22 Commits
v1.0 ... v1.3

Author SHA1 Message Date
85f5824f7b Added more descriptive error messages for three cases. 2022-04-13 13:49:22 +02:00
9bff04b518 Fixed missing change of maximum length of list name for the save list procedure 2022-04-13 13:45:38 +02:00
e995eb6648 Changed maximum length of list name from 30 to 50 chars 2022-02-12 21:20:50 +01:00
82ff17132d Final commit for v1.2, forgot to save edit_list, resolved issues #4 and #6 2022-02-01 13:40:47 +01:00
d7621582da Added display of list owners and list descriptions on index page, Added save function for list description 2022-02-01 13:31:41 +01:00
fcd2a0e395 Version bump to v1.2 2022-02-01 13:12:52 +01:00
b4cd6b8628 Security check if list parameter is not set for edit_list and save_list 2022-02-01 13:12:28 +01:00
15482bf028 Merge branch 'master' into v1.2 2022-02-01 10:31:35 +01:00
Christian Süßenguth
8524670e59 „README.md“ ändern 2021-11-25 13:55:13 +01:00
Christian Süßenguth
834ba43292 „ROADMAP.md“ ändern 2021-11-25 13:53:41 +01:00
b79f0e1844 Updated README 2021-11-25 13:37:18 +01:00
35b510fd16 Automatically sort subscribers and moderators alphabetically on page load 2021-11-25 13:24:24 +01:00
6edf9a6d47 Added an info box regarding the needed user consent fixes #7 2021-11-25 13:16:52 +01:00
2717d1fd90 Slightly text change in consent notice 2021-11-25 13:02:58 +01:00
2231b80846 Get and display list description if you edit a list (Preparation for #6) 2021-10-28 13:40:15 +02:00
82741bc121 Added functionality to sort and count lines of subs and mods (#2 and #3) 2021-10-28 13:10:18 +02:00
bbb3f35767 Fixed bug #5 2021-10-28 12:33:53 +02:00
ead32ad051 Switched to version 1.1 2021-10-28 12:31:27 +02:00
4c8137281c Merge branch 'master' of https://git.ecogood.org/services/mlmmj-light-web-ecg 2021-10-28 12:22:17 +02:00
Christian Süßenguth
9a9ae1d350 „ROADMAP.md“ ändern 2021-10-27 15:14:10 +02:00
10df9b50dd Removed unnecessary files, Added autofocus to login form 2021-08-23 12:09:32 +02:00
e7d5a4b981 Added error handling of missing ldap server connection and audit message for failed login 2021-08-18 18:02:56 +02:00
19 changed files with 143 additions and 4843 deletions

View File

@@ -13,7 +13,9 @@ A light PHP web interface for managing [mlmmj](http://mlmmj.org/) mailing lists.
### For users
- Authentication via LDAP
- List all available mailinglists on the server
- Display owners and listdescription of the respective mailing lists on the index page
- Only show the edit function for mailing lists where the user is set as owner
- Edit functions per mailing list: subscribers, moderators, prefix and listdescription
### For admins
- Error handling regarding invalid user input
@@ -69,7 +71,9 @@ Check if the values from `init.php` are still valid or need to be adapted.
## Changelog
v1.0 - Initial release (08/13/2021)
[v1.2](https://git.ecogood.org/services/mlmmj-light-web-ecg/releases/tag/v1.2) - Version 1.2 (2022-02-01)
[v1.1](https://git.ecogood.org/services/mlmmj-light-web-ecg/releases/tag/v1.1) - Version 1.1 (2021-11-25)
[v1.0](https://git.ecogood.org/services/mlmmj-light-web-ecg/releases/tag/v1.0) - Initial release (2021-08-13)
## Roadmap

View File

@@ -1,15 +1,3 @@
# ROADMAP
Updated at: 08/13/2021
## v1.1
nothing there yet
## Feature wishes
- [ ] Automatically put square brackets around the prefix `[prefix]`
- [ ] Count number of subscribers and moderators in the text areas
- [ ] Allow admins to edit all mailing lists
- [ ] Check for duplicates in the subscriber / moderator text area
- [ ] Allow users to subscribe to a list by clicking a button
- [ ] Show the list-description
- [ ] Someone enters his email address into an input field and gets an email with all mailing lists he is subscribed to
refer to [Milestones](https://git.ecogood.org/services/mlmmj-light-web-ecg/milestones)

