api-functions.php 36 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = $oAuth = $oAuthType = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  25. $oAuth = (isset($oAuth)) ? $oAuth : false;
  26. try {
  27. $database = new Dibi\Connection([
  28. 'driver' => 'sqlite3',
  29. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  30. ]);
  31. $authSuccess = false;
  32. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  33. if (!$oAuth) {
  34. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  35. switch ($GLOBALS['authType']) {
  36. case 'external':
  37. if (function_exists($function)) {
  38. $authSuccess = $function($username, $password);
  39. }
  40. break;
  41. /** @noinspection PhpMissingBreakStatementInspection */
  42. case 'both':
  43. if (function_exists($function)) {
  44. $authSuccess = $function($username, $password);
  45. }
  46. // no break
  47. default: // Internal
  48. if (!$authSuccess) {
  49. // perform the internal authentication step
  50. if (password_verify($password, $result['password'])) {
  51. $authSuccess = true;
  52. }
  53. }
  54. }
  55. } else {
  56. // Has oAuth Token!
  57. switch ($oAuthType) {
  58. case 'plex':
  59. if ($GLOBALS['plexoAuth']) {
  60. $tokenInfo = checkPlexToken($oAuth);
  61. if ($tokenInfo) {
  62. $authSuccess = array(
  63. 'username' => $tokenInfo['user']['username'],
  64. 'email' => $tokenInfo['user']['email'],
  65. 'image' => $tokenInfo['user']['thumb'],
  66. 'token' => $tokenInfo['user']['authToken']
  67. );
  68. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  69. }
  70. }
  71. break;
  72. default:
  73. return 'error';
  74. break;
  75. }
  76. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  77. }
  78. if ($authSuccess) {
  79. // Make sure user exists in database
  80. $userExists = false;
  81. $passwordMatches = ($oAuth) ? true : false;
  82. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  83. if ($result['username']) {
  84. $userExists = true;
  85. $username = $result['username'];
  86. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  87. }
  88. if ($userExists) {
  89. //does org password need to be updated
  90. if (!$passwordMatches) {
  91. $database->query('
  92. UPDATE users SET', [
  93. 'password' => password_hash($password, PASSWORD_BCRYPT)
  94. ], '
  95. WHERE id=?', $result['id']);
  96. writeLog('success', 'Login Function - User Password updated from backend', $username);
  97. }
  98. if ($token !== '') {
  99. if ($token !== $result['plex_token']) {
  100. $database->query('
  101. UPDATE users SET', [
  102. 'plex_token' => $token
  103. ], '
  104. WHERE id=?', $result['id']);
  105. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  106. }
  107. }
  108. // 2FA might go here
  109. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  110. $TFA = explode('::', $result['auth_service']);
  111. // Is code with login info?
