api-functions.php 36 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = $oAuth = $oAuthType = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  25. $oAuth = (isset($oAuth)) ? $oAuth : false;
  26. try {
  27. $database = new Dibi\Connection([
  28. 'driver' => 'sqlite3',
  29. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  30. ]);
  31. $authSuccess = false;
  32. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  33. if (!$oAuth) {
  34. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  35. switch ($GLOBALS['authType']) {
  36. case 'external':
  37. if (function_exists($function)) {
  38. $authSuccess = $function($username, $password);
  39. }
  40. break;
  41. /** @noinspection PhpMissingBreakStatementInspection */
  42. case 'both':
  43. if (function_exists($function)) {
  44. $authSuccess = $function($username, $password);
  45. }
  46. // no break
  47. default: // Internal
  48. if (!$authSuccess) {
  49. // perform the internal authentication step
  50. if (password_verify($password, $result['password'])) {
  51. $authSuccess = true;
  52. }
  53. }
  54. }
  55. } else {
  56. // Has oAuth Token!
  57. switch ($oAuthType) {
  58. case 'plex':
  59. if ($GLOBALS['plexoAuth']) {
  60. $tokenInfo = checkPlexToken($oAuth);
  61. if ($tokenInfo) {
  62. $authSuccess = array(
  63. 'username' => $tokenInfo['user']['username'],
  64. 'email' => $tokenInfo['user']['email'],
  65. 'image' => $tokenInfo['user']['thumb'],
  66. 'token' => $tokenInfo['user']['authToken']
  67. );
  68. coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
  69. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  70. }
  71. }
  72. break;
  73. default:
  74. return 'error';
  75. break;
  76. }
  77. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  78. }
  79. if ($authSuccess) {
  80. // Make sure user exists in database
  81. $userExists = false;
  82. $passwordMatches = ($oAuth) ? true : false;
  83. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  84. if ($result['username']) {
  85. $userExists = true;
  86. $username = $result['username'];
  87. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  88. }
  89. if ($userExists) {
  90. //does org password need to be updated
  91. if (!$passwordMatches) {
  92. $database->query('
  93. UPDATE users SET', [
  94. 'password' => password_hash($password, PASSWORD_BCRYPT)
  95. ], '
  96. WHERE id=?', $result['id']);
  97. writeLog('success', 'Login Function - User Password updated from backend', $username);
  98. }
  99. if ($token !== '') {
  100. if ($token !== $result['plex_token']) {
  101. $database->query('
  102. UPDATE users SET', [
  103. 'plex_token' => $token
  104. ], '
  105. WHERE id=?', $result['id']);
  106. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  107. }
  108. }
  109. // 2FA might go here
  110. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  111. $TFA = explode('::', $result['auth_service']);
  112. // Is code with login info?
