api-functions.php 35 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = $oAuth = $oAuthType = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? $GLOBALS['rememberMeDays'] : 1;
  25. $oAuth = (isset($oAuth)) ? $oAuth : false;
  26. try {
  27. $database = new Dibi\Connection([
  28. 'driver' => 'sqlite3',
  29. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  30. ]);
  31. $authSuccess = false;
  32. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  33. if (!$oAuth) {
  34. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  35. switch ($GLOBALS['authType']) {
  36. case 'external':
  37. if (function_exists($function)) {
  38. $authSuccess = $function($username, $password);
  39. }
  40. break;
  41. /** @noinspection PhpMissingBreakStatementInspection */
  42. case 'both':
  43. if (function_exists($function)) {
  44. $authSuccess = $function($username, $password);
  45. }
  46. // no break
  47. default: // Internal
  48. if (!$authSuccess) {
  49. // perform the internal authentication step
  50. if (password_verify($password, $result['password'])) {
  51. $authSuccess = true;
  52. }
  53. }
  54. }
  55. } else {
  56. // Has oAuth Token!
  57. switch ($oAuthType) {
  58. case 'plex':
  59. if ($GLOBALS['plexoAuth']) {
  60. $tokenInfo = checkPlexToken($oAuth);
  61. if ($tokenInfo) {
  62. $authSuccess = array(
  63. 'username' => $tokenInfo['user']['username'],
  64. 'email' => $tokenInfo['user']['email'],
  65. 'image' => $tokenInfo['user']['thumb'],
  66. 'token' => $tokenInfo['user']['authToken']
  67. );
  68. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  69. }
  70. }
  71. break;
  72. default:
  73. return 'error';
  74. break;
  75. }
  76. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  77. }
  78. if ($authSuccess) {
  79. // Make sure user exists in database
  80. $userExists = false;
  81. $passwordMatches = ($oAuth) ? true : false;
  82. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  83. if ($result['username']) {
  84. $userExists = true;
  85. $username = $result['username'];
  86. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  87. }
  88. if ($userExists) {
  89. //does org password need to be updated
  90. if (!$passwordMatches) {
  91. $database->query('
  92. UPDATE users SET', [
  93. 'password' => password_hash($password, PASSWORD_BCRYPT)
  94. ], '
  95. WHERE id=?', $result['id']);
  96. writeLog('success', 'Login Function - User Password updated from backend', $username);
  97. }
  98. if ($token !== '') {
  99. if ($token !== $result['plex_token']) {
  100. $database->query('
  101. UPDATE users SET', [
  102. 'plex_token' => $token
  103. ], '
  104. WHERE id=?', $result['id']);
  105. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  106. }
  107. }
  108. // 2FA might go here
  109. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  110. $TFA = explode('::', $result['auth_service']);
  111. // Is code with login info?
  112. if ($tfaCode == '') {
  113. return '2FA';
  114. } else {
  115. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  116. return '2FA-incorrect';
  117. }
  118. }
  119. }
  120. // End 2FA
  121. // authentication passed - 1) mark active and update token
  122. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  123. writeLoginLog($username, 'success');
  124. writeLog('success', 'Login Function - A User has logged in', $username);
  125. ssoCheck($username, $password, $token); //need to work on this
  126. return true;
  127. } else {
  128. return 'error';
  129. }
  130. } else {
  131. // Create User
  132. //ssoCheck($username, $password, $token);
  133. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  134. }
  135. } else {
  136. // authentication failed
  137. writeLoginLog($username, 'error');
  138. writeLog('error', 'Login Function - Wrong Password', $username);
  139. return 'mismatch';
  140. }
  141. } catch (Dibi\Exception $e) {
  142. return $e;
  143. }
  144. }
  145. function createDB($path, $filename)
  146. {
  147. try {
  148. if (!file_exists($path)) {
  149. mkdir($path, 0777, true);
  150. }
  151. $createDB = new Dibi\Connection([
  152. 'driver' => 'sqlite3',
  153. 'database' => $path . $filename,
  154. ]);
  155. // Create Users
  156. $createDB->query('CREATE TABLE `users` (
  157. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  158. `username` TEXT UNIQUE,
  159. `password` TEXT,
  160. `email` TEXT,
  161. `plex_token` TEXT,
  162. `group` TEXT,
  163. `group_id` INTEGER,
  164. `locked` INTEGER,
  165. `image` TEXT,
  166. `register_date` DATE,
  167. `auth_service` TEXT DEFAULT \'internal\'
  168. );');
  169. // Create Tokens
  170. $createDB->query('CREATE TABLE `chatroom` (
