api-functions.php 35 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897
  1. <?php
  2. function login($array){
  3. // Grab username and Password from login form
  4. foreach ($array['data'] as $items) {
  5. foreach ($items as $key => $value) {
  6. if($key == 'name'){
  7. $newKey = $value;
  8. }
  9. if($key == 'value'){
  10. $newValue = $value;
  11. }
  12. if(isset($newKey) && isset($newValue)){
  13. $$newKey = $newValue;
  14. }
  15. }
  16. }
  17. $username = strtolower($username);
  18. $days = (isset($remember)) ? 7 : 1;
  19. try {
  20. $database = new Dibi\Connection([
  21. 'driver' => 'sqlite3',
  22. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  23. ]);
  24. $authSuccess = false;
  25. $function = 'plugin_auth_'.$GLOBALS['authBackend'];
  26. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$username);
  27. switch ($GLOBALS['authType']) {
  28. case 'external':
  29. if (function_exists($function)) {
  30. $authSuccess = $function($username, $password);
  31. }
  32. break;
  33. case 'both':
  34. if (function_exists($function)) {
  35. $authSuccess = $function($username, $password);
  36. }
  37. default: // Internal
  38. if (!$authSuccess) {
  39. // perform the internal authentication step
  40. if(password_verify($password, $result['password'])){
  41. $authSuccess = true;
  42. }
  43. }
  44. }
  45. if ($authSuccess) {
  46. // Make sure user exists in database
  47. $userExists = false;
  48. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  49. if($result['username']){
  50. $userExists = true;
  51. $username = $result['username'];
  52. }
  53. if ($userExists) {
  54. // authentication passed - 1) mark active and update token
  55. if(createToken($result['username'],$result['email'],$result['image'],$result['group'],$result['group_id'],$GLOBALS['organizrHash'],$days)){
  56. writeLoginLog($username, 'success');
  57. writeLog('success', 'Login Function - A User has logged in', $username);
  58. ssoCheck($username, $password, $token); //need to work on this
  59. return true;
  60. }else{
  61. return 'error';
  62. }
  63. } else {
  64. // Create User
  65. ssoCheck($username, $password, $token);
  66. return authRegister($username,$password,'',(is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  67. }
  68. } else {
  69. // authentication failed
  70. writeLoginLog($username, 'error');
  71. writeLog('error', 'Login Function - Wrong Password', $username);
  72. return 'mismatch';
  73. }
  74. } catch (Dibi\Exception $e) {
  75. return 'error';
  76. }
  77. }
  78. function createDB($path,$filename) {
  79. if(file_exists($path.$filename)){
  80. unlink($path.$filename);
  81. }
  82. try {
  83. $createDB = new Dibi\Connection([
  84. 'driver' => 'sqlite3',
  85. 'database' => $path.$filename,
  86. ]);
  87. // Create Users
  88. $users = $createDB->query('CREATE TABLE `users` (
  89. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  90. `username` TEXT UNIQUE,
  91. `password` TEXT,
  92. `email` TEXT,
  93. `plex_token` TEXT,
  94. `group` TEXT,
  95. `group_id` INTEGER,
  96. `locked` INTEGER,
  97. `image` TEXT,
  98. `register_date` DATE,
  99. `auth_service` TEXT DEFAULT \'internal\'
  100. );');
  101. // Create Tokens
  102. $jwt = $createDB->query('CREATE TABLE `tokens` (
  103. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  104. `token` TEXT UNIQUE,
  105. `user_id` INTEGER,
  106. `created` DATE,
  107. `expires` DATE
  108. );');
  109. $groups = $createDB->query('CREATE TABLE `groups` (
  110. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  111. `group` TEXT UNIQUE,
  112. `group_id` INTEGER,
  113. `image` TEXT,
  114. `default` INTEGER
  115. );');
  116. $categories = $createDB->query('CREATE TABLE `categories` (
  117. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  118. `order` INTEGER,
  119. `category` TEXT UNIQUE,
  120. `category_id` INTEGER,
  121. `image` TEXT,
  122. `default` INTEGER
  123. );');
  124. // Create Tabs