  113. if ($tfaCode == '') {
  114. return '2FA';
  115. } else {
  116. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  117. writeLoginLog($username, 'error');
  118. writeLog('error', 'Login Function - Wrong 2FA', $username);
  119. return '2FA-incorrect';
  120. }
  121. }
  122. }
  123. // End 2FA
  124. // authentication passed - 1) mark active and update token
  125. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  126. writeLoginLog($username, 'success');
  127. writeLog('success', 'Login Function - A User has logged in', $username);
  128. ssoCheck($username, $password, $token); //need to work on this
  129. return true;
  130. } else {
  131. return 'error';
  132. }
  133. } else {
  134. // Create User
  135. //ssoCheck($username, $password, $token);
  136. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  137. }
  138. } else {
  139. // authentication failed
  140. writeLoginLog($username, 'error');
  141. writeLog('error', 'Login Function - Wrong Password', $username);
  142. return 'mismatch';
  143. }
  144. } catch (Dibi\Exception $e) {
  145. return $e;
  146. }
  147. }
  148. function createDB($path, $filename)
  149. {
  150. try {
  151. if (!file_exists($path)) {
  152. mkdir($path, 0777, true);
  153. }
  154. $createDB = new Dibi\Connection([
  155. 'driver' => 'sqlite3',
  156. 'database' => $path . $filename,
  157. ]);
  158. // Create Users
  159. $createDB->query('CREATE TABLE `users` (
  160. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  161. `username` TEXT UNIQUE,
  162. `password` TEXT,
  163. `email` TEXT,
  164. `plex_token` TEXT,
  165. `group` TEXT,
  166. `group_id` INTEGER,
  167. `locked` INTEGER,
  168. `image` TEXT,
  169. `register_date` DATE,
  170. `auth_service` TEXT DEFAULT \'internal\'
  171. );');
  172. // Create Tokens
  173. $createDB->query('CREATE TABLE `chatroom` (
  174. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  175. `username` TEXT,
  176. `gravatar` TEXT,
  177. `uid` TEXT,
  178. `date` DATE,
  179. `ip` TEXT,
  180. `message` TEXT
  181. );');
  182. $createDB->query('CREATE TABLE `tokens` (
  183. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  184. `token` TEXT UNIQUE,
  185. `user_id` INTEGER,
  186. `browser` TEXT,
  187. `ip` TEXT,
  188. `created` DATE,
  189. `expires` DATE
  190. );');
  191. $createDB->query('CREATE TABLE `groups` (
  192. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  193. `group` TEXT UNIQUE,
  194. `group_id` INTEGER,
  195. `image` TEXT,
  196. `default` INTEGER
  197. );');
  198. $createDB->query('CREATE TABLE `categories` (
  199. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  200. `order` INTEGER,
  201. `category` TEXT UNIQUE,
  202. `category_id` INTEGER,
  203. `image` TEXT,
  204. `default` INTEGER
  205. );');
  206. // Create Tabs
  207. $createDB->query('CREATE TABLE `tabs` (
  208. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  209. `order` INTEGER,
  210. `category_id` INTEGER,
  211. `name` TEXT,
  212. `url` TEXT,
  213. `url_local` TEXT,
  214. `default` INTEGER,
  215. `enabled` INTEGER,
  216. `group_id` INTEGER,
  217. `image` TEXT,
  218. `type` INTEGER,
  219. `splash` INTEGER,
  220. `ping` INTEGER,
  221. `ping_url` TEXT,
  222. `timeout` INTEGER,
  223. `timeout_ms` INTEGER,
  224. `preload` INTEGER
  225. );');
  226. // Create Options
  227. $createDB->query('CREATE TABLE `options` (
  228. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  229. `name` TEXT UNIQUE,
  230. `value` TEXT
  231. );');
  232. // Create Invites
  233. $createDB->query('CREATE TABLE `invites` (
  234. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  235. `code` TEXT UNIQUE,
  236. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  237. `email` TEXT,
  238. `username` TEXT,
  239. `dateused` TIMESTAMP,
  240. `usedby` TEXT,
  241. `ip` TEXT,
  242. `valid` TEXT,
  243. `type` TEXT
  244. );');
  245. return true;
  246. } catch (Dibi\Exception $e) {
  247. return false;
  248. }
  249. }
  250. // Upgrade Database
  251. function updateDB($oldVerNum = false)
  252. {
  253. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  254. if (!file_exists($tempLock)) {
  255. touch($tempLock);
  256. // Create Temp DB First
  257. $migrationDB = 'tempMigration.db';
