api-functions.php 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949
  1. <?php
  2. function login($array){
  3. // Grab username and Password from login form
  4. foreach ($array['data'] as $items) {
  5. foreach ($items as $key => $value) {
  6. if($key == 'name'){
  7. $newKey = $value;
  8. }
  9. if($key == 'value'){
  10. $newValue = $value;
  11. }
  12. if(isset($newKey) && isset($newValue)){
  13. $$newKey = $newValue;
  14. }
  15. }
  16. }
  17. $username = strtolower($username);
  18. $days = (isset($remember)) ? 7 : 1;
  19. try {
  20. $database = new Dibi\Connection([
  21. 'driver' => 'sqlite3',
  22. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  23. ]);
  24. $authSuccess = false;
  25. $function = 'plugin_auth_'.$GLOBALS['authBackend'];
  26. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$username);
  27. switch ($GLOBALS['authType']) {
  28. case 'external':
  29. if (function_exists($function)) {
  30. $authSuccess = $function($username, $password);
  31. }
  32. break;
  33. case 'both':
  34. if (function_exists($function)) {
  35. $authSuccess = $function($username, $password);
  36. }
  37. default: // Internal
  38. if (!$authSuccess) {
  39. // perform the internal authentication step
  40. if(password_verify($password, $result['password'])){
  41. $authSuccess = true;
  42. }
  43. }
  44. }
  45. if ($authSuccess) {
  46. // Make sure user exists in database
  47. $userExists = false;
  48. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  49. if($result['username']){
  50. $userExists = true;
  51. $username = $result['username'];
  52. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  53. }
  54. if ($userExists) {
  55. //does org password need to be updated
  56. if(!$passwordMatches){
  57. $database->query('
  58. UPDATE users SET', [
  59. 'password' => password_hash($password, PASSWORD_BCRYPT)
  60. ], '
  61. WHERE id=?', $result['id']);
  62. writeLog('success', 'Login Function - User Password updated from backend', $username);
  63. }
  64. // authentication passed - 1) mark active and update token
  65. if(createToken($result['username'],$result['email'],$result['image'],$result['group'],$result['group_id'],$GLOBALS['organizrHash'],$days)){
  66. writeLoginLog($username, 'success');
  67. writeLog('success', 'Login Function - A User has logged in', $username);
  68. ssoCheck($username, $password, $token); //need to work on this
  69. return true;
  70. }else{
  71. return 'error';
  72. }
  73. } else {
  74. // Create User
  75. ssoCheck($username, $password, $token);
  76. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username),$password,'',(is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  77. }
  78. } else {
  79. // authentication failed
  80. writeLoginLog($username, 'error');
  81. writeLog('error', 'Login Function - Wrong Password', $username);
  82. return 'mismatch';
  83. }
  84. } catch (Dibi\Exception $e) {
  85. return 'error';
  86. }
  87. }
  88. function createDB($path,$filename) {
  89. if(file_exists($path.$filename)){
  90. unlink($path.$filename);
  91. }
  92. try {
  93. $createDB = new Dibi\Connection([
  94. 'driver' => 'sqlite3',
  95. 'database' => $path.$filename,
  96. ]);
  97. // Create Users
  98. $users = $createDB->query('CREATE TABLE `users` (
  99. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  100. `username` TEXT UNIQUE,
  101. `password` TEXT,
  102. `email` TEXT,
  103. `plex_token` TEXT,
  104. `group` TEXT,
  105. `group_id` INTEGER,
  106. `locked` INTEGER,
  107. `image` TEXT,
  108. `register_date` DATE,
  109. `auth_service` TEXT DEFAULT \'internal\'
  110. );');
  111. // Create Tokens
  112. $jwt = $createDB->query('CREATE TABLE `tokens` (
  113. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  114. `token` TEXT UNIQUE,
  115. `user_id` INTEGER,
  116. `created` DATE,
  117. `expires` DATE
  118. );');
  119. $groups = $createDB->query('CREATE TABLE `groups` (
  120. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  121. `group` TEXT UNIQUE,
  122. `group_id` INTEGER,
  123. `image` TEXT,
  124. `default` INTEGER
  125. );');
  126. $categories = $createDB->query('CREATE TABLE `categories` (
  127. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  128. `order` INTEGER,
  129. `category` TEXT UNIQUE,
