r1257 + fixed annoying double-slash in generated URLs (hopefully)
[racktables] / inc / init.php
1 <?php
2 /*
3 *
4 * This file performs RackTables initialisation. After you include it
5 * from 1st-level page, don't forget to call authorize(). This is done
6 * to allow reloading of pageno and tabno variables. pageno and tabno
7 * together form security context.
8 *
9 */
10
11 $root = (empty($_SERVER['HTTPS'])?'http':'https').
12 '://'.
13 (isset($_SERVER['HTTP_HOST'])?$_SERVER['HTTP_HOST']:($_SERVER['SERVER_NAME'].($_SERVER['SERVER_PORT']=='80'?'':$_SERVER['SERVER_PORT']))).
14 dirname($_SERVER['PHP_SELF']);
15 if (substr ($root, -1) != '/')
16 $root .= '/';
17
18 // This is the first thing we need to do.
19 require_once 'inc/config.php';
20
21 // What we need first is database and interface functions.
22 require_once 'inc/interface.php';
23 require_once 'inc/functions.php';
24 require_once 'inc/database.php';
25 if (file_exists ('inc/secret.php'))
26 require_once 'inc/secret.php';
27 else
28 {
29 showError
30 (
31 "Database connection parameters are read from inc/secret.php file, " .
32 "which cannot be found.\nCopy provided inc/secret-sample.php to " .
33 "inc/secret.php and modify to your setup.\n\nThen reload the page."
34 );
35 die;
36 }
37
38 // Now try to connect...
39 try
40 {
41 $dbxlink = new PDO ($pdo_dsn, $db_username, $db_password);
42 }
43 catch (PDOException $e)
44 {
45 showError ("Database connection failed:\n\n" . $e->getMessage());
46 die();
47 }
48
49 // Escape any globals before we ever try to use them.
50 foreach ($_REQUEST as $key => $value)
51 if (gettype ($value) == 'string')
52 $_REQUEST[$key] = escapeString ($value);
53 if (isset ($_SERVER['PHP_AUTH_USER']))
54 $_SERVER['PHP_AUTH_USER'] = escapeString ($_SERVER['PHP_AUTH_USER']);
55 if (isset ($_SERVER['PHP_AUTH_PW']))
56 $_SERVER['PHP_AUTH_PW'] = escapeString ($_SERVER['PHP_AUTH_PW']);
57
58 $dbver = getDatabaseVersion();
59 if ($dbver != CODE_VERSION)
60 {
61 echo '<p align=justify>This Racktables installation seems to be ' .
62 'just upgraded to version ' . CODE_VERSION . ', while the '.
63 'database is still of version ' . $dbver . '. No user will be ' .
64 'either authenticated or shown any page until the upgrade is ' .
65 "finished. Follow <a href='${root}upgrade.php'>this link</a> and " .
66 'authenticate as administrator to finish the upgrade.</p>';
67 die;
68 }
69
70 $configCache = loadConfigCache();
71 if (!count ($configCache))
72 {
73 showError ('Failed to load configuration from the database.');
74 die();
75 }
76
77 // Now init authentication.
78
79 require_once 'inc/auth.php';
80 // Load access database once.
81 $accounts = getUserAccounts();
82 $perms = getUserPermissions();
83 if ($accounts === NULL or $perms === NULL)
84 {
85 showError ('Failed to initialize access database.');
86 die();
87 }
88
89 authenticate();
90
91 // Authentication passed.
92 // Note that we don't perform autorization here, so each 1st level page
93 // has to do it in its way, e.g. to call authorize().
94
95
96
97 $remote_username = $_SERVER['PHP_AUTH_USER'];
98 $pageno = (isset ($_REQUEST['page'])) ? $_REQUEST['page'] : 'index';
99 $tabno = (isset ($_REQUEST['tab'])) ? $_REQUEST['tab'] : 'default';
100
101 require_once 'inc/navigation.php';
102 require_once 'inc/pagetitles.php';
103 require_once 'inc/pagehandlers.php';
104 require_once 'inc/ophandlers.php';
105 require_once 'inc/triggers.php';
106 require_once 'inc/gateways.php';
107 require_once 'inc/help.php';
108
109 ?>