  258. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  259. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  260. unlink($GLOBALS['dbLocation'] . $migrationDB);
  261. }
  262. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  263. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  264. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  265. if ($success) {
  266. try {
  267. $connectOldDB = new Dibi\Connection([
  268. 'driver' => 'sqlite3',
  269. 'database' => $backupDB,
  270. ]);
  271. $connectNewDB = new Dibi\Connection([
  272. 'driver' => 'sqlite3',
  273. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  274. ]);
  275. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  276. foreach ($tables as $table) {
  277. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  278. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  279. foreach ($data as $row) {
  280. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  281. }
  282. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  283. }
  284. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  285. $connectOldDB->disconnect();
  286. $connectNewDB->disconnect();
  287. // Remove Current Database
  288. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  289. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  290. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  291. if ($newFileSize > 0) {
  292. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  293. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  294. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  295. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  296. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  297. @unlink($tempLock);
  298. return true;
  299. }
  300. }
  301. @unlink($tempLock);
  302. return false;
  303. } catch (Dibi\Exception $e) {
  304. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  305. @unlink($tempLock);
  306. return false;
  307. }
  308. }
  309. @unlink($tempLock);
  310. return false;
  311. }
  312. return false;
  313. }
  314. function createFirstAdmin($path, $filename, $username, $password, $email)
  315. {
  316. try {
  317. $createDB = new Dibi\Connection([
  318. 'driver' => 'sqlite3',
  319. 'database' => $path . $filename,
  320. ]);
  321. $userInfo = [
  322. 'username' => $username,
  323. 'password' => password_hash($password, PASSWORD_BCRYPT),
  324. 'email' => $email,
  325. 'group' => 'Admin',
  326. 'group_id' => 0,
  327. 'image' => gravatar($email),
  328. 'register_date' => $GLOBALS['currentTime'],
  329. ];
  330. $groupInfo0 = [
  331. 'group' => 'Admin',
  332. 'group_id' => 0,
  333. 'default' => false,
  334. 'image' => 'plugins/images/groups/admin.png',
  335. ];
  336. $groupInfo1 = [
  337. 'group' => 'Co-Admin',
  338. 'group_id' => 1,
  339. 'default' => false,
  340. 'image' => 'plugins/images/groups/coadmin.png',
  341. ];
  342. $groupInfo2 = [
  343. 'group' => 'Super User',
  344. 'group_id' => 2,
  345. 'default' => false,
  346. 'image' => 'plugins/images/groups/superuser.png',
  347. ];
  348. $groupInfo3 = [
  349. 'group' => 'Power User',
  350. 'group_id' => 3,
  351. 'default' => false,
  352. 'image' => 'plugins/images/groups/poweruser.png',
  353. ];
  354. $groupInfo4 = [
  355. 'group' => 'User',
  356. 'group_id' => 4,
  357. 'default' => true,
  358. 'image' => 'plugins/images/groups/user.png',
  359. ];
  360. $groupInfoGuest = [
  361. 'group' => 'Guest',
  362. 'group_id' => 999,
  363. 'default' => false,
  364. 'image' => 'plugins/images/groups/guest.png',
  365. ];
  366. $settingsInfo = [
  367. 'order' => 1,
  368. 'category_id' => 0,
  369. 'name' => 'Settings',
  370. 'url' => 'api/?v1/settings/page',
  371. 'default' => false,
  372. 'enabled' => true,
  373. 'group_id' => 1,
  374. 'image' => 'fontawesome::cog',
  375. 'type' => 0
  376. ];
  377. $homepageInfo = [
  378. 'order' => 2,
  379. 'category_id' => 0,
  380. 'name' => 'Homepage',
  381. 'url' => 'api/?v1/homepage/page',
  382. 'default' => false,
  383. 'enabled' => false,
  384. 'group_id' => 4,
  385. 'image' => 'fontawesome::home',
  386. 'type' => 0
  387. ];
  388. $unsortedInfo = [
  389. 'order' => 1,
  390. 'category' => 'Unsorted',
  391. 'category_id' => 0,
  392. 'image' => 'plugins/images/categories/unsorted.png',
  393. 'default' => true
  394. ];
  395. $createDB->query('INSERT INTO [users]', $userInfo);
