Просмотр файла setup/index.php

Размер файла: 10.55Kb
  1. <?php
  2. /**********************************
  3. * @package: PerfCMS *
  4. * @year: 2012 *
  5. * @author: Artas *
  6. * @link: http://perfcms.ru *
  7. **********************************/
  8. session_name('PSID');
  9. session_start();
  10. error_reporting(0);
  11. define('SYS', realpath(dirname(__FILE__)).'/system');
  12. $ver = parse_ini_file('../system/ini/system_info.ini');
  13. ?>
  14. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
  15. "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
  16. <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="uk" lang="uk">
  17. <head>
  18. <title>Installing PerfCMS <?=$ver['perfcms_ver'];?></title>
  19. <link href="/template/themes/wap/default/style.css" rel="stylesheet" type="text/css" />
  20. </head>
  21. <body>
  22. <div class="main">
  23. <div class="panel">Installing PerfCMS <?=$ver['perfcms_ver'];?></div>
  24. <?
  25. if(file_exists('../system/ini/db.ini') && !file_exists('../system/ini/install.txt')) {
  26. echo '<div class="post">
  27. PerfCMS already installed!
  28. </div>
  29. <div class="block">
  30. <a href="/">Home Page</a>
  31. </div>';
  32. } else {
  33. if(!isset($_GET['lang'])) {
  34. echo '<div class="post">
  35. Choose Installing language:<br/>
  36. <a href="/setup/?lang=uk">Українська</a><br/>
  37. <a href="/setup/?lang=ru">Русский</a><br/>
  38. <a href="/setup/?lang=en">English</a><br/>
  39. </div>';
  40. }
  41. else
  42. {
  43. if(file_exists('lang/'. trim($_GET['lang']).'.ini')) {
  44. $lang = parse_ini_file('lang/'. trim($_GET['lang']).'.ini');
  45. $lng = trim($_GET['lang']);
  46. } else {
  47. $lang = parse_ini_file('lang/en.ini');
  48. $lng = 'en';
  49. }
  50. if(isset($_GET['lang']) && !isset($_GET['act'])) {
  51. echo '<div class="post">'. $lang['welcome'] .'<br/>
  52. [ <a href="/setup/?act=start&amp;lang='. $lng .'">'. $lang['agree'] .'</a> | <a href="/setup/">'. $lang['nagree'] .'</a> ]</div>';
  53. }
  54. elseif(isset($_GET['lang']) && $_GET['act'] == 'start')
  55. {
  56. $chmods = array('../cache/', '../cache/downloads_images/', '../cache/downloads_jad/', '../files/', '../files/share/', '../files/avatars/', '../files/forum/', '../files/preview/', '../files/downloads/', '../files/downloads_screens/', '../system/ini/', '../system/lang/', '../system/lang/uk/', '../system/lang/en/', '../system/lang/ru/', '../tmp/');
  57. echo '<div class="post">
  58. <table>
  59. <tr>
  60. <td><b>'. $lang['fdir'] .'</b></td>
  61. <td><b>'. $lang['chmods'] .'</b></td>
  62. </tr>
  63. <tr>';
  64. foreach ($chmods as $chmod) {
  65. echo '<tr>
  66. <td>'. str_replace('../', '', $chmod) .'</td>';
  67. if (is_writable(trim($chmod))) {
  68. echo '<td><span style="color: green"><b>OK (777)</b></span></td>';
  69. $err = false;
  70. } else {
  71. echo '<td><span style="color: red">'.$lang['must_chmods'].' 777</span></td>';
  72. $err = TRUE;
  73. }
  74. echo '</tr>';
  75. }
  76. echo '</tr>
  77. </table>
  78. '. ($err == TRUE?'<a href="?act=start&amp;lang='. $lng .'">'.$lang['refresh'].'</a>':'<a href="?act=db&amp;lang='. $lng .'">'.$lang['next'].'</a>') .'
