api-functions.php 36 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = $oAuth = $oAuthType = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  25. $oAuth = (isset($oAuth)) ? $oAuth : false;
  26. try {
  27. $database = new Dibi\Connection([
  28. 'driver' => 'sqlite3',
  29. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  30. ]);
  31. $authSuccess = false;
  32. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  33. if (!$oAuth) {
  34. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  35. switch ($GLOBALS['authType']) {
  36. case 'external':
  37. if (function_exists($function)) {
  38. $authSuccess = $function($username, $password);
  39. }
  40. break;
  41. /** @noinspection PhpMissingBreakStatementInspection */
  42. case 'both':
  43. if (function_exists($function)) {
  44. $authSuccess = $function($username, $password);
  45. }
  46. // no break
  47. default: // Internal
  48. if (!$authSuccess) {
  49. // perform the internal authentication step
  50. if (password_verify($password, $result['password'])) {
  51. $authSuccess = true;
  52. }
  53. }
  54. }
  55. } else {
  56. // Has oAuth Token!
  57. switch ($oAuthType) {
  58. case 'plex':
  59. if ($GLOBALS['plexoAuth']) {
  60. $tokenInfo = checkPlexToken($oAuth);
  61. if ($tokenInfo) {
  62. $authSuccess = array(
  63. 'username' => $tokenInfo['user']['username'],
  64. 'email' => $tokenInfo['user']['email'],
  65. 'image' => $tokenInfo['user']['thumb'],
  66. 'token' => $tokenInfo['user']['authToken']
  67. );
  68. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  69. }
  70. }
  71. break;
  72. default:
  73. return 'error';
  74. break;
  75. }
  76. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  77. }
  78. if ($authSuccess) {
  79. // Make sure user exists in database
  80. $userExists = false;
  81. $passwordMatches = ($oAuth) ? true : false;
  82. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  83. if ($result['username']) {
  84. $userExists = true;
  85. $username = $result['username'];
  86. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  87. }
  88. if ($userExists) {
  89. //does org password need to be updated
  90. if (!$passwordMatches) {
  91. $database->query('
  92. UPDATE users SET', [
  93. 'password' => password_hash($password, PASSWORD_BCRYPT)
  94. ], '
  95. WHERE id=?', $result['id']);
  96. writeLog('success', 'Login Function - User Password updated from backend', $username);
  97. }
  98. if ($token !== '') {
  99. if ($token !== $result['plex_token']) {
  100. $database->query('
  101. UPDATE users SET', [
  102. 'plex_token' => $token
  103. ], '
  104. WHERE id=?', $result['id']);
  105. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  106. }
  107. }
  108. // 2FA might go here
  109. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  110. $TFA = explode('::', $result['auth_service']);
  111. // Is code with login info?
