]> git.ipfire.org Git - ipfire-2.x.git/blob - config/cfgroot/header.pl
suricata: Change midstream policy to "pass-flow"
[ipfire-2.x.git] / config / cfgroot / header.pl
1 # SmoothWall CGIs
2 #
3 # This code is distributed under the terms of the GPL
4 #
5 # (c) The SmoothWall Team
6 # Copyright (C) 2002 Alex Hudson - getcgihash() rewrite
7 # Copyright (C) 2002 Bob Grant <bob@cache.ucr.edu> - validmac()
8 # Copyright (c) 2002/04/13 Steve Bootes - add alias section, helper functions
9 # Copyright (c) 2002/08/23 Mark Wormgoor <mark@wormgoor.com> validfqdn()
10 # Copyright (c) 2003/09/11 Darren Critchley <darrenc@telus.net> srtarray()
11 #
12 package Header;
13
14 use CGI();
15 use File::Basename;
16 use HTML::Entities();
17 use Socket;
18 use Time::Local;
19
20 $|=1; # line buffering
21
22 $Header::revision = 'final';
23 $Header::swroot = '/var/ipfire';
24 $Header::graphdir='/srv/web/ipfire/html/graphs';
25 $Header::pagecolour = '#ffffff';
26 #$Header::tablecolour = '#a0a0a0';
27 $Header::tablecolour = '#FFFFFF';
28 $Header::bigboxcolour = '#F6F4F4';
29 $Header::boxcolour = '#EAE9EE';
30 $Header::bordercolour = '#000000';
31 $Header::table1colour = '#E0E0E0';
32 $Header::table2colour = '#F0F0F0';
33 $Header::colourred = '#993333';
34 $Header::colourorange = '#FF9933';
35 $Header::colouryellow = '#FFFF00';
36 $Header::colourgreen = '#339933';
37 $Header::colourblue = '#333399';
38 $Header::colourovpn = '#339999';
39 $Header::colourfw = '#000000';
40 $Header::colourvpn = '#990099';
41 $Header::colourerr = '#FF0000';
42 $Header::viewsize = 150;
43 $Header::errormessage = '';
44 my %menuhash = ();
45 my $menu = \%menuhash;
46 %settings = ();
47 %ethsettings = ();
48 %pppsettings = ();
49 @URI = ();
50
51 ### Make sure this is an SSL request
52 if ($ENV{'SERVER_ADDR'} && $ENV{'HTTPS'} ne 'on') {
53 print "Status: 302 Moved\r\n";
54 print "Location: https://$ENV{'SERVER_ADDR'}:444/$ENV{'PATH_INFO'}\r\n\r\n";
55 exit 0;
56 }
57
58 ### Initialize environment
59 &General::readhash("${swroot}/main/settings", \%settings);
60 &General::readhash("${swroot}/ethernet/settings", \%ethsettings);
61 &General::readhash("${swroot}/ppp/settings", \%pppsettings);
62 $hostname = $settings{'HOSTNAME'};
63 $hostnameintitle = 0;
64
65 ### Initialize language
66 require "${swroot}/lang.pl";
67 $language = &Lang::FindWebLanguage($settings{"LANGUAGE"});
68
69 ### Read English Files
70 if ( -d "/var/ipfire/langs/en/" ) {
71 opendir(DIR, "/var/ipfire/langs/en/");
72 @names = readdir(DIR) or die "Cannot Read Directory: $!\n";
73 foreach $name(@names) {
74 next if ($name eq ".");
75 next if ($name eq "..");
76 next if (!($name =~ /\.pl$/));
77 require "${swroot}/langs/en/${name}";
78 };
79 };
80
81
82 ### Enable Language Files
83 if ( -d "/var/ipfire/langs/${language}/" ) {
84 opendir(DIR, "/var/ipfire/langs/${language}/");
85 @names = readdir(DIR) or die "Cannot Read Directory: $!\n";
86 foreach $name(@names) {
87 next if ($name eq ".");
88 next if ($name eq "..");
