api-functions.php 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973
  1. <?php
  2. function login($array)
  3. {
  4. // Grab username and Password from login form
  5. foreach ($array['data'] as $items) {
  6. foreach ($items as $key => $value) {
  7. if ($key == 'name') {
  8. $newKey = $value;
  9. }
  10. if ($key == 'value') {
  11. $newValue = $value;
  12. }
  13. if (isset($newKey) && isset($newValue)) {
  14. $$newKey = $newValue;
  15. }
  16. }
  17. }
  18. $username = strtolower($username);
  19. $days = (isset($remember)) ? 7 : 1;
  20. try {
  21. $database = new Dibi\Connection([
  22. 'driver' => 'sqlite3',
  23. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  24. ]);
  25. $authSuccess = false;
  26. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  27. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  28. switch ($GLOBALS['authType']) {
  29. case 'external':
  30. if (function_exists($function)) {
  31. $authSuccess = $function($username, $password);
  32. }
  33. break;
  34. case 'both':
  35. if (function_exists($function)) {
  36. $authSuccess = $function($username, $password);
  37. }
  38. // no break
  39. default: // Internal
  40. if (!$authSuccess) {
  41. // perform the internal authentication step
  42. if (password_verify($password, $result['password'])) {
  43. $authSuccess = true;
  44. }
  45. }
  46. }
  47. if ($authSuccess) {
  48. // Make sure user exists in database
  49. $userExists = false;
  50. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  51. if ($result['username']) {
  52. $userExists = true;
  53. $username = $result['username'];
  54. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  55. }
  56. if ($userExists) {
  57. //does org password need to be updated
  58. if (!$passwordMatches) {
  59. $database->query('
  60. UPDATE users SET', [
  61. 'password' => password_hash($password, PASSWORD_BCRYPT)
  62. ], '
  63. WHERE id=?', $result['id']);
  64. writeLog('success', 'Login Function - User Password updated from backend', $username);
  65. }
  66. // authentication passed - 1) mark active and update token
  67. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  68. writeLoginLog($username, 'success');
  69. writeLog('success', 'Login Function - A User has logged in', $username);
  70. ssoCheck($username, $password, $token); //need to work on this
  71. return true;
  72. } else {
  73. return 'error';
  74. }
  75. } else {
  76. // Create User
  77. ssoCheck($username, $password, $token);
  78. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  79. }
  80. } else {
  81. // authentication failed
  82. writeLoginLog($username, 'error');
  83. writeLog('error', 'Login Function - Wrong Password', $username);
  84. return 'mismatch';
  85. }
  86. } catch (Dibi\Exception $e) {
  87. return 'error';
  88. }
  89. }
  90. function createDB($path, $filename)
  91. {
  92. try {
  93. if (!file_exists($path)) {
  94. mkdir($path, 0777, true);
  95. }
  96. $createDB = new Dibi\Connection([
  97. 'driver' => 'sqlite3',
  98. 'database' => $path . $filename,
  99. ]);
  100. // Create Users
  101. $users = $createDB->query('CREATE TABLE `users` (
  102. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  103. `username` TEXT UNIQUE,
  104. `password` TEXT,
  105. `email` TEXT,
  106. `plex_token` TEXT,
  107. `group` TEXT,
  108. `group_id` INTEGER,
  109. `locked` INTEGER,
  110. `image` TEXT,
  111. `register_date` DATE,
  112. `auth_service` TEXT DEFAULT \'internal\'
  113. );');
  114. // Create Tokens
  115. $jwt = $createDB->query('CREATE TABLE `tokens` (
  116. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  117. `token` TEXT UNIQUE,
  118. `user_id` INTEGER,
  119. `created` DATE,
  120. `expires` DATE
  121. );');
  122. $groups = $createDB->query('CREATE TABLE `groups` (
  123. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  124. `group` TEXT UNIQUE,
  125. `group_id` INTEGER,
  126. `image` TEXT,
  127. `default` INTEGER
  128. );');
  129. $categories = $createDB->query('CREATE TABLE `categories` (
