index.php 38 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343
  1. <?php
  2. $generationTime = -microtime(true);
  3. //include functions
  4. require_once 'functions.php';
  5. //Set result array
  6. $result = array();
  7. //Get request method
  8. $method = $_SERVER['REQUEST_METHOD'];
  9. $pretty = isset($_GET['pretty']) ? true : false;
  10. reset($_GET);
  11. $function = (key($_GET) ? str_replace("/", "_", key($_GET)) : false);
  12. //Exit if $function is blank
  13. if ($function === false) {
  14. $result['status'] = "error";
  15. $result['statusText'] = "No API Path Supplied";
  16. exit(json_encode($result));
  17. }
  18. if ($function !== 'v1_auth' && $function !== 'v1_wizard_config' && $function !== 'v1_login' && $function !== 'v1_wizard_path') {
  19. if (isApprovedRequest($method, $_POST) === false) {
  20. $result['status'] = "error";
  21. $result['statusText'] = "Not Authorized";
  22. writeLog('success', 'Killed Attack From [' . (isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : 'No Referer') . ']', $GLOBALS['organizrUser']['username']);
  23. exit(json_encode($result));
  24. }
  25. }
  26. $result['request'] = key($_GET);
  27. $result['params'] = $_POST;
  28. switch ($function) {
  29. case 'v1_settings_page':
  30. switch ($method) {
  31. case 'GET':
  32. if (qualifyRequest(1)) {
  33. $result['status'] = 'success';
  34. $result['statusText'] = 'success';
  35. $result['data'] = $pageSettings;
  36. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  37. } else {
  38. $result['status'] = 'error';
  39. $result['statusText'] = 'API/Token invalid or not set';
  40. $result['data'] = null;
  41. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  42. }
  43. break;
  44. default:
  45. $result['status'] = 'error';
  46. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  47. break;
  48. }
  49. break;
  50. case 'v1_homepage_page':
  51. switch ($method) {
  52. case 'GET':
  53. $result['status'] = 'success';
  54. $result['statusText'] = 'success';
  55. $result['data'] = $pageHomepage;
  56. break;
  57. default:
  58. $result['status'] = 'error';
  59. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  60. break;
  61. }
  62. break;
  63. case 'v1_settings_plugins':
  64. switch ($method) {
  65. case 'GET':
  66. if (qualifyRequest(1)) {
  67. $result['status'] = 'success';
  68. $result['statusText'] = 'success';
  69. $result['data'] = $pageSettingsPlugins;
  70. } else {
  71. $result['status'] = 'error';
  72. $result['statusText'] = 'API/Token invalid or not set';
  73. $result['data'] = null;
  74. }
  75. break;
  76. default:
  77. $result['status'] = 'error';
  78. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  79. break;
  80. }
  81. break;
  82. case 'v1_settings_tab_editor_homepage':
  83. switch ($method) {
  84. case 'GET':
  85. if (qualifyRequest(1)) {
  86. $result['status'] = 'success';
  87. $result['statusText'] = 'success';
  88. $result['data'] = $pageSettingsTabEditorHomepage;
  89. } else {
  90. $result['status'] = 'error';
  91. $result['statusText'] = 'API/Token invalid or not set';
  92. $result['data'] = null;
  93. }
  94. break;
  95. default:
  96. $result['status'] = 'error';
  97. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  98. break;
  99. }
  100. break;
  101. case 'v1_settings_tab_editor_homepage_order':
  102. switch ($method) {
  103. case 'GET':
  104. if (qualifyRequest(1)) {
  105. $result['status'] = 'success';
  106. $result['statusText'] = 'success';
  107. $result['data'] = $pageSettingsTabEditorHomepageOrder;
  108. } else {
  109. $result['status'] = 'error';
  110. $result['statusText'] = 'API/Token invalid or not set';
  111. $result['data'] = null;
  112. }
  113. break;
  114. default:
  115. $result['status'] = 'error';
  116. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  117. break;
  118. }
  119. break;
  120. case 'v1_settings_homepage_list':
  121. switch ($method) {
  122. case 'GET':
  123. if (qualifyRequest(1)) {
  124. $result['status'] = 'success';
  125. $result['statusText'] = 'success';
  126. $result['data'] = getHomepageList();
  127. } else {
  128. $result['status'] = 'error';
  129. $result['statusText'] = 'API/Token invalid or not set';
  130. $result['data'] = null;
  131. }
  132. break;
  133. case 'POST':
  134. if (qualifyRequest(1)) {
  135. $result['status'] = 'success';
  136. $result['statusText'] = 'success';
  137. $result['data'] = editPlugins($_POST);
  138. } else {
  139. $result['status'] = 'error';
  140. $result['statusText'] = 'API/Token invalid or not set';
  141. $result['data'] = null;
  142. }
  143. break;
  144. default:
  145. $result['status'] = 'error';
  146. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  147. break;
  148. }
  149. break;
  150. case 'v1_settings_plugins_list':
  151. switch ($method) {
  152. case 'GET':
  153. if (qualifyRequest(1)) {
  154. $result['status'] = 'success';
  155. $result['statusText'] = 'success';
  156. $result['data'] = getPlugins();
  157. } else {
