|
|
|
|
81
|
OWNCLOUD_DOWNLOAD="https://download.owncloud.org/community/$OWNCLOUD_ARCHIVE"
|
81
|
OWNCLOUD_DOWNLOAD="https://download.owncloud.org/community/$OWNCLOUD_ARCHIVE"
|
82
|
OWNCLOUD_HASH="ea07124a1b9632aa5227240d655e4d84967fb6dd49e4a16d3207d6179d031a3a"
|
82
|
OWNCLOUD_HASH="ea07124a1b9632aa5227240d655e4d84967fb6dd49e4a16d3207d6179d031a3a"
|
83
|
|
83
|
|
|
|
84
|
+# Domain name or freedns subdomain for your wiki
|
|
|
85
|
+WIKI_FREEDNS_SUBDOMAIN_CODE=
|
|
|
86
|
+WIKI_DOMAIN_NAME=
|
|
|
87
|
+WIKI_ARCHIVE="dokuwiki-stable.tgz"
|
|
|
88
|
+WIKI_DOWNLOAD="http://download.dokuwiki.org/src/dokuwiki/$WIKI_ARCHIVE"
|
|
|
89
|
+WIKI_HASH="a0e79986b87b2744421ce3c33b43a21f296deadd81b1789c25fa4bb095e8e470"
|
|
|
90
|
+# see https://www.dokuwiki.org/template:mnml-blog
|
|
|
91
|
+WIKI_MNML_BLOG_ADDON_ARCHIVE="mnml-blog.tar.gz"
|
|
|
92
|
+WIKI_MNML_BLOG_ADDON="https://andreashaerter.com/downloads/dokuwiki-template-mnml-blog/latest"
|
|
|
93
|
+WIKI_MNML_BLOG_ADDON_HASH="428c280d09ee14326fef5cd6f6772ecfcd532f7b6779cd992ff79a97381cf39f"
|
|
|
94
|
+
|
84
|
GPG_KEYSERVER="hkp://keys.gnupg.net"
|
95
|
GPG_KEYSERVER="hkp://keys.gnupg.net"
|
85
|
|
96
|
|
86
|
# optionally you can provide your exported GPG key pair here
|
97
|
# optionally you can provide your exported GPG key pair here
|
|
|
|
|
1503
|
echo 'install_web_server' >> $COMPLETION_FILE
|
1514
|
echo 'install_web_server' >> $COMPLETION_FILE
|
1504
|
}
|
1515
|
}
|
1505
|
|
1516
|
|
|
|
1517
|
+function configure_php {
|
|
|
1518
|
+ sed -i "s/memory_limit = 128M/memory_limit = $MAX_PHP_MEMORYM/g" /etc/php5/fpm/php.ini
|
|
|
1519
|
+ sed -i 's/;cgi.fix_pathinfo=1/cgi.fix_pathinfo=0/g' /etc/php5/fpm/php.ini
|
|
|
1520
|
+ sed -i "s/memory_limit = -1/memory_limit = $MAX_PHP_MEMORYM/g" /etc/php5/cli/php.ini
|
|
|
1521
|
+ sed -i "s/upload_max_filesize = 2M/upload_max_filesize = 50M/g" /etc/php5/fpm/php.ini
|
|
|
1522
|
+ sed -i "s/post_max_size = 8M/post_max_size = 50M/g" /etc/php5/fpm/php.ini
|
|
|
1523
|
+ sed -i "s/memory_limit = /memory_limit = $MAX_PHP_MEMORYM/g" /etc/php5/cli/php.ini
|
|
|
1524
|
+}
|
|
|
1525
|
+
|
1506
|
function install_owncloud {
|
1526
|
function install_owncloud {
|
1507
|
if [[ $SYSTEM_TYPE == "writer" || $SYSTEM_TYPE == "email" || $SYSTEM_TYPE == "mailbox" || $SYSTEM_TYPE == "chat" || $SYSTEM_TYPE == "social" ]]; then
|
1527
|
if [[ $SYSTEM_TYPE == "writer" || $SYSTEM_TYPE == "email" || $SYSTEM_TYPE == "mailbox" || $SYSTEM_TYPE == "chat" || $SYSTEM_TYPE == "social" ]]; then
|
1508
|
return
|
1528
|
return
|
|
|
|
|
1632
|