89 next if (!($name =~ /\.pl$/));
90 require "${swroot}/langs/${language}/${name}";
91 };
92 };
93
94
95 require "${swroot}/langs/en.pl";
96 require "${swroot}/langs/${language}.pl";
97 eval `/bin/cat /srv/web/ipfire/html/themes/ipfire/include/functions.pl`;
98
99 sub green_used() {
100 if ($ethsettings{'GREEN_DEV'} && $ethsettings{'GREEN_DEV'} ne "") {
101 return 1;
102 }
103
104 return 0;
105 }
106
107 sub orange_used () {
108 if ($ethsettings{'CONFIG_TYPE'} =~ /^[24]$/) {
109 return 1;
110 }
111 return 0;
112 }
113
114 sub blue_used () {
115 if ($ethsettings{'CONFIG_TYPE'} =~ /^[34]$/) {
116 return 1;
117 }
118 return 0;
119 }
120
121 sub is_modem {
122 if ($ethsettings{'CONFIG_TYPE'} =~ /^[0]$/) {
123 return 1;
124 }
125 return 0;
126 }
127
128 ### Initialize menu
129 sub genmenu {
130
131 my %subsystemhash = ();
132 my $subsystem = \%subsystemhash;
133
134 my %substatushash = ();
135 my $substatus = \%substatushash;
136
137 my %subnetworkhash = ();
138 my $subnetwork = \%subnetworkhash;
139
140 my %subserviceshash = ();
141 my $subservices = \%subserviceshash;
142
143 my %subfirewallhash = ();
144 my $subfirewall = \%subfirewallhash;
145
146 my %subipfirehash = ();
147 my $subipfire = \%subipfirehash;
148
149 my %sublogshash = ();
150 my $sublogs = \%sublogshash;
151
152 if ( -e "/var/ipfire/main/gpl_accepted") {
153
154 eval `/bin/cat /var/ipfire/menu.d/*.menu`;
155 eval `/bin/cat /var/ipfire/menu.d/*.main`;
156
157 if (! blue_used()) {
158 $menu->{'05.firewall'}{'subMenu'}->{'60.wireless'}{'enabled'} = 0;
159 }
160 if ( $ethsettings{'CONFIG_TYPE'} =~ /^(1|2|3|4)$/ && $ethsettings{'RED_TYPE'} eq 'STATIC' ) {
161 $menu->{'03.network'}{'subMenu'}->{'70.aliases'}{'enabled'} = 1;
162 }
163
164 if (&General::RedIsWireless()) {
165 $menu->{'01.system'}{'subMenu'}->{'21.wlan'}{'enabled'} = 1;
166 }
167
168 if ( $ethsettings{'RED_TYPE'} eq "PPPOE" && $pppsettings{'MONPORT'} ne "" ) {
169 $menu->{'02.status'}{'subMenu'}->{'74.modem-status'}{'enabled'} = 1;
170 }
171
172 # Disable the Dialup/PPPoE menu item when the RED interface is in IP mode
173 # (the "Network" module is loaded by general-functions.pl)
174 if(&Network::is_red_mode_ip()) {
175 $menu->{'01.system'}{'subMenu'}->{'20.dialup'}{'enabled'} = 0;
176 }
177
178 # Disbale unusable things in cloud environments
179 if (&General::running_in_cloud()) {
180 $menu->{'03.network'}{'subMenu'}->{'30.dhcp'}{'enabled'} = 0;
181 $menu->{'03.network'}{'subMenu'}->{'80.macadressmenu'}{'enabled'} = 0;
182 $menu->{'03.network'}{'subMenu'}->{'90.wakeonlan'}{'enabled'} = 0;
183 }
184
185 # Disable proxy when no GREEN is available
186 if (!&green_used()) {
187 $menu->{'03.network'}{'subMenu'}->{'20.proxy'}{'enabled'} = 0;
188 $menu->{'03.network'}{'subMenu'}->{'21.urlfilter'}{'enabled'} = 0;
189 $menu->{'03.network'}{'subMenu'}->{'22.updxlrator'}{'enabled'} = 0;
190 }
191 }
192 }
193
194 sub showhttpheaders
195 {
196 print "Cache-control: private\n";
197 print "Content-type: text/html; charset=UTF-8\n\n";