  171. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  172. `username` TEXT,
  173. `gravatar` TEXT,
  174. `uid` TEXT,
  175. `date` DATE,
  176. `ip` TEXT,
  177. `message` TEXT
  178. );');
  179. $createDB->query('CREATE TABLE `tokens` (
  180. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  181. `token` TEXT UNIQUE,
  182. `user_id` INTEGER,
  183. `browser` TEXT,
  184. `ip` TEXT,
  185. `created` DATE,
  186. `expires` DATE
  187. );');
  188. $createDB->query('CREATE TABLE `groups` (
  189. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  190. `group` TEXT UNIQUE,
  191. `group_id` INTEGER,
  192. `image` TEXT,
  193. `default` INTEGER
  194. );');
  195. $createDB->query('CREATE TABLE `categories` (
  196. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  197. `order` INTEGER,
  198. `category` TEXT UNIQUE,
  199. `category_id` INTEGER,
  200. `image` TEXT,
  201. `default` INTEGER
  202. );');
  203. // Create Tabs
  204. $createDB->query('CREATE TABLE `tabs` (
  205. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  206. `order` INTEGER,
  207. `category_id` INTEGER,
  208. `name` TEXT,
  209. `url` TEXT,
  210. `url_local` TEXT,
  211. `default` INTEGER,
  212. `enabled` INTEGER,
  213. `group_id` INTEGER,
  214. `image` TEXT,
  215. `type` INTEGER,
  216. `splash` INTEGER,
  217. `ping` INTEGER,
  218. `ping_url` TEXT,
  219. `timeout` INTEGER,
  220. `timeout_ms` INTEGER
  221. );');
  222. // Create Options
  223. $createDB->query('CREATE TABLE `options` (
  224. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  225. `name` TEXT UNIQUE,
  226. `value` TEXT
  227. );');
  228. // Create Invites
  229. $createDB->query('CREATE TABLE `invites` (
  230. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  231. `code` TEXT UNIQUE,
  232. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  233. `email` TEXT,
  234. `username` TEXT,
  235. `dateused` TIMESTAMP,
  236. `usedby` TEXT,
  237. `ip` TEXT,
  238. `valid` TEXT,
  239. `type` TEXT
  240. );');
  241. return true;
  242. } catch (Dibi\Exception $e) {
  243. return false;
  244. }
  245. }
  246. // Upgrade Database
  247. function updateDB($oldVerNum = false)
  248. {
  249. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  250. if (!file_exists($tempLock)) {
  251. touch($tempLock);
  252. // Create Temp DB First
  253. $migrationDB = 'tempMigration.db';
  254. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  255. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  256. unlink($GLOBALS['dbLocation'] . $migrationDB);
  257. }
  258. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  259. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  260. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  261. if ($success) {
  262. try {
  263. $connectOldDB = new Dibi\Connection([
  264. 'driver' => 'sqlite3',
  265. 'database' => $backupDB,
  266. ]);
  267. $connectNewDB = new Dibi\Connection([
  268. 'driver' => 'sqlite3',
  269. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  270. ]);
  271. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  272. foreach ($tables as $table) {
  273. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  274. foreach ($data as $row) {
  275. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  276. }
  277. }
  278. $connectOldDB->disconnect();
  279. $connectNewDB->disconnect();
  280. // Remove Current Database
  281. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  282. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  283. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  284. if ($newFileSize >= $oldFileSize) {
  285. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  286. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  287. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  288. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  289. unlink($tempLock);
  290. return true;
  291. }
  292. }
  293. unlink($tempLock);
  294. return false;
  295. } catch (Dibi\Exception $e) {
  296. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  297. unlink($tempLock);
  298. return false;
  299. }
  300. }
  301. unlink($tempLock);
  302. return false;
  303. }
  304. return false;
  305. }
  306. function createFirstAdmin($path, $filename, $username, $password, $email)
  307. {
  308. try {
  309. $createDB = new Dibi\Connection([
  310. 'driver' => 'sqlite3',
  311. 'database' => $path . $filename,
  312. ]);
  313. $userInfo = [
  314. 'username' => $username,
  315. 'password' => password_hash($password, PASSWORD_BCRYPT),
  316. 'email' => $email,
  317. 'group' => 'Admin',
  318. 'group_id' => 0,
  319. 'image' => gravatar($email),
  320. 'register_date' => $GLOBALS['currentTime'],
