Set more restrictive permissions on abook files - matches how pref files are treated...
[squirrelmail.git] / functions / abook_local_file.php
1 <?php
2
3 /**
4 * abook_local_file.php
5 *
6 * @copyright &copy; 1999-2007 The SquirrelMail Project Team
7 * @license http://opensource.org/licenses/gpl-license.php GNU Public License
8 * @version $Id$
9 * @package squirrelmail
10 * @subpackage addressbook
11 */
12
13 /**
14 * Backend for address book as a pipe separated file
15 *
16 * Stores the address book in a local file
17 *
18 * An array with the following elements must be passed to
19 * the class constructor (elements marked ? are optional):
20 *<pre>
21 * filename => path to addressbook file
22 * ? create => if true: file is created if it does not exist.
23 * ? umask => umask set before opening file.
24 * ? name => name of address book.
25 * ? detect_writeable => detect address book access permissions by
26 * checking file permissions.
27 * ? writeable => allow writing into address book. Used only when
28 * detect_writeable is set to false.
29 * ? listing => enable/disable listing
30 *</pre>
31 * NOTE. This class should not be used directly. Use the
32 * "AddressBook" class instead.
33 * @package squirrelmail
34 */
35 class abook_local_file extends addressbook_backend {
36 /**
37 * Backend type
38 * @var string
39 */
40 var $btype = 'local';
41 /**
42 * Backend name
43 * @var string
44 */
45 var $bname = 'local_file';
46
47 /**
48 * File used to store data
49 * @var string
50 */
51 var $filename = '';
52 /**
53 * File handle
54 * @var object
55 */
56 var $filehandle = 0;
57 /**
58 * Create file, if it not present
59 * @var bool
60 */
61 var $create = false;
62 /**
63 * Detect, if address book is writeable by checking file permisions
64 * @var bool
65 */
66 var $detect_writeable = true;
67 /**
68 * Control write access to address book
69 *
70 * Option does not have any effect, if 'detect_writeable' is 'true'
71 * @var bool
72 */
73 var $writeable = false;
74 /**
75 * controls listing of address book
76 * @var bool
77 */
78 var $listing = true;
79 /**
80 * Umask of the file
81 * @var string
82 */
83 var $umask;
84 /**
85 * Sets max entry size (number of bytes used for all address book fields
86 * (including escapes) + 4 delimiters + 1 linefeed)
87 * @var integer
88 * @since 1.5.2
89 */
90 var $line_length = 2048;
91
92 /* ========================== Private ======================= */
93
94 /**
95 * Constructor
96 * @param array $param backend options
97 * @return bool
98 */
99 function abook_local_file($param) {
100 $this->sname = _("Personal Address Book");
101 $this->umask = Umask();
102
103 if(is_array($param)) {
104 if(empty($param['filename'])) {
105 return $this->set_error('Invalid parameters');
106 }
107 if(!is_string($param['filename'])) {
108 return $this->set_error($param['filename'] . ': '.
109 _("Not a file name"));
110 }
111
112 $this->filename = $param['filename'];
113
114 if(isset($param['create'])) {
115 $this->create = $param['create'];
116 }
117 if(isset($param['umask'])) {
118 $this->umask = $param['umask'];
119 }
120 if(isset($param['name'])) {
121 $this->sname = $param['name'];
122 }
123 if(isset($param['detect_writeable'])) {
124 $this->detect_writeable = $param['detect_writeable'];
125 }
126 if(!empty($param['writeable'])) {
127 $this->writeable = $param['writeable'];
128 }
129 if(isset($param['listing'])) {
130 $this->listing = $param['listing'];
131 }
132 if(isset($param['line_length']) && ! empty($param['line_length'])) {
133 $this->line_length = (int) $param['line_length'];
134 }
135
136 $this->open(true);
137 } else {
138 $this->set_error('Invalid argument to constructor');
139 }
140 }
141
142 /**
143 * Open the addressbook file and store the file pointer.
144 * Use $file as the file to open, or the class' own
145 * filename property. If $param is empty and file is
146 * open, do nothing.
