From 9edea9976bd605071e0694a90d704266c0b7e0f9 Mon Sep 17 00:00:00 2001
From: Till Brehm <tbrehm@ispconfig.org>
Date: Thu, 14 Aug 2014 11:30:03 -0400
Subject: [PATCH] - Added warning in the interface when a path for a shelluser is set that is outside of the website docroot. - Added security settings feature to allow the root user of a server to control most aspects of whet the admin user of the controlpanel is allowed to do in system settings. This is especially useful for managed severs where the ispconfig admin user and the root user of the server are different persons.

---
 interface/web/admin/lib/module.conf.php |  259 +++++++++++++++++++++------------------------------
 1 files changed, 109 insertions(+), 150 deletions(-)

diff --git a/interface/web/admin/lib/module.conf.php b/interface/web/admin/lib/module.conf.php
index 20fb322..7f4d19d 100644
--- a/interface/web/admin/lib/module.conf.php
+++ b/interface/web/admin/lib/module.conf.php
@@ -2,208 +2,167 @@
 
 global $conf;
 
-$module['name'] 		= 'admin';
-$module['title'] 		= 'top_menu_system';
-$module['template'] 	= 'module.tpl.htm';
-$module['startpage'] 	= 'admin/server_list.php';
+$module['name']  = 'admin';
+$module['title']  = 'top_menu_system';
+$module['template']  = 'module.tpl.htm';
+$module['startpage']  = 'admin/server_list.php';
 $module['tab_width']    = '60';
 
 
-$items[] = array( 'title' 	=> 'Add user',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/users_edit.php',
-				  'html_id'=> 'user_add');
+$items[] = array(   'title'     => 'CP Users',
+	'target'  => 'content',
+	'link' => 'admin/users_list.php',
+	'html_id'   => 'user_list');
 
-$items[] = array( 'title' 	=> 'Edit user',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/users_list.php',
-				  'html_id'=> 'user_list');
+$items[] = array(   'title'  => 'Remote Users',
+	'target'  => 'content',
+	'link' => 'admin/remote_user_list.php',
+	'html_id'   => 'remote_user_list');
 
-
-$module['nav'][] = array(	'title'	=> 'CP Users',
-							'open' 	=> 1,
-							'items'	=> $items);
-
+$module['nav'][] = array(   'title' => 'User Management',
+	'open'  => 1,
+	'items' => $items);
 
 // cleanup
 unset($items);
-/*
-$items[] = array( 'title' 	=> 'Add group',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/groups_edit.php',
-				  'html_id'=> 'group_add');
 
-$items[] = array( 'title' 	=> 'Edit group',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/groups_list.php',
-				  'html_id'=> 'group_list');
+$items[] = array(   'title'  => 'Server Services',
+	'target'  => 'content',
+	'link' => 'admin/server_list.php',
+	'html_id'   => 'server_list');
+
+$items[] = array(   'title'  => 'Server Config',
+	'target'  => 'content',
+	'link' => 'admin/server_config_list.php',
+	'html_id'   => 'server_config_list');
+
+$items[] = array(   'title'  => 'Server IP addresses',
+	'target'  => 'content',
+	'link' => 'admin/server_ip_list.php',
+	'html_id'   => 'server_ip_list');
 
 
-$module['nav'][] = array(	'title'	=> 'Groups',
-							'open' 	=> 1,
-							'items'	=> $items);
 
+$items[] = array(   'title'  => 'Additional PHP Versions',
+	'target'  => 'content',
+	'link' => 'admin/server_php_list.php',
+	'html_id'   => 'server_php_list');
 
-// cleanup
-unset($items);
-*/
-/*
-$items[] = array( 'title' 	=> 'Add server',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/server_edit.php',
-				  'html_id'=> 'server_add');
-*/
-$items[] = array( 'title' 	=> 'Server Services',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/server_list.php',
-				  'html_id'=> 'server_list');
+$items[] = array(   'title'  => 'Directive Snippets',
+	'target'  => 'content',
+	'link' => 'admin/directive_snippets_list.php',
+	'html_id'   => 'directive_snippets_list');
 
