index.php 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783
  1. <?php
  2. include 'auto.php';
  3. if(IS_SAE)
  4. header("Location: index_sae.php");
  5. // php最低版本要求
  6. $mini_php = '5.4.0';
  7. if (file_exists('./install.lock')) {
  8. echo '
  9. <html>
  10. <head>
  11. <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
  12. </head>
  13. <body>
  14. 你已经安装过该系统,如果想重新安装,请先删除站点install目录下的 install.lock 文件,然后再安装。
  15. </body>
  16. </html>';
  17. exit;
  18. }
  19. @set_time_limit(1000);
  20. if (phpversion() <= $mini_php)
  21. @set_magic_quotes_runtime(0);
  22. if ($mini_php > phpversion()){
  23. header("Content-type:text/html;charset=utf-8");
  24. die('本系统要求PHP版本 >= '.$mini_php.',当前PHP版本为:'.phpversion() . ',请到虚拟主机控制面板里切换PHP版本,或联系空间商协助切换。<a href="http://www.eyoucms.com/help/" target="_blank">点击查看易优安装教程</a>');
  25. }
  26. define("EYOUCMS_VERSION", '20180101');
  27. date_default_timezone_set('PRC');
  28. error_reporting(E_ALL & ~E_NOTICE);
  29. header('Content-Type: text/html; charset=UTF-8');
  30. define('SITEDIR', _dir_path(substr(dirname(__FILE__), 0, -8)));
  31. define("SERVICE_URL", 'aHR0cDovL3NlcnZpY2UuZXlvdWNtcy5jb20=');
  32. //define('SITEDIR2', substr(SITEDIR,0,-7));
  33. //echo SITEDIR2;
  34. //exit;
  35. //数据库
  36. $sqlFile = 'eyoucms.sql';
  37. $configFile = 'config.php';
  38. if (!file_exists(SITEDIR . 'install/' . $sqlFile) || !file_exists(SITEDIR . 'install/' . $configFile)) {
  39. echo "缺少必要的安装文件({$sqlFile} 或 {$configFile})!";
  40. exit;
  41. }
  42. $Title = "EyouCMS安装向导";
  43. $Powered = "Powered by EyouCMS";
  44. $steps = array(
  45. '1' => '安装许可协议',
  46. '2' => '运行环境检测',
  47. '3' => '安装参数设置',
  48. '4' => '安装详细过程',
  49. '5' => '安装完成',
  50. );
  51. $step = isset($_GET['step']) ? intval($_GET['step']) : 1;
  52. //地址
  53. $scriptName = !empty($_SERVER["REQUEST_URI"]) ? $scriptName = $_SERVER["REQUEST_URI"] : $scriptName = $_SERVER["PHP_SELF"];
  54. $rootpath = @preg_replace("/\/(I|i)nstall\/index\.php(.*)$/", "", $scriptName);
  55. $domain = empty($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : $_SERVER['SERVER_NAME'];
  56. if ((int) $_SERVER['SERVER_PORT'] != 80) {
  57. $domain .= ":" . $_SERVER['SERVER_PORT'];
  58. }
  59. $domain = $domain . $rootpath;
  60. switch ($step) {
  61. case '1':
  62. include_once ("./templates/step1.php");
  63. exit();
  64. case '2':
  65. session_start();
  66. $_SESSION['isset_author'] = null;
  67. session_destroy();
  68. if (phpversion() < 5) {
  69. die('本系统需要PHP5.4.0以上 + MYSQL >= 5.0环境,当前PHP版本为:' . phpversion());
  70. }
  71. $err = 0;
  72. $phpv = @ phpversion();
  73. if ($mini_php <= phpversion()){
  74. $phpvStr = '<img src="images/ok.png">';
  75. }else{
  76. $phpvStr = '<img src="images/del.png"> &nbsp;<a href="http://www.eyoucms.com/wenda/3132.html" target="_blank">当前版本('.phpversion().')不支持</a>';
  77. $err++;
  78. }
  79. $os = PHP_OS;
  80. //$os = php_uname();
  81. $tmp = function_exists('gd_info') ? gd_info() : array();
  82. $server = $_SERVER["SERVER_SOFTWARE"];
  83. $host = (empty($_SERVER["SERVER_ADDR"]) ? $_SERVER["SERVER_HOST"] : $_SERVER["SERVER_ADDR"]);
  84. $name = $_SERVER["SERVER_NAME"];
  85. $max_execution_time = ini_get('max_execution_time');
  86. $allow_reference = (ini_get('allow_call_time_pass_reference') ? '<img src="images/ok.png">' : '<img src="images/del.png">');
