api-functions.php 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947
  1. <?php
  2. function login($array){
  3. // Grab username and Password from login form
  4. foreach ($array['data'] as $items) {
  5. foreach ($items as $key => $value) {
  6. if($key == 'name'){
  7. $newKey = $value;
  8. }
  9. if($key == 'value'){
  10. $newValue = $value;
  11. }
  12. if(isset($newKey) && isset($newValue)){
  13. $$newKey = $newValue;
  14. }
  15. }
  16. }
  17. $username = strtolower($username);
  18. $days = (isset($remember)) ? 7 : 1;
  19. try {
  20. $database = new Dibi\Connection([
  21. 'driver' => 'sqlite3',
  22. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  23. ]);
  24. $authSuccess = false;
  25. $function = 'plugin_auth_'.$GLOBALS['authBackend'];
  26. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$username);
  27. switch ($GLOBALS['authType']) {
  28. case 'external':
  29. if (function_exists($function)) {
  30. $authSuccess = $function($username, $password);
  31. }
  32. break;
  33. case 'both':
  34. if (function_exists($function)) {
  35. $authSuccess = $function($username, $password);
  36. }
  37. default: // Internal
  38. if (!$authSuccess) {
  39. // perform the internal authentication step
  40. if(password_verify($password, $result['password'])){
  41. $authSuccess = true;
  42. }
  43. }
  44. }
  45. if ($authSuccess) {
  46. // Make sure user exists in database
  47. $userExists = false;
  48. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  49. if($result['username']){
  50. $userExists = true;
  51. $username = $result['username'];
  52. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  53. }
  54. if ($userExists) {
  55. //does org password need to be updated
  56. if(!$passwordMatches){
  57. $database->query('
  58. UPDATE users SET', [
  59. 'password' => password_hash($password, PASSWORD_BCRYPT)
  60. ], '
  61. WHERE id=?', $result['id']);
  62. writeLog('success', 'Login Function - User Password updated from backend', $username);
  63. }
  64. // authentication passed - 1) mark active and update token
  65. if(createToken($result['username'],$result['email'],$result['image'],$result['group'],$result['group_id'],$GLOBALS['organizrHash'],$days)){
  66. writeLoginLog($username, 'success');
  67. writeLog('success', 'Login Function - A User has logged in', $username);
  68. ssoCheck($username, $password, $token); //need to work on this
  69. return true;
  70. }else{
  71. return 'error';
  72. }
  73. } else {
  74. // Create User
  75. ssoCheck($username, $password, $token);
  76. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username),$password,'',(is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  77. }
  78. } else {
  79. // authentication failed
  80. writeLoginLog($username, 'error');
  81. writeLog('error', 'Login Function - Wrong Password', $username);
  82. return 'mismatch';
  83. }
  84. } catch (Dibi\Exception $e) {
  85. return 'error';
  86. }
  87. }
  88. function createDB($path,$filename) {
  89. try {
  90. $createDB = new Dibi\Connection([
  91. 'driver' => 'sqlite3',
  92. 'database' => $path.$filename,
  93. ]);
  94. // Create Users
  95. $users = $createDB->query('CREATE TABLE `users` (
  96. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  97. `username` TEXT UNIQUE,
  98. `password` TEXT,
  99. `email` TEXT,
  100. `plex_token` TEXT,
  101. `group` TEXT,
  102. `group_id` INTEGER,
  103. `locked` INTEGER,
  104. `image` TEXT,
  105. `register_date` DATE,
  106. `auth_service` TEXT DEFAULT \'internal\'
  107. );');
  108. // Create Tokens
  109. $jwt = $createDB->query('CREATE TABLE `tokens` (
  110. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  111. `token` TEXT UNIQUE,
  112. `user_id` INTEGER,
  113. `created` DATE,
  114. `expires` DATE
  115. );');
  116. $groups = $createDB->query('CREATE TABLE `groups` (
  117. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  118. `group` TEXT UNIQUE,
  119. `group_id` INTEGER,
  120. `image` TEXT,
  121. `default` INTEGER
  122. );');
  123. $categories = $createDB->query('CREATE TABLE `categories` (
  124. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  125. `order` INTEGER,
  126. `category` TEXT UNIQUE,
  127. `category_id` INTEGER,
  128. `image` TEXT,
  129. `default` INTEGER
