index.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554
  1. <?php
  2. $generationTime = -microtime(true);
  3. //include functions
  4. require_once 'functions.php';
  5. //Set result array
  6. $result = array();
  7. //Get request method
  8. $method = $_SERVER['REQUEST_METHOD'];
  9. reset($_GET);
  10. $function = (key($_GET) ? str_replace("/","_",key($_GET)) : false);
  11. //Exit if $function is blank
  12. if($function === false){
  13. $result['status'] = "error";
  14. $result['statusText'] = "No API Path Supplied";
  15. exit(json_encode($result));
  16. }
  17. $result['request'] = key($_GET);
  18. switch ($function) {
  19. case 'v1_settings_page':
  20. switch ($method) {
  21. case 'GET':
  22. if(qualifyRequest(1)){
  23. $result['status'] = 'success';
  24. $result['statusText'] = 'success';
  25. $result['data'] = $pageSettings;
  26. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  27. }else{
  28. $result['status'] = 'error';
  29. $result['statusText'] = 'API/Token invalid or not set';
  30. $result['data'] = null;
  31. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  32. }
  33. break;
  34. default:
  35. $result['status'] = 'error';
  36. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  37. break;
  38. }
  39. break;
  40. case 'v1_settings_settings_logs':
  41. switch ($method) {
  42. case 'GET':
  43. if(qualifyRequest(1)){
  44. $result['status'] = 'success';
  45. $result['statusText'] = 'success';
  46. $result['data'] = $pageSettingsSettingsLogs;
  47. }else{
  48. $result['status'] = 'error';
  49. $result['statusText'] = 'API/Token invalid or not set';
  50. $result['data'] = null;
  51. }
  52. break;
  53. default:
  54. $result['status'] = 'error';
  55. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  56. break;
  57. }
  58. break;
  59. case 'v1_settings_customize_appearance':
  60. switch ($method) {
  61. case 'GET':
  62. if(qualifyRequest(1)){
  63. $result['status'] = 'success';
  64. $result['statusText'] = 'success';
  65. $result['data'] = $pageSettingsCustomizeAppearance;
  66. }else{
  67. $result['status'] = 'error';
  68. $result['statusText'] = 'API/Token invalid or not set';
  69. $result['data'] = null;
  70. }
  71. break;
  72. case 'POST':
  73. if(qualifyRequest(1)){
  74. $result['status'] = 'success';
  75. $result['statusText'] = 'success';
  76. $result['data'] = editAppearance($_POST);
  77. }else{
  78. $result['status'] = 'error';
  79. $result['statusText'] = 'API/Token invalid or not set';
  80. $result['data'] = null;
  81. }
  82. break;
  83. default:
  84. $result['status'] = 'error';
  85. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  86. break;
  87. }
  88. break;
  89. case 'v1_settings_tab_editor_tabs':
  90. switch ($method) {
  91. case 'GET':
  92. if(qualifyRequest(1)){
  93. $result['status'] = 'success';
  94. $result['statusText'] = 'success';
  95. $result['data'] = $pageSettingsTabEditorTabs;
  96. }else{
  97. $result['status'] = 'error';
  98. $result['statusText'] = 'API/Token invalid or not set';
  99. $result['data'] = null;
  100. }
  101. break;
  102. case 'POST':
  103. if(qualifyRequest(1)){
  104. $result['status'] = 'success';
  105. $result['statusText'] = 'success';
  106. $result['data'] = editTabs($_POST);
  107. }else{
  108. $result['status'] = 'error';
  109. $result['statusText'] = 'API/Token invalid or not set';
  110. $result['data'] = null;
  111. }
  112. break;
  113. default:
  114. $result['status'] = 'error';
  115. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  116. break;
  117. }
  118. break;
  119. case 'v1_settings_tab_editor_categories':
  120. switch ($method) {
  121. case 'GET':
  122. if(qualifyRequest(1)){
  123. $result['status'] = 'success';
  124. $result['statusText'] = 'success';
  125. $result['data'] = $pageSettingsTabEditorCategories;
  126. }else{
  127. $result['status'] = 'error';
  128. $result['statusText'] = 'API/Token invalid or not set';
  129. $result['data'] = null;
  130. }
  131. break;
  132. case 'POST':
  133. if(qualifyRequest(1)){
  134. $result['status'] = 'success';
  135. $result['statusText'] = 'success';