  79. </div>
  80. <div class="block">
  81. <a href="?lang='. $lng .'">'.$lang['back'].'</a>
  82. </div>';
  83. }
  84. elseif(isset($_GET['lang']) && $_GET['act'] == 'db')
  85. {
  86. if (isset($_POST['go'])) {
  87. $host = @htmlspecialchars(trim($_POST['host']));
  88. $user = @htmlspecialchars(trim($_POST['user']));
  89. $pass = @htmlspecialchars(trim($_POST['pass']));
  90. $base = @htmlspecialchars(trim($_POST['base']));
  91. if (empty($host)) $err .= $lang['empty_host'].'<br />';
  92. if (empty($user)) $err .= $lang['empty_user'].'<br />';
  93. if (empty($base)) $err .= $lang['empty_base'].'<br />';
  94. if(!isset($err)) {
  95. try {
  96. $db = new PDO('mysql:dbname='.$_POST['base'].';host='. $_POST['host'], $_POST['user'], $_POST['pass']);
  97. } catch (PDOException $e) {
  98. echo 'Connection failed: ' . $e->getMessage();
  99. }
  100. }
  101. if (!isset($err)) {
  102. $db->query("SET NAMES utf8");
  103. $cini = "host = \"$host\";\n"
  104. ."user = \"$user\";\n"
  105. ."pass = \"$pass\";\n"
  106. ."base = \"$base\";\n";
  107. file_put_contents('../system/ini/db.ini', $cini);
  108. $dump = file_get_contents('./setup.sql');
  109. $queryes = explode('-- --------------------------------------------------------', $dump);
  110. foreach($queryes as $query) {
  111. $db->query(trim($query));
  112. }
  113. echo '<div class="title">'.$lang['c_create'].'</div>
  114. <div class="menu">
  115. '.$lang['after_t'].'<br />
  116. <a href="?act=admin&amp;lang='. $lng .'">'.$lang['next'].'</a>
  117. </div>
  118. <div class="block">
  119. <a href="?act=db&amp;lang='. $lng .'">'.$lang['back'].'</a>
  120. </div>
  121. <div class="footer">PerfCMS '.$ver['perfcms_ver'].', 2012</div>
  122. </div>
  123. </body>
  124. </html>';
  125. exit();
  126. }
  127. }
  128. if (isset($err)) echo '<div class="error">'. $err .'</div>';
  129. echo '<form method="post" action="?act=db&amp;lang='. $lng .'">
  130. <div class="title">'.$lang['connection'].'</div>
  131. <div class="menu">
  132. '.$lang['host'].':<br />
  133. <input type="text" name="host" value="localhost" /><br />
  134. '.$lang['user'].':<br />
  135. <input type="text" name="user" /><br />
  136. '.$lang['pass'].':<br />
  137. <input type="password" name="pass" /><br />
  138. '.$lang['base'].':<br />
  139. <input type="text" name="base" /><br />
  140. <input type="submit" name="go" value="'.$lang['send'].'" />
  141. </div>
  142. </form>
  143. <div class="block">
  144. <a href="?act=start&amp;lang='. $lng .'">'.$lang['back'].'</a>
  145. </div>';
  146. }
  147. elseif(isset($_GET['lang']) && $_GET['act'] == 'admin')
  148. {
  149. if (isset($_POST['reg_admin'])) {
  150. $nick = htmlspecialchars(trim($_POST['nick']));
  151. $name = htmlspecialchars(trim($_POST['name']));
  152. $email = htmlspecialchars(trim($_POST['email']));
  153. $password = htmlspecialchars(trim($_POST['password']));
  154. $password2 = htmlspecialchars(trim($_POST['password2']));
  155. if (empty($nick)) $err .= $lang['no_nick'].'<br />';
  156. if (empty($name)) $err .= $lang['no_name'].'<br />';
  157. if (empty($email)) $err .= $lang['no_email'].'<br />';
  158. if (empty($password)) $err .= $lang['no_pass'].'<br />';
  159. if (empty($password2)) $err .= $lang['no_pass2'].'<br />';
  160. if (!empty($nick) && (mb_strlen($nick, 'UTF-8') < 3 || mb_strlen($nick, 'UTF-8') > 32)) $err .= $lang['e_nick'].'<br />';
  161. if (!empty($nick) && !preg_match("#^([A-zА-я0-9\-\_\ ])+$#ui", $nick)) $err .= $lang['b_nick'].'<br />';
  162. if (!empty($name) && (mb_strlen($name, 'UTF-8') > 32)) $err .= $lang['e_name'].'<br />';
  163. if (!empty($email) && (mb_strlen($email, 'UTF-8') < 3 || mb_strlen($email, 'UTF-8') > 72)) $err .= $lang['b_mail'].'<br />';
  164. if (!empty($email) && !preg_match('|^([a-z0-9_\.\-]{1,20})@([a-z0-9\.\-]{1,20})\.([a-z]{2,4})$|ius', $email)) $err .= $lang['e_email'].'<br />';
  165. if (!empty($password) && (mb_strlen($password, 'UTF-8') < 5 || mb_strlen($password, 'UTF-8') > 64)) $err .= $lang['e_pass'].'<br />';
  166. if (!empty($password) && !empty($password2) && $password != $password2) $err .= $lang['e_pass2'].'<br />';
  167. if (!isset($err)) {
  168.  
