api-functions.php 34 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860
  1. <?php
  2. function login($array){
  3. // Grab username and Password from login form
  4. foreach ($array['data'] as $items) {
  5. foreach ($items as $key => $value) {
  6. if($key == 'name'){
  7. $newKey = $value;
  8. }
  9. if($key == 'value'){
  10. $newValue = $value;
  11. }
  12. if(isset($newKey) && isset($newValue)){
  13. $$newKey = $newValue;
  14. }
  15. }
  16. }
  17. $username = strtolower($username);
  18. $days = (isset($remember)) ? 7 : 1;
  19. try {
  20. $database = new Dibi\Connection([
  21. 'driver' => 'sqlite3',
  22. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  23. ]);
  24. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$username);
  25. if(password_verify($password, $result['password'])){
  26. if(createToken($result['username'],$result['email'],$result['image'],$result['group'],$result['group_id'],$GLOBALS['organizrHash'],$days)){
  27. writeLoginLog($username, 'success');
  28. writeLog('success', 'Login Function - A User has logged in', $username);
  29. ssoCheck($username, $password);
  30. return true;
  31. }
  32. }else{
  33. writeLoginLog($username, 'error');
  34. writeLog('error', 'Login Function - Wrong Password', $username);
  35. return 'mismatch';
  36. }
  37. } catch (Dibi\Exception $e) {
  38. return 'error';
  39. }
  40. }
  41. function createDB($path,$filename) {
  42. if(file_exists($path.$filename)){
  43. unlink($path.$filename);
  44. }
  45. try {
  46. $createDB = new Dibi\Connection([
  47. 'driver' => 'sqlite3',
  48. 'database' => $path.$filename,
  49. ]);
  50. // Create Users
  51. $users = $createDB->query('CREATE TABLE `users` (
  52. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  53. `username` TEXT UNIQUE,
  54. `password` TEXT,
  55. `email` TEXT,
  56. `plex_token` TEXT,
  57. `group` TEXT,
  58. `group_id` INTEGER,
  59. `locked` INTEGER,
  60. `image` TEXT,
  61. `register_date` DATE,
  62. `auth_service` TEXT DEFAULT \'internal\'
  63. );');
  64. // Create Tokens
  65. $jwt = $createDB->query('CREATE TABLE `tokens` (
  66. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  67. `token` TEXT UNIQUE,
  68. `user_id` INTEGER,
  69. `created` DATE,
  70. `expires` DATE
  71. );');
  72. $groups = $createDB->query('CREATE TABLE `groups` (
  73. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  74. `group` TEXT UNIQUE,
  75. `group_id` INTEGER,
  76. `image` TEXT,
  77. `default` INTEGER
  78. );');
  79. $categories = $createDB->query('CREATE TABLE `categories` (
  80. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  81. `order` INTEGER,
  82. `category` TEXT UNIQUE,
  83. `category_id` INTEGER,
  84. `image` TEXT,
  85. `default` INTEGER
  86. );');
  87. // Create Tabs
  88. $tabs = $createDB->query('CREATE TABLE `tabs` (
  89. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  90. `order` INTEGER,
  91. `category_id` INTEGER,
  92. `name` TEXT,
  93. `url` TEXT,
  94. `url_local` TEXT,
  95. `default` INTEGER,
  96. `enabled` INTEGER,
  97. `group_id` INTEGER,
  98. `image` TEXT,
  99. `type` INTEGER,
  100. `splash` INTEGER,
  101. `ping` INTEGER,
  102. `ping_url` TEXT
  103. );');
  104. // Create Options
  105. $options = $createDB->query('CREATE TABLE `options` (
  106. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  107. `users_id` INTEGER UNIQUE,
  108. `title` TEXT UNIQUE,
  109. `topbar` TEXT,
  110. `bottombar` TEXT,
  111. `sidebar` TEXT,
  112. `hoverbg` TEXT,
  113. `topbartext` TEXT,
  114. `activetabBG` TEXT,
  115. `activetabicon` TEXT,
  116. `activetabtext` TEXT,
  117. `inactiveicon` TEXT,
