api-functions.php 39 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function apiLogin()
  7. {
  8. $array = array(
  9. 'data' => array(
  10. array(
  11. 'name' => 'username',
  12. 'value' => (isset($_POST['username'])) ? $_POST['username'] : false
  13. ),
  14. array(
  15. 'name' => 'password',
  16. 'value' => (isset($_POST['password'])) ? $_POST['password'] : false
  17. ),
  18. array(
  19. 'name' => 'remember',
  20. 'value' => (isset($_POST['remember'])) ? true : false
  21. ),
  22. array(
  23. 'name' => 'oAuth',
  24. 'value' => (isset($_POST['oAuth'])) ? $_POST['oAuth'] : false
  25. ),
  26. array(
  27. 'name' => 'oAuthType',
  28. 'value' => (isset($_POST['oAuthType'])) ? $_POST['oAuthType'] : false
  29. ),
  30. array(
  31. 'name' => 'tfaCode',
  32. 'value' => (isset($_POST['tfaCode'])) ? $_POST['tfaCode'] : false
  33. ),
  34. array(
  35. 'name' => 'output',
  36. 'value' => true
  37. ),
  38. )
  39. );
  40. foreach ($array['data'] as $items) {
  41. foreach ($items as $key => $value) {
  42. if ($key == 'name') {
  43. $newKey = $value;
  44. }
  45. if ($key == 'value') {
  46. $newValue = $value;
  47. }
  48. if (isset($newKey) && isset($newValue)) {
  49. $$newKey = $newValue;
  50. }
  51. }
  52. }
  53. return login($array);
  54. }
  55. function login($array)
  56. {
  57. // Grab username and Password from login form
  58. $username = $password = $oAuth = $oAuthType = '';
  59. foreach ($array['data'] as $items) {
  60. foreach ($items as $key => $value) {
  61. if ($key == 'name') {
  62. $newKey = $value;
  63. }
  64. if ($key == 'value') {
  65. $newValue = $value;
  66. }
  67. if (isset($newKey) && isset($newValue)) {
  68. $$newKey = $newValue;
  69. }
  70. }
  71. }
  72. $username = (strpos($GLOBALS['authBackend'], 'emby') !== false) ? $username : strtolower($username);
  73. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  74. $oAuth = (isset($oAuth)) ? $oAuth : false;
  75. $output = (isset($output)) ? $output : false;
  76. try {
  77. $database = new Dibi\Connection([
  78. 'driver' => 'sqlite3',
  79. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  80. ]);
  81. $authSuccess = false;
  82. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  83. if (!$oAuth) {
  84. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  85. switch ($GLOBALS['authType']) {
  86. case 'external':
  87. if (function_exists($function)) {
  88. $authSuccess = $function($username, $password);
  89. }
  90. break;
  91. /** @noinspection PhpMissingBreakStatementInspection */
  92. case 'both':
  93. if (function_exists($function)) {
  94. $authSuccess = $function($username, $password);
  95. }
  96. // no break
  97. default: // Internal
  98. if (!$authSuccess) {
  99. // perform the internal authentication step
  100. if (password_verify($password, $result['password'])) {
  101. $authSuccess = true;
  102. }
  103. }
  104. }
  105. } else {
  106. // Has oAuth Token!
  107. switch ($oAuthType) {
  108. case 'plex':
  109. if ($GLOBALS['plexoAuth']) {
  110. $tokenInfo = checkPlexToken($oAuth);
  111. if ($tokenInfo) {
  112. $authSuccess = array(
  113. 'username' => $tokenInfo['user']['username'],
  114. 'email' => $tokenInfo['user']['email'],
  115. 'image' => $tokenInfo['user']['thumb'],
  116. 'token' => $tokenInfo['user']['authToken']
  117. );
  118. coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
  119. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || (!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['email'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  120. }
  121. }
  122. break;
  123. default:
  124. return ($output) ? 'No oAuthType defined' : 'error';
  125. break;
  126. }
  127. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  128. }
  129. if ($authSuccess) {
  130. // Make sure user exists in database
  131. $userExists = false;
  132. $passwordMatches = ($oAuth) ? true : false;
  133. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  134. if ($result['username']) {
  135. $userExists = true;
  136. $username = $result['username'];
  137. if ($passwordMatches == false) {
  138. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  139. }
  140. }
  141. if ($userExists) {
  142. //does org password need to be updated
  143. if (!$passwordMatches) {
  144. $database->query('
  145. UPDATE users SET', [
  146. 'password' => password_hash($password, PASSWORD_BCRYPT)
  147. ], '
  148. WHERE id=?', $result['id']);
  149. writeLog('success', 'Login Function - User Password updated from backend', $username);
  150. }
  151. if ($token !== '') {
  152. if ($token !== $result['plex_token']) {
  153. $database->query('
  154. UPDATE users SET', [
  155. 'plex_token' => $token
  156. ], '
  157. WHERE id=?', $result['id']);
  158. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  159. }
  160. }
  161. // 2FA might go here
  162. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  163. $TFA = explode('::', $result['auth_service']);
  164. // Is code with login info?
