api-functions.php 41 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function apiLogin()
  7. {
  8. $array = array(
  9. 'data' => array(
  10. array(
  11. 'name' => 'username',
  12. 'value' => (isset($_POST['username'])) ? $_POST['username'] : false
  13. ),
  14. array(
  15. 'name' => 'password',
  16. 'value' => (isset($_POST['password'])) ? $_POST['password'] : false
  17. ),
  18. array(
  19. 'name' => 'remember',
  20. 'value' => (isset($_POST['remember'])) ? true : false
  21. ),
  22. array(
  23. 'name' => 'oAuth',
  24. 'value' => (isset($_POST['oAuth'])) ? $_POST['oAuth'] : false
  25. ),
  26. array(
  27. 'name' => 'oAuthType',
  28. 'value' => (isset($_POST['oAuthType'])) ? $_POST['oAuthType'] : false
  29. ),
  30. array(
  31. 'name' => 'tfaCode',
  32. 'value' => (isset($_POST['tfaCode'])) ? $_POST['tfaCode'] : false
  33. ),
  34. array(
  35. 'name' => 'loginAttempts',
  36. 'value' => (isset($_POST['loginAttempts'])) ? $_POST['loginAttempts'] : false
  37. ),
  38. array(
  39. 'name' => 'output',
  40. 'value' => true
  41. ),
  42. )
  43. );
  44. foreach ($array['data'] as $items) {
  45. foreach ($items as $key => $value) {
  46. if ($key == 'name') {
  47. $newKey = $value;
  48. }
  49. if ($key == 'value') {
  50. $newValue = $value;
  51. }
  52. if (isset($newKey) && isset($newValue)) {
  53. $$newKey = $newValue;
  54. }
  55. }
  56. }
  57. return login($array);
  58. }
  59. function login($array)
  60. {
  61. // Grab username and Password from login form
  62. $username = $password = $oAuth = $oAuthType = '';
  63. foreach ($array['data'] as $items) {
  64. foreach ($items as $key => $value) {
  65. if ($key == 'name') {
  66. $newKey = $value;
  67. }
  68. if ($key == 'value') {
  69. $newValue = $value;
  70. }
  71. if (isset($newKey) && isset($newValue)) {
  72. $$newKey = $newValue;
  73. }
  74. }
  75. }
  76. $username = (strpos($GLOBALS['authBackend'], 'emby') !== false) ? $username : strtolower($username);
  77. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  78. $oAuth = (isset($oAuth)) ? $oAuth : false;
  79. $output = (isset($output)) ? $output : false;
  80. $loginAttempts = (isset($loginAttempts)) ? $loginAttempts : false;
  81. if($loginAttempts > $GLOBALS['loginAttempts'] || isset($_COOKIE['lockout'])){
  82. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  83. return 'lockout';
  84. }
  85. try {
  86. $database = new Dibi\Connection([
  87. 'driver' => 'sqlite3',
  88. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  89. ]);
  90. $authSuccess = false;
  91. $authProxy = false;
  92. if($GLOBALS['authProxyEnabled'] && $GLOBALS['authProxyHeaderName'] !== '' && $GLOBALS['authProxyWhitelist'] !== ''){
  93. if(isset(getallheaders()[$GLOBALS['authProxyHeaderName']])){
  94. $usernameHeader = isset(getallheaders()[$GLOBALS['authProxyHeaderName']]) ? getallheaders()[$GLOBALS['authProxyHeaderName']] : $username;
  95. writeLog('success', 'Auth Proxy Function - Starting Verification for IP: ' . userIP() . ' for request on: ' . $_SERVER['REMOTE_ADDR'] . ' against IP/Subnet: ' . $GLOBALS['authProxyWhitelist'], $usernameHeader);
  96. $whitelistRange = analyzeIP($GLOBALS['authProxyWhitelist']);
  97. $from = $whitelistRange['from'];
  98. $to = $whitelistRange['to'];
  99. $authProxy = authProxyRangeCheck($from,$to);
  100. $username = ($authProxy) ? $usernameHeader : $username;
  101. if($authProxy){
  102. writeLog('success', 'Auth Proxy Function - IP: ' . userIP() . ' has been verified', $usernameHeader);
  103. }else{
  104. writeLog('error', 'Auth Proxy Function - IP: ' . userIP() . ' has failed verification', $usernameHeader);
  105. }
  106. }
  107. }
  108. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  109. if (!$oAuth) {
  110. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  111. switch ($GLOBALS['authType']) {
  112. case 'external':
  113. if (function_exists($function)) {
  114. $authSuccess = $function($username, $password);
  115. }
  116. break;
  117. /** @noinspection PhpMissingBreakStatementInspection */
  118. case 'both':
  119. if (function_exists($function)) {
  120. $authSuccess = $function($username, $password);
  121. }
  122. // no break
  123. default: // Internal
  124. if (!$authSuccess) {
  125. // perform the internal authentication step
  126. if (password_verify($password, $result['password'])) {
  127. $authSuccess = true;
  128. }
  129. }
  130. }
  131. $authSuccess = ($authProxy) ? true : $authSuccess;
  132. } else {
  133. // Has oAuth Token!