  118. `inactivetext` TEXT,
  119. `loading` TEXT,
  120. `hovertext` TEXT
  121. );');
  122. // Create Invites
  123. $invites = $createDB->query('CREATE TABLE `invites` (
  124. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  125. `code` TEXT UNIQUE,
  126. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  127. `email` TEXT,
  128. `username` TEXT,
  129. `dateused` TIMESTAMP,
  130. `usedby` TEXT,
  131. `ip` TEXT,
  132. `valid` TEXT,
  133. `type` TEXT
  134. );');
  135. return true;
  136. } catch (Dibi\Exception $e) {
  137. return false;
  138. }
  139. }
  140. // Upgrade Database
  141. function updateDB($path,$filename,$oldVerNum = false) {
  142. try {
  143. $connect = new Dibi\Connection([
  144. 'driver' => 'sqlite3',
  145. 'database' => $path.$filename,
  146. ]);
  147. // Cache current DB
  148. $cache = array();
  149. foreach($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  150. foreach($connect->query('SELECT * FROM '.$table['name'].';') as $key => $row) {
  151. foreach($row as $k => $v) {
  152. if (is_string($k)) {
  153. $cache[$table['name']][$key][$k] = $v;
  154. }
  155. }
  156. }
  157. }
  158. $connect->disconnect();
  159. } catch (Dibi\Exception $e) {
  160. return $e;
  161. }
  162. // Remove Current Database
  163. $pathDigest = pathinfo($path.$filename);
  164. if (file_exists($path.$filename)) {
  165. copy($path.$filename, $pathDigest['dirname'].'/'.$pathDigest['filename'].'['.date('Y-m-d_H-i-s').']'.($oldVerNum?'['.$oldVerNum.']':'').'.bak.db');
  166. unlink($path.$filename);
  167. }
  168. // Create New Database
  169. $success = createDB($path,$filename);
  170. try {
  171. $GLOBALS['connect'] = new Dibi\Connection([
  172. 'driver' => 'sqlite3',
  173. 'database' => $path.$filename,
  174. ]);
  175. // Restore Items
  176. if ($success) {
  177. foreach($cache as $table => $tableData) {
  178. if ($tableData) {
  179. $queryBase = 'INSERT INTO '.$table.' (`'.implode('`,`',array_keys(current($tableData))).'`) values ';
  180. $insertValues = array();
  181. reset($tableData);
  182. foreach($tableData as $key => $value) {
  183. $insertValues[] = '('.implode(',',array_map(function($d) {
  184. return (isset($d)?str_replace('\/', '/',json_encode($d)):'null');
  185. }, $value)).')';
  186. }
  187. $GLOBALS['connect']->query($queryBase.implode(',',$insertValues).';');
  188. }
  189. }
  190. }
  191. return true;
  192. } catch (Dibi\Exception $e) {
  193. return $e;
  194. }
  195. }
  196. function createFirstAdmin($path,$filename,$username,$password,$email) {
  197. try {
  198. $createDB = new Dibi\Connection([
  199. 'driver' => 'sqlite3',
  200. 'database' => $path.$filename,
  201. ]);
  202. $userInfo = [
  203. 'username' => $username,
  204. 'password' => password_hash($password, PASSWORD_BCRYPT),
  205. 'email' => $email,
  206. 'group' => 'Admin',
  207. 'group_id' => 0,
  208. 'image' => gravatar($email),
  209. 'register_date' => $GLOBALS['currentTime'],
  210. ];
  211. $groupInfo0 = [
  212. 'group' => 'Admin',
  213. 'group_id' => 0,
  214. 'default' => false,
  215. 'image' => 'plugins/images/groups/admin.png',
  216. ];
  217. $groupInfo1 = [
  218. 'group' => 'Co-Admin',
  219. 'group_id' => 1,
  220. 'default' => false,
  221. 'image' => 'plugins/images/groups/coadmin.png',
  222. ];
  223. $groupInfo2 = [
  224. 'group' => 'Super User',
  225. 'group_id' => 2,
  226. 'default' => false,
  227. 'image' => 'plugins/images/groups/superuser.png',
  228. ];
  229. $groupInfo3 = [
  230. 'group' => 'Power User',
  231. 'group_id' => 3,
  232. 'default' => false,
  233. 'image' => 'plugins/images/groups/poweruser.png',
