Files
OpenDRS/install.sh

654 lines
25 KiB
Bash

#!/bin/bash
# install.sh
# OpenDRS Online Discrepancy Reporting System
# Copyright (C) 2024 Rod Wright
# SPDX-License-Identifier: GPL-2.0
DRS_VERSION="1.4.2"
DOC_ROOT="/var/www"
INSTALL_LOC="opendrs"
APACHE_USER="www-data"
APACHE_GROUP="www-data"
APACHE_CONF_DIR="/etc/apache2/conf-available"
BACKUP_DIR="opendrs-previous-installation"
# test for superuser rights
if [[ $EUID -ne 0 ]]; then
echo "This script must be run with superuser privileges. Try sudo ./install.sh"
exit 1
fi
# Prevent unattended-upgrades from interfering
restart_uu=false
while systemctl status unattended-upgrades >/dev/null 2>&1
do
systemctl stop unattended-upgrades
sleep 5
restart_uu=true
done
echo ""
echo ""
echo "* * * * * Welcome to OpenDRS $DRS_VERSION Installation * * * * *"
echo ""
echo ""
echo "Just press enter at the prompts to accept the defaults shown."
echo ""
# Check for prerequisites and prompt to install
echo "Checking for prerequisites..."
echo ""
echo ""
echo " Checking for apache2 installation..."
echo ""
if dpkg -l|grep apache2 >/dev/null 2>&1
then
echo ""
echo "apache2 is installed. Continuing."
echo ""
else
echo "OpenDRS requires the apache2 http server, but it doesn't seem"
echo -n "to be installed. Install it now? [Y/n]: "
read reqinstall
if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ]
then
echo "OpenDRS requires apache2, but you have elected not to install it."
echo "Installation cannot continue."
exit 1
else
echo ""
echo "###################################################################"
echo ""
echo "Proceeding with apache2 installation"
echo ""
echo "###################################################################"
sleep 3
apt-get install -y apache2
echo ""
echo "###################################################################"
echo ""
echo "Finished with apache2 installation"
echo ""
echo "###################################################################"
sleep 3
fi
fi
echo ""
echo " Checking for php installation..."
echo ""
if dpkg -l|grep php >/dev/null 2>&1
then
echo ""
echo "php is installed. Continuing."
echo ""
else
echo ""
echo ""
echo "OpenDRS requires php, but it doesn't seem to be installed."
echo -n "Install it now? [Y/n]: "
read reqinstall
if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ]
then
echo "OpenDRS requires php, but you have elected not to install it."
echo "Installation cannot continue."
exit 1
else
echo ""
echo "###################################################################"
echo ""
echo "Proceeding with php installation"
echo ""
echo "###################################################################"
sleep 3
apt-get install -y php
echo ""
echo "###################################################################"
echo ""
echo "Finished with php installation"
echo ""
echo "###################################################################"
sleep 3
fi
fi
echo ""
echo " Checking for mariadb or mysql installation..."
echo ""
if dpkg -l|grep mariadb-server >/dev/null 2>&1
then
echo ""
echo "mariadb-server is installed. Continuing."
echo ""
elif dpkg -l|grep mysql-server >/dev/null 2>&1
then
echo ""
echo "mysql-server is installed. Continuing."
echo ""
else
echo ""
echo ""
echo "OpenDRS requires either mariadb or mysql server, but neither seem"
echo -n "to be installed. Install mariadb-server now? [Y/n]: "
read reqinstall
if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ]
then
echo "OpenDRS requires either mariadb or mysql server, but you have elected not to install it."
echo "Installation cannot continue."
exit 1
else
echo ""
echo "###################################################################"
echo ""
echo "Proceeding with mariadb-server installation"
echo ""
echo "###################################################################"
sleep 3
apt-get install -y mariadb-server
echo ""
echo "###################################################################"
echo ""
echo "Finished with mariadb-server installation"
echo ""
echo "###################################################################"
sleep 3
echo ""
echo "###################################################################"
echo ""
echo "Proceeding with mariadb configuration"
echo ""
echo "###################################################################"
sleep 3
echo ""
echo "Configuring the MariaDB installation. There will be some more prompts:"
echo ""
echo "- You'll be prompted for the current password for the root user. You've"
echo " just installed MariaDB and you haven't set one yet, so just press enter."
