api-functions.php 42 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function apiLogin()
  7. {
  8. $array = array(
  9. 'data' => array(
  10. array(
  11. 'name' => 'username',
  12. 'value' => (isset($_POST['username'])) ? $_POST['username'] : false
  13. ),
  14. array(
  15. 'name' => 'password',
  16. 'value' => (isset($_POST['password'])) ? $_POST['password'] : false
  17. ),
  18. array(
  19. 'name' => 'remember',
  20. 'value' => (isset($_POST['remember'])) ? true : false
  21. ),
  22. array(
  23. 'name' => 'oAuth',
  24. 'value' => (isset($_POST['oAuth'])) ? $_POST['oAuth'] : false
  25. ),
  26. array(
  27. 'name' => 'oAuthType',
  28. 'value' => (isset($_POST['oAuthType'])) ? $_POST['oAuthType'] : false
  29. ),
  30. array(
  31. 'name' => 'tfaCode',
  32. 'value' => (isset($_POST['tfaCode'])) ? $_POST['tfaCode'] : false
  33. ),
  34. array(
  35. 'name' => 'loginAttempts',
  36. 'value' => (isset($_POST['loginAttempts'])) ? $_POST['loginAttempts'] : false
  37. ),
  38. array(
  39. 'name' => 'output',
  40. 'value' => true
  41. ),
  42. )
  43. );
  44. foreach ($array['data'] as $items) {
  45. foreach ($items as $key => $value) {
  46. if ($key == 'name') {
  47. $newKey = $value;
  48. }
  49. if ($key == 'value') {
  50. $newValue = $value;
  51. }
  52. if (isset($newKey) && isset($newValue)) {
  53. $$newKey = $newValue;
  54. }
  55. }
  56. }
  57. return login($array);
  58. }
  59. function login($array)
  60. {
  61. // Grab username and Password from login form
  62. $username = $password = $oAuth = $oAuthType = '';
  63. foreach ($array['data'] as $items) {
  64. foreach ($items as $key => $value) {
  65. if ($key == 'name') {
  66. $newKey = $value;
  67. }
  68. if ($key == 'value') {
  69. $newValue = $value;
  70. }
  71. if (isset($newKey) && isset($newValue)) {
  72. $$newKey = $newValue;
  73. }
  74. }
  75. }
  76. $username = (strpos($GLOBALS['authBackend'], 'emby') !== false) ? $username : strtolower($username);
  77. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  78. $oAuth = (isset($oAuth)) ? $oAuth : false;
  79. $output = (isset($output)) ? $output : false;
  80. $loginAttempts = (isset($loginAttempts)) ? $loginAttempts : false;
  81. if ($loginAttempts > $GLOBALS['loginAttempts'] || isset($_COOKIE['lockout'])) {
  82. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  83. return 'lockout';
  84. }
  85. try {
  86. $database = new Dibi\Connection([
  87. 'driver' => 'sqlite3',
  88. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  89. ]);
  90. $authSuccess = false;
  91. $authProxy = false;
  92. if ($GLOBALS['authProxyEnabled'] && $GLOBALS['authProxyHeaderName'] !== '' && $GLOBALS['authProxyWhitelist'] !== '') {
  93. if (isset(getallheaders()[$GLOBALS['authProxyHeaderName']])) {
  94. $usernameHeader = isset(getallheaders()[$GLOBALS['authProxyHeaderName']]) ? getallheaders()[$GLOBALS['authProxyHeaderName']] : $username;
  95. writeLog('success', 'Auth Proxy Function - Starting Verification for IP: ' . userIP() . ' for request on: ' . $_SERVER['REMOTE_ADDR'] . ' against IP/Subnet: ' . $GLOBALS['authProxyWhitelist'], $usernameHeader);
  96. $whitelistRange = analyzeIP($GLOBALS['authProxyWhitelist']);
  97. $from = $whitelistRange['from'];
  98. $to = $whitelistRange['to'];
  99. $authProxy = authProxyRangeCheck($from, $to);
  100. $username = ($authProxy) ? $usernameHeader : $username;
  101. if ($authProxy) {
  102. writeLog('success', 'Auth Proxy Function - IP: ' . userIP() . ' has been verified', $usernameHeader);
  103. } else {
  104. writeLog('error', 'Auth Proxy Function - IP: ' . userIP() . ' has failed verification', $usernameHeader);
  105. }
  106. }
  107. }
  108. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  109. if (!$oAuth) {
  110. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  111. $result['password'] = $result['password'] ?? '';
  112. switch ($GLOBALS['authType']) {
  113. case 'external':
  114. if (function_exists($function)) {
  115. $authSuccess = $function($username, $password);
  116. }
  117. break;
  118. /** @noinspection PhpMissingBreakStatementInspection */
  119. case 'both':
  120. if (function_exists($function)) {
  121. $authSuccess = $function($username, $password);
  122. }
  123. // no break
  124. default: // Internal
  125. if (!$authSuccess) {
  126. // perform the internal authentication step
  127. if (password_verify($password, $result['password'])) {
  128. $authSuccess = true;
  129. }
  130. }
  131. }
  132. $authSuccess = ($authProxy) ? true : $authSuccess;
  133. } else {
  134. // Has oAuth Token!
