#!/bin/sh

set -eu

data_root='/var/lib/postfix-admin-console'
data_directory="${data_root}/data"
secrets_directory="${data_root}/secrets"
database_file="${data_directory}/postfix-admin-console.sqlite"
marker="${data_directory}/.installed"
username_file="${secrets_directory}/username"
password_file="${secrets_directory}/password"
persisted_settings="${secrets_directory}/settings.php"

for path in "${data_root}" "${data_directory}" "${secrets_directory}" "${database_file}" "${marker}" "${username_file}" "${password_file}" "${persisted_settings}"; do
  if [ -L "${path}" ]; then
    echo 'Refusing a symlink in Postfix Admin Console storage.' >&2
    exit 1
  fi
done

install -d -m 0750 -o www-data -g www-data "${data_directory}"
install -d -m 0700 -o root -g root "${secrets_directory}"

if [ -f "${marker}" ] && { [ ! -s "${username_file}" ] || [ ! -s "${password_file}" ]; }; then
  echo 'The initialized demo volume has incomplete stored credentials.' >&2
  exit 1
fi

username_explicit=0
password_explicit=0
if [ "${POSTFIX_ADMIN_CONSOLE_USERNAME+x}" = x ]; then
  username_explicit=1
fi
if [ "${POSTFIX_ADMIN_CONSOLE_PASSWORD+x}" = x ]; then
  password_explicit=1
fi

requested_username="${POSTFIX_ADMIN_CONSOLE_USERNAME-admin}"
requested_password="${POSTFIX_ADMIN_CONSOLE_PASSWORD-}"

has_control_character() {
  newline='
'
  case "$1" in
    *"${newline}"*) return 0 ;;
  esac
  printf '%s' "$1" | LC_ALL=C grep -q '[[:cntrl:]]'
}

if has_control_character "${requested_username}" \
  || has_control_character "${requested_password}"; then
  echo 'The Postfix Admin Console demo credentials must not contain control characters.' >&2
  exit 1
fi

if { [ "${username_explicit}" -eq 1 ] && [ -z "${requested_username}" ]; } \
  || { [ "${password_explicit}" -eq 1 ] && [ -z "${requested_password}" ]; }; then
  echo 'Explicitly configured Postfix Admin Console demo credentials must not be empty.' >&2
  exit 1
fi

if [ -s "${username_file}" ]; then
  stored_username="$(cat "${username_file}")"
  if [ "${username_explicit}" -eq 1 ] && [ "${requested_username}" != "${stored_username}" ]; then
    echo 'POSTFIX_ADMIN_CONSOLE_USERNAME conflicts with the stored demo account.' >&2
    exit 1
  fi
  effective_username="${stored_username}"
else
  effective_username="${requested_username}"
fi

if [ -s "${password_file}" ]; then
  stored_password="$(cat "${password_file}")"
  if [ "${password_explicit}" -eq 1 ] && [ "${requested_password}" != "${stored_password}" ]; then
    echo 'POSTFIX_ADMIN_CONSOLE_PASSWORD conflicts with the stored demo account.' >&2
    exit 1
  fi
  effective_password="${stored_password}"
else
  effective_password="${requested_password}"
  if [ -z "${effective_password}" ]; then
    effective_password="$(php -r 'echo bin2hex(random_bytes(24));')"
  fi
fi

if [ "${effective_username}" = site_owner ]; then
  echo 'POSTFIX_ADMIN_CONSOLE_USERNAME must not use the reserved site_owner account name.' >&2
  exit 1
fi

if [ -z "${effective_username}" ] || [ -z "${effective_password}" ]; then
  echo 'The Postfix Admin Console demo credentials must not be empty.' >&2
  exit 1
fi

if [ ! -s "${username_file}" ]; then
  (umask 077; printf '%s\n' "${effective_username}" > "${username_file}")
fi
if [ ! -s "${password_file}" ]; then
  (umask 077; printf '%s\n' "${effective_password}" > "${password_file}")
fi
chown root:root "${username_file}" "${password_file}"
chmod 0600 "${username_file}" "${password_file}"

export POSTFIX_ADMIN_CONSOLE_USERNAME="${effective_username}"
export POSTFIX_ADMIN_CONSOLE_PASSWORD="${effective_password}"
export POSTFIX_ADMIN_CONSOLE_DATABASE="${database_file}"
export POSTFIX_ADMIN_CONSOLE_INSTALL_MARKER="${marker}"
export POSTFIX_ADMIN_CONSOLE_SETTINGS="${persisted_settings}"

/usr/local/bin/postfix-admin-console-first-install

printf '\nPostfix Admin Console demo credentials\n'
printf 'Login: http://localhost:8080/user/login?destination=/admin/structure/postfix_admin/domain\n'
printf 'Username: %s\n' "${effective_username}"
printf 'Password: %s\n\n' "${effective_password}"

# The password is needed only by the first-install process. Do not let Apache
# or its PHP workers inherit it for the lifetime of the container.
unset POSTFIX_ADMIN_CONSOLE_PASSWORD
unset POSTFIX_ADMIN_CONSOLE_USERNAME POSTFIX_ADMIN_CONSOLE_DATABASE POSTFIX_ADMIN_CONSOLE_INSTALL_MARKER POSTFIX_ADMIN_CONSOLE_SETTINGS

exec /usr/local/bin/docker-php-entrypoint "$@"