198 }
199
200 sub is_menu_visible($) {
201 my $link = shift;
202 $link =~ s#\?.*$##;
203 return (-e $ENV{'DOCUMENT_ROOT'}."/../$link");
204 }
205
206
207 sub getlink($) {
208 my $root = shift;
209 if (! $root->{'enabled'}) {
210 return '';
211 }
212 if ($root->{'uri'} !~ /^$/) {
213 my $vars = '';
214 if ($root->{'vars'} !~ /^$/) {
215 $vars = '?'. $root->{'vars'};
216 }
217 if (! is_menu_visible($root->{'uri'})) {
218 return '';
219 }
220 return $root->{'uri'}.$vars;
221 }
222 my $submenus = $root->{'subMenu'};
223 if (! $submenus) {
224 return '';
225 }
226 foreach my $item (sort keys %$submenus) {
227 my $link = getlink($submenus->{$item});
228 if ($link ne '') {
229 return $link;
230 }
231 }
232 return '';
233 }
234
235
236 sub compare_url($) {
237 my $conf = shift;
238
239 my $uri = $conf->{'uri'};
240 my $vars = $conf->{'vars'};
241 my $novars = $conf->{'novars'};
242
243 if ($uri eq '') {
244 return 0;
245 }
246 if ($uri ne $URI[0]) {
247 return 0;
248 }
249 if ($novars) {
250 if ($URI[1] !~ /^$/) {
251 return 0;
252 }
253 }
254 if (! $vars) {
255 return 1;
256 }
257 return ($URI[1] eq $vars);
258 }
259
260
261 sub gettitle($) {
262 my $root = shift;
263
264 if (! $root) {
265 return '';
266 }
267 foreach my $item (sort keys %$root) {
268 my $val = $root->{$item};
269 if (compare_url($val)) {
270 $val->{'selected'} = 1;
271 if ($val->{'title'} !~ /^$/) {
272 return $val->{'title'};
273 }
274 return 'EMPTY TITLE';
275 }
276
277 my $title = gettitle($val->{'subMenu'});
278 if ($title ne '') {
279 $val->{'selected'} = 1;
280 return $title;
281 }
282 }
283 return '';
284 }
285
286 sub getcgihash {
287 my ($hash, $params) = @_;
288 my $cgi = CGI->new ();
289 $hash->{'__CGI__'} = $cgi;
290 return if ($ENV{'REQUEST_METHOD'} ne 'POST');
291 if (!$params->{'wantfile'}) {
292 $CGI::DISABLE_UPLOADS = 1;
293 $CGI::POST_MAX = 1024 * 1024;
294 } else {
295 $CGI::POST_MAX = 10 * 1024 * 1024;
296 }
297
298 $cgi->referer() =~ m/^https?\:\/\/([^\/]+)/;
299 my $referer = $1;
300 $cgi->url() =~ m/^https?\:\/\/([^\/]+)/;
301 my $servername = $1;
302 return if ($referer ne $servername);
303
304 ### Modified for getting multi-vars, split by |
305 %temp = $cgi->Vars();
306 foreach my $key (keys %temp) {
307 $hash->{$key} = $temp{$key};
308 $hash->{$key} =~ s/\0/|/g;
309 $hash->{$key} =~ s/^\s*(.*?)\s*$/$1/;
310 }
311
312 if (($params->{'wantfile'})&&($params->{'filevar'})) {
313 $hash->{$params->{'filevar'}} = $cgi->upload
314 ($params->{'filevar'});
315 }
316 return;
317 }
318
319 sub escape($) {
320 my $s = shift;
321 return HTML::Entities::encode_entities($s);
322 }
323
324 sub cleanhtml {
325 my $outstring =$_[0];
326 $outstring =~ tr/,/ / if not defined $_[1] or $_[1] ne 'y';
327
328 return escape($outstring);
329 }
330
331 sub connectionstatus
332 {
333 my %pppsettings = ();
334 my %netsettings = ();
335 my $iface='';
336
337 $pppsettings{'PROFILENAME'} = 'None';
338 &General::readhash("${General::swroot}/ppp/settings", \%pppsettings);
