/** Access to config functions */
/** access to module settings */
// start session
if (strtolower(session_module_name()) == 'files') {
// get password
if (isset($_POST['passwd'])) $passwd = $_POST['passwd'];
// check if password was entered
// if not: load login page
if (!isset($passwd) && !isset($_SESSION['conf_isAuthenticated'])) {
$_SESSION['conf_message'] = _("No password was entered!");
/** go back to login if password is empty */
if (!isset($_SESSION['conf_config']) && isset($_POST['filename'])) {
$_SESSION['conf_config'] = new LAMConfig($_POST['filename']);
$conf = &$_SESSION['conf_config'];
// check if password is valid
// if not: load login page
if ((!isset($_SESSION['conf_isAuthenticated']) || !($_SESSION['conf_isAuthenticated'] === $conf->getName())) && !$conf->check_Passwd($passwd)) {
$sessionKeys = array_keys($_SESSION);
for ($i = 0; $i < sizeof($sessionKeys); $i++) {
if (substr($sessionKeys[$i], 0, 5) == "conf_") unset($_SESSION[$sessionKeys[$i]]);
$_SESSION['conf_message'] = _("The password is invalid! Please try again.");
/** go back to login if password is invalid */
$_SESSION['conf_isAuthenticated'] = $conf->getName();
// check if user canceled editing
if (isset($_POST['cancelSettings'])) {
$errorsToDisplay = array();
// check if button was pressed and if we have to save the settings or go to another tab
if (isset($_POST['saveSettings']) || isset($_POST['editmodules'])
|| isset($_POST['edittypes']) || isset($_POST['generalSettingsButton'])
|| isset($_POST['moduleSettings'])) {
$errorsToDisplay = checkInput();
if (sizeof($errorsToDisplay) == 0) {
// go to final page
if (isset($_POST['saveSettings'])) {
// go to modules page
elseif (isset($_POST['editmodules'])) {
// go to types page
elseif (isset($_POST['edittypes'])) {
// go to module settings page
elseif (isset($_POST['moduleSettings'])) {
// index for tab order
$tabindex = 1;
echo $_SESSION['header'];
echo ("<title>" . _("LDAP Account Manager Configuration") . "</title>\n");
// include all CSS files
$cssDirName = dirname(__FILE__) . '/../../style';
$cssDir = dir($cssDirName);
while ($cssEntry = $cssDir->read()) {
if (substr($cssEntry, strlen($cssEntry) - 4, 4) != '.css') continue;
echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"" . $headerPrefix . "../../style/" . $cssEntry . "\">\n";
echo "<link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"../../graphics/favicon.ico\">\n";
echo ("</head>\n");
echo ("<body onload=\"configLoginMethodChanged()\">\n");
// include all JavaScript files
$jsDirName = dirname(__FILE__) . '/../lib';
$jsDir = dir($jsDirName);
while ($jsEntry = $jsDir->read()) {
if (substr($jsEntry, strlen($jsEntry) - 3, 3) != '.js') continue;
echo "<script type=\"text/javascript\" src=\"../lib/" . $jsEntry . "\"></script>\n";
<table border=0 width="100%" class="lamHeader">
<td align="left" height="30">
<a class="lamHeader" href="http://www.ldap-account-manager.org/" target="new_window">&nbsp;<img src="../../graphics/logo32.png" width=24 height=24 class="align-middle" alt="LDAP Account Manager">&nbsp;&nbsp;LDAP Account Manager</a>
if (!$conf->isWritable()) {
StatusMessage('WARN', 'The config file is not writable.', 'Your changes cannot be saved until you make the file writable for the webserver user.');
echo "<br>";
// display error messages
if (sizeof($errorsToDisplay) > 0) {
for ($i = 0; $i < sizeof($errorsToDisplay); $i++) {