  130. );');
  131. // Create Tabs
  132. $tabs = $createDB->query('CREATE TABLE `tabs` (
  133. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  134. `order` INTEGER,
  135. `category_id` INTEGER,
  136. `name` TEXT,
  137. `url` TEXT,
  138. `url_local` TEXT,
  139. `default` INTEGER,
  140. `enabled` INTEGER,
  141. `group_id` INTEGER,
  142. `image` TEXT,
  143. `type` INTEGER,
  144. `splash` INTEGER,
  145. `ping` INTEGER,
  146. `ping_url` TEXT
  147. );');
  148. // Create Options
  149. $options = $createDB->query('CREATE TABLE `options` (
  150. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  151. `users_id` INTEGER UNIQUE,
  152. `title` TEXT UNIQUE,
  153. `topbar` TEXT,
  154. `bottombar` TEXT,
  155. `sidebar` TEXT,
  156. `hoverbg` TEXT,
  157. `topbartext` TEXT,
  158. `activetabBG` TEXT,
  159. `activetabicon` TEXT,
  160. `activetabtext` TEXT,
  161. `inactiveicon` TEXT,
  162. `inactivetext` TEXT,
  163. `loading` TEXT,
  164. `hovertext` TEXT
  165. );');
  166. // Create Invites
  167. $invites = $createDB->query('CREATE TABLE `invites` (
  168. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  169. `code` TEXT UNIQUE,
  170. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  171. `email` TEXT,
  172. `username` TEXT,
  173. `dateused` TIMESTAMP,
  174. `usedby` TEXT,
  175. `ip` TEXT,
  176. `valid` TEXT,
  177. `type` TEXT
  178. );');
  179. return true;
  180. } catch (Dibi\Exception $e) {
  181. return false;
  182. }
  183. }
  184. // Upgrade Database
  185. function updateDB($path,$filename,$oldVerNum = false) {
  186. try {
  187. $connect = new Dibi\Connection([
  188. 'driver' => 'sqlite3',
  189. 'database' => $path.$filename,
  190. ]);
  191. // Cache current DB
  192. $cache = array();
  193. foreach($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  194. foreach($connect->query('SELECT * FROM '.$table['name'].';') as $key => $row) {
  195. foreach($row as $k => $v) {
  196. if (is_string($k)) {
  197. $cache[$table['name']][$key][$k] = $v;
  198. }
  199. }
  200. }
  201. }
  202. $connect->disconnect();
  203. } catch (Dibi\Exception $e) {
  204. return $e;
  205. }
  206. // Remove Current Database
  207. $pathDigest = pathinfo($path.$filename);
  208. if (file_exists($path.$filename)) {
  209. copy($path.$filename, $pathDigest['dirname'].'/'.$pathDigest['filename'].'['.date('Y-m-d_H-i-s').']'.($oldVerNum?'['.$oldVerNum.']':'').'.bak.db');
  210. unlink($path.$filename);
  211. }
  212. // Create New Database
  213. $success = createDB($path,$filename);
  214. try {
  215. $GLOBALS['connect'] = new Dibi\Connection([
  216. 'driver' => 'sqlite3',
  217. 'database' => $path.$filename,
  218. ]);
  219. // Restore Items
  220. if ($success) {
  221. foreach($cache as $table => $tableData) {
  222. if ($tableData) {
  223. $queryBase = 'INSERT INTO '.$table.' (`'.implode('`,`',array_keys(current($tableData))).'`) values ';
  224. $insertValues = array();
  225. reset($tableData);
  226. foreach($tableData as $key => $value) {
  227. $insertValues[] = '('.implode(',',array_map(function($d) {
  228. return (isset($d)?str_replace('\/', '/',json_encode($d)):'null');
  229. }, $value)).')';
  230. }
  231. $GLOBALS['connect']->query($queryBase.implode(',',$insertValues).';');
  232. }
  233. }
  234. }
  235. return true;
  236. } catch (Dibi\Exception $e) {
  237. return $e;
  238. }
  239. }
  240. function createFirstAdmin($path,$filename,$username,$password,$email) {
  241. try {
  242. $createDB = new Dibi\Connection([
  243. 'driver' => 'sqlite3',
  244. 'database' => $path.$filename,
  245. ]);
  246. $userInfo = [
  247. 'username' => $username,
  248. 'password' => password_hash($password, PASSWORD_BCRYPT),
  249. 'email' => $email,
  250. 'group' => 'Admin',
  251. 'group_id' => 0,
  252. 'image' => gravatar($email),
  253. 'register_date' => $GLOBALS['currentTime'],
  254. ];
  255. $groupInfo0 = [
  256. 'group' => 'Admin',
  257. 'group_id' => 0,
  258. 'default' => false,
  259. 'image' => 'plugins/images/groups/admin.png',
  260. ];
  261. $groupInfo1 = [
  262. 'group' => 'Co-Admin',
  263. 'group_id' => 1,
  264. 'default' => false,
  265. 'image' => 'plugins/images/groups/coadmin.png',
  266. ];
  267. $groupInfo2 = [
  268. 'group' => 'Super User',
  269. 'group_id' => 2,