  130. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  131. `order` INTEGER,
  132. `category` TEXT UNIQUE,
  133. `category_id` INTEGER,
  134. `image` TEXT,
  135. `default` INTEGER
  136. );');
  137. // Create Tabs
  138. $tabs = $createDB->query('CREATE TABLE `tabs` (
  139. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  140. `order` INTEGER,
  141. `category_id` INTEGER,
  142. `name` TEXT,
  143. `url` TEXT,
  144. `url_local` TEXT,
  145. `default` INTEGER,
  146. `enabled` INTEGER,
  147. `group_id` INTEGER,
  148. `image` TEXT,
  149. `type` INTEGER,
  150. `splash` INTEGER,
  151. `ping` INTEGER,
  152. `ping_url` TEXT
  153. );');
  154. // Create Options
  155. $options = $createDB->query('CREATE TABLE `options` (
  156. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  157. `name` TEXT UNIQUE,
  158. `value` TEXT
  159. );');
  160. // Create Invites
  161. $invites = $createDB->query('CREATE TABLE `invites` (
  162. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  163. `code` TEXT UNIQUE,
  164. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  165. `email` TEXT,
  166. `username` TEXT,
  167. `dateused` TIMESTAMP,
  168. `usedby` TEXT,
  169. `ip` TEXT,
  170. `valid` TEXT,
  171. `type` TEXT
  172. );');
  173. return true;
  174. } catch (Dibi\Exception $e) {
  175. return false;
  176. }
  177. }
  178. // Upgrade Database
  179. function updateDB($path, $filename, $oldVerNum = false)
  180. {
  181. try {
  182. $connect = new Dibi\Connection([
  183. 'driver' => 'sqlite3',
  184. 'database' => $path . $filename,
  185. ]);
  186. // Cache current DB
  187. $cache = array();
  188. foreach ($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  189. foreach ($connect->query('SELECT * FROM ' . $table['name'] . ';') as $key => $row) {
  190. foreach ($row as $k => $v) {
  191. if (is_string($k)) {
  192. $cache[$table['name']][$key][$k] = $v;
  193. }
  194. }
  195. }
  196. }
  197. $connect->disconnect();
  198. } catch (Dibi\Exception $e) {
  199. return $e;
  200. }
  201. // Remove Current Database
  202. $pathDigest = pathinfo($path . $filename);
  203. if (file_exists($path . $filename)) {
  204. copy($path . $filename, $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db');
  205. unlink($path . $filename);
  206. }
  207. // Create New Database
  208. $success = createDB($path, $filename);
  209. try {
  210. $GLOBALS['connect'] = new Dibi\Connection([
  211. 'driver' => 'sqlite3',
  212. 'database' => $path . $filename,
  213. ]);
  214. // Restore Items
  215. if ($success) {
  216. foreach ($cache as $table => $tableData) {
  217. if ($tableData) {
  218. $queryBase = 'INSERT INTO ' . $table . ' (`' . implode('`,`', array_keys(current($tableData))) . '`) values ';
  219. $insertValues = array();
  220. reset($tableData);
  221. foreach ($tableData as $key => $value) {
  222. $insertValues[] = '(' . implode(',', array_map(function ($d) {
  223. return (isset($d) ? str_replace('\/', '/', json_encode($d)) : 'null');
  224. }, $value)) . ')';
  225. }
  226. $GLOBALS['connect']->query($queryBase . implode(',', $insertValues) . ';');
  227. }
  228. }
  229. }
  230. updateConfig(array('configVersion' => $GLOBALS['installedVersion']));
  231. return true;
  232. } catch (Dibi\Exception $e) {
  233. return $e;
  234. }
  235. }
  236. function createFirstAdmin($path, $filename, $username, $password, $email)
  237. {
  238. try {
  239. $createDB = new Dibi\Connection([
  240. 'driver' => 'sqlite3',
  241. 'database' => $path . $filename,
  242. ]);
  243. $userInfo = [
  244. 'username' => $username,
  245. 'password' => password_hash($password, PASSWORD_BCRYPT),
  246. 'email' => $email,
  247. 'group' => 'Admin',
  248. 'group_id' => 0,
  249. 'image' => gravatar($email),
  250. 'register_date' => $GLOBALS['currentTime'],
  251. ];
  252. $groupInfo0 = [
  253. 'group' => 'Admin',
  254. 'group_id' => 0,
  255. 'default' => false,
  256. 'image' => 'plugins/images/groups/admin.png',
  257. ];
  258. $groupInfo1 = [
  259. 'group' => 'Co-Admin',
  260. 'group_id' => 1,
