api-functions.php 40 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function apiLogin()
  7. {
  8. $array = array(
  9. 'data' => array(
  10. array(
  11. 'name' => 'username',
  12. 'value' => (isset($_POST['username'])) ? $_POST['username'] : false
  13. ),
  14. array(
  15. 'name' => 'password',
  16. 'value' => (isset($_POST['password'])) ? $_POST['password'] : false
  17. ),
  18. array(
  19. 'name' => 'remember',
  20. 'value' => (isset($_POST['remember'])) ? true : false
  21. ),
  22. array(
  23. 'name' => 'oAuth',
  24. 'value' => (isset($_POST['oAuth'])) ? $_POST['oAuth'] : false
  25. ),
  26. array(
  27. 'name' => 'oAuthType',
  28. 'value' => (isset($_POST['oAuthType'])) ? $_POST['oAuthType'] : false
  29. ),
  30. array(
  31. 'name' => 'tfaCode',
  32. 'value' => (isset($_POST['tfaCode'])) ? $_POST['tfaCode'] : false
  33. ),
  34. array(
  35. 'name' => 'loginAttempts',
  36. 'value' => (isset($_POST['loginAttempts'])) ? $_POST['loginAttempts'] : false
  37. ),
  38. array(
  39. 'name' => 'output',
  40. 'value' => true
  41. ),
  42. )
  43. );
  44. foreach ($array['data'] as $items) {
  45. foreach ($items as $key => $value) {
  46. if ($key == 'name') {
  47. $newKey = $value;
  48. }
  49. if ($key == 'value') {
  50. $newValue = $value;
  51. }
  52. if (isset($newKey) && isset($newValue)) {
  53. $$newKey = $newValue;
  54. }
  55. }
  56. }
  57. return login($array);
  58. }
  59. function login($array)
  60. {
  61. // Grab username and Password from login form
  62. $username = $password = $oAuth = $oAuthType = '';
  63. foreach ($array['data'] as $items) {
  64. foreach ($items as $key => $value) {
  65. if ($key == 'name') {
  66. $newKey = $value;
  67. }
  68. if ($key == 'value') {
  69. $newValue = $value;
  70. }
  71. if (isset($newKey) && isset($newValue)) {
  72. $$newKey = $newValue;
  73. }
  74. }
  75. }
  76. $username = (strpos($GLOBALS['authBackend'], 'emby') !== false) ? $username : strtolower($username);
  77. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  78. $oAuth = (isset($oAuth)) ? $oAuth : false;
  79. $output = (isset($output)) ? $output : false;
  80. $loginAttempts = (isset($loginAttempts)) ? $loginAttempts : false;
  81. if($loginAttempts > $GLOBALS['loginAttempts'] || isset($_COOKIE['lockout'])){
  82. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  83. return 'lockout';
  84. }
  85. try {
  86. $database = new Dibi\Connection([
  87. 'driver' => 'sqlite3',
  88. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  89. ]);
  90. $authSuccess = false;
  91. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  92. if (!$oAuth) {
  93. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  94. switch ($GLOBALS['authType']) {
  95. case 'external':
  96. if (function_exists($function)) {
  97. $authSuccess = $function($username, $password);
  98. }
  99. break;
  100. /** @noinspection PhpMissingBreakStatementInspection */
  101. case 'both':
  102. if (function_exists($function)) {
  103. $authSuccess = $function($username, $password);
  104. }
  105. // no break
  106. default: // Internal
  107. if (!$authSuccess) {
  108. // perform the internal authentication step
  109. if (password_verify($password, $result['password'])) {
  110. $authSuccess = true;
  111. }
  112. }
  113. }
  114. } else {
  115. // Has oAuth Token!
