| 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246 |
- <?php /** @noinspection SqlResolve */
- /** @noinspection SqlResolve */
- /** @noinspection SqlResolve */
- /** @noinspection SqlResolve */
- /** @noinspection SyntaxError */
- function apiLogin()
- {
- $array = array(
- 'data' => array(
- array(
- 'name' => 'username',
- 'value' => (isset($_POST['username'])) ? $_POST['username'] : false
- ),
- array(
- 'name' => 'password',
- 'value' => (isset($_POST['password'])) ? $_POST['password'] : false
- ),
- array(
- 'name' => 'remember',
- 'value' => (isset($_POST['remember'])) ? true : false
- ),
- array(
- 'name' => 'oAuth',
- 'value' => (isset($_POST['oAuth'])) ? $_POST['oAuth'] : false
- ),
- array(
- 'name' => 'oAuthType',
- 'value' => (isset($_POST['oAuthType'])) ? $_POST['oAuthType'] : false
- ),
- array(
- 'name' => 'tfaCode',
- 'value' => (isset($_POST['tfaCode'])) ? $_POST['tfaCode'] : false
- ),
- array(
- 'name' => 'loginAttempts',
- 'value' => (isset($_POST['loginAttempts'])) ? $_POST['loginAttempts'] : false
- ),
- array(
- 'name' => 'output',
- 'value' => true
- ),
- )
- );
- foreach ($array['data'] as $items) {
- foreach ($items as $key => $value) {
- if ($key == 'name') {
- $newKey = $value;
- }
- if ($key == 'value') {
- $newValue = $value;
- }
- if (isset($newKey) && isset($newValue)) {
- $$newKey = $newValue;
- }
- }
- }
- return login($array);
- }
- function login($array)
- {
- // Grab username and Password from login form
- $username = $password = $oAuth = $oAuthType = '';
- foreach ($array['data'] as $items) {
- foreach ($items as $key => $value) {
- if ($key == 'name') {
- $newKey = $value;
- }
- if ($key == 'value') {
- $newValue = $value;
- }
- if (isset($newKey) && isset($newValue)) {
- $$newKey = $newValue;
- }
- }
- }
- $username = (strpos($GLOBALS['authBackend'], 'emby') !== false) ? $username : strtolower($username);
- $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
- $oAuth = (isset($oAuth)) ? $oAuth : false;
- $output = (isset($output)) ? $output : false;
- $loginAttempts = (isset($loginAttempts)) ? $loginAttempts : false;
- if($loginAttempts > $GLOBALS['loginAttempts'] || isset($_COOKIE['lockout'])){
- coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
- return 'lockout';
- }
- try {
- $database = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $authSuccess = false;
- $function = 'plugin_auth_' . $GLOBALS['authBackend'];
- if (!$oAuth) {
- $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
- switch ($GLOBALS['authType']) {
- case 'external':
- if (function_exists($function)) {
- $authSuccess = $function($username, $password);
- }
- break;
- /** @noinspection PhpMissingBreakStatementInspection */
- case 'both':
- if (function_exists($function)) {
- $authSuccess = $function($username, $password);
- }
- // no break
- default: // Internal
- if (!$authSuccess) {
- // perform the internal authentication step
- if (password_verify($password, $result['password'])) {
- $authSuccess = true;
- }
- }
- }
- } else {
- // Has oAuth Token!
- switch ($oAuthType) {
- case 'plex':
- if ($GLOBALS['plexoAuth']) {
- $tokenInfo = checkPlexToken($oAuth);
- if ($tokenInfo) {
- $authSuccess = array(
- 'username' => $tokenInfo['user']['username'],
- 'email' => $tokenInfo['user']['email'],
- 'image' => $tokenInfo['user']['thumb'],
- 'token' => $tokenInfo['user']['authToken']
- );
- coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
- $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || (!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['email'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
- }
- }
- break;
- default:
- return ($output) ? 'No oAuthType defined' : 'error';
- break;
- }
- $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
- }
- if ($authSuccess) {
- // Make sure user exists in database
- $userExists = false;
- $passwordMatches = ($oAuth) ? true : false;
- $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
- if ($result['username']) {
- $userExists = true;
- $username = $result['username'];
- if ($passwordMatches == false) {
- $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
- }
- }
- if ($userExists) {
- //does org password need to be updated
- if (!$passwordMatches) {
- $database->query('
- UPDATE users SET', [
- 'password' => password_hash($password, PASSWORD_BCRYPT)
- ], '
- WHERE id=?', $result['id']);
- writeLog('success', 'Login Function - User Password updated from backend', $username);
- }
- if ($token !== '') {
- if ($token !== $result['plex_token']) {
- $database->query('
- UPDATE users SET', [
- 'plex_token' => $token
- ], '
- WHERE id=?', $result['id']);
- writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
- }
- }
- // 2FA might go here
- if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
- $TFA = explode('::', $result['auth_service']);
- // Is code with login info?