  270. 'default' => false,
  271. 'image' => 'plugins/images/groups/superuser.png',
  272. ];
  273. $groupInfo3 = [
  274. 'group' => 'Power User',
  275. 'group_id' => 3,
  276. 'default' => false,
  277. 'image' => 'plugins/images/groups/poweruser.png',
  278. ];
  279. $groupInfo4 = [
  280. 'group' => 'User',
  281. 'group_id' => 4,
  282. 'default' => true,
  283. 'image' => 'plugins/images/groups/user.png',
  284. ];
  285. $groupInfoGuest = [
  286. 'group' => 'Guest',
  287. 'group_id' => 999,
  288. 'default' => false,
  289. 'image' => 'plugins/images/groups/guest.png',
  290. ];
  291. $settingsInfo = [
  292. 'order' => 1,
  293. 'category_id' => 0,
  294. 'name' => 'Settings',
  295. 'url' => 'api/?v1/settings/page',
  296. 'default' => false,
  297. 'enabled' => true,
  298. 'group_id' => 1,
  299. 'image' => 'fontawesome::cog',
  300. 'type' => 0
  301. ];
  302. $homepageInfo = [
  303. 'order' => 2,
  304. 'category_id' => 0,
  305. 'name' => 'Homepage',
  306. 'url' => 'api/?v1/homepage/page',
  307. 'default' => false,
  308. 'enabled' => false,
  309. 'group_id' => 4,
  310. 'image' => 'fontawesome::home',
  311. 'type' => 0
  312. ];
  313. $unsortedInfo = [
  314. 'order' => 1,
  315. 'category' => 'Unsorted',
  316. 'category_id' => 0,
  317. 'image' => 'plugins/images/categories/unsorted.png',
  318. 'default' => true
  319. ];
  320. $createDB->query('INSERT INTO [users]', $userInfo);
  321. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  322. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  323. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  324. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  325. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  326. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  327. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  328. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  329. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  330. return true;
  331. } catch (Dibi\Exception $e) {
  332. writeLog('error', 'Wizard Function - Error ['.$e.']', 'Wizard');
  333. return false;
  334. }
  335. }
  336. function defaultUserGroup(){
  337. try {
  338. $connect = new Dibi\Connection([
  339. 'driver' => 'sqlite3',
  340. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  341. ]);
  342. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  343. return $all;
  344. } catch (Dibi\Exception $e) {
  345. return false;
  346. }
  347. }
  348. function defaulTabCategory(){
  349. try {
  350. $connect = new Dibi\Connection([
  351. 'driver' => 'sqlite3',
  352. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  353. ]);
  354. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  355. return $all;
  356. } catch (Dibi\Exception $e) {
  357. return false;
  358. }
  359. }
  360. function getGuest(){
  361. if(isset($GLOBALS['dbLocation'])){
  362. try {
  363. $connect = new Dibi\Connection([
  364. 'driver' => 'sqlite3',
  365. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  366. ]);
  367. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  368. return $all;
  369. } catch (Dibi\Exception $e) {
  370. return false;
  371. }
  372. }else{
  373. return array(
  374. 'group' => 'Guest',
  375. 'group_id' => 999,
  376. 'image' => 'plugins/images/groups/guest.png'
  377. );
  378. }
  379. }
  380. function adminEditGroup($array){
  381. switch ($array['data']['action']) {
  382. case 'changeDefaultGroup':
  383. try {
  384. $connect = new Dibi\Connection([
  385. 'driver' => 'sqlite3',
  386. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  387. ]);
  388. $connect->query('UPDATE groups SET `default` = 0');
  389. $connect->query('
  390. UPDATE groups SET', [
  391. 'default' => 1
  392. ], '
  393. WHERE id=?', $array['data']['id']);
  394. writeLog('success', 'Group Management Function - Changed Default Group from ['.$array['data']['oldGroupName'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  395. return true;
  396. } catch (Dibi\Exception $e) {
  397. return false;
  398. }
  399. break;
  400. case 'deleteUserGroup':
  401. try {
  402. $connect = new Dibi\Connection([
  403. 'driver' => 'sqlite3',
  404. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  405. ]);