  234. ];
  235. $groupInfo4 = [
  236. 'group' => 'User',
  237. 'group_id' => 4,
  238. 'default' => true,
  239. 'image' => 'plugins/images/groups/user.png',
  240. ];
  241. $groupInfoGuest = [
  242. 'group' => 'Guest',
  243. 'group_id' => 999,
  244. 'default' => false,
  245. 'image' => 'plugins/images/groups/guest.png',
  246. ];
  247. $settingsInfo = [
  248. 'order' => 1,
  249. 'category_id' => 0,
  250. 'name' => 'Settings',
  251. 'url' => 'api/?v1/settings/page',
  252. 'default' => false,
  253. 'enabled' => true,
  254. 'group_id' => 1,
  255. 'image' => 'fontawesome::cog',
  256. 'type' => 0
  257. ];
  258. $homepageInfo = [
  259. 'order' => 2,
  260. 'category_id' => 0,
  261. 'name' => 'Homepage',
  262. 'url' => 'api/?v1/homepage/page',
  263. 'default' => false,
  264. 'enabled' => false,
  265. 'group_id' => 4,
  266. 'image' => 'fontawesome::home',
  267. 'type' => 0
  268. ];
  269. $unsortedInfo = [
  270. 'order' => 1,
  271. 'category' => 'Unsorted',
  272. 'category_id' => 0,
  273. 'image' => 'plugins/images/categories/unsorted.png',
  274. 'default' => true
  275. ];
  276. $createDB->query('INSERT INTO [users]', $userInfo);
  277. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  278. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  279. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  280. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  281. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  282. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  283. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  284. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  285. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  286. return true;
  287. } catch (Dibi\Exception $e) {
  288. return false;
  289. }
  290. }
  291. function defaultUserGroup(){
  292. try {
  293. $connect = new Dibi\Connection([
  294. 'driver' => 'sqlite3',
  295. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  296. ]);
  297. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  298. return $all;
  299. } catch (Dibi\Exception $e) {
  300. return false;
  301. }
  302. }
  303. function defaulTabCategory(){
  304. try {
  305. $connect = new Dibi\Connection([
  306. 'driver' => 'sqlite3',
  307. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  308. ]);
  309. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  310. return $all;
  311. } catch (Dibi\Exception $e) {
  312. return false;
  313. }
  314. }
  315. function getGuest(){
  316. if(isset($GLOBALS['dbLocation'])){
  317. try {
  318. $connect = new Dibi\Connection([
  319. 'driver' => 'sqlite3',
  320. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  321. ]);
  322. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  323. return $all;
  324. } catch (Dibi\Exception $e) {
  325. return false;
  326. }
  327. }else{
  328. return array(
  329. 'group' => 'Guest',
  330. 'group_id' => 999,
  331. 'image' => 'plugins/images/groups/guest.png'
  332. );
  333. }
  334. }
  335. function adminEditGroup($array){
  336. switch ($array['data']['action']) {
  337. case 'changeDefaultGroup':
  338. try {
  339. $connect = new Dibi\Connection([
  340. 'driver' => 'sqlite3',
  341. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  342. ]);
  343. $connect->query('UPDATE groups SET `default` = 0');
  344. $connect->query('
  345. UPDATE groups SET', [
  346. 'default' => 1
  347. ], '
  348. WHERE id=?', $array['data']['id']);
  349. writeLog('success', 'Group Management Function - Changed Default Group from ['.$array['data']['oldGroupName'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  350. return true;
