api-functions.php 44 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function apiLogin()
  7. {
  8. $array = array(
  9. 'data' => array(
  10. array(
  11. 'name' => 'username',
  12. 'value' => (isset($_POST['username'])) ? $_POST['username'] : false
  13. ),
  14. array(
  15. 'name' => 'password',
  16. 'value' => (isset($_POST['password'])) ? $_POST['password'] : false
  17. ),
  18. array(
  19. 'name' => 'remember',
  20. 'value' => (isset($_POST['remember'])) ? true : false
  21. ),
  22. array(
  23. 'name' => 'oAuth',
  24. 'value' => (isset($_POST['oAuth'])) ? $_POST['oAuth'] : false
  25. ),
  26. array(
  27. 'name' => 'oAuthType',
  28. 'value' => (isset($_POST['oAuthType'])) ? $_POST['oAuthType'] : false
  29. ),
  30. array(
  31. 'name' => 'tfaCode',
  32. 'value' => (isset($_POST['tfaCode'])) ? $_POST['tfaCode'] : false
  33. ),
  34. array(
  35. 'name' => 'loginAttempts',
  36. 'value' => (isset($_POST['loginAttempts'])) ? $_POST['loginAttempts'] : false
  37. ),
  38. array(
  39. 'name' => 'output',
  40. 'value' => true
  41. ),
  42. )
  43. );
  44. foreach ($array['data'] as $items) {
  45. foreach ($items as $key => $value) {
  46. if ($key == 'name') {
  47. $newKey = $value;
  48. }
  49. if ($key == 'value') {
  50. $newValue = $value;
  51. }
  52. if (isset($newKey) && isset($newValue)) {
  53. $$newKey = $newValue;
  54. }
  55. }
  56. }
  57. return login($array);
  58. }
  59. function login($array)
  60. {
  61. // Grab username and Password from login form
  62. $username = $password = $oAuth = $oAuthType = '';
  63. foreach ($array['data'] as $items) {
  64. foreach ($items as $key => $value) {
  65. if ($key == 'name') {
  66. $newKey = $value;
  67. }
  68. if ($key == 'value') {
  69. $newValue = $value;
  70. }
  71. if (isset($newKey) && isset($newValue)) {
  72. $$newKey = $newValue;
  73. }
  74. }
  75. }
  76. $username = (strpos($GLOBALS['authBackend'], 'emby') !== false) ? $username : strtolower($username);
  77. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  78. $oAuth = (isset($oAuth)) ? $oAuth : false;
  79. $output = (isset($output)) ? $output : false;
  80. $loginAttempts = (isset($loginAttempts)) ? $loginAttempts : false;
  81. if ($loginAttempts > $GLOBALS['loginAttempts'] || isset($_COOKIE['lockout'])) {
  82. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  83. return 'lockout';
  84. }
  85. try {
  86. $database = new Dibi\Connection([
  87. 'driver' => 'sqlite3',
  88. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  89. ]);
  90. $authSuccess = false;
  91. $authProxy = false;
  92. if ($GLOBALS['authProxyEnabled'] && $GLOBALS['authProxyHeaderName'] !== '' && $GLOBALS['authProxyWhitelist'] !== '') {
  93. if (isset(getallheaders()[$GLOBALS['authProxyHeaderName']])) {
  94. $usernameHeader = isset(getallheaders()[$GLOBALS['authProxyHeaderName']]) ? getallheaders()[$GLOBALS['authProxyHeaderName']] : $username;
  95. writeLog('success', 'Auth Proxy Function - Starting Verification for IP: ' . userIP() . ' for request on: ' . $_SERVER['REMOTE_ADDR'] . ' against IP/Subnet: ' . $GLOBALS['authProxyWhitelist'], $usernameHeader);
  96. $whitelistRange = analyzeIP($GLOBALS['authProxyWhitelist']);
  97. $from = $whitelistRange['from'];
  98. $to = $whitelistRange['to'];
  99. $authProxy = authProxyRangeCheck($from, $to);
  100. $username = ($authProxy) ? $usernameHeader : $username;
  101. if ($authProxy) {
  102. writeLog('success', 'Auth Proxy Function - IP: ' . userIP() . ' has been verified', $usernameHeader);
  103. } else {
  104. writeLog('error', 'Auth Proxy Function - IP: ' . userIP() . ' has failed verification', $usernameHeader);
  105. }
  106. }
  107. }
  108. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  109. if (!$oAuth) {
  110. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  111. $result['password'] = $result['password'] ?? '';
  112. switch ($GLOBALS['authType']) {
  113. case 'external':
  114. if (function_exists($function)) {
  115. $authSuccess = $function($username, $password);
  116. }
  117. break;
  118. /** @noinspection PhpMissingBreakStatementInspection */
  119. case 'both':
  120. if (function_exists($function)) {
  121. $authSuccess = $function($username, $password);
  122. }
  123. // no break
  124. default: // Internal
  125. if (!$authSuccess) {
  126. // perform the internal authentication step
  127. if (password_verify($password, $result['password'])) {
  128. $authSuccess = true;
  129. }
  130. }
  131. }
  132. $authSuccess = ($authProxy) ? true : $authSuccess;
  133. } else {
  134. // Has oAuth Token!
