api-functions.php 36 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = $oAuth = $oAuthType = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  25. $oAuth = (isset($oAuth)) ? $oAuth : false;
  26. try {
  27. $database = new Dibi\Connection([
  28. 'driver' => 'sqlite3',
  29. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  30. ]);
  31. $authSuccess = false;
  32. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  33. if (!$oAuth) {
  34. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  35. switch ($GLOBALS['authType']) {
  36. case 'external':
  37. if (function_exists($function)) {
  38. $authSuccess = $function($username, $password);
  39. }
  40. break;
  41. /** @noinspection PhpMissingBreakStatementInspection */
  42. case 'both':
  43. if (function_exists($function)) {
  44. $authSuccess = $function($username, $password);
  45. }
  46. // no break
  47. default: // Internal
  48. if (!$authSuccess) {
  49. // perform the internal authentication step
  50. if (password_verify($password, $result['password'])) {
  51. $authSuccess = true;
  52. }
  53. }
  54. }
  55. } else {
  56. // Has oAuth Token!
  57. switch ($oAuthType) {
  58. case 'plex':
  59. if ($GLOBALS['plexoAuth']) {
  60. $tokenInfo = checkPlexToken($oAuth);
  61. if ($tokenInfo) {
  62. $authSuccess = array(
  63. 'username' => $tokenInfo['user']['username'],
  64. 'email' => $tokenInfo['user']['email'],
  65. 'image' => $tokenInfo['user']['thumb'],
  66. 'token' => $tokenInfo['user']['authToken']
  67. );
  68. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  69. }
  70. }
  71. break;
  72. default:
  73. return 'error';
  74. break;
  75. }
  76. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  77. }
  78. if ($authSuccess) {
  79. // Make sure user exists in database
  80. $userExists = false;
  81. $passwordMatches = ($oAuth) ? true : false;
  82. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  83. if ($result['username']) {
  84. $userExists = true;
  85. $username = $result['username'];
  86. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  87. }
  88. if ($userExists) {
  89. //does org password need to be updated
  90. if (!$passwordMatches) {
  91. $database->query('
  92. UPDATE users SET', [
  93. 'password' => password_hash($password, PASSWORD_BCRYPT)
  94. ], '
  95. WHERE id=?', $result['id']);
  96. writeLog('success', 'Login Function - User Password updated from backend', $username);
  97. }
  98. if ($token !== '') {
  99. if ($token !== $result['plex_token']) {
  100. $database->query('
  101. UPDATE users SET', [
  102. 'plex_token' => $token
  103. ], '
  104. WHERE id=?', $result['id']);
  105. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  106. }
  107. }
  108. // 2FA might go here
  109. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  110. $TFA = explode('::', $result['auth_service']);
  111. // Is code with login info?