call_user_func_array('StatusMessage', $errorsToDisplay[$i]);
echo "<br>";
// display formular
echo ("<form action=\"confmain.php\" method=\"post\">\n");
echo '<div style="text-align: right;">';
echo "<button id=\"saveButton\" name=\"saveSettings\" type=\"submit\">" . _('Save') . "</button>";
echo "&nbsp;";
echo "<button id=\"cancelButton\" name=\"cancelSettings\" type=\"submit\">" . _('Cancel') . "</button>";
echo "<br><br>\n";
echo '</div>';
// hidden submit buttons which are clicked by tabs
echo "<div style=\"display: none;\">\n";
echo "<input name=\"generalSettingsButton\" type=\"submit\" value=\" \">";
echo "<input name=\"edittypes\" type=\"submit\" value=\" \">";
echo "<input name=\"editmodules\" type=\"submit\" value=\" \">";
echo "<input name=\"moduleSettings\" type=\"submit\" value=\" \">";
echo "</div>\n";
// tabs
echo '<div class="ui-tabs ui-widget ui-widget-content ui-corner-all">';
echo '<ul class="ui-tabs-nav ui-helper-reset ui-helper-clearfix ui-widget-header ui-corner-all">';
echo '<li id="generalSettingsButton" class="ui-state-default ui-corner-top">';
echo '<a href="#" onclick="document.getElementsByName(\'generalSettingsButton\')[0].click();"><img src="../../graphics/tools.png" alt=""> ';
echo _('General settings') . '</a>';
echo '</li>';
echo '<li id="edittypes" class="ui-state-default ui-corner-top">';
echo '<a href="#" onclick="document.getElementsByName(\'edittypes\')[0].click();"><img src="../../graphics/gear.png" alt=""> ';
echo _('Account types') . '</a>';
echo '</li>';
echo '<li id="editmodules" class="ui-state-default ui-corner-top">';
echo '<a href="#" onclick="document.getElementsByName(\'editmodules\')[0].click();"><img src="../../graphics/modules.png" alt=""> ';
echo _('Modules') . '</a>';
echo '</li>';
echo '<li id="moduleSettings" class="ui-state-default ui-corner-top">';
echo '<a href="#" onclick="document.getElementsByName(\'moduleSettings\')[0].click();"><img src="../../graphics/modules.png" alt=""> ';
echo _('Module settings') . '</a>';
echo '</li>';
echo '</ul>';
<script type="text/javascript">
jQuery(document).ready(function() {
icons: {
primary: 'saveButton'
icons: {
primary: 'cancelButton'
<div class="ui-tabs-panel ui-widget-content ui-corner-bottom">
echo ("<fieldset><legend><img align=\"middle\" src=\"../../graphics/profiles.png\" alt=\"profiles.png\"> <b>" . _("Server settings") . "</b></legend><br>\n");
echo ("<table border=0>");
// serverURL
echo ("<tr><td align=\"right\"><b>" . _("Server address") . " *: </b></td>".
"<td align=\"left\">".
"<input tabindex=\"$tabindex\" size=50 type=\"text\" name=\"serverurl\" value=\"" . $conf->get_ServerURL() . "\">".
echo "<td>";
printHelpLink(getHelp('', '201'), '201');
echo "</td></tr>\n";
// use TLS
echo "<tr><td align=\"right\"><b>" . _("Activate TLS") . ": </b></td>\n";
echo "<td align=\"left\">\n";
echo "<select tabindex=\"$tabindex\" size=1 name=\"useTLS\">";
$useTLS = $conf->getUseTLS();
if (isset($useTLS) && ($useTLS == 'yes')) {
echo "<option value=\"yes\" selected>" . _("yes") . "</option>";
echo "<option value=\"no\">" . _("no") . "</option>";
else {
echo "<option value=\"yes\">" . _("yes") . "</option>";
echo "<option value=\"no\" selected>" . _("no") . "</option>";
echo "</select>\n";
echo "</td>\n";
echo "<td>";
printHelpLink(getHelp('', '201'), '201');
echo "</td></tr>\n";
// new line
echo ("<tr><td colspan=3>&nbsp;</td></tr>");
// tree suffix
echo ("<tr><td align=\"right\"><b>".
