Files
wms-app/app/assets/utils/module/mailer.php
T
Thanakorn ae98dcdcdd Harden web root, secrets and realtime auth
- .htaccess: refuse .git, .env, docker, nodejs, sdlc*, scripts, archives and
  app internals; security headers, HSTS over TLS, optional HTTPS redirect
- uploads served through app/file.php to signed-in users only
- Apache/PHP hardening config for the container (ServerTokens, expose_php)
- least-privilege DB account and APP_SECRET_KEY via docker/php/provision.php;
  SMTP passwords re-encrypted with a random IV (secret_box.php)
- Socket.IO rooms from a PHP-signed token; /emit and cron refuse empty secrets
- escape notification text; CLI guards on build scripts; no fixed demo password
2026-09-24 14:53:40 +07:00

165 lines
4.4 KiB
PHP

<?php
use PHPMailer\PHPMailer\PHPMailer;
use PHPMailer\PHPMailer\SMTP;
use PHPMailer\PHPMailer\Exception;
class mailer{
public function __construct($_db){
if( empty($_db["pdo1"]) ){
exit(json_encode(["success"=>0, "message"=>"Error: Developer need to define pdo1 - class mailer"]));
}
$this->pdo1 = $_db["pdo1"];
}
public function get_authen($input = array()){
$revise = [];
$revise["company_id"] = $input["company_id"];
// If SMTP config passed directly, use it (e.g. system default from config.php)
if( !empty($input["smtp"]) && count($input["smtp"]) > 0 ){
return $input["smtp"];
}
// Otherwise read from company_smtp on pdo1 (wms)
$sth = $this->pdo1->prepare("SELECT * FROM company_smtp WHERE company_id = :company_id");
$sth->execute([":company_id" => $revise["company_id"]]);
$res = $sth->fetch(PDO::FETCH_ASSOC);
if( empty($res) ){
$answer = [];
$answer["success"] = 0;
$answer["message"] = "<b>Error:</b> You haven't set SMTP Server yet<br>----------<br>กรุณาตั้งค่า SMTP Server ก่อนส่ง Email";
exit(json_encode($answer));
}
return $res;
}
private function check_required_fields($input=[]){
$revise = [];
$revise["class"] = $input["class"];
$revise["function"] = $input["function"];
$revise["require"] = $input["require"];
$revise["input"] = $input["input"];
foreach ($revise["require"] as $key => $item) {
if( !isset($revise["input"][$item]) ){
exit(json_encode(["success"=>0, "message"=>"Error: class {$revise["class"]}->{$revise["function"]} => {$item} cannot be empty"]));
}
}
}
private function decrypt($input){
$this->check_required_fields([
"class" => "mailer",
"function" => "decrypt",
"require" => ["key","data"],
"input" => $input
]);
require_once __DIR__ . '/../secret_box.php';
return secret_decrypt((string)$input["data"], (string)$input["key"]);
}
public function send_email($input = array()){
$this->check_required_fields([
"class" => "mailer",
"function" => "send_email",
"require" => ["subject","message","company_id"],
"input" => $input
]);
// When silent=true, return false on failure instead of calling exit().
$silent = !empty($input['silent']);
$revise = [];
$revise["subject"] = $input["subject"];
$revise["message"] = $input["message"];
$revise["channel_name"] = $input["channel_name"];
$revise["to"] = $input["to"];
$revise["key"] = $input["key"];
$company_id = $input["company_id"];
$authen = $this->get_authen($input);
require_once dirname(__FILE__).'/phpmailer/vendor/autoload.php';
$mail = new PHPMailer(true);
try {
$mail->SMTPDebug = false;
$mail->isSMTP();
$mail->CharSet = "UTF-8";
$mail->Host = $authen["server"];
$mail->SMTPAuth = true;
$mail->Timeout = 20;
$mail->Username = $authen["username"];
$mail->Password = $this->decrypt(["data"=>$authen["password"],"key"=>$revise["key"]]);
$port = (string)$authen["port"];
if ($port === "465") {
$mail->SMTPSecure = PHPMailer::ENCRYPTION_SMTPS;
} elseif ($port === "587" || $port === "25") {
$mail->SMTPSecure = PHPMailer::ENCRYPTION_STARTTLS;
} else {
$mail->SMTPSecure = PHPMailer::ENCRYPTION_STARTTLS;
}
$mail->Port = $authen["port"];
$mail->SMTPOptions = [
'socket' => ['bindto' => '0.0.0.0:0']
];
// Sender
$from_email = !empty($authen["from_email"]) ? $authen["from_email"] : $authen["username"];
$from_name = !empty($revise["channel_name"]) ? $revise["channel_name"]
: (!empty($authen["from_name"]) ? $authen["from_name"] : $authen["username"]);
$mail->setFrom($from_email, $from_name);
$des = explode(",", $revise["to"]);
foreach ($des as $key => $value) {
$mail->addAddress(trim($value));
}
$mail->isHTML(true);
$mail->Subject = $revise["subject"];
$mail->Body = nl2br($revise["message"]);
$mail->AltBody = $revise["message"];
$mail->send();
return true;
}
catch (phpmailerException $e) {
$err = "<b>Error1</b>: " . nl2br($e->errorMessage());
if ($silent) { error_log('[mailer] ' . strip_tags($err)); return false; }
exit(json_encode(["success" => 0, "message" => $err]));
}
catch (Exception $e) {
$err = "<b>Error2</b>: " . nl2br($mail->ErrorInfo);
if ($silent) { error_log('[mailer] ' . strip_tags($err)); return false; }
exit(json_encode(["success" => 0, "message" => $err]));
}
}
}
?>