  165. if ($tfaCode == '') {
  166. return '2FA';
  167. } else {
  168. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  169. writeLoginLog($username, 'error');
  170. writeLog('error', 'Login Function - Wrong 2FA', $username);
  171. return '2FA-incorrect';
  172. }
  173. }
  174. }
  175. // End 2FA
  176. // authentication passed - 1) mark active and update token
  177. $createToken = createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days);
  178. if ($createToken) {
  179. writeLoginLog($username, 'success');
  180. writeLog('success', 'Login Function - A User has logged in', $username);
  181. $ssoUser = (empty($result['email'])) ? $result['username'] : (strpos($result['email'], 'placeholder') !== false) ? $result['username'] : $result['email'];
  182. ssoCheck($ssoUser, $password, $token); //need to work on this
  183. return ($output) ? array('name' => $GLOBALS['cookieName'], 'token' => (string)$createToken) : true;
  184. } else {
  185. return 'Token Creation Error';
  186. }
  187. } else {
  188. // Create User
  189. //ssoCheck($username, $password, $token);
  190. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  191. }
  192. } else {
  193. // authentication failed
  194. writeLoginLog($username, 'error');
  195. writeLog('error', 'Login Function - Wrong Password', $username);
  196. return 'mismatch';
  197. }
  198. } catch (Dibi\Exception $e) {
  199. return $e;
  200. }
  201. }
  202. function createDB($path, $filename)
  203. {
  204. try {
  205. if (!file_exists($path)) {
  206. mkdir($path, 0777, true);
  207. }
  208. $createDB = new Dibi\Connection([
  209. 'driver' => 'sqlite3',
  210. 'database' => $path . $filename,
  211. ]);
  212. // Create Users
  213. $createDB->query('CREATE TABLE `users` (
  214. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  215. `username` TEXT UNIQUE,
  216. `password` TEXT,
  217. `email` TEXT,
  218. `plex_token` TEXT,
  219. `group` TEXT,
  220. `group_id` INTEGER,
  221. `locked` INTEGER,
  222. `image` TEXT,
  223. `register_date` DATE,
  224. `auth_service` TEXT DEFAULT \'internal\'
  225. );');
  226. // Create Tokens
  227. $createDB->query('CREATE TABLE `chatroom` (
  228. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  229. `username` TEXT,
  230. `gravatar` TEXT,
  231. `uid` TEXT,
  232. `date` DATE,
  233. `ip` TEXT,
  234. `message` TEXT
  235. );');
  236. $createDB->query('CREATE TABLE `tokens` (
  237. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  238. `token` TEXT UNIQUE,
  239. `user_id` INTEGER,
  240. `browser` TEXT,
  241. `ip` TEXT,
  242. `created` DATE,
  243. `expires` DATE
  244. );');
  245. $createDB->query('CREATE TABLE `groups` (
  246. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  247. `group` TEXT UNIQUE,
  248. `group_id` INTEGER,
  249. `image` TEXT,
  250. `default` INTEGER
  251. );');
  252. $createDB->query('CREATE TABLE `categories` (
  253. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  254. `order` INTEGER,
  255. `category` TEXT UNIQUE,
  256. `category_id` INTEGER,
  257. `image` TEXT,
  258. `default` INTEGER
  259. );');
  260. // Create Tabs
  261. $createDB->query('CREATE TABLE `tabs` (
  262. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  263. `order` INTEGER,
  264. `category_id` INTEGER,
  265. `name` TEXT,
  266. `url` TEXT,
  267. `url_local` TEXT,
  268. `default` INTEGER,
  269. `enabled` INTEGER,
  270. `group_id` INTEGER,
  271. `image` TEXT,
  272. `type` INTEGER,
  273. `splash` INTEGER,
  274. `ping` INTEGER,
  275. `ping_url` TEXT,
  276. `timeout` INTEGER,
  277. `timeout_ms` INTEGER,
  278. `preload` INTEGER
  279. );');
  280. // Create Options
  281. $createDB->query('CREATE TABLE `options` (
  282. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  283. `name` TEXT UNIQUE,
  284. `value` TEXT
  285. );');
  286. // Create Invites
  287. $createDB->query('CREATE TABLE `invites` (
  288. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  289. `code` TEXT UNIQUE,
  290. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  291. `email` TEXT,
  292. `username` TEXT,
  293. `dateused` TIMESTAMP,
  294. `usedby` TEXT,
  295. `ip` TEXT,
  296. `valid` TEXT,
  297. `type` TEXT
  298. );');
  299. return true;
  300. } catch (Dibi\Exception $e) {
  301. return false;
  302. }
  303. }
  304. // Upgrade Database
  305. function updateDB($oldVerNum = false)
  306. {
  307. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  308. if (!file_exists($tempLock)) {
  309. touch($tempLock);
  310. // Create Temp DB First
  311. $migrationDB = 'tempMigration.db';
