index.php 38 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352
  1. <?php
  2. $generationTime = -microtime(true);
  3. //include functions
  4. require_once 'functions.php';
  5. //Set result array
  6. $result = array();
  7. //Get request method
  8. $method = $_SERVER['REQUEST_METHOD'];
  9. $pretty = isset($_GET['pretty']) ? true : false;
  10. reset($_GET);
  11. $function = (key($_GET) ? str_replace("/", "_", key($_GET)) : false);
  12. //Exit if $function is blank
  13. if ($function === false) {
  14. $result['status'] = "error";
  15. $result['statusText'] = "No API Path Supplied";
  16. exit(json_encode($result));
  17. }
  18. $approvedFunctionsBypass = array(
  19. 'v1_upgrade',
  20. 'v1_update',
  21. 'v1_force',
  22. 'v1_auth',
  23. 'v1_wizard_config',
  24. 'v1_login',
  25. 'v1_wizard_path',
  26. );
  27. if (!in_array($function, $approvedFunctionsBypass)) {
  28. if (isApprovedRequest($method) === false) {
  29. $result['status'] = "error";
  30. $result['statusText'] = "Not Authorized";
  31. writeLog('success', 'Killed Attack From [' . (isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : 'No Referer') . ']', $GLOBALS['organizrUser']['username']);
  32. exit(json_encode($result));
  33. }
  34. }
  35. $result['request'] = key($_GET);
  36. $result['params'] = $_POST;
  37. switch ($function) {
  38. case 'v1_settings_page':
  39. switch ($method) {
  40. case 'GET':
  41. if (qualifyRequest(1)) {
  42. $result['status'] = 'success';
  43. $result['statusText'] = 'success';
  44. $result['data'] = $pageSettings;
  45. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  46. } else {
  47. $result['status'] = 'error';
  48. $result['statusText'] = 'API/Token invalid or not set';
  49. $result['data'] = null;
  50. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  51. }
  52. break;
  53. default:
  54. $result['status'] = 'error';
  55. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  56. break;
  57. }
  58. break;
  59. case 'v1_homepage_page':
  60. switch ($method) {
  61. case 'GET':
  62. $result['status'] = 'success';
  63. $result['statusText'] = 'success';
  64. $result['data'] = $pageHomepage;
  65. break;
  66. default:
  67. $result['status'] = 'error';
  68. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  69. break;
  70. }
  71. break;
  72. case 'v1_settings_plugins':
  73. switch ($method) {
  74. case 'GET':
  75. if (qualifyRequest(1)) {
  76. $result['status'] = 'success';
  77. $result['statusText'] = 'success';
  78. $result['data'] = $pageSettingsPlugins;
  79. } else {
  80. $result['status'] = 'error';
  81. $result['statusText'] = 'API/Token invalid or not set';
  82. $result['data'] = null;
  83. }
  84. break;
  85. default:
  86. $result['status'] = 'error';
  87. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  88. break;
  89. }
  90. break;
  91. case 'v1_settings_tab_editor_homepage':
  92. switch ($method) {
  93. case 'GET':
  94. if (qualifyRequest(1)) {
  95. $result['status'] = 'success';
  96. $result['statusText'] = 'success';
  97. $result['data'] = $pageSettingsTabEditorHomepage;
  98. } else {
  99. $result['status'] = 'error';
  100. $result['statusText'] = 'API/Token invalid or not set';
  101. $result['data'] = null;
  102. }
  103. break;
  104. default:
  105. $result['status'] = 'error';
  106. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  107. break;
  108. }
  109. break;
  110. case 'v1_settings_tab_editor_homepage_order':
  111. switch ($method) {
  112. case 'GET':
  113. if (qualifyRequest(1)) {
  114. $result['status'] = 'success';
  115. $result['statusText'] = 'success';
  116. $result['data'] = $pageSettingsTabEditorHomepageOrder;
  117. } else {
  118. $result['status'] = 'error';
  119. $result['statusText'] = 'API/Token invalid or not set';
  120. $result['data'] = null;
  121. }
  122. break;
  123. default:
  124. $result['status'] = 'error';
  125. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  126. break;
  127. }
  128. break;
  129. case 'v1_settings_homepage_list':
  130. switch ($method) {
  131. case 'GET':
  132. if (qualifyRequest(1)) {
  133. $result['status'] = 'success';
  134. $result['statusText'] = 'success';
  135. $result['data'] = getHomepageList();
  136. } else {
  137. $result['status'] = 'error';
  138. $result['statusText'] = 'API/Token invalid or not set';
  139. $result['data'] = null;
  140. }
  141. break;
  142. case 'POST':
  143. if (qualifyRequest(1)) {
  144. $result['status'] = 'success';
  145. $result['statusText'] = 'success';
  146. $result['data'] = editPlugins($_POST);
  147. } else {
  148. $result['status'] = 'error';
  149. $result['statusText'] = 'API/Token invalid or not set';
  150. $result['data'] = null;
  151. }
  152. break;
  153. default:
  154. $result['status'] = 'error';
  155. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  156. break;
  157. }
  158. break;
  159. case 'v1_settings_plugins_list':
  160. switch ($method) {
  161. case 'GET':
  162. if (qualifyRequest(1)) {
  163. $result['status'] = 'success';
