api-functions.php 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949
  1. <?php
  2. function login($array){
  3. // Grab username and Password from login form
  4. foreach ($array['data'] as $items) {
  5. foreach ($items as $key => $value) {
  6. if($key == 'name'){
  7. $newKey = $value;
  8. }
  9. if($key == 'value'){
  10. $newValue = $value;
  11. }
  12. if(isset($newKey) && isset($newValue)){
  13. $$newKey = $newValue;
  14. }
  15. }
  16. }
  17. $username = strtolower($username);
  18. $days = (isset($remember)) ? 7 : 1;
  19. try {
  20. $database = new Dibi\Connection([
  21. 'driver' => 'sqlite3',
  22. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  23. ]);
  24. $authSuccess = false;
  25. $function = 'plugin_auth_'.$GLOBALS['authBackend'];
  26. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$username);
  27. switch ($GLOBALS['authType']) {
  28. case 'external':
  29. if (function_exists($function)) {
  30. $authSuccess = $function($username, $password);
  31. }
  32. break;
  33. case 'both':
  34. if (function_exists($function)) {
  35. $authSuccess = $function($username, $password);
  36. }
  37. default: // Internal
  38. if (!$authSuccess) {
  39. // perform the internal authentication step
  40. if(password_verify($password, $result['password'])){
  41. $authSuccess = true;
  42. }
  43. }
  44. }
  45. if ($authSuccess) {
  46. // Make sure user exists in database
  47. $userExists = false;
  48. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  49. if($result['username']){
  50. $userExists = true;
  51. $username = $result['username'];
  52. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  53. }
  54. if ($userExists) {
  55. //does org password need to be updated
  56. if(!$passwordMatches){
  57. $database->query('
  58. UPDATE users SET', [
  59. 'password' => password_hash($password, PASSWORD_BCRYPT)
  60. ], '
  61. WHERE id=?', $result['id']);
  62. writeLog('success', 'Login Function - User Password updated from backend', $username);
  63. }
  64. // authentication passed - 1) mark active and update token
  65. if(createToken($result['username'],$result['email'],$result['image'],$result['group'],$result['group_id'],$GLOBALS['organizrHash'],$days)){
  66. writeLoginLog($username, 'success');
  67. writeLog('success', 'Login Function - A User has logged in', $username);
  68. ssoCheck($username, $password, $token); //need to work on this
  69. return true;
  70. }else{
  71. return 'error';
  72. }
  73. } else {
  74. // Create User
  75. ssoCheck($username, $password, $token);
  76. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username),$password,'',(is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  77. }
  78. } else {
  79. // authentication failed
  80. writeLoginLog($username, 'error');
  81. writeLog('error', 'Login Function - Wrong Password', $username);
  82. return 'mismatch';
  83. }
  84. } catch (Dibi\Exception $e) {
  85. return 'error';
  86. }
  87. }
  88. function createDB($path,$filename) {
  89. try {
  90. $createDB = new Dibi\Connection([
  91. 'driver' => 'sqlite3',
  92. 'database' => $path.$filename,
  93. ]);
  94. // Create Users
  95. $users = $createDB->query('CREATE TABLE `users` (
  96. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  97. `username` TEXT UNIQUE,
  98. `password` TEXT,
  99. `email` TEXT,
  100. `plex_token` TEXT,
  101. `group` TEXT,
  102. `group_id` INTEGER,
  103. `locked` INTEGER,
  104. `image` TEXT,
  105. `register_date` DATE,
  106. `auth_service` TEXT DEFAULT \'internal\'
  107. );');
  108. // Create Tokens
  109. $jwt = $createDB->query('CREATE TABLE `tokens` (
  110. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  111. `token` TEXT UNIQUE,
  112. `user_id` INTEGER,
  113. `created` DATE,
  114. `expires` DATE
  115. );');
  116. $groups = $createDB->query('CREATE TABLE `groups` (
  117. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  118. `group` TEXT UNIQUE,
  119. `group_id` INTEGER,
  120. `image` TEXT,
  121. `default` INTEGER
  122. );');
  123. $categories = $createDB->query('CREATE TABLE `categories` (
  124. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  125. `order` INTEGER,
  126. `category` TEXT UNIQUE,
