index.php 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528
  1. <?php
  2. $generationTime = -microtime(true);
  3. //include functions
  4. require_once 'functions.php';
  5. //Set result array
  6. $result = array();
  7. //Get request method
  8. $method = $_SERVER['REQUEST_METHOD'];
  9. reset($_GET);
  10. $function = (key($_GET) ? str_replace("/","_",key($_GET)) : false);
  11. //Exit if $function is blank
  12. if($function === false){
  13. $result['status'] = "error";
  14. $result['statusText'] = "No API Path Supplied";
  15. exit(json_encode($result));
  16. }
  17. $result['request'] = key($_GET);
  18. switch ($function) {
  19. case 'v1_settings_page':
  20. switch ($method) {
  21. case 'GET':
  22. if(qualifyRequest(1)){
  23. $result['status'] = 'success';
  24. $result['statusText'] = 'success';
  25. $result['data'] = $pageSettings;
  26. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  27. }else{
  28. $result['status'] = 'error';
  29. $result['statusText'] = 'API/Token invalid or not set';
  30. $result['data'] = null;
  31. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  32. }
  33. break;
  34. default:
  35. $result['status'] = 'error';
  36. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  37. break;
  38. }
  39. break;
  40. case 'v1_settings_settings_logs':
  41. switch ($method) {
  42. case 'GET':
  43. if(qualifyRequest(1)){
  44. $result['status'] = 'success';
  45. $result['statusText'] = 'success';
  46. $result['data'] = $pageSettingsSettingsLogs;
  47. }else{
  48. $result['status'] = 'error';
  49. $result['statusText'] = 'API/Token invalid or not set';
  50. $result['data'] = null;
  51. }
  52. break;
  53. default:
  54. $result['status'] = 'error';
  55. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  56. break;
  57. }
  58. break;
  59. case 'v1_settings_customize_appearance':
  60. switch ($method) {
  61. case 'GET':
  62. if(qualifyRequest(1)){
  63. $result['status'] = 'success';
  64. $result['statusText'] = 'success';
  65. $result['data'] = $pageSettingsCustomizeAppearance;
  66. }else{
  67. $result['status'] = 'error';
  68. $result['statusText'] = 'API/Token invalid or not set';
  69. $result['data'] = null;
  70. }
  71. break;
  72. default:
  73. $result['status'] = 'error';
  74. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  75. break;
  76. }
  77. break;
  78. case 'v1_settings_tab_editor_tabs':
  79. switch ($method) {
  80. case 'GET':
  81. if(qualifyRequest(1)){
  82. $result['status'] = 'success';
  83. $result['statusText'] = 'success';
  84. $result['data'] = $pageSettingsTabEditorTabs;
  85. }else{
  86. $result['status'] = 'error';
  87. $result['statusText'] = 'API/Token invalid or not set';
  88. $result['data'] = null;
  89. }
  90. break;
  91. case 'POST':
  92. if(qualifyRequest(1)){
  93. $result['status'] = 'success';
  94. $result['statusText'] = 'success';
  95. $result['data'] = editTabs($_POST);
  96. }else{
  97. $result['status'] = 'error';
  98. $result['statusText'] = 'API/Token invalid or not set';
  99. $result['data'] = null;
  100. }
  101. break;
  102. default:
  103. $result['status'] = 'error';
  104. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  105. break;
  106. }
  107. break;
  108. case 'v1_settings_tab_editor_categories':
  109. switch ($method) {
  110. case 'GET':
  111. if(qualifyRequest(1)){
  112. $result['status'] = 'success';
  113. $result['statusText'] = 'success';
  114. $result['data'] = $pageSettingsTabEditorCategories;
  115. }else{
  116. $result['status'] = 'error';
  117. $result['statusText'] = 'API/Token invalid or not set';
  118. $result['data'] = null;
  119. }
  120. break;
  121. case 'POST':
  122. if(qualifyRequest(1)){
  123. $result['status'] = 'success';
  124. $result['statusText'] = 'success';
  125. $result['data'] = editCategories($_POST);
  126. }else{
  127. $result['status'] = 'error';
  128. $result['statusText'] = 'API/Token invalid or not set';