  351. } catch (Dibi\Exception $e) {
  352. return false;
  353. }
  354. break;
  355. case 'deleteUserGroup':
  356. try {
  357. $connect = new Dibi\Connection([
  358. 'driver' => 'sqlite3',
  359. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  360. ]);
  361. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  362. writeLog('success', 'Group Management Function - Deleted Group ['.$array['data']['groupName'].']', $GLOBALS['organizrUser']['username']);
  363. return true;
  364. } catch (Dibi\Exception $e) {
  365. return false;
  366. }
  367. break;
  368. case 'addUserGroup':
  369. try {
  370. $connect = new Dibi\Connection([
  371. 'driver' => 'sqlite3',
  372. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  373. ]);
  374. $newGroup = [
  375. 'group' => $array['data']['newGroupName'],
  376. 'group_id' => $array['data']['newGroupID'],
  377. 'default' => false,
  378. 'image' => $array['data']['newGroupImage'],
  379. ];
  380. $connect->query('INSERT INTO [groups]', $newGroup);
  381. writeLog('success', 'Group Management Function - Added Group ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  382. return true;
  383. } catch (Dibi\Exception $e) {
  384. return false;
  385. }
  386. break;
  387. case 'editUserGroup':
  388. try {
  389. $connect = new Dibi\Connection([
  390. 'driver' => 'sqlite3',
  391. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  392. ]);
  393. $connect->query('
  394. UPDATE groups SET', [
  395. 'group' => $array['data']['groupName'],
  396. 'image' => $array['data']['groupImage'],
  397. ], '
  398. WHERE id=?', $array['data']['id']);
  399. writeLog('success', 'Group Management Function - Edited Group Info for ['.$array['data']['oldGroupName'].']', $GLOBALS['organizrUser']['username']);
  400. return true;
  401. } catch (Dibi\Exception $e) {
  402. return false;
  403. }
  404. break;
  405. default:
  406. # code...
  407. break;
  408. }
  409. }
  410. function adminEditUser($array){
  411. switch ($array['data']['action']) {
  412. case 'changeGroup':
  413. try {
  414. $connect = new Dibi\Connection([
  415. 'driver' => 'sqlite3',
  416. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  417. ]);
  418. $connect->query('
  419. UPDATE users SET', [
  420. 'group' => $array['data']['newGroupName'],
  421. 'group_id' => $array['data']['newGroupID'],
  422. ], '
  423. WHERE id=?', $array['data']['id']);
  424. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  425. return true;
  426. } catch (Dibi\Exception $e) {
  427. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  428. return false;
  429. }
  430. break;
  431. case 'addNewUser':
  432. $defaults = defaultUserGroup();
  433. if(createUser($array['data']['username'],$array['data']['password'],$defaults,$array['data']['email'])){
  434. writeLog('success', 'Create User Function - Acount created for ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  435. return true;
  436. }else{
  437. writeLog('error', 'Registration Function - An error occured', $GLOBALS['organizrUser']['username']);
  438. return 'username taken';
  439. }
  440. break;
  441. case 'deleteUser':
  442. try {
  443. $connect = new Dibi\Connection([
  444. 'driver' => 'sqlite3',
  445. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  446. ]);
  447. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  448. writeLog('success', 'User Management Function - Deleted User ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  449. return true;
  450. } catch (Dibi\Exception $e) {
  451. return false;
  452. }
  453. break;
  454. default:
  455. # code...
