';
79
  $result = pg_query_params($dbh, $sql, [$_domain, $_email, $_podmin_statement, $_podmin_notify, $publickey]);
80 81
  $result || die('Error in SQL query: ' . pg_last_error());

dmorley's avatar
dmorley committed
82 83 84 85
  if ($_email) {
    $to      = $adminemail;
    $subject = 'New pod added to ' . $_SERVER['HTTP_HOST'];
    $headers = ['From: ' . $_email, 'Reply-To: ' . $_email, 'Cc: ' . $_email];
86

dmorley's avatar
dmorley committed
87 88 89 90 91 92 93
    $message_lines = [
      'https://' . $_SERVER['HTTP_HOST'],
      'Pod: https://' . $_SERVER['HTTP_HOST'] . '/db/pull.php?debug=1&domain=' . $_domain,
      '',
      'Your pod will not show up right away, as it needs to pass a few checks first.',
      'Give it a few hours!',
    ];
94

dmorley's avatar
dmorley committed
95 96 97
    @mail($to, $subject, implode("\r\n", $message_lines), implode("\r\n", $headers));
  }
  
98
  echo 'Data successfully inserted! Your pod will be reviewed and live on the list in a few hours!';
99

100
} else {
dmorley's avatar
dmorley committed
101 102
  $log->lwrite('Could not validate your pod, check your setup! ' . $_domain);
  echo 'Could not validate your pod, check your setup!<br>Take a look at <a href="https://' . $_domain . '/nodeinfo/1.0">your /nodeinfo</a>';
103
}
dmorley's avatar
dmorley committed
104
$log->lclose();