  112. if ($tfaCode == '') {
  113. return '2FA';
  114. } else {
  115. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  116. writeLoginLog($username, 'error');
  117. writeLog('error', 'Login Function - Wrong 2FA', $username);
  118. return '2FA-incorrect';
  119. }
  120. }
  121. }
  122. // End 2FA
  123. // authentication passed - 1) mark active and update token
  124. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  125. writeLoginLog($username, 'success');
  126. writeLog('success', 'Login Function - A User has logged in', $username);
  127. ssoCheck($username, $password, $token); //need to work on this
  128. return true;
  129. } else {
  130. return 'error';
  131. }
  132. } else {
  133. // Create User
  134. //ssoCheck($username, $password, $token);
  135. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  136. }
  137. } else {
  138. // authentication failed
  139. writeLoginLog($username, 'error');
  140. writeLog('error', 'Login Function - Wrong Password', $username);
  141. return 'mismatch';
  142. }
  143. } catch (Dibi\Exception $e) {
  144. return $e;
  145. }
  146. }
  147. function createDB($path, $filename)
  148. {
  149. try {
  150. if (!file_exists($path)) {
  151. mkdir($path, 0777, true);
  152. }
  153. $createDB = new Dibi\Connection([
  154. 'driver' => 'sqlite3',
  155. 'database' => $path . $filename,
  156. ]);
  157. // Create Users
  158. $createDB->query('CREATE TABLE `users` (
  159. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  160. `username` TEXT UNIQUE,
  161. `password` TEXT,
  162. `email` TEXT,
  163. `plex_token` TEXT,
  164. `group` TEXT,
  165. `group_id` INTEGER,
  166. `locked` INTEGER,
  167. `image` TEXT,
  168. `register_date` DATE,
  169. `auth_service` TEXT DEFAULT \'internal\'
  170. );');
  171. // Create Tokens
  172. $createDB->query('CREATE TABLE `chatroom` (
  173. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  174. `username` TEXT,
  175. `gravatar` TEXT,
  176. `uid` TEXT,
  177. `date` DATE,
  178. `ip` TEXT,
  179. `message` TEXT
  180. );');
  181. $createDB->query('CREATE TABLE `tokens` (
  182. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  183. `token` TEXT UNIQUE,
  184. `user_id` INTEGER,
  185. `browser` TEXT,
  186. `ip` TEXT,
  187. `created` DATE,
  188. `expires` DATE
  189. );');
  190. $createDB->query('CREATE TABLE `groups` (
  191. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  192. `group` TEXT UNIQUE,
  193. `group_id` INTEGER,
  194. `image` TEXT,
  195. `default` INTEGER
  196. );');
  197. $createDB->query('CREATE TABLE `categories` (
  198. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  199. `order` INTEGER,
  200. `category` TEXT UNIQUE,
  201. `category_id` INTEGER,
  202. `image` TEXT,
  203. `default` INTEGER
  204. );');
  205. // Create Tabs
  206. $createDB->query('CREATE TABLE `tabs` (
  207. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  208. `order` INTEGER,
  209. `category_id` INTEGER,
  210. `name` TEXT,
  211. `url` TEXT,
  212. `url_local` TEXT,
  213. `default` INTEGER,
  214. `enabled` INTEGER,
  215. `group_id` INTEGER,
  216. `image` TEXT,
  217. `type` INTEGER,
  218. `splash` INTEGER,
  219. `ping` INTEGER,
  220. `ping_url` TEXT,
  221. `timeout` INTEGER,
  222. `timeout_ms` INTEGER,
  223. `preload` INTEGER
  224. );');
  225. // Create Options
  226. $createDB->query('CREATE TABLE `options` (
  227. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  228. `name` TEXT UNIQUE,
  229. `value` TEXT
  230. );');
  231. // Create Invites
  232. $createDB->query('CREATE TABLE `invites` (
  233. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  234. `code` TEXT UNIQUE,
  235. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  236. `email` TEXT,
  237. `username` TEXT,
  238. `dateused` TIMESTAMP,
  239. `usedby` TEXT,
  240. `ip` TEXT,
  241. `valid` TEXT,
  242. `type` TEXT
  243. );');
  244. return true;
  245. } catch (Dibi\Exception $e) {
  246. return false;
  247. }
  248. }
  249. // Upgrade Database
  250. function updateDB($oldVerNum = false)
  251. {
  252. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  253. if (!file_exists($tempLock)) {
  254. touch($tempLock);
  255. // Create Temp DB First
  256. $migrationDB = 'tempMigration.db';