  456. break;
  457. }
  458. }
  459. function editTabs($array){
  460. switch ($array['data']['action']) {
  461. case 'changeGroup':
  462. try {
  463. $connect = new Dibi\Connection([
  464. 'driver' => 'sqlite3',
  465. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  466. ]);
  467. $connect->query('
  468. UPDATE tabs SET', [
  469. 'group_id' => $array['data']['newGroupID'],
  470. ], '
  471. WHERE id=?', $array['data']['id']);
  472. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s group was changed to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  473. return true;
  474. } catch (Dibi\Exception $e) {
  475. return false;
  476. }
  477. break;
  478. case 'changeCategory':
  479. try {
  480. $connect = new Dibi\Connection([
  481. 'driver' => 'sqlite3',
  482. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  483. ]);
  484. $connect->query('
  485. UPDATE tabs SET', [
  486. 'category_id' => $array['data']['newCategoryID'],
  487. ], '
  488. WHERE id=?', $array['data']['id']);
  489. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s category was changed to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  490. return true;
  491. } catch (Dibi\Exception $e) {
  492. return false;
  493. }
  494. break;
  495. case 'changeType':
  496. try {
  497. $connect = new Dibi\Connection([
  498. 'driver' => 'sqlite3',
  499. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  500. ]);
  501. $connect->query('
  502. UPDATE tabs SET', [
  503. 'type' => $array['data']['newTypeID'],
  504. ], '
  505. WHERE id=?', $array['data']['id']);
  506. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s type was changed to ['.$array['data']['newTypeName'].']', $GLOBALS['organizrUser']['username']);
  507. return true;
  508. } catch (Dibi\Exception $e) {
  509. return false;
  510. }
  511. break;
  512. case 'changeEnabled':
  513. try {
  514. $connect = new Dibi\Connection([
  515. 'driver' => 'sqlite3',
  516. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  517. ]);
  518. $connect->query('
  519. UPDATE tabs SET', [
  520. 'enabled' => $array['data']['tabEnabled'],
  521. ], '
  522. WHERE id=?', $array['data']['id']);
  523. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s enable status was changed to ['.$array['data']['tabEnabledWord'].']', $GLOBALS['organizrUser']['username']);
  524. return true;
  525. } catch (Dibi\Exception $e) {
  526. return false;
  527. }
  528. break;
  529. case 'changeSplash':
  530. try {
  531. $connect = new Dibi\Connection([
  532. 'driver' => 'sqlite3',
  533. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  534. ]);
  535. $connect->query('
  536. UPDATE tabs SET', [
  537. 'splash' => $array['data']['tabSplash'],
  538. ], '
  539. WHERE id=?', $array['data']['id']);
  540. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s splash status was changed to ['.$array['data']['tabSplashWord'].']', $GLOBALS['organizrUser']['username']);
  541. return true;
  542. } catch (Dibi\Exception $e) {
  543. return false;
  544. }
  545. break;
  546. case 'changeDefault':
  547. try {
  548. $connect = new Dibi\Connection([
  549. 'driver' => 'sqlite3',
  550. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  551. ]);
  552. $connect->query('UPDATE tabs SET `default` = 0');
  553. $connect->query('
  554. UPDATE tabs SET', [
  555. 'default' => 1
  556. ], '
  557. WHERE id=?', $array['data']['id']);
  558. writeLog('success', 'Tab Editor Function - Changed Default Tab to ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  559. return true;
  560. } catch (Dibi\Exception $e) {
  561. return false;
  562. }
  563. break;
  564. case 'deleteTab':
  565. try {
  566. $connect = new Dibi\Connection([
  567. 'driver' => 'sqlite3',
  568. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  569. ]);
  570. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  571. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  572. return true;
  573. } catch (Dibi\Exception $e) {
  574. return false;
  575. }
  576. break;
  577. case 'editTab':
  578. try {
  579. $connect = new Dibi\Connection([
  580. 'driver' => 'sqlite3',
  581. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  582. ]);
  583. $connect->query('
  584. UPDATE tabs SET', [
  585. 'name' => $array['data']['tabName'],
  586. 'url' => $array['data']['tabURL'],
  587. 'image' => $array['data']['tabImage'],
  588. ], '
  589. WHERE id=?', $array['data']['id']);
  590. writeLog('success', 'Tab Editor Function - Edited Tab Info for ['.$array['data']['tabName'].']', $GLOBALS['organizrUser']['username']);
  591. return true;
  592. } catch (Dibi\Exception $e) {
  593. return false;
  594. }
  595. case 'changeOrder':
  596. try {
  597. $connect = new Dibi\Connection([
  598. 'driver' => 'sqlite3',
  599. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  600. ]);
  601. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  602. if($value['order'] != $value['originalOrder']){
  603. $connect->query('
  604. UPDATE tabs SET', [
  605. 'order' => $value['order'],
