api-functions.php 35 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = $oAuth = $oAuthType = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  25. $oAuth = (isset($oAuth)) ? $oAuth : false;
  26. try {
  27. $database = new Dibi\Connection([
  28. 'driver' => 'sqlite3',
  29. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  30. ]);
  31. $authSuccess = false;
  32. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  33. if (!$oAuth) {
  34. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  35. switch ($GLOBALS['authType']) {
  36. case 'external':
  37. if (function_exists($function)) {
  38. $authSuccess = $function($username, $password);
  39. }
  40. break;
  41. /** @noinspection PhpMissingBreakStatementInspection */
  42. case 'both':
  43. if (function_exists($function)) {
  44. $authSuccess = $function($username, $password);
  45. }
  46. // no break
  47. default: // Internal
  48. if (!$authSuccess) {
  49. // perform the internal authentication step
  50. if (password_verify($password, $result['password'])) {
  51. $authSuccess = true;
  52. }
  53. }
  54. }
  55. } else {
  56. // Has oAuth Token!
  57. switch ($oAuthType) {
  58. case 'plex':
  59. if ($GLOBALS['plexoAuth']) {
  60. $tokenInfo = checkPlexToken($oAuth);
  61. if ($tokenInfo) {
  62. $authSuccess = array(
  63. 'username' => $tokenInfo['user']['username'],
  64. 'email' => $tokenInfo['user']['email'],
  65. 'image' => $tokenInfo['user']['thumb'],
  66. 'token' => $tokenInfo['user']['authToken']
  67. );
  68. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  69. }
  70. }
  71. break;
  72. default:
  73. return 'error';
  74. break;
  75. }
  76. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  77. }
  78. if ($authSuccess) {
  79. // Make sure user exists in database
  80. $userExists = false;
  81. $passwordMatches = ($oAuth) ? true : false;
  82. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  83. if ($result['username']) {
  84. $userExists = true;
  85. $username = $result['username'];
  86. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  87. }
  88. if ($userExists) {
  89. //does org password need to be updated
  90. if (!$passwordMatches) {
  91. $database->query('
  92. UPDATE users SET', [
  93. 'password' => password_hash($password, PASSWORD_BCRYPT)
  94. ], '
  95. WHERE id=?', $result['id']);
  96. writeLog('success', 'Login Function - User Password updated from backend', $username);
  97. }
  98. if ($token !== '') {
  99. if ($token !== $result['plex_token']) {
  100. $database->query('
  101. UPDATE users SET', [
  102. 'plex_token' => $token
  103. ], '
  104. WHERE id=?', $result['id']);
  105. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  106. }
  107. }
  108. // 2FA might go here
  109. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  110. $TFA = explode('::', $result['auth_service']);
  111. // Is code with login info?
  112. if ($tfaCode == '') {
  113. return '2FA';
  114. } else {
  115. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  116. return '2FA-incorrect';
  117. }
  118. }
  119. }
  120. // End 2FA
  121. // authentication passed - 1) mark active and update token
  122. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  123. writeLoginLog($username, 'success');
  124. writeLog('success', 'Login Function - A User has logged in', $username);
  125. ssoCheck($username, $password, $token); //need to work on this
  126. return true;
  127. } else {
  128. return 'error';
  129. }
  130. } else {
  131. // Create User
  132. //ssoCheck($username, $password, $token);
  133. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  134. }
  135. } else {
  136. // authentication failed
  137. writeLoginLog($username, 'error');
  138. writeLog('error', 'Login Function - Wrong Password', $username);
  139. return 'mismatch';
  140. }
  141. } catch (Dibi\Exception $e) {
  142. return $e;
  143. }
  144. }
  145. function createDB($path, $filename)
  146. {
  147. try {
  148. if (!file_exists($path)) {
  149. mkdir($path, 0777, true);
  150. }
  151. $createDB = new Dibi\Connection([
  152. 'driver' => 'sqlite3',
  153. 'database' => $path . $filename,
  154. ]);
  155. // Create Users
  156. $createDB->query('CREATE TABLE `users` (
  157. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  158. `username` TEXT UNIQUE,
  159. `password` TEXT,
  160. `email` TEXT,
  161. `plex_token` TEXT,
  162. `group` TEXT,
  163. `group_id` INTEGER,
  164. `locked` INTEGER,
  165. `image` TEXT,
  166. `register_date` DATE,
  167. `auth_service` TEXT DEFAULT \'internal\'
  168. );');
  169. // Create Tokens
  170. $createDB->query('CREATE TABLE `chatroom` (