  87. $allow_url_fopen = (ini_get('allow_url_fopen') ? '<img src="images/ok.png">' : '<img src="images/del.png">');
  88. $safe_mode = (ini_get('safe_mode') ? '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3125.html" target="_blank">详情</a>' : '<img src="images/ok.png">');
  89. if (empty($tmp['GD Version'])) {
  90. $gd = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3126.html" target="_blank">详情</a>';
  91. $err++;
  92. } else {
  93. $gd = '<img src="images/ok.png">';
  94. }
  95. if (function_exists('mysqli_connect')) {
  96. $mysql = '<img src="images/ok.png">';
  97. } else {
  98. $mysql = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3127.html" target="_blank">详情</a>';
  99. $err++;
  100. }
  101. // if (ini_get('file_uploads')) {
  102. // $uploadSize = '<img src="images/ok.png">';
  103. // } else {
  104. // $uploadSize = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3128.html" target="_blank">详情</a>';
  105. // }
  106. if (class_exists('pdo')) {
  107. $pdo = '<img src="images/ok.png">';
  108. } else {
  109. $pdo = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3129.html" target="_blank">详情</a>';
  110. $err++;
  111. }
  112. if (extension_loaded('pdo_mysql')) {
  113. $pdo_mysql = '<img src="images/ok.png">';
  114. } else {
  115. $pdo_mysql = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3129.html" target="_blank">详情</a>';
  116. $err++;
  117. }
  118. /* if (function_exists('session_start')) {
  119. $session = '<img src="images/ok.png">';
  120. } else {
  121. $session = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/7115.html" target="_blank">详情</a>';
  122. $err++;
  123. }*/
  124. if(function_exists('curl_init')){
  125. $curl = '<img src="images/ok.png">';
  126. }else{
  127. $curl = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3130.html" target="_blank">详情</a>';
  128. $err++;
  129. }
  130. if(function_exists('file_put_contents')){
  131. $file_put_contents = '<img src="images/ok.png">';
  132. }else{
  133. $file_put_contents = '<img src="images/del.png">&nbsp;<a href="http://www.eyoucms.com/wenda/3131.html" target="_blank">详情</a>';
  134. $err++;
  135. }
  136. // if(function_exists('scandir')){
  137. // $scandir = '<img src="images/ok.png">';
  138. // }else{
  139. // $scandir = '<img src="images/del.png">';
  140. // $err++;
  141. // }
  142. $folder = array(
  143. 'install',
  144. 'uploads',
  145. 'data/runtime',
  146. 'application/admin/conf',
  147. 'application/config.php',
  148. 'application/database.php',
  149. );
  150. include_once ("./templates/step2.php");
  151. exit();
  152. case '3':
  153. $dbName = trim(addslashes($_POST['dbName']));
  154. $dbUser = trim(addslashes($_POST['dbUser']));
  155. $dbport = !empty($_POST['dbport']) ? addslashes($_POST['dbport']) : '3306';
  156. $dbPwd = $_POST['dbPwd'];
  157. $dbHost = addslashes($_POST['dbHost']);
  158. if ($_GET['testdbpwd']) {
  159. $conn = @mysqli_connect($dbHost, $dbUser, $dbPwd,NULL,$dbport);
  160. if (mysqli_connect_errno($conn)){
  161. die(json_encode(array(
  162. 'errcode' => 0,
  163. 'dbpwmsg' => "<span for='dbname' generated='true' class='tips_error'>数据库连接失败,请重新设定</span>",
  164. )));
  165. } else {