  127. `category_id` INTEGER,
  128. `image` TEXT,
  129. `default` INTEGER
  130. );');
  131. // Create Tabs
  132. $tabs = $createDB->query('CREATE TABLE `tabs` (
  133. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  134. `order` INTEGER,
  135. `category_id` INTEGER,
  136. `name` TEXT,
  137. `url` TEXT,
  138. `url_local` TEXT,
  139. `default` INTEGER,
  140. `enabled` INTEGER,
  141. `group_id` INTEGER,
  142. `image` TEXT,
  143. `type` INTEGER,
  144. `splash` INTEGER,
  145. `ping` INTEGER,
  146. `ping_url` TEXT
  147. );');
  148. // Create Options
  149. $options = $createDB->query('CREATE TABLE `options` (
  150. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  151. `name` TEXT UNIQUE,
  152. `value` TEXT
  153. );');
  154. // Create Invites
  155. $invites = $createDB->query('CREATE TABLE `invites` (
  156. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  157. `code` TEXT UNIQUE,
  158. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  159. `email` TEXT,
  160. `username` TEXT,
  161. `dateused` TIMESTAMP,
  162. `usedby` TEXT,
  163. `ip` TEXT,
  164. `valid` TEXT,
  165. `type` TEXT
  166. );');
  167. return true;
  168. } catch (Dibi\Exception $e) {
  169. return false;
  170. }
  171. }
  172. // Upgrade Database
  173. function updateDB($path,$filename,$oldVerNum = false) {
  174. try {
  175. $connect = new Dibi\Connection([
  176. 'driver' => 'sqlite3',
  177. 'database' => $path.$filename,
  178. ]);
  179. // Cache current DB
  180. $cache = array();
  181. foreach($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  182. foreach($connect->query('SELECT * FROM '.$table['name'].';') as $key => $row) {
  183. foreach($row as $k => $v) {
  184. if (is_string($k)) {
  185. $cache[$table['name']][$key][$k] = $v;
  186. }
  187. }
  188. }
  189. }
  190. $connect->disconnect();
  191. } catch (Dibi\Exception $e) {
  192. return $e;
  193. }
  194. // Remove Current Database
  195. $pathDigest = pathinfo($path.$filename);
  196. if (file_exists($path.$filename)) {
  197. copy($path.$filename, $pathDigest['dirname'].'/'.$pathDigest['filename'].'['.date('Y-m-d_H-i-s').']'.($oldVerNum?'['.$oldVerNum.']':'').'.bak.db');
  198. unlink($path.$filename);
  199. }
  200. // Create New Database
  201. $success = createDB($path,$filename);
  202. try {
  203. $GLOBALS['connect'] = new Dibi\Connection([
  204. 'driver' => 'sqlite3',
  205. 'database' => $path.$filename,
  206. ]);
  207. // Restore Items
  208. if ($success) {
  209. foreach($cache as $table => $tableData) {
  210. if ($tableData) {
  211. $queryBase = 'INSERT INTO '.$table.' (`'.implode('`,`',array_keys(current($tableData))).'`) values ';
  212. $insertValues = array();
  213. reset($tableData);
  214. foreach($tableData as $key => $value) {
  215. $insertValues[] = '('.implode(',',array_map(function($d) {
  216. return (isset($d)?str_replace('\/', '/',json_encode($d)):'null');
  217. }, $value)).')';
  218. }
  219. $GLOBALS['connect']->query($queryBase.implode(',',$insertValues).';');
  220. }
  221. }
  222. }
  223. return true;
  224. } catch (Dibi\Exception $e) {
  225. return $e;
  226. }
  227. }
  228. function createFirstAdmin($path,$filename,$username,$password,$email) {
  229. try {
  230. $createDB = new Dibi\Connection([
  231. 'driver' => 'sqlite3',
  232. 'database' => $path.$filename,
  233. ]);
  234. $userInfo = [
  235. 'username' => $username,
  236. 'password' => password_hash($password, PASSWORD_BCRYPT),
  237. 'email' => $email,
  238. 'group' => 'Admin',
  239. 'group_id' => 0,
  240. 'image' => gravatar($email),
  241. 'register_date' => $GLOBALS['currentTime'],
  242. ];
  243. $groupInfo0 = [
  244. 'group' => 'Admin',
  245. 'group_id' => 0,
  246. 'default' => false,
  247. 'image' => 'plugins/images/groups/admin.png',
  248. ];
  249. $groupInfo1 = [
  250. 'group' => 'Co-Admin',
  251. 'group_id' => 1,
  252. 'default' => false,
  253. 'image' => 'plugins/images/groups/coadmin.png',
  254. ];
  255. $groupInfo2 = [
  256. 'group' => 'Super User',
  257. 'group_id' => 2,
  258. 'default' => false,
  259. 'image' => 'plugins/images/groups/superuser.png',
  260. ];
  261. $groupInfo3 = [
  262. 'group' => 'Power User',
  263. 'group_id' => 3,
