Deployment-Vorbereitung: Ausschlussliste, .htaccess-Haertung, Doku
Vor dem ersten FTP-Deploy nach /testumgebung.kaffeeliste.de/httpdocs/ fehlte jede Absicherung des Upload-Umfangs: sync_config.jsonc hatte eine leere excludePath-Liste, es waeren also .git (komplett herunterladbar), .env.local (Dev-DB-Zugangsdaten) und sync_config.jsonc selbst (enthaelt das FTP-Passwort im Klartext) mit ausgeliefert worden. Von diesen dreien war keines von den bestehenden .htaccess-Regeln erfasst. - sync_config.jsonc: excludePath gefuellt; scripts/ und database/ bleiben bewusst im Deploy, weil die Plesk-Scheduled-Tasks sie vom Webspace aus ausfuehren. - .htaccess: sync_config.jsonc und Dotfile-Ordner gesperrt, Vendor- Verzeichnisse (TCPDF/PHPMailer/DataTables) fuer direkte URL-Aufrufe gesperrt, HTTPS-Redirect ergaenzt (ohne ihn bekam ein http-Besucher eine Session ohne secure-Flag). - PHPMailer/ entfernt: enthielt nur noch LICENSE, composer.json und ein per URL erreichbares get_oauth_token.php, kein Quellcode. Der Versand laeuft seit M6 ueber saas_send_mail(). - docs/deployment.md: Umgebungen, Deploy-Ablauf, Migrationen und Cron-Jobs ueber Plesk Scheduled Tasks (kein SSH verfuegbar), Mail-/DNS-, Stripe- und PayPal-Voraussetzungen, Go-Live-Checkliste. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -3,5 +3,6 @@ env.local.php
|
|||||||
.local/
|
.local/
|
||||||
uploads/
|
uploads/
|
||||||
var/
|
var/
|
||||||
|
.vscode/
|
||||||
|
|
||||||
sync_config.jsonc
|
sync_config.jsonc
|
||||||
@@ -1,18 +1,42 @@
|
|||||||
# Nur *.php im Webroot und assets/ sollen direkt aufrufbar sein. Interne
|
# Nur *.php im Webroot und assets/ sollen direkt aufrufbar sein. Interne
|
||||||
# Verzeichnisse (Sessions, Mail-Logs, Migrationen, CLI-Skripte, Doku,
|
# Verzeichnisse (Sessions, Mail-Logs, Migrationen, CLI-Skripte, Doku,
|
||||||
# App-Bausteine, Legacy-DB-Shim) und Konfigurationsdateien mit
|
# App-Bausteine, Legacy-DB-Shim, Vendor-Bibliotheken), die Git-Metadaten und
|
||||||
# Zugangsdaten duerfen nicht direkt per URL abrufbar sein.
|
# Konfigurationsdateien mit Zugangsdaten duerfen nicht direkt per URL
|
||||||
|
# abrufbar sein.
|
||||||
|
|
||||||
<IfModule mod_rewrite.c>
|
<IfModule mod_rewrite.c>
|
||||||
RewriteEngine On
|
RewriteEngine On
|
||||||
|
|
||||||
|
# Alles auf HTTPS. Session-Cookies werden nur ueber HTTPS mit dem
|
||||||
|
# secure-Flag gesetzt (app_start_session()), und HSTS wird ebenfalls nur
|
||||||
|
# dann gesendet - ohne Redirect kaeme ein Nutzer per http an und bekaeme
|
||||||
|
# eine Session ohne secure-Flag. X-Forwarded-Proto deckt den Fall ab,
|
||||||
|
# dass Apache hinter dem Plesk-nginx-Proxy laeuft.
|
||||||
|
RewriteCond %{HTTPS} !=on
|
||||||
|
RewriteCond %{HTTP:X-Forwarded-Proto} !=https
|
||||||
|
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
|
||||||
|
|
||||||
RewriteCond %{REQUEST_URI} ^/(var|database|scripts|docs|app|lib)/ [NC]
|
RewriteCond %{REQUEST_URI} ^/(var|database|scripts|docs|app|lib)/ [NC]
|
||||||
RewriteRule ^ - [F]
|
RewriteRule ^ - [F]
|
||||||
|
|
||||||
|
# Vendor-Verzeichnisse werden ausschliesslich serverseitig eingebunden
|
||||||
|
# (TCPDF ueber exportKaffeeliste.php); direkte URL-Aufrufe ihrer PHP-
|
||||||
|
# Dateien sind nie erwuenscht.
|
||||||
|
RewriteCond %{REQUEST_URI} ^/(TCPDF|PHPMailer|DataTables)/ [NC]
|
||||||
|
RewriteRule ^ - [F]
|
||||||
|
|
||||||
|
# .git waere sonst komplett herunterladbar, falls es je mit deployt wird.
|
||||||
|
RewriteCond %{REQUEST_URI} ^/\.(git|claude|local)(/|$) [NC]
|
||||||
|
RewriteRule ^ - [F]
|
||||||
|
|
||||||
# Konventionelle /sitemap.xml auf die dynamische, host-korrekte Sitemap.
|
# Konventionelle /sitemap.xml auf die dynamische, host-korrekte Sitemap.
|
||||||
RewriteRule ^sitemap\.xml$ sitemap.php [L]
|
RewriteRule ^sitemap\.xml$ sitemap.php [L]
|
||||||
</IfModule>
|
</IfModule>
|
||||||
|
|
||||||
<FilesMatch "^(env\.local\.php|env\.local\.example\.php|\.env.*|composer\.(json|lock))$">
|
# Konfigurations- und Deploy-Dateien mit Zugangsdaten. sync_config.jsonc
|
||||||
|
# enthaelt das FTP-Passwort im Klartext und darf niemals ausgeliefert werden,
|
||||||
|
# auch nicht versehentlich mit hochgeladen.
|
||||||
|
<FilesMatch "^(env\.local\.php|env\.local\.example\.php|\.env.*|sync_config\.jsonc|composer\.(json|lock))$">
|
||||||
<IfModule mod_authz_core.c>
|
<IfModule mod_authz_core.c>
|
||||||
Require all denied
|
Require all denied
|
||||||
</IfModule>
|
</IfModule>
|
||||||
@@ -22,7 +46,7 @@
|
|||||||
</IfModule>
|
</IfModule>
|
||||||
</FilesMatch>
|
</FilesMatch>
|
||||||
|
|
||||||
<FilesMatch "\.(sql|md)$">
|
<FilesMatch "\.(sql|md|jsonc|yml|yaml|sh|log)$">
|
||||||
<IfModule mod_authz_core.c>
|
<IfModule mod_authz_core.c>
|
||||||
Require all denied
|
Require all denied
|
||||||
</IfModule>
|
</IfModule>
|
||||||
|
|||||||
@@ -1,46 +0,0 @@
|
|||||||
GPL Cooperation Commitment
|
|
||||||
Version 1.0
|
|
||||||
|
|
||||||
Before filing or continuing to prosecute any legal proceeding or claim
|
|
||||||
(other than a Defensive Action) arising from termination of a Covered
|
|
||||||
License, we commit to extend to the person or entity ('you') accused
|
|
||||||
of violating the Covered License the following provisions regarding
|
|
||||||
cure and reinstatement, taken from GPL version 3. As used here, the
|
|
||||||
term 'this License' refers to the specific Covered License being
|
|
||||||
enforced.
|
|
||||||
|
|
||||||
However, if you cease all violation of this License, then your
|
|
||||||
license from a particular copyright holder is reinstated (a)
|
|
||||||
provisionally, unless and until the copyright holder explicitly
|
|
||||||
and finally terminates your license, and (b) permanently, if the
|
|
||||||
copyright holder fails to notify you of the violation by some
|
|
||||||
reasonable means prior to 60 days after the cessation.
|
|
||||||
|
|
||||||
Moreover, your license from a particular copyright holder is
|
|
||||||
reinstated permanently if the copyright holder notifies you of the
|
|
||||||
violation by some reasonable means, this is the first time you
|
|
||||||
have received notice of violation of this License (for any work)
|
|
||||||
from that copyright holder, and you cure the violation prior to 30
|
|
||||||
days after your receipt of the notice.
|
|
||||||
|
|
||||||
We intend this Commitment to be irrevocable, and binding and
|
|
||||||
enforceable against us and assignees of or successors to our
|
|
||||||
copyrights.
|
|
||||||
|
|
||||||
Definitions
|
|
||||||
|
|
||||||
'Covered License' means the GNU General Public License, version 2
|
|
||||||
(GPLv2), the GNU Lesser General Public License, version 2.1
|
|
||||||
(LGPLv2.1), or the GNU Library General Public License, version 2
|
|
||||||
(LGPLv2), all as published by the Free Software Foundation.
|
|
||||||
|
|
||||||
'Defensive Action' means a legal proceeding or claim that We bring
|
|
||||||
against you in response to a prior proceeding or claim initiated by
|
|
||||||
you or your affiliate.
