X-Git-Url: http://git.roojs.org/?a=blobdiff_plain;f=DataObjects%2FCore_setting.php;h=b09acb20351bdde6c18bd1c69cbff05187929672;hb=cd0367f0b1c72b3bf7140f594c7e54ef2ed94c9e;hp=cf576e69be9ed483842da621985ebcbec7c6619f;hpb=2f658bf432818f68c5d53db7e0e155617cb6c252;p=Pman.Core diff --git a/DataObjects/Core_setting.php b/DataObjects/Core_setting.php index cf576e69..b09acb20 100644 --- a/DataObjects/Core_setting.php +++ b/DataObjects/Core_setting.php @@ -8,7 +8,8 @@ class Pman_Core_DataObjects_Core_setting extends DB_DataObject function initKeys() { - $dir = $this->keyDir(); + $dir = $this->getKeyDirectory(); + if( file_exists("{$dir}/pub.key") || file_exists("{$dir}/pri.key") @@ -30,9 +31,7 @@ class Pman_Core_DataObjects_Core_setting extends DB_DataObject file_put_contents("{$dir}/pri.key",$pri_key); } - //FIXME - rename to lookup - - function getSetting($m,$n) + function lookup($m,$n) { $s = DB_DataObject::factory('core_setting'); $s->setFrom(array( @@ -48,19 +47,17 @@ class Pman_Core_DataObjects_Core_setting extends DB_DataObject function beforeInsert($q, $roo) { exit; - - return; } - function getkeyDirectory() + function getKeyDirectory() { - $d = HTML_FlexyFramework::get()->Pman['storedir'].'/key'; - if(!file_exists($d)) { - $oldumask = umask(0); - mkdir($d, 0775, true); - umask($oldumask); + $client_dir = HTML_FlexyFramework::get()->Pman['storedir']; + $key_dir = $client_dir.'/keys'; + if(!file_exists($key_dir)) { + $this->checkWritable(get_class($this),__FUNCTION__,$client_dir); + exec("mkdir -m775 {$key_dir}"); } - return $d; + return $key_dir; } // FIXME - this needs to go in beforeInsert/beforeUpdate @@ -71,38 +68,71 @@ class Pman_Core_DataObjects_Core_setting extends DB_DataObject return; } - $c = $this->getSetting($a['module'], $a['name']); + $c = $this->lookup($a['module'], $a['name']); if($c) { return; } - $this->initKeys(); - $val = $a['val']; - if(!isset($a['is_encrypt']) || $a['is_encrypt'] == 1) { - $val = $this->encrypt($val); - } - $s = DB_DataObject::factory('core_setting'); + $s->setFrom(array( 'module' => $a['module'], 'name' => $a['name'], 'description' => $a['description'], - 'val' =>$val, + 'val' => (!isset($a['is_encrypt']) || $a['is_encrypt'] == 1) ? + $this->encrypt($a['val']) : $a['val'], 'is_encrypt' => isset($a['is_encrypt']) ? $a['is_encrypt'] : 1 )); $s->insert(); } + //one key for encrypting all the settings function encrypt($v) { - $pub_key = file_get_contents("{$this->getkeyDirectory()}/pub.key"); + $key_dir = "{$this->getKeyDirectory()}/pub.key"; + + if(!file_exists($key_dir)) { + print_r("Cannot find {$key_dir}"); + exit; + } + + $pub_key = file_get_contents($key_dir); if(!$pub_key) { return; } - openssl_public_encrypt($v, $cipher, $pub_key); - return $cipher; + openssl_public_encrypt($v, $ciphertext, $pub_key); + return $ciphertext; + } + + function decrypt($v) + { + $key_dir = "{$this->getKeyDirectory()}/pri.key"; + + if(!file_exists($key_dir)) { + print_r("Cannot find {$key_dir}"); + exit; + } + + $pri_key = file_get_contents($key_dir); + if(!$pri_key) { + return; + } + + openssl_private_decrypt($v, $plaintext, $pri_key); + return $plaintext; + } + + function checkWritable($cls_name,$func_name,$dir) + { + if(!is_writable($dir)) { + print_r("Cannot run {$cls_name} :: {$func_name}\n"); + print_r("Directory: {$dir} is not writable by current user\n"); + exit; + } + + return true; } }