4
0

api-functions.php 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955
  1. <?php
  2. function login($array)
  3. {
  4. // Grab username and Password from login form
  5. foreach ($array['data'] as $items) {
  6. foreach ($items as $key => $value) {
  7. if ($key == 'name') {
  8. $newKey = $value;
  9. }
  10. if ($key == 'value') {
  11. $newValue = $value;
  12. }
  13. if (isset($newKey) && isset($newValue)) {
  14. $$newKey = $newValue;
  15. }
  16. }
  17. }
  18. $username = strtolower($username);
  19. $days = (isset($remember)) ? 7 : 1;
  20. try {
  21. $database = new Dibi\Connection([
  22. 'driver' => 'sqlite3',
  23. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  24. ]);
  25. $authSuccess = false;
  26. $function = 'plugin_auth_'.$GLOBALS['authBackend'];
  27. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  28. switch ($GLOBALS['authType']) {
  29. case 'external':
  30. if (function_exists($function)) {
  31. $authSuccess = $function($username, $password);
  32. }
  33. break;
  34. case 'both':
  35. if (function_exists($function)) {
  36. $authSuccess = $function($username, $password);
  37. }
  38. // no break
  39. default: // Internal
  40. if (!$authSuccess) {
  41. // perform the internal authentication step
  42. if (password_verify($password, $result['password'])) {
  43. $authSuccess = true;
  44. }
  45. }
  46. }
  47. if ($authSuccess) {
  48. // Make sure user exists in database
  49. $userExists = false;
  50. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  51. if ($result['username']) {
  52. $userExists = true;
  53. $username = $result['username'];
  54. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  55. }
  56. if ($userExists) {
  57. //does org password need to be updated
  58. if (!$passwordMatches) {
  59. $database->query('
  60. UPDATE users SET', [
  61. 'password' => password_hash($password, PASSWORD_BCRYPT)
  62. ], '
  63. WHERE id=?', $result['id']);
  64. writeLog('success', 'Login Function - User Password updated from backend', $username);
  65. }
  66. // authentication passed - 1) mark active and update token
  67. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  68. writeLoginLog($username, 'success');
  69. writeLog('success', 'Login Function - A User has logged in', $username);
  70. ssoCheck($username, $password, $token); //need to work on this
  71. return true;
  72. } else {
  73. return 'error';
  74. }
  75. } else {
  76. // Create User
  77. ssoCheck($username, $password, $token);
  78. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, '', (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  79. }
  80. } else {
  81. // authentication failed
  82. writeLoginLog($username, 'error');
  83. writeLog('error', 'Login Function - Wrong Password', $username);
  84. return 'mismatch';
  85. }
  86. } catch (Dibi\Exception $e) {
  87. return 'error';
  88. }
  89. }
  90. function createDB($path, $filename)
  91. {
  92. try {
  93. $createDB = new Dibi\Connection([
  94. 'driver' => 'sqlite3',
  95. 'database' => $path.$filename,
  96. ]);
  97. // Create Users
  98. $users = $createDB->query('CREATE TABLE `users` (
  99. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  100. `username` TEXT UNIQUE,
  101. `password` TEXT,
  102. `email` TEXT,
  103. `plex_token` TEXT,
  104. `group` TEXT,
  105. `group_id` INTEGER,
  106. `locked` INTEGER,
  107. `image` TEXT,
  108. `register_date` DATE,
  109. `auth_service` TEXT DEFAULT \'internal\'
  110. );');
  111. // Create Tokens
  112. $jwt = $createDB->query('CREATE TABLE `tokens` (
  113. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  114. `token` TEXT UNIQUE,
  115. `user_id` INTEGER,
  116. `created` DATE,
  117. `expires` DATE
  118. );');
  119. $groups = $createDB->query('CREATE TABLE `groups` (
  120. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  121. `group` TEXT UNIQUE,
  122. `group_id` INTEGER,
  123. `image` TEXT,
  124. `default` INTEGER
  125. );');
  126. $categories = $createDB->query('CREATE TABLE `categories` (
  127. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  128. `order` INTEGER,
  129. `category` TEXT UNIQUE,
  130. `category_id` INTEGER,
  131. `image` TEXT,