  396. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  397. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  398. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  399. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  400. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  401. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  402. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  403. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  404. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  405. return true;
  406. } catch (Dibi\Exception $e) {
  407. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  408. return false;
  409. }
  410. }
  411. function defaultUserGroup()
  412. {
  413. try {
  414. $connect = new Dibi\Connection([
  415. 'driver' => 'sqlite3',
  416. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  417. ]);
  418. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  419. return $all;
  420. } catch (Dibi\Exception $e) {
  421. return false;
  422. }
  423. }
  424. function defaultTabCategory()
  425. {
  426. try {
  427. $connect = new Dibi\Connection([
  428. 'driver' => 'sqlite3',
  429. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  430. ]);
  431. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  432. return $all;
  433. } catch (Dibi\Exception $e) {
  434. return false;
  435. }
  436. }
  437. function getGuest()
  438. {
  439. if (isset($GLOBALS['dbLocation'])) {
  440. try {
  441. $connect = new Dibi\Connection([
  442. 'driver' => 'sqlite3',
  443. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  444. ]);
  445. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  446. return $all;
  447. } catch (Dibi\Exception $e) {
  448. return false;
  449. }
  450. } else {
  451. return array(
  452. 'group' => 'Guest',
  453. 'group_id' => 999,
  454. 'image' => 'plugins/images/groups/guest.png'
  455. );
  456. }
  457. }
  458. function adminEditGroup($array)
  459. {
  460. switch ($array['data']['action']) {
  461. case 'changeDefaultGroup':
  462. try {
  463. $connect = new Dibi\Connection([
  464. 'driver' => 'sqlite3',
  465. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  466. ]);
  467. $connect->query('UPDATE groups SET `default` = 0');
  468. $connect->query('
  469. UPDATE groups SET', [
  470. 'default' => 1
  471. ], '
  472. WHERE id=?', $array['data']['id']);
  473. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  474. return true;
  475. } catch (Dibi\Exception $e) {
  476. return false;
  477. }
  478. break;
  479. case 'deleteUserGroup':
  480. try {
  481. $connect = new Dibi\Connection([
  482. 'driver' => 'sqlite3',
  483. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  484. ]);
  485. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  486. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  487. return true;
  488. } catch (Dibi\Exception $e) {
  489. return false;
  490. }
  491. break;
  492. case 'addUserGroup':
  493. try {
  494. $connect = new Dibi\Connection([
  495. 'driver' => 'sqlite3',
  496. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  497. ]);
  498. $newGroup = [
  499. 'group' => $array['data']['newGroupName'],
  500. 'group_id' => $array['data']['newGroupID'],
  501. 'default' => false,
  502. 'image' => $array['data']['newGroupImage'],
  503. ];
  504. $connect->query('INSERT INTO [groups]', $newGroup);
  505. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  506. return true;
  507. } catch (Dibi\Exception $e) {
  508. return false;
  509. }
  510. break;
  511. case 'editUserGroup':
  512. try {
  513. $connect = new Dibi\Connection([
  514. 'driver' => 'sqlite3',
  515. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  516. ]);
  517. $connect->query('
  518. UPDATE groups SET', [
  519. 'group' => $array['data']['groupName'],
  520. 'image' => $array['data']['groupImage'],
  521. ], '
  522. WHERE id=?', $array['data']['id']);
  523. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  524. return true;
  525. } catch (Dibi\Exception $e) {
  526. return false;
  527. }
  528. break;
  529. default:
  530. return false;
  531. break;
  532. }
  533. }
  534. function adminEditUser($array)
  535. {
  536. switch ($array['data']['action']) {
  537. case 'changeGroup':
  538. try {
