api-functions.php 32 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? 7 : 1;
  25. try {
  26. $database = new Dibi\Connection([
  27. 'driver' => 'sqlite3',
  28. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  29. ]);
  30. $authSuccess = false;
  31. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  32. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  33. switch ($GLOBALS['authType']) {
  34. case 'external':
  35. if (function_exists($function)) {
  36. $authSuccess = $function($username, $password);
  37. }
  38. break;
  39. /** @noinspection PhpMissingBreakStatementInspection */
  40. case 'both':
  41. if (function_exists($function)) {
  42. $authSuccess = $function($username, $password);
  43. }
  44. // no break
  45. default: // Internal
  46. if (!$authSuccess) {
  47. // perform the internal authentication step
  48. if (password_verify($password, $result['password'])) {
  49. $authSuccess = true;
  50. }
  51. }
  52. }
  53. if ($authSuccess) {
  54. // Make sure user exists in database
  55. $userExists = false;
  56. $passwordMatches = false;
  57. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  58. if ($result['username']) {
  59. $userExists = true;
  60. $username = $result['username'];
  61. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  62. }
  63. if ($userExists) {
  64. //does org password need to be updated
  65. if (!$passwordMatches) {
  66. $database->query('
  67. UPDATE users SET', [
  68. 'password' => password_hash($password, PASSWORD_BCRYPT)
  69. ], '
  70. WHERE id=?', $result['id']);
  71. writeLog('success', 'Login Function - User Password updated from backend', $username);
  72. }
  73. // authentication passed - 1) mark active and update token
  74. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  75. writeLoginLog($username, 'success');
  76. writeLog('success', 'Login Function - A User has logged in', $username);
  77. ssoCheck($username, $password, $token); //need to work on this
  78. return true;
  79. } else {
  80. return 'error';
  81. }
  82. } else {
  83. // Create User
  84. ssoCheck($username, $password, $token);
  85. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  86. }
  87. } else {
  88. // authentication failed
  89. writeLoginLog($username, 'error');
  90. writeLog('error', 'Login Function - Wrong Password', $username);
  91. return 'mismatch';
  92. }
  93. } catch (Dibi\Exception $e) {
  94. return $e;
  95. }
  96. }
  97. function createDB($path, $filename)
  98. {
  99. try {
  100. if (!file_exists($path)) {
  101. mkdir($path, 0777, true);
  102. }
  103. $createDB = new Dibi\Connection([
  104. 'driver' => 'sqlite3',
  105. 'database' => $path . $filename,
  106. ]);
  107. // Create Users
  108. $createDB->query('CREATE TABLE `users` (
  109. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  110. `username` TEXT UNIQUE,
  111. `password` TEXT,
  112. `email` TEXT,
  113. `plex_token` TEXT,
  114. `group` TEXT,
  115. `group_id` INTEGER,
  116. `locked` INTEGER,
  117. `image` TEXT,
  118. `register_date` DATE,
  119. `auth_service` TEXT DEFAULT \'internal\'
  120. );');
  121. // Create Tokens
  122. $createDB->query('CREATE TABLE `chatroom` (
  123. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  124. `username` TEXT,
  125. `gravatar` TEXT,
  126. `uid` TEXT,
  127. `date` DATE,
  128. `ip` TEXT,
  129. `message` TEXT
  130. );');
  131. $createDB->query('CREATE TABLE `tokens` (
  132. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  133. `token` TEXT UNIQUE,
  134. `user_id` INTEGER,
  135. `created` DATE,
  136. `expires` DATE
  137. );');
  138. $createDB->query('CREATE TABLE `groups` (
  139. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  140. `group` TEXT UNIQUE,
  141. `group_id` INTEGER,
  142. `image` TEXT,
  143. `default` INTEGER
  144. );');
  145. $createDB->query('CREATE TABLE `categories` (
  146. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  147. `order` INTEGER,
  148. `category` TEXT UNIQUE,
  149. `category_id` INTEGER,
  150. `image` TEXT,
  151. `default` INTEGER
  152. );');
  153. // Create Tabs
  154. $createDB->query('CREATE TABLE `tabs` (
  155. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  156. `order` INTEGER,