echo ""
echo "- You'll be prompted to switch to unix_socket authentication. Answer Y."
echo ""
echo "- You'll be prompted to change the root password. Answer Y and enter a password."
echo " Note that this is just the password for the MariaDB root user, not the root login."
echo " DO NOT FORGET THIS PASSWORD. You'll need it later during OpenDRS install."
echo ""
echo "- Answer Y to remove anonymous users, disallow root login remotely, remove"
echo " test database and access, and reload privilege tables."
echo ""
echo -n "Press enter to proceed."
read continueok
echo ""
mysql_secure_installation
echo ""
echo "###################################################################"
echo ""
echo "Finished with mariadb configuration."
echo ""
echo "###################################################################"
sleep 3
fi
fi
echo ""
echo " Checking for phpmyadmin installation..."
echo ""
if dpkg -l|grep phpmyadmin >/dev/null 2>&1
then
echo ""
echo "phpmyadmin is installed. Continuing."
echo ""
else
echo "phpmyadmin is optional, but doesn't seem to be installed."
echo "It is an optional package that enables administration of the mysql/mariadb"
echo "database server using a friendly GUI. It is highly recommended."
echo "Note that this has the potential to be a security risk, especially"
echo "if your passwords aren't sufficiently strong."
echo -n "Install it now? [Y/n]: "
read reqinstall
if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ]
then
echo "Proceeding without installing phpmyadmin. Database administration"
echo "will require the use of the mysql/mariadb command line tools."
else
echo ""
echo "###################################################################"
echo ""
echo "Proceeding with phpmyadmin installation"
echo ""
echo "###################################################################"
sleep 3
echo ""
echo "During the following installation of phpmyadmin:"
echo ""
echo "- Select apache2 as the web server to configure automatically."
echo ""
echo "- Choose Yes when prompted to install phpmyadmin database and allow it to"
echo " generate a random password(leave the field blank)."
echo ""
echo -n "Press enter to continue."
read continueok
echo ""
apt-get install -y phpmyadmin
echo ""
echo ""
echo "You can now access phpmyadmin using a web browser pointed to:"
echo "http://$HOSTNAME/phpmyadmin"
echo "*** WARNING!! this url is accessible via unencrypted (http), not"
echo "encrypted SSL (https) connections. This is a huge security risk"
echo "since the username and password you enter will be sent in the"
echo "clear for any potential attacker to sniff! You should enable"
echo "redirection to https for phpmyadmin in your apache2 configuration."
echo ""
echo -n "Press enter to continue."
read continueok
echo ""
echo "###################################################################"
echo ""
echo "Finished with phpmyadmin installation"
echo ""
echo "###################################################################"
sleep 3
fi
fi
echo ""
echo " Checking for webmin installation..."
echo ""
if dpkg -l|grep webmin >/dev/null 2>&1
then
echo ""
echo "webmin is installed. Continuing."
echo ""
else
echo "webmin is optional, but doesn't seem to be installed."
echo "It is an optional package that enables system administration"
echo "using a friendly GUI. It is highly recommended, especially for"
echo "headless servers without any way to log in directly on the machine."
echo "Note that this has the potential to be a security risk, especially"
echo "if your passwords aren't sufficiently strong."
echo -n "Install it now? [Y/n]: "
read reqinstall
if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ]
then
echo "Proceeding without installing webmin. System administration"
echo "will require login to the server either directly or via ssh."
else
echo ""
echo "###################################################################"
echo ""
echo "Proceeding with webmin installation"
echo ""
echo "###################################################################"
sleep 3
echo "Installing webmin..."
skipwebmin="false"
if ! curl -o setup-repos.sh https://raw.githubusercontent.com/webmin/webmin/master/setup-repos.sh
then
echo "Warning: failed to download Webmin repo setup script."
echo -n "Ignore and [c]ontinue or [A]bort? [c/A]: "
read wmfailchoice
if [ "$wmfailchoice" = "C" -o "$wmfailchoice" = "c" ]
then
skipwebmin="true"
echo "Continuing without installing Webmin. You should investigate the failure"
echo "and install Webmin manually after the server is set up if you would like"
echo "to be able to manage the server from another computer with a GUI instead"
echo "of through ssh only."