  135. switch ($oAuthType) {
  136. case 'plex':
  137. if ($GLOBALS['plexoAuth']) {
  138. $tokenInfo = checkPlexToken($oAuth);
  139. if ($tokenInfo) {
  140. $authSuccess = array(
  141. 'username' => $tokenInfo['user']['username'],
  142. 'email' => $tokenInfo['user']['email'],
  143. 'image' => $tokenInfo['user']['thumb'],
  144. 'token' => $tokenInfo['user']['authToken']
  145. );
  146. coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
  147. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || (!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['email'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  148. }
  149. }
  150. break;
  151. default:
  152. return ($output) ? 'No oAuthType defined' : 'error';
  153. break;
  154. }
  155. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  156. }
  157. if ($authSuccess) {
  158. // Make sure user exists in database
  159. $userExists = false;
  160. $passwordMatches = ($oAuth || $authProxy) ? true : false;
  161. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  162. if ($result['username']) {
  163. $userExists = true;
  164. $username = $result['username'];
  165. if ($passwordMatches == false) {
  166. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  167. }
  168. }
  169. if ($userExists) {
  170. //does org password need to be updated
  171. if (!$passwordMatches) {
  172. $database->query('
  173. UPDATE users SET', [
  174. 'password' => password_hash($password, PASSWORD_BCRYPT)
  175. ], '
  176. WHERE id=?', $result['id']);
  177. writeLog('success', 'Login Function - User Password updated from backend', $username);
  178. }
  179. if ($token !== '') {
  180. if ($token !== $result['plex_token']) {
  181. $database->query('
  182. UPDATE users SET', [
  183. 'plex_token' => $token
  184. ], '
  185. WHERE id=?', $result['id']);
  186. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  187. }
  188. }
  189. // 2FA might go here
  190. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  191. $tfaProceed = true;
  192. // Add check for local or not
  193. if ($GLOBALS['ignoreTFALocal'] !== false) {
  194. $tfaProceed = (isLocal()) ? false : true;
  195. }
  196. if ($tfaProceed) {
  197. $TFA = explode('::', $result['auth_service']);
  198. // Is code with login info?
  199. if ($tfaCode == '') {
  200. return '2FA';
  201. } else {
  202. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  203. writeLoginLog($username, 'error');
  204. writeLog('error', 'Login Function - Wrong 2FA', $username);
  205. return '2FA-incorrect';
  206. }
  207. }
  208. }
  209. }
  210. // End 2FA
  211. // authentication passed - 1) mark active and update token
  212. $createToken = createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days);
  213. if ($createToken) {
  214. writeLoginLog($username, 'success');
  215. writeLog('success', 'Login Function - A User has logged in', $username);
  216. $ssoUser = ((empty($result['email'])) ? $result['username'] : (strpos($result['email'], 'placeholder') !== false)) ? $result['username'] : $result['email'];
  217. ssoCheck($ssoUser, $password, $token); //need to work on this
  218. return ($output) ? array('name' => $GLOBALS['cookieName'], 'token' => (string)$createToken) : true;
  219. } else {
  220. return 'Token Creation Error';
  221. }
  222. } else {
  223. // Create User
  224. //ssoCheck($username, $password, $token);
  225. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  226. }
  227. } else {
  228. // authentication failed
  229. writeLoginLog($username, 'error');
  230. writeLog('error', 'Login Function - Wrong Password', $username);
  231. if ($loginAttempts >= $GLOBALS['loginAttempts']) {
  232. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  233. return 'lockout';
  234. } else {
  235. return 'mismatch';
  236. }
  237. }
  238. } catch (Dibi\Exception $e) {
  239. return $e;
  240. }
  241. }
  242. function createDB($path, $filename)
  243. {
  244. try {
  245. if (!file_exists($path)) {
  246. mkdir($path, 0777, true);
  247. }
  248. $createDB = new Dibi\Connection([
  249. 'driver' => 'sqlite3',
  250. 'database' => $path . $filename,
  251. ]);
  252. // Create Users
  253. $createDB->query('CREATE TABLE `users` (
  254. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  255. `username` TEXT UNIQUE,
  256. `password` TEXT,
  257. `email` TEXT,
  258. `plex_token` TEXT,
  259. `group` TEXT,
  260. `group_id` INTEGER,
  261. `locked` INTEGER,
  262. `image` TEXT,
  263. `register_date` DATE,
  264. `auth_service` TEXT DEFAULT \'internal\'
  265. );');
  266. // Create Tokens
  267. $createDB->query('CREATE TABLE `chatroom` (
  268. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  269. `username` TEXT,
  270. `gravatar` TEXT,
  271. `uid` TEXT,
  272. `date` DATE,
  273. `ip` TEXT,
  274. `message` TEXT
  275. );');
  276. $createDB->query('CREATE TABLE `tokens` (
  277. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  278. `token` TEXT UNIQUE,
  279. `user_id` INTEGER,
  280. `browser` TEXT,
  281. `ip` TEXT,
  282. `created` DATE,
  283. `expires` DATE
  284. );');