  116. switch ($oAuthType) {
  117. case 'plex':
  118. if ($GLOBALS['plexoAuth']) {
  119. $tokenInfo = checkPlexToken($oAuth);
  120. if ($tokenInfo) {
  121. $authSuccess = array(
  122. 'username' => $tokenInfo['user']['username'],
  123. 'email' => $tokenInfo['user']['email'],
  124. 'image' => $tokenInfo['user']['thumb'],
  125. 'token' => $tokenInfo['user']['authToken']
  126. );
  127. coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
  128. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || (!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['email'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  129. }
  130. }
  131. break;
  132. default:
  133. return ($output) ? 'No oAuthType defined' : 'error';
  134. break;
  135. }
  136. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  137. }
  138. if ($authSuccess) {
  139. // Make sure user exists in database
  140. $userExists = false;
  141. $passwordMatches = ($oAuth) ? true : false;
  142. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  143. if ($result['username']) {
  144. $userExists = true;
  145. $username = $result['username'];
  146. if ($passwordMatches == false) {
  147. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  148. }
  149. }
  150. if ($userExists) {
  151. //does org password need to be updated
  152. if (!$passwordMatches) {
  153. $database->query('
  154. UPDATE users SET', [
  155. 'password' => password_hash($password, PASSWORD_BCRYPT)
  156. ], '
  157. WHERE id=?', $result['id']);
  158. writeLog('success', 'Login Function - User Password updated from backend', $username);
  159. }
  160. if ($token !== '') {
  161. if ($token !== $result['plex_token']) {
  162. $database->query('
  163. UPDATE users SET', [
  164. 'plex_token' => $token
  165. ], '
  166. WHERE id=?', $result['id']);
  167. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  168. }
  169. }
  170. // 2FA might go here
  171. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  172. $TFA = explode('::', $result['auth_service']);
  173. // Is code with login info?
  174. if ($tfaCode == '') {
  175. return '2FA';
  176. } else {
  177. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  178. writeLoginLog($username, 'error');
  179. writeLog('error', 'Login Function - Wrong 2FA', $username);
  180. return '2FA-incorrect';
  181. }
  182. }
  183. }
  184. // End 2FA
  185. // authentication passed - 1) mark active and update token
  186. $createToken = createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days);
  187. if ($createToken) {
  188. writeLoginLog($username, 'success');
  189. writeLog('success', 'Login Function - A User has logged in', $username);
  190. $ssoUser = (empty($result['email'])) ? $result['username'] : (strpos($result['email'], 'placeholder') !== false) ? $result['username'] : $result['email'];
  191. ssoCheck($ssoUser, $password, $token); //need to work on this
  192. return ($output) ? array('name' => $GLOBALS['cookieName'], 'token' => (string)$createToken) : true;
  193. } else {
  194. return 'Token Creation Error';
  195. }
  196. } else {
  197. // Create User
  198. //ssoCheck($username, $password, $token);
  199. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  200. }
  201. } else {
  202. // authentication failed
  203. writeLoginLog($username, 'error');
  204. writeLog('error', 'Login Function - Wrong Password', $username);
  205. return 'mismatch';
  206. }
  207. } catch (Dibi\Exception $e) {
  208. return $e;
  209. }
  210. }
  211. function createDB($path, $filename)
  212. {
  213. try {
  214. if (!file_exists($path)) {
  215. mkdir($path, 0777, true);
  216. }
  217. $createDB = new Dibi\Connection([
  218. 'driver' => 'sqlite3',
  219. 'database' => $path . $filename,
  220. ]);
  221. // Create Users
  222. $createDB->query('CREATE TABLE `users` (
  223. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  224. `username` TEXT UNIQUE,
  225. `password` TEXT,
  226. `email` TEXT,
  227. `plex_token` TEXT,
  228. `group` TEXT,
  229. `group_id` INTEGER,
  230. `locked` INTEGER,
  231. `image` TEXT,
  232. `register_date` DATE,
  233. `auth_service` TEXT DEFAULT \'internal\'
  234. );');
  235. // Create Tokens
  236. $createDB->query('CREATE TABLE `chatroom` (
  237. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  238. `username` TEXT,
  239. `gravatar` TEXT,
  240. `uid` TEXT,
  241. `date` DATE,
  242. `ip` TEXT,
  243. `message` TEXT
  244. );');
  245. $createDB->query('CREATE TABLE `tokens` (
  246. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  247. `token` TEXT UNIQUE,
  248. `user_id` INTEGER,
  249. `browser` TEXT,
  250. `ip` TEXT,
  251. `created` DATE,
  252. `expires` DATE
  253. );');
  254. $createDB->query('CREATE TABLE `groups` (
  255. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  256. `group` TEXT UNIQUE,
  257. `group_id` INTEGER,
  258. `image` TEXT,
  259. `default` INTEGER