  406. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  407. writeLog('success', 'Group Management Function - Deleted Group ['.$array['data']['groupName'].']', $GLOBALS['organizrUser']['username']);
  408. return true;
  409. } catch (Dibi\Exception $e) {
  410. return false;
  411. }
  412. break;
  413. case 'addUserGroup':
  414. try {
  415. $connect = new Dibi\Connection([
  416. 'driver' => 'sqlite3',
  417. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  418. ]);
  419. $newGroup = [
  420. 'group' => $array['data']['newGroupName'],
  421. 'group_id' => $array['data']['newGroupID'],
  422. 'default' => false,
  423. 'image' => $array['data']['newGroupImage'],
  424. ];
  425. $connect->query('INSERT INTO [groups]', $newGroup);
  426. writeLog('success', 'Group Management Function - Added Group ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  427. return true;
  428. } catch (Dibi\Exception $e) {
  429. return false;
  430. }
  431. break;
  432. case 'editUserGroup':
  433. try {
  434. $connect = new Dibi\Connection([
  435. 'driver' => 'sqlite3',
  436. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  437. ]);
  438. $connect->query('
  439. UPDATE groups SET', [
  440. 'group' => $array['data']['groupName'],
  441. 'image' => $array['data']['groupImage'],
  442. ], '
  443. WHERE id=?', $array['data']['id']);
  444. writeLog('success', 'Group Management Function - Edited Group Info for ['.$array['data']['oldGroupName'].']', $GLOBALS['organizrUser']['username']);
  445. return true;
  446. } catch (Dibi\Exception $e) {
  447. return false;
  448. }
  449. break;
  450. default:
  451. # code...
  452. break;
  453. }
  454. }
  455. function adminEditUser($array){
  456. switch ($array['data']['action']) {
  457. case 'changeGroup':
  458. try {
  459. $connect = new Dibi\Connection([
  460. 'driver' => 'sqlite3',
  461. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  462. ]);
  463. $connect->query('
  464. UPDATE users SET', [
  465. 'group' => $array['data']['newGroupName'],
  466. 'group_id' => $array['data']['newGroupID'],
  467. ], '
  468. WHERE id=?', $array['data']['id']);
  469. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  470. return true;
  471. } catch (Dibi\Exception $e) {
  472. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  473. return false;
  474. }
  475. break;
  476. case 'editUser':
  477. try {
  478. $connect = new Dibi\Connection([
  479. 'driver' => 'sqlite3',
  480. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  481. ]);
  482. if(!usernameTakenExcept($array['data']['username'],$array['data']['email'],$array['data']['id'])){
  483. $connect->query('
  484. UPDATE users SET', [
  485. 'username' => $array['data']['username'],
  486. 'email' => $array['data']['email'],
  487. ], '
  488. WHERE id=?', $array['data']['id']);
  489. if(!empty($array['data']['password'])){
  490. $connect->query('
  491. UPDATE users SET', [
  492. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  493. ], '
  494. WHERE id=?', $array['data']['id']);
  495. }
  496. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s info was changed', $GLOBALS['organizrUser']['username']);
  497. return true;
  498. }else{
  499. return false;
  500. }
  501. } catch (Dibi\Exception $e) {
  502. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  503. return false;
  504. }
  505. break;
  506. case 'addNewUser':
  507. $defaults = defaultUserGroup();
  508. if(createUser($array['data']['username'],$array['data']['password'],$defaults,$array['data']['email'])){
  509. writeLog('success', 'Create User Function - Acount created for ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  510. return true;
  511. }else{
  512. writeLog('error', 'Registration Function - An error occured', $GLOBALS['organizrUser']['username']);
  513. return 'username taken';
  514. }
  515. break;
  516. case 'deleteUser':
  517. try {
  518. $connect = new Dibi\Connection([
  519. 'driver' => 'sqlite3',
  520. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  521. ]);
  522. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  523. writeLog('success', 'User Management Function - Deleted User ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  524. return true;
  525. } catch (Dibi\Exception $e) {
  526. return false;
  527. }
  528. break;
  529. default:
  530. # code...