  321. ];
  322. $groupInfo0 = [
  323. 'group' => 'Admin',
  324. 'group_id' => 0,
  325. 'default' => false,
  326. 'image' => 'plugins/images/groups/admin.png',
  327. ];
  328. $groupInfo1 = [
  329. 'group' => 'Co-Admin',
  330. 'group_id' => 1,
  331. 'default' => false,
  332. 'image' => 'plugins/images/groups/coadmin.png',
  333. ];
  334. $groupInfo2 = [
  335. 'group' => 'Super User',
  336. 'group_id' => 2,
  337. 'default' => false,
  338. 'image' => 'plugins/images/groups/superuser.png',
  339. ];
  340. $groupInfo3 = [
  341. 'group' => 'Power User',
  342. 'group_id' => 3,
  343. 'default' => false,
  344. 'image' => 'plugins/images/groups/poweruser.png',
  345. ];
  346. $groupInfo4 = [
  347. 'group' => 'User',
  348. 'group_id' => 4,
  349. 'default' => true,
  350. 'image' => 'plugins/images/groups/user.png',
  351. ];
  352. $groupInfoGuest = [
  353. 'group' => 'Guest',
  354. 'group_id' => 999,
  355. 'default' => false,
  356. 'image' => 'plugins/images/groups/guest.png',
  357. ];
  358. $settingsInfo = [
  359. 'order' => 1,
  360. 'category_id' => 0,
  361. 'name' => 'Settings',
  362. 'url' => 'api/?v1/settings/page',
  363. 'default' => false,
  364. 'enabled' => true,
  365. 'group_id' => 1,
  366. 'image' => 'fontawesome::cog',
  367. 'type' => 0
  368. ];
  369. $homepageInfo = [
  370. 'order' => 2,
  371. 'category_id' => 0,
  372. 'name' => 'Homepage',
  373. 'url' => 'api/?v1/homepage/page',
  374. 'default' => false,
  375. 'enabled' => false,
  376. 'group_id' => 4,
  377. 'image' => 'fontawesome::home',
  378. 'type' => 0
  379. ];
  380. $unsortedInfo = [
  381. 'order' => 1,
  382. 'category' => 'Unsorted',
  383. 'category_id' => 0,
  384. 'image' => 'plugins/images/categories/unsorted.png',
  385. 'default' => true
  386. ];
  387. $createDB->query('INSERT INTO [users]', $userInfo);
  388. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  389. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  390. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  391. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  392. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  393. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  394. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  395. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  396. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  397. return true;
  398. } catch (Dibi\Exception $e) {
  399. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  400. return false;
  401. }
  402. }
  403. function defaultUserGroup()
  404. {
  405. try {
  406. $connect = new Dibi\Connection([
  407. 'driver' => 'sqlite3',
  408. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  409. ]);
  410. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  411. return $all;
  412. } catch (Dibi\Exception $e) {
  413. return false;
  414. }
  415. }
  416. function defaultTabCategory()
  417. {
  418. try {
  419. $connect = new Dibi\Connection([
  420. 'driver' => 'sqlite3',
  421. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  422. ]);
  423. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  424. return $all;
  425. } catch (Dibi\Exception $e) {
  426. return false;
  427. }
  428. }
  429. function getGuest()
  430. {
  431. if (isset($GLOBALS['dbLocation'])) {
  432. try {
  433. $connect = new Dibi\Connection([
  434. 'driver' => 'sqlite3',
  435. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  436. ]);
  437. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  438. return $all;
  439. } catch (Dibi\Exception $e) {
  440. return false;
  441. }
  442. } else {
  443. return array(
  444. 'group' => 'Guest',
  445. 'group_id' => 999,
  446. 'image' => 'plugins/images/groups/guest.png'
  447. );
  448. }
  449. }
  450. function adminEditGroup($array)
  451. {
  452. switch ($array['data']['action']) {
  453. case 'changeDefaultGroup':
  454. try {
  455. $connect = new Dibi\Connection([
  456. 'driver' => 'sqlite3',
  457. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  458. ]);
  459. $connect->query('UPDATE groups SET `default` = 0');
  460. $connect->query('
  461. UPDATE groups SET', [
  462. 'default' => 1
  463. ], '
  464. WHERE id=?', $array['data']['id']);
  465. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  466. return true;
  467. } catch (Dibi\Exception $e) {
  468. return false;
  469. }
  470. break;
  471. case 'deleteUserGroup':
  472. try {
  473. $connect = new Dibi\Connection([
  474. 'driver' => 'sqlite3',
  475. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  476. ]);
  477. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  478. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  479. return true;