  134. switch ($oAuthType) {
  135. case 'plex':
  136. if ($GLOBALS['plexoAuth']) {
  137. $tokenInfo = checkPlexToken($oAuth);
  138. if ($tokenInfo) {
  139. $authSuccess = array(
  140. 'username' => $tokenInfo['user']['username'],
  141. 'email' => $tokenInfo['user']['email'],
  142. 'image' => $tokenInfo['user']['thumb'],
  143. 'token' => $tokenInfo['user']['authToken']
  144. );
  145. coookie('set', 'oAuth', 'true', $GLOBALS['rememberMeDays']);
  146. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || (!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['email'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  147. }
  148. }
  149. break;
  150. default:
  151. return ($output) ? 'No oAuthType defined' : 'error';
  152. break;
  153. }
  154. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  155. }
  156. if ($authSuccess) {
  157. // Make sure user exists in database
  158. $userExists = false;
  159. $passwordMatches = ($oAuth || $authProxy) ? true : false;
  160. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  161. if ($result['username']) {
  162. $userExists = true;
  163. $username = $result['username'];
  164. if ($passwordMatches == false) {
  165. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  166. }
  167. }
  168. if ($userExists) {
  169. //does org password need to be updated
  170. if (!$passwordMatches) {
  171. $database->query('
  172. UPDATE users SET', [
  173. 'password' => password_hash($password, PASSWORD_BCRYPT)
  174. ], '
  175. WHERE id=?', $result['id']);
  176. writeLog('success', 'Login Function - User Password updated from backend', $username);
  177. }
  178. if ($token !== '') {
  179. if ($token !== $result['plex_token']) {
  180. $database->query('
  181. UPDATE users SET', [
  182. 'plex_token' => $token
  183. ], '
  184. WHERE id=?', $result['id']);
  185. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  186. }
  187. }
  188. // 2FA might go here
  189. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  190. $TFA = explode('::', $result['auth_service']);
  191. // Is code with login info?
  192. if ($tfaCode == '') {
  193. return '2FA';
  194. } else {
  195. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  196. writeLoginLog($username, 'error');
  197. writeLog('error', 'Login Function - Wrong 2FA', $username);
  198. return '2FA-incorrect';
  199. }
  200. }
  201. }
  202. // End 2FA
  203. // authentication passed - 1) mark active and update token
  204. $createToken = createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days);
  205. if ($createToken) {
  206. writeLoginLog($username, 'success');
  207. writeLog('success', 'Login Function - A User has logged in', $username);
  208. $ssoUser = (empty($result['email'])) ? $result['username'] : (strpos($result['email'], 'placeholder') !== false) ? $result['username'] : $result['email'];
  209. ssoCheck($ssoUser, $password, $token); //need to work on this
  210. return ($output) ? array('name' => $GLOBALS['cookieName'], 'token' => (string)$createToken) : true;
  211. } else {
  212. return 'Token Creation Error';
  213. }
  214. } else {
  215. // Create User
  216. //ssoCheck($username, $password, $token);
  217. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  218. }
  219. } else {
  220. // authentication failed
  221. writeLoginLog($username, 'error');
  222. writeLog('error', 'Login Function - Wrong Password', $username);
  223. if($loginAttempts >= $GLOBALS['loginAttempts']){
  224. coookieSeconds('set', 'lockout', $GLOBALS['loginLockout'], $GLOBALS['loginLockout']);
  225. return 'lockout';
  226. }else{
  227. return 'mismatch';
  228. }
  229. }
  230. } catch (Dibi\Exception $e) {
  231. return $e;
  232. }
  233. }
  234. function createDB($path, $filename)
  235. {
  236. try {
  237. if (!file_exists($path)) {
  238. mkdir($path, 0777, true);
  239. }
  240. $createDB = new Dibi\Connection([
  241. 'driver' => 'sqlite3',
  242. 'database' => $path . $filename,
  243. ]);
  244. // Create Users
  245. $createDB->query('CREATE TABLE `users` (
  246. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  247. `username` TEXT UNIQUE,
  248. `password` TEXT,
  249. `email` TEXT,
  250. `plex_token` TEXT,
  251. `group` TEXT,
  252. `group_id` INTEGER,
  253. `locked` INTEGER,
  254. `image` TEXT,
  255. `register_date` DATE,
  256. `auth_service` TEXT DEFAULT \'internal\'
  257. );');
  258. // Create Tokens
  259. $createDB->query('CREATE TABLE `chatroom` (
  260. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  261. `username` TEXT,
  262. `gravatar` TEXT,
  263. `uid` TEXT,
  264. `date` DATE,
  265. `ip` TEXT,
  266. `message` TEXT
  267. );');
  268. $createDB->query('CREATE TABLE `tokens` (
  269. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  270. `token` TEXT UNIQUE,
  271. `user_id` INTEGER,
  272. `browser` TEXT,
  273. `ip` TEXT,
  274. `created` DATE,
  275. `expires` DATE
  276. );');
  277. $createDB->query('CREATE TABLE `groups` (
