api-functions.php 32 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? 7 : 1;
  25. try {
  26. $database = new Dibi\Connection([
  27. 'driver' => 'sqlite3',
  28. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  29. ]);
  30. $authSuccess = false;
  31. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  32. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  33. switch ($GLOBALS['authType']) {
  34. case 'external':
  35. if (function_exists($function)) {
  36. $authSuccess = $function($username, $password);
  37. }
  38. break;
  39. /** @noinspection PhpMissingBreakStatementInspection */
  40. case 'both':
  41. if (function_exists($function)) {
  42. $authSuccess = $function($username, $password);
  43. }
  44. // no break
  45. default: // Internal
  46. if (!$authSuccess) {
  47. // perform the internal authentication step
  48. if (password_verify($password, $result['password'])) {
  49. $authSuccess = true;
  50. }
  51. }
  52. }
  53. if ($authSuccess) {
  54. // Make sure user exists in database
  55. $userExists = false;
  56. $passwordMatches = false;
  57. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  58. if ($result['username']) {
  59. $userExists = true;
  60. $username = $result['username'];
  61. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  62. }
  63. if ($userExists) {
  64. //does org password need to be updated
  65. if (!$passwordMatches) {
  66. $database->query('
  67. UPDATE users SET', [
  68. 'password' => password_hash($password, PASSWORD_BCRYPT)
  69. ], '
  70. WHERE id=?', $result['id']);
  71. writeLog('success', 'Login Function - User Password updated from backend', $username);
  72. }
  73. // 2FA might go here
  74. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  75. $TFA = explode('::', $result['auth_service']);
  76. // Is code with login info?
  77. if ($tfaCode == '') {
  78. return '2FA';
  79. } else {
  80. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  81. return '2FA-incorrect';
  82. }
  83. }
  84. }
  85. // End 2FA
  86. // authentication passed - 1) mark active and update token
  87. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  88. writeLoginLog($username, 'success');
  89. writeLog('success', 'Login Function - A User has logged in', $username);
  90. ssoCheck($username, $password, $token); //need to work on this
  91. return true;
  92. } else {
  93. return 'error';
  94. }
  95. } else {
  96. // Create User
  97. ssoCheck($username, $password, $token);
  98. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''));
  99. }
  100. } else {
  101. // authentication failed
  102. writeLoginLog($username, 'error');
  103. writeLog('error', 'Login Function - Wrong Password', $username);
  104. return 'mismatch';
  105. }
  106. } catch (Dibi\Exception $e) {
  107. return $e;
  108. }
  109. }
  110. function createDB($path, $filename)
  111. {
  112. try {
  113. if (!file_exists($path)) {
  114. mkdir($path, 0777, true);
  115. }
  116. $createDB = new Dibi\Connection([
  117. 'driver' => 'sqlite3',
  118. 'database' => $path . $filename,
  119. ]);
  120. // Create Users
  121. $createDB->query('CREATE TABLE `users` (
  122. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  123. `username` TEXT UNIQUE,
  124. `password` TEXT,
  125. `email` TEXT,
  126. `plex_token` TEXT,
  127. `group` TEXT,
  128. `group_id` INTEGER,
  129. `locked` INTEGER,
  130. `image` TEXT,
  131. `register_date` DATE,
  132. `auth_service` TEXT DEFAULT \'internal\'
  133. );');
  134. // Create Tokens
  135. $createDB->query('CREATE TABLE `chatroom` (
  136. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  137. `username` TEXT,
  138. `gravatar` TEXT,
  139. `uid` TEXT,
  140. `date` DATE,
  141. `ip` TEXT,
  142. `message` TEXT
  143. );');
  144. $createDB->query('CREATE TABLE `tokens` (
  145. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  146. `token` TEXT UNIQUE,
  147. `user_id` INTEGER,
  148. `created` DATE,
  149. `expires` DATE
  150. );');
  151. $createDB->query('CREATE TABLE `groups` (
  152. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  153. `group` TEXT UNIQUE,
  154. `group_id` INTEGER,
  155. `image` TEXT,
  156. `default` INTEGER
  157. );');
  158. $createDB->query('CREATE TABLE `categories` (
  159. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  160. `order` INTEGER,