  135. switch ($oAuthType) {
  136. case 'plex':
  137. if ($GLOBALS['plexoAuth']) {
  138. $tokenInfo = checkPlexToken($oAuth);
  139. if ($tokenInfo) {
  140. $authSuccess = array(
  141. 'username' => $tokenInfo['user']['username'],
  142. 'email' => $tokenInfo['user']['email'],
  143. 'image' => $tokenInfo['user']['thumb'],
  144. 'token' => $tokenInfo['user']['authToken']
  145. );
  146. coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
  147. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || (!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['email'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  148. }
  149. }
  150. break;
  151. default:
  152. return ($output) ? 'No oAuthType defined' : 'error';
  153. break;
  154. }
  155. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  156. }
  157. if ($authSuccess) {
  158. // Make sure user exists in database
  159. $userExists = false;
  160. $passwordMatches = ($oAuth || $authProxy) ? true : false;
  161. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  162. if ($result['username']) {
  163. $userExists = true;
  164. $username = $result['username'];
  165. if ($passwordMatches == false) {
  166. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  167. }
  168. }
  169. if ($userExists) {
  170. //does org password need to be updated
  171. if (!$passwordMatches) {
  172. $database->query('
  173. UPDATE users SET', [
  174. 'password' => password_hash($password, PASSWORD_BCRYPT)
  175. ], '
  176. WHERE id=?', $result['id']);
  177. writeLog('success', 'Login Function - User Password updated from backend', $username);
  178. }
  179. if ($token !== '') {
  180. if ($token !== $result['plex_token']) {
  181. $database->query('
  182. UPDATE users SET', [
  183. 'plex_token' => $token
  184. ], '
  185. WHERE id=?', $result['id']);
  186. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  187. }
  188. }
  189. // 2FA might go here
  190. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  191. $tfaProceed = true;
  192. // Add check for local or not
  193. if ($GLOBALS['ignoreTFALocal'] !== false) {
  194. $tfaProceed = (isLocal()) ? false : true;
  195. }
  196. if ($tfaProceed) {
  197. $TFA = explode('::', $result['auth_service']);
  198. // Is code with login info?
  199. if ($tfaCode == '') {
  200. return '2FA';
  201. } else {
  202. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  203. writeLoginLog($username, 'error');
  204. writeLog('error', 'Login Function - Wrong 2FA', $username);
  205. return '2FA-incorrect';
  206. }
  207. }
  208. }
  209. }
  210. // End 2FA
  211. // authentication passed - 1) mark active and update token
  212. $createToken = createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days);
  213. if ($createToken) {
  214. writeLoginLog($username, 'success');
  215. writeLog('success', 'Login Function - A User has logged in', $username);
  216. $ssoUser = ((empty($result['email'])) ? $result['username'] : (strpos($result['email'], 'placeholder') !== false)) ? $result['username'] : $result['email'];
  217. ssoCheck($ssoUser, $password, $token); //need to work on this
  218. return ($output) ? array('name' => $GLOBALS['cookieName'], 'token' => (string)$createToken) : true;
  219. } else {
  220. return 'Token Creation Error';
  221. }
  222. } else {
  223. // Create User
  224. //ssoCheck($username, $password, $token);
  225. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  226. }
  227. } else {
  228. // authentication failed
  229. writeLoginLog($username, 'error');
  230. writeLog('error', 'Login Function - Wrong Password', $username);
  231. if ($loginAttempts >= $GLOBALS['loginAttempts']) {
  232. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  233. return 'lockout';
  234. } else {
  235. return 'mismatch';
  236. }
  237. }
  238. } catch (Dibi\Exception $e) {
  239. return $e;
  240. }
  241. }
  242. function createDB($path, $filename)
  243. {
  244. try {
  245. if (!file_exists($path)) {
  246. mkdir($path, 0777, true);
  247. }
  248. $createDB = new Dibi\Connection([
  249. 'driver' => 'sqlite3',
  250. 'database' => $path . $filename,
  251. ]);
  252. // Create Users
  253. $createDB->query('CREATE TABLE `users` (
  254. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  255. `username` TEXT UNIQUE,
  256. `password` TEXT,
  257. `email` TEXT,
  258. `plex_token` TEXT,
  259. `group` TEXT,
  260. `group_id` INTEGER,
  261. `locked` INTEGER,
  262. `image` TEXT,
  263. `register_date` DATE,
  264. `auth_service` TEXT DEFAULT \'internal\'
  265. );');
  266. // Create Tokens
  267. $createDB->query('CREATE TABLE `chatroom` (
  268. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  269. `username` TEXT,
  270. `gravatar` TEXT,
  271. `uid` TEXT,
  272. `date` DATE,
  273. `ip` TEXT,
  274. `message` TEXT
  275. );');
  276. $createDB->query('CREATE TABLE `tokens` (
  277. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  278. `token` TEXT UNIQUE,
  279. `user_id` INTEGER,
  280. `browser` TEXT,
  281. `ip` TEXT,
  282. `created` DATE,
  283. `expires` DATE
  284. );');
  285. $createDB->query('CREATE TABLE `groups` (
  286. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  287. `group` TEXT UNIQUE,
  288. `group_id` INTEGER,
  289. `image` TEXT,
  290. `default` INTEGER
  291. );');
  292. $createDB->query('CREATE TABLE `categories` (
