mirror of
https://github.com/midoks/mdserver-web.git
synced 2026-10-10 14:49:25 +08:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
628175a8ee | ||
|
|
96d0115257 | ||
|
|
801fdf51a7 | ||
|
|
24fa3a7ca9 | ||
|
|
3dc781498c | ||
|
|
c3afaeb35a | ||
|
|
4390180a89 | ||
|
|
98e22f6eeb | ||
|
|
3bfd0f34f5 | ||
|
|
ec8e46494a | ||
|
|
7cb9b0acec | ||
|
|
f97d2a5987 | ||
|
|
5a50fe70a8 | ||
|
|
4ecb28575e | ||
|
|
07bf8f162c | ||
|
|
19beb1bccc | ||
|
|
33c27d7924 | ||
|
|
a9fb6c9ec9 | ||
|
|
7198a4de95 | ||
|
|
53cb56ddf2 | ||
|
|
e4582f328c | ||
|
|
bb7f1b6a7d | ||
|
|
1781d879d1 | ||
|
|
d89158124f | ||
|
|
bfdad5f9a3 | ||
|
|
165d9ba14d | ||
|
|
ad102aa940 | ||
|
|
1489d15d74 | ||
|
|
2dbda3e6dd | ||
|
|
4775d4f756 | ||
|
|
f57fd600e6 | ||
|
|
bf281107b2 | ||
|
|
083fe59fa5 | ||
|
|
8f36e0ccb2 | ||
|
|
a5b3a650eb | ||
|
|
177a08af91 | ||
|
|
5ef4b3d05d | ||
|
|
ad3d93cf8b | ||
|
|
72643b7776 | ||
|
|
45128636b0 | ||
|
|
7b962335e4 | ||
|
|
c0c67095be | ||
|
|
b3a0f11a80 | ||
|
|
088337765c | ||
|
|
066e7087c9 | ||
|
|
29144595a6 | ||
|
|
45c2b3cdca | ||
|
|
e3ecdfb2b3 | ||
|
|
560d482f31 | ||
|
|
62ffc94b69 | ||
|
|
0cb10cc926 | ||
|
|
fb4eb8747c | ||
|
|
1a26b83a46 | ||
|
|
7c2316f005 | ||
|
|
149baeb1fc | ||
|
|
9714bcb419 | ||
|
|
4e6a54dbad | ||
|
|
18498813c6 | ||
|
|
854e34a90c | ||
|
|
a0898c849e | ||
|
|
3a26b71828 | ||
|
|
f500dcac8b | ||
|
|
3a6e2e6e4b | ||
|
|
1d439e788c | ||
|
|
75a2fcdaaf | ||
|
|
2ca8598671 | ||
|
|
2d42486ac5 | ||
|
|
24f22b5b8c | ||
|
|
68f8638638 | ||
|
|
fe6b16eda4 | ||
|
|
4e35c34854 | ||
|
|
cc51d9501f | ||
|
|
c08cfd4763 | ||
|
|
5fdcb8bf71 | ||
|
|
ce3b232c4b | ||
|
|
ec7ae65f7d | ||
|
|
e4c5212ac4 | ||
|
|
23442accaf | ||
|
|
2e6f5f9add | ||
|
|
110e356fae | ||
|
|
a243d088ee | ||
|
|
365fd466c2 | ||
|
|
d1304de69e | ||
|
|
e51fa2608d | ||
|
|
cbfcd00317 | ||
|
|
7a96d3abc5 | ||
|
|
33a510a5b5 | ||
|
|
e8942128b8 | ||
|
|
7e2bd928e2 | ||
|
|
89185476aa | ||
|
|
f491641ab8 | ||
|
|
8b108d1aff | ||
|
|
2cfa7ec2ab | ||
|
|
d63aae100d | ||
|
|
e8249adc53 | ||
|
|
281427e479 | ||
|
|
af775fc77d | ||
|
|
f328354125 | ||
|
|
1f70f962cf | ||
|
|
414787447e | ||
|
|
979f2174e5 | ||
|
|
84d1c96094 | ||
|
|
0d8d9022a0 | ||
|
|
44d0e9e11c | ||
|
|
771d6e04ba | ||
|
|
87563daa1d | ||
|
|
9fefb285e1 | ||
|
|
b9ca4fc11e | ||
|
|
2646d0565d | ||
|
|
e1f900f1c5 | ||
|
|
908b3341b2 | ||
|
|
5aef2467b1 | ||
|
|
f59114a688 | ||
|
|
363ed8b3ff | ||
|
|
3970feacc3 | ||
|
|
f6c528149e | ||
|
|
8f6b5ddba9 | ||
|
|
ef350b9fd2 | ||
|
|
004dfb5e7d | ||
|
|
3c08d7c159 | ||
|
|
e227204065 | ||
|
|
ce653b7a6a | ||
|
|
a207215775 | ||
|
|
8115b0fb4d | ||
|
|
048bd573e8 | ||
|
|
918ea8d0f9 | ||
|
|
97d2fd5a63 | ||
|
|
617a517048 | ||
|
|
2e7910a84c | ||
|
|
2ee4c4e3fd | ||
|
|
9ae4d32ed4 | ||
|
|
90a7f4ea10 | ||
|
|
d22cb8305d | ||
|
|
a7a78f2103 | ||
|
|
db7ec00c07 | ||
|
|
dd21d25295 | ||
|
|
f7360aa081 | ||
|
|
1d1ba7192a | ||
|
|
0bf540c5e7 |
+6
-1
@@ -154,11 +154,15 @@ data/basic_auth.json
|
||||
data/api.json
|
||||
data/bind_domain.pl
|
||||
|
||||
plugins/vip_*
|
||||
plugins/own_*
|
||||
plugins/my_*
|
||||
plugins/l2tp
|
||||
plugins/openlitespeed
|
||||
plugins/migration_api
|
||||
plugins/system_safe
|
||||
plugins/tamper_proof
|
||||
plugins/tamper_proof_*
|
||||
plugins/op_load_balance
|
||||
plugins/gdrive
|
||||
plugins/mtproxy
|
||||
plugins/zimg
|
||||
@@ -171,3 +175,4 @@ plugins/file_search
|
||||
debug.out
|
||||
|
||||
|
||||
data/unauthorized_status.pl
|
||||
|
||||
@@ -29,6 +29,12 @@
|
||||
基本上可以使用,后续会继续优化!欢迎提供意见!
|
||||
|
||||
- 吹水组 - https://t.me/mdserver_web
|
||||
|
||||
```
|
||||
如果出现问题,最好私给我面板信息。不要让我猜。如果不提供,不要提出问题,自行解决。 — 座右铭
|
||||
Talk is cheap, show me the code. -- linus
|
||||
```
|
||||
|
||||
- [兼容性测试报告](/compatibility.md)
|
||||
- [常用命令说明](/cmd.md)
|
||||
|
||||
@@ -38,6 +44,7 @@
|
||||
* PHP[53-82] - PHP是世界上最好的编程语言。
|
||||
* MySQL - 一种关系数据库管理系统。
|
||||
* MariaDB - 是MySQL的一个重要分支。
|
||||
* MySQL[APT/YUM] - 一种关系数据库管理系统。
|
||||
* MongoDB - 一种非关系NOSQL数据库管理系统。
|
||||
* phpMyAdmin - 著名Web端MySQL管理工具。
|
||||
* Memcached - 一个高性能的分布式内存对象缓存系统。
|
||||
@@ -84,27 +91,24 @@ PHP[72-81]支持phpMyAdmin[5.2.0]
|
||||
# Docker
|
||||
|
||||
- 由[DDSRem](https://github.com/DDSRem)开发维护。
|
||||
- https://hub.docker.com/r/ddsderek/mw-server
|
||||
- https://hub.docker.com/r/ddsderek/mw
|
||||
|
||||
```
|
||||
docker run -itd --name mw-server --privileged=true -p 7200:7200 -p 80:80 -p 443:443 -p 888:888 ddsderek/mw-server:latest
|
||||
```
|
||||
|
||||
|
||||
### 版本更新 0.12.2
|
||||
### 版本更新 0.12.3
|
||||
|
||||
* 开放菜单权限配置。
|
||||
* 升级SSH终端2.0。
|
||||
* 增加已安装类型。
|
||||
* 加入切换linux软件源的命令。
|
||||
* iptables安装优化。
|
||||
* 网站统计POST获取数据优化。
|
||||
* mysql[apt/yum]迁移优化。
|
||||
* 优化防火墙导入。
|
||||
* 图标可设置。
|
||||
* 优先使用firewalld防火墙。
|
||||
* PHP[APT]加入curl扩展。
|
||||
* 配置添加【未认证响应状态】功能。
|
||||
* 存在ipv6时,启动时强制开启。
|
||||
* OP防火墙-性能优化。
|
||||
* 网站统计优化。
|
||||
* 优化backup_ftp插件。
|
||||
* 各种细节优化。
|
||||
|
||||
|
||||
### JSDelivr安装地址
|
||||
|
||||
- 初始安装
|
||||
|
||||
@@ -27,7 +27,7 @@ from flask import request
|
||||
|
||||
class config_api:
|
||||
|
||||
__version = '0.12.2'
|
||||
__version = '0.12.3'
|
||||
__api_addr = 'data/api.json'
|
||||
|
||||
def __init__(self):
|
||||
@@ -647,9 +647,22 @@ class config_api:
|
||||
else:
|
||||
return False, ''
|
||||
|
||||
def setStatusCodeApi(self):
|
||||
status_code = request.form.get('status_code', '').strip()
|
||||
if re.match("^\d+$", status_code):
|
||||
status_code = int(status_code)
|
||||
if status_code != 0:
|
||||
if status_code < 100 or status_code > 999:
|
||||
return mw.returnJson(False, '状态码范围错误!')
|
||||
else:
|
||||
return mw.returnJson(False, '状态码范围错误!')
|
||||
|
||||
mw.writeFile('data/unauthorized_status.pl', str(status_code))
|
||||
mw.writeLog('面板设置', '将未授权响应状态码设置为:{}'.format(status_code))
|
||||
return mw.returnJson(True, '设置成功!')
|
||||
|
||||
def getPanelTokenApi(self):
|
||||
api_file = self.__api_addr
|
||||
|
||||
tmp = mw.readFile(api_file)
|
||||
if not os.path.exists(api_file):
|
||||
ready_data = {"open": False, "token": "", "limit_addr": []}
|
||||
@@ -668,7 +681,7 @@ class config_api:
|
||||
token = mw.getRandomString(32)
|
||||
data['token'] = mw.md5(token)
|
||||
data['token_crypt'] = mw.enCrypt(
|
||||
data['token'], token).decode('utf-8')
|
||||
data['token'], token)
|
||||
mw.writeFile(api_file, json.dumps(data))
|
||||
data['token'] = "***********************************"
|
||||
|
||||
@@ -714,6 +727,31 @@ class config_api:
|
||||
mw.writeFile(api_file, json.dumps(data))
|
||||
return mw.returnJson(True, '保存成功!')
|
||||
|
||||
def renderUnauthorizedStatus(self, data):
|
||||
cfg_unauth_status = 'data/unauthorized_status.pl'
|
||||
if os.path.exists(cfg_unauth_status):
|
||||
status_code = mw.readFile(cfg_unauth_status)
|
||||
data['status_code'] = status_code
|
||||
data['status_code_msg'] = status_code
|
||||
if status_code == '0':
|
||||
data['status_code_msg'] = "默认-安全入口错误提示"
|
||||
elif status_code == '400':
|
||||
data['status_code_msg'] = "400-客户端请求错误"
|
||||
elif status_code == '401':
|
||||
data['status_code_msg'] = "401-未授权访问"
|
||||
elif status_code == '403':
|
||||
data['status_code_msg'] = "403-拒绝访问"
|
||||
elif status_code == '404':
|
||||
data['status_code_msg'] = "404-页面不存在"
|
||||
elif status_code == '408':
|
||||
data['status_code_msg'] = "408-客户端超时"
|
||||
elif status_code == '416':
|
||||
data['status_code_msg'] = "416-无效的请求"
|
||||
else:
|
||||
data['status_code'] = '0'
|
||||
data['status_code_msg'] = "默认-安全入口错误提示"
|
||||
return data
|
||||
|
||||
def get(self):
|
||||
|
||||
data = {}
|
||||
@@ -766,6 +804,8 @@ class config_api:
|
||||
else:
|
||||
data['bind_domain'] = ''
|
||||
|
||||
data = self.renderUnauthorizedStatus(data)
|
||||
|
||||
api_token = self.__api_addr
|
||||
if os.path.exists(api_token):
|
||||
bac = mw.readFile(api_token)
|
||||
|
||||
+21
-51
@@ -677,56 +677,29 @@ class files_api:
|
||||
if os.path.getsize(path) > 2097152:
|
||||
return mw.returnJson(False, '不能在线编辑大于2MB的文件!')
|
||||
|
||||
if os.path.isdir(path):
|
||||
return mw.returnJson(False, '这不是一个文件!')
|
||||
|
||||
fp = open(path, 'rb')
|
||||
data = {}
|
||||
data['status'] = True
|
||||
try:
|
||||
if fp:
|
||||
from chardet.universaldetector import UniversalDetector
|
||||
detector = UniversalDetector()
|
||||
srcBody = b""
|
||||
for line in fp.readlines():
|
||||
detector.feed(line)
|
||||
srcBody += line
|
||||
detector.close()
|
||||
char = detector.result
|
||||
data['encoding'] = char['encoding']
|
||||
if char['encoding'] == 'GB2312' or not char['encoding'] or char[
|
||||
'encoding'] == 'TIS-620' or char['encoding'] == 'ISO-8859-9':
|
||||
data['encoding'] = 'GBK'
|
||||
if char['encoding'] == 'ascii' or char[
|
||||
'encoding'] == 'ISO-8859-1':
|
||||
data['encoding'] = 'utf-8'
|
||||
if char['encoding'] == 'Big5':
|
||||
data['encoding'] = 'BIG5'
|
||||
|
||||
if not data['encoding'] in ['GBK', 'utf-8', 'BIG5']:
|
||||
data['encoding'] = 'utf-8'
|
||||
if fp:
|
||||
srcBody = fp.read()
|
||||
fp.close()
|
||||
|
||||
encoding_list = ['utf-8', 'GBK', 'BIG5']
|
||||
for el in encoding_list:
|
||||
try:
|
||||
if sys.version_info[0] == 2:
|
||||
data['data'] = srcBody.decode(
|
||||
data['encoding']).encode('utf-8', errors='ignore')
|
||||
else:
|
||||
data['data'] = srcBody.decode(data['encoding'])
|
||||
except:
|
||||
data['encoding'] = char['encoding']
|
||||
if sys.version_info[0] == 2:
|
||||
data['data'] = srcBody.decode(
|
||||
data['encoding']).encode('utf-8', errors='ignore')
|
||||
else:
|
||||
data['data'] = srcBody.decode(data['encoding'])
|
||||
return mw.returnJson(True, 'OK', data)
|
||||
else:
|
||||
if sys.version_info[0] == 2:
|
||||
data['data'] = srcBody.decode('utf-8').encode('utf-8')
|
||||
else:
|
||||
data['data'] = srcBody.decode('utf-8')
|
||||
data['encoding'] = 'utf-8'
|
||||
data['encoding'] = el
|
||||
data['data'] = srcBody.decode(data['encoding'])
|
||||
break
|
||||
except Exception as ex:
|
||||
if el == 'BIG5':
|
||||
return mw.returnJson(False, '文件编码不被兼容,无法正确读取文件!' + str(ex))
|
||||
else:
|
||||
return mw.returnJson(False, '文件未正常打开!')
