Config.class.php 60 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840
  1. <?php
  2. /* vim: set expandtab sw=4 ts=4 sts=4: */
  3. /**
  4. * Configuration handling.
  5. *
  6. * @package PhpMyAdmin
  7. */
  8. if (! defined('PHPMYADMIN')) {
  9. exit;
  10. }
  11. /**
  12. * Load vendor configuration.
  13. */
  14. require_once './libraries/vendor_config.php';
  15. /**
  16. * Configuration class
  17. *
  18. * @package PhpMyAdmin
  19. */
  20. class PMA_Config
  21. {
  22. /**
  23. * @var string default config source
  24. */
  25. var $default_source = './libraries/config.default.php';
  26. /**
  27. * @var array default configuration settings
  28. */
  29. var $default = array();
  30. /**
  31. * @var array configuration settings
  32. */
  33. var $settings = array();
  34. /**
  35. * @var string config source
  36. */
  37. var $source = '';
  38. /**
  39. * @var int source modification time
  40. */
  41. var $source_mtime = 0;
  42. var $default_source_mtime = 0;
  43. var $set_mtime = 0;
  44. /**
  45. * @var boolean
  46. */
  47. var $error_config_file = false;
  48. /**
  49. * @var boolean
  50. */
  51. var $error_config_default_file = false;
  52. /**
  53. * @var boolean
  54. */
  55. var $error_pma_uri = false;
  56. /**
  57. * @var array
  58. */
  59. var $default_server = array();
  60. /**
  61. * @var boolean whether init is done or not
  62. * set this to false to force some initial checks
  63. * like checking for required functions
  64. */
  65. var $done = false;
  66. /**
  67. * constructor
  68. *
  69. * @param string $source source to read config from
  70. */
  71. function __construct($source = null)
  72. {
  73. $this->settings = array();
  74. // functions need to refresh in case of config file changed goes in
  75. // PMA_Config::load()
  76. $this->load($source);
  77. // other settings, independent from config file, comes in
  78. $this->checkSystem();
  79. $this->checkIsHttps();
  80. }
  81. /**
  82. * sets system and application settings
  83. *
  84. * @return void
  85. */
  86. function checkSystem()
  87. {
  88. $this->set('PMA_VERSION', '4.0.10.20');
  89. /**
  90. * @deprecated
  91. */
  92. $this->set('PMA_THEME_VERSION', 2);
  93. /**
  94. * @deprecated
  95. */
  96. $this->set('PMA_THEME_GENERATION', 2);
  97. $this->checkPhpVersion();
  98. $this->checkWebServerOs();
  99. $this->checkWebServer();
  100. $this->checkGd2();
  101. $this->checkClient();
  102. $this->checkUpload();
  103. $this->checkUploadSize();
  104. $this->checkOutputCompression();
  105. }
  106. /**
  107. * whether to use gzip output compression or not
  108. *
  109. * @return void
  110. */
  111. function checkOutputCompression()
  112. {
  113. // If zlib output compression is set in the php configuration file, no
  114. // output buffering should be run
  115. if (@ini_get('zlib.output_compression')) {
  116. $this->set('OBGzip', false);
  117. }
  118. // disable output-buffering (if set to 'auto') for IE6, else enable it.
  119. if (strtolower($this->get('OBGzip')) == 'auto') {
  120. if ($this->get('PMA_USR_BROWSER_AGENT') == 'IE'
  121. && $this->get('PMA_USR_BROWSER_VER') >= 6
  122. && $this->get('PMA_USR_BROWSER_VER') < 7
  123. ) {
  124. $this->set('OBGzip', false);
  125. } else {
  126. $this->set('OBGzip', true);
  127. }
  128. }
  129. }
  130. /**
  131. * Determines platform (OS), browser and version of the user
  132. * Based on a phpBuilder article:
  133. *
  134. * @see http://www.phpbuilder.net/columns/tim20000821.php
  135. *
  136. * @return void
  137. */
  138. function checkClient()
  139. {
  140. if (PMA_getenv('HTTP_USER_AGENT')) {
  141. $HTTP_USER_AGENT = PMA_getenv('HTTP_USER_AGENT');
  142. } else {
  143. $HTTP_USER_AGENT = '';
  144. }
  145. // 1. Platform
  146. if (strstr($HTTP_USER_AGENT, 'Win')) {
  147. $this->set('PMA_USR_OS', 'Win');
  148. } elseif (strstr($HTTP_USER_AGENT, 'Mac')) {
  149. $this->set('PMA_USR_OS', 'Mac');
  150. } elseif (strstr($HTTP_USER_AGENT, 'Linux')) {
  151. $this->set('PMA_USR_OS', 'Linux');
  152. } elseif (strstr($HTTP_USER_AGENT, 'Unix')) {
  153. $this->set('PMA_USR_OS', 'Unix');
  154. } elseif (strstr($HTTP_USER_AGENT, 'OS/2')) {
  155. $this->set('PMA_USR_OS', 'OS/2');
  156. } else {
  157. $this->set('PMA_USR_OS', 'Other');
  158. }
  159. // 2. browser and version
  160. // (must check everything else before Mozilla)
  161. if (preg_match(
  162. '@Opera(/| )([0-9].[0-9]{1,2})@',
  163. $HTTP_USER_AGENT,
  164. $log_version
  165. )) {
  166. $this->set('PMA_USR_BROWSER_VER', $log_version[2]);
  167. $this->set('PMA_USR_BROWSER_AGENT', 'OPERA');
  168. } elseif (preg_match(
  169. '@MSIE ([0-9].[0-9]{1,2})@',
  170. $HTTP_USER_AGENT,
  171. $log_version
  172. )) {
  173. $this->set('PMA_USR_BROWSER_VER', $log_version[1]);
  174. $this->set('PMA_USR_BROWSER_AGENT', 'IE');
  175. } elseif (preg_match(
  176. '@OmniWeb/([0-9].[0-9]{1,2})@',
  177. $HTTP_USER_AGENT,
  178. $log_version
  179. )) {
  180. $this->set('PMA_USR_BROWSER_VER', $log_version[1]);
  181. $this->set('PMA_USR_BROWSER_AGENT', 'OMNIWEB');
  182. // Konqueror 2.2.2 says Konqueror/2.2.2
  183. // Konqueror 3.0.3 says Konqueror/3
  184. } elseif (preg_match(
  185. '@(Konqueror/)(.*)(;)@',
  186. $HTTP_USER_AGENT,
  187. $log_version
  188. )) {
  189. $this->set('PMA_USR_BROWSER_VER', $log_version[2]);
  190. $this->set('PMA_USR_BROWSER_AGENT', 'KONQUEROR');
  191. // must check Chrome before Safari
  192. } elseif (preg_match(
  193. '@Mozilla/([0-9].[0-9]{1,2})@',
  194. $HTTP_USER_AGENT,
  195. $log_version)
  196. && preg_match('@Chrome/([0-9]*)@', $HTTP_USER_AGENT, $log_version2)
  197. ) {
  198. $this->set('PMA_USR_BROWSER_VER', $log_version[1] . '.' . $log_version2[1]);
  199. $this->set('PMA_USR_BROWSER_AGENT', 'CHROME');
  200. // newer Safari
  201. } elseif (preg_match(
  202. '@Mozilla/([0-9].[0-9]{1,2})@',
