#!/bin/bash # install.sh # OpenDRS Online Discrepancy Reporting System # Copyright (C) 2025 Rod Wright # SPDX-License-Identifier: GPL-2.0 DRS_VERSION="1.4.4" DOC_ROOT="/var/www" INSTALL_LOC="opendrs" APACHE_USER="www-data" APACHE_GROUP="www-data" APACHE_CONF_DIR="/etc/apache2/conf-available" BACKUP_DIR="opendrs-previous-installation" # test for superuser rights if [[ $EUID -ne 0 ]]; then echo "This script must be run with superuser privileges. Try sudo ./install.sh" exit 1 fi echo "Preparing for OpenDRS installation or upgrade. Please stand by..." # Prevent unattended-upgrades from interfering restart_uu=false while systemctl status unattended-upgrades >/dev/null 2>&1 do systemctl stop unattended-upgrades sleep 5 restart_uu=true done echo "" echo "" echo "* * * * * Welcome to OpenDRS $DRS_VERSION Installation * * * * *" echo "" echo "" echo "Just press enter at the prompts to accept the defaults shown." echo "" # Check for prerequisites and prompt to install echo "Checking for prerequisites..." echo "" echo "" echo " Checking for apache2 installation..." echo "" if dpkg -l|grep apache2 >/dev/null 2>&1 then echo "" echo "apache2 is installed. Continuing." echo "" else echo "OpenDRS requires the apache2 http server, but it doesn't seem" echo -n "to be installed. Install it now? [Y/n]: " read reqinstall if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ] then echo "OpenDRS requires apache2, but you have elected not to install it." echo "Installation cannot continue." exit 1 else echo "" echo "###################################################################" echo "" echo "Proceeding with apache2 installation" echo "" echo "###################################################################" sleep 3 apt-get install -y apache2 echo "" echo "###################################################################" echo "" echo "Finished with apache2 installation" echo "" echo "###################################################################" sleep 3 fi fi echo "" echo " Checking for php installation..." echo "" if dpkg -l|grep php >/dev/null 2>&1 then echo "" echo "php is installed. Continuing." echo "" else echo "" echo "" echo "OpenDRS requires php, but it doesn't seem to be installed." echo -n "Install it now? [Y/n]: " read reqinstall if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ] then echo "OpenDRS requires php, but you have elected not to install it." echo "Installation cannot continue." exit 1 else echo "" echo "###################################################################" echo "" echo "Proceeding with php installation" echo "" echo "###################################################################" sleep 3 apt-get install -y php echo "" echo "###################################################################" echo "" echo "Finished with php installation" echo "" echo "###################################################################" sleep 3 fi fi echo "" echo " Checking for mariadb or mysql installation..." echo "" if dpkg -l|grep mariadb-server >/dev/null 2>&1 then echo "" echo "mariadb-server is installed. Continuing." echo "" elif dpkg -l|grep mysql-server >/dev/null 2>&1 then echo "" echo "mysql-server is installed. Continuing." echo "" else echo "" echo "" echo "OpenDRS requires either mariadb or mysql server, but neither seem" echo -n "to be installed. Install mariadb-server now? [Y/n]: " read reqinstall if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ] then echo "OpenDRS requires either mariadb or mysql server, but you have elected not to install it." echo "Installation cannot continue." exit 1 else echo "" echo "###################################################################" echo "" echo "Proceeding with mariadb-server installation" echo "" echo "###################################################################" sleep 3 apt-get install -y mariadb-server echo "" echo "###################################################################" echo "" echo "Finished with mariadb-server installation" echo "" echo "###################################################################" sleep 3 echo "" echo "###################################################################" echo "" echo "Proceeding with mariadb configuration" echo "" echo "###################################################################" sleep 3 echo "" echo "Configuring the MariaDB installation. There will be some more prompts:" echo "" echo "- You'll be prompted for the current password for the root user. You've" echo " just installed MariaDB and you haven't set one yet, so just press enter." echo "" echo "- You'll be prompted to switch to unix_socket authentication. Answer Y." echo "" echo "- You'll be prompted to change the root password. Answer Y and enter a password." echo " Note that this is just the password for the MariaDB root user, not the root login." echo " DO NOT FORGET THIS PASSWORD. You'll need it later during OpenDRS install." echo "" echo "- Answer Y to remove anonymous users, disallow root login remotely, remove" echo " test database and access, and reload privilege tables." echo "" echo -n "Press enter to proceed." read continueok echo "" mysql_secure_installation echo "" echo "###################################################################" echo "" echo "Finished with mariadb configuration." echo "" echo "###################################################################" sleep 3 fi fi echo "" echo " Checking for phpmyadmin installation..." echo "" if dpkg -l|grep phpmyadmin >/dev/null 2>&1 then echo "" echo "phpmyadmin is installed. Continuing." echo "" else echo "phpmyadmin is optional, but doesn't seem to be installed." echo "It is an optional package that enables administration of the mysql/mariadb" echo "database server using a friendly GUI. It is highly recommended." echo "Note that this has the potential to be a security risk, especially" echo "if your passwords aren't sufficiently strong." echo -n "Install it now? [Y/n]: " read reqinstall if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ] then echo "Proceeding without installing phpmyadmin. Database administration" echo "will require the use of the mysql/mariadb command line tools." else echo "" echo "###################################################################" echo "" echo "Proceeding with phpmyadmin installation" echo "" echo "###################################################################" sleep 3 echo "" echo "During the following installation of phpmyadmin:" echo "" echo "- Select apache2 as the web server to configure automatically." echo "" echo "- Choose Yes when prompted to install phpmyadmin database and allow it to" echo " generate a random password(leave the field blank)." echo "" echo -n "Press enter to continue." read continueok echo "" apt-get install -y phpmyadmin echo "" echo "" echo "You can now access phpmyadmin using a web browser pointed to:" echo "http://$HOSTNAME/phpmyadmin" echo "*** WARNING!! this url is accessible via unencrypted (http), not" echo "encrypted SSL (https) connections. This is a huge security risk" echo "since the username and password you enter will be sent in the" echo "clear for any potential attacker to sniff! You should enable" echo "redirection to https for phpmyadmin in your apache2 configuration." echo "" echo -n "Press enter to continue." read continueok echo "" echo "###################################################################" echo "" echo "Finished with phpmyadmin installation" echo "" echo "###################################################################" sleep 3 fi fi echo "" echo " Checking for webmin installation..." echo "" if dpkg -l|grep webmin >/dev/null 2>&1 then echo "" echo "webmin is installed. Continuing." echo "" else echo "webmin is optional, but doesn't seem to be installed." echo "It is an optional package that enables system administration" echo "using a friendly GUI. It is highly recommended, especially for" echo "headless servers without any way to log in directly on the machine." echo "Note that this has the potential to be a security risk, especially" echo "if your passwords aren't sufficiently strong." echo -n "Install it now? [Y/n]: " read reqinstall if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ] then echo "Proceeding without installing webmin. System administration" echo "will require login to the server either directly or via ssh." else echo "" echo "###################################################################" echo "" echo "Proceeding with webmin installation" echo "" echo "###################################################################" sleep 3 echo "Installing webmin..." skipwebmin="false" if ! curl -o setup-repos.sh https://raw.githubusercontent.com/webmin/webmin/master/setup-repos.sh then echo "Warning: failed to download Webmin repo setup script." echo -n "Ignore and [c]ontinue or [A]bort? [c/A]: " read wmfailchoice if [ "$wmfailchoice" = "C" -o "$wmfailchoice" = "c" ] then skipwebmin="true" echo "Continuing without installing Webmin. You should investigate the failure" echo "and install Webmin manually after the server is set up if you would like" echo "to be able to manage the server from another computer with a GUI instead" echo "of through ssh only." echo -n "Press enter to continue." read continueok echo "" fi fi if [ "$skipwebmin" = "false" ] then sh setup-repos.sh -f apt-get install -y --install-recommends webmin fi echo "...done." echo "" echo "You can now access webmin using a web browser pointed to:" echo "https://$HOSTNAME:10000" echo "Unless you have obtained valid ssl certificates, your server is" echo "using self-signed certs. This is not necessarily a problem, but" echo "your browser will complain. You can tell the browser to accept the" echo "self signed certificates and the traffic will still be encrypted," echo "however you may be vulnerable to man-in-the-middle attacks. You can" echo "get free valid certificates through LetsEncrypt." echo "See http://letsencrypt.org for more information." echo "" echo -n "Press enter to continue." read continueok echo "" echo "###################################################################" echo "" echo "Finished with webmin installation" echo "" echo "###################################################################" sleep 3 fi fi echo "" echo " Checking for uuidgen installation..." echo "" if uuidgen 2>&1 then echo "" echo "uuidgen is installed. Continuing." echo "" else echo "" echo "" echo "OpenDRS requires uuidgen, but it doesn't seem to be installed." echo -n "Install it now? [Y/n]: " read reqinstall if [ "$reqinstall" = "N" -o "$reqinstall" = "n" ] then echo "OpenDRS requires uuidgen, but you have elected not to install it." echo "Installation cannot continue." exit 1 else echo "" echo "###################################################################" echo "" echo "Proceeding with uuidgen installation" echo "" echo "###################################################################" sleep 3 apt-get install -y uuid-runtime echo "" echo "###################################################################" echo "" echo "Finished with uuidgen installation" echo "" echo "###################################################################" sleep 3 fi fi echo "" echo "" echo "Finished checking for and installing prerequisites..." echo "" echo "" sleep 3 # prompt for install location echo "Where would you like to install this version of OpenDRS? This should" echo "be somewhere the webserver can find it. If you don't know, refer to the" echo "webserver's documentation and check the server's configuration files." echo "Note that this is where the directory containing OpenDRS's files will be" echo "created." echo -n "Enter the webserver's install location [$DOC_ROOT]:" read doc_root_in echo "" echo -n "Enter name of OpenDRS installation directory [$INSTALL_LOC] :" read install_loc_in echo "" if [ "$doc_root_in" = "" ] then doc_root_in=$DOC_ROOT fi if [ "$install_loc_in" = "" ] then install_loc_in=$INSTALL_LOC fi install_path="$doc_root_in/$install_loc_in" if [ -d "$install_path" ] then # Install path exists. if [ -e "$install_path/db.php" ] then # A db.php file was found in the install path if grep -q -e "OpenDRS" -e "OpenMTS" $install_path/db.php then # the db.php file is part of an OpenDRS/OpenMTS installation echo "The installation path you chose already exists." echo "Would you like to upgrade an existing installation or cancel " echo "and restart the install using a new installation location." echo -n "[U]pgrade or [C]ancel? [C] :" read upgrade_choice if [ "$upgrade_choice" = "U" -o "$upgrade_choice" = "u" ] # Upgrade chosen then # proceed with upgrade operation="upgraded" # back up existing database echo "Backing up the current database to the package directory." curr_dbname=`grep dbname $install_path/db.php | head -1 | cut -d "\"" -f2` curr_username=`grep username $install_path/db.php | head -1 | cut -d "\"" -f2` curr_dbpass=`grep dbpass $install_path/db.php | head -1 | cut -d "\"" -f2` export MYSQL_PWD="$curr_dbpass" mysqldump --no-tablespaces -u"$curr_username" $curr_dbname > $curr_dbname-`date +%Y-%m-%d_%H:%M:%S`-backup.sql # back up existing installation echo "Backing up current installation to the package directory." cp -R $install_path $install_loc_in-`date +%Y-%m-%d_%H:%M:%S`-backup # delete all existing installation files except db.php find $install_path/ -mindepth 1 -not -name 'db.php' -delete # apply database updates mysql -u"$curr_username" -f -D $curr_dbname < opendrs-update.sql >/dev/null 2>&1 # apply updates to existing db.php bash ./opendrs-update.sh $install_path # copy distribution to install location echo "Installing distribution . . ." cp -R distfiles/* $install_path if [ ! -L "$install_path/jquery-ui" ] then ln -s $install_path/jquery-ui* $install_path/jquery-ui fi if [ ! -L "$install_path/index.php" ] then ln -s $install_path/writeups.php $install_path/index.php fi # set ownership echo "In order to set the ownership correctly, we need to know the user and" echo "group that the webserver expects its files to be owned by. This is" echo "usually not the root account. Refer to the ownership of other files in" echo "your webserver's document tree to see what this should be." echo "Enter the user and group separated by a colon (username:groupname)." echo "Enter the user:group of the OpenDRS installation" echo -n "directory [$APACHE_USER:$APACHE_GROUP] :" read httpd_user_group if [ "$httpd_user_group" = "" ] then httpd_user_group="$APACHE_USER:$APACHE_GROUP" fi echo "" echo "Setting file ownership . . ." chown -R $httpd_user_group $install_path else echo "Cancelling installation" exit fi else # This was a mistake. Exit now to avoid clobbering another app. echo "The installation directory you chose exists, but no previous installation" echo "of OpenDRS was found. Please investigate the situation. Aborting now." exit 1 fi else # This was a mistake. Exit now to avoid clobbering another app. echo "The installation directory you chose exists, but no previous installation" echo "of OpenDRS was found. Please investigate the situation. Aborting now." exit 1 fi else # This is a fresh install operation="installed" # prompt for mysql information bad_mysql_adm=true while $bad_mysql_adm do admintestdb="drsadm`date +%Y%m%d`" echo "We need to know the username and password of a MySQL administrator" echo "to be able to create the database and user for OpenDRS. Note that this" echo "is not necessarily the same as the login and password for the computer." echo -n "MySQL admin username: " read mysql_adm_user echo "" echo -n "MySQL admin password: " read -s mysql_adm_pass export MYSQL_PWD="$mysql_adm_pass" if mysql -u"$mysql_adm_user" -e "create database $admintestdb;drop database $admintestdb" then bad_mysql_adm=false else echo "ERROR: Either the username/password you supplied were incorrect or the user" echo -n "is not a MySQL administrator. Try again? [Y/N]: " read admtry if [ "$admtry" != "Y" -o "$admtry" != "y" ] then exit fi fi done echo "" echo "What would you like to call this installation of OpenDRS? If you accept" echo "the default, it will be called OpenDRS. If you will be running multiple" echo "instances of OpenDRS on this server, you should choose a distinctive name." echo "This can be changed later in the application itself." echo -n "Installation name [OpenDRS]: " read new_inst_name if [ "$new_inst_name" = "" ] then new_inst_name="OpenDRS" fi echo "" # Create initial database db_create_fail=true while $db_create_fail do echo "What would you like to call the database for this installation of OpenDRS?" echo "If you accept the default, it will be called opendrs. Again, this is fine" echo "if you will only be running this one instance, but if you will be running" echo "multiple instances of OpenDRS on this server, you should choose a " echo "distinctive name." echo -n "database name [opendrs]: " read new_db_name if [ "$new_db_name" = "" ] then new_db_name=opendrs