  157. `category_id` INTEGER,
  158. `name` TEXT,
  159. `url` TEXT,
  160. `url_local` TEXT,
  161. `default` INTEGER,
  162. `enabled` INTEGER,
  163. `group_id` INTEGER,
  164. `image` TEXT,
  165. `type` INTEGER,
  166. `splash` INTEGER,
  167. `ping` INTEGER,
  168. `ping_url` TEXT
  169. );');
  170. // Create Options
  171. $createDB->query('CREATE TABLE `options` (
  172. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  173. `name` TEXT UNIQUE,
  174. `value` TEXT
  175. );');
  176. // Create Invites
  177. $createDB->query('CREATE TABLE `invites` (
  178. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  179. `code` TEXT UNIQUE,
  180. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  181. `email` TEXT,
  182. `username` TEXT,
  183. `dateused` TIMESTAMP,
  184. `usedby` TEXT,
  185. `ip` TEXT,
  186. `valid` TEXT,
  187. `type` TEXT
  188. );');
  189. return true;
  190. } catch (Dibi\Exception $e) {
  191. return false;
  192. }
  193. }
  194. // Upgrade Database
  195. function updateDB($path, $filename, $oldVerNum = false)
  196. {
  197. try {
  198. $connect = new Dibi\Connection([
  199. 'driver' => 'sqlite3',
  200. 'database' => $path . $filename,
  201. ]);
  202. // Cache current DB
  203. $cache = array();
  204. foreach ($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  205. foreach ($connect->query('SELECT * FROM ' . $table['name'] . ';') as $key => $row) {
  206. foreach ($row as $k => $v) {
  207. if (is_string($k)) {
  208. $cache[$table['name']][$key][$k] = $v;
  209. }
  210. }
  211. }
  212. }
  213. $connect->disconnect();
  214. writeLog('success', 'Update Function - Cached Old Database', 'Database');
  215. } catch (Dibi\Exception $e) {
  216. writeLog('error', 'Update Function - Cache Error [' . $e . ']', 'Database');
  217. return $e;
  218. }
  219. // Remove Current Database
  220. $pathDigest = pathinfo($path . $filename);
  221. if (file_exists($path . $filename)) {
  222. copy($path . $filename, $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db');
  223. unlink($path . $filename);
  224. }
  225. // Create New Database
  226. $success = createDB($path, $filename);
  227. try {
  228. $GLOBALS['connect'] = new Dibi\Connection([
  229. 'driver' => 'sqlite3',
  230. 'database' => $path . $filename,
  231. ]);
  232. // Restore Items
  233. if ($success) {
  234. writeLog('success', 'Update Function - Created New Database', 'Database');
  235. foreach ($cache as $table => $tableData) {
  236. if ($tableData) {
  237. $queryBase = 'INSERT INTO ' . $table . ' (`' . implode('`,`', array_keys(current($tableData))) . '`) values ';
  238. $insertValues = array();
  239. reset($tableData);
  240. foreach ($tableData as $key => $value) {
  241. $insertValues[] = '(' . implode(',', array_map(function ($d) {
  242. return (isset($d) ? str_replace('\/', '/', json_encode($d)) : 'null');
  243. }, $value)) . ')';
  244. }
  245. $GLOBALS['connect']->query($queryBase . implode(',', $insertValues) . ';');
  246. }
  247. }
  248. }
  249. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  250. return true;
  251. } catch (Dibi\Exception $e) {
  252. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  253. return false;
  254. }
  255. }
  256. function createFirstAdmin($path, $filename, $username, $password, $email)
  257. {
  258. try {
  259. $createDB = new Dibi\Connection([
  260. 'driver' => 'sqlite3',
  261. 'database' => $path . $filename,
  262. ]);
  263. $userInfo = [
  264. 'username' => $username,
  265. 'password' => password_hash($password, PASSWORD_BCRYPT),
  266. 'email' => $email,
  267. 'group' => 'Admin',
  268. 'group_id' => 0,
  269. 'image' => gravatar($email),
  270. 'register_date' => $GLOBALS['currentTime'],
  271. ];
  272. $groupInfo0 = [
  273. 'group' => 'Admin',
  274. 'group_id' => 0,
  275. 'default' => false,
  276. 'image' => 'plugins/images/groups/admin.png',
  277. ];
  278. $groupInfo1 = [
  279. 'group' => 'Co-Admin',
  280. 'group_id' => 1,
  281. 'default' => false,
  282. 'image' => 'plugins/images/groups/coadmin.png',
  283. ];
  284. $groupInfo2 = [
  285. 'group' => 'Super User',
  286. 'group_id' => 2,
  287. 'default' => false,
  288. 'image' => 'plugins/images/groups/superuser.png',
  289. ];
  290. $groupInfo3 = [