echo ' }' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME
|
1652
|
echo ' }' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME
|
1633
|
echo '}' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME
|
1653
|
echo '}' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME
|
1634
|
|
1654
|
|
1635
|
-
|
|
|
1636
|
- sed -i "s/memory_limit = 128M/memory_limit = $MAX_PHP_MEMORYM/g" /etc/php5/fpm/php.ini
|
|
|
1637
|
- sed -i 's/;cgi.fix_pathinfo=1/cgi.fix_pathinfo=0/g' /etc/php5/fpm/php.ini
|
|
|
1638
|
- sed -i "s/memory_limit = -1/memory_limit = $MAX_PHP_MEMORYM/g" /etc/php5/cli/php.ini
|
|
|
1639
|
- sed -i "s/upload_max_filesize = 2M/upload_max_filesize = 50M/g" /etc/php5/fpm/php.ini
|
|
|
1640
|
- sed -i "s/post_max_size = 8M/post_max_size = 50M/g" /etc/php5/fpm/php.ini
|
|
|
1641
|
- sed -i "s/memory_limit = /memory_limit = $MAX_PHP_MEMORYM/g" /etc/php5/cli/php.ini
|
|
|
|
|
1655
|
+ configure_php
|
1642
|
|
1656
|
|
1643
|
if [ ! -f /etc/ssl/private/$OWNCLOUD_DOMAIN_NAME.key ]; then
|
1657
|
if [ ! -f /etc/ssl/private/$OWNCLOUD_DOMAIN_NAME.key ]; then
|
1644
|
makecert $OWNCLOUD_DOMAIN_NAME
|
1658
|
makecert $OWNCLOUD_DOMAIN_NAME
|
|
|
|
|
1795
|
sed -i 's/;MaxUsers = 23/MaxUsers = 23/g' /etc/ngircd/ngircd.conf
|
1809
|
sed -i 's/;MaxUsers = 23/MaxUsers = 23/g' /etc/ngircd/ngircd.conf
|
1796
|
sed -i 's|;KeyFile = /etc/ngircd/#chan.key|KeyFile = /etc/ngircd/#freedombone.key|g' /etc/ngircd/ngircd.conf
|
1810
|
sed -i 's|;KeyFile = /etc/ngircd/#chan.key|KeyFile = /etc/ngircd/#freedombone.key|g' /etc/ngircd/ngircd.conf
|
1797
|
sed -i 's/;CloakHost = cloaked.host/CloakHost = cloaked.host/g' /etc/ngircd/ngircd.conf
|
1811
|
sed -i 's/;CloakHost = cloaked.host/CloakHost = cloaked.host/g' /etc/ngircd/ngircd.conf
|
1798
|
- IRC_SALT=$(openssl rand -base64 64)
|
|
|
|
|
1812
|
+ IRC_SALT=$(openssl rand -base64 32)
|
1799
|
IRC_OPERATOR_PASSWORD=$(openssl rand -base64 8)
|
1813
|
IRC_OPERATOR_PASSWORD=$(openssl rand -base64 8)
|
1800
|
- sed -i "s/;CloakHostSalt = abcdefghijklmnopqrstuvwxyz/CloakHostSalt = $IRC_SALT/g" /etc/ngircd/ngircd.conf
|
|
|
|
|
1814
|
+ sed -i "s|;CloakHostSalt = abcdefghijklmnopqrstuvwxyz|CloakHostSalt = $IRC_SALT|g" /etc/ngircd/ngircd.conf
|
1801
|
sed -i 's/;ConnectIPv4 = yes/ConnectIPv4 = yes/g' /etc/ngircd/ngircd.conf
|
1815
|
sed -i 's/;ConnectIPv4 = yes/ConnectIPv4 = yes/g' /etc/ngircd/ngircd.conf
|
1802
|
sed -i 's/;MorePrivacy = no/MorePrivacy = yes/g' /etc/ngircd/ngircd.conf
|
1816
|
sed -i 's/;MorePrivacy = no/MorePrivacy = yes/g' /etc/ngircd/ngircd.conf
|
1803
|