  260. );');
  261. $createDB->query('CREATE TABLE `categories` (
  262. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  263. `order` INTEGER,
  264. `category` TEXT UNIQUE,
  265. `category_id` INTEGER,
  266. `image` TEXT,
  267. `default` INTEGER
  268. );');
  269. // Create Tabs
  270. $createDB->query('CREATE TABLE `tabs` (
  271. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  272. `order` INTEGER,
  273. `category_id` INTEGER,
  274. `name` TEXT,
  275. `url` TEXT,
  276. `url_local` TEXT,
  277. `default` INTEGER,
  278. `enabled` INTEGER,
  279. `group_id` INTEGER,
  280. `image` TEXT,
  281. `type` INTEGER,
  282. `splash` INTEGER,
  283. `ping` INTEGER,
  284. `ping_url` TEXT,
  285. `timeout` INTEGER,
  286. `timeout_ms` INTEGER,
  287. `preload` INTEGER
  288. );');
  289. // Create Options
  290. $createDB->query('CREATE TABLE `options` (
  291. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  292. `name` TEXT UNIQUE,
  293. `value` TEXT
  294. );');
  295. // Create Invites
  296. $createDB->query('CREATE TABLE `invites` (
  297. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  298. `code` TEXT UNIQUE,
  299. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  300. `email` TEXT,
  301. `username` TEXT,
  302. `dateused` TIMESTAMP,
  303. `usedby` TEXT,
  304. `ip` TEXT,
  305. `valid` TEXT,
  306. `type` TEXT
  307. );');
  308. return true;
  309. } catch (Dibi\Exception $e) {
  310. return false;
  311. }
  312. }
  313. // Upgrade Database
  314. function updateDB($oldVerNum = false)
  315. {
  316. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  317. if (!file_exists($tempLock)) {
  318. touch($tempLock);
  319. // Create Temp DB First
  320. $migrationDB = 'tempMigration.db';
  321. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  322. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  323. unlink($GLOBALS['dbLocation'] . $migrationDB);
  324. }
  325. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  326. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  327. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  328. if ($success) {
  329. try {
  330. $connectOldDB = new Dibi\Connection([
  331. 'driver' => 'sqlite3',
  332. 'database' => $backupDB,
  333. ]);
  334. $connectNewDB = new Dibi\Connection([
  335. 'driver' => 'sqlite3',
  336. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  337. ]);
  338. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  339. foreach ($tables as $table) {
  340. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  341. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  342. foreach ($data as $row) {
  343. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  344. }
  345. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  346. }
  347. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  348. $connectOldDB->disconnect();
  349. $connectNewDB->disconnect();
  350. // Remove Current Database
  351. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  352. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  353. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  354. if ($newFileSize > 0) {
  355. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  356. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  357. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  358. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  359. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  360. @unlink($tempLock);
  361. return true;
  362. }
  363. }
  364. @unlink($tempLock);
  365. return false;
  366. } catch (Dibi\Exception $e) {
  367. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  368. @unlink($tempLock);
  369. return false;
  370. }
  371. }
  372. @unlink($tempLock);
  373. return false;
  374. }
  375. return false;
  376. }
  377. function createFirstAdmin($path, $filename, $username, $password, $email)
  378. {
  379. try {
  380. $createDB = new Dibi\Connection([
  381. 'driver' => 'sqlite3',
  382. 'database' => $path . $filename,
  383. ]);
  384. $userInfo = [
  385. 'username' => $username,
  386. 'password' => password_hash($password, PASSWORD_BCRYPT),
  387. 'email' => $email,
  388. 'group' => 'Admin',
  389. 'group_id' => 0,
  390. 'image' => gravatar($email),
  391. 'register_date' => $GLOBALS['currentTime'],
  392. ];
  393. $groupInfo0 = [
  394. 'group' => 'Admin',
  395. 'group_id' => 0,
  396. 'default' => false,
  397. 'image' => 'plugins/images/groups/admin.png',
  398. ];
  399. $groupInfo1 = [
  400. 'group' => 'Co-Admin',
  401. 'group_id' => 1,
  402. 'default' => false,
  403. 'image' => 'plugins/images/groups/coadmin.png',
  404. ];
  405. $groupInfo2 = [
  406. 'group' => 'Super User',
  407. 'group_id' => 2,
  408. 'default' => false,
  409. 'image' => 'plugins/images/groups/superuser.png',
  410. ];
  411. $groupInfo3 = [
  412. 'group' => 'Power User',
  413. 'group_id' => 3,
  414. 'default' => false,