  125. $tabs = $createDB->query('CREATE TABLE `tabs` (
  126. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  127. `order` INTEGER,
  128. `category_id` INTEGER,
  129. `name` TEXT,
  130. `url` TEXT,
  131. `url_local` TEXT,
  132. `default` INTEGER,
  133. `enabled` INTEGER,
  134. `group_id` INTEGER,
  135. `image` TEXT,
  136. `type` INTEGER,
  137. `splash` INTEGER,
  138. `ping` INTEGER,
  139. `ping_url` TEXT
  140. );');
  141. // Create Options
  142. $options = $createDB->query('CREATE TABLE `options` (
  143. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  144. `users_id` INTEGER UNIQUE,
  145. `title` TEXT UNIQUE,
  146. `topbar` TEXT,
  147. `bottombar` TEXT,
  148. `sidebar` TEXT,
  149. `hoverbg` TEXT,
  150. `topbartext` TEXT,
  151. `activetabBG` TEXT,
  152. `activetabicon` TEXT,
  153. `activetabtext` TEXT,
  154. `inactiveicon` TEXT,
  155. `inactivetext` TEXT,
  156. `loading` TEXT,
  157. `hovertext` TEXT
  158. );');
  159. // Create Invites
  160. $invites = $createDB->query('CREATE TABLE `invites` (
  161. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  162. `code` TEXT UNIQUE,
  163. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  164. `email` TEXT,
  165. `username` TEXT,
  166. `dateused` TIMESTAMP,
  167. `usedby` TEXT,
  168. `ip` TEXT,
  169. `valid` TEXT,
  170. `type` TEXT
  171. );');
  172. return true;
  173. } catch (Dibi\Exception $e) {
  174. return false;
  175. }
  176. }
  177. // Upgrade Database
  178. function updateDB($path,$filename,$oldVerNum = false) {
  179. try {
  180. $connect = new Dibi\Connection([
  181. 'driver' => 'sqlite3',
  182. 'database' => $path.$filename,
  183. ]);
  184. // Cache current DB
  185. $cache = array();
  186. foreach($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  187. foreach($connect->query('SELECT * FROM '.$table['name'].';') as $key => $row) {
  188. foreach($row as $k => $v) {
  189. if (is_string($k)) {
  190. $cache[$table['name']][$key][$k] = $v;
  191. }
  192. }
  193. }
  194. }
  195. $connect->disconnect();
  196. } catch (Dibi\Exception $e) {
  197. return $e;
  198. }
  199. // Remove Current Database
  200. $pathDigest = pathinfo($path.$filename);
  201. if (file_exists($path.$filename)) {
  202. copy($path.$filename, $pathDigest['dirname'].'/'.$pathDigest['filename'].'['.date('Y-m-d_H-i-s').']'.($oldVerNum?'['.$oldVerNum.']':'').'.bak.db');
  203. unlink($path.$filename);
  204. }
  205. // Create New Database
  206. $success = createDB($path,$filename);
  207. try {
  208. $GLOBALS['connect'] = new Dibi\Connection([
  209. 'driver' => 'sqlite3',
  210. 'database' => $path.$filename,
  211. ]);
  212. // Restore Items
  213. if ($success) {
  214. foreach($cache as $table => $tableData) {
  215. if ($tableData) {
  216. $queryBase = 'INSERT INTO '.$table.' (`'.implode('`,`',array_keys(current($tableData))).'`) values ';
  217. $insertValues = array();
  218. reset($tableData);
  219. foreach($tableData as $key => $value) {
  220. $insertValues[] = '('.implode(',',array_map(function($d) {
  221. return (isset($d)?str_replace('\/', '/',json_encode($d)):'null');
  222. }, $value)).')';
  223. }
  224. $GLOBALS['connect']->query($queryBase.implode(',',$insertValues).';');
  225. }
  226. }
  227. }
  228. return true;
  229. } catch (Dibi\Exception $e) {
  230. return $e;
  231. }
  232. }
  233. function createFirstAdmin($path,$filename,$username,$password,$email) {
  234. try {
  235. $createDB = new Dibi\Connection([
  236. 'driver' => 'sqlite3',
  237. 'database' => $path.$filename,
  238. ]);
  239. $userInfo = [
  240. 'username' => $username,
  241. 'password' => password_hash($password, PASSWORD_BCRYPT),
  242. 'email' => $email,
  243. 'group' => 'Admin',
  244. 'group_id' => 0,
  245. 'image' => gravatar($email),
  246. 'register_date' => $GLOBALS['currentTime'],
  247. ];
  248. $groupInfo0 = [
  249. 'group' => 'Admin',
  250. 'group_id' => 0,
  251. 'default' => false,
  252. 'image' => 'plugins/images/groups/admin.png',