-$items[] = array( 'title' 	=> 'Server Config',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/server_config_list.php',
-				  'html_id'=> 'server_config_list');
+$items[] = array(   'title'  => 'Firewall',
+	'target'  => 'content',
+	'link' => 'admin/firewall_list.php',
+	'html_id'   => 'firewall_list');
 
-/*
-$items[] = array( 'title' 	=> 'Add Server IP',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/server_ip_edit.php',
-				  'html_id'=> 'server_ip_edit');
-*/
-$items[] = array( 'title' 	=> 'Edit Server IP',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/server_ip_list.php',
-				  'html_id'=> 'server_ip_list');
-
-
-$items[] = array( 'title' 	=> 'Interface Config',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/system_config_edit.php?id=1');
-
-$module['nav'][] = array(	'title'	=> 'System',
-							'open' 	=> 1,
-							'items'	=> $items);
-// cleanup
-unset($items);
 /*
 $items[] = array( 'title' 	=> 'Firewall IPTables',
 				  'target' 	=> 'content',
 				  'link'	=> 'admin/iptables_list.php');
 
-$items[] = array( 'title' 	=> 'Firewall',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/firewall_list.php',
-				  'html_id'=> 'firewall_list');*/
-                  
-$items[] = array( 'title' 	=> 'Basic',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/firewall_list.php');				  
-/*
 $items[] = array( 'title' 	=> 'Packet Filter',
 				  'target' 	=> 'content',
-				  'link'	=> 'admin/firewall_filter_list.php');				  
+				  'link'	=> 'admin/firewall_filter_list.php');
 
 $items[] = array( 'title' 	=> 'Port Forward',
 				  'target' 	=> 'content',
-				  'link'	=> 'admin/firewall_forward_list.php');				  
+				  'link'	=> 'admin/firewall_forward_list.php');
 */
-$module['nav'][] = array(	'title'	=> 'Firewall',
-							'open' 	=> "1",
-							'items'	=> $items);
+
+$module['nav'][] = array(   'title'     => 'System',
+	'open'  => 1,
+	'items' => $items);
+// cleanup
+unset($items);
+
+$items[] = array(   'title'  => 'Interface Config',
+	'target'  => 'content',
+	'link' => 'admin/system_config_edit.php?id=1',
+	'html_id'   => 'interface_config');
+
+$module['nav'][] = array(   'title'     => 'Interface',
+	'open'      => "1",
+	'items'     => $items);
 
 
 // cleanup
 unset($items);
 
 
-$items[] = array( 'title' 	=> 'Repositories',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/software_repo_list.php',
-				  'html_id'=> 'software_repo_list');
+$items[] = array(   'title'  => 'Repositories',
+	'target'  => 'content',
+	'link' => 'admin/software_repo_list.php',
+	'html_id'   => 'software_repo_list');
 
-$items[] = array( 'title' 	=> 'Packages',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/software_package_list.php',
-				  'html_id'=> 'software_package_list');
+$items[] = array(   'title'  => 'Packages',
+	'target'  => 'content',
+	'link' => 'admin/software_package_list.php',
+	'html_id'   => 'software_package_list');
 
-$items[] = array( 'title' 	=> 'Updates',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/software_update_list.php',
-				  'html_id'=> 'software_update_list');
+$items[] = array(   'title'  => 'Updates',
+	'target'  => 'content',
+	'link' => 'admin/software_update_list.php',
+	'html_id'   => 'software_update_list');
 
-$module['nav'][] = array(	'title'	=> 'Software',
-							'open' 	=> 1,
-							'items'	=> $items);
+$module['nav'][] = array(   'title'     => 'Software',
+	'open'  => 1,
+	'items' => $items);
 
 
 // cleanup
 unset($items);
 
