index.php 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362
  1. <?php
  2. //include functions
  3. require_once 'functions.php';
  4. //Set result array
  5. $result = array();
  6. //Get request method
  7. $method = $_SERVER['REQUEST_METHOD'];
  8. $pretty = isset($_GET['pretty']) ? true : false;
  9. reset($_GET);
  10. $function = (key($_GET) ? str_replace("/", "_", key($_GET)) : false);
  11. //Exit if $function is blank
  12. if ($function === false) {
  13. $result['status'] = "error";
  14. $result['statusText'] = "No API Path Supplied";
  15. exit(json_encode($result));
  16. }
  17. $approvedFunctionsBypass = array(
  18. 'v1_upgrade',
  19. 'v1_update',
  20. 'v1_force',
  21. 'v1_auth',
  22. 'v1_wizard_config',
  23. 'v1_login',
  24. 'v1_wizard_path',
  25. );
  26. if (!in_array($function, $approvedFunctionsBypass)) {
  27. if (isApprovedRequest($method) === false) {
  28. $result['status'] = "error";
  29. $result['statusText'] = "Not Authorized";
  30. writeLog('success', 'Killed Attack From [' . (isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : 'No Referer') . ']', $GLOBALS['organizrUser']['username']);
  31. exit(json_encode($result));
  32. }
  33. }
  34. $result['request'] = key($_GET);
  35. $result['params'] = $_POST;
  36. switch ($function) {
  37. case 'v1_settings_page':
  38. switch ($method) {
  39. case 'GET':
  40. if (qualifyRequest(1)) {
  41. $result['status'] = 'success';
  42. $result['statusText'] = 'success';
  43. $result['data'] = $pageSettings;
  44. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  45. } else {
  46. $result['status'] = 'error';
  47. $result['statusText'] = 'API/Token invalid or not set';
  48. $result['data'] = null;
  49. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  50. }
  51. break;
  52. default:
  53. $result['status'] = 'error';
  54. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  55. break;
  56. }
  57. break;
  58. case 'v1_homepage_page':
  59. switch ($method) {
  60. case 'GET':
  61. $result['status'] = 'success';
  62. $result['statusText'] = 'success';
  63. $result['data'] = $pageHomepage;
  64. break;
  65. default:
  66. $result['status'] = 'error';
  67. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  68. break;
  69. }
  70. break;
  71. case 'v1_settings_plugins':
  72. switch ($method) {
  73. case 'GET':
  74. if (qualifyRequest(1)) {
  75. $result['status'] = 'success';
  76. $result['statusText'] = 'success';
  77. $result['data'] = $pageSettingsPlugins;
  78. } else {
  79. $result['status'] = 'error';
  80. $result['statusText'] = 'API/Token invalid or not set';
  81. $result['data'] = null;
  82. }
  83. break;
  84. default:
  85. $result['status'] = 'error';
  86. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  87. break;
  88. }
  89. break;
  90. case 'v1_settings_tab_editor_homepage':
  91. switch ($method) {
  92. case 'GET':
  93. if (qualifyRequest(1)) {
  94. $result['status'] = 'success';
  95. $result['statusText'] = 'success';
  96. $result['data'] = $pageSettingsTabEditorHomepage;
  97. } else {
  98. $result['status'] = 'error';
  99. $result['statusText'] = 'API/Token invalid or not set';
  100. $result['data'] = null;
  101. }
  102. break;
  103. default:
  104. $result['status'] = 'error';
  105. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  106. break;
  107. }
  108. break;
  109. case 'v1_settings_tab_editor_homepage_order':
  110. switch ($method) {
  111. case 'GET':
  112. if (qualifyRequest(1)) {
  113. $result['status'] = 'success';
  114. $result['statusText'] = 'success';
  115. $result['data'] = $pageSettingsTabEditorHomepageOrder;
  116. } else {
  117. $result['status'] = 'error';
  118. $result['statusText'] = 'API/Token invalid or not set';
  119. $result['data'] = null;
  120. }
  121. break;
  122. default:
  123. $result['status'] = 'error';
  124. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  125. break;
  126. }
  127. break;
  128. case 'v1_settings_homepage_list':
  129. switch ($method) {
  130. case 'GET':
  131. if (qualifyRequest(1)) {
  132. $result['status'] = 'success';
  133. $result['statusText'] = 'success';
  134. $result['data'] = getHomepageList();
  135. } else {
  136. $result['status'] = 'error';
  137. $result['statusText'] = 'API/Token invalid or not set';
  138. $result['data'] = null;
  139. }
  140. break;
  141. case 'POST':
  142. if (qualifyRequest(1)) {
  143. $result['status'] = 'success';
  144. $result['statusText'] = 'success';
  145. $result['data'] = editPlugins($_POST);
  146. } else {
  147. $result['status'] = 'error';
  148. $result['statusText'] = 'API/Token invalid or not set';
  149. $result['data'] = null;
  150. }
  151. break;
  152. default:
  153. $result['status'] = 'error';
  154. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  155. break;
  156. }
  157. break;
  158. case 'v1_settings_plugins_list':
  159. switch ($method) {
  160. case 'GET':
  161. if (qualifyRequest(1)) {
  162. $result['status'] = 'success';
  163. $result['statusText'] = 'success';
  164. $result['data'] = getPlugins();