  291. 'group' => 'Power User',
  292. 'group_id' => 3,
  293. 'default' => false,
  294. 'image' => 'plugins/images/groups/poweruser.png',
  295. ];
  296. $groupInfo4 = [
  297. 'group' => 'User',
  298. 'group_id' => 4,
  299. 'default' => true,
  300. 'image' => 'plugins/images/groups/user.png',
  301. ];
  302. $groupInfoGuest = [
  303. 'group' => 'Guest',
  304. 'group_id' => 999,
  305. 'default' => false,
  306. 'image' => 'plugins/images/groups/guest.png',
  307. ];
  308. $settingsInfo = [
  309. 'order' => 1,
  310. 'category_id' => 0,
  311. 'name' => 'Settings',
  312. 'url' => 'api/?v1/settings/page',
  313. 'default' => false,
  314. 'enabled' => true,
  315. 'group_id' => 1,
  316. 'image' => 'fontawesome::cog',
  317. 'type' => 0
  318. ];
  319. $homepageInfo = [
  320. 'order' => 2,
  321. 'category_id' => 0,
  322. 'name' => 'Homepage',
  323. 'url' => 'api/?v1/homepage/page',
  324. 'default' => false,
  325. 'enabled' => false,
  326. 'group_id' => 4,
  327. 'image' => 'fontawesome::home',
  328. 'type' => 0
  329. ];
  330. $unsortedInfo = [
  331. 'order' => 1,
  332. 'category' => 'Unsorted',
  333. 'category_id' => 0,
  334. 'image' => 'plugins/images/categories/unsorted.png',
  335. 'default' => true
  336. ];
  337. $createDB->query('INSERT INTO [users]', $userInfo);
  338. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  339. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  340. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  341. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  342. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  343. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  344. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  345. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  346. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  347. return true;
  348. } catch (Dibi\Exception $e) {
  349. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  350. return false;
  351. }
  352. }
  353. function defaultUserGroup()
  354. {
  355. try {
  356. $connect = new Dibi\Connection([
  357. 'driver' => 'sqlite3',
  358. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  359. ]);
  360. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  361. return $all;
  362. } catch (Dibi\Exception $e) {
  363. return false;
  364. }
  365. }
  366. function defaultTabCategory()
  367. {
  368. try {
  369. $connect = new Dibi\Connection([
  370. 'driver' => 'sqlite3',
  371. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  372. ]);
  373. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  374. return $all;
  375. } catch (Dibi\Exception $e) {
  376. return false;
  377. }
  378. }
  379. function getGuest()
  380. {
  381. if (isset($GLOBALS['dbLocation'])) {
  382. try {
  383. $connect = new Dibi\Connection([
  384. 'driver' => 'sqlite3',
  385. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  386. ]);
  387. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  388. return $all;
  389. } catch (Dibi\Exception $e) {
  390. return false;
  391. }
  392. } else {
  393. return array(
  394. 'group' => 'Guest',
  395. 'group_id' => 999,
  396. 'image' => 'plugins/images/groups/guest.png'
  397. );
  398. }
  399. }
  400. function adminEditGroup($array)
  401. {
  402. switch ($array['data']['action']) {
  403. case 'changeDefaultGroup':
  404. try {
  405. $connect = new Dibi\Connection([
  406. 'driver' => 'sqlite3',
  407. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  408. ]);
  409. $connect->query('UPDATE groups SET `default` = 0');
  410. $connect->query('
  411. UPDATE groups SET', [
  412. 'default' => 1
  413. ], '
  414. WHERE id=?', $array['data']['id']);
  415. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  416. return true;
  417. } catch (Dibi\Exception $e) {
  418. return false;
  419. }
  420. break;
  421. case 'deleteUserGroup':
  422. try {
  423. $connect = new Dibi\Connection([
  424. 'driver' => 'sqlite3',
  425. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  426. ]);
  427. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  428. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  429. return true;
  430. } catch (Dibi\Exception $e) {
  431. return false;
  432. }