  415. 'image' => 'plugins/images/groups/poweruser.png',
  416. ];
  417. $groupInfo4 = [
  418. 'group' => 'User',
  419. 'group_id' => 4,
  420. 'default' => true,
  421. 'image' => 'plugins/images/groups/user.png',
  422. ];
  423. $groupInfoGuest = [
  424. 'group' => 'Guest',
  425. 'group_id' => 999,
  426. 'default' => false,
  427. 'image' => 'plugins/images/groups/guest.png',
  428. ];
  429. $settingsInfo = [
  430. 'order' => 1,
  431. 'category_id' => 0,
  432. 'name' => 'Settings',
  433. 'url' => 'api/?v1/settings/page',
  434. 'default' => false,
  435. 'enabled' => true,
  436. 'group_id' => 1,
  437. 'image' => 'fontawesome::cog',
  438. 'type' => 0
  439. ];
  440. $homepageInfo = [
  441. 'order' => 2,
  442. 'category_id' => 0,
  443. 'name' => 'Homepage',
  444. 'url' => 'api/?v1/homepage/page',
  445. 'default' => false,
  446. 'enabled' => false,
  447. 'group_id' => 4,
  448. 'image' => 'fontawesome::home',
  449. 'type' => 0
  450. ];
  451. $unsortedInfo = [
  452. 'order' => 1,
  453. 'category' => 'Unsorted',
  454. 'category_id' => 0,
  455. 'image' => 'plugins/images/categories/unsorted.png',
  456. 'default' => true
  457. ];
  458. $createDB->query('INSERT INTO [users]', $userInfo);
  459. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  460. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  461. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  462. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  463. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  464. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  465. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  466. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  467. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  468. return true;
  469. } catch (Dibi\Exception $e) {
  470. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  471. return false;
  472. }
  473. }
  474. function defaultUserGroup()
  475. {
  476. try {
  477. $connect = new Dibi\Connection([
  478. 'driver' => 'sqlite3',
  479. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  480. ]);
  481. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  482. return $all;
  483. } catch (Dibi\Exception $e) {
  484. return false;
  485. }
  486. }
  487. function defaultTabCategory()
  488. {
  489. try {
  490. $connect = new Dibi\Connection([
  491. 'driver' => 'sqlite3',
  492. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  493. ]);
  494. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  495. return $all;
  496. } catch (Dibi\Exception $e) {
  497. return false;
  498. }
  499. }
  500. function getGuest()
  501. {
  502. if (isset($GLOBALS['dbLocation'])) {
  503. try {
  504. $connect = new Dibi\Connection([
  505. 'driver' => 'sqlite3',
  506. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  507. ]);
  508. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  509. return $all;
  510. } catch (Dibi\Exception $e) {
  511. return false;
  512. }
  513. } else {
  514. return array(
  515. 'group' => 'Guest',
  516. 'group_id' => 999,
  517. 'image' => 'plugins/images/groups/guest.png'
  518. );
  519. }
  520. }
  521. function adminEditGroup($array)
  522. {
  523. switch ($array['data']['action']) {
  524. case 'changeDefaultGroup':
  525. try {
  526. $connect = new Dibi\Connection([
  527. 'driver' => 'sqlite3',
  528. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  529. ]);
  530. $connect->query('UPDATE groups SET `default` = 0');
  531. $connect->query('
  532. UPDATE groups SET', [
  533. 'default' => 1
  534. ], '
  535. WHERE id=?', $array['data']['id']);
  536. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  537. return true;
  538. } catch (Dibi\Exception $e) {
  539. return false;
  540. }
  541. break;
  542. case 'deleteUserGroup':
  543. try {
  544. $connect = new Dibi\Connection([
  545. 'driver' => 'sqlite3',
  546. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  547. ]);
  548. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  549. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  550. return true;
  551. } catch (Dibi\Exception $e) {
  552. return false;
  553. }
  554. break;
  555. case 'addUserGroup':
  556. try {
  557. $connect = new Dibi\Connection([
  558. 'driver' => 'sqlite3',
  559. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  560. ]);
  561. $newGroup = [
  562. 'group' => $array['data']['newGroupName'],
  563. 'group_id' => $array['data']['newGroupID'],
  564. 'default' => false,
  565. 'image' => $array['data']['newGroupImage'],
  566. ];
  567. $connect->query('INSERT INTO [groups]', $newGroup);
  568. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  569. return true;
  570. } catch (Dibi\Exception $e) {
  571. return false;
  572. }
  573. break;
  574. case 'editUserGroup':
  575. try {
  576. $connect = new Dibi\Connection([
  577. 'driver' => 'sqlite3',