  264. 'default' => false,
  265. 'image' => 'plugins/images/groups/poweruser.png',
  266. ];
  267. $groupInfo4 = [
  268. 'group' => 'User',
  269. 'group_id' => 4,
  270. 'default' => true,
  271. 'image' => 'plugins/images/groups/user.png',
  272. ];
  273. $groupInfoGuest = [
  274. 'group' => 'Guest',
  275. 'group_id' => 999,
  276. 'default' => false,
  277. 'image' => 'plugins/images/groups/guest.png',
  278. ];
  279. $settingsInfo = [
  280. 'order' => 1,
  281. 'category_id' => 0,
  282. 'name' => 'Settings',
  283. 'url' => 'api/?v1/settings/page',
  284. 'default' => false,
  285. 'enabled' => true,
  286. 'group_id' => 1,
  287. 'image' => 'fontawesome::cog',
  288. 'type' => 0
  289. ];
  290. $homepageInfo = [
  291. 'order' => 2,
  292. 'category_id' => 0,
  293. 'name' => 'Homepage',
  294. 'url' => 'api/?v1/homepage/page',
  295. 'default' => false,
  296. 'enabled' => false,
  297. 'group_id' => 4,
  298. 'image' => 'fontawesome::home',
  299. 'type' => 0
  300. ];
  301. $unsortedInfo = [
  302. 'order' => 1,
  303. 'category' => 'Unsorted',
  304. 'category_id' => 0,
  305. 'image' => 'plugins/images/categories/unsorted.png',
  306. 'default' => true
  307. ];
  308. $createDB->query('INSERT INTO [users]', $userInfo);
  309. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  310. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  311. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  312. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  313. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  314. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  315. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  316. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  317. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  318. return true;
  319. } catch (Dibi\Exception $e) {
  320. writeLog('error', 'Wizard Function - Error ['.$e.']', 'Wizard');
  321. return false;
  322. }
  323. }
  324. function defaultUserGroup(){
  325. try {
  326. $connect = new Dibi\Connection([
  327. 'driver' => 'sqlite3',
  328. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  329. ]);
  330. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  331. return $all;
  332. } catch (Dibi\Exception $e) {
  333. return false;
  334. }
  335. }
  336. function defaulTabCategory(){
  337. try {
  338. $connect = new Dibi\Connection([
  339. 'driver' => 'sqlite3',
  340. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  341. ]);
  342. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  343. return $all;
  344. } catch (Dibi\Exception $e) {
  345. return false;
  346. }
  347. }
  348. function getGuest(){
  349. if(isset($GLOBALS['dbLocation'])){
  350. try {
  351. $connect = new Dibi\Connection([
  352. 'driver' => 'sqlite3',
  353. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  354. ]);
  355. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  356. return $all;
  357. } catch (Dibi\Exception $e) {
  358. return false;
  359. }
  360. }else{
  361. return array(
  362. 'group' => 'Guest',
  363. 'group_id' => 999,
  364. 'image' => 'plugins/images/groups/guest.png'
  365. );
  366. }
  367. }
  368. function adminEditGroup($array){
  369. switch ($array['data']['action']) {
  370. case 'changeDefaultGroup':
  371. try {
  372. $connect = new Dibi\Connection([
  373. 'driver' => 'sqlite3',
  374. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  375. ]);
  376. $connect->query('UPDATE groups SET `default` = 0');
  377. $connect->query('
  378. UPDATE groups SET', [
  379. 'default' => 1
  380. ], '
  381. WHERE id=?', $array['data']['id']);
  382. writeLog('success', 'Group Management Function - Changed Default Group from ['.$array['data']['oldGroupName'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  383. return true;
  384. } catch (Dibi\Exception $e) {
  385. return false;
  386. }
  387. break;
  388. case 'deleteUserGroup':
  389. try {
  390. $connect = new Dibi\Connection([
  391. 'driver' => 'sqlite3',
  392. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  393. ]);
  394. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  395. writeLog('success', 'Group Management Function - Deleted Group ['.$array['data']['groupName'].']', $GLOBALS['organizrUser']['username']);