  112. if ($tfaCode == '') {
  113. return '2FA';
  114. } else {
  115. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  116. writeLoginLog($username, 'error');
  117. writeLog('error', 'Login Function - Wrong 2FA', $username);
  118. return '2FA-incorrect';
  119. }
  120. }
  121. }
  122. // End 2FA
  123. // authentication passed - 1) mark active and update token
  124. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  125. writeLoginLog($username, 'success');
  126. writeLog('success', 'Login Function - A User has logged in', $username);
  127. ssoCheck($username, $password, $token); //need to work on this
  128. return true;
  129. } else {
  130. return 'error';
  131. }
  132. } else {
  133. // Create User
  134. //ssoCheck($username, $password, $token);
  135. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  136. }
  137. } else {
  138. // authentication failed
  139. writeLoginLog($username, 'error');
  140. writeLog('error', 'Login Function - Wrong Password', $username);
  141. return 'mismatch';
  142. }
  143. } catch (Dibi\Exception $e) {
  144. return $e;
  145. }
  146. }
  147. function createDB($path, $filename)
  148. {
  149. try {
  150. if (!file_exists($path)) {
  151. mkdir($path, 0777, true);
  152. }
  153. $createDB = new Dibi\Connection([
  154. 'driver' => 'sqlite3',
  155. 'database' => $path . $filename,
  156. ]);
  157. // Create Users
  158. $createDB->query('CREATE TABLE `users` (
  159. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  160. `username` TEXT UNIQUE,
  161. `password` TEXT,
  162. `email` TEXT,
  163. `plex_token` TEXT,
  164. `group` TEXT,
  165. `group_id` INTEGER,
  166. `locked` INTEGER,
  167. `image` TEXT,
  168. `register_date` DATE,
  169. `auth_service` TEXT DEFAULT \'internal\'
  170. );');
  171. // Create Tokens
  172. $createDB->query('CREATE TABLE `chatroom` (
  173. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  174. `username` TEXT,
  175. `gravatar` TEXT,
  176. `uid` TEXT,
  177. `date` DATE,
  178. `ip` TEXT,
  179. `message` TEXT
  180. );');
  181. $createDB->query('CREATE TABLE `tokens` (
  182. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  183. `token` TEXT UNIQUE,
  184. `user_id` INTEGER,
  185. `browser` TEXT,
  186. `ip` TEXT,
  187. `created` DATE,
  188. `expires` DATE
  189. );');
  190. $createDB->query('CREATE TABLE `groups` (
  191. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  192. `group` TEXT UNIQUE,
  193. `group_id` INTEGER,
  194. `image` TEXT,
  195. `default` INTEGER
  196. );');
  197. $createDB->query('CREATE TABLE `categories` (
  198. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  199. `order` INTEGER,
  200. `category` TEXT UNIQUE,
  201. `category_id` INTEGER,
  202. `image` TEXT,
  203. `default` INTEGER
  204. );');
  205. // Create Tabs
  206. $createDB->query('CREATE TABLE `tabs` (
  207. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  208. `order` INTEGER,
  209. `category_id` INTEGER,
  210. `name` TEXT,
  211. `url` TEXT,
  212. `url_local` TEXT,
  213. `default` INTEGER,
  214. `enabled` INTEGER,
  215. `group_id` INTEGER,
  216. `image` TEXT,
  217. `type` INTEGER,
  218. `splash` INTEGER,
  219. `ping` INTEGER,
  220. `ping_url` TEXT,
  221. `timeout` INTEGER,
  222. `timeout_ms` INTEGER,
  223. `preload` INTEGER
  224. );');
  225. // Create Options
  226. $createDB->query('CREATE TABLE `options` (
  227. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  228. `name` TEXT UNIQUE,
  229. `value` TEXT
  230. );');
  231. // Create Invites
  232. $createDB->query('CREATE TABLE `invites` (
  233. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  234. `code` TEXT UNIQUE,
  235. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  236. `email` TEXT,
  237. `username` TEXT,
  238. `dateused` TIMESTAMP,
  239. `usedby` TEXT,
  240. `ip` TEXT,
  241. `valid` TEXT,
  242. `type` TEXT
  243. );');
  244. return true;
  245. } catch (Dibi\Exception $e) {
  246. return false;
  247. }
  248. }
  249. // Upgrade Database
  250. function updateDB($oldVerNum = false)
  251. {
  252. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  253. if (!file_exists($tempLock)) {
  254. touch($tempLock);
  255. // Create Temp DB First
  256. $migrationDB = 'tempMigration.db';