  164. $result['statusText'] = 'success';
  165. $result['data'] = getPlugins();
  166. } else {
  167. $result['status'] = 'error';
  168. $result['statusText'] = 'API/Token invalid or not set';
  169. $result['data'] = null;
  170. }
  171. break;
  172. case 'POST':
  173. if (qualifyRequest(1)) {
  174. $result['status'] = 'success';
  175. $result['statusText'] = 'success';
  176. $result['data'] = editPlugins($_POST);
  177. } else {
  178. $result['status'] = 'error';
  179. $result['statusText'] = 'API/Token invalid or not set';
  180. $result['data'] = null;
  181. }
  182. break;
  183. default:
  184. $result['status'] = 'error';
  185. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  186. break;
  187. }
  188. break;
  189. case 'v1_settings_settings_logs':
  190. switch ($method) {
  191. case 'GET':
  192. if (qualifyRequest(1)) {
  193. $result['status'] = 'success';
  194. $result['statusText'] = 'success';
  195. $result['data'] = $pageSettingsSettingsLogs;
  196. } else {
  197. $result['status'] = 'error';
  198. $result['statusText'] = 'API/Token invalid or not set';
  199. $result['data'] = null;
  200. }
  201. break;
  202. default:
  203. $result['status'] = 'error';
  204. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  205. break;
  206. }
  207. break;
  208. case 'v1_settings_settings_sso':
  209. switch ($method) {
  210. case 'GET':
  211. if (qualifyRequest(1)) {
  212. $result['status'] = 'success';
  213. $result['statusText'] = 'success';
  214. $result['data'] = $pageSettingsSettingsSSO;
  215. } else {
  216. $result['status'] = 'error';
  217. $result['statusText'] = 'API/Token invalid or not set';
  218. $result['data'] = null;
  219. }
  220. break;
  221. default:
  222. $result['status'] = 'error';
  223. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  224. break;
  225. }
  226. break;
  227. case 'v1_settings_settings_main':
  228. switch ($method) {
  229. case 'GET':
  230. if (qualifyRequest(1)) {
  231. $result['status'] = 'success';
  232. $result['statusText'] = 'success';
  233. $result['data'] = $pageSettingsSettingsMain;
  234. } else {
  235. $result['status'] = 'error';
  236. $result['statusText'] = 'API/Token invalid or not set';
  237. $result['data'] = null;
  238. }
  239. break;
  240. default:
  241. $result['status'] = 'error';
  242. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  243. break;
  244. }
  245. break;
  246. case 'v1_settings_customize_appearance':
  247. switch ($method) {
  248. case 'GET':
  249. if (qualifyRequest(1)) {
  250. $result['status'] = 'success';
  251. $result['statusText'] = 'success';
  252. $result['data'] = $pageSettingsCustomizeAppearance;
  253. } else {
  254. $result['status'] = 'error';
  255. $result['statusText'] = 'API/Token invalid or not set';
  256. $result['data'] = null;
  257. }
  258. break;
  259. case 'POST':
  260. if (qualifyRequest(1)) {
  261. $result['status'] = 'success';
  262. $result['statusText'] = 'success';
  263. $result['data'] = editAppearance($_POST);
  264. } else {
  265. $result['status'] = 'error';
  266. $result['statusText'] = 'API/Token invalid or not set';
  267. $result['data'] = null;
  268. }
  269. break;
  270. default:
  271. $result['status'] = 'error';
  272. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  273. break;
  274. }
  275. break;
  276. case 'v1_remove_file':
  277. switch ($method) {
  278. case 'POST':
  279. if (qualifyRequest(1)) {
  280. $result['status'] = 'success';
  281. $result['statusText'] = 'success';
  282. $result['data'] = removeFile($_POST);
  283. } else {
  284. $result['status'] = 'error';
  285. $result['statusText'] = 'API/Token invalid or not set';
  286. $result['data'] = null;
  287. }
  288. break;
  289. default:
  290. $result['status'] = 'error';
  291. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  292. break;
  293. }
  294. break;
  295. case 'v1_update_config':
  296. switch ($method) {
  297. case 'POST':
  298. if (qualifyRequest(1)) {
  299. $result['status'] = 'success';
  300. $result['statusText'] = 'success';
  301. $result['data'] = updateConfigItem($_POST);
  302. } else {
  303. $result['status'] = 'error';
  304. $result['statusText'] = 'API/Token invalid or not set';
  305. $result['data'] = null;
  306. }
  307. break;
  308. default:
  309. $result['status'] = 'error';
  310. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  311. break;
  312. }
  313. break;
  314. case 'v1_update_config_multiple':
  315. switch ($method) {
  316. case 'POST':
  317. if (qualifyRequest(1)) {
  318. $result['status'] = 'success';
  319. $result['statusText'] = 'success';
  320. $result['data'] = updateConfigMultiple($_POST);
  321. } else {
  322. $result['status'] = 'error';
  323. $result['statusText'] = 'API/Token invalid or not set';
  324. $result['data'] = null;
  325. }
  326. break;
  327. default:
  328. $result['status'] = 'error';
  329. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  330. break;
  331. }
  332. break;
  333. case 'v1_update_config_multiple_form':
  334. switch ($method) {