  261. 'default' => false,
  262. 'image' => 'plugins/images/groups/coadmin.png',
  263. ];
  264. $groupInfo2 = [
  265. 'group' => 'Super User',
  266. 'group_id' => 2,
  267. 'default' => false,
  268. 'image' => 'plugins/images/groups/superuser.png',
  269. ];
  270. $groupInfo3 = [
  271. 'group' => 'Power User',
  272. 'group_id' => 3,
  273. 'default' => false,
  274. 'image' => 'plugins/images/groups/poweruser.png',
  275. ];
  276. $groupInfo4 = [
  277. 'group' => 'User',
  278. 'group_id' => 4,
  279. 'default' => true,
  280. 'image' => 'plugins/images/groups/user.png',
  281. ];
  282. $groupInfoGuest = [
  283. 'group' => 'Guest',
  284. 'group_id' => 999,
  285. 'default' => false,
  286. 'image' => 'plugins/images/groups/guest.png',
  287. ];
  288. $settingsInfo = [
  289. 'order' => 1,
  290. 'category_id' => 0,
  291. 'name' => 'Settings',
  292. 'url' => 'api/?v1/settings/page',
  293. 'default' => false,
  294. 'enabled' => true,
  295. 'group_id' => 1,
  296. 'image' => 'fontawesome::cog',
  297. 'type' => 0
  298. ];
  299. $homepageInfo = [
  300. 'order' => 2,
  301. 'category_id' => 0,
  302. 'name' => 'Homepage',
  303. 'url' => 'api/?v1/homepage/page',
  304. 'default' => false,
  305. 'enabled' => false,
  306. 'group_id' => 4,
  307. 'image' => 'fontawesome::home',
  308. 'type' => 0
  309. ];
  310. $unsortedInfo = [
  311. 'order' => 1,
  312. 'category' => 'Unsorted',
  313. 'category_id' => 0,
  314. 'image' => 'plugins/images/categories/unsorted.png',
  315. 'default' => true
  316. ];
  317. $createDB->query('INSERT INTO [users]', $userInfo);
  318. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  319. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  320. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  321. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  322. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  323. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  324. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  325. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  326. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  327. return true;
  328. } catch (Dibi\Exception $e) {
  329. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  330. return false;
  331. }
  332. }
  333. function defaultUserGroup()
  334. {
  335. try {
  336. $connect = new Dibi\Connection([
  337. 'driver' => 'sqlite3',
  338. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  339. ]);
  340. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  341. return $all;
  342. } catch (Dibi\Exception $e) {
  343. return false;
  344. }
  345. }
  346. function defaultTabCategory()
  347. {
  348. try {
  349. $connect = new Dibi\Connection([
  350. 'driver' => 'sqlite3',
  351. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  352. ]);
  353. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  354. return $all;
  355. } catch (Dibi\Exception $e) {
  356. return false;
  357. }
  358. }
  359. function getGuest()
  360. {
  361. if (isset($GLOBALS['dbLocation'])) {
  362. try {
  363. $connect = new Dibi\Connection([
  364. 'driver' => 'sqlite3',
  365. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  366. ]);
  367. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  368. return $all;
  369. } catch (Dibi\Exception $e) {
  370. return false;
  371. }
  372. } else {
  373. return array(
  374. 'group' => 'Guest',
  375. 'group_id' => 999,
  376. 'image' => 'plugins/images/groups/guest.png'
  377. );
  378. }
  379. }
  380. function adminEditGroup($array)
  381. {
  382. switch ($array['data']['action']) {
  383. case 'changeDefaultGroup':
  384. try {
  385. $connect = new Dibi\Connection([
  386. 'driver' => 'sqlite3',
  387. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  388. ]);
  389. $connect->query('UPDATE groups SET `default` = 0');
  390. $connect->query('
  391. UPDATE groups SET', [
  392. 'default' => 1
  393. ], '
  394. WHERE id=?', $array['data']['id']);
  395. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  396. return true;