  257. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  258. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  259. unlink($GLOBALS['dbLocation'] . $migrationDB);
  260. }
  261. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  262. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  263. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  264. if ($success) {
  265. try {
  266. $connectOldDB = new Dibi\Connection([
  267. 'driver' => 'sqlite3',
  268. 'database' => $backupDB,
  269. ]);
  270. $connectNewDB = new Dibi\Connection([
  271. 'driver' => 'sqlite3',
  272. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  273. ]);
  274. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  275. foreach ($tables as $table) {
  276. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  277. foreach ($data as $row) {
  278. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  279. }
  280. }
  281. $connectOldDB->disconnect();
  282. $connectNewDB->disconnect();
  283. // Remove Current Database
  284. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  285. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  286. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  287. if ($newFileSize >= $oldFileSize) {
  288. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  289. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  290. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  291. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  292. unlink($tempLock);
  293. return true;
  294. }
  295. }
  296. unlink($tempLock);
  297. return false;
  298. } catch (Dibi\Exception $e) {
  299. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  300. unlink($tempLock);
  301. return false;
  302. }
  303. }
  304. unlink($tempLock);
  305. return false;
  306. }
  307. return false;
  308. }
  309. function createFirstAdmin($path, $filename, $username, $password, $email)
  310. {
  311. try {
  312. $createDB = new Dibi\Connection([
  313. 'driver' => 'sqlite3',
  314. 'database' => $path . $filename,
  315. ]);
  316. $userInfo = [
  317. 'username' => $username,
  318. 'password' => password_hash($password, PASSWORD_BCRYPT),
  319. 'email' => $email,
  320. 'group' => 'Admin',
  321. 'group_id' => 0,
  322. 'image' => gravatar($email),
  323. 'register_date' => $GLOBALS['currentTime'],
  324. ];
  325. $groupInfo0 = [
  326. 'group' => 'Admin',
  327. 'group_id' => 0,
  328. 'default' => false,
  329. 'image' => 'plugins/images/groups/admin.png',
  330. ];
  331. $groupInfo1 = [
  332. 'group' => 'Co-Admin',
  333. 'group_id' => 1,
  334. 'default' => false,
  335. 'image' => 'plugins/images/groups/coadmin.png',
  336. ];
  337. $groupInfo2 = [
  338. 'group' => 'Super User',
  339. 'group_id' => 2,
  340. 'default' => false,
  341. 'image' => 'plugins/images/groups/superuser.png',
  342. ];
  343. $groupInfo3 = [
  344. 'group' => 'Power User',
  345. 'group_id' => 3,
  346. 'default' => false,
  347. 'image' => 'plugins/images/groups/poweruser.png',
  348. ];
  349. $groupInfo4 = [
  350. 'group' => 'User',
  351. 'group_id' => 4,
  352. 'default' => true,
  353. 'image' => 'plugins/images/groups/user.png',
  354. ];
  355. $groupInfoGuest = [
  356. 'group' => 'Guest',
  357. 'group_id' => 999,
  358. 'default' => false,
  359. 'image' => 'plugins/images/groups/guest.png',
  360. ];
  361. $settingsInfo = [
  362. 'order' => 1,
  363. 'category_id' => 0,
  364. 'name' => 'Settings',
  365. 'url' => 'api/?v1/settings/page',
  366. 'default' => false,
  367. 'enabled' => true,
  368. 'group_id' => 1,
  369. 'image' => 'fontawesome::cog',
  370. 'type' => 0
  371. ];
  372. $homepageInfo = [
  373. 'order' => 2,
  374. 'category_id' => 0,
  375. 'name' => 'Homepage',
  376. 'url' => 'api/?v1/homepage/page',
  377. 'default' => false,
  378. 'enabled' => false,
  379. 'group_id' => 4,
  380. 'image' => 'fontawesome::home',
  381. 'type' => 0
  382. ];
  383. $unsortedInfo = [
  384. 'order' => 1,
  385. 'category' => 'Unsorted',
  386. 'category_id' => 0,
  387. 'image' => 'plugins/images/categories/unsorted.png',
  388. 'default' => true
  389. ];
  390. $createDB->query('INSERT INTO [users]', $userInfo);
