| | |
| | | <?php |
| | | |
| | | /* |
| | | Copyright (c) 2007, Till Brehm, projektfarm Gmbh |
| | | Copyright (c) 2007 - 2009, Till Brehm, projektfarm Gmbh |
| | | All rights reserved. |
| | | |
| | | Redistribution and use in source and binary forms, with or without modification, |
| | |
| | | $this->delete($event_name,$data); |
| | | |
| | | // Get the new config file path |
| | | $config_file_path = escapeshellcmd($this->getmail_config_dir.'/'.$data["new"]["source_server"].'_'.$data["new"]["source_username"].'.conf'); |
| | | $config_file_path = escapeshellcmd($this->getmail_config_dir.'/'.$this->_clean_path($data["new"]["source_server"]).'_'.$this->_clean_path($data["new"]["source_username"]).'.conf'); |
| | | if(stristr($config_file_path, "..") or stristr($config_file_path, "|") or stristr($config_file_path,";") or stristr($config_file_path,'$')) { |
| | | $app->log("Possibly faked path for getmail config file: '$config_file_path'. File is not written.",LOGLEVEL_ERROR); |
| | | return false; |
| | |
| | | } else { |
| | | $tpl = str_replace('{DELETE}','0',$tpl); |
| | | } |
| | | |
| | | |
| | | if($data["new"]["read_all"] == 'y') { |
| | | $tpl = str_replace('{READ_ALL}', '1', $tpl); |
| | | } else { |
| | | $tpl = str_replace('{READ_ALL}', '0', $tpl); |
| | | } |
| | | |
| | | // Set the data retriever |
| | | if($data["new"]["type"] == 'pop3') { |
| | | $tpl = str_replace('{TYPE}','SimplePOP3Retriever',$tpl); |
| | | } elseif ($data["new"]["type"] == 'imap') { |
| | | $tpl = str_replace('{TYPE}','SimpleIMAPRetriever',$tpl); |
| | | } elseif ($data["new"]["type"] == 'pop3ssl') { |
| | | $tpl = str_replace('{TYPE}','SimplePOP3SSLRetriever',$tpl); |
| | | } elseif ($data["new"]["type"] == 'imapssl') { |
| | | $tpl = str_replace('{TYPE}','SimpleIMAPSSLRetriever',$tpl); |
| | | } |
| | | |
| | | // Set server, username, password and destination. |
| | |
| | | // Write the config file. |
| | | file_put_contents($config_file_path,$tpl); |
| | | $app->log("Writing Getmail config file: $config_file_path",LOGLEVEL_DEBUG); |
| | | exec("chmod 400 $config_file_path"); |
| | | exec("chown getmail $config_file_path"); |
| | | chmod($config_file_path, 0400); |
| | | chown($config_file_path, 'getmail'); |
| | | unset($tpl); |
| | | unset($config_file_path); |
| | | |
| | |
| | | $getmail_config = $app->getconf->get_server_config($conf["server_id"], 'getmail'); |
| | | $this->getmail_config_dir = $getmail_config["getmail_config_dir"]; |
| | | |
| | | $config_file_path = escapeshellcmd($this->getmail_config_dir.'/'.$data["old"]["source_server"].'_'.$data["old"]["source_username"].'.conf'); |
| | | $config_file_path = escapeshellcmd($this->getmail_config_dir.'/'.$this->_clean_path($data["old"]["source_server"]).'_'.$this->_clean_path($data["old"]["source_username"]).'.conf'); |
| | | if(stristr($config_file_path,"..") || stristr($config_file_path,"|") || stristr($config_file_path,";") || stristr($config_file_path,'$')) { |
| | | $app->log("Possibly faked path for getmail config file: '$config_file_path'. File is not written.",LOGLEVEL_ERROR); |
| | | return false; |
| | | } |
| | | if(is_file($config_file_path)) { |
| | | unlink($config_file_path); |
| | | $app->log("Deleting file: '$config_file_path'.",LOGLEVEL_DEBUG); |
| | | } else { |
| | | $app->log("Nothing to delete: '$config_file_path'.",LOGLEVEL_DEBUG); |
| | | } |
| | | if(is_file($config_file_path)) unlink($config_file_path); |
| | | } |
| | | |
| | | function _clean_path($input) { |
| | | return preg_replace('/[^A-Za-z0-9\-_]/', '_', $input); |
| | | } |
| | | |
| | | |
| | | } // end class |
| | | |
| | | ?> |
| | | ?> |