  165. } else {
  166. $result['status'] = 'error';
  167. $result['statusText'] = 'API/Token invalid or not set';
  168. $result['data'] = null;
  169. }
  170. break;
  171. case 'POST':
  172. if (qualifyRequest(1)) {
  173. $result['status'] = 'success';
  174. $result['statusText'] = 'success';
  175. $result['data'] = editPlugins($_POST);
  176. } else {
  177. $result['status'] = 'error';
  178. $result['statusText'] = 'API/Token invalid or not set';
  179. $result['data'] = null;
  180. }
  181. break;
  182. default:
  183. $result['status'] = 'error';
  184. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  185. break;
  186. }
  187. break;
  188. case 'v1_settings_settings_logs':
  189. switch ($method) {
  190. case 'GET':
  191. if (qualifyRequest(1)) {
  192. $result['status'] = 'success';
  193. $result['statusText'] = 'success';
  194. $result['data'] = $pageSettingsSettingsLogs;
  195. } else {
  196. $result['status'] = 'error';
  197. $result['statusText'] = 'API/Token invalid or not set';
  198. $result['data'] = null;
  199. }
  200. break;
  201. default:
  202. $result['status'] = 'error';
  203. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  204. break;
  205. }
  206. break;
  207. case 'v1_settings_settings_sso':
  208. switch ($method) {
  209. case 'GET':
  210. if (qualifyRequest(1)) {
  211. $result['status'] = 'success';
  212. $result['statusText'] = 'success';
  213. $result['data'] = $pageSettingsSettingsSSO;
  214. } else {
  215. $result['status'] = 'error';
  216. $result['statusText'] = 'API/Token invalid or not set';
  217. $result['data'] = null;
  218. }
  219. break;
  220. default:
  221. $result['status'] = 'error';
  222. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  223. break;
  224. }
  225. break;
  226. case 'v1_settings_settings_main':
  227. switch ($method) {
  228. case 'GET':
  229. if (qualifyRequest(1)) {
  230. $result['status'] = 'success';
  231. $result['statusText'] = 'success';
  232. $result['data'] = $pageSettingsSettingsMain;
  233. } else {
  234. $result['status'] = 'error';
  235. $result['statusText'] = 'API/Token invalid or not set';
  236. $result['data'] = null;
  237. }
  238. break;
  239. default:
  240. $result['status'] = 'error';
  241. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  242. break;
  243. }
  244. break;
  245. case 'v1_settings_customize_appearance':
  246. switch ($method) {
  247. case 'GET':
  248. if (qualifyRequest(1)) {
  249. $result['status'] = 'success';
  250. $result['statusText'] = 'success';
  251. $result['data'] = $pageSettingsCustomizeAppearance;
  252. } else {
  253. $result['status'] = 'error';
  254. $result['statusText'] = 'API/Token invalid or not set';
  255. $result['data'] = null;
  256. }
  257. break;
  258. case 'POST':
  259. if (qualifyRequest(1)) {
  260. $result['status'] = 'success';
  261. $result['statusText'] = 'success';
  262. $result['data'] = editAppearance($_POST);
  263. } else {
  264. $result['status'] = 'error';
  265. $result['statusText'] = 'API/Token invalid or not set';
  266. $result['data'] = null;
  267. }
  268. break;
  269. default:
  270. $result['status'] = 'error';
  271. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  272. break;
  273. }
  274. break;
  275. case 'v1_remove_file':
  276. switch ($method) {
  277. case 'POST':
  278. if (qualifyRequest(1)) {
  279. $result['status'] = 'success';
  280. $result['statusText'] = 'success';
  281. $result['data'] = removeFile($_POST);
  282. } else {
  283. $result['status'] = 'error';
  284. $result['statusText'] = 'API/Token invalid or not set';
  285. $result['data'] = null;
  286. }
  287. break;
  288. default:
  289. $result['status'] = 'error';
  290. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  291. break;
  292. }
  293. break;
  294. case 'v1_update_config':
  295. switch ($method) {
  296. case 'POST':
  297. if (qualifyRequest(1)) {
  298. $result['status'] = 'success';
  299. $result['statusText'] = 'success';
  300. $result['data'] = updateConfigItem($_POST);
  301. } else {
  302. $result['status'] = 'error';
  303. $result['statusText'] = 'API/Token invalid or not set';
  304. $result['data'] = null;
  305. }
  306. break;
  307. default:
  308. $result['status'] = 'error';
  309. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  310. break;
  311. }
  312. break;
  313. case 'v1_update_config_multiple':
  314. switch ($method) {
  315. case 'POST':
  316. if (qualifyRequest(1)) {
  317. $result['status'] = 'success';
  318. $result['statusText'] = 'success';
  319. $result['data'] = updateConfigMultiple($_POST);
  320. } else {
  321. $result['status'] = 'error';
  322. $result['statusText'] = 'API/Token invalid or not set';
  323. $result['data'] = null;
  324. }
  325. break;
  326. default:
  327. $result['status'] = 'error';
  328. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  329. break;
  330. }
  331. break;
  332. case 'v1_update_config_multiple_form':
  333. switch ($method) {
  334. case 'POST':
  335. if (qualifyRequest(1)) {
  336. $result['status'] = 'success';
