index.php 57 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914
  1. <?php
  2. /**
  3. * @apiDefine UserNotAuthorizedError
  4. *
  5. * @apiError UserNotAuthorized The user is not authorized or Token not valid
  6. *
  7. * @apiErrorExample Error-Response:
  8. * HTTP/1.1 401 Not Authorized
  9. * {
  10. * "status": "error",
  11. * "statusText": "API/Token invalid or not set",
  12. * "data": null
  13. * }
  14. */
  15. /**
  16. * @apiDefine DataBooleanSuccess
  17. * @apiSuccess {Boolean} data Output Boolean.
  18. * @apiSuccessExample Success-Response:
  19. * HTTP/1.1 200 OK
  20. * {
  21. * "status": "success",
  22. * "statusText": "success",
  23. * "data": true
  24. * }
  25. *
  26. */
  27. /**
  28. * @apiDefine DataJSONSuccess
  29. * @apiSuccess {JSON} data Output JSON.
  30. * @apiSuccessExample Success-Response:
  31. * HTTP/1.1 200 OK
  32. * {
  33. * "status": "success",
  34. * "statusText": "success",
  35. * "data": { **JSON** }
  36. * }
  37. *
  38. */
  39. /**
  40. * @apiDefine DataHTMLSuccess
  41. * @apiSuccess {String} data Output of Page.
  42. *
  43. * @apiSuccessExample Success-Response:
  44. * HTTP/1.1 200 OK
  45. * {
  46. * "status": "success",
  47. * "statusText": "success",
  48. * "data": "<html>html encoded elements</html>"
  49. * }
  50. *
  51. */
  52. /**
  53. * @apiDefine admin Admin or API Key Access Only
  54. * Only the Admin/Co-Admin and API Key have access to this endpoint
  55. */
  56. //include functions
  57. require_once 'functions.php';
  58. //Set result array
  59. $result = array();
  60. //Get request method
  61. $method = $_SERVER['REQUEST_METHOD'];
  62. $pretty = isset($_GET['pretty']) ? true : false;
  63. reset($_GET);
  64. $function = (key($_GET) ? str_replace("/", "_", key($_GET)) : false);
  65. //Exit if $function is blank
  66. if ($function === false) {
  67. $result['status'] = "error";
  68. $result['statusText'] = "No API Path Supplied";
  69. exit(json_encode($result));
  70. }
  71. $approvedFunctionsBypass = array(
  72. 'v1_upgrade',
  73. 'v1_update',
  74. 'v1_force',
  75. 'v1_auth',
  76. 'v1_wizard_config',
  77. 'v1_login',
  78. 'v1_wizard_path',
  79. 'v1_login_api'
  80. );
  81. if (!in_array($function, $approvedFunctionsBypass)) {
  82. if (isApprovedRequest($method) === false) {
  83. $result['status'] = "error";
  84. $result['statusText'] = "Not Authorized";
  85. http_response_code(401);
  86. writeLog('success', 'Killed Attack From [' . (isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : 'No Referer') . ']', $GLOBALS['organizrUser']['username']);
  87. exit(json_encode($result));
  88. }
  89. }
  90. $result['request'] = key($_GET);
  91. $result['params'] = $_POST;
  92. //Custom Page Check
  93. if (strpos($function, 'v1_custom_page_') !== false) {
  94. $endpoint = explode('v1_custom_page_', $function)[1];
  95. $function = 'v1_custom_page';
  96. }
  97. switch ($function) {
  98. case 'v1_settings_page':
  99. switch ($method) {
  100. /**
  101. * @api {get} v1/settings/page Get Admin Settings
  102. * @apiVersion 1.0.0
  103. * @apiName GetSettingsPage
  104. * @apiGroup Pages
  105. * @apiUse DataBooleanSuccess
  106. * @apiUse UserNotAuthorizedError
  107. */
  108. case 'GET':
  109. if (qualifyRequest(1)) {
  110. $result['status'] = 'success';
  111. $result['statusText'] = 'success';
  112. $result['data'] = $pageSettings;
  113. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  114. } else {
  115. $result['status'] = 'error';
  116. $result['statusText'] = 'API/Token invalid or not set';
  117. $result['data'] = null;
  118. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  119. }
  120. break;
  121. default:
  122. $result['status'] = 'error';
  123. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  124. break;
  125. }
  126. break;
  127. case 'v1_homepage_page':
  128. switch ($method) {
  129. /**
  130. * @api {get} v1/homepage/page Get Homepage
  131. * @apiVersion 1.0.0
  132. * @apiName GetHomepagePage
  133. * @apiGroup Pages
  134. * @apiUse DataHTMLSuccess
  135. * @apiUse UserNotAuthorizedError
  136. */
  137. case 'GET':
  138. $result['status'] = 'success';
  139. $result['statusText'] = 'success';
  140. $result['data'] = $pageHomepage;
  141. break;
  142. default:
  143. $result['status'] = 'error';
  144. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  145. break;
  146. }
  147. break;
  148. case 'v1_settings_plugins':
  149. switch ($method) {
  150. /**
  151. * @api {get} v1/settings/plugins Get Plugins
  152. * @apiVersion 1.0.0
  153. * @apiName GetPluginsPage
  154. * @apiGroup Pages
  155. * @apiUse DataHTMLSuccess
  156. * @apiUse UserNotAuthorizedError
  157. */
  158. case 'GET':
  159. if (qualifyRequest(1)) {
  160. $result['status'] = 'success';
  161. $result['statusText'] = 'success';
  162. $result['data'] = $pageSettingsPlugins;
  163. } else {
  164. $result['status'] = 'error';
  165. $result['statusText'] = 'API/Token invalid or not set';
  166. $result['data'] = null;
  167. }
  168. break;
  169. default:
  170. $result['status'] = 'error';
  171. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  172. break;
  173. }
  174. break;
  175. case 'v1_settings_tab_editor_homepage':
  176. switch ($method) {
  177. /**
  178. * @api {get} v1/settings/tab/editor/homepage Get Homepage Settings
  179. * @apiVersion 1.0.0
  180. * @apiName GetSettingsTabEditorHomepagePage
  181. * @apiGroup Pages
  182. * @apiUse DataHTMLSuccess
  183. * @apiUse UserNotAuthorizedError
  184. */
  185. case 'GET':
  186. if (qualifyRequest(1)) {
  187. $result['status'] = 'success';
  188. $result['statusText'] = 'success';
  189. $result['data'] = $pageSettingsTabEditorHomepage;
  190. } else {
  191. $result['status'] = 'error';
  192. $result['statusText'] = 'API/Token invalid or not set';
  193. $result['data'] = null;
  194. }
  195. break;
  196. default:
  197. $result['status'] = 'error';
  198. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  199. break;
  200. }
  201. break;
  202. case 'v1_settings_tab_editor_homepage_order':
  203. switch ($method) {
  204. /**
  205. * @api {get} v1/settings/tab/editor/homepage Get Homepage Order
  206. * @apiVersion 1.0.0
  207. * @apiName GetSettingsTabEditorHomepageOrderPage
  208. * @apiGroup Pages
  209. * @apiUse DataHTMLSuccess
  210. * @apiUse UserNotAuthorizedError
  211. */
  212. case 'GET':
  213. if (qualifyRequest(1)) {
  214. $result['status'] = 'success';
  215. $result['statusText'] = 'success';
  216. $result['data'] = $pageSettingsTabEditorHomepageOrder;
  217. } else {
  218. $result['status'] = 'error';
  219. $result['statusText'] = 'API/Token invalid or not set';
  220. $result['data'] = null;
  221. }
  222. break;
  223. default:
  224. $result['status'] = 'error';
  225. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  226. break;
  227. }
  228. break;
  229. case 'v1_settings_homepage_list':
  230. switch ($method) {
  231. /**
  232. * @api {get} v1/settings/homepage/list Get Homepage Settings
  233. * @apiVersion 1.0.0
  234. * @apiName GetHomepageSettigns
  235. * @apiGroup Homepage
  236. * @apiSuccess {String} data Output of all Homepage Settings.