|
|
||||||
|
|
||||||
'We' means each contributor to this repository as of the date of
|
|
||||||
inclusion of this file, including subsidiaries of a corporate
|
|
||||||
contributor.
|
|
||||||
|
|
||||||
This work is available under a Creative Commons Attribution-ShareAlike
|
|
||||||
4.0 International license (https://creativecommons.org/licenses/by-sa/4.0/).
|
|
||||||
@@ -1,502 +0,0 @@
|
|||||||
GNU LESSER GENERAL PUBLIC LICENSE
|
|
||||||
Version 2.1, February 1999
|
|
||||||
|
|
||||||
Copyright (C) 1991, 1999 Free Software Foundation, Inc.
|
|
||||||
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
|
||||||
Everyone is permitted to copy and distribute verbatim copies
|
|
||||||
of this license document, but changing it is not allowed.
|
|
||||||
|
|
||||||
[This is the first released version of the Lesser GPL. It also counts
|
|
||||||
as the successor of the GNU Library Public License, version 2, hence
|
|
||||||
the version number 2.1.]
|
|
||||||
|
|
||||||
Preamble
|
|
||||||
|
|
||||||
The licenses for most software are designed to take away your
|
|
||||||
freedom to share and change it. By contrast, the GNU General Public
|
|
||||||
Licenses are intended to guarantee your freedom to share and change
|
|
||||||
free software--to make sure the software is free for all its users.
|
|
||||||
|
|
||||||
This license, the Lesser General Public License, applies to some
|
|
||||||
specially designated software packages--typically libraries--of the
|
|
||||||
Free Software Foundation and other authors who decide to use it. You
|
|
||||||
can use it too, but we suggest you first think carefully about whether
|
|
||||||
this license or the ordinary General Public License is the better
|
|
||||||
strategy to use in any particular case, based on the explanations below.
|
|
||||||
|
|
||||||
When we speak of free software, we are referring to freedom of use,
|
|
||||||
not price. Our General Public Licenses are designed to make sure that
|
|
||||||
you have the freedom to distribute copies of free software (and charge
|
|
||||||
for this service if you wish); that you receive source code or can get
|
|
||||||
it if you want it; that you can change the software and use pieces of
|
|
||||||
it in new free programs; and that you are informed that you can do
|
|
||||||
these things.
|
|
||||||
|
|
||||||
To protect your rights, we need to make restrictions that forbid
|
|
||||||
distributors to deny you these rights or to ask you to surrender these
|
|
||||||
rights. These restrictions translate to certain responsibilities for
|
|
||||||
you if you distribute copies of the library or if you modify it.
|
|
||||||
|
|
||||||
For example, if you distribute copies of the library, whether gratis
|
|
||||||
or for a fee, you must give the recipients all the rights that we gave
|
|
||||||
you. You must make sure that they, too, receive or can get the source
|
|
||||||
code. If you link other code with the library, you must provide
|
|
||||||
complete object files to the recipients, so that they can relink them
|
|
||||||
with the library after making changes to the library and recompiling
|
|
||||||
it. And you must show them these terms so they know their rights.
|
|
||||||
|
|
||||||
We protect your rights with a two-step method: (1) we copyright the
|
|
||||||
library, and (2) we offer you this license, which gives you legal
|
|
||||||
permission to copy, distribute and/or modify the library.
|
|
||||||
|
|
||||||
To protect each distributor, we want to make it very clear that
|
|
||||||
there is no warranty for the free library. Also, if the library is
|
|
||||||
modified by someone else and passed on, the recipients should know
|
|
||||||
that what they have is not the original version, so that the original
|
|
||||||
author's reputation will not be affected by problems that might be
|
|
||||||
introduced by others.
|
|
||||||
|
|
||||||
Finally, software patents pose a constant threat to the existence of
|
|
||||||
any free program. We wish to make sure that a company cannot
|
|
||||||
effectively restrict the users of a free program by obtaining a
|
|
||||||
restrictive license from a patent holder. Therefore, we insist that
|
|
||||||
any patent license obtained for a version of the library must be
|
|
||||||
consistent with the full freedom of use specified in this license.
|
|
||||||
|
|
||||||
Most GNU software, including some libraries, is covered by the
|
|
||||||
ordinary GNU General Public License. This license, the GNU Lesser
|
|
||||||
General Public License, applies to certain designated libraries, and
|
|
||||||
is quite different from the ordinary General Public License. We use
|
|
||||||
this license for certain libraries in order to permit linking those
|
|
||||||
libraries into non-free programs.
|
|
||||||
|
|
||||||
When a program is linked with a library, whether statically or using
|
|
||||||
a shared library, the combination of the two is legally speaking a
|
|
||||||
combined work, a derivative of the original library. The ordinary
|
|
||||||
General Public License therefore permits such linking only if the
|
|
||||||
entire combination fits its criteria of freedom. The Lesser General
|
|
||||||
Public License permits more lax criteria for linking other code with
|
|
||||||
the library.
|
|
||||||
|
|
||||||
We call this license the "Lesser" General Public License because it
|
|
||||||
does Less to protect the user's freedom than the ordinary General
|
|
||||||
Public License. It also provides other free software developers Less
|
|
||||||
of an advantage over competing non-free programs. These disadvantages
|
|
||||||
are the reason we use the ordinary General Public License for many
|
|
||||||
libraries. However, the Lesser license provides advantages in certain
|
|
||||||
special circumstances.
|
|
||||||
|
|
||||||
For example, on rare occasions, there may be a special need to
|
|
||||||
encourage the widest possible use of a certain library, so that it becomes
|
|
||||||
a de-facto standard. To achieve this, non-free programs must be
|
|
||||||
allowed to use the library. A more frequent case is that a free
|
|
||||||
library does the same job as widely used non-free libraries. In this
|
|
||||||
case, there is little to gain by limiting the free library to free
|
|
||||||
software only, so we use the Lesser General Public License.
|
|
||||||
|
|
||||||
In other cases, permission to use a particular library in non-free
|
|
||||||
programs enables a greater number of people to use a large body of
|
|
||||||
free software. For example, permission to use the GNU C Library in
|
|
||||||
non-free programs enables many more people to use the whole GNU
|
|
||||||
operating system, as well as its variant, the GNU/Linux operating
|
|
||||||
system.
|
|
||||||
|
|
||||||
Although the Lesser General Public License is Less protective of the
|
|
||||||
users' freedom, it does ensure that the user of a program that is
|
|
||||||
linked with the Library has the freedom and the wherewithal to run
|
|
||||||
that program using a modified version of the Library.
|
|
||||||
|
|
||||||
The precise terms and conditions for copying, distribution and
|
|
||||||
modification follow. Pay close attention to the difference between a
|
|
||||||
"work based on the library" and a "work that uses the library". The
|
|
||||||
former contains code derived from the library, whereas the latter must
|
|
||||||
be combined with the library in order to run.
|
|
||||||
|
|
||||||
GNU LESSER GENERAL PUBLIC LICENSE
|
|
||||||
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
|
|
||||||
|
|
||||||
0. This License Agreement applies to any software library or other
|
|
||||||
program which contains a notice placed by the copyright holder or
|
|
||||||
other authorized party saying it may be distributed under the terms of
|
|
||||||
this Lesser General Public License (also called "this License").
|
|
||||||
Each licensee is addressed as "you".
|
|
||||||
|
|
||||||
A "library" means a collection of software functions and/or data
|
|
||||||
prepared so as to be conveniently linked with application programs
|
|
||||||
(which use some of those functions and data) to form executables.
|
|
||||||
|
|
||||||
The "Library", below, refers to any such software library or work
|
|
||||||
which has been distributed under these terms. A "work based on the
|
|
||||||
Library" means either the Library or any derivative work under
|
|
||||||
copyright law: that is to say, a work containing the Library or a
|
|
||||||
portion of it, either verbatim or with modifications and/or translated
|
|
||||||
straightforwardly into another language. (Hereinafter, translation is
|
|
||||||
included without limitation in the term "modification".)
|
|
||||||
|
|
||||||
"Source code" for a work means the preferred form of the work for
|
|
||||||
making modifications to it. For a library, complete source code means
|
|
||||||
all the source code for all modules it contains, plus any associated
|
|
||||||
interface definition files, plus the scripts used to control compilation
|
|
||||||
and installation of the library.
|
|
||||||
|
|
||||||
Activities other than copying, distribution and modification are not
|
|
||||||
covered by this License; they are outside its scope. The act of
|
|
||||||
running a program using the Library is not restricted, and output from
|
|
||||||
such a program is covered only if its contents constitute a work based
|
|
||||||
on the Library (independent of the use of the Library in a tool for
|
|
||||||
writing it). Whether that is true depends on what the Library does
|
|
||||||
and what the program that uses the Library does.
