Linux cesa-www-main 6.1.0-49-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.174-1 (2026-05-26) x86_64
Apache/2.4.68 (Debian)
Server IP : 10.218.0.2 & Your IP : 216.73.216.28
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
var /
www /
cesa.co.za /
php /
includes /
Delete
Unzip
Name
Size
Permission
Date
Action
error_handling
[ DIR ]
drwxr-sr-x
2025-07-07 15:54
mail
[ DIR ]
drwxr-sr-x
2025-06-14 11:17
ADQAnswers.php
3.16
KB
-rw-r--r--
2026-06-03 05:55
ADQAudit.php
6.51
KB
-rw-r--r--
2026-06-03 05:55
ADQAuditAnswers.php
1.21
KB
-rw-r--r--
2026-06-03 05:55
ADQFirms.php
18.41
KB
-rw-r--r--
2025-12-31 10:56
ADQuestionnairesAnswers.php
1.05
KB
-rw-r--r--
2026-06-03 05:55
ADQuestionnairesAudit.php
2.01
KB
-rw-r--r--
2026-06-03 05:55
ADecQuestionnaires.php
3.31
KB
-rw-r--r--
2026-06-03 05:55
ADecQuestions.php
541
B
-rw-r--r--
2026-06-03 05:55
ADec_Contacts.php
1.61
KB
-rw-r--r--
2026-06-03 05:55
ADec_OfficeContacts.php
7.43
KB
-rw-r--r--
2026-06-03 05:55
ADec_PIUnderwriters.php
742
B
-rw-r--r--
2026-06-03 05:55
ADec_Transformation.php
817
B
-rw-r--r--
2026-06-03 05:55
ADec_tblMemberFirmOffices.php
1.49
KB
-rw-r--r--
2026-06-03 05:55
ADec_tblMemberFirmSkills.php
2.38
KB
-rw-r--r--
2026-06-03 05:55
ADec_tblMemberFirms.php
19.37
KB
-rw-r--r--
2026-06-03 05:55
AnonRespondees.php
4.25
KB
-rw-r--r--
2026-06-05 11:41
AwardsEntries.php
2.4
KB
-rw-r--r--
2026-06-06 10:48
BaseTableClass.php
950
B
-rw-r--r--
2026-04-26 08:24
BatchJob.php
4.46
KB
-rw-r--r--
2026-06-03 05:55
BceAssignmentFeedbackFormsReportService.php
6.77
KB
-rw-r--r--
2026-05-25 13:06
CCEAssignment.php
12.44
KB
-rw-r--r--
2026-05-26 14:26
CCEAssignmentMarking.php
26.26
KB
-rw-r--r--
2026-08-14 12:06
CCEBooks.php
524
B
-rw-r--r--
2026-06-03 05:55
CCEConvenorAuth.php
3.06
KB
-rw-r--r--
2026-08-19 11:18
CCECourseSchedules.php
579
B
-rw-r--r--
2026-06-03 05:55
CCEDocCategories.php
529
B
-rw-r--r--
2026-06-03 05:55
CCEDocuments.php
8.15
KB
-rw-r--r--
2026-08-20 12:16
CCEExam.php
15.87
KB
-rw-r--r--
2026-06-03 06:35
CCEExamQuestion.php
1.76
KB
-rw-r--r--
2026-06-03 05:55
CCEFacilitatorUser.php
931
B
-rw-r--r--
2026-06-03 05:55
CCEMessageLog.php
951
B
-rw-r--r--
2026-06-03 05:55
CCEMessages.php
8.88
KB
-rw-r--r--
2026-07-01 13:20
CCEModuleMarksService.php
7.16
KB
-rw-r--r--
2026-05-26 10:30
CCEModules.php
1.16
KB
-rw-r--r--
2026-06-03 05:55
CCEResourceGroups.php
591
B
-rw-r--r--
2026-06-03 05:55
CCEResources.php
896
B
-rw-r--r--
2026-06-03 05:55
CCESetup.php
256
B
-rw-r--r--
2026-02-09 16:20
CCEStAssigExtension.php
2.07
KB
-rw-r--r--
2026-06-03 05:55
CCEStAssigExtensionRequest.php
6.65
KB
-rw-r--r--
2026-06-03 05:55
CCEStudentAssignment.php
16.61
KB
-rw-r--r--
2026-07-15 14:44
CCEStudentCourses.php
611
B
-rw-r--r--
2026-06-03 05:55
CCEStudentDisplayOrder.php
4.96
KB
-rw-r--r--
2026-05-26 09:32
CCEStudents.php
8.4
KB
-rw-r--r--
2026-08-19 11:18
CCETemplates.php
896
B
-rw-r--r--
2026-06-03 05:55
CCEWeeklySessions.php
2.27
KB
-rw-r--r--
2026-02-09 16:25
CPDSPReview.php
624
B
-rw-r--r--
2026-06-03 05:55
CPDServiceProvider.php
4.57
KB
-rw-r--r--
2026-06-12 11:48
CPDTrainingMaterial.php
3.96
KB
-rw-r--r--
2026-06-12 11:48
CceUploadedFileService.php
34.9
KB
-rw-r--r--
2026-06-24 12:03
Certificates.php
8.93
KB
-rw-r--r--
2026-08-18 15:42
Contact.php
690
B
-rw-r--r--
2026-06-03 05:55
ErrorLog.php
1.22
KB
-rw-r--r--
2026-08-24 10:12
EventSchedules.php
5.39
KB
-rw-r--r--
