servnest/check.php

246 lines
6.9 KiB
PHP
Raw Normal View History

<?php
2023-04-15 14:39:41 +00:00
umask(0077);
const ROOT_PATH = __DIR__;
define('CONF', parse_ini_file(ROOT_PATH . '/config.ini', true, INI_SCANNER_TYPED));
const SFTP = '/usr/bin/sftp';
const SSHPASS = '/usr/bin/sshpass';
2023-04-15 14:39:41 +00:00
const HTTPS_PORT = '42443';
const CORE_DOMAIN = 'servnest.test';
const CORE_URL = 'https://' . CORE_DOMAIN . ':' . HTTPS_PORT;
const SUFFIX = 'test.servnest.test.';
const TOR_PROXY = 'socks5h://127.0.0.1:9050';
const LF = "\n";
exec(CONF['dns']['kdig_path'] . ' torproject.org AAAA', $output, $return_code);
if (preg_match('/^;; Flags: qr rd ra ad;/Dm', implode("\n", $output)) !== 1)
exit('Unable to do a DNSSEC-validated DNS query.' . LF);
if (CONF['common']['services']['ns'] === 'rest') {
echo 'a';
}
2023-04-15 14:39:41 +00:00
define('COOKIE_FILE', sys_get_temp_dir() . '/cookie-' . bin2hex(random_bytes(16)) . '.txt');
2023-04-15 14:39:41 +00:00
function curlTest($address, $post = [], $tor = false) {
$req = curl_init();
2023-04-15 14:39:41 +00:00
curl_setopt($req, CURLOPT_RETURNTRANSFER, true);
if (str_starts_with($address, '/'))
curl_setopt_array($req, [
CURLOPT_POST => true,
CURLOPT_HEADER => true,
CURLOPT_HTTPHEADER => [
'Sec-Fetch-Site: none',
],
CURLOPT_URL => CORE_URL . $address,
CURLOPT_COOKIEFILE => COOKIE_FILE,
CURLOPT_COOKIEJAR => COOKIE_FILE,
CURLOPT_POSTFIELDS => $post,
]);
else
curl_setopt($req, CURLOPT_URL, $address);
if ($tor)
curl_setopt($req, CURLOPT_PROXY, TOR_PROXY);
else
curl_setopt($req, CURLOPT_SSL_VERIFYPEER, false);
$result = curl_exec($req);
$status_code = curl_getinfo($req, CURLINFO_RESPONSE_CODE);
2023-04-15 14:39:41 +00:00
if ($status_code >= 400 OR $result === false) {
2023-04-19 12:59:07 +00:00
var_dump($result);
2023-04-15 14:39:41 +00:00
var_dump(curl_error($req));
exit($address . ' test failed with status code ' . $status_code . LF);
}
2023-04-15 14:39:41 +00:00
return $result;
}
$username = 'check-' . bin2hex(random_bytes(16));
$password = bin2hex(random_bytes(16));
curlTest('/auth/register', [
'username' => $username,
'password' => $password,
]);
curlTest('/auth/logout', []);
curlTest('/auth/login', [
'username' => $username,
'password' => $password,
]);
$new_password = bin2hex(random_bytes(16));
curlTest('/auth/password', [
'current-password' => $password,
'new-password' => $new_password,
]);
$password = $new_password;
curlTest('/auth/username', [
'current-password' => $password,
'new-username' => $username . '2',
]);
curlTest('/auth/username', [
'current-password' => $password,
'new-username' => $username,
]);
echo 'Created account with username "' . $username . '" and password "' . $password . '".' . LF;
2023-04-15 14:39:41 +00:00
function testReg() {
$subdomain = bin2hex(random_bytes(16));
2023-04-15 14:39:41 +00:00
curlTest('/reg/register', [
'subdomain' => $subdomain,
'suffix' => SUFFIX,
'action' => 'register',
]);
2023-04-15 14:39:41 +00:00
$domain = $subdomain . '.' . SUFFIX;
2023-04-15 14:39:41 +00:00
curlTest('/reg/ns', [
'action' => 'add',
'domain' => $domain,
'ns' => 'ns1.servnest.invalid.',
]);
exec(CONF['dns']['kdig_path'] . ' @' . CONF['reg']['address'] . ' ' . $domain . ' NS', $output);
if (preg_match('/[ \t]+ns1\.servnest\.invalid\.$/Dm', implode(LF, $output)) !== 1)
exit('Error: /reg/ns: NS record not set' . LF);
curlTest('/reg/ns', [
'action' => 'delete',
'domain' => $domain,
'ns' => 'ns1.servnest.invalid.',
]);
2023-04-15 14:39:41 +00:00
return $domain;
}
2023-04-15 14:39:41 +00:00
function testNs($domain) {
foreach (CONF['ns']['servers'] as $ns)
curlTest('/reg/ns', [
'action' => 'add',
'domain' => $domain,
'ns' => $ns,
]);
2023-04-19 12:59:07 +00:00
preg_match('#\<code\>(?<token>[0-9a-z-]{16,128}\._domain-verification\.' . preg_quote(CORE_DOMAIN, '#') . '\.)\</code\>#', curlTest('/ns/zone-add', []), $matches);