sed -i 's/;RequireAuthPing = no/RequireAuthPing = no/g' /etc/ngircd/ngircd.conf
|
1817
|
sed -i 's/;RequireAuthPing = no/RequireAuthPing = no/g' /etc/ngircd/ngircd.conf
|
|
|
|
|
1807
|
echo 'install_irc_server' >> $COMPLETION_FILE
|
1821
|
echo 'install_irc_server' >> $COMPLETION_FILE
|
1808
|
}
|
1822
|
}
|
1809
|
|
1823
|
|
|
|
1824
|
+function install_wiki {
|
|
|
1825
|
+ if [[ $SYSTEM_TYPE == "cloud" || $SYSTEM_TYPE == "email" || $SYSTEM_TYPE == "mailbox" || $SYSTEM_TYPE == "chat" || $SYSTEM_TYPE == "social" ]]; then
|
|
|
1826
|
+ return
|
|
|
1827
|
+ fi
|
|
|
1828
|
+ if grep -Fxq "install_wiki" $COMPLETION_FILE; then
|
|
|
1829
|
+ return
|
|
|
1830
|
+ fi
|
|
|
1831
|
+ # if this is exclusively a writer setup
|
|
|
1832
|
+ if [[ $SYSTEM_TYPE == "writer" ]]; then
|
|
|
1833
|
+ WIKI_DOMAIN_NAME=$DOMAIN_NAME
|
|
|
1834
|
+ WIKI_FREEDNS_SUBDOMAIN_CODE=$FREEDNS_SUBDOMAIN_CODE
|
|
|
1835
|
+ fi
|
|
|
1836
|
+ if [ ! $WIKI_DOMAIN_NAME ]; then
|
|
|
1837
|
+ return
|
|
|
1838
|
+ fi
|
|
|
1839
|
+ if ! [[ $SYSTEM_TYPE == "writer" ]]; then
|
|
|
1840
|
+ if [ ! $SYSTEM_TYPE ]; then
|
|
|
1841
|
+ return
|
|
|
1842
|
+ fi
|
|
|
1843
|
+ fi
|
|
|
1844
|
+ apt-get -y --force-yes install php5 php5-gd php-xml-parser php5-intl wget
|
|
|
1845
|
+ apt-get -y --force-yes install php5-sqlite php5-mysql smbclient curl libcurl3 php5-curl bzip2
|
|
|
1846
|
+
|
|
|
1847
|
+ if [ ! -d /var/www/$WIKI_DOMAIN_NAME ]; then
|
|
|
1848
|
+ mkdir /var/www/$WIKI_DOMAIN_NAME
|
|
|
1849
|
+ mkdir /var/www/$WIKI_DOMAIN_NAME/htdocs
|
|
|
1850
|
+ fi
|
|
|
1851
|
+
|
|
|
1852
|
+ if [ ! -f /etc/ssl/private/$WIKI_DOMAIN_NAME.key ]; then
|
|
|
1853
|
+ makecert $WIKI_DOMAIN_NAME
|
|
|
1854
|
+ fi
|
|
|
1855
|
+
|
|
|
1856
|
+ # download the archive
|
|
|
1857
|
+ cd $INSTALL_DIR
|
|
|
1858
|
+ if [ ! -f $INSTALL_DIR/$WIKI_ARCHIVE ]; then
|
|
|
1859
|
+ wget $WIKI_DOWNLOAD
|
|
|
1860
|
+ fi
|
|
|
1861
|
+ if [ ! -f $INSTALL_DIR/$WIKI_ARCHIVE ]; then
|
|
|
1862
|
+ echo 'Dokuwiki could not be downloaded. Check that it exists at '
|
|
|
1863
|
+ echo $WIKI_DOWNLOAD
|
|
|
1864
|
+ echo 'And if neccessary update the version number and hash within this script'
|
|
|
1865
|
+ exit 18
|
|
|
1866
|
+ fi
|
|
|
1867
|
+ # Check that the hash is correct
|
|
|
1868
|
+ CHECKSUM=$(sha256sum $WIKI_ARCHIVE | awk -F ' ' '{print $1}')
|
|
|
1869
|
+ if [[ $CHECKSUM != $WIKI_HASH ]]; then
|
|
|
1870
|
+ echo 'The sha256 hash of the Dokuwiki download is incorrect. Possibly the file may have been tampered with. Check the hash on the Dokuwiki web site.'