  132. `default` INTEGER
  133. );');
  134. // Create Tabs
  135. $tabs = $createDB->query('CREATE TABLE `tabs` (
  136. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  137. `order` INTEGER,
  138. `category_id` INTEGER,
  139. `name` TEXT,
  140. `url` TEXT,
  141. `url_local` TEXT,
  142. `default` INTEGER,
  143. `enabled` INTEGER,
  144. `group_id` INTEGER,
  145. `image` TEXT,
  146. `type` INTEGER,
  147. `splash` INTEGER,
  148. `ping` INTEGER,
  149. `ping_url` TEXT
  150. );');
  151. // Create Options
  152. $options = $createDB->query('CREATE TABLE `options` (
  153. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  154. `name` TEXT UNIQUE,
  155. `value` TEXT
  156. );');
  157. // Create Invites
  158. $invites = $createDB->query('CREATE TABLE `invites` (
  159. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  160. `code` TEXT UNIQUE,
  161. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  162. `email` TEXT,
  163. `username` TEXT,
  164. `dateused` TIMESTAMP,
  165. `usedby` TEXT,
  166. `ip` TEXT,
  167. `valid` TEXT,
  168. `type` TEXT
  169. );');
  170. return true;
  171. } catch (Dibi\Exception $e) {
  172. return false;
  173. }
  174. }
  175. // Upgrade Database
  176. function updateDB($path, $filename, $oldVerNum = false)
  177. {
  178. try {
  179. $connect = new Dibi\Connection([
  180. 'driver' => 'sqlite3',
  181. 'database' => $path.$filename,
  182. ]);
  183. // Cache current DB
  184. $cache = array();
  185. foreach ($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  186. foreach ($connect->query('SELECT * FROM '.$table['name'].';') as $key => $row) {
  187. foreach ($row as $k => $v) {
  188. if (is_string($k)) {
  189. $cache[$table['name']][$key][$k] = $v;
  190. }
  191. }
  192. }
  193. }
  194. $connect->disconnect();
  195. } catch (Dibi\Exception $e) {
  196. return $e;
  197. }
  198. // Remove Current Database
  199. $pathDigest = pathinfo($path.$filename);
  200. if (file_exists($path.$filename)) {
  201. copy($path.$filename, $pathDigest['dirname'].'/'.$pathDigest['filename'].'['.date('Y-m-d_H-i-s').']'.($oldVerNum?'['.$oldVerNum.']':'').'.bak.db');
  202. unlink($path.$filename);
  203. }
  204. // Create New Database
  205. $success = createDB($path, $filename);
  206. try {
  207. $GLOBALS['connect'] = new Dibi\Connection([
  208. 'driver' => 'sqlite3',
  209. 'database' => $path.$filename,
  210. ]);
  211. // Restore Items
  212. if ($success) {
  213. foreach ($cache as $table => $tableData) {
  214. if ($tableData) {
  215. $queryBase = 'INSERT INTO '.$table.' (`'.implode('`,`', array_keys(current($tableData))).'`) values ';
  216. $insertValues = array();
  217. reset($tableData);
  218. foreach ($tableData as $key => $value) {
  219. $insertValues[] = '('.implode(',', array_map(function ($d) {
  220. return (isset($d)?str_replace('\/', '/', json_encode($d)):'null');
  221. }, $value)).')';
  222. }
  223. $GLOBALS['connect']->query($queryBase.implode(',', $insertValues).';');
  224. }
  225. }
  226. }
  227. updateConfig(array('configVersion'=>$GLOBALS['installedVersion']));
  228. return true;
  229. } catch (Dibi\Exception $e) {
  230. return $e;
  231. }
  232. }
  233. function createFirstAdmin($path, $filename, $username, $password, $email)
  234. {
  235. try {
  236. $createDB = new Dibi\Connection([
  237. 'driver' => 'sqlite3',
  238. 'database' => $path.$filename,
  239. ]);
  240. $userInfo = [
  241. 'username' => $username,
  242. 'password' => password_hash($password, PASSWORD_BCRYPT),
  243. 'email' => $email,
  244. 'group' => 'Admin',
  245. 'group_id' => 0,
  246. 'image' => gravatar($email),
  247. 'register_date' => $GLOBALS['currentTime'],
  248. ];
  249. $groupInfo0 = [
  250. 'group' => 'Admin',
  251. 'group_id' => 0,
  252. 'default' => false,
  253. 'image' => 'plugins/images/groups/admin.png',
  254. ];
  255. $groupInfo1 = [
  256. 'group' => 'Co-Admin',
  257. 'group_id' => 1,
  258. 'default' => false,
  259. 'image' => 'plugins/images/groups/coadmin.png',
  260. ];
  261. $groupInfo2 = [
  262. 'group' => 'Super User',
  263. 'group_id' => 2,
  264. 'default' => false,
  265. 'image' => 'plugins/images/groups/superuser.png',
  266. ];
  267. $groupInfo3 = [