  166. /*针对mysql5版本,结合程序本身一些复杂SQL进行sql_mode设置*/
  167. // $result = mysqli_query($conn,"SELECT @@global.sql_mode");
  168. // $result = $result->fetch_array();
  169. // $version = mysqli_get_server_info($conn);
  170. // if ($version >= 5)
  171. // {
  172. // if(strstr($result[0],'STRICT_ALL_TABLES') || strstr($result[0],'TRADITIONAL') || strstr($result[0],'ANSI') || strstr($result[0],'ONLY_FULL_GROUP_BY')) {
  173. // die(json_encode(array(
  174. // 'errcode' => -1,
  175. // 'dbpwmsg' => "<span for='dbname' generated='true' class='tips_error'>请在mysql配置文件修改sql-mode或sql_mode</span>&nbsp;<a href='http://www.eyoucms.com/wenda/2799.html' target='_blank'>点击查看操作</a>",
  176. // )));
  177. // }
  178. // }
  179. /*--end*/
  180. if (empty($dbName)) {
  181. die(json_encode(array(
  182. 'errcode' => -2,
  183. 'dbpwmsg' => "<span class='green'>信息正确</span>",
  184. 'dbnamemsg' => "<span class='red'>数据库不能为空,请设定</span>",
  185. )));
  186. } else {
  187. /*检测数据库是否存在*/
  188. $result = mysqli_query($conn,"select count(table_name) as c from information_schema.`TABLES` where table_schema='$dbName'");
  189. $result = $result->fetch_array();
  190. if($result['c'] > 0) { // 存在
  191. $dbnamemsg = "<span class='red'>数据库已经存在,系统将覆盖数据库</span>";
  192. } else { // 不存在
  193. $dbnamemsg = "<span class='green'>数据库不存在,系统将自动创建</span>";
  194. }
  195. /*--end*/
  196. }
  197. die(json_encode(array(
  198. 'errcode' => 1,
  199. 'dbpwmsg' => "<span class='green'>信息正确</span>",
  200. 'dbnamemsg' => $dbnamemsg,
  201. )));
  202. }
  203. }
  204. else if ($_GET['check'])
  205. {
  206. if (!function_exists('mysqli_connect')) {
  207. $arr = array(
  208. 'code' => -1,
  209. 'msg' => "请安装 mysqli 扩展!",
  210. );
  211. die(json_encode($arr));
  212. }
  213. $conn = @mysqli_connect($dbHost, $dbUser, $dbPwd,NULL,$dbport);
  214. if (mysqli_connect_errno($conn)){
  215. $arr = array(
  216. 'code' => -1,
  217. 'msg' => "请检查数据库连接信息,".iconv('gbk', 'utf-8', mysqli_connect_error($conn)),
  218. );
  219. die(json_encode($arr));
  220. }
  221. mysqli_set_charset($conn, "utf8"); //,character_set_client=binary,sql_mode='';
  222. $version = mysqli_get_server_info($conn);
  223. if ($version < 5.1) {
  224. $arr = array(
  225. 'code' => -1,
  226. 'msg' => '数据库版本('.$version.')太低!必须 >= 5.1',
  227. );
  228. die(json_encode($arr));
  229. }
  230. if (!@mysqli_select_db($conn,$dbName)) {
  231. //创建数据时同时设置编码
  232. if (!@mysqli_query($conn,"CREATE DATABASE IF NOT EXISTS `" . $dbName . "` DEFAULT CHARACTER SET utf8;")) {
  233. $arr = array(
  234. 'code' => -1,
  235. 'msg' => '数据库 ' . $dbName . ' 不存在,也没权限创建新的数据库,建议联系空间商或者服务器负责人!',
  236. );
  237. die(json_encode($arr));
  238. }
  239. }
  240. $arr = array(
  241. 'code' => 0,
  242. 'msg' => '',
  243. );
  244. die(json_encode($arr));
  245. }
  246. include_once ("./templates/step3.php");
  247. exit();
  248. case '4':
  249. $arr = array();
  250. $dbHost = trim(addslashes($_POST['dbhost']));
  251. $dbport = !empty($_POST['dbport']) ? addslashes($_POST['dbport']) : '3306';
  252. $dbName = trim(addslashes($_POST['dbname']));
  253. $dbUser = trim(addslashes($_POST['dbuser']));
  254. $dbPwd = trim($_POST['dbpw']);
  255. $dbPrefix = empty($_POST['dbprefix']) ? 'ey_' : trim(addslashes($_POST['dbprefix']));
  256. $username = trim(addslashes($_POST['manager']));
