index.php 57 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926
  1. <?php
  2. /**
  3. * @apiDefine UserNotAuthorizedError
  4. *
  5. * @apiError UserNotAuthorized The user is not authorized or Token not valid
  6. *
  7. * @apiErrorExample Error-Response:
  8. * HTTP/1.1 401 Not Authorized
  9. * {
  10. * "status": "error",
  11. * "statusText": "API/Token invalid or not set",
  12. * "data": null
  13. * }
  14. */
  15. /**
  16. * @apiDefine DataBooleanSuccess
  17. * @apiSuccess {Boolean} data Output Boolean.
  18. * @apiSuccessExample Success-Response:
  19. * HTTP/1.1 200 OK
  20. * {
  21. * "status": "success",
  22. * "statusText": "success",
  23. * "data": true
  24. * }
  25. *
  26. */
  27. /**
  28. * @apiDefine DataJSONSuccess
  29. * @apiSuccess {JSON} data Output JSON.
  30. * @apiSuccessExample Success-Response:
  31. * HTTP/1.1 200 OK
  32. * {
  33. * "status": "success",
  34. * "statusText": "success",
  35. * "data": { **JSON** }
  36. * }
  37. *
  38. */
  39. /**
  40. * @apiDefine DataHTMLSuccess
  41. * @apiSuccess {String} data Output of Page.
  42. *
  43. * @apiSuccessExample Success-Response:
  44. * HTTP/1.1 200 OK
  45. * {
  46. * "status": "success",
  47. * "statusText": "success",
  48. * "data": "<html>html encoded elements</html>"
  49. * }
  50. *
  51. */
  52. /**
  53. * @apiDefine admin Admin or API Key Access Only
  54. * Only the Admin/Co-Admin and API Key have access to this endpoint
  55. */
  56. //include functions
  57. require_once 'functions.php';
  58. // Include all pages files
  59. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'pages' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  60. require_once $filename;
  61. }
  62. // Include all custom pages files
  63. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'pages' . DIRECTORY_SEPARATOR . 'custom' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  64. require_once $filename;
  65. }
  66. // Include all plugin files
  67. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'plugins' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  68. require_once $filename;
  69. }
  70. //Set result array
  71. $result = array();
  72. //Get request method
  73. $method = $_SERVER['REQUEST_METHOD'];
  74. $pretty = isset($_GET['pretty']) ? true : false;
  75. reset($_GET);
  76. $function = (key($_GET) ? str_replace("/", "_", key($_GET)) : false);
  77. //Exit if $function is blank
  78. if ($function === false) {
  79. $result['status'] = "error";
  80. $result['statusText'] = "No API Path Supplied";
  81. exit(json_encode($result));
  82. }
  83. $approvedFunctionsBypass = array(
  84. 'v1_upgrade',
  85. 'v1_update',
  86. 'v1_force',
  87. 'v1_auth',
  88. 'v1_wizard_config',
  89. 'v1_login',
  90. 'v1_wizard_path',
  91. 'v1_login_api'
  92. );
  93. if (!in_array($function, $approvedFunctionsBypass)) {
  94. if (isApprovedRequest($method) === false) {
  95. $result['status'] = "error";
  96. $result['statusText'] = "Not Authorized";
  97. http_response_code(401);
  98. writeLog('success', 'Killed Attack From [' . (isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : 'No Referer') . ']', $GLOBALS['organizrUser']['username']);
  99. exit(json_encode($result));
  100. }
  101. }
  102. $result['request'] = key($_GET);
  103. $result['params'] = $_POST;
  104. //Custom Page Check
  105. if (strpos($function, 'v1_custom_page_') !== false) {
  106. $endpoint = explode('v1_custom_page_', $function)[1];
  107. $function = 'v1_custom_page';
  108. }
  109. switch ($function) {
  110. case 'v1_settings_page':
  111. switch ($method) {
  112. /**
  113. * @api {get} v1/settings/page Get Admin Settings
  114. * @apiVersion 1.0.0
  115. * @apiName GetSettingsPage
  116. * @apiGroup Pages
  117. * @apiUse DataBooleanSuccess
  118. * @apiUse UserNotAuthorizedError
  119. */
  120. case 'GET':
  121. if (qualifyRequest(1)) {
  122. $result['status'] = 'success';
  123. $result['statusText'] = 'success';
  124. $result['data'] = $pageSettings;
  125. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  126. } else {
  127. $result['status'] = 'error';
  128. $result['statusText'] = 'API/Token invalid or not set';
  129. $result['data'] = null;
  130. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  131. }
  132. break;
  133. default:
  134. $result['status'] = 'error';
  135. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  136. break;
  137. }
  138. break;
  139. case 'v1_homepage_page':
  140. switch ($method) {
  141. /**
  142. * @api {get} v1/homepage/page Get Homepage
  143. * @apiVersion 1.0.0
  144. * @apiName GetHomepagePage
  145. * @apiGroup Pages
  146. * @apiUse DataHTMLSuccess
  147. * @apiUse UserNotAuthorizedError
  148. */
  149. case 'GET':
  150. $result['status'] = 'success';
  151. $result['statusText'] = 'success';
  152. $result['data'] = $pageHomepage;
  153. break;
  154. default:
  155. $result['status'] = 'error';
  156. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  157. break;
  158. }
  159. break;
  160. case 'v1_settings_plugins':
  161. switch ($method) {
  162. /**
  163. * @api {get} v1/settings/plugins Get Plugins
  164. * @apiVersion 1.0.0
  165. * @apiName GetPluginsPage
  166. * @apiGroup Pages
  167. * @apiUse DataHTMLSuccess
  168. * @apiUse UserNotAuthorizedError
  169. */
  170. case 'GET':
  171. if (qualifyRequest(1)) {
  172. $result['status'] = 'success';
  173. $result['statusText'] = 'success';
  174. $result['data'] = $pageSettingsPlugins;
  175. } else {
  176. $result['status'] = 'error';
  177. $result['statusText'] = 'API/Token invalid or not set';
  178. $result['data'] = null;
  179. }
  180. break;
  181. default:
  182. $result['status'] = 'error';
  183. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  184. break;
  185. }
  186. break;
  187. case 'v1_settings_tab_editor_homepage':
  188. switch ($method) {
  189. /**
  190. * @api {get} v1/settings/tab/editor/homepage Get Homepage Settings
  191. * @apiVersion 1.0.0
  192. * @apiName GetSettingsTabEditorHomepagePage
  193. * @apiGroup Pages
  194. * @apiUse DataHTMLSuccess
  195. * @apiUse UserNotAuthorizedError
  196. */
  197. case 'GET':
  198. if (qualifyRequest(1)) {
  199. $result['status'] = 'success';
  200. $result['statusText'] = 'success';
  201. $result['data'] = $pageSettingsTabEditorHomepage;
  202. } else {
  203. $result['status'] = 'error';
  204. $result['statusText'] = 'API/Token invalid or not set';
  205. $result['data'] = null;
  206. }
  207. break;
  208. default:
  209. $result['status'] = 'error';
  210. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  211. break;
  212. }
  213. break;
  214. case 'v1_settings_tab_editor_homepage_order':
  215. switch ($method) {
  216. /**
  217. * @api {get} v1/settings/tab/editor/homepage Get Homepage Order
  218. * @apiVersion 1.0.0
  219. * @apiName GetSettingsTabEditorHomepageOrderPage
  220. * @apiGroup Pages
  221. * @apiUse DataHTMLSuccess
  222. * @apiUse UserNotAuthorizedError
  223. */
  224. case 'GET':
  225. if (qualifyRequest(1)) {
  226. $result['status'] = 'success';
  227. $result['statusText'] = 'success';
  228. $result['data'] = $pageSettingsTabEditorHomepageOrder;
  229. } else {
  230. $result['status'] = 'error';
  231. $result['statusText'] = 'API/Token invalid or not set';
  232. $result['data'] = null;
  233. }
  234. break;
  235. default:
  236. $result['status'] = 'error';
  237. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  238. break;
  239. }
  240. break;
  241. case 'v1_settings_homepage_list':
  242. switch ($method) {
  243. /**
  244. * @api {get} v1/settings/homepage/list Get Homepage Settings
  245. * @apiVersion 1.0.0
  246. * @apiName GetHomepageSettigns
  247. * @apiGroup Homepage
  248. * @apiSuccess {String} data Output of all Homepage Settings.