|
|
||||||
|
|
||||||
1. You may copy and distribute verbatim copies of the Library's
|
|
||||||
complete source code as you receive it, in any medium, provided that
|
|
||||||
you conspicuously and appropriately publish on each copy an
|
|
||||||
appropriate copyright notice and disclaimer of warranty; keep intact
|
|
||||||
all the notices that refer to this License and to the absence of any
|
|
||||||
warranty; and distribute a copy of this License along with the
|
|
||||||
Library.
|
|
||||||
|
|
||||||
You may charge a fee for the physical act of transferring a copy,
|
|
||||||
and you may at your option offer warranty protection in exchange for a
|
|
||||||
fee.
|
|
||||||
|
|
||||||
2. You may modify your copy or copies of the Library or any portion
|
|
||||||
of it, thus forming a work based on the Library, and copy and
|
|
||||||
distribute such modifications or work under the terms of Section 1
|
|
||||||
above, provided that you also meet all of these conditions:
|
|
||||||
|
|
||||||
a) The modified work must itself be a software library.
|
|
||||||
|
|
||||||
b) You must cause the files modified to carry prominent notices
|
|
||||||
stating that you changed the files and the date of any change.
|
|
||||||
|
|
||||||
c) You must cause the whole of the work to be licensed at no
|
|
||||||
charge to all third parties under the terms of this License.
|
|
||||||
|
|
||||||
d) If a facility in the modified Library refers to a function or a
|
|
||||||
table of data to be supplied by an application program that uses
|
|
||||||
the facility, other than as an argument passed when the facility
|
|
||||||
is invoked, then you must make a good faith effort to ensure that,
|
|
||||||
in the event an application does not supply such function or
|
|
||||||
table, the facility still operates, and performs whatever part of
|
|
||||||
its purpose remains meaningful.
|
|
||||||
|
|
||||||
(For example, a function in a library to compute square roots has
|
|
||||||
a purpose that is entirely well-defined independent of the
|
|
||||||
application. Therefore, Subsection 2d requires that any
|
|
||||||
application-supplied function or table used by this function must
|
|
||||||
be optional: if the application does not supply it, the square
|
|
||||||
root function must still compute square roots.)
|
|
||||||
|
|
||||||
These requirements apply to the modified work as a whole. If
|
|
||||||
identifiable sections of that work are not derived from the Library,
|
|
||||||
and can be reasonably considered independent and separate works in
|
|
||||||
themselves, then this License, and its terms, do not apply to those
|
|
||||||
sections when you distribute them as separate works. But when you
|
|
||||||
distribute the same sections as part of a whole which is a work based
|
|
||||||
on the Library, the distribution of the whole must be on the terms of
|
|
||||||
this License, whose permissions for other licensees extend to the
|
|
||||||
entire whole, and thus to each and every part regardless of who wrote
|
|
||||||
it.
|
|
||||||
|
|
||||||
Thus, it is not the intent of this section to claim rights or contest
|
|
||||||
your rights to work written entirely by you; rather, the intent is to
|
|
||||||
exercise the right to control the distribution of derivative or
|
|
||||||
collective works based on the Library.
|
|
||||||
|
|
||||||
In addition, mere aggregation of another work not based on the Library
|
|
||||||
with the Library (or with a work based on the Library) on a volume of
|
|
||||||
a storage or distribution medium does not bring the other work under
|
|
||||||
the scope of this License.
|
|
||||||
|
|
||||||
3. You may opt to apply the terms of the ordinary GNU General Public
|
|
||||||
License instead of this License to a given copy of the Library. To do
|
|
||||||
this, you must alter all the notices that refer to this License, so
|
|
||||||
that they refer to the ordinary GNU General Public License, version 2,
|
|
||||||
instead of to this License. (If a newer version than version 2 of the
|
|
||||||
ordinary GNU General Public License has appeared, then you can specify
|
|
||||||
that version instead if you wish.) Do not make any other change in
|
|
||||||
these notices.
|
|
||||||
|
|
||||||
Once this change is made in a given copy, it is irreversible for
|
|
||||||
that copy, so the ordinary GNU General Public License applies to all
|
|
||||||
subsequent copies and derivative works made from that copy.
|
|
||||||
|
|
||||||
This option is useful when you wish to copy part of the code of
|
|
||||||
the Library into a program that is not a library.
|
|
||||||
|
|
||||||
4. You may copy and distribute the Library (or a portion or
|
|
||||||
derivative of it, under Section 2) in object code or executable form
|
|
||||||
under the terms of Sections 1 and 2 above provided that you accompany
|
|
||||||
it with the complete corresponding machine-readable source code, which
|
|
||||||
must be distributed under the terms of Sections 1 and 2 above on a
|
|
||||||
medium customarily used for software interchange.
|
|
||||||
|
|
||||||
If distribution of object code is made by offering access to copy
|
|
||||||
from a designated place, then offering equivalent access to copy the
|
|
||||||
source code from the same place satisfies the requirement to
|
|
||||||
distribute the source code, even though third parties are not
|
|
||||||
compelled to copy the source along with the object code.
|
|
||||||
|
|
||||||
5. A program that contains no derivative of any portion of the
|
|
||||||
Library, but is designed to work with the Library by being compiled or
|
|
||||||
linked with it, is called a "work that uses the Library". Such a
|
|
||||||
work, in isolation, is not a derivative work of the Library, and
|
|
||||||
therefore falls outside the scope of this License.
|
|
||||||
|
|
||||||
However, linking a "work that uses the Library" with the Library
|
|
||||||
creates an executable that is a derivative of the Library (because it
|
|
||||||
contains portions of the Library), rather than a "work that uses the
|
|
||||||
library". The executable is therefore covered by this License.
|
|
||||||
Section 6 states terms for distribution of such executables.
|
|
||||||
|
|
||||||
When a "work that uses the Library" uses material from a header file
|
|
||||||
that is part of the Library, the object code for the work may be a
|
|
||||||
derivative work of the Library even though the source code is not.
|
|
||||||
Whether this is true is especially significant if the work can be
|
|
||||||
linked without the Library, or if the work is itself a library. The
|
|
||||||
threshold for this to be true is not precisely defined by law.
|
|
||||||
|
|
||||||
If such an object file uses only numerical parameters, data
|
|
||||||
structure layouts and accessors, and small macros and small inline
|
|
||||||
functions (ten lines or less in length), then the use of the object
|
|
||||||
file is unrestricted, regardless of whether it is legally a derivative
|
|
||||||
work. (Executables containing this object code plus portions of the
|
|
||||||
Library will still fall under Section 6.)
|
|
||||||
|
|
||||||
Otherwise, if the work is a derivative of the Library, you may
|
|
||||||
distribute the object code for the work under the terms of Section 6.
|
|
||||||
Any executables containing that work also fall under Section 6,
|
|
||||||
whether or not they are linked directly with the Library itself.
|
|
||||||
|
|
||||||
6. As an exception to the Sections above, you may also combine or
|
|
||||||
link a "work that uses the Library" with the Library to produce a
|
|
||||||
work containing portions of the Library, and distribute that work
|
|
||||||
under terms of your choice, provided that the terms permit
|
|
||||||
modification of the work for the customer's own use and reverse
|
|
||||||
engineering for debugging such modifications.
|
|
||||||
|
|
||||||
You must give prominent notice with each copy of the work that the
|
|
||||||
Library is used in it and that the Library and its use are covered by
|
|
||||||
this License. You must supply a copy of this License. If the work
|
|
||||||
during execution displays copyright notices, you must include the
|
|
||||||
copyright notice for the Library among them, as well as a reference
|
|
||||||
directing the user to the copy of this License. Also, you must do one
|
|
||||||
of these things:
|
|
||||||
|
|
||||||
a) Accompany the work with the complete corresponding
|
|
||||||
machine-readable source code for the Library including whatever
|
|
||||||
changes were used in the work (which must be distributed under
|
|
||||||
Sections 1 and 2 above); and, if the work is an executable linked
|
|
||||||
with the Library, with the complete machine-readable "work that
|
|
||||||
uses the Library", as object code and/or source code, so that the
|
|
||||||
user can modify the Library and then relink to produce a modified
|
|
||||||
executable containing the modified Library. (It is understood
|
|
||||||
that the user who changes the contents of definitions files in the
|
|
||||||
Library will not necessarily be able to recompile the application
|
|
||||||
to use the modified definitions.)
|
|
||||||
|
|
||||||
b) Use a suitable shared library mechanism for linking with the
|
|
||||||
Library. A suitable mechanism is one that (1) uses at run time a
|
|
||||||
copy of the library already present on the user's computer system,
|
|
||||||
rather than copying library functions into the executable, and (2)
|
|
||||||
will operate properly with a modified version of the library, if
|
|
||||||
the user installs one, as long as the modified version is
|
|
||||||
interface-compatible with the version that the work was made with.
|
|
||||||
|
|
||||||
c) Accompany the work with a written offer, valid for at
|
|
||||||
least three years, to give the same user the materials
|
|
||||||
specified in Subsection 6a, above, for a charge no more
|
|
||||||
than the cost of performing this distribution.