  257. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  258. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  259. unlink($GLOBALS['dbLocation'] . $migrationDB);
  260. }
  261. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  262. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  263. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  264. if ($success) {
  265. try {
  266. $connectOldDB = new Dibi\Connection([
  267. 'driver' => 'sqlite3',
  268. 'database' => $backupDB,
  269. ]);
  270. $connectNewDB = new Dibi\Connection([
  271. 'driver' => 'sqlite3',
  272. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  273. ]);
  274. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  275. foreach ($tables as $table) {
  276. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  277. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  278. foreach ($data as $row) {
  279. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  280. }
  281. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  282. }
  283. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  284. $connectOldDB->disconnect();
  285. $connectNewDB->disconnect();
  286. // Remove Current Database
  287. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  288. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  289. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  290. if ($newFileSize > 0) {
  291. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  292. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  293. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  294. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  295. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  296. @unlink($tempLock);
  297. return true;
  298. }
  299. }
  300. @unlink($tempLock);
  301. return false;
  302. } catch (Dibi\Exception $e) {
  303. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  304. @unlink($tempLock);
  305. return false;
  306. }
  307. }
  308. @unlink($tempLock);
  309. return false;
  310. }
  311. return false;
  312. }
  313. function createFirstAdmin($path, $filename, $username, $password, $email)
  314. {
  315. try {
  316. $createDB = new Dibi\Connection([
  317. 'driver' => 'sqlite3',
  318. 'database' => $path . $filename,
  319. ]);
  320. $userInfo = [
  321. 'username' => $username,
  322. 'password' => password_hash($password, PASSWORD_BCRYPT),
  323. 'email' => $email,
  324. 'group' => 'Admin',
  325. 'group_id' => 0,
  326. 'image' => gravatar($email),
  327. 'register_date' => $GLOBALS['currentTime'],
  328. ];
  329. $groupInfo0 = [
  330. 'group' => 'Admin',
  331. 'group_id' => 0,
  332. 'default' => false,
  333. 'image' => 'plugins/images/groups/admin.png',
  334. ];
  335. $groupInfo1 = [
  336. 'group' => 'Co-Admin',
  337. 'group_id' => 1,
  338. 'default' => false,
  339. 'image' => 'plugins/images/groups/coadmin.png',
  340. ];
  341. $groupInfo2 = [
  342. 'group' => 'Super User',
  343. 'group_id' => 2,
  344. 'default' => false,
  345. 'image' => 'plugins/images/groups/superuser.png',
  346. ];
  347. $groupInfo3 = [
  348. 'group' => 'Power User',
  349. 'group_id' => 3,
  350. 'default' => false,
  351. 'image' => 'plugins/images/groups/poweruser.png',
  352. ];
  353. $groupInfo4 = [
  354. 'group' => 'User',
  355. 'group_id' => 4,
  356. 'default' => true,
  357. 'image' => 'plugins/images/groups/user.png',
  358. ];
  359. $groupInfoGuest = [
  360. 'group' => 'Guest',
  361. 'group_id' => 999,
  362. 'default' => false,
  363. 'image' => 'plugins/images/groups/guest.png',
  364. ];
  365. $settingsInfo = [
  366. 'order' => 1,
  367. 'category_id' => 0,
  368. 'name' => 'Settings',
  369. 'url' => 'api/?v1/settings/page',
  370. 'default' => false,
  371. 'enabled' => true,
  372. 'group_id' => 1,
  373. 'image' => 'fontawesome::cog',
  374. 'type' => 0
  375. ];
  376. $homepageInfo = [
  377. 'order' => 2,
  378. 'category_id' => 0,
  379. 'name' => 'Homepage',
  380. 'url' => 'api/?v1/homepage/page',
  381. 'default' => false,
  382. 'enabled' => false,
  383. 'group_id' => 4,
  384. 'image' => 'fontawesome::home',
  385. 'type' => 0
  386. ];
  387. $unsortedInfo = [
  388. 'order' => 1,
  389. 'category' => 'Unsorted',
  390. 'category_id' => 0,
  391. 'image' => 'plugins/images/categories/unsorted.png',
  392. 'default' => true
  393. ];
  394. $createDB->query('INSERT INTO [users]', $userInfo);