  203. $HTTP_USER_AGENT,
  204. $log_version)
  205. && preg_match('@Version/(.*) Safari@', $HTTP_USER_AGENT, $log_version2)
  206. ) {
  207. $this->set(
  208. 'PMA_USR_BROWSER_VER', $log_version2[1]
  209. );
  210. $this->set('PMA_USR_BROWSER_AGENT', 'SAFARI');
  211. // older Safari
  212. } elseif (preg_match(
  213. '@Mozilla/([0-9].[0-9]{1,2})@',
  214. $HTTP_USER_AGENT,
  215. $log_version)
  216. && preg_match('@Safari/([0-9]*)@', $HTTP_USER_AGENT, $log_version2)
  217. ) {
  218. $this->set(
  219. 'PMA_USR_BROWSER_VER', $log_version[1] . '.' . $log_version2[1]
  220. );
  221. $this->set('PMA_USR_BROWSER_AGENT', 'SAFARI');
  222. } elseif (preg_match('@rv:1.9(.*)Gecko@', $HTTP_USER_AGENT)) {
  223. $this->set('PMA_USR_BROWSER_VER', '1.9');
  224. $this->set('PMA_USR_BROWSER_AGENT', 'GECKO');
  225. } elseif (preg_match('@Mozilla/([0-9].[0-9]{1,2})@', $HTTP_USER_AGENT, $log_version)) {
  226. $this->set('PMA_USR_BROWSER_VER', $log_version[1]);
  227. $this->set('PMA_USR_BROWSER_AGENT', 'MOZILLA');
  228. } else {
  229. $this->set('PMA_USR_BROWSER_VER', 0);
  230. $this->set('PMA_USR_BROWSER_AGENT', 'OTHER');
  231. }
  232. }
  233. /**
  234. * Whether GD2 is present
  235. *
  236. * @return void
  237. */
  238. function checkGd2()
  239. {
  240. if ($this->get('GD2Available') == 'yes') {
  241. $this->set('PMA_IS_GD2', 1);
  242. } elseif ($this->get('GD2Available') == 'no') {
  243. $this->set('PMA_IS_GD2', 0);
  244. } else {
  245. if (!@function_exists('imagecreatetruecolor')) {
  246. $this->set('PMA_IS_GD2', 0);
  247. } else {
  248. if (@function_exists('gd_info')) {
  249. $gd_nfo = gd_info();
  250. if (strstr($gd_nfo["GD Version"], '2.')) {
  251. $this->set('PMA_IS_GD2', 1);
  252. } else {
  253. $this->set('PMA_IS_GD2', 0);
  254. }
  255. } else {
  256. $this->set('PMA_IS_GD2', 0);
  257. }
  258. }
  259. }
  260. }
  261. /**
  262. * Whether the Web server php is running on is IIS
  263. *
  264. * @return void
  265. */
  266. function checkWebServer()
  267. {
  268. // some versions return Microsoft-IIS, some Microsoft/IIS
  269. // we could use a preg_match() but it's slower
  270. if (PMA_getenv('SERVER_SOFTWARE')
  271. && stristr(PMA_getenv('SERVER_SOFTWARE'), 'Microsoft')
  272. && stristr(PMA_getenv('SERVER_SOFTWARE'), 'IIS')
  273. ) {
  274. $this->set('PMA_IS_IIS', 1);
  275. } else {
  276. $this->set('PMA_IS_IIS', 0);
  277. }
  278. }
  279. /**
  280. * Whether the os php is running on is windows or not
  281. *
  282. * @return void
  283. */
  284. function checkWebServerOs()
  285. {
  286. // Default to Unix or Equiv
  287. $this->set('PMA_IS_WINDOWS', 0);
  288. // If PHP_OS is defined then continue
  289. if (defined('PHP_OS')) {
  290. if (stristr(PHP_OS, 'win')) {
  291. // Is it some version of Windows
  292. $this->set('PMA_IS_WINDOWS', 1);
  293. } elseif (stristr(PHP_OS, 'OS/2')) {
  294. // Is it OS/2 (No file permissions like Windows)
  295. $this->set('PMA_IS_WINDOWS', 1);
  296. }
  297. }
  298. }
  299. /**
  300. * detects PHP version
  301. *
  302. * @return void
  303. */
  304. function checkPhpVersion()
  305. {
  306. $match = array();
  307. if (! preg_match(
  308. '@([0-9]{1,2}).([0-9]{1,2}).([0-9]{1,2})@',
  309. phpversion(),
  310. $match
  311. )) {
  312. preg_match(
  313. '@([0-9]{1,2}).([0-9]{1,2})@',
  314. phpversion(),
  315. $match
  316. );
  317. }
  318. if (isset($match) && ! empty($match[1])) {
  319. if (! isset($match[2])) {
  320. $match[2] = 0;
  321. }
  322. if (! isset($match[3])) {
  323. $match[3] = 0;
  324. }
  325. $this->set(
  326. 'PMA_PHP_INT_VERSION',
  327. (int) sprintf('%d%02d%02d', $match[1], $match[2], $match[3])
  328. );
  329. } else {
  330. $this->set('PMA_PHP_INT_VERSION', 0);
  331. }
  332. $this->set('PMA_PHP_STR_VERSION', phpversion());
  333. }
  334. /**
  335. * detects if Git revision
  336. *
  337. * @return boolean
  338. */
  339. function isGitRevision()
  340. {
  341. // caching
  342. if (isset($_SESSION['is_git_revision'])) {
  343. if ($_SESSION['is_git_revision']) {
  344. $this->set('PMA_VERSION_GIT', 1);
  345. }
  346. return $_SESSION['is_git_revision'];
  347. }
  348. // find out if there is a .git folder
  349. $git_folder = '.git';
  350. if (! @file_exists($git_folder)
  351. || ! @file_exists($git_folder . '/config')
  352. ) {
  353. $_SESSION['is_git_revision'] = false;
  354. return false;
  355. }
  356. $_SESSION['is_git_revision'] = true;
  357. return true;
  358. }
  359. /**
  360. * detects Git revision, if running inside repo
  361. *
  362. * @return void
  363. */
  364. function checkGitRevision()
  365. {
  366. // find out if there is a .git folder
  367. $git_folder = '.git';
  368. if (! $this->isGitRevision()) {
  369. return;
  370. }
  371. if (! $ref_head = @file_get_contents($git_folder . '/HEAD')) {
  372. return;
  373. }
  374. $branch = false;
  375. // are we on any branch?
  376. if (strstr($ref_head, '/')) {
  377. $ref_head = substr(trim($ref_head), 5);
  378. if (substr($ref_head, 0, 11) === 'refs/heads/') {
  379. $branch = substr($ref_head, 11);
  380. } else {
  381. $branch = basename($ref_head);
  382. }
  383. $ref_file = $git_folder . '/' . $ref_head;
  384. if (@file_exists($ref_file)) {
  385. if (! $hash = @file_get_contents($ref_file)) {
  386. return;
  387. }
  388. $hash = trim($hash);
  389. } else {
  390. // deal with packed refs
  391. if (! $packed_refs = @file_get_contents($git_folder . '/packed-refs')) {
  392. return;
  393. }
  394. // split file to lines
  395. $ref_lines = explode("\n", $packed_refs);
  396. foreach ($ref_lines as $line) {
  397. // skip comments
  398. if ($line[0] == '#') {
  399. continue;
  400. }
  401. // parse line
  402. $parts = explode(' ', $line);
  403. // care only about named refs
  404. if (count($parts) != 2) {
  405. continue;
  406. }
  407. // have found our ref?