  136. $result['data'] = editCategories($_POST);
  137. }else{
  138. $result['status'] = 'error';
  139. $result['statusText'] = 'API/Token invalid or not set';
  140. $result['data'] = null;
  141. }
  142. break;
  143. default:
  144. $result['status'] = 'error';
  145. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  146. break;
  147. }
  148. break;
  149. case 'v1_settings_user_manage_users':
  150. switch ($method) {
  151. case 'GET':
  152. if(qualifyRequest(1)){
  153. $result['status'] = 'success';
  154. $result['statusText'] = 'success';
  155. $result['data'] = $pageSettingsUserManageUsers;
  156. }else{
  157. $result['status'] = 'error';
  158. $result['statusText'] = 'API/Token invalid or not set';
  159. $result['data'] = null;
  160. }
  161. break;
  162. case 'POST':
  163. if(qualifyRequest(1)){
  164. $result['status'] = 'success';
  165. $result['statusText'] = 'success';
  166. $result['data'] = adminEditUser($_POST);
  167. }elseif(qualifyRequest(998)){
  168. $result['status'] = 'success';
  169. $result['statusText'] = 'success';
  170. $result['data'] = editUser($_POST);
  171. }else{
  172. $result['status'] = 'error';
  173. $result['statusText'] = 'API/Token invalid or not set';
  174. $result['data'] = null;
  175. }
  176. break;
  177. default:
  178. $result['status'] = 'error';
  179. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  180. break;
  181. }
  182. break;
  183. case 'v1_settings_user_manage_groups':
  184. switch ($method) {
  185. case 'GET':
  186. if(qualifyRequest(1)){
  187. $result['status'] = 'success';
  188. $result['statusText'] = 'success';
  189. $result['data'] = $pageSettingsUserManageGroups;
  190. }else{
  191. $result['status'] = 'error';
  192. $result['statusText'] = 'API/Token invalid or not set';
  193. $result['data'] = null;
  194. }
  195. break;
  196. case 'POST':
  197. if(qualifyRequest(1)){
  198. $result['status'] = 'success';
  199. $result['statusText'] = 'success';
  200. $result['data'] = adminEditGroup($_POST);
  201. }else{
  202. $result['status'] = 'error';
  203. $result['statusText'] = 'API/Token invalid or not set';
  204. $result['data'] = null;
  205. }
  206. break;
  207. default:
  208. $result['status'] = 'error';
  209. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  210. break;
  211. }
  212. break;
  213. case 'v1_wizard_page':
  214. switch ($method) {
  215. case 'GET':
  216. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  217. $result['status'] = 'success';
  218. $result['statusText'] = 'success';
  219. $result['data'] = $pageWizard;
  220. }else{
  221. $result['status'] = 'error';
  222. $result['statusText'] = 'Wizard has already been run';
  223. $result['data'] = null;
  224. }
  225. break;
  226. default:
  227. $result['status'] = 'error';
  228. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  229. break;
  230. }
  231. break;
  232. case 'v1_dependencies_page':
  233. switch ($method) {
  234. case 'GET':
  235. $result['status'] = 'success';
  236. $result['statusText'] = 'success';
  237. $result['data'] = $pageDependencies;
  238. break;
  239. default:
  240. $result['status'] = 'error';
  241. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  242. break;
  243. }
  244. break;
  245. case 'v1_wizard_config':
  246. switch ($method) {
  247. case 'POST':
  248. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  249. $result['status'] = 'success';
  250. $result['statusText'] = 'success';
  251. $result['data'] = wizardConfig($_POST);
  252. }else{
  253. $result['status'] = 'error';
  254. $result['statusText'] = 'Wizard has already been run';
  255. $result['data'] = null;
  256. }
  257. break;
  258. default:
  259. $result['status'] = 'error';
  260. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  261. break;
  262. }
  263. break;
  264. case 'v1_login':
  265. switch ($method) {
  266. case 'POST':
  267. $result['status'] = 'success';
  268. $result['statusText'] = 'success';
  269. $result['data'] = login($_POST);
  270. break;
  271. default:
  272. $result['status'] = 'error';
  273. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  274. break;