  395. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  396. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  397. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  398. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  399. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  400. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  401. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  402. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  403. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  404. return true;
  405. } catch (Dibi\Exception $e) {
  406. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  407. return false;
  408. }
  409. }
  410. function defaultUserGroup()
  411. {
  412. try {
  413. $connect = new Dibi\Connection([
  414. 'driver' => 'sqlite3',
  415. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  416. ]);
  417. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  418. return $all;
  419. } catch (Dibi\Exception $e) {
  420. return false;
  421. }
  422. }
  423. function defaultTabCategory()
  424. {
  425. try {
  426. $connect = new Dibi\Connection([
  427. 'driver' => 'sqlite3',
  428. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  429. ]);
  430. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  431. return $all;
  432. } catch (Dibi\Exception $e) {
  433. return false;
  434. }
  435. }
  436. function getGuest()
  437. {
  438. if (isset($GLOBALS['dbLocation'])) {
  439. try {
  440. $connect = new Dibi\Connection([
  441. 'driver' => 'sqlite3',
  442. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  443. ]);
  444. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  445. return $all;
  446. } catch (Dibi\Exception $e) {
  447. return false;
  448. }
  449. } else {
  450. return array(
  451. 'group' => 'Guest',
  452. 'group_id' => 999,
  453. 'image' => 'plugins/images/groups/guest.png'
  454. );
  455. }
  456. }
  457. function adminEditGroup($array)
  458. {
  459. switch ($array['data']['action']) {
  460. case 'changeDefaultGroup':
  461. try {
  462. $connect = new Dibi\Connection([
  463. 'driver' => 'sqlite3',
  464. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  465. ]);
  466. $connect->query('UPDATE groups SET `default` = 0');
  467. $connect->query('
  468. UPDATE groups SET', [
  469. 'default' => 1
  470. ], '
  471. WHERE id=?', $array['data']['id']);
  472. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  473. return true;
  474. } catch (Dibi\Exception $e) {
  475. return false;
  476. }
  477. break;
  478. case 'deleteUserGroup':
  479. try {
  480. $connect = new Dibi\Connection([
  481. 'driver' => 'sqlite3',
  482. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  483. ]);
  484. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  485. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  486. return true;
  487. } catch (Dibi\Exception $e) {
  488. return false;
  489. }
  490. break;
  491. case 'addUserGroup':
  492. try {
  493. $connect = new Dibi\Connection([
  494. 'driver' => 'sqlite3',
  495. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  496. ]);
  497. $newGroup = [
  498. 'group' => $array['data']['newGroupName'],
  499. 'group_id' => $array['data']['newGroupID'],
  500. 'default' => false,
  501. 'image' => $array['data']['newGroupImage'],
  502. ];
  503. $connect->query('INSERT INTO [groups]', $newGroup);
  504. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  505. return true;
  506. } catch (Dibi\Exception $e) {
  507. return false;
  508. }
  509. break;
  510. case 'editUserGroup':
  511. try {
  512. $connect = new Dibi\Connection([
  513. 'driver' => 'sqlite3',
  514. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  515. ]);
  516. $connect->query('
  517. UPDATE groups SET', [
  518. 'group' => $array['data']['groupName'],
  519. 'image' => $array['data']['groupImage'],
  520. ], '
  521. WHERE id=?', $array['data']['id']);
  522. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  523. return true;
  524. } catch (Dibi\Exception $e) {
  525. return false;
  526. }
  527. break;
  528. default:
  529. return false;
  530. break;
  531. }
  532. }
  533. function adminEditUser($array)
  534. {
  535. switch ($array['data']['action']) {
  536. case 'changeGroup':
  537. try {