  312. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  313. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  314. unlink($GLOBALS['dbLocation'] . $migrationDB);
  315. }
  316. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  317. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  318. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  319. if ($success) {
  320. try {
  321. $connectOldDB = new Dibi\Connection([
  322. 'driver' => 'sqlite3',
  323. 'database' => $backupDB,
  324. ]);
  325. $connectNewDB = new Dibi\Connection([
  326. 'driver' => 'sqlite3',
  327. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  328. ]);
  329. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  330. foreach ($tables as $table) {
  331. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  332. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  333. foreach ($data as $row) {
  334. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  335. }
  336. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  337. }
  338. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  339. $connectOldDB->disconnect();
  340. $connectNewDB->disconnect();
  341. // Remove Current Database
  342. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  343. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  344. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  345. if ($newFileSize > 0) {
  346. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  347. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  348. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  349. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  350. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  351. @unlink($tempLock);
  352. return true;
  353. }
  354. }
  355. @unlink($tempLock);
  356. return false;
  357. } catch (Dibi\Exception $e) {
  358. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  359. @unlink($tempLock);
  360. return false;
  361. }
  362. }
  363. @unlink($tempLock);
  364. return false;
  365. }
  366. return false;
  367. }
  368. function createFirstAdmin($path, $filename, $username, $password, $email)
  369. {
  370. try {
  371. $createDB = new Dibi\Connection([
  372. 'driver' => 'sqlite3',
  373. 'database' => $path . $filename,
  374. ]);
  375. $userInfo = [
  376. 'username' => $username,
  377. 'password' => password_hash($password, PASSWORD_BCRYPT),
  378. 'email' => $email,
  379. 'group' => 'Admin',
  380. 'group_id' => 0,
  381. 'image' => gravatar($email),
  382. 'register_date' => $GLOBALS['currentTime'],
  383. ];
  384. $groupInfo0 = [
  385. 'group' => 'Admin',
  386. 'group_id' => 0,
  387. 'default' => false,
  388. 'image' => 'plugins/images/groups/admin.png',
  389. ];
  390. $groupInfo1 = [
  391. 'group' => 'Co-Admin',
  392. 'group_id' => 1,
  393. 'default' => false,
  394. 'image' => 'plugins/images/groups/coadmin.png',
  395. ];
  396. $groupInfo2 = [
  397. 'group' => 'Super User',
  398. 'group_id' => 2,
  399. 'default' => false,
  400. 'image' => 'plugins/images/groups/superuser.png',
  401. ];
  402. $groupInfo3 = [
  403. 'group' => 'Power User',
  404. 'group_id' => 3,
  405. 'default' => false,
  406. 'image' => 'plugins/images/groups/poweruser.png',
  407. ];
  408. $groupInfo4 = [
  409. 'group' => 'User',
  410. 'group_id' => 4,
  411. 'default' => true,
  412. 'image' => 'plugins/images/groups/user.png',
  413. ];
  414. $groupInfoGuest = [
  415. 'group' => 'Guest',
  416. 'group_id' => 999,
  417. 'default' => false,
  418. 'image' => 'plugins/images/groups/guest.png',
  419. ];
  420. $settingsInfo = [
  421. 'order' => 1,
  422. 'category_id' => 0,
  423. 'name' => 'Settings',
  424. 'url' => 'api/?v1/settings/page',
  425. 'default' => false,
  426. 'enabled' => true,
  427. 'group_id' => 1,
  428. 'image' => 'fontawesome::cog',
  429. 'type' => 0
  430. ];
  431. $homepageInfo = [
  432. 'order' => 2,
  433. 'category_id' => 0,
  434. 'name' => 'Homepage',
  435. 'url' => 'api/?v1/homepage/page',
  436. 'default' => false,
  437. 'enabled' => false,
  438. 'group_id' => 4,
  439. 'image' => 'fontawesome::home',
  440. 'type' => 0
  441. ];
  442. $unsortedInfo = [
  443. 'order' => 1,
  444. 'category' => 'Unsorted',
  445. 'category_id' => 0,
  446. 'image' => 'plugins/images/categories/unsorted.png',
  447. 'default' => true
  448. ];
  449. $createDB->query('INSERT INTO [users]', $userInfo);