echo -n "Press enter to continue."
read continueok
echo ""
fi
fi
if [ "$skipwebmin" = "false" ]
then
sh setup-repos.sh -f
apt-get install -y --install-recommends webmin
fi
echo "...done."
echo ""
echo "You can now access webmin using a web browser pointed to:"
echo "https://$HOSTNAME:10000"
echo "Unless you have obtained valid ssl certificates, your server is"
echo "using self-signed certs. This is not necessarily a problem, but"
echo "your browser will complain. You can tell the browser to accept the"
echo "self signed certificates and the traffic will still be encrypted,"
echo "however you may be vulnerable to man-in-the-middle attacks. You can"
echo "get free valid certificates through LetsEncrypt."
echo "See http://letsencrypt.org for more information."
echo ""
echo -n "Press enter to continue."
read continueok
echo ""
echo "###################################################################"
echo ""
echo "Finished with webmin installation"
echo ""
echo "###################################################################"
sleep 3
fi
fi
echo ""
echo " Checking for uuidgen installation..."
echo ""
if uuidgen 2>&1
then
echo ""
echo "uuidgen is installed. Continuing."
echo ""
else
echo ""
echo ""
echo "OpenDRS requires uuidgen, but it doesn't seem to be installed."
echo -n "Install it now? [Y/n]: "
read reqinstall
if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ]
then
echo "OpenDRS requires uuidgen, but you have elected not to install it."
echo "Installation cannot continue."
exit 1
else
echo ""
echo "###################################################################"
echo ""
echo "Proceeding with uuidgen installation"
echo ""
echo "###################################################################"
sleep 3
apt-get install -y uuid-runtime
echo ""
echo "###################################################################"
echo ""
echo "Finished with uuidgen installation"
echo ""
echo "###################################################################"
sleep 3
fi
fi
echo ""
echo ""
echo "Finished checking for and installing prerequisites..."
echo ""
echo ""
sleep 3
# prompt for install location
echo "Where would you like to install this version of OpenDRS? This should"
echo "be somewhere the webserver can find it. If you don't know, refer to the"
echo "webserver's documentation and check the server's configuration files."
echo "Note that this is where the directory containing OpenDRS's files will be"
echo "created."
echo -n "Enter the webserver's install location [$DOC_ROOT]:"
read doc_root_in
echo ""
echo -n "Enter name of OpenDRS installation directory [$INSTALL_LOC] :"
read install_loc_in
echo ""
if [ "$doc_root_in" = "" ]
then
doc_root_in=$DOC_ROOT
fi
if [ "$install_loc_in" = "" ]
then
install_loc_in=$INSTALL_LOC
fi
install_path="$doc_root_in/$install_loc_in"
if [ -d "$install_path" ]
then
# Install path exists.
if [ -e "$install_path/db.php" ]
then
# A db.php file was found in the install path
if grep -q -e "OpenDRS" -e "OpenMTS" $install_path/db.php
then
# the db.php file is part of an OpenDRS/OpenMTS installation
echo "The installation path you chose already exists."
echo "Would you like to upgrade an existing installation or cancel "
echo "and restart the install using a new installation location."
echo -n "[U]pgrade or [C]ancel? [C] :"
read upgrade_choice
if [ "$upgrade_choice" = "U" -o "$upgrade_choice" = "u" ] # Upgrade chosen
then
# proceed with upgrade
operation="upgraded"
# back up existing database
echo "Backing up the current database to the package directory."
curr_dbname=`grep dbname $install_path/db.php | head -1 | cut -d "\"" -f2`
curr_username=`grep username $install_path/db.php | head -1 | cut -d "\"" -f2`
curr_dbpass=`grep dbpass $install_path/db.php | head -1 | cut -d "\"" -f2`
export MYSQL_PWD="$curr_dbpass"
mysqldump --no-tablespaces -u"$curr_username" $curr_dbname > $curr_dbname-`date +%Y-%m-%d_%H:%M:%S`-backup.sql
# back up existing installation
echo "Backing up current installation to the package directory."
cp -R $install_path $install_loc_in-`date +%Y-%m-%d_%H:%M:%S`-backup
# delete all existing installation files except db.php
find $install_path/ -mindepth 1 -not -name 'db.php' -delete
# apply database updates
mysql -u"$curr_username" -f -D $curr_dbname < opendrs-update.sql >/dev/null 2>&1
# apply updates to existing db.php
bash ./opendrs-update.sh $install_path
# copy distribution to install location
echo "Installing distribution . . ."
