X-Git-Url: https://jfr.im/git/uguu.git/blobdiff_plain/d99e1e17e6231ed1199c0ad36776ed391f135a56..95b5e1a7b6f7a88c43c27dcd58ea704436fdd384:/README.md diff --git a/README.md b/README.md index cbec537..0a59c60 100644 --- a/README.md +++ b/README.md @@ -1,48 +1,140 @@ -# About -[Uguu.se](http://uguu.se) source code, stores files and deletes after X amount of time. +# What is Uguu? -# Install -Tested with: -* Nginx+PHP5-FPM (PHP 5.4) on Debian 7 Wheezy -* Apache (PHP 5.4) on Ubuntu 14.04 LTS -* Nginx+PHP5-FPM (PHP 5.6) on Debian 8 Jessie +Uguu is a simple temporary file uploading and sharing platform where files get deleted after X amount of time. -Modify -* Modify includes/core.php where to save files and other paths. -* Set correct paths in several other files. (Will add fix for this via config file instead). -* Change uguu.se to your own name in several files. -* Cron with check.sh: `crontab -e` -* After running `crontab -e`, add `0,15,30,45 * * * * bash /home/neku/www/check.sh`, or read up on how cron works. -* Some extensions are blocked by default, this can be changed via includes/core.php's $block array. -* Everything else to your likings. +## Features -Change php.ini and nginx.conf settings to allow bigger uploads. +- One click uploading, no registration required +- A minimal, modern web interface +- Drag & drop supported +- Upload API with multiple response choices + - JSON + - HTML + - Text + - CSV +- Supports [ShareX](https://getsharex.com/) and other screenshot tools -Make the uguu/ directory modifiable to the nginx user: -`setfacl -m u:www-data:rwx /path/to/uguu/directory/` +### Demo -# Todo +See the real world example at [uguu.se](https://uguu.se). -* Restructure files. -* Make global config file. -* Probably a lot of things but I'm a lazy fuck, come with suggestions. +## Requirements +Original development environment is Nginx + PHP5.3 + SQLite, but is confirmed to +work with Apache 2.4 and newer PHP versions like PHP7.3. -# Using the API +## Install - * Leaving POST value 'name' empty will cause it to save using the original filename. - * Leaving POST value 'randomname' empty will cause it to use original filename or custom name if 'name' is set to file.ext. - - * Putting anything into POST value 'randomname' will cause it to return a random filename + ext (xxxxxx.ext). - * Putting a custom name into POST value 'name' will cause it to return a custom filename (yourpick.ext). - - E.g: - * curl -i -F name=test.jpg -F file=@localfile.jpg http://uguu.se/api.php?d=upload (HTML Response) - * curl -i -F name=test.jpg -F file=@localfile.jpg http://uguu.se/api.php?d=upload-tool (Plain text Response) +For the purposes of this guide, we won't cover setting up Nginx, PHP, SQLite, +Node, or NPM. So we'll just assume you already have them all running well. +### Compiling -This will probably get changed later since it's messy and unpractical. +First you must get a copy of the uguu code. To do so, clone this git repo. +```bash +git clone https://github.com/nokonoko/uguu +``` -# Contact +Assuming you already have Node and NPM working, compilation is easy. -[neku@pomf.se](mailto:neku@pomf.se) or [@Nekunekus](https://twitter.com/nekunekus). +Run the following commands to do so, please configure `dist.json` before you compile. +```bash +cd uguu/ +make +make install +``` +OR +```bash +make install DESTDIR=/desired/path/for/site +``` +After this, the uguu site is now compressed and set up inside `dist/`, or, if specified, `DESTDIR`. + +## Configuring + +Front-end related settings, such as the name of the site, and maximum allowable +file size, are found in `dist.json`. Changes made here will +only take effect after rebuilding the site pages. This may be done by running +`make` from the root of the site directory. + +Back-end related settings, such as database configuration, and path for uploaded files, are found in `static/php/includes/settings.inc.php`. Changes made here take effect immediately. Change the following settings: +```php +define('UGUU_DB_CONN', 'sqlite:/path/to/db/uguu.sq3'); +define('UGUU_FILES_ROOT', '/path/to/file/'); +define('UGUU_URL', 'https://subdomainforyourfiles.your.site'); +``` + +If you intend to allow uploading files larger than 2 MB, you may also need to +increase POST size limits in `php.ini` and webserver configuration. For PHP, +modify `upload_max_filesize` and `post_max_size` values. The configuration +option for nginx webserver is `client_max_body_size`. + +Edit checkdb.sh and checkfiles.sh to the proper paths: +```bash +sqlite3 /path/to/db/uguu.sq3 "DELETE FROM files WHERE date <= strftime('%s', datetime('now', '-1 day'));" +``` +```bash +find /path/to/files/ -mmin +1440 -exec rm -f {} \; +``` +Then add them to your crontab: +```bash +0,30 * * * * bash /path/to/checkfiles.sh +0,30 * * * * bash /path/to/checkdb.sh +``` + +These scripts check if DB entries and files are older then 24 hours and if they are deletes them. + +## MIME/EXT Blocking + +Blocking certain filetypes from being uploaded can be changed by editing the following settings in `static/php/includes/settings.inc.php`: +```php +define('CONFIG_BLOCKED_EXTENSIONS', serialize(['exe', 'scr', 'com', 'vbs', 'bat', 'cmd', 'htm', 'html', 'jar', 'msi', 'apk', 'phtml'])); +define('CONFIG_BLOCKED_MIME', serialize(['application/msword', 'text/html', 'application/x-dosexec', 'application/java', 'application/java-archive', 'application/x-executable', 'application/x-mach-binary'])); +``` + +By default the most common malicious filetypes are blocked. + +## Using SQLite as DB engine + +We need to create the SQLite database before it may be used by uguu. +Fortunately, this is incredibly simple. + +First create a directory for the database, e.g. `mkdir /var/db/uguu`. +Then, create a new SQLite database from the schema, e.g. `sqlite3 /var/db/uguu/uguu.sq3 -init /home/uguu/sqlite_schema.sql`. +Then, finally, ensure the permissions are correct, e.g. +```bash +chown www-data:www-data /var/db/uguu +chmod 0750 /var/db/uguu +chmod 0640 /var/db/uguu/uguu.sq3 +``` + +Finally, edit `php/includes/settings.inc.php` to indicate this is the database engine you would like to use. Make the changes outlined below +```php +define('UGUU_DB_CONN', '[stuff]'); ---> define('UGUU_DB_CONN', 'sqlite:/var/db/uguu/uguu.sq3'); +define('UGUU_DB_USER', '[stuff]'); ---> define('UGUU_DB_USER', null); +define('UGUU_DB_PASS', '[stuff]'); ---> define('UGUU_DB_PASS', null); +``` + +*NOTE: The directory where the SQLite database is stored, must be writable by the web server user* + +## Nginx/Apache + +I won't cover settings everything up, however do NOT allow PHP scripts to be executed on your subdomain serving the files or someone will just upload a PHP shell and PwN you. + +## API +To upload using curl or make a tool you can post using: +``` +curl -i -F files[]=@yourfile.jpeg https://uguu.se/upload.php (JSON Response) +``` + +## Getting help + +Hit me up at [@nekunekus](https://twitter.com/nekunekus) or email me at neku@pomf.se + +## Credits + +Uguu is based off [Pomf](http://github.com/pomf/pomf). + +## License + +Uguu is free software, and is released under the terms of the Expat license. See +`LICENSE`.