  278. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  279. `group` TEXT UNIQUE,
  280. `group_id` INTEGER,
  281. `image` TEXT,
  282. `default` INTEGER
  283. );');
  284. $createDB->query('CREATE TABLE `categories` (
  285. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  286. `order` INTEGER,
  287. `category` TEXT UNIQUE,
  288. `category_id` INTEGER,
  289. `image` TEXT,
  290. `default` INTEGER
  291. );');
  292. // Create Tabs
  293. $createDB->query('CREATE TABLE `tabs` (
  294. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  295. `order` INTEGER,
  296. `category_id` INTEGER,
  297. `name` TEXT,
  298. `url` TEXT,
  299. `url_local` TEXT,
  300. `default` INTEGER,
  301. `enabled` INTEGER,
  302. `group_id` INTEGER,
  303. `image` TEXT,
  304. `type` INTEGER,
  305. `splash` INTEGER,
  306. `ping` INTEGER,
  307. `ping_url` TEXT,
  308. `timeout` INTEGER,
  309. `timeout_ms` INTEGER,
  310. `preload` INTEGER
  311. );');
  312. // Create Options
  313. $createDB->query('CREATE TABLE `options` (
  314. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  315. `name` TEXT UNIQUE,
  316. `value` TEXT
  317. );');
  318. // Create Invites
  319. $createDB->query('CREATE TABLE `invites` (
  320. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  321. `code` TEXT UNIQUE,
  322. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  323. `email` TEXT,
  324. `username` TEXT,
  325. `dateused` TIMESTAMP,
  326. `usedby` TEXT,
  327. `ip` TEXT,
  328. `valid` TEXT,
  329. `type` TEXT
  330. );');
  331. return true;
  332. } catch (Dibi\Exception $e) {
  333. return false;
  334. }
  335. }
  336. // Upgrade Database
  337. function updateDB($oldVerNum = false)
  338. {
  339. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  340. if (!file_exists($tempLock)) {
  341. touch($tempLock);
  342. // Create Temp DB First
  343. $migrationDB = 'tempMigration.db';
  344. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  345. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  346. unlink($GLOBALS['dbLocation'] . $migrationDB);
  347. }
  348. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  349. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  350. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  351. if ($success) {
  352. try {
  353. $connectOldDB = new Dibi\Connection([
  354. 'driver' => 'sqlite3',
  355. 'database' => $backupDB,
  356. ]);
  357. $connectNewDB = new Dibi\Connection([
  358. 'driver' => 'sqlite3',
  359. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  360. ]);
  361. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  362. foreach ($tables as $table) {
  363. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  364. writeLog('success', 'Update Function - Grabbed Table data for Table: ' . $table['name'], 'Database');
  365. foreach ($data as $row) {
  366. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  367. }
  368. writeLog('success', 'Update Function - Wrote Table data for Table: ' . $table['name'], 'Database');
  369. }
  370. writeLog('success', 'Update Function - All Table data converted - Starting Movement', 'Database');
  371. $connectOldDB->disconnect();
  372. $connectNewDB->disconnect();
  373. // Remove Current Database
  374. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  375. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  376. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  377. if ($newFileSize > 0) {
  378. writeLog('success', 'Update Function - Table Size of new DB ok..', 'Database');
  379. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  380. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  381. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  382. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  383. @unlink($tempLock);
  384. return true;
  385. }
  386. }
  387. @unlink($tempLock);
  388. return false;
  389. } catch (Dibi\Exception $e) {
  390. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  391. @unlink($tempLock);
  392. return false;
  393. }
  394. }
  395. @unlink($tempLock);
  396. return false;
  397. }
  398. return false;
  399. }
  400. function createFirstAdmin($path, $filename, $username, $password, $email)
  401. {
  402. try {
  403. $createDB = new Dibi\Connection([
  404. 'driver' => 'sqlite3',
  405. 'database' => $path . $filename,
  406. ]);
  407. $userInfo = [
  408. 'username' => $username,
  409. 'password' => password_hash($password, PASSWORD_BCRYPT),
  410. 'email' => $email,
  411. 'group' => 'Admin',
  412. 'group_id' => 0,
  413. 'image' => gravatar($email),
  414. 'register_date' => $GLOBALS['currentTime'],
  415. ];
  416. $groupInfo0 = [
  417. 'group' => 'Admin',
  418. 'group_id' => 0,
  419. 'default' => false,
  420. 'image' => 'plugins/images/groups/admin.png',
  421. ];
  422. $groupInfo1 = [
  423. 'group' => 'Co-Admin',
  424. 'group_id' => 1,
  425. 'default' => false,
  426. 'image' => 'plugins/images/groups/coadmin.png',
  427. ];