  130. `category_id` INTEGER,
  131. `image` TEXT,
  132. `default` INTEGER
  133. );');
  134. // Create Tabs
  135. $tabs = $createDB->query('CREATE TABLE `tabs` (
  136. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  137. `order` INTEGER,
  138. `category_id` INTEGER,
  139. `name` TEXT,
  140. `url` TEXT,
  141. `url_local` TEXT,
  142. `default` INTEGER,
  143. `enabled` INTEGER,
  144. `group_id` INTEGER,
  145. `image` TEXT,
  146. `type` INTEGER,
  147. `splash` INTEGER,
  148. `ping` INTEGER,
  149. `ping_url` TEXT
  150. );');
  151. // Create Options
  152. $options = $createDB->query('CREATE TABLE `options` (
  153. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  154. `users_id` INTEGER UNIQUE,
  155. `title` TEXT UNIQUE,
  156. `topbar` TEXT,
  157. `bottombar` TEXT,
  158. `sidebar` TEXT,
  159. `hoverbg` TEXT,
  160. `topbartext` TEXT,
  161. `activetabBG` TEXT,
  162. `activetabicon` TEXT,
  163. `activetabtext` TEXT,
  164. `inactiveicon` TEXT,
  165. `inactivetext` TEXT,
  166. `loading` TEXT,
  167. `hovertext` TEXT
  168. );');
  169. // Create Invites
  170. $invites = $createDB->query('CREATE TABLE `invites` (
  171. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  172. `code` TEXT UNIQUE,
  173. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  174. `email` TEXT,
  175. `username` TEXT,
  176. `dateused` TIMESTAMP,
  177. `usedby` TEXT,
  178. `ip` TEXT,
  179. `valid` TEXT,
  180. `type` TEXT
  181. );');
  182. return true;
  183. } catch (Dibi\Exception $e) {
  184. return false;
  185. }
  186. }
  187. // Upgrade Database
  188. function updateDB($path,$filename,$oldVerNum = false) {
  189. try {
  190. $connect = new Dibi\Connection([
  191. 'driver' => 'sqlite3',
  192. 'database' => $path.$filename,
  193. ]);
  194. // Cache current DB
  195. $cache = array();
  196. foreach($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  197. foreach($connect->query('SELECT * FROM '.$table['name'].';') as $key => $row) {
  198. foreach($row as $k => $v) {
  199. if (is_string($k)) {
  200. $cache[$table['name']][$key][$k] = $v;
  201. }
  202. }
  203. }
  204. }
  205. $connect->disconnect();
  206. } catch (Dibi\Exception $e) {
  207. return $e;
  208. }
  209. // Remove Current Database
  210. $pathDigest = pathinfo($path.$filename);
  211. if (file_exists($path.$filename)) {
  212. copy($path.$filename, $pathDigest['dirname'].'/'.$pathDigest['filename'].'['.date('Y-m-d_H-i-s').']'.($oldVerNum?'['.$oldVerNum.']':'').'.bak.db');
  213. unlink($path.$filename);
  214. }
  215. // Create New Database
  216. $success = createDB($path,$filename);
  217. try {
  218. $GLOBALS['connect'] = new Dibi\Connection([
  219. 'driver' => 'sqlite3',
  220. 'database' => $path.$filename,
  221. ]);
  222. // Restore Items
  223. if ($success) {
  224. foreach($cache as $table => $tableData) {
  225. if ($tableData) {
  226. $queryBase = 'INSERT INTO '.$table.' (`'.implode('`,`',array_keys(current($tableData))).'`) values ';
  227. $insertValues = array();
  228. reset($tableData);
  229. foreach($tableData as $key => $value) {
  230. $insertValues[] = '('.implode(',',array_map(function($d) {
  231. return (isset($d)?str_replace('\/', '/',json_encode($d)):'null');
  232. }, $value)).')';
  233. }
  234. $GLOBALS['connect']->query($queryBase.implode(',',$insertValues).';');
  235. }
  236. }
  237. }
  238. return true;
  239. } catch (Dibi\Exception $e) {
  240. return $e;
  241. }
  242. }
  243. function createFirstAdmin($path,$filename,$username,$password,$email) {
  244. try {
  245. $createDB = new Dibi\Connection([
  246. 'driver' => 'sqlite3',
  247. 'database' => $path.$filename,
  248. ]);
  249. $userInfo = [
  250. 'username' => $username,
  251. 'password' => password_hash($password, PASSWORD_BCRYPT),
  252. 'email' => $email,
  253. 'group' => 'Admin',
  254. 'group_id' => 0,
  255. 'image' => gravatar($email),
  256. 'register_date' => $GLOBALS['currentTime'],
  257. ];
  258. $groupInfo0 = [
  259. 'group' => 'Admin',
  260. 'group_id' => 0,
  261. 'default' => false,
  262. 'image' => 'plugins/images/groups/admin.png',
  263. ];
  264. $groupInfo1 = [
  265. 'group' => 'Co-Admin',
  266. 'group_id' => 1,
  267. 'default' => false,
  268. 'image' => 'plugins/images/groups/coadmin.png',
  269. ];