  480. } catch (Dibi\Exception $e) {
  481. return false;
  482. }
  483. break;
  484. case 'addUserGroup':
  485. try {
  486. $connect = new Dibi\Connection([
  487. 'driver' => 'sqlite3',
  488. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  489. ]);
  490. $newGroup = [
  491. 'group' => $array['data']['newGroupName'],
  492. 'group_id' => $array['data']['newGroupID'],
  493. 'default' => false,
  494. 'image' => $array['data']['newGroupImage'],
  495. ];
  496. $connect->query('INSERT INTO [groups]', $newGroup);
  497. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  498. return true;
  499. } catch (Dibi\Exception $e) {
  500. return false;
  501. }
  502. break;
  503. case 'editUserGroup':
  504. try {
  505. $connect = new Dibi\Connection([
  506. 'driver' => 'sqlite3',
  507. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  508. ]);
  509. $connect->query('
  510. UPDATE groups SET', [
  511. 'group' => $array['data']['groupName'],
  512. 'image' => $array['data']['groupImage'],
  513. ], '
  514. WHERE id=?', $array['data']['id']);
  515. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  516. return true;
  517. } catch (Dibi\Exception $e) {
  518. return false;
  519. }
  520. break;
  521. default:
  522. return false;
  523. break;
  524. }
  525. }
  526. function adminEditUser($array)
  527. {
  528. switch ($array['data']['action']) {
  529. case 'changeGroup':
  530. try {
  531. $connect = new Dibi\Connection([
  532. 'driver' => 'sqlite3',
  533. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  534. ]);
  535. $connect->query('
  536. UPDATE users SET', [
  537. 'group' => $array['data']['newGroupName'],
  538. 'group_id' => $array['data']['newGroupID'],
  539. ], '
  540. WHERE id=?', $array['data']['id']);
  541. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  542. return true;
  543. } catch (Dibi\Exception $e) {
  544. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  545. return false;
  546. }
  547. break;
  548. case 'editUser':
  549. try {
  550. $connect = new Dibi\Connection([
  551. 'driver' => 'sqlite3',
  552. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  553. ]);
  554. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  555. $connect->query('
  556. UPDATE users SET', [
  557. 'username' => $array['data']['username'],
  558. 'email' => $array['data']['email'],
  559. 'image' => gravatar($array['data']['email']),
  560. ], '
  561. WHERE id=?', $array['data']['id']);
  562. if (!empty($array['data']['password'])) {
  563. $connect->query('
  564. UPDATE users SET', [
  565. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  566. ], '
  567. WHERE id=?', $array['data']['id']);
  568. }
  569. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  570. return true;
  571. } else {
  572. return false;
  573. }
  574. } catch (Dibi\Exception $e) {
  575. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  576. return false;
  577. }
  578. break;
  579. case 'addNewUser':
  580. $defaults = defaultUserGroup();
  581. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  582. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  583. return true;
  584. } else {
  585. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  586. return 'username taken';
  587. }
  588. break;
  589. case 'deleteUser':
  590. try {
  591. $connect = new Dibi\Connection([
  592. 'driver' => 'sqlite3',
  593. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  594. ]);
  595. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  596. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  597. return true;
  598. } catch (Dibi\Exception $e) {
  599. return false;
  600. }
  601. break;
  602. default:
  603. return false;
  604. break;
  605. }
  606. }
  607. function editTabs($array)
  608. {
  609. switch ($array['data']['action']) {
  610. case 'changeGroup':
  611. try {
  612. $connect = new Dibi\Connection([
  613. 'driver' => 'sqlite3',
  614. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  615. ]);
  616. $connect->query('
  617. UPDATE tabs SET', [
  618. 'group_id' => $array['data']['newGroupID'],
  619. ], '
  620. WHERE id=?', $array['data']['id']);
  621. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  622. return true;
  623. } catch (Dibi\Exception $e) {
  624. return false;
  625. }
  626. break;
  627. case 'changeCategory':
  628. try {
  629. $connect = new Dibi\Connection([
  630. 'driver' => 'sqlite3',
  631. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  632. ]);
  633. $connect->query('
  634. UPDATE tabs SET', [
  635. 'category_id' => $array['data']['newCategoryID'],
  636. ], '
