api-functions.php 40 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function apiLogin()
  7. {
  8. $array = array(
  9. 'data' => array(
  10. array(
  11. 'name' => 'username',
  12. 'value' => (isset($_POST['username'])) ? $_POST['username'] : false
  13. ),
  14. array(
  15. 'name' => 'password',
  16. 'value' => (isset($_POST['password'])) ? $_POST['password'] : false
  17. ),
  18. array(
  19. 'name' => 'remember',
  20. 'value' => (isset($_POST['remember'])) ? true : false
  21. ),
  22. array(
  23. 'name' => 'oAuth',
  24. 'value' => (isset($_POST['oAuth'])) ? $_POST['oAuth'] : false
  25. ),
  26. array(
  27. 'name' => 'oAuthType',
  28. 'value' => (isset($_POST['oAuthType'])) ? $_POST['oAuthType'] : false
  29. ),
  30. array(
  31. 'name' => 'tfaCode',
  32. 'value' => (isset($_POST['tfaCode'])) ? $_POST['tfaCode'] : false
  33. ),
  34. array(
  35. 'name' => 'loginAttempts',
  36. 'value' => (isset($_POST['loginAttempts'])) ? $_POST['loginAttempts'] : false
  37. ),
  38. array(
  39. 'name' => 'output',
  40. 'value' => true
  41. ),
  42. )
  43. );
  44. foreach ($array['data'] as $items) {
  45. foreach ($items as $key => $value) {
  46. if ($key == 'name') {
  47. $newKey = $value;
  48. }
  49. if ($key == 'value') {
  50. $newValue = $value;
  51. }
  52. if (isset($newKey) && isset($newValue)) {
  53. $$newKey = $newValue;
  54. }
  55. }
  56. }
  57. return login($array);
  58. }
  59. function login($array)
  60. {
  61. // Grab username and Password from login form
  62. $username = $password = $oAuth = $oAuthType = '';
  63. foreach ($array['data'] as $items) {
  64. foreach ($items as $key => $value) {
  65. if ($key == 'name') {
  66. $newKey = $value;
  67. }
  68. if ($key == 'value') {
  69. $newValue = $value;
  70. }
  71. if (isset($newKey) && isset($newValue)) {
  72. $$newKey = $newValue;
  73. }
  74. }
  75. }
  76. $username = (strpos($GLOBALS['authBackend'], 'emby') !== false) ? $username : strtolower($username);
  77. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  78. $oAuth = (isset($oAuth)) ? $oAuth : false;
  79. $output = (isset($output)) ? $output : false;
  80. $loginAttempts = (isset($loginAttempts)) ? $loginAttempts : false;
  81. if($loginAttempts > $GLOBALS['loginAttempts'] || isset($_COOKIE['lockout'])){
  82. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  83. return 'lockout';
  84. }
  85. try {
  86. $database = new Dibi\Connection([
  87. 'driver' => 'sqlite3',
  88. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  89. ]);
  90. $authSuccess = false;
  91. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  92. if (!$oAuth) {
  93. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  94. switch ($GLOBALS['authType']) {
  95. case 'external':
  96. if (function_exists($function)) {
  97. $authSuccess = $function($username, $password);
  98. }
  99. break;
  100. /** @noinspection PhpMissingBreakStatementInspection */
  101. case 'both':
  102. if (function_exists($function)) {
  103. $authSuccess = $function($username, $password);
  104. }
  105. // no break
  106. default: // Internal
  107. if (!$authSuccess) {
  108. // perform the internal authentication step
  109. if (password_verify($password, $result['password'])) {
  110. $authSuccess = true;
  111. }
  112. }
  113. }
  114. } else {
  115. // Has oAuth Token!
