.tmp + chown www-data * + chmod 600 (so PHP can edit the temp). * 2. fopen('w') and fwrite the rebuilt INI text into the temp. * 3. sudo mount -o remount,rw / + sudo install -m 644 -o root -g * root temp -> /etc/dmrgateway + sudo mount -o remount,ro / to * seal the rootfs again. (See edit_mmdvmhost.php for the full * rationale on the install vs cp+chmod+chown migration.) * 4. sudo systemctl restart dmrgateway.service to pick up the change. * * Admin-only access; the dashboard's Apache basic-auth gate is the * sole protection. The validation is what's in the form (none, in * effect — operator-typed values are written raw). Treat with care. */ require_once($_SERVER['DOCUMENT_ROOT'].'/config/security_headers.php'); require_once($_SERVER['DOCUMENT_ROOT'].'/config/csrf.php'); require_once($_SERVER['DOCUMENT_ROOT'].'/config/banner_warnings.inc'); setSecurityHeaders(); // CSRF protection — see config/csrf.php for the full rationale. // Must run BEFORE any output: bootstraps the session on GET (so // Set-Cookie ships) and rejects forged POSTs cleanly with 403 // before any state change (sed-i, fopen+fwrite, sudo cp, etc.). csrf_verify(); // Layer 2 of the default-password protection — see config/banner_warnings.inc. // MUST run BEFORE any output so header('Location: ...') works. pistar_warnings_enforce_redirect(); // Load the language support require_once('../config/language.php'); //Load the Pi-Star Release file $pistarReleaseConfig = '/etc/pistar-release'; $configPistarRelease = array(); $configPistarRelease = parse_ini_file($pistarReleaseConfig, true); //Load the Version Info require_once('../config/version.php'); ?> Pi-Star - Digital Voice Dashboard - Expert Editor
// doesn't persist between requests. @-suppression handles // the case where a sudo mv (e.g. fulledit_bmapikey) already // consumed the staging file before script end. register_shutdown_function(function() use ($filepath) { @unlink($filepath); }); //after the form submit if($_POST) { $data = $_POST; //update ini file, call function update_ini_file($data, $filepath); } //this is the function going to update your ini file function update_ini_file($data, $filepath) { $content = ""; //parse the ini file to get the sections //parse the ini file using default parse_ini_file() PHP function $parsed_ini = parse_ini_file($filepath, true); foreach($data as $section=>$values) { // UnBreak special cases $section = str_replace("_", " ", $section); $content .= "[".$section."]\n"; //append the values foreach($values as $key=>$value) { if (($section == "DMR Network 1" || $section == "DMR Network 2") && $key == "Password" && $value) { $value = str_replace('"', "", $value); $content .= $key."=\"".$value."\"\n"; } elseif (($section == "DMR Network 1" || $section == "DMR Network 2") && $key == "Options" && $value) { $value = str_replace('"', "", $value); $content .= $key."=\"".$value."\"\n"; } else { $content .= $key."=".$value."\n"; } } $content .= "\n"; } //write it into file if (!$handle = fopen($filepath, 'w')) { return false; } $success = fwrite($handle, $content); fclose($handle); // L-5: atomic install replaces the prior cp + chmod + chown // triplet (rejected by the tightened sudoers — see // edit_mmdvmhost.php for the full rationale). exec('sudo mount -o remount,rw /'); exec('sudo install -m 644 -o root -g root ' . escapeshellarg($filepath) . ' /etc/dmrgateway'); exec('sudo mount -o remount,ro /'); // Reload the affected daemon exec('sudo systemctl restart dmrgateway.service'); // Reload the daemon return $success; } //parse the ini file using default parse_ini_file() PHP function $parsed_ini = parse_ini_file($filepath, true); echo '
'."\n"; echo csrf_field_html()."\n"; foreach($parsed_ini as $section=>$values) { // keep the section as hidden text so we can update once the form submitted // INI section / key / value all come from the underlying // /etc/ file. Same hardening as edit_mmdvmhost.php // (#23): htmlspecialchars(ENT_QUOTES) on display so a value // with a literal `"` or `<` (e.g. an Options string) can't // break out of the `value="…"` attribute. The save handler // writes the POST bytes verbatim, so legitimate quoted // values round-trip byte-identically. $sectionHtml = htmlspecialchars((string)$section, ENT_QUOTES, 'UTF-8'); echo "\n"; echo "\n"; echo "\n"; // print all other values as input fields, so can edit. // note the name='' attribute it has both section and key foreach($values as $key=>$value) { $keyHtml = htmlspecialchars((string)$key, ENT_QUOTES, 'UTF-8'); $valueHtml = htmlspecialchars((string)$value, ENT_QUOTES, 'UTF-8'); echo "\n"; } echo "
$sectionHtml
$keyHtml
\n"; echo ''."\n"; echo "
\n"; } echo ""; ?>