  285. $createDB->query('CREATE TABLE `groups` (
  286. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  287. `group` TEXT UNIQUE,
  288. `group_id` INTEGER,
  289. `image` TEXT,
  290. `default` INTEGER
  291. );');
  292. $createDB->query('CREATE TABLE `categories` (
  293. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  294. `order` INTEGER,
  295. `category` TEXT UNIQUE,
  296. `category_id` INTEGER,
  297. `image` TEXT,
  298. `default` INTEGER
  299. );');
  300. // Create Tabs
  301. $createDB->query('CREATE TABLE `tabs` (
  302. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  303. `order` INTEGER,
  304. `category_id` INTEGER,
  305. `name` TEXT,
  306. `url` TEXT,
  307. `url_local` TEXT,
  308. `default` INTEGER,
  309. `enabled` INTEGER,
  310. `group_id` INTEGER,
  311. `image` TEXT,
  312. `type` INTEGER,
  313. `splash` INTEGER,
  314. `ping` INTEGER,
  315. `ping_url` TEXT,
  316. `timeout` INTEGER,
  317. `timeout_ms` INTEGER,
  318. `preload` INTEGER
  319. );');
  320. // Create Options
  321. $createDB->query('CREATE TABLE `options` (
  322. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  323. `name` TEXT UNIQUE,
  324. `value` TEXT
  325. );');
  326. // Create Invites
  327. $createDB->query('CREATE TABLE `invites` (
  328. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  329. `code` TEXT UNIQUE,
  330. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  331. `email` TEXT,
  332. `username` TEXT,
  333. `dateused` TIMESTAMP,
  334. `usedby` TEXT,
  335. `ip` TEXT,
  336. `valid` TEXT,
  337. `type` TEXT
  338. );');
  339. return true;
  340. } catch (Dibi\Exception $e) {
  341. return false;
  342. }
  343. }
  344. // Upgrade Database
  345. function updateDB($oldVerNum = false)
  346. {
  347. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  348. if (!file_exists($tempLock)) {
  349. touch($tempLock);
  350. // Create Temp DB First
  351. $migrationDB = 'tempMigration.db';
  352. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  353. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  354. unlink($GLOBALS['dbLocation'] . $migrationDB);
  355. }
  356. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  357. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  358. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  359. if ($success) {
  360. try {
  361. $connectOldDB = new Dibi\Connection([
  362. 'driver' => 'sqlite3',
  363. 'database' => $backupDB,
  364. ]);
  365. $connectNewDB = new Dibi\Connection([
  366. 'driver' => 'sqlite3',
  367. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  368. ]);
  369. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  370. foreach ($tables as $table) {
  371. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  372. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  373. foreach ($data as $row) {
  374. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  375. }
  376. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  377. }
  378. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  379. $connectOldDB->disconnect();
  380. $connectNewDB->disconnect();
  381. // Remove Current Database
  382. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  383. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  384. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  385. if ($newFileSize > 0) {
  386. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  387. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  388. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  389. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  390. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  391. @unlink($tempLock);
  392. return true;
  393. }
  394. }
  395. @unlink($tempLock);
  396. return false;
  397. } catch (Dibi\Exception $e) {
  398. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  399. @unlink($tempLock);
  400. return false;
  401. }
  402. }
  403. @unlink($tempLock);
  404. return false;
  405. }
  406. return false;
  407. }
  408. function createFirstAdmin($path, $filename, $username, $password, $email)
  409. {
  410. try {
  411. $createDB = new Dibi\Connection([
  412. 'driver' => 'sqlite3',
  413. 'database' => $path . $filename,
  414. ]);
  415. $userInfo = [
  416. 'username' => $username,
  417. 'password' => password_hash($password, PASSWORD_BCRYPT),
  418. 'email' => $email,
  419. 'group' => 'Admin',
  420. 'group_id' => 0,
  421. 'image' => gravatar($email),
  422. 'register_date' => $GLOBALS['currentTime'],
  423. ];
  424. $groupInfo0 = [
  425. 'group' => 'Admin',
  426. 'group_id' => 0,
  427. 'default' => false,
  428. 'image' => 'plugins/images/groups/admin.png',
  429. ];
  430. $groupInfo1 = [
  431. 'group' => 'Co-Admin',
  432. 'group_id' => 1,
  433. 'default' => false,
  434. 'image' => 'plugins/images/groups/coadmin.png',
  435. ];
  436. $groupInfo2 = [
  437. 'group' => 'Super User',
  438. 'group_id' => 2,
  439. 'default' => false,
  440. 'image' => 'plugins/images/groups/superuser.png',
  441. ];
  442. $groupInfo3 = [
  443. 'group' => 'Power User',
  444. 'group_id' => 3,
  445. 'default' => false,