  337. $result['statusText'] = 'success';
  338. $result['data'] = updateConfigMultipleForm($_POST);
  339. } else {
  340. $result['status'] = 'error';
  341. $result['statusText'] = 'API/Token invalid or not set';
  342. $result['data'] = null;
  343. }
  344. break;
  345. default:
  346. $result['status'] = 'error';
  347. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  348. break;
  349. }
  350. break;
  351. case 'v1_homepage_connect':
  352. switch ($method) {
  353. case 'POST':
  354. $result['status'] = 'success';
  355. $result['statusText'] = 'success';
  356. $result['data'] = homepageConnect($_POST);
  357. break;
  358. default:
  359. $result['status'] = 'error';
  360. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  361. break;
  362. }
  363. break;
  364. case 'v1_ping_list':
  365. switch ($method) {
  366. case 'POST':
  367. $result['status'] = 'success';
  368. $result['statusText'] = 'success';
  369. $result['data'] = ping($_POST['data']['pingList']);
  370. break;
  371. default:
  372. $result['status'] = 'error';
  373. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  374. break;
  375. }
  376. break;
  377. case 'v1_test_api_connection':
  378. switch ($method) {
  379. case 'POST':
  380. if (qualifyRequest(1)) {
  381. $result['status'] = 'success';
  382. $result['statusText'] = 'success';
  383. $result['data'] = testAPIConnection($_POST);
  384. } else {
  385. $result['status'] = 'error';
  386. $result['statusText'] = 'API/Token invalid or not set';
  387. $result['data'] = null;
  388. }
  389. break;
  390. default:
  391. $result['status'] = 'error';
  392. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  393. break;
  394. }
  395. break;
  396. case 'v1_settings_tab_editor_tabs':
  397. switch ($method) {
  398. case 'GET':
  399. if (qualifyRequest(1)) {
  400. $result['status'] = 'success';
  401. $result['statusText'] = 'success';
  402. $result['data'] = $pageSettingsTabEditorTabs;
  403. } else {
  404. $result['status'] = 'error';
  405. $result['statusText'] = 'API/Token invalid or not set';
  406. $result['data'] = null;
  407. }
  408. break;
  409. case 'POST':
  410. if (qualifyRequest(1)) {
  411. $result['status'] = 'success';
  412. $result['statusText'] = 'success';
  413. $result['data'] = editTabs($_POST);
  414. } else {
  415. $result['status'] = 'error';
  416. $result['statusText'] = 'API/Token invalid or not set';
  417. $result['data'] = null;
  418. }
  419. break;
  420. default:
  421. $result['status'] = 'error';
  422. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  423. break;
  424. }
  425. break;
  426. case 'v1_settings_tab_editor_categories':
  427. switch ($method) {
  428. case 'GET':
  429. if (qualifyRequest(1)) {
  430. $result['status'] = 'success';
  431. $result['statusText'] = 'success';
  432. $result['data'] = $pageSettingsTabEditorCategories;
  433. } else {
  434. $result['status'] = 'error';
  435. $result['statusText'] = 'API/Token invalid or not set';
  436. $result['data'] = null;
  437. }
  438. break;
  439. case 'POST':
  440. if (qualifyRequest(1)) {
  441. $result['status'] = 'success';
  442. $result['statusText'] = 'success';
  443. $result['data'] = editCategories($_POST);
  444. } else {
  445. $result['status'] = 'error';
  446. $result['statusText'] = 'API/Token invalid or not set';
  447. $result['data'] = null;
  448. }
  449. break;
  450. default:
  451. $result['status'] = 'error';
  452. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  453. break;
  454. }
  455. break;
  456. case 'v1_settings_user_manage_users':
  457. switch ($method) {
  458. case 'GET':
  459. if (qualifyRequest(1)) {
  460. $result['status'] = 'success';
  461. $result['statusText'] = 'success';
  462. $result['data'] = $pageSettingsUserManageUsers;
  463. } else {
  464. $result['status'] = 'error';
  465. $result['statusText'] = 'API/Token invalid or not set';
  466. $result['data'] = null;
  467. }
  468. break;
  469. case 'POST':
  470. if (qualifyRequest(1)) {
  471. $result['status'] = 'success';
  472. $result['statusText'] = 'success';
  473. $result['data'] = adminEditUser($_POST);
  474. } elseif (qualifyRequest(998)) {
  475. $result['status'] = 'success';
  476. $result['statusText'] = 'success';
  477. $result['data'] = editUser($_POST);
  478. } else {
  479. $result['status'] = 'error';
  480. $result['statusText'] = 'API/Token invalid or not set';
  481. $result['data'] = null;
  482. }
  483. break;
  484. default:
  485. $result['status'] = 'error';
  486. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  487. break;
  488. }
  489. break;
  490. case 'v1_manage_user':
  491. switch ($method) {
  492. case 'POST':
  493. if (qualifyRequest(998)) {
  494. $result['status'] = 'success';
  495. $result['statusText'] = 'success';
  496. $result['data'] = editUser($_POST);
  497. } else {
  498. $result['status'] = 'error';
  499. $result['statusText'] = 'API/Token invalid or not set';
  500. $result['data'] = null;
  501. }
  502. break;
  503. default:
  504. $result['status'] = 'error';