147 * @param bool $new is file already opened
148 * @return bool
149 */
150 function open($new = false) {
151 $this->error = '';
152 $file = $this->filename;
153 $create = $this->create;
154 $fopenmode = (($this->writeable && sq_is_writable($file)) ? 'a+' : 'r');
155
156 /* Return true is file is open and $new is unset */
157 if($this->filehandle && !$new) {
158 return true;
159 }
160
161 /* Check that new file exitsts */
162 if((!(file_exists($file) && is_readable($file))) && !$create) {
163 return $this->set_error("$file: " . _("No such file or directory"));
164 }
165
166 /* Close old file, if any */
167 if($this->filehandle) { $this->close(); }
168
169 umask($this->umask);
170 if (! $this->detect_writeable) {
171 $fh = @fopen($file,$fopenmode);
172 if ($fh) {
173 $this->filehandle = &$fh;
174 $this->filename = $file;
175 } else {
176 return $this->set_error("$file: " . _("Open failed"));
177 }
178 } else {
179 /* Open file. First try to open for reading and writing,
180 * but fall back to read only. */
181 $fh = @fopen($file, 'a+');
182 if($fh) {
183 $this->filehandle = &$fh;
184 $this->filename = $file;
185 $this->writeable = true;
186 } else {
187 $fh = @fopen($file, 'r');
188 if($fh) {
189 $this->filehandle = &$fh;
190 $this->filename = $file;
191 $this->writeable = false;
192 } else {
193 return $this->set_error("$file: " . _("Open failed"));
194 }
195 }
196 }
197 return true;
198 }
199
200 /** Close the file and forget the filehandle */
201 function close() {
202 @fclose($this->filehandle);
203 $this->filehandle = 0;
204 $this->filename = '';
205 $this->writable = false;
206 }
207
208 /** Lock the datafile - try 20 times in 5 seconds */
209 function lock() {
210 for($i = 0 ; $i < 20 ; $i++) {
211 if(flock($this->filehandle, 2 + 4))
212 return true;
213 else
214 usleep(250000);
215 }
216 return false;
217 }
218
219 /** Unlock the datafile */
220 function unlock() {
221 return flock($this->filehandle, 3);
222 }
223
224 /**
225 * Overwrite the file with data from $rows
226 * NOTE! Previous locks are broken by this function
227 * @param array $rows new data
228 * @return bool
229 */
230 function overwrite(&$rows) {
231 $this->unlock();
232 $newfh = @fopen($this->filename.'.tmp', 'w');
233
234 if(!$newfh) {
235 return $this->set_error($this->filename. '.tmp:' . _("Open failed"));
236 }
237
238 for($i = 0, $cnt=sizeof($rows) ; $i < $cnt ; $i++) {
239 if(is_array($rows[$i])) {
240 for($j = 0, $cnt_part=count($rows[$i]) ; $j < $cnt_part ; $j++) {
241 $rows[$i][$j] = $this->quotevalue($rows[$i][$j]);
242 }
243 $tmpwrite = sq_fwrite($newfh, join('|', $rows[$i]) . "\n");
244 if ($tmpwrite === FALSE) {
245 return $this->set_error($this->filename . '.tmp:' . _("Write failed"));
246 }
247 }
248 }
249
250 fclose($newfh);
251 if (!@copy($this->filename . '.tmp' , $this->filename)) {
252 return $this->set_error($this->filename . ':' . _("Unable to update"));
253 }
254 @unlink($this->filename . '.tmp');
255 @chmod($this->filename, 0600);
256 $this->unlock();
257 $this->open(true);
258 return true;
259 }
260
261 /* ========================== Public ======================== */
262
263 /**
264 * Search the file
265 * @param string $expr search expression
266 * @return array search results
267 */
268 function search($expr) {
269
270 /* To be replaced by advanded search expression parsing */
271 if(is_array($expr)) { return; }
272
273 // don't allow wide search when listing is disabled.
274 if ($expr=='*' && ! $this->listing)
275 return array();
276
277 /* Make regexp from glob'ed expression
278 * May want to quote other special characters like (, ), -, [, ], etc. */
279 $expr = str_replace('?', '.', $expr);
280 $expr = str_replace('*', '.*', $expr);
281
282 $res = array();
283 if(!$this->open()) {
284 return false;
285 }
286 @rewind($this->filehandle);
287
288 while ($row = @fgetcsv($this->filehandle, $this->line_length, '|')) {
289 if (count($row)<5) {
290 /**
291 * address book is corrupted.
292 */
293 global $oTemplate;
294 error_box(_("Address book is corrupted. Required fields are missing."));
295 $oTemplate->display('footer.tpl');
296 die();
297 } else {
298 $line = join(' ', $row);
299 /**
300 * TODO: regexp search is supported only in local_file backend.
301 * Do we check format of regexp or ignore errors?