  433. break;
  434. case 'addUserGroup':
  435. try {
  436. $connect = new Dibi\Connection([
  437. 'driver' => 'sqlite3',
  438. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  439. ]);
  440. $newGroup = [
  441. 'group' => $array['data']['newGroupName'],
  442. 'group_id' => $array['data']['newGroupID'],
  443. 'default' => false,
  444. 'image' => $array['data']['newGroupImage'],
  445. ];
  446. $connect->query('INSERT INTO [groups]', $newGroup);
  447. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  448. return true;
  449. } catch (Dibi\Exception $e) {
  450. return false;
  451. }
  452. break;
  453. case 'editUserGroup':
  454. try {
  455. $connect = new Dibi\Connection([
  456. 'driver' => 'sqlite3',
  457. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  458. ]);
  459. $connect->query('
  460. UPDATE groups SET', [
  461. 'group' => $array['data']['groupName'],
  462. 'image' => $array['data']['groupImage'],
  463. ], '
  464. WHERE id=?', $array['data']['id']);
  465. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  466. return true;
  467. } catch (Dibi\Exception $e) {
  468. return false;
  469. }
  470. break;
  471. default:
  472. return false;
  473. break;
  474. }
  475. }
  476. function adminEditUser($array)
  477. {
  478. switch ($array['data']['action']) {
  479. case 'changeGroup':
  480. try {
  481. $connect = new Dibi\Connection([
  482. 'driver' => 'sqlite3',
  483. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  484. ]);
  485. $connect->query('
  486. UPDATE users SET', [
  487. 'group' => $array['data']['newGroupName'],
  488. 'group_id' => $array['data']['newGroupID'],
  489. ], '
  490. WHERE id=?', $array['data']['id']);
  491. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  492. return true;
  493. } catch (Dibi\Exception $e) {
  494. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  495. return false;
  496. }
  497. break;
  498. case 'editUser':
  499. try {
  500. $connect = new Dibi\Connection([
  501. 'driver' => 'sqlite3',
  502. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  503. ]);
  504. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  505. $connect->query('
  506. UPDATE users SET', [
  507. 'username' => $array['data']['username'],
  508. 'email' => $array['data']['email'],
  509. ], '
  510. WHERE id=?', $array['data']['id']);
  511. if (!empty($array['data']['password'])) {
  512. $connect->query('
  513. UPDATE users SET', [
  514. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  515. ], '
  516. WHERE id=?', $array['data']['id']);
  517. }
  518. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  519. return true;
  520. } else {
  521. return false;
  522. }
  523. } catch (Dibi\Exception $e) {
  524. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  525. return false;
  526. }
  527. break;
  528. case 'addNewUser':
  529. $defaults = defaultUserGroup();
  530. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  531. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  532. return true;
  533. } else {
  534. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  535. return 'username taken';
  536. }
  537. break;
  538. case 'deleteUser':
  539. try {
  540. $connect = new Dibi\Connection([
  541. 'driver' => 'sqlite3',
  542. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  543. ]);
  544. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  545. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  546. return true;
  547. } catch (Dibi\Exception $e) {
  548. return false;
  549. }
  550. break;
  551. default:
  552. return false;
  553. break;
  554. }
  555. }
  556. function editTabs($array)
  557. {
  558. switch ($array['data']['action']) {
  559. case 'changeGroup':
  560. try {
  561. $connect = new Dibi\Connection([
  562. 'driver' => 'sqlite3',
  563. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  564. ]);
  565. $connect->query('
  566. UPDATE tabs SET', [
  567. 'group_id' => $array['data']['newGroupID'],
  568. ], '
  569. WHERE id=?', $array['data']['id']);
  570. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  571. return true;
  572. } catch (Dibi\Exception $e) {
  573. return false;
  574. }
  575. break;
  576. case 'changeCategory':