  538. $connect = new Dibi\Connection([
  539. 'driver' => 'sqlite3',
  540. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  541. ]);
  542. $connect->query('
  543. UPDATE users SET', [
  544. 'group' => $array['data']['newGroupName'],
  545. 'group_id' => $array['data']['newGroupID'],
  546. ], '
  547. WHERE id=?', $array['data']['id']);
  548. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  549. return true;
  550. } catch (Dibi\Exception $e) {
  551. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  552. return false;
  553. }
  554. break;
  555. case 'editUser':
  556. try {
  557. $connect = new Dibi\Connection([
  558. 'driver' => 'sqlite3',
  559. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  560. ]);
  561. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  562. $connect->query('
  563. UPDATE users SET', [
  564. 'username' => $array['data']['username'],
  565. 'email' => $array['data']['email'],
  566. 'image' => gravatar($array['data']['email']),
  567. ], '
  568. WHERE id=?', $array['data']['id']);
  569. if (!empty($array['data']['password'])) {
  570. $connect->query('
  571. UPDATE users SET', [
  572. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  573. ], '
  574. WHERE id=?', $array['data']['id']);
  575. }
  576. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  577. return true;
  578. } else {
  579. return false;
  580. }
  581. } catch (Dibi\Exception $e) {
  582. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  583. return false;
  584. }
  585. break;
  586. case 'addNewUser':
  587. $defaults = defaultUserGroup();
  588. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  589. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  590. return true;
  591. } else {
  592. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  593. return 'username taken';
  594. }
  595. break;
  596. case 'deleteUser':
  597. try {
  598. $connect = new Dibi\Connection([
  599. 'driver' => 'sqlite3',
  600. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  601. ]);
  602. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  603. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  604. return true;
  605. } catch (Dibi\Exception $e) {
  606. return false;
  607. }
  608. break;
  609. default:
  610. return false;
  611. break;
  612. }
  613. }
  614. function editTabs($array)
  615. {
  616. switch ($array['data']['action']) {
  617. case 'changeGroup':
  618. try {
  619. $connect = new Dibi\Connection([
  620. 'driver' => 'sqlite3',
  621. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  622. ]);
  623. $connect->query('
  624. UPDATE tabs SET', [
  625. 'group_id' => $array['data']['newGroupID'],
  626. ], '
  627. WHERE id=?', $array['data']['id']);
  628. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  629. return true;
  630. } catch (Dibi\Exception $e) {
  631. return false;
  632. }
  633. break;
  634. case 'changeCategory':
  635. try {
  636. $connect = new Dibi\Connection([
  637. 'driver' => 'sqlite3',
  638. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  639. ]);
  640. $connect->query('
  641. UPDATE tabs SET', [
  642. 'category_id' => $array['data']['newCategoryID'],
  643. ], '
  644. WHERE id=?', $array['data']['id']);
  645. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  646. return true;
  647. } catch (Dibi\Exception $e) {
  648. return false;
  649. }
  650. break;
  651. case 'changeType':
  652. try {
  653. $connect = new Dibi\Connection([
  654. 'driver' => 'sqlite3',
  655. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  656. ]);
  657. $connect->query('
  658. UPDATE tabs SET', [
  659. 'type' => $array['data']['newTypeID'],
  660. ], '
  661. WHERE id=?', $array['data']['id']);
  662. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  663. return true;
  664. } catch (Dibi\Exception $e) {
  665. return false;
  666. }
  667. break;
  668. case 'changeEnabled':
  669. try {
  670. $connect = new Dibi\Connection([
  671. 'driver' => 'sqlite3',
  672. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  673. ]);
  674. $connect->query('
  675. UPDATE tabs SET', [
  676. 'enabled' => $array['data']['tabEnabled'],
  677. ], '
  678. WHERE id=?', $array['data']['id']);
  679. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  680. return true;
