autodiscover.php 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306
  1. <?php
  2. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/lib/vendor/autoload.php';
  3. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/vars.inc.php';
  4. if(file_exists('inc/vars.local.inc.php')) {
  5. include_once 'inc/vars.local.inc.php';
  6. }
  7. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/functions.inc.php';
  8. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/functions.auth.inc.php';
  9. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/sessions.inc.php';
  10. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/functions.mailbox.inc.php';
  11. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/functions.ratelimit.inc.php';
  12. $default_autodiscover_config = $autodiscover_config;
  13. $autodiscover_config = array_merge($default_autodiscover_config, $autodiscover_config);
  14. // Redis
  15. $redis = new Redis();
  16. try {
  17. if (!empty(getenv('REDIS_SLAVEOF_IP'))) {
  18. $redis->connect(getenv('REDIS_SLAVEOF_IP'), getenv('REDIS_SLAVEOF_PORT'));
  19. }
  20. else {
  21. $redis->connect('redis-mailcow', 6379);
  22. }
  23. $redis->auth(getenv("REDISPASS"));
  24. }
  25. catch (Exception $e) {
  26. exit;
  27. }
  28. error_reporting(0);
  29. $data = trim(file_get_contents("php://input"));
  30. if (strpos($data, 'autodiscover/outlook/responseschema') !== false) {
  31. $autodiscover_config['autodiscoverType'] = 'imap';
  32. if ($autodiscover_config['useEASforOutlook'] == 'yes' &&
  33. // Office for macOS does not support EAS
  34. strpos($_SERVER['HTTP_USER_AGENT'], 'Mac') === false &&
  35. // Outlook 2013 (version 15) or higher
  36. preg_match('/(Outlook|Office).+1[5-9]\./', $_SERVER['HTTP_USER_AGENT'])
  37. ) {
  38. $autodiscover_config['autodiscoverType'] = 'activesync';
  39. }
  40. }
  41. if (getenv('SKIP_SOGO') == "y") {
  42. $autodiscover_config['autodiscoverType'] = 'imap';
  43. }
  44. //$dsn = $database_type . ":host=" . $database_host . ";dbname=" . $database_name;
  45. $dsn = $database_type . ":unix_socket=" . $database_sock . ";dbname=" . $database_name;
  46. $opt = [
  47. PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
  48. PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
  49. PDO::ATTR_EMULATE_PREPARES => false,
  50. ];
  51. $pdo = new PDO($dsn, $database_user, $database_pass, $opt);
  52. // Init Identity Provider
  53. $iam_provider = identity_provider('init');
  54. $iam_settings = identity_provider('get');
  55. // Passwordless autodiscover - no authentication required
  56. // Email will be extracted from the request body
  57. $login_user = null;
  58. $login_role = null;
  59. header("Content-Type: application/xml");
  60. echo '<?xml version="1.0" encoding="utf-8" ?>' . PHP_EOL;
  61. ?>
  62. <Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006">
  63. <?php
  64. if(!$data) {
  65. try {
  66. $json = json_encode(
  67. array(
  68. "time" => time(),
  69. "ua" => $_SERVER['HTTP_USER_AGENT'],
  70. "user" => "none",
  71. "ip" => $_SERVER['REMOTE_ADDR'],
  72. "service" => "Error: invalid or missing request data"
  73. )
  74. );
  75. $redis->lPush('AUTODISCOVER_LOG', $json);
  76. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  77. $redis->publish("F2B_CHANNEL", "Autodiscover: Invalid request by " . $_SERVER['REMOTE_ADDR']);
  78. error_log("Autodiscover: Invalid request by " . $_SERVER['REMOTE_ADDR']);
  79. }
  80. catch (RedisException $e) {
  81. $_SESSION['return'][] = array(
  82. 'type' => 'danger',
  83. 'msg' => 'Redis: '.$e
  84. );
