index.php 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609
  1. <?php
  2. $generationTime = -microtime(true);
  3. //include functions
  4. require_once 'functions.php';
  5. //Set result array
  6. $result = array();
  7. //Get request method
  8. $method = $_SERVER['REQUEST_METHOD'];
  9. reset($_GET);
  10. $function = (key($_GET) ? str_replace("/","_",key($_GET)) : false);
  11. //Exit if $function is blank
  12. if($function === false){
  13. $result['status'] = "error";
  14. $result['statusText'] = "No API Path Supplied";
  15. exit(json_encode($result));
  16. }
  17. $result['request'] = key($_GET);
  18. switch ($function) {
  19. case 'v1_settings_page':
  20. switch ($method) {
  21. case 'GET':
  22. if(qualifyRequest(1)){
  23. $result['status'] = 'success';
  24. $result['statusText'] = 'success';
  25. $result['data'] = $pageSettings;
  26. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  27. }else{
  28. $result['status'] = 'error';
  29. $result['statusText'] = 'API/Token invalid or not set';
  30. $result['data'] = null;
  31. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  32. }
  33. break;
  34. default:
  35. $result['status'] = 'error';
  36. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  37. break;
  38. }
  39. break;
  40. case 'v1_settings_settings_logs':
  41. switch ($method) {
  42. case 'GET':
  43. if(qualifyRequest(1)){
  44. $result['status'] = 'success';
  45. $result['statusText'] = 'success';
  46. $result['data'] = $pageSettingsSettingsLogs;
  47. }else{
  48. $result['status'] = 'error';
  49. $result['statusText'] = 'API/Token invalid or not set';
  50. $result['data'] = null;
  51. }
  52. break;
  53. default:
  54. $result['status'] = 'error';
  55. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  56. break;
  57. }
  58. break;
  59. case 'v1_settings_customize_appearance':
  60. switch ($method) {
  61. case 'GET':
  62. if(qualifyRequest(1)){
  63. $result['status'] = 'success';
  64. $result['statusText'] = 'success';
  65. $result['data'] = $pageSettingsCustomizeAppearance;
  66. }else{
  67. $result['status'] = 'error';
  68. $result['statusText'] = 'API/Token invalid or not set';
  69. $result['data'] = null;
  70. }
  71. break;
  72. case 'POST':
  73. if(qualifyRequest(1)){
  74. $result['status'] = 'success';
  75. $result['statusText'] = 'success';
  76. $result['data'] = editAppearance($_POST);
  77. }else{
  78. $result['status'] = 'error';
  79. $result['statusText'] = 'API/Token invalid or not set';
  80. $result['data'] = null;
  81. }
  82. break;
  83. default:
  84. $result['status'] = 'error';
  85. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  86. break;
  87. }
  88. break;
  89. case 'v1_settings_tab_editor_tabs':
  90. switch ($method) {
  91. case 'GET':
  92. if(qualifyRequest(1)){
  93. $result['status'] = 'success';
  94. $result['statusText'] = 'success';
  95. $result['data'] = $pageSettingsTabEditorTabs;
  96. }else{
  97. $result['status'] = 'error';
  98. $result['statusText'] = 'API/Token invalid or not set';
  99. $result['data'] = null;
  100. }
  101. break;
  102. case 'POST':
  103. if(qualifyRequest(1)){
  104. $result['status'] = 'success';
  105. $result['statusText'] = 'success';
  106. $result['data'] = editTabs($_POST);
  107. }else{
  108. $result['status'] = 'error';
  109. $result['statusText'] = 'API/Token invalid or not set';
  110. $result['data'] = null;
  111. }
  112. break;
  113. default:
  114. $result['status'] = 'error';
  115. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  116. break;
  117. }
  118. break;
  119. case 'v1_settings_tab_editor_categories':
  120. switch ($method) {
  121. case 'GET':
  122. if(qualifyRequest(1)){
  123. $result['status'] = 'success';
  124. $result['statusText'] = 'success';
  125. $result['data'] = $pageSettingsTabEditorCategories;
  126. }else{
  127. $result['status'] = 'error';
  128. $result['statusText'] = 'API/Token invalid or not set';
  129. $result['data'] = null;
  130. }
  131. break;
  132. case 'POST':
  133. if(qualifyRequest(1)){
  134. $result['status'] = 'success';
  135. $result['statusText'] = 'success';
  136. $result['data'] = editCategories($_POST);
  137. }else{
  138. $result['status'] = 'error';
  139. $result['statusText'] = 'API/Token invalid or not set';
  140. $result['data'] = null;
  141. }
  142. break;
  143. default:
  144. $result['status'] = 'error';
  145. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  146. break;
  147. }
  148. break;
  149. case 'v1_settings_user_manage_users':