  531. break;
  532. }
  533. }
  534. function editTabs($array){
  535. switch ($array['data']['action']) {
  536. case 'changeGroup':
  537. try {
  538. $connect = new Dibi\Connection([
  539. 'driver' => 'sqlite3',
  540. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  541. ]);
  542. $connect->query('
  543. UPDATE tabs SET', [
  544. 'group_id' => $array['data']['newGroupID'],
  545. ], '
  546. WHERE id=?', $array['data']['id']);
  547. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s group was changed to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  548. return true;
  549. } catch (Dibi\Exception $e) {
  550. return false;
  551. }
  552. break;
  553. case 'changeCategory':
  554. try {
  555. $connect = new Dibi\Connection([
  556. 'driver' => 'sqlite3',
  557. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  558. ]);
  559. $connect->query('
  560. UPDATE tabs SET', [
  561. 'category_id' => $array['data']['newCategoryID'],
  562. ], '
  563. WHERE id=?', $array['data']['id']);
  564. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s category was changed to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  565. return true;
  566. } catch (Dibi\Exception $e) {
  567. return false;
  568. }
  569. break;
  570. case 'changeType':
  571. try {
  572. $connect = new Dibi\Connection([
  573. 'driver' => 'sqlite3',
  574. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  575. ]);
  576. $connect->query('
  577. UPDATE tabs SET', [
  578. 'type' => $array['data']['newTypeID'],
  579. ], '
  580. WHERE id=?', $array['data']['id']);
  581. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s type was changed to ['.$array['data']['newTypeName'].']', $GLOBALS['organizrUser']['username']);
  582. return true;
  583. } catch (Dibi\Exception $e) {
  584. return false;
  585. }
  586. break;
  587. case 'changeEnabled':
  588. try {
  589. $connect = new Dibi\Connection([
  590. 'driver' => 'sqlite3',
  591. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  592. ]);
  593. $connect->query('
  594. UPDATE tabs SET', [
  595. 'enabled' => $array['data']['tabEnabled'],
  596. ], '
  597. WHERE id=?', $array['data']['id']);
  598. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s enable status was changed to ['.$array['data']['tabEnabledWord'].']', $GLOBALS['organizrUser']['username']);
  599. return true;
  600. } catch (Dibi\Exception $e) {
  601. return false;
  602. }
  603. break;
  604. case 'changeSplash':
  605. try {
  606. $connect = new Dibi\Connection([
  607. 'driver' => 'sqlite3',
  608. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  609. ]);
  610. $connect->query('
  611. UPDATE tabs SET', [
  612. 'splash' => $array['data']['tabSplash'],
  613. ], '
  614. WHERE id=?', $array['data']['id']);
  615. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s splash status was changed to ['.$array['data']['tabSplashWord'].']', $GLOBALS['organizrUser']['username']);
  616. return true;
  617. } catch (Dibi\Exception $e) {
  618. return false;
  619. }
  620. break;
  621. case 'changeDefault':
  622. try {
  623. $connect = new Dibi\Connection([
  624. 'driver' => 'sqlite3',
  625. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  626. ]);
  627. $connect->query('UPDATE tabs SET `default` = 0');
  628. $connect->query('
  629. UPDATE tabs SET', [
  630. 'default' => 1
  631. ], '
  632. WHERE id=?', $array['data']['id']);
  633. writeLog('success', 'Tab Editor Function - Changed Default Tab to ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  634. return true;
  635. } catch (Dibi\Exception $e) {
  636. return false;
  637. }
  638. break;
  639. case 'deleteTab':
  640. try {
  641. $connect = new Dibi\Connection([
  642. 'driver' => 'sqlite3',
  643. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  644. ]);
  645. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  646. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  647. return true;
  648. } catch (Dibi\Exception $e) {
  649. return false;
  650. }
  651. break;
  652. case 'editTab':
  653. try {
  654. $connect = new Dibi\Connection([
  655. 'driver' => 'sqlite3',
  656. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  657. ]);
  658. $connect->query('
  659. UPDATE tabs SET', [
  660. 'name' => $array['data']['tabName'],
  661. 'url' => $array['data']['tabURL'],
  662. 'image' => $array['data']['tabImage'],
  663. ], '
  664. WHERE id=?', $array['data']['id']);
  665. writeLog('success', 'Tab Editor Function - Edited Tab Info for ['.$array['data']['tabName'].']', $GLOBALS['organizrUser']['username']);
  666. return true;
  667. } catch (Dibi\Exception $e) {
  668. return false;
  669. }
  670. case 'changeOrder':
  671. try {
  672. $connect = new Dibi\Connection([
  673. 'driver' => 'sqlite3',
  674. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  675. ]);
  676. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  677. if($value['order'] != $value['originalOrder']){
  678. $connect->query('
  679. UPDATE tabs SET', [
  680. 'order' => $value['order'],