|
|
|
1871
|
+ exit 21
|
|
|
1872
|
+ fi
|
|
|
1873
|
+
|
|
|
1874
|
+ tar -xzvf $WIKI_ARCHIVE
|
|
|
1875
|
+ rm -rf /var/www/$WIKI_DOMAIN_NAME/htdocs
|
|
|
1876
|
+ mv dokuwiki /var/www/$WIKI_DOMAIN_NAME/htdocs
|
|
|
1877
|
+ chmod -R 755 /var/www/$WIKI_DOMAIN_NAME/htdocs
|
|
|
1878
|
+ chown -R www-data:www-data /var/www/$WIKI_DOMAIN_NAME/htdocs
|
|
|
1879
|
+
|
|
|
1880
|
+ if ! grep -q "video/ogg" /var/www/$WIKI_DOMAIN_NAME/htdocs/conf/mime.conf; then
|
|
|
1881
|
+ echo 'ogv video/ogg' >> /var/www/$WIKI_DOMAIN_NAME/htdocs/conf/mime.conf
|
|
|
1882
|
+ echo 'mp4 video/mp4' >> /var/www/$WIKI_DOMAIN_NAME/htdocs/conf/mime.conf
|
|
|
1883
|
+ echo 'webm video/webm' >> /var/www/$WIKI_DOMAIN_NAME/htdocs/conf/mime.conf
|
|
|
1884
|
+ fi
|
|
|
1885
|
+
|
|
|
1886
|
+ configure_php
|
|
|
1887
|
+
|
|
|
1888
|
+ echo 'server {' > /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1889
|
+ echo ' listen 80;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1890
|
+ echo " server_name $WIKI_DOMAIN_NAME;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1891
|
+ echo " root /var/www/$WIKI_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1892
|
+ echo " error_log /var/www/$WIKI_DOMAIN_NAME/error.log;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1893
|
+ echo ' index index.html index.htm index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1894
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1895
|
+ echo ' # Uncomment this if you need to redirect HTTP to HTTPS' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1896
|
+ echo ' #rewrite ^ https://$server_name$request_uri? permanent;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1897
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1898
|
+ echo ' location / {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1899
|
+ echo ' try_files $uri $uri/ /index.html;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1900
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1901
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1902
|
+ echo ' location ~ \.php$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1903
|
+ echo ' fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1904
|
+ echo ' fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1905
|
+ echo ' fastcgi_index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1906
|
+ echo ' include fastcgi_params;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1907
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1908
|
+ echo '}' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1909
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1910
|
+ echo 'server {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1911
|
+ echo ' listen 443 ssl;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1912
|
+ echo " root /var/www/$WIKI_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1913
|
+ echo " server_name $WIKI_DOMAIN_NAME;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1914
|
+ echo " error_log /var/www/$WIKI_DOMAIN_NAME/error_ssl.log;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1915
|
+ echo ' index index.html index.htm index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1916
|
+ echo ' charset utf-8;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1917
|
+ echo ' client_max_body_size 20m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1918
|
+ echo ' client_body_buffer_size 128k;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1919
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1920
|
+ echo ' ssl on;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1921
|
+ echo " ssl_certificate /etc/ssl/certs/$WIKI_DOMAIN_NAME.crt;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1922
|
+ echo " ssl_certificate_key /etc/ssl/private/$WIKI_DOMAIN_NAME.key;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1923
|
+ echo " ssl_dhparam /etc/ssl/certs/$WIKI_DOMAIN_NAME.dhparam;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1924
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1925
|
+ echo ' ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1926
|
+ echo ' ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1927
|
+ echo ' ssl_session_cache builtin:1000 shared:SSL:10m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1928
|
+ echo ' ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1929
|