  249. * @apiSuccessExample Success-Response:
  250. * HTTP/1.1 200 OK
  251. * {
  252. * "status": "success",
  253. * "statusText": "success",
  254. * "data": [{
  255. * "name": "HealthChecks",
  256. * "enabled": true,
  257. * "image": "plugins\/images\/tabs\/healthchecks.png",
  258. * "category": "Monitor",
  259. * "settings": {
  260. * "Enable": [
  261. * {
  262. * "type": "switch",
  263. * "name": "homepageHealthChecksEnabled",
  264. * "label": "Enable",
  265. * "value": true
  266. * }, {
  267. * "type": "select",
  268. * "name": "homepageHealthChecksAuth",
  269. * "label": "Minimum Authentication",
  270. * "value": "1",
  271. * "options": [
  272. * {
  273. * "name": "Admin",
  274. * "value": 0
  275. * }, {
  276. * "name": "Co-Admin",
  277. * "value": 1
  278. * }, {
  279. * "name": "Super User",
  280. * "value": 2
  281. * }, {
  282. * "name": "Power User",
  283. * "value": 3
  284. * }, {
  285. * "name": "User",
  286. * "value": 4
  287. * }, {
  288. * "name": "temp again",
  289. * "value": 5
  290. * }, {
  291. * "name": "GuestAccts",
  292. * "value": 999
  293. * }
  294. * ]
  295. * }
  296. * ],
  297. * "Connection": [
  298. * {
  299. * "type": "input",
  300. * "name": "healthChecksURL",
  301. * "label": "URL",
  302. * "value": "https://healthchecks.io/api/v1/checks/",
  303. * "help": "URL for HealthChecks API",
  304. * "placeholder": "HealthChecks API URL"
  305. * }, {
  306. * "type": "password-alt",
  307. * "name": "healthChecksToken",
  308. * "label": "Token",
  309. * "value": "TOKENHERE"
  310. * }
  311. * ],
  312. * "Misc Options": [
  313. * {
  314. * "type": "input",
  315. * "name": "healthChecksTags",
  316. * "label": "Tags",
  317. * "value": "",
  318. * "help": "Pull only checks with this tag - Blank for all",
  319. * "placeholder": "Multiple tags using CSV - tag1,tag2"
  320. * }, {
  321. * "type": "select",
  322. * "name": "homepageHealthChecksRefresh",
  323. * "label": "Refresh Seconds",
  324. * "value": "3600000",
  325. * "options": [
  326. * {
  327. * "name": "5",
  328. * "value": "5000"
  329. * }, {
  330. * "name": "10",
  331. * "value": "10000"
  332. * }, {
  333. * "name": "15",
  334. * "value": "15000"
  335. * }, {
  336. * "name": "30",
  337. * "value": "30000"
  338. * }, {
  339. * "name": "60 [1 Minute]",
  340. * "value": "60000"
  341. * }, {
  342. * "name": "300 [5 Minutes]",
  343. * "value": "300000"
  344. * }, {
  345. * "name": "600 [10 Minutes]",
  346. * "value": "600000"
  347. * }, {
  348. * "name": "900 [15 Minutes]",
  349. * "value": "900000"
  350. * }, {
  351. * "name": "1800 [30 Minutes]",
  352. * "value": "1800000"
  353. * }, {
  354. * "name": "3600 [1 Hour]",
  355. * "value": "3600000"
  356. * }
  357. * ]
  358. * }
  359. * ]
  360. * }]
  361. * }
  362. * @apiUse UserNotAuthorizedError
  363. */
  364. case 'GET':
  365. if (qualifyRequest(1)) {
  366. $result['status'] = 'success';
  367. $result['statusText'] = 'success';
  368. $result['data'] = getHomepageList();
  369. } else {
  370. $result['status'] = 'error';
  371. $result['statusText'] = 'API/Token invalid or not set';
  372. $result['data'] = null;
  373. }
  374. break;
  375. default:
  376. $result['status'] = 'error';
  377. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  378. break;
  379. }
  380. break;
  381. case 'v1_settings_plugins_list':
  382. /**
  383. * @api {get} v1/settings/plugins/list Get List of Plugins
  384. * @apiVersion 1.0.0
  385. * @apiName GetPlugins
  386. * @apiGroup Plugins
  387. * @apiSuccess {String} data Output plugins list.
  388. * @apiSuccessExample Success-Response:
  389. * HTTP/1.1 200 OK
  390. * {
  391. * "status": "success",
  392. * "statusText": "success",
  393. * "data": {
  394. * "chat": {
  395. * "name": "Chat",
  396. * "author": "CauseFX",
  397. * "category": "Utilities",
  398. * "link": "",
  399. * "license": "personal,business",
  400. * "idPrefix": "CHAT",
  401. * "configPrefix": "CHAT",
  402. * "version": "1.0.0",
  403. * "image": "plugins/images/chat.png",
  404. * "settings": true,
  405. * "homepage": false,
  406. * "enabled": true
  407. * }
  408. * }
  409. * }
  410. * @apiUse UserNotAuthorizedError
  411. */
  412. /**
  413. * @api {post} v1/settings/plugins/list Toggle Plugin
  414. * @apiVersion 1.0.0
  415. * @apiName TogglePlugin
  416. * @apiGroup Plugins
  417. * @apiParam {Object} data nested data object.
  418. * @apiParam {String} data[action] enable/disable.
  419. * @apiParam {String} data[name] Name of Plugin.
  420. * @apiParam {String} data[configName] configName i.e. CHAT-enabled.