2025-12-20 10:03
FileUploads.php
2.1
KB
-rw-r--r--
2026-06-03 05:55
HTMLHelper.php
17.2
KB
-rw-r--r--
2026-06-03 05:55
KeyValue.php
4.9
KB
-rw-r--r--
2026-04-25 09:34
Mailer.php
12.78
KB
-rw-r--r--
2026-07-15 09:50
MarketingAttendees.php
36.87
KB
-rw-r--r--
2026-08-14 12:06
MarketingPayments.php
2.52
KB
-rw-r--r--
2026-06-03 05:55
MemberContact.php
1.04
KB
-rw-r--r--
2026-06-03 05:55
MemberFirm.php
17.71
KB
-rw-r--r--
2026-06-03 05:55
MemberFirmOffices.php
752
B
-rw-r--r--
2026-06-03 05:55
MemberFirmSkill.php
18.04
KB
-rw-r--r--
2026-06-03 05:55
MemberPortalTransformationProxy.php
4.44
KB
-rw-r--r--
2026-05-20 09:08
MemberPortalUrls.php
1.82
KB
-rw-r--r--
2026-05-20 09:53
MsgAttachFileService.php
4.92
KB
-rw-r--r--
2026-06-22 08:37
OfficeContact.php
1.01
KB
-rw-r--r--
2026-06-03 05:55
Picklists.php
539
B
-rw-r--r--
2026-06-03 05:55
Questionnaires.php
849
B
-rw-r--r--
2026-01-23 12:39
SchoolAttendeeBulkMailerService.php
34.26
KB
-rw-r--r--
2026-08-11 10:45
SchoolAttendees.php
73.21
KB
-rw-r--r--
2026-08-11 10:45
SchoolCourses.php
7.98
KB
-rw-r--r--
2026-08-19 11:59
SchoolEvents.php
45.54
KB
-rw-r--r--
2026-08-18 15:42
SchoolPayments.php
4.48
KB
-rw-r--r--
2026-04-13 09:33
SchoolPresenters.php
1.86
KB
-rw-r--r--
2026-01-23 12:43
SchoolWeeksCoursesDashboardProxy.php
10.69
KB
-rw-r--r--
2026-08-14 12:32
TrainingProvider.php
8.06
KB
-rw-r--r--
2026-01-23 12:43
TrainingProviderDoc.php
554
B
-rw-r--r--
2026-06-03 05:55
Transformation.php
10.87
KB
-rw-r--r--
2026-05-13 09:36
UnempPractitioners.php
1.43
KB
-rw-r--r--
2026-06-03 05:55
Utils.php
13.72
KB
-rw-r--r--
2026-07-23 07:28
WeeklySessionsParser.php
7.87
KB
-rw-r--r--
2026-02-09 16:20
cceMessageAttachmentUpload.inc.php
5.12
KB
-rw-r--r--
2026-06-03 05:55
cceMessageEditor.inc.php
9.26
KB
-rw-r--r--
2026-07-01 13:20
cce_file_download_endpoint.php
1.75
KB
-rw-r--r--
2026-06-24 08:38
cstUnreadMessages.php
2.1
KB
-rw-r--r--
2026-07-01 13:20
cstWeeksCourses.php
1.84
KB
-rw-r--r--
2026-08-14 12:06
load_phpmailer.php
742
B
-rw-r--r--
2026-07-17 14:57
maill.php
19.45
KB
-rw-r--r--
2026-08-19 12:23
require_ewmysql.php
1.2
KB
-rw-r--r--
2026-08-24 10:12
sqlFunctions.php
10.48
KB
-rw-r--r--
2026-08-24 10:12
Save
Rename
<?php /** * Server-side proxy: echasl23 Weeks/Courses list → cesa-v3 HTML embed + SSO ticket. */ class SchoolWeeksCoursesDashboardProxy { private const EMBED_PATH = '/api/external/echasl23/weeks-courses/embed'; private const TICKET_TTL_SECONDS = 120; /** * Load DOCUMENT_ROOT/.env when server env does not already provide keys. */ public static function ensureEnvLoaded(): void { if (function_exists('cesaLoadEnvFile')) { cesaLoadEnvFile($_SERVER['DOCUMENT_ROOT'] . '/.env'); return; } $envFilePath = (isset($_SERVER['DOCUMENT_ROOT']) ? (string) $_SERVER['DOCUMENT_ROOT'] : '') . '/.env'; if ($envFilePath === '/.env' || !is_readable($envFilePath)) { return; } $lines = file($envFilePath, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES); if (!is_array($lines)) { return; } foreach ($lines as $line) { $line = trim($line); if ($line === '' || strpos($line, '#') === 0) { continue; } $splitPos = strpos($line, '='); if ($splitPos === false) { continue; } $name = trim(substr($line, 0, $splitPos)); $value = trim(substr($line, $splitPos + 1)); if ($name === '') { continue; } if ( strlen($value) >= 2 && (($value[0] === '"' && substr($value, -1) === '"') || ($value[0] === "'" && substr($value, -1) === "'")) ) { $value = substr($value, 1, -1); } $existing = getenv($name); if ($existing !