339 &General::readhash("${General::swroot}/ethernet/settings", \%netsettings);
340
341 my $profileused='';
342 unless ( $netsettings{'RED_TYPE'} =~ /^(DHCP|STATIC)$/ ) {
343 $profileused="- $pppsettings{'PROFILENAME'}";
344 }
345
346 my ($timestr, $connstate);
347
348 my $connstate = "<span>$Lang::tr{'idle'} $profileused</span>";
349
350 if (-e "${General::swroot}/red/active") {
351 $timestr = &General::age("${General::swroot}/red/active");
352 $connstate = "<span>$Lang::tr{'connected'} - (<span>$timestr</span>) $profileused</span>";
353 } else {
354 if ((open(KEEPCONNECTED, "</var/ipfire/red/keepconnected") == false) && ($pppsettings{'RECONNECTION'} eq "persistent")) {
355 $connstate = "<span>$Lang::tr{'connection closed'} $profileused</span>";
356 } elsif (($pppsettings{'RECONNECTION'} eq "dialondemand") && ( -e "${General::swroot}/red/dial-on-demand")) {
357 $connstate = "<span>$Lang::tr{'dod waiting'} $profileused</span>";
358 } else {
359 $connstate = "<span>$Lang::tr{'connecting'} $profileused</span>" if (system("ps -ef | grep -q '[p]ppd'"));
360 }
361 }
362
363 return $connstate;
364 }
365
366 sub CheckSortOrder {
367 #Sorting of allocated leases
368 if ($ENV{'QUERY_STRING'} =~ /^IPADDR|^ETHER|^HOSTNAME|^ENDTIME/ ) {
369 my $newsort=$ENV{'QUERY_STRING'};
370 &General::readhash("${swroot}/dhcp/settings", \%dhcpsettings);
371 $act=$dhcpsettings{'SORT_LEASELIST'};
372 #Reverse actual ?
373 if ($act =~ $newsort) {
374 if ($act !~ 'Rev') {$Rev='Rev'};
375 $newsort.=$Rev
376 };
377
378 $dhcpsettings{'SORT_LEASELIST'}=$newsort;
379 &General::writehash("${swroot}/dhcp/settings", \%dhcpsettings);
380 $dhcpsettings{'ACTION'} = 'SORT'; # avoid the next test "First lauch"
381 }
382
383 }
384
385 sub PrintActualLeases
386 {
387 &openbox('100%', 'left', $tr{'current dynamic leases'});
388 print <<END
389 <table width='100%' class='tbl'>
390 <tr>
391 <th width='25%' align='center'><a href='$ENV{'SCRIPT_NAME'}?IPADDR'><b>$tr{'ip address'}</b></a></th>
392 <th width='25%' align='center'><a href='$ENV{'SCRIPT_NAME'}?ETHER'><b>$tr{'mac address'}</b></a></th>
393 <th width='20%' align='center'><a href='$ENV{'SCRIPT_NAME'}?HOSTNAME'><b>$tr{'hostname'}</b></a></th>
394 <th width='25%' align='center'><a href='$ENV{'SCRIPT_NAME'}?ENDTIME'><b>$tr{'lease expires'} (local time d/m/y)</b></a></th>
395 <th width='5%' align='center'><b>Add to fix leases</b></th>
396 </tr>
397 END
398 ;
399
400 open(LEASES,"/var/state/dhcp/dhcpd.leases") or die "Can't open dhcpd.leases";
401 while (my $line = <LEASES>) {
402 next if( $line =~ /^\s*#/ );
403 chomp($line);
404 @temp = split (' ', $line);
405
406 if ($line =~ /^\s*lease/) {
407 $ip = $temp[1];
408 #All field are not necessarily read. Clear everything
409 $endtime = 0;
410 $endtime_print = "";
411 $expired = 0;
412 $ether = "";
413 $hostname = "";
414 }
415
416 if ($line =~ /^\s*ends/) {
417 $line =~ /(\d+)\/(\d+)\/(\d+) (\d+):(\d+):(\d+)/;
418 $endtime = timegm($6, $5, $4, $3, $2 - 1, $1 - 1900);
