Allow * (Wildcard) Domains to be used

This commit is contained in:
Thyke Adams 2021-05-08 19:34:28 -04:00
parent ba45705571
commit e67d9de6dc

View file

@ -1,369 +1,371 @@
const Mn = require('backbone.marionette'); const Mn = require("backbone.marionette");
const App = require('../../main'); const App = require("../../main");
const ProxyHostModel = require('../../../models/proxy-host'); const ProxyHostModel = require("../../../models/proxy-host");
const ProxyLocationModel = require('../../../models/proxy-host-location'); const ProxyLocationModel = require("../../../models/proxy-host-location");
const template = require('./form.ejs'); const template = require("./form.ejs");
const certListItemTemplate = require('../certificates-list-item.ejs'); const certListItemTemplate = require("../certificates-list-item.ejs");
const accessListItemTemplate = require('./access-list-item.ejs'); const accessListItemTemplate = require("./access-list-item.ejs");
const CustomLocation = require('./location'); const CustomLocation = require("./location");
const Helpers = require('../../../lib/helpers'); const Helpers = require("../../../lib/helpers");
const i18n = require('../../i18n'); const i18n = require("../../i18n");
const dns_providers = require('../../../../../global/certbot-dns-plugins'); const dns_providers = require("../../../../../global/certbot-dns-plugins");
require("jquery-serializejson");
require('jquery-serializejson'); require("selectize");
require('selectize');
module.exports = Mn.View.extend({ module.exports = Mn.View.extend({
template: template, template: template,
className: 'modal-dialog', className: "modal-dialog",
locationsCollection: new ProxyLocationModel.Collection(), locationsCollection: new ProxyLocationModel.Collection(),
ui: { ui: {
form: 'form', form: "form",
domain_names: 'input[name="domain_names"]', domain_names: 'input[name="domain_names"]',
forward_host: 'input[name="forward_host"]', forward_host: 'input[name="forward_host"]',
buttons: '.modal-footer button', buttons: ".modal-footer button",
cancel: 'button.cancel', cancel: "button.cancel",
save: 'button.save', save: "button.save",
add_location_btn: 'button.add_location', add_location_btn: "button.add_location",
locations_container: '.locations_container', locations_container: ".locations_container",
le_error_info: '#le-error-info', le_error_info: "#le-error-info",
certificate_select: 'select[name="certificate_id"]', certificate_select: 'select[name="certificate_id"]',
access_list_select: 'select[name="access_list_id"]', access_list_select: 'select[name="access_list_id"]',
ssl_forced: 'input[name="ssl_forced"]', ssl_forced: 'input[name="ssl_forced"]',
hsts_enabled: 'input[name="hsts_enabled"]', hsts_enabled: 'input[name="hsts_enabled"]',
hsts_subdomains: 'input[name="hsts_subdomains"]', hsts_subdomains: 'input[name="hsts_subdomains"]',
http2_support: 'input[name="http2_support"]', http2_support: 'input[name="http2_support"]',
dns_challenge_switch: 'input[name="meta[dns_challenge]"]', dns_challenge_switch: 'input[name="meta[dns_challenge]"]',
dns_challenge_content: '.dns-challenge', dns_challenge_content: ".dns-challenge",
dns_provider: 'select[name="meta[dns_provider]"]', dns_provider: 'select[name="meta[dns_provider]"]',
credentials_file_content: '.credentials-file-content', credentials_file_content: ".credentials-file-content",
dns_provider_credentials: 'textarea[name="meta[dns_provider_credentials]"]', dns_provider_credentials: 'textarea[name="meta[dns_provider_credentials]"]',
propagation_seconds: 'input[name="meta[propagation_seconds]"]', propagation_seconds: 'input[name="meta[propagation_seconds]"]',
forward_scheme: 'select[name="forward_scheme"]', forward_scheme: 'select[name="forward_scheme"]',
letsencrypt: '.letsencrypt' letsencrypt: ".letsencrypt"
}, },
regions: { regions: {
locations_regions: '@ui.locations_container' locations_regions: "@ui.locations_container"
}, },
events: { events: {
'change @ui.certificate_select': function () { "change @ui.certificate_select": function () {
let id = this.ui.certificate_select.val(); let id = this.ui.certificate_select.val();