  578. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  579. ]);
  580. $connect->query('
  581. UPDATE groups SET', [
  582. 'group' => $array['data']['groupName'],
  583. 'image' => $array['data']['groupImage'],
  584. ], '
  585. WHERE id=?', $array['data']['id']);
  586. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  587. return true;
  588. } catch (Dibi\Exception $e) {
  589. return false;
  590. }
  591. break;
  592. default:
  593. return false;
  594. break;
  595. }
  596. }
  597. function adminEditUser($array)
  598. {
  599. switch ($array['data']['action']) {
  600. case 'changeGroup':
  601. if ($array['data']['newGroupID'] == 0) {
  602. return false;
  603. }
  604. try {
  605. $connect = new Dibi\Connection([
  606. 'driver' => 'sqlite3',
  607. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  608. ]);
  609. $connect->query('
  610. UPDATE users SET', [
  611. 'group' => $array['data']['newGroupName'],
  612. 'group_id' => $array['data']['newGroupID'],
  613. ], '
  614. WHERE id=?', $array['data']['id']);
  615. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  616. return true;
  617. } catch (Dibi\Exception $e) {
  618. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  619. return false;
  620. }
  621. break;
  622. case 'editUser':
  623. try {
  624. $connect = new Dibi\Connection([
  625. 'driver' => 'sqlite3',
  626. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  627. ]);
  628. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  629. $connect->query('
  630. UPDATE users SET', [
  631. 'username' => $array['data']['username'],
  632. 'email' => $array['data']['email'],
  633. 'image' => gravatar($array['data']['email']),
  634. ], '
  635. WHERE id=?', $array['data']['id']);
  636. if (!empty($array['data']['password'])) {
  637. $connect->query('
  638. UPDATE users SET', [
  639. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  640. ], '
  641. WHERE id=?', $array['data']['id']);
  642. }
  643. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  644. return true;
  645. } else {
  646. return false;
  647. }
  648. } catch (Dibi\Exception $e) {
  649. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  650. return false;
  651. }
  652. break;
  653. case 'addNewUser':
  654. $defaults = defaultUserGroup();
  655. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  656. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  657. return true;
  658. } else {
  659. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  660. return 'username taken';
  661. }
  662. break;
  663. case 'deleteUser':
  664. try {
  665. $connect = new Dibi\Connection([
  666. 'driver' => 'sqlite3',
  667. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  668. ]);
  669. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  670. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  671. return true;
  672. } catch (Dibi\Exception $e) {
  673. return false;
  674. }
  675. break;
  676. default:
  677. return false;
  678. break;
  679. }
  680. }
  681. function editTabs($array)
  682. {
  683. switch ($array['data']['action']) {
  684. case 'changeGroup':
  685. try {
  686. $connect = new Dibi\Connection([
  687. 'driver' => 'sqlite3',
  688. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  689. ]);
  690. $connect->query('
  691. UPDATE tabs SET', [
  692. 'group_id' => $array['data']['newGroupID'],
  693. ], '
  694. WHERE id=?', $array['data']['id']);
  695. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  696. return true;
  697. } catch (Dibi\Exception $e) {
  698. return false;
  699. }
  700. break;
  701. case 'changeCategory':
  702. try {
  703. $connect = new Dibi\Connection([
  704. 'driver' => 'sqlite3',
  705. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  706. ]);
  707. $connect->query('
  708. UPDATE tabs SET', [
  709. 'category_id' => $array['data']['newCategoryID'],
  710. ], '
  711. WHERE id=?', $array['data']['id']);
  712. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  713. return true;
  714. } catch (Dibi\Exception $e) {
  715. return false;
  716. }
  717. break;
  718. case 'changeType':
  719. try {
  720. $connect = new Dibi\Connection([
  721. 'driver' => 'sqlite3',
  722. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  723. ]);
  724. $connect->query('
  725. UPDATE tabs SET', [
  726. 'type' => $array['data']['newTypeID'],
  727. ], '
  728. WHERE id=?', $array['data']['id']);
  729. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  730. return true;
  731. } catch (Dibi\Exception $e) {
  732. return false;
  733. }
  734. break;
  735. case 'changeEnabled':
  736. try {
  737. $connect = new Dibi\Connection([
  738. 'driver' => 'sqlite3',
  739. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  740. ]);
  741. $connect->query('
  742. UPDATE tabs SET', [
  743. 'enabled' => $array['data']['tabEnabled'],
  744. ], '
  745. WHERE id=?', $array['data']['id']);