419 ($sec, $min, $hour, $mday, $mon, $year, $wday, $yday, $dst) = localtime($endtime);
420 $endtime_print = sprintf ("%02d/%02d/%d %02d:%02d:%02d",$mday,$mon+1,$year+1900,$hour,$min,$sec);
421 $expired = $endtime < time();
422 }
423
424 if ($line =~ /^\s*hardware ethernet/) {
425 $ether = $temp[2];
426 $ether =~ s/;//g;
427 }
428
429 if ($line =~ /^\s*client-hostname/) {
430 $hostname = "$temp[1] $temp[2] $temp[3]";
431 $hostname =~ s/\"|[;\s]+?$//g; # remove quotes, trim semicolon and white space
432 }
433
434 if ($line eq "}") {
435 @record = ('IPADDR',$ip,'ENDTIME',$endtime,'ETHER',$ether,'HOSTNAME',$hostname,'endtime_print',$endtime_print,'expired',$expired);
436 $record = {}; # create a reference to empty hash
437 %{$record} = @record; # populate that hash with @record
438 $entries{$record->{'IPADDR'}} = $record; # add this to a hash of hashes
439 }
440 }
441 close(LEASES);
442
443 my $id = 0;
444 my $col = "";
445 my $divider_printed = 0;
446 foreach my $key (sort leasesort keys %entries) {
447 my $hostname = &cleanhtml($entries{$key}->{HOSTNAME},"y");
448 my $hostname_print = $hostname;
449 if($hostname_print eq "") { #print blank space if no hostname is found
450 $hostname_print = "&nbsp;&nbsp;&nbsp;";
451 }
452
453 # separate active and expired leases with a horizontal line
454 if(($entries{$key}->{expired}) && ($divider_printed == 0)) {
455 $divider_printed = 1;
456 if ($id % 2) {
457 print "<tr><td colspan='5' bgcolor='$table1colour'><hr size='1'></td></tr>\n";
458 } else {
459 print "<tr><td colspan='5' bgcolor='$table2colour'><hr size='1'></td></tr>\n";
460 }
461 $id++;
462 }
463
464 print "<form method='post' action='/cgi-bin/dhcp.cgi'><tr>\n";
465 if ($id % 2) {
466 $col="bgcolor='$table1colour'";
467 } else {
468 $col="bgcolor='$table2colour'";
469 }
470
471 if($entries{$key}->{expired}) {
472 print <<END
473 <td align='center' $col><input type='hidden' name='FIX_ADDR' value='$entries{$key}->{IPADDR}' /><strike><i>$entries{$key}->{IPADDR}</i></strike></td>
474 <td align='center' $col><input type='hidden' name='FIX_MAC' value='$entries{$key}->{ETHER}' /><strike><i>$entries{$key}->{ETHER}</i></strike></td>
475 <td align='center' $col><input type='hidden' name='FIX_REMARK' value='$hostname' /><strike><i>$hostname_print<i><strike></td>
476 <td align='center' $col><input type='hidden' name='FIX_ENABLED' value='on' /><strike><i>$entries{$key}->{endtime_print}</i></strike></td>
477 END
478 ;
479 } else {
480 print <<END
481 <td align='center' $col><input type='hidden' name='FIX_ADDR' value='$entries{$key}->{IPADDR}' />$entries{$key}->{IPADDR}</td>
482 <td align='center' $col><input type='hidden' name='FIX_MAC' value='$entries{$key}->{ETHER}' />$entries{$key}->{ETHER}</td>
483 <td align='center' $col><input type='hidden' name='FIX_REMARK' value='$hostname' />$hostname_print</td>
484 <td align='center' $col><input type='hidden' name='FIX_ENABLED' value='on' />$entries{$key}->{endtime_print}</td>