  637. WHERE id=?', $array['data']['id']);
  638. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  639. return true;
  640. } catch (Dibi\Exception $e) {
  641. return false;
  642. }
  643. break;
  644. case 'changeType':
  645. try {
  646. $connect = new Dibi\Connection([
  647. 'driver' => 'sqlite3',
  648. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  649. ]);
  650. $connect->query('
  651. UPDATE tabs SET', [
  652. 'type' => $array['data']['newTypeID'],
  653. ], '
  654. WHERE id=?', $array['data']['id']);
  655. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  656. return true;
  657. } catch (Dibi\Exception $e) {
  658. return false;
  659. }
  660. break;
  661. case 'changeEnabled':
  662. try {
  663. $connect = new Dibi\Connection([
  664. 'driver' => 'sqlite3',
  665. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  666. ]);
  667. $connect->query('
  668. UPDATE tabs SET', [
  669. 'enabled' => $array['data']['tabEnabled'],
  670. ], '
  671. WHERE id=?', $array['data']['id']);
  672. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  673. return true;
  674. } catch (Dibi\Exception $e) {
  675. return false;
  676. }
  677. break;
  678. case 'changeSplash':
  679. try {
  680. $connect = new Dibi\Connection([
  681. 'driver' => 'sqlite3',
  682. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  683. ]);
  684. $connect->query('
  685. UPDATE tabs SET', [
  686. 'splash' => $array['data']['tabSplash'],
  687. ], '
  688. WHERE id=?', $array['data']['id']);
  689. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  690. return true;
  691. } catch (Dibi\Exception $e) {
  692. return false;
  693. }
  694. break;
  695. case 'changePing':
  696. try {
  697. $connect = new Dibi\Connection([
  698. 'driver' => 'sqlite3',
  699. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  700. ]);
  701. $connect->query('
  702. UPDATE tabs SET', [
  703. 'ping' => $array['data']['tabPing'],
  704. ], '
  705. WHERE id=?', $array['data']['id']);
  706. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  707. return true;
  708. } catch (Dibi\Exception $e) {
  709. return false;
  710. }
  711. break;
  712. case 'changeDefault':
  713. try {
  714. $connect = new Dibi\Connection([
  715. 'driver' => 'sqlite3',
  716. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  717. ]);
  718. $connect->query('UPDATE tabs SET `default` = 0');
  719. $connect->query('
  720. UPDATE tabs SET', [
  721. 'default' => 1
  722. ], '
  723. WHERE id=?', $array['data']['id']);
  724. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  725. return true;
  726. } catch (Dibi\Exception $e) {
  727. return false;
  728. }
  729. break;
  730. case 'deleteTab':
  731. try {
  732. $connect = new Dibi\Connection([
  733. 'driver' => 'sqlite3',
  734. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  735. ]);
  736. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  737. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  738. return true;
  739. } catch (Dibi\Exception $e) {
  740. return false;
  741. }
  742. break;
  743. case 'editTab':
  744. try {
  745. $connect = new Dibi\Connection([
  746. 'driver' => 'sqlite3',
  747. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  748. ]);
  749. $connect->query('
  750. UPDATE tabs SET', [
  751. 'name' => $array['data']['tabName'],
  752. 'url' => $array['data']['tabURL'],
  753. 'ping_url' => $array['data']['pingURL'],
  754. 'image' => $array['data']['tabImage'],
  755. ], '
  756. WHERE id=?', $array['data']['id']);
  757. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  758. return true;
  759. } catch (Dibi\Exception $e) {
  760. return false;
  761. }
  762. case 'changeOrder':
  763. try {
  764. $connect = new Dibi\Connection([
  765. 'driver' => 'sqlite3',
  766. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  767. ]);
  768. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  769. if ($value['order'] != $value['originalOrder']) {
  770. $connect->query('
  771. UPDATE tabs SET', [
  772. 'order' => $value['order'],
  773. ], '
  774. WHERE id=?', $value['id']);
  775. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  776. }
  777. }
  778. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  779. return true;
  780. } catch (Dibi\Exception $e) {
  781. return false;
  782. }
  783. break;
  784. case 'addNewTab':
  785. try {
  786. $default = defaultTabCategory()['category_id'];
  787. $connect = new Dibi\Connection([
  788. 'driver' => 'sqlite3',
  789. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  790. ]);
  791. $newTab = [
  792. 'order' => $array['data']['tabOrder'],
  793. 'category_id' => $default,
  794. 'name' => $array['data']['tabName'],