|
||||
|
||||
return mw.returnJson(True, 'OK', data)
|
||||
except Exception as ex:
|
||||
return mw.returnJson(False, '文件编码不被兼容,无法正确读取文件!' + str(ex))
|
||||
return mw.returnJson(True, 'OK', data)
|
||||
|
||||
def saveBody(self, path, data, encoding='utf-8'):
|
||||
if not os.path.exists(path):
|
||||
@@ -734,13 +707,10 @@ class files_api:
|
||||
try:
|
||||
if encoding == 'ascii':
|
||||
encoding = 'utf-8'
|
||||
if sys.version_info[0] == 2:
|
||||
data = data.encode(encoding, errors='ignore')
|
||||
fp = open(path, 'w+')
|
||||
else:
|
||||
data = data.encode(
|
||||
encoding, errors='ignore').decode(encoding)
|
||||
fp = open(path, 'w+', encoding=encoding)
|
||||
|
||||
data = data.encode(
|
||||
encoding, errors='ignore').decode(encoding)
|
||||
fp = open(path, 'w+', encoding=encoding)
|
||||
fp.write(data)
|
||||
fp.close()
|
||||
|
||||
|
||||
@@ -34,13 +34,13 @@ class firewall_api:
|
||||
|
||||
def __init__(self):
|
||||
iptables_file = mw.systemdCfgDir() + '/iptables.service'
|
||||
if os.path.exists(iptables_file):
|
||||
self.__isIptables = True
|
||||
if os.path.exists('/usr/sbin/firewalld'):
|
||||
self.__isFirewalld = True
|
||||
if os.path.exists('/usr/sbin/ufw'):
|
||||
elif os.path.exists(iptables_file):
|
||||
self.__isIptables = True
|
||||
elif os.path.exists('/usr/sbin/ufw'):
|
||||
self.__isUfw = True
|
||||
if mw.isAppleSystem():
|
||||
elif mw.isAppleSystem():
|
||||
self.__isMac = True
|
||||
|
||||
##### ----- start ----- ###
|
||||
|
||||
+108
-5
@@ -228,6 +228,14 @@ def isIpAddr(ip):
|
||||
return False
|
||||
|
||||
|
||||
def getWebStatus():
|
||||
pid = getServerDir() + '/openresty/nginx/logs/nginx.pid'
|
||||
if os.path.exists(pid):
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
# ------------------------------ openresty start -----------------------------
|
||||
def restartWeb():
|
||||
return opWeb("reload")
|
||||
|
||||
@@ -252,6 +260,63 @@ def opWeb(method):
|
||||
return False
|
||||
|
||||
|
||||
def opLuaMake(cmd_name):
|
||||
path = getServerDir() + '/web_conf/nginx/lua/lua.conf'
|
||||
root_dir = getServerDir() + '/web_conf/nginx/lua/' + cmd_name
|
||||
dst_path = getServerDir() + '/web_conf/nginx/lua/' + cmd_name + '.lua'
|
||||
def_path = getServerDir() + '/web_conf/nginx/lua/empty.lua'
|
||||
|
||||
if not os.path.exists(root_dir):
|
||||
execShell('mkdir -p ' + root_dir)
|
||||
|
||||
files = []
|
||||
for fl in os.listdir(root_dir):
|
||||
suffix = getFileSuffix(fl)
|
||||
if suffix != 'lua':
|
||||
continue
|
||||
flpath = os.path.join(root_dir, fl)
|
||||
files.append(flpath)
|
||||
|
||||
if len(files) > 0:
|
||||
def_path = dst_path
|
||||
content = ''
|
||||
for f in files:
|
||||
t = readFile(f)
|
||||
f_base = os.path.basename(f)
|
||||
content += '-- ' + '*' * 20 + ' ' + f_base + ' start ' + '*' * 20 + "\n"
|
||||
content += t
|
||||
content += "\n" + '-- ' + '*' * 20 + ' ' + f_base + ' end ' + '*' * 20 + "\n"
|
||||
writeFile(dst_path, content)
|
||||
else:
|
||||
if os.path.exists(dst_path):
|
||||
os.remove(dst_path)
|
||||
|
||||
conf = readFile(path)
|
||||
conf = re.sub(cmd_name + ' (.*);',
|
||||
cmd_name + " " + def_path + ";", conf)
|
||||
writeFile(path, conf)
|
||||
|
||||
|
||||
def opLuaInitFile():
|
||||
opLuaMake('init_by_lua_file')
|
||||
|
||||
|
||||
def opLuaInitWorkerFile():
|
||||
opLuaMake('init_worker_by_lua_file')
|
||||
|
||||
|
||||
def opLuaInitAccessFile():
|
||||
opLuaMake('access_by_lua_file')
|
||||
|
||||
|
||||
def opLuaMakeAll():
|
||||
opLuaInitFile()
|
||||
opLuaInitWorkerFile()
|
||||
opLuaInitAccessFile()
|
||||
|
||||
# ------------------------------ openresty end -----------------------------
|
||||
|
||||
|
||||
def restartMw():
|
||||
import system_api
|
||||
system_api.system_api().restartMw()
|
||||
@@ -462,15 +527,15 @@ def getDataFromInt(val):
|
||||
|
||||
def writeLog(stype, msg, args=()):
|
||||
# 写日志
|
||||
uid = 1
|
||||
try:
|
||||
from flask import session
|
||||
uid = 1
|
||||
if 'uid' in session:
|
||||
uid = session['uid']
|
||||
return writeDbLog(stype, msg, args, uid)
|
||||
except Exception as e:
|
||||
print(getTracebackInfo())
|
||||
return False
|
||||
pass
|
||||
# print(getTracebackInfo())
|
||||
return writeDbLog(stype, msg, args, uid)
|
||||
|
||||
|
||||
def writeDbLog(stype, msg, args=(), uid=1):
|
||||
@@ -580,7 +645,7 @@ def enCrypt(key, strings):
|
||||
# 加密字符串
|
||||
try:
|
||||
import base64
|
||||
_key = md5(key).encode('utf-8')
|
||||
_key = key.encode('utf-8')
|
||||
_key = base64.urlsafe_b64encode(_key)
|
||||
|
||||
if type(strings) != bytes:
|
||||
@@ -596,6 +661,44 @@ def enCrypt(key, strings):
|
||||
|
||||
|
||||
def deCrypt(key, strings):
|
||||
|
||||
# 解密字符串
|
||||
try:
|
||||
import base64
|
||||
_key = key.encode('utf-8')
|
||||
_key = base64.urlsafe_b64encode(_key)
|
||||
|
||||
if type(strings) != bytes:
|
||||
strings = strings.encode('utf-8')
|
||||
from cryptography.fernet import Fernet
|
||||
f = Fernet(_key)
|
||||
result = f.decrypt(strings).decode('utf-8')
|
||||
return result
|
||||
except:
|
||||
print(getTracebackInfo())
|
||||
return strings
|
||||
|
||||
|
||||
def enDoubleCrypt(key, strings):
|
||||
# 加密字符串
|
||||
try:
|
||||
import base64
|
||||
_key = md5(key).encode('utf-8')
|
||||
_key = base64.urlsafe_b64encode(_key)
|
||||
|
||||
if type(strings) != bytes:
|
||||
strings = strings.encode('utf-8')
|
||||
import cryptography
|
||||
from cryptography.fernet import Fernet
|
||||
f = Fernet(_key)
|
||||
result = f.encrypt(strings)
|
||||
return result.decode('utf-8')
|
||||
except:
|
||||
print(getTracebackInfo())
|
||||
return strings
|
||||
|
||||
|
||||
def deDoubleCrypt(key, strings):
|
||||
# 解密字符串
|
||||
try:
|
||||
import base64
|
||||
|
||||
@@ -320,7 +320,7 @@ class ssh_terminal:
|
||||
|
||||
def getSshInfo(self, file):
|
||||
rdata = mw.readFile(file)
|
||||
destr = mw.deCrypt('mdserver-web', rdata)
|
||||
destr = mw.enDoubleCrypt('mdserver-web', rdata)
|
||||
return json.loads(destr)
|
||||
|
||||
def setAttr(self, sid, info):
|
||||
|
||||
@@ -724,6 +724,26 @@ class system_api:
|
||||
mw.execShell('rm -rf ' + toPath + '/mdserver-web-' + version)
|
||||
mw.execShell('rm -rf ' + toPath + '/mw.zip')
|
||||
|
||||
update_env = '''
|
||||
#!/bin/bash
|
||||
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
|
||||
|
||||
if [ ! -f /www/server/mdserver-web/bin/activate ];then
|
||||
cd /www/server/mdserver-web && python3 -m venv .
|
||||
cd /www/server/mdserver-web && source /www/server/mdserver-web/bin/activate
|
||||
else
|
||||
cd /www/server/mdserver-web && source /www/server/mdserver-web/bin/activate
|
||||
fi
|
||||
|
||||
cn=$(curl -fsSL -m 10 http://ipinfo.io/json | grep "\"country\": \"CN\"")
|
||||
PIPSRC="https://pypi.python.org/simple"
|
||||
if [ ! -z "$cn" ];then
|
||||
PIPSRC="https://pypi.tuna.tsinghua.edu.cn/simple"
|
||||
fi
|
||||
|
||||
cd /www/server/mdserver-web && pip3 install -r /www/server/mdserver-web/requirements.txt -i $PIPSRC
|
||||
'''
|
||||
os.system(update_env)
|
||||
self.restartMw()
|
||||
return mw.returnJson(True, '安装更新成功!')
|
||||
|
||||
|
||||
@@ -21,12 +21,12 @@ mw_start_task()
|
||||
sleep 0.3
|
||||
isStart=$(ps aux |grep 'task.py'|grep -v grep|awk '{print $2}')
|
||||
if [ "$isStart" == '' ];then
|
||||
echo -e "\033[31mfailed\033[0m"
|
||||
echo '------------------------------------------------------'
|
||||
tail -n 20 $DIR/logs/task.log
|
||||
echo '------------------------------------------------------'
|
||||
echo -e "\033[31mError: mw-tasks service startup failed.\033[0m"
|
||||
return;
|
||||
echo -e "\033[31mfailed\033[0m"
|
||||
echo '------------------------------------------------------'
|
||||
tail -n 20 $DIR/logs/task.log
|
||||
echo '------------------------------------------------------'
|
||||
echo -e "\033[31mError: mw-tasks service startup failed.\033[0m"
|
||||
return;
|
||||
fi
|
||||
echo -e "\033[32mdone\033[0m"
|
||||
else
|
||||
@@ -62,14 +62,14 @@ mw_stop()
|
||||
PLIST=`ps -ef|grep app:app |grep -v grep|awk '{print $2}'`
|
||||
for i in $PLIST
|
||||
do
|
||||
kill -9 $i
|
||||
kill -9 $i > /dev/null 2>&1
|
||||
done
|
||||
|
||||
pids=`ps -ef|grep task.py | grep -v grep |awk '{print $2}'`
|
||||
arr=($pids)
|
||||
for p in ${arr[@]}
|
||||
do
|
||||
kill -9 $p
|
||||
kill -9 $p > /dev/null 2>&1
|
||||
done
|
||||
}
|
||||
|
||||
|
||||
@@ -194,14 +194,17 @@ def backupAllFunc(stype):
|
||||
'/scripts/backup.py ' + args
|
||||
|
||||
os.system(cmd)
|
||||
# 开始执行上传信息
|
||||
|
||||
bk_prefix = prefix_dict[stype]
|
||||
bk_name = stype
|
||||
# 开始执行上传信息.
|
||||
|
||||
if stype.find('database_') > -1:
|
||||
bk_name = 'database'
|
||||
plugin_name = stype.replace('database_', '')
|
||||
bk_prefix = plugin_name + '/db'
|
||||
stype = 'database'
|
||||
else:
|
||||
bk_prefix = prefix_dict[stype]
|
||||
bk_name = stype
|
||||
|
||||
find_path = mw.getBackupDir() + '/' + bk_name + '/' + bk_prefix + '_' + name
|
||||
find_new_file = "ls " + find_path + \
|
||||
@@ -212,10 +215,10 @@ def backupAllFunc(stype):
|
||||
mw.echoInfo("not find upload file!")
|
||||
return False
|
||||
|
||||
print("|-准备上传文件 {}".format(filename))
|
||||
ftp = FtpPSClient()
|
||||
ftp.uploadFile(filename, stype)
|
||||
|
||||
return True
|
||||
return ''
|
||||
|
||||
|
||||
def backupSite():
|
||||
|
||||
@@ -8,8 +8,8 @@
|
||||
<p onclick="pluginConfig('gitea',null, 'conf');">配置文件</p>
|
||||
<p onclick="gogsSetConfig();">配置修改</p>
|
||||
<p onclick="giteaUserList();">用户列表</p>
|
||||
<p onclick="pluginLogs('gitea',null,'run_log');">运行日志</p>
|
||||
<p onclick="pluginLogs('gitea',null,'post_receive_log');" title="提交post-receive日志">提交日志</p>
|
||||
<!-- <p onclick="pluginLogs('gitea',null,'run_log');">运行日志</p> -->
|
||||
<!-- <p onclick="pluginLogs('gitea',null,'post_receive_log');" title="提交post-receive日志">提交日志</p> -->
|
||||
<p onclick="giteaRead();">使用说明</p>
|
||||
</div>
|
||||
<div class="bt-w-con pd15">
|
||||
|
||||
@@ -560,7 +560,7 @@ def userProjectList():
|
||||
data['data'] = ret_data
|
||||
data['args'] = args
|
||||
data['list'] = mw.getPage(
|
||||
{'count': dlist_sum, 'p': page, 'row': page_size, 'tojs': 'userProjectList'})
|
||||
{'count': dlist_sum, 'p': page, 'row': page_size, 'tojs': 'userProjectListPost'})
|
||||
|
||||
return mw.returnJson(True, 'OK', data)
|
||||
|
||||
|
||||
@@ -187,7 +187,7 @@ function userProjectList(user, search){
|
||||
<thead><tr><th>项目</th><th>操作</th></tr></thead>\
|
||||
<tbody></tbody>\
|
||||
</table>\
|
||||
<div class='dataTables_paginate paging_bootstrap pagination' style='margin-top:0px;'><ul id='gitea_page' class='page'></ul></div>\
|
||||
<div class='dataTables_paginate paging_bootstrap pagination' style='margin-top:0px;'><ul class='page'><div class='gitea_page'></div></ul></div>\
|
||||
</div>\
|
||||
</div>\
|
||||
</div>",
|
||||
@@ -230,7 +230,8 @@ function userProjectListPost(user, search){
|
||||
var project_list = rdata['data']['data'];
|
||||
for (i in project_list) {
|
||||
var name = project_list[i]['name'];
|
||||
list += '<tr><td>'+name+'</td>\
|
||||
list += '<tr>\
|
||||
<td>'+name+'</td>\
|
||||
<td>\
|
||||
<a class="btlink" target="_blank" href="'+rdata['data']['root_url']+user+'/'+name+'">源码</a> | \
|
||||
<a class="btlink" onclick="projectScript(\''+user+'\',\''+name+'\','+project_list[i]['has_hook']+');">脚本</a>\
|
||||
|
||||
@@ -62,13 +62,16 @@ def getArgs():
|
||||
|
||||
if args_len == 1:
|
||||
t = args[0].strip('{').strip('}')
|
||||
t = t.split(':')
|
||||
if t.strip() == '':
|
||||
tmp = []
|
||||
else:
|
||||
t = t.split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
tmp[t[0]] = t[1]
|
||||
elif args_len > 1:
|
||||
for i in range(len(args)):
|
||||
t = args[i].split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
|
||||
return tmp
|
||||
|
||||
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 478 B |
Executable
+292
@@ -0,0 +1,292 @@
|
||||
<style>
|
||||
.migration_content {
|
||||
position: relative;
|
||||
height: 450px;
|
||||
}
|
||||
.step_head::after {
|
||||
background-color: #ddd;
|
||||
border-top: 2px solid #ccc;
|
||||
content: "";
|
||||
display: block;
|
||||
height: 3px;
|
||||
left: 84px;
|
||||
position: absolute;
|
||||
top: 14px;
|
||||
width: 500px;
|
||||
z-index: -1;
|
||||
}
|
||||
.step_head {
|
||||
margin: 20px 0;
|
||||
}
|
||||
.step_head ul li {
|
||||
width: 24.5%;
|
||||
display: inline-block;
|
||||
}
|
||||
.step_head ul li span {
|
||||
width: 30px;
|
||||
height: 30px;
|
||||
line-height: 30px;
|
||||
display: block;
|
||||
border-radius: 15px;
|
||||
background-color: #ddd;
|
||||
color: #878787;
|
||||
margin: 0 auto;
|
||||
text-align: center;
|
||||
font-size: 16px;
|
||||
font-weight: 600;
|
||||
}
|
||||
.step_head ul li p {
|
||||
text-align: center;
|
||||
margin-top: 15px;
|
||||
}
|
||||
.step_head ul li.active span {
|
||||
background-color: #20A53A;
|
||||
color: #fff;
|
||||
}
|
||||
.step_content {
|
||||
text-align: center;
|
||||
}
|
||||
.boxHide {
|
||||
display: none
|
||||
}
|
||||
.step_content .psync_info input {
|
||||
width: 300px;
|
||||
}
|
||||
.step_content .psync_info .panel_setp_span {
|
||||
height: 32px;
|
||||
line-height: 32px;
|
||||
overflow: hidden;
|
||||
padding-right: 20px;
|
||||
text-align: right;
|
||||
text-overflow: ellipsis;
|
||||
white-space: nowrap;
|
||||
width: 130px;
|
||||
display: inline-block;
|
||||
float: left;
|
||||
}
|
||||
.step_content .psync_info .mtb20{
|
||||
padding-left: 40px;
|
||||
text-align: left;
|
||||
}
|
||||
.psync_path .table {
|
||||
text-align: left;
|
||||
}
|
||||
.psync_path .table > tbody > tr > td:nth-child(2n),
|
||||
.psync_path .table > thead > tr > th:nth-child(2n),
|
||||
.terlist .table > thead > tr > th:nth-child(2n),
|
||||
.terlist .table > tbody > tr > td:nth-child(2n),
|
||||
.terlist .table > tbody > tr > td:nth-child(1),
|
||||
.terlist .table > thead > tr > th:nth-child(1) {
|
||||
border-right: #ddd 1px solid;
|
||||
}
|
||||
|
||||
.checkbox_conten {
|
||||
background-color: #f3f3f3;
|
||||
border: #ddd 1px solid;
|
||||
border-radius: 4px;
|
||||
padding: 10px;
|
||||
margin: 0px 50px;
|
||||
}
|
||||
|
||||
.checkbox_item span {
|
||||
display: inline-block;
|
||||
height: 15px;
|
||||
overflow: hidden;
|
||||
text-align: left;
|
||||
display: block;
|
||||
padding-left: 20px;
|
||||
height: 20px;
|
||||
line-height: 20px;
|
||||
width: 152px;
|
||||
text-overflow: ellipsis;
|
||||
}
|
||||
|
||||
label.checkbox_label {
|
||||
margin-left: 6px;
|
||||
margin-bottom: 0;
|
||||
}
|
||||
|
||||
label.checkbox_label span {
|
||||
color: #000;
|
||||
}
|
||||
.psync_data {
|
||||
display: none;
|
||||
}
|
||||
.psync_data .checkbox_item input[type="checkbox"] {
|
||||
width: 15px;
|
||||
height: 15px;
|
||||
position: absolute;
|
||||
top: 50%;
|
||||
margin-top: -6px;
|
||||
}
|
||||
|
||||
.checkbox_item label {
|
||||
font-weight: normal;
|
||||
white-space: nowrap;
|
||||
position: relative;
|
||||
}
|
||||
|
||||
.psync_data .checkbox_data {
|
||||
margin: 0 5px 5px;
|
||||
display: inline-block;
|
||||
width: 166px;
|
||||
vertical-align: text-top;
|
||||
}
|
||||
|
||||
.psync_data .checkbox_data:last-child {
|
||||
margin-right: 0;
|
||||
}
|
||||
|
||||
.checkbox_item ul {
|
||||
background-color: #fff;
|
||||
max-height: 174px;
|
||||
overflow: auto;
|
||||
width: 100%;
|
||||
display: block;
|
||||
margin-top: 10px;
|
||||
}
|
||||
|
||||
.checkbox_item ul li {
|
||||
padding: 0 6px;
|
||||
}
|
||||
|
||||
.psync_data .checkbox_con {
|
||||
display: block
|
||||
}
|
||||
|
||||
.progress {
|
||||
background-color: #e2e2e2;
|
||||
border-radius: 8px;
|
||||
height: 16px;
|
||||
line-height: 16px;
|
||||
position: relative;
|
||||
}
|
||||
|
||||
.progress-bar {
|
||||
background-color: #5ab76c;
|
||||
border-radius: 8px;
|
||||
height: 16px;
|
||||
max-width: 100%;
|
||||
position: absolute;
|
||||
text-align: right;
|
||||
transition: all 0.3s ease 0s;
|
||||
width: 0;
|
||||
}
|
||||
|
||||
.progress-text {
|
||||
font-size: 12px;
|
||||
color: #fff;
|
||||
padding: 0 10px;
|
||||
position: static;
|
||||
}
|
||||
|
||||
.qystatus {
|
||||
color: #666;
|
||||
margin-bottom: 10px;
|
||||
margin-left: 5px;
|
||||
}
|
||||
|
||||
.success {
|
||||
padding: 50px 0 60px;
|
||||
margin-left: -60px;
|
||||
}
|
||||
|
||||
.success p {
|
||||
margin-top: 20px;
|
||||
font-size: 16px;
|
||||
color: #666;
|
||||
}
|
||||
.psync_tips{
|
||||
color: red;
|
||||
font-size: 15px;
|
||||
background-color: #fbfbfb;
|
||||
border: 1px solid #eee;
|
||||
line-height: 46px;
|
||||
margin-bottom: 15px;
|
||||
padding-left: 10px;
|
||||
}
|
||||
.psync_tips span{
|
||||
font-size: 12px;
|
||||
}
|
||||
</style>
|
||||
<div class="migration_api pd15">
|
||||
<div class="migration_content">
|
||||
<div class="step_head">
|
||||
<ul>
|
||||
<li class="active"><span>1</span><p>填写信息</p></li>
|
||||
<li><span>2</span><p>检测环境</p></li>
|
||||
<li><span>3</span><p>选择数据</p></li>
|
||||
<li><span>4</span><p>一键迁移</p></li>
|
||||
</ul>
|
||||
</div>
|
||||
|
||||
<div class="step_content">
|
||||
<div class="pd15 psync_info">
|
||||
<div class="psync_tips">
|
||||
<span class="glyphicon glyphicon-alert" style="color: #f39c12; margin-right: 10px;"></span>只需在发送数据服务器安装本软件,请填写<span>『 接收数据服务器 』</span>资料。
|
||||
<a href="#" target="_blank" class="bt-ico-ask" style="cursor: pointer;">?</a>
|
||||
</div>
|
||||
<div class="mtb20">
|
||||
<span class="panel_setp_span">接收数据的面板地址</span>
|
||||
<input type="text" class="bt-input-text" name="psync_url" value="" placeholder="接收数据面板地址,如: http://127.0.0.1:8888">
|
||||
</div>
|
||||
<div class="mtb20">
|
||||
<span class="panel_setp_span">接收数据的面板API</span>
|
||||
<input type="text" class="bt-input-text" name="psync_token" value="" placeholder="接收数据面板API密钥" />
|
||||