  116. switch ($oAuthType) {
  117. case 'plex':
  118. if ($GLOBALS['plexoAuth']) {
  119. $tokenInfo = checkPlexToken($oAuth);
  120. if ($tokenInfo) {
  121. $authSuccess = array(
  122. 'username' => $tokenInfo['user']['username'],
  123. 'email' => $tokenInfo['user']['email'],
  124. 'image' => $tokenInfo['user']['thumb'],
  125. 'token' => $tokenInfo['user']['authToken']
  126. );
  127. coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
  128. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || (!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['email'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  129. }
  130. }
  131. break;
  132. default:
  133. return ($output) ? 'No oAuthType defined' : 'error';
  134. break;
  135. }
  136. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  137. }
  138. if ($authSuccess) {
  139. // Make sure user exists in database
  140. $userExists = false;
  141. $passwordMatches = ($oAuth) ? true : false;
  142. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  143. if ($result['username']) {
  144. $userExists = true;
  145. $username = $result['username'];
  146. if ($passwordMatches == false) {
  147. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  148. }
  149. }
  150. if ($userExists) {
  151. //does org password need to be updated
  152. if (!$passwordMatches) {
  153. $database->query('
  154. UPDATE users SET', [
  155. 'password' => password_hash($password, PASSWORD_BCRYPT)
  156. ], '
  157. WHERE id=?', $result['id']);
  158. writeLog('success', 'Login Function - User Password updated from backend', $username);
  159. }
  160. if ($token !== '') {
  161. if ($token !== $result['plex_token']) {
  162. $database->query('
  163. UPDATE users SET', [
  164. 'plex_token' => $token
  165. ], '
  166. WHERE id=?', $result['id']);
  167. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  168. }
  169. }
  170. // 2FA might go here
  171. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  172. $TFA = explode('::', $result['auth_service']);
  173. // Is code with login info?
  174. if ($tfaCode == '') {
  175. return '2FA';
  176. } else {
  177. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  178. writeLoginLog($username, 'error');
  179. writeLog('error', 'Login Function - Wrong 2FA', $username);
  180. return '2FA-incorrect';
  181. }
  182. }
  183. }
  184. // End 2FA
  185. // authentication passed - 1) mark active and update token
  186. $createToken = createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days);
  187. if ($createToken) {
  188. writeLoginLog($username, 'success');
  189. writeLog('success', 'Login Function - A User has logged in', $username);
  190. $ssoUser = (empty($result['email'])) ? $result['username'] : (strpos($result['email'], 'placeholder') !== false) ? $result['username'] : $result['email'];
  191. ssoCheck($ssoUser, $password, $token); //need to work on this
  192. return ($output) ? array('name' => $GLOBALS['cookieName'], 'token' => (string)$createToken) : true;
  193. } else {
  194. return 'Token Creation Error';
  195. }
  196. } else {
  197. // Create User
  198. //ssoCheck($username, $password, $token);
  199. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  200. }
  201. } else {
  202. // authentication failed
  203. writeLoginLog($username, 'error');
  204. writeLog('error', 'Login Function - Wrong Password', $username);
  205. if($loginAttempts >= $GLOBALS['loginAttempts']){
  206. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  207. return 'lockout';
  208. }else{
  209. return 'mismatch';
  210. }
  211. }
  212. } catch (Dibi\Exception $e) {
  213. return $e;
  214. }
  215. }
  216. function createDB($path, $filename)
  217. {
  218. try {
  219. if (!file_exists($path)) {
  220. mkdir($path, 0777, true);
  221. }
  222. $createDB = new Dibi\Connection([
  223. 'driver' => 'sqlite3',
  224. 'database' => $path . $filename,
  225. ]);
  226. // Create Users
  227. $createDB->query('CREATE TABLE `users` (
  228. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  229. `username` TEXT UNIQUE,
  230. `password` TEXT,
  231. `email` TEXT,
  232. `plex_token` TEXT,
  233. `group` TEXT,
  234. `group_id` INTEGER,
  235. `locked` INTEGER,
  236. `image` TEXT,
  237. `register_date` DATE,
  238. `auth_service` TEXT DEFAULT \'internal\'
  239. );');
  240. // Create Tokens
  241. $createDB->query('CREATE TABLE `chatroom` (
  242. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  243. `username` TEXT,
  244. `gravatar` TEXT,
  245. `uid` TEXT,
  246. `date` DATE,
  247. `ip` TEXT,
  248. `message` TEXT
  249. );');
  250. $createDB->query('CREATE TABLE `tokens` (
  251. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  252. `token` TEXT UNIQUE,
  253. `user_id` INTEGER,
  254. `browser` TEXT,
  255. `ip` TEXT,
  256. `created` DATE,
  257. `expires` DATE
  258. );');
  259. $createDB->query('CREATE TABLE `groups` (