+ echo " ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1930
|
+ echo ' add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1931
|
+ echo ' add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1932
|
+ echo ' add_header Strict-Transport-Security "max-age=0;";' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1933
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1934
|
+ echo ' # rewrite to front controller as default rule' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1935
|
+ echo ' location / {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1936
|
+ echo ' rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1937
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1938
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1939
|
+ echo " # make sure webfinger and other well known services aren't blocked" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1940
|
+ echo ' # by denying dot files and rewrite request to the front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1941
|
+ echo ' location ^~ /.well-known/ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1942
|
+ echo ' allow all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1943
|
+ echo ' rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1944
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1945
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1946
|
+ echo ' # statically serve these file types when possible' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1947
|
+ echo ' # otherwise fall back to front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1948
|
+ echo ' # allow browser to cache them' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1949
|
+ echo ' # added .htm for advanced source code editor library' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1950
|
+ echo ' location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1951
|
+ echo ' expires 30d;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1952
|
+ echo ' try_files $uri /index.php?q=$uri&$args;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1953
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1954
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1955
|
+ echo ' # block these file types' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1956
|
+ echo ' location ~* \.(tpl|md|tgz|log|out)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1957
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1958
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1959
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1960
|
+ echo ' # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1961
|
+ echo ' # or a unix socket' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1962
|
+ echo ' location ~* \.php$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1963
|
+ echo ' # Zero-day exploit defense.' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1964
|
+ echo ' # http://forum.nginx.org/read.php?2,88845,page=3' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1965
|
+ echo " # Won't work properly (404 error) if the file is not stored on this" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1966
|
+ echo " # server, which is entirely possible with php-fpm/php-fcgi." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1967
|
+ echo " # Comment the 'try_files' line out if you set up php-fpm/php-fcgi on" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1968
|
+ echo " # another machine. And then cross your fingers that you won't get hacked." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1969
|
+ echo " try_files $uri =404;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1970
|
+ echo ' # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1971
|
+ echo ' fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1972
|
+ echo ' # With php5-cgi alone:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1973
|
+ echo ' # fastcgi_pass 127.0.0.1:9000;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1974
|
+ echo ' # With php5-fpm:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1975
|
+ echo ' fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1976
|
+ echo ' include fastcgi_params;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1977
|
+ echo ' fastcgi_index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1978
|
+ echo ' fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1979