|
|
||||||
|
|
||||||
d) If distribution of the work is made by offering access to copy
|
|
||||||
from a designated place, offer equivalent access to copy the above
|
|
||||||
specified materials from the same place.
|
|
||||||
|
|
||||||
e) Verify that the user has already received a copy of these
|
|
||||||
materials or that you have already sent this user a copy.
|
|
||||||
|
|
||||||
For an executable, the required form of the "work that uses the
|
|
||||||
Library" must include any data and utility programs needed for
|
|
||||||
reproducing the executable from it. However, as a special exception,
|
|
||||||
the materials to be distributed need not include anything that is
|
|
||||||
normally distributed (in either source or binary form) with the major
|
|
||||||
components (compiler, kernel, and so on) of the operating system on
|
|
||||||
which the executable runs, unless that component itself accompanies
|
|
||||||
the executable.
|
|
||||||
|
|
||||||
It may happen that this requirement contradicts the license
|
|
||||||
restrictions of other proprietary libraries that do not normally
|
|
||||||
accompany the operating system. Such a contradiction means you cannot
|
|
||||||
use both them and the Library together in an executable that you
|
|
||||||
distribute.
|
|
||||||
|
|
||||||
7. You may place library facilities that are a work based on the
|
|
||||||
Library side-by-side in a single library together with other library
|
|
||||||
facilities not covered by this License, and distribute such a combined
|
|
||||||
library, provided that the separate distribution of the work based on
|
|
||||||
the Library and of the other library facilities is otherwise
|
|
||||||
permitted, and provided that you do these two things:
|
|
||||||
|
|
||||||
a) Accompany the combined library with a copy of the same work
|
|
||||||
based on the Library, uncombined with any other library
|
|
||||||
facilities. This must be distributed under the terms of the
|
|
||||||
Sections above.
|
|
||||||
|
|
||||||
b) Give prominent notice with the combined library of the fact
|
|
||||||
that part of it is a work based on the Library, and explaining
|
|
||||||
where to find the accompanying uncombined form of the same work.
|
|
||||||
|
|
||||||
8. You may not copy, modify, sublicense, link with, or distribute
|
|
||||||
the Library except as expressly provided under this License. Any
|
|
||||||
attempt otherwise to copy, modify, sublicense, link with, or
|
|
||||||
distribute the Library is void, and will automatically terminate your
|
|
||||||
rights under this License. However, parties who have received copies,
|
|
||||||
or rights, from you under this License will not have their licenses
|
|
||||||
terminated so long as such parties remain in full compliance.
|
|
||||||
|
|
||||||
9. You are not required to accept this License, since you have not
|
|
||||||
signed it. However, nothing else grants you permission to modify or
|
|
||||||
distribute the Library or its derivative works. These actions are
|
|
||||||
prohibited by law if you do not accept this License. Therefore, by
|
|
||||||
modifying or distributing the Library (or any work based on the
|
|
||||||
Library), you indicate your acceptance of this License to do so, and
|
|
||||||
all its terms and conditions for copying, distributing or modifying
|
|
||||||
the Library or works based on it.
|
|
||||||
|
|
||||||
10. Each time you redistribute the Library (or any work based on the
|
|
||||||
Library), the recipient automatically receives a license from the
|
|
||||||
original licensor to copy, distribute, link with or modify the Library
|
|
||||||
subject to these terms and conditions. You may not impose any further
|
|
||||||
restrictions on the recipients' exercise of the rights granted herein.
|
|
||||||
You are not responsible for enforcing compliance by third parties with
|
|
||||||
this License.
|
|
||||||
|
|
||||||
11. If, as a consequence of a court judgment or allegation of patent
|
|
||||||
infringement or for any other reason (not limited to patent issues),
|
|
||||||
conditions are imposed on you (whether by court order, agreement or
|
|
||||||
otherwise) that contradict the conditions of this License, they do not
|
|
||||||
excuse you from the conditions of this License. If you cannot
|
|
||||||
distribute so as to satisfy simultaneously your obligations under this
|
|
||||||
License and any other pertinent obligations, then as a consequence you
|
|
||||||
may not distribute the Library at all. For example, if a patent
|
|
||||||
license would not permit royalty-free redistribution of the Library by
|
|
||||||
all those who receive copies directly or indirectly through you, then
|
|
||||||
the only way you could satisfy both it and this License would be to
|
|
||||||
refrain entirely from distribution of the Library.
|
|
||||||
|
|
||||||
If any portion of this section is held invalid or unenforceable under any
|
|
||||||
particular circumstance, the balance of the section is intended to apply,
|
|
||||||
and the section as a whole is intended to apply in other circumstances.
|
|
||||||
|
|
||||||
It is not the purpose of this section to induce you to infringe any
|
|
||||||
patents or other property right claims or to contest validity of any
|
|
||||||
such claims; this section has the sole purpose of protecting the
|
|
||||||
integrity of the free software distribution system which is
|
|
||||||
implemented by public license practices. Many people have made
|
|
||||||
generous contributions to the wide range of software distributed
|
|
||||||
through that system in reliance on consistent application of that
|
|
||||||
system; it is up to the author/donor to decide if he or she is willing
|
|
||||||
to distribute software through any other system and a licensee cannot
|
|
||||||
impose that choice.
|
|
||||||
|
|
||||||
This section is intended to make thoroughly clear what is believed to
|
|
||||||
be a consequence of the rest of this License.
|
|
||||||
|
|
||||||
12. If the distribution and/or use of the Library is restricted in
|
|
||||||
certain countries either by patents or by copyrighted interfaces, the
|
|
||||||
original copyright holder who places the Library under this License may add
|
|
||||||
an explicit geographical distribution limitation excluding those countries,
|
|
||||||
so that distribution is permitted only in or among countries not thus
|
|
||||||
excluded. In such case, this License incorporates the limitation as if
|
|
||||||
written in the body of this License.
|
|
||||||
|
|
||||||
13. The Free Software Foundation may publish revised and/or new
|
|
||||||
versions of the Lesser General Public License from time to time.
|
|
||||||
Such new versions will be similar in spirit to the present version,
|
|
||||||
but may differ in detail to address new problems or concerns.
|
|
||||||
|
|
||||||
Each version is given a distinguishing version number. If the Library
|
|
||||||
specifies a version number of this License which applies to it and
|
|
||||||
"any later version", you have the option of following the terms and
|
|
||||||
conditions either of that version or of any later version published by
|
|
||||||
the Free Software Foundation. If the Library does not specify a
|
|
||||||
license version number, you may choose any version ever published by
|
|
||||||
the Free Software Foundation.
|
|
||||||
|
|
||||||
14. If you wish to incorporate parts of the Library into other free
|
|
||||||
programs whose distribution conditions are incompatible with these,
|
|
||||||
write to the author to ask for permission. For software which is
|
|
||||||
copyrighted by the Free Software Foundation, write to the Free
|
|
||||||
Software Foundation; we sometimes make exceptions for this. Our
|
|
||||||
decision will be guided by the two goals of preserving the free status
|
|
||||||
of all derivatives of our free software and of promoting the sharing
|
|
||||||
and reuse of software generally.
|
|
||||||
|
|
||||||
NO WARRANTY
|
|
||||||
|
|
||||||
15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO
|
|
||||||
WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW.
|
|
||||||
EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
|
|
||||||
OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANTY OF ANY
|
|
||||||
KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE
|
|
||||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
|
||||||
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE
|
|
||||||
LIBRARY IS WITH YOU. SHOULD THE LIBRARY PROVE DEFECTIVE, YOU ASSUME
|
|
||||||
THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
|
||||||
|
|
||||||
16. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN
|
|
||||||
WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY
|
|
||||||
AND/OR REDISTRIBUTE THE LIBRARY AS PERMITTED ABOVE, BE LIABLE TO YOU
|
|
||||||
FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR
|
|
||||||
CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE
|
|
||||||
LIBRARY (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING
|
|
||||||
RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A
|
|
||||||
FAILURE OF THE LIBRARY TO OPERATE WITH ANY OTHER SOFTWARE), EVEN IF
|
|
||||||
SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH
|
|
||||||
DAMAGES.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
How to Apply These Terms to Your New Libraries
|
|
||||||
|
|
||||||
If you develop a new library, and you want it to be of the greatest
|
|
||||||
possible use to the public, we recommend making it free software that
|
|
||||||
everyone can redistribute and change. You can do so by permitting
|
|
||||||
redistribution under these terms (or, alternatively, under the terms of the
|
|
||||||
ordinary General Public License).
|
|
||||||
|
|
||||||
To apply these terms, attach the following notices to the library. It is
|
|
||||||
safest to attach them to the start of each source file to most effectively
|
|
||||||
convey the exclusion of warranty; and each file should have at least the
|
|
||||||
"copyright" line and a pointer to where the full notice is found.