  408. if ($parts[1] == $ref_head) {
  409. $hash = $parts[0];
  410. break;
  411. }
  412. }
  413. if (! isset($hash)) {
  414. // Could not find ref
  415. return;
  416. }
  417. }
  418. } else {
  419. $hash = trim($ref_head);
  420. }
  421. $commit = false;
  422. if ( !isset($_SESSION['PMA_VERSION_COMMITDATA_' . $hash])) {
  423. $git_file_name = $git_folder . '/objects/' . substr($hash, 0, 2)
  424. . '/' . substr($hash, 2);
  425. if (file_exists($git_file_name) ) {
  426. if (! $commit = @file_get_contents($git_file_name)) {
  427. return;
  428. }
  429. $commit = explode("\0", gzuncompress($commit), 2);
  430. $commit = explode("\n", $commit[1]);
  431. $_SESSION['PMA_VERSION_COMMITDATA_' . $hash] = $commit;
  432. } else {
  433. $pack_names = array();
  434. // work with packed data
  435. if ($packs = @file_get_contents($git_folder . '/objects/info/packs')) {
  436. // File exists. Read it, parse the file to get the names of the
  437. // packs. (to look for them in .git/object/pack directory later)
  438. foreach (explode("\n", $packs) as $line) {
  439. // skip blank lines
  440. if (strlen(trim($line)) == 0) {
  441. continue;
  442. }
  443. // skip non pack lines
  444. if ($line[0] != 'P') {
  445. continue;
  446. }
  447. // parse names
  448. $pack_names[] = substr($line, 2);
  449. }
  450. } else {
  451. // '.git/objects/info/packs' file can be missing
  452. // (atlease in mysGit)
  453. // File missing. May be we can look in the .git/object/pack
  454. // directory for all the .pack files and use that list of
  455. // files instead
  456. $it = new DirectoryIterator($git_folder . '/objects/pack');
  457. foreach ($it as $file_info) {
  458. $file_name = $file_info->getFilename();
  459. // if this is a .pack file
  460. if ($file_info->isFile()
  461. && substr($file_name, -5) == '.pack'
  462. ) {
  463. $pack_names[] = $file_name;
  464. }
  465. }
  466. }
  467. $hash = strtolower($hash);
  468. foreach ($pack_names as $pack_name) {
  469. $index_name = str_replace('.pack', '.idx', $pack_name);
  470. // load index
  471. if (! $index_data = @file_get_contents($git_folder . '/objects/pack/' . $index_name)) {
  472. continue;
  473. }
  474. // check format
  475. if (substr($index_data, 0, 4) != "\377tOc") {
  476. continue;
  477. }
  478. // check version
  479. $version = unpack('N', substr($index_data, 4, 4));
  480. if ($version[1] != 2) {
  481. continue;
  482. }
  483. // parse fanout table
  484. $fanout = unpack("N*", substr($index_data, 8, 256 * 4));
  485. // find where we should search
  486. $firstbyte = intval(substr($hash, 0, 2), 16);
  487. // array is indexed from 1 and we need to get
  488. // previous entry for start
  489. if ($firstbyte == 0) {
  490. $start = 0;
  491. } else {
  492. $start = $fanout[$firstbyte];
  493. }
  494. $end = $fanout[$firstbyte + 1];
  495. // stupid linear search for our sha
  496. $position = $start;
  497. $found = false;
  498. $offset = 8 + (256 * 4);
  499. for ($position = $start; $position < $end; $position++) {
  500. $sha = strtolower(
  501. bin2hex(
  502. substr(
  503. $index_data, $offset + ($position * 20), 20
  504. )
  505. )
  506. );
  507. if ($sha == $hash) {
  508. $found = true;
  509. break;
  510. }
  511. }
  512. if (! $found) {
  513. continue;
  514. }
  515. // read pack offset
  516. $offset = 8 + (256 * 4) + (24 * $fanout[256]);
  517. $pack_offset = unpack(
  518. 'N', substr($index_data, $offset + ($position * 4), 4)
  519. );
  520. $pack_offset = $pack_offset[1];
  521. // open pack file
  522. $pack_file = fopen(
  523. $git_folder . '/objects/pack/' . $pack_name, 'rb'
  524. );
  525. if ($pack_file === false) {
  526. continue;
  527. }
  528. // seek to start
  529. fseek($pack_file, $pack_offset);
  530. // parse header
  531. $header = ord(fread($pack_file, 1));
  532. $type = ($header >> 4) & 7;
  533. $hasnext = ($header & 128) >> 7;
  534. $size = $header & 0xf;
  535. $offset = 4;
  536. while ($hasnext) {
  537. $byte = ord(fread($pack_file, 1));
  538. $size |= ($byte & 0x7f) << $offset;
  539. $hasnext = ($byte & 128) >> 7;
  540. $offset += 7;
  541. }
  542. // we care only about commit objects
  543. if ($type != 1) {
  544. continue;
  545. }
  546. // read data
  547. $commit = fread($pack_file, $size);
  548. $commit = gzuncompress($commit);
  549. $commit = explode("\n", $commit);
  550. $_SESSION['PMA_VERSION_COMMITDATA_' . $hash] = $commit;
  551. fclose($pack_file);
  552. }
  553. }
  554. } else {
  555. $commit = $_SESSION['PMA_VERSION_COMMITDATA_' . $hash];
  556. }
  557. // check if commit exists in Github
  558. $is_remote_commit = false;
  559. if ($commit !== false
  560. && isset($_SESSION['PMA_VERSION_REMOTECOMMIT_' . $hash])
  561. ) {
  562. $is_remote_commit = $_SESSION['PMA_VERSION_REMOTECOMMIT_' . $hash];
  563. } else {
  564. $link = 'https://api.github.com/repos/phpmyadmin/phpmyadmin/git/commits/'
  565. . $hash;
  566. $is_found = $this->checkHTTP($link, !$commit);
  567. switch($is_found) {
  568. case false:
  569. $is_remote_commit = false;
  570. $_SESSION['PMA_VERSION_REMOTECOMMIT_' . $hash] = false;
  571. break;
  572. case null:
  573. // no remote link for now, but don't cache this as Github is down
  574. $is_remote_commit = false;
  575. break;
  576. default:
  577. $is_remote_commit = true;
  578. $_SESSION['PMA_VERSION_REMOTECOMMIT_' . $hash] = true;
  579. if ($commit === false) {
  580. // if no local commit data, try loading from Github
  581. $commit_json = json_decode($is_found);
  582. }
  583. break;
  584. }
  585. }
  586. $is_remote_branch = false;
  587. if ($is_remote_commit && $branch !== false) {
  588. // check if branch exists in Github
  589. if (isset($_SESSION['PMA_VERSION_REMOTEBRANCH_' . $hash])) {
  590. $is_remote_branch = $_SESSION['PMA_VERSION_REMOTEBRANCH_' . $hash];
  591. } else {
  592. $link = 'https://api.github.com/repos/phpmyadmin/phpmyadmin'
  593. . '/git/trees/' . $branch;
  594. $is_found = $this->checkHTTP($link);
  595. switch($is_found) {
  596. case true:
  597. $is_remote_branch = true;
  598. $_SESSION['PMA_VERSION_REMOTEBRANCH_' . $hash] = true;
  599. break;
  600. case false:
  601. $is_remote_branch = false;
  602. $_SESSION['PMA_VERSION_REMOTEBRANCH_' . $hash] = false;
  603. break;
  604. case null:
  605. // no remote link for now, but don't cache this as Github is down
  606. $is_remote_branch = false;
  607. break;
  608. }
  609. }
  610. }
  611. if ($commit !== false) {
  612. $author = array('name' => '', 'email' => '', 'date' => '');
  613. $committer = array('name' => '', 'email' => '', 'date' => '');
  614. do {
  615. $dataline = array_shift($commit);
  616. $datalinearr = explode(' ', $dataline, 2);
  617. $linetype = $datalinearr[0];
  618. if (in_array($linetype, array('author', 'committer'))) {
  619. $user = $datalinearr[1];
  620. preg_match('/([^<]+)<([^>]+)> ([0-9]+)( [^ ]+)?/', $user, $user);
  621. $user2 = array(
  622. 'name' => trim($user[1]),
  623. 'email' => trim($user[2]),
  624. 'date' => date('Y-m-d H:i:s', $user[3]));
  625. if (isset($user[4])) {