  293. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  294. `order` INTEGER,
  295. `category` TEXT UNIQUE,
  296. `category_id` INTEGER,
  297. `image` TEXT,
  298. `default` INTEGER
  299. );');
  300. // Create Tabs
  301. $createDB->query('CREATE TABLE `tabs` (
  302. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  303. `order` INTEGER,
  304. `category_id` INTEGER,
  305. `name` TEXT,
  306. `url` TEXT,
  307. `url_local` TEXT,
  308. `default` INTEGER,
  309. `enabled` INTEGER,
  310. `group_id` INTEGER,
  311. `image` TEXT,
  312. `type` INTEGER,
  313. `splash` INTEGER,
  314. `ping` INTEGER,
  315. `ping_url` TEXT,
  316. `timeout` INTEGER,
  317. `timeout_ms` INTEGER,
  318. `preload` INTEGER
  319. );');
  320. // Create Options
  321. $createDB->query('CREATE TABLE `options` (
  322. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  323. `name` TEXT UNIQUE,
  324. `value` TEXT
  325. );');
  326. // Create Invites
  327. $createDB->query('CREATE TABLE `invites` (
  328. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  329. `code` TEXT UNIQUE,
  330. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  331. `email` TEXT,
  332. `username` TEXT,
  333. `dateused` TIMESTAMP,
  334. `usedby` TEXT,
  335. `ip` TEXT,
  336. `valid` TEXT,
  337. `type` TEXT
  338. );');
  339. return true;
  340. } catch (Dibi\Exception $e) {
  341. return false;
  342. }
  343. }
  344. // Upgrade Database
  345. function updateDB($oldVerNum = false)
  346. {
  347. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  348. if (!file_exists($tempLock)) {
  349. touch($tempLock);
  350. // Create Temp DB First
  351. $migrationDB = 'tempMigration.db';
  352. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  353. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  354. unlink($GLOBALS['dbLocation'] . $migrationDB);
  355. }
  356. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  357. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  358. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  359. if ($success) {
  360. try {
  361. $connectOldDB = new Dibi\Connection([
  362. 'driver' => 'sqlite3',
  363. 'database' => $backupDB,
  364. ]);
  365. $connectNewDB = new Dibi\Connection([
  366. 'driver' => 'sqlite3',
  367. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  368. ]);
  369. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  370. foreach ($tables as $table) {
  371. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  372. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  373. foreach ($data as $row) {
  374. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  375. }
  376. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  377. }
  378. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  379. $connectOldDB->disconnect();
  380. $connectNewDB->disconnect();
  381. // Remove Current Database
  382. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  383. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  384. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  385. if ($newFileSize > 0) {
  386. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  387. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  388. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  389. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  390. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  391. @unlink($tempLock);
  392. return true;
  393. }
  394. }
  395. @unlink($tempLock);
  396. return false;
  397. } catch (Dibi\Exception $e) {
  398. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  399. @unlink($tempLock);
  400. return false;
  401. }
  402. }
  403. @unlink($tempLock);
  404. return false;
  405. }
  406. return false;
  407. }
  408. function createFirstAdmin($path, $filename, $username, $password, $email)
  409. {
  410. try {
  411. $createDB = new Dibi\Connection([
  412. 'driver' => 'sqlite3',
  413. 'database' => $path . $filename,
  414. ]);
  415. $userInfo = [
  416. 'username' => $username,
  417. 'password' => password_hash($password, PASSWORD_BCRYPT),
  418. 'email' => $email,
  419. 'group' => 'Admin',
  420. 'group_id' => 0,
  421. 'image' => gravatar($email),
  422. 'register_date' => $GLOBALS['currentTime'],
  423. ];
  424. $groupInfo0 = [
  425. 'group' => 'Admin',
  426. 'group_id' => 0,
  427. 'default' => false,
  428. 'image' => 'plugins/images/groups/admin.png',
  429. ];
  430. $groupInfo1 = [
  431. 'group' => 'Co-Admin',
  432. 'group_id' => 1,
  433. 'default' => false,
  434. 'image' => 'plugins/images/groups/coadmin.png',
  435. ];
  436. $groupInfo2 = [
  437. 'group' => 'Super User',
  438. 'group_id' => 2,
  439. 'default' => false,
  440. 'image' => 'plugins/images/groups/superuser.png',
  441. ];
  442. $groupInfo3 = [
  443. 'group' => 'Power User',
  444. 'group_id' => 3,
  445. 'default' => false,
  446. 'image' => 'plugins/images/groups/poweruser.png',
  447. ];
  448. $groupInfo4 = [
  449. 'group' => 'User',
  450. 'group_id' => 4,
  451. 'default' => true,
  452. 'image' => 'plugins/images/groups/user.png',
  453. ];
  454. $groupInfoGuest = [
  455. 'group' => 'Guest',
  456. 'group_id' => 999,
  457. 'default' => false,
  458. 'image' => 'plugins/images/groups/guest.png',
  459. ];
  460. $settingsInfo = [
  461. 'order' => 1,
  462. 'category_id' => 0,
  463. 'name' => 'Settings',
  464. 'url' => 'api/?v1/settings/page',
  465. 'default' => false,