View File

@@ -13,23 +13,24 @@ if (!isset($_SESSION["auth"]) || $_SESSION["auth"] != 1)
exit();
}
// We do not print any error in the next three cases, because a legitimate
// user will never produce such results, even with disabled javascript
if ( preg_match("/[^a-z0-9_-]/", $list_name) )
{
$_SESSION["error_code"] = 14;
header("Location: error.php");
exit();
}
if ( strlen($list_name) > 30 )
if ( strlen($list_name) > 50 )
{
$_SESSION["error_code"] = 13;
header("Location: error.php");
exit();
}
// Test list existence
if( !is_dir("$lists_path/$domain/$list_name") )
if( !is_dir("$lists_path/$domain/$list_name") || $list_name == "" )
{
$_SESSION["error_code"] = 12;
header("Location: error.php");
exit();
}
@@ -71,6 +72,20 @@ $prefix = file_get_contents("$lists_path/$domain/$list_name/control/prefix");
// Remove trailing empty symbols
$prefix = trim($prefix);
# Check whether there is a listdescription file
if (file_exists("$lists_path/$domain/$list_name/control/listdescription"))
{
// Get list description
$listdescription = file_get_contents("$lists_path/$domain/$list_name/control/listdescription");
// Remove trailing empty symbols
$listdescription = trim($listdescription);
}
else
{
$listdescription = NULL;
}
// Load page
$smarty->assign("headline", $headline);
$smarty->assign("web_url", $web_url);
@@ -79,6 +94,7 @@ $smarty->assign("list_name", $list_name);
$smarty->assign("domain", $domain);
$smarty->assign("moderators", $moderators);
$smarty->assign("prefix", $prefix);
$smarty->assign("listdescription", $listdescription);
$smarty->assign("username", $_SESSION["username"]);
$smarty->assign("success", $success);
$smarty->display("edit_list.tpl");

View File

@@ -1,5 +1,8 @@
<?php
# Scan loading time
$time_start = microtime(true);
require("init.php");
if (!isset($_SESSION["auth"]) || $_SESSION["auth"] != 1)
@@ -27,16 +30,40 @@ if (isset($lists))
}
$lists_new = [];
# Iterate through all lists
foreach($lists as $list)
{
# If list is in array of owned lists
if (!in_array($list, $_SESSION["array_lists_owned"]))
{
$lists_new[$list] = 0;
$lists_new[$list]["iamowner"] = 0;
}
else
{
$lists_new[$list] = 1;
$lists_new[$list]["iamowner"] = 1;
}
# Get the owners of the list and put them into the array
$owners = explode("\n", trim(shell_exec("/usr/bin/mlmmj-list -o -L $lists_path/$domain/$list")));
$lists_new[$list]["owners"] = $owners;
# Check whether there is a listdescription file
if (file_exists("$lists_path/$domain/$list/control/listdescription") && @file_get_contents("$lists_path/$domain/$list/control/listdescription") != "")
{
// Get list description
$listdescription = file_get_contents("$lists_path/$domain/$list/control/listdescription");
// Remove trailing empty symbols
$listdescription = trim($listdescription);
}
else
{
# Set listdescription to none
$listdescription = "none";
}
# Add the listdescription to the array
$lists_new[$list]["description"] = $listdescription;
}
}
else
@@ -44,11 +71,18 @@ else
$lists = NULL;
}
# Scan loading time
$time_end = microtime(true);
# Calculate loading time
$loadingtime = round(($time_end - $time_start), 2);
$smarty->assign("headline", $headline);
$smarty->assign("web_url", $web_url);
$smarty->assign("lists", $lists_new);
$smarty->assign("domain", $domain);
$smarty->assign("username", $_SESSION["username"]);
$smarty->assign("loadingtime", $loadingtime);
$smarty->display("index.tpl");
?>