  391. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  392. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  393. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  394. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  395. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  396. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  397. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  398. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  399. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  400. return true;
  401. } catch (Dibi\Exception $e) {
  402. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  403. return false;
  404. }
  405. }
  406. function defaultUserGroup()
  407. {
  408. try {
  409. $connect = new Dibi\Connection([
  410. 'driver' => 'sqlite3',
  411. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  412. ]);
  413. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  414. return $all;
  415. } catch (Dibi\Exception $e) {
  416. return false;
  417. }
  418. }
  419. function defaultTabCategory()
  420. {
  421. try {
  422. $connect = new Dibi\Connection([
  423. 'driver' => 'sqlite3',
  424. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  425. ]);
  426. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  427. return $all;
  428. } catch (Dibi\Exception $e) {
  429. return false;
  430. }
  431. }
  432. function getGuest()
  433. {
  434. if (isset($GLOBALS['dbLocation'])) {
  435. try {
  436. $connect = new Dibi\Connection([
  437. 'driver' => 'sqlite3',
  438. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  439. ]);
  440. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  441. return $all;
  442. } catch (Dibi\Exception $e) {
  443. return false;
  444. }
  445. } else {
  446. return array(
  447. 'group' => 'Guest',
  448. 'group_id' => 999,
  449. 'image' => 'plugins/images/groups/guest.png'
  450. );
  451. }
  452. }
  453. function adminEditGroup($array)
  454. {
  455. switch ($array['data']['action']) {
  456. case 'changeDefaultGroup':
  457. try {
  458. $connect = new Dibi\Connection([
  459. 'driver' => 'sqlite3',
  460. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  461. ]);
  462. $connect->query('UPDATE groups SET `default` = 0');
  463. $connect->query('
  464. UPDATE groups SET', [
  465. 'default' => 1
  466. ], '
  467. WHERE id=?', $array['data']['id']);
  468. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  469. return true;
  470. } catch (Dibi\Exception $e) {
  471. return false;
  472. }
  473. break;
  474. case 'deleteUserGroup':
  475. try {
  476. $connect = new Dibi\Connection([
  477. 'driver' => 'sqlite3',
  478. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  479. ]);
  480. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  481. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  482. return true;
  483. } catch (Dibi\Exception $e) {
  484. return false;
  485. }
  486. break;
  487. case 'addUserGroup':
  488. try {
  489. $connect = new Dibi\Connection([
  490. 'driver' => 'sqlite3',
  491. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  492. ]);
  493. $newGroup = [
  494. 'group' => $array['data']['newGroupName'],
  495. 'group_id' => $array['data']['newGroupID'],
  496. 'default' => false,
  497. 'image' => $array['data']['newGroupImage'],
  498. ];
  499. $connect->query('INSERT INTO [groups]', $newGroup);
  500. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  501. return true;
  502. } catch (Dibi\Exception $e) {
  503. return false;
  504. }
  505. break;
  506. case 'editUserGroup':
  507. try {
  508. $connect = new Dibi\Connection([
  509. 'driver' => 'sqlite3',
  510. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  511. ]);
  512. $connect->query('
  513. UPDATE groups SET', [
  514. 'group' => $array['data']['groupName'],
  515. 'image' => $array['data']['groupImage'],
  516. ], '
  517. WHERE id=?', $array['data']['id']);
  518. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  519. return true;
  520. } catch (Dibi\Exception $e) {
  521. return false;
  522. }
  523. break;
  524. default:
  525. return false;
  526. break;
  527. }
  528. }
  529. function adminEditUser($array)
  530. {
  531. switch ($array['data']['action']) {
  532. case 'changeGroup':
  533. try {
  534. $connect = new Dibi\Connection([
  535. 'driver' => 'sqlite3',
  536. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  537. ]);