<a href="#" target="_blank" class="btlink ml5">获取API秘钥</a>
|
||||
</div>
|
||||
<div class="mtb20">
|
||||
<span class="panel_setp_span">IP白名单</span>
|
||||
<span style="height: 32px;line-height: 32px;">必须将本机器IP加入接收数据服务器API的IP白名单,<a href="#" href="javascript:;" target="_blank" class="btlink">如何添加白名单</a></span>
|
||||
</div>
|
||||
<div class="mtb20" style="text-align: left;margin-left: 130px;">
|
||||
<button class="btn btn-success infoNext">下一步</button>
|
||||
</div>
|
||||
</div>
|
||||
<div class="pa15 psync_path" style="margin:0 50px">
|
||||
</div>
|
||||
<div class="pa15 psync_data" style="text-align: left;">
|
||||
<div class="checkbox_conten">
|
||||
<div class="checkbox_data">
|
||||
<div class="checkbox_item">
|
||||
<label class="checkbox_label">
|
||||
<input type="checkbox" id="sites_All" checked>
|
||||
<span>网站</span>
|
||||
</label>
|
||||
<ul></ul>
|
||||
</div>
|
||||
</div>
|
||||
<div class="checkbox_data">
|
||||
<div class="checkbox_item">
|
||||
<label class="checkbox_label">
|
||||
<input type="checkbox" id="db_All" checked>
|
||||
<span>数据库</span>
|
||||
</label>
|
||||
<ul></ul>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="line mtb20" style="margin:20px 0 0 50px">
|
||||
<button class="btn btn-default btn-sm mr20 dataBack">上一步</button>
|
||||
<button class="btn btn-success btn-sm dataMigrate">一键迁移</button>
|
||||
</div>
|
||||
</div>
|
||||
<div class="pa15 psync_migrate"></div>
|
||||
</div>
|
||||
<hr style="margin-top: 5px;" />
|
||||
<div class="step_footer" style="margin: 5px 0 0 20px;text-align: left;">
|
||||
<ul class="help-info-text c7 mlr20" style="margin-top: 0px;">
|
||||
<li>一键迁移过程中是后台执行可以关闭当前窗口</li>
|
||||
<li>一键迁移迁移数据不涉及原来数据的增删(是将原来数据打包发送)</li>
|
||||
</ul>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
|
||||
<script type="text/javascript">
|
||||
resetPluginWinWidth(700);
|
||||
$.getScript( "/plugins/file?name=migration_api&f=js/app.js", function(){
|
||||
initStep();
|
||||
});
|
||||
</script>
|
||||
Executable
+102
@@ -0,0 +1,102 @@
|
||||
# coding:utf-8
|
||||
|
||||
import sys
|
||||
import io
|
||||
import os
|
||||
import time
|
||||
import re
|
||||
|
||||
sys.path.append(os.getcwd() + "/class/core")
|
||||
import mw
|
||||
|
||||
app_debug = False
|
||||
if mw.isAppleSystem():
|
||||
app_debug = True
|
||||
|
||||
|
||||
def getPluginName():
|
||||
return 'migration_api'
|
||||
|
||||
|
||||
def getPluginDir():
|
||||
return mw.getPluginDir() + '/' + getPluginName()
|
||||
|
||||
|
||||
def getServerDir():
|
||||
return mw.getServerDir() + '/' + getPluginName()
|
||||
|
||||
|
||||
def getInitDFile():
|
||||
if app_debug:
|
||||
return '/tmp/' + getPluginName()
|
||||
return '/etc/init.d/' + getPluginName()
|
||||
|
||||
|
||||
def getConf():
|
||||
path = getServerDir() + "/ma.cfg"
|
||||
return path
|
||||
|
||||
|
||||
def getCfgData():
|
||||
path = getConf()
|
||||
if not os.path.exists(path):
|
||||
mw.writeFile(path, '{}')
|
||||
|
||||
t = mw.returnJson(path)
|
||||
return json.loads(t)
|
||||
|
||||
|
||||
def getArgs():
|
||||
args = sys.argv[2:]
|
||||
tmp = {}
|
||||
args_len = len(args)
|
||||
|
||||
if args_len == 1:
|
||||
t = args[0].strip('{').strip('}')
|
||||
if t.strip() == '':
|
||||
tmp = []
|
||||
else:
|
||||
t = t.split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
tmp[t[0]] = t[1]
|
||||
elif args_len > 1:
|
||||
for i in range(len(args)):
|
||||
t = args[i].split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
return tmp
|
||||
|
||||
|
||||
def checkArgs(data, ck=[]):
|
||||
for i in range(len(ck)):
|
||||
if not ck[i] in data:
|
||||
return (False, mw.returnJson(False, '参数:(' + ck[i] + ')没有!'))
|
||||
return (True, mw.returnJson(True, 'ok'))
|
||||
|
||||
|
||||
def status():
|
||||
return 'start'
|
||||
|
||||
|
||||
def initDreplace():
|
||||
return 'ok'
|
||||
|
||||
|
||||
def stepOne():
|
||||
data = getCfgData()
|
||||
print(data)
|
||||
|
||||
return mw.returnJson(True, 'ok')
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
func = sys.argv[1]
|
||||
if func == 'status':
|
||||
print(status())
|
||||
elif func == 'start':
|
||||
print(start())
|
||||
elif func == 'stop':
|
||||
print(stop())
|
||||
elif func == 'step_one':
|
||||
print(saveConf())
|
||||
else:
|
||||
print('error')
|
||||
Executable
+18
@@ -0,0 +1,18 @@
|
||||
{
|
||||
"sort": 7,
|
||||
"ps": "[<span style='color:red;'>潜龙勿用</span>]一键迁移,仅网站数据和MySQL数据",
|
||||
"name": "migration_api",
|
||||
"title": "一键迁移API",
|
||||
"shell": "install.sh",
|
||||
"versions":["1.0"],
|
||||
"updates":["1.0"],
|
||||
"tip": "soft",
|
||||
"checks": "server/migration_api",
|
||||
"path":"server/migration_api",
|
||||
"display": 1,
|
||||
"author": "midoks",
|
||||
"date": "2022-01-17",
|
||||
"home": "https://github.com/midoks/mdserver-web",
|
||||
"type": 0,
|
||||
"pid": "4"
|
||||
}
|
||||
Executable
+31
@@ -0,0 +1,31 @@
|
||||
#!/bin/bash
|
||||
|
||||
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
|
||||
export PATH
|
||||
|
||||
curPath=`pwd`
|
||||
rootPath=$(dirname "$curPath")
|
||||
rootPath=$(dirname "$rootPath")
|
||||
serverPath=$(dirname "$rootPath")
|
||||
|
||||
install_tmp=${rootPath}/tmp/mw_install.pl
|
||||
|
||||
VERSION=1.0
|
||||
|
||||
Install_App(){
|
||||
mkdir -p $serverPath/migration_api
|
||||
echo "${VERSION}" > $serverPath/migration_api/version.pl
|
||||
echo '正在安装脚本文件...' > $install_tmp
|
||||
}
|
||||
|
||||
Uninstall_App()
|
||||
{
|
||||
rm -rf $serverPath/migration_api
|
||||
}
|
||||
|
||||
action=$1
|
||||
if [ "${1}" == 'install' ];then
|
||||
Install_App
|
||||
else
|
||||
Uninstall_App
|
||||
fi
|
||||
Executable
+109
@@ -0,0 +1,109 @@
|
||||
function maPost(method,args,callback){
|
||||
var _args = null;
|
||||
if (typeof(args) == 'string'){
|
||||
_args = JSON.stringify(toArrayObject(args));
|
||||
} else {
|
||||
_args = JSON.stringify(args);
|
||||
}
|
||||
|
||||
var loadT = layer.msg('正在获取...', { icon: 16, time: 0, shade: 0.3 });
|
||||
$.post('/plugins/run', {name:'migration_api', func:method, args:_args}, function(data) {
|
||||
layer.close(loadT);
|
||||
if (!data.status){
|
||||
layer.msg(data.msg,{icon:0,time:2000,shade: [0.3, '#000']});
|
||||
return;
|
||||
}
|
||||
|
||||
if(typeof(callback) == 'function'){
|
||||
callback(data);
|
||||
}
|
||||
},'json');
|
||||
}
|
||||
|
||||
function maAsyncPost(method,args){
|
||||
var _args = null;
|
||||
if (typeof(args) == 'string'){
|
||||
_args = JSON.stringify(toArrayObject(args));
|
||||
} else {
|
||||
_args = JSON.stringify(args);
|
||||
}
|
||||
return syncPost('/plugins/run', {name:'migration_api', func:method, args:_args});
|
||||
}
|
||||
|
||||
function maPostCallbak(method, args, callback){
|
||||
var loadT = layer.msg('正在获取...', { icon: 16, time: 0, shade: 0.3 });
|
||||
|
||||
var req_data = {};
|
||||
req_data['name'] = 'migration_api';
|
||||
req_data['func'] = method;
|
||||
args['version'] = '1.0';
|
||||
|
||||
if (typeof(args) == 'string'){
|
||||
req_data['args'] = JSON.stringify(toArrayObject(args));
|
||||
} else {
|
||||
req_data['args'] = JSON.stringify(args);
|
||||
}
|
||||
|
||||
$.post('/plugins/callback', req_data, function(data) {
|
||||
layer.close(loadT);
|
||||
if (!data.status){
|
||||
layer.msg(data.msg,{icon:0,time:2000,shade: [0.3, '#000']});
|
||||
return;
|
||||
}
|
||||
|
||||
if(typeof(callback) == 'function'){
|
||||
callback(data);
|
||||
}
|
||||
},'json');
|
||||
}
|
||||
|
||||
|
||||
function initStep1(){
|
||||
maPost('step_one',{}, function(rdata){
|
||||
console.log(rdata);
|
||||
});
|
||||
}
|
||||
|
||||
function initStep2(){
|
||||
maPost('step_one',{}, function(rdata){
|
||||
console.log(rdata);
|
||||
});
|
||||
}
|
||||
|
||||
function initStep3(){
|
||||
maPost('step_one',{}, function(rdata){
|
||||
console.log(rdata);
|
||||
});
|
||||
}
|
||||
|
||||
function initStep4(){
|
||||
maPost('step_one',{}, function(rdata){
|
||||
console.log(rdata);
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
function initStep(){
|
||||
console.log($('.infoNext'));
|
||||
$('.infoNext').click(function(){
|
||||
var step = $('.step_head .active span').text();
|
||||
// console.log(step);
|
||||
// initStep1();
|
||||
switch(step){
|
||||
case '1':initStep1();break;
|
||||
case '2':initStep2();break;
|
||||
case '3':initStep3();break;
|
||||
case '4':initStep4();break;
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -2682,6 +2682,9 @@ def uninstallPreInspection(version):
|
||||
if mw.isDebugMode():
|
||||
return 'ok'
|
||||
|
||||
import plugins_api
|
||||
plugins_api.plugins_api().removeIndex(getPluginName(), version)
|
||||
|
||||
return "请手动删除MySQL[{}]<br/> rm -rf {}".format(version, getServerDir())
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
||||
@@ -2639,6 +2639,9 @@ def uninstallPreInspection(version):
|
||||
if mw.isDebugMode():
|
||||
return 'ok'
|
||||
|
||||
import plugins_api
|
||||
plugins_api.plugins_api().removeIndex(getPluginName(), version)
|
||||
|
||||
return "请手动删除MySQL[{}]<br/> rm -rf {}".format(version, getServerDir())
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
||||
@@ -2804,6 +2804,9 @@ def uninstallPreInspection(version):
|
||||
if mw.isDebugMode():
|
||||
return 'ok'
|
||||
|
||||
import plugins_api
|
||||
plugins_api.plugins_api().removeIndex(getPluginName(), version)
|
||||
|
||||
return "请手动删除MySQL[{}]<br/> rm -rf {}".format(version, getServerDir())
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
||||
+53
-53
@@ -225,6 +225,7 @@ def initTotalInfo():
|
||||
_name[name] = tmp
|
||||
total_contents['sites'] = _name
|
||||
|
||||
total_contents['start_time'] = str(time.time())
|
||||
cjson = mw.getJson(total_contents)
|
||||
mw.writeFile(path_total, cjson)
|
||||
|
||||
@@ -324,8 +325,41 @@ def restartWeb():
|
||||
mw.opWeb('start')
|
||||
|
||||
|
||||
def initDreplace():
|
||||
def makeDstLua():
|
||||
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
|
||||
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
|
||||
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
|
||||
path = getServerDir()
|
||||
path_tpl = getPluginDir()
|
||||
|
||||
waf_common_tpl = path_tpl + "/waf/lua/waf_common.lua"
|
||||
waf_common_dst = path + "/waf/lua/waf_common.lua"
|
||||
content = mw.readFile(waf_common_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(waf_common_dst, content)
|
||||
|
||||
waf_init_tpl = path_tpl + "/waf/lua/init_preload.lua"
|
||||
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
|
||||
content = mw.readFile(waf_init_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(waf_init_dst, content)
|
||||
|
||||
init_worker_tpl = path_tpl + "/waf/lua/init_worker.lua"
|
||||
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
|
||||
content = mw.readFile(init_worker_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(init_worker_dst, content)
|
||||
|
||||
access_file_tpl = path_tpl + "/waf/lua/init.lua"
|
||||
access_file_dst = root_access_dir + '/opwaf_init.lua'
|
||||
content = mw.readFile(access_file_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(access_file_dst, content)
|
||||
|
||||
mw.opLuaMakeAll()
|
||||
|
||||
|
||||
def initDreplace():
|
||||
path = getServerDir()
|
||||
if not os.path.exists(path + '/waf/lua'):
|
||||
sdir = getPluginDir() + '/waf'
|
||||
@@ -348,20 +382,7 @@ def initDreplace():
|
||||
content['reqfile_path'] = wfDir
|
||||
mw.writeFile(config, mw.getJson(content))
|
||||
|
||||
config = path + "/waf/lua/init.lua"
|
||||
content = mw.readFile(config)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(config, content)
|
||||
|
||||
config_common = path + "/waf/lua/common.lua"
|
||||
content = mw.readFile(config_common)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(config_common, content)
|
||||
|
||||
init_worker = path + "/waf/lua/init_worker.lua"
|
||||
content = mw.readFile(init_worker)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(init_worker, content)
|
||||
makeDstLua()
|
||||
|
||||
waf_conf = dstWafConf()
|
||||
if not os.path.exists(waf_conf):
|
||||
@@ -396,16 +417,6 @@ def status():
|
||||
def start():
|
||||
initDreplace()
|
||||
|
||||
path = mw.getServerDir() + '/web_conf/nginx/lua/lua.conf'
|
||||
init_worker_lua = getServerDir() + '/waf/lua/init_worker.lua'
|
||||
init_lua = getServerDir() + '/waf/lua/init.lua'
|
||||
conf = mw.readFile(path)
|
||||
conf = re.sub('init_worker_by_lua_file (.*);',
|
||||
"init_worker_by_lua_file " + init_worker_lua + ";", conf)
|
||||
conf = re.sub('access_by_lua_file (.*);',
|
||||
"access_by_lua_file " + init_lua + ";", conf)
|
||||
mw.writeFile(path, conf)
|
||||
|
||||
import tool_task
|
||||
tool_task.createBgTask()
|
||||
|
||||
@@ -414,15 +425,21 @@ def start():
|
||||
|
||||
|
||||
def stop():
|
||||
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
|
||||
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
|
||||
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
|
||||
|
||||
path = mw.getServerDir() + '/web_conf/nginx/lua/lua.conf'
|
||||
empty_lua = mw.getServerDir() + '/web_conf/nginx/lua/empty.lua'
|
||||
conf = mw.readFile(path)
|
||||
conf = re.sub('init_worker_by_lua_file (.*);',
|
||||
"init_worker_by_lua_file " + empty_lua + ";", conf)
|
||||
conf = re.sub('access_by_lua_file (.*);',
|
||||
"access_by_lua_file " + empty_lua + ";", conf)
|
||||
mw.writeFile(path, conf)
|
||||
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
|
||||
if os.path.exists(waf_init_dst):
|
||||
os.remove(waf_init_dst)
|
||||
|
||||
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
|
||||
if os.path.exists(init_worker_dst):
|
||||
os.remove(init_worker_dst)
|
||||
|
||||
access_file_dst = root_access_dir + '/opwaf_init.lua'
|
||||
if os.path.exists(access_file_dst):
|
||||
os.remove(access_file_dst)
|
||||
|
||||
wafconf = dstWafConf()
|
||||
if os.path.exists(wafconf):
|
||||
@@ -431,6 +448,8 @@ def stop():
|
||||
import tool_task
|
||||
tool_task.removeBgTask()
|
||||
|
||||
mw.opLuaMakeAll()
|
||||
|
||||
restartWeb()
|
||||
return 'ok'
|
||||
|
||||
@@ -443,26 +462,7 @@ def restart():
|
||||
def reload():
|
||||
stop()
|
||||
|
||||
path = getServerDir()
|
||||
path_tpl = getPluginDir()
|
||||
|
||||
config = path + "/waf/lua/common.lua"
|
||||
config_tpl = path_tpl + "/waf/lua/common.lua"
|
||||
content = mw.readFile(config_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(config, content)
|
||||
|
||||
config = path + "/waf/lua/init_worker.lua"
|
||||
config_tpl = path_tpl + "/waf/lua/init_worker.lua"
|
||||
content = mw.readFile(config_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(config, content)
|
||||
|
||||
config = path + "/waf/lua/init.lua"
|
||||
config_tpl = path_tpl + "/waf/lua/init.lua"
|
||||
content = mw.readFile(config_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(config, content)
|
||||
makeDstLua()
|
||||
|
||||
errlog = mw.getServerDir() + "/openresty/nginx/logs/error.log"
|
||||
mw.execShell('rm -rf ' + errlog)
|
||||
|
||||
@@ -12,5 +12,5 @@
|
||||
"home":"https://github.com/loveshell/ngx_lua_waf",
|
||||
"date":"2019-04-21",
|
||||
"pid": "1",
|
||||
"versions": ["0.2.4"]
|
||||
"versions": ["0.2.5"]
|
||||
}
|
||||
@@ -24,7 +24,7 @@ else
|
||||
fi
|
||||
|
||||
|
||||
Install_of(){
|
||||
Install_App(){
|
||||
|
||||
echo '正在安装脚本文件...' > $install_tmp
|
||||
mkdir -p $serverPath/source/op_waf
|
||||
@@ -41,7 +41,9 @@ Install_of(){
|
||||
cd $serverPath/source/op_waf && tar xvf luarocks-3.5.0.tar.gz
|
||||
# cd luarocks-3.9.1 && ./configure && make bootstrap
|
||||
|
||||
cd luarocks-3.5.0 && ./configure --prefix=$serverPath/op_waf/luarocks --with-lua-include=$serverPath/openresty/luajit/include/luajit-2.1 --with-lua-bin=$serverPath/openresty/luajit/bin
|
||||
cd luarocks-3.5.0 && ./configure --prefix=$serverPath/op_waf/luarocks \
|
||||
--with-lua-include=$serverPath/openresty/luajit/include/luajit-2.1 \
|
||||
--with-lua-bin=$serverPath/openresty/luajit/bin
|
||||
make -I${serverPath}/openresty/luajit/bin
|
||||
make install
|
||||
fi
|
||||
@@ -85,13 +87,10 @@ Install_of(){
|
||||
echo 'install ok' > $install_tmp
|
||||
|
||||
cd ${rootPath} && python3 ${rootPath}/plugins/op_waf/index.py start
|
||||
|
||||
|
||||
|
||||
# cd ${rootPath} && python3 ${rootPath}/plugins/op_waf/index.py restart
|
||||
}
|
||||
|
||||
Uninstall_of(){
|
||||
Uninstall_App(){
|
||||
|
||||
cd ${rootPath} && python3 ${rootPath}/plugins/op_waf/index.py stop
|
||||
if [ "$?" == "0" ];then
|
||||
@@ -102,7 +101,7 @@ Uninstall_of(){
|
||||
|
||||
action=$1
|
||||
if [ "${1}" == 'install' ];then
|
||||
Install_of
|
||||
Install_App
|
||||
else
|
||||
Uninstall_of
|
||||
Uninstall_App
|
||||
fi
|
||||
|
||||
@@ -961,8 +961,12 @@ function wafScreen(){
|
||||
owPost('waf_srceen', {}, function(data){
|
||||
var rdata = $.parseJSON(data.data);
|
||||
|
||||
var end_time = Date.now();
|
||||
var cos_time = (end_time/1000) - parseInt(rdata['start_time']);
|
||||
var cos_day = parseInt(parseInt(cos_time)/86400);
|
||||
|
||||
var con = '<div class="wavbox alert alert-success" style="margin-right:16px">总拦截<span>'+rdata.total+'</span>次</div>';
|
||||
con += '<div class="wavbox alert alert-info" style="margin-right:16px">安全防护<span>0</span>天</div>';
|
||||
con += '<div class="wavbox alert alert-info" style="margin-right:16px">安全防护<span>'+cos_day+'</span>天</div>';
|
||||
|
||||
con += '<div class="screen">\
|
||||
<div class="line"><span class="name">POST渗透</span><span class="val">'+rdata.rules.post+'</span></div>\
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
#!/bin/bash
|
||||
|
||||
DST_DIR=/www/server/op_waf
|
||||
DIS_FILE=${DST_DIR}/cpu.info
|
||||
|
||||
CPU_USAGE=`top -bn 1 | fgrep 'Cpu(s)' | awk '{print 100 -$8}' | awk -F . '{print $1}'`
|
||||
echo $CPU_USAGE
|
||||
echo $CPU_USAGE > $DIS_FILE
|
||||
echo "done success!"