  270. $groupInfo2 = [
  271. 'group' => 'Super User',
  272. 'group_id' => 2,
  273. 'default' => false,
  274. 'image' => 'plugins/images/groups/superuser.png',
  275. ];
  276. $groupInfo3 = [
  277. 'group' => 'Power User',
  278. 'group_id' => 3,
  279. 'default' => false,
  280. 'image' => 'plugins/images/groups/poweruser.png',
  281. ];
  282. $groupInfo4 = [
  283. 'group' => 'User',
  284. 'group_id' => 4,
  285. 'default' => true,
  286. 'image' => 'plugins/images/groups/user.png',
  287. ];
  288. $groupInfoGuest = [
  289. 'group' => 'Guest',
  290. 'group_id' => 999,
  291. 'default' => false,
  292. 'image' => 'plugins/images/groups/guest.png',
  293. ];
  294. $settingsInfo = [
  295. 'order' => 1,
  296. 'category_id' => 0,
  297. 'name' => 'Settings',
  298. 'url' => 'api/?v1/settings/page',
  299. 'default' => false,
  300. 'enabled' => true,
  301. 'group_id' => 1,
  302. 'image' => 'fontawesome::cog',
  303. 'type' => 0
  304. ];
  305. $homepageInfo = [
  306. 'order' => 2,
  307. 'category_id' => 0,
  308. 'name' => 'Homepage',
  309. 'url' => 'api/?v1/homepage/page',
  310. 'default' => false,
  311. 'enabled' => false,
  312. 'group_id' => 4,
  313. 'image' => 'fontawesome::home',
  314. 'type' => 0
  315. ];
  316. $unsortedInfo = [
  317. 'order' => 1,
  318. 'category' => 'Unsorted',
  319. 'category_id' => 0,
  320. 'image' => 'plugins/images/categories/unsorted.png',
  321. 'default' => true
  322. ];
  323. $createDB->query('INSERT INTO [users]', $userInfo);
  324. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  325. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  326. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  327. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  328. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  329. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  330. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  331. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  332. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  333. return true;
  334. } catch (Dibi\Exception $e) {
  335. return false;
  336. }
  337. }
  338. function defaultUserGroup(){
  339. try {
  340. $connect = new Dibi\Connection([
  341. 'driver' => 'sqlite3',
  342. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  343. ]);
  344. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  345. return $all;
  346. } catch (Dibi\Exception $e) {
  347. return false;
  348. }
  349. }
  350. function defaulTabCategory(){
  351. try {
  352. $connect = new Dibi\Connection([
  353. 'driver' => 'sqlite3',
  354. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  355. ]);
  356. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  357. return $all;
  358. } catch (Dibi\Exception $e) {
  359. return false;
  360. }
  361. }
  362. function getGuest(){
  363. if(isset($GLOBALS['dbLocation'])){
  364. try {
  365. $connect = new Dibi\Connection([
  366. 'driver' => 'sqlite3',
  367. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  368. ]);
  369. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  370. return $all;
  371. } catch (Dibi\Exception $e) {
  372. return false;
  373. }
  374. }else{
  375. return array(
  376. 'group' => 'Guest',
  377. 'group_id' => 999,
  378. 'image' => 'plugins/images/groups/guest.png'
  379. );
  380. }
  381. }
  382. function adminEditGroup($array){
  383. switch ($array['data']['action']) {
  384. case 'changeDefaultGroup':
  385. try {
  386. $connect = new Dibi\Connection([
  387. 'driver' => 'sqlite3',
  388. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  389. ]);
  390. $connect->query('UPDATE groups SET `default` = 0');
  391. $connect->query('
  392. UPDATE groups SET', [
  393. 'default' => 1
  394. ], '
  395. WHERE id=?', $array['data']['id']);
  396. writeLog('success', 'Group Management Function - Changed Default Group from ['.$array['data']['oldGroupName'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  397. return true;
  398. } catch (Dibi\Exception $e) {
  399. return false;
  400. }
  401. break;
  402. case 'deleteUserGroup':
  403. try {
  404. $connect = new Dibi\Connection([
  405. 'driver' => 'sqlite3',
  406. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  407. ]);