  335. case 'POST':
  336. if (qualifyRequest(1)) {
  337. $result['status'] = 'success';
  338. $result['statusText'] = 'success';
  339. $result['data'] = updateConfigMultipleForm($_POST);
  340. } else {
  341. $result['status'] = 'error';
  342. $result['statusText'] = 'API/Token invalid or not set';
  343. $result['data'] = null;
  344. }
  345. break;
  346. default:
  347. $result['status'] = 'error';
  348. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  349. break;
  350. }
  351. break;
  352. case 'v1_homepage_connect':
  353. switch ($method) {
  354. case 'POST':
  355. $result['status'] = 'success';
  356. $result['statusText'] = 'success';
  357. $result['data'] = homepageConnect($_POST);
  358. break;
  359. default:
  360. $result['status'] = 'error';
  361. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  362. break;
  363. }
  364. break;
  365. case 'v1_ping_list':
  366. switch ($method) {
  367. case 'POST':
  368. $result['status'] = 'success';
  369. $result['statusText'] = 'success';
  370. $result['data'] = ping($_POST['data']['pingList']);
  371. break;
  372. default:
  373. $result['status'] = 'error';
  374. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  375. break;
  376. }
  377. break;
  378. case 'v1_test_api_connection':
  379. switch ($method) {
  380. case 'POST':
  381. if (qualifyRequest(1)) {
  382. $result['status'] = 'success';
  383. $result['statusText'] = 'success';
  384. $result['data'] = testAPIConnection($_POST);
  385. } else {
  386. $result['status'] = 'error';
  387. $result['statusText'] = 'API/Token invalid or not set';
  388. $result['data'] = null;
  389. }
  390. break;
  391. default:
  392. $result['status'] = 'error';
  393. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  394. break;
  395. }
  396. break;
  397. case 'v1_settings_tab_editor_tabs':
  398. switch ($method) {
  399. case 'GET':
  400. if (qualifyRequest(1)) {
  401. $result['status'] = 'success';
  402. $result['statusText'] = 'success';
  403. $result['data'] = $pageSettingsTabEditorTabs;
  404. } else {
  405. $result['status'] = 'error';
  406. $result['statusText'] = 'API/Token invalid or not set';
  407. $result['data'] = null;
  408. }
  409. break;
  410. case 'POST':
  411. if (qualifyRequest(1)) {
  412. $result['status'] = 'success';
  413. $result['statusText'] = 'success';
  414. $result['data'] = editTabs($_POST);
  415. } else {
  416. $result['status'] = 'error';
  417. $result['statusText'] = 'API/Token invalid or not set';
  418. $result['data'] = null;
  419. }
  420. break;
  421. default:
  422. $result['status'] = 'error';
  423. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  424. break;
  425. }
  426. break;
  427. case 'v1_settings_tab_editor_categories':
  428. switch ($method) {
  429. case 'GET':
  430. if (qualifyRequest(1)) {
  431. $result['status'] = 'success';
  432. $result['statusText'] = 'success';
  433. $result['data'] = $pageSettingsTabEditorCategories;
  434. } else {
  435. $result['status'] = 'error';
  436. $result['statusText'] = 'API/Token invalid or not set';
  437. $result['data'] = null;
  438. }
  439. break;
  440. case 'POST':
  441. if (qualifyRequest(1)) {
  442. $result['status'] = 'success';
  443. $result['statusText'] = 'success';
  444. $result['data'] = editCategories($_POST);
  445. } else {
  446. $result['status'] = 'error';
  447. $result['statusText'] = 'API/Token invalid or not set';
  448. $result['data'] = null;
  449. }
  450. break;
  451. default:
  452. $result['status'] = 'error';
  453. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  454. break;
  455. }
  456. break;
  457. case 'v1_settings_user_manage_users':
  458. switch ($method) {
  459. case 'GET':
  460. if (qualifyRequest(1)) {
  461. $result['status'] = 'success';
  462. $result['statusText'] = 'success';
  463. $result['data'] = $pageSettingsUserManageUsers;
  464. } else {
  465. $result['status'] = 'error';
  466. $result['statusText'] = 'API/Token invalid or not set';
  467. $result['data'] = null;
  468. }
  469. break;
  470. case 'POST':
  471. if (qualifyRequest(1)) {
  472. $result['status'] = 'success';
  473. $result['statusText'] = 'success';
  474. $result['data'] = adminEditUser($_POST);
  475. } elseif (qualifyRequest(998)) {
  476. $result['status'] = 'success';
  477. $result['statusText'] = 'success';
  478. $result['data'] = editUser($_POST);
  479. } else {
  480. $result['status'] = 'error';
  481. $result['statusText'] = 'API/Token invalid or not set';
  482. $result['data'] = null;
  483. }
  484. break;
  485. default:
  486. $result['status'] = 'error';
  487. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  488. break;
  489. }
  490. break;
  491. case 'v1_manage_user':
  492. switch ($method) {
  493. case 'POST':
  494. if (qualifyRequest(998)) {
  495. $result['status'] = 'success';
  496. $result['statusText'] = 'success';
  497. $result['data'] = editUser($_POST);
  498. } else {
  499. $result['status'] = 'error';
  500. $result['statusText'] = 'API/Token invalid or not set';