  237. * @apiSuccessExample Success-Response:
  238. * HTTP/1.1 200 OK
  239. * {
  240. * "status": "success",
  241. * "statusText": "success",
  242. * "data": [{
  243. * "name": "HealthChecks",
  244. * "enabled": true,
  245. * "image": "plugins\/images\/tabs\/healthchecks.png",
  246. * "category": "Monitor",
  247. * "settings": {
  248. * "Enable": [
  249. * {
  250. * "type": "switch",
  251. * "name": "homepageHealthChecksEnabled",
  252. * "label": "Enable",
  253. * "value": true
  254. * }, {
  255. * "type": "select",
  256. * "name": "homepageHealthChecksAuth",
  257. * "label": "Minimum Authentication",
  258. * "value": "1",
  259. * "options": [
  260. * {
  261. * "name": "Admin",
  262. * "value": 0
  263. * }, {
  264. * "name": "Co-Admin",
  265. * "value": 1
  266. * }, {
  267. * "name": "Super User",
  268. * "value": 2
  269. * }, {
  270. * "name": "Power User",
  271. * "value": 3
  272. * }, {
  273. * "name": "User",
  274. * "value": 4
  275. * }, {
  276. * "name": "temp again",
  277. * "value": 5
  278. * }, {
  279. * "name": "GuestAccts",
  280. * "value": 999
  281. * }
  282. * ]
  283. * }
  284. * ],
  285. * "Connection": [
  286. * {
  287. * "type": "input",
  288. * "name": "healthChecksURL",
  289. * "label": "URL",
  290. * "value": "https://healthchecks.io/api/v1/checks/",
  291. * "help": "URL for HealthChecks API",
  292. * "placeholder": "HealthChecks API URL"
  293. * }, {
  294. * "type": "password-alt",
  295. * "name": "healthChecksToken",
  296. * "label": "Token",
  297. * "value": "TOKENHERE"
  298. * }
  299. * ],
  300. * "Misc Options": [
  301. * {
  302. * "type": "input",
  303. * "name": "healthChecksTags",
  304. * "label": "Tags",
  305. * "value": "",
  306. * "help": "Pull only checks with this tag - Blank for all",
  307. * "placeholder": "Multiple tags using CSV - tag1,tag2"
  308. * }, {
  309. * "type": "select",
  310. * "name": "homepageHealthChecksRefresh",
  311. * "label": "Refresh Seconds",
  312. * "value": "3600000",
  313. * "options": [
  314. * {
  315. * "name": "5",
  316. * "value": "5000"
  317. * }, {
  318. * "name": "10",
  319. * "value": "10000"
  320. * }, {
  321. * "name": "15",
  322. * "value": "15000"
  323. * }, {
  324. * "name": "30",
  325. * "value": "30000"
  326. * }, {
  327. * "name": "60 [1 Minute]",
  328. * "value": "60000"
  329. * }, {
  330. * "name": "300 [5 Minutes]",
  331. * "value": "300000"
  332. * }, {
  333. * "name": "600 [10 Minutes]",
  334. * "value": "600000"
  335. * }, {
  336. * "name": "900 [15 Minutes]",
  337. * "value": "900000"
  338. * }, {
  339. * "name": "1800 [30 Minutes]",
  340. * "value": "1800000"
  341. * }, {
  342. * "name": "3600 [1 Hour]",
  343. * "value": "3600000"
  344. * }
  345. * ]
  346. * }
  347. * ]
  348. * }]
  349. * }
  350. * @apiUse UserNotAuthorizedError
  351. */
  352. case 'GET':
  353. if (qualifyRequest(1)) {
  354. $result['status'] = 'success';
  355. $result['statusText'] = 'success';
  356. $result['data'] = getHomepageList();
  357. } else {
  358. $result['status'] = 'error';
  359. $result['statusText'] = 'API/Token invalid or not set';
  360. $result['data'] = null;
  361. }
  362. break;
  363. default:
  364. $result['status'] = 'error';
  365. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  366. break;
  367. }
  368. break;
  369. case 'v1_settings_plugins_list':
  370. /**
  371. * @api {get} v1/settings/plugins/list Get List of Plugins
  372. * @apiVersion 1.0.0
  373. * @apiName GetPlugins
  374. * @apiGroup Plugins
  375. * @apiSuccess {String} data Output plugins list.
  376. * @apiSuccessExample Success-Response:
  377. * HTTP/1.1 200 OK
  378. * {
  379. * "status": "success",
  380. * "statusText": "success",
  381. * "data": {
  382. * "chat": {
  383. * "name": "Chat",
  384. * "author": "CauseFX",
  385. * "category": "Utilities",
  386. * "link": "",
  387. * "license": "personal,business",
  388. * "idPrefix": "CHAT",
  389. * "configPrefix": "CHAT",
  390. * "version": "1.0.0",
  391. * "image": "plugins/images/chat.png",
  392. * "settings": true,
  393. * "homepage": false,
  394. * "enabled": true
  395. * }
  396. * }
  397. * }
  398. * @apiUse UserNotAuthorizedError
  399. */
  400. /**
  401. * @api {post} v1/settings/plugins/list Toggle Plugin
  402. * @apiVersion 1.0.0
  403. * @apiName TogglePlugin
  404. * @apiGroup Plugins
  405. * @apiParam {Object} data nested data object.
  406. * @apiParam {String} data[action] enable/disable.
  407. * @apiParam {String} data[name] Name of Plugin.
  408. * @apiParam {String} data[configName] configName i.e. CHAT-enabled.