302 */
303 // errors on eregi call are suppressed in order to prevent display of regexp compilation errors
304 if(@eregi($expr, $line)) {
305 array_push($res, array('nickname' => $row[0],
306 'name' => $this->fullname($row[1], $row[2]),
307 'firstname' => $row[1],
308 'lastname' => $row[2],
309 'email' => $row[3],
310 'label' => $row[4],
311 'backend' => $this->bnum,
312 'source' => &$this->sname));
313 }
314 }
315 }
316
317 return $res;
318 }
319
320 /**
321 * Lookup an address by the indicated field.
322 *
323 * @param string $value The value to look up
324 * @param integer $field The field to look in, should be one
325 * of the SM_ABOOK_FIELD_* constants
326 * defined in include/constants.php
327 * (OPTIONAL; defaults to nickname field)
328 * NOTE: uniqueness is only guaranteed
329 * when the nickname field is used here;
330 * otherwise, the first matching address
331 * is returned.
332 *
333 * @return array Array with lookup results when the value
334 * was found, an empty array if the value was
335 * not found.
336 *
337 */
338 function lookup($value, $field=SM_ABOOK_FIELD_NICKNAME) {
339 if(empty($value)) {
340 return array();
341 }
342
343 $value = strtolower($value);
344
345 $this->open();
346 @rewind($this->filehandle);
347
348 while ($row = @fgetcsv($this->filehandle, $this->line_length, '|')) {
349 if (count($row)<5) {
350 /**
351 * address book is corrupted.
352 */
353 global $oTemplate;
354 error_box(_("Address book is corrupted. Required fields are missing."));
355 $oTemplate->display('footer.tpl');
356 die();
357 } else {
358 if(strtolower($row[$field]) == $value) {
359 return array('nickname' => $row[0],
360 'name' => $this->fullname($row[1], $row[2]),
361 'firstname' => $row[1],
362 'lastname' => $row[2],
363 'email' => $row[3],
364 'label' => $row[4],
365 'backend' => $this->bnum,
366 'source' => &$this->sname);
367 }
368 }
369 }
370
371 return array();
372 }
373
374 /**
375 * List all addresses
376 * @return array list of all addresses
377 */
378 function list_addr() {
379 $res = array();
380
381 if(isset($this->listing) && !$this->listing) {
382 return array();
383 }
384
385 $this->open();
386 @rewind($this->filehandle);
387
388 while ($row = @fgetcsv($this->filehandle, $this->line_length, '|')) {
389 if (count($row)<5) {
390 /**
391 * address book is corrupted. Don't be nice to people that
392 * violate address book formating.
393 */
394 global $oTemplate;
395 error_box(_("Address book is corrupted. Required fields are missing."));
396 $oTemplate->display('footer.tpl');
397 die();
398 } else {
399 array_push($res, array('nickname' => $row[0],
400 'name' => $this->fullname($row[1], $row[2]),
401 'firstname' => $row[1],
402 'lastname' => $row[2],
403 'email' => $row[3],
404 'label' => $row[4],
405 'backend' => $this->bnum,
406 'source' => &$this->sname));
407 }
408 }
409 return $res;
410 }
411
412 /**
413 * Add address
414 * @param array $userdata new data
415 * @return bool
416 */
417 function add($userdata) {
418 if(!$this->writeable) {
419 return $this->set_error(_("Address book is read-only"));
420 }
421 /* See if user exists already */
422 $ret = $this->lookup($userdata['nickname']);
423 if(!empty($ret)) {
424 // i18n: don't use html formating in translation
425 return $this->set_error(sprintf(_("User \"%s\" already exists"),$ret['nickname']));
426 }
427
428 /* Here is the data to write */
429 $data = $this->quotevalue($userdata['nickname']) . '|' .
430 $this->quotevalue($userdata['firstname']) . '|' .
431 $this->quotevalue((!empty($userdata['lastname'])?$userdata['lastname']:'')) . '|' .
432 $this->quotevalue($userdata['email']) . '|' .
433 $this->quotevalue((!empty($userdata['label'])?$userdata['label']:''));
434
435 /* Strip linefeeds */
436 $data = ereg_replace("[\r\n]", ' ', $data);
437
438 /**
439 * Make sure that entry fits into allocated record space.