  539. $connect = new Dibi\Connection([
  540. 'driver' => 'sqlite3',
  541. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  542. ]);
  543. $connect->query('
  544. UPDATE users SET', [
  545. 'group' => $array['data']['newGroupName'],
  546. 'group_id' => $array['data']['newGroupID'],
  547. ], '
  548. WHERE id=?', $array['data']['id']);
  549. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  550. return true;
  551. } catch (Dibi\Exception $e) {
  552. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  553. return false;
  554. }
  555. break;
  556. case 'editUser':
  557. try {
  558. $connect = new Dibi\Connection([
  559. 'driver' => 'sqlite3',
  560. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  561. ]);
  562. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  563. $connect->query('
  564. UPDATE users SET', [
  565. 'username' => $array['data']['username'],
  566. 'email' => $array['data']['email'],
  567. 'image' => gravatar($array['data']['email']),
  568. ], '
  569. WHERE id=?', $array['data']['id']);
  570. if (!empty($array['data']['password'])) {
  571. $connect->query('
  572. UPDATE users SET', [
  573. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  574. ], '
  575. WHERE id=?', $array['data']['id']);
  576. }
  577. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  578. return true;
  579. } else {
  580. return false;
  581. }
  582. } catch (Dibi\Exception $e) {
  583. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  584. return false;
  585. }
  586. break;
  587. case 'addNewUser':
  588. $defaults = defaultUserGroup();
  589. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  590. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  591. return true;
  592. } else {
  593. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  594. return 'username taken';
  595. }
  596. break;
  597. case 'deleteUser':
  598. try {
  599. $connect = new Dibi\Connection([
  600. 'driver' => 'sqlite3',
  601. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  602. ]);
  603. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  604. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  605. return true;
  606. } catch (Dibi\Exception $e) {
  607. return false;
  608. }
  609. break;
  610. default:
  611. return false;
  612. break;
  613. }
  614. }
  615. function editTabs($array)
  616. {
  617. switch ($array['data']['action']) {
  618. case 'changeGroup':
  619. try {
  620. $connect = new Dibi\Connection([
  621. 'driver' => 'sqlite3',
  622. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  623. ]);
  624. $connect->query('
  625. UPDATE tabs SET', [
  626. 'group_id' => $array['data']['newGroupID'],
  627. ], '
  628. WHERE id=?', $array['data']['id']);
  629. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  630. return true;
  631. } catch (Dibi\Exception $e) {
  632. return false;
  633. }
  634. break;
  635. case 'changeCategory':
  636. try {
  637. $connect = new Dibi\Connection([
  638. 'driver' => 'sqlite3',
  639. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  640. ]);
  641. $connect->query('
  642. UPDATE tabs SET', [
  643. 'category_id' => $array['data']['newCategoryID'],
  644. ], '
  645. WHERE id=?', $array['data']['id']);
  646. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  647. return true;
  648. } catch (Dibi\Exception $e) {
  649. return false;
  650. }
  651. break;
  652. case 'changeType':
  653. try {
  654. $connect = new Dibi\Connection([
  655. 'driver' => 'sqlite3',
  656. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  657. ]);
  658. $connect->query('
  659. UPDATE tabs SET', [
  660. 'type' => $array['data']['newTypeID'],
  661. ], '
  662. WHERE id=?', $array['data']['id']);
  663. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  664. return true;
  665. } catch (Dibi\Exception $e) {
  666. return false;
  667. }
  668. break;
  669. case 'changeEnabled':
  670. try {
  671. $connect = new Dibi\Connection([
  672. 'driver' => 'sqlite3',
  673. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  674. ]);
  675. $connect->query('
  676. UPDATE tabs SET', [
  677. 'enabled' => $array['data']['tabEnabled'],
  678. ], '
  679. WHERE id=?', $array['data']['id']);
  680. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  681. return true;