  171. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  172. `username` TEXT,
  173. `gravatar` TEXT,
  174. `uid` TEXT,
  175. `date` DATE,
  176. `ip` TEXT,
  177. `message` TEXT
  178. );');
  179. $createDB->query('CREATE TABLE `tokens` (
  180. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  181. `token` TEXT UNIQUE,
  182. `user_id` INTEGER,
  183. `browser` TEXT,
  184. `ip` TEXT,
  185. `created` DATE,
  186. `expires` DATE
  187. );');
  188. $createDB->query('CREATE TABLE `groups` (
  189. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  190. `group` TEXT UNIQUE,
  191. `group_id` INTEGER,
  192. `image` TEXT,
  193. `default` INTEGER
  194. );');
  195. $createDB->query('CREATE TABLE `categories` (
  196. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  197. `order` INTEGER,
  198. `category` TEXT UNIQUE,
  199. `category_id` INTEGER,
  200. `image` TEXT,
  201. `default` INTEGER
  202. );');
  203. // Create Tabs
  204. $createDB->query('CREATE TABLE `tabs` (
  205. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  206. `order` INTEGER,
  207. `category_id` INTEGER,
  208. `name` TEXT,
  209. `url` TEXT,
  210. `url_local` TEXT,
  211. `default` INTEGER,
  212. `enabled` INTEGER,
  213. `group_id` INTEGER,
  214. `image` TEXT,
  215. `type` INTEGER,
  216. `splash` INTEGER,
  217. `ping` INTEGER,
  218. `ping_url` TEXT
  219. );');
  220. // Create Options
  221. $createDB->query('CREATE TABLE `options` (
  222. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  223. `name` TEXT UNIQUE,
  224. `value` TEXT
  225. );');
  226. // Create Invites
  227. $createDB->query('CREATE TABLE `invites` (
  228. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  229. `code` TEXT UNIQUE,
  230. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  231. `email` TEXT,
  232. `username` TEXT,
  233. `dateused` TIMESTAMP,
  234. `usedby` TEXT,
  235. `ip` TEXT,
  236. `valid` TEXT,
  237. `type` TEXT
  238. );');
  239. return true;
  240. } catch (Dibi\Exception $e) {
  241. return false;
  242. }
  243. }
  244. // Upgrade Database
  245. function updateDB($oldVerNum = false)
  246. {
  247. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  248. if (!file_exists($tempLock)) {
  249. touch($tempLock);
  250. // Create Temp DB First
  251. $migrationDB = 'tempMigration.db';
  252. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  253. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  254. unlink($GLOBALS['dbLocation'] . $migrationDB);
  255. }
  256. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  257. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  258. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  259. if ($success) {
  260. try {
  261. $connectOldDB = new Dibi\Connection([
  262. 'driver' => 'sqlite3',
  263. 'database' => $backupDB,
  264. ]);
  265. $connectNewDB = new Dibi\Connection([
  266. 'driver' => 'sqlite3',
  267. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  268. ]);
  269. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  270. foreach ($tables as $table) {
  271. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  272. foreach ($data as $row) {
  273. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  274. }
  275. }
  276. $connectOldDB->disconnect();
  277. $connectNewDB->disconnect();
  278. // Remove Current Database
  279. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  280. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  281. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  282. if ($newFileSize >= $oldFileSize) {
  283. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  284. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  285. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  286. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  287. unlink($tempLock);
  288. return true;
  289. }
  290. }
  291. unlink($tempLock);
  292. return false;
  293. } catch (Dibi\Exception $e) {
  294. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  295. unlink($tempLock);
  296. return false;
  297. }
  298. }
  299. unlink($tempLock);
  300. return false;
  301. }
  302. return false;
  303. }
  304. function createFirstAdmin($path, $filename, $username, $password, $email)
  305. {
  306. try {
  307. $createDB = new Dibi\Connection([
  308. 'driver' => 'sqlite3',
  309. 'database' => $path . $filename,
  310. ]);
  311. $userInfo = [
  312. 'username' => $username,
  313. 'password' => password_hash($password, PASSWORD_BCRYPT),
  314. 'email' => $email,
  315. 'group' => 'Admin',
  316. 'group_id' => 0,
  317. 'image' => gravatar($email),
  318. 'register_date' => $GLOBALS['currentTime'],
  319. ];
  320. $groupInfo0 = [