440 * One byte is reserved for linefeed
441 */
442 if (strlen($data) >= $this->line_length) {
443 return $this->set_error(_("Address book entry is too big"));
444 }
445
446 /* Add linefeed at end */
447 $data = $data . "\n";
448
449 /* Reopen file, just to be sure */
450 $this->open(true);
451 if(!$this->writeable) {
452 return $this->set_error(_("Address book is read-only"));
453 }
454
455 /* Lock the file */
456 if(!$this->lock()) {
457 return $this->set_error(_("Could not lock datafile"));
458 }
459
460 /* Write */
461 $r = sq_fwrite($this->filehandle, $data);
462
463 /* Unlock file */
464 $this->unlock();
465
466 /* Test write result */
467 if($r === FALSE) {
468 /* Fail */
469 $this->set_error(_("Write to address book failed"));
470 return FALSE;
471 }
472
473 return TRUE;
474 }
475
476 /**
477 * Delete address
478 * @param string $alias alias that has to be deleted
479 * @return bool
480 */
481 function remove($alias) {
482 if(!$this->writeable) {
483 return $this->set_error(_("Address book is read-only"));
484 }
485
486 /* Lock the file to make sure we're the only process working
487 * on it. */
488 if(!$this->lock()) {
489 return $this->set_error(_("Could not lock datafile"));
490 }
491
492 /* Read file into memory, ignoring nicknames to delete */
493 @rewind($this->filehandle);
494 $i = 0;
495 $rows = array();
496 while($row = @fgetcsv($this->filehandle, $this->line_length, '|')) {
497 if(!in_array($row[0], $alias)) {
498 $rows[$i++] = $row;
499 }
500 }
501
502 /* Write data back */
503 if(!$this->overwrite($rows)) {
504 $this->unlock();
505 return false;
506 }
507
508 $this->unlock();
509 return true;
510 }
511
512 /**
513 * Modify address
514 * @param string $alias modified alias
515 * @param array $userdata new data
516 * @return bool true, if operation successful
517 */
518 function modify($alias, $userdata) {
519 if(!$this->writeable) {
520 return $this->set_error(_("Address book is read-only"));
521 }
522
523 /* See if user exists */
524 $ret = $this->lookup($alias);
525 if(empty($ret)) {
526 // i18n: don't use html formating in translation
527 return $this->set_error(sprintf(_("User \"%s\" does not exist"),$alias));
528 }
529
530 /* If the alias changed, see if the new alias exists */
531 if (strtolower($alias) != strtolower($userdata['nickname'])) {
532 $ret = $this->lookup($userdata['nickname']);
533 if (!empty($ret)) {
534 return $this->set_error(sprintf(_("User \"%s\" already exists"), $userdata['nickname']));
535 }
536 }
537
538 /* Lock the file to make sure we're the only process working
539 * on it. */
540 if(!$this->lock()) {
541 return $this->set_error(_("Could not lock datafile"));
542 }
543
544 /* calculate userdata size */
545 $data = $this->quotevalue($userdata['nickname']) . '|'
546 . $this->quotevalue($userdata['firstname']) . '|'
547 . $this->quotevalue((!empty($userdata['lastname'])?$userdata['lastname']:'')) . '|'
548 . $this->quotevalue($userdata['email']) . '|'
549 . $this->quotevalue((!empty($userdata['label'])?$userdata['label']:''));
550 /* make sure that it fits into allocated space */
551 if (strlen($data) >= $this->line_length) {
552 return $this->set_error(_("Address book entry is too big"));
553 }
554
555 /* Read file into memory, modifying the data for the
556 * user identified by $alias */
557 $this->open(true);
558 @rewind($this->filehandle);
559 $i = 0;
560 $rows = array();
561 while($row = @fgetcsv($this->filehandle, $this->line_length, '|')) {
562 if(strtolower($row[0]) != strtolower($alias)) {
563 $rows[$i++] = $row;
564 } else {
565 $rows[$i++] = array(0 => $userdata['nickname'],
566 1 => $userdata['firstname'],
567 2 => (!empty($userdata['lastname'])?$userdata['lastname']:''),
568 3 => $userdata['email'],
569 4 => (!empty($userdata['label'])?$userdata['label']:''));
570 }
571 }
572
573 /* Write data back */
574 if(!$this->overwrite($rows)) {
575 $this->unlock();
576 return false;
577 }
578
579 $this->unlock();
580 return true;
581 }
582
583 /**
584 * Function for quoting values before saving
585 * @param string $value string that has to be quoted
586 * @param string quoted string
587 */
588 function quotevalue($value) {
589 /* Quote the field if it contains | or ". Double quotes need to
590 * be replaced with "" */
591 if(ereg("[|\"]", $value)) {
592 $value = '"' . str_replace('"', '""', $value) . '"';
593 }
594 return $value;
595 }
596 }