_("Tree suffix") . ": </b></td>".
"<td><input tabindex=\"$tabindex\" size=50 type=\"text\" name=\"sufftree\" value=\"" . $conf->get_Suffix('tree') . "\"></td>\n");
echo "<td>";
printHelpLink(getHelp('', '203'), '203');
echo "</td></tr>\n";
// new line
echo ("<tr><td colspan=3>&nbsp;</td></tr>");
// LDAP cache timeout
echo ("<tr><td align=\"right\"><b>".
_("Cache timeout") . ": </b></td>".
"<td><select tabindex=\"$tabindex\" name=\"cachetimeout\">\n<option selected>".$conf->get_cacheTimeout()."</option>\n");
if ($conf->get_cacheTimeout() != 0) echo("<option>0</option>\n");
if ($conf->get_cacheTimeout() != 1) echo("<option>1</option>\n");
if ($conf->get_cacheTimeout() != 2) echo("<option>2</option>\n");
if ($conf->get_cacheTimeout() != 5) echo("<option>5</option>\n");
if ($conf->get_cacheTimeout() != 10) echo("<option>10</option>\n");
if ($conf->get_cacheTimeout() != 15) echo("<option>15</option>\n");
echo ("</select></td>\n");
echo "<td>";
printHelpLink(getHelp('', '214'), '214');
echo "</td></tr>\n";
// LDAP search limit
$searchLimitOptions = array(
array(0, '-'), array(100, 100), array(500, 500),
array(1000, 1000), array(5000, 5000), array(10000, 10000),
array(50000, 50000), array(100000, 100000)
echo ("<tr><td align=\"right\"><b>".
_("LDAP search limit") . ": </b></td>".
"<td><select tabindex=\"$tabindex\" name=\"searchLimit\">\n");
for ($i = 0; $i < sizeof($searchLimitOptions); $i++) {
$selected = "";
if ($searchLimitOptions[$i][0] == $conf->get_searchLimit()) {
$selected = "selected";
echo "<option value=\"" . $searchLimitOptions[$i][0] . "\" $selected>" . $searchLimitOptions[$i][1] . "</option>";
echo ("</select></td>\n");
echo "<td>";
printHelpLink(getHelp('', '222'), '222');
echo "</td></tr>\n";
// access level is only visible in Pro version
if (isLAMProVersion()) {
// new line
echo ("<tr><td colspan=3>&nbsp;</td></tr>");
// access level
echo ("<tr><td align=\"right\"><b>".
_("Access level") . ": </b></td>".
"<td><select tabindex=\"$tabindex\" name=\"accessLevel\">\n");
if ($conf->getAccessLevel() == LAMConfig::ACCESS_ALL) {
echo("<option selected value=" . LAMConfig::ACCESS_ALL . ">" . _('Write access') . "</option>\n");
else {
echo("<option value=" . LAMConfig::ACCESS_ALL . ">" . _('Write access') . "</option>\n");
if ($conf->getAccessLevel() == LAMConfig::ACCESS_PASSWORD_CHANGE) {
echo("<option selected value=" . LAMConfig::ACCESS_PASSWORD_CHANGE . ">" . _('Change passwords') . "</option>\n");
else {
echo("<option value=" . LAMConfig::ACCESS_PASSWORD_CHANGE . ">" . _('Change passwords') . "</option>\n");
if ($conf->getAccessLevel() == LAMConfig::ACCESS_READ_ONLY) {
echo("<option selected value=" . LAMConfig::ACCESS_READ_ONLY . ">" . _('Read only') . "</option>\n");
else {
echo("<option value=" . LAMConfig::ACCESS_READ_ONLY . ">" . _('Read only') . "</option>\n");
echo ("</select></td>\n");
echo "<td>";
printHelpLink(getHelp('', '215'), '215');
echo "</td></tr>\n";
echo ("</table>");
echo ("</fieldset>");
echo ("<br>");
echo ("<fieldset><legend><img align=\"middle\" src=\"../../graphics/language.png\" alt=\"language.png\"> <b>" . _("Language settings") . "</b></legend><br>\n");
echo ("<table border=0>\n");
// language
echo ("<tr>");
echo ("<td><b>" . _("Default language") . ":</b></td><td>\n");
// read available languages
$languagefile = "../../config/language";
$file = fopen($languagefile, "r");
$i = 0;
$line = fgets($file, 1024);
if($line == "\n" || $line[0] == "#" || $line == "") continue; // ignore comment and empty lines
$languages[$i] = chop($line);
// generate language list
echo ("<select tabindex=\"$tabindex\" name=\"lang\">");
for ($i = 0; $i < sizeof($languages); $i++) {
$entry = explode(":", $languages[$i]);
