BastionGuard/webui/scripts/bastionguard-webui-wizard
specialworld83 f0f913a209 Release 2.0
2026-07-15 10:52:22 +02:00

116 lines
4.7 KiB
Bash
Executable file

#!/usr/bin/env bash
set -euo pipefail
# Dedicated BastionGuard WebPanel first-run wizard helper.
# It is intentionally separate from the generic admin helper so the WebUI can
# receive explicit sudoers permissions for initial system/user setup.
# Commands mirror src/wizard and expose the helper functions needed by setup.php.
usage() {
cat >&2 <<USAGE
Usage:
$0 run <desktop-user> <http-port> <https-port> [resolv dnsmasq firewall nftables certs webconf native useragent banks services]
$0 status <desktop-user>
$0 desktop-mode <desktop-user>
$0 detect-web
$0 apply-web-config <http-port> <https-port> [auto|distro]
$0 install-ca [desktop-user|ca-path]
$0 install-thunderbird-extension <desktop-user>
$0 ensure-configs <desktop-user>
$0 update-banks <desktop-user> [source-url]
USAGE
exit 64
}
valid_user() { [[ "${1:-}" =~ ^[A-Za-z_][A-Za-z0-9_-]*[$]?$ ]] && id "$1" >/dev/null 2>&1; }
valid_port() { [[ "${1:-}" =~ ^[0-9]+$ ]] && (( $1 >= 1 && $1 <= 65535 )); }
valid_flag() {
case "${1:-}" in
resolv|dnsmasq|firewall|nftables|certs|webconf|native|useragent|banks|services) return 0 ;;
*) return 1 ;;
esac
}
valid_url() {
[[ -z "${1:-}" || "${1:-}" == https://* ]]
}
valid_ca_arg() {
[[ -z "${1:-}" ]] && return 0
valid_user "$1" && return 0
[[ "$1" == /* && "$1" != *$'\n'* ]]
}
valid_distro() {
case "${1:-auto}" in auto|debian|fedora|arch|manjaro|endeavour|opensuse|gentoo|slackware|bsd) return 0 ;; *) return 1 ;; esac
}
ADMIN=/usr/local/sbin/bastionguard-webui-admin
[[ -x "$ADMIN" ]] || { echo "Missing admin helper: $ADMIN" >&2; exit 127; }
cmd="${1:-}"; shift || true
case "$cmd" in
run)
[[ $# -ge 3 ]] || usage
user="$1"; http="$2"; https="$3"; shift 3
valid_user "$user" || { echo "Invalid desktop user: $user" >&2; exit 67; }
valid_port "$http" || { echo "Invalid HTTP port: $http" >&2; exit 64; }
valid_port "$https" || { echo "Invalid HTTPS port: $https" >&2; exit 64; }
for f in "$@"; do valid_flag "$f" || { echo "Invalid wizard flag: $f" >&2; exit 64; }; done
exec "$ADMIN" wizard "$user" "$http" "$https" "$@"
;;
status)
[[ $# -eq 1 ]] || usage
user="$1"
valid_user "$user" || { echo "Invalid desktop user: $user" >&2; exit 67; }
echo "### desktop-mode"
"$ADMIN" desktop-mode "$user" || true
echo "### configs"
"$ADMIN" list-configs "$user" || true
;;
desktop-mode)
[[ $# -eq 1 ]] || usage
valid_user "$1" || { echo "Invalid desktop user: $1" >&2; exit 67; }
exec "$ADMIN" desktop-mode "$1"
;;
detect-web)
[[ $# -eq 0 ]] || usage
# Use apply-web-config detection helpers indirectly without modifying files.
# The generic admin helper prints equivalent detection in apply-web-config;
# this command remains read-only by reporting common binaries/services.
distro="auto"
if [[ -r /etc/os-release ]]; then . /etc/os-release; distro="${ID:-auto}"; fi
web="unknown"
if systemctl is-active --quiet apache2 2>/dev/null || systemctl is-active --quiet httpd 2>/dev/null || command -v apache2 >/dev/null 2>&1 || command -v httpd >/dev/null 2>&1; then web=apache;
elif systemctl is-active --quiet nginx 2>/dev/null || command -v nginx >/dev/null 2>&1; then web=nginx;
elif systemctl is-active --quiet lshttpd 2>/dev/null || systemctl is-active --quiet lsws 2>/dev/null || command -v lsws >/dev/null 2>&1 || command -v lshttpd >/dev/null 2>&1; then web=litespeed; fi
printf 'distro=%s\nwebserver=%s\n' "${distro,,}" "$web"
;;
apply-web-config)
[[ $# -ge 2 && $# -le 3 ]] || usage
valid_port "$1" || { echo "Invalid HTTP port: $1" >&2; exit 64; }
valid_port "$2" || { echo "Invalid HTTPS port: $2" >&2; exit 64; }
valid_distro "${3:-auto}" || { echo "Invalid distro: ${3:-}" >&2; exit 64; }
exec "$ADMIN" apply-web-config "$@"
;;
install-ca)
[[ $# -le 1 ]] || usage
valid_ca_arg "${1:-}" || { echo "Invalid CA argument. Use a desktop user or absolute certificate path." >&2; exit 64; }
exec "$ADMIN" install-secure-ca "${1:-}"
;;
install-thunderbird-extension)
[[ $# -eq 1 ]] || usage
valid_user "$1" || { echo "Invalid desktop user: $1" >&2; exit 67; }
exec "$ADMIN" install-thunderbird-extension "$1"
;;
ensure-configs)
[[ $# -eq 1 ]] || usage
valid_user "$1" || { echo "Invalid desktop user: $1" >&2; exit 67; }
exec "$ADMIN" ensure-configs "$1"
;;
update-banks)
[[ $# -ge 1 && $# -le 2 ]] || usage
user="$1"; url="${2:-}"
valid_user "$user" || { echo "Invalid desktop user: $user" >&2; exit 67; }
valid_url "$url" || { echo "Invalid URL. HTTPS only." >&2; exit 64; }
if [[ -n "$url" ]]; then exec "$ADMIN" update-banks "$user" "$url"; else exec "$ADMIN" update-banks "$user"; fi
;;
*) usage ;;
esac