  112. if ($tfaCode == '') {
  113. return '2FA';
  114. } else {
  115. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  116. writeLoginLog($username, 'error');
  117. writeLog('error', 'Login Function - Wrong 2FA', $username);
  118. return '2FA-incorrect';
  119. }
  120. }
  121. }
  122. // End 2FA
  123. // authentication passed - 1) mark active and update token
  124. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  125. writeLoginLog($username, 'success');
  126. writeLog('success', 'Login Function - A User has logged in', $username);
  127. ssoCheck($username, $password, $token); //need to work on this
  128. return true;
  129. } else {
  130. return 'error';
  131. }
  132. } else {
  133. // Create User
  134. //ssoCheck($username, $password, $token);
  135. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  136. }
  137. } else {
  138. // authentication failed
  139. writeLoginLog($username, 'error');
  140. writeLog('error', 'Login Function - Wrong Password', $username);
  141. return 'mismatch';
  142. }
  143. } catch (Dibi\Exception $e) {
  144. return $e;
  145. }
  146. }
  147. function createDB($path, $filename)
  148. {
  149. try {
  150. if (!file_exists($path)) {
  151. mkdir($path, 0777, true);
  152. }
  153. $createDB = new Dibi\Connection([
  154. 'driver' => 'sqlite3',
  155. 'database' => $path . $filename,
  156. ]);
  157. // Create Users
  158. $createDB->query('CREATE TABLE `users` (
  159. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  160. `username` TEXT UNIQUE,
  161. `password` TEXT,
  162. `email` TEXT,
  163. `plex_token` TEXT,
  164. `group` TEXT,
  165. `group_id` INTEGER,
  166. `locked` INTEGER,
  167. `image` TEXT,
  168. `register_date` DATE,
  169. `auth_service` TEXT DEFAULT \'internal\'
  170. );');
  171. // Create Tokens
  172. $createDB->query('CREATE TABLE `chatroom` (
  173. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  174. `username` TEXT,
  175. `gravatar` TEXT,
  176. `uid` TEXT,
  177. `date` DATE,
  178. `ip` TEXT,
  179. `message` TEXT
  180. );');
  181. $createDB->query('CREATE TABLE `tokens` (
  182. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  183. `token` TEXT UNIQUE,
  184. `user_id` INTEGER,
  185. `browser` TEXT,
  186. `ip` TEXT,
  187. `created` DATE,
  188. `expires` DATE
  189. );');
  190. $createDB->query('CREATE TABLE `groups` (
  191. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  192. `group` TEXT UNIQUE,
  193. `group_id` INTEGER,
  194. `image` TEXT,
  195. `default` INTEGER
  196. );');
  197. $createDB->query('CREATE TABLE `categories` (
  198. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  199. `order` INTEGER,
  200. `category` TEXT UNIQUE,
  201. `category_id` INTEGER,
  202. `image` TEXT,
  203. `default` INTEGER
  204. );');
  205. // Create Tabs
  206. $createDB->query('CREATE TABLE `tabs` (
  207. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  208. `order` INTEGER,
  209. `category_id` INTEGER,
  210. `name` TEXT,
  211. `url` TEXT,
  212. `url_local` TEXT,
  213. `default` INTEGER,
  214. `enabled` INTEGER,
  215. `group_id` INTEGER,
  216. `image` TEXT,
  217. `type` INTEGER,
  218. `splash` INTEGER,
  219. `ping` INTEGER,
  220. `ping_url` TEXT,
  221. `timeout` INTEGER,
  222. `timeout_ms` INTEGER
  223. );');
  224. // Create Options
  225. $createDB->query('CREATE TABLE `options` (
  226. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  227. `name` TEXT UNIQUE,
  228. `value` TEXT
  229. );');
  230. // Create Invites
  231. $createDB->query('CREATE TABLE `invites` (
  232. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  233. `code` TEXT UNIQUE,
  234. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  235. `email` TEXT,
  236. `username` TEXT,
  237. `dateused` TIMESTAMP,
  238. `usedby` TEXT,
  239. `ip` TEXT,
  240. `valid` TEXT,
  241. `type` TEXT
  242. );');
  243. return true;
  244. } catch (Dibi\Exception $e) {
  245. return false;
  246. }
  247. }
  248. // Upgrade Database
  249. function updateDB($oldVerNum = false)
  250. {
  251. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  252. if (!file_exists($tempLock)) {
  253. touch($tempLock);
  254. // Create Temp DB First
  255. $migrationDB = 'tempMigration.db';