  275. }
  276. break;
  277. case 'v1_register':
  278. switch ($method) {
  279. case 'POST':
  280. $result['status'] = 'success';
  281. $result['statusText'] = 'success';
  282. $result['data'] = register($_POST);
  283. break;
  284. default:
  285. $result['status'] = 'error';
  286. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  287. break;
  288. }
  289. break;
  290. case 'v1_upgrade':
  291. case 'v1_update':
  292. case 'v1_force':
  293. switch ($method) {
  294. case 'POST':
  295. $result['status'] = 'success';
  296. $result['statusText'] = 'success';
  297. $result['data'] = upgradeInstall($_POST['data']['branch'],$_POST['data']['stage']);
  298. break;
  299. default:
  300. $result['status'] = 'error';
  301. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  302. break;
  303. }
  304. break;
  305. case 'v1_login_page':
  306. switch ($method) {
  307. case 'GET':
  308. $result['status'] = 'success';
  309. $result['statusText'] = 'success';
  310. $result['data'] = $pageLogin;
  311. break;
  312. default:
  313. $result['status'] = 'error';
  314. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  315. break;
  316. }
  317. break;
  318. case 'v1_lockscreen':
  319. switch ($method) {
  320. case 'GET':
  321. $result['status'] = 'success';
  322. $result['statusText'] = 'success';
  323. $result['data'] = $pageLockScreen;
  324. break;
  325. default:
  326. $result['status'] = 'error';
  327. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  328. break;
  329. }
  330. break;
  331. case 'v1_login_log':
  332. switch ($method) {
  333. case 'GET':
  334. if(qualifyRequest(1)){
  335. $result['status'] = 'success';
  336. $result['statusText'] = 'success';
  337. $result['data'] = getLog('loginLog');
  338. }else{
  339. $result['status'] = 'error';
  340. $result['statusText'] = 'API/Token invalid or not set';
  341. $result['data'] = null;
  342. }
  343. break;
  344. default:
  345. $result['status'] = 'error';
  346. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  347. break;
  348. }
  349. break;
  350. case 'v1_organizr_log':
  351. switch ($method) {
  352. case 'GET':
  353. if(qualifyRequest(1)){
  354. $result['status'] = 'success';
  355. $result['statusText'] = 'success';
  356. $result['data'] = getLog('org');
  357. }else{
  358. $result['status'] = 'error';
  359. $result['statusText'] = 'API/Token invalid or not set';
  360. $result['data'] = null;
  361. }
  362. break;
  363. default:
  364. $result['status'] = 'error';
  365. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  366. break;
  367. }
  368. break;
  369. case 'v1_user_list':
  370. switch ($method) {
  371. case 'GET':
  372. if(qualifyRequest(1)){
  373. $result['status'] = 'success';
  374. $result['statusText'] = 'success';
  375. $result['data'] = allUsers();
  376. }else{
  377. $result['status'] = 'error';
  378. $result['statusText'] = 'API/Token invalid or not set';
  379. $result['data'] = null;
  380. }
  381. break;
  382. default:
  383. $result['status'] = 'error';
  384. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  385. break;
  386. }
  387. break;
  388. case 'v1_tab_list':
  389. switch ($method) {
  390. case 'GET':
  391. if(qualifyRequest(1)){
  392. $result['status'] = 'success';
  393. $result['statusText'] = 'success';
  394. $result['data'] = allTabs();
  395. }else{
  396. $result['status'] = 'error';
  397. $result['statusText'] = 'API/Token invalid or not set';
  398. $result['data'] = null;
  399. }
  400. break;
  401. default:
  402. $result['status'] = 'error';
  403. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  404. break;
  405. }
  406. break;
  407. case 'v1_customize_appearance':
  408. switch ($method) {
  409. case 'GET':
  410. if(qualifyRequest(1)){
  411. $result['status'] = 'success';
  412. $result['statusText'] = 'success';
  413. $result['data'] = getCustomizeAppearance();
  414. }else{
  415. $result['status'] = 'error';
  416. $result['statusText'] = 'API/Token invalid or not set';
  417. $result['data'] = null;
  418. }
  419. break;
  420. default:
  421. $result['status'] = 'error';