|
||||
@@ -0,0 +1,50 @@
|
||||
#!/bin/bash
|
||||
|
||||
DST_DIR=/www/server/op_waf
|
||||
DIS_FILE=${DST_DIR}/cpu.info
|
||||
|
||||
function GetCpuUsage(){
|
||||
cpu_info=`cat /proc/stat | head -n 1`
|
||||
idle_cpu=`echo $cpu_info|awk '{print $2}'`
|
||||
cpu_total_time=0
|
||||
for ci in ${cpu_info[@]}; do
|
||||
if [ "$ci" == "cpu" ];then
|
||||
continue
|
||||
else
|
||||
#echo $ci
|
||||
cpu_total_time=`expr $cpu_total_time + $ci`
|
||||
fi
|
||||
done
|
||||
#echo "idle_cpu:${idle_cpu}"
|
||||
#echo "cpu_total_time:${cpu_total_time}"
|
||||
|
||||
cpu_percet=$(awk "BEGIN{print ((${cpu_total_time}-${idle_cpu})/${cpu_total_time})*100}")
|
||||
echo "${cpu_percet}"
|
||||
return 0
|
||||
}
|
||||
|
||||
# one value detal
|
||||
getOne=`GetCpuUsage`
|
||||
|
||||
CPU_USAGE=`echo $getOne | awk -F . '{print $1}'`
|
||||
echo "cpu usage:${CPU_USAGE}"
|
||||
echo $CPU_USAGE > $DIS_FILE
|
||||
echo "done success!"
|
||||
|
||||
|
||||
# two value compare
|
||||
|
||||
# getOne=`GetCpuUsage`
|
||||
# echo "getOne:$getOne"
|
||||
# sleep 1
|
||||
# getTwo=`GetCpuUsage`
|
||||
# echo "getTwo:$getTwo"
|
||||
|
||||
# cpu_percet_calc=$(awk "BEGIN{print (${getOne}+${getTwo})/2}")
|
||||
# echo "cpu_percet_calc:${cpu_percet_calc}"
|
||||
|
||||
# #echo '0.61212' | awk -F . '{print $1}'
|
||||
# CPU_USAGE=`echo $cpu_percet_calc | awk -F . '{print $1}'`
|
||||
# echo "cpu usage:${CPU_USAGE}"
|
||||
# echo $CPU_USAGE > $DIS_FILE
|
||||
# echo "done success!"
|
||||
@@ -26,4 +26,5 @@ fi
|
||||
# $RUN_CMD --stap --shdict 'limit 10m' test_find_server_name.lua
|
||||
|
||||
# $RUN_CMD test_rand.lua
|
||||
$RUN_CMD test_ffi_time.lua
|
||||
# $RUN_CMD test_ffi_time.lua
|
||||
$RUN_CMD test_get_cpu.lua
|
||||
@@ -0,0 +1,69 @@
|
||||
-- cd /www/server/mdserver-web/plugins/op_waf/t/bench && bash bench.sh
|
||||
|
||||
local function target()
|
||||
ngx.re.find("hello, world.", [[\w+\.]], "jo")
|
||||
end
|
||||
for i = 1, 100 do
|
||||
target()
|
||||
end
|
||||
|
||||
local function file_exists(path)
|
||||
local file = io.open(path, "rb")
|
||||
if file then file:close() end
|
||||
return file ~= nil
|
||||
end
|
||||
|
||||
-- 以上为预热操作
|
||||
collectgarbage()
|
||||
|
||||
local json = require "cjson"
|
||||
local ngx_re = require "ngx.re"
|
||||
|
||||
local function data_split(self, str,reps )
|
||||
local rsList = {}
|
||||
string.gsub(str,'[^'..reps..']+',function(w)
|
||||
table.insert(rsList,w)
|
||||
end)
|
||||
return rsList
|
||||
end
|
||||
|
||||
local function get_cpu_stat()
|
||||
local cpu_total = 0
|
||||
local fp = io.open('/proc/stat','r')
|
||||
local cpu_line = fp:read()
|
||||
fp:close()
|
||||
|
||||
local list = ngx_re.split(cpu_line," ")
|
||||
table.remove(list,1)
|
||||
table.remove(list,1)
|
||||
|
||||
local idie = list[4]
|
||||
for i,v in pairs(list)
|
||||
do
|
||||
cpu_total = cpu_total + v
|
||||
end
|
||||
|
||||
local use_percent = tonumber(100-(idie/cpu_total)*100)
|
||||
|
||||
return cpu_total,idie,use_percent
|
||||
end
|
||||
|
||||
local function get_cpu_percent()
|
||||
local cpu_total,idie,use_percent = get_cpu_stat()
|
||||
ngx.sleep(2)
|
||||
local cpu_total2,idie2,use_percent2 = get_cpu_stat()
|
||||
local cpu_usage_percent = tonumber(100-(((idie2-idie)/(cpu_total2-cpu_total))*100))
|
||||
ngx.say("cpu_usage_percent:"..cpu_usage_percent)
|
||||
return cpu_usage_percent
|
||||
end
|
||||
|
||||
ngx.update_time()
|
||||
local begin = ngx.now()
|
||||
local N = 1e1
|
||||
for i = 1, N do
|
||||
get_cpu_stat()
|
||||
end
|
||||
ngx.update_time()
|
||||
|
||||
ngx.say("test_get_cpu elapsed: ", (ngx.now() - begin))
|
||||
|
||||
@@ -1,6 +1,46 @@
|
||||
#!/bin/sh
|
||||
export PATH=$PATH:/opt/stap/bin:/opt/stapxx
|
||||
|
||||
# cd /www/server/mdserver-web/plugins/op_waf/t && bash ngx_debug.sh lua ok
|
||||
# cd /www/server/mdserver-web/plugins/op_waf/t && bash ngx_debug.sh c ok
|
||||
|
||||
|
||||
if [ ${_os} == "Darwin" ]; then
|
||||
OSNAME='macos'
|
||||
elif grep -Eq "openSUSE" /etc/*-release; then
|
||||
OSNAME='opensuse'
|
||||
zypper refresh
|
||||
zypper install cron wget curl zip unzip
|
||||
elif grep -Eq "FreeBSD" /etc/*-release; then
|
||||
OSNAME='freebsd'
|
||||
elif grep -Eqi "CentOS" /etc/issue || grep -Eq "CentOS" /etc/*-release; then
|
||||
OSNAME='rhel'
|
||||
yum install -y wget curl zip unzip tar crontabs
|
||||
elif grep -Eqi "Fedora" /etc/issue || grep -Eq "Fedora" /etc/*-release; then
|
||||
OSNAME='fedora'
|
||||
yum install -y wget curl zip unzip tar crontabs
|
||||
elif grep -Eqi "Rocky" /etc/issue || grep -Eq "Rocky" /etc/*-release; then
|
||||
OSNAME='rhel'
|
||||
yum install -y wget curl zip unzip tar crontabs
|
||||
elif grep -Eqi "AlmaLinux" /etc/issue || grep -Eq "AlmaLinux" /etc/*-release; then
|
||||
OSNAME='rhel'
|
||||
yum install -y wget curl zip unzip tar crontabs
|
||||
elif grep -Eqi "Amazon Linux" /etc/issue || grep -Eq "Amazon Linux" /etc/*-release; then
|
||||
OSNAME='amazon'
|
||||
yum install -y wget curl zip unzip tar crontabs
|
||||
elif grep -Eqi "Debian" /etc/issue || grep -Eq "Debian" /etc/os-release; then
|
||||
OSNAME='debian'
|
||||
apt update -y
|
||||
apt install -y wget curl zip unzip tar cron
|
||||
elif grep -Eqi "Ubuntu" /etc/issue || grep -Eq "Ubuntu" /etc/os-release; then
|
||||
OSNAME='ubuntu'
|
||||
apt update -y
|
||||
apt install -y wget curl zip unzip tar cron
|
||||
else
|
||||
OSNAME='unknow'
|
||||
fi
|
||||
|
||||
|
||||
# https://moonbingbing.gitbooks.io/openresty-best-practices/content/flame_graph/install.html
|
||||
# apt install elfutils
|
||||
# sudo apt-get install -y systemtap gcc
|
||||
@@ -23,7 +63,7 @@ then
|
||||
exit
|
||||
fi
|
||||
|
||||
pid=`ps -ef|grep openresty | grep -v grep | awk '{print $2}'`
|
||||
pids=`ps -ef|grep nginx | grep -v grep | awk '{print $2}'`
|
||||
name=$2
|
||||
|
||||
|
||||
@@ -33,7 +73,13 @@ name=$2
|
||||
# apt install -y kernel-debuginfo-common kernel-debuginfo
|
||||
# apt install -y kernel-*
|
||||
|
||||
|
||||
if [ "$OSNAME" == "debian" ];then
|
||||
apt install -y systemtap
|
||||
apt-get install -y build-essential
|
||||
apt-get install -y linux-headers-$(uname -r)
|
||||
elif [ "$OSNAME" == "centos" ];then
|
||||
yum install -y kernel-devel-$(uname -r)
|
||||
fi
|
||||
|
||||
# /opt/stapxx/samples/lj-lua-stacks.sxx --arg time=5 --skip-badvars -x 45266 > tmp.bt
|
||||
|
||||
@@ -58,25 +104,45 @@ if [ ! -d /opt/FlameGraph ];then
|
||||
cd /opt && git clone https://github.com/brendangregg/FlameGraph
|
||||
fi
|
||||
|
||||
if [ $1 == "lua" ]; then
|
||||
# /opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p 377452 --luajit20 -t 30 >temp.bt
|
||||
/opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p $pid --luajit20 -t 30 >temp.bt
|
||||
# /opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >t1.bt
|
||||
/opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >${name}.bt
|
||||
elif [ $1 == "c" ]; then
|
||||
# /opt/openresty-systemtap-toolkit/sample-bt -p 496435 -t 10 -u > t2.bt
|
||||
/opt/openresty-systemtap-toolkit/sample-bt -p $pid -t 10 -u > ${name}.bt
|
||||
else
|
||||
echo "type is only lua/c"
|
||||
exit
|
||||
fi
|
||||
for pid in ${pids[@]}; do
|
||||
echo "strace:$pid"
|
||||
if [ $1 == "lua" ]; then
|
||||
# --without-luajit-gc64 | lua 模式编译时需要使用此参数
|
||||
/opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p $pid --luajit20 -t 30 >temp.bt
|
||||
/opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >${name}_${pid}.bt
|
||||
elif [ $1 == "c" ]; then
|
||||
/opt/openresty-systemtap-toolkit/sample-bt -p $pid -t 10 -u > ${name}_${pid}.bt
|
||||
else
|
||||
echo "type is only lua/c"
|
||||
exit
|
||||
fi
|
||||
|
||||
/opt/FlameGraph/stackcollapse-stap.pl ${name}_${pid}.bt >${name}_${pid}.cbt
|
||||
/opt/FlameGraph/flamegraph.pl ${name}_${pid}.cbt >${name}_${pid}.svg
|
||||
rm -f temp.bt ${name}_${pid}.bt ${name}_${pid}.cbt
|
||||
echo "strace:$pid, end!"
|
||||
echo "${name}_${pid}.svg -- make ok"
|
||||
done
|
||||
|
||||
# if [ $1 == "lua" ]; then
|
||||
# # /opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p 377452 --luajit20 -t 30 >temp.bt
|
||||
# /opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p $pid --luajit20 -t 30 >temp.bt
|
||||
# # /opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >t1.bt
|
||||
# /opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >${name}.bt
|
||||
# elif [ $1 == "c" ]; then
|
||||
# # /opt/openresty-systemtap-toolkit/sample-bt -p 496435 -t 10 -u > t2.bt
|
||||
# /opt/openresty-systemtap-toolkit/sample-bt -p $pid -t 10 -u > ${name}.bt
|
||||
# else
|
||||
# echo "type is only lua/c"
|
||||
# exit
|
||||
# fi
|
||||
|
||||
|
||||
# # debuginfo-install kernel-3.10.0-1160.80.1.el7.x86_64
|
||||
# # /opt/FlameGraph/stackcollapse-perf.pl perf.unfold &> perf.folded
|
||||
# # /opt/FlameGraph/flamegraph.pl perf.folded > perf.svg
|
||||
|
||||
# /opt/FlameGraph/stackcollapse-perf.pl perf.unfold &> perf.folded
|
||||
# /opt/FlameGraph/flamegraph.pl perf.folded > perf.svg
|
||||
|
||||
/opt/FlameGraph/stackcollapse-stap.pl ${name}.bt >${name}.cbt
|
||||
/opt/FlameGraph/flamegraph.pl ${name}.cbt >${name}.svg
|
||||
rm -f temp.bt ${name}.bt ${name}.cbt
|
||||
# /opt/FlameGraph/stackcollapse-stap.pl ${name}.bt >${name}.cbt
|
||||
# /opt/FlameGraph/flamegraph.pl ${name}.cbt >${name}.svg
|
||||
# rm -f temp.bt ${name}.bt ${name}.cbt
|
||||
|
||||
|
||||
@@ -54,7 +54,9 @@ def createBgTask():
|
||||
"period": "minute-n",
|
||||
"minute-n": "1",
|
||||
}
|
||||
createBgTaskByName(getPluginName(), args)
|
||||
|
||||
if mw.isAppleSystem():
|
||||
createBgTaskByName(getPluginName(), args)
|
||||
|
||||
|
||||
def createBgTaskByName(name, args):
|
||||
@@ -97,8 +99,14 @@ logs_file=$plugin_path/${rname}.log
|
||||
''' % (mw_dir, name, getServerDir(), getPluginDir())
|
||||
cmd += 'echo "★【`date +"%Y-%m-%d %H:%M:%S"`】 STSRT★" >> $logs_file' + "\n"
|
||||
cmd += 'echo ">>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>" >> $logs_file' + "\n"
|
||||
cmd += 'echo "cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1"' + "\n"
|
||||
cmd += 'cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1' + "\n"
|
||||
|
||||
if mw.isAppleSystem():
|
||||
cmd += 'echo "cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1"' + "\n"
|
||||
cmd += 'cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1' + "\n"
|
||||
else:
|
||||
cmd += 'echo "cd $mw_dir && source bin/activate && bash $script_path/shell/cpu_usage_file.sh >> $logs_file 2>&1"' + "\n"
|
||||
cmd += 'cd $mw_dir && source bin/activate && bash $script_path/shell/cpu_usage.sh >> $logs_file 2>&1' + "\n"
|
||||
|
||||
cmd += 'echo "【`date +"%Y-%m-%d %H:%M:%S"`】 END★" >> $logs_file' + "\n"
|
||||
cmd += 'echo "<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<" >> $logs_file' + "\n"
|
||||
|
||||
@@ -128,6 +136,9 @@ logs_file=$plugin_path/${rname}.log
|
||||
|
||||
|
||||
def removeBgTask():
|
||||
if not mw.isAppleSystem():
|
||||
return False
|
||||
|
||||
cfg_list = getConfigData()
|
||||
for x in range(len(cfg_list)):
|
||||
cfg = cfg_list[x]
|
||||
@@ -147,10 +158,15 @@ def removeBgTask():
|
||||
|
||||
|
||||
def getCpuUsed():
|
||||
import psutil
|
||||
used = psutil.cpu_percent(interval=1)
|
||||
path = getServerDir() + "/cpu.info"
|
||||
mw.writeFile(path, str(int(used)))
|
||||
if mw.isAppleSystem():
|
||||
import psutil
|
||||
used = psutil.cpu_percent(interval=1)
|
||||
mw.writeFile(path, str(int(used)))
|
||||
else:
|
||||
cmd = "top -bn 1 | fgrep 'Cpu(s)' | awk '{print 100 -$8}' | awk -F . '{print $1}'"
|
||||
data = mw.execShell(cmd)
|
||||
mw.writeFile(path, str(int(data[0].strip())))
|
||||
|
||||
|
||||
def run():
|
||||
|
||||
@@ -1,19 +1,8 @@
|
||||
local waf_root = "{$WAF_ROOT}"
|
||||
local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
|
||||
local waf_sopath = waf_root.."/waf/conf/?.so;"
|
||||
|
||||
if not package.path:find(waf_cpath) then
|
||||
package.path = waf_cpath .. package.path
|
||||
end
|
||||
|
||||
if not package.cpath:find(waf_sopath) then
|
||||
package.cpath = waf_sopath .. package.cpath
|
||||
end
|
||||
|
||||
local json = require "cjson"
|
||||
local ngx_match = ngx.re.find
|
||||
|
||||
local __WAF = require "common"
|
||||
local __WAF = require "waf_common"
|
||||
|
||||
-- print(json.encode(__C))
|
||||
local C = __WAF:getInstance()
|
||||
@@ -47,7 +36,8 @@ local url_rules = require "rule_url"
|
||||
local url_white_rules = require "rule_url_white"
|
||||
|
||||
|
||||
local server_name = string.gsub(C:get_sn(config_domains),'_','.')
