Bug 9885 Passwords generated by command line scripts are weak
[koha.git] / debian / scripts / koha-create
index 7a7fa45..8211e1c 100755 (executable)
 
 set -e
 
+usage="Usage: $0 [--create-db|--request-db|--populate-db|--use-db] \
+    [--marcflavor marc21|normarc|unimarc] \
+    [--zebralang en|nb|fr] \
+    [--defaultsql /path/to/some.sql] \
+    [--configfile /path/to/config] [--passwdfile /path/to/passwd] \
+    [--database database] [--adminuser n] instancename"
 
 die() {
     echo "$@" 1>&2
     exit 1
 }
 
-
+# UPPER CASE VARIABLES - from configfile or default value
+# lower case variables - generated within this script
 generate_config_file() {
     touch "$2"
     chown "root:$username" "$2"
     chmod 0640 "$2"
     sed -e "s/__KOHASITE__/$name/g" \
-        -e "s/__OPACPORT__/80/g" \
+        -e "s/__OPACPORT__/$OPACPORT/g" \
         -e "s/__INTRAPORT__/$INTRAPORT/g" \
-        -e "s/__OPACSERVER__/$domain/g" \
+        -e "s/__OPACSERVER__/$opacdomain/g" \
         -e "s/__INTRASERVER__/$intradomain/g" \
         -e "s/__ZEBRA_PASS__/$zebrapwd/g" \
+        -e "s/__ZEBRA_MARC_FORMAT__/$ZEBRA_MARC_FORMAT/g" \
+        -e "s/__ZEBRA_LANGUAGE__/$ZEBRA_LANGUAGE/g" \
         -e "s/__DB_NAME__/$mysqldb/g" \
+        -e "s/__DB_HOST__/$mysqlhost/g" \
         -e "s/__DB_USER__/$mysqluser/g" \
         -e "s/__DB_PASS__/$mysqlpwd/g" \
         -e "s/__UNIXUSER__/$username/g" \
@@ -44,138 +54,302 @@ generate_config_file() {
         "/etc/koha/$1" > "$2"
 }
 
+getmysqlhost() {
+    awk '
+        /^\[/ { inclient = 0 }
+        /^\[client\]/ { inclient = 1 }
+        inclient && /^ *host *=/ { print $3 }' \
+        /etc/mysql/koha-common.cnf
+}
+
+getinstancemysqlpassword() {
+    xmlstarlet sel -t -v 'yazgfs/config/pass' "/etc/koha/sites/$1/koha-conf.xml"
+}
+
+getinstancemysqluser() {
+    xmlstarlet sel -t -v 'yazgfs/config/user' "/etc/koha/sites/$1/koha-conf.xml"
+}
+
+getinstancemysqldatabase() {
+    xmlstarlet sel -t -v 'yazgfs/config/database' "/etc/koha/sites/$1/koha-conf.xml"
+}
 
 # Set defaults and read config file, if it exists.
 DOMAIN=""
+OPACPORT="80"
+OPACPREFIX=""
+OPACSUFFIX=""
 INTRAPORT="8080"
 INTRAPREFIX=""
 INTRASUFFIX=""
 DEFAULTSQL=""
+ZEBRA_MARC_FORMAT="marc21"
+ZEBRA_LANGUAGE="en"
+ADMINUSER="1"
+PASSWDFILE="/etc/koha/passwd"
 if [ -e /etc/koha/koha-sites.conf ]
 then
     . /etc/koha/koha-sites.conf
 fi
 