  396. return true;
  397. } catch (Dibi\Exception $e) {
  398. return false;
  399. }
  400. break;
  401. case 'addUserGroup':
  402. try {
  403. $connect = new Dibi\Connection([
  404. 'driver' => 'sqlite3',
  405. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  406. ]);
  407. $newGroup = [
  408. 'group' => $array['data']['newGroupName'],
  409. 'group_id' => $array['data']['newGroupID'],
  410. 'default' => false,
  411. 'image' => $array['data']['newGroupImage'],
  412. ];
  413. $connect->query('INSERT INTO [groups]', $newGroup);
  414. writeLog('success', 'Group Management Function - Added Group ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  415. return true;
  416. } catch (Dibi\Exception $e) {
  417. return false;
  418. }
  419. break;
  420. case 'editUserGroup':
  421. try {
  422. $connect = new Dibi\Connection([
  423. 'driver' => 'sqlite3',
  424. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  425. ]);
  426. $connect->query('
  427. UPDATE groups SET', [
  428. 'group' => $array['data']['groupName'],
  429. 'image' => $array['data']['groupImage'],
  430. ], '
  431. WHERE id=?', $array['data']['id']);
  432. writeLog('success', 'Group Management Function - Edited Group Info for ['.$array['data']['oldGroupName'].']', $GLOBALS['organizrUser']['username']);
  433. return true;
  434. } catch (Dibi\Exception $e) {
  435. return false;
  436. }
  437. break;
  438. default:
  439. # code...
  440. break;
  441. }
  442. }
  443. function adminEditUser($array){
  444. switch ($array['data']['action']) {
  445. case 'changeGroup':
  446. try {
  447. $connect = new Dibi\Connection([
  448. 'driver' => 'sqlite3',
  449. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  450. ]);
  451. $connect->query('
  452. UPDATE users SET', [
  453. 'group' => $array['data']['newGroupName'],
  454. 'group_id' => $array['data']['newGroupID'],
  455. ], '
  456. WHERE id=?', $array['data']['id']);
  457. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  458. return true;
  459. } catch (Dibi\Exception $e) {
  460. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  461. return false;
  462. }
  463. break;
  464. case 'editUser':
  465. try {
  466. $connect = new Dibi\Connection([
  467. 'driver' => 'sqlite3',
  468. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  469. ]);
  470. if(!usernameTakenExcept($array['data']['username'],$array['data']['email'],$array['data']['id'])){
  471. $connect->query('
  472. UPDATE users SET', [
  473. 'username' => $array['data']['username'],
  474. 'email' => $array['data']['email'],
  475. ], '
  476. WHERE id=?', $array['data']['id']);
  477. if(!empty($array['data']['password'])){
  478. $connect->query('
  479. UPDATE users SET', [
  480. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  481. ], '
  482. WHERE id=?', $array['data']['id']);
  483. }
  484. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s info was changed', $GLOBALS['organizrUser']['username']);
  485. return true;
  486. }else{
  487. return false;
  488. }
  489. } catch (Dibi\Exception $e) {
  490. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  491. return false;
  492. }
  493. break;
  494. case 'addNewUser':
  495. $defaults = defaultUserGroup();
  496. if(createUser($array['data']['username'],$array['data']['password'],$defaults,$array['data']['email'])){
  497. writeLog('success', 'Create User Function - Acount created for ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  498. return true;
  499. }else{
  500. writeLog('error', 'Registration Function - An error occured', $GLOBALS['organizrUser']['username']);
  501. return 'username taken';
  502. }
  503. break;
  504. case 'deleteUser':
  505. try {
  506. $connect = new Dibi\Connection([
  507. 'driver' => 'sqlite3',
  508. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  509. ]);
  510. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  511. writeLog('success', 'User Management Function - Deleted User ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  512. return true;
  513. } catch (Dibi\Exception $e) {
  514. return false;
  515. }
  516. break;
  517. default:
  518. # code...