  466. 'enabled' => true,
  467. 'group_id' => 1,
  468. 'image' => 'fontawesome::cog',
  469. 'type' => 0
  470. ];
  471. $homepageInfo = [
  472. 'order' => 2,
  473. 'category_id' => 0,
  474. 'name' => 'Homepage',
  475. 'url' => 'api/?v1/homepage/page',
  476. 'default' => false,
  477. 'enabled' => false,
  478. 'group_id' => 4,
  479. 'image' => 'fontawesome::home',
  480. 'type' => 0
  481. ];
  482. $unsortedInfo = [
  483. 'order' => 1,
  484. 'category' => 'Unsorted',
  485. 'category_id' => 0,
  486. 'image' => 'plugins/images/categories/unsorted.png',
  487. 'default' => true
  488. ];
  489. $createDB->query('INSERT INTO [users]', $userInfo);
  490. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  491. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  492. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  493. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  494. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  495. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  496. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  497. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  498. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  499. return true;
  500. } catch (Dibi\Exception $e) {
  501. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  502. return false;
  503. }
  504. }
  505. function defaultUserGroup()
  506. {
  507. try {
  508. $connect = new Dibi\Connection([
  509. 'driver' => 'sqlite3',
  510. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  511. ]);
  512. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  513. return $all;
  514. } catch (Dibi\Exception $e) {
  515. return false;
  516. }
  517. }
  518. function defaultTabCategory()
  519. {
  520. try {
  521. $connect = new Dibi\Connection([
  522. 'driver' => 'sqlite3',
  523. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  524. ]);
  525. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  526. return $all;
  527. } catch (Dibi\Exception $e) {
  528. return false;
  529. }
  530. }
  531. function getGuest()
  532. {
  533. if (isset($GLOBALS['dbLocation'])) {
  534. try {
  535. $connect = new Dibi\Connection([
  536. 'driver' => 'sqlite3',
  537. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  538. ]);
  539. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  540. return $all;
  541. } catch (Dibi\Exception $e) {
  542. return false;
  543. }
  544. } else {
  545. return array(
  546. 'group' => 'Guest',
  547. 'group_id' => 999,
  548. 'image' => 'plugins/images/groups/guest.png'
  549. );
  550. }
  551. }
  552. function adminEditGroup($array)
  553. {
  554. switch ($array['data']['action']) {
  555. case 'changeDefaultGroup':
  556. try {
  557. $connect = new Dibi\Connection([
  558. 'driver' => 'sqlite3',
  559. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  560. ]);
  561. $connect->query('UPDATE groups SET `default` = 0');
  562. $connect->query('
  563. UPDATE groups SET', [
  564. 'default' => 1
  565. ], '
  566. WHERE id=?', $array['data']['id']);
  567. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  568. return true;
  569. } catch (Dibi\Exception $e) {
  570. return false;
  571. }
  572. break;
  573. case 'deleteUserGroup':
  574. try {
  575. $connect = new Dibi\Connection([
  576. 'driver' => 'sqlite3',
  577. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  578. ]);
  579. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  580. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  581. return true;
  582. } catch (Dibi\Exception $e) {
  583. return false;
  584. }
  585. break;
  586. case 'addUserGroup':
  587. try {
  588. $connect = new Dibi\Connection([
  589. 'driver' => 'sqlite3',
  590. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  591. ]);
  592. $newGroup = [
  593. 'group' => $array['data']['newGroupName'],
  594. 'group_id' => $array['data']['newGroupID'],
  595. 'default' => false,
  596. 'image' => $array['data']['newGroupImage'],
  597. ];
  598. $connect->query('INSERT INTO [groups]', $newGroup);
  599. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  600. return true;
  601. } catch (Dibi\Exception $e) {
  602. return false;
  603. }
  604. break;
  605. case 'editUserGroup':
  606. try {
  607. $connect = new Dibi\Connection([
  608. 'driver' => 'sqlite3',
  609. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  610. ]);
  611. $connect->query('
  612. UPDATE groups SET', [
  613. 'group' => $array['data']['groupName'],
  614. 'image' => $array['data']['groupImage'],
  615. ], '
  616. WHERE id=?', $array['data']['id']);
  617. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  618. return true;
  619. } catch (Dibi\Exception $e) {
  620. return false;
  621. }
  622. break;
  623. default:
  624. return false;
  625. break;
  626. }
  627. }
  628. function adminEditUser($array)
  629. {
  630. switch ($array['data']['action']) {
  631. case 'changeGroup':
  632. if ($array['data']['newGroupID'] == 0) {
  633. return false;
  634. }
  635. try {
  636. $connect = new Dibi\Connection([
  637. 'driver' => 'sqlite3',
  638. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  639. ]);
  640. $connect->query('
  641. UPDATE users SET', [
  642. 'group' => $array['data']['newGroupName'],
  643. 'group_id' => $array['data']['newGroupID'],
  644. ], '
  645. WHERE id=?', $array['data']['id']);