if ($conf->get_defaultLanguage() != $languages[$i]) echo("<option value=\"" . $languages[$i] . "\">" . $entry[2] . "</option>\n");
else echo("<option selected value=\"" . $languages[$i] . "\">" . $entry[2] . "</option>\n");
echo ("</select>\n");
echo _("Unable to load available languages. Setting English as default language. For further instructions please contact the Admin of this site.");
echo ("</td>\n");
echo "<td>";
printHelpLink(getHelp('', '209'), '209');
echo "</td></tr>\n";
echo ("</table>\n");
echo ("</fieldset>\n");
echo ("<br>\n");
// lamdaemon settings
echo ("<fieldset><legend><img align=\"middle\" src=\"../../graphics/lamdaemon.png\" alt=\"lamdaemon.png\"> <b>" . _("Lamdaemon settings") . "</b></legend><br>\n");
echo ("<table border=0>\n");
echo ("<tr><td align=\"right\"><b>".
_("Server list") . ": </b></td>".
"<td><input tabindex=\"$tabindex\" size=50 type=\"text\" name=\"scriptservers\" value=\"" . $conf->get_scriptServers(false) . "\"></td>\n");
echo "<td>";
printHelpLink(getHelp('', '218'), '218');
echo "</td></tr>\n";
echo ("<tr><td align=\"right\"><b>".
_("Path to external script") . ": </b></td>".
"<td><input tabindex=\"$tabindex\" size=50 type=\"text\" name=\"scriptpath\" value=\"" . $conf->get_scriptPath() . "\"></td>\n");
echo "<td>";
printHelpLink(getHelp('', '210'), '210');
echo "</td></tr>\n";
echo "<tr><td align=\"right\"><b>". _("Rights for the home directory") . ": </b></td>\n";
$owr = "";
$oww = "";
$owe = "";
$grr = "";
$grw = "";
$gre = "";
$otr = "";
$otw = "";
$ote = "";
$chmod = $conf->get_scriptRights();
if (checkChmod("read","owner", $chmod)) $owr = 'checked';
if (checkChmod("write","owner", $chmod)) $oww = 'checked';
if (checkChmod("execute","owner", $chmod)) $owe = 'checked';
if (checkChmod("read","group", $chmod)) $grr = 'checked';
if (checkChmod("write","group", $chmod)) $grw = 'checked';
if (checkChmod("execute","group", $chmod)) $gre = 'checked';
if (checkChmod("read","other", $chmod)) $otr = 'checked';
if (checkChmod("write","other", $chmod)) $otw = 'checked';
if (checkChmod("execute","other", $chmod)) $ote = 'checked';
echo "<td align=\"center\">\n";
echo "<table width=\"280\"><tr align=\"center\">\n";
echo "<td width=\"70\"></td><th width=\"70\">" . _("Read") . "</th>\n";
echo "<th width=\"70\">" . _("Write") . "</th>\n";
echo "<th width=\"70\">"._("Execute")."</th></tr>\n";
echo "<tr align=\"center\"><th align=\"left\">"._("Owner")."</th>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_owr\" " . $owr . "></td>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_oww\" " . $oww . "></td>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_owe\" " . $owe . "></td></tr>\n";
echo "<tr align=\"center\"><th align=\"left\">"._("Group")."</th>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_grr\" " . $grr . "></td>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_grw\" " . $grw . "></td>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_gre\" " . $gre . "></td></tr>\n";
echo "<tr align=\"center\"><th align=\"left\">"._("Other")."</th>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_otr\" " . $otr . "></td>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_otw\" " . $otw . "></td>\n";
echo "<td><input type=\"checkbox\" name=\"chmod_ote\" " . $ote . "></td>\n";
echo "</tr></table>";
echo "<td>";
printHelpLink(getHelp('', '219'), '219');
echo "</td></tr>\n";
echo ("</table>\n");
echo ("</fieldset>\n");
echo ("<br>\n");
// security setings
echo ("<fieldset><legend><img align=\"middle\" src=\"../../graphics/security.png\" alt=\"security.png\"> <b>" . _("Security settings") . "</b></legend><br>\n");
echo ("<table border=0>\n");
// login method
echo ("<tr><td align=\"right\"><b>".