  519. break;
  520. }
  521. }
  522. function editTabs($array){
  523. switch ($array['data']['action']) {
  524. case 'changeGroup':
  525. try {
  526. $connect = new Dibi\Connection([
  527. 'driver' => 'sqlite3',
  528. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  529. ]);
  530. $connect->query('
  531. UPDATE tabs SET', [
  532. 'group_id' => $array['data']['newGroupID'],
  533. ], '
  534. WHERE id=?', $array['data']['id']);
  535. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s group was changed to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  536. return true;
  537. } catch (Dibi\Exception $e) {
  538. return false;
  539. }
  540. break;
  541. case 'changeCategory':
  542. try {
  543. $connect = new Dibi\Connection([
  544. 'driver' => 'sqlite3',
  545. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  546. ]);
  547. $connect->query('
  548. UPDATE tabs SET', [
  549. 'category_id' => $array['data']['newCategoryID'],
  550. ], '
  551. WHERE id=?', $array['data']['id']);
  552. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s category was changed to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  553. return true;
  554. } catch (Dibi\Exception $e) {
  555. return false;
  556. }
  557. break;
  558. case 'changeType':
  559. try {
  560. $connect = new Dibi\Connection([
  561. 'driver' => 'sqlite3',
  562. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  563. ]);
  564. $connect->query('
  565. UPDATE tabs SET', [
  566. 'type' => $array['data']['newTypeID'],
  567. ], '
  568. WHERE id=?', $array['data']['id']);
  569. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s type was changed to ['.$array['data']['newTypeName'].']', $GLOBALS['organizrUser']['username']);
  570. return true;
  571. } catch (Dibi\Exception $e) {
  572. return false;
  573. }
  574. break;
  575. case 'changeEnabled':
  576. try {
  577. $connect = new Dibi\Connection([
  578. 'driver' => 'sqlite3',
  579. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  580. ]);
  581. $connect->query('
  582. UPDATE tabs SET', [
  583. 'enabled' => $array['data']['tabEnabled'],
  584. ], '
  585. WHERE id=?', $array['data']['id']);
  586. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s enable status was changed to ['.$array['data']['tabEnabledWord'].']', $GLOBALS['organizrUser']['username']);
  587. return true;
  588. } catch (Dibi\Exception $e) {
  589. return false;
  590. }
  591. break;
  592. case 'changeSplash':
  593. try {
  594. $connect = new Dibi\Connection([
  595. 'driver' => 'sqlite3',
  596. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  597. ]);
  598. $connect->query('
  599. UPDATE tabs SET', [
  600. 'splash' => $array['data']['tabSplash'],
  601. ], '
  602. WHERE id=?', $array['data']['id']);
  603. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s splash status was changed to ['.$array['data']['tabSplashWord'].']', $GLOBALS['organizrUser']['username']);
  604. return true;
  605. } catch (Dibi\Exception $e) {
  606. return false;
  607. }
  608. break;
  609. case 'changeDefault':
  610. try {
  611. $connect = new Dibi\Connection([
  612. 'driver' => 'sqlite3',
  613. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  614. ]);
  615. $connect->query('UPDATE tabs SET `default` = 0');
  616. $connect->query('
  617. UPDATE tabs SET', [
  618. 'default' => 1
  619. ], '
  620. WHERE id=?', $array['data']['id']);
  621. writeLog('success', 'Tab Editor Function - Changed Default Tab to ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  622. return true;
  623. } catch (Dibi\Exception $e) {
  624. return false;
  625. }
  626. break;
  627. case 'deleteTab':
  628. try {
  629. $connect = new Dibi\Connection([
  630. 'driver' => 'sqlite3',
  631. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  632. ]);
  633. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  634. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  635. return true;
  636. } catch (Dibi\Exception $e) {
  637. return false;
  638. }
  639. break;
  640. case 'editTab':
  641. try {
  642. $connect = new Dibi\Connection([
  643. 'driver' => 'sqlite3',
  644. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  645. ]);
  646. $connect->query('
  647. UPDATE tabs SET', [
  648. 'name' => $array['data']['tabName'],
  649. 'url' => $array['data']['tabURL'],
  650. 'image' => $array['data']['tabImage'],
  651. ], '
  652. WHERE id=?', $array['data']['id']);
  653. writeLog('success', 'Tab Editor Function - Edited Tab Info for ['.$array['data']['tabName'].']', $GLOBALS['organizrUser']['username']);
  654. return true;
  655. } catch (Dibi\Exception $e) {
  656. return false;
  657. }
  658. case 'changeOrder':
  659. try {
  660. $connect = new Dibi\Connection([
  661. 'driver' => 'sqlite3',
  662. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  663. ]);
  664. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  665. if($value['order'] != $value['originalOrder']){
  666. $connect->query('
  667. UPDATE tabs SET', [
  668. 'order' => $value['order'],