  85. return false;
  86. }
  87. list($usec, $sec) = explode(' ', microtime());
  88. ?>
  89. <Response>
  90. <Error Time="<?=date('H:i:s', $sec) . substr($usec, 0, strlen($usec) - 2);?>" Id="<?=rand(1000000000, 9999999999);?>">
  91. <ErrorCode>600</ErrorCode>
  92. <Message>Invalid Request</Message>
  93. <DebugData />
  94. </Error>
  95. </Response>
  96. </Autodiscover>
  97. <?php
  98. exit(0);
  99. }
  100. try {
  101. $discover = new SimpleXMLElement($data);
  102. $email = $discover->Request->EMailAddress;
  103. } catch (Exception $e) {
  104. // If parsing fails, return error
  105. try {
  106. $json = json_encode(
  107. array(
  108. "time" => time(),
  109. "ua" => $_SERVER['HTTP_USER_AGENT'],
  110. "user" => "none",
  111. "ip" => $_SERVER['REMOTE_ADDR'],
  112. "service" => "Error: could not parse email from request"
  113. )
  114. );
  115. $redis->lPush('AUTODISCOVER_LOG', $json);
  116. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  117. $redis->publish("F2B_CHANNEL", "Autodiscover: Malformed XML by " . $_SERVER['REMOTE_ADDR']);
  118. error_log("Autodiscover: Malformed XML by " . $_SERVER['REMOTE_ADDR']);
  119. }
  120. catch (RedisException $e) {
  121. // Silently fail
  122. }
  123. list($usec, $sec) = explode(' ', microtime());
  124. ?>
  125. <Response>
  126. <Error Time="<?=date('H:i:s', $sec) . substr($usec, 0, strlen($usec) - 2);?>" Id="<?=rand(1000000000, 9999999999);?>">
  127. <ErrorCode>600</ErrorCode>
  128. <Message>Invalid Request</Message>
  129. <DebugData />
  130. </Error>
  131. </Response>
  132. </Autodiscover>
  133. <?php
  134. exit(0);
  135. }
  136. $username = trim((string)$email);
  137. try {
  138. $stmt = $pdo->prepare("SELECT `mailbox`.`name`, `mailbox`.`active` FROM `mailbox`
  139. INNER JOIN `domain` ON `mailbox`.`domain` = `domain`.`domain`
  140. WHERE `mailbox`.`username` = :username
  141. AND `mailbox`.`active` = '1'
  142. AND `domain`.`active` = '1'");
  143. $stmt->execute(array(':username' => $username));
  144. $MailboxData = $stmt->fetch(PDO::FETCH_ASSOC);
  145. }
  146. catch(PDOException $e) {
  147. // Database error - return error response with complete XML
  148. list($usec, $sec) = explode(' ', microtime());
  149. ?>
  150. <Response>
  151. <Error Time="<?=date('H:i:s', $sec) . substr($usec, 0, strlen($usec) - 2);?>" Id="<?=rand(1000000000, 9999999999);?>">
  152. <ErrorCode>500</ErrorCode>
  153. <Message>Database Error</Message>
  154. <DebugData />
  155. </Error>
  156. </Response>
  157. </Autodiscover>
  158. <?php
  159. exit(0);
  160. }
  161. // Mailbox not found or not active - return generic error to prevent user enumeration
  162. if (empty($MailboxData)) {
  163. try {
  164. $json = json_encode(
  165. array(
  166. "time" => time(),
  167. "ua" => $_SERVER['HTTP_USER_AGENT'],
  168. "user" => $email,
  169. "ip" => $_SERVER['REMOTE_ADDR'],
  170. "service" => "Error: mailbox not found or inactive"
  171. )
  172. );
  173. $redis->lPush('AUTODISCOVER_LOG', $json);
  174. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  175. $redis->publish("F2B_CHANNEL", "Autodiscover: Invalid mailbox attempt by " . $_SERVER['REMOTE_ADDR']);
  176. error_log("Autodiscover: Invalid mailbox attempt by " . $_SERVER['REMOTE_ADDR']);
  177. }
  178. catch (RedisException $e) {
  179. // Silently fail
  180. }
  181. list($usec, $sec) = explode(' ', microtime());
  182. ?>
  183. <Response>
  184. <Error Time="<?=date('H:i:s', $sec) . substr($usec, 0, strlen($usec) - 2);?>" Id="<?=rand(1000000000, 9999999999);?>">
  185. <ErrorCode>600</ErrorCode>