  538. $connect->query('
  539. UPDATE users SET', [
  540. 'group' => $array['data']['newGroupName'],
  541. 'group_id' => $array['data']['newGroupID'],
  542. ], '
  543. WHERE id=?', $array['data']['id']);
  544. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  545. return true;
  546. } catch (Dibi\Exception $e) {
  547. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  548. return false;
  549. }
  550. break;
  551. case 'editUser':
  552. try {
  553. $connect = new Dibi\Connection([
  554. 'driver' => 'sqlite3',
  555. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  556. ]);
  557. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  558. $connect->query('
  559. UPDATE users SET', [
  560. 'username' => $array['data']['username'],
  561. 'email' => $array['data']['email'],
  562. 'image' => gravatar($array['data']['email']),
  563. ], '
  564. WHERE id=?', $array['data']['id']);
  565. if (!empty($array['data']['password'])) {
  566. $connect->query('
  567. UPDATE users SET', [
  568. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  569. ], '
  570. WHERE id=?', $array['data']['id']);
  571. }
  572. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  573. return true;
  574. } else {
  575. return false;
  576. }
  577. } catch (Dibi\Exception $e) {
  578. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  579. return false;
  580. }
  581. break;
  582. case 'addNewUser':
  583. $defaults = defaultUserGroup();
  584. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  585. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  586. return true;
  587. } else {
  588. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  589. return 'username taken';
  590. }
  591. break;
  592. case 'deleteUser':
  593. try {
  594. $connect = new Dibi\Connection([
  595. 'driver' => 'sqlite3',
  596. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  597. ]);
  598. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  599. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  600. return true;
  601. } catch (Dibi\Exception $e) {
  602. return false;
  603. }
  604. break;
  605. default:
  606. return false;
  607. break;
  608. }
  609. }
  610. function editTabs($array)
  611. {
  612. switch ($array['data']['action']) {
  613. case 'changeGroup':
  614. try {
  615. $connect = new Dibi\Connection([
  616. 'driver' => 'sqlite3',
  617. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  618. ]);
  619. $connect->query('
  620. UPDATE tabs SET', [
  621. 'group_id' => $array['data']['newGroupID'],
  622. ], '
  623. WHERE id=?', $array['data']['id']);
  624. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  625. return true;
  626. } catch (Dibi\Exception $e) {
  627. return false;
  628. }
  629. break;
  630. case 'changeCategory':
  631. try {
  632. $connect = new Dibi\Connection([
  633. 'driver' => 'sqlite3',
  634. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  635. ]);
  636. $connect->query('
  637. UPDATE tabs SET', [
  638. 'category_id' => $array['data']['newCategoryID'],
  639. ], '
  640. WHERE id=?', $array['data']['id']);
  641. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  642. return true;
  643. } catch (Dibi\Exception $e) {
  644. return false;
  645. }
  646. break;
  647. case 'changeType':
  648. try {
  649. $connect = new Dibi\Connection([
  650. 'driver' => 'sqlite3',
  651. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  652. ]);
  653. $connect->query('
  654. UPDATE tabs SET', [
  655. 'type' => $array['data']['newTypeID'],
  656. ], '
  657. WHERE id=?', $array['data']['id']);
  658. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  659. return true;
  660. } catch (Dibi\Exception $e) {
  661. return false;
  662. }
  663. break;
  664. case 'changeEnabled':
  665. try {
  666. $connect = new Dibi\Connection([
  667. 'driver' => 'sqlite3',
  668. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  669. ]);
  670. $connect->query('
  671. UPDATE tabs SET', [
  672. 'enabled' => $array['data']['tabEnabled'],
  673. ], '
  674. WHERE id=?', $array['data']['id']);
  675. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  676. return true;
  677. } catch (Dibi\Exception $e) {
  678. return false;
  679. }
  680. break;
  681. case 'changeSplash':