|
||||
-- local server_name = string.gsub(C:get_sn(config_domains),'_','.')
|
||||
local server_name = C:get_sn(config_domains)
|
||||
|
||||
local function initParams()
|
||||
local data = {}
|
||||
@@ -533,41 +523,58 @@ end
|
||||
|
||||
function waf()
|
||||
min_route()
|
||||
-- C:D("min_route")
|
||||
-- white ip
|
||||
if waf_ip_white() then return true end
|
||||
-- C:D("waf_ip_white")
|
||||
|
||||
-- url white
|
||||
if waf_url_white() then return true end
|
||||
-- C:D("waf_url_white")
|
||||
|
||||
-- black ip
|
||||
if waf_ip_black() then return true end
|
||||
-- C:D("waf_ip_black")
|
||||
|
||||
-- 封禁ip返回
|
||||
if waf_drop_ip() then return true end
|
||||
-- C:D("waf_drop_ip")
|
||||
|
||||
-- ua check
|
||||
if waf_user_agent() then return true end
|
||||
-- C:D("waf_user_agent")
|
||||
if waf_url() then return true end
|
||||
-- C:D("waf_url")
|
||||
|
||||
-- cc setting
|
||||
if waf_cc_increase() then return true end
|
||||
-- C:D("waf_cc_increase")
|
||||
if waf_cc() then return true end
|
||||
-- C:D("waf_cc")
|
||||
|
||||
-- cookie检查
|
||||
if waf_cookie() then return true end
|
||||
-- C:D("waf_cookie")
|
||||
|
||||
-- args参数拦截
|
||||
if waf_get_args() then return true end
|
||||
-- C:D("waf_get_args")
|
||||
|
||||
-- 扫描软件禁止
|
||||
if waf_scan_black() then return true end
|
||||
-- C:D("waf_scan_black")
|
||||
if waf_post() then return true end
|
||||
-- C:D("waf_post")
|
||||
|
||||
if site_config[server_name] and site_config[server_name]['open'] then
|
||||
if X_Forwarded() then return true end
|
||||
-- C:D("X_Forwarded")
|
||||
if post_X_Forwarded() then return true end
|
||||
-- C:D("post_X_Forwarded")
|
||||
if url_ext() then return true end
|
||||
-- C:D("url_ext")
|
||||
if post_data() then return true end
|
||||
-- C:D("post_data")
|
||||
end
|
||||
end
|
||||
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
local waf_root = "{$WAF_ROOT}"
|
||||
local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
|
||||
local waf_sopath = waf_root.."/waf/conf/?.so;"
|
||||
|
||||
if not package.path:find(waf_cpath) then
|
||||
package.path = waf_cpath .. package.path
|
||||
end
|
||||
|
||||
if not package.cpath:find(waf_sopath) then
|
||||
package.cpath = waf_sopath .. package.cpath
|
||||
end
|
||||
@@ -1,38 +1,58 @@
|
||||
local waf_root = "{$WAF_ROOT}"
|
||||
local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
|
||||
local waf_sopath = waf_root.."/waf/conf/?.so;"
|
||||
|
||||
if not package.path:find(waf_cpath) then
|
||||
package.path = waf_cpath .. package.path
|
||||
end
|
||||
-- local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
|
||||
-- local waf_sopath = waf_root.."/waf/conf/?.so;"
|
||||
-- if not package.path:find(waf_cpath) then
|
||||
-- package.path = waf_cpath .. package.path
|
||||
-- end
|
||||
|
||||
if not package.cpath:find(waf_sopath) then
|
||||
package.cpath = waf_sopath .. package.cpath
|
||||
end
|
||||
-- if not package.cpath:find(waf_sopath) then
|
||||
-- package.cpath = waf_sopath .. package.cpath
|
||||
-- end
|
||||
|
||||
local json = require "cjson"
|
||||
|
||||
local __C = require "common"
|
||||
local C = __C:getInstance()
|
||||
local __WAF_C = require "waf_common"
|
||||
local WAF_C = __WAF_C:getInstance()
|
||||
|
||||
local function timer_stats_total_log(premature)
|
||||
C:timer_stats_total()
|
||||
local waf_config = require "waf_config"
|
||||
local waf_site_config = require "waf_site"
|
||||
WAF_C:setConfData(waf_config, waf_site_config)
|
||||
WAF_C:setDebug(true)
|
||||
|
||||
-- C:D("init worker"..tostring(ngx.worker.id()))
|
||||
|
||||
local function waf_timer_stats_total_log(premature)
|
||||
WAF_C:timer_stats_total()
|
||||
end
|
||||
|
||||
local waf_clean_expire_data = function(premature)
|
||||
WAF_C:clean_log()
|
||||
end
|
||||
|
||||
ngx.shared.waf_limit:set("cpu_usage", 0, 10)
|
||||
function timer_every_get_cpu(premature)
|
||||
local cpu_percent = C:read_file_body(waf_root.."/cpu.info")
|
||||
if cpu_percent then
|
||||
ngx.shared.waf_limit:set("cpu_usage", tonumber(cpu_percent), 10)
|
||||
function waf_timer_every_get_cpu(premature)
|
||||
if WAF_C:file_exists('/proc/stat') then
|
||||
local lua_cpu_percent = WAF_C:get_cpu_percent()
|
||||
-- WAF_C:D("lua_cpu_percent:"..tostring(lua_cpu_percent))
|
||||
ngx.shared.waf_limit:set("cpu_usage", math.floor(lua_cpu_percent), 10)
|
||||
else
|
||||
ngx.shared.waf_limit:set("cpu_usage", 0, 10)
|
||||
local cpu_percent = WAF_C:read_file_body(waf_root.."/cpu.info")
|
||||
-- WAF_C:D("cpu_usage:"..tostring(cpu_percent ))
|
||||
if cpu_percent then
|
||||
ngx.shared.waf_limit:set("cpu_usage", tonumber(cpu_percent), 10)
|
||||
else
|
||||
ngx.shared.waf_limit:set("cpu_usage", 0, 10)
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
if 0 == ngx.worker.id() then
|
||||
ngx.timer.every(5, timer_every_get_cpu)
|
||||
if ngx.worker.id() == 0 then
|
||||
|
||||
ngx.timer.every(6, waf_timer_every_get_cpu)
|
||||
-- 异步执行
|
||||
ngx.timer.every(3, timer_stats_total_log)
|
||||
ngx.timer.every(3, waf_timer_stats_total_log)
|
||||
ngx.timer.every(10, waf_clean_expire_data)
|
||||
|
||||
WAF_C:cron()
|
||||
end
|
||||
@@ -17,7 +17,9 @@ local mt = { __index = _M }
|
||||
local json = require "cjson"
|
||||
local sqlite3 = require "lsqlite3"
|
||||
|
||||
local ngx_re = require "ngx.re"
|
||||
local ngx_match = ngx.re.find
|
||||
|
||||
local debug_mode = false
|
||||
|
||||
local cpath = waf_root.."/waf/"
|
||||
@@ -41,42 +43,25 @@ function _M.new(self)
|
||||
end
|
||||
|
||||
|
||||
function _M.getInstance(self)
|
||||
if rawget(self, "instance") == nil then
|
||||
rawset(self, "instance", self:new())
|
||||
-- function _M.getInstance(self)
|
||||
-- if rawget(self, "instance") == nil then
|
||||
-- rawset(self, "instance", self.new())
|
||||
-- end
|
||||
-- assert(self.instance ~= nil)
|
||||
-- return self.instance
|
||||
-- end
|
||||
|
||||
if 0 == ngx.worker.id() then
|
||||
self:cron()
|
||||
end
|
||||
function _M.getInstance(self)
|
||||
if self.instance == nil then
|
||||
self.instance = self:new()
|
||||
end
|
||||
assert(self.instance ~= nil)
|
||||
return self.instance
|
||||
end
|
||||
|
||||
function _M.initDB(self)
|
||||
local path = log_dir .. "/waf.db"
|
||||
db, err = sqlite3.open(path)
|
||||
|
||||
if err then
|
||||
self:D("initDB err:"..tostring(err))
|
||||
return nil
|
||||
end
|
||||
|
||||
db:exec([[PRAGMA synchronous = 0]])
|
||||
db:exec([[PRAGMA cache_size = 8000]])
|
||||
db:exec([[PRAGMA page_size = 32768]])
|
||||
db:exec([[PRAGMA journal_mode = wal]])
|
||||
db:exec([[PRAGMA journal_size_limit = 1073741824]])
|
||||
return db
|
||||
end
|
||||
|
||||
-- 后台任务
|
||||
function _M.cron(self)
|
||||
local timer_every_get_data = function(premature)
|
||||
self:clean_log()
|
||||
end
|
||||
ngx.timer.every(10, timer_every_get_data)
|
||||
|
||||
|
||||
local timer_every_import_data = function(premature)
|
||||
|
||||
local llen, _ = ngx.shared.waf_limit:llen('waf_limit_logs')
|
||||
@@ -91,7 +76,6 @@ function _M.cron(self)
|
||||
local stmt2 = db:prepare[[INSERT INTO logs(time, ip, domain, server_name, method, status_code, uri, user_agent, rule_name, reason)
|
||||
VALUES(:time, :ip, :domain, :server_name, :method, :status_code, :uri, :user_agent, :rule_name, :reason)]]
|
||||
|
||||
|
||||
if not stmt2 then
|
||||
self:D("waf timer db:prepare fail!:"..tostring(stmt2))
|
||||
return false
|
||||
@@ -136,6 +120,22 @@ function _M.cron(self)
|
||||
ngx.timer.every(0.5, timer_every_import_data)
|
||||
end
|
||||
|
||||
function _M.initDB(self)
|
||||
local path = log_dir .. "/waf.db"
|
||||
db, err = sqlite3.open(path)
|
||||
|
||||
if err then
|
||||
self:D("initDB err:"..tostring(err))
|
||||
return nil
|
||||
end
|
||||
|
||||
db:exec([[PRAGMA synchronous = 0]])
|
||||
db:exec([[PRAGMA cache_size = 8000]])
|
||||
db:exec([[PRAGMA page_size = 32768]])
|
||||
db:exec([[PRAGMA journal_mode = wal]])
|
||||
db:exec([[PRAGMA journal_size_limit = 1073741824]])
|
||||
return db
|
||||
end
|
||||
|
||||
function _M.clean_log(self)
|
||||
local db = self:initDB()
|
||||
@@ -392,6 +392,12 @@ function _M.read_file(self, name)
|
||||
return data
|
||||
end
|
||||
|
||||
function _M.file_exists(self,path)
|
||||
local file = io.open(path, "rb")
|
||||
if file then file:close() end
|
||||
return file ~= nil
|
||||
end
|
||||
|
||||
|
||||
function _M.select_rule(self, rules)
|
||||
if not rules then return {} end
|
||||
@@ -761,6 +767,34 @@ function _M.is_key(self, arr, key)
|
||||
return false
|
||||
end
|
||||
|
||||
function _M.get_cpu_stat(self)
|
||||
local cpu_total = 0
|
||||
local fp = io.open('/proc/stat','r')
|
||||
local cpu_line = fp:read()
|
||||
fp:close()
|
||||
|
||||
local list = ngx_re.split(cpu_line," ")
|
||||
table.remove(list,1)
|
||||
table.remove(list,1)
|
||||
|
||||
local idie = list[4]
|
||||
for i,v in pairs(list)
|
||||
do
|
||||
cpu_total = cpu_total + v
|
||||
end
|
||||
|
||||
local use_percent = tonumber(100-(idie/cpu_total)*100)
|
||||
return cpu_total,idie,use_percent
|
||||
end
|
||||
|
||||
function _M.get_cpu_percent(self)
|
||||
local cpu_total,idie,use_percent = self:get_cpu_stat()
|
||||
ngx.sleep(2)
|
||||
local cpu_total2,idie2,use_percent2 = self:get_cpu_stat()
|
||||
local cpu_usage_percent = tonumber(100-(((idie2-idie)/(cpu_total2-cpu_total))*100))
|
||||
return cpu_usage_percent
|
||||
end
|
||||
|
||||
|
||||
function _M.return_post_data(self)
|
||||
if method ~= "POST" then return false end
|
||||
@@ -1 +1 @@
|
||||
[[[127, 0, 0, 1], [127, 0, 0, 255]]]
|
||||
[[[127,0,0,1], [127, 0, 0, 255]]]
|
||||
@@ -3,8 +3,11 @@ lua_package_cpath "{$SERVER_PATH}/web_conf/nginx/lua/?.so;{$SERVER_PATH}/openres
|
||||
|
||||
lua_code_cache on;
|
||||
|
||||
#waf
|
||||
#init_by_lua_file
|
||||
init_by_lua_file {$SERVER_PATH}/web_conf/nginx/lua/empty.lua;
|
||||
|
||||
#init_worker_by_lua
|
||||
init_worker_by_lua_file {$SERVER_PATH}/web_conf/nginx/lua/empty.lua;
|
||||
|
||||
#waf && webstats need;
|
||||
#access_by_lua_file
|
||||
access_by_lua_file {$SERVER_PATH}/web_conf/nginx/lua/empty.lua;
|
||||
@@ -149,16 +149,17 @@ def confReplace():
|
||||
mw.execShell('mkdir -p ' + lua_conf_dir)
|
||||
|
||||
lua_conf = lua_conf_dir + '/lua.conf'
|
||||
if not os.path.exists(lua_conf):
|
||||
lua_conf_tpl = getPluginDir() + '/conf/lua.conf'
|
||||
lua_content = mw.readFile(lua_conf_tpl)
|
||||
lua_content = lua_content.replace('{$SERVER_PATH}', service_path)
|
||||
mw.writeFile(lua_conf, lua_content)
|
||||
lua_conf_tpl = getPluginDir() + '/conf/lua.conf'
|
||||
lua_content = mw.readFile(lua_conf_tpl)
|
||||
lua_content = lua_content.replace('{$SERVER_PATH}', service_path)
|
||||
mw.writeFile(lua_conf, lua_content)
|
||||
|
||||
empty_lua = lua_conf_dir + '/empty.lua'
|
||||
if not os.path.exists(empty_lua):
|
||||
mw.writeFile(empty_lua, '')
|
||||
|
||||
mw.opLuaMakeAll()
|
||||
|
||||
# 静态配置
|
||||
php_conf = mw.getServerDir() + '/web_conf/php/conf'
|
||||
if not os.path.exists(php_conf):
|
||||
@@ -203,8 +204,8 @@ def initDreplace():
|
||||
mw.writeFile(file_bin, content)
|
||||
mw.execShell('chmod +x ' + file_bin)
|
||||
|
||||
# config replace
|
||||
confReplace()
|
||||
# config replace
|
||||
confReplace()
|
||||
|
||||
# systemd
|
||||
# /usr/lib/systemd/system
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
|
||||
export PATH
|
||||
|
||||
# cd /www/server/mdserver-web/plugins/openresty && bash install.sh install 1.21.4.1
|
||||
|
||||
curPath=`pwd`
|
||||
rootPath=$(dirname "$curPath")
|
||||
rootPath=$(dirname "$rootPath")
|
||||
|
||||
@@ -83,6 +83,7 @@ if [ "${action}" == "install" ] && [ -d ${serverPath}/php-apt/${type} ];then
|
||||
|
||||
# 安装通用扩展
|
||||
echo "install PHP-APT[${type}] extend start"
|
||||
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install curl
|
||||
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install gd
|
||||
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install iconv
|
||||
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install exif
|
||||
|
||||
@@ -233,6 +233,19 @@
|
||||
"shell": "xml.sh",
|
||||
"check": "xml"
|
||||
},
|
||||
{
|
||||
"name": "curl",
|
||||
"versions": [
|
||||
"74",
|
||||
"80",
|
||||
"81",
|
||||
"82"
|
||||
],
|
||||
"type": "通用扩展",
|
||||
"msg": "通用CURL库!",
|
||||
"shell": "curl.sh",
|
||||
"check": "curl"
|
||||
},
|
||||
{
|
||||
"name": "gd",
|
||||
"versions": [
|
||||
|
||||
@@ -16,7 +16,7 @@ function version_lt() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)"
|
||||
function version_ge() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)" == "$1"; }
|
||||
|
||||
|
||||
version=8.0.25
|
||||
version=8.0.27
|
||||
PHP_VER=80
|
||||
Install_php()
|
||||
{
|
||||
|
||||
@@ -16,7 +16,7 @@ function version_lt() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)"
|
||||
function version_ge() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)" == "$1"; }
|
||||
|
||||
|
||||
version=8.1.12
|
||||
version=8.1.15
|
||||
PHP_VER=81
|
||||
Install_php()
|
||||
{
|
||||
|
||||
@@ -16,7 +16,7 @@ function version_lt() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)"
|
||||
function version_ge() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)" == "$1"; }
|
||||
|
||||
|
||||
version=8.2.0
|
||||
version=8.2.2
|
||||
PHP_VER=82
|
||||
Install_php()
|
||||
{
|
||||
|
||||
@@ -54,13 +54,16 @@ def getArgs():
|
||||
|
||||
if args_len == 1:
|
||||
t = args[0].strip('{').strip('}')
|
||||
t = t.split(':')
|
||||
if t.strip() == '':
|
||||
tmp = []
|
||||
else:
|
||||
t = t.split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
tmp[t[0]] = t[1]
|
||||
elif args_len > 1:
|
||||
for i in range(len(args)):
|
||||
t = args[i].split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
|
||||
return tmp
|
||||
|
||||
|
||||
|
||||
@@ -34,13 +34,16 @@ def getArgs():
|
||||
|
||||
if args_len == 1:
|
||||
t = args[0].strip('{').strip('}')
|
||||
t = t.split(':')
|
||||
if t.strip() == '':
|
||||
tmp = []
|
||||
else:
|
||||
t = t.split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
tmp[t[0]] = t[1]
|
||||
elif args_len > 1:
|
||||
for i in range(len(args)):
|
||||
t = args[i].split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
|
||||
return tmp
|
||||
|
||||
|
||||
|
||||
@@ -43,13 +43,16 @@ class App():
|
||||
|
||||
if args_len == 1:
|
||||
t = args[0].strip('{').strip('}')
|
||||
t = t.split(':')
|
||||
if t.strip() == '':
|
||||
tmp = []
|
||||
else:
|
||||
t = t.split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
tmp[t[0]] = t[1]
|
||||
elif args_len > 1:
|
||||
for i in range(len(args)):
|
||||
t = args[i].split(':')
|
||||
tmp[t[0]] = t[1]
|
||||
|
||||
return tmp
|
||||
|
||||
def checkArgs(self, data, ck=[]):
|
||||
@@ -110,7 +113,7 @@ class App():
|
||||
|
||||
def getSshInfo(self, file):
|
||||
rdata = mw.readFile(file)
|
||||
destr = mw.deCrypt('mdserver-web', rdata)
|
||||
destr = mw.enDoubleCrypt('mdserver-web', rdata)
|
||||
return json.loads(destr)
|
||||
|
||||
def get_server_by_host(self):
|
||||
@@ -199,7 +202,7 @@ class App():
|
||||
if not os.path.exists(dst_host_dir):
|
||||
os.makedirs(dst_host_dir)
|
||||
|
||||
enstr = mw.enCrypt('mdserver-web', json.dumps(info))
|
||||
enstr = mw.enDoubleCrypt('mdserver-web', json.dumps(info))
|
||||
mw.writeFile(dst_host_dir + '/info.json', enstr)
|
||||
return mw.returnJson(True, '添加成功!')