  795. 'url' => $array['data']['tabURL'],
  796. 'ping_url' => $array['data']['pingURL'],
  797. 'default' => $array['data']['tabDefault'],
  798. 'enabled' => 1,
  799. 'group_id' => $array['data']['tabGroupID'],
  800. 'image' => $array['data']['tabImage'],
  801. 'type' => $array['data']['tabType']
  802. ];
  803. $connect->query('INSERT INTO [tabs]', $newTab);
  804. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  805. return true;
  806. } catch (Dibi\Exception $e) {
  807. return false;
  808. }
  809. break;
  810. default:
  811. return false;
  812. break;
  813. }
  814. }
  815. function editCategories($array)
  816. {
  817. switch ($array['data']['action']) {
  818. case 'changeDefault':
  819. try {
  820. $connect = new Dibi\Connection([
  821. 'driver' => 'sqlite3',
  822. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  823. ]);
  824. $connect->query('UPDATE categories SET `default` = 0');
  825. $connect->query('
  826. UPDATE categories SET', [
  827. 'default' => 1
  828. ], '
  829. WHERE id=?', $array['data']['id']);
  830. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  831. return true;
  832. } catch (Dibi\Exception $e) {
  833. return false;
  834. }
  835. break;
  836. case 'deleteCategory':
  837. try {
  838. $connect = new Dibi\Connection([
  839. 'driver' => 'sqlite3',
  840. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  841. ]);
  842. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  843. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  844. return true;
  845. } catch (Dibi\Exception $e) {
  846. return false;
  847. }
  848. break;
  849. case 'addNewCategory':
  850. try {
  851. $connect = new Dibi\Connection([
  852. 'driver' => 'sqlite3',
  853. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  854. ]);
  855. $newCategory = [
  856. 'category' => $array['data']['categoryName'],
  857. 'order' => $array['data']['categoryOrder'],
  858. 'category_id' => $array['data']['categoryID'],
  859. 'default' => false,
  860. 'image' => $array['data']['categoryImage'],
  861. ];
  862. $connect->query('INSERT INTO [categories]', $newCategory);
  863. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  864. return true;
  865. } catch (Dibi\Exception $e) {
  866. return $e;
  867. }
  868. break;
  869. case 'editCategory':
  870. try {
  871. $connect = new Dibi\Connection([
  872. 'driver' => 'sqlite3',
  873. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  874. ]);
  875. $connect->query('
  876. UPDATE categories SET', [
  877. 'category' => $array['data']['name'],
  878. 'image' => $array['data']['image'],
  879. ], '
  880. WHERE id=?', $array['data']['id']);
  881. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  882. return true;
  883. } catch (Dibi\Exception $e) {
  884. return false;
  885. }
  886. break;
  887. case 'changeOrder':
  888. try {
  889. $connect = new Dibi\Connection([
  890. 'driver' => 'sqlite3',
  891. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  892. ]);
  893. foreach ($array['data']['categories']['category'] as $key => $value) {
  894. if ($value['order'] != $value['originalOrder']) {
  895. $connect->query('
  896. UPDATE categories SET', [
  897. 'order' => $value['order'],
  898. ], '
  899. WHERE id=?', $value['id']);
  900. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  901. }
  902. }
  903. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  904. return true;
  905. } catch (Dibi\Exception $e) {
  906. return false;
  907. }
  908. break;
  909. default:
  910. return false;
  911. break;
  912. }
  913. }
  914. function allUsers()
  915. {
  916. try {
  917. $connect = new Dibi\Connection([
  918. 'driver' => 'sqlite3',
  919. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  920. ]);
  921. $users = $connect->fetchAll('SELECT * FROM users');
  922. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  923. foreach ($users as $k => $v) {
  924. // clear password from array
  925. unset($users[$k]['password']);
  926. }
  927. $all['users'] = $users;
  928. $all['groups'] = $groups;
  929. return $all;
  930. } catch (Dibi\Exception $e) {
  931. return false;
  932. }
  933. }
  934. function usernameTaken($username, $email)
  935. {
  936. try {
  937. $connect = new Dibi\Connection([
  938. 'driver' => 'sqlite3',
  939. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  940. ]);
  941. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  942. return ($all) ? true : false;
  943. } catch (Dibi\Exception $e) {
  944. return false;
  945. }
  946. }
  947. function usernameTakenExcept($username, $email, $id)
  948. {
  949. try {
  950. $connect = new Dibi\Connection([