  257. $password = trim($_POST['manager_pwd']);
  258. if (!function_exists('mysqli_connect')) {
  259. $arr['code'] = 0;
  260. $arr['msg'] = "请安装 mysqli 扩展!";
  261. echo json_encode($arr);
  262. exit;
  263. }
  264. $conn = @mysqli_connect($dbHost, $dbUser, $dbPwd,NULL,$dbport);
  265. if (mysqli_connect_errno($conn)){
  266. $arr['code'] = 0;
  267. $arr['msg'] = "连接数据库失败!".mysqli_connect_error($conn);
  268. echo json_encode($arr);
  269. exit;
  270. }
  271. mysqli_set_charset($conn, "utf8"); //,character_set_client=binary,sql_mode='';
  272. $version = mysqli_get_server_info($conn);
  273. if ($version < 5.1) {
  274. $arr['code'] = 0;
  275. $arr['msg'] = '数据库版本('.$version.')太低! 必须 >= 5.1';
  276. echo json_encode($arr);
  277. exit;
  278. }
  279. if (!@mysqli_select_db($conn,$dbName)) {
  280. //创建数据时同时设置编码
  281. if (!@mysqli_query($conn,"CREATE DATABASE IF NOT EXISTS `" . $dbName . "` DEFAULT CHARACTER SET utf8;")) {
  282. $arr['code'] = 0;
  283. $arr['msg'] = '数据库 ' . $dbName . ' 不存在,也没权限创建新的数据库,建议联系空间商或者服务器负责人!';
  284. echo json_encode($arr);
  285. exit;
  286. }
  287. mysqli_select_db($conn , $dbName);
  288. }
  289. // 当前CMS版本
  290. $cms_version = file_get_contents(SITEDIR .'data/conf/version.txt');
  291. //读取数据文件
  292. $sqldata = file_get_contents(SITEDIR . 'install/' . $sqlFile);
  293. $sqlFormat = sql_split($sqldata, $dbPrefix);
  294. //创建写入sql数据库文件到库中 结束
  295. /*检测对比数据库文件版本与CMS版本*/
  296. preg_match_all('/--\s*Version\s*:\s*#(v\d+\.\d+\.\d+)/', $sqldata, $matches1);
  297. $database_version = !empty($matches1[1][0]) ? $matches1[1][0] : ''; // 当前数据库版本
  298. if (!empty($cms_version) && $database_version != $cms_version) {
  299. $is_bool = true;
  300. if (preg_match('/^v\d+\.\d+\.\d+$/i', $database_version)) {
  301. $is_bool = false;
  302. } else {
  303. // CMS版本对应的官方远程数据库的所有表名
  304. $cms_datatableList = getRemoteDbTable($cms_version);
  305. if (is_array($cms_datatableList)) {
  306. // 获取当前安装目录下数据库文件的所有内置表的集合
  307. $datatableList = getLocalDbTable($sqldata);
  308. // 本地与官方的数据表对比校验
  309. $diff_datatableList = array_diff($datatableList, $cms_datatableList);
  310. if (count($datatableList) != count($cms_datatableList) || !empty($diff_datatableList)) {
  311. $is_bool = false;
  312. }
  313. }
  314. }
  315. if (false === $is_bool) {
  316. $database_version = !empty($database_version) ? $database_version :'无';
  317. $arr['code'] = 0;
  318. $arr['msg'] = "无法安装,数据库文件版本号(<font color='red'>{$database_version}</font>)与CMS源码版本号(<font color='red'>{$cms_version}</font>)不一致,<a href='http://www.eyoucms.com/wenda/7227.html' target='_blank'>点击查看</a>!";
  319. echo json_encode($arr);
  320. exit;
  321. }
  322. }
  323. /*--end*/
  324. /**
  325. * 执行SQL语句
  326. */
  327. $counts = count($sqlFormat);
  328. for ($i = 0; $i < $counts; $i++) {
  329. $sql = trim($sqlFormat[$i]);
  330. if (strstr($sql, 'CREATE TABLE')) {
  331. preg_match('/CREATE TABLE `([^ ]*)`/', $sql, $matches);
  332. mysqli_query($conn,"DROP TABLE IF EXISTS `$matches[1]");
  333. $ret = mysqli_query($conn,$sql);
  334. if (!$ret) {
  335. $message = '创建数据表' . $matches[1] . '失败,请尝试F5刷新!';
  336. $arr['code'] = 0;
  337. $arr = array('msg' => $message);
  338. echo json_encode($arr);
  339. exit;
  340. }
  341. } else {
  342. if(trim($sql) == '')