  646. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  647. return true;
  648. } catch (Dibi\Exception $e) {
  649. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  650. return false;
  651. }
  652. break;
  653. case 'editUser':
  654. try {
  655. $connect = new Dibi\Connection([
  656. 'driver' => 'sqlite3',
  657. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  658. ]);
  659. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  660. $connect->query('
  661. UPDATE users SET', [
  662. 'username' => $array['data']['username'],
  663. 'email' => $array['data']['email'],
  664. 'image' => gravatar($array['data']['email']),
  665. ], '
  666. WHERE id=?', $array['data']['id']);
  667. if (!empty($array['data']['password'])) {
  668. $connect->query('
  669. UPDATE users SET', [
  670. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  671. ], '
  672. WHERE id=?', $array['data']['id']);
  673. }
  674. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  675. return true;
  676. } else {
  677. return false;
  678. }
  679. } catch (Dibi\Exception $e) {
  680. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  681. return false;
  682. }
  683. break;
  684. case 'addNewUser':
  685. $defaults = defaultUserGroup();
  686. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  687. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  688. return true;
  689. } else {
  690. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  691. return 'username taken';
  692. }
  693. break;
  694. case 'deleteUser':
  695. try {
  696. $connect = new Dibi\Connection([
  697. 'driver' => 'sqlite3',
  698. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  699. ]);
  700. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  701. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  702. return true;
  703. } catch (Dibi\Exception $e) {
  704. return false;
  705. }
  706. break;
  707. default:
  708. return false;
  709. break;
  710. }
  711. }
  712. function editTabs($array)
  713. {
  714. switch ($array['data']['action']) {
  715. case 'changeGroup':
  716. try {
  717. $connect = new Dibi\Connection([
  718. 'driver' => 'sqlite3',
  719. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  720. ]);
  721. $connect->query('
  722. UPDATE tabs SET', [
  723. 'group_id' => $array['data']['newGroupID'],
  724. ], '
  725. WHERE id=?', $array['data']['id']);
  726. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  727. return true;
  728. } catch (Dibi\Exception $e) {
  729. return false;
  730. }
  731. break;
  732. case 'changeCategory':
  733. try {
  734. $connect = new Dibi\Connection([
  735. 'driver' => 'sqlite3',
  736. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  737. ]);
  738. $connect->query('
  739. UPDATE tabs SET', [
  740. 'category_id' => $array['data']['newCategoryID'],
  741. ], '
  742. WHERE id=?', $array['data']['id']);
  743. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  744. return true;
  745. } catch (Dibi\Exception $e) {
  746. return false;
  747. }
  748. break;
  749. case 'changeType':
  750. try {
  751. $connect = new Dibi\Connection([
  752. 'driver' => 'sqlite3',
  753. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  754. ]);
  755. $connect->query('
  756. UPDATE tabs SET', [
  757. 'type' => $array['data']['newTypeID'],
  758. ], '
  759. WHERE id=?', $array['data']['id']);
  760. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  761. return true;
  762. } catch (Dibi\Exception $e) {
  763. return false;
  764. }
  765. break;
  766. case 'changeEnabled':
  767. try {
  768. $connect = new Dibi\Connection([
  769. 'driver' => 'sqlite3',
  770. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  771. ]);
  772. $connect->query('
  773. UPDATE tabs SET', [
  774. 'enabled' => $array['data']['tabEnabled'],
  775. ], '
  776. WHERE id=?', $array['data']['id']);
  777. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  778. return true;
  779. } catch (Dibi\Exception $e) {
  780. return false;
  781. }
  782. break;
  783. case 'changeSplash':
  784. try {
  785. $connect = new Dibi\Connection([
  786. 'driver' => 'sqlite3',
  787. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  788. ]);
  789. $connect->query('
  790. UPDATE tabs SET', [
  791. 'splash' => $array['data']['tabSplash'],
  792. ], '
  793. WHERE id=?', $array['data']['id']);
  794. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  795. return true;
  796. } catch (Dibi\Exception $e) {
  797. return false;
  798. }
  799. break;
  800. case 'changePing':
  801. try {
  802. $connect = new Dibi\Connection([
  803. 'driver' => 'sqlite3',
  804. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  805. ]);
  806. $connect->query('
  807. UPDATE tabs SET', [
  808. 'ping' => $array['data']['tabPing'],
  809. ], '
  810. WHERE id=?', $array['data']['id']);
  811. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  812. return true;
  813. } catch (Dibi\Exception $e) {
  814. return false;
  815. }
  816. break;
  817. case 'changePreload':
  818. try {
  819. $connect = new Dibi\Connection([
  820. 'driver' => 'sqlite3',
  821. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  822. ]);
  823. $connect->query('
  824. UPDATE tabs SET', [
  825. 'preload' => $array['data']['tabPreload'],
  826. ], '
  827. WHERE id=?', $array['data']['id']);