  681. ], '
  682. WHERE id=?', $value['id']);
  683. writeLog('success', 'Tab Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  684. }
  685. }
  686. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  687. return true;
  688. } catch (Dibi\Exception $e) {
  689. return false;
  690. }
  691. break;
  692. case 'addNewTab':
  693. try {
  694. $default = defaulTabCategory()['category_id'];
  695. $connect = new Dibi\Connection([
  696. 'driver' => 'sqlite3',
  697. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  698. ]);
  699. $newTab = [
  700. 'order' => $array['data']['tabOrder'],
  701. 'category_id' => $default,
  702. 'name' => $array['data']['tabName'],
  703. 'url' => $array['data']['tabURL'],
  704. 'default' => $array['data']['tabDefault'],
  705. 'enabled' => 1,
  706. 'group_id' => $array['data']['tabGroupID'],
  707. 'image' => $array['data']['tabImage'],
  708. 'type' => $array['data']['tabType']
  709. ];
  710. $connect->query('INSERT INTO [tabs]', $newTab);
  711. writeLog('success', 'Tab Editor Function - Created Tab for: '.$array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  712. return true;
  713. } catch (Dibi\Exception $e) {
  714. return false;
  715. }
  716. break;
  717. case 'deleteTab':
  718. try {
  719. $connect = new Dibi\Connection([
  720. 'driver' => 'sqlite3',
  721. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  722. ]);
  723. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  724. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  725. return true;
  726. } catch (Dibi\Exception $e) {
  727. return false;
  728. }
  729. break;
  730. default:
  731. # code...
  732. break;
  733. }
  734. }
  735. function editCategories($array){
  736. switch ($array['data']['action']) {
  737. case 'changeDefault':
  738. try {
  739. $connect = new Dibi\Connection([
  740. 'driver' => 'sqlite3',
  741. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  742. ]);
  743. $connect->query('UPDATE categories SET `default` = 0');
  744. $connect->query('
  745. UPDATE categories SET', [
  746. 'default' => 1
  747. ], '
  748. WHERE id=?', $array['data']['id']);
  749. writeLog('success', 'Category Editor Function - Changed Default Category from ['.$array['data']['oldCategoryName'].'] to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  750. return true;
  751. } catch (Dibi\Exception $e) {
  752. return false;
  753. }
  754. break;
  755. case 'deleteCategory':
  756. try {
  757. $connect = new Dibi\Connection([
  758. 'driver' => 'sqlite3',
  759. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  760. ]);
  761. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  762. writeLog('success', 'Category Editor Function - Deleted Category ['.$array['data']['category'].']', $GLOBALS['organizrUser']['username']);
  763. return true;
  764. } catch (Dibi\Exception $e) {
  765. return false;
  766. }
  767. break;
  768. case 'addNewCategory':
  769. try {
  770. $connect = new Dibi\Connection([
  771. 'driver' => 'sqlite3',
  772. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  773. ]);
  774. $newCategory = [
  775. 'category' => $array['data']['categoryName'],
  776. 'order' => $array['data']['categoryOrder'],
  777. 'category_id' => $array['data']['categoryID'],
  778. 'default' => false,
  779. 'image' => $array['data']['categoryImage'],
  780. ];
  781. $connect->query('INSERT INTO [categories]', $newCategory);
  782. writeLog('success', 'Category Editor Function - Added Category ['.$array['data']['categoryName'].']', $GLOBALS['organizrUser']['username']);
  783. return true;
  784. } catch (Dibi\Exception $e) {
  785. return $e;
  786. }
  787. break;
  788. case 'editCategory':
  789. try {
  790. $connect = new Dibi\Connection([
  791. 'driver' => 'sqlite3',
  792. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  793. ]);
  794. $connect->query('
  795. UPDATE categories SET', [
  796. 'category' => $array['data']['name'],
  797. 'image' => $array['data']['image'],
  798. ], '
  799. WHERE id=?', $array['data']['id']);
  800. writeLog('success', 'Category Editor Function - Edited Category Info for ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  801. return true;
  802. } catch (Dibi\Exception $e) {
  803. return false;
  804. }
  805. break;
  806. case 'changeOrder':
  807. try {
  808. $connect = new Dibi\Connection([
  809. 'driver' => 'sqlite3',
  810. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  811. ]);
  812. foreach ($array['data']['categories']['category'] as $key => $value) {
  813. if($value['order'] != $value['originalOrder']){
  814. $connect->query('
  815. UPDATE categories SET', [
  816. 'order' => $value['order'],
  817. ], '
  818. WHERE id=?', $value['id']);
  819. writeLog('success', 'Category Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  820. }
  821. }
  822. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  823. return true;
  824. } catch (Dibi\Exception $e) {
  825. return false;
  826. }
  827. break;
  828. default:
  829. # code...
