index.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539
  1. <?php
  2. $generationTime = -microtime(true);
  3. //include functions
  4. require_once 'functions.php';
  5. //Set result array
  6. $result = array();
  7. //Get request method
  8. $method = $_SERVER['REQUEST_METHOD'];
  9. reset($_GET);
  10. $function = (key($_GET) ? str_replace("/","_",key($_GET)) : false);
  11. //Exit if $function is blank
  12. if($function === false){
  13. $result['status'] = "error";
  14. $result['statusText'] = "No API Path Supplied";
  15. exit(json_encode($result));
  16. }
  17. $result['request'] = key($_GET);
  18. switch ($function) {
  19. case 'v1_settings_page':
  20. switch ($method) {
  21. case 'GET':
  22. if(qualifyRequest(1)){
  23. $result['status'] = 'success';
  24. $result['statusText'] = 'success';
  25. $result['data'] = $pageSettings;
  26. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  27. }else{
  28. $result['status'] = 'error';
  29. $result['statusText'] = 'API/Token invalid or not set';
  30. $result['data'] = null;
  31. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  32. }
  33. break;
  34. default:
  35. $result['status'] = 'error';
  36. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  37. break;
  38. }
  39. break;
  40. case 'v1_settings_settings_logs':
  41. switch ($method) {
  42. case 'GET':
  43. if(qualifyRequest(1)){
  44. $result['status'] = 'success';
  45. $result['statusText'] = 'success';
  46. $result['data'] = $pageSettingsSettingsLogs;
  47. }else{
  48. $result['status'] = 'error';
  49. $result['statusText'] = 'API/Token invalid or not set';
  50. $result['data'] = null;
  51. }
  52. break;
  53. default:
  54. $result['status'] = 'error';
  55. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  56. break;
  57. }
  58. break;
  59. case 'v1_settings_customize_appearance':
  60. switch ($method) {
  61. case 'GET':
  62. if(qualifyRequest(1)){
  63. $result['status'] = 'success';
  64. $result['statusText'] = 'success';
  65. $result['data'] = $pageSettingsCustomizeAppearance;
  66. }else{
  67. $result['status'] = 'error';
  68. $result['statusText'] = 'API/Token invalid or not set';
  69. $result['data'] = null;
  70. }
  71. break;
  72. case 'POST':
  73. if(qualifyRequest(1)){
  74. $result['status'] = 'success';
  75. $result['statusText'] = 'success';
  76. $result['data'] = editAppearance($_POST);
  77. }else{
  78. $result['status'] = 'error';
  79. $result['statusText'] = 'API/Token invalid or not set';
  80. $result['data'] = null;
  81. }
  82. break;
  83. default:
  84. $result['status'] = 'error';
  85. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  86. break;
  87. }
  88. break;
  89. case 'v1_settings_tab_editor_tabs':
  90. switch ($method) {
  91. case 'GET':
  92. if(qualifyRequest(1)){
  93. $result['status'] = 'success';
  94. $result['statusText'] = 'success';
  95. $result['data'] = $pageSettingsTabEditorTabs;
  96. }else{
  97. $result['status'] = 'error';
  98. $result['statusText'] = 'API/Token invalid or not set';
  99. $result['data'] = null;
  100. }
  101. break;
  102. case 'POST':
  103. if(qualifyRequest(1)){
  104. $result['status'] = 'success';
  105. $result['statusText'] = 'success';
  106. $result['data'] = editTabs($_POST);
  107. }else{
  108. $result['status'] = 'error';
  109. $result['statusText'] = 'API/Token invalid or not set';
  110. $result['data'] = null;
  111. }
  112. break;
  113. default:
  114. $result['status'] = 'error';
  115. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  116. break;
  117. }
  118. break;
  119. case 'v1_settings_tab_editor_categories':
  120. switch ($method) {
  121. case 'GET':
  122. if(qualifyRequest(1)){
  123. $result['status'] = 'success';
  124. $result['statusText'] = 'success';
  125. $result['data'] = $pageSettingsTabEditorCategories;
  126. }else{
  127. $result['status'] = 'error';
  128. $result['statusText'] = 'API/Token invalid or not set';
  129. $result['data'] = null;
  130. }
  131. break;
  132. case 'POST':