  446. 'image' => 'plugins/images/groups/poweruser.png',
  447. ];
  448. $groupInfo4 = [
  449. 'group' => 'User',
  450. 'group_id' => 4,
  451. 'default' => true,
  452. 'image' => 'plugins/images/groups/user.png',
  453. ];
  454. $groupInfoGuest = [
  455. 'group' => 'Guest',
  456. 'group_id' => 999,
  457. 'default' => false,
  458. 'image' => 'plugins/images/groups/guest.png',
  459. ];
  460. $settingsInfo = [
  461. 'order' => 1,
  462. 'category_id' => 0,
  463. 'name' => 'Settings',
  464. 'url' => 'api/?v1/settings/page',
  465. 'default' => false,
  466. 'enabled' => true,
  467. 'group_id' => 1,
  468. 'image' => 'fontawesome::cog',
  469. 'type' => 0
  470. ];
  471. $homepageInfo = [
  472. 'order' => 2,
  473. 'category_id' => 0,
  474. 'name' => 'Homepage',
  475. 'url' => 'api/?v1/homepage/page',
  476. 'default' => false,
  477. 'enabled' => false,
  478. 'group_id' => 4,
  479. 'image' => 'fontawesome::home',
  480. 'type' => 0
  481. ];
  482. $unsortedInfo = [
  483. 'order' => 1,
  484. 'category' => 'Unsorted',
  485. 'category_id' => 0,
  486. 'image' => 'plugins/images/categories/unsorted.png',
  487. 'default' => true
  488. ];
  489. $createDB->query('INSERT INTO [users]', $userInfo);
  490. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  491. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  492. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  493. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  494. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  495. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  496. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  497. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  498. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  499. return true;
  500. } catch (Dibi\Exception $e) {
  501. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  502. return false;
  503. }
  504. }
  505. function defaultUserGroup()
  506. {
  507. try {
  508. $connect = new Dibi\Connection([
  509. 'driver' => 'sqlite3',
  510. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  511. ]);
  512. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  513. return $all;
  514. } catch (Dibi\Exception $e) {
  515. return false;
  516. }
  517. }
  518. function defaultTabCategory()
  519. {
  520. try {
  521. $connect = new Dibi\Connection([
  522. 'driver' => 'sqlite3',
  523. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  524. ]);
  525. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  526. return $all;
  527. } catch (Dibi\Exception $e) {
  528. return false;
  529. }
  530. }
  531. function getGuest()
  532. {
  533. if (isset($GLOBALS['dbLocation'])) {
  534. try {
  535. $connect = new Dibi\Connection([
  536. 'driver' => 'sqlite3',
  537. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  538. ]);
  539. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  540. return $all;
  541. } catch (Dibi\Exception $e) {
  542. return false;
  543. }
  544. } else {
  545. return array(
  546. 'group' => 'Guest',
  547. 'group_id' => 999,
  548. 'image' => 'plugins/images/groups/guest.png'
  549. );
  550. }
  551. }
  552. function adminEditGroup($array)
  553. {
  554. switch ($array['data']['action']) {
  555. case 'changeDefaultGroup':
  556. try {
  557. $connect = new Dibi\Connection([
  558. 'driver' => 'sqlite3',
  559. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  560. ]);
  561. $connect->query('UPDATE groups SET `default` = 0');
  562. $connect->query('
  563. UPDATE groups SET', [
  564. 'default' => 1
  565. ], '
  566. WHERE id=?', $array['data']['id']);
  567. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  568. return true;
  569. } catch (Dibi\Exception $e) {
  570. return false;
  571. }
  572. break;
  573. case 'deleteUserGroup':
  574. try {
  575. $connect = new Dibi\Connection([
  576. 'driver' => 'sqlite3',
  577. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  578. ]);
  579. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  580. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  581. return true;
  582. } catch (Dibi\Exception $e) {
  583. return false;
  584. }
  585. break;
  586. case 'addUserGroup':
  587. try {
  588. $connect = new Dibi\Connection([
  589. 'driver' => 'sqlite3',
  590. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  591. ]);
  592. $newGroup = [
  593. 'group' => $array['data']['newGroupName'],
  594. 'group_id' => $array['data']['newGroupID'],
  595. 'default' => false,
  596. 'image' => $array['data']['newGroupImage'],
  597. ];
  598. $connect->query('INSERT INTO [groups]', $newGroup);
  599. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  600. return true;
  601. } catch (Dibi\Exception $e) {
  602. return false;
  603. }
  604. break;
  605. case 'editUserGroup':
  606. try {
  607. $connect = new Dibi\Connection([
  608. 'driver' => 'sqlite3',
  609. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  610. ]);
  611. $connect->query('
  612. UPDATE groups SET', [
  613. 'group' => $array['data']['groupName'],
  614. 'image' => $array['data']['groupImage'],
  615. ], '