  256. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  257. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  258. unlink($GLOBALS['dbLocation'] . $migrationDB);
  259. }
  260. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  261. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  262. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  263. if ($success) {
  264. try {
  265. $connectOldDB = new Dibi\Connection([
  266. 'driver' => 'sqlite3',
  267. 'database' => $backupDB,
  268. ]);
  269. $connectNewDB = new Dibi\Connection([
  270. 'driver' => 'sqlite3',
  271. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  272. ]);
  273. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  274. foreach ($tables as $table) {
  275. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  276. foreach ($data as $row) {
  277. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  278. }
  279. }
  280. $connectOldDB->disconnect();
  281. $connectNewDB->disconnect();
  282. // Remove Current Database
  283. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  284. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  285. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  286. if ($newFileSize >= $oldFileSize) {
  287. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  288. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  289. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  290. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  291. unlink($tempLock);
  292. return true;
  293. }
  294. }
  295. unlink($tempLock);
  296. return false;
  297. } catch (Dibi\Exception $e) {
  298. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  299. unlink($tempLock);
  300. return false;
  301. }
  302. }
  303. unlink($tempLock);
  304. return false;
  305. }
  306. return false;
  307. }
  308. function createFirstAdmin($path, $filename, $username, $password, $email)
  309. {
  310. try {
  311. $createDB = new Dibi\Connection([
  312. 'driver' => 'sqlite3',
  313. 'database' => $path . $filename,
  314. ]);
  315. $userInfo = [
  316. 'username' => $username,
  317. 'password' => password_hash($password, PASSWORD_BCRYPT),
  318. 'email' => $email,
  319. 'group' => 'Admin',
  320. 'group_id' => 0,
  321. 'image' => gravatar($email),
  322. 'register_date' => $GLOBALS['currentTime'],
  323. ];
  324. $groupInfo0 = [
  325. 'group' => 'Admin',
  326. 'group_id' => 0,
  327. 'default' => false,
  328. 'image' => 'plugins/images/groups/admin.png',
  329. ];
  330. $groupInfo1 = [
  331. 'group' => 'Co-Admin',
  332. 'group_id' => 1,
  333. 'default' => false,
  334. 'image' => 'plugins/images/groups/coadmin.png',
  335. ];
  336. $groupInfo2 = [
  337. 'group' => 'Super User',
  338. 'group_id' => 2,
  339. 'default' => false,
  340. 'image' => 'plugins/images/groups/superuser.png',
  341. ];
  342. $groupInfo3 = [
  343. 'group' => 'Power User',
  344. 'group_id' => 3,
  345. 'default' => false,
  346. 'image' => 'plugins/images/groups/poweruser.png',
  347. ];
  348. $groupInfo4 = [
  349. 'group' => 'User',
  350. 'group_id' => 4,
  351. 'default' => true,
  352. 'image' => 'plugins/images/groups/user.png',
  353. ];
  354. $groupInfoGuest = [
  355. 'group' => 'Guest',
  356. 'group_id' => 999,
  357. 'default' => false,
  358. 'image' => 'plugins/images/groups/guest.png',
  359. ];
  360. $settingsInfo = [
  361. 'order' => 1,
  362. 'category_id' => 0,
  363. 'name' => 'Settings',
  364. 'url' => 'api/?v1/settings/page',
  365. 'default' => false,
  366. 'enabled' => true,
  367. 'group_id' => 1,
  368. 'image' => 'fontawesome::cog',
  369. 'type' => 0
  370. ];
  371. $homepageInfo = [
  372. 'order' => 2,
  373. 'category_id' => 0,
  374. 'name' => 'Homepage',
  375. 'url' => 'api/?v1/homepage/page',
  376. 'default' => false,
  377. 'enabled' => false,
  378. 'group_id' => 4,
  379. 'image' => 'fontawesome::home',
  380. 'type' => 0
  381. ];
  382. $unsortedInfo = [
  383. 'order' => 1,
  384. 'category' => 'Unsorted',
  385. 'category_id' => 0,
  386. 'image' => 'plugins/images/categories/unsorted.png',
  387. 'default' => true
  388. ];
  389. $createDB->query('INSERT INTO [users]', $userInfo);