  606. ], '
  607. WHERE id=?', $value['id']);
  608. writeLog('success', 'Tab Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  609. }
  610. }
  611. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  612. return true;
  613. } catch (Dibi\Exception $e) {
  614. return false;
  615. }
  616. break;
  617. case 'addNewTab':
  618. try {
  619. $default = defaulTabCategory()['category_id'];
  620. $connect = new Dibi\Connection([
  621. 'driver' => 'sqlite3',
  622. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  623. ]);
  624. $newTab = [
  625. 'order' => $array['data']['tabOrder'],
  626. 'category_id' => $default,
  627. 'name' => $array['data']['tabName'],
  628. 'url' => $array['data']['tabURL'],
  629. 'default' => $array['data']['tabDefault'],
  630. 'enabled' => 1,
  631. 'group_id' => $array['data']['tabGroupID'],
  632. 'image' => $array['data']['tabImage'],
  633. 'type' => $array['data']['tabType']
  634. ];
  635. $connect->query('INSERT INTO [tabs]', $newTab);
  636. writeLog('success', 'Tab Editor Function - Created Tab for: '.$array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  637. return true;
  638. } catch (Dibi\Exception $e) {
  639. return false;
  640. }
  641. break;
  642. case 'deleteTab':
  643. try {
  644. $connect = new Dibi\Connection([
  645. 'driver' => 'sqlite3',
  646. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  647. ]);
  648. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  649. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  650. return true;
  651. } catch (Dibi\Exception $e) {
  652. return false;
  653. }
  654. break;
  655. default:
  656. # code...
  657. break;
  658. }
  659. }
  660. function editCategories($array){
  661. switch ($array['data']['action']) {
  662. case 'changeDefault':
  663. try {
  664. $connect = new Dibi\Connection([
  665. 'driver' => 'sqlite3',
  666. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  667. ]);
  668. $connect->query('UPDATE categories SET `default` = 0');
  669. $connect->query('
  670. UPDATE categories SET', [
  671. 'default' => 1
  672. ], '
  673. WHERE id=?', $array['data']['id']);
  674. writeLog('success', 'Category Editor Function - Changed Default Category from ['.$array['data']['oldCategoryName'].'] to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  675. return true;
  676. } catch (Dibi\Exception $e) {
  677. return false;
  678. }
  679. break;
  680. case 'deleteCategory':
  681. try {
  682. $connect = new Dibi\Connection([
  683. 'driver' => 'sqlite3',
  684. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  685. ]);
  686. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  687. writeLog('success', 'Category Editor Function - Deleted Category ['.$array['data']['category'].']', $GLOBALS['organizrUser']['username']);
  688. return true;
  689. } catch (Dibi\Exception $e) {
  690. return false;
  691. }
  692. break;
  693. case 'addNewCategory':
  694. try {
  695. $connect = new Dibi\Connection([
  696. 'driver' => 'sqlite3',
  697. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  698. ]);
  699. $newCategory = [
  700. 'category' => $array['data']['categoryName'],
  701. 'order' => $array['data']['categoryOrder'],
  702. 'category_id' => $array['data']['categoryID'],
  703. 'default' => false,
  704. 'image' => $array['data']['categoryImage'],
  705. ];
  706. $connect->query('INSERT INTO [categories]', $newCategory);
  707. writeLog('success', 'Category Editor Function - Added Category ['.$array['data']['categoryName'].']', $GLOBALS['organizrUser']['username']);
  708. return true;
  709. } catch (Dibi\Exception $e) {
  710. return $e;
  711. }
  712. break;
  713. case 'editCategory':
  714. try {
  715. $connect = new Dibi\Connection([
  716. 'driver' => 'sqlite3',
  717. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  718. ]);
  719. $connect->query('
  720. UPDATE categories SET', [
  721. 'category' => $array['data']['name'],
  722. 'image' => $array['data']['image'],
  723. ], '
  724. WHERE id=?', $array['data']['id']);
  725. writeLog('success', 'Category Editor Function - Edited Category Info for ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  726. return true;
  727. } catch (Dibi\Exception $e) {
  728. return false;
  729. }
  730. break;
  731. case 'changeOrder':
  732. try {
  733. $connect = new Dibi\Connection([
  734. 'driver' => 'sqlite3',
  735. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  736. ]);
  737. foreach ($array['data']['categories']['category'] as $key => $value) {
  738. if($value['order'] != $value['originalOrder']){
  739. $connect->query('
  740. UPDATE categories SET', [
  741. 'order' => $value['order'],
  742. ], '
  743. WHERE id=?', $value['id']);
  744. writeLog('success', 'Category Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  745. }
  746. }
  747. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  748. return true;
  749. } catch (Dibi\Exception $e) {
  750. return false;
  751. }
  752. break;
  753. default:
  754. # code...