  505. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  506. break;
  507. }
  508. break;
  509. case 'v1_settings_user_manage_groups':
  510. switch ($method) {
  511. case 'GET':
  512. if (qualifyRequest(1)) {
  513. $result['status'] = 'success';
  514. $result['statusText'] = 'success';
  515. $result['data'] = $pageSettingsUserManageGroups;
  516. } else {
  517. $result['status'] = 'error';
  518. $result['statusText'] = 'API/Token invalid or not set';
  519. $result['data'] = null;
  520. }
  521. break;
  522. case 'POST':
  523. if (qualifyRequest(1)) {
  524. $result['status'] = 'success';
  525. $result['statusText'] = 'success';
  526. $result['data'] = adminEditGroup($_POST);
  527. } else {
  528. $result['status'] = 'error';
  529. $result['statusText'] = 'API/Token invalid or not set';
  530. $result['data'] = null;
  531. }
  532. break;
  533. default:
  534. $result['status'] = 'error';
  535. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  536. break;
  537. }
  538. break;
  539. case 'v1_settings_image_manager_view':
  540. switch ($method) {
  541. case 'GET':
  542. if (qualifyRequest(1)) {
  543. $result['status'] = 'success';
  544. $result['statusText'] = 'success';
  545. $result['data'] = $pageSettingsImageManager;
  546. } else {
  547. $result['status'] = 'error';
  548. $result['statusText'] = 'API/Token invalid or not set';
  549. $result['data'] = null;
  550. }
  551. break;
  552. case 'POST':
  553. if (qualifyRequest(1)) {
  554. $result['status'] = 'success';
  555. $result['statusText'] = 'success';
  556. $result['data'] = editImages();
  557. } else {
  558. $result['status'] = 'error';
  559. $result['statusText'] = 'API/Token invalid or not set';
  560. $result['data'] = null;
  561. }
  562. break;
  563. default:
  564. $result['status'] = 'error';
  565. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  566. break;
  567. }
  568. break;
  569. case 'v1_wizard_page':
  570. switch ($method) {
  571. case 'GET':
  572. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  573. $result['status'] = 'success';
  574. $result['statusText'] = 'success';
  575. $result['data'] = $pageWizard;
  576. } else {
  577. $result['status'] = 'error';
  578. $result['statusText'] = 'Wizard has already been run';
  579. $result['data'] = null;
  580. }
  581. break;
  582. default:
  583. $result['status'] = 'error';
  584. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  585. break;
  586. }
  587. break;
  588. case 'v1_dependencies_page':
  589. switch ($method) {
  590. case 'GET':
  591. $result['status'] = 'success';
  592. $result['statusText'] = 'success';
  593. $result['data'] = $pageDependencies;
  594. break;
  595. default:
  596. $result['status'] = 'error';
  597. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  598. break;
  599. }
  600. break;
  601. case 'v1_wizard_config':
  602. switch ($method) {
  603. case 'POST':
  604. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  605. $result['status'] = 'success';
  606. $result['statusText'] = 'success';
  607. $result['data'] = wizardConfig($_POST);
  608. } else {
  609. $result['status'] = 'error';
  610. $result['statusText'] = 'Wizard has already been run';
  611. $result['data'] = null;
  612. }
  613. break;
  614. default:
  615. $result['status'] = 'error';
  616. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  617. break;
  618. }
  619. break;
  620. case 'v1_wizard_path':
  621. switch ($method) {
  622. case 'POST':
  623. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  624. $result['status'] = 'success';
  625. $result['statusText'] = 'success';
  626. $result['data'] = wizardPath($_POST);
  627. } else {
  628. $result['status'] = 'error';
  629. $result['statusText'] = 'Wizard has already been run';
  630. $result['data'] = null;
  631. }
  632. break;
  633. default:
  634. $result['status'] = 'error';
  635. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  636. break;
  637. }
  638. break;
  639. case 'v1_login':
  640. switch ($method) {
  641. case 'POST':
  642. $result['status'] = 'success';
  643. $result['statusText'] = 'success';
  644. $result['data'] = login($_POST);
  645. break;
  646. default:
  647. $result['status'] = 'error';
  648. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  649. break;
  650. }
  651. break;
  652. case 'v1_register':
  653. switch ($method) {
  654. case 'POST':
  655. $result['status'] = 'success';
  656. $result['statusText'] = 'success';
  657. $result['data'] = register($_POST);
  658. break;
  659. default:
  660. $result['status'] = 'error';
  661. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  662. break;
  663. }
  664. break;
  665. case 'v1_recover':
  666. switch ($method) {
  667. case 'POST':
  668. $result['status'] = 'success';
  669. $result['statusText'] = 'success';
  670. $result['data'] = recover($_POST);
  671. break;
  672. default:
  673. $result['status'] = 'error';
  674. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  675. break;
  676. }
  677. break;
  678. case 'v1_unlock':
  679. switch ($method) {