  321. 'group' => 'Admin',
  322. 'group_id' => 0,
  323. 'default' => false,
  324. 'image' => 'plugins/images/groups/admin.png',
  325. ];
  326. $groupInfo1 = [
  327. 'group' => 'Co-Admin',
  328. 'group_id' => 1,
  329. 'default' => false,
  330. 'image' => 'plugins/images/groups/coadmin.png',
  331. ];
  332. $groupInfo2 = [
  333. 'group' => 'Super User',
  334. 'group_id' => 2,
  335. 'default' => false,
  336. 'image' => 'plugins/images/groups/superuser.png',
  337. ];
  338. $groupInfo3 = [
  339. 'group' => 'Power User',
  340. 'group_id' => 3,
  341. 'default' => false,
  342. 'image' => 'plugins/images/groups/poweruser.png',
  343. ];
  344. $groupInfo4 = [
  345. 'group' => 'User',
  346. 'group_id' => 4,
  347. 'default' => true,
  348. 'image' => 'plugins/images/groups/user.png',
  349. ];
  350. $groupInfoGuest = [
  351. 'group' => 'Guest',
  352. 'group_id' => 999,
  353. 'default' => false,
  354. 'image' => 'plugins/images/groups/guest.png',
  355. ];
  356. $settingsInfo = [
  357. 'order' => 1,
  358. 'category_id' => 0,
  359. 'name' => 'Settings',
  360. 'url' => 'api/?v1/settings/page',
  361. 'default' => false,
  362. 'enabled' => true,
  363. 'group_id' => 1,
  364. 'image' => 'fontawesome::cog',
  365. 'type' => 0
  366. ];
  367. $homepageInfo = [
  368. 'order' => 2,
  369. 'category_id' => 0,
  370. 'name' => 'Homepage',
  371. 'url' => 'api/?v1/homepage/page',
  372. 'default' => false,
  373. 'enabled' => false,
  374. 'group_id' => 4,
  375. 'image' => 'fontawesome::home',
  376. 'type' => 0
  377. ];
  378. $unsortedInfo = [
  379. 'order' => 1,
  380. 'category' => 'Unsorted',
  381. 'category_id' => 0,
  382. 'image' => 'plugins/images/categories/unsorted.png',
  383. 'default' => true
  384. ];
  385. $createDB->query('INSERT INTO [users]', $userInfo);
  386. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  387. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  388. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  389. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  390. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  391. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  392. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  393. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  394. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  395. return true;
  396. } catch (Dibi\Exception $e) {
  397. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  398. return false;
  399. }
  400. }
  401. function defaultUserGroup()
  402. {
  403. try {
  404. $connect = new Dibi\Connection([
  405. 'driver' => 'sqlite3',
  406. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  407. ]);
  408. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  409. return $all;
  410. } catch (Dibi\Exception $e) {
  411. return false;
  412. }
  413. }
  414. function defaultTabCategory()
  415. {
  416. try {
  417. $connect = new Dibi\Connection([
  418. 'driver' => 'sqlite3',
  419. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  420. ]);
  421. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  422. return $all;
  423. } catch (Dibi\Exception $e) {
  424. return false;
  425. }
  426. }
  427. function getGuest()
  428. {
  429. if (isset($GLOBALS['dbLocation'])) {
  430. try {
  431. $connect = new Dibi\Connection([
  432. 'driver' => 'sqlite3',
  433. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  434. ]);
  435. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  436. return $all;
  437. } catch (Dibi\Exception $e) {
  438. return false;
  439. }
  440. } else {
  441. return array(
  442. 'group' => 'Guest',
  443. 'group_id' => 999,
  444. 'image' => 'plugins/images/groups/guest.png'
  445. );
  446. }
  447. }
  448. function adminEditGroup($array)
  449. {
  450. switch ($array['data']['action']) {
  451. case 'changeDefaultGroup':
  452. try {
  453. $connect = new Dibi\Connection([
  454. 'driver' => 'sqlite3',
  455. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  456. ]);
  457. $connect->query('UPDATE groups SET `default` = 0');
  458. $connect->query('
  459. UPDATE groups SET', [
  460. 'default' => 1
  461. ], '
  462. WHERE id=?', $array['data']['id']);
  463. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  464. return true;
  465. } catch (Dibi\Exception $e) {
  466. return false;
  467. }
  468. break;
  469. case 'deleteUserGroup':
  470. try {
  471. $connect = new Dibi\Connection([
  472. 'driver' => 'sqlite3',
  473. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  474. ]);
  475. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  476. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  477. return true;