|
||||
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
"name": "webstats",
|
||||
"title": "网站统计",
|
||||
"shell": "install.sh",
|
||||
"versions":["0.2.3"],
|
||||
"versions":["0.2.4"],
|
||||
"tip": "soft",
|
||||
"install_pre_inspection":true,
|
||||
"checks": "server/webstats",
|
||||
|
||||
@@ -39,6 +39,7 @@ Install_App()
|
||||
echo '正在安装脚本文件...' > $install_tmp
|
||||
mkdir -p $serverPath/source/webstats
|
||||
mkdir -p $serverPath/webstats
|
||||
echo "${VERSION}" > $serverPath/webstats/version.pl
|
||||
|
||||
# 下载源码安装包
|
||||
# curl -O $serverPath/source/webstats/lua-5.1.5.tar.gz https://www.lua.org/ftp/lua-5.1.5.tar.gz
|
||||
@@ -110,7 +111,7 @@ Install_App()
|
||||
cp -rf $serverPath/source/webstats/GeoLite2-City.mmdb $serverPath/webstats/GeoLite2-City.mmdb
|
||||
fi
|
||||
|
||||
echo "${VERSION}" > $serverPath/webstats/version.pl
|
||||
|
||||
echo '安装完成' > $install_tmp
|
||||
|
||||
cd $rootPath && python3 ${rootPath}/plugins/webstats/index.py start
|
||||
|
||||
@@ -36,20 +36,26 @@ function _M.new(self)
|
||||
params = nil,
|
||||
site_config = nil,
|
||||
config = nil,
|
||||
|
||||
}
|
||||
-- self.dbs = {}
|
||||
return setmetatable(self, mt)
|
||||
end
|
||||
|
||||
|
||||
function _M.getInstance(self)
|
||||
if rawget(self, "instance") == nil then
|
||||
rawset(self, "instance", self.new())
|
||||
-- function _M.getInstance(self)
|
||||
-- if rawget(self, "instance") == nil then
|
||||
-- rawset(self, "instance", self.new())
|
||||
-- self.cron()
|
||||
-- end
|
||||
-- assert(self.instance ~= nil)
|
||||
-- return self.instance
|
||||
-- end
|
||||
|
||||
-- if 0 == ngx.worker.id() then
|
||||
|
||||
function _M.getInstance(self)
|
||||
if self.instance == nil then
|
||||
self.instance = self:new()
|
||||
self:cron()
|
||||
-- end
|
||||
end
|
||||
assert(self.instance ~= nil)
|
||||
return self.instance
|
||||
@@ -229,16 +235,46 @@ function _M.get_http_origin(self)
|
||||
return json.encode(headers)
|
||||
end
|
||||
|
||||
function _M.cronPre(self)
|
||||
local time_key = self:get_store_key()
|
||||
local time_key_next = self:get_store_key_with_time(ngx.time()+3600)
|
||||
|
||||
for site_k, site_v in ipairs(sites) do
|
||||
local input_sn = site_v["name"]
|
||||
|
||||
local db = self:initDB(input_sn)
|
||||
|
||||
local wc_stat = {
|
||||
'request_stat',
|
||||
'client_stat',
|
||||
'spider_stat'
|
||||
}
|
||||
|
||||
for _,ws_v in pairs(wc_stat) do
|
||||
self:_update_stat_pre(db, ws_v, time_key)
|
||||
self:_update_stat_pre(db, ws_v, time_key_next)
|
||||
end
|
||||
|
||||
if db and db:isopen() then
|
||||
db:execute([[COMMIT]])
|
||||
db:close()
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
-- 后台任务
|
||||
function _M.cron(self)
|
||||
local timer_every_get_data = function (premature)
|
||||
|
||||
local timer_every_get_data = function (premature)
|
||||
|
||||
local llen, _ = ngx.shared.mw_total:llen(total_key)
|
||||
-- self:D("llen:"..tostring(llen))
|
||||
-- self:D("PID:"..tostring(ngx.worker.id())..",llen:"..tostring(llen))
|
||||
if llen == 0 then
|
||||
return true
|
||||
end
|
||||
|
||||
self:cronPre()
|
||||
|
||||
ngx.update_time()
|
||||
local begin = ngx.now()
|
||||
|
||||
@@ -249,10 +285,10 @@ function _M.cron(self)
|
||||
local url_stats = {}
|
||||
|
||||
local time_key = self:get_store_key()
|
||||
local time_key_next = self:get_store_key_with_time(ngx.time()+3600)
|
||||
|
||||
|
||||
for site_k, site_v in ipairs(sites) do
|
||||
local input_sn = site_v["name"]
|
||||
-- self:D("input_sn:"..input_sn)
|
||||
-- 迁移合并时不执行
|
||||
if self:is_migrating(input_sn) then
|
||||
return true
|
||||
@@ -276,18 +312,6 @@ function _M.cron(self)
|
||||
tmp_stmt["web_logs"] = stmt
|
||||
stmts[input_sn] = tmp_stmt
|
||||
|
||||
local wc_stat = {
|
||||
'request_stat',
|
||||
'client_stat',
|
||||
'spider_stat'
|
||||
}
|
||||
|
||||
for _,ws_v in pairs(wc_stat) do
|
||||
self:_update_stat_pre(db, ws_v, time_key)
|
||||
self:_update_stat_pre(db, ws_v, time_key_next)
|
||||
end
|
||||
|
||||
|
||||
db:exec([[BEGIN TRANSACTION]])
|
||||
end
|
||||
end
|
||||
@@ -307,7 +331,10 @@ function _M.cron(self)
|
||||
end
|
||||
|
||||
local info = json.decode(data)
|
||||
|
||||
-- self:D("info:"..json.encode(info))
|
||||
local input_sn = info['server_name']
|
||||
-- self:D("insert data input_sn:"..input_sn)
|
||||
local db = dbs[input_sn]
|
||||
local stat_fields_is = stat_fields[input_sn]
|
||||
if not db then
|
||||
@@ -458,10 +485,9 @@ function _M.cron(self)
|
||||
|
||||
self:unlock_working(cron_key)
|
||||
ngx.update_time()
|
||||
-- self:D("--【"..tostring(llen).."】, elapsed: " .. tostring(ngx.now() - begin))
|
||||
-- self:D("PID:"..tostring(ngx.worker.id()).."--【"..tostring(llen).."】, elapsed: " .. tostring(ngx.now() - begin))
|
||||
end
|
||||
|
||||
ngx.timer.every(1, timer_every_get_data)
|
||||
ngx.timer.every(0.5, timer_every_get_data)
|
||||
end
|
||||
|
||||
|
||||
@@ -488,7 +514,7 @@ function _M.store_logs_line(self, db, stmt, input_sn, info)
|
||||
local request_headers = logline["request_headers"]
|
||||
local excluded = logline["excluded"]
|
||||
|
||||
|
||||
-- self:D("json:"..json.encode(logline))
|
||||
local time_key = logline["time_key"]
|
||||
if not excluded then
|
||||
|
||||
|
||||
@@ -8,7 +8,7 @@ log_by_lua_block {
|
||||
package.path = cpath .. "?.lua;" .. package.path
|
||||
end
|
||||
|
||||
local ver = '0.2.3'
|
||||
local ver = '0.2.4'
|
||||
local debug_mode = true
|
||||
|
||||
local __C = require "webstats_common"
|
||||
@@ -44,7 +44,7 @@ log_by_lua_block {
|
||||
local sites = require "webstats_sites"
|
||||
|
||||
-- string.gsub(C:get_sn(ngx.var.server_name),'_','.')
|
||||
local server_name = ngx.var.server_name
|
||||
local server_name = C:get_sn(ngx.var.server_name)
|
||||
|
||||
|
||||
C:setConfData(config, sites)
|
||||
@@ -210,7 +210,7 @@ log_by_lua_block {
|
||||
-- local request_time = ngx.var.request_time
|
||||
local request_time = C:get_request_time()
|
||||
local client_port = ngx.var.remote_port
|
||||
local real_server_name = server_name
|
||||
local real_server_name = ngx.var.server_name
|
||||
local uri = ngx.var.uri
|
||||
local status_code = ngx.status
|
||||
local protocol = ngx.var.server_protocol
|
||||
@@ -439,7 +439,7 @@ log_by_lua_block {
|
||||
}
|
||||
|
||||
local push_data = json.encode(data)
|
||||
|
||||
-- C:D(json.encode(push_data))
|
||||
local key = C:getTotalKey()
|
||||
ngx.shared.mw_total:rpush(key, push_data)
|
||||
end
|
||||
@@ -630,7 +630,7 @@ log_by_lua_block {
|
||||
end
|
||||
|
||||
local function run_app()
|
||||
-- D("------------ debug start ------------")
|
||||
-- C:D("------------ debug start ------------")
|
||||
init_var()
|
||||
|
||||
load_global_exclude_ip()
|
||||
@@ -641,7 +641,7 @@ log_by_lua_block {
|
||||
|
||||
-- cache_logs_old(server_name)
|
||||
-- store_logs(server_name)
|
||||
-- D("------------ debug end -------------")
|
||||
-- C:D("------------ debug end -------------")
|
||||
end
|
||||
|
||||
|
||||
|
||||
+4
-1
@@ -386,7 +386,10 @@ def get_admin_safe():
|
||||
|
||||
def admin_safe_path(path, req, data, pageFile):
|
||||
if path != req and not isLogined():
|
||||
return render_template('path.html')
|
||||
if data['status_code'] == '0':
|
||||
return render_template('path.html')
|
||||
else:
|
||||
return Response(status=int(data['status_code']))
|
||||
|
||||
if not isLogined():
|
||||
return render_template('login.html', data=data)
|
||||
|
||||
@@ -550,6 +550,61 @@ function setTempAccessReq(page){
|
||||
},'json');
|
||||
}
|
||||
|
||||
function setStatusCode(o){
|
||||
var code = $(o).data('code');
|
||||
layer.open({
|
||||
type: 1,
|
||||
area: ['420px', '220px'],
|
||||
title: "设置未认证时的响应状态",
|
||||
closeBtn: 1,
|
||||
shift: 5,
|
||||
btn:['提交','关闭'],
|
||||
shadeClose: false,
|
||||
content: '<div class="bt-form bt-form pd20">\
|
||||
<div class="line">\
|
||||
<span class="tname">相应状态</span>\
|
||||
<div class="info-r">\
|
||||
<select class="bt-input-text mr5" name="status_code" style="width: 250px;"></select>\
|
||||
</div>\
|
||||
</div>\
|
||||
<ul class="help-info-text c7"><li style="color: red;">用于未登录且未正确输入安全入口时的响应,用于隐藏面板特征</li></ul>\
|
||||
</div>',
|
||||
success:function(){
|
||||
var msg_list = [
|
||||
{'code':'0','msg':'默认-安全入口错误提示'},
|
||||
{'code':'403','msg':'403-拒绝访问'},
|
||||
{'code':'404','msg':'404-页面不存在'},
|
||||
{'code':'416','msg':'416-无效的请求'},
|
||||
{'code':'408','msg':'408-客户端超时'},
|
||||
{'code':'400','msg':'400-客户端请求错误'},
|
||||
{'code':'401','msg':'401-未授权访问'},
|
||||
];
|
||||
|
||||
var tbody = '';
|
||||
for(i in msg_list){
|
||||
if (msg_list[i]['code'] == code){
|
||||
tbody += '<option value="'+msg_list[i]['code']+'" selected>'+msg_list[i]['msg']+'</option>';
|
||||
} else{
|
||||
tbody += '<option value="'+msg_list[i]['code']+'">'+msg_list[i]['msg']+'</option>';
|
||||
}
|
||||
|
||||
}
|
||||
$('select[name="status_code"]').append(tbody);
|
||||
},
|
||||
yes:function(index){
|
||||
var loadT = layer.msg("正在设置未认证时的响应状态", { icon: 16, time: 0, shade: [0.3, '#000'] });
|
||||
var status_code = $('select[name="status_code"]').val();
|
||||
$.post('/config/set_status_code', { status_code: status_code }, function (rdata) {
|
||||
showMsg(rdata.msg, function(){
|
||||
layer.close(index);
|
||||
layer.close(loadT);
|
||||
location.reload();
|
||||
},{ icon: rdata.status ? 1 : 2 }, 2000);
|
||||
},'json');
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
function setTempAccess(){
|
||||
layer.open({
|
||||
area: ['700px', '250px'],
|
||||
|
||||
@@ -257,7 +257,7 @@ function planAdd(){
|
||||
$("#set-Config input[name='sType']").val(sType);
|
||||
$("#set-Config textarea[name='sBody']").val(decodeURIComponent(sBody));
|
||||
|
||||
if(sType == 'site' || sType == 'database'){
|
||||
if(sType == 'site' || sType == 'database' || sType == 'path'){
|
||||
var backupTo = $(".planBackupTo").find("b").attr("val");
|
||||
$("#backupTo").val(backupTo);
|
||||
}
|
||||
@@ -293,10 +293,17 @@ function planAdd(){
|
||||
var where1 = $("#ptime input[name='where1']").val();
|
||||
$("#set-Config input[name='where1']").val(where1);
|
||||
}
|
||||
|
||||
if (type == 'month'){
|
||||
var where1 = $("#ptime input[name='where1']").val();
|
||||
$("#set-Config input[name='where1']").val(where1);
|
||||
}
|
||||
|
||||
|
||||
$("#set-Config input[name='sName']").val(sName);
|
||||
layer.msg('正在添加,请稍候...!',{icon:16,time:0,shade: [0.3, '#000']});
|
||||
var data = $("#set-Config").serialize() + '&sBody='+sBody + '&urladdress=' + urladdress;
|
||||
// console.log(data);
|
||||
$.post('/crontab/add',data,function(rdata){
|
||||
if(!rdata.status) {
|
||||
layer.msg(rdata.msg,{icon:2, time:2000});
|
||||
|
||||
+27
-21
@@ -2188,39 +2188,45 @@ function pluginRollingLogs(_name, version, func, _args, line){
|
||||
|
||||
var reqTimer = null;
|
||||
|
||||
function requestLogs(fileName){
|
||||
$.post('/files/get_last_body', 'path=' + fileName+'&line='+file_line, function(rdata) {
|
||||
if (!rdata.status){
|
||||
return;
|
||||
}
|
||||
|
||||
if(rdata.data == '') {
|
||||
rdata.data = '当前没有日志!';
|
||||
}
|
||||
var ebody = '<textarea readonly="readonly" style="margin: 0px;width: 100%;height: 360px;background-color: #333;color:#fff; padding:0 5px" id="roll_info_log">'+rdata.data+'</textarea>';
|
||||
$("#plugins_rolling_logs").html(ebody);
|
||||
var ob = document.getElementById('roll_info_log');
|
||||
ob.scrollTop = ob.scrollHeight;
|
||||
},'json');
|
||||
}
|
||||
|
||||
|
||||
layer.open({
|
||||
type: 1,
|
||||
title: _name + '日志',
|
||||
area: '640px',
|
||||
end: function(){
|
||||
// console.log('end!!!');
|
||||
if (reqTimer){
|
||||
clearInterval(reqTimer);
|
||||
}
|
||||
},
|
||||
content:'<div class="change-default pd20" id="plugins_rolling_logs">\
|
||||
<textarea readonly="readonly" style="margin: 0px;width: 100%;height: 360px;background-color: #333;color:#fff; padding:0 5px" id="roll_info_log"></textarea>\
|
||||
</div>'
|
||||
</div>',
|
||||
success:function(){
|
||||
$.post('/plugins/run', {name:_name, func:func_name, version:version, args:_args},function (data) {
|
||||
var fileName = data.data;
|
||||
requestLogs(fileName);
|
||||
reqTimer = setInterval(function(){
|
||||
requestLogs(fileName);
|
||||
},1000);
|
||||
},'json');
|
||||
}
|
||||
});
|
||||
|
||||
$.post('/plugins/run', {name:_name, func:func_name, version:version,args:_args},function (data) {
|
||||
var fileName = data.data;
|
||||
reqTimer = setInterval(function(){
|
||||
$.post('/files/get_last_body', 'path=' + fileName+'&line='+file_line, function(rdata) {
|
||||
if (!rdata.status){
|
||||
return;
|
||||
}
|
||||
|
||||
if(rdata.data == '') {
|
||||
rdata.data = '当前没有日志!';
|
||||
}
|
||||
var ebody = '<textarea readonly="" style="margin: 0px;width: 100%;height: 360px;background-color: #333;color:#fff; padding:0 5px" id="roll_info_log">'+rdata.data+'</textarea>';
|
||||
$("#plugins_rolling_logs").html(ebody);
|
||||
var ob = document.getElementById('roll_info_log');
|
||||
ob.scrollTop = ob.scrollHeight;
|
||||
},'json');
|
||||
},1000);
|
||||
},'json');
|
||||
}
|
||||
|
||||
|
||||
|
||||
@@ -200,7 +200,7 @@ function webAddPage(type) {
|
||||
}
|
||||
|
||||
domainlist = domainlist.substring(0,domainlist.length-1);//子域名json
|
||||
domain ='{"domain":"'+domain[0]+'","domainlist":['+domainlist+'],"count":'+domain.length+'}';//拼接joson
|
||||
domain ='{"domain":"'+domain[0]+'","domainlist":['+domainlist+'],"count":'+domain.length+'}';//拼接json
|
||||
var loadT = layer.msg(lan.public.the_get,{icon:16,time:0,shade: [0.3, "#000"]})
|
||||
var data = $("#addweb").serialize()+"&port="+webport+"&webinfo="+domain;
|
||||
|
||||
|
||||
+129
-132
@@ -1,155 +1,152 @@
|
||||
{% extends "layout.html" %}
|
||||
{% block content %}
|
||||
<div class="main-content">
|
||||
<div class="container-fluid" style="padding-bottom:54px">
|
||||
<div class="pos-box bgw mtb15">
|
||||
<div class="position f14 c9 pull-left">
|
||||
<a class="plr10 c4" href="/">首页</a>/<span class="plr10 c4">面板设置</span>
|
||||
<div class="container-fluid" style="padding-bottom:54px">
|
||||
<div class="pos-box bgw mtb15">
|
||||
<div class="position f14 c9 pull-left"><a class="plr10 c4" href="/">首页</a>/<span class="plr10 c4">面板设置</span></div>
|
||||
</div>
|
||||
<div class="clearfix bgw mtb15 pd15">
|
||||
<div class="safe-port pull-left">
|
||||
<div class="ss-text pull-left mr50">
|
||||
<em>关闭面板</em>
|
||||
<div class="ssh-item">
|
||||
<input class="btswitch btswitch-ios" id="closePl" type="checkbox">
|
||||
<label class="btswitch-btn" for="closePl" onclick="closePanel()"></label>
|
||||
</div>
|
||||
</div>
|
||||
<div class="ss-text pull-left mr50">
|
||||
<em>开发模式</em>
|
||||
<div class="ssh-item">
|
||||
<input class="btswitch btswitch-ios" id="debugMode" type="checkbox" {{data['debug']}}>
|
||||
<label class="btswitch-btn" for="debugMode" onclick="debugMode()"></label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="ss-text pull-left mr50">
|
||||
<em title="开启后允许使用ipv6访问面板">监听IPv6</em>
|
||||
<div class='ssh-item'>
|
||||
<input class='btswitch btswitch-ios' id='panelIPv6' type='checkbox' {{data['ipv6']}}>
|
||||
<label class='btswitch-btn' for='panelIPv6' onclick="setIPv6()"></label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="clearfix bgw mtb15 pd15">