  253. ];
  254. $groupInfo1 = [
  255. 'group' => 'Co-Admin',
  256. 'group_id' => 1,
  257. 'default' => false,
  258. 'image' => 'plugins/images/groups/coadmin.png',
  259. ];
  260. $groupInfo2 = [
  261. 'group' => 'Super User',
  262. 'group_id' => 2,
  263. 'default' => false,
  264. 'image' => 'plugins/images/groups/superuser.png',
  265. ];
  266. $groupInfo3 = [
  267. 'group' => 'Power User',
  268. 'group_id' => 3,
  269. 'default' => false,
  270. 'image' => 'plugins/images/groups/poweruser.png',
  271. ];
  272. $groupInfo4 = [
  273. 'group' => 'User',
  274. 'group_id' => 4,
  275. 'default' => true,
  276. 'image' => 'plugins/images/groups/user.png',
  277. ];
  278. $groupInfoGuest = [
  279. 'group' => 'Guest',
  280. 'group_id' => 999,
  281. 'default' => false,
  282. 'image' => 'plugins/images/groups/guest.png',
  283. ];
  284. $settingsInfo = [
  285. 'order' => 1,
  286. 'category_id' => 0,
  287. 'name' => 'Settings',
  288. 'url' => 'api/?v1/settings/page',
  289. 'default' => false,
  290. 'enabled' => true,
  291. 'group_id' => 1,
  292. 'image' => 'fontawesome::cog',
  293. 'type' => 0
  294. ];
  295. $homepageInfo = [
  296. 'order' => 2,
  297. 'category_id' => 0,
  298. 'name' => 'Homepage',
  299. 'url' => 'api/?v1/homepage/page',
  300. 'default' => false,
  301. 'enabled' => false,
  302. 'group_id' => 4,
  303. 'image' => 'fontawesome::home',
  304. 'type' => 0
  305. ];
  306. $unsortedInfo = [
  307. 'order' => 1,
  308. 'category' => 'Unsorted',
  309. 'category_id' => 0,
  310. 'image' => 'plugins/images/categories/unsorted.png',
  311. 'default' => true
  312. ];
  313. $createDB->query('INSERT INTO [users]', $userInfo);
  314. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  315. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  316. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  317. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  318. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  319. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  320. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  321. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  322. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  323. return true;
  324. } catch (Dibi\Exception $e) {
  325. return false;
  326. }
  327. }
  328. function defaultUserGroup(){
  329. try {
  330. $connect = new Dibi\Connection([
  331. 'driver' => 'sqlite3',
  332. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  333. ]);
  334. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  335. return $all;
  336. } catch (Dibi\Exception $e) {
  337. return false;
  338. }
  339. }
  340. function defaulTabCategory(){
  341. try {
  342. $connect = new Dibi\Connection([
  343. 'driver' => 'sqlite3',
  344. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  345. ]);
  346. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  347. return $all;
  348. } catch (Dibi\Exception $e) {
  349. return false;
  350. }
  351. }
  352. function getGuest(){
  353. if(isset($GLOBALS['dbLocation'])){
  354. try {
  355. $connect = new Dibi\Connection([
  356. 'driver' => 'sqlite3',
  357. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  358. ]);
  359. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  360. return $all;
  361. } catch (Dibi\Exception $e) {
  362. return false;
  363. }
  364. }else{
  365. return array(
  366. 'group' => 'Guest',
  367. 'group_id' => 999,
  368. 'image' => 'plugins/images/groups/guest.png'
  369. );
  370. }
  371. }
  372. function adminEditGroup($array){
  373. switch ($array['data']['action']) {
  374. case 'changeDefaultGroup':
  375. try {
  376. $connect = new Dibi\Connection([
  377. 'driver' => 'sqlite3',
  378. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  379. ]);
  380. $connect->query('UPDATE groups SET `default` = 0');
  381. $connect->query('
  382. UPDATE groups SET', [
  383. 'default' => 1
  384. ], '
  385. WHERE id=?', $array['data']['id']);