  129. $result['data'] = null;
  130. }
  131. break;
  132. default:
  133. $result['status'] = 'error';
  134. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  135. break;
  136. }
  137. break;
  138. case 'v1_settings_user_manage_users':
  139. switch ($method) {
  140. case 'GET':
  141. if(qualifyRequest(1)){
  142. $result['status'] = 'success';
  143. $result['statusText'] = 'success';
  144. $result['data'] = $pageSettingsUserManageUsers;
  145. }else{
  146. $result['status'] = 'error';
  147. $result['statusText'] = 'API/Token invalid or not set';
  148. $result['data'] = null;
  149. }
  150. break;
  151. case 'POST':
  152. if(qualifyRequest(1)){
  153. $result['status'] = 'success';
  154. $result['statusText'] = 'success';
  155. $result['data'] = adminEditUser($_POST);
  156. }elseif(qualifyRequest(998)){
  157. $result['status'] = 'success';
  158. $result['statusText'] = 'success';
  159. $result['data'] = editUser($_POST);
  160. }else{
  161. $result['status'] = 'error';
  162. $result['statusText'] = 'API/Token invalid or not set';
  163. $result['data'] = null;
  164. }
  165. break;
  166. default:
  167. $result['status'] = 'error';
  168. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  169. break;
  170. }
  171. break;
  172. case 'v1_settings_user_manage_groups':
  173. switch ($method) {
  174. case 'GET':
  175. if(qualifyRequest(1)){
  176. $result['status'] = 'success';
  177. $result['statusText'] = 'success';
  178. $result['data'] = $pageSettingsUserManageGroups;
  179. }else{
  180. $result['status'] = 'error';
  181. $result['statusText'] = 'API/Token invalid or not set';
  182. $result['data'] = null;
  183. }
  184. break;
  185. case 'POST':
  186. if(qualifyRequest(1)){
  187. $result['status'] = 'success';
  188. $result['statusText'] = 'success';
  189. $result['data'] = adminEditGroup($_POST);
  190. }else{
  191. $result['status'] = 'error';
  192. $result['statusText'] = 'API/Token invalid or not set';
  193. $result['data'] = null;
  194. }
  195. break;
  196. default:
  197. $result['status'] = 'error';
  198. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  199. break;
  200. }
  201. break;
  202. case 'v1_wizard_page':
  203. switch ($method) {
  204. case 'GET':
  205. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  206. $result['status'] = 'success';
  207. $result['statusText'] = 'success';
  208. $result['data'] = $pageWizard;
  209. }else{
  210. $result['status'] = 'error';
  211. $result['statusText'] = 'Wizard has already been run';
  212. $result['data'] = null;
  213. }
  214. break;
  215. default:
  216. $result['status'] = 'error';
  217. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  218. break;
  219. }
  220. break;
  221. case 'v1_dependencies_page':
  222. switch ($method) {
  223. case 'GET':
  224. $result['status'] = 'success';
  225. $result['statusText'] = 'success';
  226. $result['data'] = $pageDependencies;
  227. break;
  228. default:
  229. $result['status'] = 'error';
  230. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  231. break;
  232. }
  233. break;
  234. case 'v1_wizard_config':
  235. switch ($method) {
  236. case 'POST':
  237. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  238. $result['status'] = 'success';
  239. $result['statusText'] = 'success';
  240. $result['data'] = wizardConfig($_POST);
  241. }else{
  242. $result['status'] = 'error';
  243. $result['statusText'] = 'Wizard has already been run';
  244. $result['data'] = null;
  245. }
  246. break;
  247. default:
  248. $result['status'] = 'error';
  249. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  250. break;
  251. }
  252. break;
  253. case 'v1_login':
  254. switch ($method) {
  255. case 'POST':
  256. $result['status'] = 'success';
  257. $result['statusText'] = 'success';
  258. $result['data'] = login($_POST);
  259. break;
  260. default:
  261. $result['status'] = 'error';
