index.php 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488
  1. <?php
  2. $generationTime = -microtime(true);
  3. //include functions
  4. require_once 'functions.php';
  5. //Set result array
  6. $result = array();
  7. //Get request method
  8. $method = $_SERVER['REQUEST_METHOD'];
  9. reset($_GET);
  10. $function = (key($_GET) ? str_replace("/","_",key($_GET)) : false);
  11. //Exit if $function is blank
  12. if($function === false){
  13. $result['status'] = "error";
  14. $result['statusText'] = "No API Path Supplied";
  15. exit(json_encode($result));
  16. }
  17. $result['request'] = key($_GET);
  18. switch ($function) {
  19. case 'v1_settings_page':
  20. switch ($method) {
  21. case 'GET':
  22. if(qualifyRequest(1)){
  23. $result['status'] = 'success';
  24. $result['statusText'] = 'success';
  25. $result['data'] = $pageSettings;
  26. writeLog('success', 'Admin Function - Accessed Settings Page', $GLOBALS['organizrUser']['username']);
  27. }else{
  28. $result['status'] = 'error';
  29. $result['statusText'] = 'API/Token invalid or not set';
  30. $result['data'] = null;
  31. writeLog('error', 'Admin Function - Tried to access Settings Page', $GLOBALS['organizrUser']['username']);
  32. }
  33. break;
  34. default:
  35. $result['status'] = 'error';
  36. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  37. break;
  38. }
  39. break;
  40. case 'v1_settings_settings_logs':
  41. switch ($method) {
  42. case 'GET':
  43. if(qualifyRequest(1)){
  44. $result['status'] = 'success';
  45. $result['statusText'] = 'success';
  46. $result['data'] = $pageSettingsSettingsLogs;
  47. }else{
  48. $result['status'] = 'error';
  49. $result['statusText'] = 'API/Token invalid or not set';
  50. $result['data'] = null;
  51. }
  52. break;
  53. default:
  54. $result['status'] = 'error';
  55. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  56. break;
  57. }
  58. break;
  59. case 'v1_settings_tab_editor_tabs':
  60. switch ($method) {
  61. case 'GET':
  62. if(qualifyRequest(1)){
  63. $result['status'] = 'success';
  64. $result['statusText'] = 'success';
  65. $result['data'] = $pageSettingsTabEditorTabs;
  66. }else{
  67. $result['status'] = 'error';
  68. $result['statusText'] = 'API/Token invalid or not set';
  69. $result['data'] = null;
  70. }
  71. break;
  72. case 'POST':
  73. if(qualifyRequest(1)){
  74. $result['status'] = 'success';
  75. $result['statusText'] = 'success';
  76. $result['data'] = editTabs($_POST);
  77. }else{
  78. $result['status'] = 'error';
  79. $result['statusText'] = 'API/Token invalid or not set';
  80. $result['data'] = null;
  81. }
  82. break;
  83. default:
  84. $result['status'] = 'error';
  85. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  86. break;
  87. }
  88. break;
  89. case 'v1_settings_tab_editor_categories':
  90. switch ($method) {
  91. case 'GET':
  92. if(qualifyRequest(1)){
  93. $result['status'] = 'success';
  94. $result['statusText'] = 'success';
  95. $result['data'] = $pageSettingsTabEditorCategories;
  96. }else{
  97. $result['status'] = 'error';
  98. $result['statusText'] = 'API/Token invalid or not set';
  99. $result['data'] = null;
  100. }
  101. break;
  102. case 'POST':
  103. if(qualifyRequest(1)){
  104. $result['status'] = 'success';
  105. $result['statusText'] = 'success';
  106. $result['data'] = editCategories($_POST);
  107. }else{
  108. $result['status'] = 'error';
  109. $result['statusText'] = 'API/Token invalid or not set';
  110. $result['data'] = null;
  111. }
  112. break;
  113. default:
  114. $result['status'] = 'error';
  115. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  116. break;
  117. }
  118. break;
  119. case 'v1_settings_user_manage_users':
  120. switch ($method) {
  121. case 'GET':
  122. if(qualifyRequest(1)){
  123. $result['status'] = 'success';
  124. $result['statusText'] = 'success';
  125. $result['data'] = $pageSettingsUserManageUsers;
  126. }else{
  127. $result['status'] = 'error';
  128. $result['statusText'] = 'API/Token invalid or not set';
  129. $result['data'] = null;
  130. }
  131. break;
  132. case 'POST':
  133. if(qualifyRequest(1)){
  134. $result['status'] = 'success';
  135. $result['statusText'] = 'success';
  136. $result['data'] = adminEditUser($_POST);
  137. }elseif(qualifyRequest(998)){
  138. $result['status'] = 'success';
  139. $result['statusText'] = 'success';
  140. $result['data'] = editUser($_POST);
  141. }else{
  142. $result['status'] = 'error';
  143. $result['statusText'] = 'API/Token invalid or not set';
  144. $result['data'] = null;
  145. }
  146. break;
  147. default:
  148. $result['status'] = 'error';
  149. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  150. break;
  151. }
  152. break;
  153. case 'v1_settings_user_manage_groups':
  154. switch ($method) {
  155. case 'GET':
  156. if(qualifyRequest(1)){
  157. $result['status'] = 'success';