  626. $user2['date'] .= $user[4];
  627. }
  628. $$linetype = $user2;
  629. }
  630. } while ($dataline != '');
  631. $message = trim(implode(' ', $commit));
  632. } elseif (isset($commit_json)) {
  633. $author = array(
  634. 'name' => $commit_json->author->name,
  635. 'email' => $commit_json->author->email,
  636. 'date' => $commit_json->author->date);
  637. $committer = array(
  638. 'name' => $commit_json->committer->name,
  639. 'email' => $commit_json->committer->email,
  640. 'date' => $commit_json->committer->date);
  641. $message = trim($commit_json->message);
  642. } else {
  643. return;
  644. }
  645. $this->set('PMA_VERSION_GIT', 1);
  646. $this->set('PMA_VERSION_GIT_COMMITHASH', $hash);
  647. $this->set('PMA_VERSION_GIT_BRANCH', $branch);
  648. $this->set('PMA_VERSION_GIT_MESSAGE', $message);
  649. $this->set('PMA_VERSION_GIT_AUTHOR', $author);
  650. $this->set('PMA_VERSION_GIT_COMMITTER', $committer);
  651. $this->set('PMA_VERSION_GIT_ISREMOTECOMMIT', $is_remote_commit);
  652. $this->set('PMA_VERSION_GIT_ISREMOTEBRANCH', $is_remote_branch);
  653. }
  654. /**
  655. * Checks if given URL is 200 or 404, optionally returns data
  656. *
  657. * @param mixed $link curl link
  658. * @param boolean $get_body whether to retrieve body of document
  659. *
  660. * @return test result or data
  661. */
  662. function checkHTTP($link, $get_body = false)
  663. {
  664. if (! function_exists('curl_init')) {
  665. return null;
  666. }
  667. $ch = curl_init($link);
  668. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
  669. curl_setopt($ch, CURLOPT_HEADER, 1);
  670. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  671. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  672. curl_setopt($ch, CURLOPT_USERAGENT, 'phpMyAdmin/' . PMA_VERSION);
  673. curl_setopt($ch, CURLOPT_TIMEOUT, 5);
  674. $data = @curl_exec($ch);
  675. if ($data === false) {
  676. return null;
  677. }
  678. $ok = 'HTTP/1.1 200 OK';
  679. $notfound = 'HTTP/1.1 404 Not Found';
  680. if (substr($data, 0, strlen($ok)) === $ok) {
  681. return $get_body ? substr($data, strpos($data, "\r\n\r\n") + 4) : true;
  682. } elseif (substr($data, 0, strlen($notfound)) === $notfound) {
  683. return false;
  684. }
  685. return null;
  686. }
  687. /**
  688. * loads default values from default source
  689. *
  690. * @return boolean success
  691. */
  692. function loadDefaults()
  693. {
  694. $cfg = array();
  695. if (! file_exists($this->default_source)) {
  696. $this->error_config_default_file = true;
  697. return false;
  698. }
  699. include $this->default_source;
  700. $this->default_source_mtime = filemtime($this->default_source);
  701. $this->default_server = $cfg['Servers'][1];
  702. unset($cfg['Servers']);
  703. $this->default = $cfg;
  704. $this->settings = PMA_arrayMergeRecursive($this->settings, $cfg);
  705. $this->error_config_default_file = false;
  706. return true;
  707. }
  708. /**
  709. * loads configuration from $source, usally the config file
  710. * should be called on object creation
  711. *
  712. * @param string $source config file
  713. *
  714. * @return bool
  715. */
  716. function load($source = null)
  717. {
  718. $this->loadDefaults();
  719. if (null !== $source) {
  720. $this->setSource($source);
  721. }
  722. if (! $this->checkConfigSource()) {
  723. return false;
  724. }
  725. $cfg = array();
  726. /**
  727. * Parses the configuration file, the eval is used here to avoid
  728. * problems with trailing whitespace, what is often a problem.
  729. */
  730. $old_error_reporting = error_reporting(0);
  731. $eval_result = eval('?' . '>' . trim(file_get_contents($this->getSource())));
  732. error_reporting($old_error_reporting);
  733. if ($eval_result === false) {
  734. $this->error_config_file = true;
  735. } else {
  736. $this->error_config_file = false;
  737. $this->source_mtime = filemtime($this->getSource());
  738. }
  739. /**
  740. * Backward compatibility code
  741. */
  742. if (!empty($cfg['DefaultTabTable'])) {
  743. $cfg['DefaultTabTable'] = str_replace(
  744. '_properties',
  745. '',
  746. str_replace(
  747. 'tbl_properties.php',
  748. 'tbl_sql.php',
  749. $cfg['DefaultTabTable']
  750. )
  751. );
  752. }
  753. if (!empty($cfg['DefaultTabDatabase'])) {
  754. $cfg['DefaultTabDatabase'] = str_replace(
  755. '_details',
  756. '',
  757. str_replace(
  758. 'db_details.php',
  759. 'db_sql.php',
  760. $cfg['DefaultTabDatabase']
  761. )
  762. );
  763. }
  764. $this->settings = PMA_arrayMergeRecursive($this->settings, $cfg);
  765. $this->checkPmaAbsoluteUri();
  766. $this->checkFontsize();
  767. // Handling of the collation must be done after merging of $cfg
  768. // (from config.inc.php) so that $cfg['DefaultConnectionCollation']
  769. // can have an effect. Note that the presence of collation
  770. // information in a cookie has priority over what is defined
  771. // in the default or user's config files.
  772. /**
  773. * @todo check validity of $_COOKIE['pma_collation_connection']
  774. */
  775. if (! empty($_COOKIE['pma_collation_connection'])) {
  776. $this->set(
  777. 'collation_connection',
  778. strip_tags($_COOKIE['pma_collation_connection'])
  779. );
  780. } else {
  781. $this->set(
  782. 'collation_connection',
  783. $this->get('DefaultConnectionCollation')
  784. );
  785. }
  786. // Now, a collation information could come from REQUEST
  787. // (an example of this: the collation selector in index.php)
  788. // so the following handles the setting of collation_connection
  789. // and later, in common.inc.php, the cookie will be set
  790. // according to this.
  791. $this->checkCollationConnection();
  792. return true;
  793. }
  794. /**
  795. * Loads user preferences and merges them with current config
  796. * must be called after control connection has been estabilished
  797. *
  798. * @return boolean
  799. */
  800. function loadUserPreferences()
  801. {
  802. // index.php should load these settings, so that phpmyadmin.css.php
  803. // will have everything avaiable in session cache
  804. $server = isset($GLOBALS['server'])
  805. ? $GLOBALS['server']
  806. : (!empty($GLOBALS['cfg']['ServerDefault'])
  807. ? $GLOBALS['cfg']['ServerDefault']
  808. : 0);
  809. $cache_key = 'server_' . $server;
  810. if ($server > 0 && !defined('PMA_MINIMUM_COMMON')) {
  811. $config_mtime = max($this->default_source_mtime, $this->source_mtime);
  812. // cache user preferences, use database only when needed
  813. if (! isset($_SESSION['cache'][$cache_key]['userprefs'])
  814. || $_SESSION['cache'][$cache_key]['config_mtime'] < $config_mtime
  815. ) {
  816. // load required libraries
  817. include_once './libraries/user_preferences.lib.php';
  818. $prefs = PMA_loadUserprefs();
  819. $_SESSION['cache'][$cache_key]['userprefs']
  820. = PMA_applyUserprefs($prefs['config_data']);
  821. $_SESSION['cache'][$cache_key]['userprefs_mtime'] = $prefs['mtime'];
  822. $_SESSION['cache'][$cache_key]['userprefs_type'] = $prefs['type'];
  823. $_SESSION['cache'][$cache_key]['config_mtime'] = $config_mtime;