- if ($tfaCode == '') {
- return '2FA';
- } else {
- if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
- writeLoginLog($username, 'error');
- writeLog('error', 'Login Function - Wrong 2FA', $username);
- return '2FA-incorrect';
- }
- }
- }
- // End 2FA
- // authentication passed - 1) mark active and update token
- $createToken = createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days);
- if ($createToken) {
- writeLoginLog($username, 'success');
- writeLog('success', 'Login Function - A User has logged in', $username);
- $ssoUser = (empty($result['email'])) ? $result['username'] : (strpos($result['email'], 'placeholder') !== false) ? $result['username'] : $result['email'];
- ssoCheck($ssoUser, $password, $token); //need to work on this
- return ($output) ? array('name' => $GLOBALS['cookieName'], 'token' => (string)$createToken) : true;
- } else {
- return 'Token Creation Error';
- }
- } else {
- // Create User
- //ssoCheck($username, $password, $token);
- return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
- }
- } else {
- // authentication failed
- writeLoginLog($username, 'error');
- writeLog('error', 'Login Function - Wrong Password', $username);
- return 'mismatch';
- }
- } catch (Dibi\Exception $e) {
- return $e;
- }
- }
- function createDB($path, $filename)
- {
- try {
- if (!file_exists($path)) {
- mkdir($path, 0777, true);
- }
- $createDB = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $path . $filename,
- ]);
- // Create Users
- $createDB->query('CREATE TABLE `users` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `username` TEXT UNIQUE,
- `password` TEXT,
- `email` TEXT,
- `plex_token` TEXT,
- `group` TEXT,
- `group_id` INTEGER,
- `locked` INTEGER,
- `image` TEXT,
- `register_date` DATE,
- `auth_service` TEXT DEFAULT \'internal\'
- );');
- // Create Tokens
- $createDB->query('CREATE TABLE `chatroom` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `username` TEXT,
- `gravatar` TEXT,
- `uid` TEXT,
- `date` DATE,
- `ip` TEXT,
- `message` TEXT
- );');
- $createDB->query('CREATE TABLE `tokens` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `token` TEXT UNIQUE,
- `user_id` INTEGER,
- `browser` TEXT,
- `ip` TEXT,
- `created` DATE,
- `expires` DATE
- );');
- $createDB->query('CREATE TABLE `groups` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `group` TEXT UNIQUE,
- `group_id` INTEGER,
- `image` TEXT,
- `default` INTEGER
- );');
- $createDB->query('CREATE TABLE `categories` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `order` INTEGER,
- `category` TEXT UNIQUE,
- `category_id` INTEGER,
- `image` TEXT,
- `default` INTEGER
- );');
- // Create Tabs
- $createDB->query('CREATE TABLE `tabs` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `order` INTEGER,
- `category_id` INTEGER,
- `name` TEXT,
- `url` TEXT,
- `url_local` TEXT,
- `default` INTEGER,
- `enabled` INTEGER,
- `group_id` INTEGER,
- `image` TEXT,
- `type` INTEGER,
- `splash` INTEGER,
- `ping` INTEGER,
- `ping_url` TEXT,
- `timeout` INTEGER,
- `timeout_ms` INTEGER,
- `preload` INTEGER
- );');
- // Create Options
- $createDB->query('CREATE TABLE `options` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `name` TEXT UNIQUE,
- `value` TEXT
- );');
- // Create Invites
- $createDB->query('CREATE TABLE `invites` (
- `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
- `code` TEXT UNIQUE,
- `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
- `email` TEXT,
- `username` TEXT,
- `dateused` TIMESTAMP,
- `usedby` TEXT,
- `ip` TEXT,
- `valid` TEXT,
- `type` TEXT
- );');
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- // Upgrade Database
- function updateDB($oldVerNum = false)
- {
- $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
- if (!file_exists($tempLock)) {
- touch($tempLock);
- // Create Temp DB First
- $migrationDB = 'tempMigration.db';
- $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
- if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
- unlink($GLOBALS['dbLocation'] . $migrationDB);
- }
- $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
- copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
- $success = createDB($GLOBALS['dbLocation'], $migrationDB);
- if ($success) {
- try {
- $connectOldDB = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $backupDB,
- ]);
- $connectNewDB = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $migrationDB,
- ]);
- $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
- foreach ($tables as $table) {
- $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
- writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
- foreach ($data as $row) {
- $connectNewDB->query('INSERT into ' . $table['name'], $row);
- }
- writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
- }
- writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
- $connectOldDB->disconnect();
- $connectNewDB->disconnect();
- // Remove Current Database
- if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
- $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
- $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