  755. break;
  756. }
  757. }
  758. function allUsers(){
  759. try {
  760. $connect = new Dibi\Connection([
  761. 'driver' => 'sqlite3',
  762. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  763. ]);
  764. $users = $connect->fetchAll('SELECT * FROM users');
  765. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  766. foreach ($users as $k => $v) {
  767. // clear password from array
  768. unset($users[$k]['password']);
  769. }
  770. $all['users'] = $users;
  771. $all['groups'] = $groups;
  772. return $all;
  773. } catch (Dibi\Exception $e) {
  774. return false;
  775. }
  776. }
  777. function usernameTaken($username,$email){
  778. try {
  779. $connect = new Dibi\Connection([
  780. 'driver' => 'sqlite3',
  781. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  782. ]);
  783. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$email);
  784. return ($all) ? true : false;
  785. } catch (Dibi\Exception $e) {
  786. return false;
  787. }
  788. }
  789. function createUser($username,$password,$defaults,$email=null) {
  790. $email = ($email) ? $email : random_ascii_string(10).'@placeholder.eml';
  791. try {
  792. if(!usernameTaken($username,$email)){
  793. $createDB = new Dibi\Connection([
  794. 'driver' => 'sqlite3',
  795. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  796. ]);
  797. $userInfo = [
  798. 'username' => $username,
  799. 'password' => password_hash($password, PASSWORD_BCRYPT),
  800. 'email' => $email,
  801. 'group' => $defaults['group'],
  802. 'group_id' => $defaults['group_id'],
  803. 'image' => gravatar($email),
  804. 'register_date' => $GLOBALS['currentTime'],
  805. ];
  806. $createDB->query('INSERT INTO [users]', $userInfo);
  807. return true;
  808. }else{
  809. return false;
  810. }
  811. } catch (Dibi\Exception $e) {
  812. return false;
  813. }
  814. }
  815. function allTabs(){
  816. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  817. try {
  818. $connect = new Dibi\Connection([
  819. 'driver' => 'sqlite3',
  820. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  821. ]);
  822. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  823. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  824. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  825. return $all;
  826. } catch (Dibi\Exception $e) {
  827. return false;
  828. }
  829. }
  830. }
  831. function loadTabs(){
  832. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  833. try {
  834. $connect = new Dibi\Connection([
  835. 'driver' => 'sqlite3',
  836. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  837. ]);
  838. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` DESC',$GLOBALS['organizrUser']['groupID']);
  839. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  840. $all['tabs'] = $tabs;
  841. foreach ($tabs as $k => $v) {
  842. $v['access_url'] = isset($v['url_local']) && $_SERVER['SERVER_ADDR'] == userIP() ? $v['url_local'] : $v['url'];
  843. }
  844. $count = array_map(function($element){
  845. return $element['category_id'];
  846. }, $tabs);
  847. $count = (array_count_values($count));
  848. foreach ($categories as $k => $v) {
  849. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  850. }
  851. $all['categories'] = $categories;
  852. return $all;
  853. } catch (Dibi\Exception $e) {
  854. return false;
  855. }
  856. }
  857. }