  682. } catch (Dibi\Exception $e) {
  683. return false;
  684. }
  685. break;
  686. case 'changeSplash':
  687. try {
  688. $connect = new Dibi\Connection([
  689. 'driver' => 'sqlite3',
  690. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  691. ]);
  692. $connect->query('
  693. UPDATE tabs SET', [
  694. 'splash' => $array['data']['tabSplash'],
  695. ], '
  696. WHERE id=?', $array['data']['id']);
  697. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  698. return true;
  699. } catch (Dibi\Exception $e) {
  700. return false;
  701. }
  702. break;
  703. case 'changePing':
  704. try {
  705. $connect = new Dibi\Connection([
  706. 'driver' => 'sqlite3',
  707. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  708. ]);
  709. $connect->query('
  710. UPDATE tabs SET', [
  711. 'ping' => $array['data']['tabPing'],
  712. ], '
  713. WHERE id=?', $array['data']['id']);
  714. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  715. return true;
  716. } catch (Dibi\Exception $e) {
  717. return false;
  718. }
  719. break;
  720. case 'changeDefault':
  721. try {
  722. $connect = new Dibi\Connection([
  723. 'driver' => 'sqlite3',
  724. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  725. ]);
  726. $connect->query('UPDATE tabs SET `default` = 0');
  727. $connect->query('
  728. UPDATE tabs SET', [
  729. 'default' => 1
  730. ], '
  731. WHERE id=?', $array['data']['id']);
  732. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  733. return true;
  734. } catch (Dibi\Exception $e) {
  735. return false;
  736. }
  737. break;
  738. case 'deleteTab':
  739. try {
  740. $connect = new Dibi\Connection([
  741. 'driver' => 'sqlite3',
  742. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  743. ]);
  744. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  745. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  746. return true;
  747. } catch (Dibi\Exception $e) {
  748. return false;
  749. }
  750. break;
  751. case 'editTab':
  752. try {
  753. $connect = new Dibi\Connection([
  754. 'driver' => 'sqlite3',
  755. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  756. ]);
  757. $connect->query('
  758. UPDATE tabs SET', [
  759. 'name' => $array['data']['tabName'],
  760. 'url' => $array['data']['tabURL'],
  761. 'ping_url' => $array['data']['pingURL'],
  762. 'image' => $array['data']['tabImage'],
  763. ], '
  764. WHERE id=?', $array['data']['id']);
  765. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  766. return true;
  767. } catch (Dibi\Exception $e) {
  768. return false;
  769. }
  770. case 'changeOrder':
  771. try {
  772. $connect = new Dibi\Connection([
  773. 'driver' => 'sqlite3',
  774. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  775. ]);
  776. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  777. if ($value['order'] != $value['originalOrder']) {
  778. $connect->query('
  779. UPDATE tabs SET', [
  780. 'order' => $value['order'],
  781. ], '
  782. WHERE id=?', $value['id']);
  783. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  784. }
  785. }
  786. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  787. return true;
  788. } catch (Dibi\Exception $e) {
  789. return false;
  790. }
  791. break;
  792. case 'addNewTab':
  793. try {
  794. $default = defaultTabCategory()['category_id'];
  795. $connect = new Dibi\Connection([
  796. 'driver' => 'sqlite3',
  797. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  798. ]);
  799. $newTab = [
  800. 'order' => $array['data']['tabOrder'],
  801. 'category_id' => $default,
  802. 'name' => $array['data']['tabName'],
  803. 'url' => $array['data']['tabURL'],
  804. 'ping_url' => $array['data']['pingURL'],
  805. 'default' => $array['data']['tabDefault'],
  806. 'enabled' => 1,
  807. 'group_id' => $array['data']['tabGroupID'],
  808. 'image' => $array['data']['tabImage'],
  809. 'type' => $array['data']['tabType']
  810. ];
  811. $connect->query('INSERT INTO [tabs]', $newTab);
  812. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  813. return true;
  814. } catch (Dibi\Exception $e) {
  815. return false;
  816. }
  817. break;
  818. default:
  819. return false;
  820. break;
  821. }
  822. }
  823. function editCategories($array)
  824. {
  825. switch ($array['data']['action']) {
  826. case 'changeDefault':
  827. try {