  408. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  409. writeLog('success', 'Group Management Function - Deleted Group ['.$array['data']['groupName'].']', $GLOBALS['organizrUser']['username']);
  410. return true;
  411. } catch (Dibi\Exception $e) {
  412. return false;
  413. }
  414. break;
  415. case 'addUserGroup':
  416. try {
  417. $connect = new Dibi\Connection([
  418. 'driver' => 'sqlite3',
  419. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  420. ]);
  421. $newGroup = [
  422. 'group' => $array['data']['newGroupName'],
  423. 'group_id' => $array['data']['newGroupID'],
  424. 'default' => false,
  425. 'image' => $array['data']['newGroupImage'],
  426. ];
  427. $connect->query('INSERT INTO [groups]', $newGroup);
  428. writeLog('success', 'Group Management Function - Added Group ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  429. return true;
  430. } catch (Dibi\Exception $e) {
  431. return false;
  432. }
  433. break;
  434. case 'editUserGroup':
  435. try {
  436. $connect = new Dibi\Connection([
  437. 'driver' => 'sqlite3',
  438. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  439. ]);
  440. $connect->query('
  441. UPDATE groups SET', [
  442. 'group' => $array['data']['groupName'],
  443. 'image' => $array['data']['groupImage'],
  444. ], '
  445. WHERE id=?', $array['data']['id']);
  446. writeLog('success', 'Group Management Function - Edited Group Info for ['.$array['data']['oldGroupName'].']', $GLOBALS['organizrUser']['username']);
  447. return true;
  448. } catch (Dibi\Exception $e) {
  449. return false;
  450. }
  451. break;
  452. default:
  453. # code...
  454. break;
  455. }
  456. }
  457. function adminEditUser($array){
  458. switch ($array['data']['action']) {
  459. case 'changeGroup':
  460. try {
  461. $connect = new Dibi\Connection([
  462. 'driver' => 'sqlite3',
  463. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  464. ]);
  465. $connect->query('
  466. UPDATE users SET', [
  467. 'group' => $array['data']['newGroupName'],
  468. 'group_id' => $array['data']['newGroupID'],
  469. ], '
  470. WHERE id=?', $array['data']['id']);
  471. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  472. return true;
  473. } catch (Dibi\Exception $e) {
  474. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  475. return false;
  476. }
  477. break;
  478. case 'editUser':
  479. try {
  480. $connect = new Dibi\Connection([
  481. 'driver' => 'sqlite3',
  482. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  483. ]);
  484. if(!usernameTakenExcept($array['data']['username'],$array['data']['email'],$array['data']['id'])){
  485. $connect->query('
  486. UPDATE users SET', [
  487. 'username' => $array['data']['username'],
  488. 'email' => $array['data']['email'],
  489. ], '
  490. WHERE id=?', $array['data']['id']);
  491. if(!empty($array['data']['password'])){
  492. $connect->query('
  493. UPDATE users SET', [
  494. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  495. ], '
  496. WHERE id=?', $array['data']['id']);
  497. }
  498. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s info was changed', $GLOBALS['organizrUser']['username']);
  499. return true;
  500. }else{
  501. return false;
  502. }
  503. } catch (Dibi\Exception $e) {
  504. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  505. return false;
  506. }
  507. break;
  508. case 'addNewUser':
  509. $defaults = defaultUserGroup();
  510. if(createUser($array['data']['username'],$array['data']['password'],$defaults,$array['data']['email'])){
  511. writeLog('success', 'Create User Function - Acount created for ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  512. return true;
  513. }else{
  514. writeLog('error', 'Registration Function - An error occured', $GLOBALS['organizrUser']['username']);
  515. return 'username taken';
  516. }
  517. break;
  518. case 'deleteUser':
  519. try {
  520. $connect = new Dibi\Connection([
  521. 'driver' => 'sqlite3',
  522. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  523. ]);
  524. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  525. writeLog('success', 'User Management Function - Deleted User ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  526. return true;
  527. } catch (Dibi\Exception $e) {
  528. return false;
  529. }
  530. break;
  531. default:
  532. # code...