cp -R distfiles/* $install_path
if [ ! -L "$install_path/jquery-ui" ]
then
ln -s $install_path/jquery-ui* $install_path/jquery-ui
fi
if [ ! -L "$install_path/index.php" ]
then
ln -s $install_path/writeups.php $install_path/index.php
fi
# set ownership
echo "In order to set the ownership correctly, we need to know the user and"
echo "group that the webserver expects its files to be owned by. This is"
echo "usually not the root account. Refer to the ownership of other files in"
echo "your webserver's document tree to see what this should be."
echo "Enter the user and group separated by a colon (username:groupname)."
echo "Enter the user:group of the OpenDRS installation"
echo -n "directory [$APACHE_USER:$APACHE_GROUP] :"
read httpd_user_group
if [ "$httpd_user_group" = "" ]
then
httpd_user_group="$APACHE_USER:$APACHE_GROUP"
fi
echo ""
echo "Setting file ownership . . ."
chown -R $httpd_user_group $install_path
else
echo "Cancelling installation"
exit
fi
else
# This was a mistake. Exit now to avoid clobbering another app.
echo "The installation directory you chose exists, but no previous installation"
echo "of OpenDRS was found. Please investigate the situation. Aborting now."
exit 1
fi
else
# This was a mistake. Exit now to avoid clobbering another app.
echo "The installation directory you chose exists, but no previous installation"
echo "of OpenDRS was found. Please investigate the situation. Aborting now."
exit 1
fi
else
# This is a fresh install
operation="installed"
# prompt for mysql information
bad_mysql_adm=true
while $bad_mysql_adm
do
admintestdb="drsadm`date +%Y%m%d`"
echo "We need to know the username and password of a MySQL administrator"
echo "to be able to create the database and user for OpenDRS. Note that this"
echo "is not necessarily the same as the login and password for the computer."
echo -n "MySQL admin username: "
read mysql_adm_user
echo ""
echo -n "MySQL admin password: "
read -s mysql_adm_pass
export MYSQL_PWD="$mysql_adm_pass"
if mysql -u"$mysql_adm_user" -e "create database $admintestdb;drop database $admintestdb"
then
bad_mysql_adm=false
else
echo "ERROR: Either the username/password you supplied were incorrect or the user"
echo -n "is not a MySQL administrator. Try again? [Y/N]: "
read admtry
if [ "$admtry" != "Y" -o "$admtry" != "y" ]
then
exit
fi
fi
done
echo ""
echo "What would you like to call this installation of OpenDRS? If you accept"
echo "the default, it will be called OpenDRS. If you will be running multiple"
echo "instances of OpenDRS on this server, you should choose a distinctive name."
echo "This can be changed later in the application itself."
echo -n "Installation name [OpenDRS]: "
read new_inst_name
if [ "$new_inst_name" = "" ]
then
new_inst_name="OpenDRS"
fi
echo ""
# Create initial database
db_create_fail=true
while $db_create_fail
do
echo "What would you like to call the database for this installation of OpenDRS?"
echo "If you accept the default, it will be called opendrs. Again, this is fine"
echo "if you will only be running this one instance, but if you will be running"
echo "multiple instances of OpenDRS on this server, you should choose a "
echo "distinctive name."
echo -n "database name [opendrs]: "
read new_db_name
if [ "$new_db_name" = "" ]
then
new_db_name=opendrs
fi
echo ""
export MYSQL_PWD="$mysql_adm_pass"
if mysql -u"$mysql_adm_user" -e "create database $new_db_name"
then
db_create_fail=false
else
echo "An error was encountered when trying to create the database."
echo "This probably means the database already exists."