  501. $result['data'] = null;
  502. }
  503. break;
  504. default:
  505. $result['status'] = 'error';
  506. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  507. break;
  508. }
  509. break;
  510. case 'v1_settings_user_manage_groups':
  511. switch ($method) {
  512. case 'GET':
  513. if (qualifyRequest(1)) {
  514. $result['status'] = 'success';
  515. $result['statusText'] = 'success';
  516. $result['data'] = $pageSettingsUserManageGroups;
  517. } else {
  518. $result['status'] = 'error';
  519. $result['statusText'] = 'API/Token invalid or not set';
  520. $result['data'] = null;
  521. }
  522. break;
  523. case 'POST':
  524. if (qualifyRequest(1)) {
  525. $result['status'] = 'success';
  526. $result['statusText'] = 'success';
  527. $result['data'] = adminEditGroup($_POST);
  528. } else {
  529. $result['status'] = 'error';
  530. $result['statusText'] = 'API/Token invalid or not set';
  531. $result['data'] = null;
  532. }
  533. break;
  534. default:
  535. $result['status'] = 'error';
  536. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  537. break;
  538. }
  539. break;
  540. case 'v1_settings_image_manager_view':
  541. switch ($method) {
  542. case 'GET':
  543. if (qualifyRequest(1)) {
  544. $result['status'] = 'success';
  545. $result['statusText'] = 'success';
  546. $result['data'] = $pageSettingsImageManager;
  547. } else {
  548. $result['status'] = 'error';
  549. $result['statusText'] = 'API/Token invalid or not set';
  550. $result['data'] = null;
  551. }
  552. break;
  553. case 'POST':
  554. if (qualifyRequest(1)) {
  555. $result['status'] = 'success';
  556. $result['statusText'] = 'success';
  557. $result['data'] = editImages();
  558. } else {
  559. $result['status'] = 'error';
  560. $result['statusText'] = 'API/Token invalid or not set';
  561. $result['data'] = null;
  562. }
  563. break;
  564. default:
  565. $result['status'] = 'error';
  566. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  567. break;
  568. }
  569. break;
  570. case 'v1_wizard_page':
  571. switch ($method) {
  572. case 'GET':
  573. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  574. $result['status'] = 'success';
  575. $result['statusText'] = 'success';
  576. $result['data'] = $pageWizard;
  577. } else {
  578. $result['status'] = 'error';
  579. $result['statusText'] = 'Wizard has already been run';
  580. $result['data'] = null;
  581. }
  582. break;
  583. default:
  584. $result['status'] = 'error';
  585. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  586. break;
  587. }
  588. break;
  589. case 'v1_dependencies_page':
  590. switch ($method) {
  591. case 'GET':
  592. $result['status'] = 'success';
  593. $result['statusText'] = 'success';
  594. $result['data'] = $pageDependencies;
  595. break;
  596. default:
  597. $result['status'] = 'error';
  598. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  599. break;
  600. }
  601. break;
  602. case 'v1_wizard_config':
  603. switch ($method) {
  604. case 'POST':
  605. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  606. $result['status'] = 'success';
  607. $result['statusText'] = 'success';
  608. $result['data'] = wizardConfig($_POST);
  609. } else {
  610. $result['status'] = 'error';
  611. $result['statusText'] = 'Wizard has already been run';
  612. $result['data'] = null;
  613. }
  614. break;
  615. default:
  616. $result['status'] = 'error';
  617. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  618. break;
  619. }
  620. break;
  621. case 'v1_wizard_path':
  622. switch ($method) {
  623. case 'POST':
  624. if (!file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  625. $result['status'] = 'success';
  626. $result['statusText'] = 'success';
  627. $result['data'] = wizardPath($_POST);
  628. } else {
  629. $result['status'] = 'error';
  630. $result['statusText'] = 'Wizard has already been run';
  631. $result['data'] = null;
  632. }
  633. break;
  634. default:
  635. $result['status'] = 'error';
  636. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  637. break;
  638. }
  639. break;
  640. case 'v1_login':
  641. switch ($method) {
  642. case 'POST':
  643. $result['status'] = 'success';
  644. $result['statusText'] = 'success';
  645. $result['data'] = login($_POST);
  646. break;
  647. default:
  648. $result['status'] = 'error';
  649. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  650. break;
  651. }
  652. break;
  653. case 'v1_register':
  654. switch ($method) {
  655. case 'POST':
  656. $result['status'] = 'success';
  657. $result['statusText'] = 'success';
  658. $result['data'] = register($_POST);
  659. break;
  660. default:
  661. $result['status'] = 'error';
  662. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  663. break;
  664. }
  665. break;
  666. case 'v1_recover':
  667. switch ($method) {
  668. case 'POST':
  669. $result['status'] = 'success';
  670. $result['statusText'] = 'success';
  671. $result['data'] = recover($_POST);
  672. break;
  673. default:
  674. $result['status'] = 'error';