  409. * @apiUse DataBooleanSuccess
  410. * @apiUse UserNotAuthorizedError
  411. */
  412. switch ($method) {
  413. case 'GET':
  414. if (qualifyRequest(1)) {
  415. $result['status'] = 'success';
  416. $result['statusText'] = 'success';
  417. $result['data'] = getPlugins();
  418. } else {
  419. $result['status'] = 'error';
  420. $result['statusText'] = 'API/Token invalid or not set';
  421. $result['data'] = null;
  422. }
  423. break;
  424. case 'POST':
  425. if (qualifyRequest(1)) {
  426. $result['status'] = 'success';
  427. $result['statusText'] = 'success';
  428. $result['data'] = editPlugins($_POST);
  429. } else {
  430. $result['status'] = 'error';
  431. $result['statusText'] = 'API/Token invalid or not set';
  432. $result['data'] = null;
  433. }
  434. break;
  435. default:
  436. $result['status'] = 'error';
  437. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  438. break;
  439. }
  440. break;
  441. case 'v1_settings_settings_logs':
  442. /**
  443. * @api {get} v1/settings/settings/logs Get Logs
  444. * @apiVersion 1.0.0
  445. * @apiName GetLogsPage
  446. * @apiGroup Pages
  447. * @apiUse DataHTMLSuccess
  448. * @apiUse UserNotAuthorizedError
  449. */
  450. switch ($method) {
  451. case 'GET':
  452. if (qualifyRequest(1)) {
  453. $result['status'] = 'success';
  454. $result['statusText'] = 'success';
  455. $result['data'] = $pageSettingsSettingsLogs;
  456. } else {
  457. $result['status'] = 'error';
  458. $result['statusText'] = 'API/Token invalid or not set';
  459. $result['data'] = null;
  460. }
  461. break;
  462. default:
  463. $result['status'] = 'error';
  464. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  465. break;
  466. }
  467. break;
  468. case 'v1_settings_settings_sso':
  469. /**
  470. * @api {get} v1/settings/settings/sso Get SSO
  471. * @apiVersion 1.0.0
  472. * @apiName GetSSOPage
  473. * @apiGroup Pages
  474. * @apiUse DataHTMLSuccess
  475. * @apiUse UserNotAuthorizedError
  476. */
  477. switch ($method) {
  478. case 'GET':
  479. if (qualifyRequest(1)) {
  480. $result['status'] = 'success';
  481. $result['statusText'] = 'success';
  482. $result['data'] = $pageSettingsSettingsSSO;
  483. } else {
  484. $result['status'] = 'error';
  485. $result['statusText'] = 'API/Token invalid or not set';
  486. $result['data'] = null;
  487. }
  488. break;
  489. default:
  490. $result['status'] = 'error';
  491. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  492. break;
  493. }
  494. break;
  495. case 'v1_settings_settings_main':
  496. /**
  497. * @api {get} v1/settings/settings/main Get Settings Main
  498. * @apiVersion 1.0.0
  499. * @apiName GetSettingsMainPage
  500. * @apiGroup Pages
  501. * @apiUse DataHTMLSuccess
  502. * @apiUse UserNotAuthorizedError
  503. */
  504. switch ($method) {
  505. case 'GET':
  506. if (qualifyRequest(1)) {
  507. $result['status'] = 'success';
  508. $result['statusText'] = 'success';
  509. $result['data'] = $pageSettingsSettingsMain;
  510. } else {
  511. $result['status'] = 'error';
  512. $result['statusText'] = 'API/Token invalid or not set';
  513. $result['data'] = null;
  514. }
  515. break;
  516. default:
  517. $result['status'] = 'error';
  518. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  519. break;
  520. }
  521. break;
  522. case 'v1_settings_customize_appearance':
  523. /**
  524. * @api {get} v1/settings/customize/appearance Get Customize Appearance
  525. * @apiVersion 1.0.0
  526. * @apiName GetCustomizePage
  527. * @apiGroup Pages
  528. * @apiUse DataHTMLSuccess
  529. * @apiUse UserNotAuthorizedError
  530. */
  531. /**
  532. * @api {post} v1/settings/customize/appearance Edit Customize Appearance
  533. * @apiVersion 1.0.0
  534. * @apiName PostCustomizePage
  535. * @apiGroup Appearance
  536. * @apiParam {Object} data nested data object.
  537. * @apiParam {String} data[action] editCustomizeAppearance.
  538. * @apiParam {String} data[name] Name.
  539. * @apiParam {String} data[value] Value.
  540. * @apiUse DataBooleanSuccess
  541. * @apiUse UserNotAuthorizedError
  542. */
  543. switch ($method) {
  544. case 'GET':
  545. if (qualifyRequest(1)) {
  546. $result['status'] = 'success';
  547. $result['statusText'] = 'success';
  548. $result['data'] = $pageSettingsCustomizeAppearance;
  549. } else {
  550. $result['status'] = 'error';
  551. $result['statusText'] = 'API/Token invalid or not set';
  552. $result['data'] = null;
  553. }
  554. break;
  555. case 'POST':
  556. if (qualifyRequest(1)) {
  557. $result['status'] = 'success';
  558. $result['statusText'] = 'success';
  559. $result['data'] = editAppearance($_POST);
  560. } else {
  561. $result['status'] = 'error';
  562. $result['statusText'] = 'API/Token invalid or not set';
  563. $result['data'] = null;
  564. }
  565. break;
  566. default:
  567. $result['status'] = 'error';
  568. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  569. break;
  570. }
  571. break;
  572. case 'v1_remove_file':
  573. /**
  574. * @api {post} v1/remove/file Remove File
  575. * @apiVersion 1.0.0
  576. * @apiName PostRemoveFile
  577. * @apiGroup Files
  578. * @apiParam {Object} data nested data object.
  579. * @apiParam {String} data[path] File Path.
  580. * @apiParam {String} data[name] File Name.
  581. * @apiUse DataBooleanSuccess
  582. * @apiUse UserNotAuthorizedError
  583. */
  584. switch ($method) {
  585. case 'POST':
  586. if (qualifyRequest(1)) {
  587. $result['status'] = 'success';
  588. $result['statusText'] = 'success';
  589. $result['data'] = removeFile($_POST);
  590. } else {
  591. $result['status'] = 'error';
  592. $result['statusText'] = 'API/Token invalid or not set';
  593. $result['data'] = null;
  594. }
  595. break;
  596. default:
  597. $result['status'] = 'error';
  598. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  599. break;
  600. }
  601. break;
  602. case 'v1_update_config':
  603. /**
  604. * @api {post} v1/update/config Update Config Item
  605. * @apiVersion 1.0.0
  606. * @apiName PostUpdateConfig
  607. * @apiGroup Config
  608. * @apiParam {Object} data nested data object.
  609. * @apiParam {String} data[type] input|select|switch|password.
  610. * @apiParam {String} data[name] Name.
  611. * @apiParam {String} data[value] Value.
  612. * @apiUse DataBooleanSuccess
  613. * @apiUse UserNotAuthorizedError
  614. */
  615. switch ($method) {
  616. case 'POST':
  617. if (qualifyRequest(1)) {
  618. $result['status'] = 'success';
  619. $result['statusText'] = 'success';
  620. $result['data'] = updateConfigItem($_POST);
  621. } else {
  622. $result['status'] = 'error';
  623. $result['statusText'] = 'API/Token invalid or not set';
  624. $result['data'] = null;
  625. }
  626. break;
  627. default:
  628. $result['status'] = 'error';
  629. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  630. break;
  631. }
  632. break;
  633. case 'v1_update_config_multiple':
  634. /**
  635. * @api {post} v1/update/config/multiple Update Multiple Config Items
  636. * @apiVersion 1.0.0
  637. * @apiName PostUpdateConfigMultiple
  638. * @apiGroup Config
  639. * @apiPermission admin
  640. * @apiParam {Object} data[payload] nested payload object.
  641. * @apiParam {String} data.:keyName Value of Name defined from key.
  642. * @apiParamExample {json} Request-Example:
  643. * {
  644. * "data": {
  645. * "payload": {
  646. * "title": "Organizr V2",
  647. * "logo": "plugins/images/organizr/logo-wide.png"
  648. * }
  649. * }
  650. * }
  651. * @apiUse DataBooleanSuccess
  652. * @apiUse UserNotAuthorizedError
  653. */
  654. switch ($method) {
  655. case 'POST':
  656. if (qualifyRequest(1)) {
  657. $result['status'] = 'success';
  658. $result['statusText'] = 'success';
  659. $result['data'] = updateConfigMultiple($_POST);
  660. } else {
  661. $result['status'] = 'error';
  662. $result['statusText'] = 'API/Token invalid or not set';
  663. $result['data'] = null;
  664. }
  665. break;
  666. default:
  667. $result['status'] = 'error';
  668. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  669. break;
  670. }
  671. break;
  672. case 'v1_update_config_multiple_form':
  673. /**
  674. * @api {post} v1/update/config/multiple/form Update Multiple Config Items Form
  675. * @apiVersion 1.0.0
  676. * @apiName PostUpdateConfigMultipleForm
  677. * @apiGroup Config
  678. * @apiPermission admin
  679. * @apiParam {Object} data[payload] nested payload object.
  680. * @apiParam {Object} data.:keyName Config ID/Key.
  681. * @apiParam {String} data.:keyName.name Config ID/Key.
  682. * @apiParam {String} data.:keyName.value Config Value.
  683. * @apiParam {String} data.:keyName.type Config Type input|select|switch|password.