  186. <Message>Invalid Request</Message>
  187. <DebugData />
  188. </Error>
  189. </Response>
  190. </Autodiscover>
  191. <?php
  192. exit(0);
  193. }
  194. if (!empty($MailboxData['name'])) {
  195. $displayname = $MailboxData['name'];
  196. }
  197. else {
  198. $displayname = $email;
  199. }
  200. try {
  201. $json = json_encode(
  202. array(
  203. "time" => time(),
  204. "ua" => $_SERVER['HTTP_USER_AGENT'],
  205. "user" => $email,
  206. "ip" => $_SERVER['REMOTE_ADDR'],
  207. "service" => $autodiscover_config['autodiscoverType']
  208. )
  209. );
  210. $redis->lPush('AUTODISCOVER_LOG', $json);
  211. $redis->lTrim('AUTODISCOVER_LOG', 0, 100);
  212. }
  213. catch (RedisException $e) {
  214. $_SESSION['return'][] = array(
  215. 'type' => 'danger',
  216. 'msg' => 'Redis: '.$e
  217. );
  218. return false;
  219. }
  220. if ($autodiscover_config['autodiscoverType'] == 'imap') {
  221. ?>
  222. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a">
  223. <User>
  224. <DisplayName><?=htmlspecialchars($displayname, ENT_XML1 | ENT_QUOTES, 'UTF-8');?></DisplayName>
  225. </User>
  226. <Account>
  227. <AccountType>email</AccountType>
  228. <Action>settings</Action>
  229. <Protocol>
  230. <Type>IMAP</Type>
  231. <Server><?=$autodiscover_config['imap']['server'];?></Server>
  232. <Port><?=$autodiscover_config['imap']['port'];?></Port>
  233. <DomainRequired>off</DomainRequired>
  234. <LoginName><?=$email;?></LoginName>
  235. <SPA>off</SPA>
  236. <SSL>on</SSL>
  237. <AuthRequired>on</AuthRequired>
  238. </Protocol>
  239. <Protocol>
  240. <Type>SMTP</Type>
  241. <Server><?=$autodiscover_config['smtp']['server'];?></Server>
  242. <Port><?=$autodiscover_config['smtp']['port'];?></Port>
  243. <DomainRequired>off</DomainRequired>
  244. <LoginName><?=$email;?></LoginName>
  245. <SPA>off</SPA>
  246. <SSL>on</SSL>
  247. <AuthRequired>on</AuthRequired>
  248. <UsePOPAuth>on</UsePOPAuth>
  249. <SMTPLast>off</SMTPLast>
  250. </Protocol>
  251. <?php
  252. if (getenv('SKIP_SOGO') != "y") {
  253. ?>
  254. <Protocol>
  255. <Type>CalDAV</Type>
  256. <Server>https://<?=$autodiscover_config['caldav']['server'];?><?php if ($autodiscover_config['caldav']['port'] != 443) echo ':'.$autodiscover_config['caldav']['port']; ?>/SOGo/dav/<?=$email;?>/</Server>
  257. <DomainRequired>off</DomainRequired>
  258. <LoginName><?=$email;?></LoginName>
  259. </Protocol>
  260. <Protocol>
  261. <Type>CardDAV</Type>
  262. <Server>https://<?=$autodiscover_config['carddav']['server'];?><?php if ($autodiscover_config['caldav']['port'] != 443) echo ':'.$autodiscover_config['carddav']['port']; ?>/SOGo/dav/<?=$email;?>/</Server>
  263. <DomainRequired>off</DomainRequired>
  264. <LoginName><?=$email;?></LoginName>
  265. </Protocol>
  266. <?php
  267. }
  268. ?>
  269. </Account>
  270. </Response>
  271. <?php
  272. }
  273. else if ($autodiscover_config['autodiscoverType'] == 'activesync') {
  274. ?>
  275. <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/mobilesync/responseschema/2006">
  276. <Culture>en:en</Culture>
  277. <User>
  278. <DisplayName><?=htmlspecialchars($displayname, ENT_XML1 | ENT_QUOTES, 'UTF-8');?></DisplayName>
  279. <EMailAddress><?=$email;?></EMailAddress>
  280. </User>
  281. <Action>
  282. <Settings>
  283. <Server>
  284. <Type>MobileSync</Type>
  285. <Url><?=$autodiscover_config['activesync']['url'];?></Url>
  286. <Name><?=$autodiscover_config['activesync']['url'];?></Name>
  287. </Server>
  288. </Settings>
  289. </Action>
  290. </Response>
  291. <?php
  292. }
  293. ?>
  294. </Autodiscover>