MySQL over SSL

Signed-off-by: Felix <felix.nz@hotmail.de>
This commit is contained in:
Felix
2020-06-08 16:34:49 +02:00
parent 5ee566f9b5
commit 204c5c5f0b
7 changed files with 53 additions and 3 deletions

View File

@@ -40,6 +40,9 @@ Name | Description | Details
**Database** | The name of the database. | Mandatory. **Database** | The name of the database. | Mandatory.
**Username** | The name of the user for the connection. | Optional. **Username** | The name of the user for the connection. | Optional.
**Password** | The password of the user for the connection. | Optional. **Password** | The password of the user for the connection. | Optional.
**SSL CA** | The file path to the SSL certificate authority (relative to Nextcloud serverroot) | Optional.<br/>Requires: SQL driver *mysql*.
**SSL Certificate** | The file path to the SSL certificate (relative to Nextcloud serverroot) | Optional.<br/>Requires: SQL driver *mysql*.
**SSL Key** | The file path to the SSL key (relative to Nextcloud serverroot) | Optional.<br/>Requires: SQL driver *mysql*.
**System wide values** | Place where database connection parameters are stored.<br/>- *true* - config.php (System wide values).<br/>- *false* - database (App values). | Optional.<br/>Default: *false*. **System wide values** | Place where database connection parameters are stored.<br/>- *true* - config.php (System wide values).<br/>- *false* - database (App values). | Optional.<br/>Default: *false*.
#### Options #### Options

View File

@@ -127,6 +127,21 @@ user_sql.adminSettingsUI = function () {
cryptoChanged(); cryptoChanged();
}; };
$("#db-driver").change(function () {
var ssl_ca = $("#db-ssl_ca").parent().parent();
var ssl_cert = $("#db-ssl_cert").parent().parent();
var ssl_key = $("#db-ssl_key").parent().parent();
if ($("#db-driver").val() === 'mysql') {
ssl_ca.show();
ssl_cert.show();
ssl_key.show();
} else {
ssl_ca.hide();
ssl_cert.hide();
ssl_key.hide();
}
});
$("#user_sql-db_connection_verify").click(function (event) { $("#user_sql-db_connection_verify").click(function (event) {
return click(event, "/apps/user_sql/settings/db/verify"); return click(event, "/apps/user_sql/settings/db/verify");
}); });

View File

@@ -32,6 +32,9 @@ final class DB
const DRIVER = "db.driver"; const DRIVER = "db.driver";
const HOSTNAME = "db.hostname"; const HOSTNAME = "db.hostname";
const PASSWORD = "db.password"; const PASSWORD = "db.password";
const SSL_CA = "db.ssl_ca";
const SSL_CERT = "db.ssl_cert";
const SSL_KEY = "db.ssl_key";
const USERNAME = "db.username"; const USERNAME = "db.username";
const GROUP_TABLE = "db.table.group"; const GROUP_TABLE = "db.table.group";

View File

@@ -146,6 +146,9 @@ class SettingsController extends Controller
$dbDatabase = $this->request->getParam("db-database"); $dbDatabase = $this->request->getParam("db-database");
$dbUsername = $this->request->getParam("db-username"); $dbUsername = $this->request->getParam("db-username");
$dbPassword = $this->request->getParam("db-password"); $dbPassword = $this->request->getParam("db-password");
$dbSSL_ca = $this->request->getParam("db-ssl_ca");
$dbSSL_cert = $this->request->getParam("db-ssl_cert");
$dbSSL_key = $this->request->getParam("db-ssl_key");
if (empty($dbDriver)) { if (empty($dbDriver)) {
throw new DatabaseException("No database driver specified."); throw new DatabaseException("No database driver specified.");
@@ -160,9 +163,19 @@ class SettingsController extends Controller
"password" => $dbPassword, "password" => $dbPassword,
"user" => $dbUsername, "user" => $dbUsername,
"dbname" => $dbDatabase, "dbname" => $dbDatabase,
"tablePrefix" => "" "tablePrefix" => "",
"driverOptions" => array()
]; ];
if ($dbDriver == 'mysql') {
if ($dbSSL_ca)
$parameters["driverOptions"][\PDO::MYSQL_ATTR_SSL_CA] = \OC::$SERVERROOT.'/'.$dbSSL_ca;
if ($dbSSL_cert)
$parameters["driverOptions"][\PDO::MYSQL_ATTR_SSL_CERT] = \OC::$SERVERROOT.'/'.$dbSSL_cert;
if ($dbSSL_key)
$parameters["driverOptions"][\PDO::MYSQL_ATTR_SSL_KEY] = \OC::$SERVERROOT.'/'.$dbSSL_key;
}
$connection = $connectionFactory->getConnection($dbDriver, $parameters); $connection = $connectionFactory->getConnection($dbDriver, $parameters);
$connection->executeQuery("SELECT 'user_sql'"); $connection->executeQuery("SELECT 'user_sql'");
@@ -216,6 +229,9 @@ class SettingsController extends Controller
unset($this->properties[DB::PASSWORD]); unset($this->properties[DB::PASSWORD]);
unset($this->properties[DB::USERNAME]); unset($this->properties[DB::USERNAME]);
unset($this->properties[DB::DATABASE]); unset($this->properties[DB::DATABASE]);
unset($this->properties[DB::SSL_CA]);
unset($this->properties[DB::SSL_CERT]);
unset($this->properties[DB::SSL_KEY]);
$this->properties[Opt::SAFE_STORE] = $safeStore; $this->properties[Opt::SAFE_STORE] = $safeStore;
} }