  830. break;
  831. }
  832. }
  833. function allUsers(){
  834. try {
  835. $connect = new Dibi\Connection([
  836. 'driver' => 'sqlite3',
  837. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  838. ]);
  839. $users = $connect->fetchAll('SELECT * FROM users');
  840. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  841. foreach ($users as $k => $v) {
  842. // clear password from array
  843. unset($users[$k]['password']);
  844. }
  845. $all['users'] = $users;
  846. $all['groups'] = $groups;
  847. return $all;
  848. } catch (Dibi\Exception $e) {
  849. return false;
  850. }
  851. }
  852. function usernameTaken($username,$email){
  853. try {
  854. $connect = new Dibi\Connection([
  855. 'driver' => 'sqlite3',
  856. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  857. ]);
  858. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$email);
  859. return ($all) ? true : false;
  860. } catch (Dibi\Exception $e) {
  861. return false;
  862. }
  863. }
  864. function usernameTakenExcept($username,$email,$id){
  865. try {
  866. $connect = new Dibi\Connection([
  867. 'driver' => 'sqlite3',
  868. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  869. ]);
  870. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE',$id,$username,$id,$email);
  871. return ($all) ? true : false;
  872. } catch (Dibi\Exception $e) {
  873. return false;
  874. }
  875. }
  876. function createUser($username,$password,$defaults,$email=null) {
  877. $email = ($email) ? $email : random_ascii_string(10).'@placeholder.eml';
  878. try {
  879. if(!usernameTaken($username,$email)){
  880. $createDB = new Dibi\Connection([
  881. 'driver' => 'sqlite3',
  882. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  883. ]);
  884. $userInfo = [
  885. 'username' => $username,
  886. 'password' => password_hash($password, PASSWORD_BCRYPT),
  887. 'email' => $email,
  888. 'group' => $defaults['group'],
  889. 'group_id' => $defaults['group_id'],
  890. 'image' => gravatar($email),
  891. 'register_date' => $GLOBALS['currentTime'],
  892. ];
  893. $createDB->query('INSERT INTO [users]', $userInfo);
  894. return true;
  895. }else{
  896. return false;
  897. }
  898. } catch (Dibi\Exception $e) {
  899. return false;
  900. }
  901. }
  902. function allTabs(){
  903. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  904. try {
  905. $connect = new Dibi\Connection([
  906. 'driver' => 'sqlite3',
  907. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  908. ]);
  909. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  910. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  911. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  912. return $all;
  913. } catch (Dibi\Exception $e) {
  914. return false;
  915. }
  916. }
  917. }
  918. function loadTabs(){
  919. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  920. try {
  921. $connect = new Dibi\Connection([
  922. 'driver' => 'sqlite3',
  923. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  924. ]);
  925. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` DESC',$GLOBALS['organizrUser']['groupID']);
  926. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  927. $all['tabs'] = $tabs;
  928. foreach ($tabs as $k => $v) {
  929. $v['access_url'] = isset($v['url_local']) && $_SERVER['SERVER_ADDR'] == userIP() ? $v['url_local'] : $v['url'];
  930. }
  931. $count = array_map(function($element){
  932. return $element['category_id'];
  933. }, $tabs);
  934. $count = (array_count_values($count));
  935. foreach ($categories as $k => $v) {
  936. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  937. }
  938. $all['categories'] = $categories;
  939. return $all;
  940. } catch (Dibi\Exception $e) {
  941. return false;
  942. }
  943. }
  944. }