  681. } catch (Dibi\Exception $e) {
  682. return false;
  683. }
  684. break;
  685. case 'changeSplash':
  686. try {
  687. $connect = new Dibi\Connection([
  688. 'driver' => 'sqlite3',
  689. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  690. ]);
  691. $connect->query('
  692. UPDATE tabs SET', [
  693. 'splash' => $array['data']['tabSplash'],
  694. ], '
  695. WHERE id=?', $array['data']['id']);
  696. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  697. return true;
  698. } catch (Dibi\Exception $e) {
  699. return false;
  700. }
  701. break;
  702. case 'changePing':
  703. try {
  704. $connect = new Dibi\Connection([
  705. 'driver' => 'sqlite3',
  706. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  707. ]);
  708. $connect->query('
  709. UPDATE tabs SET', [
  710. 'ping' => $array['data']['tabPing'],
  711. ], '
  712. WHERE id=?', $array['data']['id']);
  713. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  714. return true;
  715. } catch (Dibi\Exception $e) {
  716. return false;
  717. }
  718. break;
  719. case 'changeDefault':
  720. try {
  721. $connect = new Dibi\Connection([
  722. 'driver' => 'sqlite3',
  723. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  724. ]);
  725. $connect->query('UPDATE tabs SET `default` = 0');
  726. $connect->query('
  727. UPDATE tabs SET', [
  728. 'default' => 1
  729. ], '
  730. WHERE id=?', $array['data']['id']);
  731. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  732. return true;
  733. } catch (Dibi\Exception $e) {
  734. return false;
  735. }
  736. break;
  737. case 'deleteTab':
  738. try {
  739. $connect = new Dibi\Connection([
  740. 'driver' => 'sqlite3',
  741. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  742. ]);
  743. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  744. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  745. return true;
  746. } catch (Dibi\Exception $e) {
  747. return false;
  748. }
  749. break;
  750. case 'editTab':
  751. try {
  752. $connect = new Dibi\Connection([
  753. 'driver' => 'sqlite3',
  754. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  755. ]);
  756. $connect->query('
  757. UPDATE tabs SET', [
  758. 'name' => $array['data']['tabName'],
  759. 'url' => $array['data']['tabURL'],
  760. 'ping_url' => $array['data']['pingURL'],
  761. 'image' => $array['data']['tabImage'],
  762. ], '
  763. WHERE id=?', $array['data']['id']);
  764. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  765. return true;
  766. } catch (Dibi\Exception $e) {
  767. return false;
  768. }
  769. case 'changeOrder':
  770. try {
  771. $connect = new Dibi\Connection([
  772. 'driver' => 'sqlite3',
  773. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  774. ]);
  775. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  776. if ($value['order'] != $value['originalOrder']) {
  777. $connect->query('
  778. UPDATE tabs SET', [
  779. 'order' => $value['order'],
  780. ], '
  781. WHERE id=?', $value['id']);
  782. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  783. }
  784. }
  785. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  786. return true;
  787. } catch (Dibi\Exception $e) {
  788. return false;
  789. }
  790. break;
  791. case 'addNewTab':
  792. try {
  793. $default = defaultTabCategory()['category_id'];
  794. $connect = new Dibi\Connection([
  795. 'driver' => 'sqlite3',
  796. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  797. ]);
  798. $newTab = [
  799. 'order' => $array['data']['tabOrder'],
  800. 'category_id' => $default,
  801. 'name' => $array['data']['tabName'],
  802. 'url' => $array['data']['tabURL'],
  803. 'ping_url' => $array['data']['pingURL'],
  804. 'default' => $array['data']['tabDefault'],
  805. 'enabled' => 1,
  806. 'group_id' => $array['data']['tabGroupID'],
  807. 'image' => $array['data']['tabImage'],
  808. 'type' => $array['data']['tabType']
  809. ];
  810. $connect->query('INSERT INTO [tabs]', $newTab);
  811. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  812. return true;
  813. } catch (Dibi\Exception $e) {
  814. return false;
  815. }
  816. break;
  817. default:
  818. return false;
  819. break;
  820. }
  821. }
  822. function editCategories($array)
  823. {
  824. switch ($array['data']['action']) {
  825. case 'changeDefault':
  826. try {