  828. $connect = new Dibi\Connection([
  829. 'driver' => 'sqlite3',
  830. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  831. ]);
  832. $connect->query('UPDATE categories SET `default` = 0');
  833. $connect->query('
  834. UPDATE categories SET', [
  835. 'default' => 1
  836. ], '
  837. WHERE id=?', $array['data']['id']);
  838. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  839. return true;
  840. } catch (Dibi\Exception $e) {
  841. return false;
  842. }
  843. break;
  844. case 'deleteCategory':
  845. try {
  846. $connect = new Dibi\Connection([
  847. 'driver' => 'sqlite3',
  848. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  849. ]);
  850. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  851. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  852. return true;
  853. } catch (Dibi\Exception $e) {
  854. return false;
  855. }
  856. break;
  857. case 'addNewCategory':
  858. try {
  859. $connect = new Dibi\Connection([
  860. 'driver' => 'sqlite3',
  861. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  862. ]);
  863. $newCategory = [
  864. 'category' => $array['data']['categoryName'],
  865. 'order' => $array['data']['categoryOrder'],
  866. 'category_id' => $array['data']['categoryID'],
  867. 'default' => false,
  868. 'image' => $array['data']['categoryImage'],
  869. ];
  870. $connect->query('INSERT INTO [categories]', $newCategory);
  871. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  872. return true;
  873. } catch (Dibi\Exception $e) {
  874. return $e;
  875. }
  876. break;
  877. case 'editCategory':
  878. try {
  879. $connect = new Dibi\Connection([
  880. 'driver' => 'sqlite3',
  881. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  882. ]);
  883. $connect->query('
  884. UPDATE categories SET', [
  885. 'category' => $array['data']['name'],
  886. 'image' => $array['data']['image'],
  887. ], '
  888. WHERE id=?', $array['data']['id']);
  889. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  890. return true;
  891. } catch (Dibi\Exception $e) {
  892. return false;
  893. }
  894. break;
  895. case 'changeOrder':
  896. try {
  897. $connect = new Dibi\Connection([
  898. 'driver' => 'sqlite3',
  899. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  900. ]);
  901. foreach ($array['data']['categories']['category'] as $key => $value) {
  902. if ($value['order'] != $value['originalOrder']) {
  903. $connect->query('
  904. UPDATE categories SET', [
  905. 'order' => $value['order'],
  906. ], '
  907. WHERE id=?', $value['id']);
  908. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  909. }
  910. }
  911. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  912. return true;
  913. } catch (Dibi\Exception $e) {
  914. return false;
  915. }
  916. break;
  917. default:
  918. return false;
  919. break;
  920. }
  921. }
  922. function allUsers()
  923. {
  924. try {
  925. $connect = new Dibi\Connection([
  926. 'driver' => 'sqlite3',
  927. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  928. ]);
  929. $users = $connect->fetchAll('SELECT * FROM users');
  930. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  931. foreach ($users as $k => $v) {
  932. // clear password from array
  933. unset($users[$k]['password']);
  934. }
  935. $all['users'] = $users;
  936. $all['groups'] = $groups;
  937. return $all;
  938. } catch (Dibi\Exception $e) {
  939. return false;
  940. }
  941. }
  942. function usernameTaken($username, $email)
  943. {
  944. try {
  945. $connect = new Dibi\Connection([
  946. 'driver' => 'sqlite3',
  947. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  948. ]);
  949. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  950. return ($all) ? true : false;
  951. } catch (Dibi\Exception $e) {
  952. return false;
  953. }
  954. }
  955. function usernameTakenExcept($username, $email, $id)
  956. {
  957. try {
  958. $connect = new Dibi\Connection([
  959. 'driver' => 'sqlite3',
  960. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  961. ]);
  962. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  963. return ($all) ? true : false;
  964. } catch (Dibi\Exception $e) {
  965. return false;
  966. }
  967. }
  968. function createUser($username, $password, $defaults, $email = null)
  969. {