  682. try {
  683. $connect = new Dibi\Connection([
  684. 'driver' => 'sqlite3',
  685. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  686. ]);
  687. $connect->query('
  688. UPDATE tabs SET', [
  689. 'splash' => $array['data']['tabSplash'],
  690. ], '
  691. WHERE id=?', $array['data']['id']);
  692. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  693. return true;
  694. } catch (Dibi\Exception $e) {
  695. return false;
  696. }
  697. break;
  698. case 'changePing':
  699. try {
  700. $connect = new Dibi\Connection([
  701. 'driver' => 'sqlite3',
  702. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  703. ]);
  704. $connect->query('
  705. UPDATE tabs SET', [
  706. 'ping' => $array['data']['tabPing'],
  707. ], '
  708. WHERE id=?', $array['data']['id']);
  709. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  710. return true;
  711. } catch (Dibi\Exception $e) {
  712. return false;
  713. }
  714. break;
  715. case 'changeDefault':
  716. try {
  717. $connect = new Dibi\Connection([
  718. 'driver' => 'sqlite3',
  719. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  720. ]);
  721. $connect->query('UPDATE tabs SET `default` = 0');
  722. $connect->query('
  723. UPDATE tabs SET', [
  724. 'default' => 1
  725. ], '
  726. WHERE id=?', $array['data']['id']);
  727. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  728. return true;
  729. } catch (Dibi\Exception $e) {
  730. return false;
  731. }
  732. break;
  733. case 'deleteTab':
  734. try {
  735. $connect = new Dibi\Connection([
  736. 'driver' => 'sqlite3',
  737. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  738. ]);
  739. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  740. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  741. return true;
  742. } catch (Dibi\Exception $e) {
  743. return false;
  744. }
  745. break;
  746. case 'editTab':
  747. try {
  748. $connect = new Dibi\Connection([
  749. 'driver' => 'sqlite3',
  750. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  751. ]);
  752. $connect->query('
  753. UPDATE tabs SET', [
  754. 'name' => $array['data']['tabName'],
  755. 'url' => $array['data']['tabURL'],
  756. 'ping_url' => $array['data']['pingURL'],
  757. 'image' => $array['data']['tabImage'],
  758. ], '
  759. WHERE id=?', $array['data']['id']);
  760. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  761. return true;
  762. } catch (Dibi\Exception $e) {
  763. return false;
  764. }
  765. case 'changeOrder':
  766. try {
  767. $connect = new Dibi\Connection([
  768. 'driver' => 'sqlite3',
  769. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  770. ]);
  771. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  772. if ($value['order'] != $value['originalOrder']) {
  773. $connect->query('
  774. UPDATE tabs SET', [
  775. 'order' => $value['order'],
  776. ], '
  777. WHERE id=?', $value['id']);
  778. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  779. }
  780. }
  781. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  782. return true;
  783. } catch (Dibi\Exception $e) {
  784. return false;
  785. }
  786. break;
  787. case 'addNewTab':
  788. try {
  789. $default = defaultTabCategory()['category_id'];
  790. $connect = new Dibi\Connection([
  791. 'driver' => 'sqlite3',
  792. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  793. ]);
  794. $newTab = [
  795. 'order' => $array['data']['tabOrder'],
  796. 'category_id' => $default,
  797. 'name' => $array['data']['tabName'],
  798. 'url' => $array['data']['tabURL'],
  799. 'ping_url' => $array['data']['pingURL'],
  800. 'default' => $array['data']['tabDefault'],
  801. 'enabled' => 1,
  802. 'group_id' => $array['data']['tabGroupID'],
  803. 'image' => $array['data']['tabImage'],
  804. 'type' => $array['data']['tabType']
  805. ];
  806. $connect->query('INSERT INTO [tabs]', $newTab);
  807. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  808. return true;
  809. } catch (Dibi\Exception $e) {
  810. return false;
  811. }
  812. break;
  813. default:
  814. return false;
  815. break;
  816. }
  817. }
  818. function editCategories($array)
  819. {
  820. switch ($array['data']['action']) {
  821. case 'changeDefault':
  822. try {
  823. $connect = new Dibi\Connection([
  824. 'driver' => 'sqlite3',