  428. $groupInfo2 = [
  429. 'group' => 'Super User',
  430. 'group_id' => 2,
  431. 'default' => false,
  432. 'image' => 'plugins/images/groups/superuser.png',
  433. ];
  434. $groupInfo3 = [
  435. 'group' => 'Power User',
  436. 'group_id' => 3,
  437. 'default' => false,
  438. 'image' => 'plugins/images/groups/poweruser.png',
  439. ];
  440. $groupInfo4 = [
  441. 'group' => 'User',
  442. 'group_id' => 4,
  443. 'default' => true,
  444. 'image' => 'plugins/images/groups/user.png',
  445. ];
  446. $groupInfoGuest = [
  447. 'group' => 'Guest',
  448. 'group_id' => 999,
  449. 'default' => false,
  450. 'image' => 'plugins/images/groups/guest.png',
  451. ];
  452. $settingsInfo = [
  453. 'order' => 1,
  454. 'category_id' => 0,
  455. 'name' => 'Settings',
  456. 'url' => 'api/?v1/settings/page',
  457. 'default' => false,
  458. 'enabled' => true,
  459. 'group_id' => 1,
  460. 'image' => 'fontawesome::cog',
  461. 'type' => 0
  462. ];
  463. $homepageInfo = [
  464. 'order' => 2,
  465. 'category_id' => 0,
  466. 'name' => 'Homepage',
  467. 'url' => 'api/?v1/homepage/page',
  468. 'default' => false,
  469. 'enabled' => false,
  470. 'group_id' => 4,
  471. 'image' => 'fontawesome::home',
  472. 'type' => 0
  473. ];
  474. $unsortedInfo = [
  475. 'order' => 1,
  476. 'category' => 'Unsorted',
  477. 'category_id' => 0,
  478. 'image' => 'plugins/images/categories/unsorted.png',
  479. 'default' => true
  480. ];
  481. $createDB->query('INSERT INTO [users]', $userInfo);
  482. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  483. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  484. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  485. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  486. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  487. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  488. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  489. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  490. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  491. return true;
  492. } catch (Dibi\Exception $e) {
  493. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  494. return false;
  495. }
  496. }
  497. function defaultUserGroup()
  498. {
  499. try {
  500. $connect = new Dibi\Connection([
  501. 'driver' => 'sqlite3',
  502. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  503. ]);
  504. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  505. return $all;
  506. } catch (Dibi\Exception $e) {
  507. return false;
  508. }
  509. }
  510. function defaultTabCategory()
  511. {
  512. try {
  513. $connect = new Dibi\Connection([
  514. 'driver' => 'sqlite3',
  515. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  516. ]);
  517. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  518. return $all;
  519. } catch (Dibi\Exception $e) {
  520. return false;
  521. }
  522. }
  523. function getGuest()
  524. {
  525. if (isset($GLOBALS['dbLocation'])) {
  526. try {
  527. $connect = new Dibi\Connection([
  528. 'driver' => 'sqlite3',
  529. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  530. ]);
  531. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  532. return $all;
  533. } catch (Dibi\Exception $e) {
  534. return false;
  535. }
  536. } else {
  537. return array(
  538. 'group' => 'Guest',
  539. 'group_id' => 999,
  540. 'image' => 'plugins/images/groups/guest.png'
  541. );
  542. }
  543. }
  544. function adminEditGroup($array)
  545. {
  546. switch ($array['data']['action']) {
  547. case 'changeDefaultGroup':
  548. try {
  549. $connect = new Dibi\Connection([
  550. 'driver' => 'sqlite3',
  551. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  552. ]);
  553. $connect->query('UPDATE groups SET `default` = 0');
  554. $connect->query('
  555. UPDATE groups SET', [
  556. 'default' => 1
  557. ], '
  558. WHERE id=?', $array['data']['id']);
  559. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  560. return true;
  561. } catch (Dibi\Exception $e) {
  562. return false;
  563. }
  564. break;
  565. case 'deleteUserGroup':
  566. try {
  567. $connect = new Dibi\Connection([
  568. 'driver' => 'sqlite3',
  569. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  570. ]);
  571. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  572. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  573. return true;
  574. } catch (Dibi\Exception $e) {
  575. return false;
  576. }
  577. break;
  578. case 'addUserGroup':
  579. try {
  580. $connect = new Dibi\Connection([
  581. 'driver' => 'sqlite3',
  582. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  583. ]);
  584. $newGroup = [
  585. 'group' => $array['data']['newGroupName'],
  586. 'group_id' => $array['data']['newGroupID'],
  587. 'default' => false,
  588. 'image' => $array['data']['newGroupImage'],
  589. ];
  590. $connect->query('INSERT INTO [groups]', $newGroup);
  591. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  592. return true;