  684. * @apiParamExample {json} Request-Example:
  685. * {
  686. * "data": {
  687. * "payload": {
  688. * "title": {
  689. * "name": "title",
  690. * "value": "Organizr V2",
  691. * "type": "input"
  692. * },
  693. * "logo": {
  694. * "name": "logo",
  695. * "value": "plugins/images/organizr/logo-wide.png",
  696. * "type": "input"
  697. * }
  698. * }
  699. * }
  700. * }
  701. * @apiUse DataBooleanSuccess
  702. * @apiUse UserNotAuthorizedError
  703. */
  704. switch ($method) {
  705. case 'POST':
  706. if (qualifyRequest(1)) {
  707. $result['status'] = 'success';
  708. $result['statusText'] = 'success';
  709. $result['data'] = updateConfigMultipleForm($_POST);
  710. } else {
  711. $result['status'] = 'error';
  712. $result['statusText'] = 'API/Token invalid or not set';
  713. $result['data'] = null;
  714. }
  715. break;
  716. default:
  717. $result['status'] = 'error';
  718. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  719. break;
  720. }
  721. break;
  722. case 'v1_homepage_connect':
  723. /**
  724. * @api {post} v1/homepage/connect Homepage Item Connect
  725. * @apiVersion 1.0.0
  726. * @apiName PostHomepageItemConnect
  727. * @apiGroup Homepage
  728. * @apiPermission admin
  729. * @apiParam {Object} data payload object.
  730. * @apiParam {Object} data[action] Homepage Item i.e. getPlexStreams|getPlexRecent.
  731. * @apiParamExample {json} Request-Example:
  732. * {
  733. * "data": {
  734. * "action": "getPlexStreams"
  735. * }
  736. * }
  737. * @apiUse DataJSONSuccess
  738. * @apiUse UserNotAuthorizedError
  739. */
  740. switch ($method) {
  741. case 'POST':
  742. $result['status'] = 'success';
  743. $result['statusText'] = 'success';
  744. $result['data'] = homepageConnect($_POST);
  745. break;
  746. default:
  747. $result['status'] = 'error';
  748. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  749. break;
  750. }
  751. break;
  752. case 'v1_ping_list':
  753. /**
  754. * @api {post} v1/ping/list Homepage Item Connect
  755. * @apiVersion 1.0.0
  756. * @apiName PostPingList
  757. * @apiGroup Ping
  758. * @apiParam {Object} data payload object.
  759. * @apiParam {Object[]} data[pingList] List of ip/hostname and ports [Optional String of hostname:port]
  760. * @apiParamExample {json} Object
  761. * {
  762. * "data": {
  763. * "pingList": ["docker.home.lab:3579", "docker.home.lab:8181"]
  764. * }
  765. * }
  766. * @apiParamExample {json} String
  767. * {
  768. * "data": {
  769. * "pingList": ["docker.home.lab:3579", "docker.home.lab:8181"]
  770. * }
  771. * }
  772. * @apiSuccess {String} data Output ping results and response times.
  773. * @apiSuccessExample Success-Response:
  774. * HTTP/1.1 200 OK
  775. * {
  776. * "status": "success",
  777. * "statusText": "success",
  778. * "data":{
  779. * "docker.home.lab:3579":10.77,
  780. * "docker.home.lab:8181":0.66
  781. * }
  782. * }
  783. * @apiUse UserNotAuthorizedError
  784. */
  785. switch ($method) {
  786. case 'POST':
  787. $result['status'] = 'success';
  788. $result['statusText'] = 'success';
  789. $result['data'] = ping($_POST['data']['pingList']);
  790. break;
  791. default:
  792. $result['status'] = 'error';
  793. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  794. break;
  795. }
  796. break;
  797. case 'v1_test_api_connection':
  798. switch ($method) {
  799. case 'POST':
  800. if (qualifyRequest(1)) {
  801. $result['status'] = 'success';
  802. $result['statusText'] = 'success';
  803. $result['data'] = testAPIConnection($_POST);
  804. } else {
  805. $result['status'] = 'error';
  806. $result['statusText'] = 'API/Token invalid or not set';
  807. $result['data'] = null;
  808. }
  809. break;
  810. default:
  811. $result['status'] = 'error';
  812. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  813. break;
  814. }
  815. break;
  816. case 'v1_settings_tab_editor_tabs':
  817. /**
  818. * @api {get} v1/settings/tab/editor/tabs Get Tab Editor Tabs
  819. * @apiVersion 1.0.0
  820. * @apiName GetTabEditorTabsPage
  821. * @apiGroup Pages
  822. * @apiUse DataHTMLSuccess
  823. * @apiUse UserNotAuthorizedError
  824. */
  825. switch ($method) {
  826. case 'GET':
  827. if (qualifyRequest(1)) {
  828. $result['status'] = 'success';
  829. $result['statusText'] = 'success';
  830. $result['data'] = $pageSettingsTabEditorTabs;
  831. } else {
  832. $result['status'] = 'error';
  833. $result['statusText'] = 'API/Token invalid or not set';
  834. $result['data'] = null;
  835. }
  836. break;
  837. case 'POST':
  838. if (qualifyRequest(1)) {
  839. $result['status'] = 'success';
  840. $result['statusText'] = 'success';
  841. $result['data'] = editTabs($_POST);
  842. } else {
  843. $result['status'] = 'error';
  844. $result['statusText'] = 'API/Token invalid or not set';
  845. $result['data'] = null;
  846. }
  847. break;
  848. default:
  849. $result['status'] = 'error';
  850. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  851. break;
  852. }
  853. break;
  854. case 'v1_settings_tab_editor_categories':
  855. /**
  856. * @api {get} v1/settings/tab/editor/categories Get Tab Editor Categories
  857. * @apiVersion 1.0.0
  858. * @apiName GetTabEditorCategoriesPage
  859. * @apiGroup Pages
  860. * @apiUse DataHTMLSuccess
  861. * @apiUse UserNotAuthorizedError
  862. */
  863. switch ($method) {
  864. case 'GET':
  865. if (qualifyRequest(1)) {
  866. $result['status'] = 'success';
  867. $result['statusText'] = 'success';
  868. $result['data'] = $pageSettingsTabEditorCategories;
  869. } else {
  870. $result['status'] = 'error';
  871. $result['statusText'] = 'API/Token invalid or not set';
  872. $result['data'] = null;
  873. }
  874. break;
  875. case 'POST':
  876. if (qualifyRequest(1)) {
  877. $result['status'] = 'success';
  878. $result['statusText'] = 'success';
  879. $result['data'] = editCategories($_POST);
  880. } else {
  881. $result['status'] = 'error';
  882. $result['statusText'] = 'API/Token invalid or not set';
  883. $result['data'] = null;
  884. }
  885. break;
  886. default:
  887. $result['status'] = 'error';
  888. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  889. break;
  890. }
  891. break;
  892. case 'v1_settings_user_manage_users':
  893. /**
  894. * @api {get} v1/settings/user/manage/users Get Manage Users
  895. * @apiVersion 1.0.0
  896. * @apiName GetManageUsersPage
  897. * @apiGroup Pages
  898. * @apiUse DataHTMLSuccess
  899. * @apiUse UserNotAuthorizedError
  900. */
  901. switch ($method) {
  902. case 'GET':
  903. if (qualifyRequest(1)) {
  904. $result['status'] = 'success';
  905. $result['statusText'] = 'success';
  906. $result['data'] = $pageSettingsUserManageUsers;
  907. } else {
  908. $result['status'] = 'error';
  909. $result['statusText'] = 'API/Token invalid or not set';
  910. $result['data'] = null;
  911. }
  912. break;
  913. case 'POST':
  914. if (qualifyRequest(1)) {
  915. $result['status'] = 'success';
  916. $result['statusText'] = 'success';
  917. $result['data'] = adminEditUser($_POST);
  918. } elseif (qualifyRequest(998)) {
  919. $result['status'] = 'success';
  920. $result['statusText'] = 'success';
  921. $result['data'] = editUser($_POST);
  922. } else {
  923. $result['status'] = 'error';
  924. $result['statusText'] = 'API/Token invalid or not set';
  925. $result['data'] = null;
  926. }
  927. break;
  928. default:
  929. $result['status'] = 'error';
  930. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  931. break;
  932. }
  933. break;
  934. case 'v1_manage_user':
  935. switch ($method) {
  936. case 'POST':
  937. if (qualifyRequest(998)) {
  938. $result['status'] = 'success';
  939. $result['statusText'] = 'success';
  940. $result['data'] = editUser($_POST);
  941. } else {
  942. $result['status'] = 'error';
  943. $result['statusText'] = 'API/Token invalid or not set';
  944. $result['data'] = null;
  945. }
  946. break;
  947. default:
  948. $result['status'] = 'error';
  949. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  950. break;
  951. }
  952. break;
  953. case 'v1_settings_user_manage_groups':
  954. switch ($method) {
  955. case 'GET':
  956. if (qualifyRequest(1)) {
  957. $result['status'] = 'success';
  958. $result['statusText'] = 'success';
  959. $result['data'] = $pageSettingsUserManageGroups;
  960. } else {
  961. $result['status'] = 'error';
  962. $result['statusText'] = 'API/Token invalid or not set';
  963. $result['data'] = null;
  964. }
  965. break;
  966. case 'POST':
  967. if (qualifyRequest(1)) {
  968. $result['status'] = 'success';
  969. $result['statusText'] = 'success';
  970. $result['data'] = adminEditGroup($_POST);
  971. } else {
  972. $result['status'] = 'error';
  973. $result['statusText'] = 'API/Token invalid or not set';
  974. $result['data'] = null;
  975. }
  976. break;
  977. default:
  978. $result['status'] = 'error';
  979. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  980. break;
  981. }
  982. break;
  983. case 'v1_settings_image_manager_view':
  984. switch ($method) {
  985. case 'GET':
  986. if (qualifyRequest(1)) {
  987. $result['status'] = 'success';
  988. $result['statusText'] = 'success';
  989. $result['data'] = $pageSettingsImageManager;
  990. } else {
  991. $result['status'] = 'error';
  992. $result['statusText'] = 'API/Token invalid or not set';
  993. $result['data'] = null;
  994. }
  995. break;
  996. case 'POST':
  997. if (qualifyRequest(1)) {
  998. $result['status'] = 'success';
  999. $result['statusText'] = 'success';
  1000. $result['data'] = editImages();
  1001. } else {
  1002. $result['status'] = 'error';
  1003. $result['statusText'] = 'API/Token invalid or not set';
  1004. $result['data'] = null;
  1005. }
  1006. break;
  1007. default:
  1008. $result['status'] = 'error';
  1009. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1010. break;
  1011. }
  1012. break;
  1013. case 'v1_wizard_page':
  1014. switch ($method) {
  1015. case 'GET':
  1016. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1017. $result['status'] = 'success';
  1018. $result['statusText'] = 'success';
  1019. $result['data'] = $pageWizard;
  1020. } else {
  1021. $result['status'] = 'error';
  1022. $result['statusText'] = 'Wizard has already been run';
  1023. $result['data'] = null;
  1024. }
  1025. break;
  1026. default:
  1027. $result['status'] = 'error';
  1028. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1029. break;
  1030. }
  1031. break;
  1032. case 'v1_dependencies_page':
  1033. switch ($method) {
  1034. case 'GET':
  1035. $result['status'] = 'success';
  1036. $result['statusText'] = 'success';
  1037. $result['data'] = $pageDependencies;
  1038. break;
  1039. default:
  1040. $result['status'] = 'error';
  1041. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1042. break;
  1043. }
  1044. break;
  1045. case 'v1_wizard_config':
  1046. switch ($method) {
  1047. case 'POST':
  1048. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1049. $result['status'] = 'success';
  1050. $result['statusText'] = 'success';
  1051. $result['data'] = wizardConfig($_POST);
  1052. } else {
  1053. $result['status'] = 'error';
  1054. $result['statusText'] = 'Wizard has already been run';
  1055. $result['data'] = null;
  1056. }
  1057. break;
  1058. default:
  1059. $result['status'] = 'error';
  1060. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1061. break;
  1062. }
  1063. break;
  1064. case 'v1_wizard_path':
  1065. switch ($method) {
  1066. case 'POST':
  1067. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1068. $result['status'] = 'success';
  1069. $result['statusText'] = 'success';
  1070. $result['data'] = wizardPath($_POST);
  1071. } else {
  1072. $result['status'] = 'error';
  1073. $result['statusText'] = 'Wizard has already been run';
  1074. $result['data'] = null;
  1075. }
  1076. break;
  1077. default:
  1078. $result['status'] = 'error';
  1079. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1080. break;
  1081. }
  1082. break;
  1083. case 'v1_login':
  1084. switch ($method) {
  1085. case 'POST':
  1086. $result['status'] = 'success';
  1087. $result['statusText'] = 'success';
  1088. $result['data'] = login($_POST);
  1089. break;
  1090. default:
  1091. $result['status'] = 'error';
  1092. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1093. break;
  1094. }
  1095. break;
  1096. case 'v1_login_api':
  1097. switch ($method) {
  1098. case 'POST':
  1099. $result['status'] = 'success';
  1100. $result['statusText'] = 'success';
  1101. $result['data'] = apiLogin();
  1102. break;
  1103. default:
  1104. $result['status'] = 'error';
  1105. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1106. break;
  1107. }
  1108. break;
  1109. case 'v1_register':
  1110. switch ($method) {
  1111. case 'POST':
  1112. $result['status'] = 'success';
  1113. $result['statusText'] = 'success';
  1114. $result['data'] = register($_POST);
  1115. break;
  1116. default:
  1117. $result['status'] = 'error';
  1118. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1119. break;
  1120. }
  1121. break;
  1122. case 'v1_recover':
  1123. switch ($method) {
  1124. case 'POST':
  1125. $result['status'] = 'success';
  1126. $result['statusText'] = 'success';
  1127. $result['data'] = recover($_POST);
  1128. break;
  1129. default:
  1130. $result['status'] = 'error';
  1131. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1132. break;
  1133. }
  1134. break;
  1135. case 'v1_unlock':
  1136. switch ($method) {
  1137. case 'POST':
  1138. $result['status'] = 'success';
  1139. $result['statusText'] = 'success';
  1140. $result['data'] = unlock($_POST);
  1141. break;
  1142. default:
  1143. $result['status'] = 'error';
  1144. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1145. break;
  1146. }
  1147. break;
  1148. case 'v1_lock':
  1149. switch ($method) {
  1150. case 'POST':
  1151. $result['status'] = 'success';
  1152. $result['statusText'] = 'success';
  1153. $result['data'] = lock();
  1154. break;
  1155. default:
  1156. $result['status'] = 'error';
  1157. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1158. break;
  1159. }
  1160. break;
  1161. case 'v1_test_iframe':
  1162. switch ($method) {
  1163. case 'POST':
  1164. $result['status'] = 'success';
  1165. $result['statusText'] = 'success';
  1166. $result['data'] = frameTest($_POST['data']['url']);
  1167. break;
  1168. default:
  1169. $result['status'] = 'error';
  1170. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1171. break;
  1172. }
  1173. break;
  1174. case 'v1_upgrade':
  1175. case 'v1_update':
  1176. case 'v1_force':
  1177. switch ($method) {
  1178. case 'POST':
  1179. if (qualifyRequest(1)) {
  1180. $result['status'] = 'success';
  1181. $result['statusText'] = 'success';