  343. continue;
  344. preg_match('/INSERT INTO `([^ ]*)`/', $sql, $matches);
  345. $ret = mysqli_query($conn,$sql);
  346. if (!$ret) {
  347. $message = '写入表' . $matches[1] . '记录失败,请尝试F5刷新!';
  348. $arr['code'] = 0;
  349. $arr = array('msg' => $message);
  350. echo json_encode($arr);
  351. exit;
  352. }
  353. }
  354. }
  355. // 清空测试数据
  356. /* if(addslashes($_POST['demo']) != 'demo')
  357. {
  358. $result = mysqli_query($conn,"show tables");
  359. $tables=$result->fetch_all(MYSQLI_NUM);//参数MYSQL_ASSOC、MYSQLI_NUM、MYSQLI_BOTH规定产生数组类型
  360. $bl_table = array('ey_admin','ey_arcrank','ey_auth_access','ey_auth_modular','ey_auth_role','ey_auth_role_admin','ey_auth_rule','ey_channeltype','ey_config','ey_smtp_tpl','ey_users_level','ey_users_parameter');
  361. foreach($bl_table as $k => $v)
  362. {
  363. $bl_table[$k] = preg_replace('/^ey_/i', $dbPrefix, $v);
  364. }
  365. foreach($tables as $key => $val)
  366. {
  367. if(!in_array($val[0], $bl_table))
  368. {
  369. mysqli_query($conn,"truncate table ".$val[0]);
  370. }
  371. }
  372. delFile('../uploads'); // 清空测试图片
  373. }*/
  374. /*清空缓存*/
  375. delFile('../data/runtime');
  376. /*--end*/
  377. $max_i = 999999999;
  378. if ($max_i == $i) {
  379. $arr['code'] = 0;
  380. $arr['msg'] = "数据库文件过大,执行条数超过{$max_i}条,请联系技术协助!";
  381. echo json_encode($arr);
  382. exit;
  383. // exit('-1');
  384. }
  385. $time = time();
  386. //读取配置文件,并替换真实配置数据1
  387. $strConfig = file_get_contents(SITEDIR . 'install/' . $configFile);
  388. $strConfig = str_replace('#DB_HOST#', $dbHost, $strConfig);
  389. $strConfig = str_replace('#DB_NAME#', $dbName, $strConfig);
  390. $strConfig = str_replace('#DB_USER#', $dbUser, $strConfig);
  391. $strConfig = str_replace('#DB_PWD#', $dbPwd, $strConfig);
  392. $strConfig = str_replace('#DB_PORT#', $dbport, $strConfig);
  393. $strConfig = str_replace('#DB_PREFIX#', $dbPrefix, $strConfig);
  394. $strConfig = str_replace('#DB_CHARSET#', 'utf8', $strConfig);
  395. $strConfig = str_replace('#DB_DEBUG#', false, $strConfig);
  396. @chmod(SITEDIR . 'application/database.php',0777); //数据库配置文件的地址
  397. @file_put_contents(SITEDIR . 'application/database.php', $strConfig); //数据库配置文件的地址
  398. //读取配置文件,并替换缓存前缀
  399. $strConfig = file_get_contents(SITEDIR . 'application/config.php');
  400. $uniqid_str = uniqid();
  401. $uniqid_str = md5($uniqid_str);
  402. $strConfig = str_replace('eyoucms_cache_prefix', $uniqid_str, $strConfig);
  403. @chmod(SITEDIR . 'application/config.php',0777); //配置文件的地址
  404. @file_put_contents(SITEDIR . 'application/config.php', $strConfig); //配置文件的地址
  405. $web_cmspath = preg_replace('/(.*)\/install([\w]*)\/index\.php/i', '$1', $_SERVER['SCRIPT_NAME']);
  406. $web_basehost = 'http://'.trim($_SERVER['HTTP_HOST'], '/').$web_cmspath;
  407. //更新网站配置的网站网址
  408. $sql = "UPDATE `{$dbPrefix}config` SET `value` = '$web_basehost' WHERE name = 'web_basehost' AND inc_type = 'web'";
  409. mysqli_query($conn, $sql);
  410. //更新网站配置的CMS安装路径
  411. $sql = "UPDATE `{$dbPrefix}config` SET `value` = '$web_cmspath' WHERE name = 'web_cmspath' AND inc_type = 'web'";
  412. mysqli_query($conn, $sql);
  413. //更新网站配置的CMS版本号
  414. $sql = "UPDATE `{$dbPrefix}config` SET `value` = '$cms_version' WHERE name = 'system_version' AND inc_type = 'system'";