  397. } catch (Dibi\Exception $e) {
  398. return false;
  399. }
  400. break;
  401. case 'deleteUserGroup':
  402. try {
  403. $connect = new Dibi\Connection([
  404. 'driver' => 'sqlite3',
  405. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  406. ]);
  407. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  408. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  409. return true;
  410. } catch (Dibi\Exception $e) {
  411. return false;
  412. }
  413. break;
  414. case 'addUserGroup':
  415. try {
  416. $connect = new Dibi\Connection([
  417. 'driver' => 'sqlite3',
  418. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  419. ]);
  420. $newGroup = [
  421. 'group' => $array['data']['newGroupName'],
  422. 'group_id' => $array['data']['newGroupID'],
  423. 'default' => false,
  424. 'image' => $array['data']['newGroupImage'],
  425. ];
  426. $connect->query('INSERT INTO [groups]', $newGroup);
  427. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  428. return true;
  429. } catch (Dibi\Exception $e) {
  430. return false;
  431. }
  432. break;
  433. case 'editUserGroup':
  434. try {
  435. $connect = new Dibi\Connection([
  436. 'driver' => 'sqlite3',
  437. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  438. ]);
  439. $connect->query('
  440. UPDATE groups SET', [
  441. 'group' => $array['data']['groupName'],
  442. 'image' => $array['data']['groupImage'],
  443. ], '
  444. WHERE id=?', $array['data']['id']);
  445. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  446. return true;
  447. } catch (Dibi\Exception $e) {
  448. return false;
  449. }
  450. break;
  451. default:
  452. # code...
  453. break;
  454. }
  455. }
  456. function adminEditUser($array)
  457. {
  458. switch ($array['data']['action']) {
  459. case 'changeGroup':
  460. try {
  461. $connect = new Dibi\Connection([
  462. 'driver' => 'sqlite3',
  463. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  464. ]);
  465. $connect->query('
  466. UPDATE users SET', [
  467. 'group' => $array['data']['newGroupName'],
  468. 'group_id' => $array['data']['newGroupID'],
  469. ], '
  470. WHERE id=?', $array['data']['id']);
  471. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  472. return true;
  473. } catch (Dibi\Exception $e) {
  474. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  475. return false;
  476. }
  477. break;
  478. case 'editUser':
  479. try {
  480. $connect = new Dibi\Connection([
  481. 'driver' => 'sqlite3',
  482. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  483. ]);
  484. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  485. $connect->query('
  486. UPDATE users SET', [
  487. 'username' => $array['data']['username'],
  488. 'email' => $array['data']['email'],
  489. ], '
  490. WHERE id=?', $array['data']['id']);
  491. if (!empty($array['data']['password'])) {
  492. $connect->query('
  493. UPDATE users SET', [
  494. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  495. ], '
  496. WHERE id=?', $array['data']['id']);
  497. }
  498. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  499. return true;
  500. } else {
  501. return false;
  502. }
  503. } catch (Dibi\Exception $e) {
  504. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  505. return false;
  506. }
  507. break;
  508. case 'addNewUser':
  509. $defaults = defaultUserGroup();
  510. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  511. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  512. return true;
  513. } else {
  514. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  515. return 'username taken';
  516. }
  517. break;
  518. case 'deleteUser':
  519. try {
  520. $connect = new Dibi\Connection([
  521. 'driver' => 'sqlite3',
  522. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  523. ]);
  524. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  525. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  526. return true;
  527. } catch (Dibi\Exception $e) {
  528. return false;
  529. }
  530. break;
  531. default:
  532. # code...