- if ($newFileSize > 0) {
- writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
- @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
- copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
- @unlink($GLOBALS['dbLocation'] . $migrationDB);
- writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
- @unlink($tempLock);
- return true;
- }
- }
- @unlink($tempLock);
- return false;
- } catch (Dibi\Exception $e) {
- writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
- @unlink($tempLock);
- return false;
- }
- }
- @unlink($tempLock);
- return false;
- }
- return false;
- }
- function createFirstAdmin($path, $filename, $username, $password, $email)
- {
- try {
- $createDB = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $path . $filename,
- ]);
- $userInfo = [
- 'username' => $username,
- 'password' => password_hash($password, PASSWORD_BCRYPT),
- 'email' => $email,
- 'group' => 'Admin',
- 'group_id' => 0,
- 'image' => gravatar($email),
- 'register_date' => $GLOBALS['currentTime'],
- ];
- $groupInfo0 = [
- 'group' => 'Admin',
- 'group_id' => 0,
- 'default' => false,
- 'image' => 'plugins/images/groups/admin.png',
- ];
- $groupInfo1 = [
- 'group' => 'Co-Admin',
- 'group_id' => 1,
- 'default' => false,
- 'image' => 'plugins/images/groups/coadmin.png',
- ];
- $groupInfo2 = [
- 'group' => 'Super User',
- 'group_id' => 2,
- 'default' => false,
- 'image' => 'plugins/images/groups/superuser.png',
- ];
- $groupInfo3 = [
- 'group' => 'Power User',
- 'group_id' => 3,
- 'default' => false,
- 'image' => 'plugins/images/groups/poweruser.png',
- ];
- $groupInfo4 = [
- 'group' => 'User',
- 'group_id' => 4,
- 'default' => true,
- 'image' => 'plugins/images/groups/user.png',
- ];
- $groupInfoGuest = [
- 'group' => 'Guest',
- 'group_id' => 999,
- 'default' => false,
- 'image' => 'plugins/images/groups/guest.png',
- ];
- $settingsInfo = [
- 'order' => 1,
- 'category_id' => 0,
- 'name' => 'Settings',
- 'url' => 'api/?v1/settings/page',
- 'default' => false,
- 'enabled' => true,
- 'group_id' => 1,
- 'image' => 'fontawesome::cog',
- 'type' => 0
- ];
- $homepageInfo = [
- 'order' => 2,
- 'category_id' => 0,
- 'name' => 'Homepage',
- 'url' => 'api/?v1/homepage/page',
- 'default' => false,
- 'enabled' => false,
- 'group_id' => 4,
- 'image' => 'fontawesome::home',
- 'type' => 0
- ];
- $unsortedInfo = [
- 'order' => 1,
- 'category' => 'Unsorted',
- 'category_id' => 0,
- 'image' => 'plugins/images/categories/unsorted.png',
- 'default' => true
- ];
- $createDB->query('INSERT INTO [users]', $userInfo);
- $createDB->query('INSERT INTO [groups]', $groupInfo0);
- $createDB->query('INSERT INTO [groups]', $groupInfo1);
- $createDB->query('INSERT INTO [groups]', $groupInfo2);
- $createDB->query('INSERT INTO [groups]', $groupInfo3);
- $createDB->query('INSERT INTO [groups]', $groupInfo4);
- $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
- $createDB->query('INSERT INTO [tabs]', $settingsInfo);
- $createDB->query('INSERT INTO [tabs]', $homepageInfo);
- $createDB->query('INSERT INTO [categories]', $unsortedInfo);
- return true;
- } catch (Dibi\Exception $e) {
- writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
- return false;
- }
- }
- function defaultUserGroup()
- {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- function defaultTabCategory()
- {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- function getGuest()
- {
- if (isset($GLOBALS['dbLocation'])) {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- } else {
- return array(
- 'group' => 'Guest',
- 'group_id' => 999,
- 'image' => 'plugins/images/groups/guest.png'
- );
- }
- }
- function adminEditGroup($array)
- {
- switch ($array['data']['action']) {
- case 'changeDefaultGroup':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('UPDATE groups SET `default` = 0');
- $connect->query('
- UPDATE groups SET', [
- 'default' => 1
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'deleteUserGroup':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
- writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'addUserGroup':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $newGroup = [
- 'group' => $array['data']['newGroupName'],
- 'group_id' => $array['data']['newGroupID'],
- 'default' => false,
- 'image' => $array['data']['newGroupImage'],
- ];
- $connect->query('INSERT INTO [groups]', $newGroup);
- writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'editUserGroup':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE groups SET', [
- 'group' => $array['data']['groupName'],
- 'image' => $array['data']['groupImage'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- default:
- return false;
- break;
- }
- }
- function adminEditUser($array)
- {
- switch ($array['data']['action']) {
- case 'changeGroup':
- if ($array['data']['newGroupID'] == 0) {
- return false;
- }
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE users SET', [
- 'group' => $array['data']['newGroupName'],
- 'group_id' => $array['data']['newGroupID'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
- return false;
- }