  675. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  676. break;
  677. }
  678. break;
  679. case 'v1_unlock':
  680. switch ($method) {
  681. case 'POST':
  682. $result['status'] = 'success';
  683. $result['statusText'] = 'success';
  684. $result['data'] = unlock($_POST);
  685. break;
  686. default:
  687. $result['status'] = 'error';
  688. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  689. break;
  690. }
  691. break;
  692. case 'v1_lock':
  693. switch ($method) {
  694. case 'POST':
  695. $result['status'] = 'success';
  696. $result['statusText'] = 'success';
  697. $result['data'] = lock();
  698. break;
  699. default:
  700. $result['status'] = 'error';
  701. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  702. break;
  703. }
  704. break;
  705. case 'v1_test_iframe':
  706. switch ($method) {
  707. case 'POST':
  708. $result['status'] = 'success';
  709. $result['statusText'] = 'success';
  710. $result['data'] = frameTest($_POST['data']['url']);
  711. break;
  712. default:
  713. $result['status'] = 'error';
  714. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  715. break;
  716. }
  717. break;
  718. case 'v1_upgrade':
  719. case 'v1_update':
  720. case 'v1_force':
  721. switch ($method) {
  722. case 'POST':
  723. if (qualifyRequest(1)) {
  724. $result['status'] = 'success';
  725. $result['statusText'] = 'success';
  726. $result['data'] = upgradeInstall($_POST['data']['branch'], $_POST['data']['stage']);
  727. } else {
  728. $result['status'] = 'error';
  729. $result['statusText'] = 'API/Token invalid or not set';
  730. $result['data'] = null;
  731. }
  732. break;
  733. default:
  734. $result['status'] = 'error';
  735. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  736. break;
  737. }
  738. break;
  739. case 'v1_login_page':
  740. switch ($method) {
  741. case 'GET':
  742. $result['status'] = 'success';
  743. $result['statusText'] = 'success';
  744. $result['data'] = $pageLogin;
  745. break;
  746. default:
  747. $result['status'] = 'error';
  748. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  749. break;
  750. }
  751. break;
  752. case 'v1_lockscreen':
  753. switch ($method) {
  754. case 'GET':
  755. $result['status'] = 'success';
  756. $result['statusText'] = 'success';
  757. $result['data'] = $pageLockScreen;
  758. break;
  759. default:
  760. $result['status'] = 'error';
  761. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  762. break;
  763. }
  764. break;
  765. case 'v1_login_log':
  766. switch ($method) {
  767. case 'GET':
  768. if (qualifyRequest(1)) {
  769. $result['status'] = 'success';
  770. $result['statusText'] = 'success';
  771. $result['data'] = getLog('loginLog');
  772. } else {
  773. $result['status'] = 'error';
  774. $result['statusText'] = 'API/Token invalid or not set';
  775. $result['data'] = null;
  776. }
  777. break;
  778. default:
  779. $result['status'] = 'error';
  780. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  781. break;
  782. }
  783. break;
  784. case 'v1_organizr_log':
  785. switch ($method) {
  786. case 'GET':
  787. if (qualifyRequest(1)) {
  788. $result['status'] = 'success';
  789. $result['statusText'] = 'success';
  790. $result['data'] = getLog('org');
  791. } else {
  792. $result['status'] = 'error';
  793. $result['statusText'] = 'API/Token invalid or not set';
  794. $result['data'] = null;
  795. }
  796. break;
  797. default:
  798. $result['status'] = 'error';
  799. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  800. break;
  801. }
  802. break;
  803. case 'v1_user_list':
  804. switch ($method) {
  805. case 'GET':
  806. if (qualifyRequest(1)) {
  807. $result['status'] = 'success';
  808. $result['statusText'] = 'success';
  809. $result['data'] = allUsers();
  810. } else {
  811. $result['status'] = 'error';
  812. $result['statusText'] = 'API/Token invalid or not set';
  813. $result['data'] = null;
  814. }
  815. break;
  816. default:
  817. $result['status'] = 'error';
  818. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  819. break;
  820. }
  821. break;
  822. case 'v1_tab_list':
  823. switch ($method) {
  824. case 'GET':
  825. if (qualifyRequest(1)) {
  826. $result['status'] = 'success';
  827. $result['statusText'] = 'success';
  828. $result['data'] = allTabs();
  829. } else {
  830. $result['status'] = 'error';
  831. $result['statusText'] = 'API/Token invalid or not set';
  832. $result['data'] = null;
  833. }
  834. break;
  835. default:
  836. $result['status'] = 'error';
  837. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  838. break;
  839. }
  840. break;
  841. case 'v1_image_list':
  842. switch ($method) {
  843. case 'GET':
  844. if (qualifyRequest(1)) {
  845. $result['status'] = 'success';
  846. $result['statusText'] = 'success';
  847. $result['data'] = getImages();
  848. } else {
  849. $result['status'] = 'error';
  850. $result['statusText'] = 'API/Token invalid or not set';
  851. $result['data'] = null;
  852. }
  853. break;