  533. break;
  534. }
  535. }
  536. function editTabs($array)
  537. {
  538. switch ($array['data']['action']) {
  539. case 'changeGroup':
  540. try {
  541. $connect = new Dibi\Connection([
  542. 'driver' => 'sqlite3',
  543. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  544. ]);
  545. $connect->query('
  546. UPDATE tabs SET', [
  547. 'group_id' => $array['data']['newGroupID'],
  548. ], '
  549. WHERE id=?', $array['data']['id']);
  550. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  551. return true;
  552. } catch (Dibi\Exception $e) {
  553. return false;
  554. }
  555. break;
  556. case 'changeCategory':
  557. try {
  558. $connect = new Dibi\Connection([
  559. 'driver' => 'sqlite3',
  560. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  561. ]);
  562. $connect->query('
  563. UPDATE tabs SET', [
  564. 'category_id' => $array['data']['newCategoryID'],
  565. ], '
  566. WHERE id=?', $array['data']['id']);
  567. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  568. return true;
  569. } catch (Dibi\Exception $e) {
  570. return false;
  571. }
  572. break;
  573. case 'changeType':
  574. try {
  575. $connect = new Dibi\Connection([
  576. 'driver' => 'sqlite3',
  577. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  578. ]);
  579. $connect->query('
  580. UPDATE tabs SET', [
  581. 'type' => $array['data']['newTypeID'],
  582. ], '
  583. WHERE id=?', $array['data']['id']);
  584. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  585. return true;
  586. } catch (Dibi\Exception $e) {
  587. return false;
  588. }
  589. break;
  590. case 'changeEnabled':
  591. try {
  592. $connect = new Dibi\Connection([
  593. 'driver' => 'sqlite3',
  594. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  595. ]);
  596. $connect->query('
  597. UPDATE tabs SET', [
  598. 'enabled' => $array['data']['tabEnabled'],
  599. ], '
  600. WHERE id=?', $array['data']['id']);
  601. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  602. return true;
  603. } catch (Dibi\Exception $e) {
  604. return false;
  605. }
  606. break;
  607. case 'changeSplash':
  608. try {
  609. $connect = new Dibi\Connection([
  610. 'driver' => 'sqlite3',
  611. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  612. ]);
  613. $connect->query('
  614. UPDATE tabs SET', [
  615. 'splash' => $array['data']['tabSplash'],
  616. ], '
  617. WHERE id=?', $array['data']['id']);
  618. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  619. return true;
  620. } catch (Dibi\Exception $e) {
  621. return false;
  622. }
  623. break;
  624. case 'changeDefault':
  625. try {
  626. $connect = new Dibi\Connection([
  627. 'driver' => 'sqlite3',
  628. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  629. ]);
  630. $connect->query('UPDATE tabs SET `default` = 0');
  631. $connect->query('
  632. UPDATE tabs SET', [
  633. 'default' => 1
  634. ], '
  635. WHERE id=?', $array['data']['id']);
  636. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  637. return true;
  638. } catch (Dibi\Exception $e) {
  639. return false;
  640. }
  641. break;
  642. case 'deleteTab':
  643. try {
  644. $connect = new Dibi\Connection([
  645. 'driver' => 'sqlite3',
  646. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  647. ]);
  648. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  649. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  650. return true;
  651. } catch (Dibi\Exception $e) {
  652. return false;
  653. }
  654. break;
  655. case 'editTab':
  656. try {
  657. $connect = new Dibi\Connection([
  658. 'driver' => 'sqlite3',
  659. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  660. ]);
  661. $connect->query('
  662. UPDATE tabs SET', [
  663. 'name' => $array['data']['tabName'],
  664. 'url' => $array['data']['tabURL'],
  665. 'image' => $array['data']['tabImage'],
  666. ], '
  667. WHERE id=?', $array['data']['id']);
  668. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  669. return true;
  670. } catch (Dibi\Exception $e) {
  671. return false;
  672. }
  673. case 'changeOrder':
  674. try {
  675. $connect = new Dibi\Connection([
  676. 'driver' => 'sqlite3',
  677. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  678. ]);