  390. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  391. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  392. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  393. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  394. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  395. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  396. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  397. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  398. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  399. return true;
  400. } catch (Dibi\Exception $e) {
  401. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  402. return false;
  403. }
  404. }
  405. function defaultUserGroup()
  406. {
  407. try {
  408. $connect = new Dibi\Connection([
  409. 'driver' => 'sqlite3',
  410. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  411. ]);
  412. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  413. return $all;
  414. } catch (Dibi\Exception $e) {
  415. return false;
  416. }
  417. }
  418. function defaultTabCategory()
  419. {
  420. try {
  421. $connect = new Dibi\Connection([
  422. 'driver' => 'sqlite3',
  423. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  424. ]);
  425. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  426. return $all;
  427. } catch (Dibi\Exception $e) {
  428. return false;
  429. }
  430. }
  431. function getGuest()
  432. {
  433. if (isset($GLOBALS['dbLocation'])) {
  434. try {
  435. $connect = new Dibi\Connection([
  436. 'driver' => 'sqlite3',
  437. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  438. ]);
  439. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  440. return $all;
  441. } catch (Dibi\Exception $e) {
  442. return false;
  443. }
  444. } else {
  445. return array(
  446. 'group' => 'Guest',
  447. 'group_id' => 999,
  448. 'image' => 'plugins/images/groups/guest.png'
  449. );
  450. }
  451. }
  452. function adminEditGroup($array)
  453. {
  454. switch ($array['data']['action']) {
  455. case 'changeDefaultGroup':
  456. try {
  457. $connect = new Dibi\Connection([
  458. 'driver' => 'sqlite3',
  459. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  460. ]);
  461. $connect->query('UPDATE groups SET `default` = 0');
  462. $connect->query('
  463. UPDATE groups SET', [
  464. 'default' => 1
  465. ], '
  466. WHERE id=?', $array['data']['id']);
  467. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  468. return true;
  469. } catch (Dibi\Exception $e) {
  470. return false;
  471. }
  472. break;
  473. case 'deleteUserGroup':
  474. try {
  475. $connect = new Dibi\Connection([
  476. 'driver' => 'sqlite3',
  477. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  478. ]);
  479. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  480. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  481. return true;
  482. } catch (Dibi\Exception $e) {
  483. return false;
  484. }
  485. break;
  486. case 'addUserGroup':
  487. try {
  488. $connect = new Dibi\Connection([
  489. 'driver' => 'sqlite3',
  490. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  491. ]);
  492. $newGroup = [
  493. 'group' => $array['data']['newGroupName'],
  494. 'group_id' => $array['data']['newGroupID'],
  495. 'default' => false,
  496. 'image' => $array['data']['newGroupImage'],
  497. ];
  498. $connect->query('INSERT INTO [groups]', $newGroup);
  499. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  500. return true;
  501. } catch (Dibi\Exception $e) {
  502. return false;
  503. }
  504. break;
  505. case 'editUserGroup':
  506. try {
  507. $connect = new Dibi\Connection([
  508. 'driver' => 'sqlite3',
  509. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  510. ]);
  511. $connect->query('
  512. UPDATE groups SET', [
  513. 'group' => $array['data']['groupName'],
  514. 'image' => $array['data']['groupImage'],
  515. ], '
  516. WHERE id=?', $array['data']['id']);
  517. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  518. return true;
  519. } catch (Dibi\Exception $e) {
  520. return false;
  521. }
  522. break;
  523. default:
  524. return false;
  525. break;
  526. }
  527. }
  528. function adminEditUser($array)
  529. {
  530. switch ($array['data']['action']) {
  531. case 'changeGroup':
  532. try {
  533. $connect = new Dibi\Connection([
  534. 'driver' => 'sqlite3',
  535. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  536. ]);
  537. $connect->query('