  1182. $result['data'] = upgradeInstall($_POST['data']['branch'], $_POST['data']['stage']);
  1183. } else {
  1184. $result['status'] = 'error';
  1185. $result['statusText'] = 'API/Token invalid or not set';
  1186. $result['data'] = null;
  1187. }
  1188. break;
  1189. default:
  1190. $result['status'] = 'error';
  1191. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1192. break;
  1193. }
  1194. break;
  1195. case 'v1_login_page':
  1196. switch ($method) {
  1197. case 'GET':
  1198. $result['status'] = 'success';
  1199. $result['statusText'] = 'success';
  1200. $result['data'] = $pageLogin;
  1201. break;
  1202. default:
  1203. $result['status'] = 'error';
  1204. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1205. break;
  1206. }
  1207. break;
  1208. case 'v1_lockscreen':
  1209. switch ($method) {
  1210. case 'GET':
  1211. $result['status'] = 'success';
  1212. $result['statusText'] = 'success';
  1213. $result['data'] = $pageLockScreen;
  1214. break;
  1215. default:
  1216. $result['status'] = 'error';
  1217. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1218. break;
  1219. }
  1220. break;
  1221. case 'v1_login_log':
  1222. switch ($method) {
  1223. case 'GET':
  1224. if (qualifyRequest(1)) {
  1225. $result['status'] = 'success';
  1226. $result['statusText'] = 'success';
  1227. $result['data'] = getLog('loginLog');
  1228. } else {
  1229. $result['status'] = 'error';
  1230. $result['statusText'] = 'API/Token invalid or not set';
  1231. $result['data'] = null;
  1232. }
  1233. break;
  1234. default:
  1235. $result['status'] = 'error';
  1236. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1237. break;
  1238. }
  1239. break;
  1240. case 'v1_organizr_log':
  1241. switch ($method) {
  1242. case 'GET':
  1243. if (qualifyRequest(1)) {
  1244. $result['status'] = 'success';
  1245. $result['statusText'] = 'success';
  1246. $result['data'] = getLog('org');
  1247. } else {
  1248. $result['status'] = 'error';
  1249. $result['statusText'] = 'API/Token invalid or not set';
  1250. $result['data'] = null;
  1251. }
  1252. break;
  1253. default:
  1254. $result['status'] = 'error';
  1255. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1256. break;
  1257. }
  1258. break;
  1259. case 'v1_user_list':
  1260. switch ($method) {
  1261. case 'GET':
  1262. if (qualifyRequest(1)) {
  1263. $result['status'] = 'success';
  1264. $result['statusText'] = 'success';
  1265. $result['data'] = allUsers();
  1266. } else {
  1267. $result['status'] = 'error';
  1268. $result['statusText'] = 'API/Token invalid or not set';
  1269. $result['data'] = null;
  1270. }
  1271. break;
  1272. default:
  1273. $result['status'] = 'error';
  1274. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1275. break;
  1276. }
  1277. break;
  1278. case 'v1_tab_list':
  1279. switch ($method) {
  1280. case 'GET':
  1281. if (qualifyRequest(1)) {
  1282. $result['status'] = 'success';
  1283. $result['statusText'] = 'success';
  1284. $result['data'] = allTabs();
  1285. } else {
  1286. $result['status'] = 'error';
  1287. $result['statusText'] = 'API/Token invalid or not set';
  1288. $result['data'] = null;
  1289. }
  1290. break;
  1291. default:
  1292. $result['status'] = 'error';
  1293. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1294. break;
  1295. }
  1296. break;
  1297. case 'v1_image_list':
  1298. switch ($method) {
  1299. case 'GET':
  1300. if (qualifyRequest(1)) {
  1301. $result['status'] = 'success';
  1302. $result['statusText'] = 'success';
  1303. $result['data'] = getImages();
  1304. } else {
  1305. $result['status'] = 'error';
  1306. $result['statusText'] = 'API/Token invalid or not set';
  1307. $result['data'] = null;
  1308. }
  1309. break;
  1310. default:
  1311. $result['status'] = 'error';
  1312. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1313. break;
  1314. }
  1315. break;
  1316. case 'v1_customize_appearance':
  1317. switch ($method) {
  1318. case 'GET':
  1319. if (qualifyRequest(1)) {
  1320. $result['status'] = 'success';
  1321. $result['statusText'] = 'success';
  1322. $result['data'] = getCustomizeAppearance();
  1323. } else {
  1324. $result['status'] = 'error';
  1325. $result['statusText'] = 'API/Token invalid or not set';
  1326. $result['data'] = null;
  1327. }
  1328. break;
  1329. default:
  1330. $result['status'] = 'error';
  1331. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1332. break;
  1333. }
  1334. break;
  1335. case 'v1_sso':
  1336. switch ($method) {
  1337. case 'GET':
  1338. if (qualifyRequest(1)) {
  1339. $result['status'] = 'success';
  1340. $result['statusText'] = 'success';
  1341. $result['data'] = getSSO();
  1342. } else {
  1343. $result['status'] = 'error';
  1344. $result['statusText'] = 'API/Token invalid or not set';
  1345. $result['data'] = null;
  1346. }
  1347. break;
  1348. default:
  1349. $result['status'] = 'error';
  1350. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1351. break;
  1352. }
  1353. break;
  1354. case 'v1_settings_main':
  1355. switch ($method) {
  1356. case 'GET':
  1357. if (qualifyRequest(1)) {
  1358. $result['status'] = 'success';
  1359. $result['statusText'] = 'success';
  1360. $result['data'] = getSettingsMain();
  1361. } else {
  1362. $result['status'] = 'error';
  1363. $result['statusText'] = 'API/Token invalid or not set';
  1364. $result['data'] = null;
  1365. }
  1366. break;
  1367. default:
  1368. $result['status'] = 'error';
  1369. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1370. break;
  1371. }
  1372. break;
  1373. case 'v1_plugin_install':
  1374. switch ($method) {
  1375. case 'POST':
  1376. if (qualifyRequest(1)) {
  1377. $result['status'] = 'success';
  1378. $result['statusText'] = 'success';
  1379. $result['data'] = installPlugin($_POST);
  1380. } else {
  1381. $result['status'] = 'error';
  1382. $result['statusText'] = 'API/Token invalid or not set';
  1383. $result['data'] = null;
  1384. }
  1385. break;
  1386. default:
  1387. $result['status'] = 'error';
  1388. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1389. break;
  1390. }
  1391. break;
  1392. case 'v1_plugin_remove':
  1393. switch ($method) {
  1394. case 'POST':
  1395. if (qualifyRequest(1)) {
  1396. $result['status'] = 'success';
  1397. $result['statusText'] = 'success';
  1398. $result['data'] = removePlugin($_POST);
  1399. } else {
  1400. $result['status'] = 'error';
  1401. $result['statusText'] = 'API/Token invalid or not set';
  1402. $result['data'] = null;
  1403. }
  1404. break;
  1405. default:
  1406. $result['status'] = 'error';
  1407. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1408. break;
  1409. }
  1410. break;
  1411. case 'v1_theme_install':
  1412. switch ($method) {
  1413. case 'POST':
  1414. if (qualifyRequest(1)) {
  1415. $result['status'] = 'success';
  1416. $result['statusText'] = 'success';
  1417. $result['data'] = installTheme($_POST);
  1418. } else {
  1419. $result['status'] = 'error';
  1420. $result['statusText'] = 'API/Token invalid or not set';
  1421. $result['data'] = null;
  1422. }
  1423. break;
  1424. default:
  1425. $result['status'] = 'error';
  1426. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1427. break;
  1428. }
  1429. break;
  1430. case 'v1_theme_remove':
  1431. switch ($method) {
  1432. case 'POST':
  1433. if (qualifyRequest(1)) {