  828. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s preload status was changed to [' . $array['data']['tabPreloadWord'] . ']', $GLOBALS['organizrUser']['username']);
  829. return true;
  830. } catch (Dibi\Exception $e) {
  831. return false;
  832. }
  833. break;
  834. case 'changeDefault':
  835. try {
  836. $connect = new Dibi\Connection([
  837. 'driver' => 'sqlite3',
  838. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  839. ]);
  840. $connect->query('UPDATE tabs SET `default` = 0');
  841. $connect->query('
  842. UPDATE tabs SET', [
  843. 'default' => 1
  844. ], '
  845. WHERE id=?', $array['data']['id']);
  846. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  847. return true;
  848. } catch (Dibi\Exception $e) {
  849. return false;
  850. }
  851. break;
  852. case 'deleteTab':
  853. try {
  854. $connect = new Dibi\Connection([
  855. 'driver' => 'sqlite3',
  856. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  857. ]);
  858. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  859. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  860. return true;
  861. } catch (Dibi\Exception $e) {
  862. return false;
  863. }
  864. break;
  865. case 'editTab':
  866. try {
  867. $connect = new Dibi\Connection([
  868. 'driver' => 'sqlite3',
  869. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  870. ]);
  871. $connect->query('
  872. UPDATE tabs SET', [
  873. 'name' => $array['data']['tabName'],
  874. 'url' => $array['data']['tabURL'],
  875. 'url_local' => $array['data']['tabLocalURL'],
  876. 'ping_url' => $array['data']['pingURL'],
  877. 'image' => $array['data']['tabImage'],
  878. 'timeout' => $array['data']['tabActionType'],
  879. 'timeout_ms' => $array['data']['tabActionTime'],
  880. ], '
  881. WHERE id=?', $array['data']['id']);
  882. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  883. return true;
  884. } catch (Dibi\Exception $e) {
  885. return false;
  886. }
  887. case 'changeOrder':
  888. try {
  889. $connect = new Dibi\Connection([
  890. 'driver' => 'sqlite3',
  891. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  892. ]);
  893. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  894. if ($value['order'] != $value['originalOrder']) {
  895. $connect->query('
  896. UPDATE tabs SET', [
  897. 'order' => $value['order'],
  898. ], '
  899. WHERE id=?', $value['id']);
  900. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  901. }
  902. }
  903. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  904. return true;
  905. } catch (Dibi\Exception $e) {
  906. return false;
  907. }
  908. break;
  909. case 'addNewTab':
  910. try {
  911. $default = defaultTabCategory()['category_id'];
  912. $connect = new Dibi\Connection([
  913. 'driver' => 'sqlite3',
  914. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  915. ]);
  916. $newTab = [
  917. 'order' => $array['data']['tabOrder'],
  918. 'category_id' => $default,
  919. 'name' => $array['data']['tabName'],
  920. 'url' => $array['data']['tabURL'],
  921. 'url_local' => $array['data']['tabLocalURL'],
  922. 'ping_url' => $array['data']['pingURL'],
  923. 'default' => $array['data']['tabDefault'],
  924. 'enabled' => 1,
  925. 'group_id' => $array['data']['tabGroupID'],
  926. 'image' => $array['data']['tabImage'],
  927. 'type' => $array['data']['tabType'],
  928. 'timeout' => $array['data']['tabActionType'],
  929. 'timeout_ms' => $array['data']['tabActionTime'],
  930. ];
  931. $connect->query('INSERT INTO [tabs]', $newTab);
  932. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  933. return true;
  934. } catch (Dibi\Exception $e) {
  935. return false;
  936. }
  937. break;
  938. default:
  939. return false;
  940. break;
  941. }
  942. }
  943. function editCategories($array)
  944. {
  945. switch ($array['data']['action']) {
  946. case 'changeDefault':
  947. try {
  948. $connect = new Dibi\Connection([
  949. 'driver' => 'sqlite3',
  950. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  951. ]);
  952. $connect->query('UPDATE categories SET `default` = 0');
  953. $connect->query('
  954. UPDATE categories SET', [
  955. 'default' => 1
  956. ], '
  957. WHERE id=?', $array['data']['id']);
  958. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  959. return true;
  960. } catch (Dibi\Exception $e) {
  961. return false;
  962. }
  963. break;
  964. case 'deleteCategory':
  965. try {
  966. $connect = new Dibi\Connection([
  967. 'driver' => 'sqlite3',
  968. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  969. ]);
  970. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  971. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  972. return true;
  973. } catch (Dibi\Exception $e) {
  974. return false;
  975. }
  976. break;
  977. case 'addNewCategory':
  978. try {
  979. $connect = new Dibi\Connection([
  980. 'driver' => 'sqlite3',
  981. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  982. ]);
  983. $newCategory = [
  984. 'category' => $array['data']['categoryName'],
  985. 'order' => $array['data']['categoryOrder'],
  986. 'category_id' => $array['data']['categoryID'],
  987. 'default' => false,
  988. 'image' => $array['data']['categoryImage'],
  989. ];
  990. $connect->query('INSERT INTO [categories]', $newCategory);
  991. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  992. return true;
  993. } catch (Dibi\Exception $e) {
  994. return $e;
  995. }
  996. break;