  415. mysqli_query($conn, $sql);
  416. $auth_code = get_auth_code($conn, $dbPrefix);
  417. $result = mysqli_query($conn, "SELECT admin_id FROM `{$dbPrefix}admin`");
  418. $adminTotal = $result->num_rows;
  419. if (1 >= intval($adminTotal)) {
  420. mysqli_query($conn, "truncate table `{$dbPrefix}admin`"); // 清空admin表
  421. // 密码加密串,新安装程序,或者没有用户的程序,才随机给密码加密串
  422. $result2 = @mysqli_query($conn, "SELECT users_id FROM `{$dbPrefix}users`");
  423. if (empty($result2) || empty($result2->num_rows)) {
  424. $auth_code = sp_random_string(20);
  425. mysqli_query($conn, "UPDATE `{$dbPrefix}config` SET `value` = '$auth_code' WHERE name = 'system_auth_code' AND inc_type = 'system'");
  426. }
  427. } else {
  428. mysqli_query($conn, "DELETE FROM `{$dbPrefix}admin` WHERE user_name = '$username'");
  429. }
  430. //插入管理员表ey_admin
  431. $ip = get_client_ip();
  432. $ip = empty($ip) ? "0.0.0.0" : $ip;
  433. $password = md5($auth_code.trim($_POST['manager_pwd']));
  434. mysqli_query($conn, " INSERT INTO `{$dbPrefix}admin` (`user_name`,`true_name`,`password`,`last_login`,`last_ip`,`login_cnt`,`status`,`add_time`) VALUES ('$username','$username','$password','0','$ip','1','1','$time')");
  435. $url = $_SERVER['PHP_SELF']."?step=5";
  436. $arr['code'] = 1;
  437. $arr['msg'] = "安装成功";
  438. $arr['url'] = $url;
  439. echo json_encode($arr);
  440. exit;
  441. case '5':
  442. $ip = get_server_ip();
  443. $host = $_SERVER['HTTP_HOST'];
  444. $create_date = date("Ymdhis");
  445. $time = time();
  446. $phpv = urlencode(phpversion());
  447. $web_server = urlencode($_SERVER['SERVER_SOFTWARE']);
  448. $cms_version = file_get_contents(SITEDIR .'data/conf/version.txt'); // 当前CMS版本
  449. $mt_rand_str = $create_date.sp_random_string(6);
  450. $service_ey = base64_decode(SERVICE_URL);
  451. $ajax_url = 'L2luZGV4LnBocD9tPWFwaSZjPVNlcnZpY2UmYT11c2VyX3B1c2g=';
  452. $str_constant = "<?php".PHP_EOL."define('INSTALL_DATE',".$time.");".PHP_EOL."define('SERIALNUMBER','".$mt_rand_str."');";
  453. @file_put_contents(SITEDIR . 'application/admin/conf/constant.php', $str_constant);
  454. include_once ("./templates/step5.php");
  455. @touch('./install.lock');
  456. exit();
  457. }
  458. function testwrite($d) {
  459. $tfile = "_test.txt";
  460. $fp = @fopen($d . "/" . $tfile, "w");
  461. if (!$fp) {
  462. return false;
  463. }
  464. fclose($fp);
  465. $rs = @unlink($d . "/" . $tfile);
  466. if ($rs) {
  467. return true;
  468. }
  469. return false;
  470. }
  471. function sql_execute($sql, $tablepre) {
  472. $sqls = sql_split($sql, $tablepre);
  473. if (is_array($sqls)) {
  474. foreach ($sqls as $sql) {
  475. if (trim($sql) != '') {
  476. mysqli_query($sql);
  477. }
  478. }
  479. } else {
  480. mysqli_query($sqls);
  481. }
  482. return true;
  483. }
  484. function sql_split($sql, $tablepre) {
  485. /*从安装目录的数据库文件,提取数据库文件里的表前缀*/
  486. $prefix = 'ey_';
  487. preg_match_all('/CREATE\s*TABLE\s*`([^`]+)\s*/', $sql, $matches2);
  488. $datatableList = !empty($matches2[1]) ? $matches2[1] : []; // 数据库所有表名
  489. if (!empty($datatableList)) {
  490. foreach ($datatableList as $key => $val) {
  491. if (preg_match('/_admin$/i', $val)) {
  492. $prefix = preg_replace('/_admin$/i', '', $val).'_';
  493. break;
  494. }
  495. }
  496. }
  497. /*--end*/