  827. $connect = new Dibi\Connection([
  828. 'driver' => 'sqlite3',
  829. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  830. ]);
  831. $connect->query('UPDATE categories SET `default` = 0');
  832. $connect->query('
  833. UPDATE categories SET', [
  834. 'default' => 1
  835. ], '
  836. WHERE id=?', $array['data']['id']);
  837. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  838. return true;
  839. } catch (Dibi\Exception $e) {
  840. return false;
  841. }
  842. break;
  843. case 'deleteCategory':
  844. try {
  845. $connect = new Dibi\Connection([
  846. 'driver' => 'sqlite3',
  847. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  848. ]);
  849. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  850. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  851. return true;
  852. } catch (Dibi\Exception $e) {
  853. return false;
  854. }
  855. break;
  856. case 'addNewCategory':
  857. try {
  858. $connect = new Dibi\Connection([
  859. 'driver' => 'sqlite3',
  860. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  861. ]);
  862. $newCategory = [
  863. 'category' => $array['data']['categoryName'],
  864. 'order' => $array['data']['categoryOrder'],
  865. 'category_id' => $array['data']['categoryID'],
  866. 'default' => false,
  867. 'image' => $array['data']['categoryImage'],
  868. ];
  869. $connect->query('INSERT INTO [categories]', $newCategory);
  870. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  871. return true;
  872. } catch (Dibi\Exception $e) {
  873. return $e;
  874. }
  875. break;
  876. case 'editCategory':
  877. try {
  878. $connect = new Dibi\Connection([
  879. 'driver' => 'sqlite3',
  880. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  881. ]);
  882. $connect->query('
  883. UPDATE categories SET', [
  884. 'category' => $array['data']['name'],
  885. 'image' => $array['data']['image'],
  886. ], '
  887. WHERE id=?', $array['data']['id']);
  888. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  889. return true;
  890. } catch (Dibi\Exception $e) {
  891. return false;
  892. }
  893. break;
  894. case 'changeOrder':
  895. try {
  896. $connect = new Dibi\Connection([
  897. 'driver' => 'sqlite3',
  898. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  899. ]);
  900. foreach ($array['data']['categories']['category'] as $key => $value) {
  901. if ($value['order'] != $value['originalOrder']) {
  902. $connect->query('
  903. UPDATE categories SET', [
  904. 'order' => $value['order'],
  905. ], '
  906. WHERE id=?', $value['id']);
  907. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  908. }
  909. }
  910. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  911. return true;
  912. } catch (Dibi\Exception $e) {
  913. return false;
  914. }
  915. break;
  916. default:
  917. return false;
  918. break;
  919. }
  920. }
  921. function allUsers()
  922. {
  923. try {
  924. $connect = new Dibi\Connection([
  925. 'driver' => 'sqlite3',
  926. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  927. ]);
  928. $users = $connect->fetchAll('SELECT * FROM users');
  929. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  930. foreach ($users as $k => $v) {
  931. // clear password from array
  932. unset($users[$k]['password']);
  933. }
  934. $all['users'] = $users;
  935. $all['groups'] = $groups;
  936. return $all;
  937. } catch (Dibi\Exception $e) {
  938. return false;
  939. }
  940. }
  941. function usernameTaken($username, $email)
  942. {
  943. try {
  944. $connect = new Dibi\Connection([
  945. 'driver' => 'sqlite3',
  946. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  947. ]);
  948. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  949. return ($all) ? true : false;
  950. } catch (Dibi\Exception $e) {
  951. return false;
  952. }
  953. }
  954. function usernameTakenExcept($username, $email, $id)
  955. {
  956. try {
  957. $connect = new Dibi\Connection([
  958. 'driver' => 'sqlite3',
  959. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  960. ]);
  961. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  962. return ($all) ? true : false;
  963. } catch (Dibi\Exception $e) {
  964. return false;
  965. }
  966. }
  967. function createUser($username, $password, $defaults, $email = null)
  968. {