  161. `category` TEXT UNIQUE,
  162. `category_id` INTEGER,
  163. `image` TEXT,
  164. `default` INTEGER
  165. );');
  166. // Create Tabs
  167. $createDB->query('CREATE TABLE `tabs` (
  168. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  169. `order` INTEGER,
  170. `category_id` INTEGER,
  171. `name` TEXT,
  172. `url` TEXT,
  173. `url_local` TEXT,
  174. `default` INTEGER,
  175. `enabled` INTEGER,
  176. `group_id` INTEGER,
  177. `image` TEXT,
  178. `type` INTEGER,
  179. `splash` INTEGER,
  180. `ping` INTEGER,
  181. `ping_url` TEXT
  182. );');
  183. // Create Options
  184. $createDB->query('CREATE TABLE `options` (
  185. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  186. `name` TEXT UNIQUE,
  187. `value` TEXT
  188. );');
  189. // Create Invites
  190. $createDB->query('CREATE TABLE `invites` (
  191. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  192. `code` TEXT UNIQUE,
  193. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  194. `email` TEXT,
  195. `username` TEXT,
  196. `dateused` TIMESTAMP,
  197. `usedby` TEXT,
  198. `ip` TEXT,
  199. `valid` TEXT,
  200. `type` TEXT
  201. );');
  202. return true;
  203. } catch (Dibi\Exception $e) {
  204. return false;
  205. }
  206. }
  207. // Upgrade Database
  208. function updateDB($path, $filename, $oldVerNum = false)
  209. {
  210. try {
  211. $connect = new Dibi\Connection([
  212. 'driver' => 'sqlite3',
  213. 'database' => $path . $filename,
  214. ]);
  215. // Cache current DB
  216. $cache = array();
  217. foreach ($connect->query('SELECT name FROM sqlite_master WHERE type="table";') as $table) {
  218. foreach ($connect->query('SELECT * FROM ' . $table['name'] . ';') as $key => $row) {
  219. foreach ($row as $k => $v) {
  220. if (is_string($k)) {
  221. $cache[$table['name']][$key][$k] = $v;
  222. }
  223. }
  224. }
  225. }
  226. $connect->disconnect();
  227. writeLog('success', 'Update Function - Cached Old Database', 'Database');
  228. } catch (Dibi\Exception $e) {
  229. writeLog('error', 'Update Function - Cache Error [' . $e . ']', 'Database');
  230. return $e;
  231. }
  232. // Remove Current Database
  233. $pathDigest = pathinfo($path . $filename);
  234. if (file_exists($path . $filename)) {
  235. copy($path . $filename, $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db');
  236. unlink($path . $filename);
  237. }
  238. // Create New Database
  239. $success = createDB($path, $filename);
  240. try {
  241. $GLOBALS['connect'] = new Dibi\Connection([
  242. 'driver' => 'sqlite3',
  243. 'database' => $path . $filename,
  244. ]);
  245. // Restore Items
  246. if ($success) {
  247. writeLog('success', 'Update Function - Created New Database', 'Database');
  248. foreach ($cache as $table => $tableData) {
  249. if ($tableData) {
  250. $queryBase = 'INSERT INTO ' . $table . ' (`' . implode('`,`', array_keys(current($tableData))) . '`) values ';
  251. $insertValues = array();
  252. reset($tableData);
  253. foreach ($tableData as $key => $value) {
  254. $insertValues[] = '(' . implode(',', array_map(function ($d) {
  255. return (isset($d) ? str_replace('\/', '/', json_encode($d)) : 'null');
  256. }, $value)) . ')';
  257. }
  258. $GLOBALS['connect']->query($queryBase . implode(',', $insertValues) . ';');
  259. }
  260. }
  261. }
  262. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  263. return true;
  264. } catch (Dibi\Exception $e) {
  265. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  266. return false;
  267. }
  268. }
  269. function createFirstAdmin($path, $filename, $username, $password, $email)
  270. {
  271. try {
  272. $createDB = new Dibi\Connection([
  273. 'driver' => 'sqlite3',
  274. 'database' => $path . $filename,
  275. ]);
  276. $userInfo = [
  277. 'username' => $username,
  278. 'password' => password_hash($password, PASSWORD_BCRYPT),
  279. 'email' => $email,
  280. 'group' => 'Admin',
  281. 'group_id' => 0,
  282. 'image' => gravatar($email),
  283. 'register_date' => $GLOBALS['currentTime'],
  284. ];
  285. $groupInfo0 = [
  286. 'group' => 'Admin',
  287. 'group_id' => 0,
  288. 'default' => false,
  289. 'image' => 'plugins/images/groups/admin.png',
  290. ];
  291. $groupInfo1 = [
  292. 'group' => 'Co-Admin',
  293. 'group_id' => 1,