- break;
- case 'editUser':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
- $connect->query('
- UPDATE users SET', [
- 'username' => $array['data']['username'],
- 'email' => $array['data']['email'],
- 'image' => gravatar($array['data']['email']),
- ], '
- WHERE id=?', $array['data']['id']);
- if (!empty($array['data']['password'])) {
- $connect->query('
- UPDATE users SET', [
- 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
- ], '
- WHERE id=?', $array['data']['id']);
- }
- writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
- return true;
- } else {
- return false;
- }
- } catch (Dibi\Exception $e) {
- writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
- return false;
- }
- break;
- case 'addNewUser':
- $defaults = defaultUserGroup();
- if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
- writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } else {
- writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
- return 'username taken';
- }
- break;
- case 'deleteUser':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
- writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- default:
- return false;
- break;
- }
- }
- function editTabs($array)
- {
- switch ($array['data']['action']) {
- case 'changeGroup':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'group_id' => $array['data']['newGroupID'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changeCategory':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'category_id' => $array['data']['newCategoryID'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changeType':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'type' => $array['data']['newTypeID'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changeEnabled':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'enabled' => $array['data']['tabEnabled'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changeSplash':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'splash' => $array['data']['tabSplash'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changePing':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'ping' => $array['data']['tabPing'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changePreload':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'preload' => $array['data']['tabPreload'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s preload status was changed to [' . $array['data']['tabPreloadWord'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changeDefault':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('UPDATE tabs SET `default` = 0');
- $connect->query('
- UPDATE tabs SET', [
- 'default' => 1
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'deleteTab':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'editTab':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE tabs SET', [
- 'name' => $array['data']['tabName'],
- 'url' => $array['data']['tabURL'],
- 'url_local' => $array['data']['tabLocalURL'],
- 'ping_url' => $array['data']['pingURL'],
- 'image' => $array['data']['tabImage'],
- 'timeout' => $array['data']['tabActionType'],
- 'timeout_ms' => $array['data']['tabActionTime'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- case 'changeOrder':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- foreach ($array['data']['tabs']['tab'] as $key => $value) {
- if ($value['order'] != $value['originalOrder']) {
- $connect->query('
- UPDATE tabs SET', [
- 'order' => $value['order'],
- ], '
- WHERE id=?', $value['id']);
- writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
- }
- }
- writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'addNewTab':
- try {
- $default = defaultTabCategory()['category_id'];
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $newTab = [
- 'order' => $array['data']['tabOrder'],
- 'category_id' => $default,
- 'name' => $array['data']['tabName'],
- 'url' => $array['data']['tabURL'],
- 'url_local' => $array['data']['tabLocalURL'],
- 'ping_url' => $array['data']['pingURL'],
- 'default' => $array['data']['tabDefault'],
- 'enabled' => 1,
- 'group_id' => $array['data']['tabGroupID'],
- 'image' => $array['data']['tabImage'],
- 'type' => $array['data']['tabType'],
- 'timeout' => $array['data']['tabActionType'],
- 'timeout_ms' => $array['data']['tabActionTime'],
- ];
- $connect->query('INSERT INTO [tabs]', $newTab);
- writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- default:
- return false;
- break;
- }
- }
- function editCategories($array)
- {
- switch ($array['data']['action']) {
- case 'changeDefault':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('UPDATE categories SET `default` = 0');
- $connect->query('
- UPDATE categories SET', [
- 'default' => 1
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'deleteCategory':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
- writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'addNewCategory':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $newCategory = [
- 'category' => $array['data']['categoryName'],
- 'order' => $array['data']['categoryOrder'],