  421. * @apiUse DataBooleanSuccess
  422. * @apiUse UserNotAuthorizedError
  423. */
  424. switch ($method) {
  425. case 'GET':
  426. if (qualifyRequest(1)) {
  427. $result['status'] = 'success';
  428. $result['statusText'] = 'success';
  429. $result['data'] = getPlugins();
  430. } else {
  431. $result['status'] = 'error';
  432. $result['statusText'] = 'API/Token invalid or not set';
  433. $result['data'] = null;
  434. }
  435. break;
  436. case 'POST':
  437. if (qualifyRequest(1)) {
  438. $result['status'] = 'success';
  439. $result['statusText'] = 'success';
  440. $result['data'] = editPlugins($_POST);
  441. } else {
  442. $result['status'] = 'error';
  443. $result['statusText'] = 'API/Token invalid or not set';
  444. $result['data'] = null;
  445. }
  446. break;
  447. default:
  448. $result['status'] = 'error';
  449. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  450. break;
  451. }
  452. break;
  453. case 'v1_settings_settings_logs':
  454. /**
  455. * @api {get} v1/settings/settings/logs Get Logs
  456. * @apiVersion 1.0.0
  457. * @apiName GetLogsPage
  458. * @apiGroup Pages
  459. * @apiUse DataHTMLSuccess
  460. * @apiUse UserNotAuthorizedError
  461. */
  462. switch ($method) {
  463. case 'GET':
  464. if (qualifyRequest(1)) {
  465. $result['status'] = 'success';
  466. $result['statusText'] = 'success';
  467. $result['data'] = $pageSettingsSettingsLogs;
  468. } else {
  469. $result['status'] = 'error';
  470. $result['statusText'] = 'API/Token invalid or not set';
  471. $result['data'] = null;
  472. }
  473. break;
  474. default:
  475. $result['status'] = 'error';
  476. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  477. break;
  478. }
  479. break;
  480. case 'v1_settings_settings_sso':
  481. /**
  482. * @api {get} v1/settings/settings/sso Get SSO
  483. * @apiVersion 1.0.0
  484. * @apiName GetSSOPage
  485. * @apiGroup Pages
  486. * @apiUse DataHTMLSuccess
  487. * @apiUse UserNotAuthorizedError
  488. */
  489. switch ($method) {
  490. case 'GET':
  491. if (qualifyRequest(1)) {
  492. $result['status'] = 'success';
  493. $result['statusText'] = 'success';
  494. $result['data'] = $pageSettingsSettingsSSO;
  495. } else {
  496. $result['status'] = 'error';
  497. $result['statusText'] = 'API/Token invalid or not set';
  498. $result['data'] = null;
  499. }
  500. break;
  501. default:
  502. $result['status'] = 'error';
  503. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  504. break;
  505. }
  506. break;
  507. case 'v1_settings_settings_main':
  508. /**
  509. * @api {get} v1/settings/settings/main Get Settings Main
  510. * @apiVersion 1.0.0
  511. * @apiName GetSettingsMainPage
  512. * @apiGroup Pages
  513. * @apiUse DataHTMLSuccess
  514. * @apiUse UserNotAuthorizedError
  515. */
  516. switch ($method) {
  517. case 'GET':
  518. if (qualifyRequest(1)) {
  519. $result['status'] = 'success';
  520. $result['statusText'] = 'success';
  521. $result['data'] = $pageSettingsSettingsMain;
  522. } else {
  523. $result['status'] = 'error';
  524. $result['statusText'] = 'API/Token invalid or not set';
  525. $result['data'] = null;
  526. }
  527. break;
  528. default:
  529. $result['status'] = 'error';
  530. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  531. break;
  532. }
  533. break;
  534. case 'v1_settings_customize_appearance':
  535. /**
  536. * @api {get} v1/settings/customize/appearance Get Customize Appearance
  537. * @apiVersion 1.0.0
  538. * @apiName GetCustomizePage
  539. * @apiGroup Pages
  540. * @apiUse DataHTMLSuccess
  541. * @apiUse UserNotAuthorizedError
  542. */
  543. /**
  544. * @api {post} v1/settings/customize/appearance Edit Customize Appearance
  545. * @apiVersion 1.0.0
  546. * @apiName PostCustomizePage
  547. * @apiGroup Appearance
  548. * @apiParam {Object} data nested data object.
  549. * @apiParam {String} data[action] editCustomizeAppearance.
  550. * @apiParam {String} data[name] Name.
  551. * @apiParam {String} data[value] Value.
  552. * @apiUse DataBooleanSuccess
  553. * @apiUse UserNotAuthorizedError
  554. */
  555. switch ($method) {
  556. case 'GET':
  557. if (qualifyRequest(1)) {
  558. $result['status'] = 'success';
  559. $result['statusText'] = 'success';
  560. $result['data'] = $pageSettingsCustomizeAppearance;
  561. } else {
  562. $result['status'] = 'error';
  563. $result['statusText'] = 'API/Token invalid or not set';
  564. $result['data'] = null;
  565. }
  566. break;
  567. case 'POST':
  568. if (qualifyRequest(1)) {
  569. $result['status'] = 'success';
  570. $result['statusText'] = 'success';
  571. $result['data'] = editAppearance($_POST);
  572. } else {
  573. $result['status'] = 'error';
  574. $result['statusText'] = 'API/Token invalid or not set';
  575. $result['data'] = null;
  576. }
  577. break;
  578. default:
  579. $result['status'] = 'error';
  580. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  581. break;
  582. }
  583. break;
  584. case 'v1_remove_file':
  585. /**
  586. * @api {post} v1/remove/file Remove File
  587. * @apiVersion 1.0.0
  588. * @apiName PostRemoveFile
  589. * @apiGroup Files
  590. * @apiParam {Object} data nested data object.
  591. * @apiParam {String} data[path] File Path.
  592. * @apiParam {String} data[name] File Name.
  593. * @apiUse DataBooleanSuccess
  594. * @apiUse UserNotAuthorizedError
  595. */
  596. switch ($method) {
  597. case 'POST':
  598. if (qualifyRequest(1)) {
  599. $result['status'] = 'success';
  600. $result['statusText'] = 'success';
  601. $result['data'] = removeFile($_POST);
  602. } else {
  603. $result['status'] = 'error';
  604. $result['statusText'] = 'API/Token invalid or not set';
  605. $result['data'] = null;
  606. }
  607. break;
  608. default:
  609. $result['status'] = 'error';
  610. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  611. break;
  612. }
  613. break;
  614. case 'v1_update_config':
  615. /**
  616. * @api {post} v1/update/config Update Config Item
  617. * @apiVersion 1.0.0
  618. * @apiName PostUpdateConfig
  619. * @apiGroup Config
  620. * @apiParam {Object} data nested data object.
  621. * @apiParam {String} data[type] input|select|switch|password.
  622. * @apiParam {String} data[name] Name.
  623. * @apiParam {String} data[value] Value.
  624. * @apiUse DataBooleanSuccess
  625. * @apiUse UserNotAuthorizedError
  626. */
  627. switch ($method) {
  628. case 'POST':
  629. if (qualifyRequest(1)) {
  630. $result['status'] = 'success';
  631. $result['statusText'] = 'success';
  632. $result['data'] = updateConfigItem($_POST);
  633. } else {
  634. $result['status'] = 'error';
  635. $result['statusText'] = 'API/Token invalid or not set';
  636. $result['data'] = null;
  637. }
  638. break;
  639. default:
  640. $result['status'] = 'error';
  641. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  642. break;
  643. }
  644. break;
  645. case 'v1_update_config_multiple':
  646. /**
  647. * @api {post} v1/update/config/multiple Update Multiple Config Items
  648. * @apiVersion 1.0.0
  649. * @apiName PostUpdateConfigMultiple
  650. * @apiGroup Config
  651. * @apiPermission admin
  652. * @apiParam {Object} data[payload] nested payload object.
  653. * @apiParam {String} data.:keyName Value of Name defined from key.
  654. * @apiParamExample {json} Request-Example:
  655. * {
  656. * "data": {
  657. * "payload": {
  658. * "title": "Organizr V2",
  659. * "logo": "plugins/images/organizr/logo-wide.png"
  660. * }
  661. * }
  662. * }
  663. * @apiUse DataBooleanSuccess
  664. * @apiUse UserNotAuthorizedError
  665. */
  666. switch ($method) {
  667. case 'POST':
  668. if (qualifyRequest(1)) {
  669. $result['status'] = 'success';
  670. $result['statusText'] = 'success';
  671. $result['data'] = updateConfigMultiple($_POST);
  672. } else {
  673. $result['status'] = 'error';
  674. $result['statusText'] = 'API/Token invalid or not set';
  675. $result['data'] = null;
  676. }
  677. break;
  678. default:
  679. $result['status'] = 'error';
  680. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  681. break;
  682. }
  683. break;
  684. case 'v1_update_config_multiple_form':
  685. /**
  686. * @api {post} v1/update/config/multiple/form Update Multiple Config Items Form
  687. * @apiVersion 1.0.0
  688. * @apiName PostUpdateConfigMultipleForm
  689. * @apiGroup Config
  690. * @apiPermission admin
  691. * @apiParam {Object} data[payload] nested payload object.
  692. * @apiParam {Object} data.:keyName Config ID/Key.
  693. * @apiParam {String} data.:keyName.name Config ID/Key.
  694. * @apiParam {String} data.:keyName.value Config Value.
  695. * @apiParam {String} data.:keyName.type Config Type input|select|switch|password.