  478. } catch (Dibi\Exception $e) {
  479. return false;
  480. }
  481. break;
  482. case 'addUserGroup':
  483. try {
  484. $connect = new Dibi\Connection([
  485. 'driver' => 'sqlite3',
  486. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  487. ]);
  488. $newGroup = [
  489. 'group' => $array['data']['newGroupName'],
  490. 'group_id' => $array['data']['newGroupID'],
  491. 'default' => false,
  492. 'image' => $array['data']['newGroupImage'],
  493. ];
  494. $connect->query('INSERT INTO [groups]', $newGroup);
  495. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  496. return true;
  497. } catch (Dibi\Exception $e) {
  498. return false;
  499. }
  500. break;
  501. case 'editUserGroup':
  502. try {
  503. $connect = new Dibi\Connection([
  504. 'driver' => 'sqlite3',
  505. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  506. ]);
  507. $connect->query('
  508. UPDATE groups SET', [
  509. 'group' => $array['data']['groupName'],
  510. 'image' => $array['data']['groupImage'],
  511. ], '
  512. WHERE id=?', $array['data']['id']);
  513. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  514. return true;
  515. } catch (Dibi\Exception $e) {
  516. return false;
  517. }
  518. break;
  519. default:
  520. return false;
  521. break;
  522. }
  523. }
  524. function adminEditUser($array)
  525. {
  526. switch ($array['data']['action']) {
  527. case 'changeGroup':
  528. try {
  529. $connect = new Dibi\Connection([
  530. 'driver' => 'sqlite3',
  531. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  532. ]);
  533. $connect->query('
  534. UPDATE users SET', [
  535. 'group' => $array['data']['newGroupName'],
  536. 'group_id' => $array['data']['newGroupID'],
  537. ], '
  538. WHERE id=?', $array['data']['id']);
  539. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  540. return true;
  541. } catch (Dibi\Exception $e) {
  542. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  543. return false;
  544. }
  545. break;
  546. case 'editUser':
  547. try {
  548. $connect = new Dibi\Connection([
  549. 'driver' => 'sqlite3',
  550. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  551. ]);
  552. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  553. $connect->query('
  554. UPDATE users SET', [
  555. 'username' => $array['data']['username'],
  556. 'email' => $array['data']['email'],
  557. 'image' => gravatar($array['data']['email']),
  558. ], '
  559. WHERE id=?', $array['data']['id']);
  560. if (!empty($array['data']['password'])) {
  561. $connect->query('
  562. UPDATE users SET', [
  563. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  564. ], '
  565. WHERE id=?', $array['data']['id']);
  566. }
  567. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  568. return true;
  569. } else {
  570. return false;
  571. }
  572. } catch (Dibi\Exception $e) {
  573. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  574. return false;
  575. }
  576. break;
  577. case 'addNewUser':
  578. $defaults = defaultUserGroup();
  579. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  580. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  581. return true;
  582. } else {
  583. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  584. return 'username taken';
  585. }
  586. break;
  587. case 'deleteUser':
  588. try {
  589. $connect = new Dibi\Connection([
  590. 'driver' => 'sqlite3',
  591. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  592. ]);
  593. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  594. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  595. return true;
  596. } catch (Dibi\Exception $e) {
  597. return false;
  598. }
  599. break;
  600. default:
  601. return false;
  602. break;
  603. }
  604. }
  605. function editTabs($array)
  606. {
  607. switch ($array['data']['action']) {
  608. case 'changeGroup':
  609. try {
  610. $connect = new Dibi\Connection([
  611. 'driver' => 'sqlite3',
  612. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  613. ]);
  614. $connect->query('
  615. UPDATE tabs SET', [
  616. 'group_id' => $array['data']['newGroupID'],
  617. ], '
  618. WHERE id=?', $array['data']['id']);
  619. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  620. return true;
  621. } catch (Dibi\Exception $e) {
  622. return false;
  623. }
  624. break;
  625. case 'changeCategory':
  626. try {
  627. $connect = new Dibi\Connection([
  628. 'driver' => 'sqlite3',
  629. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  630. ]);
  631. $connect->query('
  632. UPDATE tabs SET', [
  633. 'category_id' => $array['data']['newCategoryID'],
  634. ], '
  635. WHERE id=?', $array['data']['id']);