  386. writeLog('success', 'Group Management Function - Changed Default Group from ['.$array['data']['oldGroupName'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  387. return true;
  388. } catch (Dibi\Exception $e) {
  389. return false;
  390. }
  391. break;
  392. case 'deleteUserGroup':
  393. try {
  394. $connect = new Dibi\Connection([
  395. 'driver' => 'sqlite3',
  396. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  397. ]);
  398. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  399. writeLog('success', 'Group Management Function - Deleted Group ['.$array['data']['groupName'].']', $GLOBALS['organizrUser']['username']);
  400. return true;
  401. } catch (Dibi\Exception $e) {
  402. return false;
  403. }
  404. break;
  405. case 'addUserGroup':
  406. try {
  407. $connect = new Dibi\Connection([
  408. 'driver' => 'sqlite3',
  409. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  410. ]);
  411. $newGroup = [
  412. 'group' => $array['data']['newGroupName'],
  413. 'group_id' => $array['data']['newGroupID'],
  414. 'default' => false,
  415. 'image' => $array['data']['newGroupImage'],
  416. ];
  417. $connect->query('INSERT INTO [groups]', $newGroup);
  418. writeLog('success', 'Group Management Function - Added Group ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  419. return true;
  420. } catch (Dibi\Exception $e) {
  421. return false;
  422. }
  423. break;
  424. case 'editUserGroup':
  425. try {
  426. $connect = new Dibi\Connection([
  427. 'driver' => 'sqlite3',
  428. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  429. ]);
  430. $connect->query('
  431. UPDATE groups SET', [
  432. 'group' => $array['data']['groupName'],
  433. 'image' => $array['data']['groupImage'],
  434. ], '
  435. WHERE id=?', $array['data']['id']);
  436. writeLog('success', 'Group Management Function - Edited Group Info for ['.$array['data']['oldGroupName'].']', $GLOBALS['organizrUser']['username']);
  437. return true;
  438. } catch (Dibi\Exception $e) {
  439. return false;
  440. }
  441. break;
  442. default:
  443. # code...
  444. break;
  445. }
  446. }
  447. function adminEditUser($array){
  448. switch ($array['data']['action']) {
  449. case 'changeGroup':
  450. try {
  451. $connect = new Dibi\Connection([
  452. 'driver' => 'sqlite3',
  453. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  454. ]);
  455. $connect->query('
  456. UPDATE users SET', [
  457. 'group' => $array['data']['newGroupName'],
  458. 'group_id' => $array['data']['newGroupID'],
  459. ], '
  460. WHERE id=?', $array['data']['id']);
  461. writeLog('success', 'User Management Function - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  462. return true;
  463. } catch (Dibi\Exception $e) {
  464. writeLog('error', 'User Management Function - Error - User: '.$array['data']['username'].'\'s group was changed from ['.$array['data']['oldGroup'].'] to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  465. return false;
  466. }
  467. break;
  468. case 'addNewUser':
  469. $defaults = defaultUserGroup();
  470. if(createUser($array['data']['username'],$array['data']['password'],$defaults,$array['data']['email'])){
  471. writeLog('success', 'Create User Function - Acount created for ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  472. return true;
  473. }else{
  474. writeLog('error', 'Registration Function - An error occured', $GLOBALS['organizrUser']['username']);
  475. return 'username taken';
  476. }
  477. break;
  478. case 'deleteUser':
  479. try {
  480. $connect = new Dibi\Connection([
  481. 'driver' => 'sqlite3',
  482. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  483. ]);
  484. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  485. writeLog('success', 'User Management Function - Deleted User ['.$array['data']['username'].']', $GLOBALS['organizrUser']['username']);
  486. return true;
  487. } catch (Dibi\Exception $e) {
  488. return false;
  489. }
  490. break;
  491. default:
  492. # code...