  450. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  451. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  452. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  453. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  454. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  455. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  456. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  457. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  458. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  459. return true;
  460. } catch (Dibi\Exception $e) {
  461. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  462. return false;
  463. }
  464. }
  465. function defaultUserGroup()
  466. {
  467. try {
  468. $connect = new Dibi\Connection([
  469. 'driver' => 'sqlite3',
  470. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  471. ]);
  472. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  473. return $all;
  474. } catch (Dibi\Exception $e) {
  475. return false;
  476. }
  477. }
  478. function defaultTabCategory()
  479. {
  480. try {
  481. $connect = new Dibi\Connection([
  482. 'driver' => 'sqlite3',
  483. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  484. ]);
  485. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  486. return $all;
  487. } catch (Dibi\Exception $e) {
  488. return false;
  489. }
  490. }
  491. function getGuest()
  492. {
  493. if (isset($GLOBALS['dbLocation'])) {
  494. try {
  495. $connect = new Dibi\Connection([
  496. 'driver' => 'sqlite3',
  497. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  498. ]);
  499. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  500. return $all;
  501. } catch (Dibi\Exception $e) {
  502. return false;
  503. }
  504. } else {
  505. return array(
  506. 'group' => 'Guest',
  507. 'group_id' => 999,
  508. 'image' => 'plugins/images/groups/guest.png'
  509. );
  510. }
  511. }
  512. function adminEditGroup($array)
  513. {
  514. switch ($array['data']['action']) {
  515. case 'changeDefaultGroup':
  516. try {
  517. $connect = new Dibi\Connection([
  518. 'driver' => 'sqlite3',
  519. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  520. ]);
  521. $connect->query('UPDATE groups SET `default` = 0');
  522. $connect->query('
  523. UPDATE groups SET', [
  524. 'default' => 1
  525. ], '
  526. WHERE id=?', $array['data']['id']);
  527. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  528. return true;
  529. } catch (Dibi\Exception $e) {
  530. return false;
  531. }
  532. break;
  533. case 'deleteUserGroup':
  534. try {
  535. $connect = new Dibi\Connection([
  536. 'driver' => 'sqlite3',
  537. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  538. ]);
  539. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  540. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  541. return true;
  542. } catch (Dibi\Exception $e) {
  543. return false;
  544. }
  545. break;
  546. case 'addUserGroup':
  547. try {
  548. $connect = new Dibi\Connection([
  549. 'driver' => 'sqlite3',
  550. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  551. ]);
  552. $newGroup = [
  553. 'group' => $array['data']['newGroupName'],
  554. 'group_id' => $array['data']['newGroupID'],
  555. 'default' => false,
  556. 'image' => $array['data']['newGroupImage'],
  557. ];
  558. $connect->query('INSERT INTO [groups]', $newGroup);
  559. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  560. return true;
  561. } catch (Dibi\Exception $e) {
  562. return false;
  563. }
  564. break;
  565. case 'editUserGroup':
  566. try {
  567. $connect = new Dibi\Connection([
  568. 'driver' => 'sqlite3',
  569. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  570. ]);
  571. $connect->query('
  572. UPDATE groups SET', [
  573. 'group' => $array['data']['groupName'],
  574. 'image' => $array['data']['groupImage'],
  575. ], '
  576. WHERE id=?', $array['data']['id']);
  577. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  578. return true;
  579. } catch (Dibi\Exception $e) {
  580. return false;
  581. }
  582. break;
  583. default:
  584. return false;
  585. break;
  586. }
  587. }
  588. function adminEditUser($array)
  589. {
  590. switch ($array['data']['action']) {
  591. case 'changeGroup':
  592. if ($array['data']['newGroupID'] == 0) {
  593. return false;
  594. }
  595. try {
  596. $connect = new Dibi\Connection([
  597. 'driver' => 'sqlite3',
  598. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  599. ]);
  600. $connect->query('
  601. UPDATE users SET', [
  602. 'group' => $array['data']['newGroupName'],
  603. 'group_id' => $array['data']['newGroupID'],
  604. ], '
  605. WHERE id=?', $array['data']['id']);
  606. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  607. return true;
  608. } catch (Dibi\Exception $e) {