  294. 'default' => false,
  295. 'image' => 'plugins/images/groups/coadmin.png',
  296. ];
  297. $groupInfo2 = [
  298. 'group' => 'Super User',
  299. 'group_id' => 2,
  300. 'default' => false,
  301. 'image' => 'plugins/images/groups/superuser.png',
  302. ];
  303. $groupInfo3 = [
  304. 'group' => 'Power User',
  305. 'group_id' => 3,
  306. 'default' => false,
  307. 'image' => 'plugins/images/groups/poweruser.png',
  308. ];
  309. $groupInfo4 = [
  310. 'group' => 'User',
  311. 'group_id' => 4,
  312. 'default' => true,
  313. 'image' => 'plugins/images/groups/user.png',
  314. ];
  315. $groupInfoGuest = [
  316. 'group' => 'Guest',
  317. 'group_id' => 999,
  318. 'default' => false,
  319. 'image' => 'plugins/images/groups/guest.png',
  320. ];
  321. $settingsInfo = [
  322. 'order' => 1,
  323. 'category_id' => 0,
  324. 'name' => 'Settings',
  325. 'url' => 'api/?v1/settings/page',
  326. 'default' => false,
  327. 'enabled' => true,
  328. 'group_id' => 1,
  329. 'image' => 'fontawesome::cog',
  330. 'type' => 0
  331. ];
  332. $homepageInfo = [
  333. 'order' => 2,
  334. 'category_id' => 0,
  335. 'name' => 'Homepage',
  336. 'url' => 'api/?v1/homepage/page',
  337. 'default' => false,
  338. 'enabled' => false,
  339. 'group_id' => 4,
  340. 'image' => 'fontawesome::home',
  341. 'type' => 0
  342. ];
  343. $unsortedInfo = [
  344. 'order' => 1,
  345. 'category' => 'Unsorted',
  346. 'category_id' => 0,
  347. 'image' => 'plugins/images/categories/unsorted.png',
  348. 'default' => true
  349. ];
  350. $createDB->query('INSERT INTO [users]', $userInfo);
  351. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  352. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  353. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  354. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  355. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  356. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  357. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  358. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  359. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  360. return true;
  361. } catch (Dibi\Exception $e) {
  362. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  363. return false;
  364. }
  365. }
  366. function defaultUserGroup()
  367. {
  368. try {
  369. $connect = new Dibi\Connection([
  370. 'driver' => 'sqlite3',
  371. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  372. ]);
  373. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  374. return $all;
  375. } catch (Dibi\Exception $e) {
  376. return false;
  377. }
  378. }
  379. function defaultTabCategory()
  380. {
  381. try {
  382. $connect = new Dibi\Connection([
  383. 'driver' => 'sqlite3',
  384. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  385. ]);
  386. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  387. return $all;
  388. } catch (Dibi\Exception $e) {
  389. return false;
  390. }
  391. }
  392. function getGuest()
  393. {
  394. if (isset($GLOBALS['dbLocation'])) {
  395. try {
  396. $connect = new Dibi\Connection([
  397. 'driver' => 'sqlite3',
  398. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  399. ]);
  400. $all = $connect->fetch('SELECT * FROM groups WHERE `group` = "Guest"');
  401. return $all;
  402. } catch (Dibi\Exception $e) {
  403. return false;
  404. }
  405. } else {
  406. return array(
  407. 'group' => 'Guest',
  408. 'group_id' => 999,
  409. 'image' => 'plugins/images/groups/guest.png'
  410. );
  411. }
  412. }
  413. function adminEditGroup($array)
  414. {
  415. switch ($array['data']['action']) {
  416. case 'changeDefaultGroup':
  417. try {
  418. $connect = new Dibi\Connection([
  419. 'driver' => 'sqlite3',
  420. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  421. ]);
  422. $connect->query('UPDATE groups SET `default` = 0');
  423. $connect->query('
  424. UPDATE groups SET', [
  425. 'default' => 1
  426. ], '
  427. WHERE id=?', $array['data']['id']);
  428. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  429. return true;
  430. } catch (Dibi\Exception $e) {
  431. return false;
  432. }
  433. break;
  434. case 'deleteUserGroup':
  435. try {
  436. $connect = new Dibi\Connection([
  437. 'driver' => 'sqlite3',