  854. default:
  855. $result['status'] = 'error';
  856. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  857. break;
  858. }
  859. break;
  860. case 'v1_customize_appearance':
  861. switch ($method) {
  862. case 'GET':
  863. if (qualifyRequest(1)) {
  864. $result['status'] = 'success';
  865. $result['statusText'] = 'success';
  866. $result['data'] = getCustomizeAppearance();
  867. } else {
  868. $result['status'] = 'error';
  869. $result['statusText'] = 'API/Token invalid or not set';
  870. $result['data'] = null;
  871. }
  872. break;
  873. default:
  874. $result['status'] = 'error';
  875. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  876. break;
  877. }
  878. break;
  879. case 'v1_sso':
  880. switch ($method) {
  881. case 'GET':
  882. if (qualifyRequest(1)) {
  883. $result['status'] = 'success';
  884. $result['statusText'] = 'success';
  885. $result['data'] = getSSO();
  886. } else {
  887. $result['status'] = 'error';
  888. $result['statusText'] = 'API/Token invalid or not set';
  889. $result['data'] = null;
  890. }
  891. break;
  892. default:
  893. $result['status'] = 'error';
  894. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  895. break;
  896. }
  897. break;
  898. case 'v1_settings_main':
  899. switch ($method) {
  900. case 'GET':
  901. if (qualifyRequest(1)) {
  902. $result['status'] = 'success';
  903. $result['statusText'] = 'success';
  904. $result['data'] = getSettingsMain();
  905. } else {
  906. $result['status'] = 'error';
  907. $result['statusText'] = 'API/Token invalid or not set';
  908. $result['data'] = null;
  909. }
  910. break;
  911. default:
  912. $result['status'] = 'error';
  913. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  914. break;
  915. }
  916. break;
  917. case 'v1_plugin_install':
  918. switch ($method) {
  919. case 'POST':
  920. if (qualifyRequest(1)) {
  921. $result['status'] = 'success';
  922. $result['statusText'] = 'success';
  923. $result['data'] = installPlugin($_POST);
  924. } else {
  925. $result['status'] = 'error';
  926. $result['statusText'] = 'API/Token invalid or not set';
  927. $result['data'] = null;
  928. }
  929. break;
  930. default:
  931. $result['status'] = 'error';
  932. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  933. break;
  934. }
  935. break;
  936. case 'v1_plugin_remove':
  937. switch ($method) {
  938. case 'POST':
  939. if (qualifyRequest(1)) {
  940. $result['status'] = 'success';
  941. $result['statusText'] = 'success';
  942. $result['data'] = removePlugin($_POST);
  943. } else {
  944. $result['status'] = 'error';
  945. $result['statusText'] = 'API/Token invalid or not set';
  946. $result['data'] = null;
  947. }
  948. break;
  949. default:
  950. $result['status'] = 'error';
  951. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  952. break;
  953. }
  954. break;
  955. case 'v1_theme_install':
  956. switch ($method) {
  957. case 'POST':
  958. if (qualifyRequest(1)) {
  959. $result['status'] = 'success';
  960. $result['statusText'] = 'success';
  961. $result['data'] = installTheme($_POST);
  962. } else {
  963. $result['status'] = 'error';
  964. $result['statusText'] = 'API/Token invalid or not set';
  965. $result['data'] = null;
  966. }
  967. break;
  968. default:
  969. $result['status'] = 'error';
  970. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  971. break;
  972. }
  973. break;
  974. case 'v1_theme_remove':
  975. switch ($method) {
  976. case 'POST':
  977. if (qualifyRequest(1)) {
  978. $result['status'] = 'success';
  979. $result['statusText'] = 'success';
  980. $result['data'] = removeTheme($_POST);
  981. } else {
  982. $result['status'] = 'error';
  983. $result['statusText'] = 'API/Token invalid or not set';
  984. $result['data'] = null;
  985. }
  986. break;
  987. default:
  988. $result['status'] = 'error';
  989. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  990. break;
  991. }
  992. break;
  993. case 'v1_user_edit':
  994. switch ($method) {
  995. case 'POST':
  996. if (qualifyRequest(1)) {
  997. $result['status'] = 'success';
  998. $result['statusText'] = 'success';
  999. $result['data'] = adminEditUser($_POST);
  1000. } elseif (qualifyRequest(998)) {
  1001. $result['status'] = 'success';
  1002. $result['statusText'] = 'success';
  1003. $result['data'] = editUser($_POST);
  1004. } else {
  1005. $result['status'] = 'error';
  1006. $result['statusText'] = 'API/Token invalid or not set';
  1007. $result['data'] = null;
  1008. }
  1009. break;
  1010. default:
  1011. $result['status'] = 'error';
  1012. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1013. break;
  1014. }
  1015. break;
  1016. case 'v1_2fa_create':
  1017. switch ($method) {
  1018. case 'POST':
  1019. if (qualifyRequest(998)) {
  1020. $result['status'] = 'success';
  1021. $result['statusText'] = 'success';
  1022. $result['data'] = create2FA($_POST['data']['type']);
  1023. } else {
  1024. $result['status'] = 'error';
  1025. $result['statusText'] = 'API/Token invalid or not set';