  538. UPDATE users SET', [
  539. 'group' => $array['data']['newGroupName'],
  540. 'group_id' => $array['data']['newGroupID'],
  541. ], '
  542. WHERE id=?', $array['data']['id']);
  543. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  544. return true;
  545. } catch (Dibi\Exception $e) {
  546. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  547. return false;
  548. }
  549. break;
  550. case 'editUser':
  551. try {
  552. $connect = new Dibi\Connection([
  553. 'driver' => 'sqlite3',
  554. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  555. ]);
  556. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  557. $connect->query('
  558. UPDATE users SET', [
  559. 'username' => $array['data']['username'],
  560. 'email' => $array['data']['email'],
  561. 'image' => gravatar($array['data']['email']),
  562. ], '
  563. WHERE id=?', $array['data']['id']);
  564. if (!empty($array['data']['password'])) {
  565. $connect->query('
  566. UPDATE users SET', [
  567. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  568. ], '
  569. WHERE id=?', $array['data']['id']);
  570. }
  571. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  572. return true;
  573. } else {
  574. return false;
  575. }
  576. } catch (Dibi\Exception $e) {
  577. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  578. return false;
  579. }
  580. break;
  581. case 'addNewUser':
  582. $defaults = defaultUserGroup();
  583. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  584. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  585. return true;
  586. } else {
  587. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  588. return 'username taken';
  589. }
  590. break;
  591. case 'deleteUser':
  592. try {
  593. $connect = new Dibi\Connection([
  594. 'driver' => 'sqlite3',
  595. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  596. ]);
  597. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  598. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  599. return true;
  600. } catch (Dibi\Exception $e) {
  601. return false;
  602. }
  603. break;
  604. default:
  605. return false;
  606. break;
  607. }
  608. }
  609. function editTabs($array)
  610. {
  611. switch ($array['data']['action']) {
  612. case 'changeGroup':
  613. try {
  614. $connect = new Dibi\Connection([
  615. 'driver' => 'sqlite3',
  616. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  617. ]);
  618. $connect->query('
  619. UPDATE tabs SET', [
  620. 'group_id' => $array['data']['newGroupID'],
  621. ], '
  622. WHERE id=?', $array['data']['id']);
  623. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  624. return true;
  625. } catch (Dibi\Exception $e) {
  626. return false;
  627. }
  628. break;
  629. case 'changeCategory':
  630. try {
  631. $connect = new Dibi\Connection([
  632. 'driver' => 'sqlite3',
  633. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  634. ]);
  635. $connect->query('
  636. UPDATE tabs SET', [
  637. 'category_id' => $array['data']['newCategoryID'],
  638. ], '
  639. WHERE id=?', $array['data']['id']);
  640. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  641. return true;
  642. } catch (Dibi\Exception $e) {
  643. return false;
  644. }
  645. break;
  646. case 'changeType':
  647. try {
  648. $connect = new Dibi\Connection([
  649. 'driver' => 'sqlite3',
  650. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  651. ]);
  652. $connect->query('
  653. UPDATE tabs SET', [
  654. 'type' => $array['data']['newTypeID'],
  655. ], '
  656. WHERE id=?', $array['data']['id']);
  657. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  658. return true;
  659. } catch (Dibi\Exception $e) {
  660. return false;
  661. }
  662. break;
  663. case 'changeEnabled':
  664. try {
  665. $connect = new Dibi\Connection([
  666. 'driver' => 'sqlite3',
  667. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  668. ]);
  669. $connect->query('
  670. UPDATE tabs SET', [
  671. 'enabled' => $array['data']['tabEnabled'],
  672. ], '
  673. WHERE id=?', $array['data']['id']);
  674. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  675. return true;
  676. } catch (Dibi\Exception $e) {
  677. return false;
  678. }
  679. break;
  680. case 'changeSplash':
  681. try {