  158. $result['statusText'] = 'success';
  159. $result['data'] = $pageSettingsUserManageGroups;
  160. }else{
  161. $result['status'] = 'error';
  162. $result['statusText'] = 'API/Token invalid or not set';
  163. $result['data'] = null;
  164. }
  165. break;
  166. case 'POST':
  167. if(qualifyRequest(1)){
  168. $result['status'] = 'success';
  169. $result['statusText'] = 'success';
  170. $result['data'] = adminEditGroup($_POST);
  171. }else{
  172. $result['status'] = 'error';
  173. $result['statusText'] = 'API/Token invalid or not set';
  174. $result['data'] = null;
  175. }
  176. break;
  177. default:
  178. $result['status'] = 'error';
  179. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  180. break;
  181. }
  182. break;
  183. case 'v1_wizard_page':
  184. switch ($method) {
  185. case 'GET':
  186. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  187. $result['status'] = 'success';
  188. $result['statusText'] = 'success';
  189. $result['data'] = $pageWizard;
  190. }else{
  191. $result['status'] = 'error';
  192. $result['statusText'] = 'Wizard has already been run';
  193. $result['data'] = null;
  194. }
  195. break;
  196. default:
  197. $result['status'] = 'error';
  198. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  199. break;
  200. }
  201. break;
  202. case 'v1_dependencies_page':
  203. switch ($method) {
  204. case 'GET':
  205. $result['status'] = 'success';
  206. $result['statusText'] = 'success';
  207. $result['data'] = $pageDependencies;
  208. break;
  209. default:
  210. $result['status'] = 'error';
  211. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  212. break;
  213. }
  214. break;
  215. case 'v1_wizard_config':
  216. switch ($method) {
  217. case 'POST':
  218. if(!file_exists('config'.DIRECTORY_SEPARATOR.'config.php')){
  219. $result['status'] = 'success';
  220. $result['statusText'] = 'success';
  221. $result['data'] = wizardConfig($_POST);
  222. }else{
  223. $result['status'] = 'error';
  224. $result['statusText'] = 'Wizard has already been run';
  225. $result['data'] = null;
  226. }
  227. break;
  228. default:
  229. $result['status'] = 'error';
  230. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  231. break;
  232. }
  233. break;
  234. case 'v1_login':
  235. switch ($method) {
  236. case 'POST':
  237. $result['status'] = 'success';
  238. $result['statusText'] = 'success';
  239. $result['data'] = login($_POST);
  240. break;
  241. default:
  242. $result['status'] = 'error';
  243. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  244. break;
  245. }
  246. break;
  247. case 'v1_register':
  248. switch ($method) {
  249. case 'POST':
  250. $result['status'] = 'success';
  251. $result['statusText'] = 'success';
  252. $result['data'] = register($_POST);
  253. break;
  254. default:
  255. $result['status'] = 'error';
  256. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  257. break;
  258. }
  259. break;
  260. case 'v1_login_page':
  261. switch ($method) {
  262. case 'GET':
  263. $result['status'] = 'success';
  264. $result['statusText'] = 'success';
  265. $result['data'] = $pageLogin;
  266. break;
  267. default:
  268. $result['status'] = 'error';
  269. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  270. break;
  271. }
  272. break;
  273. case 'v1_lockscreen':
  274. switch ($method) {
  275. case 'GET':
  276. $result['status'] = 'success';
  277. $result['statusText'] = 'success';
  278. $result['data'] = $pageLockScreen;
  279. break;
  280. default:
  281. $result['status'] = 'error';
  282. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  283. break;
  284. }
  285. break;
  286. case 'v1_login_log':
  287. switch ($method) {
  288. case 'GET':
  289. if(qualifyRequest(1)){
  290. $result['status'] = 'success';
  291. $result['statusText'] = 'success';
  292. $result['data'] = getLog('loginLog');
  293. }else{
  294. $result['status'] = 'error';
  295. $result['statusText'] = 'API/Token invalid or not set';
  296. $result['data'] = null;
  297. }
  298. break;
  299. default:
  300. $result['status'] = 'error';
  301. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  302. break;
  303. }
  304. break;
  305. case 'v1_organizr_log':
  306. switch ($method) {
  307. case 'GET':
  308. if(qualifyRequest(1)){
  309. $result['status'] = 'success';
  310. $result['statusText'] = 'success';
  311. $result['data'] = getLog('org');
  312. }else{
  313. $result['status'] = 'error';
  314. $result['statusText'] = 'API/Token invalid or not set';
  315. $result['data'] = null;
  316. }
  317. break;
  318. default:
  319. $result['status'] = 'error';
  320. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  321. break;
  322. }
  323. break;
  324. case 'v1_user_list':
  325. switch ($method) {
  326. case 'GET':
  327. if(qualifyRequest(1)){
  328. $result['status'] = 'success';