  438. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  439. ]);
  440. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  441. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  442. return true;
  443. } catch (Dibi\Exception $e) {
  444. return false;
  445. }
  446. break;
  447. case 'addUserGroup':
  448. try {
  449. $connect = new Dibi\Connection([
  450. 'driver' => 'sqlite3',
  451. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  452. ]);
  453. $newGroup = [
  454. 'group' => $array['data']['newGroupName'],
  455. 'group_id' => $array['data']['newGroupID'],
  456. 'default' => false,
  457. 'image' => $array['data']['newGroupImage'],
  458. ];
  459. $connect->query('INSERT INTO [groups]', $newGroup);
  460. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  461. return true;
  462. } catch (Dibi\Exception $e) {
  463. return false;
  464. }
  465. break;
  466. case 'editUserGroup':
  467. try {
  468. $connect = new Dibi\Connection([
  469. 'driver' => 'sqlite3',
  470. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  471. ]);
  472. $connect->query('
  473. UPDATE groups SET', [
  474. 'group' => $array['data']['groupName'],
  475. 'image' => $array['data']['groupImage'],
  476. ], '
  477. WHERE id=?', $array['data']['id']);
  478. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  479. return true;
  480. } catch (Dibi\Exception $e) {
  481. return false;
  482. }
  483. break;
  484. default:
  485. return false;
  486. break;
  487. }
  488. }
  489. function adminEditUser($array)
  490. {
  491. switch ($array['data']['action']) {
  492. case 'changeGroup':
  493. try {
  494. $connect = new Dibi\Connection([
  495. 'driver' => 'sqlite3',
  496. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  497. ]);
  498. $connect->query('
  499. UPDATE users SET', [
  500. 'group' => $array['data']['newGroupName'],
  501. 'group_id' => $array['data']['newGroupID'],
  502. ], '
  503. WHERE id=?', $array['data']['id']);
  504. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  505. return true;
  506. } catch (Dibi\Exception $e) {
  507. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  508. return false;
  509. }
  510. break;
  511. case 'editUser':
  512. try {
  513. $connect = new Dibi\Connection([
  514. 'driver' => 'sqlite3',
  515. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  516. ]);
  517. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  518. $connect->query('
  519. UPDATE users SET', [
  520. 'username' => $array['data']['username'],
  521. 'email' => $array['data']['email'],
  522. ], '
  523. WHERE id=?', $array['data']['id']);
  524. if (!empty($array['data']['password'])) {
  525. $connect->query('
  526. UPDATE users SET', [
  527. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  528. ], '
  529. WHERE id=?', $array['data']['id']);
  530. }
  531. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  532. return true;
  533. } else {
  534. return false;
  535. }
  536. } catch (Dibi\Exception $e) {
  537. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  538. return false;
  539. }
  540. break;
  541. case 'addNewUser':
  542. $defaults = defaultUserGroup();
  543. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  544. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  545. return true;
  546. } else {
  547. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  548. return 'username taken';
  549. }
  550. break;
  551. case 'deleteUser':
  552. try {
  553. $connect = new Dibi\Connection([
  554. 'driver' => 'sqlite3',
  555. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  556. ]);
  557. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  558. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  559. return true;
  560. } catch (Dibi\Exception $e) {
  561. return false;
  562. }
  563. break;
  564. default:
  565. return false;
  566. break;
  567. }
  568. }
  569. function editTabs($array)
  570. {
  571. switch ($array['data']['action']) {
  572. case 'changeGroup':
  573. try {
  574. $connect = new Dibi\Connection([
  575. 'driver' => 'sqlite3',
  576. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  577. ]);
  578. $connect->query('
  579. UPDATE tabs SET', [
  580. 'group_id' => $array['data']['newGroupID'],
  581. ], '
  582. WHERE id=?', $array['data']['id']);