  680. case 'POST':
  681. $result['status'] = 'success';
  682. $result['statusText'] = 'success';
  683. $result['data'] = unlock($_POST);
  684. break;
  685. default:
  686. $result['status'] = 'error';
  687. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  688. break;
  689. }
  690. break;
  691. case 'v1_lock':
  692. switch ($method) {
  693. case 'POST':
  694. $result['status'] = 'success';
  695. $result['statusText'] = 'success';
  696. $result['data'] = lock();
  697. break;
  698. default:
  699. $result['status'] = 'error';
  700. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  701. break;
  702. }
  703. break;
  704. case 'v1_test_iframe':
  705. switch ($method) {
  706. case 'POST':
  707. $result['status'] = 'success';
  708. $result['statusText'] = 'success';
  709. $result['data'] = frameTest($_POST['data']['url']);
  710. break;
  711. default:
  712. $result['status'] = 'error';
  713. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  714. break;
  715. }
  716. break;
  717. case 'v1_upgrade':
  718. case 'v1_update':
  719. case 'v1_force':
  720. switch ($method) {
  721. case 'POST':
  722. if (qualifyRequest(1)) {
  723. $result['status'] = 'success';
  724. $result['statusText'] = 'success';
  725. $result['data'] = upgradeInstall($_POST['data']['branch'], $_POST['data']['stage']);
  726. } else {
  727. $result['status'] = 'error';
  728. $result['statusText'] = 'API/Token invalid or not set';
  729. $result['data'] = null;
  730. }
  731. break;
  732. default:
  733. $result['status'] = 'error';
  734. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  735. break;
  736. }
  737. break;
  738. case 'v1_login_page':
  739. switch ($method) {
  740. case 'GET':
  741. $result['status'] = 'success';
  742. $result['statusText'] = 'success';
  743. $result['data'] = $pageLogin;
  744. break;
  745. default:
  746. $result['status'] = 'error';
  747. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  748. break;
  749. }
  750. break;
  751. case 'v1_lockscreen':
  752. switch ($method) {
  753. case 'GET':
  754. $result['status'] = 'success';
  755. $result['statusText'] = 'success';
  756. $result['data'] = $pageLockScreen;
  757. break;
  758. default:
  759. $result['status'] = 'error';
  760. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  761. break;
  762. }
  763. break;
  764. case 'v1_login_log':
  765. switch ($method) {
  766. case 'GET':
  767. if (qualifyRequest(1)) {
  768. $result['status'] = 'success';
  769. $result['statusText'] = 'success';
  770. $result['data'] = getLog('loginLog');
  771. } else {
  772. $result['status'] = 'error';
  773. $result['statusText'] = 'API/Token invalid or not set';
  774. $result['data'] = null;
  775. }
  776. break;
  777. default:
  778. $result['status'] = 'error';
  779. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  780. break;
  781. }
  782. break;
  783. case 'v1_organizr_log':
  784. switch ($method) {
  785. case 'GET':
  786. if (qualifyRequest(1)) {
  787. $result['status'] = 'success';
  788. $result['statusText'] = 'success';
  789. $result['data'] = getLog('org');
  790. } else {
  791. $result['status'] = 'error';
  792. $result['statusText'] = 'API/Token invalid or not set';
  793. $result['data'] = null;
  794. }
  795. break;
  796. default:
  797. $result['status'] = 'error';
  798. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  799. break;
  800. }
  801. break;
  802. case 'v1_user_list':
  803. switch ($method) {
  804. case 'GET':
  805. if (qualifyRequest(1)) {
  806. $result['status'] = 'success';
  807. $result['statusText'] = 'success';
  808. $result['data'] = allUsers();
  809. } else {
  810. $result['status'] = 'error';
  811. $result['statusText'] = 'API/Token invalid or not set';
  812. $result['data'] = null;
  813. }
  814. break;
  815. default:
  816. $result['status'] = 'error';
  817. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  818. break;
  819. }
  820. break;
  821. case 'v1_tab_list':
  822. switch ($method) {
  823. case 'GET':
  824. if (qualifyRequest(1)) {
  825. $result['status'] = 'success';
  826. $result['statusText'] = 'success';
  827. $result['data'] = allTabs();
  828. } else {
  829. $result['status'] = 'error';
  830. $result['statusText'] = 'API/Token invalid or not set';
  831. $result['data'] = null;
  832. }
  833. break;
  834. default:
  835. $result['status'] = 'error';
  836. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  837. break;
  838. }
  839. break;
  840. case 'v1_image_list':
  841. switch ($method) {
  842. case 'GET':
  843. if (qualifyRequest(1)) {
  844. $result['status'] = 'success';
  845. $result['statusText'] = 'success';
  846. $result['data'] = getImages();
  847. } else {
  848. $result['status'] = 'error';
  849. $result['statusText'] = 'API/Token invalid or not set';
  850. $result['data'] = null;
  851. }
  852. break;
  853. default:
  854. $result['status'] = 'error';
  855. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  856. break;
  857. }
  858. break;
  859. case 'v1_customize_appearance':
  860. switch ($method) {