View File

@@ -160,7 +160,7 @@ class Properties implements \ArrayAccess
*/ */
private function isSystemValue($param) private function isSystemValue($param)
{ {
return $this->safeStore && in_array($param, array(DB::HOSTNAME, DB::PASSWORD, DB::USERNAME, DB::DATABASE)); return $this->safeStore && in_array($param, array(DB::HOSTNAME, DB::PASSWORD, DB::USERNAME, DB::DATABASE, DB::SSL_CA, DB::SSL_CERT, DB::SSL_KEY));
} }
/** /**

View File

@@ -145,9 +145,19 @@ class DataQuery
"password" => $this->properties[DB::PASSWORD], "password" => $this->properties[DB::PASSWORD],
"user" => $this->properties[DB::USERNAME], "user" => $this->properties[DB::USERNAME],
"dbname" => $this->properties[DB::DATABASE], "dbname" => $this->properties[DB::DATABASE],
"tablePrefix" => "" "tablePrefix" => "",
"driverOptions" => array()
); );
if ($this->properties[DB::DRIVER] == 'mysql') {
if ($this->properties[DB::SSL_CA])
$parameters["driverOptions"][\PDO::MYSQL_ATTR_SSL_CA] = \OC::$SERVERROOT.'/'.$this->properties[DB::SSL_CA];
if ($this->properties[DB::SSL_CERT])
$parameters["driverOptions"][\PDO::MYSQL_ATTR_SSL_CERT] = \OC::$SERVERROOT.'/'.$this->properties[DB::SSL_CERT];
if ($this->properties[DB::SSL_KEY])
$parameters["driverOptions"][\PDO::MYSQL_ATTR_SSL_KEY] = \OC::$SERVERROOT.'/'.$this->properties[DB::SSL_KEY];
}
$this->connection = $connectionFactory->getConnection( $this->connection = $connectionFactory->getConnection(
$this->properties[DB::DRIVER], $parameters $this->properties[DB::DRIVER], $parameters
); );

View File

@@ -100,6 +100,9 @@ function print_select_options(
print_text_input($l, "db-database", "Database", $_["db.database"]); print_text_input($l, "db-database", "Database", $_["db.database"]);
print_text_input($l, "db-username", "Username", $_["db.username"]); print_text_input($l, "db-username", "Username", $_["db.username"]);
print_text_input($l, "db-password", "Password", $_["db.password"], "password"); print_text_input($l, "db-password", "Password", $_["db.password"], "password");
print_text_input($l, "db-ssl_ca", "SSL CA", $_["db.ssl_ca"]);
print_text_input($l, "db-ssl_cert", "SSL Certificate", $_["db.ssl_cert"]);
print_text_input($l, "db-ssl_key", "SSL Key", $_["db.ssl_key"]);
print_checkbox_input($l, "opt-safe_store", "System wide values", $_["opt.safe_store"]); ?> print_checkbox_input($l, "opt-safe_store", "System wide values", $_["opt.safe_store"]); ?>
<div class="button-right"> <div class="button-right">
<input type="submit" id="user_sql-db_connection_verify" value="<?php p($l->t("Verify settings")); ?>"> <input type="submit" id="user_sql-db_connection_verify" value="<?php p($l->t("Verify settings")); ?>">