_("Login method") . ": </b></td>".
"<td><select tabindex=\"$tabindex\" name=\"loginMethod\" onchange=\"configLoginMethodChanged()\">\n");
if ($conf->getLoginMethod() == LAMConfig::LOGIN_LIST) {
echo("<option selected value=" . LAMConfig::LOGIN_LIST . ">" . _('Fixed list') . "</option>\n");
else {
echo("<option value=" . LAMConfig::LOGIN_LIST . ">" . _('Fixed list') . "</option>\n");
if ($conf->getLoginMethod() == LAMConfig::LOGIN_SEARCH) {
echo("<option selected value=" . LAMConfig::LOGIN_SEARCH . ">" . _('LDAP search') . "</option>\n");
else {
echo("<option value=" . LAMConfig::LOGIN_SEARCH . ">" . _('LDAP search') . "</option>\n");
echo ("</select></td>\n");
echo "<td>";
printHelpLink(getHelp('', '220'), '220');
echo "</td></tr>\n";
// admin list
$adminText = implode("\n", explode(";", $conf->get_Adminstring()));
echo "<tr id=\"trAdminList\"><td align=\"right\">\n";
echo "<b>".
_("List of valid users") . " *: </b></td>".
"<td><textarea tabindex=\"$tabindex\" name=\"admins\" cols=75 rows=3>" . $adminText . "</textarea></td>\n";
echo "<td>";
printHelpLink(getHelp('', '207'), '207');
echo "</td></tr>\n";
// login search suffix
echo "<tr id=\"trLoginSearchSuffix\"><td align=\"right\">\n";
echo "<b>".
_("LDAP suffix") . " *: </b></td>".
"<td><input type=\"text\" tabindex=\"$tabindex\" name=\"loginSearchSuffix\" value=\"" . $conf->getLoginSearchSuffix() . "\" size=50></td>\n";
echo "<td>";
printHelpLink(getHelp('', '221'), '221');
echo "</td></tr>\n";
// login search filter
echo "<tr id=\"trLoginSearchFilter\"><td align=\"right\">\n";
echo "<b>".
_("LDAP filter") . " *: </b></td>".
"<td><input type=\"text\" tabindex=\"$tabindex\" name=\"loginSearchFilter\" value=\"" . $conf->getLoginSearchFilter() . "\" size=50></td>\n";
echo "<td>";
printHelpLink(getHelp('', '221'), '221');
echo "</td></tr>\n";
echo ("<tr><td colspan=3>&nbsp;</td></tr>\n");
// new password
echo ("<tr><td align=\"right\"><font color=\"red\"><b>".
_("New password") . ": </b></font></td>".
"<td align=\"left\"><input tabindex=\"$tabindex\" type=\"password\" name=\"passwd1\"></td>\n");
echo "<td rowspan=2>";
printHelpLink(getHelp('', '212'), '212');
echo "</td></tr>\n";
// reenter password
echo ("<tr><td align=\"right\"><font color=\"red\"><b>".