  746. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  747. return true;
  748. } catch (Dibi\Exception $e) {
  749. return false;
  750. }
  751. break;
  752. case 'changeSplash':
  753. try {
  754. $connect = new Dibi\Connection([
  755. 'driver' => 'sqlite3',
  756. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  757. ]);
  758. $connect->query('
  759. UPDATE tabs SET', [
  760. 'splash' => $array['data']['tabSplash'],
  761. ], '
  762. WHERE id=?', $array['data']['id']);
  763. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  764. return true;
  765. } catch (Dibi\Exception $e) {
  766. return false;
  767. }
  768. break;
  769. case 'changePing':
  770. try {
  771. $connect = new Dibi\Connection([
  772. 'driver' => 'sqlite3',
  773. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  774. ]);
  775. $connect->query('
  776. UPDATE tabs SET', [
  777. 'ping' => $array['data']['tabPing'],
  778. ], '
  779. WHERE id=?', $array['data']['id']);
  780. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  781. return true;
  782. } catch (Dibi\Exception $e) {
  783. return false;
  784. }
  785. break;
  786. case 'changePreload':
  787. try {
  788. $connect = new Dibi\Connection([
  789. 'driver' => 'sqlite3',
  790. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  791. ]);
  792. $connect->query('
  793. UPDATE tabs SET', [
  794. 'preload' => $array['data']['tabPreload'],
  795. ], '
  796. WHERE id=?', $array['data']['id']);
  797. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s preload status was changed to [' . $array['data']['tabPreloadWord'] . ']', $GLOBALS['organizrUser']['username']);
  798. return true;
  799. } catch (Dibi\Exception $e) {
  800. return false;
  801. }
  802. break;
  803. case 'changeDefault':
  804. try {
  805. $connect = new Dibi\Connection([
  806. 'driver' => 'sqlite3',
  807. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  808. ]);
  809. $connect->query('UPDATE tabs SET `default` = 0');
  810. $connect->query('
  811. UPDATE tabs SET', [
  812. 'default' => 1
  813. ], '
  814. WHERE id=?', $array['data']['id']);
  815. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  816. return true;
  817. } catch (Dibi\Exception $e) {
  818. return false;
  819. }
  820. break;
  821. case 'deleteTab':
  822. try {
  823. $connect = new Dibi\Connection([
  824. 'driver' => 'sqlite3',
  825. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  826. ]);
  827. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  828. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  829. return true;
  830. } catch (Dibi\Exception $e) {
  831. return false;
  832. }
  833. break;
  834. case 'editTab':
  835. try {
  836. $connect = new Dibi\Connection([
  837. 'driver' => 'sqlite3',
  838. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  839. ]);
  840. $connect->query('
  841. UPDATE tabs SET', [
  842. 'name' => $array['data']['tabName'],
  843. 'url' => $array['data']['tabURL'],
  844. 'url_local' => $array['data']['tabLocalURL'],
  845. 'ping_url' => $array['data']['pingURL'],
  846. 'image' => $array['data']['tabImage'],
  847. 'timeout' => $array['data']['tabActionType'],
  848. 'timeout_ms' => $array['data']['tabActionTime'],
  849. ], '
  850. WHERE id=?', $array['data']['id']);
  851. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  852. return true;
  853. } catch (Dibi\Exception $e) {
  854. return false;
  855. }
  856. case 'changeOrder':
  857. try {
  858. $connect = new Dibi\Connection([
  859. 'driver' => 'sqlite3',
  860. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  861. ]);
  862. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  863. if ($value['order'] != $value['originalOrder']) {
  864. $connect->query('
  865. UPDATE tabs SET', [
  866. 'order' => $value['order'],
  867. ], '
  868. WHERE id=?', $value['id']);
  869. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  870. }
  871. }
  872. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  873. return true;
  874. } catch (Dibi\Exception $e) {
  875. return false;
  876. }
  877. break;
  878. case 'addNewTab':
  879. try {
  880. $default = defaultTabCategory()['category_id'];
  881. $connect = new Dibi\Connection([
  882. 'driver' => 'sqlite3',
  883. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  884. ]);
  885. $newTab = [
  886. 'order' => $array['data']['tabOrder'],
  887. 'category_id' => $default,
  888. 'name' => $array['data']['tabName'],
  889. 'url' => $array['data']['tabURL'],
  890. 'url_local' => $array['data']['tabLocalURL'],
  891. 'ping_url' => $array['data']['pingURL'],
  892. 'default' => $array['data']['tabDefault'],
  893. 'enabled' => 1,
  894. 'group_id' => $array['data']['tabGroupID'],
  895. 'image' => $array['data']['tabImage'],
  896. 'type' => $array['data']['tabType'],
  897. 'timeout' => $array['data']['tabActionType'],
  898. 'timeout_ms' => $array['data']['tabActionTime'],