|
|
||||||
|
|
||||||
<one line to give the library's name and a brief idea of what it does.>
|
|
||||||
Copyright (C) <year> <name of author>
|
|
||||||
|
|
||||||
This library is free software; you can redistribute it and/or
|
|
||||||
modify it under the terms of the GNU Lesser General Public
|
|
||||||
License as published by the Free Software Foundation; either
|
|
||||||
version 2.1 of the License, or (at your option) any later version.
|
|
||||||
|
|
||||||
This library is distributed in the hope that it will be useful,
|
|
||||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
||||||
Lesser General Public License for more details.
|
|
||||||
|
|
||||||
You should have received a copy of the GNU Lesser General Public
|
|
||||||
License along with this library; if not, write to the Free Software
|
|
||||||
Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
|
||||||
|
|
||||||
Also add information on how to contact you by electronic and paper mail.
|
|
||||||
|
|
||||||
You should also get your employer (if you work as a programmer) or your
|
|
||||||
school, if any, to sign a "copyright disclaimer" for the library, if
|
|
||||||
necessary. Here is a sample; alter the names:
|
|
||||||
|
|
||||||
Yoyodyne, Inc., hereby disclaims all copyright interest in the
|
|
||||||
library `Frob' (a library for tweaking knobs) written by James Random Hacker.
|
|
||||||
|
|
||||||
<signature of Ty Coon>, 1 April 1990
|
|
||||||
Ty Coon, President of Vice
|
|
||||||
|
|
||||||
That's all there is to it!
|
|
||||||
@@ -1,79 +0,0 @@
|
|||||||
{
|
|
||||||
"name": "phpmailer/phpmailer",
|
|
||||||
"type": "library",
|
|
||||||
"description": "PHPMailer is a full-featured email creation and transfer class for PHP",
|
|
||||||
"authors": [
|
|
||||||
{
|
|
||||||
"name": "Marcus Bointon",
|
|
||||||
"email": "phpmailer@synchromedia.co.uk"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "Jim Jagielski",
|
|
||||||
"email": "jimjag@gmail.com"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "Andy Prevost",
|
|
||||||
"email": "codeworxtech@users.sourceforge.net"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "Brent R. Matzelle"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"funding": [
|
|
||||||
{
|
|
||||||
"url": "https://github.com/Synchro",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"config": {
|
|
||||||
"allow-plugins": {
|
|
||||||
"dealerdirect/phpcodesniffer-composer-installer": true
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"require": {
|
|
||||||
"php": ">=5.5.0",
|
|
||||||
"ext-ctype": "*",
|
|
||||||
"ext-filter": "*",
|
|
||||||
"ext-hash": "*"
|
|
||||||
},
|
|
||||||
"require-dev": {
|
|
||||||
"dealerdirect/phpcodesniffer-composer-installer": "^1.0",
|
|
||||||
"doctrine/annotations": "^1.2.6 || ^1.13.3",
|
|
||||||
"php-parallel-lint/php-console-highlighter": "^1.0.0",
|
|
||||||
"php-parallel-lint/php-parallel-lint": "^1.3.2",
|
|
||||||
"phpcompatibility/php-compatibility": "^9.3.5",
|
|
||||||
"roave/security-advisories": "dev-latest",
|
|
||||||
"squizlabs/php_codesniffer": "^3.7.2",
|
|
||||||
"yoast/phpunit-polyfills": "^1.0.4"
|
|
||||||
},
|
|
||||||
"suggest": {
|
|
||||||
"decomplexity/SendOauth2": "Adapter for using XOAUTH2 authentication",
|
|
||||||
"ext-mbstring": "Needed to send email in multibyte encoding charset or decode encoded addresses",
|
|
||||||
"ext-openssl": "Needed for secure SMTP sending and DKIM signing",
|
|
||||||
"greew/oauth2-azure-provider": "Needed for Microsoft Azure XOAUTH2 authentication",
|
|
||||||
"hayageek/oauth2-yahoo": "Needed for Yahoo XOAUTH2 authentication",
|
|
||||||
"league/oauth2-google": "Needed for Google XOAUTH2 authentication",
|
|
||||||
"psr/log": "For optional PSR-3 debug logging",
|
|
||||||
"thenetworg/oauth2-azure": "Needed for Microsoft XOAUTH2 authentication",
|
|
||||||
"symfony/polyfill-mbstring": "To support UTF-8 if the Mbstring PHP extension is not enabled (^1.2)"
|
|
||||||
},
|
|
||||||
"autoload": {
|
|
||||||
"psr-4": {
|
|
||||||
"PHPMailer\\PHPMailer\\": "src/"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"autoload-dev": {
|
|
||||||
"psr-4": {
|
|
||||||
"PHPMailer\\Test\\": "test/"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"license": "LGPL-2.1-only",
|
|
||||||
"scripts": {
|
|
||||||
"check": "./vendor/bin/phpcs",
|
|
||||||
"test": "./vendor/bin/phpunit --no-coverage",
|
|
||||||
"coverage": "./vendor/bin/phpunit",
|
|
||||||
"lint": [
|
|
||||||
"@php ./vendor/php-parallel-lint/php-parallel-lint/parallel-lint . --show-deprecated -e php,phps --exclude vendor --exclude .git --exclude build"
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,182 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
/**
|
|
||||||
* PHPMailer - PHP email creation and transport class.
|
|
||||||
* PHP Version 5.5
|
|
||||||
* @package PHPMailer
|
|
||||||
* @see https://github.com/PHPMailer/PHPMailer/ The PHPMailer GitHub project
|
|
||||||
* @author Marcus Bointon (Synchro/coolbru) <phpmailer@synchromedia.co.uk>
|
|
||||||
* @author Jim Jagielski (jimjag) <jimjag@gmail.com>
|
|
||||||
* @author Andy Prevost (codeworxtech) <codeworxtech@users.sourceforge.net>
|
|
||||||
* @author Brent R. Matzelle (original founder)
|
|
||||||
* @copyright 2012 - 2020 Marcus Bointon
|
|
||||||
* @copyright 2010 - 2012 Jim Jagielski
|
|
||||||
* @copyright 2004 - 2009 Andy Prevost
|
|
||||||
* @license http://www.gnu.org/copyleft/lesser.html GNU Lesser General Public License
|
|
||||||
* @note This program is distributed in the hope that it will be useful - WITHOUT
|
|
||||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
||||||
* FITNESS FOR A PARTICULAR PURPOSE.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Get an OAuth2 token from an OAuth2 provider.
|
|
||||||
* * Install this script on your server so that it's accessible
|
|
||||||
* as [https/http]://<yourdomain>/<folder>/get_oauth_token.php
|
|
||||||
* e.g.: http://localhost/phpmailer/get_oauth_token.php
|
|
||||||
* * Ensure dependencies are installed with 'composer install'
|
|
||||||
* * Set up an app in your Google/Yahoo/Microsoft account
|
|
||||||
* * Set the script address as the app's redirect URL
|
|
||||||
* If no refresh token is obtained when running this file,
|
|
||||||
* revoke access to your app and run the script again.
|
|
||||||
*/
|
|
||||||
|
|
||||||
namespace PHPMailer\PHPMailer;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Aliases for League Provider Classes
|
|
||||||
* Make sure you have added these to your composer.json and run `composer install`
|
|
||||||
* Plenty to choose from here:
|
|
||||||
* @see http://oauth2-client.thephpleague.com/providers/thirdparty/
|
|
||||||
*/
|
|
||||||
//@see https://github.com/thephpleague/oauth2-google
|
|
||||||
use League\OAuth2\Client\Provider\Google;
|
|
||||||
//@see https://packagist.org/packages/hayageek/oauth2-yahoo
|
|
||||||
use Hayageek\OAuth2\Client\Provider\Yahoo;
|
|
||||||
//@see https://github.com/stevenmaguire/oauth2-microsoft
|
|
||||||
use Stevenmaguire\OAuth2\Client\Provider\Microsoft;
|
|
||||||
//@see https://github.com/greew/oauth2-azure-provider
|
|
||||||
use Greew\OAuth2\Client\Provider\Azure;
|
|
||||||
|
|
||||||
if (!isset($_GET['code']) && !isset($_POST['provider'])) {
|
|
||||||
?>
|
|
||||||
<html>
|
|
||||||
<body>
|
|
||||||
<form method="post">
|
|
||||||
<h1>Select Provider</h1>
|
|
||||||
<input type="radio" name="provider" value="Google" id="providerGoogle">
|
|
||||||
<label for="providerGoogle">Google</label><br>
|
|
||||||
<input type="radio" name="provider" value="Yahoo" id="providerYahoo">
|
|
||||||
<label for="providerYahoo">Yahoo</label><br>
|
|
||||||
<input type="radio" name="provider" value="Microsoft" id="providerMicrosoft">
|
|
||||||
<label for="providerMicrosoft">Microsoft</label><br>
|
|
||||||
<input type="radio" name="provider" value="Azure" id="providerAzure">
|
|
||||||
<label for="providerAzure">Azure</label><br>
|
|
||||||
<h1>Enter id and secret</h1>
|
|
||||||
<p>These details are obtained by setting up an app in your provider's developer console.