  260. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  261. `group` TEXT UNIQUE,
  262. `group_id` INTEGER,
  263. `image` TEXT,
  264. `default` INTEGER
  265. );');
  266. $createDB->query('CREATE TABLE `categories` (
  267. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  268. `order` INTEGER,
  269. `category` TEXT UNIQUE,
  270. `category_id` INTEGER,
  271. `image` TEXT,
  272. `default` INTEGER
  273. );');
  274. // Create Tabs
  275. $createDB->query('CREATE TABLE `tabs` (
  276. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  277. `order` INTEGER,
  278. `category_id` INTEGER,
  279. `name` TEXT,
  280. `url` TEXT,
  281. `url_local` TEXT,
  282. `default` INTEGER,
  283. `enabled` INTEGER,
  284. `group_id` INTEGER,
  285. `image` TEXT,
  286. `type` INTEGER,
  287. `splash` INTEGER,
  288. `ping` INTEGER,
  289. `ping_url` TEXT,
  290. `timeout` INTEGER,
  291. `timeout_ms` INTEGER,
  292. `preload` INTEGER
  293. );');
  294. // Create Options
  295. $createDB->query('CREATE TABLE `options` (
  296. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  297. `name` TEXT UNIQUE,
  298. `value` TEXT
  299. );');
  300. // Create Invites
  301. $createDB->query('CREATE TABLE `invites` (
  302. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  303. `code` TEXT UNIQUE,
  304. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  305. `email` TEXT,
  306. `username` TEXT,
  307. `dateused` TIMESTAMP,
  308. `usedby` TEXT,
  309. `ip` TEXT,
  310. `valid` TEXT,
  311. `type` TEXT
  312. );');
  313. return true;
  314. } catch (Dibi\Exception $e) {
  315. return false;
  316. }
  317. }
  318. // Upgrade Database
  319. function updateDB($oldVerNum = false)
  320. {
  321. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  322. if (!file_exists($tempLock)) {
  323. touch($tempLock);
  324. // Create Temp DB First
  325. $migrationDB = 'tempMigration.db';
  326. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  327. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  328. unlink($GLOBALS['dbLocation'] . $migrationDB);
  329. }
  330. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  331. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  332. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  333. if ($success) {
  334. try {
  335. $connectOldDB = new Dibi\Connection([
  336. 'driver' => 'sqlite3',
  337. 'database' => $backupDB,
  338. ]);
  339. $connectNewDB = new Dibi\Connection([
  340. 'driver' => 'sqlite3',
  341. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  342. ]);
  343. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  344. foreach ($tables as $table) {
  345. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  346. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  347. foreach ($data as $row) {
  348. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  349. }
  350. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  351. }
  352. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  353. $connectOldDB->disconnect();
  354. $connectNewDB->disconnect();
  355. // Remove Current Database
  356. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  357. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  358. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  359. if ($newFileSize > 0) {
  360. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  361. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  362. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  363. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  364. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  365. @unlink($tempLock);
  366. return true;
  367. }
  368. }
  369. @unlink($tempLock);
  370. return false;
  371. } catch (Dibi\Exception $e) {
  372. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  373. @unlink($tempLock);
  374. return false;
  375. }
  376. }
  377. @unlink($tempLock);
  378. return false;
  379. }
  380. return false;
  381. }
  382. function createFirstAdmin($path, $filename, $username, $password, $email)
  383. {
  384. try {
  385. $createDB = new Dibi\Connection([
  386. 'driver' => 'sqlite3',
  387. 'database' => $path . $filename,
  388. ]);
  389. $userInfo = [
  390. 'username' => $username,
  391. 'password' => password_hash($password, PASSWORD_BCRYPT),
  392. 'email' => $email,
  393. 'group' => 'Admin',
  394. 'group_id' => 0,
  395. 'image' => gravatar($email),
  396. 'register_date' => $GLOBALS['currentTime'],
  397. ];
  398. $groupInfo0 = [
  399. 'group' => 'Admin',
  400. 'group_id' => 0,
  401. 'default' => false,
  402. 'image' => 'plugins/images/groups/admin.png',
  403. ];
  404. $groupInfo1 = [
  405. 'group' => 'Co-Admin',
  406. 'group_id' => 1,
  407. 'default' => false,
  408. 'image' => 'plugins/images/groups/coadmin.png',
  409. ];
  410. $groupInfo2 = [
  411. 'group' => 'Super User',
  412. 'group_id' => 2,
  413. 'default' => false,
  414. 'image' => 'plugins/images/groups/superuser.png',