  616. WHERE id=?', $array['data']['id']);
  617. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  618. return true;
  619. } catch (Dibi\Exception $e) {
  620. return false;
  621. }
  622. break;
  623. default:
  624. return false;
  625. break;
  626. }
  627. }
  628. function adminEditUser($array)
  629. {
  630. switch ($array['data']['action']) {
  631. case 'changeGroup':
  632. if ($array['data']['newGroupID'] == 0) {
  633. return false;
  634. }
  635. try {
  636. $connect = new Dibi\Connection([
  637. 'driver' => 'sqlite3',
  638. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  639. ]);
  640. $connect->query('
  641. UPDATE users SET', [
  642. 'group' => $array['data']['newGroupName'],
  643. 'group_id' => $array['data']['newGroupID'],
  644. ], '
  645. WHERE id=?', $array['data']['id']);
  646. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  647. return true;
  648. } catch (Dibi\Exception $e) {
  649. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  650. return false;
  651. }
  652. break;
  653. case 'editUser':
  654. try {
  655. $connect = new Dibi\Connection([
  656. 'driver' => 'sqlite3',
  657. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  658. ]);
  659. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  660. $connect->query('
  661. UPDATE users SET', [
  662. 'username' => $array['data']['username'],
  663. 'email' => $array['data']['email'],
  664. 'image' => gravatar($array['data']['email']),
  665. ], '
  666. WHERE id=?', $array['data']['id']);
  667. if (!empty($array['data']['password'])) {
  668. $connect->query('
  669. UPDATE users SET', [
  670. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  671. ], '
  672. WHERE id=?', $array['data']['id']);
  673. }
  674. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  675. return true;
  676. } else {
  677. return false;
  678. }
  679. } catch (Dibi\Exception $e) {
  680. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  681. return false;
  682. }
  683. break;
  684. case 'addNewUser':
  685. $defaults = defaultUserGroup();
  686. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  687. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  688. return true;
  689. } else {
  690. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  691. return 'username taken';
  692. }
  693. break;
  694. case 'deleteUser':
  695. try {
  696. $connect = new Dibi\Connection([
  697. 'driver' => 'sqlite3',
  698. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  699. ]);
  700. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  701. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  702. return true;
  703. } catch (Dibi\Exception $e) {
  704. return false;
  705. }
  706. break;
  707. default:
  708. return false;
  709. break;
  710. }
  711. }
  712. function editTabs($array)
  713. {
  714. switch ($array['data']['action']) {
  715. case 'changeGroup':
  716. try {
  717. $connect = new Dibi\Connection([
  718. 'driver' => 'sqlite3',
  719. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  720. ]);
  721. $connect->query('
  722. UPDATE tabs SET', [
  723. 'group_id' => $array['data']['newGroupID'],
  724. ], '
  725. WHERE id=?', $array['data']['id']);
  726. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  727. return true;
  728. } catch (Dibi\Exception $e) {
  729. return false;
  730. }
  731. break;
  732. case 'changeCategory':
  733. try {
  734. $connect = new Dibi\Connection([
  735. 'driver' => 'sqlite3',
  736. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  737. ]);
  738. $connect->query('
  739. UPDATE tabs SET', [
  740. 'category_id' => $array['data']['newCategoryID'],
  741. ], '
  742. WHERE id=?', $array['data']['id']);
  743. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  744. return true;
  745. } catch (Dibi\Exception $e) {
  746. return false;
  747. }
  748. break;
  749. case 'changeType':
  750. try {
  751. $connect = new Dibi\Connection([
  752. 'driver' => 'sqlite3',
  753. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  754. ]);
  755. $connect->query('
  756. UPDATE tabs SET', [
  757. 'type' => $array['data']['newTypeID'],
  758. ], '
  759. WHERE id=?', $array['data']['id']);
  760. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  761. return true;
  762. } catch (Dibi\Exception $e) {
  763. return false;
  764. }
  765. break;
  766. case 'changeEnabled':
  767. try {
  768. $connect = new Dibi\Connection([
  769. 'driver' => 'sqlite3',
  770. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  771. ]);
  772. $connect->query('
  773. UPDATE tabs SET', [
  774. 'enabled' => $array['data']['tabEnabled'],
  775. ], '
  776. WHERE id=?', $array['data']['id']);
  777. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  778. return true;
  779. } catch (Dibi\Exception $e) {
  780. return false;
  781. }
  782. break;
  783. case 'changeSplash':
  784. try {
  785. $connect = new Dibi\Connection([
  786. 'driver' => 'sqlite3',
  787. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  788. ]);
  789. $connect->query('
  790. UPDATE tabs SET', [
  791. 'splash' => $array['data']['tabSplash'],