  133. if(qualifyRequest(1)){
  134. $result['status'] = 'success';
  135. $result['statusText'] = 'success';
  136. $result['data'] = editCategories($_POST);
  137. }else{
  138. $result['status'] = 'error';
  139. $result['statusText'] = 'API/Token invalid or not set';
  140. $result['data'] = null;
  141. }
  142. break;
  143. default:
  144. $result['status'] = 'error';
  145. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  146. break;
  147. }
  148. break;
  149. case 'v1_settings_user_manage_users':
  150. switch ($method) {
  151. case 'GET':
  152. if(qualifyRequest(1)){
  153. $result['status'] = 'success';
  154. $result['statusText'] = 'success';
  155. $result['data'] = $pageSettingsUserManageUsers;
  156. }else{
  157. $result['status'] = 'error';
  158. $result['statusText'] = 'API/Token invalid or not set';
  159. $result['data'] = null;
  160. }
  161. break;
  162. case 'POST':
  163. if(qualifyRequest(1)){
  164. $result['status'] = 'success';
  165. $result['statusText'] = 'success';
  166. $result['data'] = adminEditUser($_POST);
  167. }elseif(qualifyRequest(998)){
  168. $result['status'] = 'success';
  169. $result['statusText'] = 'success';
  170. $result['data'] = editUser($_POST);
  171. }else{
  172. $result['status'] = 'error';
  173. $result['statusText'] = 'API/Token invalid or not set';
  174. $result['data'] = null;
  175. }
  176. break;
  177. default:
  178. $result['status'] = 'error';
  179. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  180. break;
  181. }
  182. break;
  183. case 'v1_settings_user_manage_groups':
  184. switch ($method) {
  185. case 'GET':
  186. if(qualifyRequest(1)){
  187. $result['status'] = 'success';
  188. $result['statusText'] = 'success';
  189. $result['data'] = $pageSettingsUserManageGroups;
  190. }else{
  191. $result['status'] = 'error';
  192. $result['statusText'] = 'API/Token invalid or not set';
  193. $result['data'] = null;
  194. }
  195. break;
  196. case 'POST':
  197. if(qualifyRequest(1)){
  198. $result['status'] = 'success';
  199. $result['statusText'] = 'success';
  200. $result['data'] = adminEditGroup($_POST);
  201. }else{
  202. $result['status'] = 'error';
  203. $result['statusText'] = 'API/Token invalid or not set';
  204. $result['data'] = null;
  205. }
  206. break;
  207. default:
  208. $result['status'] = 'error';
  209. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  210. break;
  211. }
  212. break;
  213. case 'v1_wizard_page':
  214. switch ($method) {
  215. case 'GET':
  216. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  217. $result['status'] = 'success';
  218. $result['statusText'] = 'success';
  219. $result['data'] = $pageWizard;
  220. }else{
  221. $result['status'] = 'error';
  222. $result['statusText'] = 'Wizard has already been run';
  223. $result['data'] = null;
  224. }
  225. break;
  226. default:
  227. $result['status'] = 'error';
  228. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  229. break;
  230. }
  231. break;
  232. case 'v1_dependencies_page':
  233. switch ($method) {
  234. case 'GET':
  235. $result['status'] = 'success';
  236. $result['statusText'] = 'success';
  237. $result['data'] = $pageDependencies;
  238. break;
  239. default:
  240. $result['status'] = 'error';
  241. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  242. break;
  243. }
  244. break;
  245. case 'v1_wizard_config':
  246. switch ($method) {
  247. case 'POST':
  248. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  249. $result['status'] = 'success';
  250. $result['statusText'] = 'success';
  251. $result['data'] = wizardConfig($_POST);
  252. }else{
  253. $result['status'] = 'error';
  254. $result['statusText'] = 'Wizard has already been run';
  255. $result['data'] = null;
  256. }
  257. break;
  258. default:
  259. $result['status'] = 'error';
  260. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  261. break;
  262. }
  263. break;
  264. case 'v1_login':
  265. switch ($method) {
  266. case 'POST':