  593. } catch (Dibi\Exception $e) {
  594. return false;
  595. }
  596. break;
  597. case 'editUserGroup':
  598. try {
  599. $connect = new Dibi\Connection([
  600. 'driver' => 'sqlite3',
  601. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  602. ]);
  603. $connect->query('
  604. UPDATE groups SET', [
  605. 'group' => $array['data']['groupName'],
  606. 'image' => $array['data']['groupImage'],
  607. ], '
  608. WHERE id=?', $array['data']['id']);
  609. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  610. return true;
  611. } catch (Dibi\Exception $e) {
  612. return false;
  613. }
  614. break;
  615. default:
  616. return false;
  617. break;
  618. }
  619. }
  620. function adminEditUser($array)
  621. {
  622. switch ($array['data']['action']) {
  623. case 'changeGroup':
  624. if ($array['data']['newGroupID'] == 0) {
  625. return false;
  626. }
  627. try {
  628. $connect = new Dibi\Connection([
  629. 'driver' => 'sqlite3',
  630. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  631. ]);
  632. $connect->query('
  633. UPDATE users SET', [
  634. 'group' => $array['data']['newGroupName'],
  635. 'group_id' => $array['data']['newGroupID'],
  636. ], '
  637. WHERE id=?', $array['data']['id']);
  638. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  639. return true;
  640. } catch (Dibi\Exception $e) {
  641. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  642. return false;
  643. }
  644. break;
  645. case 'editUser':
  646. try {
  647. $connect = new Dibi\Connection([
  648. 'driver' => 'sqlite3',
  649. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  650. ]);
  651. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  652. $connect->query('
  653. UPDATE users SET', [
  654. 'username' => $array['data']['username'],
  655. 'email' => $array['data']['email'],
  656. 'image' => gravatar($array['data']['email']),
  657. ], '
  658. WHERE id=?', $array['data']['id']);
  659. if (!empty($array['data']['password'])) {
  660. $connect->query('
  661. UPDATE users SET', [
  662. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  663. ], '
  664. WHERE id=?', $array['data']['id']);
  665. }
  666. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  667. return true;
  668. } else {
  669. return false;
  670. }
  671. } catch (Dibi\Exception $e) {
  672. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  673. return false;
  674. }
  675. break;
  676. case 'addNewUser':
  677. $defaults = defaultUserGroup();
  678. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  679. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  680. return true;
  681. } else {
  682. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  683. return 'username taken';
  684. }
  685. break;
  686. case 'deleteUser':
  687. try {
  688. $connect = new Dibi\Connection([
  689. 'driver' => 'sqlite3',
  690. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  691. ]);
  692. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  693. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  694. return true;
  695. } catch (Dibi\Exception $e) {
  696. return false;
  697. }
  698. break;
  699. default:
  700. return false;
  701. break;
  702. }
  703. }
  704. function editTabs($array)
  705. {
  706. switch ($array['data']['action']) {
  707. case 'changeGroup':
  708. try {
  709. $connect = new Dibi\Connection([
  710. 'driver' => 'sqlite3',
  711. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  712. ]);
  713. $connect->query('
  714. UPDATE tabs SET', [
  715. 'group_id' => $array['data']['newGroupID'],
  716. ], '
  717. WHERE id=?', $array['data']['id']);
  718. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  719. return true;
  720. } catch (Dibi\Exception $e) {
  721. return false;
  722. }
  723. break;
  724. case 'changeCategory':
  725. try {
  726. $connect = new Dibi\Connection([
  727. 'driver' => 'sqlite3',
  728. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  729. ]);
  730. $connect->query('
  731. UPDATE tabs SET', [
  732. 'category_id' => $array['data']['newCategoryID'],
  733. ], '
  734. WHERE id=?', $array['data']['id']);
  735. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  736. return true;
  737. } catch (Dibi\Exception $e) {
  738. return false;
  739. }
  740. break;
  741. case 'changeType':
  742. try {
  743. $connect = new Dibi\Connection([
  744. 'driver' => 'sqlite3',
  745. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  746. ]);
  747. $connect->query('
  748. UPDATE tabs SET', [
  749. 'type' => $array['data']['newTypeID'],
  750. ], '
  751. WHERE id=?', $array['data']['id']);
  752. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  753. return true;
  754. } catch (Dibi\Exception $e) {
  755. return false;
  756. }
  757. break;
  758. case 'changeEnabled':
  759. try {
  760. $connect = new Dibi\Connection([
  761. 'driver' => 'sqlite3',
  762. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  763. ]);