  577. try {
  578. $connect = new Dibi\Connection([
  579. 'driver' => 'sqlite3',
  580. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  581. ]);
  582. $connect->query('
  583. UPDATE tabs SET', [
  584. 'category_id' => $array['data']['newCategoryID'],
  585. ], '
  586. WHERE id=?', $array['data']['id']);
  587. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  588. return true;
  589. } catch (Dibi\Exception $e) {
  590. return false;
  591. }
  592. break;
  593. case 'changeType':
  594. try {
  595. $connect = new Dibi\Connection([
  596. 'driver' => 'sqlite3',
  597. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  598. ]);
  599. $connect->query('
  600. UPDATE tabs SET', [
  601. 'type' => $array['data']['newTypeID'],
  602. ], '
  603. WHERE id=?', $array['data']['id']);
  604. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  605. return true;
  606. } catch (Dibi\Exception $e) {
  607. return false;
  608. }
  609. break;
  610. case 'changeEnabled':
  611. try {
  612. $connect = new Dibi\Connection([
  613. 'driver' => 'sqlite3',
  614. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  615. ]);
  616. $connect->query('
  617. UPDATE tabs SET', [
  618. 'enabled' => $array['data']['tabEnabled'],
  619. ], '
  620. WHERE id=?', $array['data']['id']);
  621. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  622. return true;
  623. } catch (Dibi\Exception $e) {
  624. return false;
  625. }
  626. break;
  627. case 'changeSplash':
  628. try {
  629. $connect = new Dibi\Connection([
  630. 'driver' => 'sqlite3',
  631. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  632. ]);
  633. $connect->query('
  634. UPDATE tabs SET', [
  635. 'splash' => $array['data']['tabSplash'],
  636. ], '
  637. WHERE id=?', $array['data']['id']);
  638. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  639. return true;
  640. } catch (Dibi\Exception $e) {
  641. return false;
  642. }
  643. break;
  644. case 'changePing':
  645. try {
  646. $connect = new Dibi\Connection([
  647. 'driver' => 'sqlite3',
  648. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  649. ]);
  650. $connect->query('
  651. UPDATE tabs SET', [
  652. 'ping' => $array['data']['tabPing'],
  653. ], '
  654. WHERE id=?', $array['data']['id']);
  655. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  656. return true;
  657. } catch (Dibi\Exception $e) {
  658. return false;
  659. }
  660. break;
  661. case 'changeDefault':
  662. try {
  663. $connect = new Dibi\Connection([
  664. 'driver' => 'sqlite3',
  665. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  666. ]);
  667. $connect->query('UPDATE tabs SET `default` = 0');
  668. $connect->query('
  669. UPDATE tabs SET', [
  670. 'default' => 1
  671. ], '
  672. WHERE id=?', $array['data']['id']);
  673. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  674. return true;
  675. } catch (Dibi\Exception $e) {
  676. return false;
  677. }
  678. break;
  679. case 'deleteTab':
  680. try {
  681. $connect = new Dibi\Connection([
  682. 'driver' => 'sqlite3',
  683. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  684. ]);
  685. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  686. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  687. return true;
  688. } catch (Dibi\Exception $e) {
  689. return false;
  690. }
  691. break;
  692. case 'editTab':
  693. try {
  694. $connect = new Dibi\Connection([
  695. 'driver' => 'sqlite3',
  696. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  697. ]);
  698. $connect->query('
  699. UPDATE tabs SET', [
  700. 'name' => $array['data']['tabName'],
  701. 'url' => $array['data']['tabURL'],
  702. 'ping_url' => $array['data']['pingURL'],
  703. 'image' => $array['data']['tabImage'],
  704. ], '
  705. WHERE id=?', $array['data']['id']);
  706. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  707. return true;
  708. } catch (Dibi\Exception $e) {
  709. return false;
  710. }
  711. case 'changeOrder':
  712. try {
  713. $connect = new Dibi\Connection([
  714. 'driver' => 'sqlite3',
  715. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  716. ]);
  717. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  718. if ($value['order'] != $value['originalOrder']) {