1
info.svg Normal file
View File

@@ -0,0 +1 @@
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 64 64" enable-background="new 0 0 64 64"><path d="m32 2c-16.568 0-30 13.432-30 30s13.432 30 30 30 30-13.432 30-30-13.432-30-30-30m5 49.75h-10v-24h10v24m-5-29.5c-2.761 0-5-2.238-5-5s2.239-5 5-5c2.762 0 5 2.238 5 5s-2.238 5-5 5" fill="#dddddd"/></svg>

After

Width:  |  Height:  |  Size: 303 B

View File

@@ -22,7 +22,7 @@ $domain_global = "mlmmj";
$rc_webhook = "";
# No need to change this values
$current_version = "v1.0";
$current_version = "v1.2";
$headline = "Manage your ECG mailing lists " . $current_version;
$debug = false;

View File

@@ -18,7 +18,20 @@ if (!empty($login_username) && !empty($login_pass))
$ldap_server = "localhost";
$ldap_port = 30389;
$connect = ldap_connect($ldap_server, $ldap_port); #or die("Failed to connect to the LDAP server.");
$connect = ldap_connect($ldap_server, $ldap_port);
if (!$connect)
{
# If debug mode is on show error message
if ($debug)
{
echo "Failed to connect to the LDAP server.";
}
else
{
shell_exec('curl -X POST -H \'Content-Type: application/json\' --data \'{"alias":"ECG Notification Bot","emoji":":ghost:","text":"Failed to connect to the LDAP server."}\' https://chat.ecogood.org/hooks/A' . $rc_webhook);
}
exit;
}
ldap_set_option($connect, LDAP_OPT_PROTOCOL_VERSION, 3);
ldap_set_option($connect, LDAP_OPT_REFERRALS, 0);
@@ -26,7 +39,7 @@ if (!empty($login_username) && !empty($login_pass))
# bind user
$auth_user = "uid=" . $login_username . ",ou=users,ou=ecg";
$auth_pass = $login_pass;
$bind = ldap_bind($connect, $auth_user, $auth_pass); #or die("Failed to bind to LDAP server.");
$bind = ldap_bind($connect, $auth_user, $auth_pass);
# If the bind was successfull
if ($bind)
@@ -49,7 +62,7 @@ if (!empty($login_username) && !empty($login_pass))
# If debug mode is on show error message
if ($debug)
{
echo $return["message"];
echo $return["message"];
}
else
{
@@ -62,6 +75,9 @@ if (!empty($login_username) && !empty($login_pass))
}
else
{
# Send audit message on failed login
shell_exec('curl -X POST -H \'Content-Type: application/json\' --data \'{"alias":"ECG Notification Bot","emoji":":ghost:","text":"Login failed: ' . $login_username . ' (' . $_SERVER["REMOTE_ADDR"] . ')"}\' https://chat.ecogood.org/hooks/' . $rc_webhook);
// Incorrect password
$_SESSION["error_code"] = 3;
header("Location: error.php");

File diff suppressed because it is too large Load Diff

View File

@@ -1,2 +0,0 @@
if $message_body contains "DISCARD_THIS_MAIL" and not error_message
then seen finish endif

View File

@@ -1,14 +0,0 @@
all: foot_filter
dev: tags splint foot_filter
.PHONY: splint clean clobber
tags: foot_filter.c
ctags --excmd=number '--regex-c=-/\*[[:blank:]]*tag:[[:blank:]]*([[:alnum:]_]+)-\1-' foot_filter.c
splint:
splint +unixlib -exitarg -initallelements foot_filter.c
foot_filter: foot_filter.c
gcc -Wall -g -o foot_filter foot_filter.c -O3
clean:
-rm tags
clobber: clean
-rm foot_filter
-rm test

File diff suppressed because it is too large Load Diff

View File

@@ -1,8 +0,0 @@
#!/bin/bash
#
# mlmmj-footer-receive
#
# Adds the footer to incoming message
#
/usr/bin/foot_filter -P /$1/$2/control/footer-text -H /$1/$2/control/footer-html | /usr/bin/mlmmj-receive -F -L /$1/$2/

Binary file not shown.