-
-# Parse command line.
-[ "$#" = 1 ] || die "Usage: $0 instancename"
-name="$1"
-domain="$name$DOMAIN"
-if [ "$INTRAPORT" = 80 ] || [ "$INTRAPORT" = "" ]
+[ $# -ge 2 ] && [ $# -le 16 ] || die $usage
+
+TEMP=`getopt -o crpm:l:d:f:b:a: -l create-db,request-db,populate-db,use-db,marcflavor:,zebralang:,defaultsql:,configfile:,passwdfile:,database:,adminuser: \
+     -n "$0" -- "$@"`
+
+# Note the quotes around `$TEMP': they are essential!
+eval set -- "$TEMP"
+
+# Temporary variables for the command line options
+CLO_ZEBRA_MARC_FORMAT=""
+CLO_ZEBRA_LANGUAGE=""
+CLO_DEFAULTSQL=""
+CLO_ADMINUSER=""
+
+while true ; do
+       case "$1" in
+               -c|--create-db) op=create ; shift ;;
+               -r|--request-db) op=request ; shift ;;
+               -p|--populate-db) op=populate ; shift ;;
+        -u|--use-db) op=use ; shift ;;
+               -m|--marcflavor) CLO_ZEBRA_MARC_FORMAT="$2" ; shift 2 ;;
+               -l|--zebralang) CLO_ZEBRA_LANGUAGE="$2" ; shift 2 ;;
+               -d|--defaultsql) CLO_DEFAULTSQL="$2" ; shift 2 ;;
+               -f|--configfile) configfile="$2" ; shift 2 ;;
+        -s|--passwdfile) CLO_PASSWDFILE="$2" ; shift 2 ;;
+        -b|--database) CLO_DATABASE="$2" ; shift 2 ;;
+               -a|--adminuser) CLO_ADMINUSER="$2" ; shift 2 ;;
+               --) shift ; break ;;
+               *) die "Internal error processing command line arguments" ;;
+       esac
+done
+
+# Load the configfile given on the command line
+if [ "$configfile" != "" ]
 then
-    intradomain="$INTRAPREFIX$name$INTRASUFFIX$DOMAIN"
-else
-    intradomain="$INTRAPREFIX$name$INTRASUFFIX$DOMAIN:$INTRAPORT"
+    if [ -e "$configfile" ]
+    then
+        . "$configfile"
+    else
+        die "$configfile does not exist.";
+    fi
 fi
 
-
-# Create new user and group.
-username="$name-koha"
-if getent passwd "$username" > /dev/null
+# Make sure options from the command line get the highest precedence
+if [ "$CLO_ZEBRA_MARC_FORMAT" != "" ]
 then
-    die "User $username already exists."
+    ZEBRA_MARC_FORMAT="$CLO_ZEBRA_MARC_FORMAT"
 fi
-if getent group "$username" > /dev/null
+if [ "$CLO_ZEBRA_LANGUAGE" != "" ]
 then
-    die "Group $username already exists."
+    ZEBRA_LANGUAGE="$CLO_ZEBRA_LANGUAGE"
+fi
+if [ "$CLO_DEFAULTSQL" != "" ]
+then
+    DEFAULTSQL="$CLO_DEFAULTSQL"
+fi
+if [ "$CLO_ADMINUSER" != "" ]
+then
+    ADMINUSER="$CLO_ADMINUSER"
+fi
+if [ "$CLO_PASSWDFILE" != "" ]
+then
+    PASSWDFILE="$CLO_PASSWDFILE"
 fi
-adduser --no-create-home --disabled-login --gecos "Koha instance $username" \
-    --quiet "$username"
 
+name="$1"
 
-# Create the site-specific directories.
-mkdir "/etc/koha/sites/$name"
+opacdomain="$OPACPREFIX$name$OPACSUFFIX$DOMAIN"
+intradomain="$INTRAPREFIX$name$INTRASUFFIX$DOMAIN"
 
-mkdir "/var/lock/koha/$name"
-mkdir "/var/lock/koha/$name/authorities"
-mkdir "/var/lock/koha/$name/biblios"
-chown -R "root:$username" "/var/lock/koha/$name"
-chmod -R g+w "/var/lock/koha/$name"
-[ -d "/var/spool/koha/$name" ] || mkdir "/var/spool/koha/$name"
 
-install -d -o "$username" -g "$username" "/var/lib/koha/$name"
-install -d -o "$username" -g "$username" "/var/lib/koha/$name/authorities"
-install -d -o "$username" -g "$username" "/var/lib/koha/$name/biblios"
-install -d -o "$username" -g "$username" "/var/lib/koha/$name/biblios/key"
-install -d -o "$username" -g "$username" "/var/lib/koha/$name/biblios/register"
-install -d -o "$username" -g "$username" "/var/lib/koha/$name/biblios/shadow"
+if [ -f $PASSWDFILE ] && [ `cat $PASSWDFILE | grep "^$name:"` ]
+then
+    passwdline=`cat $PASSWDFILE | grep "^$name:"`
+    mysqluser=`echo $passwdline | cut -d ":" -f 2`
+    mysqlpwd=`echo $passwdline | cut -d ":" -f 3`
+    mysqldb=`echo $passwdline | cut -d ":" -f 4`
+fi
 
-install -d "/var/run/koha/$name/authorities"
-install -d "/var/run/koha/$name/biblios"
+# The order of precedence for MySQL database name is:
+# default < passwd file < command line
+if [ "$mysqldb" = "" ]
+then
+    mysqldb="koha_$name"
+fi
+if [ "$CLO_DATABASE" != "" ]
+then
+    mysqldb="$CLO_DATABASE"
+fi
 