  951. 'driver' => 'sqlite3',
  952. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  953. ]);
  954. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  955. return ($all) ? true : false;
  956. } catch (Dibi\Exception $e) {
  957. return false;
  958. }
  959. }
  960. function createUser($username, $password, $defaults, $email = null)
  961. {
  962. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  963. try {
  964. if (!usernameTaken($username, $email)) {
  965. $createDB = new Dibi\Connection([
  966. 'driver' => 'sqlite3',
  967. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  968. ]);
  969. $userInfo = [
  970. 'username' => $username,
  971. 'password' => password_hash($password, PASSWORD_BCRYPT),
  972. 'email' => $email,
  973. 'group' => $defaults['group'],
  974. 'group_id' => $defaults['group_id'],
  975. 'image' => gravatar($email),
  976. 'register_date' => $GLOBALS['currentTime'],
  977. ];
  978. $createDB->query('INSERT INTO [users]', $userInfo);
  979. return true;
  980. } else {
  981. return false;
  982. }
  983. } catch (Dibi\Exception $e) {
  984. return false;
  985. }
  986. }
  987. function importUsers($array)
  988. {
  989. $imported = 0;
  990. $defaults = defaultUserGroup();
  991. foreach ($array as $user) {
  992. $password = random_ascii_string(30);
  993. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  994. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  995. if (!$newUser) {
  996. writeLog('error', 'Import Function - Error', $user['username']);
  997. } else {
  998. $imported++;
  999. }
  1000. }
  1001. }
  1002. return $imported;
  1003. }
  1004. function importUsersType($array)
  1005. {
  1006. $type = $array['data']['type'];
  1007. if ($type !== '') {
  1008. switch ($type) {
  1009. case 'plex':
  1010. return importUsers(allPlexUsers(true));
  1011. break;
  1012. default:
  1013. return false;
  1014. }
  1015. }
  1016. return false;
  1017. }
  1018. function allTabs()
  1019. {
  1020. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1021. try {
  1022. $connect = new Dibi\Connection([
  1023. 'driver' => 'sqlite3',
  1024. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1025. ]);
  1026. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1027. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1028. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1029. return $all;
  1030. } catch (Dibi\Exception $e) {
  1031. return false;
  1032. }
  1033. }
  1034. return false;
  1035. }
  1036. function allGroups()
  1037. {
  1038. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1039. try {
  1040. $connect = new Dibi\Connection([
  1041. 'driver' => 'sqlite3',
  1042. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1043. ]);
  1044. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1045. return $all;
  1046. } catch (Dibi\Exception $e) {
  1047. return false;
  1048. }
  1049. }
  1050. return false;
  1051. }
  1052. function loadTabs()
  1053. {
  1054. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1055. try {
  1056. $connect = new Dibi\Connection([
  1057. 'driver' => 'sqlite3',
  1058. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1059. ]);
  1060. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1061. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1062. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1063. $all['tabs'] = $tabs;
  1064. foreach ($tabs as $k => $v) {
  1065. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  1066. }
  1067. $count = array_map(function ($element) {
  1068. return $element['category_id'];
  1069. }, $tabs);
  1070. $count = (array_count_values($count));
  1071. foreach ($categories as $k => $v) {
  1072. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1073. }
  1074. $all['categories'] = $categories;
  1075. return $all;
  1076. } catch (Dibi\Exception $e) {
  1077. return false;
  1078. }
  1079. }
  1080. return false;
  1081. }
  1082. function getActiveTokens()
  1083. {
  1084. try {
  1085. $connect = new Dibi\Connection([
  1086. 'driver' => 'sqlite3',
  1087. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1088. ]);
  1089. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1090. return $all;
  1091. } catch (Dibi\Exception $e) {
  1092. return false;
  1093. }
  1094. }
  1095. function revokeToken($array)
  1096. {
  1097. if ($array['data']['token']) {
  1098. try {
  1099. $connect = new Dibi\Connection([
  1100. 'driver' => 'sqlite3',
  1101. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1102. ]);
  1103. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1104. return true;
  1105. } catch (Dibi\Exception $e) {
  1106. return false;
  1107. }
  1108. }
  1109. }