if (id === 'new') { if (id === "new") {
this.ui.letsencrypt.show().find('input').prop('disabled', false); this.ui.letsencrypt.show().find("input").prop("disabled", false);
this.ui.dns_challenge_content.hide(); this.ui.dns_challenge_content.hide();
} else { } else {
this.ui.letsencrypt.hide().find('input').prop('disabled', true); this.ui.letsencrypt.hide().find("input").prop("disabled", true);
} }
let enabled = id === 'new' || parseInt(id, 10) > 0; let enabled = id === "new" || parseInt(id, 10) > 0;
let inputs = this.ui.ssl_forced.add(this.ui.http2_support); let inputs = this.ui.ssl_forced.add(this.ui.http2_support);
inputs inputs
.prop('disabled', !enabled) .prop("disabled", !enabled)
.parents('.form-group') .parents(".form-group")
.css('opacity', enabled ? 1 : 0.5); .css("opacity", enabled ? 1 : 0.5);
if (!enabled) { if (!enabled) {
inputs.prop('checked', false); inputs.prop("checked", false);
} }
inputs.trigger('change'); inputs.trigger("change");
}, },
'change @ui.ssl_forced': function () { "change @ui.ssl_forced": function () {
let checked = this.ui.ssl_forced.prop('checked'); let checked = this.ui.ssl_forced.prop("checked");
this.ui.hsts_enabled this.ui.hsts_enabled
.prop('disabled', !checked) .prop("disabled", !checked)
.parents('.form-group') .parents(".form-group")
.css('opacity', checked ? 1 : 0.5); .css("opacity", checked ? 1 : 0.5);
if (!checked) { if (!checked) {
this.ui.hsts_enabled.prop('checked', false); this.ui.hsts_enabled.prop("checked", false);
} }
this.ui.hsts_enabled.trigger('change'); this.ui.hsts_enabled.trigger("change");
}, },
'change @ui.hsts_enabled': function () { "change @ui.hsts_enabled": function () {
let checked = this.ui.hsts_enabled.prop('checked'); let checked = this.ui.hsts_enabled.prop("checked");
this.ui.hsts_subdomains this.ui.hsts_subdomains
.prop('disabled', !checked) .prop("disabled", !checked)
.parents('.form-group') .parents(".form-group")
.css('opacity', checked ? 1 : 0.5); .css("opacity", checked ? 1 : 0.5);
if (!checked) { if (!checked) {
this.ui.hsts_subdomains.prop('checked', false); this.ui.hsts_subdomains.prop("checked", false);
} }
}, },
'change @ui.dns_challenge_switch': function () { "change @ui.dns_challenge_switch": function () {
const checked = this.ui.dns_challenge_switch.prop('checked'); const checked = this.ui.dns_challenge_switch.prop("checked");
if (checked) { if (checked) {
this.ui.dns_provider.prop('required', 'required'); this.ui.dns_provider.prop("required", "required");
const selected_provider = this.ui.dns_provider[0].options[this.ui.dns_provider[0].selectedIndex].value; const selected_provider = this.ui.dns_provider[0].options[this.ui.dns_provider[0].selectedIndex].value;
if(selected_provider != '' && dns_providers[selected_provider].credentials !== false){ if (selected_provider != "" && dns_providers[selected_provider].credentials !== false) {
this.ui.dns_provider_credentials.prop('required', 'required'); this.ui.dns_provider_credentials.prop("required", "required");
} }
this.ui.dns_challenge_content.show(); this.ui.dns_challenge_content.show();
} else { } else {
this.ui.dns_provider.prop('required', false); this.ui.dns_provider.prop("required", false);
this.ui.dns_provider_credentials.prop('required', false); this.ui.dns_provider_credentials.prop("required", false);
this.ui.dns_challenge_content.hide(); this.ui.dns_challenge_content.hide();
} }
}, },
'change @ui.dns_provider': function () { "change @ui.dns_provider": function () {
const selected_provider = this.ui.dns_provider[0].options[this.ui.dns_provider[0].selectedIndex].value; const selected_provider = this.ui.dns_provider[0].options[this.ui.dns_provider[0].selectedIndex].value;
if (selected_provider != '' && dns_providers[selected_provider].credentials !== false) { if (selected_provider != "" && dns_providers[selected_provider].credentials !== false) {
this.ui.dns_provider_credentials.prop('required', 'required'); this.ui.dns_provider_credentials.prop("required", "required");