-$items[] = array( 'title' 	=> 'Languages',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/language_list.php',
-				  'html_id'=> 'language_list');
+$items[] = array(   'title'  => 'Languages',
+	'target'  => 'content',
+	'link' => 'admin/language_list.php',
+	'html_id'   => 'language_list');
 
-$items[] = array( 'title' 	=> 'New Language',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/language_add.php',
-				  'html_id'=> 'language_add');
+$items[] = array(   'title'  => 'New Language',
+	'target'  => 'content',
+	'link' => 'admin/language_add.php',
+	'html_id'   => 'language_add');
 
-$items[] = array( 'title' 	=> 'Merge',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/language_complete.php',
-				  'html_id'=> 'language_complete');
+$items[] = array(   'title'  => 'Merge',
+	'target'  => 'content',
+	'link' => 'admin/language_complete.php',
+	'html_id'   => 'language_complete');
 
-$items[] = array( 'title' 	=> 'Export',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/language_export.php',
-				  'html_id'=> 'language_export');
+$items[] = array(   'title'  => 'Export',
+	'target'  => 'content',
+	'link' => 'admin/language_export.php',
+	'html_id'   => 'language_export');
 
-$items[] = array( 'title' 	=> 'Import',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/language_import.php',
-				  'html_id'=> 'language_import');
+$items[] = array(   'title'  => 'Import',
+	'target'  => 'content',
+	'link' => 'admin/language_import.php',
+	'html_id'   => 'language_import');
 
-$module['nav'][] = array(	'title'	=> 'Language Editor',
-							'open' 	=> 1,
-							'items'	=> $items);
+$module['nav'][] = array(   'title'     => 'Language Editor',
+	'open'      => 1,
+	'items'     => $items);
 
 
 // cleanup
 unset($items);
 
-$items[] = array( 'title' 	=> 'Add user',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/remote_user_edit.php',
-				  'html_id'=> 'remote_user_add');
 
-$items[] = array( 'title' 	=> 'Edit user',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/remote_user_list.php',
-				  'html_id'=> 'remote_user_list');
+$items[] = array(   'title'  => 'Do OS-Update',
+	'target'  => 'content',
+	'link' => 'admin/remote_action_osupdate.php',
+	'html_id'   => 'osupdate');
 
-
-$module['nav'][] = array(	'title'	=> 'Remote Users',
-							'open' 	=> 1,
-							'items'	=> $items);
-
-// cleanup
-unset($items);
-
-$items[] = array( 'title' 	=> 'Do OS-Update',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/remote_action_osupdate.php',
-				  'html_id'=> 'osupdate');
-/*
 // ISPConfig interface update has been removed. Please use ispconfig_update.sh on the shell instead.
-$items[] = array( 'title' 	=> 'Do ISPConfig-Update',
-				  'target' 	=> 'content',
-				  'link'	=> 'admin/remote_action_ispcupdate.php',
-				  'html_id'=> 'ispcupdate');
-*/
+$items[] = array(   'title'  => 'Do ISPConfig-Update',
+	'target'  => 'content',
+	'link' => 'admin/remote_action_ispcupdate.php',
+	'html_id'   => 'ispcupdate');
 
-$module['nav'][] = array(	'title'	=> 'Remote Actions',
-							'open' 	=> 1,
-							'items'	=> $items);
+$module['nav'][] = array(   'title' => 'Remote Actions',
+	'open'  => 1,
+	'items' => $items);
 
 
 // Getting the admin options from other modules
@@ -212,7 +171,7 @@
 	foreach($modules as $mt) {
 		if(is_file($mt.'/lib/admin.conf.php')) {
 			$options = array();
-			include_once(ISPC_WEB_PATH."/$mt/lib/admin.conf.php");
+			include_once ISPC_WEB_PATH."/$mt/lib/admin.conf.php";
 			if(is_array($options)) {
 				foreach($options as $opt) {
 					$module['nav'][] = $opt;
@@ -222,4 +181,4 @@
 	}
 }
 
-?>
\ No newline at end of file
+?>

--
Gitblit v1.9.1