  415. ];
  416. $groupInfo3 = [
  417. 'group' => 'Power User',
  418. 'group_id' => 3,
  419. 'default' => false,
  420. 'image' => 'plugins/images/groups/poweruser.png',
  421. ];
  422. $groupInfo4 = [
  423. 'group' => 'User',
  424. 'group_id' => 4,
  425. 'default' => true,
  426. 'image' => 'plugins/images/groups/user.png',
  427. ];
  428. $groupInfoGuest = [
  429. 'group' => 'Guest',
  430. 'group_id' => 999,
  431. 'default' => false,
  432. 'image' => 'plugins/images/groups/guest.png',
  433. ];
  434. $settingsInfo = [
  435. 'order' => 1,
  436. 'category_id' => 0,
  437. 'name' => 'Settings',
  438. 'url' => 'api/?v1/settings/page',
  439. 'default' => false,
  440. 'enabled' => true,
  441. 'group_id' => 1,
  442. 'image' => 'fontawesome::cog',
  443. 'type' => 0
  444. ];
  445. $homepageInfo = [
  446. 'order' => 2,
  447. 'category_id' => 0,
  448. 'name' => 'Homepage',
  449. 'url' => 'api/?v1/homepage/page',
  450. 'default' => false,
  451. 'enabled' => false,
  452. 'group_id' => 4,
  453. 'image' => 'fontawesome::home',
  454. 'type' => 0
  455. ];
  456. $unsortedInfo = [
  457. 'order' => 1,
  458. 'category' => 'Unsorted',
  459. 'category_id' => 0,
  460. 'image' => 'plugins/images/categories/unsorted.png',
  461. 'default' => true
  462. ];
  463. $createDB->query('INSERT INTO [users]', $userInfo);
  464. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  465. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  466. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  467. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  468. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  469. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  470. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  471. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  472. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  473. return true;
  474. } catch (Dibi\Exception $e) {
  475. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  476. return false;
  477. }
  478. }
  479. function defaultUserGroup()
  480. {
  481. try {
  482. $connect = new Dibi\Connection([
  483. 'driver' => 'sqlite3',
  484. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  485. ]);
  486. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  487. return $all;
  488. } catch (Dibi\Exception $e) {
  489. return false;
  490. }
  491. }
  492. function defaultTabCategory()
  493. {
  494. try {
  495. $connect = new Dibi\Connection([
  496. 'driver' => 'sqlite3',
  497. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  498. ]);
  499. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  500. return $all;
  501. } catch (Dibi\Exception $e) {
  502. return false;
  503. }
  504. }
  505. function getGuest()
  506. {
  507. if (isset($GLOBALS['dbLocation'])) {
  508. try {
  509. $connect = new Dibi\Connection([
  510. 'driver' => 'sqlite3',
  511. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  512. ]);
  513. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  514. return $all;
  515. } catch (Dibi\Exception $e) {
  516. return false;
  517. }
  518. } else {
  519. return array(
  520. 'group' => 'Guest',
  521. 'group_id' => 999,
  522. 'image' => 'plugins/images/groups/guest.png'
  523. );
  524. }
  525. }
  526. function adminEditGroup($array)
  527. {
  528. switch ($array['data']['action']) {
  529. case 'changeDefaultGroup':
  530. try {
  531. $connect = new Dibi\Connection([
  532. 'driver' => 'sqlite3',
  533. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  534. ]);
  535. $connect->query('UPDATE groups SET `default` = 0');
  536. $connect->query('
  537. UPDATE groups SET', [
  538. 'default' => 1
  539. ], '
  540. WHERE id=?', $array['data']['id']);
  541. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  542. return true;
  543. } catch (Dibi\Exception $e) {
  544. return false;
  545. }
  546. break;
  547. case 'deleteUserGroup':
  548. try {
  549. $connect = new Dibi\Connection([
  550. 'driver' => 'sqlite3',
  551. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  552. ]);
  553. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  554. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  555. return true;
  556. } catch (Dibi\Exception $e) {
  557. return false;
  558. }
  559. break;
  560. case 'addUserGroup':
  561. try {
  562. $connect = new Dibi\Connection([
  563. 'driver' => 'sqlite3',
  564. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  565. ]);
  566. $newGroup = [
  567. 'group' => $array['data']['newGroupName'],
  568. 'group_id' => $array['data']['newGroupID'],
  569. 'default' => false,
  570. 'image' => $array['data']['newGroupImage'],
  571. ];
  572. $connect->query('INSERT INTO [groups]', $newGroup);
  573. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  574. return true;
  575. } catch (Dibi\Exception $e) {
  576. return false;
  577. }
  578. break;
  579. case 'editUserGroup':
  580. try {