  268. 'group' => 'Power User',
  269. 'group_id' => 3,
  270. 'default' => false,
  271. 'image' => 'plugins/images/groups/poweruser.png',
  272. ];
  273. $groupInfo4 = [
  274. 'group' => 'User',
  275. 'group_id' => 4,
  276. 'default' => true,
  277. 'image' => 'plugins/images/groups/user.png',
  278. ];
  279. $groupInfoGuest = [
  280. 'group' => 'Guest',
  281. 'group_id' => 999,
  282. 'default' => false,
  283. 'image' => 'plugins/images/groups/guest.png',
  284. ];
  285. $settingsInfo = [
  286. 'order' => 1,
  287. 'category_id' => 0,
  288. 'name' => 'Settings',
  289. 'url' => 'api/?v1/settings/page',
  290. 'default' => false,
  291. 'enabled' => true,
  292. 'group_id' => 1,
  293. 'image' => 'fontawesome::cog',
  294. 'type' => 0
  295. ];
  296. $homepageInfo = [
  297. 'order' => 2,
  298. 'category_id' => 0,
  299. 'name' => 'Homepage',
  300. 'url' => 'api/?v1/homepage/page',
  301. 'default' => false,
  302. 'enabled' => false,
  303. 'group_id' => 4,
  304. 'image' => 'fontawesome::home',
  305. 'type' => 0
  306. ];
  307. $unsortedInfo = [
  308. 'order' => 1,
  309. 'category' => 'Unsorted',
  310. 'category_id' => 0,
  311. 'image' => 'plugins/images/categories/unsorted.png',
  312. 'default' => true
  313. ];
  314. $createDB->query('INSERT INTO [users]', $userInfo);
  315. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  316. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  317. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  318. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  319. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  320. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  321. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  322. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  323. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  324. return true;
  325. } catch (Dibi\Exception $e) {
  326. writeLog('error', 'Wizard Function - Error ['.$e.']', 'Wizard');
  327. return false;
  328. }
  329. }
  330. function defaultUserGroup()
  331. {
  332. try {
  333. $connect = new Dibi\Connection([
  334. 'driver' => 'sqlite3',
  335. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  336. ]);
  337. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  338. return $all;
  339. } catch (Dibi\Exception $e) {
  340. return false;
  341. }
  342. }
  343. function defaulTabCategory()
  344. {
  345. try {
  346. $connect = new Dibi\Connection([
  347. 'driver' => 'sqlite3',
  348. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  349. ]);
  350. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  351. return $all;
  352. } catch (Dibi\Exception $e) {
  353. return false;
  354. }
  355. }
  356. function getGuest()
  357. {
  358. if (isset($GLOBALS['dbLocation'])) {
  359. try {
  360. $connect = new Dibi\Connection([
  361. 'driver' => 'sqlite3',
  362. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  363. ]);
  364. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  365. return $all;
  366. } catch (Dibi\Exception $e) {
  367. return false;
  368. }
  369. } else {
  370. return array(
  371. 'group' => 'Guest',
  372. 'group_id' => 999,
  373. 'image' => 'plugins/images/groups/guest.png'
  374. );
  375. }
  376. }
  377. function adminEditGroup($array)
  378. {
  379. switch ($array['data']['action']) {
  380. case 'changeDefaultGroup':
  381. try {
  382. $connect = new Dibi\Connection([
  383. 'driver' => 'sqlite3',
  384. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  385. ]);
  386. $connect->query('UPDATE groups SET `default` = 0');
  387. $connect->query('
  388. UPDATE groups SET', [
  389. 'default' => 1
  390. ], '
  391. WHERE id=?', $array['data']['id']);
  392. writeLog('success', 'Group Management Function - Changed Default Group from ['.$array['data']['oldGroupName'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  393. return true;
  394. } catch (Dibi\Exception $e) {
  395. return false;
  396. }
  397. break;
  398. case 'deleteUserGroup':
  399. try {
  400. $connect = new Dibi\Connection([
  401. 'driver' => 'sqlite3',
  402. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  403. ]);