  696. * @apiParamExample {json} Request-Example:
  697. * {
  698. * "data": {
  699. * "payload": {
  700. * "title": {
  701. * "name": "title",
  702. * "value": "Organizr V2",
  703. * "type": "input"
  704. * },
  705. * "logo": {
  706. * "name": "logo",
  707. * "value": "plugins/images/organizr/logo-wide.png",
  708. * "type": "input"
  709. * }
  710. * }
  711. * }
  712. * }
  713. * @apiUse DataBooleanSuccess
  714. * @apiUse UserNotAuthorizedError
  715. */
  716. switch ($method) {
  717. case 'POST':
  718. if (qualifyRequest(1)) {
  719. $result['status'] = 'success';
  720. $result['statusText'] = 'success';
  721. $result['data'] = updateConfigMultipleForm($_POST);
  722. } else {
  723. $result['status'] = 'error';
  724. $result['statusText'] = 'API/Token invalid or not set';
  725. $result['data'] = null;
  726. }
  727. break;
  728. default:
  729. $result['status'] = 'error';
  730. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  731. break;
  732. }
  733. break;
  734. case 'v1_homepage_connect':
  735. /**
  736. * @api {post} v1/homepage/connect Homepage Item Connect
  737. * @apiVersion 1.0.0
  738. * @apiName PostHomepageItemConnect
  739. * @apiGroup Homepage
  740. * @apiPermission admin
  741. * @apiParam {Object} data payload object.
  742. * @apiParam {Object} data[action] Homepage Item i.e. getPlexStreams|getPlexRecent.
  743. * @apiParamExample {json} Request-Example:
  744. * {
  745. * "data": {
  746. * "action": "getPlexStreams"
  747. * }
  748. * }
  749. * @apiUse DataJSONSuccess
  750. * @apiUse UserNotAuthorizedError
  751. */
  752. switch ($method) {
  753. case 'POST':
  754. $result['status'] = 'success';
  755. $result['statusText'] = 'success';
  756. $result['data'] = homepageConnect($_POST);
  757. break;
  758. default:
  759. $result['status'] = 'error';
  760. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  761. break;
  762. }
  763. break;
  764. case 'v1_ping_list':
  765. /**
  766. * @api {post} v1/ping/list Homepage Item Connect
  767. * @apiVersion 1.0.0
  768. * @apiName PostPingList
  769. * @apiGroup Ping
  770. * @apiParam {Object} data payload object.
  771. * @apiParam {Object[]} data[pingList] List of ip/hostname and ports [Optional String of hostname:port]
  772. * @apiParamExample {json} Object
  773. * {
  774. * "data": {
  775. * "pingList": ["docker.home.lab:3579", "docker.home.lab:8181"]
  776. * }
  777. * }
  778. * @apiParamExample {json} String
  779. * {
  780. * "data": {
  781. * "pingList": ["docker.home.lab:3579", "docker.home.lab:8181"]
  782. * }
  783. * }
  784. * @apiSuccess {String} data Output ping results and response times.
  785. * @apiSuccessExample Success-Response:
  786. * HTTP/1.1 200 OK
  787. * {
  788. * "status": "success",
  789. * "statusText": "success",
  790. * "data":{
  791. * "docker.home.lab:3579":10.77,
  792. * "docker.home.lab:8181":0.66
  793. * }
  794. * }
  795. * @apiUse UserNotAuthorizedError
  796. */
  797. switch ($method) {
  798. case 'POST':
  799. $result['status'] = 'success';
  800. $result['statusText'] = 'success';
  801. $result['data'] = ping($_POST['data']['pingList']);
  802. break;
  803. default:
  804. $result['status'] = 'error';
  805. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  806. break;
  807. }
  808. break;
  809. case 'v1_test_api_connection':
  810. switch ($method) {
  811. case 'POST':
  812. if (qualifyRequest(1)) {
  813. $result['status'] = 'success';
  814. $result['statusText'] = 'success';
  815. $result['data'] = testAPIConnection($_POST);
  816. } else {
  817. $result['status'] = 'error';
  818. $result['statusText'] = 'API/Token invalid or not set';
  819. $result['data'] = null;
  820. }
  821. break;
  822. default:
  823. $result['status'] = 'error';
  824. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  825. break;
  826. }
  827. break;
  828. case 'v1_settings_tab_editor_tabs':
  829. /**
  830. * @api {get} v1/settings/tab/editor/tabs Get Tab Editor Tabs
  831. * @apiVersion 1.0.0
  832. * @apiName GetTabEditorTabsPage
  833. * @apiGroup Pages
  834. * @apiUse DataHTMLSuccess
  835. * @apiUse UserNotAuthorizedError
  836. */
  837. switch ($method) {
  838. case 'GET':
  839. if (qualifyRequest(1)) {
  840. $result['status'] = 'success';
  841. $result['statusText'] = 'success';
  842. $result['data'] = $pageSettingsTabEditorTabs;
  843. } else {
  844. $result['status'] = 'error';
  845. $result['statusText'] = 'API/Token invalid or not set';
  846. $result['data'] = null;
  847. }
  848. break;
  849. case 'POST':
  850. if (qualifyRequest(1)) {
  851. $result['status'] = 'success';
  852. $result['statusText'] = 'success';
  853. $result['data'] = editTabs($_POST);
  854. } else {
  855. $result['status'] = 'error';
  856. $result['statusText'] = 'API/Token invalid or not set';
  857. $result['data'] = null;
  858. }
  859. break;
  860. default:
  861. $result['status'] = 'error';
  862. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  863. break;
  864. }
  865. break;
  866. case 'v1_settings_tab_editor_categories':
  867. /**
  868. * @api {get} v1/settings/tab/editor/categories Get Tab Editor Categories
  869. * @apiVersion 1.0.0
  870. * @apiName GetTabEditorCategoriesPage
  871. * @apiGroup Pages
  872. * @apiUse DataHTMLSuccess
  873. * @apiUse UserNotAuthorizedError
  874. */
  875. switch ($method) {
  876. case 'GET':
  877. if (qualifyRequest(1)) {
  878. $result['status'] = 'success';
  879. $result['statusText'] = 'success';
  880. $result['data'] = $pageSettingsTabEditorCategories;
  881. } else {
  882. $result['status'] = 'error';
  883. $result['statusText'] = 'API/Token invalid or not set';
  884. $result['data'] = null;
  885. }
  886. break;
  887. case 'POST':
  888. if (qualifyRequest(1)) {
  889. $result['status'] = 'success';
  890. $result['statusText'] = 'success';
  891. $result['data'] = editCategories($_POST);
  892. } else {
  893. $result['status'] = 'error';
  894. $result['statusText'] = 'API/Token invalid or not set';
  895. $result['data'] = null;
  896. }
  897. break;
  898. default:
  899. $result['status'] = 'error';
  900. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  901. break;
  902. }
  903. break;
  904. case 'v1_settings_user_manage_users':
  905. /**
  906. * @api {get} v1/settings/user/manage/users Get Manage Users
  907. * @apiVersion 1.0.0
  908. * @apiName GetManageUsersPage
  909. * @apiGroup Pages
  910. * @apiUse DataHTMLSuccess
  911. * @apiUse UserNotAuthorizedError
  912. */
  913. switch ($method) {
  914. case 'GET':
  915. if (qualifyRequest(1)) {
  916. $result['status'] = 'success';
  917. $result['statusText'] = 'success';
  918. $result['data'] = $pageSettingsUserManageUsers;
  919. } else {
  920. $result['status'] = 'error';
  921. $result['statusText'] = 'API/Token invalid or not set';
  922. $result['data'] = null;
  923. }
  924. break;
  925. case 'POST':
  926. if (qualifyRequest(1)) {
  927. $result['status'] = 'success';
  928. $result['statusText'] = 'success';
  929. $result['data'] = adminEditUser($_POST);
  930. } elseif (qualifyRequest(998)) {
  931. $result['status'] = 'success';
  932. $result['statusText'] = 'success';
  933. $result['data'] = editUser($_POST);
  934. } else {
  935. $result['status'] = 'error';
  936. $result['statusText'] = 'API/Token invalid or not set';
  937. $result['data'] = null;
  938. }
  939. break;
  940. default:
  941. $result['status'] = 'error';
  942. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  943. break;
  944. }
  945. break;
  946. case 'v1_manage_user':
  947. switch ($method) {
  948. case 'POST':
  949. if (qualifyRequest(998)) {
  950. $result['status'] = 'success';
  951. $result['statusText'] = 'success';
  952. $result['data'] = editUser($_POST);
  953. } else {
  954. $result['status'] = 'error';
  955. $result['statusText'] = 'API/Token invalid or not set';
  956. $result['data'] = null;
  957. }
  958. break;
  959. default:
  960. $result['status'] = 'error';
  961. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  962. break;
  963. }
  964. break;
  965. case 'v1_settings_user_manage_groups':
  966. switch ($method) {
  967. case 'GET':
  968. if (qualifyRequest(1)) {
  969. $result['status'] = 'success';
  970. $result['statusText'] = 'success';
  971. $result['data'] = $pageSettingsUserManageGroups;
  972. } else {
  973. $result['status'] = 'error';
  974. $result['statusText'] = 'API/Token invalid or not set';
  975. $result['data'] = null;
  976. }
  977. break;
  978. case 'POST':
  979. if (qualifyRequest(1)) {
  980. $result['status'] = 'success';
  981. $result['statusText'] = 'success';
  982. $result['data'] = adminEditGroup($_POST);
  983. } else {
  984. $result['status'] = 'error';
  985. $result['statusText'] = 'API/Token invalid or not set';
  986. $result['data'] = null;
  987. }
  988. break;
  989. default:
  990. $result['status'] = 'error';
  991. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  992. break;
  993. }
  994. break;
  995. case 'v1_settings_image_manager_view':
  996. switch ($method) {
  997. case 'GET':
  998. if (qualifyRequest(1)) {
  999. $result['status'] = 'success';
  1000. $result['statusText'] = 'success';
  1001. $result['data'] = $pageSettingsImageManager;
  1002. } else {
  1003. $result['status'] = 'error';
  1004. $result['statusText'] = 'API/Token invalid or not set';
  1005. $result['data'] = null;
  1006. }
  1007. break;
  1008. case 'POST':
  1009. if (qualifyRequest(1)) {
  1010. $result['status'] = 'success';
  1011. $result['statusText'] = 'success';
  1012. $result['data'] = editImages();
  1013. } else {
  1014. $result['status'] = 'error';
  1015. $result['statusText'] = 'API/Token invalid or not set';
  1016. $result['data'] = null;
  1017. }
  1018. break;
  1019. default:
  1020. $result['status'] = 'error';
  1021. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1022. break;
  1023. }
  1024. break;
  1025. case 'v1_wizard_page':
  1026. switch ($method) {
  1027. case 'GET':
  1028. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1029. $result['status'] = 'success';
  1030. $result['statusText'] = 'success';
  1031. $result['data'] = $pageWizard;
  1032. } else {
  1033. $result['status'] = 'error';
  1034. $result['statusText'] = 'Wizard has already been run';
  1035. $result['data'] = null;
  1036. }
  1037. break;
  1038. default:
  1039. $result['status'] = 'error';
  1040. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1041. break;
  1042. }
  1043. break;
  1044. case 'v1_dependencies_page':
  1045. switch ($method) {
  1046. case 'GET':
  1047. $result['status'] = 'success';
  1048. $result['statusText'] = 'success';
  1049. $result['data'] = $pageDependencies;
  1050. break;
  1051. default:
  1052. $result['status'] = 'error';
  1053. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1054. break;
  1055. }
  1056. break;
  1057. case 'v1_wizard_config':
  1058. switch ($method) {
  1059. case 'POST':
  1060. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1061. $result['status'] = 'success';
  1062. $result['statusText'] = 'success';
  1063. $result['data'] = wizardConfig($_POST);
  1064. } else {
  1065. $result['status'] = 'error';
  1066. $result['statusText'] = 'Wizard has already been run';
  1067. $result['data'] = null;
  1068. }
  1069. break;
  1070. default:
  1071. $result['status'] = 'error';
  1072. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1073. break;
  1074. }
  1075. break;
  1076. case 'v1_wizard_path':
  1077. switch ($method) {
  1078. case 'POST':
  1079. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1080. $result['status'] = 'success';
  1081. $result['statusText'] = 'success';
  1082. $result['data'] = wizardPath($_POST);
  1083. } else {
  1084. $result['status'] = 'error';
  1085. $result['statusText'] = 'Wizard has already been run';
  1086. $result['data'] = null;
  1087. }
  1088. break;
  1089. default:
  1090. $result['status'] = 'error';
  1091. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1092. break;
  1093. }
  1094. break;
  1095. case 'v1_login':
  1096. switch ($method) {
  1097. case 'POST':
  1098. $result['status'] = 'success';
  1099. $result['statusText'] = 'success';
  1100. $result['data'] = login($_POST);
  1101. break;
  1102. default:
  1103. $result['status'] = 'error';
  1104. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1105. break;
  1106. }
  1107. break;
  1108. case 'v1_login_api':
  1109. switch ($method) {
  1110. case 'POST':
  1111. $result['status'] = 'success';
  1112. $result['statusText'] = 'success';
  1113. $result['data'] = apiLogin();
  1114. break;
  1115. default:
  1116. $result['status'] = 'error';
  1117. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1118. break;
  1119. }
  1120. break;
  1121. case 'v1_register':
  1122. switch ($method) {
  1123. case 'POST':
  1124. $result['status'] = 'success';
  1125. $result['statusText'] = 'success';
  1126. $result['data'] = register($_POST);
  1127. break;
  1128. default:
  1129. $result['status'] = 'error';
  1130. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1131. break;
  1132. }
  1133. break;
  1134. case 'v1_recover':
  1135. switch ($method) {
  1136. case 'POST':
  1137. $result['status'] = 'success';
  1138. $result['statusText'] = 'success';
  1139. $result['data'] = recover($_POST);
  1140. break;
  1141. default:
  1142. $result['status'] = 'error';
  1143. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1144. break;
  1145. }
  1146. break;
  1147. case 'v1_unlock':
  1148. switch ($method) {
  1149. case 'POST':
  1150. $result['status'] = 'success';
  1151. $result['statusText'] = 'success';
  1152. $result['data'] = unlock($_POST);
  1153. break;
  1154. default:
  1155. $result['status'] = 'error';
  1156. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1157. break;
  1158. }
  1159. break;
  1160. case 'v1_lock':
  1161. switch ($method) {
  1162. case 'POST':
  1163. $result['status'] = 'success';
  1164. $result['statusText'] = 'success';
  1165. $result['data'] = lock();
  1166. break;
  1167. default:
  1168. $result['status'] = 'error';
  1169. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1170. break;
  1171. }
  1172. break;
  1173. case 'v1_test_iframe':
  1174. switch ($method) {
  1175. case 'POST':
  1176. $result['status'] = 'success';
  1177. $result['statusText'] = 'success';
  1178. $result['data'] = frameTest($_POST['data']['url']);
  1179. break;
  1180. default:
  1181. $result['status'] = 'error';
  1182. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1183. break;
  1184. }
  1185. break;
  1186. case 'v1_upgrade':
  1187. case 'v1_update':
  1188. case 'v1_force':
  1189. switch ($method) {
  1190. case 'POST':
  1191. if (qualifyRequest(1)) {
  1192. $result['status'] = 'success';
  1193. $result['statusText'] = 'success';