2023-04-15 14:39:41 +00:00
curlTest('/reg/ns', [
'action' => 'add',
'domain' => $domain,
'ns' => $matches['token'],
]);
2023-04-15 14:39:41 +00:00
curlTest('/ns/zone-add', [
'domain' => $domain,
]);
2023-04-15 14:39:41 +00:00
curlTest('/reg/ns', [
'action' => 'delete',
'domain' => $domain,
'ns' => $matches['token'],
]);
2023-04-15 14:39:41 +00:00
curlTest('/ns/caa', [
'action' => 'add',
'subdomain' => '@',
'zone' => $domain,
'ttl-value' => '2',
'ttl-multiplier' => '3600',
'flag' => '0',
'tag' => 'issue',
'value' => 'letsencrypt.org',
]);
exec(CONF['dns']['kdig_path'] . ' @' . CONF['reg']['address'] . ' ' . $domain . ' CAA', $output);
2023-04-19 12:59:07 +00:00
if (preg_match('/^' . preg_quote($domain, '/') . '[ \t]+7200[ \t]+IN[ \t]+CAA[ \t]+0[ \t]+issue[ \t]+"letsencrypt\.org"$/Dm', implode(LF, $output)) !== 1)
2023-04-15 14:39:41 +00:00
exit('Error: /ns/caa: CAA record not set' . LF);
curlTest('/ns/edit', [
'zone' => $domain,
'zone-content' => 'aaaa.' . $domain . ' 3600 AAAA ' . CONF['ht']['ipv6_address'] . "\r\n"
. '@ 86400 NS ' . CONF['ns']['servers'][0] . "\r\n",
]);
exec(CONF['dns']['kdig_path'] . ' @' . CONF['reg']['address'] . ' aaaa.' . $domain . ' AAAA', $output);
2023-04-19 12:59:07 +00:00
if (preg_match('/[ \t]+' . preg_quote(CONF['ht']['ipv6_address'], '/') . '$/Dm', implode(LF, $output)) !== 1)
2023-04-15 14:39:41 +00:00
exit('Error: /ns/edit: AAAA record not set' . LF);
}
function testHt($username, $password) {
curlTest('/ht/', []);
define('TEST_CONTENT', 'test-' . random_bytes(4));
file_put_contents(sys_get_temp_dir() . '/index.html', TEST_CONTENT);
file_put_contents(sys_get_temp_dir() . '/exec.txt', 'mkdir /_site0-
put ' . sys_get_temp_dir() . '/index.html /_site0-/index.html
exit
');
2023-04-15 14:39:41 +00:00
$process = proc_open(SSHPASS . ' ' . SFTP . ' -o BatchMode=no -b ' . sys_get_temp_dir() . '/exec.txt -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -P ' . CONF['ht']['public_sftp_port'] . ' ' . $username . '@' . CONF['ht']['sftp_domain'], [0 => ['pipe', 'r']], $pipes);
if (is_resource($process) !== true)
exit('Can\'t spawn sftp with sshpass.' . LF);
fwrite($pipes[0], $password);
fclose($pipes[0]);
if (proc_close($process) !== 0)
exit('File not sent successfully.' . LF);
{
$ht_subpath = bin2hex(random_bytes(16));
curlTest('/ht/add-subpath', [
'path' => $ht_subpath,
'dir' => '_site0-',
]);
if (curlTest('https://' . CONF['ht']['subpath_domain'] . ':' . HTTPS_PORT . '/' . $ht_subpath . '/') !== TEST_CONTENT)
exit('Unexpected subpath response' . LF);
curlTest('/ht/del', [
'site' => 'subpath:' . $ht_subpath,
]);
}
2023-04-15 14:39:41 +00:00
{
$ht_subdomain = 'test3';
curlTest('/ht/add-subdomain', [
'subdomain' => $ht_subdomain,
'dir' => '_site0-',
]);
if (curlTest('https://' . $ht_subdomain . '.' . CONF['ht']['subpath_domain'] . ':' . HTTPS_PORT . '/') !== TEST_CONTENT)
exit('Unexpected subpath response' . LF);
curlTest('/ht/del', [
'site' => 'subdomain:' . $ht_subdomain,
]);
}
2023-04-15 14:39:41 +00:00
{
$html = curlTest('/ht/add-onion', [
'dir' => '_site0-',
]);
if (preg_match('#\<code\>http\://(?<onion>[0-9a-z]{56})\.onion/\</code\>#D', $html, $matches) !== 1)
exit('Can\'t find onion address.' . LF);
2023-04-19 12:59:07 +00:00
sleep(5); // Onion services are not immediately reachable
2023-04-15 14:39:41 +00:00
if (curlTest('http://' . $matches['onion'] . '.onion/', tor: true) !== TEST_CONTENT)
exit('Unexpected onion service response (' . $matches['onion'] . '.onion)' . LF);
curlTest('/ht/del', [
'site' => 'onion:' . $matches['onion'] . '.onion',
]);
}
}
2023-04-15 14:39:41 +00:00
$domain = testReg();
testNs($domain);
testHt($username, $password);
curlTest('/auth/unregister', [
'current-password' => $password,
'delete' => 'on',
]);
unlink(COOKIE_FILE);
echo 'OK' . LF;