  609. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  610. return false;
  611. }
  612. break;
  613. case 'editUser':
  614. try {
  615. $connect = new Dibi\Connection([
  616. 'driver' => 'sqlite3',
  617. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  618. ]);
  619. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  620. $connect->query('
  621. UPDATE users SET', [
  622. 'username' => $array['data']['username'],
  623. 'email' => $array['data']['email'],
  624. 'image' => gravatar($array['data']['email']),
  625. ], '
  626. WHERE id=?', $array['data']['id']);
  627. if (!empty($array['data']['password'])) {
  628. $connect->query('
  629. UPDATE users SET', [
  630. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  631. ], '
  632. WHERE id=?', $array['data']['id']);
  633. }
  634. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  635. return true;
  636. } else {
  637. return false;
  638. }
  639. } catch (Dibi\Exception $e) {
  640. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  641. return false;
  642. }
  643. break;
  644. case 'addNewUser':
  645. $defaults = defaultUserGroup();
  646. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  647. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  648. return true;
  649. } else {
  650. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  651. return 'username taken';
  652. }
  653. break;
  654. case 'deleteUser':
  655. try {
  656. $connect = new Dibi\Connection([
  657. 'driver' => 'sqlite3',
  658. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  659. ]);
  660. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  661. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  662. return true;
  663. } catch (Dibi\Exception $e) {
  664. return false;
  665. }
  666. break;
  667. default:
  668. return false;
  669. break;
  670. }
  671. }
  672. function editTabs($array)
  673. {
  674. switch ($array['data']['action']) {
  675. case 'changeGroup':
  676. try {
  677. $connect = new Dibi\Connection([
  678. 'driver' => 'sqlite3',
  679. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  680. ]);
  681. $connect->query('
  682. UPDATE tabs SET', [
  683. 'group_id' => $array['data']['newGroupID'],
  684. ], '
  685. WHERE id=?', $array['data']['id']);
  686. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  687. return true;
  688. } catch (Dibi\Exception $e) {
  689. return false;
  690. }
  691. break;
  692. case 'changeCategory':
  693. try {
  694. $connect = new Dibi\Connection([
  695. 'driver' => 'sqlite3',
  696. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  697. ]);
  698. $connect->query('
  699. UPDATE tabs SET', [
  700. 'category_id' => $array['data']['newCategoryID'],
  701. ], '
  702. WHERE id=?', $array['data']['id']);
  703. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  704. return true;
  705. } catch (Dibi\Exception $e) {
  706. return false;
  707. }
  708. break;
  709. case 'changeType':
  710. try {
  711. $connect = new Dibi\Connection([
  712. 'driver' => 'sqlite3',
  713. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  714. ]);
  715. $connect->query('
  716. UPDATE tabs SET', [
  717. 'type' => $array['data']['newTypeID'],
  718. ], '
  719. WHERE id=?', $array['data']['id']);
  720. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  721. return true;
  722. } catch (Dibi\Exception $e) {
  723. return false;
  724. }
  725. break;
  726. case 'changeEnabled':
  727. try {
  728. $connect = new Dibi\Connection([
  729. 'driver' => 'sqlite3',
  730. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  731. ]);
  732. $connect->query('
  733. UPDATE tabs SET', [
  734. 'enabled' => $array['data']['tabEnabled'],
  735. ], '
  736. WHERE id=?', $array['data']['id']);
  737. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  738. return true;
  739. } catch (Dibi\Exception $e) {
  740. return false;
  741. }
  742. break;
  743. case 'changeSplash':
  744. try {
  745. $connect = new Dibi\Connection([
  746. 'driver' => 'sqlite3',
  747. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  748. ]);
  749. $connect->query('
  750. UPDATE tabs SET', [
  751. 'splash' => $array['data']['tabSplash'],
  752. ], '
  753. WHERE id=?', $array['data']['id']);
  754. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  755. return true;
  756. } catch (Dibi\Exception $e) {
  757. return false;
  758. }
  759. break;
  760. case 'changePing':
  761. try {
  762. $connect = new Dibi\Connection([
  763. 'driver' => 'sqlite3',
  764. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  765. ]);
  766. $connect->query('
  767. UPDATE tabs SET', [