  493. break;
  494. }
  495. }
  496. function editTabs($array){
  497. switch ($array['data']['action']) {
  498. case 'changeGroup':
  499. try {
  500. $connect = new Dibi\Connection([
  501. 'driver' => 'sqlite3',
  502. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  503. ]);
  504. $connect->query('
  505. UPDATE tabs SET', [
  506. 'group_id' => $array['data']['newGroupID'],
  507. ], '
  508. WHERE id=?', $array['data']['id']);
  509. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s group was changed to ['.$array['data']['newGroupName'].']', $GLOBALS['organizrUser']['username']);
  510. return true;
  511. } catch (Dibi\Exception $e) {
  512. return false;
  513. }
  514. break;
  515. case 'changeCategory':
  516. try {
  517. $connect = new Dibi\Connection([
  518. 'driver' => 'sqlite3',
  519. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  520. ]);
  521. $connect->query('
  522. UPDATE tabs SET', [
  523. 'category_id' => $array['data']['newCategoryID'],
  524. ], '
  525. WHERE id=?', $array['data']['id']);
  526. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s category was changed to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  527. return true;
  528. } catch (Dibi\Exception $e) {
  529. return false;
  530. }
  531. break;
  532. case 'changeType':
  533. try {
  534. $connect = new Dibi\Connection([
  535. 'driver' => 'sqlite3',
  536. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  537. ]);
  538. $connect->query('
  539. UPDATE tabs SET', [
  540. 'type' => $array['data']['newTypeID'],
  541. ], '
  542. WHERE id=?', $array['data']['id']);
  543. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s type was changed to ['.$array['data']['newTypeName'].']', $GLOBALS['organizrUser']['username']);
  544. return true;
  545. } catch (Dibi\Exception $e) {
  546. return false;
  547. }
  548. break;
  549. case 'changeEnabled':
  550. try {
  551. $connect = new Dibi\Connection([
  552. 'driver' => 'sqlite3',
  553. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  554. ]);
  555. $connect->query('
  556. UPDATE tabs SET', [
  557. 'enabled' => $array['data']['tabEnabled'],
  558. ], '
  559. WHERE id=?', $array['data']['id']);
  560. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s enable status was changed to ['.$array['data']['tabEnabledWord'].']', $GLOBALS['organizrUser']['username']);
  561. return true;
  562. } catch (Dibi\Exception $e) {
  563. return false;
  564. }
  565. break;
  566. case 'changeSplash':
  567. try {
  568. $connect = new Dibi\Connection([
  569. 'driver' => 'sqlite3',
  570. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  571. ]);
  572. $connect->query('
  573. UPDATE tabs SET', [
  574. 'splash' => $array['data']['tabSplash'],
  575. ], '
  576. WHERE id=?', $array['data']['id']);
  577. writeLog('success', 'Tab Editor Function - Tab: '.$array['data']['tab'].'\'s splash status was changed to ['.$array['data']['tabSplashWord'].']', $GLOBALS['organizrUser']['username']);
  578. return true;
  579. } catch (Dibi\Exception $e) {
  580. return false;
  581. }
  582. break;
  583. case 'changeDefault':
  584. try {
  585. $connect = new Dibi\Connection([
  586. 'driver' => 'sqlite3',
  587. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  588. ]);
  589. $connect->query('UPDATE tabs SET `default` = 0');
  590. $connect->query('
  591. UPDATE tabs SET', [
  592. 'default' => 1
  593. ], '
  594. WHERE id=?', $array['data']['id']);
  595. writeLog('success', 'Tab Editor Function - Changed Default Tab to ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  596. return true;
  597. } catch (Dibi\Exception $e) {
  598. return false;
  599. }
  600. break;
  601. case 'deleteTab':
  602. try {
  603. $connect = new Dibi\Connection([
  604. 'driver' => 'sqlite3',
  605. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  606. ]);
  607. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  608. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['tab'].']', $GLOBALS['organizrUser']['username']);
  609. return true;
  610. } catch (Dibi\Exception $e) {
  611. return false;
  612. }
  613. break;
  614. case 'editTab':
  615. try {
  616. $connect = new Dibi\Connection([
  617. 'driver' => 'sqlite3',
  618. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  619. ]);
  620. $connect->query('
  621. UPDATE tabs SET', [
  622. 'name' => $array['data']['tabName'],
  623. 'url' => $array['data']['tabURL'],
  624. 'image' => $array['data']['tabImage'],
  625. ], '
  626. WHERE id=?', $array['data']['id']);
  627. writeLog('success', 'Tab Editor Function - Edited Tab Info for ['.$array['data']['tabName'].']', $GLOBALS['organizrUser']['username']);
  628. return true;
  629. } catch (Dibi\Exception $e) {
  630. return false;
  631. }
  632. case 'changeOrder':
  633. try {
  634. $connect = new Dibi\Connection([
  635. 'driver' => 'sqlite3',
  636. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  637. ]);
  638. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  639. if($value['order'] != $value['originalOrder']){
  640. $connect->query('
  641. UPDATE tabs SET', [
  642. 'order' => $value['order'],
  643. ], '
  644. WHERE id=?', $value['id']);