  498. if ($tablepre != $prefix)
  499. $sql = str_replace('`'.$prefix, '`'.$tablepre, $sql);
  500. $sql = preg_replace("/TYPE=(InnoDB|MyISAM|MEMORY)( DEFAULT CHARSET=[^; ]+)?/", "ENGINE=\\1 DEFAULT CHARSET=utf8", $sql);
  501. $sql = str_replace("\r", "\n", $sql);
  502. $ret = array();
  503. $num = 0;
  504. $queriesarray = explode(";\n", trim($sql));
  505. unset($sql);
  506. foreach ($queriesarray as $query) {
  507. $ret[$num] = '';
  508. $queries = explode("\n", trim($query));
  509. $queries = array_filter($queries);
  510. foreach ($queries as $query) {
  511. $str1 = substr($query, 0, 1);
  512. if ($str1 != '#' && $str1 != '-')
  513. $ret[$num] .= $query;
  514. }
  515. $num++;
  516. }
  517. return $ret;
  518. }
  519. function _dir_path($path) {
  520. $path = str_replace('\\', '/', $path);
  521. if (substr($path, -1) != '/')
  522. $path = $path . '/';
  523. return $path;
  524. }
  525. // 获取客户端IP地址
  526. function get_client_ip() {
  527. static $ip = NULL;
  528. if ($ip !== NULL)
  529. return $ip;
  530. if (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) {
  531. $arr = explode(',', $_SERVER['HTTP_X_FORWARDED_FOR']);
  532. $pos = array_search('unknown', $arr);
  533. if (false !== $pos)
  534. unset($arr[$pos]);
  535. $ip = trim($arr[0]);
  536. }elseif (isset($_SERVER['HTTP_CLIENT_IP'])) {
  537. $ip = $_SERVER['HTTP_CLIENT_IP'];
  538. } elseif (isset($_SERVER['REMOTE_ADDR'])) {
  539. $ip = $_SERVER['REMOTE_ADDR'];
  540. }
  541. // IP地址合法验证
  542. $ip = (false !== ip2long($ip)) ? $ip : '0.0.0.0';
  543. return $ip;
  544. }
  545. // 服务器端IP
  546. function get_server_ip(){
  547. return gethostbyname($_SERVER["SERVER_NAME"]);
  548. }
  549. function dir_create($path, $mode = 0777) {
  550. if (is_dir($path))
  551. return TRUE;
  552. $ftp_enable = 0;
  553. $path = dir_path($path);
  554. $temp = explode('/', $path);
  555. $cur_dir = '';
  556. $max = count($temp) - 1;
  557. for ($i = 0; $i < $max; $i++) {
  558. $cur_dir .= $temp[$i] . '/';
  559. if (@is_dir($cur_dir))
  560. continue;
  561. @mkdir($cur_dir, 0777, true);
  562. @chmod($cur_dir, 0777);
  563. }
  564. return is_dir($path);
  565. }
  566. function dir_path($path) {
  567. $path = str_replace('\\', '/', $path);
  568. if (substr($path, -1) != '/')
  569. $path = $path . '/';
  570. return $path;
  571. }
  572. function sp_password($pw, $pre){
  573. $decor = md5($pre);
  574. $mi = md5($pw);
  575. return substr($decor,0,12).$mi.substr($decor,-4,4);
  576. }
  577. function sp_random_string($len = 8) {
  578. $chars = array(
  579. "a", "b", "c", "d", "e", "f", "g", "h", "i", "j", "k",
  580. "l", "m", "n", "o", "p", "q", "r", "s", "t", "u", "v",
  581. "w", "x", "y", "z", "A", "B", "C", "D", "E", "F", "G",
  582. "H", "I", "J", "K", "L", "M", "N", "O", "P", "Q", "R",
  583. "S", "T", "U", "V", "W", "X", "Y", "Z", "0", "1", "2",
  584. "3", "4", "5", "6", "7", "8", "9"
  585. );
  586. $charsLen = count($chars) - 1;
  587. shuffle($chars); // 将数组打乱
  588. $output = "";
  589. for ($i = 0; $i < $len; $i++) {
  590. $output .= $chars[mt_rand(0, $charsLen)];
  591. }
  592. return $output;
  593. }
  594. // 递归删除文件夹
  595. function delFile($dir,$file_type='') {
  596. if(is_dir($dir)){
  597. $files = scandir($dir);
  598. //打开目录 //列出目录中的所有文件并去掉 . 和 ..
