forked from webmin/webmin
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathsave_acl.cgi
executable file
·85 lines (74 loc) · 1.89 KB
/
save_acl.cgi
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
#!/usr/local/bin/perl
# Save access control options
require './frox-lib.pl';
&ReadParse();
&error_setup($text{'acl_err'});
$conf = &get_config();
&save_opt_textbox($conf, "Timeout", \&check_timeout);
&save_opt_textbox($conf, "MaxForks", \&check_forks);
&save_opt_textbox($conf, "MaxForksPerHost", \&check_forks);
&save_opt_textbox($conf, "MaxTransferRate", \&check_rate);
&save_yesno($conf, "DoNTP");
&save_opt_textbox($conf, "NTPAddress", \&check_ntp);
for($i=0; defined($in{"action_$i"}); $i++) {
next if (!$in{"action_$i"});
local @val;
push(@val, $in{"action_$i"});
if ($in{"src_${i}_def"}) {
push(@val, "*");
}
else {
&valid_srcdest($in{"src_$i"}) ||
&error(&text('acl_esrc', $i+1));
push(@val, $in{"src_$i"});
}
push(@val, "-");
if ($in{"dest_${i}_def"}) {
push(@val, "*");
}
else {
&valid_srcdest($in{"dest_$i"}) ||
&error(&text('acl_edest', $i+1));
push(@val, $in{"dest_$i"});
}
if (!$in{"ports_${i}_def"}) {
foreach $p (split(/,/, $in{"ports_$i"})) {
$p =~ /^\d+$/ || $p =~ /^\d+\-\d+$/ ||
&error(&text('acl_eports', $i+1));
}
push(@val, $in{"ports_$i"});
}
push(@acl, join(" ", @val));
}
@acl || &error($text{'acl_enone'});
&save_directive($conf, "ACL", \@acl);
&lock_file($config{'frox_conf'});
&flush_file_lines();
&unlock_file($config{'frox_conf'});
&webmin_log("acl");
&redirect("");
sub check_timeout
{
return $_[0] =~ /^\d+$/ ? undef : $text{'acl_etimeout'};
}
sub check_forks
{
return $_[0] =~ /^\d+$/ ? undef : $text{'acl_eforks'};
}
sub check_rate
{
return $_[0] =~ /^\d+$/ ? undef : $text{'acl_erate'};
}
sub check_ntp
{
return $_[0] =~ /^(\S+):(\d+)$/ && gethostbyname($1) ? undef
: $text{'acl_entp'};
}
sub valid_srcdest
{
return gethostbyname($_[0]) ||
($_[0] =~ /^([0-9\.]+)\/(\d+)$/ &&
&check_ipaddress($1) && $2 > 0 && $2 <= 32) ||
($_[0] =~ /^([0-9\.]+)\/([0-9\.]+)$/ &&
&check_ipaddress($1) && &check_ipaddress($2));
}