  792. ], '
  793. WHERE id=?', $array['data']['id']);
  794. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  795. return true;
  796. } catch (Dibi\Exception $e) {
  797. return false;
  798. }
  799. break;
  800. case 'changePing':
  801. try {
  802. $connect = new Dibi\Connection([
  803. 'driver' => 'sqlite3',
  804. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  805. ]);
  806. $connect->query('
  807. UPDATE tabs SET', [
  808. 'ping' => $array['data']['tabPing'],
  809. ], '
  810. WHERE id=?', $array['data']['id']);
  811. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  812. return true;
  813. } catch (Dibi\Exception $e) {
  814. return false;
  815. }
  816. break;
  817. case 'changePreload':
  818. try {
  819. $connect = new Dibi\Connection([
  820. 'driver' => 'sqlite3',
  821. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  822. ]);
  823. $connect->query('
  824. UPDATE tabs SET', [
  825. 'preload' => $array['data']['tabPreload'],
  826. ], '
  827. WHERE id=?', $array['data']['id']);
  828. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s preload status was changed to [' . $array['data']['tabPreloadWord'] . ']', $GLOBALS['organizrUser']['username']);
  829. return true;
  830. } catch (Dibi\Exception $e) {
  831. return false;
  832. }
  833. break;
  834. case 'changeDefault':
  835. try {
  836. $connect = new Dibi\Connection([
  837. 'driver' => 'sqlite3',
  838. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  839. ]);
  840. $connect->query('UPDATE tabs SET `default` = 0');
  841. $connect->query('
  842. UPDATE tabs SET', [
  843. 'default' => 1
  844. ], '
  845. WHERE id=?', $array['data']['id']);
  846. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  847. return true;
  848. } catch (Dibi\Exception $e) {
  849. return false;
  850. }
  851. break;
  852. case 'deleteTab':
  853. try {
  854. $connect = new Dibi\Connection([
  855. 'driver' => 'sqlite3',
  856. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  857. ]);
  858. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  859. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  860. return true;
  861. } catch (Dibi\Exception $e) {
  862. return false;
  863. }
  864. break;
  865. case 'editTab':
  866. try {
  867. $connect = new Dibi\Connection([
  868. 'driver' => 'sqlite3',
  869. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  870. ]);
  871. $connect->query('
  872. UPDATE tabs SET', [
  873. 'name' => $array['data']['tabName'],
  874. 'url' => $array['data']['tabURL'],
  875. 'url_local' => $array['data']['tabLocalURL'],
  876. 'ping_url' => $array['data']['pingURL'],
  877. 'image' => $array['data']['tabImage'],
  878. 'timeout' => $array['data']['tabActionType'],
  879. 'timeout_ms' => $array['data']['tabActionTime'],
  880. ], '
  881. WHERE id=?', $array['data']['id']);
  882. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  883. return true;
  884. } catch (Dibi\Exception $e) {
  885. return false;
  886. }
  887. case 'changeOrder':
  888. try {
  889. $connect = new Dibi\Connection([
  890. 'driver' => 'sqlite3',
  891. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  892. ]);
  893. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  894. if ($value['order'] != $value['originalOrder']) {
  895. $connect->query('
  896. UPDATE tabs SET', [
  897. 'order' => $value['order'],
  898. ], '
  899. WHERE id=?', $value['id']);
  900. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  901. }
  902. }
  903. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  904. return true;
  905. } catch (Dibi\Exception $e) {
  906. return false;
  907. }
  908. break;
  909. case 'addNewTab':
  910. try {
  911. $default = defaultTabCategory()['category_id'];
  912. $connect = new Dibi\Connection([
  913. 'driver' => 'sqlite3',
  914. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  915. ]);
  916. $newTab = [
  917. 'order' => $array['data']['tabOrder'],
  918. 'category_id' => $default,
  919. 'name' => $array['data']['tabName'],
  920. 'url' => $array['data']['tabURL'],
  921. 'url_local' => $array['data']['tabLocalURL'],
  922. 'ping_url' => $array['data']['pingURL'],
  923. 'default' => $array['data']['tabDefault'],
  924. 'enabled' => 1,
  925. 'group_id' => $array['data']['tabGroupID'],
  926. 'image' => $array['data']['tabImage'],
  927. 'type' => $array['data']['tabType'],
  928. 'timeout' => $array['data']['tabActionType'],
  929. 'timeout_ms' => $array['data']['tabActionTime'],
  930. ];
  931. $connect->query('INSERT INTO [tabs]', $newTab);
  932. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  933. return true;
  934. } catch (Dibi\Exception $e) {
  935. return false;
  936. }
  937. break;
  938. default:
  939. return false;
  940. break;
  941. }
  942. }
  943. function editCategories($array)
  944. {
  945. switch ($array['data']['action']) {
  946. case 'changeDefault':
  947. try {
  948. $connect = new Dibi\Connection([
  949. 'driver' => 'sqlite3',
  950. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  951. ]);
  952. $connect->query('UPDATE categories SET `default` = 0');