  422. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  423. break;
  424. }
  425. break;
  426. case 'v1_user_edit':
  427. switch ($method) {
  428. case 'POST':
  429. if(qualifyRequest(1)){
  430. $result['status'] = 'success';
  431. $result['statusText'] = 'success';
  432. $result['data'] = adminEditUser($_POST);
  433. }elseif(qualifyRequest(998)){
  434. $result['status'] = 'success';
  435. $result['statusText'] = 'success';
  436. $result['data'] = editUser($_POST);
  437. }else{
  438. $result['status'] = 'error';
  439. $result['statusText'] = 'API/Token invalid or not set';
  440. $result['data'] = null;
  441. }
  442. break;
  443. default:
  444. $result['status'] = 'error';
  445. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  446. break;
  447. }
  448. break;
  449. case 'v1_logout':
  450. switch ($method) {
  451. case 'GET':
  452. $result['status'] = 'success';
  453. $result['statusText'] = 'success';
  454. $result['data'] = logout();
  455. break;
  456. default:
  457. $result['status'] = 'error';
  458. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  459. break;
  460. }
  461. break;
  462. case 'v1_launch_organizr':
  463. switch ($method) {
  464. case 'GET':
  465. $status = array();
  466. $result['status'] = 'success';
  467. $result['statusText'] = 'success';
  468. $status['status'] = organizrStatus();
  469. $result['appearance'] = loadAppearance();
  470. $status['user'] = $GLOBALS['organizrUser'];
  471. $status['categories'] = loadTabs()['categories'];
  472. $status['tabs'] = loadTabs()['tabs'];
  473. $result['data'] = $status;
  474. $result['branch'] = $GLOBALS['branch'];
  475. break;
  476. default:
  477. $result['status'] = 'error';
  478. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  479. break;
  480. }
  481. break;
  482. case 'v1_auth':
  483. switch ($method) {
  484. case 'GET':
  485. auth();
  486. break;
  487. default:
  488. $result['status'] = 'error';
  489. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  490. break;
  491. }
  492. break;
  493. case 'v1_plugin':
  494. switch ($method) {
  495. case 'GET':
  496. if(qualifyRequest(1)){
  497. $result['status'] = 'success';
  498. $result['statusText'] = 'success';
  499. $result['data'] = 'plugin admin';
  500. }elseif(qualifyRequest(998)){
  501. $result['status'] = 'success';
  502. $result['statusText'] = 'success';
  503. $result['data'] = 'plugin logged in';
  504. }elseif(qualifyRequest(999)){
  505. $result['status'] = 'success';
  506. $result['statusText'] = 'success';
  507. $result['data'] = 'plugin guest';
  508. }else{
  509. $result['status'] = 'error';
  510. $result['statusText'] = 'API/Token invalid or not set';
  511. $result['data'] = null;
  512. }
  513. break;
  514. case 'POST':
  515. if(qualifyRequest(1)){
  516. $result['status'] = 'success';
  517. $result['statusText'] = 'success';
  518. $result['data'] = 'plugin admin';
  519. }elseif(qualifyRequest(998)){
  520. $result['status'] = 'success';
  521. $result['statusText'] = 'success';
  522. $result['data'] = 'plugin logged in';
  523. }elseif(qualifyRequest(999)){
  524. $result['status'] = 'success';
  525. $result['statusText'] = 'success';
  526. $result['data'] = 'plugin guest';
  527. }else{
  528. $result['status'] = 'error';
  529. $result['statusText'] = 'API/Token invalid or not set';
  530. $result['data'] = null;
  531. }
  532. break;
  533. default:
  534. $result['status'] = 'error';
  535. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  536. break;
  537. }
  538. break;
  539. default:
  540. //No Function Available
  541. $result['status'] = 'error';
  542. $result['statusText'] = 'function requested is not defined';
  543. break;
  544. }
  545. //Set Default Result
  546. if(!$result){
  547. $result['status'] = "error";
  548. $result['error'] = "An error has occurred";
  549. }
  550. $result['generationDate'] = $GLOBALS['currentTime'];
  551. $generationTime += microtime(true);
  552. $result['generationTime'] = (sprintf('%f', $generationTime)*1000).'ms';
  553. //return JSON array
  554. exit(json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));