  581. $connect = new Dibi\Connection([
  582. 'driver' => 'sqlite3',
  583. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  584. ]);
  585. $connect->query('
  586. UPDATE groups SET', [
  587. 'group' => $array['data']['groupName'],
  588. 'image' => $array['data']['groupImage'],
  589. ], '
  590. WHERE id=?', $array['data']['id']);
  591. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  592. return true;
  593. } catch (Dibi\Exception $e) {
  594. return false;
  595. }
  596. break;
  597. default:
  598. return false;
  599. break;
  600. }
  601. }
  602. function adminEditUser($array)
  603. {
  604. switch ($array['data']['action']) {
  605. case 'changeGroup':
  606. if ($array['data']['newGroupID'] == 0) {
  607. return false;
  608. }
  609. try {
  610. $connect = new Dibi\Connection([
  611. 'driver' => 'sqlite3',
  612. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  613. ]);
  614. $connect->query('
  615. UPDATE users SET', [
  616. 'group' => $array['data']['newGroupName'],
  617. 'group_id' => $array['data']['newGroupID'],
  618. ], '
  619. WHERE id=?', $array['data']['id']);
  620. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  621. return true;
  622. } catch (Dibi\Exception $e) {
  623. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  624. return false;
  625. }
  626. break;
  627. case 'editUser':
  628. try {
  629. $connect = new Dibi\Connection([
  630. 'driver' => 'sqlite3',
  631. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  632. ]);
  633. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  634. $connect->query('
  635. UPDATE users SET', [
  636. 'username' => $array['data']['username'],
  637. 'email' => $array['data']['email'],
  638. 'image' => gravatar($array['data']['email']),
  639. ], '
  640. WHERE id=?', $array['data']['id']);
  641. if (!empty($array['data']['password'])) {
  642. $connect->query('
  643. UPDATE users SET', [
  644. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  645. ], '
  646. WHERE id=?', $array['data']['id']);
  647. }
  648. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  649. return true;
  650. } else {
  651. return false;
  652. }
  653. } catch (Dibi\Exception $e) {
  654. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  655. return false;
  656. }
  657. break;
  658. case 'addNewUser':
  659. $defaults = defaultUserGroup();
  660. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  661. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  662. return true;
  663. } else {
  664. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  665. return 'username taken';
  666. }
  667. break;
  668. case 'deleteUser':
  669. try {
  670. $connect = new Dibi\Connection([
  671. 'driver' => 'sqlite3',
  672. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  673. ]);
  674. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  675. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  676. return true;
  677. } catch (Dibi\Exception $e) {
  678. return false;
  679. }
  680. break;
  681. default:
  682. return false;
  683. break;
  684. }
  685. }
  686. function editTabs($array)
  687. {
  688. switch ($array['data']['action']) {
  689. case 'changeGroup':
  690. try {
  691. $connect = new Dibi\Connection([
  692. 'driver' => 'sqlite3',
  693. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  694. ]);
  695. $connect->query('
  696. UPDATE tabs SET', [
  697. 'group_id' => $array['data']['newGroupID'],
  698. ], '
  699. WHERE id=?', $array['data']['id']);
  700. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  701. return true;
  702. } catch (Dibi\Exception $e) {
  703. return false;
  704. }
  705. break;
  706. case 'changeCategory':
  707. try {
  708. $connect = new Dibi\Connection([
  709. 'driver' => 'sqlite3',
  710. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  711. ]);
  712. $connect->query('
  713. UPDATE tabs SET', [
  714. 'category_id' => $array['data']['newCategoryID'],
  715. ], '
  716. WHERE id=?', $array['data']['id']);
  717. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  718. return true;
  719. } catch (Dibi\Exception $e) {
  720. return false;
  721. }
  722. break;
  723. case 'changeType':
  724. try {
  725. $connect = new Dibi\Connection([
  726. 'driver' => 'sqlite3',
  727. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  728. ]);
  729. $connect->query('
  730. UPDATE tabs SET', [
  731. 'type' => $array['data']['newTypeID'],
  732. ], '
  733. WHERE id=?', $array['data']['id']);
  734. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  735. return true;
  736. } catch (Dibi\Exception $e) {
  737. return false;
  738. }
  739. break;
  740. case 'changeEnabled':
  741. try {
  742. $connect = new Dibi\Connection([
  743. 'driver' => 'sqlite3',
  744. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  745. ]);
  746. $connect->query('
  747. UPDATE tabs SET', [
  748. 'enabled' => $array['data']['tabEnabled'],