  158. $result['status'] = 'error';
  159. $result['statusText'] = 'API/Token invalid or not set';
  160. $result['data'] = null;
  161. }
  162. break;
  163. case 'POST':
  164. if (qualifyRequest(1)) {
  165. $result['status'] = 'success';
  166. $result['statusText'] = 'success';
  167. $result['data'] = editPlugins($_POST);
  168. } else {
  169. $result['status'] = 'error';
  170. $result['statusText'] = 'API/Token invalid or not set';
  171. $result['data'] = null;
  172. }
  173. break;
  174. default:
  175. $result['status'] = 'error';
  176. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  177. break;
  178. }
  179. break;
  180. case 'v1_settings_settings_logs':
  181. switch ($method) {
  182. case 'GET':
  183. if (qualifyRequest(1)) {
  184. $result['status'] = 'success';
  185. $result['statusText'] = 'success';
  186. $result['data'] = $pageSettingsSettingsLogs;
  187. } else {
  188. $result['status'] = 'error';
  189. $result['statusText'] = 'API/Token invalid or not set';
  190. $result['data'] = null;
  191. }
  192. break;
  193. default:
  194. $result['status'] = 'error';
  195. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  196. break;
  197. }
  198. break;
  199. case 'v1_settings_settings_sso':
  200. switch ($method) {
  201. case 'GET':
  202. if (qualifyRequest(1)) {
  203. $result['status'] = 'success';
  204. $result['statusText'] = 'success';
  205. $result['data'] = $pageSettingsSettingsSSO;
  206. } else {
  207. $result['status'] = 'error';
  208. $result['statusText'] = 'API/Token invalid or not set';
  209. $result['data'] = null;
  210. }
  211. break;
  212. default:
  213. $result['status'] = 'error';
  214. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  215. break;
  216. }
  217. break;
  218. case 'v1_settings_settings_main':
  219. switch ($method) {
  220. case 'GET':
  221. if (qualifyRequest(1)) {
  222. $result['status'] = 'success';
  223. $result['statusText'] = 'success';
  224. $result['data'] = $pageSettingsSettingsMain;
  225. } else {
  226. $result['status'] = 'error';
  227. $result['statusText'] = 'API/Token invalid or not set';
  228. $result['data'] = null;
  229. }
  230. break;
  231. default:
  232. $result['status'] = 'error';
  233. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  234. break;
  235. }
  236. break;
  237. case 'v1_settings_customize_appearance':
  238. switch ($method) {
  239. case 'GET':
  240. if (qualifyRequest(1)) {
  241. $result['status'] = 'success';
  242. $result['statusText'] = 'success';
  243. $result['data'] = $pageSettingsCustomizeAppearance;
  244. } else {
  245. $result['status'] = 'error';
  246. $result['statusText'] = 'API/Token invalid or not set';
  247. $result['data'] = null;
  248. }
  249. break;
  250. case 'POST':
  251. if (qualifyRequest(1)) {
  252. $result['status'] = 'success';
  253. $result['statusText'] = 'success';
  254. $result['data'] = editAppearance($_POST);
  255. } else {
  256. $result['status'] = 'error';
  257. $result['statusText'] = 'API/Token invalid or not set';
  258. $result['data'] = null;
  259. }
  260. break;
  261. default:
  262. $result['status'] = 'error';
  263. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  264. break;
  265. }
  266. break;
  267. case 'v1_remove_file':
  268. switch ($method) {
  269. case 'POST':
  270. if (qualifyRequest(1)) {
  271. $result['status'] = 'success';
  272. $result['statusText'] = 'success';
  273. $result['data'] = removeFile($_POST);
  274. } else {
  275. $result['status'] = 'error';
  276. $result['statusText'] = 'API/Token invalid or not set';
  277. $result['data'] = null;
  278. }
  279. break;
  280. default:
  281. $result['status'] = 'error';
  282. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  283. break;
  284. }
  285. break;
  286. case 'v1_update_config':
  287. switch ($method) {
  288. case 'POST':
  289. if (qualifyRequest(1)) {
  290. $result['status'] = 'success';
  291. $result['statusText'] = 'success';
  292. $result['data'] = updateConfigItem($_POST);
  293. } else {
  294. $result['status'] = 'error';
  295. $result['statusText'] = 'API/Token invalid or not set';
  296. $result['data'] = null;
  297. }
  298. break;
  299. default:
  300. $result['status'] = 'error';
  301. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  302. break;
  303. }
  304. break;
  305. case 'v1_update_config_multiple':
  306. switch ($method) {
  307. case 'POST':
  308. if (qualifyRequest(1)) {
  309. $result['status'] = 'success';
  310. $result['statusText'] = 'success';
  311. $result['data'] = updateConfigMultiple($_POST);
  312. } else {
  313. $result['status'] = 'error';
  314. $result['statusText'] = 'API/Token invalid or not set';
  315. $result['data'] = null;
  316. }
  317. break;
  318. default:
  319. $result['status'] = 'error';
  320. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  321. break;
  322. }
  323. break;
  324. case 'v1_update_config_multiple_form':
  325. switch ($method) {
  326. case 'POST':
  327. if (qualifyRequest(1)) {