|
||||
<div class="safe-port pull-left">
|
||||
|
||||
<div class="ss-text pull-left mr50">
|
||||
<em>关闭面板</em>
|
||||
<div class="ssh-item">
|
||||
<input class="btswitch btswitch-ios" id="closePl" type="checkbox">
|
||||
<label class="btswitch-btn" for="closePl" onclick="closePanel()"></label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="ss-text pull-left mr50">
|
||||
<em>开发模式</em>
|
||||
<div class="ssh-item">
|
||||
<input class="btswitch btswitch-ios" id="debugMode" type="checkbox" {{data['debug']}}>
|
||||
<label class="btswitch-btn" for="debugMode" onclick="debugMode()"></label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="ss-text pull-left mr50">
|
||||
<em title="开启后允许使用ipv6访问面板">监听IPv6</em>
|
||||
<div class='ssh-item'>
|
||||
<input class='btswitch btswitch-ios' id='panelIPv6' type='checkbox' {{data['ipv6']}}>
|
||||
<label class='btswitch-btn' for='panelIPv6' onclick="setIPv6()"></label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
<div class="setbox bgw mtb15">
|
||||
<div class="title c6 plr15"><h3 class="f16">设置</h3></div>
|
||||
<div class="info-title-tips" style="margin: 20px 30px 0px;">
|
||||
<p><span class="glyphicon glyphicon-alert" style="color: #f39c12; margin-right: 10px;"></span>为了提高安全,修改面板密码!</p>
|
||||
</div>
|
||||
<div class="setbox bgw mtb15">
|
||||
<div class="title c6 plr15">
|
||||
<h3 class="f16">设置</h3>
|
||||
</div>
|
||||
<div class="info-title-tips" style="margin: 20px 30px 0px;">
|
||||
<p><span class="glyphicon glyphicon-alert" style="color: #f39c12; margin-right: 10px;"></span>为了提高安全,修改面板密码!</p>
|
||||
</div>
|
||||
<div class="setting-con pd15">
|
||||
<form id="set_config">
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right">别名</span>
|
||||
<input id="webname" name="webname" class="inputtxt bt-input-text" type="text" value="{{data['title']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_webname" disabled>保存</button>
|
||||
<span class="set-info c7">面板名称</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="服务器IP">服务器IP</span>
|
||||
<input name="host_ip" class="inputtxt bt-input-text" type="text" value="{{data['ip']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_host_ip" disabled>保存</button>
|
||||
<span class="set-info c7">默认为外网IP,若您在本地虚拟机测试,请填写虚拟机内网IP!</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right">面板端口</span>
|
||||
<input id="banport" name="port" class="inputtxt bt-input-text" type="numner" value="{{data['port']}}" maxlength="5">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_port" disabled>保存</button>
|
||||
<span class="set-info c7">建议端口范围7200 - 65535</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right">安全入口</span>
|
||||
<input id="admin_path" name="admin_path" class="inputtxt bt-input-text disable" type="text" value="{{data['admin_path']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="modifyAuthPath()">设置</button>
|
||||
<span class="set-info c7">面板管理入口,设置后只能通过指定安全入口登录面板,如: /abc</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="默认建站目录">默认建站目录</span>
|
||||
<input name="sites_path" class="inputtxt bt-input-text" type="text" value="{{data['site_path']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_sites_path" disabled>保存</button>
|
||||
<span class="set-info c7">新创建的站点,默认将保存到该目录的下级目录!</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="默认建站目录">默认备份目录</span>
|
||||
<input name="backup_path" class="inputtxt bt-input-text" type="text" value="{{data['backup_path']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_backup_path" disabled>保存</button>
|
||||
<span class="set-info c7">网站和数据库的备份目录!</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="服务器时间">服务器时间</span>
|
||||
<input id="systemdate" name="systemdate" class="inputtxt bt-input-text disable" type="text" value="{{data['systemdate']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="syncDate()">同步</button>
|
||||
<span class="set-info c7">同步当前服务器时间</span>
|
||||
</p>
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="面板用户">面板用户</span>
|
||||
<input name="username_" class="inputtxt bt-input-text disable" type="text" value="{{data['username']}}" disabled>
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="setUserName()">设置</button>
|
||||
<span class="set-info c7">设置面板账号</span>
|
||||
</p>
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="面板密码">面板密码</span>
|
||||
<input name="password_" class="inputtxt bt-input-text disable" type="text" value="******" disabled>
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="setPassword()">设置</button>
|
||||
<span class="set-info c7">设置面板密码</span>
|
||||
</p>
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<div class="title c6 plr15">
|
||||
<h3 class="f16">安全</h3>
|
||||
</div>
|
||||
|
||||
<div class="setting-con pd15">
|
||||
|
||||
<div class="setting-con pd15">
|
||||
<form id="set_config">
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="绑定域名" style="float: left;">绑定域名</span>
|
||||
<input name="bind_domain" class="inputtxt bt-input-text" type="text" value="{{data['bind_domain']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_bind_domain" disabled>保存</button>
|
||||
<span class="set-info c7">为面板绑定一个访问域名,<b style="color: red;">注意:一旦绑定域名,只能通过域名访问面板</b></span>
|
||||
<span class="set-tit text-right">别名</span>
|
||||
<input id="webname" name="webname" class="inputtxt bt-input-text" type="text" value="{{data['title']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_webname" disabled>保存</button>
|
||||
<span class="set-info c7">面板名称</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="面板SSL" style="float: left;">面板SSL</span>
|
||||
<input id="cfg_ssl" name="bind_ssl" class="btswitch btswitch-ios" type="checkbox" {{data['ssl']}}>
|
||||
<label class="btswitch-btn ml5" for="cfg_ssl" style="float: left;margin-top:4px;"></label>
|
||||
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="getPanelSSL();">面板SSL配置</button>
|
||||
<span class="set-info c7">为面板设置https协议访问,提升面板访问<b style="color: red;">安全性</b></span>
|
||||
<span class="set-tit text-right" title="服务器IP">服务器IP</span>
|
||||
<input name="host_ip" class="inputtxt bt-input-text" type="text" value="{{data['ip']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_host_ip" disabled>保存</button>
|
||||
<span class="set-info c7">默认为外网IP,若您在本地虚拟机测试,请填写虚拟机内网IP!</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="BasicAuth认证" style="float: left;">BasicAuth认证</span>
|
||||
<input class="btswitch btswitch-ios" id="cfg_basic_auth" type="checkbox" {{data['basic_auth']}}/>
|
||||
<label class="btswitch-btn ml5" for="cfg_basic_auth" style="float: left;margin-top:4px;" onclick="setBasicAuth()"></label>
|
||||
<span class="set-info c7">为面板增加一道基于BasicAuth的认证服务,有效防止面板被扫描</span>
|
||||
<span class="set-tit text-right">面板端口</span>
|
||||
<input id="banport" name="port" class="inputtxt bt-input-text" type="numner" value="{{data['port']}}" maxlength="5">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_port" disabled>保存</button>
|
||||
<span class="set-info c7">建议端口范围7200 - 65535</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="API接口" style="float: left;">API接口</span>
|
||||
<input class="btswitch btswitch-ios" id="cfg_panel_api" type="checkbox" {{data['api_token']}}/>
|
||||
<label class="btswitch-btn ml5" for="cfg_panel_api" style="float: left;margin-top:4px;" onclick="setPanelApi()"></label>
|
||||
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="showPanelApi();">API接口配置</button>
|
||||
<span class="set-info c7">提供面板API接口访问的支持</span>
|
||||
<span class="set-tit text-right">安全入口</span>
|
||||
<input id="admin_path" name="admin_path" class="inputtxt bt-input-text disable" type="text" value="{{data['admin_path']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="modifyAuthPath()">设置</button>
|
||||
<span class="set-info c7">面板管理入口,设置后只能通过指定安全入口登录面板,如: /abc</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="临时访问授权">临时访问授权</span>
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="setTempAccess()">临时访问授权管理</button>
|
||||
<span class="set-info c7">为非管理员临时提供面板访问权限</span>
|
||||
<span class="set-tit text-right" title="默认建站目录">默认建站目录</span>
|
||||
<input name="sites_path" class="inputtxt bt-input-text" type="text" value="{{data['site_path']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_sites_path" disabled>保存</button>
|
||||
<span class="set-info c7">新创建的站点,默认将保存到该目录的下级目录!</span>
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="默认建站目录">默认备份目录</span>
|
||||
<input name="backup_path" class="inputtxt bt-input-text" type="text" value="{{data['backup_path']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_backup_path" disabled>保存</button>
|
||||
<span class="set-info c7">网站和数据库的备份目录!</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="服务器时间">服务器时间</span>
|
||||
<input id="systemdate" name="systemdate" class="inputtxt bt-input-text disable" type="text" value="{{data['systemdate']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="syncDate()">同步</button>
|
||||
<span class="set-info c7">同步当前服务器时间</span>
|
||||
</p>
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="面板用户">面板用户</span>
|
||||
<input name="username_" class="inputtxt bt-input-text disable" type="text" value="{{data['username']}}" disabled>
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="setUserName()">设置</button>
|
||||
<span class="set-info c7">设置面板账号</span>
|
||||
</p>
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="面板密码">面板密码</span>
|
||||
<input name="password_" class="inputtxt bt-input-text disable" type="text" value="******" disabled>
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="setPassword()">设置</button>
|
||||
<span class="set-info c7">设置面板密码</span>
|
||||
</p>
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<div class="title c6 plr15"><h3 class="f16">安全</h3></div>
|
||||
|
||||
<div class="setting-con pd15">
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="绑定域名" style="float: left;">绑定域名</span>
|
||||
<input name="bind_domain" class="inputtxt bt-input-text" type="text" value="{{data['bind_domain']}}">
|
||||
<button type="button" class="btn btn-success btn-sm ml5 btn_bind_domain" disabled>保存</button>
|
||||
<span class="set-info c7">为面板绑定一个访问域名,<b style="color: red;">注意:一旦绑定域名,只能通过域名访问面板</b></span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="面板SSL" style="float: left;">面板SSL</span>
|
||||
<input id="cfg_ssl" name="bind_ssl" class="btswitch btswitch-ios" type="checkbox" {{data['ssl']}}>
|
||||
<label class="btswitch-btn ml5" for="cfg_ssl" style="float: left;margin-top:4px;"></label>
|
||||
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="getPanelSSL();">面板SSL配置</button>
|
||||
<span class="set-info c7">为面板设置https协议访问,提升面板访问<b style="color: red;">安全性</b></span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="BasicAuth认证" style="float: left;">BasicAuth认证</span>
|
||||
<input class="btswitch btswitch-ios" id="cfg_basic_auth" type="checkbox" {{data['basic_auth']}}/>
|
||||
<label class="btswitch-btn ml5" for="cfg_basic_auth" style="float: left;margin-top:4px;" onclick="setBasicAuth()"></label>
|
||||
<span class="set-info c7">为面板增加一道基于BasicAuth的认证服务,有效防止面板被扫描</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="API接口" style="float: left;">API接口</span>
|
||||
<input class="btswitch btswitch-ios" id="cfg_panel_api" type="checkbox" {{data['api_token']}}/>
|
||||
<label class="btswitch-btn ml5" for="cfg_panel_api" style="float: left;margin-top:4px;" onclick="setPanelApi()"></label>
|
||||
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="showPanelApi();">API接口配置</button>
|
||||
<span class="set-info c7">提供面板API接口访问的支持</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="未认证响应状态">未认证响应状态</span>
|
||||
<input name="status_code" class="inputtxt bt-input-text disable" type="text" value="{{data['status_code_msg']}}" disabled>
|
||||
<button type="button" class="btn btn-success btn-sm ml5" data-code="{{data['status_code']}}" onclick="setStatusCode(this)">设置</button>
|
||||
<span class="set-info c7">用于在未登录且未正确输入安全入口时的响应,可用于隐藏面板特征</span>
|
||||
</p>
|
||||
|
||||
<p class="mtb15">
|
||||
<span class="set-tit text-right" title="临时访问授权">临时访问授权</span>
|
||||
<button type="button" class="btn btn-success btn-sm ml5" onclick="setTempAccess()">临时访问授权管理</button>
|
||||
<span class="set-info c7">为非管理员临时提供面板访问权限</span>
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
</div>
|
||||
<div class="search pull-right">
|
||||
<form target="hid" onsubmit='getSList()'>
|
||||
<input type="text" id="SearchValue" class="ser-text pull-left" placeholder="search" />
|
||||
<input type="text" id="SearchValue" class="ser-text pull-left" placeholder="搜索" />
|
||||
<button type="button" class="ser-sub pull-left" onclick='getSList()'></button>
|
||||
</form>
|
||||
</div>
|
||||
@@ -27,7 +27,7 @@
|
||||
<table class="table table-hover" width="100%" cellspacing="0" cellpadding="0" border="0">
|
||||
<thead>
|
||||
<tr>
|
||||
<th width="165">软件名称</th>
|
||||
<th width="185">软件名称</th>
|
||||
<th>说明</th>
|
||||
<th width="40">位置</th>
|
||||
<th width="40">状态</th>
|
||||
|
||||
+12
-5
@@ -14,7 +14,7 @@
|
||||
|
||||
|
||||
PATH=/usr/local/bin:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
|
||||
# export LANG=en_US.UTF-8
|
||||
export LANG=en_US.UTF-8
|
||||
|
||||
mw_path={$SERVER_PATH}
|
||||
PATH=$PATH:$mw_path/bin
|
||||
@@ -38,7 +38,7 @@ mw_start_panel()
|
||||
sleep 0.5
|
||||
isStart=$(lsof -n -P -i:$port|grep LISTEN|grep -v grep|awk '{print $2}'|xargs)
|
||||
let n+=1
|
||||
if [ $n -gt 15 ];then
|
||||
if [ $n -gt 20 ];then
|
||||
break;
|
||||
fi
|
||||
done
|
||||
@@ -98,7 +98,7 @@ mw_stop_task()
|
||||
arr=($pids)
|
||||
for p in ${arr[@]}
|
||||
do
|
||||
kill -9 $p
|
||||
kill -9 $p > /dev/null 2>&1
|
||||
done
|
||||
echo -e "\033[32mdone\033[0m"
|
||||
}
|
||||
@@ -109,7 +109,7 @@ mw_stop_panel()
|
||||
arr=`ps aux|grep 'gunicorn -c setting.py app:app'|grep -v grep|awk '{print $2}'`
|
||||
for p in ${arr[@]}
|
||||
do
|
||||
kill -9 $p &>/dev/null
|
||||
kill -9 $p > /dev/null 2>&1
|
||||
done
|
||||
|
||||
pidfile=${mw_path}/logs/mw.pid
|
||||
@@ -313,11 +313,18 @@ case "$1" in
|
||||
auth_path=$(cat $mw_path/data/admin_path.pl)
|
||||
fi
|
||||
|
||||
if [ "$address" = "" ];then
|
||||
if [ "$address" == "" ];then
|
||||
v4=$(python3 $mw_path/tools.py getServerIp 4)
|
||||
v6=$(python3 $mw_path/tools.py getServerIp 6)
|
||||
|
||||
if [ "$v4" != "" ] && [ "$v6" != "" ]; then
|
||||
|
||||
if [ ! -f $mw_path/data/ipv6.pl ];then
|
||||
echo 'True' > $mw_path/data/ipv6.pl
|
||||
mw_stop
|
||||
mw_start
|
||||
fi
|
||||
|
||||
address="MW-Panel-Url-Ipv4: http://$v4:$port$auth_path \nMW-Panel-Url-Ipv6: http://[$v6]:$port$auth_path"
|
||||
elif [ "$v4" != "" ]; then
|
||||
address="MW-Panel-Url: http://$v4:$port$auth_path"
|
||||
|
||||
+21
-21
@@ -14,26 +14,25 @@ dnf install -y python-devel
|
||||
dnf install -y crontabs
|
||||
dnf install -y mysql-devel
|
||||
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
if [ -f /usr/sbin/iptables ];then
|
||||
# if [ -f /usr/sbin/iptables ];then
|
||||
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# service iptables save
|
||||
|
||||