  825. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  826. ]);
  827. $connect->query('UPDATE categories SET `default` = 0');
  828. $connect->query('
  829. UPDATE categories SET', [
  830. 'default' => 1
  831. ], '
  832. WHERE id=?', $array['data']['id']);
  833. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  834. return true;
  835. } catch (Dibi\Exception $e) {
  836. return false;
  837. }
  838. break;
  839. case 'deleteCategory':
  840. try {
  841. $connect = new Dibi\Connection([
  842. 'driver' => 'sqlite3',
  843. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  844. ]);
  845. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  846. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  847. return true;
  848. } catch (Dibi\Exception $e) {
  849. return false;
  850. }
  851. break;
  852. case 'addNewCategory':
  853. try {
  854. $connect = new Dibi\Connection([
  855. 'driver' => 'sqlite3',
  856. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  857. ]);
  858. $newCategory = [
  859. 'category' => $array['data']['categoryName'],
  860. 'order' => $array['data']['categoryOrder'],
  861. 'category_id' => $array['data']['categoryID'],
  862. 'default' => false,
  863. 'image' => $array['data']['categoryImage'],
  864. ];
  865. $connect->query('INSERT INTO [categories]', $newCategory);
  866. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  867. return true;
  868. } catch (Dibi\Exception $e) {
  869. return $e;
  870. }
  871. break;
  872. case 'editCategory':
  873. try {
  874. $connect = new Dibi\Connection([
  875. 'driver' => 'sqlite3',
  876. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  877. ]);
  878. $connect->query('
  879. UPDATE categories SET', [
  880. 'category' => $array['data']['name'],
  881. 'image' => $array['data']['image'],
  882. ], '
  883. WHERE id=?', $array['data']['id']);
  884. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  885. return true;
  886. } catch (Dibi\Exception $e) {
  887. return false;
  888. }
  889. break;
  890. case 'changeOrder':
  891. try {
  892. $connect = new Dibi\Connection([
  893. 'driver' => 'sqlite3',
  894. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  895. ]);
  896. foreach ($array['data']['categories']['category'] as $key => $value) {
  897. if ($value['order'] != $value['originalOrder']) {
  898. $connect->query('
  899. UPDATE categories SET', [
  900. 'order' => $value['order'],
  901. ], '
  902. WHERE id=?', $value['id']);
  903. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  904. }
  905. }
  906. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  907. return true;
  908. } catch (Dibi\Exception $e) {
  909. return false;
  910. }
  911. break;
  912. default:
  913. return false;
  914. break;
  915. }
  916. }
  917. function allUsers()
  918. {
  919. try {
  920. $connect = new Dibi\Connection([
  921. 'driver' => 'sqlite3',
  922. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  923. ]);
  924. $users = $connect->fetchAll('SELECT * FROM users');
  925. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  926. foreach ($users as $k => $v) {
  927. // clear password from array
  928. unset($users[$k]['password']);
  929. }
  930. $all['users'] = $users;
  931. $all['groups'] = $groups;
  932. return $all;
  933. } catch (Dibi\Exception $e) {
  934. return false;
  935. }
  936. }
  937. function usernameTaken($username, $email)
  938. {
  939. try {
  940. $connect = new Dibi\Connection([
  941. 'driver' => 'sqlite3',
  942. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  943. ]);
  944. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  945. return ($all) ? true : false;
  946. } catch (Dibi\Exception $e) {
  947. return false;
  948. }
  949. }
  950. function usernameTakenExcept($username, $email, $id)
  951. {
  952. try {
  953. $connect = new Dibi\Connection([
  954. 'driver' => 'sqlite3',
  955. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  956. ]);
  957. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  958. return ($all) ? true : false;
  959. } catch (Dibi\Exception $e) {
  960. return false;
  961. }
  962. }
  963. function createUser($username, $password, $defaults, $email = null)
  964. {
  965. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  966. try {