|
|
||||||
</p>
|
|
||||||
<p>ClientId: <input type="text" name="clientId"><p>
|
|
||||||
<p>ClientSecret: <input type="text" name="clientSecret"></p>
|
|
||||||
<p>TenantID (only relevant for Azure): <input type="text" name="tenantId"></p>
|
|
||||||
<input type="submit" value="Continue">
|
|
||||||
</form>
|
|
||||||
</body>
|
|
||||||
</html>
|
|
||||||
<?php
|
|
||||||
exit;
|
|
||||||
}
|
|
||||||
|
|
||||||
require 'vendor/autoload.php';
|
|
||||||
|
|
||||||
session_start();
|
|
||||||
|
|
||||||
$providerName = '';
|
|
||||||
$clientId = '';
|
|
||||||
$clientSecret = '';
|
|
||||||
$tenantId = '';
|
|
||||||
|
|
||||||
if (array_key_exists('provider', $_POST)) {
|
|
||||||
$providerName = $_POST['provider'];
|
|
||||||
$clientId = $_POST['clientId'];
|
|
||||||
$clientSecret = $_POST['clientSecret'];
|
|
||||||
$tenantId = $_POST['tenantId'];
|
|
||||||
$_SESSION['provider'] = $providerName;
|
|
||||||
$_SESSION['clientId'] = $clientId;
|
|
||||||
$_SESSION['clientSecret'] = $clientSecret;
|
|
||||||
$_SESSION['tenantId'] = $tenantId;
|
|
||||||
} elseif (array_key_exists('provider', $_SESSION)) {
|
|
||||||
$providerName = $_SESSION['provider'];
|
|
||||||
$clientId = $_SESSION['clientId'];
|
|
||||||
$clientSecret = $_SESSION['clientSecret'];
|
|
||||||
$tenantId = $_SESSION['tenantId'];
|
|
||||||
}
|
|
||||||
|
|
||||||
//If you don't want to use the built-in form, set your client id and secret here
|
|
||||||
//$clientId = 'RANDOMCHARS-----duv1n2.apps.googleusercontent.com';
|
|
||||||
//$clientSecret = 'RANDOMCHARS-----lGyjPcRtvP';
|
|
||||||
|
|
||||||
//If this automatic URL doesn't work, set it yourself manually to the URL of this script
|
|
||||||
$redirectUri = (isset($_SERVER['HTTPS']) ? 'https://' : 'http://') . $_SERVER['HTTP_HOST'] . $_SERVER['PHP_SELF'];
|
|
||||||
//$redirectUri = 'http://localhost/PHPMailer/redirect';
|
|
||||||
|
|
||||||
$params = [
|
|
||||||
'clientId' => $clientId,
|
|
||||||
'clientSecret' => $clientSecret,
|
|
||||||
'redirectUri' => $redirectUri,
|
|
||||||
'accessType' => 'offline'
|
|
||||||
];
|
|
||||||
|
|
||||||
$options = [];
|
|
||||||
$provider = null;
|
|
||||||
|
|
||||||
switch ($providerName) {
|
|
||||||
case 'Google':
|
|
||||||
$provider = new Google($params);
|
|
||||||
$options = [
|
|
||||||
'scope' => [
|
|
||||||
'https://mail.google.com/'
|
|
||||||
]
|
|
||||||
];
|
|
||||||
break;
|
|
||||||
case 'Yahoo':
|
|
||||||
$provider = new Yahoo($params);
|
|
||||||
break;
|
|
||||||
case 'Microsoft':
|
|
||||||
$provider = new Microsoft($params);
|
|
||||||
$options = [
|
|
||||||
'scope' => [
|
|
||||||
'wl.imap',
|
|
||||||
'wl.offline_access'
|
|
||||||
]
|
|
||||||
];
|
|
||||||
break;
|
|
||||||
case 'Azure':
|
|
||||||
$params['tenantId'] = $tenantId;
|
|
||||||
|
|
||||||
$provider = new Azure($params);
|
|
||||||
$options = [
|
|
||||||
'scope' => [
|
|
||||||
'https://outlook.office.com/SMTP.Send',
|
|
||||||
'offline_access'
|
|
||||||
]
|
|
||||||
];
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (null === $provider) {
|
|
||||||
exit('Provider missing');
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!isset($_GET['code'])) {
|
|
||||||
//If we don't have an authorization code then get one
|
|
||||||
$authUrl = $provider->getAuthorizationUrl($options);
|
|
||||||
$_SESSION['oauth2state'] = $provider->getState();
|
|
||||||
header('Location: ' . $authUrl);
|
|
||||||
exit;
|
|
||||||
//Check given state against previously stored one to mitigate CSRF attack
|
|
||||||
} elseif (empty($_GET['state']) || ($_GET['state'] !== $_SESSION['oauth2state'])) {
|
|
||||||
unset($_SESSION['oauth2state']);
|
|
||||||
unset($_SESSION['provider']);
|
|
||||||
exit('Invalid state');
|
|
||||||
} else {
|
|
||||||
unset($_SESSION['provider']);
|
|
||||||
//Try to get an access token (using the authorization code grant)
|
|
||||||
$token = $provider->getAccessToken(
|
|
||||||
'authorization_code',
|
|
||||||
[
|
|
||||||
'code' => $_GET['code']
|
|
||||||
]
|
|
||||||
);
|
|
||||||
//Use this to interact with an API on the users behalf
|
|
||||||
//Use this to get a new access token if the old one expires
|
|
||||||
echo 'Refresh Token: ', $token->getRefreshToken();
|
|
||||||
}
|
|
||||||
@@ -23,7 +23,8 @@ Fortschritt je Meilenstein steht in `docs/m2-technical-foundation.md` bis
|
|||||||
`scripts/migrate.php`.
|
`scripts/migrate.php`.
|
||||||
- `scripts/`: Migrations-, Backfill- und Prüfskripte (Golden Master,
|
- `scripts/`: Migrations-, Backfill- und Prüfskripte (Golden Master,
|
||||||
HTTP-Smoke, M3/M4-Checks).
|
HTTP-Smoke, M3/M4-Checks).
|
||||||
- `docs/`: Planungs- und Meilensteindokumentation.
|
- `docs/`: Planungs- und Meilensteindokumentation. Ausrollen und
|
||||||
|
Inbetriebnahme auf dem Webspace beschreibt `docs/deployment.md`.
|
||||||
|
|
||||||
## Umgang mit Legacy-Seiten
|
## Umgang mit Legacy-Seiten
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,279 @@
|
|||||||
|
# Deployment und Go-Live
|
||||||
|
|
||||||
|
Stand: 2026-08-06
|
||||||
|
|
||||||
|
Dieses Dokument beschreibt, wie die Anwendung auf den Netcup-Webspace
|
||||||
|
(Plesk) ausgerollt und in Betrieb genommen wird. Es ergänzt
|
||||||
|
`docs/betrieb-backup-monitoring.md` (Backup/Monitoring) und
|
||||||
|
`docs/betrieb-mail.md` (Mailversand).
|
||||||
|
|
||||||
|
## Umgebungen
|
||||||
|
|
||||||
|
| Umgebung | Host | Webroot | Zweck |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| Staging | `testumgebung.kaffeeliste.de` | `/testumgebung.kaffeeliste.de/httpdocs/` | Vollständiger Durchlauf vor jedem Produktiv-Deploy |
|
||||||
|
| Produktion | `app.kaffeeliste.de` (App) + `kaffeeliste.de` (Marketing) | noch einzurichten | Echtbetrieb |
|
||||||
|
|
||||||
|
Beide Umgebungen brauchen **eigene Datenbanken** und **eigene**
|
||||||
|
`env.local.php`. Die Staging-Umgebung läuft mit Stripe-Testkeys, die
|
||||||
|
Produktion mit Live-Keys.
|
||||||
|
|
||||||
|
### Host-Split beachten
|
||||||
|
|
||||||
|
`index.php` prüft den Request-Host gegen `APP_HOST`: stimmt er nicht
|
||||||
|
überein, wird statt des Dashboards die Landingpage ausgeliefert. Auf
|
||||||
|
Staging muss deshalb `APP_HOST=testumgebung.kaffeeliste.de` gesetzt sein,
|
||||||
|
sonst kommt man nie ins Dashboard.
|
||||||
|
|
||||||
|
In Produktion zeigen beide Vhosts (`kaffeeliste.de` und
|
||||||
|
`app.kaffeeliste.de`) auf dasselbe Webroot; `APP_HOST=app.kaffeeliste.de`
|
||||||
|
sorgt dann automatisch dafür, dass die Marketing-Domain die Landingpage
|
||||||
|
und die App-Domain das Dashboard zeigt.