Before

Width:  |  Height:  |  Size: 25 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

View File

@@ -44,7 +44,7 @@
//{/literal}
</script>
</head>
<body>
<body onload="document.getElementById('subscribers').value = document.getElementById('subscribers').value.split('\n').sort().join('\n'); document.getElementById('moderators').value = document.getElementById('moderators').value.split('\n').sort().join('\n');">
<div id="header">
<div id="header_left">
<a href="{$web_url}">{$headline}</a>
@@ -56,6 +56,9 @@
<div id="breadcrumbs">
<a href="index.php">Home</a>&nbsp;/&nbsp;{$list_name}
</div>
<div style="width: 75%; border: 2px solid #000; margin: 0 auto 30px; text-align: center; padding: 20px; border-radius: 10px; background-color: #FFF7A4; border-color: #C1AE00;">
Please be aware that you need the user's consent to receive mails from the list <strong>before</strong> you add him to the list of subscribers.<br />This tool <strong>won't send a double opt-in message</strong> to new subscribers automatically.
</div>
{if $success eq true}<p class="success">List was successfully updated.</p>{/if}
<form method="post" action="save_list.php" id="save_list" onsubmit="return validate_form()">
<div id="edit_page">
@@ -66,9 +69,10 @@
<div class="tooltip">
<img src="help.svg" width=15 height=15>
<span class="help_sub">
Please provide one email address per line.<br /><br />Please be aware that you need the user's consent to receive mails from the list <strong>before</strong> you add him to the list of subscribers. This tool won't send a double opt-in message to new subscribers.
Please provide one email address per line.<br /><br />Please be aware that you need the user's consent to receive mails from the list <strong>before</strong> you add him to the list of subscribers. This tool won't send a double opt-in message to new subscribers automatically.
</span>
</div>
&nbsp;|&nbsp;<a href="#" onclick="document.getElementById('subscribers').value = document.getElementById('subscribers').value.split('\n').sort().join('\n'); alert('Subscribers list has been sorted alphabetically.');">A-Z</a>&nbsp;|&nbsp;<a href="#" onclick="alert('Current subscribers count: ' + document.getElementById('subscribers').value.trim().split('\n').length);">Count</a>
</div>
<div id="subscribers_body">
<textarea name="subscribers" id="subscribers">{$subscribers}</textarea>
@@ -95,6 +99,22 @@
</td>
</tr>
</table>
<table style="width: 100%; text-align: center; margin-top: 50px; padding: 0 25px 0 25px;">
<tr>
<td colspan="2">
<div id="listdescription_header">
<div class="tooltip">
<img src="help.svg" width=15 height=15>
<span class="help_prefix">
This is the list description which is displayed in the overview.<br /><br />Can be left blank.
</span>
</div>
&nbsp;List description:
</div>
<textarea name="listdescription" id="listdescription" style="height: 100%; width: 100%;">{$listdescription|escape:'htmlall'}</textarea>
</td>
</tr>
</table>
</div>
<div id="save_btn">
<input type="submit" name="submit" value="Save">
@@ -112,6 +132,7 @@
In case of a moderated list the messages will be send to these recipients before they get published to the list.<br /><br />Please be aware that you need the user's consent to receive mails from the list <strong>before</strong> you add him to the list of moderators. This tool won't send a double opt-in message to new moderators.
</span>
</div>
&nbsp;|&nbsp;<a href="#" onclick="document.getElementById('moderators').value = document.getElementById('moderators').value.split('\n').sort().join('\n'); alert('Moderators list has been sorted alphabetically.');">A-Z</a>&nbsp;|&nbsp;<a href="#" onclick="alert('Current moderators count: ' + document.getElementById('moderators').value.trim().split('\n').length);">Count</a>
</div>
<div id="moderators_body">
<textarea name="moderators" id="moderators">{$moderators}</textarea>