  404. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  405. writeLog('success', 'Group Management Function - Deleted Group ['.$array['data']['groupName'].']', $GLOBALS['organizrUser']['username']);
  406. return true;
  407. } catch (Dibi\Exception $e) {
  408. return false;
  409. }
  410. break;
  411. case 'addUserGroup':
  412. try {
  413. $connect = new Dibi\Connection([
  414. 'driver' => 'sqlite3',
  415. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  416. ]);
  417. $newGroup = [
  418. 'group' => $array['data']['newGroupName'],
  419. 'group_id' => $array['data']['newGroupID'],
  420. 'default' => false,
  421. 'image' => $array['data']['newGroupImage'],
  422. ];
  423. $connect->query('INSERT INTO [groups]', $newGroup);
  424. writeLog('success', 'Group Management Function - Added Group ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  425. return true;
  426. } catch (Dibi\Exception $e) {
  427. return false;
  428. }
  429. break;
  430. case 'editUserGroup':
  431. try {
  432. $connect = new Dibi\Connection([
  433. 'driver' => 'sqlite3',
  434. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  435. ]);
  436. $connect->query('
  437. UPDATE groups SET', [
  438. 'group' => $array['data']['groupName'],
  439. 'image' => $array['data']['groupImage'],
  440. ], '
  441. WHERE id=?', $array['data']['id']);
  442. writeLog('success', 'Group Management Function - Edited Group Info for ['.$array['data']['oldGroupName'].']', $GLOBALS['organizrUser']['username']);
  443. return true;
  444. } catch (Dibi\Exception $e) {
  445. return false;
  446. }
  447. break;
  448. default:
  449. # code...
  450. break;
  451. }
  452. }
  453. function adminEditUser($array)
  454. {
  455. switch ($array['data']['action']) {
  456. case 'changeGroup':
  457. try {
  458. $connect = new Dibi\Connection([
  459. 'driver' => 'sqlite3',
  460. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  461. ]);
  462. $connect->query('
  463. UPDATE users SET', [
  464. 'group' => $array['data']['newGroupName'],
  465. 'group_id' => $array['data']['newGroupID'],
  466. ], '
  467. WHERE id=?', $array['data']['id']);
  468. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  469. return true;
  470. } catch (Dibi\Exception $e) {
  471. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  472. return false;
  473. }
  474. break;
  475. case 'editUser':
  476. try {
  477. $connect = new Dibi\Connection([
  478. 'driver' => 'sqlite3',
  479. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  480. ]);
  481. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  482. $connect->query('
  483. UPDATE users SET', [
  484. 'username' => $array['data']['username'],
  485. 'email' => $array['data']['email'],
  486. ], '
  487. WHERE id=?', $array['data']['id']);
  488. if (!empty($array['data']['password'])) {
  489. $connect->query('
  490. UPDATE users SET', [
  491. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  492. ], '
  493. WHERE id=?', $array['data']['id']);
  494. }
  495. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s info was changed', $GLOBALS['organizrUser']['username']);
  496. return true;
  497. } else {
  498. return false;
  499. }
  500. } catch (Dibi\Exception $e) {
  501. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  502. return false;
  503. }
  504. break;
  505. case 'addNewUser':
  506. $defaults = defaultUserGroup();
  507. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  508. writeLog('success', 'Create User Function - Acount created for ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  509. return true;
  510. } else {
  511. writeLog('error', 'Registration Function - An error occured', $GLOBALS['organizrUser']['username']);
  512. return 'username taken';
  513. }
  514. break;
  515. case 'deleteUser':
  516. try {
  517. $connect = new Dibi\Connection([
  518. 'driver' => 'sqlite3',
  519. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  520. ]);
  521. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  522. writeLog('success', 'User Management Function - Deleted User ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  523. return true;
  524. } catch (Dibi\Exception $e) {
  525. return false;
  526. }
  527. break;
  528. default:
  529. # code...