  267. $result['status'] = 'success';
  268. $result['statusText'] = 'success';
  269. $result['data'] = login($_POST);
  270. break;
  271. default:
  272. $result['status'] = 'error';
  273. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  274. break;
  275. }
  276. break;
  277. case 'v1_register':
  278. switch ($method) {
  279. case 'POST':
  280. $result['status'] = 'success';
  281. $result['statusText'] = 'success';
  282. $result['data'] = register($_POST);
  283. break;
  284. default:
  285. $result['status'] = 'error';
  286. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  287. break;
  288. }
  289. break;
  290. case 'v1_login_page':
  291. switch ($method) {
  292. case 'GET':
  293. $result['status'] = 'success';
  294. $result['statusText'] = 'success';
  295. $result['data'] = $pageLogin;
  296. break;
  297. default:
  298. $result['status'] = 'error';
  299. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  300. break;
  301. }
  302. break;
  303. case 'v1_lockscreen':
  304. switch ($method) {
  305. case 'GET':
  306. $result['status'] = 'success';
  307. $result['statusText'] = 'success';
  308. $result['data'] = $pageLockScreen;
  309. break;
  310. default:
  311. $result['status'] = 'error';
  312. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  313. break;
  314. }
  315. break;
  316. case 'v1_login_log':
  317. switch ($method) {
  318. case 'GET':
  319. if(qualifyRequest(1)){
  320. $result['status'] = 'success';
  321. $result['statusText'] = 'success';
  322. $result['data'] = getLog('loginLog');
  323. }else{
  324. $result['status'] = 'error';
  325. $result['statusText'] = 'API/Token invalid or not set';
  326. $result['data'] = null;
  327. }
  328. break;
  329. default:
  330. $result['status'] = 'error';
  331. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  332. break;
  333. }
  334. break;
  335. case 'v1_organizr_log':
  336. switch ($method) {
  337. case 'GET':
  338. if(qualifyRequest(1)){
  339. $result['status'] = 'success';
  340. $result['statusText'] = 'success';
  341. $result['data'] = getLog('org');
  342. }else{
  343. $result['status'] = 'error';
  344. $result['statusText'] = 'API/Token invalid or not set';
  345. $result['data'] = null;
  346. }
  347. break;
  348. default:
  349. $result['status'] = 'error';
  350. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  351. break;
  352. }
  353. break;
  354. case 'v1_user_list':
  355. switch ($method) {
  356. case 'GET':
  357. if(qualifyRequest(1)){
  358. $result['status'] = 'success';
  359. $result['statusText'] = 'success';
  360. $result['data'] = allUsers();
  361. }else{
  362. $result['status'] = 'error';
  363. $result['statusText'] = 'API/Token invalid or not set';
  364. $result['data'] = null;
  365. }
  366. break;
  367. default:
  368. $result['status'] = 'error';
  369. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  370. break;
  371. }
  372. break;
  373. case 'v1_tab_list':
  374. switch ($method) {
  375. case 'GET':
  376. if(qualifyRequest(1)){
  377. $result['status'] = 'success';
  378. $result['statusText'] = 'success';
  379. $result['data'] = allTabs();
  380. }else{
  381. $result['status'] = 'error';
  382. $result['statusText'] = 'API/Token invalid or not set';
  383. $result['data'] = null;
  384. }
  385. break;
  386. default:
  387. $result['status'] = 'error';
  388. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  389. break;
  390. }
  391. break;
  392. case 'v1_customize_appearance':
  393. switch ($method) {
  394. case 'GET':
  395. if(qualifyRequest(1)){
  396. $result['status'] = 'success';
  397. $result['statusText'] = 'success';
  398. $result['data'] = getCustomizeAppearance();
  399. }else{
  400. $result['status'] = 'error';
  401. $result['statusText'] = 'API/Token invalid or not set';
  402. $result['data'] = null;
  403. }
  404. break;
  405. default:
  406. $result['status'] = 'error';
  407. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  408. break;
  409. }
  410. break;
  411. case 'v1_user_edit':