  967. if (!usernameTaken($username, $email)) {
  968. $createDB = new Dibi\Connection([
  969. 'driver' => 'sqlite3',
  970. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  971. ]);
  972. $userInfo = [
  973. 'username' => $username,
  974. 'password' => password_hash($password, PASSWORD_BCRYPT),
  975. 'email' => $email,
  976. 'group' => $defaults['group'],
  977. 'group_id' => $defaults['group_id'],
  978. 'image' => gravatar($email),
  979. 'register_date' => $GLOBALS['currentTime'],
  980. ];
  981. $createDB->query('INSERT INTO [users]', $userInfo);
  982. return true;
  983. } else {
  984. return false;
  985. }
  986. } catch (Dibi\Exception $e) {
  987. return false;
  988. }
  989. }
  990. function importUsers($array)
  991. {
  992. $imported = 0;
  993. $defaults = defaultUserGroup();
  994. foreach ($array as $user) {
  995. $password = random_ascii_string(30);
  996. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  997. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  998. if (!$newUser) {
  999. writeLog('error', 'Import Function - Error', $user['username']);
  1000. } else {
  1001. $imported++;
  1002. }
  1003. }
  1004. }
  1005. return $imported;
  1006. }
  1007. function importUsersType($array)
  1008. {
  1009. $type = $array['data']['type'];
  1010. if ($type !== '') {
  1011. switch ($type) {
  1012. case 'plex':
  1013. return importUsers(allPlexUsers(true));
  1014. break;
  1015. default:
  1016. return false;
  1017. }
  1018. }
  1019. return false;
  1020. }
  1021. function allTabs()
  1022. {
  1023. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1024. try {
  1025. $connect = new Dibi\Connection([
  1026. 'driver' => 'sqlite3',
  1027. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1028. ]);
  1029. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1030. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1031. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1032. return $all;
  1033. } catch (Dibi\Exception $e) {
  1034. return false;
  1035. }
  1036. }
  1037. return false;
  1038. }
  1039. function allGroups()
  1040. {
  1041. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1042. try {
  1043. $connect = new Dibi\Connection([
  1044. 'driver' => 'sqlite3',
  1045. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1046. ]);
  1047. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1048. return $all;
  1049. } catch (Dibi\Exception $e) {
  1050. return false;
  1051. }
  1052. }
  1053. return false;
  1054. }
  1055. function loadTabs()
  1056. {
  1057. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1058. try {
  1059. $connect = new Dibi\Connection([
  1060. 'driver' => 'sqlite3',
  1061. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1062. ]);
  1063. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1064. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1065. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1066. $all['tabs'] = $tabs;
  1067. foreach ($tabs as $k => $v) {
  1068. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  1069. }
  1070. $count = array_map(function ($element) {
  1071. return $element['category_id'];
  1072. }, $tabs);
  1073. $count = (array_count_values($count));
  1074. foreach ($categories as $k => $v) {
  1075. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1076. }
  1077. $all['categories'] = $categories;
  1078. return $all;
  1079. } catch (Dibi\Exception $e) {
  1080. return false;
  1081. }
  1082. }
  1083. return false;
  1084. }
  1085. function getActiveTokens()
  1086. {
  1087. try {
  1088. $connect = new Dibi\Connection([
  1089. 'driver' => 'sqlite3',
  1090. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1091. ]);
  1092. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1093. return $all;
  1094. } catch (Dibi\Exception $e) {
  1095. return false;
  1096. }
  1097. }
  1098. function revokeToken($array)
  1099. {
  1100. if ($array['data']['token']) {
  1101. try {
  1102. $connect = new Dibi\Connection([
  1103. 'driver' => 'sqlite3',
  1104. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1105. ]);
  1106. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1107. return true;
  1108. } catch (Dibi\Exception $e) {
  1109. return false;
  1110. }
  1111. }
  1112. }