  861. case 'GET':
  862. if (qualifyRequest(1)) {
  863. $result['status'] = 'success';
  864. $result['statusText'] = 'success';
  865. $result['data'] = getCustomizeAppearance();
  866. } else {
  867. $result['status'] = 'error';
  868. $result['statusText'] = 'API/Token invalid or not set';
  869. $result['data'] = null;
  870. }
  871. break;
  872. default:
  873. $result['status'] = 'error';
  874. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  875. break;
  876. }
  877. break;
  878. case 'v1_sso':
  879. switch ($method) {
  880. case 'GET':
  881. if (qualifyRequest(1)) {
  882. $result['status'] = 'success';
  883. $result['statusText'] = 'success';
  884. $result['data'] = getSSO();
  885. } else {
  886. $result['status'] = 'error';
  887. $result['statusText'] = 'API/Token invalid or not set';
  888. $result['data'] = null;
  889. }
  890. break;
  891. default:
  892. $result['status'] = 'error';
  893. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  894. break;
  895. }
  896. break;
  897. case 'v1_settings_main':
  898. switch ($method) {
  899. case 'GET':
  900. if (qualifyRequest(1)) {
  901. $result['status'] = 'success';
  902. $result['statusText'] = 'success';
  903. $result['data'] = getSettingsMain();
  904. } else {
  905. $result['status'] = 'error';
  906. $result['statusText'] = 'API/Token invalid or not set';
  907. $result['data'] = null;
  908. }
  909. break;
  910. default:
  911. $result['status'] = 'error';
  912. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  913. break;
  914. }
  915. break;
  916. case 'v1_plugin_install':
  917. switch ($method) {
  918. case 'POST':
  919. if (qualifyRequest(1)) {
  920. $result['status'] = 'success';
  921. $result['statusText'] = 'success';
  922. $result['data'] = installPlugin($_POST);
  923. } else {
  924. $result['status'] = 'error';
  925. $result['statusText'] = 'API/Token invalid or not set';
  926. $result['data'] = null;
  927. }
  928. break;
  929. default:
  930. $result['status'] = 'error';
  931. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  932. break;
  933. }
  934. break;
  935. case 'v1_plugin_remove':
  936. switch ($method) {
  937. case 'POST':
  938. if (qualifyRequest(1)) {
  939. $result['status'] = 'success';
  940. $result['statusText'] = 'success';
  941. $result['data'] = removePlugin($_POST);
  942. } else {
  943. $result['status'] = 'error';
  944. $result['statusText'] = 'API/Token invalid or not set';
  945. $result['data'] = null;
  946. }
  947. break;
  948. default:
  949. $result['status'] = 'error';
  950. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  951. break;
  952. }
  953. break;
  954. case 'v1_theme_install':
  955. switch ($method) {
  956. case 'POST':
  957. if (qualifyRequest(1)) {
  958. $result['status'] = 'success';
  959. $result['statusText'] = 'success';
  960. $result['data'] = installTheme($_POST);
  961. } else {
  962. $result['status'] = 'error';
  963. $result['statusText'] = 'API/Token invalid or not set';
  964. $result['data'] = null;
  965. }
  966. break;
  967. default:
  968. $result['status'] = 'error';
  969. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  970. break;
  971. }
  972. break;
  973. case 'v1_theme_remove':
  974. switch ($method) {
  975. case 'POST':
  976. if (qualifyRequest(1)) {
  977. $result['status'] = 'success';
  978. $result['statusText'] = 'success';
  979. $result['data'] = removeTheme($_POST);
  980. } else {
  981. $result['status'] = 'error';
  982. $result['statusText'] = 'API/Token invalid or not set';
  983. $result['data'] = null;
  984. }
  985. break;
  986. default:
  987. $result['status'] = 'error';
  988. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  989. break;
  990. }
  991. break;
  992. case 'v1_user_edit':
  993. switch ($method) {
  994. case 'POST':
  995. if (qualifyRequest(1)) {
  996. $result['status'] = 'success';
  997. $result['statusText'] = 'success';
  998. $result['data'] = adminEditUser($_POST);
  999. } elseif (qualifyRequest(998)) {
  1000. $result['status'] = 'success';
  1001. $result['statusText'] = 'success';
  1002. $result['data'] = editUser($_POST);
  1003. } else {
  1004. $result['status'] = 'error';
  1005. $result['statusText'] = 'API/Token invalid or not set';
  1006. $result['data'] = null;
  1007. }
  1008. break;
  1009. default:
  1010. $result['status'] = 'error';
  1011. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1012. break;
  1013. }
  1014. break;
  1015. case 'v1_2fa_create':
  1016. switch ($method) {
  1017. case 'POST':
  1018. if (qualifyRequest(998)) {
  1019. $result['status'] = 'success';
  1020. $result['statusText'] = 'success';
  1021. $result['data'] = create2FA($_POST['data']['type']);
  1022. } else {
  1023. $result['status'] = 'error';
  1024. $result['statusText'] = 'API/Token invalid or not set';
  1025. $result['data'] = null;
  1026. }
  1027. break;
  1028. default:
  1029. $result['status'] = 'error';
  1030. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1031. break;
  1032. }
  1033. break;
  1034. case 'v1_2fa_save':