  599. foreach($files as $filename){
  600. if($filename!='.' && $filename!='..'){
  601. if(!is_dir($dir.'/'.$filename)){
  602. if(empty($file_type)){
  603. unlink($dir.'/'.$filename);
  604. }else{
  605. if(is_array($file_type)){
  606. //正则匹配指定文件
  607. if(preg_match($file_type[0],$filename)){
  608. unlink($dir.'/'.$filename);
  609. }
  610. }else{
  611. //指定包含某些字符串的文件
  612. if(false!=stristr($filename,$file_type)){
  613. unlink($dir.'/'.$filename);
  614. }
  615. }
  616. }
  617. }else{
  618. delFile($dir.'/'.$filename);
  619. rmdir($dir.'/'.$filename);
  620. }
  621. }
  622. }
  623. }else{
  624. if(file_exists($dir)) unlink($dir);
  625. }
  626. }
  627. /**
  628. * 获取当前CMS版本对应的官方远程数据库所有内置表的集合
  629. */
  630. function getRemoteDbTable($version = '')
  631. {
  632. if (empty($version)) {
  633. return false;
  634. }
  635. $service_ey = SERVICE_URL;
  636. $tmp_str = 'L2luZGV4LnBocD9tPWFwaSZjPVNlcnZpY2UmYT1nZXRfZGF0YWJhc2VfdHh0';
  637. $service_url = base64_decode($service_ey).base64_decode($tmp_str);
  638. $url = $service_url . '&version=' . $version;
  639. $context = stream_context_set_default(array('http' => array('timeout' => 3,'method'=>'GET')));
  640. $response = @file_get_contents($url,false,$context);
  641. $params = json_decode($response,true);
  642. if (is_array($params)) {
  643. /*------------------组合官方远程数据库信息----------------------*/
  644. $info = $params['info'];
  645. $info = preg_replace("#[\r\n]{1,}#", "\n", $info);
  646. $infos = explode("\n", $info);
  647. $infolists = [];
  648. foreach ($infos as $key => $val) {
  649. if (!empty($val)) {
  650. $arr = explode('|', $val);
  651. $infolists[$arr[0]] = $val;
  652. }
  653. }
  654. $cms_datatableList = array_keys($infolists);
  655. /*------------------end----------------------*/
  656. return $cms_datatableList;
  657. } else {
  658. return false;
  659. }
  660. }
  661. /**
  662. * 获取当前安装目录下数据库文件的所有内置表的集合
  663. */
  664. function getLocalDbTable($sqldata = '')
  665. {
  666. /*从安装目录的数据库文件,提取出排除插件之外的数据表*/
  667. preg_match_all('/CREATE\s*TABLE\s*`([^`]+)\s*/', $sqldata, $matches2);
  668. $datatableList = !empty($matches2[1]) ? $matches2[1] : []; // 数据库所有表名
  669. if (!empty($datatableList)) {
  670. /*获取数据库文件里的表前缀*/
  671. foreach ($datatableList as $key => $val) {
  672. if (preg_match('/_admin$/i', $val)) {
  673. $old_prefix = preg_replace('/_admin$/i', '', $val).'_';
  674. break;
  675. }
  676. }
  677. /*--end*/
  678. /*过滤插件数据表,只保留与内置数据表*/
  679. $new_datatableList = [];
  680. foreach ($datatableList as $key => $val) {
  681. if (!preg_match('/^'.$old_prefix.'weapp_/i', $val)) {
  682. $new_datatableList[] = preg_replace('/^'.$old_prefix.'/i', 'ey_', $val);
  683. }
  684. }
  685. $datatableList = $new_datatableList;
  686. /*--end*/
  687. }
  688. /*--end*/
  689. return $datatableList;
  690. }
  691. /**
  692. * 密码加密串
  693. */
  694. function get_auth_code($conn, $dbPrefix)
  695. {
  696. $auth_code = '!*&^eyoucms<>|?';
  697. $result = mysqli_query($conn, " SELECT value FROM `{$dbPrefix}config` WHERE name = 'system_auth_code' AND inc_type = 'system' LIMIT 1 ");
  698. if (0 < $result->num_rows) {
  699. while($row = mysqli_fetch_array($result))
  700. {
  701. $auth_code = $row['value'];
  702. }
  703. } else {
  704. $time = time();
  705. mysqli_query($conn, " INSERT INTO `{$dbPrefix}config` (`name`,`value`,`inc_type`,`update_time`) VALUES ('system_auth_code','$auth_code','system','$time')");
  706. }
  707. return $auth_code;
  708. }
  709. ?>