r2154 - don't escape user password
[racktables] / inc / init.php
CommitLineData
b325120a 1<?php
e673ee24
DO
2/*
3*
4* This file performs RackTables initialisation. After you include it
da958e52 5* from 1st-level page, don't forget to call fixContext(). This is done
e673ee24 6* to allow reloading of pageno and tabno variables. pageno and tabno
c3a8284b
DO
7* together participate in forming security context by generating
8* related autotags.
e673ee24
DO
9*
10*/
11
12$root = (empty($_SERVER['HTTPS'])?'http':'https').
13 '://'.
14 (isset($_SERVER['HTTP_HOST'])?$_SERVER['HTTP_HOST']:($_SERVER['SERVER_NAME'].($_SERVER['SERVER_PORT']=='80'?'':$_SERVER['SERVER_PORT']))).
9c6e7a97
DO
15 dirname($_SERVER['PHP_SELF']);
16if (substr ($root, -1) != '/')
17 $root .= '/';
e673ee24
DO
18
19// This is the first thing we need to do.
20require_once 'inc/config.php';
21
22// What we need first is database and interface functions.
23require_once 'inc/interface.php';
24require_once 'inc/functions.php';
25require_once 'inc/database.php';
26if (file_exists ('inc/secret.php'))
27 require_once 'inc/secret.php';
28else
29{
30 showError
31 (
32 "Database connection parameters are read from inc/secret.php file, " .
e6093686 33 "which cannot be found.\nYou probably need to complete the installation " .
b0348307
DO
34 "procedure by following <a href='${root}install.php'>this link</a>.",
35 __FILE__
e673ee24
DO
36 );
37 die;
38}
39
40// Now try to connect...
41try
42{
43 $dbxlink = new PDO ($pdo_dsn, $db_username, $db_password);
44}
45catch (PDOException $e)
46{
b0348307 47 showError ("Database connection failed:\n\n" . $e->getMessage(), __FILE__);
e673ee24
DO
48 die();
49}
50
4d55392a
DO
51$dbxlink->exec ("set names 'utf8'");
52
b8d1ab66
DO
53if (get_magic_quotes_gpc())
54 foreach ($_REQUEST as $key => $value)
f4d511df
DO
55 if (gettype ($value) == 'string')
56 $_REQUEST[$key] = stripslashes ($value);
b8d1ab66
DO
57
58if (!set_magic_quotes_runtime (0))
59{
b0348307 60 showError ('Failed to turn magic quotes off', __FILE__);
b8d1ab66
DO
61 die;
62}
6bae5fbb 63
e673ee24
DO
64// Escape any globals before we ever try to use them.
65foreach ($_REQUEST as $key => $value)
f4d511df 66 if (gettype ($value) == 'string')
b8d1ab66 67 $_REQUEST[$key] = escapeString ($value);
6bae5fbb 68
e673ee24
DO
69if (isset ($_SERVER['PHP_AUTH_USER']))
70 $_SERVER['PHP_AUTH_USER'] = escapeString ($_SERVER['PHP_AUTH_USER']);
e673ee24 71
fbbb74fb
DO
72$dbver = getDatabaseVersion();
73if ($dbver != CODE_VERSION)
74{
75 echo '<p align=justify>This Racktables installation seems to be ' .
76 'just upgraded to version ' . CODE_VERSION . ', while the '.
db914a6c 77 'database version is ' . $dbver . '. No user will be ' .
fbbb74fb
DO
78 'either authenticated or shown any page until the upgrade is ' .
79 "finished. Follow <a href='${root}upgrade.php'>this link</a> and " .