|
||||||
|
|
||||||
|
## Was deployt wird — und was nicht
|
||||||
|
|
||||||
|
Der Upload läuft über den FTP-Sync (`sync_config.jsonc`, Umgebung
|
||||||
|
`netcup`). Die Ausschlussliste dort ist sicherheitsrelevant und darf nicht
|
||||||
|
geleert werden:
|
||||||
|
|
||||||
|
Nicht ausliefern: `.git`, `.gitignore`, `.claude`, `.local`, `.vscode`,
|
||||||
|
`.env.local`, `env.local.php`, `sync_config.jsonc`, `var/`, `docs/`,
|
||||||
|
`README.md`.
|
||||||
|
|
||||||
|
- `.git` wäre sonst komplett herunterladbar (kompletter Quellcode plus
|
||||||
|
Historie).
|
||||||
|
- `.env.local` enthält die Zugangsdaten der Entwicklungsdatenbank.
|
||||||
|
- `sync_config.jsonc` enthält das FTP-Passwort im Klartext.
|
||||||
|
- `var/` ist Laufzeitzustand des Servers (Sessions, Uploads) und würde
|
||||||
|
vom lokalen Stand überschrieben.
|
||||||
|
|
||||||
|
`scripts/` und `database/` **werden** mit ausgeliefert — die
|
||||||
|
Plesk-Scheduled-Tasks führen sie vom Webspace aus. Per URL sind sie durch
|
||||||
|
die `.htaccess` gesperrt.
|
||||||
|
|
||||||
|
Zusätzlich sperrt die `.htaccess` `var|database|scripts|docs|app|lib`,
|
||||||
|
die Vendor-Verzeichnisse `TCPDF|PHPMailer|DataTables`, Dotfile-Ordner
|
||||||
|
sowie Konfigurationsdateien und `.sql`/`.md`/`.jsonc`/`.sh`/`.log`-Dateien.
|
||||||
|
Sie erzwingt außerdem HTTPS — ohne Redirect käme ein Nutzer per `http` an
|
||||||
|
und bekäme eine Session-Cookie ohne `secure`-Flag.
|
||||||
|
|
||||||
|
## Erstinbetriebnahme einer Umgebung
|
||||||
|
|
||||||
|
### 1. Hosting-Voraussetzungen prüfen
|
||||||
|
|
||||||
|
In Plesk unter *PHP-Einstellungen* bzw. über eine temporäre
|
||||||
|
`phpinfo()`-Datei kontrollieren:
|
||||||
|
|
||||||
|
- PHP ≥ 8.1
|
||||||
|
- Extensions: `pdo_mysql`, `fileinfo` (CSV-Upload), `openssl`, `imap`
|
||||||
|
(nur für den PayPal-Mailabruf nötig)
|
||||||
|
- **`allow_url_fopen = On`** — `app/stripe.php` und `app/dolibarr.php`
|
||||||
|
sprechen ihre APIs bewusst über PHP-Streams statt cURL an und fallen
|
||||||
|
ohne diese Einstellung aus
|
||||||
|
- `display_errors = Off`, `log_errors = On` (siehe
|
||||||
|
`docs/betrieb-backup-monitoring.md`)
|
||||||
|
- Let's-Encrypt-Zertifikat für den Host ausgestellt
|
||||||
|
|
||||||
|
Die temporäre `phpinfo()`-Datei danach wieder löschen.
|
||||||
|
|
||||||
|
### 2. Datenbank anlegen
|
||||||
|
|
||||||
|
In Plesk eine leere MySQL-Datenbank samt eigenem Benutzer anlegen. Die
|
||||||
|
Zugangsdaten werden gleich in `env.local.php` eingetragen.
|
||||||
|
|
||||||
|
Die vorhandene Entwicklungsdatenbank **nicht** übernehmen: sie enthält
|
||||||
|
ausschließlich Testdaten inklusive des migrierten Default-Mandanten aus
|
||||||
|
der Legacy-App.
|
||||||
|
|
||||||
|
### 3. Dateien hochladen
|
||||||
|
|
||||||
|
FTP-Sync ausführen. Danach prüfen, dass folgende URLs **403/404** liefern
|
||||||
|
und nicht etwa Inhalt:
|
||||||
|
|
||||||
|
```
|
||||||
|
https://<host>/sync_config.jsonc
|
||||||
|
https://<host>/.env.local
|
||||||
|
https://<host>/.git/config
|
||||||
|
https://<host>/scripts/migrate.php
|
||||||
|
https://<host>/docs/deployment.md
|
||||||
|
https://<host>/app/bootstrap.php
|
||||||
|
```
|
||||||
|
|
||||||
|
Liefert eine davon Inhalt, greift die `.htaccess` nicht (z. B. weil
|
||||||
|
`AllowOverride` deaktiviert ist) — dann erst weitermachen, wenn das
|
||||||
|
geklärt ist.
|
||||||
|
|
||||||
|
### 4. `env.local.php` anlegen
|
||||||
|
|
||||||
|
`env.local.example.php` als Vorlage nehmen, ausfüllen und **direkt per
|
||||||
|
FTP** als `env.local.php` ins Webroot legen. Die Datei ist bewusst nicht
|
||||||
|
im Repository und wird nicht mit deployt, damit ein Deploy sie nie
|
||||||
|
überschreibt.
|
||||||
|
|
||||||
|
Für Staging mindestens:
|
||||||
|
|
||||||
|
```php
|
||||||
|
putenv('APP_ENV=prod'); // 'dev' würde Mails nur ins Log schreiben
|
||||||
|
putenv('APP_HOST=testumgebung.kaffeeliste.de');
|
||||||
|
putenv('APP_TIMEZONE=Europe/Berlin');
|
||||||
|
putenv('APP_DB_DRIVER=mysql');
|
||||||
|
putenv('DB_HOST=localhost');
|
||||||
|
putenv('DB_NAME=…'); putenv('DB_USER=…'); putenv('DB_PASS=…');
|
||||||
|
putenv('APP_SESSION_PATH=' . __DIR__ . '/var/sessions');
|
||||||
|
putenv('APP_MAIL_TRANSPORT=mail');
|
||||||
|
putenv('APP_MAIL_FROM=noreply@kaffeeliste.de');
|
||||||
|
```
|
||||||
|
|
||||||
|
Stripe-, Dolibarr- und IMAP-Werte je Umgebung ergänzen (siehe unten).
|
||||||
|
|
||||||
|
### 5. Schreibrechte für `var/`
|
||||||
|
|
||||||
|
`app_start_session()` legt `var/sessions` bei Bedarf selbst an, braucht
|
||||||
|
dafür aber Schreibrechte im Webroot. Nach dem ersten Aufruf prüfen, dass
|
||||||
|
`var/sessions` existiert und beschreibbar ist; ebenso `var/uploads` für
|
||||||
|
den CSV-Import. Beide sind per `.htaccess` von außen gesperrt.
|
||||||
|
|
||||||
|
### 6. Migrationen einspielen
|
||||||
|
|
||||||
|
Es gibt 24 versionierte Migrationen in `database/migrations/`, angewendet
|
||||||
|
über `scripts/migrate.php`. Das Skript ist idempotent und wendet nur
|
||||||
|
fehlende Migrationen an.
|
||||||
|
|
||||||
|
Ohne SSH-Zugang läuft das über **Plesk → Geplante Aufgaben (Scheduled
|
||||||
|
Tasks)** als einmalig ausgeführter Task vom Typ *PHP-Skript ausführen*:
|
||||||
|
|
||||||
|
```
|
||||||
|
Skriptpfad: /httpdocs/scripts/migrate.php
|
||||||
|
```
|
||||||
|
|
||||||
|
Der Task muss nach dem Ausführen wieder deaktiviert oder gelöscht werden.
|
||||||
|
Die Ausgabe (`Applied migration: …` bzw. `No new migrations.`) lässt sich
|
||||||
|
per E-Mail-Benachrichtigung des Tasks kontrollieren.
|
||||||
|
|
||||||
|
Alternative ohne Scheduled Task: die Migrationsdateien der Reihe nach in
|
||||||
|
phpMyAdmin importieren — dann fehlt allerdings der Eintrag in der
|
||||||
|
Versionstabelle, den `migrate.php` pflegt. Der Scheduled-Task-Weg ist
|
||||||
|
deutlich vorzuziehen.
|
||||||
|
|
||||||
|
**Nach jedem Deploy mit neuen Migrationen wiederholen.**
|
||||||
|
|
||||||
|
### 7. Ersten Mandanten anlegen
|
||||||
|
|
||||||
|
Über `register.php` auf dem konfigurierten Host registrieren. Für
|
||||||
|
Plattform-Administrationsrechte (Back-Office über alle Mandanten hinweg)
|
||||||
|
anschließend `scripts/grant-platform-admin.php` als einmaligen
|
||||||
|
Plesk-Task ausführen.