  262. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  263. break;
  264. }
  265. break;
  266. case 'v1_register':
  267. switch ($method) {
  268. case 'POST':
  269. $result['status'] = 'success';
  270. $result['statusText'] = 'success';
  271. $result['data'] = register($_POST);
  272. break;
  273. default:
  274. $result['status'] = 'error';
  275. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  276. break;
  277. }
  278. break;
  279. case 'v1_login_page':
  280. switch ($method) {
  281. case 'GET':
  282. $result['status'] = 'success';
  283. $result['statusText'] = 'success';
  284. $result['data'] = $pageLogin;
  285. break;
  286. default:
  287. $result['status'] = 'error';
  288. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  289. break;
  290. }
  291. break;
  292. case 'v1_lockscreen':
  293. switch ($method) {
  294. case 'GET':
  295. $result['status'] = 'success';
  296. $result['statusText'] = 'success';
  297. $result['data'] = $pageLockScreen;
  298. break;
  299. default:
  300. $result['status'] = 'error';
  301. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  302. break;
  303. }
  304. break;
  305. case 'v1_login_log':
  306. switch ($method) {
  307. case 'GET':
  308. if(qualifyRequest(1)){
  309. $result['status'] = 'success';
  310. $result['statusText'] = 'success';
  311. $result['data'] = getLog('loginLog');
  312. }else{
  313. $result['status'] = 'error';
  314. $result['statusText'] = 'API/Token invalid or not set';
  315. $result['data'] = null;
  316. }
  317. break;
  318. default:
  319. $result['status'] = 'error';
  320. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  321. break;
  322. }
  323. break;
  324. case 'v1_organizr_log':
  325. switch ($method) {
  326. case 'GET':
  327. if(qualifyRequest(1)){
  328. $result['status'] = 'success';
  329. $result['statusText'] = 'success';
  330. $result['data'] = getLog('org');
  331. }else{
  332. $result['status'] = 'error';
  333. $result['statusText'] = 'API/Token invalid or not set';
  334. $result['data'] = null;
  335. }
  336. break;
  337. default:
  338. $result['status'] = 'error';
  339. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  340. break;
  341. }
  342. break;
  343. case 'v1_user_list':
  344. switch ($method) {
  345. case 'GET':
  346. if(qualifyRequest(1)){
  347. $result['status'] = 'success';
  348. $result['statusText'] = 'success';
  349. $result['data'] = allUsers();
  350. }else{
  351. $result['status'] = 'error';
  352. $result['statusText'] = 'API/Token invalid or not set';
  353. $result['data'] = null;
  354. }
  355. break;
  356. default:
  357. $result['status'] = 'error';
  358. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  359. break;
  360. }
  361. break;
  362. case 'v1_tab_list':
  363. switch ($method) {
  364. case 'GET':
  365. if(qualifyRequest(1)){
  366. $result['status'] = 'success';
  367. $result['statusText'] = 'success';
  368. $result['data'] = allTabs();
  369. }else{
  370. $result['status'] = 'error';
  371. $result['statusText'] = 'API/Token invalid or not set';
  372. $result['data'] = null;
  373. }
  374. break;
  375. default:
  376. $result['status'] = 'error';
  377. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  378. break;
  379. }
  380. break;
  381. case 'v1_customize_appearance':
  382. switch ($method) {
  383. case 'GET':
  384. if(qualifyRequest(1)){
  385. $result['status'] = 'success';
  386. $result['statusText'] = 'success';
  387. $result['data'] = getCustomizeAppearance();
  388. }else{
  389. $result['status'] = 'error';
  390. $result['statusText'] = 'API/Token invalid or not set';
  391. $result['data'] = null;
  392. }
  393. break;
  394. default:
  395. $result['status'] = 'error';
  396. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  397. break;
  398. }
  399. break;
  400. case 'v1_user_edit':
  401. switch ($method) {
  402. case 'POST':
  403. if(qualifyRequest(1)){