  669. ], '
  670. WHERE id=?', $value['id']);
  671. writeLog('success', 'Tab Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  672. }
  673. }
  674. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  675. return true;
  676. } catch (Dibi\Exception $e) {
  677. return false;
  678. }
  679. break;
  680. case 'addNewTab':
  681. try {
  682. $default = defaulTabCategory()['category_id'];
  683. $connect = new Dibi\Connection([
  684. 'driver' => 'sqlite3',
  685. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  686. ]);
  687. $newTab = [
  688. 'order' => $array['data']['tabOrder'],
  689. 'category_id' => $default,
  690. 'name' => $array['data']['tabName'],
  691. 'url' => $array['data']['tabURL'],
  692. 'default' => $array['data']['tabDefault'],
  693. 'enabled' => 1,
  694. 'group_id' => $array['data']['tabGroupID'],
  695. 'image' => $array['data']['tabImage'],
  696. 'type' => $array['data']['tabType']
  697. ];
  698. $connect->query('INSERT INTO [tabs]', $newTab);
  699. writeLog('success', 'Tab Editor Function - Created Tab for: '.$array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  700. return true;
  701. } catch (Dibi\Exception $e) {
  702. return false;
  703. }
  704. break;
  705. case 'deleteTab':
  706. try {
  707. $connect = new Dibi\Connection([
  708. 'driver' => 'sqlite3',
  709. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  710. ]);
  711. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  712. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  713. return true;
  714. } catch (Dibi\Exception $e) {
  715. return false;
  716. }
  717. break;
  718. default:
  719. # code...
  720. break;
  721. }
  722. }
  723. function editCategories($array){
  724. switch ($array['data']['action']) {
  725. case 'changeDefault':
  726. try {
  727. $connect = new Dibi\Connection([
  728. 'driver' => 'sqlite3',
  729. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  730. ]);
  731. $connect->query('UPDATE categories SET `default` = 0');
  732. $connect->query('
  733. UPDATE categories SET', [
  734. 'default' => 1
  735. ], '
  736. WHERE id=?', $array['data']['id']);
  737. writeLog('success', 'Category Editor Function - Changed Default Category from ['.$array['data']['oldCategoryName'].'] to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  738. return true;
  739. } catch (Dibi\Exception $e) {
  740. return false;
  741. }
  742. break;
  743. case 'deleteCategory':
  744. try {
  745. $connect = new Dibi\Connection([
  746. 'driver' => 'sqlite3',
  747. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  748. ]);
  749. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  750. writeLog('success', 'Category Editor Function - Deleted Category ['.$array['data']['category'].']', $GLOBALS['organizrUser']['username']);
  751. return true;
  752. } catch (Dibi\Exception $e) {
  753. return false;
  754. }
  755. break;
  756. case 'addNewCategory':
  757. try {
  758. $connect = new Dibi\Connection([
  759. 'driver' => 'sqlite3',
  760. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  761. ]);
  762. $newCategory = [
  763. 'category' => $array['data']['categoryName'],
  764. 'order' => $array['data']['categoryOrder'],
  765. 'category_id' => $array['data']['categoryID'],
  766. 'default' => false,
  767. 'image' => $array['data']['categoryImage'],
  768. ];
  769. $connect->query('INSERT INTO [categories]', $newCategory);
  770. writeLog('success', 'Category Editor Function - Added Category ['.$array['data']['categoryName'].']', $GLOBALS['organizrUser']['username']);
  771. return true;
  772. } catch (Dibi\Exception $e) {
  773. return $e;
  774. }
  775. break;
  776. case 'editCategory':
  777. try {
  778. $connect = new Dibi\Connection([
  779. 'driver' => 'sqlite3',
  780. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  781. ]);
  782. $connect->query('
  783. UPDATE categories SET', [
  784. 'category' => $array['data']['name'],
  785. 'image' => $array['data']['image'],
  786. ], '
  787. WHERE id=?', $array['data']['id']);
  788. writeLog('success', 'Category Editor Function - Edited Category Info for ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  789. return true;
  790. } catch (Dibi\Exception $e) {
  791. return false;
  792. }
  793. break;
  794. case 'changeOrder':
  795. try {
  796. $connect = new Dibi\Connection([
  797. 'driver' => 'sqlite3',
  798. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  799. ]);
  800. foreach ($array['data']['categories']['category'] as $key => $value) {
  801. if($value['order'] != $value['originalOrder']){
  802. $connect->query('
  803. UPDATE categories SET', [
  804. 'order' => $value['order'],
  805. ], '
  806. WHERE id=?', $value['id']);
  807. writeLog('success', 'Category Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  808. }
  809. }
  810. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  811. return true;
  812. } catch (Dibi\Exception $e) {
  813. return false;
  814. }
  815. break;
  816. default:
  817. # code...