  329. $result['statusText'] = 'success';
  330. $result['data'] = allUsers();
  331. }else{
  332. $result['status'] = 'error';
  333. $result['statusText'] = 'API/Token invalid or not set';
  334. $result['data'] = null;
  335. }
  336. break;
  337. default:
  338. $result['status'] = 'error';
  339. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  340. break;
  341. }
  342. break;
  343. case 'v1_tab_list':
  344. switch ($method) {
  345. case 'GET':
  346. if(qualifyRequest(1)){
  347. $result['status'] = 'success';
  348. $result['statusText'] = 'success';
  349. $result['data'] = allTabs();
  350. }else{
  351. $result['status'] = 'error';
  352. $result['statusText'] = 'API/Token invalid or not set';
  353. $result['data'] = null;
  354. }
  355. break;
  356. default:
  357. $result['status'] = 'error';
  358. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  359. break;
  360. }
  361. break;
  362. case 'v1_user_edit':
  363. switch ($method) {
  364. case 'POST':
  365. if(qualifyRequest(1)){
  366. $result['status'] = 'success';
  367. $result['statusText'] = 'success';
  368. $result['data'] = adminEditUser($_POST);
  369. }elseif(qualifyRequest(998)){
  370. $result['status'] = 'success';
  371. $result['statusText'] = 'success';
  372. $result['data'] = editUser($_POST);
  373. }else{
  374. $result['status'] = 'error';
  375. $result['statusText'] = 'API/Token invalid or not set';
  376. $result['data'] = null;
  377. }
  378. break;
  379. default:
  380. $result['status'] = 'error';
  381. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  382. break;
  383. }
  384. break;
  385. case 'v1_logout':
  386. switch ($method) {
  387. case 'GET':
  388. $result['status'] = 'success';
  389. $result['statusText'] = 'success';
  390. $result['data'] = logout();
  391. break;
  392. default:
  393. $result['status'] = 'error';
  394. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  395. break;
  396. }
  397. break;
  398. case 'v1_launch_organizr':
  399. switch ($method) {
  400. case 'GET':
  401. $status = array();
  402. $result['status'] = 'success';
  403. $result['statusText'] = 'success';
  404. $status['status'] = organizrStatus();
  405. $status['user'] = $GLOBALS['organizrUser'];
  406. $status['categories'] = loadTabs()['categories'];
  407. $status['tabs'] = loadTabs()['tabs'];
  408. $result['data'] = $status;
  409. break;
  410. default:
  411. $result['status'] = 'error';
  412. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  413. break;
  414. }
  415. break;
  416. case 'v1_auth':
  417. switch ($method) {
  418. case 'GET':
  419. auth();
  420. break;
  421. default:
  422. $result['status'] = 'error';
  423. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  424. break;
  425. }
  426. break;
  427. case 'v1_plugin':
  428. switch ($method) {
  429. case 'GET':
  430. if(qualifyRequest(1)){
  431. $result['status'] = 'success';
  432. $result['statusText'] = 'success';
  433. $result['data'] = 'plugin admin';
  434. }elseif(qualifyRequest(998)){
  435. $result['status'] = 'success';
  436. $result['statusText'] = 'success';
  437. $result['data'] = 'plugin logged in';
  438. }elseif(qualifyRequest(999)){
  439. $result['status'] = 'success';
  440. $result['statusText'] = 'success';
  441. $result['data'] = 'plugin guest';
  442. }else{
  443. $result['status'] = 'error';
  444. $result['statusText'] = 'API/Token invalid or not set';
  445. $result['data'] = null;
  446. }
  447. break;
  448. case 'POST':
  449. if(qualifyRequest(1)){
  450. $result['status'] = 'success';
  451. $result['statusText'] = 'success';
  452. $result['data'] = 'plugin admin';
  453. }elseif(qualifyRequest(998)){
  454. $result['status'] = 'success';
  455. $result['statusText'] = 'success';
  456. $result['data'] = 'plugin logged in';
  457. }elseif(qualifyRequest(999)){
  458. $result['status'] = 'success';
  459. $result['statusText'] = 'success';
  460. $result['data'] = 'plugin guest';
  461. }else{
  462. $result['status'] = 'error';
  463. $result['statusText'] = 'API/Token invalid or not set';
  464. $result['data'] = null;
  465. }
  466. break;
  467. default:
  468. $result['status'] = 'error';
  469. $result['statusText'] = 'The function requested is not defined for method: '.$method;
  470. break;
  471. }
  472. break;
  473. default:
  474. //No Function Available
  475. $result['status'] = 'error';
  476. $result['statusText'] = 'function requested is not defined';
  477. break;
  478. }
  479. //Set Default Result
  480. if(!$result){
  481. $result['status'] = "error";
  482. $result['error'] = "An error has occurred";
  483. }
  484. $result['generationDate'] = $GLOBALS['currentTime'];
  485. $generationTime += microtime(true);
  486. $result['generationTime'] = (sprintf('%f', $generationTime)*1000).'ms';
  487. //return JSON array
  488. exit(json_encode($result, JSON_HEX_QUOT | JSON_HEX_TAG));