  150. switch ($method) {
  151. case 'GET':
  152. if(qualifyRequest(1)){
  153. $result['status'] = 'success';
  154. $result['statusText'] = 'success';
  155. $result['data'] = $pageSettingsUserManageUsers;
  156. }else{
  157. $result['status'] = 'error';
  158. $result['statusText'] = 'API/Token invalid or not set';
  159. $result['data'] = null;
  160. }
  161. break;
  162. case 'POST':
  163. if(qualifyRequest(1)){
  164. $result['status'] = 'success';
  165. $result['statusText'] = 'success';
  166. $result['data'] = adminEditUser($_POST);
  167. }elseif(qualifyRequest(998)){
  168. $result['status'] = 'success';
  169. $result['statusText'] = 'success';
  170. $result['data'] = editUser($_POST);
  171. }else{
  172. $result['status'] = 'error';
  173. $result['statusText'] = 'API/Token invalid or not set';
  174. $result['data'] = null;
  175. }
  176. break;
  177. default:
  178. $result['status'] = 'error';
  179. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  180. break;
  181. }
  182. break;
  183. case 'v1_settings_user_manage_groups':
  184. switch ($method) {
  185. case 'GET':
  186. if(qualifyRequest(1)){
  187. $result['status'] = 'success';
  188. $result['statusText'] = 'success';
  189. $result['data'] = $pageSettingsUserManageGroups;
  190. }else{
  191. $result['status'] = 'error';
  192. $result['statusText'] = 'API/Token invalid or not set';
  193. $result['data'] = null;
  194. }
  195. break;
  196. case 'POST':
  197. if(qualifyRequest(1)){
  198. $result['status'] = 'success';
  199. $result['statusText'] = 'success';
  200. $result['data'] = adminEditGroup($_POST);
  201. }else{
  202. $result['status'] = 'error';
  203. $result['statusText'] = 'API/Token invalid or not set';
  204. $result['data'] = null;
  205. }
  206. break;
  207. default:
  208. $result['status'] = 'error';
  209. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  210. break;
  211. }
  212. break;
  213. case 'v1_settings_image_manager_view':
  214. switch ($method) {
  215. case 'GET':
  216. if(qualifyRequest(1)){
  217. $result['status'] = 'success';
  218. $result['statusText'] = 'success';
  219. $result['data'] = $pageSettingsImageManager;
  220. }else{
  221. $result['status'] = 'error';
  222. $result['statusText'] = 'API/Token invalid or not set';
  223. $result['data'] = null;
  224. }
  225. break;
  226. case 'POST':
  227. if(qualifyRequest(1)){
  228. $result['status'] = 'success';
  229. $result['statusText'] = 'success';
  230. $result['data'] = editImages();
  231. }else{
  232. $result['status'] = 'error';
  233. $result['statusText'] = 'API/Token invalid or not set';
  234. $result['data'] = null;
  235. }
  236. break;
  237. default:
  238. $result['status'] = 'error';
  239. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  240. break;
  241. }
  242. break;
  243. case 'v1_wizard_page':
  244. switch ($method) {
  245. case 'GET':
  246. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  247. $result['status'] = 'success';
  248. $result['statusText'] = 'success';
  249. $result['data'] = $pageWizard;
  250. }else{
  251. $result['status'] = 'error';
  252. $result['statusText'] = 'Wizard has already been run';
  253. $result['data'] = null;
  254. }
  255. break;
  256. default:
  257. $result['status'] = 'error';
  258. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  259. break;
  260. }
  261. break;
  262. case 'v1_dependencies_page':
  263. switch ($method) {
  264. case 'GET':
  265. $result['status'] = 'success';
  266. $result['statusText'] = 'success';
  267. $result['data'] = $pageDependencies;
  268. break;
  269. default:
  270. $result['status'] = 'error';
  271. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  272. break;
  273. }
  274. break;
  275. case 'v1_wizard_config':
  276. switch ($method) {
  277. case 'POST':
  278. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  279. $result['status'] = 'success';
  280. $result['statusText'] = 'success';
  281. $result['data'] = wizardConfig($_POST);
  282. }else{
  283. $result['status'] = 'error';
  284. $result['statusText'] = 'Wizard has already been run';
  285. $result['data'] = null;
  286. }
  287. break;
  288. default:
  289. $result['status'] = 'error';
  290. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  291. break;
  292. }
  293. break;
  294. case 'v1_login':
  295. switch ($method) {
  296. case 'POST':
  297. $result['status'] = 'success';
  298. $result['statusText'] = 'success';
  299. $result['data'] = login($_POST);
  300. break;
  301. default:
  302. $result['status'] = 'error';
  303. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  304. break;
  305. }
  306. break;
  307. case 'v1_register':
  308. switch ($method) {
  309. case 'POST':
  310. $result['status'] = 'success';
  311. $result['statusText'] = 'success';
  312. $result['data'] = register($_POST);
  313. break;
  314. default:
  315. $result['status'] = 'error';
  316. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  317. break;
  318. }
  319. break;
  320. case 'v1_upgrade':
  321. case 'v1_update':
  322. case 'v1_force':
  323. switch ($method) {
  324. case 'POST':
  325. if(qualifyRequest(1)){
  326. $result['status'] = 'success';
  327. $result['statusText'] = 'success';
  328. $result['data'] = upgradeInstall($_POST['data']['branch'],$_POST['data']['stage']);
  329. }else{
  330. $result['status'] = 'error';
  331. $result['statusText'] = 'API/Token invalid or not set';
  332. $result['data'] = null;
  333. }
  334. break;
  335. default:
  336. $result['status'] = 'error';
  337. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  338. break;
  339. }
  340. break;
  341. case 'v1_login_page':
  342. switch ($method) {
  343. case 'GET':
  344. $result['status'] = 'success';
  345. $result['statusText'] = 'success';
  346. $result['data'] = $pageLogin;
  347. break;
  348. default:
  349. $result['status'] = 'error';
  350. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  351. break;
  352. }
  353. break;
  354. case 'v1_lockscreen':
  355. switch ($method) {
  356. case 'GET':
  357. $result['status'] = 'success';
  358. $result['statusText'] = 'success';
  359. $result['data'] = $pageLockScreen;
  360. break;
  361. default:
  362. $result['status'] = 'error';
  363. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  364. break;
  365. }
  366. break;
  367. case 'v1_login_log':
  368. switch ($method) {
  369. case 'GET':
  370. if(qualifyRequest(1)){
  371. $result['status'] = 'success';
  372. $result['statusText'] = 'success';
  373. $result['data'] = getLog('loginLog');
  374. }else{
  375. $result['status'] = 'error';
  376. $result['statusText'] = 'API/Token invalid or not set';
  377. $result['data'] = null;
  378. }
  379. break;
  380. default:
  381. $result['status'] = 'error';
  382. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  383. break;
  384. }
  385. break;
  386. case 'v1_organizr_log':
  387. switch ($method) {
  388. case 'GET':
  389. if(qualifyRequest(1)){
  390. $result['status'] = 'success';
  391. $result['statusText'] = 'success';
  392. $result['data'] = getLog('org');
  393. }else{
  394. $result['status'] = 'error';
  395. $result['statusText'] = 'API/Token invalid or not set';
  396. $result['data'] = null;
  397. }
  398. break;
  399. default:
  400. $result['status'] = 'error';
  401. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  402. break;
  403. }
  404. break;
  405. case 'v1_user_list':
  406. switch ($method) {
  407. case 'GET':
  408. if(qualifyRequest(1)){
  409. $result['status'] = 'success';
  410. $result['statusText'] = 'success';
  411. $result['data'] = allUsers();
  412. }else{
  413. $result['status'] = 'error';
  414. $result['statusText'] = 'API/Token invalid or not set';
  415. $result['data'] = null;
  416. }
  417. break;
  418. default:
  419. $result['status'] = 'error';
  420. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  421. break;
  422. }
  423. break;
  424. case 'v1_tab_list':
  425. switch ($method) {
  426. case 'GET':
  427. if(qualifyRequest(1)){
  428. $result['status'] = 'success';
  429. $result['statusText'] = 'success';
  430. $result['data'] = allTabs();
  431. }else{
  432. $result['status'] = 'error';
  433. $result['statusText'] = 'API/Token invalid or not set';
  434. $result['data'] = null;
  435. }
  436. break;
  437. default:
  438. $result['status'] = 'error';
  439. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  440. break;
  441. }
  442. break;
  443. case 'v1_image_list':
  444. switch ($method) {
  445. case 'GET':
  446. if(qualifyRequest(1)){
  447. $result['status'] = 'success';
  448. $result['statusText'] = 'success';
  449. $result['data'] = getImages();
  450. }else{
  451. $result['status'] = 'error';
  452. $result['statusText'] = 'API/Token invalid or not set';
  453. $result['data'] = null;
  454. }
  455. break;
  456. default:
  457. $result['status'] = 'error';
  458. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  459. break;
  460. }
  461. break;
  462. case 'v1_customize_appearance':
  463. switch ($method) {