echo -n "Try again with a different database name? [Y/N]: "
read dbcreatetry
if [ "$dbcreatetry" != "Y" -o "$dbcreatetry" != "y" ]
then
exit
fi
fi
done
# Create user and give rights to database
drs_user="$new_db_name`date +%Y%m%d%H%M%S`"
drs_pass=`uuidgen`
export MYSQL_PWD="$mysql_adm_pass"
mysql -u"$mysql_adm_user" -e "create user if not exists '$drs_user'@'localhost' identified by '$drs_pass'"
mysql -u"$mysql_adm_user" -e "grant all on $new_db_name.* to '$drs_user'@'localhost'"
mysql -u"$mysql_adm_user" -e "flush privileges"
# Populate initial database
mysql -u"$mysql_adm_user" $new_db_name < opendrs-initial.sql
# Set the installation name
export MYSQL_PWD="$drs_pass"
mysql -u"$drs_user" $new_db_name -e "update config set value=\"$new_inst_name\",defaultvalue=\"$new_inst_name\" where name=\"app_name\""
# Create install path
echo "Creating installation directory . . ."
mkdir $install_path
# Create db.php if it doesn't exist
if [ ! -f "$install_path/db.php" ]
then
cp db.php.template $install_path/db.php
sed -i "s/DBNAME/$new_db_name/g" $install_path/db.php
sed -i "s/DBUSER/$drs_user/g" $install_path/db.php
sed -i "s/DBPASS/$drs_pass/g" $install_path/db.php
fi
# copy distribution to install location
echo "Installing distribution . . ."
cp -R distfiles/* $install_path
if [ ! -L "$install_path/jquery-ui" ]
then
ln -s $install_path/jquery-ui* $install_path/jquery-ui
fi
if [ ! -L "$install_path/index.php" ]
then
ln -s $install_path/writeups.php $install_path/index.php
fi
# set ownership
echo "In order to set the ownership correctly, we need to know the user and"
echo "group that the webserver expects its files to be owned by. This is"
echo "usually not the root account. Refer to the ownership of other files in"
echo "your webserver's document tree to see what this should be."
echo "Enter the user and group separated by a colon (username:groupname)."
echo "Enter the user:group of the OpenDRS installation"
echo -n "directory [$APACHE_USER:$APACHE_GROUP] :"
read httpd_user_group
if [ "$httpd_user_group" = "" ]
then
httpd_user_group="$APACHE_USER:$APACHE_GROUP"
fi
echo ""
echo "Setting file ownership . . ."
chown -R $httpd_user_group $install_path
fi
echo ""
# tell user to launch web browser to continue
echo ""
echo ""
echo ""
echo "OpenDRS has been $operation."
base_url=$install_loc_in
if [ "$operation" = "installed" ]
then
echo "# OpenDRS default Apache configuration" > $APACHE_CONF_DIR/$base_url.conf
echo "" >> $APACHE_CONF_DIR/$base_url.conf
echo "Alias /$base_url $doc_root_in/$base_url" >> $APACHE_CONF_DIR/$base_url.conf
echo "" >> $APACHE_CONF_DIR/$base_url.conf
echo "<Directory $doc_root_in/$base_url>" >> $APACHE_CONF_DIR/$base_url.conf
echo " Options FollowSymLinks" >> $APACHE_CONF_DIR/$base_url.conf
echo " DirectoryIndex index.php" >> $APACHE_CONF_DIR/$base_url.conf
echo "</Directory>" >> $APACHE_CONF_DIR/$base_url.conf
echo -n "The apache2 $base_url configuration must be enabled. Would you like to do that now? [Y] :"
read enconf
if [ "$enconf" = "" -o "$enconf" = "Y" -o "$enconf" = "y" ]
then
a2enconf $base_url.conf >/dev/null
service apache2 reload
echo "You can now point a web browser to $base_url on your web server "
echo "to set up and configure OpenDRS."
echo ""
echo "IMPORTANT: The default login credentials for the initial admin user are:"
echo ""
echo "login: drsadmin"
echo "password: OpenDRS-1"
echo ""
echo "Remember these credentials. Otherwise, you will not be able to log in and"
echo "configure your new installation."
echo "It is highly recommended that you change the initial password to something"
echo "secure after logging in for the first time."
else
echo "You will need to manually enable the configuration by executing:"
echo " a2enconf $base_url.conf"
echo " service apache2 reload"
echo "as a superuser before it can be accessed."
fi
else
echo "You can now point a web browser to $base_url on your web server "
echo "to use your upgraded OpenDRS."
fi
# Re-enable unattended-upgrades
if $restart_uu; then systemctl start unattended-upgrades; fi