  636. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  637. return true;
  638. } catch (Dibi\Exception $e) {
  639. return false;
  640. }
  641. break;
  642. case 'changeType':
  643. try {
  644. $connect = new Dibi\Connection([
  645. 'driver' => 'sqlite3',
  646. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  647. ]);
  648. $connect->query('
  649. UPDATE tabs SET', [
  650. 'type' => $array['data']['newTypeID'],
  651. ], '
  652. WHERE id=?', $array['data']['id']);
  653. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  654. return true;
  655. } catch (Dibi\Exception $e) {
  656. return false;
  657. }
  658. break;
  659. case 'changeEnabled':
  660. try {
  661. $connect = new Dibi\Connection([
  662. 'driver' => 'sqlite3',
  663. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  664. ]);
  665. $connect->query('
  666. UPDATE tabs SET', [
  667. 'enabled' => $array['data']['tabEnabled'],
  668. ], '
  669. WHERE id=?', $array['data']['id']);
  670. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  671. return true;
  672. } catch (Dibi\Exception $e) {
  673. return false;
  674. }
  675. break;
  676. case 'changeSplash':
  677. try {
  678. $connect = new Dibi\Connection([
  679. 'driver' => 'sqlite3',
  680. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  681. ]);
  682. $connect->query('
  683. UPDATE tabs SET', [
  684. 'splash' => $array['data']['tabSplash'],
  685. ], '
  686. WHERE id=?', $array['data']['id']);
  687. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  688. return true;
  689. } catch (Dibi\Exception $e) {
  690. return false;
  691. }
  692. break;
  693. case 'changePing':
  694. try {
  695. $connect = new Dibi\Connection([
  696. 'driver' => 'sqlite3',
  697. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  698. ]);
  699. $connect->query('
  700. UPDATE tabs SET', [
  701. 'ping' => $array['data']['tabPing'],
  702. ], '
  703. WHERE id=?', $array['data']['id']);
  704. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  705. return true;
  706. } catch (Dibi\Exception $e) {
  707. return false;
  708. }
  709. break;
  710. case 'changeDefault':
  711. try {
  712. $connect = new Dibi\Connection([
  713. 'driver' => 'sqlite3',
  714. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  715. ]);
  716. $connect->query('UPDATE tabs SET `default` = 0');
  717. $connect->query('
  718. UPDATE tabs SET', [
  719. 'default' => 1
  720. ], '
  721. WHERE id=?', $array['data']['id']);
  722. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  723. return true;
  724. } catch (Dibi\Exception $e) {
  725. return false;
  726. }
  727. break;
  728. case 'deleteTab':
  729. try {
  730. $connect = new Dibi\Connection([
  731. 'driver' => 'sqlite3',
  732. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  733. ]);
  734. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  735. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  736. return true;
  737. } catch (Dibi\Exception $e) {
  738. return false;
  739. }
  740. break;
  741. case 'editTab':
  742. try {
  743. $connect = new Dibi\Connection([
  744. 'driver' => 'sqlite3',
  745. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  746. ]);
  747. $connect->query('
  748. UPDATE tabs SET', [
  749. 'name' => $array['data']['tabName'],
  750. 'url' => $array['data']['tabURL'],
  751. 'ping_url' => $array['data']['pingURL'],
  752. 'image' => $array['data']['tabImage'],
  753. ], '
  754. WHERE id=?', $array['data']['id']);
  755. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  756. return true;
  757. } catch (Dibi\Exception $e) {
  758. return false;
  759. }
  760. case 'changeOrder':
  761. try {
  762. $connect = new Dibi\Connection([
  763. 'driver' => 'sqlite3',
  764. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  765. ]);
  766. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  767. if ($value['order'] != $value['originalOrder']) {
  768. $connect->query('
  769. UPDATE tabs SET', [
  770. 'order' => $value['order'],
  771. ], '
  772. WHERE id=?', $value['id']);
  773. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  774. }
  775. }
  776. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  777. return true;
  778. } catch (Dibi\Exception $e) {
  779. return false;
  780. }
  781. break;
  782. case 'addNewTab':
  783. try {
  784. $default = defaultTabCategory()['category_id'];
  785. $connect = new Dibi\Connection([
  786. 'driver' => 'sqlite3',
  787. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  788. ]);
  789. $newTab = [
  790. 'order' => $array['data']['tabOrder'],
  791. 'category_id' => $default,
  792. 'name' => $array['data']['tabName'],