  533. break;
  534. }
  535. }
  536. function editTabs($array){
  537. switch ($array['data']['action']) {
  538. case 'changeGroup':
  539. try {
  540. $connect = new Dibi\Connection([
  541. 'driver' => 'sqlite3',
  542. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  543. ]);
  544. $connect->query('
  545. UPDATE tabs SET', [
  546. 'group_id' => $array['data']['newGroupID'],
  547. ], '
  548. WHERE id=?', $array['data']['id']);
  549. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s group was changed to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  550. return true;
  551. } catch (Dibi\Exception $e) {
  552. return false;
  553. }
  554. break;
  555. case 'changeCategory':
  556. try {
  557. $connect = new Dibi\Connection([
  558. 'driver' => 'sqlite3',
  559. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  560. ]);
  561. $connect->query('
  562. UPDATE tabs SET', [
  563. 'category_id' => $array['data']['newCategoryID'],
  564. ], '
  565. WHERE id=?', $array['data']['id']);
  566. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s category was changed to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  567. return true;
  568. } catch (Dibi\Exception $e) {
  569. return false;
  570. }
  571. break;
  572. case 'changeType':
  573. try {
  574. $connect = new Dibi\Connection([
  575. 'driver' => 'sqlite3',
  576. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  577. ]);
  578. $connect->query('
  579. UPDATE tabs SET', [
  580. 'type' => $array['data']['newTypeID'],
  581. ], '
  582. WHERE id=?', $array['data']['id']);
  583. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s type was changed to ['.$array['data']['newTypeName'].']', $GLOBALS['organizrUser']['username']);
  584. return true;
  585. } catch (Dibi\Exception $e) {
  586. return false;
  587. }
  588. break;
  589. case 'changeEnabled':
  590. try {
  591. $connect = new Dibi\Connection([
  592. 'driver' => 'sqlite3',
  593. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  594. ]);
  595. $connect->query('
  596. UPDATE tabs SET', [
  597. 'enabled' => $array['data']['tabEnabled'],
  598. ], '
  599. WHERE id=?', $array['data']['id']);
  600. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s enable status was changed to ['.$array['data']['tabEnabledWord'].']', $GLOBALS['organizrUser']['username']);
  601. return true;
  602. } catch (Dibi\Exception $e) {
  603. return false;
  604. }
  605. break;
  606. case 'changeSplash':
  607. try {
  608. $connect = new Dibi\Connection([
  609. 'driver' => 'sqlite3',
  610. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  611. ]);
  612. $connect->query('
  613. UPDATE tabs SET', [
  614. 'splash' => $array['data']['tabSplash'],
  615. ], '
  616. WHERE id=?', $array['data']['id']);
  617. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s splash status was changed to ['.$array['data']['tabSplashWord'].']', $GLOBALS['organizrUser']['username']);
  618. return true;
  619. } catch (Dibi\Exception $e) {
  620. return false;
  621. }
  622. break;
  623. case 'changeDefault':
  624. try {
  625. $connect = new Dibi\Connection([
  626. 'driver' => 'sqlite3',
  627. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  628. ]);
  629. $connect->query('UPDATE tabs SET `default` = 0');
  630. $connect->query('
  631. UPDATE tabs SET', [
  632. 'default' => 1
  633. ], '
  634. WHERE id=?', $array['data']['id']);
  635. writeLog('success', 'Tab Editor Function - Changed Default Tab to ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  636. return true;
  637. } catch (Dibi\Exception $e) {
  638. return false;
  639. }
  640. break;
  641. case 'deleteTab':
  642. try {
  643. $connect = new Dibi\Connection([
  644. 'driver' => 'sqlite3',
  645. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  646. ]);
  647. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  648. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  649. return true;
  650. } catch (Dibi\Exception $e) {
  651. return false;
  652. }
  653. break;
  654. case 'editTab':
  655. try {
  656. $connect = new Dibi\Connection([
  657. 'driver' => 'sqlite3',
  658. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  659. ]);
  660. $connect->query('
  661. UPDATE tabs SET', [
  662. 'name' => $array['data']['tabName'],
  663. 'url' => $array['data']['tabURL'],
  664. 'image' => $array['data']['tabImage'],
  665. ], '
  666. WHERE id=?', $array['data']['id']);
  667. writeLog('success', 'Tab Editor Function - Edited Tab Info for ['.$array['data']['tabName'].']', $GLOBALS['organizrUser']['username']);
  668. return true;
  669. } catch (Dibi\Exception $e) {
  670. return false;
  671. }
  672. case 'changeOrder':
  673. try {
  674. $connect = new Dibi\Connection([
  675. 'driver' => 'sqlite3',
  676. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  677. ]);
  678. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  679. if($value['order'] != $value['originalOrder']){
  680. $connect->query('
  681. UPDATE tabs SET', [
  682. 'order' => $value['order'],