  824. }
  825. } elseif ($server == 0
  826. || ! isset($_SESSION['cache'][$cache_key]['userprefs'])
  827. ) {
  828. $this->set('user_preferences', false);
  829. return;
  830. }
  831. $config_data = $_SESSION['cache'][$cache_key]['userprefs'];
  832. // type is 'db' or 'session'
  833. $this->set(
  834. 'user_preferences',
  835. $_SESSION['cache'][$cache_key]['userprefs_type']
  836. );
  837. $this->set(
  838. 'user_preferences_mtime',
  839. $_SESSION['cache'][$cache_key]['userprefs_mtime']
  840. );
  841. // backup some settings
  842. $org_fontsize = '';
  843. if (isset($this->settings['fontsize'])) {
  844. $org_fontsize = $this->settings['fontsize'];
  845. }
  846. // load config array
  847. $this->settings = PMA_arrayMergeRecursive($this->settings, $config_data);
  848. $GLOBALS['cfg'] = PMA_arrayMergeRecursive($GLOBALS['cfg'], $config_data);
  849. if (defined('PMA_MINIMUM_COMMON')) {
  850. return;
  851. }
  852. // settings below start really working on next page load, but
  853. // changes are made only in index.php so everything is set when
  854. // in frames
  855. // save theme
  856. $tmanager = $_SESSION['PMA_Theme_Manager'];
  857. if ($tmanager->getThemeCookie() || isset($_REQUEST['set_theme'])) {
  858. if ((! isset($config_data['ThemeDefault'])
  859. && $tmanager->theme->getId() != 'original')
  860. || isset($config_data['ThemeDefault'])
  861. && $config_data['ThemeDefault'] != $tmanager->theme->getId()
  862. ) {
  863. // new theme was set in common.inc.php
  864. $this->setUserValue(
  865. null,
  866. 'ThemeDefault',
  867. $tmanager->theme->getId(),
  868. 'original'
  869. );
  870. }
  871. } else {
  872. // no cookie - read default from settings
  873. if ($this->settings['ThemeDefault'] != $tmanager->theme->getId()
  874. && $tmanager->checkTheme($this->settings['ThemeDefault'])
  875. ) {
  876. $tmanager->setActiveTheme($this->settings['ThemeDefault']);
  877. $tmanager->setThemeCookie();
  878. }
  879. }
  880. // save font size
  881. if ((! isset($config_data['fontsize'])
  882. && $org_fontsize != '82%')
  883. || isset($config_data['fontsize'])
  884. && $org_fontsize != $config_data['fontsize']
  885. ) {
  886. $this->setUserValue(null, 'fontsize', $org_fontsize, '82%');
  887. }
  888. // save language
  889. if (isset($_COOKIE['pma_lang']) || isset($_POST['lang'])) {
  890. if ((! isset($config_data['lang'])
  891. && $GLOBALS['lang'] != 'en')
  892. || isset($config_data['lang'])
  893. && $GLOBALS['lang'] != $config_data['lang']
  894. ) {
  895. $this->setUserValue(null, 'lang', $GLOBALS['lang'], 'en');
  896. }
  897. } else {
  898. // read language from settings
  899. if (isset($config_data['lang']) && PMA_langSet($config_data['lang'])) {
  900. $this->setCookie('pma_lang', $GLOBALS['lang']);
  901. }
  902. }
  903. // save connection collation
  904. if (isset($_COOKIE['pma_collation_connection'])
  905. || isset($_POST['collation_connection'])
  906. ) {
  907. if ((! isset($config_data['collation_connection'])
  908. && $GLOBALS['collation_connection'] != 'utf8_general_ci')
  909. || isset($config_data['collation_connection'])
  910. && $GLOBALS['collation_connection'] != $config_data['collation_connection']
  911. ) {
  912. $this->setUserValue(
  913. null,
  914. 'collation_connection',
  915. $GLOBALS['collation_connection'],
  916. 'utf8_general_ci'
  917. );
  918. }
  919. } else {
  920. // read collation from settings
  921. if (isset($config_data['collation_connection'])) {
  922. $GLOBALS['collation_connection']
  923. = $config_data['collation_connection'];
  924. $this->setCookie(
  925. 'pma_collation_connection',
  926. $GLOBALS['collation_connection']
  927. );
  928. }
  929. }
  930. }
  931. /**
  932. * Sets config value which is stored in user preferences (if available)
  933. * or in a cookie.
  934. *
  935. * If user preferences are not yet initialized, option is applied to
  936. * global config and added to a update queue, which is processed
  937. * by {@link loadUserPreferences()}
  938. *
  939. * @param string $cookie_name can be null
  940. * @param string $cfg_path configuration path
  941. * @param mixed $new_cfg_value new value
  942. * @param mixed $default_value default value
  943. *
  944. * @return void
  945. */
  946. function setUserValue($cookie_name, $cfg_path, $new_cfg_value,
  947. $default_value = null
  948. ) {
  949. // use permanent user preferences if possible
  950. $prefs_type = $this->get('user_preferences');
  951. if ($prefs_type) {
  952. include_once './libraries/user_preferences.lib.php';
  953. if ($default_value === null) {
  954. $default_value = PMA_arrayRead($cfg_path, $this->default);
  955. }
  956. PMA_persistOption($cfg_path, $new_cfg_value, $default_value);
  957. }
  958. if ($prefs_type != 'db' && $cookie_name) {
  959. // fall back to cookies
  960. if ($default_value === null) {
  961. $default_value = PMA_arrayRead($cfg_path, $this->settings);
  962. }
  963. $this->setCookie($cookie_name, $new_cfg_value, $default_value);
  964. }
  965. PMA_arrayWrite($cfg_path, $GLOBALS['cfg'], $new_cfg_value);
  966. PMA_arrayWrite($cfg_path, $this->settings, $new_cfg_value);
  967. }
  968. /**
  969. * Reads value stored by {@link setUserValue()}
  970. *
  971. * @param string $cookie_name cookie name
  972. * @param mixed $cfg_value config value
  973. *
  974. * @return mixed
  975. */
  976. function getUserValue($cookie_name, $cfg_value)
  977. {
  978. $cookie_exists = isset($_COOKIE) && !empty($_COOKIE[$cookie_name]);
  979. $prefs_type = $this->get('user_preferences');
  980. if ($prefs_type == 'db') {
  981. // permanent user preferences value exists, remove cookie
  982. if ($cookie_exists) {
  983. $this->removeCookie($cookie_name);
  984. }
  985. } else if ($cookie_exists) {
  986. return $_COOKIE[$cookie_name];
  987. }
  988. // return value from $cfg array
  989. return $cfg_value;
  990. }
  991. /**
  992. * set source
  993. *
  994. * @param string $source source
  995. *
  996. * @return void
  997. */
  998. function setSource($source)
  999. {
  1000. $this->source = trim($source);
  1001. }
  1002. /**
  1003. * check config source
  1004. *
  1005. * @return boolean whether source is valid or not
  1006. */
  1007. function checkConfigSource()
  1008. {
  1009. if (! $this->getSource()) {
  1010. // no configuration file set at all
  1011. return false;
  1012. }
  1013. if (! file_exists($this->getSource())) {
  1014. $this->source_mtime = 0;
  1015. return false;
  1016. }
  1017. if (! is_readable($this->getSource())) {
  1018. // manually check if file is readable
  1019. // might be bug #3059806 Supporting running from CIFS/Samba shares
  1020. $contents = false;
  1021. $handle = @fopen($this->getSource(), 'r');
  1022. if ($handle !== false) {
  1023. $contents = @fread($handle, 1); // reading 1 byte is enough to test
  1024. @fclose($handle);
  1025. }
  1026. if ($contents === false) {
  1027. $this->source_mtime = 0;
  1028. PMA_fatalError(
  1029. sprintf(
  1030. function_exists('__')
  1031. ? __('Existing configuration file (%s) is not readable.')