  768. 'ping' => $array['data']['tabPing'],
  769. ], '
  770. WHERE id=?', $array['data']['id']);
  771. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  772. return true;
  773. } catch (Dibi\Exception $e) {
  774. return false;
  775. }
  776. break;
  777. case 'changePreload':
  778. try {
  779. $connect = new Dibi\Connection([
  780. 'driver' => 'sqlite3',
  781. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  782. ]);
  783. $connect->query('
  784. UPDATE tabs SET', [
  785. 'preload' => $array['data']['tabPreload'],
  786. ], '
  787. WHERE id=?', $array['data']['id']);
  788. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s preload status was changed to [' . $array['data']['tabPreloadWord'] . ']', $GLOBALS['organizrUser']['username']);
  789. return true;
  790. } catch (Dibi\Exception $e) {
  791. return false;
  792. }
  793. break;
  794. case 'changeDefault':
  795. try {
  796. $connect = new Dibi\Connection([
  797. 'driver' => 'sqlite3',
  798. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  799. ]);
  800. $connect->query('UPDATE tabs SET `default` = 0');
  801. $connect->query('
  802. UPDATE tabs SET', [
  803. 'default' => 1
  804. ], '
  805. WHERE id=?', $array['data']['id']);
  806. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  807. return true;
  808. } catch (Dibi\Exception $e) {
  809. return false;
  810. }
  811. break;
  812. case 'deleteTab':
  813. try {
  814. $connect = new Dibi\Connection([
  815. 'driver' => 'sqlite3',
  816. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  817. ]);
  818. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  819. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  820. return true;
  821. } catch (Dibi\Exception $e) {
  822. return false;
  823. }
  824. break;
  825. case 'editTab':
  826. try {
  827. $connect = new Dibi\Connection([
  828. 'driver' => 'sqlite3',
  829. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  830. ]);
  831. $connect->query('
  832. UPDATE tabs SET', [
  833. 'name' => $array['data']['tabName'],
  834. 'url' => $array['data']['tabURL'],
  835. 'url_local' => $array['data']['tabLocalURL'],
  836. 'ping_url' => $array['data']['pingURL'],
  837. 'image' => $array['data']['tabImage'],
  838. 'timeout' => $array['data']['tabActionType'],
  839. 'timeout_ms' => $array['data']['tabActionTime'],
  840. ], '
  841. WHERE id=?', $array['data']['id']);
  842. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  843. return true;
  844. } catch (Dibi\Exception $e) {
  845. return false;
  846. }
  847. case 'changeOrder':
  848. try {
  849. $connect = new Dibi\Connection([
  850. 'driver' => 'sqlite3',
  851. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  852. ]);
  853. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  854. if ($value['order'] != $value['originalOrder']) {
  855. $connect->query('
  856. UPDATE tabs SET', [
  857. 'order' => $value['order'],
  858. ], '
  859. WHERE id=?', $value['id']);
  860. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  861. }
  862. }
  863. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  864. return true;
  865. } catch (Dibi\Exception $e) {
  866. return false;
  867. }
  868. break;
  869. case 'addNewTab':
  870. try {
  871. $default = defaultTabCategory()['category_id'];
  872. $connect = new Dibi\Connection([
  873. 'driver' => 'sqlite3',
  874. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  875. ]);
  876. $newTab = [
  877. 'order' => $array['data']['tabOrder'],
  878. 'category_id' => $default,
  879. 'name' => $array['data']['tabName'],
  880. 'url' => $array['data']['tabURL'],
  881. 'url_local' => $array['data']['tabLocalURL'],
  882. 'ping_url' => $array['data']['pingURL'],
  883. 'default' => $array['data']['tabDefault'],
  884. 'enabled' => 1,
  885. 'group_id' => $array['data']['tabGroupID'],
  886. 'image' => $array['data']['tabImage'],
  887. 'type' => $array['data']['tabType'],
  888. 'timeout' => $array['data']['tabActionType'],
  889. 'timeout_ms' => $array['data']['tabActionTime'],
  890. ];
  891. $connect->query('INSERT INTO [tabs]', $newTab);
  892. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  893. return true;
  894. } catch (Dibi\Exception $e) {
  895. return false;
  896. }
  897. break;
  898. default:
  899. return false;
  900. break;
  901. }
  902. }
  903. function editCategories($array)
  904. {
  905. switch ($array['data']['action']) {
  906. case 'changeDefault':
  907. try {
  908. $connect = new Dibi\Connection([
  909. 'driver' => 'sqlite3',
  910. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  911. ]);