  683. ], '
  684. WHERE id=?', $value['id']);
  685. writeLog('success', 'Tab Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  686. }
  687. }
  688. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  689. return true;
  690. } catch (Dibi\Exception $e) {
  691. return false;
  692. }
  693. break;
  694. case 'addNewTab':
  695. try {
  696. $default = defaulTabCategory()['category_id'];
  697. $connect = new Dibi\Connection([
  698. 'driver' => 'sqlite3',
  699. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  700. ]);
  701. $newTab = [
  702. 'order' => $array['data']['tabOrder'],
  703. 'category_id' => $default,
  704. 'name' => $array['data']['tabName'],
  705. 'url' => $array['data']['tabURL'],
  706. 'default' => $array['data']['tabDefault'],
  707. 'enabled' => 1,
  708. 'group_id' => $array['data']['tabGroupID'],
  709. 'image' => $array['data']['tabImage'],
  710. 'type' => $array['data']['tabType']
  711. ];
  712. $connect->query('INSERT INTO [tabs]', $newTab);
  713. writeLog('success', 'Tab Editor Function - Created Tab for: '.$array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  714. return true;
  715. } catch (Dibi\Exception $e) {
  716. return false;
  717. }
  718. break;
  719. case 'deleteTab':
  720. try {
  721. $connect = new Dibi\Connection([
  722. 'driver' => 'sqlite3',
  723. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  724. ]);
  725. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  726. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  727. return true;
  728. } catch (Dibi\Exception $e) {
  729. return false;
  730. }
  731. break;
  732. default:
  733. # code...
  734. break;
  735. }
  736. }
  737. function editCategories($array){
  738. switch ($array['data']['action']) {
  739. case 'changeDefault':
  740. try {
  741. $connect = new Dibi\Connection([
  742. 'driver' => 'sqlite3',
  743. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  744. ]);
  745. $connect->query('UPDATE categories SET `default` = 0');
  746. $connect->query('
  747. UPDATE categories SET', [
  748. 'default' => 1
  749. ], '
  750. WHERE id=?', $array['data']['id']);
  751. writeLog('success', 'Category Editor Function - Changed Default Category from ['.$array['data']['oldCategoryName'].'] to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  752. return true;
  753. } catch (Dibi\Exception $e) {
  754. return false;
  755. }
  756. break;
  757. case 'deleteCategory':
  758. try {
  759. $connect = new Dibi\Connection([
  760. 'driver' => 'sqlite3',
  761. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  762. ]);
  763. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  764. writeLog('success', 'Category Editor Function - Deleted Category ['.$array['data']['category'].']', $GLOBALS['organizrUser']['username']);
  765. return true;
  766. } catch (Dibi\Exception $e) {
  767. return false;
  768. }
  769. break;
  770. case 'addNewCategory':
  771. try {
  772. $connect = new Dibi\Connection([
  773. 'driver' => 'sqlite3',
  774. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  775. ]);
  776. $newCategory = [
  777. 'category' => $array['data']['categoryName'],
  778. 'order' => $array['data']['categoryOrder'],
  779. 'category_id' => $array['data']['categoryID'],
  780. 'default' => false,
  781. 'image' => $array['data']['categoryImage'],
  782. ];
  783. $connect->query('INSERT INTO [categories]', $newCategory);
  784. writeLog('success', 'Category Editor Function - Added Category ['.$array['data']['categoryName'].']', $GLOBALS['organizrUser']['username']);
  785. return true;
  786. } catch (Dibi\Exception $e) {
  787. return $e;
  788. }
  789. break;
  790. case 'editCategory':
  791. try {
  792. $connect = new Dibi\Connection([
  793. 'driver' => 'sqlite3',
  794. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  795. ]);
  796. $connect->query('
  797. UPDATE categories SET', [
  798. 'category' => $array['data']['name'],
  799. 'image' => $array['data']['image'],
  800. ], '
  801. WHERE id=?', $array['data']['id']);
  802. writeLog('success', 'Category Editor Function - Edited Category Info for ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  803. return true;
  804. } catch (Dibi\Exception $e) {
  805. return false;
  806. }
  807. break;
  808. case 'changeOrder':
  809. try {
  810. $connect = new Dibi\Connection([
  811. 'driver' => 'sqlite3',
  812. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  813. ]);
  814. foreach ($array['data']['categories']['category'] as $key => $value) {
  815. if($value['order'] != $value['originalOrder']){
  816. $connect->query('
  817. UPDATE categories SET', [
  818. 'order' => $value['order'],
  819. ], '
  820. WHERE id=?', $value['id']);
  821. writeLog('success', 'Category Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  822. }
  823. }
  824. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  825. return true;
  826. } catch (Dibi\Exception $e) {
  827. return false;
  828. }
  829. break;
  830. default:
  831. # code...