  1026. $result['data'] = null;
  1027. }
  1028. break;
  1029. default:
  1030. $result['status'] = 'error';
  1031. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1032. break;
  1033. }
  1034. break;
  1035. case 'v1_2fa_save':
  1036. switch ($method) {
  1037. case 'POST':
  1038. if (qualifyRequest(998)) {
  1039. $result['status'] = 'success';
  1040. $result['statusText'] = 'success';
  1041. $result['data'] = save2FA($_POST['data']['secret'], $_POST['data']['type']);
  1042. } else {
  1043. $result['status'] = 'error';
  1044. $result['statusText'] = 'API/Token invalid or not set';
  1045. $result['data'] = null;
  1046. }
  1047. break;
  1048. default:
  1049. $result['status'] = 'error';
  1050. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1051. break;
  1052. }
  1053. break;
  1054. case 'v1_2fa_verify':
  1055. switch ($method) {
  1056. case 'POST':
  1057. if (qualifyRequest(998)) {
  1058. $result['status'] = 'success';
  1059. $result['statusText'] = 'success';
  1060. $result['data'] = verify2FA($_POST['data']['secret'], $_POST['data']['code'], $_POST['data']['type']);
  1061. } else {
  1062. $result['status'] = 'error';
  1063. $result['statusText'] = 'API/Token invalid or not set';
  1064. $result['data'] = null;
  1065. }
  1066. break;
  1067. default:
  1068. $result['status'] = 'error';
  1069. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1070. break;
  1071. }
  1072. break;
  1073. case 'v1_2fa_remove':
  1074. switch ($method) {
  1075. case 'GET':
  1076. if (qualifyRequest(998)) {
  1077. $result['status'] = 'success';
  1078. $result['statusText'] = 'success';
  1079. $result['data'] = remove2FA();
  1080. } else {
  1081. $result['status'] = 'error';
  1082. $result['statusText'] = 'API/Token invalid or not set';
  1083. $result['data'] = null;
  1084. }
  1085. break;
  1086. default:
  1087. $result['status'] = 'error';
  1088. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1089. break;
  1090. }
  1091. break;
  1092. case 'v1_logout':
  1093. switch ($method) {
  1094. case 'GET':
  1095. $result['status'] = 'success';
  1096. $result['statusText'] = 'success';
  1097. $result['data'] = logout();
  1098. break;
  1099. default:
  1100. $result['status'] = 'error';
  1101. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1102. break;
  1103. }
  1104. break;
  1105. case 'v1_launch_organizr':
  1106. switch ($method) {
  1107. case 'GET':
  1108. $pluginSearch = '-enabled';
  1109. $pluginInclude = '-include';
  1110. $status = array();
  1111. $result['status'] = 'success';
  1112. $result['statusText'] = 'success';
  1113. $status['status'] = organizrStatus();
  1114. $result['appearance'] = loadAppearance();
  1115. $status['user'] = $GLOBALS['organizrUser'];
  1116. $status['categories'] = loadTabs()['categories'];
  1117. $status['tabs'] = loadTabs()['tabs'];
  1118. $status['plugins'] = array_filter($GLOBALS, function ($k) use ($pluginSearch) {
  1119. return stripos($k, $pluginSearch) !== false;
  1120. }, ARRAY_FILTER_USE_KEY);
  1121. $status['plugins']['includes'] = array_filter($GLOBALS, function ($k) use ($pluginInclude) {
  1122. return stripos($k, $pluginInclude) !== false;
  1123. }, ARRAY_FILTER_USE_KEY);
  1124. $result['data'] = $status;
  1125. $result['branch'] = $GLOBALS['branch'];
  1126. $result['theme'] = $GLOBALS['theme'];
  1127. $result['style'] = $GLOBALS['style'];
  1128. $result['version'] = $GLOBALS['installedVersion'];
  1129. $result['sso'] = array(
  1130. 'myPlexAccessToken' => isset($_COOKIE['mpt']) ? $_COOKIE['mpt'] : false,
  1131. 'id_token' => isset($_COOKIE['Auth']) ? $_COOKIE['Auth'] : false
  1132. );
  1133. $result['settings'] = organizrSpecialSettings();
  1134. break;
  1135. default:
  1136. $result['status'] = 'error';
  1137. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1138. break;
  1139. }
  1140. break;
  1141. case 'v1_auth':
  1142. switch ($method) {
  1143. case 'GET':
  1144. auth();
  1145. break;
  1146. default:
  1147. $result['status'] = 'error';
  1148. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1149. break;
  1150. }
  1151. break;
  1152. case 'v1_plugin':
  1153. switch ($method) {
  1154. case 'POST':
  1155. case 'GET':
  1156. // Include all plugin api Calls
  1157. foreach (glob(__DIR__ . DIRECTORY_SEPARATOR . 'plugins' . DIRECTORY_SEPARATOR . 'api' . DIRECTORY_SEPARATOR . "*.php") as $filename) {
  1158. require_once $filename;
  1159. }
  1160. break;
  1161. default:
  1162. $result['status'] = 'error';
  1163. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1164. break;
  1165. }
  1166. break;
  1167. case 'v1_image':
  1168. switch ($method) {
  1169. case 'GET':
  1170. getImage();
  1171. break;
  1172. default:
  1173. $result['status'] = 'error';
  1174. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1175. break;
  1176. }
  1177. break;
  1178. case 'v1_downloader':
  1179. switch ($method) {
  1180. case 'POST':
  1181. $result['status'] = 'success';
  1182. $result['statusText'] = 'success';
  1183. $result['data'] = downloader($_POST);