  530. break;
  531. }
  532. }
  533. function editTabs($array)
  534. {
  535. switch ($array['data']['action']) {
  536. case 'changeGroup':
  537. try {
  538. $connect = new Dibi\Connection([
  539. 'driver' => 'sqlite3',
  540. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  541. ]);
  542. $connect->query('
  543. UPDATE tabs SET', [
  544. 'group_id' => $array['data']['newGroupID'],
  545. ], '
  546. WHERE id=?', $array['data']['id']);
  547. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s group was changed to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  548. return true;
  549. } catch (Dibi\Exception $e) {
  550. return false;
  551. }
  552. break;
  553. case 'changeCategory':
  554. try {
  555. $connect = new Dibi\Connection([
  556. 'driver' => 'sqlite3',
  557. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  558. ]);
  559. $connect->query('
  560. UPDATE tabs SET', [
  561. 'category_id' => $array['data']['newCategoryID'],
  562. ], '
  563. WHERE id=?', $array['data']['id']);
  564. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s category was changed to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  565. return true;
  566. } catch (Dibi\Exception $e) {
  567. return false;
  568. }
  569. break;
  570. case 'changeType':
  571. try {
  572. $connect = new Dibi\Connection([
  573. 'driver' => 'sqlite3',
  574. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  575. ]);
  576. $connect->query('
  577. UPDATE tabs SET', [
  578. 'type' => $array['data']['newTypeID'],
  579. ], '
  580. WHERE id=?', $array['data']['id']);
  581. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s type was changed to ['.$array['data']['newTypeName'].']', $GLOBALS['organizrUser']['username']);
  582. return true;
  583. } catch (Dibi\Exception $e) {
  584. return false;
  585. }
  586. break;
  587. case 'changeEnabled':
  588. try {
  589. $connect = new Dibi\Connection([
  590. 'driver' => 'sqlite3',
  591. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  592. ]);
  593. $connect->query('
  594. UPDATE tabs SET', [
  595. 'enabled' => $array['data']['tabEnabled'],
  596. ], '
  597. WHERE id=?', $array['data']['id']);
  598. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s enable status was changed to ['.$array['data']['tabEnabledWord'].']', $GLOBALS['organizrUser']['username']);
  599. return true;
  600. } catch (Dibi\Exception $e) {
  601. return false;
  602. }
  603. break;
  604. case 'changeSplash':
  605. try {
  606. $connect = new Dibi\Connection([
  607. 'driver' => 'sqlite3',
  608. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  609. ]);
  610. $connect->query('
  611. UPDATE tabs SET', [
  612. 'splash' => $array['data']['tabSplash'],
  613. ], '
  614. WHERE id=?', $array['data']['id']);
  615. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s splash status was changed to ['.$array['data']['tabSplashWord'].']', $GLOBALS['organizrUser']['username']);
  616. return true;
  617. } catch (Dibi\Exception $e) {
  618. return false;
  619. }
  620. break;
  621. case 'changeDefault':
  622. try {
  623. $connect = new Dibi\Connection([
  624. 'driver' => 'sqlite3',
  625. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  626. ]);
  627. $connect->query('UPDATE tabs SET `default` = 0');
  628. $connect->query('
  629. UPDATE tabs SET', [
  630. 'default' => 1
  631. ], '
  632. WHERE id=?', $array['data']['id']);
  633. writeLog('success', 'Tab Editor Function - Changed Default Tab to ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  634. return true;
  635. } catch (Dibi\Exception $e) {
  636. return false;
  637. }
  638. break;
  639. case 'deleteTab':
  640. try {
  641. $connect = new Dibi\Connection([
  642. 'driver' => 'sqlite3',
  643. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  644. ]);
  645. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  646. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  647. return true;
  648. } catch (Dibi\Exception $e) {
  649. return false;
  650. }
  651. break;
  652. case 'editTab':
  653. try {
  654. $connect = new Dibi\Connection([
  655. 'driver' => 'sqlite3',
  656. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  657. ]);
  658. $connect->query('
  659. UPDATE tabs SET', [
  660. 'name' => $array['data']['tabName'],
  661. 'url' => $array['data']['tabURL'],
  662. 'image' => $array['data']['tabImage'],
  663. ], '
  664. WHERE id=?', $array['data']['id']);
  665. writeLog('success', 'Tab Editor Function - Edited Tab Info for ['.$array['data']['tabName'].']', $GLOBALS['organizrUser']['username']);
  666. return true;
  667. } catch (Dibi\Exception $e) {
  668. return false;
  669. }
  670. case 'changeOrder':
  671. try {
  672. $connect = new Dibi\Connection([
  673. 'driver' => 'sqlite3',
  674. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  675. ]);