  1032. : 'Existing configuration file (%s) is not readable.',
  1033. $this->getSource()
  1034. )
  1035. );
  1036. return false;
  1037. }
  1038. }
  1039. return true;
  1040. }
  1041. /**
  1042. * verifies the permissions on config file (if asked by configuration)
  1043. * (must be called after config.inc.php has been merged)
  1044. *
  1045. * @return void
  1046. */
  1047. function checkPermissions()
  1048. {
  1049. // Check for permissions (on platforms that support it):
  1050. if ($this->get('CheckConfigurationPermissions')) {
  1051. $perms = @fileperms($this->getSource());
  1052. if (!($perms === false) && ($perms & 2)) {
  1053. // This check is normally done after loading configuration
  1054. $this->checkWebServerOs();
  1055. if ($this->get('PMA_IS_WINDOWS') == 0) {
  1056. $this->source_mtime = 0;
  1057. /* Gettext is possibly still not loaded */
  1058. if (function_exists('__')) {
  1059. $msg = __('Wrong permissions on configuration file, should not be world writable!');
  1060. } else {
  1061. $msg = 'Wrong permissions on configuration file, should not be world writable!';
  1062. }
  1063. PMA_fatalError($msg);
  1064. }
  1065. }
  1066. }
  1067. }
  1068. /**
  1069. * returns specific config setting
  1070. *
  1071. * @param string $setting config setting
  1072. *
  1073. * @return mixed value
  1074. */
  1075. function get($setting)
  1076. {
  1077. if (isset($this->settings[$setting])) {
  1078. return $this->settings[$setting];
  1079. }
  1080. return null;
  1081. }
  1082. /**
  1083. * sets configuration variable
  1084. *
  1085. * @param string $setting configuration option
  1086. * @param string $value new value for configuration option
  1087. *
  1088. * @return void
  1089. */
  1090. function set($setting, $value)
  1091. {
  1092. if (! isset($this->settings[$setting])
  1093. || $this->settings[$setting] != $value
  1094. ) {
  1095. $this->settings[$setting] = $value;
  1096. $this->set_mtime = time();
  1097. }
  1098. }
  1099. /**
  1100. * returns source for current config
  1101. *
  1102. * @return string config source
  1103. */
  1104. function getSource()
  1105. {
  1106. return $this->source;
  1107. }
  1108. /**
  1109. * returns a unique value to force a CSS reload if either the config
  1110. * or the theme changes
  1111. * must also check the pma_fontsize cookie in case there is no
  1112. * config file
  1113. *
  1114. * @return int Summary of unix timestamps and fontsize,
  1115. * to be unique on theme parameters change
  1116. */
  1117. function getThemeUniqueValue()
  1118. {
  1119. if (null !== $this->get('fontsize')) {
  1120. $fontsize = intval($this->get('fontsize'));
  1121. } elseif (isset($_COOKIE['pma_fontsize'])) {
  1122. $fontsize = intval($_COOKIE['pma_fontsize']);
  1123. } else {
  1124. $fontsize = 0;
  1125. }
  1126. return (
  1127. $fontsize +
  1128. $this->source_mtime +
  1129. $this->default_source_mtime +
  1130. $this->get('user_preferences_mtime') +
  1131. $_SESSION['PMA_Theme']->mtime_info +
  1132. $_SESSION['PMA_Theme']->filesize_info);
  1133. }
  1134. /**
  1135. * $cfg['PmaAbsoluteUri'] is a required directive else cookies won't be
  1136. * set properly and, depending on browsers, inserting or updating a
  1137. * record might fail
  1138. *
  1139. * @return bool
  1140. */
  1141. function checkPmaAbsoluteUri()
  1142. {
  1143. // Setup a default value to let the people and lazy sysadmins work anyway,
  1144. // they'll get an error if the autodetect code doesn't work
  1145. $pma_absolute_uri = $this->get('PmaAbsoluteUri');
  1146. $is_https = $this->detectHttps();
  1147. if (strlen($pma_absolute_uri) < 5) {
  1148. $url = array();
  1149. // If we don't have scheme, we didn't have full URL so we need to
  1150. // dig deeper
  1151. if (empty($url['scheme'])) {
  1152. // Scheme
  1153. if ($is_https) {
  1154. $url['scheme'] = 'https';
  1155. } else {
  1156. $url['scheme'] = 'http';
  1157. }
  1158. // Host and port
  1159. if (PMA_getenv('HTTP_HOST')) {
  1160. // Prepend the scheme before using parse_url() since this
  1161. // is not part of the RFC2616 Host request-header
  1162. $parsed_url = parse_url(
  1163. $url['scheme'] . '://' . PMA_getenv('HTTP_HOST')
  1164. );
  1165. if (!empty($parsed_url['host'])) {
  1166. $url = $parsed_url;
  1167. } else {
  1168. $url['host'] = PMA_getenv('HTTP_HOST');
  1169. }
  1170. } elseif (PMA_getenv('SERVER_NAME')) {
  1171. $url['host'] = PMA_getenv('SERVER_NAME');
  1172. } else {
  1173. $this->error_pma_uri = true;
  1174. return false;
  1175. }
  1176. // If we didn't set port yet...
  1177. if (empty($url['port']) && PMA_getenv('SERVER_PORT')) {
  1178. $url['port'] = PMA_getenv('SERVER_PORT');
  1179. }
  1180. // And finally the path could be already set from REQUEST_URI
  1181. if (empty($url['path'])) {
  1182. // we got a case with nginx + php-fpm where PHP_SELF
  1183. // was not set, so PMA_PHP_SELF was not set as well
  1184. if (isset($GLOBALS['PMA_PHP_SELF'])) {
  1185. $path = parse_url($GLOBALS['PMA_PHP_SELF']);
  1186. } else {
  1187. $path = parse_url(PMA_getenv('REQUEST_URI'));
  1188. }
  1189. $url['path'] = $path['path'];
  1190. }
  1191. }
  1192. // Make url from parts we have
  1193. $pma_absolute_uri = $url['scheme'] . '://';
  1194. // Was there user information?
  1195. if (!empty($url['user'])) {
  1196. $pma_absolute_uri .= $url['user'];
  1197. if (!empty($url['pass'])) {
  1198. $pma_absolute_uri .= ':' . $url['pass'];
  1199. }
  1200. $pma_absolute_uri .= '@';
  1201. }
  1202. // Add hostname
  1203. $pma_absolute_uri .= urlencode($url['host']);
  1204. // Add port, if it not the default one
  1205. if (! empty($url['port'])
  1206. && (($url['scheme'] == 'http' && $url['port'] != 80)
  1207. || ($url['scheme'] == 'https' && $url['port'] != 443))
  1208. ) {
  1209. $pma_absolute_uri .= ':' . $url['port'];
  1210. }
  1211. // And finally path, without script name, the 'a' is there not to
  1212. // strip our directory, when path is only /pmadir/ without filename.
  1213. // Backslashes returned by Windows have to be changed.
  1214. // Only replace backslashes by forward slashes if on Windows,
  1215. // as the backslash could be valid on a non-Windows system.
  1216. $this->checkWebServerOs();
  1217. if ($this->get('PMA_IS_WINDOWS') == 1) {
  1218. $path = str_replace("\\", "/", dirname($url['path'] . 'a'));
  1219. } else {
  1220. $path = dirname($url['path'] . 'a');
  1221. }
  1222. // To work correctly within transformations overview:
  1223. if (defined('PMA_PATH_TO_BASEDIR') && PMA_PATH_TO_BASEDIR == '../../') {
  1224. if ($this->get('PMA_IS_WINDOWS') == 1) {
  1225. $path = str_replace("\\", "/", dirname(dirname($path)));
  1226. } else {
  1227. $path = dirname(dirname($path));
  1228. }
  1229. }
  1230. // PHP's dirname function would have returned a dot
  1231. // when $path contains no slash
  1232. if ($path == '.') {
  1233. $path = '';
  1234. }
  1235. // in vhost situations, there could be already an ending slash
  1236. if (substr($path, -1) != '/') {
  1237. $path .= '/';
  1238. }
  1239. $pma_absolute_uri .= $path;
  1240. // This is to handle the case of a reverse proxy
  1241. if ($this->get('ForceSSL')) {
  1242. $this->set('PmaAbsoluteUri', $pma_absolute_uri);
  1243. $pma_absolute_uri = $this->getSSLUri();
  1244. $this->checkIsHttps();
  1245. }
  1246. // We used to display a warning if PmaAbsoluteUri wasn't set, but now
  1247. // the autodetect code works well enough that we don't display the
  1248. // warning at all. The user can still set PmaAbsoluteUri manually.
  1249. } else {
  1250. // The URI is specified, however users do often specify this
  1251. // wrongly, so we try to fix this.
  1252. // Adds a trailing slash et the end of the phpMyAdmin uri if it
  1253. // does not exist.
  1254. if (substr($pma_absolute_uri, -1) != '/') {
  1255. $pma_absolute_uri .= '/';
  1256. }
  1257. // If URI doesn't start with http:// or https://, we will add
  1258. // this.
  1259. if (substr($pma_absolute_uri, 0, 7) != 'http://'
  1260. && substr($pma_absolute_uri, 0, 8) != 'https://'
  1261. ) {
  1262. $pma_absolute_uri
  1263. = ($is_https ? 'https' : 'http')
  1264. . ':' . (substr($pma_absolute_uri, 0, 2) == '//' ? '' : '//')
  1265. . $pma_absolute_uri;
  1266. }
  1267. }
  1268. $this->set('PmaAbsoluteUri', $pma_absolute_uri);
  1269. }
  1270. /**
  1271. * Converts currently used PmaAbsoluteUri to SSL based variant.