  1184. break;
  1185. default:
  1186. $result['status'] = 'error';
  1187. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1188. break;
  1189. }
  1190. break;
  1191. case 'v1_import_users':
  1192. switch ($method) {
  1193. case 'POST':
  1194. if (qualifyRequest(1)) {
  1195. $result['status'] = 'success';
  1196. $result['statusText'] = 'success';
  1197. $result['data'] = importUsersType($_POST);
  1198. } else {
  1199. $result['status'] = 'error';
  1200. $result['statusText'] = 'API/Token invalid or not set';
  1201. $result['data'] = null;
  1202. }
  1203. break;
  1204. default:
  1205. $result['status'] = 'error';
  1206. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1207. break;
  1208. }
  1209. break;
  1210. case 'v1_ombi':
  1211. switch ($method) {
  1212. case 'POST':
  1213. $result['status'] = 'success';
  1214. $result['statusText'] = 'success';
  1215. $result['data'] = ombiAPI($_POST);
  1216. break;
  1217. default:
  1218. $result['status'] = 'error';
  1219. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1220. break;
  1221. }
  1222. break;
  1223. case 'v1_plex_join':
  1224. switch ($method) {
  1225. case 'POST':
  1226. $result['status'] = 'success';
  1227. $result['statusText'] = 'success';
  1228. $result['data'] = plexJoinAPI($_POST);
  1229. break;
  1230. default:
  1231. $result['status'] = 'error';
  1232. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1233. break;
  1234. }
  1235. break;
  1236. case 'v1_token_revoke':
  1237. switch ($method) {
  1238. case 'POST':
  1239. $result['status'] = 'success';
  1240. $result['statusText'] = 'success';
  1241. $result['data'] = revokeToken($_POST);
  1242. break;
  1243. default:
  1244. $result['status'] = 'error';
  1245. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1246. break;
  1247. }
  1248. break;
  1249. case 'v1_update_db_manual':
  1250. switch ($method) {
  1251. case 'GET':
  1252. if (qualifyRequest(1)) {
  1253. $result['status'] = 'success';
  1254. $result['statusText'] = 'success';
  1255. $result['data'] = updateDB($GLOBALS['installedVersion']);
  1256. } else {
  1257. $result['status'] = 'error';
  1258. $result['statusText'] = 'API/Token invalid or not set';
  1259. $result['data'] = null;
  1260. }
  1261. break;
  1262. default:
  1263. $result['status'] = 'error';
  1264. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1265. break;
  1266. }
  1267. break;
  1268. case 'v1_version':
  1269. switch ($method) {
  1270. case 'GET':
  1271. $result['status'] = 'success';
  1272. $result['statusText'] = 'success';
  1273. $result['data'] = $GLOBALS['installedVersion'];
  1274. break;
  1275. default:
  1276. $result['status'] = 'error';
  1277. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1278. break;
  1279. }
  1280. break;
  1281. case 'v1_ping':
  1282. switch ($method) {
  1283. case 'GET':
  1284. $result['status'] = 'success';
  1285. $result['statusText'] = 'success';
  1286. $result['data'] = 'pong';
  1287. break;
  1288. default:
  1289. $result['status'] = 'error';
  1290. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1291. break;
  1292. }
  1293. break;
  1294. case 'v1_docker_update':
  1295. switch ($method) {
  1296. case 'GET':
  1297. if (qualifyRequest(1)) {
  1298. $result['status'] = 'success';
  1299. $result['statusText'] = 'success';
  1300. $result['data'] = dockerUpdate();
  1301. } else {
  1302. $result['status'] = 'error';
  1303. $result['statusText'] = 'API/Token invalid or not set';
  1304. $result['data'] = null;
  1305. }
  1306. break;
  1307. default:
  1308. $result['status'] = 'error';
  1309. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1310. break;
  1311. }
  1312. break;
  1313. case 'v1_windows_update':
  1314. switch ($method) {
  1315. case 'GET':
  1316. if (qualifyRequest(1)) {
  1317. $result['status'] = 'success';
  1318. $result['statusText'] = 'success';
  1319. $result['data'] = windowsUpdate();
  1320. } else {
  1321. $result['status'] = 'error';
  1322. $result['statusText'] = 'API/Token invalid or not set';
  1323. $result['data'] = null;
  1324. }
  1325. break;
  1326. default:
  1327. $result['status'] = 'error';
  1328. $result['statusText'] = 'The function requested is not defined for method: ' . $method;
  1329. break;
  1330. }
  1331. break;
  1332. default:
  1333. //No Function Available
  1334. $result['status'] = 'error';
  1335. $result['statusText'] = 'function requested is not defined';
  1336. break;
  1337. }
  1338. //Set Default Result
  1339. if (!$result) {
  1340. $result['status'] = "error";
  1341. $result['error'] = "An error has occurred";
  1342. }
  1343. $result['generationDate'] = $GLOBALS['currentTime'];
  1344. $generationTime += microtime(true);
  1345. $result['generationTime'] = (sprintf('%f', $generationTime) * 1000) . 'ms';
  1346. //return JSON array
  1347. if ($pretty) {
  1348. echo '<pre>' . safe_json_encode($result, JSON_PRETTY_PRINT) . '</pre>';
  1349. } else {
  1350. exit(safe_json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));
  1351. }