this.ui.dns_provider_credentials[0].value = dns_providers[selected_provider].credentials; this.ui.dns_provider_credentials[0].value = dns_providers[selected_provider].credentials;
this.ui.credentials_file_content.show(); this.ui.credentials_file_content.show();
} else { } else {
this.ui.dns_provider_credentials.prop('required', false); this.ui.dns_provider_credentials.prop("required", false);
this.ui.credentials_file_content.hide(); this.ui.credentials_file_content.hide();
} }
}, },
'click @ui.add_location_btn': function (e) { "click @ui.add_location_btn": function (e) {
e.preventDefault(); e.preventDefault();
const model = new ProxyLocationModel.Model();
this.locationsCollection.add(model);
},
'click @ui.save': function (e) { const model = new ProxyLocationModel.Model();
e.preventDefault(); this.locationsCollection.add(model);
this.ui.le_error_info.hide(); },
if (!this.ui.form[0].checkValidity()) { "click @ui.save": function (e) {
$('<input type="submit">').hide().appendTo(this.ui.form).click().remove(); e.preventDefault();
return; this.ui.le_error_info.hide();
}
let view = this; if (!this.ui.form[0].checkValidity()) {
let data = this.ui.form.serializeJSON(); $('<input type="submit">').hide().appendTo(this.ui.form).click().remove();
return;
}
// Add locations let view = this;
data.locations = []; let data = this.ui.form.serializeJSON();
this.locationsCollection.models.forEach((location) => {
data.locations.push(location.toJSON());
});
// Serialize collects path from custom locations // Add locations
// This field must be removed from root object data.locations = [];
delete data.path; this.locationsCollection.models.forEach((location) => {
data.locations.push(location.toJSON());
});
// Manipulate // Serialize collects path from custom locations
data.forward_port = parseInt(data.forward_port, 10); // This field must be removed from root object
data.block_exploits = !!data.block_exploits; delete data.path;
data.caching_enabled = !!data.caching_enabled;
data.allow_websocket_upgrade = !!data.allow_websocket_upgrade;
data.http2_support = !!data.http2_support;
data.hsts_enabled = !!data.hsts_enabled;
data.hsts_subdomains = !!data.hsts_subdomains;
data.ssl_forced = !!data.ssl_forced;
if (typeof data.meta === 'undefined') data.meta = {};
data.meta.letsencrypt_agree = data.meta.letsencrypt_agree == 1;
data.meta.dns_challenge = data.meta.dns_challenge == 1;
if(!data.meta.dns_challenge){
data.meta.dns_provider = undefined;
data.meta.dns_provider_credentials = undefined;
data.meta.propagation_seconds = undefined;
} else {
if(data.meta.propagation_seconds === '') data.meta.propagation_seconds = undefined;
}
if (typeof data.domain_names === 'string' && data.domain_names) { // Manipulate
data.domain_names = data.domain_names.split(','); data.forward_port = parseInt(data.forward_port, 10);
} data.block_exploits = !!data.block_exploits;
data.caching_enabled = !!data.caching_enabled;
data.allow_websocket_upgrade = !!data.allow_websocket_upgrade;
data.http2_support = !!data.http2_support;
data.hsts_enabled = !!data.hsts_enabled;
data.hsts_subdomains = !!data.hsts_subdomains;
data.ssl_forced = !!data.ssl_forced;
// Check for any domain names containing wildcards, which are not allowed with letsencrypt if (typeof data.meta === "undefined") data.meta = {};
if (data.certificate_id === 'new') { data.meta.letsencrypt_agree = data.meta.letsencrypt_agree == 1;
let domain_err = false; data.meta.dns_challenge = data.meta.dns_challenge == 1;
if (!data.meta.dns_challenge) {
data.domain_names.map(function (name) {
if (name.match(/\*/im)) {
domain_err = true;
}
});
}
if (domain_err) { if (!data.meta.dns_challenge) {
alert(i18n('ssl', 'no-wildcard-without-dns')); data.meta.dns_provider = undefined;
return; data.meta.dns_provider_credentials = undefined;
} data.meta.propagation_seconds = undefined;
} else { } else {
data.certificate_id = parseInt(data.certificate_id, 10); if (data.meta.propagation_seconds === "") data.meta.propagation_seconds = undefined;
} }
let method = App.Api.Nginx.ProxyHosts.create; if (typeof data.domain_names === "string" && data.domain_names) {
let is_new = true; data.domain_names = data.domain_names.split(",");