  953. $connect->query('
  954. UPDATE categories SET', [
  955. 'default' => 1
  956. ], '
  957. WHERE id=?', $array['data']['id']);
  958. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  959. return true;
  960. } catch (Dibi\Exception $e) {
  961. return false;
  962. }
  963. break;
  964. case 'deleteCategory':
  965. try {
  966. $connect = new Dibi\Connection([
  967. 'driver' => 'sqlite3',
  968. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  969. ]);
  970. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  971. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  972. return true;
  973. } catch (Dibi\Exception $e) {
  974. return false;
  975. }
  976. break;
  977. case 'addNewCategory':
  978. try {
  979. $connect = new Dibi\Connection([
  980. 'driver' => 'sqlite3',
  981. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  982. ]);
  983. $newCategory = [
  984. 'category' => $array['data']['categoryName'],
  985. 'order' => $array['data']['categoryOrder'],
  986. 'category_id' => $array['data']['categoryID'],
  987. 'default' => false,
  988. 'image' => $array['data']['categoryImage'],
  989. ];
  990. $connect->query('INSERT INTO [categories]', $newCategory);
  991. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  992. return true;
  993. } catch (Dibi\Exception $e) {
  994. return $e;
  995. }
  996. break;
  997. case 'editCategory':
  998. try {
  999. $connect = new Dibi\Connection([
  1000. 'driver' => 'sqlite3',
  1001. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1002. ]);
  1003. $connect->query('
  1004. UPDATE categories SET', [
  1005. 'category' => $array['data']['name'],
  1006. 'image' => $array['data']['image'],
  1007. ], '
  1008. WHERE id=?', $array['data']['id']);
  1009. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  1010. return true;
  1011. } catch (Dibi\Exception $e) {
  1012. return false;
  1013. }
  1014. break;
  1015. case 'changeOrder':
  1016. try {
  1017. $connect = new Dibi\Connection([
  1018. 'driver' => 'sqlite3',
  1019. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1020. ]);
  1021. foreach ($array['data']['categories']['category'] as $key => $value) {
  1022. if ($value['order'] != $value['originalOrder']) {
  1023. $connect->query('
  1024. UPDATE categories SET', [
  1025. 'order' => $value['order'],
  1026. ], '
  1027. WHERE id=?', $value['id']);
  1028. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  1029. }
  1030. }
  1031. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  1032. return true;
  1033. } catch (Dibi\Exception $e) {
  1034. return false;
  1035. }
  1036. break;
  1037. default:
  1038. return false;
  1039. break;
  1040. }
  1041. }
  1042. function allUsers()
  1043. {
  1044. try {
  1045. $connect = new Dibi\Connection([
  1046. 'driver' => 'sqlite3',
  1047. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1048. ]);
  1049. $users = $connect->fetchAll('SELECT * FROM users');
  1050. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  1051. foreach ($users as $k => $v) {
  1052. // clear password from array
  1053. unset($users[$k]['password']);
  1054. }
  1055. $all['users'] = $users;
  1056. $all['groups'] = $groups;
  1057. return $all;
  1058. } catch (Dibi\Exception $e) {
  1059. return false;
  1060. }
  1061. }
  1062. function usernameTaken($username, $email)
  1063. {
  1064. try {
  1065. $connect = new Dibi\Connection([
  1066. 'driver' => 'sqlite3',
  1067. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1068. ]);
  1069. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  1070. return ($all) ? true : false;
  1071. } catch (Dibi\Exception $e) {
  1072. return false;
  1073. }
  1074. }
  1075. function usernameTakenExcept($username, $email, $id)
  1076. {
  1077. try {
  1078. $connect = new Dibi\Connection([
  1079. 'driver' => 'sqlite3',
  1080. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1081. ]);
  1082. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  1083. return ($all) ? true : false;
  1084. } catch (Dibi\Exception $e) {
  1085. return false;
  1086. }
  1087. }
  1088. function createUser($username, $password, $defaults, $email = null)
  1089. {
  1090. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  1091. try {
  1092. if (!usernameTaken($username, $email)) {
  1093. $createDB = new Dibi\Connection([
  1094. 'driver' => 'sqlite3',
  1095. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1096. ]);
  1097. $userInfo = [
  1098. 'username' => $username,
  1099. 'password' => password_hash($password, PASSWORD_BCRYPT),
  1100. 'email' => $email,
  1101. 'group' => $defaults['group'],
  1102. 'group_id' => $defaults['group_id'],
  1103. 'image' => gravatar($email),
  1104. 'register_date' => $GLOBALS['currentTime'],
  1105. ];
  1106. $createDB->query('INSERT INTO [users]', $userInfo);
  1107. return true;
  1108. } else {
  1109. return false;
  1110. }
  1111. } catch (Dibi\Exception $e) {
  1112. return false;
  1113. }
  1114. }
  1115. function importUsers($array)
  1116. {
  1117. $imported = 0;
  1118. $defaults = defaultUserGroup();
  1119. foreach ($array as $user) {