View File

@@ -36,6 +36,12 @@
There is an incorrect email in the moderators list.
{elseif $error_code == 11}
You do not own this list.
{elseif $error_code == 12}
The list does not exist within the mlmmj working folder.
{elseif $error_code == 13}
The list name exceeds the maximum length of 50 chars.
{elseif $error_code == 14}
The list name contains chars which are not allowed.
{else}
Unknown error.
{/if}

View File

@@ -58,13 +58,19 @@
</tr>
{foreach $lists as $list}
{if $list == 1}
{if $list.iamowner == 1}
<tr>
<td>
&check;
</td>
<td>
<a href="edit_list.php?list_name={$list@key}">{$list@key}</a>
<div class="tooltip">
<img src="info.svg" width=15 height=15>
<span class="help_add_list">
<strong>Description</strong><br />{$list.description}<br /><br /><strong>List owner(s)</strong><br />{foreach $list.owners as $owner}{$owner}<br />{/foreach}
</span>
</div>
</td>
</tr>
{/if}
@@ -94,18 +100,26 @@
</tr>
{foreach $lists as $list}
{if $list == 0}
{if $list.iamowner == 0}
<tr>
<td>
&cross;
</td>
<td>
{$list@key}
<div class="tooltip">
<img src="info.svg" width=15 height=15>
<span class="help_add_list">
<strong>Description</strong><br />{$list.description}<br /><br /><strong>List owner(s)</strong><br />{foreach $list.owners as $owner}{$owner}<br />{/foreach}
</span>
</div>
</td>
</tr>
{/if}
{/foreach}
</table>
<br />
<span>Loading time: {$loadingtime} seconds</span>
</div>
</body>
</html>

View File

@@ -42,7 +42,7 @@
Username:
</div>
<div id="username_right">
<input type="text" name="login_username" id="username_input">
<input type="text" name="login_username" id="username_input" autofocus>
</div>
</div>
<div id="password">

View File

@@ -19,6 +19,7 @@ function trim_array($arr)
$list_name = isset( $_POST["list_name"] ) ? $_POST["list_name"] : NULL;
$prefix = isset ( $_POST["prefix"] ) ? $_POST["prefix"] : NULL;
$listdescription = isset ( $_POST["listdescription"] ) ? $_POST["listdescription"] : NULL;
$new_subscribers = isset ( $_POST["subscribers"] ) ? $_POST["subscribers"] : NULL;
$moderators = isset ( $_POST["moderators"] ) ? $_POST["moderators"] : NULL;
@@ -31,23 +32,24 @@ if ( !isset($_SESSION["auth"]) || $_SESSION["auth"] != 1 )
$domain = $_SESSION["domain"];
// We do not print any error in the next four cases, because a legitimate
// user will never produce such results, even with disabled javascript
if ( preg_match("/[^a-z0-9_-]/", $list_name) )
{
$_SESSION["error_code"] = 14;
header("Location: error.php");
exit();
}
if ( strlen($list_name) > 30 )
if ( strlen($list_name) > 50 )
{
$_SESSION["error_code"] = 13;
header("Location: error.php");
exit();
}
// Test list existence
if( !is_dir("$lists_path/$domain/$list_name") )
if( !is_dir("$lists_path/$domain/$list_name") || $list_name == "" )
{
$_SESSION["error_code"] = 12;
header("Location: error.php");
exit();
}
@@ -89,7 +91,7 @@ if ($new_subscribers != NULL)
header("Location: error.php");
exit();
}
shell_exec("/usr/bin/mlmmj-sub -L $lists_path/$domain/$list_name -a $new_subscriber -fq");
shell_exec("/usr/bin/mlmmj-sub -L $lists_path/$domain/$list_name -a $new_subscriber -fsq");
}
}
@@ -158,11 +160,18 @@ if ($moderators !== NULL)
}
}
# Add prefix to the respective file
if ($prefix !== NULL)
{
file_put_contents("$lists_path/$domain/$list_name/control/prefix", "$prefix");
}
# Add listdescription to the respective file
if ($listdescription !== NULL)
{
file_put_contents("$lists_path/$domain/$list_name/control/listdescription", "$listdescription");
}
# The following code section is for audit log only
# -------------------------------------------------------------