}
if (this.model.get('id')) { // Check for any domain names containing wildcards, which are not allowed with letsencrypt
// edit if (data.certificate_id === "new") {
is_new = false; let domain_err = false;
method = App.Api.Nginx.ProxyHosts.update; if (!data.meta.dns_challenge) {
data.id = this.model.get('id'); data.domain_names.map(function (name) {
} if (name.match(/\*/im)) {
domain_err = true;
}
});
}
this.ui.buttons.prop('disabled', true).addClass('btn-disabled'); if (domain_err) {
this.ui.save.addClass('btn-loading'); alert(i18n("ssl", "no-wildcard-without-dns"));
return;
}
} else {
data.certificate_id = parseInt(data.certificate_id, 10);
}
method(data) let method = App.Api.Nginx.ProxyHosts.create;
.then(result => { let is_new = true;
view.model.set(result);
App.UI.closeModal(function () { if (this.model.get("id")) {
if (is_new) { // edit
App.Controller.showNginxProxy(); is_new = false;
} method = App.Api.Nginx.ProxyHosts.update;
}); data.id = this.model.get("id");
}) }
.catch(err => {
let more_info = '';
if(err.code === 500 && err.debug){
try{
more_info = JSON.parse(err.debug).debug.stack.join("\n");
} catch(e) {}
}
this.ui.le_error_info[0].innerHTML = `${err.message}${more_info !== '' ? `<pre class="mt-3">${more_info}</pre>`:''}`;
this.ui.le_error_info.show();
this.ui.le_error_info[0].scrollIntoView();
this.ui.buttons.prop('disabled', false).removeClass('btn-disabled');
this.ui.save.removeClass('btn-loading');
});
}
},
templateContext: { this.ui.buttons.prop("disabled", true).addClass("btn-disabled");
getLetsencryptEmail: function () { this.ui.save.addClass("btn-loading");
return App.Cache.User.get('email');
},
getUseDnsChallenge: function () {
return typeof this.meta.dns_challenge !== 'undefined' ? this.meta.dns_challenge : false;
},
getDnsProvider: function () {
return typeof this.meta.dns_provider !== 'undefined' && this.meta.dns_provider != '' ? this.meta.dns_provider : null;
},
getDnsProviderCredentials: function () {
return typeof this.meta.dns_provider_credentials !== 'undefined' ? this.meta.dns_provider_credentials : '';
},
getPropagationSeconds: function () {
return typeof this.meta.propagation_seconds !== 'undefined' ? this.meta.propagation_seconds : '';
},
dns_plugins: dns_providers,
},
onRender: function () { method(data)
let view = this; .then((result) => {
view.model.set(result);
this.ui.ssl_forced.trigger('change'); App.UI.closeModal(function () {
this.ui.hsts_enabled.trigger('change'); if (is_new) {
App.Controller.showNginxProxy();
}
});
})
.catch((err) => {
let more_info = "";
if (err.code === 500 && err.debug) {
try {
more_info = JSON.parse(err.debug).debug.stack.join("\n");
} catch (e) {}
}
this.ui.le_error_info[0].innerHTML = `${err.message}${more_info !== "" ? `<pre class="mt-3">${more_info}</pre>` : ""}`;
this.ui.le_error_info.show();
this.ui.le_error_info[0].scrollIntoView();
this.ui.buttons.prop("disabled", false).removeClass("btn-disabled");
this.ui.save.removeClass("btn-loading");
});
}
},
// Domain names templateContext: {
this.ui.domain_names.selectize({ getLetsencryptEmail: function () {
delimiter: ',', return App.Cache.User.get("email");
persist: false, },
maxOptions: 15, getUseDnsChallenge: function () {
create: function (input) { return typeof this.meta.dns_challenge !== "undefined" ? this.meta.dns_challenge : false;
return { },
value: input, getDnsProvider: function () {
text: input return typeof this.meta.dns_provider !== "undefined" && this.meta.dns_provider != "" ? this.meta.dns_provider : null;
}; },
}, getDnsProviderCredentials: function () {
createFilter: /^(?:\.)?(?:[^.*]+\.?)+[^.]$/ return typeof this.meta.dns_provider_credentials !== "undefined" ? this.meta.dns_provider_credentials : "";
}); },
getPropagationSeconds: function () {
return typeof this.meta.propagation_seconds !== "undefined" ? this.meta.propagation_seconds : "";
},
dns_plugins: dns_providers
},
// Access Lists onRender: function () {
this.ui.access_list_select.selectize({ let view = this;
valueField: 'id',
labelField: 'name',
searchField: ['name'],
create: false,
preload: true,