== false && $existing !== '') { continue; } putenv($name . '=' . $value); $_ENV[$name] = $value; $_SERVER[$name] = $value; } } /** * @param array{from?: string|null, to?: string|null, q?: string|null, page?: string|null, per_page?: string|null, sort?: string|null, dir?: string|null, export?: string|null} $filters * @return array{ok: bool, html: string, error: string, http_code: int} */ public static function fetchEmbedHtml(string $username, array $filters = []): array { self::ensureEnvLoaded(); $username = trim($username); if ($username === '') { return [ 'ok' => false, 'html' => '', 'error' => 'Missing logged-in username for SSO.', 'http_code' => 401, ]; } try { $ticket = self::mintTicket($username); } catch (Throwable $e) { if (class_exists('ErrorLog')) { ErrorLog::logError('Weeks/Courses SSO ticket mint failed: ' . $e->getMessage()); } return [ 'ok' => false, 'html' => '', 'error' => 'SSO is not configured (ECHASL23_SSO_SECRET).', 'http_code' => 500, ]; } $payload = [ 'ticket' => $ticket, ]; foreach (['from', 'to', 'q', 'page', 'per_page', 'sort', 'dir'] as $key) { if (!array_key_exists($key, $filters)) { continue; } if ($filters[$key] === null || $filters[$key] === '') { continue; } if (is_scalar($filters[$key])) { $payload[$key] = trim((string) $filters[$key]); } } $baseUrl = self::resolveV3BaseUrl(); $result = Utils::curlRequest( $baseUrl . self::EMBED_PATH, 'POST', $payload, ['Accept: text/html'], 15, 90, ); $httpCode = isset($result['http_code']) ? (int) $result['http_code'] : 0; $body = isset($result['response']) ? (string) $result['response'] : ''; $curlError = isset($result['error']) ? (string) $result['error'] : ''; if ($httpCode >= 200 && $httpCode < 300 && $body !== '') { return [ 'ok' => true, 'html' => $body, 'error' => '', 'http_code' => $httpCode, ]; } $error = 'Unable to load Weeks/Courses dashboard from application server.'; if ($curlError !== '') { $error .= ' (' . $curlError . ')'; } elseif ($body !== '') { $plain = trim(strip_tags($body)); if ($plain !== '') { $error .= ' ' . $plain; } } elseif ($httpCode > 0) { $error .= ' HTTP ' . $httpCode . '.'; } if (class_exists('ErrorLog')) { ErrorLog::logError('Weeks/Courses embed failed: HTTP ' . $httpCode . ' ' . $curlError); } return [ 'ok' => false, 'html' => '', 'error' => $error, 'http_code' => $httpCode > 0 ? $httpCode : 502, ]; } /** * Download Excel export for current filters (all matching rows). * * @param array{from?: string|null, to?: string|null, q?: string|null, sort?: string|null, dir?: string|null} $filters * @return array{ok: bool, body: string, error: string, http_code: int, content_type: string, filename: string} */ public static function fetchExportBinary(string $username, array $filters = []): array { self::ensureEnvLoaded(); $username = trim($username); if ($username === '') { return [ 'ok' => false, 'body' => '', 'error' => 'Missing logged-in username for SSO.', 'http_code' => 401, 'content_type' => '', 'filename' => '', ]; } try { $ticket = self::mintTicket($username); } catch (Throwable $e) { if (class_exists('ErrorLog')) { ErrorLog::logError('Weeks/Courses SSO ticket mint failed: ' . $e->getMessage()); } return [ 'ok' => false, 'body' => '', 'error' => 'SSO is not configured (ECHASL23_SSO_SECRET).', 