  793. 'url' => $array['data']['tabURL'],
  794. 'ping_url' => $array['data']['pingURL'],
  795. 'default' => $array['data']['tabDefault'],
  796. 'enabled' => 1,
  797. 'group_id' => $array['data']['tabGroupID'],
  798. 'image' => $array['data']['tabImage'],
  799. 'type' => $array['data']['tabType']
  800. ];
  801. $connect->query('INSERT INTO [tabs]', $newTab);
  802. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  803. return true;
  804. } catch (Dibi\Exception $e) {
  805. return false;
  806. }
  807. break;
  808. default:
  809. return false;
  810. break;
  811. }
  812. }
  813. function editCategories($array)
  814. {
  815. switch ($array['data']['action']) {
  816. case 'changeDefault':
  817. try {
  818. $connect = new Dibi\Connection([
  819. 'driver' => 'sqlite3',
  820. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  821. ]);
  822. $connect->query('UPDATE categories SET `default` = 0');
  823. $connect->query('
  824. UPDATE categories SET', [
  825. 'default' => 1
  826. ], '
  827. WHERE id=?', $array['data']['id']);
  828. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  829. return true;
  830. } catch (Dibi\Exception $e) {
  831. return false;
  832. }
  833. break;
  834. case 'deleteCategory':
  835. try {
  836. $connect = new Dibi\Connection([
  837. 'driver' => 'sqlite3',
  838. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  839. ]);
  840. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  841. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  842. return true;
  843. } catch (Dibi\Exception $e) {
  844. return false;
  845. }
  846. break;
  847. case 'addNewCategory':
  848. try {
  849. $connect = new Dibi\Connection([
  850. 'driver' => 'sqlite3',
  851. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  852. ]);
  853. $newCategory = [
  854. 'category' => $array['data']['categoryName'],
  855. 'order' => $array['data']['categoryOrder'],
  856. 'category_id' => $array['data']['categoryID'],
  857. 'default' => false,
  858. 'image' => $array['data']['categoryImage'],
  859. ];
  860. $connect->query('INSERT INTO [categories]', $newCategory);
  861. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  862. return true;
  863. } catch (Dibi\Exception $e) {
  864. return $e;
  865. }
  866. break;
  867. case 'editCategory':
  868. try {
  869. $connect = new Dibi\Connection([
  870. 'driver' => 'sqlite3',
  871. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  872. ]);
  873. $connect->query('
  874. UPDATE categories SET', [
  875. 'category' => $array['data']['name'],
  876. 'image' => $array['data']['image'],
  877. ], '
  878. WHERE id=?', $array['data']['id']);
  879. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  880. return true;
  881. } catch (Dibi\Exception $e) {
  882. return false;
  883. }
  884. break;
  885. case 'changeOrder':
  886. try {
  887. $connect = new Dibi\Connection([
  888. 'driver' => 'sqlite3',
  889. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  890. ]);
  891. foreach ($array['data']['categories']['category'] as $key => $value) {
  892. if ($value['order'] != $value['originalOrder']) {
  893. $connect->query('
  894. UPDATE categories SET', [
  895. 'order' => $value['order'],
  896. ], '
  897. WHERE id=?', $value['id']);
  898. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  899. }
  900. }
  901. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  902. return true;
  903. } catch (Dibi\Exception $e) {
  904. return false;
  905. }
  906. break;
  907. default:
  908. return false;
  909. break;
  910. }
  911. }
  912. function allUsers()
  913. {
  914. try {
  915. $connect = new Dibi\Connection([
  916. 'driver' => 'sqlite3',
  917. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  918. ]);
  919. $users = $connect->fetchAll('SELECT * FROM users');
  920. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  921. foreach ($users as $k => $v) {
  922. // clear password from array
  923. unset($users[$k]['password']);
  924. }
  925. $all['users'] = $users;
  926. $all['groups'] = $groups;
  927. return $all;
  928. } catch (Dibi\Exception $e) {
  929. return false;
  930. }
  931. }
  932. function usernameTaken($username, $email)
  933. {
  934. try {
  935. $connect = new Dibi\Connection([
  936. 'driver' => 'sqlite3',
  937. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  938. ]);
  939. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  940. return ($all) ? true : false;
  941. } catch (Dibi\Exception $e) {
  942. return false;
  943. }
  944. }
  945. function usernameTakenExcept($username, $email, $id)
  946. {
  947. try {
  948. $connect = new Dibi\Connection([
  949. 'driver' => 'sqlite3',