  1434. $result['status'] = 'success';
  1435. $result['statusText'] = 'success';
  1436. $result['data'] = removeTheme($_POST);
  1437. } else {
  1438. $result['status'] = 'error';
  1439. $result['statusText'] = 'API/Token invalid or not set';
  1440. $result['data'] = null;
  1441. }
  1442. break;
  1443. default:
  1444. $result['status'] = 'error';
  1445. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1446. break;
  1447. }
  1448. break;
  1449. case 'v1_user_edit':
  1450. switch ($method) {
  1451. case 'POST':
  1452. if (qualifyRequest(1)) {
  1453. $result['status'] = 'success';
  1454. $result['statusText'] = 'success';
  1455. $result['data'] = adminEditUser($_POST);
  1456. } elseif (qualifyRequest(998)) {
  1457. $result['status'] = 'success';
  1458. $result['statusText'] = 'success';
  1459. $result['data'] = editUser($_POST);
  1460. } else {
  1461. $result['status'] = 'error';
  1462. $result['statusText'] = 'API/Token invalid or not set';
  1463. $result['data'] = null;
  1464. }
  1465. break;
  1466. default:
  1467. $result['status'] = 'error';
  1468. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1469. break;
  1470. }
  1471. break;
  1472. case 'v1_2fa_create':
  1473. switch ($method) {
  1474. case 'POST':
  1475. if (qualifyRequest(998)) {
  1476. $result['status'] = 'success';
  1477. $result['statusText'] = 'success';
  1478. $result['data'] = create2FA($_POST['data']['type']);
  1479. } else {
  1480. $result['status'] = 'error';
  1481. $result['statusText'] = 'API/Token invalid or not set';
  1482. $result['data'] = null;
  1483. }
  1484. break;
  1485. default:
  1486. $result['status'] = 'error';
  1487. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1488. break;
  1489. }
  1490. break;
  1491. case 'v1_2fa_save':
  1492. switch ($method) {
  1493. case 'POST':
  1494. if (qualifyRequest(998)) {
  1495. $result['status'] = 'success';
  1496. $result['statusText'] = 'success';
  1497. $result['data'] = save2FA($_POST['data']['secret'], $_POST['data']['type']);
  1498. } else {
  1499. $result['status'] = 'error';
  1500. $result['statusText'] = 'API/Token invalid or not set';
  1501. $result['data'] = null;
  1502. }
  1503. break;
  1504. default:
  1505. $result['status'] = 'error';
  1506. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1507. break;
  1508. }
  1509. break;
  1510. case 'v1_2fa_verify':
  1511. switch ($method) {
  1512. case 'POST':
  1513. if (qualifyRequest(998)) {
  1514. $result['status'] = 'success';
  1515. $result['statusText'] = 'success';
  1516. $result['data'] = verify2FA($_POST['data']['secret'], $_POST['data']['code'], $_POST['data']['type']);
  1517. } else {
  1518. $result['status'] = 'error';
  1519. $result['statusText'] = 'API/Token invalid or not set';
  1520. $result['data'] = null;
  1521. }
  1522. break;
  1523. default:
  1524. $result['status'] = 'error';
  1525. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1526. break;
  1527. }
  1528. break;
  1529. case 'v1_2fa_remove':
  1530. switch ($method) {
  1531. case 'GET':
  1532. if (qualifyRequest(998)) {
  1533. $result['status'] = 'success';
  1534. $result['statusText'] = 'success';
  1535. $result['data'] = remove2FA();
  1536. } else {
  1537. $result['status'] = 'error';
  1538. $result['statusText'] = 'API/Token invalid or not set';
  1539. $result['data'] = null;
  1540. }
  1541. break;
  1542. default:
  1543. $result['status'] = 'error';
  1544. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1545. break;
  1546. }
  1547. break;
  1548. case 'v1_logout':
  1549. switch ($method) {
  1550. case 'GET':
  1551. $result['status'] = 'success';
  1552. $result['statusText'] = 'success';
  1553. $result['data'] = logout();
  1554. break;
  1555. default:
  1556. $result['status'] = 'error';
  1557. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1558. break;
  1559. }
  1560. break;
  1561. case 'v1_launch_organizr':
  1562. switch ($method) {
  1563. case 'GET':
  1564. $pluginSearch = '-enabled';
  1565. $pluginInclude = '-include';
  1566. $status = array();
  1567. $result['status'] = 'success';
  1568. $result['statusText'] = 'success';
  1569. $status['status'] = organizrStatus();
  1570. $result['appearance'] = loadAppearance();
  1571. $status['user'] = $GLOBALS['organizrUser'];
  1572. $status['categories'] = loadTabs('categories');
  1573. $status['tabs'] = loadTabs('tabs');
  1574. $status['plugins'] = array_filter($GLOBALS, function ($k) use ($pluginSearch) {
  1575. return stripos($k, $pluginSearch) !== false;
  1576. }, ARRAY_FILTER_USE_KEY);
  1577. $status['plugins']['includes'] = array_filter($GLOBALS, function ($k) use ($pluginInclude) {
  1578. return stripos($k, $pluginInclude) !== false;
  1579. }, ARRAY_FILTER_USE_KEY);
  1580. $result['data'] = $status;
  1581. $result['branch'] = $GLOBALS['branch'];
  1582. $result['theme'] = $GLOBALS['theme'];
  1583. $result['style'] = $GLOBALS['style'];
  1584. $result['version'] = $GLOBALS['installedVersion'];
  1585. $result['sso'] = array(
  1586. 'myPlexAccessToken' => isset($_COOKIE['mpt']) ? $_COOKIE['mpt'] : false,
  1587. 'id_token' => isset($_COOKIE['Auth']) ? $_COOKIE['Auth'] : false
  1588. );
  1589. $result['settings'] = organizrSpecialSettings();
  1590. break;
  1591. default:
  1592. $result['status'] = 'error';
  1593. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1594. break;
  1595. }
  1596. break;
  1597. case 'v1_auth':
  1598. switch ($method) {
  1599. case 'GET':
  1600. auth();
  1601. break;
  1602. default:
  1603. //exit(http_response_code(401));
  1604. auth();
  1605. break;
  1606. }
  1607. break;
  1608. case 'v1_plugin':
  1609. switch ($method) {
  1610. case 'POST':
  1611. case 'GET':
  1612. // Include all plugin api Calls
  1613. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'plugins' . DIRECTORY_SEPARATOR . 'api' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  1614. require_once $filename;
  1615. }
  1616. break;
  1617. default:
  1618. $result['status'] = 'error';
  1619. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1620. break;
  1621. }
  1622. break;
  1623. case 'v1_image':
  1624. switch ($method) {
  1625. case 'GET':
  1626. getImage();
  1627. break;
  1628. default:
  1629. $result['status'] = 'error';
  1630. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1631. break;
  1632. }
  1633. break;
  1634. case 'v1_downloader':
  1635. switch ($method) {
  1636. case 'POST':
  1637. $result['status'] = 'success';
  1638. $result['statusText'] = 'success';
  1639. $result['data'] = downloader($_POST);
  1640. break;
  1641. default:
  1642. $result['status'] = 'error';
  1643. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1644. break;
  1645. }
  1646. break;
  1647. case 'v1_import_users':
  1648. switch ($method) {
  1649. case 'POST':
  1650. if (qualifyRequest(1)) {
  1651. $result['status'] = 'success';
  1652. $result['statusText'] = 'success';
  1653. $result['data'] = importUsersType($_POST);
  1654. } else {
  1655. $result['status'] = 'error';
  1656. $result['statusText'] = 'API/Token invalid or not set';
  1657. $result['data'] = null;
  1658. }
  1659. break;
  1660. default:
  1661. $result['status'] = 'error';
  1662. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1663. break;
  1664. }
  1665. break;
  1666. case 'v1_ombi':
  1667. switch ($method) {
  1668. case 'POST':
  1669. $result['status'] = 'success';