  719. $connect->query('
  720. UPDATE tabs SET', [
  721. 'order' => $value['order'],
  722. ], '
  723. WHERE id=?', $value['id']);
  724. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  725. }
  726. }
  727. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  728. return true;
  729. } catch (Dibi\Exception $e) {
  730. return false;
  731. }
  732. break;
  733. case 'addNewTab':
  734. try {
  735. $default = defaultTabCategory()['category_id'];
  736. $connect = new Dibi\Connection([
  737. 'driver' => 'sqlite3',
  738. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  739. ]);
  740. $newTab = [
  741. 'order' => $array['data']['tabOrder'],
  742. 'category_id' => $default,
  743. 'name' => $array['data']['tabName'],
  744. 'url' => $array['data']['tabURL'],
  745. 'ping_url' => $array['data']['pingURL'],
  746. 'default' => $array['data']['tabDefault'],
  747. 'enabled' => 1,
  748. 'group_id' => $array['data']['tabGroupID'],
  749. 'image' => $array['data']['tabImage'],
  750. 'type' => $array['data']['tabType']
  751. ];
  752. $connect->query('INSERT INTO [tabs]', $newTab);
  753. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  754. return true;
  755. } catch (Dibi\Exception $e) {
  756. return false;
  757. }
  758. break;
  759. default:
  760. return false;
  761. break;
  762. }
  763. }
  764. function editCategories($array)
  765. {
  766. switch ($array['data']['action']) {
  767. case 'changeDefault':
  768. try {
  769. $connect = new Dibi\Connection([
  770. 'driver' => 'sqlite3',
  771. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  772. ]);
  773. $connect->query('UPDATE categories SET `default` = 0');
  774. $connect->query('
  775. UPDATE categories SET', [
  776. 'default' => 1
  777. ], '
  778. WHERE id=?', $array['data']['id']);
  779. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  780. return true;
  781. } catch (Dibi\Exception $e) {
  782. return false;
  783. }
  784. break;
  785. case 'deleteCategory':
  786. try {
  787. $connect = new Dibi\Connection([
  788. 'driver' => 'sqlite3',
  789. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  790. ]);
  791. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  792. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  793. return true;
  794. } catch (Dibi\Exception $e) {
  795. return false;
  796. }
  797. break;
  798. case 'addNewCategory':
  799. try {
  800. $connect = new Dibi\Connection([
  801. 'driver' => 'sqlite3',
  802. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  803. ]);
  804. $newCategory = [
  805. 'category' => $array['data']['categoryName'],
  806. 'order' => $array['data']['categoryOrder'],
  807. 'category_id' => $array['data']['categoryID'],
  808. 'default' => false,
  809. 'image' => $array['data']['categoryImage'],
  810. ];
  811. $connect->query('INSERT INTO [categories]', $newCategory);
  812. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  813. return true;
  814. } catch (Dibi\Exception $e) {
  815. return $e;
  816. }
  817. break;
  818. case 'editCategory':
  819. try {
  820. $connect = new Dibi\Connection([
  821. 'driver' => 'sqlite3',
  822. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  823. ]);
  824. $connect->query('
  825. UPDATE categories SET', [
  826. 'category' => $array['data']['name'],
  827. 'image' => $array['data']['image'],
  828. ], '
  829. WHERE id=?', $array['data']['id']);
  830. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  831. return true;
  832. } catch (Dibi\Exception $e) {
  833. return false;
  834. }
  835. break;
  836. case 'changeOrder':
  837. try {
  838. $connect = new Dibi\Connection([
  839. 'driver' => 'sqlite3',
  840. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  841. ]);
  842. foreach ($array['data']['categories']['category'] as $key => $value) {
  843. if ($value['order'] != $value['originalOrder']) {
  844. $connect->query('
  845. UPDATE categories SET', [
  846. 'order' => $value['order'],
  847. ], '
  848. WHERE id=?', $value['id']);
  849. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  850. }
  851. }
  852. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  853. return true;
  854. } catch (Dibi\Exception $e) {
  855. return false;
  856. }
  857. break;