  1194. $result['data'] = upgradeInstall($_POST['data']['branch'], $_POST['data']['stage']);
  1195. } else {
  1196. $result['status'] = 'error';
  1197. $result['statusText'] = 'API/Token invalid or not set';
  1198. $result['data'] = null;
  1199. }
  1200. break;
  1201. default:
  1202. $result['status'] = 'error';
  1203. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1204. break;
  1205. }
  1206. break;
  1207. case 'v1_login_page':
  1208. switch ($method) {
  1209. case 'GET':
  1210. $result['status'] = 'success';
  1211. $result['statusText'] = 'success';
  1212. $result['data'] = $pageLogin;
  1213. break;
  1214. default:
  1215. $result['status'] = 'error';
  1216. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1217. break;
  1218. }
  1219. break;
  1220. case 'v1_lockscreen':
  1221. switch ($method) {
  1222. case 'GET':
  1223. $result['status'] = 'success';
  1224. $result['statusText'] = 'success';
  1225. $result['data'] = $pageLockScreen;
  1226. break;
  1227. default:
  1228. $result['status'] = 'error';
  1229. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1230. break;
  1231. }
  1232. break;
  1233. case 'v1_login_log':
  1234. switch ($method) {
  1235. case 'GET':
  1236. if (qualifyRequest(1)) {
  1237. $result['status'] = 'success';
  1238. $result['statusText'] = 'success';
  1239. $result['data'] = getLog('loginLog');
  1240. } else {
  1241. $result['status'] = 'error';
  1242. $result['statusText'] = 'API/Token invalid or not set';
  1243. $result['data'] = null;
  1244. }
  1245. break;
  1246. default:
  1247. $result['status'] = 'error';
  1248. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1249. break;
  1250. }
  1251. break;
  1252. case 'v1_organizr_log':
  1253. switch ($method) {
  1254. case 'GET':
  1255. if (qualifyRequest(1)) {
  1256. $result['status'] = 'success';
  1257. $result['statusText'] = 'success';
  1258. $result['data'] = getLog('org');
  1259. } else {
  1260. $result['status'] = 'error';
  1261. $result['statusText'] = 'API/Token invalid or not set';
  1262. $result['data'] = null;
  1263. }
  1264. break;
  1265. default:
  1266. $result['status'] = 'error';
  1267. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1268. break;
  1269. }
  1270. break;
  1271. case 'v1_user_list':
  1272. switch ($method) {
  1273. case 'GET':
  1274. if (qualifyRequest(1)) {
  1275. $result['status'] = 'success';
  1276. $result['statusText'] = 'success';
  1277. $result['data'] = allUsers();
  1278. } else {
  1279. $result['status'] = 'error';
  1280. $result['statusText'] = 'API/Token invalid or not set';
  1281. $result['data'] = null;
  1282. }
  1283. break;
  1284. default:
  1285. $result['status'] = 'error';
  1286. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1287. break;
  1288. }
  1289. break;
  1290. case 'v1_tab_list':
  1291. switch ($method) {
  1292. case 'GET':
  1293. if (qualifyRequest(1)) {
  1294. $result['status'] = 'success';
  1295. $result['statusText'] = 'success';
  1296. $result['data'] = allTabs();
  1297. } else {
  1298. $result['status'] = 'error';
  1299. $result['statusText'] = 'API/Token invalid or not set';
  1300. $result['data'] = null;
  1301. }
  1302. break;
  1303. default:
  1304. $result['status'] = 'error';
  1305. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1306. break;
  1307. }
  1308. break;
  1309. case 'v1_image_list':
  1310. switch ($method) {
  1311. case 'GET':
  1312. if (qualifyRequest(1)) {
  1313. $result['status'] = 'success';
  1314. $result['statusText'] = 'success';
  1315. $result['data'] = getImages();
  1316. } else {
  1317. $result['status'] = 'error';
  1318. $result['statusText'] = 'API/Token invalid or not set';
  1319. $result['data'] = null;
  1320. }
  1321. break;
  1322. default:
  1323. $result['status'] = 'error';
  1324. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1325. break;
  1326. }
  1327. break;
  1328. case 'v1_customize_appearance':
  1329. switch ($method) {
  1330. case 'GET':
  1331. if (qualifyRequest(1)) {
  1332. $result['status'] = 'success';
  1333. $result['statusText'] = 'success';
  1334. $result['data'] = getCustomizeAppearance();
  1335. } else {
  1336. $result['status'] = 'error';
  1337. $result['statusText'] = 'API/Token invalid or not set';
  1338. $result['data'] = null;
  1339. }
  1340. break;
  1341. default:
  1342. $result['status'] = 'error';
  1343. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1344. break;
  1345. }
  1346. break;
  1347. case 'v1_sso':
  1348. switch ($method) {
  1349. case 'GET':
  1350. if (qualifyRequest(1)) {
  1351. $result['status'] = 'success';
  1352. $result['statusText'] = 'success';
  1353. $result['data'] = getSSO();
  1354. } else {
  1355. $result['status'] = 'error';
  1356. $result['statusText'] = 'API/Token invalid or not set';
  1357. $result['data'] = null;
  1358. }
  1359. break;
  1360. default:
  1361. $result['status'] = 'error';
  1362. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1363. break;
  1364. }
  1365. break;
  1366. case 'v1_settings_main':
  1367. switch ($method) {
  1368. case 'GET':
  1369. if (qualifyRequest(1)) {
  1370. $result['status'] = 'success';
  1371. $result['statusText'] = 'success';
  1372. $result['data'] = getSettingsMain();
  1373. } else {
  1374. $result['status'] = 'error';
  1375. $result['statusText'] = 'API/Token invalid or not set';
  1376. $result['data'] = null;
  1377. }
  1378. break;
  1379. default:
  1380. $result['status'] = 'error';
  1381. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1382. break;
  1383. }
  1384. break;
  1385. case 'v1_plugin_install':
  1386. switch ($method) {
  1387. case 'POST':
  1388. if (qualifyRequest(1)) {
  1389. $result['status'] = 'success';
  1390. $result['statusText'] = 'success';
  1391. $result['data'] = installPlugin($_POST);
  1392. } else {
  1393. $result['status'] = 'error';
  1394. $result['statusText'] = 'API/Token invalid or not set';
  1395. $result['data'] = null;
  1396. }
  1397. break;
  1398. default:
  1399. $result['status'] = 'error';
  1400. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1401. break;
  1402. }
  1403. break;
  1404. case 'v1_plugin_remove':
  1405. switch ($method) {
  1406. case 'POST':
  1407. if (qualifyRequest(1)) {
  1408. $result['status'] = 'success';
  1409. $result['statusText'] = 'success';
  1410. $result['data'] = removePlugin($_POST);
  1411. } else {
  1412. $result['status'] = 'error';
  1413. $result['statusText'] = 'API/Token invalid or not set';
  1414. $result['data'] = null;
  1415. }
  1416. break;
  1417. default:
  1418. $result['status'] = 'error';
  1419. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1420. break;
  1421. }
  1422. break;
  1423. case 'v1_theme_install':
  1424. switch ($method) {
  1425. case 'POST':
  1426. if (qualifyRequest(1)) {
  1427. $result['status'] = 'success';
  1428. $result['statusText'] = 'success';
  1429. $result['data'] = installTheme($_POST);
  1430. } else {
  1431. $result['status'] = 'error';
  1432. $result['statusText'] = 'API/Token invalid or not set';
  1433. $result['data'] = null;
  1434. }
  1435. break;
  1436. default:
  1437. $result['status'] = 'error';
  1438. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1439. break;
  1440. }
  1441. break;
  1442. case 'v1_theme_remove':
  1443. switch ($method) {
  1444. case 'POST':
  1445. if (qualifyRequest(1)) {