  969. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  970. try {
  971. if (!usernameTaken($username, $email)) {
  972. $createDB = new Dibi\Connection([
  973. 'driver' => 'sqlite3',
  974. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  975. ]);
  976. $userInfo = [
  977. 'username' => $username,
  978. 'password' => password_hash($password, PASSWORD_BCRYPT),
  979. 'email' => $email,
  980. 'group' => $defaults['group'],
  981. 'group_id' => $defaults['group_id'],
  982. 'image' => gravatar($email),
  983. 'register_date' => $GLOBALS['currentTime'],
  984. ];
  985. $createDB->query('INSERT INTO [users]', $userInfo);
  986. return true;
  987. } else {
  988. return false;
  989. }
  990. } catch (Dibi\Exception $e) {
  991. return false;
  992. }
  993. }
  994. function importUsers($array)
  995. {
  996. $imported = 0;
  997. $defaults = defaultUserGroup();
  998. foreach ($array as $user) {
  999. $password = random_ascii_string(30);
  1000. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1001. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1002. if (!$newUser) {
  1003. writeLog('error', 'Import Function - Error', $user['username']);
  1004. } else {
  1005. $imported++;
  1006. }
  1007. }
  1008. }
  1009. return $imported;
  1010. }
  1011. function importUsersType($array)
  1012. {
  1013. $type = $array['data']['type'];
  1014. if ($type !== '') {
  1015. switch ($type) {
  1016. case 'plex':
  1017. return importUsers(allPlexUsers(true));
  1018. break;
  1019. default:
  1020. return false;
  1021. }
  1022. }
  1023. return false;
  1024. }
  1025. function allTabs()
  1026. {
  1027. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1028. try {
  1029. $connect = new Dibi\Connection([
  1030. 'driver' => 'sqlite3',
  1031. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1032. ]);
  1033. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1034. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1035. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1036. return $all;
  1037. } catch (Dibi\Exception $e) {
  1038. return false;
  1039. }
  1040. }
  1041. return false;
  1042. }
  1043. function allGroups()
  1044. {
  1045. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1046. try {
  1047. $connect = new Dibi\Connection([
  1048. 'driver' => 'sqlite3',
  1049. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1050. ]);
  1051. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1052. return $all;
  1053. } catch (Dibi\Exception $e) {
  1054. return false;
  1055. }
  1056. }
  1057. return false;
  1058. }
  1059. function loadTabs()
  1060. {
  1061. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1062. try {
  1063. $connect = new Dibi\Connection([
  1064. 'driver' => 'sqlite3',
  1065. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1066. ]);
  1067. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1068. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1069. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1070. $all['tabs'] = $tabs;
  1071. foreach ($tabs as $k => $v) {
  1072. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  1073. }
  1074. $count = array_map(function ($element) {
  1075. return $element['category_id'];
  1076. }, $tabs);
  1077. $count = (array_count_values($count));
  1078. foreach ($categories as $k => $v) {
  1079. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1080. }
  1081. $all['categories'] = $categories;
  1082. return $all;
  1083. } catch (Dibi\Exception $e) {
  1084. return false;
  1085. }
  1086. }
  1087. return false;
  1088. }
  1089. function getActiveTokens()
  1090. {
  1091. try {
  1092. $connect = new Dibi\Connection([
  1093. 'driver' => 'sqlite3',
  1094. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1095. ]);
  1096. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1097. return $all;
  1098. } catch (Dibi\Exception $e) {
  1099. return false;
  1100. }
  1101. }
  1102. function revokeToken($array)
  1103. {
  1104. if ($array['data']['token']) {
  1105. try {
  1106. $connect = new Dibi\Connection([
  1107. 'driver' => 'sqlite3',
  1108. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1109. ]);
  1110. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1111. return true;
  1112. } catch (Dibi\Exception $e) {
  1113. return false;
  1114. }
  1115. }
  1116. }