  583. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  584. return true;
  585. } catch (Dibi\Exception $e) {
  586. return false;
  587. }
  588. break;
  589. case 'changeCategory':
  590. try {
  591. $connect = new Dibi\Connection([
  592. 'driver' => 'sqlite3',
  593. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  594. ]);
  595. $connect->query('
  596. UPDATE tabs SET', [
  597. 'category_id' => $array['data']['newCategoryID'],
  598. ], '
  599. WHERE id=?', $array['data']['id']);
  600. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  601. return true;
  602. } catch (Dibi\Exception $e) {
  603. return false;
  604. }
  605. break;
  606. case 'changeType':
  607. try {
  608. $connect = new Dibi\Connection([
  609. 'driver' => 'sqlite3',
  610. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  611. ]);
  612. $connect->query('
  613. UPDATE tabs SET', [
  614. 'type' => $array['data']['newTypeID'],
  615. ], '
  616. WHERE id=?', $array['data']['id']);
  617. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  618. return true;
  619. } catch (Dibi\Exception $e) {
  620. return false;
  621. }
  622. break;
  623. case 'changeEnabled':
  624. try {
  625. $connect = new Dibi\Connection([
  626. 'driver' => 'sqlite3',
  627. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  628. ]);
  629. $connect->query('
  630. UPDATE tabs SET', [
  631. 'enabled' => $array['data']['tabEnabled'],
  632. ], '
  633. WHERE id=?', $array['data']['id']);
  634. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  635. return true;
  636. } catch (Dibi\Exception $e) {
  637. return false;
  638. }
  639. break;
  640. case 'changeSplash':
  641. try {
  642. $connect = new Dibi\Connection([
  643. 'driver' => 'sqlite3',
  644. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  645. ]);
  646. $connect->query('
  647. UPDATE tabs SET', [
  648. 'splash' => $array['data']['tabSplash'],
  649. ], '
  650. WHERE id=?', $array['data']['id']);
  651. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  652. return true;
  653. } catch (Dibi\Exception $e) {
  654. return false;
  655. }
  656. break;
  657. case 'changePing':
  658. try {
  659. $connect = new Dibi\Connection([
  660. 'driver' => 'sqlite3',
  661. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  662. ]);
  663. $connect->query('
  664. UPDATE tabs SET', [
  665. 'ping' => $array['data']['tabPing'],
  666. ], '
  667. WHERE id=?', $array['data']['id']);
  668. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  669. return true;
  670. } catch (Dibi\Exception $e) {
  671. return false;
  672. }
  673. break;
  674. case 'changeDefault':
  675. try {
  676. $connect = new Dibi\Connection([
  677. 'driver' => 'sqlite3',
  678. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  679. ]);
  680. $connect->query('UPDATE tabs SET `default` = 0');
  681. $connect->query('
  682. UPDATE tabs SET', [
  683. 'default' => 1
  684. ], '
  685. WHERE id=?', $array['data']['id']);
  686. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  687. return true;
  688. } catch (Dibi\Exception $e) {
  689. return false;
  690. }
  691. break;
  692. case 'deleteTab':
  693. try {
  694. $connect = new Dibi\Connection([
  695. 'driver' => 'sqlite3',
  696. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  697. ]);
  698. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  699. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  700. return true;
  701. } catch (Dibi\Exception $e) {
  702. return false;
  703. }
  704. break;
  705. case 'editTab':
  706. try {
  707. $connect = new Dibi\Connection([
  708. 'driver' => 'sqlite3',
  709. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  710. ]);
  711. $connect->query('
  712. UPDATE tabs SET', [
  713. 'name' => $array['data']['tabName'],
  714. 'url' => $array['data']['tabURL'],
  715. 'ping_url' => $array['data']['pingURL'],
  716. 'image' => $array['data']['tabImage'],
  717. ], '
  718. WHERE id=?', $array['data']['id']);
  719. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  720. return true;
  721. } catch (Dibi\Exception $e) {
  722. return false;
  723. }
  724. case 'changeOrder':
  725. try {
  726. $connect = new Dibi\Connection([
  727. 'driver' => 'sqlite3',
  728. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  729. ]);