  764. $connect->query('
  765. UPDATE tabs SET', [
  766. 'enabled' => $array['data']['tabEnabled'],
  767. ], '
  768. WHERE id=?', $array['data']['id']);
  769. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  770. return true;
  771. } catch (Dibi\Exception $e) {
  772. return false;
  773. }
  774. break;
  775. case 'changeSplash':
  776. try {
  777. $connect = new Dibi\Connection([
  778. 'driver' => 'sqlite3',
  779. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  780. ]);
  781. $connect->query('
  782. UPDATE tabs SET', [
  783. 'splash' => $array['data']['tabSplash'],
  784. ], '
  785. WHERE id=?', $array['data']['id']);
  786. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  787. return true;
  788. } catch (Dibi\Exception $e) {
  789. return false;
  790. }
  791. break;
  792. case 'changePing':
  793. try {
  794. $connect = new Dibi\Connection([
  795. 'driver' => 'sqlite3',
  796. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  797. ]);
  798. $connect->query('
  799. UPDATE tabs SET', [
  800. 'ping' => $array['data']['tabPing'],
  801. ], '
  802. WHERE id=?', $array['data']['id']);
  803. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  804. return true;
  805. } catch (Dibi\Exception $e) {
  806. return false;
  807. }
  808. break;
  809. case 'changePreload':
  810. try {
  811. $connect = new Dibi\Connection([
  812. 'driver' => 'sqlite3',
  813. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  814. ]);
  815. $connect->query('
  816. UPDATE tabs SET', [
  817. 'preload' => $array['data']['tabPreload'],
  818. ], '
  819. WHERE id=?', $array['data']['id']);
  820. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s preload status was changed to [' . $array['data']['tabPreloadWord'] . ']', $GLOBALS['organizrUser']['username']);
  821. return true;
  822. } catch (Dibi\Exception $e) {
  823. return false;
  824. }
  825. break;
  826. case 'changeDefault':
  827. try {
  828. $connect = new Dibi\Connection([
  829. 'driver' => 'sqlite3',
  830. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  831. ]);
  832. $connect->query('UPDATE tabs SET `default` = 0');
  833. $connect->query('
  834. UPDATE tabs SET', [
  835. 'default' => 1
  836. ], '
  837. WHERE id=?', $array['data']['id']);
  838. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  839. return true;
  840. } catch (Dibi\Exception $e) {
  841. return false;
  842. }
  843. break;
  844. case 'deleteTab':
  845. try {
  846. $connect = new Dibi\Connection([
  847. 'driver' => 'sqlite3',
  848. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  849. ]);
  850. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  851. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  852. return true;
  853. } catch (Dibi\Exception $e) {
  854. return false;
  855. }
  856. break;
  857. case 'editTab':
  858. try {
  859. $connect = new Dibi\Connection([
  860. 'driver' => 'sqlite3',
  861. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  862. ]);
  863. $connect->query('
  864. UPDATE tabs SET', [
  865. 'name' => $array['data']['tabName'],
  866. 'url' => $array['data']['tabURL'],
  867. 'url_local' => $array['data']['tabLocalURL'],
  868. 'ping_url' => $array['data']['pingURL'],
  869. 'image' => $array['data']['tabImage'],
  870. 'timeout' => $array['data']['tabActionType'],
  871. 'timeout_ms' => $array['data']['tabActionTime'],
  872. ], '
  873. WHERE id=?', $array['data']['id']);
  874. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  875. return true;
  876. } catch (Dibi\Exception $e) {
  877. return false;
  878. }
  879. case 'changeOrder':
  880. try {
  881. $connect = new Dibi\Connection([
  882. 'driver' => 'sqlite3',
  883. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  884. ]);
  885. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  886. if ($value['order'] != $value['originalOrder']) {
  887. $connect->query('
  888. UPDATE tabs SET', [
  889. 'order' => $value['order'],
  890. ], '
  891. WHERE id=?', $value['id']);
  892. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  893. }
  894. }
  895. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  896. return true;
  897. } catch (Dibi\Exception $e) {
  898. return false;
  899. }
  900. break;
  901. case 'addNewTab':
  902. try {
  903. $default = defaultTabCategory()['category_id'];
  904. $connect = new Dibi\Connection([
  905. 'driver' => 'sqlite3',
  906. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  907. ]);
  908. $newTab = [
  909. 'order' => $array['data']['tabOrder'],
  910. 'category_id' => $default,
  911. 'name' => $array['data']['tabName'],
  912. 'url' => $array['data']['tabURL'],
  913. 'url_local' => $array['data']['tabLocalURL'],
  914. 'ping_url' => $array['data']['pingURL'],
  915. 'default' => $array['data']['tabDefault'],
  916. 'enabled' => 1,
  917. 'group_id' => $array['data']['tabGroupID'],
  918. 'image' => $array['data']['tabImage'],
  919. 'type' => $array['data']['tabType'],