_("Reenter password") . ": </b></font></td>".
"<td align=\"left\"><input tabindex=\"$tabindex\" type=\"password\" name=\"passwd2\"></td></tr>\n");
echo ("</table>\n");
echo ("</fieldset>\n");
echo ("<p>* = ". _("required") . "</p>");
echo ("</div></div></form>\n");
echo ("</body>\n");
echo ("</html>\n");
* Checks user input and saves the entered settings.
* @return array list of errors
function checkInput() {
$conf = &$_SESSION['conf_config'];
$types = $conf->get_ActiveTypes();
// remove double slashes if magic quotes are on
if (get_magic_quotes_gpc() == 1) {
$postKeys = array_keys($_POST);
for ($i = 0; $i < sizeof($postKeys); $i++) {
if (is_string($_POST[$postKeys[$i]])) $_POST[$postKeys[$i]] = stripslashes($_POST[$postKeys[$i]]);
// check new preferences
$errors = array();
if (!$conf->set_ServerURL($_POST['serverurl'])) {
$errors[] = array("ERROR", _("Server address is invalid!"));
if (!$conf->set_cacheTimeout($_POST['cachetimeout'])) {
$errors[] = array("ERROR", _("Cache timeout is invalid!"));
if (isLAMProVersion()) {
$adminText = $_POST['admins'];
$adminText = explode("\n", $adminText);
$adminTextNew = array();
for ($i = 0; $i < sizeof($adminText); $i++) {
if (trim($adminText[$i]) == "") continue;
$adminTextNew[] = trim($adminText[$i]);
if (!$conf->set_Adminstring(implode(";", $adminTextNew))) {
$errors[] = array("ERROR", _("List of admin users is empty or invalid!"));
if (!$conf->set_Suffix("tree", $_POST['sufftree'])) {
$errors[] = array("ERROR", _("TreeSuffix is invalid!"));
if (!$conf->set_defaultLanguage($_POST['lang'])) {
$errors[] = array("ERROR", _("Language is not defined!"));
if (!$conf->set_scriptpath($_POST['scriptpath'])) {
$errors[] = array("ERROR", _("Script path is invalid!"));
if (!$conf->set_scriptservers($_POST['scriptservers'])) {
$errors[] = array("ERROR", _("Script server is invalid!"));
$chmodOwner = 0;
$chmodGroup = 0;
$chmodOther = 0;
if (isset($_POST['chmod_owr']) && ($_POST['chmod_owr'] == 'on')) $chmodOwner += 4;
if (isset($_POST['chmod_oww']) && ($_POST['chmod_oww'] == 'on')) $chmodOwner += 2;
if (isset($_POST['chmod_owe']) && ($_POST['chmod_owe'] == 'on')) $chmodOwner += 1;
if (isset($_POST['chmod_grr']) && ($_POST['chmod_grr'] == 'on')) $chmodGroup += 4;
if (isset($_POST['chmod_grw']) && ($_POST['chmod_grw'] == 'on')) $chmodGroup += 2;
if (isset($_POST['chmod_gre']) && ($_POST['chmod_gre'] == 'on')) $chmodGroup += 1;
if (isset($_POST['chmod_otr']) && ($_POST['chmod_otr'] == 'on')) $chmodOther += 4;
if (isset($_POST['chmod_otw']) && ($_POST['chmod_otw'] == 'on')) $chmodOther += 2;
if (isset($_POST['chmod_ote']) && ($_POST['chmod_ote'] == 'on')) $chmodOther += 1;
$chmod = $chmodOwner . $chmodGroup . $chmodOther;
if (!$conf->set_scriptrights($chmod)) {
$errors[] = array("ERROR", _("Script rights are invalid!"));
// check if password was changed
if (isset($_POST['passwd1']) && ($_POST['passwd1'] != '')) {
if ($_POST['passwd1'] != $_POST['passwd2']) {
$errors[] = array("ERROR", _("Passwords are different!"));
else {
// set new password
return $errors;