  464. case 'GET':
  465. if(qualifyRequest(1)){
  466. $result['status'] = 'success';
  467. $result['statusText'] = 'success';
  468. $result['data'] = getCustomizeAppearance();
  469. }else{
  470. $result['status'] = 'error';
  471. $result['statusText'] = 'API/Token invalid or not set';
  472. $result['data'] = null;
  473. }
  474. break;
  475. default:
  476. $result['status'] = 'error';
  477. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  478. break;
  479. }
  480. break;
  481. case 'v1_user_edit':
  482. switch ($method) {
  483. case 'POST':
  484. if(qualifyRequest(1)){
  485. $result['status'] = 'success';
  486. $result['statusText'] = 'success';
  487. $result['data'] = adminEditUser($_POST);
  488. }elseif(qualifyRequest(998)){
  489. $result['status'] = 'success';
  490. $result['statusText'] = 'success';
  491. $result['data'] = editUser($_POST);
  492. }else{
  493. $result['status'] = 'error';
  494. $result['statusText'] = 'API/Token invalid or not set';
  495. $result['data'] = null;
  496. }
  497. break;
  498. default:
  499. $result['status'] = 'error';
  500. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  501. break;
  502. }
  503. break;
  504. case 'v1_logout':
  505. switch ($method) {
  506. case 'GET':
  507. $result['status'] = 'success';
  508. $result['statusText'] = 'success';
  509. $result['data'] = logout();
  510. break;
  511. default:
  512. $result['status'] = 'error';
  513. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  514. break;
  515. }
  516. break;
  517. case 'v1_launch_organizr':
  518. switch ($method) {
  519. case 'GET':
  520. $status = array();
  521. $result['status'] = 'success';
  522. $result['statusText'] = 'success';
  523. $status['status'] = organizrStatus();
  524. $result['appearance'] = loadAppearance();
  525. $status['user'] = $GLOBALS['organizrUser'];
  526. $status['categories'] = loadTabs()['categories'];
  527. $status['tabs'] = loadTabs()['tabs'];
  528. $result['data'] = $status;
  529. $result['branch'] = $GLOBALS['branch'];
  530. break;
  531. default:
  532. $result['status'] = 'error';
  533. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  534. break;
  535. }
  536. break;
  537. case 'v1_auth':
  538. switch ($method) {
  539. case 'GET':
  540. auth();
  541. break;
  542. default:
  543. $result['status'] = 'error';
  544. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  545. break;
  546. }
  547. break;
  548. case 'v1_plugin':
  549. switch ($method) {
  550. case 'GET':
  551. if(qualifyRequest(1)){
  552. $result['status'] = 'success';
  553. $result['statusText'] = 'success';
  554. $result['data'] = 'plugin admin';
  555. }elseif(qualifyRequest(998)){
  556. $result['status'] = 'success';
  557. $result['statusText'] = 'success';
  558. $result['data'] = 'plugin logged in';
  559. }elseif(qualifyRequest(999)){
  560. $result['status'] = 'success';
  561. $result['statusText'] = 'success';
  562. $result['data'] = 'plugin guest';
  563. }else{
  564. $result['status'] = 'error';
  565. $result['statusText'] = 'API/Token invalid or not set';
  566. $result['data'] = null;
  567. }
  568. break;
  569. case 'POST':
  570. if(qualifyRequest(1)){
  571. $result['status'] = 'success';
  572. $result['statusText'] = 'success';
  573. $result['data'] = 'plugin admin';
  574. }elseif(qualifyRequest(998)){
  575. $result['status'] = 'success';
  576. $result['statusText'] = 'success';
  577. $result['data'] = 'plugin logged in';
  578. }elseif(qualifyRequest(999)){
  579. $result['status'] = 'success';
  580. $result['statusText'] = 'success';
  581. $result['data'] = 'plugin guest';
  582. }else{
  583. $result['status'] = 'error';
  584. $result['statusText'] = 'API/Token invalid or not set';
  585. $result['data'] = null;
  586. }
  587. break;
  588. default:
  589. $result['status'] = 'error';
  590. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  591. break;
  592. }
  593. break;
  594. default:
  595. //No Function Available
  596. $result['status'] = 'error';
  597. $result['statusText'] = 'function requested is not defined';
  598. break;
  599. }
  600. //Set Default Result
  601. if(!$result){
  602. $result['status'] = "error";
  603. $result['error'] = "An error has occurred";
  604. }
  605. $result['generationDate'] = $GLOBALS['currentTime'];
  606. $generationTime += microtime(true);
  607. $result['generationTime'] = (sprintf('%f', $generationTime)*1000).'ms';
  608. //return JSON array
  609. exit(json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));