  682. $connect = new Dibi\Connection([
  683. 'driver' => 'sqlite3',
  684. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  685. ]);
  686. $connect->query('
  687. UPDATE tabs SET', [
  688. 'splash' => $array['data']['tabSplash'],
  689. ], '
  690. WHERE id=?', $array['data']['id']);
  691. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  692. return true;
  693. } catch (Dibi\Exception $e) {
  694. return false;
  695. }
  696. break;
  697. case 'changePing':
  698. try {
  699. $connect = new Dibi\Connection([
  700. 'driver' => 'sqlite3',
  701. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  702. ]);
  703. $connect->query('
  704. UPDATE tabs SET', [
  705. 'ping' => $array['data']['tabPing'],
  706. ], '
  707. WHERE id=?', $array['data']['id']);
  708. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  709. return true;
  710. } catch (Dibi\Exception $e) {
  711. return false;
  712. }
  713. break;
  714. case 'changeDefault':
  715. try {
  716. $connect = new Dibi\Connection([
  717. 'driver' => 'sqlite3',
  718. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  719. ]);
  720. $connect->query('UPDATE tabs SET `default` = 0');
  721. $connect->query('
  722. UPDATE tabs SET', [
  723. 'default' => 1
  724. ], '
  725. WHERE id=?', $array['data']['id']);
  726. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  727. return true;
  728. } catch (Dibi\Exception $e) {
  729. return false;
  730. }
  731. break;
  732. case 'deleteTab':
  733. try {
  734. $connect = new Dibi\Connection([
  735. 'driver' => 'sqlite3',
  736. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  737. ]);
  738. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  739. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  740. return true;
  741. } catch (Dibi\Exception $e) {
  742. return false;
  743. }
  744. break;
  745. case 'editTab':
  746. try {
  747. $connect = new Dibi\Connection([
  748. 'driver' => 'sqlite3',
  749. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  750. ]);
  751. $connect->query('
  752. UPDATE tabs SET', [
  753. 'name' => $array['data']['tabName'],
  754. 'url' => $array['data']['tabURL'],
  755. 'ping_url' => $array['data']['pingURL'],
  756. 'image' => $array['data']['tabImage'],
  757. ], '
  758. WHERE id=?', $array['data']['id']);
  759. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  760. return true;
  761. } catch (Dibi\Exception $e) {
  762. return false;
  763. }
  764. case 'changeOrder':
  765. try {
  766. $connect = new Dibi\Connection([
  767. 'driver' => 'sqlite3',
  768. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  769. ]);
  770. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  771. if ($value['order'] != $value['originalOrder']) {
  772. $connect->query('
  773. UPDATE tabs SET', [
  774. 'order' => $value['order'],
  775. ], '
  776. WHERE id=?', $value['id']);
  777. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  778. }
  779. }
  780. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  781. return true;
  782. } catch (Dibi\Exception $e) {
  783. return false;
  784. }
  785. break;
  786. case 'addNewTab':
  787. try {
  788. $default = defaultTabCategory()['category_id'];
  789. $connect = new Dibi\Connection([
  790. 'driver' => 'sqlite3',
  791. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  792. ]);
  793. $newTab = [
  794. 'order' => $array['data']['tabOrder'],
  795. 'category_id' => $default,
  796. 'name' => $array['data']['tabName'],
  797. 'url' => $array['data']['tabURL'],
  798. 'ping_url' => $array['data']['pingURL'],
  799. 'default' => $array['data']['tabDefault'],
  800. 'enabled' => 1,
  801. 'group_id' => $array['data']['tabGroupID'],
  802. 'image' => $array['data']['tabImage'],
  803. 'type' => $array['data']['tabType']
  804. ];
  805. $connect->query('INSERT INTO [tabs]', $newTab);
  806. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  807. return true;
  808. } catch (Dibi\Exception $e) {
  809. return false;
  810. }
  811. break;
  812. default:
  813. return false;
  814. break;
  815. }
  816. }
  817. function editCategories($array)
  818. {
  819. switch ($array['data']['action']) {
  820. case 'changeDefault':
  821. try {
  822. $connect = new Dibi\Connection([
  823. 'driver' => 'sqlite3',