  169. function crypto($var) {
  170. return md5(base64_encode($var) .'_PerfCMS_');
  171. }
  172. # Кодуємо пароль
  173. $password = crypto($password);
  174. $mysql = parse_ini_file('../system/ini/db.ini');
  175. try {
  176. $db = new PDO('mysql:dbname='.$mysql['base'].';host='. $mysql['host'], $mysql['user'], $mysql['pass']);
  177. } catch (PDOException $e) {
  178. echo 'Connection failed: ' . $e->getMessage();
  179. }
  180. $db->query("SET NAMES utf8");
  181. function escape($inp)
  182. {
  183. if(is_array($inp))
  184. return array_map(__METHOD__, $inp);
  185.  
  186. if(!empty($inp) && is_string($inp)) {
  187. return str_replace(array('\\', "\0", "\n", "\r", "'", '"', "\x1a"), array('\\', '\0', '\n', '\r', "\'", '\"', '\Z'), $inp);
  188. }
  189.  
  190. return $inp;
  191. }
  192. # Запит на реєстрацію
  193. $db->query("INSERT INTO `users` SET `name` = '". escape(trim($name)) ."', `nick` = '". escape(trim($nick)) ."', `password` = '". escape(trim($password)) ."', `reg_time` = '". time() ."', `time` = '". time() ."', `email` = '". escape(trim($email)) ."', `level` = '7', `gender`='0'");
  194. $language = $lng;
  195. $db->query("INSERT INTO `settings` SET `user_id` = '". $db->lastInsertId() ."', `lang` = '". $language ."', `ames` = '10', `theme` = 'default', `web_theme` = 'default', `fast_mess` = 'no', `view_profile` = 'all', `show_email` = 'no', `timezone` = 'Europe/Kiev'");
  196. $db->query("UPDATE `system` SET `lang` = '$language'");
  197. // print_r($db->errorInfo());
  198. unlink('../system/ini/install.txt');
  199. session_destroy();
  200. echo '<div class="title">'.$lang['end_i'].'</div>
  201. <div class="menu">
  202. '.$lang['end_i_t'].' <b>/setup/</b>.<br />
  203. <a href="/sign_in/?nick='. $nick .'&amp;password='. $password2 .'">'.$lang['go_site'].'</a>
  204. </div>
  205. <div class="block">
  206. <a href="?act=admin&amp;lang='. $lng .'">'.$lang['back'].'</a>
  207. </div>
  208. </div>
  209. <div class="footer">PerfCMS '.$ver['perfcms_ver'].', 2012</div>
  210. </div>
  211. </body>
  212. </html>';
  213. exit();
  214. }
  215. }
  216. if (isset($err)) echo '<div class="err">'. $err .'</div>';
  217. echo '<form method="post" action="?act=admin&amp;lang='. $lng .'">
  218. <div class="title">Administration Registration</div>
  219. <div class="menu">
  220. '.$lang['nick'].':<br />
  221. <input type="text" name="nick" value="'. htmlspecialchars($_POST['nick']) .'" /><br />
  222. '.$lang['name'].':<br />
  223. <input type="text" name="name" value="'. htmlspecialchars($_POST['name']) .'" /><br />
  224. E-Mail:<br />
  225. <input type="text" name="email" value="'. htmlspecialchars($_POST['email']) .'" /><br />
  226. '.$lang['password'].':<br />
  227. <input type="password" name="password" /><br />
  228. '.$lang['password2'].':<br />
  229. <input type="password" name="password2" /><br />
  230. <input type="submit" name="reg_admin" value="'.$lang['sign_up'].'" />
  231. </div>
  232. </form>
  233. <div class="block">
  234. <a href="?act=db&amp;lang='. $lng .'">'.$lang['back'].'</a>
  235. </div>';
  236.  
  237. }
  238. }
  239. }
  240. ?>
  241. <div class="footer">PerfCMS <?=$ver['perfcms_ver'];?>, 2012</div>
  242. </div>
  243. </body>
  244. </html>