- 'category_id' => $array['data']['categoryID'],
- 'default' => false,
- 'image' => $array['data']['categoryImage'],
- ];
- $connect->query('INSERT INTO [categories]', $newCategory);
- writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return $e;
- }
- break;
- case 'editCategory':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('
- UPDATE categories SET', [
- 'category' => $array['data']['name'],
- 'image' => $array['data']['image'],
- ], '
- WHERE id=?', $array['data']['id']);
- writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- case 'changeOrder':
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- foreach ($array['data']['categories']['category'] as $key => $value) {
- if ($value['order'] != $value['originalOrder']) {
- $connect->query('
- UPDATE categories SET', [
- 'order' => $value['order'],
- ], '
- WHERE id=?', $value['id']);
- writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
- }
- }
- writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- break;
- default:
- return false;
- break;
- }
- }
- function allUsers()
- {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $users = $connect->fetchAll('SELECT * FROM users');
- $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
- foreach ($users as $k => $v) {
- // clear password from array
- unset($users[$k]['password']);
- }
- $all['users'] = $users;
- $all['groups'] = $groups;
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- function usernameTaken($username, $email)
- {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
- return ($all) ? true : false;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- function usernameTakenExcept($username, $email, $id)
- {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
- return ($all) ? true : false;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- function createUser($username, $password, $defaults, $email = null)
- {
- $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
- try {
- if (!usernameTaken($username, $email)) {
- $createDB = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $userInfo = [
- 'username' => $username,
- 'password' => password_hash($password, PASSWORD_BCRYPT),
- 'email' => $email,
- 'group' => $defaults['group'],
- 'group_id' => $defaults['group_id'],
- 'image' => gravatar($email),
- 'register_date' => $GLOBALS['currentTime'],
- ];
- $createDB->query('INSERT INTO [users]', $userInfo);
- return true;
- } else {
- return false;
- }
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- function importUsers($array)
- {
- $imported = 0;
- $defaults = defaultUserGroup();
- foreach ($array as $user) {
- $password = random_ascii_string(30);
- if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
- $newUser = createUser($user['username'], $password, $defaults, $user['email']);
- if (!$newUser) {
- writeLog('error', 'Import Function - Error', $user['username']);
- } else {
- $imported++;
- }
- }
- }
- return $imported;
- }
- function importUsersType($array)
- {
- $type = $array['data']['type'];
- if ($type !== '') {
- switch ($type) {
- case 'plex':
- return importUsers(allPlexUsers(true));
- break;
- default:
- return false;
- }
- }
- return false;
- }
- function allTabs()
- {
- if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
- $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
- $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- return false;
- }
- function allGroups()
- {
- if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- return false;
- }
- function loadTabs()
- {
- if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
- $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
- $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
- $all['tabs'] = $tabs;
- foreach ($tabs as $k => $v) {
- $v['access_url'] = (!empty($v['url_local']) && ($v['url_local'] !== null) && ($v['url_local'] !== 'null') && isLocal() && $v['type'] !== 0) ? $v['url_local'] : $v['url'];
- }
- $count = array_map(function ($element) {
- return $element['category_id'];
- }, $tabs);
- $count = (array_count_values($count));
- foreach ($categories as $k => $v) {
- $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
- }
- $all['categories'] = $categories;
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- return false;
- }
- function getActiveTokens()
- {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
- return $all;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- function revokeToken($array)
- {
- if ($array['data']['token']) {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
- return true;
- } catch (Dibi\Exception $e) {
- return false;
- }
- }
- }
- function getSchema()
- {
- if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
- try {
- $connect = new Dibi\Connection([
- 'driver' => 'sqlite3',
- 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
- ]);
- $result = $connect->fetchAll(' SELECT name, sql FROM sqlite_master WHERE type=\'table\' ORDER BY name');
- return $result;
- } catch (Dibi\Exception $e) {
- return false;
- }
- } else {
- return 'DB not set yet...';
- }
- }
|