如何让PHP以gmodserver用户执行Shell脚本重启Garry's Mod服务器?
Got it, let's walk through how to set up a secure PHP endpoint that lets authorized users restart your Garry's Mod server—running the restart script as your gmodserver user, just like you need. Security is non-negotiable here, so we'll cover that every step of the way.
First, we need to make sure only people with your exclusive secret key can trigger the restart. Here's a simple PHP snippet to handle that validation:
<?php // Replace this with a long, random secret key (use a password generator for this!) $VALID_SECRET = "your_super_long_random_secret_key_123!@#"; // Check if the secret key is present and matches if (!isset($_GET['secret']) || $_GET['secret'] !== $VALID_SECRET) { http_response_code(403); echo "Forbidden: Invalid or missing access key"; exit; } // Rest of the logic goes below... ?>
Pro tip: Use POST instead of GET if you want to hide the key from URL logs—just swap $_GET with $_POST and send the key in a form body or API request.
PHP runs under your web server's user (usually www-data for Apache/Nginx on Debian/Ubuntu, or apache on RHEL/CentOS). We need to let this user run your restart script as gmodserver without entering a password.
Edit the sudoers file safely with:
sudo visudo
Add this line at the bottom (replace www-data with your web server user, and /home/gmodserver/restart_gmod.sh with your actual script path):
www-data ALL=(gmodserver) NOPASSWD: /home/gmodserver/restart_gmod.sh
Save and exit (in visudo, that's Ctrl+O then Ctrl+X). This gives only permission to run that exact script as gmodserver—no extra access, which keeps things secure.
Now, add code to your PHP script to run the restart command via sudo. We'll use exec() to capture output and check if it succeeded:
<?php // ... secret key validation from step 1 ... $restartScript = "/home/gmodserver/restart_gmod.sh"; // Build the command to run as gmodserver $command = "sudo -u gmodserver {$restartScript}"; // Execute and capture results exec($command, $output, $exitCode); if ($exitCode === 0) { echo "GMod server restart initiated successfully!"; } else { http_response_code(500); echo "Failed to restart server. Error details: " . implode("\n", $output); } ?>
The $exitCode will be 0 if the script ran successfully—any other number means something went wrong. The $output array will hold any messages or errors from the script, which is helpful for debugging.
Don't stop at the basics—add these extra safeguards:
- Secure the restart script: Make sure only
gmodservercan read/write it:chown gmodserver:gmodserver /home/gmodserver/restart_gmod.sh chmod 700 /home/gmodserver/restart_gmod.sh - Use HTTPS: Always serve this endpoint over HTTPS so your secret key isn't sent in plaintext. Most hosting providers offer free SSL certificates via Let's Encrypt.
- Log all actions: Track who triggered restarts and whether they succeeded. Add this to your PHP script:
Then secure the log file:$logMessage = date("Y-m-d H:i:s") . " | IP: " . $_SERVER['REMOTE_ADDR'] . " | Restart " . ($exitCode === 0 ? "SUCCESS" : "FAILED") . "\n"; file_put_contents("/var/log/gmod_restarts.log", $logMessage, FILE_APPEND);touch /var/log/gmod_restarts.log chown www-data:www-data /var/log/gmod_restarts.log chmod 600 /var/log/gmod_restarts.log
Before putting it live:
- Test the sudo command manually as the web server user:
If this works without asking for a password, you're good to go.sudo -u www-data sudo -u gmodserver /home/gmodserver/restart_gmod.sh - Visit your PHP endpoint in a browser (or use curl) with the secret key:
Check if the server restarts and if the log entry is created.curl "https://your-domain.com/restart.php?secret=your_super_long_random_secret_key_123!@#"
内容的提问来源于stack exchange,提问作者MoustacheSpy

