blob: fef7958bae3a666ae34a3b128cf24a2acfffaa44 [file] [log] [blame]
Matthias Andreas Benkardb382b102021-01-02 15:32:21 +01001#!/bin/bash
2
3# Wait for MySQL to warm-up
4while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
5 echo "Waiting for database to come up..."
6 sleep 2
7done
8
9# Wait until port becomes free and send sig
10until ! nc -z sogo-mailcow 20000;
11do
12 killall -TERM sogod
13 sleep 3
14done
15
16# Wait for updated schema
17DBV_NOW=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions WHERE application = 'db_schema';" -BN)
18DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
19while [[ "${DBV_NOW}" != "${DBV_NEW}" ]]; do
20 echo "Waiting for schema update..."
21 DBV_NOW=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions WHERE application = 'db_schema';" -BN)
22 DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
23 sleep 5
24done
25echo "DB schema is ${DBV_NOW}"
26
27# Recreate view
28if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
29 echo "We are master, preparing sogo_view..."
30 mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "DROP VIEW IF EXISTS sogo_view"
31 while [[ ${VIEW_OK} != 'OK' ]]; do
32 mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
33CREATE VIEW sogo_view (c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, ext_acl, kind, multiple_bookings) AS
34SELECT
35 mailbox.username,
36 mailbox.domain,
37 mailbox.username,
38 IF(JSON_UNQUOTE(JSON_VALUE(attributes, '$.force_pw_update')) = '0', IF(JSON_UNQUOTE(JSON_VALUE(attributes, '$.sogo_access')) = 1, password, '{SSHA256}A123A123A321A321A321B321B321B123B123B321B432F123E321123123321321'), '{SSHA256}A123A123A321A321A321B321B321B123B123B321B432F123E321123123321321'),
39 mailbox.name,
40 mailbox.username,
41 IFNULL(GROUP_CONCAT(ga.aliases ORDER BY ga.aliases SEPARATOR ' '), ''),
42 IFNULL(gda.ad_alias, ''),
43 IFNULL(external_acl.send_as_acl, ''),
44 mailbox.kind,
45 mailbox.multiple_bookings
46FROM
47 mailbox
48 LEFT OUTER JOIN
49 grouped_mail_aliases ga
50 ON ga.username REGEXP CONCAT('(^|,)', mailbox.username, '($|,)')
51 LEFT OUTER JOIN
52 grouped_domain_alias_address gda
53 ON gda.username = mailbox.username
54 LEFT OUTER JOIN
55 grouped_sender_acl_external external_acl
56 ON external_acl.username = mailbox.username
57WHERE
58 mailbox.active = '1'
59GROUP BY
60 mailbox.username;
61EOF
62 if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = 'sogo_view'") ]]; then
63 VIEW_OK=OK
64 else
65 echo "Will retry to setup SOGo view in 3s..."
66 sleep 3
67 fi
68 done
69else
70 while [[ ${VIEW_OK} != 'OK' ]]; do
71 if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = 'sogo_view'") ]]; then
72 VIEW_OK=OK
73 else
74 echo "Waiting for SOGo view to be created by master..."
75 sleep 3
76 fi
77 done
78fi
79
80# Wait for static view table if missing after update and update content
81if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
82 echo "We are master, preparing _sogo_static_view..."
83 while [[ ${STATIC_VIEW_OK} != 'OK' ]]; do
84 if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = '_sogo_static_view'") ]]; then
85 STATIC_VIEW_OK=OK
86 echo "Updating _sogo_static_view content..."
87 # If changed, also update init_db.inc.php
88 mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "REPLACE INTO _sogo_static_view (c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, ext_acl, kind, multiple_bookings) SELECT c_uid, domain, c_name, c_password, c_cn, mail, aliases, ad_aliases, ext_acl, kind, multiple_bookings from sogo_view;"
89 mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "DELETE FROM _sogo_static_view WHERE c_uid NOT IN (SELECT username FROM mailbox WHERE active = '1')"
90 else
91 echo "Waiting for database initialization..."
92 sleep 3
93 fi
94 done
95else
96 while [[ ${STATIC_VIEW_OK} != 'OK' ]]; do
97 if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME = '_sogo_static_view'") ]]; then
98 STATIC_VIEW_OK=OK
99 else
100 echo "Waiting for database initialization by master..."
101 sleep 3
102 fi
103 done
104fi
105
106
107# Recreate password update trigger
108if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
109 echo "We are master, preparing update trigger..."
