servnest/sftpgo-auth.php

48 lines
1.3 KiB
PHP
Raw Normal View History

2022-05-19 16:59:32 +02:00
<?php
const DEBUG = false;
!DEBUG or ob_start();
require 'init.php';
2022-05-19 16:59:32 +02:00
function deny($reason) {
!DEBUG or file_put_contents(ROOT_PATH . '/db/debug.txt', ob_get_contents() . $reason . LF);
2023-03-09 14:40:26 +01:00
http_response_code(403);
exit();
}
if (CONF['common']['services']['ht'] !== 'enabled')
deny('Service not enabled.');
2023-03-09 14:40:26 +01:00
$auth_data = json_decode(file_get_contents('php://input'), true, flags: JSON_THROW_ON_ERROR);
2022-05-19 16:59:32 +02:00
$username = hashUsername($auth_data['username']);
2022-11-26 21:45:48 +01:00
2023-03-09 14:40:26 +01:00
if (usernameExists($username) !== true)
deny('This username doesn\'t exist.');
2023-03-09 14:40:26 +01:00
2023-03-18 18:38:27 +01:00
if (!in_array('ht', explode(',', query('select', 'users', ['username' => $username], 'services')[0]), true))
deny('Service not enabled for this user.');
2023-03-18 18:38:27 +01:00
$id = query('select', 'users', ['username' => $username], 'id')[0];
2023-03-09 14:40:26 +01:00
if (checkPassword($id, $auth_data['password']) !== true)
deny('Wrong password.');
2023-03-09 14:40:26 +01:00
echo '
{
"status": 1,
"username": ' . json_encode($auth_data['username']) . ',
"home_dir": "' . CONF['ht']['ht_path'] . '/fs/' . $id . '",
2023-03-09 14:40:26 +01:00
"quota_size": ' . ((query('select', 'users', ['id' => $id], 'type')[0] === 'approved') ? CONF['ht']['user_quota_approved'] : CONF['ht']['user_quota_testing']) . ',
"permissions": {
"/": [
"*"
]
2022-06-28 22:08:34 +02:00
}
2022-05-19 16:59:32 +02:00
}
2023-03-09 14:40:26 +01:00
';
!DEBUG or file_put_contents(ROOT_PATH . '/db/debug.txt', ob_get_contents());
2023-03-09 14:40:26 +01:00
http_response_code(200);