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1980
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1981
|
+ echo ' # deny access to all dot files' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1982
|
+ echo ' location ~ /\. {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1983
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1984
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1985
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1986
|
+ echo ' #deny access to store' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1987
|
+ echo ' location ~ /store {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1988
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1989
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1990
|
+ echo '}' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
|
1991
|
+
|
|
|
1992
|
+ nginx_ensite $WIKI_DOMAIN_NAME
|
|
|
1993
|
+ service php5-fpm restart
|
|
|
1994
|
+ service nginx restart
|
|
|
1995
|
+
|
|
|
1996
|
+ # update the dynamic DNS
|
|
|
1997
|
+ if [[ $WIKI_FREEDNS_SUBDOMAIN_CODE != $FREEDNS_SUBDOMAIN_CODE ]]; then
|
|
|
1998
|
+ if ! grep -q "$WIKI_DOMAIN_NAME" /usr/bin/dynamicdns; then
|
|
|
1999
|
+ echo "# $WIKI_DOMAIN_NAME" >> /usr/bin/dynamicdns
|
|
|
2000
|
+ echo "wget -O - https://freedns.afraid.org/dynamic/update.php?$WIKI_FREEDNS_SUBDOMAIN_CODE== >> /dev/null 2>&1" >> /usr/bin/dynamicdns
|
|
|
2001
|
+ fi
|
|
|
2002
|
+ fi
|
|
|
2003
|
+
|
|
|
2004
|
+ # add some post-install instructions
|
|
|
2005
|
+ if ! grep -q "Once you have set up the wiki" /home/$MY_USERNAME/README; then
|
|
|
2006
|
+ echo '' >> /home/$MY_USERNAME/README
|
|
|
2007
|
+ echo 'Once you have set up the wiki then remove the install file:' >> /home/$MY_USERNAME/README
|
|
|
2008
|
+ echo '' >> /home/$MY_USERNAME/README
|
|
|
2009
|
+ echo " rm /var/www/$WIKI_DOMAIN_NAME/htdocs/install.php" >> /home/$MY_USERNAME/README
|
|
|
2010
|
+ fi
|
|
|
2011
|
+
|
|
|
2012
|
+ echo 'install_wiki' >> $COMPLETION_FILE
|
|
|
2013
|
+}
|
|
|
2014
|
+
|
|
|
2015
|
+function install_blog {
|
|
|
2016
|
+ if [[ $SYSTEM_TYPE == "cloud" || $SYSTEM_TYPE == "email" || $SYSTEM_TYPE == "mailbox" || $SYSTEM_TYPE == "chat" || $SYSTEM_TYPE == "social" ]]; then
|
|
|
2017
|
+ return
|
|
|
2018
|
+ fi
|
|
|
2019
|
+ if grep -Fxq "install_blog" $COMPLETION_FILE; then
|
|
|
2020
|
+ return
|
|
|
2021
|
+ fi
|
|
|
2022
|
+
|
|
|
2023
|
+ cd $INSTALL_DIR
|
|
|
2024
|
+ rm -f latest
|
|
|
2025
|
+ wget $WIKI_MNML_BLOG_ADDON
|
|
|
2026
|
+ if [ ! -f "$INSTALL_DIR/latest" ]; then
|
|
|
2027
|
+ echo 'Dokuwiki mnml-blog addon could not be downloaded. Check the Dokuwiki web site and alter WIKI_MNML_BLOG_ADDON at the top of this script as needed.'
|
|
|
2028
|
+ exit 21
|
|
|
2029
|
+ fi
|
|
|
2030
|
+ mv latest $WIKI_MNML_BLOG_ADDON_ARCHIVE
|
|
|
2031
|
+
|
|
|
2032
|
+ # Check that the hash is correct
|
|
|
2033
|
+ CHECKSUM=$(sha256sum $WIKI_MNML_BLOG_ADDON_ARCHIVE | awk -F ' ' '{print $1}')
|
|
|
2034
|
+ if [[ $CHECKSUM != $WIKI_MNML_BLOG_ADDON_HASH ]]; then
|
|
|
2035
|
+ echo 'The sha256 hash of the mnml-blog download is incorrect. Possibly the file may have been tampered with. Check the hash on the Dokuwiki mnmlblog web site and alter WIKI_MNML_BLOG_ADDON_HASH if needed.'
|
|
|
2036
|
+ exit 22
|
|
|
2037
|
+ fi
|
|
|
2038
|
+
|
|
|
2039
|
+ tar -xzvf $WIKI_MNML_BLOG_ADDON_ARCHIVE
|
|
|
2040
|
+ cp mnml-blog /var/www/$WIKI_DOMAIN_NAME/htdocs/lib/tpl/
|
|
|
2041
|
+ cp -r /var/www/$WIKI_DOMAIN_NAME/htdocs/lib/tpl/mnml-blog/blogtng-tpl/* /var/www/$WIKI_DOMAIN_NAME/htdocs/lib/plugins/blogtng/tpl/default/
|
|
|
2042
|
+
|
|
|
2043
|
+ echo 'install_blog' >> $COMPLETION_FILE
|
|
|
2044
|
+}
|
|
|
2045
|
+
|
1810
|
function install_final {
|
2046
|
function install_final {
|
1811
|
if grep -Fxq "install_final" $COMPLETION_FILE; then
|
2047
|
if grep -Fxq "install_final" $COMPLETION_FILE; then
|
1812
|
return
|
2048
|
return
|
|
|
|
|
1865
|
configure_firewall_for_xmpp
|
2101
|
configure_firewall_for_xmpp
|
1866
|
install_irc_server
|
2102
|
install_irc_server
|
1867
|
configure_firewall_for_irc
|
2103
|
configure_firewall_for_irc
|
|
|
2104
|
+install_wiki
|
|
|
2105
|
+#install_blog
|
1868
|
install_final
|
2106
|
install_final
|
1869
|
echo 'Freedombone installation is complete'
|
2107
|
echo 'Freedombone installation is complete'
|
1870
|
exit 0
|
2108
|
exit 0
|