110 mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "DROP TRIGGER IF EXISTS sogo_update_password"
111 while [[ ${TRIGGER_OK} != 'OK' ]]; do
112 mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
113DELIMITER -
114CREATE TRIGGER sogo_update_password AFTER UPDATE ON _sogo_static_view
115FOR EACH ROW
116BEGIN
117UPDATE mailbox SET password = NEW.c_password WHERE NEW.c_uid = username;
118END;
119-
120DELIMITER ;
121EOF
122 if [[ ! -z $(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -B -e "SELECT 'OK' FROM INFORMATION_SCHEMA.TRIGGERS WHERE TRIGGER_NAME = 'sogo_update_password'") ]]; then
123 TRIGGER_OK=OK
124 else
125 echo "Will retry to setup SOGo password update trigger in 3s"
126 sleep 3
127 fi
128 done
129fi
130
131if [[ "${ALLOW_ADMIN_EMAIL_LOGIN}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
132 TRUST_PROXY="YES"
133else
134 TRUST_PROXY="NO"
135fi
136# cat /dev/urandom seems to hang here occasionally and is not recommended anyway, better use openssl
137RAND_PASS=$(openssl rand -base64 16 | tr -dc _A-Z-a-z-0-9)
138
139# Generate plist header with timezone data
140mkdir -p /var/lib/sogo/GNUstep/Defaults/
141cat <<EOF > /var/lib/sogo/GNUstep/Defaults/sogod.plist
142<?xml version="1.0" encoding="UTF-8"?>
143<!DOCTYPE plist PUBLIC "-//GNUstep//DTD plist 0.9//EN" "http://www.gnustep.org/plist-0_9.xml">
144<plist version="0.9">
145<dict>
146 <key>OCSAclURL</key>
147 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_acl</string>
148 <key>SOGoIMAPServer</key>
149 <string>imap://${IPV4_NETWORK}.250:143/?TLS=YES&amp;tlsVerifyMode=none</string>
150 <key>SOGoTrustProxyAuthentication</key>
151 <string>${TRUST_PROXY}</string>
152 <key>SOGoEncryptionKey</key>
153 <string>${RAND_PASS}</string>
154 <key>OCSCacheFolderURL</key>
155 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_cache_folder</string>
156 <key>OCSEMailAlarmsFolderURL</key>
157 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_alarms_folder</string>
158 <key>OCSFolderInfoURL</key>
159 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_folder_info</string>
160 <key>OCSSessionsFolderURL</key>
161 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_sessions_folder</string>
162 <key>OCSStoreURL</key>
163 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_store</string>
164 <key>SOGoProfileURL</key>
165 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_user_profile</string>
166 <key>SOGoTimeZone</key>
167 <string>${TZ}</string>
168 <key>domains</key>
169 <dict>
170EOF
171
172# Generate multi-domain setup
173while read -r line gal
174 do
175 echo " <key>${line}</key>
176 <dict>
177 <key>SOGoMailDomain</key>
178 <string>${line}</string>
179 <key>SOGoUserSources</key>
180 <array>
181 <dict>
182 <key>MailFieldNames</key>
183 <array>
184 <string>aliases</string>
185 <string>ad_aliases</string>
186 <string>ext_acl</string>
187 </array>
188 <key>KindFieldName</key>
189 <string>kind</string>
190 <key>DomainFieldName</key>
191 <string>domain</string>
192 <key>MultipleBookingsFieldName</key>
193 <string>multiple_bookings</string>
194 <key>listRequiresDot</key>
195 <string>NO</string>
196 <key>canAuthenticate</key>
197 <string>YES</string>
198 <key>displayName</key>
199 <string>GAL ${line}</string>
200 <key>id</key>
201 <string>${line}</string>
202 <key>isAddressBook</key>
203 <string>${gal}</string>
204 <key>type</key>
205 <string>sql</string>
206 <key>userPasswordAlgorithm</key>
207 <string>${MAILCOW_PASS_SCHEME}</string>
208 <key>prependPasswordScheme</key>
209 <string>YES</string>
210 <key>viewURL</key>
211 <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/_sogo_static_view</string>
212 </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
213 # Generate alternative LDAP authentication dict, when SQL authentication fails
214 # This will nevertheless read attributes from LDAP
215 line=${line} envsubst < /etc/sogo/plist_ldap >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
216 echo " </array>
217 </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
218done < <(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT domain, CASE gal WHEN '1' THEN 'YES' ELSE 'NO' END AS gal FROM domain;" -B -N)
219
220# Generate footer
221echo ' </dict>
222</dict>
223</plist>' >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
224
225# Fix permissions
226chown sogo:sogo -R /var/lib/sogo/
227chmod 600 /var/lib/sogo/GNUstep/Defaults/sogod.plist
228
229# Patch ACLs
230#if [[ ${ACL_ANYONE} == 'allow' ]]; then
231# #enable any or authenticated targets for ACL
232# if patch -R -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
233# patch -R /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
234# fi
235#else
236# #disable any or authenticated targets for ACL
237# if patch -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
238# patch /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
239# fi
240#fi
241
242# Copy logo, if any
243[[ -f /etc/sogo/sogo-full.svg ]] && cp /etc/sogo/sogo-full.svg /usr/lib/GNUstep/SOGo/WebServerResources/img/sogo-full.svg
244
245# Rsync web content
246echo "Syncing web content with named volume"
247rsync -a /usr/lib/GNUstep/SOGo/. /sogo_web/
248
249# Chown backup path
250chown -R sogo:sogo /sogo_backup
251
252# Creating cronjobs
253if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
254 echo "* * * * * sogo /usr/sbin/sogo-ealarms-notify -p /etc/sogo/sieve.creds 2>/dev/null" > /etc/cron.d/sogo
255 echo "* * * * * sogo /usr/sbin/sogo-tool expire-sessions ${SOGO_EXPIRE_SESSION}" >> /etc/cron.d/sogo
256 echo "0 0 * * * sogo /usr/sbin/sogo-tool update-autoreply -p /etc/sogo/sieve.creds" >> /etc/cron.d/sogo
257 echo "0 2 * * * sogo /usr/sbin/sogo-tool backup /sogo_backup ALL" >> /etc/cron.d/sogo
258else
259 rm /etc/cron.d/sogo
260fi
261
262exec gosu sogo /usr/sbin/sogod