  899. ];
  900. $connect->query('INSERT INTO [tabs]', $newTab);
  901. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  902. return true;
  903. } catch (Dibi\Exception $e) {
  904. return false;
  905. }
  906. break;
  907. default:
  908. return false;
  909. break;
  910. }
  911. }
  912. function editCategories($array)
  913. {
  914. switch ($array['data']['action']) {
  915. case 'changeDefault':
  916. try {
  917. $connect = new Dibi\Connection([
  918. 'driver' => 'sqlite3',
  919. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  920. ]);
  921. $connect->query('UPDATE categories SET `default` = 0');
  922. $connect->query('
  923. UPDATE categories SET', [
  924. 'default' => 1
  925. ], '
  926. WHERE id=?', $array['data']['id']);
  927. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  928. return true;
  929. } catch (Dibi\Exception $e) {
  930. return false;
  931. }
  932. break;
  933. case 'deleteCategory':
  934. try {
  935. $connect = new Dibi\Connection([
  936. 'driver' => 'sqlite3',
  937. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  938. ]);
  939. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  940. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  941. return true;
  942. } catch (Dibi\Exception $e) {
  943. return false;
  944. }
  945. break;
  946. case 'addNewCategory':
  947. try {
  948. $connect = new Dibi\Connection([
  949. 'driver' => 'sqlite3',
  950. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  951. ]);
  952. $newCategory = [
  953. 'category' => $array['data']['categoryName'],
  954. 'order' => $array['data']['categoryOrder'],
  955. 'category_id' => $array['data']['categoryID'],
  956. 'default' => false,
  957. 'image' => $array['data']['categoryImage'],
  958. ];
  959. $connect->query('INSERT INTO [categories]', $newCategory);
  960. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  961. return true;
  962. } catch (Dibi\Exception $e) {
  963. return $e;
  964. }
  965. break;
  966. case 'editCategory':
  967. try {
  968. $connect = new Dibi\Connection([
  969. 'driver' => 'sqlite3',
  970. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  971. ]);
  972. $connect->query('
  973. UPDATE categories SET', [
  974. 'category' => $array['data']['name'],
  975. 'image' => $array['data']['image'],
  976. ], '
  977. WHERE id=?', $array['data']['id']);
  978. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  979. return true;
  980. } catch (Dibi\Exception $e) {
  981. return false;
  982. }
  983. break;
  984. case 'changeOrder':
  985. try {
  986. $connect = new Dibi\Connection([
  987. 'driver' => 'sqlite3',
  988. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  989. ]);
  990. foreach ($array['data']['categories']['category'] as $key => $value) {
  991. if ($value['order'] != $value['originalOrder']) {
  992. $connect->query('
  993. UPDATE categories SET', [
  994. 'order' => $value['order'],
  995. ], '
  996. WHERE id=?', $value['id']);
  997. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  998. }
  999. }
  1000. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  1001. return true;
  1002. } catch (Dibi\Exception $e) {
  1003. return false;
  1004. }
  1005. break;
  1006. default:
  1007. return false;
  1008. break;
  1009. }
  1010. }
  1011. function allUsers()
  1012. {
  1013. try {
  1014. $connect = new Dibi\Connection([
  1015. 'driver' => 'sqlite3',
  1016. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1017. ]);
  1018. $users = $connect->fetchAll('SELECT * FROM users');
  1019. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  1020. foreach ($users as $k => $v) {
  1021. // clear password from array
  1022. unset($users[$k]['password']);
  1023. }
  1024. $all['users'] = $users;
  1025. $all['groups'] = $groups;
  1026. return $all;
  1027. } catch (Dibi\Exception $e) {
  1028. return false;
  1029. }
  1030. }
  1031. function usernameTaken($username, $email)
  1032. {
  1033. try {
  1034. $connect = new Dibi\Connection([
  1035. 'driver' => 'sqlite3',
  1036. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1037. ]);
  1038. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  1039. return ($all) ? true : false;
  1040. } catch (Dibi\Exception $e) {
  1041. return false;
  1042. }
  1043. }
  1044. function usernameTakenExcept($username, $email, $id)
  1045. {
  1046. try {
  1047. $connect = new Dibi\Connection([
  1048. 'driver' => 'sqlite3',
  1049. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1050. ]);
  1051. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  1052. return ($all) ? true : false;
  1053. } catch (Dibi\Exception $e) {
  1054. return false;
  1055. }
  1056. }
  1057. function createUser($username, $password, $defaults, $email = null)
  1058. {
  1059. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  1060. try {
  1061. if (!usernameTaken($username, $email)) {