485 END
486 ;
487 }
488
489 print <<END
490 <td $col><input type='hidden' name='ACTION' value='$Lang::tr{'add'}2' /><input type='submit' name='SUBMIT' value='$Lang::tr{'add'}' /></td>
491 </tr></form>
492 END
493 ;
494 $id++;
495 }
496
497 print "</table>";
498 &closebox();
499 }
500
501
502 # This sub is used during display of actives leases
503 sub leasesort {
504 if (rindex ($dhcpsettings{'SORT_LEASELIST'},'Rev') != -1)
505 {
506 $qs=substr ($dhcpsettings{'SORT_LEASELIST'},0,length($dhcpsettings{'SORT_LEASELIST'})-3);
507 if ($qs eq 'IPADDR') {
508 @a = split(/\./,$entries{$a}->{$qs});
509 @b = split(/\./,$entries{$b}->{$qs});
510 $entries{$a}->{'expired'} <=> $entries{$b}->{'expired'} || # always sort by expiration first
511 ($b[0]<=>$a[0]) ||
512 ($b[1]<=>$a[1]) ||
513 ($b[2]<=>$a[2]) ||
514 ($b[3]<=>$a[3]);
515 } else {
516 $entries{$a}->{'expired'} <=> $entries{$b}->{'expired'} ||
517 $entries{$b}->{$qs} cmp $entries{$a}->{$qs};
518 }
519 }
520 else #not reverse
521 {
522 $qs=$dhcpsettings{'SORT_LEASELIST'};
523 if ($qs eq 'IPADDR') {
524 @a = split(/\./,$entries{$a}->{$qs});
525 @b = split(/\./,$entries{$b}->{$qs});
526 $entries{$a}->{'expired'} <=> $entries{$b}->{'expired'} ||
527 ($a[0]<=>$b[0]) ||
528 ($a[1]<=>$b[1]) ||
529 ($a[2]<=>$b[2]) ||
530 ($a[3]<=>$b[3]);
531 } else {
532 $entries{$a}->{'expired'} <=> $entries{$b}->{'expired'} ||
533 $entries{$a}->{$qs} cmp $entries{$b}->{$qs};
534 }
535 }
536 }
537
538 sub colorize {
539 my $string = $_[0];
540 my @array = split(/\//,$string);
541 my $string2 = $array[0];
542
543 if ( $string eq "*" or $string eq "" ){
544 return $string;
545 } elsif ( $string =~ "ipsec" ){
546 return "<font color='".${Header::colourvpn}."'>".$string."</font>";
547 } elsif ( $string =~ "tun" ){
548 return "<font color='".${Header::colourovpn}."'>".$string."</font>";
549 } elsif ( $string =~ "lo" or $string =~ "127.0.0.0" ){
550 return "<font color='".${Header::colourfw}."'>".$string."</font>";
551 } elsif ( $string =~ $ethsettings{'GREEN_DEV'} or &General::IpInSubnet($string2,$ethsettings{'GREEN_NETADDRESS'},$ethsettings{'GREEN_NETMASK'}) ){
552 return "<font color='".${Header::colourgreen}."'>".$string."</font>";
553 } elsif ( $string =~ "ppp0" or $string =~ $ethsettings{'RED_DEV'} or $string =~ "0.0.0.0" or $string =~ $ethsettings{'RED_ADDRESS'} ){
554 return "<font color='".${Header::colourred}."'>".$string."</font>";
555 } elsif ( $ethsettings{'CONFIG_TYPE'}>1 and ( $string =~ $ethsettings{'BLUE_DEV'} or &General::IpInSubnet($string2,$ethsettings{'BLUE_NETADDRESS'},$ethsettings{'BLUE_NETMASK'}) )){
556 return "<font color='".${Header::colourblue}."'>".$string."</font>";
557 } elsif ( $ethsettings{'CONFIG_TYPE'}>2 and ( $string =~ $ethsettings{'ORANGE_DEV'} or &General::IpInSubnet($string2,$ethsettings{'ORANGE_NETADDRESS'},$ethsettings{'ORANGE_NETMASK'}) )){
558 return "<font color='".${Header::colourorange}."'>".$string."</font>";
559 } else {
560 return $string;
561 }
562 }