allowEmptyOption: true,
render: {
option: function (item) {
item.i18n = App.i18n;
item.formatDbDate = Helpers.formatDbDate;
return accessListItemTemplate(item);
}
},
load: function (query, callback) {
App.Api.Nginx.AccessLists.getAll(['items', 'clients'])
.then(rows => {
callback(rows);
})
.catch(err => {
console.error(err);
callback();
});
},
onLoad: function () {
view.ui.access_list_select[0].selectize.setValue(view.model.get('access_list_id'));
}
});
// Certificates this.ui.ssl_forced.trigger("change");
this.ui.le_error_info.hide(); this.ui.hsts_enabled.trigger("change");
this.ui.dns_challenge_content.hide();
this.ui.credentials_file_content.hide();
this.ui.letsencrypt.hide();
this.ui.certificate_select.selectize({
valueField: 'id',
labelField: 'nice_name',
searchField: ['nice_name', 'domain_names'],
create: false,
preload: true,
allowEmptyOption: true,
render: {
option: function (item) {
item.i18n = App.i18n;
item.formatDbDate = Helpers.formatDbDate;
return certListItemTemplate(item);
}
},
load: function (query, callback) {
App.Api.Nginx.Certificates.getAll()
.then(rows => {
callback(rows);
})
.catch(err => {
console.error(err);
callback();
});
},
onLoad: function () {
view.ui.certificate_select[0].selectize.setValue(view.model.get('certificate_id'));
}
});
},
initialize: function (options) { // Domain names
if (typeof options.model === 'undefined' || !options.model) { this.ui.domain_names.selectize({
this.model = new ProxyHostModel.Model(); delimiter: ",",
} persist: false,
maxOptions: 15,
create: function (input) {
return {
value: input,
text: input
};
},
createFilter: /^(?:[^.]+\.?)+[^.]$/
});
this.locationsCollection = new ProxyLocationModel.Collection(); // Access Lists
this.ui.access_list_select.selectize({
valueField: "id",
labelField: "name",
searchField: ["name"],
create: false,
preload: true,
allowEmptyOption: true,
render: {
option: function (item) {
item.i18n = App.i18n;
item.formatDbDate = Helpers.formatDbDate;
return accessListItemTemplate(item);
}
},
load: function (query, callback) {
App.Api.Nginx.AccessLists.getAll(["items", "clients"])
.then((rows) => {
callback(rows);
})
.catch((err) => {
console.error(err);
callback();
});
},
onLoad: function () {
view.ui.access_list_select[0].selectize.setValue(view.model.get("access_list_id"));
}
});
// Custom locations // Certificates
this.showChildView('locations_regions', new CustomLocation.LocationCollectionView({ this.ui.le_error_info.hide();
collection: this.locationsCollection this.ui.dns_challenge_content.hide();
})); this.ui.credentials_file_content.hide();
this.ui.letsencrypt.hide();
this.ui.certificate_select.selectize({
valueField: "id",
labelField: "nice_name",
searchField: ["nice_name", "domain_names"],
create: false,
preload: true,
allowEmptyOption: true,
render: {
option: function (item) {
item.i18n = App.i18n;
item.formatDbDate = Helpers.formatDbDate;
return certListItemTemplate(item);
}
},
load: function (query, callback) {
App.Api.Nginx.Certificates.getAll()
.then((rows) => {
callback(rows);
})
.catch((err) => {
console.error(err);
callback();
});
},
onLoad: function () {
view.ui.certificate_select[0].selectize.setValue(view.model.get("certificate_id"));
}
});
},
// Check wether there are any location defined initialize: function (options) {
if (options.model && Array.isArray(options.model.attributes.locations)) { if (typeof options.model === "undefined" || !options.model) {
options.model.attributes.locations.forEach((location) => { this.model = new ProxyHostModel.Model();
let m = new ProxyLocationModel.Model(location); }
this.locationsCollection.add(m);
}); this.locationsCollection = new ProxyLocationModel.Collection();
}
} // Custom locations
this.showChildView(
"locations_regions",
new CustomLocation.LocationCollectionView({
collection: this.locationsCollection
})
);
// Check wether there are any location defined
if (options.model && Array.isArray(options.model.attributes.locations)) {
options.model.attributes.locations.forEach((location) => {
let m = new ProxyLocationModel.Model(location);
this.locationsCollection.add(m);
});
}
}
}); });