  730. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  731. if ($value['order'] != $value['originalOrder']) {
  732. $connect->query('
  733. UPDATE tabs SET', [
  734. 'order' => $value['order'],
  735. ], '
  736. WHERE id=?', $value['id']);
  737. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  738. }
  739. }
  740. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  741. return true;
  742. } catch (Dibi\Exception $e) {
  743. return false;
  744. }
  745. break;
  746. case 'addNewTab':
  747. try {
  748. $default = defaultTabCategory()['category_id'];
  749. $connect = new Dibi\Connection([
  750. 'driver' => 'sqlite3',
  751. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  752. ]);
  753. $newTab = [
  754. 'order' => $array['data']['tabOrder'],
  755. 'category_id' => $default,
  756. 'name' => $array['data']['tabName'],
  757. 'url' => $array['data']['tabURL'],
  758. 'ping_url' => $array['data']['pingURL'],
  759. 'default' => $array['data']['tabDefault'],
  760. 'enabled' => 1,
  761. 'group_id' => $array['data']['tabGroupID'],
  762. 'image' => $array['data']['tabImage'],
  763. 'type' => $array['data']['tabType']
  764. ];
  765. $connect->query('INSERT INTO [tabs]', $newTab);
  766. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  767. return true;
  768. } catch (Dibi\Exception $e) {
  769. return false;
  770. }
  771. break;
  772. default:
  773. return false;
  774. break;
  775. }
  776. }
  777. function editCategories($array)
  778. {
  779. switch ($array['data']['action']) {
  780. case 'changeDefault':
  781. try {
  782. $connect = new Dibi\Connection([
  783. 'driver' => 'sqlite3',
  784. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  785. ]);
  786. $connect->query('UPDATE categories SET `default` = 0');
  787. $connect->query('
  788. UPDATE categories SET', [
  789. 'default' => 1
  790. ], '
  791. WHERE id=?', $array['data']['id']);
  792. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  793. return true;
  794. } catch (Dibi\Exception $e) {
  795. return false;
  796. }
  797. break;
  798. case 'deleteCategory':
  799. try {
  800. $connect = new Dibi\Connection([
  801. 'driver' => 'sqlite3',
  802. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  803. ]);
  804. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  805. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  806. return true;
  807. } catch (Dibi\Exception $e) {
  808. return false;
  809. }
  810. break;
  811. case 'addNewCategory':
  812. try {
  813. $connect = new Dibi\Connection([
  814. 'driver' => 'sqlite3',
  815. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  816. ]);
  817. $newCategory = [
  818. 'category' => $array['data']['categoryName'],
  819. 'order' => $array['data']['categoryOrder'],
  820. 'category_id' => $array['data']['categoryID'],
  821. 'default' => false,
  822. 'image' => $array['data']['categoryImage'],
  823. ];
  824. $connect->query('INSERT INTO [categories]', $newCategory);
  825. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  826. return true;
  827. } catch (Dibi\Exception $e) {
  828. return $e;
  829. }
  830. break;
  831. case 'editCategory':
  832. try {
  833. $connect = new Dibi\Connection([
  834. 'driver' => 'sqlite3',
  835. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  836. ]);
  837. $connect->query('
  838. UPDATE categories SET', [
  839. 'category' => $array['data']['name'],
  840. 'image' => $array['data']['image'],
  841. ], '
  842. WHERE id=?', $array['data']['id']);
  843. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  844. return true;
  845. } catch (Dibi\Exception $e) {
  846. return false;
  847. }
  848. break;
  849. case 'changeOrder':
  850. try {
  851. $connect = new Dibi\Connection([
  852. 'driver' => 'sqlite3',
  853. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  854. ]);
  855. foreach ($array['data']['categories']['category'] as $key => $value) {
  856. if ($value['order'] != $value['originalOrder']) {
  857. $connect->query('
  858. UPDATE categories SET', [
  859. 'order' => $value['order'],
  860. ], '
  861. WHERE id=?', $value['id']);
  862. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  863. }
  864. }
  865. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  866. return true;
  867. } catch (Dibi\Exception $e) {