  328. $result['status'] = 'success';
  329. $result['statusText'] = 'success';
  330. $result['data'] = updateConfigMultipleForm($_POST);
  331. } else {
  332. $result['status'] = 'error';
  333. $result['statusText'] = 'API/Token invalid or not set';
  334. $result['data'] = null;
  335. }
  336. break;
  337. default:
  338. $result['status'] = 'error';
  339. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  340. break;
  341. }
  342. break;
  343. case 'v1_homepage_connect':
  344. switch ($method) {
  345. case 'POST':
  346. $result['status'] = 'success';
  347. $result['statusText'] = 'success';
  348. $result['data'] = homepageConnect($_POST);
  349. break;
  350. default:
  351. $result['status'] = 'error';
  352. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  353. break;
  354. }
  355. break;
  356. case 'v1_ping_list':
  357. switch ($method) {
  358. case 'POST':
  359. $result['status'] = 'success';
  360. $result['statusText'] = 'success';
  361. $result['data'] = ping($_POST['data']['pingList']);
  362. break;
  363. default:
  364. $result['status'] = 'error';
  365. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  366. break;
  367. }
  368. break;
  369. case 'v1_test_api_connection':
  370. switch ($method) {
  371. case 'POST':
  372. if (qualifyRequest(1)) {
  373. $result['status'] = 'success';
  374. $result['statusText'] = 'success';
  375. $result['data'] = testAPIConnection($_POST);
  376. } else {
  377. $result['status'] = 'error';
  378. $result['statusText'] = 'API/Token invalid or not set';
  379. $result['data'] = null;
  380. }
  381. break;
  382. default:
  383. $result['status'] = 'error';
  384. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  385. break;
  386. }
  387. break;
  388. case 'v1_settings_tab_editor_tabs':
  389. switch ($method) {
  390. case 'GET':
  391. if (qualifyRequest(1)) {
  392. $result['status'] = 'success';
  393. $result['statusText'] = 'success';
  394. $result['data'] = $pageSettingsTabEditorTabs;
  395. } else {
  396. $result['status'] = 'error';
  397. $result['statusText'] = 'API/Token invalid or not set';
  398. $result['data'] = null;
  399. }
  400. break;
  401. case 'POST':
  402. if (qualifyRequest(1)) {
  403. $result['status'] = 'success';
  404. $result['statusText'] = 'success';
  405. $result['data'] = editTabs($_POST);
  406. } else {
  407. $result['status'] = 'error';
  408. $result['statusText'] = 'API/Token invalid or not set';
  409. $result['data'] = null;
  410. }
  411. break;
  412. default:
  413. $result['status'] = 'error';
  414. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  415. break;
  416. }
  417. break;
  418. case 'v1_settings_tab_editor_categories':
  419. switch ($method) {
  420. case 'GET':
  421. if (qualifyRequest(1)) {
  422. $result['status'] = 'success';
  423. $result['statusText'] = 'success';
  424. $result['data'] = $pageSettingsTabEditorCategories;
  425. } else {
  426. $result['status'] = 'error';
  427. $result['statusText'] = 'API/Token invalid or not set';
  428. $result['data'] = null;
  429. }
  430. break;
  431. case 'POST':
  432. if (qualifyRequest(1)) {
  433. $result['status'] = 'success';
  434. $result['statusText'] = 'success';
  435. $result['data'] = editCategories($_POST);
  436. } else {
  437. $result['status'] = 'error';
  438. $result['statusText'] = 'API/Token invalid or not set';
  439. $result['data'] = null;
  440. }
  441. break;
  442. default:
  443. $result['status'] = 'error';
  444. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  445. break;
  446. }
  447. break;
  448. case 'v1_settings_user_manage_users':
  449. switch ($method) {
  450. case 'GET':
  451. if (qualifyRequest(1)) {
  452. $result['status'] = 'success';
  453. $result['statusText'] = 'success';
  454. $result['data'] = $pageSettingsUserManageUsers;
  455. } else {
  456. $result['status'] = 'error';
  457. $result['statusText'] = 'API/Token invalid or not set';
  458. $result['data'] = null;
  459. }
  460. break;
  461. case 'POST':
  462. if (qualifyRequest(1)) {
  463. $result['status'] = 'success';
  464. $result['statusText'] = 'success';
  465. $result['data'] = adminEditUser($_POST);
  466. } elseif (qualifyRequest(998)) {
  467. $result['status'] = 'success';
  468. $result['statusText'] = 'success';
  469. $result['data'] = editUser($_POST);
  470. } else {
  471. $result['status'] = 'error';
  472. $result['statusText'] = 'API/Token invalid or not set';
  473. $result['data'] = null;
  474. }
  475. break;
  476. default:
  477. $result['status'] = 'error';
  478. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  479. break;
  480. }
  481. break;
  482. case 'v1_manage_user':
  483. switch ($method) {
  484. case 'POST':
  485. if (qualifyRequest(998)) {
  486. $result['status'] = 'success';
  487. $result['statusText'] = 'success';
  488. $result['data'] = editUser($_POST);
  489. } else {
  490. $result['status'] = 'error';
  491. $result['statusText'] = 'API/Token invalid or not set';
  492. $result['data'] = null;
  493. }