+if [ "$mysqluser" = "" ]
+then
+    mysqluser="koha_$name"
+fi
+mysqlhost="$(getmysqlhost)"
 
-# Generate Zebra database password.
-zebrapwd="$(pwgen -1)"
+if [ "$op" = create ] || [ "$op" = request ] || [ "$op" = use ]
+then
+    if [ "$mysqlpwd" = "" ]
+    then
+        mysqlpwd="$(pwgen -s 16 1)"
+    fi
+else
+    mysqlpwd="$(getinstancemysqlpassword $name)"
+fi
 
 
-# Set up MySQL database for this instance.
-mysqldb="koha_$name"
-mysqluser="koha_$name"
-mysqlpwd="$(pwgen -1)"
-mysql --defaults-extra-file=/etc/mysql/debian.cnf <<eof
-CREATE DATABASE $mysqldb;
-CREATE USER '$mysqluser' IDENTIFIED BY '$mysqlpwd';
-GRANT ALL PRIVILEGES ON $mysqldb.* TO '$mysqluser';
+if [ "$op" = create ] || [ "$op" = request ] || [ "$op" = use ]
+then
+    # Create new user and group.
+    username="$name-koha"
+    if getent passwd "$username" > /dev/null
+    then
+        die "User $username already exists."
+    fi
+    if getent group "$username" > /dev/null
+    then
+        die "Group $username already exists."
+    fi
+    adduser --no-create-home --disabled-login \
+        --gecos "Koha instance $username" \
+        --home "/var/lib/koha/$name" \
+        --quiet "$username"
+
+    # Create the site-specific directories.
+    koha-create-dirs "$name"
+
+    # Generate Zebra database password.
+    zebrapwd="$(pwgen -s 16 1)"
+    # Future enhancement: make this configurable for when your db is on
+    # another server.
+    mysql_hostname="localhost"
+    # Set up MySQL database for this instance.
+    if [ "$op" = create ]
+    then
+        mysql --defaults-extra-file=/etc/mysql/koha-common.cnf <<eof
+CREATE DATABASE \`$mysqldb\`;
+CREATE USER \`$mysqluser\`@'$mysql_hostname' IDENTIFIED BY '$mysqlpwd';
+CREATE USER \`$mysqluser\`@'%' IDENTIFIED BY '$mysqlpwd';
+GRANT ALL PRIVILEGES ON \`$mysqldb\`.* TO \`$mysqluser\`;
 FLUSH PRIVILEGES;
+eof
+    fi #`
+
+    if [ "$op" = use ]
+    then
+        mysql --defaults-extra-file=/etc/mysql/koha-common.cnf --force <<eof
+CREATE USER \`$mysqluser\`@'$mysql_hostname' IDENTIFIED BY '$mysqlpwd';
+CREATE USER \`$mysqluser\`@'%' IDENTIFIED BY '$mysqlpwd';
+GRANT ALL PRIVILEGES ON \`$mysqldb\`.* TO \`$mysqluser\`;
+FLUSH PRIVILEGES;
+eof
+    fi #`
+
+    # Generate and install Apache site-available file and log dir.
+    generate_config_file apache-site.conf.in \
+        "/etc/apache2/sites-available/$name"
+    mkdir "/var/log/koha/$name"
+    chown "$username:$username" "/var/log/koha/$name"
+
+
+    # Generate and install main Koha config file.
+    generate_config_file koha-conf-site.xml.in \
+        "/etc/koha/sites/$name/koha-conf.xml"
+
+    # Generate and install Zebra config files.
+    generate_config_file zebra-biblios-site.cfg.in \
+        "/etc/koha/sites/$name/zebra-biblios.cfg"
+    generate_config_file zebra-authorities-site.cfg.in \
+        "/etc/koha/sites/$name/zebra-authorities.cfg"
+    generate_config_file zebra-authorities-dom-site.cfg.in \
+        "/etc/koha/sites/$name/zebra-authorities-dom.cfg"
+    generate_config_file zebra.passwd.in \
+        "/etc/koha/sites/$name/zebra.passwd"
+
+
+    # Create a GPG-encrypted file for requesting a DB to be set up.
+    if [ "$op" = request ]
+    then
+        touch "$name-db-request.txt"
+        chmod 0600 "$name-db-request.txt"
+        cat > "$name-db-request.txt" << eof
+Please create a MySQL database and user on $mysqlhost as follows:
+
+database name: $mysqldb
+database user: $mysqluser
+     password: $mysqlpwd
+
+Thank you.
 eof
 