  749. ], '
  750. WHERE id=?', $array['data']['id']);
  751. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  752. return true;
  753. } catch (Dibi\Exception $e) {
  754. return false;
  755. }
  756. break;
  757. case 'changeSplash':
  758. try {
  759. $connect = new Dibi\Connection([
  760. 'driver' => 'sqlite3',
  761. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  762. ]);
  763. $connect->query('
  764. UPDATE tabs SET', [
  765. 'splash' => $array['data']['tabSplash'],
  766. ], '
  767. WHERE id=?', $array['data']['id']);
  768. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  769. return true;
  770. } catch (Dibi\Exception $e) {
  771. return false;
  772. }
  773. break;
  774. case 'changePing':
  775. try {
  776. $connect = new Dibi\Connection([
  777. 'driver' => 'sqlite3',
  778. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  779. ]);
  780. $connect->query('
  781. UPDATE tabs SET', [
  782. 'ping' => $array['data']['tabPing'],
  783. ], '
  784. WHERE id=?', $array['data']['id']);
  785. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  786. return true;
  787. } catch (Dibi\Exception $e) {
  788. return false;
  789. }
  790. break;
  791. case 'changePreload':
  792. try {
  793. $connect = new Dibi\Connection([
  794. 'driver' => 'sqlite3',
  795. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  796. ]);
  797. $connect->query('
  798. UPDATE tabs SET', [
  799. 'preload' => $array['data']['tabPreload'],
  800. ], '
  801. WHERE id=?', $array['data']['id']);
  802. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s preload status was changed to [' . $array['data']['tabPreloadWord'] . ']', $GLOBALS['organizrUser']['username']);
  803. return true;
  804. } catch (Dibi\Exception $e) {
  805. return false;
  806. }
  807. break;
  808. case 'changeDefault':
  809. try {
  810. $connect = new Dibi\Connection([
  811. 'driver' => 'sqlite3',
  812. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  813. ]);
  814. $connect->query('UPDATE tabs SET `default` = 0');
  815. $connect->query('
  816. UPDATE tabs SET', [
  817. 'default' => 1
  818. ], '
  819. WHERE id=?', $array['data']['id']);
  820. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  821. return true;
  822. } catch (Dibi\Exception $e) {
  823. return false;
  824. }
  825. break;
  826. case 'deleteTab':
  827. try {
  828. $connect = new Dibi\Connection([
  829. 'driver' => 'sqlite3',
  830. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  831. ]);
  832. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  833. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  834. return true;
  835. } catch (Dibi\Exception $e) {
  836. return false;
  837. }
  838. break;
  839. case 'editTab':
  840. try {
  841. $connect = new Dibi\Connection([
  842. 'driver' => 'sqlite3',
  843. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  844. ]);
  845. $connect->query('
  846. UPDATE tabs SET', [
  847. 'name' => $array['data']['tabName'],
  848. 'url' => $array['data']['tabURL'],
  849. 'url_local' => $array['data']['tabLocalURL'],
  850. 'ping_url' => $array['data']['pingURL'],
  851. 'image' => $array['data']['tabImage'],
  852. 'timeout' => $array['data']['tabActionType'],
  853. 'timeout_ms' => $array['data']['tabActionTime'],
  854. ], '
  855. WHERE id=?', $array['data']['id']);
  856. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  857. return true;
  858. } catch (Dibi\Exception $e) {
  859. return false;
  860. }
  861. case 'changeOrder':
  862. try {
  863. $connect = new Dibi\Connection([
  864. 'driver' => 'sqlite3',
  865. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  866. ]);
  867. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  868. if ($value['order'] != $value['originalOrder']) {
  869. $connect->query('
  870. UPDATE tabs SET', [
  871. 'order' => $value['order'],
  872. ], '
  873. WHERE id=?', $value['id']);
  874. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  875. }
  876. }
  877. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  878. return true;
  879. } catch (Dibi\Exception $e) {
  880. return false;
  881. }
  882. break;
  883. case 'addNewTab':
  884. try {
  885. $default = defaultTabCategory()['category_id'];
  886. $connect = new Dibi\Connection([
  887. 'driver' => 'sqlite3',
  888. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  889. ]);
  890. $newTab = [
  891. 'order' => $array['data']['tabOrder'],
  892. 'category_id' => $default,
  893. 'name' => $array['data']['tabName'],
  894. 'url' => $array['data']['tabURL'],
  895. 'url_local' => $array['data']['tabLocalURL'],
  896. 'ping_url' => $array['data']['pingURL'],
  897. 'default' => $array['data']['tabDefault'],
  898. 'enabled' => 1,
  899. 'group_id' => $array['data']['tabGroupID'],
  900. 'image' => $array['data']['tabImage'],
  901. 'type' => $array['data']['tabType'],
  902. 'timeout' => $array['data']['tabActionType'],