  1120. $password = random_ascii_string(30);
  1121. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1122. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1123. if (!$newUser) {
  1124. writeLog('error', 'Import Function - Error', $user['username']);
  1125. } else {
  1126. $imported++;
  1127. }
  1128. }
  1129. }
  1130. return $imported;
  1131. }
  1132. function importUsersType($array)
  1133. {
  1134. $type = $array['data']['type'];
  1135. if ($type !== '') {
  1136. switch ($type) {
  1137. case 'plex':
  1138. return importUsers(allPlexUsers(true));
  1139. break;
  1140. default:
  1141. return false;
  1142. }
  1143. }
  1144. return false;
  1145. }
  1146. function allTabs()
  1147. {
  1148. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1149. try {
  1150. $connect = new Dibi\Connection([
  1151. 'driver' => 'sqlite3',
  1152. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1153. ]);
  1154. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1155. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1156. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1157. return $all;
  1158. } catch (Dibi\Exception $e) {
  1159. return false;
  1160. }
  1161. }
  1162. return false;
  1163. }
  1164. function allGroups()
  1165. {
  1166. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1167. try {
  1168. $connect = new Dibi\Connection([
  1169. 'driver' => 'sqlite3',
  1170. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1171. ]);
  1172. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1173. return $all;
  1174. } catch (Dibi\Exception $e) {
  1175. return false;
  1176. }
  1177. }
  1178. return false;
  1179. }
  1180. function loadTabs($type = null)
  1181. {
  1182. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php') && $type) {
  1183. try {
  1184. $connect = new Dibi\Connection([
  1185. 'driver' => 'sqlite3',
  1186. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1187. ]);
  1188. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1189. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1190. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1191. $all['tabs'] = $tabs;
  1192. foreach ($tabs as $k => $v) {
  1193. $v['access_url'] = (!empty($v['url_local']) && ($v['url_local'] !== null) && ($v['url_local'] !== 'null') && isLocal() && $v['type'] !== 0) ? $v['url_local'] : $v['url'];
  1194. }
  1195. $count = array_map(function ($element) {
  1196. return $element['category_id'];
  1197. }, $tabs);
  1198. $count = (array_count_values($count));
  1199. foreach ($categories as $k => $v) {
  1200. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1201. }
  1202. $all['categories'] = $categories;
  1203. switch ($type) {
  1204. case 'categories':
  1205. return $all['categories'];
  1206. case 'tabs':
  1207. return $all['tabs'];
  1208. default:
  1209. return $all;
  1210. }
  1211. } catch (Dibi\Exception $e) {
  1212. return false;
  1213. }
  1214. }
  1215. return false;
  1216. }
  1217. function getActiveTokens()
  1218. {
  1219. try {
  1220. $connect = new Dibi\Connection([
  1221. 'driver' => 'sqlite3',
  1222. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1223. ]);
  1224. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1225. return $all;
  1226. } catch (Dibi\Exception $e) {
  1227. return false;
  1228. }
  1229. }
  1230. function revokeToken($array)
  1231. {
  1232. if ($array['data']['token']) {
  1233. try {
  1234. $connect = new Dibi\Connection([
  1235. 'driver' => 'sqlite3',
  1236. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1237. ]);
  1238. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1239. return true;
  1240. } catch (Dibi\Exception $e) {
  1241. return false;
  1242. }
  1243. }
  1244. }
  1245. function getSchema()
  1246. {
  1247. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1248. try {
  1249. $connect = new Dibi\Connection([
  1250. 'driver' => 'sqlite3',
  1251. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1252. ]);
  1253. $result = $connect->fetchAll(' SELECT name, sql FROM sqlite_master WHERE type=\'table\' ORDER BY name');
  1254. return $result;
  1255. } catch (Dibi\Exception $e) {
  1256. return false;
  1257. }
  1258. } else {
  1259. return 'DB not set yet...';
  1260. }
  1261. }
  1262. function youtubeSearch($query)
  1263. {
  1264. if (!$query) {
  1265. return 'no query provided!';
  1266. }
  1267. $keys = array('AIzaSyBsdt8nLJRMTwOq5PY5A5GLZ2q7scgn01w', 'AIzaSyD-8SHutB60GCcSM8q_Fle38rJUV7ujd8k', 'AIzaSyBzOpVBT6VII-b-8gWD0MOEosGg4hyhCsQ');
  1268. $randomKeyIndex = array_rand($keys);
  1269. $key = $keys[$randomKeyIndex];
  1270. $apikey = ($GLOBALS['youtubeAPI'] !== '') ? $GLOBALS['youtubeAPI'] : $key;
  1271. $results = false;
  1272. $url = "https://www.googleapis.com/youtube/v3/search?part=snippet&q=$query+official+trailer&part=snippet&maxResults=1&type=video&videoDuration=short&key=$apikey";
  1273. $response = Requests::get($url);
  1274. if ($response->success) {
  1275. $results = json_decode($response->body, true);
  1276. }
  1277. return ($results) ? $results : false;
  1278. }