  679. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  680. if ($value['order'] != $value['originalOrder']) {
  681. $connect->query('
  682. UPDATE tabs SET', [
  683. 'order' => $value['order'],
  684. ], '
  685. WHERE id=?', $value['id']);
  686. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  687. }
  688. }
  689. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  690. return true;
  691. } catch (Dibi\Exception $e) {
  692. return false;
  693. }
  694. break;
  695. case 'addNewTab':
  696. try {
  697. $default = defaultTabCategory()['category_id'];
  698. $connect = new Dibi\Connection([
  699. 'driver' => 'sqlite3',
  700. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  701. ]);
  702. $newTab = [
  703. 'order' => $array['data']['tabOrder'],
  704. 'category_id' => $default,
  705. 'name' => $array['data']['tabName'],
  706. 'url' => $array['data']['tabURL'],
  707. 'default' => $array['data']['tabDefault'],
  708. 'enabled' => 1,
  709. 'group_id' => $array['data']['tabGroupID'],
  710. 'image' => $array['data']['tabImage'],
  711. 'type' => $array['data']['tabType']
  712. ];
  713. $connect->query('INSERT INTO [tabs]', $newTab);
  714. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  715. return true;
  716. } catch (Dibi\Exception $e) {
  717. return false;
  718. }
  719. break;
  720. default:
  721. # code...
  722. break;
  723. }
  724. }
  725. function editCategories($array)
  726. {
  727. switch ($array['data']['action']) {
  728. case 'changeDefault':
  729. try {
  730. $connect = new Dibi\Connection([
  731. 'driver' => 'sqlite3',
  732. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  733. ]);
  734. $connect->query('UPDATE categories SET `default` = 0');
  735. $connect->query('
  736. UPDATE categories SET', [
  737. 'default' => 1
  738. ], '
  739. WHERE id=?', $array['data']['id']);
  740. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  741. return true;
  742. } catch (Dibi\Exception $e) {
  743. return false;
  744. }
  745. break;
  746. case 'deleteCategory':
  747. try {
  748. $connect = new Dibi\Connection([
  749. 'driver' => 'sqlite3',
  750. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  751. ]);
  752. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  753. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  754. return true;
  755. } catch (Dibi\Exception $e) {
  756. return false;
  757. }
  758. break;
  759. case 'addNewCategory':
  760. try {
  761. $connect = new Dibi\Connection([
  762. 'driver' => 'sqlite3',
  763. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  764. ]);
  765. $newCategory = [
  766. 'category' => $array['data']['categoryName'],
  767. 'order' => $array['data']['categoryOrder'],
  768. 'category_id' => $array['data']['categoryID'],
  769. 'default' => false,
  770. 'image' => $array['data']['categoryImage'],
  771. ];
  772. $connect->query('INSERT INTO [categories]', $newCategory);
  773. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  774. return true;
  775. } catch (Dibi\Exception $e) {
  776. return $e;
  777. }
  778. break;
  779. case 'editCategory':
  780. try {
  781. $connect = new Dibi\Connection([
  782. 'driver' => 'sqlite3',
  783. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  784. ]);
  785. $connect->query('
  786. UPDATE categories SET', [
  787. 'category' => $array['data']['name'],
  788. 'image' => $array['data']['image'],
  789. ], '
  790. WHERE id=?', $array['data']['id']);
  791. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  792. return true;
  793. } catch (Dibi\Exception $e) {
  794. return false;
  795. }
  796. break;
  797. case 'changeOrder':
  798. try {
  799. $connect = new Dibi\Connection([
  800. 'driver' => 'sqlite3',
  801. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  802. ]);
  803. foreach ($array['data']['categories']['category'] as $key => $value) {
  804. if ($value['order'] != $value['originalOrder']) {
  805. $connect->query('
  806. UPDATE categories SET', [
  807. 'order' => $value['order'],
  808. ], '
  809. WHERE id=?', $value['id']);
  810. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  811. }
  812. }
  813. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  814. return true;
  815. } catch (Dibi\Exception $e) {
  816. return false;
  817. }
  818. break;
  819. default:
  820. # code...