  903. 'timeout_ms' => $array['data']['tabActionTime'],
  904. ];
  905. $connect->query('INSERT INTO [tabs]', $newTab);
  906. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  907. return true;
  908. } catch (Dibi\Exception $e) {
  909. return false;
  910. }
  911. break;
  912. default:
  913. return false;
  914. break;
  915. }
  916. }
  917. function editCategories($array)
  918. {
  919. switch ($array['data']['action']) {
  920. case 'changeDefault':
  921. try {
  922. $connect = new Dibi\Connection([
  923. 'driver' => 'sqlite3',
  924. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  925. ]);
  926. $connect->query('UPDATE categories SET `default` = 0');
  927. $connect->query('
  928. UPDATE categories SET', [
  929. 'default' => 1
  930. ], '
  931. WHERE id=?', $array['data']['id']);
  932. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  933. return true;
  934. } catch (Dibi\Exception $e) {
  935. return false;
  936. }
  937. break;
  938. case 'deleteCategory':
  939. try {
  940. $connect = new Dibi\Connection([
  941. 'driver' => 'sqlite3',
  942. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  943. ]);
  944. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  945. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  946. return true;
  947. } catch (Dibi\Exception $e) {
  948. return false;
  949. }
  950. break;
  951. case 'addNewCategory':
  952. try {
  953. $connect = new Dibi\Connection([
  954. 'driver' => 'sqlite3',
  955. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  956. ]);
  957. $newCategory = [
  958. 'category' => $array['data']['categoryName'],
  959. 'order' => $array['data']['categoryOrder'],
  960. 'category_id' => $array['data']['categoryID'],
  961. 'default' => false,
  962. 'image' => $array['data']['categoryImage'],
  963. ];
  964. $connect->query('INSERT INTO [categories]', $newCategory);
  965. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  966. return true;
  967. } catch (Dibi\Exception $e) {
  968. return $e;
  969. }
  970. break;
  971. case 'editCategory':
  972. try {
  973. $connect = new Dibi\Connection([
  974. 'driver' => 'sqlite3',
  975. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  976. ]);
  977. $connect->query('
  978. UPDATE categories SET', [
  979. 'category' => $array['data']['name'],
  980. 'image' => $array['data']['image'],
  981. ], '
  982. WHERE id=?', $array['data']['id']);
  983. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  984. return true;
  985. } catch (Dibi\Exception $e) {
  986. return false;
  987. }
  988. break;
  989. case 'changeOrder':
  990. try {
  991. $connect = new Dibi\Connection([
  992. 'driver' => 'sqlite3',
  993. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  994. ]);
  995. foreach ($array['data']['categories']['category'] as $key => $value) {
  996. if ($value['order'] != $value['originalOrder']) {
  997. $connect->query('
  998. UPDATE categories SET', [
  999. 'order' => $value['order'],
  1000. ], '
  1001. WHERE id=?', $value['id']);
  1002. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  1003. }
  1004. }
  1005. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  1006. return true;
  1007. } catch (Dibi\Exception $e) {
  1008. return false;
  1009. }
  1010. break;
  1011. default:
  1012. return false;
  1013. break;
  1014. }
  1015. }
  1016. function allUsers()
  1017. {
  1018. try {
  1019. $connect = new Dibi\Connection([
  1020. 'driver' => 'sqlite3',
  1021. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1022. ]);
  1023. $users = $connect->fetchAll('SELECT * FROM users');
  1024. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  1025. foreach ($users as $k => $v) {
  1026. // clear password from array
  1027. unset($users[$k]['password']);
  1028. }
  1029. $all['users'] = $users;
  1030. $all['groups'] = $groups;
  1031. return $all;
  1032. } catch (Dibi\Exception $e) {
  1033. return false;
  1034. }
  1035. }
  1036. function usernameTaken($username, $email)
  1037. {
  1038. try {
  1039. $connect = new Dibi\Connection([
  1040. 'driver' => 'sqlite3',
  1041. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1042. ]);
  1043. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  1044. return ($all) ? true : false;
  1045. } catch (Dibi\Exception $e) {
  1046. return false;
  1047. }
  1048. }
  1049. function usernameTakenExcept($username, $email, $id)
  1050. {
  1051. try {
  1052. $connect = new Dibi\Connection([
  1053. 'driver' => 'sqlite3',
  1054. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1055. ]);
  1056. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  1057. return ($all) ? true : false;
  1058. } catch (Dibi\Exception $e) {
  1059. return false;
  1060. }
  1061. }
  1062. function createUser($username, $password, $defaults, $email = null)
  1063. {
  1064. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  1065. try {