  1446. $result['status'] = 'success';
  1447. $result['statusText'] = 'success';
  1448. $result['data'] = removeTheme($_POST);
  1449. } else {
  1450. $result['status'] = 'error';
  1451. $result['statusText'] = 'API/Token invalid or not set';
  1452. $result['data'] = null;
  1453. }
  1454. break;
  1455. default:
  1456. $result['status'] = 'error';
  1457. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1458. break;
  1459. }
  1460. break;
  1461. case 'v1_user_edit':
  1462. switch ($method) {
  1463. case 'POST':
  1464. if (qualifyRequest(1)) {
  1465. $result['status'] = 'success';
  1466. $result['statusText'] = 'success';
  1467. $result['data'] = adminEditUser($_POST);
  1468. } elseif (qualifyRequest(998)) {
  1469. $result['status'] = 'success';
  1470. $result['statusText'] = 'success';
  1471. $result['data'] = editUser($_POST);
  1472. } else {
  1473. $result['status'] = 'error';
  1474. $result['statusText'] = 'API/Token invalid or not set';
  1475. $result['data'] = null;
  1476. }
  1477. break;
  1478. default:
  1479. $result['status'] = 'error';
  1480. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1481. break;
  1482. }
  1483. break;
  1484. case 'v1_2fa_create':
  1485. switch ($method) {
  1486. case 'POST':
  1487. if (qualifyRequest(998)) {
  1488. $result['status'] = 'success';
  1489. $result['statusText'] = 'success';
  1490. $result['data'] = create2FA($_POST['data']['type']);
  1491. } else {
  1492. $result['status'] = 'error';
  1493. $result['statusText'] = 'API/Token invalid or not set';
  1494. $result['data'] = null;
  1495. }
  1496. break;
  1497. default:
  1498. $result['status'] = 'error';
  1499. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1500. break;
  1501. }
  1502. break;
  1503. case 'v1_2fa_save':
  1504. switch ($method) {
  1505. case 'POST':
  1506. if (qualifyRequest(998)) {
  1507. $result['status'] = 'success';
  1508. $result['statusText'] = 'success';
  1509. $result['data'] = save2FA($_POST['data']['secret'], $_POST['data']['type']);
  1510. } else {
  1511. $result['status'] = 'error';
  1512. $result['statusText'] = 'API/Token invalid or not set';
  1513. $result['data'] = null;
  1514. }
  1515. break;
  1516. default:
  1517. $result['status'] = 'error';
  1518. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1519. break;
  1520. }
  1521. break;
  1522. case 'v1_2fa_verify':
  1523. switch ($method) {
  1524. case 'POST':
  1525. if (qualifyRequest(998)) {
  1526. $result['status'] = 'success';
  1527. $result['statusText'] = 'success';
  1528. $result['data'] = verify2FA($_POST['data']['secret'], $_POST['data']['code'], $_POST['data']['type']);
  1529. } else {
  1530. $result['status'] = 'error';
  1531. $result['statusText'] = 'API/Token invalid or not set';
  1532. $result['data'] = null;
  1533. }
  1534. break;
  1535. default:
  1536. $result['status'] = 'error';
  1537. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1538. break;
  1539. }
  1540. break;
  1541. case 'v1_2fa_remove':
  1542. switch ($method) {
  1543. case 'GET':
  1544. if (qualifyRequest(998)) {
  1545. $result['status'] = 'success';
  1546. $result['statusText'] = 'success';
  1547. $result['data'] = remove2FA();
  1548. } else {
  1549. $result['status'] = 'error';
  1550. $result['statusText'] = 'API/Token invalid or not set';
  1551. $result['data'] = null;
  1552. }
  1553. break;
  1554. default:
  1555. $result['status'] = 'error';
  1556. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1557. break;
  1558. }
  1559. break;
  1560. case 'v1_logout':
  1561. switch ($method) {
  1562. case 'GET':
  1563. $result['status'] = 'success';
  1564. $result['statusText'] = 'success';
  1565. $result['data'] = logout();
  1566. break;
  1567. default:
  1568. $result['status'] = 'error';
  1569. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1570. break;
  1571. }
  1572. break;
  1573. case 'v1_launch_organizr':
  1574. switch ($method) {
  1575. case 'GET':
  1576. $pluginSearch = '-enabled';
  1577. $pluginInclude = '-include';
  1578. $status = array();
  1579. $result['status'] = 'success';
  1580. $result['statusText'] = 'success';
  1581. $status['status'] = organizrStatus();
  1582. $result['appearance'] = loadAppearance();
  1583. $status['user'] = $GLOBALS['organizrUser'];
  1584. $status['categories'] = loadTabs('categories');
  1585. $status['tabs'] = loadTabs('tabs');
  1586. $status['plugins'] = array_filter($GLOBALS, function ($k) use ($pluginSearch) {
  1587. return stripos($k, $pluginSearch) !== false;
  1588. }, ARRAY_FILTER_USE_KEY);
  1589. $status['plugins']['includes'] = array_filter($GLOBALS, function ($k) use ($pluginInclude) {
  1590. return stripos($k, $pluginInclude) !== false;
  1591. }, ARRAY_FILTER_USE_KEY);
  1592. $result['data'] = $status;
  1593. $result['branch'] = $GLOBALS['branch'];
  1594. $result['theme'] = $GLOBALS['theme'];
  1595. $result['style'] = $GLOBALS['style'];
  1596. $result['version'] = $GLOBALS['installedVersion'];
  1597. $result['sso'] = array(
  1598. 'myPlexAccessToken' => isset($_COOKIE['mpt']) ? $_COOKIE['mpt'] : false,
  1599. 'id_token' => isset($_COOKIE['Auth']) ? $_COOKIE['Auth'] : false
  1600. );
  1601. $result['settings'] = organizrSpecialSettings();
  1602. break;
  1603. default:
  1604. $result['status'] = 'error';
  1605. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1606. break;
  1607. }
  1608. break;
  1609. case 'v1_auth':
  1610. switch ($method) {
  1611. case 'GET':
  1612. auth();
  1613. break;
  1614. default:
  1615. //exit(http_response_code(401));
  1616. auth();
  1617. break;
  1618. }
  1619. break;
  1620. case 'v1_plugin':
  1621. switch ($method) {
  1622. case 'POST':
  1623. case 'GET':
  1624. // Include all plugin api Calls
  1625. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'plugins' . DIRECTORY_SEPARATOR . 'api' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  1626. require_once $filename;
  1627. }
  1628. break;
  1629. default:
  1630. $result['status'] = 'error';
  1631. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1632. break;
  1633. }
  1634. break;
  1635. case 'v1_image':
  1636. switch ($method) {
  1637. case 'GET':
  1638. getImage();
  1639. break;
  1640. default:
  1641. $result['status'] = 'error';
  1642. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1643. break;
  1644. }
  1645. break;
  1646. case 'v1_downloader':
  1647. switch ($method) {
  1648. case 'POST':
  1649. $result['status'] = 'success';
  1650. $result['statusText'] = 'success';
  1651. $result['data'] = downloader($_POST);
  1652. break;
  1653. default:
  1654. $result['status'] = 'error';
  1655. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1656. break;
  1657. }
  1658. break;
  1659. case 'v1_import_users':
  1660. switch ($method) {
  1661. case 'POST':
  1662. if (qualifyRequest(1)) {
  1663. $result['status'] = 'success';
  1664. $result['statusText'] = 'success';
  1665. $result['data'] = importUsersType($_POST);
  1666. } else {
  1667. $result['status'] = 'error';
  1668. $result['statusText'] = 'API/Token invalid or not set';
  1669. $result['data'] = null;
  1670. }
  1671. break;
  1672. default:
  1673. $result['status'] = 'error';
  1674. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1675. break;
  1676. }
  1677. break;
  1678. case 'v1_ombi':
  1679. switch ($method) {
  1680. case 'POST':
  1681. $result['status'] = 'success';