  1272. *
  1273. * @return String witch adjusted URI
  1274. */
  1275. function getSSLUri()
  1276. {
  1277. // grab current URL
  1278. $url = $this->get('PmaAbsoluteUri');
  1279. // Parse current URL
  1280. $parsed = parse_url($url);
  1281. // In case parsing has failed do stupid string replacement
  1282. if ($parsed === false) {
  1283. // Replace http protocol
  1284. return preg_replace('@^http:@', 'https:', $url);
  1285. }
  1286. // Reconstruct URL using parsed parts
  1287. return 'https://' . $parsed['host'] . ':443' . $parsed['path'];
  1288. }
  1289. /**
  1290. * check selected collation_connection
  1291. *
  1292. * @todo check validity of $_REQUEST['collation_connection']
  1293. *
  1294. * @return void
  1295. */
  1296. function checkCollationConnection()
  1297. {
  1298. if (! empty($_REQUEST['collation_connection'])) {
  1299. $this->set(
  1300. 'collation_connection',
  1301. strip_tags($_REQUEST['collation_connection'])
  1302. );
  1303. }
  1304. }
  1305. /**
  1306. * checks for font size configuration, and sets font size as requested by user
  1307. *
  1308. * @return void
  1309. */
  1310. function checkFontsize()
  1311. {
  1312. $new_fontsize = '';
  1313. if (isset($_GET['set_fontsize'])) {
  1314. $new_fontsize = $_GET['set_fontsize'];
  1315. } elseif (isset($_POST['set_fontsize'])) {
  1316. $new_fontsize = $_POST['set_fontsize'];
  1317. } elseif (isset($_COOKIE['pma_fontsize'])) {
  1318. $new_fontsize = $_COOKIE['pma_fontsize'];
  1319. }
  1320. if (preg_match('/^[0-9.]+(px|em|pt|\%)$/', $new_fontsize)) {
  1321. $this->set('fontsize', $new_fontsize);
  1322. } elseif (! $this->get('fontsize')) {
  1323. // 80% would correspond to the default browser font size
  1324. // of 16, but use 82% to help read the monoface font
  1325. $this->set('fontsize', '82%');
  1326. }
  1327. $this->setCookie('pma_fontsize', $this->get('fontsize'), '82%');
  1328. }
  1329. /**
  1330. * checks if upload is enabled
  1331. *
  1332. * @return void
  1333. */
  1334. function checkUpload()
  1335. {
  1336. if (ini_get('file_uploads')) {
  1337. $this->set('enable_upload', true);
  1338. // if set "php_admin_value file_uploads Off" in httpd.conf
  1339. // ini_get() also returns the string "Off" in this case:
  1340. if ('off' == strtolower(ini_get('file_uploads'))) {
  1341. $this->set('enable_upload', false);
  1342. }
  1343. } else {
  1344. $this->set('enable_upload', false);
  1345. }
  1346. }
  1347. /**
  1348. * Maximum upload size as limited by PHP
  1349. * Used with permission from Moodle (http://moodle.org) by Martin Dougiamas
  1350. *
  1351. * this section generates $max_upload_size in bytes
  1352. *
  1353. * @return void
  1354. */
  1355. function checkUploadSize()
  1356. {
  1357. if (! $filesize = ini_get('upload_max_filesize')) {
  1358. $filesize = "5M";
  1359. }
  1360. if ($postsize = ini_get('post_max_size')) {
  1361. $this->set(
  1362. 'max_upload_size',
  1363. min(PMA_getRealSize($filesize), PMA_getRealSize($postsize))
  1364. );
  1365. } else {
  1366. $this->set('max_upload_size', PMA_getRealSize($filesize));
  1367. }
  1368. }
  1369. /**
  1370. * check for https
  1371. *
  1372. * @return void
  1373. */
  1374. function checkIsHttps()
  1375. {
  1376. $this->set('is_https', $this->isHttps());
  1377. }
  1378. /**
  1379. * Checks if protocol is https
  1380. *
  1381. * This function checks if the https protocol is used in the PmaAbsoluteUri
  1382. * configuration setting, as opposed to detectHttps() which checks if the
  1383. * https protocol is used on the active connection.
  1384. *
  1385. * @return bool
  1386. */
  1387. public function isHttps()
  1388. {
  1389. static $is_https = null;
  1390. if (null !== $is_https) {
  1391. return $is_https;
  1392. }
  1393. $url = parse_url($this->get('PmaAbsoluteUri'));
  1394. if (isset($url['scheme']) && $url['scheme'] == 'https') {
  1395. $is_https = true;
  1396. } else {
  1397. $is_https = false;
  1398. }
  1399. return $is_https;
  1400. }
  1401. /**
  1402. * Detects whether https appears to be used.
  1403. *
  1404. * This function checks if the https protocol is used in the current connection
  1405. * with the webserver, based on environment variables.
  1406. * Please note that this just detects what we see, so
  1407. * it completely ignores things like reverse proxies.
  1408. *
  1409. * @return bool
  1410. */
  1411. function detectHttps()
  1412. {
  1413. $is_https = false;
  1414. $url = array();
  1415. // At first we try to parse REQUEST_URI, it might contain full URL,
  1416. if (PMA_getenv('REQUEST_URI')) {
  1417. // produces E_WARNING if it cannot get parsed, e.g. '/foobar:/'
  1418. $url = @parse_url(PMA_getenv('REQUEST_URI'));
  1419. if ($url === false) {
  1420. $url = array();
  1421. }
  1422. }
  1423. // If we don't have scheme, we didn't have full URL so we need to
  1424. // dig deeper
  1425. if (empty($url['scheme'])) {
  1426. // Scheme
  1427. if (PMA_getenv('HTTP_SCHEME')) {
  1428. $url['scheme'] = PMA_getenv('HTTP_SCHEME');
  1429. } elseif (PMA_getenv('HTTPS')
  1430. && strtolower(PMA_getenv('HTTPS')) == 'on'
  1431. ) {
  1432. $url['scheme'] = 'https';
  1433. // A10 Networks load balancer:
  1434. } elseif (PMA_getenv('HTTP_HTTPS_FROM_LB')
  1435. && strtolower(PMA_getenv('HTTP_HTTPS_FROM_LB')) == 'on') {
  1436. $url['scheme'] = 'https';
  1437. } elseif (PMA_getenv('HTTP_X_FORWARDED_PROTO')) {
  1438. $url['scheme'] = strtolower(PMA_getenv('HTTP_X_FORWARDED_PROTO'));
  1439. } elseif (PMA_getenv('HTTP_FRONT_END_HTTPS')
  1440. && strtolower(PMA_getenv('HTTP_FRONT_END_HTTPS')) == 'on'
  1441. ) {
  1442. $url['scheme'] = 'https';
  1443. } else {
  1444. $url['scheme'] = 'http';
  1445. }
  1446. }
  1447. if (isset($url['scheme']) && $url['scheme'] == 'https') {
  1448. $is_https = true;
  1449. } else {
  1450. $is_https = false;
  1451. }
  1452. return $is_https;
  1453. }
  1454. /**
  1455. * detect correct cookie path
  1456. *
  1457. * @return void
  1458. */
  1459. function checkCookiePath()
  1460. {
  1461. $this->set('cookie_path', $this->getCookiePath());
  1462. }
  1463. /**
  1464. * Get cookie path
  1465. *
  1466. * @return string
  1467. */
  1468. public function getCookiePath()
  1469. {
  1470. static $cookie_path = null;
  1471. if (null !== $cookie_path && !defined('TESTSUITE')) {
  1472. return $cookie_path;
  1473. }
  1474. $parsed_url = parse_url($this->get('PmaAbsoluteUri'));
  1475. $cookie_path = $parsed_url['path'];
  1476. return $cookie_path;
  1477. }
  1478. /**
  1479. * enables backward compatibility
  1480. *
  1481. * @return void
  1482. */
  1483. function enableBc()