  920. 'timeout' => $array['data']['tabActionType'],
  921. 'timeout_ms' => $array['data']['tabActionTime'],
  922. ];
  923. $connect->query('INSERT INTO [tabs]', $newTab);
  924. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  925. return true;
  926. } catch (Dibi\Exception $e) {
  927. return false;
  928. }
  929. break;
  930. default:
  931. return false;
  932. break;
  933. }
  934. }
  935. function editCategories($array)
  936. {
  937. switch ($array['data']['action']) {
  938. case 'changeDefault':
  939. try {
  940. $connect = new Dibi\Connection([
  941. 'driver' => 'sqlite3',
  942. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  943. ]);
  944. $connect->query('UPDATE categories SET `default` = 0');
  945. $connect->query('
  946. UPDATE categories SET', [
  947. 'default' => 1
  948. ], '
  949. WHERE id=?', $array['data']['id']);
  950. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  951. return true;
  952. } catch (Dibi\Exception $e) {
  953. return false;
  954. }
  955. break;
  956. case 'deleteCategory':
  957. try {
  958. $connect = new Dibi\Connection([
  959. 'driver' => 'sqlite3',
  960. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  961. ]);
  962. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  963. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  964. return true;
  965. } catch (Dibi\Exception $e) {
  966. return false;
  967. }
  968. break;
  969. case 'addNewCategory':
  970. try {
  971. $connect = new Dibi\Connection([
  972. 'driver' => 'sqlite3',
  973. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  974. ]);
  975. $newCategory = [
  976. 'category' => $array['data']['categoryName'],
  977. 'order' => $array['data']['categoryOrder'],
  978. 'category_id' => $array['data']['categoryID'],
  979. 'default' => false,
  980. 'image' => $array['data']['categoryImage'],
  981. ];
  982. $connect->query('INSERT INTO [categories]', $newCategory);
  983. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  984. return true;
  985. } catch (Dibi\Exception $e) {
  986. return $e;
  987. }
  988. break;
  989. case 'editCategory':
  990. try {
  991. $connect = new Dibi\Connection([
  992. 'driver' => 'sqlite3',
  993. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  994. ]);
  995. $connect->query('
  996. UPDATE categories SET', [
  997. 'category' => $array['data']['name'],
  998. 'image' => $array['data']['image'],
  999. ], '
  1000. WHERE id=?', $array['data']['id']);
  1001. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  1002. return true;
  1003. } catch (Dibi\Exception $e) {
  1004. return false;
  1005. }
  1006. break;
  1007. case 'changeOrder':
  1008. try {
  1009. $connect = new Dibi\Connection([
  1010. 'driver' => 'sqlite3',
  1011. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1012. ]);
  1013. foreach ($array['data']['categories']['category'] as $key => $value) {
  1014. if ($value['order'] != $value['originalOrder']) {
  1015. $connect->query('
  1016. UPDATE categories SET', [
  1017. 'order' => $value['order'],
  1018. ], '
  1019. WHERE id=?', $value['id']);
  1020. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  1021. }
  1022. }
  1023. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  1024. return true;
  1025. } catch (Dibi\Exception $e) {
  1026. return false;
  1027. }
  1028. break;
  1029. default:
  1030. return false;
  1031. break;
  1032. }
  1033. }
  1034. function allUsers()
  1035. {
  1036. try {
  1037. $connect = new Dibi\Connection([
  1038. 'driver' => 'sqlite3',
  1039. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1040. ]);
  1041. $users = $connect->fetchAll('SELECT * FROM users');
  1042. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  1043. foreach ($users as $k => $v) {
  1044. // clear password from array
  1045. unset($users[$k]['password']);
  1046. }
  1047. $all['users'] = $users;
  1048. $all['groups'] = $groups;
  1049. return $all;
  1050. } catch (Dibi\Exception $e) {
  1051. return false;
  1052. }
  1053. }
  1054. function usernameTaken($username, $email)
  1055. {
  1056. try {
  1057. $connect = new Dibi\Connection([
  1058. 'driver' => 'sqlite3',
  1059. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1060. ]);
  1061. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  1062. return ($all) ? true : false;
  1063. } catch (Dibi\Exception $e) {
  1064. return false;
  1065. }
  1066. }
  1067. function usernameTakenExcept($username, $email, $id)
  1068. {
  1069. try {
  1070. $connect = new Dibi\Connection([
  1071. 'driver' => 'sqlite3',
  1072. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1073. ]);
  1074. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  1075. return ($all) ? true : false;
  1076. } catch (Dibi\Exception $e) {
  1077. return false;
  1078. }
  1079. }
  1080. function createUser($username, $password, $defaults, $email = null)
  1081. {
  1082. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  1083. try {