-
-# Use the default database content if that exists.
-if [ -e "$DEFAULTSQL" ]
-then
-    # Populate the database with default content.
-    zcat "$DEFAULTSQL" |
-    sed "s/__KOHASITE__/$name/g" |
-    mysql --defaults-extra-file=/etc/mysql/debian.cnf
+        echo "See $name-db-request.txt for database creation request."
+        echo "Please forward it to the right person, and then run"
+        echo "$0 --populate-db $name"
+        echo "Thanks."
+    fi
+fi
 
 
-    # Change the default user's password.
-    staffpass="$(pwgen -1)"
-    staffdigest=$(echo -n "$staffpass" |
-                  perl -e '
-                        use Digest::MD5 qw(md5_base64); 
-                        while (<>) { print md5_base64($_), "\n"; }')
-    mysql --defaults-extra-file=/etc/mysql/debian.cnf <<eof
+if [ "$op" = create ] || [ "$op" = populate ]
+then
+    # Re-fetch the passwords from the config we've generated, allows it
+    # to be different from what we set, in case the user had to change
+    # something.
+    mysqluser=$(getinstancemysqluser $name)
+    mysqldb=$(getinstancemysqldatabase $name)
+    # Use the default database content if that exists.
+    if [ -e "$DEFAULTSQL" ]
+    then
+        # Populate the database with default content.
+        zcat "$DEFAULTSQL" |
+        sed "s/__KOHASITE__/$name/g" |
+        mysql --host="$mysqlhost" --user="$mysqluser" --password="$mysqlpwd" "$mysqldb"
+
+
+        # Change the default user's password.
+        staffpass="$(pwgen 12 1)"
+        staffdigest=$(echo -n "$staffpass" |
+                      perl -e '
+                            use Digest::MD5 qw(md5_base64); 
+                            while (<>) { print md5_base64($_), "\n"; }')
+        mysql --host="$mysqlhost" --user="$mysqluser" \
+--password="$mysqlpwd" <<eof
 USE \`$mysqldb\`;
 UPDATE borrowers 
 SET password = '$staffdigest' 
-WHERE borrowernumber = 3;
+WHERE borrowernumber = $ADMINUSER;
 eof
-    echo "staff user password is '$staffpass' but keep that secret"
-else
-    echo "Koha instance is empty, no staff user created."
+        #`
+        echo "staff user password is '$staffpass' but keep that secret"
+
+        # Upgrade the database schema, just in case the dump was from an 
+        # old version.
+        koha-upgrade-schema "$name"
+    else
+        echo "Koha instance is empty, no staff user created."
+    fi
 fi
 
 
-# Generate and install Apache site-available file and log dir.
-generate_config_file apache-site.conf.in "/etc/apache2/sites-available/$name"
-mkdir "/var/log/koha/$name"
-chown "$username:$username" "/var/log/koha/$name"
-
-
-# Generate and install main Koha config file.
-generate_config_file koha-conf-site.xml.in \
-    "/etc/koha/sites/$name/koha-conf.xml"
-
-
-# Generate and install Zebra config files.
-generate_config_file zebra-biblios-site.cfg.in \
-    "/etc/koha/sites/$name/zebra-biblios.cfg"
-generate_config_file zebra-authorities-site.cfg.in \
-    "/etc/koha/sites/$name/zebra-authorities.cfg"
-generate_config_file zebra-authorities-dom-site.cfg.in \
-    "/etc/koha/sites/$name/zebra-authorities-dom.cfg"
-generate_config_file zebra.passwd.in \
-    "/etc/koha/sites/$name/zebra.passwd"
+if [ "$op" = create ] || [ "$op" = populate ] || [ "$op" = use ]
+then
+    # Reconfigure Apache.
+    a2ensite "$name"
+    service apache2 restart
 
+    # Start Zebra.
+    koha-start-zebra "$name"
+fi
 
-# Upgrade the database schema, just in case the dump was from an old version.
-koha-upgrade-schema "$name"
 
+if [ "$op" = request ]
+then
+    koha-disable "$name"
+fi
 
-# Reconfigure Apache.
-a2ensite "$name"
-service apache2 restart
+echo <<eoh
 
-# Start Zebra.
-koha-start-zebra "$name"
+Email for this instance is disabled. When you're ready to enable it, use:
+koha-email-enable $name
+eoh