fi echo "" export MYSQL_PWD="$mysql_adm_pass" if mysql -u"$mysql_adm_user" -e "create database $new_db_name" then db_create_fail=false else echo "An error was encountered when trying to create the database." echo "This probably means the database already exists." echo -n "Try again with a different database name? [Y/N]: " read dbcreatetry if [ "$dbcreatetry" != "Y" -o "$dbcreatetry" != "y" ] then exit fi fi done # Create user and give rights to database drs_user="$new_db_name`date +%Y%m%d%H%M%S`" drs_pass=`uuidgen` export MYSQL_PWD="$mysql_adm_pass" mysql -u"$mysql_adm_user" -e "create user if not exists '$drs_user'@'localhost' identified by '$drs_pass'" mysql -u"$mysql_adm_user" -e "grant all on $new_db_name.* to '$drs_user'@'localhost'" mysql -u"$mysql_adm_user" -e "flush privileges" # Populate initial database mysql -u"$mysql_adm_user" $new_db_name < opendrs-initial.sql # Set the installation name export MYSQL_PWD="$drs_pass" mysql -u"$drs_user" $new_db_name -e "update config set value=\"$new_inst_name\",defaultvalue=\"$new_inst_name\" where name=\"app_name\"" # Create install path echo "Creating installation directory . . ." mkdir $install_path # Create db.php if it doesn't exist if [ ! -f "$install_path/db.php" ] then cp db.php.template $install_path/db.php sed -i "s/DBNAME/$new_db_name/g" $install_path/db.php sed -i "s/DBUSER/$drs_user/g" $install_path/db.php sed -i "s/DBPASS/$drs_pass/g" $install_path/db.php fi # copy distribution to install location echo "Installing distribution . . ." cp -R distfiles/* $install_path if [ ! -L "$install_path/jquery-ui" ] then ln -s $install_path/jquery-ui* $install_path/jquery-ui fi if [ ! -L "$install_path/index.php" ] then ln -s $install_path/writeups.php $install_path/index.php fi # set ownership echo "In order to set the ownership correctly, we need to know the user and" echo "group that the webserver expects its files to be owned by. This is" echo "usually not the root account. Refer to the ownership of other files in" echo "your webserver's document tree to see what this should be." echo "Enter the user and group separated by a colon (username:groupname)." echo "Enter the user:group of the OpenDRS installation" echo -n "directory [$APACHE_USER:$APACHE_GROUP] :" read httpd_user_group if [ "$httpd_user_group" = "" ] then httpd_user_group="$APACHE_USER:$APACHE_GROUP" fi echo "" echo "Setting file ownership . . ." chown -R $httpd_user_group $install_path fi echo "" # tell user to launch web browser to continue echo "" echo "" echo "" echo "OpenDRS has been $operation." base_url=$install_loc_in if [ "$operation" = "installed" ] then echo "# OpenDRS default Apache configuration" > $APACHE_CONF_DIR/$base_url.conf echo "" >> $APACHE_CONF_DIR/$base_url.conf echo "Alias /$base_url $doc_root_in/$base_url" >> $APACHE_CONF_DIR/$base_url.conf echo "" >> $APACHE_CONF_DIR/$base_url.conf echo "" >> $APACHE_CONF_DIR/$base_url.conf echo " Options FollowSymLinks" >> $APACHE_CONF_DIR/$base_url.conf echo " DirectoryIndex index.php" >> $APACHE_CONF_DIR/$base_url.conf echo "" >> $APACHE_CONF_DIR/$base_url.conf echo -n "The apache2 $base_url configuration must be enabled. Would you like to do that now? [Y] :" read enconf if [ "$enconf" = "" -o "$enconf" = "Y" -o "$enconf" = "y" ] then a2enconf $base_url.conf >/dev/null service apache2 reload echo "You can now point a web browser to $base_url on your web server " echo "to set up and configure OpenDRS." echo "" echo "IMPORTANT: The default login credentials for the initial admin user are:" echo "" echo "login: drsadmin" echo "password: OpenDRS-1" echo "" echo "Remember these credentials. Otherwise, you will not be able to log in and" echo "configure your new installation." echo "It is highly recommended that you change the initial password to something" echo "secure after logging in for the first time." else echo "You will need to manually enable the configuration by executing:" echo " a2enconf $base_url.conf" echo " service apache2 reload" echo "as a superuser before it can be accessed." fi else echo "You can now point a web browser to $base_url on your web server " echo "to use your upgraded OpenDRS." fi # Re-enable unattended-upgrades if $restart_uu; then systemctl start unattended-upgrades; fi