  645. writeLog('success', 'Tab Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  646. }
  647. }
  648. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  649. return true;
  650. } catch (Dibi\Exception $e) {
  651. return false;
  652. }
  653. break;
  654. case 'addNewTab':
  655. try {
  656. $default = defaulTabCategory()['category_id'];
  657. $connect = new Dibi\Connection([
  658. 'driver' => 'sqlite3',
  659. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  660. ]);
  661. $newTab = [
  662. 'order' => $array['data']['tabOrder'],
  663. 'category_id' => $default,
  664. 'name' => $array['data']['tabName'],
  665. 'url' => $array['data']['tabURL'],
  666. 'default' => $array['data']['tabDefault'],
  667. 'enabled' => 1,
  668. 'group_id' => $array['data']['tabGroupID'],
  669. 'image' => $array['data']['tabImage'],
  670. 'type' => $array['data']['tabType']
  671. ];
  672. $connect->query('INSERT INTO [tabs]', $newTab);
  673. writeLog('success', 'Tab Editor Function - Created Tab for: '.$array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  674. return true;
  675. } catch (Dibi\Exception $e) {
  676. return false;
  677. }
  678. break;
  679. case 'deleteTab':
  680. try {
  681. $connect = new Dibi\Connection([
  682. 'driver' => 'sqlite3',
  683. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  684. ]);
  685. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  686. writeLog('success', 'Tab Editor Function - Deleted Tab ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  687. return true;
  688. } catch (Dibi\Exception $e) {
  689. return false;
  690. }
  691. break;
  692. default:
  693. # code...
  694. break;
  695. }
  696. }
  697. function editCategories($array){
  698. switch ($array['data']['action']) {
  699. case 'changeDefault':
  700. try {
  701. $connect = new Dibi\Connection([
  702. 'driver' => 'sqlite3',
  703. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  704. ]);
  705. $connect->query('UPDATE categories SET `default` = 0');
  706. $connect->query('
  707. UPDATE categories SET', [
  708. 'default' => 1
  709. ], '
  710. WHERE id=?', $array['data']['id']);
  711. writeLog('success', 'Category Editor Function - Changed Default Category from ['.$array['data']['oldCategoryName'].'] to ['.$array['data']['newCategoryName'].']', $GLOBALS['organizrUser']['username']);
  712. return true;
  713. } catch (Dibi\Exception $e) {
  714. return false;
  715. }
  716. break;
  717. case 'deleteCategory':
  718. try {
  719. $connect = new Dibi\Connection([
  720. 'driver' => 'sqlite3',
  721. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  722. ]);
  723. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  724. writeLog('success', 'Category Editor Function - Deleted Category ['.$array['data']['category'].']', $GLOBALS['organizrUser']['username']);
  725. return true;
  726. } catch (Dibi\Exception $e) {
  727. return false;
  728. }
  729. break;
  730. case 'addNewCategory':
  731. try {
  732. $connect = new Dibi\Connection([
  733. 'driver' => 'sqlite3',
  734. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  735. ]);
  736. $newCategory = [
  737. 'category' => $array['data']['categoryName'],
  738. 'order' => $array['data']['categoryOrder'],
  739. 'category_id' => $array['data']['categoryID'],
  740. 'default' => false,
  741. 'image' => $array['data']['categoryImage'],
  742. ];
  743. $connect->query('INSERT INTO [categories]', $newCategory);
  744. writeLog('success', 'Category Editor Function - Added Category ['.$array['data']['categoryName'].']', $GLOBALS['organizrUser']['username']);
  745. return true;
  746. } catch (Dibi\Exception $e) {
  747. return $e;
  748. }
  749. break;
  750. case 'editCategory':
  751. try {
  752. $connect = new Dibi\Connection([
  753. 'driver' => 'sqlite3',
  754. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  755. ]);
  756. $connect->query('
  757. UPDATE categories SET', [
  758. 'category' => $array['data']['name'],
  759. 'image' => $array['data']['image'],
  760. ], '
  761. WHERE id=?', $array['data']['id']);
  762. writeLog('success', 'Category Editor Function - Edited Category Info for ['.$array['data']['name'].']', $GLOBALS['organizrUser']['username']);
  763. return true;
  764. } catch (Dibi\Exception $e) {
  765. return false;
  766. }
  767. break;
  768. case 'changeOrder':
  769. try {
  770. $connect = new Dibi\Connection([
  771. 'driver' => 'sqlite3',
  772. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  773. ]);
  774. foreach ($array['data']['categories']['category'] as $key => $value) {
  775. if($value['order'] != $value['originalOrder']){
  776. $connect->query('
  777. UPDATE categories SET', [
  778. 'order' => $value['order'],
  779. ], '
  780. WHERE id=?', $value['id']);
  781. writeLog('success', 'Category Editor Function - '.$value['name'].' Order Changed From '.$value['order'].' to '.$value['originalOrder'], $GLOBALS['organizrUser']['username']);
  782. }
  783. }
  784. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  785. return true;
  786. } catch (Dibi\Exception $e) {
  787. return false;
  788. }
  789. break;
  790. default:
  791. # code...