'http_code' => 500, 'content_type' => '', 'filename' => '', ]; } $payload = [ 'ticket' => $ticket, 'export' => '1', ]; foreach (['from', 'to', 'q', 'sort', 'dir'] as $key) { if (!array_key_exists($key, $filters)) { continue; } if ($filters[$key] === null || $filters[$key] === '') { continue; } if (is_scalar($filters[$key])) { $payload[$key] = trim((string) $filters[$key]); } } $baseUrl = self::resolveV3BaseUrl(); $result = Utils::curlRequest( $baseUrl . self::EMBED_PATH, 'POST', $payload, ['Accept: application/vnd.openxmlformats-officedocument.spreadsheetml.sheet, application/octet-stream, */*'], 15, 180, ); $httpCode = isset($result['http_code']) ? (int) $result['http_code'] : 0; $body = isset($result['response']) ? (string) $result['response'] : ''; $curlError = isset($result['error']) ? (string) $result['error'] : ''; $contentType = isset($result['content_type']) ? (string) $result['content_type'] : ''; if ($httpCode >= 200 && $httpCode < 300 && $body !== '') { return [ 'ok' => true, 'body' => $body, 'error' => '', 'http_code' => $httpCode, 'content_type' => $contentType !== '' ? $contentType : 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet', 'filename' => 'sce-weeks-courses.xlsx', ]; } $error = 'Unable to export Weeks/Courses dashboard.'; if ($curlError !== '') { $error .= ' (' . $curlError . ')'; } elseif ($body !== '') { $plain = trim(strip_tags($body)); if ($plain !== '') { $error .= ' ' . $plain; } } elseif ($httpCode > 0) { $error .= ' HTTP ' . $httpCode . '.'; } return [ 'ok' => false, 'body' => '', 'error' => $error, 'http_code' => $httpCode > 0 ? $httpCode : 502, 'content_type' => '', 'filename' => '', ]; } /** * Mint HMAC ticket compatible with cesa-v3 Echasl23SsoTicketService. */ public static function mintTicket(string $username, ?int $ttlSeconds = null): string { $secret = self::resolveSharedSecret(); if ($secret === '') { throw new RuntimeException('ECHASL23_SSO_SECRET is not configured.'); } $username = trim($username); if ($username === '') { throw new InvalidArgumentException('Username is required to mint an SSO ticket.'); } $ttl = $ttlSeconds ?? self::TICKET_TTL_SECONDS; if ($ttl <= 0) { $ttl = self::TICKET_TTL_SECONDS; } $payload = [ 'u' => $username, 'exp' => time() + $ttl, 'n' => bin2hex(random_bytes(8)), ]; $payloadJson = json_encode($payload, JSON_UNESCAPED_SLASHES); if ($payloadJson === false) { throw new RuntimeException('Could not encode SSO ticket payload.'); } $payloadB64 = rtrim(strtr(base64_encode($payloadJson), '+/', '-_'), '='); $sig = hash_hmac('sha256', $payloadB64, $secret); return $payloadB64 . '.' . $sig; } public static function resolveSharedSecret(): string { if (defined('ECHASL23_SSO_SECRET') && (string) ECHASL23_SSO_SECRET !== '') { return (string) ECHASL23_SSO_SECRET; } return (string) ( $_ENV['ECHASL23_SSO_SECRET'] ?? $_SERVER['ECHASL23_SSO_SECRET'] ?? getenv('ECHASL23_SSO_SECRET') ?: '' ); } /** * @return string Base URL without trailing slash */ public static function resolveV3BaseUrl(): string { $baseUrl = getenv('CESA_V3_API_BASE_URL'); if (empty($baseUrl)) { $baseUrl = getenv('CESA_V3_BASE_URL'); } if (empty($baseUrl)) { if (isset($_SERVER['HTTP_HOST']) && strpos((string) $_SERVER['HTTP_HOST'], 'devstage') !== false) { $baseUrl = 'https://cesa-v3.devstage.co.za'; } else { $baseUrl = 'https://v3.cesa.co.za'; } } return rtrim((string) $baseUrl, '/'); } }