  997. case 'editCategory':
  998. try {
  999. $connect = new Dibi\Connection([
  1000. 'driver' => 'sqlite3',
  1001. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1002. ]);
  1003. $connect->query('
  1004. UPDATE categories SET', [
  1005. 'category' => $array['data']['name'],
  1006. 'image' => $array['data']['image'],
  1007. ], '
  1008. WHERE id=?', $array['data']['id']);
  1009. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  1010. return true;
  1011. } catch (Dibi\Exception $e) {
  1012. return false;
  1013. }
  1014. break;
  1015. case 'changeOrder':
  1016. try {
  1017. $connect = new Dibi\Connection([
  1018. 'driver' => 'sqlite3',
  1019. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1020. ]);
  1021. foreach ($array['data']['categories']['category'] as $key => $value) {
  1022. if ($value['order'] != $value['originalOrder']) {
  1023. $connect->query('
  1024. UPDATE categories SET', [
  1025. 'order' => $value['order'],
  1026. ], '
  1027. WHERE id=?', $value['id']);
  1028. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  1029. }
  1030. }
  1031. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  1032. return true;
  1033. } catch (Dibi\Exception $e) {
  1034. return false;
  1035. }
  1036. break;
  1037. default:
  1038. return false;
  1039. break;
  1040. }
  1041. }
  1042. function allUsers()
  1043. {
  1044. try {
  1045. $connect = new Dibi\Connection([
  1046. 'driver' => 'sqlite3',
  1047. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1048. ]);
  1049. $users = $connect->fetchAll('SELECT * FROM users');
  1050. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  1051. foreach ($users as $k => $v) {
  1052. // clear password from array
  1053. unset($users[$k]['password']);
  1054. }
  1055. $all['users'] = $users;
  1056. $all['groups'] = $groups;
  1057. return $all;
  1058. } catch (Dibi\Exception $e) {
  1059. return false;
  1060. }
  1061. }
  1062. function usernameTaken($username, $email)
  1063. {
  1064. try {
  1065. $connect = new Dibi\Connection([
  1066. 'driver' => 'sqlite3',
  1067. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1068. ]);
  1069. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  1070. return ($all) ? true : false;
  1071. } catch (Dibi\Exception $e) {
  1072. return false;
  1073. }
  1074. }
  1075. function usernameTakenExcept($username, $email, $id)
  1076. {
  1077. try {
  1078. $connect = new Dibi\Connection([
  1079. 'driver' => 'sqlite3',
  1080. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1081. ]);
  1082. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  1083. return ($all) ? true : false;
  1084. } catch (Dibi\Exception $e) {
  1085. return false;
  1086. }
  1087. }
  1088. function createUser($username, $password, $defaults, $email = null)
  1089. {
  1090. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  1091. try {
  1092. if (!usernameTaken($username, $email)) {
  1093. $createDB = new Dibi\Connection([
  1094. 'driver' => 'sqlite3',
  1095. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1096. ]);
  1097. $userInfo = [
  1098. 'username' => $username,
  1099. 'password' => password_hash($password, PASSWORD_BCRYPT),
  1100. 'email' => $email,
  1101. 'group' => $defaults['group'],
  1102. 'group_id' => $defaults['group_id'],
  1103. 'image' => gravatar($email),
  1104. 'register_date' => $GLOBALS['currentTime'],
  1105. ];
  1106. $createDB->query('INSERT INTO [users]', $userInfo);
  1107. return true;
  1108. } else {
  1109. return false;
  1110. }
  1111. } catch (Dibi\Exception $e) {
  1112. return false;
  1113. }
  1114. }
  1115. function importUsers($array)
  1116. {
  1117. $imported = 0;
  1118. $defaults = defaultUserGroup();
  1119. foreach ($array as $user) {
  1120. $password = random_ascii_string(30);
  1121. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1122. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1123. if (!$newUser) {
  1124. writeLog('error', 'Import Function - Error', $user['username']);
  1125. } else {
  1126. $imported++;
  1127. }
  1128. }
  1129. }
  1130. return $imported;
  1131. }
  1132. function importUsersType($array)
  1133. {
  1134. $type = $array['data']['type'];
  1135. if ($type !== '') {
  1136. switch ($type) {
  1137. case 'plex':
  1138. return importUsers(allPlexUsers(true));
  1139. break;
  1140. default:
  1141. return false;
  1142. }
  1143. }
  1144. return false;
  1145. }
  1146. function allTabs()
  1147. {
  1148. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1149. try {
  1150. $connect = new Dibi\Connection([
  1151. 'driver' => 'sqlite3',
  1152. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1153. ]);
  1154. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1155. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1156. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1157. return $all;
  1158. } catch (Dibi\Exception $e) {
  1159. return false;
  1160. }
  1161. }
  1162. return false;
  1163. }
  1164. function allGroups()
  1165. {
  1166. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1167. try {
  1168. $connect = new Dibi\Connection([
  1169. 'driver' => 'sqlite3',
  1170. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1171. ]);
  1172. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1173. return $all;
  1174. } catch (Dibi\Exception $e) {
  1175. return false;
  1176. }
  1177. }