  494. break;
  495. default:
  496. $result['status'] = 'error';
  497. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  498. break;
  499. }
  500. break;
  501. case 'v1_settings_user_manage_groups':
  502. switch ($method) {
  503. case 'GET':
  504. if (qualifyRequest(1)) {
  505. $result['status'] = 'success';
  506. $result['statusText'] = 'success';
  507. $result['data'] = $pageSettingsUserManageGroups;
  508. } else {
  509. $result['status'] = 'error';
  510. $result['statusText'] = 'API/Token invalid or not set';
  511. $result['data'] = null;
  512. }
  513. break;
  514. case 'POST':
  515. if (qualifyRequest(1)) {
  516. $result['status'] = 'success';
  517. $result['statusText'] = 'success';
  518. $result['data'] = adminEditGroup($_POST);
  519. } else {
  520. $result['status'] = 'error';
  521. $result['statusText'] = 'API/Token invalid or not set';
  522. $result['data'] = null;
  523. }
  524. break;
  525. default:
  526. $result['status'] = 'error';
  527. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  528. break;
  529. }
  530. break;
  531. case 'v1_settings_image_manager_view':
  532. switch ($method) {
  533. case 'GET':
  534. if (qualifyRequest(1)) {
  535. $result['status'] = 'success';
  536. $result['statusText'] = 'success';
  537. $result['data'] = $pageSettingsImageManager;
  538. } else {
  539. $result['status'] = 'error';
  540. $result['statusText'] = 'API/Token invalid or not set';
  541. $result['data'] = null;
  542. }
  543. break;
  544. case 'POST':
  545. if (qualifyRequest(1)) {
  546. $result['status'] = 'success';
  547. $result['statusText'] = 'success';
  548. $result['data'] = editImages();
  549. } else {
  550. $result['status'] = 'error';
  551. $result['statusText'] = 'API/Token invalid or not set';
  552. $result['data'] = null;
  553. }
  554. break;
  555. default:
  556. $result['status'] = 'error';
  557. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  558. break;
  559. }
  560. break;
  561. case 'v1_wizard_page':
  562. switch ($method) {
  563. case 'GET':
  564. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  565. $result['status'] = 'success';
  566. $result['statusText'] = 'success';
  567. $result['data'] = $pageWizard;
  568. } else {
  569. $result['status'] = 'error';
  570. $result['statusText'] = 'Wizard has already been run';
  571. $result['data'] = null;
  572. }
  573. break;
  574. default:
  575. $result['status'] = 'error';
  576. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  577. break;
  578. }
  579. break;
  580. case 'v1_dependencies_page':
  581. switch ($method) {
  582. case 'GET':
  583. $result['status'] = 'success';
  584. $result['statusText'] = 'success';
  585. $result['data'] = $pageDependencies;
  586. break;
  587. default:
  588. $result['status'] = 'error';
  589. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  590. break;
  591. }
  592. break;
  593. case 'v1_wizard_config':
  594. switch ($method) {
  595. case 'POST':
  596. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  597. $result['status'] = 'success';
  598. $result['statusText'] = 'success';
  599. $result['data'] = wizardConfig($_POST);
  600. } else {
  601. $result['status'] = 'error';
  602. $result['statusText'] = 'Wizard has already been run';
  603. $result['data'] = null;
  604. }
  605. break;
  606. default:
  607. $result['status'] = 'error';
  608. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  609. break;
  610. }
  611. break;
  612. case 'v1_wizard_path':
  613. switch ($method) {
  614. case 'POST':
  615. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  616. $result['status'] = 'success';
  617. $result['statusText'] = 'success';
  618. $result['data'] = wizardPath($_POST);
  619. } else {
  620. $result['status'] = 'error';
  621. $result['statusText'] = 'Wizard has already been run';
  622. $result['data'] = null;
  623. }
  624. break;
  625. default:
  626. $result['status'] = 'error';
  627. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  628. break;
  629. }
  630. break;
  631. case 'v1_login':
  632. switch ($method) {
  633. case 'POST':
  634. $result['status'] = 'success';
  635. $result['statusText'] = 'success';
  636. $result['data'] = login($_POST);
  637. break;
  638. default:
  639. $result['status'] = 'error';
  640. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  641. break;
  642. }
  643. break;
  644. case 'v1_register':
  645. switch ($method) {
  646. case 'POST':
  647. $result['status'] = 'success';
  648. $result['statusText'] = 'success';
  649. $result['data'] = register($_POST);
  650. break;
  651. default:
  652. $result['status'] = 'error';
  653. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  654. break;
  655. }
  656. break;
  657. case 'v1_recover':
  658. switch ($method) {
  659. case 'POST':
  660. $result['status'] = 'success';
  661. $result['statusText'] = 'success';
  662. $result['data'] = recover($_POST);
  663. break;
  664. default:
  665. $result['status'] = 'error';