  832. break;
  833. }
  834. }
  835. function allUsers(){
  836. try {
  837. $connect = new Dibi\Connection([
  838. 'driver' => 'sqlite3',
  839. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  840. ]);
  841. $users = $connect->fetchAll('SELECT * FROM users');
  842. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  843. foreach ($users as $k => $v) {
  844. // clear password from array
  845. unset($users[$k]['password']);
  846. }
  847. $all['users'] = $users;
  848. $all['groups'] = $groups;
  849. return $all;
  850. } catch (Dibi\Exception $e) {
  851. return false;
  852. }
  853. }
  854. function usernameTaken($username,$email){
  855. try {
  856. $connect = new Dibi\Connection([
  857. 'driver' => 'sqlite3',
  858. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  859. ]);
  860. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$email);
  861. return ($all) ? true : false;
  862. } catch (Dibi\Exception $e) {
  863. return false;
  864. }
  865. }
  866. function usernameTakenExcept($username,$email,$id){
  867. try {
  868. $connect = new Dibi\Connection([
  869. 'driver' => 'sqlite3',
  870. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  871. ]);
  872. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE',$id,$username,$id,$email);
  873. return ($all) ? true : false;
  874. } catch (Dibi\Exception $e) {
  875. return false;
  876. }
  877. }
  878. function createUser($username,$password,$defaults,$email=null) {
  879. $email = ($email) ? $email : random_ascii_string(10).'@placeholder.eml';
  880. try {
  881. if(!usernameTaken($username,$email)){
  882. $createDB = new Dibi\Connection([
  883. 'driver' => 'sqlite3',
  884. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  885. ]);
  886. $userInfo = [
  887. 'username' => $username,
  888. 'password' => password_hash($password, PASSWORD_BCRYPT),
  889. 'email' => $email,
  890. 'group' => $defaults['group'],
  891. 'group_id' => $defaults['group_id'],
  892. 'image' => gravatar($email),
  893. 'register_date' => $GLOBALS['currentTime'],
  894. ];
  895. $createDB->query('INSERT INTO [users]', $userInfo);
  896. return true;
  897. }else{
  898. return false;
  899. }
  900. } catch (Dibi\Exception $e) {
  901. return false;
  902. }
  903. }
  904. function allTabs(){
  905. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  906. try {
  907. $connect = new Dibi\Connection([
  908. 'driver' => 'sqlite3',
  909. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  910. ]);
  911. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  912. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  913. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  914. return $all;
  915. } catch (Dibi\Exception $e) {
  916. return false;
  917. }
  918. }
  919. }
  920. function loadTabs(){
  921. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  922. try {
  923. $connect = new Dibi\Connection([
  924. 'driver' => 'sqlite3',
  925. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  926. ]);
  927. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` DESC',$GLOBALS['organizrUser']['groupID']);
  928. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  929. $all['tabs'] = $tabs;
  930. foreach ($tabs as $k => $v) {
  931. $v['access_url'] = isset($v['url_local']) && $_SERVER['SERVER_ADDR'] == userIP() ? $v['url_local'] : $v['url'];
  932. }
  933. $count = array_map(function($element){
  934. return $element['category_id'];
  935. }, $tabs);
  936. $count = (array_count_values($count));
  937. foreach ($categories as $k => $v) {
  938. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  939. }
  940. $all['categories'] = $categories;
  941. return $all;
  942. } catch (Dibi\Exception $e) {
  943. return false;
  944. }
  945. }
  946. }