|
||||||
|
|
||||||
|
## Wiederkehrende Aufgaben (Plesk Scheduled Tasks)
|
||||||
|
|
||||||
|
Ohne diese Tasks fehlen Zahlungserinnerungen, die automatische
|
||||||
|
PayPal-Verbuchung und — kritisch — die Backups.
|
||||||
|
|
||||||
|
| Task | Skript / Befehl | Empfohlener Takt |
|
||||||
|
| --- | --- | --- |
|
||||||
|
| Zahlungserinnerungen | `/httpdocs/scripts/send-payment-reminders.php` | täglich, z. B. 07:00 |
|
||||||
|
| PayPal-Mailabruf | `/httpdocs/scripts/fetch-paypal-payments.php` | alle 15–30 Minuten |
|
||||||
|
| Datenbank-Backup | Shell-Befehl, siehe `docs/betrieb-backup-monitoring.md` | täglich nachts |
|
||||||
|
|
||||||
|
Zum Backup-Task: Das Zielverzeichnis muss **außerhalb** von `httpdocs`
|
||||||
|
liegen (z. B. `/backups` auf Vhost-Ebene), sonst wären die Dumps
|
||||||
|
öffentlich abrufbar. Zusätzlich mindestens eine Kopie an einen anderen
|
||||||
|
Ort übertragen — ein Backup, das nur auf demselben Webspace liegt,
|
||||||
|
schützt nicht gegen den Ausfall des Anbieters.
|
||||||
|
|
||||||
|
Vor der Scharfschaltung beide PHP-Tasks einmal manuell auslösen.
|
||||||
|
`send-payment-reminders.php` unterstützt dafür `--dry-run`.
|
||||||
|
|
||||||
|
## Mailversand und DNS
|
||||||
|
|
||||||
|
Der Versand läuft über PHPs `mail()` (`APP_MAIL_TRANSPORT=mail`, siehe
|
||||||
|
`docs/betrieb-mail.md`). Das betrifft Registrierungsbestätigung,
|
||||||
|
E-Mail-Verifikation, Passwort-Reset, Mitglieder-Einladungen,
|
||||||
|
Zahlungserinnerungen und den Massenmailversand — also den kompletten
|
||||||
|
Onboarding-Pfad.
|
||||||
|
|
||||||
|
Vor Go-Live für die Absenderdomain einrichten und prüfen:
|
||||||
|
|
||||||
|
- **SPF**-Eintrag, der den Mailserver des Webspace autorisiert
|
||||||
|
- **DKIM**-Signierung (in Plesk pro Domain aktivierbar)
|
||||||
|
- **DMARC**-Eintrag
|
||||||
|
- `APP_MAIL_FROM` auf eine echte Adresse der eigenen Domain setzen —
|
||||||
|
eine fremde Absenderdomain bricht SPF/DKIM
|
||||||
|
|
||||||
|
Testen mit einer Registrierung auf eine externe Adresse (Gmail/Outlook)
|
||||||
|
und Kontrolle, ob die Mail im Posteingang statt im Spam landet.
|
||||||
|
Fehlversuche stehen in der Tabelle `outbound_emails` mit
|
||||||
|
`status = 'failed'`.
|
||||||
|
|
||||||
|
## Stripe und Dolibarr
|
||||||
|
|
||||||
|
Details zur Funktionsweise stehen in `docs/billing.md`. Für den Go-Live:
|
||||||
|
|
||||||
|
1. **Staging** mit Stripe-**Test**-Keys betreiben und den kompletten
|
||||||
|
Ablauf einmal durchspielen: Checkout, Upgrade, Downgrade, Kündigung,
|
||||||
|
Customer Portal.
|
||||||
|
2. Webhook-Endpunkt im Stripe-Dashboard auf
|
||||||
|
`https://<host>/stripe-webhook.php` registrieren (je Umgebung einen
|
||||||
|
eigenen) und das dort erzeugte Signing Secret als
|
||||||
|
`STRIPE_WEBHOOK_SECRET` eintragen. Ohne gültiges Secret weist
|
||||||
|
`stripe-webhook.php` alle Ereignisse ab.
|
||||||
|
3. Für Produktion auf **Live**-Keys wechseln und den Webhook erneut
|
||||||
|
registrieren — Test- und Live-Modus haben getrennte Webhooks und
|
||||||
|
getrennte Secrets.
|
||||||
|
4. Dolibarr: `DOLIBARR_URL` und `DOLIBARR_API_KEY` eintragen. Achtung,
|
||||||
|
das ist die **produktive** Buchhaltungsinstanz des Kunden, es gibt
|
||||||
|
keine Sandbox. Der `validate()`-Aufruf beim Rechnungsabschluss ist
|
||||||
|
laut `docs/billing.md` bewusst nie live getestet worden — der erste
|
||||||
|
echte Zahlungseingang ist dessen erster Test. Danach in Dolibarr
|
||||||
|
kontrollieren, ob die Rechnung korrekt angelegt und validiert wurde.
|
||||||
|
|
||||||
|
## PayPal-Postfach
|
||||||
|
|
||||||
|
Für die automatische Verbuchung weitergeleiteter PayPal-Zahlungsmails
|
||||||
|
muss das Postfach aus `PAYPAL_INBOX_BASE` (Vorgabe
|
||||||
|
`zahlungen@kaffeeliste.de`) existieren und **Plus-Adressierung an
|
||||||
|
dieselbe Mailbox zustellen** (Catch-All), damit die pro Mandant
|
||||||
|
generierten Adressen `zahlungen+<token>@…` ankommen. IMAP-Zugangsdaten in
|
||||||
|
`env.local.php` eintragen und die `imap`-Extension auf dem Host prüfen.
|
||||||
|
|
||||||
|
## Deploy-Ablauf für ein Update
|
||||||
|
|
||||||
|
1. Lokal committen und pushen.
|
||||||
|
2. FTP-Sync ausführen (Ausschlussliste greift automatisch).
|
||||||
|
3. Falls neue Migrationen dabei sind: Migrations-Task in Plesk einmal
|
||||||
|
auslösen.
|
||||||
|
4. Stichprobe: Login, Dashboard, eine Strich-Buchung, PDF-Export.
|
||||||
|
|
||||||
|
Ein echtes Rollback gibt es nicht; im Fehlerfall wird der vorherige
|
||||||
|
Commit-Stand erneut hochgeladen. Migrationen sind nicht rückwärts
|
||||||
|
lauffähig — vor einem Deploy mit Schemaänderungen daher immer ein
|
||||||
|
frisches Backup ziehen.
|
||||||
|
|
||||||
|
## Go-Live-Checkliste
|
||||||
|
|
||||||
|
Vor der Umstellung auf `app.kaffeeliste.de`:
|
||||||
|
|
||||||
|
- [ ] Kompletter Funktionsdurchlauf auf Staging erfolgreich
|
||||||
|
(Registrierung, Mailversand, Mitglieder, Striche, Einzahlungen,
|
||||||
|
CSV-Import, PDF-Export, Jahresauswertung, Stripe im Testmodus)
|
||||||
|
- [ ] Die sechs Abruf-Tests aus Schritt 3 liefern alle 403/404
|
||||||
|
- [ ] `display_errors` produktiv aus, `log_errors` an
|
||||||
|
- [ ] SPF/DKIM/DMARC gesetzt, Testmail landet nicht im Spam
|
||||||
|
- [ ] Backup-Task läuft und ein Restore wurde einmal testweise
|
||||||
|
eingespielt (`docs/betrieb-backup-monitoring.md`)
|
||||||
|
- [ ] Stripe-Live-Keys und Produktiv-Webhook eingetragen
|
||||||
|
- [ ] Impressum, AGB und Datenschutzerklärung inhaltlich freigegeben
|
||||||
|
- [ ] Auftragsverarbeitungsvertrag (AVV) für Kunden vorbereitet
|
||||||
|
- [ ] Frische Produktivdatenbank ohne Testdaten
|
||||||
|
|
||||||
|
## Bewusst offen
|
||||||
|
|
||||||
|
- **Content-Security-Policy**: nicht gesetzt, weil die Templates
|
||||||
|
durchgängig Inline-Styles nutzen. Begründung und Umfang in
|
||||||
|
`docs/m8-haertung.md`.
|
||||||
|
- **Automatisiertes Deployment** (CI/CD, Build-Schritt): nicht
|
||||||
|
eingerichtet. Bei einer flachen PHP-App ohne Build-Prozess und einem
|
||||||
|
einzelnen Deployer ist der FTP-Sync angemessen.
|
||||||
|
- **`DataTables/` und `js/`**: liegen im Repo, werden aber von keiner
|
||||||
|
Seite mehr eingebunden. Sie sind per `.htaccess` gesperrt und können
|
||||||
|
bei Gelegenheit entfernt werden.
|
||||||
Reference in New Issue
Block a user