  666. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  667. break;
  668. }
  669. break;
  670. case 'v1_unlock':
  671. switch ($method) {
  672. case 'POST':
  673. $result['status'] = 'success';
  674. $result['statusText'] = 'success';
  675. $result['data'] = unlock($_POST);
  676. break;
  677. default:
  678. $result['status'] = 'error';
  679. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  680. break;
  681. }
  682. break;
  683. case 'v1_lock':
  684. switch ($method) {
  685. case 'POST':
  686. $result['status'] = 'success';
  687. $result['statusText'] = 'success';
  688. $result['data'] = lock();
  689. break;
  690. default:
  691. $result['status'] = 'error';
  692. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  693. break;
  694. }
  695. break;
  696. case 'v1_test_iframe':
  697. switch ($method) {
  698. case 'POST':
  699. $result['status'] = 'success';
  700. $result['statusText'] = 'success';
  701. $result['data'] = frameTest($_POST['data']['url']);
  702. break;
  703. default:
  704. $result['status'] = 'error';
  705. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  706. break;
  707. }
  708. break;
  709. case 'v1_upgrade':
  710. case 'v1_update':
  711. case 'v1_force':
  712. switch ($method) {
  713. case 'POST':
  714. if (qualifyRequest(1)) {
  715. $result['status'] = 'success';
  716. $result['statusText'] = 'success';
  717. $result['data'] = upgradeInstall($_POST['data']['branch'], $_POST['data']['stage']);
  718. } else {
  719. $result['status'] = 'error';
  720. $result['statusText'] = 'API/Token invalid or not set';
  721. $result['data'] = null;
  722. }
  723. break;
  724. default:
  725. $result['status'] = 'error';
  726. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  727. break;
  728. }
  729. break;
  730. case 'v1_login_page':
  731. switch ($method) {
  732. case 'GET':
  733. $result['status'] = 'success';
  734. $result['statusText'] = 'success';
  735. $result['data'] = $pageLogin;
  736. break;
  737. default:
  738. $result['status'] = 'error';
  739. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  740. break;
  741. }
  742. break;
  743. case 'v1_lockscreen':
  744. switch ($method) {
  745. case 'GET':
  746. $result['status'] = 'success';
  747. $result['statusText'] = 'success';
  748. $result['data'] = $pageLockScreen;
  749. break;
  750. default:
  751. $result['status'] = 'error';
  752. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  753. break;
  754. }
  755. break;
  756. case 'v1_login_log':
  757. switch ($method) {
  758. case 'GET':
  759. if (qualifyRequest(1)) {
  760. $result['status'] = 'success';
  761. $result['statusText'] = 'success';
  762. $result['data'] = getLog('loginLog');
  763. } else {
  764. $result['status'] = 'error';
  765. $result['statusText'] = 'API/Token invalid or not set';
  766. $result['data'] = null;
  767. }
  768. break;
  769. default:
  770. $result['status'] = 'error';
  771. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  772. break;
  773. }
  774. break;
  775. case 'v1_organizr_log':
  776. switch ($method) {
  777. case 'GET':
  778. if (qualifyRequest(1)) {
  779. $result['status'] = 'success';
  780. $result['statusText'] = 'success';
  781. $result['data'] = getLog('org');
  782. } else {
  783. $result['status'] = 'error';
  784. $result['statusText'] = 'API/Token invalid or not set';
  785. $result['data'] = null;
  786. }
  787. break;
  788. default:
  789. $result['status'] = 'error';
  790. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  791. break;
  792. }
  793. break;
  794. case 'v1_user_list':
  795. switch ($method) {
  796. case 'GET':
  797. if (qualifyRequest(1)) {
  798. $result['status'] = 'success';
  799. $result['statusText'] = 'success';
  800. $result['data'] = allUsers();
  801. } else {
  802. $result['status'] = 'error';
  803. $result['statusText'] = 'API/Token invalid or not set';
  804. $result['data'] = null;
  805. }
  806. break;
  807. default:
  808. $result['status'] = 'error';
  809. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  810. break;
  811. }
  812. break;
  813. case 'v1_tab_list':
  814. switch ($method) {
  815. case 'GET':
  816. if (qualifyRequest(1)) {
  817. $result['status'] = 'success';
  818. $result['statusText'] = 'success';
  819. $result['data'] = allTabs();
  820. } else {
  821. $result['status'] = 'error';
  822. $result['statusText'] = 'API/Token invalid or not set';
  823. $result['data'] = null;
  824. }
  825. break;
  826. default:
  827. $result['status'] = 'error';
  828. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  829. break;
  830. }
  831. break;
  832. case 'v1_image_list':
  833. switch ($method) {
  834. case 'GET':
  835. if (qualifyRequest(1)) {
  836. $result['status'] = 'success';
  837. $result['statusText'] = 'success';
  838. $result['data'] = getImages();
  839. } else {
  840. $result['status'] = 'error';
  841. $result['statusText'] = 'API/Token invalid or not set';
  842. $result['data'] = null;
  843. }
  844. break;
  845. default:
  846. $result['status'] = 'error';
  847. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  848. break;
  849. }
  850. break;
  851. case 'v1_customize_appearance':
  852. switch ($method) {
  853. case 'GET':
  854. if (qualifyRequest(1)) {
  855. $result['status'] = 'success';
  856. $result['statusText'] = 'success';
  857. $result['data'] = getCustomizeAppearance();
  858. } else {
  859. $result['status'] = 'error';
  860. $result['statusText'] = 'API/Token invalid or not set';
  861. $result['data'] = null;
  862. }
  863. break;
  864. default:
  865. $result['status'] = 'error';
  866. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  867. break;
  868. }
  869. break;
  870. case 'v1_sso':
  871. switch ($method) {
  872. case 'GET':
  873. if (qualifyRequest(1)) {
  874. $result['status'] = 'success';
  875. $result['statusText'] = 'success';
  876. $result['data'] = getSSO();
  877. } else {
  878. $result['status'] = 'error';
  879. $result['statusText'] = 'API/Token invalid or not set';
  880. $result['data'] = null;
  881. }
  882. break;
  883. default:
  884. $result['status'] = 'error';
  885. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  886. break;
  887. }
  888. break;
  889. case 'v1_settings_main':
  890. switch ($method) {
  891. case 'GET':
  892. if (qualifyRequest(1)) {
  893. $result['status'] = 'success';
  894. $result['statusText'] = 'success';
  895. $result['data'] = getSettingsMain();
  896. } else {
  897. $result['status'] = 'error';
  898. $result['statusText'] = 'API/Token invalid or not set';
  899. $result['data'] = null;
  900. }
  901. break;
  902. default:
  903. $result['status'] = 'error';
  904. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  905. break;
  906. }
  907. break;
  908. case 'v1_plugin_install':
  909. switch ($method) {
  910. case 'POST':
  911. if (qualifyRequest(1)) {
  912. $result['status'] = 'success';
  913. $result['statusText'] = 'success';
  914. $result['data'] = installPlugin($_POST);
  915. } else {
  916. $result['status'] = 'error';
  917. $result['statusText'] = 'API/Token invalid or not set';
  918. $result['data'] = null;
  919. }
  920. break;
  921. default:
  922. $result['status'] = 'error';
  923. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  924. break;
  925. }
  926. break;
  927. case 'v1_plugin_remove':
  928. switch ($method) {
  929. case 'POST':
  930. if (qualifyRequest(1)) {
  931. $result['status'] = 'success';
  932. $result['statusText'] = 'success';
  933. $result['data'] = removePlugin($_POST);
  934. } else {
  935. $result['status'] = 'error';
  936. $result['statusText'] = 'API/Token invalid or not set';
  937. $result['data'] = null;
  938. }
  939. break;
  940. default:
  941. $result['status'] = 'error';
  942. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  943. break;
  944. }
  945. break;
  946. case 'v1_theme_install':
  947. switch ($method) {
  948. case 'POST':
  949. if (qualifyRequest(1)) {
  950. $result['status'] = 'success';
  951. $result['statusText'] = 'success';
  952. $result['data'] = installTheme($_POST);
  953. } else {
  954. $result['status'] = 'error';
  955. $result['statusText'] = 'API/Token invalid or not set';
  956. $result['data'] = null;
  957. }
  958. break;
  959. default:
  960. $result['status'] = 'error';
  961. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  962. break;
  963. }
  964. break;
  965. case 'v1_theme_remove':
  966. switch ($method) {
  967. case 'POST':
  968. if (qualifyRequest(1)) {
  969. $result['status'] = 'success';
  970. $result['statusText'] = 'success';
  971. $result['data'] = removeTheme($_POST);
  972. } else {
  973. $result['status'] = 'error';
  974. $result['statusText'] = 'API/Token invalid or not set';
  975. $result['data'] = null;
  976. }
  977. break;
  978. default:
  979. $result['status'] = 'error';
  980. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  981. break;
  982. }
  983. break;
  984. case 'v1_user_edit':
  985. switch ($method) {
  986. case 'POST':
  987. if (qualifyRequest(1)) {
  988. $result['status'] = 'success';
  989. $result['statusText'] = 'success';
  990. $result['data'] = adminEditUser($_POST);
  991. } elseif (qualifyRequest(998)) {
  992. $result['status'] = 'success';
  993. $result['statusText'] = 'success';
  994. $result['data'] = editUser($_POST);
  995. } else {
  996. $result['status'] = 'error';
  997. $result['statusText'] = 'API/Token invalid or not set';
  998. $result['data'] = null;
  999. }
  1000. break;
  1001. default:
  1002. $result['status'] = 'error';
  1003. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1004. break;
  1005. }
  1006. break;
  1007. case 'v1_2fa_create':
  1008. switch ($method) {
  1009. case 'POST':
  1010. if (qualifyRequest(998)) {
  1011. $result['status'] = 'success';
  1012. $result['statusText'] = 'success';
  1013. $result['data'] = create2FA($_POST['data']['type']);
  1014. } else {
  1015. $result['status'] = 'error';
  1016. $result['statusText'] = 'API/Token invalid or not set';