  792. break;
  793. }
  794. }
  795. function allUsers(){
  796. try {
  797. $connect = new Dibi\Connection([
  798. 'driver' => 'sqlite3',
  799. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  800. ]);
  801. $users = $connect->fetchAll('SELECT * FROM users');
  802. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  803. foreach ($users as $k => $v) {
  804. // clear password from array
  805. unset($users[$k]['password']);
  806. }
  807. $all['users'] = $users;
  808. $all['groups'] = $groups;
  809. return $all;
  810. } catch (Dibi\Exception $e) {
  811. return false;
  812. }
  813. }
  814. function usernameTaken($username,$email){
  815. try {
  816. $connect = new Dibi\Connection([
  817. 'driver' => 'sqlite3',
  818. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  819. ]);
  820. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE',$username,$email);
  821. return ($all) ? true : false;
  822. } catch (Dibi\Exception $e) {
  823. return false;
  824. }
  825. }
  826. function createUser($username,$password,$defaults,$email=null) {
  827. $email = ($email) ? $email : random_ascii_string(10).'@placeholder.eml';
  828. try {
  829. if(!usernameTaken($username,$email)){
  830. $createDB = new Dibi\Connection([
  831. 'driver' => 'sqlite3',
  832. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  833. ]);
  834. $userInfo = [
  835. 'username' => $username,
  836. 'password' => password_hash($password, PASSWORD_BCRYPT),
  837. 'email' => $email,
  838. 'group' => $defaults['group'],
  839. 'group_id' => $defaults['group_id'],
  840. 'image' => gravatar($email),
  841. 'register_date' => $GLOBALS['currentTime'],
  842. ];
  843. $createDB->query('INSERT INTO [users]', $userInfo);
  844. return true;
  845. }else{
  846. return false;
  847. }
  848. } catch (Dibi\Exception $e) {
  849. return false;
  850. }
  851. }
  852. function allTabs(){
  853. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  854. try {
  855. $connect = new Dibi\Connection([
  856. 'driver' => 'sqlite3',
  857. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  858. ]);
  859. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  860. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  861. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  862. return $all;
  863. } catch (Dibi\Exception $e) {
  864. return false;
  865. }
  866. }
  867. }
  868. function loadTabs(){
  869. if(file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  870. try {
  871. $connect = new Dibi\Connection([
  872. 'driver' => 'sqlite3',
  873. 'database' => $GLOBALS['dbLocation'].$GLOBALS['dbName'],
  874. ]);
  875. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` DESC',$GLOBALS['organizrUser']['groupID']);
  876. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  877. $all['tabs'] = $tabs;
  878. foreach ($tabs as $k => $v) {
  879. $v['access_url'] = isset($v['url_local']) && $_SERVER['SERVER_ADDR'] == userIP() ? $v['url_local'] : $v['url'];
  880. }
  881. $count = array_map(function($element){
  882. return $element['category_id'];
  883. }, $tabs);
  884. $count = (array_count_values($count));
  885. foreach ($categories as $k => $v) {
  886. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  887. }
  888. $all['categories'] = $categories;
  889. return $all;
  890. } catch (Dibi\Exception $e) {
  891. return false;
  892. }
  893. }
  894. }