  912. $connect->query('UPDATE categories SET `default` = 0');
  913. $connect->query('
  914. UPDATE categories SET', [
  915. 'default' => 1
  916. ], '
  917. WHERE id=?', $array['data']['id']);
  918. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  919. return true;
  920. } catch (Dibi\Exception $e) {
  921. return false;
  922. }
  923. break;
  924. case 'deleteCategory':
  925. try {
  926. $connect = new Dibi\Connection([
  927. 'driver' => 'sqlite3',
  928. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  929. ]);
  930. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  931. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  932. return true;
  933. } catch (Dibi\Exception $e) {
  934. return false;
  935. }
  936. break;
  937. case 'addNewCategory':
  938. try {
  939. $connect = new Dibi\Connection([
  940. 'driver' => 'sqlite3',
  941. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  942. ]);
  943. $newCategory = [
  944. 'category' => $array['data']['categoryName'],
  945. 'order' => $array['data']['categoryOrder'],
  946. 'category_id' => $array['data']['categoryID'],
  947. 'default' => false,
  948. 'image' => $array['data']['categoryImage'],
  949. ];
  950. $connect->query('INSERT INTO [categories]', $newCategory);
  951. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  952. return true;
  953. } catch (Dibi\Exception $e) {
  954. return $e;
  955. }
  956. break;
  957. case 'editCategory':
  958. try {
  959. $connect = new Dibi\Connection([
  960. 'driver' => 'sqlite3',
  961. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  962. ]);
  963. $connect->query('
  964. UPDATE categories SET', [
  965. 'category' => $array['data']['name'],
  966. 'image' => $array['data']['image'],
  967. ], '
  968. WHERE id=?', $array['data']['id']);
  969. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  970. return true;
  971. } catch (Dibi\Exception $e) {
  972. return false;
  973. }
  974. break;
  975. case 'changeOrder':
  976. try {
  977. $connect = new Dibi\Connection([
  978. 'driver' => 'sqlite3',
  979. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  980. ]);
  981. foreach ($array['data']['categories']['category'] as $key => $value) {
  982. if ($value['order'] != $value['originalOrder']) {
  983. $connect->query('
  984. UPDATE categories SET', [
  985. 'order' => $value['order'],
  986. ], '
  987. WHERE id=?', $value['id']);
  988. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  989. }
  990. }
  991. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  992. return true;
  993. } catch (Dibi\Exception $e) {
  994. return false;
  995. }
  996. break;
  997. default:
  998. return false;
  999. break;
  1000. }
  1001. }
  1002. function allUsers()
  1003. {
  1004. try {
  1005. $connect = new Dibi\Connection([
  1006. 'driver' => 'sqlite3',
  1007. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1008. ]);
  1009. $users = $connect->fetchAll('SELECT * FROM users');
  1010. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  1011. foreach ($users as $k => $v) {
  1012. // clear password from array
  1013. unset($users[$k]['password']);
  1014. }
  1015. $all['users'] = $users;
  1016. $all['groups'] = $groups;
  1017. return $all;
  1018. } catch (Dibi\Exception $e) {
  1019. return false;
  1020. }
  1021. }
  1022. function usernameTaken($username, $email)
  1023. {
  1024. try {
  1025. $connect = new Dibi\Connection([
  1026. 'driver' => 'sqlite3',
  1027. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1028. ]);
  1029. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  1030. return ($all) ? true : false;
  1031. } catch (Dibi\Exception $e) {
  1032. return false;
  1033. }
  1034. }
  1035. function usernameTakenExcept($username, $email, $id)
  1036. {
  1037. try {
  1038. $connect = new Dibi\Connection([
  1039. 'driver' => 'sqlite3',
  1040. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1041. ]);
  1042. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  1043. return ($all) ? true : false;
  1044. } catch (Dibi\Exception $e) {
  1045. return false;
  1046. }
  1047. }
  1048. function createUser($username, $password, $defaults, $email = null)
  1049. {
  1050. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  1051. try {
  1052. if (!usernameTaken($username, $email)) {
  1053. $createDB = new Dibi\Connection([
  1054. 'driver' => 'sqlite3',
  1055. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1056. ]);
  1057. $userInfo = [
  1058. 'username' => $username,
  1059. 'password' => password_hash($password, PASSWORD_BCRYPT),
  1060. 'email' => $email,