  824. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  825. ]);
  826. $connect->query('UPDATE categories SET `default` = 0');
  827. $connect->query('
  828. UPDATE categories SET', [
  829. 'default' => 1
  830. ], '
  831. WHERE id=?', $array['data']['id']);
  832. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  833. return true;
  834. } catch (Dibi\Exception $e) {
  835. return false;
  836. }
  837. break;
  838. case 'deleteCategory':
  839. try {
  840. $connect = new Dibi\Connection([
  841. 'driver' => 'sqlite3',
  842. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  843. ]);
  844. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  845. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  846. return true;
  847. } catch (Dibi\Exception $e) {
  848. return false;
  849. }
  850. break;
  851. case 'addNewCategory':
  852. try {
  853. $connect = new Dibi\Connection([
  854. 'driver' => 'sqlite3',
  855. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  856. ]);
  857. $newCategory = [
  858. 'category' => $array['data']['categoryName'],
  859. 'order' => $array['data']['categoryOrder'],
  860. 'category_id' => $array['data']['categoryID'],
  861. 'default' => false,
  862. 'image' => $array['data']['categoryImage'],
  863. ];
  864. $connect->query('INSERT INTO [categories]', $newCategory);
  865. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  866. return true;
  867. } catch (Dibi\Exception $e) {
  868. return $e;
  869. }
  870. break;
  871. case 'editCategory':
  872. try {
  873. $connect = new Dibi\Connection([
  874. 'driver' => 'sqlite3',
  875. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  876. ]);
  877. $connect->query('
  878. UPDATE categories SET', [
  879. 'category' => $array['data']['name'],
  880. 'image' => $array['data']['image'],
  881. ], '
  882. WHERE id=?', $array['data']['id']);
  883. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  884. return true;
  885. } catch (Dibi\Exception $e) {
  886. return false;
  887. }
  888. break;
  889. case 'changeOrder':
  890. try {
  891. $connect = new Dibi\Connection([
  892. 'driver' => 'sqlite3',
  893. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  894. ]);
  895. foreach ($array['data']['categories']['category'] as $key => $value) {
  896. if ($value['order'] != $value['originalOrder']) {
  897. $connect->query('
  898. UPDATE categories SET', [
  899. 'order' => $value['order'],
  900. ], '
  901. WHERE id=?', $value['id']);
  902. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  903. }
  904. }
  905. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  906. return true;
  907. } catch (Dibi\Exception $e) {
  908. return false;
  909. }
  910. break;
  911. default:
  912. return false;
  913. break;
  914. }
  915. }
  916. function allUsers()
  917. {
  918. try {
  919. $connect = new Dibi\Connection([
  920. 'driver' => 'sqlite3',
  921. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  922. ]);
  923. $users = $connect->fetchAll('SELECT * FROM users');
  924. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  925. foreach ($users as $k => $v) {
  926. // clear password from array
  927. unset($users[$k]['password']);
  928. }
  929. $all['users'] = $users;
  930. $all['groups'] = $groups;
  931. return $all;
  932. } catch (Dibi\Exception $e) {
  933. return false;
  934. }
  935. }
  936. function usernameTaken($username, $email)
  937. {
  938. try {
  939. $connect = new Dibi\Connection([
  940. 'driver' => 'sqlite3',
  941. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  942. ]);
  943. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  944. return ($all) ? true : false;
  945. } catch (Dibi\Exception $e) {
  946. return false;
  947. }
  948. }
  949. function usernameTakenExcept($username, $email, $id)
  950. {
  951. try {
  952. $connect = new Dibi\Connection([
  953. 'driver' => 'sqlite3',
  954. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  955. ]);
  956. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  957. return ($all) ? true : false;
  958. } catch (Dibi\Exception $e) {
  959. return false;
  960. }
  961. }
  962. function createUser($username, $password, $defaults, $email = null)
  963. {
  964. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  965. try {