  1682. $result['statusText'] = 'success';
  1683. $result['data'] = ombiAPI($_POST);
  1684. break;
  1685. default:
  1686. $result['status'] = 'error';
  1687. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1688. break;
  1689. }
  1690. break;
  1691. case 'v1_plex_join':
  1692. switch ($method) {
  1693. case 'POST':
  1694. $result['status'] = 'success';
  1695. $result['statusText'] = 'success';
  1696. $result['data'] = plexJoinAPI($_POST);
  1697. break;
  1698. default:
  1699. $result['status'] = 'error';
  1700. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1701. break;
  1702. }
  1703. break;
  1704. case 'v1_emby_join':
  1705. switch ($method) {
  1706. case 'POST':
  1707. $result['status'] = 'success';
  1708. $result['statusText'] = 'success';
  1709. $result['data'] = embyJoinAPI($_POST);
  1710. break;
  1711. default:
  1712. $result['status'] = 'error';
  1713. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1714. break;
  1715. }
  1716. break;
  1717. case 'v1_token_revoke':
  1718. switch ($method) {
  1719. case 'POST':
  1720. $result['status'] = 'success';
  1721. $result['statusText'] = 'success';
  1722. $result['data'] = revokeToken($_POST);
  1723. break;
  1724. default:
  1725. $result['status'] = 'error';
  1726. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1727. break;
  1728. }
  1729. break;
  1730. case 'v1_token_validate':
  1731. switch ($method) {
  1732. case 'GET':
  1733. $token = $_GET['token'] ?? false;
  1734. break;
  1735. case 'POST':
  1736. $token = $_POST['token'] ?? false;
  1737. break;
  1738. default:
  1739. $result['status'] = 'error';
  1740. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1741. break;
  1742. }
  1743. $token = validateToken($token);
  1744. if ($token) {
  1745. $result['status'] = 'success';
  1746. $result['statusText'] = 'success';
  1747. $result['data'] = $token;
  1748. } else {
  1749. $result['status'] = 'error';
  1750. $result['statusText'] = 'Token not validated or empty';
  1751. }
  1752. break;
  1753. case 'v1_update_db_manual':
  1754. switch ($method) {
  1755. case 'GET':
  1756. if (qualifyRequest(1)) {
  1757. $result['status'] = 'success';
  1758. $result['statusText'] = 'success';
  1759. $result['data'] = updateDB($GLOBALS['installedVersion']);
  1760. } else {
  1761. $result['status'] = 'error';
  1762. $result['statusText'] = 'API/Token invalid or not set';
  1763. $result['data'] = null;
  1764. }
  1765. break;
  1766. default:
  1767. $result['status'] = 'error';
  1768. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1769. break;
  1770. }
  1771. break;
  1772. case 'v1_version':
  1773. switch ($method) {
  1774. case 'GET':
  1775. $result['status'] = 'success';
  1776. $result['statusText'] = 'success';
  1777. $result['data'] = $GLOBALS['installedVersion'];
  1778. break;
  1779. default:
  1780. $result['status'] = 'error';
  1781. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1782. break;
  1783. }
  1784. break;
  1785. case 'v1_ping':
  1786. switch ($method) {
  1787. case 'GET':
  1788. $result['status'] = 'success';
  1789. $result['statusText'] = 'success';
  1790. $result['data'] = 'pong';
  1791. break;
  1792. default:
  1793. $result['status'] = 'error';
  1794. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1795. break;
  1796. }
  1797. break;
  1798. case 'v1_docker_update':
  1799. switch ($method) {
  1800. case 'GET':
  1801. if (qualifyRequest(1)) {
  1802. $result['status'] = 'success';
  1803. $result['statusText'] = 'success';
  1804. $result['data'] = dockerUpdate();
  1805. } else {
  1806. $result['status'] = 'error';
  1807. $result['statusText'] = 'API/Token invalid or not set';
  1808. $result['data'] = null;
  1809. }
  1810. break;
  1811. default:
  1812. $result['status'] = 'error';
  1813. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1814. break;
  1815. }
  1816. break;
  1817. case 'v1_windows_update':
  1818. switch ($method) {
  1819. case 'GET':
  1820. if (qualifyRequest(1)) {
  1821. $result['status'] = 'success';
  1822. $result['statusText'] = 'success';
  1823. $result['data'] = windowsUpdate();
  1824. } else {
  1825. $result['status'] = 'error';
  1826. $result['statusText'] = 'API/Token invalid or not set';
  1827. $result['data'] = null;
  1828. }
  1829. break;
  1830. default:
  1831. $result['status'] = 'error';
  1832. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1833. break;
  1834. }
  1835. break;
  1836. case 'v1_custom_page':
  1837. switch ($method) {
  1838. case 'GET':
  1839. $customPage = 'customPage' . ucwords($endpoint);
  1840. $result['status'] = 'success';
  1841. $result['statusText'] = 'success';
  1842. $result['data'] = $$customPage;
  1843. break;
  1844. default:
  1845. $result['status'] = 'error';
  1846. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1847. break;
  1848. }
  1849. break;
  1850. case 'v1_youtube_search':
  1851. switch ($method) {
  1852. case 'GET':
  1853. $query = isset($_GET['q']) ? $_GET['q'] : false;
  1854. $result['status'] = isset($_GET['q']) ? 'success' : 'error';
  1855. $result['statusText'] = isset($_GET['q']) ? 'success' : 'missing query';
  1856. $result['data'] = youtubeSearch($query);
  1857. break;
  1858. default:
  1859. $result['status'] = 'error';
  1860. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1861. break;
  1862. }
  1863. break;
  1864. case 'v1_scrape':
  1865. switch ($method) {
  1866. case 'POST':
  1867. if (qualifyRequest(998)) {
  1868. $result['status'] = 'success';
  1869. $result['statusText'] = 'success';
  1870. $result['data'] = scrapePage($_POST);
  1871. } else {
  1872. $result['status'] = 'error';
  1873. $result['statusText'] = 'API/Token invalid or not set';
  1874. $result['data'] = null;
  1875. }
  1876. break;
  1877. default:
  1878. $result['status'] = 'error';
  1879. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1880. break;
  1881. }
  1882. break;
  1883. case 'v1_coordinates_search':
  1884. switch ($method) {
  1885. case 'POST':
  1886. if (qualifyRequest(1)) {
  1887. $result['status'] = 'success';
  1888. $result['statusText'] = 'success';
  1889. $result['data'] = searchCityForCoordinates($_POST);
  1890. } else {
  1891. $result['status'] = 'error';
  1892. $result['statusText'] = 'API/Token invalid or not set';
  1893. $result['data'] = null;
  1894. }
  1895. break;
  1896. default:
  1897. $result['status'] = 'error';
  1898. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1899. break;
  1900. }
  1901. break;
  1902. default:
  1903. //No Function Available
  1904. $result['status'] = 'error';
  1905. $result['statusText'] = 'function requested is not defined';
  1906. break;
  1907. }
  1908. //Set Default Result
  1909. if (!$result) {
  1910. $result['status'] = "error";
  1911. $result['error'] = "An error has occurred";
  1912. }
  1913. $result['generationDate'] = $GLOBALS['currentTime'];
  1914. $result['generationTime'] = formatSeconds(timeExecution());
  1915. //Set HTTP Code
  1916. if ($result['statusText'] == "API/Token invalid or not set") {
  1917. http_response_code(401);
  1918. } else {
  1919. http_response_code(200);
  1920. }
  1921. //return JSON array
  1922. if ($pretty) {
  1923. echo '<pre>' . safe_json_encode($result, JSON_PRETTY_PRINT) . '</pre>';
  1924. } else {
  1925. exit(safe_json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));
  1926. }