iptables_status=`service iptables status | grep 'not running'`
|
||||
if [ "${iptables_status}" == '' ];then
|
||||
service iptables restart
|
||||
fi
|
||||
# iptables_status=`service iptables status | grep 'not running'`
|
||||
# if [ "${iptables_status}" == '' ];then
|
||||
# service iptables restart
|
||||
# fi
|
||||
|
||||
#安装时不开启
|
||||
service iptables stop
|
||||
fi
|
||||
# #安装时不开启
|
||||
# service iptables stop
|
||||
# fi
|
||||
|
||||
|
||||
if [ ! -f /usr/sbin/iptables ];then
|
||||
@@ -41,14 +40,15 @@ if [ ! -f /usr/sbin/iptables ];then
|
||||
systemctl enable firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
|
||||
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
|
||||
firewall-cmd --reload
|
||||
|
||||
+23
-22
@@ -21,42 +21,43 @@ yum install -y curl-devel libmcrypt libmcrypt-devel
|
||||
yum install -y mysql-devel
|
||||
yum install -y expect
|
||||
|
||||
if [ -f /usr/sbin/iptables ];then
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
# if [ -f /usr/sbin/iptables ];then
|
||||
|
||||
iptables_status=`service iptables status | grep 'not running'`
|
||||
if [ "${iptables_status}" == '' ];then
|
||||
service iptables restart
|
||||
fi
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# service iptables save
|
||||
|
||||
#安装时不开启
|
||||
service iptables stop
|
||||
fi
|
||||
# iptables_status=`service iptables status | grep 'not running'`
|
||||
# if [ "${iptables_status}" == '' ];then
|
||||
# service iptables restart
|
||||
# fi
|
||||
|
||||
# #安装时不开启
|
||||
# service iptables stop
|
||||
# fi
|
||||
|
||||
|
||||
if [ ! -f /usr/sbin/iptables ];then
|
||||
if [ ! -f /usr/sbin/firewalld ];then
|
||||
yum install firewalld -y
|
||||
systemctl enable firewalld
|
||||
#取消服务锁定
|
||||
systemctl unmask firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
|
||||
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
|
||||
firewall-cmd --reload
|
||||
|
||||
+23
-22
@@ -54,40 +54,41 @@ echo y | pacman -Syu icu
|
||||
|
||||
hwclock --systohc
|
||||
|
||||
if [ -f /usr/sbin/iptables ];then
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
# if [ -f /usr/sbin/iptables ];then
|
||||
|
||||
iptables_status=`service iptables status | grep 'not running'`
|
||||
if [ "${iptables_status}" == '' ];then
|
||||
service iptables restart
|
||||
fi
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# service iptables save
|
||||
|
||||
#安装时不开启
|
||||
service iptables stop
|
||||
fi
|
||||
# iptables_status=`service iptables status | grep 'not running'`
|
||||
# if [ "${iptables_status}" == '' ];then
|
||||
# service iptables restart
|
||||
# fi
|
||||
|
||||
# #安装时不开启
|
||||
# service iptables stop
|
||||
# fi
|
||||
|
||||
|
||||
if [ ! -f /usr/sbin/iptables ];then
|
||||
if [ ! -f /usr/sbin/firewalld ];then
|
||||
echo y | pacman -Sy firewalld
|
||||
systemctl enable firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
|
||||
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
|
||||
firewall-cmd --reload
|
||||
|
||||
@@ -29,9 +29,6 @@ if [ -f /usr/sbin/iptables ];then
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
|
||||
iptables_status=`service iptables status | grep 'not running'`
|
||||
@@ -55,9 +52,6 @@ if [ ! -f /usr/sbin/iptables ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
|
||||
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
|
||||
|
||||
+27
-21
@@ -25,38 +25,44 @@ if [ ! -z "$cn" ];then
|
||||
fi
|
||||
ntpdate $NTPHOST | logger -t NTP
|
||||
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
# choose lang cmd
|
||||
# dpkg-reconfigure --frontend=noninteractive locales
|
||||
if [ ! -f /usr/sbin/locale-gen ];then
|
||||
apt install -y locales
|
||||
sed -i '/en_US.UTF-8/s/^# //g' /etc/locale.gen
|
||||
locale-gen en_US.UTF-8
|
||||
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8
|
||||
dpkg-reconfigure --frontend=noninteractive locales
|
||||
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8 > /dev/null 2>&1
|
||||
update-locale LANG=en_US.UTF-8
|
||||
else
|
||||
locale-gen en_US.UTF-8
|
||||
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8
|
||||
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8 > /dev/null 2>&1
|
||||
fi
|
||||
|
||||
apt-get update -y
|
||||
apt install -y wget curl lsof unzip tar cron expect locate
|
||||
apt install -y python3-pip python3-dev python3-venv
|
||||
|
||||
if [ -f /usr/sbin/ufw ];then
|
||||
|
||||
ufw allow 22/tcp
|
||||
ufw allow 80/tcp
|
||||
ufw allow 443/tcp
|
||||
ufw allow 888/tcp
|
||||
# ufw allow 7200/tcp
|
||||
# ufw allow 3306/tcp
|
||||
# ufw allow 30000:40000/tcp
|
||||
fi
|
||||
# if [ -f /usr/sbin/ufw ];then
|
||||
# if [ "$SSH_PORT" != "" ];then
|
||||
# ufw allow $SSH_PORT/tcp
|
||||
# else
|
||||
# ufw allow 22/tcp
|
||||
# fi
|
||||
|
||||
if [ -f /usr/sbin/ufw ];then
|
||||
ufw disable
|
||||
fi
|
||||
# ufw allow 80/tcp
|
||||
# ufw allow 443/tcp
|
||||
# ufw allow 888/tcp
|
||||
# fi
|
||||
|
||||
if [ ! -f /usr/sbin/ufw ];then
|
||||
# if [ -f /usr/sbin/ufw ];then
|
||||
# ufw disable
|
||||
# fi
|
||||
|
||||
if [ ! -f /usr/sbin/firewalld ];then
|
||||
# look
|
||||
# firewall-cmd --list-all
|
||||
|
||||
@@ -66,20 +72,20 @@ if [ ! -f /usr/sbin/ufw ];then
|
||||
systemctl unmask firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
# fix:debian10 firewalld faq
|
||||
# https://kawsing.gitbook.io/opensystem/andoid-shou-ji/untitled/fang-huo-qiang#debian-10-firewalld-0.6.3-error-commandfailed-usrsbinip6tablesrestorewn-failed-ip6tablesrestore-v1.8
|
||||
sed -i 's#IndividualCalls=no#IndividualCalls=yes#g' /etc/firewalld/firewalld.conf
|
||||
|
||||
firewall-cmd --reload
|
||||
|
||||
#安装时不开启
|
||||
systemctl stop firewalld
|
||||
fi
|
||||
|
||||
+32
-29
@@ -17,45 +17,48 @@ yum install -y wget curl lsof unzip
|
||||
yum install -y expect
|
||||
dnf install crontabs -y
|
||||
|
||||
if [ -f /usr/sbin/iptables ];then
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
# if [ -f /usr/sbin/iptables ];then
|
||||
|
||||
iptables_status=`service iptables status | grep 'not running'`
|
||||
if [ "${iptables_status}" == '' ];then
|
||||
service iptables restart
|
||||
fi
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
# service iptables save
|
||||
|
||||
#安装时不开启
|
||||
service iptables stop
|
||||
fi
|
||||
# iptables_status=`service iptables status | grep 'not running'`
|
||||
# if [ "${iptables_status}" == '' ];then
|
||||
# service iptables restart
|
||||
# fi
|
||||
|
||||
# #安装时不开启
|
||||
# service iptables stop
|
||||
# fi
|
||||
|
||||
|
||||
if [ ! -f /usr/sbin/iptables ];then
|
||||
yum install firewalld -y
|
||||
systemctl enable firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
if [ "${isVersion}" == '' ];then
|
||||
if [ ! -f "/usr/sbin/iptables" ];then
|
||||
yum install firewalld -y
|
||||
systemctl enable firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
firewall-cmd --reload
|
||||
fi
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
firewall-cmd --reload
|
||||
fi
|
||||
|
||||
|
||||
#安装时不开启
|
||||
systemctl stop firewalld
|
||||
|
||||
|
||||
+21
-23
@@ -39,39 +39,40 @@ pkg install -y harfbuzz
|
||||
|
||||
pkg autoremove -y
|
||||
|
||||
if [ -f /usr/sbin/iptables ];then
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
# if [ -f /usr/sbin/iptables ];then
|
||||
|
||||
iptables_status=`service iptables status | grep 'not running'`
|
||||
if [ "${iptables_status}" == '' ];then
|
||||
service iptables restart
|
||||
fi
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# service iptables save
|
||||
|
||||
#安装时不开启
|
||||
service iptables stop
|
||||
fi
|
||||
# iptables_status=`service iptables status | grep 'not running'`
|
||||
# if [ "${iptables_status}" == '' ];then
|
||||
# service iptables restart
|
||||
# fi
|
||||
|
||||
# #安装时不开启
|
||||
# service iptables stop
|
||||
# fi
|
||||
|
||||
if [ ! -f /usr/sbin/iptables ];then
|
||||
pkg install -y firewalld
|
||||
systemctl enable firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
|
||||
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
|
||||
@@ -80,9 +81,6 @@ if [ ! -f /usr/sbin/iptables ];then
|
||||
systemctl stop firewalld
|
||||
fi
|
||||
|
||||
|
||||
|
||||
|
||||
cd /www/server/mdserver-web/scripts && bash lib.sh
|
||||
chmod 755 /www/server/mdserver-web/data
|
||||
|
||||
|
||||
+23
-22
@@ -52,40 +52,41 @@ zypper install -y freetype2-devel
|
||||
|
||||
# zypper install -y php-config
|
||||
|
||||
if [ -f /usr/sbin/iptables ];then
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
# if [ -f /usr/sbin/iptables ];then
|
||||
|
||||
iptables_status=`service iptables status | grep 'not running'`
|
||||
if [ "${iptables_status}" == '' ];then
|
||||
service iptables restart
|
||||
fi
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# service iptables save
|
||||
|
||||
#安装时不开启
|
||||
service iptables stop
|
||||
fi
|
||||
# iptables_status=`service iptables status | grep 'not running'`
|
||||
# if [ "${iptables_status}" == '' ];then
|
||||
# service iptables restart
|
||||
# fi
|
||||
|
||||
# #安装时不开启
|
||||
# service iptables stop
|
||||
# fi
|
||||
|
||||
|
||||
if [ ! -f /usr/sbin/iptables ];then
|
||||
if [ ! -f /usr/sbin/firewalld ];then
|
||||
zypper install -y firewalld
|
||||
systemctl enable firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
|
||||
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
|
||||
firewall-cmd --reload
|
||||
|
||||
+43
-30
@@ -33,42 +33,51 @@ if [ ! -d /root/.acme.sh ];then
|
||||
curl https://get.acme.sh | sh
|
||||
fi
|
||||
|
||||
echo "iptables wrap start"
|
||||
if [ -f /usr/sbin/iptables ];then
|
||||
$PKGMGR install -y iptables-services
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
# iptables -nL --line-number
|
||||
# redhat , iptables no default
|
||||
# echo "iptables wrap start"
|
||||
# if [ -f /usr/sbin/iptables ];then
|
||||
# $PKGMGR install -y iptables-services
|
||||
|
||||
# # iptables -nL --line-number
|
||||
|
||||
echo "iptables start"
|
||||
iptables_status=`systemctl status iptables | grep 'inactive'`
|
||||
if [ "${iptables_status}" != '' ];then
|
||||
service iptables restart
|
||||
# echo "iptables start"
|
||||
# iptables_status=`systemctl status iptables | grep 'inactive'`
|
||||
# if [ "${iptables_status}" != '' ];then
|
||||
# service iptables restart
|
||||
|
||||
# iptables -P FORWARD DROP
|
||||
iptables -P INPUT DROP
|
||||
iptables -P OUTPUT ACCEPT
|
||||
iptables -A INPUT -p tcp -s 127.0.0.1 -j ACCEPT
|
||||
# # iptables -P FORWARD DROP
|
||||
# iptables -P INPUT DROP
|
||||
# iptables -P OUTPUT ACCEPT
|
||||
# iptables -A INPUT -p tcp -s 127.0.0.1 -j ACCEPT
|
||||
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
service iptables save
|
||||
fi
|
||||
# if [ "$SSH_PORT" != "" ];then
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport ${SSH_PORT} -j ACCEPT
|
||||
# else
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
|
||||
# fi
|
||||
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
|
||||
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
|
||||
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
|
||||
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
|
||||
# service iptables save
|
||||
# fi
|
||||
|
||||
# 安装时不开启
|
||||
# stop之后清空了所有规则,所以安装是不能stop.
|
||||
# 要在代码修复这个问题,开启时,重新执行一下放行端口。
|
||||
#service iptables stop
|
||||
# # 安装时不开启
|
||||
# # stop之后清空了所有规则,所以安装是不能stop.
|
||||
# # 要在代码修复这个问题,开启时,重新执行一下放行端口。
|
||||
# #service iptables stop
|
||||
|
||||
echo "iptables end"
|
||||
fi
|
||||
echo "iptables wrap start"
|
||||
# echo "iptables end"
|
||||
# fi
|
||||
# echo "iptables wrap start"
|
||||
|
||||
if [ ! -f /usr/sbin/iptables ];then
|
||||
if [ ! -f /usr/sbin/firewalld ];then
|
||||
$PKGMGR install firewalld -y
|
||||
systemctl enable firewalld
|
||||
#取消服务锁定
|
||||
@@ -81,7 +90,11 @@ if [ ! -f /usr/sbin/iptables ];then
|
||||
# look
|
||||
# firewall-cmd --list-all
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
|
||||
+25
-17
@@ -24,36 +24,44 @@ apt install -y locate
|
||||
locale-gen en_US.UTF-8
|
||||
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8
|
||||
|
||||
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
|
||||
echo "SSH PORT:${SSH_PORT}"
|
||||
|
||||
if [ -f /usr/sbin/ufw ];then
|
||||
# if [ -f /usr/sbin/ufw ];then
|
||||
|
||||
ufw allow 22/tcp
|
||||
ufw allow 80/tcp
|
||||
ufw allow 443/tcp
|
||||
ufw allow 888/tcp
|
||||
# ufw allow 7200/tcp
|
||||
# ufw allow 3306/tcp
|
||||
# ufw allow 30000:40000/tcp
|
||||
# # look
|
||||
# # ufw status
|
||||
# ufw enable
|
||||
|
||||
fi
|
||||
# if [ "$SSH_PORT" != "" ];then
|
||||
# ufw allow $SSH_PORT/tcp
|
||||
# else
|
||||
# ufw allow 22/tcp
|
||||
# fi
|
||||
|
||||
# ufw allow 80/tcp
|
||||
# ufw allow 443/tcp
|
||||
# ufw allow 888/tcp
|
||||
# fi
|
||||
|
||||
if [ -f /usr/sbin/ufw ];then
|
||||
ufw disable
|
||||
fi
|
||||
# if [ -f /usr/sbin/ufw ];then
|
||||
# ufw disable
|
||||
# fi
|
||||
|
||||
if [ ! -f /usr/sbin/ufw ];then
|
||||
if [ ! -f /usr/sbin/firewalld ];then
|
||||
apt install -y firewalld
|
||||
systemctl enable firewalld
|
||||
systemctl start firewalld
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
if [ "$SSH_PORT" != "" ];then
|
||||
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
|
||||
else
|
||||
firewall-cmd --permanent --zone=public --add-port=22/tcp
|
||||
fi
|
||||
|
||||
firewall-cmd --permanent --zone=public --add-port=80/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=443/tcp
|
||||
firewall-cmd --permanent --zone=public --add-port=888/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
|
||||
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
|
||||
|
||||
# fix:debian10 firewalld faq
|
||||
# https://kawsing.gitbook.io/opensystem/andoid-shou-ji/untitled/fang-huo-qiang#debian-10-firewalld-0.6.3-error-commandfailed-usrsbinip6tablesrestorewn-failed-ip6tablesrestore-v1.8
|
||||
|
||||
@@ -3,12 +3,12 @@ PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
|
||||
export PATH
|
||||
export DEBIAN_FRONTEND=noninteractive
|
||||
|
||||
# apt install -y locate
|
||||
# locale-gen C.UTF-8
|
||||
# export LC_CTYPE=C.UTF-8
|
||||
# export LC_ALL=C.UTF-8
|
||||
# export LANG=C.UTF-8
|
||||
|
||||
apt install -y locate
|
||||
locale-gen en_US.UTF-8
|
||||
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8 > /dev/null 2>&1
|
||||
export LC_CTYPE=en_US.UTF-8
|
||||
export LC_ALL=en_US.UTF-8
|
||||
export LANG=en_US.UTF-8
|
||||
|
||||
# echo "LC_ALL=en_US.UTF-8" > /etc/default/locale
|
||||
# echo "LANG=en_US.UTF-8" > /etc/default/locale
|
||||
|
||||
@@ -92,6 +92,8 @@ def mwcli(mw_input=0):
|
||||
firewall_api.firewall_api().addAcceptPortArgs(
|
||||
in_port, 'WEB面板[TOOLS修改]', 'port')
|
||||
mw.writeFile('data/port.pl', in_port)
|
||||
os.system(INIT_CMD + " restart_panel")
|
||||
os.system(INIT_CMD + " default")
|
||||
else:
|
||||
print("|-端口范围在0-65536之间")
|
||||
return
|
||||
@@ -167,7 +169,7 @@ def show_panel_pwd():
|
||||
if mw.md5(file_pwd) == password:
|
||||
print('password: ' + file_pwd)
|
||||
return
|
||||
print("the password has been changed!")
|
||||
print("password has been changed!")
|
||||
|
||||
|
||||
def set_panel_username(username=None):
|
||||
|
||||
Reference in New Issue
Block a user