grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026#!/bin/sh # Quote CUR_DIR here as well as at every later use: an install path containing # whitespace would otherwise fail at this cd, before any of the password logic # below runs. CUR_DIR=`dirname "$0"` cd "$CUR_DIR" || exit 1 CUR_DIR=`pwd` SUCC=0 cat <:", # so a ':' would terminate the name early and a newline would append a SECOND # credential line. Restrict it to a charset that cannot do either. USER_OK=0 while [ $USER_OK -eq 0 ]; do printf "%s" "User name [admin]: " read -r ADMIN_USER if [ "x$ADMIN_USER" = "x" ]; then ADMIN_USER=admin fi case "$ADMIN_USER" in *[!a-zA-Z0-9_-]*) echo "" echo "[ERROR] Sorry, the user name may only contain letters, digits, '_' and '-'. Try again!" echo "" ;; *) USER_OK=1 ;; esac done cat </cmdline while the process runs. ENCRYPT_PASS=`LSWS_ADMIN_PASS="$PASS_ONE" "$LSWS_PHP" \ -c "$CUR_DIR/php.ini" -q "$CUR_DIR/htpasswd.php"` || ENCRYPT_PASS='' # Reject junk before matching the prefix: a startup warning appended AFTER the # hash still starts with $2y$, so a prefix-only test would accept it. # # The cost is pinned to bcrypt's defined 04-31 range and the length to 60, # rather than accepting any two characters as the cost. Those two together are # what reject a capture that is a valid hash followed by trailing junk drawn # from the bcrypt alphabet -- the negated bracket cannot catch that case, # because every character in it is legal. case "$ENCRYPT_PASS" in *[!./A-Za-z0-9\$]*) _pass_ok=0 ;; '$2y$'0[4-9]'$'*|'$2a$'0[4-9]'$'*|'$2b$'0[4-9]'$'*|\ '$2y$'[12][0-9]'$'*|'$2a$'[12][0-9]'$'*|'$2b$'[12][0-9]'$'*|\ '$2y$'3[01]'$'*|'$2a$'3[01]'$'*|'$2b$'3[01]'$'*) # bcrypt is always 60 chars: 7 prefix and cost, 22 salt, 31 digest. if [ ${#ENCRYPT_PASS} -eq 60 ]; then _pass_ok=1 else _pass_ok=0 fi ;; *) _pass_ok=0 ;; esac # Unlike the installer, aborting here is safe: admpass.sh is standalone with # nothing sequenced after it, so leaving htpasswd untouched preserves the # existing password. if [ $_pass_ok -eq 1 ]; then printf '%s:%s\n' "$ADMIN_USER" "$ENCRYPT_PASS" \ > "$CUR_DIR/../conf/htpasswd" \ && echo "Administrator's username/password is updated successfully!" else echo "[ERROR] Failed to generate the password hash; htpasswd was NOT changed." echo "[ERROR] The previous password (if any) is unchanged." exit 1 fi