  1062. $createDB = new Dibi\Connection([
  1063. 'driver' => 'sqlite3',
  1064. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1065. ]);
  1066. $userInfo = [
  1067. 'username' => $username,
  1068. 'password' => password_hash($password, PASSWORD_BCRYPT),
  1069. 'email' => $email,
  1070. 'group' => $defaults['group'],
  1071. 'group_id' => $defaults['group_id'],
  1072. 'image' => gravatar($email),
  1073. 'register_date' => $GLOBALS['currentTime'],
  1074. ];
  1075. $createDB->query('INSERT INTO [users]', $userInfo);
  1076. return true;
  1077. } else {
  1078. return false;
  1079. }
  1080. } catch (Dibi\Exception $e) {
  1081. return false;
  1082. }
  1083. }
  1084. function importUsers($array)
  1085. {
  1086. $imported = 0;
  1087. $defaults = defaultUserGroup();
  1088. foreach ($array as $user) {
  1089. $password = random_ascii_string(30);
  1090. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1091. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1092. if (!$newUser) {
  1093. writeLog('error', 'Import Function - Error', $user['username']);
  1094. } else {
  1095. $imported++;
  1096. }
  1097. }
  1098. }
  1099. return $imported;
  1100. }
  1101. function importUsersType($array)
  1102. {
  1103. $type = $array['data']['type'];
  1104. if ($type !== '') {
  1105. switch ($type) {
  1106. case 'plex':
  1107. return importUsers(allPlexUsers(true));
  1108. break;
  1109. default:
  1110. return false;
  1111. }
  1112. }
  1113. return false;
  1114. }
  1115. function allTabs()
  1116. {
  1117. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1118. try {
  1119. $connect = new Dibi\Connection([
  1120. 'driver' => 'sqlite3',
  1121. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1122. ]);
  1123. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1124. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1125. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1126. return $all;
  1127. } catch (Dibi\Exception $e) {
  1128. return false;
  1129. }
  1130. }
  1131. return false;
  1132. }
  1133. function allGroups()
  1134. {
  1135. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1136. try {
  1137. $connect = new Dibi\Connection([
  1138. 'driver' => 'sqlite3',
  1139. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1140. ]);
  1141. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1142. return $all;
  1143. } catch (Dibi\Exception $e) {
  1144. return false;
  1145. }
  1146. }
  1147. return false;
  1148. }
  1149. function loadTabs()
  1150. {
  1151. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1152. try {
  1153. $connect = new Dibi\Connection([
  1154. 'driver' => 'sqlite3',
  1155. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1156. ]);
  1157. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1158. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1159. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1160. $all['tabs'] = $tabs;
  1161. foreach ($tabs as $k => $v) {
  1162. $v['access_url'] = (!empty($v['url_local']) && ($v['url_local'] !== null) && ($v['url_local'] !== 'null') && isLocal() && $v['type'] !== 0) ? $v['url_local'] : $v['url'];
  1163. }
  1164. $count = array_map(function ($element) {
  1165. return $element['category_id'];
  1166. }, $tabs);
  1167. $count = (array_count_values($count));
  1168. foreach ($categories as $k => $v) {
  1169. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1170. }
  1171. $all['categories'] = $categories;
  1172. return $all;
  1173. } catch (Dibi\Exception $e) {
  1174. return false;
  1175. }
  1176. }
  1177. return false;
  1178. }
  1179. function getActiveTokens()
  1180. {
  1181. try {
  1182. $connect = new Dibi\Connection([
  1183. 'driver' => 'sqlite3',
  1184. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1185. ]);
  1186. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1187. return $all;
  1188. } catch (Dibi\Exception $e) {
  1189. return false;
  1190. }
  1191. }
  1192. function revokeToken($array)
  1193. {
  1194. if ($array['data']['token']) {
  1195. try {
  1196. $connect = new Dibi\Connection([
  1197. 'driver' => 'sqlite3',
  1198. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1199. ]);
  1200. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1201. return true;
  1202. } catch (Dibi\Exception $e) {
  1203. return false;
  1204. }
  1205. }
  1206. }
  1207. function getSchema()
  1208. {
  1209. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1210. try {
  1211. $connect = new Dibi\Connection([
  1212. 'driver' => 'sqlite3',
  1213. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1214. ]);
  1215. $result = $connect->fetchAll(' SELECT name, sql FROM sqlite_master WHERE type=\'table\' ORDER BY name');
  1216. return $result;
  1217. } catch (Dibi\Exception $e) {
  1218. return false;
  1219. }
  1220. } else {
  1221. return 'DB not set yet...';
  1222. }
  1223. }