  1066. if (!usernameTaken($username, $email)) {
  1067. $createDB = new Dibi\Connection([
  1068. 'driver' => 'sqlite3',
  1069. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1070. ]);
  1071. $userInfo = [
  1072. 'username' => $username,
  1073. 'password' => password_hash($password, PASSWORD_BCRYPT),
  1074. 'email' => $email,
  1075. 'group' => $defaults['group'],
  1076. 'group_id' => $defaults['group_id'],
  1077. 'image' => gravatar($email),
  1078. 'register_date' => $GLOBALS['currentTime'],
  1079. ];
  1080. $createDB->query('INSERT INTO [users]', $userInfo);
  1081. return true;
  1082. } else {
  1083. return false;
  1084. }
  1085. } catch (Dibi\Exception $e) {
  1086. return false;
  1087. }
  1088. }
  1089. function importUsers($array)
  1090. {
  1091. $imported = 0;
  1092. $defaults = defaultUserGroup();
  1093. foreach ($array as $user) {
  1094. $password = random_ascii_string(30);
  1095. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1096. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1097. if (!$newUser) {
  1098. writeLog('error', 'Import Function - Error', $user['username']);
  1099. } else {
  1100. $imported++;
  1101. }
  1102. }
  1103. }
  1104. return $imported;
  1105. }
  1106. function importUsersType($array)
  1107. {
  1108. $type = $array['data']['type'];
  1109. if ($type !== '') {
  1110. switch ($type) {
  1111. case 'plex':
  1112. return importUsers(allPlexUsers(true));
  1113. break;
  1114. default:
  1115. return false;
  1116. }
  1117. }
  1118. return false;
  1119. }
  1120. function allTabs()
  1121. {
  1122. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1123. try {
  1124. $connect = new Dibi\Connection([
  1125. 'driver' => 'sqlite3',
  1126. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1127. ]);
  1128. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1129. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1130. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1131. return $all;
  1132. } catch (Dibi\Exception $e) {
  1133. return false;
  1134. }
  1135. }
  1136. return false;
  1137. }
  1138. function allGroups()
  1139. {
  1140. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1141. try {
  1142. $connect = new Dibi\Connection([
  1143. 'driver' => 'sqlite3',
  1144. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1145. ]);
  1146. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1147. return $all;
  1148. } catch (Dibi\Exception $e) {
  1149. return false;
  1150. }
  1151. }
  1152. return false;
  1153. }
  1154. function loadTabs()
  1155. {
  1156. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1157. try {
  1158. $connect = new Dibi\Connection([
  1159. 'driver' => 'sqlite3',
  1160. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1161. ]);
  1162. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1163. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1164. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1165. $all['tabs'] = $tabs;
  1166. foreach ($tabs as $k => $v) {
  1167. $v['access_url'] = (!empty($v['url_local']) && ($v['url_local'] !== null) && ($v['url_local'] !== 'null') && isLocal() && $v['type'] !== 0) ? $v['url_local'] : $v['url'];
  1168. }
  1169. $count = array_map(function ($element) {
  1170. return $element['category_id'];
  1171. }, $tabs);
  1172. $count = (array_count_values($count));
  1173. foreach ($categories as $k => $v) {
  1174. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1175. }
  1176. $all['categories'] = $categories;
  1177. return $all;
  1178. } catch (Dibi\Exception $e) {
  1179. return false;
  1180. }
  1181. }
  1182. return false;
  1183. }
  1184. function getActiveTokens()
  1185. {
  1186. try {
  1187. $connect = new Dibi\Connection([
  1188. 'driver' => 'sqlite3',
  1189. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1190. ]);
  1191. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1192. return $all;
  1193. } catch (Dibi\Exception $e) {
  1194. return false;
  1195. }
  1196. }
  1197. function revokeToken($array)
  1198. {
  1199. if ($array['data']['token']) {
  1200. try {
  1201. $connect = new Dibi\Connection([
  1202. 'driver' => 'sqlite3',
  1203. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1204. ]);
  1205. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1206. return true;
  1207. } catch (Dibi\Exception $e) {
  1208. return false;
  1209. }
  1210. }
  1211. }
  1212. function getSchema()
  1213. {
  1214. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1215. try {
  1216. $connect = new Dibi\Connection([
  1217. 'driver' => 'sqlite3',
  1218. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1219. ]);
  1220. $result = $connect->fetchAll(' SELECT name, sql FROM sqlite_master WHERE type=\'table\' ORDER BY name');
  1221. return $result;
  1222. } catch (Dibi\Exception $e) {
  1223. return false;
  1224. }
  1225. } else {
  1226. return 'DB not set yet...';
  1227. }
  1228. }