  818. break;
  819. }
  820. }
  821. function allUsers(){
  822. try {
  823. $connect = new Dibi\Connection([
  824. 'driver' => 'sqlite3',
  825. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  826. ]);
  827. $users = $connect->fetchAll('SELECT * FROM users');
  828. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  829. foreach ($users as $k => $v) {
  830. // clear password from array
  831. unset($users[$k]['password']);
  832. }
  833. $all['users'] = $users;
  834. $all['groups'] = $groups;
  835. return $all;
  836. } catch (Dibi\Exception $e) {
  837. return false;
  838. }
  839. }
  840. function usernameTaken($username,$email){
  841. try {
  842. $connect = new Dibi\Connection([
  843. 'driver' => 'sqlite3',
  844. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  845. ]);
  846. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$email);
  847. return ($all) ? true : false;
  848. } catch (Dibi\Exception $e) {
  849. return false;
  850. }
  851. }
  852. function usernameTakenExcept($username,$email,$id){
  853. try {
  854. $connect = new Dibi\Connection([
  855. 'driver' => 'sqlite3',
  856. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  857. ]);
  858. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE',$id,$username,$id,$email);
  859. return ($all) ? true : false;
  860. } catch (Dibi\Exception $e) {
  861. return false;
  862. }
  863. }
  864. function createUser($username,$password,$defaults,$email=null) {
  865. $email = ($email) ? $email : random_ascii_string(10).'@placeholder.eml';
  866. try {
  867. if(!usernameTaken($username,$email)){
  868. $createDB = new Dibi\Connection([
  869. 'driver' => 'sqlite3',
  870. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  871. ]);
  872. $userInfo = [
  873. 'username' => $username,
  874. 'password' => password_hash($password, PASSWORD_BCRYPT),
  875. 'email' => $email,
  876. 'group' => $defaults['group'],
  877. 'group_id' => $defaults['group_id'],
  878. 'image' => gravatar($email),
  879. 'register_date' => $GLOBALS['currentTime'],
  880. ];
  881. $createDB->query('INSERT INTO [users]', $userInfo);
  882. return true;
  883. }else{
  884. return false;
  885. }
  886. } catch (Dibi\Exception $e) {
  887. return false;
  888. }
  889. }
  890. function allTabs(){
  891. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  892. try {
  893. $connect = new Dibi\Connection([
  894. 'driver' => 'sqlite3',
  895. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  896. ]);
  897. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  898. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  899. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  900. return $all;
  901. } catch (Dibi\Exception $e) {
  902. return false;
  903. }
  904. }
  905. }
  906. function allGroups(){
  907. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  908. try {
  909. $connect = new Dibi\Connection([
  910. 'driver' => 'sqlite3',
  911. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  912. ]);
  913. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  914. return $all;
  915. } catch (Dibi\Exception $e) {
  916. return false;
  917. }
  918. }
  919. }
  920. function loadTabs(){
  921. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  922. try {
  923. $connect = new Dibi\Connection([
  924. 'driver' => 'sqlite3',
  925. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  926. ]);
  927. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` DESC',$GLOBALS['organizrUser']['groupID']);
  928. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  929. $all['tabs'] = $tabs;
  930. foreach ($tabs as $k => $v) {
  931. $v['access_url'] = isset($v['url_local']) && $_SERVER['SERVER_ADDR'] == userIP() ? $v['url_local'] : $v['url'];
  932. }
  933. $count = array_map(function($element){
  934. return $element['category_id'];
  935. }, $tabs);
  936. $count = (array_count_values($count));
  937. foreach ($categories as $k => $v) {
  938. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  939. }
  940. $all['categories'] = $categories;
  941. return $all;
  942. } catch (Dibi\Exception $e) {
  943. return false;
  944. }
  945. }
  946. }