  966. if (!usernameTaken($username, $email)) {
  967. $createDB = new Dibi\Connection([
  968. 'driver' => 'sqlite3',
  969. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  970. ]);
  971. $userInfo = [
  972. 'username' => $username,
  973. 'password' => password_hash($password, PASSWORD_BCRYPT),
  974. 'email' => $email,
  975. 'group' => $defaults['group'],
  976. 'group_id' => $defaults['group_id'],
  977. 'image' => gravatar($email),
  978. 'register_date' => $GLOBALS['currentTime'],
  979. ];
  980. $createDB->query('INSERT INTO [users]', $userInfo);
  981. return true;
  982. } else {
  983. return false;
  984. }
  985. } catch (Dibi\Exception $e) {
  986. return false;
  987. }
  988. }
  989. function importUsers($array)
  990. {
  991. $imported = 0;
  992. $defaults = defaultUserGroup();
  993. foreach ($array as $user) {
  994. $password = random_ascii_string(30);
  995. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  996. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  997. if (!$newUser) {
  998. writeLog('error', 'Import Function - Error', $user['username']);
  999. } else {
  1000. $imported++;
  1001. }
  1002. }
  1003. }
  1004. return $imported;
  1005. }
  1006. function importUsersType($array)
  1007. {
  1008. $type = $array['data']['type'];
  1009. if ($type !== '') {
  1010. switch ($type) {
  1011. case 'plex':
  1012. return importUsers(allPlexUsers(true));
  1013. break;
  1014. default:
  1015. return false;
  1016. }
  1017. }
  1018. return false;
  1019. }
  1020. function allTabs()
  1021. {
  1022. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1023. try {
  1024. $connect = new Dibi\Connection([
  1025. 'driver' => 'sqlite3',
  1026. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1027. ]);
  1028. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1029. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1030. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1031. return $all;
  1032. } catch (Dibi\Exception $e) {
  1033. return false;
  1034. }
  1035. }
  1036. return false;
  1037. }
  1038. function allGroups()
  1039. {
  1040. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1041. try {
  1042. $connect = new Dibi\Connection([
  1043. 'driver' => 'sqlite3',
  1044. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1045. ]);
  1046. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1047. return $all;
  1048. } catch (Dibi\Exception $e) {
  1049. return false;
  1050. }
  1051. }
  1052. return false;
  1053. }
  1054. function loadTabs()
  1055. {
  1056. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1057. try {
  1058. $connect = new Dibi\Connection([
  1059. 'driver' => 'sqlite3',
  1060. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1061. ]);
  1062. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1063. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1064. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1065. $all['tabs'] = $tabs;
  1066. foreach ($tabs as $k => $v) {
  1067. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  1068. }
  1069. $count = array_map(function ($element) {
  1070. return $element['category_id'];
  1071. }, $tabs);
  1072. $count = (array_count_values($count));
  1073. foreach ($categories as $k => $v) {
  1074. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1075. }
  1076. $all['categories'] = $categories;
  1077. return $all;
  1078. } catch (Dibi\Exception $e) {
  1079. return false;
  1080. }
  1081. }
  1082. return false;
  1083. }
  1084. function getActiveTokens()
  1085. {
  1086. try {
  1087. $connect = new Dibi\Connection([
  1088. 'driver' => 'sqlite3',
  1089. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1090. ]);
  1091. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1092. return $all;
  1093. } catch (Dibi\Exception $e) {
  1094. return false;
  1095. }
  1096. }
  1097. function revokeToken($array)
  1098. {
  1099. if ($array['data']['token']) {
  1100. try {
  1101. $connect = new Dibi\Connection([
  1102. 'driver' => 'sqlite3',
  1103. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1104. ]);
  1105. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1106. return true;
  1107. } catch (Dibi\Exception $e) {
  1108. return false;
  1109. }
  1110. }
  1111. }