  868. return false;
  869. }
  870. break;
  871. default:
  872. return false;
  873. break;
  874. }
  875. }
  876. function allUsers()
  877. {
  878. try {
  879. $connect = new Dibi\Connection([
  880. 'driver' => 'sqlite3',
  881. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  882. ]);
  883. $users = $connect->fetchAll('SELECT * FROM users');
  884. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  885. foreach ($users as $k => $v) {
  886. // clear password from array
  887. unset($users[$k]['password']);
  888. }
  889. $all['users'] = $users;
  890. $all['groups'] = $groups;
  891. return $all;
  892. } catch (Dibi\Exception $e) {
  893. return false;
  894. }
  895. }
  896. function usernameTaken($username, $email)
  897. {
  898. try {
  899. $connect = new Dibi\Connection([
  900. 'driver' => 'sqlite3',
  901. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  902. ]);
  903. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  904. return ($all) ? true : false;
  905. } catch (Dibi\Exception $e) {
  906. return false;
  907. }
  908. }
  909. function usernameTakenExcept($username, $email, $id)
  910. {
  911. try {
  912. $connect = new Dibi\Connection([
  913. 'driver' => 'sqlite3',
  914. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  915. ]);
  916. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  917. return ($all) ? true : false;
  918. } catch (Dibi\Exception $e) {
  919. return false;
  920. }
  921. }
  922. function createUser($username, $password, $defaults, $email = null)
  923. {
  924. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  925. try {
  926. if (!usernameTaken($username, $email)) {
  927. $createDB = new Dibi\Connection([
  928. 'driver' => 'sqlite3',
  929. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  930. ]);
  931. $userInfo = [
  932. 'username' => $username,
  933. 'password' => password_hash($password, PASSWORD_BCRYPT),
  934. 'email' => $email,
  935. 'group' => $defaults['group'],
  936. 'group_id' => $defaults['group_id'],
  937. 'image' => gravatar($email),
  938. 'register_date' => $GLOBALS['currentTime'],
  939. ];
  940. $createDB->query('INSERT INTO [users]', $userInfo);
  941. return true;
  942. } else {
  943. return false;
  944. }
  945. } catch (Dibi\Exception $e) {
  946. return false;
  947. }
  948. }
  949. function allTabs()
  950. {
  951. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  952. try {
  953. $connect = new Dibi\Connection([
  954. 'driver' => 'sqlite3',
  955. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  956. ]);
  957. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  958. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  959. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  960. return $all;
  961. } catch (Dibi\Exception $e) {
  962. return false;
  963. }
  964. }
  965. return false;
  966. }
  967. function allGroups()
  968. {
  969. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  970. try {
  971. $connect = new Dibi\Connection([
  972. 'driver' => 'sqlite3',
  973. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  974. ]);
  975. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  976. return $all;
  977. } catch (Dibi\Exception $e) {
  978. return false;
  979. }
  980. }
  981. return false;
  982. }
  983. function loadTabs()
  984. {
  985. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  986. try {
  987. $connect = new Dibi\Connection([
  988. 'driver' => 'sqlite3',
  989. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  990. ]);
  991. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  992. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  993. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  994. $all['tabs'] = $tabs;
  995. foreach ($tabs as $k => $v) {
  996. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  997. }
  998. $count = array_map(function ($element) {
  999. return $element['category_id'];
  1000. }, $tabs);
  1001. $count = (array_count_values($count));
  1002. foreach ($categories as $k => $v) {
  1003. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1004. }
  1005. $all['categories'] = $categories;
  1006. return $all;
  1007. } catch (Dibi\Exception $e) {
  1008. return false;
  1009. }
  1010. }
  1011. return false;
  1012. }