  412. switch ($method) {
  413. case 'POST':
  414. if(qualifyRequest(1)){
  415. $result['status'] = 'success';
  416. $result['statusText'] = 'success';
  417. $result['data'] = adminEditUser($_POST);
  418. }elseif(qualifyRequest(998)){
  419. $result['status'] = 'success';
  420. $result['statusText'] = 'success';
  421. $result['data'] = editUser($_POST);
  422. }else{
  423. $result['status'] = 'error';
  424. $result['statusText'] = 'API/Token invalid or not set';
  425. $result['data'] = null;
  426. }
  427. break;
  428. default:
  429. $result['status'] = 'error';
  430. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  431. break;
  432. }
  433. break;
  434. case 'v1_logout':
  435. switch ($method) {
  436. case 'GET':
  437. $result['status'] = 'success';
  438. $result['statusText'] = 'success';
  439. $result['data'] = logout();
  440. break;
  441. default:
  442. $result['status'] = 'error';
  443. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  444. break;
  445. }
  446. break;
  447. case 'v1_launch_organizr':
  448. switch ($method) {
  449. case 'GET':
  450. $status = array();
  451. $result['status'] = 'success';
  452. $result['statusText'] = 'success';
  453. $status['status'] = organizrStatus();
  454. $result['appearance'] = loadAppearance();
  455. $status['user'] = $GLOBALS['organizrUser'];
  456. $status['categories'] = loadTabs()['categories'];
  457. $status['tabs'] = loadTabs()['tabs'];
  458. $result['data'] = $status;
  459. $result['branch'] = $GLOBALS['branch'];
  460. break;
  461. default:
  462. $result['status'] = 'error';
  463. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  464. break;
  465. }
  466. break;
  467. case 'v1_auth':
  468. switch ($method) {
  469. case 'GET':
  470. auth();
  471. break;
  472. default:
  473. $result['status'] = 'error';
  474. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  475. break;
  476. }
  477. break;
  478. case 'v1_plugin':
  479. switch ($method) {
  480. case 'GET':
  481. if(qualifyRequest(1)){
  482. $result['status'] = 'success';
  483. $result['statusText'] = 'success';
  484. $result['data'] = 'plugin admin';
  485. }elseif(qualifyRequest(998)){
  486. $result['status'] = 'success';
  487. $result['statusText'] = 'success';
  488. $result['data'] = 'plugin logged in';
  489. }elseif(qualifyRequest(999)){
  490. $result['status'] = 'success';
  491. $result['statusText'] = 'success';
  492. $result['data'] = 'plugin guest';
  493. }else{
  494. $result['status'] = 'error';
  495. $result['statusText'] = 'API/Token invalid or not set';
  496. $result['data'] = null;
  497. }
  498. break;
  499. case 'POST':
  500. if(qualifyRequest(1)){
  501. $result['status'] = 'success';
  502. $result['statusText'] = 'success';
  503. $result['data'] = 'plugin admin';
  504. }elseif(qualifyRequest(998)){
  505. $result['status'] = 'success';
  506. $result['statusText'] = 'success';
  507. $result['data'] = 'plugin logged in';
  508. }elseif(qualifyRequest(999)){
  509. $result['status'] = 'success';
  510. $result['statusText'] = 'success';
  511. $result['data'] = 'plugin guest';
  512. }else{
  513. $result['status'] = 'error';
  514. $result['statusText'] = 'API/Token invalid or not set';
  515. $result['data'] = null;
  516. }
  517. break;
  518. default:
  519. $result['status'] = 'error';
  520. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  521. break;
  522. }
  523. break;
  524. default:
  525. //No Function Available
  526. $result['status'] = 'error';
  527. $result['statusText'] = 'function requested is not defined';
  528. break;
  529. }
  530. //Set Default Result
  531. if(!$result){
  532. $result['status'] = "error";
  533. $result['error'] = "An error has occurred";
  534. }
  535. $result['generationDate'] = $GLOBALS['currentTime'];
  536. $generationTime += microtime(true);
  537. $result['generationTime'] = (sprintf('%f', $generationTime)*1000).'ms';
  538. //return JSON array
  539. exit(json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));