  1017. $result['data'] = null;
  1018. }
  1019. break;
  1020. default:
  1021. $result['status'] = 'error';
  1022. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1023. break;
  1024. }
  1025. break;
  1026. case 'v1_2fa_save':
  1027. switch ($method) {
  1028. case 'POST':
  1029. if (qualifyRequest(998)) {
  1030. $result['status'] = 'success';
  1031. $result['statusText'] = 'success';
  1032. $result['data'] = save2FA($_POST['data']['secret'], $_POST['data']['type']);
  1033. } else {
  1034. $result['status'] = 'error';
  1035. $result['statusText'] = 'API/Token invalid or not set';
  1036. $result['data'] = null;
  1037. }
  1038. break;
  1039. default:
  1040. $result['status'] = 'error';
  1041. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1042. break;
  1043. }
  1044. break;
  1045. case 'v1_2fa_verify':
  1046. switch ($method) {
  1047. case 'POST':
  1048. if (qualifyRequest(998)) {
  1049. $result['status'] = 'success';
  1050. $result['statusText'] = 'success';
  1051. $result['data'] = verify2FA($_POST['data']['secret'], $_POST['data']['code'], $_POST['data']['type']);
  1052. } else {
  1053. $result['status'] = 'error';
  1054. $result['statusText'] = 'API/Token invalid or not set';
  1055. $result['data'] = null;
  1056. }
  1057. break;
  1058. default:
  1059. $result['status'] = 'error';
  1060. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1061. break;
  1062. }
  1063. break;
  1064. case 'v1_2fa_remove':
  1065. switch ($method) {
  1066. case 'GET':
  1067. if (qualifyRequest(998)) {
  1068. $result['status'] = 'success';
  1069. $result['statusText'] = 'success';
  1070. $result['data'] = remove2FA();
  1071. } else {
  1072. $result['status'] = 'error';
  1073. $result['statusText'] = 'API/Token invalid or not set';
  1074. $result['data'] = null;
  1075. }
  1076. break;
  1077. default:
  1078. $result['status'] = 'error';
  1079. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1080. break;
  1081. }
  1082. break;
  1083. case 'v1_logout':
  1084. switch ($method) {
  1085. case 'GET':
  1086. $result['status'] = 'success';
  1087. $result['statusText'] = 'success';
  1088. $result['data'] = logout();
  1089. break;
  1090. default:
  1091. $result['status'] = 'error';
  1092. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1093. break;
  1094. }
  1095. break;
  1096. case 'v1_launch_organizr':
  1097. switch ($method) {
  1098. case 'GET':
  1099. $pluginSearch = '-enabled';
  1100. $pluginInclude = '-include';
  1101. $status = array();
  1102. $result['status'] = 'success';
  1103. $result['statusText'] = 'success';
  1104. $status['status'] = organizrStatus();
  1105. $result['appearance'] = loadAppearance();
  1106. $status['user'] = $GLOBALS['organizrUser'];
  1107. $status['categories'] = loadTabs()['categories'];
  1108. $status['tabs'] = loadTabs()['tabs'];
  1109. $status['plugins'] = array_filter($GLOBALS, function ($k) use ($pluginSearch) {
  1110. return stripos($k, $pluginSearch) !== false;
  1111. }, ARRAY_FILTER_USE_KEY);
  1112. $status['plugins']['includes'] = array_filter($GLOBALS, function ($k) use ($pluginInclude) {
  1113. return stripos($k, $pluginInclude) !== false;
  1114. }, ARRAY_FILTER_USE_KEY);
  1115. $result['data'] = $status;
  1116. $result['branch'] = $GLOBALS['branch'];
  1117. $result['theme'] = $GLOBALS['theme'];
  1118. $result['style'] = $GLOBALS['style'];
  1119. $result['version'] = $GLOBALS['installedVersion'];
  1120. $result['sso'] = array(
  1121. 'myPlexAccessToken' => isset($_COOKIE['mpt']) ? $_COOKIE['mpt'] : false,
  1122. 'id_token' => isset($_COOKIE['Auth']) ? $_COOKIE['Auth'] : false
  1123. );
  1124. $result['settings'] = organizrSpecialSettings();
  1125. break;
  1126. default:
  1127. $result['status'] = 'error';
  1128. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1129. break;
  1130. }
  1131. break;
  1132. case 'v1_auth':
  1133. switch ($method) {
  1134. case 'GET':
  1135. auth();
  1136. break;
  1137. default:
  1138. $result['status'] = 'error';
  1139. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1140. break;
  1141. }
  1142. break;
  1143. case 'v1_plugin':
  1144. switch ($method) {
  1145. case 'POST':
  1146. case 'GET':
  1147. // Include all plugin api Calls
  1148. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'plugins' . DIRECTORY_SEPARATOR . 'api' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  1149. require_once $filename;
  1150. }
  1151. break;
  1152. default:
  1153. $result['status'] = 'error';
  1154. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1155. break;
  1156. }
  1157. break;
  1158. case 'v1_image':
  1159. switch ($method) {
  1160. case 'GET':
  1161. getImage();
  1162. break;
  1163. default:
  1164. $result['status'] = 'error';
  1165. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1166. break;
  1167. }
  1168. break;
  1169. case 'v1_downloader':
  1170. switch ($method) {
  1171. case 'POST':
  1172. $result['status'] = 'success';
  1173. $result['statusText'] = 'success';
  1174. $result['data'] = downloader($_POST);