  676. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  677. if ($value['order'] != $value['originalOrder']) {
  678. $connect->query('
  679. UPDATE tabs SET', [
  680. 'order' => $value['order'],
  681. ], '
  682. WHERE id=?', $value['id']);
  683. writeLog('success', 'Tab Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  684. }
  685. }
  686. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  687. return true;
  688. } catch (Dibi\Exception $e) {
  689. return false;
  690. }
  691. break;
  692. case 'addNewTab':
  693. try {
  694. $default = defaulTabCategory()['category_id'];
  695. $connect = new Dibi\Connection([
  696. 'driver' => 'sqlite3',
  697. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  698. ]);
  699. $newTab = [
  700. 'order' => $array['data']['tabOrder'],
  701. 'category_id' => $default,
  702. 'name' => $array['data']['tabName'],
  703. 'url' => $array['data']['tabURL'],
  704. 'default' => $array['data']['tabDefault'],
  705. 'enabled' => 1,
  706. 'group_id' => $array['data']['tabGroupID'],
  707. 'image' => $array['data']['tabImage'],
  708. 'type' => $array['data']['tabType']
  709. ];
  710. $connect->query('INSERT INTO [tabs]', $newTab);
  711. writeLog('success', 'Tab Editor Function - Created Tab for: '.$array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  712. return true;
  713. } catch (Dibi\Exception $e) {
  714. return false;
  715. }
  716. break;
  717. default:
  718. # code...
  719. break;
  720. }
  721. }
  722. function editCategories($array)
  723. {
  724. switch ($array['data']['action']) {
  725. case 'changeDefault':
  726. try {
  727. $connect = new Dibi\Connection([
  728. 'driver' => 'sqlite3',
  729. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  730. ]);
  731. $connect->query('UPDATE categories SET `default` = 0');
  732. $connect->query('
  733. UPDATE categories SET', [
  734. 'default' => 1
  735. ], '
  736. WHERE id=?', $array['data']['id']);
  737. writeLog('success', 'Category Editor Function - Changed Default Category from ['.$array['data']['oldCategoryName'].'] to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  738. return true;
  739. } catch (Dibi\Exception $e) {
  740. return false;
  741. }
  742. break;
  743. case 'deleteCategory':
  744. try {
  745. $connect = new Dibi\Connection([
  746. 'driver' => 'sqlite3',
  747. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  748. ]);
  749. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  750. writeLog('success', 'Category Editor Function - Deleted Category ['.$array['data']['category'].']', $GLOBALS['organizrUser']['username']);
  751. return true;
  752. } catch (Dibi\Exception $e) {
  753. return false;
  754. }
  755. break;
  756. case 'addNewCategory':
  757. try {
  758. $connect = new Dibi\Connection([
  759. 'driver' => 'sqlite3',
  760. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  761. ]);
  762. $newCategory = [
  763. 'category' => $array['data']['categoryName'],
  764. 'order' => $array['data']['categoryOrder'],
  765. 'category_id' => $array['data']['categoryID'],
  766. 'default' => false,
  767. 'image' => $array['data']['categoryImage'],
  768. ];
  769. $connect->query('INSERT INTO [categories]', $newCategory);
  770. writeLog('success', 'Category Editor Function - Added Category ['.$array['data']['categoryName'].']', $GLOBALS['organizrUser']['username']);
  771. return true;
  772. } catch (Dibi\Exception $e) {
  773. return $e;
  774. }
  775. break;
  776. case 'editCategory':
  777. try {
  778. $connect = new Dibi\Connection([
  779. 'driver' => 'sqlite3',
  780. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  781. ]);
  782. $connect->query('
  783. UPDATE categories SET', [
  784. 'category' => $array['data']['name'],
  785. 'image' => $array['data']['image'],
  786. ], '
  787. WHERE id=?', $array['data']['id']);
  788. writeLog('success', 'Category Editor Function - Edited Category Info for ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  789. return true;
  790. } catch (Dibi\Exception $e) {
  791. return false;
  792. }
  793. break;
  794. case 'changeOrder':
  795. try {
  796. $connect = new Dibi\Connection([
  797. 'driver' => 'sqlite3',
  798. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  799. ]);
  800. foreach ($array['data']['categories']['category'] as $key => $value) {
  801. if ($value['order'] != $value['originalOrder']) {
  802. $connect->query('
  803. UPDATE categories SET', [
  804. 'order' => $value['order'],
  805. ], '
  806. WHERE id=?', $value['id']);
  807. writeLog('success', 'Category Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  808. }
  809. }
  810. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  811. return true;
  812. } catch (Dibi\Exception $e) {
  813. return false;
  814. }
  815. break;
  816. default:
  817. # code...