  1061. 'group' => $defaults['group'],
  1062. 'group_id' => $defaults['group_id'],
  1063. 'image' => gravatar($email),
  1064. 'register_date' => $GLOBALS['currentTime'],
  1065. ];
  1066. $createDB->query('INSERT INTO [users]', $userInfo);
  1067. return true;
  1068. } else {
  1069. return false;
  1070. }
  1071. } catch (Dibi\Exception $e) {
  1072. return false;
  1073. }
  1074. }
  1075. function importUsers($array)
  1076. {
  1077. $imported = 0;
  1078. $defaults = defaultUserGroup();
  1079. foreach ($array as $user) {
  1080. $password = random_ascii_string(30);
  1081. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1082. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1083. if (!$newUser) {
  1084. writeLog('error', 'Import Function - Error', $user['username']);
  1085. } else {
  1086. $imported++;
  1087. }
  1088. }
  1089. }
  1090. return $imported;
  1091. }
  1092. function importUsersType($array)
  1093. {
  1094. $type = $array['data']['type'];
  1095. if ($type !== '') {
  1096. switch ($type) {
  1097. case 'plex':
  1098. return importUsers(allPlexUsers(true));
  1099. break;
  1100. default:
  1101. return false;
  1102. }
  1103. }
  1104. return false;
  1105. }
  1106. function allTabs()
  1107. {
  1108. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1109. try {
  1110. $connect = new Dibi\Connection([
  1111. 'driver' => 'sqlite3',
  1112. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1113. ]);
  1114. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1115. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1116. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1117. return $all;
  1118. } catch (Dibi\Exception $e) {
  1119. return false;
  1120. }
  1121. }
  1122. return false;
  1123. }
  1124. function allGroups()
  1125. {
  1126. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1127. try {
  1128. $connect = new Dibi\Connection([
  1129. 'driver' => 'sqlite3',
  1130. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1131. ]);
  1132. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1133. return $all;
  1134. } catch (Dibi\Exception $e) {
  1135. return false;
  1136. }
  1137. }
  1138. return false;
  1139. }
  1140. function loadTabs()
  1141. {
  1142. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1143. try {
  1144. $connect = new Dibi\Connection([
  1145. 'driver' => 'sqlite3',
  1146. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1147. ]);
  1148. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1149. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1150. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1151. $all['tabs'] = $tabs;
  1152. foreach ($tabs as $k => $v) {
  1153. $v['access_url'] = (!empty($v['url_local']) && ($v['url_local'] !== null) && ($v['url_local'] !== 'null') && isLocal() && $v['type'] !== 0) ? $v['url_local'] : $v['url'];
  1154. }
  1155. $count = array_map(function ($element) {
  1156. return $element['category_id'];
  1157. }, $tabs);
  1158. $count = (array_count_values($count));
  1159. foreach ($categories as $k => $v) {
  1160. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1161. }
  1162. $all['categories'] = $categories;
  1163. return $all;
  1164. } catch (Dibi\Exception $e) {
  1165. return false;
  1166. }
  1167. }
  1168. return false;
  1169. }
  1170. function getActiveTokens()
  1171. {
  1172. try {
  1173. $connect = new Dibi\Connection([
  1174. 'driver' => 'sqlite3',
  1175. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1176. ]);
  1177. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1178. return $all;
  1179. } catch (Dibi\Exception $e) {
  1180. return false;
  1181. }
  1182. }
  1183. function revokeToken($array)
  1184. {
  1185. if ($array['data']['token']) {
  1186. try {
  1187. $connect = new Dibi\Connection([
  1188. 'driver' => 'sqlite3',
  1189. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1190. ]);
  1191. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1192. return true;
  1193. } catch (Dibi\Exception $e) {
  1194. return false;
  1195. }
  1196. }
  1197. }
  1198. function getSchema()
  1199. {
  1200. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1201. try {
  1202. $connect = new Dibi\Connection([
  1203. 'driver' => 'sqlite3',
  1204. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1205. ]);
  1206. $result = $connect->fetchAll(' SELECT name, sql FROM sqlite_master WHERE type=\'table\' ORDER BY name');
  1207. return $result;
  1208. } catch (Dibi\Exception $e) {
  1209. return false;
  1210. }
  1211. } else {
  1212. return 'DB not set yet...';
  1213. }
  1214. }