  1178. return false;
  1179. }
  1180. function loadTabs($type = null)
  1181. {
  1182. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php') && $type) {
  1183. try {
  1184. $connect = new Dibi\Connection([
  1185. 'driver' => 'sqlite3',
  1186. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1187. ]);
  1188. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1189. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1190. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1191. $all['tabs'] = $tabs;
  1192. foreach ($tabs as $k => $v) {
  1193. $v['access_url'] = (!empty($v['url_local']) && ($v['url_local'] !== null) && ($v['url_local'] !== 'null') && isLocal() && $v['type'] !== 0) ? $v['url_local'] : $v['url'];
  1194. }
  1195. $count = array_map(function ($element) {
  1196. return $element['category_id'];
  1197. }, $tabs);
  1198. $count = (array_count_values($count));
  1199. foreach ($categories as $k => $v) {
  1200. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1201. }
  1202. $all['categories'] = $categories;
  1203. switch ($type) {
  1204. case 'categories':
  1205. return $all['categories'];
  1206. case 'tabs':
  1207. return $all['tabs'];
  1208. default:
  1209. return $all;
  1210. }
  1211. } catch (Dibi\Exception $e) {
  1212. return false;
  1213. }
  1214. }
  1215. return false;
  1216. }
  1217. function getActiveTokens()
  1218. {
  1219. try {
  1220. $connect = new Dibi\Connection([
  1221. 'driver' => 'sqlite3',
  1222. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1223. ]);
  1224. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1225. return $all;
  1226. } catch (Dibi\Exception $e) {
  1227. return false;
  1228. }
  1229. }
  1230. function revokeToken($array)
  1231. {
  1232. if ($array['data']['token']) {
  1233. try {
  1234. $connect = new Dibi\Connection([
  1235. 'driver' => 'sqlite3',
  1236. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1237. ]);
  1238. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1239. return true;
  1240. } catch (Dibi\Exception $e) {
  1241. return false;
  1242. }
  1243. }
  1244. }
  1245. function getSchema()
  1246. {
  1247. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1248. try {
  1249. $connect = new Dibi\Connection([
  1250. 'driver' => 'sqlite3',
  1251. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1252. ]);
  1253. $result = $connect->fetchAll(' SELECT name, sql FROM sqlite_master WHERE type=\'table\' ORDER BY name');
  1254. return $result;
  1255. } catch (Dibi\Exception $e) {
  1256. return false;
  1257. }
  1258. } else {
  1259. return 'DB not set yet...';
  1260. }
  1261. }
  1262. function youtubeSearch($query)
  1263. {
  1264. if (!$query) {
  1265. return 'no query provided!';
  1266. }
  1267. $keys = array('AIzaSyBsdt8nLJRMTwOq5PY5A5GLZ2q7scgn01w', 'AIzaSyD-8SHutB60GCcSM8q_Fle38rJUV7ujd8k', 'AIzaSyBzOpVBT6VII-b-8gWD0MOEosGg4hyhCsQ', 'AIzaSyBKnRe1P8fpfBHgooJpmT0WOsrdUtZ4cpk');
  1268. $randomKeyIndex = array_rand($keys);
  1269. $key = $keys[$randomKeyIndex];
  1270. $apikey = ($GLOBALS['youtubeAPI'] !== '') ? $GLOBALS['youtubeAPI'] : $key;
  1271. $results = false;
  1272. $url = "https://www.googleapis.com/youtube/v3/search?part=snippet&q=$query+official+trailer&part=snippet&maxResults=1&type=video&videoDuration=short&key=$apikey";
  1273. $response = Requests::get($url);
  1274. if ($response->success) {
  1275. $results = json_decode($response->body, true);
  1276. }
  1277. return ($results) ? $results : false;
  1278. }
  1279. function scrapePage($array)
  1280. {
  1281. try {
  1282. $url = $array['data']['url'] ?? false;
  1283. $type = $array['data']['type'] ?? false;
  1284. if (!$url) return array(
  1285. 'result' => 'Error',
  1286. 'data' => 'No URL'
  1287. );
  1288. $url = qualifyURL($url);
  1289. $data = array(
  1290. 'full_url' => $url,
  1291. 'drill_url' => qualifyURL($url, true)
  1292. );
  1293. $options = array('verify' => false);
  1294. $response = Requests::get($url, array(), $options);
  1295. $data['response_code'] = $response->status_code;
  1296. if ($response->success) {
  1297. $data['result'] = 'Success';
  1298. switch ($type) {
  1299. case 'html':
  1300. $data['data'] = html_entity_decode($response->body);
  1301. break;
  1302. case 'json':
  1303. $data['data'] = json_decode($response->body);
  1304. break;
  1305. default:
  1306. $data['data'] = $response->body;
  1307. }
  1308. return $data;
  1309. }
  1310. } catch (Requests_Exception $e) {
  1311. return array(
  1312. 'result' => 'Error',
  1313. 'data' => $e->getMessage()
  1314. );
  1315. };
  1316. return array('result' => 'Error');
  1317. }
  1318. function searchCityForCoordinates($array)
  1319. {
  1320. try {
  1321. $query = $array['data']['query'] ?? false;
  1322. $url = qualifyURL('https://api.mapbox.com/geocoding/v5/mapbox.places/' . urlencode($query) . '.json?access_token=pk.eyJ1IjoiY2F1c2VmeCIsImEiOiJjazhyeGxqeXgwMWd2M2ZydWQ4YmdjdGlzIn0.R50iYuMewh1CnUZ7sFPdHA&limit=5&fuzzyMatch=true');
  1323. $options = array('verify' => false);
  1324. $response = Requests::get($url, array(), $options);
  1325. if ($response->success) {
  1326. return json_decode($response->body);
  1327. }
  1328. } catch (Requests_Exception $e) {
  1329. return array(
  1330. 'result' => 'Error',
  1331. 'data' => $e->getMessage()
  1332. );
  1333. };
  1334. return array('result' => 'Error');
  1335. }