  818. break;
  819. }
  820. }
  821. function allUsers()
  822. {
  823. try {
  824. $connect = new Dibi\Connection([
  825. 'driver' => 'sqlite3',
  826. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  827. ]);
  828. $users = $connect->fetchAll('SELECT * FROM users');
  829. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  830. foreach ($users as $k => $v) {
  831. // clear password from array
  832. unset($users[$k]['password']);
  833. }
  834. $all['users'] = $users;
  835. $all['groups'] = $groups;
  836. return $all;
  837. } catch (Dibi\Exception $e) {
  838. return false;
  839. }
  840. }
  841. function usernameTaken($username, $email)
  842. {
  843. try {
  844. $connect = new Dibi\Connection([
  845. 'driver' => 'sqlite3',
  846. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  847. ]);
  848. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  849. return ($all) ? true : false;
  850. } catch (Dibi\Exception $e) {
  851. return false;
  852. }
  853. }
  854. function usernameTakenExcept($username, $email, $id)
  855. {
  856. try {
  857. $connect = new Dibi\Connection([
  858. 'driver' => 'sqlite3',
  859. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  860. ]);
  861. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  862. return ($all) ? true : false;
  863. } catch (Dibi\Exception $e) {
  864. return false;
  865. }
  866. }
  867. function createUser($username, $password, $defaults, $email=null)
  868. {
  869. $email = ($email) ? $email : random_ascii_string(10).'@placeholder.eml';
  870. try {
  871. if (!usernameTaken($username, $email)) {
  872. $createDB = new Dibi\Connection([
  873. 'driver' => 'sqlite3',
  874. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  875. ]);
  876. $userInfo = [
  877. 'username' => $username,
  878. 'password' => password_hash($password, PASSWORD_BCRYPT),
  879. 'email' => $email,
  880. 'group' => $defaults['group'],
  881. 'group_id' => $defaults['group_id'],
  882. 'image' => gravatar($email),
  883. 'register_date' => $GLOBALS['currentTime'],
  884. ];
  885. $createDB->query('INSERT INTO [users]', $userInfo);
  886. return true;
  887. } else {
  888. return false;
  889. }
  890. } catch (Dibi\Exception $e) {
  891. return false;
  892. }
  893. }
  894. function allTabs()
  895. {
  896. if (file_exists('config'.DIRECTORY_SEPARATOR.'config.php')) {
  897. try {
  898. $connect = new Dibi\Connection([
  899. 'driver' => 'sqlite3',
  900. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  901. ]);
  902. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  903. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  904. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  905. return $all;
  906. } catch (Dibi\Exception $e) {
  907. return false;
  908. }
  909. }
  910. }
  911. function allGroups()
  912. {
  913. if (file_exists('config'.DIRECTORY_SEPARATOR.'config.php')) {
  914. try {
  915. $connect = new Dibi\Connection([
  916. 'driver' => 'sqlite3',
  917. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  918. ]);
  919. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  920. return $all;
  921. } catch (Dibi\Exception $e) {
  922. return false;
  923. }
  924. }
  925. }
  926. function loadTabs()
  927. {
  928. if (file_exists('config'.DIRECTORY_SEPARATOR.'config.php')) {
  929. try {
  930. $connect = new Dibi\Connection([
  931. 'driver' => 'sqlite3',
  932. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  933. ]);
  934. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` DESC', $GLOBALS['organizrUser']['groupID']);
  935. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  936. $all['tabs'] = $tabs;
  937. foreach ($tabs as $k => $v) {
  938. $v['access_url'] = isset($v['url_local']) && $_SERVER['SERVER_ADDR'] == userIP() ? $v['url_local'] : $v['url'];
  939. }
  940. $count = array_map(function ($element) {
  941. return $element['category_id'];
  942. }, $tabs);
  943. $count = (array_count_values($count));
  944. foreach ($categories as $k => $v) {
  945. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  946. }
  947. $all['categories'] = $categories;
  948. return $all;
  949. } catch (Dibi\Exception $e) {
  950. return false;
  951. }
  952. }
  953. }