  821. break;
  822. }
  823. }
  824. function allUsers()
  825. {
  826. try {
  827. $connect = new Dibi\Connection([
  828. 'driver' => 'sqlite3',
  829. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  830. ]);
  831. $users = $connect->fetchAll('SELECT * FROM users');
  832. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  833. foreach ($users as $k => $v) {
  834. // clear password from array
  835. unset($users[$k]['password']);
  836. }
  837. $all['users'] = $users;
  838. $all['groups'] = $groups;
  839. return $all;
  840. } catch (Dibi\Exception $e) {
  841. return false;
  842. }
  843. }
  844. function usernameTaken($username, $email)
  845. {
  846. try {
  847. $connect = new Dibi\Connection([
  848. 'driver' => 'sqlite3',
  849. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  850. ]);
  851. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  852. return ($all) ? true : false;
  853. } catch (Dibi\Exception $e) {
  854. return false;
  855. }
  856. }
  857. function usernameTakenExcept($username, $email, $id)
  858. {
  859. try {
  860. $connect = new Dibi\Connection([
  861. 'driver' => 'sqlite3',
  862. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  863. ]);
  864. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  865. return ($all) ? true : false;
  866. } catch (Dibi\Exception $e) {
  867. return false;
  868. }
  869. }
  870. function createUser($username, $password, $defaults, $email = null)
  871. {
  872. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  873. try {
  874. if (!usernameTaken($username, $email)) {
  875. $createDB = new Dibi\Connection([
  876. 'driver' => 'sqlite3',
  877. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  878. ]);
  879. $userInfo = [
  880. 'username' => $username,
  881. 'password' => password_hash($password, PASSWORD_BCRYPT),
  882. 'email' => $email,
  883. 'group' => $defaults['group'],
  884. 'group_id' => $defaults['group_id'],
  885. 'image' => gravatar($email),
  886. 'register_date' => $GLOBALS['currentTime'],
  887. ];
  888. $createDB->query('INSERT INTO [users]', $userInfo);
  889. return true;
  890. } else {
  891. return false;
  892. }
  893. } catch (Dibi\Exception $e) {
  894. return false;
  895. }
  896. }
  897. function allTabs()
  898. {
  899. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  900. try {
  901. $connect = new Dibi\Connection([
  902. 'driver' => 'sqlite3',
  903. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  904. ]);
  905. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  906. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  907. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  908. return $all;
  909. } catch (Dibi\Exception $e) {
  910. return false;
  911. }
  912. }
  913. }
  914. function allGroups()
  915. {
  916. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  917. try {
  918. $connect = new Dibi\Connection([
  919. 'driver' => 'sqlite3',
  920. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  921. ]);
  922. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  923. return $all;
  924. } catch (Dibi\Exception $e) {
  925. return false;
  926. }
  927. }
  928. }
  929. function loadTabs()
  930. {
  931. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  932. try {
  933. $connect = new Dibi\Connection([
  934. 'driver' => 'sqlite3',
  935. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  936. ]);
  937. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` DESC', $GLOBALS['organizrUser']['groupID']);
  938. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  939. $all['tabs'] = $tabs;
  940. foreach ($tabs as $k => $v) {
  941. $v['access_url'] = isset($v['url_local']) && $_SERVER['SERVER_ADDR'] == userIP() ? $v['url_local'] : $v['url'];
  942. }
  943. $count = array_map(function ($element) {
  944. return $element['category_id'];
  945. }, $tabs);
  946. $count = (array_count_values($count));
  947. foreach ($categories as $k => $v) {
  948. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  949. }
  950. $all['categories'] = $categories;
  951. return $all;
  952. } catch (Dibi\Exception $e) {
  953. return false;
  954. }
  955. }
  956. }