  1035. switch ($method) {
  1036. case 'POST':
  1037. if (qualifyRequest(998)) {
  1038. $result['status'] = 'success';
  1039. $result['statusText'] = 'success';
  1040. $result['data'] = save2FA($_POST['data']['secret'], $_POST['data']['type']);
  1041. } else {
  1042. $result['status'] = 'error';
  1043. $result['statusText'] = 'API/Token invalid or not set';
  1044. $result['data'] = null;
  1045. }
  1046. break;
  1047. default:
  1048. $result['status'] = 'error';
  1049. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1050. break;
  1051. }
  1052. break;
  1053. case 'v1_2fa_verify':
  1054. switch ($method) {
  1055. case 'POST':
  1056. if (qualifyRequest(998)) {
  1057. $result['status'] = 'success';
  1058. $result['statusText'] = 'success';
  1059. $result['data'] = verify2FA($_POST['data']['secret'], $_POST['data']['code'], $_POST['data']['type']);
  1060. } else {
  1061. $result['status'] = 'error';
  1062. $result['statusText'] = 'API/Token invalid or not set';
  1063. $result['data'] = null;
  1064. }
  1065. break;
  1066. default:
  1067. $result['status'] = 'error';
  1068. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1069. break;
  1070. }
  1071. break;
  1072. case 'v1_2fa_remove':
  1073. switch ($method) {
  1074. case 'GET':
  1075. if (qualifyRequest(998)) {
  1076. $result['status'] = 'success';
  1077. $result['statusText'] = 'success';
  1078. $result['data'] = remove2FA();
  1079. } else {
  1080. $result['status'] = 'error';
  1081. $result['statusText'] = 'API/Token invalid or not set';
  1082. $result['data'] = null;
  1083. }
  1084. break;
  1085. default:
  1086. $result['status'] = 'error';
  1087. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1088. break;
  1089. }
  1090. break;
  1091. case 'v1_logout':
  1092. switch ($method) {
  1093. case 'GET':
  1094. $result['status'] = 'success';
  1095. $result['statusText'] = 'success';
  1096. $result['data'] = logout();
  1097. break;
  1098. default:
  1099. $result['status'] = 'error';
  1100. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1101. break;
  1102. }
  1103. break;
  1104. case 'v1_launch_organizr':
  1105. switch ($method) {
  1106. case 'GET':
  1107. $pluginSearch = '-enabled';
  1108. $pluginInclude = '-include';
  1109. $status = array();
  1110. $result['status'] = 'success';
  1111. $result['statusText'] = 'success';
  1112. $status['status'] = organizrStatus();
  1113. $result['appearance'] = loadAppearance();
  1114. $status['user'] = $GLOBALS['organizrUser'];
  1115. $status['categories'] = loadTabs()['categories'];
  1116. $status['tabs'] = loadTabs()['tabs'];
  1117. $status['plugins'] = array_filter($GLOBALS, function ($k) use ($pluginSearch) {
  1118. return stripos($k, $pluginSearch) !== false;
  1119. }, ARRAY_FILTER_USE_KEY);
  1120. $status['plugins']['includes'] = array_filter($GLOBALS, function ($k) use ($pluginInclude) {
  1121. return stripos($k, $pluginInclude) !== false;
  1122. }, ARRAY_FILTER_USE_KEY);
  1123. $result['data'] = $status;
  1124. $result['branch'] = $GLOBALS['branch'];
  1125. $result['theme'] = $GLOBALS['theme'];
  1126. $result['style'] = $GLOBALS['style'];
  1127. $result['version'] = $GLOBALS['installedVersion'];
  1128. $result['sso'] = array(
  1129. 'myPlexAccessToken' => isset($_COOKIE['mpt']) ? $_COOKIE['mpt'] : false,
  1130. 'id_token' => isset($_COOKIE['Auth']) ? $_COOKIE['Auth'] : false
  1131. );
  1132. $result['settings'] = organizrSpecialSettings();
  1133. break;
  1134. default:
  1135. $result['status'] = 'error';
  1136. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1137. break;
  1138. }
  1139. break;
  1140. case 'v1_auth':
  1141. switch ($method) {
  1142. case 'GET':
  1143. auth();
  1144. break;
  1145. default:
  1146. $result['status'] = 'error';
  1147. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1148. break;
  1149. }
  1150. break;
  1151. case 'v1_plugin':
  1152. switch ($method) {
  1153. case 'POST':
  1154. case 'GET':
  1155. // Include all plugin api Calls
  1156. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'plugins' . DIRECTORY_SEPARATOR . 'api' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  1157. require_once $filename;
  1158. }
  1159. break;
  1160. default:
  1161. $result['status'] = 'error';
  1162. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1163. break;
  1164. }
  1165. break;
  1166. case 'v1_image':
  1167. switch ($method) {
  1168. case 'GET':
  1169. getImage();
  1170. break;
  1171. default:
  1172. $result['status'] = 'error';
  1173. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1174. break;
  1175. }
  1176. break;
  1177. case 'v1_downloader':
  1178. switch ($method) {
  1179. case 'POST':
  1180. $result['status'] = 'success';
  1181. $result['statusText'] = 'success';
  1182. $result['data'] = downloader($_POST);
  1183. break;
  1184. default:
  1185. $result['status'] = 'error';
  1186. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1187. break;
  1188. }
  1189. break;
  1190. case 'v1_import_users':
  1191. switch ($method) {
  1192. case 'POST':