  1175. break;
  1176. default:
  1177. $result['status'] = 'error';
  1178. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1179. break;
  1180. }
  1181. break;
  1182. case 'v1_import_users':
  1183. switch ($method) {
  1184. case 'POST':
  1185. if (qualifyRequest(1)) {
  1186. $result['status'] = 'success';
  1187. $result['statusText'] = 'success';
  1188. $result['data'] = importUsersType($_POST);
  1189. } else {
  1190. $result['status'] = 'error';
  1191. $result['statusText'] = 'API/Token invalid or not set';
  1192. $result['data'] = null;
  1193. }
  1194. break;
  1195. default:
  1196. $result['status'] = 'error';
  1197. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1198. break;
  1199. }
  1200. break;
  1201. case 'v1_ombi':
  1202. switch ($method) {
  1203. case 'POST':
  1204. $result['status'] = 'success';
  1205. $result['statusText'] = 'success';
  1206. $result['data'] = ombiAPI($_POST);
  1207. break;
  1208. default:
  1209. $result['status'] = 'error';
  1210. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1211. break;
  1212. }
  1213. break;
  1214. case 'v1_plex_join':
  1215. switch ($method) {
  1216. case 'POST':
  1217. $result['status'] = 'success';
  1218. $result['statusText'] = 'success';
  1219. $result['data'] = plexJoinAPI($_POST);
  1220. break;
  1221. default:
  1222. $result['status'] = 'error';
  1223. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1224. break;
  1225. }
  1226. break;
  1227. case 'v1_token_revoke':
  1228. switch ($method) {
  1229. case 'POST':
  1230. $result['status'] = 'success';
  1231. $result['statusText'] = 'success';
  1232. $result['data'] = revokeToken($_POST);
  1233. break;
  1234. default:
  1235. $result['status'] = 'error';
  1236. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1237. break;
  1238. }
  1239. break;
  1240. case 'v1_update_db_manual':
  1241. switch ($method) {
  1242. case 'GET':
  1243. if (qualifyRequest(1)) {
  1244. $result['status'] = 'success';
  1245. $result['statusText'] = 'success';
  1246. $result['data'] = updateDB($GLOBALS['installedVersion']);
  1247. } else {
  1248. $result['status'] = 'error';
  1249. $result['statusText'] = 'API/Token invalid or not set';
  1250. $result['data'] = null;
  1251. }
  1252. break;
  1253. default:
  1254. $result['status'] = 'error';
  1255. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1256. break;
  1257. }
  1258. break;
  1259. case 'v1_version':
  1260. switch ($method) {
  1261. case 'GET':
  1262. $result['status'] = 'success';
  1263. $result['statusText'] = 'success';
  1264. $result['data'] = $GLOBALS['installedVersion'];
  1265. break;
  1266. default:
  1267. $result['status'] = 'error';
  1268. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1269. break;
  1270. }
  1271. break;
  1272. case 'v1_ping':
  1273. switch ($method) {
  1274. case 'GET':
  1275. $result['status'] = 'success';
  1276. $result['statusText'] = 'success';
  1277. $result['data'] = 'pong';
  1278. break;
  1279. default:
  1280. $result['status'] = 'error';
  1281. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1282. break;
  1283. }
  1284. break;
  1285. case 'v1_docker_update':
  1286. switch ($method) {
  1287. case 'GET':
  1288. if (qualifyRequest(1)) {
  1289. $result['status'] = 'success';
  1290. $result['statusText'] = 'success';
  1291. $result['data'] = dockerUpdate();
  1292. } else {
  1293. $result['status'] = 'error';
  1294. $result['statusText'] = 'API/Token invalid or not set';
  1295. $result['data'] = null;
  1296. }
  1297. break;
  1298. default:
  1299. $result['status'] = 'error';
  1300. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1301. break;
  1302. }
  1303. break;
  1304. case 'v1_windows_update':
  1305. switch ($method) {
  1306. case 'GET':
  1307. if (qualifyRequest(1)) {
  1308. $result['status'] = 'success';
  1309. $result['statusText'] = 'success';
  1310. $result['data'] = windowsUpdate();
  1311. } else {
  1312. $result['status'] = 'error';
  1313. $result['statusText'] = 'API/Token invalid or not set';
  1314. $result['data'] = null;
  1315. }
  1316. break;
  1317. default:
  1318. $result['status'] = 'error';
  1319. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1320. break;
  1321. }
  1322. break;
  1323. default:
  1324. //No Function Available
  1325. $result['status'] = 'error';
  1326. $result['statusText'] = 'function requested is not defined';
  1327. break;
  1328. }
  1329. //Set Default Result
  1330. if (!$result) {
  1331. $result['status'] = "error";
  1332. $result['error'] = "An error has occurred";
  1333. }
  1334. $result['generationDate'] = $GLOBALS['currentTime'];
  1335. $generationTime += microtime(true);
  1336. $result['generationTime'] = (sprintf('%f', $generationTime) * 1000) . 'ms';
  1337. //return JSON array
  1338. if ($pretty) {
  1339. echo '<pre>' . safe_json_encode($result, JSON_PRETTY_PRINT) . '</pre>';
  1340. } else {
  1341. exit(safe_json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));
  1342. }