80 'authenticate as administrator to finish the upgrade.</p>';
81 die;
82}
83
26131670
DO
84if (!mb_internal_encoding ('UTF-8') or !mb_regex_encoding ('UTF-8'))
85{
b0348307 86 showError ('Failed setting multibyte string encoding to UTF-8', __FILE__);
26131670
DO
87 die;
88}
06f23fd4
DO
89$configCache = loadConfigCache();
90if (!count ($configCache))
91{
b0348307 92 showError ('Failed to load configuration from the database.', __FILE__);
06f23fd4
DO
93 die();
94}
95
bcd37231 96require_once 'inc/code.php';
4a6a28f1
DO
97$rackCodeCache = loadScript ('RackCodeCache');
98if ($rackCodeCache == NULL or empty ($rackCodeCache))
99{
100// $t1 = microtime (TRUE);
101 $rackCode = getRackCode (loadScript ('RackCode'));
102// $t2 = microtime (TRUE);
103// echo 'DEBUG: parsed RackCode tree from scratch in ' . ($t2 - $t1) . ' second(s)<br>';
104 saveScript ('RackCodeCache', base64_encode (serialize ($rackCode)));
105}
106else
107{
108// $t1 = microtime (TRUE);
109 $rackCode = unserialize (base64_decode ($rackCodeCache));
110// $t2 = microtime (TRUE);
111// echo 'DEBUG: loaded RackCode cache in ' . ($t2 - $t1) . ' second(s)<br>';
112 if ($rackCode === FALSE) // invalid cache
113 {
114 saveScript ('RackCodeCache', '');
115// $t1 = microtime (TRUE);
116 $rackCode = getRackCode (loadScript ('RackCode'));
117// $t2 = microtime (TRUE);
118// echo 'DEBUG: discarded RackCode cache and parsed tree from scratch in ' . ($t2 - $t1) . ' second(s)<br>';
119 }
120}
121
cf25e649
DO
122// Depending on the 'result' value the 'load' carries either the
123// parse tree or error message.
cf25e649
DO
124if ($rackCode['result'] != 'ACK')
125{
126 // FIXME: display a message with an option to reset RackCode text
b0348307 127 showError ('Could not load the RackCode due to error: ' . $rackCode['load'], __FILE__);
cf25e649
DO
128 die;
129}
130$rackCode = $rackCode['load'];
bcd37231 131
e673ee24
DO
132// Now init authentication.
133
134require_once 'inc/auth.php';
135// Load access database once.
136$accounts = getUserAccounts();
c35e997f 137if ($accounts === NULL)
e673ee24 138{
b0348307 139 showError ('Failed to initialize access database.', __FILE__);
e673ee24
DO
140 die();
141}
142
143authenticate();
144
145// Authentication passed.
146// Note that we don't perform autorization here, so each 1st level page
147// has to do it in its way, e.g. to call authorize().
148
149$remote_username = $_SERVER['PHP_AUTH_USER'];
150$pageno = (isset ($_REQUEST['page'])) ? $_REQUEST['page'] : 'index';
b0348307
DO
151// Special handling of tab number to substitute the "last" index where applicable.
152// Always show explicitly requested tab, substitute the last used name in case
153// it is awailable, fall back to the default one.
154if (isset ($_REQUEST['tab']))
155 $tabno = $_REQUEST['tab'];
156elseif (getConfigVar ('SHOW_LAST_TAB') == 'yes' and isset ($_COOKIE['RTLT-' . $pageno]))
157 $tabno = $_COOKIE['RTLT-' . $pageno];
158else
159 $tabno = 'default';
da958e52 160$op = (isset ($_REQUEST['op'])) ? $_REQUEST['op'] : '';
b0348307 161
20c901a7
DO
162// Order matters here.
163$taglist = getTagList();
164$tagtree = getTagTree();
e673ee24
DO
165
166require_once 'inc/navigation.php';
167require_once 'inc/pagetitles.php';
e673ee24 168require_once 'inc/ophandlers.php';
641fe9b0 169require_once 'inc/triggers.php';
d33645ff 170require_once 'inc/gateways.php';
3ec29bf4 171require_once 'inc/snmp.php';
e77d763c
DO
172if (file_exists ('inc/local.php'))
173 require_once 'inc/local.php';
e673ee24 174
da958e52
DO
175// These will be filled in by fixContext()
176$auto_tags = array();
2fb24351
DO
177$expl_tags = array();
178$impl_tags = array();
da958e52
DO
179// and this will remain constant
180$user_tags = loadUserTags ($accounts[$remote_username]['user_id']);
181$user_tags = array_merge ($user_tags, getImplicitTags ($user_tags), getUserAutoTags());
2fb24351 182
e673ee24 183?>