  1193. if (qualifyRequest(1)) {
  1194. $result['status'] = 'success';
  1195. $result['statusText'] = 'success';
  1196. $result['data'] = importUsersType($_POST);
  1197. } else {
  1198. $result['status'] = 'error';
  1199. $result['statusText'] = 'API/Token invalid or not set';
  1200. $result['data'] = null;
  1201. }
  1202. break;
  1203. default:
  1204. $result['status'] = 'error';
  1205. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1206. break;
  1207. }
  1208. break;
  1209. case 'v1_ombi':
  1210. switch ($method) {
  1211. case 'POST':
  1212. $result['status'] = 'success';
  1213. $result['statusText'] = 'success';
  1214. $result['data'] = ombiAPI($_POST);
  1215. break;
  1216. default:
  1217. $result['status'] = 'error';
  1218. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1219. break;
  1220. }
  1221. break;
  1222. case 'v1_plex_join':
  1223. switch ($method) {
  1224. case 'POST':
  1225. $result['status'] = 'success';
  1226. $result['statusText'] = 'success';
  1227. $result['data'] = plexJoinAPI($_POST);
  1228. break;
  1229. default:
  1230. $result['status'] = 'error';
  1231. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1232. break;
  1233. }
  1234. break;
  1235. case 'v1_emby_join':
  1236. switch ($method) {
  1237. case 'POST':
  1238. $result['status'] = 'success';
  1239. $result['statusText'] = 'success';
  1240. $result['data'] = embyJoinAPI($_POST);
  1241. break;
  1242. default:
  1243. $result['status'] = 'error';
  1244. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1245. break;
  1246. }
  1247. break;
  1248. case 'v1_token_revoke':
  1249. switch ($method) {
  1250. case 'POST':
  1251. $result['status'] = 'success';
  1252. $result['statusText'] = 'success';
  1253. $result['data'] = revokeToken($_POST);
  1254. break;
  1255. default:
  1256. $result['status'] = 'error';
  1257. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1258. break;
  1259. }
  1260. break;
  1261. case 'v1_update_db_manual':
  1262. switch ($method) {
  1263. case 'GET':
  1264. if (qualifyRequest(1)) {
  1265. $result['status'] = 'success';
  1266. $result['statusText'] = 'success';
  1267. $result['data'] = updateDB($GLOBALS['installedVersion']);
  1268. } else {
  1269. $result['status'] = 'error';
  1270. $result['statusText'] = 'API/Token invalid or not set';
  1271. $result['data'] = null;
  1272. }
  1273. break;
  1274. default:
  1275. $result['status'] = 'error';
  1276. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1277. break;
  1278. }
  1279. break;
  1280. case 'v1_version':
  1281. switch ($method) {
  1282. case 'GET':
  1283. $result['status'] = 'success';
  1284. $result['statusText'] = 'success';
  1285. $result['data'] = $GLOBALS['installedVersion'];
  1286. break;
  1287. default:
  1288. $result['status'] = 'error';
  1289. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1290. break;
  1291. }
  1292. break;
  1293. case 'v1_ping':
  1294. switch ($method) {
  1295. case 'GET':
  1296. $result['status'] = 'success';
  1297. $result['statusText'] = 'success';
  1298. $result['data'] = 'pong';
  1299. break;
  1300. default:
  1301. $result['status'] = 'error';
  1302. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1303. break;
  1304. }
  1305. break;
  1306. case 'v1_docker_update':
  1307. switch ($method) {
  1308. case 'GET':
  1309. if (qualifyRequest(1)) {
  1310. $result['status'] = 'success';
  1311. $result['statusText'] = 'success';
  1312. $result['data'] = dockerUpdate();
  1313. } else {
  1314. $result['status'] = 'error';
  1315. $result['statusText'] = 'API/Token invalid or not set';
  1316. $result['data'] = null;
  1317. }
  1318. break;
  1319. default:
  1320. $result['status'] = 'error';
  1321. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1322. break;
  1323. }
  1324. break;
  1325. case 'v1_windows_update':
  1326. switch ($method) {
  1327. case 'GET':
  1328. if (qualifyRequest(1)) {
  1329. $result['status'] = 'success';
  1330. $result['statusText'] = 'success';
  1331. $result['data'] = windowsUpdate();
  1332. } else {
  1333. $result['status'] = 'error';
  1334. $result['statusText'] = 'API/Token invalid or not set';
  1335. $result['data'] = null;
  1336. }
  1337. break;
  1338. default:
  1339. $result['status'] = 'error';
  1340. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1341. break;
  1342. }
  1343. break;
  1344. default:
  1345. //No Function Available
  1346. $result['status'] = 'error';
  1347. $result['statusText'] = 'function requested is not defined';
  1348. break;
  1349. }
  1350. //Set Default Result
  1351. if (!$result) {
  1352. $result['status'] = "error";
  1353. $result['error'] = "An error has occurred";
  1354. }
  1355. $result['generationDate'] = $GLOBALS['currentTime'];
  1356. $result['generationTime'] = formatSeconds(timeExecution());
  1357. //return JSON array
  1358. if ($pretty) {
  1359. echo '<pre>' . safe_json_encode($result, JSON_PRETTY_PRINT) . '</pre>';
  1360. } else {
  1361. exit(safe_json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));
  1362. }