  950. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  951. ]);
  952. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  953. return ($all) ? true : false;
  954. } catch (Dibi\Exception $e) {
  955. return false;
  956. }
  957. }
  958. function createUser($username, $password, $defaults, $email = null)
  959. {
  960. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  961. try {
  962. if (!usernameTaken($username, $email)) {
  963. $createDB = new Dibi\Connection([
  964. 'driver' => 'sqlite3',
  965. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  966. ]);
  967. $userInfo = [
  968. 'username' => $username,
  969. 'password' => password_hash($password, PASSWORD_BCRYPT),
  970. 'email' => $email,
  971. 'group' => $defaults['group'],
  972. 'group_id' => $defaults['group_id'],
  973. 'image' => gravatar($email),
  974. 'register_date' => $GLOBALS['currentTime'],
  975. ];
  976. $createDB->query('INSERT INTO [users]', $userInfo);
  977. return true;
  978. } else {
  979. return false;
  980. }
  981. } catch (Dibi\Exception $e) {
  982. return false;
  983. }
  984. }
  985. function importUsers($array)
  986. {
  987. $imported = 0;
  988. $defaults = defaultUserGroup();
  989. foreach ($array as $user) {
  990. $password = random_ascii_string(30);
  991. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  992. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  993. if (!$newUser) {
  994. writeLog('error', 'Import Function - Error', $user['username']);
  995. } else {
  996. $imported++;
  997. }
  998. }
  999. }
  1000. return $imported;
  1001. }
  1002. function importUsersType($array)
  1003. {
  1004. $type = $array['data']['type'];
  1005. if ($type !== '') {
  1006. switch ($type) {
  1007. case 'plex':
  1008. return importUsers(allPlexUsers(true));
  1009. break;
  1010. default:
  1011. return false;
  1012. }
  1013. }
  1014. return false;
  1015. }
  1016. function allTabs()
  1017. {
  1018. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1019. try {
  1020. $connect = new Dibi\Connection([
  1021. 'driver' => 'sqlite3',
  1022. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1023. ]);
  1024. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1025. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1026. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1027. return $all;
  1028. } catch (Dibi\Exception $e) {
  1029. return false;
  1030. }
  1031. }
  1032. return false;
  1033. }
  1034. function allGroups()
  1035. {
  1036. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1037. try {
  1038. $connect = new Dibi\Connection([
  1039. 'driver' => 'sqlite3',
  1040. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1041. ]);
  1042. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1043. return $all;
  1044. } catch (Dibi\Exception $e) {
  1045. return false;
  1046. }
  1047. }
  1048. return false;
  1049. }
  1050. function loadTabs()
  1051. {
  1052. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1053. try {
  1054. $connect = new Dibi\Connection([
  1055. 'driver' => 'sqlite3',
  1056. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1057. ]);
  1058. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1059. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1060. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1061. $all['tabs'] = $tabs;
  1062. foreach ($tabs as $k => $v) {
  1063. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  1064. }
  1065. $count = array_map(function ($element) {
  1066. return $element['category_id'];
  1067. }, $tabs);
  1068. $count = (array_count_values($count));
  1069. foreach ($categories as $k => $v) {
  1070. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1071. }
  1072. $all['categories'] = $categories;
  1073. return $all;
  1074. } catch (Dibi\Exception $e) {
  1075. return false;
  1076. }
  1077. }
  1078. return false;
  1079. }
  1080. function getActiveTokens()
  1081. {
  1082. try {
  1083. $connect = new Dibi\Connection([
  1084. 'driver' => 'sqlite3',
  1085. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1086. ]);
  1087. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1088. return $all;
  1089. } catch (Dibi\Exception $e) {
  1090. return false;
  1091. }
  1092. }
  1093. function revokeToken($array)
  1094. {
  1095. if ($array['data']['token']) {
  1096. try {
  1097. $connect = new Dibi\Connection([
  1098. 'driver' => 'sqlite3',
  1099. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1100. ]);
  1101. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1102. return true;
  1103. } catch (Dibi\Exception $e) {
  1104. return false;
  1105. }
  1106. }
  1107. }