  1670. $result['statusText'] = 'success';
  1671. $result['data'] = ombiAPI($_POST);
  1672. break;
  1673. default:
  1674. $result['status'] = 'error';
  1675. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1676. break;
  1677. }
  1678. break;
  1679. case 'v1_plex_join':
  1680. switch ($method) {
  1681. case 'POST':
  1682. $result['status'] = 'success';
  1683. $result['statusText'] = 'success';
  1684. $result['data'] = plexJoinAPI($_POST);
  1685. break;
  1686. default:
  1687. $result['status'] = 'error';
  1688. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1689. break;
  1690. }
  1691. break;
  1692. case 'v1_emby_join':
  1693. switch ($method) {
  1694. case 'POST':
  1695. $result['status'] = 'success';
  1696. $result['statusText'] = 'success';
  1697. $result['data'] = embyJoinAPI($_POST);
  1698. break;
  1699. default:
  1700. $result['status'] = 'error';
  1701. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1702. break;
  1703. }
  1704. break;
  1705. case 'v1_token_revoke':
  1706. switch ($method) {
  1707. case 'POST':
  1708. $result['status'] = 'success';
  1709. $result['statusText'] = 'success';
  1710. $result['data'] = revokeToken($_POST);
  1711. break;
  1712. default:
  1713. $result['status'] = 'error';
  1714. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1715. break;
  1716. }
  1717. break;
  1718. case 'v1_token_validate':
  1719. switch ($method) {
  1720. case 'GET':
  1721. $token = $_GET['token'] ?? false;
  1722. break;
  1723. case 'POST':
  1724. $token = $_POST['token'] ?? false;
  1725. break;
  1726. default:
  1727. $result['status'] = 'error';
  1728. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1729. break;
  1730. }
  1731. $token = validateToken($token);
  1732. if ($token) {
  1733. $result['status'] = 'success';
  1734. $result['statusText'] = 'success';
  1735. $result['data'] = $token;
  1736. } else {
  1737. $result['status'] = 'error';
  1738. $result['statusText'] = 'Token not validated or empty';
  1739. }
  1740. break;
  1741. case 'v1_update_db_manual':
  1742. switch ($method) {
  1743. case 'GET':
  1744. if (qualifyRequest(1)) {
  1745. $result['status'] = 'success';
  1746. $result['statusText'] = 'success';
  1747. $result['data'] = updateDB($GLOBALS['installedVersion']);
  1748. } else {
  1749. $result['status'] = 'error';
  1750. $result['statusText'] = 'API/Token invalid or not set';
  1751. $result['data'] = null;
  1752. }
  1753. break;
  1754. default:
  1755. $result['status'] = 'error';
  1756. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1757. break;
  1758. }
  1759. break;
  1760. case 'v1_version':
  1761. switch ($method) {
  1762. case 'GET':
  1763. $result['status'] = 'success';
  1764. $result['statusText'] = 'success';
  1765. $result['data'] = $GLOBALS['installedVersion'];
  1766. break;
  1767. default:
  1768. $result['status'] = 'error';
  1769. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1770. break;
  1771. }
  1772. break;
  1773. case 'v1_ping':
  1774. switch ($method) {
  1775. case 'GET':
  1776. $result['status'] = 'success';
  1777. $result['statusText'] = 'success';
  1778. $result['data'] = 'pong';
  1779. break;
  1780. default:
  1781. $result['status'] = 'error';
  1782. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1783. break;
  1784. }
  1785. break;
  1786. case 'v1_docker_update':
  1787. switch ($method) {
  1788. case 'GET':
  1789. if (qualifyRequest(1)) {
  1790. $result['status'] = 'success';
  1791. $result['statusText'] = 'success';
  1792. $result['data'] = dockerUpdate();
  1793. } else {
  1794. $result['status'] = 'error';
  1795. $result['statusText'] = 'API/Token invalid or not set';
  1796. $result['data'] = null;
  1797. }
  1798. break;
  1799. default:
  1800. $result['status'] = 'error';
  1801. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1802. break;
  1803. }
  1804. break;
  1805. case 'v1_windows_update':
  1806. switch ($method) {
  1807. case 'GET':
  1808. if (qualifyRequest(1)) {
  1809. $result['status'] = 'success';
  1810. $result['statusText'] = 'success';
  1811. $result['data'] = windowsUpdate();
  1812. } else {
  1813. $result['status'] = 'error';
  1814. $result['statusText'] = 'API/Token invalid or not set';
  1815. $result['data'] = null;
  1816. }
  1817. break;
  1818. default:
  1819. $result['status'] = 'error';
  1820. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1821. break;
  1822. }
  1823. break;
  1824. case 'v1_custom_page':
  1825. switch ($method) {
  1826. case 'GET':
  1827. $customPage = 'customPage' . ucwords($endpoint);
  1828. $result['status'] = 'success';
  1829. $result['statusText'] = 'success';
  1830. $result['data'] = $$customPage;
  1831. break;
  1832. default:
  1833. $result['status'] = 'error';
  1834. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1835. break;
  1836. }
  1837. break;
  1838. case 'v1_youtube_search':
  1839. switch ($method) {
  1840. case 'GET':
  1841. $query = isset($_GET['q']) ? $_GET['q'] : false;
  1842. $result['status'] = isset($_GET['q']) ? 'success' : 'error';
  1843. $result['statusText'] = isset($_GET['q']) ? 'success' : 'missing query';
  1844. $result['data'] = youtubeSearch($query);
  1845. break;
  1846. default:
  1847. $result['status'] = 'error';
  1848. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1849. break;
  1850. }
  1851. break;
  1852. case 'v1_scrape':
  1853. switch ($method) {
  1854. case 'POST':
  1855. if (qualifyRequest(998)) {
  1856. $result['status'] = 'success';
  1857. $result['statusText'] = 'success';
  1858. $result['data'] = scrapePage($_POST);
  1859. } else {
  1860. $result['status'] = 'error';
  1861. $result['statusText'] = 'API/Token invalid or not set';
  1862. $result['data'] = null;
  1863. }
  1864. break;
  1865. default:
  1866. $result['status'] = 'error';
  1867. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1868. break;
  1869. }
  1870. break;
  1871. case 'v1_coordinates_search':
  1872. switch ($method) {
  1873. case 'POST':
  1874. if (qualifyRequest(1)) {
  1875. $result['status'] = 'success';
  1876. $result['statusText'] = 'success';
  1877. $result['data'] = searchCityForCoordinates($_POST);
  1878. } else {
  1879. $result['status'] = 'error';
  1880. $result['statusText'] = 'API/Token invalid or not set';
  1881. $result['data'] = null;
  1882. }
  1883. break;
  1884. default:
  1885. $result['status'] = 'error';
  1886. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1887. break;
  1888. }
  1889. break;
  1890. default:
  1891. //No Function Available
  1892. $result['status'] = 'error';
  1893. $result['statusText'] = 'function requested is not defined';
  1894. break;
  1895. }
  1896. //Set Default Result
  1897. if (!$result) {
  1898. $result['status'] = "error";
  1899. $result['error'] = "An error has occurred";
  1900. }
  1901. $result['generationDate'] = $GLOBALS['currentTime'];
  1902. $result['generationTime'] = formatSeconds(timeExecution());
  1903. //Set HTTP Code
  1904. if ($result['statusText'] == "API/Token invalid or not set") {
  1905. http_response_code(401);
  1906. } else {
  1907. http_response_code(200);
  1908. }
  1909. //return JSON array
  1910. if ($pretty) {
  1911. echo '<pre>' . safe_json_encode($result, JSON_PRETTY_PRINT) . '</pre>';
  1912. } else {
  1913. exit(safe_json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));
  1914. }