  1084. if (!usernameTaken($username, $email)) {
  1085. $createDB = new Dibi\Connection([
  1086. 'driver' => 'sqlite3',
  1087. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1088. ]);
  1089. $userInfo = [
  1090. 'username' => $username,
  1091. 'password' => password_hash($password, PASSWORD_BCRYPT),
  1092. 'email' => $email,
  1093. 'group' => $defaults['group'],
  1094. 'group_id' => $defaults['group_id'],
  1095. 'image' => gravatar($email),
  1096. 'register_date' => $GLOBALS['currentTime'],
  1097. ];
  1098. $createDB->query('INSERT INTO [users]', $userInfo);
  1099. return true;
  1100. } else {
  1101. return false;
  1102. }
  1103. } catch (Dibi\Exception $e) {
  1104. return false;
  1105. }
  1106. }
  1107. function importUsers($array)
  1108. {
  1109. $imported = 0;
  1110. $defaults = defaultUserGroup();
  1111. foreach ($array as $user) {
  1112. $password = random_ascii_string(30);
  1113. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  1114. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  1115. if (!$newUser) {
  1116. writeLog('error', 'Import Function - Error', $user['username']);
  1117. } else {
  1118. $imported++;
  1119. }
  1120. }
  1121. }
  1122. return $imported;
  1123. }
  1124. function importUsersType($array)
  1125. {
  1126. $type = $array['data']['type'];
  1127. if ($type !== '') {
  1128. switch ($type) {
  1129. case 'plex':
  1130. return importUsers(allPlexUsers(true));
  1131. break;
  1132. default:
  1133. return false;
  1134. }
  1135. }
  1136. return false;
  1137. }
  1138. function allTabs()
  1139. {
  1140. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1141. try {
  1142. $connect = new Dibi\Connection([
  1143. 'driver' => 'sqlite3',
  1144. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1145. ]);
  1146. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1147. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1148. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1149. return $all;
  1150. } catch (Dibi\Exception $e) {
  1151. return false;
  1152. }
  1153. }
  1154. return false;
  1155. }
  1156. function allGroups()
  1157. {
  1158. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1159. try {
  1160. $connect = new Dibi\Connection([
  1161. 'driver' => 'sqlite3',
  1162. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1163. ]);
  1164. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1165. return $all;
  1166. } catch (Dibi\Exception $e) {
  1167. return false;
  1168. }
  1169. }
  1170. return false;
  1171. }
  1172. function loadTabs()
  1173. {
  1174. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1175. try {
  1176. $connect = new Dibi\Connection([
  1177. 'driver' => 'sqlite3',
  1178. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1179. ]);
  1180. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1181. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1182. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1183. $all['tabs'] = $tabs;
  1184. foreach ($tabs as $k => $v) {
  1185. $v['access_url'] = (!empty($v['url_local']) && ($v['url_local'] !== null) && ($v['url_local'] !== 'null') && isLocal() && $v['type'] !== 0) ? $v['url_local'] : $v['url'];
  1186. }
  1187. $count = array_map(function ($element) {
  1188. return $element['category_id'];
  1189. }, $tabs);
  1190. $count = (array_count_values($count));
  1191. foreach ($categories as $k => $v) {
  1192. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1193. }
  1194. $all['categories'] = $categories;
  1195. return $all;
  1196. } catch (Dibi\Exception $e) {
  1197. return false;
  1198. }
  1199. }
  1200. return false;
  1201. }
  1202. function getActiveTokens()
  1203. {
  1204. try {
  1205. $connect = new Dibi\Connection([
  1206. 'driver' => 'sqlite3',
  1207. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1208. ]);
  1209. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1210. return $all;
  1211. } catch (Dibi\Exception $e) {
  1212. return false;
  1213. }
  1214. }
  1215. function revokeToken($array)
  1216. {
  1217. if ($array['data']['token']) {
  1218. try {
  1219. $connect = new Dibi\Connection([
  1220. 'driver' => 'sqlite3',
  1221. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1222. ]);
  1223. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1224. return true;
  1225. } catch (Dibi\Exception $e) {
  1226. return false;
  1227. }
  1228. }
  1229. }
  1230. function getSchema()
  1231. {
  1232. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1233. try {
  1234. $connect = new Dibi\Connection([
  1235. 'driver' => 'sqlite3',
  1236. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1237. ]);
  1238. $result = $connect->fetchAll(' SELECT name, sql FROM sqlite_master WHERE type=\'table\' ORDER BY name');
  1239. return $result;
  1240. } catch (Dibi\Exception $e) {
  1241. return false;
  1242. }
  1243. } else {
  1244. return 'DB not set yet...';
  1245. }
  1246. }