  858. default:
  859. return false;
  860. break;
  861. }
  862. }
  863. function allUsers()
  864. {
  865. try {
  866. $connect = new Dibi\Connection([
  867. 'driver' => 'sqlite3',
  868. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  869. ]);
  870. $users = $connect->fetchAll('SELECT * FROM users');
  871. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  872. foreach ($users as $k => $v) {
  873. // clear password from array
  874. unset($users[$k]['password']);
  875. }
  876. $all['users'] = $users;
  877. $all['groups'] = $groups;
  878. return $all;
  879. } catch (Dibi\Exception $e) {
  880. return false;
  881. }
  882. }
  883. function usernameTaken($username, $email)
  884. {
  885. try {
  886. $connect = new Dibi\Connection([
  887. 'driver' => 'sqlite3',
  888. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  889. ]);
  890. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  891. return ($all) ? true : false;
  892. } catch (Dibi\Exception $e) {
  893. return false;
  894. }
  895. }
  896. function usernameTakenExcept($username, $email, $id)
  897. {
  898. try {
  899. $connect = new Dibi\Connection([
  900. 'driver' => 'sqlite3',
  901. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  902. ]);
  903. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  904. return ($all) ? true : false;
  905. } catch (Dibi\Exception $e) {
  906. return false;
  907. }
  908. }
  909. function createUser($username, $password, $defaults, $email = null)
  910. {
  911. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  912. try {
  913. if (!usernameTaken($username, $email)) {
  914. $createDB = new Dibi\Connection([
  915. 'driver' => 'sqlite3',
  916. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  917. ]);
  918. $userInfo = [
  919. 'username' => $username,
  920. 'password' => password_hash($password, PASSWORD_BCRYPT),
  921. 'email' => $email,
  922. 'group' => $defaults['group'],
  923. 'group_id' => $defaults['group_id'],
  924. 'image' => gravatar($email),
  925. 'register_date' => $GLOBALS['currentTime'],
  926. ];
  927. $createDB->query('INSERT INTO [users]', $userInfo);
  928. return true;
  929. } else {
  930. return false;
  931. }
  932. } catch (Dibi\Exception $e) {
  933. return false;
  934. }
  935. }
  936. function allTabs()
  937. {
  938. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  939. try {
  940. $connect = new Dibi\Connection([
  941. 'driver' => 'sqlite3',
  942. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  943. ]);
  944. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  945. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  946. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  947. return $all;
  948. } catch (Dibi\Exception $e) {
  949. return false;
  950. }
  951. }
  952. return false;
  953. }
  954. function allGroups()
  955. {
  956. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  957. try {
  958. $connect = new Dibi\Connection([
  959. 'driver' => 'sqlite3',
  960. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  961. ]);
  962. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  963. return $all;
  964. } catch (Dibi\Exception $e) {
  965. return false;
  966. }
  967. }
  968. return false;
  969. }
  970. function loadTabs()
  971. {
  972. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  973. try {
  974. $connect = new Dibi\Connection([
  975. 'driver' => 'sqlite3',
  976. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  977. ]);
  978. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  979. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  980. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  981. $all['tabs'] = $tabs;
  982. foreach ($tabs as $k => $v) {
  983. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  984. }
  985. $count = array_map(function ($element) {
  986. return $element['category_id'];
  987. }, $tabs);
  988. $count = (array_count_values($count));
  989. foreach ($categories as $k => $v) {
  990. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  991. }
  992. $all['categories'] = $categories;
  993. return $all;
  994. } catch (Dibi\Exception $e) {
  995. return false;
  996. }
  997. }
  998. return false;
  999. }