  1484. {
  1485. $GLOBALS['cfg'] = $this->settings;
  1486. $GLOBALS['default_server'] = $this->default_server;
  1487. unset($this->default_server);
  1488. $GLOBALS['collation_connection'] = $this->get('collation_connection');
  1489. $GLOBALS['is_upload'] = $this->get('enable_upload');
  1490. $GLOBALS['max_upload_size'] = $this->get('max_upload_size');
  1491. $GLOBALS['cookie_path'] = $this->get('cookie_path');
  1492. $GLOBALS['is_https'] = $this->get('is_https');
  1493. $defines = array(
  1494. 'PMA_VERSION',
  1495. 'PMA_THEME_VERSION',
  1496. 'PMA_THEME_GENERATION',
  1497. 'PMA_PHP_STR_VERSION',
  1498. 'PMA_PHP_INT_VERSION',
  1499. 'PMA_IS_WINDOWS',
  1500. 'PMA_IS_IIS',
  1501. 'PMA_IS_GD2',
  1502. 'PMA_USR_OS',
  1503. 'PMA_USR_BROWSER_VER',
  1504. 'PMA_USR_BROWSER_AGENT'
  1505. );
  1506. foreach ($defines as $define) {
  1507. if (! defined($define)) {
  1508. define($define, $this->get($define));
  1509. }
  1510. }
  1511. }
  1512. /**
  1513. * returns options for font size selection
  1514. *
  1515. * @param string $current_size current selected font size with unit
  1516. *
  1517. * @return array selectable font sizes
  1518. *
  1519. * @static
  1520. */
  1521. static protected function getFontsizeOptions($current_size = '82%')
  1522. {
  1523. $unit = preg_replace('/[0-9.]*/', '', $current_size);
  1524. $value = preg_replace('/[^0-9.]*/', '', $current_size);
  1525. $factors = array();
  1526. $options = array();
  1527. $options["$value"] = $value . $unit;
  1528. if ($unit === '%') {
  1529. $factors[] = 1;
  1530. $factors[] = 5;
  1531. $factors[] = 10;
  1532. } elseif ($unit === 'em') {
  1533. $factors[] = 0.05;
  1534. $factors[] = 0.2;
  1535. $factors[] = 1;
  1536. } elseif ($unit === 'pt') {
  1537. $factors[] = 0.5;
  1538. $factors[] = 2;
  1539. } elseif ($unit === 'px') {
  1540. $factors[] = 1;
  1541. $factors[] = 5;
  1542. $factors[] = 10;
  1543. } else {
  1544. //unknown font size unit
  1545. $factors[] = 0.05;
  1546. $factors[] = 0.2;
  1547. $factors[] = 1;
  1548. $factors[] = 5;
  1549. $factors[] = 10;
  1550. }
  1551. foreach ($factors as $key => $factor) {
  1552. $option_inc = $value + $factor;
  1553. $option_dec = $value - $factor;
  1554. while (count($options) < 21) {
  1555. $options["$option_inc"] = $option_inc . $unit;
  1556. if ($option_dec > $factors[0]) {
  1557. $options["$option_dec"] = $option_dec . $unit;
  1558. }
  1559. $option_inc += $factor;
  1560. $option_dec -= $factor;
  1561. if (isset($factors[$key + 1])
  1562. && $option_inc >= $value + $factors[$key + 1]
  1563. ) {
  1564. break;
  1565. }
  1566. }
  1567. }
  1568. ksort($options);
  1569. return $options;
  1570. }
  1571. /**
  1572. * returns html selectbox for font sizes
  1573. *
  1574. * @static
  1575. *
  1576. * @return string html selectbox
  1577. */
  1578. static protected function getFontsizeSelection()
  1579. {
  1580. $current_size = $GLOBALS['PMA_Config']->get('fontsize');
  1581. // for the case when there is no config file (this is supported)
  1582. if (empty($current_size)) {
  1583. if (isset($_COOKIE['pma_fontsize'])) {
  1584. $current_size = htmlspecialchars($_COOKIE['pma_fontsize']);
  1585. } else {
  1586. $current_size = '82%';
  1587. }
  1588. }
  1589. $options = PMA_Config::getFontsizeOptions($current_size);
  1590. $return = '<label for="select_fontsize">' . __('Font size')
  1591. . ':</label>' . "\n"
  1592. . '<select name="set_fontsize" id="select_fontsize"'
  1593. . ' class="autosubmit">' . "\n";
  1594. foreach ($options as $option) {
  1595. $return .= '<option value="' . $option . '"';
  1596. if ($option == $current_size) {
  1597. $return .= ' selected="selected"';
  1598. }
  1599. $return .= '>' . $option . '</option>' . "\n";
  1600. }
  1601. $return .= '</select>';
  1602. return $return;
  1603. }
  1604. /**
  1605. * return complete font size selection form
  1606. *
  1607. * @static
  1608. *
  1609. * @return string html selectbox
  1610. */
  1611. static public function getFontsizeForm()
  1612. {
  1613. return '<form name="form_fontsize_selection" id="form_fontsize_selection"'
  1614. . ' method="get" action="index.php" class="disableAjax">' . "\n"
  1615. . PMA_generate_common_hidden_inputs() . "\n"
  1616. . PMA_Config::getFontsizeSelection() . "\n"
  1617. . '</form>';
  1618. }
  1619. /**
  1620. * removes cookie
  1621. *
  1622. * @param string $cookie name of cookie to remove
  1623. *
  1624. * @return boolean result of setcookie()
  1625. */
  1626. function removeCookie($cookie)
  1627. {
  1628. if (defined('TESTSUITE')) {
  1629. if (isset($_COOKIE[$cookie])) {
  1630. unset($_COOKIE[$cookie]);
  1631. }
  1632. return true;
  1633. }
  1634. return setcookie(
  1635. $cookie,
  1636. '',
  1637. time() - 3600,
  1638. $this->getCookiePath(),
  1639. '',
  1640. $this->isHttps()
  1641. );
  1642. }
  1643. /**
  1644. * sets cookie if value is different from current cookie value,
  1645. * or removes if value is equal to default
  1646. *
  1647. * @param string $cookie name of cookie to remove
  1648. * @param mixed $value new cookie value
  1649. * @param string $default default value
  1650. * @param int $validity validity of cookie in seconds (default is one month)
  1651. * @param bool $httponly whether cookie is only for HTTP (and not for scripts)
  1652. *
  1653. * @return boolean result of setcookie()
  1654. */
  1655. function setCookie($cookie, $value, $default = null, $validity = null,
  1656. $httponly = true
  1657. ) {
  1658. if (strlen($value) && null !== $default && $value === $default) {
  1659. // default value is used
  1660. if (isset($_COOKIE[$cookie])) {
  1661. // remove cookie
  1662. return $this->removeCookie($cookie);
  1663. }
  1664. return false;
  1665. }
  1666. if (! strlen($value) && isset($_COOKIE[$cookie])) {
  1667. // remove cookie, value is empty
  1668. return $this->removeCookie($cookie);
  1669. }
  1670. if (! isset($_COOKIE[$cookie]) || $_COOKIE[$cookie] !== $value) {
  1671. // set cookie with new value
  1672. /* Calculate cookie validity */
  1673. if ($validity === null) {
  1674. $validity = time() + 2592000;
  1675. } elseif ($validity == 0) {
  1676. $validity = 0;
  1677. } else {
  1678. $validity = time() + $validity;
  1679. }
  1680. if (defined('TESTSUITE')) {
  1681. $_COOKIE[$cookie] = $value;
  1682. return true;
  1683. }
  1684. return setcookie(
  1685. $cookie,
  1686. $value,
  1687. $validity,
  1688. $this->getCookiePath(),
  1689. '',
  1690. $this->isHttps(),
  1691. $httponly
  1692. );
  1693. }
  1694. // cookie has already $value as value
  1695. return true;
  1696. }
  1697. }
  1698. ?>