  404. $result['status'] = 'success';
  405. $result['statusText'] = 'success';
  406. $result['data'] = adminEditUser($_POST);
  407. }elseif(qualifyRequest(998)){
  408. $result['status'] = 'success';
  409. $result['statusText'] = 'success';
  410. $result['data'] = editUser($_POST);
  411. }else{
  412. $result['status'] = 'error';
  413. $result['statusText'] = 'API/Token invalid or not set';
  414. $result['data'] = null;
  415. }
  416. break;
  417. default:
  418. $result['status'] = 'error';
  419. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  420. break;
  421. }
  422. break;
  423. case 'v1_logout':
  424. switch ($method) {
  425. case 'GET':
  426. $result['status'] = 'success';
  427. $result['statusText'] = 'success';
  428. $result['data'] = logout();
  429. break;
  430. default:
  431. $result['status'] = 'error';
  432. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  433. break;
  434. }
  435. break;
  436. case 'v1_launch_organizr':
  437. switch ($method) {
  438. case 'GET':
  439. $status = array();
  440. $result['status'] = 'success';
  441. $result['statusText'] = 'success';
  442. $status['status'] = organizrStatus();
  443. $result['appearance'] = loadAppearance();
  444. $status['user'] = $GLOBALS['organizrUser'];
  445. $status['categories'] = loadTabs()['categories'];
  446. $status['tabs'] = loadTabs()['tabs'];
  447. $result['data'] = $status;
  448. $result['branch'] = $GLOBALS['branch'];
  449. break;
  450. default:
  451. $result['status'] = 'error';
  452. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  453. break;
  454. }
  455. break;
  456. case 'v1_auth':
  457. switch ($method) {
  458. case 'GET':
  459. auth();
  460. break;
  461. default:
  462. $result['status'] = 'error';
  463. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  464. break;
  465. }
  466. break;
  467. case 'v1_plugin':
  468. switch ($method) {
  469. case 'GET':
  470. if(qualifyRequest(1)){
  471. $result['status'] = 'success';
  472. $result['statusText'] = 'success';
  473. $result['data'] = 'plugin admin';
  474. }elseif(qualifyRequest(998)){
  475. $result['status'] = 'success';
  476. $result['statusText'] = 'success';
  477. $result['data'] = 'plugin logged in';
  478. }elseif(qualifyRequest(999)){
  479. $result['status'] = 'success';
  480. $result['statusText'] = 'success';
  481. $result['data'] = 'plugin guest';
  482. }else{
  483. $result['status'] = 'error';
  484. $result['statusText'] = 'API/Token invalid or not set';
  485. $result['data'] = null;
  486. }
  487. break;
  488. case 'POST':
  489. if(qualifyRequest(1)){
  490. $result['status'] = 'success';
  491. $result['statusText'] = 'success';
  492. $result['data'] = 'plugin admin';
  493. }elseif(qualifyRequest(998)){
  494. $result['status'] = 'success';
  495. $result['statusText'] = 'success';
  496. $result['data'] = 'plugin logged in';
  497. }elseif(qualifyRequest(999)){
  498. $result['status'] = 'success';
  499. $result['statusText'] = 'success';
  500. $result['data'] = 'plugin guest';
  501. }else{
  502. $result['status'] = 'error';
  503. $result['statusText'] = 'API/Token invalid or not set';
  504. $result['data'] = null;
  505. }
  506. break;
  507. default:
  508. $result['status'] = 'error';
  509. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  510. break;
  511. }
  512. break;
  513. default:
  514. //No Function Available
  515. $result['status'] = 'error';
  516. $result['statusText'] = 'function requested is not defined';
  517. break;
  518. }
  519. //Set Default Result
  520. if(!$result){
  521. $result['status'] = "error";
  522. $result['error'] = "An error has occurred";
  523. }
  524. $result['generationDate'] = $GLOBALS['currentTime'];
  525. $generationTime += microtime(true);
  526. $result['generationTime'] = (sprintf('%f', $generationTime)*1000).'ms';
  527. //return JSON array
  528. exit(json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));