  970. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  971. try {
  972. if (!usernameTaken($username, $email)) {
  973. $createDB = new Dibi\Connection([
  974. 'driver' => 'sqlite3',
  975. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  976. ]);
  977. $userInfo = [
  978. 'username' => $username,
  979. 'password' => password_hash($password, PASSWORD_BCRYPT),
  980. 'email' => $email,
  981. 'group' => $defaults['group'],
  982. 'group_id' => $defaults['group_id'],
  983. 'image' => gravatar($email),
  984. 'register_date' => $GLOBALS['currentTime'],
  985. ];
  986. $createDB->query('INSERT INTO [users]', $userInfo);
  987. return true;
  988. } else {
  989. return false;
  990. }
  991. } catch (Dibi\Exception $e) {
  992. return false;
  993. }
  994. }
  995. function importUsers($array)
  996. {
  997. $imported = 0;
  998. $defaults = defaultUserGroup();
  999. foreach ($array as $user) {
  1000. $password = random_ascii_string(30);
  1001. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1002. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1003. if (!$newUser) {
  1004. writeLog('error', 'Import Function - Error', $user['username']);
  1005. } else {
  1006. $imported++;
  1007. }
  1008. }
  1009. }
  1010. return $imported;
  1011. }
  1012. function importUsersType($array)
  1013. {
  1014. $type = $array['data']['type'];
  1015. if ($type !== '') {
  1016. switch ($type) {
  1017. case 'plex':
  1018. return importUsers(allPlexUsers(true));
  1019. break;
  1020. default:
  1021. return false;
  1022. }
  1023. }
  1024. return false;
  1025. }
  1026. function allTabs()
  1027. {
  1028. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1029. try {
  1030. $connect = new Dibi\Connection([
  1031. 'driver' => 'sqlite3',
  1032. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1033. ]);
  1034. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1035. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1036. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1037. return $all;
  1038. } catch (Dibi\Exception $e) {
  1039. return false;
  1040. }
  1041. }
  1042. return false;
  1043. }
  1044. function allGroups()
  1045. {
  1046. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1047. try {
  1048. $connect = new Dibi\Connection([
  1049. 'driver' => 'sqlite3',
  1050. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1051. ]);
  1052. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1053. return $all;
  1054. } catch (Dibi\Exception $e) {
  1055. return false;
  1056. }
  1057. }
  1058. return false;
  1059. }
  1060. function loadTabs()
  1061. {
  1062. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1063. try {
  1064. $connect = new Dibi\Connection([
  1065. 'driver' => 'sqlite3',
  1066. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1067. ]);
  1068. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1069. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1070. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1071. $all['tabs'] = $tabs;
  1072. foreach ($tabs as $k => $v) {
  1073. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  1074. }
  1075. $count = array_map(function ($element) {
  1076. return $element['category_id'];
  1077. }, $tabs);
  1078. $count = (array_count_values($count));
  1079. foreach ($categories as $k => $v) {
  1080. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1081. }
  1082. $all['categories'] = $categories;
  1083. return $all;
  1084. } catch (Dibi\Exception $e) {
  1085. return false;
  1086. }
  1087. }
  1088. return false;
  1089. }
  1090. function getActiveTokens()
  1091. {
  1092. try {
  1093. $connect = new Dibi\Connection([
  1094. 'driver' => 'sqlite3',
  1095. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1096. ]);
  1097. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1098. return $all;
  1099. } catch (Dibi\Exception $e) {
  1100. return false;
  1101. }
  1102. }
  1103. function revokeToken($array)
  1104. {
  1105. if ($array['data']['token']) {
  1106. try {
  1107. $connect = new Dibi\Connection([
  1108. 'driver' => 'sqlite3',
  1109. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1110. ]);
  1111. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1112. return true;
  1113. } catch (Dibi\Exception $e) {
  1114. return false;
  1115. }
  1116. }
  1117. }